HEX
Server: Apache
System: Linux sh00085.hostgator.com 5.14.0-687.29.1.el9_8.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Jul 23 16:18:48 EDT 2026 x86_64
User: yqegzjte (1064)
PHP: 8.5.8
Disabled: NONE
Upload Files
File: //etc/httpd/error_log
[Thu Jul 30 11:41:00.445809 2026] [lsapi:notice] [pid 8929:tid 8929] mod_lsapi:  version 1.1-92
[Thu Jul 30 11:41:00.449768 2026] [:notice] [pid 642290:tid 642290] [host root@sh00085.hostgator.com] mod_lsapi:  Selfstarter 642290 started
[Thu Jul 30 11:41:01.052505 2026] [ssl:warn] [pid 8929:tid 8929] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Jul 30 11:41:01.060103 2026] [qos:notice] [pid 8929:tid 8929] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Jul 30 11:41:01.222999 2026] [http2:info] [pid 8929:tid 8929] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Thu Jul 30 11:41:01.226053 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Jul 30 11:41:01.226072 2026] [core:notice] [pid 8929:tid 8929] AH00094: Command line: '/usr/sbin/httpd'
[Thu Jul 30 11:41:02.271201 2026] [http2:info] [pid 642360:tid 642360] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 11:41:02.491053 2026] [core:error] [pid 642360:tid 642539] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.491079 2026] [core:error] [pid 642360:tid 642539] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.491317 2026] [core:error] [pid 642360:tid 642540] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.491339 2026] [core:error] [pid 642360:tid 642540] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.513916 2026] [core:error] [pid 642360:tid 642556] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.513936 2026] [core:error] [pid 642360:tid 642556] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.523304 2026] [security2:error] [pid 642360:tid 642516] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-npSUkh3e5AhEJOBQfQABqX8"]
[Thu Jul 30 11:41:02.526907 2026] [core:error] [pid 642360:tid 642554] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.526929 2026] [core:error] [pid 642360:tid 642554] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.529818 2026] [core:error] [pid 642360:tid 642558] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.529855 2026] [core:error] [pid 642360:tid 642558] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:02.556877 2026] [security2:error] [pid 642360:tid 642386] [remote 57.141.0.48:45156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/1685"] [unique_id "amt-npSUkh3e5AhEJOBQvQAB7Rk"]
[Thu Jul 30 11:41:02.718507 2026] [security2:error] [pid 642360:tid 642576] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQtgAAAeU"]
[Thu Jul 30 11:41:02.783433 2026] [security2:error] [pid 642360:tid 642524] [client 43.166.136.153:38040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.136.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Euclid"] [unique_id "amt-npSUkh3e5AhEJOBQowAAAbE"], referer: https://ejournalugj.com/index_php/Euclid
[Thu Jul 30 11:41:03.135633 2026] [security2:error] [pid 642360:tid 642574] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQsAAAAeM"]
[Thu Jul 30 11:41:04.114743 2026] [security2:error] [pid 642360:tid 642554] [client 181.54.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amt-n5SUkh3e5AhEJOBQ2QAAAc8"], referer: https://online-hope.com
[Thu Jul 30 11:41:04.425000 2026] [security2:error] [pid 642360:tid 642530] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQxQABtx4"]
[Thu Jul 30 11:41:04.478618 2026] [security2:error] [pid 642360:tid 642525] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQxgABsh8"]
[Thu Jul 30 11:41:04.622623 2026] [security2:error] [pid 642360:tid 642585] [client 109.236.45.26:49488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.45.236.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "journeywomenscenter.org"] [uri "/xmlrpc.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ8QAAAe4"]
[Thu Jul 30 11:41:04.623294 2026] [security2:error] [pid 642360:tid 642585] [client 109.236.45.26:49488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "journeywomenscenter.org"] [uri "/xmlrpc.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ8QAAAe4"]
[Thu Jul 30 11:41:04.751017 2026] [security2:error] [pid 642360:tid 642597] [client 185.156.175.171:50440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ8gAAAfo"]
[Thu Jul 30 11:41:04.751130 2026] [security2:error] [pid 642360:tid 642597] [client 185.156.175.171:50440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ8gAAAfo"]
[Thu Jul 30 11:41:04.989060 2026] [core:error] [pid 642360:tid 642491] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:41:04.989085 2026] [core:error] [pid 642360:tid 642491] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:41:05.432478 2026] [security2:error] [pid 642360:tid 642610] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-npSUkh3e5AhEJOBQxwACByA"]
[Thu Jul 30 11:41:06.196730 2026] [security2:error] [pid 642360:tid 642600] [client 104.210.56.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRCAAB_S8"]
[Thu Jul 30 11:41:06.428843 2026] [security2:error] [pid 642360:tid 642616] [client 172.237.109.114:55602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ_QAAAg0"]
[Thu Jul 30 11:41:06.450599 2026] [security2:error] [pid 642360:tid 642613] [client 172.237.109.114:6488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ-AAAAgo"]
[Thu Jul 30 11:41:06.507339 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:37976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRCQAAAec"]
[Thu Jul 30 11:41:06.555291 2026] [security2:error] [pid 642360:tid 642611] [client 172.237.109.114:10415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ9wAAAgg"]
[Thu Jul 30 11:41:06.556008 2026] [security2:error] [pid 642360:tid 642493] [client 172.237.109.114:24535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRBQAAAZI"]
[Thu Jul 30 11:41:06.594913 2026] [security2:error] [pid 642360:tid 642615] [client 172.237.109.114:18197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ_AAAAgw"]
[Thu Jul 30 11:41:06.603459 2026] [security2:error] [pid 642360:tid 642492] [client 172.237.109.114:29607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRAQAAAZE"]
[Thu Jul 30 11:41:06.616282 2026] [security2:error] [pid 642360:tid 642496] [client 172.237.109.114:30333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ_gAAAZU"]
[Thu Jul 30 11:41:06.623623 2026] [security2:error] [pid 642360:tid 642511] [client 172.237.109.114:64277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ9gAAAaQ"]
[Thu Jul 30 11:41:06.623696 2026] [security2:error] [pid 642360:tid 642614] [client 172.237.109.114:26191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ-wAAAgs"]
[Thu Jul 30 11:41:06.628441 2026] [security2:error] [pid 642360:tid 642499] [client 172.237.109.114:60882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRAAAAAZg"]
[Thu Jul 30 11:41:06.650932 2026] [security2:error] [pid 642360:tid 642555] [client 172.237.109.114:11858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRBgAAAdA"]
[Thu Jul 30 11:41:06.661999 2026] [security2:error] [pid 642360:tid 642543] [client 172.237.109.114:65318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBRDAAAAcQ"]
[Thu Jul 30 11:41:06.666598 2026] [security2:error] [pid 642360:tid 642540] [client 172.237.109.114:1426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBRDQAAAcE"]
[Thu Jul 30 11:41:06.668819 2026] [security2:error] [pid 642360:tid 642542] [client 172.237.109.114:32816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRBwAAAcM"]
[Thu Jul 30 11:41:06.693780 2026] [security2:error] [pid 642360:tid 642524] [client 172.237.109.114:7571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBQ-gAAAbE"]
[Thu Jul 30 11:41:06.775306 2026] [security2:error] [pid 642360:tid 642512] [client 172.237.109.114:53532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBREAAAAaU"]
[Thu Jul 30 11:41:06.781836 2026] [security2:error] [pid 642360:tid 642565] [client 172.237.109.114:25893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBRDwAAAdo"]
[Thu Jul 30 11:41:07.233563 2026] [security2:error] [pid 642360:tid 642574] [client 172.237.109.114:26104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oZSUkh3e5AhEJOBRDgAAAeM"]
[Thu Jul 30 11:41:07.258896 2026] [security2:error] [pid 642360:tid 642534] [client 172.237.109.114:45802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-oJSUkh3e5AhEJOBRBAAAAbs"]
[Thu Jul 30 11:41:07.342382 2026] [security2:error] [pid 642360:tid 642507] [client 5.161.117.52:10464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amt-o5SUkh3e5AhEJOBRQQAAAaA"], referer: https://globalmarks.pk/
[Thu Jul 30 11:41:07.439737 2026] [core:notice] [pid 642360:tid 642425] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:07.831779 2026] [security2:error] [pid 642360:tid 642430] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-o5SUkh3e5AhEJOBRUwABo0U"]
[Thu Jul 30 11:41:07.831959 2026] [security2:error] [pid 642360:tid 642510] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-o5SUkh3e5AhEJOBRUwABo0U"]
[Thu Jul 30 11:41:07.891171 2026] [security2:error] [pid 642360:tid 642533] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-o5SUkh3e5AhEJOBRRwAAAbo"]
[Thu Jul 30 11:41:08.113389 2026] [security2:error] [pid 642360:tid 642561] [client 176.241.66.87:35317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-pJSUkh3e5AhEJOBRXQAAAdY"]
[Thu Jul 30 11:41:08.113547 2026] [security2:error] [pid 642360:tid 642561] [client 176.241.66.87:35317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-pJSUkh3e5AhEJOBRXQAAAdY"]
[Thu Jul 30 11:41:08.580991 2026] [core:notice] [pid 642360:tid 642570] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:10.246420 2026] [security2:error] [pid 642360:tid 642455] [remote 57.141.0.68:49244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/FocusandScope"] [unique_id "amt-ppSUkh3e5AhEJOBRjQABzV4"]
[Thu Jul 30 11:41:10.466129 2026] [security2:error] [pid 642360:tid 642532] [client 178.20.44.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-pZSUkh3e5AhEJOBRdwABuVc"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 11:41:11.263816 2026] [security2:error] [pid 642360:tid 642496] [client 143.198.88.13:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-976d73dd.ubp.hmu.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amt-p5SUkh3e5AhEJOBRnwAAAZU"], referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.489856 2026] [core:error] [pid 642360:tid 642530] [client 143.198.88.13:57839] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.489878 2026] [core:error] [pid 642360:tid 642530] [client 143.198.88.13:57839] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.719012 2026] [core:error] [pid 642360:tid 642542] [client 143.198.88.13:61900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.719035 2026] [core:error] [pid 642360:tid 642542] [client 143.198.88.13:61900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.974757 2026] [core:error] [pid 642360:tid 642599] [client 143.198.88.13:57622] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:11.974779 2026] [core:error] [pid 642360:tid 642599] [client 143.198.88.13:57622] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:12.216563 2026] [core:error] [pid 642360:tid 642576] [client 143.198.88.13:49169] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:12.216584 2026] [core:error] [pid 642360:tid 642576] [client 143.198.88.13:49169] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-88aad310.rja.sfu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:41:12.300415 2026] [security2:error] [pid 642360:tid 642597] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-qJSUkh3e5AhEJOBRsAAB-mk"]
[Thu Jul 30 11:41:12.408187 2026] [security2:error] [pid 642360:tid 642491] [client 178.20.44.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-ppSUkh3e5AhEJOBRmQABkGM"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 11:41:12.415372 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:12.523179 2026] [security2:error] [pid 642360:tid 642541] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-ppSUkh3e5AhEJOBRmAABwmI"]
[Thu Jul 30 11:41:13.170715 2026] [core:notice] [pid 642360:tid 642472] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:13.958035 2026] [security2:error] [pid 642360:tid 642532] [client 1.13.255.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-qZSUkh3e5AhEJOBRzgAAAbk"], referer: https://cnpinyin.com/
[Thu Jul 30 11:41:15.666885 2026] [core:error] [pid 642360:tid 642369] [remote 57.141.0.33:39774] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:15.666919 2026] [core:error] [pid 642360:tid 642369] [remote 57.141.0.33:39774] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:15.878363 2026] [security2:error] [pid 642360:tid 642565] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-q5SUkh3e5AhEJOBR9QAAAdo"]
[Thu Jul 30 11:41:16.300082 2026] [security2:error] [pid 642360:tid 642549] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aletihadfurnituretransportllc.cc"] [uri "/index.php"] [unique_id "amt-rJSUkh3e5AhEJOBSBQAByg4"], referer: www.website-93bf5d36.fyb.fxy.temporary.site/blog//wp-login.php
[Thu Jul 30 11:41:16.431588 2026] [security2:error] [pid 642360:tid 642535] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-q5SUkh3e5AhEJOBSAAAAAbw"]
[Thu Jul 30 11:41:16.695677 2026] [security2:error] [pid 642360:tid 642510] [client 213.152.187.230:55074] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amt-rJSUkh3e5AhEJOBSFgAAAaM"]
[Thu Jul 30 11:41:16.695791 2026] [security2:error] [pid 642360:tid 642510] [client 213.152.187.230:55074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amt-rJSUkh3e5AhEJOBSFgAAAaM"]
[Thu Jul 30 11:41:17.430042 2026] [security2:error] [pid 642360:tid 642506] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-q5SUkh3e5AhEJOBR_QABnww"]
[Thu Jul 30 11:41:17.508261 2026] [security2:error] [pid 642360:tid 642391] [remote 74.7.241.59:48388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amt-rZSUkh3e5AhEJOBSNAABoR4"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/pixelyoursite/includes
[Thu Jul 30 11:41:18.184238 2026] [core:notice] [pid 642360:tid 642546] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:18.376677 2026] [security2:error] [pid 642360:tid 642580] [client 57.141.0.23:49986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amt-rZSUkh3e5AhEJOBSWwAB6Us"], referer: https://igetvape-australia.com/store/?product-page=4&add-to-cart=1049
[Thu Jul 30 11:41:18.533182 2026] [security2:error] [pid 642360:tid 642587] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-rZSUkh3e5AhEJOBSMwAB8AE"]
[Thu Jul 30 11:41:18.652870 2026] [security2:error] [pid 642360:tid 642444] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-rpSUkh3e5AhEJOBSbQAB11M"]
[Thu Jul 30 11:41:18.653026 2026] [security2:error] [pid 642360:tid 642562] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-rpSUkh3e5AhEJOBSbQAB11M"]
[Thu Jul 30 11:41:18.747149 2026] [security2:error] [pid 642360:tid 642494] [client 176.241.66.87:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-rpSUkh3e5AhEJOBScgAAAZM"]
[Thu Jul 30 11:41:18.747275 2026] [security2:error] [pid 642360:tid 642494] [client 176.241.66.87:53119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-rpSUkh3e5AhEJOBScgAAAZM"]
[Thu Jul 30 11:41:18.832699 2026] [security2:error] [pid 642360:tid 642545] [client 43.172.195.154:36912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/09/26/collection-cachemire-c-et-a/"] [unique_id "amt-rpSUkh3e5AhEJOBSagAAAcY"]
[Thu Jul 30 11:41:18.990299 2026] [fcgid:warn] [pid 642360:tid 642578] (70014)End of file found: [client 157.245.105.107:39920] mod_fcgid: can't get data from http client
[Thu Jul 30 11:41:19.239651 2026] [security2:error] [pid 642360:tid 642550] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-rpSUkh3e5AhEJOBSbgAAAcs"]
[Thu Jul 30 11:41:19.461221 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:19.466476 2026] [security2:error] [pid 642360:tid 642582] [client 43.172.197.47:58842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/09/26/collection-cachemire-c-et-a/"] [unique_id "amt-r5SUkh3e5AhEJOBSggAAAes"], referer: https://carnetdeshopping.com/index.php/2016/09/26/collection-cachemire-c-et-a/
[Thu Jul 30 11:41:20.065859 2026] [security2:error] [pid 642360:tid 642602] [client 213.152.187.230:45272] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt-sJSUkh3e5AhEJOBSiwAAAf8"]
[Thu Jul 30 11:41:20.065972 2026] [security2:error] [pid 642360:tid 642602] [client 213.152.187.230:45272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt-sJSUkh3e5AhEJOBSiwAAAf8"]
[Thu Jul 30 11:41:22.932595 2026] [security2:error] [pid 642360:tid 642616] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-spSUkh3e5AhEJOBStAACDWs"]
[Thu Jul 30 11:41:23.397808 2026] [authz_core:error] [pid 642360:tid 642613] [client 118.194.253.208:58554] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/config.yml
[Thu Jul 30 11:41:23.995169 2026] [security2:error] [pid 642360:tid 642547] [client 185.156.175.171:40066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt-s5SUkh3e5AhEJOBS0wAAAcg"]
[Thu Jul 30 11:41:23.995264 2026] [security2:error] [pid 642360:tid 642547] [client 185.156.175.171:40066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt-s5SUkh3e5AhEJOBS0wAAAcg"]
[Thu Jul 30 11:41:24.236582 2026] [security2:error] [pid 642360:tid 642531] [client 72.27.155.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amt-s5SUkh3e5AhEJOBSzwAAAbg"], referer: https://online-hope.com
[Thu Jul 30 11:41:24.686559 2026] [core:error] [pid 642360:tid 642496] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.686582 2026] [core:error] [pid 642360:tid 642496] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.710694 2026] [core:error] [pid 642360:tid 642533] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.710714 2026] [core:error] [pid 642360:tid 642533] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.723954 2026] [core:error] [pid 642360:tid 642561] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:24.723991 2026] [core:error] [pid 642360:tid 642561] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:25.345516 2026] [security2:error] [pid 642360:tid 642551] [client 74.7.241.192:38182] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.mxk.djb.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amt-tZSUkh3e5AhEJOBTBQAAAcw"]
[Thu Jul 30 11:41:25.647821 2026] [security2:error] [pid 642360:tid 642583] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-tJSUkh3e5AhEJOBS-gAB7Hk"]
[Thu Jul 30 11:41:26.274997 2026] [security2:error] [pid 642360:tid 642583] [client 50.6.43.217:10952] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amt-tpSUkh3e5AhEJOBTHQAAAew"]
[Thu Jul 30 11:41:26.306767 2026] [http2:info] [pid 643253:tid 643253] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 11:41:26.701769 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTtwAAAfY
[Thu Jul 30 11:41:26.704874 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTuQAAAbU
[Thu Jul 30 11:41:26.705059 2026] [qos:error] [pid 643253:tid 643461] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiUwAAAE0
[Thu Jul 30 11:41:26.708202 2026] [qos:error] [pid 642360:tid 642504] [client 136.109.111.23:47498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTugAAAZ0
[Thu Jul 30 11:41:26.711084 2026] [qos:error] [pid 642360:tid 642543] [client 136.109.111.23:47850] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTvAAAAcQ
[Thu Jul 30 11:41:26.712555 2026] [qos:error] [pid 643253:tid 643468] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiVgAAAFQ
[Thu Jul 30 11:41:26.713604 2026] [qos:error] [pid 643253:tid 643471] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiWQAAAFc
[Thu Jul 30 11:41:26.713626 2026] [qos:error] [pid 643253:tid 643470] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiWAAAAFY
[Thu Jul 30 11:41:26.718796 2026] [qos:error] [pid 643253:tid 643480] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiXAAAAGA
[Thu Jul 30 11:41:26.735890 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTvgAAAgo
[Thu Jul 30 11:41:26.737149 2026] [autoindex:error] [pid 643253:tid 643482] [client 200.45.130.42:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:41:26.745090 2026] [qos:error] [pid 643253:tid 643489] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiYgAAAGk
[Thu Jul 30 11:41:26.846810 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTwAAAAfc
[Thu Jul 30 11:41:26.885099 2026] [qos:error] [pid 642360:tid 642504] [client 136.109.111.23:47246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTwgAAAZ0
[Thu Jul 30 11:41:26.885407 2026] [qos:error] [pid 642360:tid 642543] [client 136.109.111.23:47374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTwwAAAcQ
[Thu Jul 30 11:41:26.886657 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47236] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTxAAAAf4
[Thu Jul 30 11:41:26.887384 2026] [qos:error] [pid 643253:tid 643495] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiZAAAAG8
[Thu Jul 30 11:41:26.950947 2026] [qos:error] [pid 642360:tid 642563] [client 136.109.111.23:47714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTxwAAAdg
[Thu Jul 30 11:41:26.952028 2026] [qos:error] [pid 643253:tid 643499] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYiZgAAAHM
[Thu Jul 30 11:41:26.973058 2026] [qos:error] [pid 643253:tid 643465] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYidAAAAFE
[Thu Jul 30 11:41:26.987901 2026] [qos:error] [pid 642360:tid 642568] [client 136.109.111.23:47760] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTygAAAd0
[Thu Jul 30 11:41:26.990831 2026] [authz_core:error] [pid 642360:tid 642527] [client 118.194.253.208:44398] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/serverless.yml
[Thu Jul 30 11:41:26.991612 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTzAAAAf8
[Thu Jul 30 11:41:26.992333 2026] [qos:error] [pid 642360:tid 642525] [client 136.109.111.23:47488] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTzQAAAbI
[Thu Jul 30 11:41:26.993258 2026] [qos:error] [pid 643253:tid 643476] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-tsjqbtjBYzqM1uYifAAAAFw
[Thu Jul 30 11:41:26.993778 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBTzgAAAfY
[Thu Jul 30 11:41:26.997258 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:47406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBT0AAAAfc
[Thu Jul 30 11:41:26.998662 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBT0gAAAdQ
[Thu Jul 30 11:41:26.998963 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47628] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBT0QAAAbU
[Thu Jul 30 11:41:26.999568 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47618] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-tpSUkh3e5AhEJOBT0wAAAbU
[Thu Jul 30 11:41:27.003927 2026] [qos:error] [pid 642360:tid 642543] [client 136.109.111.23:47562] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT1AAAAcQ
[Thu Jul 30 11:41:27.005710 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47716] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT1QAAAf4
[Thu Jul 30 11:41:27.007471 2026] [qos:error] [pid 643253:tid 643480] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYifgAAAGA
[Thu Jul 30 11:41:27.021844 2026] [qos:error] [pid 642360:tid 642563] [client 136.109.111.23:47700] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT1wAAAdg
[Thu Jul 30 11:41:27.025619 2026] [qos:error] [pid 643253:tid 643462] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYigAAAAE4
[Thu Jul 30 11:41:27.038301 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT2QAAAdM
[Thu Jul 30 11:41:27.044966 2026] [qos:error] [pid 643253:tid 643491] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYihQAAAGs
[Thu Jul 30 11:41:27.114960 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBT3AAAAfY
[Thu Jul 30 11:41:27.125646 2026] [qos:error] [pid 642360:tid 642504] [client 136.109.111.23:47796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT3wAAAZ0
[Thu Jul 30 11:41:27.143912 2026] [qos:error] [pid 643253:tid 643496] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYiiQAAAHA
[Thu Jul 30 11:41:27.147550 2026] [qos:error] [pid 642360:tid 642533] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT4wAAAbo
[Thu Jul 30 11:41:27.157579 2026] [qos:error] [pid 643253:tid 643500] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYiiwAAAHQ
[Thu Jul 30 11:41:27.165535 2026] [qos:error] [pid 642360:tid 642537] [client 136.109.111.23:47594] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT5gAAAb4
[Thu Jul 30 11:41:27.172129 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47450] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT5wAAAdM
[Thu Jul 30 11:41:27.201696 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT6QAAAf8
[Thu Jul 30 11:41:27.202052 2026] [qos:error] [pid 642360:tid 642588] [client 136.109.111.23:47306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT6gAAAfE
[Thu Jul 30 11:41:27.224122 2026] [qos:error] [pid 642360:tid 642525] [client 136.109.111.23:47714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT7AAAAbI
[Thu Jul 30 11:41:27.225746 2026] [qos:error] [pid 642360:tid 642521] [client 136.109.111.23:47318] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT7QAAAa4
[Thu Jul 30 11:41:27.226127 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT7gAAAfY
[Thu Jul 30 11:41:27.227593 2026] [qos:error] [pid 642360:tid 642527] [client 136.109.111.23:47246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT8AAAAbQ
[Thu Jul 30 11:41:27.227644 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:47374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT7wAAAgo
[Thu Jul 30 11:41:27.228396 2026] [qos:error] [pid 642360:tid 642504] [client 136.109.111.23:47760] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT8QAAAZ0
[Thu Jul 30 11:41:27.229243 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47488] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT8gAAAdQ
[Thu Jul 30 11:41:27.229705 2026] [qos:error] [pid 642360:tid 642543] [client 136.109.111.23:47270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT8wAAAcQ
[Thu Jul 30 11:41:27.229776 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT9AAAAf4
[Thu Jul 30 11:41:27.230631 2026] [qos:error] [pid 642360:tid 642533] [client 136.109.111.23:47236] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT9QAAAbo
[Thu Jul 30 11:41:27.231480 2026] [qos:error] [pid 642360:tid 642523] [client 136.109.111.23:47344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT9gAAAbA
[Thu Jul 30 11:41:27.235308 2026] [qos:error] [pid 642360:tid 642537] [client 136.109.111.23:47412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT9wAAAb4
[Thu Jul 30 11:41:27.235789 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47580] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT-AAAAdM
[Thu Jul 30 11:41:27.241413 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47694] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT-QAAAbU
[Thu Jul 30 11:41:27.244372 2026] [qos:error] [pid 642360:tid 642578] [client 136.109.111.23:47186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT-gAAAec
[Thu Jul 30 11:41:27.248371 2026] [qos:error] [pid 642360:tid 642568] [client 136.109.111.23:47618] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT-wAAAd0
[Thu Jul 30 11:41:27.258628 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:47406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBT_AAAAfc
[Thu Jul 30 11:41:27.296220 2026] [security2:error] [pid 642360:tid 642520] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tpSUkh3e5AhEJOBTiAAAAa0"]
[Thu Jul 30 11:41:27.324329 2026] [http2:info] [pid 643573:tid 643573] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 11:41:27.346676 2026] [security2:error] [pid 643253:tid 643410] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiIAAAABo"]
[Thu Jul 30 11:41:27.355364 2026] [security2:error] [pid 643253:tid 643413] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiHAAAAB0"]
[Thu Jul 30 11:41:27.371440 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUBAAAAdM
[Thu Jul 30 11:41:27.394427 2026] [qos:error] [pid 642360:tid 642606] [client 136.109.111.23:47796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUCAAAAgM
[Thu Jul 30 11:41:27.395020 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUCQAAAfc
[Thu Jul 30 11:41:27.441986 2026] [qos:error] [pid 642360:tid 642520] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUDAAAAa0
[Thu Jul 30 11:41:27.444350 2026] [core:notice] [pid 643253:tid 643459] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:27.445846 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47594] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUDgAAAfY
[Thu Jul 30 11:41:27.446052 2026] [qos:error] [pid 642360:tid 642521] [client 136.109.111.23:47524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUDQAAAa4
[Thu Jul 30 11:41:27.446121 2026] [qos:error] [pid 642360:tid 642522] [client 136.109.111.23:47384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUDwAAAa8
[Thu Jul 30 11:41:27.446699 2026] [qos:error] [pid 642360:tid 642577] [client 136.109.111.23:47306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUEQAAAeY
[Thu Jul 30 11:41:27.447528 2026] [qos:error] [pid 642360:tid 642612] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUEAAAAgk
[Thu Jul 30 11:41:27.448190 2026] [qos:error] [pid 642360:tid 642531] [client 136.109.111.23:47714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUEgAAAbg
[Thu Jul 30 11:41:27.448832 2026] [qos:error] [pid 642360:tid 642527] [client 136.109.111.23:47690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUEwAAAbQ
[Thu Jul 30 11:41:27.449717 2026] [qos:error] [pid 643573:tid 643729] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TJQAAAic
[Thu Jul 30 11:41:27.453804 2026] [qos:error] [pid 642360:tid 642576] [client 136.109.111.23:47246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUFQAAAeU
[Thu Jul 30 11:41:27.454381 2026] [qos:error] [pid 642360:tid 642576] [client 136.109.111.23:47318] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUFwAAAeU
[Thu Jul 30 11:41:27.454685 2026] [qos:error] [pid 642360:tid 642542] [client 136.109.111.23:47374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUFgAAAcM
[Thu Jul 30 11:41:27.458214 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47760] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUGAAAAf4
[Thu Jul 30 11:41:27.458779 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47450] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUGQAAAdM
[Thu Jul 30 11:41:27.461519 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUGgAAAbU
[Thu Jul 30 11:41:27.467609 2026] [qos:error] [pid 642360:tid 642606] [client 136.109.111.23:47236] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUHAAAAgM
[Thu Jul 30 11:41:27.477714 2026] [qos:error] [pid 643573:tid 643718] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TKAAAAhw
[Thu Jul 30 11:41:27.482812 2026] [qos:error] [pid 642360:tid 642520] [client 136.109.111.23:47362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUIAAAAa0
[Thu Jul 30 11:41:27.491616 2026] [qos:error] [pid 643573:tid 643727] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TKgAAAiU
[Thu Jul 30 11:41:27.539153 2026] [qos:error] [pid 643573:tid 643715] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TKwAAAhk
[Thu Jul 30 11:41:27.612549 2026] [qos:error] [pid 642360:tid 642527] [client 136.109.111.23:47186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUJQAAAbQ
[Thu Jul 30 11:41:27.612623 2026] [qos:error] [pid 642360:tid 642531] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUJgAAAbg
[Thu Jul 30 11:41:27.619090 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47618] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUKAAAAdQ
[Thu Jul 30 11:41:27.622087 2026] [qos:error] [pid 642360:tid 642542] [client 136.109.111.23:47406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUKgAAAcM
[Thu Jul 30 11:41:27.622355 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUKwAAAf4
[Thu Jul 30 11:41:27.628672 2026] [qos:error] [pid 643253:tid 643488] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYilQAAAGg
[Thu Jul 30 11:41:27.628871 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47558] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBULAAAAdM
[Thu Jul 30 11:41:27.657531 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUMAAAAgo
[Thu Jul 30 11:41:27.682837 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUNQAAAf8
[Thu Jul 30 11:41:27.682998 2026] [qos:error] [pid 642360:tid 642505] [client 136.109.111.23:47594] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUNAAAAZ4
[Thu Jul 30 11:41:27.684224 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUNgAAAf8
[Thu Jul 30 11:41:27.684623 2026] [qos:error] [pid 642360:tid 642521] [client 136.109.111.23:47384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUNwAAAa4
[Thu Jul 30 11:41:27.684922 2026] [qos:error] [pid 642360:tid 642527] [client 136.109.111.23:47220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUOwAAAbQ
[Thu Jul 30 11:41:27.685065 2026] [qos:error] [pid 642360:tid 642577] [client 136.109.111.23:47690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUOgAAAeY
[Thu Jul 30 11:41:27.685099 2026] [qos:error] [pid 642360:tid 642540] [client 136.109.111.23:47306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUOAAAAcE
[Thu Jul 30 11:41:27.685574 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUOQAAAfY
[Thu Jul 30 11:41:27.686458 2026] [qos:error] [pid 642360:tid 642531] [client 136.109.111.23:47446] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUPAAAAbg
[Thu Jul 30 11:41:27.688072 2026] [qos:error] [pid 642360:tid 642502] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUPQAAAZs
[Thu Jul 30 11:41:27.706698 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUQQAAAdM
[Thu Jul 30 11:41:27.708063 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUQgAAAdM
[Thu Jul 30 11:41:27.711716 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUQwAAAbU
[Thu Jul 30 11:41:27.713460 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:47246] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBURAAAAgo
[Thu Jul 30 11:41:27.713651 2026] [qos:error] [pid 642360:tid 642594] [client 136.109.111.23:47374] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBURgAAAfc
[Thu Jul 30 11:41:27.720263 2026] [qos:error] [pid 642360:tid 642505] [client 136.109.111.23:47488] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUSAAAAZ4
[Thu Jul 30 11:41:27.721710 2026] [qos:error] [pid 642360:tid 642602] [client 136.109.111.23:47450] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUSQAAAf8
[Thu Jul 30 11:41:27.731735 2026] [qos:error] [pid 643253:tid 643492] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t8jqbtjBYzqM1uYilwAAAGw
[Thu Jul 30 11:41:27.784359 2026] [qos:error] [pid 642360:tid 642540] [client 136.109.111.23:47270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUTgAAAcE
[Thu Jul 30 11:41:27.794173 2026] [qos:error] [pid 643573:tid 643762] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TOAAAAkg
[Thu Jul 30 11:41:27.850735 2026] [qos:error] [pid 642360:tid 642520] [client 136.109.111.23:47186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUUgAAAa0
[Thu Jul 30 11:41:27.852666 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUUwAAAdQ
[Thu Jul 30 11:41:27.852844 2026] [qos:error] [pid 643573:tid 643759] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TOQAAAkU
[Thu Jul 30 11:41:27.861859 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47618] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUVQAAAbU
[Thu Jul 30 11:41:27.862146 2026] [qos:error] [pid 642360:tid 642601] [client 136.109.111.23:47412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUVgAAAf4
[Thu Jul 30 11:41:27.865562 2026] [qos:error] [pid 643573:tid 643758] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TOwAAAkQ
[Thu Jul 30 11:41:27.877457 2026] [qos:error] [pid 642360:tid 642557] [client 136.109.111.23:47406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUWQAAAdI
[Thu Jul 30 11:41:27.878508 2026] [qos:error] [pid 642360:tid 642613] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUWgAAAgo
[Thu Jul 30 11:41:27.912856 2026] [security2:error] [pid 642360:tid 642560] [client 50.6.43.217:10962] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amt-t5SUkh3e5AhEJOBUXAAAAdU"]
[Thu Jul 30 11:41:27.916304 2026] [qos:error] [pid 642360:tid 642577] [client 136.109.111.23:47594] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUXgAAAeY
[Thu Jul 30 11:41:27.919358 2026] [qos:error] [pid 642360:tid 642531] [client 136.109.111.23:47150] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUYAAAAbg
[Thu Jul 30 11:41:27.919805 2026] [qos:error] [pid 642360:tid 642559] [client 136.109.111.23:47562] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUYgAAAdQ
[Thu Jul 30 11:41:27.919814 2026] [qos:error] [pid 642360:tid 642520] [client 136.109.111.23:47558] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUYQAAAa0
[Thu Jul 30 11:41:27.924113 2026] [qos:error] [pid 642360:tid 642612] [client 136.109.111.23:47532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUYwAAAgk
[Thu Jul 30 11:41:27.924590 2026] [qos:error] [pid 642360:tid 642558] [client 136.109.111.23:47384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUZAAAAdM
[Thu Jul 30 11:41:27.925381 2026] [qos:error] [pid 642360:tid 642523] [client 136.109.111.23:47306] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUZgAAAbA
[Thu Jul 30 11:41:27.925537 2026] [qos:error] [pid 642360:tid 642502] [client 136.109.111.23:47550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUZQAAAZs
[Thu Jul 30 11:41:27.925632 2026] [qos:error] [pid 643573:tid 643756] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TPAAAAkI
[Thu Jul 30 11:41:27.926009 2026] [qos:error] [pid 642360:tid 642528] [client 136.109.111.23:47690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUZwAAAbU
[Thu Jul 30 11:41:27.938241 2026] [qos:error] [pid 642360:tid 642542] [client 136.109.111.23:47832] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUaQAAAcM
[Thu Jul 30 11:41:27.940923 2026] [qos:error] [pid 642360:tid 642578] [client 136.109.111.23:47446] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUagAAAec
[Thu Jul 30 11:41:27.941042 2026] [qos:error] [pid 642360:tid 642606] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t5SUkh3e5AhEJOBUawAAAgM
[Thu Jul 30 11:41:27.951001 2026] [qos:error] [pid 642360:tid 642593] [client 136.109.111.23:47498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=136.109.111.23, id=amt-t5SUkh3e5AhEJOBUbQAAAfY
[Thu Jul 30 11:41:27.956049 2026] [qos:error] [pid 643573:tid 643766] [client 136.109.111.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.112.84, id=amt-t_xWyxgRnoFKAJ_TPwAAAkw
[Thu Jul 30 11:41:28.217199 2026] [security2:error] [pid 643253:tid 643417] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiKAAAACE"]
[Thu Jul 30 11:41:28.247432 2026] [security2:error] [pid 642360:tid 642576] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-t5SUkh3e5AhEJOBUKQAAAeU"]
[Thu Jul 30 11:41:28.277237 2026] [security2:error] [pid 643253:tid 643421] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiKwAAACU"]
[Thu Jul 30 11:41:28.286683 2026] [security2:error] [pid 643253:tid 643419] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiKQAAACM"]
[Thu Jul 30 11:41:28.294157 2026] [security2:error] [pid 643253:tid 643411] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiGwAAABs"]
[Thu Jul 30 11:41:28.374770 2026] [security2:error] [pid 642360:tid 642536] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tpSUkh3e5AhEJOBTlgAAAb0"]
[Thu Jul 30 11:41:28.378464 2026] [security2:error] [pid 643253:tid 643426] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiMAAAACo"]
[Thu Jul 30 11:41:28.389288 2026] [security2:error] [pid 642360:tid 642597] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tpSUkh3e5AhEJOBTlAAAAfo"]
[Thu Jul 30 11:41:29.311057 2026] [security2:error] [pid 642360:tid 642560] [client 68.221.186.136:22271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/LA.php"] [unique_id "amt-uZSUkh3e5AhEJOBUjAAAAdU"]
[Thu Jul 30 11:41:29.316730 2026] [security2:error] [pid 643253:tid 643432] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiOAAAADA"]
[Thu Jul 30 11:41:29.342804 2026] [security2:error] [pid 642360:tid 642499] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tpSUkh3e5AhEJOBToQAAAZg"]
[Thu Jul 30 11:41:29.383557 2026] [security2:error] [pid 643573:tid 643684] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-ufxWyxgRnoFKAJ_TUAACfWc"]
[Thu Jul 30 11:41:29.383805 2026] [security2:error] [pid 643573:tid 643815] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-ufxWyxgRnoFKAJ_TUAACfWc"]
[Thu Jul 30 11:41:29.436630 2026] [security2:error] [pid 643573:tid 643813] [client 176.241.66.87:53644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-ufxWyxgRnoFKAJ_TUwAAAns"]
[Thu Jul 30 11:41:29.436809 2026] [security2:error] [pid 643573:tid 643813] [client 176.241.66.87:53644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-ufxWyxgRnoFKAJ_TUwAAAns"]
[Thu Jul 30 11:41:29.579231 2026] [security2:error] [pid 643573:tid 643803] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-uPxWyxgRnoFKAJ_TRwACcWQ"]
[Thu Jul 30 11:41:30.047280 2026] [security2:error] [pid 642360:tid 642584] [client 68.221.186.136:20272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/admin.php"] [unique_id "amt-upSUkh3e5AhEJOBUoAAAAe0"]
[Thu Jul 30 11:41:30.241115 2026] [security2:error] [pid 643253:tid 643430] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiNQAAAC4"]
[Thu Jul 30 11:41:30.297106 2026] [security2:error] [pid 643253:tid 643438] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiPgAAADY"]
[Thu Jul 30 11:41:30.315796 2026] [security2:error] [pid 643253:tid 643442] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiPwAAADo"]
[Thu Jul 30 11:41:30.338282 2026] [security2:error] [pid 643253:tid 643452] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiSAAAAEQ"]
[Thu Jul 30 11:41:30.342208 2026] [security2:error] [pid 643253:tid 643439] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiPQAAADc"]
[Thu Jul 30 11:41:31.224821 2026] [security2:error] [pid 643253:tid 643436] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiPAAAADQ"]
[Thu Jul 30 11:41:31.242134 2026] [security2:error] [pid 643573:tid 643802] [client 68.221.186.136:22250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/class_api.php"] [unique_id "amt-u_xWyxgRnoFKAJ_TYAAAAnA"]
[Thu Jul 30 11:41:31.309187 2026] [security2:error] [pid 643253:tid 643475] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYiewAAAFs"]
[Thu Jul 30 11:41:31.311590 2026] [security2:error] [pid 643253:tid 643510] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYibgAAAH4"]
[Thu Jul 30 11:41:31.312798 2026] [security2:error] [pid 643253:tid 643461] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYicwAAAE0"]
[Thu Jul 30 11:41:31.324035 2026] [security2:error] [pid 643253:tid 643456] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYidwAAAEg"]
[Thu Jul 30 11:41:31.330105 2026] [security2:error] [pid 643253:tid 643445] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYibwAAAD0"]
[Thu Jul 30 11:41:31.337893 2026] [security2:error] [pid 643253:tid 643490] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-t8jqbtjBYzqM1uYigwAAAGo"]
[Thu Jul 30 11:41:31.974882 2026] [security2:error] [pid 643573:tid 643825] [client 68.221.186.136:14602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amt-u_xWyxgRnoFKAJ_TZgAAAoc"]
[Thu Jul 30 11:41:32.258756 2026] [security2:error] [pid 643253:tid 643509] [client 136.109.111.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt-tsjqbtjBYzqM1uYibQAAAH0"]
[Thu Jul 30 11:41:33.060179 2026] [security2:error] [pid 642360:tid 642597] [client 68.221.186.136:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.tmb/wp-login.php"] [unique_id "amt-vJSUkh3e5AhEJOBU0wAAAfo"]
[Thu Jul 30 11:41:33.579282 2026] [security2:error] [pid 643573:tid 643764] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-vfxWyxgRnoFKAJ_TcgACSiQ"]
[Thu Jul 30 11:41:33.620864 2026] [access_compat:error] [pid 643573:tid 643750] [client 157.245.105.107:57702] AH01797: client denied by server configuration: /home1/lomgzjte/public_html/web/server-status
[Thu Jul 30 11:41:33.774452 2026] [security2:error] [pid 643573:tid 643829] [client 66.249.68.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.dapperdangolf.com"] [uri "/index.php"] [unique_id "amt-u_xWyxgRnoFKAJ_TXwACiyA"]
[Thu Jul 30 11:41:33.874527 2026] [security2:error] [pid 643573:tid 643732] [client 68.221.186.136:18153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amt-vfxWyxgRnoFKAJ_TdAAAAio"]
[Thu Jul 30 11:41:34.122600 2026] [security2:error] [pid 643253:tid 643260] [remote 209.42.18.223:40882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wce.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amt-vsjqbtjBYzqM1uYiqQAAAgU"]
[Thu Jul 30 11:41:34.495466 2026] [security2:error] [pid 643573:tid 643753] [client 68.221.186.136:14882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/991176.php"] [unique_id "amt-vvxWyxgRnoFKAJ_TewAAAj8"]
[Thu Jul 30 11:41:34.732394 2026] [security2:error] [pid 642360:tid 642411] [remote 208.122.213.225:60670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daralnaseemdxb.com"] [uri "/wp-login.php"] [unique_id "amt-vpSUkh3e5AhEJOBU7gABmjI"]
[Thu Jul 30 11:41:35.968533 2026] [security2:error] [pid 643573:tid 643782] [client 68.221.186.136:14889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amt-v_xWyxgRnoFKAJ_ThwAAAlw"]
[Thu Jul 30 11:41:36.089623 2026] [proxy:error] [pid 642360:tid 642545] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:36.089675 2026] [proxy_http:error] [pid 642360:tid 642545] [client 193.47.62.167:45826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:36.090246 2026] [proxy:error] [pid 642360:tid 642545] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:36.090292 2026] [proxy_http:error] [pid 642360:tid 642545] [client 193.47.62.167:45826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:37.189467 2026] [core:notice] [pid 642360:tid 642586] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:37.918800 2026] [core:notice] [pid 642360:tid 642574] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:38.132060 2026] [security2:error] [pid 643573:tid 643729] [client 43.172.194.63:45554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amt-wfxWyxgRnoFKAJ_TmQAAAic"]
[Thu Jul 30 11:41:38.617898 2026] [core:error] [pid 643573:tid 643735] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.617923 2026] [core:error] [pid 643573:tid 643735] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.620359 2026] [core:error] [pid 642360:tid 642497] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.620390 2026] [core:error] [pid 642360:tid 642497] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.624035 2026] [core:error] [pid 643573:tid 643762] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.624054 2026] [core:error] [pid 643573:tid 643762] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.664219 2026] [core:error] [pid 643253:tid 643451] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.664242 2026] [core:error] [pid 643253:tid 643451] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.664696 2026] [core:error] [pid 643573:tid 643755] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.664709 2026] [core:error] [pid 643573:tid 643755] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:41:38.707131 2026] [security2:error] [pid 642360:tid 642577] [client 68.221.186.136:18574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amt-wpSUkh3e5AhEJOBVLgAAAeY"]
[Thu Jul 30 11:41:38.940887 2026] [security2:error] [pid 642360:tid 642404] [remote 57.141.0.63:23146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amt-wpSUkh3e5AhEJOBVMQABvis"]
[Thu Jul 30 11:41:39.119079 2026] [security2:error] [pid 643573:tid 643742] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-wvxWyxgRnoFKAJ_TowAAAjQ"]
[Thu Jul 30 11:41:39.550940 2026] [security2:error] [pid 643573:tid 643797] [client 68.221.186.136:18842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amt-w_xWyxgRnoFKAJ_TvQAAAms"]
[Thu Jul 30 11:41:40.037315 2026] [core:notice] [pid 643573:tid 643781] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:40.056071 2026] [security2:error] [pid 643573:tid 643769] [client 176.241.66.87:54178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TwgAAAk8"]
[Thu Jul 30 11:41:40.056192 2026] [security2:error] [pid 643573:tid 643769] [client 176.241.66.87:54178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TwgAAAk8"]
[Thu Jul 30 11:41:40.106317 2026] [core:error] [pid 642360:tid 642526] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 11:41:40.106347 2026] [core:error] [pid 642360:tid 642526] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 11:41:40.247703 2026] [security2:error] [pid 643573:tid 643627] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TxAACXC4"]
[Thu Jul 30 11:41:40.247842 2026] [security2:error] [pid 643573:tid 643782] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TxAACXC4"]
[Thu Jul 30 11:41:40.697595 2026] [security2:error] [pid 643573:tid 643834] [client 68.221.186.136:46731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amt-xPxWyxgRnoFKAJ_TxQAAApA"]
[Thu Jul 30 11:41:41.018249 2026] [security2:error] [pid 642360:tid 642516] [client 57.141.0.61:50488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amt-xJSUkh3e5AhEJOBVUwABqU8"], referer: https://igetvape-australia.com/product-category/alibarbar-rich-8000-puffs/?add-to-cart=1053
[Thu Jul 30 11:41:41.381254 2026] [security2:error] [pid 643253:tid 643478] [client 68.221.186.136:17656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amt-xcjqbtjBYzqM1uYitAAAAF4"]
[Thu Jul 30 11:41:41.621559 2026] [authz_core:error] [pid 642360:tid 642492] [client 157.245.105.107:57788] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.DS_Store
[Thu Jul 30 11:41:42.416351 2026] [authz_core:error] [pid 643573:tid 643711] [client 157.245.105.107:46774] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:41:42.547482 2026] [proxy:error] [pid 642360:tid 642593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:42.547535 2026] [proxy_http:error] [pid 642360:tid 642593] [client 44.216.125.112:54490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:42.548106 2026] [proxy:error] [pid 642360:tid 642593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:42.548151 2026] [proxy_http:error] [pid 642360:tid 642593] [client 44.216.125.112:54490] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:42.791333 2026] [security2:error] [pid 642360:tid 642494] [client 68.221.186.136:17622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amt-xpSUkh3e5AhEJOBVbQAAAZM"]
[Thu Jul 30 11:41:43.491896 2026] [security2:error] [pid 643573:tid 643726] [client 68.221.186.136:17630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amt-x_xWyxgRnoFKAJ_T3gAAAiQ"]
[Thu Jul 30 11:41:44.179177 2026] [security2:error] [pid 643573:tid 643756] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-x_xWyxgRnoFKAJ_T4QACQmw"]
[Thu Jul 30 11:41:44.331924 2026] [security2:error] [pid 642360:tid 642505] [client 68.221.186.136:17638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amt-yJSUkh3e5AhEJOBVgAAAAZ4"]
[Thu Jul 30 11:41:44.884828 2026] [security2:error] [pid 643253:tid 643443] [client 68.221.186.136:20280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amt-yMjqbtjBYzqM1uYitgAAADs"]
[Thu Jul 30 11:41:46.577899 2026] [authz_core:error] [pid 643573:tid 643792] [client 157.245.105.107:46796] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:41:46.893151 2026] [proxy:error] [pid 643573:tid 643828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:46.893219 2026] [proxy_http:error] [pid 643573:tid 643828] [client 34.224.175.62:29096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:46.893783 2026] [proxy:error] [pid 643573:tid 643828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:46.893827 2026] [proxy_http:error] [pid 643573:tid 643828] [client 34.224.175.62:29096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:46.977037 2026] [proxy:error] [pid 643573:tid 643831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:46.977131 2026] [proxy_http:error] [pid 643573:tid 643831] [client 32.194.121.99:16370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:46.977974 2026] [proxy:error] [pid 643573:tid 643831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:46.978046 2026] [proxy_http:error] [pid 643573:tid 643831] [client 32.194.121.99:16370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:47.545400 2026] [proxy:error] [pid 642360:tid 642574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:47.545627 2026] [proxy_http:error] [pid 642360:tid 642574] [client 54.87.222.253:46114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:47.546189 2026] [proxy:error] [pid 642360:tid 642574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:47.546232 2026] [proxy_http:error] [pid 642360:tid 642574] [client 54.87.222.253:46114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:47.634535 2026] [proxy:error] [pid 642360:tid 642597] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:47.634643 2026] [proxy_http:error] [pid 642360:tid 642597] [client 3.228.112.215:6872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:47.635507 2026] [proxy:error] [pid 642360:tid 642597] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:41:47.635572 2026] [proxy_http:error] [pid 642360:tid 642597] [client 3.228.112.215:6872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:41:48.194587 2026] [core:notice] [pid 642360:tid 642546] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:41:48.350914 2026] [security2:error] [pid 643573:tid 643752] [client 68.221.186.136:18109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amt-zPxWyxgRnoFKAJ_UDgAAAj4"]
[Thu Jul 30 11:41:48.449605 2026] [autoindex:error] [pid 642360:tid 642514] [client 40.77.167.150:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:41:49.239917 2026] [security2:error] [pid 643253:tid 643417] [client 68.221.186.136:17648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amt-zcjqbtjBYzqM1uYiuwAAACE"]
[Thu Jul 30 11:41:49.387795 2026] [security2:error] [pid 643573:tid 643694] [remote 74.7.241.60:60694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/article.php"] [unique_id "amt-zfxWyxgRnoFKAJ_UGwACSXE"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/1784122425_Physioth%C3%A9rapie%20%C3%A0%20Domicile.jpg
[Thu Jul 30 11:41:49.973042 2026] [security2:error] [pid 643573:tid 643800] [client 68.221.186.136:18104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amt-zfxWyxgRnoFKAJ_UIAAAAm4"]
[Thu Jul 30 11:41:50.042671 2026] [security2:error] [pid 642360:tid 642544] [client 213.152.187.230:40786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt-zpSUkh3e5AhEJOBV1AAAAcU"]
[Thu Jul 30 11:41:50.042779 2026] [security2:error] [pid 642360:tid 642544] [client 213.152.187.230:40786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt-zpSUkh3e5AhEJOBV1AAAAcU"]
[Thu Jul 30 11:41:50.789395 2026] [security2:error] [pid 643573:tid 643780] [client 176.241.66.87:54710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-zvxWyxgRnoFKAJ_UJwAAAlo"]
[Thu Jul 30 11:41:50.789537 2026] [security2:error] [pid 643573:tid 643780] [client 176.241.66.87:54710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-zvxWyxgRnoFKAJ_UJwAAAlo"]
[Thu Jul 30 11:41:51.152243 2026] [security2:error] [pid 643573:tid 643697] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-z_xWyxgRnoFKAJ_UKwACYHQ"]
[Thu Jul 30 11:41:51.152409 2026] [security2:error] [pid 643573:tid 643786] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-z_xWyxgRnoFKAJ_UKwACYHQ"]
[Thu Jul 30 11:41:51.211817 2026] [security2:error] [pid 643573:tid 643744] [client 68.221.186.136:20249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amt-z_xWyxgRnoFKAJ_ULQAAAjY"]
[Thu Jul 30 11:41:52.133155 2026] [security2:error] [pid 643573:tid 643791] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-z_xWyxgRnoFKAJ_UOQAAAmU"]
[Thu Jul 30 11:41:52.588927 2026] [security2:error] [pid 642360:tid 642499] [client 157.245.105.107:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.105.245.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.greensparkle.net.lom.gzj.temporary.site"] [uri "/info.php"] [unique_id "amt-0JSUkh3e5AhEJOBV9AAAAZg"]
[Thu Jul 30 11:41:53.546755 2026] [security2:error] [pid 643573:tid 643824] [client 68.221.186.136:20257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/amaxx.php"] [unique_id "amt-0fxWyxgRnoFKAJ_USgAAAoY"]
[Thu Jul 30 11:41:54.612942 2026] [security2:error] [pid 643573:tid 643760] [client 68.221.186.136:18078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/bek.php"] [unique_id "amt-0vxWyxgRnoFKAJ_UWQAAAkY"]
[Thu Jul 30 11:41:54.835287 2026] [security2:error] [pid 643573:tid 643739] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-0vxWyxgRnoFKAJ_UWwACMXw"]
[Thu Jul 30 11:41:55.399634 2026] [security2:error] [pid 642360:tid 642504] [client 46.232.235.3:47398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.greensparkle.net"] [uri "/.env"] [unique_id "amt-05SUkh3e5AhEJOBWEAAAAZ0"]
[Thu Jul 30 11:41:56.503690 2026] [security2:error] [pid 643573:tid 643797] [client 68.221.186.136:17238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amt-1PxWyxgRnoFKAJ_UeAAAAms"]
[Thu Jul 30 11:41:56.908809 2026] [authz_core:error] [pid 643573:tid 643759] [client 46.232.235.3:35508] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:41:56.925999 2026] [authz_core:error] [pid 643573:tid 643720] [client 46.232.235.3:35498] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:41:57.446545 2026] [authz_core:error] [pid 643573:tid 643818] [client 157.245.105.107:41036] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.vscode
[Thu Jul 30 11:41:57.503084 2026] [authz_core:error] [pid 642360:tid 642542] [client 46.232.235.3:35522] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:41:57.602263 2026] [security2:error] [pid 643573:tid 643826] [client 68.221.186.136:14736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/class.api.php"] [unique_id "amt-1fxWyxgRnoFKAJ_UhAAAAog"]
[Thu Jul 30 11:41:57.701768 2026] [authz_core:error] [pid 642360:tid 642604] [client 46.232.235.3:35536] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:41:57.702530 2026] [security2:error] [pid 642360:tid 642604] [client 46.232.235.3:35536] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "greensparkle.net"] [uri "/cgi-sys/403.html"] [unique_id "amt-1ZSUkh3e5AhEJOBWLAAAAgE"]
[Thu Jul 30 11:41:58.196511 2026] [security2:error] [pid 643573:tid 643716] [client 68.221.186.136:14730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/cong.php"] [unique_id "amt-1vxWyxgRnoFKAJ_UhQAAAho"]
[Thu Jul 30 11:41:58.944694 2026] [security2:error] [pid 643573:tid 643725] [client 68.221.186.136:17221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/content.php"] [unique_id "amt-1vxWyxgRnoFKAJ_UkgAAAiM"]
[Thu Jul 30 11:41:59.013654 2026] [authz_core:error] [pid 643573:tid 643726] [client 46.232.235.3:35542] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:41:59.489682 2026] [security2:error] [pid 643573:tid 643745] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/backup/.env"] [unique_id "amt-1_xWyxgRnoFKAJ_UmAAAAjc"]
[Thu Jul 30 11:41:59.681689 2026] [authz_core:error] [pid 643573:tid 643804] [client 46.232.235.3:35558] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:41:59.766851 2026] [security2:error] [pid 642360:tid 642601] [client 68.221.186.136:17228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amt-15SUkh3e5AhEJOBWRgAAAf4"]
[Thu Jul 30 11:41:59.822962 2026] [security2:error] [pid 643573:tid 643760] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/backups/.env"] [unique_id "amt-1_xWyxgRnoFKAJ_UmgAAAkY"]
[Thu Jul 30 11:42:00.155671 2026] [security2:error] [pid 643573:tid 643816] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/old/.env"] [unique_id "amt-2PxWyxgRnoFKAJ_UngAAAn4"]
[Thu Jul 30 11:42:00.252613 2026] [core:notice] [pid 642360:tid 642421] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:00.257167 2026] [security2:error] [pid 642360:tid 642566] [client 191.36.149.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/get/acm-sig-proceedings"] [unique_id "amt-15SUkh3e5AhEJOBWSQAB2zw"]
[Thu Jul 30 11:42:00.487885 2026] [security2:error] [pid 643573:tid 643806] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/temp/.env"] [unique_id "amt-2PxWyxgRnoFKAJ_UpQAAAnQ"]
[Thu Jul 30 11:42:00.506437 2026] [security2:error] [pid 643573:tid 643762] [client 68.221.186.136:20251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/elp.php"] [unique_id "amt-2PxWyxgRnoFKAJ_UpgAAAkg"]
[Thu Jul 30 11:42:00.821300 2026] [security2:error] [pid 643573:tid 643823] [client 118.194.253.208:49476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/tmp/.env"] [unique_id "amt-2PxWyxgRnoFKAJ_UqwAAAoU"]
[Thu Jul 30 11:42:01.154273 2026] [authz_core:error] [pid 643573:tid 643720] [client 118.194.253.208:49476] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.streamlit
[Thu Jul 30 11:42:01.270144 2026] [security2:error] [pid 642360:tid 642559] [client 68.221.186.136:20265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amt-2ZSUkh3e5AhEJOBWVAAAAdQ"]
[Thu Jul 30 11:42:01.522027 2026] [security2:error] [pid 642360:tid 642579] [client 176.241.66.87:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-2ZSUkh3e5AhEJOBWWAAAAeg"]
[Thu Jul 30 11:42:01.522234 2026] [security2:error] [pid 642360:tid 642579] [client 176.241.66.87:55244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-2ZSUkh3e5AhEJOBWWAAAAeg"]
[Thu Jul 30 11:42:01.775466 2026] [security2:error] [pid 643573:tid 643727] [client 68.221.186.136:14762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amt-2fxWyxgRnoFKAJ_UvQAAAiU"]
[Thu Jul 30 11:42:02.047315 2026] [security2:error] [pid 642360:tid 642417] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-2pSUkh3e5AhEJOBWXAACBjg"]
[Thu Jul 30 11:42:02.047476 2026] [security2:error] [pid 642360:tid 642609] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-2pSUkh3e5AhEJOBWXAACBjg"]
[Thu Jul 30 11:42:02.102931 2026] [core:notice] [pid 643573:tid 643616] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:02.622452 2026] [security2:error] [pid 643253:tid 643451] [client 68.221.186.136:20252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amt-2sjqbtjBYzqM1uYi5wAAAEM"]
[Thu Jul 30 11:42:03.704252 2026] [security2:error] [pid 643573:tid 643619] [remote 72.167.132.114:57990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amt-2_xWyxgRnoFKAJ_UzwACWSY"]
[Thu Jul 30 11:42:03.905777 2026] [security2:error] [pid 643253:tid 643436] [client 68.221.186.136:17222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amt-28jqbtjBYzqM1uYi7gAAADQ"]
[Thu Jul 30 11:42:04.414839 2026] [core:notice] [pid 643573:tid 643630] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:05.066195 2026] [security2:error] [pid 643573:tid 643773] [client 68.221.186.136:18049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U1gAAAlM"]
[Thu Jul 30 11:42:05.132445 2026] [core:notice] [pid 643573:tid 643631] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:05.620447 2026] [security2:error] [pid 643573:tid 643833] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U3gACjzk"]
[Thu Jul 30 11:42:05.929878 2026] [security2:error] [pid 643253:tid 643471] [client 68.221.186.136:18065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amt-3cjqbtjBYzqM1uYi_AAAAFc"]
[Thu Jul 30 11:42:05.933653 2026] [security2:error] [pid 643573:tid 643775] [client 89.37.95.54:35340] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U3QAAAlU"]
[Thu Jul 30 11:42:06.049240 2026] [security2:error] [pid 643573:tid 643775] [client 89.37.95.54:35340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U3QAAAlU"]
[Thu Jul 30 11:42:06.050304 2026] [security2:error] [pid 643573:tid 643775] [client 89.37.95.54:35340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amt-3fxWyxgRnoFKAJ_U3QAAAlU"]
[Thu Jul 30 11:42:06.217941 2026] [authz_core:error] [pid 643573:tid 643724] [client 46.232.235.3:54030] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:42:06.355277 2026] [authz_core:error] [pid 643253:tid 643456] [client 46.232.235.3:54032] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:42:06.687869 2026] [security2:error] [pid 643573:tid 643718] [client 68.221.186.136:17393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amt-3vxWyxgRnoFKAJ_U6QAAAhw"]
[Thu Jul 30 11:42:07.290069 2026] [authz_core:error] [pid 642360:tid 642532] [client 46.232.235.3:54044] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:42:07.372840 2026] [authz_core:error] [pid 642360:tid 642581] [client 46.232.235.3:54056] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:42:07.833658 2026] [security2:error] [pid 642360:tid 642515] [client 118.194.253.208:59072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.greensparkle.net"] [uri "/index.php"] [unique_id "amt-35SUkh3e5AhEJOBWpwAAAag"]
[Thu Jul 30 11:42:07.833859 2026] [security2:error] [pid 643573:tid 643725] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-3_xWyxgRnoFKAJ_U-wAAAiM"]
[Thu Jul 30 11:42:08.451008 2026] [core:notice] [pid 643573:tid 643804] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:10.102496 2026] [security2:error] [pid 643573:tid 643730] [client 68.221.186.136:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amt-4vxWyxgRnoFKAJ_VJwAAAig"]
[Thu Jul 30 11:42:10.659667 2026] [authz_core:error] [pid 643573:tid 643734] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/secrets.yml
[Thu Jul 30 11:42:10.694563 2026] [security2:error] [pid 642360:tid 642497] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-4ZSUkh3e5AhEJOBWwQABlmE"]
[Thu Jul 30 11:42:10.998867 2026] [authz_core:error] [pid 643573:tid 643796] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.secrets
[Thu Jul 30 11:42:11.340554 2026] [authz_core:error] [pid 643573:tid 643782] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env.vault
[Thu Jul 30 11:42:11.472878 2026] [security2:error] [pid 643573:tid 643827] [client 68.221.186.136:17361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amt-4_xWyxgRnoFKAJ_VNQAAAok"]
[Thu Jul 30 11:42:11.682346 2026] [authz_core:error] [pid 643573:tid 643758] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.aws
[Thu Jul 30 11:42:12.022901 2026] [authz_core:error] [pid 643573:tid 643830] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.aws
[Thu Jul 30 11:42:12.093303 2026] [security2:error] [pid 643573:tid 643740] [client 176.241.66.87:55784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VQAAAAjI"]
[Thu Jul 30 11:42:12.093441 2026] [security2:error] [pid 643573:tid 643740] [client 176.241.66.87:55784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VQAAAAjI"]
[Thu Jul 30 11:42:12.201885 2026] [security2:error] [pid 643573:tid 643833] [client 213.152.187.230:43960] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VQQAAAo8"]
[Thu Jul 30 11:42:12.202002 2026] [security2:error] [pid 643573:tid 643833] [client 213.152.187.230:43960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VQQAAAo8"]
[Thu Jul 30 11:42:12.349479 2026] [security2:error] [pid 642360:tid 642614] [client 110.249.201.23:20232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/robots.txt"] [unique_id "amt-5JSUkh3e5AhEJOBW2AAAAgs"]
[Thu Jul 30 11:42:12.363240 2026] [authz_core:error] [pid 643573:tid 643800] [client 118.194.253.208:59080] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.docker
[Thu Jul 30 11:42:12.702604 2026] [security2:error] [pid 643573:tid 643822] [client 118.194.253.208:59080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/storage/framework/.env"] [unique_id "amt-5PxWyxgRnoFKAJ_VUAAAAoQ"]
[Thu Jul 30 11:42:12.921953 2026] [security2:error] [pid 643573:tid 643661] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VVAACc1A"]
[Thu Jul 30 11:42:12.922164 2026] [security2:error] [pid 643573:tid 643805] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-5PxWyxgRnoFKAJ_VVAACc1A"]
[Thu Jul 30 11:42:13.042029 2026] [security2:error] [pid 643573:tid 643736] [client 118.194.253.208:59080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.greensparkle.net"] [uri "/laravel/.env"] [unique_id "amt-5fxWyxgRnoFKAJ_VWAAAAi4"]
[Thu Jul 30 11:42:13.317390 2026] [security2:error] [pid 643573:tid 643726] [client 68.221.186.136:29588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amt-5fxWyxgRnoFKAJ_VWgAAAiQ"]
[Thu Jul 30 11:42:14.225160 2026] [security2:error] [pid 642360:tid 642480] [remote 216.73.216.152:52199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt-5pSUkh3e5AhEJOBW-QABtHc"]
[Thu Jul 30 11:42:14.452414 2026] [security2:error] [pid 643573:tid 643789] [client 68.221.186.136:21198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amt-5vxWyxgRnoFKAJ_VYAAAAmM"]
[Thu Jul 30 11:42:15.030847 2026] [security2:error] [pid 643573:tid 643830] [client 68.221.186.136:21217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amt-5_xWyxgRnoFKAJ_VZQAAAow"]
[Thu Jul 30 11:42:15.101031 2026] [authz_core:error] [pid 642360:tid 642525] [client 118.194.253.208:59148] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.gcp
[Thu Jul 30 11:42:15.436646 2026] [authz_core:error] [pid 642360:tid 642565] [client 118.194.253.208:59148] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.gcp
[Thu Jul 30 11:42:15.639922 2026] [security2:error] [pid 643573:tid 643767] [client 68.221.186.136:21223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amt-5_xWyxgRnoFKAJ_VagAAAk0"]
[Thu Jul 30 11:42:16.126029 2026] [security2:error] [pid 643573:tid 643666] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-6PxWyxgRnoFKAJ_VbAACjVU"]
[Thu Jul 30 11:42:16.126206 2026] [security2:error] [pid 643573:tid 643831] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-6PxWyxgRnoFKAJ_VbAACjVU"]
[Thu Jul 30 11:42:16.498372 2026] [security2:error] [pid 643573:tid 643724] [client 68.221.186.136:29678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amt-6PxWyxgRnoFKAJ_VcAAAAiI"]
[Thu Jul 30 11:42:16.680492 2026] [security2:error] [pid 643573:tid 643800] [client 66.249.64.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.j-nintei.com"] [uri "/index.php"] [unique_id "amt-5_xWyxgRnoFKAJ_VZwAAAm4"]
[Thu Jul 30 11:42:17.645905 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:17.711564 2026] [security2:error] [pid 643573:tid 643733] [client 68.221.186.136:29651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amt-6fxWyxgRnoFKAJ_VdgAAAis"]
[Thu Jul 30 11:42:18.445008 2026] [security2:error] [pid 643573:tid 643827] [client 68.221.186.136:14536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amt-6vxWyxgRnoFKAJ_VegAAAok"]
[Thu Jul 30 11:42:19.451453 2026] [security2:error] [pid 643573:tid 643773] [client 68.221.186.136:19829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amt-6_xWyxgRnoFKAJ_VgAAAAlM"]
[Thu Jul 30 11:42:20.567599 2026] [security2:error] [pid 643573:tid 643669] [remote 74.7.241.59:58724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amt-7PxWyxgRnoFKAJ_VhwACGlg"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/pixelyoursite/includes
[Thu Jul 30 11:42:20.701213 2026] [security2:error] [pid 643573:tid 643819] [client 68.221.186.136:14528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amt-7PxWyxgRnoFKAJ_ViAAAAoE"]
[Thu Jul 30 11:42:21.121819 2026] [security2:error] [pid 643573:tid 643671] [remote 185.191.171.1:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifelogstory.com"] [uri "/robots.txt"] [unique_id "amt-7fxWyxgRnoFKAJ_VigACVlo"]
[Thu Jul 30 11:42:21.122019 2026] [security2:error] [pid 643573:tid 643776] [client 185.191.171.1:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifelogstory.com"] [uri "/robots.txt"] [unique_id "amt-7fxWyxgRnoFKAJ_VigACVlo"]
[Thu Jul 30 11:42:21.453542 2026] [security2:error] [pid 643573:tid 643736] [client 68.221.186.136:29677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amt-7fxWyxgRnoFKAJ_VjAAAAi4"]
[Thu Jul 30 11:42:22.567278 2026] [security2:error] [pid 643573:tid 643815] [client 57.141.0.66:54566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amt-7vxWyxgRnoFKAJ_VlAACfVs"], referer: https://igetvape-australia.com/store/?product-page=11&add-to-cart=117
[Thu Jul 30 11:42:22.607409 2026] [security2:error] [pid 643573:tid 643675] [remote 47.128.28.107:64228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moose-knuckles-jacket-black-10/"] [unique_id "amt-7vxWyxgRnoFKAJ_VlwACbV4"]
[Thu Jul 30 11:42:22.776155 2026] [security2:error] [pid 642360:tid 642553] [client 176.241.66.87:40163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-7pSUkh3e5AhEJOBXSAAAAc4"]
[Thu Jul 30 11:42:22.776274 2026] [security2:error] [pid 642360:tid 642553] [client 176.241.66.87:40163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt-7pSUkh3e5AhEJOBXSAAAAc4"]
[Thu Jul 30 11:42:23.017310 2026] [security2:error] [pid 643573:tid 643806] [client 162.19.8.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "higherdimensionsii.com"] [uri "/index.php"] [unique_id "amt-7vxWyxgRnoFKAJ_VlQACdFw"]
[Thu Jul 30 11:42:23.241116 2026] [core:notice] [pid 642360:tid 642400] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:23.728041 2026] [security2:error] [pid 643573:tid 643738] [client 68.221.186.136:20224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amt-7_xWyxgRnoFKAJ_VowAAAjA"]
[Thu Jul 30 11:42:23.886898 2026] [security2:error] [pid 643573:tid 643610] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-7_xWyxgRnoFKAJ_VpgACWR0"]
[Thu Jul 30 11:42:23.887098 2026] [security2:error] [pid 643573:tid 643779] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt-7_xWyxgRnoFKAJ_VpgACWR0"]
[Thu Jul 30 11:42:23.951265 2026] [security2:error] [pid 643573:tid 643603] [remote 185.191.171.13:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifelogstory.com"] [uri "/"] [unique_id "amt-7_xWyxgRnoFKAJ_VpwACJBY"]
[Thu Jul 30 11:42:23.951439 2026] [security2:error] [pid 643573:tid 643726] [client 185.191.171.13:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifelogstory.com"] [uri "/"] [unique_id "amt-7_xWyxgRnoFKAJ_VpwACJBY"]
[Thu Jul 30 11:42:25.659056 2026] [security2:error] [pid 643573:tid 643684] [remote 57.141.0.66:44056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/REFORMASI/issue/archive"] [unique_id "amt-8fxWyxgRnoFKAJ_VvQACOGc"]
[Thu Jul 30 11:42:26.171798 2026] [security2:error] [pid 643573:tid 643618] [remote 85.208.96.194:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifelogstory.com"] [uri "/sitemap.xml"] [unique_id "amt-8vxWyxgRnoFKAJ_VzAACMSU"]
[Thu Jul 30 11:42:26.172049 2026] [security2:error] [pid 643573:tid 643739] [client 85.208.96.194:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifelogstory.com"] [uri "/sitemap.xml"] [unique_id "amt-8vxWyxgRnoFKAJ_VzAACMSU"]
[Thu Jul 30 11:42:26.524204 2026] [security2:error] [pid 642360:tid 642526] [client 68.221.186.136:14217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amt-8pSUkh3e5AhEJOBXagAAAbM"]
[Thu Jul 30 11:42:26.745328 2026] [security2:error] [pid 642360:tid 642417] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-8pSUkh3e5AhEJOBXbAAB1jg"]
[Thu Jul 30 11:42:26.745635 2026] [security2:error] [pid 642360:tid 642561] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-8pSUkh3e5AhEJOBXbAAB1jg"]
[Thu Jul 30 11:42:26.847479 2026] [security2:error] [pid 643253:tid 643467] [client 172.237.109.114:7652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8sjqbtjBYzqM1uYjMAAAAFM"]
[Thu Jul 30 11:42:26.847834 2026] [security2:error] [pid 643573:tid 643744] [client 172.237.109.114:31046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VxgAAAjY"]
[Thu Jul 30 11:42:26.887723 2026] [security2:error] [pid 643573:tid 643743] [client 172.237.109.114:64374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VyQAAAjU"]
[Thu Jul 30 11:42:26.905581 2026] [security2:error] [pid 643573:tid 643833] [client 172.237.109.114:19304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VxwAAAo8"]
[Thu Jul 30 11:42:26.905730 2026] [security2:error] [pid 643573:tid 643835] [client 172.237.109.114:12036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VyAAAApE"]
[Thu Jul 30 11:42:26.906789 2026] [security2:error] [pid 643253:tid 643492] [client 172.237.109.114:44511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8sjqbtjBYzqM1uYjMgAAAGw"]
[Thu Jul 30 11:42:26.927170 2026] [security2:error] [pid 643253:tid 643484] [client 172.237.109.114:45682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8sjqbtjBYzqM1uYjMQAAAGQ"]
[Thu Jul 30 11:42:26.930624 2026] [security2:error] [pid 643573:tid 643823] [client 172.237.109.114:6984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8vxWyxgRnoFKAJ_VygAAAoU"]
[Thu Jul 30 11:42:27.139141 2026] [security2:error] [pid 643573:tid 643597] [remote 213.180.203.123:59738] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/enhancing-project-management-processes-with-business-consulting/"] [unique_id "amt-8_xWyxgRnoFKAJ_V2wACVxA"]
[Thu Jul 30 11:42:27.167104 2026] [core:notice] [pid 642360:tid 642515] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:27.512430 2026] [security2:error] [pid 643253:tid 643446] [client 185.156.175.171:59254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amt-88jqbtjBYzqM1uYjOgAAAD4"]
[Thu Jul 30 11:42:27.512647 2026] [security2:error] [pid 643253:tid 643446] [client 185.156.175.171:59254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amt-88jqbtjBYzqM1uYjOgAAAD4"]
[Thu Jul 30 11:42:27.700463 2026] [security2:error] [pid 643253:tid 643463] [client 162.19.8.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "higherdimensionsii.com"] [uri "/index.php"] [unique_id "amt-8sjqbtjBYzqM1uYjOAAATxQ"]
[Thu Jul 30 11:42:27.788240 2026] [security2:error] [pid 643573:tid 643763] [client 172.237.109.114:32112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V2QAAAkk"]
[Thu Jul 30 11:42:27.796491 2026] [security2:error] [pid 643573:tid 643827] [client 172.237.109.114:57885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V2gAAAok"]
[Thu Jul 30 11:42:27.801476 2026] [security2:error] [pid 643573:tid 643736] [client 172.237.109.114:20806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V2AAAAi4"]
[Thu Jul 30 11:42:27.801502 2026] [security2:error] [pid 642360:tid 642524] [client 172.237.109.114:27051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-85SUkh3e5AhEJOBXbwAAAbE"]
[Thu Jul 30 11:42:27.816486 2026] [security2:error] [pid 643573:tid 643723] [client 172.237.109.114:44997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V1wAAAiE"]
[Thu Jul 30 11:42:27.817206 2026] [security2:error] [pid 642360:tid 642516] [client 172.237.109.114:12228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-85SUkh3e5AhEJOBXcAAAAak"]
[Thu Jul 30 11:42:27.837334 2026] [security2:error] [pid 642360:tid 642605] [client 172.237.109.114:65228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-85SUkh3e5AhEJOBXcQAAAgI"]
[Thu Jul 30 11:42:27.843688 2026] [security2:error] [pid 643573:tid 643767] [client 172.237.109.114:58190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-8_xWyxgRnoFKAJ_V3AAAAk0"]
[Thu Jul 30 11:42:27.969381 2026] [security2:error] [pid 642360:tid 642403] [remote 57.141.0.44:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amt-85SUkh3e5AhEJOBXgAAB5io"]
[Thu Jul 30 11:42:28.002150 2026] [security2:error] [pid 643573:tid 643807] [client 68.221.186.136:14220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amt-9PxWyxgRnoFKAJ_V4wAAAnU"]
[Thu Jul 30 11:42:28.308811 2026] [autoindex:error] [pid 643573:tid 643826] [client 143.198.88.13:56054] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: www.website-aa1e85b2.kxl.dup.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:42:28.685139 2026] [security2:error] [pid 643573:tid 643731] [client 172.237.109.114:57655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-9PxWyxgRnoFKAJ_V5wAAAik"]
[Thu Jul 30 11:42:28.685201 2026] [security2:error] [pid 643573:tid 643728] [client 172.237.109.114:24036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-9PxWyxgRnoFKAJ_V5gAAAiY"]
[Thu Jul 30 11:42:28.713860 2026] [security2:error] [pid 643573:tid 643727] [client 172.237.109.114:51884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-9PxWyxgRnoFKAJ_V6AAAAiU"]
[Thu Jul 30 11:42:28.714129 2026] [security2:error] [pid 643253:tid 643495] [client 172.237.109.114:14432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt-9MjqbtjBYzqM1uYjPAAAAG8"]
[Thu Jul 30 11:42:29.803700 2026] [security2:error] [pid 643253:tid 643475] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-9cjqbtjBYzqM1uYjPgAAWxg"]
[Thu Jul 30 11:42:30.142252 2026] [security2:error] [pid 643573:tid 643741] [client 68.221.186.136:20328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amt-9vxWyxgRnoFKAJ_V_QAAAjM"]
[Thu Jul 30 11:42:30.363616 2026] [security2:error] [pid 642360:tid 642596] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt-9ZSUkh3e5AhEJOBXmgAAAfk"]
[Thu Jul 30 11:42:30.735964 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:30.765961 2026] [security2:error] [pid 643573:tid 643714] [client 64.31.3.126:50668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amt-7_xWyxgRnoFKAJ_VpAAAAkw"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2269
[Thu Jul 30 11:42:30.854731 2026] [security2:error] [pid 642360:tid 642526] [client 68.221.186.136:14222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amt-9pSUkh3e5AhEJOBXqAAAAbM"]
[Thu Jul 30 11:42:31.050458 2026] [core:notice] [pid 643573:tid 643780] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:31.409935 2026] [core:notice] [pid 643253:tid 643280] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:31.435068 2026] [security2:error] [pid 643573:tid 643767] [client 68.221.186.136:18911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amt-9_xWyxgRnoFKAJ_WCQAAAk0"]
[Thu Jul 30 11:42:31.623972 2026] [security2:error] [pid 643573:tid 643751] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-9_xWyxgRnoFKAJ_WBwACPWk"]
[Thu Jul 30 11:42:31.856488 2026] [core:notice] [pid 643573:tid 643693] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:31.861105 2026] [security2:error] [pid 643573:tid 643759] [client 74.7.230.15:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amt-9_xWyxgRnoFKAJ_WDAACRXA"]
[Thu Jul 30 11:42:32.635062 2026] [core:notice] [pid 643573:tid 643694] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:32.876254 2026] [security2:error] [pid 643573:tid 643825] [client 68.221.186.136:18936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amt--PxWyxgRnoFKAJ_WFwAAAoc"]
[Thu Jul 30 11:42:33.110883 2026] [authz_core:error] [pid 643573:tid 643794] [client 94.154.43.183:26860] AH01630: client denied by server configuration: /home1/jstnyxte/public_html/website_602f6769/.env
[Thu Jul 30 11:42:33.142934 2026] [security2:error] [pid 642360:tid 642592] [client 85.208.98.18:23764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/robots.txt"] [unique_id "amt--ZSUkh3e5AhEJOBXvQAAAfU"]
[Thu Jul 30 11:42:33.143057 2026] [security2:error] [pid 642360:tid 642592] [client 85.208.98.18:23764] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/robots.txt"] [unique_id "amt--ZSUkh3e5AhEJOBXvQAAAfU"]
[Thu Jul 30 11:42:33.440309 2026] [security2:error] [pid 643573:tid 643784] [client 85.208.98.18:20012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amt--fxWyxgRnoFKAJ_WIAAAAl4"], referer: https://insurancecouncilinc.com/
[Thu Jul 30 11:42:33.440442 2026] [security2:error] [pid 643573:tid 643784] [client 85.208.98.18:20012] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amt--fxWyxgRnoFKAJ_WIAAAAl4"], referer: https://insurancecouncilinc.com/
[Thu Jul 30 11:42:33.444867 2026] [security2:error] [pid 643573:tid 643757] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-32476423.xnc.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt--PxWyxgRnoFKAJ_WEwAAAkM"]
[Thu Jul 30 11:42:33.554253 2026] [security2:error] [pid 643573:tid 643713] [client 176.241.66.87:40843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt--fxWyxgRnoFKAJ_WIwAAAhc"]
[Thu Jul 30 11:42:33.554393 2026] [security2:error] [pid 643573:tid 643713] [client 176.241.66.87:40843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt--fxWyxgRnoFKAJ_WIwAAAhc"]
[Thu Jul 30 11:42:33.872761 2026] [security2:error] [pid 643573:tid 643701] [remote 85.208.98.18:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "teknomalay.com"] [uri "/robots.txt"] [unique_id "amt--fxWyxgRnoFKAJ_WJgACI3g"], referer: http://teknomalay.com/robots.txt
[Thu Jul 30 11:42:33.872930 2026] [security2:error] [pid 643573:tid 643725] [client 85.208.98.18:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teknomalay.com"] [uri "/robots.txt"] [unique_id "amt--fxWyxgRnoFKAJ_WJgACI3g"], referer: http://teknomalay.com/robots.txt
[Thu Jul 30 11:42:33.934914 2026] [security2:error] [pid 643573:tid 643834] [client 68.221.186.136:21162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amt--fxWyxgRnoFKAJ_WJwAAApA"]
[Thu Jul 30 11:42:34.808704 2026] [security2:error] [pid 642360:tid 642462] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt--pSUkh3e5AhEJOBXygABv2U"]
[Thu Jul 30 11:42:34.808864 2026] [security2:error] [pid 642360:tid 642538] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt--pSUkh3e5AhEJOBXygABv2U"]
[Thu Jul 30 11:42:35.085466 2026] [security2:error] [pid 642360:tid 642500] [client 47.79.228.42:53176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.womenclothingbox.com"] [uri "/"] [unique_id "amt--5SUkh3e5AhEJOBX8AAAAZk"]
[Thu Jul 30 11:42:35.158459 2026] [security2:error] [pid 642360:tid 642575] [client 47.79.228.42:53176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.womenclothingbox.com"] [uri "/wp-json/batch/v1"] [unique_id "amt--5SUkh3e5AhEJOBX9QAAAeQ"]
[Thu Jul 30 11:42:35.415814 2026] [security2:error] [pid 643573:tid 643809] [client 207.58.142.67:37617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt--vxWyxgRnoFKAJ_WMAAAAnc"]
[Thu Jul 30 11:42:35.897813 2026] [core:notice] [pid 642360:tid 642505] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:42:36.097925 2026] [security2:error] [pid 643573:tid 643767] [client 68.221.186.136:14113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amt-_PxWyxgRnoFKAJ_WPwAAAk0"]
[Thu Jul 30 11:42:36.128003 2026] [security2:error] [pid 642360:tid 642490] [client 207.58.142.67:19888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-_JSUkh3e5AhEJOBX_wAAAY8"]
[Thu Jul 30 11:42:36.303243 2026] [security2:error] [pid 643573:tid 643703] [remote 52.167.144.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/303/310"] [unique_id "amt-_PxWyxgRnoFKAJ_WQwACYHo"]
[Thu Jul 30 11:42:36.856012 2026] [security2:error] [pid 643573:tid 643815] [client 207.58.142.67:7634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-_PxWyxgRnoFKAJ_WRwAAAn0"]
[Thu Jul 30 11:42:37.009800 2026] [core:error] [pid 642360:tid 642543] [client 66.249.74.5:34855] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:42:37.009827 2026] [core:error] [pid 642360:tid 642543] [client 66.249.74.5:34855] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:42:37.444299 2026] [security2:error] [pid 643573:tid 643698] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-_fxWyxgRnoFKAJ_WSgACGXU"]
[Thu Jul 30 11:42:37.444470 2026] [security2:error] [pid 643573:tid 643715] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt-_fxWyxgRnoFKAJ_WSgACGXU"]
[Thu Jul 30 11:42:37.558642 2026] [security2:error] [pid 643573:tid 643740] [client 68.221.186.136:20291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amt-_fxWyxgRnoFKAJ_WSwAAAjI"]
[Thu Jul 30 11:42:37.574243 2026] [security2:error] [pid 643573:tid 643757] [client 207.58.142.67:16126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-_fxWyxgRnoFKAJ_WTAAAAkM"]
[Thu Jul 30 11:42:38.057606 2026] [security2:error] [pid 642360:tid 642590] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt-_ZSUkh3e5AhEJOBYCgAB8w4"]
[Thu Jul 30 11:42:38.210940 2026] [security2:error] [pid 643573:tid 643819] [client 68.221.186.136:20292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amt-_vxWyxgRnoFKAJ_WTwAAAoE"]
[Thu Jul 30 11:42:38.292918 2026] [security2:error] [pid 643573:tid 643823] [client 207.58.142.67:23387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-_vxWyxgRnoFKAJ_WUAAAAoU"]
[Thu Jul 30 11:42:39.004277 2026] [security2:error] [pid 643573:tid 643830] [client 207.58.142.67:28630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-__xWyxgRnoFKAJ_WVAAAAow"]
[Thu Jul 30 11:42:39.045511 2026] [security2:error] [pid 643573:tid 643708] [remote 52.167.144.212:7225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/planejamento-controle-gestao-convenios/article.php"] [unique_id "amt-__xWyxgRnoFKAJ_WVQACN38"]
[Thu Jul 30 11:42:39.328159 2026] [security2:error] [pid 643573:tid 643755] [client 68.221.186.136:21167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amt-__xWyxgRnoFKAJ_WWgAAAkE"]
[Thu Jul 30 11:42:39.739501 2026] [security2:error] [pid 643573:tid 643820] [client 207.58.142.67:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt-__xWyxgRnoFKAJ_WYAAAAoI"]
[Thu Jul 30 11:42:39.867671 2026] [security2:error] [pid 643573:tid 643832] [client 68.221.186.136:21136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amt-__xWyxgRnoFKAJ_WYQAAAo4"]
[Thu Jul 30 11:42:40.467779 2026] [security2:error] [pid 643573:tid 643747] [client 207.58.142.67:22071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_APxWyxgRnoFKAJ_WZwAAAjk"]
[Thu Jul 30 11:42:41.121352 2026] [security2:error] [pid 643573:tid 643834] [client 68.221.186.136:18898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amt_AfxWyxgRnoFKAJ_WcAAAApA"]
[Thu Jul 30 11:42:41.187500 2026] [security2:error] [pid 643573:tid 643755] [client 207.58.142.67:20976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_AfxWyxgRnoFKAJ_WcQAAAkE"]
[Thu Jul 30 11:42:41.580320 2026] [security2:error] [pid 643573:tid 643820] [client 74.7.175.180:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.allmontecristi.com"] [uri "/robots.txt"] [unique_id "amt_AfxWyxgRnoFKAJ_WeAAAAoI"]
[Thu Jul 30 11:42:41.580883 2026] [security2:error] [pid 643573:tid 643788] [client 74.7.175.180:35404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.allmontecristi.com"] [uri "/robots.txt"] [unique_id "amt_AfxWyxgRnoFKAJ_WdgACYnw"]
[Thu Jul 30 11:42:41.659157 2026] [security2:error] [pid 643573:tid 643589] [remote 57.141.0.20:42538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15975943371/feed/rss2/"] [unique_id "amt_AfxWyxgRnoFKAJ_WeQACcgg"]
[Thu Jul 30 11:42:41.914685 2026] [security2:error] [pid 643573:tid 643805] [client 207.58.142.67:55153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_AfxWyxgRnoFKAJ_WewAAAnM"]
[Thu Jul 30 11:42:42.619859 2026] [security2:error] [pid 642360:tid 642508] [client 207.58.142.67:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_ApSUkh3e5AhEJOBYkAAAAaE"]
[Thu Jul 30 11:42:42.928600 2026] [authz_core:error] [pid 643573:tid 643834] [client 118.194.253.208:39376] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.hcloud.toml
[Thu Jul 30 11:42:43.249204 2026] [security2:error] [pid 642360:tid 642468] [remote 3.7.204.22:36196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.204.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amt_A5SUkh3e5AhEJOBYlQAB4Gs"]
[Thu Jul 30 11:42:43.266256 2026] [authz_core:error] [pid 643573:tid 643716] [client 118.194.253.208:39376] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/hcloud.yml
[Thu Jul 30 11:42:43.335235 2026] [security2:error] [pid 643573:tid 643751] [client 207.58.142.67:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_A_xWyxgRnoFKAJ_WjgAAAj0"]
[Thu Jul 30 11:42:43.344222 2026] [security2:error] [pid 643573:tid 643763] [client 40.77.167.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amt_AvxWyxgRnoFKAJ_WiQAAAkk"]
[Thu Jul 30 11:42:43.388282 2026] [security2:error] [pid 643253:tid 643419] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_AsjqbtjBYzqM1uYjSQAAIxs"]
[Thu Jul 30 11:42:43.719751 2026] [security2:error] [pid 643573:tid 643605] [remote 85.208.98.18:25646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amt_A_xWyxgRnoFKAJ_WlwACYhg"]
[Thu Jul 30 11:42:43.719930 2026] [security2:error] [pid 643573:tid 643788] [client 85.208.98.18:25646] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amt_A_xWyxgRnoFKAJ_WlwACYhg"]
[Thu Jul 30 11:42:44.047687 2026] [security2:error] [pid 643573:tid 643813] [client 207.58.142.67:40711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BPxWyxgRnoFKAJ_WngAAAns"]
[Thu Jul 30 11:42:44.126287 2026] [security2:error] [pid 643573:tid 643805] [client 176.241.66.87:57784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_BPxWyxgRnoFKAJ_WoQAAAnM"]
[Thu Jul 30 11:42:44.126414 2026] [security2:error] [pid 643573:tid 643805] [client 176.241.66.87:57784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_BPxWyxgRnoFKAJ_WoQAAAnM"]
[Thu Jul 30 11:42:44.281407 2026] [authz_core:error] [pid 643573:tid 643775] [client 118.194.253.208:39376] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.linode-cli
[Thu Jul 30 11:42:44.434855 2026] [security2:error] [pid 643573:tid 643756] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_A_xWyxgRnoFKAJ_WmQAAAkI"]
[Thu Jul 30 11:42:44.470284 2026] [security2:error] [pid 643573:tid 643787] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_A_xWyxgRnoFKAJ_WnAAAAmE"]
[Thu Jul 30 11:42:44.762295 2026] [security2:error] [pid 642360:tid 642561] [client 207.58.142.67:47633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BJSUkh3e5AhEJOBYowAAAdY"]
[Thu Jul 30 11:42:44.862921 2026] [security2:error] [pid 642360:tid 642381] [remote 216.73.216.152:37561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_BJSUkh3e5AhEJOBYpQACARQ"]
[Thu Jul 30 11:42:45.296278 2026] [authz_core:error] [pid 643573:tid 643806] [client 118.194.253.208:39376] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.vultr-cli.yaml
[Thu Jul 30 11:42:45.466919 2026] [security2:error] [pid 642360:tid 642550] [client 207.58.142.67:23476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BZSUkh3e5AhEJOBYsAAAAcs"]
[Thu Jul 30 11:42:45.671355 2026] [security2:error] [pid 643573:tid 643590] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_BfxWyxgRnoFKAJ_WrgACYgk"]
[Thu Jul 30 11:42:45.671557 2026] [security2:error] [pid 643573:tid 643788] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_BfxWyxgRnoFKAJ_WrgACYgk"]
[Thu Jul 30 11:42:46.173693 2026] [security2:error] [pid 643573:tid 643798] [client 207.58.142.67:34477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BvxWyxgRnoFKAJ_WtQAAAmw"]
[Thu Jul 30 11:42:46.889232 2026] [security2:error] [pid 643573:tid 643812] [client 207.58.142.67:1853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_BvxWyxgRnoFKAJ_WvAAAAno"]
[Thu Jul 30 11:42:47.396153 2026] [security2:error] [pid 643573:tid 643609] [remote 85.208.98.18:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "teknomalay.com"] [uri "/category/tutorial/"] [unique_id "amt_B_xWyxgRnoFKAJ_WwAACZBw"]
[Thu Jul 30 11:42:47.396449 2026] [security2:error] [pid 643573:tid 643790] [client 85.208.98.18:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teknomalay.com"] [uri "/category/tutorial/"] [unique_id "amt_B_xWyxgRnoFKAJ_WwAACZBw"]
[Thu Jul 30 11:42:47.608474 2026] [security2:error] [pid 643573:tid 643713] [client 207.58.142.67:45036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_B_xWyxgRnoFKAJ_WwwAAAhc"]
[Thu Jul 30 11:42:48.039619 2026] [security2:error] [pid 643573:tid 643600] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_CPxWyxgRnoFKAJ_WyQACexM"]
[Thu Jul 30 11:42:48.039830 2026] [security2:error] [pid 643573:tid 643813] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_CPxWyxgRnoFKAJ_WyQACexM"]
[Thu Jul 30 11:42:48.328366 2026] [security2:error] [pid 643573:tid 643819] [client 207.58.142.67:8246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_CPxWyxgRnoFKAJ_WzQAAAoE"]
[Thu Jul 30 11:42:48.534334 2026] [security2:error] [pid 642360:tid 642408] [remote 97.74.93.24:56472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amt_CJSUkh3e5AhEJOBYygABpS8"]
[Thu Jul 30 11:42:49.046064 2026] [security2:error] [pid 643573:tid 643718] [client 207.58.142.67:43216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/components/com_jdownloads/assets/upload/upload-handler.php"] [unique_id "amt_CfxWyxgRnoFKAJ_W1gAAAhw"]
[Thu Jul 30 11:42:49.377774 2026] [security2:error] [pid 642360:tid 642435] [remote 216.73.216.152:37561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_CZSUkh3e5AhEJOBY2wAB_Uo"]
[Thu Jul 30 11:42:49.962411 2026] [security2:error] [pid 642360:tid 642564] [client 50.116.63.89:59952] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "sh00085.hostgator.com"] [uri "/"] [unique_id "amt_CZSUkh3e5AhEJOBY6AAAAdk"]
[Thu Jul 30 11:42:50.488851 2026] [security2:error] [pid 642360:tid 642564] [client 50.116.63.89:59952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amt_CZSUkh3e5AhEJOBY6AAAAdk"]
[Thu Jul 30 11:42:50.640060 2026] [security2:error] [pid 643573:tid 643729] [client 172.237.109.114:22348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CvxWyxgRnoFKAJ_W3wAAAic"]
[Thu Jul 30 11:42:50.732038 2026] [security2:error] [pid 643573:tid 643752] [client 172.237.109.114:6923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CvxWyxgRnoFKAJ_W4AAAAj4"]
[Thu Jul 30 11:42:50.732133 2026] [security2:error] [pid 642360:tid 642490] [client 172.237.109.114:7731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CpSUkh3e5AhEJOBY6gAAAY8"]
[Thu Jul 30 11:42:50.757304 2026] [security2:error] [pid 642360:tid 642496] [client 172.237.109.114:22426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CpSUkh3e5AhEJOBY6wAAAZU"]
[Thu Jul 30 11:42:50.791649 2026] [security2:error] [pid 643253:tid 643405] [client 172.237.109.114:45295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_CsjqbtjBYzqM1uYjTwAAABU"]
[Thu Jul 30 11:42:54.347535 2026] [security2:error] [pid 642360:tid 642546] [client 172.237.109.114:38233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZEgAAAcc"]
[Thu Jul 30 11:42:54.347781 2026] [security2:error] [pid 642360:tid 642514] [client 172.237.109.114:49147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZEQAAAac"]
[Thu Jul 30 11:42:54.402524 2026] [security2:error] [pid 642360:tid 642601] [client 172.237.109.114:62292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZEAAAAf4"]
[Thu Jul 30 11:42:54.489136 2026] [security2:error] [pid 643573:tid 643729] [client 172.237.109.114:9242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DfxWyxgRnoFKAJ_W-wAAAic"]
[Thu Jul 30 11:42:54.497736 2026] [security2:error] [pid 643573:tid 643753] [client 172.237.109.114:29630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DfxWyxgRnoFKAJ_W-gAAAj8"]
[Thu Jul 30 11:42:54.500414 2026] [security2:error] [pid 643253:tid 643442] [client 172.237.109.114:14105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjUgAAADo"]
[Thu Jul 30 11:42:54.506357 2026] [security2:error] [pid 642360:tid 642589] [client 172.237.109.114:16388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZEwAAAfI"]
[Thu Jul 30 11:42:54.520756 2026] [security2:error] [pid 643253:tid 643449] [client 172.237.109.114:51745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjUwAAAEE"]
[Thu Jul 30 11:42:54.521669 2026] [security2:error] [pid 642360:tid 642591] [client 172.237.109.114:31327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZFAAAAfQ"]
[Thu Jul 30 11:42:54.524022 2026] [security2:error] [pid 643573:tid 643801] [client 172.237.109.114:18596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DfxWyxgRnoFKAJ_W_AAAAm8"]
[Thu Jul 30 11:42:54.535524 2026] [security2:error] [pid 642360:tid 642506] [client 172.237.109.114:33243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZFQAAAZ8"]
[Thu Jul 30 11:42:54.543027 2026] [security2:error] [pid 643253:tid 643411] [client 172.237.109.114:41534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjVQAAABs"]
[Thu Jul 30 11:42:54.558358 2026] [security2:error] [pid 643253:tid 643474] [client 172.237.109.114:42090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjVAAAAFo"]
[Thu Jul 30 11:42:54.558431 2026] [security2:error] [pid 643253:tid 643451] [client 172.237.109.114:28133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DcjqbtjBYzqM1uYjVgAAAEM"]
[Thu Jul 30 11:42:54.563106 2026] [security2:error] [pid 642360:tid 642494] [client 172.237.109.114:56968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_DZSUkh3e5AhEJOBZFgAAAZM"]
[Thu Jul 30 11:42:54.843824 2026] [security2:error] [pid 642360:tid 642532] [client 176.241.66.87:42425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_DpSUkh3e5AhEJOBZJgAAAbk"]
[Thu Jul 30 11:42:54.844008 2026] [security2:error] [pid 642360:tid 642532] [client 176.241.66.87:42425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_DpSUkh3e5AhEJOBZJgAAAbk"]
[Thu Jul 30 11:42:55.118567 2026] [security2:error] [pid 643573:tid 643626] [remote 74.7.241.60:38426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/article.php"] [unique_id "amt_D_xWyxgRnoFKAJ_XCQACSy0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/1784122425_Physioth%C3%A9rapie%20%C3%A0%20Domicile.jpg
[Thu Jul 30 11:42:55.204494 2026] [security2:error] [pid 643573:tid 643750] [client 213.152.161.25:34982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amt_D_xWyxgRnoFKAJ_XDAAAAjw"]
[Thu Jul 30 11:42:55.204581 2026] [security2:error] [pid 643573:tid 643750] [client 213.152.161.25:34982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amt_D_xWyxgRnoFKAJ_XDAAAAjw"]
[Thu Jul 30 11:42:55.773466 2026] [security2:error] [pid 643573:tid 643629] [remote 157.55.39.49:46851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/2025/10/08/add.php"] [unique_id "amt_D_xWyxgRnoFKAJ_XEQACeTA"]
[Thu Jul 30 11:42:56.716807 2026] [security2:error] [pid 643573:tid 643616] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_EPxWyxgRnoFKAJ_XGAACKiM"]
[Thu Jul 30 11:42:56.716996 2026] [security2:error] [pid 643573:tid 643732] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_EPxWyxgRnoFKAJ_XGAACKiM"]
[Thu Jul 30 11:42:58.614688 2026] [security2:error] [pid 643573:tid 643631] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_EvxWyxgRnoFKAJ_XJwACjDI"]
[Thu Jul 30 11:42:58.614924 2026] [security2:error] [pid 643573:tid 643830] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_EvxWyxgRnoFKAJ_XJwACjDI"]
[Thu Jul 30 11:42:59.382746 2026] [security2:error] [pid 643253:tid 643287] [remote 216.73.216.152:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_E8jqbtjBYzqM1uYjZQAATSA"]
[Thu Jul 30 11:43:00.586856 2026] [security2:error] [pid 643573:tid 643641] [remote 94.101.115.105:30416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.alseermarine.com"] [uri "/.git/config"] [unique_id "amt_FPxWyxgRnoFKAJ_XMQACdDw"], referer: http://alseermarine.ae/.git/config
[Thu Jul 30 11:43:01.607700 2026] [security2:error] [pid 643573:tid 643636] [remote 94.101.115.105:30416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.alseermarine.com"] [uri "/.git/config"] [unique_id "amt_FfxWyxgRnoFKAJ_XOgACTTc"], referer: https://alseermarine.ae/.git/config
[Thu Jul 30 11:43:02.639849 2026] [core:notice] [pid 643573:tid 643766] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:02.676630 2026] [core:notice] [pid 643253:tid 643473] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:03.365679 2026] [core:error] [pid 642360:tid 642482] (36)File name too long: [remote 91.192.240.21:20349] AH00036: access to />","sale_flash_html":""},{"attributes":{"attribute_size":"42"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N/A","display_price":209.9,"display_regular_price":209.9,"image":{"title":"8765f1ca-scaled-1.jpg","caption":"","url":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1.jpg","alt":"8765f1ca-scaled-1.jpg","src":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1-600x400.jpg","srcset":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1-600x400.jpg failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/>","sale_flash_html":""},{"attributes":{"attribute_size":"42"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N'), referer: https://kicksity.com/product/nike-air-jordan-4-mushroom/
[Thu Jul 30 11:43:04.089972 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:04.384926 2026] [security2:error] [pid 643253:tid 643288] [remote 216.73.216.152:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_GMjqbtjBYzqM1uYjawAACSE"]
[Thu Jul 30 11:43:04.748511 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:05.458652 2026] [security2:error] [pid 643573:tid 643798] [client 176.241.66.87:43395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_GfxWyxgRnoFKAJ_XegAAAmw"]
[Thu Jul 30 11:43:05.458873 2026] [security2:error] [pid 643573:tid 643798] [client 176.241.66.87:43395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_GfxWyxgRnoFKAJ_XegAAAmw"]
[Thu Jul 30 11:43:06.294576 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:13938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XZAAAAmA"]
[Thu Jul 30 11:43:06.297497 2026] [security2:error] [pid 643573:tid 643833] [client 172.236.9.101:62660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XZgAAAo8"]
[Thu Jul 30 11:43:06.310798 2026] [security2:error] [pid 643573:tid 643756] [client 172.236.9.101:8060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XYgAAAkI"]
[Thu Jul 30 11:43:06.331192 2026] [security2:error] [pid 643573:tid 643768] [client 172.236.9.101:37259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XZQAAAk4"]
[Thu Jul 30 11:43:06.335413 2026] [security2:error] [pid 643573:tid 643789] [client 172.236.9.101:37816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XZwAAAmM"]
[Thu Jul 30 11:43:06.364255 2026] [security2:error] [pid 642360:tid 642554] [client 172.236.9.101:17111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZfgAAAc8"]
[Thu Jul 30 11:43:06.386967 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:28237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XawAAAn4"]
[Thu Jul 30 11:43:06.387400 2026] [security2:error] [pid 642360:tid 642505] [client 172.236.9.101:1196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZfQAAAZ4"]
[Thu Jul 30 11:43:06.388540 2026] [security2:error] [pid 642360:tid 642571] [client 172.236.9.101:10568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZfwAAAeA"]
[Thu Jul 30 11:43:06.416376 2026] [security2:error] [pid 642360:tid 642493] [client 172.236.9.101:4317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZfAAAAZI"]
[Thu Jul 30 11:43:06.426849 2026] [security2:error] [pid 643253:tid 643495] [client 172.236.9.101:10260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GMjqbtjBYzqM1uYjagAAAG8"]
[Thu Jul 30 11:43:06.428554 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:10279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XbwAAAlk"]
[Thu Jul 30 11:43:06.446487 2026] [security2:error] [pid 642360:tid 642508] [client 172.236.9.101:6132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZewAAAaE"]
[Thu Jul 30 11:43:06.448498 2026] [security2:error] [pid 643573:tid 643819] [client 172.236.9.101:1578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XYwAAAoE"]
[Thu Jul 30 11:43:06.466186 2026] [security2:error] [pid 643573:tid 643813] [client 172.236.9.101:41573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XbQAAAns"]
[Thu Jul 30 11:43:06.505349 2026] [security2:error] [pid 643573:tid 643752] [client 172.236.9.101:50359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XaQAAAj4"]
[Thu Jul 30 11:43:06.516530 2026] [security2:error] [pid 643573:tid 643762] [client 172.236.9.101:11253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XbAAAAkg"]
[Thu Jul 30 11:43:06.528754 2026] [security2:error] [pid 643573:tid 643714] [client 172.236.9.101:36977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XagAAAhg"]
[Thu Jul 30 11:43:06.573765 2026] [security2:error] [pid 642360:tid 642544] [client 172.236.9.101:55076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GJSUkh3e5AhEJOBZgAAAAcU"]
[Thu Jul 30 11:43:06.640664 2026] [security2:error] [pid 643573:tid 643736] [client 172.236.9.101:9068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_GPxWyxgRnoFKAJ_XbgAAAi4"]
[Thu Jul 30 11:43:07.155345 2026] [security2:error] [pid 643573:tid 643808] [client 185.191.171.19:22042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/19/ataque-a-tiros-deixa-duas-pessoas-feridas-no-castelo-branco-em-joao-pessoa/"] [unique_id "amt_G_xWyxgRnoFKAJ_XgwAAAnY"]
[Thu Jul 30 11:43:07.155476 2026] [security2:error] [pid 643573:tid 643808] [client 185.191.171.19:22042] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/19/ataque-a-tiros-deixa-duas-pessoas-feridas-no-castelo-branco-em-joao-pessoa/"] [unique_id "amt_G_xWyxgRnoFKAJ_XgwAAAnY"]
[Thu Jul 30 11:43:07.631816 2026] [security2:error] [pid 643253:tid 643289] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_G8jqbtjBYzqM1uYjbwAAcSI"]
[Thu Jul 30 11:43:07.632003 2026] [security2:error] [pid 643253:tid 643497] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_G8jqbtjBYzqM1uYjbwAAcSI"]
[Thu Jul 30 11:43:08.759139 2026] [security2:error] [pid 642360:tid 642524] [client 74.208.150.73:59213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.adviseassociates.com"] [uri "/"] [unique_id "amt_HJSUkh3e5AhEJOBZoQAAAbE"]
[Thu Jul 30 11:43:09.296213 2026] [security2:error] [pid 643573:tid 643637] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_HfxWyxgRnoFKAJ_XkQACOTg"]
[Thu Jul 30 11:43:09.296381 2026] [security2:error] [pid 643573:tid 643747] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_HfxWyxgRnoFKAJ_XkQACOTg"]
[Thu Jul 30 11:43:09.386566 2026] [security2:error] [pid 643253:tid 643290] [remote 216.73.216.152:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_HcjqbtjBYzqM1uYjcgAAHiM"]
[Thu Jul 30 11:43:10.145709 2026] [core:notice] [pid 642360:tid 642603] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:10.188503 2026] [core:error] [pid 643573:tid 643656] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/
[Thu Jul 30 11:43:10.188526 2026] [core:error] [pid 643573:tid 643656] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/
[Thu Jul 30 11:43:10.733125 2026] [core:error] [pid 642360:tid 642365] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wp/
[Thu Jul 30 11:43:10.733151 2026] [core:error] [pid 642360:tid 642365] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wp/
[Thu Jul 30 11:43:11.266825 2026] [core:error] [pid 642360:tid 642373] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wp/
[Thu Jul 30 11:43:11.266848 2026] [core:error] [pid 642360:tid 642373] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wp/
[Thu Jul 30 11:43:11.799318 2026] [core:error] [pid 643573:tid 643659] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wordpress/
[Thu Jul 30 11:43:11.799347 2026] [core:error] [pid 643573:tid 643659] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wordpress/
[Thu Jul 30 11:43:12.372972 2026] [core:error] [pid 643573:tid 643632] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wordpress/
[Thu Jul 30 11:43:12.373009 2026] [core:error] [pid 643573:tid 643632] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/wordpress/
[Thu Jul 30 11:43:12.736149 2026] [security2:error] [pid 643573:tid 643765] [client 172.236.9.101:45469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IPxWyxgRnoFKAJ_XqAAAAks"]
[Thu Jul 30 11:43:12.773813 2026] [security2:error] [pid 643573:tid 643777] [client 172.236.9.101:51547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IPxWyxgRnoFKAJ_XqQAAAlc"]
[Thu Jul 30 11:43:12.853486 2026] [security2:error] [pid 643253:tid 643488] [client 172.236.9.101:35300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IMjqbtjBYzqM1uYjdAAAAGg"]
[Thu Jul 30 11:43:12.918345 2026] [core:error] [pid 643573:tid 643661] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/blog/
[Thu Jul 30 11:43:12.918367 2026] [core:error] [pid 643573:tid 643661] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/blog/
[Thu Jul 30 11:43:13.466230 2026] [core:error] [pid 643573:tid 643662] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/blog/
[Thu Jul 30 11:43:13.466271 2026] [core:error] [pid 643573:tid 643662] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/blog/
[Thu Jul 30 11:43:13.664641 2026] [core:error] [pid 643573:tid 643666] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/old/
[Thu Jul 30 11:43:13.664666 2026] [core:error] [pid 643573:tid 643666] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/old/
[Thu Jul 30 11:43:14.200492 2026] [security2:error] [pid 643253:tid 643428] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_IcjqbtjBYzqM1uYjegAAACw"]
[Thu Jul 30 11:43:14.241528 2026] [core:error] [pid 643573:tid 643669] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/old/
[Thu Jul 30 11:43:14.241566 2026] [core:error] [pid 643573:tid 643669] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/old/
[Thu Jul 30 11:43:14.452235 2026] [core:error] [pid 643573:tid 643671] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/test/
[Thu Jul 30 11:43:14.452268 2026] [core:error] [pid 643573:tid 643671] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/test/
[Thu Jul 30 11:43:14.533673 2026] [security2:error] [pid 643573:tid 643755] [client 172.236.9.101:35549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XsgAAAkE"]
[Thu Jul 30 11:43:14.541199 2026] [security2:error] [pid 643573:tid 643739] [client 172.236.9.101:47670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XswAAAjE"]
[Thu Jul 30 11:43:14.547109 2026] [security2:error] [pid 642360:tid 642538] [client 172.236.9.101:28648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZwQAAAb8"]
[Thu Jul 30 11:43:14.662030 2026] [core:error] [pid 642360:tid 642440] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/test/
[Thu Jul 30 11:43:14.662056 2026] [core:error] [pid 642360:tid 642440] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/test/
[Thu Jul 30 11:43:15.071009 2026] [security2:error] [pid 643573:tid 643668] [remote 216.73.216.152:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_I_xWyxgRnoFKAJ_XzQACLlc"]
[Thu Jul 30 11:43:15.231066 2026] [security2:error] [pid 642360:tid 642532] [client 172.236.9.101:8763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZxQAAAbk"]
[Thu Jul 30 11:43:15.236631 2026] [core:error] [pid 643573:tid 643670] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/dev/
[Thu Jul 30 11:43:15.236666 2026] [core:error] [pid 643573:tid 643670] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/dev/
[Thu Jul 30 11:43:15.244102 2026] [security2:error] [pid 643253:tid 643385] [client 172.236.9.101:15723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IcjqbtjBYzqM1uYjdgAAAAE"]
[Thu Jul 30 11:43:15.248714 2026] [security2:error] [pid 642360:tid 642503] [client 172.236.9.101:49879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZwwAAAZw"]
[Thu Jul 30 11:43:15.252604 2026] [security2:error] [pid 642360:tid 642528] [client 172.236.9.101:60028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZyAAAAbU"]
[Thu Jul 30 11:43:15.260794 2026] [security2:error] [pid 643573:tid 643716] [client 172.236.9.101:49114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XtAAAAho"]
[Thu Jul 30 11:43:15.261155 2026] [security2:error] [pid 642360:tid 642557] [client 172.236.9.101:63132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZyQAAAdI"]
[Thu Jul 30 11:43:15.261456 2026] [security2:error] [pid 642360:tid 642570] [client 172.236.9.101:34216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZxwAAAd8"]
[Thu Jul 30 11:43:15.263643 2026] [security2:error] [pid 642360:tid 642575] [client 172.236.9.101:62264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZxgAAAeQ"]
[Thu Jul 30 11:43:15.272899 2026] [security2:error] [pid 642360:tid 642511] [client 172.236.9.101:32376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZxAAAAaQ"]
[Thu Jul 30 11:43:15.273935 2026] [security2:error] [pid 642360:tid 642500] [client 172.236.9.101:61914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZygAAAZk"]
[Thu Jul 30 11:43:15.277304 2026] [security2:error] [pid 643573:tid 643737] [client 172.236.9.101:25817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XtgAAAi8"]
[Thu Jul 30 11:43:15.277306 2026] [security2:error] [pid 643573:tid 643796] [client 172.236.9.101:9926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XtQAAAmo"]
[Thu Jul 30 11:43:15.278012 2026] [security2:error] [pid 642360:tid 642611] [client 172.236.9.101:9602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IZSUkh3e5AhEJOBZwgAAAgg"]
[Thu Jul 30 11:43:15.289367 2026] [security2:error] [pid 643573:tid 643829] [client 172.236.9.101:6480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_IfxWyxgRnoFKAJ_XtwAAAos"]
[Thu Jul 30 11:43:15.442055 2026] [core:error] [pid 643573:tid 643672] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/dev/
[Thu Jul 30 11:43:15.442076 2026] [core:error] [pid 643573:tid 643672] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/dev/
[Thu Jul 30 11:43:15.647386 2026] [core:error] [pid 642360:tid 642417] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/backup/
[Thu Jul 30 11:43:15.647418 2026] [core:error] [pid 642360:tid 642417] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/backup/
[Thu Jul 30 11:43:15.847843 2026] [core:error] [pid 642360:tid 642430] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/backup/
[Thu Jul 30 11:43:15.847872 2026] [core:error] [pid 642360:tid 642430] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/backup/
[Thu Jul 30 11:43:16.046666 2026] [core:error] [pid 642360:tid 642435] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/staging/
[Thu Jul 30 11:43:16.046690 2026] [core:error] [pid 642360:tid 642435] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/staging/
[Thu Jul 30 11:43:16.080844 2026] [security2:error] [pid 642360:tid 642549] [client 176.241.66.87:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_JJSUkh3e5AhEJOBZ4AAAAco"]
[Thu Jul 30 11:43:16.080972 2026] [security2:error] [pid 642360:tid 642549] [client 176.241.66.87:59426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_JJSUkh3e5AhEJOBZ4AAAAco"]
[Thu Jul 30 11:43:16.260297 2026] [core:error] [pid 643573:tid 643601] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/staging/
[Thu Jul 30 11:43:16.260329 2026] [core:error] [pid 643573:tid 643601] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/staging/
[Thu Jul 30 11:43:16.712577 2026] [security2:error] [pid 643573:tid 643756] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_JPxWyxgRnoFKAJ_X3gAAAkI"]
[Thu Jul 30 11:43:16.891313 2026] [core:error] [pid 643573:tid 643678] [remote 74.7.228.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:43:16.891338 2026] [core:error] [pid 643573:tid 643678] [remote 74.7.228.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:43:16.891591 2026] [security2:error] [pid 643573:tid 643739] [client 74.7.228.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.professionalfurnituremovingcompanyllc.store"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amt_JPxWyxgRnoFKAJ_X5QACMWE"]
[Thu Jul 30 11:43:17.065566 2026] [core:error] [pid 643573:tid 643648] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/
[Thu Jul 30 11:43:17.065592 2026] [core:error] [pid 643573:tid 643648] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.prestigemassagestudio.cfd/
[Thu Jul 30 11:43:17.699779 2026] [security2:error] [pid 643573:tid 643726] [client 34.231.118.144:3190] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/L%C3%A9o-400x400.jpg"] [unique_id "amt_JfxWyxgRnoFKAJ_X8wAAAiQ"]
[Thu Jul 30 11:43:17.826219 2026] [security2:error] [pid 642360:tid 642545] [client 74.7.241.136:39236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-14b4edfb.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_JJSUkh3e5AhEJOBZ4QABxi0"]
[Thu Jul 30 11:43:18.544462 2026] [security2:error] [pid 643573:tid 643681] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_JvxWyxgRnoFKAJ_X-QACPWQ"]
[Thu Jul 30 11:43:18.544597 2026] [security2:error] [pid 643573:tid 643751] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_JvxWyxgRnoFKAJ_X-QACPWQ"]
[Thu Jul 30 11:43:18.852628 2026] [security2:error] [pid 643573:tid 643791] [client 74.7.230.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.vvr.hfl.temporary.site"] [uri "/index.php"] [unique_id "amt_JvxWyxgRnoFKAJ_X-gAAAmU"]
[Thu Jul 30 11:43:18.853708 2026] [security2:error] [pid 643253:tid 643458] [client 74.7.230.49:47270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.vvr.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amt_JsjqbtjBYzqM1uYjfAAASiQ"]
[Thu Jul 30 11:43:19.930952 2026] [security2:error] [pid 643573:tid 643597] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_J_xWyxgRnoFKAJ_YBwACVRA"]
[Thu Jul 30 11:43:19.931171 2026] [security2:error] [pid 643573:tid 643775] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_J_xWyxgRnoFKAJ_YBwACVRA"]
[Thu Jul 30 11:43:20.201896 2026] [core:notice] [pid 643573:tid 643759] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:21.783674 2026] [security2:error] [pid 643573:tid 643767] [client 74.7.228.15:44030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amt_KfxWyxgRnoFKAJ_YDwAAAk0"]
[Thu Jul 30 11:43:23.204749 2026] [security2:error] [pid 643573:tid 643739] [client 43.153.96.233:59090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.96.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amt_KvxWyxgRnoFKAJ_YGAAAAjE"]
[Thu Jul 30 11:43:24.396355 2026] [security2:error] [pid 643573:tid 643595] [remote 216.73.216.152:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_LPxWyxgRnoFKAJ_YLgACXw4"]
[Thu Jul 30 11:43:25.339843 2026] [security2:error] [pid 642360:tid 642542] [client 172.236.9.101:9163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaIQAAAcM"]
[Thu Jul 30 11:43:25.349721 2026] [security2:error] [pid 643573:tid 643792] [client 172.236.9.101:20222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YIwAAAmY"]
[Thu Jul 30 11:43:25.355261 2026] [security2:error] [pid 643573:tid 643751] [client 172.236.9.101:24336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YHwAAAj0"]
[Thu Jul 30 11:43:25.355345 2026] [security2:error] [pid 642360:tid 642606] [client 172.236.9.101:6411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaHwAAAgM"]
[Thu Jul 30 11:43:25.365539 2026] [security2:error] [pid 643573:tid 643768] [client 172.236.9.101:8421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YJAAAAk4"]
[Thu Jul 30 11:43:25.365859 2026] [security2:error] [pid 642360:tid 642569] [client 172.236.9.101:27023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaIAAAAd4"]
[Thu Jul 30 11:43:25.366610 2026] [security2:error] [pid 643573:tid 643711] [client 172.236.9.101:24562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YHgAAAhU"]
[Thu Jul 30 11:43:25.369855 2026] [security2:error] [pid 642360:tid 642611] [client 172.236.9.101:14189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaHgAAAgg"]
[Thu Jul 30 11:43:25.390661 2026] [security2:error] [pid 643573:tid 643784] [client 172.236.9.101:39343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YIQAAAl4"]
[Thu Jul 30 11:43:25.392178 2026] [security2:error] [pid 643573:tid 643713] [client 172.236.9.101:21925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YHQAAAhc"]
[Thu Jul 30 11:43:25.394963 2026] [security2:error] [pid 642360:tid 642500] [client 172.236.9.101:19320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaHQAAAZk"]
[Thu Jul 30 11:43:25.412446 2026] [security2:error] [pid 643573:tid 643801] [client 172.236.9.101:42258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YJgAAAm8"]
[Thu Jul 30 11:43:25.414991 2026] [security2:error] [pid 643573:tid 643743] [client 172.236.9.101:55833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YKgAAAjU"]
[Thu Jul 30 11:43:25.422053 2026] [security2:error] [pid 643573:tid 643837] [client 172.236.9.101:3859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YIgAAApM"]
[Thu Jul 30 11:43:25.437249 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:18192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YKAAAAmA"]
[Thu Jul 30 11:43:25.438171 2026] [security2:error] [pid 642360:tid 642543] [client 172.236.9.101:34762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaIwAAAcQ"]
[Thu Jul 30 11:43:25.479666 2026] [security2:error] [pid 643573:tid 643729] [client 172.236.9.101:41989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YIAAAAic"]
[Thu Jul 30 11:43:25.496404 2026] [security2:error] [pid 642360:tid 642584] [client 172.236.9.101:46985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K5SUkh3e5AhEJOBaIgAAAe0"]
[Thu Jul 30 11:43:25.508049 2026] [security2:error] [pid 643573:tid 643727] [client 172.236.9.101:51814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YKQAAAiU"]
[Thu Jul 30 11:43:25.523413 2026] [security2:error] [pid 643573:tid 643789] [client 172.236.9.101:12417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_K_xWyxgRnoFKAJ_YJwAAAmM"]
[Thu Jul 30 11:43:25.931647 2026] [security2:error] [pid 643573:tid 643746] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_LfxWyxgRnoFKAJ_YNQAAAjg"]
[Thu Jul 30 11:43:26.701568 2026] [security2:error] [pid 642360:tid 642520] [client 52.167.144.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amt_LpSUkh3e5AhEJOBaOgAAAa0"]
[Thu Jul 30 11:43:26.705933 2026] [security2:error] [pid 643573:tid 643738] [client 176.241.66.87:45392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_LvxWyxgRnoFKAJ_YQQAAAjA"]
[Thu Jul 30 11:43:26.706067 2026] [security2:error] [pid 643573:tid 643738] [client 176.241.66.87:45392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_LvxWyxgRnoFKAJ_YQQAAAjA"]
[Thu Jul 30 11:43:26.712501 2026] [core:error] [pid 642360:tid 642449] [remote 74.7.230.55:42834] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:43:26.712518 2026] [core:error] [pid 642360:tid 642449] [remote 74.7.230.55:42834] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:43:26.712714 2026] [security2:error] [pid 642360:tid 642550] [client 74.7.230.55:42834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-55c6e681.wrf.zzt.temporary.site"] [uri "/website_55c6e681/index.php"] [unique_id "amt_LpSUkh3e5AhEJOBaQAABy1g"]
[Thu Jul 30 11:43:27.773493 2026] [security2:error] [pid 643573:tid 643687] [remote 57.141.0.39:39400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amt_L_xWyxgRnoFKAJ_YTQACXmo"]
[Thu Jul 30 11:43:28.756043 2026] [core:notice] [pid 643573:tid 643764] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:29.411874 2026] [security2:error] [pid 642360:tid 642476] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_MZSUkh3e5AhEJOBaUAAB_nM"]
[Thu Jul 30 11:43:29.412065 2026] [security2:error] [pid 642360:tid 642601] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_MZSUkh3e5AhEJOBaUAAB_nM"]
[Thu Jul 30 11:43:30.634609 2026] [security2:error] [pid 643573:tid 643697] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_MvxWyxgRnoFKAJ_YbQACZHQ"]
[Thu Jul 30 11:43:30.634773 2026] [security2:error] [pid 643573:tid 643790] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_MvxWyxgRnoFKAJ_YbQACZHQ"]
[Thu Jul 30 11:43:31.307302 2026] [security2:error] [pid 643573:tid 643808] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_MvxWyxgRnoFKAJ_YbAACdm8"]
[Thu Jul 30 11:43:31.307575 2026] [security2:error] [pid 643573:tid 643699] [remote 216.244.66.246:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/product-tag/%E0%B8%9A%E0%B8%B8%E0%B8%AB%E0%B8%A3%E0%B8%B5%E0%B9%88/"] [unique_id "amt_M_xWyxgRnoFKAJ_YcwACSXY"]
[Thu Jul 30 11:43:31.307761 2026] [security2:error] [pid 643573:tid 643763] [client 216.244.66.246:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spececigarette.com"] [uri "/product-tag/%E0%B8%9A%E0%B8%B8%E0%B8%AB%E0%B8%A3%E0%B8%B5%E0%B9%88/"] [unique_id "amt_M_xWyxgRnoFKAJ_YcwACSXY"]
[Thu Jul 30 11:43:31.376348 2026] [security2:error] [pid 643573:tid 643779] [client 159.65.49.75:47624] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "sh00085.hostgator.com"] [uri "/"] [unique_id "amt_M_xWyxgRnoFKAJ_YdAAAAlk"]
[Thu Jul 30 11:43:31.412869 2026] [security2:error] [pid 643573:tid 643786] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_MvxWyxgRnoFKAJ_YbgACYHg"]
[Thu Jul 30 11:43:31.909694 2026] [security2:error] [pid 643573:tid 643779] [client 159.65.49.75:47624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amt_M_xWyxgRnoFKAJ_YdAAAAlk"]
[Thu Jul 30 11:43:32.677141 2026] [security2:error] [pid 643573:tid 643800] [client 172.237.109.114:23715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M_xWyxgRnoFKAJ_YeAAAAm4"]
[Thu Jul 30 11:43:32.725321 2026] [security2:error] [pid 643573:tid 643809] [client 172.237.109.114:4910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M_xWyxgRnoFKAJ_YeQAAAnc"]
[Thu Jul 30 11:43:32.736648 2026] [security2:error] [pid 643573:tid 643833] [client 172.237.109.114:34892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M_xWyxgRnoFKAJ_YegAAAo8"]
[Thu Jul 30 11:43:32.738329 2026] [security2:error] [pid 643573:tid 643824] [client 172.237.109.114:19867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M_xWyxgRnoFKAJ_YewAAAoY"]
[Thu Jul 30 11:43:32.741333 2026] [security2:error] [pid 642360:tid 642570] [client 172.237.109.114:20333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M5SUkh3e5AhEJOBaagAAAd8"]
[Thu Jul 30 11:43:32.756057 2026] [security2:error] [pid 642360:tid 642511] [client 172.237.109.114:57005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M5SUkh3e5AhEJOBabQAAAaQ"]
[Thu Jul 30 11:43:32.765133 2026] [security2:error] [pid 642360:tid 642575] [client 172.237.109.114:46460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M5SUkh3e5AhEJOBabAAAAeQ"]
[Thu Jul 30 11:43:32.780024 2026] [security2:error] [pid 642360:tid 642547] [client 172.237.109.114:1283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NJSUkh3e5AhEJOBabgAAAcg"]
[Thu Jul 30 11:43:32.782938 2026] [security2:error] [pid 643573:tid 643714] [client 172.237.109.114:12464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YfQAAAhg"]
[Thu Jul 30 11:43:32.789910 2026] [security2:error] [pid 642360:tid 642528] [client 172.237.109.114:45839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_M5SUkh3e5AhEJOBaawAAAbU"]
[Thu Jul 30 11:43:32.791196 2026] [security2:error] [pid 643573:tid 643738] [client 172.237.109.114:11934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YfAAAAjA"]
[Thu Jul 30 11:43:32.793881 2026] [security2:error] [pid 643573:tid 643827] [client 172.237.109.114:1436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YfgAAAok"]
[Thu Jul 30 11:43:33.767095 2026] [fcgid:warn] [pid 643573:tid 643746] (70014)End of file found: [client 159.65.49.75:47642] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:34.400417 2026] [security2:error] [pid 643573:tid 643698] [remote 216.73.216.152:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_NvxWyxgRnoFKAJ_YmQACWnU"]
[Thu Jul 30 11:43:34.603337 2026] [security2:error] [pid 643573:tid 643804] [client 172.236.9.101:54786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YiAAAAnI"]
[Thu Jul 30 11:43:34.607225 2026] [security2:error] [pid 643573:tid 643795] [client 172.237.109.114:12695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YhAAAAmk"]
[Thu Jul 30 11:43:34.869574 2026] [proxy:error] [pid 643573:tid 643752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:34.869631 2026] [proxy_http:error] [pid 643573:tid 643752] [client 3.228.112.215:35733] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:34.870419 2026] [proxy:error] [pid 643573:tid 643752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:34.870470 2026] [proxy_http:error] [pid 643573:tid 643752] [client 3.228.112.215:35733] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:35.276652 2026] [security2:error] [pid 643573:tid 643743] [client 172.237.109.114:1045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YgwAAAjU"]
[Thu Jul 30 11:43:35.362600 2026] [security2:error] [pid 643573:tid 643741] [client 172.236.9.101:7683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YiwAAAjM"]
[Thu Jul 30 11:43:35.404427 2026] [security2:error] [pid 643573:tid 643789] [client 172.236.9.101:42249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YigAAAmM"]
[Thu Jul 30 11:43:35.417728 2026] [security2:error] [pid 643573:tid 643784] [client 172.237.109.114:53714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YhwAAAl4"]
[Thu Jul 30 11:43:35.438947 2026] [security2:error] [pid 642360:tid 642544] [client 172.237.109.114:62996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NJSUkh3e5AhEJOBadwAAAcU"]
[Thu Jul 30 11:43:35.447725 2026] [security2:error] [pid 642360:tid 642521] [client 172.236.9.101:40040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBaewAAAa4"]
[Thu Jul 30 11:43:35.522416 2026] [security2:error] [pid 643573:tid 643835] [client 172.237.109.114:23576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YhgAAApE"]
[Thu Jul 30 11:43:35.523483 2026] [security2:error] [pid 642360:tid 642606] [client 172.236.9.101:51661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBafQAAAgM"]
[Thu Jul 30 11:43:35.530860 2026] [security2:error] [pid 642360:tid 642567] [client 172.237.109.114:11756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NJSUkh3e5AhEJOBaeAAAAdw"]
[Thu Jul 30 11:43:35.568549 2026] [security2:error] [pid 642360:tid 642542] [client 172.236.9.101:16511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBafAAAAcM"]
[Thu Jul 30 11:43:36.268512 2026] [security2:error] [pid 642360:tid 642604] [client 172.236.9.101:5621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBaegAAAgE"]
[Thu Jul 30 11:43:36.285789 2026] [security2:error] [pid 643573:tid 643832] [client 172.236.9.101:12354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YjQAAAo4"]
[Thu Jul 30 11:43:36.286189 2026] [security2:error] [pid 643573:tid 643722] [client 172.237.109.114:40439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NPxWyxgRnoFKAJ_YhQAAAiA"]
[Thu Jul 30 11:43:36.289420 2026] [security2:error] [pid 643253:tid 643435] [client 172.236.9.101:25964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjjQAAADM"]
[Thu Jul 30 11:43:36.306544 2026] [security2:error] [pid 643253:tid 643452] [client 172.236.9.101:3492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjjwAAAEQ"]
[Thu Jul 30 11:43:36.326582 2026] [security2:error] [pid 642360:tid 642526] [client 172.236.9.101:21216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBaeQAAAbM"]
[Thu Jul 30 11:43:36.334093 2026] [security2:error] [pid 643253:tid 643502] [client 172.236.9.101:52842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjjgAAAHY"]
[Thu Jul 30 11:43:36.342601 2026] [security2:error] [pid 643573:tid 643797] [client 172.236.9.101:40000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YjgAAAms"]
[Thu Jul 30 11:43:36.345510 2026] [security2:error] [pid 643573:tid 643735] [client 172.236.9.101:15583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YjwAAAi0"]
[Thu Jul 30 11:43:36.387053 2026] [security2:error] [pid 642360:tid 642611] [client 172.236.9.101:45485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBafwAAAgg"]
[Thu Jul 30 11:43:36.388257 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:8503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YjAAAAhw"]
[Thu Jul 30 11:43:36.406247 2026] [security2:error] [pid 642360:tid 642500] [client 172.236.9.101:51012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NZSUkh3e5AhEJOBagAAAAZk"]
[Thu Jul 30 11:43:36.438567 2026] [security2:error] [pid 643573:tid 643733] [client 172.236.9.101:46096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YkAAAAis"]
[Thu Jul 30 11:43:36.485343 2026] [security2:error] [pid 643253:tid 643413] [client 172.236.9.101:12562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjkQAAAB0"]
[Thu Jul 30 11:43:36.513303 2026] [security2:error] [pid 643253:tid 643480] [client 172.236.9.101:20468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NcjqbtjBYzqM1uYjkAAAAGA"]
[Thu Jul 30 11:43:36.581356 2026] [security2:error] [pid 643573:tid 643755] [client 172.237.109.114:53894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_NfxWyxgRnoFKAJ_YlQAAAkE"]
[Thu Jul 30 11:43:37.244745 2026] [fcgid:warn] [pid 643573:tid 643818] (70014)End of file found: [client 159.65.49.75:47674] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:37.335924 2026] [security2:error] [pid 643573:tid 643765] [client 176.241.66.87:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_OfxWyxgRnoFKAJ_YqwAAAks"]
[Thu Jul 30 11:43:37.336114 2026] [security2:error] [pid 643573:tid 643765] [client 176.241.66.87:60512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_OfxWyxgRnoFKAJ_YqwAAAks"]
[Thu Jul 30 11:43:37.482536 2026] [fcgid:warn] [pid 643573:tid 643796] (70014)End of file found: [client 159.65.49.75:47678] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:39.339626 2026] [fcgid:warn] [pid 643573:tid 643726] (70014)End of file found: [client 159.65.49.75:47702] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:39.400174 2026] [security2:error] [pid 643573:tid 643651] [remote 216.73.216.152:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_O_xWyxgRnoFKAJ_YtwACHUY"]
[Thu Jul 30 11:43:40.235364 2026] [security2:error] [pid 642360:tid 642423] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_PJSUkh3e5AhEJOBavwABxD4"]
[Thu Jul 30 11:43:40.235521 2026] [security2:error] [pid 642360:tid 642543] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_PJSUkh3e5AhEJOBavwABxD4"]
[Thu Jul 30 11:43:41.001332 2026] [security2:error] [pid 643573:tid 643794] [client 185.156.175.171:51530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amt_PfxWyxgRnoFKAJ_YxAAAAmg"]
[Thu Jul 30 11:43:41.001487 2026] [security2:error] [pid 643573:tid 643794] [client 185.156.175.171:51530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amt_PfxWyxgRnoFKAJ_YxAAAAmg"]
[Thu Jul 30 11:43:41.068274 2026] [autoindex:error] [pid 643573:tid 643789] [client 8.234.138.211:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.otbola.click
[Thu Jul 30 11:43:41.199167 2026] [fcgid:warn] [pid 642360:tid 642572] (70014)End of file found: [client 159.65.49.75:56932] mod_fcgid: can't get data from http client
[Thu Jul 30 11:43:41.246765 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:41.278916 2026] [security2:error] [pid 643573:tid 643587] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_PfxWyxgRnoFKAJ_YyAACUgY"]
[Thu Jul 30 11:43:41.279081 2026] [security2:error] [pid 643573:tid 643772] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_PfxWyxgRnoFKAJ_YyAACUgY"]
[Thu Jul 30 11:43:41.289137 2026] [security2:error] [pid 642360:tid 642574] [client 143.198.88.13:59373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_PZSUkh3e5AhEJOBayQAAAeM"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:41.545178 2026] [proxy:error] [pid 643253:tid 643492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:41.545238 2026] [proxy_http:error] [pid 643253:tid 643492] [client 98.87.102.177:33811] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:41.545798 2026] [proxy:error] [pid 643253:tid 643492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:41.545841 2026] [proxy_http:error] [pid 643253:tid 643492] [client 98.87.102.177:33811] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:41.570284 2026] [proxy:error] [pid 643573:tid 643732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:41.570355 2026] [proxy_http:error] [pid 643573:tid 643732] [client 44.216.125.112:56535] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:41.571201 2026] [proxy:error] [pid 643573:tid 643732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:41.571260 2026] [proxy_http:error] [pid 643573:tid 643732] [client 44.216.125.112:56535] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:42.255896 2026] [security2:error] [pid 643573:tid 643585] [remote 198.244.242.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "saiqon.net"] [uri "/hello-world/"] [unique_id "amt_PvxWyxgRnoFKAJ_Y1QACawQ"]
[Thu Jul 30 11:43:42.256121 2026] [security2:error] [pid 643573:tid 643797] [client 198.244.242.68:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "saiqon.net"] [uri "/hello-world/"] [unique_id "amt_PvxWyxgRnoFKAJ_Y1QACawQ"]
[Thu Jul 30 11:43:42.517727 2026] [security2:error] [pid 643253:tid 643504] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amt_PcjqbtjBYzqM1uYjowAAAHg"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:42.820386 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:61676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PpSUkh3e5AhEJOBa1QAAAdM"]
[Thu Jul 30 11:43:42.832957 2026] [security2:error] [pid 643573:tid 643719] [client 172.236.9.101:27187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PvxWyxgRnoFKAJ_Y1AAAAh0"]
[Thu Jul 30 11:43:42.916108 2026] [security2:error] [pid 642360:tid 642567] [client 172.236.9.101:52721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PpSUkh3e5AhEJOBa1wAAAdw"]
[Thu Jul 30 11:43:42.924831 2026] [security2:error] [pid 642360:tid 642499] [client 172.236.9.101:55619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PpSUkh3e5AhEJOBa1gAAAZg"]
[Thu Jul 30 11:43:42.930843 2026] [security2:error] [pid 643253:tid 643447] [client 172.236.9.101:41373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_PsjqbtjBYzqM1uYjpAAAAD8"]
[Thu Jul 30 11:43:44.220530 2026] [security2:error] [pid 642360:tid 642545] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_PpSUkh3e5AhEJOBa0AABxjk"]
[Thu Jul 30 11:43:44.392637 2026] [proxy:error] [pid 643573:tid 643751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:44.392731 2026] [proxy_http:error] [pid 643573:tid 643751] [client 74.7.230.26:54014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:44.394099 2026] [proxy:error] [pid 643573:tid 643751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:43:44.394168 2026] [proxy_http:error] [pid 643573:tid 643751] [client 74.7.230.26:54014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:43:44.394457 2026] [security2:error] [pid 643573:tid 643751] [client 74.7.230.26:54014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.bah.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amt_QPxWyxgRnoFKAJ_Y7AAAAj0"]
[Thu Jul 30 11:43:44.464552 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:54557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y3gAAAn4"]
[Thu Jul 30 11:43:44.474641 2026] [security2:error] [pid 643573:tid 643770] [client 172.236.9.101:38414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y4AAAAlA"]
[Thu Jul 30 11:43:44.489868 2026] [security2:error] [pid 643573:tid 643777] [client 172.236.9.101:19826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y3QAAAlc"]
[Thu Jul 30 11:43:44.506122 2026] [security2:error] [pid 643573:tid 643811] [client 172.236.9.101:57648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y3AAAAnk"]
[Thu Jul 30 11:43:44.512863 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:58791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y3wAAAk8"]
[Thu Jul 30 11:43:44.581502 2026] [security2:error] [pid 642360:tid 642553] [client 172.236.9.101:18105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P5SUkh3e5AhEJOBa4gAAAc4"]
[Thu Jul 30 11:43:44.586764 2026] [security2:error] [pid 643573:tid 643793] [client 172.236.9.101:15787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y4gAAAmc"]
[Thu Jul 30 11:43:44.603189 2026] [security2:error] [pid 643573:tid 643818] [client 172.236.9.101:60907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y4wAAAoA"]
[Thu Jul 30 11:43:44.624476 2026] [security2:error] [pid 643253:tid 643393] [client 172.236.9.101:4066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P8jqbtjBYzqM1uYjpgAAAAk"]
[Thu Jul 30 11:43:44.625036 2026] [security2:error] [pid 642360:tid 642591] [client 172.236.9.101:51945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P5SUkh3e5AhEJOBa4wAAAfQ"]
[Thu Jul 30 11:43:44.627950 2026] [security2:error] [pid 643573:tid 643766] [client 172.236.9.101:26209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y4QAAAkw"]
[Thu Jul 30 11:43:44.638858 2026] [security2:error] [pid 643573:tid 643785] [client 172.236.9.101:14308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y5QAAAl8"]
[Thu Jul 30 11:43:44.666515 2026] [security2:error] [pid 643573:tid 643743] [client 172.236.9.101:16533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y5gAAAjU"]
[Thu Jul 30 11:43:44.668063 2026] [security2:error] [pid 643253:tid 643407] [client 172.236.9.101:11853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P8jqbtjBYzqM1uYjpwAAABc"]
[Thu Jul 30 11:43:44.668082 2026] [security2:error] [pid 643573:tid 643765] [client 172.236.9.101:31145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y5AAAAks"]
[Thu Jul 30 11:43:44.763391 2026] [security2:error] [pid 643573:tid 643753] [client 143.198.88.13:59424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amt_P_xWyxgRnoFKAJ_Y6QAAAj8"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:45.025873 2026] [security2:error] [pid 643573:tid 643622] [remote 216.73.216.152:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_QfxWyxgRnoFKAJ_Y8gACOCk"]
[Thu Jul 30 11:43:45.728648 2026] [security2:error] [pid 643573:tid 643819] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amt_QPxWyxgRnoFKAJ_Y8QAAAoE"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:47.019747 2026] [security2:error] [pid 643573:tid 643738] [client 143.198.88.13:59424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amt_QvxWyxgRnoFKAJ_Y-wAAAjA"], referer: www.website-c08187ca.rka.jtu.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:43:47.116671 2026] [security2:error] [pid 643573:tid 643743] [client 143.198.88.13:59424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBAAAAjU"]
[Thu Jul 30 11:43:47.116804 2026] [security2:error] [pid 643573:tid 643743] [client 143.198.88.13:59424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBAAAAjU"]
[Thu Jul 30 11:43:47.494055 2026] [security2:error] [pid 643573:tid 643757] [client 143.198.88.13:51141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/blog//wp-login.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBQAAAkM"], referer: https://seven-stars-shop.com//blog//wp-login.php
[Thu Jul 30 11:43:47.988882 2026] [security2:error] [pid 643573:tid 643718] [client 176.241.66.87:47313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBgAAAhw"]
[Thu Jul 30 11:43:47.989029 2026] [security2:error] [pid 643573:tid 643718] [client 176.241.66.87:47313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_Q_xWyxgRnoFKAJ_ZBgAAAhw"]
[Thu Jul 30 11:43:48.870796 2026] [security2:error] [pid 643573:tid 643780] [client 172.236.9.101:12230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RPxWyxgRnoFKAJ_ZBwAAAlo"]
[Thu Jul 30 11:43:48.872703 2026] [security2:error] [pid 642360:tid 642492] [client 172.236.9.101:41138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbFgAAAZE"]
[Thu Jul 30 11:43:49.245636 2026] [security2:error] [pid 642360:tid 642577] [client 172.236.9.101:35823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbFwAAAeY"]
[Thu Jul 30 11:43:49.273625 2026] [security2:error] [pid 642360:tid 642598] [client 172.236.9.101:11892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbGAAAAfs"]
[Thu Jul 30 11:43:49.307897 2026] [security2:error] [pid 643573:tid 643805] [client 172.236.9.101:59506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RPxWyxgRnoFKAJ_ZCAAAAnM"]
[Thu Jul 30 11:43:49.315432 2026] [security2:error] [pid 642360:tid 642603] [client 172.236.9.101:4263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbGgAAAgA"]
[Thu Jul 30 11:43:49.331588 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:28738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbGQAAAbY"]
[Thu Jul 30 11:43:49.338006 2026] [security2:error] [pid 642360:tid 642563] [client 172.236.9.101:47421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbGwAAAdg"]
[Thu Jul 30 11:43:49.344294 2026] [security2:error] [pid 643253:tid 643501] [client 172.236.9.101:63294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RMjqbtjBYzqM1uYjrwAAAHU"]
[Thu Jul 30 11:43:49.361857 2026] [security2:error] [pid 642360:tid 642606] [client 172.236.9.101:2322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RJSUkh3e5AhEJOBbHAAAAgM"]
[Thu Jul 30 11:43:49.406242 2026] [security2:error] [pid 643573:tid 643609] [remote 216.73.216.152:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_RfxWyxgRnoFKAJ_ZIAACUhw"]
[Thu Jul 30 11:43:49.408129 2026] [security2:error] [pid 642360:tid 642601] [client 127.0.0.1:57226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amt_RZSUkh3e5AhEJOBbJwAAAf4"]
[Thu Jul 30 11:43:49.408396 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.230.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.royalrelaxspa.sbs"] [uri "/robots.txt"] [unique_id "amt_RZSUkh3e5AhEJOBbJgAB3VQ"]
[Thu Jul 30 11:43:50.307730 2026] [security2:error] [pid 642360:tid 642567] [client 172.236.9.101:48545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RZSUkh3e5AhEJOBbJAAAAdw"]
[Thu Jul 30 11:43:50.325930 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:16775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZGAAAApE"]
[Thu Jul 30 11:43:50.334125 2026] [security2:error] [pid 642360:tid 642499] [client 172.236.9.101:1301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RZSUkh3e5AhEJOBbJQAAAZg"]
[Thu Jul 30 11:43:50.362190 2026] [security2:error] [pid 643573:tid 643781] [client 172.236.9.101:65289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZGgAAAls"]
[Thu Jul 30 11:43:50.420327 2026] [security2:error] [pid 643573:tid 643789] [client 172.236.9.101:38053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZGQAAAmM"]
[Thu Jul 30 11:43:50.438155 2026] [security2:error] [pid 643573:tid 643775] [client 172.236.9.101:15352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZGwAAAlU"]
[Thu Jul 30 11:43:50.440241 2026] [security2:error] [pid 643573:tid 643831] [client 172.236.9.101:65236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZHQAAAo0"]
[Thu Jul 30 11:43:50.440453 2026] [security2:error] [pid 643573:tid 643829] [client 172.236.9.101:12130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZHAAAAos"]
[Thu Jul 30 11:43:50.458798 2026] [security2:error] [pid 643573:tid 643792] [client 172.236.9.101:36992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZHwAAAmY"]
[Thu Jul 30 11:43:50.469267 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:64774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_RfxWyxgRnoFKAJ_ZHgAAAoY"]
[Thu Jul 30 11:43:50.619841 2026] [security2:error] [pid 643573:tid 643598] [remote 152.53.37.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.37.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amt_RvxWyxgRnoFKAJ_ZJgACfBE"]
[Thu Jul 30 11:43:50.620048 2026] [security2:error] [pid 643573:tid 643814] [client 152.53.37.129:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amt_RvxWyxgRnoFKAJ_ZJgACfBE"]
[Thu Jul 30 11:43:51.205266 2026] [security2:error] [pid 643573:tid 643608] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZKQACTRs"]
[Thu Jul 30 11:43:51.205410 2026] [security2:error] [pid 643573:tid 643767] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZKQACTRs"]
[Thu Jul 30 11:43:51.933580 2026] [security2:error] [pid 643573:tid 643583] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZLAACIwI"]
[Thu Jul 30 11:43:51.933730 2026] [security2:error] [pid 643573:tid 643725] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZLAACIwI"]
[Thu Jul 30 11:43:52.793593 2026] [security2:error] [pid 642360:tid 642456] [remote 40.77.167.70:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/download/bibtex"] [unique_id "amt_SJSUkh3e5AhEJOBbTwABzV8"]
[Thu Jul 30 11:43:52.959334 2026] [security2:error] [pid 643573:tid 643796] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amt_R_xWyxgRnoFKAJ_ZLgAAAmo"], referer: https://marlboro-shop.com/marlboro-rank/
[Thu Jul 30 11:43:53.317934 2026] [security2:error] [pid 643573:tid 643625] [remote 217.181.86.111:47568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amt_SfxWyxgRnoFKAJ_ZNgACgCw"], referer: https://deltaedu.net/
[Thu Jul 30 11:43:54.408111 2026] [security2:error] [pid 643573:tid 643616] [remote 216.73.216.152:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_SvxWyxgRnoFKAJ_ZTAACTCM"]
[Thu Jul 30 11:43:55.793159 2026] [security2:error] [pid 643573:tid 643737] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_S_xWyxgRnoFKAJ_ZVgAAAi8"]
[Thu Jul 30 11:43:56.538170 2026] [core:notice] [pid 643573:tid 643810] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:57.503636 2026] [security2:error] [pid 643573:tid 643749] [client 172.236.9.101:9067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZYgAAAjs"]
[Thu Jul 30 11:43:57.508859 2026] [core:notice] [pid 643573:tid 643770] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:57.546243 2026] [security2:error] [pid 643573:tid 643831] [client 172.236.9.101:47497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZYQAAAo0"]
[Thu Jul 30 11:43:58.231506 2026] [security2:error] [pid 643573:tid 643763] [client 172.236.9.101:61122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZYAAAAkk"]
[Thu Jul 30 11:43:58.259903 2026] [security2:error] [pid 643573:tid 643776] [client 172.236.9.101:61955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZYwAAAlY"]
[Thu Jul 30 11:43:58.274094 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:1599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TJSUkh3e5AhEJOBbZwAAAbY"]
[Thu Jul 30 11:43:58.280250 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:13349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZZQAAAlk"]
[Thu Jul 30 11:43:58.280332 2026] [security2:error] [pid 643253:tid 643424] [client 172.236.9.101:14516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TMjqbtjBYzqM1uYjuAAAACg"]
[Thu Jul 30 11:43:58.286535 2026] [security2:error] [pid 643573:tid 643762] [client 172.236.9.101:23794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZZAAAAkg"]
[Thu Jul 30 11:43:58.287414 2026] [security2:error] [pid 643573:tid 643804] [client 172.236.9.101:60968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZZgAAAnI"]
[Thu Jul 30 11:43:58.287461 2026] [security2:error] [pid 643253:tid 643431] [client 172.236.9.101:1746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TMjqbtjBYzqM1uYjuQAAAC8"]
[Thu Jul 30 11:43:58.295488 2026] [security2:error] [pid 643573:tid 643758] [client 172.236.9.101:19117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZagAAAkQ"]
[Thu Jul 30 11:43:58.298669 2026] [security2:error] [pid 643573:tid 643767] [client 172.236.9.101:38358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZaQAAAk0"]
[Thu Jul 30 11:43:58.307509 2026] [security2:error] [pid 643573:tid 643795] [client 172.236.9.101:35932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZaAAAAmk"]
[Thu Jul 30 11:43:58.313138 2026] [security2:error] [pid 643573:tid 643748] [client 172.236.9.101:41204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZZwAAAjo"]
[Thu Jul 30 11:43:58.317234 2026] [security2:error] [pid 643253:tid 643418] [client 172.236.9.101:20085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TMjqbtjBYzqM1uYjtwAAACI"]
[Thu Jul 30 11:43:58.328686 2026] [security2:error] [pid 643573:tid 643764] [client 172.236.9.101:10406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TPxWyxgRnoFKAJ_ZawAAAko"]
[Thu Jul 30 11:43:58.545011 2026] [core:notice] [pid 643573:tid 643730] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:43:58.604660 2026] [security2:error] [pid 643253:tid 643462] [client 172.236.9.101:10620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TcjqbtjBYzqM1uYjvAAAAE4"]
[Thu Jul 30 11:43:58.632795 2026] [security2:error] [pid 643253:tid 643464] [client 176.241.66.87:48243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_TsjqbtjBYzqM1uYjvwAAAFA"]
[Thu Jul 30 11:43:58.633258 2026] [security2:error] [pid 643253:tid 643464] [client 176.241.66.87:48243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_TsjqbtjBYzqM1uYjvwAAAFA"]
[Thu Jul 30 11:43:58.649340 2026] [security2:error] [pid 643253:tid 643455] [client 172.236.9.101:28920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TcjqbtjBYzqM1uYjvQAAAEc"]
[Thu Jul 30 11:43:58.682057 2026] [security2:error] [pid 643573:tid 643836] [client 172.236.9.101:11343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TfxWyxgRnoFKAJ_ZcwAAApI"]
[Thu Jul 30 11:43:58.712183 2026] [security2:error] [pid 643253:tid 643421] [client 172.236.9.101:62908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_TcjqbtjBYzqM1uYjvgAAACU"]
[Thu Jul 30 11:43:58.941489 2026] [security2:error] [pid 642360:tid 642501] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_TpSUkh3e5AhEJOBbdwAAAZo"]
[Thu Jul 30 11:44:00.047544 2026] [security2:error] [pid 643573:tid 643828] [client 78.47.173.76:45656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amt_UPxWyxgRnoFKAJ_ZkwAAAoo"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:44:00.334295 2026] [security2:error] [pid 643573:tid 643642] [remote 74.7.241.60:35984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/article.php"] [unique_id "amt_UPxWyxgRnoFKAJ_ZmQACRD0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/1784122425_Physioth%C3%A9rapie%20%C3%A0%20Domicile.jpg
[Thu Jul 30 11:44:00.847461 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:00.852902 2026] [security2:error] [pid 643573:tid 643788] [client 78.47.173.76:45658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_UPxWyxgRnoFKAJ_ZnQAAAmI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:44:00.969131 2026] [core:notice] [pid 643573:tid 643780] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:01.481629 2026] [security2:error] [pid 642360:tid 642511] [client 78.47.173.76:45672] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amt_UZSUkh3e5AhEJOBbjgAAAaQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:44:02.120110 2026] [security2:error] [pid 642360:tid 642470] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_UpSUkh3e5AhEJOBblAAB_G0"]
[Thu Jul 30 11:44:02.120327 2026] [security2:error] [pid 642360:tid 642599] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_UpSUkh3e5AhEJOBblAAB_G0"]
[Thu Jul 30 11:44:02.272686 2026] [security2:error] [pid 642360:tid 642530] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "plumbingplumb.com"] [uri "/index.php"] [unique_id "amt_UpSUkh3e5AhEJOBblQABt3U"], referer: https://chenclean2015.com//blog//wp-login.php
[Thu Jul 30 11:44:02.339358 2026] [security2:error] [pid 643573:tid 643790] [client 172.202.44.182:47271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/chosen.php"] [unique_id "amt_UvxWyxgRnoFKAJ_ZrAAAAmQ"]
[Thu Jul 30 11:44:02.572692 2026] [security2:error] [pid 643573:tid 643654] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_UvxWyxgRnoFKAJ_ZrwACaUk"]
[Thu Jul 30 11:44:02.572845 2026] [security2:error] [pid 643573:tid 643795] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_UvxWyxgRnoFKAJ_ZrwACaUk"]
[Thu Jul 30 11:44:03.238594 2026] [security2:error] [pid 643573:tid 643728] [client 172.202.44.182:22360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/xleet.php"] [unique_id "amt_U_xWyxgRnoFKAJ_ZtwAAAiY"]
[Thu Jul 30 11:44:03.270328 2026] [security2:error] [pid 643573:tid 643837] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_UvxWyxgRnoFKAJ_ZpgACk0I"]
[Thu Jul 30 11:44:03.310665 2026] [security2:error] [pid 643573:tid 643733] [client 185.191.171.2:39692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amt_U_xWyxgRnoFKAJ_ZugAAAis"]
[Thu Jul 30 11:44:03.310770 2026] [security2:error] [pid 643573:tid 643733] [client 185.191.171.2:39692] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amt_U_xWyxgRnoFKAJ_ZugAAAis"]
[Thu Jul 30 11:44:04.251358 2026] [security2:error] [pid 643573:tid 643725] [client 85.208.96.202:59274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/08/25/bb-libera-r-2-bi-para-recuperacao-de-lavouras-atingidas-por-geada/"] [unique_id "amt_VPxWyxgRnoFKAJ_ZvwAAAiM"]
[Thu Jul 30 11:44:04.251460 2026] [security2:error] [pid 643573:tid 643725] [client 85.208.96.202:59274] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/08/25/bb-libera-r-2-bi-para-recuperacao-de-lavouras-atingidas-por-geada/"] [unique_id "amt_VPxWyxgRnoFKAJ_ZvwAAAiM"]
[Thu Jul 30 11:44:04.443421 2026] [core:notice] [pid 642360:tid 642361] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:04.450687 2026] [security2:error] [pid 642360:tid 642525] [client 20.235.75.219:49857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/camic/article/download/9051/3903"] [unique_id "amt_VJSUkh3e5AhEJOBbowABsgA"]
[Thu Jul 30 11:44:04.781105 2026] [security2:error] [pid 643253:tid 643465] [client 170.64.210.244:46400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "50.6.43.58"] [uri "/.env"] [unique_id "amt_VMjqbtjBYzqM1uYjwwAAAFE"]
[Thu Jul 30 11:44:05.028875 2026] [core:notice] [pid 643573:tid 643632] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:06.203513 2026] [security2:error] [pid 642360:tid 642546] [client 172.202.44.182:60948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ds.php"] [unique_id "amt_VpSUkh3e5AhEJOBbvAAAAcc"]
[Thu Jul 30 11:44:07.218408 2026] [security2:error] [pid 643573:tid 643743] [client 172.202.44.182:60943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/f5.php"] [unique_id "amt_V_xWyxgRnoFKAJ_Z3gAAAjU"]
[Thu Jul 30 11:44:07.301697 2026] [security2:error] [pid 642360:tid 642559] [client 172.236.9.101:11304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbqwAAAdQ"]
[Thu Jul 30 11:44:07.344359 2026] [security2:error] [pid 642360:tid 642604] [client 172.236.9.101:47605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbrAAAAgE"]
[Thu Jul 30 11:44:07.351460 2026] [security2:error] [pid 642360:tid 642615] [client 172.236.9.101:55841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbrQAAAgw"]
[Thu Jul 30 11:44:07.351666 2026] [security2:error] [pid 643573:tid 643793] [client 172.236.9.101:27992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZzAAAAmc"]
[Thu Jul 30 11:44:07.386928 2026] [security2:error] [pid 643573:tid 643813] [client 172.236.9.101:42705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZzwAAAns"]
[Thu Jul 30 11:44:07.393727 2026] [security2:error] [pid 642360:tid 642514] [client 172.236.9.101:33986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbrwAAAac"]
[Thu Jul 30 11:44:07.394573 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:4889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZzQAAAhw"]
[Thu Jul 30 11:44:07.394973 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:16169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbrgAAAdM"]
[Thu Jul 30 11:44:07.395023 2026] [security2:error] [pid 642360:tid 642598] [client 172.236.9.101:41610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbswAAAfs"]
[Thu Jul 30 11:44:07.399549 2026] [security2:error] [pid 642360:tid 642603] [client 172.236.9.101:22226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbtAAAAgA"]
[Thu Jul 30 11:44:07.409017 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:41877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZzgAAAoY"]
[Thu Jul 30 11:44:07.409734 2026] [security2:error] [pid 643573:tid 643722] [client 172.236.9.101:26792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_Z0QAAAiA"]
[Thu Jul 30 11:44:07.410242 2026] [security2:error] [pid 642360:tid 642563] [client 172.236.9.101:39878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbtwAAAdg"]
[Thu Jul 30 11:44:07.430047 2026] [security2:error] [pid 643573:tid 643782] [client 172.236.9.101:19690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_Z0gAAAlw"]
[Thu Jul 30 11:44:07.434781 2026] [security2:error] [pid 642360:tid 642526] [client 172.236.9.101:11246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbsAAAAbM"]
[Thu Jul 30 11:44:07.452007 2026] [security2:error] [pid 642360:tid 642500] [client 172.236.9.101:55989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbtgAAAZk"]
[Thu Jul 30 11:44:07.463122 2026] [security2:error] [pid 643253:tid 643416] [client 172.236.9.101:12925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VcjqbtjBYzqM1uYjxAAAACA"]
[Thu Jul 30 11:44:07.480224 2026] [security2:error] [pid 643573:tid 643819] [client 172.236.9.101:13940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_Z0wAAAoE"]
[Thu Jul 30 11:44:07.482714 2026] [security2:error] [pid 642360:tid 642610] [client 172.236.9.101:28129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VZSUkh3e5AhEJOBbtQAAAgc"]
[Thu Jul 30 11:44:07.500510 2026] [security2:error] [pid 643573:tid 643814] [client 172.236.9.101:5558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_VfxWyxgRnoFKAJ_ZywAAAnw"]
[Thu Jul 30 11:44:08.389648 2026] [security2:error] [pid 643573:tid 643745] [client 172.202.44.182:22397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/god4m.php"] [unique_id "amt_WPxWyxgRnoFKAJ_Z5wAAAjc"]
[Thu Jul 30 11:44:08.855688 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:09.291682 2026] [security2:error] [pid 643573:tid 643811] [client 176.241.66.87:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_WfxWyxgRnoFKAJ_Z8QAAAnk"]
[Thu Jul 30 11:44:09.291801 2026] [security2:error] [pid 643573:tid 643811] [client 176.241.66.87:62122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_WfxWyxgRnoFKAJ_Z8QAAAnk"]
[Thu Jul 30 11:44:09.412040 2026] [security2:error] [pid 643573:tid 643669] [remote 216.73.216.152:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_WfxWyxgRnoFKAJ_Z8wACg1g"]
[Thu Jul 30 11:44:09.582441 2026] [security2:error] [pid 643573:tid 643819] [client 172.202.44.182:22017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/info.php"] [unique_id "amt_WfxWyxgRnoFKAJ_Z9QAAAoE"]
[Thu Jul 30 11:44:09.843552 2026] [security2:error] [pid 643573:tid 643789] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_WfxWyxgRnoFKAJ_Z7gAAAmM"]
[Thu Jul 30 11:44:11.036053 2026] [security2:error] [pid 643573:tid 643753] [client 172.202.44.182:47233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/.__info.php"] [unique_id "amt_W_xWyxgRnoFKAJ_aAAAAAj8"]
[Thu Jul 30 11:44:11.817990 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.065865 2026] [core:notice] [pid 643573:tid 643763] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.191512 2026] [security2:error] [pid 642360:tid 642597] [client 20.215.191.139:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/011i.php"] [unique_id "amt_XJSUkh3e5AhEJOBb7gAAAfo"]
[Thu Jul 30 11:44:12.265227 2026] [core:notice] [pid 643573:tid 643812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.265405 2026] [security2:error] [pid 642360:tid 642527] [client 172.202.44.182:60945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/0.php"] [unique_id "amt_XJSUkh3e5AhEJOBb7wAAAbQ"]
[Thu Jul 30 11:44:12.537524 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.731785 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:12.970265 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:13.011507 2026] [security2:error] [pid 643573:tid 643756] [client 57.141.0.50:49478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amt_XPxWyxgRnoFKAJ_aCwACQlM"], referer: https://igetvape-australia.com/product-category/alibarbar-rich-8000-puffs/?add-to-cart=1049
[Thu Jul 30 11:44:13.030458 2026] [security2:error] [pid 643573:tid 643751] [client 20.215.191.139:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/03a005685d.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aDwAAAj0"]
[Thu Jul 30 11:44:13.119290 2026] [security2:error] [pid 643573:tid 643668] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aEAACRVc"]
[Thu Jul 30 11:44:13.119489 2026] [security2:error] [pid 643573:tid 643759] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aEAACRVc"]
[Thu Jul 30 11:44:13.189899 2026] [security2:error] [pid 643573:tid 643670] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aEQACPlk"]
[Thu Jul 30 11:44:13.190091 2026] [security2:error] [pid 643573:tid 643752] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_XfxWyxgRnoFKAJ_aEQACPlk"]
[Thu Jul 30 11:44:13.222409 2026] [core:notice] [pid 643573:tid 643818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:13.306344 2026] [security2:error] [pid 643573:tid 643805] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_XPxWyxgRnoFKAJ_aDAAAAnM"]
[Thu Jul 30 11:44:13.476609 2026] [core:notice] [pid 643573:tid 643740] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:13.687263 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:13.911277 2026] [core:notice] [pid 642360:tid 642615] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.157963 2026] [core:notice] [pid 643573:tid 643835] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.395542 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.570581 2026] [security2:error] [pid 643573:tid 643667] [remote 173.231.241.109:57246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.241.231.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-aa23bb9f.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amt_XvxWyxgRnoFKAJ_aKAACSVY"]
[Thu Jul 30 11:44:14.645728 2026] [core:notice] [pid 643573:tid 643724] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.871216 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:14.966106 2026] [security2:error] [pid 643573:tid 643747] [client 20.215.191.139:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/403.php"] [unique_id "amt_XvxWyxgRnoFKAJ_aMQAAAjk"]
[Thu Jul 30 11:44:15.054640 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:15.136018 2026] [security2:error] [pid 643573:tid 643610] [remote 216.73.216.152:4364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_X_xWyxgRnoFKAJ_aNQACWB0"]
[Thu Jul 30 11:44:15.437761 2026] [security2:error] [pid 643573:tid 643773] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_XvxWyxgRnoFKAJ_aLwAAAlM"]
[Thu Jul 30 11:44:15.963578 2026] [security2:error] [pid 643573:tid 643730] [client 20.215.191.139:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/404.php"] [unique_id "amt_X_xWyxgRnoFKAJ_aPAAAAig"]
[Thu Jul 30 11:44:16.048203 2026] [core:notice] [pid 643573:tid 643784] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:16.137614 2026] [security2:error] [pid 643573:tid 643710] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_X_xWyxgRnoFKAJ_aOQAAAhQ"]
[Thu Jul 30 11:44:16.565395 2026] [core:notice] [pid 643573:tid 643772] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:16.848193 2026] [security2:error] [pid 642360:tid 642608] [client 47.236.199.168:42352] ModSecurity: Warning. Matched phrase "WebCopier" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "legalsnaps.info"] [uri "/wp-content/uploads/2026/04/ChatGPT-Image-Apr-21-2026-12_09_00-AM.png"] [unique_id "amt_RpSUkh3e5AhEJOBbOAAAAgU"]
[Thu Jul 30 11:44:16.890579 2026] [security2:error] [pid 643573:tid 643677] [remote 188.132.136.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.136.132.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trustedmoversandpackersabudhabi.online"] [uri "/xmlrpc.php"] [unique_id "amt_YPxWyxgRnoFKAJ_aQQACLGA"]
[Thu Jul 30 11:44:16.890799 2026] [security2:error] [pid 643573:tid 643734] [client 188.132.136.190:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "trustedmoversandpackersabudhabi.online"] [uri "/xmlrpc.php"] [unique_id "amt_YPxWyxgRnoFKAJ_aQQACLGA"]
[Thu Jul 30 11:44:17.172109 2026] [core:notice] [pid 643573:tid 643832] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:17.209237 2026] [core:error] [pid 643253:tid 643387] [client 185.247.137.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:17.209265 2026] [core:error] [pid 643253:tid 643387] [client 185.247.137.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:17.508626 2026] [security2:error] [pid 643573:tid 643737] [client 85.208.96.198:20636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/10/em-apenas-uma-semana-paraiba-registra-mais-de-3-mil-novos-casos-de-dengue-zika-e-chikungunya/"] [unique_id "amt_YfxWyxgRnoFKAJ_aRgAAAi8"]
[Thu Jul 30 11:44:17.508807 2026] [security2:error] [pid 643573:tid 643737] [client 85.208.96.198:20636] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/10/em-apenas-uma-semana-paraiba-registra-mais-de-3-mil-novos-casos-de-dengue-zika-e-chikungunya/"] [unique_id "amt_YfxWyxgRnoFKAJ_aRgAAAi8"]
[Thu Jul 30 11:44:17.528331 2026] [security2:error] [pid 643573:tid 643781] [client 20.215.191.139:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/aa.php"] [unique_id "amt_YfxWyxgRnoFKAJ_aRwAAAls"]
[Thu Jul 30 11:44:17.796044 2026] [security2:error] [pid 643573:tid 643798] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_YfxWyxgRnoFKAJ_aQgACbBI"]
[Thu Jul 30 11:44:17.923423 2026] [core:notice] [pid 643573:tid 643791] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:18.506638 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:19.030023 2026] [security2:error] [pid 643573:tid 643733] [client 20.215.191.139:49133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/aafewc0k.php"] [unique_id "amt_Y_xWyxgRnoFKAJ_aWgAAAis"]
[Thu Jul 30 11:44:19.155186 2026] [autoindex:error] [pid 643573:tid 643800] [client 106.219.166.254:3823] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:44:19.258756 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:19.307268 2026] [security2:error] [pid 643573:tid 643754] [client 129.159.56.14:55084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amt_Y_xWyxgRnoFKAJ_aXgAAAkA"]
[Thu Jul 30 11:44:19.423206 2026] [security2:error] [pid 643573:tid 643648] [remote 216.73.216.152:4364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_Y_xWyxgRnoFKAJ_aYQACLEM"]
[Thu Jul 30 11:44:19.626637 2026] [security2:error] [pid 643573:tid 643788] [client 2407:d000:1c:9d56:64c4:87bd:6970:5a53:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_Y_xWyxgRnoFKAJ_aWwACYmU"]
[Thu Jul 30 11:44:19.787800 2026] [security2:error] [pid 643253:tid 643487] [client 172.202.44.182:22358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/07.php"] [unique_id "amt_Y8jqbtjBYzqM1uYjzAAAAGc"]
[Thu Jul 30 11:44:19.857457 2026] [security2:error] [pid 643573:tid 643785] [client 176.241.66.87:49916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_Y_xWyxgRnoFKAJ_aYwAAAl8"]
[Thu Jul 30 11:44:19.857612 2026] [security2:error] [pid 643573:tid 643785] [client 176.241.66.87:49916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_Y_xWyxgRnoFKAJ_aYwAAAl8"]
[Thu Jul 30 11:44:19.877839 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:21.203592 2026] [security2:error] [pid 643573:tid 643683] [remote 57.141.0.32:32318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amt_ZfxWyxgRnoFKAJ_abQACUWY"]
[Thu Jul 30 11:44:21.319138 2026] [security2:error] [pid 643573:tid 643751] [client 20.215.191.139:65309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/abcd.php"] [unique_id "amt_ZfxWyxgRnoFKAJ_abgAAAj0"]
[Thu Jul 30 11:44:21.961430 2026] [security2:error] [pid 643573:tid 643790] [client 20.215.191.139:49149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/about.php"] [unique_id "amt_ZfxWyxgRnoFKAJ_adwAAAmQ"]
[Thu Jul 30 11:44:22.092452 2026] [core:notice] [pid 643573:tid 643676] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:22.180827 2026] [core:notice] [pid 643573:tid 643813] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:22.241641 2026] [security2:error] [pid 643573:tid 643735] [client 47.128.120.38:26752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/robots.txt"] [unique_id "amt_ZvxWyxgRnoFKAJ_afgAAAi0"]
[Thu Jul 30 11:44:22.435748 2026] [security2:error] [pid 643573:tid 643836] [client 43.173.177.44:40016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.177.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/03/21/bijoux-en-perles-de-culture-histoire-d-or/"] [unique_id "amt_ZvxWyxgRnoFKAJ_aggAAApI"]
[Thu Jul 30 11:44:22.717142 2026] [security2:error] [pid 643573:tid 643833] [client 43.172.194.179:39530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/04/04/shopping-13-pieces-chez-zara/"] [unique_id "amt_ZvxWyxgRnoFKAJ_agwAAAo8"]
[Thu Jul 30 11:44:22.874354 2026] [core:notice] [pid 642360:tid 642499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:22.879628 2026] [security2:error] [pid 642360:tid 642499] [client 43.173.177.197:33636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/03/21/bijoux-en-perles-de-culture-histoire-d-or/"] [unique_id "amt_ZpSUkh3e5AhEJOBcSgAAAZg"], referer: https://carnetdeshopping.com/index.php/2016/03/21/bijoux-en-perles-de-culture-histoire-d-or/
[Thu Jul 30 11:44:22.912519 2026] [security2:error] [pid 643573:tid 643812] [client 172.202.44.182:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/dropdown.php"] [unique_id "amt_ZvxWyxgRnoFKAJ_aiwAAAno"]
[Thu Jul 30 11:44:23.162400 2026] [security2:error] [pid 643573:tid 643751] [client 143.198.88.13:59236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_ajwAAAj0"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:23.439079 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:23.451498 2026] [security2:error] [pid 643573:tid 643824] [client 43.173.177.222:46074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/04/04/shopping-13-pieces-chez-zara/"] [unique_id "amt_Z_xWyxgRnoFKAJ_amgAAAoY"], referer: https://carnetdeshopping.com/index.php/2014/04/04/shopping-13-pieces-chez-zara/
[Thu Jul 30 11:44:23.873191 2026] [security2:error] [pid 642360:tid 642449] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcWQABuVg"]
[Thu Jul 30 11:44:23.873482 2026] [security2:error] [pid 642360:tid 642532] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcWQABuVg"]
[Thu Jul 30 11:44:23.919599 2026] [security2:error] [pid 643253:tid 643510] [client 172.202.44.182:22095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/makeasmtp.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj2gAAAH4"]
[Thu Jul 30 11:44:23.933295 2026] [security2:error] [pid 642360:tid 642368] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcWgABzgc"]
[Thu Jul 30 11:44:23.933449 2026] [security2:error] [pid 642360:tid 642553] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcWgABzgc"]
[Thu Jul 30 11:44:24.214949 2026] [security2:error] [pid 643253:tid 643482] [client 20.215.191.139:48746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/admin.php"] [unique_id "amt_aMjqbtjBYzqM1uYj2wAAAGI"]
[Thu Jul 30 11:44:24.870337 2026] [security2:error] [pid 642360:tid 642610] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcVwAAAgc"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:24.949561 2026] [security2:error] [pid 642360:tid 642566] [client 20.215.191.139:48727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/adminfuns.php"] [unique_id "amt_aJSUkh3e5AhEJOBcYgAAAds"]
[Thu Jul 30 11:44:25.104482 2026] [security2:error] [pid 643573:tid 643614] [remote 216.73.216.152:36964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_afxWyxgRnoFKAJ_arwACLyE"]
[Thu Jul 30 11:44:25.161651 2026] [security2:error] [pid 643573:tid 643763] [client 74.7.175.155:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jta.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_ZvxWyxgRnoFKAJ_aiQAAAkk"]
[Thu Jul 30 11:44:25.162409 2026] [security2:error] [pid 643573:tid 643766] [client 74.7.175.155:42312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jta.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_ZvxWyxgRnoFKAJ_ahwACTGQ"]
[Thu Jul 30 11:44:25.258710 2026] [security2:error] [pid 642360:tid 642598] [client 172.236.9.101:14321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcUQAAAfs"]
[Thu Jul 30 11:44:25.266595 2026] [security2:error] [pid 643573:tid 643710] [client 172.236.9.101:33856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_akgAAAhQ"]
[Thu Jul 30 11:44:25.271677 2026] [security2:error] [pid 643573:tid 643723] [client 172.236.9.101:23318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_alAAAAiE"]
[Thu Jul 30 11:44:25.289905 2026] [security2:error] [pid 643573:tid 643785] [client 172.236.9.101:38121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_alwAAAl8"]
[Thu Jul 30 11:44:25.335357 2026] [security2:error] [pid 643573:tid 643828] [client 172.236.9.101:32303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_algAAAoo"]
[Thu Jul 30 11:44:25.346704 2026] [security2:error] [pid 642360:tid 642589] [client 172.236.9.101:34219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcUwAAAfI"]
[Thu Jul 30 11:44:25.354050 2026] [security2:error] [pid 643253:tid 643477] [client 172.236.9.101:1423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj1gAAAF0"]
[Thu Jul 30 11:44:25.357481 2026] [security2:error] [pid 642360:tid 642512] [client 172.202.44.182:60983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-sigunq.php"] [unique_id "amt_aZSUkh3e5AhEJOBcZQAAAaU"]
[Thu Jul 30 11:44:25.363458 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:24378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_amAAAAlk"]
[Thu Jul 30 11:44:25.431553 2026] [security2:error] [pid 643573:tid 643778] [client 172.236.9.101:51696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_alQAAAlg"]
[Thu Jul 30 11:44:25.449661 2026] [security2:error] [pid 643253:tid 643491] [client 172.236.9.101:11601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj1AAAAGs"]
[Thu Jul 30 11:44:25.481368 2026] [security2:error] [pid 643573:tid 643834] [client 172.236.9.101:6074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_akwAAApA"]
[Thu Jul 30 11:44:25.486266 2026] [security2:error] [pid 643253:tid 643472] [client 172.236.9.101:48265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj1QAAAFg"]
[Thu Jul 30 11:44:25.520455 2026] [security2:error] [pid 642360:tid 642603] [client 172.236.9.101:37078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z5SUkh3e5AhEJOBcUgAAAgA"]
[Thu Jul 30 11:44:25.561530 2026] [security2:error] [pid 643573:tid 643738] [client 172.236.9.101:40278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_akQAAAjA"]
[Thu Jul 30 11:44:25.578869 2026] [security2:error] [pid 643573:tid 643721] [client 172.236.9.101:16056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_akAAAAh8"]
[Thu Jul 30 11:44:25.580360 2026] [security2:error] [pid 643253:tid 643443] [client 172.236.9.101:54126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj0wAAADs"]
[Thu Jul 30 11:44:25.596530 2026] [security2:error] [pid 643573:tid 643762] [client 172.236.9.101:6382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z_xWyxgRnoFKAJ_amQAAAkg"]
[Thu Jul 30 11:44:25.641158 2026] [security2:error] [pid 643253:tid 643402] [client 172.236.9.101:27079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj2QAAABI"]
[Thu Jul 30 11:44:25.657944 2026] [security2:error] [pid 643253:tid 643493] [client 172.236.9.101:47680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj2AAAAG0"]
[Thu Jul 30 11:44:25.721599 2026] [security2:error] [pid 643253:tid 643459] [client 172.236.9.101:27758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_Z8jqbtjBYzqM1uYj1wAAAEs"]
[Thu Jul 30 11:44:26.026045 2026] [proxy:error] [pid 643573:tid 643833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:26.026148 2026] [proxy_http:error] [pid 643573:tid 643833] [client 32.194.121.99:53424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:26.027270 2026] [proxy:error] [pid 643573:tid 643833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:26.027329 2026] [proxy_http:error] [pid 643573:tid 643833] [client 32.194.121.99:53424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:26.413496 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.44.182:22351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wso112233.php"] [unique_id "amt_avxWyxgRnoFKAJ_azAAAAiI"]
[Thu Jul 30 11:44:26.465263 2026] [security2:error] [pid 643573:tid 643720] [client 20.215.191.139:49097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/albin.php"] [unique_id "amt_avxWyxgRnoFKAJ_azgAAAh4"]
[Thu Jul 30 11:44:26.709169 2026] [core:error] [pid 643253:tid 643446] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.709197 2026] [core:error] [pid 643253:tid 643446] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.712632 2026] [core:error] [pid 643253:tid 643463] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.712652 2026] [core:error] [pid 643253:tid 643463] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.719457 2026] [security2:error] [pid 643573:tid 643768] [client 143.198.88.13:64237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amt_afxWyxgRnoFKAJ_avAAAAk4"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:26.724048 2026] [core:error] [pid 643253:tid 643445] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.724067 2026] [core:error] [pid 643253:tid 643445] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.748590 2026] [core:error] [pid 643573:tid 643759] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.748619 2026] [core:error] [pid 643573:tid 643759] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.760733 2026] [core:error] [pid 642360:tid 642514] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:26.760753 2026] [core:error] [pid 642360:tid 642514] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:27.585958 2026] [security2:error] [pid 642360:tid 642550] [client 172.202.44.182:22083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/alfanew.php"] [unique_id "amt_a5SUkh3e5AhEJOBcfwAAAcs"]
[Thu Jul 30 11:44:27.628536 2026] [security2:error] [pid 643573:tid 643765] [client 20.215.191.139:48767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/amfsqvgv.php"] [unique_id "amt_a_xWyxgRnoFKAJ_a6AAAAks"]
[Thu Jul 30 11:44:27.862246 2026] [security2:error] [pid 643573:tid 643767] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amt_avxWyxgRnoFKAJ_a3wAAAk0"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:28.210969 2026] [security2:error] [pid 643573:tid 643775] [client 20.215.191.139:48735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/ant.php"] [unique_id "amt_bPxWyxgRnoFKAJ_a8wAAAlU"]
[Thu Jul 30 11:44:28.315739 2026] [security2:error] [pid 642360:tid 642611] [client 94.154.43.183:29500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "saifalkhaleejest.com"] [uri "/.env"] [unique_id "amt_bJSUkh3e5AhEJOBchAAAAgg"]
[Thu Jul 30 11:44:28.613747 2026] [security2:error] [pid 643573:tid 643764] [client 172.202.44.182:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/fw.php"] [unique_id "amt_bPxWyxgRnoFKAJ_a9wAAAko"]
[Thu Jul 30 11:44:28.790350 2026] [security2:error] [pid 643573:tid 643741] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amt_a_xWyxgRnoFKAJ_a6QACMw0"]
[Thu Jul 30 11:44:29.029089 2026] [security2:error] [pid 643573:tid 643782] [client 20.215.191.139:48946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/appreciators.php"] [unique_id "amt_bfxWyxgRnoFKAJ_a_gAAAlw"]
[Thu Jul 30 11:44:29.436288 2026] [security2:error] [pid 643573:tid 643694] [remote 216.73.216.152:36964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_bfxWyxgRnoFKAJ_bAwACd3E"]
[Thu Jul 30 11:44:29.606274 2026] [security2:error] [pid 643573:tid 643789] [client 34.182.188.145:64435] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amt_bfxWyxgRnoFKAJ_bBwAAAmM"]
[Thu Jul 30 11:44:29.778191 2026] [security2:error] [pid 643573:tid 643778] [client 143.198.88.13:64237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amt_bPxWyxgRnoFKAJ_a_QAAAlg"], referer: www.website-d1827c3b.palatov.com/blog//wp-login.php
[Thu Jul 30 11:44:29.897813 2026] [security2:error] [pid 643573:tid 643736] [client 143.198.88.13:64237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_bfxWyxgRnoFKAJ_bDAAAAi4"]
[Thu Jul 30 11:44:29.897966 2026] [security2:error] [pid 643573:tid 643736] [client 143.198.88.13:64237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tereashops.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_bfxWyxgRnoFKAJ_bDAAAAi4"]
[Thu Jul 30 11:44:30.388002 2026] [security2:error] [pid 643573:tid 643815] [client 143.198.88.13:53819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/blog//wp-login.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFAAAAn0"], referer: https://tereashops.com//blog//wp-login.php
[Thu Jul 30 11:44:30.578623 2026] [security2:error] [pid 643573:tid 643752] [client 34.182.188.145:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.188.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFQAAAj4"]
[Thu Jul 30 11:44:30.598925 2026] [security2:error] [pid 643573:tid 643795] [client 176.241.66.87:50715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFgAAAmk"]
[Thu Jul 30 11:44:30.599090 2026] [security2:error] [pid 643573:tid 643795] [client 176.241.66.87:50715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFgAAAmk"]
[Thu Jul 30 11:44:30.681353 2026] [security2:error] [pid 643573:tid 643714] [client 20.215.191.139:64287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/archive.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bFwAAAhg"]
[Thu Jul 30 11:44:30.735605 2026] [security2:error] [pid 643573:tid 643700] [remote 57.141.0.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amt_bvxWyxgRnoFKAJ_bGAACenc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=nylon,plastic,polyester,silicon,steel,wood&filter_size=large&filter_brand=desigual&unfilter=1
[Thu Jul 30 11:44:31.082782 2026] [security2:error] [pid 643573:tid 643692] [remote 52.167.144.18:13612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/download/8922/3577"] [unique_id "amt_bvxWyxgRnoFKAJ_bGgACIW8"]
[Thu Jul 30 11:44:31.251697 2026] [security2:error] [pid 643573:tid 643699] [remote 57.141.0.11:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amt_b_xWyxgRnoFKAJ_bHQACKXY"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=nylon,plastic,polyester,silicon,steel,wood&filter_size=large&filter_brand=desigual&unfilter=1
[Thu Jul 30 11:44:33.112337 2026] [security2:error] [pid 643573:tid 643832] [client 143.198.88.13:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-dc09cfb9.jud.zzt.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amt_cfxWyxgRnoFKAJ_bKgAAAo4"], referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:33.244988 2026] [security2:error] [pid 642360:tid 642564] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_b5SUkh3e5AhEJOBcowAB2XY"]
[Thu Jul 30 11:44:33.499686 2026] [security2:error] [pid 643573:tid 643714] [client 20.91.199.21:12259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/geju.php"] [unique_id "amt_cfxWyxgRnoFKAJ_bMgAAAhg"]
[Thu Jul 30 11:44:33.808403 2026] [core:error] [pid 643253:tid 643486] [client 143.198.88.13:60072] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:33.808429 2026] [core:error] [pid 643253:tid 643486] [client 143.198.88.13:60072] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.031645 2026] [core:error] [pid 642360:tid 642616] [client 143.198.88.13:58281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.031675 2026] [core:error] [pid 642360:tid 642616] [client 143.198.88.13:58281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.278438 2026] [core:error] [pid 643573:tid 643789] [client 143.198.88.13:58431] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.278461 2026] [core:error] [pid 643573:tid 643789] [client 143.198.88.13:58431] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.331991 2026] [security2:error] [pid 643573:tid 643732] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_cfxWyxgRnoFKAJ_bNQAAAio"]
[Thu Jul 30 11:44:34.437405 2026] [security2:error] [pid 643573:tid 643698] [remote 216.73.216.152:36964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_cvxWyxgRnoFKAJ_bQAACcHU"]
[Thu Jul 30 11:44:34.482614 2026] [core:error] [pid 643573:tid 643796] [client 143.198.88.13:62841] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.482637 2026] [core:error] [pid 643573:tid 643796] [client 143.198.88.13:62841] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.website-d7a8aca5.vwn.lxf.temporary.site//blog//wp-login.php
[Thu Jul 30 11:44:34.509139 2026] [security2:error] [pid 643573:tid 643708] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_cvxWyxgRnoFKAJ_bQgACN38"]
[Thu Jul 30 11:44:34.509348 2026] [security2:error] [pid 643573:tid 643745] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_cvxWyxgRnoFKAJ_bQgACN38"]
[Thu Jul 30 11:44:34.757956 2026] [security2:error] [pid 643573:tid 643707] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_cvxWyxgRnoFKAJ_bQwACLH4"]
[Thu Jul 30 11:44:34.758122 2026] [security2:error] [pid 643573:tid 643734] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_cvxWyxgRnoFKAJ_bQwACLH4"]
[Thu Jul 30 11:44:35.638102 2026] [security2:error] [pid 643573:tid 643649] [remote 40.77.167.247:36904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/edunomic/article/download/9127/3948"] [unique_id "amt_c_xWyxgRnoFKAJ_bUgACe0Q"]
[Thu Jul 30 11:44:36.203459 2026] [security2:error] [pid 642360:tid 642609] [client 172.202.44.182:22080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-login.php"] [unique_id "amt_c5SUkh3e5AhEJOBcuwAAAgY"]
[Thu Jul 30 11:44:36.658618 2026] [security2:error] [pid 643573:tid 643740] [client 34.182.188.145:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.188.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_dPxWyxgRnoFKAJ_bWwAAAjI"]
[Thu Jul 30 11:44:36.658729 2026] [security2:error] [pid 643573:tid 643740] [client 34.182.188.145:55256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_dPxWyxgRnoFKAJ_bWwAAAjI"]
[Thu Jul 30 11:44:36.666053 2026] [core:notice] [pid 643573:tid 643792] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:44:36.780123 2026] [security2:error] [pid 643253:tid 643489] [client 20.91.199.21:14998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/about.php"] [unique_id "amt_dMjqbtjBYzqM1uYj7AAAAGk"]
[Thu Jul 30 11:44:36.796025 2026] [security2:error] [pid 643253:tid 643401] [client 143.198.88.13:64154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_dMjqbtjBYzqM1uYj7QAAABE"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:37.168825 2026] [security2:error] [pid 643573:tid 643765] [client 172.202.44.182:61014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/simple.php"] [unique_id "amt_dfxWyxgRnoFKAJ_bYAAAAks"]
[Thu Jul 30 11:44:38.003468 2026] [security2:error] [pid 643253:tid 643400] [client 172.202.44.182:47244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/classsmtps.php"] [unique_id "amt_dsjqbtjBYzqM1uYj8AAAABA"]
[Thu Jul 30 11:44:38.155055 2026] [security2:error] [pid 643573:tid 643751] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amt_dfxWyxgRnoFKAJ_bYgAAAj0"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:38.424696 2026] [security2:error] [pid 643573:tid 643734] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_dfxWyxgRnoFKAJ_bXwACLAg"]
[Thu Jul 30 11:44:38.449630 2026] [security2:error] [pid 643573:tid 643585] [remote 57.141.0.12:21084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amt_dvxWyxgRnoFKAJ_bcgACIQQ"]
[Thu Jul 30 11:44:38.577200 2026] [core:error] [pid 643253:tid 643458] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.577225 2026] [core:error] [pid 643253:tid 643458] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.585131 2026] [core:error] [pid 643573:tid 643725] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.585165 2026] [core:error] [pid 643573:tid 643725] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.595201 2026] [core:error] [pid 643253:tid 643431] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.595232 2026] [core:error] [pid 643253:tid 643431] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.596238 2026] [core:error] [pid 643253:tid 643418] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.596262 2026] [core:error] [pid 643253:tid 643418] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.597163 2026] [core:error] [pid 643253:tid 643395] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.597184 2026] [core:error] [pid 643253:tid 643395] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:38.629730 2026] [security2:error] [pid 643573:tid 643745] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_dfxWyxgRnoFKAJ_bYwACN3w"]
[Thu Jul 30 11:44:38.838213 2026] [security2:error] [pid 643573:tid 643768] [client 20.91.199.21:45286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp.php"] [unique_id "amt_dvxWyxgRnoFKAJ_biAAAAk4"]
[Thu Jul 30 11:44:39.250701 2026] [security2:error] [pid 643573:tid 643796] [client 172.202.44.182:60935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-blog-header.php"] [unique_id "amt_d_xWyxgRnoFKAJ_bkAAAAmo"]
[Thu Jul 30 11:44:39.439290 2026] [security2:error] [pid 643573:tid 643605] [remote 216.73.216.152:36964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_d_xWyxgRnoFKAJ_bkQACexg"]
[Thu Jul 30 11:44:39.717855 2026] [proxy:error] [pid 643573:tid 643743] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:39.717958 2026] [proxy_http:error] [pid 643573:tid 643743] [client 32.194.121.99:2406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:39.718757 2026] [security2:error] [pid 642360:tid 642617] [client 143.198.88.13:60799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amt_dpSUkh3e5AhEJOBczAAAAg4"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:39.718834 2026] [proxy:error] [pid 643573:tid 643743] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:39.718893 2026] [proxy_http:error] [pid 643573:tid 643743] [client 32.194.121.99:2406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:39.724306 2026] [proxy:error] [pid 643573:tid 643797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:39.724369 2026] [proxy_http:error] [pid 643573:tid 643797] [client 34.224.175.62:47937] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:39.724920 2026] [proxy:error] [pid 643573:tid 643797] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:39.724963 2026] [proxy_http:error] [pid 643573:tid 643797] [client 34.224.175.62:47937] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:39.800311 2026] [security2:error] [pid 643253:tid 643511] [client 20.91.199.21:45482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/aaa.php"] [unique_id "amt_d8jqbtjBYzqM1uYj_AAAAH8"]
[Thu Jul 30 11:44:40.469486 2026] [security2:error] [pid 643253:tid 643429] [client 172.202.44.182:22338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-trackback.php"] [unique_id "amt_eMjqbtjBYzqM1uYj_gAAAC0"]
[Thu Jul 30 11:44:40.537925 2026] [security2:error] [pid 643573:tid 643715] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_d_xWyxgRnoFKAJ_bigACGUg"]
[Thu Jul 30 11:44:40.640541 2026] [security2:error] [pid 643253:tid 643416] [client 20.91.199.21:3998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/hoot.php"] [unique_id "amt_eMjqbtjBYzqM1uYj_wAAACA"]
[Thu Jul 30 11:44:40.773737 2026] [security2:error] [pid 643253:tid 643465] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amt_d8jqbtjBYzqM1uYj_QAAAFE"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:41.207216 2026] [security2:error] [pid 643573:tid 643770] [client 176.241.66.87:51419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_efxWyxgRnoFKAJ_brAAAAlA"]
[Thu Jul 30 11:44:41.207402 2026] [security2:error] [pid 643573:tid 643770] [client 176.241.66.87:51419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_efxWyxgRnoFKAJ_brAAAAlA"]
[Thu Jul 30 11:44:41.470670 2026] [security2:error] [pid 643573:tid 643736] [client 20.91.199.21:3968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/about.php"] [unique_id "amt_efxWyxgRnoFKAJ_brwAAAi4"]
[Thu Jul 30 11:44:41.940284 2026] [security2:error] [pid 643573:tid 643719] [client 20.215.191.139:64272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/as.php"] [unique_id "amt_efxWyxgRnoFKAJ_bsgAAAh0"]
[Thu Jul 30 11:44:42.218352 2026] [security2:error] [pid 643573:tid 643780] [client 172.202.44.182:60953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-signup.php"] [unique_id "amt_evxWyxgRnoFKAJ_bswAAAlo"]
[Thu Jul 30 11:44:42.246510 2026] [security2:error] [pid 643253:tid 643481] [client 172.236.9.101:9601] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/privatekey.key"] [unique_id "amt_esjqbtjBYzqM1uYkAgAAAGE"]
[Thu Jul 30 11:44:42.274579 2026] [security2:error] [pid 643573:tid 643735] [client 20.91.199.21:5698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/admin.php"] [unique_id "amt_evxWyxgRnoFKAJ_buAAAAi0"]
[Thu Jul 30 11:44:42.291706 2026] [security2:error] [pid 643573:tid 643822] [client 172.236.9.101:64365] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_dsa"] [unique_id "amt_evxWyxgRnoFKAJ_buQAAAoQ"]
[Thu Jul 30 11:44:42.292165 2026] [security2:error] [pid 642360:tid 642563] [client 172.236.9.101:9638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/key.pem"] [unique_id "amt_epSUkh3e5AhEJOBc6wAAAdg"]
[Thu Jul 30 11:44:42.294821 2026] [security2:error] [pid 642360:tid 642578] [client 172.236.9.101:59518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_rsa"] [unique_id "amt_epSUkh3e5AhEJOBc7AAAAec"]
[Thu Jul 30 11:44:42.410036 2026] [security2:error] [pid 642360:tid 642534] [client 143.198.88.13:60799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amt_eZSUkh3e5AhEJOBc4AAAAbs"], referer: www.website-dbe2688a.snappyhomeoffers.com/blog//wp-login.php
[Thu Jul 30 11:44:42.489331 2026] [security2:error] [pid 642360:tid 642591] [client 143.198.88.13:60799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_epSUkh3e5AhEJOBc7gAAAfQ"]
[Thu Jul 30 11:44:42.489538 2026] [security2:error] [pid 642360:tid 642591] [client 143.198.88.13:60799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kool-shop.com"] [uri "/blog//xmlrpc.php"] [unique_id "amt_epSUkh3e5AhEJOBc7gAAAfQ"]
[Thu Jul 30 11:44:42.858091 2026] [security2:error] [pid 643573:tid 643712] [client 143.198.88.13:64839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/blog//wp-login.php"] [unique_id "amt_evxWyxgRnoFKAJ_bwgAAAhY"], referer: https://kool-shop.com//blog//wp-login.php
[Thu Jul 30 11:44:42.930518 2026] [security2:error] [pid 642360:tid 642587] [client 172.236.9.101:61473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_epSUkh3e5AhEJOBc5QAAAfA"]
[Thu Jul 30 11:44:42.936251 2026] [security2:error] [pid 643573:tid 643743] [client 172.236.9.101:45935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_btgAAAjU"]
[Thu Jul 30 11:44:42.941733 2026] [security2:error] [pid 643573:tid 643774] [client 172.236.9.101:11996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_buwAAAlQ"]
[Thu Jul 30 11:44:42.949070 2026] [security2:error] [pid 643253:tid 643387] [client 172.236.9.101:63630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_esjqbtjBYzqM1uYkAwAAAAM"]
[Thu Jul 30 11:44:42.963243 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:41134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_epSUkh3e5AhEJOBc5gAAAbY"]
[Thu Jul 30 11:44:42.982659 2026] [security2:error] [pid 643573:tid 643754] [client 172.236.9.101:47520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_btwAAAkA"]
[Thu Jul 30 11:44:42.983946 2026] [security2:error] [pid 643573:tid 643756] [client 172.236.9.101:47985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_bugAAAkI"]
[Thu Jul 30 11:44:42.986781 2026] [security2:error] [pid 642360:tid 642615] [client 172.236.9.101:6338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_epSUkh3e5AhEJOBc6AAAAgw"]
[Thu Jul 30 11:44:43.088396 2026] [security2:error] [pid 642360:tid 642536] [client 172.202.44.182:22107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-comments-post.php"] [unique_id "amt_e5SUkh3e5AhEJOBc8gAAAb0"]
[Thu Jul 30 11:44:43.265439 2026] [security2:error] [pid 643573:tid 643753] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_evxWyxgRnoFKAJ_bvwAAAj8"]
[Thu Jul 30 11:44:43.277307 2026] [security2:error] [pid 642360:tid 642508] [client 172.236.9.101:32444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_dsa"] [unique_id "amt_e5SUkh3e5AhEJOBc9AAAAaE"]
[Thu Jul 30 11:44:43.277334 2026] [security2:error] [pid 643573:tid 643724] [client 172.236.9.101:14087] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_rsa"] [unique_id "amt_e_xWyxgRnoFKAJ_bygAAAiI"]
[Thu Jul 30 11:44:43.674809 2026] [core:error] [pid 643573:tid 643609] [remote 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:43.674844 2026] [core:error] [pid 643573:tid 643609] [remote 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:43.708517 2026] [core:error] [pid 642360:tid 642412] [remote 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:43.708564 2026] [core:error] [pid 642360:tid 642412] [remote 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:43.783919 2026] [security2:error] [pid 643573:tid 643715] [client 172.236.9.101:46297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e_xWyxgRnoFKAJ_bxwAAAhk"]
[Thu Jul 30 11:44:43.796669 2026] [security2:error] [pid 642360:tid 642571] [client 172.236.9.101:64113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e5SUkh3e5AhEJOBc9gAAAeA"]
[Thu Jul 30 11:44:43.813098 2026] [security2:error] [pid 643573:tid 643744] [client 172.236.9.101:18374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e_xWyxgRnoFKAJ_byQAAAjY"]
[Thu Jul 30 11:44:43.818268 2026] [security2:error] [pid 642360:tid 642570] [client 172.236.9.101:33813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e5SUkh3e5AhEJOBc9QAAAd8"]
[Thu Jul 30 11:44:43.829054 2026] [security2:error] [pid 643573:tid 643817] [client 172.236.9.101:22024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e_xWyxgRnoFKAJ_bxgAAAn8"]
[Thu Jul 30 11:44:43.841780 2026] [security2:error] [pid 643573:tid 643788] [client 172.236.9.101:60034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_e_xWyxgRnoFKAJ_bywAAAmI"]
[Thu Jul 30 11:44:44.219847 2026] [security2:error] [pid 643573:tid 643710] [client 172.202.44.182:61023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-mail.php"] [unique_id "amt_fPxWyxgRnoFKAJ_b1AAAAhQ"]
[Thu Jul 30 11:44:45.071996 2026] [security2:error] [pid 643573:tid 643608] [remote 216.73.216.152:20905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_ffxWyxgRnoFKAJ_b2gACUhs"]
[Thu Jul 30 11:44:45.106578 2026] [security2:error] [pid 642360:tid 642514] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amt_fJSUkh3e5AhEJOBdBgABpzs"]
[Thu Jul 30 11:44:45.214351 2026] [security2:error] [pid 642360:tid 642406] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_fZSUkh3e5AhEJOBdCwACBi0"]
[Thu Jul 30 11:44:45.214531 2026] [security2:error] [pid 642360:tid 642609] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_fZSUkh3e5AhEJOBdCwACBi0"]
[Thu Jul 30 11:44:45.261241 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.44.182:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-activate.php"] [unique_id "amt_ffxWyxgRnoFKAJ_b2wAAAkM"]
[Thu Jul 30 11:44:45.574133 2026] [security2:error] [pid 643573:tid 643588] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_ffxWyxgRnoFKAJ_b4AACMgc"]
[Thu Jul 30 11:44:45.574265 2026] [security2:error] [pid 643573:tid 643740] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_ffxWyxgRnoFKAJ_b4AACMgc"]
[Thu Jul 30 11:44:46.237680 2026] [security2:error] [pid 642360:tid 642415] [remote 47.128.125.43:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fantasynamelist.com"] [uri "/robots.txt"] [unique_id "amt_fpSUkh3e5AhEJOBdEQAB4TY"]
[Thu Jul 30 11:44:46.538566 2026] [security2:error] [pid 643253:tid 643434] [client 20.215.191.139:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/atomlib.php"] [unique_id "amt_fsjqbtjBYzqM1uYkHAAAADI"]
[Thu Jul 30 11:44:46.562931 2026] [security2:error] [pid 643573:tid 643725] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_ffxWyxgRnoFKAJ_b3AACIwI"]
[Thu Jul 30 11:44:47.098214 2026] [security2:error] [pid 643573:tid 643801] [client 172.202.44.182:22120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/post.php"] [unique_id "amt_f_xWyxgRnoFKAJ_b7QAAAm8"]
[Thu Jul 30 11:44:47.422399 2026] [security2:error] [pid 643573:tid 643755] [client 20.91.199.21:18122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/admin.php"] [unique_id "amt_f_xWyxgRnoFKAJ_b8gAAAkE"]
[Thu Jul 30 11:44:47.436834 2026] [security2:error] [pid 643573:tid 643793] [client 20.215.191.139:64326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/autoload_classmap.php"] [unique_id "amt_f_xWyxgRnoFKAJ_b8wAAAmc"]
[Thu Jul 30 11:44:48.078231 2026] [security2:error] [pid 643573:tid 643753] [client 20.91.199.21:15037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/db-cache.php"] [unique_id "amt_gPxWyxgRnoFKAJ_b-wAAAj8"]
[Thu Jul 30 11:44:48.657414 2026] [security2:error] [pid 643573:tid 643761] [client 172.202.44.182:61032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-2019.php"] [unique_id "amt_gPxWyxgRnoFKAJ_cAwAAAkc"]
[Thu Jul 30 11:44:48.916320 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:13846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amt_gPxWyxgRnoFKAJ_cBgAAAn8"]
[Thu Jul 30 11:44:48.917294 2026] [security2:error] [pid 643573:tid 643813] [client 20.215.191.139:64355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/bb.php"] [unique_id "amt_gPxWyxgRnoFKAJ_cBwAAAns"]
[Thu Jul 30 11:44:49.277713 2026] [security2:error] [pid 643253:tid 643494] [client 220.124.216.164:44476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_gMjqbtjBYzqM1uYkHQAAAG4"]
[Thu Jul 30 11:44:49.449145 2026] [security2:error] [pid 643573:tid 643626] [remote 216.73.216.152:20905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_gfxWyxgRnoFKAJ_cDgACcS0"]
[Thu Jul 30 11:44:49.607750 2026] [security2:error] [pid 643573:tid 643784] [client 20.215.191.139:48338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/bnm.php"] [unique_id "amt_gfxWyxgRnoFKAJ_cEgAAAl4"]
[Thu Jul 30 11:44:49.764576 2026] [security2:error] [pid 643573:tid 643772] [client 44.248.244.184:38574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.shorewooddaycare.com"] [uri "/"] [unique_id "amt_gfxWyxgRnoFKAJ_cFgAAAlI"]
[Thu Jul 30 11:44:50.290475 2026] [security2:error] [pid 643573:tid 643827] [client 172.202.44.182:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/hoot.php"] [unique_id "amt_gvxWyxgRnoFKAJ_cHAAAAok"]
[Thu Jul 30 11:44:50.340273 2026] [security2:error] [pid 643573:tid 643837] [client 20.215.191.139:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/bootstrap.php"] [unique_id "amt_gvxWyxgRnoFKAJ_cHQAAApM"]
[Thu Jul 30 11:44:50.539328 2026] [security2:error] [pid 643573:tid 643820] [client 44.248.244.184:35936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.shorewooddaycare.com"] [uri "/index.html"] [unique_id "amt_gvxWyxgRnoFKAJ_cHwAAAoI"], referer: http://www.shorewooddaycare.com/
[Thu Jul 30 11:44:50.986080 2026] [security2:error] [pid 642360:tid 642604] [client 20.215.191.139:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/buy.php"] [unique_id "amt_gpSUkh3e5AhEJOBdLQAAAgE"]
[Thu Jul 30 11:44:51.350456 2026] [security2:error] [pid 643573:tid 643729] [client 172.202.44.182:61050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/log.php"] [unique_id "amt_g_xWyxgRnoFKAJ_cJwAAAic"]
[Thu Jul 30 11:44:51.359281 2026] [security2:error] [pid 643573:tid 643749] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_gfxWyxgRnoFKAJ_cFwACOyM"]
[Thu Jul 30 11:44:51.455783 2026] [security2:error] [pid 643573:tid 643710] [client 82.181.86.116:57276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_gvxWyxgRnoFKAJ_cHgAAAlM"]
[Thu Jul 30 11:44:51.525884 2026] [security2:error] [pid 643253:tid 643409] [client 213.152.161.25:46194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt_g8jqbtjBYzqM1uYkHgAAABk"]
[Thu Jul 30 11:44:51.526030 2026] [security2:error] [pid 643253:tid 643409] [client 213.152.161.25:46194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amt_g8jqbtjBYzqM1uYkHgAAABk"]
[Thu Jul 30 11:44:51.601096 2026] [security2:error] [pid 643573:tid 643817] [client 118.193.33.19:55498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amt_g_xWyxgRnoFKAJ_cJAAAAn8"]
[Thu Jul 30 11:44:51.761686 2026] [security2:error] [pid 642360:tid 642563] [client 20.91.199.21:45408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amt_g5SUkh3e5AhEJOBdNAAAAdg"]
[Thu Jul 30 11:44:51.854288 2026] [security2:error] [pid 643573:tid 643738] [client 176.241.66.87:52192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_g_xWyxgRnoFKAJ_cKgAAAjA"]
[Thu Jul 30 11:44:51.854390 2026] [security2:error] [pid 643573:tid 643738] [client 176.241.66.87:52192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_g_xWyxgRnoFKAJ_cKgAAAjA"]
[Thu Jul 30 11:44:52.081126 2026] [fcgid:warn] [pid 642360:tid 642587] (70014)End of file found: [client 118.193.33.19:59062] mod_fcgid: can't get data from http client
[Thu Jul 30 11:44:52.303252 2026] [fcgid:warn] [pid 642360:tid 642554] (70014)End of file found: [client 118.193.33.19:59092] mod_fcgid: can't get data from http client
[Thu Jul 30 11:44:52.532922 2026] [fcgid:warn] [pid 643573:tid 643734] (70014)End of file found: [client 118.193.33.19:59146] mod_fcgid: can't get data from http client
[Thu Jul 30 11:44:53.333345 2026] [security2:error] [pid 643253:tid 643473] [client 172.202.44.182:60960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/bak.php"] [unique_id "amt_hcjqbtjBYzqM1uYkKAAAAFk"]
[Thu Jul 30 11:44:53.374463 2026] [core:error] [pid 643253:tid 643468] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.374486 2026] [core:error] [pid 643253:tid 643468] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.413882 2026] [core:error] [pid 643573:tid 643811] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.413901 2026] [core:error] [pid 643573:tid 643811] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.425571 2026] [core:error] [pid 643573:tid 643798] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.425595 2026] [core:error] [pid 643573:tid 643798] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.441840 2026] [core:error] [pid 642360:tid 642603] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.441858 2026] [core:error] [pid 642360:tid 642603] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.442821 2026] [core:error] [pid 643573:tid 643788] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.442836 2026] [core:error] [pid 643573:tid 643788] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:53.479844 2026] [security2:error] [pid 643573:tid 643781] [client 179.43.134.114:42010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrecoveryserviceabudhabillc.site"] [uri "/wp-login.php"] [unique_id "amt_hfxWyxgRnoFKAJ_cMQAAAls"]
[Thu Jul 30 11:44:53.803559 2026] [security2:error] [pid 643573:tid 643768] [client 20.91.199.21:11660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amt_hfxWyxgRnoFKAJ_cQQAAAk4"]
[Thu Jul 30 11:44:54.074394 2026] [security2:error] [pid 643573:tid 643801] [client 20.215.191.139:64283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/chosen.php"] [unique_id "amt_hvxWyxgRnoFKAJ_cRwAAAm8"]
[Thu Jul 30 11:44:54.269759 2026] [core:error] [pid 642360:tid 642612] [client 179.43.134.114:42020] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:54.269786 2026] [core:error] [pid 642360:tid 642612] [client 179.43.134.114:42020] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:44:54.344634 2026] [security2:error] [pid 643573:tid 643822] [client 59.0.218.253:34118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_hfxWyxgRnoFKAJ_cQAAAAi4"]
[Thu Jul 30 11:44:54.448919 2026] [security2:error] [pid 643573:tid 643630] [remote 216.73.216.152:20905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amt_hvxWyxgRnoFKAJ_cTQACYDE"]
[Thu Jul 30 11:44:54.948078 2026] [security2:error] [pid 642360:tid 642584] [client 20.215.191.139:64373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/class-wp-image.php"] [unique_id "amt_hpSUkh3e5AhEJOBdUwAAAe0"]
[Thu Jul 30 11:44:55.789930 2026] [security2:error] [pid 643573:tid 643744] [client 20.215.191.139:48325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/classsmtps.php"] [unique_id "amt_h_xWyxgRnoFKAJ_cXAAAAjY"]
[Thu Jul 30 11:44:55.828332 2026] [security2:error] [pid 642360:tid 642380] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_h5SUkh3e5AhEJOBdVwABvxM"]
[Thu Jul 30 11:44:55.828555 2026] [security2:error] [pid 642360:tid 642538] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_h5SUkh3e5AhEJOBdVwABvxM"]
[Thu Jul 30 11:44:56.282802 2026] [security2:error] [pid 643253:tid 643392] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_h8jqbtjBYzqM1uYkLgAAAAg"]
[Thu Jul 30 11:44:56.379584 2026] [security2:error] [pid 643573:tid 643769] [client 20.91.199.21:45511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amt_iPxWyxgRnoFKAJ_cYAAAAk8"]
[Thu Jul 30 11:44:56.484062 2026] [security2:error] [pid 643573:tid 643721] [client 20.215.191.139:63953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/classwithtostring.php"] [unique_id "amt_iPxWyxgRnoFKAJ_cYQAAAh8"]
[Thu Jul 30 11:44:56.519854 2026] [security2:error] [pid 643573:tid 643643] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_iPxWyxgRnoFKAJ_cZAACHT4"]
[Thu Jul 30 11:44:56.520045 2026] [security2:error] [pid 643573:tid 643719] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_iPxWyxgRnoFKAJ_cZAACHT4"]
[Thu Jul 30 11:44:56.540581 2026] [security2:error] [pid 643573:tid 643817] [client 85.240.122.127:34716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_h_xWyxgRnoFKAJ_cWgAAAmw"]
[Thu Jul 30 11:44:56.945478 2026] [proxy:error] [pid 643573:tid 643749] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:56.945529 2026] [proxy_http:error] [pid 643573:tid 643749] [client 195.96.139.95:51419] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:56.946094 2026] [proxy:error] [pid 643573:tid 643749] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:44:56.946139 2026] [proxy_http:error] [pid 643573:tid 643749] [client 195.96.139.95:51419] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:44:58.076740 2026] [security2:error] [pid 643573:tid 643765] [client 114.119.132.101:46849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltaedu.net"] [uri "/low-tution-fee"] [unique_id "amt_ivxWyxgRnoFKAJ_ccgAAAks"], referer: https://deltaedu.net/
[Thu Jul 30 11:44:58.359199 2026] [security2:error] [pid 643573:tid 643811] [client 172.236.9.101:30107] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backup.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cdQAAAnk"]
[Thu Jul 30 11:44:58.361148 2026] [security2:error] [pid 642360:tid 642562] [client 172.236.9.101:56461] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/dump.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdbQAAAdc"]
[Thu Jul 30 11:44:58.368246 2026] [security2:error] [pid 642360:tid 642577] [client 172.236.9.101:52720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/alseermarine.com:443.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdbgAAAeY"]
[Thu Jul 30 11:44:58.368727 2026] [security2:error] [pid 642360:tid 642579] [client 172.236.9.101:38920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backups/database.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdbwAAAeg"]
[Thu Jul 30 11:44:58.375103 2026] [security2:error] [pid 643573:tid 643770] [client 172.236.9.101:7701] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/database.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cdgAAAlA"]
[Thu Jul 30 11:44:58.377639 2026] [security2:error] [pid 643573:tid 643785] [client 172.236.9.101:50002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/mysql.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cdwAAAl8"]
[Thu Jul 30 11:44:58.384571 2026] [security2:error] [pid 643573:tid 643714] [client 172.236.9.101:55161] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/alseermarine.com:443.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_ceAAAAhg"]
[Thu Jul 30 11:44:58.404415 2026] [security2:error] [pid 642360:tid 642533] [client 172.236.9.101:57424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/database.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdcQAAAbo"]
[Thu Jul 30 11:44:58.404416 2026] [security2:error] [pid 642360:tid 642614] [client 172.236.9.101:30781] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/database.sql"] [unique_id "amt_ipSUkh3e5AhEJOBdcAAAAgs"]
[Thu Jul 30 11:44:58.404796 2026] [security2:error] [pid 643573:tid 643790] [client 172.236.9.101:17610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_ceQAAAmQ"]
[Thu Jul 30 11:44:58.430401 2026] [security2:error] [pid 643573:tid 643799] [client 172.236.9.101:41969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/db.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cegAAAm0"]
[Thu Jul 30 11:44:58.430491 2026] [security2:error] [pid 643573:tid 643761] [client 172.236.9.101:34940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "amt_ivxWyxgRnoFKAJ_cewAAAkc"]
[Thu Jul 30 11:44:58.628567 2026] [security2:error] [pid 642360:tid 642593] [client 20.91.199.21:45673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amt_ipSUkh3e5AhEJOBddAAAAfY"]
[Thu Jul 30 11:44:58.797785 2026] [security2:error] [pid 643573:tid 643782] [client 172.202.44.182:61013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/content.php"] [unique_id "amt_ivxWyxgRnoFKAJ_cfwAAAlw"]
[Thu Jul 30 11:44:59.876716 2026] [security2:error] [pid 643573:tid 643726] [client 20.91.199.21:3453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/content.php"] [unique_id "amt_i_xWyxgRnoFKAJ_chgAAAiQ"]
[Thu Jul 30 11:44:59.901501 2026] [security2:error] [pid 642360:tid 642490] [client 172.202.44.182:21993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/upfile.php"] [unique_id "amt_i5SUkh3e5AhEJOBdfwAAAY8"]
[Thu Jul 30 11:45:00.055726 2026] [security2:error] [pid 642360:tid 642468] [remote 216.73.216.152:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amt_jJSUkh3e5AhEJOBdgAAB8Gs"]
[Thu Jul 30 11:45:00.827191 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.44.182:60930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/bypass.php"] [unique_id "amt_jPxWyxgRnoFKAJ_ckAAAAnQ"]
[Thu Jul 30 11:45:01.240539 2026] [security2:error] [pid 643573:tid 643779] [client 85.208.96.204:59560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/11/14/doria-pode-sofrer-impeachment-por-cheque-em-branco-a-china/"] [unique_id "amt_jfxWyxgRnoFKAJ_ckgAAAlk"]
[Thu Jul 30 11:45:01.240704 2026] [security2:error] [pid 643573:tid 643779] [client 85.208.96.204:59560] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/11/14/doria-pode-sofrer-impeachment-por-cheque-em-branco-a-china/"] [unique_id "amt_jfxWyxgRnoFKAJ_ckgAAAlk"]
[Thu Jul 30 11:45:01.392234 2026] [fcgid:warn] [pid 643573:tid 643729] (70014)End of file found: [client 118.193.33.19:57190] mod_fcgid: can't get data from http client
[Thu Jul 30 11:45:01.631012 2026] [security2:error] [pid 642360:tid 642470] [remote 74.7.241.60:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amt_jZSUkh3e5AhEJOBdjgAB1m0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:45:02.236097 2026] [security2:error] [pid 642360:tid 642547] [client 20.215.191.139:64334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/config.php"] [unique_id "amt_jpSUkh3e5AhEJOBdkwAAAcg"]
[Thu Jul 30 11:45:02.264018 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.44.182:60977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/updates.php"] [unique_id "amt_jvxWyxgRnoFKAJ_cmgAAAiU"]
[Thu Jul 30 11:45:02.470582 2026] [security2:error] [pid 643573:tid 643646] [remote 57.141.0.16:25002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/589953950/feed/rss2/"] [unique_id "amt_jvxWyxgRnoFKAJ_clwACZ0E"]
[Thu Jul 30 11:45:02.544093 2026] [security2:error] [pid 643573:tid 643828] [client 176.241.66.87:52870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_jvxWyxgRnoFKAJ_cnQAAAoo"]
[Thu Jul 30 11:45:02.544334 2026] [security2:error] [pid 643573:tid 643828] [client 176.241.66.87:52870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_jvxWyxgRnoFKAJ_cnQAAAoo"]
[Thu Jul 30 11:45:02.895668 2026] [security2:error] [pid 642360:tid 642607] [client 20.91.199.21:6969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amt_jpSUkh3e5AhEJOBdnAAAAgQ"]
[Thu Jul 30 11:45:03.226698 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:03.503055 2026] [security2:error] [pid 643573:tid 643720] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_jvxWyxgRnoFKAJ_cngAAAh4"]
[Thu Jul 30 11:45:03.811199 2026] [security2:error] [pid 642360:tid 642541] [client 20.215.191.139:64336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/core.php"] [unique_id "amt_j5SUkh3e5AhEJOBdpAAAAcI"]
[Thu Jul 30 11:45:04.023206 2026] [security2:error] [pid 643253:tid 643509] [client 2407:d000:1c:9d56:64c4:87bd:6970:5a53:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_j8jqbtjBYzqM1uYkNAAAfVo"]
[Thu Jul 30 11:45:04.271896 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.44.182:21955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/xmrlpc.php"] [unique_id "amt_kPxWyxgRnoFKAJ_cqwAAAkM"]
[Thu Jul 30 11:45:04.276476 2026] [core:notice] [pid 642360:tid 642527] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:05.154824 2026] [security2:error] [pid 643573:tid 643760] [client 20.91.199.21:14110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amt_kfxWyxgRnoFKAJ_csgAAAkY"]
[Thu Jul 30 11:45:06.260552 2026] [security2:error] [pid 643573:tid 643799] [client 20.91.199.21:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amt_kvxWyxgRnoFKAJ_cvAAAAm0"]
[Thu Jul 30 11:45:06.422117 2026] [security2:error] [pid 643573:tid 643637] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_kvxWyxgRnoFKAJ_cvQACdjg"]
[Thu Jul 30 11:45:06.422331 2026] [security2:error] [pid 643573:tid 643808] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_kvxWyxgRnoFKAJ_cvQACdjg"]
[Thu Jul 30 11:45:06.627767 2026] [security2:error] [pid 643573:tid 643730] [client 20.215.191.139:48340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/css.php"] [unique_id "amt_kvxWyxgRnoFKAJ_cwgAAAig"]
[Thu Jul 30 11:45:07.349538 2026] [security2:error] [pid 643573:tid 643835] [client 172.202.44.182:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ae.php"] [unique_id "amt_k_xWyxgRnoFKAJ_cxwAAApE"]
[Thu Jul 30 11:45:07.486430 2026] [security2:error] [pid 642360:tid 642437] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_k5SUkh3e5AhEJOBdzgABm0w"]
[Thu Jul 30 11:45:07.486631 2026] [security2:error] [pid 642360:tid 642502] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_k5SUkh3e5AhEJOBdzgABm0w"]
[Thu Jul 30 11:45:07.516681 2026] [security2:error] [pid 642360:tid 642490] [client 20.91.199.21:13925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amt_k5SUkh3e5AhEJOBdzwAAAY8"]
[Thu Jul 30 11:45:07.568741 2026] [security2:error] [pid 643573:tid 643771] [client 103.215.74.26:46190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amt_k_xWyxgRnoFKAJ_cxgAAAlE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:07.577638 2026] [security2:error] [pid 643573:tid 643789] [client 20.215.191.139:48353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/database.php"] [unique_id "amt_k_xWyxgRnoFKAJ_cyQAAAmM"]
[Thu Jul 30 11:45:07.763929 2026] [security2:error] [pid 643573:tid 643807] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt_k_xWyxgRnoFKAJ_cywAAAnU"]
[Thu Jul 30 11:45:08.105359 2026] [core:error] [pid 643573:tid 643657] [remote 216.73.216.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:45:08.105392 2026] [core:error] [pid 643573:tid 643657] [remote 216.73.216.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:45:08.230434 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:08.256684 2026] [security2:error] [pid 642360:tid 642547] [client 20.91.199.21:45539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amt_lJSUkh3e5AhEJOBd1wAAAcg"]
[Thu Jul 30 11:45:08.331683 2026] [security2:error] [pid 642360:tid 642496] [client 103.215.74.26:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/blog/wp-login.php"] [unique_id "amt_lJSUkh3e5AhEJOBd2AAAAZU"], referer: https://carnetdeshopping.com/blog/
[Thu Jul 30 11:45:08.593639 2026] [security2:error] [pid 643573:tid 643717] [client 172.202.44.182:21961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/moon.php"] [unique_id "amt_lPxWyxgRnoFKAJ_c2gAAAhs"]
[Thu Jul 30 11:45:08.610366 2026] [core:notice] [pid 642360:tid 642573] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:08.638386 2026] [security2:error] [pid 643573:tid 643824] [client 20.215.191.139:48370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/db.php"] [unique_id "amt_lPxWyxgRnoFKAJ_c2wAAAoY"]
[Thu Jul 30 11:45:08.715090 2026] [security2:error] [pid 643573:tid 643776] [client 20.104.18.253:30831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/011i.php"] [unique_id "amt_lPxWyxgRnoFKAJ_c3AAAAlY"]
[Thu Jul 30 11:45:09.096872 2026] [security2:error] [pid 643573:tid 643744] [client 103.215.74.26:46208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wordpress/wp-login.php"] [unique_id "amt_lfxWyxgRnoFKAJ_c4QAAAjY"], referer: https://carnetdeshopping.com/wordpress/
[Thu Jul 30 11:45:09.566399 2026] [security2:error] [pid 642360:tid 642609] [client 74.7.228.16:58582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.hoki188win.com"] [uri "/robots.txt"] [unique_id "amt_lZSUkh3e5AhEJOBd4AACBkc"]
[Thu Jul 30 11:45:09.851169 2026] [security2:error] [pid 642360:tid 642515] [client 103.215.74.26:46216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp/wp-login.php"] [unique_id "amt_lZSUkh3e5AhEJOBd5QAAAag"], referer: https://carnetdeshopping.com/wp/
[Thu Jul 30 11:45:09.863269 2026] [security2:error] [pid 643573:tid 643760] [client 20.104.18.253:23335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/03a005685d.php"] [unique_id "amt_lfxWyxgRnoFKAJ_c6gAAAkY"]
[Thu Jul 30 11:45:09.892372 2026] [security2:error] [pid 643573:tid 643756] [client 20.215.191.139:48361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/default.php"] [unique_id "amt_lfxWyxgRnoFKAJ_c6wAAAkI"]
[Thu Jul 30 11:45:10.605174 2026] [security2:error] [pid 642360:tid 642550] [client 103.215.74.26:46232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/cms/wp-login.php"] [unique_id "amt_lpSUkh3e5AhEJOBd6wAAAcs"], referer: https://carnetdeshopping.com/cms/
[Thu Jul 30 11:45:10.635257 2026] [security2:error] [pid 642360:tid 642525] [client 74.7.228.58:42028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pkfprogroup.com"] [uri "/cgi-sys/404.html"] [unique_id "amt_lpSUkh3e5AhEJOBd7QABsk8"]
[Thu Jul 30 11:45:10.715713 2026] [security2:error] [pid 642360:tid 642509] [client 20.215.191.139:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/dropdown.php"] [unique_id "amt_lpSUkh3e5AhEJOBd9AAAAaI"]
[Thu Jul 30 11:45:11.094059 2026] [security2:error] [pid 643253:tid 643498] [client 20.104.18.253:28411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/403.php"] [unique_id "amt_l8jqbtjBYzqM1uYkNQAAAHI"]
[Thu Jul 30 11:45:11.341753 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:46242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/site/wp-login.php"] [unique_id "amt_l8jqbtjBYzqM1uYkNwAAAHM"], referer: https://carnetdeshopping.com/site/
[Thu Jul 30 11:45:11.903317 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:11.939380 2026] [security2:error] [pid 643573:tid 643735] [client 20.104.18.253:22926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/404.php"] [unique_id "amt_l_xWyxgRnoFKAJ_c9AAAAi0"]
[Thu Jul 30 11:45:12.097214 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:46254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/main/wp-login.php"] [unique_id "amt_mJSUkh3e5AhEJOBeAwAAAdQ"], referer: https://carnetdeshopping.com/main/
[Thu Jul 30 11:45:12.473999 2026] [security2:error] [pid 643573:tid 643780] [client 20.91.199.21:3877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c-gAAAlo"]
[Thu Jul 30 11:45:12.666785 2026] [security2:error] [pid 643573:tid 643744] [client 172.237.109.114:33023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c9QAAAjY"]
[Thu Jul 30 11:45:12.701789 2026] [core:notice] [pid 642360:tid 642531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:12.743136 2026] [security2:error] [pid 643573:tid 643712] [client 172.237.109.114:14255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c9gAAAhY"]
[Thu Jul 30 11:45:12.762066 2026] [security2:error] [pid 643573:tid 643713] [client 172.237.109.114:26176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c9wAAAhc"]
[Thu Jul 30 11:45:12.769036 2026] [security2:error] [pid 642360:tid 642555] [client 172.237.109.114:21389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mJSUkh3e5AhEJOBeBAAAAdA"]
[Thu Jul 30 11:45:12.793885 2026] [security2:error] [pid 642360:tid 642563] [client 172.237.109.114:36712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_mJSUkh3e5AhEJOBeBQAAAdg"]
[Thu Jul 30 11:45:12.848531 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:46268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/new/wp-login.php"] [unique_id "amt_mJSUkh3e5AhEJOBeEQAAAds"], referer: https://carnetdeshopping.com/new/
[Thu Jul 30 11:45:12.890203 2026] [security2:error] [pid 643573:tid 643791] [client 172.202.44.182:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/blog.php"] [unique_id "amt_mPxWyxgRnoFKAJ_c_AAAAmU"]
[Thu Jul 30 11:45:13.003999 2026] [security2:error] [pid 642360:tid 642536] [client 176.241.66.87:65386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_mZSUkh3e5AhEJOBeEwAAAb0"]
[Thu Jul 30 11:45:13.004188 2026] [security2:error] [pid 642360:tid 642536] [client 176.241.66.87:65386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_mZSUkh3e5AhEJOBeEwAAAb0"]
[Thu Jul 30 11:45:13.418962 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:29848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amt_mfxWyxgRnoFKAJ_dAgAAAh4"], referer: http://carnetdeshopping.com/
[Thu Jul 30 11:45:13.542267 2026] [security2:error] [pid 643573:tid 643714] [client 20.104.18.253:55834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/aa.php"] [unique_id "amt_mfxWyxgRnoFKAJ_dBQAAAhg"]
[Thu Jul 30 11:45:13.892843 2026] [security2:error] [pid 643573:tid 643729] [client 103.215.74.26:29850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/blog/wp-login.php"] [unique_id "amt_mfxWyxgRnoFKAJ_dCwAAAic"], referer: http://carnetdeshopping.com/blog/
[Thu Jul 30 11:45:13.893012 2026] [security2:error] [pid 643573:tid 643779] [client 172.202.44.182:60993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ini.php"] [unique_id "amt_mfxWyxgRnoFKAJ_dDAAAAlk"]
[Thu Jul 30 11:45:14.382920 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:29856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wordpress/wp-login.php"] [unique_id "amt_mvxWyxgRnoFKAJ_dEQAAAow"], referer: http://carnetdeshopping.com/wordpress/
[Thu Jul 30 11:45:14.935468 2026] [security2:error] [pid 642360:tid 642602] [client 103.215.74.26:29858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp/wp-login.php"] [unique_id "amt_mpSUkh3e5AhEJOBeJgAAAf8"], referer: http://carnetdeshopping.com/wp/
[Thu Jul 30 11:45:15.380068 2026] [security2:error] [pid 643573:tid 643823] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_mvxWyxgRnoFKAJ_dFwAAAoU"]
[Thu Jul 30 11:45:15.426070 2026] [security2:error] [pid 642360:tid 642595] [client 103.215.74.26:29862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/cms/wp-login.php"] [unique_id "amt_m5SUkh3e5AhEJOBeLQAAAfg"], referer: http://carnetdeshopping.com/cms/
[Thu Jul 30 11:45:15.515402 2026] [security2:error] [pid 643573:tid 643743] [client 20.104.18.253:32005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/aafewc0k.php"] [unique_id "amt_m_xWyxgRnoFKAJ_dIAAAAjU"]
[Thu Jul 30 11:45:15.949379 2026] [security2:error] [pid 642360:tid 642516] [client 172.202.44.182:61002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/admin-ajax.php"] [unique_id "amt_m5SUkh3e5AhEJOBeMwAAAak"]
[Thu Jul 30 11:45:15.957731 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:29878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/site/wp-login.php"] [unique_id "amt_m_xWyxgRnoFKAJ_dJQAAAiE"], referer: http://carnetdeshopping.com/site/
[Thu Jul 30 11:45:16.271231 2026] [security2:error] [pid 643573:tid 643829] [client 20.104.18.253:28381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/abcd.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dKQAAAos"]
[Thu Jul 30 11:45:16.387324 2026] [security2:error] [pid 643253:tid 643464] [client 172.236.9.101:16888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amt_nMjqbtjBYzqM1uYkPwAAAFA"]
[Thu Jul 30 11:45:16.431594 2026] [security2:error] [pid 643253:tid 643391] [client 172.236.9.101:21719] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amt_nMjqbtjBYzqM1uYkQQAAAAc"]
[Thu Jul 30 11:45:16.469040 2026] [security2:error] [pid 642360:tid 642517] [client 103.215.74.26:29894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/main/wp-login.php"] [unique_id "amt_nJSUkh3e5AhEJOBePAAAAao"], referer: http://carnetdeshopping.com/main/
[Thu Jul 30 11:45:16.988243 2026] [security2:error] [pid 643253:tid 643394] [client 103.215.74.26:29900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/new/wp-login.php"] [unique_id "amt_nMjqbtjBYzqM1uYkQwAAAAo"], referer: http://carnetdeshopping.com/new/
[Thu Jul 30 11:45:17.061459 2026] [security2:error] [pid 643573:tid 643671] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_nfxWyxgRnoFKAJ_dNAACJFo"]
[Thu Jul 30 11:45:17.061664 2026] [security2:error] [pid 643573:tid 643726] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_nfxWyxgRnoFKAJ_dNAACJFo"]
[Thu Jul 30 11:45:17.215831 2026] [security2:error] [pid 643573:tid 643733] [client 172.236.9.101:20436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dKwAAAis"]
[Thu Jul 30 11:45:17.216914 2026] [security2:error] [pid 643573:tid 643792] [client 172.236.9.101:23086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dKgAAAmY"]
[Thu Jul 30 11:45:17.277180 2026] [security2:error] [pid 643253:tid 643431] [client 172.236.9.101:12495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkOwAAAC8"]
[Thu Jul 30 11:45:17.288784 2026] [security2:error] [pid 643253:tid 643406] [client 172.236.9.101:1660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkPAAAABY"]
[Thu Jul 30 11:45:17.319469 2026] [security2:error] [pid 643253:tid 643418] [client 172.236.9.101:38822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkPQAAACI"]
[Thu Jul 30 11:45:17.319498 2026] [security2:error] [pid 643253:tid 643462] [client 172.236.9.101:52197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkPgAAAE4"]
[Thu Jul 30 11:45:17.322704 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:33072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dLAAAAhw"]
[Thu Jul 30 11:45:17.333107 2026] [security2:error] [pid 643253:tid 643395] [client 172.236.9.101:34193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nMjqbtjBYzqM1uYkQAAAAAs"]
[Thu Jul 30 11:45:17.348213 2026] [security2:error] [pid 642360:tid 642579] [client 172.236.9.101:49846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nJSUkh3e5AhEJOBeOwAAAeg"]
[Thu Jul 30 11:45:17.350881 2026] [security2:error] [pid 643573:tid 643737] [client 172.236.9.101:33014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_nPxWyxgRnoFKAJ_dLQAAAi8"]
[Thu Jul 30 11:45:17.530953 2026] [security2:error] [pid 642360:tid 642527] [client 20.104.18.253:23354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/about.php"] [unique_id "amt_nZSUkh3e5AhEJOBeRAAAAbQ"]
[Thu Jul 30 11:45:17.710857 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:18.135892 2026] [security2:error] [pid 642360:tid 642600] [client 172.202.44.182:47293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/akc.php"] [unique_id "amt_npSUkh3e5AhEJOBeTgAAAf0"]
[Thu Jul 30 11:45:18.512656 2026] [security2:error] [pid 643573:tid 643644] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_nvxWyxgRnoFKAJ_dRQACcz8"]
[Thu Jul 30 11:45:18.512828 2026] [security2:error] [pid 643573:tid 643805] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_nvxWyxgRnoFKAJ_dRQACcz8"]
[Thu Jul 30 11:45:19.007708 2026] [security2:error] [pid 642360:tid 642566] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_npSUkh3e5AhEJOBeUQAAAds"]
[Thu Jul 30 11:45:19.400440 2026] [security2:error] [pid 642360:tid 642526] [client 172.202.44.182:61009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/akcc.php"] [unique_id "amt_n5SUkh3e5AhEJOBeXgAAAbM"]
[Thu Jul 30 11:45:19.508213 2026] [security2:error] [pid 643573:tid 643761] [client 20.104.18.253:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/admin.php"] [unique_id "amt_n_xWyxgRnoFKAJ_dTwAAAkc"]
[Thu Jul 30 11:45:19.826470 2026] [core:notice] [pid 643573:tid 643794] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:21.289154 2026] [security2:error] [pid 642360:tid 642574] [client 20.91.199.21:45690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/Requests/about.php"] [unique_id "amt_oZSUkh3e5AhEJOBedQAAAeM"]
[Thu Jul 30 11:45:21.648749 2026] [security2:error] [pid 642360:tid 642495] [client 20.104.18.253:43187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/adminfuns.php"] [unique_id "amt_oZSUkh3e5AhEJOBeegAAAZQ"]
[Thu Jul 30 11:45:21.687396 2026] [security2:error] [pid 642360:tid 642597] [client 74.7.175.171:37396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.gbv.gzj.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amt_oZSUkh3e5AhEJOBeewAAAfo"]
[Thu Jul 30 11:45:21.886587 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:22.343863 2026] [security2:error] [pid 643573:tid 643715] [client 20.215.191.139:48343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/edit.php"] [unique_id "amt_ovxWyxgRnoFKAJ_dZAAAAhk"]
[Thu Jul 30 11:45:22.403334 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:61296] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/WEB_VMS/LEVEL15/"] [unique_id "amt_ovxWyxgRnoFKAJ_dZQAAAmA"]
[Thu Jul 30 11:45:22.721053 2026] [core:notice] [pid 643253:tid 643444] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:23.179786 2026] [security2:error] [pid 643573:tid 643748] [client 20.104.18.253:35618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/albin.php"] [unique_id "amt_o_xWyxgRnoFKAJ_daQAAAjo"]
[Thu Jul 30 11:45:23.447496 2026] [security2:error] [pid 643573:tid 643828] [client 20.215.191.139:64352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/f35.php"] [unique_id "amt_o_xWyxgRnoFKAJ_dbAAAAoo"]
[Thu Jul 30 11:45:23.655610 2026] [security2:error] [pid 643573:tid 643745] [client 176.241.66.87:54315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_o_xWyxgRnoFKAJ_dbQAAAjc"]
[Thu Jul 30 11:45:23.655755 2026] [security2:error] [pid 643573:tid 643745] [client 176.241.66.87:54315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_o_xWyxgRnoFKAJ_dbQAAAjc"]
[Thu Jul 30 11:45:23.851153 2026] [security2:error] [pid 642360:tid 642570] [client 103.215.74.26:25470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amt_o5SUkh3e5AhEJOBeogAAAd8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:24.363650 2026] [security2:error] [pid 642360:tid 642569] [client 20.104.18.253:35634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/amfsqvgv.php"] [unique_id "amt_pJSUkh3e5AhEJOBeqgAAAd4"]
[Thu Jul 30 11:45:24.601057 2026] [core:notice] [pid 642360:tid 642511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:24.709119 2026] [security2:error] [pid 643573:tid 643770] [client 20.215.191.139:64377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/f7.php"] [unique_id "amt_pPxWyxgRnoFKAJ_dcQAAAlA"]
[Thu Jul 30 11:45:25.084173 2026] [security2:error] [pid 643573:tid 643806] [client 43.173.181.31:42124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/toulouse-2/"] [unique_id "amt_pPxWyxgRnoFKAJ_dcwAAAnQ"]
[Thu Jul 30 11:45:25.094070 2026] [security2:error] [pid 642360:tid 642538] [client 172.202.44.182:36718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/asasx.php"] [unique_id "amt_pZSUkh3e5AhEJOBetAAAAb8"]
[Thu Jul 30 11:45:25.147694 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.152465 2026] [security2:error] [pid 643573:tid 643754] [client 43.173.175.106:38848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amt_pPxWyxgRnoFKAJ_ddAAAAkA"]
[Thu Jul 30 11:45:25.160969 2026] [security2:error] [pid 642360:tid 642475] [remote 47.128.96.19:31020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/4514"] [unique_id "amt_pJSUkh3e5AhEJOBesQAB-HI"]
[Thu Jul 30 11:45:25.234262 2026] [core:notice] [pid 642360:tid 642459] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.239645 2026] [security2:error] [pid 642360:tid 642592] [client 47.128.96.19:31020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/4514"] [unique_id "amt_pZSUkh3e5AhEJOBetgAB9WI"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:45:25.402436 2026] [core:notice] [pid 642360:tid 642480] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.497241 2026] [core:notice] [pid 642360:tid 642482] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.561883 2026] [core:notice] [pid 642360:tid 642382] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.655074 2026] [security2:error] [pid 643573:tid 643809] [client 20.104.18.253:30360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/ant.php"] [unique_id "amt_pfxWyxgRnoFKAJ_dfgAAAnc"]
[Thu Jul 30 11:45:25.838215 2026] [core:notice] [pid 643573:tid 643735] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:25.843512 2026] [security2:error] [pid 643573:tid 643735] [client 43.173.175.113:56080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/toulouse-2/"] [unique_id "amt_pfxWyxgRnoFKAJ_dgwAAAi0"], referer: https://carnetdeshopping.com/index.php/tag/toulouse-2/
[Thu Jul 30 11:45:26.279891 2026] [core:error] [pid 643573:tid 643603] [remote 74.7.230.40:37448] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:45:26.279913 2026] [core:error] [pid 643573:tid 643603] [remote 74.7.230.40:37448] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:45:26.280118 2026] [security2:error] [pid 643573:tid 643746] [client 74.7.230.40:37448] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-a94f61be.jst.nyx.temporary.site"] [uri "/website_a94f61be/index.php"] [unique_id "amt_pvxWyxgRnoFKAJ_dhgACOBY"]
[Thu Jul 30 11:45:26.616451 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:26.809623 2026] [security2:error] [pid 643573:tid 643718] [client 20.104.18.253:36188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/appreciators.php"] [unique_id "amt_pvxWyxgRnoFKAJ_diQAAAhw"]
[Thu Jul 30 11:45:27.708722 2026] [security2:error] [pid 643573:tid 643617] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_p_xWyxgRnoFKAJ_dnAACTCQ"]
[Thu Jul 30 11:45:27.708897 2026] [security2:error] [pid 643573:tid 643766] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_p_xWyxgRnoFKAJ_dnAACTCQ"]
[Thu Jul 30 11:45:27.866015 2026] [core:error] [pid 642360:tid 642600] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:45:27.866039 2026] [core:error] [pid 642360:tid 642600] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:45:28.591639 2026] [security2:error] [pid 643573:tid 643721] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_p_xWyxgRnoFKAJ_doQAAAh8"]
[Thu Jul 30 11:45:28.665139 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:29.451564 2026] [security2:error] [pid 643573:tid 643597] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_qfxWyxgRnoFKAJ_dsAACRhA"]
[Thu Jul 30 11:45:29.451821 2026] [security2:error] [pid 643573:tid 643760] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_qfxWyxgRnoFKAJ_dsAACRhA"]
[Thu Jul 30 11:45:29.941549 2026] [security2:error] [pid 642360:tid 642534] [client 20.91.199.21:3305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amt_qZSUkh3e5AhEJOBe8AAAAbs"]
[Thu Jul 30 11:45:30.287319 2026] [security2:error] [pid 642360:tid 642566] [client 172.236.9.101:48771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe2wAAAds"]
[Thu Jul 30 11:45:30.290848 2026] [security2:error] [pid 642360:tid 642528] [client 172.236.9.101:62600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe1wAAAbU"]
[Thu Jul 30 11:45:30.310192 2026] [security2:error] [pid 642360:tid 642616] [client 172.236.9.101:49842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe4QAAAg0"]
[Thu Jul 30 11:45:30.343182 2026] [security2:error] [pid 642360:tid 642561] [client 172.236.9.101:46760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe3AAAAdY"]
[Thu Jul 30 11:45:30.347601 2026] [security2:error] [pid 642360:tid 642588] [client 172.236.9.101:60052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe2QAAAfE"]
[Thu Jul 30 11:45:30.370771 2026] [security2:error] [pid 643573:tid 643829] [client 172.236.9.101:7954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qPxWyxgRnoFKAJ_dpgAAAos"]
[Thu Jul 30 11:45:30.374153 2026] [security2:error] [pid 642360:tid 642564] [client 172.236.9.101:8635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe2gAAAdk"]
[Thu Jul 30 11:45:30.412275 2026] [security2:error] [pid 643253:tid 643479] [client 172.236.9.101:8686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qMjqbtjBYzqM1uYkSwAAAF8"]
[Thu Jul 30 11:45:30.415143 2026] [security2:error] [pid 643573:tid 643801] [client 172.236.9.101:27161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qPxWyxgRnoFKAJ_dpwAAAm8"]
[Thu Jul 30 11:45:30.437005 2026] [security2:error] [pid 642360:tid 642578] [client 172.236.9.101:27532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe2AAAAec"]
[Thu Jul 30 11:45:30.449797 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:27610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe3wAAAbY"]
[Thu Jul 30 11:45:30.457123 2026] [security2:error] [pid 642360:tid 642580] [client 172.236.9.101:13558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe4AAAAek"]
[Thu Jul 30 11:45:30.457248 2026] [security2:error] [pid 642360:tid 642596] [client 172.236.9.101:61840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe3QAAAfk"]
[Thu Jul 30 11:45:30.469424 2026] [security2:error] [pid 643253:tid 643481] [client 172.236.9.101:13132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qMjqbtjBYzqM1uYkSgAAAGE"]
[Thu Jul 30 11:45:30.472673 2026] [security2:error] [pid 642360:tid 642570] [client 172.236.9.101:53403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe3gAAAd8"]
[Thu Jul 30 11:45:30.482231 2026] [security2:error] [pid 643253:tid 643398] [client 172.236.9.101:46143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qMjqbtjBYzqM1uYkSAAAAA4"]
[Thu Jul 30 11:45:30.497082 2026] [security2:error] [pid 643573:tid 643735] [client 172.236.9.101:54903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qPxWyxgRnoFKAJ_dqAAAAi0"]
[Thu Jul 30 11:45:30.497089 2026] [security2:error] [pid 642360:tid 642594] [client 172.236.9.101:25754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe4gAAAfc"]
[Thu Jul 30 11:45:30.509693 2026] [security2:error] [pid 643253:tid 643396] [client 172.236.9.101:10760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qMjqbtjBYzqM1uYkSQAAAAw"]
[Thu Jul 30 11:45:30.545466 2026] [security2:error] [pid 642360:tid 642543] [client 172.236.9.101:42099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_qJSUkh3e5AhEJOBe4wAAAcQ"]
[Thu Jul 30 11:45:30.739091 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:30.757491 2026] [security2:error] [pid 642360:tid 642574] [client 20.91.199.21:45516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amt_qpSUkh3e5AhEJOBe-AAAAeM"]
[Thu Jul 30 11:45:31.406140 2026] [security2:error] [pid 643573:tid 643737] [client 74.7.175.167:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-137a15f9.brx.dtn.temporary.site"] [uri "/index.php"] [unique_id "amt_qfxWyxgRnoFKAJ_dtQAAAi8"]
[Thu Jul 30 11:45:31.406954 2026] [security2:error] [pid 643573:tid 643765] [client 74.7.175.167:38586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-137a15f9.brx.dtn.temporary.site"] [uri "/robots.txt"] [unique_id "amt_qfxWyxgRnoFKAJ_dswACSyU"]
[Thu Jul 30 11:45:31.665958 2026] [security2:error] [pid 643573:tid 643717] [client 20.104.18.253:30372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/archive.php"] [unique_id "amt_q_xWyxgRnoFKAJ_dvwAAAhs"]
[Thu Jul 30 11:45:32.433148 2026] [security2:error] [pid 643253:tid 643417] [client 20.104.18.253:50286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/as.php"] [unique_id "amt_rMjqbtjBYzqM1uYkVAAAACE"]
[Thu Jul 30 11:45:32.700926 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:32.877534 2026] [security2:error] [pid 643573:tid 643779] [client 131.226.102.36:43714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amt_rPxWyxgRnoFKAJ_dwgACWS4"]
[Thu Jul 30 11:45:32.965011 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.44.182:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/axx.php"] [unique_id "amt_rPxWyxgRnoFKAJ_dyQAAAlQ"]
[Thu Jul 30 11:45:33.376862 2026] [security2:error] [pid 643573:tid 643720] [client 104.28.90.40:17227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amt_rPxWyxgRnoFKAJ_dwQACHiA"]
[Thu Jul 30 11:45:33.459133 2026] [security2:error] [pid 643573:tid 643787] [client 74.7.241.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "guardian-heir.com"] [uri "/index.php"] [unique_id "amt_rfxWyxgRnoFKAJ_dzQACYWs"]
[Thu Jul 30 11:45:33.952300 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:22691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amt_rZSUkh3e5AhEJOBfGAAAAew"]
[Thu Jul 30 11:45:34.045480 2026] [security2:error] [pid 643573:tid 643819] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_rfxWyxgRnoFKAJ_d0AAAAoE"]
[Thu Jul 30 11:45:34.261013 2026] [security2:error] [pid 642360:tid 642532] [client 176.241.66.87:55291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_rpSUkh3e5AhEJOBfHwAAAbk"]
[Thu Jul 30 11:45:34.261144 2026] [security2:error] [pid 642360:tid 642532] [client 176.241.66.87:55291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_rpSUkh3e5AhEJOBfHwAAAbk"]
[Thu Jul 30 11:45:34.593283 2026] [security2:error] [pid 643573:tid 643777] [client 172.202.44.182:37704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/berax.php"] [unique_id "amt_rvxWyxgRnoFKAJ_d2wAAAlc"]
[Thu Jul 30 11:45:34.696517 2026] [core:notice] [pid 643573:tid 643785] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:34.787119 2026] [security2:error] [pid 643573:tid 643818] [client 20.104.18.253:36211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/atomlib.php"] [unique_id "amt_rvxWyxgRnoFKAJ_d4AAAAoA"]
[Thu Jul 30 11:45:35.807969 2026] [security2:error] [pid 642360:tid 642586] [client 172.236.9.101:49485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_r5SUkh3e5AhEJOBfKQAAAe8"]
[Thu Jul 30 11:45:35.809525 2026] [security2:error] [pid 642360:tid 642511] [client 172.236.9.101:53199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_r5SUkh3e5AhEJOBfKgAAAaQ"]
[Thu Jul 30 11:45:35.854992 2026] [security2:error] [pid 643253:tid 643507] [client 172.202.44.182:50257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/build.php"] [unique_id "amt_r8jqbtjBYzqM1uYkWAAAAHs"]
[Thu Jul 30 11:45:35.893567 2026] [security2:error] [pid 643253:tid 643443] [client 172.236.9.101:16320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_r8jqbtjBYzqM1uYkVgAAADs"]
[Thu Jul 30 11:45:36.140548 2026] [security2:error] [pid 642360:tid 642588] [client 20.91.199.21:22718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/banners/about.php"] [unique_id "amt_sJSUkh3e5AhEJOBfMgAAAfE"]
[Thu Jul 30 11:45:36.650601 2026] [core:notice] [pid 643573:tid 643783] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:36.912772 2026] [security2:error] [pid 643573:tid 643799] [client 20.91.199.21:12641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/about.php"] [unique_id "amt_sPxWyxgRnoFKAJ_eYAAAAm0"]
[Thu Jul 30 11:45:37.736382 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:3451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/.well-known/about.php"] [unique_id "amt_sfxWyxgRnoFKAJ_ebQAAAn8"]
[Thu Jul 30 11:45:37.834577 2026] [security2:error] [pid 643573:tid 643774] [client 172.236.9.101:6070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eZgAAAlQ"]
[Thu Jul 30 11:45:37.838048 2026] [security2:error] [pid 643573:tid 643803] [client 172.236.9.101:44978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eZQAAAnE"]
[Thu Jul 30 11:45:37.854572 2026] [security2:error] [pid 643573:tid 643728] [client 172.236.9.101:3344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eZwAAAiY"]
[Thu Jul 30 11:45:37.943385 2026] [security2:error] [pid 642360:tid 642539] [client 172.236.9.101:63667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sZSUkh3e5AhEJOBfPAAAAcA"]
[Thu Jul 30 11:45:37.943895 2026] [security2:error] [pid 643573:tid 643721] [client 172.236.9.101:31489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eaAAAAh8"]
[Thu Jul 30 11:45:37.949559 2026] [security2:error] [pid 642360:tid 642601] [client 172.236.9.101:15682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sZSUkh3e5AhEJOBfOwAAAf4"]
[Thu Jul 30 11:45:37.951516 2026] [security2:error] [pid 643573:tid 643776] [client 172.236.9.101:32055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eaQAAAlY"]
[Thu Jul 30 11:45:37.952081 2026] [security2:error] [pid 642360:tid 642493] [client 172.236.9.101:51658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sZSUkh3e5AhEJOBfPQAAAZI"]
[Thu Jul 30 11:45:38.004896 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:47041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_sfxWyxgRnoFKAJ_eagAAApE"]
[Thu Jul 30 11:45:38.387161 2026] [security2:error] [pid 643573:tid 643688] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_svxWyxgRnoFKAJ_edgACfGs"]
[Thu Jul 30 11:45:38.387404 2026] [security2:error] [pid 643573:tid 643814] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_svxWyxgRnoFKAJ_edgACfGs"]
[Thu Jul 30 11:45:38.392693 2026] [security2:error] [pid 642360:tid 642541] [client 20.104.18.253:28423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/autoload_classmap.php"] [unique_id "amt_spSUkh3e5AhEJOBfTAAAAcI"]
[Thu Jul 30 11:45:38.433057 2026] [security2:error] [pid 643253:tid 643470] [client 20.91.199.21:3402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/Text/about.php"] [unique_id "amt_ssjqbtjBYzqM1uYkWQAAAFY"]
[Thu Jul 30 11:45:38.656713 2026] [security2:error] [pid 643573:tid 643711] [client 119.73.97.132:31164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amt_svxWyxgRnoFKAJ_edQACFSA"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 11:45:38.672552 2026] [security2:error] [pid 643573:tid 643710] [client 172.202.44.182:36710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/buy.php"] [unique_id "amt_svxWyxgRnoFKAJ_eeQAAAhQ"]
[Thu Jul 30 11:45:38.759374 2026] [core:notice] [pid 642360:tid 642558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:38.836764 2026] [security2:error] [pid 642360:tid 642584] [client 172.236.9.101:58532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfRwAAAe0"]
[Thu Jul 30 11:45:38.836897 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:49244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_svxWyxgRnoFKAJ_edAAAAn4"]
[Thu Jul 30 11:45:38.843761 2026] [security2:error] [pid 642360:tid 642606] [client 172.236.9.101:10002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfSAAAAgM"]
[Thu Jul 30 11:45:38.848449 2026] [security2:error] [pid 643573:tid 643792] [client 172.236.9.101:32203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_svxWyxgRnoFKAJ_ecwAAAmY"]
[Thu Jul 30 11:45:38.866906 2026] [security2:error] [pid 642360:tid 642565] [client 172.236.9.101:8031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfRgAAAdo"]
[Thu Jul 30 11:45:38.875252 2026] [security2:error] [pid 642360:tid 642491] [client 172.236.9.101:31101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfSQAAAZA"]
[Thu Jul 30 11:45:38.893255 2026] [security2:error] [pid 642360:tid 642546] [client 172.236.9.101:9753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfSgAAAcc"]
[Thu Jul 30 11:45:38.893269 2026] [security2:error] [pid 642360:tid 642581] [client 172.236.9.101:51323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_spSUkh3e5AhEJOBfSwAAAeo"]
[Thu Jul 30 11:45:38.957431 2026] [proxy:error] [pid 643573:tid 643739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:45:38.957485 2026] [proxy_http:error] [pid 643573:tid 643739] [client 185.247.137.152:33131] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:45:38.958055 2026] [proxy:error] [pid 643573:tid 643739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:45:38.958099 2026] [proxy_http:error] [pid 643573:tid 643739] [client 185.247.137.152:33131] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:45:39.417470 2026] [security2:error] [pid 643573:tid 643781] [client 119.73.97.132:31164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amt_s_xWyxgRnoFKAJ_ehgACW24"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 11:45:40.022801 2026] [security2:error] [pid 643573:tid 643715] [client 172.202.44.182:37721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/checkbox.php"] [unique_id "amt_tPxWyxgRnoFKAJ_emAAAAhk"]
[Thu Jul 30 11:45:40.247090 2026] [security2:error] [pid 643573:tid 643720] [client 20.91.199.21:4873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/ID3/about.php"] [unique_id "amt_tPxWyxgRnoFKAJ_emQAAAh4"]
[Thu Jul 30 11:45:40.348510 2026] [security2:error] [pid 642360:tid 642401] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_tJSUkh3e5AhEJOBfZAAB0Cg"]
[Thu Jul 30 11:45:40.348664 2026] [security2:error] [pid 642360:tid 642555] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_tJSUkh3e5AhEJOBfZAAB0Cg"]
[Thu Jul 30 11:45:40.806170 2026] [security2:error] [pid 643573:tid 643730] [client 103.215.74.26:63446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php"] [unique_id "amt_tPxWyxgRnoFKAJ_erAAAAig"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:40.966531 2026] [security2:error] [pid 643573:tid 643742] [client 172.202.44.182:36696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/cong.php"] [unique_id "amt_tPxWyxgRnoFKAJ_erQAAAjQ"]
[Thu Jul 30 11:45:40.981942 2026] [security2:error] [pid 643573:tid 643710] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_tPxWyxgRnoFKAJ_eowAAAhQ"]
[Thu Jul 30 11:45:41.179383 2026] [security2:error] [pid 643573:tid 643803] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nfi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_s_xWyxgRnoFKAJ_elgAAAnE"]
[Thu Jul 30 11:45:41.179418 2026] [security2:error] [pid 643573:tid 643803] [client 74.7.230.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nfi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_s_xWyxgRnoFKAJ_elgAAAnE"]
[Thu Jul 30 11:45:41.180231 2026] [security2:error] [pid 643573:tid 643751] [client 74.7.230.1:44604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nfi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_s_xWyxgRnoFKAJ_elAACPXM"]
[Thu Jul 30 11:45:41.531262 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:41.843103 2026] [security2:error] [pid 642360:tid 642605] [client 20.104.18.253:52425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/bb.php"] [unique_id "amt_tZSUkh3e5AhEJOBfcwAAAgI"]
[Thu Jul 30 11:45:41.972373 2026] [security2:error] [pid 643573:tid 643776] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nfi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_tfxWyxgRnoFKAJ_euQAAAlY"], referer: https://www.nfi.nyx.temporary.site/robots.txt
[Thu Jul 30 11:45:41.973269 2026] [security2:error] [pid 643253:tid 643508] [client 74.7.230.1:44614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nfi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_tcjqbtjBYzqM1uYkYgAAfF8"], referer: https://www.nfi.nyx.temporary.site/robots.txt
[Thu Jul 30 11:45:42.315422 2026] [security2:error] [pid 642360:tid 642585] [client 20.91.199.21:3242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/img/about.php"] [unique_id "amt_tpSUkh3e5AhEJOBfdwAAAe4"]
[Thu Jul 30 11:45:42.470541 2026] [security2:error] [pid 642360:tid 642586] [client 172.202.44.182:56343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/file4.php"] [unique_id "amt_tpSUkh3e5AhEJOBfegAAAe8"]
[Thu Jul 30 11:45:42.491084 2026] [security2:error] [pid 643573:tid 643743] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_tfxWyxgRnoFKAJ_etQACNQo"]
[Thu Jul 30 11:45:42.851990 2026] [proxy:error] [pid 643573:tid 643773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:45:42.852096 2026] [proxy_http:error] [pid 643573:tid 643773] [client 74.7.175.131:33634] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:45:42.853425 2026] [proxy:error] [pid 643573:tid 643773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:45:42.853497 2026] [proxy_http:error] [pid 643573:tid 643773] [client 74.7.175.131:33634] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:45:42.853654 2026] [security2:error] [pid 643573:tid 643773] [client 74.7.175.131:33634] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.mxk.djb.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amt_tvxWyxgRnoFKAJ_fBwAAAlM"]
[Thu Jul 30 11:45:43.243211 2026] [security2:error] [pid 642360:tid 642521] [client 20.91.199.21:22322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/languages/about.php"] [unique_id "amt_t5SUkh3e5AhEJOBfgAAAAa4"]
[Thu Jul 30 11:45:43.455131 2026] [security2:error] [pid 643573:tid 643737] [client 20.104.18.253:49702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/bnm.php"] [unique_id "amt_t_xWyxgRnoFKAJ_fEAAAAi8"]
[Thu Jul 30 11:45:43.548444 2026] [security2:error] [pid 643573:tid 643830] [client 172.202.44.182:36695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/flower.php"] [unique_id "amt_t_xWyxgRnoFKAJ_fEQAAAow"]
[Thu Jul 30 11:45:43.599113 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:43.603652 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:48574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_t_xWyxgRnoFKAJ_fEgAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:43.663447 2026] [security2:error] [pid 642360:tid 642524] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_t5SUkh3e5AhEJOBffwAAAbE"]
[Thu Jul 30 11:45:44.354603 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:44.355512 2026] [security2:error] [pid 643573:tid 643802] [client 2407:d000:1c:9d56:64c4:87bd:6970:5a53:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_t_xWyxgRnoFKAJ_fGAACcB0"]
[Thu Jul 30 11:45:44.360355 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:48584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_uPxWyxgRnoFKAJ_fJQAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:44.630828 2026] [security2:error] [pid 643573:tid 643740] [client 20.91.199.21:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/customize/about.php"] [unique_id "amt_uPxWyxgRnoFKAJ_fJgAAAjI"]
[Thu Jul 30 11:45:44.645178 2026] [security2:error] [pid 643253:tid 643408] [client 172.237.109.114:23220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_uMjqbtjBYzqM1uYkZwAAABg"]
[Thu Jul 30 11:45:45.042130 2026] [security2:error] [pid 643573:tid 643718] [client 176.241.66.87:50654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fKgAAAhw"]
[Thu Jul 30 11:45:45.042253 2026] [security2:error] [pid 643573:tid 643718] [client 176.241.66.87:50654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fKgAAAhw"]
[Thu Jul 30 11:45:45.075787 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:45.079903 2026] [security2:error] [pid 643573:tid 643712] [client 103.215.74.26:48592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_ufxWyxgRnoFKAJ_fKwAAAhY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:45.106448 2026] [core:notice] [pid 643573:tid 643738] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:45.574456 2026] [security2:error] [pid 643573:tid 643827] [client 172.237.109.114:51751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fLAAAAok"]
[Thu Jul 30 11:45:45.596043 2026] [security2:error] [pid 643573:tid 643727] [client 172.237.109.114:1543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fLgAAAiU"]
[Thu Jul 30 11:45:45.680204 2026] [security2:error] [pid 642360:tid 642590] [client 20.104.18.253:28449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/bootstrap.php"] [unique_id "amt_uZSUkh3e5AhEJOBfjgAAAfM"]
[Thu Jul 30 11:45:45.695785 2026] [core:notice] [pid 643573:tid 643734] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:45.721568 2026] [security2:error] [pid 642360:tid 642516] [client 172.237.109.114:21390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_uZSUkh3e5AhEJOBfigAAAak"]
[Thu Jul 30 11:45:45.724624 2026] [security2:error] [pid 643573:tid 643710] [client 172.237.109.114:46395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_ufxWyxgRnoFKAJ_fLwAAAhQ"]
[Thu Jul 30 11:45:45.803931 2026] [core:notice] [pid 643573:tid 643770] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:45.808515 2026] [security2:error] [pid 643573:tid 643770] [client 103.215.74.26:48596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_ufxWyxgRnoFKAJ_fOgAAAlA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:46.020310 2026] [security2:error] [pid 643573:tid 643748] [client 85.208.96.198:52718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/28/tjpb-mantem-validade-de-ato-do-tce-que-julgou-irregular-contratacao-de-escritorio-de-advocacia/"] [unique_id "amt_uvxWyxgRnoFKAJ_fPQAAAjo"]
[Thu Jul 30 11:45:46.020434 2026] [security2:error] [pid 643573:tid 643748] [client 85.208.96.198:52718] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/28/tjpb-mantem-validade-de-ato-do-tce-que-julgou-irregular-contratacao-de-escritorio-de-advocacia/"] [unique_id "amt_uvxWyxgRnoFKAJ_fPQAAAjo"]
[Thu Jul 30 11:45:46.530611 2026] [core:notice] [pid 642360:tid 642491] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:46.534538 2026] [security2:error] [pid 642360:tid 642491] [client 103.215.74.26:48606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_upSUkh3e5AhEJOBflQAAAZA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:46.659479 2026] [security2:error] [pid 642360:tid 642581] [client 20.104.18.253:40996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/buy.php"] [unique_id "amt_upSUkh3e5AhEJOBflgAAAeo"]
[Thu Jul 30 11:45:47.247392 2026] [core:notice] [pid 643573:tid 643780] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:47.251375 2026] [security2:error] [pid 643573:tid 643780] [client 103.215.74.26:48622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_u_xWyxgRnoFKAJ_fSAAAAlo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:47.975065 2026] [security2:error] [pid 642360:tid 642615] [client 20.91.199.21:14133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amt_u5SUkh3e5AhEJOBfpQAAAgw"]
[Thu Jul 30 11:45:47.989956 2026] [autoindex:error] [pid 643573:tid 643807] [client 143.198.88.13:63581] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: www.website-f723eabb.ikn.mzi.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:48.028902 2026] [core:notice] [pid 642360:tid 642522] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:48.034048 2026] [security2:error] [pid 642360:tid 642522] [client 103.215.74.26:48624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_vJSUkh3e5AhEJOBfqAAAAa8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:48.055500 2026] [security2:error] [pid 643573:tid 643812] [client 20.104.18.253:43021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/chosen.php"] [unique_id "amt_vPxWyxgRnoFKAJ_fTwAAAno"]
[Thu Jul 30 11:45:48.616096 2026] [security2:error] [pid 643573:tid 643712] [client 172.202.44.182:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/form.php"] [unique_id "amt_vPxWyxgRnoFKAJ_fUwAAAhY"]
[Thu Jul 30 11:45:48.832843 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:48.837819 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:48634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_vMjqbtjBYzqM1uYkbgAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:49.009461 2026] [security2:error] [pid 643573:tid 643796] [client 20.104.18.253:38710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/class-wp-image.php"] [unique_id "amt_vfxWyxgRnoFKAJ_fVgAAAmo"]
[Thu Jul 30 11:45:49.042507 2026] [security2:error] [pid 643573:tid 643682] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_vfxWyxgRnoFKAJ_fWAACZmU"]
[Thu Jul 30 11:45:49.042663 2026] [security2:error] [pid 643573:tid 643792] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_vfxWyxgRnoFKAJ_fWAACZmU"]
[Thu Jul 30 11:45:49.127407 2026] [security2:error] [pid 642360:tid 642559] [client 193.47.62.167:37476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.besthomemovingcompanysharjah.boutique"] [uri "/index.php"] [unique_id "amt_upSUkh3e5AhEJOBfmAAAAdQ"]
[Thu Jul 30 11:45:49.149091 2026] [security2:error] [pid 643573:tid 643730] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_vPxWyxgRnoFKAJ_fUgAAAig"]
[Thu Jul 30 11:45:49.542270 2026] [security2:error] [pid 643573:tid 643804] [client 172.202.44.182:36687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/gecko.php"] [unique_id "amt_vfxWyxgRnoFKAJ_fWgAAAnI"]
[Thu Jul 30 11:45:49.548988 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:49.553161 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:48650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_vfxWyxgRnoFKAJ_fWwAAAow"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:49.761101 2026] [core:notice] [pid 643573:tid 643715] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:50.020689 2026] [security2:error] [pid 643573:tid 643748] [client 20.104.18.253:45575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/classsmtps.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fZAAAAjo"]
[Thu Jul 30 11:45:50.299996 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:50.308210 2026] [security2:error] [pid 643573:tid 643802] [client 103.215.74.26:48666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_vvxWyxgRnoFKAJ_fcwAAAnA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:50.519196 2026] [security2:error] [pid 643573:tid 643790] [client 20.91.199.21:16295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/widgets/about.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fdQAAAmQ"]
[Thu Jul 30 11:45:50.683738 2026] [security2:error] [pid 643253:tid 643419] [client 172.202.44.182:37724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/kyami.php"] [unique_id "amt_vsjqbtjBYzqM1uYkdQAAACM"]
[Thu Jul 30 11:45:50.687687 2026] [core:notice] [pid 643573:tid 643738] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:50.792652 2026] [security2:error] [pid 642360:tid 642572] [client 20.104.18.253:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/classwithtostring.php"] [unique_id "amt_vpSUkh3e5AhEJOBfwgAAAeE"]
[Thu Jul 30 11:45:51.056201 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:51.061156 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:48668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_v5SUkh3e5AhEJOBfxQAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:51.208281 2026] [security2:error] [pid 642360:tid 642487] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_v5SUkh3e5AhEJOBfxwABv34"]
[Thu Jul 30 11:45:51.208448 2026] [security2:error] [pid 642360:tid 642538] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_v5SUkh3e5AhEJOBfxwABv34"]
[Thu Jul 30 11:45:51.822784 2026] [core:notice] [pid 642360:tid 642592] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:51.827269 2026] [security2:error] [pid 642360:tid 642592] [client 103.215.74.26:48674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_v5SUkh3e5AhEJOBfzAAAAfU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:51.870904 2026] [security2:error] [pid 643573:tid 643730] [client 172.202.44.182:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/manager.php"] [unique_id "amt_v_xWyxgRnoFKAJ_fhAAAAig"]
[Thu Jul 30 11:45:51.879600 2026] [security2:error] [pid 643573:tid 643797] [client 127.0.0.1:35310] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amt_v_xWyxgRnoFKAJ_fgwAAAms"]
[Thu Jul 30 11:45:51.879620 2026] [security2:error] [pid 643573:tid 643830] [client 127.0.0.1:35302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amt_v_xWyxgRnoFKAJ_fgQAAAow"]
[Thu Jul 30 11:45:51.879661 2026] [security2:error] [pid 643573:tid 643723] [client 74.7.230.4:37624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.xff.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_v_xWyxgRnoFKAJ_fggACIWc"]
[Thu Jul 30 11:45:51.879777 2026] [security2:error] [pid 643573:tid 643778] [client 74.7.228.45:45062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.pse.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_v_xWyxgRnoFKAJ_fgAACWCE"]
[Thu Jul 30 11:45:52.031953 2026] [security2:error] [pid 643253:tid 643455] [client 20.91.199.21:15389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/IXR/about.php"] [unique_id "amt_wMjqbtjBYzqM1uYkdwAAAEc"]
[Thu Jul 30 11:45:52.256992 2026] [security2:error] [pid 643573:tid 643758] [client 172.236.9.101:12230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fZwAAAkQ"]
[Thu Jul 30 11:45:52.324666 2026] [security2:error] [pid 643573:tid 643736] [client 172.236.9.101:17717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_faAAAAi4"]
[Thu Jul 30 11:45:52.333171 2026] [security2:error] [pid 643573:tid 643811] [client 172.236.9.101:58083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fawAAAnk"]
[Thu Jul 30 11:45:52.336204 2026] [security2:error] [pid 643253:tid 643458] [client 172.236.9.101:5334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkcAAAAEo"]
[Thu Jul 30 11:45:52.342510 2026] [security2:error] [pid 643573:tid 643721] [client 172.236.9.101:31214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fagAAAh8"]
[Thu Jul 30 11:45:52.345804 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:30444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_faQAAAoY"]
[Thu Jul 30 11:45:52.356737 2026] [security2:error] [pid 642360:tid 642582] [client 172.236.9.101:33001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vpSUkh3e5AhEJOBfugAAAes"]
[Thu Jul 30 11:45:52.362075 2026] [security2:error] [pid 643573:tid 643735] [client 172.236.9.101:42601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fbAAAAi0"]
[Thu Jul 30 11:45:52.362965 2026] [security2:error] [pid 643253:tid 643441] [client 172.236.9.101:44579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkcQAAADk"]
[Thu Jul 30 11:45:52.385334 2026] [security2:error] [pid 643573:tid 643791] [client 172.236.9.101:28536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fbQAAAmU"]
[Thu Jul 30 11:45:52.402495 2026] [security2:error] [pid 642360:tid 642534] [client 172.236.9.101:37129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vpSUkh3e5AhEJOBfuQAAAbs"]
[Thu Jul 30 11:45:52.412755 2026] [security2:error] [pid 643253:tid 643464] [client 172.236.9.101:4281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkdAAAAFA"]
[Thu Jul 30 11:45:52.413992 2026] [security2:error] [pid 642360:tid 642528] [client 172.236.9.101:31317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vpSUkh3e5AhEJOBfuwAAAbU"]
[Thu Jul 30 11:45:52.422548 2026] [security2:error] [pid 643253:tid 643430] [client 172.236.9.101:60662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkcgAAAC4"]
[Thu Jul 30 11:45:52.438873 2026] [security2:error] [pid 643573:tid 643772] [client 172.236.9.101:1634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fbwAAAlI"]
[Thu Jul 30 11:45:52.444059 2026] [security2:error] [pid 643253:tid 643422] [client 172.236.9.101:55461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vsjqbtjBYzqM1uYkcwAAACY"]
[Thu Jul 30 11:45:52.444944 2026] [security2:error] [pid 643573:tid 643743] [client 172.236.9.101:54571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fcQAAAjU"]
[Thu Jul 30 11:45:52.448042 2026] [security2:error] [pid 643573:tid 643725] [client 172.236.9.101:52075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fcAAAAiM"]
[Thu Jul 30 11:45:52.462500 2026] [security2:error] [pid 643573:tid 643788] [client 172.236.9.101:56135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fbgAAAmI"]
[Thu Jul 30 11:45:52.480355 2026] [security2:error] [pid 643573:tid 643739] [client 172.236.9.101:33105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_vvxWyxgRnoFKAJ_fcgAAAjE"]
[Thu Jul 30 11:45:52.554768 2026] [core:notice] [pid 643573:tid 643724] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:52.559147 2026] [security2:error] [pid 643573:tid 643724] [client 103.215.74.26:48688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_wPxWyxgRnoFKAJ_fjAAAAiI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:52.856451 2026] [security2:error] [pid 643573:tid 643740] [client 172.202.44.182:37718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/mari.php"] [unique_id "amt_wPxWyxgRnoFKAJ_flAAAAjI"]
[Thu Jul 30 11:45:53.145998 2026] [security2:error] [pid 643573:tid 643710] [client 20.104.18.253:28420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/config.php"] [unique_id "amt_wfxWyxgRnoFKAJ_flwAAAhQ"]
[Thu Jul 30 11:45:53.249391 2026] [security2:error] [pid 642360:tid 642574] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_wJSUkh3e5AhEJOBf0QAAAeM"]
[Thu Jul 30 11:45:53.287672 2026] [core:notice] [pid 643573:tid 643796] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:53.293130 2026] [security2:error] [pid 643573:tid 643796] [client 103.215.74.26:17556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_wfxWyxgRnoFKAJ_fmQAAAmo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:53.884105 2026] [security2:error] [pid 643573:tid 643801] [client 20.91.199.21:12666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/js/about.php"] [unique_id "amt_wfxWyxgRnoFKAJ_fpAAAAm8"]
[Thu Jul 30 11:45:54.021007 2026] [core:notice] [pid 643573:tid 643805] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:54.025384 2026] [security2:error] [pid 643573:tid 643805] [client 103.215.74.26:17558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_wvxWyxgRnoFKAJ_fpQAAAnM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:54.683700 2026] [security2:error] [pid 643573:tid 643836] [client 20.91.199.21:4888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amt_wvxWyxgRnoFKAJ_frwAAApI"]
[Thu Jul 30 11:45:55.132809 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.18.253:43060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/core.php"] [unique_id "amt_w_xWyxgRnoFKAJ_ftAAAAjI"]
[Thu Jul 30 11:45:55.504140 2026] [security2:error] [pid 643573:tid 643775] [client 176.241.66.87:57592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_w_xWyxgRnoFKAJ_ftgAAAlU"]
[Thu Jul 30 11:45:55.504315 2026] [security2:error] [pid 643573:tid 643775] [client 176.241.66.87:57592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_w_xWyxgRnoFKAJ_ftgAAAlU"]
[Thu Jul 30 11:45:56.245065 2026] [security2:error] [pid 643573:tid 643779] [client 20.91.199.21:45633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/pomo/about.php"] [unique_id "amt_xPxWyxgRnoFKAJ_fvgAAAlk"]
[Thu Jul 30 11:45:56.408534 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.44.182:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/nc4.php"] [unique_id "amt_xPxWyxgRnoFKAJ_fvwAAAkM"]
[Thu Jul 30 11:45:57.444955 2026] [security2:error] [pid 642360:tid 642553] [client 143.198.88.13:57171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-fbcbfb4b.brx.dtn.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amt_xZSUkh3e5AhEJOBf8wAAAc4"], referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:57.656515 2026] [core:error] [pid 643573:tid 643730] [client 143.198.88.13:50012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:57.656541 2026] [core:error] [pid 643573:tid 643730] [client 143.198.88.13:50012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:57.968911 2026] [security2:error] [pid 643573:tid 643686] [remote 57.141.0.43:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amt_xfxWyxgRnoFKAJ_fzwACJGk"]
[Thu Jul 30 11:45:58.298617 2026] [security2:error] [pid 643573:tid 643820] [client 20.104.18.253:49724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/css.php"] [unique_id "amt_xvxWyxgRnoFKAJ_f0gAAAoI"]
[Thu Jul 30 11:45:58.415951 2026] [security2:error] [pid 643573:tid 643740] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_xfxWyxgRnoFKAJ_fzgAAAjI"]
[Thu Jul 30 11:45:58.703670 2026] [security2:error] [pid 643573:tid 643833] [client 154.57.218.68:44579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amt_xvxWyxgRnoFKAJ_f1AACjyc"], referer: https://trello.com/
[Thu Jul 30 11:45:58.775318 2026] [security2:error] [pid 643573:tid 643771] [client 172.236.9.101:26680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_xvxWyxgRnoFKAJ_f0QAAAlE"]
[Thu Jul 30 11:45:58.917395 2026] [core:error] [pid 643573:tid 643779] [client 143.198.88.13:51607] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:58.917422 2026] [core:error] [pid 643573:tid 643779] [client 143.198.88.13:51607] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:45:58.972445 2026] [cgid:error] [pid 643573:tid 643725] [client 172.202.44.182:57010] AH01264: stderr from /home1/khwnyxte/alshateeintl.com/cgi-bin: script not found or unable to stat
[Thu Jul 30 11:45:59.620737 2026] [security2:error] [pid 643573:tid 643752] [client 20.91.199.21:14130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f5QAAAj4"]
[Thu Jul 30 11:45:59.630307 2026] [security2:error] [pid 643573:tid 643747] [client 20.104.18.253:39353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/database.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f5gAAAjk"]
[Thu Jul 30 11:45:59.745522 2026] [security2:error] [pid 642360:tid 642361] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_x5SUkh3e5AhEJOBgBwAB2wA"]
[Thu Jul 30 11:45:59.745753 2026] [security2:error] [pid 642360:tid 642566] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_x5SUkh3e5AhEJOBgBwAB2wA"]
[Thu Jul 30 11:45:59.758694 2026] [security2:error] [pid 643573:tid 643791] [client 172.236.9.101:5531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f3gAAAmU"]
[Thu Jul 30 11:45:59.766685 2026] [core:notice] [pid 643253:tid 643416] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:45:59.771961 2026] [security2:error] [pid 643253:tid 643416] [client 103.215.74.26:17568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_x8jqbtjBYzqM1uYkfQAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:45:59.778400 2026] [security2:error] [pid 642360:tid 642505] [client 172.236.9.101:39152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x5SUkh3e5AhEJOBgBAAAAZ4"]
[Thu Jul 30 11:45:59.882891 2026] [security2:error] [pid 642360:tid 642519] [client 172.236.9.101:60195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x5SUkh3e5AhEJOBgBQAAAaw"]
[Thu Jul 30 11:45:59.892029 2026] [security2:error] [pid 643253:tid 643429] [client 172.236.9.101:58317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x8jqbtjBYzqM1uYkfAAAAC0"]
[Thu Jul 30 11:45:59.916361 2026] [security2:error] [pid 643573:tid 643825] [client 172.236.9.101:19926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f3wAAAoc"]
[Thu Jul 30 11:46:00.213694 2026] [core:error] [pid 643573:tid 643770] [client 143.198.88.13:49520] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:46:00.213719 2026] [core:error] [pid 643573:tid 643770] [client 143.198.88.13:49520] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:46:00.491757 2026] [core:error] [pid 643253:tid 643389] [client 143.198.88.13:50407] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:46:00.491788 2026] [core:error] [pid 643253:tid 643389] [client 143.198.88.13:50407] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: www.website-e2d5057b.ogv.ajs.mybluehost.me/blog//wp-login.php
[Thu Jul 30 11:46:00.492820 2026] [core:notice] [pid 643573:tid 643728] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:00.506236 2026] [security2:error] [pid 643573:tid 643728] [client 103.215.74.26:17576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_yPxWyxgRnoFKAJ_f-AAAAiY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:00.553755 2026] [core:error] [pid 642360:tid 642390] [remote 74.7.241.162:53854] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:00.553785 2026] [core:error] [pid 642360:tid 642390] [remote 74.7.241.162:53854] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:00.554202 2026] [security2:error] [pid 642360:tid 642578] [client 74.7.241.162:53854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.bisbeetour.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgEwAB5x0"]
[Thu Jul 30 11:46:01.236609 2026] [core:notice] [pid 643573:tid 643724] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:01.245919 2026] [security2:error] [pid 643573:tid 643724] [client 103.215.74.26:17584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_yfxWyxgRnoFKAJ_f_gAAAiI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:01.293794 2026] [security2:error] [pid 643573:tid 643746] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_x_xWyxgRnoFKAJ_f4QACOHI"]
[Thu Jul 30 11:46:01.465951 2026] [security2:error] [pid 642360:tid 642586] [client 172.236.9.101:45933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgDAAAAe8"]
[Thu Jul 30 11:46:01.471845 2026] [security2:error] [pid 643573:tid 643784] [client 172.236.9.101:10914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f8QAAAl4"]
[Thu Jul 30 11:46:01.537407 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:23726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f7QAAAn4"]
[Thu Jul 30 11:46:01.571352 2026] [security2:error] [pid 643573:tid 643774] [client 172.236.9.101:10514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f7gAAAlQ"]
[Thu Jul 30 11:46:01.631561 2026] [security2:error] [pid 642360:tid 642594] [client 172.236.9.101:43278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgEQAAAfc"]
[Thu Jul 30 11:46:01.632625 2026] [security2:error] [pid 643573:tid 643715] [client 172.236.9.101:21590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f8gAAAhk"]
[Thu Jul 30 11:46:01.633939 2026] [security2:error] [pid 643573:tid 643766] [client 172.236.9.101:5249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f9AAAAkw"]
[Thu Jul 30 11:46:01.649437 2026] [security2:error] [pid 642360:tid 642552] [client 172.236.9.101:55274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgEgAAAc0"]
[Thu Jul 30 11:46:01.649647 2026] [security2:error] [pid 642360:tid 642572] [client 172.236.9.101:65444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgDQAAAeE"]
[Thu Jul 30 11:46:01.652685 2026] [security2:error] [pid 643573:tid 643726] [client 172.236.9.101:23677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f8AAAAiQ"]
[Thu Jul 30 11:46:01.653220 2026] [security2:error] [pid 642360:tid 642513] [client 172.236.9.101:54409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgDwAAAaY"]
[Thu Jul 30 11:46:01.663308 2026] [security2:error] [pid 643573:tid 643831] [client 172.236.9.101:2829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yPxWyxgRnoFKAJ_f8wAAAo0"]
[Thu Jul 30 11:46:01.670739 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:27792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yJSUkh3e5AhEJOBgEAAAAbY"]
[Thu Jul 30 11:46:01.675305 2026] [security2:error] [pid 643253:tid 643438] [client 172.236.9.101:15319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_yMjqbtjBYzqM1uYkfgAAADY"]
[Thu Jul 30 11:46:01.981310 2026] [core:notice] [pid 643253:tid 643439] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:01.986264 2026] [security2:error] [pid 643253:tid 643439] [client 103.215.74.26:17592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_ycjqbtjBYzqM1uYkggAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:02.152956 2026] [security2:error] [pid 643573:tid 643697] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_yvxWyxgRnoFKAJ_gBQACYXQ"]
[Thu Jul 30 11:46:02.153165 2026] [security2:error] [pid 643573:tid 643787] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_yvxWyxgRnoFKAJ_gBQACYXQ"]
[Thu Jul 30 11:46:02.319076 2026] [security2:error] [pid 643573:tid 643825] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_yfxWyxgRnoFKAJ_gAgAAAoc"]
[Thu Jul 30 11:46:02.656386 2026] [security2:error] [pid 643573:tid 643736] [client 62.102.148.185:42078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amt_yvxWyxgRnoFKAJ_gBgAAAi4"]
[Thu Jul 30 11:46:02.656574 2026] [security2:error] [pid 643573:tid 643736] [client 62.102.148.185:42078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amt_yvxWyxgRnoFKAJ_gBgAAAi4"]
[Thu Jul 30 11:46:02.730263 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:02.735645 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:17600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_ypSUkh3e5AhEJOBgMAAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:02.820014 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:02.938424 2026] [security2:error] [pid 642360:tid 642426] [remote 74.7.241.60:43616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amt_ypSUkh3e5AhEJOBgMgABkUE"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:46:03.048534 2026] [security2:error] [pid 643573:tid 643815] [client 20.104.18.253:43048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/db.php"] [unique_id "amt_y_xWyxgRnoFKAJ_gDgAAAn0"]
[Thu Jul 30 11:46:03.286571 2026] [security2:error] [pid 643573:tid 643708] [remote 57.141.0.12:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/24984966950/feed/rss2/"] [unique_id "amt_y_xWyxgRnoFKAJ_gEAACc38"]
[Thu Jul 30 11:46:03.301142 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:03.405793 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:03.520160 2026] [core:notice] [pid 643253:tid 643425] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:03.524417 2026] [security2:error] [pid 643253:tid 643425] [client 103.215.74.26:26990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_y8jqbtjBYzqM1uYkhAAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:05.012557 2026] [security2:error] [pid 642360:tid 642526] [client 20.104.18.253:43063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/default.php"] [unique_id "amt_zZSUkh3e5AhEJOBgQAAAAbM"]
[Thu Jul 30 11:46:06.109874 2026] [security2:error] [pid 643573:tid 643784] [client 114.119.134.220:48965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thdinfinity.com"] [uri "/healthcareg/physical-therapy-assistant-schools-alabama"] [unique_id "amt_zvxWyxgRnoFKAJ_gMQAAAl4"], referer: https://thdinfinity.com/healthcareg/physical-therapy-assistant-schools-alabama
[Thu Jul 30 11:46:06.170004 2026] [security2:error] [pid 642360:tid 642607] [client 176.241.66.87:58783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_zpSUkh3e5AhEJOBgTwAAAgQ"]
[Thu Jul 30 11:46:06.170131 2026] [security2:error] [pid 642360:tid 642607] [client 176.241.66.87:58783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_zpSUkh3e5AhEJOBgTwAAAgQ"]
[Thu Jul 30 11:46:06.782369 2026] [security2:error] [pid 643573:tid 643734] [client 172.236.9.101:6740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gMwAAAiw"]
[Thu Jul 30 11:46:06.782970 2026] [security2:error] [pid 643573:tid 643808] [client 172.236.9.101:27373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gMgAAAnY"]
[Thu Jul 30 11:46:06.840075 2026] [security2:error] [pid 643573:tid 643809] [client 172.236.9.101:61376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gNAAAAnc"]
[Thu Jul 30 11:46:06.851139 2026] [security2:error] [pid 642360:tid 642609] [client 172.236.9.101:24208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zpSUkh3e5AhEJOBgUAAAAgY"]
[Thu Jul 30 11:46:06.896359 2026] [security2:error] [pid 643573:tid 643813] [client 172.236.9.101:3108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gNQAAAns"]
[Thu Jul 30 11:46:06.984943 2026] [security2:error] [pid 643573:tid 643780] [client 143.198.88.13:57337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-ff6a65b0.vdb.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amt_zvxWyxgRnoFKAJ_gPAAAAlo"], referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.226877 2026] [core:error] [pid 643573:tid 643833] [client 143.198.88.13:55708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.226901 2026] [core:error] [pid 643573:tid 643833] [client 143.198.88.13:55708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.462741 2026] [core:error] [pid 643253:tid 643452] [client 143.198.88.13:55636] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.462774 2026] [core:error] [pid 643253:tid 643452] [client 143.198.88.13:55636] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.673026 2026] [core:error] [pid 642360:tid 642582] [client 143.198.88.13:58778] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.673059 2026] [core:error] [pid 642360:tid 642582] [client 143.198.88.13:58778] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.913559 2026] [core:error] [pid 642360:tid 642499] [client 143.198.88.13:53319] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:07.913582 2026] [core:error] [pid 642360:tid 642499] [client 143.198.88.13:53319] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://china2026.icsa.org//blog//wp-login.php
[Thu Jul 30 11:46:08.778076 2026] [security2:error] [pid 643573:tid 643592] [remote 97.74.93.24:37518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gWQACfgs"]
[Thu Jul 30 11:46:09.179032 2026] [security2:error] [pid 643573:tid 643778] [client 74.7.244.62:35990] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.dqy.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amt_0fxWyxgRnoFKAJ_gWgAAAlg"]
[Thu Jul 30 11:46:09.236949 2026] [core:notice] [pid 643573:tid 643729] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:09.243539 2026] [security2:error] [pid 643573:tid 643729] [client 103.215.74.26:27002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_0fxWyxgRnoFKAJ_gXQAAAic"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:09.403337 2026] [security2:error] [pid 643573:tid 643795] [client 20.91.199.21:4926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/updraft/about.php"] [unique_id "amt_0fxWyxgRnoFKAJ_gXgAAAmk"]
[Thu Jul 30 11:46:09.424881 2026] [security2:error] [pid 643573:tid 643724] [client 172.236.9.101:28006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gSgAAAiI"]
[Thu Jul 30 11:46:09.453724 2026] [security2:error] [pid 642360:tid 642539] [client 172.236.9.101:10316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgaAAAAcA"]
[Thu Jul 30 11:46:09.464639 2026] [security2:error] [pid 642360:tid 642509] [client 172.236.9.101:1271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgaQAAAaI"]
[Thu Jul 30 11:46:09.466861 2026] [security2:error] [pid 642360:tid 642504] [client 172.236.9.101:33625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgagAAAZ0"]
[Thu Jul 30 11:46:09.514622 2026] [security2:error] [pid 643573:tid 643734] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "heir-holdings.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amt_0fxWyxgRnoFKAJ_gYQAAAiw"]
[Thu Jul 30 11:46:09.540566 2026] [security2:error] [pid 642360:tid 642541] [client 172.236.9.101:15089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgawAAAcI"]
[Thu Jul 30 11:46:09.571427 2026] [security2:error] [pid 642360:tid 642597] [client 172.236.9.101:35040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgbAAAAfo"]
[Thu Jul 30 11:46:09.577588 2026] [security2:error] [pid 642360:tid 642614] [client 172.236.9.101:55630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgbQAAAgs"]
[Thu Jul 30 11:46:09.580625 2026] [security2:error] [pid 643573:tid 643732] [client 172.236.9.101:1137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gSwAAAio"]
[Thu Jul 30 11:46:09.589297 2026] [security2:error] [pid 643573:tid 643719] [client 172.236.9.101:7621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gTQAAAh0"]
[Thu Jul 30 11:46:09.593356 2026] [security2:error] [pid 642360:tid 642495] [client 172.236.9.101:20263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgbgAAAZQ"]
[Thu Jul 30 11:46:09.596524 2026] [security2:error] [pid 643573:tid 643746] [client 172.236.9.101:12307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gTwAAAjg"]
[Thu Jul 30 11:46:09.598305 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:31773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gTAAAAk8"]
[Thu Jul 30 11:46:09.598718 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:7639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgbwAAAdM"]
[Thu Jul 30 11:46:09.605699 2026] [security2:error] [pid 643573:tid 643818] [client 172.236.9.101:24716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0PxWyxgRnoFKAJ_gTgAAAoA"]
[Thu Jul 30 11:46:09.618550 2026] [security2:error] [pid 643253:tid 643479] [client 172.236.9.101:39271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_0MjqbtjBYzqM1uYkigAAAF8"]
[Thu Jul 30 11:46:09.984838 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:09.989047 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:27016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_0cjqbtjBYzqM1uYkjgAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:10.426601 2026] [security2:error] [pid 643253:tid 643353] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_0sjqbtjBYzqM1uYkkQAAe2I"]
[Thu Jul 30 11:46:10.426762 2026] [security2:error] [pid 643253:tid 643507] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_0sjqbtjBYzqM1uYkkQAAe2I"]
[Thu Jul 30 11:46:10.754903 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:10.759108 2026] [security2:error] [pid 642360:tid 642571] [client 103.215.74.26:27018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_0pSUkh3e5AhEJOBgjgAAAeA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:10.862808 2026] [security2:error] [pid 642360:tid 642611] [client 20.104.18.253:39354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/dropdown.php"] [unique_id "amt_0pSUkh3e5AhEJOBgkAAAAgg"]
[Thu Jul 30 11:46:11.216136 2026] [security2:error] [pid 643573:tid 643725] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_0vxWyxgRnoFKAJ_gaQAAAiM"]
[Thu Jul 30 11:46:11.365811 2026] [security2:error] [pid 642360:tid 642493] [client 66.249.73.98:37889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amt_0JSUkh3e5AhEJOBgcAAAAZI"]
[Thu Jul 30 11:46:11.420398 2026] [security2:error] [pid 642360:tid 642600] [client 20.91.199.21:15405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amt_05SUkh3e5AhEJOBglwAAAf0"]
[Thu Jul 30 11:46:11.498570 2026] [core:notice] [pid 643573:tid 643727] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:11.506358 2026] [security2:error] [pid 643573:tid 643727] [client 103.215.74.26:27022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_0_xWyxgRnoFKAJ_gewAAAiU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:11.605009 2026] [security2:error] [pid 642360:tid 642505] [client 74.7.230.43:33494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.google-search.org.meg.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amt_05SUkh3e5AhEJOBgmAABnlo"]
[Thu Jul 30 11:46:11.851841 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:11.900106 2026] [security2:error] [pid 643573:tid 643834] [client 20.104.18.253:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/edit.php"] [unique_id "amt_0_xWyxgRnoFKAJ_ggQAAApA"]
[Thu Jul 30 11:46:11.988764 2026] [security2:error] [pid 643573:tid 643732] [client 20.91.199.21:3252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/themes/about.php"] [unique_id "amt_0_xWyxgRnoFKAJ_gggAAAio"]
[Thu Jul 30 11:46:12.240925 2026] [core:notice] [pid 643573:tid 643728] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:12.247583 2026] [security2:error] [pid 643573:tid 643728] [client 103.215.74.26:27036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_1PxWyxgRnoFKAJ_ggwAAAiY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:12.791500 2026] [security2:error] [pid 643573:tid 643625] [remote 92.222.104.212:21940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kayomanis.com"] [uri "/menu-grid/"] [unique_id "amt_1PxWyxgRnoFKAJ_gkQACciw"]
[Thu Jul 30 11:46:12.791714 2026] [security2:error] [pid 643573:tid 643804] [client 92.222.104.212:21940] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kayomanis.com"] [uri "/menu-grid/"] [unique_id "amt_1PxWyxgRnoFKAJ_gkQACciw"]
[Thu Jul 30 11:46:12.801050 2026] [security2:error] [pid 642360:tid 642596] [client 172.236.9.101:3074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1JSUkh3e5AhEJOBgoQAAAfk"]
[Thu Jul 30 11:46:12.812782 2026] [security2:error] [pid 643573:tid 643748] [client 172.236.9.101:11116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_ghQAAAjo"]
[Thu Jul 30 11:46:12.844209 2026] [security2:error] [pid 643573:tid 643762] [client 172.236.9.101:11941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_ghAAAAkg"]
[Thu Jul 30 11:46:12.898469 2026] [security2:error] [pid 643573:tid 643800] [client 172.236.9.101:18775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_ghgAAAm4"]
[Thu Jul 30 11:46:12.918175 2026] [security2:error] [pid 643573:tid 643832] [client 172.236.9.101:51255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_ghwAAAo4"]
[Thu Jul 30 11:46:12.929238 2026] [security2:error] [pid 643573:tid 643801] [client 172.236.9.101:55321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1PxWyxgRnoFKAJ_giAAAAm8"]
[Thu Jul 30 11:46:12.966223 2026] [security2:error] [pid 643573:tid 643634] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_1PxWyxgRnoFKAJ_glAACgTU"]
[Thu Jul 30 11:46:12.966386 2026] [security2:error] [pid 643573:tid 643819] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_1PxWyxgRnoFKAJ_glAACgTU"]
[Thu Jul 30 11:46:12.972618 2026] [core:notice] [pid 643573:tid 643765] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:12.976773 2026] [security2:error] [pid 643573:tid 643765] [client 103.215.74.26:27038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_1PxWyxgRnoFKAJ_glQAAAks"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:12.986471 2026] [security2:error] [pid 643253:tid 643409] [client 20.104.18.253:30912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/f35.php"] [unique_id "amt_1MjqbtjBYzqM1uYklgAAABk"]
[Thu Jul 30 11:46:13.443006 2026] [security2:error] [pid 643573:tid 643812] [client 20.91.199.21:4865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/includes/about.php"] [unique_id "amt_1fxWyxgRnoFKAJ_gmwAAAno"]
[Thu Jul 30 11:46:13.778590 2026] [security2:error] [pid 643253:tid 643468] [client 20.104.18.253:61987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.laduchessecollections.com"] [uri "/f7.php"] [unique_id "amt_1cjqbtjBYzqM1uYkmgAAAFQ"]
[Thu Jul 30 11:46:13.778753 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:59342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1fxWyxgRnoFKAJ_gmQAAAhw"]
[Thu Jul 30 11:46:13.796501 2026] [security2:error] [pid 643253:tid 643471] [client 172.236.9.101:26662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1cjqbtjBYzqM1uYkmAAAAFc"]
[Thu Jul 30 11:46:13.799131 2026] [security2:error] [pid 643573:tid 643731] [client 172.236.9.101:38982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1fxWyxgRnoFKAJ_gmgAAAik"]
[Thu Jul 30 11:46:13.801436 2026] [security2:error] [pid 642360:tid 642617] [client 172.236.9.101:44920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1ZSUkh3e5AhEJOBgqwAAAg4"]
[Thu Jul 30 11:46:14.166265 2026] [security2:error] [pid 642360:tid 642584] [client 20.91.199.21:41047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/images/about.php"] [unique_id "amt_1pSUkh3e5AhEJOBguAAAAe0"]
[Thu Jul 30 11:46:14.352894 2026] [security2:error] [pid 642360:tid 642537] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_1ZSUkh3e5AhEJOBgsgAAAb4"]
[Thu Jul 30 11:46:14.615768 2026] [core:notice] [pid 642360:tid 642529] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:14.838868 2026] [security2:error] [pid 643573:tid 643721] [client 172.236.9.101:19885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_goAAAAh8"]
[Thu Jul 30 11:46:14.850035 2026] [security2:error] [pid 643573:tid 643817] [client 172.236.9.101:48957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gowAAAn8"]
[Thu Jul 30 11:46:14.870858 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:45360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gpAAAAk8"]
[Thu Jul 30 11:46:14.872732 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:49721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_goQAAAmA"]
[Thu Jul 30 11:46:14.875092 2026] [security2:error] [pid 643573:tid 643734] [client 172.236.9.101:23508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gnwAAAiw"]
[Thu Jul 30 11:46:14.875454 2026] [security2:error] [pid 643573:tid 643747] [client 172.236.9.101:8745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gogAAAjk"]
[Thu Jul 30 11:46:15.226854 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:4407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gpgAAAoY"]
[Thu Jul 30 11:46:15.231483 2026] [security2:error] [pid 643573:tid 643818] [client 172.236.9.101:26071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gpQAAAoA"]
[Thu Jul 30 11:46:15.232731 2026] [security2:error] [pid 643573:tid 643719] [client 172.236.9.101:47949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gqAAAAh0"]
[Thu Jul 30 11:46:15.235521 2026] [security2:error] [pid 643573:tid 643758] [client 172.236.9.101:3042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_1vxWyxgRnoFKAJ_gpwAAAkQ"]
[Thu Jul 30 11:46:15.375150 2026] [security2:error] [pid 643573:tid 643835] [client 20.91.199.21:15402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amt_1_xWyxgRnoFKAJ_gsAAAApE"]
[Thu Jul 30 11:46:16.669473 2026] [security2:error] [pid 643573:tid 643751] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_2PxWyxgRnoFKAJ_gtwAAAj0"]
[Thu Jul 30 11:46:16.801255 2026] [security2:error] [pid 643573:tid 643816] [client 176.241.66.87:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_2PxWyxgRnoFKAJ_gvgAAAn4"]
[Thu Jul 30 11:46:16.801395 2026] [security2:error] [pid 643573:tid 643816] [client 176.241.66.87:52286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_2PxWyxgRnoFKAJ_gvgAAAn4"]
[Thu Jul 30 11:46:17.673096 2026] [core:notice] [pid 643573:tid 643633] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:17.677007 2026] [security2:error] [pid 643573:tid 643728] [client 66.249.74.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/30/33/62"] [unique_id "amt_2fxWyxgRnoFKAJ_gxQACJjQ"]
[Thu Jul 30 11:46:18.832026 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:18.839693 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:50870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_2pSUkh3e5AhEJOBg5wAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:19.058717 2026] [security2:error] [pid 643573:tid 643723] [client 20.91.199.21:17889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/images/about.php"] [unique_id "amt_2_xWyxgRnoFKAJ_g0wAAAiE"]
[Thu Jul 30 11:46:19.158890 2026] [security2:error] [pid 643573:tid 643824] [client 2407:d000:1c:9d56:64c4:87bd:6970:5a53:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_2vxWyxgRnoFKAJ_g0QAChjo"]
[Thu Jul 30 11:46:19.603049 2026] [core:notice] [pid 643573:tid 643823] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:19.609767 2026] [security2:error] [pid 643573:tid 643823] [client 103.215.74.26:50884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_2_xWyxgRnoFKAJ_g2AAAAoU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:20.188436 2026] [security2:error] [pid 642360:tid 642590] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt_25SUkh3e5AhEJOBg9wAAAfM"]
[Thu Jul 30 11:46:20.354743 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:20.358795 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:50886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3PxWyxgRnoFKAJ_g4QAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:20.855427 2026] [security2:error] [pid 643573:tid 643737] [client 20.91.199.21:5279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/about.php"] [unique_id "amt_3PxWyxgRnoFKAJ_g7gAAAi8"]
[Thu Jul 30 11:46:21.060533 2026] [security2:error] [pid 643573:tid 643646] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g7wACdUE"]
[Thu Jul 30 11:46:21.060702 2026] [security2:error] [pid 643573:tid 643807] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g7wACdUE"]
[Thu Jul 30 11:46:21.094957 2026] [core:notice] [pid 642360:tid 642614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:21.098958 2026] [security2:error] [pid 642360:tid 642614] [client 103.215.74.26:50890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3ZSUkh3e5AhEJOBhBwAAAgs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:21.843894 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:21.849017 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:50906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3fxWyxgRnoFKAJ_hAQAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:21.892787 2026] [security2:error] [pid 643253:tid 643501] [client 20.91.199.21:5357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/cgi-bin/about.php"] [unique_id "amt_3cjqbtjBYzqM1uYkpgAAAHU"]
[Thu Jul 30 11:46:22.441445 2026] [security2:error] [pid 643573:tid 643773] [client 172.236.9.101:1924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g8wAAAlM"]
[Thu Jul 30 11:46:22.518658 2026] [security2:error] [pid 642360:tid 642507] [client 172.236.9.101:19046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3ZSUkh3e5AhEJOBhDAAAAaA"]
[Thu Jul 30 11:46:22.579428 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:22.584392 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:50916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3vxWyxgRnoFKAJ_hDAAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:22.614175 2026] [security2:error] [pid 642360:tid 642493] [client 116.204.97.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhIgAAAZI"]
[Thu Jul 30 11:46:23.248418 2026] [security2:error] [pid 643573:tid 643738] [client 172.236.9.101:56153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g_AAAAjA"]
[Thu Jul 30 11:46:23.259245 2026] [security2:error] [pid 643573:tid 643719] [client 172.236.9.101:35642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g-QAAAh0"]
[Thu Jul 30 11:46:23.261300 2026] [security2:error] [pid 643573:tid 643818] [client 172.236.9.101:22691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g9wAAAoA"]
[Thu Jul 30 11:46:23.264603 2026] [security2:error] [pid 643573:tid 643745] [client 172.236.9.101:32960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g-gAAAjc"]
[Thu Jul 30 11:46:23.271213 2026] [security2:error] [pid 643573:tid 643786] [client 172.236.9.101:31225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g9gAAAmA"]
[Thu Jul 30 11:46:23.272381 2026] [security2:error] [pid 643573:tid 643741] [client 172.236.9.101:42166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g9QAAAjM"]
[Thu Jul 30 11:46:23.292396 2026] [security2:error] [pid 643573:tid 643832] [client 172.236.9.101:39467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g-wAAAo4"]
[Thu Jul 30 11:46:23.295176 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:33872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g9AAAAlk"]
[Thu Jul 30 11:46:23.328391 2026] [core:notice] [pid 643573:tid 643814] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:23.328998 2026] [security2:error] [pid 643573:tid 643758] [client 172.236.9.101:28960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g-AAAAkQ"]
[Thu Jul 30 11:46:23.332416 2026] [security2:error] [pid 643253:tid 643432] [client 172.236.9.101:2354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3cjqbtjBYzqM1uYkowAAADA"]
[Thu Jul 30 11:46:23.340140 2026] [security2:error] [pid 643573:tid 643814] [client 103.215.74.26:40566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_3_xWyxgRnoFKAJ_hFgAAAnw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:23.363803 2026] [security2:error] [pid 643573:tid 643803] [client 172.236.9.101:24879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g_gAAAnE"]
[Thu Jul 30 11:46:23.410232 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:10873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3fxWyxgRnoFKAJ_g_QAAApE"]
[Thu Jul 30 11:46:23.667503 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:23.687956 2026] [security2:error] [pid 642360:tid 642372] [remote 47.128.27.31:53344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-victori-one-slide-2/"] [unique_id "amt_35SUkh3e5AhEJOBhLwABuws"]
[Thu Jul 30 11:46:23.882589 2026] [security2:error] [pid 643253:tid 643483] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_38jqbtjBYzqM1uYkrwAAAGM"]
[Thu Jul 30 11:46:23.896805 2026] [security2:error] [pid 643573:tid 643703] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_3_xWyxgRnoFKAJ_hGgACc3o"]
[Thu Jul 30 11:46:23.896921 2026] [security2:error] [pid 643573:tid 643805] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_3_xWyxgRnoFKAJ_hGgACc3o"]
[Thu Jul 30 11:46:24.069921 2026] [core:notice] [pid 642360:tid 642542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:24.075190 2026] [security2:error] [pid 642360:tid 642542] [client 103.215.74.26:40582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_4JSUkh3e5AhEJOBhMwAAAcM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:24.111139 2026] [core:notice] [pid 642360:tid 642611] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:24.388096 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:24.438461 2026] [security2:error] [pid 642360:tid 642508] [client 172.236.9.101:5643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhGgAAAaE"]
[Thu Jul 30 11:46:24.445837 2026] [security2:error] [pid 643253:tid 643496] [client 172.236.9.101:42939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkqAAAAHA"]
[Thu Jul 30 11:46:24.446766 2026] [security2:error] [pid 643573:tid 643794] [client 172.236.9.101:49692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hBgAAAmg"]
[Thu Jul 30 11:46:24.463694 2026] [security2:error] [pid 642360:tid 642608] [client 172.236.9.101:11798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhIQAAAgU"]
[Thu Jul 30 11:46:24.481738 2026] [security2:error] [pid 643253:tid 643401] [client 172.236.9.101:56242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkpwAAABE"]
[Thu Jul 30 11:46:24.498269 2026] [security2:error] [pid 642360:tid 642602] [client 172.236.9.101:47896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhGwAAAf8"]
[Thu Jul 30 11:46:24.603751 2026] [security2:error] [pid 643253:tid 643390] [client 172.236.9.101:36301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkqgAAAAY"]
[Thu Jul 30 11:46:24.622898 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:3040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hBQAAAhw"]
[Thu Jul 30 11:46:24.633005 2026] [security2:error] [pid 642360:tid 642559] [client 172.236.9.101:19319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhIwAAAdQ"]
[Thu Jul 30 11:46:24.638097 2026] [security2:error] [pid 643253:tid 643509] [client 172.236.9.101:19260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkqQAAAH0"]
[Thu Jul 30 11:46:24.639019 2026] [security2:error] [pid 643573:tid 643722] [client 172.236.9.101:1158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hCAAAAiA"]
[Thu Jul 30 11:46:24.645830 2026] [security2:error] [pid 643253:tid 643506] [client 172.236.9.101:42268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkqwAAAHo"]
[Thu Jul 30 11:46:24.646855 2026] [security2:error] [pid 642360:tid 642549] [client 172.236.9.101:45611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhHwAAAco"]
[Thu Jul 30 11:46:24.649451 2026] [security2:error] [pid 643573:tid 643727] [client 172.236.9.101:60277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hCgAAAiU"]
[Thu Jul 30 11:46:24.650084 2026] [security2:error] [pid 643573:tid 643750] [client 172.236.9.101:25464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hCQAAAjw"]
[Thu Jul 30 11:46:24.669951 2026] [security2:error] [pid 642360:tid 642523] [client 172.236.9.101:46549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhJQAAAbA"]
[Thu Jul 30 11:46:25.241800 2026] [security2:error] [pid 643253:tid 643400] [client 172.236.9.101:28925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3sjqbtjBYzqM1uYkrAAAABA"]
[Thu Jul 30 11:46:25.252562 2026] [security2:error] [pid 643573:tid 643751] [client 172.236.9.101:19711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3vxWyxgRnoFKAJ_hCwAAAj0"]
[Thu Jul 30 11:46:25.280492 2026] [security2:error] [pid 642360:tid 642531] [client 172.236.9.101:53194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_3pSUkh3e5AhEJOBhJAAAAbg"]
[Thu Jul 30 11:46:25.939021 2026] [core:error] [pid 643573:tid 643742] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:25.939043 2026] [core:error] [pid 643573:tid 643742] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:25.940132 2026] [core:error] [pid 643573:tid 643720] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:25.940155 2026] [core:error] [pid 643573:tid 643720] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:26.004097 2026] [core:error] [pid 643573:tid 643833] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:26.004123 2026] [core:error] [pid 643573:tid 643833] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:46:26.769624 2026] [security2:error] [pid 642360:tid 642615] [client 20.91.199.21:3765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/gallery/about.php"] [unique_id "amt_4pSUkh3e5AhEJOBhTwAAAgw"]
[Thu Jul 30 11:46:27.322081 2026] [security2:error] [pid 643573:tid 643817] [client 176.241.66.87:60680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_4_xWyxgRnoFKAJ_hNAAAAn8"]
[Thu Jul 30 11:46:27.322233 2026] [security2:error] [pid 643573:tid 643817] [client 176.241.66.87:60680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_4_xWyxgRnoFKAJ_hNAAAAn8"]
[Thu Jul 30 11:46:27.495649 2026] [security2:error] [pid 642360:tid 642423] [remote 41.210.146.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amt_4pSUkh3e5AhEJOBhUwABjz4"], referer: https://flixon.net/lost-password/
[Thu Jul 30 11:46:28.326556 2026] [security2:error] [pid 643573:tid 643800] [client 57.129.81.227:39140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hPQAAAm4"]
[Thu Jul 30 11:46:28.493865 2026] [security2:error] [pid 643573:tid 643791] [client 141.94.76.134:38800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.76.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hQgAAAmU"]
[Thu Jul 30 11:46:29.245143 2026] [security2:error] [pid 643573:tid 643782] [client 145.239.83.37:42402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.83.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5fxWyxgRnoFKAJ_hVQAAAlw"]
[Thu Jul 30 11:46:29.523296 2026] [security2:error] [pid 643573:tid 643808] [client 217.182.77.22:41252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.77.182.217.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5fxWyxgRnoFKAJ_hZwAAAnY"]
[Thu Jul 30 11:46:29.539570 2026] [security2:error] [pid 643573:tid 643751] [client 172.237.109.114:43499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hUgAAAj0"]
[Thu Jul 30 11:46:29.548393 2026] [security2:error] [pid 643573:tid 643830] [client 172.237.109.114:40858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hUwAAAow"]
[Thu Jul 30 11:46:29.582040 2026] [security2:error] [pid 643573:tid 643732] [client 57.129.81.224:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5fxWyxgRnoFKAJ_haAAAAio"]
[Thu Jul 30 11:46:29.601765 2026] [security2:error] [pid 643573:tid 643725] [client 172.237.109.114:21453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5PxWyxgRnoFKAJ_hVAAAAiM"]
[Thu Jul 30 11:46:29.604772 2026] [security2:error] [pid 643573:tid 643795] [client 172.237.109.114:9134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5fxWyxgRnoFKAJ_hVgAAAmk"]
[Thu Jul 30 11:46:29.644958 2026] [security2:error] [pid 642360:tid 642612] [client 172.237.109.114:20980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5ZSUkh3e5AhEJOBhYwAAAgk"]
[Thu Jul 30 11:46:29.717729 2026] [security2:error] [pid 643573:tid 643731] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_5fxWyxgRnoFKAJ_hZgAAAik"]
[Thu Jul 30 11:46:29.945773 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:29.952693 2026] [security2:error] [pid 643573:tid 643797] [client 103.215.74.26:40584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_5fxWyxgRnoFKAJ_hawAAAms"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:30.038018 2026] [security2:error] [pid 643573:tid 643818] [client 213.32.68.81:52994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.68.32.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amt_5vxWyxgRnoFKAJ_hbAAAAoA"]
[Thu Jul 30 11:46:30.682273 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:30.687646 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:40598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_5vxWyxgRnoFKAJ_hdQAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:30.827137 2026] [security2:error] [pid 643253:tid 643360] [remote 185.95.156.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.156.95.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mskabir.com"] [uri "/wp-login.php"] [unique_id "amt_5sjqbtjBYzqM1uYkwQAAA2k"]
[Thu Jul 30 11:46:31.410535 2026] [core:notice] [pid 643253:tid 643435] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:31.417823 2026] [security2:error] [pid 643253:tid 643435] [client 103.215.74.26:40602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_58jqbtjBYzqM1uYkxAAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:31.680630 2026] [security2:error] [pid 642360:tid 642416] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_55SUkh3e5AhEJOBhegABrjc"]
[Thu Jul 30 11:46:31.680864 2026] [security2:error] [pid 642360:tid 642521] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_55SUkh3e5AhEJOBhegABrjc"]
[Thu Jul 30 11:46:31.769598 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:25820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5_xWyxgRnoFKAJ_hfgAAAoY"]
[Thu Jul 30 11:46:31.801782 2026] [security2:error] [pid 643573:tid 643780] [client 172.236.9.101:21279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_5_xWyxgRnoFKAJ_hfwAAAlo"]
[Thu Jul 30 11:46:31.801782 2026] [security2:error] [pid 642360:tid 642543] [client 172.236.9.101:8439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_55SUkh3e5AhEJOBhdwAAAcQ"]
[Thu Jul 30 11:46:31.823461 2026] [security2:error] [pid 642360:tid 642524] [client 172.236.9.101:37314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_55SUkh3e5AhEJOBheAAAAbE"]
[Thu Jul 30 11:46:32.122849 2026] [security2:error] [pid 642360:tid 642552] [client 20.91.199.21:18454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/blocks/about.php"] [unique_id "amt_6JSUkh3e5AhEJOBhfwAAAc0"]
[Thu Jul 30 11:46:32.157126 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:32.161490 2026] [security2:error] [pid 643573:tid 643756] [client 103.215.74.26:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_6PxWyxgRnoFKAJ_hiQAAAkI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:32.882960 2026] [security2:error] [pid 643573:tid 643789] [client 112.86.225.178:45704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/colunistas/ramalho-leite/"] [unique_id "amt_6PxWyxgRnoFKAJ_hmQAAAmM"]
[Thu Jul 30 11:46:32.883071 2026] [security2:error] [pid 643573:tid 643789] [client 112.86.225.178:45704] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/colunistas/ramalho-leite/"] [unique_id "amt_6PxWyxgRnoFKAJ_hmQAAAmM"]
[Thu Jul 30 11:46:32.888609 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:32.893945 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:40612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_6MjqbtjBYzqM1uYkywAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:33.441898 2026] [security2:error] [pid 642360:tid 642608] [client 172.236.9.101:10193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6JSUkh3e5AhEJOBhggAAAgU"]
[Thu Jul 30 11:46:33.476371 2026] [security2:error] [pid 643253:tid 643451] [client 172.236.9.101:19826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6MjqbtjBYzqM1uYkxQAAAEM"]
[Thu Jul 30 11:46:33.490173 2026] [security2:error] [pid 643573:tid 643810] [client 172.236.9.101:40376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hjQAAAng"]
[Thu Jul 30 11:46:33.507448 2026] [security2:error] [pid 643573:tid 643754] [client 172.236.9.101:37700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hjAAAAkA"]
[Thu Jul 30 11:46:33.551115 2026] [security2:error] [pid 642360:tid 642602] [client 172.236.9.101:30561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6JSUkh3e5AhEJOBhgwAAAf8"]
[Thu Jul 30 11:46:33.572628 2026] [security2:error] [pid 643573:tid 643768] [client 172.236.9.101:21881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hiwAAAk4"]
[Thu Jul 30 11:46:33.576412 2026] [security2:error] [pid 642360:tid 642586] [client 172.236.9.101:43547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6JSUkh3e5AhEJOBhhAAAAe8"]
[Thu Jul 30 11:46:33.582774 2026] [security2:error] [pid 643573:tid 643724] [client 172.236.9.101:1970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hkgAAAiI"]
[Thu Jul 30 11:46:33.590239 2026] [security2:error] [pid 643573:tid 643809] [client 172.236.9.101:47323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hkAAAAnc"]
[Thu Jul 30 11:46:33.601382 2026] [security2:error] [pid 642360:tid 642574] [client 172.236.9.101:1447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6JSUkh3e5AhEJOBhhQAAAeM"]
[Thu Jul 30 11:46:33.602267 2026] [security2:error] [pid 643253:tid 643398] [client 172.236.9.101:60306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6MjqbtjBYzqM1uYkxgAAAA4"]
[Thu Jul 30 11:46:33.603081 2026] [security2:error] [pid 643573:tid 643782] [client 172.236.9.101:2542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hlAAAAlw"]
[Thu Jul 30 11:46:33.607406 2026] [core:notice] [pid 642360:tid 642531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:33.607677 2026] [security2:error] [pid 643573:tid 643816] [client 172.236.9.101:55538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hjwAAAn4"]
[Thu Jul 30 11:46:33.608349 2026] [security2:error] [pid 643573:tid 643775] [client 172.236.9.101:35674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hkwAAAlU"]
[Thu Jul 30 11:46:33.614523 2026] [security2:error] [pid 643573:tid 643813] [client 172.236.9.101:43680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hkQAAAns"]
[Thu Jul 30 11:46:33.615425 2026] [security2:error] [pid 642360:tid 642531] [client 103.215.74.26:32938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_6ZSUkh3e5AhEJOBhkwAAAbg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:33.620659 2026] [security2:error] [pid 643573:tid 643822] [client 172.236.9.101:58756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_6PxWyxgRnoFKAJ_hjgAAAoQ"]
[Thu Jul 30 11:46:34.098394 2026] [security2:error] [pid 643573:tid 643784] [client 20.91.199.21:16334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/css/about.php"] [unique_id "amt_6vxWyxgRnoFKAJ_hoQAAAl4"]
[Thu Jul 30 11:46:34.529701 2026] [security2:error] [pid 642360:tid 642541] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_6ZSUkh3e5AhEJOBhlQABwh4"]
[Thu Jul 30 11:46:34.617500 2026] [security2:error] [pid 643253:tid 643472] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_6cjqbtjBYzqM1uYkzgAAWG8"]
[Thu Jul 30 11:46:34.826009 2026] [security2:error] [pid 643573:tid 643686] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_6vxWyxgRnoFKAJ_hqgACk2k"]
[Thu Jul 30 11:46:34.826131 2026] [security2:error] [pid 643573:tid 643837] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_6vxWyxgRnoFKAJ_hqgACk2k"]
[Thu Jul 30 11:46:35.492183 2026] [security2:error] [pid 642360:tid 642451] [remote 57.141.0.25:57114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6164509415/feed/rss2/"] [unique_id "amt_65SUkh3e5AhEJOBhogABq1o"]
[Thu Jul 30 11:46:35.886424 2026] [security2:error] [pid 643253:tid 643484] [client 20.91.199.21:6934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/images/about.php"] [unique_id "amt_68jqbtjBYzqM1uYk0gAAAGQ"]
[Thu Jul 30 11:46:36.821211 2026] [security2:error] [pid 643573:tid 643728] [client 20.91.199.21:12203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amt_7PxWyxgRnoFKAJ_htgAAAiY"]
[Thu Jul 30 11:46:37.864059 2026] [security2:error] [pid 643573:tid 643822] [client 172.236.9.101:14388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7fxWyxgRnoFKAJ_hugAAAoQ"]
[Thu Jul 30 11:46:38.073359 2026] [security2:error] [pid 643573:tid 643715] [client 176.241.66.87:61630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hvgAAAhk"]
[Thu Jul 30 11:46:38.073491 2026] [security2:error] [pid 643573:tid 643715] [client 176.241.66.87:61630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hvgAAAhk"]
[Thu Jul 30 11:46:38.353857 2026] [security2:error] [pid 642360:tid 642566] [client 74.7.228.27:60314] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ssl.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amt_7pSUkh3e5AhEJOBhvQAAAds"]
[Thu Jul 30 11:46:38.919458 2026] [security2:error] [pid 643573:tid 643824] [client 172.236.9.101:19026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hwgAAAoY"]
[Thu Jul 30 11:46:38.924539 2026] [security2:error] [pid 643573:tid 643831] [client 172.236.9.101:30778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hwAAAAo0"]
[Thu Jul 30 11:46:38.973721 2026] [security2:error] [pid 643573:tid 643769] [client 20.91.199.21:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hxwAAAk8"]
[Thu Jul 30 11:46:38.993750 2026] [security2:error] [pid 643253:tid 643445] [client 172.236.9.101:3544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7sjqbtjBYzqM1uYk0wAAAD0"]
[Thu Jul 30 11:46:38.994152 2026] [security2:error] [pid 643573:tid 643780] [client 172.236.9.101:3978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hwQAAAlo"]
[Thu Jul 30 11:46:39.027249 2026] [security2:error] [pid 643573:tid 643796] [client 172.236.9.101:37115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hxAAAAmo"]
[Thu Jul 30 11:46:39.027249 2026] [security2:error] [pid 643573:tid 643752] [client 172.236.9.101:12249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hwwAAAj4"]
[Thu Jul 30 11:46:39.042023 2026] [security2:error] [pid 643573:tid 643726] [client 172.236.9.101:2117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_7vxWyxgRnoFKAJ_hxQAAAiQ"]
[Thu Jul 30 11:46:39.244593 2026] [security2:error] [pid 643573:tid 643698] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amt_7_xWyxgRnoFKAJ_hygACJ3U"]
[Thu Jul 30 11:46:39.244800 2026] [security2:error] [pid 643573:tid 643729] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amt_7_xWyxgRnoFKAJ_hygACJ3U"]
[Thu Jul 30 11:46:39.354234 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:39.358543 2026] [security2:error] [pid 642360:tid 642601] [client 103.215.74.26:32942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_75SUkh3e5AhEJOBhygAAAf4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:40.043158 2026] [security2:error] [pid 643573:tid 643624] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h0AACLis"]
[Thu Jul 30 11:46:40.043358 2026] [security2:error] [pid 643573:tid 643736] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h0AACLis"]
[Thu Jul 30 11:46:40.076095 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:40.081025 2026] [security2:error] [pid 643253:tid 643427] [client 103.215.74.26:32944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8MjqbtjBYzqM1uYk1QAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:40.315720 2026] [security2:error] [pid 643573:tid 643702] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/xstelth.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h0wACeHk"]
[Thu Jul 30 11:46:40.315960 2026] [security2:error] [pid 643573:tid 643810] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/xstelth.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h0wACeHk"]
[Thu Jul 30 11:46:40.571564 2026] [security2:error] [pid 643573:tid 643695] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h1QACQ3I"]
[Thu Jul 30 11:46:40.571734 2026] [security2:error] [pid 643573:tid 643757] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h1QACQ3I"]
[Thu Jul 30 11:46:40.835397 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:40.839795 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:32958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8PxWyxgRnoFKAJ_h2AAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:40.909043 2026] [security2:error] [pid 643573:tid 643697] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/newfile.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h2QACe3Q"]
[Thu Jul 30 11:46:40.909337 2026] [security2:error] [pid 643573:tid 643813] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/newfile.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h2QACe3Q"]
[Thu Jul 30 11:46:41.024851 2026] [security2:error] [pid 643573:tid 643724] [client 66.249.74.74:36694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amt_8PxWyxgRnoFKAJ_h1wAAAiI"], referer: https://supreme-hydraulics.com/
[Thu Jul 30 11:46:41.195027 2026] [security2:error] [pid 643573:tid 643690] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/tBEZGQz.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3AACYW0"]
[Thu Jul 30 11:46:41.195193 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/tBEZGQz.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3AACYW0"]
[Thu Jul 30 11:46:41.212741 2026] [core:notice] [pid 643253:tid 643369] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:41.343853 2026] [security2:error] [pid 643573:tid 643828] [client 74.7.228.6:50106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ege.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_7_xWyxgRnoFKAJ_hywACiic"]
[Thu Jul 30 11:46:41.343882 2026] [security2:error] [pid 643573:tid 643828] [client 74.7.228.6:50106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ege.nyx.temporary.site"] [uri "/index.php"] [unique_id "amt_7_xWyxgRnoFKAJ_hywACiic"]
[Thu Jul 30 11:46:41.468462 2026] [security2:error] [pid 643573:tid 643740] [client 66.249.74.74:43533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3QAAAjI"], referer: https://supreme-hydraulics.com/
[Thu Jul 30 11:46:41.587484 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:41.592005 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:32974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8ZSUkh3e5AhEJOBh5gAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:41.755608 2026] [security2:error] [pid 643573:tid 643807] [client 66.249.74.74:36694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h4AAAAnU"], referer: https://supreme-hydraulics.com/
[Thu Jul 30 11:46:42.179442 2026] [security2:error] [pid 643573:tid 643675] [remote 190.6.176.90:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.176.6.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-login.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h5gACc14"]
[Thu Jul 30 11:46:42.321569 2026] [security2:error] [pid 643573:tid 643704] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h7QACens"]
[Thu Jul 30 11:46:42.321771 2026] [security2:error] [pid 643573:tid 643812] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h7QACens"]
[Thu Jul 30 11:46:42.331597 2026] [core:notice] [pid 642360:tid 642529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:42.335862 2026] [security2:error] [pid 642360:tid 642529] [client 103.215.74.26:32988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8pSUkh3e5AhEJOBh7wAAAbY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:42.586667 2026] [security2:error] [pid 643573:tid 643714] [client 74.7.228.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "medaxco.com"] [uri "/index.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h6QACGHc"], referer: https://www.ege.nyx.temporary.site/robots.txt
[Thu Jul 30 11:46:42.717097 2026] [security2:error] [pid 643573:tid 643711] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3wACFXA"]
[Thu Jul 30 11:46:42.717143 2026] [security2:error] [pid 643573:tid 643711] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_8fxWyxgRnoFKAJ_h3wACFXA"]
[Thu Jul 30 11:46:42.734548 2026] [security2:error] [pid 642360:tid 642549] [client 20.91.199.21:5271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/network/cloud.php"] [unique_id "amt_8pSUkh3e5AhEJOBh8wAAAco"]
[Thu Jul 30 11:46:42.743494 2026] [security2:error] [pid 643253:tid 643501] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amt_8sjqbtjBYzqM1uYk2QAAAHU"]
[Thu Jul 30 11:46:43.071489 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:43.075424 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:38796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8_xWyxgRnoFKAJ_h9AAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:43.232589 2026] [security2:error] [pid 643573:tid 643707] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/drykl.php"] [unique_id "amt_8_xWyxgRnoFKAJ_h9gACRn4"]
[Thu Jul 30 11:46:43.232803 2026] [security2:error] [pid 643573:tid 643760] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/drykl.php"] [unique_id "amt_8_xWyxgRnoFKAJ_h9gACRn4"]
[Thu Jul 30 11:46:43.513345 2026] [security2:error] [pid 643573:tid 643701] [remote 194.116.184.179:17681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amt_8_xWyxgRnoFKAJ_h9wACWng"]
[Thu Jul 30 11:46:43.604112 2026] [autoindex:error] [pid 643573:tid 643706] [remote 20.104.16.169:0] AH01276: Cannot serve directory /home2/xncnyxte/public_html/website_32476423/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:46:43.604950 2026] [security2:error] [pid 643573:tid 643742] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "allmontecristi.com"] [uri "/cgi-sys/403.html"] [unique_id "amt_8_xWyxgRnoFKAJ_h-wACNH0"]
[Thu Jul 30 11:46:43.815937 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:43.819962 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:38810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_8_xWyxgRnoFKAJ_iAAAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:43.863803 2026] [security2:error] [pid 643573:tid 643788] [client 20.91.199.21:8644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/cloud.php"] [unique_id "amt_8_xWyxgRnoFKAJ_iAQAAAmI"]
[Thu Jul 30 11:46:43.905774 2026] [security2:error] [pid 643573:tid 643593] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ls.php"] [unique_id "amt_8_xWyxgRnoFKAJ_iAgACKAw"]
[Thu Jul 30 11:46:43.905930 2026] [security2:error] [pid 643573:tid 643730] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ls.php"] [unique_id "amt_8_xWyxgRnoFKAJ_iAgACKAw"]
[Thu Jul 30 11:46:44.126671 2026] [security2:error] [pid 643573:tid 643756] [client 54.87.112.51:24778] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amt_8vxWyxgRnoFKAJ_h8wAAAkI"], referer: https://globalmarks.pk/
[Thu Jul 30 11:46:44.227870 2026] [security2:error] [pid 643573:tid 643699] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/dx.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iCAACf3Y"]
[Thu Jul 30 11:46:44.228116 2026] [security2:error] [pid 643573:tid 643817] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/dx.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iCAACf3Y"]
[Thu Jul 30 11:46:44.537540 2026] [security2:error] [pid 643573:tid 643809] [client 20.91.199.21:3944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/cgi-bin/cloud.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iCgAAAnc"]
[Thu Jul 30 11:46:44.544469 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:44.545961 2026] [security2:error] [pid 643573:tid 643589] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/mac.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iDAACSQg"]
[Thu Jul 30 11:46:44.546116 2026] [security2:error] [pid 643573:tid 643763] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/mac.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iDAACSQg"]
[Thu Jul 30 11:46:44.548824 2026] [security2:error] [pid 643573:tid 643816] [client 103.215.74.26:38826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9PxWyxgRnoFKAJ_iCwAAAn4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:44.857411 2026] [security2:error] [pid 643573:tid 643585] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/485.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iDgACggQ"]
[Thu Jul 30 11:46:44.857669 2026] [security2:error] [pid 643573:tid 643820] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/485.php"] [unique_id "amt_9PxWyxgRnoFKAJ_iDgACggQ"]
[Thu Jul 30 11:46:45.143150 2026] [security2:error] [pid 643573:tid 643586] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gelio1.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iDwACIQU"]
[Thu Jul 30 11:46:45.143376 2026] [security2:error] [pid 643573:tid 643723] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gelio1.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iDwACIQU"]
[Thu Jul 30 11:46:45.311649 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:45.318273 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:38836] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9ZSUkh3e5AhEJOBiEAAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:45.441512 2026] [security2:error] [pid 643573:tid 643651] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/lp6.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iEwACgUY"]
[Thu Jul 30 11:46:45.441753 2026] [security2:error] [pid 643573:tid 643819] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/lp6.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iEwACgUY"]
[Thu Jul 30 11:46:45.737157 2026] [security2:error] [pid 643573:tid 643622] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iGAACQSk"]
[Thu Jul 30 11:46:45.737297 2026] [security2:error] [pid 643573:tid 643755] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iGAACQSk"]
[Thu Jul 30 11:46:45.751244 2026] [security2:error] [pid 643573:tid 643587] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iGQACegY"]
[Thu Jul 30 11:46:45.751410 2026] [security2:error] [pid 643573:tid 643812] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amt_9fxWyxgRnoFKAJ_iGQACegY"]
[Thu Jul 30 11:46:45.794927 2026] [security2:error] [pid 643573:tid 643727] [client 139.28.219.70:49260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amt_9fxWyxgRnoFKAJ_iGgAAAiU"]
[Thu Jul 30 11:46:46.044137 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:46.051734 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:38842] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9vxWyxgRnoFKAJ_iHgAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:46.061292 2026] [autoindex:error] [pid 643573:tid 643596] [remote 20.104.16.169:0] AH01276: Cannot serve directory /home2/xncnyxte/public_html/website_32476423/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:46:46.062135 2026] [security2:error] [pid 643573:tid 643737] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "allmontecristi.com"] [uri "/cgi-sys/403.html"] [unique_id "amt_9vxWyxgRnoFKAJ_iHwACLw8"]
[Thu Jul 30 11:46:46.279642 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:46.325059 2026] [security2:error] [pid 643573:tid 643796] [client 139.28.219.70:49270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iIwAAAmo"]
[Thu Jul 30 11:46:46.346727 2026] [security2:error] [pid 643573:tid 643623] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/w3llscc.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iJAACaSo"]
[Thu Jul 30 11:46:46.346870 2026] [security2:error] [pid 643573:tid 643795] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/w3llscc.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iJAACaSo"]
[Thu Jul 30 11:46:46.648107 2026] [security2:error] [pid 643573:tid 643600] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/miru3.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iJwACYxM"]
[Thu Jul 30 11:46:46.648293 2026] [security2:error] [pid 643573:tid 643789] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/miru3.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iJwACYxM"]
[Thu Jul 30 11:46:46.774388 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:46.778670 2026] [security2:error] [pid 643573:tid 643771] [client 103.215.74.26:38854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9vxWyxgRnoFKAJ_iKQAAAlE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:46.941409 2026] [core:notice] [pid 642360:tid 642398] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:46.956877 2026] [security2:error] [pid 643573:tid 643745] [client 139.28.219.70:49274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amt_9vxWyxgRnoFKAJ_iKwAAAjc"]
[Thu Jul 30 11:46:46.957084 2026] [security2:error] [pid 643573:tid 643608] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/autoload_classmap.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iKgACXRs"]
[Thu Jul 30 11:46:46.957203 2026] [security2:error] [pid 643573:tid 643783] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/autoload_classmap.php"] [unique_id "amt_9vxWyxgRnoFKAJ_iKgACXRs"]
[Thu Jul 30 11:46:47.301414 2026] [security2:error] [pid 643573:tid 643756] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "allmontecristi.com"] [uri "/wp-content/index.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iLgACQgk"]
[Thu Jul 30 11:46:47.511183 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:47.516228 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:38860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_9_xWyxgRnoFKAJ_iMAAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:47.520311 2026] [security2:error] [pid 643573:tid 643739] [client 139.28.219.70:49290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amt_9_xWyxgRnoFKAJ_iMQAAAjE"]
[Thu Jul 30 11:46:47.634606 2026] [security2:error] [pid 643573:tid 643629] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-content/themes/index.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iMwACezA"]
[Thu Jul 30 11:46:47.634809 2026] [security2:error] [pid 643573:tid 643813] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-content/themes/index.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iMwACezA"]
[Thu Jul 30 11:46:47.665716 2026] [security2:error] [pid 643573:tid 643778] [client 20.91.199.21:3763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/updates.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iNAAAAlg"]
[Thu Jul 30 11:46:47.891176 2026] [security2:error] [pid 643573:tid 643616] [remote 208.122.213.225:53446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iNgACgCM"]
[Thu Jul 30 11:46:47.942591 2026] [security2:error] [pid 643573:tid 643605] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/av.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iNwACMhg"]
[Thu Jul 30 11:46:47.942805 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/av.php"] [unique_id "amt_9_xWyxgRnoFKAJ_iNwACMhg"]
[Thu Jul 30 11:46:48.052813 2026] [security2:error] [pid 643573:tid 643748] [client 139.28.219.70:49304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amt_-PxWyxgRnoFKAJ_iOgAAAjo"]
[Thu Jul 30 11:46:48.238511 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:48.246148 2026] [security2:error] [pid 643573:tid 643801] [client 103.215.74.26:38866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-PxWyxgRnoFKAJ_iPgAAAm8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:48.272874 2026] [autoindex:error] [pid 643573:tid 643621] [remote 20.104.16.169:0] AH01276: Cannot serve directory /home2/xncnyxte/public_html/website_32476423/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:46:48.273661 2026] [security2:error] [pid 643573:tid 643715] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "allmontecristi.com"] [uri "/cgi-sys/403.html"] [unique_id "amt_-PxWyxgRnoFKAJ_iPwACGSg"]
[Thu Jul 30 11:46:48.578473 2026] [security2:error] [pid 643573:tid 643762] [client 139.28.219.70:49308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amt_-PxWyxgRnoFKAJ_iQQAAAkg"]
[Thu Jul 30 11:46:48.734544 2026] [security2:error] [pid 643573:tid 643827] [client 213.152.161.240:32890] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt_-PxWyxgRnoFKAJ_iRAAAAok"]
[Thu Jul 30 11:46:48.734662 2026] [security2:error] [pid 643573:tid 643827] [client 213.152.161.240:32890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amt_-PxWyxgRnoFKAJ_iRAAAAok"]
[Thu Jul 30 11:46:48.846714 2026] [security2:error] [pid 642360:tid 642540] [client 176.241.66.87:62551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_-JSUkh3e5AhEJOBiMAAAAcE"]
[Thu Jul 30 11:46:48.846866 2026] [security2:error] [pid 642360:tid 642540] [client 176.241.66.87:62551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amt_-JSUkh3e5AhEJOBiMAAAAcE"]
[Thu Jul 30 11:46:48.959867 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:48.964137 2026] [security2:error] [pid 643573:tid 643718] [client 103.215.74.26:38868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-PxWyxgRnoFKAJ_iRgAAAhw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:49.213426 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_-PxWyxgRnoFKAJ_iQgACZS8"]
[Thu Jul 30 11:46:49.213455 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amt_-PxWyxgRnoFKAJ_iQgACZS8"]
[Thu Jul 30 11:46:49.348889 2026] [security2:error] [pid 643573:tid 643711] [client 139.28.219.70:49322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amt_-fxWyxgRnoFKAJ_iSAAAAhU"]
[Thu Jul 30 11:46:49.693563 2026] [core:notice] [pid 642360:tid 642544] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:49.697665 2026] [security2:error] [pid 642360:tid 642544] [client 103.215.74.26:38872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-ZSUkh3e5AhEJOBiOQAAAcU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:49.763740 2026] [security2:error] [pid 643573:tid 643615] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/tiny.php"] [unique_id "amt_-fxWyxgRnoFKAJ_iTQACjiI"]
[Thu Jul 30 11:46:49.763927 2026] [security2:error] [pid 643573:tid 643832] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/tiny.php"] [unique_id "amt_-fxWyxgRnoFKAJ_iTQACjiI"]
[Thu Jul 30 11:46:50.001741 2026] [security2:error] [pid 643573:tid 643833] [client 139.28.219.70:49328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amt_-vxWyxgRnoFKAJ_iTwAAAo8"]
[Thu Jul 30 11:46:50.061663 2026] [security2:error] [pid 643573:tid 643609] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iUAACKBw"]
[Thu Jul 30 11:46:50.061836 2026] [security2:error] [pid 643573:tid 643730] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iUAACKBw"]
[Thu Jul 30 11:46:50.358692 2026] [security2:error] [pid 643573:tid 643604] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/zrrhj.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iVgACKxc"]
[Thu Jul 30 11:46:50.358885 2026] [security2:error] [pid 643573:tid 643733] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/zrrhj.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iVgACKxc"]
[Thu Jul 30 11:46:50.419314 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:50.423401 2026] [security2:error] [pid 643573:tid 643761] [client 103.215.74.26:38888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-vxWyxgRnoFKAJ_iVwAAAkc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:50.519847 2026] [security2:error] [pid 643573:tid 643815] [client 139.28.219.70:49344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amt_-vxWyxgRnoFKAJ_iWQAAAn0"]
[Thu Jul 30 11:46:50.690885 2026] [security2:error] [pid 643573:tid 643612] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iWgACOh8"]
[Thu Jul 30 11:46:50.691129 2026] [security2:error] [pid 643573:tid 643748] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iWgACOh8"]
[Thu Jul 30 11:46:50.748461 2026] [security2:error] [pid 642360:tid 642529] [client 172.236.9.101:7694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-pSUkh3e5AhEJOBiPQAAAbY"]
[Thu Jul 30 11:46:50.800059 2026] [security2:error] [pid 643573:tid 643782] [client 172.236.9.101:28831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iVAAAAlw"]
[Thu Jul 30 11:46:50.866635 2026] [security2:error] [pid 643573:tid 643739] [client 172.236.9.101:65287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iUwAAAjE"]
[Thu Jul 30 11:46:50.985689 2026] [security2:error] [pid 643573:tid 643588] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wpgum.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iYAACiAc"]
[Thu Jul 30 11:46:50.985883 2026] [security2:error] [pid 643573:tid 643826] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wpgum.php"] [unique_id "amt_-vxWyxgRnoFKAJ_iYAACiAc"]
[Thu Jul 30 11:46:50.995095 2026] [security2:error] [pid 643573:tid 643625] [remote 52.167.144.219:56963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/download/6852/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amt_-vxWyxgRnoFKAJ_iYQACFCw"]
[Thu Jul 30 11:46:51.043437 2026] [security2:error] [pid 643573:tid 643779] [client 139.28.219.70:39766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amt_-_xWyxgRnoFKAJ_iYwAAAlk"]
[Thu Jul 30 11:46:51.148426 2026] [core:notice] [pid 643573:tid 643834] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:51.155471 2026] [security2:error] [pid 643573:tid 643834] [client 103.215.74.26:38902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amt_-_xWyxgRnoFKAJ_iZQAAApA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:51.286511 2026] [security2:error] [pid 643573:tid 643607] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ywwbf.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibAAChho"]
[Thu Jul 30 11:46:51.286824 2026] [security2:error] [pid 643573:tid 643824] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ywwbf.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibAAChho"]
[Thu Jul 30 11:46:51.611846 2026] [security2:error] [pid 643573:tid 643630] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/xoldj.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibwACaTE"]
[Thu Jul 30 11:46:51.612181 2026] [security2:error] [pid 643573:tid 643795] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/xoldj.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibwACaTE"]
[Thu Jul 30 11:46:51.650922 2026] [security2:error] [pid 643573:tid 643830] [client 139.28.219.70:39774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amt_-_xWyxgRnoFKAJ_icAAAAow"]
[Thu Jul 30 11:46:51.896893 2026] [security2:error] [pid 643573:tid 643631] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/f35.php"] [unique_id "amt_-_xWyxgRnoFKAJ_icgACYDI"]
[Thu Jul 30 11:46:51.897127 2026] [security2:error] [pid 643573:tid 643786] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/f35.php"] [unique_id "amt_-_xWyxgRnoFKAJ_icgACYDI"]
[Thu Jul 30 11:46:52.043934 2026] [security2:error] [pid 643573:tid 643800] [client 20.91.199.21:3950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/css/cloud.php"] [unique_id "amt__PxWyxgRnoFKAJ_icwAAAm4"]
[Thu Jul 30 11:46:52.409021 2026] [security2:error] [pid 643253:tid 643469] [client 139.28.219.70:39780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amt__MjqbtjBYzqM1uYk3QAAAFU"]
[Thu Jul 30 11:46:52.537751 2026] [security2:error] [pid 643573:tid 643770] [client 172.236.9.101:14221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iZwAAAlA"]
[Thu Jul 30 11:46:52.538863 2026] [security2:error] [pid 643573:tid 643718] [client 172.236.9.101:9125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iaAAAAhw"]
[Thu Jul 30 11:46:52.546927 2026] [security2:error] [pid 642360:tid 642490] [client 172.236.9.101:58683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiSAAAAY8"]
[Thu Jul 30 11:46:52.572926 2026] [security2:error] [pid 643573:tid 643773] [client 172.236.9.101:15722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iaQAAAlM"]
[Thu Jul 30 11:46:52.755443 2026] [security2:error] [pid 643573:tid 643809] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mgr3.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amt__PxWyxgRnoFKAJ_ifAAAAnc"]
[Thu Jul 30 11:46:52.931395 2026] [security2:error] [pid 643573:tid 643777] [client 139.28.219.70:39796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amt__PxWyxgRnoFKAJ_ifgAAAlc"]
[Thu Jul 30 11:46:52.932260 2026] [core:notice] [pid 642360:tid 642425] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:52.936293 2026] [security2:error] [pid 643573:tid 643645] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt__PxWyxgRnoFKAJ_ifwACikA"]
[Thu Jul 30 11:46:52.936434 2026] [security2:error] [pid 643573:tid 643828] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amt__PxWyxgRnoFKAJ_ifwACikA"]
[Thu Jul 30 11:46:52.999367 2026] [security2:error] [pid 643573:tid 643638] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gk.php"] [unique_id "amt__PxWyxgRnoFKAJ_igAACMjk"]
[Thu Jul 30 11:46:52.999577 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gk.php"] [unique_id "amt__PxWyxgRnoFKAJ_igAACMjk"]
[Thu Jul 30 11:46:53.228682 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:19997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iagAAAnQ"]
[Thu Jul 30 11:46:53.231414 2026] [security2:error] [pid 642360:tid 642589] [client 172.236.9.101:47716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiRwAAAfI"]
[Thu Jul 30 11:46:53.231795 2026] [security2:error] [pid 642360:tid 642530] [client 172.236.9.101:64164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiTAAAAbc"]
[Thu Jul 30 11:46:53.231898 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:60377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiSQAAAdM"]
[Thu Jul 30 11:46:53.232855 2026] [security2:error] [pid 642360:tid 642571] [client 172.236.9.101:60326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiSwAAAeA"]
[Thu Jul 30 11:46:53.235947 2026] [security2:error] [pid 642360:tid 642536] [client 172.236.9.101:15255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiTgAAAb0"]
[Thu Jul 30 11:46:53.241914 2026] [security2:error] [pid 642360:tid 642569] [client 172.236.9.101:1070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiTwAAAd4"]
[Thu Jul 30 11:46:53.253882 2026] [security2:error] [pid 643573:tid 643837] [client 172.236.9.101:58508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_iawAAApM"]
[Thu Jul 30 11:46:53.254148 2026] [security2:error] [pid 642360:tid 642556] [client 172.236.9.101:30976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiSgAAAdE"]
[Thu Jul 30 11:46:53.267320 2026] [security2:error] [pid 642360:tid 642526] [client 172.236.9.101:17284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-5SUkh3e5AhEJOBiTQAAAbM"]
[Thu Jul 30 11:46:53.282147 2026] [security2:error] [pid 643573:tid 643744] [client 172.236.9.101:57513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibQAAAjY"]
[Thu Jul 30 11:46:53.294217 2026] [security2:error] [pid 643573:tid 643747] [client 172.236.9.101:16436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-_xWyxgRnoFKAJ_ibgAAAjk"]
[Thu Jul 30 11:46:53.297849 2026] [security2:error] [pid 643253:tid 643432] [client 172.236.9.101:12593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amt_-8jqbtjBYzqM1uYk2gAAADA"]
[Thu Jul 30 11:46:53.299155 2026] [security2:error] [pid 643573:tid 643641] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amt__fxWyxgRnoFKAJ_ihAACbzw"]
[Thu Jul 30 11:46:53.299386 2026] [security2:error] [pid 643573:tid 643801] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amt__fxWyxgRnoFKAJ_ihAACbzw"]
[Thu Jul 30 11:46:53.601970 2026] [security2:error] [pid 643573:tid 643633] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wper3.php"] [unique_id "amt__fxWyxgRnoFKAJ_ihwACIDQ"]
[Thu Jul 30 11:46:53.602186 2026] [security2:error] [pid 643573:tid 643722] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wper3.php"] [unique_id "amt__fxWyxgRnoFKAJ_ihwACIDQ"]
[Thu Jul 30 11:46:53.906039 2026] [security2:error] [pid 643573:tid 643650] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bthil.php"] [unique_id "amt__fxWyxgRnoFKAJ_ijQACTUU"]
[Thu Jul 30 11:46:53.906252 2026] [security2:error] [pid 643573:tid 643767] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/bthil.php"] [unique_id "amt__fxWyxgRnoFKAJ_ijQACTUU"]
[Thu Jul 30 11:46:54.210087 2026] [security2:error] [pid 643573:tid 643647] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wyzer1.php"] [unique_id "amt__vxWyxgRnoFKAJ_ikwACdkI"]
[Thu Jul 30 11:46:54.210261 2026] [security2:error] [pid 643573:tid 643808] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wyzer1.php"] [unique_id "amt__vxWyxgRnoFKAJ_ikwACdkI"]
[Thu Jul 30 11:46:54.492996 2026] [security2:error] [pid 643573:tid 643751] [client 20.91.199.21:3912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/user/cloud.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilQAAAj0"]
[Thu Jul 30 11:46:54.494210 2026] [security2:error] [pid 643573:tid 643581] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/mh.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilgACMAA"]
[Thu Jul 30 11:46:54.494343 2026] [security2:error] [pid 643573:tid 643738] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/mh.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilgACMAA"]
[Thu Jul 30 11:46:54.796569 2026] [security2:error] [pid 643573:tid 643652] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilwACa0c"]
[Thu Jul 30 11:46:54.796860 2026] [security2:error] [pid 643573:tid 643797] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amt__vxWyxgRnoFKAJ_ilwACa0c"]
[Thu Jul 30 11:46:55.105813 2026] [security2:error] [pid 643573:tid 643658] [remote 20.104.16.169:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "allmontecristi.com"] [uri "/1.php"] [unique_id "amt___xWyxgRnoFKAJ_ioAACg00"]
[Thu Jul 30 11:46:55.105940 2026] [security2:error] [pid 643573:tid 643658] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/1.php"] [unique_id "amt___xWyxgRnoFKAJ_ioAACg00"]
[Thu Jul 30 11:46:55.106120 2026] [security2:error] [pid 643573:tid 643821] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/1.php"] [unique_id "amt___xWyxgRnoFKAJ_ioAACg00"]
[Thu Jul 30 11:46:55.391242 2026] [security2:error] [pid 643573:tid 643661] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/chosen.php"] [unique_id "amt___xWyxgRnoFKAJ_iowACJlA"]
[Thu Jul 30 11:46:55.391407 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/chosen.php"] [unique_id "amt___xWyxgRnoFKAJ_iowACJlA"]
[Thu Jul 30 11:46:55.676669 2026] [security2:error] [pid 643573:tid 643668] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/sd.php"] [unique_id "amt___xWyxgRnoFKAJ_iqAACU1c"]
[Thu Jul 30 11:46:55.676845 2026] [security2:error] [pid 643573:tid 643773] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/sd.php"] [unique_id "amt___xWyxgRnoFKAJ_iqAACU1c"]
[Thu Jul 30 11:46:55.814887 2026] [security2:error] [pid 643573:tid 643718] [client 20.91.199.21:22285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/img/cloud.php"] [unique_id "amt___xWyxgRnoFKAJ_iqQAAAhw"]
[Thu Jul 30 11:46:55.993747 2026] [security2:error] [pid 643573:tid 643671] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/z60.php"] [unique_id "amt___xWyxgRnoFKAJ_irAACfVo"]
[Thu Jul 30 11:46:55.993957 2026] [security2:error] [pid 643573:tid 643815] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/z60.php"] [unique_id "amt___xWyxgRnoFKAJ_irAACfVo"]
[Thu Jul 30 11:46:56.286714 2026] [security2:error] [pid 643573:tid 643632] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/home.php"] [unique_id "amuAAPxWyxgRnoFKAJ_isAACgjM"]
[Thu Jul 30 11:46:56.286990 2026] [security2:error] [pid 643573:tid 643820] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/home.php"] [unique_id "amuAAPxWyxgRnoFKAJ_isAACgjM"]
[Thu Jul 30 11:46:56.536491 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.199.21:3745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuAAMjqbtjBYzqM1uYk4QAAAEo"]
[Thu Jul 30 11:46:56.574411 2026] [security2:error] [pid 643573:tid 643644] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ws58.php"] [unique_id "amuAAPxWyxgRnoFKAJ_isQACZj8"]
[Thu Jul 30 11:46:56.574568 2026] [security2:error] [pid 643573:tid 643792] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ws58.php"] [unique_id "amuAAPxWyxgRnoFKAJ_isQACZj8"]
[Thu Jul 30 11:46:56.655400 2026] [security2:error] [pid 642360:tid 642427] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAAJSUkh3e5AhEJOBifAAB10I"]
[Thu Jul 30 11:46:56.655588 2026] [security2:error] [pid 642360:tid 642562] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAAJSUkh3e5AhEJOBifAAB10I"]
[Thu Jul 30 11:46:56.733388 2026] [security2:error] [pid 642360:tid 642568] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAAJSUkh3e5AhEJOBidgAAAd0"]
[Thu Jul 30 11:46:56.858478 2026] [security2:error] [pid 643573:tid 643591] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gulu.php"] [unique_id "amuAAPxWyxgRnoFKAJ_iswACOQo"]
[Thu Jul 30 11:46:56.858634 2026] [security2:error] [pid 643573:tid 643747] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/gulu.php"] [unique_id "amuAAPxWyxgRnoFKAJ_iswACOQo"]
[Thu Jul 30 11:46:56.884340 2026] [core:notice] [pid 642360:tid 642591] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:56.888761 2026] [security2:error] [pid 642360:tid 642591] [client 103.215.74.26:30272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAAJSUkh3e5AhEJOBigAAAAfQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:57.144585 2026] [security2:error] [pid 643573:tid 643619] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuAAfxWyxgRnoFKAJ_itgACXiY"]
[Thu Jul 30 11:46:57.144760 2026] [security2:error] [pid 643573:tid 643784] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuAAfxWyxgRnoFKAJ_itgACXiY"]
[Thu Jul 30 11:46:57.436126 2026] [security2:error] [pid 643573:tid 643666] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wpls.php"] [unique_id "amuAAfxWyxgRnoFKAJ_iuAACSFU"]
[Thu Jul 30 11:46:57.436274 2026] [security2:error] [pid 643573:tid 643762] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wpls.php"] [unique_id "amuAAfxWyxgRnoFKAJ_iuAACSFU"]
[Thu Jul 30 11:46:57.615125 2026] [core:notice] [pid 643573:tid 643812] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:57.618960 2026] [security2:error] [pid 643573:tid 643812] [client 103.215.74.26:30278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAAfxWyxgRnoFKAJ_iuwAAAno"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:57.703751 2026] [security2:error] [pid 642360:tid 642587] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAAZSUkh3e5AhEJOBihQAAAfA"]
[Thu Jul 30 11:46:57.738995 2026] [security2:error] [pid 643573:tid 643660] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/php.php"] [unique_id "amuAAfxWyxgRnoFKAJ_ivAACbE8"]
[Thu Jul 30 11:46:57.739198 2026] [security2:error] [pid 643573:tid 643798] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/php.php"] [unique_id "amuAAfxWyxgRnoFKAJ_ivAACbE8"]
[Thu Jul 30 11:46:57.920581 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:58.059459 2026] [security2:error] [pid 643573:tid 643672] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/100.php"] [unique_id "amuAAvxWyxgRnoFKAJ_ivwACZVs"]
[Thu Jul 30 11:46:58.059655 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/100.php"] [unique_id "amuAAvxWyxgRnoFKAJ_ivwACZVs"]
[Thu Jul 30 11:46:58.168882 2026] [security2:error] [pid 643573:tid 643757] [client 20.91.199.21:17896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuAAvxWyxgRnoFKAJ_iwAAAAkM"]
[Thu Jul 30 11:46:58.348723 2026] [security2:error] [pid 643573:tid 643664] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/BDKR28WP.php"] [unique_id "amuAAvxWyxgRnoFKAJ_iwwACeVM"]
[Thu Jul 30 11:46:58.348896 2026] [security2:error] [pid 643573:tid 643811] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/BDKR28WP.php"] [unique_id "amuAAvxWyxgRnoFKAJ_iwwACeVM"]
[Thu Jul 30 11:46:58.352149 2026] [core:notice] [pid 643573:tid 643746] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:58.356363 2026] [security2:error] [pid 643573:tid 643746] [client 103.215.74.26:30290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAAvxWyxgRnoFKAJ_ixAAAAjg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:59.016830 2026] [security2:error] [pid 643573:tid 643610] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/browse.php"] [unique_id "amuAA_xWyxgRnoFKAJ_iywACgx0"]
[Thu Jul 30 11:46:59.017090 2026] [security2:error] [pid 643573:tid 643821] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/browse.php"] [unique_id "amuAA_xWyxgRnoFKAJ_iywACgx0"]
[Thu Jul 30 11:46:59.079393 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:46:59.084359 2026] [security2:error] [pid 643573:tid 643797] [client 103.215.74.26:30304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAA_xWyxgRnoFKAJ_izAAAAms"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:46:59.306910 2026] [security2:error] [pid 643573:tid 643584] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-good.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i0QACLgM"]
[Thu Jul 30 11:46:59.307115 2026] [security2:error] [pid 643573:tid 643736] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-good.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i0QACLgM"]
[Thu Jul 30 11:46:59.377161 2026] [security2:error] [pid 643573:tid 643836] [client 176.241.66.87:63423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i0gAAApI"]
[Thu Jul 30 11:46:59.377308 2026] [security2:error] [pid 643573:tid 643836] [client 176.241.66.87:63423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i0gAAApI"]
[Thu Jul 30 11:46:59.523083 2026] [security2:error] [pid 642360:tid 642575] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAApSUkh3e5AhEJOBikgAAAeQ"]
[Thu Jul 30 11:46:59.575847 2026] [security2:error] [pid 642360:tid 642547] [client 50.6.43.217:51330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAApSUkh3e5AhEJOBijQAAAcg"]
[Thu Jul 30 11:46:59.611244 2026] [security2:error] [pid 643573:tid 643599] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/8573.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i1AACixI"]
[Thu Jul 30 11:46:59.611433 2026] [security2:error] [pid 643573:tid 643829] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/8573.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i1AACixI"]
[Thu Jul 30 11:46:59.779882 2026] [security2:error] [pid 643573:tid 643764] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAA_xWyxgRnoFKAJ_izwAAAko"]
[Thu Jul 30 11:46:59.947880 2026] [security2:error] [pid 643573:tid 643682] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-admin/install.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i2QACfmU"]
[Thu Jul 30 11:46:59.948092 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-admin/install.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i2QACfmU"]
[Thu Jul 30 11:47:00.240467 2026] [security2:error] [pid 642360:tid 642599] [client 20.91.199.21:4864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/avaa.php"] [unique_id "amuABJSUkh3e5AhEJOBingAAAfw"]
[Thu Jul 30 11:47:00.276102 2026] [security2:error] [pid 643573:tid 643680] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/classwithtostring.php"] [unique_id "amuABPxWyxgRnoFKAJ_i2wACZ2M"]
[Thu Jul 30 11:47:00.276272 2026] [security2:error] [pid 643573:tid 643793] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/classwithtostring.php"] [unique_id "amuABPxWyxgRnoFKAJ_i2wACZ2M"]
[Thu Jul 30 11:47:00.382838 2026] [security2:error] [pid 642360:tid 642561] [client 50.6.43.217:51346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAA5SUkh3e5AhEJOBimQAAAdY"]
[Thu Jul 30 11:47:00.577556 2026] [security2:error] [pid 643573:tid 643603] [remote 97.74.93.24:45906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuABPxWyxgRnoFKAJ_i3gACVxY"]
[Thu Jul 30 11:47:00.587168 2026] [security2:error] [pid 643573:tid 643614] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ohct.php"] [unique_id "amuABPxWyxgRnoFKAJ_i3wACOyE"]
[Thu Jul 30 11:47:00.587347 2026] [security2:error] [pid 643573:tid 643749] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ohct.php"] [unique_id "amuABPxWyxgRnoFKAJ_i3wACOyE"]
[Thu Jul 30 11:47:00.907418 2026] [security2:error] [pid 643573:tid 643677] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bless.php"] [unique_id "amuABPxWyxgRnoFKAJ_i4gACiWA"]
[Thu Jul 30 11:47:00.907633 2026] [security2:error] [pid 643573:tid 643827] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/bless.php"] [unique_id "amuABPxWyxgRnoFKAJ_i4gACiWA"]
[Thu Jul 30 11:47:00.978456 2026] [security2:error] [pid 643573:tid 643721] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAA_xWyxgRnoFKAJ_i1QACHxQ"]
[Thu Jul 30 11:47:01.218880 2026] [security2:error] [pid 643573:tid 643681] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/about.php"] [unique_id "amuABfxWyxgRnoFKAJ_i5gACRWQ"]
[Thu Jul 30 11:47:01.219122 2026] [security2:error] [pid 643573:tid 643759] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/about.php"] [unique_id "amuABfxWyxgRnoFKAJ_i5gACRWQ"]
[Thu Jul 30 11:47:01.379265 2026] [security2:error] [pid 643573:tid 643711] [client 20.91.199.21:4871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/images/cloud.php"] [unique_id "amuABfxWyxgRnoFKAJ_i6AAAAhU"]
[Thu Jul 30 11:47:01.538561 2026] [security2:error] [pid 643573:tid 643662] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuABfxWyxgRnoFKAJ_i7AACg1E"]
[Thu Jul 30 11:47:01.538715 2026] [security2:error] [pid 643573:tid 643821] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuABfxWyxgRnoFKAJ_i7AACg1E"]
[Thu Jul 30 11:47:01.888289 2026] [security2:error] [pid 643573:tid 643617] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ta0ol.php"] [unique_id "amuABfxWyxgRnoFKAJ_i7wACYyQ"]
[Thu Jul 30 11:47:01.888452 2026] [security2:error] [pid 643573:tid 643789] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ta0ol.php"] [unique_id "amuABfxWyxgRnoFKAJ_i7wACYyQ"]
[Thu Jul 30 11:47:02.185989 2026] [security2:error] [pid 643573:tid 643627] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/sa.php7"] [unique_id "amuABvxWyxgRnoFKAJ_i8gACSS4"]
[Thu Jul 30 11:47:02.186223 2026] [security2:error] [pid 643573:tid 643763] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/sa.php7"] [unique_id "amuABvxWyxgRnoFKAJ_i8gACSS4"]
[Thu Jul 30 11:47:02.269587 2026] [security2:error] [pid 643253:tid 643509] [client 20.91.199.21:16290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuABsjqbtjBYzqM1uYk5gAAAH0"]
[Thu Jul 30 11:47:02.488379 2026] [security2:error] [pid 643573:tid 643582] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-class.php"] [unique_id "amuABvxWyxgRnoFKAJ_i-AACIQE"]
[Thu Jul 30 11:47:02.488543 2026] [security2:error] [pid 643573:tid 643723] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-class.php"] [unique_id "amuABvxWyxgRnoFKAJ_i-AACIQE"]
[Thu Jul 30 11:47:02.529632 2026] [security2:error] [pid 643573:tid 643597] [remote 57.141.0.55:28228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/407345907/feed/rss2/"] [unique_id "amuABvxWyxgRnoFKAJ_i-gACghA"]
[Thu Jul 30 11:47:02.649678 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:02.789315 2026] [security2:error] [pid 643573:tid 643613] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/8.php"] [unique_id "amuABvxWyxgRnoFKAJ_i_gACWSA"]
[Thu Jul 30 11:47:02.789540 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/8.php"] [unique_id "amuABvxWyxgRnoFKAJ_i_gACWSA"]
[Thu Jul 30 11:47:03.112570 2026] [security2:error] [pid 643573:tid 643595] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bootstrap.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jAQACPg4"]
[Thu Jul 30 11:47:03.112746 2026] [security2:error] [pid 643573:tid 643752] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/bootstrap.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jAQACPg4"]
[Thu Jul 30 11:47:03.397866 2026] [security2:error] [pid 643573:tid 643686] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-blog-header.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jBAACHWk"]
[Thu Jul 30 11:47:03.398064 2026] [security2:error] [pid 643573:tid 643719] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-blog-header.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jBAACHWk"]
[Thu Jul 30 11:47:03.546046 2026] [security2:error] [pid 643573:tid 643687] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jBgACM2o"]
[Thu Jul 30 11:47:03.546253 2026] [security2:error] [pid 643573:tid 643741] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jBgACM2o"]
[Thu Jul 30 11:47:03.702288 2026] [security2:error] [pid 643573:tid 643694] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/aa.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jDAACQnE"]
[Thu Jul 30 11:47:03.702492 2026] [security2:error] [pid 643573:tid 643756] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/aa.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jDAACQnE"]
[Thu Jul 30 11:47:03.819730 2026] [security2:error] [pid 643573:tid 643755] [client 20.91.199.21:45188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuAB_xWyxgRnoFKAJ_jDQAAAkE"]
[Thu Jul 30 11:47:03.967412 2026] [security2:error] [pid 642360:tid 642449] [remote 74.7.241.60:42596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuAB5SUkh3e5AhEJOBiugAB6lg"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:47:04.004223 2026] [security2:error] [pid 643573:tid 643698] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/tx79.php"] [unique_id "amuACPxWyxgRnoFKAJ_jDgACi3U"]
[Thu Jul 30 11:47:04.004391 2026] [security2:error] [pid 643573:tid 643829] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/tx79.php"] [unique_id "amuACPxWyxgRnoFKAJ_jDgACi3U"]
[Thu Jul 30 11:47:04.327658 2026] [security2:error] [pid 643573:tid 643624] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/motu.php"] [unique_id "amuACPxWyxgRnoFKAJ_jEwACiis"]
[Thu Jul 30 11:47:04.327823 2026] [security2:error] [pid 643573:tid 643828] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/motu.php"] [unique_id "amuACPxWyxgRnoFKAJ_jEwACiis"]
[Thu Jul 30 11:47:04.632782 2026] [security2:error] [pid 643573:tid 643702] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-head.php"] [unique_id "amuACPxWyxgRnoFKAJ_jFQACVHk"]
[Thu Jul 30 11:47:04.632991 2026] [security2:error] [pid 643573:tid 643774] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-head.php"] [unique_id "amuACPxWyxgRnoFKAJ_jFQACVHk"]
[Thu Jul 30 11:47:04.875172 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:04.879937 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:23440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuACMjqbtjBYzqM1uYk5wAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:05.040811 2026] [security2:error] [pid 643573:tid 643594] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuACfxWyxgRnoFKAJ_jGAACFA0"]
[Thu Jul 30 11:47:05.041080 2026] [security2:error] [pid 643573:tid 643710] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuACfxWyxgRnoFKAJ_jGAACFA0"]
[Thu Jul 30 11:47:05.341560 2026] [security2:error] [pid 643573:tid 643675] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/60856e3a4findex.php"] [unique_id "amuACfxWyxgRnoFKAJ_jHwACiV4"]
[Thu Jul 30 11:47:05.341723 2026] [security2:error] [pid 643573:tid 643827] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/60856e3a4findex.php"] [unique_id "amuACfxWyxgRnoFKAJ_jHwACiV4"]
[Thu Jul 30 11:47:05.421472 2026] [security2:error] [pid 643573:tid 643807] [client 20.91.199.21:3234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuACfxWyxgRnoFKAJ_jIQAAAnU"]
[Thu Jul 30 11:47:05.605675 2026] [security2:error] [pid 643573:tid 643685] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-the.php"] [unique_id "amuACfxWyxgRnoFKAJ_jJAACNGg"]
[Thu Jul 30 11:47:05.605874 2026] [security2:error] [pid 643573:tid 643742] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-the.php"] [unique_id "amuACfxWyxgRnoFKAJ_jJAACNGg"]
[Thu Jul 30 11:47:05.609102 2026] [core:notice] [pid 643573:tid 643776] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:05.614072 2026] [security2:error] [pid 643573:tid 643776] [client 103.215.74.26:23444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuACfxWyxgRnoFKAJ_jJQAAAlY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:05.665542 2026] [autoindex:error] [pid 643573:tid 643719] [client 43.157.20.63:52436] AH01276: Cannot serve directory /home1/uixgzjte/public_html/chicago-mfg.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:05.886460 2026] [security2:error] [pid 643573:tid 643693] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp.php"] [unique_id "amuACfxWyxgRnoFKAJ_jLAACKHA"]
[Thu Jul 30 11:47:05.886614 2026] [security2:error] [pid 643573:tid 643730] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp.php"] [unique_id "amuACfxWyxgRnoFKAJ_jLAACKHA"]
[Thu Jul 30 11:47:06.089704 2026] [security2:error] [pid 643573:tid 643746] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuACfxWyxgRnoFKAJ_jIgACOHs"]
[Thu Jul 30 11:47:06.147377 2026] [security2:error] [pid 643573:tid 643692] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/users.php"] [unique_id "amuACvxWyxgRnoFKAJ_jLQACYG8"]
[Thu Jul 30 11:47:06.147620 2026] [security2:error] [pid 643573:tid 643786] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/users.php"] [unique_id "amuACvxWyxgRnoFKAJ_jLQACYG8"]
[Thu Jul 30 11:47:06.354898 2026] [core:notice] [pid 643573:tid 643789] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:06.359291 2026] [security2:error] [pid 643573:tid 643789] [client 103.215.74.26:23452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuACvxWyxgRnoFKAJ_jMgAAAmM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:06.430958 2026] [security2:error] [pid 643573:tid 643701] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/tinysd.php"] [unique_id "amuACvxWyxgRnoFKAJ_jNAACfXg"]
[Thu Jul 30 11:47:06.431126 2026] [security2:error] [pid 643573:tid 643815] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/tinysd.php"] [unique_id "amuACvxWyxgRnoFKAJ_jNAACfXg"]
[Thu Jul 30 11:47:06.719631 2026] [security2:error] [pid 643573:tid 643706] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ws78.php"] [unique_id "amuACvxWyxgRnoFKAJ_jNgACNn0"]
[Thu Jul 30 11:47:06.719772 2026] [security2:error] [pid 643573:tid 643744] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ws78.php"] [unique_id "amuACvxWyxgRnoFKAJ_jNgACNn0"]
[Thu Jul 30 11:47:06.991928 2026] [security2:error] [pid 643573:tid 643649] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/elp.php"] [unique_id "amuACvxWyxgRnoFKAJ_jOAACXEQ"]
[Thu Jul 30 11:47:06.992146 2026] [security2:error] [pid 643573:tid 643782] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/elp.php"] [unique_id "amuACvxWyxgRnoFKAJ_jOAACXEQ"]
[Thu Jul 30 11:47:07.085139 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:07.089831 2026] [security2:error] [pid 643573:tid 643739] [client 103.215.74.26:23454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAC_xWyxgRnoFKAJ_jOQAAAjE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:07.283892 2026] [security2:error] [pid 643573:tid 643696] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/atomlib.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPQACjXM"]
[Thu Jul 30 11:47:07.284218 2026] [security2:error] [pid 643573:tid 643831] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/atomlib.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPQACjXM"]
[Thu Jul 30 11:47:07.527138 2026] [security2:error] [pid 643573:tid 643699] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPwACdXY"]
[Thu Jul 30 11:47:07.527318 2026] [security2:error] [pid 643573:tid 643807] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPwACdXY"]
[Thu Jul 30 11:47:07.575163 2026] [security2:error] [pid 643573:tid 643589] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wyzer3.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jQAACHwg"]
[Thu Jul 30 11:47:07.575343 2026] [security2:error] [pid 643573:tid 643721] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wyzer3.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jQAACHwg"]
[Thu Jul 30 11:47:07.647781 2026] [core:error] [pid 643253:tid 643370] [remote 74.7.244.56:54136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:47:07.647810 2026] [core:error] [pid 643253:tid 643370] [remote 74.7.244.56:54136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:47:07.648002 2026] [security2:error] [pid 643253:tid 643399] [client 74.7.244.56:54136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-d7e4058d.xdi.djb.temporary.site"] [uri "/website_d7e4058d/index.php"] [unique_id "amuAC8jqbtjBYzqM1uYk6QAAD3M"]
[Thu Jul 30 11:47:07.794612 2026] [core:notice] [pid 643573:tid 643785] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:07.822691 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:07.824669 2026] [security2:error] [pid 643573:tid 643825] [client 172.236.9.101:48305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jPAAAAoc"]
[Thu Jul 30 11:47:07.825424 2026] [security2:error] [pid 642360:tid 642551] [client 172.236.9.101:12038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAC5SUkh3e5AhEJOBi1QAAAcw"]
[Thu Jul 30 11:47:07.826008 2026] [security2:error] [pid 642360:tid 642582] [client 172.236.9.101:26530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAC5SUkh3e5AhEJOBi1AAAAes"]
[Thu Jul 30 11:47:07.827502 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:23456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAC_xWyxgRnoFKAJ_jQwAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:07.845539 2026] [security2:error] [pid 643573:tid 643585] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/max.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jRAACRQQ"]
[Thu Jul 30 11:47:07.845691 2026] [security2:error] [pid 643573:tid 643759] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/max.php"] [unique_id "amuAC_xWyxgRnoFKAJ_jRAACRQQ"]
[Thu Jul 30 11:47:08.120567 2026] [security2:error] [pid 643573:tid 643586] [remote 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ftde.php"] [unique_id "amuADPxWyxgRnoFKAJ_jRwACHQU"]
[Thu Jul 30 11:47:08.120838 2026] [security2:error] [pid 643573:tid 643719] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/ftde.php"] [unique_id "amuADPxWyxgRnoFKAJ_jRwACHQU"]
[Thu Jul 30 11:47:08.345701 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:08.564880 2026] [core:notice] [pid 642360:tid 642554] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:08.572617 2026] [security2:error] [pid 642360:tid 642554] [client 103.215.74.26:23458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuADJSUkh3e5AhEJOBi4AAAAc8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:08.793881 2026] [security2:error] [pid 643573:tid 643771] [client 172.236.9.101:44577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jSAAAAlE"]
[Thu Jul 30 11:47:08.825304 2026] [security2:error] [pid 642360:tid 642607] [client 172.236.9.101:49529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADJSUkh3e5AhEJOBi3gAAAgQ"]
[Thu Jul 30 11:47:08.836134 2026] [security2:error] [pid 643573:tid 643741] [client 172.236.9.101:13805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jSQAAAjM"]
[Thu Jul 30 11:47:08.864542 2026] [security2:error] [pid 643573:tid 643745] [client 172.236.9.101:26851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jSgAAAjc"]
[Thu Jul 30 11:47:08.914329 2026] [security2:error] [pid 643573:tid 643783] [client 172.236.9.101:24865] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jTAAAAl0"]
[Thu Jul 30 11:47:08.921417 2026] [security2:error] [pid 643573:tid 643821] [client 172.236.9.101:65397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jSwAAAoM"]
[Thu Jul 30 11:47:08.922272 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:38776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jTgAAApE"]
[Thu Jul 30 11:47:08.939660 2026] [security2:error] [pid 643573:tid 643788] [client 172.236.9.101:5614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADPxWyxgRnoFKAJ_jTQAAAmI"]
[Thu Jul 30 11:47:08.944714 2026] [security2:error] [pid 643573:tid 643786] [client 20.91.199.21:3878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuADPxWyxgRnoFKAJ_jVQAAAmA"]
[Thu Jul 30 11:47:09.290802 2026] [security2:error] [pid 643573:tid 643744] [client 172.236.9.101:34618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/ssl/private/alseermarine.com_key.pem"] [unique_id "amuADfxWyxgRnoFKAJ_jXQAAAjY"]
[Thu Jul 30 11:47:09.292653 2026] [core:notice] [pid 642360:tid 642535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:09.302050 2026] [security2:error] [pid 642360:tid 642535] [client 103.215.74.26:23466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuADZSUkh3e5AhEJOBi6QAAAbw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:09.828579 2026] [security2:error] [pid 643573:tid 643793] [client 172.236.9.101:18283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jWAAAAmc"]
[Thu Jul 30 11:47:09.840739 2026] [security2:error] [pid 643573:tid 643772] [client 172.236.9.101:6631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jWQAAAlI"]
[Thu Jul 30 11:47:09.847553 2026] [security2:error] [pid 643573:tid 643748] [client 172.236.9.101:35087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jVwAAAjo"]
[Thu Jul 30 11:47:09.847638 2026] [security2:error] [pid 643573:tid 643820] [client 172.236.9.101:11812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jWwAAAoI"]
[Thu Jul 30 11:47:09.854828 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:22263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jWgAAAnQ"]
[Thu Jul 30 11:47:09.870811 2026] [security2:error] [pid 642360:tid 642585] [client 172.236.9.101:19118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADZSUkh3e5AhEJOBi6AAAAe4"]
[Thu Jul 30 11:47:09.872521 2026] [security2:error] [pid 643573:tid 643775] [client 172.236.9.101:12574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jXAAAAlU"]
[Thu Jul 30 11:47:09.881784 2026] [security2:error] [pid 643573:tid 643747] [client 172.236.9.101:59906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuADfxWyxgRnoFKAJ_jXgAAAjk"]
[Thu Jul 30 11:47:10.021459 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:10.026670 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:23470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuADvxWyxgRnoFKAJ_jZgAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:10.168708 2026] [security2:error] [pid 643573:tid 643798] [client 176.241.66.87:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuADvxWyxgRnoFKAJ_jaQAAAmw"]
[Thu Jul 30 11:47:10.168866 2026] [security2:error] [pid 643573:tid 643798] [client 176.241.66.87:55020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuADvxWyxgRnoFKAJ_jaQAAAmw"]
[Thu Jul 30 11:47:10.602742 2026] [security2:error] [pid 642360:tid 642530] [client 20.91.199.21:15900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuADpSUkh3e5AhEJOBi8gAAAbc"]
[Thu Jul 30 11:47:10.751693 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:10.757120 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:23480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuADvxWyxgRnoFKAJ_jcQAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:10.771270 2026] [security2:error] [pid 642360:tid 642536] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuADpSUkh3e5AhEJOBi7gABvWw"]
[Thu Jul 30 11:47:11.282176 2026] [security2:error] [pid 643573:tid 643821] [client 20.91.199.21:4868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/cloud.php"] [unique_id "amuAD_xWyxgRnoFKAJ_jcwAAAoM"]
[Thu Jul 30 11:47:11.493095 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:11.497198 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:23492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAD_xWyxgRnoFKAJ_jeQAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:12.201549 2026] [security2:error] [pid 643573:tid 643623] [remote 57.141.0.9:63170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amuAEPxWyxgRnoFKAJ_jgAACOSo"]
[Thu Jul 30 11:47:12.210737 2026] [security2:error] [pid 643573:tid 643827] [client 47.128.48.248:39884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/robots.txt"] [unique_id "amuAEPxWyxgRnoFKAJ_jgQAAAok"]
[Thu Jul 30 11:47:12.215949 2026] [core:notice] [pid 643573:tid 643799] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:12.219943 2026] [security2:error] [pid 643573:tid 643799] [client 103.215.74.26:23494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAEPxWyxgRnoFKAJ_jggAAAm0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:12.869535 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:12.968546 2026] [core:notice] [pid 643573:tid 643726] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:12.973043 2026] [security2:error] [pid 643573:tid 643726] [client 103.215.74.26:23504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAEPxWyxgRnoFKAJ_jiwAAAiQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:13.456429 2026] [security2:error] [pid 643573:tid 643736] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAEPxWyxgRnoFKAJ_jiAAAAi4"]
[Thu Jul 30 11:47:13.721857 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:13.728410 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:4630] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAEfxWyxgRnoFKAJ_jjgAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:14.211897 2026] [security2:error] [pid 643573:tid 643608] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAEvxWyxgRnoFKAJ_jkgACihs"]
[Thu Jul 30 11:47:14.212108 2026] [security2:error] [pid 643573:tid 643828] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAEvxWyxgRnoFKAJ_jkgACihs"]
[Thu Jul 30 11:47:14.468055 2026] [security2:error] [pid 642360:tid 642503] [client 68.221.186.136:42574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/json.php"] [unique_id "amuAEpSUkh3e5AhEJOBjEQAAAZw"]
[Thu Jul 30 11:47:14.473116 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:14.479712 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:4642] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAEvxWyxgRnoFKAJ_jlQAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:14.601240 2026] [security2:error] [pid 643573:tid 643837] [client 20.91.199.21:3708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/updates.php"] [unique_id "amuAEvxWyxgRnoFKAJ_jmAAAApM"]
[Thu Jul 30 11:47:15.229770 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:15.233807 2026] [security2:error] [pid 643573:tid 643793] [client 103.215.74.26:4650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAE_xWyxgRnoFKAJ_jnQAAAmc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:15.335705 2026] [security2:error] [pid 642360:tid 642602] [client 68.221.186.136:44356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/mini.php"] [unique_id "amuAE5SUkh3e5AhEJOBjGgAAAf8"]
[Thu Jul 30 11:47:15.407966 2026] [security2:error] [pid 642360:tid 642544] [client 20.91.199.21:6913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/libraries/legacy/updates.php"] [unique_id "amuAE5SUkh3e5AhEJOBjGwAAAcU"]
[Thu Jul 30 11:47:15.543119 2026] [security2:error] [pid 643573:tid 643777] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAEvxWyxgRnoFKAJ_jmgACVzA"]
[Thu Jul 30 11:47:15.974303 2026] [core:notice] [pid 643573:tid 643827] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:15.981180 2026] [security2:error] [pid 643573:tid 643827] [client 103.215.74.26:4652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAE_xWyxgRnoFKAJ_jpgAAAok"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:16.426390 2026] [security2:error] [pid 643573:tid 643780] [client 68.221.186.136:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amuAFPxWyxgRnoFKAJ_jrgAAAlo"]
[Thu Jul 30 11:47:16.710560 2026] [core:notice] [pid 643573:tid 643730] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:16.717347 2026] [security2:error] [pid 643573:tid 643730] [client 103.215.74.26:4658] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAFPxWyxgRnoFKAJ_jsQAAAig"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:16.801559 2026] [security2:error] [pid 642360:tid 642424] [remote 208.122.213.225:40632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuAFJSUkh3e5AhEJOBjJgAB2D8"]
[Thu Jul 30 11:47:17.464043 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:17.468761 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:4660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAFfxWyxgRnoFKAJ_juAAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:17.877234 2026] [core:notice] [pid 643573:tid 643784] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:18.201832 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:18.207191 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:4672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAFpSUkh3e5AhEJOBjNAAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:18.295157 2026] [security2:error] [pid 643253:tid 643474] [client 34.91.115.13:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.alseermarine.com"] [uri "/"] [unique_id "amuAFsjqbtjBYzqM1uYk9AAAAFo"], referer: https://alseermarine.ae/
[Thu Jul 30 11:47:18.295244 2026] [security2:error] [pid 643253:tid 643474] [client 34.91.115.13:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/"] [unique_id "amuAFsjqbtjBYzqM1uYk9AAAAFo"], referer: https://alseermarine.ae/
[Thu Jul 30 11:47:18.504727 2026] [security2:error] [pid 642360:tid 642432] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAFpSUkh3e5AhEJOBjNwABqEc"]
[Thu Jul 30 11:47:18.504931 2026] [security2:error] [pid 642360:tid 642515] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAFpSUkh3e5AhEJOBjNwABqEc"]
[Thu Jul 30 11:47:18.959516 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:18.963751 2026] [security2:error] [pid 643573:tid 643713] [client 103.215.74.26:4678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAFvxWyxgRnoFKAJ_jxwAAAhc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:19.491148 2026] [security2:error] [pid 643573:tid 643724] [client 20.91.199.21:5341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuAF_xWyxgRnoFKAJ_jzQAAAiI"]
[Thu Jul 30 11:47:19.682568 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:19.686618 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:4690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAF_xWyxgRnoFKAJ_j0AAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:20.179137 2026] [security2:error] [pid 643573:tid 643816] [client 198.54.128.138:34936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuAGPxWyxgRnoFKAJ_j1AAAAn4"]
[Thu Jul 30 11:47:20.179296 2026] [security2:error] [pid 643573:tid 643816] [client 198.54.128.138:34936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuAGPxWyxgRnoFKAJ_j1AAAAn4"]
[Thu Jul 30 11:47:20.278779 2026] [core:notice] [pid 643573:tid 643818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:20.434478 2026] [security2:error] [pid 643573:tid 643722] [client 127.0.0.1:18536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuAGPxWyxgRnoFKAJ_j2wAAAiA"]
[Thu Jul 30 11:47:20.434503 2026] [security2:error] [pid 643573:tid 643822] [client 127.0.0.1:18534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.qpsuae.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuAGPxWyxgRnoFKAJ_j2gAAAoQ"]
[Thu Jul 30 11:47:20.434614 2026] [security2:error] [pid 642360:tid 642499] [client 74.7.228.50:40764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.qpsuae.com"] [uri "/robots.txt"] [unique_id "amuAGJSUkh3e5AhEJOBjSAABmEo"]
[Thu Jul 30 11:47:20.436608 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:20.440989 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:4700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAGPxWyxgRnoFKAJ_j3AAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:20.765675 2026] [security2:error] [pid 643253:tid 643435] [client 176.241.66.87:65487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAGMjqbtjBYzqM1uYk9QAAADM"]
[Thu Jul 30 11:47:20.765824 2026] [security2:error] [pid 643253:tid 643435] [client 176.241.66.87:65487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAGMjqbtjBYzqM1uYk9QAAADM"]
[Thu Jul 30 11:47:20.944795 2026] [core:notice] [pid 643573:tid 643799] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:21.161962 2026] [security2:error] [pid 642360:tid 642601] [client 152.232.72.98:48987] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAGJSUkh3e5AhEJOBjTgAAAf4"]
[Thu Jul 30 11:47:21.162114 2026] [security2:error] [pid 642360:tid 642601] [client 152.232.72.98:48987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAGJSUkh3e5AhEJOBjTgAAAf4"]
[Thu Jul 30 11:47:21.166210 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:21.170116 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:4706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAGfxWyxgRnoFKAJ_j6gAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:21.171224 2026] [security2:error] [pid 643573:tid 643791] [client 103.253.27.196:61055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuAGfxWyxgRnoFKAJ_j6wAAAmU"]
[Thu Jul 30 11:47:21.410947 2026] [security2:error] [pid 643573:tid 643710] [client 68.221.186.136:45302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/kj.php"] [unique_id "amuAGfxWyxgRnoFKAJ_j7gAAAhQ"]
[Thu Jul 30 11:47:21.417647 2026] [security2:error] [pid 643573:tid 643759] [client 20.91.199.21:3935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/libraries/vendor/updates.php"] [unique_id "amuAGfxWyxgRnoFKAJ_j7wAAAkU"]
[Thu Jul 30 11:47:22.039811 2026] [core:notice] [pid 642360:tid 642503] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:22.046044 2026] [security2:error] [pid 642360:tid 642503] [client 103.253.27.196:61120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/xmlrpc.php"] [unique_id "amuAGZSUkh3e5AhEJOBjVwAAAZw"]
[Thu Jul 30 11:47:22.079634 2026] [security2:error] [pid 643573:tid 643768] [client 68.221.186.136:44961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-files.php"] [unique_id "amuAGvxWyxgRnoFKAJ_j9gAAAk4"]
[Thu Jul 30 11:47:22.259003 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:22.286077 2026] [lsapi:error] [pid 643573:tid 643674] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/keeper-vj-junior/
[Thu Jul 30 11:47:22.624252 2026] [security2:error] [pid 642360:tid 642610] [client 103.253.27.196:61120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuAGpSUkh3e5AhEJOBjZAAAAgc"]
[Thu Jul 30 11:47:22.822032 2026] [security2:error] [pid 643253:tid 643480] [client 152.232.72.98:38532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAGsjqbtjBYzqM1uYk-wAAAGA"]
[Thu Jul 30 11:47:22.886846 2026] [core:notice] [pid 642360:tid 642541] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:23.049880 2026] [security2:error] [pid 643253:tid 643480] [client 152.232.72.98:38532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAGsjqbtjBYzqM1uYk-wAAAGA"]
[Thu Jul 30 11:47:23.076124 2026] [security2:error] [pid 642360:tid 642613] [client 103.253.27.196:61215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuAG5SUkh3e5AhEJOBjbQAAAgo"]
[Thu Jul 30 11:47:23.236559 2026] [security2:error] [pid 643573:tid 643749] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAGvxWyxgRnoFKAJ_j-gAAAjs"]
[Thu Jul 30 11:47:23.424267 2026] [security2:error] [pid 643573:tid 643820] [client 103.253.27.196:61233] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuAG_xWyxgRnoFKAJ_kBAAAAoI"]
[Thu Jul 30 11:47:23.728810 2026] [security2:error] [pid 643573:tid 643822] [client 116.172.248.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuAGvxWyxgRnoFKAJ_j_gAAAoQ"]
[Thu Jul 30 11:47:24.029207 2026] [security2:error] [pid 643253:tid 643443] [client 103.253.27.196:61251] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuAHMjqbtjBYzqM1uYk_QAAADs"]
[Thu Jul 30 11:47:24.040545 2026] [security2:error] [pid 643573:tid 643744] [client 68.221.186.136:43027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-setup.php"] [unique_id "amuAHPxWyxgRnoFKAJ_kEwAAAjY"]
[Thu Jul 30 11:47:24.203392 2026] [security2:error] [pid 643253:tid 643402] [client 103.253.27.196:61275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuAHMjqbtjBYzqM1uYk_wAAABI"]
[Thu Jul 30 11:47:24.232324 2026] [security2:error] [pid 643573:tid 643731] [client 5.255.231.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAHPxWyxgRnoFKAJ_kFgAAAik"]
[Thu Jul 30 11:47:24.235066 2026] [security2:error] [pid 643573:tid 643812] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAG_xWyxgRnoFKAJ_kCgAAAno"]
[Thu Jul 30 11:47:24.405947 2026] [security2:error] [pid 643573:tid 643783] [client 103.253.27.196:61285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuAHPxWyxgRnoFKAJ_kGAAAAl0"]
[Thu Jul 30 11:47:24.427213 2026] [security2:error] [pid 643573:tid 643722] [client 20.91.199.21:17915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/alfa-rex.php7"] [unique_id "amuAHPxWyxgRnoFKAJ_kGQAAAiA"]
[Thu Jul 30 11:47:24.479804 2026] [security2:error] [pid 643253:tid 643398] [client 152.232.72.98:53927] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAHMjqbtjBYzqM1uYlAAAAAA4"]
[Thu Jul 30 11:47:24.705320 2026] [security2:error] [pid 643253:tid 643398] [client 152.232.72.98:53927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAHMjqbtjBYzqM1uYlAAAAAA4"]
[Thu Jul 30 11:47:24.753674 2026] [security2:error] [pid 643573:tid 643815] [client 103.253.27.196:61303] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuAHPxWyxgRnoFKAJ_kIAAAAn0"]
[Thu Jul 30 11:47:24.791320 2026] [security2:error] [pid 642360:tid 642585] [client 62.102.148.185:55518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marlboro-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAHJSUkh3e5AhEJOBjewAAAe4"]
[Thu Jul 30 11:47:24.791447 2026] [security2:error] [pid 642360:tid 642585] [client 62.102.148.185:55518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marlboro-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAHJSUkh3e5AhEJOBjewAAAe4"]
[Thu Jul 30 11:47:24.868149 2026] [security2:error] [pid 642360:tid 642419] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAHJSUkh3e5AhEJOBjfAABszo"]
[Thu Jul 30 11:47:24.868365 2026] [security2:error] [pid 642360:tid 642526] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAHJSUkh3e5AhEJOBjfAABszo"]
[Thu Jul 30 11:47:25.088401 2026] [security2:error] [pid 642360:tid 642519] [client 103.253.27.196:61316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuAHZSUkh3e5AhEJOBjgAAAAaw"]
[Thu Jul 30 11:47:25.496011 2026] [security2:error] [pid 643573:tid 643721] [client 103.253.27.196:61343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuAHfxWyxgRnoFKAJ_kIwAAAh8"]
[Thu Jul 30 11:47:25.876567 2026] [security2:error] [pid 643573:tid 643795] [client 103.253.27.196:61363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuAHfxWyxgRnoFKAJ_kKQAAAmk"]
[Thu Jul 30 11:47:26.001427 2026] [core:notice] [pid 642360:tid 642454] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:26.239175 2026] [security2:error] [pid 643573:tid 643810] [client 103.253.27.196:61378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuAHvxWyxgRnoFKAJ_kLgAAAng"]
[Thu Jul 30 11:47:26.358028 2026] [security2:error] [pid 643253:tid 643493] [client 152.232.72.98:57810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAHsjqbtjBYzqM1uYlAQAAAG0"]
[Thu Jul 30 11:47:26.586138 2026] [security2:error] [pid 643253:tid 643493] [client 152.232.72.98:57810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAHsjqbtjBYzqM1uYlAQAAAG0"]
[Thu Jul 30 11:47:26.604138 2026] [security2:error] [pid 642360:tid 642502] [client 103.253.27.196:61401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuAHpSUkh3e5AhEJOBjiQAAAZs"]
[Thu Jul 30 11:47:26.891283 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:26.895223 2026] [security2:error] [pid 643573:tid 643771] [client 103.215.74.26:39658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAHvxWyxgRnoFKAJ_kNwAAAlE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:26.985438 2026] [security2:error] [pid 642360:tid 642499] [client 103.253.27.196:61421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuAHpSUkh3e5AhEJOBjjgAAAZg"]
[Thu Jul 30 11:47:27.394933 2026] [security2:error] [pid 643253:tid 643409] [client 103.253.27.196:61439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ejournalugj.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuAH8jqbtjBYzqM1uYlBAAAABk"]
[Thu Jul 30 11:47:27.456189 2026] [security2:error] [pid 643573:tid 643789] [client 20.91.199.21:3879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/alfanew.php"] [unique_id "amuAH_xWyxgRnoFKAJ_kOgAAAmM"]
[Thu Jul 30 11:47:27.617567 2026] [core:notice] [pid 643573:tid 643740] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:27.622972 2026] [security2:error] [pid 643573:tid 643740] [client 103.215.74.26:39674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAH_xWyxgRnoFKAJ_kPgAAAjI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:28.189308 2026] [security2:error] [pid 643253:tid 643447] [client 153.0.81.232:57412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuAHsjqbtjBYzqM1uYlAgAAAFY"]
[Thu Jul 30 11:47:28.207244 2026] [security2:error] [pid 643573:tid 643806] [client 20.91.199.21:3873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuAIPxWyxgRnoFKAJ_kRQAAAnQ"]
[Thu Jul 30 11:47:28.230364 2026] [security2:error] [pid 642360:tid 642533] [client 68.221.186.136:44358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/defaults.php"] [unique_id "amuAIJSUkh3e5AhEJOBjlwAAAbo"]
[Thu Jul 30 11:47:28.354423 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:28.362000 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:39678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAIPxWyxgRnoFKAJ_kSQAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:28.477394 2026] [security2:error] [pid 642360:tid 642457] [remote 57.141.0.50:42940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuAIJSUkh3e5AhEJOBjnAABx2A"]
[Thu Jul 30 11:47:28.491365 2026] [security2:error] [pid 643573:tid 643747] [client 152.232.72.98:49795] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAIPxWyxgRnoFKAJ_kSwAAAjk"]
[Thu Jul 30 11:47:28.719026 2026] [security2:error] [pid 643573:tid 643747] [client 152.232.72.98:49795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuAIPxWyxgRnoFKAJ_kSwAAAjk"]
[Thu Jul 30 11:47:28.888654 2026] [security2:error] [pid 643573:tid 643768] [client 20.91.199.21:6947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuAIPxWyxgRnoFKAJ_kZgAAAk4"]
[Thu Jul 30 11:47:29.112605 2026] [core:notice] [pid 643573:tid 643764] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:29.117124 2026] [security2:error] [pid 643573:tid 643764] [client 103.215.74.26:39680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAIfxWyxgRnoFKAJ_kbgAAAko"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:29.338891 2026] [security2:error] [pid 643573:tid 643765] [client 68.221.186.136:26708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/gtc.php"] [unique_id "amuAIfxWyxgRnoFKAJ_kcQAAAks"]
[Thu Jul 30 11:47:29.357208 2026] [security2:error] [pid 643573:tid 643735] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAIPxWyxgRnoFKAJ_kVwACLVA"]
[Thu Jul 30 11:47:29.384121 2026] [security2:error] [pid 642360:tid 642446] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAIZSUkh3e5AhEJOBjogACB1U"]
[Thu Jul 30 11:47:29.384282 2026] [security2:error] [pid 642360:tid 642610] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAIZSUkh3e5AhEJOBjogACB1U"]
[Thu Jul 30 11:47:29.418740 2026] [security2:error] [pid 643573:tid 643584] [remote 57.141.0.36:42448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/issue/view/571"] [unique_id "amuAIfxWyxgRnoFKAJ_kcgACFwM"]
[Thu Jul 30 11:47:29.537022 2026] [security2:error] [pid 642360:tid 642587] [client 20.91.199.21:3653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-p.php7"] [unique_id "amuAIZSUkh3e5AhEJOBjpQAAAfA"]
[Thu Jul 30 11:47:29.844709 2026] [core:notice] [pid 643573:tid 643715] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:29.849311 2026] [security2:error] [pid 643573:tid 643715] [client 103.215.74.26:39696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAIfxWyxgRnoFKAJ_kfQAAAhk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:30.582314 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:30.586638 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:39698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAIvxWyxgRnoFKAJ_kgQAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:31.304938 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:31.309507 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:39702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAI_xWyxgRnoFKAJ_khgAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:31.349470 2026] [security2:error] [pid 643573:tid 643793] [client 176.241.66.87:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAI_xWyxgRnoFKAJ_khwAAAmc"]
[Thu Jul 30 11:47:31.349615 2026] [security2:error] [pid 643573:tid 643793] [client 176.241.66.87:1931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAI_xWyxgRnoFKAJ_khwAAAmc"]
[Thu Jul 30 11:47:31.701692 2026] [security2:error] [pid 643573:tid 643741] [client 68.221.186.136:42599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/import.php"] [unique_id "amuAI_xWyxgRnoFKAJ_kigAAAjM"]
[Thu Jul 30 11:47:34.511804 2026] [security2:error] [pid 643573:tid 643771] [client 20.91.199.21:4905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-admin/repeater.php"] [unique_id "amuAJvxWyxgRnoFKAJ_koQAAAlE"]
[Thu Jul 30 11:47:35.451363 2026] [security2:error] [pid 643573:tid 643677] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAJ_xWyxgRnoFKAJ_ktwACKGA"]
[Thu Jul 30 11:47:35.451543 2026] [security2:error] [pid 643573:tid 643730] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAJ_xWyxgRnoFKAJ_ktwACKGA"]
[Thu Jul 30 11:47:35.942737 2026] [security2:error] [pid 642360:tid 642611] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAJ5SUkh3e5AhEJOBj0wACCHE"]
[Thu Jul 30 11:47:36.270367 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:36.337157 2026] [security2:error] [pid 643573:tid 643791] [client 20.91.199.21:13646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-includes/repeater.php"] [unique_id "amuAKPxWyxgRnoFKAJ_kxwAAAmU"]
[Thu Jul 30 11:47:36.563189 2026] [security2:error] [pid 642360:tid 642523] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAJ5SUkh3e5AhEJOBj2QAAAbA"]
[Thu Jul 30 11:47:37.025269 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:37.029876 2026] [security2:error] [pid 642360:tid 642561] [client 103.215.74.26:42712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAKZSUkh3e5AhEJOBj5QAAAdY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:37.701458 2026] [security2:error] [pid 643253:tid 643486] [client 20.91.199.21:41085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/wp-content/repeater.php"] [unique_id "amuAKcjqbtjBYzqM1uYlDgAAAGY"]
[Thu Jul 30 11:47:37.789617 2026] [core:notice] [pid 642360:tid 642610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:37.793906 2026] [security2:error] [pid 642360:tid 642610] [client 103.215.74.26:42716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAKZSUkh3e5AhEJOBj8wAAAgc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:37.916959 2026] [security2:error] [pid 643573:tid 643711] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAKfxWyxgRnoFKAJ_k0AAAAhU"]
[Thu Jul 30 11:47:38.186073 2026] [security2:error] [pid 643573:tid 643742] [client 68.221.186.136:44371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/lufix.php"] [unique_id "amuAKvxWyxgRnoFKAJ_k2wAAAjQ"]
[Thu Jul 30 11:47:38.395156 2026] [security2:error] [pid 643573:tid 643787] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aaapropertiesph.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuAKvxWyxgRnoFKAJ_k3gAAAmE"]
[Thu Jul 30 11:47:38.522615 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:38.527356 2026] [security2:error] [pid 642360:tid 642510] [client 103.215.74.26:42724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAKpSUkh3e5AhEJOBj_AAAAaM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:38.567215 2026] [core:notice] [pid 643573:tid 643698] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:39.098564 2026] [security2:error] [pid 643573:tid 643831] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aaapropertiesph.com"] [uri "/media/system/js/core.js"] [unique_id "amuAK_xWyxgRnoFKAJ_k5wAAAo0"]
[Thu Jul 30 11:47:39.175922 2026] [core:notice] [pid 643573:tid 643702] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:39.236570 2026] [security2:error] [pid 643573:tid 643747] [client 103.156.16.241:50373] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAKvxWyxgRnoFKAJ_k4QAAAjk"]
[Thu Jul 30 11:47:39.260870 2026] [core:notice] [pid 643573:tid 643727] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:39.264878 2026] [security2:error] [pid 643573:tid 643727] [client 103.215.74.26:42730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAK_xWyxgRnoFKAJ_k6gAAAiU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:39.956514 2026] [security2:error] [pid 643573:tid 643764] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAK_xWyxgRnoFKAJ_k7gAAAko"]
[Thu Jul 30 11:47:39.980049 2026] [core:notice] [pid 643573:tid 643735] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:39.983931 2026] [security2:error] [pid 643573:tid 643735] [client 103.215.74.26:42734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAK_xWyxgRnoFKAJ_k9AAAAi0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:40.389584 2026] [security2:error] [pid 643573:tid 643827] [client 68.221.186.136:26948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/Geforce.php"] [unique_id "amuALPxWyxgRnoFKAJ_k-AAAAok"]
[Thu Jul 30 11:47:40.548287 2026] [security2:error] [pid 643573:tid 643697] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuALPxWyxgRnoFKAJ_k_AACWXQ"]
[Thu Jul 30 11:47:40.548449 2026] [security2:error] [pid 643573:tid 643779] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuALPxWyxgRnoFKAJ_k_AACWXQ"]
[Thu Jul 30 11:47:40.719223 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:40.723162 2026] [security2:error] [pid 643573:tid 643713] [client 103.215.74.26:42742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuALPxWyxgRnoFKAJ_k_QAAAhc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:41.448036 2026] [core:notice] [pid 643573:tid 643789] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:41.452506 2026] [security2:error] [pid 643573:tid 643789] [client 103.215.74.26:42744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuALfxWyxgRnoFKAJ_lCQAAAmM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:41.944261 2026] [security2:error] [pid 643573:tid 643813] [client 176.241.66.87:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuALfxWyxgRnoFKAJ_lEgAAAns"]
[Thu Jul 30 11:47:41.944393 2026] [security2:error] [pid 643573:tid 643813] [client 176.241.66.87:2788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuALfxWyxgRnoFKAJ_lEgAAAns"]
[Thu Jul 30 11:47:42.025530 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:42.190519 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:42.198400 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:42754] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuALvxWyxgRnoFKAJ_lIAAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:42.274718 2026] [autoindex:error] [pid 643573:tid 643743] [client 185.247.137.125:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.otbola.click:2086
[Thu Jul 30 11:47:42.596047 2026] [security2:error] [pid 643573:tid 643729] [client 180.163.29.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuALfxWyxgRnoFKAJ_lDAAAAic"]
[Thu Jul 30 11:47:42.924805 2026] [core:notice] [pid 643573:tid 643714] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:42.932438 2026] [security2:error] [pid 643573:tid 643714] [client 103.215.74.26:42756] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuALvxWyxgRnoFKAJ_lJQAAAhg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:43.580936 2026] [proxy:error] [pid 643573:tid 643762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:43.581023 2026] [proxy_http:error] [pid 643573:tid 643762] [client 44.216.125.112:12225] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:43.581594 2026] [proxy:error] [pid 643573:tid 643762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:43.581638 2026] [proxy_http:error] [pid 643573:tid 643762] [client 44.216.125.112:12225] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:43.582657 2026] [autoindex:error] [pid 642360:tid 642577] [client 18.211.55.47:12735] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:43.633334 2026] [autoindex:error] [pid 642360:tid 642586] [client 44.216.125.112:65052] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:43.638251 2026] [autoindex:error] [pid 643573:tid 643740] [client 18.211.55.47:35560] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:43.646718 2026] [proxy:error] [pid 643573:tid 643804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:43.646793 2026] [proxy_http:error] [pid 643573:tid 643804] [client 18.211.55.47:63268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:43.647371 2026] [proxy:error] [pid 643573:tid 643804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:43.647417 2026] [proxy_http:error] [pid 643573:tid 643804] [client 18.211.55.47:63268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:43.657535 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:43.661404 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:19608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAL_xWyxgRnoFKAJ_lNAAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:43.996725 2026] [security2:error] [pid 643573:tid 643707] [remote 95.108.213.147:50408] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/enhancing-project-management-processes-with-business-consulting/"] [unique_id "amuAL_xWyxgRnoFKAJ_lOQACcX4"]
[Thu Jul 30 11:47:44.395374 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:44.399627 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:19624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAMPxWyxgRnoFKAJ_lPgAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:44.438161 2026] [security2:error] [pid 643573:tid 643785] [client 68.221.186.136:43885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/a4.php"] [unique_id "amuAMPxWyxgRnoFKAJ_lPwAAAl8"]
[Thu Jul 30 11:47:45.133424 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:45.140783 2026] [security2:error] [pid 643573:tid 643801] [client 103.215.74.26:19634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAMfxWyxgRnoFKAJ_lSQAAAm8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:45.239615 2026] [security2:error] [pid 643573:tid 643750] [client 68.221.186.136:27863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/011i.php"] [unique_id "amuAMfxWyxgRnoFKAJ_lSwAAAjw"]
[Thu Jul 30 11:47:45.871286 2026] [core:notice] [pid 643573:tid 643730] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:45.875349 2026] [security2:error] [pid 643573:tid 643730] [client 103.215.74.26:19644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAMfxWyxgRnoFKAJ_lUgAAAig"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:46.015223 2026] [security2:error] [pid 643573:tid 643705] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lVwACXXw"]
[Thu Jul 30 11:47:46.015382 2026] [security2:error] [pid 643573:tid 643783] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lVwACXXw"]
[Thu Jul 30 11:47:46.339130 2026] [security2:error] [pid 643573:tid 643797] [client 68.221.186.136:43494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/accueil.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lWwAAAms"]
[Thu Jul 30 11:47:46.572460 2026] [security2:error] [pid 643573:tid 643802] [client 68.221.186.136:41254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/03a005685d.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lXwAAAnA"]
[Thu Jul 30 11:47:46.609109 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:46.613255 2026] [security2:error] [pid 643573:tid 643712] [client 103.215.74.26:19646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAMvxWyxgRnoFKAJ_lYAAAAhY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:46.889723 2026] [security2:error] [pid 643573:tid 643772] [client 68.221.186.136:43066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/dashboard.php"] [unique_id "amuAMvxWyxgRnoFKAJ_lZwAAAlI"]
[Thu Jul 30 11:47:47.338131 2026] [core:notice] [pid 643573:tid 643819] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:47.342242 2026] [security2:error] [pid 643573:tid 643819] [client 103.215.74.26:19650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAM_xWyxgRnoFKAJ_lcQAAAoE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:47.674621 2026] [security2:error] [pid 642360:tid 642528] [client 68.221.186.136:44183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/radio.php"] [unique_id "amuAM5SUkh3e5AhEJOBkYAAAAbU"]
[Thu Jul 30 11:47:47.947356 2026] [security2:error] [pid 643573:tid 643747] [client 103.156.16.241:50373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAKvxWyxgRnoFKAJ_k4QAAAjk"]
[Thu Jul 30 11:47:47.947419 2026] [security2:error] [pid 643573:tid 643747] [client 103.156.16.241:50373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAKvxWyxgRnoFKAJ_k4QAAAjk"]
[Thu Jul 30 11:47:48.058659 2026] [core:notice] [pid 642360:tid 642499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:48.066938 2026] [security2:error] [pid 642360:tid 642499] [client 103.215.74.26:19664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuANJSUkh3e5AhEJOBkZQAAAZg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:48.265354 2026] [security2:error] [pid 643573:tid 643712] [client 68.221.186.136:44989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wpsml-sys.php"] [unique_id "amuANPxWyxgRnoFKAJ_leQAAAhY"]
[Thu Jul 30 11:47:48.339209 2026] [security2:error] [pid 643573:tid 643815] [client 68.221.186.136:41238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/403.php"] [unique_id "amuANPxWyxgRnoFKAJ_lewAAAn0"]
[Thu Jul 30 11:47:48.437913 2026] [security2:error] [pid 643573:tid 643808] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAM_xWyxgRnoFKAJ_ldQACdhM"]
[Thu Jul 30 11:47:48.784355 2026] [security2:error] [pid 643253:tid 643432] [client 103.156.16.241:50586] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuANMjqbtjBYzqM1uYlFwAAADA"]
[Thu Jul 30 11:47:48.796065 2026] [core:notice] [pid 643573:tid 643792] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:48.803572 2026] [security2:error] [pid 643573:tid 643792] [client 103.215.74.26:19680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuANPxWyxgRnoFKAJ_lhQAAAmY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:48.815479 2026] [security2:error] [pid 643573:tid 643739] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuANPxWyxgRnoFKAJ_lggAAAjE"]
[Thu Jul 30 11:47:48.940659 2026] [security2:error] [pid 643573:tid 643830] [client 68.221.186.136:41220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/404.php"] [unique_id "amuANPxWyxgRnoFKAJ_lhgAAAow"]
[Thu Jul 30 11:47:49.156439 2026] [security2:error] [pid 642360:tid 642584] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuANJSUkh3e5AhEJOBkaAAB7S0"]
[Thu Jul 30 11:47:49.371007 2026] [security2:error] [pid 642360:tid 642566] [client 68.221.186.136:42580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/02.php"] [unique_id "amuANZSUkh3e5AhEJOBkdAAAAds"]
[Thu Jul 30 11:47:49.530372 2026] [core:notice] [pid 642360:tid 642577] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:49.536741 2026] [security2:error] [pid 642360:tid 642577] [client 103.215.74.26:19692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuANZSUkh3e5AhEJOBkdQAAAeY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:49.641826 2026] [security2:error] [pid 643253:tid 643432] [client 103.156.16.241:50586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuANMjqbtjBYzqM1uYlFwAAADA"]
[Thu Jul 30 11:47:50.120479 2026] [security2:error] [pid 643573:tid 643758] [client 68.221.186.136:41229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/aa.php"] [unique_id "amuANvxWyxgRnoFKAJ_ljgAAAkQ"]
[Thu Jul 30 11:47:50.154785 2026] [security2:error] [pid 642360:tid 642587] [client 185.191.171.1:49266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/17/carioca-flamengo-sai-da-frente-do-vasco-na-busca-de-vaga-para-a-final/"] [unique_id "amuANpSUkh3e5AhEJOBkfAAAAfA"]
[Thu Jul 30 11:47:50.154942 2026] [security2:error] [pid 642360:tid 642587] [client 185.191.171.1:49266] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/17/carioca-flamengo-sai-da-frente-do-vasco-na-busca-de-vaga-para-a-final/"] [unique_id "amuANpSUkh3e5AhEJOBkfAAAAfA"]
[Thu Jul 30 11:47:50.263400 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:50.269350 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:19698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuANvxWyxgRnoFKAJ_lkAAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:50.768570 2026] [autoindex:error] [pid 643573:tid 643813] [client 207.175.47.108:61346] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:47:50.844265 2026] [security2:error] [pid 642360:tid 642518] [client 68.221.186.136:25309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/infos.php"] [unique_id "amuANpSUkh3e5AhEJOBkggAAAas"]
[Thu Jul 30 11:47:51.027042 2026] [core:notice] [pid 643573:tid 643744] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:51.031583 2026] [security2:error] [pid 643573:tid 643744] [client 103.215.74.26:19714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAN_xWyxgRnoFKAJ_lmgAAAjY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:51.298186 2026] [security2:error] [pid 643573:tid 643728] [client 68.221.186.136:41226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/aafewc0k.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lnAAAAiY"]
[Thu Jul 30 11:47:51.360062 2026] [security2:error] [pid 643573:tid 643590] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lngACbgk"]
[Thu Jul 30 11:47:51.360248 2026] [security2:error] [pid 643573:tid 643800] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lngACbgk"]
[Thu Jul 30 11:47:51.725516 2026] [security2:error] [pid 642360:tid 642610] [client 68.221.186.136:44552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/updates.php"] [unique_id "amuAN5SUkh3e5AhEJOBkhwAAAgc"]
[Thu Jul 30 11:47:51.760465 2026] [core:notice] [pid 643573:tid 643810] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:51.764936 2026] [security2:error] [pid 643573:tid 643810] [client 103.215.74.26:19728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAN_xWyxgRnoFKAJ_loQAAAng"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:51.932412 2026] [security2:error] [pid 643573:tid 643820] [client 103.156.16.241:50632] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lowAAAoI"]
[Thu Jul 30 11:47:52.092575 2026] [security2:error] [pid 642360:tid 642547] [client 68.221.186.136:41237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/abcd.php"] [unique_id "amuAOJSUkh3e5AhEJOBkjgAAAcg"]
[Thu Jul 30 11:47:52.557382 2026] [security2:error] [pid 643253:tid 643454] [client 68.221.186.136:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/user.php"] [unique_id "amuAOMjqbtjBYzqM1uYlGgAAAEY"]
[Thu Jul 30 11:47:52.590063 2026] [security2:error] [pid 643253:tid 643458] [client 176.241.66.87:3587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAOMjqbtjBYzqM1uYlGwAAAEo"]
[Thu Jul 30 11:47:52.590193 2026] [security2:error] [pid 643253:tid 643458] [client 176.241.66.87:3587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAOMjqbtjBYzqM1uYlGwAAAEo"]
[Thu Jul 30 11:47:52.812200 2026] [security2:error] [pid 643573:tid 643820] [client 103.156.16.241:50632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAN_xWyxgRnoFKAJ_lowAAAoI"]
[Thu Jul 30 11:47:52.928262 2026] [security2:error] [pid 642360:tid 642589] [client 68.221.186.136:41260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/about.php"] [unique_id "amuAOJSUkh3e5AhEJOBklgAAAfI"]
[Thu Jul 30 11:47:52.933775 2026] [security2:error] [pid 643573:tid 643740] [client 14.116.236.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amuAOPxWyxgRnoFKAJ_lqwAAAjI"]
[Thu Jul 30 11:47:54.053038 2026] [security2:error] [pid 643573:tid 643598] [remote 5.161.62.209:7544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.otbola.click.mbm.udi.temporary.site"] [uri "/.env"] [unique_id "amuAOvxWyxgRnoFKAJ_lswACIBE"]
[Thu Jul 30 11:47:54.357184 2026] [security2:error] [pid 643573:tid 643765] [client 5.161.62.209:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.otbola.click"] [uri "/.env"] [unique_id "amuAOvxWyxgRnoFKAJ_luAAAAks"]
[Thu Jul 30 11:47:54.910543 2026] [security2:error] [pid 643573:tid 643740] [client 68.221.186.136:41268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/admin.php"] [unique_id "amuAOvxWyxgRnoFKAJ_lvgAAAjI"]
[Thu Jul 30 11:47:55.100400 2026] [security2:error] [pid 643573:tid 643785] [client 47.128.21.167:21790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/robots.txt"] [unique_id "amuAO_xWyxgRnoFKAJ_lwAAAAl8"]
[Thu Jul 30 11:47:55.441809 2026] [security2:error] [pid 643573:tid 643829] [client 103.156.16.241:50714] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lxAAAAos"]
[Thu Jul 30 11:47:55.636770 2026] [security2:error] [pid 643573:tid 643714] [client 68.221.186.136:43042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/admin-ajax.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lxwAAAhg"]
[Thu Jul 30 11:47:55.994330 2026] [security2:error] [pid 643573:tid 643720] [client 68.221.186.136:41232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/adminfuns.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lzQAAAh4"]
[Thu Jul 30 11:47:56.648192 2026] [security2:error] [pid 642360:tid 642442] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAPJSUkh3e5AhEJOBkuwAB_1E"]
[Thu Jul 30 11:47:56.648343 2026] [security2:error] [pid 642360:tid 642602] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAPJSUkh3e5AhEJOBkuwAB_1E"]
[Thu Jul 30 11:47:56.926522 2026] [security2:error] [pid 642360:tid 642497] [client 68.221.186.136:41279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/albin.php"] [unique_id "amuAPJSUkh3e5AhEJOBkvQAAAZY"]
[Thu Jul 30 11:47:56.929540 2026] [security2:error] [pid 643573:tid 643773] [client 62.102.148.185:43902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuAPPxWyxgRnoFKAJ_l3gAAAlM"]
[Thu Jul 30 11:47:56.929613 2026] [security2:error] [pid 643573:tid 643773] [client 62.102.148.185:43902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuAPPxWyxgRnoFKAJ_l3gAAAlM"]
[Thu Jul 30 11:47:57.011648 2026] [security2:error] [pid 642360:tid 642574] [client 68.221.186.136:44173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/alfa.php"] [unique_id "amuAPZSUkh3e5AhEJOBkvgAAAeM"]
[Thu Jul 30 11:47:57.509031 2026] [core:notice] [pid 643573:tid 643714] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:57.513205 2026] [security2:error] [pid 643573:tid 643714] [client 103.215.74.26:17126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAPfxWyxgRnoFKAJ_l5gAAAhg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:57.828370 2026] [proxy:error] [pid 643573:tid 643738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:57.828425 2026] [proxy_http:error] [pid 643573:tid 643738] [client 68.221.186.136:44575] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:57.828994 2026] [proxy:error] [pid 643573:tid 643738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:47:57.829041 2026] [proxy_http:error] [pid 643573:tid 643738] [client 68.221.186.136:44575] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:47:58.221402 2026] [security2:error] [pid 642360:tid 642576] [client 68.221.186.136:41240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/amfsqvgv.php"] [unique_id "amuAPpSUkh3e5AhEJOBkygAAAeU"]
[Thu Jul 30 11:47:58.270069 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:58.274726 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:17128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAPvxWyxgRnoFKAJ_l9wAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:47:58.459883 2026] [security2:error] [pid 643573:tid 643773] [client 23.23.104.107:1429] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/captura-de-tela-2016-10-24-090123.png"] [unique_id "amuAPvxWyxgRnoFKAJ_mAQAAAlM"]
[Thu Jul 30 11:47:59.227820 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:59.415012 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:47:59.471238 2026] [security2:error] [pid 642360:tid 642603] [client 68.221.186.136:46563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/hehe.php"] [unique_id "amuAP5SUkh3e5AhEJOBkzwAAAgA"]
[Thu Jul 30 11:48:00.206081 2026] [security2:error] [pid 642360:tid 642495] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "magicmooncorp.com"] [uri "/index.php"] [unique_id "amuAPZSUkh3e5AhEJOBkxAAAAZQ"]
[Thu Jul 30 11:48:00.658571 2026] [security2:error] [pid 642360:tid 642532] [client 68.221.186.136:41269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/ant.php"] [unique_id "amuAQJSUkh3e5AhEJOBk2gAAAbk"]
[Thu Jul 30 11:48:00.881003 2026] [security2:error] [pid 643573:tid 643731] [client 172.236.9.101:5334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mIgAAAik"]
[Thu Jul 30 11:48:00.882247 2026] [security2:error] [pid 643573:tid 643835] [client 172.236.9.101:64121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mJQAAApE"]
[Thu Jul 30 11:48:00.895158 2026] [security2:error] [pid 643573:tid 643737] [client 172.236.9.101:5912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mJAAAAi8"]
[Thu Jul 30 11:48:00.924604 2026] [security2:error] [pid 643573:tid 643759] [client 172.236.9.101:53623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mIwAAAkU"]
[Thu Jul 30 11:48:00.929933 2026] [security2:error] [pid 643573:tid 643794] [client 172.236.9.101:7924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQPxWyxgRnoFKAJ_mKAAAAmg"]
[Thu Jul 30 11:48:01.224657 2026] [security2:error] [pid 643573:tid 643763] [client 68.221.186.136:25337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/rk2.php"] [unique_id "amuAQfxWyxgRnoFKAJ_mMgAAAkk"]
[Thu Jul 30 11:48:01.262110 2026] [security2:error] [pid 643573:tid 643829] [client 103.156.16.241:50714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lxAAAAos"]
[Thu Jul 30 11:48:01.262165 2026] [security2:error] [pid 643573:tid 643829] [client 103.156.16.241:50714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAO_xWyxgRnoFKAJ_lxAAAAos"]
[Thu Jul 30 11:48:01.839924 2026] [fcgid:warn] [pid 643573:tid 643826] (70014)End of file found: [client 66.132.195.44:42672] mod_fcgid: can't get data from http client
[Thu Jul 30 11:48:01.850950 2026] [security2:error] [pid 642360:tid 642600] [client 68.221.186.136:43923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/setup-config.php"] [unique_id "amuAQZSUkh3e5AhEJOBk4gAAAf0"]
[Thu Jul 30 11:48:01.860049 2026] [security2:error] [pid 643573:tid 643795] [client 54.235.125.129:53521] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/instagram-pode-incluir-transmissao-ao-vivo-no-app.jpg"] [unique_id "amuAQfxWyxgRnoFKAJ_mOAAAAmk"]
[Thu Jul 30 11:48:02.296211 2026] [security2:error] [pid 643253:tid 643381] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAQsjqbtjBYzqM1uYlMAAARH4"]
[Thu Jul 30 11:48:02.296376 2026] [security2:error] [pid 643253:tid 643452] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAQsjqbtjBYzqM1uYlMAAARH4"]
[Thu Jul 30 11:48:03.116678 2026] [security2:error] [pid 642360:tid 642528] [client 176.241.66.87:4399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAQ5SUkh3e5AhEJOBk8QAAAbU"]
[Thu Jul 30 11:48:03.116821 2026] [security2:error] [pid 642360:tid 642528] [client 176.241.66.87:4399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAQ5SUkh3e5AhEJOBk8QAAAbU"]
[Thu Jul 30 11:48:03.336685 2026] [security2:error] [pid 643573:tid 643733] [client 213.152.186.19:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mTQAAAis"]
[Thu Jul 30 11:48:03.336796 2026] [security2:error] [pid 643573:tid 643733] [client 213.152.186.19:54948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mTQAAAis"]
[Thu Jul 30 11:48:03.756172 2026] [security2:error] [pid 643573:tid 643716] [client 172.236.9.101:11786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mSAAAAho"]
[Thu Jul 30 11:48:03.756222 2026] [security2:error] [pid 643573:tid 643739] [client 172.236.9.101:39373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mRwAAAjE"]
[Thu Jul 30 11:48:03.757342 2026] [security2:error] [pid 643573:tid 643803] [client 172.236.9.101:38529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAQ_xWyxgRnoFKAJ_mSQAAAnE"]
[Thu Jul 30 11:48:04.113171 2026] [core:notice] [pid 643573:tid 643800] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:04.117609 2026] [security2:error] [pid 643573:tid 643800] [client 103.215.74.26:51772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuARPxWyxgRnoFKAJ_mWQAAAm4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:04.159448 2026] [security2:error] [pid 642360:tid 642516] [client 103.156.16.241:50928] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuARJSUkh3e5AhEJOBk9wAAAak"]
[Thu Jul 30 11:48:04.796907 2026] [security2:error] [pid 643253:tid 643397] [client 172.236.9.101:19239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuARMjqbtjBYzqM1uYlMwAAAA0"]
[Thu Jul 30 11:48:04.811204 2026] [security2:error] [pid 642360:tid 642533] [client 172.236.9.101:2033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuARJSUkh3e5AhEJOBk-AAAAbo"]
[Thu Jul 30 11:48:04.841664 2026] [security2:error] [pid 643253:tid 643413] [client 68.221.186.136:42941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/a7.php"] [unique_id "amuARMjqbtjBYzqM1uYlNAAAAB0"]
[Thu Jul 30 11:48:04.842618 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:04.847290 2026] [security2:error] [pid 642360:tid 642494] [client 103.215.74.26:51780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuARJSUkh3e5AhEJOBk-wAAAZM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:04.944526 2026] [security2:error] [pid 643253:tid 643417] [client 62.102.148.185:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuARMjqbtjBYzqM1uYlNQAAACE"]
[Thu Jul 30 11:48:04.944684 2026] [security2:error] [pid 643253:tid 643417] [client 62.102.148.185:56666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuARMjqbtjBYzqM1uYlNQAAACE"]
[Thu Jul 30 11:48:05.095074 2026] [security2:error] [pid 642360:tid 642516] [client 103.156.16.241:50928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuARJSUkh3e5AhEJOBk9wAAAak"]
[Thu Jul 30 11:48:05.530347 2026] [security2:error] [pid 643573:tid 643812] [client 68.221.186.136:44214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/f7.php"] [unique_id "amuARfxWyxgRnoFKAJ_mbgAAAno"]
[Thu Jul 30 11:48:05.563015 2026] [core:notice] [pid 643573:tid 643827] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:05.571506 2026] [security2:error] [pid 643573:tid 643827] [client 103.215.74.26:51790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuARfxWyxgRnoFKAJ_mbwAAAok"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:06.207749 2026] [security2:error] [pid 643573:tid 643834] [client 103.156.16.241:50996] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuARvxWyxgRnoFKAJ_mfAAAApA"]
[Thu Jul 30 11:48:06.234521 2026] [core:notice] [pid 643573:tid 643836] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:06.238185 2026] [security2:error] [pid 643573:tid 643836] [client 168.197.25.44:23516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/signal/article/view/9507"] [unique_id "amuARfxWyxgRnoFKAJ_mdwAAApI"]
[Thu Jul 30 11:48:06.295355 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:06.299859 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:51802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuARvxWyxgRnoFKAJ_mfQAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:06.986994 2026] [security2:error] [pid 643573:tid 643611] [remote 57.141.0.67:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6113126855/feed/rss2/"] [unique_id "amuARvxWyxgRnoFKAJ_miQACeR4"]
[Thu Jul 30 11:48:07.004583 2026] [security2:error] [pid 643573:tid 643658] [remote 74.7.241.60:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuAR_xWyxgRnoFKAJ_migACUk0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:48:07.037439 2026] [core:notice] [pid 643573:tid 643636] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:07.045174 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:07.049350 2026] [security2:error] [pid 643573:tid 643739] [client 103.215.74.26:51816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAR_xWyxgRnoFKAJ_mjAAAAjE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:07.066086 2026] [security2:error] [pid 643573:tid 643834] [client 103.156.16.241:50996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuARvxWyxgRnoFKAJ_mfAAAApA"]
[Thu Jul 30 11:48:07.275817 2026] [security2:error] [pid 643573:tid 643656] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAR_xWyxgRnoFKAJ_mjwACdUs"]
[Thu Jul 30 11:48:07.276023 2026] [security2:error] [pid 643573:tid 643807] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAR_xWyxgRnoFKAJ_mjwACdUs"]
[Thu Jul 30 11:48:07.559331 2026] [security2:error] [pid 643573:tid 643763] [client 68.221.186.136:43963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/nw.php"] [unique_id "amuAR_xWyxgRnoFKAJ_mkQAAAkk"]
[Thu Jul 30 11:48:07.625176 2026] [core:notice] [pid 643573:tid 643654] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:07.807747 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:07.812494 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:51830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAR_xWyxgRnoFKAJ_mmwAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:08.312970 2026] [security2:error] [pid 643573:tid 643722] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAR_xWyxgRnoFKAJ_mlQACIEw"]
[Thu Jul 30 11:48:08.337465 2026] [security2:error] [pid 643573:tid 643813] [client 68.221.186.136:43942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ova.php"] [unique_id "amuASPxWyxgRnoFKAJ_mpwAAAns"]
[Thu Jul 30 11:48:08.532192 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:08.536207 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:51836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuASJSUkh3e5AhEJOBlGwAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:08.642863 2026] [security2:error] [pid 643573:tid 643837] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuASPxWyxgRnoFKAJ_mogAAApM"]
[Thu Jul 30 11:48:08.914164 2026] [security2:error] [pid 643573:tid 643781] [client 103.156.16.241:51064] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASPxWyxgRnoFKAJ_mqwAAAls"]
[Thu Jul 30 11:48:09.189308 2026] [fcgid:warn] [pid 643253:tid 643493] (70014)End of file found: [client 66.132.195.44:60822] mod_fcgid: can't get data from http client
[Thu Jul 30 11:48:09.258513 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:09.263449 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:51844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuASfxWyxgRnoFKAJ_msgAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:09.731525 2026] [security2:error] [pid 643573:tid 643711] [client 74.7.244.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-788fb95f.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuASfxWyxgRnoFKAJ_msQAAAhU"]
[Thu Jul 30 11:48:09.732459 2026] [security2:error] [pid 643253:tid 643507] [client 74.7.244.4:33706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-788fb95f.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuAScjqbtjBYzqM1uYlOQAAewE"]
[Thu Jul 30 11:48:09.754191 2026] [security2:error] [pid 643573:tid 643781] [client 103.156.16.241:51064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASPxWyxgRnoFKAJ_mqwAAAls"]
[Thu Jul 30 11:48:09.846371 2026] [security2:error] [pid 643573:tid 643715] [client 198.54.128.138:48876] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "marlboro-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuASfxWyxgRnoFKAJ_muQAAAhk"]
[Thu Jul 30 11:48:09.846472 2026] [security2:error] [pid 643573:tid 643715] [client 198.54.128.138:48876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "marlboro-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuASfxWyxgRnoFKAJ_muQAAAhk"]
[Thu Jul 30 11:48:09.896340 2026] [security2:error] [pid 643573:tid 643741] [client 68.221.186.136:25315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/robots.php"] [unique_id "amuASfxWyxgRnoFKAJ_mugAAAjM"]
[Thu Jul 30 11:48:10.002483 2026] [core:notice] [pid 643573:tid 643748] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:10.007617 2026] [security2:error] [pid 643573:tid 643748] [client 103.215.74.26:51850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuASvxWyxgRnoFKAJ_muwAAAjo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:10.372783 2026] [core:notice] [pid 643573:tid 643789] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:10.530413 2026] [security2:error] [pid 643573:tid 643813] [client 68.221.186.136:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/alf.php"] [unique_id "amuASvxWyxgRnoFKAJ_mwgAAAns"]
[Thu Jul 30 11:48:10.734839 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:10.741670 2026] [security2:error] [pid 643573:tid 643793] [client 103.215.74.26:51866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuASvxWyxgRnoFKAJ_mxQAAAmc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:10.867094 2026] [security2:error] [pid 643573:tid 643820] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuASvxWyxgRnoFKAJ_mwQACgj8"]
[Thu Jul 30 11:48:10.877811 2026] [security2:error] [pid 642360:tid 642525] [client 103.156.16.241:51133] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASpSUkh3e5AhEJOBlMAAAAbI"]
[Thu Jul 30 11:48:11.194257 2026] [core:error] [pid 643253:tid 643494] [client 74.7.244.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:48:11.194291 2026] [core:error] [pid 643253:tid 643494] [client 74.7.244.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:48:11.194458 2026] [security2:error] [pid 643253:tid 643494] [client 74.7.244.14:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ahm.djb.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuAS8jqbtjBYzqM1uYlPQAAAG4"]
[Thu Jul 30 11:48:11.195119 2026] [security2:error] [pid 643253:tid 643472] [client 74.7.244.14:52954] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ahm.djb.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuAS8jqbtjBYzqM1uYlPAAAWAI"]
[Thu Jul 30 11:48:11.469000 2026] [core:notice] [pid 642360:tid 642594] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:11.476124 2026] [security2:error] [pid 642360:tid 642594] [client 103.215.74.26:51870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAS5SUkh3e5AhEJOBlOgAAAfc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:12.795165 2026] [security2:error] [pid 643573:tid 643733] [client 68.221.186.136:27869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/appreciators.php"] [unique_id "amuATPxWyxgRnoFKAJ_m6gAAAis"]
[Thu Jul 30 11:48:12.964945 2026] [core:notice] [pid 643573:tid 643813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:12.968943 2026] [security2:error] [pid 642360:tid 642527] [client 68.221.186.136:44167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/feedback.php"] [unique_id "amuATJSUkh3e5AhEJOBlRAAAAbQ"]
[Thu Jul 30 11:48:13.174468 2026] [security2:error] [pid 643573:tid 643662] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuATfxWyxgRnoFKAJ_m7QACdFE"]
[Thu Jul 30 11:48:13.174674 2026] [security2:error] [pid 643573:tid 643806] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuATfxWyxgRnoFKAJ_m7QACdFE"]
[Thu Jul 30 11:48:13.610869 2026] [security2:error] [pid 643253:tid 643409] [client 176.241.66.87:5186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuATcjqbtjBYzqM1uYlPgAAABk"]
[Thu Jul 30 11:48:13.611021 2026] [security2:error] [pid 643253:tid 643409] [client 176.241.66.87:5186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuATcjqbtjBYzqM1uYlPgAAABk"]
[Thu Jul 30 11:48:13.726604 2026] [security2:error] [pid 643573:tid 643723] [client 68.221.186.136:41275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/archive.php"] [unique_id "amuATfxWyxgRnoFKAJ_m8wAAAiE"]
[Thu Jul 30 11:48:14.293326 2026] [security2:error] [pid 643573:tid 643836] [client 44.223.232.55:60346] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/150/956b6156835979bdf1fbd69e57a7eeed.jpg"] [unique_id "amuATvxWyxgRnoFKAJ_m9wAAApI"]
[Thu Jul 30 11:48:14.330640 2026] [security2:error] [pid 643573:tid 643763] [client 68.221.186.136:46589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/gettest.php"] [unique_id "amuATvxWyxgRnoFKAJ_m-AAAAkk"]
[Thu Jul 30 11:48:15.051304 2026] [security2:error] [pid 643573:tid 643826] [client 43.134.91.35:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.91.134.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JGST"] [unique_id "amuAT_xWyxgRnoFKAJ_m_QAAAog"], referer: https://ejournalugj.com/index_php/JGST
[Thu Jul 30 11:48:15.374311 2026] [security2:error] [pid 643573:tid 643783] [client 68.221.186.136:46551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/maint.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nDgAAAl0"]
[Thu Jul 30 11:48:15.573831 2026] [security2:error] [pid 643573:tid 643835] [client 66.249.68.67:48012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nobleinternationals.com"] [uri "/index.php/favicon.ico"] [unique_id "amuAT_xWyxgRnoFKAJ_nEAAAApE"]
[Thu Jul 30 11:48:15.865019 2026] [security2:error] [pid 643573:tid 643800] [client 172.236.9.101:45744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nBQAAAm4"]
[Thu Jul 30 11:48:15.898185 2026] [security2:error] [pid 643573:tid 643736] [client 172.236.9.101:7591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nBwAAAi4"]
[Thu Jul 30 11:48:15.913712 2026] [security2:error] [pid 643573:tid 643774] [client 172.236.9.101:1685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nBgAAAlQ"]
[Thu Jul 30 11:48:15.975592 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:5788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nCQAAAnQ"]
[Thu Jul 30 11:48:15.984924 2026] [security2:error] [pid 643573:tid 643805] [client 172.236.9.101:60806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nCAAAAnM"]
[Thu Jul 30 11:48:16.229883 2026] [security2:error] [pid 643573:tid 643784] [client 64.127.138.130:11823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nAgACXhA"]
[Thu Jul 30 11:48:16.346605 2026] [security2:error] [pid 643573:tid 643683] [remote 64.127.138.130:11823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nAQACXmY"]
[Thu Jul 30 11:48:16.413045 2026] [security2:error] [pid 642360:tid 642525] [client 103.156.16.241:51133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASpSUkh3e5AhEJOBlMAAAAbI"]
[Thu Jul 30 11:48:16.413123 2026] [security2:error] [pid 642360:tid 642525] [client 103.156.16.241:51133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuASpSUkh3e5AhEJOBlMAAAAbI"]
[Thu Jul 30 11:48:16.613557 2026] [security2:error] [pid 643573:tid 643784] [client 64.127.138.130:11823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAT_xWyxgRnoFKAJ_nAwACXi4"]
[Thu Jul 30 11:48:16.869289 2026] [security2:error] [pid 642360:tid 642522] [client 68.221.186.136:25280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/files.php"] [unique_id "amuAUJSUkh3e5AhEJOBlXwAAAa8"]
[Thu Jul 30 11:48:16.886571 2026] [security2:error] [pid 642360:tid 642494] [client 68.221.186.136:41266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/as.php"] [unique_id "amuAUJSUkh3e5AhEJOBlYAAAAZM"]
[Thu Jul 30 11:48:17.260712 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:17.264939 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:32150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAUZSUkh3e5AhEJOBlagAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:17.409469 2026] [security2:error] [pid 643573:tid 643729] [client 64.127.138.130:11160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAUPxWyxgRnoFKAJ_nHwACJw4"]
[Thu Jul 30 11:48:17.547374 2026] [security2:error] [pid 642360:tid 642490] [client 103.156.16.241:51317] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAUZSUkh3e5AhEJOBlawAAAY8"]
[Thu Jul 30 11:48:17.620368 2026] [security2:error] [pid 643573:tid 643793] [client 68.221.186.136:41259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/atomlib.php"] [unique_id "amuAUfxWyxgRnoFKAJ_nKQAAAmc"]
[Thu Jul 30 11:48:17.901028 2026] [security2:error] [pid 643573:tid 643698] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAUfxWyxgRnoFKAJ_nKgACgnU"]
[Thu Jul 30 11:48:17.901320 2026] [security2:error] [pid 643573:tid 643820] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAUfxWyxgRnoFKAJ_nKgACgnU"]
[Thu Jul 30 11:48:17.983315 2026] [core:notice] [pid 642360:tid 642554] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:17.989882 2026] [security2:error] [pid 642360:tid 642554] [client 103.215.74.26:32160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAUZSUkh3e5AhEJOBlcgAAAc8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:18.167604 2026] [security2:error] [pid 643253:tid 643508] [client 68.221.186.136:41278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/autoload_classmap.php"] [unique_id "amuAUsjqbtjBYzqM1uYlRgAAAHw"]
[Thu Jul 30 11:48:18.333704 2026] [security2:error] [pid 643573:tid 643785] [client 68.221.186.136:44549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/gecko.php"] [unique_id "amuAUvxWyxgRnoFKAJ_nLwAAAl8"]
[Thu Jul 30 11:48:18.403251 2026] [security2:error] [pid 642360:tid 642490] [client 103.156.16.241:51317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAUZSUkh3e5AhEJOBlawAAAY8"]
[Thu Jul 30 11:48:18.718780 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:18.726422 2026] [security2:error] [pid 643573:tid 643762] [client 103.215.74.26:32176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAUvxWyxgRnoFKAJ_nMwAAAkg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:18.901323 2026] [security2:error] [pid 642360:tid 642592] [client 68.221.186.136:26454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/zwso.php"] [unique_id "amuAUpSUkh3e5AhEJOBlfQAAAfU"]
[Thu Jul 30 11:48:18.962726 2026] [security2:error] [pid 642360:tid 642538] [client 68.221.186.136:41219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/bb.php"] [unique_id "amuAUpSUkh3e5AhEJOBlfgAAAb8"]
[Thu Jul 30 11:48:19.036137 2026] [security2:error] [pid 643573:tid 643770] [client 64.127.138.130:11160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAUvxWyxgRnoFKAJ_nLAACUHE"]
[Thu Jul 30 11:48:19.055068 2026] [security2:error] [pid 642360:tid 642575] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAUpSUkh3e5AhEJOBldgAAAeQ"]
[Thu Jul 30 11:48:19.466089 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:19.470336 2026] [security2:error] [pid 643573:tid 643721] [client 103.215.74.26:32192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAU_xWyxgRnoFKAJ_nOgAAAh8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:19.500701 2026] [security2:error] [pid 642360:tid 642548] [client 103.156.16.241:51372] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAU5SUkh3e5AhEJOBlhQAAAck"]
[Thu Jul 30 11:48:19.742667 2026] [security2:error] [pid 643573:tid 643715] [client 68.221.186.136:41272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/bnm.php"] [unique_id "amuAU_xWyxgRnoFKAJ_nOwAAAhk"]
[Thu Jul 30 11:48:19.791404 2026] [security2:error] [pid 643573:tid 643737] [client 172.236.9.101:17092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAU_xWyxgRnoFKAJ_nOAAAAi8"]
[Thu Jul 30 11:48:19.864103 2026] [security2:error] [pid 642360:tid 642508] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAU5SUkh3e5AhEJOBlgQAAAaE"]
[Thu Jul 30 11:48:19.943106 2026] [security2:error] [pid 643573:tid 643799] [client 114.119.149.78:25599] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bisbeewalk.com"] [uri "/images/Bisbee_jflatspanfromtun.jpg"] [unique_id "amuAU_xWyxgRnoFKAJ_nPQAAAm0"], referer: https://bisbeewalk.com/images/Bisbee_jflatspanfromtun.jpg
[Thu Jul 30 11:48:20.189816 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:20.193828 2026] [security2:error] [pid 643573:tid 643731] [client 103.215.74.26:32206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAVPxWyxgRnoFKAJ_nPgAAAik"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:20.363178 2026] [security2:error] [pid 642360:tid 642548] [client 103.156.16.241:51372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "tereashops.com"] [uri "/wp-comments-post.php"] [unique_id "amuAU5SUkh3e5AhEJOBlhQAAAck"]
[Thu Jul 30 11:48:20.542882 2026] [security2:error] [pid 642360:tid 642608] [client 68.221.186.136:41218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/bootstrap.php"] [unique_id "amuAVJSUkh3e5AhEJOBllAAAAgU"]
[Thu Jul 30 11:48:20.793505 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:43355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVPxWyxgRnoFKAJ_nPwAAAnQ"]
[Thu Jul 30 11:48:20.846508 2026] [security2:error] [pid 643573:tid 643805] [client 172.236.9.101:40128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVPxWyxgRnoFKAJ_nQAAAAnM"]
[Thu Jul 30 11:48:20.888475 2026] [security2:error] [pid 643573:tid 643822] [client 172.236.9.101:38132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVPxWyxgRnoFKAJ_nQQAAAoQ"]
[Thu Jul 30 11:48:20.912752 2026] [security2:error] [pid 643573:tid 643767] [client 172.236.9.101:27428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVPxWyxgRnoFKAJ_nQgAAAk0"]
[Thu Jul 30 11:48:20.924111 2026] [core:notice] [pid 643573:tid 643775] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:20.932151 2026] [security2:error] [pid 643573:tid 643775] [client 103.215.74.26:32222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAVPxWyxgRnoFKAJ_nRwAAAlU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:21.408661 2026] [security2:error] [pid 642360:tid 642419] [remote 190.92.174.190:37100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amuAVZSUkh3e5AhEJOBlnQAB8Do"]
[Thu Jul 30 11:48:21.667387 2026] [core:notice] [pid 642360:tid 642504] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:21.671508 2026] [security2:error] [pid 642360:tid 642504] [client 103.215.74.26:32224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAVZSUkh3e5AhEJOBloQAAAZ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:22.403596 2026] [core:notice] [pid 642360:tid 642539] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:22.409947 2026] [security2:error] [pid 642360:tid 642539] [client 103.215.74.26:32232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAVpSUkh3e5AhEJOBlpwAAAcA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:22.482391 2026] [security2:error] [pid 642360:tid 642593] [client 68.221.186.136:46583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/13.php"] [unique_id "amuAVpSUkh3e5AhEJOBlqQAAAfY"]
[Thu Jul 30 11:48:22.639267 2026] [security2:error] [pid 643253:tid 643505] [client 172.237.109.114:22355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVsjqbtjBYzqM1uYlSgAAAHk"]
[Thu Jul 30 11:48:22.690806 2026] [security2:error] [pid 643573:tid 643812] [client 172.237.109.114:47058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nTAAAAno"]
[Thu Jul 30 11:48:22.722924 2026] [security2:error] [pid 643253:tid 643475] [client 172.237.109.114:30313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVsjqbtjBYzqM1uYlSwAAAFs"]
[Thu Jul 30 11:48:22.763610 2026] [security2:error] [pid 643573:tid 643779] [client 172.237.109.114:61857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nTQAAAlk"]
[Thu Jul 30 11:48:22.822673 2026] [security2:error] [pid 642360:tid 642563] [client 172.237.109.114:58081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVpSUkh3e5AhEJOBlpgAAAdg"]
[Thu Jul 30 11:48:22.860534 2026] [security2:error] [pid 643573:tid 643793] [client 172.237.109.114:35879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nTgAAAmc"]
[Thu Jul 30 11:48:23.297735 2026] [security2:error] [pid 643573:tid 643828] [client 172.236.9.101:15376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nUwAAAoo"]
[Thu Jul 30 11:48:23.303396 2026] [security2:error] [pid 643573:tid 643778] [client 172.236.9.101:31340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nTwAAAlg"]
[Thu Jul 30 11:48:23.304160 2026] [security2:error] [pid 643573:tid 643827] [client 172.236.9.101:50152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nUAAAAok"]
[Thu Jul 30 11:48:23.325505 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:35888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nUgAAAk8"]
[Thu Jul 30 11:48:23.348604 2026] [security2:error] [pid 643573:tid 643733] [client 172.236.9.101:22658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAVvxWyxgRnoFKAJ_nUQAAAis"]
[Thu Jul 30 11:48:23.382770 2026] [security2:error] [pid 642360:tid 642541] [client 68.221.186.136:41251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/buy.php"] [unique_id "amuAV5SUkh3e5AhEJOBlswAAAcI"]
[Thu Jul 30 11:48:23.477324 2026] [core:notice] [pid 643253:tid 643433] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:23.589133 2026] [security2:error] [pid 643573:tid 643773] [client 68.221.186.136:25325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ava.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nZQAAAlM"]
[Thu Jul 30 11:48:24.057713 2026] [core:notice] [pid 643253:tid 643448] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:24.088861 2026] [security2:error] [pid 643573:tid 643690] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAWPxWyxgRnoFKAJ_naAACVW0"]
[Thu Jul 30 11:48:24.088999 2026] [security2:error] [pid 643573:tid 643775] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAWPxWyxgRnoFKAJ_naAACVW0"]
[Thu Jul 30 11:48:24.317764 2026] [security2:error] [pid 643573:tid 643712] [client 176.241.66.87:59252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAWPxWyxgRnoFKAJ_nawAAAhY"]
[Thu Jul 30 11:48:24.318028 2026] [security2:error] [pid 643573:tid 643712] [client 176.241.66.87:59252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAWPxWyxgRnoFKAJ_nawAAAhY"]
[Thu Jul 30 11:48:24.434150 2026] [security2:error] [pid 643573:tid 643772] [client 172.237.109.114:32604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nXgAAAlI"]
[Thu Jul 30 11:48:24.445444 2026] [security2:error] [pid 643573:tid 643720] [client 172.237.109.114:35746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nXwAAAh4"]
[Thu Jul 30 11:48:24.482228 2026] [security2:error] [pid 642360:tid 642495] [client 172.237.109.114:1612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV5SUkh3e5AhEJOBlrwAAAZQ"]
[Thu Jul 30 11:48:24.484734 2026] [security2:error] [pid 643253:tid 643427] [client 172.237.109.114:55498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV8jqbtjBYzqM1uYlTAAAACs"]
[Thu Jul 30 11:48:24.485048 2026] [security2:error] [pid 643573:tid 643783] [client 172.237.109.114:61019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nWgAAAl0"]
[Thu Jul 30 11:48:24.499455 2026] [security2:error] [pid 643573:tid 643739] [client 172.237.109.114:12895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nXQAAAjE"]
[Thu Jul 30 11:48:24.530833 2026] [security2:error] [pid 643573:tid 643809] [client 172.237.109.114:50896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nYQAAAnc"]
[Thu Jul 30 11:48:24.530893 2026] [security2:error] [pid 643573:tid 643798] [client 172.237.109.114:9987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nYwAAAmw"]
[Thu Jul 30 11:48:24.557529 2026] [security2:error] [pid 642360:tid 642510] [client 172.237.109.114:53864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV5SUkh3e5AhEJOBlsAAAAaM"]
[Thu Jul 30 11:48:24.562556 2026] [security2:error] [pid 642360:tid 642565] [client 172.237.109.114:21942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV5SUkh3e5AhEJOBlsgAAAdo"]
[Thu Jul 30 11:48:24.562556 2026] [security2:error] [pid 643253:tid 643486] [client 172.237.109.114:43371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV8jqbtjBYzqM1uYlTQAAAGY"]
[Thu Jul 30 11:48:24.567253 2026] [security2:error] [pid 643573:tid 643781] [client 172.237.109.114:14077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nYAAAAls"]
[Thu Jul 30 11:48:24.583785 2026] [security2:error] [pid 643573:tid 643835] [client 172.237.109.114:30257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV_xWyxgRnoFKAJ_nYgAAApE"]
[Thu Jul 30 11:48:24.590258 2026] [security2:error] [pid 642360:tid 642616] [client 172.237.109.114:14012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAV5SUkh3e5AhEJOBlsQAAAg0"]
[Thu Jul 30 11:48:25.233400 2026] [security2:error] [pid 643573:tid 643785] [client 68.221.186.136:27843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/chosen.php"] [unique_id "amuAWfxWyxgRnoFKAJ_negAAAl8"]
[Thu Jul 30 11:48:25.314160 2026] [security2:error] [pid 643573:tid 643718] [client 68.221.186.136:44573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/main.php"] [unique_id "amuAWfxWyxgRnoFKAJ_newAAAhw"]
[Thu Jul 30 11:48:26.296218 2026] [security2:error] [pid 643573:tid 643801] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAWfxWyxgRnoFKAJ_ngAAAAm8"]
[Thu Jul 30 11:48:26.460610 2026] [security2:error] [pid 642360:tid 642567] [client 68.221.186.136:41273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/class-wp-image.php"] [unique_id "amuAWpSUkh3e5AhEJOBlzgAAAdw"]
[Thu Jul 30 11:48:26.753633 2026] [security2:error] [pid 643573:tid 643827] [client 172.236.9.101:28407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWvxWyxgRnoFKAJ_nhQAAAok"]
[Thu Jul 30 11:48:26.760161 2026] [security2:error] [pid 643573:tid 643769] [client 172.236.9.101:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWvxWyxgRnoFKAJ_nhgAAAk8"]
[Thu Jul 30 11:48:26.764877 2026] [security2:error] [pid 642360:tid 642542] [client 172.236.9.101:63289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWpSUkh3e5AhEJOBlzAAAAcM"]
[Thu Jul 30 11:48:26.766283 2026] [security2:error] [pid 642360:tid 642528] [client 172.236.9.101:16462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWpSUkh3e5AhEJOBlywAAAbU"]
[Thu Jul 30 11:48:26.917061 2026] [security2:error] [pid 642360:tid 642491] [client 172.236.9.101:59150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAWpSUkh3e5AhEJOBlzQAAAZA"]
[Thu Jul 30 11:48:27.531366 2026] [security2:error] [pid 643253:tid 643412] [client 68.221.186.136:45702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-file.php"] [unique_id "amuAW8jqbtjBYzqM1uYlVAAAABw"]
[Thu Jul 30 11:48:27.775124 2026] [security2:error] [pid 643573:tid 643829] [client 50.6.43.217:47428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAWvxWyxgRnoFKAJ_njgAAAos"]
[Thu Jul 30 11:48:28.125137 2026] [security2:error] [pid 643573:tid 643739] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAW_xWyxgRnoFKAJ_nmAAAAjE"]
[Thu Jul 30 11:48:28.172748 2026] [security2:error] [pid 643573:tid 643795] [client 68.221.186.136:41246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/classsmtps.php"] [unique_id "amuAXPxWyxgRnoFKAJ_nogAAAmk"]
[Thu Jul 30 11:48:28.194610 2026] [security2:error] [pid 643573:tid 643820] [client 68.221.186.136:45246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-signin.php"] [unique_id "amuAXPxWyxgRnoFKAJ_npAAAAoI"]
[Thu Jul 30 11:48:28.257253 2026] [core:notice] [pid 643573:tid 643814] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:28.261159 2026] [security2:error] [pid 643573:tid 643814] [client 103.215.74.26:34406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAXPxWyxgRnoFKAJ_nqwAAAnw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:28.587853 2026] [security2:error] [pid 643573:tid 643622] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAXPxWyxgRnoFKAJ_nrQACdik"]
[Thu Jul 30 11:48:28.588060 2026] [security2:error] [pid 643573:tid 643808] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAXPxWyxgRnoFKAJ_nrQACdik"]
[Thu Jul 30 11:48:28.589454 2026] [security2:error] [pid 643573:tid 643750] [client 50.6.43.217:47450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuAW_xWyxgRnoFKAJ_nnAAAAjw"]
[Thu Jul 30 11:48:28.906306 2026] [security2:error] [pid 643573:tid 643759] [client 68.221.186.136:27877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/classwithtostring.php"] [unique_id "amuAXPxWyxgRnoFKAJ_ntAAAAkU"]
[Thu Jul 30 11:48:29.020720 2026] [core:notice] [pid 643573:tid 643794] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:29.024853 2026] [security2:error] [pid 643573:tid 643794] [client 103.215.74.26:34408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAXfxWyxgRnoFKAJ_ntQAAAmg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:29.754405 2026] [core:notice] [pid 643573:tid 643767] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:29.758385 2026] [security2:error] [pid 643573:tid 643767] [client 103.215.74.26:34414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAXfxWyxgRnoFKAJ_nuwAAAk0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:30.118061 2026] [security2:error] [pid 643573:tid 643722] [client 68.221.186.136:27845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/config.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nvgAAAiA"]
[Thu Jul 30 11:48:30.493841 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:30.500734 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:34430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAXvxWyxgRnoFKAJ_nxQAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:30.753115 2026] [security2:error] [pid 643573:tid 643729] [client 172.236.9.101:17360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nwAAAAic"]
[Thu Jul 30 11:48:30.757208 2026] [security2:error] [pid 643573:tid 643728] [client 172.236.9.101:50274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nvwAAAiY"]
[Thu Jul 30 11:48:30.826303 2026] [security2:error] [pid 643573:tid 643811] [client 172.236.9.101:4244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nwgAAAnk"]
[Thu Jul 30 11:48:30.829692 2026] [security2:error] [pid 643253:tid 643464] [client 172.236.9.101:5920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXsjqbtjBYzqM1uYlVwAAAFA"]
[Thu Jul 30 11:48:30.833816 2026] [security2:error] [pid 643573:tid 643754] [client 172.236.9.101:18624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nwQAAAkA"]
[Thu Jul 30 11:48:30.843015 2026] [security2:error] [pid 643573:tid 643751] [client 68.221.186.136:27870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/core.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nxgAAAj0"]
[Thu Jul 30 11:48:30.952122 2026] [security2:error] [pid 643573:tid 643799] [client 68.221.186.136:45733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/simi.php"] [unique_id "amuAXvxWyxgRnoFKAJ_nywAAAm0"]
[Thu Jul 30 11:48:31.241861 2026] [core:notice] [pid 643573:tid 643755] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:31.246488 2026] [security2:error] [pid 643573:tid 643755] [client 103.215.74.26:34438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAX_xWyxgRnoFKAJ_nzQAAAkE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:31.979369 2026] [core:notice] [pid 642360:tid 642505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:31.984389 2026] [security2:error] [pid 642360:tid 642505] [client 103.215.74.26:34448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAX5SUkh3e5AhEJOBl9wAAAZ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:31.989469 2026] [security2:error] [pid 642360:tid 642555] [client 68.221.186.136:27846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/css.php"] [unique_id "amuAX5SUkh3e5AhEJOBl-AAAAdA"]
[Thu Jul 30 11:48:31.995049 2026] [security2:error] [pid 643573:tid 643741] [client 68.221.186.136:44186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-conf.php"] [unique_id "amuAX_xWyxgRnoFKAJ_n0QAAAjM"]
[Thu Jul 30 11:48:32.699505 2026] [core:notice] [pid 642360:tid 642532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:32.703538 2026] [security2:error] [pid 642360:tid 642532] [client 103.215.74.26:34464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAYJSUkh3e5AhEJOBl_gAAAbk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:32.977824 2026] [security2:error] [pid 642360:tid 642588] [client 68.221.186.136:41233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/database.php"] [unique_id "amuAYJSUkh3e5AhEJOBmAQAAAfE"]
[Thu Jul 30 11:48:33.534806 2026] [security2:error] [pid 643573:tid 643827] [client 68.221.186.136:41241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/db.php"] [unique_id "amuAYfxWyxgRnoFKAJ_n3QAAAok"]
[Thu Jul 30 11:48:34.086040 2026] [core:notice] [pid 643573:tid 643787] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:34.307219 2026] [security2:error] [pid 643573:tid 643759] [client 68.221.186.136:46535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n5QAAAkU"]
[Thu Jul 30 11:48:34.458740 2026] [security2:error] [pid 643573:tid 643744] [client 68.221.186.136:27859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/default.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n5gAAAjY"]
[Thu Jul 30 11:48:34.745318 2026] [security2:error] [pid 642360:tid 642558] [client 172.236.9.101:12439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAYpSUkh3e5AhEJOBmCgAAAdM"]
[Thu Jul 30 11:48:34.750650 2026] [security2:error] [pid 642360:tid 642556] [client 172.236.9.101:19579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAYpSUkh3e5AhEJOBmCwAAAdE"]
[Thu Jul 30 11:48:34.843680 2026] [security2:error] [pid 642360:tid 642536] [client 172.236.9.101:60455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAYpSUkh3e5AhEJOBmDAAAAb0"]
[Thu Jul 30 11:48:34.844460 2026] [security2:error] [pid 643573:tid 643722] [client 172.236.9.101:59809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n5AAAAiA"]
[Thu Jul 30 11:48:34.920784 2026] [security2:error] [pid 643253:tid 643496] [client 176.241.66.87:59802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAYsjqbtjBYzqM1uYlWgAAAHA"]
[Thu Jul 30 11:48:34.920909 2026] [security2:error] [pid 643253:tid 643496] [client 176.241.66.87:59802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAYsjqbtjBYzqM1uYlWgAAAHA"]
[Thu Jul 30 11:48:34.944645 2026] [security2:error] [pid 643573:tid 643651] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n6AACGkY"]
[Thu Jul 30 11:48:34.944805 2026] [security2:error] [pid 643573:tid 643716] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAYvxWyxgRnoFKAJ_n6AACGkY"]
[Thu Jul 30 11:48:35.746380 2026] [security2:error] [pid 643573:tid 643779] [client 172.236.9.101:18497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAY_xWyxgRnoFKAJ_n7gAAAlk"]
[Thu Jul 30 11:48:36.515245 2026] [security2:error] [pid 643573:tid 643733] [client 20.203.148.31:43052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/011i.php"] [unique_id "amuAZPxWyxgRnoFKAJ_n-gAAAis"]
[Thu Jul 30 11:48:37.005380 2026] [security2:error] [pid 642360:tid 642617] [client 198.54.128.138:60082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuAZJSUkh3e5AhEJOBmIgAAAg4"]
[Thu Jul 30 11:48:37.005488 2026] [security2:error] [pid 642360:tid 642617] [client 198.54.128.138:60082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuAZJSUkh3e5AhEJOBmIgAAAg4"]
[Thu Jul 30 11:48:37.315693 2026] [security2:error] [pid 642360:tid 642601] [client 20.203.148.31:48275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/03a005685d.php"] [unique_id "amuAZZSUkh3e5AhEJOBmKAAAAf4"]
[Thu Jul 30 11:48:37.844522 2026] [security2:error] [pid 643573:tid 643590] [remote 97.74.93.24:36774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-login.php"] [unique_id "amuAZfxWyxgRnoFKAJ_oAAACJAk"]
[Thu Jul 30 11:48:37.899302 2026] [security2:error] [pid 642360:tid 642575] [client 68.221.186.136:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/dropdown.php"] [unique_id "amuAZZSUkh3e5AhEJOBmMAAAAeQ"]
[Thu Jul 30 11:48:38.489686 2026] [security2:error] [pid 643573:tid 643829] [client 68.221.186.136:27860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/edit.php"] [unique_id "amuAZvxWyxgRnoFKAJ_oBQAAAos"]
[Thu Jul 30 11:48:38.490015 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:38.494382 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:10110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAZvxWyxgRnoFKAJ_oBAAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:39.185382 2026] [security2:error] [pid 643573:tid 643768] [client 68.221.186.136:26461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/bala.php"] [unique_id "amuAZ_xWyxgRnoFKAJ_oCQAAAk4"]
[Thu Jul 30 11:48:39.215284 2026] [security2:error] [pid 643573:tid 643616] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAZ_xWyxgRnoFKAJ_oCgACPyM"]
[Thu Jul 30 11:48:39.215431 2026] [security2:error] [pid 643573:tid 643753] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAZ_xWyxgRnoFKAJ_oCgACPyM"]
[Thu Jul 30 11:48:39.229313 2026] [core:notice] [pid 642360:tid 642603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:39.233678 2026] [security2:error] [pid 642360:tid 642603] [client 103.215.74.26:10120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAZ5SUkh3e5AhEJOBmPwAAAgA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:39.374739 2026] [security2:error] [pid 643253:tid 643418] [client 68.221.186.136:41277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/f35.php"] [unique_id "amuAZ8jqbtjBYzqM1uYlWwAAACI"]
[Thu Jul 30 11:48:39.395877 2026] [security2:error] [pid 642360:tid 642573] [client 66.249.65.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAZpSUkh3e5AhEJOBmPgAAAeI"]
[Thu Jul 30 11:48:39.409183 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:39.959587 2026] [core:notice] [pid 643253:tid 643462] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:39.963983 2026] [security2:error] [pid 643253:tid 643462] [client 103.215.74.26:10128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAZ8jqbtjBYzqM1uYlXQAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:40.303218 2026] [security2:error] [pid 643573:tid 643783] [client 20.203.148.31:36638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/403.php"] [unique_id "amuAaPxWyxgRnoFKAJ_oEAAAAl0"]
[Thu Jul 30 11:48:40.365156 2026] [security2:error] [pid 643573:tid 643747] [client 213.152.161.240:42042] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuAaPxWyxgRnoFKAJ_oDwAAAjk"]
[Thu Jul 30 11:48:40.365307 2026] [security2:error] [pid 643573:tid 643747] [client 213.152.161.240:42042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuAaPxWyxgRnoFKAJ_oDwAAAjk"]
[Thu Jul 30 11:48:40.696808 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:40.701391 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:10130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAaMjqbtjBYzqM1uYlXgAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:40.816956 2026] [security2:error] [pid 642360:tid 642588] [client 20.203.148.31:43061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/404.php"] [unique_id "amuAaJSUkh3e5AhEJOBmTAAAAfE"]
[Thu Jul 30 11:48:40.961072 2026] [security2:error] [pid 643573:tid 643803] [client 68.221.186.136:27356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "upns.ca"] [uri "/f7.php"] [unique_id "amuAaPxWyxgRnoFKAJ_oGAAAAnE"]
[Thu Jul 30 11:48:40.962375 2026] [security2:error] [pid 642360:tid 642564] [client 68.221.186.136:45567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/bk.php"] [unique_id "amuAaJSUkh3e5AhEJOBmUQAAAdk"]
[Thu Jul 30 11:48:41.460143 2026] [core:notice] [pid 642360:tid 642578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:41.464666 2026] [security2:error] [pid 642360:tid 642578] [client 103.215.74.26:10134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAaZSUkh3e5AhEJOBmVgAAAec"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:42.201091 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:42.205461 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:10162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAavxWyxgRnoFKAJ_oIQAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:42.408418 2026] [security2:error] [pid 643573:tid 643605] [remote 57.141.0.24:22632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuAavxWyxgRnoFKAJ_oJwACHRg"]
[Thu Jul 30 11:48:42.620744 2026] [security2:error] [pid 643573:tid 643788] [client 20.203.148.31:43886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/aa.php"] [unique_id "amuAavxWyxgRnoFKAJ_oLQAAAmI"]
[Thu Jul 30 11:48:42.794806 2026] [security2:error] [pid 643573:tid 643830] [client 74.7.241.129:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-f3494d1e.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAavxWyxgRnoFKAJ_oJAAAAow"]
[Thu Jul 30 11:48:42.795527 2026] [security2:error] [pid 643573:tid 643726] [client 74.7.241.129:37854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-f3494d1e.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuAavxWyxgRnoFKAJ_oIgACJCg"]
[Thu Jul 30 11:48:42.914243 2026] [security2:error] [pid 643573:tid 643814] [client 207.58.142.67:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAavxWyxgRnoFKAJ_oLgAAAnw"]
[Thu Jul 30 11:48:42.944822 2026] [core:notice] [pid 643573:tid 643822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:42.949427 2026] [security2:error] [pid 643573:tid 643822] [client 103.215.74.26:10170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAavxWyxgRnoFKAJ_oLwAAAoQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:42.992632 2026] [security2:error] [pid 643573:tid 643723] [client 68.221.186.136:45530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ahax.php"] [unique_id "amuAavxWyxgRnoFKAJ_oMAAAAiE"]
[Thu Jul 30 11:48:43.296790 2026] [security2:error] [pid 642360:tid 642509] [client 20.203.148.31:43260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/aafewc0k.php"] [unique_id "amuAa5SUkh3e5AhEJOBmYwAAAaI"]
[Thu Jul 30 11:48:43.682919 2026] [core:notice] [pid 642360:tid 642546] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:43.687309 2026] [security2:error] [pid 642360:tid 642546] [client 103.215.74.26:41498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAa5SUkh3e5AhEJOBmaQAAAcc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:44.414911 2026] [core:notice] [pid 643573:tid 643823] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:44.419229 2026] [security2:error] [pid 643573:tid 643823] [client 103.215.74.26:41500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAbPxWyxgRnoFKAJ_oOAAAAoU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:44.948149 2026] [security2:error] [pid 643573:tid 643775] [client 20.203.148.31:43847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/abcd.php"] [unique_id "amuAbPxWyxgRnoFKAJ_oPAAAAlU"]
[Thu Jul 30 11:48:45.140292 2026] [core:notice] [pid 643573:tid 643749] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:45.144394 2026] [security2:error] [pid 643573:tid 643749] [client 103.215.74.26:41510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAbfxWyxgRnoFKAJ_oRAAAAjs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:45.155382 2026] [security2:error] [pid 643573:tid 643800] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAbPxWyxgRnoFKAJ_oPwAAAm4"]
[Thu Jul 30 11:48:45.641101 2026] [security2:error] [pid 643253:tid 643386] [client 20.203.148.31:37249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/about.php"] [unique_id "amuAbcjqbtjBYzqM1uYlYQAAAAI"]
[Thu Jul 30 11:48:45.690807 2026] [security2:error] [pid 643573:tid 643751] [client 176.241.66.87:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oSAAAAj0"]
[Thu Jul 30 11:48:45.690956 2026] [security2:error] [pid 643573:tid 643751] [client 176.241.66.87:60358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oSAAAAj0"]
[Thu Jul 30 11:48:45.761224 2026] [security2:error] [pid 643573:tid 643729] [client 172.236.9.101:52176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oRQAAAic"]
[Thu Jul 30 11:48:45.821337 2026] [security2:error] [pid 642360:tid 642597] [client 172.236.9.101:48133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAbZSUkh3e5AhEJOBmdQAAAfo"]
[Thu Jul 30 11:48:45.822648 2026] [security2:error] [pid 643573:tid 643604] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oSQACUBc"]
[Thu Jul 30 11:48:45.822813 2026] [security2:error] [pid 643573:tid 643770] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oSQACUBc"]
[Thu Jul 30 11:48:45.866564 2026] [security2:error] [pid 643573:tid 643788] [client 172.236.9.101:45899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAbfxWyxgRnoFKAJ_oRgAAAmI"]
[Thu Jul 30 11:48:45.873318 2026] [core:notice] [pid 642360:tid 642498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:45.877369 2026] [security2:error] [pid 642360:tid 642498] [client 103.215.74.26:41518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAbZSUkh3e5AhEJOBmfAAAAZc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:46.135723 2026] [security2:error] [pid 643573:tid 643758] [client 207.58.142.67:58811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAbvxWyxgRnoFKAJ_oTQAAAkQ"]
[Thu Jul 30 11:48:46.195268 2026] [security2:error] [pid 643573:tid 643743] [client 20.203.148.31:43202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/admin.php"] [unique_id "amuAbvxWyxgRnoFKAJ_oUAAAAjU"]
[Thu Jul 30 11:48:46.856560 2026] [security2:error] [pid 643573:tid 643831] [client 207.58.142.67:1270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAbvxWyxgRnoFKAJ_oUwAAAo0"]
[Thu Jul 30 11:48:47.312223 2026] [security2:error] [pid 643573:tid 643724] [client 20.203.148.31:43857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/adminfuns.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oWgAAAiI"]
[Thu Jul 30 11:48:47.559791 2026] [security2:error] [pid 642360:tid 642555] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAb5SUkh3e5AhEJOBmjAAAAdA"]
[Thu Jul 30 11:48:47.578220 2026] [security2:error] [pid 643573:tid 643753] [client 207.58.142.67:49255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oXgAAAj8"]
[Thu Jul 30 11:48:47.600240 2026] [security2:error] [pid 642360:tid 642418] [remote 40.77.167.30:23421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/anwendungen/braille-pruefung/aboutf.php"] [unique_id "amuAb5SUkh3e5AhEJOBmkAABrDk"]
[Thu Jul 30 11:48:47.784752 2026] [security2:error] [pid 643573:tid 643806] [client 172.236.9.101:11349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oVwAAAnQ"]
[Thu Jul 30 11:48:47.841667 2026] [security2:error] [pid 643573:tid 643826] [client 172.236.9.101:54168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oWAAAAog"]
[Thu Jul 30 11:48:47.848661 2026] [security2:error] [pid 642360:tid 642580] [client 172.236.9.101:31523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb5SUkh3e5AhEJOBmiQAAAek"]
[Thu Jul 30 11:48:47.869008 2026] [security2:error] [pid 643573:tid 643798] [client 172.236.9.101:17283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb_xWyxgRnoFKAJ_oWQAAAmw"]
[Thu Jul 30 11:48:47.940152 2026] [security2:error] [pid 643253:tid 643429] [client 172.236.9.101:16268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb8jqbtjBYzqM1uYlYgAAAC0"]
[Thu Jul 30 11:48:47.956498 2026] [security2:error] [pid 642360:tid 642599] [client 172.236.9.101:3435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb5SUkh3e5AhEJOBmigAAAfw"]
[Thu Jul 30 11:48:47.957945 2026] [security2:error] [pid 642360:tid 642549] [client 172.236.9.101:13075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAb5SUkh3e5AhEJOBmiwAAAco"]
[Thu Jul 30 11:48:48.288070 2026] [security2:error] [pid 643573:tid 643801] [client 207.58.142.67:36012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/nxproof.php.json"] [unique_id "amuAcPxWyxgRnoFKAJ_oYwAAAm8"]
[Thu Jul 30 11:48:49.001832 2026] [security2:error] [pid 643573:tid 643728] [client 207.58.142.67:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuAcfxWyxgRnoFKAJ_ocAAAAiY"]
[Thu Jul 30 11:48:49.124111 2026] [security2:error] [pid 643573:tid 643816] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAcPxWyxgRnoFKAJ_oZwAAAn4"]
[Thu Jul 30 11:48:49.710350 2026] [security2:error] [pid 643573:tid 643770] [client 207.58.142.67:61784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.142.58.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/templates/shaper_helixultimate/layout/nxproof.php.json"] [unique_id "amuAcfxWyxgRnoFKAJ_odQAAAlA"]
[Thu Jul 30 11:48:49.816439 2026] [security2:error] [pid 643573:tid 643824] [client 20.203.148.31:43222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/albin.php"] [unique_id "amuAcfxWyxgRnoFKAJ_odwAAAoY"]
[Thu Jul 30 11:48:49.884011 2026] [security2:error] [pid 643573:tid 643625] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAcfxWyxgRnoFKAJ_oewACOSw"]
[Thu Jul 30 11:48:49.884202 2026] [security2:error] [pid 643573:tid 643747] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAcfxWyxgRnoFKAJ_oewACOSw"]
[Thu Jul 30 11:48:50.282598 2026] [security2:error] [pid 643573:tid 643588] [remote 152.228.213.32:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-login.php"] [unique_id "amuAcvxWyxgRnoFKAJ_ogQACaAc"]
[Thu Jul 30 11:48:51.120324 2026] [security2:error] [pid 643573:tid 643772] [client 20.203.148.31:43841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/amfsqvgv.php"] [unique_id "amuAc_xWyxgRnoFKAJ_ojQAAAlI"]
[Thu Jul 30 11:48:51.598473 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:51.602718 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:41532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAc8jqbtjBYzqM1uYlZQAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:52.342448 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:52.347828 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:41536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAdPxWyxgRnoFKAJ_okwAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:52.879459 2026] [security2:error] [pid 643573:tid 643640] [remote 74.7.241.59:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuAdPxWyxgRnoFKAJ_olgACjTs"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/pixelyoursite/includes
[Thu Jul 30 11:48:53.078758 2026] [core:notice] [pid 642360:tid 642542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:53.085453 2026] [security2:error] [pid 642360:tid 642542] [client 103.215.74.26:4474] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAdZSUkh3e5AhEJOBmuwAAAcM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:53.778768 2026] [security2:error] [pid 643573:tid 643762] [client 57.141.0.52:36506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuAdfxWyxgRnoFKAJ_omQACSDw"]
[Thu Jul 30 11:48:53.813235 2026] [security2:error] [pid 643573:tid 643798] [client 20.203.148.31:48293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/ant.php"] [unique_id "amuAdfxWyxgRnoFKAJ_omwAAAmw"]
[Thu Jul 30 11:48:54.122002 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:54.128686 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:4504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAdvxWyxgRnoFKAJ_onwAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:54.853493 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:48:54.858732 2026] [security2:error] [pid 642360:tid 642613] [client 103.215.74.26:4526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAdpSUkh3e5AhEJOBmygAAAgo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:48:55.236156 2026] [security2:error] [pid 643573:tid 643789] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAdvxWyxgRnoFKAJ_opQAAAmM"]
[Thu Jul 30 11:48:55.311665 2026] [security2:error] [pid 643573:tid 643768] [client 20.203.148.31:43217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/appreciators.php"] [unique_id "amuAd_xWyxgRnoFKAJ_orQAAAk4"]
[Thu Jul 30 11:48:56.032927 2026] [security2:error] [pid 643573:tid 643758] [client 20.203.148.31:43030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/archive.php"] [unique_id "amuAePxWyxgRnoFKAJ_otgAAAkQ"]
[Thu Jul 30 11:48:56.204218 2026] [autoindex:error] [pid 642360:tid 642582] [client 169.58.39.192:50066] AH01276: Cannot serve directory /home2/evkgplte/public_html/website_178d2f94/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 11:48:56.249998 2026] [security2:error] [pid 643573:tid 643788] [client 176.241.66.87:60908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_ouQAAAmI"]
[Thu Jul 30 11:48:56.250136 2026] [security2:error] [pid 643573:tid 643788] [client 176.241.66.87:60908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_ouQAAAmI"]
[Thu Jul 30 11:48:56.294696 2026] [security2:error] [pid 642360:tid 642547] [client 172.236.9.101:42735] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/certificates/alseermarine.com_privkey.pem"] [unique_id "amuAeJSUkh3e5AhEJOBm1wAAAcg"]
[Thu Jul 30 11:48:56.788924 2026] [security2:error] [pid 643573:tid 643637] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_owQACcjg"]
[Thu Jul 30 11:48:56.789202 2026] [security2:error] [pid 643573:tid 643804] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_owQACcjg"]
[Thu Jul 30 11:48:56.823701 2026] [security2:error] [pid 643573:tid 643809] [client 172.236.9.101:24955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAePxWyxgRnoFKAJ_ouAAAAnc"]
[Thu Jul 30 11:48:56.920176 2026] [security2:error] [pid 642360:tid 642539] [client 172.236.9.101:14719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAeJSUkh3e5AhEJOBm1QAAAcA"]
[Thu Jul 30 11:48:56.922739 2026] [security2:error] [pid 643573:tid 643827] [client 172.236.9.101:29847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAePxWyxgRnoFKAJ_ouwAAAok"]
[Thu Jul 30 11:48:56.925004 2026] [security2:error] [pid 642360:tid 642563] [client 172.236.9.101:4336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAeJSUkh3e5AhEJOBm1AAAAdg"]
[Thu Jul 30 11:48:56.928081 2026] [security2:error] [pid 642360:tid 642541] [client 172.236.9.101:37822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAeJSUkh3e5AhEJOBm1gAAAcI"]
[Thu Jul 30 11:48:56.978185 2026] [security2:error] [pid 643573:tid 643784] [client 172.236.9.101:46671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuAePxWyxgRnoFKAJ_ougAAAl4"]
[Thu Jul 30 11:48:57.141804 2026] [security2:error] [pid 642360:tid 642515] [client 20.203.148.31:43216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/as.php"] [unique_id "amuAeZSUkh3e5AhEJOBm3wAAAag"]
[Thu Jul 30 11:48:57.205824 2026] [security2:error] [pid 643573:tid 643797] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAePxWyxgRnoFKAJ_owAACazo"]
[Thu Jul 30 11:48:58.801889 2026] [security2:error] [pid 643573:tid 643806] [client 167.88.167.87:53364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alseermarine.com"] [uri "/"] [unique_id "amuAevxWyxgRnoFKAJ_o2QAAAnQ"]
[Thu Jul 30 11:49:00.363091 2026] [core:error] [pid 643573:tid 643754] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:49:00.363116 2026] [core:error] [pid 643573:tid 643754] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:49:00.504413 2026] [security2:error] [pid 643573:tid 643703] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAfPxWyxgRnoFKAJ_o4QACiXo"]
[Thu Jul 30 11:49:00.504578 2026] [security2:error] [pid 643573:tid 643827] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAfPxWyxgRnoFKAJ_o4QACiXo"]
[Thu Jul 30 11:49:00.584481 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:00.588795 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:4574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAfJSUkh3e5AhEJOBnAwAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:00.687554 2026] [security2:error] [pid 643573:tid 643830] [client 41.210.146.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuAfPxWyxgRnoFKAJ_o4AACjEc"], referer: https://flixon.net/lost-password/
[Thu Jul 30 11:49:01.318950 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:01.326582 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:4588] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAfZSUkh3e5AhEJOBnCgAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:02.051276 2026] [core:notice] [pid 643573:tid 643794] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:02.055249 2026] [security2:error] [pid 643573:tid 643794] [client 103.215.74.26:4592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "775"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAfvxWyxgRnoFKAJ_o7QAAAmg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:02.773820 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:02.777732 2026] [security2:error] [pid 643573:tid 643739] [client 103.215.74.26:4608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAfvxWyxgRnoFKAJ_o8wAAAjE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:03.498869 2026] [security2:error] [pid 643573:tid 643619] [remote 57.141.0.49:42754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuAf_xWyxgRnoFKAJ_o_AACOiY"]
[Thu Jul 30 11:49:03.556497 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:03.563223 2026] [security2:error] [pid 643573:tid 643802] [client 103.215.74.26:42914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAf_xWyxgRnoFKAJ_o_gAAAnA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:03.653021 2026] [core:notice] [pid 643573:tid 643672] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:03.967935 2026] [security2:error] [pid 643573:tid 643830] [client 66.249.66.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAf_xWyxgRnoFKAJ_o-QACjFI"]
[Thu Jul 30 11:49:04.292515 2026] [core:notice] [pid 643573:tid 643794] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:04.296578 2026] [security2:error] [pid 643573:tid 643794] [client 103.215.74.26:42918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAgPxWyxgRnoFKAJ_pAwAAAmg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:05.050204 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:05.054556 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:42920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAgfxWyxgRnoFKAJ_pEgAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:05.785315 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:05.789413 2026] [security2:error] [pid 642360:tid 642502] [client 103.215.74.26:42922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAgZSUkh3e5AhEJOBnNQAAAZs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:06.517488 2026] [core:notice] [pid 643253:tid 643403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:06.522618 2026] [security2:error] [pid 643253:tid 643403] [client 103.215.74.26:42926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAgsjqbtjBYzqM1uYlbgAAABM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:06.831918 2026] [security2:error] [pid 643573:tid 643715] [client 176.241.66.87:3925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAgvxWyxgRnoFKAJ_pJgAAAhk"]
[Thu Jul 30 11:49:06.832070 2026] [security2:error] [pid 643573:tid 643715] [client 176.241.66.87:3925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAgvxWyxgRnoFKAJ_pJgAAAhk"]
[Thu Jul 30 11:49:07.256693 2026] [core:notice] [pid 643573:tid 643733] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:07.261254 2026] [security2:error] [pid 643573:tid 643733] [client 103.215.74.26:42940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAg_xWyxgRnoFKAJ_pKAAAAis"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:07.301662 2026] [security2:error] [pid 642360:tid 642611] [client 3.77.67.4:63402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuAg5SUkh3e5AhEJOBnPQAAAgg"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:49:07.640783 2026] [security2:error] [pid 643253:tid 643267] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAg8jqbtjBYzqM1uYlbwAADAw"]
[Thu Jul 30 11:49:07.640945 2026] [security2:error] [pid 643253:tid 643396] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAg8jqbtjBYzqM1uYlbwAADAw"]
[Thu Jul 30 11:49:07.933243 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:07.937621 2026] [security2:error] [pid 643573:tid 643762] [client 3.77.67.4:34044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAg_xWyxgRnoFKAJ_pLgAAAkg"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:49:07.984609 2026] [core:notice] [pid 643573:tid 643829] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:07.989242 2026] [security2:error] [pid 643573:tid 643829] [client 103.215.74.26:42942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAg_xWyxgRnoFKAJ_pLwAAAos"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:08.497725 2026] [security2:error] [pid 643573:tid 643781] [client 3.77.67.4:34048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuAhPxWyxgRnoFKAJ_pNAAAAls"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:49:08.732156 2026] [core:notice] [pid 643573:tid 643774] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:08.736535 2026] [security2:error] [pid 643573:tid 643774] [client 103.215.74.26:42948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAhPxWyxgRnoFKAJ_pNgAAAlQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:09.070554 2026] [core:notice] [pid 643573:tid 643755] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:09.477771 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:09.482341 2026] [security2:error] [pid 643573:tid 643712] [client 103.215.74.26:42950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAhfxWyxgRnoFKAJ_pPQAAAhY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:10.142028 2026] [core:notice] [pid 643573:tid 643676] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:10.246302 2026] [core:notice] [pid 643573:tid 643758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:10.250701 2026] [security2:error] [pid 643573:tid 643758] [client 103.215.74.26:42958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAhvxWyxgRnoFKAJ_pSAAAAkQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:10.890906 2026] [security2:error] [pid 643253:tid 643417] [client 157.148.43.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amuAhsjqbtjBYzqM1uYlcQAAACE"]
[Thu Jul 30 11:49:11.171005 2026] [security2:error] [pid 643573:tid 643597] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pVwACUxA"]
[Thu Jul 30 11:49:11.171204 2026] [security2:error] [pid 643573:tid 643773] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pVwACUxA"]
[Thu Jul 30 11:49:11.248571 2026] [core:error] [pid 642360:tid 642396] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:49:11.248593 2026] [core:error] [pid 642360:tid 642396] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:49:11.297639 2026] [security2:error] [pid 643573:tid 643683] [remote 74.7.241.60:47638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pWgACXmY"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:49:11.402108 2026] [security2:error] [pid 642360:tid 642493] [client 74.7.228.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.alpha518.com"] [uri "/cgi-sys/404.html"] [unique_id "amuAh5SUkh3e5AhEJOBnYgABkgo"]
[Thu Jul 30 11:49:11.454529 2026] [security2:error] [pid 643573:tid 643808] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pWwAAAnY"]
[Thu Jul 30 11:49:11.454645 2026] [security2:error] [pid 643573:tid 643808] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuAh_xWyxgRnoFKAJ_pWwAAAnY"]
[Thu Jul 30 11:49:11.483383 2026] [core:error] [pid 642360:tid 642426] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:49:11.483401 2026] [core:error] [pid 642360:tid 642426] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:49:12.023745 2026] [security2:error] [pid 643573:tid 643730] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuAiPxWyxgRnoFKAJ_pZgAAAig"]
[Thu Jul 30 11:49:12.023859 2026] [security2:error] [pid 643573:tid 643730] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuAiPxWyxgRnoFKAJ_pZgAAAig"]
[Thu Jul 30 11:49:12.568299 2026] [security2:error] [pid 643573:tid 643755] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/xstelth.php"] [unique_id "amuAiPxWyxgRnoFKAJ_pawAAAkE"]
[Thu Jul 30 11:49:12.568441 2026] [security2:error] [pid 643573:tid 643755] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/xstelth.php"] [unique_id "amuAiPxWyxgRnoFKAJ_pawAAAkE"]
[Thu Jul 30 11:49:13.079380 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/584062352875874akp.php"] [unique_id "amuAifxWyxgRnoFKAJ_pcQAAAnQ"]
[Thu Jul 30 11:49:13.079497 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/584062352875874akp.php"] [unique_id "amuAifxWyxgRnoFKAJ_pcQAAAnQ"]
[Thu Jul 30 11:49:13.587930 2026] [security2:error] [pid 643573:tid 643756] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/newfile.php"] [unique_id "amuAifxWyxgRnoFKAJ_pdAAAAkI"]
[Thu Jul 30 11:49:13.588090 2026] [security2:error] [pid 643573:tid 643756] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/newfile.php"] [unique_id "amuAifxWyxgRnoFKAJ_pdAAAAkI"]
[Thu Jul 30 11:49:14.003142 2026] [security2:error] [pid 642360:tid 642440] [remote 195.26.253.119:52454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lld.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuAipSUkh3e5AhEJOBndgABpE8"]
[Thu Jul 30 11:49:14.144580 2026] [security2:error] [pid 643573:tid 643719] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tBEZGQz.php"] [unique_id "amuAivxWyxgRnoFKAJ_pdQAAAh0"]
[Thu Jul 30 11:49:14.144756 2026] [security2:error] [pid 643573:tid 643719] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tBEZGQz.php"] [unique_id "amuAivxWyxgRnoFKAJ_pdQAAAh0"]
[Thu Jul 30 11:49:14.719425 2026] [proxy:error] [pid 643573:tid 643718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:14.719498 2026] [proxy_http:error] [pid 643573:tid 643718] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:14.720059 2026] [proxy:error] [pid 643573:tid 643718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:14.720104 2026] [proxy_http:error] [pid 643573:tid 643718] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:14.720201 2026] [security2:error] [pid 643573:tid 643718] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAivxWyxgRnoFKAJ_pewAAAhw"]
[Thu Jul 30 11:49:15.246211 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/drykl.php"] [unique_id "amuAi_xWyxgRnoFKAJ_phgAAAnQ"]
[Thu Jul 30 11:49:15.246327 2026] [security2:error] [pid 643573:tid 643806] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/drykl.php"] [unique_id "amuAi_xWyxgRnoFKAJ_phgAAAnQ"]
[Thu Jul 30 11:49:15.768646 2026] [proxy:error] [pid 643573:tid 643802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:15.768722 2026] [proxy_http:error] [pid 643573:tid 643802] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:15.769313 2026] [proxy:error] [pid 643573:tid 643802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:15.769359 2026] [proxy_http:error] [pid 643573:tid 643802] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:15.769445 2026] [security2:error] [pid 643573:tid 643802] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAi_xWyxgRnoFKAJ_pjQAAAnA"]
[Thu Jul 30 11:49:15.984094 2026] [core:notice] [pid 643573:tid 643803] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:15.988550 2026] [security2:error] [pid 643573:tid 643803] [client 103.215.74.26:6148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAi_xWyxgRnoFKAJ_pkwAAAnE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:16.441505 2026] [security2:error] [pid 643573:tid 643790] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ls.php"] [unique_id "amuAjPxWyxgRnoFKAJ_pzAAAAmQ"]
[Thu Jul 30 11:49:16.441640 2026] [security2:error] [pid 643573:tid 643790] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ls.php"] [unique_id "amuAjPxWyxgRnoFKAJ_pzAAAAmQ"]
[Thu Jul 30 11:49:17.018116 2026] [security2:error] [pid 643573:tid 643786] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/dx.php"] [unique_id "amuAjfxWyxgRnoFKAJ_p0QAAAmA"]
[Thu Jul 30 11:49:17.018228 2026] [security2:error] [pid 643573:tid 643786] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/dx.php"] [unique_id "amuAjfxWyxgRnoFKAJ_p0QAAAmA"]
[Thu Jul 30 11:49:17.450107 2026] [security2:error] [pid 642360:tid 642577] [client 176.241.66.87:62000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAjZSUkh3e5AhEJOBnlAAAAeY"]
[Thu Jul 30 11:49:17.450261 2026] [security2:error] [pid 642360:tid 642577] [client 176.241.66.87:62000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAjZSUkh3e5AhEJOBnlAAAAeY"]
[Thu Jul 30 11:49:17.559261 2026] [security2:error] [pid 642360:tid 642561] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amuAjZSUkh3e5AhEJOBnlQAAAdY"]
[Thu Jul 30 11:49:17.559385 2026] [security2:error] [pid 642360:tid 642561] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amuAjZSUkh3e5AhEJOBnlQAAAdY"]
[Thu Jul 30 11:49:18.036307 2026] [security2:error] [pid 643573:tid 643818] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/485.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p2gAAAoA"]
[Thu Jul 30 11:49:18.036412 2026] [security2:error] [pid 643573:tid 643818] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/485.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p2gAAAoA"]
[Thu Jul 30 11:49:18.221655 2026] [security2:error] [pid 643573:tid 643836] [client 198.54.128.138:41566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p3AAAApI"]
[Thu Jul 30 11:49:18.221773 2026] [security2:error] [pid 643573:tid 643836] [client 198.54.128.138:41566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p3AAAApI"]
[Thu Jul 30 11:49:18.452465 2026] [security2:error] [pid 643573:tid 643659] [remote 103.20.243.198:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.243.20.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p4AACZk4"]
[Thu Jul 30 11:49:18.452646 2026] [security2:error] [pid 643573:tid 643792] [client 103.20.243.198:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAjvxWyxgRnoFKAJ_p4AACZk4"]
[Thu Jul 30 11:49:18.474232 2026] [security2:error] [pid 643573:tid 643830] [client 85.208.96.211:10560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/25/brasil-governo-federal-remaneja-r-5876-milhoes-para-passaportes-e-carros-pipa/"] [unique_id "amuAjvxWyxgRnoFKAJ_p4QAAAow"]
[Thu Jul 30 11:49:18.474363 2026] [security2:error] [pid 643573:tid 643830] [client 85.208.96.211:10560] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/25/brasil-governo-federal-remaneja-r-5876-milhoes-para-passaportes-e-carros-pipa/"] [unique_id "amuAjvxWyxgRnoFKAJ_p4QAAAow"]
[Thu Jul 30 11:49:18.559903 2026] [security2:error] [pid 642360:tid 642602] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gelio1.php"] [unique_id "amuAjpSUkh3e5AhEJOBnnAAAAf8"]
[Thu Jul 30 11:49:18.560001 2026] [security2:error] [pid 642360:tid 642602] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gelio1.php"] [unique_id "amuAjpSUkh3e5AhEJOBnnAAAAf8"]
[Thu Jul 30 11:49:19.052930 2026] [security2:error] [pid 642360:tid 642529] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/lp6.php"] [unique_id "amuAj5SUkh3e5AhEJOBnoAAAAbY"]
[Thu Jul 30 11:49:19.053065 2026] [security2:error] [pid 642360:tid 642529] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/lp6.php"] [unique_id "amuAj5SUkh3e5AhEJOBnoAAAAbY"]
[Thu Jul 30 11:49:19.223558 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:19.552505 2026] [security2:error] [pid 643573:tid 643743] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuAj_xWyxgRnoFKAJ_p8gAAAjU"]
[Thu Jul 30 11:49:19.552615 2026] [security2:error] [pid 643573:tid 643743] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuAj_xWyxgRnoFKAJ_p8gAAAjU"]
[Thu Jul 30 11:49:21.077714 2026] [proxy:error] [pid 643573:tid 643711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:21.077789 2026] [proxy_http:error] [pid 643573:tid 643711] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:21.078401 2026] [proxy:error] [pid 643573:tid 643711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:21.078448 2026] [proxy_http:error] [pid 643573:tid 643711] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:21.078539 2026] [security2:error] [pid 643573:tid 643711] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAkfxWyxgRnoFKAJ_qCwAAAhU"]
[Thu Jul 30 11:49:21.581543 2026] [security2:error] [pid 643573:tid 643803] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/w3llscc.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qFAAAAnE"]
[Thu Jul 30 11:49:21.581658 2026] [security2:error] [pid 643573:tid 643803] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/w3llscc.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qFAAAAnE"]
[Thu Jul 30 11:49:21.710430 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:21.714442 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:6150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAkfxWyxgRnoFKAJ_qFwAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:21.715170 2026] [core:error] [pid 643573:tid 643757] [client 74.7.244.60:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:21.715197 2026] [core:error] [pid 643573:tid 643757] [client 74.7.244.60:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:21.715347 2026] [security2:error] [pid 643573:tid 643757] [client 74.7.244.60:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.smoke-tfhk.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qGAAAAkM"]
[Thu Jul 30 11:49:21.715897 2026] [security2:error] [pid 643573:tid 643825] [client 74.7.244.60:40394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.smoke-tfhk.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuAkfxWyxgRnoFKAJ_qFgACh1k"]
[Thu Jul 30 11:49:21.861051 2026] [security2:error] [pid 643573:tid 643663] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qGQACO1I"]
[Thu Jul 30 11:49:21.861254 2026] [security2:error] [pid 643573:tid 643749] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAkfxWyxgRnoFKAJ_qGQACO1I"]
[Thu Jul 30 11:49:21.958595 2026] [security2:error] [pid 643573:tid 643732] [client 74.7.175.154:33102] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.arabian-tours.com"] [uri "/cgi-sys/404.html"] [unique_id "amuAkfxWyxgRnoFKAJ_qGwACKlM"]
[Thu Jul 30 11:49:22.098167 2026] [security2:error] [pid 643573:tid 643744] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/miru3.php"] [unique_id "amuAkvxWyxgRnoFKAJ_qHwAAAjY"]
[Thu Jul 30 11:49:22.098283 2026] [security2:error] [pid 643573:tid 643744] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/miru3.php"] [unique_id "amuAkvxWyxgRnoFKAJ_qHwAAAjY"]
[Thu Jul 30 11:49:22.444074 2026] [core:notice] [pid 643573:tid 643722] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:22.449524 2026] [security2:error] [pid 643573:tid 643722] [client 103.215.74.26:6164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAkvxWyxgRnoFKAJ_qIgAAAiA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:22.578919 2026] [security2:error] [pid 643573:tid 643824] [client 52.5.242.243:50929] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "radiojelli.com"] [uri "/img/articles/68/famous-men-classified-by-myers-briggs-type-6.jpg"] [unique_id "amuAkvxWyxgRnoFKAJ_qJgAAAoY"]
[Thu Jul 30 11:49:22.599470 2026] [security2:error] [pid 643573:tid 643791] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/autoload_classmap.php"] [unique_id "amuAkvxWyxgRnoFKAJ_qJwAAAmU"]
[Thu Jul 30 11:49:22.599563 2026] [security2:error] [pid 643573:tid 643791] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/autoload_classmap.php"] [unique_id "amuAkvxWyxgRnoFKAJ_qJwAAAmU"]
[Thu Jul 30 11:49:22.870430 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:23.090241 2026] [proxy:error] [pid 643573:tid 643796] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:23.090319 2026] [proxy_http:error] [pid 643573:tid 643796] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:23.090866 2026] [proxy:error] [pid 643573:tid 643796] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:23.090908 2026] [proxy_http:error] [pid 643573:tid 643796] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:23.091016 2026] [security2:error] [pid 643573:tid 643796] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAk_xWyxgRnoFKAJ_qMAAAAmo"]
[Thu Jul 30 11:49:23.179858 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:23.184141 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:4530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAk_xWyxgRnoFKAJ_qMgAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:23.591475 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-content/themes/index.php"] [unique_id "amuAk_xWyxgRnoFKAJ_qNgAAAlQ"]
[Thu Jul 30 11:49:23.591587 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-content/themes/index.php"] [unique_id "amuAk_xWyxgRnoFKAJ_qNgAAAlQ"]
[Thu Jul 30 11:49:23.937472 2026] [core:notice] [pid 643573:tid 643768] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:23.941580 2026] [security2:error] [pid 643573:tid 643768] [client 103.215.74.26:4538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAk_xWyxgRnoFKAJ_qOwAAAk4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:24.091288 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/av.php"] [unique_id "amuAlPxWyxgRnoFKAJ_qPAAAAiU"]
[Thu Jul 30 11:49:24.091390 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/av.php"] [unique_id "amuAlPxWyxgRnoFKAJ_qPAAAAiU"]
[Thu Jul 30 11:49:24.599908 2026] [proxy:error] [pid 643573:tid 643715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:24.599995 2026] [proxy_http:error] [pid 643573:tid 643715] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:24.600550 2026] [proxy:error] [pid 643573:tid 643715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:24.600592 2026] [proxy_http:error] [pid 643573:tid 643715] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:24.600678 2026] [security2:error] [pid 643573:tid 643715] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAlPxWyxgRnoFKAJ_qPwAAAhk"]
[Thu Jul 30 11:49:24.661405 2026] [core:notice] [pid 642360:tid 642556] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:24.666452 2026] [security2:error] [pid 642360:tid 642556] [client 103.215.74.26:4546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAlJSUkh3e5AhEJOBnxwAAAdE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:25.106907 2026] [proxy:error] [pid 643573:tid 643792] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:25.107009 2026] [proxy_http:error] [pid 643573:tid 643792] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:25.107814 2026] [proxy:error] [pid 643573:tid 643792] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:25.107865 2026] [proxy_http:error] [pid 643573:tid 643792] [client 172.202.95.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:25.107973 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAlfxWyxgRnoFKAJ_qRQAAAmY"]
[Thu Jul 30 11:49:25.390995 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:25.395099 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:4552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAlZSUkh3e5AhEJOBnzAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:25.606307 2026] [security2:error] [pid 642360:tid 642517] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tiny.php"] [unique_id "amuAlZSUkh3e5AhEJOBnzQAAAao"]
[Thu Jul 30 11:49:25.606469 2026] [security2:error] [pid 642360:tid 642517] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tiny.php"] [unique_id "amuAlZSUkh3e5AhEJOBnzQAAAao"]
[Thu Jul 30 11:49:26.132750 2026] [security2:error] [pid 643573:tid 643808] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuAlvxWyxgRnoFKAJ_qUgAAAnY"]
[Thu Jul 30 11:49:26.132861 2026] [security2:error] [pid 643573:tid 643808] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuAlvxWyxgRnoFKAJ_qUgAAAnY"]
[Thu Jul 30 11:49:26.216849 2026] [security2:error] [pid 643573:tid 643768] [client 57.141.0.4:40468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuAlfxWyxgRnoFKAJ_qTwACTms"], referer: https://igetvape-australia.com/product/iget-one-blackberry-ice/
[Thu Jul 30 11:49:26.281999 2026] [core:notice] [pid 643573:tid 643835] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:26.678739 2026] [security2:error] [pid 642360:tid 642546] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/zrrhj.php"] [unique_id "amuAlpSUkh3e5AhEJOBn2AAAAcc"]
[Thu Jul 30 11:49:26.678886 2026] [security2:error] [pid 642360:tid 642546] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/zrrhj.php"] [unique_id "amuAlpSUkh3e5AhEJOBn2AAAAcc"]
[Thu Jul 30 11:49:27.223995 2026] [security2:error] [pid 643573:tid 643744] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuAl_xWyxgRnoFKAJ_qXwAAAjY"]
[Thu Jul 30 11:49:27.224124 2026] [security2:error] [pid 643573:tid 643744] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuAl_xWyxgRnoFKAJ_qXwAAAjY"]
[Thu Jul 30 11:49:27.816570 2026] [security2:error] [pid 643573:tid 643837] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wpgum.php"] [unique_id "amuAl_xWyxgRnoFKAJ_qZQAAApM"]
[Thu Jul 30 11:49:27.816685 2026] [security2:error] [pid 643573:tid 643837] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wpgum.php"] [unique_id "amuAl_xWyxgRnoFKAJ_qZQAAApM"]
[Thu Jul 30 11:49:27.940927 2026] [core:notice] [pid 643573:tid 643687] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:27.945468 2026] [security2:error] [pid 643573:tid 643784] [client 23.124.173.168:37513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/4514"] [unique_id "amuAl_xWyxgRnoFKAJ_qYgACXmo"]
[Thu Jul 30 11:49:28.061548 2026] [security2:error] [pid 643573:tid 643726] [client 176.241.66.87:62550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qaQAAAiQ"]
[Thu Jul 30 11:49:28.061694 2026] [security2:error] [pid 643573:tid 643726] [client 176.241.66.87:62550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qaQAAAiQ"]
[Thu Jul 30 11:49:28.378501 2026] [security2:error] [pid 643573:tid 643735] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ywwbf.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qbwAAAi0"]
[Thu Jul 30 11:49:28.378607 2026] [security2:error] [pid 643573:tid 643735] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ywwbf.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qbwAAAi0"]
[Thu Jul 30 11:49:28.680637 2026] [core:notice] [pid 643573:tid 643695] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:28.931786 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/xoldj.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qcwAAAmY"]
[Thu Jul 30 11:49:28.931934 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/xoldj.php"] [unique_id "amuAmPxWyxgRnoFKAJ_qcwAAAmY"]
[Thu Jul 30 11:49:28.964016 2026] [core:error] [pid 642360:tid 642481] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:28.964042 2026] [core:error] [pid 642360:tid 642481] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.459802 2026] [security2:error] [pid 643573:tid 643731] [client 47.128.26.97:23772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-kent.com"] [uri "/robots.txt"] [unique_id "amuAmfxWyxgRnoFKAJ_qegAAAik"]
[Thu Jul 30 11:49:29.502590 2026] [security2:error] [pid 642360:tid 642506] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/f35.php"] [unique_id "amuAmZSUkh3e5AhEJOBn7AAAAZ8"]
[Thu Jul 30 11:49:29.502694 2026] [security2:error] [pid 642360:tid 642506] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/f35.php"] [unique_id "amuAmZSUkh3e5AhEJOBn7AAAAZ8"]
[Thu Jul 30 11:49:29.650325 2026] [core:error] [pid 643573:tid 643826] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.650346 2026] [core:error] [pid 643573:tid 643826] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.672851 2026] [core:error] [pid 643573:tid 643727] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.672874 2026] [core:error] [pid 643573:tid 643727] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.675265 2026] [core:error] [pid 642360:tid 642507] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.675291 2026] [core:error] [pid 642360:tid 642507] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.676512 2026] [core:error] [pid 642360:tid 642582] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.676527 2026] [core:error] [pid 642360:tid 642582] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.678153 2026] [core:error] [pid 643573:tid 643801] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:29.678168 2026] [core:error] [pid 643573:tid 643801] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:30.016018 2026] [security2:error] [pid 643573:tid 643827] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gk.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qjAAAAok"]
[Thu Jul 30 11:49:30.016127 2026] [security2:error] [pid 643573:tid 643827] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gk.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qjAAAAok"]
[Thu Jul 30 11:49:30.394469 2026] [security2:error] [pid 643573:tid 643704] [remote 159.75.55.41:42184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.75.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qkQACQHs"]
[Thu Jul 30 11:49:30.568848 2026] [security2:error] [pid 643573:tid 643825] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/584062352875874akp.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qkgAAAoc"]
[Thu Jul 30 11:49:30.569018 2026] [security2:error] [pid 643573:tid 643825] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/584062352875874akp.php"] [unique_id "amuAmvxWyxgRnoFKAJ_qkgAAAoc"]
[Thu Jul 30 11:49:30.613317 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.228.11:52408] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.website-97076a0a.jst.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAmZSUkh3e5AhEJOBn-wAB3Xo"]
[Thu Jul 30 11:49:30.613352 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.228.11:52408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.website-97076a0a.jst.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAmZSUkh3e5AhEJOBn-wAB3Xo"]
[Thu Jul 30 11:49:31.104031 2026] [core:notice] [pid 642360:tid 642541] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.108587 2026] [security2:error] [pid 642360:tid 642541] [client 103.215.74.26:4566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAm5SUkh3e5AhEJOBoAwAAAcI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:31.162816 2026] [core:notice] [pid 643573:tid 643675] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.163939 2026] [security2:error] [pid 643573:tid 643801] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wper3.php"] [unique_id "amuAm_xWyxgRnoFKAJ_qqgAAAm8"]
[Thu Jul 30 11:49:31.164060 2026] [security2:error] [pid 643573:tid 643801] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wper3.php"] [unique_id "amuAm_xWyxgRnoFKAJ_qqgAAAm8"]
[Thu Jul 30 11:49:31.167207 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/index_php/index/---call---/page/page/css-name-stylesheet.css"] [unique_id "amuAmvxWyxgRnoFKAJ_qngACeV4"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.172167 2026] [core:notice] [pid 643573:tid 643700] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.173338 2026] [core:notice] [pid 643573:tid 643693] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.174264 2026] [core:notice] [pid 643573:tid 643685] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.176597 2026] [core:notice] [pid 643573:tid 643701] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.176707 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amuAmvxWyxgRnoFKAJ_qmgACeXc"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.176867 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/site/pageHeaderTitleImage_id_ID.jpg"] [unique_id "amuAmvxWyxgRnoFKAJ_qnQACeXA"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.178206 2026] [core:notice] [pid 643573:tid 643589] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.180436 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/index_php/index/---call---/page/page/css-name-font.css"] [unique_id "amuAmvxWyxgRnoFKAJ_qmwACeWg"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.181025 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/lib/pkp/styles/fontawesome/fontawesome_v-3.3.0.17.css"] [unique_id "amuAmvxWyxgRnoFKAJ_qnAACeXg"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.182451 2026] [security2:error] [pid 643573:tid 643811] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/17/journalThumbnail_en_US.png"] [unique_id "amuAmvxWyxgRnoFKAJ_qnwACeQg"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.263236 2026] [core:notice] [pid 643573:tid 643592] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263308 2026] [core:notice] [pid 643573:tid 643590] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263403 2026] [core:notice] [pid 643573:tid 643596] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263411 2026] [core:notice] [pid 643573:tid 643615] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263450 2026] [core:notice] [pid 643573:tid 643699] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263545 2026] [core:notice] [pid 643573:tid 643587] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263551 2026] [core:notice] [pid 643573:tid 643586] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263607 2026] [core:notice] [pid 643573:tid 643583] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263680 2026] [core:notice] [pid 643573:tid 643623] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.263776 2026] [core:notice] [pid 643573:tid 643651] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.264159 2026] [core:notice] [pid 643573:tid 643696] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.264296 2026] [core:notice] [pid 643573:tid 643585] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.267069 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/32/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qrAACTgs"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.267944 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/20/journalThumbnail_en_US.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qtQACTgk"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.268639 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/44/journalThumbnail_id_ID.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qrgACTg8"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.269059 2026] [core:notice] [pid 643573:tid 643592] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.269638 2026] [core:notice] [pid 643573:tid 643616] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.269731 2026] [core:notice] [pid 643573:tid 643649] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.269786 2026] [core:notice] [pid 643573:tid 643590] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.269834 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/site/images/apranolo/Crossref_Logo_Stacked_RGB_SMALL.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qrQACTiI"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.270204 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/22/journalThumbnail_en_US.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qsAACTnY"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.270296 2026] [core:notice] [pid 643573:tid 643596] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.270322 2026] [core:notice] [pid 643573:tid 643684] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.270583 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/39/journalThumbnail_en_US.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qsQACTgY"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.270637 2026] [core:notice] [pid 643573:tid 643600] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.270700 2026] [core:notice] [pid 643573:tid 643628] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.270868 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/8/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qsgACTgI"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.270932 2026] [core:notice] [pid 643573:tid 643598] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.271079 2026] [core:notice] [pid 643573:tid 643705] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.271335 2026] [core:notice] [pid 643573:tid 643626] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.271354 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/24/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qtgACTgU"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.271565 2026] [core:notice] [pid 643573:tid 643699] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.271708 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/7/journalThumbnail_id_ID.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qtwACTkY"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.272096 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/19/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qswACTnM"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.272347 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/10/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qtAACTgQ"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.272734 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/33/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qrwACTio"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.274558 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/14/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_quQACTgk"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.275080 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/3/journalThumbnail_en_US.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_quwACTiM"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.275392 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/4/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qvgACTmc"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.275823 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/2/journalThumbnail_id_ID.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qwQACThE"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.276098 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/templates/images/ojs_brand.png"] [unique_id "amuAm_xWyxgRnoFKAJ_qwwACTnw"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.276412 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/29/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qugACTkQ"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.276739 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/21/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_quAACTgs"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.277006 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/1/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qwAACTg8"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.277321 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/35/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qvQACTi8"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.277657 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/25/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qvwACTi0"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.277901 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/13/journalThumbnail_id_ID.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qwgACTnY"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.278201 2026] [security2:error] [pid 643573:tid 643768] [client 161.123.34.220:39435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/public/journals/6/journalThumbnail_en_US.jpg"] [unique_id "amuAm_xWyxgRnoFKAJ_qvAACThM"], referer: https://ejournalugj.com/index.php/RILL/article/view/4514?articlesBySimilarityPage=4
[Thu Jul 30 11:49:31.420789 2026] [security2:error] [pid 643573:tid 643724] [client 74.7.228.11:52416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-97076a0a.jst.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAm_xWyxgRnoFKAJ_qxwACIig"], referer: https://www.website-97076a0a.jst.nyx.temporary.site/robots.txt
[Thu Jul 30 11:49:31.836008 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:31.843304 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:4578] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAm8jqbtjBYzqM1uYldgAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:32.554994 2026] [security2:error] [pid 642360:tid 642382] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAnJSUkh3e5AhEJOBoEQABpxU"]
[Thu Jul 30 11:49:32.555150 2026] [security2:error] [pid 642360:tid 642514] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAnJSUkh3e5AhEJOBoEQABpxU"]
[Thu Jul 30 11:49:32.576912 2026] [core:notice] [pid 643573:tid 643741] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:32.583879 2026] [security2:error] [pid 643573:tid 643741] [client 103.215.74.26:4590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAnPxWyxgRnoFKAJ_q0wAAAjM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:32.750866 2026] [security2:error] [pid 643573:tid 643739] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bthil.php"] [unique_id "amuAnPxWyxgRnoFKAJ_q2gAAAjE"]
[Thu Jul 30 11:49:32.751003 2026] [security2:error] [pid 643573:tid 643739] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bthil.php"] [unique_id "amuAnPxWyxgRnoFKAJ_q2gAAAjE"]
[Thu Jul 30 11:49:32.838993 2026] [security2:error] [pid 642360:tid 642592] [client 41.210.146.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuAnJSUkh3e5AhEJOBoDgAB9Xc"], referer: https://flixon.net/lost-password/?ur-lp-error=invalid&message=Invalid%20username%20or%20email.
[Thu Jul 30 11:49:33.271897 2026] [security2:error] [pid 643573:tid 643784] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wyzer1.php"] [unique_id "amuAnfxWyxgRnoFKAJ_q4AAAAl4"]
[Thu Jul 30 11:49:33.272023 2026] [security2:error] [pid 643573:tid 643784] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wyzer1.php"] [unique_id "amuAnfxWyxgRnoFKAJ_q4AAAAl4"]
[Thu Jul 30 11:49:33.309257 2026] [core:notice] [pid 642360:tid 642579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:33.313174 2026] [security2:error] [pid 642360:tid 642579] [client 103.215.74.26:37956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAnZSUkh3e5AhEJOBoFgAAAeg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:33.778570 2026] [security2:error] [pid 642360:tid 642505] [client 157.230.39.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAnZSUkh3e5AhEJOBoGQAAAZ4"]
[Thu Jul 30 11:49:33.785786 2026] [security2:error] [pid 643573:tid 643740] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/mh.php"] [unique_id "amuAnfxWyxgRnoFKAJ_q6QAAAjI"]
[Thu Jul 30 11:49:33.785886 2026] [security2:error] [pid 643573:tid 643740] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/mh.php"] [unique_id "amuAnfxWyxgRnoFKAJ_q6QAAAjI"]
[Thu Jul 30 11:49:34.033500 2026] [core:notice] [pid 643573:tid 643782] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:34.037354 2026] [security2:error] [pid 643573:tid 643782] [client 103.215.74.26:37962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAnvxWyxgRnoFKAJ_q7gAAAlw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:34.279887 2026] [security2:error] [pid 643573:tid 643803] [client 39.46.2.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q9AAAAnE"]
[Thu Jul 30 11:49:34.340830 2026] [security2:error] [pid 643573:tid 643823] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q-QAAAoU"]
[Thu Jul 30 11:49:34.340929 2026] [security2:error] [pid 643573:tid 643823] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q-QAAAoU"]
[Thu Jul 30 11:49:34.718165 2026] [security2:error] [pid 643573:tid 643749] [client 138.199.40.165:35894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q-gACO0U"], referer: https://www.urwru.club/fitness-coaching/
[Thu Jul 30 11:49:34.763857 2026] [security2:error] [pid 643573:tid 643761] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q9gACRwc"]
[Thu Jul 30 11:49:34.776525 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:34.783323 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:37972] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAnpSUkh3e5AhEJOBoJAAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:34.830015 2026] [security2:error] [pid 643573:tid 643745] [client 190.104.114.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAnvxWyxgRnoFKAJ_q_wAAAjc"]
[Thu Jul 30 11:49:34.922897 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.95.21:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuAnsjqbtjBYzqM1uYlegAAABk"]
[Thu Jul 30 11:49:34.923028 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuAnsjqbtjBYzqM1uYlegAAABk"]
[Thu Jul 30 11:49:34.923145 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuAnsjqbtjBYzqM1uYlegAAABk"]
[Thu Jul 30 11:49:35.282624 2026] [security2:error] [pid 643573:tid 643770] [client 139.180.187.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAn_xWyxgRnoFKAJ_rCAAAAlA"]
[Thu Jul 30 11:49:35.500525 2026] [security2:error] [pid 642360:tid 642503] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/chosen.php"] [unique_id "amuAn5SUkh3e5AhEJOBoMQAAAZw"]
[Thu Jul 30 11:49:35.500636 2026] [security2:error] [pid 642360:tid 642503] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/chosen.php"] [unique_id "amuAn5SUkh3e5AhEJOBoMQAAAZw"]
[Thu Jul 30 11:49:35.515346 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:35.519561 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:37988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "775"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAn_xWyxgRnoFKAJ_rEgAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:35.554695 2026] [security2:error] [pid 643573:tid 643764] [client 168.144.47.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAn_xWyxgRnoFKAJ_rDwAAAko"]
[Thu Jul 30 11:49:35.866428 2026] [security2:error] [pid 643253:tid 643461] [client 102.129.223.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAnsjqbtjBYzqM1uYleQAATQ8"], referer: http://allmontecristi.com
[Thu Jul 30 11:49:36.044315 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/sd.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rJgAAAlQ"]
[Thu Jul 30 11:49:36.044419 2026] [security2:error] [pid 643573:tid 643774] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/sd.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rJgAAAlQ"]
[Thu Jul 30 11:49:36.242787 2026] [core:notice] [pid 643573:tid 643833] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:36.246744 2026] [security2:error] [pid 643573:tid 643833] [client 103.215.74.26:37996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAoPxWyxgRnoFKAJ_rKQAAAo8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:36.380110 2026] [security2:error] [pid 643573:tid 643718] [client 14.231.251.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rKwAAAhw"]
[Thu Jul 30 11:49:36.591906 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/z60.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rPQAAAiU"]
[Thu Jul 30 11:49:36.592020 2026] [security2:error] [pid 643573:tid 643727] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/z60.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rPQAAAiU"]
[Thu Jul 30 11:49:36.716108 2026] [security2:error] [pid 642360:tid 642377] [remote 20.54.134.42:2424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuAoJSUkh3e5AhEJOBoPAAB0BA"]
[Thu Jul 30 11:49:36.718887 2026] [security2:error] [pid 643573:tid 643770] [client 45.165.62.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAoPxWyxgRnoFKAJ_rQAAAAlA"]
[Thu Jul 30 11:49:37.008284 2026] [core:notice] [pid 643573:tid 643834] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:37.012254 2026] [security2:error] [pid 643573:tid 643834] [client 103.215.74.26:38006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAofxWyxgRnoFKAJ_rRwAAApA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:37.138653 2026] [security2:error] [pid 643573:tid 643767] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/home.php"] [unique_id "amuAofxWyxgRnoFKAJ_rUAAAAk0"]
[Thu Jul 30 11:49:37.138773 2026] [security2:error] [pid 643573:tid 643767] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/home.php"] [unique_id "amuAofxWyxgRnoFKAJ_rUAAAAk0"]
[Thu Jul 30 11:49:37.666494 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ws58.php"] [unique_id "amuAofxWyxgRnoFKAJ_rXAAAAng"]
[Thu Jul 30 11:49:37.666662 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ws58.php"] [unique_id "amuAofxWyxgRnoFKAJ_rXAAAAng"]
[Thu Jul 30 11:49:37.735782 2026] [core:notice] [pid 643573:tid 643804] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:37.739772 2026] [security2:error] [pid 643573:tid 643804] [client 103.215.74.26:38018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAofxWyxgRnoFKAJ_rXQAAAnI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:38.163387 2026] [security2:error] [pid 643573:tid 643835] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gulu.php"] [unique_id "amuAovxWyxgRnoFKAJ_rYwAAApE"]
[Thu Jul 30 11:49:38.163563 2026] [security2:error] [pid 643573:tid 643835] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/gulu.php"] [unique_id "amuAovxWyxgRnoFKAJ_rYwAAApE"]
[Thu Jul 30 11:49:38.467159 2026] [core:notice] [pid 643573:tid 643765] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:38.472576 2026] [security2:error] [pid 643573:tid 643765] [client 103.215.74.26:38024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAovxWyxgRnoFKAJ_rbQAAAks"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:38.692448 2026] [security2:error] [pid 642360:tid 642514] [client 176.241.66.87:63100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAopSUkh3e5AhEJOBoVAAAAac"]
[Thu Jul 30 11:49:38.692636 2026] [security2:error] [pid 642360:tid 642514] [client 176.241.66.87:63100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAopSUkh3e5AhEJOBoVAAAAac"]
[Thu Jul 30 11:49:38.698533 2026] [security2:error] [pid 643573:tid 643819] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuAovxWyxgRnoFKAJ_rcQAAAoE"]
[Thu Jul 30 11:49:38.698646 2026] [security2:error] [pid 643573:tid 643819] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuAovxWyxgRnoFKAJ_rcQAAAoE"]
[Thu Jul 30 11:49:39.186885 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wpls.php"] [unique_id "amuAo_xWyxgRnoFKAJ_reAAAAmY"]
[Thu Jul 30 11:49:39.187072 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wpls.php"] [unique_id "amuAo_xWyxgRnoFKAJ_reAAAAmY"]
[Thu Jul 30 11:49:39.201786 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:39.206591 2026] [security2:error] [pid 643573:tid 643797] [client 103.215.74.26:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAo_xWyxgRnoFKAJ_reQAAAms"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:39.563849 2026] [security2:error] [pid 642360:tid 642517] [client 57.141.0.2:56070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuAo5SUkh3e5AhEJOBoWAABqh8"], referer: https://igetvape-australia.com/store/?product-page=10&add-to-cart=108
[Thu Jul 30 11:49:39.702166 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/php.php"] [unique_id "amuAo_xWyxgRnoFKAJ_rggAAAng"]
[Thu Jul 30 11:49:39.702309 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/php.php"] [unique_id "amuAo_xWyxgRnoFKAJ_rggAAAng"]
[Thu Jul 30 11:49:39.756094 2026] [security2:error] [pid 642360:tid 642611] [client 216.73.217.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.collectgabon.com"] [uri "/index.php"] [unique_id "amuAo5SUkh3e5AhEJOBoawACCEc"]
[Thu Jul 30 11:49:39.962046 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:39.966505 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:38040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAo8jqbtjBYzqM1uYljAAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:40.257909 2026] [security2:error] [pid 642360:tid 642603] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/100.php"] [unique_id "amuApJSUkh3e5AhEJOBodgAAAgA"]
[Thu Jul 30 11:49:40.258027 2026] [security2:error] [pid 642360:tid 642603] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/100.php"] [unique_id "amuApJSUkh3e5AhEJOBodgAAAgA"]
[Thu Jul 30 11:49:40.696184 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:40.704406 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:38042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuApPxWyxgRnoFKAJ_rmgAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:40.785195 2026] [security2:error] [pid 643573:tid 643809] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/BDKR28WP.php"] [unique_id "amuApPxWyxgRnoFKAJ_rmwAAAnc"]
[Thu Jul 30 11:49:40.785299 2026] [security2:error] [pid 643573:tid 643809] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/BDKR28WP.php"] [unique_id "amuApPxWyxgRnoFKAJ_rmwAAAnc"]
[Thu Jul 30 11:49:40.879839 2026] [core:error] [pid 643573:tid 643644] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:40.879870 2026] [core:error] [pid 643573:tid 643644] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:40.963165 2026] [core:error] [pid 643573:tid 643591] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:40.963186 2026] [core:error] [pid 643573:tid 643591] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:41.152901 2026] [core:error] [pid 643573:tid 643619] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:41.152921 2026] [core:error] [pid 643573:tid 643619] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:41.170451 2026] [security2:error] [pid 642360:tid 642610] [client 68.67.112.24:28093] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuApZSUkh3e5AhEJOBogAAAAgc"]
[Thu Jul 30 11:49:41.501694 2026] [security2:error] [pid 643573:tid 643817] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/browse.php"] [unique_id "amuApfxWyxgRnoFKAJ_rsQAAAn8"]
[Thu Jul 30 11:49:41.501773 2026] [security2:error] [pid 643573:tid 643817] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/browse.php"] [unique_id "amuApfxWyxgRnoFKAJ_rsQAAAn8"]
[Thu Jul 30 11:49:42.050348 2026] [security2:error] [pid 643253:tid 643462] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-good.php"] [unique_id "amuApsjqbtjBYzqM1uYlkwAAAE4"]
[Thu Jul 30 11:49:42.050452 2026] [security2:error] [pid 643253:tid 643462] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-good.php"] [unique_id "amuApsjqbtjBYzqM1uYlkwAAAE4"]
[Thu Jul 30 11:49:42.306513 2026] [core:error] [pid 643573:tid 643666] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:42.306544 2026] [core:error] [pid 643573:tid 643666] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:42.586014 2026] [security2:error] [pid 643573:tid 643789] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/8573.php"] [unique_id "amuApvxWyxgRnoFKAJ_r9AAAAmM"]
[Thu Jul 30 11:49:42.586110 2026] [security2:error] [pid 643573:tid 643789] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/8573.php"] [unique_id "amuApvxWyxgRnoFKAJ_r9AAAAmM"]
[Thu Jul 30 11:49:42.684878 2026] [core:error] [pid 643573:tid 643661] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:42.684898 2026] [core:error] [pid 643573:tid 643661] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:43.150062 2026] [security2:error] [pid 642360:tid 642544] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/install.php"] [unique_id "amuAp5SUkh3e5AhEJOBorAAAAcU"]
[Thu Jul 30 11:49:43.150168 2026] [security2:error] [pid 642360:tid 642544] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/install.php"] [unique_id "amuAp5SUkh3e5AhEJOBorAAAAcU"]
[Thu Jul 30 11:49:43.219326 2026] [security2:error] [pid 643573:tid 643673] [remote 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sEgACVFw"]
[Thu Jul 30 11:49:43.219558 2026] [security2:error] [pid 643573:tid 643774] [client 2001:4490:4c45:dc24:94c3:b7bb:7bfb:46e1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sEgACVFw"]
[Thu Jul 30 11:49:43.268398 2026] [core:error] [pid 643573:tid 643584] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:43.268425 2026] [core:error] [pid 643573:tid 643584] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:49:43.589430 2026] [security2:error] [pid 643573:tid 643648] [remote 65.181.116.253:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sGQACPUM"]
[Thu Jul 30 11:49:43.713628 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/classwithtostring.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sHAAAAiI"]
[Thu Jul 30 11:49:43.713776 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/classwithtostring.php"] [unique_id "amuAp_xWyxgRnoFKAJ_sHAAAAiI"]
[Thu Jul 30 11:49:44.147677 2026] [security2:error] [pid 643573:tid 643731] [client 121.229.156.36:38436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/adidas-samba-xlg-11/"] [unique_id "amuAqPxWyxgRnoFKAJ_sJAAAAik"]
[Thu Jul 30 11:49:44.147784 2026] [security2:error] [pid 643573:tid 643731] [client 121.229.156.36:38436] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/adidas-samba-xlg-11/"] [unique_id "amuAqPxWyxgRnoFKAJ_sJAAAAik"]
[Thu Jul 30 11:49:44.273023 2026] [security2:error] [pid 643573:tid 643732] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ohct.php"] [unique_id "amuAqPxWyxgRnoFKAJ_sKAAAAio"]
[Thu Jul 30 11:49:44.273125 2026] [security2:error] [pid 643573:tid 643732] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ohct.php"] [unique_id "amuAqPxWyxgRnoFKAJ_sKAAAAio"]
[Thu Jul 30 11:49:44.615009 2026] [security2:error] [pid 643573:tid 643793] [client 74.7.175.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amuAqPxWyxgRnoFKAJ_sLQAAAmc"]
[Thu Jul 30 11:49:44.615633 2026] [security2:error] [pid 643573:tid 643829] [client 74.7.175.133:38852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amuAqPxWyxgRnoFKAJ_sKwACixY"]
[Thu Jul 30 11:49:44.697370 2026] [core:error] [pid 643573:tid 643617] (36)File name too long: [remote 104.200.74.237:56678] AH00036: access to />","sale_flash_html":""},{"attributes":{"attribute_pa_size":"40"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N/A","display_price":209,"display_regular_price":209,"image":{"title":"cae69bf9.jpeg","caption":"","url":"https:/kicksity.com/wp-content/uploads/2024/11/cae69bf9.jpeg","alt":"cae69bf9.jpeg","src":"https:/kicksity.com/wp-content/uploads/2024/11/cae69bf9-600x400.jpeg","srcset":"https:/kicksity.com/wp-content/uploads/2024/11/cae69bf9-600x400.jpeg failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/>","sale_flash_html":""},{"attributes":{"attribute_pa_size":"40"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N'), referer: https://kicksity.com/product/ro-sneaker-black-2/
[Thu Jul 30 11:49:44.806305 2026] [security2:error] [pid 643573:tid 643735] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bless.php"] [unique_id "amuAqPxWyxgRnoFKAJ_sNQAAAi0"]
[Thu Jul 30 11:49:44.806411 2026] [security2:error] [pid 643573:tid 643735] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bless.php"] [unique_id "amuAqPxWyxgRnoFKAJ_sNQAAAi0"]
[Thu Jul 30 11:49:45.349957 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sSwAAAiI"]
[Thu Jul 30 11:49:45.350103 2026] [security2:error] [pid 643573:tid 643724] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sSwAAAiI"]
[Thu Jul 30 11:49:45.875531 2026] [security2:error] [pid 643573:tid 643787] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sYAAAAmE"]
[Thu Jul 30 11:49:45.875625 2026] [security2:error] [pid 643573:tid 643787] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sYAAAAmE"]
[Thu Jul 30 11:49:45.972647 2026] [security2:error] [pid 642360:tid 642500] [client 172.237.109.114:48562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/database.sql"] [unique_id "amuAqZSUkh3e5AhEJOBo0AAAAZk"]
[Thu Jul 30 11:49:45.977165 2026] [security2:error] [pid 643573:tid 643775] [client 172.237.109.114:44988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/database.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sZgAAAlU"]
[Thu Jul 30 11:49:45.977209 2026] [security2:error] [pid 643573:tid 643829] [client 172.237.109.114:31246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/database.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sZQAAAos"]
[Thu Jul 30 11:49:45.977303 2026] [security2:error] [pid 643573:tid 643803] [client 172.237.109.114:62824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sZAAAAnE"]
[Thu Jul 30 11:49:45.990088 2026] [security2:error] [pid 643573:tid 643747] [client 172.237.109.114:52073] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/alseermarine.com:80.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sZwAAAjk"]
[Thu Jul 30 11:49:45.990256 2026] [security2:error] [pid 643573:tid 643819] [client 172.237.109.114:40140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_saAAAAoE"]
[Thu Jul 30 11:49:45.991281 2026] [security2:error] [pid 643573:tid 643796] [client 172.237.109.114:64552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backups/database.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_saQAAAmo"]
[Thu Jul 30 11:49:45.991792 2026] [security2:error] [pid 643253:tid 643503] [client 172.237.109.114:15840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/mysql.sql"] [unique_id "amuAqcjqbtjBYzqM1uYlnQAAAHc"]
[Thu Jul 30 11:49:45.992111 2026] [security2:error] [pid 643573:tid 643777] [client 172.237.109.114:22003] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backup.sql"] [unique_id "amuAqfxWyxgRnoFKAJ_sagAAAlc"]
[Thu Jul 30 11:49:46.010287 2026] [security2:error] [pid 643573:tid 643798] [client 172.237.109.114:1345] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/alseermarine.com:80.sql"] [unique_id "amuAqvxWyxgRnoFKAJ_sbAAAAmw"]
[Thu Jul 30 11:49:46.010361 2026] [security2:error] [pid 643573:tid 643834] [client 172.237.109.114:13444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/dump.sql"] [unique_id "amuAqvxWyxgRnoFKAJ_sbQAAApA"]
[Thu Jul 30 11:49:46.010392 2026] [security2:error] [pid 642360:tid 642559] [client 172.237.109.114:32753] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/db.sql"] [unique_id "amuAqpSUkh3e5AhEJOBo0gAAAdQ"]
[Thu Jul 30 11:49:46.420520 2026] [security2:error] [pid 643253:tid 643442] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ta0ol.php"] [unique_id "amuAqsjqbtjBYzqM1uYlngAAADo"]
[Thu Jul 30 11:49:46.420604 2026] [security2:error] [pid 643253:tid 643442] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ta0ol.php"] [unique_id "amuAqsjqbtjBYzqM1uYlngAAADo"]
[Thu Jul 30 11:49:46.428172 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:46.433355 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:21346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAqvxWyxgRnoFKAJ_sdgAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:46.988450 2026] [security2:error] [pid 643573:tid 643804] [client 74.7.241.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ztk.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuAqfxWyxgRnoFKAJ_sVAAAAnI"]
[Thu Jul 30 11:49:46.988765 2026] [security2:error] [pid 643253:tid 643425] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/sa.php7"] [unique_id "amuAqsjqbtjBYzqM1uYloAAAACk"]
[Thu Jul 30 11:49:46.988874 2026] [security2:error] [pid 643253:tid 643425] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/sa.php7"] [unique_id "amuAqsjqbtjBYzqM1uYloAAAACk"]
[Thu Jul 30 11:49:46.989185 2026] [security2:error] [pid 643573:tid 643764] [client 74.7.241.174:33326] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ztk.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuAqfxWyxgRnoFKAJ_sUgACShA"]
[Thu Jul 30 11:49:47.554226 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-class.php"] [unique_id "amuAq_xWyxgRnoFKAJ_sfwAAAkM"]
[Thu Jul 30 11:49:47.554336 2026] [security2:error] [pid 643573:tid 643757] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-class.php"] [unique_id "amuAq_xWyxgRnoFKAJ_sfwAAAkM"]
[Thu Jul 30 11:49:47.736494 2026] [security2:error] [pid 643573:tid 643829] [client 103.97.165.206:61168] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "happyspree.app"] [uri "/"] [unique_id "amuAq_xWyxgRnoFKAJ_sgQAAAos"]
[Thu Jul 30 11:49:47.973783 2026] [security2:error] [pid 642360:tid 642598] [client 185.191.171.2:54734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2024/02/28/bolsonaro-passa-por-exames-e-equipe-medica-discute-realizacao-de-nova-cirurgia-no-abdomen/"] [unique_id "amuAq5SUkh3e5AhEJOBo6wAAAfs"]
[Thu Jul 30 11:49:47.973938 2026] [security2:error] [pid 642360:tid 642598] [client 185.191.171.2:54734] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2024/02/28/bolsonaro-passa-por-exames-e-equipe-medica-discute-realizacao-de-nova-cirurgia-no-abdomen/"] [unique_id "amuAq5SUkh3e5AhEJOBo6wAAAfs"]
[Thu Jul 30 11:49:48.108926 2026] [security2:error] [pid 643573:tid 643760] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amuArPxWyxgRnoFKAJ_siAAAAkY"]
[Thu Jul 30 11:49:48.109018 2026] [security2:error] [pid 643573:tid 643760] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amuArPxWyxgRnoFKAJ_siAAAAkY"]
[Thu Jul 30 11:49:48.672931 2026] [security2:error] [pid 643573:tid 643833] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bootstrap.php"] [unique_id "amuArPxWyxgRnoFKAJ_sjwAAAo8"]
[Thu Jul 30 11:49:48.673060 2026] [security2:error] [pid 643573:tid 643833] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/bootstrap.php"] [unique_id "amuArPxWyxgRnoFKAJ_sjwAAAo8"]
[Thu Jul 30 11:49:49.164166 2026] [security2:error] [pid 643573:tid 643815] [client 173.252.87.113:34510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuArPxWyxgRnoFKAJ_siQAAAn0"]
[Thu Jul 30 11:49:49.464484 2026] [security2:error] [pid 643573:tid 643822] [client 176.241.66.87:10735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuArfxWyxgRnoFKAJ_smAAAAoQ"]
[Thu Jul 30 11:49:49.464602 2026] [security2:error] [pid 643573:tid 643822] [client 176.241.66.87:10735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuArfxWyxgRnoFKAJ_smAAAAoQ"]
[Thu Jul 30 11:49:49.472640 2026] [security2:error] [pid 642360:tid 642585] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuArJSUkh3e5AhEJOBo8wAAAe4"]
[Thu Jul 30 11:49:49.788945 2026] [security2:error] [pid 642360:tid 642612] [client 173.252.87.38:61140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuArZSUkh3e5AhEJOBo-wAAAgk"]
[Thu Jul 30 11:49:50.022385 2026] [security2:error] [pid 642360:tid 642520] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-blog-header.php"] [unique_id "amuArpSUkh3e5AhEJOBo_QAAAa0"]
[Thu Jul 30 11:49:50.022490 2026] [security2:error] [pid 642360:tid 642520] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-blog-header.php"] [unique_id "amuArpSUkh3e5AhEJOBo_QAAAa0"]
[Thu Jul 30 11:49:50.512702 2026] [security2:error] [pid 643573:tid 643831] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/aa.php"] [unique_id "amuArvxWyxgRnoFKAJ_sowAAAo0"]
[Thu Jul 30 11:49:50.512783 2026] [security2:error] [pid 643573:tid 643831] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/aa.php"] [unique_id "amuArvxWyxgRnoFKAJ_sowAAAo0"]
[Thu Jul 30 11:49:51.048453 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tx79.php"] [unique_id "amuAr_xWyxgRnoFKAJ_sqwAAAng"]
[Thu Jul 30 11:49:51.048547 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tx79.php"] [unique_id "amuAr_xWyxgRnoFKAJ_sqwAAAng"]
[Thu Jul 30 11:49:51.485993 2026] [security2:error] [pid 643573:tid 643800] [client 200.66.118.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAr_xWyxgRnoFKAJ_ssQAAAm4"]
[Thu Jul 30 11:49:51.604786 2026] [security2:error] [pid 643253:tid 643481] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/motu.php"] [unique_id "amuAr8jqbtjBYzqM1uYlpAAAAGE"]
[Thu Jul 30 11:49:51.604904 2026] [security2:error] [pid 643253:tid 643481] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/motu.php"] [unique_id "amuAr8jqbtjBYzqM1uYlpAAAAGE"]
[Thu Jul 30 11:49:52.163770 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:52.165868 2026] [proxy:error] [pid 643573:tid 643826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:52.165952 2026] [proxy_http:error] [pid 643573:tid 643826] [client 52.4.19.39:38508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:52.166575 2026] [proxy:error] [pid 643573:tid 643826] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:52.166622 2026] [proxy_http:error] [pid 643573:tid 643826] [client 52.4.19.39:38508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:52.168339 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:21350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAsMjqbtjBYzqM1uYlpQAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:52.196156 2026] [security2:error] [pid 643573:tid 643802] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-head.php"] [unique_id "amuAsPxWyxgRnoFKAJ_swQAAAnA"]
[Thu Jul 30 11:49:52.196246 2026] [security2:error] [pid 643573:tid 643802] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-head.php"] [unique_id "amuAsPxWyxgRnoFKAJ_swQAAAnA"]
[Thu Jul 30 11:49:52.201205 2026] [proxy:error] [pid 643253:tid 643482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:52.201306 2026] [proxy_http:error] [pid 643253:tid 643482] [client 52.4.19.39:26207] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:52.202102 2026] [proxy:error] [pid 643253:tid 643482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:49:52.202155 2026] [proxy_http:error] [pid 643253:tid 643482] [client 52.4.19.39:26207] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:49:52.707688 2026] [security2:error] [pid 642360:tid 642505] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuAsJSUkh3e5AhEJOBpEwAAAZ4"]
[Thu Jul 30 11:49:52.707821 2026] [security2:error] [pid 642360:tid 642505] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuAsJSUkh3e5AhEJOBpEwAAAZ4"]
[Thu Jul 30 11:49:52.897346 2026] [core:notice] [pid 643573:tid 643741] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:52.901670 2026] [security2:error] [pid 643573:tid 643741] [client 103.215.74.26:21362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAsPxWyxgRnoFKAJ_sxwAAAjM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:52.982802 2026] [security2:error] [pid 642360:tid 642463] [remote 40.77.167.70:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/258/257"] [unique_id "amuAsJSUkh3e5AhEJOBpFwABuWY"]
[Thu Jul 30 11:49:53.222677 2026] [security2:error] [pid 642360:tid 642581] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/60856e3a4findex.php"] [unique_id "amuAsZSUkh3e5AhEJOBpGwAAAeo"]
[Thu Jul 30 11:49:53.222798 2026] [security2:error] [pid 642360:tid 642581] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/60856e3a4findex.php"] [unique_id "amuAsZSUkh3e5AhEJOBpGwAAAeo"]
[Thu Jul 30 11:49:53.579115 2026] [core:notice] [pid 643573:tid 643618] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:53.623456 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:53.630540 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:11248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAscjqbtjBYzqM1uYlpwAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:53.721469 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-the.php"] [unique_id "amuAsfxWyxgRnoFKAJ_szgAAAng"]
[Thu Jul 30 11:49:53.721577 2026] [security2:error] [pid 643573:tid 643810] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp-the.php"] [unique_id "amuAsfxWyxgRnoFKAJ_szgAAAng"]
[Thu Jul 30 11:49:53.754073 2026] [security2:error] [pid 643573:tid 643798] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "imailearninghub.com"] [uri "/media/system/js/core.js"] [unique_id "amuAsfxWyxgRnoFKAJ_szwAAAmw"]
[Thu Jul 30 11:49:54.280048 2026] [security2:error] [pid 643573:tid 643772] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp.php"] [unique_id "amuAsvxWyxgRnoFKAJ_s1QAAAlI"]
[Thu Jul 30 11:49:54.280157 2026] [security2:error] [pid 643573:tid 643772] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wp.php"] [unique_id "amuAsvxWyxgRnoFKAJ_s1QAAAlI"]
[Thu Jul 30 11:49:54.354058 2026] [core:notice] [pid 642360:tid 642562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:54.359551 2026] [security2:error] [pid 642360:tid 642562] [client 103.215.74.26:11260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAspSUkh3e5AhEJOBpKwAAAdc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:54.794176 2026] [security2:error] [pid 643573:tid 643721] [client 20.100.187.246:16872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/--wp-lgj.php"] [unique_id "amuAsvxWyxgRnoFKAJ_s4QAAAh8"]
[Thu Jul 30 11:49:54.884066 2026] [security2:error] [pid 642360:tid 642575] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuAspSUkh3e5AhEJOBpKQAB5G8"]
[Thu Jul 30 11:49:55.029064 2026] [security2:error] [pid 643573:tid 643794] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAsvxWyxgRnoFKAJ_s4gAAAmg"]
[Thu Jul 30 11:49:55.067296 2026] [core:notice] [pid 642360:tid 642512] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:55.072685 2026] [security2:error] [pid 642360:tid 642512] [client 103.215.74.26:11276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAs5SUkh3e5AhEJOBpOAAAAaU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:55.311045 2026] [security2:error] [pid 642360:tid 642547] [client 213.152.161.240:57458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuAs5SUkh3e5AhEJOBpNwAAAcg"]
[Thu Jul 30 11:49:55.311133 2026] [security2:error] [pid 642360:tid 642547] [client 213.152.161.240:57458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuAs5SUkh3e5AhEJOBpNwAAAcg"]
[Thu Jul 30 11:49:55.609074 2026] [core:notice] [pid 643573:tid 643707] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:55.803644 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:55.808048 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:11282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAs_xWyxgRnoFKAJ_s-AAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:56.541758 2026] [core:notice] [pid 642360:tid 642536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:49:56.546738 2026] [security2:error] [pid 642360:tid 642536] [client 103.215.74.26:11292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAtJSUkh3e5AhEJOBpSgAAAb0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:49:57.208827 2026] [security2:error] [pid 642360:tid 642524] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAtZSUkh3e5AhEJOBpTgAAAbE"]
[Thu Jul 30 11:49:59.484905 2026] [security2:error] [pid 643573:tid 643723] [client 20.100.187.246:7774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuAt_xWyxgRnoFKAJ_tIgAAAiE"]
[Thu Jul 30 11:50:00.095400 2026] [security2:error] [pid 643573:tid 643782] [client 176.241.66.87:11317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAuPxWyxgRnoFKAJ_tJgAAAlw"]
[Thu Jul 30 11:50:00.095544 2026] [security2:error] [pid 643573:tid 643782] [client 176.241.66.87:11317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAuPxWyxgRnoFKAJ_tJgAAAlw"]
[Thu Jul 30 11:50:01.397844 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/users.php"] [unique_id "amuAufxWyxgRnoFKAJ_tPAAAAmY"]
[Thu Jul 30 11:50:01.397993 2026] [security2:error] [pid 643573:tid 643792] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/users.php"] [unique_id "amuAufxWyxgRnoFKAJ_tPAAAAmY"]
[Thu Jul 30 11:50:01.422027 2026] [core:error] [pid 643573:tid 643583] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wp/
[Thu Jul 30 11:50:01.422050 2026] [core:error] [pid 643573:tid 643583] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wp/
[Thu Jul 30 11:50:01.422880 2026] [security2:error] [pid 642360:tid 642575] [client 198.54.128.138:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuAuZSUkh3e5AhEJOBpdwAAAeQ"]
[Thu Jul 30 11:50:01.422959 2026] [security2:error] [pid 642360:tid 642575] [client 198.54.128.138:50756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuAuZSUkh3e5AhEJOBpdwAAAeQ"]
[Thu Jul 30 11:50:01.673233 2026] [security2:error] [pid 643573:tid 643766] [client 20.100.187.246:16888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/flower.php"] [unique_id "amuAufxWyxgRnoFKAJ_tQgAAAkw"]
[Thu Jul 30 11:50:01.737838 2026] [security2:error] [pid 643573:tid 643724] [client 52.22.64.232:7283] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/1455/xdc0ccf5f4bd9e8c2a4674ee92378cf27.jpg.pagespeed.ic.PXGK_Uz8yM.webp"] [unique_id "amuAufxWyxgRnoFKAJ_tQwAAAiI"]
[Thu Jul 30 11:50:01.979194 2026] [core:error] [pid 642360:tid 642379] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wp/
[Thu Jul 30 11:50:01.979223 2026] [core:error] [pid 642360:tid 642379] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wp/
[Thu Jul 30 11:50:02.192891 2026] [core:error] [pid 642360:tid 642479] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wordpress/
[Thu Jul 30 11:50:02.192913 2026] [core:error] [pid 642360:tid 642479] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wordpress/
[Thu Jul 30 11:50:02.282519 2026] [core:notice] [pid 642360:tid 642610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:02.289465 2026] [security2:error] [pid 642360:tid 642610] [client 103.215.74.26:11300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAupSUkh3e5AhEJOBphwAAAgc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:02.754505 2026] [core:error] [pid 643573:tid 643696] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wordpress/
[Thu Jul 30 11:50:02.754532 2026] [core:error] [pid 643573:tid 643696] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/wordpress/
[Thu Jul 30 11:50:02.931787 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:03.014537 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:03.019533 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:47912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAu8jqbtjBYzqM1uYlrwAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:03.114361 2026] [security2:error] [pid 643573:tid 643775] [client 20.100.187.246:15334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/xleet.php"] [unique_id "amuAu_xWyxgRnoFKAJ_tVgAAAlU"]
[Thu Jul 30 11:50:03.256687 2026] [core:notice] [pid 643573:tid 643791] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:03.319198 2026] [core:error] [pid 642360:tid 642396] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/blog/
[Thu Jul 30 11:50:03.319223 2026] [core:error] [pid 642360:tid 642396] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/blog/
[Thu Jul 30 11:50:03.548830 2026] [core:error] [pid 642360:tid 642371] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/blog/
[Thu Jul 30 11:50:03.548874 2026] [core:error] [pid 642360:tid 642371] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/blog/
[Thu Jul 30 11:50:03.763243 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:03.768099 2026] [security2:error] [pid 642360:tid 642601] [client 103.215.74.26:47920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAu5SUkh3e5AhEJOBpqAAAAf4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:03.795191 2026] [security2:error] [pid 642360:tid 642608] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAu5SUkh3e5AhEJOBpnwAAAgU"]
[Thu Jul 30 11:50:04.056724 2026] [security2:error] [pid 642360:tid 642574] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tinysd.php"] [unique_id "amuAvJSUkh3e5AhEJOBpsAAAAeM"]
[Thu Jul 30 11:50:04.056844 2026] [security2:error] [pid 642360:tid 642574] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/tinysd.php"] [unique_id "amuAvJSUkh3e5AhEJOBpsAAAAeM"]
[Thu Jul 30 11:50:04.114006 2026] [core:error] [pid 642360:tid 642421] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/old/
[Thu Jul 30 11:50:04.114034 2026] [core:error] [pid 642360:tid 642421] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/old/
[Thu Jul 30 11:50:04.501137 2026] [core:notice] [pid 643573:tid 643832] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:04.505586 2026] [security2:error] [pid 643573:tid 643832] [client 103.215.74.26:47922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAvPxWyxgRnoFKAJ_tbgAAAo4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:04.554821 2026] [security2:error] [pid 642360:tid 642617] [client 20.100.187.246:21005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuAvJSUkh3e5AhEJOBptwAAAg4"]
[Thu Jul 30 11:50:04.700708 2026] [core:error] [pid 643253:tid 643274] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/old/
[Thu Jul 30 11:50:04.700730 2026] [core:error] [pid 643253:tid 643274] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/old/
[Thu Jul 30 11:50:04.919207 2026] [core:error] [pid 643573:tid 643628] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/test/
[Thu Jul 30 11:50:04.919227 2026] [core:error] [pid 643573:tid 643628] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/test/
[Thu Jul 30 11:50:05.138104 2026] [core:error] [pid 643573:tid 643634] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/test/
[Thu Jul 30 11:50:05.138131 2026] [core:error] [pid 643573:tid 643634] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/test/
[Thu Jul 30 11:50:05.355366 2026] [core:error] [pid 642360:tid 642408] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/dev/
[Thu Jul 30 11:50:05.355386 2026] [core:error] [pid 642360:tid 642408] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/dev/
[Thu Jul 30 11:50:05.583494 2026] [core:error] [pid 642360:tid 642417] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/dev/
[Thu Jul 30 11:50:05.583514 2026] [core:error] [pid 642360:tid 642417] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/dev/
[Thu Jul 30 11:50:05.645221 2026] [security2:error] [pid 643573:tid 643710] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuAu_xWyxgRnoFKAJ_tXgAAAhQ"]
[Thu Jul 30 11:50:05.733541 2026] [security2:error] [pid 643573:tid 643788] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ws78.php"] [unique_id "amuAvfxWyxgRnoFKAJ_trQAAAmI"]
[Thu Jul 30 11:50:05.733664 2026] [security2:error] [pid 643573:tid 643788] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ws78.php"] [unique_id "amuAvfxWyxgRnoFKAJ_trQAAAmI"]
[Thu Jul 30 11:50:05.795056 2026] [core:error] [pid 643573:tid 643647] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/backup/
[Thu Jul 30 11:50:05.795084 2026] [core:error] [pid 643573:tid 643647] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/backup/
[Thu Jul 30 11:50:06.011055 2026] [core:error] [pid 643573:tid 643604] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/backup/
[Thu Jul 30 11:50:06.011083 2026] [core:error] [pid 643573:tid 643604] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/backup/
[Thu Jul 30 11:50:06.223869 2026] [core:error] [pid 643573:tid 643674] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/staging/
[Thu Jul 30 11:50:06.223896 2026] [core:error] [pid 643573:tid 643674] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/staging/
[Thu Jul 30 11:50:06.281893 2026] [security2:error] [pid 643573:tid 643726] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/elp.php"] [unique_id "amuAvvxWyxgRnoFKAJ_twwAAAiQ"]
[Thu Jul 30 11:50:06.282003 2026] [security2:error] [pid 643573:tid 643726] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/elp.php"] [unique_id "amuAvvxWyxgRnoFKAJ_twwAAAiQ"]
[Thu Jul 30 11:50:06.434430 2026] [core:error] [pid 642360:tid 642418] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/staging/
[Thu Jul 30 11:50:06.434450 2026] [core:error] [pid 642360:tid 642418] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/staging/
[Thu Jul 30 11:50:06.607443 2026] [core:error] [pid 643573:tid 643821] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:06.607464 2026] [core:error] [pid 643573:tid 643821] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:06.607557 2026] [security2:error] [pid 643573:tid 643821] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webdisk.theregentsbarber.com.au"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_tzgAAAoM"]
[Thu Jul 30 11:50:06.608102 2026] [security2:error] [pid 643573:tid 643793] [client 35.221.246.130:37732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webdisk.theregentsbarber.com.au"] [uri "/___proxy_subdomain_webdisk/.git/config"] [unique_id "amuAvvxWyxgRnoFKAJ_tywAAAmc"]
[Thu Jul 30 11:50:06.853605 2026] [security2:error] [pid 643573:tid 643775] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/atomlib.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t2wAAAlU"]
[Thu Jul 30 11:50:06.853700 2026] [security2:error] [pid 643573:tid 643775] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/atomlib.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t2wAAAlU"]
[Thu Jul 30 11:50:06.976659 2026] [core:error] [pid 643573:tid 643637] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:50:06.976681 2026] [core:error] [pid 643573:tid 643637] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:50:07.018171 2026] [security2:error] [pid 642360:tid 642558] [client 216.244.66.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "embassyofspaininpakistan.info"] [uri "/robots.txt"] [unique_id "amuAv5SUkh3e5AhEJOBpzwAAAdM"]
[Thu Jul 30 11:50:07.018298 2026] [security2:error] [pid 642360:tid 642558] [client 216.244.66.250:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "embassyofspaininpakistan.info"] [uri "/robots.txt"] [unique_id "amuAv5SUkh3e5AhEJOBpzwAAAdM"]
[Thu Jul 30 11:50:07.196256 2026] [core:error] [pid 642360:tid 642425] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:50:07.196294 2026] [core:error] [pid 642360:tid 642425] [remote 93.123.109.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.applinex.pro/
[Thu Jul 30 11:50:07.257031 2026] [security2:error] [pid 643573:tid 643794] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t3gAAAmg"]
[Thu Jul 30 11:50:07.264861 2026] [core:error] [pid 643573:tid 643751] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.264881 2026] [core:error] [pid 643573:tid 643751] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.264996 2026] [security2:error] [pid 643573:tid 643751] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.theregentsbarber.com.au"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuAv_xWyxgRnoFKAJ_t5wAAAj0"]
[Thu Jul 30 11:50:07.266865 2026] [security2:error] [pid 642360:tid 642595] [client 35.221.246.130:37738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.theregentsbarber.com.au"] [uri "/___proxy_subdomain_webmail/.git/config"] [unique_id "amuAv5SUkh3e5AhEJOBp1gAAAfg"]
[Thu Jul 30 11:50:07.274480 2026] [core:error] [pid 643573:tid 643810] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.274498 2026] [core:error] [pid 643573:tid 643810] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.274604 2026] [core:error] [pid 643573:tid 643712] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.274626 2026] [core:error] [pid 643573:tid 643712] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.282072 2026] [security2:error] [pid 642360:tid 642428] [remote 52.238.199.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afropakmedical.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuAv5SUkh3e5AhEJOBp2AABxEM"]
[Thu Jul 30 11:50:07.313057 2026] [core:error] [pid 643573:tid 643783] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313077 2026] [core:error] [pid 643573:tid 643783] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313423 2026] [core:error] [pid 643573:tid 643722] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313433 2026] [core:error] [pid 643573:tid 643722] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313484 2026] [core:error] [pid 642360:tid 642500] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.313500 2026] [core:error] [pid 642360:tid 642500] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.444482 2026] [security2:error] [pid 643573:tid 643782] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wyzer3.php"] [unique_id "amuAv_xWyxgRnoFKAJ_t_AAAAlw"]
[Thu Jul 30 11:50:07.444590 2026] [security2:error] [pid 643573:tid 643782] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/wyzer3.php"] [unique_id "amuAv_xWyxgRnoFKAJ_t_AAAAlw"]
[Thu Jul 30 11:50:07.980368 2026] [core:error] [pid 642360:tid 642586] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.980397 2026] [core:error] [pid 642360:tid 642586] [client 35.221.246.130:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:07.980561 2026] [security2:error] [pid 642360:tid 642586] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.theregentsbarber.com.au"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuAv5SUkh3e5AhEJOBp5QAAAe8"]
[Thu Jul 30 11:50:07.981257 2026] [security2:error] [pid 643573:tid 643730] [client 35.221.246.130:37756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.theregentsbarber.com.au"] [uri "/___proxy_subdomain_cpanel/.git/config"] [unique_id "amuAv_xWyxgRnoFKAJ_uEQAAAig"]
[Thu Jul 30 11:50:07.984160 2026] [security2:error] [pid 642360:tid 642527] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/max.php"] [unique_id "amuAv5SUkh3e5AhEJOBp5gAAAbQ"]
[Thu Jul 30 11:50:07.984247 2026] [security2:error] [pid 642360:tid 642527] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/max.php"] [unique_id "amuAv5SUkh3e5AhEJOBp5gAAAbQ"]
[Thu Jul 30 11:50:08.039005 2026] [security2:error] [pid 643573:tid 643720] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuAv_xWyxgRnoFKAJ_t-wAAAh4"]
[Thu Jul 30 11:50:08.251233 2026] [security2:error] [pid 643573:tid 643725] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuAv_xWyxgRnoFKAJ_uDwAAAiM"]
[Thu Jul 30 11:50:08.413471 2026] [security2:error] [pid 643573:tid 643611] [remote 45.252.248.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.248.252.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesounddepot.com"] [uri "/wp-login.php"] [unique_id "amuAwPxWyxgRnoFKAJ_uHQACiB4"]
[Thu Jul 30 11:50:08.559282 2026] [security2:error] [pid 643573:tid 643793] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ftde.php"] [unique_id "amuAwPxWyxgRnoFKAJ_uHgAAAmc"]
[Thu Jul 30 11:50:08.559400 2026] [security2:error] [pid 643573:tid 643793] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.prestigemassagestudio.cfd"] [uri "/ftde.php"] [unique_id "amuAwPxWyxgRnoFKAJ_uHgAAAmc"]
[Thu Jul 30 11:50:08.635703 2026] [security2:error] [pid 643573:tid 643715] [client 20.100.187.246:7781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuAwPxWyxgRnoFKAJ_uHwAAAhk"]
[Thu Jul 30 11:50:08.699498 2026] [security2:error] [pid 642360:tid 642532] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.theregentsbarber.com.au"] [uri "/index.php"] [unique_id "amuAv5SUkh3e5AhEJOBp4gAAAbk"]
[Thu Jul 30 11:50:08.699525 2026] [security2:error] [pid 642360:tid 642532] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.theregentsbarber.com.au"] [uri "/index.php"] [unique_id "amuAv5SUkh3e5AhEJOBp4gAAAbk"]
[Thu Jul 30 11:50:08.700170 2026] [security2:error] [pid 642360:tid 642556] [client 35.221.246.130:37748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.theregentsbarber.com.au"] [uri "/.git/config"] [unique_id "amuAv5SUkh3e5AhEJOBp4AAAAdE"]
[Thu Jul 30 11:50:08.768648 2026] [core:notice] [pid 643573:tid 643827] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:08.802141 2026] [security2:error] [pid 643573:tid 643754] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.theregentsbarber.com.au"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t2gAAAkA"]
[Thu Jul 30 11:50:08.802176 2026] [security2:error] [pid 643573:tid 643754] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.theregentsbarber.com.au"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t2gAAAkA"]
[Thu Jul 30 11:50:08.803003 2026] [security2:error] [pid 643573:tid 643759] [client 35.221.246.130:37720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.theregentsbarber.com.au"] [uri "/.git/config"] [unique_id "amuAvvxWyxgRnoFKAJ_t2AAAAkU"]
[Thu Jul 30 11:50:09.109387 2026] [security2:error] [pid 643573:tid 643796] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-d54872a1.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t0wAAAmo"]
[Thu Jul 30 11:50:09.109421 2026] [security2:error] [pid 643573:tid 643796] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.website-d54872a1.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuAvvxWyxgRnoFKAJ_t0wAAAmo"]
[Thu Jul 30 11:50:09.110023 2026] [security2:error] [pid 642360:tid 642539] [client 35.221.246.130:37706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.website-d54872a1.ear.djb.temporary.site"] [uri "/.git/config"] [unique_id "amuAvpSUkh3e5AhEJOBpzgAAAcA"]
[Thu Jul 30 11:50:09.713660 2026] [security2:error] [pid 643573:tid 643725] [client 20.100.187.246:14873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuAwfxWyxgRnoFKAJ_uNwAAAiM"]
[Thu Jul 30 11:50:10.142833 2026] [security2:error] [pid 642360:tid 642576] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuAwZSUkh3e5AhEJOBp_AAB5TA"]
[Thu Jul 30 11:50:10.312152 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:10.318764 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:47924] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAwvxWyxgRnoFKAJ_uRQAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:10.753595 2026] [security2:error] [pid 643573:tid 643775] [client 176.241.66.87:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAwvxWyxgRnoFKAJ_uUAAAAlU"]
[Thu Jul 30 11:50:10.753703 2026] [security2:error] [pid 643573:tid 643775] [client 176.241.66.87:64760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAwvxWyxgRnoFKAJ_uUAAAAlU"]
[Thu Jul 30 11:50:10.920421 2026] [security2:error] [pid 643573:tid 643788] [client 20.100.187.246:20994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuAwvxWyxgRnoFKAJ_uVQAAAmI"]
[Thu Jul 30 11:50:10.997226 2026] [core:notice] [pid 643573:tid 643805] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:11.063461 2026] [core:notice] [pid 643573:tid 643758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:11.070962 2026] [security2:error] [pid 643573:tid 643758] [client 103.215.74.26:47936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAw_xWyxgRnoFKAJ_uVwAAAkQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:11.814004 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:11.817880 2026] [security2:error] [pid 642360:tid 642551] [client 103.215.74.26:47952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAw5SUkh3e5AhEJOBqCwAAAcw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:12.417539 2026] [core:error] [pid 643573:tid 643731] [client 74.7.241.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:12.417563 2026] [core:error] [pid 643573:tid 643731] [client 74.7.241.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:12.417704 2026] [security2:error] [pid 643573:tid 643731] [client 74.7.241.152:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.hvacairductscleaners.us"] [uri "/website_141a2c45/index.php"] [unique_id "amuAxPxWyxgRnoFKAJ_uagAAAik"]
[Thu Jul 30 11:50:12.418902 2026] [security2:error] [pid 643573:tid 643759] [client 74.7.241.152:42592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.hvacairductscleaners.us"] [uri "/robots.txt"] [unique_id "amuAxPxWyxgRnoFKAJ_uaAACRUw"]
[Thu Jul 30 11:50:12.437454 2026] [security2:error] [pid 643253:tid 643275] [remote 74.7.241.60:41884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuAxMjqbtjBYzqM1uYlwQAAUBQ"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:50:13.843132 2026] [security2:error] [pid 643573:tid 643803] [client 20.100.187.246:14894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuAxfxWyxgRnoFKAJ_ueAAAAnE"]
[Thu Jul 30 11:50:14.302621 2026] [proxy:error] [pid 643253:tid 643454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:50:14.302696 2026] [proxy_http:error] [pid 643253:tid 643454] [client 74.7.241.156:52084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:50:14.303266 2026] [proxy:error] [pid 643253:tid 643454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:50:14.303317 2026] [proxy_http:error] [pid 643253:tid 643454] [client 74.7.241.156:52084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:50:14.303447 2026] [security2:error] [pid 643253:tid 643454] [client 74.7.241.156:52084] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.qse.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuAxsjqbtjBYzqM1uYlwwAAAEY"]
[Thu Jul 30 11:50:15.631852 2026] [security2:error] [pid 643573:tid 643653] [remote 173.231.241.109:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.241.231.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ldk.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuAx_xWyxgRnoFKAJ_uhgACikg"]
[Thu Jul 30 11:50:16.716436 2026] [core:error] [pid 642360:tid 642531] [client 162.19.8.250:49518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:16.716468 2026] [core:error] [pid 642360:tid 642531] [client 162.19.8.250:49518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:17.551277 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:17.555341 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:34376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAyfxWyxgRnoFKAJ_ulQAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:17.642465 2026] [core:error] [pid 643573:tid 643726] [client 162.19.8.250:49534] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:17.642485 2026] [core:error] [pid 643573:tid 643726] [client 162.19.8.250:49534] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:17.655747 2026] [core:notice] [pid 643573:tid 643669] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:18.310962 2026] [core:notice] [pid 643573:tid 643792] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:18.317097 2026] [security2:error] [pid 643573:tid 643792] [client 103.215.74.26:34378] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAyvxWyxgRnoFKAJ_unwAAAmY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:18.413245 2026] [core:error] [pid 643573:tid 643824] [client 162.19.8.250:49550] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:18.413267 2026] [core:error] [pid 643573:tid 643824] [client 162.19.8.250:49550] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:18.945814 2026] [core:error] [pid 643573:tid 643732] [client 162.19.8.250:49564] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:18.945841 2026] [core:error] [pid 643573:tid 643732] [client 162.19.8.250:49564] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:19.063340 2026] [core:notice] [pid 643573:tid 643793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:19.067296 2026] [security2:error] [pid 643573:tid 643793] [client 103.215.74.26:34380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "774"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAy_xWyxgRnoFKAJ_uqQAAAmc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:19.437321 2026] [core:notice] [pid 643573:tid 643672] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:19.559167 2026] [core:error] [pid 642360:tid 642565] [client 162.19.8.250:49580] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:19.559194 2026] [core:error] [pid 642360:tid 642565] [client 162.19.8.250:49580] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:19.826762 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:19.831352 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:34386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAy_xWyxgRnoFKAJ_usAAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:20.150648 2026] [core:error] [pid 643573:tid 643765] [client 162.19.8.250:49596] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:20.150671 2026] [core:error] [pid 643573:tid 643765] [client 162.19.8.250:49596] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:20.215464 2026] [security2:error] [pid 643573:tid 643749] [client 103.216.116.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuAzPxWyxgRnoFKAJ_usgAAAjs"], referer: https://cnpinyin.com/register
[Thu Jul 30 11:50:20.579219 2026] [core:notice] [pid 643573:tid 643731] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:20.583937 2026] [security2:error] [pid 643573:tid 643731] [client 103.215.74.26:34388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAzPxWyxgRnoFKAJ_uuAAAAik"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:20.714731 2026] [core:error] [pid 642360:tid 642612] [client 162.19.8.250:49612] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:20.714751 2026] [core:error] [pid 642360:tid 642612] [client 162.19.8.250:49612] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:20.997902 2026] [security2:error] [pid 643573:tid 643717] [client 20.100.187.246:21116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuAzPxWyxgRnoFKAJ_uvwAAAhs"]
[Thu Jul 30 11:50:21.207621 2026] [core:error] [pid 643573:tid 643833] [client 162.19.8.250:49626] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:21.207651 2026] [core:error] [pid 643573:tid 643833] [client 162.19.8.250:49626] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:21.318886 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:21.322738 2026] [security2:error] [pid 643573:tid 643756] [client 103.215.74.26:34394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAzfxWyxgRnoFKAJ_uwgAAAkI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:21.357487 2026] [security2:error] [pid 643573:tid 643809] [client 176.241.66.87:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAzfxWyxgRnoFKAJ_uxgAAAnc"]
[Thu Jul 30 11:50:21.357643 2026] [security2:error] [pid 643573:tid 643809] [client 176.241.66.87:65312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuAzfxWyxgRnoFKAJ_uxgAAAnc"]
[Thu Jul 30 11:50:21.676512 2026] [core:error] [pid 643573:tid 643721] [client 162.19.8.250:49634] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:21.676542 2026] [core:error] [pid 643573:tid 643721] [client 162.19.8.250:49634] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.072249 2026] [core:notice] [pid 642360:tid 642500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:22.076773 2026] [security2:error] [pid 642360:tid 642500] [client 103.215.74.26:34402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAzpSUkh3e5AhEJOBqXAAAAZk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:22.251212 2026] [core:error] [pid 643573:tid 643819] [client 162.19.8.250:49640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.251242 2026] [core:error] [pid 643573:tid 643819] [client 162.19.8.250:49640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.340317 2026] [security2:error] [pid 643573:tid 643725] [client 20.100.187.246:7736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuAzvxWyxgRnoFKAJ_u0QAAAiM"]
[Thu Jul 30 11:50:22.776515 2026] [core:error] [pid 643253:tid 643465] [client 162.19.8.250:49646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.776546 2026] [core:error] [pid 643253:tid 643465] [client 162.19.8.250:49646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:22.827730 2026] [core:notice] [pid 643573:tid 643818] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:22.831950 2026] [security2:error] [pid 643573:tid 643818] [client 103.215.74.26:34414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAzvxWyxgRnoFKAJ_u1gAAAoA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:22.972874 2026] [security2:error] [pid 643573:tid 643723] [client 20.100.187.246:7831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuAzvxWyxgRnoFKAJ_u2gAAAiE"]
[Thu Jul 30 11:50:23.167497 2026] [core:error] [pid 643573:tid 643726] [client 162.19.8.250:49656] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:23.167518 2026] [core:error] [pid 643573:tid 643726] [client 162.19.8.250:49656] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:23.598431 2026] [core:notice] [pid 643573:tid 643745] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:23.602656 2026] [security2:error] [pid 643573:tid 643745] [client 103.215.74.26:19864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuAz_xWyxgRnoFKAJ_u5AAAAjc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:23.775497 2026] [core:error] [pid 643573:tid 643804] [client 162.19.8.250:49670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:23.775524 2026] [core:error] [pid 643573:tid 643804] [client 162.19.8.250:49670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:23.985426 2026] [security2:error] [pid 643573:tid 643665] [remote 47.128.28.112:33292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-aj1-air-jordan-1-low-christmas-white-red/"] [unique_id "amuAz_xWyxgRnoFKAJ_u6QACe1Q"]
[Thu Jul 30 11:50:24.199527 2026] [core:error] [pid 643253:tid 643439] [client 162.19.8.250:49676] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:24.199558 2026] [core:error] [pid 643253:tid 643439] [client 162.19.8.250:49676] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:24.364730 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:24.369063 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:19880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0PxWyxgRnoFKAJ_u7AAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:24.715558 2026] [core:notice] [pid 643573:tid 643660] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:24.782991 2026] [core:error] [pid 643573:tid 643818] [client 162.19.8.250:49684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:24.783012 2026] [core:error] [pid 643573:tid 643818] [client 162.19.8.250:49684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:24.795320 2026] [security2:error] [pid 643573:tid 643760] [client 20.100.187.246:29298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuA0PxWyxgRnoFKAJ_u9QAAAkY"]
[Thu Jul 30 11:50:25.084738 2026] [core:notice] [pid 643573:tid 643795] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:25.089093 2026] [security2:error] [pid 643573:tid 643795] [client 103.215.74.26:19890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0fxWyxgRnoFKAJ_u-AAAAmk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:25.545900 2026] [security2:error] [pid 643573:tid 643823] [client 20.100.187.246:7697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuA0fxWyxgRnoFKAJ_u-gAAAoU"]
[Thu Jul 30 11:50:25.811602 2026] [core:notice] [pid 643573:tid 643810] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:25.815913 2026] [security2:error] [pid 643573:tid 643810] [client 103.215.74.26:19894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0fxWyxgRnoFKAJ_u_wAAAng"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:26.217601 2026] [security2:error] [pid 643573:tid 643762] [client 20.100.187.246:7729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuA0vxWyxgRnoFKAJ_vBQAAAkg"]
[Thu Jul 30 11:50:26.405833 2026] [core:error] [pid 643573:tid 643715] [client 162.19.8.250:58352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:26.405857 2026] [core:error] [pid 643573:tid 643715] [client 162.19.8.250:58352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:26.552198 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:26.556707 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:19898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0sjqbtjBYzqM1uYl0wAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:26.800860 2026] [core:error] [pid 642360:tid 642518] [client 162.19.8.250:58368] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:26.800882 2026] [core:error] [pid 642360:tid 642518] [client 162.19.8.250:58368] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:26.900691 2026] [security2:error] [pid 643573:tid 643800] [client 20.100.187.246:14389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuA0vxWyxgRnoFKAJ_vCAAAAm4"]
[Thu Jul 30 11:50:27.301645 2026] [core:error] [pid 643253:tid 643502] [client 162.19.8.250:58384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:27.301668 2026] [core:error] [pid 643253:tid 643502] [client 162.19.8.250:58384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:27.305703 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:27.310016 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:19908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA0_xWyxgRnoFKAJ_vDgAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:27.564684 2026] [security2:error] [pid 643573:tid 643743] [client 20.100.187.246:12644] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.lilyinspires.com"] [uri "/1.php"] [unique_id "amuA0_xWyxgRnoFKAJ_vDwAAAjU"]
[Thu Jul 30 11:50:27.564824 2026] [security2:error] [pid 643573:tid 643743] [client 20.100.187.246:12644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/1.php"] [unique_id "amuA0_xWyxgRnoFKAJ_vDwAAAjU"]
[Thu Jul 30 11:50:27.713020 2026] [core:error] [pid 643573:tid 643760] [client 162.19.8.250:58398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:27.713042 2026] [core:error] [pid 643573:tid 643760] [client 162.19.8.250:58398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:28.035171 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:28.039581 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:19920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA1PxWyxgRnoFKAJ_vFgAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:28.117730 2026] [security2:error] [pid 643573:tid 643747] [client 74.7.228.57:53842] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ooj.hfl.temporary.site"] [uri "/index.php"] [unique_id "amuA0_xWyxgRnoFKAJ_vFAACOR0"]
[Thu Jul 30 11:50:28.713153 2026] [security2:error] [pid 643573:tid 643766] [client 20.100.187.246:29259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/admin.php"] [unique_id "amuA1PxWyxgRnoFKAJ_vHQAAAkw"]
[Thu Jul 30 11:50:29.526639 2026] [security2:error] [pid 643573:tid 643800] [client 20.100.187.246:7680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/as.php"] [unique_id "amuA1fxWyxgRnoFKAJ_vJwAAAm4"]
[Thu Jul 30 11:50:31.077621 2026] [security2:error] [pid 643573:tid 643720] [client 20.100.187.246:19549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/autoload_classmap.php"] [unique_id "amuA1_xWyxgRnoFKAJ_vNQAAAh4"]
[Thu Jul 30 11:50:31.341337 2026] [autoindex:error] [pid 643253:tid 643417] [client 43.135.145.73:53826] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:50:31.536343 2026] [security2:error] [pid 643573:tid 643776] [client 66.249.64.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.skilledfurnituremoversuae.com"] [uri "/index.php"] [unique_id "amuA1fxWyxgRnoFKAJ_vJQAAAlY"]
[Thu Jul 30 11:50:31.986139 2026] [security2:error] [pid 643573:tid 643755] [client 176.241.66.87:13167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA1_xWyxgRnoFKAJ_vPgAAAkE"]
[Thu Jul 30 11:50:31.986269 2026] [security2:error] [pid 643573:tid 643755] [client 176.241.66.87:13167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA1_xWyxgRnoFKAJ_vPgAAAkE"]
[Thu Jul 30 11:50:33.773966 2026] [core:notice] [pid 643573:tid 643764] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:33.778400 2026] [security2:error] [pid 643573:tid 643764] [client 103.215.74.26:5832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA2fxWyxgRnoFKAJ_vSQAAAko"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:33.952153 2026] [core:error] [pid 643573:tid 643662] [remote 216.73.216.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:33.952175 2026] [core:error] [pid 643573:tid 643662] [remote 216.73.216.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:34.478951 2026] [security2:error] [pid 643573:tid 643711] [client 20.100.187.246:13313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/back.php"] [unique_id "amuA2vxWyxgRnoFKAJ_vUQAAAhU"]
[Thu Jul 30 11:50:35.486685 2026] [security2:error] [pid 643573:tid 643772] [client 20.100.187.246:13353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vZQAAAlI"]
[Thu Jul 30 11:50:36.401312 2026] [security2:error] [pid 643253:tid 643508] [client 127.0.0.1:13056] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuA3MjqbtjBYzqM1uYl6AAAAHw"]
[Thu Jul 30 11:50:36.402368 2026] [security2:error] [pid 642360:tid 642593] [client 74.7.228.62:44578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.qmv.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuA3JSUkh3e5AhEJOBq1wAAAfY"]
[Thu Jul 30 11:50:36.535739 2026] [security2:error] [pid 643573:tid 643820] [client 172.237.109.114:14406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vVwAAAoI"]
[Thu Jul 30 11:50:37.182376 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:37.219449 2026] [security2:error] [pid 642360:tid 642509] [client 172.237.109.114:42514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqxQAAAaI"]
[Thu Jul 30 11:50:37.225960 2026] [security2:error] [pid 642360:tid 642590] [client 172.237.109.114:9546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqwgAAAfM"]
[Thu Jul 30 11:50:37.228672 2026] [security2:error] [pid 643573:tid 643800] [client 172.237.109.114:35766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vWwAAAm4"]
[Thu Jul 30 11:50:37.253016 2026] [security2:error] [pid 643573:tid 643817] [client 172.237.109.114:60726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vXQAAAn8"]
[Thu Jul 30 11:50:37.255277 2026] [security2:error] [pid 643573:tid 643754] [client 172.237.109.114:63104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vWgAAAkA"]
[Thu Jul 30 11:50:37.266235 2026] [security2:error] [pid 642360:tid 642614] [client 172.237.109.114:58275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqyQAAAgs"]
[Thu Jul 30 11:50:37.290561 2026] [security2:error] [pid 642360:tid 642542] [client 172.237.109.114:19998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqygAAAcM"]
[Thu Jul 30 11:50:37.302735 2026] [security2:error] [pid 643573:tid 643827] [client 172.237.109.114:41738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vWAAAAok"]
[Thu Jul 30 11:50:37.310692 2026] [security2:error] [pid 642360:tid 642560] [client 172.237.109.114:38131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqxwAAAdU"]
[Thu Jul 30 11:50:37.331049 2026] [security2:error] [pid 643573:tid 643803] [client 172.237.109.114:45642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vWQAAAnE"]
[Thu Jul 30 11:50:37.331628 2026] [security2:error] [pid 643573:tid 643773] [client 172.237.109.114:4834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vYAAAAlM"]
[Thu Jul 30 11:50:37.339936 2026] [security2:error] [pid 643573:tid 643750] [client 172.237.109.114:40932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vYwAAAjw"]
[Thu Jul 30 11:50:37.343196 2026] [security2:error] [pid 643253:tid 643447] [client 172.237.109.114:36517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA28jqbtjBYzqM1uYl4wAAAD8"]
[Thu Jul 30 11:50:37.350920 2026] [security2:error] [pid 642360:tid 642577] [client 172.237.109.114:31979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqyAAAAeY"]
[Thu Jul 30 11:50:37.357204 2026] [security2:error] [pid 642360:tid 642611] [client 172.237.109.114:30203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqwwAAAgg"]
[Thu Jul 30 11:50:37.392436 2026] [security2:error] [pid 643573:tid 643729] [client 172.237.109.114:45415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vXgAAAic"]
[Thu Jul 30 11:50:37.392527 2026] [security2:error] [pid 642360:tid 642550] [client 172.237.109.114:30844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA25SUkh3e5AhEJOBqywAAAcs"]
[Thu Jul 30 11:50:37.406268 2026] [security2:error] [pid 643573:tid 643789] [client 172.237.109.114:25015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA2_xWyxgRnoFKAJ_vZAAAAmM"]
[Thu Jul 30 11:50:37.417939 2026] [security2:error] [pid 643253:tid 643470] [client 172.237.109.114:7425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA28jqbtjBYzqM1uYl4gAAAFY"]
[Thu Jul 30 11:50:37.997814 2026] [security2:error] [pid 643253:tid 643393] [client 20.100.187.246:12642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/c/flower.php"] [unique_id "amuA3cjqbtjBYzqM1uYl6wAAAAk"]
[Thu Jul 30 11:50:38.927378 2026] [security2:error] [pid 643573:tid 643788] [client 20.100.187.246:12615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/c/xleet.php"] [unique_id "amuA3vxWyxgRnoFKAJ_vhwAAAmI"]
[Thu Jul 30 11:50:39.275801 2026] [security2:error] [pid 643573:tid 643829] [client 172.237.109.114:6474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vdgAAAos"]
[Thu Jul 30 11:50:39.309547 2026] [security2:error] [pid 643573:tid 643711] [client 172.237.109.114:26727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vcQAAAhU"]
[Thu Jul 30 11:50:39.309626 2026] [security2:error] [pid 643573:tid 643724] [client 172.237.109.114:53130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vdQAAAiI"]
[Thu Jul 30 11:50:39.312946 2026] [security2:error] [pid 642360:tid 642507] [client 172.237.109.114:47388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq3wAAAaA"]
[Thu Jul 30 11:50:39.315152 2026] [security2:error] [pid 642360:tid 642603] [client 172.237.109.114:45681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq4AAAAgA"]
[Thu Jul 30 11:50:39.328699 2026] [security2:error] [pid 643573:tid 643797] [client 172.237.109.114:64947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_veAAAAms"]
[Thu Jul 30 11:50:39.339370 2026] [security2:error] [pid 643253:tid 643423] [client 172.237.109.114:14625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3cjqbtjBYzqM1uYl6gAAACc"]
[Thu Jul 30 11:50:39.344403 2026] [security2:error] [pid 643573:tid 643802] [client 172.237.109.114:7824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vegAAAnA"]
[Thu Jul 30 11:50:39.348298 2026] [security2:error] [pid 642360:tid 642512] [client 172.237.109.114:9820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq4wAAAaU"]
[Thu Jul 30 11:50:39.364354 2026] [security2:error] [pid 643573:tid 643755] [client 172.237.109.114:17269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vcwAAAkE"]
[Thu Jul 30 11:50:39.364949 2026] [security2:error] [pid 643573:tid 643784] [client 172.237.109.114:54214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_veQAAAl4"]
[Thu Jul 30 11:50:39.373443 2026] [security2:error] [pid 643573:tid 643819] [client 172.237.109.114:63931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vewAAAoE"]
[Thu Jul 30 11:50:39.379385 2026] [security2:error] [pid 642360:tid 642563] [client 172.237.109.114:29249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq3QAAAdg"]
[Thu Jul 30 11:50:39.399482 2026] [security2:error] [pid 643573:tid 643811] [client 172.237.109.114:38727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vcgAAAnk"]
[Thu Jul 30 11:50:39.405080 2026] [security2:error] [pid 642360:tid 642522] [client 172.237.109.114:6124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3ZSUkh3e5AhEJOBq3gAAAa8"]
[Thu Jul 30 11:50:39.412496 2026] [security2:error] [pid 643573:tid 643821] [client 172.237.109.114:42556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3fxWyxgRnoFKAJ_vdAAAAoM"]
[Thu Jul 30 11:50:39.521883 2026] [core:notice] [pid 643253:tid 643408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:39.529325 2026] [security2:error] [pid 643253:tid 643408] [client 103.215.74.26:5862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA38jqbtjBYzqM1uYl8AAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:39.539838 2026] [security2:error] [pid 642360:tid 642580] [client 172.237.109.114:2991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3pSUkh3e5AhEJOBq6AAAAek"]
[Thu Jul 30 11:50:39.555482 2026] [security2:error] [pid 642360:tid 642520] [client 172.237.109.114:7903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3pSUkh3e5AhEJOBq6gAAAa0"]
[Thu Jul 30 11:50:39.558546 2026] [security2:error] [pid 643573:tid 643775] [client 172.237.109.114:7802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3vxWyxgRnoFKAJ_vggAAAlU"]
[Thu Jul 30 11:50:39.583470 2026] [security2:error] [pid 642360:tid 642610] [client 172.237.109.114:26425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA3pSUkh3e5AhEJOBq6QAAAgc"]
[Thu Jul 30 11:50:39.650388 2026] [security2:error] [pid 643253:tid 643488] [client 20.100.187.246:19540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/classwithtostring.php"] [unique_id "amuA38jqbtjBYzqM1uYl8QAAAGg"]
[Thu Jul 30 11:50:39.695695 2026] [lsapi:error] [pid 643573:tid 643689] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/teen-lust-vj-emmy/
[Thu Jul 30 11:50:39.799727 2026] [security2:error] [pid 643573:tid 643756] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuA3_xWyxgRnoFKAJ_viwACQmI"]
[Thu Jul 30 11:50:39.952387 2026] [security2:error] [pid 643573:tid 643815] [client 213.152.186.19:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuA3_xWyxgRnoFKAJ_vkAAAAn0"]
[Thu Jul 30 11:50:39.952534 2026] [security2:error] [pid 643573:tid 643815] [client 213.152.186.19:33486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuA3_xWyxgRnoFKAJ_vkAAAAn0"]
[Thu Jul 30 11:50:39.975315 2026] [security2:error] [pid 642360:tid 642543] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuA35SUkh3e5AhEJOBq9AAAAcQ"]
[Thu Jul 30 11:50:40.282946 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:40.287255 2026] [security2:error] [pid 643573:tid 643757] [client 103.215.74.26:5870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4PxWyxgRnoFKAJ_vlwAAAkM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:40.492149 2026] [security2:error] [pid 643573:tid 643807] [client 20.100.187.246:36453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/content.php"] [unique_id "amuA4PxWyxgRnoFKAJ_vmAAAAnU"]
[Thu Jul 30 11:50:41.050542 2026] [core:notice] [pid 642360:tid 642559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:41.057072 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:5884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4ZSUkh3e5AhEJOBrBQAAAdQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:41.473153 2026] [security2:error] [pid 643573:tid 643712] [client 20.100.187.246:18004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/doc.php"] [unique_id "amuA4fxWyxgRnoFKAJ_vnAAAAhY"]
[Thu Jul 30 11:50:41.793758 2026] [core:notice] [pid 643573:tid 643776] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:41.797472 2026] [security2:error] [pid 643573:tid 643776] [client 103.215.74.26:5900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4fxWyxgRnoFKAJ_vnwAAAlY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:42.529898 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:42.533924 2026] [security2:error] [pid 643573:tid 643786] [client 103.215.74.26:5912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4vxWyxgRnoFKAJ_vpQAAAmA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:42.771067 2026] [security2:error] [pid 643573:tid 643728] [client 176.241.66.87:13855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA4vxWyxgRnoFKAJ_vqgAAAiY"]
[Thu Jul 30 11:50:42.771202 2026] [security2:error] [pid 643573:tid 643728] [client 176.241.66.87:13855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA4vxWyxgRnoFKAJ_vqgAAAiY"]
[Thu Jul 30 11:50:43.244880 2026] [security2:error] [pid 642360:tid 642496] [client 74.7.228.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.odk.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuA45SUkh3e5AhEJOBrEwAAAZU"]
[Thu Jul 30 11:50:43.245376 2026] [security2:error] [pid 643573:tid 643796] [client 74.7.228.56:52742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.odk.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuA4_xWyxgRnoFKAJ_vrgAAAmo"]
[Thu Jul 30 11:50:43.306345 2026] [core:notice] [pid 643573:tid 643785] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:43.310594 2026] [security2:error] [pid 643573:tid 643785] [client 103.215.74.26:24554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA4_xWyxgRnoFKAJ_vsAAAAl8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:43.501688 2026] [security2:error] [pid 643573:tid 643763] [client 74.7.228.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.odk.udi.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuA4_xWyxgRnoFKAJ_vswAAAkk"], referer: https://www.odk.udi.temporary.site/robots.txt
[Thu Jul 30 11:50:43.502214 2026] [security2:error] [pid 643573:tid 643780] [client 74.7.228.56:52742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.odk.udi.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuA4_xWyxgRnoFKAJ_vsQAAAlo"], referer: https://www.odk.udi.temporary.site/robots.txt
[Thu Jul 30 11:50:44.065931 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:44.072735 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:24564] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA5PxWyxgRnoFKAJ_vugAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:44.155552 2026] [security2:error] [pid 643573:tid 643751] [client 20.91.199.21:47586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/json.php"] [unique_id "amuA5PxWyxgRnoFKAJ_vvAAAAj0"]
[Thu Jul 30 11:50:44.472693 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:44.476238 2026] [security2:error] [pid 643573:tid 643788] [client 66.249.79.1:52381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/issue/archive"] [unique_id "amuA5PxWyxgRnoFKAJ_vvgAAAmI"]
[Thu Jul 30 11:50:44.790494 2026] [core:notice] [pid 643253:tid 643394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:44.797150 2026] [security2:error] [pid 643253:tid 643394] [client 103.215.74.26:24574] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA5MjqbtjBYzqM1uYl9AAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:44.809890 2026] [core:error] [pid 642360:tid 642453] [remote 74.7.230.55:34116] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:44.809915 2026] [core:error] [pid 642360:tid 642453] [remote 74.7.230.55:34116] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:44.810064 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.230.55:34116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "albayanfurnituremovers.cc"] [uri "/index.php"] [unique_id "amuA5JSUkh3e5AhEJOBrJAAB3Vw"]
[Thu Jul 30 11:50:44.866403 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.187.246:12174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/dropdown.php"] [unique_id "amuA5MjqbtjBYzqM1uYl9QAAAGM"]
[Thu Jul 30 11:50:45.229081 2026] [security2:error] [pid 643253:tid 643430] [client 127.0.0.1:38766] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuA5cjqbtjBYzqM1uYl9wAAAC4"]
[Thu Jul 30 11:50:45.229143 2026] [security2:error] [pid 643253:tid 643432] [client 74.7.244.44:37928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ege.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuA5cjqbtjBYzqM1uYl9gAAMCE"]
[Thu Jul 30 11:50:45.378546 2026] [core:notice] [pid 643253:tid 643289] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:45.535679 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:45.541214 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:24588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA5cjqbtjBYzqM1uYl-QAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:45.618737 2026] [security2:error] [pid 643573:tid 643810] [client 172.237.109.114:14165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vxwAAAng"]
[Thu Jul 30 11:50:45.627259 2026] [security2:error] [pid 643573:tid 643730] [client 172.237.109.114:58169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vyAAAAig"]
[Thu Jul 30 11:50:45.671964 2026] [security2:error] [pid 643573:tid 643714] [client 172.237.109.114:1872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vyQAAAhg"]
[Thu Jul 30 11:50:45.688972 2026] [security2:error] [pid 643573:tid 643776] [client 172.237.109.114:28595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vygAAAlY"]
[Thu Jul 30 11:50:45.744854 2026] [security2:error] [pid 643573:tid 643745] [client 172.237.109.114:34844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vywAAAjc"]
[Thu Jul 30 11:50:45.772921 2026] [security2:error] [pid 643573:tid 643836] [client 172.237.109.114:38078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5fxWyxgRnoFKAJ_vzAAAApI"]
[Thu Jul 30 11:50:45.914404 2026] [security2:error] [pid 642360:tid 642547] [client 20.91.199.21:47598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/mini.php"] [unique_id "amuA5ZSUkh3e5AhEJOBrMQAAAcg"]
[Thu Jul 30 11:50:46.311516 2026] [core:notice] [pid 643573:tid 643781] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:46.315530 2026] [security2:error] [pid 643573:tid 643781] [client 103.215.74.26:24594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA5vxWyxgRnoFKAJ_v0wAAAls"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:46.411802 2026] [core:notice] [pid 643573:tid 643697] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:46.414915 2026] [security2:error] [pid 643573:tid 643715] [client 20.100.187.246:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/ee.php"] [unique_id "amuA5vxWyxgRnoFKAJ_v2gAAAhk"]
[Thu Jul 30 11:50:46.748769 2026] [security2:error] [pid 642360:tid 642522] [client 20.91.199.21:47555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/chosen.php"] [unique_id "amuA5pSUkh3e5AhEJOBrNgAAAa8"]
[Thu Jul 30 11:50:46.874809 2026] [core:notice] [pid 643573:tid 643622] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:46.878521 2026] [security2:error] [pid 643573:tid 643734] [client 66.249.74.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/303/310"] [unique_id "amuA5vxWyxgRnoFKAJ_v4QACLCk"]
[Thu Jul 30 11:50:47.067101 2026] [core:notice] [pid 642360:tid 642511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:47.073814 2026] [security2:error] [pid 642360:tid 642511] [client 103.215.74.26:24608] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA55SUkh3e5AhEJOBrPAAAAaQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:47.173280 2026] [security2:error] [pid 642360:tid 642534] [client 20.100.187.246:18046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/flower.php"] [unique_id "amuA55SUkh3e5AhEJOBrRQAAAbs"]
[Thu Jul 30 11:50:47.694088 2026] [security2:error] [pid 642360:tid 642605] [client 172.237.109.114:51732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrPgAAAgI"]
[Thu Jul 30 11:50:47.704173 2026] [security2:error] [pid 642360:tid 642508] [client 172.237.109.114:59596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrQQAAAaE"]
[Thu Jul 30 11:50:47.705031 2026] [security2:error] [pid 642360:tid 642535] [client 172.237.109.114:6066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrPwAAAbw"]
[Thu Jul 30 11:50:47.732752 2026] [security2:error] [pid 642360:tid 642491] [client 172.237.109.114:15436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrPQAAAZA"]
[Thu Jul 30 11:50:47.794987 2026] [security2:error] [pid 643573:tid 643835] [client 172.237.109.114:65194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v5QAAApE"]
[Thu Jul 30 11:50:47.800085 2026] [security2:error] [pid 643573:tid 643823] [client 172.237.109.114:41354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v5AAAAoU"]
[Thu Jul 30 11:50:47.808482 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:47.813863 2026] [security2:error] [pid 643253:tid 643395] [client 103.215.74.26:24618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "776"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA58jqbtjBYzqM1uYl_wAAAAs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:47.816197 2026] [security2:error] [pid 642360:tid 642516] [client 172.237.109.114:62543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrQgAAAak"]
[Thu Jul 30 11:50:47.819906 2026] [security2:error] [pid 643573:tid 643766] [client 20.100.187.246:12624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/gecko-new.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v8wAAAkw"]
[Thu Jul 30 11:50:47.838618 2026] [security2:error] [pid 643573:tid 643751] [client 172.237.109.114:52953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v5gAAAj0"]
[Thu Jul 30 11:50:47.862365 2026] [security2:error] [pid 642360:tid 642609] [client 172.237.109.114:34562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrRAAAAgY"]
[Thu Jul 30 11:50:47.870246 2026] [security2:error] [pid 642360:tid 642606] [client 172.237.109.114:57002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA55SUkh3e5AhEJOBrQwAAAgM"]
[Thu Jul 30 11:50:47.884426 2026] [security2:error] [pid 643573:tid 643820] [client 172.237.109.114:6933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA5_xWyxgRnoFKAJ_v5wAAAoI"]
[Thu Jul 30 11:50:48.549761 2026] [core:notice] [pid 642360:tid 642604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:48.558043 2026] [security2:error] [pid 642360:tid 642604] [client 103.215.74.26:24622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA6JSUkh3e5AhEJOBrWgAAAgE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:48.678709 2026] [security2:error] [pid 643573:tid 643825] [client 172.237.109.114:26919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA6PxWyxgRnoFKAJ_v-gAAAoc"]
[Thu Jul 30 11:50:48.680093 2026] [security2:error] [pid 643573:tid 643800] [client 172.237.109.114:31001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA6PxWyxgRnoFKAJ_v-QAAAm4"]
[Thu Jul 30 11:50:48.680124 2026] [security2:error] [pid 643573:tid 643794] [client 172.237.109.114:17128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuA6PxWyxgRnoFKAJ_v-AAAAmg"]
[Thu Jul 30 11:50:49.298809 2026] [core:notice] [pid 643573:tid 643777] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:49.303234 2026] [security2:error] [pid 643573:tid 643777] [client 103.215.74.26:24636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA6fxWyxgRnoFKAJ_wAQAAAlc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:49.733928 2026] [security2:error] [pid 643573:tid 643832] [client 100.29.107.38:13963] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/"] [unique_id "amuA6fxWyxgRnoFKAJ_wBQAAAo4"]
[Thu Jul 30 11:50:49.860161 2026] [security2:error] [pid 643573:tid 643837] [client 20.100.187.246:36465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/m.php"] [unique_id "amuA6fxWyxgRnoFKAJ_wBgAAApM"]
[Thu Jul 30 11:50:50.026276 2026] [core:notice] [pid 643573:tid 643717] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:50.030494 2026] [security2:error] [pid 643573:tid 643717] [client 103.215.74.26:24650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA6vxWyxgRnoFKAJ_wCQAAAhs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:50.627426 2026] [security2:error] [pid 643573:tid 643784] [client 20.91.199.21:47590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/kj.php"] [unique_id "amuA6vxWyxgRnoFKAJ_wDgAAAl4"]
[Thu Jul 30 11:50:50.645916 2026] [security2:error] [pid 642360:tid 642597] [client 20.100.187.246:28612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuA6pSUkh3e5AhEJOBrbgAAAfo"]
[Thu Jul 30 11:50:50.716523 2026] [core:notice] [pid 643573:tid 643747] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:50.754461 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:50.759853 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:24664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA6vxWyxgRnoFKAJ_wEAAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:51.564951 2026] [security2:error] [pid 642360:tid 642530] [client 20.100.187.246:29253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/mah/flower.php"] [unique_id "amuA65SUkh3e5AhEJOBrdgAAAbc"]
[Thu Jul 30 11:50:52.450670 2026] [security2:error] [pid 642360:tid 642480] [remote 57.141.0.35:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuA7JSUkh3e5AhEJOBrgAABwXc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon,denim,polyester,plastic,linen,wood,nylon&orderby=date&rating=5&tax_product_cat=furniture&min_price=200&max_price=300&unfilter=1
[Thu Jul 30 11:50:52.540452 2026] [security2:error] [pid 643573:tid 643778] [client 20.100.187.246:36450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/mah/xleet.php"] [unique_id "amuA7PxWyxgRnoFKAJ_wHgAAAlg"]
[Thu Jul 30 11:50:53.130769 2026] [security2:error] [pid 643573:tid 643587] [remote 57.141.0.56:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuA7fxWyxgRnoFKAJ_wJAACZwY"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon,denim,polyester,plastic,linen,wood,nylon&orderby=date&rating=5&tax_product_cat=furniture&min_price=200&max_price=300&unfilter=1
[Thu Jul 30 11:50:53.236624 2026] [security2:error] [pid 643573:tid 643835] [client 20.100.187.246:7693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/mini.php"] [unique_id "amuA7fxWyxgRnoFKAJ_wJwAAApE"]
[Thu Jul 30 11:50:53.425885 2026] [security2:error] [pid 643573:tid 643751] [client 176.241.66.87:14515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA7fxWyxgRnoFKAJ_wKAAAAj0"]
[Thu Jul 30 11:50:53.426098 2026] [security2:error] [pid 643573:tid 643751] [client 176.241.66.87:14515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA7fxWyxgRnoFKAJ_wKAAAAj0"]
[Thu Jul 30 11:50:53.962863 2026] [security2:error] [pid 643573:tid 643586] [remote 110.249.201.164:12068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-kent.com"] [uri "/product/kent-2/"] [unique_id "amuA7fxWyxgRnoFKAJ_wLwACUgU"]
[Thu Jul 30 11:50:54.285864 2026] [security2:error] [pid 642360:tid 642607] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuA7ZSUkh3e5AhEJOBrigAAAgQ"]
[Thu Jul 30 11:50:55.303198 2026] [core:error] [pid 643253:tid 643387] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.303229 2026] [core:error] [pid 643253:tid 643387] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.335319 2026] [autoindex:error] [pid 642360:tid 642519] [client 52.4.19.39:10739] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_a59f0c15/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:50:55.339330 2026] [core:error] [pid 643573:tid 643771] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.339348 2026] [core:error] [pid 643573:tid 643771] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.369554 2026] [core:error] [pid 642360:tid 642560] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:55.369576 2026] [core:error] [pid 642360:tid 642560] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:50:56.333680 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:47591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-files.php"] [unique_id "amuA8JSUkh3e5AhEJOBrqgAAAew"]
[Thu Jul 30 11:50:56.529023 2026] [core:notice] [pid 642360:tid 642615] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:56.532942 2026] [security2:error] [pid 642360:tid 642615] [client 103.215.74.26:10474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA8JSUkh3e5AhEJOBrrgAAAgw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:56.598880 2026] [security2:error] [pid 643573:tid 643811] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuA7_xWyxgRnoFKAJ_wUAACeQQ"]
[Thu Jul 30 11:50:56.975334 2026] [security2:error] [pid 643573:tid 643772] [client 35.221.246.130:60744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.eaw.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/.git/config"] [unique_id "amuA8PxWyxgRnoFKAJ_wWgAAAlI"]
[Thu Jul 30 11:50:56.986724 2026] [security2:error] [pid 642360:tid 642612] [client 35.221.246.130:60722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.eaw.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/.git/config"] [unique_id "amuA8JSUkh3e5AhEJOBrswAAAgk"]
[Thu Jul 30 11:50:57.015810 2026] [security2:error] [pid 643573:tid 643741] [client 35.221.246.130:60720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "advancedvisiondxb.com"] [uri "/index.cgi"] [unique_id "amuA8fxWyxgRnoFKAJ_wXAAAAjM"]
[Thu Jul 30 11:50:57.065505 2026] [security2:error] [pid 642360:tid 642499] [client 35.221.246.130:60728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.eaw.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/.git/config"] [unique_id "amuA8ZSUkh3e5AhEJOBrtAAAAZg"]
[Thu Jul 30 11:50:57.274572 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:57.278617 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:10490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA8fxWyxgRnoFKAJ_wXwAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:50:57.403830 2026] [security2:error] [pid 643573:tid 643740] [client 35.221.246.130:60748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.eaw.nyx.temporary.site"] [uri "/index.cgi"] [unique_id "amuA8fxWyxgRnoFKAJ_wYgAAAjI"]
[Thu Jul 30 11:50:57.815847 2026] [security2:error] [pid 643573:tid 643794] [client 20.100.187.246:36435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/moon.php"] [unique_id "amuA8fxWyxgRnoFKAJ_wcQAAAmg"]
[Thu Jul 30 11:50:57.882894 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:50:58.017477 2026] [security2:error] [pid 643573:tid 643746] [client 35.221.246.130:60718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.eaw.nyx.temporary.site"] [uri "/index.cgi"] [unique_id "amuA8fxWyxgRnoFKAJ_wXQAAAjg"]
[Thu Jul 30 11:50:59.532305 2026] [security2:error] [pid 642360:tid 642516] [client 20.100.187.246:7695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/new.php"] [unique_id "amuA85SUkh3e5AhEJOBrzQAAAak"]
[Thu Jul 30 11:51:00.487027 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:00.539679 2026] [security2:error] [pid 642360:tid 642517] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuA85SUkh3e5AhEJOBr0QAAAao"]
[Thu Jul 30 11:51:01.413042 2026] [security2:error] [pid 643573:tid 643770] [client 20.100.187.246:21083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/radio.php"] [unique_id "amuA9fxWyxgRnoFKAJ_wlAAAAlA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 11:51:02.591679 2026] [security2:error] [pid 643573:tid 643814] [client 20.91.199.21:46994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-setup.php"] [unique_id "amuA9vxWyxgRnoFKAJ_woQAAAnw"]
[Thu Jul 30 11:51:02.831187 2026] [core:notice] [pid 642360:tid 642416] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:03.073110 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:03.077463 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:51586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA9_xWyxgRnoFKAJ_wowAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:03.578235 2026] [security2:error] [pid 642360:tid 642614] [client 20.100.187.246:16864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/s.php"] [unique_id "amuA95SUkh3e5AhEJOBr7wAAAgs"]
[Thu Jul 30 11:51:03.698474 2026] [security2:error] [pid 642360:tid 642612] [client 213.152.161.240:51338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA95SUkh3e5AhEJOBr9AAAAgk"]
[Thu Jul 30 11:51:03.698590 2026] [security2:error] [pid 642360:tid 642612] [client 213.152.161.240:51338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA95SUkh3e5AhEJOBr9AAAAgk"]
[Thu Jul 30 11:51:03.825435 2026] [core:notice] [pid 643573:tid 643784] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:03.829786 2026] [security2:error] [pid 643573:tid 643784] [client 103.215.74.26:51600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA9_xWyxgRnoFKAJ_wpwAAAl4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:04.009782 2026] [security2:error] [pid 643573:tid 643755] [client 176.241.66.87:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA-PxWyxgRnoFKAJ_wqgAAAkE"]
[Thu Jul 30 11:51:04.009923 2026] [security2:error] [pid 643573:tid 643755] [client 176.241.66.87:51156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuA-PxWyxgRnoFKAJ_wqgAAAkE"]
[Thu Jul 30 11:51:04.559479 2026] [core:notice] [pid 643573:tid 643821] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:04.564100 2026] [security2:error] [pid 643573:tid 643821] [client 103.215.74.26:51616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-PxWyxgRnoFKAJ_wrwAAAoM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:04.747917 2026] [security2:error] [pid 643573:tid 643822] [client 20.100.187.246:29309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/sim.php"] [unique_id "amuA-PxWyxgRnoFKAJ_wsQAAAoQ"]
[Thu Jul 30 11:51:04.824088 2026] [security2:error] [pid 642360:tid 642505] [client 20.91.199.21:47585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/defaults.php"] [unique_id "amuA-JSUkh3e5AhEJOBsBQAAAZ4"]
[Thu Jul 30 11:51:05.320814 2026] [core:notice] [pid 643573:tid 643749] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:05.325371 2026] [security2:error] [pid 643573:tid 643749] [client 103.215.74.26:51618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-fxWyxgRnoFKAJ_wtQAAAjs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:05.576183 2026] [security2:error] [pid 643573:tid 643772] [client 20.100.187.246:16890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/text.php"] [unique_id "amuA-fxWyxgRnoFKAJ_wtgAAAlI"]
[Thu Jul 30 11:51:06.088266 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:06.092752 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:51620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-pSUkh3e5AhEJOBsEQAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:06.245580 2026] [security2:error] [pid 643573:tid 643764] [client 20.100.187.246:29251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/user.php"] [unique_id "amuA-vxWyxgRnoFKAJ_wugAAAko"]
[Thu Jul 30 11:51:06.830670 2026] [core:notice] [pid 642360:tid 642617] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:06.834908 2026] [security2:error] [pid 642360:tid 642617] [client 103.215.74.26:51636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-pSUkh3e5AhEJOBsFwAAAg4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:07.254997 2026] [autoindex:error] [pid 643253:tid 643459] [client 34.233.129.35:32025] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:51:07.261908 2026] [proxy:error] [pid 642360:tid 642607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:07.261956 2026] [proxy_http:error] [pid 642360:tid 642607] [client 34.233.129.35:27555] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:07.262524 2026] [proxy:error] [pid 642360:tid 642607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:07.262569 2026] [proxy_http:error] [pid 642360:tid 642607] [client 34.233.129.35:27555] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:07.271180 2026] [autoindex:error] [pid 643573:tid 643819] [client 34.233.129.35:14724] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:51:07.273144 2026] [security2:error] [pid 643573:tid 643812] [client 85.208.96.202:29910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2023/01/30/ufpb-seleciona-alunos-para-residencia-medica-com-bolsa-de-r-41-mil/"] [unique_id "amuA-_xWyxgRnoFKAJ_wxAAAAno"]
[Thu Jul 30 11:51:07.273305 2026] [security2:error] [pid 643573:tid 643812] [client 85.208.96.202:29910] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2023/01/30/ufpb-seleciona-alunos-para-residencia-medica-com-bolsa-de-r-41-mil/"] [unique_id "amuA-_xWyxgRnoFKAJ_wxAAAAno"]
[Thu Jul 30 11:51:07.287411 2026] [proxy:error] [pid 642360:tid 642562] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:07.287477 2026] [proxy_http:error] [pid 642360:tid 642562] [client 34.233.129.35:15676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:07.288243 2026] [proxy:error] [pid 642360:tid 642562] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:07.288307 2026] [proxy_http:error] [pid 642360:tid 642562] [client 34.233.129.35:15676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:07.292005 2026] [autoindex:error] [pid 643573:tid 643833] [client 32.194.121.99:27085] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:51:07.592023 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:07.596471 2026] [security2:error] [pid 642360:tid 642613] [client 103.215.74.26:51638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA-5SUkh3e5AhEJOBsIAAAAgo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:08.374491 2026] [core:notice] [pid 642360:tid 642518] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:08.380343 2026] [security2:error] [pid 642360:tid 642518] [client 103.215.74.26:51654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA_JSUkh3e5AhEJOBsJwAAAas"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:09.016627 2026] [security2:error] [pid 643573:tid 643765] [client 20.100.187.246:7739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/webadmin.php"] [unique_id "amuA_fxWyxgRnoFKAJ_w0QAAAks"]
[Thu Jul 30 11:51:09.106242 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:09.110462 2026] [security2:error] [pid 643573:tid 643721] [client 103.215.74.26:51664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuA_fxWyxgRnoFKAJ_w1AAAAh8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:09.302491 2026] [security2:error] [pid 643573:tid 643785] [client 49.232.81.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuA_fxWyxgRnoFKAJ_w2AAAAl8"], referer: http://cnpinyin.com/dict?search=%e5%8a%b3%e5%8a%a8%e5%8a%9b
[Thu Jul 30 11:51:10.194757 2026] [security2:error] [pid 642360:tid 642615] [client 20.100.187.246:56965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amuA_pSUkh3e5AhEJOBsOQAAAgw"]
[Thu Jul 30 11:51:11.194209 2026] [security2:error] [pid 643573:tid 643804] [client 20.91.199.21:47597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/gtc.php"] [unique_id "amuA__xWyxgRnoFKAJ_w7QAAAnI"]
[Thu Jul 30 11:51:11.896188 2026] [proxy:error] [pid 643573:tid 643774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:11.896268 2026] [proxy_http:error] [pid 643573:tid 643774] [client 193.47.62.167:40980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:11.896850 2026] [proxy:error] [pid 643573:tid 643774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:11.896893 2026] [proxy_http:error] [pid 643573:tid 643774] [client 193.47.62.167:40980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:12.766239 2026] [security2:error] [pid 643573:tid 643710] [client 20.100.187.246:14872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amuBAPxWyxgRnoFKAJ_w-AAAAhQ"]
[Thu Jul 30 11:51:12.806408 2026] [security2:error] [pid 642360:tid 642595] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBAJSUkh3e5AhEJOBsTAAB-A0"]
[Thu Jul 30 11:51:13.179937 2026] [security2:error] [pid 643573:tid 643611] [remote 74.7.241.60:55662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuBAfxWyxgRnoFKAJ_w-gACKR4"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:51:13.792725 2026] [security2:error] [pid 643573:tid 643716] [client 20.100.187.246:7765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amuBAfxWyxgRnoFKAJ_xAAAAAho"]
[Thu Jul 30 11:51:13.914359 2026] [security2:error] [pid 643573:tid 643803] [client 20.91.199.21:47556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/import.php"] [unique_id "amuBAfxWyxgRnoFKAJ_xAQAAAnE"]
[Thu Jul 30 11:51:14.579007 2026] [security2:error] [pid 642360:tid 642596] [client 20.100.187.246:21053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amuBApSUkh3e5AhEJOBsXgAAAfk"]
[Thu Jul 30 11:51:14.728725 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:51704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBAvxWyxgRnoFKAJ_xDAAAAoY"]
[Thu Jul 30 11:51:14.728832 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:51704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBAvxWyxgRnoFKAJ_xDAAAAoY"]
[Thu Jul 30 11:51:14.900370 2026] [core:notice] [pid 642360:tid 642503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:14.904393 2026] [security2:error] [pid 642360:tid 642503] [client 103.215.74.26:23898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBApSUkh3e5AhEJOBsYgAAAZw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:14.984188 2026] [security2:error] [pid 642360:tid 642501] [client 20.91.199.21:46991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/lufix.php"] [unique_id "amuBApSUkh3e5AhEJOBsYwAAAZo"]
[Thu Jul 30 11:51:15.573317 2026] [security2:error] [pid 642360:tid 642566] [client 20.91.199.21:47005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/Geforce.php"] [unique_id "amuBA5SUkh3e5AhEJOBsaAAAAds"]
[Thu Jul 30 11:51:15.650602 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:15.656878 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:23906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBA5SUkh3e5AhEJOBsaQAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:16.125824 2026] [core:notice] [pid 643573:tid 643738] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:16.270875 2026] [security2:error] [pid 643573:tid 643775] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBA_xWyxgRnoFKAJ_xDwACVUk"]
[Thu Jul 30 11:51:16.393804 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:16.395670 2026] [security2:error] [pid 642360:tid 642590] [client 20.91.199.21:47588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/a4.php"] [unique_id "amuBBJSUkh3e5AhEJOBscQAAAfM"]
[Thu Jul 30 11:51:16.397713 2026] [security2:error] [pid 643573:tid 643721] [client 103.215.74.26:23910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "736"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBBPxWyxgRnoFKAJ_xIAAAAh8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:17.119510 2026] [core:notice] [pid 643573:tid 643763] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:17.123804 2026] [security2:error] [pid 643573:tid 643763] [client 103.215.74.26:23920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBBfxWyxgRnoFKAJ_xIgAAAkk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:17.228596 2026] [security2:error] [pid 642360:tid 642495] [client 20.100.187.246:11583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amuBBZSUkh3e5AhEJOBseQAAAZQ"]
[Thu Jul 30 11:51:17.314333 2026] [security2:error] [pid 643573:tid 643764] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBBfxWyxgRnoFKAJ_xJQAAAko"]
[Thu Jul 30 11:51:17.930792 2026] [security2:error] [pid 643573:tid 643783] [client 5.255.119.161:56862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/.env"] [unique_id "amuBBfxWyxgRnoFKAJ_xKwAAAl0"]
[Thu Jul 30 11:51:18.177105 2026] [security2:error] [pid 643573:tid 643829] [client 20.100.187.246:11552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amuBBvxWyxgRnoFKAJ_xMAAAAos"]
[Thu Jul 30 11:51:18.794436 2026] [security2:error] [pid 643573:tid 643718] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBBvxWyxgRnoFKAJ_xNwAAAhw"]
[Thu Jul 30 11:51:19.128686 2026] [security2:error] [pid 642360:tid 642612] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB5SUkh3e5AhEJOBsgwAAAgk"]
[Thu Jul 30 11:51:19.196600 2026] [security2:error] [pid 643573:tid 643837] [client 5.255.119.161:50606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/api/.env"] [unique_id "amuBB_xWyxgRnoFKAJ_xPgAAApM"]
[Thu Jul 30 11:51:19.204610 2026] [security2:error] [pid 643573:tid 643824] [client 5.255.119.161:50602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/backend/.env"] [unique_id "amuBB_xWyxgRnoFKAJ_xRgAAAoY"]
[Thu Jul 30 11:51:19.314156 2026] [security2:error] [pid 643573:tid 643826] [client 5.255.119.161:50612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xPwAAAog"]
[Thu Jul 30 11:51:19.318697 2026] [security2:error] [pid 643573:tid 643714] [client 5.255.119.161:50616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xRQAAAhg"]
[Thu Jul 30 11:51:19.350582 2026] [security2:error] [pid 643573:tid 643815] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xSQAAAn0"]
[Thu Jul 30 11:51:19.350922 2026] [security2:error] [pid 643573:tid 643774] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xSgAAAlQ"]
[Thu Jul 30 11:51:19.351408 2026] [security2:error] [pid 643573:tid 643791] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xSAAAAmU"]
[Thu Jul 30 11:51:19.382901 2026] [security2:error] [pid 642360:tid 642507] [client 5.255.119.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBB5SUkh3e5AhEJOBshQAAAaA"]
[Thu Jul 30 11:51:19.417016 2026] [security2:error] [pid 643573:tid 643745] [client 20.100.187.246:15353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuBB_xWyxgRnoFKAJ_xTQAAAjc"]
[Thu Jul 30 11:51:20.013922 2026] [security2:error] [pid 643573:tid 643735] [client 74.7.244.56:53128] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ghm.hmu.temporary.site"] [uri "/robots.txt"] [unique_id "amuBCPxWyxgRnoFKAJ_xUwAAAi0"]
[Thu Jul 30 11:51:20.079496 2026] [core:error] [pid 643253:tid 643407] [client 74.7.175.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:20.079518 2026] [core:error] [pid 643253:tid 643407] [client 74.7.175.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:20.079638 2026] [security2:error] [pid 643253:tid 643407] [client 74.7.175.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuBCMjqbtjBYzqM1uYmIgAAABc"]
[Thu Jul 30 11:51:20.080305 2026] [security2:error] [pid 643253:tid 643445] [client 74.7.175.172:51804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuBCMjqbtjBYzqM1uYmIQAAPTE"]
[Thu Jul 30 11:51:20.624062 2026] [security2:error] [pid 643573:tid 643742] [client 20.100.187.246:21731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amuBCPxWyxgRnoFKAJ_xWQAAAjQ"]
[Thu Jul 30 11:51:21.835025 2026] [security2:error] [pid 643253:tid 643475] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBCcjqbtjBYzqM1uYmJAAAWzM"]
[Thu Jul 30 11:51:21.866758 2026] [security2:error] [pid 642360:tid 642491] [client 20.91.199.21:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/accueil.php"] [unique_id "amuBCZSUkh3e5AhEJOBslwAAAZA"]
[Thu Jul 30 11:51:22.074195 2026] [security2:error] [pid 643573:tid 643809] [client 20.100.187.246:17173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amuBCvxWyxgRnoFKAJ_xaAAAAnc"]
[Thu Jul 30 11:51:22.464822 2026] [security2:error] [pid 643573:tid 643754] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBCfxWyxgRnoFKAJ_xYwACQFk"]
[Thu Jul 30 11:51:22.961622 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:22.968791 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:23926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBCvxWyxgRnoFKAJ_xaQAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:23.722490 2026] [core:notice] [pid 642360:tid 642556] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:23.729013 2026] [security2:error] [pid 642360:tid 642556] [client 103.215.74.26:62454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBC5SUkh3e5AhEJOBsqgAAAdE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:23.851451 2026] [security2:error] [pid 643573:tid 643714] [client 66.249.70.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/wp-login.php"] [unique_id "amuBCvxWyxgRnoFKAJ_xagACGFU"]
[Thu Jul 30 11:51:24.199513 2026] [security2:error] [pid 642360:tid 642544] [client 20.91.199.21:47573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/dashboard.php"] [unique_id "amuBDJSUkh3e5AhEJOBssgAAAcU"]
[Thu Jul 30 11:51:24.444849 2026] [core:notice] [pid 643573:tid 643763] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:24.448861 2026] [security2:error] [pid 643573:tid 643763] [client 103.215.74.26:62460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBDPxWyxgRnoFKAJ_xdwAAAkk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:25.182660 2026] [core:notice] [pid 643573:tid 643808] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:25.189540 2026] [security2:error] [pid 643573:tid 643808] [client 103.215.74.26:62472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBDfxWyxgRnoFKAJ_xfQAAAnY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:25.307002 2026] [security2:error] [pid 643573:tid 643770] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBDPxWyxgRnoFKAJ_xeQACUFA"]
[Thu Jul 30 11:51:25.317131 2026] [security2:error] [pid 643573:tid 643753] [client 176.241.66.87:52264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBDfxWyxgRnoFKAJ_xfgAAAj8"]
[Thu Jul 30 11:51:25.317254 2026] [security2:error] [pid 643573:tid 643753] [client 176.241.66.87:52264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBDfxWyxgRnoFKAJ_xfgAAAj8"]
[Thu Jul 30 11:51:25.681437 2026] [security2:error] [pid 643573:tid 643797] [client 20.91.199.21:46989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/radio.php"] [unique_id "amuBDfxWyxgRnoFKAJ_xgQAAAms"]
[Thu Jul 30 11:51:25.772776 2026] [security2:error] [pid 643573:tid 643673] [remote 95.108.213.181:58094] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/tag/business/"] [unique_id "amuBDfxWyxgRnoFKAJ_xggACalw"]
[Thu Jul 30 11:51:25.784348 2026] [proxy:error] [pid 643573:tid 643610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:25.784395 2026] [proxy_http:error] [pid 643573:tid 643610] [remote 216.73.217.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:25.784954 2026] [proxy:error] [pid 643573:tid 643610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:25.785017 2026] [proxy_http:error] [pid 643573:tid 643610] [remote 216.73.217.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:25.926034 2026] [core:notice] [pid 643573:tid 643828] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:25.933785 2026] [security2:error] [pid 643573:tid 643828] [client 103.215.74.26:62488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBDfxWyxgRnoFKAJ_xhQAAAoo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:26.520636 2026] [security2:error] [pid 642360:tid 642496] [client 20.100.187.246:17209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amuBDpSUkh3e5AhEJOBszAAAAZU"]
[Thu Jul 30 11:51:26.657595 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:26.661658 2026] [security2:error] [pid 643573:tid 643816] [client 103.215.74.26:62502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBDvxWyxgRnoFKAJ_xjgAAAn4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:26.668661 2026] [security2:error] [pid 642360:tid 642546] [client 20.91.199.21:47612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wpsml-sys.php"] [unique_id "amuBDpSUkh3e5AhEJOBszwAAAcc"]
[Thu Jul 30 11:51:26.748804 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:27.409299 2026] [core:notice] [pid 643573:tid 643807] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:27.414047 2026] [security2:error] [pid 643573:tid 643807] [client 103.215.74.26:62512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBD_xWyxgRnoFKAJ_xkwAAAnU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:27.548285 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:46981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/02.php"] [unique_id "amuBD_xWyxgRnoFKAJ_xlAAAAn8"]
[Thu Jul 30 11:51:28.152118 2026] [core:notice] [pid 643573:tid 643780] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:28.156063 2026] [security2:error] [pid 643573:tid 643780] [client 103.215.74.26:62522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBEPxWyxgRnoFKAJ_xmwAAAlo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:28.399655 2026] [security2:error] [pid 643573:tid 643776] [client 20.91.199.21:46985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/infos.php"] [unique_id "amuBEPxWyxgRnoFKAJ_xoAAAAlY"]
[Thu Jul 30 11:51:28.920533 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:28.924506 2026] [security2:error] [pid 643573:tid 643824] [client 103.215.74.26:62532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBEPxWyxgRnoFKAJ_xpgAAAoY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:30.266633 2026] [security2:error] [pid 642360:tid 642416] [remote 57.141.0.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuBEpSUkh3e5AhEJOBs8wABuTc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum,denim,lycra,nylon,polyester,steel&filter_size=extra-extra-large&max_price=125&min_price=75&orderby=menu_order&rating=5&status=instock&unfilter=1
[Thu Jul 30 11:51:30.273894 2026] [security2:error] [pid 642360:tid 642411] [remote 57.141.0.65:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuBEpSUkh3e5AhEJOBs9AAB4zI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum,denim,lycra,nylon,polyester,steel&filter_size=extra-extra-large&max_price=125&min_price=75&orderby=menu_order&rating=5&status=instock&unfilter=1
[Thu Jul 30 11:51:31.219960 2026] [security2:error] [pid 642360:tid 642510] [client 20.91.199.21:47595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/updates.php"] [unique_id "amuBE5SUkh3e5AhEJOBs_QAAAaM"]
[Thu Jul 30 11:51:31.291341 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:34.676157 2026] [security2:error] [pid 642360:tid 642511] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBFpSUkh3e5AhEJOBtGAAAAaQ"]
[Thu Jul 30 11:51:34.751675 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:34.755824 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:59776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBFpSUkh3e5AhEJOBtIAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:35.091178 2026] [security2:error] [pid 642360:tid 642564] [client 20.91.199.21:46992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/user.php"] [unique_id "amuBF5SUkh3e5AhEJOBtJQAAAdk"]
[Thu Jul 30 11:51:35.483352 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:35.487322 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:59792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBF_xWyxgRnoFKAJ_x5AAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:35.932566 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBF_xWyxgRnoFKAJ_x5gAAAoY"]
[Thu Jul 30 11:51:35.932696 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:52822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBF_xWyxgRnoFKAJ_x5gAAAoY"]
[Thu Jul 30 11:51:36.211090 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:36.215087 2026] [security2:error] [pid 643573:tid 643757] [client 103.215.74.26:59798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBGPxWyxgRnoFKAJ_x6AAAAkM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:36.936177 2026] [core:notice] [pid 642360:tid 642560] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:36.940249 2026] [security2:error] [pid 642360:tid 642560] [client 103.215.74.26:59814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBGJSUkh3e5AhEJOBtNwAAAdU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:37.498305 2026] [security2:error] [pid 643573:tid 643744] [client 20.91.199.21:47036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/admin-ajax.php"] [unique_id "amuBGfxWyxgRnoFKAJ_x8AAAAjY"]
[Thu Jul 30 11:51:37.582627 2026] [security2:error] [pid 643573:tid 643782] [client 20.100.187.246:20660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/flower.php"] [unique_id "amuBGfxWyxgRnoFKAJ_x8QAAAlw"]
[Thu Jul 30 11:51:37.664860 2026] [core:notice] [pid 643573:tid 643807] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:37.668741 2026] [security2:error] [pid 643573:tid 643807] [client 103.215.74.26:59828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBGfxWyxgRnoFKAJ_x8gAAAnU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:38.401484 2026] [core:notice] [pid 642360:tid 642554] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:38.405814 2026] [security2:error] [pid 642360:tid 642554] [client 103.215.74.26:59834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBGpSUkh3e5AhEJOBtRQAAAc8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:38.672859 2026] [security2:error] [pid 643573:tid 643831] [client 20.91.199.21:47581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/alfa.php"] [unique_id "amuBGvxWyxgRnoFKAJ_x9wAAAo0"]
[Thu Jul 30 11:51:39.119326 2026] [core:notice] [pid 643573:tid 643784] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:39.123320 2026] [security2:error] [pid 643573:tid 643784] [client 103.215.74.26:59844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBG_xWyxgRnoFKAJ_x-gAAAl4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:39.271463 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.187.246:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amuBG8jqbtjBYzqM1uYmQwAAAAA"]
[Thu Jul 30 11:51:39.837290 2026] [core:notice] [pid 643253:tid 643320] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:39.846498 2026] [core:notice] [pid 643573:tid 643802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:39.850420 2026] [security2:error] [pid 643573:tid 643802] [client 103.215.74.26:59848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBG_xWyxgRnoFKAJ_yCQAAAnA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:39.918120 2026] [security2:error] [pid 643573:tid 643752] [client 20.100.187.246:8218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amuBG_xWyxgRnoFKAJ_yCgAAAj4"]
[Thu Jul 30 11:51:40.585476 2026] [core:notice] [pid 643253:tid 643410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:40.590310 2026] [security2:error] [pid 643253:tid 643410] [client 103.215.74.26:59858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBHMjqbtjBYzqM1uYmRwAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:41.147338 2026] [security2:error] [pid 642360:tid 642543] [client 20.100.187.246:36487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amuBHZSUkh3e5AhEJOBtXgAAAcQ"]
[Thu Jul 30 11:51:41.334878 2026] [core:notice] [pid 643573:tid 643743] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:41.339055 2026] [security2:error] [pid 643573:tid 643743] [client 103.215.74.26:59874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBHfxWyxgRnoFKAJ_yEAAAAjU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:41.722576 2026] [core:notice] [pid 643573:tid 643781] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:42.078349 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:42.082939 2026] [security2:error] [pid 643573:tid 643761] [client 103.215.74.26:59888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBHvxWyxgRnoFKAJ_yGwAAAkc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:42.479630 2026] [security2:error] [pid 643573:tid 643727] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBHfxWyxgRnoFKAJ_yGAAAAiU"]
[Thu Jul 30 11:51:42.775415 2026] [core:error] [pid 643573:tid 643627] [remote 32.193.37.124:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:42.775441 2026] [core:error] [pid 643573:tid 643627] [remote 32.193.37.124:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:42.814652 2026] [core:notice] [pid 642360:tid 642531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:42.818958 2026] [security2:error] [pid 642360:tid 642531] [client 103.215.74.26:59894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBHpSUkh3e5AhEJOBtcAAAAbg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:42.838456 2026] [security2:error] [pid 643573:tid 643792] [client 20.91.199.21:46995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/hehe.php"] [unique_id "amuBHvxWyxgRnoFKAJ_yIQAAAmY"]
[Thu Jul 30 11:51:42.893759 2026] [security2:error] [pid 643573:tid 643775] [client 20.100.187.246:8086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuBHvxWyxgRnoFKAJ_yIgAAAlU"]
[Thu Jul 30 11:51:43.458696 2026] [core:notice] [pid 643573:tid 643697] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:43.546425 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:43.550887 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBH_xWyxgRnoFKAJ_yNQAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:43.891879 2026] [security2:error] [pid 643573:tid 643747] [client 20.100.187.246:8008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuBH_xWyxgRnoFKAJ_yPwAAAjk"]
[Thu Jul 30 11:51:44.281316 2026] [core:notice] [pid 643573:tid 643823] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:44.285660 2026] [security2:error] [pid 643573:tid 643823] [client 103.215.74.26:44110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBIPxWyxgRnoFKAJ_yRQAAAoU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:44.523543 2026] [security2:error] [pid 642360:tid 642494] [client 20.91.199.21:47613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/rk2.php"] [unique_id "amuBIJSUkh3e5AhEJOBtfQAAAZM"]
[Thu Jul 30 11:51:44.809610 2026] [ssl:error] [pid 643573:tid 643719] [client 199.45.154.140:54636] AH02032: Hostname sh00085.hostgator.com (default host as no SNI was provided) and hostname mail.kendarikomputer.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Thu Jul 30 11:51:44.990815 2026] [security2:error] [pid 643573:tid 643822] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBIPxWyxgRnoFKAJ_ySAAAAoQ"]
[Thu Jul 30 11:51:45.027897 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:45.032679 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:44120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBIcjqbtjBYzqM1uYmTQAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:45.751382 2026] [security2:error] [pid 643573:tid 643758] [client 20.91.199.21:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/setup-config.php"] [unique_id "amuBIfxWyxgRnoFKAJ_yVwAAAkQ"]
[Thu Jul 30 11:51:45.808983 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:45.813294 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:44132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBIfxWyxgRnoFKAJ_yWQAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:46.010444 2026] [security2:error] [pid 642360:tid 642568] [client 20.100.187.246:8078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amuBIpSUkh3e5AhEJOBtiQAAAd0"]
[Thu Jul 30 11:51:46.071049 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:46.444743 2026] [security2:error] [pid 643573:tid 643786] [client 20.91.199.21:47609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/a7.php"] [unique_id "amuBIvxWyxgRnoFKAJ_yYwAAAmA"]
[Thu Jul 30 11:51:46.532593 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:46.537020 2026] [security2:error] [pid 643573:tid 643718] [client 103.215.74.26:44136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBIvxWyxgRnoFKAJ_yZwAAAhw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:46.599871 2026] [security2:error] [pid 643573:tid 643836] [client 176.241.66.87:17781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBIvxWyxgRnoFKAJ_ybAAAApI"]
[Thu Jul 30 11:51:46.599989 2026] [security2:error] [pid 643573:tid 643836] [client 176.241.66.87:17781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBIvxWyxgRnoFKAJ_ybAAAApI"]
[Thu Jul 30 11:51:46.767552 2026] [security2:error] [pid 643573:tid 643742] [client 20.100.187.246:58926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/json.php"] [unique_id "amuBIvxWyxgRnoFKAJ_yfgAAAjQ"]
[Thu Jul 30 11:51:46.857338 2026] [proxy:error] [pid 643573:tid 643626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:46.857394 2026] [proxy_http:error] [pid 643573:tid 643626] [remote 74.7.228.16:40956] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:46.857958 2026] [proxy:error] [pid 643573:tid 643626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:46.858015 2026] [proxy_http:error] [pid 643573:tid 643626] [remote 74.7.228.16:40956] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:47.218185 2026] [security2:error] [pid 643573:tid 643834] [client 20.91.199.21:47564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/f7.php"] [unique_id "amuBI_xWyxgRnoFKAJ_yigAAApA"]
[Thu Jul 30 11:51:47.257141 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:47.261126 2026] [security2:error] [pid 642360:tid 642571] [client 103.215.74.26:44146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBI5SUkh3e5AhEJOBtkgAAAeA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:47.282569 2026] [core:notice] [pid 643573:tid 643714] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:47.284746 2026] [security2:error] [pid 643573:tid 643714] [client 144.76.23.169:56324] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuBI_xWyxgRnoFKAJ_yiwAAAhg"]
[Thu Jul 30 11:51:47.666496 2026] [security2:error] [pid 643573:tid 643748] [client 217.181.88.32:28574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuBI_xWyxgRnoFKAJ_yjgACOjw"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 11:51:48.038531 2026] [core:notice] [pid 642360:tid 642496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:48.042697 2026] [security2:error] [pid 642360:tid 642496] [client 103.215.74.26:44152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJJSUkh3e5AhEJOBtmAAAAZU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:48.151789 2026] [security2:error] [pid 643573:tid 643760] [client 20.100.187.246:8104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuBJPxWyxgRnoFKAJ_ylgAAAkY"]
[Thu Jul 30 11:51:48.771244 2026] [core:notice] [pid 643573:tid 643800] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:48.775342 2026] [security2:error] [pid 643573:tid 643800] [client 103.215.74.26:44160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJPxWyxgRnoFKAJ_yrQAAAm4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:49.410775 2026] [security2:error] [pid 643573:tid 643771] [client 20.91.199.21:47559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/nw.php"] [unique_id "amuBJfxWyxgRnoFKAJ_ytAAAAlE"]
[Thu Jul 30 11:51:49.488628 2026] [core:notice] [pid 643573:tid 643765] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:49.493052 2026] [security2:error] [pid 643573:tid 643765] [client 103.215.74.26:44162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJfxWyxgRnoFKAJ_ytgAAAks"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:49.561231 2026] [security2:error] [pid 643573:tid 643715] [client 20.100.187.246:29096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amuBJfxWyxgRnoFKAJ_ytwAAAhk"]
[Thu Jul 30 11:51:50.214469 2026] [core:notice] [pid 642360:tid 642609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:50.221089 2026] [security2:error] [pid 642360:tid 642609] [client 103.215.74.26:44164] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJpSUkh3e5AhEJOBtqgAAAgY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:50.466784 2026] [security2:error] [pid 642360:tid 642610] [client 20.100.187.246:33733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/mini.php"] [unique_id "amuBJpSUkh3e5AhEJOBtsQAAAgc"]
[Thu Jul 30 11:51:50.494480 2026] [core:notice] [pid 642360:tid 642521] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:50.496795 2026] [security2:error] [pid 642360:tid 642521] [client 144.76.23.169:47678] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/feed/"] [unique_id "amuBJpSUkh3e5AhEJOBtsgAAAa4"]
[Thu Jul 30 11:51:50.616329 2026] [security2:error] [pid 642360:tid 642516] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBJZSUkh3e5AhEJOBtqQABqSU"]
[Thu Jul 30 11:51:50.642761 2026] [security2:error] [pid 642360:tid 642520] [client 20.91.199.21:47208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/ova.php"] [unique_id "amuBJpSUkh3e5AhEJOBttAAAAa0"]
[Thu Jul 30 11:51:50.720552 2026] [security2:error] [pid 642360:tid 642531] [client 20.100.187.246:29110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amuBJpSUkh3e5AhEJOBttQAAAbg"]
[Thu Jul 30 11:51:50.721766 2026] [security2:error] [pid 643573:tid 643799] [client 178.156.189.249:7000] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuBJfxWyxgRnoFKAJ_ytQAAAm0"], referer: https://globalmarks.pk/
[Thu Jul 30 11:51:50.992726 2026] [core:notice] [pid 642360:tid 642517] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:50.999674 2026] [security2:error] [pid 642360:tid 642517] [client 103.215.74.26:44170] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJpSUkh3e5AhEJOBtuQAAAao"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:51.721480 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:51.725501 2026] [security2:error] [pid 643573:tid 643797] [client 103.215.74.26:44180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBJ_xWyxgRnoFKAJ_yygAAAms"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:51.800187 2026] [core:notice] [pid 643573:tid 643668] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:51.803839 2026] [security2:error] [pid 643573:tid 643796] [client 66.249.65.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/223/241"] [unique_id "amuBJ_xWyxgRnoFKAJ_yyQACalc"]
[Thu Jul 30 11:51:51.991416 2026] [security2:error] [pid 643573:tid 643717] [client 20.91.199.21:47605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/robots.php"] [unique_id "amuBJ_xWyxgRnoFKAJ_yzQAAAhs"]
[Thu Jul 30 11:51:52.450969 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:52.454943 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:44194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "772"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBKPxWyxgRnoFKAJ_y0AAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:52.780736 2026] [core:notice] [pid 643573:tid 643807] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:52.877860 2026] [security2:error] [pid 643573:tid 643817] [client 74.7.244.3:34442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.arabiandubaisafari.com.khw.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuBKPxWyxgRnoFKAJ_y0gACf0k"]
[Thu Jul 30 11:51:53.177011 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:53.184940 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:17946] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBKfxWyxgRnoFKAJ_y1wAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:53.203797 2026] [security2:error] [pid 643573:tid 643771] [client 20.91.199.21:47001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/alf.php"] [unique_id "amuBKfxWyxgRnoFKAJ_y2AAAAlE"]
[Thu Jul 30 11:51:53.307177 2026] [security2:error] [pid 642360:tid 642526] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "madeninsabah.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBKZSUkh3e5AhEJOBtzQAAAbM"]
[Thu Jul 30 11:51:53.331093 2026] [security2:error] [pid 643573:tid 643793] [client 20.100.187.246:11872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuBKfxWyxgRnoFKAJ_y3AAAAmc"]
[Thu Jul 30 11:51:53.830350 2026] [proxy:error] [pid 643573:tid 643632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:53.830429 2026] [proxy_http:error] [pid 643573:tid 643632] [remote 74.7.228.34:59616] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:53.831258 2026] [proxy:error] [pid 643573:tid 643632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:51:53.831327 2026] [proxy_http:error] [pid 643573:tid 643632] [remote 74.7.228.34:59616] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:51:53.845066 2026] [core:error] [pid 643573:tid 643794] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:53.845093 2026] [core:error] [pid 643573:tid 643794] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:53.845250 2026] [security2:error] [pid 643573:tid 643794] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuBKfxWyxgRnoFKAJ_y4AAAAmg"]
[Thu Jul 30 11:51:53.845835 2026] [security2:error] [pid 642360:tid 642541] [client 74.7.244.51:60296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuBKZSUkh3e5AhEJOBt0wABwiQ"]
[Thu Jul 30 11:51:53.900349 2026] [security2:error] [pid 643253:tid 643398] [client 20.91.199.21:46980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/feedback.php"] [unique_id "amuBKcjqbtjBYzqM1uYmUgAAAA4"]
[Thu Jul 30 11:51:53.911930 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:53.913448 2026] [security2:error] [pid 643573:tid 643829] [client 52.23.112.144:27225] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/cerveja-faz-bem-saude-web.jpg"] [unique_id "amuBKfxWyxgRnoFKAJ_y4QAAAos"]
[Thu Jul 30 11:51:53.915890 2026] [security2:error] [pid 643253:tid 643493] [client 103.215.74.26:17948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "785"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBKcjqbtjBYzqM1uYmUwAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:51:53.945333 2026] [security2:error] [pid 642360:tid 642514] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "madeninsabah.com"] [uri "/media/system/js/core.js"] [unique_id "amuBKZSUkh3e5AhEJOBt1gAAAac"]
[Thu Jul 30 11:51:54.291824 2026] [security2:error] [pid 642360:tid 642606] [client 119.73.97.132:30215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/wp-login.php"] [unique_id "amuBJ5SUkh3e5AhEJOBtvgACA0w"], referer: https://www.urwru.club/wp-login.php?redirect_to=https%3A%2F%2Fwww.urwru.club%2Fwp-admin%2F&reauth=1
[Thu Jul 30 11:51:54.381134 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:54.474242 2026] [security2:error] [pid 642360:tid 642567] [client 20.100.187.246:64912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/chosen.php"] [unique_id "amuBKpSUkh3e5AhEJOBt3AAAAdw"]
[Thu Jul 30 11:51:54.651421 2026] [core:notice] [pid 643253:tid 643326] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:54.874380 2026] [core:notice] [pid 643573:tid 643767] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:55.478191 2026] [core:error] [pid 643573:tid 643823] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:55.478212 2026] [core:error] [pid 643573:tid 643823] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:51:56.711353 2026] [security2:error] [pid 642360:tid 642450] [remote 57.141.0.34:20702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/logika/about/submissions"] [unique_id "amuBLJSUkh3e5AhEJOBuDwABwVk"]
[Thu Jul 30 11:51:56.969788 2026] [security2:error] [pid 643253:tid 643504] [client 20.100.187.246:29100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-config-sample.php"] [unique_id "amuBLMjqbtjBYzqM1uYmXgAAAHg"]
[Thu Jul 30 11:51:57.302699 2026] [security2:error] [pid 643573:tid 643815] [client 176.241.66.87:18427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBLfxWyxgRnoFKAJ_y-wAAAn0"]
[Thu Jul 30 11:51:57.302842 2026] [security2:error] [pid 643573:tid 643815] [client 176.241.66.87:18427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBLfxWyxgRnoFKAJ_y-wAAAn0"]
[Thu Jul 30 11:51:59.495088 2026] [security2:error] [pid 643573:tid 643788] [client 20.91.199.21:47025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/gettest.php"] [unique_id "amuBL_xWyxgRnoFKAJ_zDAAAAmI"]
[Thu Jul 30 11:51:59.638050 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:51:59.642110 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:17956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBL5SUkh3e5AhEJOBueQAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:00.359647 2026] [core:notice] [pid 643573:tid 643729] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:00.363771 2026] [security2:error] [pid 643573:tid 643729] [client 103.215.74.26:17960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBMPxWyxgRnoFKAJ_zEwAAAic"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:01.089611 2026] [core:notice] [pid 643573:tid 643803] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:01.093668 2026] [security2:error] [pid 643573:tid 643803] [client 103.215.74.26:17974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBMfxWyxgRnoFKAJ_zGAAAAnE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:01.404971 2026] [security2:error] [pid 643573:tid 643765] [client 20.91.199.21:47583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/maint.php"] [unique_id "amuBMfxWyxgRnoFKAJ_zHQAAAks"]
[Thu Jul 30 11:52:01.490247 2026] [security2:error] [pid 643573:tid 643714] [client 47.128.35.78:28718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltaedu.net"] [uri "/robots.txt"] [unique_id "amuBMfxWyxgRnoFKAJ_zIAAAAhg"]
[Thu Jul 30 11:52:01.817917 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:01.823443 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:17978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBMfxWyxgRnoFKAJ_zJgAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:02.401595 2026] [security2:error] [pid 642360:tid 642393] [remote 52.238.199.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afropakmedical.com"] [uri "/.well-known/file.php"] [unique_id "amuBMpSUkh3e5AhEJOBukgACCSA"]
[Thu Jul 30 11:52:02.553632 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:02.557573 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:17988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBMvxWyxgRnoFKAJ_zLAAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:02.621355 2026] [security2:error] [pid 643573:tid 643767] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBMvxWyxgRnoFKAJ_zKQACTRY"]
[Thu Jul 30 11:52:03.143789 2026] [security2:error] [pid 642360:tid 642592] [client 20.91.199.21:47572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/files.php"] [unique_id "amuBM5SUkh3e5AhEJOBumwAAAfU"]
[Thu Jul 30 11:52:03.199288 2026] [security2:error] [pid 643573:tid 643601] [remote 52.238.199.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afropakmedical.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuBM_xWyxgRnoFKAJ_zOgACJxQ"]
[Thu Jul 30 11:52:04.107850 2026] [security2:error] [pid 643573:tid 643686] [remote 52.238.199.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "afropakmedical.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuBNPxWyxgRnoFKAJ_zRgACbWk"]
[Thu Jul 30 11:52:04.760702 2026] [security2:error] [pid 643573:tid 643735] [client 20.91.199.21:46852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/gecko.php"] [unique_id "amuBNPxWyxgRnoFKAJ_zTgAAAi0"]
[Thu Jul 30 11:52:04.777576 2026] [security2:error] [pid 643573:tid 643753] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBNPxWyxgRnoFKAJ_zSQAAAj8"]
[Thu Jul 30 11:52:05.080498 2026] [core:notice] [pid 643573:tid 643704] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:05.273507 2026] [core:error] [pid 643573:tid 643782] [client 66.249.73.202:45521] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:05.273542 2026] [core:error] [pid 643573:tid 643782] [client 66.249.73.202:45521] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.028083 2026] [core:notice] [pid 642360:tid 642416] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:06.050959 2026] [security2:error] [pid 642360:tid 642525] [client 20.91.199.21:46866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/zwso.php"] [unique_id "amuBNpSUkh3e5AhEJOBuugAAAbI"]
[Thu Jul 30 11:52:06.337926 2026] [core:error] [pid 643573:tid 643773] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.337950 2026] [core:error] [pid 643573:tid 643773] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.343136 2026] [core:error] [pid 643573:tid 643766] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.343152 2026] [core:error] [pid 643573:tid 643766] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.345097 2026] [core:error] [pid 643573:tid 643780] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.345116 2026] [core:error] [pid 643573:tid 643780] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.379036 2026] [core:error] [pid 643573:tid 643833] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.379058 2026] [core:error] [pid 643573:tid 643833] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.400936 2026] [core:error] [pid 643573:tid 643724] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.400960 2026] [core:error] [pid 643573:tid 643724] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:06.542668 2026] [core:notice] [pid 642360:tid 642577] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:07.960140 2026] [security2:error] [pid 643573:tid 643805] [client 176.241.66.87:19069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBN_xWyxgRnoFKAJ_zggAAAnM"]
[Thu Jul 30 11:52:07.960285 2026] [security2:error] [pid 643573:tid 643805] [client 176.241.66.87:19069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBN_xWyxgRnoFKAJ_zggAAAnM"]
[Thu Jul 30 11:52:08.342655 2026] [core:notice] [pid 643573:tid 643726] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:08.347414 2026] [security2:error] [pid 643573:tid 643726] [client 103.215.74.26:51264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBOPxWyxgRnoFKAJ_zhgAAAiQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:09.069569 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:09.073597 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:51268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBOfxWyxgRnoFKAJ_zigAAAow"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:11.039556 2026] [security2:error] [pid 643573:tid 643832] [client 52.167.144.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cnpinyin.com"] [uri "/index.php"] [unique_id "amuBOvxWyxgRnoFKAJ_zlwAAAo4"]
[Thu Jul 30 11:52:12.368118 2026] [security2:error] [pid 643573:tid 643726] [client 20.91.199.21:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/13.php"] [unique_id "amuBPPxWyxgRnoFKAJ_zngAAAiQ"]
[Thu Jul 30 11:52:13.127025 2026] [security2:error] [pid 643573:tid 643833] [client 57.141.0.46:60662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuBPPxWyxgRnoFKAJ_zoQACj0Y"], referer: https://igetvape-australia.com/product-tag/alibarbar-ingot-quadruple-berry-9000-puffs/
[Thu Jul 30 11:52:13.276287 2026] [autoindex:error] [pid 642360:tid 642603] [client 54.87.222.253:50431] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_a59f0c15/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:52:13.293446 2026] [core:error] [pid 643573:tid 643823] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.293464 2026] [core:error] [pid 643573:tid 643823] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.294770 2026] [core:error] [pid 642360:tid 642549] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.294784 2026] [core:error] [pid 642360:tid 642549] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.298252 2026] [core:error] [pid 643573:tid 643788] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:13.298280 2026] [core:error] [pid 643573:tid 643788] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:14.117870 2026] [security2:error] [pid 642360:tid 642508] [client 20.91.199.21:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/ava.php"] [unique_id "amuBPpSUkh3e5AhEJOBvGgAAAaE"]
[Thu Jul 30 11:52:14.501191 2026] [core:notice] [pid 643253:tid 643333] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:14.815225 2026] [core:notice] [pid 642360:tid 642528] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:14.819499 2026] [security2:error] [pid 642360:tid 642528] [client 103.215.74.26:63186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBPpSUkh3e5AhEJOBvJAAAAbU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:14.952469 2026] [security2:error] [pid 642360:tid 642497] [client 20.91.199.21:47056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/main.php"] [unique_id "amuBPpSUkh3e5AhEJOBvJQAAAZY"]
[Thu Jul 30 11:52:15.439338 2026] [core:notice] [pid 642360:tid 642394] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:15.539683 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:15.544137 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:63188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBP_xWyxgRnoFKAJ_zvAAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:15.744380 2026] [security2:error] [pid 642360:tid 642601] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBP5SUkh3e5AhEJOBvJgAB_nc"]
[Thu Jul 30 11:52:15.865537 2026] [proxy:error] [pid 643573:tid 643748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:15.865615 2026] [proxy_http:error] [pid 643573:tid 643748] [client 85.204.70.98:1105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:15.866215 2026] [proxy:error] [pid 643573:tid 643748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:15.866259 2026] [proxy_http:error] [pid 643573:tid 643748] [client 85.204.70.98:1105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.123960 2026] [proxy:error] [pid 643573:tid 643758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:16.124074 2026] [proxy_http:error] [pid 643573:tid 643758] [client 85.204.70.98:44316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.124892 2026] [proxy:error] [pid 643573:tid 643758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:16.124944 2026] [proxy_http:error] [pid 643573:tid 643758] [client 85.204.70.98:44316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.262601 2026] [core:notice] [pid 643573:tid 643773] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:16.266840 2026] [security2:error] [pid 643573:tid 643773] [client 103.215.74.26:63204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQPxWyxgRnoFKAJ_zyAAAAlM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:16.387629 2026] [security2:error] [pid 643573:tid 643774] [client 85.204.70.98:44318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuBQPxWyxgRnoFKAJ_zywAAAlQ"]
[Thu Jul 30 11:52:16.568900 2026] [security2:error] [pid 642360:tid 642376] [remote 216.73.216.152:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuBQJSUkh3e5AhEJOBvMwAB9g8"]
[Thu Jul 30 11:52:16.657778 2026] [security2:error] [pid 642360:tid 642590] [client 85.204.70.98:44322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBQJSUkh3e5AhEJOBvNAAAAfM"]
[Thu Jul 30 11:52:16.863114 2026] [security2:error] [pid 643573:tid 643747] [client 82.221.131.86:57484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.131.221.82.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBQPxWyxgRnoFKAJ_zzAAAAjk"]
[Thu Jul 30 11:52:16.865925 2026] [security2:error] [pid 643573:tid 643830] [client 20.91.199.21:47040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-file.php"] [unique_id "amuBQPxWyxgRnoFKAJ_zzQAAAow"]
[Thu Jul 30 11:52:16.927596 2026] [proxy:error] [pid 643573:tid 643754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:16.927678 2026] [proxy_http:error] [pid 643573:tid 643754] [client 85.204.70.98:44334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.928256 2026] [proxy:error] [pid 643573:tid 643754] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:52:16.928311 2026] [proxy_http:error] [pid 643573:tid 643754] [client 85.204.70.98:44334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:52:16.990672 2026] [core:notice] [pid 642360:tid 642490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:16.995174 2026] [security2:error] [pid 642360:tid 642490] [client 103.215.74.26:63220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQJSUkh3e5AhEJOBvOwAAAY8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:17.193694 2026] [security2:error] [pid 642360:tid 642568] [client 85.204.70.98:26610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuBQZSUkh3e5AhEJOBvPAAAAd0"]
[Thu Jul 30 11:52:17.458237 2026] [security2:error] [pid 642360:tid 642577] [client 85.204.70.98:44352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuBQZSUkh3e5AhEJOBvQwAAAeY"]
[Thu Jul 30 11:52:17.636339 2026] [security2:error] [pid 643573:tid 643735] [client 20.91.199.21:47102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-signin.php"] [unique_id "amuBQfxWyxgRnoFKAJ_z0AAAAi0"]
[Thu Jul 30 11:52:17.730733 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:17.735256 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:63232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQfxWyxgRnoFKAJ_z0QAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:17.746643 2026] [security2:error] [pid 643573:tid 643791] [client 85.204.70.98:44356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuBQfxWyxgRnoFKAJ_z0gAAAmU"]
[Thu Jul 30 11:52:17.948058 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:17.997624 2026] [security2:error] [pid 643573:tid 643742] [client 85.204.70.98:44366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuBQfxWyxgRnoFKAJ_z1gAAAjQ"]
[Thu Jul 30 11:52:18.258179 2026] [security2:error] [pid 643573:tid 643769] [client 85.204.70.98:44368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuBQvxWyxgRnoFKAJ_z1wAAAk8"]
[Thu Jul 30 11:52:18.280679 2026] [security2:error] [pid 643573:tid 643716] [client 20.91.199.21:47099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/simi.php"] [unique_id "amuBQvxWyxgRnoFKAJ_z2AAAAho"]
[Thu Jul 30 11:52:18.379601 2026] [security2:error] [pid 643573:tid 643592] [remote 74.7.241.60:52566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuBQvxWyxgRnoFKAJ_z2QACPAs"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:52:18.487780 2026] [core:notice] [pid 642360:tid 642547] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:18.492264 2026] [security2:error] [pid 642360:tid 642547] [client 103.215.74.26:63248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQpSUkh3e5AhEJOBvTgAAAcg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:18.611058 2026] [security2:error] [pid 643573:tid 643837] [client 176.241.66.87:19739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBQvxWyxgRnoFKAJ_z4QAAApM"]
[Thu Jul 30 11:52:18.611205 2026] [security2:error] [pid 643573:tid 643837] [client 176.241.66.87:19739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBQvxWyxgRnoFKAJ_z4QAAApM"]
[Thu Jul 30 11:52:18.692737 2026] [core:notice] [pid 642360:tid 642426] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:18.760325 2026] [core:error] [pid 643253:tid 643496] [client 74.7.230.52:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:18.760354 2026] [core:error] [pid 643253:tid 643496] [client 74.7.230.52:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:18.760472 2026] [security2:error] [pid 643253:tid 643496] [client 74.7.230.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.clm.udi.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuBQsjqbtjBYzqM1uYmbgAAAHA"]
[Thu Jul 30 11:52:18.761026 2026] [security2:error] [pid 643573:tid 643761] [client 74.7.230.52:50944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.clm.udi.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuBQvxWyxgRnoFKAJ_z4gACRxM"]
[Thu Jul 30 11:52:19.245237 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:19.249669 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:63250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQ_xWyxgRnoFKAJ_z5wAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:19.418444 2026] [security2:error] [pid 643573:tid 643770] [client 20.91.199.21:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/wp-conf.php"] [unique_id "amuBQ_xWyxgRnoFKAJ_z6AAAAlA"]
[Thu Jul 30 11:52:19.577365 2026] [security2:error] [pid 643573:tid 643804] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ciunews.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBQ_xWyxgRnoFKAJ_z7AAAAnI"]
[Thu Jul 30 11:52:19.988005 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:19.995197 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:63260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBQ5SUkh3e5AhEJOBvWAAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:20.257367 2026] [security2:error] [pid 642360:tid 642575] [client 172.234.80.100:60166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/wp-login.php"] [unique_id "amuBP5SUkh3e5AhEJOBvLQAAAfQ"]
[Thu Jul 30 11:52:20.561104 2026] [security2:error] [pid 643573:tid 643762] [client 20.91.199.21:47093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuBRPxWyxgRnoFKAJ_z9QAAAkg"]
[Thu Jul 30 11:52:20.716229 2026] [core:notice] [pid 643573:tid 643835] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:20.720279 2026] [security2:error] [pid 643573:tid 643835] [client 103.215.74.26:63266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBRPxWyxgRnoFKAJ_z-QAAApE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:21.494808 2026] [core:notice] [pid 643573:tid 643783] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:21.498844 2026] [security2:error] [pid 643573:tid 643783] [client 103.215.74.26:63280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBRfxWyxgRnoFKAJ_z_QAAAl0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:22.224567 2026] [core:notice] [pid 643573:tid 643775] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:22.228418 2026] [security2:error] [pid 643573:tid 643775] [client 103.215.74.26:63286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBRvxWyxgRnoFKAJ_0BAAAAlU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:22.960590 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:22.965406 2026] [security2:error] [pid 642360:tid 642582] [client 103.215.74.26:63298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBRpSUkh3e5AhEJOBvcwAAAes"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:23.415552 2026] [security2:error] [pid 642360:tid 642511] [client 20.91.199.21:47062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/bala.php"] [unique_id "amuBR5SUkh3e5AhEJOBveAAAAaQ"]
[Thu Jul 30 11:52:23.690550 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:23.697314 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:36412] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBR_xWyxgRnoFKAJ_0EQAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:24.228621 2026] [security2:error] [pid 643573:tid 643810] [client 171.25.193.39:60834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.193.25.171.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBSPxWyxgRnoFKAJ_0GgAAAng"]
[Thu Jul 30 11:52:24.420409 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:24.427513 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:36422] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBSPxWyxgRnoFKAJ_0IwAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:24.643704 2026] [security2:error] [pid 643573:tid 643767] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBSPxWyxgRnoFKAJ_0FAAAAk0"]
[Thu Jul 30 11:52:25.157551 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:25.161524 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:36426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBSZSUkh3e5AhEJOBvigAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:25.325903 2026] [security2:error] [pid 643573:tid 643796] [client 20.91.199.21:47391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/bk.php"] [unique_id "amuBSfxWyxgRnoFKAJ_0LgAAAmo"]
[Thu Jul 30 11:52:25.395603 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:25.783834 2026] [security2:error] [pid 643253:tid 643498] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBScjqbtjBYzqM1uYmcQAAAHI"]
[Thu Jul 30 11:52:25.892747 2026] [core:notice] [pid 643573:tid 643772] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:25.896676 2026] [security2:error] [pid 643573:tid 643772] [client 103.215.74.26:36442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "772"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBSfxWyxgRnoFKAJ_0NQAAAlI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:26.325042 2026] [security2:error] [pid 642360:tid 642507] [client 127.0.0.1:52190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuBSpSUkh3e5AhEJOBvlgAAAaA"]
[Thu Jul 30 11:52:26.325055 2026] [security2:error] [pid 643573:tid 643819] [client 127.0.0.1:52174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fiyan.co"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuBSvxWyxgRnoFKAJ_0OAAAAoE"]
[Thu Jul 30 11:52:26.325283 2026] [security2:error] [pid 643573:tid 643718] [client 74.7.230.38:55446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fiyan.co"] [uri "/robots.txt"] [unique_id "amuBSvxWyxgRnoFKAJ_0NwACHEs"]
[Thu Jul 30 11:52:26.635070 2026] [core:notice] [pid 642360:tid 642545] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:26.642149 2026] [security2:error] [pid 642360:tid 642545] [client 103.215.74.26:36472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBSpSUkh3e5AhEJOBvmwAAAcY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:27.395672 2026] [core:notice] [pid 643573:tid 643737] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:27.400077 2026] [security2:error] [pid 643573:tid 643737] [client 103.215.74.26:36478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "785"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBS_xWyxgRnoFKAJ_0UAAAAi8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:27.420100 2026] [security2:error] [pid 643573:tid 643818] [client 68.221.186.136:46224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/json.php"] [unique_id "amuBS_xWyxgRnoFKAJ_0UgAAAoA"]
[Thu Jul 30 11:52:27.532077 2026] [security2:error] [pid 643573:tid 643834] [client 20.91.199.21:47379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.nordeste1.com"] [uri "/ahax.php"] [unique_id "amuBS_xWyxgRnoFKAJ_0VwAAApA"]
[Thu Jul 30 11:52:27.589245 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:28.115829 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:28.120600 2026] [security2:error] [pid 643573:tid 643713] [client 103.215.74.26:36498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBTPxWyxgRnoFKAJ_0XwAAAhc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:28.601411 2026] [security2:error] [pid 643253:tid 643399] [client 45.137.70.158:41826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.70.137.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBTMjqbtjBYzqM1uYmdAAAAA8"]
[Thu Jul 30 11:52:28.852726 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:28.856682 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:36502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBTPxWyxgRnoFKAJ_0aAAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:29.430697 2026] [security2:error] [pid 643573:tid 643781] [client 176.241.66.87:55640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBTfxWyxgRnoFKAJ_0bwAAAls"]
[Thu Jul 30 11:52:29.430845 2026] [security2:error] [pid 643573:tid 643781] [client 176.241.66.87:55640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBTfxWyxgRnoFKAJ_0bwAAAls"]
[Thu Jul 30 11:52:29.574175 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:29.578027 2026] [security2:error] [pid 643573:tid 643721] [client 103.215.74.26:36518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBTfxWyxgRnoFKAJ_0cwAAAh8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:29.766878 2026] [security2:error] [pid 643573:tid 643807] [client 185.100.85.24:3096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.85.100.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBTfxWyxgRnoFKAJ_0cAAAAnU"]
[Thu Jul 30 11:52:30.145293 2026] [security2:error] [pid 643573:tid 643761] [client 198.54.128.138:43206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuBTvxWyxgRnoFKAJ_0eQAAAkc"]
[Thu Jul 30 11:52:30.145396 2026] [security2:error] [pid 643573:tid 643761] [client 198.54.128.138:43206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuBTvxWyxgRnoFKAJ_0eQAAAkc"]
[Thu Jul 30 11:52:30.303324 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:30.307876 2026] [security2:error] [pid 643573:tid 643837] [client 103.215.74.26:36534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBTvxWyxgRnoFKAJ_0egAAApM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:31.031382 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:31.036190 2026] [security2:error] [pid 643573:tid 643786] [client 103.215.74.26:36540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBT_xWyxgRnoFKAJ_0ggAAAmA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:31.100901 2026] [security2:error] [pid 643573:tid 643670] [remote 185.61.152.44:49698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.152.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuBT_xWyxgRnoFKAJ_0gwACiFk"]
[Thu Jul 30 11:52:31.429300 2026] [security2:error] [pid 642360:tid 642588] [client 43.173.173.214:42268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/28/bruxelles-quartier-europeen-et-parcours-bd/"] [unique_id "amuBT5SUkh3e5AhEJOBvvwAAAfE"]
[Thu Jul 30 11:52:31.466944 2026] [security2:error] [pid 642360:tid 642511] [client 185.100.87.166:52396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.87.100.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBT5SUkh3e5AhEJOBvwAAAAaQ"]
[Thu Jul 30 11:52:31.469015 2026] [security2:error] [pid 642360:tid 642593] [client 62.102.148.185:49850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuBT5SUkh3e5AhEJOBvwQAAAfY"]
[Thu Jul 30 11:52:31.469122 2026] [security2:error] [pid 642360:tid 642593] [client 62.102.148.185:49850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuBT5SUkh3e5AhEJOBvwQAAAfY"]
[Thu Jul 30 11:52:31.604889 2026] [security2:error] [pid 643573:tid 643787] [client 68.221.186.136:46239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/mini.php"] [unique_id "amuBT_xWyxgRnoFKAJ_0iAAAAmE"]
[Thu Jul 30 11:52:31.755518 2026] [core:notice] [pid 643253:tid 643444] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:31.759477 2026] [security2:error] [pid 643253:tid 643444] [client 103.215.74.26:36552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBT8jqbtjBYzqM1uYmeQAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:32.023778 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.064557 2026] [core:notice] [pid 643573:tid 643833] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.310691 2026] [core:notice] [pid 643573:tid 643741] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.315851 2026] [security2:error] [pid 643573:tid 643741] [client 43.173.173.62:35924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/28/bruxelles-quartier-europeen-et-parcours-bd/"] [unique_id "amuBUPxWyxgRnoFKAJ_0jwAAAjM"], referer: https://carnetdeshopping.com/index.php/2013/05/28/bruxelles-quartier-europeen-et-parcours-bd/
[Thu Jul 30 11:52:32.323315 2026] [security2:error] [pid 643253:tid 643511] [client 57.141.0.46:46858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuBUMjqbtjBYzqM1uYmewAAf1E"]
[Thu Jul 30 11:52:32.363078 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.486485 2026] [security2:error] [pid 643573:tid 643777] [client 68.221.186.136:26613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/chosen.php"] [unique_id "amuBUPxWyxgRnoFKAJ_0kQAAAlc"]
[Thu Jul 30 11:52:32.490805 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:32.498688 2026] [security2:error] [pid 643573:tid 643756] [client 103.215.74.26:36558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBUPxWyxgRnoFKAJ_0kgAAAkI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:33.230834 2026] [core:notice] [pid 643573:tid 643745] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:33.234967 2026] [security2:error] [pid 643573:tid 643745] [client 103.215.74.26:45548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBUfxWyxgRnoFKAJ_0mwAAAjc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:33.370696 2026] [security2:error] [pid 643573:tid 643763] [client 68.221.186.136:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/kj.php"] [unique_id "amuBUfxWyxgRnoFKAJ_0nQAAAkk"]
[Thu Jul 30 11:52:33.614330 2026] [security2:error] [pid 643573:tid 643820] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBUPxWyxgRnoFKAJ_0lgACglw"]
[Thu Jul 30 11:52:33.956172 2026] [core:notice] [pid 643573:tid 643808] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:33.960268 2026] [security2:error] [pid 643573:tid 643808] [client 103.215.74.26:45554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBUfxWyxgRnoFKAJ_0pAAAAnY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:34.201553 2026] [security2:error] [pid 643573:tid 643809] [client 68.221.186.136:44162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-files.php"] [unique_id "amuBUvxWyxgRnoFKAJ_0pwAAAnc"]
[Thu Jul 30 11:52:34.682016 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:34.686385 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:45560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBUvxWyxgRnoFKAJ_0qwAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:34.720577 2026] [core:notice] [pid 643573:tid 643819] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:35.021354 2026] [security2:error] [pid 643573:tid 643828] [client 68.221.186.136:25283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-setup.php"] [unique_id "amuBU_xWyxgRnoFKAJ_0sQAAAoo"]
[Thu Jul 30 11:52:35.406220 2026] [core:notice] [pid 643573:tid 643791] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:35.410612 2026] [security2:error] [pid 643573:tid 643791] [client 103.215.74.26:45574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBU_xWyxgRnoFKAJ_0ugAAAmU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:36.147178 2026] [core:notice] [pid 643573:tid 643715] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:36.151545 2026] [security2:error] [pid 643573:tid 643715] [client 103.215.74.26:45584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBVPxWyxgRnoFKAJ_0vwAAAhk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:36.156234 2026] [security2:error] [pid 643573:tid 643759] [client 68.221.186.136:42617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/defaults.php"] [unique_id "amuBVPxWyxgRnoFKAJ_0wAAAAkU"]
[Thu Jul 30 11:52:36.673029 2026] [security2:error] [pid 642360:tid 642513] [client 85.208.96.203:46320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2023/01/04/inscricoes-em-processo-seletivo-da-rede-municipal-de-ensino-de-dona-ines-pb-terminam-nesta-quarta-4/"] [unique_id "amuBVJSUkh3e5AhEJOBwCQAAAaY"]
[Thu Jul 30 11:52:36.673154 2026] [security2:error] [pid 642360:tid 642513] [client 85.208.96.203:46320] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2023/01/04/inscricoes-em-processo-seletivo-da-rede-municipal-de-ensino-de-dona-ines-pb-terminam-nesta-quarta-4/"] [unique_id "amuBVJSUkh3e5AhEJOBwCQAAAaY"]
[Thu Jul 30 11:52:36.879760 2026] [core:notice] [pid 643573:tid 643778] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:36.884099 2026] [security2:error] [pid 643573:tid 643778] [client 103.215.74.26:45594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBVPxWyxgRnoFKAJ_0yAAAAlg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:37.272179 2026] [security2:error] [pid 643573:tid 643775] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBVPxWyxgRnoFKAJ_0xwACVWQ"]
[Thu Jul 30 11:52:37.308707 2026] [security2:error] [pid 643573:tid 643796] [client 68.221.186.136:44220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gtc.php"] [unique_id "amuBVfxWyxgRnoFKAJ_0zAAAAmo"]
[Thu Jul 30 11:52:38.264793 2026] [security2:error] [pid 642360:tid 642498] [client 45.84.107.74:51149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuBVpSUkh3e5AhEJOBwGAAAAZc"]
[Thu Jul 30 11:52:40.056912 2026] [security2:error] [pid 643573:tid 643727] [client 176.241.66.87:21099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBWPxWyxgRnoFKAJ_06QAAAiU"]
[Thu Jul 30 11:52:40.057089 2026] [security2:error] [pid 643573:tid 643727] [client 176.241.66.87:21099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBWPxWyxgRnoFKAJ_06QAAAiU"]
[Thu Jul 30 11:52:41.354803 2026] [security2:error] [pid 642360:tid 642540] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBWJSUkh3e5AhEJOBwXAABwV4"]
[Thu Jul 30 11:52:41.557284 2026] [security2:error] [pid 643573:tid 643770] [client 68.221.186.136:43037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/import.php"] [unique_id "amuBWfxWyxgRnoFKAJ_07wAAAlA"]
[Thu Jul 30 11:52:41.579175 2026] [security2:error] [pid 643573:tid 643688] [remote 216.73.216.152:5618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBWfxWyxgRnoFKAJ_08AACY2s"]
[Thu Jul 30 11:52:42.605771 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:42.610115 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:45604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBWvxWyxgRnoFKAJ_09wAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:42.647334 2026] [security2:error] [pid 642360:tid 642566] [client 68.221.186.136:25336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/lufix.php"] [unique_id "amuBWpSUkh3e5AhEJOBwbwAAAds"]
[Thu Jul 30 11:52:43.330013 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:43.334384 2026] [security2:error] [pid 642360:tid 642613] [client 103.215.74.26:43464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBW5SUkh3e5AhEJOBwdAAAAgo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:43.422715 2026] [core:notice] [pid 642360:tid 642464] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:43.496577 2026] [security2:error] [pid 643573:tid 643716] [client 68.221.186.136:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/Geforce.php"] [unique_id "amuBW_xWyxgRnoFKAJ_0_AAAAho"]
[Thu Jul 30 11:52:43.818648 2026] [security2:error] [pid 643573:tid 643724] [client 216.244.66.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "embassyofspaininpakistan.info"] [uri "/"] [unique_id "amuBW_xWyxgRnoFKAJ_0_wAAAiI"]
[Thu Jul 30 11:52:43.818762 2026] [security2:error] [pid 643573:tid 643724] [client 216.244.66.250:0] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "embassyofspaininpakistan.info"] [uri "/"] [unique_id "amuBW_xWyxgRnoFKAJ_0_wAAAiI"]
[Thu Jul 30 11:52:43.893038 2026] [core:notice] [pid 643573:tid 643796] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:43.903419 2026] [core:error] [pid 643573:tid 643796] [client 66.249.65.196:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:43.903583 2026] [security2:error] [pid 643573:tid 643796] [client 66.249.65.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/112/109.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuBW_xWyxgRnoFKAJ_0_gAAAmo"]
[Thu Jul 30 11:52:44.062289 2026] [core:notice] [pid 643573:tid 643726] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:44.066069 2026] [security2:error] [pid 643573:tid 643726] [client 103.215.74.26:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBXPxWyxgRnoFKAJ_1AAAAAiQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:44.476233 2026] [core:notice] [pid 643573:tid 643689] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:44.479814 2026] [core:notice] [pid 643573:tid 643627] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:44.791568 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:44.797125 2026] [security2:error] [pid 643573:tid 643718] [client 103.215.74.26:43496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBXPxWyxgRnoFKAJ_1BwAAAhw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:45.020777 2026] [security2:error] [pid 643573:tid 643787] [client 85.204.70.98:45394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuBXfxWyxgRnoFKAJ_1CQAAAmE"]
[Thu Jul 30 11:52:45.286110 2026] [security2:error] [pid 642360:tid 642599] [client 85.204.70.98:45408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuBXZSUkh3e5AhEJOBwhwAAAfw"]
[Thu Jul 30 11:52:45.517939 2026] [core:notice] [pid 643573:tid 643810] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:45.521873 2026] [security2:error] [pid 643573:tid 643810] [client 103.215.74.26:43510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBXfxWyxgRnoFKAJ_1DAAAAng"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:45.572112 2026] [security2:error] [pid 643573:tid 643762] [client 85.204.70.98:45412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuBXfxWyxgRnoFKAJ_1DQAAAkg"]
[Thu Jul 30 11:52:45.903468 2026] [security2:error] [pid 642360:tid 642537] [client 85.204.70.98:45414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuBXZSUkh3e5AhEJOBwjwAAAb4"]
[Thu Jul 30 11:52:46.164569 2026] [security2:error] [pid 643573:tid 643783] [client 85.204.70.98:45426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuBXvxWyxgRnoFKAJ_1FgAAAl0"]
[Thu Jul 30 11:52:46.278310 2026] [core:notice] [pid 642360:tid 642565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:46.282807 2026] [security2:error] [pid 642360:tid 642565] [client 103.215.74.26:43520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBXpSUkh3e5AhEJOBwkwAAAdo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:46.323373 2026] [core:notice] [pid 643573:tid 643721] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:46.430122 2026] [security2:error] [pid 642360:tid 642614] [client 85.204.70.98:28314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuBXpSUkh3e5AhEJOBwlAAAAgs"]
[Thu Jul 30 11:52:46.489474 2026] [security2:error] [pid 643573:tid 643712] [client 68.221.186.136:26620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/a4.php"] [unique_id "amuBXvxWyxgRnoFKAJ_1HAAAAhY"]
[Thu Jul 30 11:52:46.708344 2026] [security2:error] [pid 643573:tid 643816] [client 85.204.70.98:45444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuBXvxWyxgRnoFKAJ_1HgAAAn4"]
[Thu Jul 30 11:52:46.975791 2026] [security2:error] [pid 643573:tid 643829] [client 85.204.70.98:45452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuBXvxWyxgRnoFKAJ_1IQAAAos"]
[Thu Jul 30 11:52:47.022628 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:47.029648 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:43524] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBX8jqbtjBYzqM1uYmgwAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:47.226063 2026] [security2:error] [pid 643253:tid 643482] [client 85.204.70.98:45456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuBX8jqbtjBYzqM1uYmhAAAAGI"]
[Thu Jul 30 11:52:47.491240 2026] [security2:error] [pid 643573:tid 643718] [client 85.204.70.98:45472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sua.nyx.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuBX_xWyxgRnoFKAJ_1MAAAAhw"]
[Thu Jul 30 11:52:47.758528 2026] [security2:error] [pid 643253:tid 643477] [client 68.221.186.136:44940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/accueil.php"] [unique_id "amuBX8jqbtjBYzqM1uYmhgAAAF0"]
[Thu Jul 30 11:52:47.761801 2026] [core:notice] [pid 643573:tid 643768] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:47.768486 2026] [security2:error] [pid 643573:tid 643768] [client 103.215.74.26:43528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBX_xWyxgRnoFKAJ_1NAAAAk4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:48.226708 2026] [security2:error] [pid 642360:tid 642587] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBX5SUkh3e5AhEJOBwoAAAAfA"]
[Thu Jul 30 11:52:48.486090 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:48.491057 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:43530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBYJSUkh3e5AhEJOBwpgAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:48.573170 2026] [security2:error] [pid 642360:tid 642563] [client 68.221.186.136:42587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/dashboard.php"] [unique_id "amuBYJSUkh3e5AhEJOBwpwAAAdg"]
[Thu Jul 30 11:52:48.954932 2026] [security2:error] [pid 643573:tid 643824] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBYPxWyxgRnoFKAJ_1OQAChmk"]
[Thu Jul 30 11:52:49.182480 2026] [security2:error] [pid 643573:tid 643755] [client 68.221.186.136:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/radio.php"] [unique_id "amuBYfxWyxgRnoFKAJ_1QQAAAkE"]
[Thu Jul 30 11:52:49.222713 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:49.226862 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:43540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBYcjqbtjBYzqM1uYmhwAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:49.624985 2026] [security2:error] [pid 643573:tid 643785] [client 86.241.173.36:59790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBYfxWyxgRnoFKAJ_1RQAAAl8"], referer: http://pkf.jo
[Thu Jul 30 11:52:50.035339 2026] [security2:error] [pid 643573:tid 643827] [client 59.183.69.7:59000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBYfxWyxgRnoFKAJ_1SwAAAok"], referer: http://pkf.jo
[Thu Jul 30 11:52:50.045554 2026] [security2:error] [pid 643573:tid 643833] [client 170.64.210.244:58938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:lang. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:lang"] [severity "CRITICAL"] [hostname "50.6.43.58"] [uri "/remote/fgt_lang"] [unique_id "amuBYvxWyxgRnoFKAJ_1TgAAAo8"]
[Thu Jul 30 11:52:50.175459 2026] [security2:error] [pid 643253:tid 643493] [client 68.221.186.136:26571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wpsml-sys.php"] [unique_id "amuBYsjqbtjBYzqM1uYmiwAAAG0"]
[Thu Jul 30 11:52:50.625949 2026] [security2:error] [pid 643253:tid 643409] [client 176.241.66.87:56862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBYsjqbtjBYzqM1uYmjQAAABk"]
[Thu Jul 30 11:52:50.626089 2026] [security2:error] [pid 643253:tid 643409] [client 176.241.66.87:56862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBYsjqbtjBYzqM1uYmjQAAABk"]
[Thu Jul 30 11:52:50.973824 2026] [security2:error] [pid 643573:tid 643726] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBYvxWyxgRnoFKAJ_1UgACJCU"]
[Thu Jul 30 11:52:51.441468 2026] [security2:error] [pid 642360:tid 642511] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fantasynamelist.com"] [uri "/media/system/js/core.js"] [unique_id "amuBY5SUkh3e5AhEJOBwvgAAAaQ"]
[Thu Jul 30 11:52:51.584381 2026] [security2:error] [pid 643573:tid 643708] [remote 216.73.216.152:44174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuBY_xWyxgRnoFKAJ_1YAAChn8"]
[Thu Jul 30 11:52:52.453855 2026] [security2:error] [pid 643573:tid 643829] [client 106.76.74.61:37539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBZPxWyxgRnoFKAJ_1ZgAAAos"], referer: http://pkf.jo
[Thu Jul 30 11:52:53.068740 2026] [core:error] [pid 643573:tid 643774] [client 74.7.244.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:53.068761 2026] [core:error] [pid 643573:tid 643774] [client 74.7.244.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:52:53.068877 2026] [security2:error] [pid 643573:tid 643774] [client 74.7.244.37:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ymk.udi.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuBZfxWyxgRnoFKAJ_1bgAAAlQ"]
[Thu Jul 30 11:52:53.069531 2026] [security2:error] [pid 642360:tid 642542] [client 74.7.244.37:33888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ymk.udi.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuBZZSUkh3e5AhEJOBwygABw20"]
[Thu Jul 30 11:52:53.822511 2026] [security2:error] [pid 643573:tid 643746] [client 74.7.244.59:54442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.adbacklink.com"] [uri "/robots.txt"] [unique_id "amuBZfxWyxgRnoFKAJ_1dAACOHg"]
[Thu Jul 30 11:52:54.183723 2026] [security2:error] [pid 643573:tid 643814] [client 68.221.186.136:42969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/02.php"] [unique_id "amuBZvxWyxgRnoFKAJ_1egAAAnw"]
[Thu Jul 30 11:52:54.390581 2026] [security2:error] [pid 643573:tid 643819] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBZfxWyxgRnoFKAJ_1cQACgW4"]
[Thu Jul 30 11:52:54.747127 2026] [security2:error] [pid 643573:tid 643819] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBZfxWyxgRnoFKAJ_1dwACgQg"]
[Thu Jul 30 11:52:54.986427 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:54.993242 2026] [security2:error] [pid 642360:tid 642597] [client 103.215.74.26:33700] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBZpSUkh3e5AhEJOBw3AAAAfo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:55.723349 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:55.727381 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:33708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "784"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBZ_xWyxgRnoFKAJ_1gQAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:56.456321 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:56.460295 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:33718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBaPxWyxgRnoFKAJ_1hQAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:57.197544 2026] [security2:error] [pid 643573:tid 643587] [remote 216.73.216.152:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBafxWyxgRnoFKAJ_1iwACVAY"]
[Thu Jul 30 11:52:57.199256 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:57.203176 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:33726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBafxWyxgRnoFKAJ_1jAAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:57.236353 2026] [security2:error] [pid 642360:tid 642523] [client 62.102.148.185:37376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuBaZSUkh3e5AhEJOBw6wAAAbA"]
[Thu Jul 30 11:52:57.236437 2026] [security2:error] [pid 642360:tid 642523] [client 62.102.148.185:37376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuBaZSUkh3e5AhEJOBw6wAAAbA"]
[Thu Jul 30 11:52:57.240514 2026] [security2:error] [pid 642360:tid 642503] [client 74.7.175.142:49464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bep-viet.bonafideadvisors.com"] [uri "/index.php"] [unique_id "amuBZJSUkh3e5AhEJOBwxQABnAM"]
[Thu Jul 30 11:52:57.989232 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:57.993226 2026] [security2:error] [pid 642360:tid 642561] [client 103.215.74.26:33742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBaZSUkh3e5AhEJOBw8AAAAdY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:58.181474 2026] [security2:error] [pid 643573:tid 643595] [remote 51.161.37.104:58664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kicksity.com"] [uri "/product/nik-air-jordan-4-canyon-purple/feed/"] [unique_id "amuBavxWyxgRnoFKAJ_1lwACQg4"]
[Thu Jul 30 11:52:58.181616 2026] [security2:error] [pid 643573:tid 643756] [client 51.161.37.104:58664] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nik-air-jordan-4-canyon-purple/feed/"] [unique_id "amuBavxWyxgRnoFKAJ_1lwACQg4"]
[Thu Jul 30 11:52:58.714309 2026] [core:notice] [pid 642360:tid 642563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:58.718729 2026] [security2:error] [pid 642360:tid 642563] [client 103.215.74.26:33750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBapSUkh3e5AhEJOBw9wAAAdg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:59.158558 2026] [security2:error] [pid 643573:tid 643808] [client 68.221.186.136:44394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/infos.php"] [unique_id "amuBa_xWyxgRnoFKAJ_1owAAAnY"]
[Thu Jul 30 11:52:59.222342 2026] [security2:error] [pid 643573:tid 643727] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBavxWyxgRnoFKAJ_1ngAAAiU"]
[Thu Jul 30 11:52:59.447636 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:52:59.451738 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:33754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBa_xWyxgRnoFKAJ_1pwAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:52:59.608372 2026] [security2:error] [pid 643573:tid 643714] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBavxWyxgRnoFKAJ_1ogACGEY"]
[Thu Jul 30 11:52:59.681783 2026] [security2:error] [pid 643573:tid 643772] [client 77.83.36.161:35087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuBa_xWyxgRnoFKAJ_1pgAAAlI"]
[Thu Jul 30 11:52:59.881770 2026] [core:notice] [pid 643573:tid 643684] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:00.173137 2026] [security2:error] [pid 643573:tid 643781] [client 68.221.186.136:43007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/updates.php"] [unique_id "amuBbPxWyxgRnoFKAJ_1tAAAAls"]
[Thu Jul 30 11:53:00.182038 2026] [core:notice] [pid 642360:tid 642532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:00.185835 2026] [security2:error] [pid 642360:tid 642532] [client 103.215.74.26:33756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBbJSUkh3e5AhEJOBxBAAAAbk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:00.246945 2026] [security2:error] [pid 643573:tid 643749] [client 77.83.36.161:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuBbPxWyxgRnoFKAJ_1tQAAAjs"]
[Thu Jul 30 11:53:00.630059 2026] [security2:error] [pid 642360:tid 642555] [client 190.2.142.78:30488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alqahtanifurnituremoversllc.site"] [uri "/wp-login.php"] [unique_id "amuBbJSUkh3e5AhEJOBxCAAAAdA"]
[Thu Jul 30 11:53:00.804039 2026] [security2:error] [pid 643573:tid 643745] [client 77.83.36.161:35841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuBbPxWyxgRnoFKAJ_1vgAAAjc"]
[Thu Jul 30 11:53:00.902794 2026] [security2:error] [pid 642360:tid 642562] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBbJSUkh3e5AhEJOBxBwAAAdc"]
[Thu Jul 30 11:53:00.910947 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:00.915348 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:33766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBbPxWyxgRnoFKAJ_1wQAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:00.953301 2026] [security2:error] [pid 642360:tid 642593] [client 68.221.186.136:42987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/user.php"] [unique_id "amuBbJSUkh3e5AhEJOBxDQAAAfY"]
[Thu Jul 30 11:53:01.110348 2026] [core:error] [pid 643573:tid 643806] [client 190.2.142.78:30500] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:01.110372 2026] [core:error] [pid 643573:tid 643806] [client 190.2.142.78:30500] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:01.268458 2026] [security2:error] [pid 643573:tid 643763] [client 176.241.66.87:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBbfxWyxgRnoFKAJ_1xAAAAkk"]
[Thu Jul 30 11:53:01.268574 2026] [security2:error] [pid 643573:tid 643763] [client 176.241.66.87:57626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBbfxWyxgRnoFKAJ_1xAAAAkk"]
[Thu Jul 30 11:53:01.598709 2026] [autoindex:error] [pid 643573:tid 643748] [client 190.2.142.78:30512] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:01.604477 2026] [security2:error] [pid 643573:tid 643770] [client 68.221.186.136:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/admin-ajax.php"] [unique_id "amuBbfxWyxgRnoFKAJ_1xwAAAlA"]
[Thu Jul 30 11:53:01.606562 2026] [security2:error] [pid 643573:tid 643600] [remote 216.73.216.152:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBbfxWyxgRnoFKAJ_1yAACKxM"]
[Thu Jul 30 11:53:01.636155 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:01.640396 2026] [security2:error] [pid 643573:tid 643713] [client 103.215.74.26:33770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBbfxWyxgRnoFKAJ_1yQAAAhc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:02.365101 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:02.369503 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:33780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBbvxWyxgRnoFKAJ_10wAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:02.630099 2026] [security2:error] [pid 643573:tid 643753] [client 103.59.160.82:52538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bonafideadvisors.com"] [uri "/index.php"] [unique_id "amuBbvxWyxgRnoFKAJ_11QAAAj8"]
[Thu Jul 30 11:53:03.098146 2026] [core:notice] [pid 642360:tid 642599] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:03.102621 2026] [security2:error] [pid 642360:tid 642599] [client 103.215.74.26:12458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBb5SUkh3e5AhEJOBxHAAAAfw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:03.372915 2026] [security2:error] [pid 643573:tid 643737] [client 68.221.186.136:42569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfa.php"] [unique_id "amuBb_xWyxgRnoFKAJ_12wAAAi8"]
[Thu Jul 30 11:53:03.832908 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:03.837285 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:12470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBb_xWyxgRnoFKAJ_13gAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:04.232028 2026] [security2:error] [pid 642360:tid 642615] [client 72.252.232.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBb5SUkh3e5AhEJOBxHgACDEg"], referer: https://allmontecristi.com
[Thu Jul 30 11:53:06.110855 2026] [security2:error] [pid 643573:tid 643759] [client 190.2.142.78:20012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alqimmafurnituremovers.xyz"] [uri "/wp-login.php"] [unique_id "amuBcvxWyxgRnoFKAJ_19QAAAkU"]
[Thu Jul 30 11:53:06.256795 2026] [proxy:error] [pid 643573:tid 643773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:06.256898 2026] [proxy_http:error] [pid 643573:tid 643773] [client 68.221.186.136:42289] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:06.257894 2026] [proxy:error] [pid 643573:tid 643773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:06.257955 2026] [proxy_http:error] [pid 643573:tid 643773] [client 68.221.186.136:42289] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:06.592704 2026] [core:error] [pid 643573:tid 643720] [client 190.2.142.78:20022] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:06.592726 2026] [core:error] [pid 643573:tid 643720] [client 190.2.142.78:20022] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:07.049046 2026] [security2:error] [pid 643573:tid 643808] [client 203.175.125.116:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tmrfsl.com"] [uri "/wp-json/batch/v1"] [unique_id "amuBc_xWyxgRnoFKAJ_1_wAAAnY"]
[Thu Jul 30 11:53:07.117694 2026] [security2:error] [pid 643573:tid 643728] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBcvxWyxgRnoFKAJ_1_AACJjU"]
[Thu Jul 30 11:53:07.217633 2026] [security2:error] [pid 642360:tid 642454] [remote 216.73.216.152:24715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBc5SUkh3e5AhEJOBxNgAB1l0"]
[Thu Jul 30 11:53:09.356635 2026] [security2:error] [pid 643573:tid 643782] [client 68.221.186.136:42583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/hehe.php"] [unique_id "amuBdfxWyxgRnoFKAJ_2DwAAAlw"]
[Thu Jul 30 11:53:09.598056 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:09.603205 2026] [security2:error] [pid 642360:tid 642582] [client 103.215.74.26:12506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBdZSUkh3e5AhEJOBxTQAAAes"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:10.114867 2026] [security2:error] [pid 643573:tid 643810] [client 68.221.186.136:43017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/rk2.php"] [unique_id "amuBdvxWyxgRnoFKAJ_2FAAAAng"]
[Thu Jul 30 11:53:10.340325 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:10.344417 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:12508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBdvxWyxgRnoFKAJ_2GwAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:10.582699 2026] [security2:error] [pid 643573:tid 643763] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "illicali.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBdvxWyxgRnoFKAJ_2HAAAAkk"]
[Thu Jul 30 11:53:11.116542 2026] [core:notice] [pid 643573:tid 643804] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:11.120878 2026] [security2:error] [pid 643573:tid 643804] [client 103.215.74.26:12512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBd_xWyxgRnoFKAJ_2IQAAAnI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:11.616614 2026] [security2:error] [pid 642360:tid 642446] [remote 216.73.216.152:24715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBd5SUkh3e5AhEJOBxXgABqFU"]
[Thu Jul 30 11:53:11.925212 2026] [security2:error] [pid 643573:tid 643821] [client 176.241.66.87:23255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBd_xWyxgRnoFKAJ_2JwAAAoM"]
[Thu Jul 30 11:53:11.925404 2026] [security2:error] [pid 643573:tid 643821] [client 176.241.66.87:23255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBd_xWyxgRnoFKAJ_2JwAAAoM"]
[Thu Jul 30 11:53:12.743843 2026] [security2:error] [pid 643573:tid 643737] [client 68.221.186.136:43049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/setup-config.php"] [unique_id "amuBePxWyxgRnoFKAJ_2MgAAAi8"]
[Thu Jul 30 11:53:13.505722 2026] [security2:error] [pid 642360:tid 642594] [client 172.213.208.20:6668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wk/index.php"] [unique_id "amuBeZSUkh3e5AhEJOBxeAAAAfc"]
[Thu Jul 30 11:53:13.596542 2026] [security2:error] [pid 643573:tid 643769] [client 68.221.186.136:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/a7.php"] [unique_id "amuBefxWyxgRnoFKAJ_2OAAAAk8"]
[Thu Jul 30 11:53:14.376257 2026] [security2:error] [pid 643573:tid 643776] [client 172.213.208.20:22611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/av.php"] [unique_id "amuBevxWyxgRnoFKAJ_2PAAAAlY"]
[Thu Jul 30 11:53:15.499511 2026] [security2:error] [pid 643573:tid 643710] [client 172.213.208.20:44816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/mini.php"] [unique_id "amuBe_xWyxgRnoFKAJ_2QgAAAhQ"]
[Thu Jul 30 11:53:15.701405 2026] [security2:error] [pid 643573:tid 643828] [client 68.221.186.136:43266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/f7.php"] [unique_id "amuBe_xWyxgRnoFKAJ_2RwAAAoo"]
[Thu Jul 30 11:53:15.802537 2026] [security2:error] [pid 643253:tid 643408] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBe8jqbtjBYzqM1uYmmAAAABg"]
[Thu Jul 30 11:53:15.841657 2026] [security2:error] [pid 643573:tid 643607] [remote 57.141.0.42:63024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuBe_xWyxgRnoFKAJ_2SAACHho"]
[Thu Jul 30 11:53:16.294736 2026] [security2:error] [pid 643253:tid 643488] [client 68.221.186.136:44706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/nw.php"] [unique_id "amuBfMjqbtjBYzqM1uYmmgAAAGg"]
[Thu Jul 30 11:53:16.846913 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:16.851299 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:26388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBfPxWyxgRnoFKAJ_2UgAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:17.225153 2026] [security2:error] [pid 643573:tid 643658] [remote 216.73.216.152:61267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBffxWyxgRnoFKAJ_2VwACck0"]
[Thu Jul 30 11:53:18.091603 2026] [security2:error] [pid 643573:tid 643836] [client 68.221.186.136:43068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ova.php"] [unique_id "amuBfvxWyxgRnoFKAJ_2XgAAApI"]
[Thu Jul 30 11:53:18.380677 2026] [security2:error] [pid 643573:tid 643755] [client 34.86.95.193:52091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "skcarrental.ae"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuBfvxWyxgRnoFKAJ_2YgAAAkE"]
[Thu Jul 30 11:53:18.642786 2026] [security2:error] [pid 643573:tid 643741] [client 172.213.208.20:6490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/aa.php"] [unique_id "amuBfvxWyxgRnoFKAJ_2ZwAAAjM"]
[Thu Jul 30 11:53:19.227927 2026] [security2:error] [pid 643253:tid 643489] [client 68.221.186.136:42522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/robots.php"] [unique_id "amuBf8jqbtjBYzqM1uYmnAAAAGk"]
[Thu Jul 30 11:53:19.228122 2026] [core:notice] [pid 643573:tid 643834] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:19.750487 2026] [security2:error] [pid 643573:tid 643714] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBf_xWyxgRnoFKAJ_2cQAAAhg"]
[Thu Jul 30 11:53:19.757796 2026] [security2:error] [pid 643573:tid 643827] [client 95.126.50.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBf_xWyxgRnoFKAJ_2bgACiUk"], referer: https://allmontecristi.com
[Thu Jul 30 11:53:20.017646 2026] [security2:error] [pid 643573:tid 643831] [client 68.221.186.136:45609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alf.php"] [unique_id "amuBgPxWyxgRnoFKAJ_2fAAAAo0"]
[Thu Jul 30 11:53:20.134406 2026] [core:notice] [pid 643573:tid 643655] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:20.634230 2026] [security2:error] [pid 643573:tid 643671] [remote 74.7.241.60:41892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amuBgPxWyxgRnoFKAJ_2hAACa1o"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 11:53:20.693771 2026] [security2:error] [pid 643573:tid 643774] [client 62.102.148.185:45252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuBgPxWyxgRnoFKAJ_2iwAAAlQ"]
[Thu Jul 30 11:53:20.693876 2026] [security2:error] [pid 643573:tid 643774] [client 62.102.148.185:45252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuBgPxWyxgRnoFKAJ_2iwAAAlQ"]
[Thu Jul 30 11:53:20.700209 2026] [security2:error] [pid 643573:tid 643723] [client 216.244.66.242:37788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/politica/hc/en-us/articles/41383541904281-Envato-Market-Terms"] [unique_id "amuBgPxWyxgRnoFKAJ_2jQAAAiE"]
[Thu Jul 30 11:53:20.700351 2026] [security2:error] [pid 643573:tid 643723] [client 216.244.66.242:37788] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/politica/hc/en-us/articles/41383541904281-Envato-Market-Terms"] [unique_id "amuBgPxWyxgRnoFKAJ_2jQAAAiE"]
[Thu Jul 30 11:53:20.749307 2026] [core:error] [pid 643573:tid 643755] [client 206.238.68.173:55404] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Jul 30 11:53:21.006169 2026] [security2:error] [pid 643573:tid 643751] [client 172.213.208.20:14846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/w.php"] [unique_id "amuBgfxWyxgRnoFKAJ_2kwAAAj0"]
[Thu Jul 30 11:53:21.009789 2026] [autoindex:error] [pid 643573:tid 643761] [client 101.33.55.204:54440] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:21.018630 2026] [security2:error] [pid 643573:tid 643781] [client 68.221.186.136:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/feedback.php"] [unique_id "amuBgfxWyxgRnoFKAJ_2lAAAAls"]
[Thu Jul 30 11:53:21.623920 2026] [security2:error] [pid 643573:tid 643666] [remote 216.73.216.152:61267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBgfxWyxgRnoFKAJ_2ngACTlU"]
[Thu Jul 30 11:53:21.799430 2026] [core:error] [pid 643573:tid 643663] [remote 216.73.217.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:21.799453 2026] [core:error] [pid 643573:tid 643663] [remote 216.73.217.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:21.869973 2026] [security2:error] [pid 642360:tid 642523] [client 172.213.208.20:18515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amuBgZSUkh3e5AhEJOBxvwAAAbA"]
[Thu Jul 30 11:53:22.097059 2026] [security2:error] [pid 642360:tid 642557] [client 68.221.186.136:44524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gettest.php"] [unique_id "amuBgpSUkh3e5AhEJOBxwgAAAdI"]
[Thu Jul 30 11:53:22.243591 2026] [core:notice] [pid 642360:tid 642480] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:22.523013 2026] [security2:error] [pid 643573:tid 643802] [client 176.241.66.87:23925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBgvxWyxgRnoFKAJ_2qAAAAnA"]
[Thu Jul 30 11:53:22.523150 2026] [security2:error] [pid 643573:tid 643802] [client 176.241.66.87:23925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBgvxWyxgRnoFKAJ_2qAAAAnA"]
[Thu Jul 30 11:53:22.632366 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:22.636530 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:26400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBgsjqbtjBYzqM1uYmngAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:22.884306 2026] [autoindex:error] [pid 643573:tid 643732] [client 195.96.139.114:51223] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:22.978862 2026] [security2:error] [pid 643573:tid 643828] [client 34.86.95.193:60105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBgvxWyxgRnoFKAJ_2qQAAAoo"]
[Thu Jul 30 11:53:23.280056 2026] [security2:error] [pid 642360:tid 642563] [client 187.249.92.243:33474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBgpSUkh3e5AhEJOBxyQAAAdg"], referer: http://pkf.jo
[Thu Jul 30 11:53:23.295793 2026] [security2:error] [pid 642360:tid 642521] [client 68.221.186.136:43267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/maint.php"] [unique_id "amuBg5SUkh3e5AhEJOBxzwAAAa4"]
[Thu Jul 30 11:53:23.302010 2026] [core:notice] [pid 642360:tid 642376] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:23.316769 2026] [core:notice] [pid 643573:tid 643648] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:23.322067 2026] [core:notice] [pid 642360:tid 642365] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:23.371619 2026] [core:notice] [pid 643253:tid 643432] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:23.375767 2026] [security2:error] [pid 643253:tid 643432] [client 103.215.74.26:56034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBg8jqbtjBYzqM1uYmoQAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:23.479916 2026] [security2:error] [pid 642360:tid 642528] [client 172.213.208.20:36541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuBg5SUkh3e5AhEJOBx1AAAAbU"]
[Thu Jul 30 11:53:23.606994 2026] [security2:error] [pid 643573:tid 643745] [client 138.36.48.104:23892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBg_xWyxgRnoFKAJ_2rgAAAjc"], referer: http://pkf.jo
[Thu Jul 30 11:53:23.677046 2026] [security2:error] [pid 643573:tid 643763] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBg_xWyxgRnoFKAJ_2rAACSVw"]
[Thu Jul 30 11:53:24.090246 2026] [core:notice] [pid 643573:tid 643769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:24.095131 2026] [security2:error] [pid 643573:tid 643769] [client 103.215.74.26:56046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhPxWyxgRnoFKAJ_2twAAAk8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:24.198291 2026] [security2:error] [pid 642360:tid 642566] [client 34.86.95.193:62859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBhJSUkh3e5AhEJOBx2QAAAds"]
[Thu Jul 30 11:53:24.458392 2026] [security2:error] [pid 642360:tid 642494] [client 68.221.186.136:43057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/files.php"] [unique_id "amuBhJSUkh3e5AhEJOBx2wAAAZM"]
[Thu Jul 30 11:53:24.531180 2026] [security2:error] [pid 642360:tid 642590] [client 172.213.208.20:6214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/m.php"] [unique_id "amuBhJSUkh3e5AhEJOBx3gAAAfM"]
[Thu Jul 30 11:53:24.820579 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:24.824951 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:56058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhPxWyxgRnoFKAJ_2vAAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:25.334120 2026] [security2:error] [pid 643573:tid 643835] [client 85.107.103.96:41264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBhfxWyxgRnoFKAJ_2vgAAApE"], referer: http://pkf.jo
[Thu Jul 30 11:53:25.353259 2026] [security2:error] [pid 643573:tid 643768] [client 34.86.95.193:62762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBhfxWyxgRnoFKAJ_2wwAAAk4"]
[Thu Jul 30 11:53:25.441568 2026] [autoindex:error] [pid 643573:tid 643738] [client 129.226.174.80:35156] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:25.546246 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:25.552230 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:56066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhfxWyxgRnoFKAJ_2yAAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:26.279183 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:26.286029 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:56076] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhvxWyxgRnoFKAJ_20QAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:26.357155 2026] [core:notice] [pid 642360:tid 642602] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:26.516501 2026] [security2:error] [pid 643253:tid 643446] [client 34.86.95.193:62128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBhsjqbtjBYzqM1uYmogAAAD4"]
[Thu Jul 30 11:53:26.627737 2026] [security2:error] [pid 642360:tid 642515] [client 172.213.208.20:43749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuBhpSUkh3e5AhEJOBx7QAAAag"]
[Thu Jul 30 11:53:26.996601 2026] [core:notice] [pid 642360:tid 642526] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:27.000777 2026] [security2:error] [pid 642360:tid 642526] [client 103.215.74.26:56078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBhpSUkh3e5AhEJOBx8QAAAbM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:27.271386 2026] [security2:error] [pid 643573:tid 643687] [remote 216.73.216.152:22365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBh_xWyxgRnoFKAJ_26AACg2o"]
[Thu Jul 30 11:53:27.630263 2026] [security2:error] [pid 642360:tid 642512] [client 172.237.109.114:14420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh5SUkh3e5AhEJOBx8gAAAaU"]
[Thu Jul 30 11:53:27.689740 2026] [security2:error] [pid 643573:tid 643786] [client 172.237.109.114:29500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_24gAAAmA"]
[Thu Jul 30 11:53:27.708095 2026] [security2:error] [pid 643573:tid 643735] [client 172.237.109.114:48149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_24QAAAi0"]
[Thu Jul 30 11:53:27.720246 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:27.724352 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:56082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBh_xWyxgRnoFKAJ_27QAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:27.750545 2026] [security2:error] [pid 643573:tid 643795] [client 172.237.109.114:4671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_25AAAAmk"]
[Thu Jul 30 11:53:27.750649 2026] [security2:error] [pid 643573:tid 643748] [client 172.237.109.114:64789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_24wAAAjo"]
[Thu Jul 30 11:53:27.755330 2026] [security2:error] [pid 643573:tid 643726] [client 34.86.95.193:55588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBh_xWyxgRnoFKAJ_26wAAAiQ"]
[Thu Jul 30 11:53:27.771445 2026] [security2:error] [pid 643573:tid 643767] [client 172.237.109.114:27602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBh_xWyxgRnoFKAJ_25QAAAk0"]
[Thu Jul 30 11:53:28.326150 2026] [security2:error] [pid 643573:tid 643698] [remote 57.141.0.44:25524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuBiPxWyxgRnoFKAJ_2_QACJXU"]
[Thu Jul 30 11:53:28.462550 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:28.473899 2026] [security2:error] [pid 643573:tid 643824] [client 103.215.74.26:56086] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBiPxWyxgRnoFKAJ_2_gAAAoY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:28.725930 2026] [security2:error] [pid 643573:tid 643749] [client 68.221.186.136:42525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gecko.php"] [unique_id "amuBiPxWyxgRnoFKAJ_3AQAAAjs"]
[Thu Jul 30 11:53:29.032177 2026] [security2:error] [pid 642360:tid 642603] [client 34.86.95.193:49154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBiJSUkh3e5AhEJOByBQAAAgA"]
[Thu Jul 30 11:53:29.205291 2026] [core:notice] [pid 643573:tid 643807] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:29.209418 2026] [security2:error] [pid 643573:tid 643807] [client 103.215.74.26:56098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "786"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBifxWyxgRnoFKAJ_3BwAAAnU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:29.252342 2026] [security2:error] [pid 643573:tid 643829] [client 172.237.109.114:9417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_28QAAAos"]
[Thu Jul 30 11:53:29.284887 2026] [security2:error] [pid 643573:tid 643732] [client 172.237.109.114:58705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_28AAAAio"]
[Thu Jul 30 11:53:29.287096 2026] [security2:error] [pid 643573:tid 643755] [client 172.237.109.114:59970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_28gAAAkE"]
[Thu Jul 30 11:53:29.308004 2026] [security2:error] [pid 643573:tid 643810] [client 172.237.109.114:38041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_28wAAAng"]
[Thu Jul 30 11:53:29.315361 2026] [security2:error] [pid 643573:tid 643803] [client 68.221.186.136:46274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zwso.php"] [unique_id "amuBifxWyxgRnoFKAJ_3CgAAAnE"]
[Thu Jul 30 11:53:29.317043 2026] [security2:error] [pid 642360:tid 642507] [client 172.237.109.114:13050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx-gAAAaA"]
[Thu Jul 30 11:53:29.320537 2026] [security2:error] [pid 643573:tid 643745] [client 172.237.109.114:63840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_29AAAAjc"]
[Thu Jul 30 11:53:29.367353 2026] [security2:error] [pid 642360:tid 642580] [client 172.237.109.114:28612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx-wAAAek"]
[Thu Jul 30 11:53:29.378968 2026] [security2:error] [pid 642360:tid 642591] [client 172.237.109.114:16876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx_AAAAfQ"]
[Thu Jul 30 11:53:29.385400 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:1658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx-QAAAec"]
[Thu Jul 30 11:53:29.409881 2026] [security2:error] [pid 642360:tid 642594] [client 172.237.109.114:53114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx_gAAAfc"]
[Thu Jul 30 11:53:29.422529 2026] [security2:error] [pid 642360:tid 642545] [client 172.237.109.114:42406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiJSUkh3e5AhEJOBx_QAAAcY"]
[Thu Jul 30 11:53:29.423717 2026] [security2:error] [pid 643573:tid 643724] [client 172.237.109.114:42555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_29gAAAiI"]
[Thu Jul 30 11:53:29.439286 2026] [security2:error] [pid 643573:tid 643725] [client 172.237.109.114:24790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_29QAAAiM"]
[Thu Jul 30 11:53:29.461905 2026] [security2:error] [pid 643573:tid 643785] [client 172.237.109.114:17862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBiPxWyxgRnoFKAJ_2-AAAAl8"]
[Thu Jul 30 11:53:29.490675 2026] [security2:error] [pid 643573:tid 643697] [remote 57.141.0.60:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuBifxWyxgRnoFKAJ_3DQACgXQ"]
[Thu Jul 30 11:53:29.951843 2026] [core:notice] [pid 643573:tid 643779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:29.956936 2026] [security2:error] [pid 643573:tid 643779] [client 103.215.74.26:56100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBifxWyxgRnoFKAJ_3EgAAAlk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:29.988255 2026] [security2:error] [pid 643573:tid 643831] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBifxWyxgRnoFKAJ_3CwACjWI"]
[Thu Jul 30 11:53:30.198798 2026] [security2:error] [pid 643573:tid 643746] [client 34.86.95.193:61304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBivxWyxgRnoFKAJ_3EwAAAjg"]
[Thu Jul 30 11:53:30.463373 2026] [security2:error] [pid 643573:tid 643780] [client 68.221.186.136:46319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/13.php"] [unique_id "amuBivxWyxgRnoFKAJ_3HAAAAlo"]
[Thu Jul 30 11:53:30.480492 2026] [proxy:error] [pid 643573:tid 643801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:30.480586 2026] [proxy_http:error] [pid 643573:tid 643801] [client 34.224.175.62:35920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:30.481423 2026] [proxy:error] [pid 643573:tid 643801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:30.481482 2026] [proxy_http:error] [pid 643573:tid 643801] [client 34.224.175.62:35920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:30.514548 2026] [proxy:error] [pid 643573:tid 643713] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:30.514627 2026] [proxy_http:error] [pid 643573:tid 643713] [client 34.233.129.35:49502] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:30.515470 2026] [proxy:error] [pid 643573:tid 643713] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:30.515528 2026] [proxy_http:error] [pid 643573:tid 643713] [client 34.233.129.35:49502] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:53:30.667846 2026] [security2:error] [pid 643573:tid 643800] [client 172.213.208.20:16296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/classwithtostring.php"] [unique_id "amuBivxWyxgRnoFKAJ_3IQAAAm4"]
[Thu Jul 30 11:53:30.789282 2026] [security2:error] [pid 643573:tid 643692] [remote 57.141.0.12:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/358522518/feed/rss2/"] [unique_id "amuBivxWyxgRnoFKAJ_3IwACf28"]
[Thu Jul 30 11:53:30.890068 2026] [core:error] [pid 643573:tid 643803] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:53:30.890090 2026] [core:error] [pid 643573:tid 643803] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 11:53:30.970664 2026] [core:notice] [pid 643573:tid 643729] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:31.175362 2026] [core:error] [pid 643573:tid 643708] [remote 74.7.175.160:38496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:31.175397 2026] [core:error] [pid 643573:tid 643708] [remote 74.7.175.160:38496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:31.175697 2026] [security2:error] [pid 643573:tid 643708] [remote 74.7.175.160:38496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-78cdf888.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3NgACFn8"]
[Thu Jul 30 11:53:31.408293 2026] [security2:error] [pid 643573:tid 643768] [client 34.86.95.193:54046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3NwAAAk4"]
[Thu Jul 30 11:53:31.543338 2026] [security2:error] [pid 642360:tid 642516] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBipSUkh3e5AhEJOByFgABqUM"]
[Thu Jul 30 11:53:31.633444 2026] [security2:error] [pid 643573:tid 643690] [remote 216.73.216.152:22365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBi_xWyxgRnoFKAJ_3OwACRm0"]
[Thu Jul 30 11:53:31.698249 2026] [security2:error] [pid 642360:tid 642490] [client 43.172.198.249:37618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/05/12/robes-pour-un-mariage-d-ete/"] [unique_id "amuBi5SUkh3e5AhEJOByIwAAAY8"]
[Thu Jul 30 11:53:32.077678 2026] [proxy:error] [pid 643573:tid 643718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:32.077746 2026] [proxy_http:error] [pid 643573:tid 643718] [client 87.236.176.48:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:8080
[Thu Jul 30 11:53:32.078368 2026] [proxy:error] [pid 643573:tid 643718] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:53:32.078413 2026] [proxy_http:error] [pid 643573:tid 643718] [client 87.236.176.48:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:8080
[Thu Jul 30 11:53:32.182455 2026] [security2:error] [pid 643573:tid 643810] [client 68.221.186.136:46282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ava.php"] [unique_id "amuBjPxWyxgRnoFKAJ_3SAAAAng"]
[Thu Jul 30 11:53:32.431232 2026] [security2:error] [pid 643573:tid 643745] [client 172.237.109.114:60273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3JwAAAjc"]
[Thu Jul 30 11:53:32.432648 2026] [security2:error] [pid 643253:tid 643506] [client 172.237.109.114:35593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi8jqbtjBYzqM1uYmqQAAAHo"]
[Thu Jul 30 11:53:32.455041 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:32.464548 2026] [security2:error] [pid 643573:tid 643771] [client 43.173.175.10:59698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/05/12/robes-pour-un-mariage-d-ete/"] [unique_id "amuBjPxWyxgRnoFKAJ_3TAAAAlE"], referer: https://carnetdeshopping.com/index.php/2014/05/12/robes-pour-un-mariage-d-ete/
[Thu Jul 30 11:53:32.493916 2026] [security2:error] [pid 643573:tid 643805] [client 172.237.109.114:55236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3KAAAAnM"]
[Thu Jul 30 11:53:32.541440 2026] [security2:error] [pid 643573:tid 643786] [client 172.237.109.114:10682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3KwAAAmA"]
[Thu Jul 30 11:53:32.571776 2026] [security2:error] [pid 643573:tid 643778] [client 172.237.109.114:6681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3MAAAAlg"]
[Thu Jul 30 11:53:32.573817 2026] [security2:error] [pid 643573:tid 643836] [client 172.237.109.114:40263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3MwAAApI"]
[Thu Jul 30 11:53:32.577511 2026] [security2:error] [pid 643573:tid 643724] [client 172.237.109.114:39179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3LgAAAiI"]
[Thu Jul 30 11:53:32.644408 2026] [security2:error] [pid 642360:tid 642525] [client 34.86.95.193:62305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBjJSUkh3e5AhEJOByKAAAAbI"]
[Thu Jul 30 11:53:32.736474 2026] [security2:error] [pid 643573:tid 643802] [client 85.208.96.207:16962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/17/cicero-descarta-que-progressistas-possa-seguir-caminho-divergente-do-de-joao-e-prega-uniao-em-torno-do-melhor-para-a-paraiba/"] [unique_id "amuBjPxWyxgRnoFKAJ_3TgAAAnA"]
[Thu Jul 30 11:53:32.736588 2026] [security2:error] [pid 643573:tid 643802] [client 85.208.96.207:16962] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/17/cicero-descarta-que-progressistas-possa-seguir-caminho-divergente-do-de-joao-e-prega-uniao-em-torno-do-melhor-para-a-paraiba/"] [unique_id "amuBjPxWyxgRnoFKAJ_3TgAAAnA"]
[Thu Jul 30 11:53:33.206587 2026] [security2:error] [pid 643573:tid 643803] [client 176.241.66.87:24571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBjfxWyxgRnoFKAJ_3UwAAAnE"]
[Thu Jul 30 11:53:33.206710 2026] [security2:error] [pid 643573:tid 643803] [client 176.241.66.87:24571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBjfxWyxgRnoFKAJ_3UwAAAnE"]
[Thu Jul 30 11:53:33.219856 2026] [security2:error] [pid 643573:tid 643795] [client 172.237.109.114:4265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3LQAAAmk"]
[Thu Jul 30 11:53:33.229481 2026] [security2:error] [pid 643573:tid 643765] [client 172.237.109.114:61956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3KgAAAks"]
[Thu Jul 30 11:53:33.229858 2026] [security2:error] [pid 642360:tid 642566] [client 172.237.109.114:53403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi5SUkh3e5AhEJOByHgAAAds"]
[Thu Jul 30 11:53:33.234301 2026] [security2:error] [pid 643573:tid 643785] [client 172.237.109.114:57746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3NQAAAl8"]
[Thu Jul 30 11:53:33.240007 2026] [security2:error] [pid 643573:tid 643740] [client 172.237.109.114:52813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3KQAAAjI"]
[Thu Jul 30 11:53:33.241053 2026] [security2:error] [pid 643573:tid 643726] [client 172.237.109.114:35978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3MQAAAiQ"]
[Thu Jul 30 11:53:33.241342 2026] [security2:error] [pid 643573:tid 643735] [client 172.237.109.114:36723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3LAAAAi0"]
[Thu Jul 30 11:53:33.262269 2026] [security2:error] [pid 643253:tid 643418] [client 172.237.109.114:34663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi8jqbtjBYzqM1uYmqwAAACI"]
[Thu Jul 30 11:53:33.270062 2026] [security2:error] [pid 643573:tid 643767] [client 172.237.109.114:29207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3NAAAAk0"]
[Thu Jul 30 11:53:33.287344 2026] [security2:error] [pid 643253:tid 643454] [client 172.237.109.114:31242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi8jqbtjBYzqM1uYmqgAAAEY"]
[Thu Jul 30 11:53:33.329421 2026] [security2:error] [pid 643573:tid 643725] [client 172.237.109.114:3407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3MgAAAiM"]
[Thu Jul 30 11:53:33.330410 2026] [security2:error] [pid 643573:tid 643748] [client 172.237.109.114:56603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi_xWyxgRnoFKAJ_3LwAAAjo"]
[Thu Jul 30 11:53:33.336208 2026] [security2:error] [pid 642360:tid 642588] [client 172.237.109.114:49470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBi5SUkh3e5AhEJOByHQAAAfE"]
[Thu Jul 30 11:53:33.879802 2026] [security2:error] [pid 642360:tid 642514] [client 34.86.95.193:63342] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBjZSUkh3e5AhEJOByNAAAAac"]
[Thu Jul 30 11:53:33.879841 2026] [security2:error] [pid 642360:tid 642514] [client 34.86.95.193:63342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBjZSUkh3e5AhEJOByNAAAAac"]
[Thu Jul 30 11:53:34.324482 2026] [security2:error] [pid 643573:tid 643728] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBjfxWyxgRnoFKAJ_3WQAAAiY"]
[Thu Jul 30 11:53:34.328878 2026] [security2:error] [pid 643573:tid 643727] [client 172.213.208.20:30425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/gmo.php"] [unique_id "amuBjvxWyxgRnoFKAJ_3XQAAAiU"]
[Thu Jul 30 11:53:35.062423 2026] [security2:error] [pid 643573:tid 643758] [client 34.86.95.193:58138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBjvxWyxgRnoFKAJ_3ZQAAAkQ"]
[Thu Jul 30 11:53:35.681298 2026] [core:notice] [pid 643573:tid 643828] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:35.685306 2026] [security2:error] [pid 643573:tid 643828] [client 103.215.74.26:43814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBj_xWyxgRnoFKAJ_3bQAAAoo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:36.101512 2026] [security2:error] [pid 643573:tid 643820] [client 34.86.95.193:57134] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBkPxWyxgRnoFKAJ_3dgAAAoI"]
[Thu Jul 30 11:53:36.101618 2026] [security2:error] [pid 643573:tid 643820] [client 34.86.95.193:57134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amuBkPxWyxgRnoFKAJ_3dgAAAoI"]
[Thu Jul 30 11:53:36.198537 2026] [security2:error] [pid 643573:tid 643790] [client 68.221.186.136:44031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/main.php"] [unique_id "amuBkPxWyxgRnoFKAJ_3dwAAAmQ"]
[Thu Jul 30 11:53:36.445804 2026] [core:notice] [pid 643573:tid 643822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:36.449774 2026] [security2:error] [pid 643573:tid 643822] [client 103.215.74.26:43824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBkPxWyxgRnoFKAJ_3egAAAoQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:37.034660 2026] [core:notice] [pid 643253:tid 643341] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:37.177336 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:37.181933 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:43834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBkfxWyxgRnoFKAJ_3fwAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:37.262466 2026] [security2:error] [pid 642360:tid 642608] [client 172.213.208.20:16271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuBkZSUkh3e5AhEJOByTQAAAgU"]
[Thu Jul 30 11:53:37.296889 2026] [security2:error] [pid 643573:tid 643623] [remote 216.73.216.152:19096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBkfxWyxgRnoFKAJ_3gAACWSo"]
[Thu Jul 30 11:53:37.901342 2026] [core:notice] [pid 642360:tid 642535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:37.905213 2026] [security2:error] [pid 642360:tid 642535] [client 103.215.74.26:43850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBkZSUkh3e5AhEJOByVQAAAbw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:38.436562 2026] [security2:error] [pid 642360:tid 642528] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBkpSUkh3e5AhEJOByVgABtVw"]
[Thu Jul 30 11:53:38.653999 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:38.658003 2026] [security2:error] [pid 643573:tid 643801] [client 103.215.74.26:43858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBkvxWyxgRnoFKAJ_3hQAAAm8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:39.382227 2026] [core:notice] [pid 643573:tid 643812] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:39.389628 2026] [security2:error] [pid 643573:tid 643812] [client 103.215.74.26:43862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBk_xWyxgRnoFKAJ_3iwAAAno"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:40.107950 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:40.112783 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:43866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBlPxWyxgRnoFKAJ_3kQAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:40.117374 2026] [security2:error] [pid 642360:tid 642590] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBk5SUkh3e5AhEJOByYgAAAfM"]
[Thu Jul 30 11:53:40.226309 2026] [security2:error] [pid 643573:tid 643757] [client 68.221.186.136:44509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-file.php"] [unique_id "amuBlPxWyxgRnoFKAJ_3kgAAAkM"]
[Thu Jul 30 11:53:40.827942 2026] [core:notice] [pid 643573:tid 643725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:40.832763 2026] [security2:error] [pid 643573:tid 643725] [client 103.215.74.26:43870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBlPxWyxgRnoFKAJ_3mgAAAiM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:40.861487 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:40.866337 2026] [core:notice] [pid 643573:tid 643791] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:41.531020 2026] [security2:error] [pid 642360:tid 642549] [client 172.213.208.20:19111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-the.php"] [unique_id "amuBlZSUkh3e5AhEJOBydwAAAco"]
[Thu Jul 30 11:53:41.558659 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:41.562792 2026] [security2:error] [pid 643573:tid 643761] [client 103.215.74.26:43880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBlfxWyxgRnoFKAJ_3ogAAAkc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:41.639999 2026] [security2:error] [pid 643573:tid 643638] [remote 216.73.216.152:19096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuBlfxWyxgRnoFKAJ_3pQAChjk"]
[Thu Jul 30 11:53:42.290704 2026] [core:notice] [pid 643573:tid 643777] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:42.296151 2026] [security2:error] [pid 643573:tid 643777] [client 103.215.74.26:43890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBlvxWyxgRnoFKAJ_3rQAAAlc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:42.463300 2026] [security2:error] [pid 643573:tid 643796] [client 68.221.186.136:45700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-signin.php"] [unique_id "amuBlvxWyxgRnoFKAJ_3rgAAAmo"]
[Thu Jul 30 11:53:43.012714 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:43.017106 2026] [security2:error] [pid 642360:tid 642548] [client 103.215.74.26:18372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBl5SUkh3e5AhEJOBygwAAAck"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:43.750989 2026] [core:notice] [pid 643573:tid 643783] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:43.755384 2026] [security2:error] [pid 643573:tid 643783] [client 103.215.74.26:18376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBl_xWyxgRnoFKAJ_3uwAAAl0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:43.879477 2026] [security2:error] [pid 643573:tid 643756] [client 176.241.66.87:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBl_xWyxgRnoFKAJ_3vQAAAkI"]
[Thu Jul 30 11:53:43.879631 2026] [security2:error] [pid 643573:tid 643756] [client 176.241.66.87:59904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBl_xWyxgRnoFKAJ_3vQAAAkI"]
[Thu Jul 30 11:53:43.935048 2026] [autoindex:error] [pid 643573:tid 643738] [client 66.249.74.34:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:53:44.485269 2026] [core:notice] [pid 643573:tid 643757] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:44.489455 2026] [security2:error] [pid 643573:tid 643757] [client 103.215.74.26:18380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBmPxWyxgRnoFKAJ_3xgAAAkM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:44.995405 2026] [security2:error] [pid 643573:tid 643674] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "shiftofy.it.com"] [uri "/"] [unique_id "amuBmPxWyxgRnoFKAJ_3zQACNl0"]
[Thu Jul 30 11:53:45.211117 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:45.215954 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:18394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBmfxWyxgRnoFKAJ_30AAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:45.412191 2026] [security2:error] [pid 642360:tid 642569] [client 68.221.186.136:45183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/simi.php"] [unique_id "amuBmZSUkh3e5AhEJOBymwAAAd4"]
[Thu Jul 30 11:53:45.933218 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:45.937306 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:18408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBmfxWyxgRnoFKAJ_31AAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:45.974299 2026] [security2:error] [pid 643253:tid 643436] [client 68.221.186.136:43972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-conf.php"] [unique_id "amuBmcjqbtjBYzqM1uYmtwAAADQ"]
[Thu Jul 30 11:53:46.337734 2026] [security2:error] [pid 643573:tid 643825] [client 172.213.208.20:52357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/404.php"] [unique_id "amuBmvxWyxgRnoFKAJ_31QAAAoc"]
[Thu Jul 30 11:53:46.658394 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:46.899236 2026] [security2:error] [pid 643573:tid 643745] [client 68.221.186.136:42527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuBmvxWyxgRnoFKAJ_32gAAAjc"]
[Thu Jul 30 11:53:47.190372 2026] [security2:error] [pid 643573:tid 643829] [client 172.213.208.20:52400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/init.php"] [unique_id "amuBm_xWyxgRnoFKAJ_33QAAAos"]
[Thu Jul 30 11:53:47.521327 2026] [security2:error] [pid 643573:tid 643723] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "shiftofy.it.com"] [uri "/"] [unique_id "amuBm_xWyxgRnoFKAJ_34AAAAiE"]
[Thu Jul 30 11:53:47.740836 2026] [security2:error] [pid 643573:tid 643741] [client 209.126.2.173:53137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-mevius.com"] [uri "/"] [unique_id "amuBm_xWyxgRnoFKAJ_35AAAAjM"]
[Thu Jul 30 11:53:48.036998 2026] [security2:error] [pid 643573:tid 643837] [client 172.213.208.20:25040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/file5.php"] [unique_id "amuBnPxWyxgRnoFKAJ_35gAAApM"]
[Thu Jul 30 11:53:48.713872 2026] [security2:error] [pid 642360:tid 642510] [client 172.237.109.114:5627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnJSUkh3e5AhEJOByuAAAAaM"]
[Thu Jul 30 11:53:48.727008 2026] [security2:error] [pid 642360:tid 642490] [client 172.237.109.114:55962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnJSUkh3e5AhEJOBytQAAAY8"]
[Thu Jul 30 11:53:48.733237 2026] [security2:error] [pid 642360:tid 642562] [client 172.237.109.114:58264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnJSUkh3e5AhEJOBytgAAAdc"]
[Thu Jul 30 11:53:48.763252 2026] [security2:error] [pid 642360:tid 642590] [client 172.237.109.114:10513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnJSUkh3e5AhEJOBytwAAAfM"]
[Thu Jul 30 11:53:48.773044 2026] [security2:error] [pid 643573:tid 643809] [client 172.237.109.114:57220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuBnPxWyxgRnoFKAJ_35wAAAnc"]
[Thu Jul 30 11:53:49.081517 2026] [security2:error] [pid 643573:tid 643743] [client 172.213.208.20:26047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuBnfxWyxgRnoFKAJ_37QAAAjU"]
[Thu Jul 30 11:53:49.652358 2026] [security2:error] [pid 643573:tid 643773] [client 68.221.186.136:45166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/bala.php"] [unique_id "amuBnfxWyxgRnoFKAJ_38AAAAlM"]
[Thu Jul 30 11:53:49.804173 2026] [security2:error] [pid 643573:tid 643759] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kinyeraagro.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBnfxWyxgRnoFKAJ_38QAAAkU"]
[Thu Jul 30 11:53:49.809851 2026] [security2:error] [pid 642360:tid 642576] [client 209.126.2.173:51002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-mevius.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBnZSUkh3e5AhEJOByxAAAAeU"]
[Thu Jul 30 11:53:50.913818 2026] [security2:error] [pid 643573:tid 643754] [client 68.221.186.136:42548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/bk.php"] [unique_id "amuBnvxWyxgRnoFKAJ_3-QAAAkA"]
[Thu Jul 30 11:53:51.231268 2026] [security2:error] [pid 642360:tid 642557] [client 209.126.2.173:53245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-mevius.com"] [uri "/media/system/js/core.js"] [unique_id "amuBn5SUkh3e5AhEJOBy1AAAAdI"]
[Thu Jul 30 11:53:51.520799 2026] [security2:error] [pid 642360:tid 642592] [client 68.221.186.136:45552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ahax.php"] [unique_id "amuBn5SUkh3e5AhEJOBy3gAAAfU"]
[Thu Jul 30 11:53:51.661912 2026] [core:notice] [pid 642360:tid 642586] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:51.666488 2026] [security2:error] [pid 642360:tid 642586] [client 103.215.74.26:18412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBn5SUkh3e5AhEJOBy3wAAAe8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:52.135074 2026] [security2:error] [pid 643573:tid 643744] [client 74.7.230.23:33326] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.qse.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuBoPxWyxgRnoFKAJ_4DgAAAjY"]
[Thu Jul 30 11:53:52.383703 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:52.387792 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:18424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBoPxWyxgRnoFKAJ_4EAAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:52.612693 2026] [security2:error] [pid 643573:tid 643731] [client 95.86.50.135:29725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.50.86.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuBoPxWyxgRnoFKAJ_4DwAAAik"]
[Thu Jul 30 11:53:52.612899 2026] [security2:error] [pid 643573:tid 643731] [client 95.86.50.135:29725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuBoPxWyxgRnoFKAJ_4DwAAAik"]
[Thu Jul 30 11:53:53.000798 2026] [core:error] [pid 643253:tid 643463] [client 74.7.241.141:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:53.000818 2026] [core:error] [pid 643253:tid 643463] [client 74.7.241.141:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:53:53.000910 2026] [security2:error] [pid 643253:tid 643463] [client 74.7.241.141:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.akth.com.pk"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuBoMjqbtjBYzqM1uYmwgAAAE8"]
[Thu Jul 30 11:53:53.001468 2026] [security2:error] [pid 643573:tid 643752] [client 74.7.241.141:41712] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.akth.com.pk"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuBoPxWyxgRnoFKAJ_4EwACPks"]
[Thu Jul 30 11:53:53.110974 2026] [core:notice] [pid 643253:tid 643494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:53.115406 2026] [security2:error] [pid 643253:tid 643494] [client 103.215.74.26:49110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBocjqbtjBYzqM1uYmxQAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:53.813617 2026] [core:notice] [pid 643573:tid 643825] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:53.824730 2026] [core:notice] [pid 643573:tid 643735] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:53.830754 2026] [security2:error] [pid 643573:tid 643735] [client 103.215.74.26:49116] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBofxWyxgRnoFKAJ_4GAAAAi0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:53.943753 2026] [core:notice] [pid 643253:tid 643344] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:53.949226 2026] [security2:error] [pid 643253:tid 643445] [client 47.128.96.122:36396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/2656"] [unique_id "amuBocjqbtjBYzqM1uYmyAAAPVk"]
[Thu Jul 30 11:53:54.188691 2026] [security2:error] [pid 643253:tid 643392] [client 185.191.171.10:40474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cal-sync.co"] [uri "/robots.txt"] [unique_id "amuBosjqbtjBYzqM1uYmyQAAAAg"]
[Thu Jul 30 11:53:54.188805 2026] [security2:error] [pid 643253:tid 643392] [client 185.191.171.10:40474] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cal-sync.co"] [uri "/robots.txt"] [unique_id "amuBosjqbtjBYzqM1uYmyQAAAAg"]
[Thu Jul 30 11:53:54.222429 2026] [core:notice] [pid 642360:tid 642426] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:54.340147 2026] [core:notice] [pid 642360:tid 642402] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:54.340203 2026] [core:notice] [pid 642360:tid 642396] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:54.549618 2026] [core:notice] [pid 642360:tid 642490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:54.556033 2026] [security2:error] [pid 642360:tid 642490] [client 103.215.74.26:49122] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBopSUkh3e5AhEJOBzAAAAAY8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:54.558042 2026] [security2:error] [pid 643573:tid 643789] [client 176.241.66.87:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBovxWyxgRnoFKAJ_4HgAAAmM"]
[Thu Jul 30 11:53:54.558159 2026] [security2:error] [pid 643573:tid 643789] [client 176.241.66.87:60464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBovxWyxgRnoFKAJ_4HgAAAmM"]
[Thu Jul 30 11:53:55.092083 2026] [security2:error] [pid 642360:tid 642567] [client 85.208.96.210:54148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cal-sync.co"] [uri "/"] [unique_id "amuBo5SUkh3e5AhEJOBzDAAAAdw"]
[Thu Jul 30 11:53:55.092186 2026] [security2:error] [pid 642360:tid 642567] [client 85.208.96.210:54148] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cal-sync.co"] [uri "/"] [unique_id "amuBo5SUkh3e5AhEJOBzDAAAAdw"]
[Thu Jul 30 11:53:55.266629 2026] [security2:error] [pid 643573:tid 643794] [client 172.213.208.20:19083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/shell.php"] [unique_id "amuBo_xWyxgRnoFKAJ_4IwAAAmg"]
[Thu Jul 30 11:53:55.301614 2026] [core:notice] [pid 643573:tid 643759] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:55.305788 2026] [security2:error] [pid 643573:tid 643759] [client 103.215.74.26:49126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBo_xWyxgRnoFKAJ_4JAAAAkU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:53:55.517434 2026] [core:notice] [pid 643573:tid 643766] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:53:56.675311 2026] [security2:error] [pid 643573:tid 643813] [client 172.116.43.68:34369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBpPxWyxgRnoFKAJ_4LQAAAns"], referer: http://pkf.jo
[Thu Jul 30 11:53:56.729041 2026] [security2:error] [pid 642360:tid 642523] [client 14.171.253.47:58720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBpJSUkh3e5AhEJOBzFgAAAbA"], referer: http://pkf.jo
[Thu Jul 30 11:53:56.786325 2026] [security2:error] [pid 642360:tid 642609] [client 172.213.208.20:28798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/f35.php"] [unique_id "amuBpJSUkh3e5AhEJOBzIQAAAgY"]
[Thu Jul 30 11:53:57.494727 2026] [security2:error] [pid 643573:tid 643741] [client 172.213.208.20:19100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/new.php"] [unique_id "amuBpfxWyxgRnoFKAJ_4NAAAAjM"]
[Thu Jul 30 11:53:58.264765 2026] [security2:error] [pid 643573:tid 643824] [client 172.213.208.20:37203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/adminfuns.php"] [unique_id "amuBpvxWyxgRnoFKAJ_4OgAAAoY"]
[Thu Jul 30 11:53:58.339004 2026] [security2:error] [pid 642360:tid 642569] [client 189.203.39.144:19014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBppSUkh3e5AhEJOBzKgAAAd4"], referer: http://pkf.jo
[Thu Jul 30 11:54:00.747297 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:01.027093 2026] [core:notice] [pid 642360:tid 642602] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:01.031134 2026] [security2:error] [pid 642360:tid 642602] [client 103.215.74.26:49134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBqZSUkh3e5AhEJOBzSQAAAf8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:01.253090 2026] [security2:error] [pid 642360:tid 642495] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBqJSUkh3e5AhEJOBzQgAAAZQ"]
[Thu Jul 30 11:54:01.769298 2026] [core:notice] [pid 643573:tid 643744] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:01.776201 2026] [security2:error] [pid 643573:tid 643744] [client 103.215.74.26:49146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBqfxWyxgRnoFKAJ_4WwAAAjY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:01.795177 2026] [autoindex:error] [pid 642360:tid 642615] [client 43.131.253.14:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_d836eabf/wp-content/uploads/2026/07/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:54:01.816207 2026] [security2:error] [pid 643573:tid 643767] [client 85.208.96.195:47280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuBqfxWyxgRnoFKAJ_4XQAAAk0"]
[Thu Jul 30 11:54:01.816321 2026] [security2:error] [pid 643573:tid 643767] [client 85.208.96.195:47280] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuBqfxWyxgRnoFKAJ_4XQAAAk0"]
[Thu Jul 30 11:54:02.240741 2026] [security2:error] [pid 643573:tid 643751] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBqfxWyxgRnoFKAJ_4WAAAAj0"]
[Thu Jul 30 11:54:02.493553 2026] [core:notice] [pid 643573:tid 643824] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:02.497507 2026] [security2:error] [pid 643573:tid 643824] [client 103.215.74.26:49158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "778"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBqvxWyxgRnoFKAJ_4ZQAAAoY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:02.926411 2026] [security2:error] [pid 643253:tid 643412] [client 185.191.171.15:15688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carnetdeshopping.com"] [uri "/index.php/about/"] [unique_id "amuBqsjqbtjBYzqM1uYm1gAAABw"]
[Thu Jul 30 11:54:02.926537 2026] [security2:error] [pid 643253:tid 643412] [client 185.191.171.15:15688] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "carnetdeshopping.com"] [uri "/index.php/about/"] [unique_id "amuBqsjqbtjBYzqM1uYm1gAAABw"]
[Thu Jul 30 11:54:03.252047 2026] [core:notice] [pid 643573:tid 643804] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:03.256023 2026] [security2:error] [pid 643573:tid 643804] [client 103.215.74.26:11580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBq_xWyxgRnoFKAJ_4bgAAAnI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:03.543845 2026] [security2:error] [pid 643573:tid 643802] [client 185.191.171.1:10666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cal-sync.co"] [uri "/sitemap.xml"] [unique_id "amuBq_xWyxgRnoFKAJ_4dAAAAnA"]
[Thu Jul 30 11:54:03.543943 2026] [security2:error] [pid 643573:tid 643802] [client 185.191.171.1:10666] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cal-sync.co"] [uri "/sitemap.xml"] [unique_id "amuBq_xWyxgRnoFKAJ_4dAAAAnA"]
[Thu Jul 30 11:54:03.992207 2026] [core:notice] [pid 643573:tid 643774] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:03.996449 2026] [security2:error] [pid 643573:tid 643774] [client 103.215.74.26:11582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBq_xWyxgRnoFKAJ_4dwAAAlQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:04.127701 2026] [security2:error] [pid 642360:tid 642579] [client 34.53.152.12:54882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vzz.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuBrJSUkh3e5AhEJOBzYgAAAeg"]
[Thu Jul 30 11:54:04.737043 2026] [core:notice] [pid 642360:tid 642500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:04.740947 2026] [security2:error] [pid 642360:tid 642500] [client 103.215.74.26:11598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBrJSUkh3e5AhEJOBzZQAAAZk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:05.092332 2026] [security2:error] [pid 643573:tid 643779] [client 172.213.208.20:37200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/fm.php"] [unique_id "amuBrfxWyxgRnoFKAJ_4hAAAAlk"]
[Thu Jul 30 11:54:05.118364 2026] [security2:error] [pid 642360:tid 642591] [client 176.241.66.87:61022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBrZSUkh3e5AhEJOBzaQAAAfQ"]
[Thu Jul 30 11:54:05.118484 2026] [security2:error] [pid 642360:tid 642591] [client 176.241.66.87:61022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBrZSUkh3e5AhEJOBzaQAAAfQ"]
[Thu Jul 30 11:54:05.274465 2026] [core:notice] [pid 642360:tid 642447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:05.485505 2026] [core:notice] [pid 643573:tid 643717] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:05.488251 2026] [proxy:error] [pid 643573:tid 643788] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:54:05.488354 2026] [proxy_http:error] [pid 643573:tid 643788] [client 74.7.241.155:59574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:54:05.489023 2026] [proxy:error] [pid 643573:tid 643788] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:54:05.489072 2026] [proxy_http:error] [pid 643573:tid 643788] [client 74.7.241.155:59574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:54:05.489203 2026] [security2:error] [pid 643573:tid 643788] [client 74.7.241.155:59574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.dqy.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuBrfxWyxgRnoFKAJ_4iAAAAmI"]
[Thu Jul 30 11:54:05.489437 2026] [security2:error] [pid 643573:tid 643717] [client 103.215.74.26:11612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBrfxWyxgRnoFKAJ_4hwAAAhs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:06.218459 2026] [core:notice] [pid 642360:tid 642517] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:06.222442 2026] [security2:error] [pid 642360:tid 642517] [client 103.215.74.26:11620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBrpSUkh3e5AhEJOBzcwAAAao"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:06.963376 2026] [core:notice] [pid 642360:tid 642574] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:06.968075 2026] [security2:error] [pid 642360:tid 642574] [client 103.215.74.26:11630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBrpSUkh3e5AhEJOBzfQAAAeM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:07.268259 2026] [security2:error] [pid 643573:tid 643712] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuBrvxWyxgRnoFKAJ_4lwAAAhY"]
[Thu Jul 30 11:54:07.284241 2026] [core:notice] [pid 642360:tid 642509] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:07.616531 2026] [security2:error] [pid 643573:tid 643719] [client 34.53.152.12:58461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vzz.udi.temporary.site"] [uri "/index.php"] [unique_id "amuBr_xWyxgRnoFKAJ_4pgAAAh0"]
[Thu Jul 30 11:54:07.697634 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:07.701742 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:11640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBr_xWyxgRnoFKAJ_4qAAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:08.111548 2026] [security2:error] [pid 643573:tid 643734] [client 34.53.152.12:58461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBr_xWyxgRnoFKAJ_4qwAAAiw"]
[Thu Jul 30 11:54:08.139336 2026] [security2:error] [pid 643573:tid 643722] [client 66.249.66.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lalibanista.com"] [uri "/index.php"] [unique_id "amuBrvxWyxgRnoFKAJ_4ngACIFY"]
[Thu Jul 30 11:54:08.259094 2026] [security2:error] [pid 643573:tid 643727] [client 172.213.208.20:45951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/file.php"] [unique_id "amuBsPxWyxgRnoFKAJ_4sAAAAiU"]
[Thu Jul 30 11:54:08.423923 2026] [core:notice] [pid 643573:tid 643788] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:08.427957 2026] [security2:error] [pid 643573:tid 643788] [client 103.215.74.26:11644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBsPxWyxgRnoFKAJ_4sQAAAmI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:09.011922 2026] [security2:error] [pid 643573:tid 643835] [client 34.53.152.12:62699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBsPxWyxgRnoFKAJ_4tAAAApE"]
[Thu Jul 30 11:54:09.158711 2026] [core:notice] [pid 642360:tid 642546] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:09.163078 2026] [security2:error] [pid 642360:tid 642546] [client 103.215.74.26:11654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBsZSUkh3e5AhEJOBzlwAAAcc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:09.740260 2026] [security2:error] [pid 642360:tid 642530] [client 34.53.152.12:51772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBsZSUkh3e5AhEJOBzmQAAAbc"]
[Thu Jul 30 11:54:09.781641 2026] [security2:error] [pid 642360:tid 642456] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBsZSUkh3e5AhEJOBzngABp18"]
[Thu Jul 30 11:54:09.781823 2026] [security2:error] [pid 642360:tid 642514] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuBsZSUkh3e5AhEJOBzngABp18"]
[Thu Jul 30 11:54:09.903343 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:09.907387 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:11664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBsfxWyxgRnoFKAJ_4vAAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:10.445222 2026] [security2:error] [pid 643253:tid 643355] [remote 157.55.39.195:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/blogs/likejapan%E6%9C%83%E5%93%A1%E5%84%AA%E6%83%A0%E5%90%88%E9%9B%86-%E9%81%8A%E6%97%A5%E5%84%AA%E6%83%A0%E5%8A%B5/article.php"] [unique_id "amuBssjqbtjBYzqM1uYm3AAAFmQ"]
[Thu Jul 30 11:54:10.521880 2026] [security2:error] [pid 642360:tid 642565] [client 34.53.152.12:59165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBspSUkh3e5AhEJOBzoQAAAdo"]
[Thu Jul 30 11:54:10.621816 2026] [core:notice] [pid 643253:tid 643424] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:10.625995 2026] [security2:error] [pid 643253:tid 643424] [client 103.215.74.26:11670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBssjqbtjBYzqM1uYm3QAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:11.227661 2026] [security2:error] [pid 643573:tid 643782] [client 34.53.152.12:60043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBs_xWyxgRnoFKAJ_4xQAAAlw"]
[Thu Jul 30 11:54:11.359838 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:11.364756 2026] [security2:error] [pid 643573:tid 643837] [client 103.215.74.26:11676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBs_xWyxgRnoFKAJ_4zQAAApM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:11.772087 2026] [security2:error] [pid 643573:tid 643717] [client 62.102.148.185:57250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuBs_xWyxgRnoFKAJ_41QAAAhs"]
[Thu Jul 30 11:54:11.772173 2026] [security2:error] [pid 643573:tid 643717] [client 62.102.148.185:57250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuBs_xWyxgRnoFKAJ_41QAAAhs"]
[Thu Jul 30 11:54:11.787213 2026] [security2:error] [pid 643573:tid 643683] [remote 57.141.0.31:25082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuBs_xWyxgRnoFKAJ_41gACUWY"]
[Thu Jul 30 11:54:12.097407 2026] [core:notice] [pid 643573:tid 643758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:12.101920 2026] [security2:error] [pid 643573:tid 643758] [client 103.215.74.26:11686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtPxWyxgRnoFKAJ_42gAAAkQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:12.144891 2026] [security2:error] [pid 643573:tid 643710] [client 34.53.152.12:59087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBs_xWyxgRnoFKAJ_42QAAAhQ"]
[Thu Jul 30 11:54:12.842057 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:12.846783 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:11696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtPxWyxgRnoFKAJ_44AAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:12.958249 2026] [security2:error] [pid 642360:tid 642499] [client 34.53.152.12:58899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBtJSUkh3e5AhEJOBzsgAAAZg"]
[Thu Jul 30 11:54:13.571772 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:13.576214 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:46668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtfxWyxgRnoFKAJ_45wAAAow"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:13.688850 2026] [security2:error] [pid 643573:tid 643781] [client 34.53.152.12:61718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBtfxWyxgRnoFKAJ_45QAAAls"]
[Thu Jul 30 11:54:13.762604 2026] [security2:error] [pid 643573:tid 643752] [client 52.28.162.93:62498] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuBtfxWyxgRnoFKAJ_46AAAAj4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:54:14.164409 2026] [core:notice] [pid 643573:tid 643799] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:14.168794 2026] [security2:error] [pid 643573:tid 643799] [client 52.28.162.93:62512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtvxWyxgRnoFKAJ_47gAAAm0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:54:14.289380 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:14.296762 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:46670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBtvxWyxgRnoFKAJ_48AAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:14.331160 2026] [security2:error] [pid 642360:tid 642570] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBtZSUkh3e5AhEJOBzvAAB3xs"]
[Thu Jul 30 11:54:14.400628 2026] [security2:error] [pid 643573:tid 643796] [client 34.53.152.12:59547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBtvxWyxgRnoFKAJ_47wAAAmo"]
[Thu Jul 30 11:54:14.606725 2026] [security2:error] [pid 643573:tid 643727] [client 52.28.162.93:62518] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuBtvxWyxgRnoFKAJ_48gAAAiU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:54:15.039675 2026] [core:notice] [pid 643573:tid 643821] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:15.044103 2026] [security2:error] [pid 643573:tid 643821] [client 103.215.74.26:46686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBt_xWyxgRnoFKAJ_48wAAAoM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:15.135120 2026] [security2:error] [pid 642360:tid 642611] [client 34.53.152.12:57114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBtpSUkh3e5AhEJOBzyQAAAgg"]
[Thu Jul 30 11:54:15.774790 2026] [core:notice] [pid 643573:tid 643773] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:15.779108 2026] [security2:error] [pid 643573:tid 643773] [client 103.215.74.26:46698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBt_xWyxgRnoFKAJ_4-wAAAlM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:15.872065 2026] [security2:error] [pid 643573:tid 643835] [client 176.241.66.87:27021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBt_xWyxgRnoFKAJ_4_QAAApE"]
[Thu Jul 30 11:54:15.872196 2026] [security2:error] [pid 643573:tid 643835] [client 176.241.66.87:27021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBt_xWyxgRnoFKAJ_4_QAAApE"]
[Thu Jul 30 11:54:15.970621 2026] [core:notice] [pid 643573:tid 643828] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:16.047207 2026] [security2:error] [pid 643573:tid 643724] [client 34.53.152.12:58187] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBt_xWyxgRnoFKAJ_4_AAAAiI"]
[Thu Jul 30 11:54:16.047244 2026] [security2:error] [pid 643573:tid 643724] [client 34.53.152.12:58187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBt_xWyxgRnoFKAJ_4_AAAAiI"]
[Thu Jul 30 11:54:16.193133 2026] [security2:error] [pid 643573:tid 643808] [client 74.7.175.150:38764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.pwy.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuBuPxWyxgRnoFKAJ_5AwAAAnY"]
[Thu Jul 30 11:54:16.515255 2026] [core:notice] [pid 643573:tid 643814] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:16.519663 2026] [security2:error] [pid 643573:tid 643814] [client 103.215.74.26:46714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBuPxWyxgRnoFKAJ_5BgAAAnw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:16.561260 2026] [security2:error] [pid 642360:tid 642562] [client 34.53.152.12:52830] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBuJSUkh3e5AhEJOBz1QAAAdc"]
[Thu Jul 30 11:54:16.561377 2026] [security2:error] [pid 642360:tid 642562] [client 34.53.152.12:52830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vzz.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuBuJSUkh3e5AhEJOBz1QAAAdc"]
[Thu Jul 30 11:54:17.244231 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:17.248755 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:46726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBufxWyxgRnoFKAJ_5CgAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:17.461851 2026] [security2:error] [pid 642360:tid 642535] [client 74.7.175.177:54296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-87175f7b.bkv.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuBtpSUkh3e5AhEJOBzxAABvBk"]
[Thu Jul 30 11:54:17.974796 2026] [core:notice] [pid 643573:tid 643746] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:17.978972 2026] [security2:error] [pid 643573:tid 643746] [client 103.215.74.26:46730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBufxWyxgRnoFKAJ_5DwAAAjg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:18.701887 2026] [core:notice] [pid 643573:tid 643816] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:18.705885 2026] [security2:error] [pid 643573:tid 643816] [client 103.215.74.26:46746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBuvxWyxgRnoFKAJ_5FAAAAn4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:18.997052 2026] [security2:error] [pid 642360:tid 642565] [client 178.20.47.39:64659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.47.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/email-now.php"] [unique_id "amuBupSUkh3e5AhEJOBz7AAAAdo"], referer: http://arabiandubaisafari.com/contact.html
[Thu Jul 30 11:54:19.169477 2026] [core:error] [pid 643573:tid 643744] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.169498 2026] [core:error] [pid 643573:tid 643744] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.174879 2026] [core:error] [pid 643573:tid 643754] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.174895 2026] [core:error] [pid 643573:tid 643754] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.185640 2026] [core:error] [pid 642360:tid 642603] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.185657 2026] [core:error] [pid 642360:tid 642603] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.186076 2026] [core:error] [pid 643573:tid 643750] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.186090 2026] [core:error] [pid 643573:tid 643750] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.187615 2026] [core:error] [pid 642360:tid 642612] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.187630 2026] [core:error] [pid 642360:tid 642612] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:19.277626 2026] [core:notice] [pid 642360:tid 642372] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:19.417888 2026] [core:notice] [pid 643573:tid 643833] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:19.422675 2026] [security2:error] [pid 643573:tid 643833] [client 103.215.74.26:46756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBu_xWyxgRnoFKAJ_5MgAAAo8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:20.145768 2026] [core:notice] [pid 643573:tid 643760] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:20.150065 2026] [security2:error] [pid 643573:tid 643760] [client 103.215.74.26:46768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBvPxWyxgRnoFKAJ_5OgAAAkY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:20.825574 2026] [security2:error] [pid 643573:tid 643836] [client 198.54.128.138:59462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuBvPxWyxgRnoFKAJ_5PgAAApI"]
[Thu Jul 30 11:54:20.825683 2026] [security2:error] [pid 643573:tid 643836] [client 198.54.128.138:59462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuBvPxWyxgRnoFKAJ_5PgAAApI"]
[Thu Jul 30 11:54:20.851765 2026] [security2:error] [pid 643573:tid 643746] [client 172.213.208.20:45927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/bolt.php"] [unique_id "amuBvPxWyxgRnoFKAJ_5PwAAAjg"]
[Thu Jul 30 11:54:20.868333 2026] [core:notice] [pid 642360:tid 642540] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:20.874563 2026] [security2:error] [pid 642360:tid 642540] [client 103.215.74.26:46778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBvJSUkh3e5AhEJOB0AgAAAcE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:21.598356 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:21.605240 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:46786] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBvfxWyxgRnoFKAJ_5RgAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:21.820691 2026] [security2:error] [pid 643573:tid 643794] [client 172.213.208.20:27989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/3.php"] [unique_id "amuBvfxWyxgRnoFKAJ_5SAAAAmg"]
[Thu Jul 30 11:54:21.878418 2026] [security2:error] [pid 643573:tid 643622] [remote 57.141.0.30:33146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JSTE/announcement"] [unique_id "amuBvfxWyxgRnoFKAJ_5TAACISk"]
[Thu Jul 30 11:54:22.339482 2026] [core:notice] [pid 642360:tid 642611] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:22.343327 2026] [security2:error] [pid 642360:tid 642611] [client 103.215.74.26:46794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBvpSUkh3e5AhEJOB0EAAAAgg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:22.673509 2026] [security2:error] [pid 643573:tid 643754] [client 66.249.73.100:47155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBvvxWyxgRnoFKAJ_5UgAAAkA"]
[Thu Jul 30 11:54:23.068654 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:23.072513 2026] [security2:error] [pid 642360:tid 642494] [client 103.215.74.26:28442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBv5SUkh3e5AhEJOB0FwAAAZM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:23.193375 2026] [security2:error] [pid 642360:tid 642552] [client 74.7.244.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.fud.udi.temporary.site"] [uri "/index.php"] [unique_id "amuBu5SUkh3e5AhEJOBz7gAAAc0"]
[Thu Jul 30 11:54:23.194461 2026] [security2:error] [pid 643573:tid 643726] [client 74.7.244.63:47406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.fud.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuBu_xWyxgRnoFKAJ_5HAACJGk"]
[Thu Jul 30 11:54:23.248060 2026] [security2:error] [pid 643573:tid 643715] [client 94.154.43.184:36768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shop-mevius.com"] [uri "/.env"] [unique_id "amuBv_xWyxgRnoFKAJ_5XwAAAhk"]
[Thu Jul 30 11:54:23.819056 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:23.825558 2026] [security2:error] [pid 643573:tid 643809] [client 103.215.74.26:28444] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBv_xWyxgRnoFKAJ_5YwAAAnc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:23.846689 2026] [security2:error] [pid 642360:tid 642616] [client 66.249.73.96:37592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuBv5SUkh3e5AhEJOB0GwAAAg0"]
[Thu Jul 30 11:54:23.987927 2026] [security2:error] [pid 643573:tid 643804] [client 74.7.175.190:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fyi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuBvvxWyxgRnoFKAJ_5VwAAAnI"]
[Thu Jul 30 11:54:23.988850 2026] [security2:error] [pid 642360:tid 642604] [client 74.7.175.190:54454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fyi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuBvpSUkh3e5AhEJOB0FQACAUU"]
[Thu Jul 30 11:54:24.391445 2026] [security2:error] [pid 643573:tid 643606] [remote 47.128.27.88:22538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/"] [unique_id "amuBwPxWyxgRnoFKAJ_5awACRBk"]
[Thu Jul 30 11:54:24.407269 2026] [security2:error] [pid 642360:tid 642506] [client 172.213.208.20:45911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/222.php"] [unique_id "amuBwJSUkh3e5AhEJOB0JQAAAZ8"]
[Thu Jul 30 11:54:24.556373 2026] [core:notice] [pid 642360:tid 642535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:24.560192 2026] [security2:error] [pid 642360:tid 642535] [client 103.215.74.26:28454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBwJSUkh3e5AhEJOB0JgAAAbw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:24.625758 2026] [core:notice] [pid 643573:tid 643693] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:24.940296 2026] [security2:error] [pid 643573:tid 643700] [remote 74.7.241.60:58672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/login.php"] [unique_id "amuBwPxWyxgRnoFKAJ_5dAACbnc"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:54:25.297837 2026] [core:notice] [pid 643573:tid 643808] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:25.301858 2026] [security2:error] [pid 643573:tid 643808] [client 103.215.74.26:28458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBwfxWyxgRnoFKAJ_5egAAAnY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:25.680873 2026] [security2:error] [pid 642360:tid 642515] [client 74.7.241.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fdd.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuBwJSUkh3e5AhEJOB0IQAAAag"]
[Thu Jul 30 11:54:25.681901 2026] [security2:error] [pid 643573:tid 643761] [client 74.7.241.130:50492] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fdd.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuBwPxWyxgRnoFKAJ_5aQACR24"]
[Thu Jul 30 11:54:26.037212 2026] [security2:error] [pid 643573:tid 643696] [remote 40.77.167.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/209/204/406"] [unique_id "amuBwvxWyxgRnoFKAJ_5gAACXHM"]
[Thu Jul 30 11:54:26.376877 2026] [security2:error] [pid 643573:tid 643828] [client 176.241.66.87:27661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBwvxWyxgRnoFKAJ_5hAAAAoo"]
[Thu Jul 30 11:54:26.377034 2026] [security2:error] [pid 643573:tid 643828] [client 176.241.66.87:27661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBwvxWyxgRnoFKAJ_5hAAAAoo"]
[Thu Jul 30 11:54:26.624825 2026] [security2:error] [pid 643573:tid 643731] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBwvxWyxgRnoFKAJ_5fwACKQ4"]
[Thu Jul 30 11:54:27.682784 2026] [security2:error] [pid 643573:tid 643807] [client 74.7.230.57:37088] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-300f3810.ahk.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuBw_xWyxgRnoFKAJ_5jwACdSM"]
[Thu Jul 30 11:54:28.607440 2026] [security2:error] [pid 643573:tid 643829] [client 172.213.208.20:28014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuBxPxWyxgRnoFKAJ_5mQAAAos"]
[Thu Jul 30 11:54:29.633162 2026] [security2:error] [pid 643573:tid 643716] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "saptora.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuBxfxWyxgRnoFKAJ_5nQAAAho"]
[Thu Jul 30 11:54:30.044769 2026] [security2:error] [pid 643573:tid 643779] [client 46.232.235.4:60310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.greensparkle.net"] [uri "/.env"] [unique_id "amuBxvxWyxgRnoFKAJ_5nwAAAlk"]
[Thu Jul 30 11:54:30.299943 2026] [security2:error] [pid 642360:tid 642569] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "saptora.com"] [uri "/media/system/js/core.js"] [unique_id "amuBxpSUkh3e5AhEJOB0UAAAAd4"]
[Thu Jul 30 11:54:31.037820 2026] [core:notice] [pid 642360:tid 642511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:31.042013 2026] [security2:error] [pid 642360:tid 642511] [client 103.215.74.26:28460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBx5SUkh3e5AhEJOB0WQAAAaQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:31.102725 2026] [authz_core:error] [pid 642360:tid 642544] [client 46.232.235.4:45738] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:31.144520 2026] [authz_core:error] [pid 643573:tid 643756] [client 46.232.235.4:45762] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:31.547818 2026] [authz_core:error] [pid 643573:tid 643732] [client 46.232.235.4:45728] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:31.562692 2026] [authz_core:error] [pid 642360:tid 642613] [client 46.232.235.4:45748] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:31.760587 2026] [core:notice] [pid 643573:tid 643822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:31.764634 2026] [security2:error] [pid 643573:tid 643822] [client 103.215.74.26:28474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBx_xWyxgRnoFKAJ_5tAAAAoQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:31.875487 2026] [security2:error] [pid 643573:tid 643775] [client 172.213.208.20:22040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuBx_xWyxgRnoFKAJ_5tgAAAlU"]
[Thu Jul 30 11:54:32.493887 2026] [core:notice] [pid 643573:tid 643767] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:32.498242 2026] [security2:error] [pid 643573:tid 643767] [client 103.215.74.26:28488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuByPxWyxgRnoFKAJ_5vAAAAk0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:32.605260 2026] [security2:error] [pid 643573:tid 643730] [client 57.141.0.64:51562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuByPxWyxgRnoFKAJ_5uQACKEQ"], referer: https://igetvape-australia.com/product/iget-bar-pro-strawberry-raspberry/?add-to-cart=103
[Thu Jul 30 11:54:32.842586 2026] [authz_core:error] [pid 643573:tid 643752] [client 46.232.235.4:45776] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:33.045049 2026] [authz_core:error] [pid 642360:tid 642534] [client 46.232.235.4:45778] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:33.246847 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:33.250905 2026] [security2:error] [pid 642360:tid 642548] [client 103.215.74.26:55018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuByZSUkh3e5AhEJOB0iAAAAck"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:33.577693 2026] [core:notice] [pid 642360:tid 642522] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:33.979571 2026] [core:notice] [pid 643573:tid 643743] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:33.983429 2026] [security2:error] [pid 643573:tid 643743] [client 103.215.74.26:55032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuByfxWyxgRnoFKAJ_5xAAAAjU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:34.719193 2026] [core:notice] [pid 643573:tid 643811] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:34.723618 2026] [security2:error] [pid 643573:tid 643811] [client 103.215.74.26:55044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuByvxWyxgRnoFKAJ_5xwAAAnk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:35.088429 2026] [security2:error] [pid 642360:tid 642507] [client 172.213.208.20:28010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/admin.php"] [unique_id "amuBy5SUkh3e5AhEJOB0nQAAAaA"]
[Thu Jul 30 11:54:35.464146 2026] [core:notice] [pid 643573:tid 643711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:35.468396 2026] [security2:error] [pid 643573:tid 643711] [client 103.215.74.26:55060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuBy_xWyxgRnoFKAJ_5zQAAAhU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:35.742893 2026] [security2:error] [pid 643573:tid 643792] [client 172.213.208.20:18644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-configs.php"] [unique_id "amuBy_xWyxgRnoFKAJ_50AAAAmY"]
[Thu Jul 30 11:54:36.017454 2026] [security2:error] [pid 643573:tid 643795] [client 85.208.96.205:24204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/01/18/inter-soma-quase-triplo-de-pontos-do-sao-paulo-em-seis-rodadas-e-esquenta-disputa-pelo-titulo/"] [unique_id "amuBzPxWyxgRnoFKAJ_50wAAAmk"]
[Thu Jul 30 11:54:36.017563 2026] [security2:error] [pid 643573:tid 643795] [client 85.208.96.205:24204] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/01/18/inter-soma-quase-triplo-de-pontos-do-sao-paulo-em-seis-rodadas-e-esquenta-disputa-pelo-titulo/"] [unique_id "amuBzPxWyxgRnoFKAJ_50wAAAmk"]
[Thu Jul 30 11:54:36.317487 2026] [security2:error] [pid 643573:tid 643585] [remote 194.116.184.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imailearninghub.com"] [uri "/wp/xmlrpc.php"] [unique_id "amuBzPxWyxgRnoFKAJ_51AACVgQ"]
[Thu Jul 30 11:54:36.317732 2026] [security2:error] [pid 643573:tid 643776] [client 194.116.184.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "imailearninghub.com"] [uri "/wp/xmlrpc.php"] [unique_id "amuBzPxWyxgRnoFKAJ_51AACVgQ"]
[Thu Jul 30 11:54:36.413251 2026] [security2:error] [pid 643573:tid 643716] [client 172.213.208.20:44715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/php.php"] [unique_id "amuBzPxWyxgRnoFKAJ_51wAAAho"]
[Thu Jul 30 11:54:36.826550 2026] [security2:error] [pid 642360:tid 642586] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuBzJSUkh3e5AhEJOB0pAAB73I"]
[Thu Jul 30 11:54:37.074369 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:28281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBzfxWyxgRnoFKAJ_53wAAAoY"]
[Thu Jul 30 11:54:37.074512 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:28281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuBzfxWyxgRnoFKAJ_53wAAAoY"]
[Thu Jul 30 11:54:37.652000 2026] [security2:error] [pid 643573:tid 643720] [client 172.213.208.20:22028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/index.php"] [unique_id "amuBzfxWyxgRnoFKAJ_54wAAAh4"]
[Thu Jul 30 11:54:39.894335 2026] [security2:error] [pid 642360:tid 642551] [client 198.54.128.138:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuBz5SUkh3e5AhEJOB0xgAAAcw"]
[Thu Jul 30 11:54:39.894434 2026] [security2:error] [pid 642360:tid 642551] [client 198.54.128.138:35540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuBz5SUkh3e5AhEJOB0xgAAAcw"]
[Thu Jul 30 11:54:40.253235 2026] [authz_core:error] [pid 642360:tid 642566] [client 46.232.235.4:45830] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:40.582101 2026] [authz_core:error] [pid 642360:tid 642602] [client 46.232.235.4:45838] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 11:54:41.216526 2026] [core:notice] [pid 643573:tid 643733] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:41.220894 2026] [security2:error] [pid 643573:tid 643733] [client 103.215.74.26:55076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB0fxWyxgRnoFKAJ_59wAAAis"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:41.223658 2026] [security2:error] [pid 643573:tid 643825] [client 57.141.0.6:58224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuB0PxWyxgRnoFKAJ_59QACh3Y"], referer: https://igetvape-australia.com/product/alibarbar-ingot-wtf-grapefruit-9000-puffs/?add-to-cart=924
[Thu Jul 30 11:54:41.317464 2026] [authz_core:error] [pid 643573:tid 643805] [client 46.232.235.4:46256] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:41.355132 2026] [authz_core:error] [pid 643573:tid 643717] [client 46.232.235.4:46242] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 11:54:41.665016 2026] [security2:error] [pid 643573:tid 643706] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuB0fxWyxgRnoFKAJ_5_gACSn0"]
[Thu Jul 30 11:54:41.665173 2026] [security2:error] [pid 643573:tid 643764] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuB0fxWyxgRnoFKAJ_5_gACSn0"]
[Thu Jul 30 11:54:41.783839 2026] [security2:error] [pid 642360:tid 642526] [client 123.28.19.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "journeywomenscenter.org"] [uri "/index.php"] [unique_id "amuB0JSUkh3e5AhEJOB0yQAAAbM"], referer: https://journeywomenscenter.org/
[Thu Jul 30 11:54:41.956614 2026] [core:notice] [pid 642360:tid 642525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:41.964207 2026] [security2:error] [pid 642360:tid 642525] [client 103.215.74.26:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB0ZSUkh3e5AhEJOB03gAAAbI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:42.339954 2026] [security2:error] [pid 643573:tid 643818] [client 172.213.208.20:14740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/a.php"] [unique_id "amuB0vxWyxgRnoFKAJ_6DQAAAoA"]
[Thu Jul 30 11:54:42.702157 2026] [core:notice] [pid 642360:tid 642559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:42.709618 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:55090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB0pSUkh3e5AhEJOB06gAAAdQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:42.915500 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:43.207541 2026] [core:notice] [pid 643573:tid 643674] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:43.457468 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:43.461907 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:48092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB0_xWyxgRnoFKAJ_6FAAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:44.191265 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:44.195650 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:48100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1JSUkh3e5AhEJOB0-AAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:44.317402 2026] [security2:error] [pid 642360:tid 642596] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuB05SUkh3e5AhEJOB08gAAAfk"]
[Thu Jul 30 11:54:44.936947 2026] [core:notice] [pid 642360:tid 642509] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:44.941552 2026] [security2:error] [pid 642360:tid 642509] [client 103.215.74.26:48114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1JSUkh3e5AhEJOB1BQAAAaI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:45.669365 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:45.673707 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1cjqbtjBYzqM1uYm8wAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:46.125431 2026] [security2:error] [pid 643573:tid 643788] [client 74.7.230.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rru.djb.temporary.site"] [uri "/index.php"] [unique_id "amuB1PxWyxgRnoFKAJ_6HgAAAmI"]
[Thu Jul 30 11:54:46.126349 2026] [security2:error] [pid 642360:tid 642563] [client 74.7.230.11:50752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rru.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuB1JSUkh3e5AhEJOB0_QAB2Ao"]
[Thu Jul 30 11:54:46.286304 2026] [security2:error] [pid 643573:tid 643819] [client 172.213.208.20:19850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuB1vxWyxgRnoFKAJ_6KAAAAoE"]
[Thu Jul 30 11:54:46.434092 2026] [core:notice] [pid 643573:tid 643755] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:46.440894 2026] [security2:error] [pid 643573:tid 643755] [client 103.215.74.26:48124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1vxWyxgRnoFKAJ_6KgAAAkE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:47.185105 2026] [core:notice] [pid 642360:tid 642536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:47.188845 2026] [security2:error] [pid 642360:tid 642536] [client 103.215.74.26:48138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB15SUkh3e5AhEJOB1GwAAAb0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:47.611593 2026] [security2:error] [pid 643573:tid 643761] [client 176.241.66.87:63245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB1_xWyxgRnoFKAJ_6OAAAAkc"]
[Thu Jul 30 11:54:47.611746 2026] [security2:error] [pid 643573:tid 643761] [client 176.241.66.87:63245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB1_xWyxgRnoFKAJ_6OAAAAkc"]
[Thu Jul 30 11:54:47.918764 2026] [core:notice] [pid 643573:tid 643828] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:47.922764 2026] [security2:error] [pid 643573:tid 643828] [client 103.215.74.26:48144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB1_xWyxgRnoFKAJ_6OQAAAoo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:48.000380 2026] [autoindex:error] [pid 643573:tid 643779] [client 52.4.19.39:4043] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:54:48.073724 2026] [security2:error] [pid 642360:tid 642553] [client 172.213.208.20:45949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin.php"] [unique_id "amuB2JSUkh3e5AhEJOB1IgAAAc4"]
[Thu Jul 30 11:54:48.658587 2026] [core:notice] [pid 643573:tid 643759] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:48.662933 2026] [security2:error] [pid 643573:tid 643759] [client 103.215.74.26:48152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB2PxWyxgRnoFKAJ_6QQAAAkU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:49.388477 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:49.395127 2026] [security2:error] [pid 643573:tid 643756] [client 103.215.74.26:48160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB2fxWyxgRnoFKAJ_6QwAAAkI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:50.131563 2026] [core:notice] [pid 643573:tid 643753] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:50.138470 2026] [security2:error] [pid 643573:tid 643753] [client 103.215.74.26:48174] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB2vxWyxgRnoFKAJ_6TgAAAj8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:50.793219 2026] [security2:error] [pid 643573:tid 643795] [client 172.213.208.20:38311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/size.php"] [unique_id "amuB2vxWyxgRnoFKAJ_6VAAAAmk"]
[Thu Jul 30 11:54:50.860371 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:50.864141 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:48190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB2vxWyxgRnoFKAJ_6VwAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:51.595508 2026] [core:notice] [pid 642360:tid 642560] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:51.599780 2026] [security2:error] [pid 642360:tid 642560] [client 103.215.74.26:48198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB25SUkh3e5AhEJOB1PgAAAdU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:51.701334 2026] [security2:error] [pid 643573:tid 643727] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuB2_xWyxgRnoFKAJ_6XAAAAiU"]
[Thu Jul 30 11:54:51.886854 2026] [core:error] [pid 642360:tid 642600] [client 74.7.230.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:51.886874 2026] [core:error] [pid 642360:tid 642600] [client 74.7.230.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:54:51.887002 2026] [security2:error] [pid 642360:tid 642600] [client 74.7.230.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.thdinfinity.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuB25SUkh3e5AhEJOB1RAAAAf0"]
[Thu Jul 30 11:54:51.887729 2026] [security2:error] [pid 643573:tid 643717] [client 74.7.230.5:47126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.thdinfinity.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuB2_xWyxgRnoFKAJ_6ZQACG0w"]
[Thu Jul 30 11:54:52.364314 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:52.370619 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:48200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3PxWyxgRnoFKAJ_6awAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:53.087675 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:53.091813 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:3014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3fxWyxgRnoFKAJ_6dgAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:53.532748 2026] [security2:error] [pid 642360:tid 642457] [remote 20.52.125.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuB3ZSUkh3e5AhEJOB1UQABwGA"]
[Thu Jul 30 11:54:53.823620 2026] [core:notice] [pid 642360:tid 642616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:53.827483 2026] [security2:error] [pid 642360:tid 642616] [client 103.215.74.26:3028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3ZSUkh3e5AhEJOB1VAAAAg0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:53.987689 2026] [security2:error] [pid 643573:tid 643655] [remote 20.52.125.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/flower.php"] [unique_id "amuB3fxWyxgRnoFKAJ_6fgACWko"]
[Thu Jul 30 11:54:54.160312 2026] [security2:error] [pid 643573:tid 643834] [client 172.213.208.20:17674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuB3vxWyxgRnoFKAJ_6fwAAApA"]
[Thu Jul 30 11:54:54.422366 2026] [security2:error] [pid 642360:tid 642405] [remote 20.52.125.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/xleet.php"] [unique_id "amuB3pSUkh3e5AhEJOB1WgAB2Cw"]
[Thu Jul 30 11:54:54.560292 2026] [core:notice] [pid 642360:tid 642604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:54.564288 2026] [security2:error] [pid 642360:tid 642604] [client 103.215.74.26:3032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3pSUkh3e5AhEJOB1WwAAAgE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:54.815779 2026] [security2:error] [pid 642360:tid 642416] [remote 20.52.125.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuB3pSUkh3e5AhEJOB1XwAB-jc"]
[Thu Jul 30 11:54:55.289902 2026] [security2:error] [pid 643573:tid 643765] [client 74.7.241.182:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qax.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuB3PxWyxgRnoFKAJ_6cQAAAks"]
[Thu Jul 30 11:54:55.290636 2026] [security2:error] [pid 643573:tid 643750] [client 74.7.241.182:48618] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qax.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amuB3PxWyxgRnoFKAJ_6bgACPEg"]
[Thu Jul 30 11:54:55.294557 2026] [core:notice] [pid 643573:tid 643801] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:55.298502 2026] [security2:error] [pid 643573:tid 643801] [client 103.215.74.26:3040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB3_xWyxgRnoFKAJ_6iAAAAm8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:54:55.302847 2026] [security2:error] [pid 642360:tid 642495] [client 172.213.208.20:14751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/403.php"] [unique_id "amuB35SUkh3e5AhEJOB1YQAAAZQ"]
[Thu Jul 30 11:54:55.720923 2026] [core:notice] [pid 643573:tid 643797] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:55.787878 2026] [security2:error] [pid 643573:tid 643781] [client 74.7.241.150:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.nexiummedication.store"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuB3_xWyxgRnoFKAJ_6kAAAAls"]
[Thu Jul 30 11:54:56.269474 2026] [security2:error] [pid 643573:tid 643740] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuB3_xWyxgRnoFKAJ_6jgAAAjI"]
[Thu Jul 30 11:54:56.563687 2026] [security2:error] [pid 643573:tid 643802] [client 172.213.208.20:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuB4PxWyxgRnoFKAJ_6lgAAAnA"]
[Thu Jul 30 11:54:56.975572 2026] [security2:error] [pid 643253:tid 643420] [client 114.119.132.101:41297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltaedu.net"] [uri "/robots.txt"] [unique_id "amuB4MjqbtjBYzqM1uYm_gAAACQ"], referer: http://deltaedu.net/robots.txt
[Thu Jul 30 11:54:57.045972 2026] [security2:error] [pid 643253:tid 643471] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuB4MjqbtjBYzqM1uYm_AAAAFc"]
[Thu Jul 30 11:54:57.114810 2026] [security2:error] [pid 643573:tid 643632] [remote 57.141.0.50:32432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/74297757886/feed/rss2/"] [unique_id "amuB4fxWyxgRnoFKAJ_6nwACWDM"]
[Thu Jul 30 11:54:57.173283 2026] [core:notice] [pid 643573:tid 643770] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:57.472176 2026] [security2:error] [pid 643573:tid 643789] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB4PxWyxgRnoFKAJ_6mwACYwo"]
[Thu Jul 30 11:54:58.347544 2026] [security2:error] [pid 643573:tid 643790] [client 176.241.66.87:29481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB4vxWyxgRnoFKAJ_6rgAAAmQ"]
[Thu Jul 30 11:54:58.347651 2026] [security2:error] [pid 643573:tid 643790] [client 176.241.66.87:29481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB4vxWyxgRnoFKAJ_6rgAAAmQ"]
[Thu Jul 30 11:54:58.935810 2026] [core:notice] [pid 643573:tid 643712] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:59.129641 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:59.519517 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:54:59.685360 2026] [core:notice] [pid 643573:tid 643713] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:00.507805 2026] [security2:error] [pid 642360:tid 642511] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tuwaiq-sa.tech"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuB5JSUkh3e5AhEJOB1iAAAAaQ"]
[Thu Jul 30 11:55:01.034361 2026] [core:notice] [pid 643573:tid 643820] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:01.038729 2026] [security2:error] [pid 643573:tid 643820] [client 103.215.74.26:3044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB5fxWyxgRnoFKAJ_6yAAAAoI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:01.057620 2026] [security2:error] [pid 642360:tid 642600] [client 190.2.142.78:23636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuB5JSUkh3e5AhEJOB1jAAAAf0"]
[Thu Jul 30 11:55:01.238811 2026] [security2:error] [pid 642360:tid 642509] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tuwaiq-sa.tech"] [uri "/media/system/js/core.js"] [unique_id "amuB5ZSUkh3e5AhEJOB1kgAAAaI"]
[Thu Jul 30 11:55:01.350550 2026] [security2:error] [pid 643573:tid 643676] [remote 190.2.142.78:18970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuB5fxWyxgRnoFKAJ_6ywACiF8"], referer: http://alseermarine.ae/wp-login.php
[Thu Jul 30 11:55:01.798518 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:01.805534 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:3052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB5fxWyxgRnoFKAJ_61wAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:01.863509 2026] [security2:error] [pid 643573:tid 643836] [client 172.213.208.20:44677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/as.php"] [unique_id "amuB5fxWyxgRnoFKAJ_62gAAApI"]
[Thu Jul 30 11:55:02.177928 2026] [security2:error] [pid 643573:tid 643832] [client 50.6.43.217:25558] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-cron.php"] [unique_id "amuB5vxWyxgRnoFKAJ_63gAAAo4"]
[Thu Jul 30 11:55:02.335943 2026] [security2:error] [pid 643573:tid 643806] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB5fxWyxgRnoFKAJ_60wACdCQ"]
[Thu Jul 30 11:55:02.433399 2026] [core:notice] [pid 642360:tid 642586] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:02.469855 2026] [security2:error] [pid 643573:tid 643771] [client 172.213.208.20:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuB5vxWyxgRnoFKAJ_64QAAAlE"]
[Thu Jul 30 11:55:02.899596 2026] [security2:error] [pid 642360:tid 642514] [client 190.2.142.78:18982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuB5pSUkh3e5AhEJOB1pQABp2I"], referer: http://alseermarine.com/wp-admin/
[Thu Jul 30 11:55:02.899870 2026] [security2:error] [pid 642360:tid 642514] [client 190.2.142.78:18982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuB5pSUkh3e5AhEJOB1pAABp3A"], referer: https://www.alseermarine.com/wp-admin/
[Thu Jul 30 11:55:03.506789 2026] [security2:error] [pid 643573:tid 643735] [client 112.86.225.114:37086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product-category/sneaker/nike-sneaker/nike-sb-dunk/"] [unique_id "amuB5_xWyxgRnoFKAJ_68QAAAi0"]
[Thu Jul 30 11:55:03.506889 2026] [security2:error] [pid 643573:tid 643735] [client 112.86.225.114:37086] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product-category/sneaker/nike-sneaker/nike-sb-dunk/"] [unique_id "amuB5_xWyxgRnoFKAJ_68QAAAi0"]
[Thu Jul 30 11:55:04.313220 2026] [security2:error] [pid 642360:tid 642567] [client 190.2.142.78:18982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuB6JSUkh3e5AhEJOB1tAAB3Gw"], referer: http://alseermarine.com/wp-admin/
[Thu Jul 30 11:55:05.280567 2026] [core:notice] [pid 643573:tid 643818] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:05.583647 2026] [security2:error] [pid 643573:tid 643760] [client 91.142.73.116:53492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.73.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/register"] [unique_id "amuB6fxWyxgRnoFKAJ_6-gAAAkY"], referer: https://cnpinyin.com/register
[Thu Jul 30 11:55:06.442020 2026] [security2:error] [pid 643573:tid 643794] [client 91.142.73.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuB6vxWyxgRnoFKAJ_7AQAAAmg"], referer: https://cnpinyin.com/register
[Thu Jul 30 11:55:07.583353 2026] [core:notice] [pid 643573:tid 643762] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:07.587311 2026] [security2:error] [pid 643573:tid 643762] [client 103.215.74.26:24620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB6_xWyxgRnoFKAJ_7CgAAAkg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:07.654467 2026] [security2:error] [pid 642360:tid 642556] [client 172.213.208.20:17692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuB65SUkh3e5AhEJOB12AAAAdE"]
[Thu Jul 30 11:55:07.943667 2026] [security2:error] [pid 643573:tid 643754] [client 47.128.122.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuB6_xWyxgRnoFKAJ_7DgAAAkA"]
[Thu Jul 30 11:55:08.324109 2026] [core:notice] [pid 643573:tid 643752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:08.328475 2026] [security2:error] [pid 643573:tid 643752] [client 103.215.74.26:24636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB7PxWyxgRnoFKAJ_7EQAAAj4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:09.040489 2026] [security2:error] [pid 642360:tid 642588] [client 176.241.66.87:30099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB7ZSUkh3e5AhEJOB15QAAAfE"]
[Thu Jul 30 11:55:09.040651 2026] [security2:error] [pid 642360:tid 642588] [client 176.241.66.87:30099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB7ZSUkh3e5AhEJOB15QAAAfE"]
[Thu Jul 30 11:55:09.060950 2026] [core:notice] [pid 643573:tid 643728] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:09.065417 2026] [security2:error] [pid 643573:tid 643728] [client 103.215.74.26:24648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB7fxWyxgRnoFKAJ_7FAAAAiY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:09.632401 2026] [security2:error] [pid 642360:tid 642373] [remote 194.116.184.179:55843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuB7ZSUkh3e5AhEJOB16gABygw"]
[Thu Jul 30 11:55:11.507805 2026] [security2:error] [pid 643573:tid 643836] [client 34.86.95.193:63707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psz.dtn.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuB7_xWyxgRnoFKAJ_7JwAAApI"]
[Thu Jul 30 11:55:12.550259 2026] [security2:error] [pid 643573:tid 643834] [client 34.86.95.193:52313] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "psz.dtn.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuB8PxWyxgRnoFKAJ_7MQAAApA"]
[Thu Jul 30 11:55:13.211740 2026] [security2:error] [pid 643573:tid 643597] [remote 52.204.253.129:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "appliancerepairservice.one"] [uri "/"] [unique_id "amuB8fxWyxgRnoFKAJ_7PwAChxA"]
[Thu Jul 30 11:55:13.928660 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:13.937858 2026] [security2:error] [pid 642360:tid 642536] [client 172.213.208.20:38385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/plugins.php"] [unique_id "amuB8ZSUkh3e5AhEJOB2CgAAAb0"]
[Thu Jul 30 11:55:14.039308 2026] [security2:error] [pid 643573:tid 643698] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuB8vxWyxgRnoFKAJ_7RAACiXU"]
[Thu Jul 30 11:55:14.039461 2026] [security2:error] [pid 643573:tid 643827] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuB8vxWyxgRnoFKAJ_7RAACiXU"]
[Thu Jul 30 11:55:14.488553 2026] [security2:error] [pid 643573:tid 643728] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuB8PxWyxgRnoFKAJ_7NQAAAiY"]
[Thu Jul 30 11:55:14.794560 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:14.799451 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:10742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB8pSUkh3e5AhEJOB2GAAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:15.076735 2026] [security2:error] [pid 642360:tid 642550] [client 172.213.208.20:17657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuB85SUkh3e5AhEJOB2GwAAAcs"]
[Thu Jul 30 11:55:15.133641 2026] [security2:error] [pid 642360:tid 642593] [client 190.2.142.78:42970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-login.php"] [unique_id "amuB85SUkh3e5AhEJOB2HAAAAfY"]
[Thu Jul 30 11:55:15.399490 2026] [security2:error] [pid 643573:tid 643793] [client 34.86.95.193:52313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "psz.dtn.temporary.site"] [uri "/index.php"] [unique_id "amuB8_xWyxgRnoFKAJ_7WAAAAmc"]
[Thu Jul 30 11:55:15.527418 2026] [core:notice] [pid 643573:tid 643771] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:15.532479 2026] [security2:error] [pid 643573:tid 643771] [client 103.215.74.26:10748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB8_xWyxgRnoFKAJ_7WwAAAlE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:15.799063 2026] [security2:error] [pid 643573:tid 643794] [client 34.86.95.193:52313] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "psz.dtn.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuB8_xWyxgRnoFKAJ_7XAAAAmg"]
[Thu Jul 30 11:55:15.799162 2026] [security2:error] [pid 643573:tid 643794] [client 34.86.95.193:52313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "psz.dtn.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuB8_xWyxgRnoFKAJ_7XAAAAmg"]
[Thu Jul 30 11:55:16.796289 2026] [security2:error] [pid 642360:tid 642586] [client 190.153.80.20:4655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2LQAAAe8"], referer: http://pkf.jo
[Thu Jul 30 11:55:17.067332 2026] [security2:error] [pid 642360:tid 642514] [client 52.167.144.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2MwAAAac"]
[Thu Jul 30 11:55:17.344782 2026] [security2:error] [pid 642360:tid 642599] [client 152.231.104.86:57637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2MQAAAfw"], referer: http://pkf.jo
[Thu Jul 30 11:55:17.386069 2026] [security2:error] [pid 642360:tid 642493] [client 45.190.91.98:40566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2MgAAAZI"], referer: http://pkf.jo
[Thu Jul 30 11:55:17.389388 2026] [security2:error] [pid 643573:tid 643766] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB9PxWyxgRnoFKAJ_7XQACTHk"]
[Thu Jul 30 11:55:17.409784 2026] [security2:error] [pid 642360:tid 642506] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB9JSUkh3e5AhEJOB2LAABnys"]
[Thu Jul 30 11:55:17.497873 2026] [security2:error] [pid 643573:tid 643827] [client 172.213.208.20:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/go.php"] [unique_id "amuB9fxWyxgRnoFKAJ_7awAAAok"]
[Thu Jul 30 11:55:18.103228 2026] [core:notice] [pid 643573:tid 643832] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:18.106880 2026] [security2:error] [pid 642360:tid 642553] [client 172.213.208.20:44681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/test1.php"] [unique_id "amuB9pSUkh3e5AhEJOB2QgAAAc4"]
[Thu Jul 30 11:55:18.610031 2026] [security2:error] [pid 643573:tid 643780] [client 177.201.241.2:33868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuB9vxWyxgRnoFKAJ_7dgAAAlo"], referer: http://pkf.jo
[Thu Jul 30 11:55:19.240191 2026] [core:notice] [pid 643573:tid 643756] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:19.810586 2026] [security2:error] [pid 643573:tid 643801] [client 176.241.66.87:30735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB9_xWyxgRnoFKAJ_7hAAAAm8"]
[Thu Jul 30 11:55:19.810733 2026] [security2:error] [pid 643573:tid 643801] [client 176.241.66.87:30735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuB9_xWyxgRnoFKAJ_7hAAAAm8"]
[Thu Jul 30 11:55:20.628329 2026] [security2:error] [pid 642360:tid 642532] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB95SUkh3e5AhEJOB2UgABuV0"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 11:55:21.291152 2026] [core:notice] [pid 643573:tid 643815] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:21.295378 2026] [security2:error] [pid 643573:tid 643815] [client 103.215.74.26:10762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB-fxWyxgRnoFKAJ_7igAAAn0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:21.724804 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:21.989904 2026] [security2:error] [pid 643573:tid 643726] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuB-fxWyxgRnoFKAJ_7iwACJH4"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 11:55:22.023499 2026] [core:notice] [pid 643573:tid 643714] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:22.028540 2026] [security2:error] [pid 643573:tid 643714] [client 103.215.74.26:10764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB-vxWyxgRnoFKAJ_7jwAAAhg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:22.552970 2026] [security2:error] [pid 643573:tid 643783] [client 172.213.208.20:30242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/images/index.php"] [unique_id "amuB-vxWyxgRnoFKAJ_7kgAAAl0"]
[Thu Jul 30 11:55:22.752811 2026] [core:notice] [pid 643573:tid 643727] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:22.757373 2026] [security2:error] [pid 643573:tid 643727] [client 103.215.74.26:10778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB-vxWyxgRnoFKAJ_7lwAAAiU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:23.485206 2026] [core:notice] [pid 643253:tid 643449] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:23.489772 2026] [security2:error] [pid 643253:tid 643449] [client 103.215.74.26:7440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuB-8jqbtjBYzqM1uYnJQAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:26.868710 2026] [core:notice] [pid 643573:tid 643751] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:27.141707 2026] [security2:error] [pid 643573:tid 643795] [client 44.205.192.249:4911] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuB__xWyxgRnoFKAJ_7wQAAAmk"]
[Thu Jul 30 11:55:27.584309 2026] [security2:error] [pid 643573:tid 643819] [client 107.170.61.160:35534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ylw.gpl.temporary.site"] [uri "/.env"] [unique_id "amuB__xWyxgRnoFKAJ_7xQAAAoE"]
[Thu Jul 30 11:55:28.804230 2026] [security2:error] [pid 643573:tid 643684] [remote 74.7.241.60:58700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/article.php"] [unique_id "amuCAPxWyxgRnoFKAJ_70wACcWc"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:55:28.929399 2026] [security2:error] [pid 643573:tid 643800] [client 204.12.208.18:58124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuCAPxWyxgRnoFKAJ_70gAAAm4"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 11:55:29.237867 2026] [core:notice] [pid 643573:tid 643718] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:29.242209 2026] [security2:error] [pid 643573:tid 643718] [client 103.215.74.26:7450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCAfxWyxgRnoFKAJ_71QAAAhw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:29.538355 2026] [security2:error] [pid 643573:tid 643713] [client 204.12.208.18:58139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuCAfxWyxgRnoFKAJ_72AAAAhc"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 11:55:29.613949 2026] [security2:error] [pid 643573:tid 643810] [client 172.213.208.20:25934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/asd.php"] [unique_id "amuCAfxWyxgRnoFKAJ_72QAAAng"]
[Thu Jul 30 11:55:29.836733 2026] [security2:error] [pid 643573:tid 643761] [client 52.204.71.8:44225] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/783/x01cae62c33381bef08ae27cbbb8b72e4.jpg.pagespeed.ic.vbgVUHucDG.webp"] [unique_id "amuCAfxWyxgRnoFKAJ_73gAAAkc"]
[Thu Jul 30 11:55:29.963837 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:29.967797 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:7452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCAfxWyxgRnoFKAJ_74AAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:30.160790 2026] [security2:error] [pid 642360:tid 642555] [client 204.12.208.18:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuCApSUkh3e5AhEJOB2sgAAAdA"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 11:55:30.364861 2026] [security2:error] [pid 642360:tid 642556] [client 176.241.66.87:65478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCApSUkh3e5AhEJOB2swAAAdE"]
[Thu Jul 30 11:55:30.365019 2026] [security2:error] [pid 642360:tid 642556] [client 176.241.66.87:65478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCApSUkh3e5AhEJOB2swAAAdE"]
[Thu Jul 30 11:55:31.100077 2026] [security2:error] [pid 642360:tid 642546] [client 172.213.208.20:45903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuCA5SUkh3e5AhEJOB2vAAAAcc"]
[Thu Jul 30 11:55:32.249582 2026] [security2:error] [pid 643573:tid 643585] [remote 190.92.174.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "echomemoversalain.casa"] [uri "/xmlrpc.php"] [unique_id "amuCBPxWyxgRnoFKAJ_79QACTwQ"]
[Thu Jul 30 11:55:32.249773 2026] [security2:error] [pid 643573:tid 643769] [client 190.92.174.188:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "echomemoversalain.casa"] [uri "/xmlrpc.php"] [unique_id "amuCBPxWyxgRnoFKAJ_79QACTwQ"]
[Thu Jul 30 11:55:32.258136 2026] [security2:error] [pid 642360:tid 642599] [client 17.241.219.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuCBJSUkh3e5AhEJOB2ywAAAfw"]
[Thu Jul 30 11:55:33.070953 2026] [security2:error] [pid 643573:tid 643836] [client 50.6.43.217:32614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuCBPxWyxgRnoFKAJ_7_AACkgs"]
[Thu Jul 30 11:55:33.071010 2026] [security2:error] [pid 643573:tid 643836] [client 50.6.43.217:32614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuCBPxWyxgRnoFKAJ_7_AACkgs"]
[Thu Jul 30 11:55:34.385770 2026] [security2:error] [pid 643253:tid 643480] [client 186.79.68.169:45462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCBsjqbtjBYzqM1uYnKQAAAGA"], referer: http://pkf.jo
[Thu Jul 30 11:55:34.681847 2026] [security2:error] [pid 643573:tid 643792] [client 172.213.208.20:20827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuCBvxWyxgRnoFKAJ_8BwAAAmY"]
[Thu Jul 30 11:55:35.542256 2026] [security2:error] [pid 642360:tid 642531] [client 52.70.209.13:22594] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuCB5SUkh3e5AhEJOB26gAAAbg"]
[Thu Jul 30 11:55:35.716099 2026] [core:notice] [pid 642360:tid 642527] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:35.720274 2026] [security2:error] [pid 642360:tid 642527] [client 103.215.74.26:10572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCB5SUkh3e5AhEJOB27QAAAbQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:36.208159 2026] [security2:error] [pid 643573:tid 643800] [client 172.213.208.20:39407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/atomlib.php"] [unique_id "amuCCPxWyxgRnoFKAJ_8DQAAAm4"]
[Thu Jul 30 11:55:36.502460 2026] [core:notice] [pid 643573:tid 643744] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:36.506393 2026] [security2:error] [pid 643573:tid 643744] [client 103.215.74.26:10584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCCPxWyxgRnoFKAJ_8EQAAAjY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:37.274721 2026] [core:notice] [pid 643573:tid 643740] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:37.278858 2026] [security2:error] [pid 643573:tid 643740] [client 103.215.74.26:10586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCCfxWyxgRnoFKAJ_8GgAAAjI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:37.712599 2026] [security2:error] [pid 643573:tid 643779] [client 54.84.147.79:35233] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuCCfxWyxgRnoFKAJ_8HgAAAlk"]
[Thu Jul 30 11:55:38.006082 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:38.012843 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:10590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCCvxWyxgRnoFKAJ_8KgAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:38.079891 2026] [core:notice] [pid 643573:tid 643625] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:38.639525 2026] [security2:error] [pid 643573:tid 643808] [client 50.6.43.217:32626] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuCCvxWyxgRnoFKAJ_8NQAAAnY"]
[Thu Jul 30 11:55:38.670744 2026] [security2:error] [pid 643573:tid 643822] [client 50.6.43.217:32628] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuCCvxWyxgRnoFKAJ_8OAAAAoQ"]
[Thu Jul 30 11:55:38.767316 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:38.773896 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:10602] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCCpSUkh3e5AhEJOB3BAAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:39.500453 2026] [core:notice] [pid 643573:tid 643742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:39.504468 2026] [security2:error] [pid 643573:tid 643742] [client 103.215.74.26:10604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCC_xWyxgRnoFKAJ_8QAAAAjQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:40.249570 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:40.253516 2026] [security2:error] [pid 643573:tid 643754] [client 103.215.74.26:10618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCDPxWyxgRnoFKAJ_8SQAAAkA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:40.705939 2026] [security2:error] [pid 643573:tid 643783] [client 50.6.43.217:32642] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuCDPxWyxgRnoFKAJ_8TQAAAl0"]
[Thu Jul 30 11:55:40.876125 2026] [security2:error] [pid 643573:tid 643825] [client 50.6.43.217:32656] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuCDPxWyxgRnoFKAJ_8TgAAAoc"]
[Thu Jul 30 11:55:40.986992 2026] [core:notice] [pid 643573:tid 643789] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:40.993443 2026] [security2:error] [pid 643573:tid 643789] [client 103.215.74.26:10634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCDPxWyxgRnoFKAJ_8UAAAAmM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:40.997506 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:32007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCDPxWyxgRnoFKAJ_8UQAAAoY"]
[Thu Jul 30 11:55:40.997611 2026] [security2:error] [pid 643573:tid 643824] [client 176.241.66.87:32007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCDPxWyxgRnoFKAJ_8UQAAAoY"]
[Thu Jul 30 11:55:41.607178 2026] [security2:error] [pid 642360:tid 642553] [client 20.91.199.21:56529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/011i.php"] [unique_id "amuCDZSUkh3e5AhEJOB3JAAAAc4"]
[Thu Jul 30 11:55:41.738746 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:41.742669 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:10648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "769"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCDZSUkh3e5AhEJOB3JwAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:41.779447 2026] [core:notice] [pid 643573:tid 643739] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:41.998310 2026] [security2:error] [pid 642360:tid 642564] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCDZSUkh3e5AhEJOB3IAAAAdk"]
[Thu Jul 30 11:55:42.365939 2026] [security2:error] [pid 643573:tid 643775] [client 185.191.171.6:26912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/03/instituicao-oferece-plataforma-gratuita-para-quem-quer-estudar-para-o-enem/"] [unique_id "amuCDvxWyxgRnoFKAJ_8YQAAAlU"]
[Thu Jul 30 11:55:42.366070 2026] [security2:error] [pid 643573:tid 643775] [client 185.191.171.6:26912] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/03/instituicao-oferece-plataforma-gratuita-para-quem-quer-estudar-para-o-enem/"] [unique_id "amuCDvxWyxgRnoFKAJ_8YQAAAlU"]
[Thu Jul 30 11:55:42.490847 2026] [core:notice] [pid 643573:tid 643805] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:42.494843 2026] [security2:error] [pid 643573:tid 643805] [client 103.215.74.26:10656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCDvxWyxgRnoFKAJ_8YgAAAnM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:42.831732 2026] [security2:error] [pid 642360:tid 642540] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCDpSUkh3e5AhEJOB3LAAAAcE"]
[Thu Jul 30 11:55:43.240451 2026] [core:notice] [pid 643253:tid 643445] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:43.244748 2026] [security2:error] [pid 643253:tid 643445] [client 103.215.74.26:56512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCD8jqbtjBYzqM1uYnOAAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:44.001608 2026] [core:notice] [pid 643253:tid 643433] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:44.005752 2026] [security2:error] [pid 643253:tid 643433] [client 103.215.74.26:56518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCD8jqbtjBYzqM1uYnPAAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:44.495141 2026] [security2:error] [pid 643573:tid 643716] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCD_xWyxgRnoFKAJ_8aQACGkA"]
[Thu Jul 30 11:55:44.567152 2026] [security2:error] [pid 643573:tid 643607] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCEPxWyxgRnoFKAJ_8bwACVBo"]
[Thu Jul 30 11:55:44.567321 2026] [security2:error] [pid 643573:tid 643774] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCEPxWyxgRnoFKAJ_8bwACVBo"]
[Thu Jul 30 11:55:44.603480 2026] [security2:error] [pid 643573:tid 643781] [client 20.91.199.21:52390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/03a005685d.php"] [unique_id "amuCEPxWyxgRnoFKAJ_8cAAAAls"]
[Thu Jul 30 11:55:44.749610 2026] [core:notice] [pid 643573:tid 643830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:44.753826 2026] [security2:error] [pid 643573:tid 643830] [client 103.215.74.26:56526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCEPxWyxgRnoFKAJ_8cQAAAow"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:45.423375 2026] [lsapi:error] [pid 643573:tid 643694] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/teen-lust-vj-emmy/
[Thu Jul 30 11:55:45.512536 2026] [core:notice] [pid 643573:tid 643737] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:45.516489 2026] [security2:error] [pid 643573:tid 643737] [client 103.215.74.26:56528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCEfxWyxgRnoFKAJ_8gQAAAi8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:45.703587 2026] [security2:error] [pid 642360:tid 642590] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCEZSUkh3e5AhEJOB3RAAAAfM"]
[Thu Jul 30 11:55:45.921589 2026] [security2:error] [pid 643573:tid 643776] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCEfxWyxgRnoFKAJ_8fgAAAlY"]
[Thu Jul 30 11:55:46.123496 2026] [core:notice] [pid 643573:tid 643658] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:46.133897 2026] [core:error] [pid 643573:tid 643658] [remote 66.249.74.12:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:46.134110 2026] [security2:error] [pid 643573:tid 643820] [client 66.249.74.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/29/32.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuCEfxWyxgRnoFKAJ_8hAACgk0"]
[Thu Jul 30 11:55:46.227688 2026] [security2:error] [pid 643573:tid 643777] [client 172.213.208.20:39479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuCEvxWyxgRnoFKAJ_8hgAAAlc"]
[Thu Jul 30 11:55:46.267533 2026] [core:notice] [pid 643573:tid 643798] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:46.271268 2026] [security2:error] [pid 643573:tid 643798] [client 103.215.74.26:56540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCEvxWyxgRnoFKAJ_8hwAAAmw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:46.507912 2026] [security2:error] [pid 643573:tid 643730] [client 20.91.199.21:36500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/403.php"] [unique_id "amuCEvxWyxgRnoFKAJ_8jgAAAig"]
[Thu Jul 30 11:55:46.831710 2026] [core:notice] [pid 643573:tid 643655] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:46.993688 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:46.998328 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:56554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCEsjqbtjBYzqM1uYnPwAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:47.121188 2026] [security2:error] [pid 643573:tid 643790] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCEvxWyxgRnoFKAJ_8jQACZEE"]
[Thu Jul 30 11:55:47.489619 2026] [security2:error] [pid 642360:tid 642517] [client 107.170.60.13:37586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.tvs.nyx.temporary.site"] [uri "/.env"] [unique_id "amuCE5SUkh3e5AhEJOB3WgAAAao"]
[Thu Jul 30 11:55:47.731433 2026] [core:notice] [pid 643573:tid 643732] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:47.735837 2026] [security2:error] [pid 643573:tid 643732] [client 103.215.74.26:56558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCE_xWyxgRnoFKAJ_8mgAAAio"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:47.946157 2026] [security2:error] [pid 643573:tid 643792] [client 20.91.199.21:52800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/404.php"] [unique_id "amuCE_xWyxgRnoFKAJ_8nAAAAmY"]
[Thu Jul 30 11:55:48.377915 2026] [security2:error] [pid 643573:tid 643720] [client 40.77.167.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuCFPxWyxgRnoFKAJ_8nwAAAh4"]
[Thu Jul 30 11:55:48.504141 2026] [core:notice] [pid 643573:tid 643806] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:48.508388 2026] [security2:error] [pid 643573:tid 643806] [client 103.215.74.26:56574] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCFPxWyxgRnoFKAJ_8qwAAAnQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:48.687591 2026] [security2:error] [pid 643573:tid 643807] [client 113.173.144.54:44823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCFPxWyxgRnoFKAJ_8pwAAAnU"], referer: http://pkf.jo
[Thu Jul 30 11:55:48.864339 2026] [security2:error] [pid 642360:tid 642506] [client 92.118.39.171:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bestdogproductguide.com"] [uri "/.env"] [unique_id "amuCFJSUkh3e5AhEJOB3ZAAAAZ8"]
[Thu Jul 30 11:55:48.870275 2026] [security2:error] [pid 643573:tid 643753] [client 40.77.167.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuCFPxWyxgRnoFKAJ_8rgAAAj8"]
[Thu Jul 30 11:55:49.241209 2026] [core:notice] [pid 643573:tid 643782] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:49.245387 2026] [security2:error] [pid 643573:tid 643782] [client 103.215.74.26:56578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCFfxWyxgRnoFKAJ_8tQAAAlw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:49.253555 2026] [security2:error] [pid 643573:tid 643788] [client 92.118.39.171:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bestdogproductguide.com"] [uri "/"] [unique_id "amuCFfxWyxgRnoFKAJ_8tgAAAmI"]
[Thu Jul 30 11:55:49.971096 2026] [security2:error] [pid 643573:tid 643722] [client 84.32.223.22:37902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCFfxWyxgRnoFKAJ_8vQAAAiA"], referer: http://pkf.jo
[Thu Jul 30 11:55:50.297398 2026] [security2:error] [pid 643573:tid 643762] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCFfxWyxgRnoFKAJ_8vAACSD8"]
[Thu Jul 30 11:55:50.811132 2026] [security2:error] [pid 643253:tid 643486] [client 216.145.84.209:49843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCFsjqbtjBYzqM1uYnQQAAAGY"], referer: http://pkf.jo
[Thu Jul 30 11:55:51.729719 2026] [security2:error] [pid 643253:tid 643489] [client 176.241.66.87:32647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCF8jqbtjBYzqM1uYnQgAAAGk"]
[Thu Jul 30 11:55:51.729906 2026] [security2:error] [pid 643253:tid 643489] [client 176.241.66.87:32647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCF8jqbtjBYzqM1uYnQgAAAGk"]
[Thu Jul 30 11:55:52.090208 2026] [security2:error] [pid 642360:tid 642528] [client 57.141.0.1:63730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuCF5SUkh3e5AhEJOB3fQABtR4"], referer: https://igetvape-australia.com/product-tag/alibarbar-ice-adjust-12000-puffs-skittles/
[Thu Jul 30 11:55:52.272295 2026] [core:error] [pid 642360:tid 642589] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:52.272320 2026] [core:error] [pid 642360:tid 642589] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:52.296606 2026] [core:error] [pid 643253:tid 643469] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:52.296642 2026] [core:error] [pid 643253:tid 643469] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:55:53.083944 2026] [security2:error] [pid 643573:tid 643808] [client 185.223.152.54:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "propertyspro.com"] [uri "/"] [unique_id "amuCGfxWyxgRnoFKAJ_82QAAAnY"]
[Thu Jul 30 11:55:53.150547 2026] [security2:error] [pid 643573:tid 643761] [client 20.91.199.21:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/aa.php"] [unique_id "amuCGfxWyxgRnoFKAJ_82wAAAkc"]
[Thu Jul 30 11:55:53.462861 2026] [security2:error] [pid 643573:tid 643759] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCGPxWyxgRnoFKAJ_81AACRVQ"]
[Thu Jul 30 11:55:53.521968 2026] [security2:error] [pid 643253:tid 643499] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCGMjqbtjBYzqM1uYnRQAAAHM"]
[Thu Jul 30 11:55:53.793161 2026] [security2:error] [pid 643573:tid 643831] [client 185.223.152.54:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "propertyspro.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCGfxWyxgRnoFKAJ_84gAAAo0"]
[Thu Jul 30 11:55:53.824609 2026] [security2:error] [pid 643573:tid 643722] [client 20.91.199.21:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/aafewc0k.php"] [unique_id "amuCGfxWyxgRnoFKAJ_85AAAAiA"]
[Thu Jul 30 11:55:53.983914 2026] [security2:error] [pid 643573:tid 643738] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCGfxWyxgRnoFKAJ_83gAAAjA"]
[Thu Jul 30 11:55:54.476149 2026] [core:notice] [pid 643573:tid 643754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:54.541232 2026] [security2:error] [pid 643573:tid 643732] [client 185.223.152.54:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "propertyspro.com"] [uri "/media/system/js/core.js"] [unique_id "amuCGvxWyxgRnoFKAJ_87AAAAio"]
[Thu Jul 30 11:55:54.901077 2026] [security2:error] [pid 643573:tid 643734] [client 20.91.199.21:53503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/abcd.php"] [unique_id "amuCGvxWyxgRnoFKAJ_87wAAAiw"]
[Thu Jul 30 11:55:54.972273 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:54.979506 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:42440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCGsjqbtjBYzqM1uYnSQAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:55.722107 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:55.726582 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:42464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCG8jqbtjBYzqM1uYnUQAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:56.207951 2026] [security2:error] [pid 643573:tid 643713] [client 20.91.199.21:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/about.php"] [unique_id "amuCHPxWyxgRnoFKAJ_8-gAAAhc"]
[Thu Jul 30 11:55:56.455644 2026] [core:notice] [pid 643253:tid 643440] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:56.460503 2026] [security2:error] [pid 643253:tid 643440] [client 103.215.74.26:42470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCHMjqbtjBYzqM1uYnUwAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:56.851200 2026] [security2:error] [pid 643573:tid 643737] [client 216.73.216.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aakmiddleast.com"] [uri "/index.php"] [unique_id "amuCHPxWyxgRnoFKAJ_8_AACLwE"]
[Thu Jul 30 11:55:57.203618 2026] [core:notice] [pid 643573:tid 643753] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:57.208003 2026] [security2:error] [pid 643573:tid 643753] [client 103.215.74.26:42476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCHfxWyxgRnoFKAJ_8_wAAAj8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:57.871640 2026] [security2:error] [pid 643573:tid 643681] [remote 47.86.33.52:4076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuCHfxWyxgRnoFKAJ_9BgACUGQ"]
[Thu Jul 30 11:55:57.937387 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:57.941748 2026] [security2:error] [pid 643573:tid 643837] [client 103.215.74.26:42484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCHfxWyxgRnoFKAJ_9CAAAApM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:58.078056 2026] [security2:error] [pid 643253:tid 643418] [client 172.213.208.20:42369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/inputs.php"] [unique_id "amuCHsjqbtjBYzqM1uYnVQAAACI"]
[Thu Jul 30 11:55:58.665919 2026] [core:notice] [pid 642360:tid 642578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:58.669842 2026] [security2:error] [pid 642360:tid 642578] [client 103.215.74.26:42496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCHpSUkh3e5AhEJOB3vgAAAec"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:55:59.064531 2026] [core:notice] [pid 643573:tid 643819] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:59.413040 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:55:59.416971 2026] [security2:error] [pid 643573:tid 643786] [client 103.215.74.26:42510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCH_xWyxgRnoFKAJ_9IAAAAmA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:00.148322 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:00.152215 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:42516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCIPxWyxgRnoFKAJ_9NgAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:00.539740 2026] [security2:error] [pid 643573:tid 643813] [client 172.213.208.20:39461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/index.php"] [unique_id "amuCIPxWyxgRnoFKAJ_9QAAAAns"]
[Thu Jul 30 11:56:00.542027 2026] [security2:error] [pid 643573:tid 643781] [client 20.91.199.21:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amuCIPxWyxgRnoFKAJ_9QQAAAls"]
[Thu Jul 30 11:56:00.898362 2026] [core:notice] [pid 643573:tid 643736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:00.902702 2026] [security2:error] [pid 643573:tid 643736] [client 103.215.74.26:42528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCIPxWyxgRnoFKAJ_9SgAAAi4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:01.155910 2026] [security2:error] [pid 643573:tid 643808] [client 172.213.208.20:52539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9VgAAAnY"]
[Thu Jul 30 11:56:01.240151 2026] [security2:error] [pid 643573:tid 643766] [client 20.91.199.21:53051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/adminfuns.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9XwAAAkw"]
[Thu Jul 30 11:56:01.655536 2026] [core:notice] [pid 643573:tid 643722] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:01.666415 2026] [security2:error] [pid 643573:tid 643722] [client 103.215.74.26:42544] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCIfxWyxgRnoFKAJ_9aAAAAiA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:01.736512 2026] [security2:error] [pid 643573:tid 643761] [client 172.237.109.114:58484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9UQAAAkc"]
[Thu Jul 30 11:56:01.739819 2026] [security2:error] [pid 643573:tid 643811] [client 172.237.109.114:18963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9UAAAAnk"]
[Thu Jul 30 11:56:01.740385 2026] [security2:error] [pid 642360:tid 642611] [client 172.237.109.114:40852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIZSUkh3e5AhEJOB30wAAAgg"]
[Thu Jul 30 11:56:01.791721 2026] [security2:error] [pid 642360:tid 642570] [client 172.237.109.114:16091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIZSUkh3e5AhEJOB31AAAAd8"]
[Thu Jul 30 11:56:01.810381 2026] [security2:error] [pid 643573:tid 643777] [client 172.237.109.114:60802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9VQAAAlc"]
[Thu Jul 30 11:56:01.847043 2026] [security2:error] [pid 643573:tid 643779] [client 172.213.208.20:39473] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/1.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9bgAAAlk"]
[Thu Jul 30 11:56:01.847160 2026] [security2:error] [pid 643573:tid 643779] [client 172.213.208.20:39473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/1.php"] [unique_id "amuCIfxWyxgRnoFKAJ_9bgAAAlk"]
[Thu Jul 30 11:56:02.149992 2026] [core:notice] [pid 643573:tid 643630] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:02.374668 2026] [security2:error] [pid 643573:tid 643784] [client 176.241.66.87:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCIvxWyxgRnoFKAJ_9egAAAl4"]
[Thu Jul 30 11:56:02.374807 2026] [security2:error] [pid 643573:tid 643784] [client 176.241.66.87:50762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCIvxWyxgRnoFKAJ_9egAAAl4"]
[Thu Jul 30 11:56:02.417806 2026] [core:notice] [pid 643573:tid 643768] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:02.424438 2026] [security2:error] [pid 643573:tid 643768] [client 103.215.74.26:42560] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCIvxWyxgRnoFKAJ_9ewAAAk4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:02.783329 2026] [security2:error] [pid 643573:tid 643821] [client 20.91.199.21:53038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/albin.php"] [unique_id "amuCIvxWyxgRnoFKAJ_9gwAAAoM"]
[Thu Jul 30 11:56:03.147471 2026] [core:notice] [pid 643573:tid 643781] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:03.152638 2026] [security2:error] [pid 643573:tid 643781] [client 103.215.74.26:46542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCI_xWyxgRnoFKAJ_9igAAAls"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:03.174566 2026] [security2:error] [pid 643573:tid 643750] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCIvxWyxgRnoFKAJ_9fQACPDg"]
[Thu Jul 30 11:56:03.264516 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:03.888863 2026] [core:notice] [pid 642360:tid 642614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:03.892830 2026] [security2:error] [pid 642360:tid 642614] [client 103.215.74.26:46548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCI5SUkh3e5AhEJOB37wAAAgs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:04.099414 2026] [core:notice] [pid 643573:tid 643809] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:04.502060 2026] [security2:error] [pid 643573:tid 643740] [client 20.91.199.21:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/amfsqvgv.php"] [unique_id "amuCJPxWyxgRnoFKAJ_9rQAAAjI"]
[Thu Jul 30 11:56:05.043598 2026] [security2:error] [pid 643573:tid 643727] [client 20.91.199.21:36452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/ant.php"] [unique_id "amuCJfxWyxgRnoFKAJ_97gAAAiU"]
[Thu Jul 30 11:56:05.485650 2026] [proxy:error] [pid 642360:tid 642376] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:05.485707 2026] [proxy_http:error] [pid 642360:tid 642376] [remote 74.7.175.156:41440] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:05.486564 2026] [proxy:error] [pid 642360:tid 642376] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:05.486613 2026] [proxy_http:error] [pid 642360:tid 642376] [remote 74.7.175.156:41440] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:05.652266 2026] [security2:error] [pid 643573:tid 643729] [client 172.237.109.114:39866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_97wAAAic"]
[Thu Jul 30 11:56:05.666767 2026] [security2:error] [pid 643573:tid 643763] [client 172.237.109.114:49264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_98AAAAkk"]
[Thu Jul 30 11:56:05.803892 2026] [security2:error] [pid 643573:tid 643711] [client 50.6.43.217:36196] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-cron.php"] [unique_id "amuCJfxWyxgRnoFKAJ_9_AAAAhU"]
[Thu Jul 30 11:56:05.810153 2026] [security2:error] [pid 642360:tid 642492] [client 172.237.109.114:35171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJZSUkh3e5AhEJOB3-AAAAZE"]
[Thu Jul 30 11:56:05.810855 2026] [security2:error] [pid 643573:tid 643764] [client 172.237.109.114:47124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_98QAAAko"]
[Thu Jul 30 11:56:05.819358 2026] [security2:error] [pid 643573:tid 643830] [client 172.237.109.114:29950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_98gAAAow"]
[Thu Jul 30 11:56:05.929258 2026] [security2:error] [pid 643573:tid 643803] [client 20.91.199.21:53000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/appreciators.php"] [unique_id "amuCJfxWyxgRnoFKAJ_-BwAAAnE"]
[Thu Jul 30 11:56:06.034587 2026] [security2:error] [pid 643573:tid 643783] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCJfxWyxgRnoFKAJ_99AACXRE"]
[Thu Jul 30 11:56:06.065850 2026] [core:notice] [pid 643573:tid 643621] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:06.069660 2026] [security2:error] [pid 643573:tid 643737] [client 66.249.65.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/230/224"] [unique_id "amuCJfxWyxgRnoFKAJ_-AQACLyg"]
[Thu Jul 30 11:56:06.391082 2026] [security2:error] [pid 643573:tid 643743] [client 41.108.145.88:48432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCJvxWyxgRnoFKAJ_-CgAAAjU"], referer: http://pkf.jo
[Thu Jul 30 11:56:06.663870 2026] [security2:error] [pid 643573:tid 643821] [client 65.55.210.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dapperdangolf.com"] [uri "/index.php"] [unique_id "amuCJvxWyxgRnoFKAJ_-EQACg10"]
[Thu Jul 30 11:56:06.748677 2026] [security2:error] [pid 643573:tid 643807] [client 20.91.199.21:52395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/archive.php"] [unique_id "amuCJvxWyxgRnoFKAJ_-EgAAAnU"]
[Thu Jul 30 11:56:07.009322 2026] [proxy:error] [pid 643573:tid 643798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:07.009397 2026] [proxy_http:error] [pid 643573:tid 643798] [client 193.47.62.167:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:07.009947 2026] [proxy:error] [pid 643573:tid 643798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:07.010000 2026] [proxy_http:error] [pid 643573:tid 643798] [client 193.47.62.167:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:07.240312 2026] [core:notice] [pid 643573:tid 643633] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:07.772139 2026] [core:notice] [pid 643573:tid 643796] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:08.497544 2026] [security2:error] [pid 643253:tid 643371] [remote 57.141.0.5:64302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/626900273/feed/rss2/"] [unique_id "amuCKMjqbtjBYzqM1uYnWQAAOnQ"]
[Thu Jul 30 11:56:09.076094 2026] [security2:error] [pid 642360:tid 642616] [client 20.91.199.21:52356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/as.php"] [unique_id "amuCKZSUkh3e5AhEJOB4HgAAAg0"]
[Thu Jul 30 11:56:09.166308 2026] [security2:error] [pid 643573:tid 643645] [remote 151.158.180.11:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.180.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itrnetwork.org"] [uri "/wp-login.php"] [unique_id "amuCKfxWyxgRnoFKAJ_-JgACOkA"]
[Thu Jul 30 11:56:09.609749 2026] [core:notice] [pid 643573:tid 643786] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:09.616111 2026] [security2:error] [pid 643573:tid 643786] [client 103.215.74.26:46550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCKfxWyxgRnoFKAJ_-MAAAAmA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:10.085395 2026] [security2:error] [pid 642360:tid 642584] [client 172.213.208.20:44865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/plugin.php"] [unique_id "amuCKpSUkh3e5AhEJOB4KAAAAe0"]
[Thu Jul 30 11:56:10.365320 2026] [core:notice] [pid 643573:tid 643774] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:10.369241 2026] [security2:error] [pid 643573:tid 643774] [client 103.215.74.26:46554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCKvxWyxgRnoFKAJ_-PQAAAlQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:10.617197 2026] [security2:error] [pid 643573:tid 643800] [client 20.91.199.21:52353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/atomlib.php"] [unique_id "amuCKvxWyxgRnoFKAJ_-QQAAAm4"]
[Thu Jul 30 11:56:11.094218 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:11.098139 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:46564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "733"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCK_xWyxgRnoFKAJ_-SQAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:11.856447 2026] [core:notice] [pid 643573:tid 643745] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:11.861504 2026] [security2:error] [pid 643573:tid 643745] [client 103.215.74.26:46576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCK_xWyxgRnoFKAJ_-UQAAAjc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:12.029295 2026] [security2:error] [pid 643573:tid 643735] [client 20.91.199.21:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/autoload_classmap.php"] [unique_id "amuCLPxWyxgRnoFKAJ_-UwAAAi0"]
[Thu Jul 30 11:56:12.579509 2026] [security2:error] [pid 643573:tid 643822] [client 172.213.208.20:18152] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/1.php"] [unique_id "amuCLPxWyxgRnoFKAJ_-VgAAAoQ"]
[Thu Jul 30 11:56:12.579634 2026] [security2:error] [pid 643573:tid 643822] [client 172.213.208.20:18152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/1.php"] [unique_id "amuCLPxWyxgRnoFKAJ_-VgAAAoQ"]
[Thu Jul 30 11:56:12.616421 2026] [core:notice] [pid 643573:tid 643750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:12.620551 2026] [security2:error] [pid 643573:tid 643750] [client 103.215.74.26:46578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCLPxWyxgRnoFKAJ_-WAAAAjw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:13.019873 2026] [security2:error] [pid 643573:tid 643837] [client 176.241.66.87:33991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCLfxWyxgRnoFKAJ_-YAAAApM"]
[Thu Jul 30 11:56:13.020044 2026] [security2:error] [pid 643573:tid 643837] [client 176.241.66.87:33991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCLfxWyxgRnoFKAJ_-YAAAApM"]
[Thu Jul 30 11:56:13.343468 2026] [core:notice] [pid 642360:tid 642534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:13.348121 2026] [security2:error] [pid 642360:tid 642534] [client 103.215.74.26:44130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCLZSUkh3e5AhEJOB4TQAAAbs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:13.610782 2026] [security2:error] [pid 643573:tid 643714] [client 172.213.208.20:34081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/gg.php"] [unique_id "amuCLfxWyxgRnoFKAJ_-aQAAAhg"]
[Thu Jul 30 11:56:13.871129 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:36479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/bb.php"] [unique_id "amuCLfxWyxgRnoFKAJ_-bQAAAn8"]
[Thu Jul 30 11:56:14.084018 2026] [security2:error] [pid 643253:tid 643502] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCLcjqbtjBYzqM1uYnXAAAAHY"]
[Thu Jul 30 11:56:14.105023 2026] [core:notice] [pid 643573:tid 643761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:14.111538 2026] [security2:error] [pid 643573:tid 643761] [client 103.215.74.26:44138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCLvxWyxgRnoFKAJ_-bwAAAkc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:14.339161 2026] [security2:error] [pid 642360:tid 642610] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCLZSUkh3e5AhEJOB4UgAAAgc"]
[Thu Jul 30 11:56:14.841660 2026] [core:notice] [pid 643573:tid 643716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:14.845632 2026] [security2:error] [pid 643573:tid 643716] [client 103.215.74.26:44142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCLvxWyxgRnoFKAJ_-cgAAAho"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:16.165199 2026] [security2:error] [pid 643573:tid 643746] [client 20.91.199.21:36424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/bnm.php"] [unique_id "amuCMPxWyxgRnoFKAJ_-xwAAAjg"]
[Thu Jul 30 11:56:16.713710 2026] [security2:error] [pid 643573:tid 643751] [client 20.91.199.21:52998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/bootstrap.php"] [unique_id "amuCMPxWyxgRnoFKAJ_-0QAAAj0"]
[Thu Jul 30 11:56:17.726971 2026] [security2:error] [pid 642360:tid 642544] [client 20.91.199.21:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/buy.php"] [unique_id "amuCMZSUkh3e5AhEJOB4eQAAAcU"]
[Thu Jul 30 11:56:18.652779 2026] [security2:error] [pid 643253:tid 643397] [client 20.91.199.21:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amuCMsjqbtjBYzqM1uYnYAAAAA0"]
[Thu Jul 30 11:56:18.700821 2026] [security2:error] [pid 643253:tid 643417] [client 66.249.73.98:61057] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCMsjqbtjBYzqM1uYnXwAAACE"]
[Thu Jul 30 11:56:18.941399 2026] [core:notice] [pid 643573:tid 643632] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:19.578219 2026] [security2:error] [pid 642360:tid 642535] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCMpSUkh3e5AhEJOB4iQABvGE"]
[Thu Jul 30 11:56:19.792496 2026] [security2:error] [pid 643573:tid 643785] [client 173.249.217.7:41688] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuCM_xWyxgRnoFKAJ__EgAAAl8"]
[Thu Jul 30 11:56:19.792600 2026] [security2:error] [pid 643573:tid 643785] [client 173.249.217.7:41688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuCM_xWyxgRnoFKAJ__EgAAAl8"]
[Thu Jul 30 11:56:19.822314 2026] [security2:error] [pid 643253:tid 643402] [client 182.10.183.57:6994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCM8jqbtjBYzqM1uYnYwAAABI"], referer: http://pkf.jo
[Thu Jul 30 11:56:20.634345 2026] [core:notice] [pid 643573:tid 643723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:20.638554 2026] [security2:error] [pid 643573:tid 643723] [client 103.215.74.26:44146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCNPxWyxgRnoFKAJ__KwAAAiE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:20.717814 2026] [security2:error] [pid 643573:tid 643773] [client 203.175.125.36:58427] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "fireworkskenya.co.ke"] [uri "/wp-json/batch/v1"] [unique_id "amuCNPxWyxgRnoFKAJ__LQAAAlM"]
[Thu Jul 30 11:56:20.739228 2026] [security2:error] [pid 642360:tid 642538] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCNJSUkh3e5AhEJOB4mAAAAb8"]
[Thu Jul 30 11:56:21.412477 2026] [security2:error] [pid 643573:tid 643765] [client 172.213.208.20:45826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp.php"] [unique_id "amuCNfxWyxgRnoFKAJ__OwAAAks"]
[Thu Jul 30 11:56:21.426735 2026] [security2:error] [pid 643573:tid 643719] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCNPxWyxgRnoFKAJ__MAACHV4"]
[Thu Jul 30 11:56:21.903545 2026] [security2:error] [pid 642360:tid 642477] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCNZSUkh3e5AhEJOB4pQAB53Q"]
[Thu Jul 30 11:56:21.903745 2026] [security2:error] [pid 642360:tid 642578] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCNZSUkh3e5AhEJOB4pQAB53Q"]
[Thu Jul 30 11:56:22.020941 2026] [security2:error] [pid 643573:tid 643758] [client 108.52.149.162:56222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCNfxWyxgRnoFKAJ__TwAAAkQ"], referer: http://pkf.jo
[Thu Jul 30 11:56:22.380723 2026] [security2:error] [pid 643573:tid 643732] [client 172.213.208.20:32323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuCNvxWyxgRnoFKAJ__kAAAAio"]
[Thu Jul 30 11:56:22.932863 2026] [security2:error] [pid 643573:tid 643727] [client 223.123.111.153:12226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCNvxWyxgRnoFKAJ__kwAAAiU"], referer: http://pkf.jo
[Thu Jul 30 11:56:23.593075 2026] [security2:error] [pid 642360:tid 642589] [client 176.241.66.87:51862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCN5SUkh3e5AhEJOB4tQAAAfI"]
[Thu Jul 30 11:56:23.593219 2026] [security2:error] [pid 642360:tid 642589] [client 176.241.66.87:51862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCN5SUkh3e5AhEJOB4tQAAAfI"]
[Thu Jul 30 11:56:23.718122 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:49375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/class-wp-image.php"] [unique_id "amuCN5SUkh3e5AhEJOB4tgAAAew"]
[Thu Jul 30 11:56:24.479754 2026] [security2:error] [pid 643573:tid 643787] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "embassyofspaininpakistan.info"] [uri "/media/system/js/core.js"] [unique_id "amuCOPxWyxgRnoFKAJ__mgAAAmE"]
[Thu Jul 30 11:56:25.353669 2026] [security2:error] [pid 643573:tid 643801] [client 20.91.199.21:36417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/classsmtps.php"] [unique_id "amuCOfxWyxgRnoFKAJ__oAAAAm8"]
[Thu Jul 30 11:56:25.684868 2026] [security2:error] [pid 642360:tid 642497] [client 172.213.208.20:20401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/file.php"] [unique_id "amuCOZSUkh3e5AhEJOB4wwAAAZY"]
[Thu Jul 30 11:56:25.782451 2026] [core:notice] [pid 643253:tid 643504] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:26.137337 2026] [security2:error] [pid 643573:tid 643766] [client 20.91.199.21:56831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/classwithtostring.php"] [unique_id "amuCOvxWyxgRnoFKAJ__pAAAAkw"]
[Thu Jul 30 11:56:26.365592 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:26.372751 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:61518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCOvxWyxgRnoFKAJ__pQAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:27.103601 2026] [core:notice] [pid 642360:tid 642491] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:27.108128 2026] [security2:error] [pid 642360:tid 642491] [client 103.215.74.26:61526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCO5SUkh3e5AhEJOB40QAAAZA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:27.648599 2026] [security2:error] [pid 643573:tid 643722] [client 172.213.208.20:31243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuCO_xWyxgRnoFKAJ__sAAAAiA"]
[Thu Jul 30 11:56:27.885523 2026] [security2:error] [pid 643253:tid 643433] [client 20.91.199.21:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/config.php"] [unique_id "amuCO8jqbtjBYzqM1uYndAAAADE"]
[Thu Jul 30 11:56:28.526567 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.199.21:49797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/core.php"] [unique_id "amuCPMjqbtjBYzqM1uYndQAAAEA"]
[Thu Jul 30 11:56:28.696375 2026] [security2:error] [pid 642360:tid 642610] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuCPJSUkh3e5AhEJOB44AAAAgc"]
[Thu Jul 30 11:56:28.696498 2026] [security2:error] [pid 642360:tid 642610] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuCPJSUkh3e5AhEJOB44AAAAgc"]
[Thu Jul 30 11:56:29.073583 2026] [security2:error] [pid 643573:tid 643602] [remote 74.7.241.60:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/article.php"] [unique_id "amuCPfxWyxgRnoFKAJ__vQACWBU"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:56:29.180482 2026] [security2:error] [pid 643573:tid 643737] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuCPfxWyxgRnoFKAJ__vgAAAi8"]
[Thu Jul 30 11:56:29.180591 2026] [security2:error] [pid 643573:tid 643737] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuCPfxWyxgRnoFKAJ__vgAAAi8"]
[Thu Jul 30 11:56:29.500355 2026] [security2:error] [pid 642360:tid 642608] [client 172.213.208.20:24082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuCPZSUkh3e5AhEJOB46gAAAgU"]
[Thu Jul 30 11:56:29.697375 2026] [security2:error] [pid 642360:tid 642540] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/xstelth.php"] [unique_id "amuCPZSUkh3e5AhEJOB47gAAAcE"]
[Thu Jul 30 11:56:29.697495 2026] [security2:error] [pid 642360:tid 642540] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/xstelth.php"] [unique_id "amuCPZSUkh3e5AhEJOB47gAAAcE"]
[Thu Jul 30 11:56:29.959350 2026] [security2:error] [pid 643253:tid 643415] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCPcjqbtjBYzqM1uYndwAAAB8"]
[Thu Jul 30 11:56:29.995740 2026] [security2:error] [pid 643573:tid 643822] [client 20.91.199.21:49403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/css.php"] [unique_id "amuCPfxWyxgRnoFKAJ__wgAAAoQ"]
[Thu Jul 30 11:56:30.186144 2026] [security2:error] [pid 642360:tid 642498] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/584062352875874akp.php"] [unique_id "amuCPpSUkh3e5AhEJOB49QAAAZc"]
[Thu Jul 30 11:56:30.186257 2026] [security2:error] [pid 642360:tid 642498] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/584062352875874akp.php"] [unique_id "amuCPpSUkh3e5AhEJOB49QAAAZc"]
[Thu Jul 30 11:56:30.243737 2026] [security2:error] [pid 642360:tid 642574] [client 172.213.208.20:49771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/index/function.php"] [unique_id "amuCPpSUkh3e5AhEJOB49gAAAeM"]
[Thu Jul 30 11:56:30.333391 2026] [security2:error] [pid 643253:tid 643427] [client 50.6.43.217:28012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuCPcjqbtjBYzqM1uYneAAAACs"]
[Thu Jul 30 11:56:30.691259 2026] [security2:error] [pid 643253:tid 643414] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/newfile.php"] [unique_id "amuCPsjqbtjBYzqM1uYnewAAAB4"]
[Thu Jul 30 11:56:30.691424 2026] [security2:error] [pid 643253:tid 643414] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/newfile.php"] [unique_id "amuCPsjqbtjBYzqM1uYnewAAAB4"]
[Thu Jul 30 11:56:31.052263 2026] [security2:error] [pid 642360:tid 642598] [client 50.6.43.217:28026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuCPpSUkh3e5AhEJOB49wAAAfs"]
[Thu Jul 30 11:56:31.150515 2026] [security2:error] [pid 643253:tid 643489] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCPsjqbtjBYzqM1uYneQAAAGk"]
[Thu Jul 30 11:56:31.175879 2026] [security2:error] [pid 643573:tid 643836] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/tBEZGQz.php"] [unique_id "amuCP_xWyxgRnoFKAJ__yQAAApI"]
[Thu Jul 30 11:56:31.175968 2026] [security2:error] [pid 643573:tid 643836] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/tBEZGQz.php"] [unique_id "amuCP_xWyxgRnoFKAJ__yQAAApI"]
[Thu Jul 30 11:56:31.700272 2026] [security2:error] [pid 643573:tid 643712] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/phpinfo"] [unique_id "amuCP_xWyxgRnoFKAJ__zgAAAhY"]
[Thu Jul 30 11:56:31.960134 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/drykl.php"] [unique_id "amuCP_xWyxgRnoFKAJ__0gAAAn4"]
[Thu Jul 30 11:56:31.960259 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/drykl.php"] [unique_id "amuCP_xWyxgRnoFKAJ__0gAAAn4"]
[Thu Jul 30 11:56:32.089319 2026] [core:notice] [pid 643573:tid 643584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:32.494972 2026] [security2:error] [pid 643573:tid 643759] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuCQPxWyxgRnoFKAJ__2AAAAkU"]
[Thu Jul 30 11:56:32.557361 2026] [security2:error] [pid 642360:tid 642544] [client 20.91.199.21:52804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/database.php"] [unique_id "amuCQJSUkh3e5AhEJOB5DQAAAcU"]
[Thu Jul 30 11:56:32.857277 2026] [core:notice] [pid 643573:tid 643790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:32.861674 2026] [security2:error] [pid 643573:tid 643790] [client 103.215.74.26:61536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCQPxWyxgRnoFKAJ__3QAAAmQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:32.980851 2026] [security2:error] [pid 642360:tid 642530] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ls.php"] [unique_id "amuCQJSUkh3e5AhEJOB5EAAAAbc"]
[Thu Jul 30 11:56:32.980964 2026] [security2:error] [pid 642360:tid 642530] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ls.php"] [unique_id "amuCQJSUkh3e5AhEJOB5EAAAAbc"]
[Thu Jul 30 11:56:33.485352 2026] [security2:error] [pid 643573:tid 643764] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/dx.php"] [unique_id "amuCQfxWyxgRnoFKAJ__5QAAAko"]
[Thu Jul 30 11:56:33.485457 2026] [security2:error] [pid 643573:tid 643764] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/dx.php"] [unique_id "amuCQfxWyxgRnoFKAJ__5QAAAko"]
[Thu Jul 30 11:56:33.595214 2026] [core:notice] [pid 643573:tid 643720] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:33.599599 2026] [security2:error] [pid 643573:tid 643720] [client 103.215.74.26:17794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCQfxWyxgRnoFKAJ__5gAAAh4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:33.755005 2026] [security2:error] [pid 643573:tid 643833] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/mac.php"] [unique_id "amuCQfxWyxgRnoFKAJ__7QAAAo8"]
[Thu Jul 30 11:56:33.755136 2026] [security2:error] [pid 643573:tid 643833] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/mac.php"] [unique_id "amuCQfxWyxgRnoFKAJ__7QAAAo8"]
[Thu Jul 30 11:56:33.804844 2026] [core:error] [pid 643573:tid 643812] [client 74.7.230.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:56:33.804868 2026] [core:error] [pid 643573:tid 643812] [client 74.7.230.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:56:33.804987 2026] [security2:error] [pid 643573:tid 643812] [client 74.7.230.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuCQfxWyxgRnoFKAJ__8AAAAno"]
[Thu Jul 30 11:56:33.805596 2026] [security2:error] [pid 643573:tid 643756] [client 74.7.230.45:48142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuCQfxWyxgRnoFKAJ__7gACQms"]
[Thu Jul 30 11:56:34.000274 2026] [security2:error] [pid 642360:tid 642549] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCQZSUkh3e5AhEJOB5FAAAAco"]
[Thu Jul 30 11:56:34.299501 2026] [security2:error] [pid 643573:tid 643807] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/485.php"] [unique_id "amuCQvxWyxgRnoFKAJ__9QAAAnU"]
[Thu Jul 30 11:56:34.299589 2026] [security2:error] [pid 643573:tid 643807] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/485.php"] [unique_id "amuCQvxWyxgRnoFKAJ__9QAAAnU"]
[Thu Jul 30 11:56:34.302602 2026] [security2:error] [pid 643573:tid 643770] [client 176.241.66.87:52410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCQvxWyxgRnoFKAJ__9gAAAlA"]
[Thu Jul 30 11:56:34.302732 2026] [security2:error] [pid 643573:tid 643770] [client 176.241.66.87:52410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCQvxWyxgRnoFKAJ__9gAAAlA"]
[Thu Jul 30 11:56:34.340258 2026] [security2:error] [pid 643573:tid 643731] [client 110.249.202.228:36196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/robots.txt"] [unique_id "amuCQvxWyxgRnoFKAJ__9wAAAik"]
[Thu Jul 30 11:56:34.810531 2026] [security2:error] [pid 642360:tid 642581] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gelio1.php"] [unique_id "amuCQpSUkh3e5AhEJOB5HAAAAeo"]
[Thu Jul 30 11:56:34.810663 2026] [security2:error] [pid 642360:tid 642581] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gelio1.php"] [unique_id "amuCQpSUkh3e5AhEJOB5HAAAAeo"]
[Thu Jul 30 11:56:34.957454 2026] [security2:error] [pid 643573:tid 643831] [client 143.244.57.92:50964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kamiliacademy.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuCQvxWyxgRnoFKAJ8ABwAAAo0"]
[Thu Jul 30 11:56:35.330197 2026] [security2:error] [pid 642360:tid 642506] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/lp6.php"] [unique_id "amuCQ5SUkh3e5AhEJOB5IwAAAZ8"]
[Thu Jul 30 11:56:35.330329 2026] [security2:error] [pid 642360:tid 642506] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/lp6.php"] [unique_id "amuCQ5SUkh3e5AhEJOB5IwAAAZ8"]
[Thu Jul 30 11:56:35.765601 2026] [security2:error] [pid 643573:tid 643780] [client 143.244.57.92:45626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCQ_xWyxgRnoFKAJ8AEwAAAlo"]
[Thu Jul 30 11:56:35.876008 2026] [security2:error] [pid 643573:tid 643717] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuCQ_xWyxgRnoFKAJ8AFwAAAhs"]
[Thu Jul 30 11:56:35.876109 2026] [security2:error] [pid 643573:tid 643717] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuCQ_xWyxgRnoFKAJ8AFwAAAhs"]
[Thu Jul 30 11:56:36.423000 2026] [security2:error] [pid 642360:tid 642502] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuCRJSUkh3e5AhEJOB5KgAAAZs"]
[Thu Jul 30 11:56:36.529797 2026] [core:notice] [pid 643573:tid 643618] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:36.674525 2026] [security2:error] [pid 642360:tid 642592] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/w3llscc.php"] [unique_id "amuCRJSUkh3e5AhEJOB5KwAAAfU"]
[Thu Jul 30 11:56:36.674642 2026] [security2:error] [pid 642360:tid 642592] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/w3llscc.php"] [unique_id "amuCRJSUkh3e5AhEJOB5KwAAAfU"]
[Thu Jul 30 11:56:37.180839 2026] [security2:error] [pid 643573:tid 643734] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/miru3.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AJQAAAiw"]
[Thu Jul 30 11:56:37.180955 2026] [security2:error] [pid 643573:tid 643734] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/miru3.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AJQAAAiw"]
[Thu Jul 30 11:56:37.635317 2026] [security2:error] [pid 643573:tid 643794] [client 20.91.199.21:36028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/db.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AOQAAAmg"]
[Thu Jul 30 11:56:37.693033 2026] [security2:error] [pid 643573:tid 643823] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/autoload_classmap.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AOgAAAoU"]
[Thu Jul 30 11:56:37.693146 2026] [security2:error] [pid 643573:tid 643823] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/autoload_classmap.php"] [unique_id "amuCRfxWyxgRnoFKAJ8AOgAAAoU"]
[Thu Jul 30 11:56:38.223582 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuCRvxWyxgRnoFKAJ8ARgAAAjI"]
[Thu Jul 30 11:56:38.483120 2026] [security2:error] [pid 643573:tid 643755] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuCRvxWyxgRnoFKAJ8ATgAAAkE"]
[Thu Jul 30 11:56:38.483218 2026] [security2:error] [pid 643573:tid 643755] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuCRvxWyxgRnoFKAJ8ATgAAAkE"]
[Thu Jul 30 11:56:38.994919 2026] [security2:error] [pid 643253:tid 643446] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/av.php"] [unique_id "amuCRsjqbtjBYzqM1uYngQAAAD4"]
[Thu Jul 30 11:56:38.995032 2026] [security2:error] [pid 643253:tid 643446] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/av.php"] [unique_id "amuCRsjqbtjBYzqM1uYngQAAAD4"]
[Thu Jul 30 11:56:39.354747 2026] [core:notice] [pid 642360:tid 642498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:39.358830 2026] [security2:error] [pid 642360:tid 642498] [client 103.215.74.26:17806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCR5SUkh3e5AhEJOB5UgAAAZc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:39.534010 2026] [security2:error] [pid 642360:tid 642500] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuCR5SUkh3e5AhEJOB5VQAAAZk"]
[Thu Jul 30 11:56:39.607839 2026] [security2:error] [pid 643573:tid 643775] [client 143.244.57.92:45636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCR_xWyxgRnoFKAJ8AWwAAAlU"]
[Thu Jul 30 11:56:39.607953 2026] [security2:error] [pid 643573:tid 643775] [client 143.244.57.92:45636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCR_xWyxgRnoFKAJ8AWwAAAlU"]
[Thu Jul 30 11:56:39.849149 2026] [security2:error] [pid 642360:tid 642577] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.propertyspro.com"] [uri "/___proxy_subdomain_webdisk/wordpress/wp-admin/maint/"] [unique_id "amuCR5SUkh3e5AhEJOB5WAAAAeY"]
[Thu Jul 30 11:56:40.097183 2026] [core:notice] [pid 642360:tid 642593] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:40.101625 2026] [security2:error] [pid 642360:tid 642593] [client 103.215.74.26:17816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCSJSUkh3e5AhEJOB5XQAAAfY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:40.134753 2026] [security2:error] [pid 642360:tid 642562] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/tiny.php"] [unique_id "amuCSJSUkh3e5AhEJOB5XgAAAdc"]
[Thu Jul 30 11:56:40.134838 2026] [security2:error] [pid 642360:tid 642562] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/tiny.php"] [unique_id "amuCSJSUkh3e5AhEJOB5XgAAAdc"]
[Thu Jul 30 11:56:40.165567 2026] [security2:error] [pid 643573:tid 643773] [client 143.244.57.92:45638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCSPxWyxgRnoFKAJ8AXwAAAlM"]
[Thu Jul 30 11:56:40.165671 2026] [security2:error] [pid 643573:tid 643773] [client 143.244.57.92:45638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuCSPxWyxgRnoFKAJ8AXwAAAlM"]
[Thu Jul 30 11:56:40.654511 2026] [security2:error] [pid 643573:tid 643731] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "emmanueljrodriguez.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCSPxWyxgRnoFKAJ8AYwAAAik"]
[Thu Jul 30 11:56:40.659379 2026] [security2:error] [pid 642360:tid 642546] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuCSJSUkh3e5AhEJOB5ZAAAAcc"]
[Thu Jul 30 11:56:40.659491 2026] [security2:error] [pid 642360:tid 642546] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuCSJSUkh3e5AhEJOB5ZAAAAcc"]
[Thu Jul 30 11:56:40.819107 2026] [core:notice] [pid 642360:tid 642554] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:40.823399 2026] [security2:error] [pid 642360:tid 642554] [client 103.215.74.26:17822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCSJSUkh3e5AhEJOB5ZgAAAc8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:41.156419 2026] [security2:error] [pid 643573:tid 643824] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/zrrhj.php"] [unique_id "amuCSfxWyxgRnoFKAJ8AbwAAAoY"]
[Thu Jul 30 11:56:41.156514 2026] [security2:error] [pid 643573:tid 643824] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/zrrhj.php"] [unique_id "amuCSfxWyxgRnoFKAJ8AbwAAAoY"]
[Thu Jul 30 11:56:41.665269 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuCSfxWyxgRnoFKAJ8AcgAAAn4"]
[Thu Jul 30 11:56:41.665421 2026] [security2:error] [pid 643573:tid 643816] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuCSfxWyxgRnoFKAJ8AcgAAAn4"]
[Thu Jul 30 11:56:42.174486 2026] [security2:error] [pid 642360:tid 642535] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wpgum.php"] [unique_id "amuCSpSUkh3e5AhEJOB5dQAAAbw"]
[Thu Jul 30 11:56:42.174607 2026] [security2:error] [pid 642360:tid 642535] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wpgum.php"] [unique_id "amuCSpSUkh3e5AhEJOB5dQAAAbw"]
[Thu Jul 30 11:56:42.670292 2026] [security2:error] [pid 643573:tid 643809] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ywwbf.php"] [unique_id "amuCSvxWyxgRnoFKAJ8AewAAAnc"]
[Thu Jul 30 11:56:42.670398 2026] [security2:error] [pid 643573:tid 643809] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ywwbf.php"] [unique_id "amuCSvxWyxgRnoFKAJ8AewAAAnc"]
[Thu Jul 30 11:56:43.180036 2026] [security2:error] [pid 642360:tid 642502] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/xoldj.php"] [unique_id "amuCS5SUkh3e5AhEJOB5fwAAAZs"]
[Thu Jul 30 11:56:43.180184 2026] [security2:error] [pid 642360:tid 642502] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/xoldj.php"] [unique_id "amuCS5SUkh3e5AhEJOB5fwAAAZs"]
[Thu Jul 30 11:56:44.142184 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/f35.php"] [unique_id "amuCTPxWyxgRnoFKAJ8AjAAAAmE"]
[Thu Jul 30 11:56:44.142319 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/f35.php"] [unique_id "amuCTPxWyxgRnoFKAJ8AjAAAAmE"]
[Thu Jul 30 11:56:44.674328 2026] [security2:error] [pid 642360:tid 642529] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCTJSUkh3e5AhEJOB5jgAAAbY"]
[Thu Jul 30 11:56:44.685682 2026] [security2:error] [pid 643573:tid 643806] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gk.php"] [unique_id "amuCTPxWyxgRnoFKAJ8AjgAAAnQ"]
[Thu Jul 30 11:56:44.685815 2026] [security2:error] [pid 643573:tid 643806] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gk.php"] [unique_id "amuCTPxWyxgRnoFKAJ8AjgAAAnQ"]
[Thu Jul 30 11:56:44.725388 2026] [security2:error] [pid 643253:tid 643462] [client 35.239.2.194:52916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "alnukhbafurnituremovers.cc"] [uri "/"] [unique_id "amuCTMjqbtjBYzqM1uYnhwAAAE4"]
[Thu Jul 30 11:56:45.045077 2026] [security2:error] [pid 643573:tid 643793] [client 176.241.66.87:36053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCTfxWyxgRnoFKAJ8AkQAAAmc"]
[Thu Jul 30 11:56:45.045235 2026] [security2:error] [pid 643573:tid 643793] [client 176.241.66.87:36053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCTfxWyxgRnoFKAJ8AkQAAAmc"]
[Thu Jul 30 11:56:45.226871 2026] [security2:error] [pid 642360:tid 642507] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/584062352875874akp.php"] [unique_id "amuCTZSUkh3e5AhEJOB5mQAAAaA"]
[Thu Jul 30 11:56:45.226996 2026] [security2:error] [pid 642360:tid 642507] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/584062352875874akp.php"] [unique_id "amuCTZSUkh3e5AhEJOB5mQAAAaA"]
[Thu Jul 30 11:56:45.485117 2026] [security2:error] [pid 642360:tid 642585] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCTJSUkh3e5AhEJOB5kwAB7gc"]
[Thu Jul 30 11:56:45.711001 2026] [security2:error] [pid 643573:tid 643719] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wper3.php"] [unique_id "amuCTfxWyxgRnoFKAJ8AmQAAAh0"]
[Thu Jul 30 11:56:45.711106 2026] [security2:error] [pid 643573:tid 643719] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wper3.php"] [unique_id "amuCTfxWyxgRnoFKAJ8AmQAAAh0"]
[Thu Jul 30 11:56:46.224234 2026] [security2:error] [pid 643573:tid 643772] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/bthil.php"] [unique_id "amuCTvxWyxgRnoFKAJ8AmwAAAlI"]
[Thu Jul 30 11:56:46.224343 2026] [security2:error] [pid 643573:tid 643772] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/bthil.php"] [unique_id "amuCTvxWyxgRnoFKAJ8AmwAAAlI"]
[Thu Jul 30 11:56:46.295757 2026] [security2:error] [pid 642360:tid 642543] [client 172.213.208.20:29089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/aaa.php"] [unique_id "amuCTpSUkh3e5AhEJOB5nwAAAcQ"]
[Thu Jul 30 11:56:46.554954 2026] [core:notice] [pid 643253:tid 643416] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:46.559384 2026] [security2:error] [pid 643253:tid 643416] [client 103.215.74.26:57824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCTsjqbtjBYzqM1uYnjAAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:46.740776 2026] [security2:error] [pid 642360:tid 642568] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wyzer1.php"] [unique_id "amuCTpSUkh3e5AhEJOB5pQAAAd0"]
[Thu Jul 30 11:56:46.740868 2026] [security2:error] [pid 642360:tid 642568] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wyzer1.php"] [unique_id "amuCTpSUkh3e5AhEJOB5pQAAAd0"]
[Thu Jul 30 11:56:47.223836 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/mh.php"] [unique_id "amuCT_xWyxgRnoFKAJ8AoQAAAjI"]
[Thu Jul 30 11:56:47.223928 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/mh.php"] [unique_id "amuCT_xWyxgRnoFKAJ8AoQAAAjI"]
[Thu Jul 30 11:56:47.303466 2026] [core:notice] [pid 643573:tid 643730] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:47.307572 2026] [security2:error] [pid 643573:tid 643730] [client 103.215.74.26:57830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCT_xWyxgRnoFKAJ8AogAAAig"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:47.380948 2026] [proxy:error] [pid 642360:tid 642482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:47.381019 2026] [proxy_http:error] [pid 642360:tid 642482] [remote 74.7.230.58:38990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:47.381574 2026] [proxy:error] [pid 642360:tid 642482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:56:47.381616 2026] [proxy_http:error] [pid 642360:tid 642482] [remote 74.7.230.58:38990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:56:47.547255 2026] [security2:error] [pid 642360:tid 642566] [client 172.213.208.20:33522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/getid3-core.php"] [unique_id "amuCT5SUkh3e5AhEJOB5sAAAAds"]
[Thu Jul 30 11:56:47.735464 2026] [security2:error] [pid 642360:tid 642554] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuCT5SUkh3e5AhEJOB5sQAAAc8"]
[Thu Jul 30 11:56:47.735583 2026] [security2:error] [pid 642360:tid 642554] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuCT5SUkh3e5AhEJOB5sQAAAc8"]
[Thu Jul 30 11:56:48.061259 2026] [core:notice] [pid 642360:tid 642595] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:48.065456 2026] [security2:error] [pid 642360:tid 642595] [client 103.215.74.26:57834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "734"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCUJSUkh3e5AhEJOB5twAAAfg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:48.250592 2026] [security2:error] [pid 642360:tid 642525] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.propertyspro.com"] [uri "/1.php"] [unique_id "amuCUJSUkh3e5AhEJOB5uAAAAbI"]
[Thu Jul 30 11:56:48.250704 2026] [security2:error] [pid 642360:tid 642525] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/1.php"] [unique_id "amuCUJSUkh3e5AhEJOB5uAAAAbI"]
[Thu Jul 30 11:56:48.250815 2026] [security2:error] [pid 642360:tid 642525] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/1.php"] [unique_id "amuCUJSUkh3e5AhEJOB5uAAAAbI"]
[Thu Jul 30 11:56:48.489599 2026] [security2:error] [pid 643573:tid 643720] [client 37.120.155.179:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuCUPxWyxgRnoFKAJ8ArAAAAh4"]
[Thu Jul 30 11:56:48.489710 2026] [security2:error] [pid 643573:tid 643720] [client 37.120.155.179:51796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuCUPxWyxgRnoFKAJ8ArAAAAh4"]
[Thu Jul 30 11:56:48.633804 2026] [core:notice] [pid 642360:tid 642501] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:48.756686 2026] [security2:error] [pid 643253:tid 643429] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/chosen.php"] [unique_id "amuCUMjqbtjBYzqM1uYnjgAAAC0"]
[Thu Jul 30 11:56:48.756851 2026] [security2:error] [pid 643253:tid 643429] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/chosen.php"] [unique_id "amuCUMjqbtjBYzqM1uYnjgAAAC0"]
[Thu Jul 30 11:56:48.799450 2026] [core:notice] [pid 642360:tid 642495] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:48.803449 2026] [security2:error] [pid 642360:tid 642495] [client 103.215.74.26:57840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "731"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCUJSUkh3e5AhEJOB5vwAAAZQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:49.006459 2026] [security2:error] [pid 643573:tid 643774] [client 172.213.208.20:33479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/adminer.php"] [unique_id "amuCUfxWyxgRnoFKAJ8ArwAAAlQ"]
[Thu Jul 30 11:56:49.047400 2026] [core:notice] [pid 643573:tid 643753] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:49.050403 2026] [security2:error] [pid 643573:tid 643753] [client 66.249.65.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/81/84"] [unique_id "amuCUPxWyxgRnoFKAJ8ArgAAAj8"]
[Thu Jul 30 11:56:49.258078 2026] [security2:error] [pid 642360:tid 642575] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/sd.php"] [unique_id "amuCUZSUkh3e5AhEJOB5xAAAAeQ"]
[Thu Jul 30 11:56:49.258219 2026] [security2:error] [pid 642360:tid 642575] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/sd.php"] [unique_id "amuCUZSUkh3e5AhEJOB5xAAAAeQ"]
[Thu Jul 30 11:56:49.564080 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:49.568802 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:57854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCUcjqbtjBYzqM1uYnkAAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:49.628768 2026] [security2:error] [pid 643253:tid 643389] [client 20.91.199.21:49378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/default.php"] [unique_id "amuCUcjqbtjBYzqM1uYnkQAAAAU"]
[Thu Jul 30 11:56:49.764934 2026] [security2:error] [pid 642360:tid 642524] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/z60.php"] [unique_id "amuCUZSUkh3e5AhEJOB5yQAAAbE"]
[Thu Jul 30 11:56:49.765095 2026] [security2:error] [pid 642360:tid 642524] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/z60.php"] [unique_id "amuCUZSUkh3e5AhEJOB5yQAAAbE"]
[Thu Jul 30 11:56:50.016019 2026] [core:notice] [pid 643573:tid 643628] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:50.246741 2026] [security2:error] [pid 642360:tid 642582] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/home.php"] [unique_id "amuCUpSUkh3e5AhEJOB50AAAAes"]
[Thu Jul 30 11:56:50.246860 2026] [security2:error] [pid 642360:tid 642582] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/home.php"] [unique_id "amuCUpSUkh3e5AhEJOB50AAAAes"]
[Thu Jul 30 11:56:50.297105 2026] [core:notice] [pid 643573:tid 643746] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:50.304052 2026] [security2:error] [pid 643573:tid 643746] [client 103.215.74.26:57858] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCUvxWyxgRnoFKAJ8AuAAAAjg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:50.727229 2026] [security2:error] [pid 643573:tid 643793] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ws58.php"] [unique_id "amuCUvxWyxgRnoFKAJ8AvgAAAmc"]
[Thu Jul 30 11:56:50.727345 2026] [security2:error] [pid 643573:tid 643793] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ws58.php"] [unique_id "amuCUvxWyxgRnoFKAJ8AvgAAAmc"]
[Thu Jul 30 11:56:50.800512 2026] [core:notice] [pid 643573:tid 643640] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:50.963332 2026] [security2:error] [pid 643573:tid 643727] [client 119.73.97.132:30991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuCUvxWyxgRnoFKAJ8AuQACJQc"], referer: https://www.urwru.club/wp-admin/post.php?post=685&action=elementor
[Thu Jul 30 11:56:51.020927 2026] [core:notice] [pid 643573:tid 643837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:51.027603 2026] [security2:error] [pid 643573:tid 643837] [client 103.215.74.26:57874] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCU_xWyxgRnoFKAJ8AwwAAApM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:51.042899 2026] [core:notice] [pid 643573:tid 643611] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:51.253270 2026] [security2:error] [pid 642360:tid 642541] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/gulu.php"] [unique_id "amuCU5SUkh3e5AhEJOB52AAAAcI"]
[Thu Jul 30 11:56:51.253401 2026] [security2:error] [pid 642360:tid 642541] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/gulu.php"] [unique_id "amuCU5SUkh3e5AhEJOB52AAAAcI"]
[Thu Jul 30 11:56:51.746048 2026] [security2:error] [pid 642360:tid 642540] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuCU5SUkh3e5AhEJOB54AAAAcE"]
[Thu Jul 30 11:56:51.746158 2026] [security2:error] [pid 642360:tid 642540] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuCU5SUkh3e5AhEJOB54AAAAcE"]
[Thu Jul 30 11:56:51.788774 2026] [core:notice] [pid 643573:tid 643831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:51.793161 2026] [security2:error] [pid 643573:tid 643831] [client 103.215.74.26:57886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCU_xWyxgRnoFKAJ8A0QAAAo0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:52.156713 2026] [security2:error] [pid 643253:tid 643256] [remote 34.9.172.22:10112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.172.9.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/about"] [unique_id "amuCU8jqbtjBYzqM1uYnlgAAGgE"]
[Thu Jul 30 11:56:52.274654 2026] [security2:error] [pid 643573:tid 643762] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wpls.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A1QAAAkg"]
[Thu Jul 30 11:56:52.274762 2026] [security2:error] [pid 643573:tid 643762] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wpls.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A1QAAAkg"]
[Thu Jul 30 11:56:52.645678 2026] [security2:error] [pid 643573:tid 643782] [client 20.91.199.21:36430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/dropdown.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A2wAAAlw"]
[Thu Jul 30 11:56:52.768463 2026] [security2:error] [pid 643573:tid 643753] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/php.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A3wAAAj8"]
[Thu Jul 30 11:56:52.768555 2026] [security2:error] [pid 643573:tid 643753] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/php.php"] [unique_id "amuCVPxWyxgRnoFKAJ8A3wAAAj8"]
[Thu Jul 30 11:56:53.069144 2026] [core:notice] [pid 643253:tid 643257] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.118402 2026] [core:notice] [pid 643573:tid 643631] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.285519 2026] [security2:error] [pid 643573:tid 643769] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/100.php"] [unique_id "amuCVfxWyxgRnoFKAJ8A4gAAAk8"]
[Thu Jul 30 11:56:53.285624 2026] [security2:error] [pid 643573:tid 643769] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/100.php"] [unique_id "amuCVfxWyxgRnoFKAJ8A4gAAAk8"]
[Thu Jul 30 11:56:53.339066 2026] [core:notice] [pid 643253:tid 643258] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.352490 2026] [security2:error] [pid 643253:tid 643452] [client 20.91.199.21:36460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/edit.php"] [unique_id "amuCVcjqbtjBYzqM1uYnmgAAAEQ"]
[Thu Jul 30 11:56:53.387528 2026] [core:notice] [pid 643573:tid 643639] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.713422 2026] [core:notice] [pid 642360:tid 642373] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:53.783682 2026] [security2:error] [pid 642360:tid 642497] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/BDKR28WP.php"] [unique_id "amuCVZSUkh3e5AhEJOB5-AAAAZY"]
[Thu Jul 30 11:56:53.783830 2026] [security2:error] [pid 642360:tid 642497] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/BDKR28WP.php"] [unique_id "amuCVZSUkh3e5AhEJOB5-AAAAZY"]
[Thu Jul 30 11:56:53.966998 2026] [security2:error] [pid 643573:tid 643635] [remote 121.200.217.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.217.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espairsa.com"] [uri "/wp-login.php"] [unique_id "amuCVfxWyxgRnoFKAJ8A6AACXjY"]
[Thu Jul 30 11:56:55.347236 2026] [security2:error] [pid 643573:tid 643636] [remote 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A8gACFzc"]
[Thu Jul 30 11:56:55.347423 2026] [security2:error] [pid 643573:tid 643713] [client 2407:d000:1c:9d56:69b8:2b43:16e9:e505:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A8gACFzc"]
[Thu Jul 30 11:56:55.377009 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/browse.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A8wAAAlk"]
[Thu Jul 30 11:56:55.377107 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/browse.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A8wAAAlk"]
[Thu Jul 30 11:56:55.571946 2026] [security2:error] [pid 643253:tid 643403] [client 176.241.66.87:53504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCV8jqbtjBYzqM1uYnnAAAABM"]
[Thu Jul 30 11:56:55.572099 2026] [security2:error] [pid 643253:tid 643403] [client 176.241.66.87:53504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCV8jqbtjBYzqM1uYnnAAAABM"]
[Thu Jul 30 11:56:55.709321 2026] [security2:error] [pid 643573:tid 643739] [client 173.249.217.7:56546] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A9AAAAjE"]
[Thu Jul 30 11:56:55.709426 2026] [security2:error] [pid 643573:tid 643739] [client 173.249.217.7:56546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A9AAAAjE"]
[Thu Jul 30 11:56:55.886134 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-good.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A-QAAAjI"]
[Thu Jul 30 11:56:55.886263 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-good.php"] [unique_id "amuCV_xWyxgRnoFKAJ8A-QAAAjI"]
[Thu Jul 30 11:56:55.995272 2026] [security2:error] [pid 643253:tid 643413] [client 172.213.208.20:6938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/alfa.php"] [unique_id "amuCV8jqbtjBYzqM1uYnnQAAAB0"]
[Thu Jul 30 11:56:56.397229 2026] [security2:error] [pid 642360:tid 642548] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/8573.php"] [unique_id "amuCWJSUkh3e5AhEJOB6DAAAAck"]
[Thu Jul 30 11:56:56.397352 2026] [security2:error] [pid 642360:tid 642548] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/8573.php"] [unique_id "amuCWJSUkh3e5AhEJOB6DAAAAck"]
[Thu Jul 30 11:56:56.659387 2026] [security2:error] [pid 642360:tid 642522] [client 5.161.177.47:49510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCV5SUkh3e5AhEJOB6BgAAAa8"], referer: https://globalmarks.pk/
[Thu Jul 30 11:56:57.334609 2026] [security2:error] [pid 643573:tid 643773] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/install.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BCAAAAlM"]
[Thu Jul 30 11:56:57.334722 2026] [security2:error] [pid 643573:tid 643773] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/install.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BCAAAAlM"]
[Thu Jul 30 11:56:57.533731 2026] [core:notice] [pid 643573:tid 643763] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:57.537599 2026] [security2:error] [pid 643573:tid 643763] [client 103.215.74.26:9528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCWfxWyxgRnoFKAJ8BCwAAAkk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:57.856718 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/classwithtostring.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BDwAAAiY"]
[Thu Jul 30 11:56:57.856824 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/classwithtostring.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BDwAAAiY"]
[Thu Jul 30 11:56:57.957866 2026] [security2:error] [pid 643573:tid 643817] [client 20.91.199.21:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/f35.php"] [unique_id "amuCWfxWyxgRnoFKAJ8BEQAAAn8"]
[Thu Jul 30 11:56:58.298419 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:56:58.304970 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:9532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCWpSUkh3e5AhEJOB6GAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:56:58.393258 2026] [security2:error] [pid 643573:tid 643738] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ohct.php"] [unique_id "amuCWvxWyxgRnoFKAJ8BEgAAAjA"]
[Thu Jul 30 11:56:58.393380 2026] [security2:error] [pid 643573:tid 643738] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ohct.php"] [unique_id "amuCWvxWyxgRnoFKAJ8BEgAAAjA"]
[Thu Jul 30 11:56:58.686435 2026] [security2:error] [pid 642360:tid 642610] [client 20.91.199.21:49393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bonafideadvisors.com"] [uri "/f7.php"] [unique_id "amuCWpSUkh3e5AhEJOB6HwAAAgc"]
[Thu Jul 30 11:56:58.891411 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/bless.php"] [unique_id "amuCWvxWyxgRnoFKAJ8BFAAAAlk"]
[Thu Jul 30 11:56:58.891539 2026] [security2:error] [pid 643573:tid 643779] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/bless.php"] [unique_id "amuCWvxWyxgRnoFKAJ8BFAAAAlk"]
[Thu Jul 30 11:56:59.405567 2026] [security2:error] [pid 643573:tid 643732] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/about.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BFwAAAio"]
[Thu Jul 30 11:56:59.405695 2026] [security2:error] [pid 643573:tid 643732] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/about.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BFwAAAio"]
[Thu Jul 30 11:56:59.781932 2026] [security2:error] [pid 643573:tid 643791] [client 172.213.208.20:22114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BGgAAAmU"]
[Thu Jul 30 11:56:59.913386 2026] [security2:error] [pid 643573:tid 643757] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BGwAAAkM"]
[Thu Jul 30 11:56:59.913512 2026] [security2:error] [pid 643573:tid 643757] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuCW_xWyxgRnoFKAJ8BGwAAAkM"]
[Thu Jul 30 11:57:00.459035 2026] [security2:error] [pid 643573:tid 643800] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ta0ol.php"] [unique_id "amuCXPxWyxgRnoFKAJ8BHgAAAm4"]
[Thu Jul 30 11:57:00.459214 2026] [security2:error] [pid 643573:tid 643800] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ta0ol.php"] [unique_id "amuCXPxWyxgRnoFKAJ8BHgAAAm4"]
[Thu Jul 30 11:57:01.011162 2026] [security2:error] [pid 643573:tid 643756] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/sa.php7"] [unique_id "amuCXfxWyxgRnoFKAJ8BIgAAAkI"]
[Thu Jul 30 11:57:01.011342 2026] [security2:error] [pid 643573:tid 643756] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/sa.php7"] [unique_id "amuCXfxWyxgRnoFKAJ8BIgAAAkI"]
[Thu Jul 30 11:57:01.526869 2026] [security2:error] [pid 642360:tid 642584] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-class.php"] [unique_id "amuCXZSUkh3e5AhEJOB6NQAAAe0"]
[Thu Jul 30 11:57:01.526998 2026] [security2:error] [pid 642360:tid 642584] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-class.php"] [unique_id "amuCXZSUkh3e5AhEJOB6NQAAAe0"]
[Thu Jul 30 11:57:02.048577 2026] [security2:error] [pid 643573:tid 643784] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/8.php"] [unique_id "amuCXvxWyxgRnoFKAJ8BKwAAAl4"]
[Thu Jul 30 11:57:02.048675 2026] [security2:error] [pid 643573:tid 643784] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/8.php"] [unique_id "amuCXvxWyxgRnoFKAJ8BKwAAAl4"]
[Thu Jul 30 11:57:02.570985 2026] [security2:error] [pid 643573:tid 643819] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/bootstrap.php"] [unique_id "amuCXvxWyxgRnoFKAJ8BLgAAAoE"]
[Thu Jul 30 11:57:02.571108 2026] [security2:error] [pid 643573:tid 643819] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/bootstrap.php"] [unique_id "amuCXvxWyxgRnoFKAJ8BLgAAAoE"]
[Thu Jul 30 11:57:03.095933 2026] [security2:error] [pid 643573:tid 643766] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-blog-header.php"] [unique_id "amuCX_xWyxgRnoFKAJ8BMQAAAkw"]
[Thu Jul 30 11:57:03.096060 2026] [security2:error] [pid 643573:tid 643766] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-blog-header.php"] [unique_id "amuCX_xWyxgRnoFKAJ8BMQAAAkw"]
[Thu Jul 30 11:57:03.145718 2026] [security2:error] [pid 643573:tid 643823] [client 172.213.208.20:16900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuCX_xWyxgRnoFKAJ8BMgAAAoU"]
[Thu Jul 30 11:57:03.615616 2026] [security2:error] [pid 643253:tid 643459] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/aa.php"] [unique_id "amuCX8jqbtjBYzqM1uYnoAAAAEs"]
[Thu Jul 30 11:57:03.615725 2026] [security2:error] [pid 643253:tid 643459] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/aa.php"] [unique_id "amuCX8jqbtjBYzqM1uYnoAAAAEs"]
[Thu Jul 30 11:57:04.025061 2026] [core:notice] [pid 642360:tid 642567] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:04.028970 2026] [security2:error] [pid 642360:tid 642567] [client 103.215.74.26:45712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYJSUkh3e5AhEJOB6XQAAAdw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:04.074695 2026] [security2:error] [pid 643253:tid 643507] [client 47.128.114.17:49670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "globalmarks.pk"] [uri "/robots.txt"] [unique_id "amuCYMjqbtjBYzqM1uYnogAAAHs"]
[Thu Jul 30 11:57:04.117582 2026] [security2:error] [pid 643573:tid 643808] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/tx79.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BNgAAAnY"]
[Thu Jul 30 11:57:04.117719 2026] [security2:error] [pid 643573:tid 643808] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/tx79.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BNgAAAnY"]
[Thu Jul 30 11:57:04.610238 2026] [security2:error] [pid 643573:tid 643780] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/motu.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BOwAAAlo"]
[Thu Jul 30 11:57:04.610444 2026] [security2:error] [pid 643573:tid 643780] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/motu.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BOwAAAlo"]
[Thu Jul 30 11:57:04.723550 2026] [security2:error] [pid 643573:tid 643727] [client 38.22.182.134:52912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BOAAAAiU"], referer: http://pkf.jo
[Thu Jul 30 11:57:04.765600 2026] [core:notice] [pid 643573:tid 643758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:04.769441 2026] [security2:error] [pid 643573:tid 643758] [client 103.215.74.26:45722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYPxWyxgRnoFKAJ8BPQAAAkQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:05.029747 2026] [security2:error] [pid 642360:tid 642548] [client 123.26.92.241:50377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCYJSUkh3e5AhEJOB6XgAAAck"], referer: http://pkf.jo
[Thu Jul 30 11:57:05.152479 2026] [core:notice] [pid 643573:tid 643671] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:05.274135 2026] [security2:error] [pid 643573:tid 643722] [client 181.211.104.23:16419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCYPxWyxgRnoFKAJ8BPgAAAiA"], referer: http://pkf.jo
[Thu Jul 30 11:57:05.325242 2026] [core:notice] [pid 643573:tid 643717] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:05.484481 2026] [core:notice] [pid 643573:tid 643803] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:05.488434 2026] [security2:error] [pid 643573:tid 643803] [client 103.215.74.26:45730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYfxWyxgRnoFKAJ8BUwAAAnE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:05.499490 2026] [security2:error] [pid 642360:tid 642536] [client 201.216.101.53:64143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCYZSUkh3e5AhEJOB6aQAAAb0"], referer: http://pkf.jo
[Thu Jul 30 11:57:05.580624 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-head.php"] [unique_id "amuCYfxWyxgRnoFKAJ8BVQAAAmE"]
[Thu Jul 30 11:57:05.580724 2026] [security2:error] [pid 643573:tid 643787] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-head.php"] [unique_id "amuCYfxWyxgRnoFKAJ8BVQAAAmE"]
[Thu Jul 30 11:57:05.979668 2026] [security2:error] [pid 643573:tid 643783] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCYfxWyxgRnoFKAJ8BTwACXT8"]
[Thu Jul 30 11:57:06.072612 2026] [security2:error] [pid 643573:tid 643801] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BWQAAAm8"]
[Thu Jul 30 11:57:06.072747 2026] [security2:error] [pid 643573:tid 643801] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BWQAAAm8"]
[Thu Jul 30 11:57:06.217778 2026] [core:notice] [pid 643573:tid 643822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:06.221745 2026] [security2:error] [pid 643573:tid 643822] [client 103.215.74.26:45744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYvxWyxgRnoFKAJ8BWgAAAoQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:06.266268 2026] [security2:error] [pid 643573:tid 643806] [client 176.241.66.87:37495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BWwAAAnQ"]
[Thu Jul 30 11:57:06.266396 2026] [security2:error] [pid 643573:tid 643806] [client 176.241.66.87:37495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BWwAAAnQ"]
[Thu Jul 30 11:57:06.561918 2026] [security2:error] [pid 643573:tid 643795] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/60856e3a4findex.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BXgAAAmk"]
[Thu Jul 30 11:57:06.562036 2026] [security2:error] [pid 643573:tid 643795] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/60856e3a4findex.php"] [unique_id "amuCYvxWyxgRnoFKAJ8BXgAAAmk"]
[Thu Jul 30 11:57:06.955997 2026] [core:notice] [pid 642360:tid 642504] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:06.959923 2026] [security2:error] [pid 642360:tid 642504] [client 103.215.74.26:45756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCYpSUkh3e5AhEJOB6eAAAAZ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:07.055278 2026] [security2:error] [pid 643573:tid 643670] [remote 34.44.196.215:1024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.196.44.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/about"] [unique_id "amuCYvxWyxgRnoFKAJ8BXwACPFk"]
[Thu Jul 30 11:57:07.378852 2026] [security2:error] [pid 643573:tid 643804] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp-the.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BZwAAAnI"]
[Thu Jul 30 11:57:07.378986 2026] [security2:error] [pid 643573:tid 643804] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp-the.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BZwAAAnI"]
[Thu Jul 30 11:57:07.874268 2026] [security2:error] [pid 643573:tid 643779] [client 172.213.208.20:17342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BawAAAlk"]
[Thu Jul 30 11:57:07.878657 2026] [security2:error] [pid 643573:tid 643712] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wp.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BbAAAAhY"]
[Thu Jul 30 11:57:07.878750 2026] [security2:error] [pid 643573:tid 643712] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wp.php"] [unique_id "amuCY_xWyxgRnoFKAJ8BbAAAAhY"]
[Thu Jul 30 11:57:08.128853 2026] [security2:error] [pid 643573:tid 643599] [remote 47.128.112.245:60702] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "club4.au"] [uri "/robots.txt"] [unique_id "amuCZPxWyxgRnoFKAJ8BcwACURI"]
[Thu Jul 30 11:57:08.371725 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/users.php"] [unique_id "amuCZPxWyxgRnoFKAJ8BdQAAAmU"]
[Thu Jul 30 11:57:08.371844 2026] [security2:error] [pid 643573:tid 643791] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/users.php"] [unique_id "amuCZPxWyxgRnoFKAJ8BdQAAAmU"]
[Thu Jul 30 11:57:08.872359 2026] [security2:error] [pid 643573:tid 643830] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/tinysd.php"] [unique_id "amuCZPxWyxgRnoFKAJ8BfQAAAow"]
[Thu Jul 30 11:57:08.872479 2026] [security2:error] [pid 643573:tid 643830] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/tinysd.php"] [unique_id "amuCZPxWyxgRnoFKAJ8BfQAAAow"]
[Thu Jul 30 11:57:09.121841 2026] [autoindex:error] [pid 643573:tid 643756] [client 106.54.62.156:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://n1rmalabet88.com
[Thu Jul 30 11:57:09.335693 2026] [security2:error] [pid 643573:tid 643752] [client 161.153.99.62:42094] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuCZfxWyxgRnoFKAJ8BgwAAAj4"], referer: https://historiadevenezuela.org/partido-conservador/?main_page=product_info&products_id=5167
[Thu Jul 30 11:57:09.335816 2026] [security2:error] [pid 643573:tid 643752] [client 161.153.99.62:42094] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuCZfxWyxgRnoFKAJ8BgwAAAj4"], referer: https://historiadevenezuela.org/partido-conservador/?main_page=product_info&products_id=5167
[Thu Jul 30 11:57:09.358525 2026] [security2:error] [pid 643573:tid 643802] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ws78.php"] [unique_id "amuCZfxWyxgRnoFKAJ8BhAAAAnA"]
[Thu Jul 30 11:57:09.358612 2026] [security2:error] [pid 643573:tid 643802] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ws78.php"] [unique_id "amuCZfxWyxgRnoFKAJ8BhAAAAnA"]
[Thu Jul 30 11:57:09.870663 2026] [security2:error] [pid 643573:tid 643763] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/elp.php"] [unique_id "amuCZfxWyxgRnoFKAJ8BiAAAAkk"]
[Thu Jul 30 11:57:09.870793 2026] [security2:error] [pid 643573:tid 643763] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/elp.php"] [unique_id "amuCZfxWyxgRnoFKAJ8BiAAAAkk"]
[Thu Jul 30 11:57:10.295761 2026] [security2:error] [pid 643573:tid 643807] [client 172.213.208.20:7001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/edit.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BjQAAAnU"]
[Thu Jul 30 11:57:10.353522 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/atomlib.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BjgAAAiY"]
[Thu Jul 30 11:57:10.353614 2026] [security2:error] [pid 643573:tid 643728] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/atomlib.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BjgAAAiY"]
[Thu Jul 30 11:57:10.847299 2026] [security2:error] [pid 643573:tid 643827] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/wyzer3.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BlAAAAok"]
[Thu Jul 30 11:57:10.847390 2026] [security2:error] [pid 643573:tid 643827] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/wyzer3.php"] [unique_id "amuCZvxWyxgRnoFKAJ8BlAAAAok"]
[Thu Jul 30 11:57:11.373590 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/max.php"] [unique_id "amuCZ_xWyxgRnoFKAJ8BlwAAAjI"]
[Thu Jul 30 11:57:11.373706 2026] [security2:error] [pid 643573:tid 643740] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/max.php"] [unique_id "amuCZ_xWyxgRnoFKAJ8BlwAAAjI"]
[Thu Jul 30 11:57:11.916272 2026] [security2:error] [pid 643573:tid 643777] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.propertyspro.com"] [uri "/ftde.php"] [unique_id "amuCZ_xWyxgRnoFKAJ8BngAAAlc"]
[Thu Jul 30 11:57:11.916385 2026] [security2:error] [pid 643573:tid 643777] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.propertyspro.com"] [uri "/ftde.php"] [unique_id "amuCZ_xWyxgRnoFKAJ8BngAAAlc"]
[Thu Jul 30 11:57:12.685072 2026] [core:notice] [pid 643573:tid 643812] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:12.689039 2026] [security2:error] [pid 643573:tid 643812] [client 103.215.74.26:45764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCaPxWyxgRnoFKAJ8BqQAAAno"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:13.118832 2026] [security2:error] [pid 642360:tid 642581] [client 103.59.160.82:49354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "azureskyfilms.com"] [uri "/index.php"] [unique_id "amuCaZSUkh3e5AhEJOB6owAAAeo"]
[Thu Jul 30 11:57:13.410245 2026] [core:notice] [pid 642360:tid 642587] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:13.414438 2026] [security2:error] [pid 642360:tid 642587] [client 103.215.74.26:26306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCaZSUkh3e5AhEJOB6rgAAAfA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:14.156390 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:14.160586 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:26312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCasjqbtjBYzqM1uYnqQAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:14.510790 2026] [security2:error] [pid 642360:tid 642511] [client 123.21.175.29:37386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCapSUkh3e5AhEJOB6vwAAAaQ"], referer: http://pkf.jo
[Thu Jul 30 11:57:14.911743 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:14.915811 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:26326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCapSUkh3e5AhEJOB6yQAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:15.629104 2026] [security2:error] [pid 643253:tid 643392] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCasjqbtjBYzqM1uYnrQAAAAg"]
[Thu Jul 30 11:57:15.632508 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:15.636860 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:26332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCa5SUkh3e5AhEJOB60wAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:16.096861 2026] [security2:error] [pid 643253:tid 643475] [client 191.114.12.14:59986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCa8jqbtjBYzqM1uYnsAAAAFs"], referer: http://pkf.jo
[Thu Jul 30 11:57:16.363691 2026] [core:notice] [pid 642360:tid 642616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:16.367489 2026] [security2:error] [pid 642360:tid 642616] [client 103.215.74.26:26336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCbJSUkh3e5AhEJOB62wAAAg0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:16.882758 2026] [security2:error] [pid 643253:tid 643488] [client 176.241.66.87:54604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCbMjqbtjBYzqM1uYntgAAAGg"]
[Thu Jul 30 11:57:16.882867 2026] [security2:error] [pid 643253:tid 643488] [client 176.241.66.87:54604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCbMjqbtjBYzqM1uYntgAAAGg"]
[Thu Jul 30 11:57:17.093579 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:17.097833 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:26348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCbcjqbtjBYzqM1uYntwAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:17.605446 2026] [security2:error] [pid 643253:tid 643391] [client 172.213.208.20:30609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/sf.php"] [unique_id "amuCbcjqbtjBYzqM1uYnugAAAAc"]
[Thu Jul 30 11:57:17.832194 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:17.836545 2026] [security2:error] [pid 642360:tid 642597] [client 103.215.74.26:26350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCbZSUkh3e5AhEJOB67gAAAfo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:18.556968 2026] [core:notice] [pid 642360:tid 642567] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:18.561274 2026] [security2:error] [pid 642360:tid 642567] [client 103.215.74.26:26352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCbpSUkh3e5AhEJOB69wAAAdw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:19.280946 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:19.285210 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:26364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCb8jqbtjBYzqM1uYnvgAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:20.018300 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:20.022864 2026] [security2:error] [pid 643253:tid 643454] [client 103.215.74.26:26368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCcMjqbtjBYzqM1uYnxwAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:20.763313 2026] [core:notice] [pid 643253:tid 643399] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:20.767767 2026] [security2:error] [pid 643253:tid 643399] [client 103.215.74.26:26378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCcMjqbtjBYzqM1uYnyQAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:21.501825 2026] [core:notice] [pid 642360:tid 642606] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:21.506267 2026] [security2:error] [pid 642360:tid 642606] [client 103.215.74.26:26388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCcZSUkh3e5AhEJOB7IwAAAgM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:21.714279 2026] [security2:error] [pid 642360:tid 642572] [client 74.7.244.37:54272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCcZSUkh3e5AhEJOB7IgAAAeE"]
[Thu Jul 30 11:57:22.378731 2026] [security2:error] [pid 642360:tid 642598] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCcZSUkh3e5AhEJOB7JQAAAfs"]
[Thu Jul 30 11:57:23.006225 2026] [security2:error] [pid 642360:tid 642558] [client 172.213.208.20:23554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wso.php"] [unique_id "amuCc5SUkh3e5AhEJOB7PgAAAdM"]
[Thu Jul 30 11:57:23.607772 2026] [security2:error] [pid 642360:tid 642616] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-212fe300.mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amuCcZSUkh3e5AhEJOB7HgAAAg0"]
[Thu Jul 30 11:57:23.607808 2026] [security2:error] [pid 642360:tid 642616] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-212fe300.mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amuCcZSUkh3e5AhEJOB7HgAAAg0"]
[Thu Jul 30 11:57:23.608586 2026] [security2:error] [pid 643253:tid 643438] [client 35.221.246.130:45800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "website-212fe300.mty.djb.temporary.site"] [uri "/.git/config"] [unique_id "amuCccjqbtjBYzqM1uYnzAAAADY"]
[Thu Jul 30 11:57:23.940624 2026] [security2:error] [pid 642360:tid 642492] [client 172.213.208.20:6757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/ioxi-o.php"] [unique_id "amuCc5SUkh3e5AhEJOB7VAAAAZE"]
[Thu Jul 30 11:57:24.167619 2026] [security2:error] [pid 642360:tid 642576] [client 103.178.2.97:37414] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "ghggeneralcontracting.com"] [uri "/wp-comments-post.php"] [unique_id "amuCc5SUkh3e5AhEJOB7SwAAAeU"]
[Thu Jul 30 11:57:24.436518 2026] [security2:error] [pid 642360:tid 642576] [client 103.178.2.97:37414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "ghggeneralcontracting.com"] [uri "/wp-comments-post.php"] [unique_id "amuCc5SUkh3e5AhEJOB7SwAAAeU"]
[Thu Jul 30 11:57:24.470115 2026] [security2:error] [pid 642360:tid 642419] [remote 184.168.126.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuCdJSUkh3e5AhEJOB7WQAB7Do"]
[Thu Jul 30 11:57:24.653126 2026] [security2:error] [pid 642360:tid 642550] [client 172.213.208.20:23612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/file56.php"] [unique_id "amuCdJSUkh3e5AhEJOB7XQAAAcs"]
[Thu Jul 30 11:57:26.362593 2026] [security2:error] [pid 642360:tid 642598] [client 172.213.208.20:6590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuCdpSUkh3e5AhEJOB7bQAAAfs"]
[Thu Jul 30 11:57:27.235444 2026] [core:notice] [pid 642360:tid 642612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:27.247200 2026] [security2:error] [pid 642360:tid 642612] [client 103.215.74.26:58192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCd5SUkh3e5AhEJOB7kQAAAgk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:27.346533 2026] [security2:error] [pid 642360:tid 642558] [client 172.213.208.20:43681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7kgAAAdM"]
[Thu Jul 30 11:57:27.510640 2026] [security2:error] [pid 642360:tid 642565] [client 176.241.66.87:38943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCd5SUkh3e5AhEJOB7lgAAAdo"]
[Thu Jul 30 11:57:27.510846 2026] [security2:error] [pid 642360:tid 642565] [client 176.241.66.87:38943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCd5SUkh3e5AhEJOB7lgAAAdo"]
[Thu Jul 30 11:57:28.578670 2026] [security2:error] [pid 643253:tid 643445] [client 172.237.109.114:54939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd8jqbtjBYzqM1uYn5QAAAD0"]
[Thu Jul 30 11:57:28.583880 2026] [security2:error] [pid 643253:tid 643433] [client 172.237.109.114:32001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd8jqbtjBYzqM1uYn5gAAADE"]
[Thu Jul 30 11:57:28.597261 2026] [security2:error] [pid 642360:tid 642541] [client 172.237.109.114:13824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7hAAAAcI"]
[Thu Jul 30 11:57:28.601035 2026] [security2:error] [pid 642360:tid 642523] [client 172.237.109.114:11772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7fQAAAbA"]
[Thu Jul 30 11:57:28.683022 2026] [security2:error] [pid 643253:tid 643501] [client 172.213.208.20:36363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/edit.php"] [unique_id "amuCeMjqbtjBYzqM1uYn7wAAAHU"]
[Thu Jul 30 11:57:28.981342 2026] [core:notice] [pid 642360:tid 642439] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:29.217427 2026] [security2:error] [pid 642360:tid 642616] [client 172.237.109.114:17404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7jwAAAg0"]
[Thu Jul 30 11:57:29.229015 2026] [security2:error] [pid 642360:tid 642499] [client 172.237.109.114:11191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7fAAAAZg"]
[Thu Jul 30 11:57:29.237212 2026] [security2:error] [pid 642360:tid 642532] [client 172.237.109.114:25339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7jQAAAbk"]
[Thu Jul 30 11:57:29.243463 2026] [security2:error] [pid 642360:tid 642592] [client 172.237.109.114:62653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7ggAAAfU"]
[Thu Jul 30 11:57:29.250461 2026] [security2:error] [pid 642360:tid 642514] [client 172.237.109.114:20534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7fwAAAac"]
[Thu Jul 30 11:57:29.250567 2026] [security2:error] [pid 642360:tid 642594] [client 172.237.109.114:2021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7hQAAAfc"]
[Thu Jul 30 11:57:29.256929 2026] [security2:error] [pid 642360:tid 642587] [client 172.237.109.114:16153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7iAAAAfA"]
[Thu Jul 30 11:57:29.271495 2026] [security2:error] [pid 642360:tid 642529] [client 172.237.109.114:36059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7hwAAAbY"]
[Thu Jul 30 11:57:29.275234 2026] [core:notice] [pid 642360:tid 642462] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:29.289146 2026] [security2:error] [pid 642360:tid 642560] [client 172.237.109.114:16152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7iwAAAdU"]
[Thu Jul 30 11:57:29.325689 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:29282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7gQAAAec"]
[Thu Jul 30 11:57:29.337371 2026] [security2:error] [pid 642360:tid 642601] [client 172.237.109.114:5319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7jgAAAf4"]
[Thu Jul 30 11:57:29.382327 2026] [security2:error] [pid 642360:tid 642614] [client 172.237.109.114:44812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7kAAAAgs"]
[Thu Jul 30 11:57:29.391651 2026] [security2:error] [pid 642360:tid 642617] [client 172.237.109.114:41994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7iQAAAg4"]
[Thu Jul 30 11:57:29.424527 2026] [security2:error] [pid 642360:tid 642582] [client 172.237.109.114:60718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7hgAAAes"]
[Thu Jul 30 11:57:29.442245 2026] [security2:error] [pid 642360:tid 642503] [client 172.237.109.114:15898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7jAAAAZw"]
[Thu Jul 30 11:57:29.449092 2026] [security2:error] [pid 642360:tid 642504] [client 172.237.109.114:29791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCd5SUkh3e5AhEJOB7igAAAZ0"]
[Thu Jul 30 11:57:31.309110 2026] [security2:error] [pid 643253:tid 643466] [client 34.194.226.74:35382] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "ai-kr.com"] [uri "/"] [unique_id "amuCe8jqbtjBYzqM1uYoAgAAAFI"]
[Thu Jul 30 11:57:32.965856 2026] [core:notice] [pid 643253:tid 643435] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:32.970331 2026] [security2:error] [pid 643253:tid 643435] [client 103.215.74.26:58206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCfMjqbtjBYzqM1uYoCAAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:33.352663 2026] [security2:error] [pid 643253:tid 643275] [remote 74.7.241.60:54156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/article.php"] [unique_id "amuCfcjqbtjBYzqM1uYoCgAAYhQ"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:57:33.643647 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:33.692842 2026] [core:notice] [pid 643253:tid 643426] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:33.697512 2026] [security2:error] [pid 643253:tid 643426] [client 103.215.74.26:62538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCfcjqbtjBYzqM1uYoEQAAACo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:33.796734 2026] [security2:error] [pid 642360:tid 642530] [client 172.213.208.20:6464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/2.php"] [unique_id "amuCfZSUkh3e5AhEJOB74wAAAbc"]
[Thu Jul 30 11:57:34.422924 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:34.426771 2026] [security2:error] [pid 643253:tid 643484] [client 103.215.74.26:62554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCfsjqbtjBYzqM1uYoFQAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:34.446959 2026] [security2:error] [pid 643253:tid 643493] [client 172.213.208.20:6524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuCfsjqbtjBYzqM1uYoFgAAAG0"]
[Thu Jul 30 11:57:35.171488 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:35.175423 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:62562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCf8jqbtjBYzqM1uYoHAAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:35.905709 2026] [core:notice] [pid 642360:tid 642575] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:35.909827 2026] [security2:error] [pid 642360:tid 642575] [client 103.215.74.26:62566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCf5SUkh3e5AhEJOB7-AAAAeQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:36.525911 2026] [security2:error] [pid 643253:tid 643404] [client 172.213.208.20:44805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/mah.php"] [unique_id "amuCgMjqbtjBYzqM1uYoIgAAABQ"]
[Thu Jul 30 11:57:36.660691 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:36.813784 2026] [security2:error] [pid 643253:tid 643445] [client 43.173.174.102:51526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/11/09/au-hasard-toile-29/"] [unique_id "amuCgMjqbtjBYzqM1uYoIwAAAD0"]
[Thu Jul 30 11:57:36.832045 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:36.984694 2026] [security2:error] [pid 643253:tid 643499] [client 14.173.161.232:59234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgMjqbtjBYzqM1uYoJAAAAHM"], referer: http://pkf.jo
[Thu Jul 30 11:57:37.132637 2026] [security2:error] [pid 642360:tid 642534] [client 85.208.96.193:64486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/21/morre-o-ator-pedro-paulo-rangel-de-gabriela-e-o-cravo-e-a-rosa-aos-74-anos/"] [unique_id "amuCgZSUkh3e5AhEJOB8CgAAAbs"]
[Thu Jul 30 11:57:37.132789 2026] [security2:error] [pid 642360:tid 642534] [client 85.208.96.193:64486] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/21/morre-o-ator-pedro-paulo-rangel-de-gabriela-e-o-cravo-e-a-rosa-aos-74-anos/"] [unique_id "amuCgZSUkh3e5AhEJOB8CgAAAbs"]
[Thu Jul 30 11:57:37.431057 2026] [core:notice] [pid 642360:tid 642500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:37.435739 2026] [security2:error] [pid 642360:tid 642500] [client 43.173.180.250:43434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/11/09/au-hasard-toile-29/"] [unique_id "amuCgZSUkh3e5AhEJOB8EAAAAZk"], referer: https://carnetdeshopping.com/index.php/2014/11/09/au-hasard-toile-29/
[Thu Jul 30 11:57:37.512260 2026] [security2:error] [pid 642360:tid 642379] [remote 72.167.132.114:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amuCgZSUkh3e5AhEJOB8EQABwRI"]
[Thu Jul 30 11:57:37.615895 2026] [security2:error] [pid 642360:tid 642490] [client 102.209.220.142:9241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgZSUkh3e5AhEJOB8DwAAAY8"], referer: http://pkf.jo
[Thu Jul 30 11:57:38.080392 2026] [security2:error] [pid 642360:tid 642513] [client 36.50.197.107:46458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgZSUkh3e5AhEJOB8GQAAAaY"], referer: http://pkf.jo
[Thu Jul 30 11:57:38.141380 2026] [security2:error] [pid 642360:tid 642576] [client 176.241.66.87:55714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCgpSUkh3e5AhEJOB8HwAAAeU"]
[Thu Jul 30 11:57:38.141506 2026] [security2:error] [pid 642360:tid 642576] [client 176.241.66.87:55714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCgpSUkh3e5AhEJOB8HwAAAeU"]
[Thu Jul 30 11:57:38.201626 2026] [security2:error] [pid 642360:tid 642593] [client 202.163.81.152:21373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgZSUkh3e5AhEJOB8GgAAAfY"], referer: http://pkf.jo
[Thu Jul 30 11:57:38.502881 2026] [security2:error] [pid 642360:tid 642550] [client 160.226.222.221:40060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCgpSUkh3e5AhEJOB8IAAAAcs"], referer: http://pkf.jo
[Thu Jul 30 11:57:39.223633 2026] [core:error] [pid 642360:tid 642377] [remote 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:39.223653 2026] [core:error] [pid 642360:tid 642377] [remote 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:39.334058 2026] [core:error] [pid 642360:tid 642506] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:39.334087 2026] [core:error] [pid 642360:tid 642506] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:39.334206 2026] [security2:error] [pid 642360:tid 642506] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.zmt.fcn.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuCg5SUkh3e5AhEJOB8OwAAAZ8"]
[Thu Jul 30 11:57:39.334776 2026] [security2:error] [pid 642360:tid 642592] [client 74.7.228.63:42494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.zmt.fcn.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuCg5SUkh3e5AhEJOB8OQAB9QA"]
[Thu Jul 30 11:57:39.484307 2026] [security2:error] [pid 642360:tid 642581] [client 172.213.208.20:36522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/send.php"] [unique_id "amuCg5SUkh3e5AhEJOB8PQAAAeo"]
[Thu Jul 30 11:57:40.282731 2026] [security2:error] [pid 642360:tid 642536] [client 74.7.228.31:37970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.eow.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuChJSUkh3e5AhEJOB8RgABvRw"]
[Thu Jul 30 11:57:41.640118 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:41.647157 2026] [security2:error] [pid 642360:tid 642571] [client 103.215.74.26:62572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuChZSUkh3e5AhEJOB8XwAAAeA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:41.765345 2026] [security2:error] [pid 642360:tid 642543] [client 172.213.208.20:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuChZSUkh3e5AhEJOB8YAAAAcQ"]
[Thu Jul 30 11:57:42.379565 2026] [core:notice] [pid 642360:tid 642555] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:42.386335 2026] [security2:error] [pid 642360:tid 642555] [client 103.215.74.26:62574] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuChpSUkh3e5AhEJOB8bgAAAdA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:43.120893 2026] [core:notice] [pid 643253:tid 643405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:43.127761 2026] [security2:error] [pid 643253:tid 643405] [client 103.215.74.26:31256] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCh8jqbtjBYzqM1uYoNAAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:43.877274 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:43.881321 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:31272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCh8jqbtjBYzqM1uYoNgAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:44.547635 2026] [core:notice] [pid 643253:tid 643396] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:44.602700 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:44.607707 2026] [security2:error] [pid 642360:tid 642520] [client 103.215.74.26:31280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "777"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCiJSUkh3e5AhEJOB8lAAAAa0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:44.702742 2026] [core:notice] [pid 642360:tid 642415] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:45.290077 2026] [core:notice] [pid 642360:tid 642393] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:45.385624 2026] [proxy:error] [pid 642360:tid 642590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:57:45.385685 2026] [proxy_http:error] [pid 642360:tid 642590] [client 44.216.125.112:51279] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:57:45.386262 2026] [proxy:error] [pid 642360:tid 642590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:57:45.386313 2026] [proxy_http:error] [pid 642360:tid 642590] [client 44.216.125.112:51279] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:57:45.960299 2026] [core:error] [pid 642360:tid 642599] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.960326 2026] [core:error] [pid 642360:tid 642599] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.971943 2026] [core:error] [pid 642360:tid 642561] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.971959 2026] [core:error] [pid 642360:tid 642561] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.987853 2026] [core:error] [pid 642360:tid 642501] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.987871 2026] [core:error] [pid 642360:tid 642501] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.998163 2026] [core:error] [pid 642360:tid 642602] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:45.998188 2026] [core:error] [pid 642360:tid 642602] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:46.007964 2026] [core:error] [pid 642360:tid 642517] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:46.008002 2026] [core:error] [pid 642360:tid 642517] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:57:46.929783 2026] [security2:error] [pid 642360:tid 642575] [client 187.244.73.74:45224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCipSUkh3e5AhEJOB8vgAAAeQ"], referer: http://pkf.jo
[Thu Jul 30 11:57:48.854866 2026] [security2:error] [pid 643253:tid 643469] [client 176.241.66.87:40407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCjMjqbtjBYzqM1uYoUgAAAFU"]
[Thu Jul 30 11:57:48.855024 2026] [security2:error] [pid 643253:tid 643469] [client 176.241.66.87:40407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCjMjqbtjBYzqM1uYoUgAAAFU"]
[Thu Jul 30 11:57:49.502030 2026] [security2:error] [pid 643253:tid 643414] [client 157.34.209.103:37249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCjcjqbtjBYzqM1uYoVAAAAB4"], referer: http://pkf.jo
[Thu Jul 30 11:57:50.036634 2026] [security2:error] [pid 643253:tid 643499] [client 20.226.5.174:27875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/011i.php"] [unique_id "amuCjsjqbtjBYzqM1uYoVgAAAHM"]
[Thu Jul 30 11:57:50.053794 2026] [security2:error] [pid 642360:tid 642497] [client 74.7.230.21:34694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-54a868fb.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuCjpSUkh3e5AhEJOB87AABlmQ"]
[Thu Jul 30 11:57:50.164854 2026] [security2:error] [pid 642360:tid 642547] [client 87.217.47.18:57682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCjZSUkh3e5AhEJOB86gAAAcg"], referer: http://pkf.jo
[Thu Jul 30 11:57:50.232039 2026] [security2:error] [pid 642360:tid 642537] [client 102.129.68.138:34708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCjZSUkh3e5AhEJOB86wAAAb4"], referer: http://pkf.jo
[Thu Jul 30 11:57:50.361442 2026] [core:notice] [pid 642360:tid 642563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:50.368262 2026] [security2:error] [pid 642360:tid 642563] [client 103.215.74.26:31288] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCjpSUkh3e5AhEJOB88AAAAdg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:50.554784 2026] [security2:error] [pid 642360:tid 642572] [client 74.7.244.24:48900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.asd.fyv.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuCjpSUkh3e5AhEJOB89QAAAeE"]
[Thu Jul 30 11:57:51.126002 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:51.130445 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:31294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "790"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCj5SUkh3e5AhEJOB8_gAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:51.178188 2026] [security2:error] [pid 642360:tid 642609] [client 37.120.155.179:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuCj5SUkh3e5AhEJOB9AAAAAgY"]
[Thu Jul 30 11:57:51.178317 2026] [security2:error] [pid 642360:tid 642609] [client 37.120.155.179:58432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuCj5SUkh3e5AhEJOB9AAAAAgY"]
[Thu Jul 30 11:57:51.191721 2026] [security2:error] [pid 642360:tid 642578] [client 20.226.5.174:28270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/03a005685d.php"] [unique_id "amuCj5SUkh3e5AhEJOB9AQAAAec"]
[Thu Jul 30 11:57:51.736135 2026] [security2:error] [pid 642360:tid 642522] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCj5SUkh3e5AhEJOB8_wAAAa8"]
[Thu Jul 30 11:57:51.821823 2026] [security2:error] [pid 642360:tid 642566] [client 172.213.208.20:36274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/about.php"] [unique_id "amuCj5SUkh3e5AhEJOB9CAAAAds"]
[Thu Jul 30 11:57:51.866294 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:51.871155 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:31300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCj8jqbtjBYzqM1uYoXAAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:52.500818 2026] [security2:error] [pid 642360:tid 642520] [client 20.226.5.174:28236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/403.php"] [unique_id "amuCkJSUkh3e5AhEJOB9EwAAAa0"]
[Thu Jul 30 11:57:52.636763 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:52.640823 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:31306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCkJSUkh3e5AhEJOB9GAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:52.773491 2026] [security2:error] [pid 643253:tid 643454] [client 172.213.208.20:27253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/options.php"] [unique_id "amuCkMjqbtjBYzqM1uYoYwAAAEY"]
[Thu Jul 30 11:57:53.385754 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:53.392317 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:6894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCkZSUkh3e5AhEJOB9IQAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:53.581434 2026] [security2:error] [pid 642360:tid 642492] [client 20.226.5.174:28233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/404.php"] [unique_id "amuCkZSUkh3e5AhEJOB9KAAAAZE"]
[Thu Jul 30 11:57:54.119026 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:54.123787 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:6900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCksjqbtjBYzqM1uYoaQAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:54.407787 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:54.812916 2026] [security2:error] [pid 643253:tid 643503] [client 20.226.5.174:28242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/aa.php"] [unique_id "amuCksjqbtjBYzqM1uYobgAAAHc"]
[Thu Jul 30 11:57:54.864708 2026] [core:notice] [pid 643253:tid 643436] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:54.872559 2026] [security2:error] [pid 643253:tid 643436] [client 103.215.74.26:6914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCksjqbtjBYzqM1uYobwAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:54.880453 2026] [security2:error] [pid 642360:tid 642517] [client 49.36.105.4:42722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCkpSUkh3e5AhEJOB9NQAAAao"], referer: http://pkf.jo
[Thu Jul 30 11:57:54.978611 2026] [security2:error] [pid 643253:tid 643478] [client 64.31.3.126:32598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCkcjqbtjBYzqM1uYoZAAAAEU"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2269
[Thu Jul 30 11:57:55.212420 2026] [security2:error] [pid 642360:tid 642544] [client 154.208.54.20:7729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCkpSUkh3e5AhEJOB9OQAAAcU"], referer: http://pkf.jo
[Thu Jul 30 11:57:55.220752 2026] [security2:error] [pid 642360:tid 642611] [client 172.213.208.20:15330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuCk5SUkh3e5AhEJOB9QAAAAgg"]
[Thu Jul 30 11:57:55.604464 2026] [core:notice] [pid 642360:tid 642617] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:55.608198 2026] [security2:error] [pid 642360:tid 642617] [client 103.215.74.26:6922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCk5SUkh3e5AhEJOB9RAAAAg4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:55.853959 2026] [security2:error] [pid 642360:tid 642526] [client 20.226.5.174:28313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/aafewc0k.php"] [unique_id "amuCk5SUkh3e5AhEJOB9SAAAAbM"]
[Thu Jul 30 11:57:56.130230 2026] [security2:error] [pid 642360:tid 642591] [client 172.213.208.20:52394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/wp-file.php"] [unique_id "amuClJSUkh3e5AhEJOB9TQAAAfQ"]
[Thu Jul 30 11:57:56.364479 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:56.368797 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:6938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuClMjqbtjBYzqM1uYocgAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:56.983740 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:57.090846 2026] [core:notice] [pid 642360:tid 642585] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:57:57.095020 2026] [security2:error] [pid 642360:tid 642585] [client 103.215.74.26:6954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuClZSUkh3e5AhEJOB9WgAAAe4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:57:57.104181 2026] [security2:error] [pid 643253:tid 643467] [client 172.213.208.20:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bonafideadvisors.com"] [uri "/sid3.php"] [unique_id "amuClcjqbtjBYzqM1uYodwAAAFM"]
[Thu Jul 30 11:57:57.305455 2026] [security2:error] [pid 643253:tid 643485] [client 20.226.5.174:28276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/abcd.php"] [unique_id "amuClcjqbtjBYzqM1uYoeQAAAGU"]
[Thu Jul 30 11:57:57.378262 2026] [security2:error] [pid 642360:tid 642510] [client 169.224.19.57:22868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuClZSUkh3e5AhEJOB9WQAAAaM"], referer: http://pkf.jo
[Thu Jul 30 11:57:57.830394 2026] [security2:error] [pid 642360:tid 642398] [remote 45.252.248.17:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.248.252.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baitultateeqmoverscompany.com"] [uri "/xmlrpc.php"] [unique_id "amuClZSUkh3e5AhEJOB9ZwAB_CU"]
[Thu Jul 30 11:57:57.830548 2026] [security2:error] [pid 642360:tid 642599] [client 45.252.248.17:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "baitultateeqmoverscompany.com"] [uri "/xmlrpc.php"] [unique_id "amuClZSUkh3e5AhEJOB9ZwAB_CU"]
[Thu Jul 30 11:57:58.565208 2026] [security2:error] [pid 642360:tid 642496] [client 20.226.5.174:28237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/about.php"] [unique_id "amuClpSUkh3e5AhEJOB9cAAAAZU"]
[Thu Jul 30 11:57:59.556807 2026] [security2:error] [pid 642360:tid 642559] [client 176.241.66.87:41101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCl5SUkh3e5AhEJOB9gQAAAdQ"]
[Thu Jul 30 11:57:59.556952 2026] [security2:error] [pid 642360:tid 642559] [client 176.241.66.87:41101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCl5SUkh3e5AhEJOB9gQAAAdQ"]
[Thu Jul 30 11:57:59.800680 2026] [security2:error] [pid 642360:tid 642519] [client 37.120.155.179:41252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuCl5SUkh3e5AhEJOB9hQAAAaw"]
[Thu Jul 30 11:57:59.800787 2026] [security2:error] [pid 642360:tid 642519] [client 37.120.155.179:41252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuCl5SUkh3e5AhEJOB9hQAAAaw"]
[Thu Jul 30 11:58:00.591111 2026] [core:error] [pid 643253:tid 643447] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:00.591136 2026] [core:error] [pid 643253:tid 643447] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:01.309871 2026] [core:notice] [pid 643253:tid 643303] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:01.536879 2026] [security2:error] [pid 643253:tid 643500] [client 20.226.5.174:28342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/admin.php"] [unique_id "amuCmcjqbtjBYzqM1uYojgAAAHQ"]
[Thu Jul 30 11:58:02.765852 2026] [security2:error] [pid 643253:tid 643412] [client 20.226.5.174:27943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/adminfuns.php"] [unique_id "amuCmsjqbtjBYzqM1uYokgAAABw"]
[Thu Jul 30 11:58:02.852059 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:02.856279 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:6966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCmpSUkh3e5AhEJOB9rgAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:03.330534 2026] [security2:error] [pid 642360:tid 642529] [client 158.158.38.215:40022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuCm5SUkh3e5AhEJOB9swAAAbY"]
[Thu Jul 30 11:58:03.330648 2026] [security2:error] [pid 642360:tid 642529] [client 158.158.38.215:40022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuCm5SUkh3e5AhEJOB9swAAAbY"]
[Thu Jul 30 11:58:03.589343 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:03.594564 2026] [security2:error] [pid 643253:tid 643385] [client 103.215.74.26:31136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCm8jqbtjBYzqM1uYolgAAAAE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:03.605362 2026] [security2:error] [pid 643253:tid 643460] [client 158.158.38.215:36819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuCm8jqbtjBYzqM1uYolwAAAEw"]
[Thu Jul 30 11:58:03.605508 2026] [security2:error] [pid 643253:tid 643460] [client 158.158.38.215:36819] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuCm8jqbtjBYzqM1uYolwAAAEw"]
[Thu Jul 30 11:58:03.809327 2026] [core:notice] [pid 642360:tid 642611] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:03.964688 2026] [security2:error] [pid 642360:tid 642592] [client 158.158.38.215:48422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wawe.php"] [unique_id "amuCm5SUkh3e5AhEJOB9vgAAAfU"]
[Thu Jul 30 11:58:03.964809 2026] [security2:error] [pid 642360:tid 642592] [client 158.158.38.215:48422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/wawe.php"] [unique_id "amuCm5SUkh3e5AhEJOB9vgAAAfU"]
[Thu Jul 30 11:58:03.988664 2026] [lsapi:error] [pid 643573:tid 643629] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 11:58:04.278960 2026] [security2:error] [pid 643253:tid 643401] [client 158.158.38.215:42126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/alfa123.php"] [unique_id "amuCnMjqbtjBYzqM1uYomQAAABE"]
[Thu Jul 30 11:58:04.279104 2026] [security2:error] [pid 643253:tid 643401] [client 158.158.38.215:42126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/alfa123.php"] [unique_id "amuCnMjqbtjBYzqM1uYomQAAABE"]
[Thu Jul 30 11:58:04.327586 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:04.332053 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:31148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCnJSUkh3e5AhEJOB9wgAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:04.639072 2026] [core:notice] [pid 642360:tid 642431] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:04.725795 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:04.741415 2026] [security2:error] [pid 642360:tid 642555] [client 158.158.38.215:48441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/kn.php"] [unique_id "amuCnJSUkh3e5AhEJOB9ygAAAdA"]
[Thu Jul 30 11:58:04.741499 2026] [security2:error] [pid 642360:tid 642555] [client 158.158.38.215:48441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/kn.php"] [unique_id "amuCnJSUkh3e5AhEJOB9ygAAAdA"]
[Thu Jul 30 11:58:05.057539 2026] [core:notice] [pid 642360:tid 642526] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:05.064634 2026] [security2:error] [pid 642360:tid 642526] [client 103.215.74.26:31158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCnZSUkh3e5AhEJOB9zwAAAbM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:05.143815 2026] [security2:error] [pid 642360:tid 642534] [client 158.158.38.215:42140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/class-wp.php"] [unique_id "amuCnZSUkh3e5AhEJOB91gAAAbs"]
[Thu Jul 30 11:58:05.143973 2026] [security2:error] [pid 642360:tid 642534] [client 158.158.38.215:42140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/class-wp.php"] [unique_id "amuCnZSUkh3e5AhEJOB91gAAAbs"]
[Thu Jul 30 11:58:05.629152 2026] [security2:error] [pid 643253:tid 643454] [client 158.158.38.215:36807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/shelp.php"] [unique_id "amuCncjqbtjBYzqM1uYoqwAAAEY"]
[Thu Jul 30 11:58:05.629331 2026] [security2:error] [pid 643253:tid 643454] [client 158.158.38.215:36807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/shelp.php"] [unique_id "amuCncjqbtjBYzqM1uYoqwAAAEY"]
[Thu Jul 30 11:58:05.805542 2026] [core:notice] [pid 643253:tid 643418] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:05.810223 2026] [security2:error] [pid 643253:tid 643418] [client 103.215.74.26:31174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCncjqbtjBYzqM1uYorAAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:05.942465 2026] [security2:error] [pid 642360:tid 642510] [client 158.158.38.215:48389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/phpi.php"] [unique_id "amuCnZSUkh3e5AhEJOB94wAAAaM"]
[Thu Jul 30 11:58:05.942578 2026] [security2:error] [pid 642360:tid 642510] [client 158.158.38.215:48389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/phpi.php"] [unique_id "amuCnZSUkh3e5AhEJOB94wAAAaM"]
[Thu Jul 30 11:58:05.980332 2026] [security2:error] [pid 642360:tid 642610] [client 103.138.171.41:48196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB93wAAAgc"], referer: http://pkf.jo
[Thu Jul 30 11:58:06.258738 2026] [core:error] [pid 642360:tid 642552] [client 34.150.193.0:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:06.258777 2026] [core:error] [pid 642360:tid 642552] [client 34.150.193.0:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:06.306189 2026] [security2:error] [pid 642360:tid 642569] [client 158.158.38.215:40054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/birlingsless.php"] [unique_id "amuCnpSUkh3e5AhEJOB99gAAAd4"]
[Thu Jul 30 11:58:06.306421 2026] [security2:error] [pid 642360:tid 642569] [client 158.158.38.215:40054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/birlingsless.php"] [unique_id "amuCnpSUkh3e5AhEJOB99gAAAd4"]
[Thu Jul 30 11:58:06.622497 2026] [security2:error] [pid 643253:tid 643425] [client 158.158.38.215:42532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/shell20211028.php"] [unique_id "amuCnsjqbtjBYzqM1uYouAAAACk"]
[Thu Jul 30 11:58:06.622688 2026] [security2:error] [pid 643253:tid 643425] [client 158.158.38.215:42532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/shell20211028.php"] [unique_id "amuCnsjqbtjBYzqM1uYouAAAACk"]
[Thu Jul 30 11:58:06.940752 2026] [core:notice] [pid 642360:tid 642550] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:07.160991 2026] [core:error] [pid 642360:tid 642491] [client 34.150.193.0:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:07.161015 2026] [core:error] [pid 642360:tid 642491] [client 34.150.193.0:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:07.169620 2026] [core:notice] [pid 642360:tid 642517] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:07.237724 2026] [security2:error] [pid 643253:tid 643424] [client 172.237.109.114:21221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYonwAAACg"]
[Thu Jul 30 11:58:07.239171 2026] [security2:error] [pid 642360:tid 642612] [client 172.237.109.114:6493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB90AAAAgk"]
[Thu Jul 30 11:58:07.264374 2026] [security2:error] [pid 643253:tid 643400] [client 172.237.109.114:59849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYopAAAABA"]
[Thu Jul 30 11:58:07.305330 2026] [security2:error] [pid 642360:tid 642574] [client 172.237.109.114:1378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB90QAAAeM"]
[Thu Jul 30 11:58:07.315515 2026] [security2:error] [pid 643253:tid 643421] [client 172.237.109.114:56738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYoogAAACU"]
[Thu Jul 30 11:58:07.327237 2026] [security2:error] [pid 642360:tid 642535] [client 158.158.38.215:36862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCn5SUkh3e5AhEJOB-AQAAAbw"]
[Thu Jul 30 11:58:07.327278 2026] [security2:error] [pid 642360:tid 642535] [client 158.158.38.215:36862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCn5SUkh3e5AhEJOB-AQAAAbw"]
[Thu Jul 30 11:58:07.358949 2026] [security2:error] [pid 643253:tid 643476] [client 172.237.109.114:5069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYoqAAAAFw"]
[Thu Jul 30 11:58:07.361198 2026] [security2:error] [pid 643253:tid 643509] [client 172.237.109.114:46418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYooQAAAH0"]
[Thu Jul 30 11:58:07.362215 2026] [security2:error] [pid 643253:tid 643506] [client 172.237.109.114:43257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYoowAAAHo"]
[Thu Jul 30 11:58:07.387155 2026] [security2:error] [pid 642360:tid 642565] [client 172.237.109.114:14866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB92AAAAdo"]
[Thu Jul 30 11:58:07.443694 2026] [security2:error] [pid 643253:tid 643458] [client 172.237.109.114:51508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYongAAAEo"]
[Thu Jul 30 11:58:07.469110 2026] [security2:error] [pid 643253:tid 643431] [client 172.237.109.114:43452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYooAAAAC8"]
[Thu Jul 30 11:58:07.483244 2026] [security2:error] [pid 642360:tid 642591] [client 172.237.109.114:5467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB91QAAAfQ"]
[Thu Jul 30 11:58:07.487909 2026] [security2:error] [pid 643253:tid 643386] [client 172.237.109.114:61139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYopgAAAAI"]
[Thu Jul 30 11:58:07.496093 2026] [security2:error] [pid 642360:tid 642542] [client 172.237.109.114:42570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB92QAAAcM"]
[Thu Jul 30 11:58:07.499194 2026] [security2:error] [pid 643253:tid 643440] [client 172.237.109.114:14719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYopQAAADg"]
[Thu Jul 30 11:58:07.513021 2026] [security2:error] [pid 642360:tid 642608] [client 172.237.109.114:24887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB91wAAAgU"]
[Thu Jul 30 11:58:07.696206 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:07.699273 2026] [security2:error] [pid 642360:tid 642615] [client 158.158.38.215:36862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-slss.php"] [unique_id "amuCn5SUkh3e5AhEJOB-CAAAAgw"]
[Thu Jul 30 11:58:07.699382 2026] [security2:error] [pid 642360:tid 642615] [client 158.158.38.215:36862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/wp-slss.php"] [unique_id "amuCn5SUkh3e5AhEJOB-CAAAAgw"]
[Thu Jul 30 11:58:08.242826 2026] [security2:error] [pid 642360:tid 642558] [client 172.237.109.114:64901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB90gAAAdM"]
[Thu Jul 30 11:58:08.257106 2026] [security2:error] [pid 642360:tid 642524] [client 172.237.109.114:6195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB90wAAAbE"]
[Thu Jul 30 11:58:08.294331 2026] [security2:error] [pid 643253:tid 643416] [client 172.237.109.114:11624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYoqQAAACA"]
[Thu Jul 30 11:58:08.308397 2026] [security2:error] [pid 642360:tid 642502] [client 172.237.109.114:54403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnZSUkh3e5AhEJOB91AAAAZs"]
[Thu Jul 30 11:58:08.399473 2026] [security2:error] [pid 643253:tid 643406] [client 172.237.109.114:64203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCncjqbtjBYzqM1uYopwAAABY"]
[Thu Jul 30 11:58:08.499093 2026] [security2:error] [pid 642360:tid 642528] [client 158.158.38.215:42504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCoJSUkh3e5AhEJOB-FQAAAbU"]
[Thu Jul 30 11:58:08.499131 2026] [security2:error] [pid 642360:tid 642528] [client 158.158.38.215:42504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuCoJSUkh3e5AhEJOB-FQAAAbU"]
[Thu Jul 30 11:58:08.541083 2026] [autoindex:error] [pid 642360:tid 642526] [client 20.193.250.173:59086] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_d35de2e9/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 11:58:08.567798 2026] [security2:error] [pid 642360:tid 642518] [client 172.237.109.114:60938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB96gAAAas"]
[Thu Jul 30 11:58:08.721157 2026] [security2:error] [pid 643253:tid 643409] [client 103.240.207.111:14618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCoMjqbtjBYzqM1uYowQAAABk"], referer: http://pkf.jo
[Thu Jul 30 11:58:08.904953 2026] [security2:error] [pid 642360:tid 642490] [client 158.158.38.215:42504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.38.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/amxloxxr.php"] [unique_id "amuCoJSUkh3e5AhEJOB-IAAAAY8"]
[Thu Jul 30 11:58:08.905085 2026] [security2:error] [pid 642360:tid 642490] [client 158.158.38.215:42504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "globalmarks.pk"] [uri "/amxloxxr.php"] [unique_id "amuCoJSUkh3e5AhEJOB-IAAAAY8"]
[Thu Jul 30 11:58:09.099879 2026] [security2:error] [pid 642360:tid 642577] [client 94.54.228.168:37072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCoJSUkh3e5AhEJOB-HAAAAeY"], referer: http://pkf.jo
[Thu Jul 30 11:58:09.265244 2026] [security2:error] [pid 642360:tid 642571] [client 172.237.109.114:28688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB96QAAAeA"]
[Thu Jul 30 11:58:09.266513 2026] [security2:error] [pid 642360:tid 642492] [client 172.237.109.114:29036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB96wAAAZE"]
[Thu Jul 30 11:58:09.276808 2026] [security2:error] [pid 642360:tid 642545] [client 172.237.109.114:14982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB97QAAAcY"]
[Thu Jul 30 11:58:09.353085 2026] [security2:error] [pid 642360:tid 642523] [client 172.237.109.114:14858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB97AAAAbA"]
[Thu Jul 30 11:58:09.358201 2026] [security2:error] [pid 642360:tid 642511] [client 172.237.109.114:15897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB98AAAAaQ"]
[Thu Jul 30 11:58:09.358483 2026] [security2:error] [pid 643253:tid 643453] [client 172.237.109.114:62041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYorgAAAEU"]
[Thu Jul 30 11:58:09.378795 2026] [security2:error] [pid 642360:tid 642541] [client 172.237.109.114:50454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB96AAAAcI"]
[Thu Jul 30 11:58:09.400052 2026] [security2:error] [pid 643253:tid 643444] [client 172.237.109.114:64428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYosAAAADw"]
[Thu Jul 30 11:58:09.401236 2026] [security2:error] [pid 643253:tid 643511] [client 172.237.109.114:7712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYosQAAAH8"]
[Thu Jul 30 11:58:09.420395 2026] [security2:error] [pid 642360:tid 642606] [client 172.237.109.114:42338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB97gAAAgM"]
[Thu Jul 30 11:58:09.468717 2026] [security2:error] [pid 643253:tid 643487] [client 172.237.109.114:8442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYoswAAAGc"]
[Thu Jul 30 11:58:09.476035 2026] [security2:error] [pid 643253:tid 643439] [client 172.237.109.114:19530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYorwAAADc"]
[Thu Jul 30 11:58:09.477198 2026] [security2:error] [pid 643253:tid 643410] [client 172.237.109.114:52843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYotAAAABo"]
[Thu Jul 30 11:58:09.485273 2026] [security2:error] [pid 642360:tid 642607] [client 172.237.109.114:59630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB97wAAAgQ"]
[Thu Jul 30 11:58:09.500421 2026] [security2:error] [pid 642360:tid 642599] [client 172.237.109.114:25661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB98QAAAfw"]
[Thu Jul 30 11:58:09.503992 2026] [security2:error] [pid 642360:tid 642586] [client 172.237.109.114:32839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnpSUkh3e5AhEJOB98gAAAe8"]
[Thu Jul 30 11:58:09.547763 2026] [security2:error] [pid 643253:tid 643405] [client 172.237.109.114:27813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYotQAAABU"]
[Thu Jul 30 11:58:09.547785 2026] [security2:error] [pid 643253:tid 643429] [client 172.237.109.114:37668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCnsjqbtjBYzqM1uYosgAAAC0"]
[Thu Jul 30 11:58:10.110691 2026] [security2:error] [pid 643253:tid 643486] [client 176.241.66.87:41813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCosjqbtjBYzqM1uYozQAAAGY"]
[Thu Jul 30 11:58:10.110834 2026] [security2:error] [pid 643253:tid 643486] [client 176.241.66.87:41813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCosjqbtjBYzqM1uYozQAAAGY"]
[Thu Jul 30 11:58:10.182018 2026] [security2:error] [pid 642360:tid 642535] [client 196.217.180.183:46272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCoZSUkh3e5AhEJOB-LwAAAbw"], referer: http://pkf.jo
[Thu Jul 30 11:58:11.521598 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:11.526664 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:31196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCo5SUkh3e5AhEJOB-QQAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:12.256606 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:12.260921 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:31210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCpJSUkh3e5AhEJOB-SwAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:13.004897 2026] [core:notice] [pid 642360:tid 642564] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:13.008875 2026] [security2:error] [pid 642360:tid 642564] [client 103.215.74.26:31226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCpZSUkh3e5AhEJOB-VgAAAdk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:13.172889 2026] [core:notice] [pid 642360:tid 642596] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:13.714274 2026] [core:notice] [pid 642360:tid 642523] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:13.752063 2026] [core:notice] [pid 642360:tid 642521] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:13.756276 2026] [security2:error] [pid 642360:tid 642521] [client 103.215.74.26:12112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCpZSUkh3e5AhEJOB-XQAAAa4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:13.920569 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:14.335115 2026] [security2:error] [pid 642360:tid 642537] [client 74.7.241.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.inmobiliariadia.com.tfy.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuCppSUkh3e5AhEJOB-aAAAAb4"]
[Thu Jul 30 11:58:14.335735 2026] [security2:error] [pid 643253:tid 643510] [client 74.7.241.191:53320] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.inmobiliariadia.com.tfy.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuCpsjqbtjBYzqM1uYo3QAAfjk"]
[Thu Jul 30 11:58:14.847924 2026] [security2:error] [pid 642360:tid 642561] [client 20.226.5.174:27915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/albin.php"] [unique_id "amuCppSUkh3e5AhEJOB-cAAAAdY"]
[Thu Jul 30 11:58:15.081903 2026] [proxy:error] [pid 643253:tid 643403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:58:15.081957 2026] [proxy_http:error] [pid 643253:tid 643403] [client 185.247.137.138:46381] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:58:15.082538 2026] [proxy:error] [pid 643253:tid 643403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:58:15.082582 2026] [proxy_http:error] [pid 643253:tid 643403] [client 185.247.137.138:46381] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:58:15.138303 2026] [security2:error] [pid 642360:tid 642506] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCppSUkh3e5AhEJOB-bQAAAZ8"]
[Thu Jul 30 11:58:15.178757 2026] [autoindex:error] [pid 643253:tid 643479] [client 74.7.242.49:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:16.154383 2026] [security2:error] [pid 642360:tid 642601] [client 20.226.5.174:27925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/amfsqvgv.php"] [unique_id "amuCqJSUkh3e5AhEJOB-hAAAAf4"]
[Thu Jul 30 11:58:16.174607 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:16.223556 2026] [core:notice] [pid 643253:tid 643491] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:16.228376 2026] [security2:error] [pid 643253:tid 643491] [client 195.23.32.200:54656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/feed/"] [unique_id "amuCqMjqbtjBYzqM1uYo5wAAAGs"]
[Thu Jul 30 11:58:17.132863 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:17.137601 2026] [security2:error] [pid 643253:tid 643485] [client 195.23.32.200:54744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/feed/"] [unique_id "amuCqcjqbtjBYzqM1uYo6gAAAGU"]
[Thu Jul 30 11:58:17.252376 2026] [security2:error] [pid 642360:tid 642494] [client 20.226.5.174:34777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/ant.php"] [unique_id "amuCqZSUkh3e5AhEJOB-lgAAAZM"]
[Thu Jul 30 11:58:18.701253 2026] [security2:error] [pid 643253:tid 643416] [client 195.23.32.200:54810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuCqsjqbtjBYzqM1uYo7gAAACA"]
[Thu Jul 30 11:58:19.360538 2026] [security2:error] [pid 642360:tid 642616] [client 189.244.154.225:41928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuCq5SUkh3e5AhEJOB-qgAAAg0"], referer: http://pkf.jo
[Thu Jul 30 11:58:19.469431 2026] [core:notice] [pid 643253:tid 643457] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:19.473292 2026] [security2:error] [pid 643253:tid 643457] [client 103.215.74.26:12122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCq8jqbtjBYzqM1uYo9AAAAEk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:19.495887 2026] [security2:error] [pid 643253:tid 643492] [client 213.152.161.219:59346] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuCq8jqbtjBYzqM1uYo8gAAAGw"]
[Thu Jul 30 11:58:19.496024 2026] [security2:error] [pid 643253:tid 643492] [client 213.152.161.219:59346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuCq8jqbtjBYzqM1uYo8gAAAGw"]
[Thu Jul 30 11:58:20.207528 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:20.212001 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:12128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCrMjqbtjBYzqM1uYo9wAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:20.734174 2026] [security2:error] [pid 642360:tid 642580] [client 176.241.66.87:58292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCrJSUkh3e5AhEJOB-wgAAAek"]
[Thu Jul 30 11:58:20.734293 2026] [security2:error] [pid 642360:tid 642580] [client 176.241.66.87:58292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCrJSUkh3e5AhEJOB-wgAAAek"]
[Thu Jul 30 11:58:20.946000 2026] [core:notice] [pid 642360:tid 642496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:20.952495 2026] [security2:error] [pid 642360:tid 642496] [client 103.215.74.26:12144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCrJSUkh3e5AhEJOB-xgAAAZU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:21.187817 2026] [security2:error] [pid 642360:tid 642593] [client 20.226.5.174:34601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/appreciators.php"] [unique_id "amuCrZSUkh3e5AhEJOB-yAAAAfY"]
[Thu Jul 30 11:58:21.270437 2026] [autoindex:error] [pid 642360:tid 642551] [client 52.202.41.153:56141] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:21.677105 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:21.684763 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:12148] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCrZSUkh3e5AhEJOB-0QAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:22.409672 2026] [core:notice] [pid 643253:tid 643420] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:22.416333 2026] [security2:error] [pid 643253:tid 643420] [client 103.215.74.26:12164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCrsjqbtjBYzqM1uYo_wAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:22.858031 2026] [security2:error] [pid 642360:tid 642597] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mannyplatoncuevas.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCrpSUkh3e5AhEJOB-5AAAAfo"]
[Thu Jul 30 11:58:23.423069 2026] [security2:error] [pid 642360:tid 642363] [remote 57.141.0.19:54032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuCr5SUkh3e5AhEJOB-7QABoQI"]
[Thu Jul 30 11:58:23.499896 2026] [security2:error] [pid 643253:tid 643433] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mannyplatoncuevas.com"] [uri "/media/system/js/core.js"] [unique_id "amuCr8jqbtjBYzqM1uYpAQAAADE"]
[Thu Jul 30 11:58:23.809459 2026] [security2:error] [pid 643253:tid 643500] [client 20.226.5.174:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/archive.php"] [unique_id "amuCr8jqbtjBYzqM1uYpAwAAAHQ"]
[Thu Jul 30 11:58:24.011844 2026] [core:notice] [pid 642360:tid 642512] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:24.643251 2026] [security2:error] [pid 642360:tid 642372] [remote 47.128.28.119:39480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-high-og-wmns-silver-toe/"] [unique_id "amuCsJSUkh3e5AhEJOB-_QABxgs"]
[Thu Jul 30 11:58:24.923385 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:24.951494 2026] [security2:error] [pid 642360:tid 642424] [remote 57.141.0.25:36296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuCsJSUkh3e5AhEJOB_AQABzD8"]
[Thu Jul 30 11:58:25.022514 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:25.126271 2026] [security2:error] [pid 642360:tid 642500] [client 20.226.5.174:34586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/as.php"] [unique_id "amuCsZSUkh3e5AhEJOB_BgAAAZk"]
[Thu Jul 30 11:58:25.471910 2026] [core:notice] [pid 642360:tid 642556] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:27.348953 2026] [security2:error] [pid 643253:tid 643498] [client 213.152.161.219:49394] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCs8jqbtjBYzqM1uYpCQAAAHI"]
[Thu Jul 30 11:58:27.349067 2026] [security2:error] [pid 643253:tid 643498] [client 213.152.161.219:49394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCs8jqbtjBYzqM1uYpCQAAAHI"]
[Thu Jul 30 11:58:27.738496 2026] [autoindex:error] [pid 642360:tid 642417] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:27.739426 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCs5SUkh3e5AhEJOB_MQABjzg"]
[Thu Jul 30 11:58:28.127258 2026] [core:notice] [pid 642360:tid 642568] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:28.131241 2026] [security2:error] [pid 642360:tid 642568] [client 103.215.74.26:38634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "777"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCtJSUkh3e5AhEJOB_NgAAAd0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:28.145831 2026] [autoindex:error] [pid 642360:tid 642412] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.146681 2026] [security2:error] [pid 642360:tid 642511] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_NwABpDM"]
[Thu Jul 30 11:58:28.315546 2026] [autoindex:error] [pid 642360:tid 642437] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.316443 2026] [security2:error] [pid 642360:tid 642590] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_PQAB80w"]
[Thu Jul 30 11:58:28.388613 2026] [security2:error] [pid 642360:tid 642522] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCs5SUkh3e5AhEJOB_KwABrzw"]
[Thu Jul 30 11:58:28.483777 2026] [autoindex:error] [pid 642360:tid 642418] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.484622 2026] [security2:error] [pid 642360:tid 642584] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_PgAB7Tk"]
[Thu Jul 30 11:58:28.650934 2026] [autoindex:error] [pid 642360:tid 642378] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.651707 2026] [security2:error] [pid 642360:tid 642556] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_QAAB0RE"]
[Thu Jul 30 11:58:28.819245 2026] [autoindex:error] [pid 642360:tid 642440] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.820020 2026] [security2:error] [pid 642360:tid 642594] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_RwAB908"]
[Thu Jul 30 11:58:28.901171 2026] [core:notice] [pid 642360:tid 642586] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:28.907613 2026] [security2:error] [pid 642360:tid 642586] [client 103.215.74.26:38644] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCtJSUkh3e5AhEJOB_SgAAAe8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:28.989338 2026] [autoindex:error] [pid 642360:tid 642401] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:28.990106 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtJSUkh3e5AhEJOB_SwABkCg"]
[Thu Jul 30 11:58:29.160504 2026] [autoindex:error] [pid 642360:tid 642419] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:29.161514 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCtZSUkh3e5AhEJOB_TwACCTo"]
[Thu Jul 30 11:58:29.646214 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:29.651324 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:38648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "790"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCtcjqbtjBYzqM1uYpEAAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:29.652971 2026] [security2:error] [pid 642360:tid 642505] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCtZSUkh3e5AhEJOB_TAABnjE"]
[Thu Jul 30 11:58:29.702990 2026] [core:error] [pid 642360:tid 642566] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 11:58:29.703015 2026] [core:error] [pid 642360:tid 642566] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 11:58:29.726777 2026] [security2:error] [pid 642360:tid 642530] [client 20.226.5.174:34766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/atomlib.php"] [unique_id "amuCtZSUkh3e5AhEJOB_WwAAAbc"]
[Thu Jul 30 11:58:30.378871 2026] [core:notice] [pid 642360:tid 642605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:30.383136 2026] [security2:error] [pid 642360:tid 642605] [client 103.215.74.26:38656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCtpSUkh3e5AhEJOB_ZAAAAgI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:30.806864 2026] [security2:error] [pid 643253:tid 643446] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCtsjqbtjBYzqM1uYpEwAAPkA"]
[Thu Jul 30 11:58:31.026827 2026] [core:notice] [pid 642360:tid 642527] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:31.280716 2026] [security2:error] [pid 642360:tid 642542] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCtZSUkh3e5AhEJOB_UgABwys"]
[Thu Jul 30 11:58:31.280752 2026] [security2:error] [pid 642360:tid 642542] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCtZSUkh3e5AhEJOB_UgABwys"]
[Thu Jul 30 11:58:31.936853 2026] [security2:error] [pid 642360:tid 642571] [client 176.241.66.87:58846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCt5SUkh3e5AhEJOB_dwAAAeA"]
[Thu Jul 30 11:58:31.937003 2026] [security2:error] [pid 642360:tid 642571] [client 176.241.66.87:58846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCt5SUkh3e5AhEJOB_dwAAAeA"]
[Thu Jul 30 11:58:31.939653 2026] [security2:error] [pid 643253:tid 643400] [client 20.226.5.174:34575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/autoload_classmap.php"] [unique_id "amuCt8jqbtjBYzqM1uYpGgAAABA"]
[Thu Jul 30 11:58:32.032120 2026] [core:notice] [pid 642360:tid 642583] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:32.092717 2026] [security2:error] [pid 642360:tid 642610] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCt5SUkh3e5AhEJOB_cgACB00"]
[Thu Jul 30 11:58:32.092755 2026] [security2:error] [pid 642360:tid 642610] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCt5SUkh3e5AhEJOB_cgACB00"]
[Thu Jul 30 11:58:32.282370 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:32.659719 2026] [security2:error] [pid 642360:tid 642556] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCuJSUkh3e5AhEJOB_fQAB0VI"]
[Thu Jul 30 11:58:32.659747 2026] [security2:error] [pid 642360:tid 642556] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCuJSUkh3e5AhEJOB_fQAB0VI"]
[Thu Jul 30 11:58:32.829613 2026] [autoindex:error] [pid 642360:tid 642446] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:32.830405 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuJSUkh3e5AhEJOB_iwACCVU"]
[Thu Jul 30 11:58:32.923036 2026] [security2:error] [pid 642360:tid 642616] [client 209.126.2.173:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kbaagency.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCuJSUkh3e5AhEJOB_jwAAAg0"]
[Thu Jul 30 11:58:33.001495 2026] [autoindex:error] [pid 642360:tid 642467] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.002425 2026] [security2:error] [pid 642360:tid 642591] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuJSUkh3e5AhEJOB_kgAB9Go"]
[Thu Jul 30 11:58:33.171062 2026] [security2:error] [pid 642360:tid 642517] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "amuCuZSUkh3e5AhEJOB_lAABqmQ"]
[Thu Jul 30 11:58:33.238077 2026] [security2:error] [pid 642360:tid 642546] [client 20.226.5.174:27787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/bb.php"] [unique_id "amuCuZSUkh3e5AhEJOB_lQAAAcc"]
[Thu Jul 30 11:58:33.347805 2026] [autoindex:error] [pid 642360:tid 642407] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.348609 2026] [security2:error] [pid 642360:tid 642611] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuZSUkh3e5AhEJOB_lgACCC4"]
[Thu Jul 30 11:58:33.517792 2026] [autoindex:error] [pid 642360:tid 642445] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.518621 2026] [security2:error] [pid 642360:tid 642548] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuZSUkh3e5AhEJOB_mQAByVQ"]
[Thu Jul 30 11:58:33.684842 2026] [autoindex:error] [pid 642360:tid 642466] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.685686 2026] [security2:error] [pid 642360:tid 642567] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuZSUkh3e5AhEJOB_ngAB3Gk"]
[Thu Jul 30 11:58:33.854582 2026] [autoindex:error] [pid 642360:tid 642464] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:33.855470 2026] [security2:error] [pid 642360:tid 642588] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCuZSUkh3e5AhEJOB_nwAB8Wc"]
[Thu Jul 30 11:58:34.024906 2026] [autoindex:error] [pid 642360:tid 642456] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:34.025733 2026] [security2:error] [pid 642360:tid 642509] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCupSUkh3e5AhEJOB_owABol8"]
[Thu Jul 30 11:58:34.519443 2026] [security2:error] [pid 642360:tid 642527] [client 20.226.5.174:27820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/bnm.php"] [unique_id "amuCupSUkh3e5AhEJOB_qwAAAbQ"]
[Thu Jul 30 11:58:34.566361 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCupSUkh3e5AhEJOB_pwABj1c"]
[Thu Jul 30 11:58:34.566398 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCupSUkh3e5AhEJOB_pwABj1c"]
[Thu Jul 30 11:58:35.114107 2026] [security2:error] [pid 642360:tid 642577] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCupSUkh3e5AhEJOB_rwAB5mM"]
[Thu Jul 30 11:58:35.114139 2026] [security2:error] [pid 642360:tid 642577] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCupSUkh3e5AhEJOB_rwAB5mM"]
[Thu Jul 30 11:58:35.418359 2026] [autoindex:error] [pid 642360:tid 642477] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:35.419198 2026] [security2:error] [pid 642360:tid 642554] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCu5SUkh3e5AhEJOB_uQABz3Q"]
[Thu Jul 30 11:58:35.585836 2026] [cgid:error] [pid 642360:tid 642471] [remote 143.244.57.82:0] AH01265: stderr from /home1/injnyxte/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 11:58:35.586655 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCu5SUkh3e5AhEJOB_vQABzW4"]
[Thu Jul 30 11:58:36.102253 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:36.106262 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:24612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCvMjqbtjBYzqM1uYpIwAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:36.136213 2026] [security2:error] [pid 642360:tid 642483] [remote 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCu5SUkh3e5AhEJOB_wAAB_3o"]
[Thu Jul 30 11:58:36.136249 2026] [security2:error] [pid 642360:tid 642483] [remote 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCu5SUkh3e5AhEJOB_wAAB_3o"]
[Thu Jul 30 11:58:36.181701 2026] [security2:error] [pid 643253:tid 643322] [remote 74.7.241.60:46880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/article.php"] [unique_id "amuCvMjqbtjBYzqM1uYpJAAAYEM"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/main_image_6a2a8e70efd49.jpg
[Thu Jul 30 11:58:36.702447 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:36.836720 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:36.844436 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:24618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "769"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCvJSUkh3e5AhEJOB_0wAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:36.893111 2026] [security2:error] [pid 642360:tid 642546] [client 20.226.5.174:27801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/bootstrap.php"] [unique_id "amuCvJSUkh3e5AhEJOB_1AAAAcc"]
[Thu Jul 30 11:58:36.911161 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvJSUkh3e5AhEJOB_zgABkBo"]
[Thu Jul 30 11:58:36.911184 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvJSUkh3e5AhEJOB_zgABkBo"]
[Thu Jul 30 11:58:37.164771 2026] [security2:error] [pid 642360:tid 642540] [client 173.239.218.8:43615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuCvZSUkh3e5AhEJOB_2wAAAcE"]
[Thu Jul 30 11:58:37.454655 2026] [security2:error] [pid 642360:tid 642578] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvZSUkh3e5AhEJOB_2gAB52s"]
[Thu Jul 30 11:58:37.454686 2026] [security2:error] [pid 642360:tid 642578] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvZSUkh3e5AhEJOB_2gAB52s"]
[Thu Jul 30 11:58:37.570059 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:37.575708 2026] [security2:error] [pid 642360:tid 642510] [client 103.215.74.26:24634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCvZSUkh3e5AhEJOB_4gAAAaM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:37.883432 2026] [security2:error] [pid 642360:tid 642610] [client 213.152.187.225:58308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuCvZSUkh3e5AhEJOB_5wAAAgc"]
[Thu Jul 30 11:58:37.883536 2026] [security2:error] [pid 642360:tid 642610] [client 213.152.187.225:58308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuCvZSUkh3e5AhEJOB_5wAAAgc"]
[Thu Jul 30 11:58:37.995397 2026] [security2:error] [pid 642360:tid 642576] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvZSUkh3e5AhEJOB_5AAB5Rs"]
[Thu Jul 30 11:58:37.995431 2026] [security2:error] [pid 642360:tid 642576] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvZSUkh3e5AhEJOB_5AAB5Rs"]
[Thu Jul 30 11:58:38.223226 2026] [security2:error] [pid 642360:tid 642600] [client 20.226.5.174:27835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/buy.php"] [unique_id "amuCvpSUkh3e5AhEJOB_7QAAAf0"]
[Thu Jul 30 11:58:38.300178 2026] [core:notice] [pid 642360:tid 642599] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:38.304148 2026] [security2:error] [pid 642360:tid 642599] [client 103.215.74.26:24644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCvpSUkh3e5AhEJOB_8AAAAfw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:38.334489 2026] [security2:error] [pid 642360:tid 642612] [client 173.239.218.125:49919] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuCvpSUkh3e5AhEJOB_9gAAAgk"]
[Thu Jul 30 11:58:38.543281 2026] [security2:error] [pid 642360:tid 642523] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvpSUkh3e5AhEJOB_7AABsG0"]
[Thu Jul 30 11:58:38.543328 2026] [security2:error] [pid 642360:tid 642523] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvpSUkh3e5AhEJOB_7AABsG0"]
[Thu Jul 30 11:58:39.025704 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:39.029734 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:24646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCv5SUkh3e5AhEJOB__gAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:39.049071 2026] [core:notice] [pid 642360:tid 642544] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:39.085037 2026] [security2:error] [pid 642360:tid 642563] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvpSUkh3e5AhEJOB_-gAB2CI"]
[Thu Jul 30 11:58:39.085067 2026] [security2:error] [pid 642360:tid 642563] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCvpSUkh3e5AhEJOB_-gAB2CI"]
[Thu Jul 30 11:58:39.246111 2026] [security2:error] [pid 642360:tid 642605] [client 173.239.218.90:31395] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/media/system/js/core.js"] [unique_id "amuCv5SUkh3e5AhEJOCABAAAAgI"]
[Thu Jul 30 11:58:39.468565 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:39.626355 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCv5SUkh3e5AhEJOCAAwABoHY"]
[Thu Jul 30 11:58:39.626386 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCv5SUkh3e5AhEJOCAAwABoHY"]
[Thu Jul 30 11:58:39.917533 2026] [security2:error] [pid 642360:tid 642540] [client 20.226.5.174:27781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/chosen.php"] [unique_id "amuCv5SUkh3e5AhEJOCAIwAAAcE"]
[Thu Jul 30 11:58:39.976516 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:40.178663 2026] [security2:error] [pid 642360:tid 642538] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCv5SUkh3e5AhEJOCAIgABvx8"]
[Thu Jul 30 11:58:40.178697 2026] [security2:error] [pid 642360:tid 642538] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCv5SUkh3e5AhEJOCAIgABvx8"]
[Thu Jul 30 11:58:40.179668 2026] [security2:error] [pid 642360:tid 642527] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuCwJSUkh3e5AhEJOCAJgAAAbQ"]
[Thu Jul 30 11:58:40.488169 2026] [core:notice] [pid 643253:tid 643439] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:40.562745 2026] [security2:error] [pid 642360:tid 642515] [client 173.249.217.7:47840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuCwJSUkh3e5AhEJOCAKwAAAag"]
[Thu Jul 30 11:58:40.562887 2026] [security2:error] [pid 642360:tid 642515] [client 173.249.217.7:47840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuCwJSUkh3e5AhEJOCAKwAAAag"]
[Thu Jul 30 11:58:40.650155 2026] [security2:error] [pid 642360:tid 642583] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwJSUkh3e5AhEJOCALAAB7Ew"]
[Thu Jul 30 11:58:40.650183 2026] [security2:error] [pid 642360:tid 642583] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwJSUkh3e5AhEJOCALAAB7Ew"]
[Thu Jul 30 11:58:41.260374 2026] [security2:error] [pid 642360:tid 642570] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-admin/index.php"] [unique_id "amuCwJSUkh3e5AhEJOCAMgAB3zk"]
[Thu Jul 30 11:58:41.402117 2026] [security2:error] [pid 642360:tid 642435] [remote 143.244.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuCwZSUkh3e5AhEJOCAOgACCUo"]
[Thu Jul 30 11:58:41.402318 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuCwZSUkh3e5AhEJOCAOgACCUo"]
[Thu Jul 30 11:58:41.954734 2026] [security2:error] [pid 642360:tid 642561] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwZSUkh3e5AhEJOCAPQAB1k8"]
[Thu Jul 30 11:58:41.954759 2026] [security2:error] [pid 642360:tid 642561] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwZSUkh3e5AhEJOCAPQAB1k8"]
[Thu Jul 30 11:58:41.984276 2026] [security2:error] [pid 643253:tid 643490] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCwcjqbtjBYzqM1uYpOgAAAGo"]
[Thu Jul 30 11:58:42.159966 2026] [security2:error] [pid 642360:tid 642574] [client 20.226.5.174:34564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/class-wp-image.php"] [unique_id "amuCwpSUkh3e5AhEJOCASQAAAeM"]
[Thu Jul 30 11:58:42.295802 2026] [security2:error] [pid 642360:tid 642535] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCwZSUkh3e5AhEJOCAQAAAAbw"]
[Thu Jul 30 11:58:42.302040 2026] [security2:error] [pid 642360:tid 642575] [client 176.241.66.87:44006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCwpSUkh3e5AhEJOCASgAAAeQ"]
[Thu Jul 30 11:58:42.302219 2026] [security2:error] [pid 642360:tid 642575] [client 176.241.66.87:44006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCwpSUkh3e5AhEJOCASgAAAeQ"]
[Thu Jul 30 11:58:42.501799 2026] [security2:error] [pid 642360:tid 642579] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCASAAB6Do"]
[Thu Jul 30 11:58:42.501827 2026] [security2:error] [pid 642360:tid 642579] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCASAAB6Do"]
[Thu Jul 30 11:58:43.066924 2026] [security2:error] [pid 642360:tid 642546] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCAUwABxyY"]
[Thu Jul 30 11:58:43.066952 2026] [security2:error] [pid 642360:tid 642546] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCAUwABxyY"]
[Thu Jul 30 11:58:43.420751 2026] [security2:error] [pid 642360:tid 642496] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuCwpSUkh3e5AhEJOCAWAAAAZU"]
[Thu Jul 30 11:58:43.622816 2026] [security2:error] [pid 642360:tid 642536] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCw5SUkh3e5AhEJOCAXgABvV0"]
[Thu Jul 30 11:58:43.622849 2026] [security2:error] [pid 642360:tid 642536] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCw5SUkh3e5AhEJOCAXgABvV0"]
[Thu Jul 30 11:58:44.185416 2026] [security2:error] [pid 642360:tid 642577] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCw5SUkh3e5AhEJOCAaQAB5jA"]
[Thu Jul 30 11:58:44.185446 2026] [security2:error] [pid 642360:tid 642577] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCw5SUkh3e5AhEJOCAaQAB5jA"]
[Thu Jul 30 11:58:44.742518 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxJSUkh3e5AhEJOCAcQABzV4"]
[Thu Jul 30 11:58:44.742550 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxJSUkh3e5AhEJOCAcQABzV4"]
[Thu Jul 30 11:58:44.780108 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:44.784579 2026] [security2:error] [pid 643253:tid 643470] [client 103.215.74.26:39190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCxMjqbtjBYzqM1uYpRQAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:45.310596 2026] [security2:error] [pid 642360:tid 642611] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxJSUkh3e5AhEJOCAeQACCE4"]
[Thu Jul 30 11:58:45.310634 2026] [security2:error] [pid 642360:tid 642611] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxJSUkh3e5AhEJOCAeQACCE4"]
[Thu Jul 30 11:58:45.502283 2026] [core:notice] [pid 642360:tid 642506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:45.509725 2026] [security2:error] [pid 642360:tid 642506] [client 103.215.74.26:39194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCxZSUkh3e5AhEJOCAhQAAAZ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:45.864363 2026] [security2:error] [pid 642360:tid 642601] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxZSUkh3e5AhEJOCAgwAB_lg"]
[Thu Jul 30 11:58:45.864401 2026] [security2:error] [pid 642360:tid 642601] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxZSUkh3e5AhEJOCAgwAB_lg"]
[Thu Jul 30 11:58:46.260645 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:46.266033 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:39196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCxsjqbtjBYzqM1uYpSQAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:46.434444 2026] [security2:error] [pid 642360:tid 642604] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxpSUkh3e5AhEJOCAkAACAWQ"]
[Thu Jul 30 11:58:46.434474 2026] [security2:error] [pid 642360:tid 642604] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxpSUkh3e5AhEJOCAkAACAWQ"]
[Thu Jul 30 11:58:46.974098 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxpSUkh3e5AhEJOCAmgABy2E"]
[Thu Jul 30 11:58:46.974128 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCxpSUkh3e5AhEJOCAmgABy2E"]
[Thu Jul 30 11:58:46.980575 2026] [core:notice] [pid 642360:tid 642547] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:46.984719 2026] [security2:error] [pid 642360:tid 642547] [client 103.215.74.26:39212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCxpSUkh3e5AhEJOCAnwAAAcg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:47.563187 2026] [security2:error] [pid 642360:tid 642565] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCx5SUkh3e5AhEJOCApQAB2l8"]
[Thu Jul 30 11:58:47.563223 2026] [security2:error] [pid 642360:tid 642565] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCx5SUkh3e5AhEJOCApQAB2l8"]
[Thu Jul 30 11:58:47.713527 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:47.717929 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:39214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCx8jqbtjBYzqM1uYpUQAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:48.107521 2026] [security2:error] [pid 642360:tid 642535] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCx5SUkh3e5AhEJOCAsAABvHE"]
[Thu Jul 30 11:58:48.107547 2026] [security2:error] [pid 642360:tid 642535] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCx5SUkh3e5AhEJOCAsAABvHE"]
[Thu Jul 30 11:58:48.329656 2026] [security2:error] [pid 642360:tid 642519] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyJSUkh3e5AhEJOCAuAABrHg"]
[Thu Jul 30 11:58:48.455271 2026] [core:notice] [pid 642360:tid 642558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:48.459575 2026] [security2:error] [pid 642360:tid 642558] [client 103.215.74.26:39224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCyJSUkh3e5AhEJOCAuwAAAdM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:48.879144 2026] [security2:error] [pid 642360:tid 642542] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyJSUkh3e5AhEJOCAvAABw3Q"]
[Thu Jul 30 11:58:48.879173 2026] [security2:error] [pid 642360:tid 642542] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyJSUkh3e5AhEJOCAvAABw3Q"]
[Thu Jul 30 11:58:49.191219 2026] [core:notice] [pid 642360:tid 642524] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:49.195953 2026] [security2:error] [pid 642360:tid 642524] [client 103.215.74.26:39230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCyZSUkh3e5AhEJOCAyAAAAbE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:49.435850 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyZSUkh3e5AhEJOCAxQABuHM"]
[Thu Jul 30 11:58:49.435880 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyZSUkh3e5AhEJOCAxQABuHM"]
[Thu Jul 30 11:58:49.912194 2026] [core:notice] [pid 642360:tid 642584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:49.916710 2026] [security2:error] [pid 642360:tid 642584] [client 103.215.74.26:39244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCyZSUkh3e5AhEJOCA2AAAAe0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:49.989614 2026] [security2:error] [pid 642360:tid 642526] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyZSUkh3e5AhEJOCA0AABsxg"]
[Thu Jul 30 11:58:49.989646 2026] [security2:error] [pid 642360:tid 642526] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCyZSUkh3e5AhEJOCA0AABsxg"]
[Thu Jul 30 11:58:50.542816 2026] [security2:error] [pid 642360:tid 642554] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCypSUkh3e5AhEJOCA2QABz38"]
[Thu Jul 30 11:58:50.542845 2026] [security2:error] [pid 642360:tid 642554] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCypSUkh3e5AhEJOCA2QABz38"]
[Thu Jul 30 11:58:50.582709 2026] [security2:error] [pid 642360:tid 642504] [client 20.226.5.174:27784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/classsmtps.php"] [unique_id "amuCypSUkh3e5AhEJOCA5QAAAZ0"]
[Thu Jul 30 11:58:50.640792 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:50.646020 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:39260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCysjqbtjBYzqM1uYpWgAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:51.083962 2026] [security2:error] [pid 642360:tid 642528] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCypSUkh3e5AhEJOCA6QABtWs"]
[Thu Jul 30 11:58:51.084004 2026] [security2:error] [pid 642360:tid 642528] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCypSUkh3e5AhEJOCA6QABtWs"]
[Thu Jul 30 11:58:51.407378 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:51.411950 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:39272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCy5SUkh3e5AhEJOCA8wAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:51.561488 2026] [security2:error] [pid 643253:tid 643339] [remote 57.141.0.36:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amuCy8jqbtjBYzqM1uYpXAAASlQ"]
[Thu Jul 30 11:58:51.618711 2026] [security2:error] [pid 642360:tid 642469] [remote 57.141.0.8:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuCy5SUkh3e5AhEJOCA9AABuWw"]
[Thu Jul 30 11:58:51.629914 2026] [security2:error] [pid 642360:tid 642580] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCy5SUkh3e5AhEJOCA7AAB6XI"]
[Thu Jul 30 11:58:51.629942 2026] [security2:error] [pid 642360:tid 642580] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCy5SUkh3e5AhEJOCA7AAB6XI"]
[Thu Jul 30 11:58:52.119003 2026] [core:notice] [pid 642360:tid 642379] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:52.145557 2026] [core:notice] [pid 642360:tid 642492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:52.149582 2026] [security2:error] [pid 642360:tid 642492] [client 103.215.74.26:39286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCzJSUkh3e5AhEJOCA_QAAAZE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:52.251508 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCy5SUkh3e5AhEJOCA-AABriU"]
[Thu Jul 30 11:58:52.251537 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCy5SUkh3e5AhEJOCA-AABriU"]
[Thu Jul 30 11:58:52.389137 2026] [core:notice] [pid 642360:tid 642370] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:52.468578 2026] [autoindex:error] [pid 642360:tid 642395] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:52.469468 2026] [security2:error] [pid 642360:tid 642527] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzJSUkh3e5AhEJOCBAwABtCI"]
[Thu Jul 30 11:58:52.537997 2026] [security2:error] [pid 643253:tid 643482] [client 20.226.5.174:27819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/classwithtostring.php"] [unique_id "amuCzMjqbtjBYzqM1uYpYQAAAGI"]
[Thu Jul 30 11:58:52.878790 2026] [core:notice] [pid 642360:tid 642547] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:52.882744 2026] [security2:error] [pid 642360:tid 642547] [client 103.215.74.26:39292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCzJSUkh3e5AhEJOCBDAAAAcg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:52.944382 2026] [security2:error] [pid 642360:tid 642534] [client 176.241.66.87:44708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCzJSUkh3e5AhEJOCBDQAAAbs"]
[Thu Jul 30 11:58:52.944574 2026] [security2:error] [pid 642360:tid 642534] [client 176.241.66.87:44708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuCzJSUkh3e5AhEJOCBDQAAAbs"]
[Thu Jul 30 11:58:52.954918 2026] [proxy:error] [pid 642360:tid 642386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:58:52.955021 2026] [proxy_http:error] [pid 642360:tid 642386] [remote 74.7.228.22:59822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:58:52.955674 2026] [proxy:error] [pid 642360:tid 642386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:58:52.955719 2026] [proxy_http:error] [pid 642360:tid 642386] [remote 74.7.228.22:59822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:58:53.019920 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCzJSUkh3e5AhEJOCBBwABywQ"]
[Thu Jul 30 11:58:53.019962 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCzJSUkh3e5AhEJOCBBwABywQ"]
[Thu Jul 30 11:58:53.192601 2026] [autoindex:error] [pid 642360:tid 642424] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:53.193511 2026] [security2:error] [pid 642360:tid 642609] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzZSUkh3e5AhEJOCBEQACBj8"]
[Thu Jul 30 11:58:53.317682 2026] [security2:error] [pid 642360:tid 642515] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuCzJSUkh3e5AhEJOCBCAABqAI"]
[Thu Jul 30 11:58:53.411539 2026] [autoindex:error] [pid 642360:tid 642400] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:53.412361 2026] [security2:error] [pid 642360:tid 642603] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzZSUkh3e5AhEJOCBEgACACc"]
[Thu Jul 30 11:58:53.608714 2026] [core:notice] [pid 642360:tid 642565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:53.613171 2026] [security2:error] [pid 642360:tid 642565] [client 103.215.74.26:52694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCzZSUkh3e5AhEJOCBGgAAAdo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:53.969995 2026] [security2:error] [pid 642360:tid 642602] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCzZSUkh3e5AhEJOCBGQAB_yM"]
[Thu Jul 30 11:58:53.970028 2026] [security2:error] [pid 642360:tid 642602] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCzZSUkh3e5AhEJOCBGQAB_yM"]
[Thu Jul 30 11:58:54.142769 2026] [autoindex:error] [pid 642360:tid 642389] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.143511 2026] [security2:error] [pid 642360:tid 642616] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBIQACDRw"]
[Thu Jul 30 11:58:54.195156 2026] [security2:error] [pid 642360:tid 642614] [client 74.248.33.8:35645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuCzpSUkh3e5AhEJOCBIgAAAgs"]
[Thu Jul 30 11:58:54.312607 2026] [autoindex:error] [pid 642360:tid 642423] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.313392 2026] [security2:error] [pid 642360:tid 642617] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBIwACDj4"]
[Thu Jul 30 11:58:54.334749 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:54.341304 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:52710] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCzsjqbtjBYzqM1uYpZAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:54.481822 2026] [autoindex:error] [pid 642360:tid 642480] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.482670 2026] [security2:error] [pid 642360:tid 642528] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBJgABtXc"]
[Thu Jul 30 11:58:54.591684 2026] [security2:error] [pid 642360:tid 642390] [remote 37.140.254.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.254.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/archivarix.cms.php"] [unique_id "amuCzpSUkh3e5AhEJOCBKwAByh0"]
[Thu Jul 30 11:58:54.598477 2026] [core:notice] [pid 642360:tid 642505] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:54.600632 2026] [core:notice] [pid 643253:tid 643341] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:54.651671 2026] [autoindex:error] [pid 642360:tid 642429] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.652506 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBMQABoEQ"]
[Thu Jul 30 11:58:54.820317 2026] [autoindex:error] [pid 642360:tid 642392] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.821161 2026] [security2:error] [pid 642360:tid 642564] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBMgAB2R8"]
[Thu Jul 30 11:58:54.988561 2026] [autoindex:error] [pid 642360:tid 642408] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:54.989455 2026] [security2:error] [pid 642360:tid 642546] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCzpSUkh3e5AhEJOCBNQABxy8"]
[Thu Jul 30 11:58:55.096155 2026] [core:notice] [pid 642360:tid 642545] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:55.102821 2026] [security2:error] [pid 642360:tid 642545] [client 103.215.74.26:52720] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCz5SUkh3e5AhEJOCBOQAAAcY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:55.159047 2026] [autoindex:error] [pid 642360:tid 642437] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:55.159901 2026] [security2:error] [pid 642360:tid 642571] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCz5SUkh3e5AhEJOCBOwAB4Ew"]
[Thu Jul 30 11:58:55.288371 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:55.289769 2026] [security2:error] [pid 642360:tid 642580] [client 74.248.33.8:26176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/m.php"] [unique_id "amuCz5SUkh3e5AhEJOCBPQAAAek"]
[Thu Jul 30 11:58:55.328591 2026] [autoindex:error] [pid 642360:tid 642371] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:55.329398 2026] [security2:error] [pid 642360:tid 642590] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuCz5SUkh3e5AhEJOCBPgAB8wo"]
[Thu Jul 30 11:58:55.593151 2026] [security2:error] [pid 642360:tid 642604] [client 213.152.161.219:49416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuCz5SUkh3e5AhEJOCBRwAAAgE"]
[Thu Jul 30 11:58:55.593304 2026] [security2:error] [pid 642360:tid 642604] [client 213.152.161.219:49416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuCz5SUkh3e5AhEJOCBRwAAAgE"]
[Thu Jul 30 11:58:55.837039 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:55.840951 2026] [security2:error] [pid 642360:tid 642551] [client 103.215.74.26:52732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuCz5SUkh3e5AhEJOCBSAAAAcw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:55.876207 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBQQABuCo"]
[Thu Jul 30 11:58:55.876231 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBQQABuCo"]
[Thu Jul 30 11:58:55.978204 2026] [security2:error] [pid 642360:tid 642556] [client 172.237.109.114:1877] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amuCz5SUkh3e5AhEJOCBTAAAAdE"]
[Thu Jul 30 11:58:55.992678 2026] [security2:error] [pid 643253:tid 643416] [client 172.237.109.114:51913] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amuCz8jqbtjBYzqM1uYpagAAACA"]
[Thu Jul 30 11:58:56.050513 2026] [security2:error] [pid 642360:tid 642513] [client 185.191.171.3:14730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2023/01/02/voces-ouviram-lula-falar-em-combater-a-corrupcao-nos-seus-discursos-diz-sergio-moro/"] [unique_id "amuC0JSUkh3e5AhEJOCBUwAAAaY"]
[Thu Jul 30 11:58:56.050663 2026] [security2:error] [pid 642360:tid 642513] [client 185.191.171.3:14730] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2023/01/02/voces-ouviram-lula-falar-em-combater-a-corrupcao-nos-seus-discursos-diz-sergio-moro/"] [unique_id "amuC0JSUkh3e5AhEJOCBUwAAAaY"]
[Thu Jul 30 11:58:56.053006 2026] [autoindex:error] [pid 642360:tid 642378] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.053870 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBUgACCRE"]
[Thu Jul 30 11:58:56.094584 2026] [security2:error] [pid 642360:tid 642555] [client 20.226.5.174:27829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/config.php"] [unique_id "amuC0JSUkh3e5AhEJOCBVwAAAdA"]
[Thu Jul 30 11:58:56.229901 2026] [autoindex:error] [pid 642360:tid 642427] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.231018 2026] [security2:error] [pid 642360:tid 642495] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBWAABlEI"]
[Thu Jul 30 11:58:56.411897 2026] [autoindex:error] [pid 642360:tid 642440] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.412858 2026] [security2:error] [pid 642360:tid 642503] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBWgABnE8"]
[Thu Jul 30 11:58:56.583161 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:56.589220 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:52744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "776"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC0MjqbtjBYzqM1uYpbwAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:56.590611 2026] [autoindex:error] [pid 642360:tid 642431] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.591772 2026] [security2:error] [pid 642360:tid 642517] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBXQABqkY"]
[Thu Jul 30 11:58:56.633158 2026] [security2:error] [pid 642360:tid 642577] [client 172.237.109.114:19191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBSgAAAeY"]
[Thu Jul 30 11:58:56.656850 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:6743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBSQAAAec"]
[Thu Jul 30 11:58:56.657320 2026] [security2:error] [pid 642360:tid 642547] [client 172.237.109.114:14657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBSwAAAcg"]
[Thu Jul 30 11:58:56.657551 2026] [security2:error] [pid 643253:tid 643406] [client 172.237.109.114:57124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz8jqbtjBYzqM1uYpaAAAABY"]
[Thu Jul 30 11:58:56.663758 2026] [security2:error] [pid 642360:tid 642562] [client 172.237.109.114:29294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBTgAAAdc"]
[Thu Jul 30 11:58:56.686299 2026] [security2:error] [pid 642360:tid 642599] [client 172.237.109.114:1473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuC0JSUkh3e5AhEJOCBTwAAAfw"]
[Thu Jul 30 11:58:56.690653 2026] [security2:error] [pid 642360:tid 642560] [client 172.237.109.114:45338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz5SUkh3e5AhEJOCBTQAAAdU"]
[Thu Jul 30 11:58:56.691118 2026] [security2:error] [pid 643253:tid 643471] [client 172.237.109.114:10365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuCz8jqbtjBYzqM1uYpaQAAAFc"]
[Thu Jul 30 11:58:56.719816 2026] [security2:error] [pid 643253:tid 643456] [client 172.237.109.114:30055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuC0MjqbtjBYzqM1uYpbAAAAEg"]
[Thu Jul 30 11:58:56.728528 2026] [security2:error] [pid 643253:tid 643461] [client 172.237.109.114:54309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuC0MjqbtjBYzqM1uYpawAAAE0"]
[Thu Jul 30 11:58:56.759665 2026] [autoindex:error] [pid 642360:tid 642406] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.760441 2026] [security2:error] [pid 642360:tid 642574] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBYwAB4y0"]
[Thu Jul 30 11:58:56.928382 2026] [autoindex:error] [pid 642360:tid 642419] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:56.929239 2026] [security2:error] [pid 642360:tid 642605] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0JSUkh3e5AhEJOCBZAACAjo"]
[Thu Jul 30 11:58:56.956680 2026] [security2:error] [pid 642360:tid 642584] [client 74.248.33.8:35627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuC0JSUkh3e5AhEJOCBYgAAAe0"]
[Thu Jul 30 11:58:57.168797 2026] [autoindex:error] [pid 642360:tid 642422] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:57.169597 2026] [security2:error] [pid 642360:tid 642616] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0ZSUkh3e5AhEJOCBZQACDT0"]
[Thu Jul 30 11:58:57.263718 2026] [security2:error] [pid 642360:tid 642502] [client 20.226.5.174:27807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/core.php"] [unique_id "amuC0ZSUkh3e5AhEJOCBawAAAZs"]
[Thu Jul 30 11:58:57.329201 2026] [core:notice] [pid 642360:tid 642614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:57.335969 2026] [security2:error] [pid 642360:tid 642614] [client 103.215.74.26:52746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC0ZSUkh3e5AhEJOCBbQAAAgs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:57.387810 2026] [autoindex:error] [pid 642360:tid 642413] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:58:57.388677 2026] [security2:error] [pid 642360:tid 642533] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC0ZSUkh3e5AhEJOCBbAABujQ"]
[Thu Jul 30 11:58:57.555732 2026] [security2:error] [pid 643253:tid 643429] [client 74.248.33.8:50269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/wk/index.php"] [unique_id "amuC0cjqbtjBYzqM1uYpeQAAAC0"]
[Thu Jul 30 11:58:57.792341 2026] [security2:error] [pid 642360:tid 642519] [client 57.141.0.18:53226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuC0ZSUkh3e5AhEJOCBbgABrCA"], referer: https://igetvape-australia.com/product/iget-bar-strawberry-kiwi-ice/?add-to-cart=118
[Thu Jul 30 11:58:58.005630 2026] [security2:error] [pid 642360:tid 642538] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0ZSUkh3e5AhEJOCBcAABvyY"]
[Thu Jul 30 11:58:58.005665 2026] [security2:error] [pid 642360:tid 642538] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0ZSUkh3e5AhEJOCBcAABvyY"]
[Thu Jul 30 11:58:58.079486 2026] [security2:error] [pid 642360:tid 642534] [client 104.28.196.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuC0JSUkh3e5AhEJOCBWQABu0g"]
[Thu Jul 30 11:58:58.083623 2026] [core:notice] [pid 642360:tid 642606] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:58.088500 2026] [security2:error] [pid 642360:tid 642606] [client 103.215.74.26:52752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "789"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC0pSUkh3e5AhEJOCBdQAAAgM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:58.549164 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0pSUkh3e5AhEJOCBeAABkGA"]
[Thu Jul 30 11:58:58.549203 2026] [security2:error] [pid 642360:tid 642491] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0pSUkh3e5AhEJOCBeAABkGA"]
[Thu Jul 30 11:58:58.819487 2026] [core:notice] [pid 642360:tid 642492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:58.823462 2026] [security2:error] [pid 642360:tid 642492] [client 103.215.74.26:52764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC0pSUkh3e5AhEJOCBgwAAAZE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:59.097345 2026] [security2:error] [pid 642360:tid 642607] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0pSUkh3e5AhEJOCBfQACBGg"]
[Thu Jul 30 11:58:59.097375 2026] [security2:error] [pid 642360:tid 642607] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC0pSUkh3e5AhEJOCBfQACBGg"]
[Thu Jul 30 11:58:59.322554 2026] [security2:error] [pid 642360:tid 642585] [client 74.248.33.8:37701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/mini.php"] [unique_id "amuC05SUkh3e5AhEJOCBjAAAAe4"]
[Thu Jul 30 11:58:59.549531 2026] [core:notice] [pid 642360:tid 642608] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:58:59.554250 2026] [security2:error] [pid 642360:tid 642608] [client 103.215.74.26:52776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC05SUkh3e5AhEJOCBkQAAAgU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:58:59.590122 2026] [security2:error] [pid 642360:tid 642531] [client 85.208.96.201:22196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/29/joao-azevedo-exonera-zezinho-do-botafogo-do-cargo-de-secretario-de-esporte-da-paraiba/"] [unique_id "amuC05SUkh3e5AhEJOCBkgAAAbg"]
[Thu Jul 30 11:58:59.590267 2026] [security2:error] [pid 642360:tid 642531] [client 85.208.96.201:22196] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/29/joao-azevedo-exonera-zezinho-do-botafogo-do-cargo-de-secretario-de-esporte-da-paraiba/"] [unique_id "amuC05SUkh3e5AhEJOCBkgAAAbg"]
[Thu Jul 30 11:58:59.651266 2026] [security2:error] [pid 642360:tid 642555] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBiQAB0Fw"]
[Thu Jul 30 11:58:59.651299 2026] [security2:error] [pid 642360:tid 642555] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBiQAB0Fw"]
[Thu Jul 30 11:58:59.887671 2026] [core:error] [pid 642360:tid 642579] [client 74.7.244.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:59.887693 2026] [core:error] [pid 642360:tid 642579] [client 74.7.244.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:58:59.887825 2026] [security2:error] [pid 642360:tid 642579] [client 74.7.244.55:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.hvacairductscleaners.us"] [uri "/___proxy_subdomain_webdisk/website_141a2c45/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBmwAAAeg"]
[Thu Jul 30 11:58:59.888566 2026] [security2:error] [pid 643253:tid 643501] [client 74.7.244.55:46548] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.hvacairductscleaners.us"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuC08jqbtjBYzqM1uYpiAAAdV8"]
[Thu Jul 30 11:59:00.203011 2026] [authz_core:error] [pid 643253:tid 643404] [client 94.154.43.229:45654] AH01630: client denied by server configuration: /home1/jstnyxte/public_html/website_42104935/.env
[Thu Jul 30 11:59:00.224763 2026] [security2:error] [pid 642360:tid 642562] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBlgAB11Y"]
[Thu Jul 30 11:59:00.224789 2026] [security2:error] [pid 642360:tid 642562] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC05SUkh3e5AhEJOCBlgAB11Y"]
[Thu Jul 30 11:59:00.248242 2026] [security2:error] [pid 643253:tid 643486] [client 172.202.44.182:45102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amuC1MjqbtjBYzqM1uYpigAAAGY"]
[Thu Jul 30 11:59:00.420811 2026] [security2:error] [pid 642360:tid 642611] [client 20.226.5.174:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/css.php"] [unique_id "amuC1JSUkh3e5AhEJOCBowAAAgg"]
[Thu Jul 30 11:59:00.781456 2026] [security2:error] [pid 642360:tid 642568] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBogAB3VU"]
[Thu Jul 30 11:59:00.781490 2026] [security2:error] [pid 642360:tid 642568] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBogAB3VU"]
[Thu Jul 30 11:59:01.329120 2026] [security2:error] [pid 642360:tid 642519] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBqgABrFg"]
[Thu Jul 30 11:59:01.329149 2026] [security2:error] [pid 642360:tid 642519] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBqgABrFg"]
[Thu Jul 30 11:59:01.336892 2026] [security2:error] [pid 642360:tid 642508] [client 172.202.44.182:45116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/xleet.php"] [unique_id "amuC1ZSUkh3e5AhEJOCBrQAAAaE"]
[Thu Jul 30 11:59:01.496036 2026] [core:notice] [pid 642360:tid 642534] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:01.514569 2026] [security2:error] [pid 642360:tid 642549] [client 66.249.66.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.allmontecristi.com"] [uri "/index.php"] [unique_id "amuC1JSUkh3e5AhEJOCBpAAByh4"]
[Thu Jul 30 11:59:01.545539 2026] [security2:error] [pid 643253:tid 643388] [client 74.248.33.8:15448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/aa.php"] [unique_id "amuC1cjqbtjBYzqM1uYpjgAAAAQ"]
[Thu Jul 30 11:59:01.925775 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1ZSUkh3e5AhEJOCBsgABrlo"]
[Thu Jul 30 11:59:01.925803 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1ZSUkh3e5AhEJOCBsgABrlo"]
[Thu Jul 30 11:59:02.316607 2026] [security2:error] [pid 643253:tid 643449] [client 74.248.33.8:26951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/w.php"] [unique_id "amuC1sjqbtjBYzqM1uYpkgAAAEE"]
[Thu Jul 30 11:59:02.481318 2026] [security2:error] [pid 642360:tid 642526] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBvAABs2E"]
[Thu Jul 30 11:59:02.481357 2026] [security2:error] [pid 642360:tid 642526] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBvAABs2E"]
[Thu Jul 30 11:59:02.611946 2026] [security2:error] [pid 642360:tid 642586] [client 172.202.44.182:45103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ds.php"] [unique_id "amuC1pSUkh3e5AhEJOCBwwAAAe8"]
[Thu Jul 30 11:59:02.944990 2026] [core:notice] [pid 642360:tid 642608] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:03.008582 2026] [security2:error] [pid 642360:tid 642536] [client 20.226.5.174:27837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/database.php"] [unique_id "amuC15SUkh3e5AhEJOCBzgAAAb0"]
[Thu Jul 30 11:59:03.039701 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBxQAByxM"]
[Thu Jul 30 11:59:03.039734 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBxQAByxM"]
[Thu Jul 30 11:59:03.214123 2026] [autoindex:error] [pid 642360:tid 642485] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/plugins/contact-form-7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:03.214934 2026] [security2:error] [pid 642360:tid 642554] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC15SUkh3e5AhEJOCBzwABz3w"]
[Thu Jul 30 11:59:03.236125 2026] [security2:error] [pid 642360:tid 642547] [client 74.248.33.8:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amuC15SUkh3e5AhEJOCB0AAAAcg"]
[Thu Jul 30 11:59:03.252743 2026] [security2:error] [pid 642360:tid 642592] [client 66.249.66.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuC1pSUkh3e5AhEJOCBxAAB9Xs"]
[Thu Jul 30 11:59:03.573511 2026] [security2:error] [pid 642360:tid 642504] [client 176.241.66.87:45381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC15SUkh3e5AhEJOCB2AAAAZ0"]
[Thu Jul 30 11:59:03.573644 2026] [security2:error] [pid 642360:tid 642504] [client 176.241.66.87:45381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC15SUkh3e5AhEJOCB2AAAAZ0"]
[Thu Jul 30 11:59:03.726337 2026] [security2:error] [pid 643253:tid 643421] [client 172.202.44.182:45068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/f5.php"] [unique_id "amuC18jqbtjBYzqM1uYpmAAAACU"]
[Thu Jul 30 11:59:03.767681 2026] [security2:error] [pid 642360:tid 642529] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC15SUkh3e5AhEJOCB0gABtg0"]
[Thu Jul 30 11:59:03.767733 2026] [security2:error] [pid 642360:tid 642529] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC15SUkh3e5AhEJOCB0gABtg0"]
[Thu Jul 30 11:59:03.897543 2026] [core:notice] [pid 642360:tid 642593] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:03.995473 2026] [autoindex:error] [pid 642360:tid 642460] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:03.996406 2026] [security2:error] [pid 642360:tid 642614] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC15SUkh3e5AhEJOCB2gACC2M"]
[Thu Jul 30 11:59:04.346438 2026] [security2:error] [pid 643253:tid 643403] [client 20.226.5.174:34585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/db.php"] [unique_id "amuC2MjqbtjBYzqM1uYpmwAAABM"]
[Thu Jul 30 11:59:04.515617 2026] [security2:error] [pid 642360:tid 642533] [client 74.248.33.8:15477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/404.php"] [unique_id "amuC2JSUkh3e5AhEJOCB5gAAAbo"]
[Thu Jul 30 11:59:04.542885 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2JSUkh3e5AhEJOCB3wABoH4"]
[Thu Jul 30 11:59:04.542913 2026] [security2:error] [pid 642360:tid 642507] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2JSUkh3e5AhEJOCB3wABoH4"]
[Thu Jul 30 11:59:04.591479 2026] [security2:error] [pid 642360:tid 642610] [client 172.202.44.182:13074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/god4m.php"] [unique_id "amuC2JSUkh3e5AhEJOCB6QAAAgc"]
[Thu Jul 30 11:59:05.091635 2026] [security2:error] [pid 642360:tid 642539] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2JSUkh3e5AhEJOCB6gABwBU"]
[Thu Jul 30 11:59:05.091685 2026] [security2:error] [pid 642360:tid 642539] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2JSUkh3e5AhEJOCB6gABwBU"]
[Thu Jul 30 11:59:05.273529 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:05.277429 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:46066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC2cjqbtjBYzqM1uYpoAAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:05.558023 2026] [core:notice] [pid 642360:tid 642612] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:05.647010 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2ZSUkh3e5AhEJOCB9QABzQg"]
[Thu Jul 30 11:59:05.647052 2026] [security2:error] [pid 642360:tid 642552] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2ZSUkh3e5AhEJOCB9QABzQg"]
[Thu Jul 30 11:59:05.819740 2026] [autoindex:error] [pid 642360:tid 642469] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/plugins/woocommerce/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:05.820551 2026] [security2:error] [pid 642360:tid 642595] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC2ZSUkh3e5AhEJOCCAQAB-Gw"]
[Thu Jul 30 11:59:05.852083 2026] [security2:error] [pid 642360:tid 642573] [client 172.202.44.182:45056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/info.php"] [unique_id "amuC2ZSUkh3e5AhEJOCCAgAAAeI"]
[Thu Jul 30 11:59:05.989881 2026] [autoindex:error] [pid 642360:tid 642475] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/plugins/woocommerce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:05.990676 2026] [security2:error] [pid 642360:tid 642536] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC2ZSUkh3e5AhEJOCCBAABvXI"]
[Thu Jul 30 11:59:06.015128 2026] [core:notice] [pid 642360:tid 642560] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:06.019140 2026] [security2:error] [pid 642360:tid 642560] [client 103.215.74.26:46070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC2pSUkh3e5AhEJOCCBQAAAdU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:06.215849 2026] [security2:error] [pid 642360:tid 642515] [client 177.32.179.54:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.179.32.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/xmlrpc.php"] [unique_id "amuC2ZSUkh3e5AhEJOCCAwAAAag"]
[Thu Jul 30 11:59:06.216056 2026] [security2:error] [pid 642360:tid 642515] [client 177.32.179.54:62578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "asian-connect.com"] [uri "/xmlrpc.php"] [unique_id "amuC2ZSUkh3e5AhEJOCCAwAAAag"]
[Thu Jul 30 11:59:06.548056 2026] [security2:error] [pid 642360:tid 642587] [client 143.244.57.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2pSUkh3e5AhEJOCCCQAB8Bc"]
[Thu Jul 30 11:59:06.548084 2026] [security2:error] [pid 642360:tid 642587] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuC2pSUkh3e5AhEJOCCCQAB8Bc"]
[Thu Jul 30 11:59:06.688188 2026] [security2:error] [pid 643253:tid 643397] [client 74.248.33.8:24929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/init.php"] [unique_id "amuC2sjqbtjBYzqM1uYpowAAAA0"]
[Thu Jul 30 11:59:06.764913 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:06.770077 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:46074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC2sjqbtjBYzqM1uYppQAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:06.788843 2026] [security2:error] [pid 642360:tid 642563] [client 20.215.191.139:54661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/json.php"] [unique_id "amuC2pSUkh3e5AhEJOCCEAAAAdg"]
[Thu Jul 30 11:59:06.928050 2026] [security2:error] [pid 643253:tid 643508] [client 199.195.248.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuC2sjqbtjBYzqM1uYppAAAfGU"]
[Thu Jul 30 11:59:07.096381 2026] [security2:error] [pid 642360:tid 642605] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuC2pSUkh3e5AhEJOCCDgACAm0"]
[Thu Jul 30 11:59:07.231702 2026] [security2:error] [pid 642360:tid 642395] [remote 143.244.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC25SUkh3e5AhEJOCCFwAB3SI"]
[Thu Jul 30 11:59:07.231972 2026] [security2:error] [pid 642360:tid 642568] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC25SUkh3e5AhEJOCCFwAB3SI"]
[Thu Jul 30 11:59:07.324508 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:07.399377 2026] [security2:error] [pid 642360:tid 642601] [client 20.215.191.139:54669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/mini.php"] [unique_id "amuC25SUkh3e5AhEJOCCHQAAAf4"]
[Thu Jul 30 11:59:07.494852 2026] [core:notice] [pid 642360:tid 642572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:07.498926 2026] [security2:error] [pid 642360:tid 642572] [client 103.215.74.26:46076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC25SUkh3e5AhEJOCCHgAAAeE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:07.523255 2026] [proxy:error] [pid 642360:tid 642564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:59:07.523313 2026] [proxy_http:error] [pid 642360:tid 642564] [client 172.202.44.182:39224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:59:07.523855 2026] [proxy:error] [pid 642360:tid 642564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 11:59:07.523896 2026] [proxy_http:error] [pid 642360:tid 642564] [client 172.202.44.182:39224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 11:59:07.763571 2026] [security2:error] [pid 642360:tid 642519] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuC25SUkh3e5AhEJOCCHAABrAk"]
[Thu Jul 30 11:59:07.898794 2026] [security2:error] [pid 642360:tid 642365] [remote 143.244.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC25SUkh3e5AhEJOCCKAABkQQ"]
[Thu Jul 30 11:59:07.898961 2026] [security2:error] [pid 642360:tid 642492] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC25SUkh3e5AhEJOCCKAABkQQ"]
[Thu Jul 30 11:59:07.977480 2026] [authz_core:error] [pid 642360:tid 642491] [client 94.154.43.186:44060] AH01630: client denied by server configuration: /home1/jstnyxte/public_html/website_42104935/.env
[Thu Jul 30 11:59:08.028301 2026] [security2:error] [pid 642360:tid 642499] [client 20.215.191.139:54381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/chosen.php"] [unique_id "amuC3JSUkh3e5AhEJOCCLAAAAZg"]
[Thu Jul 30 11:59:08.068489 2026] [security2:error] [pid 642360:tid 642521] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/wp-content/index.php"] [unique_id "amuC3JSUkh3e5AhEJOCCLgABrj8"]
[Thu Jul 30 11:59:08.236240 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:08.240695 2026] [security2:error] [pid 643253:tid 643484] [client 103.215.74.26:46082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC3MjqbtjBYzqM1uYpqwAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:08.241219 2026] [security2:error] [pid 642360:tid 642540] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/wp-content/plugins/index.php"] [unique_id "amuC3JSUkh3e5AhEJOCCLwABwQI"]
[Thu Jul 30 11:59:08.312701 2026] [core:notice] [pid 642360:tid 642591] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:08.413008 2026] [security2:error] [pid 642360:tid 642531] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "spececigarette.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuC3JSUkh3e5AhEJOCCNwABuAA"]
[Thu Jul 30 11:59:08.635697 2026] [autoindex:error] [pid 642360:tid 642396] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:08.636462 2026] [security2:error] [pid 642360:tid 642612] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC3JSUkh3e5AhEJOCCOAACCSM"]
[Thu Jul 30 11:59:08.927201 2026] [security2:error] [pid 642360:tid 642570] [client 172.202.44.182:50523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/.__info.php"] [unique_id "amuC3JSUkh3e5AhEJOCCQAAAAd8"]
[Thu Jul 30 11:59:08.940954 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:08.977129 2026] [core:notice] [pid 642360:tid 642536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:08.981497 2026] [security2:error] [pid 642360:tid 642536] [client 103.215.74.26:46086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC3JSUkh3e5AhEJOCCQgAAAb0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:09.167644 2026] [security2:error] [pid 642360:tid 642550] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-admin/index.php"] [unique_id "amuC3JSUkh3e5AhEJOCCPAABy0E"]
[Thu Jul 30 11:59:09.303449 2026] [security2:error] [pid 642360:tid 642402] [remote 143.244.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCRwABvCk"]
[Thu Jul 30 11:59:09.303703 2026] [security2:error] [pid 642360:tid 642535] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCRwABvCk"]
[Thu Jul 30 11:59:09.320397 2026] [security2:error] [pid 642360:tid 642523] [client 20.215.191.139:54656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/kj.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCSAAAAbA"]
[Thu Jul 30 11:59:09.471804 2026] [autoindex:error] [pid 642360:tid 642397] [remote 143.244.57.82:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 11:59:09.472550 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "spececigarette.com"] [uri "/cgi-sys/403.html"] [unique_id "amuC3ZSUkh3e5AhEJOCCTAABjyQ"]
[Thu Jul 30 11:59:09.505478 2026] [security2:error] [pid 642360:tid 642597] [client 20.226.5.174:27788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/default.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCTQAAAfo"]
[Thu Jul 30 11:59:09.701324 2026] [core:notice] [pid 642360:tid 642528] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:09.705734 2026] [security2:error] [pid 642360:tid 642528] [client 103.215.74.26:46088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC3ZSUkh3e5AhEJOCCUQAAAbU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:09.762812 2026] [security2:error] [pid 642360:tid 642547] [client 193.46.199.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuC3ZSUkh3e5AhEJOCCQwAByD4"]
[Thu Jul 30 11:59:10.349313 2026] [security2:error] [pid 642360:tid 642572] [client 20.215.191.139:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-files.php"] [unique_id "amuC3pSUkh3e5AhEJOCCWAAAAeE"]
[Thu Jul 30 11:59:10.426751 2026] [core:notice] [pid 643253:tid 643405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:10.432073 2026] [security2:error] [pid 643253:tid 643405] [client 103.215.74.26:46104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC3sjqbtjBYzqM1uYprgAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:10.620215 2026] [security2:error] [pid 643253:tid 643437] [client 20.226.5.174:34573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/dropdown.php"] [unique_id "amuC3sjqbtjBYzqM1uYpsAAAADU"]
[Thu Jul 30 11:59:10.763485 2026] [security2:error] [pid 642360:tid 642496] [client 172.202.44.182:45075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/0.php"] [unique_id "amuC3pSUkh3e5AhEJOCCXwAAAZU"]
[Thu Jul 30 11:59:10.799314 2026] [core:notice] [pid 642360:tid 642500] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:11.134962 2026] [security2:error] [pid 643253:tid 643419] [client 20.215.191.139:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-setup.php"] [unique_id "amuC38jqbtjBYzqM1uYpsgAAACM"]
[Thu Jul 30 11:59:11.185086 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:11.189504 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:46108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC35SUkh3e5AhEJOCCZAAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:11.776313 2026] [security2:error] [pid 642360:tid 642514] [client 20.215.191.139:43354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/LA.php"] [unique_id "amuC35SUkh3e5AhEJOCCbQAAAac"]
[Thu Jul 30 11:59:11.846176 2026] [security2:error] [pid 642360:tid 642531] [client 20.226.5.174:27822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/edit.php"] [unique_id "amuC35SUkh3e5AhEJOCCbgAAAbg"]
[Thu Jul 30 11:59:11.913157 2026] [core:notice] [pid 643253:tid 643483] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:11.917607 2026] [security2:error] [pid 643253:tid 643483] [client 103.215.74.26:46116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC38jqbtjBYzqM1uYptQAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:12.634575 2026] [core:notice] [pid 643253:tid 643472] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:12.639514 2026] [core:notice] [pid 642360:tid 642599] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:12.644672 2026] [security2:error] [pid 642360:tid 642599] [client 103.215.74.26:46132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC4JSUkh3e5AhEJOCCeAAAAfw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:13.290664 2026] [security2:error] [pid 642360:tid 642574] [client 20.215.191.139:17594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/admin.php"] [unique_id "amuC4ZSUkh3e5AhEJOCCfwAAAeM"]
[Thu Jul 30 11:59:13.368970 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:13.373197 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:20950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC4ZSUkh3e5AhEJOCCggAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:13.619985 2026] [security2:error] [pid 642360:tid 642544] [client 172.202.44.182:45096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/07.php"] [unique_id "amuC4ZSUkh3e5AhEJOCChQAAAcU"]
[Thu Jul 30 11:59:14.113960 2026] [core:notice] [pid 642360:tid 642507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:14.118404 2026] [security2:error] [pid 642360:tid 642507] [client 103.215.74.26:20952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC4pSUkh3e5AhEJOCCigAAAaA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:14.295930 2026] [security2:error] [pid 642360:tid 642492] [client 176.241.66.87:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC4pSUkh3e5AhEJOCCjgAAAZE"]
[Thu Jul 30 11:59:14.296078 2026] [security2:error] [pid 642360:tid 642492] [client 176.241.66.87:46071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC4pSUkh3e5AhEJOCCjgAAAZE"]
[Thu Jul 30 11:59:14.345488 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:14.859624 2026] [core:notice] [pid 642360:tid 642607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:14.863660 2026] [security2:error] [pid 642360:tid 642607] [client 103.215.74.26:20954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC4pSUkh3e5AhEJOCClwAAAgQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:15.011028 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:15.241282 2026] [security2:error] [pid 642360:tid 642511] [client 20.215.191.139:36148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/class_api.php"] [unique_id "amuC45SUkh3e5AhEJOCCoQAAAaQ"]
[Thu Jul 30 11:59:15.258471 2026] [security2:error] [pid 642360:tid 642537] [client 172.202.44.182:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/dropdown.php"] [unique_id "amuC45SUkh3e5AhEJOCCogAAAb4"]
[Thu Jul 30 11:59:15.619036 2026] [core:notice] [pid 642360:tid 642536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:15.623295 2026] [security2:error] [pid 642360:tid 642536] [client 103.215.74.26:20964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC45SUkh3e5AhEJOCCpgAAAb0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:15.803366 2026] [security2:error] [pid 643253:tid 643441] [client 54.235.232.111:46546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuC4cjqbtjBYzqM1uYpxAAAADk"]
[Thu Jul 30 11:59:15.978993 2026] [core:notice] [pid 642360:tid 642575] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:16.194068 2026] [security2:error] [pid 642360:tid 642592] [client 20.226.5.174:34752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/f35.php"] [unique_id "amuC5JSUkh3e5AhEJOCCsQAAAfU"]
[Thu Jul 30 11:59:16.344281 2026] [core:notice] [pid 643253:tid 643435] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:16.346638 2026] [core:notice] [pid 642360:tid 642509] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:16.348250 2026] [security2:error] [pid 643253:tid 643435] [client 103.215.74.26:20968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC5MjqbtjBYzqM1uYpzgAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:16.406546 2026] [security2:error] [pid 642360:tid 642616] [client 172.202.44.182:45095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/makeasmtp.php"] [unique_id "amuC5JSUkh3e5AhEJOCCuAAAAg0"]
[Thu Jul 30 11:59:16.484742 2026] [security2:error] [pid 642360:tid 642490] [client 20.215.191.139:36142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuC5JSUkh3e5AhEJOCCuQAAAY8"]
[Thu Jul 30 11:59:16.785422 2026] [security2:error] [pid 642360:tid 642532] [client 20.215.191.139:54660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/defaults.php"] [unique_id "amuC5JSUkh3e5AhEJOCCvQAAAbk"]
[Thu Jul 30 11:59:17.069931 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:17.077185 2026] [security2:error] [pid 642360:tid 642520] [client 103.215.74.26:20980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC5ZSUkh3e5AhEJOCCxAAAAa0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:17.392970 2026] [security2:error] [pid 643253:tid 643452] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.saptora.com"] [uri "/index.php"] [unique_id "amuC4sjqbtjBYzqM1uYpxwAAAEQ"]
[Thu Jul 30 11:59:17.393703 2026] [security2:error] [pid 643253:tid 643418] [client 74.7.241.181:60406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.saptora.com"] [uri "/robots.txt"] [unique_id "amuC4sjqbtjBYzqM1uYpxgAAInA"]
[Thu Jul 30 11:59:17.618773 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:17.682823 2026] [security2:error] [pid 642360:tid 642521] [client 20.215.191.139:55112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuC5ZSUkh3e5AhEJOCCyQAAAa4"]
[Thu Jul 30 11:59:17.692955 2026] [security2:error] [pid 642360:tid 642604] [client 74.7.228.24:49168] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.ols.fyv.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuC5ZSUkh3e5AhEJOCCzgAAAgE"]
[Thu Jul 30 11:59:17.709245 2026] [core:notice] [pid 642360:tid 642495] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:17.851256 2026] [core:notice] [pid 642360:tid 642609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:17.862131 2026] [security2:error] [pid 642360:tid 642609] [client 103.215.74.26:20984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC5ZSUkh3e5AhEJOCC0wAAAgY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:18.374190 2026] [security2:error] [pid 642360:tid 642537] [client 20.215.191.139:36137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuC5pSUkh3e5AhEJOCC2gAAAb4"]
[Thu Jul 30 11:59:18.571421 2026] [core:notice] [pid 642360:tid 642562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:18.577872 2026] [security2:error] [pid 642360:tid 642562] [client 103.215.74.26:20988] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC5pSUkh3e5AhEJOCC3wAAAdc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:18.589291 2026] [security2:error] [pid 642360:tid 642576] [client 20.226.5.174:34764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/f7.php"] [unique_id "amuC5pSUkh3e5AhEJOCC4AAAAeU"]
[Thu Jul 30 11:59:18.750034 2026] [security2:error] [pid 642360:tid 642514] [client 20.215.191.139:54664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/gtc.php"] [unique_id "amuC5pSUkh3e5AhEJOCC4gAAAac"]
[Thu Jul 30 11:59:18.857086 2026] [security2:error] [pid 642360:tid 642575] [client 49.13.134.145:59324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuC5pSUkh3e5AhEJOCC5gAAAeQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:59:19.086311 2026] [security2:error] [pid 642360:tid 642592] [client 20.215.191.139:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/991176.php"] [unique_id "amuC55SUkh3e5AhEJOCC6gAAAfU"]
[Thu Jul 30 11:59:19.238135 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:19.245125 2026] [security2:error] [pid 642360:tid 642601] [client 49.13.134.145:59326] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC55SUkh3e5AhEJOCC6wAAAf4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:59:19.305991 2026] [core:notice] [pid 642360:tid 642502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:19.309833 2026] [security2:error] [pid 642360:tid 642502] [client 103.215.74.26:20992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC55SUkh3e5AhEJOCC8QAAAZs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:19.858071 2026] [security2:error] [pid 642360:tid 642534] [client 49.13.134.145:59342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuC55SUkh3e5AhEJOCC-AAAAbs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 11:59:19.893813 2026] [security2:error] [pid 642360:tid 642588] [client 20.215.191.139:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/import.php"] [unique_id "amuC55SUkh3e5AhEJOCC-gAAAfE"]
[Thu Jul 30 11:59:19.926117 2026] [security2:error] [pid 642360:tid 642564] [client 172.202.44.182:39190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-sigunq.php"] [unique_id "amuC55SUkh3e5AhEJOCC-wAAAdk"]
[Thu Jul 30 11:59:20.038461 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:20.042467 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:20998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "778"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC6JSUkh3e5AhEJOCC_AAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:20.276056 2026] [core:error] [pid 643253:tid 643451] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:20.276077 2026] [core:error] [pid 643253:tid 643451] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:20.285898 2026] [core:error] [pid 642360:tid 642607] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:20.285915 2026] [core:error] [pid 642360:tid 642607] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:20.652797 2026] [security2:error] [pid 642360:tid 642604] [client 20.215.191.139:54692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/lufix.php"] [unique_id "amuC6JSUkh3e5AhEJOCDDQAAAgE"]
[Thu Jul 30 11:59:20.783004 2026] [core:notice] [pid 642360:tid 642608] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:20.790127 2026] [security2:error] [pid 642360:tid 642608] [client 103.215.74.26:21012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC6JSUkh3e5AhEJOCDEAAAAgU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:20.990230 2026] [security2:error] [pid 642360:tid 642500] [client 20.215.191.139:36151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuC6JSUkh3e5AhEJOCDEwAAAZk"]
[Thu Jul 30 11:59:21.472277 2026] [security2:error] [pid 642360:tid 642563] [client 20.215.191.139:54670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/Geforce.php"] [unique_id "amuC6ZSUkh3e5AhEJOCDHQAAAdg"]
[Thu Jul 30 11:59:21.526264 2026] [core:notice] [pid 642360:tid 642581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:21.530496 2026] [security2:error] [pid 642360:tid 642581] [client 103.215.74.26:21026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "791"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC6ZSUkh3e5AhEJOCDIAAAAeo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:21.934134 2026] [security2:error] [pid 643253:tid 643406] [client 20.215.191.139:43339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuC6cjqbtjBYzqM1uYp5QAAABY"]
[Thu Jul 30 11:59:22.270431 2026] [core:notice] [pid 642360:tid 642527] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:22.274456 2026] [security2:error] [pid 642360:tid 642527] [client 103.215.74.26:21028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC6pSUkh3e5AhEJOCDKgAAAbQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:22.493638 2026] [security2:error] [pid 643253:tid 643416] [client 172.202.44.182:39185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wso112233.php"] [unique_id "amuC6sjqbtjBYzqM1uYp-QAAACA"]
[Thu Jul 30 11:59:22.794882 2026] [security2:error] [pid 643253:tid 643419] [client 20.215.191.139:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/a4.php"] [unique_id "amuC6sjqbtjBYzqM1uYp-wAAACM"]
[Thu Jul 30 11:59:23.003375 2026] [core:notice] [pid 643253:tid 643412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:23.007538 2026] [security2:error] [pid 643253:tid 643412] [client 103.215.74.26:21034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC68jqbtjBYzqM1uYp_AAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:23.289605 2026] [security2:error] [pid 643253:tid 643262] [remote 74.7.241.59:34448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuC68jqbtjBYzqM1uYp_gAAQgc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 11:59:23.485532 2026] [security2:error] [pid 643253:tid 643488] [client 20.215.191.139:36110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuC68jqbtjBYzqM1uYp_wAAAGg"]
[Thu Jul 30 11:59:23.725764 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:23.729726 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:8956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC68jqbtjBYzqM1uYqAAAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:24.187610 2026] [security2:error] [pid 642360:tid 642586] [client 20.215.191.139:35021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuC7JSUkh3e5AhEJOCDQAAAAe8"]
[Thu Jul 30 11:59:24.321575 2026] [security2:error] [pid 642360:tid 642615] [client 74.7.244.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.saiqon.net"] [uri "/index.php"] [unique_id "amuC6pSUkh3e5AhEJOCDMAAAAgw"]
[Thu Jul 30 11:59:24.322476 2026] [security2:error] [pid 642360:tid 642557] [client 74.7.244.17:51080] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.saiqon.net"] [uri "/robots.txt"] [unique_id "amuC6pSUkh3e5AhEJOCDLgAB0h4"]
[Thu Jul 30 11:59:24.451318 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:24.455743 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:8968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC7MjqbtjBYzqM1uYqBwAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:24.860063 2026] [security2:error] [pid 643253:tid 643464] [client 20.215.191.139:17553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuC7MjqbtjBYzqM1uYqCAAAAFA"]
[Thu Jul 30 11:59:24.880031 2026] [security2:error] [pid 642360:tid 642548] [client 176.241.66.87:46749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC7JSUkh3e5AhEJOCDSgAAAck"]
[Thu Jul 30 11:59:24.880196 2026] [security2:error] [pid 642360:tid 642548] [client 176.241.66.87:46749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC7JSUkh3e5AhEJOCDSgAAAck"]
[Thu Jul 30 11:59:25.187730 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:25.191596 2026] [security2:error] [pid 642360:tid 642597] [client 103.215.74.26:8978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC7ZSUkh3e5AhEJOCDUAAAAfo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:25.401443 2026] [security2:error] [pid 643253:tid 643486] [client 74.7.241.165:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "saiqon.net"] [uri "/index.php"] [unique_id "amuC7cjqbtjBYzqM1uYqCQAAZgk"]
[Thu Jul 30 11:59:25.841040 2026] [security2:error] [pid 643253:tid 643408] [client 20.215.191.139:55114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuC7cjqbtjBYzqM1uYqDAAAABg"]
[Thu Jul 30 11:59:25.933122 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:25.936888 2026] [security2:error] [pid 642360:tid 642601] [client 103.215.74.26:8988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC7ZSUkh3e5AhEJOCDWgAAAf4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:26.461925 2026] [security2:error] [pid 643253:tid 643267] [remote 74.7.241.59:34448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuC7sjqbtjBYzqM1uYqDwAAOQw"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 11:59:26.548075 2026] [security2:error] [pid 642360:tid 642591] [client 20.215.191.139:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/accueil.php"] [unique_id "amuC7pSUkh3e5AhEJOCDYAAAAfQ"]
[Thu Jul 30 11:59:26.663927 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:26.668328 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:8996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC7pSUkh3e5AhEJOCDZAAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:26.727054 2026] [security2:error] [pid 643253:tid 643472] [client 172.202.44.182:50527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/alfanew.php"] [unique_id "amuC7sjqbtjBYzqM1uYqEAAAAFg"]
[Thu Jul 30 11:59:27.394899 2026] [core:notice] [pid 643253:tid 643452] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:27.399295 2026] [security2:error] [pid 643253:tid 643452] [client 103.215.74.26:9000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC78jqbtjBYzqM1uYqFAAAAEQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:27.899064 2026] [security2:error] [pid 643253:tid 643481] [client 20.215.191.139:17564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuC78jqbtjBYzqM1uYqFgAAAGE"]
[Thu Jul 30 11:59:28.128370 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:28.132831 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:9012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC8JSUkh3e5AhEJOCDdAAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:28.435687 2026] [security2:error] [pid 643253:tid 643503] [client 172.202.44.182:50534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/fw.php"] [unique_id "amuC8MjqbtjBYzqM1uYqGgAAAHc"]
[Thu Jul 30 11:59:28.552958 2026] [core:notice] [pid 642360:tid 642607] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:28.941441 2026] [core:notice] [pid 642360:tid 642599] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:28.945798 2026] [security2:error] [pid 642360:tid 642599] [client 103.215.74.26:9020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC8JSUkh3e5AhEJOCDggAAAfw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:29.705143 2026] [core:notice] [pid 642360:tid 642601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:29.709525 2026] [security2:error] [pid 642360:tid 642601] [client 103.215.74.26:9026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC8ZSUkh3e5AhEJOCDkgAAAf4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:29.822933 2026] [security2:error] [pid 642360:tid 642615] [client 20.215.191.139:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/dashboard.php"] [unique_id "amuC8ZSUkh3e5AhEJOCDkwAAAgw"]
[Thu Jul 30 11:59:30.442919 2026] [core:notice] [pid 642360:tid 642594] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:30.447342 2026] [security2:error] [pid 642360:tid 642594] [client 103.215.74.26:9034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC8pSUkh3e5AhEJOCDpAAAAfc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:30.633295 2026] [security2:error] [pid 642360:tid 642540] [client 20.215.191.139:54365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/radio.php"] [unique_id "amuC8pSUkh3e5AhEJOCDpQAAAcE"]
[Thu Jul 30 11:59:31.174628 2026] [core:notice] [pid 642360:tid 642612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:31.179057 2026] [security2:error] [pid 642360:tid 642612] [client 103.215.74.26:9048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC85SUkh3e5AhEJOCDrgAAAgk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:31.259761 2026] [security2:error] [pid 642360:tid 642544] [client 172.202.44.182:45097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-login.php"] [unique_id "amuC8pSUkh3e5AhEJOCDrAAAAcU"]
[Thu Jul 30 11:59:31.418440 2026] [security2:error] [pid 642360:tid 642504] [client 139.28.219.70:47854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuC85SUkh3e5AhEJOCDsgAAAZ0"]
[Thu Jul 30 11:59:31.655476 2026] [core:error] [pid 642360:tid 642518] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:31.655499 2026] [core:error] [pid 642360:tid 642518] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:31.912704 2026] [core:notice] [pid 642360:tid 642610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:31.917079 2026] [security2:error] [pid 642360:tid 642610] [client 103.215.74.26:9064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC85SUkh3e5AhEJOCDuwAAAgc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:31.968377 2026] [security2:error] [pid 642360:tid 642500] [client 20.215.191.139:54386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wpsml-sys.php"] [unique_id "amuC85SUkh3e5AhEJOCDvAAAAZk"]
[Thu Jul 30 11:59:32.089949 2026] [security2:error] [pid 642360:tid 642563] [client 139.28.219.70:47858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuC9JSUkh3e5AhEJOCDwgAAAdg"]
[Thu Jul 30 11:59:32.356803 2026] [security2:error] [pid 642360:tid 642508] [client 139.28.219.70:47860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuC9JSUkh3e5AhEJOCDwwAAAaE"]
[Thu Jul 30 11:59:32.630622 2026] [security2:error] [pid 642360:tid 642572] [client 139.28.219.70:47874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuC9JSUkh3e5AhEJOCDyQAAAeE"]
[Thu Jul 30 11:59:32.650342 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:32.655046 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:9068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC9MjqbtjBYzqM1uYqJQAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:32.897701 2026] [security2:error] [pid 642360:tid 642510] [client 139.28.219.70:47888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuC9JSUkh3e5AhEJOCDygAAAaM"]
[Thu Jul 30 11:59:33.168670 2026] [security2:error] [pid 642360:tid 642603] [client 139.28.219.70:47896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuC9ZSUkh3e5AhEJOCD0QAAAgA"]
[Thu Jul 30 11:59:33.380284 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:33.384206 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:62836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC9ZSUkh3e5AhEJOCD0wAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:33.392434 2026] [core:notice] [pid 642360:tid 642574] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:33.439217 2026] [security2:error] [pid 642360:tid 642530] [client 139.28.219.70:47910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuC9ZSUkh3e5AhEJOCD1QAAAbc"]
[Thu Jul 30 11:59:33.799102 2026] [security2:error] [pid 642360:tid 642570] [client 139.28.219.70:47924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuC9ZSUkh3e5AhEJOCD3AAAAd8"]
[Thu Jul 30 11:59:34.113764 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:34.117640 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:62846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC9pSUkh3e5AhEJOCD4QAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:34.147503 2026] [security2:error] [pid 642360:tid 642511] [client 139.28.219.70:47940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuC9pSUkh3e5AhEJOCD4wAAAaQ"]
[Thu Jul 30 11:59:34.433756 2026] [security2:error] [pid 642360:tid 642548] [client 139.28.219.70:47952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuC9pSUkh3e5AhEJOCD5gAAAck"]
[Thu Jul 30 11:59:34.746651 2026] [security2:error] [pid 642360:tid 642597] [client 139.28.219.70:47966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuC9pSUkh3e5AhEJOCD7QAAAfo"]
[Thu Jul 30 11:59:34.866844 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:34.871549 2026] [security2:error] [pid 643253:tid 643392] [client 103.215.74.26:62866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC9sjqbtjBYzqM1uYqKwAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:35.049912 2026] [security2:error] [pid 642360:tid 642568] [client 139.28.219.70:47976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuC95SUkh3e5AhEJOCD8AAAAd0"]
[Thu Jul 30 11:59:35.323148 2026] [security2:error] [pid 643253:tid 643420] [client 139.28.219.70:47978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuC98jqbtjBYzqM1uYqMAAAACQ"]
[Thu Jul 30 11:59:35.593987 2026] [security2:error] [pid 643253:tid 643433] [client 139.28.219.70:47988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuC98jqbtjBYzqM1uYqMgAAADE"]
[Thu Jul 30 11:59:35.602202 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:35.606624 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:62880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC95SUkh3e5AhEJOCD-AAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:35.622140 2026] [security2:error] [pid 643253:tid 643490] [client 176.241.66.87:62174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC98jqbtjBYzqM1uYqMwAAAGo"]
[Thu Jul 30 11:59:35.622336 2026] [security2:error] [pid 643253:tid 643490] [client 176.241.66.87:62174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuC98jqbtjBYzqM1uYqMwAAAGo"]
[Thu Jul 30 11:59:35.873343 2026] [security2:error] [pid 642360:tid 642492] [client 139.28.219.70:48000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuC95SUkh3e5AhEJOCEBQAAAZE"]
[Thu Jul 30 11:59:36.064590 2026] [security2:error] [pid 642360:tid 642414] [remote 74.7.241.59:54104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuC-JSUkh3e5AhEJOCEBgABozU"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 11:59:36.183494 2026] [core:error] [pid 642360:tid 642598] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:36.183521 2026] [core:error] [pid 642360:tid 642598] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:36.208661 2026] [security2:error] [pid 643253:tid 643477] [client 20.215.191.139:54373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/02.php"] [unique_id "amuC-MjqbtjBYzqM1uYqNAAAAF0"]
[Thu Jul 30 11:59:36.235181 2026] [security2:error] [pid 642360:tid 642520] [client 139.28.219.70:48010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rocket-bookkeepers.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuC-JSUkh3e5AhEJOCEEQAAAa0"]
[Thu Jul 30 11:59:36.352257 2026] [core:notice] [pid 642360:tid 642589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:36.358773 2026] [security2:error] [pid 642360:tid 642589] [client 103.215.74.26:62882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-JSUkh3e5AhEJOCEEgAAAfI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:36.553680 2026] [security2:error] [pid 642360:tid 642501] [client 20.215.191.139:43345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuC-JSUkh3e5AhEJOCEFAAAAZo"]
[Thu Jul 30 11:59:36.735878 2026] [core:notice] [pid 642360:tid 642578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:36.960029 2026] [security2:error] [pid 642360:tid 642591] [client 172.202.44.182:45064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/simple.php"] [unique_id "amuC-JSUkh3e5AhEJOCEHgAAAfQ"]
[Thu Jul 30 11:59:36.999910 2026] [security2:error] [pid 642360:tid 642608] [client 20.215.191.139:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/infos.php"] [unique_id "amuC-JSUkh3e5AhEJOCEIgAAAgU"]
[Thu Jul 30 11:59:37.107561 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:37.114326 2026] [security2:error] [pid 642360:tid 642561] [client 103.215.74.26:62898] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-ZSUkh3e5AhEJOCEIwAAAdY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:37.490741 2026] [security2:error] [pid 643253:tid 643415] [client 20.215.191.139:54347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/updates.php"] [unique_id "amuC-cjqbtjBYzqM1uYqNgAAAB8"]
[Thu Jul 30 11:59:37.599477 2026] [security2:error] [pid 642360:tid 642560] [client 20.215.191.139:17595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuC-ZSUkh3e5AhEJOCEKgAAAdU"]
[Thu Jul 30 11:59:37.848255 2026] [core:notice] [pid 642360:tid 642505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:37.852196 2026] [security2:error] [pid 642360:tid 642505] [client 103.215.74.26:62904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-ZSUkh3e5AhEJOCELgAAAZ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:38.213880 2026] [security2:error] [pid 642360:tid 642573] [client 43.153.73.200:42742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.73.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/issue/current"] [unique_id "amuC-pSUkh3e5AhEJOCEMgAAAeI"], referer: https://ejournalugj.com/index_php/tumed/issue/current
[Thu Jul 30 11:59:38.280393 2026] [security2:error] [pid 642360:tid 642605] [client 172.202.44.182:45114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/classsmtps.php"] [unique_id "amuC-pSUkh3e5AhEJOCENgAAAgI"]
[Thu Jul 30 11:59:38.594391 2026] [core:notice] [pid 642360:tid 642498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:38.598487 2026] [security2:error] [pid 642360:tid 642498] [client 103.215.74.26:62912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-pSUkh3e5AhEJOCEOQAAAZc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:38.736157 2026] [security2:error] [pid 642360:tid 642529] [client 20.215.191.139:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/user.php"] [unique_id "amuC-pSUkh3e5AhEJOCEOwAAAbY"]
[Thu Jul 30 11:59:38.820018 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:38.889235 2026] [security2:error] [pid 642360:tid 642440] [remote 74.7.241.60:57288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuC-pSUkh3e5AhEJOCEQQAB-U8"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 11:59:39.238653 2026] [security2:error] [pid 642360:tid 642491] [client 185.191.171.16:59030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/28/90-dos-eleitores-de-nilvan-no-1o-turno-declaram-voto-em-pedro-mesmo-com-neutralidade/"] [unique_id "amuC-5SUkh3e5AhEJOCEQgAAAZA"]
[Thu Jul 30 11:59:39.238849 2026] [security2:error] [pid 642360:tid 642491] [client 185.191.171.16:59030] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/28/90-dos-eleitores-de-nilvan-no-1o-turno-declaram-voto-em-pedro-mesmo-com-neutralidade/"] [unique_id "amuC-5SUkh3e5AhEJOCEQgAAAZA"]
[Thu Jul 30 11:59:39.322067 2026] [core:notice] [pid 642360:tid 642496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:39.328530 2026] [security2:error] [pid 642360:tid 642496] [client 103.215.74.26:62922] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC-5SUkh3e5AhEJOCERgAAAZU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:39.332769 2026] [security2:error] [pid 643253:tid 643460] [client 20.215.191.139:54666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/admin-ajax.php"] [unique_id "amuC-8jqbtjBYzqM1uYqPAAAAEw"]
[Thu Jul 30 11:59:39.868952 2026] [security2:error] [pid 642360:tid 642419] [remote 198.244.226.21:54408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "koriusa.info"] [uri "/robots.txt"] [unique_id "amuC-5SUkh3e5AhEJOCEUQACBDo"]
[Thu Jul 30 11:59:39.869100 2026] [security2:error] [pid 642360:tid 642607] [client 198.244.226.21:54408] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "koriusa.info"] [uri "/robots.txt"] [unique_id "amuC-5SUkh3e5AhEJOCEUQACBDo"]
[Thu Jul 30 11:59:40.048466 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:40.052502 2026] [security2:error] [pid 642360:tid 642582] [client 103.215.74.26:62924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "783"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_JSUkh3e5AhEJOCEVAAAAes"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:40.088402 2026] [security2:error] [pid 643253:tid 643496] [client 20.215.191.139:35055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuC_MjqbtjBYzqM1uYqPwAAAHA"]
[Thu Jul 30 11:59:40.618538 2026] [security2:error] [pid 643253:tid 643486] [client 172.202.44.182:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-blog-header.php"] [unique_id "amuC_MjqbtjBYzqM1uYqQwAAAGY"]
[Thu Jul 30 11:59:40.782681 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:40.786646 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:62968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_JSUkh3e5AhEJOCEWwAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:40.984517 2026] [security2:error] [pid 642360:tid 642597] [client 20.215.191.139:36143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuC_JSUkh3e5AhEJOCEYgAAAfo"]
[Thu Jul 30 11:59:41.242801 2026] [security2:error] [pid 642360:tid 642444] [remote 198.244.183.195:33546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "koriusa.info"] [uri "/adjustable-airflow-vape-guide-why-its-essential-in-2026/"] [unique_id "amuC_ZSUkh3e5AhEJOCEZAABrFM"]
[Thu Jul 30 11:59:41.242967 2026] [security2:error] [pid 642360:tid 642519] [client 198.244.183.195:33546] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "koriusa.info"] [uri "/adjustable-airflow-vape-guide-why-its-essential-in-2026/"] [unique_id "amuC_ZSUkh3e5AhEJOCEZAABrFM"]
[Thu Jul 30 11:59:41.517824 2026] [core:notice] [pid 642360:tid 642572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:41.521884 2026] [security2:error] [pid 642360:tid 642572] [client 103.215.74.26:62986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_ZSUkh3e5AhEJOCEawAAAeE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:41.755402 2026] [security2:error] [pid 642360:tid 642565] [client 20.215.191.139:54273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/alfa.php"] [unique_id "amuC_ZSUkh3e5AhEJOCEbQAAAdo"]
[Thu Jul 30 11:59:42.258787 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:42.262853 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:62988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_pSUkh3e5AhEJOCEdgAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:42.989847 2026] [core:notice] [pid 642360:tid 642544] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:42.996082 2026] [security2:error] [pid 642360:tid 642544] [client 103.215.74.26:62990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_pSUkh3e5AhEJOCEfwAAAcU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:43.024952 2026] [core:notice] [pid 642360:tid 642517] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:43.173717 2026] [security2:error] [pid 642360:tid 642576] [client 20.215.191.139:54348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/hehe.php"] [unique_id "amuC_5SUkh3e5AhEJOCEhAAAAeU"]
[Thu Jul 30 11:59:43.759772 2026] [core:notice] [pid 642360:tid 642610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:43.763736 2026] [security2:error] [pid 642360:tid 642610] [client 103.215.74.26:20576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuC_5SUkh3e5AhEJOCEigAAAgc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:43.835158 2026] [security2:error] [pid 642360:tid 642536] [client 57.141.0.2:38494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuC_5SUkh3e5AhEJOCEhQABvVs"], referer: https://igetvape-australia.com/product/iget-moon-pomegranate-kiwi-ice/?add-to-cart=177
[Thu Jul 30 11:59:44.498959 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:44.502970 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:20590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDAJSUkh3e5AhEJOCElQAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:45.149071 2026] [security2:error] [pid 643253:tid 643474] [client 20.215.191.139:39423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuDAcjqbtjBYzqM1uYqeAAAAFo"]
[Thu Jul 30 11:59:45.230525 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:45.237178 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:20602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDAcjqbtjBYzqM1uYqfAAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:45.412786 2026] [security2:error] [pid 642360:tid 642503] [client 216.244.66.243:36062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amuDAZSUkh3e5AhEJOCEogAAAZw"]
[Thu Jul 30 11:59:45.412928 2026] [security2:error] [pid 642360:tid 642503] [client 216.244.66.243:36062] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amuDAZSUkh3e5AhEJOCEogAAAZw"]
[Thu Jul 30 11:59:45.603445 2026] [security2:error] [pid 643253:tid 643482] [client 50.6.43.217:45624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuDAcjqbtjBYzqM1uYqfQAAAGI"]
[Thu Jul 30 11:59:45.672440 2026] [security2:error] [pid 642360:tid 642580] [client 172.202.44.182:45090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-trackback.php"] [unique_id "amuDAZSUkh3e5AhEJOCEpgAAAek"]
[Thu Jul 30 11:59:45.726054 2026] [security2:error] [pid 643253:tid 643428] [client 50.6.43.217:45638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuDAcjqbtjBYzqM1uYqfgAAACw"]
[Thu Jul 30 11:59:45.838267 2026] [security2:error] [pid 643253:tid 643426] [client 20.215.191.139:43357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuDAcjqbtjBYzqM1uYqgAAAACo"]
[Thu Jul 30 11:59:45.972283 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:45.976229 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:20616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDAcjqbtjBYzqM1uYqgQAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:46.195790 2026] [security2:error] [pid 642360:tid 642451] [remote 5.39.1.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "massageandspaislamabad.rest"] [uri "/robots.txt"] [unique_id "amuDApSUkh3e5AhEJOCErgABmFo"]
[Thu Jul 30 11:59:46.195963 2026] [security2:error] [pid 642360:tid 642499] [client 5.39.1.236:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "massageandspaislamabad.rest"] [uri "/robots.txt"] [unique_id "amuDApSUkh3e5AhEJOCErgABmFo"]
[Thu Jul 30 11:59:46.321959 2026] [security2:error] [pid 643253:tid 643473] [client 176.241.66.87:48145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDAsjqbtjBYzqM1uYqhAAAAFk"]
[Thu Jul 30 11:59:46.322139 2026] [security2:error] [pid 643253:tid 643473] [client 176.241.66.87:48145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDAsjqbtjBYzqM1uYqhAAAAFk"]
[Thu Jul 30 11:59:46.564645 2026] [security2:error] [pid 642360:tid 642537] [client 172.202.44.182:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-signup.php"] [unique_id "amuDApSUkh3e5AhEJOCEtQAAAb4"]
[Thu Jul 30 11:59:46.705846 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:46.710231 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:20628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDAsjqbtjBYzqM1uYqhwAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:46.825958 2026] [security2:error] [pid 642360:tid 642517] [client 20.215.191.139:35010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuDApSUkh3e5AhEJOCEvgAAAao"]
[Thu Jul 30 11:59:47.006391 2026] [core:notice] [pid 642360:tid 642577] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:47.039955 2026] [core:notice] [pid 642360:tid 642380] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:47.431498 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:47.435654 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:20630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDA5SUkh3e5AhEJOCEyAAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:47.591567 2026] [security2:error] [pid 642360:tid 642490] [client 20.215.191.139:17528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/bek.php"] [unique_id "amuDA5SUkh3e5AhEJOCEyQAAAY8"]
[Thu Jul 30 11:59:48.182044 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:48.186098 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:20632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDBJSUkh3e5AhEJOCE0gAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:48.239525 2026] [security2:error] [pid 642360:tid 642546] [client 3.255.255.17:24014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/04/favicon-300x300.jpg"] [unique_id "amuDBJSUkh3e5AhEJOCE1AABx3E"]
[Thu Jul 30 11:59:48.270992 2026] [security2:error] [pid 642360:tid 642492] [client 43.172.194.241:33510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/oembed/1.0/embed"] [unique_id "amuDBJSUkh3e5AhEJOCE0QAAAZE"]
[Thu Jul 30 11:59:48.681055 2026] [security2:error] [pid 643253:tid 643511] [client 191.232.199.39:7085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/chosen.php"] [unique_id "amuDBMjqbtjBYzqM1uYqjQAAAH8"]
[Thu Jul 30 11:59:48.739360 2026] [security2:error] [pid 643253:tid 643409] [client 34.245.220.244:57262] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/05/parlx-services-commercial-5.jpg"] [unique_id "amuDBMjqbtjBYzqM1uYqjAAAGT8"]
[Thu Jul 30 11:59:48.975535 2026] [core:notice] [pid 642360:tid 642613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:48.981041 2026] [security2:error] [pid 642360:tid 642613] [client 43.173.173.127:42498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/oembed/1.0/embed"] [unique_id "amuDBJSUkh3e5AhEJOCE4QAAAgo"], referer: https://carnetdeshopping.com/index.php/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fcarnetdeshopping.com%2Findex.php%2F2012%2F06%2F07%2Fmiami-excursion-au-parc-national-des-everglades%2F&format=xml
[Thu Jul 30 11:59:49.301789 2026] [security2:error] [pid 642360:tid 642504] [client 20.215.191.139:54686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/rk2.php"] [unique_id "amuDBZSUkh3e5AhEJOCE4gAAAZ0"]
[Thu Jul 30 11:59:49.964284 2026] [security2:error] [pid 642360:tid 642608] [client 191.232.199.39:7059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/xleet.php"] [unique_id "amuDBZSUkh3e5AhEJOCE8QAAAgU"]
[Thu Jul 30 11:59:49.975671 2026] [security2:error] [pid 642360:tid 642578] [client 43.173.182.22:50336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sellvia.womenclothingbox.com"] [uri "/"] [unique_id "amuDBZSUkh3e5AhEJOCE6QAAAec"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:49.998765 2026] [security2:error] [pid 642360:tid 642610] [client 172.202.44.182:50507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-comments-post.php"] [unique_id "amuDBZSUkh3e5AhEJOCE9QAAAgc"]
[Thu Jul 30 11:59:50.057606 2026] [security2:error] [pid 642360:tid 642487] [remote 47.128.96.2:25992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/2045"] [unique_id "amuDBZSUkh3e5AhEJOCE6gABzX4"]
[Thu Jul 30 11:59:50.105778 2026] [security2:error] [pid 642360:tid 642570] [client 20.215.191.139:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/setup-config.php"] [unique_id "amuDBpSUkh3e5AhEJOCE9gAAAd8"]
[Thu Jul 30 11:59:50.129659 2026] [core:notice] [pid 642360:tid 642366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:50.134199 2026] [security2:error] [pid 642360:tid 642587] [client 47.128.96.2:25992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/2045"] [unique_id "amuDBpSUkh3e5AhEJOCE9wAB8AU"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 11:59:50.294791 2026] [core:notice] [pid 642360:tid 642382] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:50.380299 2026] [core:notice] [pid 642360:tid 642385] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:50.380499 2026] [core:notice] [pid 642360:tid 642478] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:50.610095 2026] [security2:error] [pid 642360:tid 642507] [client 20.215.191.139:35069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuDBpSUkh3e5AhEJOCFAQAAAaA"]
[Thu Jul 30 11:59:51.306517 2026] [security2:error] [pid 643253:tid 643460] [client 191.232.199.39:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/ds.php"] [unique_id "amuDB8jqbtjBYzqM1uYqkwAAAEw"]
[Thu Jul 30 11:59:51.537776 2026] [security2:error] [pid 643253:tid 643320] [remote 92.222.104.209:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "massageandspaislamabad.rest"] [uri "/"] [unique_id "amuDB8jqbtjBYzqM1uYqlAAAUEE"]
[Thu Jul 30 11:59:51.537926 2026] [security2:error] [pid 643253:tid 643464] [client 92.222.104.209:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "massageandspaislamabad.rest"] [uri "/"] [unique_id "amuDB8jqbtjBYzqM1uYqlAAAUEE"]
[Thu Jul 30 11:59:51.582504 2026] [security2:error] [pid 643253:tid 643430] [client 20.215.191.139:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/a7.php"] [unique_id "amuDB8jqbtjBYzqM1uYqlQAAAC4"]
[Thu Jul 30 11:59:52.292530 2026] [core:notice] [pid 643253:tid 643321] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:52.311469 2026] [security2:error] [pid 642360:tid 642503] [client 172.202.44.182:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-mail.php"] [unique_id "amuDCJSUkh3e5AhEJOCFFgAAAZw"]
[Thu Jul 30 11:59:52.338792 2026] [core:error] [pid 642360:tid 642589] [client 66.249.73.204:45465] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:52.338811 2026] [core:error] [pid 642360:tid 642589] [client 66.249.73.204:45465] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:52.456625 2026] [security2:error] [pid 642360:tid 642502] [client 20.215.191.139:17515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/class.api.php"] [unique_id "amuDCJSUkh3e5AhEJOCFGAAAAZs"]
[Thu Jul 30 11:59:52.775962 2026] [security2:error] [pid 642360:tid 642606] [client 191.232.199.39:57725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/f5.php"] [unique_id "amuDCJSUkh3e5AhEJOCFHgAAAgM"]
[Thu Jul 30 11:59:52.789513 2026] [security2:error] [pid 642360:tid 642612] [client 74.7.230.58:52008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.iig.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuDCJSUkh3e5AhEJOCFHwAAAgk"]
[Thu Jul 30 11:59:53.005191 2026] [core:error] [pid 643253:tid 643322] [remote 74.7.230.10:44554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:53.005521 2026] [core:error] [pid 643253:tid 643322] [remote 74.7.230.10:44554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 11:59:53.005697 2026] [security2:error] [pid 643253:tid 643442] [client 74.7.230.10:44554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-170cb886.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuDCcjqbtjBYzqM1uYqmQAAOkM"]
[Thu Jul 30 11:59:53.090505 2026] [security2:error] [pid 643253:tid 643387] [client 20.215.191.139:54691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/f7.php"] [unique_id "amuDCcjqbtjBYzqM1uYqmgAAAAM"]
[Thu Jul 30 11:59:53.858141 2026] [security2:error] [pid 642360:tid 642614] [client 20.215.191.139:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/nw.php"] [unique_id "amuDCZSUkh3e5AhEJOCFLgAAAgs"]
[Thu Jul 30 11:59:53.921920 2026] [security2:error] [pid 642360:tid 642560] [client 172.245.102.89:61529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moswey.com"] [uri "/"] [unique_id "amuDCZSUkh3e5AhEJOCFLwAAAdU"]
[Thu Jul 30 11:59:53.959243 2026] [security2:error] [pid 643253:tid 643436] [client 191.232.199.39:57763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/god4m.php"] [unique_id "amuDCcjqbtjBYzqM1uYqngAAADQ"]
[Thu Jul 30 11:59:54.085081 2026] [core:notice] [pid 643253:tid 643478] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:54.089652 2026] [security2:error] [pid 643253:tid 643478] [client 103.215.74.26:55898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDCsjqbtjBYzqM1uYqnwAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:54.152403 2026] [security2:error] [pid 643253:tid 643452] [client 20.215.191.139:36153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/cong.php"] [unique_id "amuDCsjqbtjBYzqM1uYqoAAAAEQ"]
[Thu Jul 30 11:59:54.817509 2026] [core:notice] [pid 642360:tid 642563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:54.821790 2026] [security2:error] [pid 642360:tid 642563] [client 103.215.74.26:55914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDCpSUkh3e5AhEJOCFPwAAAdg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:54.842904 2026] [security2:error] [pid 642360:tid 642605] [client 136.144.33.249:28787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moswey.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuDCpSUkh3e5AhEJOCFQAAAAgI"]
[Thu Jul 30 11:59:54.869890 2026] [core:notice] [pid 643253:tid 643323] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:55.045443 2026] [security2:error] [pid 643253:tid 643474] [client 20.215.191.139:39365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/content.php"] [unique_id "amuDC8jqbtjBYzqM1uYqogAAAFo"]
[Thu Jul 30 11:59:55.363629 2026] [security2:error] [pid 642360:tid 642573] [client 20.215.191.139:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/ova.php"] [unique_id "amuDC5SUkh3e5AhEJOCFRgAAAeI"]
[Thu Jul 30 11:59:55.557178 2026] [core:notice] [pid 642360:tid 642572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:55.561624 2026] [security2:error] [pid 642360:tid 642572] [client 103.215.74.26:55922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDC5SUkh3e5AhEJOCFSAAAAeE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:55.610572 2026] [security2:error] [pid 643253:tid 643434] [client 191.232.199.39:6269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/info.php"] [unique_id "amuDC8jqbtjBYzqM1uYqpgAAADI"]
[Thu Jul 30 11:59:55.833110 2026] [security2:error] [pid 642360:tid 642590] [client 136.144.33.66:22959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moswey.com"] [uri "/media/system/js/core.js"] [unique_id "amuDC5SUkh3e5AhEJOCFTgAAAfM"]
[Thu Jul 30 11:59:55.851858 2026] [security2:error] [pid 642360:tid 642565] [client 20.215.191.139:39984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuDC5SUkh3e5AhEJOCFTwAAAdo"]
[Thu Jul 30 11:59:56.267466 2026] [security2:error] [pid 643253:tid 643428] [client 20.215.191.139:54370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/robots.php"] [unique_id "amuDDMjqbtjBYzqM1uYqqAAAACw"]
[Thu Jul 30 11:59:56.305672 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:56.310186 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:55926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDDJSUkh3e5AhEJOCFVgAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:56.548751 2026] [security2:error] [pid 642360:tid 642512] [client 20.215.191.139:39408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/elp.php"] [unique_id "amuDDJSUkh3e5AhEJOCFVwAAAaU"]
[Thu Jul 30 11:59:56.949639 2026] [security2:error] [pid 643253:tid 643324] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/chosen.php"] [unique_id "amuDDMjqbtjBYzqM1uYqqgAAQ0U"]
[Thu Jul 30 11:59:56.971266 2026] [security2:error] [pid 642360:tid 642544] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDDJSUkh3e5AhEJOCFYAAAAcU"]
[Thu Jul 30 11:59:57.049141 2026] [security2:error] [pid 642360:tid 642586] [client 176.241.66.87:48817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDDZSUkh3e5AhEJOCFZAAAAe8"]
[Thu Jul 30 11:59:57.049256 2026] [security2:error] [pid 642360:tid 642586] [client 176.241.66.87:48817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDDZSUkh3e5AhEJOCFZAAAAe8"]
[Thu Jul 30 11:59:57.052895 2026] [core:notice] [pid 642360:tid 642591] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:57.057278 2026] [security2:error] [pid 642360:tid 642591] [client 103.215.74.26:55930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDDZSUkh3e5AhEJOCFZQAAAfQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:57.347354 2026] [security2:error] [pid 643253:tid 643426] [client 20.215.191.139:54675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/alf.php"] [unique_id "amuDDcjqbtjBYzqM1uYqrQAAACo"]
[Thu Jul 30 11:59:57.761051 2026] [security2:error] [pid 643253:tid 643508] [client 191.232.199.39:6252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.__info.php"] [unique_id "amuDDcjqbtjBYzqM1uYqrwAAAHw"]
[Thu Jul 30 11:59:57.796376 2026] [core:notice] [pid 642360:tid 642555] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:57.802520 2026] [security2:error] [pid 642360:tid 642555] [client 103.215.74.26:55942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDDZSUkh3e5AhEJOCFdQAAAdA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:57.813929 2026] [security2:error] [pid 642360:tid 642373] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/xleet.php"] [unique_id "amuDDZSUkh3e5AhEJOCFdgABsgw"]
[Thu Jul 30 11:59:58.148470 2026] [security2:error] [pid 642360:tid 642426] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ds.php"] [unique_id "amuDDpSUkh3e5AhEJOCFeQABrEE"]
[Thu Jul 30 11:59:58.206152 2026] [security2:error] [pid 642360:tid 642507] [client 20.215.191.139:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/feedback.php"] [unique_id "amuDDpSUkh3e5AhEJOCFegAAAaA"]
[Thu Jul 30 11:59:58.215695 2026] [security2:error] [pid 642360:tid 642550] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDDZSUkh3e5AhEJOCFaAAByyk"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 11:59:58.455810 2026] [security2:error] [pid 642360:tid 642392] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/f5.php"] [unique_id "amuDDpSUkh3e5AhEJOCFgAABlx8"]
[Thu Jul 30 11:59:58.535320 2026] [core:notice] [pid 642360:tid 642532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 11:59:58.539713 2026] [security2:error] [pid 642360:tid 642532] [client 103.215.74.26:55948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDDpSUkh3e5AhEJOCFgQAAAbk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 11:59:58.766844 2026] [security2:error] [pid 642360:tid 642408] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/god4m.php"] [unique_id "amuDDpSUkh3e5AhEJOCFggABny8"]
[Thu Jul 30 11:59:58.883641 2026] [security2:error] [pid 643253:tid 643493] [client 20.215.191.139:35009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuDDsjqbtjBYzqM1uYqsgAAAG0"]
[Thu Jul 30 11:59:58.886573 2026] [security2:error] [pid 642360:tid 642617] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDDpSUkh3e5AhEJOCFeAACDnY"]
[Thu Jul 30 11:59:58.986577 2026] [security2:error] [pid 642360:tid 642603] [client 20.215.191.139:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/gettest.php"] [unique_id "amuDDpSUkh3e5AhEJOCFiAAAAgA"]
[Thu Jul 30 11:59:59.075610 2026] [security2:error] [pid 642360:tid 642437] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/info.php"] [unique_id "amuDD5SUkh3e5AhEJOCFiQAB8Uw"]
[Thu Jul 30 11:59:59.102808 2026] [security2:error] [pid 643253:tid 643480] [client 191.232.199.39:6259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/0.php"] [unique_id "amuDD8jqbtjBYzqM1uYqswAAAGA"]
[Thu Jul 30 11:59:59.391254 2026] [security2:error] [pid 643253:tid 643409] [client 20.215.191.139:39399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuDD8jqbtjBYzqM1uYqtQAAABk"]
[Thu Jul 30 11:59:59.741987 2026] [security2:error] [pid 643253:tid 643438] [client 178.20.45.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDD8jqbtjBYzqM1uYqtAAANkg"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 12:00:00.270219 2026] [security2:error] [pid 642360:tid 642522] [client 191.232.199.39:36418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/07.php"] [unique_id "amuDEJSUkh3e5AhEJOCFmwAAAa8"]
[Thu Jul 30 12:00:00.358768 2026] [security2:error] [pid 642360:tid 642491] [client 172.202.44.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDD5SUkh3e5AhEJOCFkAABkEA"]
[Thu Jul 30 12:00:00.657201 2026] [autoindex:error] [pid 643253:tid 643423] [client 44.213.206.96:16713] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:00:00.783062 2026] [security2:error] [pid 642360:tid 642539] [client 172.202.44.182:45106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-activate.php"] [unique_id "amuDEJSUkh3e5AhEJOCFpwAAAcA"]
[Thu Jul 30 12:00:00.821677 2026] [security2:error] [pid 643253:tid 643475] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDD8jqbtjBYzqM1uYqtwAAW0c"]
[Thu Jul 30 12:00:00.838482 2026] [security2:error] [pid 642360:tid 642516] [client 20.215.191.139:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/maint.php"] [unique_id "amuDEJSUkh3e5AhEJOCFqAAAAak"]
[Thu Jul 30 12:00:00.945057 2026] [security2:error] [pid 643253:tid 643331] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/.__info.php"] [unique_id "amuDEMjqbtjBYzqM1uYqvAAAI0w"]
[Thu Jul 30 12:00:01.234815 2026] [security2:error] [pid 643253:tid 643329] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/0.php"] [unique_id "amuDEcjqbtjBYzqM1uYqvQAACko"]
[Thu Jul 30 12:00:01.482303 2026] [security2:error] [pid 643253:tid 643450] [client 20.215.191.139:54663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/files.php"] [unique_id "amuDEcjqbtjBYzqM1uYqwgAAAEI"]
[Thu Jul 30 12:00:01.513197 2026] [security2:error] [pid 643253:tid 643333] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/07.php"] [unique_id "amuDEcjqbtjBYzqM1uYqxAAAaU4"]
[Thu Jul 30 12:00:01.537325 2026] [security2:error] [pid 642360:tid 642515] [client 191.232.199.39:6232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/dropdown.php"] [unique_id "amuDEZSUkh3e5AhEJOCFswAAAag"]
[Thu Jul 30 12:00:01.761961 2026] [security2:error] [pid 643253:tid 643335] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/dropdown.php"] [unique_id "amuDEcjqbtjBYzqM1uYqyQAATlA"]
[Thu Jul 30 12:00:01.859401 2026] [core:notice] [pid 643253:tid 643336] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:02.068472 2026] [security2:error] [pid 642360:tid 642528] [client 20.215.191.139:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/gecko.php"] [unique_id "amuDEpSUkh3e5AhEJOCFuQAAAbU"]
[Thu Jul 30 12:00:02.072579 2026] [security2:error] [pid 643253:tid 643334] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/makeasmtp.php"] [unique_id "amuDEsjqbtjBYzqM1uYqzAAAFE8"]
[Thu Jul 30 12:00:02.189494 2026] [security2:error] [pid 642360:tid 642577] [client 172.202.44.182:45105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/post.php"] [unique_id "amuDEpSUkh3e5AhEJOCFwAAAAeY"]
[Thu Jul 30 12:00:02.321039 2026] [security2:error] [pid 643253:tid 643337] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-sigunq.php"] [unique_id "amuDEsjqbtjBYzqM1uYq0AAAJlI"]
[Thu Jul 30 12:00:02.377731 2026] [security2:error] [pid 642360:tid 642592] [client 20.215.191.139:40207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuDEpSUkh3e5AhEJOCFwwAAAfU"]
[Thu Jul 30 12:00:02.566417 2026] [security2:error] [pid 642360:tid 642444] [remote 74.7.241.59:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuDEpSUkh3e5AhEJOCFxwACAlM"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:00:02.571308 2026] [security2:error] [pid 643253:tid 643339] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wso112233.php"] [unique_id "amuDEsjqbtjBYzqM1uYq0gAAAFQ"]
[Thu Jul 30 12:00:02.790942 2026] [security2:error] [pid 643253:tid 643460] [client 172.237.109.114:17111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEsjqbtjBYzqM1uYqzQAAAEw"]
[Thu Jul 30 12:00:02.793200 2026] [security2:error] [pid 642360:tid 642611] [client 172.237.109.114:57009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEpSUkh3e5AhEJOCFugAAAgg"]
[Thu Jul 30 12:00:02.813949 2026] [security2:error] [pid 643253:tid 643395] [client 172.237.109.114:6908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEsjqbtjBYzqM1uYqzgAAAAs"]
[Thu Jul 30 12:00:02.822701 2026] [security2:error] [pid 643253:tid 643338] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/alfanew.php"] [unique_id "amuDEsjqbtjBYzqM1uYq1AAAUVM"]
[Thu Jul 30 12:00:02.826922 2026] [security2:error] [pid 643253:tid 643464] [client 172.237.109.114:47879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEsjqbtjBYzqM1uYqzwAAAFA"]
[Thu Jul 30 12:00:02.828488 2026] [security2:error] [pid 642360:tid 642490] [client 172.237.109.114:42763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEpSUkh3e5AhEJOCFvgAAAY8"]
[Thu Jul 30 12:00:02.830491 2026] [security2:error] [pid 642360:tid 642493] [client 172.237.109.114:40699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDEpSUkh3e5AhEJOCFvwAAAZI"]
[Thu Jul 30 12:00:02.958043 2026] [security2:error] [pid 642360:tid 642599] [client 191.232.199.39:6241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/makeasmtp.php"] [unique_id "amuDEpSUkh3e5AhEJOCF0AAAAfw"]
[Thu Jul 30 12:00:03.070706 2026] [security2:error] [pid 643253:tid 643340] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/fw.php"] [unique_id "amuDE8jqbtjBYzqM1uYq1QAAQVU"]
[Thu Jul 30 12:00:03.319708 2026] [security2:error] [pid 643253:tid 643341] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuDE8jqbtjBYzqM1uYq3wAAM1Y"]
[Thu Jul 30 12:00:03.604728 2026] [security2:error] [pid 643253:tid 643342] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/simple.php"] [unique_id "amuDE8jqbtjBYzqM1uYq4QAAXlc"]
[Thu Jul 30 12:00:03.852771 2026] [security2:error] [pid 643253:tid 643343] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/classsmtps.php"] [unique_id "amuDE8jqbtjBYzqM1uYq4wAARFg"]
[Thu Jul 30 12:00:04.093008 2026] [security2:error] [pid 642360:tid 642558] [client 20.215.191.139:40227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuDFJSUkh3e5AhEJOCF4wAAAdM"]
[Thu Jul 30 12:00:04.258653 2026] [core:notice] [pid 642360:tid 642607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:04.261930 2026] [security2:error] [pid 642360:tid 642531] [client 172.237.109.114:40813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF0gAAAbg"]
[Thu Jul 30 12:00:04.266187 2026] [security2:error] [pid 642360:tid 642607] [client 103.215.74.26:43502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDFJSUkh3e5AhEJOCF5gAAAgQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:04.268806 2026] [security2:error] [pid 643253:tid 643388] [client 172.237.109.114:19861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq2AAAAAQ"]
[Thu Jul 30 12:00:04.269362 2026] [security2:error] [pid 643253:tid 643466] [client 172.237.109.114:64870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq1wAAAFI"]
[Thu Jul 30 12:00:04.274783 2026] [security2:error] [pid 643253:tid 643345] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-blog-header.php"] [unique_id "amuDFMjqbtjBYzqM1uYq5gAAWlo"]
[Thu Jul 30 12:00:04.283154 2026] [security2:error] [pid 642360:tid 642574] [client 172.237.109.114:55658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF0QAAAeM"]
[Thu Jul 30 12:00:04.283744 2026] [security2:error] [pid 642360:tid 642409] [remote 57.141.0.52:39074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/index"] [unique_id "amuDFJSUkh3e5AhEJOCF5wABwTA"]
[Thu Jul 30 12:00:04.290379 2026] [security2:error] [pid 643253:tid 643501] [client 172.237.109.114:61384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq1gAAAHU"]
[Thu Jul 30 12:00:04.294517 2026] [security2:error] [pid 642360:tid 642520] [client 172.237.109.114:6334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF1AAAAa0"]
[Thu Jul 30 12:00:04.352836 2026] [security2:error] [pid 643253:tid 643389] [client 172.237.109.114:52777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq2QAAAAU"]
[Thu Jul 30 12:00:04.364996 2026] [security2:error] [pid 643253:tid 643390] [client 172.237.109.114:63236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq2gAAAAY"]
[Thu Jul 30 12:00:04.369543 2026] [security2:error] [pid 642360:tid 642565] [client 172.237.109.114:57959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF0wAAAdo"]
[Thu Jul 30 12:00:04.378225 2026] [security2:error] [pid 642360:tid 642596] [client 172.237.109.114:21059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF1wAAAfk"]
[Thu Jul 30 12:00:04.381649 2026] [security2:error] [pid 643253:tid 643408] [client 172.237.109.114:51490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq3AAAABg"]
[Thu Jul 30 12:00:04.398159 2026] [security2:error] [pid 643253:tid 643387] [client 172.237.109.114:47995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq3QAAAAM"]
[Thu Jul 30 12:00:04.422941 2026] [security2:error] [pid 643253:tid 643441] [client 172.237.109.114:17850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE8jqbtjBYzqM1uYq3gAAADk"]
[Thu Jul 30 12:00:04.425113 2026] [security2:error] [pid 642360:tid 642521] [client 172.237.109.114:51373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDE5SUkh3e5AhEJOCF2AAAAa4"]
[Thu Jul 30 12:00:04.522885 2026] [security2:error] [pid 643253:tid 643346] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-trackback.php"] [unique_id "amuDFMjqbtjBYzqM1uYq5wAASls"]
[Thu Jul 30 12:00:04.742752 2026] [security2:error] [pid 643253:tid 643431] [client 191.232.199.39:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-sigunq.php"] [unique_id "amuDFMjqbtjBYzqM1uYq6wAAAC8"]
[Thu Jul 30 12:00:04.807553 2026] [security2:error] [pid 643253:tid 643347] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-signup.php"] [unique_id "amuDFMjqbtjBYzqM1uYq7AAAblw"]
[Thu Jul 30 12:00:04.990792 2026] [core:notice] [pid 643253:tid 643468] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:04.995529 2026] [security2:error] [pid 643253:tid 643468] [client 103.215.74.26:43514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDFMjqbtjBYzqM1uYq7QAAAFQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:05.058051 2026] [security2:error] [pid 643253:tid 643349] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-comments-post.php"] [unique_id "amuDFcjqbtjBYzqM1uYq7gAAT14"]
[Thu Jul 30 12:00:05.304899 2026] [security2:error] [pid 643253:tid 643350] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-mail.php"] [unique_id "amuDFcjqbtjBYzqM1uYq7wAAF18"]
[Thu Jul 30 12:00:05.564703 2026] [security2:error] [pid 643253:tid 643348] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-activate.php"] [unique_id "amuDFcjqbtjBYzqM1uYq8gAAbF0"]
[Thu Jul 30 12:00:05.726340 2026] [core:notice] [pid 642360:tid 642569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:05.730331 2026] [security2:error] [pid 642360:tid 642569] [client 103.215.74.26:43528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDFZSUkh3e5AhEJOCF_QAAAd4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:05.781169 2026] [security2:error] [pid 643253:tid 643398] [client 20.215.191.139:17490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuDFcjqbtjBYzqM1uYq9AAAAA4"]
[Thu Jul 30 12:00:05.886558 2026] [security2:error] [pid 643253:tid 643351] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/post.php"] [unique_id "amuDFcjqbtjBYzqM1uYq9QAAZ2A"]
[Thu Jul 30 12:00:06.137573 2026] [security2:error] [pid 643253:tid 643353] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-2019.php"] [unique_id "amuDFsjqbtjBYzqM1uYq9gAAPGI"]
[Thu Jul 30 12:00:06.309023 2026] [security2:error] [pid 642360:tid 642504] [client 213.152.161.219:40610] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuDFpSUkh3e5AhEJOCGAgAAAZ0"]
[Thu Jul 30 12:00:06.309142 2026] [security2:error] [pid 642360:tid 642504] [client 213.152.161.219:40610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuDFpSUkh3e5AhEJOCGAgAAAZ0"]
[Thu Jul 30 12:00:06.409749 2026] [security2:error] [pid 643253:tid 643352] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/hoot.php"] [unique_id "amuDFsjqbtjBYzqM1uYq-AAALWE"]
[Thu Jul 30 12:00:06.460046 2026] [core:notice] [pid 642360:tid 642522] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:06.464511 2026] [security2:error] [pid 642360:tid 642522] [client 103.215.74.26:43542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDFpSUkh3e5AhEJOCGCgAAAa8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:06.531767 2026] [security2:error] [pid 642360:tid 642604] [client 191.232.199.39:36453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wso112233.php"] [unique_id "amuDFpSUkh3e5AhEJOCGCwAAAgE"]
[Thu Jul 30 12:00:06.656727 2026] [security2:error] [pid 643253:tid 643354] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/log.php"] [unique_id "amuDFsjqbtjBYzqM1uYq-QAANmM"]
[Thu Jul 30 12:00:07.116574 2026] [security2:error] [pid 643253:tid 643355] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bak.php"] [unique_id "amuDF8jqbtjBYzqM1uYq_QAAMWQ"]
[Thu Jul 30 12:00:07.186852 2026] [core:notice] [pid 642360:tid 642615] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:07.190944 2026] [security2:error] [pid 642360:tid 642615] [client 103.215.74.26:43558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDF5SUkh3e5AhEJOCGEwAAAgw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:07.397131 2026] [security2:error] [pid 643253:tid 643356] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/content.php"] [unique_id "amuDF8jqbtjBYzqM1uYq_gAAJ2U"]
[Thu Jul 30 12:00:07.398154 2026] [security2:error] [pid 642360:tid 642466] [remote 198.38.90.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.90.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altaazi.com"] [uri "/wp-login.php"] [unique_id "amuDF5SUkh3e5AhEJOCGGgAB72k"]
[Thu Jul 30 12:00:07.647444 2026] [security2:error] [pid 643253:tid 643357] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/upfile.php"] [unique_id "amuDF8jqbtjBYzqM1uYq_wAAS2Y"]
[Thu Jul 30 12:00:07.692914 2026] [security2:error] [pid 642360:tid 642520] [client 176.241.66.87:49497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDF5SUkh3e5AhEJOCGHAAAAa0"]
[Thu Jul 30 12:00:07.693034 2026] [security2:error] [pid 642360:tid 642520] [client 176.241.66.87:49497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDF5SUkh3e5AhEJOCGHAAAAa0"]
[Thu Jul 30 12:00:07.697955 2026] [security2:error] [pid 643253:tid 643427] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDF8jqbtjBYzqM1uYq_AAAACs"]
[Thu Jul 30 12:00:07.758333 2026] [proxy:error] [pid 642360:tid 642552] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:07.758397 2026] [proxy_http:error] [pid 642360:tid 642552] [client 34.233.129.35:30914] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:07.758932 2026] [proxy:error] [pid 642360:tid 642552] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:07.758988 2026] [proxy_http:error] [pid 642360:tid 642552] [client 34.233.129.35:30914] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:07.809204 2026] [security2:error] [pid 642360:tid 642596] [client 20.215.191.139:39387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuDF5SUkh3e5AhEJOCGJAAAAfk"]
[Thu Jul 30 12:00:07.833287 2026] [security2:error] [pid 642360:tid 642591] [client 191.232.199.39:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/alfanew.php"] [unique_id "amuDF5SUkh3e5AhEJOCGJQAAAfQ"]
[Thu Jul 30 12:00:07.969107 2026] [security2:error] [pid 643253:tid 643358] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/bypass.php"] [unique_id "amuDF8jqbtjBYzqM1uYrAAAAHGc"]
[Thu Jul 30 12:00:07.970369 2026] [core:notice] [pid 642360:tid 642542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:07.974687 2026] [security2:error] [pid 642360:tid 642542] [client 103.215.74.26:43564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDF5SUkh3e5AhEJOCGJgAAAcM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:08.107325 2026] [security2:error] [pid 642360:tid 642526] [client 172.202.44.182:45067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/wp-2019.php"] [unique_id "amuDGJSUkh3e5AhEJOCGKgAAAbM"]
[Thu Jul 30 12:00:08.225575 2026] [security2:error] [pid 643253:tid 643359] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/updates.php"] [unique_id "amuDGMjqbtjBYzqM1uYrAQAACmg"]
[Thu Jul 30 12:00:08.272955 2026] [security2:error] [pid 642360:tid 642551] [client 192.250.229.28:11760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDGJSUkh3e5AhEJOCGLQABzFc"]
[Thu Jul 30 12:00:08.473372 2026] [security2:error] [pid 643253:tid 643361] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/xmrlpc.php"] [unique_id "amuDGMjqbtjBYzqM1uYrAwAACWo"]
[Thu Jul 30 12:00:08.610311 2026] [security2:error] [pid 642360:tid 642605] [client 20.215.191.139:39965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuDGJSUkh3e5AhEJOCGNAAAAgI"]
[Thu Jul 30 12:00:08.718871 2026] [core:notice] [pid 642360:tid 642603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:08.725634 2026] [security2:error] [pid 642360:tid 642603] [client 103.215.74.26:43568] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDGJSUkh3e5AhEJOCGNQAAAgA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:08.799224 2026] [security2:error] [pid 643253:tid 643360] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ae.php"] [unique_id "amuDGMjqbtjBYzqM1uYrBAAAeWk"]
[Thu Jul 30 12:00:09.010812 2026] [security2:error] [pid 642360:tid 642611] [client 191.232.199.39:6317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/fw.php"] [unique_id "amuDGZSUkh3e5AhEJOCGPgAAAgg"]
[Thu Jul 30 12:00:09.066430 2026] [security2:error] [pid 643253:tid 643362] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/moon.php"] [unique_id "amuDGcjqbtjBYzqM1uYrBgAAaGs"]
[Thu Jul 30 12:00:09.098867 2026] [security2:error] [pid 642360:tid 642533] [client 172.202.44.182:45071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/hoot.php"] [unique_id "amuDGZSUkh3e5AhEJOCGPwAAAbo"]
[Thu Jul 30 12:00:09.200489 2026] [security2:error] [pid 642360:tid 642590] [client 66.249.73.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "vvr.hfl.temporary.site"] [uri "/index.php"] [unique_id "amuDGJSUkh3e5AhEJOCGOgAAAfM"]
[Thu Jul 30 12:00:09.330896 2026] [security2:error] [pid 642360:tid 642503] [client 20.215.191.139:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuDGZSUkh3e5AhEJOCGQwAAAZw"]
[Thu Jul 30 12:00:09.340432 2026] [security2:error] [pid 643253:tid 643363] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/blog.php"] [unique_id "amuDGcjqbtjBYzqM1uYrBwAAaWw"]
[Thu Jul 30 12:00:09.469558 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:09.476412 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:43584] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDGZSUkh3e5AhEJOCGRQAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:09.652226 2026] [security2:error] [pid 643253:tid 643364] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/ini.php"] [unique_id "amuDGcjqbtjBYzqM1uYrCAAAc20"]
[Thu Jul 30 12:00:09.902016 2026] [security2:error] [pid 643253:tid 643365] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/admin-ajax.php"] [unique_id "amuDGcjqbtjBYzqM1uYrCQAAVm4"]
[Thu Jul 30 12:00:09.978130 2026] [core:error] [pid 642360:tid 642548] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:00:09.978154 2026] [core:error] [pid 642360:tid 642548] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:00:10.111880 2026] [security2:error] [pid 642360:tid 642585] [client 20.215.191.139:17494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuDGpSUkh3e5AhEJOCGWAAAAe4"]
[Thu Jul 30 12:00:10.133016 2026] [security2:error] [pid 642360:tid 642523] [client 172.202.44.182:45085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/log.php"] [unique_id "amuDGpSUkh3e5AhEJOCGWgAAAbA"]
[Thu Jul 30 12:00:10.205416 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:10.209367 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:43592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDGsjqbtjBYzqM1uYrCgAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:10.347867 2026] [proxy:error] [pid 642360:tid 642596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:10.347943 2026] [proxy_http:error] [pid 642360:tid 642596] [client 143.244.57.82:52584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:10.348537 2026] [proxy:error] [pid 642360:tid 642596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:10.348593 2026] [proxy_http:error] [pid 642360:tid 642596] [client 143.244.57.82:52584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:10.373373 2026] [security2:error] [pid 643253:tid 643368] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/akc.php"] [unique_id "amuDGsjqbtjBYzqM1uYrCwAAAXE"]
[Thu Jul 30 12:00:10.639863 2026] [proxy:error] [pid 642360:tid 642577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:10.639934 2026] [proxy_http:error] [pid 642360:tid 642577] [client 143.244.57.82:52590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:10.640509 2026] [proxy:error] [pid 642360:tid 642577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:00:10.640554 2026] [proxy_http:error] [pid 642360:tid 642577] [client 143.244.57.82:52590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:00:10.642387 2026] [security2:error] [pid 643253:tid 643367] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/akcc.php"] [unique_id "amuDGsjqbtjBYzqM1uYrDQAAPXA"]
[Thu Jul 30 12:00:10.790373 2026] [security2:error] [pid 642360:tid 642597] [client 20.215.191.139:39388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuDGpSUkh3e5AhEJOCGZQAAAfo"]
[Thu Jul 30 12:00:10.858095 2026] [security2:error] [pid 642360:tid 642582] [client 191.232.199.39:6215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amuDGpSUkh3e5AhEJOCGYwAAAes"]
[Thu Jul 30 12:00:10.890314 2026] [security2:error] [pid 643253:tid 643366] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/asasx.php"] [unique_id "amuDGsjqbtjBYzqM1uYrDgAAJm8"]
[Thu Jul 30 12:00:10.925878 2026] [security2:error] [pid 642360:tid 642601] [client 143.244.57.82:52604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuDGpSUkh3e5AhEJOCGagAAAf4"]
[Thu Jul 30 12:00:10.927741 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:10.931937 2026] [security2:error] [pid 643253:tid 643414] [client 103.215.74.26:43594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDGsjqbtjBYzqM1uYrDwAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:11.136434 2026] [security2:error] [pid 643253:tid 643369] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/axx.php"] [unique_id "amuDG8jqbtjBYzqM1uYrEQAAAHI"]
[Thu Jul 30 12:00:11.216055 2026] [security2:error] [pid 642360:tid 642588] [client 143.244.57.82:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuDG5SUkh3e5AhEJOCGcAAAAfE"]
[Thu Jul 30 12:00:11.385835 2026] [security2:error] [pid 643253:tid 643370] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/berax.php"] [unique_id "amuDG8jqbtjBYzqM1uYrEgAAZnM"]
[Thu Jul 30 12:00:11.491126 2026] [security2:error] [pid 643253:tid 643472] [client 143.244.57.82:52626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuDG8jqbtjBYzqM1uYrFAAAAFg"]
[Thu Jul 30 12:00:11.528871 2026] [security2:error] [pid 642360:tid 642490] [client 20.215.191.139:39372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuDG5SUkh3e5AhEJOCGdAAAAY8"]
[Thu Jul 30 12:00:11.562073 2026] [security2:error] [pid 643253:tid 643401] [client 20.91.199.21:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/011i.php"] [unique_id "amuDG8jqbtjBYzqM1uYrFQAAABE"]
[Thu Jul 30 12:00:11.682853 2026] [security2:error] [pid 643253:tid 643371] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/build.php"] [unique_id "amuDG8jqbtjBYzqM1uYrFgAAKXQ"]
[Thu Jul 30 12:00:11.684258 2026] [core:notice] [pid 642360:tid 642572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:11.691117 2026] [security2:error] [pid 642360:tid 642572] [client 103.215.74.26:43600] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDG5SUkh3e5AhEJOCGeAAAAeE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:11.773488 2026] [security2:error] [pid 642360:tid 642503] [client 143.244.57.82:52642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuDG5SUkh3e5AhEJOCGeQAAAZw"]
[Thu Jul 30 12:00:11.930356 2026] [security2:error] [pid 643253:tid 643373] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/buy.php"] [unique_id "amuDG8jqbtjBYzqM1uYrGQAAM3Y"]
[Thu Jul 30 12:00:12.068100 2026] [security2:error] [pid 643253:tid 643436] [client 143.244.57.82:52658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuDHMjqbtjBYzqM1uYrGgAAADQ"]
[Thu Jul 30 12:00:12.149307 2026] [security2:error] [pid 642360:tid 642538] [client 172.202.44.182:45062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/bak.php"] [unique_id "amuDHJSUkh3e5AhEJOCGfwAAAb8"]
[Thu Jul 30 12:00:12.179448 2026] [security2:error] [pid 643253:tid 643374] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/checkbox.php"] [unique_id "amuDHMjqbtjBYzqM1uYrGwAAXnc"]
[Thu Jul 30 12:00:12.266449 2026] [security2:error] [pid 643253:tid 643424] [client 191.232.199.39:57772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/simple.php"] [unique_id "amuDHMjqbtjBYzqM1uYrHAAAACg"]
[Thu Jul 30 12:00:12.291868 2026] [security2:error] [pid 642360:tid 642613] [client 20.215.191.139:54594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/zwso.php"] [unique_id "amuDHJSUkh3e5AhEJOCGgAAAAgo"]
[Thu Jul 30 12:00:12.346663 2026] [security2:error] [pid 642360:tid 642600] [client 143.244.57.82:52668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuDHJSUkh3e5AhEJOCGggAAAf0"]
[Thu Jul 30 12:00:12.419704 2026] [core:notice] [pid 642360:tid 642604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:12.423770 2026] [security2:error] [pid 642360:tid 642604] [client 103.215.74.26:43604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDHJSUkh3e5AhEJOCGgwAAAgE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:12.446798 2026] [security2:error] [pid 643253:tid 643375] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/cong.php"] [unique_id "amuDHMjqbtjBYzqM1uYrHQAARHg"]
[Thu Jul 30 12:00:12.523101 2026] [security2:error] [pid 642360:tid 642576] [client 64.31.3.126:53313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuDGpSUkh3e5AhEJOCGaQAAAgM"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2269
[Thu Jul 30 12:00:12.535022 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:52683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/03a005685d.php"] [unique_id "amuDHJSUkh3e5AhEJOCGhwAAAew"]
[Thu Jul 30 12:00:12.580431 2026] [security2:error] [pid 643253:tid 643502] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDG8jqbtjBYzqM1uYrFwAAdnU"]
[Thu Jul 30 12:00:12.621754 2026] [security2:error] [pid 643253:tid 643400] [client 143.244.57.82:52674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuDHMjqbtjBYzqM1uYrHgAAABA"]
[Thu Jul 30 12:00:12.694541 2026] [security2:error] [pid 643253:tid 643376] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/file4.php"] [unique_id "amuDHMjqbtjBYzqM1uYrHwAAfnk"]
[Thu Jul 30 12:00:12.911332 2026] [security2:error] [pid 643253:tid 643466] [client 143.244.57.82:52682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuDHMjqbtjBYzqM1uYrIAAAAFI"]
[Thu Jul 30 12:00:12.973018 2026] [security2:error] [pid 643253:tid 643377] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/flower.php"] [unique_id "amuDHMjqbtjBYzqM1uYrIQAAWno"]
[Thu Jul 30 12:00:13.203606 2026] [security2:error] [pid 643253:tid 643386] [client 143.244.57.82:52686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuDHcjqbtjBYzqM1uYrIwAAAAI"]
[Thu Jul 30 12:00:13.310337 2026] [security2:error] [pid 642360:tid 642519] [client 114.119.159.236:61267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/share-series"] [unique_id "amuDHZSUkh3e5AhEJOCGlAAAAaw"], referer: https://alseermarine.com/investor-relations/fact-sheet
[Thu Jul 30 12:00:13.438964 2026] [security2:error] [pid 643253:tid 643378] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/form.php"] [unique_id "amuDHcjqbtjBYzqM1uYrJAAAA3s"]
[Thu Jul 30 12:00:13.456229 2026] [security2:error] [pid 642360:tid 642610] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDHJSUkh3e5AhEJOCGjgACB3I"]
[Thu Jul 30 12:00:13.480377 2026] [security2:error] [pid 643253:tid 643441] [client 143.244.57.82:52698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuDHcjqbtjBYzqM1uYrJQAAADk"]
[Thu Jul 30 12:00:13.734681 2026] [security2:error] [pid 643253:tid 643379] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/gecko.php"] [unique_id "amuDHcjqbtjBYzqM1uYrJgAAXHw"]
[Thu Jul 30 12:00:13.746522 2026] [security2:error] [pid 642360:tid 642596] [client 191.232.199.39:6242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/classsmtps.php"] [unique_id "amuDHZSUkh3e5AhEJOCGmwAAAfk"]
[Thu Jul 30 12:00:13.784698 2026] [security2:error] [pid 642360:tid 642571] [client 143.244.57.82:52708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuDHZSUkh3e5AhEJOCGnAAAAeA"]
[Thu Jul 30 12:00:14.020657 2026] [security2:error] [pid 643253:tid 643382] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/kyami.php"] [unique_id "amuDHsjqbtjBYzqM1uYrJwAAX38"]
[Thu Jul 30 12:00:14.096104 2026] [security2:error] [pid 642360:tid 642506] [client 143.244.57.82:52718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuDHpSUkh3e5AhEJOCGowAAAZ8"]
[Thu Jul 30 12:00:14.180912 2026] [security2:error] [pid 643253:tid 643481] [client 20.91.199.21:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/403.php"] [unique_id "amuDHsjqbtjBYzqM1uYrKAAAAGE"]
[Thu Jul 30 12:00:14.267842 2026] [security2:error] [pid 643253:tid 643380] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/manager.php"] [unique_id "amuDHsjqbtjBYzqM1uYrKQAAJX0"]
[Thu Jul 30 12:00:14.375436 2026] [security2:error] [pid 642360:tid 642490] [client 143.244.57.82:52732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuDHpSUkh3e5AhEJOCGpwAAAY8"]
[Thu Jul 30 12:00:14.559123 2026] [security2:error] [pid 643253:tid 643255] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/mari.php"] [unique_id "amuDHsjqbtjBYzqM1uYrKgAAYgA"]
[Thu Jul 30 12:00:14.678373 2026] [security2:error] [pid 642360:tid 642594] [client 143.244.57.82:52740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuDHpSUkh3e5AhEJOCGqwAAAfc"]
[Thu Jul 30 12:00:14.758824 2026] [security2:error] [pid 642360:tid 642509] [client 172.202.44.182:45089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/content.php"] [unique_id "amuDHpSUkh3e5AhEJOCGrwAAAaI"]
[Thu Jul 30 12:00:14.806269 2026] [security2:error] [pid 643253:tid 643381] [remote 172.202.44.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/nc4.php"] [unique_id "amuDHsjqbtjBYzqM1uYrKwAAO34"]
[Thu Jul 30 12:00:14.947754 2026] [security2:error] [pid 643253:tid 643458] [client 191.232.199.39:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-blog-header.php"] [unique_id "amuDHsjqbtjBYzqM1uYrLAAAAEo"]
[Thu Jul 30 12:00:14.951732 2026] [security2:error] [pid 643253:tid 643403] [client 20.91.199.21:56803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/404.php"] [unique_id "amuDHsjqbtjBYzqM1uYrLQAAABM"]
[Thu Jul 30 12:00:14.969622 2026] [security2:error] [pid 643253:tid 643428] [client 143.244.57.82:52746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuDHsjqbtjBYzqM1uYrLgAAACw"]
[Thu Jul 30 12:00:15.140355 2026] [cgid:error] [pid 643253:tid 643256] [remote 172.202.44.182:0] AH01265: stderr from /home2/xncnyxte/public_html/website_32476423/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:00:15.260875 2026] [security2:error] [pid 642360:tid 642587] [client 143.244.57.82:52750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.yaz.gzj.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuDH5SUkh3e5AhEJOCGtgAAAfA"]
[Thu Jul 30 12:00:15.384053 2026] [core:notice] [pid 642360:tid 642497] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:15.556647 2026] [security2:error] [pid 642360:tid 642493] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDHpSUkh3e5AhEJOCGsAABkg4"]
[Thu Jul 30 12:00:15.643143 2026] [security2:error] [pid 643253:tid 643451] [client 20.91.199.21:56564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/aa.php"] [unique_id "amuDH8jqbtjBYzqM1uYrMAAAAEM"]
[Thu Jul 30 12:00:15.647558 2026] [security2:error] [pid 642360:tid 642560] [client 114.119.154.215:59833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2023/01/200.webp"] [unique_id "amuDH5SUkh3e5AhEJOCGvgAAAdU"], referer: https://portal9nordeste.com.br/mulher-e-crianca-morrem-apos-desabamento-de-estrutura-de-concreto-em-cajazeiras-nordeste-1/
[Thu Jul 30 12:00:15.995463 2026] [security2:error] [pid 642360:tid 642616] [client 172.202.44.182:50533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/upfile.php"] [unique_id "amuDH5SUkh3e5AhEJOCGwgAAAg0"]
[Thu Jul 30 12:00:16.144898 2026] [security2:error] [pid 642360:tid 642541] [client 191.232.199.39:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-trackback.php"] [unique_id "amuDIJSUkh3e5AhEJOCGxgAAAcI"]
[Thu Jul 30 12:00:16.372804 2026] [security2:error] [pid 643253:tid 643431] [client 20.91.199.21:56569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/aafewc0k.php"] [unique_id "amuDIMjqbtjBYzqM1uYrMwAAAC8"]
[Thu Jul 30 12:00:16.632685 2026] [security2:error] [pid 643253:tid 643498] [client 50.6.43.217:47168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amuDEcjqbtjBYzqM1uYqyAAAAHI"]
[Thu Jul 30 12:00:17.532529 2026] [security2:error] [pid 642360:tid 642594] [client 191.232.199.39:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-signup.php"] [unique_id "amuDIZSUkh3e5AhEJOCG5gAAAfc"]
[Thu Jul 30 12:00:17.735883 2026] [security2:error] [pid 642360:tid 642599] [client 172.202.44.182:50515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/bypass.php"] [unique_id "amuDIZSUkh3e5AhEJOCG7AAAAfw"]
[Thu Jul 30 12:00:18.049157 2026] [security2:error] [pid 642360:tid 642613] [client 20.215.191.139:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuDIpSUkh3e5AhEJOCG-AAAAgo"]
[Thu Jul 30 12:00:18.168834 2026] [core:notice] [pid 642360:tid 642567] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:18.172821 2026] [security2:error] [pid 642360:tid 642567] [client 103.215.74.26:60080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDIpSUkh3e5AhEJOCG-QAAAdw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:18.299737 2026] [security2:error] [pid 642360:tid 642585] [client 176.241.66.87:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDIpSUkh3e5AhEJOCG_QAAAe4"]
[Thu Jul 30 12:00:18.299857 2026] [security2:error] [pid 642360:tid 642585] [client 176.241.66.87:50238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDIpSUkh3e5AhEJOCG_QAAAe4"]
[Thu Jul 30 12:00:18.670406 2026] [security2:error] [pid 642360:tid 642577] [client 37.120.155.179:54164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuDIpSUkh3e5AhEJOCHAQAAAeY"]
[Thu Jul 30 12:00:18.670513 2026] [security2:error] [pid 642360:tid 642577] [client 37.120.155.179:54164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuDIpSUkh3e5AhEJOCHAQAAAeY"]
[Thu Jul 30 12:00:18.897622 2026] [core:notice] [pid 642360:tid 642596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:18.902450 2026] [security2:error] [pid 642360:tid 642596] [client 103.215.74.26:60084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDIpSUkh3e5AhEJOCHBAAAAfk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:18.959141 2026] [security2:error] [pid 642360:tid 642519] [client 191.232.199.39:58427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuDIpSUkh3e5AhEJOCHBQAAAaw"]
[Thu Jul 30 12:00:18.985940 2026] [security2:error] [pid 642360:tid 642569] [client 20.91.199.21:52727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/abcd.php"] [unique_id "amuDIpSUkh3e5AhEJOCHBgAAAd4"]
[Thu Jul 30 12:00:19.306590 2026] [security2:error] [pid 642360:tid 642606] [client 114.119.128.6:59745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sv.radiojelli.com"] [uri "/why-i-love-to-watch-football"] [unique_id "amuDI5SUkh3e5AhEJOCHDAAAAgM"], referer: https://sv.radiojelli.com/sitemaps/sitemap0.xml
[Thu Jul 30 12:00:19.647264 2026] [core:notice] [pid 643253:tid 643409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:19.651442 2026] [security2:error] [pid 643253:tid 643409] [client 103.215.74.26:60092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDI8jqbtjBYzqM1uYrQAAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:19.892195 2026] [security2:error] [pid 642360:tid 642580] [client 20.91.199.21:36543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/about.php"] [unique_id "amuDI5SUkh3e5AhEJOCHGwAAAek"]
[Thu Jul 30 12:00:20.398519 2026] [core:notice] [pid 642360:tid 642565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:20.404008 2026] [security2:error] [pid 642360:tid 642565] [client 103.215.74.26:60096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJJSUkh3e5AhEJOCHHwAAAdo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:20.438141 2026] [security2:error] [pid 642360:tid 642597] [client 172.202.44.182:45101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/updates.php"] [unique_id "amuDJJSUkh3e5AhEJOCHJAAAAfo"]
[Thu Jul 30 12:00:20.502723 2026] [security2:error] [pid 643253:tid 643410] [client 191.232.199.39:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-mail.php"] [unique_id "amuDJMjqbtjBYzqM1uYrRAAAABo"]
[Thu Jul 30 12:00:20.843134 2026] [security2:error] [pid 643253:tid 643394] [client 20.91.199.21:56800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/admin.php"] [unique_id "amuDJMjqbtjBYzqM1uYrRgAAAAo"]
[Thu Jul 30 12:00:21.138958 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:21.142958 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:60100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJcjqbtjBYzqM1uYrSAAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:21.496985 2026] [security2:error] [pid 642360:tid 642585] [client 20.91.199.21:56521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/adminfuns.php"] [unique_id "amuDJZSUkh3e5AhEJOCHNQAAAe4"]
[Thu Jul 30 12:00:21.823278 2026] [security2:error] [pid 643253:tid 643489] [client 191.232.199.39:6257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-activate.php"] [unique_id "amuDJcjqbtjBYzqM1uYrSQAAAGk"]
[Thu Jul 30 12:00:21.881739 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:21.885788 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:60112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJcjqbtjBYzqM1uYrSgAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:22.446654 2026] [security2:error] [pid 642360:tid 642573] [client 20.91.199.21:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/albin.php"] [unique_id "amuDJpSUkh3e5AhEJOCHPwAAAeI"]
[Thu Jul 30 12:00:22.607695 2026] [core:notice] [pid 642360:tid 642603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:22.611828 2026] [security2:error] [pid 642360:tid 642603] [client 103.215.74.26:60122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJpSUkh3e5AhEJOCHQwAAAgA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:22.696539 2026] [security2:error] [pid 642360:tid 642557] [client 20.215.191.139:54713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/13.php"] [unique_id "amuDJpSUkh3e5AhEJOCHSAAAAdI"]
[Thu Jul 30 12:00:22.796021 2026] [security2:error] [pid 642360:tid 642553] [client 114.119.138.27:52087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/un-long-week-end-a-stockholm-norrmalm-et-ostermalm/stockholm-norrmalm_5/"] [unique_id "amuDJpSUkh3e5AhEJOCHSwAAAc4"], referer: https://www.carnetdeshopping.com/un-long-week-end-a-stockholm-norrmalm-et-ostermalm/stockholm-norrmalm_5/
[Thu Jul 30 12:00:23.018755 2026] [security2:error] [pid 643253:tid 643487] [client 20.215.191.139:40221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuDJ8jqbtjBYzqM1uYrTgAAAGc"]
[Thu Jul 30 12:00:23.243098 2026] [security2:error] [pid 642360:tid 642517] [client 191.232.199.39:6270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/post.php"] [unique_id "amuDJ5SUkh3e5AhEJOCHUgAAAao"]
[Thu Jul 30 12:00:23.344031 2026] [core:notice] [pid 642360:tid 642604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:23.348263 2026] [security2:error] [pid 642360:tid 642604] [client 103.215.74.26:65446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDJ5SUkh3e5AhEJOCHVQAAAgE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:23.769719 2026] [security2:error] [pid 642360:tid 642565] [client 20.91.199.21:36496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/amfsqvgv.php"] [unique_id "amuDJ5SUkh3e5AhEJOCHWgAAAdo"]
[Thu Jul 30 12:00:24.094161 2026] [core:notice] [pid 642360:tid 642493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:24.098720 2026] [security2:error] [pid 642360:tid 642493] [client 103.215.74.26:65448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDKJSUkh3e5AhEJOCHYwAAAZI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:24.721515 2026] [security2:error] [pid 643253:tid 643384] [client 191.232.199.39:57755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-2019.php"] [unique_id "amuDKMjqbtjBYzqM1uYrUgAAAAA"]
[Thu Jul 30 12:00:24.824105 2026] [core:notice] [pid 642360:tid 642581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:24.828448 2026] [security2:error] [pid 642360:tid 642581] [client 103.215.74.26:65450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDKJSUkh3e5AhEJOCHaQAAAeo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:24.969211 2026] [autoindex:error] [pid 643253:tid 643442] [client 3.228.112.215:64287] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:00:25.183347 2026] [security2:error] [pid 643253:tid 643266] [remote 57.141.0.58:59260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuDKMjqbtjBYzqM1uYrUwAAUAs"]
[Thu Jul 30 12:00:25.326446 2026] [security2:error] [pid 642360:tid 642607] [client 20.215.191.139:54620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/ava.php"] [unique_id "amuDKZSUkh3e5AhEJOCHbwAAAgQ"]
[Thu Jul 30 12:00:25.497579 2026] [security2:error] [pid 643253:tid 643483] [client 20.215.191.139:17546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuDKcjqbtjBYzqM1uYrWQAAAGM"]
[Thu Jul 30 12:00:25.562673 2026] [core:notice] [pid 642360:tid 642598] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:25.567257 2026] [security2:error] [pid 642360:tid 642598] [client 103.215.74.26:65454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDKZSUkh3e5AhEJOCHcgAAAfs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:25.567987 2026] [security2:error] [pid 643253:tid 643465] [client 20.91.199.21:52697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/ant.php"] [unique_id "amuDKcjqbtjBYzqM1uYrWgAAAFE"]
[Thu Jul 30 12:00:25.639957 2026] [security2:error] [pid 642360:tid 642454] [remote 62.81.179.164:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.179.81.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "urbanshiftmovingcompany.one"] [uri "/xmlrpc.php"] [unique_id "amuDKZSUkh3e5AhEJOCHdQACAl0"]
[Thu Jul 30 12:00:25.640124 2026] [security2:error] [pid 642360:tid 642605] [client 62.81.179.164:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "urbanshiftmovingcompany.one"] [uri "/xmlrpc.php"] [unique_id "amuDKZSUkh3e5AhEJOCHdQACAl0"]
[Thu Jul 30 12:00:25.918794 2026] [security2:error] [pid 642360:tid 642606] [client 172.202.44.182:45086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/xmrlpc.php"] [unique_id "amuDKZSUkh3e5AhEJOCHdgAAAgM"]
[Thu Jul 30 12:00:26.235693 2026] [security2:error] [pid 643253:tid 643446] [client 20.215.191.139:40229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuDKsjqbtjBYzqM1uYrXQAAAD4"]
[Thu Jul 30 12:00:26.298073 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:26.302467 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:65456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDKsjqbtjBYzqM1uYrXgAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:26.303741 2026] [security2:error] [pid 642360:tid 642569] [client 191.232.199.39:58457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/hoot.php"] [unique_id "amuDKpSUkh3e5AhEJOCHfAAAAd4"]
[Thu Jul 30 12:00:27.020897 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:27.025163 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:65468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDK8jqbtjBYzqM1uYrYAAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:27.433243 2026] [security2:error] [pid 642360:tid 642566] [client 20.215.191.139:17493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuDK5SUkh3e5AhEJOCHiAAAAds"]
[Thu Jul 30 12:00:27.610200 2026] [security2:error] [pid 643253:tid 643386] [client 172.202.44.182:50521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ae.php"] [unique_id "amuDK8jqbtjBYzqM1uYrYgAAAAI"]
[Thu Jul 30 12:00:27.738944 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:27.743329 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:65476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDK8jqbtjBYzqM1uYrYwAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:27.924675 2026] [security2:error] [pid 642360:tid 642572] [client 191.232.199.39:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/log.php"] [unique_id "amuDK5SUkh3e5AhEJOCHkQAAAeE"]
[Thu Jul 30 12:00:27.968917 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:28.216361 2026] [security2:error] [pid 643253:tid 643509] [client 20.215.191.139:54647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/main.php"] [unique_id "amuDLMjqbtjBYzqM1uYrZQAAAH0"]
[Thu Jul 30 12:00:28.275221 2026] [security2:error] [pid 642360:tid 642560] [client 20.215.191.139:17492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuDLJSUkh3e5AhEJOCHnAAAAdU"]
[Thu Jul 30 12:00:28.487056 2026] [core:notice] [pid 642360:tid 642549] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:28.494568 2026] [security2:error] [pid 642360:tid 642549] [client 103.215.74.26:65490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDLJSUkh3e5AhEJOCHngAAAco"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:28.496529 2026] [security2:error] [pid 643253:tid 643421] [client 20.91.199.21:55309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/appreciators.php"] [unique_id "amuDLMjqbtjBYzqM1uYrZgAAACU"]
[Thu Jul 30 12:00:28.898103 2026] [security2:error] [pid 642360:tid 642610] [client 176.241.66.87:50955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDLJSUkh3e5AhEJOCHowAAAgc"]
[Thu Jul 30 12:00:28.898224 2026] [security2:error] [pid 642360:tid 642610] [client 176.241.66.87:50955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDLJSUkh3e5AhEJOCHowAAAgc"]
[Thu Jul 30 12:00:29.142215 2026] [security2:error] [pid 642360:tid 642507] [client 172.202.44.182:45077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/moon.php"] [unique_id "amuDLZSUkh3e5AhEJOCHqAAAAaA"]
[Thu Jul 30 12:00:29.237369 2026] [security2:error] [pid 643253:tid 643485] [client 20.215.191.139:40718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuDLcjqbtjBYzqM1uYrawAAAGU"]
[Thu Jul 30 12:00:29.253422 2026] [security2:error] [pid 643253:tid 643482] [client 74.7.230.36:46444] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDLMjqbtjBYzqM1uYraAAAYgc"]
[Thu Jul 30 12:00:29.253449 2026] [security2:error] [pid 643253:tid 643482] [client 74.7.230.36:46444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDLMjqbtjBYzqM1uYraAAAYgc"]
[Thu Jul 30 12:00:29.524309 2026] [security2:error] [pid 643253:tid 643417] [client 191.232.199.39:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/bak.php"] [unique_id "amuDLcjqbtjBYzqM1uYrcAAAACE"]
[Thu Jul 30 12:00:29.825048 2026] [security2:error] [pid 642360:tid 642502] [client 20.215.191.139:54634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-file.php"] [unique_id "amuDLZSUkh3e5AhEJOCHswAAAZs"]
[Thu Jul 30 12:00:30.427448 2026] [security2:error] [pid 643253:tid 643507] [client 74.7.230.36:46450] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDLcjqbtjBYzqM1uYrdQAAewk"], referer: https://www.fireworkskenya.co.ke/robots.txt
[Thu Jul 30 12:00:30.669954 2026] [security2:error] [pid 643253:tid 643429] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDLsjqbtjBYzqM1uYregAAAC0"]
[Thu Jul 30 12:00:30.767158 2026] [security2:error] [pid 642360:tid 642513] [client 191.232.199.39:58378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/content.php"] [unique_id "amuDLpSUkh3e5AhEJOCHxQAAAaY"]
[Thu Jul 30 12:00:30.850970 2026] [security2:error] [pid 643253:tid 643484] [client 20.91.199.21:55324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/archive.php"] [unique_id "amuDLsjqbtjBYzqM1uYrewAAAGQ"]
[Thu Jul 30 12:00:30.959095 2026] [security2:error] [pid 642360:tid 642602] [client 20.215.191.139:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-signin.php"] [unique_id "amuDLpSUkh3e5AhEJOCHyQAAAf8"]
[Thu Jul 30 12:00:31.083857 2026] [core:notice] [pid 643253:tid 643268] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:31.228686 2026] [security2:error] [pid 643253:tid 643494] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDLcjqbtjBYzqM1uYrcgAAAG4"]
[Thu Jul 30 12:00:31.742643 2026] [security2:error] [pid 643253:tid 643412] [client 114.119.145.116:21487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/search"] [unique_id "amuDL8jqbtjBYzqM1uYrgQAAABw"], referer: https://www.kendarikomputer.com/search?updated-max=2023-05-30T13%3A43%3A00%2B08%3A00&max-results=10&reverse-paginate=true&m=1
[Thu Jul 30 12:00:31.758022 2026] [core:notice] [pid 643253:tid 643269] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:31.892619 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:32.094157 2026] [security2:error] [pid 643253:tid 643393] [client 191.232.199.39:48431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/upfile.php"] [unique_id "amuDMMjqbtjBYzqM1uYriAAAAAk"]
[Thu Jul 30 12:00:32.125629 2026] [security2:error] [pid 643253:tid 643270] [remote 47.86.33.52:41370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jgp.fxh.temporary.site"] [uri "/wp-login.php"] [unique_id "amuDMMjqbtjBYzqM1uYriQAAaQ8"]
[Thu Jul 30 12:00:32.845392 2026] [security2:error] [pid 643253:tid 643394] [client 20.91.199.21:52732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/as.php"] [unique_id "amuDMMjqbtjBYzqM1uYrkQAAAAo"]
[Thu Jul 30 12:00:33.099617 2026] [security2:error] [pid 643253:tid 643480] [client 20.215.191.139:17481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuDMcjqbtjBYzqM1uYrlQAAAGA"]
[Thu Jul 30 12:00:33.181496 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:33.358834 2026] [security2:error] [pid 643253:tid 643418] [client 191.232.199.39:6308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/bypass.php"] [unique_id "amuDMcjqbtjBYzqM1uYrmQAAACI"]
[Thu Jul 30 12:00:33.915571 2026] [security2:error] [pid 642360:tid 642590] [client 20.215.191.139:54645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/simi.php"] [unique_id "amuDMZSUkh3e5AhEJOCH5QAAAfM"]
[Thu Jul 30 12:00:34.235614 2026] [core:notice] [pid 642360:tid 642501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:34.242188 2026] [security2:error] [pid 642360:tid 642501] [client 103.215.74.26:37200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDMpSUkh3e5AhEJOCH6QAAAZo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:34.494217 2026] [security2:error] [pid 642360:tid 642503] [client 20.215.191.139:54648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-conf.php"] [unique_id "amuDMpSUkh3e5AhEJOCH7AAAAZw"]
[Thu Jul 30 12:00:34.551550 2026] [core:notice] [pid 642360:tid 642476] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:34.782931 2026] [security2:error] [pid 642360:tid 642509] [client 20.215.191.139:40739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuDMpSUkh3e5AhEJOCH8QAAAaI"]
[Thu Jul 30 12:00:34.841310 2026] [security2:error] [pid 643253:tid 643472] [client 191.232.199.39:48411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/updates.php"] [unique_id "amuDMsjqbtjBYzqM1uYrngAAAFg"]
[Thu Jul 30 12:00:34.987813 2026] [core:notice] [pid 643253:tid 643509] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:34.993822 2026] [security2:error] [pid 643253:tid 643509] [client 103.215.74.26:37202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDMsjqbtjBYzqM1uYroAAAAH0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:35.231091 2026] [security2:error] [pid 642360:tid 642611] [client 20.91.199.21:56827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/atomlib.php"] [unique_id "amuDM5SUkh3e5AhEJOCH-QAAAgg"]
[Thu Jul 30 12:00:35.460606 2026] [core:notice] [pid 642360:tid 642477] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:35.680418 2026] [core:notice] [pid 643253:tid 643275] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:35.690319 2026] [security2:error] [pid 643253:tid 643426] [client 20.215.191.139:40216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuDM8jqbtjBYzqM1uYrpgAAACo"]
[Thu Jul 30 12:00:36.034409 2026] [security2:error] [pid 643253:tid 643431] [client 20.91.199.21:55336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/autoload_classmap.php"] [unique_id "amuDNMjqbtjBYzqM1uYrpwAAAC8"]
[Thu Jul 30 12:00:36.321679 2026] [security2:error] [pid 642360:tid 642572] [client 20.215.191.139:54597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuDNJSUkh3e5AhEJOCIBgAAAeE"]
[Thu Jul 30 12:00:36.432254 2026] [security2:error] [pid 643253:tid 643508] [client 191.232.199.39:48166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/xmrlpc.php"] [unique_id "amuDNMjqbtjBYzqM1uYrqQAAAHw"]
[Thu Jul 30 12:00:36.541305 2026] [security2:error] [pid 642360:tid 642616] [client 173.249.217.7:35294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuDNJSUkh3e5AhEJOCIBQAAAg0"]
[Thu Jul 30 12:00:36.541413 2026] [security2:error] [pid 642360:tid 642616] [client 173.249.217.7:35294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuDNJSUkh3e5AhEJOCIBQAAAg0"]
[Thu Jul 30 12:00:36.703276 2026] [security2:error] [pid 642360:tid 642524] [client 34.91.100.7:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.cnpinyin.com"] [uri "/"] [unique_id "amuDNJSUkh3e5AhEJOCICwAAAbE"]
[Thu Jul 30 12:00:36.703371 2026] [security2:error] [pid 642360:tid 642524] [client 34.91.100.7:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.cnpinyin.com"] [uri "/"] [unique_id "amuDNJSUkh3e5AhEJOCICwAAAbE"]
[Thu Jul 30 12:00:36.719483 2026] [security2:error] [pid 642360:tid 642545] [client 172.202.44.182:50548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/blog.php"] [unique_id "amuDNJSUkh3e5AhEJOCIDAAAAcY"]
[Thu Jul 30 12:00:36.725192 2026] [security2:error] [pid 642360:tid 642369] [remote 114.119.157.108:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/get/vancouver"] [unique_id "amuDNJSUkh3e5AhEJOCIDQAB2Ag"], referer: https://www.jipkl.com/index.php/JIPKL/article/view/79
[Thu Jul 30 12:00:37.009823 2026] [security2:error] [pid 642360:tid 642510] [client 20.215.191.139:38821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuDNZSUkh3e5AhEJOCIEAAAAaM"]
[Thu Jul 30 12:00:37.158862 2026] [security2:error] [pid 643253:tid 643398] [client 20.215.191.139:54601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/bala.php"] [unique_id "amuDNcjqbtjBYzqM1uYrrQAAAA4"]
[Thu Jul 30 12:00:37.209677 2026] [core:notice] [pid 642360:tid 642528] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:37.726675 2026] [security2:error] [pid 643253:tid 643429] [client 114.119.158.251:43011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/the-importance-of-alloy-steel-chains-in-construction/"] [unique_id "amuDNcjqbtjBYzqM1uYrsAAAAC0"], referer: https://saifalkhaleejest.com/the-importance-of-alloy-steel-chains-in-construction/
[Thu Jul 30 12:00:37.906007 2026] [security2:error] [pid 642360:tid 642491] [client 66.249.73.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDNZSUkh3e5AhEJOCIHgAAAZA"]
[Thu Jul 30 12:00:38.200204 2026] [security2:error] [pid 643253:tid 643409] [client 191.232.199.39:48402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/ae.php"] [unique_id "amuDNsjqbtjBYzqM1uYrtAAAABk"]
[Thu Jul 30 12:00:38.717663 2026] [security2:error] [pid 642360:tid 642557] [client 20.91.199.21:56798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/bb.php"] [unique_id "amuDNpSUkh3e5AhEJOCIJwAAAdI"]
[Thu Jul 30 12:00:38.888329 2026] [security2:error] [pid 643253:tid 643433] [client 50.6.43.217:57150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDNsjqbtjBYzqM1uYrswAAADE"]
[Thu Jul 30 12:00:39.047887 2026] [security2:error] [pid 642360:tid 642538] [client 172.202.44.182:45061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/ini.php"] [unique_id "amuDN5SUkh3e5AhEJOCILAAAAb8"]
[Thu Jul 30 12:00:39.206941 2026] [security2:error] [pid 642360:tid 642511] [client 20.215.191.139:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/bk.php"] [unique_id "amuDN5SUkh3e5AhEJOCIMAAAAaQ"]
[Thu Jul 30 12:00:39.589881 2026] [security2:error] [pid 643253:tid 643419] [client 50.6.43.217:57152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuDNsjqbtjBYzqM1uYrvAAAACM"]
[Thu Jul 30 12:00:39.624831 2026] [security2:error] [pid 642360:tid 642615] [client 191.232.199.39:32518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/moon.php"] [unique_id "amuDN5SUkh3e5AhEJOCINgAAAgw"]
[Thu Jul 30 12:00:39.748445 2026] [security2:error] [pid 643253:tid 643477] [client 176.241.66.87:51663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDN8jqbtjBYzqM1uYrvwAAAF0"]
[Thu Jul 30 12:00:39.748600 2026] [security2:error] [pid 643253:tid 643477] [client 176.241.66.87:51663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDN8jqbtjBYzqM1uYrvwAAAF0"]
[Thu Jul 30 12:00:39.868828 2026] [security2:error] [pid 642360:tid 642583] [client 20.91.199.21:53033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/bnm.php"] [unique_id "amuDN5SUkh3e5AhEJOCIOQAAAew"]
[Thu Jul 30 12:00:40.332439 2026] [security2:error] [pid 642360:tid 642559] [client 172.202.44.182:50520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/admin-ajax.php"] [unique_id "amuDOJSUkh3e5AhEJOCIQQAAAdQ"]
[Thu Jul 30 12:00:40.397622 2026] [core:notice] [pid 642360:tid 642400] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:40.599247 2026] [security2:error] [pid 642360:tid 642584] [client 20.215.191.139:40720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuDOJSUkh3e5AhEJOCIRAAAAe0"]
[Thu Jul 30 12:00:40.655963 2026] [security2:error] [pid 643253:tid 643454] [client 20.215.191.139:54625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/ahax.php"] [unique_id "amuDOMjqbtjBYzqM1uYrwwAAAEY"]
[Thu Jul 30 12:00:40.770314 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:40.774569 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:37210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDOMjqbtjBYzqM1uYrxQAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:40.849304 2026] [core:notice] [pid 642360:tid 642372] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:40.906155 2026] [core:notice] [pid 642360:tid 642396] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:40.926557 2026] [security2:error] [pid 643253:tid 643414] [client 191.232.199.39:48178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/blog.php"] [unique_id "amuDOMjqbtjBYzqM1uYrxwAAAB4"]
[Thu Jul 30 12:00:41.297011 2026] [security2:error] [pid 643253:tid 643460] [client 20.91.199.21:36480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/bootstrap.php"] [unique_id "amuDOcjqbtjBYzqM1uYryQAAAEw"]
[Thu Jul 30 12:00:41.394537 2026] [security2:error] [pid 642360:tid 642490] [client 20.215.191.139:38819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuDOZSUkh3e5AhEJOCIUwAAAY8"]
[Thu Jul 30 12:00:41.523133 2026] [core:notice] [pid 642360:tid 642534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:41.527636 2026] [security2:error] [pid 642360:tid 642534] [client 103.215.74.26:37218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDOZSUkh3e5AhEJOCIVAAAAbs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:41.548088 2026] [core:notice] [pid 642360:tid 642480] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:41.553020 2026] [security2:error] [pid 642360:tid 642573] [client 172.202.44.182:50551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/akc.php"] [unique_id "amuDOZSUkh3e5AhEJOCIVgAAAeI"]
[Thu Jul 30 12:00:41.704163 2026] [core:notice] [pid 642360:tid 642423] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:41.961654 2026] [security2:error] [pid 642360:tid 642588] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDOZSUkh3e5AhEJOCIUAAAAfE"]
[Thu Jul 30 12:00:42.123717 2026] [security2:error] [pid 642360:tid 642432] [remote 74.7.241.60:50116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuDOpSUkh3e5AhEJOCIYQAB2kc"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:00:42.234507 2026] [security2:error] [pid 642360:tid 642594] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDOZSUkh3e5AhEJOCIVwAB9yQ"]
[Thu Jul 30 12:00:42.259167 2026] [security2:error] [pid 642360:tid 642587] [client 191.232.199.39:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/ini.php"] [unique_id "amuDOpSUkh3e5AhEJOCIZQAAAfA"]
[Thu Jul 30 12:00:42.282930 2026] [core:notice] [pid 642360:tid 642525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:42.289163 2026] [security2:error] [pid 642360:tid 642525] [client 103.215.74.26:37234] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDOpSUkh3e5AhEJOCIZwAAAbI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:42.510272 2026] [security2:error] [pid 642360:tid 642493] [client 43.172.195.199:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/05/21/vente-privee-de-maillots-de-bain-seafolly/"] [unique_id "amuDOpSUkh3e5AhEJOCIZgAAAZI"]
[Thu Jul 30 12:00:42.622300 2026] [security2:error] [pid 642360:tid 642523] [client 43.173.178.198:42614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/30/on-va-decouvrir-la-collection-pe14-naf-naf-avec-leighton-meester/"] [unique_id "amuDOpSUkh3e5AhEJOCIagAAAbA"]
[Thu Jul 30 12:00:42.649960 2026] [security2:error] [pid 643253:tid 643388] [client 172.202.44.182:50552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/akcc.php"] [unique_id "amuDOsjqbtjBYzqM1uYr0wAAAAQ"]
[Thu Jul 30 12:00:42.767823 2026] [core:notice] [pid 642360:tid 642518] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:42.772447 2026] [security2:error] [pid 642360:tid 642518] [client 43.173.178.253:36810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/05/21/vente-privee-de-maillots-de-bain-seafolly/"] [unique_id "amuDOpSUkh3e5AhEJOCIcQAAAas"], referer: https://carnetdeshopping.com/index.php/2011/05/21/vente-privee-de-maillots-de-bain-seafolly/
[Thu Jul 30 12:00:42.809617 2026] [core:notice] [pid 642360:tid 642607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:42.814642 2026] [security2:error] [pid 642360:tid 642607] [client 43.172.194.135:48396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/30/on-va-decouvrir-la-collection-pe14-naf-naf-avec-leighton-meester/"] [unique_id "amuDOpSUkh3e5AhEJOCIdgAAAgQ"], referer: https://carnetdeshopping.com/index.php/2014/03/30/on-va-decouvrir-la-collection-pe14-naf-naf-avec-leighton-meester/?replytocom=1195
[Thu Jul 30 12:00:42.871076 2026] [security2:error] [pid 642360:tid 642615] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDOpSUkh3e5AhEJOCIaQAAAgw"]
[Thu Jul 30 12:00:43.522063 2026] [security2:error] [pid 642360:tid 642610] [client 191.232.199.39:6475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/admin-ajax.php"] [unique_id "amuDO5SUkh3e5AhEJOCIgAAAAgc"]
[Thu Jul 30 12:00:43.871329 2026] [security2:error] [pid 642360:tid 642563] [client 20.215.191.139:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuDO5SUkh3e5AhEJOCIhQAAAdg"]
[Thu Jul 30 12:00:44.002595 2026] [core:notice] [pid 642360:tid 642417] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:44.114094 2026] [security2:error] [pid 642360:tid 642551] [client 20.91.199.21:36495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/buy.php"] [unique_id "amuDPJSUkh3e5AhEJOCIjAAAAcw"]
[Thu Jul 30 12:00:44.387537 2026] [security2:error] [pid 642360:tid 642604] [client 114.119.137.64:53221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiantourz.com"] [uri "/soldes/homme-superdry-waterpolo-swim-short-bleu-maillots-shorts-de-bain"] [unique_id "amuDPJSUkh3e5AhEJOCIjQAAAgE"], referer: https://www.arabiantourz.com/soldes/homme-superdry-waterpolo-swim-short-bleu-maillots-shorts-de-bain
[Thu Jul 30 12:00:44.566022 2026] [core:notice] [pid 642360:tid 642378] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:44.581222 2026] [security2:error] [pid 642360:tid 642500] [client 172.202.44.182:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/asasx.php"] [unique_id "amuDPJSUkh3e5AhEJOCIlwAAAZk"]
[Thu Jul 30 12:00:44.815147 2026] [security2:error] [pid 643253:tid 643434] [client 191.232.199.39:7017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/akc.php"] [unique_id "amuDPMjqbtjBYzqM1uYr1wAAADI"]
[Thu Jul 30 12:00:44.974880 2026] [security2:error] [pid 642360:tid 642573] [client 20.215.191.139:38828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuDPJSUkh3e5AhEJOCInAAAAeI"]
[Thu Jul 30 12:00:45.657520 2026] [security2:error] [pid 642360:tid 642611] [client 20.91.199.21:56515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/chosen.php"] [unique_id "amuDPZSUkh3e5AhEJOCIqAAAAgg"]
[Thu Jul 30 12:00:45.841676 2026] [security2:error] [pid 643253:tid 643404] [client 20.215.191.139:40253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuDPcjqbtjBYzqM1uYr3gAAABQ"]
[Thu Jul 30 12:00:46.241857 2026] [security2:error] [pid 643253:tid 643491] [client 191.232.199.39:7039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/akcc.php"] [unique_id "amuDPsjqbtjBYzqM1uYr3wAAAGs"]
[Thu Jul 30 12:00:46.264281 2026] [security2:error] [pid 642360:tid 642533] [client 114.119.140.175:57853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kingstarenterprises.com"] [uri "/product-category/gym-club-accessories/weight-lifting-half-finger-gloves/"] [unique_id "amuDPpSUkh3e5AhEJOCIrwAAAbo"], referer: http://www.kingstarenterprises.com/
[Thu Jul 30 12:00:46.364283 2026] [security2:error] [pid 643253:tid 643467] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDPcjqbtjBYzqM1uYr3QAAAFM"]
[Thu Jul 30 12:00:46.406536 2026] [security2:error] [pid 642360:tid 642515] [client 172.202.44.182:39201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/axx.php"] [unique_id "amuDPpSUkh3e5AhEJOCIsQAAAag"]
[Thu Jul 30 12:00:46.528507 2026] [security2:error] [pid 643253:tid 643413] [client 20.215.191.139:40218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuDPsjqbtjBYzqM1uYr4AAAAB0"]
[Thu Jul 30 12:00:47.388911 2026] [security2:error] [pid 643253:tid 643426] [client 172.202.44.182:50523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/berax.php"] [unique_id "amuDP8jqbtjBYzqM1uYr4gAAACo"]
[Thu Jul 30 12:00:47.461913 2026] [security2:error] [pid 642360:tid 642609] [client 20.91.199.21:49887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/class-wp-image.php"] [unique_id "amuDP5SUkh3e5AhEJOCIvwAAAgY"]
[Thu Jul 30 12:00:47.508854 2026] [security2:error] [pid 642360:tid 642580] [client 213.152.161.219:38406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuDP5SUkh3e5AhEJOCIwAAAAek"]
[Thu Jul 30 12:00:47.508943 2026] [security2:error] [pid 642360:tid 642580] [client 213.152.161.219:38406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuDP5SUkh3e5AhEJOCIwAAAAek"]
[Thu Jul 30 12:00:47.642415 2026] [security2:error] [pid 642360:tid 642563] [client 191.232.199.39:6476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/asasx.php"] [unique_id "amuDP5SUkh3e5AhEJOCIyAAAAdg"]
[Thu Jul 30 12:00:47.646427 2026] [security2:error] [pid 642360:tid 642517] [client 20.215.191.139:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuDP5SUkh3e5AhEJOCIyQAAAao"]
[Thu Jul 30 12:00:47.786157 2026] [security2:error] [pid 642360:tid 642544] [client 213.152.187.225:42954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuDP5SUkh3e5AhEJOCIwQAAAcU"]
[Thu Jul 30 12:00:47.786307 2026] [security2:error] [pid 642360:tid 642544] [client 213.152.187.225:42954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuDP5SUkh3e5AhEJOCIwQAAAcU"]
[Thu Jul 30 12:00:48.023582 2026] [core:notice] [pid 643253:tid 643506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:48.030871 2026] [security2:error] [pid 643253:tid 643506] [client 103.215.74.26:48066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQMjqbtjBYzqM1uYr4wAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:48.135147 2026] [security2:error] [pid 642360:tid 642531] [client 114.119.131.200:24159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/docs/5cfb7b-portsmouth-kit-20/5cfb7b-who-wrote-the-original-valerie-song"] [unique_id "amuDQJSUkh3e5AhEJOCI0QAAAbg"], referer: https://arabiandubaisafari.com/docs/5cfb7b-portsmouth-kit-20/5cfb7b-who-wrote-the-original-valerie-song
[Thu Jul 30 12:00:48.200905 2026] [security2:error] [pid 642360:tid 642558] [client 20.91.199.21:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/classsmtps.php"] [unique_id "amuDQJSUkh3e5AhEJOCI1QAAAdM"]
[Thu Jul 30 12:00:48.364750 2026] [security2:error] [pid 642360:tid 642494] [client 172.202.44.182:50506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/build.php"] [unique_id "amuDQJSUkh3e5AhEJOCI1gAAAZM"]
[Thu Jul 30 12:00:48.772649 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:48.776670 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:48076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQMjqbtjBYzqM1uYr5QAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:48.796480 2026] [security2:error] [pid 642360:tid 642591] [client 114.119.158.112:63269] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabian-tours.com"] [uri "/site/michael-scholar-56216b"] [unique_id "amuDQJSUkh3e5AhEJOCI3wAAAfQ"], referer: https://arabian-tours.com/site/sweeney_sydney-instagram-56216b
[Thu Jul 30 12:00:48.912547 2026] [security2:error] [pid 642360:tid 642572] [client 20.91.199.21:36522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/classwithtostring.php"] [unique_id "amuDQJSUkh3e5AhEJOCI4AAAAeE"]
[Thu Jul 30 12:00:49.097949 2026] [security2:error] [pid 642360:tid 642543] [client 191.232.199.39:58895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/axx.php"] [unique_id "amuDQZSUkh3e5AhEJOCI4wAAAcQ"]
[Thu Jul 30 12:00:49.505873 2026] [core:notice] [pid 642360:tid 642498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:49.509881 2026] [security2:error] [pid 642360:tid 642498] [client 103.215.74.26:48090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQZSUkh3e5AhEJOCI7AAAAZc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:50.250149 2026] [security2:error] [pid 642360:tid 642578] [client 176.241.66.87:52670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDQpSUkh3e5AhEJOCI9wAAAec"]
[Thu Jul 30 12:00:50.250354 2026] [security2:error] [pid 642360:tid 642578] [client 176.241.66.87:52670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDQpSUkh3e5AhEJOCI9wAAAec"]
[Thu Jul 30 12:00:50.280536 2026] [core:notice] [pid 642360:tid 642516] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:50.287140 2026] [security2:error] [pid 642360:tid 642516] [client 103.215.74.26:48104] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQpSUkh3e5AhEJOCI-AAAAak"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:50.338010 2026] [security2:error] [pid 642360:tid 642491] [client 191.232.199.39:6500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/berax.php"] [unique_id "amuDQpSUkh3e5AhEJOCI-QAAAZA"]
[Thu Jul 30 12:00:50.343275 2026] [security2:error] [pid 642360:tid 642595] [client 172.202.44.182:45076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/buy.php"] [unique_id "amuDQpSUkh3e5AhEJOCI-gAAAfg"]
[Thu Jul 30 12:00:50.877803 2026] [security2:error] [pid 642360:tid 642610] [client 20.215.191.139:40949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuDQpSUkh3e5AhEJOCJAwAAAgc"]
[Thu Jul 30 12:00:51.024400 2026] [core:notice] [pid 642360:tid 642530] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:51.028578 2026] [security2:error] [pid 642360:tid 642530] [client 103.215.74.26:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQ5SUkh3e5AhEJOCJBwAAAbc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:51.164545 2026] [core:error] [pid 642360:tid 642446] [remote 74.7.175.142:40992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:00:51.164577 2026] [core:error] [pid 642360:tid 642446] [remote 74.7.175.142:40992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:00:51.164803 2026] [security2:error] [pid 642360:tid 642565] [client 74.7.175.142:40992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-8880a99c.lld.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuDQ5SUkh3e5AhEJOCJCAAB2lU"]
[Thu Jul 30 12:00:51.251318 2026] [security2:error] [pid 642360:tid 642587] [client 172.202.44.182:45099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/checkbox.php"] [unique_id "amuDQ5SUkh3e5AhEJOCJDAAAAfA"]
[Thu Jul 30 12:00:51.641119 2026] [security2:error] [pid 642360:tid 642510] [client 191.232.199.39:58834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/build.php"] [unique_id "amuDQ5SUkh3e5AhEJOCJEAAAAaM"]
[Thu Jul 30 12:00:51.733721 2026] [core:notice] [pid 642360:tid 642568] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:51.742726 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:51.746489 2026] [security2:error] [pid 642360:tid 642494] [client 103.215.74.26:48130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDQ5SUkh3e5AhEJOCJFQAAAZM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:51.781743 2026] [security2:error] [pid 642360:tid 642461] [remote 217.182.128.41:42678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuDQ5SUkh3e5AhEJOCJFgAB6GQ"]
[Thu Jul 30 12:00:52.302897 2026] [security2:error] [pid 642360:tid 642603] [client 74.7.244.54:57458] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "msz.udi.temporary.site"] [uri "/index.php"] [unique_id "amuDQpSUkh3e5AhEJOCI9gACAAE"]
[Thu Jul 30 12:00:52.399700 2026] [security2:error] [pid 642360:tid 642529] [client 20.215.191.139:38800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuDRJSUkh3e5AhEJOCJHwAAAbY"]
[Thu Jul 30 12:00:52.458372 2026] [security2:error] [pid 642360:tid 642582] [client 20.91.199.21:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/config.php"] [unique_id "amuDRJSUkh3e5AhEJOCJIAAAAes"]
[Thu Jul 30 12:00:52.483649 2026] [core:notice] [pid 642360:tid 642590] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:52.487780 2026] [security2:error] [pid 642360:tid 642590] [client 103.215.74.26:48134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDRJSUkh3e5AhEJOCJIQAAAfM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:52.637557 2026] [security2:error] [pid 642360:tid 642611] [client 172.202.44.182:50546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/cong.php"] [unique_id "amuDRJSUkh3e5AhEJOCJJAAAAgg"]
[Thu Jul 30 12:00:53.212745 2026] [core:notice] [pid 642360:tid 642501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:53.219193 2026] [security2:error] [pid 642360:tid 642501] [client 103.215.74.26:34820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDRZSUkh3e5AhEJOCJMAAAAZo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:53.341519 2026] [security2:error] [pid 642360:tid 642507] [client 191.232.199.39:58850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/buy.php"] [unique_id "amuDRZSUkh3e5AhEJOCJNAAAAaA"]
[Thu Jul 30 12:00:53.377717 2026] [security2:error] [pid 643253:tid 643416] [client 20.91.199.21:53468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/core.php"] [unique_id "amuDRcjqbtjBYzqM1uYr7QAAACA"]
[Thu Jul 30 12:00:53.819195 2026] [security2:error] [pid 642360:tid 642544] [client 193.9.48.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDRZSUkh3e5AhEJOCJOwAAAcU"], referer: https://cnpinyin.com/register
[Thu Jul 30 12:00:53.894829 2026] [security2:error] [pid 642360:tid 642563] [client 172.202.44.182:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/file4.php"] [unique_id "amuDRZSUkh3e5AhEJOCJPwAAAdg"]
[Thu Jul 30 12:00:53.949878 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:53.954377 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:34832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDRcjqbtjBYzqM1uYr7gAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:54.592769 2026] [security2:error] [pid 643253:tid 643463] [client 20.215.191.139:40725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuDRsjqbtjBYzqM1uYr8AAAAE8"]
[Thu Jul 30 12:00:54.671854 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:54.675810 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:34834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDRpSUkh3e5AhEJOCJSAAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:54.729862 2026] [security2:error] [pid 643253:tid 643505] [client 191.232.199.39:58848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/checkbox.php"] [unique_id "amuDRsjqbtjBYzqM1uYr8QAAAHk"]
[Thu Jul 30 12:00:55.022624 2026] [security2:error] [pid 642360:tid 642614] [client 20.91.199.21:49866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/css.php"] [unique_id "amuDR5SUkh3e5AhEJOCJSwAAAgs"]
[Thu Jul 30 12:00:55.060782 2026] [security2:error] [pid 642360:tid 642581] [client 172.202.44.182:45073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/flower.php"] [unique_id "amuDR5SUkh3e5AhEJOCJTAAAAeo"]
[Thu Jul 30 12:00:55.426779 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:55.432871 2026] [security2:error] [pid 643253:tid 643419] [client 103.215.74.26:34840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDR8jqbtjBYzqM1uYr9gAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:56.127896 2026] [security2:error] [pid 642360:tid 642605] [client 191.232.199.39:48220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/cong.php"] [unique_id "amuDSJSUkh3e5AhEJOCJVgAAAgI"]
[Thu Jul 30 12:00:56.169408 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:56.176381 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:34852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDSJSUkh3e5AhEJOCJWgAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:56.332310 2026] [security2:error] [pid 642360:tid 642571] [client 172.202.44.182:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/form.php"] [unique_id "amuDSJSUkh3e5AhEJOCJWwAAAeA"]
[Thu Jul 30 12:00:56.363309 2026] [security2:error] [pid 642360:tid 642532] [client 114.119.139.115:34997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/40/"] [unique_id "amuDSJSUkh3e5AhEJOCJXAAAAbk"], referer: https://kicksity.com/shop/?min_price=140&max_price=280&filtering=1&filter_product_cat=166%2C231%2C146%2C186%2C157
[Thu Jul 30 12:00:56.416036 2026] [security2:error] [pid 643253:tid 643401] [client 114.119.155.115:39163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/contact-2/"] [unique_id "amuDSMjqbtjBYzqM1uYr_AAAABE"], referer: http://pkf.jo/Home/News?id=7142&parid=0&ltid=4
[Thu Jul 30 12:00:56.603953 2026] [security2:error] [pid 643253:tid 643393] [client 172.237.109.114:24572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSMjqbtjBYzqM1uYr-gAAAAk"]
[Thu Jul 30 12:00:56.944662 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:56.949930 2026] [security2:error] [pid 643253:tid 643414] [client 103.215.74.26:34864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDSMjqbtjBYzqM1uYsAAAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:57.286675 2026] [security2:error] [pid 642360:tid 642572] [client 20.215.191.139:40901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuDSZSUkh3e5AhEJOCJYQAAAeE"]
[Thu Jul 30 12:00:57.510771 2026] [security2:error] [pid 643253:tid 643452] [client 191.232.199.39:58852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/file4.php"] [unique_id "amuDScjqbtjBYzqM1uYsBQAAAEQ"]
[Thu Jul 30 12:00:57.604774 2026] [security2:error] [pid 642360:tid 642544] [client 51.68.111.240:34593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amuDSZSUkh3e5AhEJOCJegAAAcU"]
[Thu Jul 30 12:00:57.604961 2026] [security2:error] [pid 642360:tid 642544] [client 51.68.111.240:34593] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amuDSZSUkh3e5AhEJOCJegAAAcU"]
[Thu Jul 30 12:00:57.715815 2026] [core:notice] [pid 642360:tid 642509] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:00:57.720230 2026] [security2:error] [pid 642360:tid 642509] [client 103.215.74.26:34872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDSZSUkh3e5AhEJOCJewAAAaI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:00:57.722611 2026] [security2:error] [pid 642360:tid 642385] [remote 57.141.0.71:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/491057609/feed/rss2/"] [unique_id "amuDSZSUkh3e5AhEJOCJfAABlRg"]
[Thu Jul 30 12:00:58.107465 2026] [security2:error] [pid 643253:tid 643483] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuDSMjqbtjBYzqM1uYr_wAAYx8"]
[Thu Jul 30 12:00:58.322114 2026] [security2:error] [pid 643253:tid 643442] [client 172.237.109.114:60471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDScjqbtjBYzqM1uYsAQAAADo"]
[Thu Jul 30 12:00:58.422185 2026] [security2:error] [pid 643253:tid 643418] [client 172.237.109.114:61223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDScjqbtjBYzqM1uYsAgAAACI"]
[Thu Jul 30 12:00:58.455209 2026] [security2:error] [pid 642360:tid 642534] [client 172.237.109.114:1575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJbQAAAbs"]
[Thu Jul 30 12:00:58.458096 2026] [security2:error] [pid 642360:tid 642580] [client 172.237.109.114:20232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJaAAAAek"]
[Thu Jul 30 12:00:58.472353 2026] [security2:error] [pid 642360:tid 642514] [client 172.237.109.114:59009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJZgAAAac"]
[Thu Jul 30 12:00:58.475235 2026] [security2:error] [pid 642360:tid 642499] [client 172.237.109.114:55705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJZwAAAZg"]
[Thu Jul 30 12:00:58.477971 2026] [security2:error] [pid 642360:tid 642561] [client 172.237.109.114:9397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJZQAAAdY"]
[Thu Jul 30 12:00:58.485138 2026] [security2:error] [pid 643253:tid 643502] [client 172.237.109.114:63315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDScjqbtjBYzqM1uYsAwAAAHY"]
[Thu Jul 30 12:00:58.488724 2026] [security2:error] [pid 642360:tid 642521] [client 172.237.109.114:60207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJagAAAa4"]
[Thu Jul 30 12:00:58.493100 2026] [security2:error] [pid 642360:tid 642609] [client 172.237.109.114:60984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJaQAAAgY"]
[Thu Jul 30 12:00:58.501499 2026] [security2:error] [pid 642360:tid 642551] [client 172.237.109.114:55185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJawAAAcw"]
[Thu Jul 30 12:00:58.505275 2026] [security2:error] [pid 642360:tid 642516] [client 172.237.109.114:59288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJbgAAAak"]
[Thu Jul 30 12:00:58.519641 2026] [security2:error] [pid 642360:tid 642578] [client 172.237.109.114:16753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJbAAAAec"]
[Thu Jul 30 12:00:58.530405 2026] [security2:error] [pid 642360:tid 642491] [client 172.237.109.114:28937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSZSUkh3e5AhEJOCJbwAAAZA"]
[Thu Jul 30 12:00:58.551115 2026] [security2:error] [pid 643253:tid 643478] [client 172.237.109.114:31203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDScjqbtjBYzqM1uYsBAAAAF4"]
[Thu Jul 30 12:00:59.047203 2026] [security2:error] [pid 642360:tid 642543] [client 191.232.199.39:39774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/flower.php"] [unique_id "amuDS5SUkh3e5AhEJOCJlwAAAcQ"]
[Thu Jul 30 12:00:59.486589 2026] [security2:error] [pid 643253:tid 643388] [client 172.237.109.114:26199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSsjqbtjBYzqM1uYsDAAAAAQ"]
[Thu Jul 30 12:00:59.521035 2026] [security2:error] [pid 642360:tid 642587] [client 172.237.109.114:29651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSpSUkh3e5AhEJOCJiAAAAfA"]
[Thu Jul 30 12:01:00.037468 2026] [security2:error] [pid 642360:tid 642522] [client 20.91.199.21:53490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/database.php"] [unique_id "amuDTJSUkh3e5AhEJOCJrQAAAa8"]
[Thu Jul 30 12:01:00.216335 2026] [security2:error] [pid 642360:tid 642612] [client 172.237.109.114:52925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSpSUkh3e5AhEJOCJhwAAAgk"]
[Thu Jul 30 12:01:00.242645 2026] [security2:error] [pid 642360:tid 642613] [client 172.237.109.114:18506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSpSUkh3e5AhEJOCJjQAAAgo"]
[Thu Jul 30 12:01:00.248274 2026] [security2:error] [pid 642360:tid 642531] [client 172.237.109.114:50569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSpSUkh3e5AhEJOCJiQAAAbg"]
[Thu Jul 30 12:01:00.388811 2026] [security2:error] [pid 642360:tid 642610] [client 191.232.199.39:6465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/form.php"] [unique_id "amuDTJSUkh3e5AhEJOCJsgAAAgc"]
[Thu Jul 30 12:01:00.458370 2026] [security2:error] [pid 643253:tid 643408] [client 172.237.109.114:26178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDSsjqbtjBYzqM1uYsDQAAABg"]
[Thu Jul 30 12:01:00.662286 2026] [proxy:error] [pid 642360:tid 642583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:00.662379 2026] [proxy_http:error] [pid 642360:tid 642583] [client 193.47.62.167:54384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:00.663123 2026] [proxy:error] [pid 642360:tid 642583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:00.663169 2026] [proxy_http:error] [pid 642360:tid 642583] [client 193.47.62.167:54384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:00.847251 2026] [security2:error] [pid 642360:tid 642575] [client 20.91.199.21:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/db.php"] [unique_id "amuDTJSUkh3e5AhEJOCJtgAAAeQ"]
[Thu Jul 30 12:01:01.228819 2026] [security2:error] [pid 642360:tid 642524] [client 172.237.109.114:18918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJowAAAbE"]
[Thu Jul 30 12:01:01.233733 2026] [security2:error] [pid 642360:tid 642490] [client 172.237.109.114:20191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJpAAAAY8"]
[Thu Jul 30 12:01:01.240731 2026] [security2:error] [pid 643253:tid 643434] [client 172.237.109.114:30773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsEgAAADI"]
[Thu Jul 30 12:01:01.251432 2026] [security2:error] [pid 642360:tid 642536] [client 172.237.109.114:1997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJngAAAb0"]
[Thu Jul 30 12:01:01.255792 2026] [security2:error] [pid 642360:tid 642589] [client 172.237.109.114:3642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJnAAAAfI"]
[Thu Jul 30 12:01:01.287613 2026] [security2:error] [pid 642360:tid 642504] [client 172.237.109.114:39802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJmgAAAZ0"]
[Thu Jul 30 12:01:01.320019 2026] [security2:error] [pid 643253:tid 643421] [client 172.237.109.114:14989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsFAAAACU"]
[Thu Jul 30 12:01:01.322625 2026] [security2:error] [pid 642360:tid 642569] [client 172.237.109.114:37806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJnwAAAd4"]
[Thu Jul 30 12:01:01.330744 2026] [security2:error] [pid 642360:tid 642519] [client 172.237.109.114:54018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJmAAAAaw"]
[Thu Jul 30 12:01:01.338607 2026] [security2:error] [pid 643253:tid 643476] [client 172.237.109.114:59932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsEQAAAFw"]
[Thu Jul 30 12:01:01.342661 2026] [security2:error] [pid 642360:tid 642564] [client 172.237.109.114:6162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJmQAAAdk"]
[Thu Jul 30 12:01:01.343942 2026] [security2:error] [pid 642360:tid 642503] [client 172.237.109.114:26225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJogAAAZw"]
[Thu Jul 30 12:01:01.346682 2026] [security2:error] [pid 642360:tid 642606] [client 172.237.109.114:10011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJmwAAAgM"]
[Thu Jul 30 12:01:01.354584 2026] [security2:error] [pid 642360:tid 642495] [client 172.237.109.114:25245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJnQAAAZQ"]
[Thu Jul 30 12:01:01.370263 2026] [security2:error] [pid 643253:tid 643472] [client 172.237.109.114:40796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsEAAAAFg"]
[Thu Jul 30 12:01:01.416242 2026] [security2:error] [pid 643253:tid 643509] [client 172.237.109.114:39027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsFQAAAH0"]
[Thu Jul 30 12:01:01.432505 2026] [security2:error] [pid 642360:tid 642546] [client 176.241.66.87:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDTZSUkh3e5AhEJOCJvgAAAcc"]
[Thu Jul 30 12:01:01.432644 2026] [security2:error] [pid 642360:tid 642546] [client 176.241.66.87:53643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDTZSUkh3e5AhEJOCJvgAAAcc"]
[Thu Jul 30 12:01:01.439939 2026] [security2:error] [pid 643253:tid 643443] [client 172.237.109.114:28122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS8jqbtjBYzqM1uYsFgAAADs"]
[Thu Jul 30 12:01:01.467599 2026] [security2:error] [pid 642360:tid 642501] [client 172.237.109.114:25859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDS5SUkh3e5AhEJOCJpQAAAZo"]
[Thu Jul 30 12:01:01.861155 2026] [security2:error] [pid 642360:tid 642596] [client 191.232.199.39:58943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/gecko.php"] [unique_id "amuDTZSUkh3e5AhEJOCJxgAAAfk"]
[Thu Jul 30 12:01:01.887951 2026] [security2:error] [pid 642360:tid 642532] [client 20.91.199.21:53491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/default.php"] [unique_id "amuDTZSUkh3e5AhEJOCJxwAAAbk"]
[Thu Jul 30 12:01:01.983702 2026] [core:notice] [pid 643253:tid 643293] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:02.467958 2026] [security2:error] [pid 643253:tid 643429] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDTcjqbtjBYzqM1uYsJAAALRI"]
[Thu Jul 30 12:01:02.637877 2026] [security2:error] [pid 643253:tid 643423] [client 114.119.132.238:32793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product/black-devil-3/"] [unique_id "amuDTsjqbtjBYzqM1uYsKAAAACc"], referer: https://online-hope.com/
[Thu Jul 30 12:01:02.711641 2026] [proxy:error] [pid 642360:tid 642537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:02.711695 2026] [proxy_http:error] [pid 642360:tid 642537] [client 3.228.112.215:5655] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:02.712253 2026] [proxy:error] [pid 642360:tid 642537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:02.712305 2026] [proxy_http:error] [pid 642360:tid 642537] [client 3.228.112.215:5655] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:02.814771 2026] [security2:error] [pid 642360:tid 642509] [client 114.119.162.251:46277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/product-reviews/B0DG4WZZPV/ref=acr_dp_hist_2"] [unique_id "amuDTpSUkh3e5AhEJOCJ1wAAAaI"], referer: http://www.bedandbreakfast-skye.com/
[Thu Jul 30 12:01:02.822226 2026] [security2:error] [pid 642360:tid 642531] [client 20.91.199.21:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/dropdown.php"] [unique_id "amuDTpSUkh3e5AhEJOCJ2QAAAbg"]
[Thu Jul 30 12:01:03.300304 2026] [security2:error] [pid 642360:tid 642552] [client 191.232.199.39:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/kyami.php"] [unique_id "amuDT5SUkh3e5AhEJOCJ6QAAAc0"]
[Thu Jul 30 12:01:03.581011 2026] [core:notice] [pid 642360:tid 642561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:03.585241 2026] [security2:error] [pid 642360:tid 642561] [client 103.215.74.26:21886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDT5SUkh3e5AhEJOCJ8wAAAdY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:03.631886 2026] [security2:error] [pid 642360:tid 642516] [client 20.91.199.21:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/edit.php"] [unique_id "amuDT5SUkh3e5AhEJOCJ9QAAAak"]
[Thu Jul 30 12:01:04.199018 2026] [security2:error] [pid 642360:tid 642528] [client 20.91.199.21:49913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/f35.php"] [unique_id "amuDUJSUkh3e5AhEJOCJ_QAAAbU"]
[Thu Jul 30 12:01:04.418015 2026] [security2:error] [pid 642360:tid 642605] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDT5SUkh3e5AhEJOCJ9wAAAgI"]
[Thu Jul 30 12:01:04.994609 2026] [security2:error] [pid 642360:tid 642597] [client 191.232.199.39:60599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/manager.php"] [unique_id "amuDUJSUkh3e5AhEJOCKCgAAAfo"]
[Thu Jul 30 12:01:05.334656 2026] [security2:error] [pid 643253:tid 643488] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDUMjqbtjBYzqM1uYsMQAAaCw"]
[Thu Jul 30 12:01:05.818541 2026] [security2:error] [pid 642360:tid 642408] [remote 57.141.0.5:37470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amuDUZSUkh3e5AhEJOCKFAABki8"]
[Thu Jul 30 12:01:06.243956 2026] [security2:error] [pid 642360:tid 642614] [client 191.232.199.39:60545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mari.php"] [unique_id "amuDUpSUkh3e5AhEJOCKHgAAAgs"]
[Thu Jul 30 12:01:06.475218 2026] [security2:error] [pid 642360:tid 642601] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDUZSUkh3e5AhEJOCKGQAB_kw"]
[Thu Jul 30 12:01:06.742836 2026] [security2:error] [pid 643253:tid 643298] [remote 74.7.241.59:47970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuDUsjqbtjBYzqM1uYsNQAAcSs"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:01:06.970863 2026] [security2:error] [pid 643253:tid 643307] [remote 57.141.0.41:31138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuDUsjqbtjBYzqM1uYsNwAACTQ"]
[Thu Jul 30 12:01:07.519459 2026] [security2:error] [pid 643253:tid 643430] [client 20.91.199.21:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/f7.php"] [unique_id "amuDU8jqbtjBYzqM1uYsOQAAAC4"]
[Thu Jul 30 12:01:07.619506 2026] [security2:error] [pid 643253:tid 643424] [client 178.20.45.128:60455] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.45.128" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuDU8jqbtjBYzqM1uYsOwAAACg"], referer: https://deltaedu.net/2016/11/04/university-scholarship-2017/#comment-25
[Thu Jul 30 12:01:07.619610 2026] [security2:error] [pid 643253:tid 643424] [client 178.20.45.128:60455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuDU8jqbtjBYzqM1uYsOwAAACg"], referer: https://deltaedu.net/2016/11/04/university-scholarship-2017/#comment-25
[Thu Jul 30 12:01:07.887697 2026] [security2:error] [pid 642360:tid 642510] [client 191.232.199.39:6473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/nc4.php"] [unique_id "amuDU5SUkh3e5AhEJOCKQAAAAaM"]
[Thu Jul 30 12:01:07.944037 2026] [security2:error] [pid 643253:tid 643501] [client 127.0.0.1:36914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuDU8jqbtjBYzqM1uYsPgAAAHU"]
[Thu Jul 30 12:01:07.944050 2026] [security2:error] [pid 642360:tid 642550] [client 127.0.0.1:36904] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ssm.njr.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuDU5SUkh3e5AhEJOCKQgAAAcs"]
[Thu Jul 30 12:01:07.944217 2026] [security2:error] [pid 642360:tid 642506] [client 74.7.228.11:57860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ssm.njr.temporary.site"] [uri "/robots.txt"] [unique_id "amuDU5SUkh3e5AhEJOCKQQABn0g"]
[Thu Jul 30 12:01:08.012752 2026] [security2:error] [pid 642360:tid 642507] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDU5SUkh3e5AhEJOCKNQAAAaA"]
[Thu Jul 30 12:01:08.498418 2026] [security2:error] [pid 643253:tid 643494] [client 172.202.44.182:45093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/gecko.php"] [unique_id "amuDVMjqbtjBYzqM1uYsQQAAAG4"]
[Thu Jul 30 12:01:09.254614 2026] [cgid:error] [pid 642360:tid 642519] [client 191.232.199.39:0] AH01265: stderr from /home1/ssadjbte/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:01:09.297543 2026] [core:notice] [pid 642360:tid 642609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:09.301825 2026] [security2:error] [pid 642360:tid 642609] [client 103.215.74.26:21898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDVZSUkh3e5AhEJOCKWwAAAgY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:10.029393 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:10.033750 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:21904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDVsjqbtjBYzqM1uYsTwAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:10.425781 2026] [security2:error] [pid 642360:tid 642528] [client 172.202.44.182:45066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/kyami.php"] [unique_id "amuDVpSUkh3e5AhEJOCKbAAAAbU"]
[Thu Jul 30 12:01:10.770033 2026] [core:notice] [pid 642360:tid 642513] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:10.774382 2026] [security2:error] [pid 642360:tid 642513] [client 103.215.74.26:21912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDVpSUkh3e5AhEJOCKbgAAAaY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:12.129229 2026] [security2:error] [pid 642360:tid 642555] [client 172.202.44.182:50557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/manager.php"] [unique_id "amuDWJSUkh3e5AhEJOCKgQAAAdA"]
[Thu Jul 30 12:01:12.448178 2026] [security2:error] [pid 642360:tid 642493] [client 176.241.66.87:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDWJSUkh3e5AhEJOCKiAAAAZI"]
[Thu Jul 30 12:01:12.448342 2026] [security2:error] [pid 642360:tid 642493] [client 176.241.66.87:50730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDWJSUkh3e5AhEJOCKiAAAAZI"]
[Thu Jul 30 12:01:12.985366 2026] [security2:error] [pid 642360:tid 642514] [client 47.128.112.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "club4.au"] [uri "/index.php"] [unique_id "amuDVZSUkh3e5AhEJOCKUwAAAac"]
[Thu Jul 30 12:01:13.347240 2026] [security2:error] [pid 643253:tid 643509] [client 172.202.44.182:39197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/mari.php"] [unique_id "amuDWcjqbtjBYzqM1uYsWgAAAH0"]
[Thu Jul 30 12:01:15.345783 2026] [security2:error] [pid 642360:tid 642568] [client 74.7.175.152:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuDWpSUkh3e5AhEJOCKsQAAAd0"]
[Thu Jul 30 12:01:15.346561 2026] [security2:error] [pid 642360:tid 642579] [client 74.7.175.152:60030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "kool-shop.com"] [uri "/robots.txt"] [unique_id "amuDWpSUkh3e5AhEJOCKrwAB6FI"]
[Thu Jul 30 12:01:15.547064 2026] [security2:error] [pid 643253:tid 643444] [client 172.202.44.182:50541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bonafideadvisors.com"] [uri "/nc4.php"] [unique_id "amuDW8jqbtjBYzqM1uYsXgAAADw"]
[Thu Jul 30 12:01:16.493719 2026] [core:notice] [pid 642360:tid 642510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:16.498107 2026] [security2:error] [pid 642360:tid 642510] [client 103.215.74.26:64558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDXJSUkh3e5AhEJOCK0wAAAaM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:17.197938 2026] [core:notice] [pid 642360:tid 642476] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:17.228619 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:17.234207 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:64562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDXcjqbtjBYzqM1uYsYAAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:17.958454 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:17.962497 2026] [security2:error] [pid 642360:tid 642551] [client 103.215.74.26:64564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDXZSUkh3e5AhEJOCK6wAAAcw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:18.089637 2026] [proxy:error] [pid 642360:tid 642583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:18.089723 2026] [proxy_http:error] [pid 642360:tid 642583] [client 172.202.44.182:50497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:18.090398 2026] [proxy:error] [pid 642360:tid 642583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:18.090447 2026] [proxy_http:error] [pid 642360:tid 642583] [client 172.202.44.182:50497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:18.685842 2026] [security2:error] [pid 642360:tid 642613] [client 85.208.96.202:49420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/13/hospital-de-clinicas-inicia-consultas-para-cirurgias-ortopedicas-pelo-opera-paraiba/"] [unique_id "amuDXpSUkh3e5AhEJOCK8gAAAgo"]
[Thu Jul 30 12:01:18.685966 2026] [security2:error] [pid 642360:tid 642613] [client 85.208.96.202:49420] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/13/hospital-de-clinicas-inicia-consultas-para-cirurgias-ortopedicas-pelo-opera-paraiba/"] [unique_id "amuDXpSUkh3e5AhEJOCK8gAAAgo"]
[Thu Jul 30 12:01:18.728217 2026] [core:notice] [pid 642360:tid 642582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:18.732082 2026] [security2:error] [pid 642360:tid 642582] [client 103.215.74.26:64578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDXpSUkh3e5AhEJOCK9gAAAes"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:19.505402 2026] [core:notice] [pid 642360:tid 642493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:19.509446 2026] [security2:error] [pid 642360:tid 642493] [client 103.215.74.26:64582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDX5SUkh3e5AhEJOCLAAAAAZI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:19.653658 2026] [security2:error] [pid 643253:tid 643318] [remote 57.141.0.63:47622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/PBB/article/view/7396"] [unique_id "amuDX8jqbtjBYzqM1uYsaAAAeT8"]
[Thu Jul 30 12:01:19.827084 2026] [security2:error] [pid 642360:tid 642609] [client 20.215.191.139:50817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/json.php"] [unique_id "amuDX5SUkh3e5AhEJOCLBQAAAgY"]
[Thu Jul 30 12:01:19.873747 2026] [security2:error] [pid 642360:tid 642506] [client 74.7.228.30:36518] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.tereasshop.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuDX5SUkh3e5AhEJOCLBgAAAZ8"]
[Thu Jul 30 12:01:20.224055 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:20.228602 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:64594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDYMjqbtjBYzqM1uYsagAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:20.528947 2026] [security2:error] [pid 642360:tid 642532] [client 20.215.191.139:51416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/mini.php"] [unique_id "amuDYJSUkh3e5AhEJOCLDQAAAbk"]
[Thu Jul 30 12:01:20.950492 2026] [core:notice] [pid 642360:tid 642537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:20.961188 2026] [security2:error] [pid 642360:tid 642537] [client 103.215.74.26:64608] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDYJSUkh3e5AhEJOCLEQAAAb4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:21.011126 2026] [core:notice] [pid 642360:tid 642549] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:21.129233 2026] [security2:error] [pid 642360:tid 642528] [client 20.215.191.139:50824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/chosen.php"] [unique_id "amuDYZSUkh3e5AhEJOCLFwAAAbU"]
[Thu Jul 30 12:01:21.211547 2026] [security2:error] [pid 642360:tid 642558] [client 54.223.173.193:61920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jesus.claims"] [uri "/index.php"] [unique_id "amuDYZSUkh3e5AhEJOCLFgAAAdM"]
[Thu Jul 30 12:01:21.686511 2026] [core:notice] [pid 642360:tid 642565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:21.693278 2026] [security2:error] [pid 642360:tid 642565] [client 103.215.74.26:64610] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDYZSUkh3e5AhEJOCLHQAAAdo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:22.092317 2026] [security2:error] [pid 642360:tid 642547] [client 114.119.137.160:29635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/product/black-devil%e9%bb%91%e9%ad%94%e9%ac%bc%e8%96%84%e8%8d%b7%e9%a6%99%e7%85%9910mg%e6%97%a5%e6%9c%ac%e6%9c%ac%e5%9c%9f%e5%85%8d%e7%a8%85%e9%a6%99%e6%b8%af%e7%8f%be%e8%b2%a8/"] [unique_id "amuDYpSUkh3e5AhEJOCLJAAAAcg"], referer: https://lark-shop.com/product/black-devil%E9%BB%91%E9%AD%94%E9%AC%BC%E6%9C%B1%E5%8F%A4%E5%8A%9B%E9%A6%99%E7%85%9910mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/
[Thu Jul 30 12:01:22.261197 2026] [security2:error] [pid 642360:tid 642499] [client 20.215.191.139:50842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/kj.php"] [unique_id "amuDYpSUkh3e5AhEJOCLJQAAAZg"]
[Thu Jul 30 12:01:22.448091 2026] [core:notice] [pid 642360:tid 642491] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:22.452065 2026] [security2:error] [pid 642360:tid 642491] [client 103.215.74.26:64622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDYpSUkh3e5AhEJOCLKQAAAZA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:22.855890 2026] [security2:error] [pid 642360:tid 642561] [client 20.215.191.139:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-files.php"] [unique_id "amuDYpSUkh3e5AhEJOCLLgAAAdY"]
[Thu Jul 30 12:01:23.106134 2026] [security2:error] [pid 642360:tid 642591] [client 114.119.145.102:23895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/leatherflower/darkmans53852.html"] [unique_id "amuDY5SUkh3e5AhEJOCLNAAAAfQ"], referer: https://www.shorewooddaycare.com/leatherflower/darkmans53852.html
[Thu Jul 30 12:01:23.445379 2026] [security2:error] [pid 643253:tid 643384] [client 176.241.66.87:55724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDY8jqbtjBYzqM1uYscwAAAAA"]
[Thu Jul 30 12:01:23.445565 2026] [security2:error] [pid 643253:tid 643384] [client 176.241.66.87:55724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDY8jqbtjBYzqM1uYscwAAAAA"]
[Thu Jul 30 12:01:23.515263 2026] [proxy:error] [pid 642360:tid 642543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:23.515352 2026] [proxy_http:error] [pid 642360:tid 642543] [client 18.211.55.47:22774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:23.515896 2026] [proxy:error] [pid 642360:tid 642543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:23.515938 2026] [proxy_http:error] [pid 642360:tid 642543] [client 18.211.55.47:22774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:24.535374 2026] [core:error] [pid 642360:tid 642386] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:24.535403 2026] [core:error] [pid 642360:tid 642386] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:24.777921 2026] [security2:error] [pid 642360:tid 642605] [client 20.215.191.139:51413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-setup.php"] [unique_id "amuDZJSUkh3e5AhEJOCLTgAAAgI"]
[Thu Jul 30 12:01:24.939665 2026] [security2:error] [pid 642360:tid 642522] [client 114.119.143.77:50733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/missiles"] [unique_id "amuDZJSUkh3e5AhEJOCLTwAAAa8"], referer: https://fireworkskenya.co.ke/our-products/consumer-fireworks/big-display-cakes/hangoverator-z2093-square-cake-36-shots
[Thu Jul 30 12:01:25.384802 2026] [security2:error] [pid 643253:tid 643396] [client 20.215.191.139:50839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/defaults.php"] [unique_id "amuDZcjqbtjBYzqM1uYseAAAAAw"]
[Thu Jul 30 12:01:25.395073 2026] [core:error] [pid 642360:tid 642480] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:25.395091 2026] [core:error] [pid 642360:tid 642480] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:25.747818 2026] [proxy:error] [pid 642360:tid 642535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:25.747901 2026] [proxy_http:error] [pid 642360:tid 642535] [client 98.87.102.177:32111] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:25.748485 2026] [proxy:error] [pid 642360:tid 642535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:25.748534 2026] [proxy_http:error] [pid 642360:tid 642535] [client 98.87.102.177:32111] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:25.841842 2026] [security2:error] [pid 643253:tid 643414] [client 114.119.130.26:42489] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cnpinyin.com"] [uri "/study/Chinese-grammar/%E6%9C%89%E7%82%B9%2Bor%2B%E6%9C%89%E4%B8%80%E7%82%B9%2B"] [unique_id "amuDZcjqbtjBYzqM1uYsegAAAB4"], referer: http://cnpinyin.com/study/chinese-grammar/page/21
[Thu Jul 30 12:01:26.166102 2026] [security2:error] [pid 643253:tid 643424] [client 20.215.191.139:50852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/gtc.php"] [unique_id "amuDZsjqbtjBYzqM1uYsfAAAACg"]
[Thu Jul 30 12:01:26.688881 2026] [proxy:error] [pid 642360:tid 642402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:26.688942 2026] [proxy_http:error] [pid 642360:tid 642402] [remote 74.7.244.14:35588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:26.689727 2026] [proxy:error] [pid 642360:tid 642402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:01:26.689781 2026] [proxy_http:error] [pid 642360:tid 642402] [remote 74.7.244.14:35588] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:01:26.799637 2026] [security2:error] [pid 642360:tid 642556] [client 20.215.191.139:50822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/import.php"] [unique_id "amuDZpSUkh3e5AhEJOCLcgAAAdE"]
[Thu Jul 30 12:01:27.565383 2026] [security2:error] [pid 643253:tid 643418] [client 20.215.191.139:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/lufix.php"] [unique_id "amuDZ8jqbtjBYzqM1uYsggAAACI"]
[Thu Jul 30 12:01:27.913918 2026] [security2:error] [pid 642360:tid 642603] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDZZSUkh3e5AhEJOCLYwAAAgA"]
[Thu Jul 30 12:01:28.214270 2026] [security2:error] [pid 642360:tid 642557] [client 123.1.209.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuDZ5SUkh3e5AhEJOCLhgAAAdI"]
[Thu Jul 30 12:01:28.231438 2026] [core:notice] [pid 642360:tid 642504] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:28.238269 2026] [security2:error] [pid 642360:tid 642504] [client 103.215.74.26:25186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDaJSUkh3e5AhEJOCLjwAAAZ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:28.610063 2026] [security2:error] [pid 643253:tid 643478] [client 123.1.209.245:50282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuDZ8jqbtjBYzqM1uYshQAAXkI"]
[Thu Jul 30 12:01:28.610398 2026] [security2:error] [pid 643253:tid 643320] [remote 123.1.209.245:50282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuDZ8jqbtjBYzqM1uYshAAAXkE"]
[Thu Jul 30 12:01:28.982228 2026] [core:notice] [pid 642360:tid 642529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:28.988995 2026] [security2:error] [pid 642360:tid 642529] [client 103.215.74.26:25200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDaJSUkh3e5AhEJOCLpQAAAbY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:29.173648 2026] [fcgid:warn] [pid 642360:tid 642513] (70014)End of file found: [client 167.94.146.61:3922] mod_fcgid: can't get data from http client
[Thu Jul 30 12:01:29.295540 2026] [autoindex:error] [pid 642360:tid 642510] [client 18.211.55.47:5075] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:01:29.571751 2026] [security2:error] [pid 642360:tid 642499] [client 114.119.130.248:38017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/events/retreat-dates/eventsbyday/2026/5/16/-"] [unique_id "amuDaZSUkh3e5AhEJOCLsgAAAZg"], referer: https://www.hmhs.ph/events/retreat-dates/monthcalendar/2026/5/-
[Thu Jul 30 12:01:29.723160 2026] [core:notice] [pid 642360:tid 642532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:29.727158 2026] [security2:error] [pid 642360:tid 642532] [client 103.215.74.26:25232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDaZSUkh3e5AhEJOCLswAAAbk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:30.444251 2026] [core:notice] [pid 643253:tid 643440] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:30.448487 2026] [security2:error] [pid 643253:tid 643440] [client 103.215.74.26:25238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDasjqbtjBYzqM1uYsowAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:31.185468 2026] [core:notice] [pid 642360:tid 642559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:31.189345 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:25272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDa5SUkh3e5AhEJOCL0wAAAdQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:31.926098 2026] [core:notice] [pid 642360:tid 642548] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:31.929841 2026] [security2:error] [pid 642360:tid 642548] [client 103.215.74.26:25278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDa5SUkh3e5AhEJOCL4gAAAck"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:32.568993 2026] [security2:error] [pid 642360:tid 642511] [client 20.215.191.139:50858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/Geforce.php"] [unique_id "amuDbJSUkh3e5AhEJOCL_AAAAaQ"]
[Thu Jul 30 12:01:32.719103 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:32.723505 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:25316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDbJSUkh3e5AhEJOCL_gAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:33.395029 2026] [security2:error] [pid 642360:tid 642615] [client 20.215.191.139:50866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/a4.php"] [unique_id "amuDbZSUkh3e5AhEJOCMDgAAAgw"]
[Thu Jul 30 12:01:33.477862 2026] [core:notice] [pid 643253:tid 643401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:33.482040 2026] [security2:error] [pid 643253:tid 643401] [client 103.215.74.26:34056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDbcjqbtjBYzqM1uYtCAAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:34.209169 2026] [core:notice] [pid 642360:tid 642549] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:34.213132 2026] [security2:error] [pid 642360:tid 642549] [client 103.215.74.26:34070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDbpSUkh3e5AhEJOCMIAAAAco"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:34.373346 2026] [security2:error] [pid 642360:tid 642608] [client 176.241.66.87:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDbpSUkh3e5AhEJOCMIQAAAgU"]
[Thu Jul 30 12:01:34.373499 2026] [security2:error] [pid 642360:tid 642608] [client 176.241.66.87:56772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDbpSUkh3e5AhEJOCMIQAAAgU"]
[Thu Jul 30 12:01:34.521072 2026] [security2:error] [pid 642360:tid 642515] [client 20.215.191.139:50857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/accueil.php"] [unique_id "amuDbpSUkh3e5AhEJOCMJAAAAag"]
[Thu Jul 30 12:01:34.948951 2026] [core:notice] [pid 642360:tid 642570] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:34.953503 2026] [security2:error] [pid 642360:tid 642570] [client 103.215.74.26:34086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDbpSUkh3e5AhEJOCMLgAAAd8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:34.988888 2026] [security2:error] [pid 642360:tid 642560] [client 114.119.151.192:51973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dhowcruisedinner.com"] [uri "/new-year-party-canal.html"] [unique_id "amuDbpSUkh3e5AhEJOCMMwAAAdU"]
[Thu Jul 30 12:01:35.108421 2026] [security2:error] [pid 642360:tid 642525] [client 74.7.228.21:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vvr.hfl.temporary.site"] [uri "/index.php"] [unique_id "amuDbpSUkh3e5AhEJOCMLQAAAbI"]
[Thu Jul 30 12:01:35.109272 2026] [security2:error] [pid 642360:tid 642593] [client 74.7.228.21:58914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vvr.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuDbpSUkh3e5AhEJOCMKwAB9lk"]
[Thu Jul 30 12:01:35.276159 2026] [security2:error] [pid 642360:tid 642568] [client 20.215.191.139:50859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/dashboard.php"] [unique_id "amuDb5SUkh3e5AhEJOCMPQAAAd0"]
[Thu Jul 30 12:01:35.397991 2026] [security2:error] [pid 642360:tid 642536] [client 158.181.41.199:3672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuDb5SUkh3e5AhEJOCMNwAAAb0"]
[Thu Jul 30 12:01:35.710551 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:35.715911 2026] [security2:error] [pid 643253:tid 643441] [client 103.215.74.26:34100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDb8jqbtjBYzqM1uYtEAAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:36.452335 2026] [core:notice] [pid 642360:tid 642553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:36.456867 2026] [security2:error] [pid 642360:tid 642553] [client 103.215.74.26:34112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDcJSUkh3e5AhEJOCMUAAAAc4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:36.990739 2026] [security2:error] [pid 642360:tid 642609] [client 20.215.191.139:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/radio.php"] [unique_id "amuDcJSUkh3e5AhEJOCMWwAAAgY"]
[Thu Jul 30 12:01:37.205273 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:37.209636 2026] [security2:error] [pid 642360:tid 642533] [client 103.215.74.26:34122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDcZSUkh3e5AhEJOCMXwAAAbo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:37.378372 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuDccjqbtjBYzqM1uYtFwAAAAI"]
[Thu Jul 30 12:01:37.379743 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuDccjqbtjBYzqM1uYtFwAAAAI"]
[Thu Jul 30 12:01:37.934035 2026] [core:notice] [pid 642360:tid 642504] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:37.937253 2026] [security2:error] [pid 642360:tid 642535] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuDcZSUkh3e5AhEJOCMbgAAAbw"]
[Thu Jul 30 12:01:37.937371 2026] [security2:error] [pid 642360:tid 642535] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuDcZSUkh3e5AhEJOCMbgAAAbw"]
[Thu Jul 30 12:01:37.938476 2026] [security2:error] [pid 642360:tid 642504] [client 103.215.74.26:34130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDcZSUkh3e5AhEJOCMbQAAAZ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:38.064060 2026] [security2:error] [pid 642360:tid 642617] [client 74.7.244.22:53388] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/robots.txt"] [unique_id "amuDcpSUkh3e5AhEJOCMcAACDmE"]
[Thu Jul 30 12:01:38.480890 2026] [security2:error] [pid 642360:tid 642584] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wicked.php"] [unique_id "amuDcpSUkh3e5AhEJOCMeAAAAe0"]
[Thu Jul 30 12:01:38.481070 2026] [security2:error] [pid 642360:tid 642584] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wicked.php"] [unique_id "amuDcpSUkh3e5AhEJOCMeAAAAe0"]
[Thu Jul 30 12:01:38.659028 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:38.663455 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:34138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDcsjqbtjBYzqM1uYtIAAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:38.987849 2026] [security2:error] [pid 642360:tid 642510] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wpx.php"] [unique_id "amuDcpSUkh3e5AhEJOCMgQAAAaM"]
[Thu Jul 30 12:01:38.987994 2026] [security2:error] [pid 642360:tid 642510] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wpx.php"] [unique_id "amuDcpSUkh3e5AhEJOCMgQAAAaM"]
[Thu Jul 30 12:01:39.160397 2026] [security2:error] [pid 643253:tid 643387] [client 20.215.191.139:50832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wpsml-sys.php"] [unique_id "amuDc8jqbtjBYzqM1uYtIwAAAAM"]
[Thu Jul 30 12:01:39.351691 2026] [security2:error] [pid 642360:tid 642607] [client 43.173.174.152:42374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/11/16/sacs-a-main-en-cuir-automne-2015/"] [unique_id "amuDc5SUkh3e5AhEJOCMhQAAAgQ"]
[Thu Jul 30 12:01:39.388313 2026] [core:notice] [pid 642360:tid 642543] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:39.392688 2026] [security2:error] [pid 642360:tid 642543] [client 103.215.74.26:34142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDc5SUkh3e5AhEJOCMiwAAAcQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:39.529074 2026] [security2:error] [pid 642360:tid 642520] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/images.php"] [unique_id "amuDc5SUkh3e5AhEJOCMjwAAAa0"]
[Thu Jul 30 12:01:39.529163 2026] [security2:error] [pid 642360:tid 642520] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/images.php"] [unique_id "amuDc5SUkh3e5AhEJOCMjwAAAa0"]
[Thu Jul 30 12:01:39.561001 2026] [core:notice] [pid 642360:tid 642499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:39.565701 2026] [security2:error] [pid 642360:tid 642499] [client 43.172.195.84:60838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/11/16/sacs-a-main-en-cuir-automne-2015/"] [unique_id "amuDc5SUkh3e5AhEJOCMkQAAAZg"], referer: https://carnetdeshopping.com/index.php/2015/11/16/sacs-a-main-en-cuir-automne-2015/
[Thu Jul 30 12:01:39.614149 2026] [security2:error] [pid 642360:tid 642542] [client 43.173.174.75:50564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/07/01/alternative-fragrance-beauty-2016/"] [unique_id "amuDc5SUkh3e5AhEJOCMhwAAAcM"]
[Thu Jul 30 12:01:39.619134 2026] [security2:error] [pid 642360:tid 642553] [client 43.172.194.163:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/11/09/lenseigne-espagnole-suiteblanco-lance-son-eshop-en-france/"] [unique_id "amuDc5SUkh3e5AhEJOCMhgAAAc4"]
[Thu Jul 30 12:01:40.052700 2026] [core:notice] [pid 642360:tid 642533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:40.057482 2026] [security2:error] [pid 642360:tid 642533] [client 43.173.180.204:35128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/07/01/alternative-fragrance-beauty-2016/"] [unique_id "amuDdJSUkh3e5AhEJOCMnAAAAbo"], referer: https://carnetdeshopping.com/index.php/2016/07/01/alternative-fragrance-beauty-2016/
[Thu Jul 30 12:01:40.107486 2026] [security2:error] [pid 642360:tid 642523] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1xmomo.php"] [unique_id "amuDdJSUkh3e5AhEJOCMngAAAbA"]
[Thu Jul 30 12:01:40.107575 2026] [security2:error] [pid 642360:tid 642523] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1xmomo.php"] [unique_id "amuDdJSUkh3e5AhEJOCMngAAAbA"]
[Thu Jul 30 12:01:40.141591 2026] [core:notice] [pid 642360:tid 642522] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:40.145937 2026] [security2:error] [pid 642360:tid 642522] [client 103.215.74.26:34154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDdJSUkh3e5AhEJOCMnwAAAa8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:40.347389 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:40.354580 2026] [security2:error] [pid 642360:tid 642551] [client 43.173.173.143:52060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/11/09/lenseigne-espagnole-suiteblanco-lance-son-eshop-en-france/"] [unique_id "amuDdJSUkh3e5AhEJOCMpgAAAcw"], referer: https://carnetdeshopping.com/index.php/2012/11/09/lenseigne-espagnole-suiteblanco-lance-son-eshop-en-france/
[Thu Jul 30 12:01:40.544801 2026] [security2:error] [pid 642360:tid 642518] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDc5SUkh3e5AhEJOCMmgAAAas"]
[Thu Jul 30 12:01:40.669766 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1revo.php"] [unique_id "amuDdJSUkh3e5AhEJOCMrAAAAgg"]
[Thu Jul 30 12:01:40.669907 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1revo.php"] [unique_id "amuDdJSUkh3e5AhEJOCMrAAAAgg"]
[Thu Jul 30 12:01:40.872046 2026] [core:notice] [pid 642360:tid 642497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:40.876547 2026] [security2:error] [pid 642360:tid 642497] [client 103.215.74.26:34160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDdJSUkh3e5AhEJOCMswAAAZY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:41.218601 2026] [security2:error] [pid 643253:tid 643509] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/cong.php"] [unique_id "amuDdcjqbtjBYzqM1uYtJgAAAH0"]
[Thu Jul 30 12:01:41.218705 2026] [security2:error] [pid 643253:tid 643509] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/cong.php"] [unique_id "amuDdcjqbtjBYzqM1uYtJgAAAH0"]
[Thu Jul 30 12:01:41.334512 2026] [security2:error] [pid 642360:tid 642567] [client 20.215.191.139:51052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/02.php"] [unique_id "amuDdZSUkh3e5AhEJOCMugAAAdw"]
[Thu Jul 30 12:01:41.617516 2026] [core:notice] [pid 642360:tid 642556] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:41.621514 2026] [security2:error] [pid 642360:tid 642556] [client 103.215.74.26:34164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDdZSUkh3e5AhEJOCMwwAAAdE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:41.754859 2026] [security2:error] [pid 642360:tid 642597] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/a.php"] [unique_id "amuDdZSUkh3e5AhEJOCMxAAAAfo"]
[Thu Jul 30 12:01:41.755018 2026] [security2:error] [pid 642360:tid 642597] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/a.php"] [unique_id "amuDdZSUkh3e5AhEJOCMxAAAAfo"]
[Thu Jul 30 12:01:42.292574 2026] [security2:error] [pid 642360:tid 642591] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/srontol.php"] [unique_id "amuDdpSUkh3e5AhEJOCMzQAAAfQ"]
[Thu Jul 30 12:01:42.292682 2026] [security2:error] [pid 642360:tid 642591] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/srontol.php"] [unique_id "amuDdpSUkh3e5AhEJOCMzQAAAfQ"]
[Thu Jul 30 12:01:42.401597 2026] [core:notice] [pid 642360:tid 642538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:42.405466 2026] [security2:error] [pid 642360:tid 642538] [client 103.215.74.26:34170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDdpSUkh3e5AhEJOCMzwAAAb8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:42.500721 2026] [security2:error] [pid 642360:tid 642487] [remote 74.7.241.60:47012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuDdpSUkh3e5AhEJOCM1QACBn4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:01:42.836159 2026] [security2:error] [pid 642360:tid 642551] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuDdpSUkh3e5AhEJOCM2QAAAcw"]
[Thu Jul 30 12:01:42.836264 2026] [security2:error] [pid 642360:tid 642551] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuDdpSUkh3e5AhEJOCM2QAAAcw"]
[Thu Jul 30 12:01:43.132201 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:43.136195 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:64342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDd8jqbtjBYzqM1uYtKgAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:43.409339 2026] [security2:error] [pid 642360:tid 642563] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file5.php"] [unique_id "amuDd5SUkh3e5AhEJOCM4gAAAdg"]
[Thu Jul 30 12:01:43.409479 2026] [security2:error] [pid 642360:tid 642563] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file5.php"] [unique_id "amuDd5SUkh3e5AhEJOCM4gAAAdg"]
[Thu Jul 30 12:01:43.656328 2026] [security2:error] [pid 642360:tid 642611] [client 114.119.130.32:25255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ejournalugj.com"] [uri "/index_php/jibm"] [unique_id "amuDd5SUkh3e5AhEJOCM6QAAAgg"], referer: https://www.ejournalugj.com/
[Thu Jul 30 12:01:43.963717 2026] [security2:error] [pid 643253:tid 643444] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/domvf.php"] [unique_id "amuDd8jqbtjBYzqM1uYtLQAAADw"]
[Thu Jul 30 12:01:43.963818 2026] [security2:error] [pid 643253:tid 643444] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/domvf.php"] [unique_id "amuDd8jqbtjBYzqM1uYtLQAAADw"]
[Thu Jul 30 12:01:44.454934 2026] [security2:error] [pid 643253:tid 643447] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zero.php"] [unique_id "amuDeMjqbtjBYzqM1uYtLwAAAD8"]
[Thu Jul 30 12:01:44.455044 2026] [security2:error] [pid 643253:tid 643447] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zero.php"] [unique_id "amuDeMjqbtjBYzqM1uYtLwAAAD8"]
[Thu Jul 30 12:01:44.953438 2026] [security2:error] [pid 642360:tid 642587] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/002.php"] [unique_id "amuDeJSUkh3e5AhEJOCM9QAAAfA"]
[Thu Jul 30 12:01:44.953560 2026] [security2:error] [pid 642360:tid 642587] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/002.php"] [unique_id "amuDeJSUkh3e5AhEJOCM9QAAAfA"]
[Thu Jul 30 12:01:45.511893 2026] [security2:error] [pid 642360:tid 642578] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/thoms.php"] [unique_id "amuDeZSUkh3e5AhEJOCM_wAAAec"]
[Thu Jul 30 12:01:45.512018 2026] [security2:error] [pid 642360:tid 642578] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/thoms.php"] [unique_id "amuDeZSUkh3e5AhEJOCM_wAAAec"]
[Thu Jul 30 12:01:45.630064 2026] [security2:error] [pid 642360:tid 642534] [client 176.241.66.87:58020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDeZSUkh3e5AhEJOCNAgAAAbs"]
[Thu Jul 30 12:01:45.630222 2026] [security2:error] [pid 642360:tid 642534] [client 176.241.66.87:58020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDeZSUkh3e5AhEJOCNAgAAAbs"]
[Thu Jul 30 12:01:45.804436 2026] [security2:error] [pid 642360:tid 642564] [client 20.215.191.139:51066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/infos.php"] [unique_id "amuDeZSUkh3e5AhEJOCNBQAAAdk"]
[Thu Jul 30 12:01:46.098575 2026] [security2:error] [pid 643253:tid 643462] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fi22.php"] [unique_id "amuDesjqbtjBYzqM1uYtOgAAAE4"]
[Thu Jul 30 12:01:46.098670 2026] [security2:error] [pid 643253:tid 643462] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fi22.php"] [unique_id "amuDesjqbtjBYzqM1uYtOgAAAE4"]
[Thu Jul 30 12:01:46.519417 2026] [core:notice] [pid 642360:tid 642547] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:46.644996 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuDepSUkh3e5AhEJOCNEQAAAgs"]
[Thu Jul 30 12:01:46.910726 2026] [security2:error] [pid 642360:tid 642511] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/82.php"] [unique_id "amuDepSUkh3e5AhEJOCNFAAAAaQ"]
[Thu Jul 30 12:01:46.910835 2026] [security2:error] [pid 642360:tid 642511] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/82.php"] [unique_id "amuDepSUkh3e5AhEJOCNFAAAAaQ"]
[Thu Jul 30 12:01:47.408761 2026] [security2:error] [pid 642360:tid 642509] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sx.php"] [unique_id "amuDe5SUkh3e5AhEJOCNHwAAAaI"]
[Thu Jul 30 12:01:47.408882 2026] [security2:error] [pid 642360:tid 642509] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sx.php"] [unique_id "amuDe5SUkh3e5AhEJOCNHwAAAaI"]
[Thu Jul 30 12:01:47.673002 2026] [core:error] [pid 642360:tid 642398] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:47.673057 2026] [core:error] [pid 642360:tid 642398] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:47.682564 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:47.696100 2026] [security2:error] [pid 642360:tid 642577] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDe5SUkh3e5AhEJOCNGQAAAeY"]
[Thu Jul 30 12:01:47.918712 2026] [security2:error] [pid 643253:tid 643464] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/dex.php"] [unique_id "amuDe8jqbtjBYzqM1uYtSQAAAFA"]
[Thu Jul 30 12:01:47.918820 2026] [security2:error] [pid 643253:tid 643464] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/dex.php"] [unique_id "amuDe8jqbtjBYzqM1uYtSQAAAFA"]
[Thu Jul 30 12:01:48.471411 2026] [security2:error] [pid 642360:tid 642520] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fpwch.php"] [unique_id "amuDfJSUkh3e5AhEJOCNMAAAAa0"]
[Thu Jul 30 12:01:48.471521 2026] [security2:error] [pid 642360:tid 642520] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fpwch.php"] [unique_id "amuDfJSUkh3e5AhEJOCNMAAAAa0"]
[Thu Jul 30 12:01:48.531088 2026] [security2:error] [pid 642360:tid 642537] [client 20.215.191.139:51020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/updates.php"] [unique_id "amuDfJSUkh3e5AhEJOCNMQAAAb4"]
[Thu Jul 30 12:01:48.783717 2026] [security2:error] [pid 643253:tid 643494] [client 93.152.221.59:59212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "lark-shop.com"] [uri "/"] [unique_id "amuDfMjqbtjBYzqM1uYtTQAAAG4"]
[Thu Jul 30 12:01:48.859907 2026] [core:notice] [pid 643253:tid 643416] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:48.864291 2026] [security2:error] [pid 643253:tid 643416] [client 103.215.74.26:64354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDfMjqbtjBYzqM1uYtUAAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:48.996114 2026] [core:error] [pid 643253:tid 643301] [remote 74.7.230.41:43942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:48.996135 2026] [core:error] [pid 643253:tid 643301] [remote 74.7.230.41:43942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:01:48.996359 2026] [security2:error] [pid 643253:tid 643502] [client 74.7.230.41:43942] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.chicago-mfg.com"] [uri "/index.php"] [unique_id "amuDfMjqbtjBYzqM1uYtUwAAdi4"]
[Thu Jul 30 12:01:49.038934 2026] [security2:error] [pid 643253:tid 643481] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/black.php"] [unique_id "amuDfcjqbtjBYzqM1uYtVQAAAGE"]
[Thu Jul 30 12:01:49.039075 2026] [security2:error] [pid 643253:tid 643481] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/black.php"] [unique_id "amuDfcjqbtjBYzqM1uYtVQAAAGE"]
[Thu Jul 30 12:01:49.080673 2026] [security2:error] [pid 642360:tid 642424] [remote 45.252.248.45:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.248.252.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuDfJSUkh3e5AhEJOCNNwABsz8"]
[Thu Jul 30 12:01:49.547480 2026] [security2:error] [pid 643253:tid 643386] [client 20.215.191.139:51070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/user.php"] [unique_id "amuDfcjqbtjBYzqM1uYtWQAAAAI"]
[Thu Jul 30 12:01:49.586569 2026] [core:notice] [pid 642360:tid 642609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:49.586947 2026] [security2:error] [pid 643253:tid 643471] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/loader.php"] [unique_id "amuDfcjqbtjBYzqM1uYtWgAAAFc"]
[Thu Jul 30 12:01:49.587058 2026] [security2:error] [pid 643253:tid 643471] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/loader.php"] [unique_id "amuDfcjqbtjBYzqM1uYtWgAAAFc"]
[Thu Jul 30 12:01:49.592561 2026] [security2:error] [pid 642360:tid 642609] [client 103.215.74.26:64360] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDfZSUkh3e5AhEJOCNQQAAAgY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:50.101452 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file61.php"] [unique_id "amuDfpSUkh3e5AhEJOCNSwAAAgs"]
[Thu Jul 30 12:01:50.101559 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file61.php"] [unique_id "amuDfpSUkh3e5AhEJOCNSwAAAgs"]
[Thu Jul 30 12:01:50.336917 2026] [core:notice] [pid 642360:tid 642593] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:50.343715 2026] [security2:error] [pid 642360:tid 642593] [client 103.215.74.26:64364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDfpSUkh3e5AhEJOCNTwAAAfY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:50.646611 2026] [security2:error] [pid 642360:tid 642567] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-css.php"] [unique_id "amuDfpSUkh3e5AhEJOCNWAAAAdw"]
[Thu Jul 30 12:01:50.646771 2026] [security2:error] [pid 642360:tid 642567] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-css.php"] [unique_id "amuDfpSUkh3e5AhEJOCNWAAAAdw"]
[Thu Jul 30 12:01:50.784021 2026] [security2:error] [pid 643253:tid 643413] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDfsjqbtjBYzqM1uYtWwAAHTY"]
[Thu Jul 30 12:01:51.121060 2026] [core:notice] [pid 642360:tid 642550] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:51.125170 2026] [security2:error] [pid 642360:tid 642550] [client 103.215.74.26:64374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDf5SUkh3e5AhEJOCNZQAAAcs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:51.254681 2026] [security2:error] [pid 642360:tid 642587] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-blink.php"] [unique_id "amuDf5SUkh3e5AhEJOCNZgAAAfA"]
[Thu Jul 30 12:01:51.254797 2026] [security2:error] [pid 642360:tid 642587] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-blink.php"] [unique_id "amuDf5SUkh3e5AhEJOCNZgAAAfA"]
[Thu Jul 30 12:01:51.257014 2026] [security2:error] [pid 643253:tid 643498] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuDfsjqbtjBYzqM1uYtXAAAAHI"]
[Thu Jul 30 12:01:51.275440 2026] [security2:error] [pid 642360:tid 642571] [client 20.215.191.139:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/admin-ajax.php"] [unique_id "amuDf5SUkh3e5AhEJOCNZwAAAeA"]
[Thu Jul 30 12:01:51.831052 2026] [security2:error] [pid 642360:tid 642608] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/txets.php"] [unique_id "amuDf5SUkh3e5AhEJOCNbQAAAgU"]
[Thu Jul 30 12:01:51.831181 2026] [security2:error] [pid 642360:tid 642608] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/txets.php"] [unique_id "amuDf5SUkh3e5AhEJOCNbQAAAgU"]
[Thu Jul 30 12:01:51.900323 2026] [core:notice] [pid 642360:tid 642597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:51.904076 2026] [security2:error] [pid 642360:tid 642597] [client 103.215.74.26:64380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDf5SUkh3e5AhEJOCNcQAAAfo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:52.390639 2026] [security2:error] [pid 642360:tid 642495] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/pucci.php"] [unique_id "amuDgJSUkh3e5AhEJOCNdgAAAZQ"]
[Thu Jul 30 12:01:52.390743 2026] [security2:error] [pid 642360:tid 642495] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/pucci.php"] [unique_id "amuDgJSUkh3e5AhEJOCNdgAAAZQ"]
[Thu Jul 30 12:01:52.405169 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:52.630793 2026] [core:notice] [pid 642360:tid 642514] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:52.637406 2026] [security2:error] [pid 642360:tid 642514] [client 103.215.74.26:64388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDgJSUkh3e5AhEJOCNegAAAac"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:52.913162 2026] [security2:error] [pid 642360:tid 642605] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDgJSUkh3e5AhEJOCNdQACAkQ"]
[Thu Jul 30 12:01:52.927153 2026] [security2:error] [pid 643253:tid 643456] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xwpg.php"] [unique_id "amuDgMjqbtjBYzqM1uYtZgAAAEg"]
[Thu Jul 30 12:01:52.927251 2026] [security2:error] [pid 643253:tid 643456] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xwpg.php"] [unique_id "amuDgMjqbtjBYzqM1uYtZgAAAEg"]
[Thu Jul 30 12:01:53.365533 2026] [core:notice] [pid 642360:tid 642559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:53.369523 2026] [security2:error] [pid 642360:tid 642559] [client 103.215.74.26:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDgZSUkh3e5AhEJOCNggAAAdQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:53.507127 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuDgZSUkh3e5AhEJOCNhwAAAgg"]
[Thu Jul 30 12:01:53.507219 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuDgZSUkh3e5AhEJOCNhwAAAgg"]
[Thu Jul 30 12:01:54.080088 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1.php"] [unique_id "amuDgpSUkh3e5AhEJOCNkgAAAfk"]
[Thu Jul 30 12:01:54.080195 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1.php"] [unique_id "amuDgpSUkh3e5AhEJOCNkgAAAfk"]
[Thu Jul 30 12:01:54.080263 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/1.php"] [unique_id "amuDgpSUkh3e5AhEJOCNkgAAAfk"]
[Thu Jul 30 12:01:54.093792 2026] [core:notice] [pid 642360:tid 642568] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:54.097890 2026] [security2:error] [pid 642360:tid 642568] [client 103.215.74.26:7526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDgpSUkh3e5AhEJOCNkwAAAd0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:54.449043 2026] [security2:error] [pid 642360:tid 642598] [client 14.191.136.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuDgpSUkh3e5AhEJOCNlAAB-zg"]
[Thu Jul 30 12:01:54.657279 2026] [security2:error] [pid 642360:tid 642528] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mac.php"] [unique_id "amuDgpSUkh3e5AhEJOCNmwAAAbU"]
[Thu Jul 30 12:01:54.657426 2026] [security2:error] [pid 642360:tid 642528] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mac.php"] [unique_id "amuDgpSUkh3e5AhEJOCNmwAAAbU"]
[Thu Jul 30 12:01:54.818255 2026] [core:notice] [pid 642360:tid 642571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:54.822511 2026] [security2:error] [pid 642360:tid 642571] [client 103.215.74.26:7530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDgpSUkh3e5AhEJOCNnAAAAeA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:55.222762 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuDg8jqbtjBYzqM1uYtZwAAAHs"]
[Thu Jul 30 12:01:55.222882 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuDg8jqbtjBYzqM1uYtZwAAAHs"]
[Thu Jul 30 12:01:55.558403 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:55.564748 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:7542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDg5SUkh3e5AhEJOCNqQAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:55.660908 2026] [security2:error] [pid 642360:tid 642533] [client 20.215.191.139:50826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/alfa.php"] [unique_id "amuDg5SUkh3e5AhEJOCNrgAAAbo"]
[Thu Jul 30 12:01:55.758884 2026] [security2:error] [pid 643253:tid 643392] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/aa.php"] [unique_id "amuDg8jqbtjBYzqM1uYtaQAAAAg"]
[Thu Jul 30 12:01:55.759045 2026] [security2:error] [pid 643253:tid 643392] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/aa.php"] [unique_id "amuDg8jqbtjBYzqM1uYtaQAAAAg"]
[Thu Jul 30 12:01:56.281143 2026] [security2:error] [pid 642360:tid 642545] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xyn.php"] [unique_id "amuDhJSUkh3e5AhEJOCNuAAAAcY"]
[Thu Jul 30 12:01:56.281278 2026] [security2:error] [pid 642360:tid 642545] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xyn.php"] [unique_id "amuDhJSUkh3e5AhEJOCNuAAAAcY"]
[Thu Jul 30 12:01:56.292031 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:56.296475 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:7552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDhMjqbtjBYzqM1uYtagAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:56.726242 2026] [security2:error] [pid 642360:tid 642512] [client 176.241.66.87:59057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDhJSUkh3e5AhEJOCNwgAAAaU"]
[Thu Jul 30 12:01:56.726364 2026] [security2:error] [pid 642360:tid 642512] [client 176.241.66.87:59057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDhJSUkh3e5AhEJOCNwgAAAaU"]
[Thu Jul 30 12:01:56.787005 2026] [security2:error] [pid 642360:tid 642540] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-wp.php"] [unique_id "amuDhJSUkh3e5AhEJOCNwwAAAcE"]
[Thu Jul 30 12:01:56.787115 2026] [security2:error] [pid 642360:tid 642540] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-wp.php"] [unique_id "amuDhJSUkh3e5AhEJOCNwwAAAcE"]
[Thu Jul 30 12:01:57.036600 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:57.040534 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:7562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDhcjqbtjBYzqM1uYtbAAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:57.267351 2026] [security2:error] [pid 642360:tid 642588] [client 74.7.241.181:37158] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "mail.ege.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuDg5SUkh3e5AhEJOCNoQAB8U8"]
[Thu Jul 30 12:01:57.267377 2026] [security2:error] [pid 642360:tid 642588] [client 74.7.241.181:37158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.ege.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuDg5SUkh3e5AhEJOCNoQAB8U8"]
[Thu Jul 30 12:01:57.287731 2026] [security2:error] [pid 643253:tid 643433] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/aw.php"] [unique_id "amuDhcjqbtjBYzqM1uYtbgAAADE"]
[Thu Jul 30 12:01:57.287822 2026] [security2:error] [pid 643253:tid 643433] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/aw.php"] [unique_id "amuDhcjqbtjBYzqM1uYtbgAAADE"]
[Thu Jul 30 12:01:57.777872 2026] [core:notice] [pid 642360:tid 642566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:57.780866 2026] [security2:error] [pid 643253:tid 643455] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/classwithtostring.php"] [unique_id "amuDhcjqbtjBYzqM1uYtcgAAAEc"]
[Thu Jul 30 12:01:57.780957 2026] [security2:error] [pid 643253:tid 643455] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/classwithtostring.php"] [unique_id "amuDhcjqbtjBYzqM1uYtcgAAAEc"]
[Thu Jul 30 12:01:57.784797 2026] [security2:error] [pid 642360:tid 642566] [client 103.215.74.26:7578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDhZSUkh3e5AhEJOCNzwAAAds"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:58.300926 2026] [security2:error] [pid 643253:tid 643504] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yawa.php"] [unique_id "amuDhsjqbtjBYzqM1uYtdAAAAHg"]
[Thu Jul 30 12:01:58.301086 2026] [security2:error] [pid 643253:tid 643504] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yawa.php"] [unique_id "amuDhsjqbtjBYzqM1uYtdAAAAHg"]
[Thu Jul 30 12:01:58.506165 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:01:58.510491 2026] [security2:error] [pid 643253:tid 643470] [client 103.215.74.26:7582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDhsjqbtjBYzqM1uYtdQAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:01:58.565273 2026] [security2:error] [pid 642360:tid 642592] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "medaxco.com"] [uri "/index.php"] [unique_id "amuDhpSUkh3e5AhEJOCN0gAB9V0"], referer: https://mail.ege.nyx.temporary.site/robots.txt
[Thu Jul 30 12:01:58.816838 2026] [security2:error] [pid 642360:tid 642549] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sym403.php"] [unique_id "amuDhpSUkh3e5AhEJOCN2QAAAco"]
[Thu Jul 30 12:01:58.816940 2026] [security2:error] [pid 642360:tid 642549] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sym403.php"] [unique_id "amuDhpSUkh3e5AhEJOCN2QAAAco"]
[Thu Jul 30 12:01:59.399970 2026] [security2:error] [pid 642360:tid 642521] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuDh5SUkh3e5AhEJOCN4QAAAa4"]
[Thu Jul 30 12:01:59.718177 2026] [security2:error] [pid 642360:tid 642551] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/adminner.php"] [unique_id "amuDh5SUkh3e5AhEJOCN5QAAAcw"]
[Thu Jul 30 12:01:59.718304 2026] [security2:error] [pid 642360:tid 642551] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/adminner.php"] [unique_id "amuDh5SUkh3e5AhEJOCN5QAAAcw"]
[Thu Jul 30 12:02:00.199641 2026] [security2:error] [pid 643253:tid 643436] [client 20.215.191.139:51053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/hehe.php"] [unique_id "amuDiMjqbtjBYzqM1uYtegAAADQ"]
[Thu Jul 30 12:02:00.334359 2026] [security2:error] [pid 643253:tid 643394] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yup.php"] [unique_id "amuDiMjqbtjBYzqM1uYtfAAAAAo"]
[Thu Jul 30 12:02:00.334473 2026] [security2:error] [pid 643253:tid 643394] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yup.php"] [unique_id "amuDiMjqbtjBYzqM1uYtfAAAAAo"]
[Thu Jul 30 12:02:00.510833 2026] [core:notice] [pid 643253:tid 643314] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:00.514949 2026] [security2:error] [pid 643253:tid 643477] [client 125.165.105.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/287/287"] [unique_id "amuDiMjqbtjBYzqM1uYtewAAXTs"]
[Thu Jul 30 12:02:00.917811 2026] [security2:error] [pid 643253:tid 643424] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/config.json.php"] [unique_id "amuDiMjqbtjBYzqM1uYtfgAAACg"]
[Thu Jul 30 12:02:00.917906 2026] [security2:error] [pid 643253:tid 643424] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/config.json.php"] [unique_id "amuDiMjqbtjBYzqM1uYtfgAAACg"]
[Thu Jul 30 12:02:00.999711 2026] [core:notice] [pid 642360:tid 642447] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:01.397516 2026] [security2:error] [pid 643253:tid 643452] [client 52.15.147.27:47262] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuDicjqbtjBYzqM1uYtgAAAAEQ"], referer: https://globalmarks.pk/
[Thu Jul 30 12:02:01.513658 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-includes/block-bindings/"] [unique_id "amuDiZSUkh3e5AhEJOCN_AAAAfk"]
[Thu Jul 30 12:02:01.528681 2026] [security2:error] [pid 642360:tid 642562] [client 20.215.191.139:50825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/rk2.php"] [unique_id "amuDiZSUkh3e5AhEJOCN_QAAAdc"]
[Thu Jul 30 12:02:01.821317 2026] [security2:error] [pid 642360:tid 642595] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2.php"] [unique_id "amuDiZSUkh3e5AhEJOCN_gAAAfg"]
[Thu Jul 30 12:02:01.821446 2026] [security2:error] [pid 642360:tid 642595] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2.php"] [unique_id "amuDiZSUkh3e5AhEJOCN_gAAAfg"]
[Thu Jul 30 12:02:02.355778 2026] [security2:error] [pid 642360:tid 642572] [client 20.215.191.139:50873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/setup-config.php"] [unique_id "amuDipSUkh3e5AhEJOCOCAAAAeE"]
[Thu Jul 30 12:02:02.397575 2026] [security2:error] [pid 642360:tid 642532] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/f35.update.php"] [unique_id "amuDipSUkh3e5AhEJOCOCQAAAbk"]
[Thu Jul 30 12:02:02.397672 2026] [security2:error] [pid 642360:tid 642532] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/f35.update.php"] [unique_id "amuDipSUkh3e5AhEJOCOCQAAAbk"]
[Thu Jul 30 12:02:02.940805 2026] [security2:error] [pid 643253:tid 643503] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/k.php"] [unique_id "amuDisjqbtjBYzqM1uYtgwAAAHc"]
[Thu Jul 30 12:02:02.940923 2026] [security2:error] [pid 643253:tid 643503] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/k.php"] [unique_id "amuDisjqbtjBYzqM1uYtgwAAAHc"]
[Thu Jul 30 12:02:03.349212 2026] [security2:error] [pid 643253:tid 643313] [remote 47.128.27.89:50610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/search/Nike/page/59/"] [unique_id "amuDi8jqbtjBYzqM1uYthQAAIDo"]
[Thu Jul 30 12:02:03.518736 2026] [security2:error] [pid 642360:tid 642525] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/"] [unique_id "amuDi5SUkh3e5AhEJOCOHAAAAbI"]
[Thu Jul 30 12:02:03.784763 2026] [security2:error] [pid 642360:tid 642500] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/spadex.php"] [unique_id "amuDi5SUkh3e5AhEJOCOIgAAAZk"]
[Thu Jul 30 12:02:03.784911 2026] [security2:error] [pid 642360:tid 642500] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/spadex.php"] [unique_id "amuDi5SUkh3e5AhEJOCOIgAAAZk"]
[Thu Jul 30 12:02:03.865697 2026] [security2:error] [pid 642360:tid 642520] [client 20.215.191.139:50837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/a7.php"] [unique_id "amuDi5SUkh3e5AhEJOCOIwAAAa0"]
[Thu Jul 30 12:02:04.062007 2026] [security2:error] [pid 642360:tid 642505] [client 64.31.3.126:46892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuDipSUkh3e5AhEJOCOEAAAAfc"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2266
[Thu Jul 30 12:02:04.235549 2026] [core:notice] [pid 643253:tid 643445] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:04.239969 2026] [security2:error] [pid 643253:tid 643445] [client 103.215.74.26:35160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDjMjqbtjBYzqM1uYtiAAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:04.282114 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mg.php"] [unique_id "amuDjJSUkh3e5AhEJOCOKgAAAgg"]
[Thu Jul 30 12:02:04.282225 2026] [security2:error] [pid 642360:tid 642611] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mg.php"] [unique_id "amuDjJSUkh3e5AhEJOCOKgAAAgg"]
[Thu Jul 30 12:02:04.845804 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fnstall.php"] [unique_id "amuDjJSUkh3e5AhEJOCOMAAAAfk"]
[Thu Jul 30 12:02:04.845919 2026] [security2:error] [pid 642360:tid 642596] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fnstall.php"] [unique_id "amuDjJSUkh3e5AhEJOCOMAAAAfk"]
[Thu Jul 30 12:02:04.986591 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:04.991183 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:35168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDjMjqbtjBYzqM1uYtigAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:05.368355 2026] [security2:error] [pid 642360:tid 642528] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ortasekerli1.php"] [unique_id "amuDjZSUkh3e5AhEJOCOQAAAAbU"]
[Thu Jul 30 12:02:05.368470 2026] [security2:error] [pid 642360:tid 642528] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ortasekerli1.php"] [unique_id "amuDjZSUkh3e5AhEJOCOQAAAAbU"]
[Thu Jul 30 12:02:05.450807 2026] [security2:error] [pid 642360:tid 642496] [client 20.215.191.139:50823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/f7.php"] [unique_id "amuDjZSUkh3e5AhEJOCOQgAAAZU"]
[Thu Jul 30 12:02:05.711617 2026] [core:notice] [pid 642360:tid 642530] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:05.715953 2026] [security2:error] [pid 642360:tid 642530] [client 103.215.74.26:35170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDjZSUkh3e5AhEJOCORQAAAbc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:05.875170 2026] [security2:error] [pid 643253:tid 643402] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sump1.php"] [unique_id "amuDjcjqbtjBYzqM1uYtkQAAABI"]
[Thu Jul 30 12:02:05.875265 2026] [security2:error] [pid 643253:tid 643402] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sump1.php"] [unique_id "amuDjcjqbtjBYzqM1uYtkQAAABI"]
[Thu Jul 30 12:02:06.418476 2026] [security2:error] [pid 643253:tid 643473] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuDjsjqbtjBYzqM1uYtkwAAAFk"]
[Thu Jul 30 12:02:06.418588 2026] [security2:error] [pid 643253:tid 643473] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuDjsjqbtjBYzqM1uYtkwAAAFk"]
[Thu Jul 30 12:02:06.538985 2026] [core:notice] [pid 642360:tid 642557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:06.543333 2026] [security2:error] [pid 642360:tid 642557] [client 103.215.74.26:35180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDjpSUkh3e5AhEJOCOWAAAAdI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:06.957736 2026] [security2:error] [pid 642360:tid 642518] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-post-data.php"] [unique_id "amuDjpSUkh3e5AhEJOCObQAAAas"]
[Thu Jul 30 12:02:06.957817 2026] [security2:error] [pid 642360:tid 642518] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-post-data.php"] [unique_id "amuDjpSUkh3e5AhEJOCObQAAAas"]
[Thu Jul 30 12:02:07.152006 2026] [security2:error] [pid 643253:tid 643387] [client 20.215.191.139:51055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/nw.php"] [unique_id "amuDj8jqbtjBYzqM1uYtmAAAAAM"]
[Thu Jul 30 12:02:07.173411 2026] [security2:error] [pid 642360:tid 642473] [remote 45.148.10.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.massageandspaislamabad.rest"] [uri "/wp-json/batch/v1"] [unique_id "amuDj5SUkh3e5AhEJOCOcwACCXA"]
[Thu Jul 30 12:02:07.283270 2026] [core:notice] [pid 642360:tid 642494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:07.287319 2026] [security2:error] [pid 642360:tid 642494] [client 103.215.74.26:35184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDj5SUkh3e5AhEJOCOdgAAAZM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:07.417418 2026] [security2:error] [pid 642360:tid 642383] [remote 74.7.241.59:36266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuDj5SUkh3e5AhEJOCOeQAB7xY"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:02:07.494958 2026] [security2:error] [pid 642360:tid 642538] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/root.php"] [unique_id "amuDj5SUkh3e5AhEJOCOewAAAb8"]
[Thu Jul 30 12:02:07.495072 2026] [security2:error] [pid 642360:tid 642538] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/root.php"] [unique_id "amuDj5SUkh3e5AhEJOCOewAAAb8"]
[Thu Jul 30 12:02:07.708569 2026] [security2:error] [pid 642360:tid 642469] [remote 45.148.10.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.massageandspaislamabad.rest"] [uri "/"] [unique_id "amuDj5SUkh3e5AhEJOCOgAAB12w"]
[Thu Jul 30 12:02:07.806182 2026] [security2:error] [pid 642360:tid 642571] [client 176.241.66.87:60096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDj5SUkh3e5AhEJOCOhAAAAeA"]
[Thu Jul 30 12:02:07.806399 2026] [security2:error] [pid 642360:tid 642571] [client 176.241.66.87:60096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDj5SUkh3e5AhEJOCOhAAAAeA"]
[Thu Jul 30 12:02:08.058323 2026] [security2:error] [pid 643253:tid 643511] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/v543.php"] [unique_id "amuDkMjqbtjBYzqM1uYtmwAAAH8"]
[Thu Jul 30 12:02:08.058439 2026] [security2:error] [pid 643253:tid 643511] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/v543.php"] [unique_id "amuDkMjqbtjBYzqM1uYtmwAAAH8"]
[Thu Jul 30 12:02:08.062946 2026] [core:notice] [pid 642360:tid 642552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:08.067781 2026] [security2:error] [pid 642360:tid 642552] [client 103.215.74.26:35198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDkJSUkh3e5AhEJOCOjQAAAc0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:08.169293 2026] [lsapi:error] [pid 643573:tid 643666] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/fall-for-me-vj-junior/
[Thu Jul 30 12:02:08.173449 2026] [security2:error] [pid 642360:tid 642574] [client 20.215.191.139:50838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/ova.php"] [unique_id "amuDkJSUkh3e5AhEJOCOjgAAAeM"]
[Thu Jul 30 12:02:08.496076 2026] [security2:error] [pid 642360:tid 642395] [remote 103.57.220.209:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.57.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "edgecomm.info"] [uri "/wp-login.php"] [unique_id "amuDkJSUkh3e5AhEJOCOlAABxyI"]
[Thu Jul 30 12:02:08.589921 2026] [security2:error] [pid 642360:tid 642545] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sixxis.php"] [unique_id "amuDkJSUkh3e5AhEJOCOlQAAAcY"]
[Thu Jul 30 12:02:08.590050 2026] [security2:error] [pid 642360:tid 642545] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sixxis.php"] [unique_id "amuDkJSUkh3e5AhEJOCOlQAAAcY"]
[Thu Jul 30 12:02:08.968970 2026] [security2:error] [pid 643253:tid 643484] [client 20.215.191.139:50816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/robots.php"] [unique_id "amuDkMjqbtjBYzqM1uYtnQAAAGQ"]
[Thu Jul 30 12:02:09.128040 2026] [security2:error] [pid 642360:tid 642540] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ip.php"] [unique_id "amuDkZSUkh3e5AhEJOCOngAAAcE"]
[Thu Jul 30 12:02:09.128142 2026] [security2:error] [pid 642360:tid 642540] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ip.php"] [unique_id "amuDkZSUkh3e5AhEJOCOngAAAcE"]
[Thu Jul 30 12:02:09.685073 2026] [security2:error] [pid 642360:tid 642567] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/kq1.php"] [unique_id "amuDkZSUkh3e5AhEJOCOpwAAAdw"]
[Thu Jul 30 12:02:09.685184 2026] [security2:error] [pid 642360:tid 642567] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/kq1.php"] [unique_id "amuDkZSUkh3e5AhEJOCOpwAAAdw"]
[Thu Jul 30 12:02:09.932925 2026] [security2:error] [pid 643253:tid 643505] [client 20.215.191.139:51059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/alf.php"] [unique_id "amuDkcjqbtjBYzqM1uYtogAAAHk"]
[Thu Jul 30 12:02:10.181796 2026] [security2:error] [pid 642360:tid 642572] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fw/faiyy.php"] [unique_id "amuDkpSUkh3e5AhEJOCOrAAAAeE"]
[Thu Jul 30 12:02:10.181952 2026] [security2:error] [pid 642360:tid 642572] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fw/faiyy.php"] [unique_id "amuDkpSUkh3e5AhEJOCOrAAAAeE"]
[Thu Jul 30 12:02:10.740615 2026] [security2:error] [pid 642360:tid 642599] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/h02ugyh.php"] [unique_id "amuDkpSUkh3e5AhEJOCOtAAAAfw"]
[Thu Jul 30 12:02:10.740755 2026] [security2:error] [pid 642360:tid 642599] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/h02ugyh.php"] [unique_id "amuDkpSUkh3e5AhEJOCOtAAAAfw"]
[Thu Jul 30 12:02:11.357814 2026] [security2:error] [pid 642360:tid 642579] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-temp.php"] [unique_id "amuDk5SUkh3e5AhEJOCOugAAAeg"]
[Thu Jul 30 12:02:11.357919 2026] [security2:error] [pid 642360:tid 642579] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-temp.php"] [unique_id "amuDk5SUkh3e5AhEJOCOugAAAeg"]
[Thu Jul 30 12:02:11.795507 2026] [core:notice] [pid 643253:tid 643433] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:11.930328 2026] [security2:error] [pid 643253:tid 643395] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/cong.php"] [unique_id "amuDk8jqbtjBYzqM1uYtqQAAAAs"]
[Thu Jul 30 12:02:11.930438 2026] [security2:error] [pid 643253:tid 643395] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/cong.php"] [unique_id "amuDk8jqbtjBYzqM1uYtqQAAAAs"]
[Thu Jul 30 12:02:12.314957 2026] [security2:error] [pid 643253:tid 643455] [client 20.215.191.139:51065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/feedback.php"] [unique_id "amuDlMjqbtjBYzqM1uYtrQAAAEc"]
[Thu Jul 30 12:02:12.504997 2026] [security2:error] [pid 642360:tid 642511] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/widget/"] [unique_id "amuDlJSUkh3e5AhEJOCO0QAAAaQ"]
[Thu Jul 30 12:02:12.797016 2026] [security2:error] [pid 642360:tid 642509] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/css/index.php"] [unique_id "amuDlJSUkh3e5AhEJOCO2QAAAaI"]
[Thu Jul 30 12:02:12.797159 2026] [security2:error] [pid 642360:tid 642509] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/css/index.php"] [unique_id "amuDlJSUkh3e5AhEJOCO2QAAAaI"]
[Thu Jul 30 12:02:12.923020 2026] [security2:error] [pid 642360:tid 642595] [client 206.0.24.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuDlJSUkh3e5AhEJOCO2AAB-DM"]
[Thu Jul 30 12:02:13.356433 2026] [security2:error] [pid 642360:tid 642493] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/jj.php"] [unique_id "amuDlZSUkh3e5AhEJOCO5AAAAZI"]
[Thu Jul 30 12:02:13.356570 2026] [security2:error] [pid 642360:tid 642493] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/jj.php"] [unique_id "amuDlZSUkh3e5AhEJOCO5AAAAZI"]
[Thu Jul 30 12:02:13.827359 2026] [core:notice] [pid 642360:tid 642508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:13.831816 2026] [security2:error] [pid 642360:tid 642508] [client 103.215.74.26:60568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDlZSUkh3e5AhEJOCO7QAAAaE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:13.901272 2026] [security2:error] [pid 642360:tid 642581] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/class-walker-footer-dev.php"] [unique_id "amuDlZSUkh3e5AhEJOCO7gAAAeo"]
[Thu Jul 30 12:02:13.901387 2026] [security2:error] [pid 642360:tid 642581] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/class-walker-footer-dev.php"] [unique_id "amuDlZSUkh3e5AhEJOCO7gAAAeo"]
[Thu Jul 30 12:02:14.157227 2026] [security2:error] [pid 643253:tid 643394] [client 157.230.8.64:60459] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "pvc.hfl.temporary.site"] [uri "/wp-json/batch/v1"] [unique_id "amuDlsjqbtjBYzqM1uYttQAAAAo"]
[Thu Jul 30 12:02:14.460395 2026] [security2:error] [pid 642360:tid 642565] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xpwer1.php"] [unique_id "amuDlpSUkh3e5AhEJOCO9QAAAdo"]
[Thu Jul 30 12:02:14.460508 2026] [security2:error] [pid 642360:tid 642565] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xpwer1.php"] [unique_id "amuDlpSUkh3e5AhEJOCO9QAAAdo"]
[Thu Jul 30 12:02:14.553826 2026] [security2:error] [pid 643253:tid 643480] [client 20.215.191.139:51026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/gettest.php"] [unique_id "amuDlsjqbtjBYzqM1uYttwAAAGA"]
[Thu Jul 30 12:02:14.555727 2026] [core:notice] [pid 642360:tid 642520] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:14.560119 2026] [security2:error] [pid 642360:tid 642520] [client 103.215.74.26:60578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDlpSUkh3e5AhEJOCO9gAAAa0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:14.733419 2026] [security2:error] [pid 642360:tid 642597] [client 157.230.8.64:60516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "pvc.hfl.temporary.site"] [uri "/"] [unique_id "amuDlpSUkh3e5AhEJOCO-QAAAfo"]
[Thu Jul 30 12:02:14.840273 2026] [security2:error] [pid 642360:tid 642500] [client 20.203.148.31:21591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/--wp-lgj.php"] [unique_id "amuDlpSUkh3e5AhEJOCO_AAAAZk"]
[Thu Jul 30 12:02:14.998067 2026] [security2:error] [pid 642360:tid 642616] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/flox.php"] [unique_id "amuDlpSUkh3e5AhEJOCO_QAAAg0"]
[Thu Jul 30 12:02:14.998176 2026] [security2:error] [pid 642360:tid 642616] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/flox.php"] [unique_id "amuDlpSUkh3e5AhEJOCO_QAAAg0"]
[Thu Jul 30 12:02:15.245228 2026] [security2:error] [pid 642360:tid 642604] [client 20.215.191.139:51047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/maint.php"] [unique_id "amuDl5SUkh3e5AhEJOCPBAAAAgE"]
[Thu Jul 30 12:02:15.289706 2026] [security2:error] [pid 642360:tid 642510] [client 157.230.8.64:60573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "pvc.hfl.temporary.site"] [uri "/wp-json/batch/v1"] [unique_id "amuDl5SUkh3e5AhEJOCPCAAAAaM"]
[Thu Jul 30 12:02:15.317937 2026] [core:notice] [pid 642360:tid 642506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:15.321805 2026] [security2:error] [pid 642360:tid 642506] [client 103.215.74.26:60580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDl5SUkh3e5AhEJOCPCQAAAZ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:15.478461 2026] [security2:error] [pid 642360:tid 642584] [client 20.203.148.31:20555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuDl5SUkh3e5AhEJOCPCwAAAe0"]
[Thu Jul 30 12:02:15.596700 2026] [security2:error] [pid 643253:tid 643494] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/popo.php"] [unique_id "amuDl8jqbtjBYzqM1uYtugAAAG4"]
[Thu Jul 30 12:02:15.596820 2026] [security2:error] [pid 643253:tid 643494] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/popo.php"] [unique_id "amuDl8jqbtjBYzqM1uYtugAAAG4"]
[Thu Jul 30 12:02:16.059930 2026] [core:notice] [pid 642360:tid 642524] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:16.064320 2026] [security2:error] [pid 642360:tid 642524] [client 103.215.74.26:60588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmJSUkh3e5AhEJOCPEwAAAbE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:16.129953 2026] [security2:error] [pid 643253:tid 643416] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yas.php"] [unique_id "amuDmMjqbtjBYzqM1uYtvAAAACA"]
[Thu Jul 30 12:02:16.130086 2026] [security2:error] [pid 643253:tid 643416] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/yas.php"] [unique_id "amuDmMjqbtjBYzqM1uYtvAAAACA"]
[Thu Jul 30 12:02:16.168416 2026] [security2:error] [pid 642360:tid 642512] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDl5SUkh3e5AhEJOCPDAABpUo"]
[Thu Jul 30 12:02:16.662600 2026] [security2:error] [pid 642360:tid 642523] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/water.php"] [unique_id "amuDmJSUkh3e5AhEJOCPGgAAAbA"]
[Thu Jul 30 12:02:16.662712 2026] [security2:error] [pid 642360:tid 642523] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/water.php"] [unique_id "amuDmJSUkh3e5AhEJOCPGgAAAbA"]
[Thu Jul 30 12:02:16.804011 2026] [core:notice] [pid 642360:tid 642534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:16.807928 2026] [security2:error] [pid 642360:tid 642534] [client 103.215.74.26:60602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmJSUkh3e5AhEJOCPGwAAAbs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:16.973765 2026] [security2:error] [pid 642360:tid 642493] [client 20.203.148.31:12574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/flower.php"] [unique_id "amuDmJSUkh3e5AhEJOCPHwAAAZI"]
[Thu Jul 30 12:02:17.238521 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/nano.php"] [unique_id "amuDmZSUkh3e5AhEJOCPJgAAAgs"]
[Thu Jul 30 12:02:17.238634 2026] [security2:error] [pid 642360:tid 642614] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/nano.php"] [unique_id "amuDmZSUkh3e5AhEJOCPJgAAAgs"]
[Thu Jul 30 12:02:17.515443 2026] [security2:error] [pid 642360:tid 642535] [client 20.203.148.31:18955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/xleet.php"] [unique_id "amuDmZSUkh3e5AhEJOCPKwAAAbw"]
[Thu Jul 30 12:02:17.529489 2026] [core:notice] [pid 642360:tid 642551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:17.534498 2026] [security2:error] [pid 642360:tid 642551] [client 103.215.74.26:60610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmZSUkh3e5AhEJOCPLAAAAcw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:17.733925 2026] [security2:error] [pid 642360:tid 642511] [client 188.166.98.61:33098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.nordeste1.com"] [uri "/"] [unique_id "amuDmZSUkh3e5AhEJOCPMAAAAaQ"]
[Thu Jul 30 12:02:17.860871 2026] [security2:error] [pid 642360:tid 642589] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/moon.php"] [unique_id "amuDmZSUkh3e5AhEJOCPMwAAAfI"]
[Thu Jul 30 12:02:17.860995 2026] [security2:error] [pid 642360:tid 642589] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/moon.php"] [unique_id "amuDmZSUkh3e5AhEJOCPMwAAAfI"]
[Thu Jul 30 12:02:17.999108 2026] [security2:error] [pid 643253:tid 643442] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDmcjqbtjBYzqM1uYtwwAAOkQ"]
[Thu Jul 30 12:02:18.263095 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:18.269578 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:60626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmsjqbtjBYzqM1uYtyAAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:18.421231 2026] [security2:error] [pid 642360:tid 642537] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-info.php"] [unique_id "amuDmpSUkh3e5AhEJOCPPwAAAb4"]
[Thu Jul 30 12:02:18.421338 2026] [security2:error] [pid 642360:tid 642537] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-info.php"] [unique_id "amuDmpSUkh3e5AhEJOCPPwAAAb4"]
[Thu Jul 30 12:02:18.697627 2026] [security2:error] [pid 642360:tid 642574] [client 20.203.148.31:12321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuDmpSUkh3e5AhEJOCPQgAAAeM"]
[Thu Jul 30 12:02:18.952703 2026] [security2:error] [pid 642360:tid 642579] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file5.php"] [unique_id "amuDmpSUkh3e5AhEJOCPSgAAAeg"]
[Thu Jul 30 12:02:18.952814 2026] [security2:error] [pid 642360:tid 642579] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file5.php"] [unique_id "amuDmpSUkh3e5AhEJOCPSgAAAeg"]
[Thu Jul 30 12:02:18.954728 2026] [security2:error] [pid 643253:tid 643445] [client 20.215.191.139:50818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/files.php"] [unique_id "amuDmsjqbtjBYzqM1uYtzgAAAD0"]
[Thu Jul 30 12:02:18.962313 2026] [security2:error] [pid 643253:tid 643403] [client 176.241.66.87:61165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDmsjqbtjBYzqM1uYtzwAAABM"]
[Thu Jul 30 12:02:18.962420 2026] [security2:error] [pid 643253:tid 643403] [client 176.241.66.87:61165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDmsjqbtjBYzqM1uYtzwAAABM"]
[Thu Jul 30 12:02:18.996913 2026] [core:notice] [pid 642360:tid 642525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:19.003430 2026] [security2:error] [pid 642360:tid 642525] [client 103.215.74.26:60650] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDmpSUkh3e5AhEJOCPSwAAAbI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:19.397905 2026] [security2:error] [pid 642360:tid 642534] [client 20.203.148.31:12588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuDm5SUkh3e5AhEJOCPTwAAAbs"]
[Thu Jul 30 12:02:19.620418 2026] [security2:error] [pid 643253:tid 643398] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2000.php"] [unique_id "amuDm8jqbtjBYzqM1uYt0QAAAA4"]
[Thu Jul 30 12:02:19.620561 2026] [security2:error] [pid 643253:tid 643398] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2000.php"] [unique_id "amuDm8jqbtjBYzqM1uYt0QAAAA4"]
[Thu Jul 30 12:02:19.676717 2026] [security2:error] [pid 643253:tid 643476] [client 20.215.191.139:51039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/gecko.php"] [unique_id "amuDm8jqbtjBYzqM1uYt0gAAAFw"]
[Thu Jul 30 12:02:19.739352 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:19.743362 2026] [security2:error] [pid 643253:tid 643493] [client 103.215.74.26:60654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDm8jqbtjBYzqM1uYt0wAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:20.199189 2026] [security2:error] [pid 642360:tid 642546] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/122.php"] [unique_id "amuDnJSUkh3e5AhEJOCPVwAAAcc"]
[Thu Jul 30 12:02:20.199319 2026] [security2:error] [pid 642360:tid 642546] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/122.php"] [unique_id "amuDnJSUkh3e5AhEJOCPVwAAAcc"]
[Thu Jul 30 12:02:20.460660 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:20.464596 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:60668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDnMjqbtjBYzqM1uYt1QAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:20.509895 2026] [security2:error] [pid 642360:tid 642505] [client 20.215.191.139:50869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/zwso.php"] [unique_id "amuDnJSUkh3e5AhEJOCPWwAAAZ4"]
[Thu Jul 30 12:02:20.784592 2026] [security2:error] [pid 642360:tid 642513] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mds.php"] [unique_id "amuDnJSUkh3e5AhEJOCPXwAAAaY"]
[Thu Jul 30 12:02:20.784724 2026] [security2:error] [pid 642360:tid 642513] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mds.php"] [unique_id "amuDnJSUkh3e5AhEJOCPXwAAAaY"]
[Thu Jul 30 12:02:21.161820 2026] [security2:error] [pid 642360:tid 642519] [client 20.215.191.139:51064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/13.php"] [unique_id "amuDnZSUkh3e5AhEJOCPZQAAAaw"]
[Thu Jul 30 12:02:21.317077 2026] [security2:error] [pid 642360:tid 642517] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zc-208.php"] [unique_id "amuDnZSUkh3e5AhEJOCPZgAAAao"]
[Thu Jul 30 12:02:21.317213 2026] [security2:error] [pid 642360:tid 642517] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zc-208.php"] [unique_id "amuDnZSUkh3e5AhEJOCPZgAAAao"]
[Thu Jul 30 12:02:21.604678 2026] [security2:error] [pid 643253:tid 643392] [client 20.203.148.31:11160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuDncjqbtjBYzqM1uYt1wAAAAg"]
[Thu Jul 30 12:02:21.873092 2026] [security2:error] [pid 642360:tid 642544] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sid4.php"] [unique_id "amuDnZSUkh3e5AhEJOCPbwAAAcU"]
[Thu Jul 30 12:02:21.873202 2026] [security2:error] [pid 642360:tid 642544] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sid4.php"] [unique_id "amuDnZSUkh3e5AhEJOCPbwAAAcU"]
[Thu Jul 30 12:02:22.041058 2026] [security2:error] [pid 643253:tid 643409] [client 20.215.191.139:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/ava.php"] [unique_id "amuDnsjqbtjBYzqM1uYt2gAAABk"]
[Thu Jul 30 12:02:22.118730 2026] [security2:error] [pid 642360:tid 642561] [client 20.203.148.31:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuDnpSUkh3e5AhEJOCPdQAAAdY"]
[Thu Jul 30 12:02:22.438809 2026] [security2:error] [pid 642360:tid 642574] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuDnpSUkh3e5AhEJOCPeQAAAeM"]
[Thu Jul 30 12:02:22.713901 2026] [security2:error] [pid 642360:tid 642503] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wmore1.php"] [unique_id "amuDnpSUkh3e5AhEJOCPfwAAAZw"]
[Thu Jul 30 12:02:22.714029 2026] [security2:error] [pid 642360:tid 642503] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wmore1.php"] [unique_id "amuDnpSUkh3e5AhEJOCPfwAAAZw"]
[Thu Jul 30 12:02:23.112218 2026] [security2:error] [pid 642360:tid 642523] [client 20.215.191.139:51062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/main.php"] [unique_id "amuDn5SUkh3e5AhEJOCPhgAAAbA"]
[Thu Jul 30 12:02:23.279567 2026] [security2:error] [pid 643253:tid 643490] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/solo1.php"] [unique_id "amuDn8jqbtjBYzqM1uYt3gAAAGo"]
[Thu Jul 30 12:02:23.279692 2026] [security2:error] [pid 643253:tid 643490] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/solo1.php"] [unique_id "amuDn8jqbtjBYzqM1uYt3gAAAGo"]
[Thu Jul 30 12:02:23.904010 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-includes/assets/"] [unique_id "amuDn8jqbtjBYzqM1uYt5gAAAAA"]
[Thu Jul 30 12:02:24.076529 2026] [security2:error] [pid 643253:tid 643470] [client 20.215.191.139:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-file.php"] [unique_id "amuDoMjqbtjBYzqM1uYt6wAAAFY"]
[Thu Jul 30 12:02:24.203619 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:24.229907 2026] [security2:error] [pid 643253:tid 643400] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/"] [unique_id "amuDoMjqbtjBYzqM1uYt8AAAABA"]
[Thu Jul 30 12:02:24.551752 2026] [security2:error] [pid 643253:tid 643457] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/public/css.php"] [unique_id "amuDoMjqbtjBYzqM1uYt-AAAAEk"]
[Thu Jul 30 12:02:24.551858 2026] [security2:error] [pid 643253:tid 643457] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/public/css.php"] [unique_id "amuDoMjqbtjBYzqM1uYt-AAAAEk"]
[Thu Jul 30 12:02:25.155071 2026] [security2:error] [pid 643253:tid 643458] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/output.php"] [unique_id "amuDocjqbtjBYzqM1uYuAwAAAEo"]
[Thu Jul 30 12:02:25.155177 2026] [security2:error] [pid 643253:tid 643458] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/output.php"] [unique_id "amuDocjqbtjBYzqM1uYuAwAAAEo"]
[Thu Jul 30 12:02:25.755379 2026] [security2:error] [pid 643253:tid 643468] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-file-120.php"] [unique_id "amuDocjqbtjBYzqM1uYuDwAAAFQ"]
[Thu Jul 30 12:02:25.755477 2026] [security2:error] [pid 643253:tid 643468] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-file-120.php"] [unique_id "amuDocjqbtjBYzqM1uYuDwAAAFQ"]
[Thu Jul 30 12:02:25.814880 2026] [security2:error] [pid 643253:tid 643478] [client 20.203.148.31:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuDocjqbtjBYzqM1uYuEAAAAF4"]
[Thu Jul 30 12:02:26.232448 2026] [core:notice] [pid 643253:tid 643443] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:26.239480 2026] [security2:error] [pid 643253:tid 643443] [client 103.215.74.26:21906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDosjqbtjBYzqM1uYuFgAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:26.329863 2026] [security2:error] [pid 643253:tid 643392] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/special.php"] [unique_id "amuDosjqbtjBYzqM1uYuHQAAAAg"]
[Thu Jul 30 12:02:26.330178 2026] [security2:error] [pid 643253:tid 643392] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/special.php"] [unique_id "amuDosjqbtjBYzqM1uYuHQAAAAg"]
[Thu Jul 30 12:02:26.343156 2026] [security2:error] [pid 643253:tid 643426] [client 114.119.142.72:29913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/robots.txt"] [unique_id "amuDosjqbtjBYzqM1uYuHgAAACo"], referer: https://alseermarine.com/robots.txt
[Thu Jul 30 12:02:26.556094 2026] [security2:error] [pid 643253:tid 643397] [client 20.203.148.31:12383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuDosjqbtjBYzqM1uYuSgAAAA0"]
[Thu Jul 30 12:02:26.745027 2026] [security2:error] [pid 643253:tid 643432] [client 20.203.148.31:56875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/json.php"] [unique_id "amuDosjqbtjBYzqM1uYuTAAAADA"]
[Thu Jul 30 12:02:26.871950 2026] [security2:error] [pid 643253:tid 643411] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/as.php"] [unique_id "amuDosjqbtjBYzqM1uYuTwAAABs"]
[Thu Jul 30 12:02:26.872075 2026] [security2:error] [pid 643253:tid 643411] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/as.php"] [unique_id "amuDosjqbtjBYzqM1uYuTwAAABs"]
[Thu Jul 30 12:02:26.976947 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:26.980889 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:21908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDosjqbtjBYzqM1uYuUAAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:27.303471 2026] [security2:error] [pid 643253:tid 643387] [client 20.215.191.139:50870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-signin.php"] [unique_id "amuDo8jqbtjBYzqM1uYuVwAAAAM"]
[Thu Jul 30 12:02:27.402873 2026] [security2:error] [pid 643253:tid 643502] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/cgi-bin/index.php"] [unique_id "amuDo8jqbtjBYzqM1uYuWAAAAHY"]
[Thu Jul 30 12:02:27.404592 2026] [security2:error] [pid 643253:tid 643502] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/cgi-bin/index.php"] [unique_id "amuDo8jqbtjBYzqM1uYuWAAAAHY"]
[Thu Jul 30 12:02:27.959285 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w1px.php"] [unique_id "amuDo8jqbtjBYzqM1uYuYwAAAGY"]
[Thu Jul 30 12:02:27.959395 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w1px.php"] [unique_id "amuDo8jqbtjBYzqM1uYuYwAAAGY"]
[Thu Jul 30 12:02:28.098909 2026] [security2:error] [pid 643253:tid 643459] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDo8jqbtjBYzqM1uYuXAAASwA"]
[Thu Jul 30 12:02:28.459630 2026] [security2:error] [pid 643253:tid 643389] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/js.php"] [unique_id "amuDpMjqbtjBYzqM1uYucwAAAAU"]
[Thu Jul 30 12:02:28.459757 2026] [security2:error] [pid 643253:tid 643389] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/js.php"] [unique_id "amuDpMjqbtjBYzqM1uYucwAAAAU"]
[Thu Jul 30 12:02:28.519423 2026] [core:notice] [pid 643253:tid 643478] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:28.523445 2026] [security2:error] [pid 643253:tid 643478] [client 103.215.74.26:21914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDpMjqbtjBYzqM1uYudAAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:28.856731 2026] [security2:error] [pid 643253:tid 643415] [client 20.215.191.139:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/simi.php"] [unique_id "amuDpMjqbtjBYzqM1uYufQAAAB8"]
[Thu Jul 30 12:02:28.972161 2026] [security2:error] [pid 643253:tid 643420] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/core.php"] [unique_id "amuDpMjqbtjBYzqM1uYufgAAACQ"]
[Thu Jul 30 12:02:28.972280 2026] [security2:error] [pid 643253:tid 643420] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/core.php"] [unique_id "amuDpMjqbtjBYzqM1uYufgAAACQ"]
[Thu Jul 30 12:02:29.253571 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:29.257663 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:21916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDpcjqbtjBYzqM1uYuggAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:29.408117 2026] [security2:error] [pid 643253:tid 643384] [client 20.215.191.139:50835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/wp-conf.php"] [unique_id "amuDpcjqbtjBYzqM1uYuiQAAAAA"]
[Thu Jul 30 12:02:29.480350 2026] [security2:error] [pid 643253:tid 643401] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fffm.php"] [unique_id "amuDpcjqbtjBYzqM1uYuigAAABE"]
[Thu Jul 30 12:02:29.480461 2026] [security2:error] [pid 643253:tid 643401] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fffm.php"] [unique_id "amuDpcjqbtjBYzqM1uYuigAAABE"]
[Thu Jul 30 12:02:29.989370 2026] [core:notice] [pid 643253:tid 643424] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:29.994087 2026] [security2:error] [pid 643253:tid 643424] [client 103.215.74.26:21924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDpcjqbtjBYzqM1uYukQAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:30.029472 2026] [security2:error] [pid 643253:tid 643430] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ww.php"] [unique_id "amuDpsjqbtjBYzqM1uYukwAAAC4"]
[Thu Jul 30 12:02:30.029614 2026] [security2:error] [pid 643253:tid 643430] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ww.php"] [unique_id "amuDpsjqbtjBYzqM1uYukwAAAC4"]
[Thu Jul 30 12:02:30.084993 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:30.142949 2026] [security2:error] [pid 643253:tid 643441] [client 20.203.148.31:41403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/mini.php"] [unique_id "amuDpsjqbtjBYzqM1uYumAAAADk"]
[Thu Jul 30 12:02:30.155636 2026] [security2:error] [pid 643253:tid 643400] [client 176.241.66.87:54576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDpsjqbtjBYzqM1uYumQAAABA"]
[Thu Jul 30 12:02:30.155735 2026] [security2:error] [pid 643253:tid 643400] [client 176.241.66.87:54576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDpsjqbtjBYzqM1uYumQAAABA"]
[Thu Jul 30 12:02:30.288330 2026] [security2:error] [pid 643253:tid 643477] [client 20.215.191.139:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuDpsjqbtjBYzqM1uYunAAAAF0"]
[Thu Jul 30 12:02:30.421010 2026] [proxy:error] [pid 643253:tid 643391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:02:30.421093 2026] [proxy_http:error] [pid 643253:tid 643391] [client 193.47.62.167:41548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:02:30.421657 2026] [proxy:error] [pid 643253:tid 643391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:02:30.421699 2026] [proxy_http:error] [pid 643253:tid 643391] [client 193.47.62.167:41548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:02:30.573262 2026] [security2:error] [pid 643253:tid 643485] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/domvf.php"] [unique_id "amuDpsjqbtjBYzqM1uYuoQAAAGU"]
[Thu Jul 30 12:02:30.573399 2026] [security2:error] [pid 643253:tid 643485] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/domvf.php"] [unique_id "amuDpsjqbtjBYzqM1uYuoQAAAGU"]
[Thu Jul 30 12:02:30.813206 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:30.817174 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:21936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDpsjqbtjBYzqM1uYuqQAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:31.096518 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/echkm.php"] [unique_id "amuDp8jqbtjBYzqM1uYurgAAAGg"]
[Thu Jul 30 12:02:31.096690 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/echkm.php"] [unique_id "amuDp8jqbtjBYzqM1uYurgAAAGg"]
[Thu Jul 30 12:02:31.100031 2026] [security2:error] [pid 643253:tid 643468] [client 20.215.191.139:50874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/bala.php"] [unique_id "amuDp8jqbtjBYzqM1uYurwAAAFQ"]
[Thu Jul 30 12:02:31.260154 2026] [security2:error] [pid 643253:tid 643280] [remote 97.74.93.24:40646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuDp8jqbtjBYzqM1uYutgAAWhk"]
[Thu Jul 30 12:02:31.528693 2026] [core:notice] [pid 643253:tid 643446] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:31.532799 2026] [security2:error] [pid 643253:tid 643446] [client 103.215.74.26:21938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDp8jqbtjBYzqM1uYuvQAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:31.655721 2026] [security2:error] [pid 643253:tid 643450] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ano.php"] [unique_id "amuDp8jqbtjBYzqM1uYuvwAAAEI"]
[Thu Jul 30 12:02:31.655882 2026] [security2:error] [pid 643253:tid 643450] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ano.php"] [unique_id "amuDp8jqbtjBYzqM1uYuvwAAAEI"]
[Thu Jul 30 12:02:31.900334 2026] [security2:error] [pid 643253:tid 643438] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.topmoversandpackerssharjah.art"] [uri "/index.php"] [unique_id "amuDp8jqbtjBYzqM1uYuvgAANh8"]
[Thu Jul 30 12:02:31.900367 2026] [security2:error] [pid 643253:tid 643438] [client 74.7.244.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.topmoversandpackerssharjah.art"] [uri "/index.php"] [unique_id "amuDp8jqbtjBYzqM1uYuvgAANh8"]
[Thu Jul 30 12:02:32.180814 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ah25.php"] [unique_id "amuDqMjqbtjBYzqM1uYuxgAAAAA"]
[Thu Jul 30 12:02:32.180923 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ah25.php"] [unique_id "amuDqMjqbtjBYzqM1uYuxgAAAAA"]
[Thu Jul 30 12:02:32.193232 2026] [security2:error] [pid 643253:tid 643278] [remote 57.141.0.39:28072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuDqMjqbtjBYzqM1uYuxwAAdBc"]
[Thu Jul 30 12:02:32.277436 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:32.281389 2026] [security2:error] [pid 643253:tid 643470] [client 103.215.74.26:21948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDqMjqbtjBYzqM1uYuywAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:32.372332 2026] [security2:error] [pid 643253:tid 643407] [client 20.203.148.31:62018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/chosen.php"] [unique_id "amuDqMjqbtjBYzqM1uYuzAAAABc"]
[Thu Jul 30 12:02:32.446249 2026] [security2:error] [pid 643253:tid 643489] [client 20.215.191.139:51050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/bk.php"] [unique_id "amuDqMjqbtjBYzqM1uYuzQAAAGk"]
[Thu Jul 30 12:02:32.688029 2026] [security2:error] [pid 643253:tid 643425] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/term.php"] [unique_id "amuDqMjqbtjBYzqM1uYu0QAAACk"]
[Thu Jul 30 12:02:32.688154 2026] [security2:error] [pid 643253:tid 643425] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/term.php"] [unique_id "amuDqMjqbtjBYzqM1uYu0QAAACk"]
[Thu Jul 30 12:02:33.010070 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:33.016823 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:4326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDqcjqbtjBYzqM1uYu1gAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:33.253491 2026] [security2:error] [pid 643253:tid 643391] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/we.php"] [unique_id "amuDqcjqbtjBYzqM1uYu3QAAAAc"]
[Thu Jul 30 12:02:33.253605 2026] [security2:error] [pid 643253:tid 643391] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/we.php"] [unique_id "amuDqcjqbtjBYzqM1uYu3QAAAAc"]
[Thu Jul 30 12:02:33.367700 2026] [security2:error] [pid 643253:tid 643457] [client 20.215.191.139:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arabian-tours.com"] [uri "/ahax.php"] [unique_id "amuDqcjqbtjBYzqM1uYu3gAAAEk"]
[Thu Jul 30 12:02:33.762450 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:33.766377 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:4328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDqcjqbtjBYzqM1uYu6AAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:33.810183 2026] [security2:error] [pid 643253:tid 643456] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zip-onee.php"] [unique_id "amuDqcjqbtjBYzqM1uYu6QAAAEg"]
[Thu Jul 30 12:02:33.810283 2026] [security2:error] [pid 643253:tid 643456] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zip-onee.php"] [unique_id "amuDqcjqbtjBYzqM1uYu6QAAAEg"]
[Thu Jul 30 12:02:34.305755 2026] [security2:error] [pid 643253:tid 643460] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/il.php"] [unique_id "amuDqsjqbtjBYzqM1uYu8AAAAEw"]
[Thu Jul 30 12:02:34.305865 2026] [security2:error] [pid 643253:tid 643460] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/il.php"] [unique_id "amuDqsjqbtjBYzqM1uYu8AAAAEw"]
[Thu Jul 30 12:02:34.439048 2026] [security2:error] [pid 643253:tid 643416] [client 20.203.148.31:58535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/kj.php"] [unique_id "amuDqsjqbtjBYzqM1uYu8QAAACA"]
[Thu Jul 30 12:02:34.529845 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:34.534200 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:4330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDqsjqbtjBYzqM1uYu8gAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:34.832557 2026] [security2:error] [pid 643253:tid 643505] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/one.php"] [unique_id "amuDqsjqbtjBYzqM1uYu_QAAAHk"]
[Thu Jul 30 12:02:34.832654 2026] [security2:error] [pid 643253:tid 643505] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/one.php"] [unique_id "amuDqsjqbtjBYzqM1uYu_QAAAHk"]
[Thu Jul 30 12:02:34.890642 2026] [security2:error] [pid 643253:tid 643440] [client 217.165.158.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amuDqsjqbtjBYzqM1uYu8wAAOCs"]
[Thu Jul 30 12:02:34.910883 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:35.279717 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:35.283784 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:4344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDq8jqbtjBYzqM1uYvCAAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:35.385470 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/002.php"] [unique_id "amuDq8jqbtjBYzqM1uYvCQAAAEE"]
[Thu Jul 30 12:02:35.385574 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/002.php"] [unique_id "amuDq8jqbtjBYzqM1uYvCQAAAEE"]
[Thu Jul 30 12:02:35.723099 2026] [security2:error] [pid 643253:tid 643405] [client 20.203.148.31:20055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuDq8jqbtjBYzqM1uYvEAAAABU"]
[Thu Jul 30 12:02:35.924062 2026] [security2:error] [pid 643253:tid 643397] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file1.php"] [unique_id "amuDq8jqbtjBYzqM1uYvEQAAAA0"]
[Thu Jul 30 12:02:35.924184 2026] [security2:error] [pid 643253:tid 643397] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/file1.php"] [unique_id "amuDq8jqbtjBYzqM1uYvEQAAAA0"]
[Thu Jul 30 12:02:36.223097 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:36.449018 2026] [security2:error] [pid 643253:tid 643466] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/akimet.php"] [unique_id "amuDrMjqbtjBYzqM1uYvGwAAAFI"]
[Thu Jul 30 12:02:36.449175 2026] [security2:error] [pid 643253:tid 643466] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/akimet.php"] [unique_id "amuDrMjqbtjBYzqM1uYvGwAAAFI"]
[Thu Jul 30 12:02:36.676140 2026] [security2:error] [pid 643253:tid 643435] [client 20.203.148.31:16544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuDrMjqbtjBYzqM1uYvIQAAADM"]
[Thu Jul 30 12:02:37.011880 2026] [core:notice] [pid 643253:tid 643312] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:37.017068 2026] [security2:error] [pid 643253:tid 643498] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuDrcjqbtjBYzqM1uYvJgAAAHI"]
[Thu Jul 30 12:02:37.017150 2026] [security2:error] [pid 643253:tid 643498] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuDrcjqbtjBYzqM1uYvJgAAAHI"]
[Thu Jul 30 12:02:37.186413 2026] [security2:error] [pid 643253:tid 643418] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDrMjqbtjBYzqM1uYvHAAAIjY"]
[Thu Jul 30 12:02:37.540332 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/h.php"] [unique_id "amuDrcjqbtjBYzqM1uYvLQAAAGg"]
[Thu Jul 30 12:02:37.540488 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/h.php"] [unique_id "amuDrcjqbtjBYzqM1uYvLQAAAGg"]
[Thu Jul 30 12:02:37.610192 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:37.782687 2026] [security2:error] [pid 643253:tid 643468] [client 20.203.148.31:16571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuDrcjqbtjBYzqM1uYvNAAAAFQ"]
[Thu Jul 30 12:02:38.065309 2026] [security2:error] [pid 643253:tid 643440] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2x.php"] [unique_id "amuDrsjqbtjBYzqM1uYvPAAAADg"]
[Thu Jul 30 12:02:38.065416 2026] [security2:error] [pid 643253:tid 643440] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2x.php"] [unique_id "amuDrsjqbtjBYzqM1uYvPAAAADg"]
[Thu Jul 30 12:02:38.302501 2026] [security2:error] [pid 643253:tid 643495] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDrcjqbtjBYzqM1uYvLwAAbz4"]
[Thu Jul 30 12:02:38.610118 2026] [security2:error] [pid 643253:tid 643509] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/petx.php"] [unique_id "amuDrsjqbtjBYzqM1uYvRwAAAH0"]
[Thu Jul 30 12:02:38.610225 2026] [security2:error] [pid 643253:tid 643509] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/petx.php"] [unique_id "amuDrsjqbtjBYzqM1uYvRwAAAH0"]
[Thu Jul 30 12:02:39.154330 2026] [security2:error] [pid 643253:tid 643489] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zxz.php"] [unique_id "amuDr8jqbtjBYzqM1uYvTwAAAGk"]
[Thu Jul 30 12:02:39.154462 2026] [security2:error] [pid 643253:tid 643489] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/zxz.php"] [unique_id "amuDr8jqbtjBYzqM1uYvTwAAAGk"]
[Thu Jul 30 12:02:39.547951 2026] [security2:error] [pid 643253:tid 643501] [client 20.203.148.31:57978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/wp-files.php"] [unique_id "amuDr8jqbtjBYzqM1uYvVwAAAHU"]
[Thu Jul 30 12:02:39.721824 2026] [security2:error] [pid 643253:tid 643400] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2.php"] [unique_id "amuDr8jqbtjBYzqM1uYvWgAAABA"]
[Thu Jul 30 12:02:39.721944 2026] [security2:error] [pid 643253:tid 643400] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/2.php"] [unique_id "amuDr8jqbtjBYzqM1uYvWgAAABA"]
[Thu Jul 30 12:02:40.124519 2026] [security2:error] [pid 643253:tid 643500] [client 20.203.148.31:17569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuDsMjqbtjBYzqM1uYvYQAAAHQ"]
[Thu Jul 30 12:02:40.271924 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/op.php"] [unique_id "amuDsMjqbtjBYzqM1uYvYgAAAAI"]
[Thu Jul 30 12:02:40.272065 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/op.php"] [unique_id "amuDsMjqbtjBYzqM1uYvYgAAAAI"]
[Thu Jul 30 12:02:40.836393 2026] [security2:error] [pid 643253:tid 643418] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/a5.php"] [unique_id "amuDsMjqbtjBYzqM1uYvagAAACI"]
[Thu Jul 30 12:02:40.836500 2026] [security2:error] [pid 643253:tid 643418] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/a5.php"] [unique_id "amuDsMjqbtjBYzqM1uYvagAAACI"]
[Thu Jul 30 12:02:41.076833 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:41.080756 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:4354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDscjqbtjBYzqM1uYvdQAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:41.254683 2026] [security2:error] [pid 643253:tid 643488] [client 41.220.17.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDscjqbtjBYzqM1uYvdAAAAGg"], referer: https://cnpinyin.com/
[Thu Jul 30 12:02:41.301944 2026] [security2:error] [pid 643253:tid 643459] [client 176.241.66.87:63108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDscjqbtjBYzqM1uYvdwAAAEs"]
[Thu Jul 30 12:02:41.302075 2026] [security2:error] [pid 643253:tid 643459] [client 176.241.66.87:63108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDscjqbtjBYzqM1uYvdwAAAEs"]
[Thu Jul 30 12:02:41.411135 2026] [security2:error] [pid 643253:tid 643409] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ws80.php"] [unique_id "amuDscjqbtjBYzqM1uYveAAAABk"]
[Thu Jul 30 12:02:41.411247 2026] [security2:error] [pid 643253:tid 643409] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ws80.php"] [unique_id "amuDscjqbtjBYzqM1uYveAAAABk"]
[Thu Jul 30 12:02:41.620217 2026] [security2:error] [pid 643253:tid 643443] [client 20.203.148.31:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/wp-setup.php"] [unique_id "amuDscjqbtjBYzqM1uYvfwAAADs"]
[Thu Jul 30 12:02:41.645198 2026] [core:notice] [pid 643253:tid 643468] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:41.985220 2026] [security2:error] [pid 643253:tid 643454] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xa.php"] [unique_id "amuDscjqbtjBYzqM1uYvhAAAAEY"]
[Thu Jul 30 12:02:41.985332 2026] [security2:error] [pid 643253:tid 643454] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xa.php"] [unique_id "amuDscjqbtjBYzqM1uYvhAAAAEY"]
[Thu Jul 30 12:02:42.321395 2026] [security2:error] [pid 643253:tid 643455] [client 37.120.155.179:38726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuDssjqbtjBYzqM1uYviAAAAEc"]
[Thu Jul 30 12:02:42.321496 2026] [security2:error] [pid 643253:tid 643455] [client 37.120.155.179:38726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuDssjqbtjBYzqM1uYviAAAAEc"]
[Thu Jul 30 12:02:42.524482 2026] [security2:error] [pid 643253:tid 643401] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/asd67.php"] [unique_id "amuDssjqbtjBYzqM1uYvjgAAABE"]
[Thu Jul 30 12:02:42.524603 2026] [security2:error] [pid 643253:tid 643401] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/asd67.php"] [unique_id "amuDssjqbtjBYzqM1uYvjgAAABE"]
[Thu Jul 30 12:02:42.765138 2026] [security2:error] [pid 643253:tid 643449] [client 20.203.148.31:17092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuDssjqbtjBYzqM1uYvkgAAAEE"]
[Thu Jul 30 12:02:43.056822 2026] [security2:error] [pid 643253:tid 643420] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/bk.php"] [unique_id "amuDs8jqbtjBYzqM1uYvmQAAACQ"]
[Thu Jul 30 12:02:43.056940 2026] [security2:error] [pid 643253:tid 643420] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/bk.php"] [unique_id "amuDs8jqbtjBYzqM1uYvmQAAACQ"]
[Thu Jul 30 12:02:43.646873 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-links.php"] [unique_id "amuDs8jqbtjBYzqM1uYvpAAAAAI"]
[Thu Jul 30 12:02:43.647007 2026] [security2:error] [pid 643253:tid 643386] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-links.php"] [unique_id "amuDs8jqbtjBYzqM1uYvpAAAAAI"]
[Thu Jul 30 12:02:44.206877 2026] [security2:error] [pid 643253:tid 643445] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mosty.php"] [unique_id "amuDtMjqbtjBYzqM1uYvrAAAAD0"]
[Thu Jul 30 12:02:44.207026 2026] [security2:error] [pid 643253:tid 643445] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/mosty.php"] [unique_id "amuDtMjqbtjBYzqM1uYvrAAAAD0"]
[Thu Jul 30 12:02:44.646361 2026] [security2:error] [pid 643253:tid 643428] [client 20.203.148.31:27306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuDtMjqbtjBYzqM1uYvsQAAACw"]
[Thu Jul 30 12:02:44.736951 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sump3.php"] [unique_id "amuDtMjqbtjBYzqM1uYvtQAAAHs"]
[Thu Jul 30 12:02:44.737114 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/sump3.php"] [unique_id "amuDtMjqbtjBYzqM1uYvtQAAAHs"]
[Thu Jul 30 12:02:45.284954 2026] [security2:error] [pid 643253:tid 643484] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/first.php"] [unique_id "amuDtcjqbtjBYzqM1uYvxAAAAGQ"]
[Thu Jul 30 12:02:45.285073 2026] [security2:error] [pid 643253:tid 643484] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/first.php"] [unique_id "amuDtcjqbtjBYzqM1uYvxAAAAGQ"]
[Thu Jul 30 12:02:45.715970 2026] [security2:error] [pid 643253:tid 643459] [client 172.237.109.114:11354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvvgAAAEs"]
[Thu Jul 30 12:02:45.716757 2026] [security2:error] [pid 643253:tid 643389] [client 172.237.109.114:17460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvvQAAAAU"]
[Thu Jul 30 12:02:45.728780 2026] [security2:error] [pid 643253:tid 643409] [client 172.237.109.114:21959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvwAAAABk"]
[Thu Jul 30 12:02:45.735195 2026] [security2:error] [pid 643253:tid 643493] [client 172.237.109.114:17804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvvAAAAG0"]
[Thu Jul 30 12:02:45.739050 2026] [security2:error] [pid 643253:tid 643437] [client 172.237.109.114:24530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuDtcjqbtjBYzqM1uYvvwAAADU"]
[Thu Jul 30 12:02:45.871802 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/acp.php"] [unique_id "amuDtcjqbtjBYzqM1uYvzwAAAAA"]
[Thu Jul 30 12:02:45.871913 2026] [security2:error] [pid 643253:tid 643384] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/acp.php"] [unique_id "amuDtcjqbtjBYzqM1uYvzwAAAAA"]
[Thu Jul 30 12:02:46.457266 2026] [security2:error] [pid 643253:tid 643466] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-good.php"] [unique_id "amuDtsjqbtjBYzqM1uYv2QAAAFI"]
[Thu Jul 30 12:02:46.457398 2026] [security2:error] [pid 643253:tid 643466] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-good.php"] [unique_id "amuDtsjqbtjBYzqM1uYv2QAAAFI"]
[Thu Jul 30 12:02:46.652581 2026] [security2:error] [pid 643253:tid 643414] [client 20.203.148.31:33458] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.revolutionary-technologies.com"] [uri "/1.php"] [unique_id "amuDtsjqbtjBYzqM1uYv3gAAAB4"]
[Thu Jul 30 12:02:46.652719 2026] [security2:error] [pid 643253:tid 643414] [client 20.203.148.31:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/1.php"] [unique_id "amuDtsjqbtjBYzqM1uYv3gAAAB4"]
[Thu Jul 30 12:02:46.802690 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:46.807060 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:33062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDtsjqbtjBYzqM1uYv3wAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:47.054778 2026] [security2:error] [pid 643253:tid 643439] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDtsjqbtjBYzqM1uYv2gAAN24"]
[Thu Jul 30 12:02:47.057597 2026] [security2:error] [pid 643253:tid 643465] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/daerl3.php"] [unique_id "amuDt8jqbtjBYzqM1uYv5AAAAFE"]
[Thu Jul 30 12:02:47.057722 2026] [security2:error] [pid 643253:tid 643465] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/daerl3.php"] [unique_id "amuDt8jqbtjBYzqM1uYv5AAAAFE"]
[Thu Jul 30 12:02:47.222429 2026] [security2:error] [pid 643253:tid 643371] [remote 74.7.241.60:34698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuDt8jqbtjBYzqM1uYv6AAABnQ"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:02:47.534306 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:47.538632 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:33074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDt8jqbtjBYzqM1uYv7QAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:47.614193 2026] [security2:error] [pid 643253:tid 643432] [client 20.203.148.31:2958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/admin.php"] [unique_id "amuDt8jqbtjBYzqM1uYv7gAAADA"]
[Thu Jul 30 12:02:47.672169 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/php5.php"] [unique_id "amuDt8jqbtjBYzqM1uYv9gAAAHs"]
[Thu Jul 30 12:02:47.672286 2026] [security2:error] [pid 643253:tid 643507] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/php5.php"] [unique_id "amuDt8jqbtjBYzqM1uYv9gAAAHs"]
[Thu Jul 30 12:02:48.222267 2026] [security2:error] [pid 643253:tid 643495] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xoot.php"] [unique_id "amuDuMjqbtjBYzqM1uYwAQAAAG8"]
[Thu Jul 30 12:02:48.222390 2026] [security2:error] [pid 643253:tid 643495] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/xoot.php"] [unique_id "amuDuMjqbtjBYzqM1uYwAQAAAG8"]
[Thu Jul 30 12:02:48.302568 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:48.306862 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:33086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDuMjqbtjBYzqM1uYwAgAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:48.532627 2026] [security2:error] [pid 643253:tid 643462] [client 20.203.148.31:41050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/defaults.php"] [unique_id "amuDuMjqbtjBYzqM1uYwBgAAAE4"]
[Thu Jul 30 12:02:48.616092 2026] [security2:error] [pid 643253:tid 643450] [client 20.203.148.31:12854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/as.php"] [unique_id "amuDuMjqbtjBYzqM1uYwCgAAAEI"]
[Thu Jul 30 12:02:48.717329 2026] [security2:error] [pid 643253:tid 643394] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/clxcc.php"] [unique_id "amuDuMjqbtjBYzqM1uYwEgAAAAo"]
[Thu Jul 30 12:02:48.717443 2026] [security2:error] [pid 643253:tid 643394] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/clxcc.php"] [unique_id "amuDuMjqbtjBYzqM1uYwEgAAAAo"]
[Thu Jul 30 12:02:49.041861 2026] [core:notice] [pid 643253:tid 643396] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:49.046275 2026] [security2:error] [pid 643253:tid 643396] [client 103.215.74.26:33096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDucjqbtjBYzqM1uYwHgAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:49.212834 2026] [security2:error] [pid 643253:tid 643430] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ai.php"] [unique_id "amuDucjqbtjBYzqM1uYwIgAAAC4"]
[Thu Jul 30 12:02:49.212963 2026] [security2:error] [pid 643253:tid 643430] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ai.php"] [unique_id "amuDucjqbtjBYzqM1uYwIgAAAC4"]
[Thu Jul 30 12:02:49.763735 2026] [core:notice] [pid 643253:tid 643406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:49.768364 2026] [security2:error] [pid 643253:tid 643406] [client 103.215.74.26:33098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDucjqbtjBYzqM1uYwKQAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:49.772779 2026] [security2:error] [pid 643253:tid 643388] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/nwflm.php"] [unique_id "amuDucjqbtjBYzqM1uYwKgAAAAQ"]
[Thu Jul 30 12:02:49.772870 2026] [security2:error] [pid 643253:tid 643388] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/nwflm.php"] [unique_id "amuDucjqbtjBYzqM1uYwKgAAAAQ"]
[Thu Jul 30 12:02:50.050998 2026] [security2:error] [pid 643253:tid 643435] [client 20.203.148.31:2945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/autoload_classmap.php"] [unique_id "amuDusjqbtjBYzqM1uYwLgAAADM"]
[Thu Jul 30 12:02:50.353535 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/hypo.php"] [unique_id "amuDusjqbtjBYzqM1uYwNAAAAB0"]
[Thu Jul 30 12:02:50.353663 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/hypo.php"] [unique_id "amuDusjqbtjBYzqM1uYwNAAAAB0"]
[Thu Jul 30 12:02:50.517957 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:50.523247 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:33102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDusjqbtjBYzqM1uYwOAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:50.613749 2026] [security2:error] [pid 643253:tid 643408] [client 57.141.0.2:40150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuDusjqbtjBYzqM1uYwMAAAGAo"], referer: https://igetvape-australia.com/product-category/alibarbar-ingot-9000-puffs/?add-to-cart=919
[Thu Jul 30 12:02:50.648703 2026] [security2:error] [pid 643253:tid 643442] [client 20.203.148.31:33434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/back.php"] [unique_id "amuDusjqbtjBYzqM1uYwOgAAADo"]
[Thu Jul 30 12:02:50.846313 2026] [core:notice] [pid 643253:tid 643476] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:50.870676 2026] [security2:error] [pid 643253:tid 643475] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w3llscc.php"] [unique_id "amuDusjqbtjBYzqM1uYwQgAAAFs"]
[Thu Jul 30 12:02:50.870781 2026] [security2:error] [pid 643253:tid 643475] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w3llscc.php"] [unique_id "amuDusjqbtjBYzqM1uYwQgAAAFs"]
[Thu Jul 30 12:02:50.878254 2026] [security2:error] [pid 643253:tid 643403] [client 20.203.148.31:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/gtc.php"] [unique_id "amuDusjqbtjBYzqM1uYwRAAAABM"]
[Thu Jul 30 12:02:51.272041 2026] [core:notice] [pid 643253:tid 643495] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:51.276412 2026] [security2:error] [pid 643253:tid 643495] [client 103.215.74.26:33106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDu8jqbtjBYzqM1uYwRgAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:51.405225 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:51.434382 2026] [security2:error] [pid 643253:tid 643493] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuDu8jqbtjBYzqM1uYwSwAAAG0"]
[Thu Jul 30 12:02:51.434496 2026] [security2:error] [pid 643253:tid 643493] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuDu8jqbtjBYzqM1uYwSwAAAG0"]
[Thu Jul 30 12:02:51.576097 2026] [security2:error] [pid 643253:tid 643469] [client 20.203.148.31:22086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuDu8jqbtjBYzqM1uYwTwAAAFU"]
[Thu Jul 30 12:02:51.997959 2026] [security2:error] [pid 643253:tid 643399] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/8.php"] [unique_id "amuDu8jqbtjBYzqM1uYwVAAAAA8"]
[Thu Jul 30 12:02:51.998096 2026] [security2:error] [pid 643253:tid 643399] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/8.php"] [unique_id "amuDu8jqbtjBYzqM1uYwVAAAAA8"]
[Thu Jul 30 12:02:52.057178 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:52.061910 2026] [security2:error] [pid 643253:tid 643419] [client 103.215.74.26:33114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDvMjqbtjBYzqM1uYwWQAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:52.296713 2026] [security2:error] [pid 643253:tid 643449] [client 20.203.148.31:41225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/import.php"] [unique_id "amuDvMjqbtjBYzqM1uYwXQAAAEE"]
[Thu Jul 30 12:02:52.394793 2026] [security2:error] [pid 643253:tid 643496] [client 176.241.66.87:55734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDvMjqbtjBYzqM1uYwXwAAAHA"]
[Thu Jul 30 12:02:52.394921 2026] [security2:error] [pid 643253:tid 643496] [client 176.241.66.87:55734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDvMjqbtjBYzqM1uYwXwAAAHA"]
[Thu Jul 30 12:02:52.540202 2026] [security2:error] [pid 643253:tid 643387] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fnstall.php"] [unique_id "amuDvMjqbtjBYzqM1uYwZgAAAAM"]
[Thu Jul 30 12:02:52.540319 2026] [security2:error] [pid 643253:tid 643387] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fnstall.php"] [unique_id "amuDvMjqbtjBYzqM1uYwZgAAAAM"]
[Thu Jul 30 12:02:52.806200 2026] [core:notice] [pid 643253:tid 643412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:52.810614 2026] [security2:error] [pid 643253:tid 643412] [client 103.215.74.26:33128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDvMjqbtjBYzqM1uYwaAAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:52.874764 2026] [security2:error] [pid 643253:tid 643401] [client 20.203.148.31:22098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/flower.php"] [unique_id "amuDvMjqbtjBYzqM1uYwaQAAABE"]
[Thu Jul 30 12:02:52.991240 2026] [security2:error] [pid 643253:tid 643400] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDvMjqbtjBYzqM1uYwXgAAECQ"]
[Thu Jul 30 12:02:53.046031 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/edorxrr.php"] [unique_id "amuDvcjqbtjBYzqM1uYwcwAAAB0"]
[Thu Jul 30 12:02:53.046124 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/edorxrr.php"] [unique_id "amuDvcjqbtjBYzqM1uYwcwAAAB0"]
[Thu Jul 30 12:02:53.129858 2026] [security2:error] [pid 643253:tid 643458] [client 20.203.148.31:58530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/lufix.php"] [unique_id "amuDvcjqbtjBYzqM1uYwdAAAAEo"]
[Thu Jul 30 12:02:53.541897 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:53.548574 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:48082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDvcjqbtjBYzqM1uYweAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:53.607100 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/setup.php"] [unique_id "amuDvcjqbtjBYzqM1uYwfAAAAGY"]
[Thu Jul 30 12:02:53.607201 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/setup.php"] [unique_id "amuDvcjqbtjBYzqM1uYwfAAAAGY"]
[Thu Jul 30 12:02:54.190048 2026] [security2:error] [pid 643253:tid 643462] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/6.php"] [unique_id "amuDvsjqbtjBYzqM1uYwgwAAAE4"]
[Thu Jul 30 12:02:54.190179 2026] [security2:error] [pid 643253:tid 643462] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/6.php"] [unique_id "amuDvsjqbtjBYzqM1uYwgwAAAE4"]
[Thu Jul 30 12:02:54.348511 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:54.352485 2026] [security2:error] [pid 643253:tid 643454] [client 103.215.74.26:48086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDvsjqbtjBYzqM1uYwhAAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:54.748241 2026] [security2:error] [pid 643253:tid 643419] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w3lls.php"] [unique_id "amuDvsjqbtjBYzqM1uYwiwAAACM"]
[Thu Jul 30 12:02:54.748358 2026] [security2:error] [pid 643253:tid 643419] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/w3lls.php"] [unique_id "amuDvsjqbtjBYzqM1uYwiwAAACM"]
[Thu Jul 30 12:02:54.817046 2026] [security2:error] [pid 643253:tid 643492] [client 20.203.148.31:17641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/xleet.php"] [unique_id "amuDvsjqbtjBYzqM1uYwjAAAAGw"]
[Thu Jul 30 12:02:55.081083 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:55.085048 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:48118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDv8jqbtjBYzqM1uYwkAAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:55.261634 2026] [security2:error] [pid 643253:tid 643423] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/99.php"] [unique_id "amuDv8jqbtjBYzqM1uYwlAAAACc"]
[Thu Jul 30 12:02:55.261745 2026] [security2:error] [pid 643253:tid 643423] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/99.php"] [unique_id "amuDv8jqbtjBYzqM1uYwlAAAACc"]
[Thu Jul 30 12:02:55.382305 2026] [security2:error] [pid 643253:tid 643447] [client 20.203.148.31:41074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/Geforce.php"] [unique_id "amuDv8jqbtjBYzqM1uYwlQAAAD8"]
[Thu Jul 30 12:02:55.749842 2026] [security2:error] [pid 643253:tid 643482] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/admin.php"] [unique_id "amuDv8jqbtjBYzqM1uYwnQAAAGI"]
[Thu Jul 30 12:02:55.750003 2026] [security2:error] [pid 643253:tid 643482] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/admin.php"] [unique_id "amuDv8jqbtjBYzqM1uYwnQAAAGI"]
[Thu Jul 30 12:02:55.853624 2026] [core:notice] [pid 643253:tid 643436] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:55.857972 2026] [security2:error] [pid 643253:tid 643436] [client 103.215.74.26:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDv8jqbtjBYzqM1uYwngAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:56.015816 2026] [security2:error] [pid 643253:tid 643489] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDv8jqbtjBYzqM1uYwlgAAaSo"]
[Thu Jul 30 12:02:56.206839 2026] [security2:error] [pid 643253:tid 643400] [client 47.128.122.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuDwMjqbtjBYzqM1uYwoQAAABA"]
[Thu Jul 30 12:02:56.314346 2026] [security2:error] [pid 643253:tid 643461] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/media.php"] [unique_id "amuDwMjqbtjBYzqM1uYwqQAAAE0"]
[Thu Jul 30 12:02:56.314452 2026] [security2:error] [pid 643253:tid 643461] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/media.php"] [unique_id "amuDwMjqbtjBYzqM1uYwqQAAAE0"]
[Thu Jul 30 12:02:56.594538 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:56.601292 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:48192] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDwMjqbtjBYzqM1uYwrAAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:56.757306 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:56.898118 2026] [security2:error] [pid 643253:tid 643481] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuDwMjqbtjBYzqM1uYwtAAAAGE"]
[Thu Jul 30 12:02:56.898235 2026] [security2:error] [pid 643253:tid 643481] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuDwMjqbtjBYzqM1uYwtAAAAGE"]
[Thu Jul 30 12:02:57.365565 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:57.372403 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:48200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDwcjqbtjBYzqM1uYwvQAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:57.456243 2026] [security2:error] [pid 643253:tid 643504] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/222.php"] [unique_id "amuDwcjqbtjBYzqM1uYwvgAAAHg"]
[Thu Jul 30 12:02:57.456400 2026] [security2:error] [pid 643253:tid 643504] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/222.php"] [unique_id "amuDwcjqbtjBYzqM1uYwvgAAAHg"]
[Thu Jul 30 12:02:57.530468 2026] [security2:error] [pid 643253:tid 643484] [client 20.203.148.31:41301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/a4.php"] [unique_id "amuDwcjqbtjBYzqM1uYwvwAAAGQ"]
[Thu Jul 30 12:02:57.983778 2026] [security2:error] [pid 643253:tid 643453] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-load.php"] [unique_id "amuDwcjqbtjBYzqM1uYwyQAAAEU"]
[Thu Jul 30 12:02:57.983872 2026] [security2:error] [pid 643253:tid 643453] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-load.php"] [unique_id "amuDwcjqbtjBYzqM1uYwyQAAAEU"]
[Thu Jul 30 12:02:58.100641 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:58.104577 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:48202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDwsjqbtjBYzqM1uYwywAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:58.216863 2026] [core:notice] [pid 643253:tid 643452] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:58.553139 2026] [security2:error] [pid 643253:tid 643391] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/themes/index.php"] [unique_id "amuDwsjqbtjBYzqM1uYw0wAAAAc"]
[Thu Jul 30 12:02:58.553256 2026] [security2:error] [pid 643253:tid 643391] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-content/themes/index.php"] [unique_id "amuDwsjqbtjBYzqM1uYw0wAAAAc"]
[Thu Jul 30 12:02:58.762863 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:58.810168 2026] [security2:error] [pid 643253:tid 643470] [client 20.203.148.31:17635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/classwithtostring.php"] [unique_id "amuDwsjqbtjBYzqM1uYw2wAAAFY"]
[Thu Jul 30 12:02:58.828755 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:58.832770 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:48204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDwsjqbtjBYzqM1uYw3QAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:58.851134 2026] [security2:error] [pid 643253:tid 643410] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuDwsjqbtjBYzqM1uYw4AAAABo"]
[Thu Jul 30 12:02:58.851810 2026] [security2:error] [pid 643253:tid 643502] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuDwsjqbtjBYzqM1uYw3gAAdj8"]
[Thu Jul 30 12:02:59.067509 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:59.073177 2026] [security2:error] [pid 643253:tid 643398] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw5gAAAA4"], referer: https://webmail.vwh.hfl.temporary.site/robots.txt
[Thu Jul 30 12:02:59.073692 2026] [security2:error] [pid 643253:tid 643435] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw4QAAMz0"], referer: https://webmail.vwh.hfl.temporary.site/robots.txt
[Thu Jul 30 12:02:59.123946 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuDw8jqbtjBYzqM1uYw6AAAAB0"]
[Thu Jul 30 12:02:59.124057 2026] [security2:error] [pid 643253:tid 643413] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuDw8jqbtjBYzqM1uYw6AAAAB0"]
[Thu Jul 30 12:02:59.297603 2026] [security2:error] [pid 643253:tid 643488] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw6wAAAGg"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.298155 2026] [security2:error] [pid 643253:tid 643400] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw6QAAED4"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.298812 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:59.415000 2026] [proxy:error] [pid 643253:tid 643431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:02:59.415054 2026] [proxy_http:error] [pid 643253:tid 643431] [client 34.224.175.62:13720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:02:59.415614 2026] [proxy:error] [pid 643253:tid 643431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:02:59.415657 2026] [proxy_http:error] [pid 643253:tid 643431] [client 34.224.175.62:13720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:02:59.519396 2026] [security2:error] [pid 643253:tid 643440] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw9wAAADg"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.521417 2026] [security2:error] [pid 643253:tid 643446] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw9QAAPkA"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.597856 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:02:59.604776 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:48210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDw8jqbtjBYzqM1uYw-AAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:02:59.712243 2026] [security2:error] [pid 643253:tid 643505] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/memberfuns.php"] [unique_id "amuDw8jqbtjBYzqM1uYw-QAAAHk"]
[Thu Jul 30 12:02:59.712358 2026] [security2:error] [pid 643253:tid 643505] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/memberfuns.php"] [unique_id "amuDw8jqbtjBYzqM1uYw-QAAAHk"]
[Thu Jul 30 12:02:59.742474 2026] [security2:error] [pid 643253:tid 643468] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw_AAAAFQ"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.742928 2026] [security2:error] [pid 643253:tid 643421] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYw-gAAJUI"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.966926 2026] [security2:error] [pid 643253:tid 643450] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYxBQAAAEI"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:02:59.967560 2026] [security2:error] [pid 643253:tid 643416] [client 74.7.241.169:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "webmail.vwh.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/suspendedpage.cgi"] [unique_id "amuDw8jqbtjBYzqM1uYxAwAAIEg"], referer: https://webmail.vwh.hfl.temporary.site/cgi-sys/suspendedpage.cgi
[Thu Jul 30 12:03:00.270191 2026] [security2:error] [pid 643253:tid 643397] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/orange3.php"] [unique_id "amuDxMjqbtjBYzqM1uYxBgAAAA0"]
[Thu Jul 30 12:03:00.270310 2026] [security2:error] [pid 643253:tid 643397] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/orange3.php"] [unique_id "amuDxMjqbtjBYzqM1uYxBgAAAA0"]
[Thu Jul 30 12:03:00.331649 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:00.336539 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:48220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDxMjqbtjBYzqM1uYxBwAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:00.852478 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuDxMjqbtjBYzqM1uYxEwAAAEE"]
[Thu Jul 30 12:03:00.852609 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuDxMjqbtjBYzqM1uYxEwAAAEE"]
[Thu Jul 30 12:03:00.955461 2026] [security2:error] [pid 643253:tid 643493] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDxMjqbtjBYzqM1uYxCwAAbUk"]
[Thu Jul 30 12:03:01.069560 2026] [core:notice] [pid 643253:tid 643494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:01.074726 2026] [security2:error] [pid 643253:tid 643494] [client 103.215.74.26:48228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDxcjqbtjBYzqM1uYxIQAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:01.234772 2026] [core:error] [pid 643253:tid 643489] [client 74.7.228.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:01.234801 2026] [core:error] [pid 643253:tid 643489] [client 74.7.228.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:01.234940 2026] [security2:error] [pid 643253:tid 643489] [client 74.7.228.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.met.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuDxcjqbtjBYzqM1uYxJwAAAGk"]
[Thu Jul 30 12:03:01.235567 2026] [security2:error] [pid 643253:tid 643483] [client 74.7.228.50:53876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.met.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuDxcjqbtjBYzqM1uYxJQAAY1I"]
[Thu Jul 30 12:03:01.294892 2026] [security2:error] [pid 643253:tid 643453] [client 20.100.187.246:58651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/json.php"] [unique_id "amuDxcjqbtjBYzqM1uYxLAAAAEU"]
[Thu Jul 30 12:03:01.338308 2026] [security2:error] [pid 643253:tid 643480] [client 185.191.171.6:58460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/"] [unique_id "amuDxcjqbtjBYzqM1uYxLQAAAGA"]
[Thu Jul 30 12:03:01.338457 2026] [security2:error] [pid 643253:tid 643480] [client 185.191.171.6:58460] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/"] [unique_id "amuDxcjqbtjBYzqM1uYxLQAAAGA"]
[Thu Jul 30 12:03:01.386850 2026] [security2:error] [pid 643253:tid 643430] [client 20.203.148.31:15172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/content.php"] [unique_id "amuDxcjqbtjBYzqM1uYxLwAAAC4"]
[Thu Jul 30 12:03:01.417009 2026] [security2:error] [pid 643253:tid 643404] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-the.php"] [unique_id "amuDxcjqbtjBYzqM1uYxMwAAABQ"]
[Thu Jul 30 12:03:01.417131 2026] [security2:error] [pid 643253:tid 643404] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/wp-the.php"] [unique_id "amuDxcjqbtjBYzqM1uYxMwAAABQ"]
[Thu Jul 30 12:03:01.796966 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:01.800833 2026] [security2:error] [pid 643253:tid 643456] [client 103.215.74.26:48240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDxcjqbtjBYzqM1uYxQAAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:01.930617 2026] [security2:error] [pid 643253:tid 643492] [client 20.203.148.31:57304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/accueil.php"] [unique_id "amuDxcjqbtjBYzqM1uYxRAAAAGw"]
[Thu Jul 30 12:03:01.998172 2026] [security2:error] [pid 643253:tid 643490] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/crgio.php"] [unique_id "amuDxcjqbtjBYzqM1uYxSAAAAGo"]
[Thu Jul 30 12:03:01.998280 2026] [security2:error] [pid 643253:tid 643490] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/crgio.php"] [unique_id "amuDxcjqbtjBYzqM1uYxSAAAAGo"]
[Thu Jul 30 12:03:02.436351 2026] [security2:error] [pid 643253:tid 643501] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuDxsjqbtjBYzqM1uYxUgAAAHU"]
[Thu Jul 30 12:03:02.436468 2026] [security2:error] [pid 643253:tid 643501] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuDxsjqbtjBYzqM1uYxUgAAAHU"]
[Thu Jul 30 12:03:02.520610 2026] [core:notice] [pid 643253:tid 643399] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:02.524505 2026] [security2:error] [pid 643253:tid 643399] [client 103.215.74.26:48262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDxsjqbtjBYzqM1uYxVgAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:02.561865 2026] [security2:error] [pid 643253:tid 643477] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ws13.php"] [unique_id "amuDxsjqbtjBYzqM1uYxWgAAAF0"]
[Thu Jul 30 12:03:02.561951 2026] [security2:error] [pid 643253:tid 643477] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ws13.php"] [unique_id "amuDxsjqbtjBYzqM1uYxWgAAAF0"]
[Thu Jul 30 12:03:02.683848 2026] [security2:error] [pid 643253:tid 643487] [client 20.203.148.31:41317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/dashboard.php"] [unique_id "amuDxsjqbtjBYzqM1uYxXgAAAGc"]
[Thu Jul 30 12:03:02.764622 2026] [security2:error] [pid 643253:tid 643482] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuDxsjqbtjBYzqM1uYxXwAAAGI"]
[Thu Jul 30 12:03:02.764746 2026] [security2:error] [pid 643253:tid 643482] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuDxsjqbtjBYzqM1uYxXwAAAGI"]
[Thu Jul 30 12:03:03.048446 2026] [security2:error] [pid 643253:tid 643386] [client 20.203.148.31:16003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/doc.php"] [unique_id "amuDx8jqbtjBYzqM1uYxbAAAAAI"]
[Thu Jul 30 12:03:03.094463 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/srontol.php"] [unique_id "amuDx8jqbtjBYzqM1uYxcAAAAGg"]
[Thu Jul 30 12:03:03.094599 2026] [security2:error] [pid 643253:tid 643488] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/srontol.php"] [unique_id "amuDx8jqbtjBYzqM1uYxcAAAAGg"]
[Thu Jul 30 12:03:03.202223 2026] [security2:error] [pid 643253:tid 643388] [client 85.208.96.199:16140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuDx8jqbtjBYzqM1uYxcgAAAAQ"]
[Thu Jul 30 12:03:03.202354 2026] [security2:error] [pid 643253:tid 643388] [client 85.208.96.199:16140] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuDx8jqbtjBYzqM1uYxcgAAAAQ"]
[Thu Jul 30 12:03:03.263929 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:03.269114 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:55702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDx8jqbtjBYzqM1uYxcwAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:03.462806 2026] [security2:error] [pid 643253:tid 643408] [client 20.203.148.31:41324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/radio.php"] [unique_id "amuDx8jqbtjBYzqM1uYxdAAAABg"]
[Thu Jul 30 12:03:03.503121 2026] [security2:error] [pid 643253:tid 643473] [client 20.100.187.246:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/mini.php"] [unique_id "amuDx8jqbtjBYzqM1uYxdQAAAFk"]
[Thu Jul 30 12:03:03.605439 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/miru3.php"] [unique_id "amuDx8jqbtjBYzqM1uYxegAAAGY"]
[Thu Jul 30 12:03:03.605591 2026] [security2:error] [pid 643253:tid 643486] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/miru3.php"] [unique_id "amuDx8jqbtjBYzqM1uYxegAAAGY"]
[Thu Jul 30 12:03:04.007152 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:04.011008 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:55718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDyMjqbtjBYzqM1uYxhAAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:04.175535 2026] [security2:error] [pid 643253:tid 643416] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ingfo.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjQAAACA"]
[Thu Jul 30 12:03:04.175650 2026] [security2:error] [pid 643253:tid 643416] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ingfo.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjQAAACA"]
[Thu Jul 30 12:03:04.230173 2026] [security2:error] [pid 643253:tid 643504] [client 176.241.66.87:65114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjgAAAHg"]
[Thu Jul 30 12:03:04.230381 2026] [security2:error] [pid 643253:tid 643504] [client 176.241.66.87:65114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjgAAAHg"]
[Thu Jul 30 12:03:04.470120 2026] [security2:error] [pid 643253:tid 643490] [client 20.100.187.246:57351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/chosen.php"] [unique_id "amuDyMjqbtjBYzqM1uYxjwAAAGo"]
[Thu Jul 30 12:03:04.769573 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ey5.php"] [unique_id "amuDyMjqbtjBYzqM1uYxlgAAAEE"]
[Thu Jul 30 12:03:04.769676 2026] [security2:error] [pid 643253:tid 643449] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/ey5.php"] [unique_id "amuDyMjqbtjBYzqM1uYxlgAAAEE"]
[Thu Jul 30 12:03:04.771764 2026] [core:notice] [pid 643253:tid 643448] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:04.775873 2026] [security2:error] [pid 643253:tid 643448] [client 103.215.74.26:55722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDyMjqbtjBYzqM1uYxlwAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:04.973936 2026] [security2:error] [pid 643253:tid 643470] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/xstelth.php"] [unique_id "amuDyMjqbtjBYzqM1uYxnAAAAFY"]
[Thu Jul 30 12:03:04.974077 2026] [security2:error] [pid 643253:tid 643470] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/xstelth.php"] [unique_id "amuDyMjqbtjBYzqM1uYxnAAAAFY"]
[Thu Jul 30 12:03:05.314519 2026] [security2:error] [pid 643253:tid 643398] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/584062352875874akp.php"] [unique_id "amuDycjqbtjBYzqM1uYxpAAAAA4"]
[Thu Jul 30 12:03:05.314633 2026] [security2:error] [pid 643253:tid 643398] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/584062352875874akp.php"] [unique_id "amuDycjqbtjBYzqM1uYxpAAAAA4"]
[Thu Jul 30 12:03:05.379644 2026] [security2:error] [pid 643253:tid 643432] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fine.php"] [unique_id "amuDycjqbtjBYzqM1uYxpQAAADA"]
[Thu Jul 30 12:03:05.379780 2026] [security2:error] [pid 643253:tid 643432] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.vanguardlegalassociates.team"] [uri "/fine.php"] [unique_id "amuDycjqbtjBYzqM1uYxpQAAADA"]
[Thu Jul 30 12:03:05.507867 2026] [core:notice] [pid 643253:tid 643439] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:05.514881 2026] [security2:error] [pid 643253:tid 643439] [client 103.215.74.26:55738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDycjqbtjBYzqM1uYxpwAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:05.643613 2026] [security2:error] [pid 643253:tid 643465] [client 20.100.187.246:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/kj.php"] [unique_id "amuDycjqbtjBYzqM1uYxqQAAAFE"]
[Thu Jul 30 12:03:05.668707 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/newfile.php"] [unique_id "amuDycjqbtjBYzqM1uYxrAAAAGM"]
[Thu Jul 30 12:03:05.668807 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/newfile.php"] [unique_id "amuDycjqbtjBYzqM1uYxrAAAAGM"]
[Thu Jul 30 12:03:05.946279 2026] [security2:error] [pid 643253:tid 643464] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDycjqbtjBYzqM1uYxpgAAUHo"]
[Thu Jul 30 12:03:06.011711 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tBEZGQz.php"] [unique_id "amuDysjqbtjBYzqM1uYxsAAAABY"]
[Thu Jul 30 12:03:06.011867 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tBEZGQz.php"] [unique_id "amuDysjqbtjBYzqM1uYxsAAAABY"]
[Thu Jul 30 12:03:06.354416 2026] [proxy:error] [pid 643253:tid 643481] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:06.354491 2026] [proxy_http:error] [pid 643253:tid 643481] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:06.355062 2026] [proxy:error] [pid 643253:tid 643481] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:06.355106 2026] [proxy_http:error] [pid 643253:tid 643481] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:06.355204 2026] [security2:error] [pid 643253:tid 643481] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDysjqbtjBYzqM1uYxuAAAAGE"]
[Thu Jul 30 12:03:06.502684 2026] [security2:error] [pid 643253:tid 643510] [client 47.128.27.6:64020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuDysjqbtjBYzqM1uYxuQAAAH4"]
[Thu Jul 30 12:03:06.684694 2026] [security2:error] [pid 643253:tid 643451] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/drykl.php"] [unique_id "amuDysjqbtjBYzqM1uYxugAAAEM"]
[Thu Jul 30 12:03:06.684827 2026] [security2:error] [pid 643253:tid 643451] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/drykl.php"] [unique_id "amuDysjqbtjBYzqM1uYxugAAAEM"]
[Thu Jul 30 12:03:06.701637 2026] [security2:error] [pid 643253:tid 643391] [client 20.203.148.31:27269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/dropdown.php"] [unique_id "amuDysjqbtjBYzqM1uYxuwAAAAc"]
[Thu Jul 30 12:03:07.012071 2026] [proxy:error] [pid 643253:tid 643450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:07.012149 2026] [proxy_http:error] [pid 643253:tid 643450] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:07.012707 2026] [proxy:error] [pid 643253:tid 643450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:07.012765 2026] [proxy_http:error] [pid 643253:tid 643450] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:07.012855 2026] [security2:error] [pid 643253:tid 643450] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDy8jqbtjBYzqM1uYxwgAAAEI"]
[Thu Jul 30 12:03:07.190877 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:07.303783 2026] [security2:error] [pid 643253:tid 643369] [remote 185.61.152.44:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.152.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuDy8jqbtjBYzqM1uYxygAAeHI"]
[Thu Jul 30 12:03:07.337272 2026] [security2:error] [pid 643253:tid 643437] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ls.php"] [unique_id "amuDy8jqbtjBYzqM1uYxywAAADU"]
[Thu Jul 30 12:03:07.337374 2026] [security2:error] [pid 643253:tid 643437] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ls.php"] [unique_id "amuDy8jqbtjBYzqM1uYxywAAADU"]
[Thu Jul 30 12:03:07.438223 2026] [security2:error] [pid 643253:tid 643462] [client 20.100.187.246:35929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-files.php"] [unique_id "amuDy8jqbtjBYzqM1uYxzAAAAE4"]
[Thu Jul 30 12:03:07.670324 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/dx.php"] [unique_id "amuDy8jqbtjBYzqM1uYxzwAAABs"]
[Thu Jul 30 12:03:07.670439 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/dx.php"] [unique_id "amuDy8jqbtjBYzqM1uYxzwAAABs"]
[Thu Jul 30 12:03:08.028395 2026] [security2:error] [pid 643253:tid 643466] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/mac.php"] [unique_id "amuDzMjqbtjBYzqM1uYx2QAAAFI"]
[Thu Jul 30 12:03:08.028485 2026] [security2:error] [pid 643253:tid 643466] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/mac.php"] [unique_id "amuDzMjqbtjBYzqM1uYx2QAAAFI"]
[Thu Jul 30 12:03:08.110808 2026] [security2:error] [pid 643253:tid 643454] [client 20.203.148.31:23130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ee.php"] [unique_id "amuDzMjqbtjBYzqM1uYx2gAAAEY"]
[Thu Jul 30 12:03:08.290421 2026] [security2:error] [pid 643253:tid 643266] [remote 74.7.241.59:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuDzMjqbtjBYzqM1uYx3gAAcAs"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:03:08.297912 2026] [security2:error] [pid 643253:tid 643395] [client 20.100.187.246:63511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-setup.php"] [unique_id "amuDzMjqbtjBYzqM1uYx3wAAAAs"]
[Thu Jul 30 12:03:08.356368 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/485.php"] [unique_id "amuDzMjqbtjBYzqM1uYx4wAAACs"]
[Thu Jul 30 12:03:08.356495 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/485.php"] [unique_id "amuDzMjqbtjBYzqM1uYx4wAAACs"]
[Thu Jul 30 12:03:08.693357 2026] [security2:error] [pid 643253:tid 643453] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gelio1.php"] [unique_id "amuDzMjqbtjBYzqM1uYx5AAAAEU"]
[Thu Jul 30 12:03:08.693474 2026] [security2:error] [pid 643253:tid 643453] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gelio1.php"] [unique_id "amuDzMjqbtjBYzqM1uYx5AAAAEU"]
[Thu Jul 30 12:03:09.023934 2026] [security2:error] [pid 643253:tid 643471] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/lp6.php"] [unique_id "amuDzcjqbtjBYzqM1uYx6wAAAFc"]
[Thu Jul 30 12:03:09.024071 2026] [security2:error] [pid 643253:tid 643471] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/lp6.php"] [unique_id "amuDzcjqbtjBYzqM1uYx6wAAAFc"]
[Thu Jul 30 12:03:09.363634 2026] [security2:error] [pid 643253:tid 643505] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuDzcjqbtjBYzqM1uYx8AAAAHk"]
[Thu Jul 30 12:03:09.363741 2026] [security2:error] [pid 643253:tid 643505] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuDzcjqbtjBYzqM1uYx8AAAAHk"]
[Thu Jul 30 12:03:09.701821 2026] [proxy:error] [pid 643253:tid 643492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:09.701888 2026] [proxy_http:error] [pid 643253:tid 643492] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:09.702462 2026] [proxy:error] [pid 643253:tid 643492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:09.702506 2026] [proxy_http:error] [pid 643253:tid 643492] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:09.702598 2026] [security2:error] [pid 643253:tid 643492] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDzcjqbtjBYzqM1uYx-AAAAGw"]
[Thu Jul 30 12:03:09.997478 2026] [security2:error] [pid 643253:tid 643462] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/w3llscc.php"] [unique_id "amuDzcjqbtjBYzqM1uYx_wAAAE4"]
[Thu Jul 30 12:03:09.997617 2026] [security2:error] [pid 643253:tid 643462] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/w3llscc.php"] [unique_id "amuDzcjqbtjBYzqM1uYx_wAAAE4"]
[Thu Jul 30 12:03:10.014649 2026] [security2:error] [pid 643253:tid 643461] [client 20.203.148.31:33439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/flower.php"] [unique_id "amuDzsjqbtjBYzqM1uYyAAAAAE0"]
[Thu Jul 30 12:03:10.300014 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/miru3.php"] [unique_id "amuDzsjqbtjBYzqM1uYyAQAAABs"]
[Thu Jul 30 12:03:10.300126 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/miru3.php"] [unique_id "amuDzsjqbtjBYzqM1uYyAQAAABs"]
[Thu Jul 30 12:03:10.622179 2026] [security2:error] [pid 643253:tid 643464] [client 20.100.187.246:63339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/defaults.php"] [unique_id "amuDzsjqbtjBYzqM1uYyDAAAAFA"]
[Thu Jul 30 12:03:10.635368 2026] [security2:error] [pid 643253:tid 643394] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/autoload_classmap.php"] [unique_id "amuDzsjqbtjBYzqM1uYyDQAAAAo"]
[Thu Jul 30 12:03:10.635479 2026] [security2:error] [pid 643253:tid 643394] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/autoload_classmap.php"] [unique_id "amuDzsjqbtjBYzqM1uYyDQAAAAo"]
[Thu Jul 30 12:03:10.968003 2026] [proxy:error] [pid 643253:tid 643414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:10.968077 2026] [proxy_http:error] [pid 643253:tid 643414] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:10.968660 2026] [proxy:error] [pid 643253:tid 643414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:10.968704 2026] [proxy_http:error] [pid 643253:tid 643414] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:10.968795 2026] [security2:error] [pid 643253:tid 643414] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDzsjqbtjBYzqM1uYyEgAAAB4"]
[Thu Jul 30 12:03:11.084060 2026] [security2:error] [pid 643253:tid 643477] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuDzsjqbtjBYzqM1uYyCQAAXQ0"]
[Thu Jul 30 12:03:11.300240 2026] [security2:error] [pid 643253:tid 643436] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/index.php"] [unique_id "amuDz8jqbtjBYzqM1uYyFwAAADQ"]
[Thu Jul 30 12:03:11.300364 2026] [security2:error] [pid 643253:tid 643436] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/index.php"] [unique_id "amuDz8jqbtjBYzqM1uYyFwAAADQ"]
[Thu Jul 30 12:03:11.309539 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:11.317032 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:55746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuDz8jqbtjBYzqM1uYyGAAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:11.600967 2026] [security2:error] [pid 643253:tid 643439] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/av.php"] [unique_id "amuDz8jqbtjBYzqM1uYyHwAAADc"]
[Thu Jul 30 12:03:11.601126 2026] [security2:error] [pid 643253:tid 643439] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/av.php"] [unique_id "amuDz8jqbtjBYzqM1uYyHwAAADc"]
[Thu Jul 30 12:03:11.909673 2026] [proxy:error] [pid 643253:tid 643404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:11.909748 2026] [proxy_http:error] [pid 643253:tid 643404] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:11.910325 2026] [proxy:error] [pid 643253:tid 643404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:11.910371 2026] [proxy_http:error] [pid 643253:tid 643404] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:11.910467 2026] [security2:error] [pid 643253:tid 643404] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuDz8jqbtjBYzqM1uYyIgAAABQ"]
[Thu Jul 30 12:03:12.244474 2026] [proxy:error] [pid 643253:tid 643431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:12.244550 2026] [proxy_http:error] [pid 643253:tid 643431] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:12.245119 2026] [proxy:error] [pid 643253:tid 643431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:12.245162 2026] [proxy_http:error] [pid 643253:tid 643431] [client 20.100.173.28:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:12.245253 2026] [security2:error] [pid 643253:tid 643431] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuD0MjqbtjBYzqM1uYyKQAAAC8"]
[Thu Jul 30 12:03:12.557781 2026] [security2:error] [pid 643253:tid 643401] [client 20.100.187.246:63322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/gtc.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMAAAABE"]
[Thu Jul 30 12:03:12.572869 2026] [security2:error] [pid 643253:tid 643463] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tiny.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMQAAAE8"]
[Thu Jul 30 12:03:12.572946 2026] [security2:error] [pid 643253:tid 643463] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tiny.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMQAAAE8"]
[Thu Jul 30 12:03:12.917515 2026] [security2:error] [pid 643253:tid 643468] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMwAAAFQ"]
[Thu Jul 30 12:03:12.917636 2026] [security2:error] [pid 643253:tid 643468] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuD0MjqbtjBYzqM1uYyMwAAAFQ"]
[Thu Jul 30 12:03:13.001947 2026] [security2:error] [pid 643253:tid 643454] [client 20.203.148.31:23128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/gecko-new.php"] [unique_id "amuD0cjqbtjBYzqM1uYyOgAAAEY"]
[Thu Jul 30 12:03:13.250466 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/zrrhj.php"] [unique_id "amuD0cjqbtjBYzqM1uYyRAAAAAA"]
[Thu Jul 30 12:03:13.250571 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/zrrhj.php"] [unique_id "amuD0cjqbtjBYzqM1uYyRAAAAAA"]
[Thu Jul 30 12:03:13.492290 2026] [security2:error] [pid 643253:tid 643461] [client 127.0.0.1:26462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuD0cjqbtjBYzqM1uYyTAAAAE0"]
[Thu Jul 30 12:03:13.492381 2026] [security2:error] [pid 643253:tid 643397] [client 74.7.175.152:37736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.deltaedu.net"] [uri "/robots.txt"] [unique_id "amuD0cjqbtjBYzqM1uYySwAADRM"]
[Thu Jul 30 12:03:13.547724 2026] [security2:error] [pid 643253:tid 643503] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuD0cjqbtjBYzqM1uYyUgAAAHc"]
[Thu Jul 30 12:03:13.547818 2026] [security2:error] [pid 643253:tid 643503] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuD0cjqbtjBYzqM1uYyUgAAAHc"]
[Thu Jul 30 12:03:13.856870 2026] [security2:error] [pid 643253:tid 643393] [client 20.203.148.31:21518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/m.php"] [unique_id "amuD0cjqbtjBYzqM1uYyWQAAAAk"]
[Thu Jul 30 12:03:13.891971 2026] [security2:error] [pid 643253:tid 643477] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wpgum.php"] [unique_id "amuD0cjqbtjBYzqM1uYyWgAAAF0"]
[Thu Jul 30 12:03:13.892083 2026] [security2:error] [pid 643253:tid 643477] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wpgum.php"] [unique_id "amuD0cjqbtjBYzqM1uYyWgAAAF0"]
[Thu Jul 30 12:03:14.196686 2026] [security2:error] [pid 643253:tid 643457] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ywwbf.php"] [unique_id "amuD0sjqbtjBYzqM1uYyYAAAAEk"]
[Thu Jul 30 12:03:14.196790 2026] [security2:error] [pid 643253:tid 643457] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ywwbf.php"] [unique_id "amuD0sjqbtjBYzqM1uYyYAAAAEk"]
[Thu Jul 30 12:03:14.240829 2026] [security2:error] [pid 643253:tid 643491] [client 20.100.187.246:63284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/import.php"] [unique_id "amuD0sjqbtjBYzqM1uYyYQAAAGs"]
[Thu Jul 30 12:03:14.485774 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:14.581742 2026] [core:notice] [pid 643253:tid 643303] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:14.836520 2026] [lsapi:error] [pid 642360:tid 642436] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:03:14.852725 2026] [core:notice] [pid 643253:tid 643390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:14.928203 2026] [security2:error] [pid 643253:tid 643435] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuD0sjqbtjBYzqM1uYyXwAAMyg"]
[Thu Jul 30 12:03:15.068626 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.187.246:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/lufix.php"] [unique_id "amuD08jqbtjBYzqM1uYycwAAABY"]
[Thu Jul 30 12:03:15.461607 2026] [security2:error] [pid 643253:tid 643463] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/xoldj.php"] [unique_id "amuD08jqbtjBYzqM1uYydQAAAE8"]
[Thu Jul 30 12:03:15.461718 2026] [security2:error] [pid 643253:tid 643463] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/xoldj.php"] [unique_id "amuD08jqbtjBYzqM1uYydQAAAE8"]
[Thu Jul 30 12:03:15.574406 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:15.677458 2026] [security2:error] [pid 643253:tid 643468] [client 20.100.187.246:35757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/Geforce.php"] [unique_id "amuD08jqbtjBYzqM1uYyfgAAAFQ"]
[Thu Jul 30 12:03:15.806551 2026] [security2:error] [pid 643253:tid 643461] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/f35.php"] [unique_id "amuD08jqbtjBYzqM1uYygAAAAE0"]
[Thu Jul 30 12:03:15.806661 2026] [security2:error] [pid 643253:tid 643461] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/f35.php"] [unique_id "amuD08jqbtjBYzqM1uYygAAAAE0"]
[Thu Jul 30 12:03:15.832551 2026] [security2:error] [pid 643253:tid 643397] [client 185.191.171.10:36386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/21/maioria-dos-novatos-na-camara-esta-em-pl-uniao-brasil-e-mdb/"] [unique_id "amuD08jqbtjBYzqM1uYygQAAAA0"]
[Thu Jul 30 12:03:15.832655 2026] [security2:error] [pid 643253:tid 643397] [client 185.191.171.10:36386] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/21/maioria-dos-novatos-na-camara-esta-em-pl-uniao-brasil-e-mdb/"] [unique_id "amuD08jqbtjBYzqM1uYygQAAAA0"]
[Thu Jul 30 12:03:16.121737 2026] [security2:error] [pid 643253:tid 643415] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gk.php"] [unique_id "amuD1MjqbtjBYzqM1uYyggAAAB8"]
[Thu Jul 30 12:03:16.121871 2026] [security2:error] [pid 643253:tid 643415] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gk.php"] [unique_id "amuD1MjqbtjBYzqM1uYyggAAAB8"]
[Thu Jul 30 12:03:16.194610 2026] [security2:error] [pid 643253:tid 643480] [client 20.203.148.31:18521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuD1MjqbtjBYzqM1uYyhgAAAGA"]
[Thu Jul 30 12:03:16.205861 2026] [security2:error] [pid 643253:tid 643475] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD08jqbtjBYzqM1uYyfQAAWwU"]
[Thu Jul 30 12:03:16.431950 2026] [security2:error] [pid 643253:tid 643509] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/584062352875874akp.php"] [unique_id "amuD1MjqbtjBYzqM1uYyjAAAAH0"]
[Thu Jul 30 12:03:16.432071 2026] [security2:error] [pid 643253:tid 643509] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/584062352875874akp.php"] [unique_id "amuD1MjqbtjBYzqM1uYyjAAAAH0"]
[Thu Jul 30 12:03:16.455043 2026] [proxy:error] [pid 643253:tid 643476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:16.455100 2026] [proxy_http:error] [pid 643253:tid 643476] [client 192.210.150.196:45418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:16.455808 2026] [proxy:error] [pid 643253:tid 643476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:16.455853 2026] [proxy_http:error] [pid 643253:tid 643476] [client 192.210.150.196:45418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:16.600406 2026] [security2:error] [pid 643253:tid 643411] [client 176.241.66.87:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD1MjqbtjBYzqM1uYyjgAAABs"]
[Thu Jul 30 12:03:16.600556 2026] [security2:error] [pid 643253:tid 643411] [client 176.241.66.87:1591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD1MjqbtjBYzqM1uYyjgAAABs"]
[Thu Jul 30 12:03:17.119167 2026] [core:notice] [pid 643253:tid 643487] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:17.123853 2026] [security2:error] [pid 643253:tid 643487] [client 103.215.74.26:47788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD1cjqbtjBYzqM1uYylQAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:17.177514 2026] [security2:error] [pid 643253:tid 643448] [client 20.100.187.246:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/a4.php"] [unique_id "amuD1cjqbtjBYzqM1uYynAAAAEA"]
[Thu Jul 30 12:03:17.289873 2026] [security2:error] [pid 643253:tid 643465] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wper3.php"] [unique_id "amuD1cjqbtjBYzqM1uYyngAAAFE"]
[Thu Jul 30 12:03:17.289990 2026] [security2:error] [pid 643253:tid 643465] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wper3.php"] [unique_id "amuD1cjqbtjBYzqM1uYyngAAAFE"]
[Thu Jul 30 12:03:17.601386 2026] [security2:error] [pid 643253:tid 643439] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bthil.php"] [unique_id "amuD1cjqbtjBYzqM1uYynwAAADc"]
[Thu Jul 30 12:03:17.601504 2026] [security2:error] [pid 643253:tid 643439] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bthil.php"] [unique_id "amuD1cjqbtjBYzqM1uYynwAAADc"]
[Thu Jul 30 12:03:17.696877 2026] [security2:error] [pid 643253:tid 643393] [client 172.237.109.114:50037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1cjqbtjBYzqM1uYylwAAAAk"]
[Thu Jul 30 12:03:17.832080 2026] [proxy:error] [pid 643253:tid 643429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:17.832172 2026] [proxy_http:error] [pid 643253:tid 643429] [client 192.210.150.196:32778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:17.832745 2026] [proxy:error] [pid 643253:tid 643429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:17.832787 2026] [proxy_http:error] [pid 643253:tid 643429] [client 192.210.150.196:32778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:17.860650 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:17.865014 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:47800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD1cjqbtjBYzqM1uYypwAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:17.915329 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wyzer1.php"] [unique_id "amuD1cjqbtjBYzqM1uYyqAAAAGM"]
[Thu Jul 30 12:03:17.915437 2026] [security2:error] [pid 643253:tid 643483] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wyzer1.php"] [unique_id "amuD1cjqbtjBYzqM1uYyqAAAAGM"]
[Thu Jul 30 12:03:18.246958 2026] [security2:error] [pid 643253:tid 643401] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/mh.php"] [unique_id "amuD1sjqbtjBYzqM1uYytgAAABE"]
[Thu Jul 30 12:03:18.247102 2026] [security2:error] [pid 643253:tid 643401] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/mh.php"] [unique_id "amuD1sjqbtjBYzqM1uYytgAAABE"]
[Thu Jul 30 12:03:18.557253 2026] [security2:error] [pid 643253:tid 643450] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuD1sjqbtjBYzqM1uYyugAAAEI"]
[Thu Jul 30 12:03:18.557413 2026] [security2:error] [pid 643253:tid 643450] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuD1sjqbtjBYzqM1uYyugAAAEI"]
[Thu Jul 30 12:03:18.565967 2026] [core:notice] [pid 643253:tid 643321] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:18.584761 2026] [security2:error] [pid 643253:tid 643460] [client 172.237.109.114:17696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYyrQAAAEw"]
[Thu Jul 30 12:03:18.587049 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:18.594487 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:47810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD1sjqbtjBYzqM1uYyvAAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:18.645242 2026] [security2:error] [pid 643253:tid 643390] [client 172.237.109.114:34600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYyrgAAAAY"]
[Thu Jul 30 12:03:18.651227 2026] [security2:error] [pid 643253:tid 643435] [client 172.237.109.114:56197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYyrwAAADM"]
[Thu Jul 30 12:03:18.653951 2026] [security2:error] [pid 643253:tid 643440] [client 172.237.109.114:32702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYysAAAADg"]
[Thu Jul 30 12:03:18.695570 2026] [security2:error] [pid 643253:tid 643467] [client 172.237.109.114:40631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYysQAAAFM"]
[Thu Jul 30 12:03:18.774198 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:18.868584 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuD1sjqbtjBYzqM1uYyxQAAAGA"]
[Thu Jul 30 12:03:18.868691 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuD1sjqbtjBYzqM1uYyxQAAAGA"]
[Thu Jul 30 12:03:18.868780 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuD1sjqbtjBYzqM1uYyxQAAAGA"]
[Thu Jul 30 12:03:18.967318 2026] [security2:error] [pid 643253:tid 643461] [client 20.100.187.246:63317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/accueil.php"] [unique_id "amuD1sjqbtjBYzqM1uYyxgAAAE0"]
[Thu Jul 30 12:03:19.205203 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/chosen.php"] [unique_id "amuD18jqbtjBYzqM1uYyyQAAABs"]
[Thu Jul 30 12:03:19.205370 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/chosen.php"] [unique_id "amuD18jqbtjBYzqM1uYyyQAAABs"]
[Thu Jul 30 12:03:19.313265 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:19.317734 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:47832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD18jqbtjBYzqM1uYy0AAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:19.526697 2026] [security2:error] [pid 643253:tid 643487] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/sd.php"] [unique_id "amuD18jqbtjBYzqM1uYy0QAAAGc"]
[Thu Jul 30 12:03:19.526852 2026] [security2:error] [pid 643253:tid 643487] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/sd.php"] [unique_id "amuD18jqbtjBYzqM1uYy0QAAAGc"]
[Thu Jul 30 12:03:19.578256 2026] [security2:error] [pid 643253:tid 643509] [client 172.237.109.114:50182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD18jqbtjBYzqM1uYyxwAAAH0"]
[Thu Jul 30 12:03:19.836448 2026] [security2:error] [pid 643253:tid 643455] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/z60.php"] [unique_id "amuD18jqbtjBYzqM1uYy1wAAAEc"]
[Thu Jul 30 12:03:19.836529 2026] [security2:error] [pid 643253:tid 643455] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/z60.php"] [unique_id "amuD18jqbtjBYzqM1uYy1wAAAEc"]
[Thu Jul 30 12:03:20.042597 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:20.046932 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:47836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD2MjqbtjBYzqM1uYy2gAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:20.141175 2026] [security2:error] [pid 643253:tid 643471] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/home.php"] [unique_id "amuD2MjqbtjBYzqM1uYy4QAAAFc"]
[Thu Jul 30 12:03:20.141347 2026] [security2:error] [pid 643253:tid 643471] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/home.php"] [unique_id "amuD2MjqbtjBYzqM1uYy4QAAAFc"]
[Thu Jul 30 12:03:20.445826 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ws58.php"] [unique_id "amuD2MjqbtjBYzqM1uYy6AAAABY"]
[Thu Jul 30 12:03:20.445929 2026] [security2:error] [pid 643253:tid 643406] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ws58.php"] [unique_id "amuD2MjqbtjBYzqM1uYy6AAAABY"]
[Thu Jul 30 12:03:20.505727 2026] [security2:error] [pid 643253:tid 643418] [client 216.73.216.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuD1sjqbtjBYzqM1uYytQAAIkM"], referer: http://www.spececigarette.com/sitemap.xml
[Thu Jul 30 12:03:20.592443 2026] [security2:error] [pid 643253:tid 643430] [client 172.237.109.114:40879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD2MjqbtjBYzqM1uYy3wAAAC4"]
[Thu Jul 30 12:03:20.601390 2026] [security2:error] [pid 643253:tid 643439] [client 172.237.109.114:13796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD2MjqbtjBYzqM1uYy3gAAADc"]
[Thu Jul 30 12:03:20.653960 2026] [security2:error] [pid 643253:tid 643444] [client 172.237.109.114:28938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD2MjqbtjBYzqM1uYy4AAAADw"]
[Thu Jul 30 12:03:20.769091 2026] [security2:error] [pid 643253:tid 643431] [client 20.100.187.246:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/dashboard.php"] [unique_id "amuD2MjqbtjBYzqM1uYy6wAAAC8"]
[Thu Jul 30 12:03:20.789096 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gulu.php"] [unique_id "amuD2MjqbtjBYzqM1uYy7QAAAG8"]
[Thu Jul 30 12:03:20.789195 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/gulu.php"] [unique_id "amuD2MjqbtjBYzqM1uYy7QAAAG8"]
[Thu Jul 30 12:03:20.808042 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:20.812164 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:47838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD2MjqbtjBYzqM1uYy8AAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:21.105796 2026] [security2:error] [pid 643253:tid 643419] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuD2cjqbtjBYzqM1uYy9AAAACM"]
[Thu Jul 30 12:03:21.105910 2026] [security2:error] [pid 643253:tid 643419] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuD2cjqbtjBYzqM1uYy9AAAACM"]
[Thu Jul 30 12:03:21.280327 2026] [security2:error] [pid 643253:tid 643505] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD2MjqbtjBYzqM1uYy6gAAeVI"]
[Thu Jul 30 12:03:21.436021 2026] [security2:error] [pid 643253:tid 643473] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wpls.php"] [unique_id "amuD2cjqbtjBYzqM1uYy_QAAAFk"]
[Thu Jul 30 12:03:21.436133 2026] [security2:error] [pid 643253:tid 643473] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wpls.php"] [unique_id "amuD2cjqbtjBYzqM1uYy_QAAAFk"]
[Thu Jul 30 12:03:21.546660 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:21.551033 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:47842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD2cjqbtjBYzqM1uYy_gAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:21.791143 2026] [security2:error] [pid 643253:tid 643490] [client 20.100.187.246:63529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/radio.php"] [unique_id "amuD2cjqbtjBYzqM1uYzBAAAAGo"]
[Thu Jul 30 12:03:22.276963 2026] [security2:error] [pid 643253:tid 643448] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/php.php"] [unique_id "amuD2sjqbtjBYzqM1uYzDwAAAEA"]
[Thu Jul 30 12:03:22.277097 2026] [security2:error] [pid 643253:tid 643448] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/php.php"] [unique_id "amuD2sjqbtjBYzqM1uYzDwAAAEA"]
[Thu Jul 30 12:03:22.290248 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:22.294249 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:47844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD2sjqbtjBYzqM1uYzEAAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:22.526995 2026] [autoindex:error] [pid 643253:tid 643432] [client 34.224.175.62:38407] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:03:22.561089 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:22.630521 2026] [security2:error] [pid 643253:tid 643423] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/100.php"] [unique_id "amuD2sjqbtjBYzqM1uYzHAAAACc"]
[Thu Jul 30 12:03:22.630633 2026] [security2:error] [pid 643253:tid 643423] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/100.php"] [unique_id "amuD2sjqbtjBYzqM1uYzHAAAACc"]
[Thu Jul 30 12:03:22.661804 2026] [security2:error] [pid 643253:tid 643509] [client 173.252.87.112:45156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ecvh.ae"] [uri "/index.php"] [unique_id "amuD2sjqbtjBYzqM1uYzDgAAAH0"]
[Thu Jul 30 12:03:22.934946 2026] [security2:error] [pid 643253:tid 643452] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/BDKR28WP.php"] [unique_id "amuD2sjqbtjBYzqM1uYzIgAAAEQ"]
[Thu Jul 30 12:03:22.935057 2026] [security2:error] [pid 643253:tid 643452] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/BDKR28WP.php"] [unique_id "amuD2sjqbtjBYzqM1uYzIgAAAEQ"]
[Thu Jul 30 12:03:23.254964 2026] [security2:error] [pid 643253:tid 643444] [client 173.252.87.112:45170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecvh.ae"] [uri "/index.php"] [unique_id "amuD28jqbtjBYzqM1uYzKQAAADw"]
[Thu Jul 30 12:03:23.274464 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/browse.php"] [unique_id "amuD28jqbtjBYzqM1uYzKgAAAG8"]
[Thu Jul 30 12:03:23.274557 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/browse.php"] [unique_id "amuD28jqbtjBYzqM1uYzKgAAAG8"]
[Thu Jul 30 12:03:23.540911 2026] [security2:error] [pid 643253:tid 643465] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD2sjqbtjBYzqM1uYzIAAAUWc"]
[Thu Jul 30 12:03:23.548781 2026] [security2:error] [pid 643253:tid 643474] [client 173.252.87.4:51340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ecvh.ae"] [uri "/index.php"] [unique_id "amuD28jqbtjBYzqM1uYzMwAAAFo"]
[Thu Jul 30 12:03:23.587188 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-good.php"] [unique_id "amuD28jqbtjBYzqM1uYzSAAAAGA"]
[Thu Jul 30 12:03:23.587280 2026] [security2:error] [pid 643253:tid 643480] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-good.php"] [unique_id "amuD28jqbtjBYzqM1uYzSAAAAGA"]
[Thu Jul 30 12:03:23.895822 2026] [security2:error] [pid 643253:tid 643500] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/8573.php"] [unique_id "amuD28jqbtjBYzqM1uYzSwAAAHQ"]
[Thu Jul 30 12:03:23.895927 2026] [security2:error] [pid 643253:tid 643500] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/8573.php"] [unique_id "amuD28jqbtjBYzqM1uYzSwAAAHQ"]
[Thu Jul 30 12:03:24.063830 2026] [security2:error] [pid 643253:tid 643385] [client 173.252.87.4:51348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecvh.ae"] [uri "/index.php"] [unique_id "amuD3MjqbtjBYzqM1uYzZgAAAAE"]
[Thu Jul 30 12:03:24.227305 2026] [security2:error] [pid 643253:tid 643502] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/install.php"] [unique_id "amuD3MjqbtjBYzqM1uYzaAAAAHY"]
[Thu Jul 30 12:03:24.227420 2026] [security2:error] [pid 643253:tid 643502] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/install.php"] [unique_id "amuD3MjqbtjBYzqM1uYzaAAAAHY"]
[Thu Jul 30 12:03:24.564873 2026] [security2:error] [pid 643253:tid 643445] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/classwithtostring.php"] [unique_id "amuD3MjqbtjBYzqM1uYzbAAAAD0"]
[Thu Jul 30 12:03:24.564968 2026] [security2:error] [pid 643253:tid 643445] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/classwithtostring.php"] [unique_id "amuD3MjqbtjBYzqM1uYzbAAAAD0"]
[Thu Jul 30 12:03:24.924904 2026] [security2:error] [pid 643253:tid 643470] [client 173.252.87.7:44604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecvh.ae"] [uri "/index.php"] [unique_id "amuD3MjqbtjBYzqM1uYzcAAAVhU"]
[Thu Jul 30 12:03:25.222813 2026] [security2:error] [pid 643253:tid 643452] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ohct.php"] [unique_id "amuD3cjqbtjBYzqM1uYzdwAAAEQ"]
[Thu Jul 30 12:03:25.222921 2026] [security2:error] [pid 643253:tid 643452] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ohct.php"] [unique_id "amuD3cjqbtjBYzqM1uYzdwAAAEQ"]
[Thu Jul 30 12:03:25.528933 2026] [security2:error] [pid 643253:tid 643405] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bless.php"] [unique_id "amuD3cjqbtjBYzqM1uYzfgAAABU"]
[Thu Jul 30 12:03:25.529041 2026] [security2:error] [pid 643253:tid 643405] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bless.php"] [unique_id "amuD3cjqbtjBYzqM1uYzfgAAABU"]
[Thu Jul 30 12:03:25.843999 2026] [proxy:error] [pid 643253:tid 643477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:25.844072 2026] [proxy_http:error] [pid 643253:tid 643477] [client 192.210.150.196:45434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:25.844839 2026] [proxy:error] [pid 643253:tid 643477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:25.844891 2026] [proxy_http:error] [pid 643253:tid 643477] [client 192.210.150.196:45434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:25.879665 2026] [security2:error] [pid 643253:tid 643397] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuD3cjqbtjBYzqM1uYziwAAAA0"]
[Thu Jul 30 12:03:25.879772 2026] [security2:error] [pid 643253:tid 643397] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuD3cjqbtjBYzqM1uYziwAAAA0"]
[Thu Jul 30 12:03:26.190416 2026] [security2:error] [pid 643253:tid 643504] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuD3sjqbtjBYzqM1uYzlQAAAHg"]
[Thu Jul 30 12:03:26.190501 2026] [security2:error] [pid 643253:tid 643504] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuD3sjqbtjBYzqM1uYzlQAAAHg"]
[Thu Jul 30 12:03:26.199285 2026] [security2:error] [pid 643253:tid 643437] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD3cjqbtjBYzqM1uYzgwAANSE"]
[Thu Jul 30 12:03:26.502400 2026] [security2:error] [pid 643253:tid 643399] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ta0ol.php"] [unique_id "amuD3sjqbtjBYzqM1uYzlwAAAA8"]
[Thu Jul 30 12:03:26.502511 2026] [security2:error] [pid 643253:tid 643399] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ta0ol.php"] [unique_id "amuD3sjqbtjBYzqM1uYzlwAAAA8"]
[Thu Jul 30 12:03:26.806380 2026] [security2:error] [pid 643253:tid 643447] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/sa.php7"] [unique_id "amuD3sjqbtjBYzqM1uYznwAAAD8"]
[Thu Jul 30 12:03:26.806507 2026] [security2:error] [pid 643253:tid 643447] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/sa.php7"] [unique_id "amuD3sjqbtjBYzqM1uYznwAAAD8"]
[Thu Jul 30 12:03:27.118724 2026] [security2:error] [pid 643253:tid 643423] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-class.php"] [unique_id "amuD38jqbtjBYzqM1uYz5gAAACc"]
[Thu Jul 30 12:03:27.118816 2026] [security2:error] [pid 643253:tid 643423] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-class.php"] [unique_id "amuD38jqbtjBYzqM1uYz5gAAACc"]
[Thu Jul 30 12:03:27.344334 2026] [security2:error] [pid 643253:tid 643492] [client 176.241.66.87:2470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD38jqbtjBYzqM1uY0cAAAAGw"]
[Thu Jul 30 12:03:27.344442 2026] [security2:error] [pid 643253:tid 643492] [client 176.241.66.87:2470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD38jqbtjBYzqM1uY0cAAAAGw"]
[Thu Jul 30 12:03:27.467810 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/8.php"] [unique_id "amuD38jqbtjBYzqM1uY0lwAAACs"]
[Thu Jul 30 12:03:27.467903 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/8.php"] [unique_id "amuD38jqbtjBYzqM1uY0lwAAACs"]
[Thu Jul 30 12:03:27.724834 2026] [security2:error] [pid 643253:tid 643448] [client 50.6.43.217:37500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuD38jqbtjBYzqM1uY0oQAAAEA"]
[Thu Jul 30 12:03:27.734341 2026] [security2:error] [pid 643253:tid 643396] [client 50.6.43.217:37504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuD38jqbtjBYzqM1uY0owAAAAw"]
[Thu Jul 30 12:03:27.744790 2026] [security2:error] [pid 643253:tid 643387] [client 50.6.43.217:37510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuD38jqbtjBYzqM1uY0pAAAAAM"]
[Thu Jul 30 12:03:27.998445 2026] [security2:error] [pid 643253:tid 643455] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bootstrap.php"] [unique_id "amuD38jqbtjBYzqM1uY0rAAAAEc"]
[Thu Jul 30 12:03:27.998531 2026] [security2:error] [pid 643253:tid 643455] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/bootstrap.php"] [unique_id "amuD38jqbtjBYzqM1uY0rAAAAEc"]
[Thu Jul 30 12:03:28.043334 2026] [core:notice] [pid 643253:tid 643432] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:28.048127 2026] [security2:error] [pid 643253:tid 643432] [client 103.215.74.26:22266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD4MjqbtjBYzqM1uY0rQAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:28.306522 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-blog-header.php"] [unique_id "amuD4MjqbtjBYzqM1uY0uAAAAG8"]
[Thu Jul 30 12:03:28.306624 2026] [security2:error] [pid 643253:tid 643495] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-blog-header.php"] [unique_id "amuD4MjqbtjBYzqM1uY0uAAAAG8"]
[Thu Jul 30 12:03:28.466756 2026] [security2:error] [pid 643253:tid 643510] [client 20.100.187.246:35742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wpsml-sys.php"] [unique_id "amuD4MjqbtjBYzqM1uY0uQAAAH4"]
[Thu Jul 30 12:03:28.506150 2026] [core:notice] [pid 643253:tid 643491] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:28.525418 2026] [proxy:error] [pid 643253:tid 643481] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:28.525515 2026] [proxy_http:error] [pid 643253:tid 643481] [client 192.210.150.196:41498] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:28.526104 2026] [proxy:error] [pid 643253:tid 643481] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:28.526149 2026] [proxy_http:error] [pid 643253:tid 643481] [client 192.210.150.196:41498] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:28.625487 2026] [security2:error] [pid 643253:tid 643474] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/aa.php"] [unique_id "amuD4MjqbtjBYzqM1uY0vQAAAFo"]
[Thu Jul 30 12:03:28.625595 2026] [security2:error] [pid 643253:tid 643474] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/aa.php"] [unique_id "amuD4MjqbtjBYzqM1uY0vQAAAFo"]
[Thu Jul 30 12:03:28.938157 2026] [security2:error] [pid 643253:tid 643415] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tx79.php"] [unique_id "amuD4MjqbtjBYzqM1uY0xAAAAB8"]
[Thu Jul 30 12:03:28.938264 2026] [security2:error] [pid 643253:tid 643415] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tx79.php"] [unique_id "amuD4MjqbtjBYzqM1uY0xAAAAB8"]
[Thu Jul 30 12:03:29.260680 2026] [security2:error] [pid 643253:tid 643484] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/motu.php"] [unique_id "amuD4cjqbtjBYzqM1uY0ywAAAGQ"]
[Thu Jul 30 12:03:29.260782 2026] [security2:error] [pid 643253:tid 643484] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/motu.php"] [unique_id "amuD4cjqbtjBYzqM1uY0ywAAAGQ"]
[Thu Jul 30 12:03:29.571264 2026] [security2:error] [pid 643253:tid 643492] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-head.php"] [unique_id "amuD4cjqbtjBYzqM1uY0zAAAAGw"]
[Thu Jul 30 12:03:29.571382 2026] [security2:error] [pid 643253:tid 643492] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-head.php"] [unique_id "amuD4cjqbtjBYzqM1uY0zAAAAGw"]
[Thu Jul 30 12:03:29.596900 2026] [security2:error] [pid 643253:tid 643418] [client 20.100.187.246:59835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/02.php"] [unique_id "amuD4cjqbtjBYzqM1uY0zQAAACI"]
[Thu Jul 30 12:03:29.885447 2026] [security2:error] [pid 643253:tid 643399] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuD4cjqbtjBYzqM1uY01QAAAA8"]
[Thu Jul 30 12:03:29.885572 2026] [security2:error] [pid 643253:tid 643399] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuD4cjqbtjBYzqM1uY01QAAAA8"]
[Thu Jul 30 12:03:29.933331 2026] [security2:error] [pid 643253:tid 643260] [remote 65.181.116.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theaq.global"] [uri "/wp-login.php"] [unique_id "amuD4cjqbtjBYzqM1uY01gAAYAU"]
[Thu Jul 30 12:03:30.198209 2026] [security2:error] [pid 643253:tid 643434] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/60856e3a4findex.php"] [unique_id "amuD4sjqbtjBYzqM1uY01wAAADI"]
[Thu Jul 30 12:03:30.198326 2026] [security2:error] [pid 643253:tid 643434] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/60856e3a4findex.php"] [unique_id "amuD4sjqbtjBYzqM1uY01wAAADI"]
[Thu Jul 30 12:03:30.509476 2026] [security2:error] [pid 643253:tid 643489] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-the.php"] [unique_id "amuD4sjqbtjBYzqM1uY04AAAAGk"]
[Thu Jul 30 12:03:30.509592 2026] [security2:error] [pid 643253:tid 643489] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp-the.php"] [unique_id "amuD4sjqbtjBYzqM1uY04AAAAGk"]
[Thu Jul 30 12:03:30.832541 2026] [security2:error] [pid 643253:tid 643494] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp.php"] [unique_id "amuD4sjqbtjBYzqM1uY06QAAAG4"]
[Thu Jul 30 12:03:30.832641 2026] [security2:error] [pid 643253:tid 643494] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wp.php"] [unique_id "amuD4sjqbtjBYzqM1uY06QAAAG4"]
[Thu Jul 30 12:03:31.254168 2026] [security2:error] [pid 643253:tid 643498] [client 57.141.0.1:63978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuD4sjqbtjBYzqM1uY07AAAciQ"], referer: https://igetvape-australia.com/product/plus-s3-kit-cherry-pomegranate/
[Thu Jul 30 12:03:31.412755 2026] [security2:error] [pid 643253:tid 643479] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/users.php"] [unique_id "amuD48jqbtjBYzqM1uY09QAAAF8"]
[Thu Jul 30 12:03:31.412850 2026] [security2:error] [pid 643253:tid 643479] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/users.php"] [unique_id "amuD48jqbtjBYzqM1uY09QAAAF8"]
[Thu Jul 30 12:03:31.619740 2026] [proxy:error] [pid 643253:tid 643316] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:31.619801 2026] [proxy_http:error] [pid 643253:tid 643316] [remote 74.7.244.52:48496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:31.620375 2026] [proxy:error] [pid 643253:tid 643316] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:03:31.620419 2026] [proxy_http:error] [pid 643253:tid 643316] [remote 74.7.244.52:48496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:03:31.758019 2026] [security2:error] [pid 643253:tid 643435] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tinysd.php"] [unique_id "amuD48jqbtjBYzqM1uY0-AAAADM"]
[Thu Jul 30 12:03:31.758130 2026] [security2:error] [pid 643253:tid 643435] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/tinysd.php"] [unique_id "amuD48jqbtjBYzqM1uY0-AAAADM"]
[Thu Jul 30 12:03:32.066358 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ws78.php"] [unique_id "amuD5MjqbtjBYzqM1uY1AAAAAAA"]
[Thu Jul 30 12:03:32.066474 2026] [security2:error] [pid 643253:tid 643384] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ws78.php"] [unique_id "amuD5MjqbtjBYzqM1uY1AAAAAAA"]
[Thu Jul 30 12:03:32.145593 2026] [security2:error] [pid 643253:tid 643460] [client 57.141.0.10:27530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuD48jqbtjBYzqM1uY0_wAATEA"], referer: https://igetvape-australia.com/product-tag/alibarbar-pandora-blueberry-blast-7000-puffs/
[Thu Jul 30 12:03:32.384804 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/elp.php"] [unique_id "amuD5MjqbtjBYzqM1uY1BwAAABs"]
[Thu Jul 30 12:03:32.384948 2026] [security2:error] [pid 643253:tid 643411] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/elp.php"] [unique_id "amuD5MjqbtjBYzqM1uY1BwAAABs"]
[Thu Jul 30 12:03:32.569951 2026] [core:error] [pid 643253:tid 643420] [client 74.7.175.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:32.569972 2026] [core:error] [pid 643253:tid 643420] [client 74.7.175.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:32.570115 2026] [security2:error] [pid 643253:tid 643420] [client 74.7.175.131:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuD5MjqbtjBYzqM1uY1IwAAACQ"]
[Thu Jul 30 12:03:32.570712 2026] [security2:error] [pid 643253:tid 643446] [client 74.7.175.131:52758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuD5MjqbtjBYzqM1uY1IQAAPls"]
[Thu Jul 30 12:03:32.699144 2026] [security2:error] [pid 643253:tid 643409] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/atomlib.php"] [unique_id "amuD5MjqbtjBYzqM1uY1JAAAABk"]
[Thu Jul 30 12:03:32.699256 2026] [security2:error] [pid 643253:tid 643409] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/atomlib.php"] [unique_id "amuD5MjqbtjBYzqM1uY1JAAAABk"]
[Thu Jul 30 12:03:32.748222 2026] [security2:error] [pid 643253:tid 643438] [client 20.100.187.246:59262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/infos.php"] [unique_id "amuD5MjqbtjBYzqM1uY1JQAAADY"]
[Thu Jul 30 12:03:33.018244 2026] [security2:error] [pid 643253:tid 643509] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wyzer3.php"] [unique_id "amuD5cjqbtjBYzqM1uY1NgAAAH0"]
[Thu Jul 30 12:03:33.018360 2026] [security2:error] [pid 643253:tid 643509] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/wyzer3.php"] [unique_id "amuD5cjqbtjBYzqM1uY1NgAAAH0"]
[Thu Jul 30 12:03:33.170509 2026] [core:notice] [pid 643253:tid 643313] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:33.331756 2026] [security2:error] [pid 643253:tid 643491] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/max.php"] [unique_id "amuD5cjqbtjBYzqM1uY1ZwAAAGs"]
[Thu Jul 30 12:03:33.331861 2026] [security2:error] [pid 643253:tid 643491] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/max.php"] [unique_id "amuD5cjqbtjBYzqM1uY1ZwAAAGs"]
[Thu Jul 30 12:03:33.639131 2026] [security2:error] [pid 643253:tid 643435] [client 20.100.173.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ftde.php"] [unique_id "amuD5cjqbtjBYzqM1uY1bAAAADM"]
[Thu Jul 30 12:03:33.639243 2026] [security2:error] [pid 643253:tid 643435] [client 20.100.173.28:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/ftde.php"] [unique_id "amuD5cjqbtjBYzqM1uY1bAAAADM"]
[Thu Jul 30 12:03:33.858180 2026] [core:notice] [pid 643253:tid 643401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:33.862285 2026] [security2:error] [pid 643253:tid 643401] [client 103.215.74.26:51778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD5cjqbtjBYzqM1uY1cQAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:34.547092 2026] [security2:error] [pid 643253:tid 643422] [client 20.100.187.246:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/updates.php"] [unique_id "amuD5sjqbtjBYzqM1uY1hQAAACY"]
[Thu Jul 30 12:03:34.592469 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:34.596903 2026] [security2:error] [pid 643253:tid 643392] [client 103.215.74.26:51792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD5sjqbtjBYzqM1uY1hgAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:35.117155 2026] [security2:error] [pid 643253:tid 643305] [remote 57.141.0.31:39644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuD58jqbtjBYzqM1uY1lAAAGTI"]
[Thu Jul 30 12:03:35.223005 2026] [security2:error] [pid 643253:tid 643446] [client 20.100.187.246:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/user.php"] [unique_id "amuD58jqbtjBYzqM1uY1lQAAAD4"]
[Thu Jul 30 12:03:35.350587 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:35.357183 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:51798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD58jqbtjBYzqM1uY1nAAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:36.081917 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:36.089972 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:51802] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD6MjqbtjBYzqM1uY1rAAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:36.352500 2026] [security2:error] [pid 643253:tid 643439] [client 223.109.255.168:51308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/louis-vuitton-lv-trainer-white-brown/"] [unique_id "amuD6MjqbtjBYzqM1uY1rgAAADc"]
[Thu Jul 30 12:03:36.352665 2026] [security2:error] [pid 643253:tid 643439] [client 223.109.255.168:51308] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/louis-vuitton-lv-trainer-white-brown/"] [unique_id "amuD6MjqbtjBYzqM1uY1rgAAADc"]
[Thu Jul 30 12:03:36.833798 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:36.838013 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:51816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD6MjqbtjBYzqM1uY1ugAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:37.029407 2026] [security2:error] [pid 643253:tid 643414] [client 20.100.187.246:63746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/admin-ajax.php"] [unique_id "amuD6cjqbtjBYzqM1uY1wAAAAB4"]
[Thu Jul 30 12:03:37.546353 2026] [security2:error] [pid 643253:tid 643318] [remote 190.92.171.214:54624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.171.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuD6cjqbtjBYzqM1uY1xQAACD8"]
[Thu Jul 30 12:03:37.584621 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:37.589663 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:51830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD6cjqbtjBYzqM1uY1yQAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:38.010837 2026] [security2:error] [pid 643253:tid 643490] [client 176.241.66.87:58316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.66.241.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD6sjqbtjBYzqM1uY1zwAAAGo"]
[Thu Jul 30 12:03:38.011021 2026] [security2:error] [pid 643253:tid 643490] [client 176.241.66.87:58316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuD6sjqbtjBYzqM1uY1zwAAAGo"]
[Thu Jul 30 12:03:38.303795 2026] [core:error] [pid 643253:tid 643413] [client 74.7.228.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:38.303815 2026] [core:error] [pid 643253:tid 643413] [client 74.7.228.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:03:38.303931 2026] [security2:error] [pid 643253:tid 643413] [client 74.7.228.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.jst.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuD6sjqbtjBYzqM1uY11wAAAB0"]
[Thu Jul 30 12:03:38.304550 2026] [security2:error] [pid 643253:tid 643436] [client 74.7.228.59:47812] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.jst.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuD6sjqbtjBYzqM1uY11QAANEU"]
[Thu Jul 30 12:03:38.310317 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:38.316702 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:51842] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD6sjqbtjBYzqM1uY12AAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:38.829026 2026] [security2:error] [pid 643253:tid 643444] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuD6sjqbtjBYzqM1uY14AAAPEw"]
[Thu Jul 30 12:03:38.876242 2026] [security2:error] [pid 643253:tid 643457] [client 20.100.187.246:63751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/alfa.php"] [unique_id "amuD6sjqbtjBYzqM1uY14QAAAEk"]
[Thu Jul 30 12:03:39.042949 2026] [core:notice] [pid 643253:tid 643496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:39.047081 2026] [security2:error] [pid 643253:tid 643496] [client 103.215.74.26:51846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD68jqbtjBYzqM1uY15AAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:39.304565 2026] [security2:error] [pid 643253:tid 643332] [remote 57.141.0.51:47876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuD68jqbtjBYzqM1uY16wAAKU0"]
[Thu Jul 30 12:03:39.789204 2026] [core:notice] [pid 643253:tid 643448] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:39.793204 2026] [security2:error] [pid 643253:tid 643448] [client 103.215.74.26:51862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD68jqbtjBYzqM1uY19AAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:39.860348 2026] [security2:error] [pid 643253:tid 643468] [client 20.100.187.246:61345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/hehe.php"] [unique_id "amuD68jqbtjBYzqM1uY19QAAAFQ"]
[Thu Jul 30 12:03:40.516001 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:40.519973 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:51874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD7MjqbtjBYzqM1uY1_gAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:41.215929 2026] [security2:error] [pid 643253:tid 643480] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD7MjqbtjBYzqM1uY1_QAAYGU"]
[Thu Jul 30 12:03:41.242800 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:41.247437 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:51890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD7cjqbtjBYzqM1uY2DQAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:41.456223 2026] [security2:error] [pid 643253:tid 643462] [client 20.100.187.246:58685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/rk2.php"] [unique_id "amuD7cjqbtjBYzqM1uY2EQAAAE4"]
[Thu Jul 30 12:03:41.767778 2026] [security2:error] [pid 643253:tid 643334] [remote 52.167.144.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/228/222/445"] [unique_id "amuD7cjqbtjBYzqM1uY2EgAAWE8"]
[Thu Jul 30 12:03:42.718023 2026] [security2:error] [pid 643253:tid 643444] [client 20.100.187.246:61331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/setup-config.php"] [unique_id "amuD7sjqbtjBYzqM1uY2IQAAADw"]
[Thu Jul 30 12:03:43.034959 2026] [security2:error] [pid 643253:tid 643479] [client 144.76.32.117:48060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "emmelevate.club"] [uri "/index.php"] [unique_id "amuD7sjqbtjBYzqM1uY2JwAAAF8"]
[Thu Jul 30 12:03:43.503164 2026] [security2:error] [pid 643253:tid 643450] [client 20.100.187.246:35914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/a7.php"] [unique_id "amuD78jqbtjBYzqM1uY2NQAAAEI"]
[Thu Jul 30 12:03:45.647852 2026] [security2:error] [pid 643253:tid 643476] [client 20.100.187.246:57421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/f7.php"] [unique_id "amuD8cjqbtjBYzqM1uY2UgAAAFw"]
[Thu Jul 30 12:03:46.382650 2026] [security2:error] [pid 643253:tid 643506] [client 20.100.187.246:35926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/nw.php"] [unique_id "amuD8sjqbtjBYzqM1uY2WwAAAHo"]
[Thu Jul 30 12:03:46.970025 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:46.975142 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:6242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD8sjqbtjBYzqM1uY2aAAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:47.436161 2026] [security2:error] [pid 643253:tid 643458] [client 20.100.187.246:58654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/ova.php"] [unique_id "amuD88jqbtjBYzqM1uY2cQAAAEo"]
[Thu Jul 30 12:03:47.733677 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:47.740691 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:6274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD88jqbtjBYzqM1uY2dQAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:47.742940 2026] [security2:error] [pid 643253:tid 643375] [remote 74.7.241.60:45136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuD88jqbtjBYzqM1uY2dgAAQXg"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:03:47.887989 2026] [core:notice] [pid 643253:tid 643259] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:47.968341 2026] [core:notice] [pid 643253:tid 643370] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:48.221060 2026] [security2:error] [pid 643253:tid 643460] [client 20.100.187.246:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/robots.php"] [unique_id "amuD9MjqbtjBYzqM1uY2hQAAAEw"]
[Thu Jul 30 12:03:48.495701 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:48.499725 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:6294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD9MjqbtjBYzqM1uY2iwAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:48.652082 2026] [core:notice] [pid 643253:tid 643263] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:48.808717 2026] [core:notice] [pid 643253:tid 643348] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:49.222212 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:49.226613 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:6302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD9cjqbtjBYzqM1uY2nQAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:49.945804 2026] [core:notice] [pid 643253:tid 643406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:49.950315 2026] [security2:error] [pid 643253:tid 643406] [client 103.215.74.26:6310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD9cjqbtjBYzqM1uY2rgAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:50.670077 2026] [core:notice] [pid 643253:tid 643443] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:50.674890 2026] [security2:error] [pid 643253:tid 643443] [client 103.215.74.26:6320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD9sjqbtjBYzqM1uY2vQAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:51.007872 2026] [security2:error] [pid 643253:tid 643490] [client 127.0.0.1:19848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuD9sjqbtjBYzqM1uY2wAAAAGo"]
[Thu Jul 30 12:03:51.007949 2026] [security2:error] [pid 643253:tid 643496] [client 74.7.244.41:51272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.alsafwafurnituremovers.cc"] [uri "/robots.txt"] [unique_id "amuD9sjqbtjBYzqM1uY2vwAAcHs"]
[Thu Jul 30 12:03:51.412834 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:51.417346 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:6326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD98jqbtjBYzqM1uY2yQAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:51.934272 2026] [security2:error] [pid 643253:tid 643473] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuD98jqbtjBYzqM1uY2yAAAWRA"]
[Thu Jul 30 12:03:52.182082 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:52.187498 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:6340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-MjqbtjBYzqM1uY22QAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:52.907460 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:52.912710 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:6342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-MjqbtjBYzqM1uY25QAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:53.160824 2026] [security2:error] [pid 643253:tid 643470] [client 20.100.187.246:35170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/alf.php"] [unique_id "amuD-cjqbtjBYzqM1uY26QAAAFY"]
[Thu Jul 30 12:03:53.640722 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:53.645889 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:9760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-cjqbtjBYzqM1uY28wAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:53.835534 2026] [security2:error] [pid 643253:tid 643392] [client 4.223.71.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mshstrategic.com"] [uri "/.well-known/about.php"] [unique_id "amuD-cjqbtjBYzqM1uY2-QAAAAg"]
[Thu Jul 30 12:03:53.835694 2026] [security2:error] [pid 643253:tid 643392] [client 4.223.71.149:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mshstrategic.com"] [uri "/.well-known/about.php"] [unique_id "amuD-cjqbtjBYzqM1uY2-QAAAAg"]
[Thu Jul 30 12:03:54.362846 2026] [core:notice] [pid 643253:tid 643460] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:54.367307 2026] [security2:error] [pid 643253:tid 643460] [client 103.215.74.26:9762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-sjqbtjBYzqM1uY3BwAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:55.120692 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:55.125830 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:9766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-8jqbtjBYzqM1uY3GAAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:55.857877 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:55.861820 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:9782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD-8jqbtjBYzqM1uY3IwAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:56.120524 2026] [security2:error] [pid 643253:tid 643426] [client 20.100.187.246:59151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/feedback.php"] [unique_id "amuD_MjqbtjBYzqM1uY3KQAAACo"]
[Thu Jul 30 12:03:56.585708 2026] [core:notice] [pid 643253:tid 643506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:56.589698 2026] [security2:error] [pid 643253:tid 643506] [client 103.215.74.26:9786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_MjqbtjBYzqM1uY3MAAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:57.310527 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:57.317414 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:9792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_cjqbtjBYzqM1uY3UwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:58.037682 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:58.042093 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:9794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_sjqbtjBYzqM1uY3YwAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:58.778246 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:58.785824 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:9800] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_sjqbtjBYzqM1uY3dgAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:59.334479 2026] [security2:error] [pid 643253:tid 643469] [client 172.236.9.101:37653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3QwAAAFU"]
[Thu Jul 30 12:03:59.348371 2026] [security2:error] [pid 643253:tid 643462] [client 172.236.9.101:22513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3SQAAAE4"]
[Thu Jul 30 12:03:59.352384 2026] [security2:error] [pid 643253:tid 643484] [client 172.236.9.101:32471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3PwAAAGQ"]
[Thu Jul 30 12:03:59.368527 2026] [security2:error] [pid 643253:tid 643445] [client 172.236.9.101:39339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3RwAAAD0"]
[Thu Jul 30 12:03:59.368713 2026] [security2:error] [pid 643253:tid 643442] [client 172.236.9.101:2718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3TQAAADo"]
[Thu Jul 30 12:03:59.368912 2026] [security2:error] [pid 643253:tid 643500] [client 172.236.9.101:5252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3RAAAAHQ"]
[Thu Jul 30 12:03:59.372814 2026] [security2:error] [pid 643253:tid 643487] [client 172.236.9.101:3423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3QgAAAGc"]
[Thu Jul 30 12:03:59.375819 2026] [security2:error] [pid 643253:tid 643464] [client 172.236.9.101:22465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3UQAAAFA"]
[Thu Jul 30 12:03:59.384726 2026] [security2:error] [pid 643253:tid 643499] [client 172.236.9.101:30153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3SAAAAHM"]
[Thu Jul 30 12:03:59.387560 2026] [security2:error] [pid 643253:tid 643459] [client 172.236.9.101:7433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3SwAAAEs"]
[Thu Jul 30 12:03:59.392244 2026] [security2:error] [pid 643253:tid 643504] [client 172.236.9.101:51727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3RgAAAHg"]
[Thu Jul 30 12:03:59.401185 2026] [security2:error] [pid 643253:tid 643455] [client 172.236.9.101:31350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3UAAAAEc"]
[Thu Jul 30 12:03:59.404227 2026] [security2:error] [pid 643253:tid 643420] [client 172.236.9.101:13648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3RQAAACQ"]
[Thu Jul 30 12:03:59.415695 2026] [security2:error] [pid 643253:tid 643394] [client 172.236.9.101:64185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3QQAAAAo"]
[Thu Jul 30 12:03:59.425787 2026] [security2:error] [pid 643253:tid 643389] [client 172.236.9.101:26054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3TAAAAAU"]
[Thu Jul 30 12:03:59.447745 2026] [security2:error] [pid 643253:tid 643480] [client 172.236.9.101:2613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3QAAAAGA"]
[Thu Jul 30 12:03:59.452630 2026] [security2:error] [pid 643253:tid 643482] [client 172.236.9.101:38906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3SgAAAGI"]
[Thu Jul 30 12:03:59.469869 2026] [security2:error] [pid 643253:tid 643497] [client 172.236.9.101:1135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3TwAAAHE"]
[Thu Jul 30 12:03:59.520119 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:03:59.527608 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:9806] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuD_8jqbtjBYzqM1uY3jAAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:03:59.549550 2026] [security2:error] [pid 643253:tid 643446] [client 172.236.9.101:54375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3TgAAAD4"]
[Thu Jul 30 12:03:59.601622 2026] [security2:error] [pid 643253:tid 643472] [client 172.236.9.101:11082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuD_cjqbtjBYzqM1uY3UgAAAFg"]
[Thu Jul 30 12:03:59.679378 2026] [security2:error] [pid 643253:tid 643450] [client 155.254.34.253:36023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuD_8jqbtjBYzqM1uY3gQAAAEI"], referer: https://cnpinyin.com/login/?redirect_to=https%3A%2F%2Fcnpinyin.com
[Thu Jul 30 12:04:00.248449 2026] [security2:error] [pid 643253:tid 643467] [client 20.100.187.246:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/gettest.php"] [unique_id "amuEAMjqbtjBYzqM1uY3lwAAAFM"]
[Thu Jul 30 12:04:00.248917 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:00.255688 2026] [security2:error] [pid 643253:tid 643419] [client 103.215.74.26:9808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEAMjqbtjBYzqM1uY3lgAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:00.732256 2026] [security2:error] [pid 643253:tid 643506] [client 35.238.83.104:59422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.progroupdoha.com"] [uri "/.env"] [unique_id "amuEAMjqbtjBYzqM1uY3wgAAAHo"]
[Thu Jul 30 12:04:00.961446 2026] [security2:error] [pid 643253:tid 643491] [client 57.141.0.40:22800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuEAMjqbtjBYzqM1uY3owAAa04"], referer: https://igetvape-australia.com/store/?product-page=8&add-to-cart=426
[Thu Jul 30 12:04:00.987894 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:00.992900 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:9824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEAMjqbtjBYzqM1uY3yAAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:01.153218 2026] [security2:error] [pid 643253:tid 643500] [client 20.100.187.246:35173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/maint.php"] [unique_id "amuEAcjqbtjBYzqM1uY35AAAAHQ"]
[Thu Jul 30 12:04:01.710156 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:01.718424 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:9840] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEAcjqbtjBYzqM1uY37wAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:02.294903 2026] [security2:error] [pid 643253:tid 643486] [client 50.6.43.217:46040] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "pkf.jo"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "amuEAsjqbtjBYzqM1uY3_QAAAGY"]
[Thu Jul 30 12:04:02.442327 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:02.446336 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:9844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEAsjqbtjBYzqM1uY4BAAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:02.820457 2026] [security2:error] [pid 643253:tid 643413] [client 85.208.96.201:40960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/28/joao-azevedo-inaugura-e-autoriza-novas-obras-em-mais-seis-municipios-do-interior-da-paraiba-neste-sabado/"] [unique_id "amuEAsjqbtjBYzqM1uY4CwAAAB0"]
[Thu Jul 30 12:04:02.820615 2026] [security2:error] [pid 643253:tid 643413] [client 85.208.96.201:40960] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/28/joao-azevedo-inaugura-e-autoriza-novas-obras-em-mais-seis-municipios-do-interior-da-paraiba-neste-sabado/"] [unique_id "amuEAsjqbtjBYzqM1uY4CwAAAB0"]
[Thu Jul 30 12:04:03.175618 2026] [core:notice] [pid 643253:tid 643435] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:03.179636 2026] [security2:error] [pid 643253:tid 643435] [client 103.215.74.26:8628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEA8jqbtjBYzqM1uY4FQAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:03.369697 2026] [security2:error] [pid 643253:tid 643400] [client 155.254.34.253:57617] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuEAsjqbtjBYzqM1uY4CAAAABA"], referer: https://cnpinyin.com/%e5%a5%87%e6%80%aa%e7%9a%84%e4%b8%ad%e8%8d%af%e8%8d%af%e9%85%92strange-brew/
[Thu Jul 30 12:04:03.486521 2026] [security2:error] [pid 643253:tid 643400] [client 155.254.34.253:57617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuEAsjqbtjBYzqM1uY4CAAAABA"], referer: https://cnpinyin.com/%e5%a5%87%e6%80%aa%e7%9a%84%e4%b8%ad%e8%8d%af%e8%8d%af%e9%85%92strange-brew/
[Thu Jul 30 12:04:03.486589 2026] [security2:error] [pid 643253:tid 643400] [client 155.254.34.253:57617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuEAsjqbtjBYzqM1uY4CAAAABA"], referer: https://cnpinyin.com/%e5%a5%87%e6%80%aa%e7%9a%84%e4%b8%ad%e8%8d%af%e8%8d%af%e9%85%92strange-brew/
[Thu Jul 30 12:04:03.908866 2026] [core:notice] [pid 643253:tid 643480] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:03.912999 2026] [security2:error] [pid 643253:tid 643480] [client 103.215.74.26:8632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEA8jqbtjBYzqM1uY4HQAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:04.628177 2026] [core:notice] [pid 643253:tid 643393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:04.633098 2026] [security2:error] [pid 643253:tid 643393] [client 103.215.74.26:8646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEBMjqbtjBYzqM1uY4LwAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:04.908695 2026] [security2:error] [pid 643253:tid 643414] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEBMjqbtjBYzqM1uY4KAAAHhA"]
[Thu Jul 30 12:04:05.360755 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:05.365148 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:8662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEBcjqbtjBYzqM1uY4QgAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:05.446191 2026] [core:error] [pid 643253:tid 643467] [client 74.7.230.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:05.446214 2026] [core:error] [pid 643253:tid 643467] [client 74.7.230.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:05.446333 2026] [security2:error] [pid 643253:tid 643467] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.elitegaragedoorrepairservices.us"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuEBcjqbtjBYzqM1uY4UAAAAFM"]
[Thu Jul 30 12:04:05.447060 2026] [security2:error] [pid 643253:tid 643441] [client 74.7.230.63:41788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.elitegaragedoorrepairservices.us"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuEBcjqbtjBYzqM1uY4TQAAORM"]
[Thu Jul 30 12:04:05.807739 2026] [security2:error] [pid 643253:tid 643502] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEBcjqbtjBYzqM1uY4OAAAAHY"]
[Thu Jul 30 12:04:06.106479 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:06.110632 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:8664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEBsjqbtjBYzqM1uY4aAAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:06.463109 2026] [core:notice] [pid 643253:tid 643302] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:06.833242 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:06.837218 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:8676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEBsjqbtjBYzqM1uY4oAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:07.151448 2026] [core:notice] [pid 643253:tid 643319] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.151512 2026] [core:notice] [pid 643253:tid 643318] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.151848 2026] [core:notice] [pid 643253:tid 643324] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.403494 2026] [core:notice] [pid 643253:tid 643337] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.569570 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.574150 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:8680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEB8jqbtjBYzqM1uY4vAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:07.663404 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679219 2026] [core:notice] [pid 643253:tid 643336] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679223 2026] [core:notice] [pid 643253:tid 643332] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679355 2026] [core:notice] [pid 643253:tid 643339] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679541 2026] [core:notice] [pid 643253:tid 643335] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:07.679712 2026] [core:notice] [pid 643253:tid 643331] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:08.192471 2026] [core:notice] [pid 643253:tid 643343] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:08.195321 2026] [security2:error] [pid 643253:tid 643439] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuECMjqbtjBYzqM1uY40QAAN2U"]
[Thu Jul 30 12:04:08.294426 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:08.298704 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:8686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuECMjqbtjBYzqM1uY42QAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:08.304191 2026] [security2:error] [pid 643253:tid 643434] [client 20.100.187.246:35913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/files.php"] [unique_id "amuECMjqbtjBYzqM1uY42wAAADI"]
[Thu Jul 30 12:04:08.886662 2026] [core:notice] [pid 643253:tid 643328] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:09.035698 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:09.040251 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:8698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuECcjqbtjBYzqM1uY48QAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:09.767074 2026] [core:notice] [pid 643253:tid 643358] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:09.767627 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:09.771677 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:8714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuECcjqbtjBYzqM1uY5AgAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:10.027639 2026] [core:notice] [pid 643253:tid 643345] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.027639 2026] [core:notice] [pid 643253:tid 643368] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.027639 2026] [core:notice] [pid 643253:tid 643346] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.027885 2026] [core:notice] [pid 643253:tid 643354] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.064046 2026] [autoindex:error] [pid 643253:tid 643417] [client 66.132.172.129:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:04:10.282910 2026] [core:notice] [pid 643253:tid 643350] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.282910 2026] [core:notice] [pid 643253:tid 643344] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.282910 2026] [core:notice] [pid 643253:tid 643374] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.283071 2026] [core:notice] [pid 643253:tid 643366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.511319 2026] [core:notice] [pid 643253:tid 643433] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.516717 2026] [security2:error] [pid 643253:tid 643433] [client 103.215.74.26:8718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuECsjqbtjBYzqM1uY5HgAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:10.548178 2026] [core:notice] [pid 643253:tid 643369] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.548179 2026] [core:notice] [pid 643253:tid 643347] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.548179 2026] [core:notice] [pid 643253:tid 643333] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:10.867299 2026] [core:error] [pid 643253:tid 643367] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:10.867332 2026] [core:error] [pid 643253:tid 643367] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:10.938730 2026] [core:error] [pid 643253:tid 643381] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:10.938752 2026] [core:error] [pid 643253:tid 643381] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:10.993718 2026] [security2:error] [pid 643253:tid 643481] [client 136.70.70.191:62827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "billsnap.fiyan.co"] [uri "/billsnap-ai-receipt-splitter//wp-includes/wlwmanifest.xml"] [unique_id "amuECsjqbtjBYzqM1uY5LAAAAGE"]
[Thu Jul 30 12:04:11.006595 2026] [core:notice] [pid 643253:tid 643364] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.106446 2026] [security2:error] [pid 643253:tid 643268] [remote 74.7.241.59:38904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuEC8jqbtjBYzqM1uY5LgAARQ0"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:04:11.259439 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.263689 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:8732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEC8jqbtjBYzqM1uY5NQAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:11.583438 2026] [core:notice] [pid 643253:tid 643352] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.816026 2026] [security2:error] [pid 643253:tid 643428] [client 20.100.187.246:59226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/gecko.php"] [unique_id "amuEC8jqbtjBYzqM1uY5QQAAACw"]
[Thu Jul 30 12:04:11.831288 2026] [core:notice] [pid 643253:tid 643264] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.831288 2026] [core:notice] [pid 643253:tid 643375] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.831288 2026] [core:notice] [pid 643253:tid 643349] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:11.853013 2026] [security2:error] [pid 643253:tid 643496] [client 172.202.44.182:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/chosen.php"] [unique_id "amuEC8jqbtjBYzqM1uY5RQAAAHA"]
[Thu Jul 30 12:04:12.007833 2026] [core:notice] [pid 643253:tid 643394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.008338 2026] [security2:error] [pid 643253:tid 643502] [client 136.70.70.191:56782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.70.70.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "billsnap.fiyan.co"] [uri "/billsnap-ai-receipt-splitter//xmlrpc.php"] [unique_id "amuEDMjqbtjBYzqM1uY5TAAAAHY"]
[Thu Jul 30 12:04:12.012247 2026] [security2:error] [pid 643253:tid 643394] [client 103.215.74.26:8748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEDMjqbtjBYzqM1uY5TQAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:12.092199 2026] [core:notice] [pid 643253:tid 643277] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.092358 2026] [core:notice] [pid 643253:tid 643370] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.343130 2026] [core:notice] [pid 643253:tid 643316] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.595516 2026] [core:notice] [pid 643253:tid 643269] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.747276 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.754642 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:8756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEDMjqbtjBYzqM1uY5YQAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:12.834721 2026] [security2:error] [pid 643253:tid 643466] [client 74.7.228.48:37132] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "happyspree.app.gxj.udi.temporary.site"] [uri "/index.php"] [unique_id "amuEDMjqbtjBYzqM1uY5WAAAUgY"]
[Thu Jul 30 12:04:12.886819 2026] [core:notice] [pid 643253:tid 643267] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:12.886995 2026] [core:notice] [pid 643253:tid 643256] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:13.026318 2026] [security2:error] [pid 643253:tid 643473] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEDMjqbtjBYzqM1uY5VwAAWXQ"]
[Thu Jul 30 12:04:13.348597 2026] [security2:error] [pid 643253:tid 643457] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEDMjqbtjBYzqM1uY5YAAAAEk"]
[Thu Jul 30 12:04:13.450664 2026] [core:notice] [pid 643253:tid 643286] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:13.482510 2026] [core:notice] [pid 643253:tid 643398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:13.486896 2026] [security2:error] [pid 643253:tid 643398] [client 103.215.74.26:47048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEDcjqbtjBYzqM1uY5fQAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:13.510092 2026] [security2:error] [pid 643253:tid 643420] [client 20.100.187.246:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/zwso.php"] [unique_id "amuEDcjqbtjBYzqM1uY5fgAAACQ"]
[Thu Jul 30 12:04:14.211059 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:14.218711 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:47052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEDsjqbtjBYzqM1uY5kgAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:14.219172 2026] [security2:error] [pid 643253:tid 643415] [client 172.202.44.182:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/xleet.php"] [unique_id "amuEDsjqbtjBYzqM1uY5kwAAAB8"]
[Thu Jul 30 12:04:14.236593 2026] [security2:error] [pid 643253:tid 643476] [client 20.100.187.246:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/13.php"] [unique_id "amuEDsjqbtjBYzqM1uY5lAAAAFw"]
[Thu Jul 30 12:04:14.302454 2026] [core:notice] [pid 643253:tid 643410] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:14.338241 2026] [core:notice] [pid 643253:tid 643273] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:14.474729 2026] [core:error] [pid 643253:tid 643401] [client 74.7.241.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:14.474753 2026] [core:error] [pid 643253:tid 643401] [client 74.7.241.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:04:14.474886 2026] [security2:error] [pid 643253:tid 643401] [client 74.7.241.165:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.muu.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuEDsjqbtjBYzqM1uY5nAAAABE"]
[Thu Jul 30 12:04:14.476662 2026] [security2:error] [pid 643253:tid 643502] [client 74.7.241.165:52430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.muu.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuEDsjqbtjBYzqM1uY5mgAAdhE"]
[Thu Jul 30 12:04:14.600987 2026] [core:notice] [pid 643253:tid 643297] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:15.538728 2026] [security2:error] [pid 643253:tid 643505] [client 172.202.44.182:43842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/ds.php"] [unique_id "amuED8jqbtjBYzqM1uY5rwAAAHk"]
[Thu Jul 30 12:04:16.001156 2026] [core:notice] [pid 643253:tid 643293] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:16.005017 2026] [security2:error] [pid 643253:tid 643458] [client 23.112.95.228:35027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/2045"] [unique_id "amuED8jqbtjBYzqM1uY5sgAASiY"], referer: https://ejournalugj.com/
[Thu Jul 30 12:04:16.464683 2026] [core:notice] [pid 643253:tid 643288] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:16.712839 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:16.777942 2026] [security2:error] [pid 643253:tid 643462] [client 64.233.173.96:38045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEEMjqbtjBYzqM1uY5wgAAAE4"]
[Thu Jul 30 12:04:18.413640 2026] [security2:error] [pid 643253:tid 643387] [client 136.70.70.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "billsnap.fiyan.co"] [uri "/index.php"] [unique_id "amuEEsjqbtjBYzqM1uY55QAAAAM"]
[Thu Jul 30 12:04:18.503235 2026] [security2:error] [pid 643253:tid 643405] [client 20.203.148.31:20193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/--wp-lgj.php"] [unique_id "amuEEsjqbtjBYzqM1uY56gAAABU"]
[Thu Jul 30 12:04:18.635862 2026] [security2:error] [pid 643253:tid 643423] [client 172.202.44.182:44270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/f5.php"] [unique_id "amuEEsjqbtjBYzqM1uY57wAAACc"]
[Thu Jul 30 12:04:18.814775 2026] [core:notice] [pid 643253:tid 643314] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:19.331221 2026] [security2:error] [pid 643253:tid 643318] [remote 207.46.13.92:8863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/sistema-erp-totvs-protheus/valuef.php"] [unique_id "amuEE8jqbtjBYzqM1uY5_AAADj8"]
[Thu Jul 30 12:04:19.603069 2026] [security2:error] [pid 643253:tid 643483] [client 20.203.148.31:20184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuEE8jqbtjBYzqM1uY6AAAAAGM"]
[Thu Jul 30 12:04:19.937155 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:19.941288 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:47054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEE8jqbtjBYzqM1uY6CAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:20.329132 2026] [security2:error] [pid 643253:tid 643397] [client 136.70.70.191:60166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "billsnap.fiyan.co"] [uri "/index.php"] [unique_id "amuEFMjqbtjBYzqM1uY6CgAAAA0"]
[Thu Jul 30 12:04:20.396030 2026] [security2:error] [pid 643253:tid 643462] [client 20.203.148.31:25156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/flower.php"] [unique_id "amuEFMjqbtjBYzqM1uY6EQAAAE4"]
[Thu Jul 30 12:04:20.616217 2026] [security2:error] [pid 643253:tid 643440] [client 172.202.44.182:4346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/god4m.php"] [unique_id "amuEFMjqbtjBYzqM1uY6FgAAADg"]
[Thu Jul 30 12:04:20.665048 2026] [core:notice] [pid 643253:tid 643386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:20.669354 2026] [security2:error] [pid 643253:tid 643386] [client 103.215.74.26:47068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEFMjqbtjBYzqM1uY6FwAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:20.723403 2026] [security2:error] [pid 643253:tid 643472] [client 136.70.70.191:60166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "billsnap.fiyan.co"] [uri "/index.php"] [unique_id "amuEFMjqbtjBYzqM1uY6FQAAAFg"]
[Thu Jul 30 12:04:20.960221 2026] [security2:error] [pid 643253:tid 643401] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuEFMjqbtjBYzqM1uY6HwAAABE"]
[Thu Jul 30 12:04:20.977202 2026] [security2:error] [pid 643253:tid 643454] [client 136.70.70.191:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.70.70.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "billsnap.fiyan.co"] [uri "/billsnap-ai-receipt-splitter//xmlrpc.php"] [unique_id "amuEFMjqbtjBYzqM1uY6JQAAAEY"]
[Thu Jul 30 12:04:20.977337 2026] [security2:error] [pid 643253:tid 643454] [client 136.70.70.191:60166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "billsnap.fiyan.co"] [uri "/billsnap-ai-receipt-splitter//xmlrpc.php"] [unique_id "amuEFMjqbtjBYzqM1uY6JQAAAEY"]
[Thu Jul 30 12:04:21.121456 2026] [security2:error] [pid 643253:tid 643423] [client 162.216.148.0:22657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "aptlaw.kr"] [uri "/robots.txt"] [unique_id "amuEFcjqbtjBYzqM1uY6JgAAACc"]
[Thu Jul 30 12:04:21.391896 2026] [security2:error] [pid 643253:tid 643425] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEFMjqbtjBYzqM1uY6IAAAACk"]
[Thu Jul 30 12:04:21.395925 2026] [core:notice] [pid 643253:tid 643426] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.400391 2026] [security2:error] [pid 643253:tid 643426] [client 103.215.74.26:47078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEFcjqbtjBYzqM1uY6NQAAACo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:21.630380 2026] [core:notice] [pid 643253:tid 643309] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.634945 2026] [security2:error] [pid 643253:tid 643430] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/site/pageHeaderTitleImage_id_ID.jpg"] [unique_id "amuEFcjqbtjBYzqM1uY6NAAALjY"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:21.636481 2026] [core:notice] [pid 643253:tid 643317] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.638788 2026] [core:notice] [pid 643253:tid 643301] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.640316 2026] [security2:error] [pid 643253:tid 643430] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/index_php/index/---call---/page/page/css-name-font.css"] [unique_id "amuEFcjqbtjBYzqM1uY6MQAALj4"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:21.642265 2026] [core:notice] [pid 643253:tid 643341] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:21.642832 2026] [security2:error] [pid 643253:tid 643430] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/index_php/index/---call---/page/page/css-name-stylesheet.css"] [unique_id "amuEFcjqbtjBYzqM1uY6MwAALi4"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:21.646031 2026] [security2:error] [pid 643253:tid 643430] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/lib/pkp/styles/fontawesome/fontawesome_v-3.3.0.17.css"] [unique_id "amuEFcjqbtjBYzqM1uY6MgAALlY"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:21.659868 2026] [security2:error] [pid 643253:tid 643419] [client 172.202.44.182:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/info.php"] [unique_id "amuEFcjqbtjBYzqM1uY6NgAAACM"]
[Thu Jul 30 12:04:21.711043 2026] [security2:error] [pid 643253:tid 643503] [client 20.203.148.31:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/xleet.php"] [unique_id "amuEFcjqbtjBYzqM1uY6NwAAAHc"]
[Thu Jul 30 12:04:22.010430 2026] [core:notice] [pid 643253:tid 643351] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010430 2026] [core:notice] [pid 643253:tid 643329] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010477 2026] [core:notice] [pid 643253:tid 643342] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010632 2026] [core:notice] [pid 643253:tid 643355] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010685 2026] [core:notice] [pid 643253:tid 643334] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010708 2026] [core:notice] [pid 643253:tid 643338] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010729 2026] [core:notice] [pid 643253:tid 643361] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.010744 2026] [core:notice] [pid 643253:tid 643326] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.014155 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/17/journalThumbnail_en_US.png"] [unique_id "amuEFsjqbtjBYzqM1uY6QQAAZGA"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.014520 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6QgAAZEo"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.014999 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/site/images/apranolo/Crossref_Logo_Stacked_RGB_SMALL.png"] [unique_id "amuEFsjqbtjBYzqM1uY6RgAAZFM"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.015219 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/33/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6RQAAZFc"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.015478 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/19/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6RwAAZEc"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.015613 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/22/journalThumbnail_en_US.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6SAAAZGQ"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.016827 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/32/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6QwAAZE8"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.017114 2026] [security2:error] [pid 643253:tid 643484] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/44/journalThumbnail_id_ID.png"] [unique_id "amuEFsjqbtjBYzqM1uY6RAAAZGo"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.039388 2026] [security2:error] [pid 643253:tid 643477] [client 37.120.155.179:45060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuEFsjqbtjBYzqM1uY6SQAAAF0"]
[Thu Jul 30 12:04:22.039479 2026] [security2:error] [pid 643253:tid 643477] [client 37.120.155.179:45060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuEFsjqbtjBYzqM1uY6SQAAAF0"]
[Thu Jul 30 12:04:22.119703 2026] [core:notice] [pid 643253:tid 643483] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.130878 2026] [security2:error] [pid 643253:tid 643483] [client 103.215.74.26:47080] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEFsjqbtjBYzqM1uY6SgAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:22.264129 2026] [core:notice] [pid 643253:tid 643363] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264134 2026] [core:notice] [pid 643253:tid 643346] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264193 2026] [core:notice] [pid 643253:tid 643344] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264195 2026] [core:notice] [pid 643253:tid 643354] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264240 2026] [core:notice] [pid 643253:tid 643368] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264444 2026] [core:notice] [pid 643253:tid 643345] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264444 2026] [core:notice] [pid 643253:tid 643358] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.264548 2026] [core:notice] [pid 643253:tid 643365] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.267802 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/10/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6UQAAQ2w"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.268181 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/21/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6VQAAQ2M"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.269798 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/14/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6VgAAQ1k"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270132 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/39/journalThumbnail_en_US.png"] [unique_id "amuEFsjqbtjBYzqM1uY6TwAAQ24"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270251 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/8/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6UAAAQ2c"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270472 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/20/journalThumbnail_en_US.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6UgAAQ3E"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270662 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/7/journalThumbnail_id_ID.png"] [unique_id "amuEFsjqbtjBYzqM1uY6VAAAQ1s"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.270885 2026] [security2:error] [pid 643253:tid 643451] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/24/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6UwAAQ1o"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.516077 2026] [core:notice] [pid 643253:tid 643340] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516077 2026] [core:notice] [pid 643253:tid 643377] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516078 2026] [core:notice] [pid 643253:tid 643333] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516077 2026] [core:notice] [pid 643253:tid 643366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516184 2026] [core:notice] [pid 643253:tid 643373] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516205 2026] [core:notice] [pid 643253:tid 643347] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516411 2026] [core:notice] [pid 643253:tid 643369] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.516411 2026] [core:notice] [pid 643253:tid 643313] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.519686 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/6/journalThumbnail_en_US.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6XgAAc28"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.519852 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/29/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6YAAAc1U"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.519951 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/3/journalThumbnail_en_US.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6XwAAc3o"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520249 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/4/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6ZAAAczo"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520409 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/1/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6YQAAc3Y"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520502 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/2/journalThumbnail_id_ID.png"] [unique_id "amuEFsjqbtjBYzqM1uY6YwAAc1w"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520662 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/35/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6YgAAc04"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.520889 2026] [security2:error] [pid 643253:tid 643499] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/25/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6ZQAAc3I"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.733244 2026] [core:notice] [pid 643253:tid 643367] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.733244 2026] [core:notice] [pid 643253:tid 643359] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.736730 2026] [security2:error] [pid 643253:tid 643495] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/public/journals/13/journalThumbnail_id_ID.jpg"] [unique_id "amuEFsjqbtjBYzqM1uY6ZwAAb2g"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.736894 2026] [security2:error] [pid 643253:tid 643495] [client 103.85.231.200:40587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/3161/templates/images/ojs_brand.png"] [unique_id "amuEFsjqbtjBYzqM1uY6ZgAAb3A"], referer: https://ejournalugj.com/index.php/jka/article/view/3161/2045
[Thu Jul 30 12:04:22.854785 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:22.861574 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:47082] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEFsjqbtjBYzqM1uY6awAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:23.176701 2026] [security2:error] [pid 643253:tid 643401] [client 172.202.44.182:62018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/.__info.php"] [unique_id "amuEF8jqbtjBYzqM1uY6cwAAABE"]
[Thu Jul 30 12:04:23.395776 2026] [security2:error] [pid 643253:tid 643388] [client 20.203.148.31:19632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuEF8jqbtjBYzqM1uY6eAAAAAQ"]
[Thu Jul 30 12:04:23.595013 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:23.599398 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:9436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEF8jqbtjBYzqM1uY6fwAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:24.323873 2026] [core:notice] [pid 643253:tid 643494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:24.328951 2026] [security2:error] [pid 643253:tid 643494] [client 103.215.74.26:9442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGMjqbtjBYzqM1uY6jAAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:24.437108 2026] [security2:error] [pid 643253:tid 643395] [client 20.203.148.31:31475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuEGMjqbtjBYzqM1uY6kwAAAAs"]
[Thu Jul 30 12:04:24.532770 2026] [security2:error] [pid 643253:tid 643427] [client 20.100.187.246:63188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/ava.php"] [unique_id "amuEGMjqbtjBYzqM1uY6lwAAACs"]
[Thu Jul 30 12:04:24.584604 2026] [security2:error] [pid 643253:tid 643509] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEGMjqbtjBYzqM1uY6iAAAfQI"]
[Thu Jul 30 12:04:24.589353 2026] [security2:error] [pid 643253:tid 643503] [client 172.202.44.182:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/0.php"] [unique_id "amuEGMjqbtjBYzqM1uY6mQAAAHc"]
[Thu Jul 30 12:04:25.002337 2026] [security2:error] [pid 643253:tid 643399] [client 20.203.148.31:35333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuEGcjqbtjBYzqM1uY6pAAAAA8"]
[Thu Jul 30 12:04:25.054319 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:25.061321 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:9454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGcjqbtjBYzqM1uY6pQAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:25.106826 2026] [security2:error] [pid 643253:tid 643462] [client 88.99.80.227:44438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuEGcjqbtjBYzqM1uY6pgAAAE4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:04:25.476841 2026] [security2:error] [pid 643253:tid 643415] [client 116.179.37.217:2146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/ELTERA/$$$call$$$/page/page/css"] [unique_id "amuEGcjqbtjBYzqM1uY6pwAAAB8"], referer: https://ejournalugj.com/index.php/ELTERA/login
[Thu Jul 30 12:04:25.491531 2026] [security2:error] [pid 643253:tid 643407] [client 116.179.37.88:40214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/ELTERA/$$$call$$$/page/page/css"] [unique_id "amuEGcjqbtjBYzqM1uY6qAAAABc"], referer: https://ejournalugj.com/index.php/ELTERA/login
[Thu Jul 30 12:04:25.497796 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:25.502164 2026] [security2:error] [pid 643253:tid 643414] [client 88.99.80.227:44452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGcjqbtjBYzqM1uY6rwAAAB4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:04:25.794028 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:25.798114 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:9470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGcjqbtjBYzqM1uY6sAAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:25.850167 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.44.182:44247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/07.php"] [unique_id "amuEGcjqbtjBYzqM1uY6sQAAABk"]
[Thu Jul 30 12:04:25.954494 2026] [security2:error] [pid 643253:tid 643459] [client 88.99.80.227:44460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuEGcjqbtjBYzqM1uY6sgAAAEs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:04:26.552832 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:26.556728 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:9476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEGsjqbtjBYzqM1uY6vwAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:26.790319 2026] [security2:error] [pid 643253:tid 643385] [client 172.202.44.182:44284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/dropdown.php"] [unique_id "amuEGsjqbtjBYzqM1uY6xAAAAAE"]
[Thu Jul 30 12:04:27.290087 2026] [core:notice] [pid 643253:tid 643419] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:27.292172 2026] [security2:error] [pid 643253:tid 643498] [client 213.152.187.225:39902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuEG8jqbtjBYzqM1uY6zgAAAHI"]
[Thu Jul 30 12:04:27.292268 2026] [security2:error] [pid 643253:tid 643498] [client 213.152.187.225:39902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuEG8jqbtjBYzqM1uY6zgAAAHI"]
[Thu Jul 30 12:04:27.294051 2026] [security2:error] [pid 643253:tid 643419] [client 103.215.74.26:9482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEG8jqbtjBYzqM1uY6zwAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:27.937426 2026] [security2:error] [pid 643253:tid 643402] [client 151.245.32.125:38232] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuEG8jqbtjBYzqM1uY62QAAABI"]
[Thu Jul 30 12:04:28.026434 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:28.030533 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:9488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHMjqbtjBYzqM1uY63gAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:28.123023 2026] [security2:error] [pid 643253:tid 643437] [client 172.202.44.182:4249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/makeasmtp.php"] [unique_id "amuEHMjqbtjBYzqM1uY65QAAADU"]
[Thu Jul 30 12:04:28.281033 2026] [security2:error] [pid 643253:tid 643478] [client 151.245.32.125:35778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuEHMjqbtjBYzqM1uY67QAAAF4"]
[Thu Jul 30 12:04:28.745413 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:28.750703 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:9502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHMjqbtjBYzqM1uY68gAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:28.882334 2026] [security2:error] [pid 643253:tid 643271] [remote 57.141.0.52:26282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/407345907/feed/rss2/"] [unique_id "amuEHMjqbtjBYzqM1uY6-QAAERA"]
[Thu Jul 30 12:04:29.495029 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:29.498953 2026] [security2:error] [pid 643253:tid 643441] [client 103.215.74.26:9510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHcjqbtjBYzqM1uY7AwAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:30.183680 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:30.228922 2026] [core:notice] [pid 643253:tid 643465] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:30.232860 2026] [security2:error] [pid 643253:tid 643465] [client 103.215.74.26:9522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHsjqbtjBYzqM1uY7DwAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:30.299079 2026] [security2:error] [pid 643253:tid 643457] [client 20.100.187.246:59212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/main.php"] [unique_id "amuEHsjqbtjBYzqM1uY7EAAAAEk"]
[Thu Jul 30 12:04:30.532519 2026] [security2:error] [pid 643253:tid 643494] [client 66.249.73.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mjsnailspa.com"] [uri "/index.php"] [unique_id "amuEHcjqbtjBYzqM1uY7BAAAAG4"]
[Thu Jul 30 12:04:30.680933 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:30.942962 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:30.947346 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:9538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEHsjqbtjBYzqM1uY7IwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:31.047532 2026] [security2:error] [pid 643253:tid 643472] [client 172.202.44.182:62056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-sigunq.php"] [unique_id "amuEH8jqbtjBYzqM1uY7OAAAAFg"]
[Thu Jul 30 12:04:31.587721 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:31.670294 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:31.674717 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:9552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEH8jqbtjBYzqM1uY7SgAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:32.092061 2026] [security2:error] [pid 643253:tid 643441] [client 172.202.44.182:4533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wso112233.php"] [unique_id "amuEIMjqbtjBYzqM1uY7UQAAADk"]
[Thu Jul 30 12:04:32.175406 2026] [security2:error] [pid 643253:tid 643475] [client 20.100.187.246:63481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-file.php"] [unique_id "amuEIMjqbtjBYzqM1uY7UgAAAFs"]
[Thu Jul 30 12:04:32.418884 2026] [security2:error] [pid 643253:tid 643421] [client 172.237.109.114:21395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7JgAAACU"]
[Thu Jul 30 12:04:32.423878 2026] [security2:error] [pid 643253:tid 643511] [client 172.237.109.114:52115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7JwAAAH8"]
[Thu Jul 30 12:04:32.426751 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:32.429481 2026] [security2:error] [pid 643253:tid 643435] [client 172.237.109.114:39381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7MAAAADM"]
[Thu Jul 30 12:04:32.434250 2026] [security2:error] [pid 643253:tid 643470] [client 172.237.109.114:43320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7KgAAAFY"]
[Thu Jul 30 12:04:32.437392 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:9562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEIMjqbtjBYzqM1uY7VQAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:32.437709 2026] [security2:error] [pid 643253:tid 643459] [client 172.237.109.114:62814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7NAAAAEs"]
[Thu Jul 30 12:04:32.448284 2026] [security2:error] [pid 643253:tid 643414] [client 172.237.109.114:18084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7JQAAAB4"]
[Thu Jul 30 12:04:32.459253 2026] [security2:error] [pid 643253:tid 643474] [client 172.237.109.114:13182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7LQAAAFo"]
[Thu Jul 30 12:04:32.466028 2026] [security2:error] [pid 643253:tid 643400] [client 172.237.109.114:2957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7MQAAABA"]
[Thu Jul 30 12:04:32.485244 2026] [security2:error] [pid 643253:tid 643391] [client 172.237.109.114:15268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7MwAAAAc"]
[Thu Jul 30 12:04:32.504246 2026] [security2:error] [pid 643253:tid 643423] [client 172.237.109.114:28368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7NQAAACc"]
[Thu Jul 30 12:04:32.532039 2026] [security2:error] [pid 643253:tid 643389] [client 172.237.109.114:32860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7LwAAAAU"]
[Thu Jul 30 12:04:32.536729 2026] [security2:error] [pid 643253:tid 643388] [client 172.237.109.114:36672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7MgAAAAQ"]
[Thu Jul 30 12:04:32.537070 2026] [security2:error] [pid 643253:tid 643496] [client 172.237.109.114:55908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7LgAAAHA"]
[Thu Jul 30 12:04:32.558129 2026] [security2:error] [pid 643253:tid 643433] [client 172.237.109.114:1584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7NgAAADE"]
[Thu Jul 30 12:04:32.565511 2026] [security2:error] [pid 643253:tid 643445] [client 172.237.109.114:18770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7LAAAAD0"]
[Thu Jul 30 12:04:32.579733 2026] [security2:error] [pid 643253:tid 643409] [client 172.237.109.114:49083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEH8jqbtjBYzqM1uY7NwAAABk"]
[Thu Jul 30 12:04:32.582438 2026] [security2:error] [pid 643253:tid 643405] [client 172.237.109.114:2894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7KwAAABU"]
[Thu Jul 30 12:04:32.599869 2026] [security2:error] [pid 643253:tid 643392] [client 172.237.109.114:58081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7KAAAAAg"]
[Thu Jul 30 12:04:32.615512 2026] [security2:error] [pid 643253:tid 643499] [client 172.237.109.114:49640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7JAAAAHM"]
[Thu Jul 30 12:04:32.633464 2026] [security2:error] [pid 643253:tid 643507] [client 172.237.109.114:29980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEHsjqbtjBYzqM1uY7KQAAAHs"]
[Thu Jul 30 12:04:33.162346 2026] [core:notice] [pid 643253:tid 643466] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:33.167715 2026] [security2:error] [pid 643253:tid 643466] [client 103.215.74.26:18056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEIcjqbtjBYzqM1uY7ZQAAAFI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:33.400030 2026] [security2:error] [pid 643253:tid 643386] [client 172.202.44.182:44228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/alfanew.php"] [unique_id "amuEIcjqbtjBYzqM1uY7awAAAAI"]
[Thu Jul 30 12:04:33.423771 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:33.451615 2026] [security2:error] [pid 643253:tid 643444] [client 20.203.148.31:35350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuEIcjqbtjBYzqM1uY7cQAAADw"]
[Thu Jul 30 12:04:33.906595 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:33.911281 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:18066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEIcjqbtjBYzqM1uY7fAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:34.132483 2026] [core:error] [pid 643253:tid 643414] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:04:34.132516 2026] [core:error] [pid 643253:tid 643414] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:04:34.328365 2026] [security2:error] [pid 643253:tid 643427] [client 20.203.148.31:9188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuEIsjqbtjBYzqM1uY7iQAAACs"]
[Thu Jul 30 12:04:34.457509 2026] [security2:error] [pid 643253:tid 643432] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEIcjqbtjBYzqM1uY7ewAAMC8"]
[Thu Jul 30 12:04:34.646507 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:34.650949 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:18076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEIsjqbtjBYzqM1uY7kQAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:34.779986 2026] [security2:error] [pid 643253:tid 643423] [client 172.202.44.182:44225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/fw.php"] [unique_id "amuEIsjqbtjBYzqM1uY7kwAAACc"]
[Thu Jul 30 12:04:35.031863 2026] [security2:error] [pid 643253:tid 643402] [client 20.203.148.31:21464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuEI8jqbtjBYzqM1uY7lwAAABI"]
[Thu Jul 30 12:04:35.394003 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:35.398388 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:18082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEI8jqbtjBYzqM1uY7ogAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:35.637006 2026] [security2:error] [pid 643253:tid 643439] [client 20.203.148.31:28999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuEI8jqbtjBYzqM1uY7pgAAADc"]
[Thu Jul 30 12:04:36.133101 2026] [core:notice] [pid 643253:tid 643478] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:36.137458 2026] [security2:error] [pid 643253:tid 643478] [client 103.215.74.26:18090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJMjqbtjBYzqM1uY7rwAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:36.163576 2026] [security2:error] [pid 643253:tid 643384] [client 172.202.44.182:4541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-login.php"] [unique_id "amuEJMjqbtjBYzqM1uY7sAAAAAA"]
[Thu Jul 30 12:04:36.316477 2026] [security2:error] [pid 643253:tid 643453] [client 20.203.148.31:22908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuEJMjqbtjBYzqM1uY7tQAAAEU"]
[Thu Jul 30 12:04:36.651030 2026] [security2:error] [pid 643253:tid 643452] [client 85.208.96.199:30368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/07/08/fortaleza-e-dominado-perde-para-o-estudiantes-e-esta-eliminado-da-libertadores/"] [unique_id "amuEJMjqbtjBYzqM1uY7uQAAAEQ"]
[Thu Jul 30 12:04:36.651167 2026] [security2:error] [pid 643253:tid 643452] [client 85.208.96.199:30368] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/07/08/fortaleza-e-dominado-perde-para-o-estudiantes-e-esta-eliminado-da-libertadores/"] [unique_id "amuEJMjqbtjBYzqM1uY7uQAAAEQ"]
[Thu Jul 30 12:04:36.689390 2026] [security2:error] [pid 643253:tid 643467] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEJMjqbtjBYzqM1uY7sQAAAFM"]
[Thu Jul 30 12:04:36.878011 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:36.881674 2026] [security2:error] [pid 643253:tid 643331] [remote 82.130.249.15:57994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.249.130.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuEJMjqbtjBYzqM1uY7vQAAZUw"]
[Thu Jul 30 12:04:36.882532 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:18094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJMjqbtjBYzqM1uY7vgAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:37.046822 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:37.349832 2026] [security2:error] [pid 643253:tid 643406] [client 20.203.148.31:19681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuEJcjqbtjBYzqM1uY7ygAAABY"]
[Thu Jul 30 12:04:37.384025 2026] [security2:error] [pid 643253:tid 643498] [client 172.202.44.182:62064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/simple.php"] [unique_id "amuEJcjqbtjBYzqM1uY7ywAAAHI"]
[Thu Jul 30 12:04:37.548557 2026] [security2:error] [pid 643253:tid 643405] [client 20.100.187.246:63679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-signin.php"] [unique_id "amuEJcjqbtjBYzqM1uY7zAAAABU"]
[Thu Jul 30 12:04:37.613075 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:37.616843 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:18102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJcjqbtjBYzqM1uY7zgAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:37.670434 2026] [security2:error] [pid 643253:tid 643483] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEJcjqbtjBYzqM1uY7wwAAAGM"]
[Thu Jul 30 12:04:38.307945 2026] [access_compat:error] [pid 643253:tid 643453] [client 207.154.212.47:0] AH01797: client denied by server configuration: /home1/glbnyxte/public_html/website_bcd72044/server-status
[Thu Jul 30 12:04:38.323722 2026] [security2:error] [pid 643253:tid 643394] [client 172.202.44.182:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/classsmtps.php"] [unique_id "amuEJsjqbtjBYzqM1uY77AAAAAo"]
[Thu Jul 30 12:04:38.354344 2026] [core:notice] [pid 643253:tid 643408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:38.361621 2026] [security2:error] [pid 643253:tid 643408] [client 103.215.74.26:18106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJsjqbtjBYzqM1uY77wAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:38.364644 2026] [security2:error] [pid 643253:tid 643411] [client 20.203.148.31:22503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuEJsjqbtjBYzqM1uY78AAAABs"]
[Thu Jul 30 12:04:38.663579 2026] [security2:error] [pid 643253:tid 643476] [client 185.191.171.3:64600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/20/presidente-do-pdt-se-reune-com-cicero-avanca-em-dialogo-e-diz-que-vai-se-encontrar-com-joao-azevedo/"] [unique_id "amuEJsjqbtjBYzqM1uY8CgAAAFw"]
[Thu Jul 30 12:04:38.663692 2026] [security2:error] [pid 643253:tid 643476] [client 185.191.171.3:64600] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/20/presidente-do-pdt-se-reune-com-cicero-avanca-em-dialogo-e-diz-que-vai-se-encontrar-com-joao-azevedo/"] [unique_id "amuEJsjqbtjBYzqM1uY8CgAAAFw"]
[Thu Jul 30 12:04:38.872285 2026] [security2:error] [pid 643253:tid 643407] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEJsjqbtjBYzqM1uY75wAAF1g"]
[Thu Jul 30 12:04:38.928383 2026] [security2:error] [pid 643253:tid 643469] [client 192.82.55.10:16808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/time_mobile.php"] [unique_id "amuEJsjqbtjBYzqM1uY8FQAAVUk"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:04:39.036474 2026] [security2:error] [pid 643253:tid 643419] [client 192.82.55.10:16808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuEJ8jqbtjBYzqM1uY8GQAAI0s"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:04:39.090520 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:39.094570 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:18120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJ8jqbtjBYzqM1uY8GgAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:39.406930 2026] [security2:error] [pid 643253:tid 643506] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEJsjqbtjBYzqM1uY8BgAAemQ"]
[Thu Jul 30 12:04:39.816286 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:39.818110 2026] [security2:error] [pid 643253:tid 643508] [client 20.203.148.31:24411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuEJ8jqbtjBYzqM1uY8OAAAAHw"]
[Thu Jul 30 12:04:39.820655 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:18122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEJ8jqbtjBYzqM1uY8NwAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:40.126118 2026] [security2:error] [pid 643253:tid 643501] [client 20.100.187.246:59253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/simi.php"] [unique_id "amuEKMjqbtjBYzqM1uY8QwAAAHU"]
[Thu Jul 30 12:04:40.530006 2026] [security2:error] [pid 643253:tid 643466] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEJ8jqbtjBYzqM1uY8QgAAAFI"]
[Thu Jul 30 12:04:40.549066 2026] [core:notice] [pid 643253:tid 643398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:40.555230 2026] [security2:error] [pid 643253:tid 643398] [client 103.215.74.26:18138] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEKMjqbtjBYzqM1uY8TwAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:41.011315 2026] [security2:error] [pid 643253:tid 643403] [client 172.202.44.182:4516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-blog-header.php"] [unique_id "amuEKcjqbtjBYzqM1uY8XgAAABM"]
[Thu Jul 30 12:04:41.302419 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:41.310054 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:18144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEKcjqbtjBYzqM1uY8awAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:41.692609 2026] [security2:error] [pid 643253:tid 643430] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEKcjqbtjBYzqM1uY8XwAAAC4"]
[Thu Jul 30 12:04:41.939956 2026] [security2:error] [pid 643253:tid 643386] [client 172.202.44.182:62058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-trackback.php"] [unique_id "amuEKcjqbtjBYzqM1uY8fAAAAAI"]
[Thu Jul 30 12:04:42.048020 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:42.052008 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:18146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEKsjqbtjBYzqM1uY8fQAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:42.231920 2026] [security2:error] [pid 643253:tid 643437] [client 185.191.171.5:18232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/31/senado-aprova-indicacoes-para-o-conselho-da-republica/"] [unique_id "amuEKsjqbtjBYzqM1uY8fgAAADU"]
[Thu Jul 30 12:04:42.232068 2026] [security2:error] [pid 643253:tid 643437] [client 185.191.171.5:18232] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/31/senado-aprova-indicacoes-para-o-conselho-da-republica/"] [unique_id "amuEKsjqbtjBYzqM1uY8fgAAADU"]
[Thu Jul 30 12:04:42.496015 2026] [security2:error] [pid 643253:tid 643460] [client 20.100.187.246:63693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-conf.php"] [unique_id "amuEKsjqbtjBYzqM1uY8jwAAAEw"]
[Thu Jul 30 12:04:42.789448 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:42.796286 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:18160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEKsjqbtjBYzqM1uY8lQAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:42.881042 2026] [security2:error] [pid 643253:tid 643463] [client 20.203.148.31:9458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuEKsjqbtjBYzqM1uY8mgAAAE8"]
[Thu Jul 30 12:04:43.523882 2026] [core:notice] [pid 643253:tid 643425] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:43.530533 2026] [security2:error] [pid 643253:tid 643425] [client 103.215.74.26:5592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEK8jqbtjBYzqM1uY8qgAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:43.584588 2026] [security2:error] [pid 643253:tid 643443] [client 20.100.187.246:59207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuEK8jqbtjBYzqM1uY8rAAAADs"]
[Thu Jul 30 12:04:43.777643 2026] [security2:error] [pid 643253:tid 643409] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEK8jqbtjBYzqM1uY8ogAAABk"]
[Thu Jul 30 12:04:44.079781 2026] [security2:error] [pid 643253:tid 643412] [client 172.202.44.182:4156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-signup.php"] [unique_id "amuELMjqbtjBYzqM1uY8vgAAABw"]
[Thu Jul 30 12:04:44.250079 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:44.254258 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:5596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuELMjqbtjBYzqM1uY8wAAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:44.298542 2026] [security2:error] [pid 643253:tid 643506] [client 20.100.187.246:63632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/bala.php"] [unique_id "amuELMjqbtjBYzqM1uY8wgAAAHo"]
[Thu Jul 30 12:04:44.667864 2026] [security2:error] [pid 643253:tid 643447] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEK8jqbtjBYzqM1uY8tgAAPwg"]
[Thu Jul 30 12:04:44.897266 2026] [security2:error] [pid 643253:tid 643489] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuELMjqbtjBYzqM1uY8ugAAaQk"]
[Thu Jul 30 12:04:44.913485 2026] [security2:error] [pid 643253:tid 643460] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuELMjqbtjBYzqM1uY8xwAAAEw"]
[Thu Jul 30 12:04:45.083861 2026] [security2:error] [pid 643253:tid 643450] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuELMjqbtjBYzqM1uY8ygAAAEI"]
[Thu Jul 30 12:04:45.196283 2026] [security2:error] [pid 643253:tid 643405] [client 172.202.44.182:62020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-comments-post.php"] [unique_id "amuELcjqbtjBYzqM1uY82QAAABU"]
[Thu Jul 30 12:04:45.257660 2026] [security2:error] [pid 643253:tid 643400] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuELMjqbtjBYzqM1uY8wQAAEHg"]
[Thu Jul 30 12:04:45.802283 2026] [security2:error] [pid 643253:tid 643421] [client 20.100.187.246:61949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/bk.php"] [unique_id "amuELcjqbtjBYzqM1uY8-AAAACU"]
[Thu Jul 30 12:04:46.209942 2026] [security2:error] [pid 643253:tid 643427] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuELcjqbtjBYzqM1uY89wAAACs"]
[Thu Jul 30 12:04:46.331754 2026] [security2:error] [pid 643253:tid 643447] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuELMjqbtjBYzqM1uY80QAAP3M"]
[Thu Jul 30 12:04:46.381121 2026] [core:notice] [pid 643253:tid 643265] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:46.411042 2026] [security2:error] [pid 643253:tid 643426] [client 20.203.148.31:17156] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.revolutionary-technologies.com"] [uri "/1.php"] [unique_id "amuELsjqbtjBYzqM1uY9BgAAACo"]
[Thu Jul 30 12:04:46.411200 2026] [security2:error] [pid 643253:tid 643426] [client 20.203.148.31:17156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/1.php"] [unique_id "amuELsjqbtjBYzqM1uY9BgAAACo"]
[Thu Jul 30 12:04:46.587279 2026] [core:notice] [pid 643253:tid 643418] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:46.594129 2026] [security2:error] [pid 643253:tid 643418] [client 103.215.74.26:5606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuELsjqbtjBYzqM1uY9EAAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:47.062726 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.148.31:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/admin.php"] [unique_id "amuEL8jqbtjBYzqM1uY9FwAAAGo"]
[Thu Jul 30 12:04:47.092837 2026] [security2:error] [pid 643253:tid 643476] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuELsjqbtjBYzqM1uY9DwAAAFw"]
[Thu Jul 30 12:04:47.394574 2026] [security2:error] [pid 643253:tid 643454] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuELsjqbtjBYzqM1uY9AgAARns"]
[Thu Jul 30 12:04:47.551216 2026] [security2:error] [pid 643253:tid 643428] [client 207.154.212.47:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.echomemoversalain.casa"] [uri "/.env"] [unique_id "amuEL8jqbtjBYzqM1uY9HwAAACw"]
[Thu Jul 30 12:04:48.095533 2026] [security2:error] [pid 643253:tid 643414] [client 20.203.148.31:17165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/as.php"] [unique_id "amuEMMjqbtjBYzqM1uY9KAAAAB4"]
[Thu Jul 30 12:04:48.680324 2026] [core:notice] [pid 643253:tid 643282] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:49.013778 2026] [security2:error] [pid 643253:tid 643421] [client 20.100.187.246:61926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/ahax.php"] [unique_id "amuEMcjqbtjBYzqM1uY9PAAAACU"]
[Thu Jul 30 12:04:49.224738 2026] [security2:error] [pid 643253:tid 643307] [remote 57.141.0.33:60728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/358522518/feed/rss2/"] [unique_id "amuEMcjqbtjBYzqM1uY9QAAAfDQ"]
[Thu Jul 30 12:04:49.307716 2026] [security2:error] [pid 643253:tid 643485] [client 20.203.148.31:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/autoload_classmap.php"] [unique_id "amuEMcjqbtjBYzqM1uY9RQAAAGU"]
[Thu Jul 30 12:04:49.376343 2026] [security2:error] [pid 643253:tid 643458] [client 172.202.44.182:62022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-mail.php"] [unique_id "amuEMcjqbtjBYzqM1uY9RgAAAEo"]
[Thu Jul 30 12:04:49.955347 2026] [security2:error] [pid 643253:tid 643505] [client 20.203.148.31:17234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/back.php"] [unique_id "amuEMcjqbtjBYzqM1uY9WAAAAHk"]
[Thu Jul 30 12:04:50.052139 2026] [security2:error] [pid 643253:tid 643287] [remote 57.141.0.65:56776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuEMcjqbtjBYzqM1uY9VAAAVCA"]
[Thu Jul 30 12:04:50.137992 2026] [security2:error] [pid 643253:tid 643396] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEMcjqbtjBYzqM1uY9TgAAAAw"]
[Thu Jul 30 12:04:50.674144 2026] [security2:error] [pid 643253:tid 643298] [remote 74.7.241.60:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuEMsjqbtjBYzqM1uY9XwAAASs"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:04:50.846949 2026] [security2:error] [pid 643253:tid 643487] [client 172.202.44.182:44258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-activate.php"] [unique_id "amuEMsjqbtjBYzqM1uY9ZgAAAGc"]
[Thu Jul 30 12:04:51.256892 2026] [security2:error] [pid 643253:tid 643509] [client 20.203.148.31:23487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuEM8jqbtjBYzqM1uY9awAAAH0"]
[Thu Jul 30 12:04:52.251949 2026] [security2:error] [pid 643253:tid 643489] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEM8jqbtjBYzqM1uY9bwAAAGk"]
[Thu Jul 30 12:04:52.343322 2026] [security2:error] [pid 643253:tid 643425] [client 213.152.161.219:36954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuENMjqbtjBYzqM1uY9fQAAACk"]
[Thu Jul 30 12:04:52.343457 2026] [security2:error] [pid 643253:tid 643425] [client 213.152.161.219:36954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuENMjqbtjBYzqM1uY9fQAAACk"]
[Thu Jul 30 12:04:52.353047 2026] [security2:error] [pid 643253:tid 643427] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEM8jqbtjBYzqM1uY9cgAAACs"]
[Thu Jul 30 12:04:52.385125 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:52.389805 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:5614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuENMjqbtjBYzqM1uY9gAAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:52.848925 2026] [security2:error] [pid 643253:tid 643393] [client 20.203.148.31:17177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/flower.php"] [unique_id "amuENMjqbtjBYzqM1uY9iQAAAAk"]
[Thu Jul 30 12:04:53.080558 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.088638 2026] [security2:error] [pid 643253:tid 643490] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuENMjqbtjBYzqM1uY9hQAAAGo"]
[Thu Jul 30 12:04:53.092611 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.112677 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.123129 2026] [core:notice] [pid 643253:tid 643473] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.126919 2026] [security2:error] [pid 643253:tid 643473] [client 103.215.74.26:48954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuENcjqbtjBYzqM1uY9kwAAAFk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:53.438402 2026] [security2:error] [pid 643253:tid 643477] [client 20.203.148.31:9520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/c/xleet.php"] [unique_id "amuENcjqbtjBYzqM1uY9nAAAAF0"]
[Thu Jul 30 12:04:53.455004 2026] [security2:error] [pid 643253:tid 643466] [client 172.202.44.182:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/post.php"] [unique_id "amuENcjqbtjBYzqM1uY9nQAAAFI"]
[Thu Jul 30 12:04:53.973649 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:53.987589 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:54.020472 2026] [security2:error] [pid 643253:tid 643435] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuENcjqbtjBYzqM1uY9ngAAADM"]
[Thu Jul 30 12:04:54.102521 2026] [security2:error] [pid 643253:tid 643499] [client 20.203.148.31:14782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/classwithtostring.php"] [unique_id "amuENsjqbtjBYzqM1uY9qwAAAHM"]
[Thu Jul 30 12:04:54.148697 2026] [core:notice] [pid 643253:tid 643324] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:54.228392 2026] [core:notice] [pid 643253:tid 643327] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:54.237375 2026] [core:notice] [pid 643253:tid 643300] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:54.893395 2026] [security2:error] [pid 643253:tid 643397] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuENsjqbtjBYzqM1uY9rwAAAA0"]
[Thu Jul 30 12:04:55.386345 2026] [core:notice] [pid 643253:tid 643278] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:55.386621 2026] [core:notice] [pid 643253:tid 643317] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:55.460357 2026] [security2:error] [pid 643253:tid 643402] [client 20.203.148.31:23466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/content.php"] [unique_id "amuEN8jqbtjBYzqM1uY9ywAAABI"]
[Thu Jul 30 12:04:55.570199 2026] [security2:error] [pid 643253:tid 643476] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEN8jqbtjBYzqM1uY9wAAAXFE"]
[Thu Jul 30 12:04:55.745037 2026] [security2:error] [pid 643253:tid 643390] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEN8jqbtjBYzqM1uY9xAAAAAY"]
[Thu Jul 30 12:04:56.733705 2026] [security2:error] [pid 643253:tid 643435] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEOMjqbtjBYzqM1uY93QAAADM"]
[Thu Jul 30 12:04:56.801282 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:57.328557 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.148.31:23459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/doc.php"] [unique_id "amuEOcjqbtjBYzqM1uY97gAAAG0"]
[Thu Jul 30 12:04:57.617625 2026] [security2:error] [pid 643253:tid 643401] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEOcjqbtjBYzqM1uY97AAAABE"]
[Thu Jul 30 12:04:57.910803 2026] [security2:error] [pid 643253:tid 643447] [client 172.202.44.182:4538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-2019.php"] [unique_id "amuEOcjqbtjBYzqM1uY99wAAAD8"]
[Thu Jul 30 12:04:58.745118 2026] [security2:error] [pid 643253:tid 643459] [client 172.202.44.182:4531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/hoot.php"] [unique_id "amuEOsjqbtjBYzqM1uY-CAAAAEs"]
[Thu Jul 30 12:04:58.875329 2026] [security2:error] [pid 643253:tid 643478] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEOsjqbtjBYzqM1uY9_gAAAF4"]
[Thu Jul 30 12:04:58.923053 2026] [security2:error] [pid 643253:tid 643390] [client 20.203.148.31:23431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/dropdown.php"] [unique_id "amuEOsjqbtjBYzqM1uY-DAAAAAY"]
[Thu Jul 30 12:04:58.936348 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:58.940291 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:48970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEOsjqbtjBYzqM1uY-DQAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:59.654586 2026] [core:notice] [pid 643253:tid 643494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:04:59.658397 2026] [security2:error] [pid 643253:tid 643494] [client 103.215.74.26:48984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEO8jqbtjBYzqM1uY-GgAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:04:59.745620 2026] [security2:error] [pid 643253:tid 643420] [client 172.202.44.182:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/log.php"] [unique_id "amuEO8jqbtjBYzqM1uY-JAAAACQ"]
[Thu Jul 30 12:05:00.382334 2026] [core:notice] [pid 643253:tid 643377] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:00.386333 2026] [security2:error] [pid 643253:tid 643444] [client 66.249.74.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/33/59"] [unique_id "amuEPMjqbtjBYzqM1uY-KAAAPHo"]
[Thu Jul 30 12:05:00.387100 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:00.391022 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:48996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEPMjqbtjBYzqM1uY-MAAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:00.620669 2026] [security2:error] [pid 643253:tid 643406] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEPMjqbtjBYzqM1uY-KQAAABY"]
[Thu Jul 30 12:05:00.645945 2026] [autoindex:error] [pid 643253:tid 643402] [client 54.173.131.118:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:05:00.757254 2026] [autoindex:error] [pid 643253:tid 643393] [client 3.217.141.132:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:05:00.873456 2026] [security2:error] [pid 643253:tid 643410] [client 20.203.148.31:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ee.php"] [unique_id "amuEPMjqbtjBYzqM1uY-OgAAABo"]
[Thu Jul 30 12:05:00.976543 2026] [security2:error] [pid 643253:tid 643510] [client 172.202.44.182:62067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/bak.php"] [unique_id "amuEPMjqbtjBYzqM1uY-QAAAAH4"]
[Thu Jul 30 12:05:01.124151 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:01.128122 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:49004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEPcjqbtjBYzqM1uY-QQAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:01.448282 2026] [security2:error] [pid 643253:tid 643478] [client 207.154.212.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.212.154.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/info.php"] [unique_id "amuEPcjqbtjBYzqM1uY-RQAAAF4"]
[Thu Jul 30 12:05:01.852893 2026] [core:notice] [pid 643253:tid 643460] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:01.856848 2026] [security2:error] [pid 643253:tid 643460] [client 103.215.74.26:49008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEPcjqbtjBYzqM1uY-VAAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:02.519906 2026] [security2:error] [pid 643253:tid 643421] [client 172.202.44.182:62047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/content.php"] [unique_id "amuEPsjqbtjBYzqM1uY-YQAAACU"]
[Thu Jul 30 12:05:02.579434 2026] [core:notice] [pid 643253:tid 643411] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:02.585029 2026] [security2:error] [pid 643253:tid 643411] [client 103.215.74.26:49020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEPsjqbtjBYzqM1uY-YgAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:02.907351 2026] [autoindex:error] [pid 643253:tid 643444] [client 43.130.60.195:52814] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:05:03.064505 2026] [security2:error] [pid 643253:tid 643488] [client 74.7.244.60:43008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ajakholding.net"] [uri "/index.php"] [unique_id "amuEPcjqbtjBYzqM1uY-UAAAaGI"]
[Thu Jul 30 12:05:03.315629 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:03.320576 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:30224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEP8jqbtjBYzqM1uY-bgAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:03.407051 2026] [security2:error] [pid 643253:tid 643441] [client 172.202.44.182:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/upfile.php"] [unique_id "amuEP8jqbtjBYzqM1uY-dgAAADk"]
[Thu Jul 30 12:05:03.786378 2026] [security2:error] [pid 643253:tid 643263] [remote 216.73.216.152:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuEP8jqbtjBYzqM1uY-ewAAWwg"]
[Thu Jul 30 12:05:03.801755 2026] [security2:error] [pid 643253:tid 643479] [client 20.203.148.31:23478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/flower.php"] [unique_id "amuEP8jqbtjBYzqM1uY-fQAAAF8"]
[Thu Jul 30 12:05:04.056688 2026] [core:notice] [pid 643253:tid 643452] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:04.060661 2026] [security2:error] [pid 643253:tid 643452] [client 103.215.74.26:30228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQMjqbtjBYzqM1uY-hQAAAEQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:04.103248 2026] [security2:error] [pid 643253:tid 643470] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEP8jqbtjBYzqM1uY-egAAAFY"]
[Thu Jul 30 12:05:04.111713 2026] [security2:error] [pid 643253:tid 643485] [client 57.141.18.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laduchessecollections.com"] [uri "/index.php"] [unique_id "amuEPsjqbtjBYzqM1uY-YAAAZQ0"]
[Thu Jul 30 12:05:04.323064 2026] [security2:error] [pid 643253:tid 643432] [client 172.202.44.182:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/bypass.php"] [unique_id "amuEQMjqbtjBYzqM1uY-igAAADA"]
[Thu Jul 30 12:05:04.359893 2026] [core:notice] [pid 643253:tid 643459] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:04.773747 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:04.778091 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:30238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQMjqbtjBYzqM1uY-kQAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:05.242590 2026] [security2:error] [pid 643253:tid 643462] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEQMjqbtjBYzqM1uY-kAAAAE4"]
[Thu Jul 30 12:05:05.244518 2026] [security2:error] [pid 643253:tid 643460] [client 20.52.125.110:14914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/011i.php"] [unique_id "amuEQcjqbtjBYzqM1uY-pAAAAEw"]
[Thu Jul 30 12:05:05.499615 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:05.506165 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:30240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQcjqbtjBYzqM1uY-sAAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:05.569713 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:05.751943 2026] [security2:error] [pid 643253:tid 643399] [client 20.203.148.31:16683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/gecko-new.php"] [unique_id "amuEQcjqbtjBYzqM1uY-swAAAA8"]
[Thu Jul 30 12:05:05.864017 2026] [security2:error] [pid 643253:tid 643480] [client 20.52.125.110:14293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/03a005685d.php"] [unique_id "amuEQcjqbtjBYzqM1uY-vAAAAGA"]
[Thu Jul 30 12:05:06.136106 2026] [security2:error] [pid 643253:tid 643481] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEQcjqbtjBYzqM1uY-sgAAYXQ"]
[Thu Jul 30 12:05:06.224778 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:06.232102 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:30246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQsjqbtjBYzqM1uY-zQAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:06.425498 2026] [security2:error] [pid 643253:tid 643457] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEQcjqbtjBYzqM1uY-vQAAAEk"]
[Thu Jul 30 12:05:06.467839 2026] [security2:error] [pid 643253:tid 643443] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEQcjqbtjBYzqM1uY-uwAAOx8"]
[Thu Jul 30 12:05:06.630065 2026] [security2:error] [pid 643253:tid 643434] [client 20.52.125.110:14331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/403.php"] [unique_id "amuEQsjqbtjBYzqM1uY-3wAAADI"]
[Thu Jul 30 12:05:06.642594 2026] [security2:error] [pid 643253:tid 643392] [client 20.203.148.31:23427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/m.php"] [unique_id "amuEQsjqbtjBYzqM1uY-4AAAAAg"]
[Thu Jul 30 12:05:06.994053 2026] [core:notice] [pid 643253:tid 643415] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:06.998521 2026] [security2:error] [pid 643253:tid 643415] [client 103.215.74.26:30260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQsjqbtjBYzqM1uY-5QAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:07.729820 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:07.734654 2026] [security2:error] [pid 643253:tid 643488] [client 103.215.74.26:30272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEQ8jqbtjBYzqM1uY_BAAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:07.812321 2026] [security2:error] [pid 643253:tid 643420] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEQsjqbtjBYzqM1uY-4QAAJCg"]
[Thu Jul 30 12:05:07.908031 2026] [security2:error] [pid 643253:tid 643447] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY--AAAAD8"]
[Thu Jul 30 12:05:08.077837 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:14926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/404.php"] [unique_id "amuERMjqbtjBYzqM1uY_BwAAAEE"]
[Thu Jul 30 12:05:08.465241 2026] [core:notice] [pid 643253:tid 643410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:08.474292 2026] [security2:error] [pid 643253:tid 643410] [client 103.215.74.26:30286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuERMjqbtjBYzqM1uY_DQAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:08.765147 2026] [security2:error] [pid 643253:tid 643468] [client 20.203.148.31:9457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuERMjqbtjBYzqM1uY_FAAAAFQ"]
[Thu Jul 30 12:05:08.787705 2026] [security2:error] [pid 643253:tid 643323] [remote 216.73.216.152:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuERMjqbtjBYzqM1uY_FQAAUkQ"]
[Thu Jul 30 12:05:08.890300 2026] [security2:error] [pid 643253:tid 643510] [client 172.202.44.182:4105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/updates.php"] [unique_id "amuERMjqbtjBYzqM1uY_FgAAAH4"]
[Thu Jul 30 12:05:09.200247 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:09.204607 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:30292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuERcjqbtjBYzqM1uY_IgAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:09.323028 2026] [security2:error] [pid 643253:tid 643471] [client 172.236.9.101:37907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-8AAAAFc"]
[Thu Jul 30 12:05:09.325858 2026] [security2:error] [pid 643253:tid 643401] [client 172.236.9.101:4320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-6wAAABE"]
[Thu Jul 30 12:05:09.342513 2026] [security2:error] [pid 643253:tid 643455] [client 172.236.9.101:45328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-7wAAAEc"]
[Thu Jul 30 12:05:09.344440 2026] [security2:error] [pid 643253:tid 643403] [client 172.236.9.101:60479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-8gAAABM"]
[Thu Jul 30 12:05:09.348422 2026] [security2:error] [pid 643253:tid 643431] [client 172.236.9.101:2004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-8QAAAC8"]
[Thu Jul 30 12:05:09.356557 2026] [security2:error] [pid 643253:tid 643493] [client 172.236.9.101:16721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-6gAAAG0"]
[Thu Jul 30 12:05:09.359676 2026] [security2:error] [pid 643253:tid 643389] [client 172.236.9.101:5947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-7AAAAAU"]
[Thu Jul 30 12:05:09.364117 2026] [security2:error] [pid 643253:tid 643424] [client 172.236.9.101:19948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-7QAAACg"]
[Thu Jul 30 12:05:09.364409 2026] [security2:error] [pid 643253:tid 643505] [client 172.236.9.101:2622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY--wAAAHk"]
[Thu Jul 30 12:05:09.379598 2026] [security2:error] [pid 643253:tid 643407] [client 172.236.9.101:20164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY--QAAABc"]
[Thu Jul 30 12:05:09.387272 2026] [security2:error] [pid 643253:tid 643504] [client 172.236.9.101:54700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-6QAAAHg"]
[Thu Jul 30 12:05:09.389713 2026] [security2:error] [pid 643253:tid 643460] [client 172.236.9.101:9059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-9QAAAEw"]
[Thu Jul 30 12:05:09.397744 2026] [security2:error] [pid 643253:tid 643462] [client 172.236.9.101:10833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-9AAAAE4"]
[Thu Jul 30 12:05:09.418045 2026] [security2:error] [pid 643253:tid 643486] [client 172.236.9.101:45205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-9gAAAGY"]
[Thu Jul 30 12:05:09.431175 2026] [security2:error] [pid 643253:tid 643482] [client 172.236.9.101:43397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-7gAAAGI"]
[Thu Jul 30 12:05:09.445062 2026] [security2:error] [pid 643253:tid 643385] [client 172.236.9.101:17746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-9wAAAAE"]
[Thu Jul 30 12:05:09.475286 2026] [security2:error] [pid 643253:tid 643444] [client 172.236.9.101:10634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY--gAAADw"]
[Thu Jul 30 12:05:09.502548 2026] [security2:error] [pid 643253:tid 643433] [client 172.236.9.101:20484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-_QAAADE"]
[Thu Jul 30 12:05:09.514006 2026] [security2:error] [pid 643253:tid 643461] [client 172.236.9.101:62663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-8wAAAE0"]
[Thu Jul 30 12:05:09.552284 2026] [security2:error] [pid 643253:tid 643438] [client 172.236.9.101:64613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEQ8jqbtjBYzqM1uY-_AAAADY"]
[Thu Jul 30 12:05:09.618264 2026] [security2:error] [pid 643253:tid 643484] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuERcjqbtjBYzqM1uY_GgAAAGQ"]
[Thu Jul 30 12:05:09.933987 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:09.938519 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:30296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuERcjqbtjBYzqM1uY_LgAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:10.117462 2026] [security2:error] [pid 643253:tid 643502] [client 20.52.125.110:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/aa.php"] [unique_id "amuERsjqbtjBYzqM1uY_MgAAAHY"]
[Thu Jul 30 12:05:10.133257 2026] [security2:error] [pid 643253:tid 643497] [client 172.202.44.182:4362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/xmrlpc.php"] [unique_id "amuERsjqbtjBYzqM1uY_NAAAAHE"]
[Thu Jul 30 12:05:10.205176 2026] [security2:error] [pid 643253:tid 643474] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuERcjqbtjBYzqM1uY_KAAAAFo"]
[Thu Jul 30 12:05:10.661854 2026] [core:notice] [pid 643253:tid 643473] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:10.666104 2026] [security2:error] [pid 643253:tid 643473] [client 103.215.74.26:30308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuERsjqbtjBYzqM1uY_PAAAAFk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:11.387213 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:11.391207 2026] [security2:error] [pid 643253:tid 643453] [client 103.215.74.26:30320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuER8jqbtjBYzqM1uY_SAAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:11.654786 2026] [security2:error] [pid 643253:tid 643390] [client 20.52.125.110:14916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/aafewc0k.php"] [unique_id "amuER8jqbtjBYzqM1uY_SQAAAAY"]
[Thu Jul 30 12:05:11.689731 2026] [security2:error] [pid 643253:tid 643452] [client 172.202.44.182:4408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/ae.php"] [unique_id "amuER8jqbtjBYzqM1uY_TQAAAEQ"]
[Thu Jul 30 12:05:12.093547 2026] [security2:error] [pid 643253:tid 643435] [client 20.203.148.31:21973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mah/flower.php"] [unique_id "amuESMjqbtjBYzqM1uY_UwAAADM"]
[Thu Jul 30 12:05:12.126831 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:12.130909 2026] [security2:error] [pid 643253:tid 643385] [client 103.215.74.26:30334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuESMjqbtjBYzqM1uY_VAAAAAE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:12.223603 2026] [security2:error] [pid 643253:tid 643427] [client 35.221.246.130:57902] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gbq.rty.temporary.site"] [uri "/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_WwAAACs"]
[Thu Jul 30 12:05:12.223709 2026] [security2:error] [pid 643253:tid 643427] [client 35.221.246.130:57902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.gbq.rty.temporary.site"] [uri "/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_WwAAACs"]
[Thu Jul 30 12:05:12.342282 2026] [security2:error] [pid 643253:tid 643450] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "gbq.rty.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuESMjqbtjBYzqM1uY_YgAAAEI"]
[Thu Jul 30 12:05:12.342771 2026] [security2:error] [pid 643253:tid 643405] [client 35.221.246.130:57906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "gbq.rty.temporary.site"] [uri "/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_YAAAABU"]
[Thu Jul 30 12:05:12.484938 2026] [security2:error] [pid 643253:tid 643507] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cpcontacts.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/404.html"] [unique_id "amuESMjqbtjBYzqM1uY_ZQAAAHs"]
[Thu Jul 30 12:05:12.485504 2026] [security2:error] [pid 643253:tid 643465] [client 35.221.246.130:57886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cpcontacts.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_YwAAAFE"]
[Thu Jul 30 12:05:12.684542 2026] [security2:error] [pid 643253:tid 643442] [client 20.203.148.31:17277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mah/xleet.php"] [unique_id "amuESMjqbtjBYzqM1uY_ZgAAADo"]
[Thu Jul 30 12:05:12.844950 2026] [security2:error] [pid 643253:tid 643414] [client 20.52.125.110:14929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/abcd.php"] [unique_id "amuESMjqbtjBYzqM1uY_bQAAAB4"]
[Thu Jul 30 12:05:12.852398 2026] [core:notice] [pid 643253:tid 643420] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:12.856424 2026] [security2:error] [pid 643253:tid 643420] [client 103.215.74.26:30338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuESMjqbtjBYzqM1uY_bgAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:12.887411 2026] [security2:error] [pid 643253:tid 643430] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cpcalendars.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/404.html"] [unique_id "amuESMjqbtjBYzqM1uY_cQAAAC4"]
[Thu Jul 30 12:05:12.887905 2026] [security2:error] [pid 643253:tid 643437] [client 35.221.246.130:57908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cpcalendars.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_bwAAADU"]
[Thu Jul 30 12:05:13.373177 2026] [security2:error] [pid 643253:tid 643387] [client 86.128.158.166:50630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEScjqbtjBYzqM1uY_cwAAAAM"], referer: http://pkf.jo
[Thu Jul 30 12:05:13.425566 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.148.31:9329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mini.php"] [unique_id "amuEScjqbtjBYzqM1uY_fQAAAGo"]
[Thu Jul 30 12:05:13.551223 2026] [security2:error] [pid 643253:tid 643469] [client 172.202.44.182:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/moon.php"] [unique_id "amuEScjqbtjBYzqM1uY_hgAAAFU"]
[Thu Jul 30 12:05:13.592876 2026] [security2:error] [pid 643253:tid 643466] [client 91.73.21.151:26273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEScjqbtjBYzqM1uY_dAAAAFI"], referer: http://pkf.jo
[Thu Jul 30 12:05:13.592997 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:13.598385 2026] [security2:error] [pid 643253:tid 643470] [client 103.215.74.26:34914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEScjqbtjBYzqM1uY_iAAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:14.112802 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:14.120909 2026] [security2:error] [pid 643253:tid 643415] [client 66.249.73.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuESsjqbtjBYzqM1uY_mAAAAB8"]
[Thu Jul 30 12:05:14.321463 2026] [core:notice] [pid 643253:tid 643445] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:14.328015 2026] [security2:error] [pid 643253:tid 643445] [client 103.215.74.26:34924] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuESsjqbtjBYzqM1uY_ngAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:14.338143 2026] [security2:error] [pid 643253:tid 643411] [client 20.52.125.110:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/about.php"] [unique_id "amuESsjqbtjBYzqM1uY_nwAAABs"]
[Thu Jul 30 12:05:14.350573 2026] [core:notice] [pid 643253:tid 643355] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:14.742914 2026] [security2:error] [pid 643253:tid 643447] [client 20.203.148.31:16681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/moon.php"] [unique_id "amuESsjqbtjBYzqM1uY_pgAAAD8"]
[Thu Jul 30 12:05:14.905577 2026] [security2:error] [pid 643253:tid 643410] [client 37.120.155.179:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuESsjqbtjBYzqM1uY_rAAAABo"]
[Thu Jul 30 12:05:14.905667 2026] [security2:error] [pid 643253:tid 643410] [client 37.120.155.179:55654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuESsjqbtjBYzqM1uY_rAAAABo"]
[Thu Jul 30 12:05:15.024262 2026] [security2:error] [pid 643253:tid 643436] [client 20.52.125.110:14312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/admin.php"] [unique_id "amuES8jqbtjBYzqM1uY_sgAAADQ"]
[Thu Jul 30 12:05:15.057245 2026] [core:notice] [pid 643253:tid 643393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:15.066403 2026] [security2:error] [pid 643253:tid 643393] [client 103.215.74.26:34940] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuES8jqbtjBYzqM1uY_swAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:15.140237 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:15.239961 2026] [security2:error] [pid 643253:tid 643483] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.riyadhprinter.com"] [uri "/index.php"] [unique_id "amuEScjqbtjBYzqM1uY_iwAAAGM"]
[Thu Jul 30 12:05:15.240021 2026] [security2:error] [pid 643253:tid 643483] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.riyadhprinter.com"] [uri "/index.php"] [unique_id "amuEScjqbtjBYzqM1uY_iwAAAGM"]
[Thu Jul 30 12:05:15.240745 2026] [security2:error] [pid 643253:tid 643476] [client 35.221.246.130:57910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.riyadhprinter.com"] [uri "/.git/config"] [unique_id "amuEScjqbtjBYzqM1uY_iQAAAFw"]
[Thu Jul 30 12:05:15.263126 2026] [security2:error] [pid 643253:tid 643392] [client 35.221.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.riyadhprinter.com"] [uri "/index.php"] [unique_id "amuESMjqbtjBYzqM1uY_WAAAAAg"]
[Thu Jul 30 12:05:15.263148 2026] [security2:error] [pid 643253:tid 643392] [client 35.221.246.130:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.riyadhprinter.com"] [uri "/index.php"] [unique_id "amuESMjqbtjBYzqM1uY_WAAAAAg"]
[Thu Jul 30 12:05:15.263877 2026] [security2:error] [pid 643253:tid 643460] [client 35.221.246.130:57860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.riyadhprinter.com"] [uri "/.git/config"] [unique_id "amuESMjqbtjBYzqM1uY_VgAAAEw"]
[Thu Jul 30 12:05:15.725081 2026] [security2:error] [pid 643253:tid 643485] [client 20.203.148.31:14722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/new.php"] [unique_id "amuES8jqbtjBYzqM1uY_wQAAAGU"]
[Thu Jul 30 12:05:15.826796 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:15.830806 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:34950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuES8jqbtjBYzqM1uY_wgAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:15.964533 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:16.159408 2026] [security2:error] [pid 643253:tid 643495] [client 20.52.125.110:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/adminfuns.php"] [unique_id "amuETMjqbtjBYzqM1uY_zgAAAG8"]
[Thu Jul 30 12:05:16.203283 2026] [security2:error] [pid 643253:tid 643389] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuES8jqbtjBYzqM1uY_wAAABXc"]
[Thu Jul 30 12:05:16.429349 2026] [security2:error] [pid 643253:tid 643498] [client 37.120.155.179:55656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuETMjqbtjBYzqM1uY_0gAAAHI"]
[Thu Jul 30 12:05:16.429457 2026] [security2:error] [pid 643253:tid 643498] [client 37.120.155.179:55656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuETMjqbtjBYzqM1uY_0gAAAHI"]
[Thu Jul 30 12:05:16.595190 2026] [security2:error] [pid 643253:tid 643401] [client 172.202.44.182:4397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/blog.php"] [unique_id "amuETMjqbtjBYzqM1uY_1wAAABE"]
[Thu Jul 30 12:05:16.614436 2026] [core:notice] [pid 643253:tid 643487] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:16.618422 2026] [security2:error] [pid 643253:tid 643487] [client 103.215.74.26:34954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuETMjqbtjBYzqM1uY_2AAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:16.633570 2026] [security2:error] [pid 643253:tid 643491] [client 74.7.241.154:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thdinfinity.com"] [uri "/robots.txt"] [unique_id "amuETMjqbtjBYzqM1uY_2wAAAGs"]
[Thu Jul 30 12:05:16.634260 2026] [security2:error] [pid 643253:tid 643472] [client 74.7.241.154:48378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thdinfinity.com"] [uri "/robots.txt"] [unique_id "amuETMjqbtjBYzqM1uY_2QAAWHI"]
[Thu Jul 30 12:05:16.888832 2026] [security2:error] [pid 643253:tid 643440] [client 20.203.148.31:9869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/radio.php"] [unique_id "amuETMjqbtjBYzqM1uY_3wAAADg"]
[Thu Jul 30 12:05:17.001655 2026] [security2:error] [pid 643253:tid 643429] [client 207.154.212.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.echomemoversalain.casa"] [uri "/index.php"] [unique_id "amuETMjqbtjBYzqM1uY_1gAAAC0"]
[Thu Jul 30 12:05:17.118043 2026] [security2:error] [pid 643253:tid 643405] [client 20.52.125.110:14913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/albin.php"] [unique_id "amuETcjqbtjBYzqM1uY_5wAAABU"]
[Thu Jul 30 12:05:17.345893 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:17.353334 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:34956] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuETcjqbtjBYzqM1uY_6AAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:17.465387 2026] [core:notice] [pid 643253:tid 643393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:17.512425 2026] [security2:error] [pid 643253:tid 643408] [client 20.203.148.31:21987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/s.php"] [unique_id "amuETcjqbtjBYzqM1uY_9AAAABg"]
[Thu Jul 30 12:05:17.700224 2026] [security2:error] [pid 643253:tid 643455] [client 74.7.175.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mhh.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuES8jqbtjBYzqM1uY_zAAAAEc"]
[Thu Jul 30 12:05:17.701107 2026] [security2:error] [pid 643253:tid 643428] [client 74.7.175.157:36014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mhh.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuES8jqbtjBYzqM1uY_ygAALHo"]
[Thu Jul 30 12:05:17.774128 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:14283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/amfsqvgv.php"] [unique_id "amuETcjqbtjBYzqM1uY_-QAAACc"]
[Thu Jul 30 12:05:18.021515 2026] [security2:error] [pid 643253:tid 643499] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuETcjqbtjBYzqM1uY_6QAAc34"]
[Thu Jul 30 12:05:18.049229 2026] [core:notice] [pid 643253:tid 643470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:18.078371 2026] [core:notice] [pid 643253:tid 643466] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:18.082351 2026] [security2:error] [pid 643253:tid 643466] [client 103.215.74.26:34960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuETsjqbtjBYzqM1uZABAAAAFI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:18.093511 2026] [security2:error] [pid 643253:tid 643425] [client 172.202.44.182:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/ini.php"] [unique_id "amuETsjqbtjBYzqM1uZABQAAACk"]
[Thu Jul 30 12:05:18.394779 2026] [security2:error] [pid 643253:tid 643435] [client 74.7.241.168:46750] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "stunningtouchcleaning.com"] [uri "/robots.txt"] [unique_id "amuETsjqbtjBYzqM1uZACQAAM2k"]
[Thu Jul 30 12:05:18.421320 2026] [security2:error] [pid 643253:tid 643461] [client 20.203.148.31:16692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sim.php"] [unique_id "amuETsjqbtjBYzqM1uZACwAAAE0"]
[Thu Jul 30 12:05:18.458622 2026] [security2:error] [pid 643253:tid 643486] [client 20.52.125.110:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/ant.php"] [unique_id "amuETsjqbtjBYzqM1uZADAAAAGY"]
[Thu Jul 30 12:05:18.807042 2026] [core:notice] [pid 643253:tid 643411] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:18.811025 2026] [security2:error] [pid 643253:tid 643411] [client 103.215.74.26:34976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuETsjqbtjBYzqM1uZAFwAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:18.995962 2026] [security2:error] [pid 643253:tid 643472] [client 190.6.14.187:10956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuETsjqbtjBYzqM1uZAFQAAAFg"], referer: http://pkf.jo
[Thu Jul 30 12:05:19.090117 2026] [security2:error] [pid 643253:tid 643396] [client 172.202.44.182:46815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/admin-ajax.php"] [unique_id "amuET8jqbtjBYzqM1uZAHwAAAAw"]
[Thu Jul 30 12:05:19.218054 2026] [security2:error] [pid 643253:tid 643437] [client 20.52.125.110:14322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/appreciators.php"] [unique_id "amuET8jqbtjBYzqM1uZAIwAAADU"]
[Thu Jul 30 12:05:19.252774 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:19.536984 2026] [core:notice] [pid 643253:tid 643476] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:19.540945 2026] [security2:error] [pid 643253:tid 643476] [client 103.215.74.26:34988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuET8jqbtjBYzqM1uZAJQAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:20.272596 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:20.276601 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:34996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEUMjqbtjBYzqM1uZANQAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:20.324214 2026] [security2:error] [pid 643253:tid 643459] [client 20.52.125.110:14928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/archive.php"] [unique_id "amuEUMjqbtjBYzqM1uZANwAAAEs"]
[Thu Jul 30 12:05:20.483660 2026] [security2:error] [pid 643253:tid 643428] [client 172.202.44.182:62068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/akc.php"] [unique_id "amuEUMjqbtjBYzqM1uZAOwAAACw"]
[Thu Jul 30 12:05:20.532487 2026] [security2:error] [pid 643253:tid 643265] [remote 74.7.242.7:52036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuEUMjqbtjBYzqM1uZANgAASQo"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:05:21.082690 2026] [security2:error] [pid 643253:tid 643498] [client 20.203.148.31:26370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/text.php"] [unique_id "amuEUcjqbtjBYzqM1uZASwAAAHI"]
[Thu Jul 30 12:05:21.093322 2026] [security2:error] [pid 643253:tid 643426] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEUMjqbtjBYzqM1uZAOgAAACo"]
[Thu Jul 30 12:05:21.577729 2026] [security2:error] [pid 643253:tid 643394] [client 172.202.44.182:62026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/akcc.php"] [unique_id "amuEUcjqbtjBYzqM1uZAVAAAAAo"]
[Thu Jul 30 12:05:21.786800 2026] [security2:error] [pid 643253:tid 643384] [client 66.249.74.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bensecuritylocksmith.site"] [uri "/index.php"] [unique_id "amuEUcjqbtjBYzqM1uZAUgAAABE"]
[Thu Jul 30 12:05:21.938950 2026] [security2:error] [pid 643253:tid 643406] [client 20.203.148.31:21992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/user.php"] [unique_id "amuEUcjqbtjBYzqM1uZAXgAAABY"]
[Thu Jul 30 12:05:22.702280 2026] [security2:error] [pid 643253:tid 643506] [client 20.203.148.31:9414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/webadmin.php"] [unique_id "amuEUsjqbtjBYzqM1uZAaAAAAHo"]
[Thu Jul 30 12:05:22.722516 2026] [core:error] [pid 643253:tid 643453] [client 195.96.139.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:05:22.722535 2026] [core:error] [pid 643253:tid 643453] [client 195.96.139.69:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:05:22.959828 2026] [security2:error] [pid 643253:tid 643448] [client 172.202.44.182:4388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/asasx.php"] [unique_id "amuEUsjqbtjBYzqM1uZAbwAAAEA"]
[Thu Jul 30 12:05:23.146498 2026] [security2:error] [pid 643253:tid 643294] [remote 74.7.242.7:52036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuEU8jqbtjBYzqM1uZAcAAAcyc"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:05:23.513091 2026] [security2:error] [pid 643253:tid 643438] [client 20.52.125.110:14321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/as.php"] [unique_id "amuEU8jqbtjBYzqM1uZAeAAAADY"]
[Thu Jul 30 12:05:23.517616 2026] [security2:error] [pid 643253:tid 643509] [client 88.241.169.202:36622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEU8jqbtjBYzqM1uZAcQAAAH0"], referer: http://pkf.jo
[Thu Jul 30 12:05:24.091435 2026] [security2:error] [pid 643253:tid 643464] [client 185.91.192.106:58001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEU8jqbtjBYzqM1uZAgQAAAFA"], referer: http://pkf.jo
[Thu Jul 30 12:05:24.331642 2026] [security2:error] [pid 643253:tid 643504] [client 172.202.44.182:62031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/axx.php"] [unique_id "amuEVMjqbtjBYzqM1uZAjgAAAHg"]
[Thu Jul 30 12:05:24.846794 2026] [security2:error] [pid 643253:tid 643489] [client 20.203.148.31:26960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amuEVMjqbtjBYzqM1uZAlQAAAGk"]
[Thu Jul 30 12:05:25.677811 2026] [security2:error] [pid 643253:tid 643406] [client 172.202.44.182:62024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/berax.php"] [unique_id "amuEVcjqbtjBYzqM1uZAnQAAABY"]
[Thu Jul 30 12:05:25.851241 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:25.916746 2026] [security2:error] [pid 643253:tid 643477] [client 20.52.125.110:14934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/atomlib.php"] [unique_id "amuEVcjqbtjBYzqM1uZApgAAAF0"]
[Thu Jul 30 12:05:26.014502 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:26.018883 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:39748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEVsjqbtjBYzqM1uZApwAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:26.116764 2026] [security2:error] [pid 643253:tid 643387] [client 106.200.13.198:28444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.13.200.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "urwru.club"] [uri "/xmlrpc.php"] [unique_id "amuEVcjqbtjBYzqM1uZAowAAAAM"]
[Thu Jul 30 12:05:26.116960 2026] [security2:error] [pid 643253:tid 643387] [client 106.200.13.198:28444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "urwru.club"] [uri "/xmlrpc.php"] [unique_id "amuEVcjqbtjBYzqM1uZAowAAAAM"]
[Thu Jul 30 12:05:26.615459 2026] [security2:error] [pid 643253:tid 643416] [client 20.52.125.110:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/autoload_classmap.php"] [unique_id "amuEVsjqbtjBYzqM1uZAsQAAACA"]
[Thu Jul 30 12:05:26.736581 2026] [core:notice] [pid 643253:tid 643425] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:26.740419 2026] [security2:error] [pid 643253:tid 643425] [client 103.215.74.26:39756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEVsjqbtjBYzqM1uZAswAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:26.922291 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:27.473154 2026] [security2:error] [pid 643253:tid 643463] [client 20.52.125.110:14314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/bb.php"] [unique_id "amuEV8jqbtjBYzqM1uZAwgAAAE8"]
[Thu Jul 30 12:05:27.475928 2026] [core:notice] [pid 643253:tid 643445] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:27.479863 2026] [security2:error] [pid 643253:tid 643445] [client 103.215.74.26:39758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEV8jqbtjBYzqM1uZAwwAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:28.205512 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:28.209580 2026] [security2:error] [pid 643253:tid 643484] [client 103.215.74.26:39760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEWMjqbtjBYzqM1uZAywAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:28.607201 2026] [security2:error] [pid 643253:tid 643422] [client 20.52.125.110:14333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/bnm.php"] [unique_id "amuEWMjqbtjBYzqM1uZA1gAAACY"]
[Thu Jul 30 12:05:28.948275 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:28.952353 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:39768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEWMjqbtjBYzqM1uZA2wAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:29.106691 2026] [security2:error] [pid 643253:tid 643501] [client 172.202.44.182:51783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/build.php"] [unique_id "amuEWcjqbtjBYzqM1uZA4QAAAHU"]
[Thu Jul 30 12:05:29.235437 2026] [security2:error] [pid 643253:tid 643437] [client 20.52.125.110:14332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/bootstrap.php"] [unique_id "amuEWcjqbtjBYzqM1uZA4gAAADU"]
[Thu Jul 30 12:05:29.339229 2026] [security2:error] [pid 643253:tid 643455] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuEWcjqbtjBYzqM1uZA4wAAR0M"]
[Thu Jul 30 12:05:29.664516 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:29.668872 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:39776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEWcjqbtjBYzqM1uZA6wAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:29.953126 2026] [security2:error] [pid 643253:tid 643392] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEWcjqbtjBYzqM1uZA5AAACEI"]
[Thu Jul 30 12:05:29.995219 2026] [security2:error] [pid 643253:tid 643409] [client 20.203.148.31:26966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amuEWcjqbtjBYzqM1uZA-wAAABk"]
[Thu Jul 30 12:05:30.004748 2026] [security2:error] [pid 643253:tid 643403] [client 172.202.44.182:4459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/buy.php"] [unique_id "amuEWsjqbtjBYzqM1uZA_gAAABM"]
[Thu Jul 30 12:05:30.384289 2026] [security2:error] [pid 643253:tid 643425] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEWcjqbtjBYzqM1uZA7gAAACk"]
[Thu Jul 30 12:05:30.415691 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:30.420001 2026] [security2:error] [pid 643253:tid 643486] [client 103.215.74.26:39782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEWsjqbtjBYzqM1uZBAwAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:30.869096 2026] [security2:error] [pid 643253:tid 643507] [client 172.202.44.182:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/checkbox.php"] [unique_id "amuEWsjqbtjBYzqM1uZBDgAAAHs"]
[Thu Jul 30 12:05:30.926775 2026] [security2:error] [pid 643253:tid 643491] [client 20.203.148.31:33996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amuEWsjqbtjBYzqM1uZBDwAAAGs"]
[Thu Jul 30 12:05:31.151178 2026] [core:notice] [pid 643253:tid 643449] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:31.155560 2026] [security2:error] [pid 643253:tid 643449] [client 103.215.74.26:39798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEW8jqbtjBYzqM1uZBGgAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:31.387378 2026] [security2:error] [pid 643253:tid 643428] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEWsjqbtjBYzqM1uZBDQAAACw"]
[Thu Jul 30 12:05:31.554034 2026] [security2:error] [pid 643253:tid 643429] [client 20.203.148.31:26407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amuEW8jqbtjBYzqM1uZBHgAAAC0"]
[Thu Jul 30 12:05:31.699016 2026] [security2:error] [pid 643253:tid 643410] [client 172.202.44.182:51821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/cong.php"] [unique_id "amuEW8jqbtjBYzqM1uZBIgAAABo"]
[Thu Jul 30 12:05:31.873312 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:31.877633 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:39804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEW8jqbtjBYzqM1uZBJAAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:32.583104 2026] [security2:error] [pid 643253:tid 643462] [client 172.202.44.182:46802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/file4.php"] [unique_id "amuEXMjqbtjBYzqM1uZBNgAAAE4"]
[Thu Jul 30 12:05:32.599171 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:32.602393 2026] [security2:error] [pid 643253:tid 643435] [client 139.28.219.70:40806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuEXMjqbtjBYzqM1uZBOAAAADM"]
[Thu Jul 30 12:05:32.606569 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:39810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEXMjqbtjBYzqM1uZBNwAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:32.689204 2026] [security2:error] [pid 643253:tid 643474] [client 20.203.148.31:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amuEXMjqbtjBYzqM1uZBPAAAAFo"]
[Thu Jul 30 12:05:32.877039 2026] [security2:error] [pid 643253:tid 643431] [client 139.28.219.70:40814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alqimmafurnituremovers.xyz"] [uri "/xmlrpc.php"] [unique_id "amuEXMjqbtjBYzqM1uZBPQAAAC8"]
[Thu Jul 30 12:05:33.136455 2026] [security2:error] [pid 643253:tid 643389] [client 139.28.219.70:40820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuEXcjqbtjBYzqM1uZBQgAAAAU"]
[Thu Jul 30 12:05:33.395223 2026] [security2:error] [pid 643253:tid 643485] [client 139.28.219.70:40828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuEXcjqbtjBYzqM1uZBRgAAAGU"]
[Thu Jul 30 12:05:33.522155 2026] [security2:error] [pid 643253:tid 643450] [client 20.203.148.31:16665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amuEXcjqbtjBYzqM1uZBRwAAAEI"]
[Thu Jul 30 12:05:33.715773 2026] [security2:error] [pid 643253:tid 643451] [client 139.28.219.70:40830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuEXcjqbtjBYzqM1uZBTgAAAEM"]
[Thu Jul 30 12:05:34.073114 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:34.097834 2026] [security2:error] [pid 643253:tid 643396] [client 139.28.219.70:40842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuEXsjqbtjBYzqM1uZBVQAAAAw"]
[Thu Jul 30 12:05:34.345540 2026] [security2:error] [pid 643253:tid 643428] [client 136.111.185.9:10752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.185.111.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/PBB/issue/current"] [unique_id "amuEXsjqbtjBYzqM1uZBVAAAACw"]
[Thu Jul 30 12:05:34.478628 2026] [security2:error] [pid 643253:tid 643508] [client 139.28.219.70:40854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuEXsjqbtjBYzqM1uZBXgAAAHw"]
[Thu Jul 30 12:05:34.543177 2026] [security2:error] [pid 643253:tid 643452] [client 172.202.44.182:46845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/flower.php"] [unique_id "amuEXsjqbtjBYzqM1uZBXwAAAEQ"]
[Thu Jul 30 12:05:34.739777 2026] [security2:error] [pid 643253:tid 643412] [client 139.28.219.70:40858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuEXsjqbtjBYzqM1uZBZAAAABw"]
[Thu Jul 30 12:05:35.012055 2026] [security2:error] [pid 643253:tid 643448] [client 139.28.219.70:40868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuEX8jqbtjBYzqM1uZBaAAAAEA"]
[Thu Jul 30 12:05:35.168498 2026] [security2:error] [pid 643253:tid 643434] [client 20.203.148.31:9647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuEX8jqbtjBYzqM1uZBaQAAADI"]
[Thu Jul 30 12:05:35.349283 2026] [security2:error] [pid 643253:tid 643403] [client 139.28.219.70:40884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuEX8jqbtjBYzqM1uZBcAAAABM"]
[Thu Jul 30 12:05:35.468681 2026] [security2:error] [pid 643253:tid 643473] [client 20.52.125.110:14304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/buy.php"] [unique_id "amuEX8jqbtjBYzqM1uZBcgAAAFk"]
[Thu Jul 30 12:05:35.664375 2026] [security2:error] [pid 643253:tid 643474] [client 139.28.219.70:40900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuEX8jqbtjBYzqM1uZBcwAAAFo"]
[Thu Jul 30 12:05:35.792370 2026] [security2:error] [pid 643253:tid 643458] [client 20.203.148.31:9430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amuEX8jqbtjBYzqM1uZBeQAAAEo"]
[Thu Jul 30 12:05:35.847364 2026] [core:error] [pid 643253:tid 643359] [remote 43.140.223.163:53002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://mahsudtransportandbuildingdemolition.business/robots.txt
[Thu Jul 30 12:05:35.847384 2026] [core:error] [pid 643253:tid 643359] [remote 43.140.223.163:53002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://mahsudtransportandbuildingdemolition.business/robots.txt
[Thu Jul 30 12:05:35.852083 2026] [core:error] [pid 643253:tid 643348] [remote 120.53.89.23:54390] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://mahsudtransportandbuildingdemolition.business/robots.txt
[Thu Jul 30 12:05:35.852101 2026] [core:error] [pid 643253:tid 643348] [remote 120.53.89.23:54390] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://mahsudtransportandbuildingdemolition.business/robots.txt
[Thu Jul 30 12:05:35.932924 2026] [security2:error] [pid 643253:tid 643479] [client 139.28.219.70:40916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuEX8jqbtjBYzqM1uZBfQAAAF8"]
[Thu Jul 30 12:05:36.267829 2026] [security2:error] [pid 643253:tid 643487] [client 139.28.219.70:40932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuEYMjqbtjBYzqM1uZBgQAAAGc"]
[Thu Jul 30 12:05:36.345535 2026] [security2:error] [pid 643253:tid 643426] [client 20.52.125.110:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/chosen.php"] [unique_id "amuEYMjqbtjBYzqM1uZBggAAACo"]
[Thu Jul 30 12:05:36.386239 2026] [security2:error] [pid 643253:tid 643401] [client 20.203.148.31:16685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amuEYMjqbtjBYzqM1uZBhgAAABE"]
[Thu Jul 30 12:05:36.439156 2026] [security2:error] [pid 643253:tid 643409] [client 172.202.44.182:62059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/form.php"] [unique_id "amuEYMjqbtjBYzqM1uZBhwAAABk"]
[Thu Jul 30 12:05:36.551083 2026] [security2:error] [pid 643253:tid 643449] [client 139.28.219.70:40936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuEYMjqbtjBYzqM1uZBiwAAAEE"]
[Thu Jul 30 12:05:36.698274 2026] [security2:error] [pid 643253:tid 643377] [remote 172.232.108.36:42030] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuEYMjqbtjBYzqM1uZBjAAADno"]
[Thu Jul 30 12:05:36.860950 2026] [security2:error] [pid 643253:tid 643436] [client 139.28.219.70:40950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuEYMjqbtjBYzqM1uZBkQAAADQ"]
[Thu Jul 30 12:05:36.990091 2026] [security2:error] [pid 643253:tid 643381] [remote 139.59.102.237:54490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.102.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/wp-login.php"] [unique_id "amuEYMjqbtjBYzqM1uZBjQAAWH4"]
[Thu Jul 30 12:05:37.136127 2026] [security2:error] [pid 643253:tid 643492] [client 139.28.219.70:40962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alqimmafurnituremovers.xyz"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuEYcjqbtjBYzqM1uZBlQAAAGw"]
[Thu Jul 30 12:05:37.188541 2026] [security2:error] [pid 643253:tid 643396] [client 20.203.148.31:34021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amuEYcjqbtjBYzqM1uZBlgAAAAw"]
[Thu Jul 30 12:05:37.478214 2026] [security2:error] [pid 643253:tid 643483] [client 172.202.44.182:51789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/gecko.php"] [unique_id "amuEYcjqbtjBYzqM1uZBnQAAAGM"]
[Thu Jul 30 12:05:37.653545 2026] [security2:error] [pid 643253:tid 643406] [client 20.52.125.110:14311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/class-wp-image.php"] [unique_id "amuEYcjqbtjBYzqM1uZBoAAAABY"]
[Thu Jul 30 12:05:37.952897 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.148.31:17677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/flower.php"] [unique_id "amuEYcjqbtjBYzqM1uZBqQAAAGo"]
[Thu Jul 30 12:05:38.378727 2026] [security2:error] [pid 643253:tid 643466] [client 172.202.44.182:46832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/kyami.php"] [unique_id "amuEYsjqbtjBYzqM1uZBrgAAAFI"]
[Thu Jul 30 12:05:38.411483 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:38.415720 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:63838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEYsjqbtjBYzqM1uZBsAAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:38.589032 2026] [security2:error] [pid 643253:tid 643427] [client 20.52.125.110:14925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/classsmtps.php"] [unique_id "amuEYsjqbtjBYzqM1uZBtAAAACs"]
[Thu Jul 30 12:05:39.042920 2026] [security2:error] [pid 643253:tid 643459] [client 20.203.148.31:33989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amuEY8jqbtjBYzqM1uZBvgAAAEs"]
[Thu Jul 30 12:05:39.142841 2026] [core:notice] [pid 643253:tid 643440] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:39.147233 2026] [security2:error] [pid 643253:tid 643440] [client 103.215.74.26:63840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEY8jqbtjBYzqM1uZBvwAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:39.534017 2026] [security2:error] [pid 643253:tid 643430] [client 172.202.44.182:62065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/manager.php"] [unique_id "amuEY8jqbtjBYzqM1uZBxwAAAC4"]
[Thu Jul 30 12:05:39.716395 2026] [security2:error] [pid 643253:tid 643390] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEY8jqbtjBYzqM1uZBwAAABgw"]
[Thu Jul 30 12:05:39.869798 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:39.873888 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:63846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEY8jqbtjBYzqM1uZByQAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:40.275571 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:40.462732 2026] [security2:error] [pid 643253:tid 643391] [client 172.202.44.182:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/mari.php"] [unique_id "amuEZMjqbtjBYzqM1uZB1QAAAAc"]
[Thu Jul 30 12:05:40.591389 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:40.595511 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:63850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZMjqbtjBYzqM1uZB3AAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:41.327247 2026] [core:notice] [pid 643253:tid 643496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:41.331365 2026] [security2:error] [pid 643253:tid 643496] [client 103.215.74.26:63860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZcjqbtjBYzqM1uZB6AAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:41.518637 2026] [security2:error] [pid 643253:tid 643475] [client 172.202.44.182:4453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/nc4.php"] [unique_id "amuEZcjqbtjBYzqM1uZB6QAAAFs"]
[Thu Jul 30 12:05:41.657498 2026] [security2:error] [pid 643253:tid 643297] [remote 97.74.93.24:43452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amuEZcjqbtjBYzqM1uZB8wAAPCo"]
[Thu Jul 30 12:05:42.063955 2026] [core:notice] [pid 643253:tid 643425] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:42.067796 2026] [security2:error] [pid 643253:tid 643467] [client 20.52.125.110:14948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/classwithtostring.php"] [unique_id "amuEZsjqbtjBYzqM1uZB9gAAAFM"]
[Thu Jul 30 12:05:42.068465 2026] [security2:error] [pid 643253:tid 643425] [client 103.215.74.26:63866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZsjqbtjBYzqM1uZB9AAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:42.800317 2026] [core:notice] [pid 643253:tid 643451] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:42.807781 2026] [security2:error] [pid 643253:tid 643451] [client 103.215.74.26:63868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZsjqbtjBYzqM1uZCBAAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:42.850204 2026] [cgid:error] [pid 643253:tid 643401] [client 172.202.44.182:57998] AH01265: stderr from /home2/xjjgzjte/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:05:42.855572 2026] [security2:error] [pid 643253:tid 643388] [client 57.141.0.68:36022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuEZsjqbtjBYzqM1uZB_AAABHQ"], referer: https://igetvape-australia.com/product-tag/iget-moon-passion-fruit-lychee-5000-puffs/
[Thu Jul 30 12:05:42.871068 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:14922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/config.php"] [unique_id "amuEZsjqbtjBYzqM1uZCBgAAACc"]
[Thu Jul 30 12:05:43.452801 2026] [core:notice] [pid 643253:tid 643287] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:43.534473 2026] [core:notice] [pid 643253:tid 643396] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:43.541084 2026] [security2:error] [pid 643253:tid 643396] [client 103.215.74.26:55852] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEZ8jqbtjBYzqM1uZCFwAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:43.797148 2026] [security2:error] [pid 643253:tid 643419] [client 34.86.95.193:58940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kev.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuEZ8jqbtjBYzqM1uZCGAAAACM"]
[Thu Jul 30 12:05:44.203239 2026] [security2:error] [pid 643253:tid 643492] [client 20.52.125.110:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/core.php"] [unique_id "amuEaMjqbtjBYzqM1uZCIwAAAGw"]
[Thu Jul 30 12:05:44.333833 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:44.556968 2026] [security2:error] [pid 643253:tid 643438] [client 113.191.118.192:48921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEaMjqbtjBYzqM1uZCJAAAADY"], referer: http://pkf.jo
[Thu Jul 30 12:05:44.663684 2026] [security2:error] [pid 643253:tid 643392] [client 114.119.147.113:57799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jwcpartners.org"] [uri "/robots.txt"] [unique_id "amuEaMjqbtjBYzqM1uZCNAAAAAg"], referer: https://jwcpartners.org/robots.txt
[Thu Jul 30 12:05:44.922631 2026] [core:notice] [pid 643253:tid 643312] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:44.936829 2026] [security2:error] [pid 643253:tid 643424] [client 20.203.148.31:17241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amuEaMjqbtjBYzqM1uZCOQAAACg"]
[Thu Jul 30 12:05:45.045316 2026] [security2:error] [pid 643253:tid 643425] [client 20.52.125.110:14401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/css.php"] [unique_id "amuEacjqbtjBYzqM1uZCPgAAACk"]
[Thu Jul 30 12:05:45.212444 2026] [core:notice] [pid 643253:tid 643323] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:45.421271 2026] [security2:error] [pid 643253:tid 643507] [client 106.214.131.239:48812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEacjqbtjBYzqM1uZCQgAAAHs"], referer: http://pkf.jo
[Thu Jul 30 12:05:45.595552 2026] [security2:error] [pid 643253:tid 643411] [client 20.52.125.110:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/database.php"] [unique_id "amuEacjqbtjBYzqM1uZCTAAAABs"]
[Thu Jul 30 12:05:46.114995 2026] [security2:error] [pid 643253:tid 643506] [client 107.175.212.202:39102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.212.175.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.northyorksheridanmall.com"] [uri "/wp-comments-post.php"] [unique_id "amuEasjqbtjBYzqM1uZCVAAAAHo"], referer: http://www.northyorksheridanmall.com/?p=26
[Thu Jul 30 12:05:46.115104 2026] [security2:error] [pid 643253:tid 643506] [client 107.175.212.202:39102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.northyorksheridanmall.com"] [uri "/wp-comments-post.php"] [unique_id "amuEasjqbtjBYzqM1uZCVAAAAHo"], referer: http://www.northyorksheridanmall.com/?p=26
[Thu Jul 30 12:05:46.458989 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:46.708394 2026] [security2:error] [pid 643253:tid 643472] [client 34.86.95.193:61436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kev.udi.temporary.site"] [uri "/index.php"] [unique_id "amuEasjqbtjBYzqM1uZCXQAAAFg"]
[Thu Jul 30 12:05:46.956792 2026] [security2:error] [pid 643253:tid 643478] [client 34.86.95.193:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.95.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kev.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuEasjqbtjBYzqM1uZCYQAAAF4"]
[Thu Jul 30 12:05:46.956923 2026] [security2:error] [pid 643253:tid 643478] [client 34.86.95.193:61436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kev.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuEasjqbtjBYzqM1uZCYQAAAF4"]
[Thu Jul 30 12:05:47.374275 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:47.432344 2026] [security2:error] [pid 643253:tid 643511] [client 20.52.125.110:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/db.php"] [unique_id "amuEa8jqbtjBYzqM1uZCbAAAAH8"]
[Thu Jul 30 12:05:47.724698 2026] [core:notice] [pid 643253:tid 643401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:47.876544 2026] [security2:error] [pid 643253:tid 643500] [client 74.7.230.14:34946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ajg.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuEa8jqbtjBYzqM1uZCdgAAAHQ"]
[Thu Jul 30 12:05:48.025895 2026] [security2:error] [pid 643253:tid 643395] [client 20.52.125.110:14919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/default.php"] [unique_id "amuEbMjqbtjBYzqM1uZCdwAAAAs"]
[Thu Jul 30 12:05:49.021230 2026] [security2:error] [pid 643253:tid 643418] [client 202.21.121.117:53949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.121.21.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vertexfurnituretransport.site"] [uri "/xmlrpc.php"] [unique_id "amuEbMjqbtjBYzqM1uZCggAAACI"]
[Thu Jul 30 12:05:49.021454 2026] [security2:error] [pid 643253:tid 643418] [client 202.21.121.117:53949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vertexfurnituretransport.site"] [uri "/xmlrpc.php"] [unique_id "amuEbMjqbtjBYzqM1uZCggAAACI"]
[Thu Jul 30 12:05:49.209480 2026] [security2:error] [pid 643253:tid 643398] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEbMjqbtjBYzqM1uZCgQAADlY"]
[Thu Jul 30 12:05:49.270358 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:49.274273 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:55856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEbcjqbtjBYzqM1uZCkAAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:50.030540 2026] [core:notice] [pid 643253:tid 643478] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:50.034579 2026] [security2:error] [pid 643253:tid 643478] [client 103.215.74.26:55860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEbsjqbtjBYzqM1uZCmwAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:50.479033 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:14975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/dropdown.php"] [unique_id "amuEbsjqbtjBYzqM1uZCowAAAEE"]
[Thu Jul 30 12:05:50.797705 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:50.804390 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:55866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEbsjqbtjBYzqM1uZCqQAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:51.311145 2026] [security2:error] [pid 643253:tid 643331] [remote 74.7.241.60:56584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuEb8jqbtjBYzqM1uZCsAAAOkw"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:05:51.541347 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:51.545405 2026] [security2:error] [pid 643253:tid 643414] [client 103.215.74.26:55876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEb8jqbtjBYzqM1uZCtQAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:51.650799 2026] [security2:error] [pid 643253:tid 643463] [client 186.114.235.94:50215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEb8jqbtjBYzqM1uZCsQAAAE8"], referer: http://pkf.jo
[Thu Jul 30 12:05:52.096317 2026] [security2:error] [pid 643253:tid 643511] [client 20.203.148.31:26415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amuEcMjqbtjBYzqM1uZCvwAAAH8"]
[Thu Jul 30 12:05:52.289816 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:52.294000 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:55882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEcMjqbtjBYzqM1uZCwwAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:53.030377 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:53.034286 2026] [security2:error] [pid 643253:tid 643454] [client 103.215.74.26:36000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEccjqbtjBYzqM1uZCzgAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:53.817378 2026] [security2:error] [pid 643253:tid 643460] [client 47.128.24.232:14544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-mevius.com"] [uri "/robots.txt"] [unique_id "amuEccjqbtjBYzqM1uZC4wAAAEw"]
[Thu Jul 30 12:05:53.851523 2026] [security2:error] [pid 643253:tid 643478] [client 74.7.241.130:42460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ajakholding.net"] [uri "/index.php"] [unique_id "amuEccjqbtjBYzqM1uZC3gAAXjo"]
[Thu Jul 30 12:05:54.253037 2026] [security2:error] [pid 643253:tid 643456] [client 20.203.148.31:13705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuEcsjqbtjBYzqM1uZC7wAAAEg"]
[Thu Jul 30 12:05:54.605590 2026] [security2:error] [pid 643253:tid 643494] [client 20.52.125.110:14946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/edit.php"] [unique_id "amuEcsjqbtjBYzqM1uZC9gAAAG4"]
[Thu Jul 30 12:05:55.318952 2026] [security2:error] [pid 643253:tid 643405] [client 117.207.246.107:58378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEc8jqbtjBYzqM1uZC-wAAABU"], referer: http://pkf.jo
[Thu Jul 30 12:05:55.454075 2026] [security2:error] [pid 643253:tid 643507] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEcsjqbtjBYzqM1uZC9wAAe2g"]
[Thu Jul 30 12:05:55.685462 2026] [security2:error] [pid 643253:tid 643390] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEc8jqbtjBYzqM1uZC_AAABmE"]
[Thu Jul 30 12:05:56.141115 2026] [core:error] [pid 643253:tid 643428] [client 144.76.32.236:30484] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:05:56.141139 2026] [core:error] [pid 643253:tid 643428] [client 144.76.32.236:30484] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:05:56.277121 2026] [security2:error] [pid 643253:tid 643408] [client 20.52.125.110:14417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/f35.php"] [unique_id "amuEdMjqbtjBYzqM1uZDDgAAABg"]
[Thu Jul 30 12:05:56.298737 2026] [security2:error] [pid 643253:tid 643480] [client 152.59.143.78:35611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEdMjqbtjBYzqM1uZDCQAAAGA"], referer: http://pkf.jo
[Thu Jul 30 12:05:56.354953 2026] [security2:error] [pid 643253:tid 643429] [client 20.203.148.31:16689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuEdMjqbtjBYzqM1uZDDwAAAC0"]
[Thu Jul 30 12:05:56.509945 2026] [autoindex:error] [pid 643253:tid 643419] [client 144.76.32.236:30492] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:05:57.106241 2026] [security2:error] [pid 643253:tid 643406] [client 20.203.148.31:26414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amuEdcjqbtjBYzqM1uZDGwAAABY"]
[Thu Jul 30 12:05:57.495041 2026] [security2:error] [pid 643253:tid 643277] [remote 74.7.242.7:58618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuEdcjqbtjBYzqM1uZDIAAAShY"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:05:57.718724 2026] [security2:error] [pid 643253:tid 643457] [client 20.52.125.110:14923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.emmanueljrodriguez.com"] [uri "/f7.php"] [unique_id "amuEdcjqbtjBYzqM1uZDKwAAAEk"]
[Thu Jul 30 12:05:58.752583 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:58.756649 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:36008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEdsjqbtjBYzqM1uZDOgAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:58.824796 2026] [proxy:error] [pid 643253:tid 643370] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:05:58.824850 2026] [proxy_http:error] [pid 643253:tid 643370] [remote 74.7.228.46:52504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:05:58.825555 2026] [proxy:error] [pid 643253:tid 643370] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:05:58.825601 2026] [proxy_http:error] [pid 643253:tid 643370] [remote 74.7.228.46:52504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:05:59.488254 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:05:59.492578 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:36012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEd8jqbtjBYzqM1uZDSAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:05:59.604150 2026] [security2:error] [pid 643253:tid 643400] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEd8jqbtjBYzqM1uZDQAAAEBA"]
[Thu Jul 30 12:06:00.219806 2026] [core:notice] [pid 643253:tid 643503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:00.223813 2026] [security2:error] [pid 643253:tid 643503] [client 103.215.74.26:36016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEeMjqbtjBYzqM1uZDUwAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:00.958128 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:00.962178 2026] [security2:error] [pid 643253:tid 643461] [client 103.215.74.26:36026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEeMjqbtjBYzqM1uZDXgAAAE0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:01.257672 2026] [security2:error] [pid 643253:tid 643438] [client 20.203.148.31:25537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuEecjqbtjBYzqM1uZDZAAAADY"]
[Thu Jul 30 12:06:01.711702 2026] [core:notice] [pid 643253:tid 643487] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:01.716073 2026] [security2:error] [pid 643253:tid 643487] [client 103.215.74.26:36028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEecjqbtjBYzqM1uZDawAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:02.291612 2026] [security2:error] [pid 643253:tid 643411] [client 20.203.148.31:13716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amuEesjqbtjBYzqM1uZDdgAAABs"]
[Thu Jul 30 12:06:02.463325 2026] [core:notice] [pid 643253:tid 643402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:02.467578 2026] [security2:error] [pid 643253:tid 643402] [client 103.215.74.26:36030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEesjqbtjBYzqM1uZDeQAAABI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:03.205833 2026] [core:notice] [pid 643253:tid 643390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:03.211501 2026] [security2:error] [pid 643253:tid 643390] [client 103.215.74.26:21834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEe8jqbtjBYzqM1uZDggAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:03.938857 2026] [core:notice] [pid 643253:tid 643448] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:03.943374 2026] [security2:error] [pid 643253:tid 643448] [client 103.215.74.26:21844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEe8jqbtjBYzqM1uZDjwAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:04.636245 2026] [proxy:error] [pid 643253:tid 643287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:06:04.636299 2026] [proxy_http:error] [pid 643253:tid 643287] [remote 74.7.175.149:46874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:06:04.636906 2026] [proxy:error] [pid 643253:tid 643287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:06:04.636948 2026] [proxy_http:error] [pid 643253:tid 643287] [remote 74.7.175.149:46874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:06:04.683124 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:04.687449 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:21846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEfMjqbtjBYzqM1uZDmgAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:05.075936 2026] [security2:error] [pid 643253:tid 643394] [client 20.203.148.31:9450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amuEfcjqbtjBYzqM1uZDowAAAAo"]
[Thu Jul 30 12:06:05.436782 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:05.441171 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:21856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEfcjqbtjBYzqM1uZDqwAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:06.157211 2026] [core:notice] [pid 643253:tid 643447] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:06.161655 2026] [security2:error] [pid 643253:tid 643447] [client 103.215.74.26:21864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEfsjqbtjBYzqM1uZDswAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:06.894022 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:06.898467 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:21870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEfsjqbtjBYzqM1uZDvgAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:07.218007 2026] [security2:error] [pid 643253:tid 643470] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEfsjqbtjBYzqM1uZDugAAVi8"]
[Thu Jul 30 12:06:07.621552 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:07.625958 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:21876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEf8jqbtjBYzqM1uZDywAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:08.357421 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:08.361496 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:21882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEgMjqbtjBYzqM1uZD6gAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:08.377199 2026] [security2:error] [pid 643253:tid 643398] [client 20.203.148.31:14776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuEgMjqbtjBYzqM1uZD6wAAAA4"]
[Thu Jul 30 12:06:09.085078 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:09.089070 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:21896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEgcjqbtjBYzqM1uZD9gAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:09.777970 2026] [security2:error] [pid 643253:tid 643447] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEgcjqbtjBYzqM1uZD-gAAP1Y"]
[Thu Jul 30 12:06:09.823585 2026] [core:notice] [pid 643253:tid 643405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:09.827571 2026] [security2:error] [pid 643253:tid 643405] [client 103.215.74.26:21908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEgcjqbtjBYzqM1uZEAgAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:10.557866 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:10.562265 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:21918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEgsjqbtjBYzqM1uZEEAAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:10.724533 2026] [security2:error] [pid 643253:tid 643510] [client 54.164.106.236:14520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2019/09/24b803c5-4f4b-4cc4-9562-0e95a621eaee-300x300.jpg"] [unique_id "amuEgsjqbtjBYzqM1uZEFAAAAH4"]
[Thu Jul 30 12:06:10.861434 2026] [security2:error] [pid 643253:tid 643477] [client 20.203.148.31:9251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-config-sample.php"] [unique_id "amuEgsjqbtjBYzqM1uZEFQAAAF0"]
[Thu Jul 30 12:06:11.184231 2026] [lsapi:error] [pid 642360:tid 642455] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/shall-we-dance-vj-junior/
[Thu Jul 30 12:06:11.278538 2026] [core:notice] [pid 643253:tid 643449] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:11.285084 2026] [security2:error] [pid 643253:tid 643449] [client 103.215.74.26:21926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEg8jqbtjBYzqM1uZEHQAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:11.324499 2026] [security2:error] [pid 643253:tid 643363] [remote 57.141.0.52:26638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amuEg8jqbtjBYzqM1uZEHgAAWWw"]
[Thu Jul 30 12:06:12.027973 2026] [core:notice] [pid 643253:tid 643398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:12.034615 2026] [security2:error] [pid 643253:tid 643398] [client 103.215.74.26:21934] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhMjqbtjBYzqM1uZEKAAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:12.761469 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:12.765513 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:21940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhMjqbtjBYzqM1uZENAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:13.495546 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:13.499549 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:56728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhcjqbtjBYzqM1uZEPwAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:13.749997 2026] [security2:error] [pid 643253:tid 643413] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEhcjqbtjBYzqM1uZEOgAAAB0"]
[Thu Jul 30 12:06:13.824318 2026] [security2:error] [pid 643253:tid 643369] [remote 47.128.125.87:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fantasynamelist.com"] [uri "/robots.txt"] [unique_id "amuEhcjqbtjBYzqM1uZERwAAdXI"]
[Thu Jul 30 12:06:13.960184 2026] [security2:error] [pid 643253:tid 643412] [client 57.141.0.34:23156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuEhcjqbtjBYzqM1uZERQAAHFw"], referer: https://igetvape-australia.com/product/alibarbar-rich-8000-puffs-8/
[Thu Jul 30 12:06:14.236419 2026] [core:notice] [pid 643253:tid 643420] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:14.247346 2026] [security2:error] [pid 643253:tid 643420] [client 103.215.74.26:56738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhsjqbtjBYzqM1uZEUQAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:14.457960 2026] [security2:error] [pid 643253:tid 643505] [client 18.214.186.220:43202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/20150321053259-300x168.jpg"] [unique_id "amuEhsjqbtjBYzqM1uZEUwAAAHk"]
[Thu Jul 30 12:06:14.981391 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:14.985350 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:56740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEhsjqbtjBYzqM1uZEXgAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:15.730884 2026] [core:notice] [pid 643253:tid 643450] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:15.735897 2026] [security2:error] [pid 643253:tid 643450] [client 103.215.74.26:56748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEh8jqbtjBYzqM1uZEaQAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:15.937084 2026] [security2:error] [pid 643253:tid 643434] [client 57.141.0.39:32550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuEh8jqbtjBYzqM1uZEaAAAMl4"], referer: https://igetvape-australia.com/product/alibarbar-ingot-strawberry-lychee-ice-9000-puffs/?add-to-cart=940
[Thu Jul 30 12:06:16.394792 2026] [security2:error] [pid 643253:tid 643431] [client 191.232.199.39:20310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/chosen.php"] [unique_id "amuEiMjqbtjBYzqM1uZEdwAAAC8"]
[Thu Jul 30 12:06:16.523696 2026] [security2:error] [pid 643253:tid 643442] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEh8jqbtjBYzqM1uZEcAAAADo"]
[Thu Jul 30 12:06:16.995519 2026] [security2:error] [pid 643253:tid 643404] [client 186.148.85.50:37998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEiMjqbtjBYzqM1uZEfAAAABQ"], referer: http://pkf.jo
[Thu Jul 30 12:06:17.282225 2026] [core:notice] [pid 643253:tid 643453] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:17.897971 2026] [security2:error] [pid 643253:tid 643455] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEicjqbtjBYzqM1uZEhAAARxY"]
[Thu Jul 30 12:06:17.933868 2026] [security2:error] [pid 643253:tid 643419] [client 190.12.153.11:44082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEicjqbtjBYzqM1uZEigAAACM"], referer: http://pkf.jo
[Thu Jul 30 12:06:18.713084 2026] [security2:error] [pid 643253:tid 643490] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEisjqbtjBYzqM1uZEkwAAagI"]
[Thu Jul 30 12:06:18.776078 2026] [security2:error] [pid 643253:tid 643412] [client 191.232.199.39:19628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/xleet.php"] [unique_id "amuEisjqbtjBYzqM1uZEoAAAABw"]
[Thu Jul 30 12:06:19.633871 2026] [security2:error] [pid 643253:tid 643280] [remote 5.182.209.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amuEi8jqbtjBYzqM1uZErwAAKRk"]
[Thu Jul 30 12:06:19.634088 2026] [security2:error] [pid 643253:tid 643425] [client 5.182.209.54:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amuEi8jqbtjBYzqM1uZErwAAKRk"]
[Thu Jul 30 12:06:19.659841 2026] [security2:error] [pid 643253:tid 643261] [remote 74.7.242.7:53098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuEi8jqbtjBYzqM1uZEsAAAZwY"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:06:20.235987 2026] [security2:error] [pid 643253:tid 643499] [client 191.232.199.39:19587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/ds.php"] [unique_id "amuEjMjqbtjBYzqM1uZEwAAAAHM"]
[Thu Jul 30 12:06:20.280240 2026] [security2:error] [pid 643253:tid 643426] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEi8jqbtjBYzqM1uZErgAAKn0"]
[Thu Jul 30 12:06:20.616502 2026] [security2:error] [pid 643253:tid 643508] [client 20.91.139.111:48717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuEjMjqbtjBYzqM1uZEygAAAHw"]
[Thu Jul 30 12:06:20.616591 2026] [security2:error] [pid 643253:tid 643508] [client 20.91.139.111:48717] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuEjMjqbtjBYzqM1uZEygAAAHw"]
[Thu Jul 30 12:06:20.738635 2026] [security2:error] [pid 643253:tid 643452] [client 74.7.244.8:57910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pkfprogroup.com"] [uri "/cgi-sys/404.html"] [unique_id "amuEjMjqbtjBYzqM1uZEzwAARCc"]
[Thu Jul 30 12:06:20.860101 2026] [security2:error] [pid 643253:tid 643481] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEjMjqbtjBYzqM1uZEwwAAAGE"]
[Thu Jul 30 12:06:21.130020 2026] [security2:error] [pid 643253:tid 643470] [client 74.7.175.155:44616] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuEjMjqbtjBYzqM1uZEzgAAVnQ"]
[Thu Jul 30 12:06:21.130072 2026] [security2:error] [pid 643253:tid 643470] [client 74.7.175.155:44616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuEjMjqbtjBYzqM1uZEzgAAVnQ"]
[Thu Jul 30 12:06:21.455968 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:21.460067 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:56752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEjcjqbtjBYzqM1uZE2wAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:21.935286 2026] [security2:error] [pid 643253:tid 643510] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuEjcjqbtjBYzqM1uZE0wAAfiY"]
[Thu Jul 30 12:06:22.098271 2026] [security2:error] [pid 643253:tid 643433] [client 74.7.175.155:44632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEjcjqbtjBYzqM1uZE5AAAMSM"], referer: https://www.alseermarine.com/robots.txt
[Thu Jul 30 12:06:22.205443 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:22.212206 2026] [security2:error] [pid 643253:tid 643392] [client 103.215.74.26:56766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEjsjqbtjBYzqM1uZE6wAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:22.941773 2026] [core:notice] [pid 643253:tid 643402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:22.946239 2026] [security2:error] [pid 643253:tid 643402] [client 103.215.74.26:56774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEjsjqbtjBYzqM1uZE-wAAABI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:23.439053 2026] [security2:error] [pid 643253:tid 643415] [client 81.0.42.156:36646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEj8jqbtjBYzqM1uZE_AAAAB8"], referer: http://pkf.jo
[Thu Jul 30 12:06:23.441817 2026] [security2:error] [pid 643253:tid 643461] [client 139.28.219.70:34584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuEj8jqbtjBYzqM1uZFCQAAAE0"]
[Thu Jul 30 12:06:23.670537 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:23.674561 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:46488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEj8jqbtjBYzqM1uZFCgAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:23.760328 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.139.111:36691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuEj8jqbtjBYzqM1uZFEgAAAEo"]
[Thu Jul 30 12:06:23.760439 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.139.111:36691] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuEj8jqbtjBYzqM1uZFEgAAAEo"]
[Thu Jul 30 12:06:24.403029 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:24.406964 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:46490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEkMjqbtjBYzqM1uZFIwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:24.455999 2026] [security2:error] [pid 643253:tid 643505] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEj8jqbtjBYzqM1uZFFgAAeTc"]
[Thu Jul 30 12:06:25.150714 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:25.155250 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:46492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEkcjqbtjBYzqM1uZFLgAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:25.877091 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:25.881146 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:46494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEkcjqbtjBYzqM1uZFPgAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:26.050465 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.139.111:59421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/xstelth.php"] [unique_id "amuEksjqbtjBYzqM1uZFPwAAAEA"]
[Thu Jul 30 12:06:26.050615 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.139.111:59421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/xstelth.php"] [unique_id "amuEksjqbtjBYzqM1uZFPwAAAEA"]
[Thu Jul 30 12:06:26.391514 2026] [security2:error] [pid 643253:tid 643419] [client 14.184.103.235:34227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEksjqbtjBYzqM1uZFQAAAACM"], referer: http://pkf.jo
[Thu Jul 30 12:06:26.633780 2026] [core:notice] [pid 643253:tid 643473] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:26.638184 2026] [security2:error] [pid 643253:tid 643473] [client 103.215.74.26:46498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEksjqbtjBYzqM1uZFSQAAAFk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:26.725171 2026] [security2:error] [pid 643253:tid 643385] [client 191.232.199.39:41216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/f5.php"] [unique_id "amuEksjqbtjBYzqM1uZFSgAAAAE"]
[Thu Jul 30 12:06:27.145508 2026] [security2:error] [pid 643253:tid 643490] [client 139.28.219.70:34592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuEk8jqbtjBYzqM1uZFUQAAAGo"]
[Thu Jul 30 12:06:27.145632 2026] [security2:error] [pid 643253:tid 643490] [client 139.28.219.70:34592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuEk8jqbtjBYzqM1uZFUQAAAGo"]
[Thu Jul 30 12:06:27.470731 2026] [core:notice] [pid 643253:tid 643505] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:27.475153 2026] [security2:error] [pid 643253:tid 643505] [client 103.215.74.26:46512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEk8jqbtjBYzqM1uZFVwAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:27.567426 2026] [security2:error] [pid 643253:tid 643495] [client 20.91.139.111:50534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/584062352875874akp.php"] [unique_id "amuEk8jqbtjBYzqM1uZFWQAAAG8"]
[Thu Jul 30 12:06:27.567531 2026] [security2:error] [pid 643253:tid 643495] [client 20.91.139.111:50534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/584062352875874akp.php"] [unique_id "amuEk8jqbtjBYzqM1uZFWQAAAG8"]
[Thu Jul 30 12:06:27.820950 2026] [security2:error] [pid 643253:tid 643435] [client 139.28.219.70:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuEk8jqbtjBYzqM1uZFWwAAADM"]
[Thu Jul 30 12:06:27.821092 2026] [security2:error] [pid 643253:tid 643435] [client 139.28.219.70:34608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amuEk8jqbtjBYzqM1uZFWwAAADM"]
[Thu Jul 30 12:06:28.226679 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:28.231167 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:46526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuElMjqbtjBYzqM1uZFZwAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:28.242969 2026] [security2:error] [pid 643253:tid 643465] [client 87.11.104.83:35698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEk8jqbtjBYzqM1uZFXQAAAFE"], referer: http://pkf.jo
[Thu Jul 30 12:06:28.937117 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.139.111:59447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/newfile.php"] [unique_id "amuElMjqbtjBYzqM1uZFdwAAAEA"]
[Thu Jul 30 12:06:28.937261 2026] [security2:error] [pid 643253:tid 643448] [client 20.91.139.111:59447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/newfile.php"] [unique_id "amuElMjqbtjBYzqM1uZFdwAAAEA"]
[Thu Jul 30 12:06:29.004765 2026] [core:notice] [pid 643253:tid 643443] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:29.009051 2026] [security2:error] [pid 643253:tid 643443] [client 103.215.74.26:46538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuElcjqbtjBYzqM1uZFfgAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:29.034844 2026] [security2:error] [pid 643253:tid 643444] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuElMjqbtjBYzqM1uZFawAAADw"]
[Thu Jul 30 12:06:29.739905 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:29.744378 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:46548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuElcjqbtjBYzqM1uZFiQAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:30.037379 2026] [security2:error] [pid 643253:tid 643467] [client 20.91.139.111:50611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/tBEZGQz.php"] [unique_id "amuElsjqbtjBYzqM1uZFigAAAFM"]
[Thu Jul 30 12:06:30.037508 2026] [security2:error] [pid 643253:tid 643467] [client 20.91.139.111:50611] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/tBEZGQz.php"] [unique_id "amuElsjqbtjBYzqM1uZFigAAAFM"]
[Thu Jul 30 12:06:30.231529 2026] [security2:error] [pid 643253:tid 643479] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuElcjqbtjBYzqM1uZFiAAAXzY"]
[Thu Jul 30 12:06:30.470932 2026] [core:notice] [pid 643253:tid 643401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:30.475458 2026] [security2:error] [pid 643253:tid 643401] [client 103.215.74.26:46550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuElsjqbtjBYzqM1uZFkgAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:31.027863 2026] [security2:error] [pid 643253:tid 643435] [client 20.91.139.111:54585] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/phpinfo"] [unique_id "amuElsjqbtjBYzqM1uZFmwAAADM"]
[Thu Jul 30 12:06:31.206820 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:31.211206 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:46566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEl8jqbtjBYzqM1uZFowAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:31.595208 2026] [security2:error] [pid 643253:tid 643445] [client 20.91.139.111:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/drykl.php"] [unique_id "amuEl8jqbtjBYzqM1uZFpAAAAD0"]
[Thu Jul 30 12:06:31.595364 2026] [security2:error] [pid 643253:tid 643445] [client 20.91.139.111:54585] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/drykl.php"] [unique_id "amuEl8jqbtjBYzqM1uZFpAAAAD0"]
[Thu Jul 30 12:06:31.929424 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:31.933435 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:46582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEl8jqbtjBYzqM1uZFrAAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:32.058412 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:32.623575 2026] [security2:error] [pid 643253:tid 643403] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEmMjqbtjBYzqM1uZFrQAAE2c"]
[Thu Jul 30 12:06:32.654128 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:32.655722 2026] [security2:error] [pid 643253:tid 643509] [client 20.91.139.111:27970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/blue/"] [unique_id "amuEmMjqbtjBYzqM1uZFtQAAAH0"]
[Thu Jul 30 12:06:32.658110 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:46596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEmMjqbtjBYzqM1uZFtgAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:32.973327 2026] [security2:error] [pid 643253:tid 643471] [client 20.91.139.111:27970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/ls.php"] [unique_id "amuEmMjqbtjBYzqM1uZFvgAAAFc"]
[Thu Jul 30 12:06:32.973451 2026] [security2:error] [pid 643253:tid 643471] [client 20.91.139.111:27970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/ls.php"] [unique_id "amuEmMjqbtjBYzqM1uZFvgAAAFc"]
[Thu Jul 30 12:06:33.411834 2026] [core:notice] [pid 643253:tid 643480] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:33.419141 2026] [security2:error] [pid 643253:tid 643480] [client 103.215.74.26:60758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEmcjqbtjBYzqM1uZFxQAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:34.139771 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:34.144112 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:60766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEmsjqbtjBYzqM1uZFzwAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:34.283374 2026] [security2:error] [pid 643253:tid 643439] [client 20.91.139.111:53449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/dx.php"] [unique_id "amuEmsjqbtjBYzqM1uZF0wAAADc"]
[Thu Jul 30 12:06:34.283516 2026] [security2:error] [pid 643253:tid 643439] [client 20.91.139.111:53449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/dx.php"] [unique_id "amuEmsjqbtjBYzqM1uZF0wAAADc"]
[Thu Jul 30 12:06:34.558092 2026] [core:notice] [pid 643253:tid 643389] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:34.874881 2026] [core:notice] [pid 643253:tid 643497] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:34.881410 2026] [security2:error] [pid 643253:tid 643497] [client 103.215.74.26:60772] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEmsjqbtjBYzqM1uZF3wAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:35.235212 2026] [security2:error] [pid 643253:tid 643495] [client 57.141.18.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sagalandfilms.com"] [uri "/index.php"] [unique_id "amuEm8jqbtjBYzqM1uZF4AAAb20"]
[Thu Jul 30 12:06:35.600205 2026] [core:notice] [pid 643253:tid 643398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:35.607333 2026] [security2:error] [pid 643253:tid 643398] [client 103.215.74.26:60784] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEm8jqbtjBYzqM1uZF5wAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:35.754530 2026] [core:error] [pid 643253:tid 643373] [remote 74.7.241.185:40788] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:35.754551 2026] [core:error] [pid 643253:tid 643373] [remote 74.7.241.185:40788] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:35.754716 2026] [security2:error] [pid 643253:tid 643466] [client 74.7.241.185:40788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-8a52acf5.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuEm8jqbtjBYzqM1uZF6AAAUnY"]
[Thu Jul 30 12:06:35.760889 2026] [security2:error] [pid 643253:tid 643396] [client 20.91.139.111:50618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/mac.php"] [unique_id "amuEm8jqbtjBYzqM1uZF6QAAAAw"]
[Thu Jul 30 12:06:35.760965 2026] [security2:error] [pid 643253:tid 643396] [client 20.91.139.111:50618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/mac.php"] [unique_id "amuEm8jqbtjBYzqM1uZF6QAAAAw"]
[Thu Jul 30 12:06:35.797198 2026] [core:notice] [pid 643253:tid 643459] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:35.852561 2026] [security2:error] [pid 643253:tid 643386] [client 172.232.108.36:5416] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.217"] [uri "/"] [unique_id "amuEm8jqbtjBYzqM1uZF7gAAAAI"]
[Thu Jul 30 12:06:36.333371 2026] [core:notice] [pid 643253:tid 643412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:36.337340 2026] [security2:error] [pid 643253:tid 643412] [client 103.215.74.26:60786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEnMjqbtjBYzqM1uZF-QAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:36.474840 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:36.602639 2026] [security2:error] [pid 643253:tid 643486] [client 20.91.139.111:3888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/485.php"] [unique_id "amuEnMjqbtjBYzqM1uZGBQAAAGY"]
[Thu Jul 30 12:06:36.602744 2026] [security2:error] [pid 643253:tid 643486] [client 20.91.139.111:3888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/485.php"] [unique_id "amuEnMjqbtjBYzqM1uZGBQAAAGY"]
[Thu Jul 30 12:06:36.833380 2026] [security2:error] [pid 643253:tid 643482] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEnMjqbtjBYzqM1uZF9wAAYn4"]
[Thu Jul 30 12:06:37.078453 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:37.082248 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:60800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEncjqbtjBYzqM1uZGDQAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:37.094596 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:37.323405 2026] [security2:error] [pid 643253:tid 643437] [client 20.91.139.111:53443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/gelio1.php"] [unique_id "amuEncjqbtjBYzqM1uZGEQAAADU"]
[Thu Jul 30 12:06:37.323527 2026] [security2:error] [pid 643253:tid 643437] [client 20.91.139.111:53443] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/gelio1.php"] [unique_id "amuEncjqbtjBYzqM1uZGEQAAADU"]
[Thu Jul 30 12:06:37.813225 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:37.819834 2026] [security2:error] [pid 643253:tid 643493] [client 103.215.74.26:60802] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEncjqbtjBYzqM1uZGGAAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:37.959327 2026] [security2:error] [pid 643253:tid 643424] [client 191.232.199.39:59777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/god4m.php"] [unique_id "amuEncjqbtjBYzqM1uZGHAAAACg"]
[Thu Jul 30 12:06:38.387024 2026] [security2:error] [pid 643253:tid 643441] [client 20.91.139.111:19603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/lp6.php"] [unique_id "amuEnsjqbtjBYzqM1uZGJAAAADk"]
[Thu Jul 30 12:06:38.387156 2026] [security2:error] [pid 643253:tid 643441] [client 20.91.139.111:19603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/lp6.php"] [unique_id "amuEnsjqbtjBYzqM1uZGJAAAADk"]
[Thu Jul 30 12:06:38.548137 2026] [core:notice] [pid 643253:tid 643396] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:38.552283 2026] [security2:error] [pid 643253:tid 643396] [client 103.215.74.26:60818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEnsjqbtjBYzqM1uZGKAAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:38.615776 2026] [security2:error] [pid 643253:tid 643502] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEnsjqbtjBYzqM1uZGHwAAAHY"]
[Thu Jul 30 12:06:38.854035 2026] [security2:error] [pid 643253:tid 643476] [client 20.226.5.174:33870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/011i.php"] [unique_id "amuEnsjqbtjBYzqM1uZGLwAAAFw"]
[Thu Jul 30 12:06:39.272854 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:39.276882 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:60824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEn8jqbtjBYzqM1uZGOQAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:39.383887 2026] [security2:error] [pid 643253:tid 643470] [client 191.232.199.39:19735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/info.php"] [unique_id "amuEn8jqbtjBYzqM1uZGOgAAAFY"]
[Thu Jul 30 12:06:39.603128 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:39.732522 2026] [security2:error] [pid 643253:tid 643475] [client 20.91.139.111:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuEn8jqbtjBYzqM1uZGSQAAAFs"]
[Thu Jul 30 12:06:39.732622 2026] [security2:error] [pid 643253:tid 643475] [client 20.91.139.111:53448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuEn8jqbtjBYzqM1uZGSQAAAFs"]
[Thu Jul 30 12:06:39.882711 2026] [security2:error] [pid 643253:tid 643483] [client 20.226.5.174:34271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/03a005685d.php"] [unique_id "amuEn8jqbtjBYzqM1uZGTQAAAGM"]
[Thu Jul 30 12:06:41.011716 2026] [security2:error] [pid 643253:tid 643488] [client 20.91.139.111:36900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wp-includes/sodium_compat/"] [unique_id "amuEoMjqbtjBYzqM1uZGXwAAAGg"]
[Thu Jul 30 12:06:41.315696 2026] [security2:error] [pid 643253:tid 643435] [client 20.91.139.111:36900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/w3llscc.php"] [unique_id "amuEocjqbtjBYzqM1uZGZgAAADM"]
[Thu Jul 30 12:06:41.315854 2026] [security2:error] [pid 643253:tid 643435] [client 20.91.139.111:36900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/w3llscc.php"] [unique_id "amuEocjqbtjBYzqM1uZGZgAAADM"]
[Thu Jul 30 12:06:41.687545 2026] [security2:error] [pid 643253:tid 643447] [client 20.226.5.174:33874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/403.php"] [unique_id "amuEocjqbtjBYzqM1uZGcQAAAD8"]
[Thu Jul 30 12:06:41.855561 2026] [security2:error] [pid 643253:tid 643507] [client 20.91.139.111:19638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/miru3.php"] [unique_id "amuEocjqbtjBYzqM1uZGdwAAAHs"]
[Thu Jul 30 12:06:41.855684 2026] [security2:error] [pid 643253:tid 643507] [client 20.91.139.111:19638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/miru3.php"] [unique_id "amuEocjqbtjBYzqM1uZGdwAAAHs"]
[Thu Jul 30 12:06:42.366152 2026] [security2:error] [pid 643253:tid 643391] [client 47.157.71.177:59736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEosjqbtjBYzqM1uZGeQAAAAc"], referer: http://pkf.jo
[Thu Jul 30 12:06:42.855350 2026] [security2:error] [pid 643253:tid 643488] [client 20.91.139.111:27998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/autoload_classmap.php"] [unique_id "amuEosjqbtjBYzqM1uZGjgAAAGg"]
[Thu Jul 30 12:06:42.855458 2026] [security2:error] [pid 643253:tid 643488] [client 20.91.139.111:27998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/autoload_classmap.php"] [unique_id "amuEosjqbtjBYzqM1uZGjgAAAGg"]
[Thu Jul 30 12:06:43.131714 2026] [security2:error] [pid 643253:tid 643424] [client 20.226.5.174:34300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/404.php"] [unique_id "amuEo8jqbtjBYzqM1uZGkAAAACg"]
[Thu Jul 30 12:06:43.498521 2026] [security2:error] [pid 643253:tid 643466] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEosjqbtjBYzqM1uZGjwAAUjM"]
[Thu Jul 30 12:06:43.665328 2026] [security2:error] [pid 643253:tid 643469] [client 20.91.139.111:39470] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wp-content/"] [unique_id "amuEo8jqbtjBYzqM1uZGpAAAAFU"]
[Thu Jul 30 12:06:44.113273 2026] [security2:error] [pid 643253:tid 643439] [client 20.91.139.111:39470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuEpMjqbtjBYzqM1uZGsAAAADc"]
[Thu Jul 30 12:06:44.113467 2026] [security2:error] [pid 643253:tid 643439] [client 20.91.139.111:39470] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuEpMjqbtjBYzqM1uZGsAAAADc"]
[Thu Jul 30 12:06:44.163777 2026] [security2:error] [pid 643253:tid 643498] [client 179.43.134.114:15912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-login.php"] [unique_id "amuEpMjqbtjBYzqM1uZGsgAAAHI"]
[Thu Jul 30 12:06:44.424845 2026] [security2:error] [pid 643253:tid 643491] [client 105.245.181.151:37853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEpMjqbtjBYzqM1uZGsQAAAGs"], referer: http://pkf.jo
[Thu Jul 30 12:06:44.465833 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:44.574784 2026] [security2:error] [pid 643253:tid 643500] [client 20.226.5.174:34297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/aa.php"] [unique_id "amuEpMjqbtjBYzqM1uZGyAAAAHQ"]
[Thu Jul 30 12:06:44.990448 2026] [core:notice] [pid 643253:tid 643450] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:44.994469 2026] [security2:error] [pid 643253:tid 643450] [client 103.215.74.26:37738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEpMjqbtjBYzqM1uZG0gAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:45.008387 2026] [security2:error] [pid 643253:tid 643487] [client 213.152.187.215:47688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuEpMjqbtjBYzqM1uZGywAAAGc"]
[Thu Jul 30 12:06:45.008498 2026] [security2:error] [pid 643253:tid 643487] [client 213.152.187.215:47688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuEpMjqbtjBYzqM1uZGywAAAGc"]
[Thu Jul 30 12:06:45.164055 2026] [security2:error] [pid 643253:tid 643490] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEpMjqbtjBYzqM1uZGxwAAAGo"]
[Thu Jul 30 12:06:45.467646 2026] [core:error] [pid 643253:tid 643384] [client 179.43.134.114:29250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:45.467668 2026] [core:error] [pid 643253:tid 643384] [client 179.43.134.114:29250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:45.719040 2026] [core:notice] [pid 643253:tid 643471] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:45.723305 2026] [security2:error] [pid 643253:tid 643471] [client 103.215.74.26:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEpcjqbtjBYzqM1uZG4AAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:46.241706 2026] [security2:error] [pid 643253:tid 643492] [client 20.226.5.174:34265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/aafewc0k.php"] [unique_id "amuEpsjqbtjBYzqM1uZG6AAAAGw"]
[Thu Jul 30 12:06:46.450625 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:46.455027 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:37760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEpsjqbtjBYzqM1uZG6gAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:46.661421 2026] [security2:error] [pid 643253:tid 643505] [client 20.91.139.111:26207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/av.php"] [unique_id "amuEpsjqbtjBYzqM1uZG9AAAAHk"]
[Thu Jul 30 12:06:46.661535 2026] [security2:error] [pid 643253:tid 643505] [client 20.91.139.111:26207] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/av.php"] [unique_id "amuEpsjqbtjBYzqM1uZG9AAAAHk"]
[Thu Jul 30 12:06:46.850659 2026] [security2:error] [pid 643253:tid 643455] [client 191.232.199.39:41220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/.__info.php"] [unique_id "amuEpsjqbtjBYzqM1uZG9wAAAEc"]
[Thu Jul 30 12:06:46.949599 2026] [security2:error] [pid 643253:tid 643477] [client 66.249.64.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuEpsjqbtjBYzqM1uZG8gAAXUw"]
[Thu Jul 30 12:06:47.174319 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:47.178473 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:37762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEp8jqbtjBYzqM1uZHAAAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:47.445808 2026] [security2:error] [pid 643253:tid 643493] [client 20.226.5.174:34279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/abcd.php"] [unique_id "amuEp8jqbtjBYzqM1uZHAgAAAG0"]
[Thu Jul 30 12:06:47.901583 2026] [core:notice] [pid 643253:tid 643499] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:47.905591 2026] [security2:error] [pid 643253:tid 643499] [client 103.215.74.26:37770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEp8jqbtjBYzqM1uZHCgAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:48.353818 2026] [security2:error] [pid 643253:tid 643394] [client 20.91.139.111:42794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wp-includes/l10n/"] [unique_id "amuEqMjqbtjBYzqM1uZHEQAAAAo"]
[Thu Jul 30 12:06:48.624600 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:48.629186 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:37784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEqMjqbtjBYzqM1uZHGAAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:48.692752 2026] [security2:error] [pid 643253:tid 643470] [client 20.91.139.111:42794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.nordeste1.com"] [uri "/___proxy_subdomain_webmail/wordpress/wp-admin/maint/"] [unique_id "amuEqMjqbtjBYzqM1uZHGwAAAFY"]
[Thu Jul 30 12:06:48.845972 2026] [security2:error] [pid 643253:tid 643463] [client 20.91.139.111:42794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/tiny.php"] [unique_id "amuEqMjqbtjBYzqM1uZHHgAAAE8"]
[Thu Jul 30 12:06:48.846132 2026] [security2:error] [pid 643253:tid 643463] [client 20.91.139.111:42794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/tiny.php"] [unique_id "amuEqMjqbtjBYzqM1uZHHgAAAE8"]
[Thu Jul 30 12:06:49.347745 2026] [core:notice] [pid 643253:tid 643421] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:49.352063 2026] [security2:error] [pid 643253:tid 643421] [client 103.215.74.26:37786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEqcjqbtjBYzqM1uZHKgAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:49.443007 2026] [security2:error] [pid 643253:tid 643509] [client 191.232.199.39:20328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/0.php"] [unique_id "amuEqcjqbtjBYzqM1uZHKwAAAH0"]
[Thu Jul 30 12:06:49.711888 2026] [security2:error] [pid 643253:tid 643501] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEqcjqbtjBYzqM1uZHKAAAdQM"]
[Thu Jul 30 12:06:49.762006 2026] [security2:error] [pid 643253:tid 643444] [client 20.226.5.174:34249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/about.php"] [unique_id "amuEqcjqbtjBYzqM1uZHMwAAADw"]
[Thu Jul 30 12:06:50.094646 2026] [security2:error] [pid 643253:tid 643511] [client 20.91.139.111:22433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuEqsjqbtjBYzqM1uZHOAAAAH8"]
[Thu Jul 30 12:06:50.094749 2026] [security2:error] [pid 643253:tid 643511] [client 20.91.139.111:22433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuEqsjqbtjBYzqM1uZHOAAAAH8"]
[Thu Jul 30 12:06:50.105923 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:50.110257 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:37792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEqsjqbtjBYzqM1uZHOQAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:50.783475 2026] [security2:error] [pid 643253:tid 643404] [client 191.232.199.39:19712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/07.php"] [unique_id "amuEqsjqbtjBYzqM1uZHRgAAABQ"]
[Thu Jul 30 12:06:50.783560 2026] [security2:error] [pid 643253:tid 643438] [client 20.226.5.174:33864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/admin.php"] [unique_id "amuEqsjqbtjBYzqM1uZHRwAAADY"]
[Thu Jul 30 12:06:50.881971 2026] [core:notice] [pid 643253:tid 643508] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:50.886379 2026] [security2:error] [pid 643253:tid 643508] [client 103.215.74.26:37806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEqsjqbtjBYzqM1uZHSwAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:50.965683 2026] [security2:error] [pid 643253:tid 643415] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHQgAAAB8"]
[Thu Jul 30 12:06:51.258688 2026] [security2:error] [pid 643253:tid 643485] [client 20.91.139.111:39472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/zrrhj.php"] [unique_id "amuEq8jqbtjBYzqM1uZHXAAAAGU"]
[Thu Jul 30 12:06:51.258826 2026] [security2:error] [pid 643253:tid 643485] [client 20.91.139.111:39472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/zrrhj.php"] [unique_id "amuEq8jqbtjBYzqM1uZHXAAAAGU"]
[Thu Jul 30 12:06:51.536848 2026] [security2:error] [pid 643253:tid 643445] [client 207.58.142.67:45457] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHYQAAAD0"]
[Thu Jul 30 12:06:51.626747 2026] [security2:error] [pid 643253:tid 643504] [client 172.237.109.114:36180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHTwAAAHg"]
[Thu Jul 30 12:06:51.645826 2026] [security2:error] [pid 643253:tid 643433] [client 172.237.109.114:55802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHUQAAADE"]
[Thu Jul 30 12:06:51.649383 2026] [security2:error] [pid 643253:tid 643435] [client 172.237.109.114:22295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHTgAAADM"]
[Thu Jul 30 12:06:51.653306 2026] [security2:error] [pid 643253:tid 643442] [client 172.237.109.114:51477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHVAAAADo"]
[Thu Jul 30 12:06:51.653352 2026] [security2:error] [pid 643253:tid 643427] [client 172.237.109.114:64796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHTAAAACs"]
[Thu Jul 30 12:06:51.655412 2026] [security2:error] [pid 643253:tid 643476] [client 172.237.109.114:38830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHTQAAAFw"]
[Thu Jul 30 12:06:51.665786 2026] [security2:error] [pid 643253:tid 643413] [client 172.237.109.114:14350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHUAAAAB0"]
[Thu Jul 30 12:06:51.678851 2026] [security2:error] [pid 643253:tid 643446] [client 172.237.109.114:35226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHVQAAAD4"]
[Thu Jul 30 12:06:51.681401 2026] [security2:error] [pid 643253:tid 643406] [client 172.237.109.114:48409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEqsjqbtjBYzqM1uZHUgAAABY"]
[Thu Jul 30 12:06:51.696380 2026] [security2:error] [pid 643253:tid 643425] [client 172.237.109.114:8782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHUwAAACk"]
[Thu Jul 30 12:06:51.886595 2026] [security2:error] [pid 643253:tid 643505] [client 20.91.139.111:32637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuEq8jqbtjBYzqM1uZHbwAAAHk"]
[Thu Jul 30 12:06:51.886739 2026] [security2:error] [pid 643253:tid 643505] [client 20.91.139.111:32637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuEq8jqbtjBYzqM1uZHbwAAAHk"]
[Thu Jul 30 12:06:52.105869 2026] [core:notice] [pid 643253:tid 643388] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:52.438880 2026] [security2:error] [pid 643253:tid 643444] [client 191.232.199.39:20348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/dropdown.php"] [unique_id "amuErMjqbtjBYzqM1uZHhwAAADw"]
[Thu Jul 30 12:06:52.519098 2026] [security2:error] [pid 643253:tid 643438] [client 20.91.139.111:64173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wpgum.php"] [unique_id "amuErMjqbtjBYzqM1uZHiQAAADY"]
[Thu Jul 30 12:06:52.519261 2026] [security2:error] [pid 643253:tid 643438] [client 20.91.139.111:64173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wpgum.php"] [unique_id "amuErMjqbtjBYzqM1uZHiQAAADY"]
[Thu Jul 30 12:06:52.567766 2026] [security2:error] [pid 643253:tid 643461] [client 74.7.244.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.shop-kent.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHZwAAAE0"]
[Thu Jul 30 12:06:52.567816 2026] [security2:error] [pid 643253:tid 643461] [client 74.7.244.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.shop-kent.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHZwAAAE0"]
[Thu Jul 30 12:06:52.568868 2026] [security2:error] [pid 643253:tid 643468] [client 74.7.244.34:36162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.shop-kent.com"] [uri "/robots.txt"] [unique_id "amuEq8jqbtjBYzqM1uZHYwAAVBY"]
[Thu Jul 30 12:06:52.671120 2026] [security2:error] [pid 643253:tid 643494] [client 172.237.109.114:10093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHcwAAAG4"]
[Thu Jul 30 12:06:52.679896 2026] [security2:error] [pid 643253:tid 643464] [client 172.237.109.114:15025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHcAAAAFA"]
[Thu Jul 30 12:06:52.687739 2026] [security2:error] [pid 643253:tid 643389] [client 172.237.109.114:7466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHdgAAAAU"]
[Thu Jul 30 12:06:52.688154 2026] [security2:error] [pid 643253:tid 643405] [client 172.237.109.114:48188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHcQAAABU"]
[Thu Jul 30 12:06:52.691213 2026] [security2:error] [pid 643253:tid 643434] [client 172.237.109.114:29748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHdAAAADI"]
[Thu Jul 30 12:06:52.691213 2026] [security2:error] [pid 643253:tid 643402] [client 172.237.109.114:25388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuErMjqbtjBYzqM1uZHeAAAABI"]
[Thu Jul 30 12:06:52.692840 2026] [security2:error] [pid 643253:tid 643391] [client 172.237.109.114:38145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHcgAAAAc"]
[Thu Jul 30 12:06:52.711524 2026] [security2:error] [pid 643253:tid 643398] [client 172.237.109.114:42142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuErMjqbtjBYzqM1uZHeQAAAA4"]
[Thu Jul 30 12:06:52.715416 2026] [security2:error] [pid 643253:tid 643397] [client 172.237.109.114:49582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEq8jqbtjBYzqM1uZHdQAAAA0"]
[Thu Jul 30 12:06:52.719556 2026] [security2:error] [pid 643253:tid 643480] [client 172.237.109.114:33698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuErMjqbtjBYzqM1uZHdwAAAGA"]
[Thu Jul 30 12:06:52.768763 2026] [security2:error] [pid 643253:tid 643271] [remote 74.7.241.60:58360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuErMjqbtjBYzqM1uZHkAAAJhA"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:06:52.807873 2026] [security2:error] [pid 643253:tid 643428] [client 181.115.120.79:20944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuErMjqbtjBYzqM1uZHhgAAACw"], referer: http://pkf.jo
[Thu Jul 30 12:06:53.209803 2026] [security2:error] [pid 643253:tid 643506] [client 74.7.244.34:36166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop-kent.com"] [uri "/robots.txt"] [unique_id "amuErcjqbtjBYzqM1uZHmAAAeiI"], referer: https://www.shop-kent.com/robots.txt
[Thu Jul 30 12:06:53.401386 2026] [security2:error] [pid 643253:tid 643408] [client 20.91.139.111:7617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/ywwbf.php"] [unique_id "amuErcjqbtjBYzqM1uZHoAAAABg"]
[Thu Jul 30 12:06:53.401476 2026] [security2:error] [pid 643253:tid 643408] [client 20.91.139.111:7617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/ywwbf.php"] [unique_id "amuErcjqbtjBYzqM1uZHoAAAABg"]
[Thu Jul 30 12:06:53.647435 2026] [security2:error] [pid 643253:tid 643446] [client 20.226.5.174:34257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/adminfuns.php"] [unique_id "amuErcjqbtjBYzqM1uZHpAAAAD4"]
[Thu Jul 30 12:06:53.724399 2026] [security2:error] [pid 643253:tid 643505] [client 143.198.88.13:54468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.yardex.ae"] [uri "/xmlrpc.php"] [unique_id "amuErcjqbtjBYzqM1uZHpQAAAHk"], referer: https://ycss.de//wp-login.php
[Thu Jul 30 12:06:54.008472 2026] [security2:error] [pid 643253:tid 643509] [client 191.232.199.39:59835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/makeasmtp.php"] [unique_id "amuErsjqbtjBYzqM1uZHrwAAAH0"]
[Thu Jul 30 12:06:54.216051 2026] [security2:error] [pid 643253:tid 643440] [client 20.91.139.111:32590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/xoldj.php"] [unique_id "amuErsjqbtjBYzqM1uZHtgAAADg"]
[Thu Jul 30 12:06:54.216149 2026] [security2:error] [pid 643253:tid 643440] [client 20.91.139.111:32590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/xoldj.php"] [unique_id "amuErsjqbtjBYzqM1uZHtgAAADg"]
[Thu Jul 30 12:06:54.795754 2026] [security2:error] [pid 643253:tid 643396] [client 20.226.5.174:34259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/albin.php"] [unique_id "amuErsjqbtjBYzqM1uZHxAAAAAw"]
[Thu Jul 30 12:06:54.979903 2026] [security2:error] [pid 643253:tid 643410] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuErsjqbtjBYzqM1uZHwwAAGgc"]
[Thu Jul 30 12:06:55.326408 2026] [security2:error] [pid 643253:tid 643481] [client 20.91.139.111:12850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/f35.php"] [unique_id "amuEr8jqbtjBYzqM1uZHzQAAAGE"]
[Thu Jul 30 12:06:55.326511 2026] [security2:error] [pid 643253:tid 643481] [client 20.91.139.111:12850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/f35.php"] [unique_id "amuEr8jqbtjBYzqM1uZHzQAAAGE"]
[Thu Jul 30 12:06:55.649908 2026] [security2:error] [pid 643253:tid 643391] [client 47.128.20.58:54642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amuEr8jqbtjBYzqM1uZH1wAAAAc"]
[Thu Jul 30 12:06:55.723612 2026] [security2:error] [pid 643253:tid 643442] [client 185.189.112.11:40116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuEr8jqbtjBYzqM1uZH2AAAADo"]
[Thu Jul 30 12:06:55.723757 2026] [security2:error] [pid 643253:tid 643442] [client 185.189.112.11:40116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuEr8jqbtjBYzqM1uZH2AAAADo"]
[Thu Jul 30 12:06:56.025337 2026] [security2:error] [pid 643253:tid 643504] [client 191.232.199.39:59837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-sigunq.php"] [unique_id "amuEsMjqbtjBYzqM1uZH3AAAAHg"]
[Thu Jul 30 12:06:56.289815 2026] [security2:error] [pid 643253:tid 643421] [client 74.7.230.38:35612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ad-company.net"] [uri "/index.php"] [unique_id "amuEsMjqbtjBYzqM1uZH4AAAJSc"]
[Thu Jul 30 12:06:56.297469 2026] [core:error] [pid 643253:tid 643483] [client 74.7.230.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:56.297487 2026] [core:error] [pid 643253:tid 643483] [client 74.7.230.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:06:56.297610 2026] [security2:error] [pid 643253:tid 643483] [client 74.7.230.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.fud.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuEsMjqbtjBYzqM1uZH4wAAAGM"]
[Thu Jul 30 12:06:56.298333 2026] [security2:error] [pid 643253:tid 643435] [client 74.7.230.28:42054] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.fud.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuEsMjqbtjBYzqM1uZH4QAAMxs"]
[Thu Jul 30 12:06:56.392361 2026] [security2:error] [pid 643253:tid 643492] [client 20.226.5.174:33866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/amfsqvgv.php"] [unique_id "amuEsMjqbtjBYzqM1uZH6AAAAGw"]
[Thu Jul 30 12:06:56.429617 2026] [security2:error] [pid 643253:tid 643484] [client 20.91.139.111:12862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/gk.php"] [unique_id "amuEsMjqbtjBYzqM1uZH6gAAAGQ"]
[Thu Jul 30 12:06:56.429718 2026] [security2:error] [pid 643253:tid 643484] [client 20.91.139.111:12862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/gk.php"] [unique_id "amuEsMjqbtjBYzqM1uZH6gAAAGQ"]
[Thu Jul 30 12:06:56.677465 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:56.681800 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:35136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEsMjqbtjBYzqM1uZH8gAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:56.955571 2026] [security2:error] [pid 643253:tid 643444] [client 47.128.121.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuEsMjqbtjBYzqM1uZH9QAAADw"]
[Thu Jul 30 12:06:57.118877 2026] [security2:error] [pid 643253:tid 643482] [client 20.91.139.111:22447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/584062352875874akp.php"] [unique_id "amuEscjqbtjBYzqM1uZH_QAAAGI"]
[Thu Jul 30 12:06:57.118993 2026] [security2:error] [pid 643253:tid 643482] [client 20.91.139.111:22447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/584062352875874akp.php"] [unique_id "amuEscjqbtjBYzqM1uZH_QAAAGI"]
[Thu Jul 30 12:06:57.411896 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:57.416366 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:35142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEscjqbtjBYzqM1uZIBAAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:57.755270 2026] [security2:error] [pid 643253:tid 643428] [client 20.91.139.111:27970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wper3.php"] [unique_id "amuEscjqbtjBYzqM1uZICwAAACw"]
[Thu Jul 30 12:06:57.755442 2026] [security2:error] [pid 643253:tid 643428] [client 20.91.139.111:27970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wper3.php"] [unique_id "amuEscjqbtjBYzqM1uZICwAAACw"]
[Thu Jul 30 12:06:58.078095 2026] [security2:error] [pid 643253:tid 643447] [client 66.249.70.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.widedaddy.com"] [uri "/index.php"] [unique_id "amuEr8jqbtjBYzqM1uZH1gAAAD8"]
[Thu Jul 30 12:06:58.155565 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:58.159832 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:35156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEssjqbtjBYzqM1uZIFgAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:58.527016 2026] [security2:error] [pid 643253:tid 643412] [client 68.221.186.136:34984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/011i.php"] [unique_id "amuEssjqbtjBYzqM1uZIFwAAABw"]
[Thu Jul 30 12:06:58.722948 2026] [security2:error] [pid 643253:tid 643419] [client 20.226.5.174:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/ant.php"] [unique_id "amuEssjqbtjBYzqM1uZIHgAAACM"]
[Thu Jul 30 12:06:58.887732 2026] [core:notice] [pid 643253:tid 643414] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:58.892243 2026] [security2:error] [pid 643253:tid 643414] [client 103.215.74.26:35170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEssjqbtjBYzqM1uZIIQAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:58.989329 2026] [security2:error] [pid 643253:tid 643457] [client 20.91.139.111:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/bthil.php"] [unique_id "amuEssjqbtjBYzqM1uZIJQAAAEk"]
[Thu Jul 30 12:06:58.989439 2026] [security2:error] [pid 643253:tid 643457] [client 20.91.139.111:13210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/bthil.php"] [unique_id "amuEssjqbtjBYzqM1uZIJQAAAEk"]
[Thu Jul 30 12:06:59.136240 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:59.566138 2026] [security2:error] [pid 643253:tid 643431] [client 191.232.199.39:59825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wso112233.php"] [unique_id "amuEs8jqbtjBYzqM1uZILQAAAC8"]
[Thu Jul 30 12:06:59.651836 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:06:59.656381 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:35176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEs8jqbtjBYzqM1uZILwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:06:59.915377 2026] [security2:error] [pid 643253:tid 643444] [client 68.221.186.136:39406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/03a005685d.php"] [unique_id "amuEs8jqbtjBYzqM1uZINgAAADw"]
[Thu Jul 30 12:07:00.048614 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.139.111:32621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/wyzer1.php"] [unique_id "amuEtMjqbtjBYzqM1uZINwAAAEo"]
[Thu Jul 30 12:07:00.048724 2026] [security2:error] [pid 643253:tid 643458] [client 20.91.139.111:32621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/wyzer1.php"] [unique_id "amuEtMjqbtjBYzqM1uZINwAAAEo"]
[Thu Jul 30 12:07:00.149027 2026] [security2:error] [pid 643253:tid 643441] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEs8jqbtjBYzqM1uZILgAAOTc"]
[Thu Jul 30 12:07:00.279394 2026] [security2:error] [pid 643253:tid 643495] [client 20.226.5.174:33858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/appreciators.php"] [unique_id "amuEtMjqbtjBYzqM1uZIOwAAAG8"]
[Thu Jul 30 12:07:00.373137 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:00.376881 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:35186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEtMjqbtjBYzqM1uZIPQAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:01.097914 2026] [core:notice] [pid 643253:tid 643454] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:01.104304 2026] [security2:error] [pid 643253:tid 643454] [client 103.215.74.26:35192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEtcjqbtjBYzqM1uZIUAAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:01.176339 2026] [security2:error] [pid 643253:tid 643504] [client 20.91.139.111:52532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/mh.php"] [unique_id "amuEtcjqbtjBYzqM1uZIUgAAAHg"]
[Thu Jul 30 12:07:01.176432 2026] [security2:error] [pid 643253:tid 643504] [client 20.91.139.111:52532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/mh.php"] [unique_id "amuEtcjqbtjBYzqM1uZIUgAAAHg"]
[Thu Jul 30 12:07:01.547306 2026] [core:notice] [pid 643253:tid 643351] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:01.849557 2026] [core:notice] [pid 643253:tid 643409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:01.856512 2026] [security2:error] [pid 643253:tid 643409] [client 103.215.74.26:35206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEtcjqbtjBYzqM1uZIYgAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:01.930841 2026] [security2:error] [pid 643253:tid 643416] [client 68.221.186.136:25775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/403.php"] [unique_id "amuEtcjqbtjBYzqM1uZIZgAAACA"]
[Thu Jul 30 12:07:02.005986 2026] [security2:error] [pid 643253:tid 643437] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEtcjqbtjBYzqM1uZIWwAAADU"]
[Thu Jul 30 12:07:02.092059 2026] [security2:error] [pid 643253:tid 643433] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuEtcjqbtjBYzqM1uZITwAAADE"], referer: https://smoke-tfhk.com/product/ark-royal-sweet-chocolate/?add-to-cart=2024
[Thu Jul 30 12:07:02.211106 2026] [security2:error] [pid 643253:tid 643480] [client 191.232.199.39:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/alfanew.php"] [unique_id "amuEtsjqbtjBYzqM1uZIaQAAAGA"]
[Thu Jul 30 12:07:02.256401 2026] [security2:error] [pid 643253:tid 643404] [client 20.91.139.111:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuEtsjqbtjBYzqM1uZIagAAABQ"]
[Thu Jul 30 12:07:02.256508 2026] [security2:error] [pid 643253:tid 643404] [client 20.91.139.111:59344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuEtsjqbtjBYzqM1uZIagAAABQ"]
[Thu Jul 30 12:07:02.590175 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:02.594605 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:35210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEtsjqbtjBYzqM1uZIcQAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:02.692860 2026] [core:notice] [pid 643253:tid 643440] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:02.770617 2026] [security2:error] [pid 643253:tid 643335] [remote 157.55.39.58:6630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/ja/login.php"] [unique_id "amuEtsjqbtjBYzqM1uZIcwAAEFA"]
[Thu Jul 30 12:07:02.779036 2026] [security2:error] [pid 643253:tid 643455] [client 20.226.5.174:33868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/archive.php"] [unique_id "amuEtsjqbtjBYzqM1uZIdAAAAEc"]
[Thu Jul 30 12:07:03.343407 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:03.349971 2026] [security2:error] [pid 643253:tid 643395] [client 103.215.74.26:39164] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEt8jqbtjBYzqM1uZIfwAAAAs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:04.061443 2026] [core:notice] [pid 643253:tid 643399] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:04.067816 2026] [security2:error] [pid 643253:tid 643399] [client 103.215.74.26:39176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEuMjqbtjBYzqM1uZIjAAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:04.100541 2026] [security2:error] [pid 643253:tid 643482] [client 68.221.186.136:26183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/404.php"] [unique_id "amuEuMjqbtjBYzqM1uZIjgAAAGI"]
[Thu Jul 30 12:07:04.635278 2026] [security2:error] [pid 643253:tid 643388] [client 68.221.186.136:21877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/aa.php"] [unique_id "amuEuMjqbtjBYzqM1uZIlgAAAAQ"]
[Thu Jul 30 12:07:04.794634 2026] [core:notice] [pid 643253:tid 643510] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:04.798545 2026] [security2:error] [pid 643253:tid 643510] [client 103.215.74.26:39180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEuMjqbtjBYzqM1uZImQAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:04.862663 2026] [security2:error] [pid 643253:tid 643504] [client 20.226.5.174:34263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/as.php"] [unique_id "amuEuMjqbtjBYzqM1uZImwAAAHg"]
[Thu Jul 30 12:07:04.961386 2026] [security2:error] [pid 643253:tid 643437] [client 74.7.244.11:51394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.uuv.rty.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuEuMjqbtjBYzqM1uZIoAAAADU"]
[Thu Jul 30 12:07:05.029088 2026] [security2:error] [pid 643253:tid 643502] [client 136.116.113.96:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEuMjqbtjBYzqM1uZIlwAAAHY"]
[Thu Jul 30 12:07:05.550899 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:05.554856 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:39192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEucjqbtjBYzqM1uZIsAAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:05.991434 2026] [security2:error] [pid 643253:tid 643400] [client 68.221.186.136:37639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/aafewc0k.php"] [unique_id "amuEucjqbtjBYzqM1uZItwAAABA"]
[Thu Jul 30 12:07:06.284754 2026] [core:notice] [pid 643253:tid 643507] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:06.291370 2026] [security2:error] [pid 643253:tid 643507] [client 103.215.74.26:39196] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEusjqbtjBYzqM1uZIvgAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:06.314453 2026] [security2:error] [pid 643253:tid 643468] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEucjqbtjBYzqM1uZIpwAAVFk"]
[Thu Jul 30 12:07:06.461203 2026] [security2:error] [pid 643253:tid 643481] [client 20.226.5.174:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/atomlib.php"] [unique_id "amuEusjqbtjBYzqM1uZIwgAAAGE"]
[Thu Jul 30 12:07:06.607662 2026] [security2:error] [pid 643253:tid 643384] [client 135.148.195.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIwQAAAAA"]
[Thu Jul 30 12:07:06.709653 2026] [security2:error] [pid 643253:tid 643454] [client 191.232.199.39:59821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/fw.php"] [unique_id "amuEusjqbtjBYzqM1uZIygAAAEY"]
[Thu Jul 30 12:07:06.861450 2026] [security2:error] [pid 643253:tid 643442] [client 172.236.9.101:12319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIvAAAADo"]
[Thu Jul 30 12:07:06.863271 2026] [security2:error] [pid 643253:tid 643391] [client 172.236.9.101:38676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIvQAAAAc"]
[Thu Jul 30 12:07:06.890986 2026] [security2:error] [pid 643253:tid 643445] [client 172.236.9.101:46230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIuwAAAD0"]
[Thu Jul 30 12:07:06.910766 2026] [security2:error] [pid 643253:tid 643447] [client 172.236.9.101:34727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIvwAAAD8"]
[Thu Jul 30 12:07:06.957056 2026] [core:error] [pid 643253:tid 643401] [client 74.7.175.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:06.957079 2026] [core:error] [pid 643253:tid 643401] [client 74.7.175.143:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:06.957203 2026] [security2:error] [pid 643253:tid 643401] [client 74.7.175.143:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ssa.djb.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuEusjqbtjBYzqM1uZIzwAAABE"]
[Thu Jul 30 12:07:06.957968 2026] [security2:error] [pid 643253:tid 643399] [client 74.7.175.143:45060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ssa.djb.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuEusjqbtjBYzqM1uZIzQAADwM"]
[Thu Jul 30 12:07:07.019597 2026] [core:notice] [pid 643253:tid 643506] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:07.023621 2026] [security2:error] [pid 643253:tid 643506] [client 103.215.74.26:39202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEu8jqbtjBYzqM1uZI0wAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:07.122045 2026] [security2:error] [pid 643253:tid 643494] [client 66.249.66.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.palison.co"] [uri "/index.php"] [unique_id "amuEucjqbtjBYzqM1uZIsgAAbjo"]
[Thu Jul 30 12:07:07.364439 2026] [security2:error] [pid 643253:tid 643499] [client 20.91.139.111:32622] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.nordeste1.com"] [uri "/1.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6AAAAHM"]
[Thu Jul 30 12:07:07.364613 2026] [security2:error] [pid 643253:tid 643499] [client 20.91.139.111:32622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nordeste1.com"] [uri "/1.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6AAAAHM"]
[Thu Jul 30 12:07:07.364739 2026] [security2:error] [pid 643253:tid 643499] [client 20.91.139.111:32622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.nordeste1.com"] [uri "/1.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6AAAAHM"]
[Thu Jul 30 12:07:07.480099 2026] [security2:error] [pid 643253:tid 643387] [client 68.221.186.136:34563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/abcd.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6QAAAAM"]
[Thu Jul 30 12:07:07.507142 2026] [security2:error] [pid 643253:tid 643393] [client 20.226.5.174:34269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/autoload_classmap.php"] [unique_id "amuEu8jqbtjBYzqM1uZI6gAAAAk"]
[Thu Jul 30 12:07:07.760667 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:07.765003 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEu8jqbtjBYzqM1uZI9gAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:08.418869 2026] [security2:error] [pid 643253:tid 643478] [client 5.161.194.92:12036] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI0AAAAF4"], referer: https://globalmarks.pk/
[Thu Jul 30 12:07:08.470008 2026] [security2:error] [pid 643253:tid 643500] [client 172.236.9.101:18203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI2QAAAHQ"]
[Thu Jul 30 12:07:08.482860 2026] [security2:error] [pid 643253:tid 643461] [client 191.232.199.39:19755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-login.php"] [unique_id "amuEvMjqbtjBYzqM1uZI_QAAAE0"]
[Thu Jul 30 12:07:08.488493 2026] [security2:error] [pid 643253:tid 643423] [client 172.236.9.101:48269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI2gAAACc"]
[Thu Jul 30 12:07:08.489856 2026] [security2:error] [pid 643253:tid 643508] [client 68.221.186.136:21854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/about.php"] [unique_id "amuEvMjqbtjBYzqM1uZI_gAAAHw"]
[Thu Jul 30 12:07:08.490666 2026] [security2:error] [pid 643253:tid 643504] [client 172.236.9.101:5684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI2AAAAHg"]
[Thu Jul 30 12:07:08.497816 2026] [security2:error] [pid 643253:tid 643431] [client 172.236.9.101:25743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI2wAAAC8"]
[Thu Jul 30 12:07:08.534573 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:08.540297 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:39220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEvMjqbtjBYzqM1uZI_wAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:08.571297 2026] [security2:error] [pid 643253:tid 643437] [client 172.236.9.101:14833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI3QAAADU"]
[Thu Jul 30 12:07:08.579229 2026] [security2:error] [pid 643253:tid 643490] [client 172.236.9.101:30396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI3AAAAGo"]
[Thu Jul 30 12:07:08.580745 2026] [security2:error] [pid 643253:tid 643453] [client 172.236.9.101:36971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI3gAAAEU"]
[Thu Jul 30 12:07:08.586545 2026] [security2:error] [pid 643253:tid 643450] [client 172.236.9.101:43740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI4wAAAEI"]
[Thu Jul 30 12:07:08.596687 2026] [security2:error] [pid 643253:tid 643392] [client 172.236.9.101:62987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI3wAAAAg"]
[Thu Jul 30 12:07:08.598128 2026] [security2:error] [pid 643253:tid 643420] [client 172.236.9.101:24893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI5gAAACQ"]
[Thu Jul 30 12:07:08.605277 2026] [security2:error] [pid 643253:tid 643433] [client 172.236.9.101:37554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI4QAAADE"]
[Thu Jul 30 12:07:08.613623 2026] [security2:error] [pid 643253:tid 643451] [client 172.236.9.101:60538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI5QAAAEM"]
[Thu Jul 30 12:07:08.613659 2026] [security2:error] [pid 643253:tid 643406] [client 172.236.9.101:59406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI4gAAABY"]
[Thu Jul 30 12:07:08.616934 2026] [security2:error] [pid 643253:tid 643459] [client 172.236.9.101:10681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI5AAAAEs"]
[Thu Jul 30 12:07:08.620747 2026] [security2:error] [pid 643253:tid 643487] [client 172.236.9.101:54555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI4AAAAGc"]
[Thu Jul 30 12:07:08.630284 2026] [security2:error] [pid 643253:tid 643477] [client 172.236.9.101:5970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEu8jqbtjBYzqM1uZI5wAAAF0"]
[Thu Jul 30 12:07:09.248243 2026] [security2:error] [pid 643253:tid 643422] [client 20.226.5.174:34252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/bb.php"] [unique_id "amuEvcjqbtjBYzqM1uZJFQAAACY"]
[Thu Jul 30 12:07:09.300505 2026] [core:notice] [pid 643253:tid 643446] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:09.304821 2026] [security2:error] [pid 643253:tid 643446] [client 103.215.74.26:39234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEvcjqbtjBYzqM1uZJFgAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:09.826628 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:09.925266 2026] [security2:error] [pid 643253:tid 643439] [client 68.221.186.136:38431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/admin.php"] [unique_id "amuEvcjqbtjBYzqM1uZJKAAAADc"]
[Thu Jul 30 12:07:10.015060 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:10.019491 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:39240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEvsjqbtjBYzqM1uZJKgAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:10.324059 2026] [security2:error] [pid 643253:tid 643470] [client 20.226.5.174:34258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/bnm.php"] [unique_id "amuEvsjqbtjBYzqM1uZJNAAAAFY"]
[Thu Jul 30 12:07:10.503299 2026] [core:notice] [pid 643253:tid 643378] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:10.528955 2026] [security2:error] [pid 643253:tid 643464] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEvcjqbtjBYzqM1uZJJwAAUAw"]
[Thu Jul 30 12:07:10.590597 2026] [core:error] [pid 643253:tid 643456] [client 212.56.53.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://blueskyroofingco.shop/
[Thu Jul 30 12:07:10.590627 2026] [core:error] [pid 643253:tid 643456] [client 212.56.53.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://blueskyroofingco.shop/
[Thu Jul 30 12:07:10.786442 2026] [security2:error] [pid 643253:tid 643424] [client 191.232.199.39:20299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/simple.php"] [unique_id "amuEvsjqbtjBYzqM1uZJQwAAACg"]
[Thu Jul 30 12:07:10.788515 2026] [core:notice] [pid 643253:tid 643483] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:10.792709 2026] [security2:error] [pid 643253:tid 643483] [client 103.215.74.26:39242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEvsjqbtjBYzqM1uZJRAAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:11.474548 2026] [security2:error] [pid 643253:tid 643462] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEvsjqbtjBYzqM1uZJTwAAThs"]
[Thu Jul 30 12:07:11.475394 2026] [security2:error] [pid 643253:tid 643388] [client 172.237.109.114:56163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEvsjqbtjBYzqM1uZJUQAAAAQ"]
[Thu Jul 30 12:07:11.509392 2026] [core:notice] [pid 643253:tid 643465] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:11.513683 2026] [security2:error] [pid 643253:tid 643465] [client 103.215.74.26:39258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEv8jqbtjBYzqM1uZJZQAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:11.538211 2026] [security2:error] [pid 643253:tid 643308] [remote 74.7.241.59:49048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuEv8jqbtjBYzqM1uZJZgAABjU"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:07:11.580768 2026] [security2:error] [pid 643253:tid 643446] [client 20.226.5.174:33885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/bootstrap.php"] [unique_id "amuEv8jqbtjBYzqM1uZJZwAAAD4"]
[Thu Jul 30 12:07:11.612255 2026] [security2:error] [pid 643253:tid 643402] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEvsjqbtjBYzqM1uZJUgAAEnQ"]
[Thu Jul 30 12:07:11.727359 2026] [security2:error] [pid 643253:tid 643479] [client 43.173.174.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJVwAAAF8"]
[Thu Jul 30 12:07:12.240576 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:12.250859 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:39266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEwMjqbtjBYzqM1uZJiQAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:12.378517 2026] [security2:error] [pid 643253:tid 643442] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuEwMjqbtjBYzqM1uZJiAAAOhg"]
[Thu Jul 30 12:07:13.000965 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:13.005407 2026] [security2:error] [pid 643253:tid 643427] [client 103.215.74.26:39268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEwMjqbtjBYzqM1uZJpAAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:13.313229 2026] [security2:error] [pid 643253:tid 643481] [client 172.237.109.114:4541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJdAAAAGE"]
[Thu Jul 30 12:07:13.336109 2026] [security2:error] [pid 643253:tid 643420] [client 172.237.109.114:35101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJcgAAACQ"]
[Thu Jul 30 12:07:13.342193 2026] [security2:error] [pid 643253:tid 643468] [client 172.237.109.114:6106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJcwAAAFQ"]
[Thu Jul 30 12:07:13.344556 2026] [security2:error] [pid 643253:tid 643463] [client 191.232.199.39:61090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/classsmtps.php"] [unique_id "amuEwcjqbtjBYzqM1uZJrQAAAE8"]
[Thu Jul 30 12:07:13.392966 2026] [security2:error] [pid 643253:tid 643507] [client 172.237.109.114:59606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJeQAAAHs"]
[Thu Jul 30 12:07:13.396481 2026] [security2:error] [pid 643253:tid 643470] [client 172.237.109.114:54135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJdQAAAFY"]
[Thu Jul 30 12:07:13.410111 2026] [security2:error] [pid 643253:tid 643501] [client 172.237.109.114:16386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJdwAAAHU"]
[Thu Jul 30 12:07:13.419964 2026] [security2:error] [pid 643253:tid 643437] [client 172.237.109.114:11413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJeAAAADU"]
[Thu Jul 30 12:07:13.444302 2026] [security2:error] [pid 643253:tid 643486] [client 172.237.109.114:2156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJfQAAAGY"]
[Thu Jul 30 12:07:13.444379 2026] [security2:error] [pid 643253:tid 643406] [client 172.237.109.114:29294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJfgAAABY"]
[Thu Jul 30 12:07:13.445167 2026] [security2:error] [pid 643253:tid 643456] [client 172.237.109.114:53776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJgwAAAEg"]
[Thu Jul 30 12:07:13.462087 2026] [security2:error] [pid 643253:tid 643454] [client 172.237.109.114:47597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJhAAAAEY"]
[Thu Jul 30 12:07:13.462771 2026] [security2:error] [pid 643253:tid 643421] [client 172.237.109.114:18573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJfAAAACU"]
[Thu Jul 30 12:07:13.469731 2026] [security2:error] [pid 643253:tid 643460] [client 172.237.109.114:37134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJgQAAAEw"]
[Thu Jul 30 12:07:13.470203 2026] [security2:error] [pid 643253:tid 643413] [client 172.237.109.114:35855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJewAAAB0"]
[Thu Jul 30 12:07:13.478027 2026] [security2:error] [pid 643253:tid 643496] [client 172.237.109.114:31413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJggAAAHA"]
[Thu Jul 30 12:07:13.503875 2026] [security2:error] [pid 643253:tid 643469] [client 172.237.109.114:57510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJegAAAFU"]
[Thu Jul 30 12:07:13.506942 2026] [security2:error] [pid 643253:tid 643436] [client 172.237.109.114:27427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEv8jqbtjBYzqM1uZJdgAAADQ"]
[Thu Jul 30 12:07:13.555415 2026] [security2:error] [pid 643253:tid 643475] [client 172.237.109.114:1519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJhQAAAFs"]
[Thu Jul 30 12:07:13.565587 2026] [security2:error] [pid 643253:tid 643464] [client 172.237.109.114:30043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuEwMjqbtjBYzqM1uZJgAAAAFA"]
[Thu Jul 30 12:07:13.724880 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:13.729257 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:13908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEwcjqbtjBYzqM1uZJugAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:14.438563 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:14.441000 2026] [security2:error] [pid 643253:tid 643492] [client 197.244.88.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEwcjqbtjBYzqM1uZJuAAAbE0"], referer: https://allmontecristi.com
[Thu Jul 30 12:07:14.447134 2026] [security2:error] [pid 643253:tid 643427] [client 103.215.74.26:13918] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEwsjqbtjBYzqM1uZJ0gAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:14.648339 2026] [security2:error] [pid 643253:tid 643424] [client 20.226.5.174:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/buy.php"] [unique_id "amuEwsjqbtjBYzqM1uZJ3QAAACg"]
[Thu Jul 30 12:07:14.753016 2026] [security2:error] [pid 643253:tid 643426] [client 138.97.188.101:19622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEwsjqbtjBYzqM1uZJ0wAAACo"], referer: http://pkf.jo
[Thu Jul 30 12:07:15.022649 2026] [security2:error] [pid 643253:tid 643463] [client 191.232.199.39:59823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-blog-header.php"] [unique_id "amuEw8jqbtjBYzqM1uZJ5gAAAE8"]
[Thu Jul 30 12:07:15.270603 2026] [security2:error] [pid 643253:tid 643443] [client 103.173.162.49:34177] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "agr8story.site"] [uri "/wp-comments-post.php"] [unique_id "amuEwsjqbtjBYzqM1uZJ3wAAADs"]
[Thu Jul 30 12:07:15.412720 2026] [security2:error] [pid 643253:tid 643443] [client 103.173.162.49:34177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "agr8story.site"] [uri "/wp-comments-post.php"] [unique_id "amuEwsjqbtjBYzqM1uZJ3wAAADs"]
[Thu Jul 30 12:07:15.499027 2026] [security2:error] [pid 643253:tid 643258] [remote 40.77.167.57:35546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/download/7529/3035/20005"] [unique_id "amuEw8jqbtjBYzqM1uZJ7gAAeAM"]
[Thu Jul 30 12:07:16.205579 2026] [security2:error] [pid 643253:tid 643384] [client 20.226.5.174:34322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/chosen.php"] [unique_id "amuExMjqbtjBYzqM1uZKAgAAAAA"]
[Thu Jul 30 12:07:17.659504 2026] [security2:error] [pid 643253:tid 643497] [client 191.232.199.39:59779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-trackback.php"] [unique_id "amuExcjqbtjBYzqM1uZKFQAAAHE"]
[Thu Jul 30 12:07:17.673358 2026] [security2:error] [pid 643253:tid 643449] [client 20.203.142.71:4879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuExcjqbtjBYzqM1uZKFgAAAEE"]
[Thu Jul 30 12:07:17.673474 2026] [security2:error] [pid 643253:tid 643449] [client 20.203.142.71:4879] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuExcjqbtjBYzqM1uZKFgAAAEE"]
[Thu Jul 30 12:07:18.112775 2026] [security2:error] [pid 643253:tid 643405] [client 20.226.5.174:34267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/class-wp-image.php"] [unique_id "amuExsjqbtjBYzqM1uZKGgAAABU"]
[Thu Jul 30 12:07:18.850937 2026] [security2:error] [pid 643253:tid 643426] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuExsjqbtjBYzqM1uZKIQAAKj0"]
[Thu Jul 30 12:07:19.097497 2026] [lsapi:error] [pid 642360:tid 642444] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/fall-for-me-vj-junior/
[Thu Jul 30 12:07:19.593964 2026] [security2:error] [pid 643253:tid 643406] [client 191.232.199.39:19728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-signup.php"] [unique_id "amuEx8jqbtjBYzqM1uZKPAAAABY"]
[Thu Jul 30 12:07:20.173373 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:20.179676 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:13928] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEyMjqbtjBYzqM1uZKQwAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:20.362756 2026] [security2:error] [pid 643253:tid 643470] [client 68.221.186.136:25420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/adminfuns.php"] [unique_id "amuEyMjqbtjBYzqM1uZKTgAAAFY"]
[Thu Jul 30 12:07:20.857157 2026] [security2:error] [pid 643253:tid 643509] [client 20.226.5.174:34049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/classsmtps.php"] [unique_id "amuEyMjqbtjBYzqM1uZKVgAAAH0"]
[Thu Jul 30 12:07:20.927689 2026] [core:notice] [pid 643253:tid 643389] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:20.932112 2026] [security2:error] [pid 643253:tid 643389] [client 103.215.74.26:13944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEyMjqbtjBYzqM1uZKWQAAAAU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:21.655301 2026] [core:notice] [pid 643253:tid 643488] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:21.659552 2026] [security2:error] [pid 643253:tid 643488] [client 103.215.74.26:13948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEycjqbtjBYzqM1uZKZwAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:21.930874 2026] [security2:error] [pid 643253:tid 643398] [client 50.6.43.217:58064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuEycjqbtjBYzqM1uZKcAAAAA4"]
[Thu Jul 30 12:07:21.941157 2026] [security2:error] [pid 643253:tid 643508] [client 50.6.43.217:58070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuEycjqbtjBYzqM1uZKcQAAAHw"]
[Thu Jul 30 12:07:21.950355 2026] [security2:error] [pid 643253:tid 643485] [client 50.6.43.217:58086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuEycjqbtjBYzqM1uZKcgAAAGU"]
[Thu Jul 30 12:07:22.179342 2026] [security2:error] [pid 643253:tid 643504] [client 95.142.47.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEycjqbtjBYzqM1uZKZgAAeH0"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 12:07:22.392663 2026] [core:notice] [pid 643253:tid 643386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:22.398594 2026] [security2:error] [pid 643253:tid 643386] [client 103.215.74.26:13956] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEysjqbtjBYzqM1uZKfwAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:22.568129 2026] [core:notice] [pid 643253:tid 643305] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:22.658337 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.142.71:42912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuEysjqbtjBYzqM1uZKhgAAAG0"]
[Thu Jul 30 12:07:22.658447 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.142.71:42912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuEysjqbtjBYzqM1uZKhgAAAG0"]
[Thu Jul 30 12:07:22.926456 2026] [security2:error] [pid 643253:tid 643420] [client 34.86.95.193:64928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereashops.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuEysjqbtjBYzqM1uZKjwAAACQ"]
[Thu Jul 30 12:07:23.135922 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:23.140132 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:46726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEy8jqbtjBYzqM1uZKkwAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:23.207308 2026] [core:notice] [pid 643253:tid 643311] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:23.563508 2026] [security2:error] [pid 643253:tid 643462] [client 95.142.47.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEy8jqbtjBYzqM1uZKkQAATig"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 12:07:23.664858 2026] [security2:error] [pid 643253:tid 643449] [client 68.221.186.136:38862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/albin.php"] [unique_id "amuEy8jqbtjBYzqM1uZKngAAAEE"]
[Thu Jul 30 12:07:23.763247 2026] [core:error] [pid 643253:tid 643445] [client 74.7.228.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:23.763272 2026] [core:error] [pid 643253:tid 643445] [client 74.7.228.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:23.763409 2026] [security2:error] [pid 643253:tid 643445] [client 74.7.228.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.dug.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuEy8jqbtjBYzqM1uZKoQAAAD0"]
[Thu Jul 30 12:07:23.764028 2026] [security2:error] [pid 643253:tid 643407] [client 74.7.228.34:49470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.dug.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuEy8jqbtjBYzqM1uZKnwAAF0g"]
[Thu Jul 30 12:07:23.865280 2026] [core:notice] [pid 643253:tid 643460] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:23.870963 2026] [security2:error] [pid 643253:tid 643460] [client 103.215.74.26:46742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEy8jqbtjBYzqM1uZKowAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:23.905146 2026] [security2:error] [pid 643253:tid 643405] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuEy8jqbtjBYzqM1uZKlQAAFUA"]
[Thu Jul 30 12:07:23.961630 2026] [security2:error] [pid 643253:tid 643421] [client 34.86.95.193:60733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.95.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amuEy8jqbtjBYzqM1uZKrQAAACU"]
[Thu Jul 30 12:07:24.298031 2026] [security2:error] [pid 643253:tid 643399] [client 20.203.142.71:29368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuEzMjqbtjBYzqM1uZKsgAAAA8"]
[Thu Jul 30 12:07:24.298141 2026] [security2:error] [pid 643253:tid 643399] [client 20.203.142.71:29368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuEzMjqbtjBYzqM1uZKsgAAAA8"]
[Thu Jul 30 12:07:24.371883 2026] [security2:error] [pid 643253:tid 643456] [client 191.232.199.39:59822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-comments-post.php"] [unique_id "amuEzMjqbtjBYzqM1uZKtAAAAEg"]
[Thu Jul 30 12:07:24.596618 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:24.600903 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:46746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuEzMjqbtjBYzqM1uZKvQAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:24.795657 2026] [security2:error] [pid 643253:tid 643286] [remote 57.141.0.43:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458216670/feed/rss2/"] [unique_id "amuEzMjqbtjBYzqM1uZKvgAAFB8"]
[Thu Jul 30 12:07:24.800794 2026] [security2:error] [pid 643253:tid 643444] [client 213.152.187.215:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuEzMjqbtjBYzqM1uZKvwAAADw"]
[Thu Jul 30 12:07:24.800867 2026] [security2:error] [pid 643253:tid 643444] [client 213.152.187.215:59028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuEzMjqbtjBYzqM1uZKvwAAADw"]
[Thu Jul 30 12:07:25.135756 2026] [security2:error] [pid 643253:tid 643504] [client 68.221.186.136:37450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/amfsqvgv.php"] [unique_id "amuEzcjqbtjBYzqM1uZKywAAAHg"]
[Thu Jul 30 12:07:25.209205 2026] [security2:error] [pid 643253:tid 643497] [client 20.203.142.71:47234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/err.php"] [unique_id "amuEzcjqbtjBYzqM1uZKzAAAAHE"]
[Thu Jul 30 12:07:25.209346 2026] [security2:error] [pid 643253:tid 643497] [client 20.203.142.71:47234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/err.php"] [unique_id "amuEzcjqbtjBYzqM1uZKzAAAAHE"]
[Thu Jul 30 12:07:25.252337 2026] [security2:error] [pid 643253:tid 643458] [client 181.121.14.41:44894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEzMjqbtjBYzqM1uZKxAAAAEo"], referer: http://pkf.jo
[Thu Jul 30 12:07:25.256415 2026] [security2:error] [pid 643253:tid 643472] [client 46.232.251.191:50438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuEzcjqbtjBYzqM1uZKygAAWFE"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:07:25.630901 2026] [security2:error] [pid 643253:tid 643509] [client 37.111.246.182:31575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuEzcjqbtjBYzqM1uZKzgAAAH0"], referer: http://pkf.jo
[Thu Jul 30 12:07:25.992025 2026] [security2:error] [pid 643253:tid 643465] [client 68.221.186.136:25354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/ant.php"] [unique_id "amuEzcjqbtjBYzqM1uZK2QAAAFE"]
[Thu Jul 30 12:07:26.153233 2026] [security2:error] [pid 643253:tid 643457] [client 20.226.5.174:33944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/classwithtostring.php"] [unique_id "amuEzsjqbtjBYzqM1uZK4AAAAEk"]
[Thu Jul 30 12:07:26.397242 2026] [security2:error] [pid 643253:tid 643503] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ab9d1028.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuEzsjqbtjBYzqM1uZK3AAAAHc"]
[Thu Jul 30 12:07:26.398090 2026] [security2:error] [pid 643253:tid 643413] [client 74.7.244.52:43718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ab9d1028.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuEzcjqbtjBYzqM1uZK2gAAHU8"]
[Thu Jul 30 12:07:26.414689 2026] [security2:error] [pid 643253:tid 643392] [client 20.203.142.71:25377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/img.php"] [unique_id "amuEzsjqbtjBYzqM1uZK5AAAAAg"]
[Thu Jul 30 12:07:26.414804 2026] [security2:error] [pid 643253:tid 643392] [client 20.203.142.71:25377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/img.php"] [unique_id "amuEzsjqbtjBYzqM1uZK5AAAAAg"]
[Thu Jul 30 12:07:26.780559 2026] [security2:error] [pid 643253:tid 643418] [client 68.221.186.136:38199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/appreciators.php"] [unique_id "amuEzsjqbtjBYzqM1uZK7gAAACI"]
[Thu Jul 30 12:07:27.324424 2026] [security2:error] [pid 643253:tid 643475] [client 20.226.5.174:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/config.php"] [unique_id "amuEz8jqbtjBYzqM1uZK-AAAAFs"]
[Thu Jul 30 12:07:27.587877 2026] [security2:error] [pid 643253:tid 643480] [client 68.221.186.136:38183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/archive.php"] [unique_id "amuEz8jqbtjBYzqM1uZK_QAAAGA"]
[Thu Jul 30 12:07:27.773958 2026] [security2:error] [pid 643253:tid 643420] [client 20.203.142.71:32596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/aa.php"] [unique_id "amuEz8jqbtjBYzqM1uZLBAAAACQ"]
[Thu Jul 30 12:07:27.774088 2026] [security2:error] [pid 643253:tid 643420] [client 20.203.142.71:32596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/aa.php"] [unique_id "amuEz8jqbtjBYzqM1uZLBAAAACQ"]
[Thu Jul 30 12:07:28.507166 2026] [security2:error] [pid 643253:tid 643446] [client 20.226.5.174:35573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/core.php"] [unique_id "amuE0MjqbtjBYzqM1uZLEQAAAD4"]
[Thu Jul 30 12:07:29.387373 2026] [security2:error] [pid 643253:tid 643413] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE0MjqbtjBYzqM1uZLGQAAHWQ"]
[Thu Jul 30 12:07:29.455137 2026] [security2:error] [pid 643253:tid 643426] [client 68.221.186.136:37472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/as.php"] [unique_id "amuE0cjqbtjBYzqM1uZLJgAAACo"]
[Thu Jul 30 12:07:29.565472 2026] [security2:error] [pid 643253:tid 643477] [client 20.226.5.174:35525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/css.php"] [unique_id "amuE0cjqbtjBYzqM1uZLJwAAAF0"]
[Thu Jul 30 12:07:30.171229 2026] [security2:error] [pid 643253:tid 643344] [remote 57.141.0.28:45862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/404010317/feed/rss2/"] [unique_id "amuE0cjqbtjBYzqM1uZLNAAAGlk"]
[Thu Jul 30 12:07:30.322970 2026] [core:notice] [pid 643253:tid 643389] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:30.328233 2026] [security2:error] [pid 643253:tid 643389] [client 103.215.74.26:46752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE0sjqbtjBYzqM1uZLPgAAAAU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:30.329915 2026] [security2:error] [pid 643253:tid 643428] [client 191.232.199.39:61115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-mail.php"] [unique_id "amuE0sjqbtjBYzqM1uZLPwAAACw"]
[Thu Jul 30 12:07:30.512784 2026] [security2:error] [pid 643253:tid 643423] [client 34.86.95.193:64639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.95.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amuE0sjqbtjBYzqM1uZLQAAAACc"]
[Thu Jul 30 12:07:30.512905 2026] [security2:error] [pid 643253:tid 643423] [client 34.86.95.193:64639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amuE0sjqbtjBYzqM1uZLQAAAACc"]
[Thu Jul 30 12:07:30.566154 2026] [security2:error] [pid 643253:tid 643502] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE0cjqbtjBYzqM1uZLNQAAdlw"]
[Thu Jul 30 12:07:30.633890 2026] [security2:error] [pid 643253:tid 643400] [client 173.252.82.52:59958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.innovativefurnituretransportpackagingllc.cc"] [uri "/index.php"] [unique_id "amuE0cjqbtjBYzqM1uZLJAAAEHc"]
[Thu Jul 30 12:07:30.921082 2026] [security2:error] [pid 643253:tid 643450] [client 20.226.5.174:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/database.php"] [unique_id "amuE0sjqbtjBYzqM1uZLSgAAAEI"]
[Thu Jul 30 12:07:31.040698 2026] [security2:error] [pid 643253:tid 643441] [client 20.203.142.71:25374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/av.php"] [unique_id "amuE08jqbtjBYzqM1uZLSwAAADk"]
[Thu Jul 30 12:07:31.040819 2026] [security2:error] [pid 643253:tid 643441] [client 20.203.142.71:25374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/av.php"] [unique_id "amuE08jqbtjBYzqM1uZLSwAAADk"]
[Thu Jul 30 12:07:31.950031 2026] [security2:error] [pid 643253:tid 643510] [client 20.226.5.174:33480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/db.php"] [unique_id "amuE08jqbtjBYzqM1uZLYAAAAH4"]
[Thu Jul 30 12:07:32.022860 2026] [security2:error] [pid 643253:tid 643475] [client 191.232.199.39:20302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-activate.php"] [unique_id "amuE1MjqbtjBYzqM1uZLYQAAAFs"]
[Thu Jul 30 12:07:32.381622 2026] [security2:error] [pid 643253:tid 643500] [client 68.221.186.136:39356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/atomlib.php"] [unique_id "amuE1MjqbtjBYzqM1uZLZQAAAHQ"]
[Thu Jul 30 12:07:33.004197 2026] [security2:error] [pid 643253:tid 643426] [client 172.213.232.128:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/011i.php"] [unique_id "amuE1cjqbtjBYzqM1uZLcgAAACo"]
[Thu Jul 30 12:07:33.490994 2026] [security2:error] [pid 643253:tid 643482] [client 20.203.142.71:39009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xa.php"] [unique_id "amuE1cjqbtjBYzqM1uZLewAAAGI"]
[Thu Jul 30 12:07:33.491089 2026] [security2:error] [pid 643253:tid 643482] [client 20.203.142.71:39009] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xa.php"] [unique_id "amuE1cjqbtjBYzqM1uZLewAAAGI"]
[Thu Jul 30 12:07:33.600138 2026] [security2:error] [pid 643253:tid 643453] [client 136.70.106.31:60104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuE1cjqbtjBYzqM1uZLcwAAAEU"]
[Thu Jul 30 12:07:33.648096 2026] [security2:error] [pid 643253:tid 643434] [client 20.226.5.174:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/default.php"] [unique_id "amuE1cjqbtjBYzqM1uZLgAAAADI"]
[Thu Jul 30 12:07:33.675131 2026] [security2:error] [pid 643253:tid 643398] [client 213.152.187.215:33906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuE1cjqbtjBYzqM1uZLgQAAAA4"]
[Thu Jul 30 12:07:33.675249 2026] [security2:error] [pid 643253:tid 643398] [client 213.152.187.215:33906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuE1cjqbtjBYzqM1uZLgQAAAA4"]
[Thu Jul 30 12:07:34.212412 2026] [security2:error] [pid 643253:tid 643487] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE1cjqbtjBYzqM1uZLfgAAAGc"]
[Thu Jul 30 12:07:34.343461 2026] [security2:error] [pid 643253:tid 643494] [client 68.221.186.136:39341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/autoload_classmap.php"] [unique_id "amuE1sjqbtjBYzqM1uZLjQAAAG4"]
[Thu Jul 30 12:07:34.490470 2026] [security2:error] [pid 643253:tid 643418] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE1cjqbtjBYzqM1uZLhQAAIgE"]
[Thu Jul 30 12:07:34.797959 2026] [security2:error] [pid 643253:tid 643477] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE1sjqbtjBYzqM1uZLjAAAAF0"]
[Thu Jul 30 12:07:34.907750 2026] [security2:error] [pid 643253:tid 643489] [client 20.226.5.174:33479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/dropdown.php"] [unique_id "amuE1sjqbtjBYzqM1uZLoAAAAGk"]
[Thu Jul 30 12:07:34.956649 2026] [security2:error] [pid 643253:tid 643399] [client 191.232.199.39:19744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/post.php"] [unique_id "amuE1sjqbtjBYzqM1uZLpAAAAA8"]
[Thu Jul 30 12:07:34.976849 2026] [security2:error] [pid 643253:tid 643481] [client 20.52.125.110:7143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/LA.php"] [unique_id "amuE1sjqbtjBYzqM1uZLpQAAAGE"]
[Thu Jul 30 12:07:35.447995 2026] [security2:error] [pid 643253:tid 643379] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuE18jqbtjBYzqM1uZLqwAAO3w"]
[Thu Jul 30 12:07:35.479531 2026] [security2:error] [pid 643253:tid 643476] [client 20.52.125.110:7123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/admin.php"] [unique_id "amuE18jqbtjBYzqM1uZLrAAAAFw"]
[Thu Jul 30 12:07:35.808767 2026] [security2:error] [pid 643253:tid 643386] [client 172.213.232.128:55969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/03a005685d.php"] [unique_id "amuE18jqbtjBYzqM1uZLsAAAAAI"]
[Thu Jul 30 12:07:35.905297 2026] [security2:error] [pid 643253:tid 643459] [client 68.221.186.136:26066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/bb.php"] [unique_id "amuE18jqbtjBYzqM1uZLtAAAAEs"]
[Thu Jul 30 12:07:35.919166 2026] [security2:error] [pid 643253:tid 643478] [client 20.52.125.110:7122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/class_api.php"] [unique_id "amuE18jqbtjBYzqM1uZLtwAAAF4"]
[Thu Jul 30 12:07:35.956183 2026] [security2:error] [pid 643253:tid 643269] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuE18jqbtjBYzqM1uZLuQAAOQ4"]
[Thu Jul 30 12:07:36.042579 2026] [core:notice] [pid 643253:tid 643496] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:36.046818 2026] [security2:error] [pid 643253:tid 643496] [client 103.215.74.26:55008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE2MjqbtjBYzqM1uZLvQAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:36.185247 2026] [security2:error] [pid 643253:tid 643457] [client 20.226.5.174:34374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/edit.php"] [unique_id "amuE2MjqbtjBYzqM1uZLvgAAAEk"]
[Thu Jul 30 12:07:36.287042 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.142.71:42907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/media.php"] [unique_id "amuE2MjqbtjBYzqM1uZLwAAAAGo"]
[Thu Jul 30 12:07:36.287157 2026] [security2:error] [pid 643253:tid 643490] [client 20.203.142.71:42907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/media.php"] [unique_id "amuE2MjqbtjBYzqM1uZLwAAAAGo"]
[Thu Jul 30 12:07:36.343226 2026] [security2:error] [pid 643253:tid 643474] [client 20.52.125.110:7133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuE2MjqbtjBYzqM1uZLwQAAAFo"]
[Thu Jul 30 12:07:36.778450 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:36.784893 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:55016] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE2MjqbtjBYzqM1uZLzAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:36.818266 2026] [security2:error] [pid 643253:tid 643396] [client 20.52.125.110:7120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuE2MjqbtjBYzqM1uZLzQAAAAw"]
[Thu Jul 30 12:07:37.241206 2026] [security2:error] [pid 643253:tid 643468] [client 20.52.125.110:7156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuE2cjqbtjBYzqM1uZL1wAAAFQ"]
[Thu Jul 30 12:07:37.255816 2026] [security2:error] [pid 643253:tid 643442] [client 85.208.96.204:49520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/23/homem-e-preso-por-porte-ilegal-de-armas-em-guarabira/"] [unique_id "amuE2cjqbtjBYzqM1uZL2QAAADo"]
[Thu Jul 30 12:07:37.255932 2026] [security2:error] [pid 643253:tid 643442] [client 85.208.96.204:49520] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/23/homem-e-preso-por-porte-ilegal-de-armas-em-guarabira/"] [unique_id "amuE2cjqbtjBYzqM1uZL2QAAADo"]
[Thu Jul 30 12:07:37.261939 2026] [security2:error] [pid 643253:tid 643414] [client 136.70.106.31:60477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuE2MjqbtjBYzqM1uZLxAAAHgc"], referer: http://fireworkskenya.co.ke/media/system/js/core.js
[Thu Jul 30 12:07:37.445629 2026] [security2:error] [pid 643253:tid 643411] [client 172.213.232.128:55985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/403.php"] [unique_id "amuE2cjqbtjBYzqM1uZL2gAAABs"]
[Thu Jul 30 12:07:37.677954 2026] [security2:error] [pid 643253:tid 643384] [client 20.52.125.110:7150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/991176.php"] [unique_id "amuE2cjqbtjBYzqM1uZL5gAAAAA"]
[Thu Jul 30 12:07:37.753991 2026] [security2:error] [pid 643253:tid 643415] [client 20.203.142.71:30111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/images.php"] [unique_id "amuE2cjqbtjBYzqM1uZL5wAAAB8"]
[Thu Jul 30 12:07:37.754094 2026] [security2:error] [pid 643253:tid 643415] [client 20.203.142.71:30111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/images.php"] [unique_id "amuE2cjqbtjBYzqM1uZL5wAAAB8"]
[Thu Jul 30 12:07:37.956118 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:38.150962 2026] [security2:error] [pid 643253:tid 643434] [client 20.52.125.110:7153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuE2sjqbtjBYzqM1uZL8AAAADI"]
[Thu Jul 30 12:07:38.197295 2026] [security2:error] [pid 643253:tid 643496] [client 172.213.232.128:55952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/404.php"] [unique_id "amuE2sjqbtjBYzqM1uZL9AAAAHA"]
[Thu Jul 30 12:07:38.221791 2026] [security2:error] [pid 643253:tid 643465] [client 50.6.43.217:35072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuE2cjqbtjBYzqM1uZL3gAAAFE"]
[Thu Jul 30 12:07:38.560226 2026] [security2:error] [pid 643253:tid 643511] [client 20.52.125.110:8193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/LA.php"] [unique_id "amuE2sjqbtjBYzqM1uZL-wAAAH8"]
[Thu Jul 30 12:07:38.593455 2026] [security2:error] [pid 643253:tid 643451] [client 20.52.125.110:7131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuE2sjqbtjBYzqM1uZL_QAAAEM"]
[Thu Jul 30 12:07:38.620466 2026] [security2:error] [pid 643253:tid 643303] [remote 40.77.167.47:42964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/2024/10/stafff.php"] [unique_id "amuE2sjqbtjBYzqM1uZMAQAASjA"]
[Thu Jul 30 12:07:38.951281 2026] [security2:error] [pid 643253:tid 643494] [client 50.6.43.217:35074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuE2sjqbtjBYzqM1uZL9QAAAG4"]
[Thu Jul 30 12:07:39.040697 2026] [security2:error] [pid 643253:tid 643472] [client 20.52.125.110:8452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/admin.php"] [unique_id "amuE28jqbtjBYzqM1uZMCwAAAFg"]
[Thu Jul 30 12:07:39.109221 2026] [security2:error] [pid 643253:tid 643442] [client 20.52.125.110:7116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuE28jqbtjBYzqM1uZMDwAAADo"]
[Thu Jul 30 12:07:39.611022 2026] [security2:error] [pid 643253:tid 643438] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE28jqbtjBYzqM1uZMCgAAADY"]
[Thu Jul 30 12:07:39.622658 2026] [security2:error] [pid 643253:tid 643508] [client 20.52.125.110:7160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuE28jqbtjBYzqM1uZMGwAAAHw"]
[Thu Jul 30 12:07:39.641806 2026] [security2:error] [pid 643253:tid 643432] [client 20.52.125.110:8470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/class_api.php"] [unique_id "amuE28jqbtjBYzqM1uZMHAAAADA"]
[Thu Jul 30 12:07:40.039049 2026] [security2:error] [pid 643253:tid 643501] [client 20.203.142.71:36048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/gecko.php"] [unique_id "amuE3MjqbtjBYzqM1uZMIwAAAHU"]
[Thu Jul 30 12:07:40.039134 2026] [security2:error] [pid 643253:tid 643501] [client 20.203.142.71:36048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/gecko.php"] [unique_id "amuE3MjqbtjBYzqM1uZMIwAAAHU"]
[Thu Jul 30 12:07:40.100519 2026] [security2:error] [pid 643253:tid 643441] [client 68.221.186.136:31086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/bnm.php"] [unique_id "amuE3MjqbtjBYzqM1uZMJAAAADk"]
[Thu Jul 30 12:07:40.103849 2026] [security2:error] [pid 643253:tid 643482] [client 20.52.125.110:7149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuE3MjqbtjBYzqM1uZMJgAAAGI"]
[Thu Jul 30 12:07:40.164339 2026] [security2:error] [pid 643253:tid 643419] [client 20.52.125.110:8199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuE3MjqbtjBYzqM1uZMKwAAACM"]
[Thu Jul 30 12:07:40.484602 2026] [security2:error] [pid 643253:tid 643470] [client 20.203.142.71:29369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/82.php"] [unique_id "amuE3MjqbtjBYzqM1uZMMQAAAFY"]
[Thu Jul 30 12:07:40.484695 2026] [security2:error] [pid 643253:tid 643470] [client 20.203.142.71:29369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/82.php"] [unique_id "amuE3MjqbtjBYzqM1uZMMQAAAFY"]
[Thu Jul 30 12:07:40.654727 2026] [security2:error] [pid 643253:tid 643511] [client 20.52.125.110:8205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuE3MjqbtjBYzqM1uZMNAAAAH8"]
[Thu Jul 30 12:07:40.745048 2026] [security2:error] [pid 643253:tid 643477] [client 20.52.125.110:7121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuE3MjqbtjBYzqM1uZMOwAAAF0"]
[Thu Jul 30 12:07:40.812642 2026] [security2:error] [pid 643253:tid 643401] [client 68.221.186.136:31069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/bootstrap.php"] [unique_id "amuE3MjqbtjBYzqM1uZMPAAAABE"]
[Thu Jul 30 12:07:40.967195 2026] [security2:error] [pid 643253:tid 643315] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuE3MjqbtjBYzqM1uZMPQAANTw"]
[Thu Jul 30 12:07:41.043443 2026] [security2:error] [pid 643253:tid 643494] [client 20.203.142.71:36446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xstelth.php"] [unique_id "amuE3cjqbtjBYzqM1uZMPgAAAG4"]
[Thu Jul 30 12:07:41.043556 2026] [security2:error] [pid 643253:tid 643494] [client 20.203.142.71:36446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xstelth.php"] [unique_id "amuE3cjqbtjBYzqM1uZMPgAAAG4"]
[Thu Jul 30 12:07:41.199408 2026] [security2:error] [pid 643253:tid 643395] [client 20.52.125.110:7130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuE3cjqbtjBYzqM1uZMQgAAAAs"]
[Thu Jul 30 12:07:41.379890 2026] [security2:error] [pid 643253:tid 643481] [client 20.52.125.110:8480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuE3cjqbtjBYzqM1uZMSQAAAGE"]
[Thu Jul 30 12:07:41.464072 2026] [security2:error] [pid 643253:tid 643424] [client 68.221.186.136:39032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/buy.php"] [unique_id "amuE3cjqbtjBYzqM1uZMSgAAACg"]
[Thu Jul 30 12:07:41.723546 2026] [security2:error] [pid 643253:tid 643438] [client 20.52.125.110:6664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuE3cjqbtjBYzqM1uZMTgAAADY"]
[Thu Jul 30 12:07:41.932522 2026] [security2:error] [pid 643253:tid 643498] [client 20.203.142.71:25381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xp.php"] [unique_id "amuE3cjqbtjBYzqM1uZMVQAAAHI"]
[Thu Jul 30 12:07:41.932634 2026] [security2:error] [pid 643253:tid 643498] [client 20.203.142.71:25381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/xp.php"] [unique_id "amuE3cjqbtjBYzqM1uZMVQAAAHI"]
[Thu Jul 30 12:07:42.038344 2026] [security2:error] [pid 643253:tid 643433] [client 20.52.125.110:8483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/991176.php"] [unique_id "amuE3sjqbtjBYzqM1uZMWQAAADE"]
[Thu Jul 30 12:07:42.189847 2026] [security2:error] [pid 643253:tid 643394] [client 20.52.125.110:7138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuE3sjqbtjBYzqM1uZMWwAAAAo"]
[Thu Jul 30 12:07:42.220854 2026] [security2:error] [pid 643253:tid 643459] [client 68.221.186.136:39297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/chosen.php"] [unique_id "amuE3sjqbtjBYzqM1uZMXAAAAEs"]
[Thu Jul 30 12:07:42.347856 2026] [security2:error] [pid 643253:tid 643432] [client 172.213.232.128:55965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/aa.php"] [unique_id "amuE3sjqbtjBYzqM1uZMYwAAADA"]
[Thu Jul 30 12:07:42.422159 2026] [security2:error] [pid 643253:tid 643387] [client 20.226.5.174:33481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/f35.php"] [unique_id "amuE3sjqbtjBYzqM1uZMZwAAAAM"]
[Thu Jul 30 12:07:42.560458 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:42.566821 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:55022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE3sjqbtjBYzqM1uZMawAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:42.651253 2026] [security2:error] [pid 643253:tid 643465] [client 20.52.125.110:8510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuE3sjqbtjBYzqM1uZMbAAAAFE"]
[Thu Jul 30 12:07:42.690364 2026] [security2:error] [pid 643253:tid 643406] [client 20.52.125.110:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuE3sjqbtjBYzqM1uZMbQAAABY"]
[Thu Jul 30 12:07:42.802501 2026] [security2:error] [pid 643253:tid 643470] [client 68.221.186.136:38262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/class-wp-image.php"] [unique_id "amuE3sjqbtjBYzqM1uZMcQAAAFY"]
[Thu Jul 30 12:07:42.949182 2026] [security2:error] [pid 643253:tid 643479] [client 191.232.199.39:61119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-2019.php"] [unique_id "amuE3sjqbtjBYzqM1uZMdQAAAF8"]
[Thu Jul 30 12:07:43.209205 2026] [security2:error] [pid 643253:tid 643504] [client 20.52.125.110:6677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuE38jqbtjBYzqM1uZMeQAAAHg"]
[Thu Jul 30 12:07:43.266573 2026] [security2:error] [pid 643253:tid 643388] [client 20.52.125.110:8077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuE38jqbtjBYzqM1uZMegAAAAQ"]
[Thu Jul 30 12:07:43.277189 2026] [core:notice] [pid 643253:tid 643475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:43.281426 2026] [security2:error] [pid 643253:tid 643475] [client 103.215.74.26:17058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE38jqbtjBYzqM1uZMewAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:43.361624 2026] [security2:error] [pid 643253:tid 643500] [client 68.221.186.136:26089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/classsmtps.php"] [unique_id "amuE38jqbtjBYzqM1uZMgQAAAHQ"]
[Thu Jul 30 12:07:43.630202 2026] [security2:error] [pid 643253:tid 643443] [client 20.203.142.71:35599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/admin.php"] [unique_id "amuE38jqbtjBYzqM1uZMiAAAADs"]
[Thu Jul 30 12:07:43.630305 2026] [security2:error] [pid 643253:tid 643443] [client 20.203.142.71:35599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/admin.php"] [unique_id "amuE38jqbtjBYzqM1uZMiAAAADs"]
[Thu Jul 30 12:07:43.632479 2026] [security2:error] [pid 643253:tid 643440] [client 20.52.125.110:6981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuE38jqbtjBYzqM1uZMiQAAADg"]
[Thu Jul 30 12:07:43.838268 2026] [security2:error] [pid 643253:tid 643389] [client 20.52.125.110:8482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuE38jqbtjBYzqM1uZMjgAAAAU"]
[Thu Jul 30 12:07:44.030891 2026] [core:notice] [pid 643253:tid 643476] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:44.035233 2026] [security2:error] [pid 643253:tid 643476] [client 103.215.74.26:17066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE4MjqbtjBYzqM1uZMlgAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:44.164278 2026] [security2:error] [pid 643253:tid 643421] [client 20.52.125.110:6704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuE4MjqbtjBYzqM1uZMlwAAACU"]
[Thu Jul 30 12:07:44.424693 2026] [security2:error] [pid 643253:tid 643394] [client 20.52.125.110:8508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuE4MjqbtjBYzqM1uZMoAAAAAo"]
[Thu Jul 30 12:07:44.654088 2026] [security2:error] [pid 643253:tid 643484] [client 20.52.125.110:7136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuE4MjqbtjBYzqM1uZMxAAAAGQ"]
[Thu Jul 30 12:07:44.750819 2026] [core:notice] [pid 643253:tid 643427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:44.756890 2026] [security2:error] [pid 643253:tid 643427] [client 103.215.74.26:17078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE4MjqbtjBYzqM1uZMxgAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:44.767220 2026] [security2:error] [pid 643253:tid 643451] [client 20.203.142.71:29337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/adminner.php"] [unique_id "amuE4MjqbtjBYzqM1uZMxwAAAEM"]
[Thu Jul 30 12:07:44.767372 2026] [security2:error] [pid 643253:tid 643451] [client 20.203.142.71:29337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/adminner.php"] [unique_id "amuE4MjqbtjBYzqM1uZMxwAAAEM"]
[Thu Jul 30 12:07:44.994199 2026] [security2:error] [pid 643253:tid 643458] [client 20.52.125.110:8501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuE4MjqbtjBYzqM1uZM0gAAAEo"]
[Thu Jul 30 12:07:45.119147 2026] [security2:error] [pid 643253:tid 643388] [client 20.52.125.110:6682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/bek.php"] [unique_id "amuE4cjqbtjBYzqM1uZM1gAAAAQ"]
[Thu Jul 30 12:07:45.333447 2026] [security2:error] [pid 643253:tid 643492] [client 191.232.199.39:19724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/hoot.php"] [unique_id "amuE4cjqbtjBYzqM1uZM5gAAAGw"]
[Thu Jul 30 12:07:45.396462 2026] [security2:error] [pid 643253:tid 643428] [client 20.226.5.174:33677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cnpinyin.com"] [uri "/f7.php"] [unique_id "amuE4cjqbtjBYzqM1uZM6gAAACw"]
[Thu Jul 30 12:07:45.480258 2026] [core:notice] [pid 643253:tid 643423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:45.484531 2026] [security2:error] [pid 643253:tid 643423] [client 103.215.74.26:17080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE4cjqbtjBYzqM1uZM7gAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:45.602120 2026] [security2:error] [pid 643253:tid 643433] [client 20.52.125.110:8478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuE4cjqbtjBYzqM1uZM9QAAADE"]
[Thu Jul 30 12:07:45.659224 2026] [security2:error] [pid 643253:tid 643384] [client 20.52.125.110:6662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuE4cjqbtjBYzqM1uZM9gAAAAA"]
[Thu Jul 30 12:07:46.136328 2026] [security2:error] [pid 643253:tid 643505] [client 20.52.125.110:7113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/class.api.php"] [unique_id "amuE4sjqbtjBYzqM1uZNAwAAAHk"]
[Thu Jul 30 12:07:46.144160 2026] [security2:error] [pid 643253:tid 643501] [client 20.52.125.110:8504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuE4sjqbtjBYzqM1uZNBAAAAHU"]
[Thu Jul 30 12:07:46.208191 2026] [security2:error] [pid 643253:tid 643430] [client 14.177.3.227:38137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuE4cjqbtjBYzqM1uZM-QAAAC4"], referer: http://pkf.jo
[Thu Jul 30 12:07:46.612740 2026] [security2:error] [pid 643253:tid 643447] [client 20.52.125.110:6990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/cong.php"] [unique_id "amuE4sjqbtjBYzqM1uZNEQAAAD8"]
[Thu Jul 30 12:07:46.654245 2026] [security2:error] [pid 643253:tid 643396] [client 20.52.125.110:8214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuE4sjqbtjBYzqM1uZNEgAAAAw"]
[Thu Jul 30 12:07:47.025387 2026] [security2:error] [pid 643253:tid 643480] [client 20.52.125.110:7135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/content.php"] [unique_id "amuE48jqbtjBYzqM1uZNGgAAAGA"]
[Thu Jul 30 12:07:47.083460 2026] [security2:error] [pid 643253:tid 643442] [client 20.203.142.71:4329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/a.php"] [unique_id "amuE48jqbtjBYzqM1uZNHgAAADo"]
[Thu Jul 30 12:07:47.083565 2026] [security2:error] [pid 643253:tid 643442] [client 20.203.142.71:4329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/a.php"] [unique_id "amuE48jqbtjBYzqM1uZNHgAAADo"]
[Thu Jul 30 12:07:47.142210 2026] [security2:error] [pid 643253:tid 643489] [client 20.52.125.110:8208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuE48jqbtjBYzqM1uZNHwAAAGk"]
[Thu Jul 30 12:07:47.246653 2026] [security2:error] [pid 643253:tid 643495] [client 185.191.171.1:12702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/robots.txt"] [unique_id "amuE48jqbtjBYzqM1uZNIAAAAG8"]
[Thu Jul 30 12:07:47.246786 2026] [security2:error] [pid 643253:tid 643495] [client 185.191.171.1:12702] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "online-hope.com"] [uri "/robots.txt"] [unique_id "amuE48jqbtjBYzqM1uZNIAAAAG8"]
[Thu Jul 30 12:07:47.510165 2026] [security2:error] [pid 643253:tid 643486] [client 20.52.125.110:7125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuE48jqbtjBYzqM1uZNJwAAAGY"]
[Thu Jul 30 12:07:47.744749 2026] [security2:error] [pid 643253:tid 643386] [client 20.52.125.110:8505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuE48jqbtjBYzqM1uZNLwAAAAI"]
[Thu Jul 30 12:07:47.986625 2026] [security2:error] [pid 643253:tid 643426] [client 20.52.125.110:6659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/elp.php"] [unique_id "amuE48jqbtjBYzqM1uZNMQAAACo"]
[Thu Jul 30 12:07:48.223338 2026] [security2:error] [pid 643253:tid 643457] [client 20.52.125.110:8251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuE5MjqbtjBYzqM1uZNOwAAAEk"]
[Thu Jul 30 12:07:48.436675 2026] [security2:error] [pid 643253:tid 643419] [client 20.52.125.110:7166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuE5MjqbtjBYzqM1uZNPAAAACM"]
[Thu Jul 30 12:07:48.644432 2026] [security2:error] [pid 643253:tid 643459] [client 185.191.171.2:53894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product-tag/hope-%E5%B8%8C%E6%9C%9B%E9%A6%99%E7%85%9914mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/"] [unique_id "amuE5MjqbtjBYzqM1uZNSQAAAEs"]
[Thu Jul 30 12:07:48.644764 2026] [security2:error] [pid 643253:tid 643459] [client 185.191.171.2:53894] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "online-hope.com"] [uri "/product-tag/hope-%E5%B8%8C%E6%9C%9B%E9%A6%99%E7%85%9914mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/"] [unique_id "amuE5MjqbtjBYzqM1uZNSQAAAEs"]
[Thu Jul 30 12:07:48.784218 2026] [security2:error] [pid 643253:tid 643444] [client 20.52.125.110:8460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuE5MjqbtjBYzqM1uZNSwAAADw"]
[Thu Jul 30 12:07:48.896728 2026] [security2:error] [pid 643253:tid 643484] [client 20.52.125.110:7134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuE5MjqbtjBYzqM1uZNTAAAAGQ"]
[Thu Jul 30 12:07:48.990600 2026] [security2:error] [pid 643253:tid 643298] [remote 57.141.0.13:48086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuE5MjqbtjBYzqM1uZNTgAAUys"]
[Thu Jul 30 12:07:49.023801 2026] [core:notice] [pid 643253:tid 643260] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:49.271185 2026] [security2:error] [pid 643253:tid 643411] [client 20.52.125.110:8456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuE5cjqbtjBYzqM1uZNWgAAABs"]
[Thu Jul 30 12:07:49.463996 2026] [security2:error] [pid 643253:tid 643495] [client 20.52.125.110:7167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuE5cjqbtjBYzqM1uZNXwAAAG8"]
[Thu Jul 30 12:07:49.804366 2026] [security2:error] [pid 643253:tid 643445] [client 20.52.125.110:8493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuE5cjqbtjBYzqM1uZNawAAAD0"]
[Thu Jul 30 12:07:49.813735 2026] [security2:error] [pid 643253:tid 643497] [client 191.232.199.39:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/log.php"] [unique_id "amuE5cjqbtjBYzqM1uZNbAAAAHE"]
[Thu Jul 30 12:07:49.968838 2026] [security2:error] [pid 643253:tid 643426] [client 20.52.125.110:7151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuE5cjqbtjBYzqM1uZNbQAAACo"]
[Thu Jul 30 12:07:50.362503 2026] [security2:error] [pid 643253:tid 643505] [client 20.52.125.110:8494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/bek.php"] [unique_id "amuE5sjqbtjBYzqM1uZNeAAAAHk"]
[Thu Jul 30 12:07:50.420034 2026] [security2:error] [pid 643253:tid 643503] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE5cjqbtjBYzqM1uZNagAAd0g"]
[Thu Jul 30 12:07:50.486507 2026] [security2:error] [pid 643253:tid 643408] [client 20.52.125.110:7139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuE5sjqbtjBYzqM1uZNeQAAABg"]
[Thu Jul 30 12:07:50.790018 2026] [core:notice] [pid 643253:tid 643302] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:50.793788 2026] [security2:error] [pid 643253:tid 643422] [client 47.128.96.150:49434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/9559"] [unique_id "amuE5sjqbtjBYzqM1uZNfQAAJi8"]
[Thu Jul 30 12:07:50.858305 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:50.924007 2026] [security2:error] [pid 643253:tid 643511] [client 20.52.125.110:8454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuE5sjqbtjBYzqM1uZNhgAAAH8"]
[Thu Jul 30 12:07:50.941414 2026] [security2:error] [pid 643253:tid 643506] [client 20.52.125.110:6694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuE5sjqbtjBYzqM1uZNhwAAAHo"]
[Thu Jul 30 12:07:51.096916 2026] [core:notice] [pid 643253:tid 643286] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.224834 2026] [core:notice] [pid 643253:tid 643480] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.229322 2026] [security2:error] [pid 643253:tid 643480] [client 103.215.74.26:17082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE58jqbtjBYzqM1uZNjwAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:51.238438 2026] [core:notice] [pid 643253:tid 643278] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.238557 2026] [core:notice] [pid 643253:tid 643276] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.389679 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:6667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuE58jqbtjBYzqM1uZNlwAAAEE"]
[Thu Jul 30 12:07:51.472405 2026] [security2:error] [pid 643253:tid 643507] [client 20.52.125.110:8206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/class.api.php"] [unique_id "amuE58jqbtjBYzqM1uZNmwAAAHs"]
[Thu Jul 30 12:07:51.794282 2026] [security2:error] [pid 643253:tid 643445] [client 20.52.125.110:7165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuE58jqbtjBYzqM1uZNqgAAAD0"]
[Thu Jul 30 12:07:51.864890 2026] [core:error] [pid 643253:tid 643476] [client 66.249.79.199:38810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:51.864910 2026] [core:error] [pid 643253:tid 643476] [client 66.249.79.199:38810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:07:51.965370 2026] [security2:error] [pid 643253:tid 643478] [client 20.52.125.110:8474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/cong.php"] [unique_id "amuE58jqbtjBYzqM1uZNrQAAAF4"]
[Thu Jul 30 12:07:51.966422 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:51.970661 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:17090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE58jqbtjBYzqM1uZNrAAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:52.181204 2026] [security2:error] [pid 643253:tid 643328] [remote 57.141.0.61:26162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Grageman/announcement"] [unique_id "amuE6MjqbtjBYzqM1uZNsgAAeUk"]
[Thu Jul 30 12:07:52.220486 2026] [security2:error] [pid 643253:tid 643387] [client 20.52.125.110:7119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuE6MjqbtjBYzqM1uZNswAAAAM"]
[Thu Jul 30 12:07:52.355781 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.142.71:33872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/k.php"] [unique_id "amuE6MjqbtjBYzqM1uZNugAAAG0"]
[Thu Jul 30 12:07:52.355885 2026] [security2:error] [pid 643253:tid 643493] [client 20.203.142.71:33872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/k.php"] [unique_id "amuE6MjqbtjBYzqM1uZNugAAAG0"]
[Thu Jul 30 12:07:52.505047 2026] [security2:error] [pid 643253:tid 643465] [client 20.52.125.110:8491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/content.php"] [unique_id "amuE6MjqbtjBYzqM1uZNuwAAAFE"]
[Thu Jul 30 12:07:52.708403 2026] [security2:error] [pid 643253:tid 643510] [client 20.52.125.110:7126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuE6MjqbtjBYzqM1uZNvwAAAH4"]
[Thu Jul 30 12:07:52.717356 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:52.721696 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:17104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE6MjqbtjBYzqM1uZNwAAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:52.749764 2026] [security2:error] [pid 643253:tid 643425] [client 191.232.199.39:19718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/bak.php"] [unique_id "amuE6MjqbtjBYzqM1uZNwQAAACk"]
[Thu Jul 30 12:07:53.026647 2026] [security2:error] [pid 643253:tid 643388] [client 20.52.125.110:8500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuE6cjqbtjBYzqM1uZNzgAAAAQ"]
[Thu Jul 30 12:07:53.191248 2026] [security2:error] [pid 643253:tid 643480] [client 20.52.125.110:7147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuE6cjqbtjBYzqM1uZNzwAAAGA"]
[Thu Jul 30 12:07:53.261531 2026] [security2:error] [pid 643253:tid 643484] [client 172.213.232.128:55983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/aafewc0k.php"] [unique_id "amuE6cjqbtjBYzqM1uZN0AAAAGQ"]
[Thu Jul 30 12:07:53.484266 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:8194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/elp.php"] [unique_id "amuE6cjqbtjBYzqM1uZN2AAAAEE"]
[Thu Jul 30 12:07:53.485228 2026] [core:notice] [pid 643253:tid 643431] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:53.489708 2026] [security2:error] [pid 643253:tid 643431] [client 103.215.74.26:54206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE6cjqbtjBYzqM1uZN1wAAAC8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:53.619270 2026] [security2:error] [pid 643253:tid 643433] [client 20.52.125.110:6673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuE6cjqbtjBYzqM1uZN3gAAADE"]
[Thu Jul 30 12:07:53.984356 2026] [security2:error] [pid 643253:tid 643412] [client 20.52.125.110:8197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuE6cjqbtjBYzqM1uZN5QAAABw"]
[Thu Jul 30 12:07:54.010946 2026] [security2:error] [pid 643253:tid 643347] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuE6sjqbtjBYzqM1uZN5gAAClw"]
[Thu Jul 30 12:07:54.146896 2026] [security2:error] [pid 643253:tid 643497] [client 172.213.232.128:55548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/abcd.php"] [unique_id "amuE6sjqbtjBYzqM1uZN6AAAAHE"]
[Thu Jul 30 12:07:54.170546 2026] [security2:error] [pid 643253:tid 643478] [client 20.52.125.110:7199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuE6sjqbtjBYzqM1uZN6QAAAF4"]
[Thu Jul 30 12:07:54.219903 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:54.226378 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:54210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE6sjqbtjBYzqM1uZN6wAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:54.523837 2026] [security2:error] [pid 643253:tid 643461] [client 20.52.125.110:8226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuE6sjqbtjBYzqM1uZN9AAAAE0"]
[Thu Jul 30 12:07:54.613547 2026] [security2:error] [pid 643253:tid 643429] [client 20.52.125.110:6832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuE6sjqbtjBYzqM1uZN9gAAAC0"]
[Thu Jul 30 12:07:54.807070 2026] [security2:error] [pid 643253:tid 643424] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuE6sjqbtjBYzqM1uZN6gAAKFk"]
[Thu Jul 30 12:07:54.983361 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:54.989848 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:54214] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE6sjqbtjBYzqM1uZN_QAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:54.993384 2026] [security2:error] [pid 643253:tid 643465] [client 20.52.125.110:8502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuE6sjqbtjBYzqM1uZN_gAAAFE"]
[Thu Jul 30 12:07:55.199747 2026] [security2:error] [pid 643253:tid 643506] [client 20.52.125.110:7185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuE68jqbtjBYzqM1uZOBgAAAHo"]
[Thu Jul 30 12:07:55.378745 2026] [security2:error] [pid 643253:tid 643413] [client 172.213.232.128:55530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/about.php"] [unique_id "amuE68jqbtjBYzqM1uZOBwAAAB0"]
[Thu Jul 30 12:07:55.538078 2026] [security2:error] [pid 643253:tid 643388] [client 20.52.125.110:8202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuE68jqbtjBYzqM1uZOEAAAAAQ"]
[Thu Jul 30 12:07:55.625485 2026] [security2:error] [pid 643253:tid 643484] [client 20.52.125.110:7173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuE68jqbtjBYzqM1uZOEgAAAGQ"]
[Thu Jul 30 12:07:55.725209 2026] [core:notice] [pid 643253:tid 643481] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:55.729521 2026] [security2:error] [pid 643253:tid 643481] [client 103.215.74.26:54228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE68jqbtjBYzqM1uZOEwAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:56.029347 2026] [security2:error] [pid 643253:tid 643334] [remote 216.73.216.152:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuE7MjqbtjBYzqM1uZOFwAAJU8"]
[Thu Jul 30 12:07:56.126899 2026] [security2:error] [pid 643253:tid 643386] [client 20.52.125.110:6837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuE7MjqbtjBYzqM1uZOGwAAAAI"]
[Thu Jul 30 12:07:56.167449 2026] [security2:error] [pid 643253:tid 643390] [client 20.52.125.110:8207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuE7MjqbtjBYzqM1uZOHAAAAAY"]
[Thu Jul 30 12:07:56.182912 2026] [security2:error] [pid 643253:tid 643392] [client 191.232.199.39:19739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/content.php"] [unique_id "amuE7MjqbtjBYzqM1uZOHQAAAAg"]
[Thu Jul 30 12:07:56.446579 2026] [core:notice] [pid 643253:tid 643412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:56.450508 2026] [security2:error] [pid 643253:tid 643412] [client 103.215.74.26:54232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE7MjqbtjBYzqM1uZOHgAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:56.567001 2026] [security2:error] [pid 643253:tid 643474] [client 20.52.125.110:6798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuE7MjqbtjBYzqM1uZOKgAAAFo"]
[Thu Jul 30 12:07:56.625371 2026] [security2:error] [pid 643253:tid 643439] [client 213.152.187.215:44550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuE7MjqbtjBYzqM1uZOKwAAADc"]
[Thu Jul 30 12:07:56.625453 2026] [security2:error] [pid 643253:tid 643439] [client 213.152.187.215:44550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuE7MjqbtjBYzqM1uZOKwAAADc"]
[Thu Jul 30 12:07:56.676038 2026] [security2:error] [pid 643253:tid 643461] [client 20.52.125.110:8468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuE7MjqbtjBYzqM1uZOLAAAAE0"]
[Thu Jul 30 12:07:56.809262 2026] [security2:error] [pid 643253:tid 643387] [client 172.213.232.128:55534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/admin.php"] [unique_id "amuE7MjqbtjBYzqM1uZOLQAAAAM"]
[Thu Jul 30 12:07:57.071997 2026] [security2:error] [pid 643253:tid 643434] [client 20.52.125.110:6838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuE7cjqbtjBYzqM1uZONQAAADI"]
[Thu Jul 30 12:07:57.117147 2026] [security2:error] [pid 643253:tid 643464] [client 68.221.186.136:34678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/classwithtostring.php"] [unique_id "amuE7cjqbtjBYzqM1uZONwAAAFA"]
[Thu Jul 30 12:07:57.162539 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:57.169304 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:54240] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE7cjqbtjBYzqM1uZOOgAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:57.294361 2026] [security2:error] [pid 643253:tid 643420] [client 20.52.125.110:8497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuE7cjqbtjBYzqM1uZOOwAAACQ"]
[Thu Jul 30 12:07:57.347068 2026] [security2:error] [pid 643253:tid 643399] [client 14.237.140.74:51685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuE7cjqbtjBYzqM1uZONAAAAA8"], referer: http://pkf.jo
[Thu Jul 30 12:07:57.529367 2026] [security2:error] [pid 643253:tid 643388] [client 172.213.232.128:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/adminfuns.php"] [unique_id "amuE7cjqbtjBYzqM1uZOQAAAAAQ"]
[Thu Jul 30 12:07:57.624337 2026] [security2:error] [pid 643253:tid 643384] [client 20.52.125.110:6795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuE7cjqbtjBYzqM1uZORwAAAAA"]
[Thu Jul 30 12:07:57.771162 2026] [security2:error] [pid 643253:tid 643277] [remote 74.7.241.60:57394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuE7cjqbtjBYzqM1uZOSQAASBY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:07:57.790529 2026] [security2:error] [pid 643253:tid 643386] [client 20.52.125.110:8103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuE7cjqbtjBYzqM1uZOSgAAAAI"]
[Thu Jul 30 12:07:57.894734 2026] [core:notice] [pid 643253:tid 643394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:57.899161 2026] [security2:error] [pid 643253:tid 643394] [client 103.215.74.26:54244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE7cjqbtjBYzqM1uZOSwAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:58.027257 2026] [security2:error] [pid 643253:tid 643395] [client 191.232.199.39:61077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/upfile.php"] [unique_id "amuE7sjqbtjBYzqM1uZOTQAAAAs"]
[Thu Jul 30 12:07:58.128587 2026] [security2:error] [pid 643253:tid 643473] [client 20.52.125.110:6826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuE7sjqbtjBYzqM1uZOVwAAAFk"]
[Thu Jul 30 12:07:58.320863 2026] [security2:error] [pid 643253:tid 643424] [client 20.52.125.110:8511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuE7sjqbtjBYzqM1uZOWwAAACg"]
[Thu Jul 30 12:07:58.560913 2026] [security2:error] [pid 643253:tid 643432] [client 172.213.232.128:55977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/albin.php"] [unique_id "amuE7sjqbtjBYzqM1uZOYAAAADA"]
[Thu Jul 30 12:07:58.627284 2026] [core:notice] [pid 643253:tid 643393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:58.632534 2026] [security2:error] [pid 643253:tid 643393] [client 103.215.74.26:54260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE7sjqbtjBYzqM1uZOZgAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:58.648749 2026] [security2:error] [pid 643253:tid 643425] [client 20.52.125.110:6834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuE7sjqbtjBYzqM1uZOaAAAACk"]
[Thu Jul 30 12:07:58.854949 2026] [security2:error] [pid 643253:tid 643418] [client 20.52.125.110:8484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuE7sjqbtjBYzqM1uZOaQAAACI"]
[Thu Jul 30 12:07:59.189140 2026] [security2:error] [pid 643253:tid 643504] [client 172.213.232.128:55971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/amfsqvgv.php"] [unique_id "amuE78jqbtjBYzqM1uZObgAAAHg"]
[Thu Jul 30 12:07:59.195347 2026] [security2:error] [pid 643253:tid 643509] [client 20.52.125.110:6817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuE78jqbtjBYzqM1uZObwAAAH0"]
[Thu Jul 30 12:07:59.362068 2026] [core:notice] [pid 643253:tid 643502] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:07:59.366495 2026] [security2:error] [pid 643253:tid 643502] [client 103.215.74.26:54270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE78jqbtjBYzqM1uZOcwAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:07:59.445340 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:8200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuE78jqbtjBYzqM1uZOdgAAACc"]
[Thu Jul 30 12:07:59.630565 2026] [security2:error] [pid 643253:tid 643471] [client 20.52.125.110:7178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuE78jqbtjBYzqM1uZOeAAAAFc"]
[Thu Jul 30 12:07:59.837568 2026] [security2:error] [pid 643253:tid 643489] [client 191.232.199.39:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/bypass.php"] [unique_id "amuE78jqbtjBYzqM1uZOgAAAAGk"]
[Thu Jul 30 12:08:00.004601 2026] [security2:error] [pid 643253:tid 643392] [client 20.52.125.110:8475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuE8MjqbtjBYzqM1uZOgQAAAAg"]
[Thu Jul 30 12:08:00.098620 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:00.103336 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:54274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE8MjqbtjBYzqM1uZOgwAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:00.103507 2026] [security2:error] [pid 643253:tid 643476] [client 20.52.125.110:6833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuE8MjqbtjBYzqM1uZOhAAAAFw"]
[Thu Jul 30 12:08:00.188437 2026] [security2:error] [pid 643253:tid 643498] [client 172.213.232.128:55963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/ant.php"] [unique_id "amuE8MjqbtjBYzqM1uZOiAAAAHI"]
[Thu Jul 30 12:08:00.263192 2026] [core:notice] [pid 643253:tid 643449] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:00.317438 2026] [security2:error] [pid 643253:tid 643441] [client 68.221.186.136:34187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/config.php"] [unique_id "amuE8MjqbtjBYzqM1uZOjwAAADk"]
[Thu Jul 30 12:08:00.577094 2026] [security2:error] [pid 643253:tid 643419] [client 20.52.125.110:6808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuE8MjqbtjBYzqM1uZOkAAAACM"]
[Thu Jul 30 12:08:00.597017 2026] [security2:error] [pid 643253:tid 643444] [client 2.90.102.171:44272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuE8MjqbtjBYzqM1uZOjgAAADw"], referer: http://pkf.jo
[Thu Jul 30 12:08:00.785101 2026] [security2:error] [pid 643253:tid 643446] [client 20.52.125.110:8490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuE8MjqbtjBYzqM1uZOmAAAAD4"]
[Thu Jul 30 12:08:00.879238 2026] [core:notice] [pid 643253:tid 643424] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:00.886632 2026] [security2:error] [pid 643253:tid 643424] [client 103.215.74.26:54278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE8MjqbtjBYzqM1uZOmwAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:01.029848 2026] [security2:error] [pid 643253:tid 643479] [client 20.52.125.110:6802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuE8cjqbtjBYzqM1uZOnwAAAF8"]
[Thu Jul 30 12:08:01.454592 2026] [security2:error] [pid 643253:tid 643492] [client 20.52.125.110:8455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuE8cjqbtjBYzqM1uZOpwAAAGw"]
[Thu Jul 30 12:08:01.512822 2026] [security2:error] [pid 643253:tid 643420] [client 20.52.125.110:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuE8cjqbtjBYzqM1uZOqQAAACQ"]
[Thu Jul 30 12:08:01.533059 2026] [security2:error] [pid 643253:tid 643404] [client 172.213.232.128:55972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/appreciators.php"] [unique_id "amuE8cjqbtjBYzqM1uZOqgAAABQ"]
[Thu Jul 30 12:08:01.648361 2026] [core:notice] [pid 643253:tid 643399] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:01.654930 2026] [security2:error] [pid 643253:tid 643399] [client 103.215.74.26:54284] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE8cjqbtjBYzqM1uZOqwAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:01.683583 2026] [security2:error] [pid 643253:tid 643442] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuE8MjqbtjBYzqM1uZOmQAAOjQ"]
[Thu Jul 30 12:08:01.686517 2026] [security2:error] [pid 643253:tid 643387] [client 68.221.186.136:34220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/core.php"] [unique_id "amuE8cjqbtjBYzqM1uZOrAAAAAM"]
[Thu Jul 30 12:08:02.037264 2026] [security2:error] [pid 643253:tid 643483] [client 20.52.125.110:7184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuE8sjqbtjBYzqM1uZOtAAAAGM"]
[Thu Jul 30 12:08:02.078463 2026] [security2:error] [pid 643253:tid 643390] [client 20.52.125.110:8495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuE8sjqbtjBYzqM1uZOtQAAAAY"]
[Thu Jul 30 12:08:02.290597 2026] [security2:error] [pid 643253:tid 643448] [client 191.232.199.39:59810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/updates.php"] [unique_id "amuE8sjqbtjBYzqM1uZOuQAAAEA"]
[Thu Jul 30 12:08:02.385409 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:02.392042 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:54292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE8sjqbtjBYzqM1uZOvQAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:02.449794 2026] [security2:error] [pid 643253:tid 643386] [client 68.221.186.136:34197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/css.php"] [unique_id "amuE8sjqbtjBYzqM1uZOvwAAAAI"]
[Thu Jul 30 12:08:02.503290 2026] [security2:error] [pid 643253:tid 643397] [client 20.52.125.110:7175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuE8sjqbtjBYzqM1uZOwAAAAA0"]
[Thu Jul 30 12:08:02.711658 2026] [security2:error] [pid 643253:tid 643427] [client 20.52.125.110:8204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuE8sjqbtjBYzqM1uZOwgAAACs"]
[Thu Jul 30 12:08:02.989012 2026] [security2:error] [pid 643253:tid 643385] [client 20.52.125.110:7188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuE8sjqbtjBYzqM1uZOyQAAAAE"]
[Thu Jul 30 12:08:03.096242 2026] [security2:error] [pid 643253:tid 643415] [client 172.213.232.128:55504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/archive.php"] [unique_id "amuE88jqbtjBYzqM1uZOywAAAB8"]
[Thu Jul 30 12:08:03.112275 2026] [core:notice] [pid 643253:tid 643467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:03.116620 2026] [security2:error] [pid 643253:tid 643467] [client 103.215.74.26:23412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE88jqbtjBYzqM1uZOzAAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:03.287897 2026] [security2:error] [pid 643253:tid 643425] [client 20.52.125.110:8083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuE88jqbtjBYzqM1uZOzgAAACk"]
[Thu Jul 30 12:08:03.470595 2026] [security2:error] [pid 643253:tid 643401] [client 20.52.125.110:6793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuE88jqbtjBYzqM1uZO2AAAABE"]
[Thu Jul 30 12:08:03.626432 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:03.643751 2026] [security2:error] [pid 643253:tid 643446] [client 68.221.186.136:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/database.php"] [unique_id "amuE88jqbtjBYzqM1uZO3QAAAD4"]
[Thu Jul 30 12:08:03.840496 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:03.842724 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:8245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuE88jqbtjBYzqM1uZO4AAAACc"]
[Thu Jul 30 12:08:03.845371 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:23428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE88jqbtjBYzqM1uZO3wAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:03.931120 2026] [security2:error] [pid 643253:tid 643481] [client 20.52.125.110:7177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arabian-tours.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuE88jqbtjBYzqM1uZO5AAAAGE"]
[Thu Jul 30 12:08:04.295494 2026] [security2:error] [pid 643253:tid 643488] [client 20.52.125.110:8477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuE9MjqbtjBYzqM1uZO7AAAAGg"]
[Thu Jul 30 12:08:04.625595 2026] [core:notice] [pid 643253:tid 643443] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:04.632209 2026] [security2:error] [pid 643253:tid 643443] [client 103.215.74.26:23442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE9MjqbtjBYzqM1uZO9wAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:04.688917 2026] [security2:error] [pid 643253:tid 643455] [client 191.232.199.39:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/xmrlpc.php"] [unique_id "amuE9MjqbtjBYzqM1uZO-AAAAEc"]
[Thu Jul 30 12:08:04.698698 2026] [security2:error] [pid 643253:tid 643511] [client 172.213.232.128:55989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/as.php"] [unique_id "amuE9MjqbtjBYzqM1uZO-QAAAH8"]
[Thu Jul 30 12:08:04.709364 2026] [security2:error] [pid 643253:tid 643460] [client 20.52.125.110:8498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuE9MjqbtjBYzqM1uZO-gAAAEw"]
[Thu Jul 30 12:08:04.793648 2026] [security2:error] [pid 643253:tid 643304] [remote 77.46.136.200:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.136.46.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amuE9MjqbtjBYzqM1uZO8AAAYzE"]
[Thu Jul 30 12:08:04.793897 2026] [security2:error] [pid 643253:tid 643483] [client 77.46.136.200:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amuE9MjqbtjBYzqM1uZO8AAAYzE"]
[Thu Jul 30 12:08:05.190293 2026] [security2:error] [pid 643253:tid 643415] [client 20.52.125.110:8451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuE9cjqbtjBYzqM1uZPBgAAAB8"]
[Thu Jul 30 12:08:05.370068 2026] [core:notice] [pid 643253:tid 643464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:05.374455 2026] [security2:error] [pid 643253:tid 643464] [client 103.215.74.26:23450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE9cjqbtjBYzqM1uZPCAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:05.472088 2026] [security2:error] [pid 643253:tid 643456] [client 68.221.186.136:35057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/db.php"] [unique_id "amuE9cjqbtjBYzqM1uZPCQAAAEg"]
[Thu Jul 30 12:08:05.612080 2026] [security2:error] [pid 643253:tid 643419] [client 172.213.232.128:55992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/atomlib.php"] [unique_id "amuE9cjqbtjBYzqM1uZPGwAAACM"]
[Thu Jul 30 12:08:05.768261 2026] [security2:error] [pid 643253:tid 643486] [client 20.52.125.110:8008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuE9cjqbtjBYzqM1uZPHAAAAGY"]
[Thu Jul 30 12:08:05.949310 2026] [security2:error] [pid 643253:tid 643418] [client 191.232.199.39:59826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/ae.php"] [unique_id "amuE9cjqbtjBYzqM1uZPIwAAACI"]
[Thu Jul 30 12:08:06.114137 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:06.115300 2026] [security2:error] [pid 643253:tid 643411] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE9cjqbtjBYzqM1uZPDwAAABs"]
[Thu Jul 30 12:08:06.119071 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:23464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE9sjqbtjBYzqM1uZPLQAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:06.141931 2026] [security2:error] [pid 643253:tid 643492] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuE9cjqbtjBYzqM1uZPFgAAAGw"]
[Thu Jul 30 12:08:06.189073 2026] [security2:error] [pid 643253:tid 643508] [client 68.221.186.136:39670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/011i.php"] [unique_id "amuE9sjqbtjBYzqM1uZPLgAAAHw"]
[Thu Jul 30 12:08:06.233878 2026] [security2:error] [pid 643253:tid 643384] [client 20.52.125.110:8220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuE9sjqbtjBYzqM1uZPLwAAAAA"]
[Thu Jul 30 12:08:06.513853 2026] [core:notice] [pid 643253:tid 643408] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:06.540087 2026] [security2:error] [pid 643253:tid 643448] [client 68.221.186.136:38550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/default.php"] [unique_id "amuE9sjqbtjBYzqM1uZPMQAAAEA"]
[Thu Jul 30 12:08:06.758218 2026] [security2:error] [pid 643253:tid 643493] [client 20.52.125.110:8066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuE9sjqbtjBYzqM1uZPPQAAAG0"]
[Thu Jul 30 12:08:06.852251 2026] [core:notice] [pid 643253:tid 643403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:06.856592 2026] [security2:error] [pid 643253:tid 643403] [client 103.215.74.26:23474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE9sjqbtjBYzqM1uZPQQAAABM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:07.298348 2026] [security2:error] [pid 643253:tid 643447] [client 172.213.232.128:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/autoload_classmap.php"] [unique_id "amuE98jqbtjBYzqM1uZPTAAAAD8"]
[Thu Jul 30 12:08:07.298472 2026] [security2:error] [pid 643253:tid 643389] [client 20.52.125.110:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuE98jqbtjBYzqM1uZPTQAAAAU"]
[Thu Jul 30 12:08:07.577348 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:07.581664 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:23482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE98jqbtjBYzqM1uZPVgAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:07.605746 2026] [security2:error] [pid 643253:tid 643496] [client 185.189.112.11:43884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuE98jqbtjBYzqM1uZPWAAAAHA"]
[Thu Jul 30 12:08:07.605868 2026] [security2:error] [pid 643253:tid 643496] [client 185.189.112.11:43884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuE98jqbtjBYzqM1uZPWAAAAHA"]
[Thu Jul 30 12:08:07.632684 2026] [security2:error] [pid 643253:tid 643398] [client 191.232.199.39:41229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/moon.php"] [unique_id "amuE98jqbtjBYzqM1uZPWQAAAA4"]
[Thu Jul 30 12:08:07.814525 2026] [security2:error] [pid 643253:tid 643392] [client 20.52.125.110:8212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuE98jqbtjBYzqM1uZPYAAAAAg"]
[Thu Jul 30 12:08:07.877196 2026] [security2:error] [pid 643253:tid 643428] [client 172.213.232.128:55527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/bb.php"] [unique_id "amuE98jqbtjBYzqM1uZPYgAAACw"]
[Thu Jul 30 12:08:08.157175 2026] [security2:error] [pid 643253:tid 643435] [client 50.6.43.217:12776] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE-MjqbtjBYzqM1uZPbAAAADM"]
[Thu Jul 30 12:08:08.181950 2026] [security2:error] [pid 643253:tid 643409] [client 50.6.43.217:12788] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE-MjqbtjBYzqM1uZPbQAAABk"]
[Thu Jul 30 12:08:08.216043 2026] [security2:error] [pid 643253:tid 643391] [client 57.141.0.64:58368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuE98jqbtjBYzqM1uZPYQAAB0Y"], referer: https://igetvape-australia.com/product-tag/alibarbar-ice-adjust-12000-puffs-blueberry-blast/
[Thu Jul 30 12:08:08.316004 2026] [core:notice] [pid 643253:tid 643397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:08.320318 2026] [security2:error] [pid 643253:tid 643397] [client 103.215.74.26:23496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-MjqbtjBYzqM1uZPcQAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:08.401863 2026] [security2:error] [pid 643253:tid 643459] [client 20.52.125.110:8067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuE-MjqbtjBYzqM1uZPcgAAAEs"]
[Thu Jul 30 12:08:08.692310 2026] [core:error] [pid 643253:tid 643396] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:08:08.692338 2026] [core:error] [pid 643253:tid 643396] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:08:08.712800 2026] [security2:error] [pid 643253:tid 643386] [client 127.0.0.1:29556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuE-MjqbtjBYzqM1uZPfQAAAAI"]
[Thu Jul 30 12:08:08.712833 2026] [security2:error] [pid 643253:tid 643468] [client 74.7.175.158:56174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.aaapropertiesph.com"] [uri "/robots.txt"] [unique_id "amuE-MjqbtjBYzqM1uZPewAAAFQ"]
[Thu Jul 30 12:08:08.731489 2026] [security2:error] [pid 643253:tid 643463] [client 68.221.186.136:31297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/03a005685d.php"] [unique_id "amuE-MjqbtjBYzqM1uZPggAAAE8"]
[Thu Jul 30 12:08:08.871854 2026] [security2:error] [pid 643253:tid 643475] [client 191.232.199.39:61094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/blog.php"] [unique_id "amuE-MjqbtjBYzqM1uZPgwAAAFs"]
[Thu Jul 30 12:08:08.898623 2026] [security2:error] [pid 643253:tid 643456] [client 20.52.125.110:8229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuE-MjqbtjBYzqM1uZPhAAAAEg"]
[Thu Jul 30 12:08:09.103613 2026] [core:notice] [pid 643253:tid 643438] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:09.110374 2026] [security2:error] [pid 643253:tid 643438] [client 103.215.74.26:23502] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-cjqbtjBYzqM1uZPiQAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:09.162689 2026] [security2:error] [pid 643253:tid 643419] [client 212.193.3.94:65525] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuE-cjqbtjBYzqM1uZPigAAACM"]
[Thu Jul 30 12:08:09.307446 2026] [security2:error] [pid 643253:tid 643418] [client 172.213.232.128:55567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/bnm.php"] [unique_id "amuE-cjqbtjBYzqM1uZPkgAAACI"]
[Thu Jul 30 12:08:09.340246 2026] [security2:error] [pid 643253:tid 643482] [client 50.6.43.217:55976] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE-cjqbtjBYzqM1uZPkwAAAGI"]
[Thu Jul 30 12:08:09.353990 2026] [security2:error] [pid 643253:tid 643457] [client 20.52.125.110:8223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuE-cjqbtjBYzqM1uZPlAAAAEk"]
[Thu Jul 30 12:08:09.485744 2026] [security2:error] [pid 643253:tid 643496] [client 68.221.186.136:40663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/403.php"] [unique_id "amuE-cjqbtjBYzqM1uZPlgAAAHA"]
[Thu Jul 30 12:08:09.572481 2026] [security2:error] [pid 643253:tid 643388] [client 212.193.3.94:49212] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "deltaedu.net"] [uri "/wp-json/batch/v1"] [unique_id "amuE-cjqbtjBYzqM1uZPmgAAAAQ"]
[Thu Jul 30 12:08:09.576866 2026] [security2:error] [pid 643253:tid 643374] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuE-cjqbtjBYzqM1uZPmwAAWnc"]
[Thu Jul 30 12:08:09.747263 2026] [security2:error] [pid 643253:tid 643431] [client 68.221.186.136:34207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/dropdown.php"] [unique_id "amuE-cjqbtjBYzqM1uZPowAAAC8"]
[Thu Jul 30 12:08:09.844535 2026] [core:notice] [pid 643253:tid 643392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:09.851019 2026] [security2:error] [pid 643253:tid 643392] [client 103.215.74.26:23508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-cjqbtjBYzqM1uZPpQAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:09.968042 2026] [security2:error] [pid 643253:tid 643449] [client 20.52.125.110:8248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuE-cjqbtjBYzqM1uZPpgAAAEE"]
[Thu Jul 30 12:08:10.003396 2026] [security2:error] [pid 643253:tid 643505] [client 212.193.3.94:49256] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuE-cjqbtjBYzqM1uZPpwAAAHk"]
[Thu Jul 30 12:08:10.460920 2026] [security2:error] [pid 643253:tid 643413] [client 20.52.125.110:8072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuE-sjqbtjBYzqM1uZPtgAAAB0"]
[Thu Jul 30 12:08:10.573156 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:10.580242 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:23514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-sjqbtjBYzqM1uZPtwAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:10.756192 2026] [security2:error] [pid 643253:tid 643503] [client 172.213.232.128:55563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/bootstrap.php"] [unique_id "amuE-sjqbtjBYzqM1uZPwgAAAHc"]
[Thu Jul 30 12:08:10.759392 2026] [security2:error] [pid 643253:tid 643430] [client 50.6.43.217:55988] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE-sjqbtjBYzqM1uZPwQAAAC4"]
[Thu Jul 30 12:08:10.978700 2026] [security2:error] [pid 643253:tid 643500] [client 20.52.125.110:8496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuE-sjqbtjBYzqM1uZPxAAAAHQ"]
[Thu Jul 30 12:08:11.324973 2026] [core:notice] [pid 643253:tid 643485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:11.329423 2026] [security2:error] [pid 643253:tid 643485] [client 103.215.74.26:23518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE-8jqbtjBYzqM1uZP0QAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:11.427995 2026] [security2:error] [pid 643253:tid 643388] [client 68.221.186.136:30152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/404.php"] [unique_id "amuE-8jqbtjBYzqM1uZP0gAAAAQ"]
[Thu Jul 30 12:08:11.470701 2026] [security2:error] [pid 643253:tid 643510] [client 20.52.125.110:8485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.kingstarenterprises.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuE-8jqbtjBYzqM1uZP0wAAAH4"]
[Thu Jul 30 12:08:11.879520 2026] [security2:error] [pid 643253:tid 643506] [client 172.213.232.128:55590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/buy.php"] [unique_id "amuE-8jqbtjBYzqM1uZP4QAAAHo"]
[Thu Jul 30 12:08:11.902219 2026] [security2:error] [pid 643253:tid 643490] [client 20.52.125.110:12225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/json.php"] [unique_id "amuE-8jqbtjBYzqM1uZP4gAAAGo"]
[Thu Jul 30 12:08:11.905502 2026] [security2:error] [pid 643253:tid 643424] [client 68.221.186.136:46103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/aa.php"] [unique_id "amuE-8jqbtjBYzqM1uZP4wAAACg"]
[Thu Jul 30 12:08:12.059736 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:12.066301 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:23528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_MjqbtjBYzqM1uZP6AAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:12.600688 2026] [security2:error] [pid 643253:tid 643403] [client 50.6.43.217:59592] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_MjqbtjBYzqM1uZP9QAAABM"]
[Thu Jul 30 12:08:12.675650 2026] [security2:error] [pid 643253:tid 643503] [client 172.213.232.128:55571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/chosen.php"] [unique_id "amuE_MjqbtjBYzqM1uZP-AAAAHc"]
[Thu Jul 30 12:08:12.754345 2026] [security2:error] [pid 643253:tid 643468] [client 50.6.43.217:59600] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_MjqbtjBYzqM1uZP-QAAAFQ"]
[Thu Jul 30 12:08:12.790831 2026] [core:notice] [pid 643253:tid 643417] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:12.795025 2026] [security2:error] [pid 643253:tid 643417] [client 103.215.74.26:23542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_MjqbtjBYzqM1uZP_AAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:12.929152 2026] [security2:error] [pid 643253:tid 643478] [client 191.232.199.39:61098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/ini.php"] [unique_id "amuE_MjqbtjBYzqM1uZQAQAAAF4"]
[Thu Jul 30 12:08:13.377660 2026] [security2:error] [pid 643253:tid 643401] [client 68.221.186.136:23762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/aafewc0k.php"] [unique_id "amuE_cjqbtjBYzqM1uZQCwAAABE"]
[Thu Jul 30 12:08:13.409115 2026] [security2:error] [pid 643253:tid 643492] [client 172.213.232.128:55552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/class-wp-image.php"] [unique_id "amuE_cjqbtjBYzqM1uZQDAAAAGw"]
[Thu Jul 30 12:08:13.482198 2026] [security2:error] [pid 643253:tid 643443] [client 50.6.43.217:58480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuE_cjqbtjBYzqM1uZQDgAAADs"]
[Thu Jul 30 12:08:13.492669 2026] [security2:error] [pid 643253:tid 643429] [client 50.6.43.217:58492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuE_cjqbtjBYzqM1uZQEQAAAC0"]
[Thu Jul 30 12:08:13.502871 2026] [security2:error] [pid 643253:tid 643449] [client 50.6.43.217:58500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuE_cjqbtjBYzqM1uZQEwAAAEE"]
[Thu Jul 30 12:08:13.506554 2026] [core:notice] [pid 643253:tid 643400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:13.514380 2026] [security2:error] [pid 643253:tid 643400] [client 103.215.74.26:59912] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_cjqbtjBYzqM1uZQFAAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:14.228765 2026] [security2:error] [pid 643253:tid 643456] [client 50.6.43.217:59612] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_sjqbtjBYzqM1uZQKAAAAEg"]
[Thu Jul 30 12:08:14.252549 2026] [core:notice] [pid 643253:tid 643422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:14.259559 2026] [security2:error] [pid 643253:tid 643422] [client 103.215.74.26:59918] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_sjqbtjBYzqM1uZQKQAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:14.373958 2026] [security2:error] [pid 643253:tid 643438] [client 50.6.43.217:59618] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_sjqbtjBYzqM1uZQLQAAADY"]
[Thu Jul 30 12:08:14.659285 2026] [security2:error] [pid 643253:tid 643404] [client 172.213.232.128:55553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/classsmtps.php"] [unique_id "amuE_sjqbtjBYzqM1uZQNQAAABQ"]
[Thu Jul 30 12:08:14.685770 2026] [security2:error] [pid 643253:tid 643423] [client 20.52.125.110:12203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/mini.php"] [unique_id "amuE_sjqbtjBYzqM1uZQNgAAACc"]
[Thu Jul 30 12:08:14.895816 2026] [security2:error] [pid 643253:tid 643477] [client 68.221.186.136:46109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/abcd.php"] [unique_id "amuE_sjqbtjBYzqM1uZQOgAAAF0"]
[Thu Jul 30 12:08:14.967479 2026] [security2:error] [pid 643253:tid 643386] [client 79.106.125.194:42358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuE_sjqbtjBYzqM1uZQIQAAAAI"], referer: http://pkf.jo
[Thu Jul 30 12:08:15.007486 2026] [security2:error] [pid 643253:tid 643458] [client 47.128.22.17:42546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "moswey.com"] [uri "/robots.txt"] [unique_id "amuE_8jqbtjBYzqM1uZQQAAAAEo"]
[Thu Jul 30 12:08:15.008419 2026] [core:notice] [pid 643253:tid 643407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:15.014825 2026] [security2:error] [pid 643253:tid 643407] [client 103.215.74.26:59922] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_8jqbtjBYzqM1uZQPwAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:15.481120 2026] [security2:error] [pid 643253:tid 643505] [client 172.213.232.128:55519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.raad.pk"] [uri "/classwithtostring.php"] [unique_id "amuE_8jqbtjBYzqM1uZQTgAAAHk"]
[Thu Jul 30 12:08:15.746244 2026] [core:notice] [pid 643253:tid 643385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:15.752797 2026] [security2:error] [pid 643253:tid 643385] [client 103.215.74.26:59938] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuE_8jqbtjBYzqM1uZQUwAAAAE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:15.772355 2026] [security2:error] [pid 643253:tid 643467] [client 50.6.43.217:59634] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_8jqbtjBYzqM1uZQVAAAAFM"]
[Thu Jul 30 12:08:15.812470 2026] [security2:error] [pid 643253:tid 643429] [client 68.221.186.136:33047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuE_8jqbtjBYzqM1uZQVQAAAC0"]
[Thu Jul 30 12:08:15.843669 2026] [security2:error] [pid 643253:tid 643399] [client 191.232.199.39:61096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin-ajax.php"] [unique_id "amuE_8jqbtjBYzqM1uZQWAAAAA8"]
[Thu Jul 30 12:08:15.932779 2026] [security2:error] [pid 643253:tid 643498] [client 50.6.43.217:59642] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuE_8jqbtjBYzqM1uZQWgAAAHI"]
[Thu Jul 30 12:08:16.042139 2026] [autoindex:error] [pid 643253:tid 643292] [remote 172.239.144.164:51038] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:08:16.460370 2026] [security2:error] [pid 643253:tid 643438] [client 103.76.47.160:41148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFAMjqbtjBYzqM1uZQZAAAADY"], referer: http://pkf.jo
[Thu Jul 30 12:08:16.479397 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:16.489972 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:59952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFAMjqbtjBYzqM1uZQawAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:16.886966 2026] [security2:error] [pid 643253:tid 643468] [client 68.221.186.136:33031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuFAMjqbtjBYzqM1uZQdAAAAFQ"]
[Thu Jul 30 12:08:17.212705 2026] [core:notice] [pid 643253:tid 643457] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:17.213396 2026] [security2:error] [pid 643253:tid 643404] [client 20.52.125.110:12195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/chosen.php"] [unique_id "amuFAcjqbtjBYzqM1uZQfAAAABQ"]
[Thu Jul 30 12:08:17.218964 2026] [security2:error] [pid 643253:tid 643457] [client 103.215.74.26:59956] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFAcjqbtjBYzqM1uZQewAAAEk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:17.462614 2026] [security2:error] [pid 643253:tid 643508] [client 191.232.199.39:59795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/akc.php"] [unique_id "amuFAcjqbtjBYzqM1uZQhgAAAHw"]
[Thu Jul 30 12:08:17.933728 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:17.939457 2026] [security2:error] [pid 643253:tid 643429] [client 103.215.74.26:59960] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFAcjqbtjBYzqM1uZQjgAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:18.000929 2026] [security2:error] [pid 643253:tid 643480] [client 68.221.186.136:33028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/adminfuns.php"] [unique_id "amuFAsjqbtjBYzqM1uZQkgAAAGA"]
[Thu Jul 30 12:08:18.195796 2026] [security2:error] [pid 643253:tid 643413] [client 68.221.186.136:38614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/edit.php"] [unique_id "amuFAsjqbtjBYzqM1uZQmAAAAB0"]
[Thu Jul 30 12:08:18.509747 2026] [core:notice] [pid 643253:tid 643324] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:18.700832 2026] [security2:error] [pid 643253:tid 643493] [client 20.52.125.110:12194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/kj.php"] [unique_id "amuFAsjqbtjBYzqM1uZQowAAAG0"]
[Thu Jul 30 12:08:18.720837 2026] [core:notice] [pid 643253:tid 643430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:18.727219 2026] [security2:error] [pid 643253:tid 643430] [client 103.215.74.26:59966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFAsjqbtjBYzqM1uZQpAAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:19.006896 2026] [security2:error] [pid 643253:tid 643503] [client 68.221.186.136:37974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/f35.php"] [unique_id "amuFA8jqbtjBYzqM1uZQqQAAAHc"]
[Thu Jul 30 12:08:19.043019 2026] [core:notice] [pid 643253:tid 643302] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:19.377465 2026] [security2:error] [pid 643253:tid 643386] [client 20.52.125.110:12212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-files.php"] [unique_id "amuFA8jqbtjBYzqM1uZQsQAAAAI"]
[Thu Jul 30 12:08:19.987749 2026] [security2:error] [pid 643253:tid 643457] [client 185.191.171.3:40544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/27/bolsonaro-sanciona-com-vetos-criacao-do-programa-pro-leitos/"] [unique_id "amuFA8jqbtjBYzqM1uZQvAAAAEk"]
[Thu Jul 30 12:08:19.987874 2026] [security2:error] [pid 643253:tid 643457] [client 185.191.171.3:40544] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/27/bolsonaro-sanciona-com-vetos-criacao-do-programa-pro-leitos/"] [unique_id "amuFA8jqbtjBYzqM1uZQvAAAAEk"]
[Thu Jul 30 12:08:20.239084 2026] [security2:error] [pid 643253:tid 643471] [client 20.52.125.110:12214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-setup.php"] [unique_id "amuFBMjqbtjBYzqM1uZQxgAAAFc"]
[Thu Jul 30 12:08:20.622183 2026] [security2:error] [pid 643253:tid 643309] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFBMjqbtjBYzqM1uZQzgAAWjY"]
[Thu Jul 30 12:08:20.727156 2026] [security2:error] [pid 643253:tid 643437] [client 68.221.186.136:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/albin.php"] [unique_id "amuFBMjqbtjBYzqM1uZQzwAAADU"]
[Thu Jul 30 12:08:20.987171 2026] [security2:error] [pid 643253:tid 643482] [client 68.221.186.136:39493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dhowcruisedinner.com"] [uri "/f7.php"] [unique_id "amuFBMjqbtjBYzqM1uZQ0QAAAGI"]
[Thu Jul 30 12:08:21.033137 2026] [security2:error] [pid 643253:tid 643413] [client 20.52.125.110:12184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/defaults.php"] [unique_id "amuFBcjqbtjBYzqM1uZQ0gAAAB0"]
[Thu Jul 30 12:08:21.253359 2026] [security2:error] [pid 643253:tid 643509] [client 191.232.199.39:20327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/akcc.php"] [unique_id "amuFBcjqbtjBYzqM1uZQ3AAAAH0"]
[Thu Jul 30 12:08:21.631790 2026] [security2:error] [pid 643253:tid 643330] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFBcjqbtjBYzqM1uZQ3wAAVEs"]
[Thu Jul 30 12:08:21.693110 2026] [security2:error] [pid 643253:tid 643486] [client 20.52.125.110:12230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/gtc.php"] [unique_id "amuFBcjqbtjBYzqM1uZQ5QAAAGY"]
[Thu Jul 30 12:08:22.134475 2026] [security2:error] [pid 643253:tid 643321] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFBsjqbtjBYzqM1uZQ6gAATEI"]
[Thu Jul 30 12:08:22.588233 2026] [security2:error] [pid 643253:tid 643439] [client 191.232.199.39:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/asasx.php"] [unique_id "amuFBsjqbtjBYzqM1uZQ7wAAADc"]
[Thu Jul 30 12:08:22.941780 2026] [security2:error] [pid 643253:tid 643485] [client 20.52.125.110:12182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/import.php"] [unique_id "amuFBsjqbtjBYzqM1uZQ-QAAAGU"]
[Thu Jul 30 12:08:23.341768 2026] [security2:error] [pid 643253:tid 643471] [client 68.221.186.136:40645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/amfsqvgv.php"] [unique_id "amuFB8jqbtjBYzqM1uZRBwAAAFc"]
[Thu Jul 30 12:08:23.693364 2026] [security2:error] [pid 643253:tid 643358] [remote 57.141.0.60:52958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuFB8jqbtjBYzqM1uZRDAAAYmc"]
[Thu Jul 30 12:08:24.077855 2026] [security2:error] [pid 643253:tid 643374] [remote 20.54.134.42:2185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/wp-login.php"] [unique_id "amuFCMjqbtjBYzqM1uZRFgAAHXc"]
[Thu Jul 30 12:08:24.152926 2026] [security2:error] [pid 643253:tid 643416] [client 103.134.1.54:21991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFB8jqbtjBYzqM1uZRFAAAACA"], referer: http://pkf.jo
[Thu Jul 30 12:08:24.172817 2026] [security2:error] [pid 643253:tid 643466] [client 191.232.199.39:59800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/axx.php"] [unique_id "amuFCMjqbtjBYzqM1uZRGgAAAFI"]
[Thu Jul 30 12:08:24.235671 2026] [security2:error] [pid 643253:tid 643468] [client 20.52.125.110:12247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/lufix.php"] [unique_id "amuFCMjqbtjBYzqM1uZRHgAAAFQ"]
[Thu Jul 30 12:08:24.470159 2026] [core:notice] [pid 643253:tid 643428] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:24.477461 2026] [security2:error] [pid 643253:tid 643428] [client 103.215.74.26:21108] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFCMjqbtjBYzqM1uZRJgAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:25.079581 2026] [security2:error] [pid 643253:tid 643467] [client 20.52.125.110:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/Geforce.php"] [unique_id "amuFCcjqbtjBYzqM1uZRRwAAAFM"]
[Thu Jul 30 12:08:25.196503 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:25.203237 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:21122] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFCcjqbtjBYzqM1uZRSwAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:25.371788 2026] [security2:error] [pid 643253:tid 643429] [client 191.232.199.39:20324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/berax.php"] [unique_id "amuFCcjqbtjBYzqM1uZRUgAAAC0"]
[Thu Jul 30 12:08:25.774280 2026] [security2:error] [pid 643253:tid 643289] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuFCcjqbtjBYzqM1uZRVwAATiI"]
[Thu Jul 30 12:08:25.860553 2026] [security2:error] [pid 643253:tid 643491] [client 20.52.125.110:12211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/a4.php"] [unique_id "amuFCcjqbtjBYzqM1uZRXgAAAGs"]
[Thu Jul 30 12:08:25.911380 2026] [core:notice] [pid 643253:tid 643469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:25.917926 2026] [security2:error] [pid 643253:tid 643469] [client 103.215.74.26:21134] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFCcjqbtjBYzqM1uZRYgAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:26.034249 2026] [security2:error] [pid 643253:tid 643397] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFCcjqbtjBYzqM1uZRUwAADRA"]
[Thu Jul 30 12:08:26.147788 2026] [security2:error] [pid 643253:tid 643395] [client 185.189.112.11:45326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuFCsjqbtjBYzqM1uZRZwAAAAs"]
[Thu Jul 30 12:08:26.147885 2026] [security2:error] [pid 643253:tid 643395] [client 185.189.112.11:45326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuFCsjqbtjBYzqM1uZRZwAAAAs"]
[Thu Jul 30 12:08:26.252641 2026] [security2:error] [pid 643253:tid 643433] [client 68.221.186.136:37233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ant.php"] [unique_id "amuFCsjqbtjBYzqM1uZRagAAADE"]
[Thu Jul 30 12:08:26.562891 2026] [security2:error] [pid 643253:tid 643510] [client 20.52.125.110:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/accueil.php"] [unique_id "amuFCsjqbtjBYzqM1uZRdgAAAH4"]
[Thu Jul 30 12:08:26.573595 2026] [security2:error] [pid 643253:tid 643372] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/404.php"] [unique_id "amuFCsjqbtjBYzqM1uZRdwAAXHU"]
[Thu Jul 30 12:08:26.684623 2026] [core:notice] [pid 643253:tid 643458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:26.691331 2026] [security2:error] [pid 643253:tid 643458] [client 103.215.74.26:21144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFCsjqbtjBYzqM1uZRfwAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:26.785413 2026] [security2:error] [pid 643253:tid 643487] [client 191.232.199.39:61058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/build.php"] [unique_id "amuFCsjqbtjBYzqM1uZRggAAAGc"]
[Thu Jul 30 12:08:26.936624 2026] [security2:error] [pid 643253:tid 643294] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-configs.php"] [unique_id "amuFCsjqbtjBYzqM1uZRiwAAZSc"]
[Thu Jul 30 12:08:27.243116 2026] [security2:error] [pid 643253:tid 643297] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/simple.php"] [unique_id "amuFC8jqbtjBYzqM1uZRkQAAbio"]
[Thu Jul 30 12:08:27.249818 2026] [security2:error] [pid 643253:tid 643500] [client 20.52.125.110:12188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/dashboard.php"] [unique_id "amuFC8jqbtjBYzqM1uZRkgAAAHQ"]
[Thu Jul 30 12:08:27.452741 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:27.459836 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:21156] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFC8jqbtjBYzqM1uZRmgAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:27.552435 2026] [security2:error] [pid 643253:tid 643282] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/themes.php"] [unique_id "amuFC8jqbtjBYzqM1uZRmwAAaxs"]
[Thu Jul 30 12:08:27.858766 2026] [security2:error] [pid 643253:tid 643287] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ini.php"] [unique_id "amuFC8jqbtjBYzqM1uZRowAAdyA"]
[Thu Jul 30 12:08:28.125965 2026] [security2:error] [pid 643253:tid 643465] [client 154.66.167.97:45156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFC8jqbtjBYzqM1uZRnwAAAFE"], referer: http://pkf.jo
[Thu Jul 30 12:08:28.166829 2026] [security2:error] [pid 643253:tid 643371] [remote 216.73.216.152:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFDMjqbtjBYzqM1uZRqQAABnQ"]
[Thu Jul 30 12:08:28.169097 2026] [security2:error] [pid 643253:tid 643270] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuFDMjqbtjBYzqM1uZRqgAAYw8"]
[Thu Jul 30 12:08:28.190160 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:28.196776 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:21160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFDMjqbtjBYzqM1uZRqwAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:28.499032 2026] [security2:error] [pid 643253:tid 643311] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/as.php"] [unique_id "amuFDMjqbtjBYzqM1uZRtwAABDg"]
[Thu Jul 30 12:08:28.843002 2026] [security2:error] [pid 643253:tid 643279] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin/upload/css.php"] [unique_id "amuFDMjqbtjBYzqM1uZRvAAAKRg"]
[Thu Jul 30 12:08:28.939646 2026] [core:notice] [pid 643253:tid 643424] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:28.946228 2026] [security2:error] [pid 643253:tid 643424] [client 103.215.74.26:21164] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFDMjqbtjBYzqM1uZRwwAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:28.980151 2026] [security2:error] [pid 643253:tid 643451] [client 68.221.186.136:31632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/appreciators.php"] [unique_id "amuFDMjqbtjBYzqM1uZRxAAAAEM"]
[Thu Jul 30 12:08:29.103470 2026] [security2:error] [pid 643253:tid 643432] [client 102.64.161.35:15676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFDMjqbtjBYzqM1uZRuwAAADA"], referer: http://pkf.jo
[Thu Jul 30 12:08:29.141791 2026] [security2:error] [pid 643253:tid 643319] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/afnew.php"] [unique_id "amuFDcjqbtjBYzqM1uZRyAAAUEA"]
[Thu Jul 30 12:08:29.222410 2026] [security2:error] [pid 643253:tid 643408] [client 191.232.199.39:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/buy.php"] [unique_id "amuFDcjqbtjBYzqM1uZRyQAAABg"]
[Thu Jul 30 12:08:29.246012 2026] [security2:error] [pid 643253:tid 643490] [client 20.52.125.110:12186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/radio.php"] [unique_id "amuFDcjqbtjBYzqM1uZRygAAAGo"]
[Thu Jul 30 12:08:29.453724 2026] [security2:error] [pid 643253:tid 643324] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/lufix.php"] [unique_id "amuFDcjqbtjBYzqM1uZR0AAANEU"]
[Thu Jul 30 12:08:29.668321 2026] [core:notice] [pid 643253:tid 643384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:29.674626 2026] [security2:error] [pid 643253:tid 643384] [client 103.215.74.26:21166] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFDcjqbtjBYzqM1uZR1AAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:29.820467 2026] [security2:error] [pid 643253:tid 643322] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/media.php"] [unique_id "amuFDcjqbtjBYzqM1uZR1QAATUM"]
[Thu Jul 30 12:08:29.947364 2026] [security2:error] [pid 643253:tid 643426] [client 68.221.186.136:31642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/archive.php"] [unique_id "amuFDcjqbtjBYzqM1uZR1wAAACo"]
[Thu Jul 30 12:08:30.126832 2026] [security2:error] [pid 643253:tid 643337] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/simple.php"] [unique_id "amuFDsjqbtjBYzqM1uZR3gAAIFI"]
[Thu Jul 30 12:08:30.276434 2026] [core:notice] [pid 643253:tid 643395] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:30.404667 2026] [core:notice] [pid 643253:tid 643465] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:30.410794 2026] [security2:error] [pid 643253:tid 643465] [client 103.215.74.26:21170] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFDsjqbtjBYzqM1uZR4gAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:30.436610 2026] [security2:error] [pid 643253:tid 643300] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/contact.php"] [unique_id "amuFDsjqbtjBYzqM1uZR4wAADi0"]
[Thu Jul 30 12:08:30.532764 2026] [security2:error] [pid 643253:tid 643417] [client 191.232.199.39:61056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/checkbox.php"] [unique_id "amuFDsjqbtjBYzqM1uZR5wAAACE"]
[Thu Jul 30 12:08:30.656625 2026] [security2:error] [pid 643253:tid 643419] [client 20.52.125.110:12187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wpsml-sys.php"] [unique_id "amuFDsjqbtjBYzqM1uZR7gAAACM"]
[Thu Jul 30 12:08:30.747385 2026] [security2:error] [pid 643253:tid 643276] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/byp.php"] [unique_id "amuFDsjqbtjBYzqM1uZR7wAAbxU"]
[Thu Jul 30 12:08:30.910707 2026] [security2:error] [pid 643253:tid 643385] [client 185.200.117.131:56146] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFDsjqbtjBYzqM1uZR8AAAAAE"]
[Thu Jul 30 12:08:30.910811 2026] [security2:error] [pid 643253:tid 643385] [client 185.200.117.131:56146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFDsjqbtjBYzqM1uZR8AAAAAE"]
[Thu Jul 30 12:08:31.050103 2026] [security2:error] [pid 643253:tid 643335] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/upload.php"] [unique_id "amuFD8jqbtjBYzqM1uZR9QAAWFA"]
[Thu Jul 30 12:08:31.150427 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:31.156523 2026] [security2:error] [pid 643253:tid 643441] [client 103.215.74.26:21176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFD8jqbtjBYzqM1uZR-gAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:31.199412 2026] [security2:error] [pid 643253:tid 643428] [client 68.221.186.136:37195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/as.php"] [unique_id "amuFD8jqbtjBYzqM1uZR-wAAACw"]
[Thu Jul 30 12:08:31.349716 2026] [security2:error] [pid 643253:tid 643341] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "amuFD8jqbtjBYzqM1uZSAwAALlY"]
[Thu Jul 30 12:08:31.667454 2026] [security2:error] [pid 643253:tid 643361] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cong.php"] [unique_id "amuFD8jqbtjBYzqM1uZSDAAAOGo"]
[Thu Jul 30 12:08:31.918720 2026] [core:notice] [pid 643253:tid 643500] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:31.925012 2026] [security2:error] [pid 643253:tid 643500] [client 103.215.74.26:21188] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFD8jqbtjBYzqM1uZSDgAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:31.976955 2026] [security2:error] [pid 643253:tid 643321] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/about/function.php"] [unique_id "amuFD8jqbtjBYzqM1uZSDwAAW0I"]
[Thu Jul 30 12:08:32.325911 2026] [security2:error] [pid 643253:tid 643362] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/filemanager/dialog.php"] [unique_id "amuFEMjqbtjBYzqM1uZSGAAAAGs"]
[Thu Jul 30 12:08:32.343619 2026] [security2:error] [pid 643253:tid 643438] [client 191.232.199.39:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/cong.php"] [unique_id "amuFEMjqbtjBYzqM1uZSGQAAADY"]
[Thu Jul 30 12:08:32.634945 2026] [security2:error] [pid 643253:tid 643460] [client 68.221.186.136:40703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/atomlib.php"] [unique_id "amuFEMjqbtjBYzqM1uZSHgAAAEw"]
[Thu Jul 30 12:08:32.661301 2026] [security2:error] [pid 643253:tid 643368] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/bak.php"] [unique_id "amuFEMjqbtjBYzqM1uZSIQAAOnE"]
[Thu Jul 30 12:08:32.666413 2026] [core:notice] [pid 643253:tid 643461] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:32.672464 2026] [security2:error] [pid 643253:tid 643461] [client 103.215.74.26:21196] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFEMjqbtjBYzqM1uZSIwAAAE0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:33.007725 2026] [security2:error] [pid 643253:tid 643329] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-info.php"] [unique_id "amuFEcjqbtjBYzqM1uZSJQAAZko"]
[Thu Jul 30 12:08:33.355200 2026] [security2:error] [pid 643253:tid 643374] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/files/index.php"] [unique_id "amuFEcjqbtjBYzqM1uZSMgAAcHc"]
[Thu Jul 30 12:08:33.402403 2026] [core:notice] [pid 643253:tid 643404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:33.408122 2026] [security2:error] [pid 643253:tid 643404] [client 103.215.74.26:58470] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFEcjqbtjBYzqM1uZSNQAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:33.659358 2026] [security2:error] [pid 643253:tid 643340] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/css.php"] [unique_id "amuFEcjqbtjBYzqM1uZSPgAAZVU"]
[Thu Jul 30 12:08:33.695919 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:33.799783 2026] [security2:error] [pid 643253:tid 643444] [client 68.221.186.136:36410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/autoload_classmap.php"] [unique_id "amuFEcjqbtjBYzqM1uZSRQAAADw"]
[Thu Jul 30 12:08:34.023659 2026] [security2:error] [pid 643253:tid 643348] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/css/index.php"] [unique_id "amuFEsjqbtjBYzqM1uZSSAAAGF0"]
[Thu Jul 30 12:08:34.139216 2026] [core:notice] [pid 643253:tid 643463] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.145262 2026] [security2:error] [pid 643253:tid 643463] [client 103.215.74.26:58472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFEsjqbtjBYzqM1uZSSgAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:34.340644 2026] [security2:error] [pid 643253:tid 643268] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/bak.php"] [unique_id "amuFEsjqbtjBYzqM1uZSUQAANA0"]
[Thu Jul 30 12:08:34.344519 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.344519 2026] [core:notice] [pid 643253:tid 643432] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.346629 2026] [core:notice] [pid 643253:tid 643429] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.648034 2026] [security2:error] [pid 643253:tid 643375] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfa-rex.php7"] [unique_id "amuFEsjqbtjBYzqM1uZSVwAAdXg"]
[Thu Jul 30 12:08:34.872542 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:34.879170 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:58478] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFEsjqbtjBYzqM1uZSYAAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:34.921970 2026] [security2:error] [pid 643253:tid 643453] [client 20.52.125.110:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/02.php"] [unique_id "amuFEsjqbtjBYzqM1uZSZAAAAEU"]
[Thu Jul 30 12:08:35.218007 2026] [security2:error] [pid 643253:tid 643384] [client 191.232.199.39:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/file4.php"] [unique_id "amuFE8jqbtjBYzqM1uZSaQAAAAA"]
[Thu Jul 30 12:08:35.223686 2026] [security2:error] [pid 643253:tid 643277] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/wp-login.php"] [unique_id "amuFEsjqbtjBYzqM1uZSZQAAQhY"]
[Thu Jul 30 12:08:35.582788 2026] [security2:error] [pid 643253:tid 643263] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/cloud.php"] [unique_id "amuFE8jqbtjBYzqM1uZSdAAAYwg"]
[Thu Jul 30 12:08:35.629098 2026] [core:notice] [pid 643253:tid 643511] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:35.635396 2026] [security2:error] [pid 643253:tid 643511] [client 103.215.74.26:58482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFE8jqbtjBYzqM1uZSdQAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:35.669516 2026] [security2:error] [pid 643253:tid 643473] [client 68.221.186.136:23437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/bb.php"] [unique_id "amuFE8jqbtjBYzqM1uZSdgAAAFk"]
[Thu Jul 30 12:08:35.803995 2026] [security2:error] [pid 643253:tid 643477] [client 20.52.125.110:12178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/infos.php"] [unique_id "amuFE8jqbtjBYzqM1uZSewAAAF0"]
[Thu Jul 30 12:08:35.911531 2026] [security2:error] [pid 643253:tid 643379] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/index.php"] [unique_id "amuFE8jqbtjBYzqM1uZSfwAAHnw"]
[Thu Jul 30 12:08:36.002228 2026] [security2:error] [pid 643253:tid 643428] [client 157.15.46.53:46360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFE8jqbtjBYzqM1uZSdwAAACw"], referer: http://pkf.jo
[Thu Jul 30 12:08:36.223099 2026] [security2:error] [pid 643253:tid 643261] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/readme.php"] [unique_id "amuFFMjqbtjBYzqM1uZSggAAdAY"]
[Thu Jul 30 12:08:36.374758 2026] [core:notice] [pid 643253:tid 643391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:36.381172 2026] [security2:error] [pid 643253:tid 643391] [client 103.215.74.26:58494] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFFMjqbtjBYzqM1uZShgAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:36.437165 2026] [security2:error] [pid 643253:tid 643459] [client 20.52.125.110:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/updates.php"] [unique_id "amuFFMjqbtjBYzqM1uZShwAAAEs"]
[Thu Jul 30 12:08:36.548305 2026] [security2:error] [pid 643253:tid 643264] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/about.php"] [unique_id "amuFFMjqbtjBYzqM1uZSiwAAdwk"]
[Thu Jul 30 12:08:37.109946 2026] [core:notice] [pid 643253:tid 643387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:37.116268 2026] [security2:error] [pid 643253:tid 643387] [client 103.215.74.26:58498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFFcjqbtjBYzqM1uZSlAAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:37.574329 2026] [security2:error] [pid 643253:tid 643478] [client 68.221.186.136:36413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/bnm.php"] [unique_id "amuFFcjqbtjBYzqM1uZSowAAAF4"]
[Thu Jul 30 12:08:37.674835 2026] [security2:error] [pid 643253:tid 643487] [client 45.4.230.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuFFcjqbtjBYzqM1uZSogAAAGc"]
[Thu Jul 30 12:08:37.678182 2026] [security2:error] [pid 643253:tid 643316] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/404.php"] [unique_id "amuFFcjqbtjBYzqM1uZSpgAAXT0"]
[Thu Jul 30 12:08:37.753001 2026] [security2:error] [pid 643253:tid 643467] [client 103.141.175.162:59016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFFcjqbtjBYzqM1uZSnwAAAFM"], referer: http://pkf.jo
[Thu Jul 30 12:08:37.837234 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:37.843686 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:58504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFFcjqbtjBYzqM1uZSqQAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:38.109438 2026] [security2:error] [pid 643253:tid 643272] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/index.php"] [unique_id "amuFFsjqbtjBYzqM1uZStAAAOBE"]
[Thu Jul 30 12:08:38.150726 2026] [security2:error] [pid 643253:tid 643457] [client 20.203.156.12:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/wp-login.php"] [unique_id "amuFFcjqbtjBYzqM1uZSpAAAAEk"]
[Thu Jul 30 12:08:38.150859 2026] [security2:error] [pid 643253:tid 643457] [client 20.203.156.12:50012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/wp-login.php"] [unique_id "amuFFcjqbtjBYzqM1uZSpAAAAEk"]
[Thu Jul 30 12:08:38.231716 2026] [security2:error] [pid 643253:tid 643446] [client 191.232.199.39:59806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/flower.php"] [unique_id "amuFFsjqbtjBYzqM1uZSuQAAAD4"]
[Thu Jul 30 12:08:38.416246 2026] [security2:error] [pid 643253:tid 643285] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes.php"] [unique_id "amuFFsjqbtjBYzqM1uZSvAAALR4"]
[Thu Jul 30 12:08:38.571629 2026] [core:notice] [pid 643253:tid 643490] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:38.577849 2026] [security2:error] [pid 643253:tid 643490] [client 103.215.74.26:58518] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFFsjqbtjBYzqM1uZSwwAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:38.639846 2026] [security2:error] [pid 643253:tid 643461] [client 43.130.9.111:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.9.130.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/rreportf.php"] [unique_id "amuFFsjqbtjBYzqM1uZSxAAAAE0"]
[Thu Jul 30 12:08:38.763505 2026] [security2:error] [pid 643253:tid 643287] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/dropdown.php"] [unique_id "amuFFsjqbtjBYzqM1uZSxQAAVSA"]
[Thu Jul 30 12:08:39.086012 2026] [security2:error] [pid 643253:tid 643270] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/404.php"] [unique_id "amuFF8jqbtjBYzqM1uZSzgAAAw8"]
[Thu Jul 30 12:08:39.316077 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:39.322326 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:58520] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFF8jqbtjBYzqM1uZS0gAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:39.438380 2026] [security2:error] [pid 643253:tid 643382] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuFF8jqbtjBYzqM1uZS1AAAZX8"]
[Thu Jul 30 12:08:39.512541 2026] [security2:error] [pid 643253:tid 643392] [client 191.232.199.39:61081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/form.php"] [unique_id "amuFF8jqbtjBYzqM1uZS1gAAAAg"]
[Thu Jul 30 12:08:39.786151 2026] [security2:error] [pid 643253:tid 643260] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/file.php"] [unique_id "amuFF8jqbtjBYzqM1uZS3AAAFQU"]
[Thu Jul 30 12:08:39.909034 2026] [security2:error] [pid 643253:tid 643468] [client 68.221.186.136:37193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/bootstrap.php"] [unique_id "amuFF8jqbtjBYzqM1uZS3gAAAFQ"]
[Thu Jul 30 12:08:40.052489 2026] [core:notice] [pid 643253:tid 643455] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:40.058269 2026] [security2:error] [pid 643253:tid 643455] [client 103.215.74.26:58526] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFGMjqbtjBYzqM1uZS5QAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:40.096217 2026] [security2:error] [pid 643253:tid 643291] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/index.php"] [unique_id "amuFGMjqbtjBYzqM1uZS5gAASSQ"]
[Thu Jul 30 12:08:40.420695 2026] [security2:error] [pid 643253:tid 643304] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/cloud.php"] [unique_id "amuFGMjqbtjBYzqM1uZS6wAAEjE"]
[Thu Jul 30 12:08:40.527117 2026] [security2:error] [pid 643253:tid 643506] [client 20.52.125.110:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/user.php"] [unique_id "amuFGMjqbtjBYzqM1uZS7AAAAHo"]
[Thu Jul 30 12:08:40.745422 2026] [security2:error] [pid 643253:tid 643322] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amuFGMjqbtjBYzqM1uZS8wAAVUM"]
[Thu Jul 30 12:08:40.784777 2026] [core:notice] [pid 643253:tid 643474] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:40.791119 2026] [security2:error] [pid 643253:tid 643474] [client 103.215.74.26:58534] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFGMjqbtjBYzqM1uZS9AAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:41.063797 2026] [security2:error] [pid 643253:tid 643315] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/404.php"] [unique_id "amuFGcjqbtjBYzqM1uZS9QAADDw"]
[Thu Jul 30 12:08:41.191851 2026] [security2:error] [pid 643253:tid 643493] [client 191.232.199.39:59815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/gecko.php"] [unique_id "amuFGcjqbtjBYzqM1uZS_AAAAG0"]
[Thu Jul 30 12:08:41.399148 2026] [security2:error] [pid 643253:tid 643302] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/function.php"] [unique_id "amuFGcjqbtjBYzqM1uZS_gAAcC8"]
[Thu Jul 30 12:08:41.513745 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:41.520171 2026] [security2:error] [pid 643253:tid 643486] [client 103.215.74.26:58550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFGcjqbtjBYzqM1uZS_wAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:41.648618 2026] [security2:error] [pid 643253:tid 643436] [client 68.221.186.136:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/buy.php"] [unique_id "amuFGcjqbtjBYzqM1uZTAQAAADQ"]
[Thu Jul 30 12:08:41.717695 2026] [security2:error] [pid 643253:tid 643276] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/file.php"] [unique_id "amuFGcjqbtjBYzqM1uZTBQAAKBU"]
[Thu Jul 30 12:08:42.023516 2026] [security2:error] [pid 643253:tid 643318] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/autoload_classmap.php"] [unique_id "amuFGsjqbtjBYzqM1uZTDgAAOz8"]
[Thu Jul 30 12:08:42.231602 2026] [security2:error] [pid 643253:tid 643451] [client 20.52.125.110:12200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/admin-ajax.php"] [unique_id "amuFGsjqbtjBYzqM1uZTDwAAAEM"]
[Thu Jul 30 12:08:42.254097 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:42.263533 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:58558] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFGsjqbtjBYzqM1uZTFQAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:42.338477 2026] [security2:error] [pid 643253:tid 643317] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/themes.php"] [unique_id "amuFGsjqbtjBYzqM1uZTFwAAVz4"]
[Thu Jul 30 12:08:42.425932 2026] [security2:error] [pid 643253:tid 643444] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFGcjqbtjBYzqM1uZTDAAAADw"]
[Thu Jul 30 12:08:42.666569 2026] [security2:error] [pid 643253:tid 643342] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/wp-login.php"] [unique_id "amuFGsjqbtjBYzqM1uZTGgAAS1c"]
[Thu Jul 30 12:08:42.802214 2026] [security2:error] [pid 643253:tid 643391] [client 46.29.29.113:57362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuFGsjqbtjBYzqM1uZTGQAAAAc"], referer: http://pkf.jo
[Thu Jul 30 12:08:42.993665 2026] [security2:error] [pid 643253:tid 643320] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/file.php"] [unique_id "amuFGsjqbtjBYzqM1uZTIwAAOkE"]
[Thu Jul 30 12:08:43.006704 2026] [core:notice] [pid 643253:tid 643482] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:43.013090 2026] [security2:error] [pid 643253:tid 643482] [client 103.215.74.26:58560] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFG8jqbtjBYzqM1uZTJAAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:43.263905 2026] [security2:error] [pid 643253:tid 643400] [client 68.221.186.136:23458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/chosen.php"] [unique_id "amuFG8jqbtjBYzqM1uZTKQAAABA"]
[Thu Jul 30 12:08:43.350890 2026] [security2:error] [pid 643253:tid 643332] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-trackback.php"] [unique_id "amuFG8jqbtjBYzqM1uZTLwAAFE0"]
[Thu Jul 30 12:08:43.384499 2026] [security2:error] [pid 643253:tid 643509] [client 20.52.125.110:12227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/alfa.php"] [unique_id "amuFG8jqbtjBYzqM1uZTMAAAAH0"]
[Thu Jul 30 12:08:43.523432 2026] [security2:error] [pid 643253:tid 643330] [remote 40.77.167.67:5122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/view/7021"] [unique_id "amuFG8jqbtjBYzqM1uZTKgAAfks"]
[Thu Jul 30 12:08:43.659764 2026] [security2:error] [pid 643253:tid 643362] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "amuFG8jqbtjBYzqM1uZTMgAAfGs"]
[Thu Jul 30 12:08:43.738497 2026] [core:notice] [pid 643253:tid 643479] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:43.744716 2026] [security2:error] [pid 643253:tid 643479] [client 103.215.74.26:50032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFG8jqbtjBYzqM1uZTMwAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:43.980672 2026] [security2:error] [pid 643253:tid 643329] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/index.php"] [unique_id "amuFG8jqbtjBYzqM1uZTPgAASEo"]
[Thu Jul 30 12:08:44.285366 2026] [security2:error] [pid 643253:tid 643347] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/themes.php"] [unique_id "amuFHMjqbtjBYzqM1uZTQAAAGlw"]
[Thu Jul 30 12:08:44.494827 2026] [core:notice] [pid 643253:tid 643498] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.501040 2026] [security2:error] [pid 643253:tid 643498] [client 103.215.74.26:50034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFHMjqbtjBYzqM1uZTSAAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:44.586482 2026] [core:notice] [pid 643253:tid 643325] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.596530 2026] [core:notice] [pid 643253:tid 643374] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.598441 2026] [security2:error] [pid 643253:tid 643356] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/cloud.php"] [unique_id "amuFHMjqbtjBYzqM1uZTSwAAI2U"]
[Thu Jul 30 12:08:44.616130 2026] [security2:error] [pid 643253:tid 643424] [client 68.221.186.136:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/class-wp-image.php"] [unique_id "amuFHMjqbtjBYzqM1uZTTAAAACg"]
[Thu Jul 30 12:08:44.818848 2026] [security2:error] [pid 643253:tid 643340] [remote 57.141.0.9:39870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuFHMjqbtjBYzqM1uZTUQAAdlU"]
[Thu Jul 30 12:08:44.859186 2026] [core:notice] [pid 643253:tid 643369] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.871000 2026] [core:notice] [pid 643253:tid 643345] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:44.902395 2026] [security2:error] [pid 643253:tid 643366] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/wp-load.php"] [unique_id "amuFHMjqbtjBYzqM1uZTVwAAG28"]
[Thu Jul 30 12:08:45.209485 2026] [security2:error] [pid 643253:tid 643348] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/file.php"] [unique_id "amuFHcjqbtjBYzqM1uZTWQAAQl0"]
[Thu Jul 30 12:08:45.522104 2026] [security2:error] [pid 643253:tid 643268] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuFHcjqbtjBYzqM1uZTZgAAeQ0"]
[Thu Jul 30 12:08:45.574964 2026] [security2:error] [pid 643253:tid 643397] [client 68.221.186.136:37207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/classsmtps.php"] [unique_id "amuFHcjqbtjBYzqM1uZTZwAAAA0"]
[Thu Jul 30 12:08:45.606487 2026] [core:notice] [pid 643253:tid 643386] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:45.837452 2026] [security2:error] [pid 643253:tid 643375] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/index.php"] [unique_id "amuFHcjqbtjBYzqM1uZTbAAAZXg"]
[Thu Jul 30 12:08:46.166151 2026] [security2:error] [pid 643253:tid 643277] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuFHsjqbtjBYzqM1uZTcwAAfxY"]
[Thu Jul 30 12:08:46.507881 2026] [security2:error] [pid 643253:tid 643259] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/404.php"] [unique_id "amuFHsjqbtjBYzqM1uZTgAAASQQ"]
[Thu Jul 30 12:08:46.640136 2026] [security2:error] [pid 643253:tid 643406] [client 68.221.186.136:46059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/classwithtostring.php"] [unique_id "amuFHsjqbtjBYzqM1uZTgQAAABY"]
[Thu Jul 30 12:08:46.818465 2026] [security2:error] [pid 643253:tid 643381] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "amuFHsjqbtjBYzqM1uZTgwAAI34"]
[Thu Jul 30 12:08:46.968666 2026] [security2:error] [pid 643253:tid 643497] [client 20.52.125.110:12253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/hehe.php"] [unique_id "amuFHsjqbtjBYzqM1uZTigAAAHE"]
[Thu Jul 30 12:08:47.168911 2026] [security2:error] [pid 643253:tid 643360] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/radio.php"] [unique_id "amuFH8jqbtjBYzqM1uZTiwAANWk"]
[Thu Jul 30 12:08:47.223655 2026] [security2:error] [pid 643253:tid 643499] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFHcjqbtjBYzqM1uZTaQAAcxw"]
[Thu Jul 30 12:08:47.557857 2026] [security2:error] [pid 643253:tid 643334] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuFH8jqbtjBYzqM1uZTkgAAA08"]
[Thu Jul 30 12:08:47.608500 2026] [security2:error] [pid 643253:tid 643449] [client 191.232.199.39:59820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/kyami.php"] [unique_id "amuFH8jqbtjBYzqM1uZTkwAAAEE"]
[Thu Jul 30 12:08:47.711311 2026] [core:notice] [pid 643253:tid 643416] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:47.753208 2026] [security2:error] [pid 643253:tid 643438] [client 20.52.125.110:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/rk2.php"] [unique_id "amuFH8jqbtjBYzqM1uZTlgAAADY"]
[Thu Jul 30 12:08:47.909062 2026] [security2:error] [pid 643253:tid 643266] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/admin.php"] [unique_id "amuFH8jqbtjBYzqM1uZTmAAAFAs"]
[Thu Jul 30 12:08:48.218945 2026] [security2:error] [pid 643253:tid 643264] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/system_log.php"] [unique_id "amuFIMjqbtjBYzqM1uZToQAAeQk"]
[Thu Jul 30 12:08:48.538641 2026] [security2:error] [pid 643253:tid 643271] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/wp-activate.php"] [unique_id "amuFIMjqbtjBYzqM1uZTqAAAHxA"]
[Thu Jul 30 12:08:48.759730 2026] [security2:error] [pid 643253:tid 643397] [client 20.52.125.110:12180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/setup-config.php"] [unique_id "amuFIMjqbtjBYzqM1uZTqQAAAA0"]
[Thu Jul 30 12:08:48.854265 2026] [security2:error] [pid 643253:tid 643274] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/makeasmtp.php"] [unique_id "amuFIMjqbtjBYzqM1uZTqwAAGBM"]
[Thu Jul 30 12:08:49.194910 2026] [security2:error] [pid 643253:tid 643267] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuFIcjqbtjBYzqM1uZTtQAAFgw"]
[Thu Jul 30 12:08:49.505919 2026] [security2:error] [pid 643253:tid 643255] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/link.php"] [unique_id "amuFIcjqbtjBYzqM1uZTtgAADwA"]
[Thu Jul 30 12:08:49.508329 2026] [security2:error] [pid 643253:tid 643498] [client 68.221.186.136:38375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/config.php"] [unique_id "amuFIcjqbtjBYzqM1uZTtwAAAHI"]
[Thu Jul 30 12:08:49.550035 2026] [security2:error] [pid 643253:tid 643433] [client 191.232.199.39:59794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/manager.php"] [unique_id "amuFIcjqbtjBYzqM1uZTuwAAADE"]
[Thu Jul 30 12:08:49.824046 2026] [security2:error] [pid 643253:tid 643294] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuFIcjqbtjBYzqM1uZTvwAAdyc"]
[Thu Jul 30 12:08:49.890117 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:50.172782 2026] [security2:error] [pid 643253:tid 643297] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/themes.php"] [unique_id "amuFIsjqbtjBYzqM1uZTyQAAAyo"]
[Thu Jul 30 12:08:50.256576 2026] [core:notice] [pid 643253:tid 643442] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:50.263435 2026] [security2:error] [pid 643253:tid 643442] [client 103.215.74.26:50040] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFIsjqbtjBYzqM1uZT0gAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:50.475772 2026] [security2:error] [pid 643253:tid 643308] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuFIsjqbtjBYzqM1uZT0wAAeDU"]
[Thu Jul 30 12:08:50.838399 2026] [security2:error] [pid 643253:tid 643311] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuFIsjqbtjBYzqM1uZT2wAACDg"]
[Thu Jul 30 12:08:50.992784 2026] [core:notice] [pid 643253:tid 643489] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:50.999482 2026] [security2:error] [pid 643253:tid 643489] [client 103.215.74.26:50042] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFIsjqbtjBYzqM1uZT3AAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:51.061117 2026] [security2:error] [pid 643253:tid 643509] [client 85.208.96.205:59834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/21/apostas-de-guarabira-e-joao-pessoa-acertam-quina-da-mega-sena-e-cada-uma-leva-mais-de-r-76-mil/"] [unique_id "amuFI8jqbtjBYzqM1uZT3QAAAH0"]
[Thu Jul 30 12:08:51.061246 2026] [security2:error] [pid 643253:tid 643509] [client 85.208.96.205:59834] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/21/apostas-de-guarabira-e-joao-pessoa-acertam-quina-da-mega-sena-e-cada-uma-leva-mais-de-r-76-mil/"] [unique_id "amuFI8jqbtjBYzqM1uZT3QAAAH0"]
[Thu Jul 30 12:08:51.085646 2026] [security2:error] [pid 643253:tid 643474] [client 20.52.125.110:12183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/a7.php"] [unique_id "amuFI8jqbtjBYzqM1uZT3gAAAFo"]
[Thu Jul 30 12:08:51.184222 2026] [security2:error] [pid 643253:tid 643260] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/function.php"] [unique_id "amuFI8jqbtjBYzqM1uZT4gAABQU"]
[Thu Jul 30 12:08:51.290067 2026] [security2:error] [pid 643253:tid 643401] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFIsjqbtjBYzqM1uZT2AAAEX8"]
[Thu Jul 30 12:08:51.504261 2026] [security2:error] [pid 643253:tid 643279] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/wp-login.php"] [unique_id "amuFI8jqbtjBYzqM1uZT5gAAWxg"]
[Thu Jul 30 12:08:51.723179 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:51.729233 2026] [security2:error] [pid 643253:tid 643456] [client 103.215.74.26:50058] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFI8jqbtjBYzqM1uZT6gAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:51.812601 2026] [security2:error] [pid 643253:tid 643291] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/log.php"] [unique_id "amuFI8jqbtjBYzqM1uZT7gAAEyQ"]
[Thu Jul 30 12:08:51.825396 2026] [security2:error] [pid 643253:tid 643468] [client 20.52.125.110:12558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/f7.php"] [unique_id "amuFI8jqbtjBYzqM1uZT7wAAAFQ"]
[Thu Jul 30 12:08:52.080068 2026] [security2:error] [pid 643253:tid 643470] [client 191.232.199.39:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/mari.php"] [unique_id "amuFJMjqbtjBYzqM1uZT8AAAAFY"]
[Thu Jul 30 12:08:52.118325 2026] [security2:error] [pid 643253:tid 643319] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "amuFJMjqbtjBYzqM1uZT8QAAckA"]
[Thu Jul 30 12:08:52.408892 2026] [security2:error] [pid 643253:tid 643462] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFJMjqbtjBYzqM1uZT-QAATkM"]
[Thu Jul 30 12:08:52.427340 2026] [security2:error] [pid 643253:tid 643310] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/themes.php"] [unique_id "amuFJMjqbtjBYzqM1uZT-gAAczc"]
[Thu Jul 30 12:08:52.460725 2026] [core:notice] [pid 643253:tid 643411] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:52.466989 2026] [security2:error] [pid 643253:tid 643411] [client 103.215.74.26:50074] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJMjqbtjBYzqM1uZT-wAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:52.764559 2026] [security2:error] [pid 643253:tid 643306] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/radio.php"] [unique_id "amuFJMjqbtjBYzqM1uZUBQAAdDM"]
[Thu Jul 30 12:08:53.082534 2026] [security2:error] [pid 643253:tid 643336] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-mail.php"] [unique_id "amuFJcjqbtjBYzqM1uZUCgAAUlE"]
[Thu Jul 30 12:08:53.158813 2026] [security2:error] [pid 643253:tid 643339] [remote 57.141.0.39:30608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3390535976/feed/rss2/"] [unique_id "amuFJcjqbtjBYzqM1uZUCwAAAVQ"]
[Thu Jul 30 12:08:53.212659 2026] [core:notice] [pid 643253:tid 643486] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:53.218923 2026] [security2:error] [pid 643253:tid 643486] [client 103.215.74.26:51716] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJcjqbtjBYzqM1uZUDQAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:53.436918 2026] [security2:error] [pid 643253:tid 643317] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuFJcjqbtjBYzqM1uZUFQAAaD4"]
[Thu Jul 30 12:08:53.751232 2026] [security2:error] [pid 643253:tid 643506] [client 20.52.125.110:12544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/nw.php"] [unique_id "amuFJcjqbtjBYzqM1uZUGAAAAHo"]
[Thu Jul 30 12:08:53.756104 2026] [security2:error] [pid 643253:tid 643342] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/admin.php"] [unique_id "amuFJcjqbtjBYzqM1uZUGQAADVc"]
[Thu Jul 30 12:08:53.818489 2026] [security2:error] [pid 643253:tid 643483] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFJcjqbtjBYzqM1uZUDgAAYz8"]
[Thu Jul 30 12:08:53.967537 2026] [core:notice] [pid 643253:tid 643413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:53.973891 2026] [security2:error] [pid 643253:tid 643413] [client 103.215.74.26:51726] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJcjqbtjBYzqM1uZUHwAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:53.976569 2026] [security2:error] [pid 643253:tid 643301] [remote 57.141.0.2:22316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuFJcjqbtjBYzqM1uZUIAAAby4"]
[Thu Jul 30 12:08:54.072239 2026] [security2:error] [pid 643253:tid 643361] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuFJsjqbtjBYzqM1uZUJQAAJmo"]
[Thu Jul 30 12:08:54.425814 2026] [security2:error] [pid 643253:tid 643321] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-links-opml.php"] [unique_id "amuFJsjqbtjBYzqM1uZULAAAD0I"]
[Thu Jul 30 12:08:54.463953 2026] [security2:error] [pid 643253:tid 643446] [client 20.52.125.110:12165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/ova.php"] [unique_id "amuFJsjqbtjBYzqM1uZULgAAAD4"]
[Thu Jul 30 12:08:54.538949 2026] [security2:error] [pid 643253:tid 643437] [client 68.221.186.136:34832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/core.php"] [unique_id "amuFJsjqbtjBYzqM1uZUMAAAADU"]
[Thu Jul 30 12:08:54.727367 2026] [core:notice] [pid 643253:tid 643501] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:54.733680 2026] [security2:error] [pid 643253:tid 643501] [client 103.215.74.26:51734] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJsjqbtjBYzqM1uZUMwAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:54.795858 2026] [security2:error] [pid 643253:tid 643354] [remote 57.141.0.32:49300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3390535976/feed/rss2/"] [unique_id "amuFJsjqbtjBYzqM1uZUNwAAcWM"]
[Thu Jul 30 12:08:54.801121 2026] [security2:error] [pid 643253:tid 643331] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/radio.php"] [unique_id "amuFJsjqbtjBYzqM1uZUOAAATkw"]
[Thu Jul 30 12:08:54.830824 2026] [security2:error] [pid 643253:tid 643463] [client 191.232.199.39:61103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/nc4.php"] [unique_id "amuFJsjqbtjBYzqM1uZUOgAAAE8"]
[Thu Jul 30 12:08:55.151555 2026] [security2:error] [pid 643253:tid 643368] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/file.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUQAAAbXE"]
[Thu Jul 30 12:08:55.455481 2026] [core:notice] [pid 643253:tid 643409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:55.461810 2026] [security2:error] [pid 643253:tid 643409] [client 103.215.74.26:51740] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFJ8jqbtjBYzqM1uZURwAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:55.470823 2026] [security2:error] [pid 643253:tid 643343] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/upgrade/function.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUSAAAeVg"]
[Thu Jul 30 12:08:55.590836 2026] [security2:error] [pid 643253:tid 643418] [client 68.221.186.136:23205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/css.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUSgAAACI"]
[Thu Jul 30 12:08:55.717248 2026] [security2:error] [pid 643253:tid 643385] [client 20.52.125.110:12175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/robots.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUSwAAAAE"]
[Thu Jul 30 12:08:55.773499 2026] [security2:error] [pid 643253:tid 643358] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/user/themes.php"] [unique_id "amuFJ8jqbtjBYzqM1uZUTAAAX2c"]
[Thu Jul 30 12:08:56.100826 2026] [security2:error] [pid 643253:tid 643356] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/radio.php"] [unique_id "amuFKMjqbtjBYzqM1uZUWwAAL2U"]
[Thu Jul 30 12:08:56.202164 2026] [core:notice] [pid 643253:tid 643434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:56.208529 2026] [security2:error] [pid 643253:tid 643434] [client 103.215.74.26:51752] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFKMjqbtjBYzqM1uZUXAAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:56.216647 2026] [security2:error] [pid 643253:tid 643483] [client 68.221.186.136:23210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/database.php"] [unique_id "amuFKMjqbtjBYzqM1uZUXQAAAGM"]
[Thu Jul 30 12:08:56.305696 2026] [security2:error] [pid 643253:tid 643475] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuFJsjqbtjBYzqM1uZUIwAAAFs"]
[Thu Jul 30 12:08:56.413341 2026] [security2:error] [pid 643253:tid 643366] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/license.php"] [unique_id "amuFKMjqbtjBYzqM1uZUZgAAI28"]
[Thu Jul 30 12:08:56.849202 2026] [security2:error] [pid 643253:tid 643348] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/radio.php"] [unique_id "amuFKMjqbtjBYzqM1uZUbQAAB10"]
[Thu Jul 30 12:08:56.941916 2026] [core:notice] [pid 643253:tid 643437] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:56.948439 2026] [security2:error] [pid 643253:tid 643437] [client 103.215.74.26:51760] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFKMjqbtjBYzqM1uZUcQAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:57.187560 2026] [security2:error] [pid 643253:tid 643323] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuFKcjqbtjBYzqM1uZUcwAAA0Q"]
[Thu Jul 30 12:08:57.233359 2026] [security2:error] [pid 643253:tid 643459] [client 68.221.186.136:34879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/db.php"] [unique_id "amuFKcjqbtjBYzqM1uZUdAAAAEs"]
[Thu Jul 30 12:08:57.323615 2026] [security2:error] [pid 643253:tid 643491] [client 20.52.125.110:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/alf.php"] [unique_id "amuFKcjqbtjBYzqM1uZUdQAAAGs"]
[Thu Jul 30 12:08:57.509106 2026] [security2:error] [pid 643253:tid 643265] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuFKcjqbtjBYzqM1uZUfAAAdgo"]
[Thu Jul 30 12:08:57.664072 2026] [core:notice] [pid 643253:tid 643441] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:57.670488 2026] [security2:error] [pid 643253:tid 643441] [client 103.215.74.26:51776] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFKcjqbtjBYzqM1uZUfgAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:57.815585 2026] [security2:error] [pid 643253:tid 643373] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/wp-login.php"] [unique_id "amuFKcjqbtjBYzqM1uZUgwAAInY"]
[Thu Jul 30 12:08:58.020772 2026] [security2:error] [pid 643253:tid 643426] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuFKcjqbtjBYzqM1uZUgAAAACo"]
[Thu Jul 30 12:08:58.061373 2026] [security2:error] [pid 643253:tid 643429] [client 20.52.125.110:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/feedback.php"] [unique_id "amuFKsjqbtjBYzqM1uZUiwAAAC0"]
[Thu Jul 30 12:08:58.161711 2026] [security2:error] [pid 643253:tid 643333] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/wp-load.php"] [unique_id "amuFKsjqbtjBYzqM1uZUjAAAAk4"]
[Thu Jul 30 12:08:58.378040 2026] [security2:error] [pid 643253:tid 643394] [client 68.221.186.136:36782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/default.php"] [unique_id "amuFKsjqbtjBYzqM1uZUjQAAAAo"]
[Thu Jul 30 12:08:58.396067 2026] [core:notice] [pid 643253:tid 643472] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:08:58.402423 2026] [security2:error] [pid 643253:tid 643472] [client 103.215.74.26:51786] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFKsjqbtjBYzqM1uZUjgAAAFg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:08:58.466268 2026] [security2:error] [pid 643253:tid 643381] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/file.php"] [unique_id "amuFKsjqbtjBYzqM1uZUlQAAbH4"]
[Thu Jul 30 12:08:58.596271 2026] [security2:error] [pid 643253:tid 643467] [client 74.7.175.190:56454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.bah.djb.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuFKsjqbtjBYzqM1uZUlgAAAFM"]
[Thu Jul 30 12:08:58.725514 2026] [security2:error] [pid 643253:tid 643458] [client 20.52.125.110:12170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/gettest.php"] [unique_id "amuFKsjqbtjBYzqM1uZUmgAAAEo"]
[Thu Jul 30 12:08:58.791088 2026] [security2:error] [pid 643253:tid 643364] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/dropdown.php"] [unique_id "amuFKsjqbtjBYzqM1uZUnAAARG0"]
[Thu Jul 30 12:08:59.146512 2026] [security2:error] [pid 643253:tid 643263] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/dropdown.php"] [unique_id "amuFK8jqbtjBYzqM1uZUpgAAdQg"]
[Thu Jul 30 12:08:59.262972 2026] [security2:error] [pid 643253:tid 643470] [client 20.52.125.110:12216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/maint.php"] [unique_id "amuFK8jqbtjBYzqM1uZUpwAAAFY"]
[Thu Jul 30 12:08:59.307570 2026] [security2:error] [pid 643253:tid 643484] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFKsjqbtjBYzqM1uZUmQAAAGQ"]
[Thu Jul 30 12:08:59.467381 2026] [security2:error] [pid 643253:tid 643379] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuFK8jqbtjBYzqM1uZUqwAAIXw"]
[Thu Jul 30 12:08:59.797581 2026] [security2:error] [pid 643253:tid 643289] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-signup.php"] [unique_id "amuFK8jqbtjBYzqM1uZUrwAACyI"]
[Thu Jul 30 12:09:00.137156 2026] [security2:error] [pid 643253:tid 643284] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/images/css.php"] [unique_id "amuFLMjqbtjBYzqM1uZUtwAAKR0"]
[Thu Jul 30 12:09:00.484616 2026] [security2:error] [pid 643253:tid 643271] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/chosen.php"] [unique_id "amuFLMjqbtjBYzqM1uZUuAAAARA"]
[Thu Jul 30 12:09:00.701859 2026] [security2:error] [pid 643253:tid 643459] [client 20.52.125.110:12196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/files.php"] [unique_id "amuFLMjqbtjBYzqM1uZUwgAAAEs"]
[Thu Jul 30 12:09:00.796860 2026] [security2:error] [pid 643253:tid 643372] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/cong.php"] [unique_id "amuFLMjqbtjBYzqM1uZUwwAAZnU"]
[Thu Jul 30 12:09:00.832082 2026] [security2:error] [pid 643253:tid 643316] [remote 74.7.241.60:57284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuFLMjqbtjBYzqM1uZUxAAAED0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:09:01.105355 2026] [security2:error] [pid 643253:tid 643296] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/mah.php"] [unique_id "amuFLcjqbtjBYzqM1uZUywAAWyk"]
[Thu Jul 30 12:09:01.208445 2026] [security2:error] [pid 643253:tid 643498] [client 68.221.186.136:23181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/dropdown.php"] [unique_id "amuFLcjqbtjBYzqM1uZUzQAAAHI"]
[Thu Jul 30 12:09:01.423242 2026] [security2:error] [pid 643253:tid 643293] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuFLcjqbtjBYzqM1uZUzwAAIyY"]
[Thu Jul 30 12:09:01.567025 2026] [security2:error] [pid 643253:tid 643421] [client 20.52.125.110:12246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/gecko.php"] [unique_id "amuFLcjqbtjBYzqM1uZU0AAAACU"]
[Thu Jul 30 12:09:01.736023 2026] [security2:error] [pid 643253:tid 643307] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ova-tools.php"] [unique_id "amuFLcjqbtjBYzqM1uZU1wAABzQ"]
[Thu Jul 30 12:09:02.026958 2026] [security2:error] [pid 643253:tid 643417] [client 68.221.186.136:37861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/edit.php"] [unique_id "amuFLsjqbtjBYzqM1uZU2gAAACE"]
[Thu Jul 30 12:09:02.083373 2026] [security2:error] [pid 643253:tid 643297] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuFLsjqbtjBYzqM1uZU2wAAQio"]
[Thu Jul 30 12:09:02.159032 2026] [security2:error] [pid 643253:tid 643469] [client 20.52.125.110:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/zwso.php"] [unique_id "amuFLsjqbtjBYzqM1uZU4AAAAFU"]
[Thu Jul 30 12:09:02.414673 2026] [security2:error] [pid 643253:tid 643292] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuFLsjqbtjBYzqM1uZU5wAAACU"]
[Thu Jul 30 12:09:02.747808 2026] [security2:error] [pid 643253:tid 643371] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuFLsjqbtjBYzqM1uZU8QAAKnQ"]
[Thu Jul 30 12:09:02.951160 2026] [security2:error] [pid 643253:tid 643385] [client 68.221.186.136:33669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/f35.php"] [unique_id "amuFLsjqbtjBYzqM1uZU9QAAAAE"]
[Thu Jul 30 12:09:03.118955 2026] [security2:error] [pid 643253:tid 643279] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuFL8jqbtjBYzqM1uZU9wAABBg"]
[Thu Jul 30 12:09:03.236755 2026] [security2:error] [pid 643253:tid 643505] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFLsjqbtjBYzqM1uZU9AAAeX8"]
[Thu Jul 30 12:09:03.400325 2026] [core:notice] [pid 643253:tid 643390] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:03.472496 2026] [security2:error] [pid 643253:tid 643291] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuFL8jqbtjBYzqM1uZU_wAAciQ"]
[Thu Jul 30 12:09:03.537042 2026] [autoindex:error] [pid 643253:tid 643319] [remote 27.124.10.134:0] AH01276: Cannot serve directory /home1/injnyxte/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:09:03.691230 2026] [security2:error] [pid 643253:tid 643435] [client 68.221.186.136:31992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/f7.php"] [unique_id "amuFL8jqbtjBYzqM1uZVAgAAADM"]
[Thu Jul 30 12:09:03.833030 2026] [security2:error] [pid 643253:tid 643300] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/license.php"] [unique_id "amuFL8jqbtjBYzqM1uZVCgAAdS0"]
[Thu Jul 30 12:09:03.967924 2026] [core:notice] [pid 643253:tid 643484] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:04.136409 2026] [core:notice] [pid 643253:tid 643428] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:04.142789 2026] [security2:error] [pid 643253:tid 643428] [client 103.215.74.26:21540] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFMMjqbtjBYzqM1uZVDwAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:04.153937 2026] [security2:error] [pid 643253:tid 643278] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/about.php"] [unique_id "amuFMMjqbtjBYzqM1uZVEAAABxc"]
[Thu Jul 30 12:09:04.327278 2026] [security2:error] [pid 643253:tid 643471] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFL8jqbtjBYzqM1uZVAwAAV0U"]
[Thu Jul 30 12:09:04.460414 2026] [security2:error] [pid 643253:tid 643327] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/about.php"] [unique_id "amuFMMjqbtjBYzqM1uZVGAAAVUg"]
[Thu Jul 30 12:09:04.805590 2026] [security2:error] [pid 643253:tid 643351] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuFMMjqbtjBYzqM1uZVHwAAa2A"]
[Thu Jul 30 12:09:04.895597 2026] [core:notice] [pid 643253:tid 643493] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:04.906178 2026] [security2:error] [pid 643253:tid 643493] [client 103.215.74.26:21554] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFMMjqbtjBYzqM1uZVJgAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:05.318506 2026] [security2:error] [pid 643253:tid 643342] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/schema-markup-rich-snippets/readme.txt"] [unique_id "amuFMcjqbtjBYzqM1uZVKgAAZVc"]
[Thu Jul 30 12:09:05.553381 2026] [security2:error] [pid 643253:tid 643318] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuFMcjqbtjBYzqM1uZVLgAAJz8"]
[Thu Jul 30 12:09:05.628735 2026] [core:notice] [pid 643253:tid 643459] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:05.634960 2026] [security2:error] [pid 643253:tid 643459] [client 103.215.74.26:21562] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFMcjqbtjBYzqM1uZVMAAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:05.874110 2026] [security2:error] [pid 643253:tid 643301] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/img/about.php"] [unique_id "amuFMcjqbtjBYzqM1uZVNQAARy4"]
[Thu Jul 30 12:09:05.945643 2026] [security2:error] [pid 643253:tid 643385] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFMcjqbtjBYzqM1uZVLwAAAUc"]
[Thu Jul 30 12:09:06.237644 2026] [security2:error] [pid 643253:tid 643355] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuFMsjqbtjBYzqM1uZVOQAAJWQ"]
[Thu Jul 30 12:09:06.327408 2026] [security2:error] [pid 643253:tid 643495] [client 20.52.125.110:12236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/13.php"] [unique_id "amuFMsjqbtjBYzqM1uZVOgAAAG8"]
[Thu Jul 30 12:09:06.362528 2026] [core:notice] [pid 643253:tid 643468] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:06.369291 2026] [security2:error] [pid 643253:tid 643468] [client 103.215.74.26:21572] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFMsjqbtjBYzqM1uZVPwAAAFQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:06.637454 2026] [security2:error] [pid 643253:tid 643328] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuFMsjqbtjBYzqM1uZVRgAATkk"]
[Thu Jul 30 12:09:06.752662 2026] [security2:error] [pid 643253:tid 643429] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFMsjqbtjBYzqM1uZVOwAALU0"], referer: https://www.spececigarette.com/wp-content/plugins/schema-markup-rich-snippets/Readme.txt
[Thu Jul 30 12:09:06.792336 2026] [core:notice] [pid 643253:tid 643431] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:06.942902 2026] [security2:error] [pid 643253:tid 643453] [client 20.52.125.110:12162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/ava.php"] [unique_id "amuFMsjqbtjBYzqM1uZVTQAAAEU"]
[Thu Jul 30 12:09:06.957742 2026] [security2:error] [pid 643253:tid 643346] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuFMsjqbtjBYzqM1uZVTgAAJFs"]
[Thu Jul 30 12:09:07.110794 2026] [core:notice] [pid 643253:tid 643450] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:07.116970 2026] [security2:error] [pid 643253:tid 643450] [client 103.215.74.26:21580] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFM8jqbtjBYzqM1uZVUgAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:07.307233 2026] [security2:error] [pid 643253:tid 643347] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuFM8jqbtjBYzqM1uZVVQAAT1w"]
[Thu Jul 30 12:09:07.501398 2026] [security2:error] [pid 643253:tid 643396] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFM8jqbtjBYzqM1uZVUwAADHE"]
[Thu Jul 30 12:09:07.667683 2026] [security2:error] [pid 643253:tid 643350] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuFM8jqbtjBYzqM1uZVXAAAfV8"]
[Thu Jul 30 12:09:07.849034 2026] [core:notice] [pid 643253:tid 643436] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:07.855461 2026] [security2:error] [pid 643253:tid 643436] [client 103.215.74.26:21590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFM8jqbtjBYzqM1uZVXQAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:07.905830 2026] [security2:error] [pid 643253:tid 643397] [client 20.52.125.110:17588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/main.php"] [unique_id "amuFM8jqbtjBYzqM1uZVXwAAAA0"]
[Thu Jul 30 12:09:07.986625 2026] [security2:error] [pid 643253:tid 643325] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuFM8jqbtjBYzqM1uZVYwAAbEY"]
[Thu Jul 30 12:09:08.272659 2026] [security2:error] [pid 643253:tid 643388] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFM8jqbtjBYzqM1uZVXgAABGc"], referer: https://www.spececigarette.com/wp-content/plugins/schema-markup-rich-snippets/README.txt
[Thu Jul 30 12:09:08.292446 2026] [security2:error] [pid 643253:tid 643341] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuFNMjqbtjBYzqM1uZVaAAAHVY"]
[Thu Jul 30 12:09:08.318475 2026] [core:notice] [pid 643253:tid 643376] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:08.417706 2026] [security2:error] [pid 643253:tid 643476] [client 74.7.244.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.kamiliacademy.com"] [uri "/index.php"] [unique_id "amuFMMjqbtjBYzqM1uZVGwAAAFw"]
[Thu Jul 30 12:09:08.418680 2026] [security2:error] [pid 643253:tid 643442] [client 74.7.244.30:54000] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.kamiliacademy.com"] [uri "/robots.txt"] [unique_id "amuFMMjqbtjBYzqM1uZVGQAAOlE"]
[Thu Jul 30 12:09:08.598841 2026] [security2:error] [pid 643253:tid 643366] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuFNMjqbtjBYzqM1uZVdAAALm8"]
[Thu Jul 30 12:09:08.603645 2026] [core:notice] [pid 643253:tid 643418] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:08.610165 2026] [security2:error] [pid 643253:tid 643418] [client 103.215.74.26:21598] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFNMjqbtjBYzqM1uZVdQAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:08.643273 2026] [security2:error] [pid 643253:tid 643369] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/automattic-for-agencies-client/readme.txt"] [unique_id "amuFNMjqbtjBYzqM1uZVdgAAc3I"]
[Thu Jul 30 12:09:08.906622 2026] [security2:error] [pid 643253:tid 643345] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuFNMjqbtjBYzqM1uZVegAAQVo"]
[Thu Jul 30 12:09:09.246819 2026] [security2:error] [pid 643253:tid 643256] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuFNcjqbtjBYzqM1uZVggAATwE"]
[Thu Jul 30 12:09:09.274447 2026] [security2:error] [pid 643253:tid 643500] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFNMjqbtjBYzqM1uZVewAAdGg"]
[Thu Jul 30 12:09:09.335094 2026] [core:notice] [pid 643253:tid 643409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:09.341568 2026] [security2:error] [pid 643253:tid 643409] [client 103.215.74.26:21600] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFNcjqbtjBYzqM1uZVgwAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:09.427470 2026] [security2:error] [pid 643253:tid 643480] [client 20.52.125.110:17597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-file.php"] [unique_id "amuFNcjqbtjBYzqM1uZVhQAAAGA"]
[Thu Jul 30 12:09:09.558214 2026] [security2:error] [pid 643253:tid 643265] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuFNcjqbtjBYzqM1uZViQAAFwo"]
[Thu Jul 30 12:09:09.868659 2026] [security2:error] [pid 643253:tid 643373] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuFNcjqbtjBYzqM1uZVjgAAOXY"]
[Thu Jul 30 12:09:10.022447 2026] [security2:error] [pid 643253:tid 643397] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFNcjqbtjBYzqM1uZVjQAADWI"], referer: https://www.spececigarette.com/wp-content/plugins/automattic-for-agencies-client/Readme.txt
[Thu Jul 30 12:09:10.069712 2026] [core:notice] [pid 643253:tid 643492] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:10.075739 2026] [security2:error] [pid 643253:tid 643492] [client 103.215.74.26:21608] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFNsjqbtjBYzqM1uZVkwAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:10.233672 2026] [security2:error] [pid 643253:tid 643349] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuFNsjqbtjBYzqM1uZVmAAAXl4"]
[Thu Jul 30 12:09:10.262824 2026] [security2:error] [pid 643253:tid 643381] [remote 74.7.241.59:44542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuFNsjqbtjBYzqM1uZVmQAAXX4"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:09:10.527137 2026] [security2:error] [pid 643253:tid 643405] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFNsjqbtjBYzqM1uZVlwAAFU4"]
[Thu Jul 30 12:09:10.562491 2026] [security2:error] [pid 643253:tid 643365] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/images/about.php"] [unique_id "amuFNsjqbtjBYzqM1uZVmwAACW4"]
[Thu Jul 30 12:09:10.580602 2026] [lsapi:error] [pid 643253:tid 643357] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/love-hurts-vj-junior/
[Thu Jul 30 12:09:10.751087 2026] [security2:error] [pid 643253:tid 643403] [client 20.52.125.110:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-signin.php"] [unique_id "amuFNsjqbtjBYzqM1uZVpAAAABM"]
[Thu Jul 30 12:09:10.796621 2026] [core:notice] [pid 643253:tid 643456] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:10.803083 2026] [security2:error] [pid 643253:tid 643456] [client 103.215.74.26:21620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFNsjqbtjBYzqM1uZVpQAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:11.209932 2026] [security2:error] [pid 643253:tid 643489] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFNsjqbtjBYzqM1uZVpgAAaQg"], referer: https://www.spececigarette.com/wp-content/plugins/automattic-for-agencies-client/README.txt
[Thu Jul 30 12:09:11.761341 2026] [security2:error] [pid 643253:tid 643417] [client 172.236.9.101:61203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFN8jqbtjBYzqM1uZVrgAAACE"]
[Thu Jul 30 12:09:11.838467 2026] [security2:error] [pid 643253:tid 643448] [client 172.236.9.101:60436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFN8jqbtjBYzqM1uZVsAAAAEA"]
[Thu Jul 30 12:09:11.864853 2026] [security2:error] [pid 643253:tid 643449] [client 172.236.9.101:1230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFN8jqbtjBYzqM1uZVsgAAAEE"]
[Thu Jul 30 12:09:11.865568 2026] [security2:error] [pid 643253:tid 643404] [client 172.236.9.101:35736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFN8jqbtjBYzqM1uZVsQAAABQ"]
[Thu Jul 30 12:09:11.899995 2026] [security2:error] [pid 643253:tid 643281] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuFN8jqbtjBYzqM1uZVwQAAZRo"]
[Thu Jul 30 12:09:11.962589 2026] [security2:error] [pid 643253:tid 643398] [client 20.52.125.110:12164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/simi.php"] [unique_id "amuFN8jqbtjBYzqM1uZV0QAAAA4"]
[Thu Jul 30 12:09:12.307630 2026] [security2:error] [pid 643253:tid 643279] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuFOMjqbtjBYzqM1uZV8wAASRg"]
[Thu Jul 30 12:09:12.462427 2026] [security2:error] [pid 643253:tid 643406] [client 20.52.125.110:12199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/wp-conf.php"] [unique_id "amuFOMjqbtjBYzqM1uZV9AAAABY"]
[Thu Jul 30 12:09:12.631992 2026] [security2:error] [pid 643253:tid 643303] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/about.php"] [unique_id "amuFOMjqbtjBYzqM1uZV9QAALDA"]
[Thu Jul 30 12:09:12.649687 2026] [security2:error] [pid 643253:tid 643490] [client 213.152.187.215:50668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuFOMjqbtjBYzqM1uZV9gAAAGo"]
[Thu Jul 30 12:09:12.649879 2026] [security2:error] [pid 643253:tid 643490] [client 213.152.187.215:50668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuFOMjqbtjBYzqM1uZV9gAAAGo"]
[Thu Jul 30 12:09:12.962148 2026] [security2:error] [pid 643253:tid 643291] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/about.php"] [unique_id "amuFOMjqbtjBYzqM1uZV_gAAaSQ"]
[Thu Jul 30 12:09:13.195758 2026] [security2:error] [pid 643253:tid 643432] [client 20.52.125.110:12172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuFOcjqbtjBYzqM1uZWBwAAADA"]
[Thu Jul 30 12:09:13.291727 2026] [security2:error] [pid 643253:tid 643315] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuFOcjqbtjBYzqM1uZWDgAAADw"]
[Thu Jul 30 12:09:13.473862 2026] [security2:error] [pid 643253:tid 643459] [client 172.236.9.101:12679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV4gAAAEs"]
[Thu Jul 30 12:09:13.503283 2026] [security2:error] [pid 643253:tid 643401] [client 172.236.9.101:48577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV4AAAABE"]
[Thu Jul 30 12:09:13.503457 2026] [security2:error] [pid 643253:tid 643472] [client 172.236.9.101:43412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV4QAAAFg"]
[Thu Jul 30 12:09:13.507475 2026] [security2:error] [pid 643253:tid 643498] [client 172.236.9.101:35838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV4wAAAHI"]
[Thu Jul 30 12:09:13.573306 2026] [security2:error] [pid 643253:tid 643444] [client 172.236.9.101:46072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV7gAAADw"]
[Thu Jul 30 12:09:13.577092 2026] [security2:error] [pid 643253:tid 643506] [client 172.236.9.101:6827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV5QAAAHo"]
[Thu Jul 30 12:09:13.579752 2026] [security2:error] [pid 643253:tid 643385] [client 172.236.9.101:65117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV5AAAAAE"]
[Thu Jul 30 12:09:13.597615 2026] [security2:error] [pid 643253:tid 643390] [client 172.236.9.101:22679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV5gAAAAY"]
[Thu Jul 30 12:09:13.598311 2026] [security2:error] [pid 643253:tid 643466] [client 172.236.9.101:23710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV5wAAAFI"]
[Thu Jul 30 12:09:13.602678 2026] [security2:error] [pid 643253:tid 643439] [client 172.236.9.101:51232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV6AAAADc"]
[Thu Jul 30 12:09:13.603871 2026] [security2:error] [pid 643253:tid 643478] [client 172.236.9.101:58755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV6gAAAF4"]
[Thu Jul 30 12:09:13.606706 2026] [security2:error] [pid 643253:tid 643452] [client 172.236.9.101:31987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV7QAAAEQ"]
[Thu Jul 30 12:09:13.608614 2026] [security2:error] [pid 643253:tid 643413] [client 172.236.9.101:60570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV7AAAAB0"]
[Thu Jul 30 12:09:13.619930 2026] [security2:error] [pid 643253:tid 643405] [client 172.236.9.101:28160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV8AAAABU"]
[Thu Jul 30 12:09:13.621202 2026] [security2:error] [pid 643253:tid 643393] [client 172.236.9.101:60318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV8gAAAAk"]
[Thu Jul 30 12:09:13.624827 2026] [security2:error] [pid 643253:tid 643476] [client 172.236.9.101:44506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFOMjqbtjBYzqM1uZV8QAAAFw"]
[Thu Jul 30 12:09:13.638306 2026] [security2:error] [pid 643253:tid 643339] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuFOcjqbtjBYzqM1uZWEwAAaFQ"]
[Thu Jul 30 12:09:13.857262 2026] [security2:error] [pid 643253:tid 643317] [remote 216.73.216.152:2913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFOcjqbtjBYzqM1uZWGgAARz4"]
[Thu Jul 30 12:09:13.974635 2026] [security2:error] [pid 643253:tid 643335] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuFOcjqbtjBYzqM1uZWGwAAFlA"]
[Thu Jul 30 12:09:14.281267 2026] [security2:error] [pid 643253:tid 643301] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuFOsjqbtjBYzqM1uZWHwAAai4"]
[Thu Jul 30 12:09:15.082415 2026] [security2:error] [pid 643253:tid 643346] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuFO8jqbtjBYzqM1uZWNAAAC1s"]
[Thu Jul 30 12:09:15.388179 2026] [security2:error] [pid 643253:tid 643347] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuFO8jqbtjBYzqM1uZWOwAAS1w"]
[Thu Jul 30 12:09:15.739943 2026] [security2:error] [pid 643253:tid 643376] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuFO8jqbtjBYzqM1uZWSgAAHXk"]
[Thu Jul 30 12:09:15.924415 2026] [security2:error] [pid 643253:tid 643385] [client 144.124.193.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuFO8jqbtjBYzqM1uZWRgAAAAE"], referer: https://tereashops.com/product/ploom-x-aura-evo-tropical-berry-crystal-%E7%86%B1%E5%B8%B6%E8%8E%93%E6%9E%9C%E8%8A%92%E6%9E%9C%E7%88%86%E7%8F%A0%E7%85%99%E5%BD%88/
[Thu Jul 30 12:09:15.948537 2026] [security2:error] [pid 643253:tid 643452] [client 20.52.125.110:17554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/bala.php"] [unique_id "amuFO8jqbtjBYzqM1uZWUwAAAEQ"]
[Thu Jul 30 12:09:16.061606 2026] [security2:error] [pid 643253:tid 643340] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cloud.php"] [unique_id "amuFPMjqbtjBYzqM1uZWVAAAW1U"]
[Thu Jul 30 12:09:16.379356 2026] [security2:error] [pid 643253:tid 643377] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuFPMjqbtjBYzqM1uZWVQAAAno"]
[Thu Jul 30 12:09:16.527501 2026] [core:notice] [pid 643253:tid 643477] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:16.534073 2026] [security2:error] [pid 643253:tid 643477] [client 103.215.74.26:14510] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFPMjqbtjBYzqM1uZWXQAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:16.599691 2026] [security2:error] [pid 643253:tid 643348] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/op-kassa-for-woocommerce/readme.txt"] [unique_id "amuFPMjqbtjBYzqM1uZWXgAAal0"]
[Thu Jul 30 12:09:16.705821 2026] [security2:error] [pid 643253:tid 643323] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/updates.php"] [unique_id "amuFPMjqbtjBYzqM1uZWXwAAd0Q"]
[Thu Jul 30 12:09:16.825069 2026] [core:notice] [pid 643253:tid 643428] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:17.939523 2026] [http2:info] [pid 703393:tid 703393] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:09:17.999193 2026] [security2:error] [pid 643253:tid 643467] [client 20.52.125.110:12185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/bk.php"] [unique_id "amuFPcjqbtjBYzqM1uZWbAAAAFM"]
[Thu Jul 30 12:09:18.110633 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:18.200448 2026] [security2:error] [pid 703393:tid 703395] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/css/cloud.php"] [unique_id "amuFPs637Arlr6Yb1EfnyQAAiQE"]
[Thu Jul 30 12:09:18.202354 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:18.211173 2026] [security2:error] [pid 703393:tid 703523] [client 103.215.74.26:14516] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFPs637Arlr6Yb1EfnyAAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:18.381064 2026] [security2:error] [pid 703393:tid 703533] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFPs637Arlr6Yb1EfnwgAAj38"]
[Thu Jul 30 12:09:18.515372 2026] [security2:error] [pid 703393:tid 703457] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuFPs637Arlr6Yb1EfoBwAAsz8"]
[Thu Jul 30 12:09:18.932902 2026] [security2:error] [pid 703393:tid 703462] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/img/cloud.php"] [unique_id "amuFPs637Arlr6Yb1EfoEgAAxkQ"]
[Thu Jul 30 12:09:18.937029 2026] [core:notice] [pid 703393:tid 703580] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:18.944673 2026] [security2:error] [pid 703393:tid 703580] [client 103.215.74.26:14530] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFPs637Arlr6Yb1EfoEwAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:19.282395 2026] [security2:error] [pid 703393:tid 703481] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuFP8637Arlr6Yb1EfoLAAA4Vc"]
[Thu Jul 30 12:09:19.460638 2026] [security2:error] [pid 703393:tid 703586] [client 20.52.125.110:17548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/ahax.php"] [unique_id "amuFP8637Arlr6Yb1EfoNAAAAMQ"]
[Thu Jul 30 12:09:19.612346 2026] [security2:error] [pid 703393:tid 703489] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuFP8637Arlr6Yb1EfoOQAA8V8"]
[Thu Jul 30 12:09:19.665669 2026] [core:notice] [pid 703393:tid 703622] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:19.673260 2026] [security2:error] [pid 703393:tid 703622] [client 103.215.74.26:14540] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFP8637Arlr6Yb1EfoOwAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:19.776801 2026] [security2:error] [pid 703393:tid 703626] [client 52.167.144.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuFP8637Arlr6Yb1EfoMwAAAOw"]
[Thu Jul 30 12:09:19.946040 2026] [security2:error] [pid 703393:tid 703493] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/avaa.php"] [unique_id "amuFP8637Arlr6Yb1EfoQQAA_2M"]
[Thu Jul 30 12:09:20.174672 2026] [security2:error] [pid 703393:tid 703634] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFP8637Arlr6Yb1EfoPQAA9GE"], referer: https://www.spececigarette.com/wp-content/plugins/op-kassa-for-woocommerce/Readme.txt
[Thu Jul 30 12:09:20.274710 2026] [security2:error] [pid 703393:tid 703495] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/images/cloud.php"] [unique_id "amuFQM637Arlr6Yb1EfoRQAAjWU"]
[Thu Jul 30 12:09:20.390833 2026] [core:notice] [pid 703393:tid 703649] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:20.397628 2026] [security2:error] [pid 703393:tid 703649] [client 103.215.74.26:14556] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQM637Arlr6Yb1EfoSgAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:20.585677 2026] [security2:error] [pid 703393:tid 703500] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuFQM637Arlr6Yb1EfoTwAAo2o"]
[Thu Jul 30 12:09:20.686081 2026] [security2:error] [pid 703393:tid 703523] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFQM637Arlr6Yb1EfoSQAAhWc"]
[Thu Jul 30 12:09:20.895639 2026] [security2:error] [pid 703393:tid 703504] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuFQM637Arlr6Yb1EfoWQAAsG4"]
[Thu Jul 30 12:09:21.129136 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:21.136665 2026] [security2:error] [pid 703393:tid 703565] [client 103.215.74.26:14562] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQc637Arlr6Yb1EfoWgAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:21.223050 2026] [security2:error] [pid 703393:tid 703508] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuFQc637Arlr6Yb1EfoYAAAwnI"]
[Thu Jul 30 12:09:21.547062 2026] [security2:error] [pid 703393:tid 703510] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuFQc637Arlr6Yb1EfoZAAAmHQ"]
[Thu Jul 30 12:09:21.575789 2026] [security2:error] [pid 703393:tid 703572] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFQc637Arlr6Yb1EfoXQAAtnA"], referer: https://www.spececigarette.com/wp-content/plugins/op-kassa-for-woocommerce/README.txt
[Thu Jul 30 12:09:21.891432 2026] [core:notice] [pid 703393:tid 703589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:21.896358 2026] [security2:error] [pid 703393:tid 703516] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuFQc637Arlr6Yb1EfobQAA1Xo"]
[Thu Jul 30 12:09:21.898396 2026] [security2:error] [pid 703393:tid 703589] [client 103.215.74.26:14564] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQc637Arlr6Yb1EfoawAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:22.240068 2026] [security2:error] [pid 703393:tid 703518] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuFQs637Arlr6Yb1EfoeAAA4Hw"]
[Thu Jul 30 12:09:22.507386 2026] [security2:error] [pid 703393:tid 703579] [client 172.237.109.114:22745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQc637Arlr6Yb1EfocAAAAL0"]
[Thu Jul 30 12:09:22.550553 2026] [security2:error] [pid 703393:tid 703606] [client 172.237.109.114:27831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQc637Arlr6Yb1EfocQAAANg"]
[Thu Jul 30 12:09:22.554063 2026] [security2:error] [pid 703393:tid 703577] [client 172.237.109.114:58560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQc637Arlr6Yb1EfocgAAALs"]
[Thu Jul 30 12:09:22.570661 2026] [security2:error] [pid 703393:tid 703395] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/updates.php"] [unique_id "amuFQs637Arlr6Yb1EfofQAAxAE"]
[Thu Jul 30 12:09:22.582719 2026] [security2:error] [pid 703393:tid 703607] [client 172.237.109.114:35668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQs637Arlr6Yb1EfocwAAANk"]
[Thu Jul 30 12:09:22.583729 2026] [security2:error] [pid 703393:tid 703608] [client 172.237.109.114:3417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFQs637Arlr6Yb1EfodAAAANo"]
[Thu Jul 30 12:09:22.622336 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:22.629101 2026] [security2:error] [pid 703393:tid 703619] [client 103.215.74.26:14576] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQs637Arlr6Yb1EfofgAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:22.905539 2026] [security2:error] [pid 703393:tid 703399] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuFQs637Arlr6Yb1EfoggAA7AU"]
[Thu Jul 30 12:09:23.216917 2026] [security2:error] [pid 703393:tid 703402] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuFQ8637Arlr6Yb1EfohwAA-gg"]
[Thu Jul 30 12:09:23.356031 2026] [core:notice] [pid 703393:tid 703641] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:23.362685 2026] [security2:error] [pid 703393:tid 703641] [client 103.215.74.26:20014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFQ8637Arlr6Yb1EfoiwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:23.550779 2026] [security2:error] [pid 703393:tid 703405] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuFQ8637Arlr6Yb1EfojwAAjQs"]
[Thu Jul 30 12:09:23.874091 2026] [security2:error] [pid 703393:tid 703415] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfa-rex.php7"] [unique_id "amuFQ8637Arlr6Yb1EfomgAApBU"]
[Thu Jul 30 12:09:24.060440 2026] [security2:error] [pid 703393:tid 703417] [remote 74.7.242.7:46426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuFRM637Arlr6Yb1EfonwAAhhc"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:09:24.084470 2026] [core:notice] [pid 703393:tid 703649] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:24.092022 2026] [security2:error] [pid 703393:tid 703649] [client 103.215.74.26:20026] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFRM637Arlr6Yb1EfooAAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:24.193726 2026] [security2:error] [pid 703393:tid 703418] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfanew.php"] [unique_id "amuFRM637Arlr6Yb1EfooQAArBg"]
[Thu Jul 30 12:09:24.510139 2026] [security2:error] [pid 703393:tid 703429] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuFRM637Arlr6Yb1EfoqwAAwyM"]
[Thu Jul 30 12:09:24.816115 2026] [core:notice] [pid 703393:tid 703568] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:24.818960 2026] [security2:error] [pid 703393:tid 703430] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuFRM637Arlr6Yb1EforQAAtCQ"]
[Thu Jul 30 12:09:24.822870 2026] [security2:error] [pid 703393:tid 703568] [client 103.215.74.26:20034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFRM637Arlr6Yb1EforAAAALI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:24.937876 2026] [core:notice] [pid 703393:tid 703536] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:25.141529 2026] [security2:error] [pid 703393:tid 703439] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-p.php7"] [unique_id "amuFRc637Arlr6Yb1EfowAAA2y0"]
[Thu Jul 30 12:09:25.401942 2026] [security2:error] [pid 703393:tid 703615] [client 52.167.144.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuFRc637Arlr6Yb1EfovgAAAOE"]
[Thu Jul 30 12:09:25.504411 2026] [security2:error] [pid 703393:tid 703421] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuFRc637Arlr6Yb1EfoyAAA6xs"]
[Thu Jul 30 12:09:25.824244 2026] [security2:error] [pid 703393:tid 703453] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuFRc637Arlr6Yb1EfozQABAjs"]
[Thu Jul 30 12:09:26.169835 2026] [security2:error] [pid 703393:tid 703444] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/repeater.php"] [unique_id "amuFRs637Arlr6Yb1Efo1wAAnjI"]
[Thu Jul 30 12:09:26.494135 2026] [security2:error] [pid 703393:tid 703452] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wsoyanz.php"] [unique_id "amuFRs637Arlr6Yb1Efo3wAAiDo"]
[Thu Jul 30 12:09:26.722165 2026] [security2:error] [pid 703393:tid 703457] [remote 47.128.21.210:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "intelprocess.net"] [uri "/robots.txt"] [unique_id "amuFRs637Arlr6Yb1Efo4wAAuT8"]
[Thu Jul 30 12:09:26.839148 2026] [security2:error] [pid 703393:tid 703422] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/yanz.php"] [unique_id "amuFRs637Arlr6Yb1Efo5AAAtBw"]
[Thu Jul 30 12:09:26.937370 2026] [security2:error] [pid 703393:tid 703409] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/wc-rest-payment/readme.txt"] [unique_id "amuFRs637Arlr6Yb1Efo5QAAxQ8"]
[Thu Jul 30 12:09:27.185956 2026] [security2:error] [pid 703393:tid 703458] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "amuFR8637Arlr6Yb1Efo7QAAvkA"]
[Thu Jul 30 12:09:27.260005 2026] [security2:error] [pid 703393:tid 703592] [client 85.208.96.210:55394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/30/joao-azevedo-e-reeleito-governador-da-paraiba/"] [unique_id "amuFR8637Arlr6Yb1Efo7gAAAMo"]
[Thu Jul 30 12:09:27.260147 2026] [security2:error] [pid 703393:tid 703592] [client 85.208.96.210:55394] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/30/joao-azevedo-e-reeleito-governador-da-paraiba/"] [unique_id "amuFR8637Arlr6Yb1Efo7gAAAMo"]
[Thu Jul 30 12:09:27.530814 2026] [security2:error] [pid 703393:tid 703448] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "amuFR8637Arlr6Yb1Efo9gAA2TY"]
[Thu Jul 30 12:09:27.633545 2026] [security2:error] [pid 703393:tid 703593] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFR8637Arlr6Yb1Efo7wAAyxo"]
[Thu Jul 30 12:09:27.843183 2026] [security2:error] [pid 703393:tid 703463] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cache-compat.php"] [unique_id "amuFR8637Arlr6Yb1EfpAwAA60U"]
[Thu Jul 30 12:09:28.142637 2026] [security2:error] [pid 703393:tid 703468] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ajax-actions.php"] [unique_id "amuFSM637Arlr6Yb1EfpCgAAi0o"]
[Thu Jul 30 12:09:28.223966 2026] [security2:error] [pid 703393:tid 703469] [remote 103.77.162.29:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.162.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amuFSM637Arlr6Yb1EfpDwABAEs"]
[Thu Jul 30 12:09:28.224149 2026] [security2:error] [pid 703393:tid 703646] [client 103.77.162.29:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amuFSM637Arlr6Yb1EfpDwABAEs"]
[Thu Jul 30 12:09:28.507561 2026] [security2:error] [pid 703393:tid 703473] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/ajax-actions.php"] [unique_id "amuFSM637Arlr6Yb1EfpEgAAlk8"]
[Thu Jul 30 12:09:28.525339 2026] [autoindex:error] [pid 703393:tid 703475] [remote 45.33.74.9:57306] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:09:28.817649 2026] [security2:error] [pid 703393:tid 703476] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-consar.php"] [unique_id "amuFSM637Arlr6Yb1EfpGgAA-1I"]
[Thu Jul 30 12:09:29.164932 2026] [security2:error] [pid 703393:tid 703459] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/repeater.php"] [unique_id "amuFSc637Arlr6Yb1EfpHwAAnUE"]
[Thu Jul 30 12:09:29.497573 2026] [security2:error] [pid 703393:tid 703479] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin-post.php"] [unique_id "amuFSc637Arlr6Yb1EfpJgAAnFU"]
[Thu Jul 30 12:09:29.842510 2026] [security2:error] [pid 703393:tid 703487] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "amuFSc637Arlr6Yb1EfpLgAA0l0"]
[Thu Jul 30 12:09:29.914437 2026] [security2:error] [pid 703393:tid 703549] [client 110.54.151.244:29556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/my_attendance_mobile.php"] [unique_id "amuFSc637Arlr6Yb1EfpHgAAn0w"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:09:29.930962 2026] [core:notice] [pid 703393:tid 703572] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:29.962701 2026] [security2:error] [pid 703393:tid 703601] [client 110.54.151.244:29556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/my_attendance_mobile.php"] [unique_id "amuFSc637Arlr6Yb1EfpMAAA018"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:09:30.105029 2026] [security2:error] [pid 703393:tid 703605] [client 110.54.151.244:29556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuFSs637Arlr6Yb1EfpMgAA114"], referer: https://hris.rgserve.ph/time_mobile.php
[Thu Jul 30 12:09:30.181657 2026] [security2:error] [pid 703393:tid 703492] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/dropdown.php"] [unique_id "amuFSs637Arlr6Yb1EfpNAAA2WI"]
[Thu Jul 30 12:09:30.481818 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:30.491457 2026] [fcgid:warn] [pid 703393:tid 703628] (70014)End of file found: [client 199.45.155.108:42640] mod_fcgid: can't get data from http client
[Thu Jul 30 12:09:30.544950 2026] [security2:error] [pid 703393:tid 703494] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuFSs637Arlr6Yb1EfpQAAAz2Q"]
[Thu Jul 30 12:09:30.603864 2026] [core:notice] [pid 703393:tid 703610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:30.611261 2026] [security2:error] [pid 703393:tid 703610] [client 103.215.74.26:20040] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFSs637Arlr6Yb1EfpQwAAANw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:30.882946 2026] [security2:error] [pid 703393:tid 703478] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/dropdown.php"] [unique_id "amuFSs637Arlr6Yb1EfpSgAAlVQ"]
[Thu Jul 30 12:09:31.200655 2026] [security2:error] [pid 703393:tid 703499] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/about.php"] [unique_id "amuFS8637Arlr6Yb1EfpTQAA72k"]
[Thu Jul 30 12:09:31.331478 2026] [core:notice] [pid 703393:tid 703638] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:31.339075 2026] [security2:error] [pid 703393:tid 703638] [client 103.215.74.26:20054] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFS8637Arlr6Yb1EfpUQAAAPg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:31.568948 2026] [security2:error] [pid 703393:tid 703502] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/about.php7"] [unique_id "amuFS8637Arlr6Yb1EfpVQAAm2w"]
[Thu Jul 30 12:09:31.786569 2026] [security2:error] [pid 703393:tid 703556] [client 18.192.166.72:64022] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuFS8637Arlr6Yb1EfpVgAAAKY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:09:31.886463 2026] [security2:error] [pid 703393:tid 703504] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfanew.php7"] [unique_id "amuFS8637Arlr6Yb1EfpXQAAqm4"]
[Thu Jul 30 12:09:32.064308 2026] [core:notice] [pid 703393:tid 703559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:32.071795 2026] [security2:error] [pid 703393:tid 703559] [client 103.215.74.26:20064] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTM637Arlr6Yb1EfpXgAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:32.174420 2026] [core:notice] [pid 703393:tid 703583] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:32.178955 2026] [security2:error] [pid 703393:tid 703583] [client 18.192.166.72:64038] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTM637Arlr6Yb1EfpXwAAAME"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:09:32.260750 2026] [security2:error] [pid 703393:tid 703503] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminfuns.php7"] [unique_id "amuFTM637Arlr6Yb1EfpYAAAsG0"]
[Thu Jul 30 12:09:32.600336 2026] [security2:error] [pid 703393:tid 703508] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ebs.php7"] [unique_id "amuFTM637Arlr6Yb1EfpaAAAtnI"]
[Thu Jul 30 12:09:32.691790 2026] [security2:error] [pid 703393:tid 703549] [client 18.192.166.72:64040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuFTM637Arlr6Yb1EfpagAAAJ8"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:09:32.799340 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:32.806123 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:20072] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTM637Arlr6Yb1EfpbQAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:32.812487 2026] [security2:error] [pid 703393:tid 703588] [client 20.203.156.12:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/wp-load.php"] [unique_id "amuFTM637Arlr6Yb1EfpbgAAAMY"]
[Thu Jul 30 12:09:32.812644 2026] [security2:error] [pid 703393:tid 703588] [client 20.203.156.12:54936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/wp-load.php"] [unique_id "amuFTM637Arlr6Yb1EfpbgAAAMY"]
[Thu Jul 30 12:09:32.950514 2026] [security2:error] [pid 703393:tid 703511] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ws.php7"] [unique_id "amuFTM637Arlr6Yb1EfpdQAA8XU"]
[Thu Jul 30 12:09:33.291602 2026] [security2:error] [pid 703393:tid 703513] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfanew2.php7"] [unique_id "amuFTc637Arlr6Yb1EfpfAAAjXc"]
[Thu Jul 30 12:09:33.526008 2026] [security2:error] [pid 703393:tid 703512] [remote 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFTc637Arlr6Yb1EfpeQAAz3Y"], referer: https://www.spececigarette.com/wp-content/plugins/wc-rest-payment/Readme.txt
[Thu Jul 30 12:09:33.548526 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:33.555963 2026] [security2:error] [pid 703393:tid 703646] [client 103.215.74.26:54852] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTc637Arlr6Yb1EfphgAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:33.632728 2026] [security2:error] [pid 703393:tid 703517] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfa-rex2.php7"] [unique_id "amuFTc637Arlr6Yb1EfphwAApns"]
[Thu Jul 30 12:09:33.675133 2026] [core:notice] [pid 703393:tid 703638] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:33.939312 2026] [security2:error] [pid 703393:tid 703400] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuFTc637Arlr6Yb1EfpmQAA1QY"]
[Thu Jul 30 12:09:34.220426 2026] [security2:error] [pid 703393:tid 703584] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFTc637Arlr6Yb1EfplwAAwgA"]
[Thu Jul 30 12:09:34.277635 2026] [security2:error] [pid 703393:tid 703402] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "amuFTs637Arlr6Yb1EfpogAA2wg"]
[Thu Jul 30 12:09:34.286111 2026] [core:notice] [pid 703393:tid 703605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:34.293661 2026] [security2:error] [pid 703393:tid 703605] [client 103.215.74.26:54860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFTs637Arlr6Yb1EfpowAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:34.590165 2026] [security2:error] [pid 703393:tid 703415] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuFTs637Arlr6Yb1EfpsgAA6RU"]
[Thu Jul 30 12:09:34.887708 2026] [security2:error] [pid 703393:tid 703414] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "amuFTs637Arlr6Yb1EfpwAAAohQ"]
[Thu Jul 30 12:09:34.928088 2026] [security2:error] [pid 703393:tid 703529] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFTs637Arlr6Yb1EfprQAAi38"], referer: https://www.spececigarette.com/wp-content/plugins/wc-rest-payment/README.txt
[Thu Jul 30 12:09:35.196623 2026] [security2:error] [pid 703393:tid 703424] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuFT8637Arlr6Yb1EfpywAAuR4"]
[Thu Jul 30 12:09:35.312793 2026] [security2:error] [pid 703393:tid 703411] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "amuFT8637Arlr6Yb1Efp0QAAshE"]
[Thu Jul 30 12:09:35.513955 2026] [security2:error] [pid 703393:tid 703430] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "amuFT8637Arlr6Yb1Efp2QAAjCQ"]
[Thu Jul 30 12:09:35.566311 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:35.831804 2026] [security2:error] [pid 703393:tid 703433] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "amuFT8637Arlr6Yb1Efp4QAA9yc"]
[Thu Jul 30 12:09:35.943392 2026] [security2:error] [pid 703393:tid 703613] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFT8637Arlr6Yb1Efp3QAA3yY"]
[Thu Jul 30 12:09:36.174026 2026] [security2:error] [pid 703393:tid 703437] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/xmrlpc.php"] [unique_id "amuFUM637Arlr6Yb1Efp7QAApCs"]
[Thu Jul 30 12:09:36.493380 2026] [security2:error] [pid 703393:tid 703623] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFUM637Arlr6Yb1Efp6gAA6Sw"], referer: https://flixon.net/free-movies/
[Thu Jul 30 12:09:36.497066 2026] [security2:error] [pid 703393:tid 703436] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuFUM637Arlr6Yb1Efp_wAAsCo"]
[Thu Jul 30 12:09:36.653224 2026] [security2:error] [pid 703393:tid 703527] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFUM637Arlr6Yb1Efp-gAAiS0"], referer: https://www.spececigarette.com/wp-content/plugins/woocommerce/Readme.txt
[Thu Jul 30 12:09:36.772241 2026] [security2:error] [pid 703393:tid 703632] [client 65.109.100.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuFT8637Arlr6Yb1Efp4AAAAPI"]
[Thu Jul 30 12:09:36.822705 2026] [security2:error] [pid 703393:tid 703421] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/css/xmrlpc.php"] [unique_id "amuFUM637Arlr6Yb1EfqCQAAwBs"]
[Thu Jul 30 12:09:37.148277 2026] [security2:error] [pid 703393:tid 703454] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuFUc637Arlr6Yb1EfqEAAA1zw"]
[Thu Jul 30 12:09:37.188199 2026] [security2:error] [pid 703393:tid 703601] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFUM637Arlr6Yb1EfqCgAA0zA"]
[Thu Jul 30 12:09:37.452380 2026] [security2:error] [pid 703393:tid 703447] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/img/xmrlpc.php"] [unique_id "amuFUc637Arlr6Yb1EfqFgAA3DU"]
[Thu Jul 30 12:09:37.772826 2026] [security2:error] [pid 703393:tid 703425] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "amuFUc637Arlr6Yb1EfqHgAA-R8"]
[Thu Jul 30 12:09:37.794819 2026] [security2:error] [pid 703393:tid 703592] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFUc637Arlr6Yb1EfqDAAAyi4"], referer: https://flixon.net/free-movies/
[Thu Jul 30 12:09:38.088771 2026] [security2:error] [pid 703393:tid 703451] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "amuFUs637Arlr6Yb1EfqKgAAozk"]
[Thu Jul 30 12:09:38.414535 2026] [security2:error] [pid 703393:tid 703404] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/images/xmrlpc.php"] [unique_id "amuFUs637Arlr6Yb1EfqMQAA-Ao"]
[Thu Jul 30 12:09:38.768699 2026] [security2:error] [pid 703393:tid 703449] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "amuFUs637Arlr6Yb1EfqPQAAtTc"]
[Thu Jul 30 12:09:39.154692 2026] [security2:error] [pid 703393:tid 703427] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "amuFU8637Arlr6Yb1EfqSgAA1yE"]
[Thu Jul 30 12:09:39.503556 2026] [security2:error] [pid 703393:tid 703412] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "amuFU8637Arlr6Yb1EfqVwAApBI"]
[Thu Jul 30 12:09:39.847941 2026] [security2:error] [pid 703393:tid 703462] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "amuFU8637Arlr6Yb1EfqYwABAEQ"]
[Thu Jul 30 12:09:40.095357 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:40.102679 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:54868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFVM637Arlr6Yb1EfqZAAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:40.629672 2026] [security2:error] [pid 703393:tid 703472] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/xmrlpc.php"] [unique_id "amuFVM637Arlr6Yb1EfqhAAAsU4"]
[Thu Jul 30 12:09:40.787701 2026] [core:notice] [pid 703393:tid 703459] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:40.821486 2026] [core:notice] [pid 703393:tid 703612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:40.833344 2026] [security2:error] [pid 703393:tid 703612] [client 103.215.74.26:54870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFVM637Arlr6Yb1EfqkQAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:40.934270 2026] [security2:error] [pid 703393:tid 703481] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/text.php"] [unique_id "amuFVM637Arlr6Yb1EfqkwAA3Vc"]
[Thu Jul 30 12:09:41.237488 2026] [security2:error] [pid 703393:tid 703484] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuFVc637Arlr6Yb1EfqmwAAlVo"]
[Thu Jul 30 12:09:41.292126 2026] [core:notice] [pid 703393:tid 703487] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:41.523884 2026] [security2:error] [pid 703393:tid 703553] [client 172.237.109.114:60489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVc637Arlr6Yb1EfqlAAAAKM"]
[Thu Jul 30 12:09:41.565614 2026] [core:notice] [pid 703393:tid 703583] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:41.572679 2026] [security2:error] [pid 703393:tid 703583] [client 103.215.74.26:54872] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFVc637Arlr6Yb1EfqpgAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:41.579907 2026] [security2:error] [pid 703393:tid 703492] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/makeasmtp.php"] [unique_id "amuFVc637Arlr6Yb1EfqpwAAzGI"]
[Thu Jul 30 12:09:42.328351 2026] [core:notice] [pid 703393:tid 703569] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:42.335645 2026] [security2:error] [pid 703393:tid 703569] [client 103.215.74.26:54884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFVs637Arlr6Yb1EfqtgAAALM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:42.387267 2026] [autoindex:error] [pid 703393:tid 703599] [client 54.173.131.118:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:09:42.529803 2026] [security2:error] [pid 703393:tid 703533] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFVc637Arlr6Yb1EfqsQAAj2M"]
[Thu Jul 30 12:09:42.896502 2026] [security2:error] [pid 703393:tid 703581] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqvAAAv2A"], referer: https://www.spececigarette.com/wp-content/plugins/woocommerce/README.txt
[Thu Jul 30 12:09:43.052870 2026] [autoindex:error] [pid 703393:tid 703541] [client 54.173.131.118:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:09:43.112143 2026] [core:notice] [pid 703393:tid 703622] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:43.124667 2026] [security2:error] [pid 703393:tid 703622] [client 103.215.74.26:59936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFV8637Arlr6Yb1Efq2gAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:43.722383 2026] [security2:error] [pid 703393:tid 703502] [remote 20.16.180.61:58684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.180.16.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amuFV8637Arlr6Yb1Efq5wAAtWw"]
[Thu Jul 30 12:09:43.852128 2026] [core:notice] [pid 703393:tid 703614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:43.861256 2026] [security2:error] [pid 703393:tid 703614] [client 103.215.74.26:59952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFV8637Arlr6Yb1Efq6AAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:44.339830 2026] [security2:error] [pid 703393:tid 703564] [client 172.237.109.114:26336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqxwAAAK4"]
[Thu Jul 30 12:09:44.357723 2026] [security2:error] [pid 703393:tid 703613] [client 172.237.109.114:33511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqxgAAAN8"]
[Thu Jul 30 12:09:44.417653 2026] [security2:error] [pid 703393:tid 703611] [client 172.237.109.114:50086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq0AAAAN0"]
[Thu Jul 30 12:09:44.421217 2026] [security2:error] [pid 703393:tid 703626] [client 172.237.109.114:62967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqywAAAOw"]
[Thu Jul 30 12:09:44.429030 2026] [security2:error] [pid 703393:tid 703593] [client 172.237.109.114:45408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqzQAAAMs"]
[Thu Jul 30 12:09:44.452360 2026] [security2:error] [pid 703393:tid 703636] [client 172.237.109.114:64606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqzAAAAPY"]
[Thu Jul 30 12:09:44.458723 2026] [security2:error] [pid 703393:tid 703579] [client 172.237.109.114:1626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq0gAAAL0"]
[Thu Jul 30 12:09:44.461189 2026] [security2:error] [pid 703393:tid 703590] [client 172.237.109.114:5827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq1QAAAMg"]
[Thu Jul 30 12:09:44.461435 2026] [security2:error] [pid 703393:tid 703526] [client 172.237.109.114:60289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq1gAAAIg"]
[Thu Jul 30 12:09:44.464350 2026] [security2:error] [pid 703393:tid 703628] [client 172.237.109.114:6649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqygAAAO4"]
[Thu Jul 30 12:09:44.465865 2026] [security2:error] [pid 703393:tid 703650] [client 172.237.109.114:46585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqyAAAAQQ"]
[Thu Jul 30 12:09:44.472813 2026] [security2:error] [pid 703393:tid 703603] [client 172.237.109.114:9050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqzwAAANU"]
[Thu Jul 30 12:09:44.473454 2026] [security2:error] [pid 703393:tid 703625] [client 172.237.109.114:30972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqzgAAAOs"]
[Thu Jul 30 12:09:44.486396 2026] [security2:error] [pid 703393:tid 703604] [client 172.237.109.114:30216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq0wAAANY"]
[Thu Jul 30 12:09:44.487732 2026] [security2:error] [pid 703393:tid 703543] [client 172.237.109.114:8470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1EfqyQAAAJk"]
[Thu Jul 30 12:09:44.491139 2026] [security2:error] [pid 703393:tid 703532] [client 172.237.109.114:28188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq1AAAAI4"]
[Thu Jul 30 12:09:44.496625 2026] [security2:error] [pid 703393:tid 703606] [client 172.237.109.114:41957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFV8637Arlr6Yb1Efq2AAAANg"]
[Thu Jul 30 12:09:44.502411 2026] [security2:error] [pid 703393:tid 703528] [client 172.237.109.114:25686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq1wAAAIo"]
[Thu Jul 30 12:09:44.502631 2026] [security2:error] [pid 703393:tid 703534] [client 172.237.109.114:40503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFVs637Arlr6Yb1Efq0QAAAJA"]
[Thu Jul 30 12:09:44.593617 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:44.601230 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:59966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFWM637Arlr6Yb1EfrCwAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:44.762679 2026] [security2:error] [pid 703393:tid 703535] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFWM637Arlr6Yb1EfrBwAAkWs"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:09:44.929404 2026] [security2:error] [pid 703393:tid 703533] [client 121.229.156.67:40298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "azureskyfilms.com"] [uri "/"] [unique_id "amuFWM637Arlr6Yb1EfrEAAAAI8"]
[Thu Jul 30 12:09:44.929532 2026] [security2:error] [pid 703393:tid 703533] [client 121.229.156.67:40298] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "azureskyfilms.com"] [uri "/"] [unique_id "amuFWM637Arlr6Yb1EfrEAAAAI8"]
[Thu Jul 30 12:09:45.323102 2026] [core:notice] [pid 703393:tid 703601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:45.334080 2026] [security2:error] [pid 703393:tid 703601] [client 103.215.74.26:59968] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFWc637Arlr6Yb1EfrGgAAANM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:46.008070 2026] [security2:error] [pid 703393:tid 703627] [client 213.152.187.215:48904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuFWs637Arlr6Yb1EfrJwAAAO0"]
[Thu Jul 30 12:09:46.008182 2026] [security2:error] [pid 703393:tid 703627] [client 213.152.187.215:48904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuFWs637Arlr6Yb1EfrJwAAAO0"]
[Thu Jul 30 12:09:46.030381 2026] [security2:error] [pid 703393:tid 703561] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFWc637Arlr6Yb1EfrGQAAq3Q"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:09:46.081464 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:46.089362 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:59970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFWs637Arlr6Yb1EfrKwAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:46.820102 2026] [core:notice] [pid 703393:tid 703559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:46.827269 2026] [security2:error] [pid 703393:tid 703559] [client 103.215.74.26:59974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFWs637Arlr6Yb1EfrOQAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:47.454666 2026] [security2:error] [pid 703393:tid 703576] [client 185.189.112.11:39756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuFW8637Arlr6Yb1EfrRgAAALo"]
[Thu Jul 30 12:09:47.454776 2026] [security2:error] [pid 703393:tid 703576] [client 185.189.112.11:39756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuFW8637Arlr6Yb1EfrRgAAALo"]
[Thu Jul 30 12:09:47.556099 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:47.566740 2026] [security2:error] [pid 703393:tid 703600] [client 103.215.74.26:59988] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFW8637Arlr6Yb1EfrSgAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:47.740206 2026] [security2:error] [pid 703393:tid 703529] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFW8637Arlr6Yb1EfrQwAAi30"]
[Thu Jul 30 12:09:48.298884 2026] [security2:error] [pid 703393:tid 703413] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/mainichi-shopify-products-connect/readme.txt"] [unique_id "amuFXM637Arlr6Yb1EfrVwABAhM"]
[Thu Jul 30 12:09:48.301379 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:48.309305 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:59990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFXM637Arlr6Yb1EfrWAAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:48.971712 2026] [security2:error] [pid 703393:tid 703611] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFXM637Arlr6Yb1EfrXgAA3Qs"]
[Thu Jul 30 12:09:49.015218 2026] [security2:error] [pid 703393:tid 703592] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFXM637Arlr6Yb1EfrXQAAygU"]
[Thu Jul 30 12:09:49.036078 2026] [core:notice] [pid 703393:tid 703551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:49.042957 2026] [security2:error] [pid 703393:tid 703551] [client 103.215.74.26:60006] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFXc637Arlr6Yb1EfrbAAAAKE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:49.771605 2026] [core:notice] [pid 703393:tid 703553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:49.778868 2026] [security2:error] [pid 703393:tid 703553] [client 103.215.74.26:60008] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFXc637Arlr6Yb1EfrfQAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:50.504291 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:50.511013 2026] [security2:error] [pid 703393:tid 703600] [client 103.215.74.26:60020] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFXs637Arlr6Yb1EfrhgAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:50.734278 2026] [security2:error] [pid 703393:tid 703566] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFXs637Arlr6Yb1EfrhQAAsCg"], referer: https://www.spececigarette.com/wp-content/plugins/mainichi-shopify-products-connect/Readme.txt
[Thu Jul 30 12:09:51.247346 2026] [core:notice] [pid 703393:tid 703595] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:51.248814 2026] [security2:error] [pid 703393:tid 703640] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFXs637Arlr6Yb1EfrjwAA-io"]
[Thu Jul 30 12:09:51.253875 2026] [security2:error] [pid 703393:tid 703595] [client 103.215.74.26:60032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFX8637Arlr6Yb1EfrkgAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:51.990391 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:51.998010 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:60044] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFX8637Arlr6Yb1EfrpQAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:52.212854 2026] [security2:error] [pid 703393:tid 703560] [client 65.55.210.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuFYM637Arlr6Yb1EfrqAAAAKo"]
[Thu Jul 30 12:09:52.314325 2026] [security2:error] [pid 703393:tid 703539] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFX8637Arlr6Yb1EfrpAAAlTA"], referer: https://www.spececigarette.com/wp-content/plugins/mainichi-shopify-products-connect/README.txt
[Thu Jul 30 12:09:52.657277 2026] [core:error] [pid 703393:tid 703444] [remote 74.7.175.163:39466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:09:52.657304 2026] [core:error] [pid 703393:tid 703444] [remote 74.7.175.163:39466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:09:52.657563 2026] [security2:error] [pid 703393:tid 703643] [client 74.7.175.163:39466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/index.php"] [unique_id "amuFYM637Arlr6Yb1EfrswAA_TI"]
[Thu Jul 30 12:09:52.705262 2026] [security2:error] [pid 703393:tid 703425] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/fuse-social-floating-sidebar/readme.txt"] [unique_id "amuFYM637Arlr6Yb1EfrtAAAzB8"]
[Thu Jul 30 12:09:54.163146 2026] [security2:error] [pid 703393:tid 703608] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFYc637Arlr6Yb1EfryAAA2j8"]
[Thu Jul 30 12:09:54.891663 2026] [security2:error] [pid 703393:tid 703561] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFYs637Arlr6Yb1Efr1wAAqzc"], referer: https://www.spececigarette.com/wp-content/plugins/fuse-social-floating-sidebar/Readme.txt
[Thu Jul 30 12:09:55.398992 2026] [security2:error] [pid 703393:tid 703559] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFY8637Arlr6Yb1Efr6AAAqTY"]
[Thu Jul 30 12:09:57.781704 2026] [core:notice] [pid 703393:tid 703578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:57.790144 2026] [security2:error] [pid 703393:tid 703578] [client 103.215.74.26:13364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFZc637Arlr6Yb1EfsQAAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:58.517246 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:58.524184 2026] [security2:error] [pid 703393:tid 703646] [client 103.215.74.26:13378] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFZs637Arlr6Yb1EfsTQAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:59.249665 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:59.256005 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:13388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFZ8637Arlr6Yb1EfsXwAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:09:59.537681 2026] [security2:error] [pid 703393:tid 703541] [client 66.249.66.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dapperdangolf.com"] [uri "/index.php"] [unique_id "amuFZc637Arlr6Yb1EfsLgAAl1A"]
[Thu Jul 30 12:09:59.985893 2026] [core:notice] [pid 703393:tid 703634] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:09:59.992763 2026] [security2:error] [pid 703393:tid 703634] [client 103.215.74.26:13396] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFZ8637Arlr6Yb1EfscAAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:00.713961 2026] [core:notice] [pid 703393:tid 703628] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:00.721136 2026] [security2:error] [pid 703393:tid 703628] [client 103.215.74.26:13406] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFaM637Arlr6Yb1EfslwAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:01.135724 2026] [security2:error] [pid 703393:tid 703592] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFaM637Arlr6Yb1EfslAAAynA"], referer: https://www.spececigarette.com/wp-content/plugins/fuse-social-floating-sidebar/README.txt
[Thu Jul 30 12:10:01.269051 2026] [security2:error] [pid 703393:tid 703591] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFaM637Arlr6Yb1EfsjwAAyXE"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:01.462717 2026] [core:notice] [pid 703393:tid 703612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:01.470283 2026] [security2:error] [pid 703393:tid 703612] [client 103.215.74.26:13414] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFac637Arlr6Yb1EfsxAAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:01.488414 2026] [security2:error] [pid 703393:tid 703437] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/slick-popup/readme.txt"] [unique_id "amuFac637Arlr6Yb1EfsxQAAoys"]
[Thu Jul 30 12:10:02.192424 2026] [security2:error] [pid 703393:tid 703582] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFac637Arlr6Yb1EfszwAAwC8"]
[Thu Jul 30 12:10:02.916296 2026] [security2:error] [pid 703393:tid 703599] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFas637Arlr6Yb1Efs4AAA0RA"], referer: https://www.spececigarette.com/wp-content/plugins/slick-popup/Readme.txt
[Thu Jul 30 12:10:03.460608 2026] [security2:error] [pid 703393:tid 703594] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFa8637Arlr6Yb1Efs7QAAzC4"]
[Thu Jul 30 12:10:03.997882 2026] [security2:error] [pid 703393:tid 703601] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFa8637Arlr6Yb1EftAgAA0zg"], referer: https://www.spececigarette.com/wp-content/plugins/slick-popup/README.txt
[Thu Jul 30 12:10:04.306059 2026] [security2:error] [pid 703393:tid 703455] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/rishi-checkout-for-woocommerce/readme.txt"] [unique_id "amuFbM637Arlr6Yb1EftEgAAiD0"]
[Thu Jul 30 12:10:04.927910 2026] [security2:error] [pid 703393:tid 703420] [remote 74.7.241.59:36728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuFbM637Arlr6Yb1EftJwAAhxo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:10:05.064049 2026] [core:notice] [pid 703393:tid 703462] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:05.379790 2026] [security2:error] [pid 703393:tid 703580] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFbM637Arlr6Yb1EftIgAAvjY"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:05.499914 2026] [core:notice] [pid 703393:tid 703556] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:06.110476 2026] [security2:error] [pid 703393:tid 703536] [client 185.189.112.11:46434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFbs637Arlr6Yb1EftQQAAAJI"]
[Thu Jul 30 12:10:06.110556 2026] [security2:error] [pid 703393:tid 703536] [client 185.189.112.11:46434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFbs637Arlr6Yb1EftQQAAAJI"]
[Thu Jul 30 12:10:06.116678 2026] [security2:error] [pid 703393:tid 703544] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFbc637Arlr6Yb1EftNwAAmks"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:06.161746 2026] [security2:error] [pid 703393:tid 703540] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFbc637Arlr6Yb1EftOQAAlk8"]
[Thu Jul 30 12:10:06.294644 2026] [security2:error] [pid 703393:tid 703477] [remote 74.7.241.60:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuFbs637Arlr6Yb1EftRgAA0FM"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:10:06.556296 2026] [core:notice] [pid 703393:tid 703564] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:06.678765 2026] [security2:error] [pid 703393:tid 703530] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFbs637Arlr6Yb1EftRAAAjEY"], referer: https://www.spececigarette.com/wp-content/plugins/rishi-checkout-for-woocommerce/Readme.txt
[Thu Jul 30 12:10:07.099949 2026] [security2:error] [pid 703393:tid 703609] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFbs637Arlr6Yb1EftVwAA214"]
[Thu Jul 30 12:10:07.194406 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:07.201481 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:35514] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFb8637Arlr6Yb1EftYQAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:07.790823 2026] [security2:error] [pid 703393:tid 703528] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFb8637Arlr6Yb1EftZwAAimE"], referer: https://www.spececigarette.com/wp-content/plugins/rishi-checkout-for-woocommerce/README.txt
[Thu Jul 30 12:10:07.928262 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:07.934610 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:35528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFb8637Arlr6Yb1EftcAAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:08.170639 2026] [security2:error] [pid 703393:tid 703501] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/worth-the-read/readme.txt"] [unique_id "amuFcM637Arlr6Yb1EfteQAAzGs"]
[Thu Jul 30 12:10:08.681005 2026] [core:notice] [pid 703393:tid 703598] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:08.689456 2026] [security2:error] [pid 703393:tid 703598] [client 103.215.74.26:35530] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFcM637Arlr6Yb1EftgwAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:08.952568 2026] [core:notice] [pid 703393:tid 703650] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:09.345609 2026] [security2:error] [pid 703393:tid 703509] [remote 216.73.216.152:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuFcc637Arlr6Yb1EftkgAA6HM"]
[Thu Jul 30 12:10:09.418517 2026] [core:notice] [pid 703393:tid 703579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:09.425403 2026] [security2:error] [pid 703393:tid 703579] [client 103.215.74.26:35536] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFcc637Arlr6Yb1EftlQAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:09.623825 2026] [security2:error] [pid 703393:tid 703539] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFcc637Arlr6Yb1EftjgAAlXI"]
[Thu Jul 30 12:10:10.139467 2026] [security2:error] [pid 703393:tid 703611] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFcc637Arlr6Yb1EftngAA3Xo"], referer: https://www.spececigarette.com/wp-content/plugins/worth-the-read/Readme.txt
[Thu Jul 30 12:10:10.151708 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:10.158044 2026] [security2:error] [pid 703393:tid 703646] [client 103.215.74.26:35550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFcs637Arlr6Yb1EftoQAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:10.546338 2026] [security2:error] [pid 703393:tid 703632] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFcs637Arlr6Yb1EftqAAA8nw"]
[Thu Jul 30 12:10:10.884572 2026] [core:notice] [pid 703393:tid 703571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:10.891116 2026] [security2:error] [pid 703393:tid 703571] [client 103.215.74.26:35554] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFcs637Arlr6Yb1EftsgAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:11.163036 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:11.459511 2026] [security2:error] [pid 703393:tid 703633] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFcs637Arlr6Yb1EftsQAApns"], referer: https://www.spececigarette.com/wp-content/plugins/worth-the-read/README.txt
[Thu Jul 30 12:10:11.465718 2026] [security2:error] [pid 703393:tid 703519] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/spec-theme-options/readme.txt"] [unique_id "amuFc8637Arlr6Yb1EftuwABBH0"]
[Thu Jul 30 12:10:11.632188 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:11.639809 2026] [security2:error] [pid 703393:tid 703624] [client 103.215.74.26:35562] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFc8637Arlr6Yb1EftvQAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:11.773231 2026] [security2:error] [pid 703393:tid 703649] [client 185.200.117.131:53994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuFc8637Arlr6Yb1EftvAAAAQM"]
[Thu Jul 30 12:10:11.773382 2026] [security2:error] [pid 703393:tid 703649] [client 185.200.117.131:53994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuFc8637Arlr6Yb1EftvAAAAQM"]
[Thu Jul 30 12:10:12.419015 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:12.425041 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:35578] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFdM637Arlr6Yb1EftyQAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:13.153054 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:13.160400 2026] [security2:error] [pid 703393:tid 703600] [client 103.215.74.26:34976] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFdc637Arlr6Yb1Eft2AAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:13.880125 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:13.887602 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:34978] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFdc637Arlr6Yb1Eft6wAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:14.045256 2026] [security2:error] [pid 703393:tid 703598] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFdc637Arlr6Yb1Eft4gAAANA"]
[Thu Jul 30 12:10:14.615255 2026] [core:notice] [pid 703393:tid 703542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:14.624299 2026] [security2:error] [pid 703393:tid 703542] [client 103.215.74.26:34994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFds637Arlr6Yb1Eft_AAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:15.053205 2026] [core:notice] [pid 703393:tid 703553] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:15.343378 2026] [core:notice] [pid 703393:tid 703576] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:15.347548 2026] [security2:error] [pid 703393:tid 703646] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFds637Arlr6Yb1EfuAAAAAQA"]
[Thu Jul 30 12:10:15.350897 2026] [security2:error] [pid 703393:tid 703576] [client 103.215.74.26:34996] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFd8637Arlr6Yb1EfuEQAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:15.386933 2026] [core:notice] [pid 703393:tid 703571] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:15.522395 2026] [security2:error] [pid 703393:tid 703570] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFds637Arlr6Yb1EfuAQAAtCU"]
[Thu Jul 30 12:10:15.727768 2026] [security2:error] [pid 703393:tid 703618] [client 74.7.175.180:57232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "arabian-tours.com"] [uri "/cgi-sys/404.html"] [unique_id "amuFd8637Arlr6Yb1EfuHwAA5DU"]
[Thu Jul 30 12:10:16.088335 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:16.095805 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:35002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFeM637Arlr6Yb1EfuJAAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:16.215529 2026] [core:notice] [pid 703393:tid 703442] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:16.220285 2026] [security2:error] [pid 703393:tid 703607] [client 87.250.224.116:44656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/1316"] [unique_id "amuFd8637Arlr6Yb1EfuIAAA2TA"]
[Thu Jul 30 12:10:16.825919 2026] [core:notice] [pid 703393:tid 703589] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:16.832904 2026] [security2:error] [pid 703393:tid 703589] [client 103.215.74.26:35016] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFeM637Arlr6Yb1EfuMwAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:17.087042 2026] [core:notice] [pid 703393:tid 703422] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:17.105939 2026] [security2:error] [pid 703393:tid 703609] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFeM637Arlr6Yb1EfuMgAA2w0"]
[Thu Jul 30 12:10:17.343423 2026] [security2:error] [pid 703393:tid 703547] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFeM637Arlr6Yb1EfuMQAAnRA"], referer: https://flixon.net/v/ideo_tag/vj-ice-p
[Thu Jul 30 12:10:17.565640 2026] [core:notice] [pid 703393:tid 703587] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:17.573184 2026] [security2:error] [pid 703393:tid 703587] [client 103.215.74.26:35018] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFec637Arlr6Yb1EfuQgAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:17.799285 2026] [security2:error] [pid 703393:tid 703445] [remote 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFec637Arlr6Yb1EfuQQAApTM"], referer: https://www.spececigarette.com/wp-content/plugins/spec-theme-options/Readme.txt
[Thu Jul 30 12:10:18.296562 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:18.302677 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:35022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFes637Arlr6Yb1EfuVgAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:18.310189 2026] [security2:error] [pid 703393:tid 703572] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFec637Arlr6Yb1EfuTAAAtjc"]
[Thu Jul 30 12:10:18.387331 2026] [security2:error] [pid 703393:tid 703600] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFec637Arlr6Yb1EfuSQAA0j0"], referer: https://flixon.net/v/ideo_tag/vj-ice-p
[Thu Jul 30 12:10:19.034499 2026] [core:notice] [pid 703393:tid 703603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:19.043013 2026] [security2:error] [pid 703393:tid 703603] [client 103.215.74.26:35034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFe8637Arlr6Yb1EfuYwAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:19.775382 2026] [core:notice] [pid 703393:tid 703532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:19.782238 2026] [security2:error] [pid 703393:tid 703532] [client 103.215.74.26:35050] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFe8637Arlr6Yb1EfudAAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:19.820091 2026] [core:notice] [pid 703393:tid 703567] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:19.824542 2026] [security2:error] [pid 703393:tid 703567] [client 74.0.19.12:37825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/3849/1891/10502"] [unique_id "amuFe8637Arlr6Yb1EfucAAAALE"]
[Thu Jul 30 12:10:20.512785 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:20.519304 2026] [security2:error] [pid 703393:tid 703619] [client 103.215.74.26:35052] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFfM637Arlr6Yb1EfuiQAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:20.781813 2026] [security2:error] [pid 703393:tid 703562] [client 172.236.9.101:6411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfM637Arlr6Yb1EfugQAAAKw"]
[Thu Jul 30 12:10:20.850231 2026] [security2:error] [pid 703393:tid 703531] [client 172.236.9.101:59950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfM637Arlr6Yb1EfugwAAAI0"]
[Thu Jul 30 12:10:20.857895 2026] [security2:error] [pid 703393:tid 703529] [client 172.236.9.101:1278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfM637Arlr6Yb1EfuhAAAAIs"]
[Thu Jul 30 12:10:20.859940 2026] [security2:error] [pid 703393:tid 703614] [client 172.236.9.101:57009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfM637Arlr6Yb1EfuhQAAAOA"]
[Thu Jul 30 12:10:21.031282 2026] [core:notice] [pid 703393:tid 703535] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:21.246434 2026] [core:notice] [pid 703393:tid 703650] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:21.254218 2026] [security2:error] [pid 703393:tid 703650] [client 103.215.74.26:35062] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFfc637Arlr6Yb1EfulwAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:21.771230 2026] [security2:error] [pid 703393:tid 703635] [client 172.236.9.101:57650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfumAAAAPU"]
[Thu Jul 30 12:10:21.771381 2026] [security2:error] [pid 703393:tid 703565] [client 172.236.9.101:60608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfumQAAAK8"]
[Thu Jul 30 12:10:21.776399 2026] [security2:error] [pid 703393:tid 703607] [client 172.236.9.101:17080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfumgAAANk"]
[Thu Jul 30 12:10:21.794166 2026] [security2:error] [pid 703393:tid 703525] [client 172.236.9.101:24470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfumwAAAIc"]
[Thu Jul 30 12:10:21.868070 2026] [security2:error] [pid 703393:tid 703604] [client 172.236.9.101:46239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFfc637Arlr6Yb1EfunAAAANY"]
[Thu Jul 30 12:10:21.981168 2026] [core:notice] [pid 703393:tid 703534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:21.988792 2026] [security2:error] [pid 703393:tid 703534] [client 103.215.74.26:35076] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFfc637Arlr6Yb1EfupwAAAJA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:22.764044 2026] [security2:error] [pid 703393:tid 703600] [client 20.100.187.180:57294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuFfs637Arlr6Yb1EfuuQAAANI"]
[Thu Jul 30 12:10:22.764183 2026] [security2:error] [pid 703393:tid 703600] [client 20.100.187.180:57294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuFfs637Arlr6Yb1EfuuQAAANI"]
[Thu Jul 30 12:10:23.395908 2026] [security2:error] [pid 703393:tid 703548] [client 74.7.175.180:40164] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.openspacelab.tech"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuFf8637Arlr6Yb1EfuxAAAAJ4"]
[Thu Jul 30 12:10:23.938717 2026] [security2:error] [pid 703393:tid 703544] [client 20.203.156.12:12988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/index.php"] [unique_id "amuFf8637Arlr6Yb1EfuzAAAAJo"]
[Thu Jul 30 12:10:23.938829 2026] [security2:error] [pid 703393:tid 703544] [client 20.203.156.12:12988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/index.php"] [unique_id "amuFf8637Arlr6Yb1EfuzAAAAJo"]
[Thu Jul 30 12:10:24.050096 2026] [security2:error] [pid 703393:tid 703626] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFf8637Arlr6Yb1EfuyAAA7E0"], referer: https://www.spececigarette.com/wp-content/plugins/spec-theme-options/README.txt
[Thu Jul 30 12:10:24.434019 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:25.413421 2026] [security2:error] [pid 703393:tid 703504] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/stacks-mobile-app-builder/readme.txt"] [unique_id "amuFgc637Arlr6Yb1Efu5wAAjG4"]
[Thu Jul 30 12:10:26.089116 2026] [security2:error] [pid 703393:tid 703569] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFgc637Arlr6Yb1Efu7gAAs2o"]
[Thu Jul 30 12:10:27.765786 2026] [core:notice] [pid 703393:tid 703612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:27.776691 2026] [security2:error] [pid 703393:tid 703612] [client 103.215.74.26:60848] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFg8637Arlr6Yb1EfvEgAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:28.505511 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:28.512697 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:60850] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFhM637Arlr6Yb1EfvHQAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:28.530059 2026] [security2:error] [pid 703393:tid 703586] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFg8637Arlr6Yb1EfvEwAAxAE"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:28.995824 2026] [security2:error] [pid 703393:tid 703557] [client 20.100.187.180:59988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuFhM637Arlr6Yb1EfvLgAAAKc"]
[Thu Jul 30 12:10:28.995920 2026] [security2:error] [pid 703393:tid 703557] [client 20.100.187.180:59988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuFhM637Arlr6Yb1EfvLgAAAKc"]
[Thu Jul 30 12:10:29.232400 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:29.238858 2026] [security2:error] [pid 703393:tid 703621] [client 103.215.74.26:60862] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFhc637Arlr6Yb1EfvNQAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:29.459202 2026] [security2:error] [pid 703393:tid 703591] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFhM637Arlr6Yb1EfvKAAAyQg"], referer: https://flixon.net/wp-content/uploads/2025/11/FlixOn-Movhref=https:/flixon.net/wp-content/uploads/2026/02/Flix-On-Movies_V1.apkies.apk
[Thu Jul 30 12:10:29.980626 2026] [core:notice] [pid 703393:tid 703628] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:29.987349 2026] [security2:error] [pid 703393:tid 703628] [client 103.215.74.26:60874] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFhc637Arlr6Yb1EfvQwAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:30.706142 2026] [core:notice] [pid 703393:tid 703602] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:30.714408 2026] [security2:error] [pid 703393:tid 703602] [client 103.215.74.26:60878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFhs637Arlr6Yb1EfvVQAAANQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:30.889792 2026] [core:notice] [pid 703393:tid 703539] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:30.920288 2026] [security2:error] [pid 703393:tid 703573] [client 41.210.146.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuFhs637Arlr6Yb1EfvRQAAtxU"], referer: https://flixon.net/free-movies/
[Thu Jul 30 12:10:31.394299 2026] [core:notice] [pid 703393:tid 703605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:31.421430 2026] [core:notice] [pid 703393:tid 703647] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:31.428793 2026] [security2:error] [pid 703393:tid 703647] [client 103.215.74.26:60886] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFh8637Arlr6Yb1EfvZgAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:31.549965 2026] [core:notice] [pid 703393:tid 703418] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:31.608622 2026] [security2:error] [pid 703393:tid 703587] [client 20.100.187.180:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuFh8637Arlr6Yb1EfvawAAAMU"]
[Thu Jul 30 12:10:31.608737 2026] [security2:error] [pid 703393:tid 703587] [client 20.100.187.180:60014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuFh8637Arlr6Yb1EfvawAAAMU"]
[Thu Jul 30 12:10:31.808915 2026] [core:notice] [pid 703393:tid 703506] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:31.817172 2026] [security2:error] [pid 703393:tid 703635] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFh8637Arlr6Yb1EfvZQAA9Qs"], referer: https://www.spececigarette.com/wp-content/plugins/stacks-mobile-app-builder/Readme.txt
[Thu Jul 30 12:10:32.193132 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:32.203913 2026] [security2:error] [pid 703393:tid 703600] [client 103.215.74.26:60890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFiM637Arlr6Yb1EfveQAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:32.540249 2026] [security2:error] [pid 703393:tid 703636] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFiM637Arlr6Yb1EfvegAA9iw"]
[Thu Jul 30 12:10:32.940127 2026] [core:notice] [pid 703393:tid 703576] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:32.946726 2026] [security2:error] [pid 703393:tid 703576] [client 103.215.74.26:60896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFiM637Arlr6Yb1EfvhgAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:33.218929 2026] [security2:error] [pid 703393:tid 703622] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFiM637Arlr6Yb1EfvggAA6C0"], referer: https://www.spececigarette.com/wp-content/plugins/stacks-mobile-app-builder/README.txt
[Thu Jul 30 12:10:33.667748 2026] [core:notice] [pid 703393:tid 703606] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:33.674399 2026] [security2:error] [pid 703393:tid 703606] [client 103.215.74.26:8264] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFic637Arlr6Yb1EfvkgAAANg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:34.419838 2026] [security2:error] [pid 703393:tid 703425] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/popup-maker/readme.txt"] [unique_id "amuFis637Arlr6Yb1EfvoQAAtB8"]
[Thu Jul 30 12:10:35.047943 2026] [security2:error] [pid 703393:tid 703607] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFis637Arlr6Yb1EfvqAAA2TE"]
[Thu Jul 30 12:10:35.088554 2026] [security2:error] [pid 703393:tid 703409] [remote 57.141.0.33:50878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuFi8637Arlr6Yb1EfvsQAApw8"]
[Thu Jul 30 12:10:35.591340 2026] [security2:error] [pid 703393:tid 703536] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFis637Arlr6Yb1EfvrwAAkj8"]
[Thu Jul 30 12:10:35.745301 2026] [security2:error] [pid 703393:tid 703531] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFi8637Arlr6Yb1EfvtwAAjS4"], referer: https://www.spececigarette.com/wp-content/plugins/popup-maker/Readme.txt
[Thu Jul 30 12:10:36.249108 2026] [security2:error] [pid 703393:tid 703548] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFi8637Arlr6Yb1EfvvwAAnjc"]
[Thu Jul 30 12:10:36.626027 2026] [core:notice] [pid 703393:tid 703601] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:36.720375 2026] [security2:error] [pid 703393:tid 703584] [client 20.100.187.180:37070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/err.php"] [unique_id "amuFjM637Arlr6Yb1EfvywAAAMI"]
[Thu Jul 30 12:10:36.720473 2026] [security2:error] [pid 703393:tid 703584] [client 20.100.187.180:37070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/err.php"] [unique_id "amuFjM637Arlr6Yb1EfvywAAAMI"]
[Thu Jul 30 12:10:37.201663 2026] [core:notice] [pid 703393:tid 703539] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:37.929685 2026] [security2:error] [pid 703393:tid 703542] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFjc637Arlr6Yb1Efv1wAAmA4"], referer: https://www.spececigarette.com/wp-content/plugins/popup-maker/README.txt
[Thu Jul 30 12:10:39.338580 2026] [security2:error] [pid 703393:tid 703540] [client 20.100.187.180:60029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/img.php"] [unique_id "amuFj8637Arlr6Yb1Efv8wAAAJY"]
[Thu Jul 30 12:10:39.338695 2026] [security2:error] [pid 703393:tid 703540] [client 20.100.187.180:60029] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/img.php"] [unique_id "amuFj8637Arlr6Yb1Efv8wAAAJY"]
[Thu Jul 30 12:10:39.456872 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:39.463366 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:8278] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFj8637Arlr6Yb1Efv-AAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:40.165372 2026] [core:notice] [pid 703393:tid 703600] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:40.186136 2026] [core:notice] [pid 703393:tid 703574] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:40.192898 2026] [security2:error] [pid 703393:tid 703574] [client 103.215.74.26:8294] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFkM637Arlr6Yb1EfwAwAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:40.925848 2026] [core:notice] [pid 703393:tid 703545] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:40.936719 2026] [security2:error] [pid 703393:tid 703545] [client 103.215.74.26:8302] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFkM637Arlr6Yb1EfwFQAAAJs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:41.170333 2026] [security2:error] [pid 703393:tid 703592] [client 2.51.55.76:52433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFkM637Arlr6Yb1EfwDQAAykY"]
[Thu Jul 30 12:10:41.349585 2026] [security2:error] [pid 703393:tid 703592] [client 2.51.55.76:52433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFkM637Arlr6Yb1EfwDAAAylw"]
[Thu Jul 30 12:10:41.350069 2026] [security2:error] [pid 703393:tid 703592] [client 2.51.55.76:52433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuFkM637Arlr6Yb1EfwCwAAykw"]
[Thu Jul 30 12:10:41.489224 2026] [security2:error] [pid 703393:tid 703580] [client 20.100.187.180:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/aa.php"] [unique_id "amuFkc637Arlr6Yb1EfwHwAAAL4"]
[Thu Jul 30 12:10:41.489368 2026] [security2:error] [pid 703393:tid 703580] [client 20.100.187.180:23450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/aa.php"] [unique_id "amuFkc637Arlr6Yb1EfwHwAAAL4"]
[Thu Jul 30 12:10:41.640816 2026] [security2:error] [pid 703393:tid 703627] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFkc637Arlr6Yb1EfwIAAA7V4"]
[Thu Jul 30 12:10:41.678483 2026] [core:notice] [pid 703393:tid 703533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:41.684641 2026] [security2:error] [pid 703393:tid 703533] [client 103.215.74.26:8304] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFkc637Arlr6Yb1EfwJgAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:42.109545 2026] [security2:error] [pid 703393:tid 703639] [client 35.204.157.49:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "ad-company.net"] [uri "/"] [unique_id "amuFks637Arlr6Yb1EfwNAAAAPk"]
[Thu Jul 30 12:10:42.109658 2026] [security2:error] [pid 703393:tid 703639] [client 35.204.157.49:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ad-company.net"] [uri "/"] [unique_id "amuFks637Arlr6Yb1EfwNAAAAPk"]
[Thu Jul 30 12:10:42.406139 2026] [core:notice] [pid 703393:tid 703561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:42.413553 2026] [security2:error] [pid 703393:tid 703561] [client 103.215.74.26:8316] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFks637Arlr6Yb1EfwNgAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:42.858694 2026] [core:notice] [pid 703393:tid 703497] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:43.026749 2026] [proxy:error] [pid 703393:tid 703478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:10:43.026803 2026] [proxy_http:error] [pid 703393:tid 703478] [remote 74.7.230.40:44910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:10:43.027380 2026] [proxy:error] [pid 703393:tid 703478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:10:43.027425 2026] [proxy_http:error] [pid 703393:tid 703478] [remote 74.7.230.40:44910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:10:43.093524 2026] [core:notice] [pid 703393:tid 703505] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:43.141655 2026] [core:notice] [pid 703393:tid 703527] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:43.149163 2026] [security2:error] [pid 703393:tid 703527] [client 103.215.74.26:21190] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFk8637Arlr6Yb1EfwSAAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:43.156172 2026] [core:notice] [pid 703393:tid 703540] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:43.310600 2026] [security2:error] [pid 703393:tid 703511] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/wp-store-lite/readme.txt"] [unique_id "amuFk8637Arlr6Yb1EfwTAAA2HU"]
[Thu Jul 30 12:10:43.436494 2026] [security2:error] [pid 703393:tid 703546] [client 20.104.18.253:32345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/011i.php"] [unique_id "amuFk8637Arlr6Yb1EfwTgAAAJw"]
[Thu Jul 30 12:10:43.937678 2026] [security2:error] [pid 703393:tid 703602] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFk8637Arlr6Yb1EfwTwAA1GQ"]
[Thu Jul 30 12:10:44.381064 2026] [security2:error] [pid 703393:tid 703611] [client 20.104.18.253:25473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/03a005685d.php"] [unique_id "amuFlM637Arlr6Yb1EfwWQAAAN0"]
[Thu Jul 30 12:10:44.629035 2026] [security2:error] [pid 703393:tid 703566] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFlM637Arlr6Yb1EfwUQAAsHQ"], referer: https://www.spececigarette.com/wp-content/plugins/wp-store-lite/Readme.txt
[Thu Jul 30 12:10:45.129404 2026] [security2:error] [pid 703393:tid 703572] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFlM637Arlr6Yb1EfwYAAAtgY"]
[Thu Jul 30 12:10:45.825327 2026] [security2:error] [pid 703393:tid 703562] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFlc637Arlr6Yb1EfwdAAArBQ"], referer: https://www.spececigarette.com/wp-content/plugins/wp-store-lite/README.txt
[Thu Jul 30 12:10:46.230044 2026] [security2:error] [pid 703393:tid 703416] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/c4d-plugin-manager/readme.txt"] [unique_id "amuFls637Arlr6Yb1EfwfwAApBY"]
[Thu Jul 30 12:10:46.311410 2026] [security2:error] [pid 703393:tid 703582] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFlc637Arlr6Yb1EfweAAAwBE"]
[Thu Jul 30 12:10:46.474787 2026] [security2:error] [pid 703393:tid 703617] [client 74.7.244.35:46402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "rgserve.ph.qnj.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuFls637Arlr6Yb1EfwhQAA4yA"]
[Thu Jul 30 12:10:46.515740 2026] [security2:error] [pid 703393:tid 703625] [client 20.100.187.180:16421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/av.php"] [unique_id "amuFls637Arlr6Yb1EfwiAAAAOs"]
[Thu Jul 30 12:10:46.515866 2026] [security2:error] [pid 703393:tid 703625] [client 20.100.187.180:16421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/av.php"] [unique_id "amuFls637Arlr6Yb1EfwiAAAAOs"]
[Thu Jul 30 12:10:46.592441 2026] [core:error] [pid 703393:tid 703424] [remote 74.7.230.49:53410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:10:46.592463 2026] [core:error] [pid 703393:tid 703424] [remote 74.7.230.49:53410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:10:46.592697 2026] [security2:error] [pid 703393:tid 703601] [client 74.7.230.49:53410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.ampcloudku.com"] [uri "/index.php"] [unique_id "amuFls637Arlr6Yb1EfwiQAA0x4"]
[Thu Jul 30 12:10:46.673791 2026] [security2:error] [pid 703393:tid 703574] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFls637Arlr6Yb1EfwgAAAuCQ"]
[Thu Jul 30 12:10:47.219168 2026] [security2:error] [pid 703393:tid 703636] [client 43.161.224.78:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.224.161.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati"] [unique_id "amuFl8637Arlr6Yb1EfwkAAAAPY"], referer: https://ejournalugj.com/index_php/agrijati
[Thu Jul 30 12:10:47.819767 2026] [security2:error] [pid 703393:tid 703586] [client 43.173.174.105:49568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/12/06/noel-2015-idees-cadeaux-cosmetiques-bio/"] [unique_id "amuFl8637Arlr6Yb1EfwmwAAAMQ"]
[Thu Jul 30 12:10:47.923160 2026] [security2:error] [pid 703393:tid 703523] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFl8637Arlr6Yb1EfwkwAAAIU"]
[Thu Jul 30 12:10:48.292721 2026] [core:notice] [pid 703393:tid 703528] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:48.297580 2026] [security2:error] [pid 703393:tid 703528] [client 43.173.174.105:49580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/12/06/noel-2015-idees-cadeaux-cosmetiques-bio/"] [unique_id "amuFmM637Arlr6Yb1EfwqgAAAIo"], referer: https://carnetdeshopping.com/index.php/2015/12/06/noel-2015-idees-cadeaux-cosmetiques-bio/
[Thu Jul 30 12:10:48.402766 2026] [security2:error] [pid 703393:tid 703594] [client 20.104.18.253:38941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/403.php"] [unique_id "amuFmM637Arlr6Yb1EfwqwAAAMw"]
[Thu Jul 30 12:10:48.980080 2026] [core:notice] [pid 703393:tid 703649] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:48.986800 2026] [security2:error] [pid 703393:tid 703649] [client 103.215.74.26:21198] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFmM637Arlr6Yb1EfwswAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:49.597249 2026] [security2:error] [pid 703393:tid 703573] [client 20.100.187.180:56990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/xa.php"] [unique_id "amuFmc637Arlr6Yb1EfwwQAAALc"]
[Thu Jul 30 12:10:49.597348 2026] [security2:error] [pid 703393:tid 703573] [client 20.100.187.180:56990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/xa.php"] [unique_id "amuFmc637Arlr6Yb1EfwwQAAALc"]
[Thu Jul 30 12:10:49.707275 2026] [core:notice] [pid 703393:tid 703617] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:49.713714 2026] [security2:error] [pid 703393:tid 703617] [client 103.215.74.26:21200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFmc637Arlr6Yb1EfwxQAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:50.463855 2026] [core:notice] [pid 703393:tid 703616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:50.470295 2026] [security2:error] [pid 703393:tid 703616] [client 103.215.74.26:21210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFms637Arlr6Yb1EfwzgAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:51.165449 2026] [security2:error] [pid 703393:tid 703534] [client 20.104.18.253:35205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/404.php"] [unique_id "amuFm8637Arlr6Yb1Efw2QAAAJA"]
[Thu Jul 30 12:10:51.186390 2026] [core:notice] [pid 703393:tid 703635] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:51.193581 2026] [security2:error] [pid 703393:tid 703635] [client 103.215.74.26:21226] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFm8637Arlr6Yb1Efw2gAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:51.747010 2026] [core:notice] [pid 703393:tid 703567] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:51.909243 2026] [core:notice] [pid 703393:tid 703650] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:51.915556 2026] [security2:error] [pid 703393:tid 703650] [client 103.215.74.26:21238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFm8637Arlr6Yb1Efw6wAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:52.075275 2026] [security2:error] [pid 703393:tid 703527] [client 20.100.187.180:16425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/media.php"] [unique_id "amuFnM637Arlr6Yb1Efw7AAAAIk"]
[Thu Jul 30 12:10:52.075401 2026] [security2:error] [pid 703393:tid 703527] [client 20.100.187.180:16425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/media.php"] [unique_id "amuFnM637Arlr6Yb1Efw7AAAAIk"]
[Thu Jul 30 12:10:52.635757 2026] [core:notice] [pid 703393:tid 703640] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:52.638834 2026] [security2:error] [pid 703393:tid 703625] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFnM637Arlr6Yb1Efw8AAA6w8"], referer: https://www.spececigarette.com/wp-content/plugins/c4d-plugin-manager/Readme.txt
[Thu Jul 30 12:10:52.642411 2026] [security2:error] [pid 703393:tid 703640] [client 103.215.74.26:21248] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFnM637Arlr6Yb1Efw9gAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:52.797063 2026] [security2:error] [pid 703393:tid 703544] [client 20.104.18.253:42452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/aa.php"] [unique_id "amuFnM637Arlr6Yb1Efw_QAAAJo"]
[Thu Jul 30 12:10:53.334456 2026] [security2:error] [pid 703393:tid 703558] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFnc637Arlr6Yb1Efw_gAAqC4"]
[Thu Jul 30 12:10:53.363127 2026] [core:notice] [pid 703393:tid 703618] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:53.369455 2026] [security2:error] [pid 703393:tid 703618] [client 103.215.74.26:28150] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFnc637Arlr6Yb1EfxBQAAAOQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:53.571233 2026] [security2:error] [pid 703393:tid 703579] [client 20.100.187.180:37112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/images.php"] [unique_id "amuFnc637Arlr6Yb1EfxBgAAAL0"]
[Thu Jul 30 12:10:53.571367 2026] [security2:error] [pid 703393:tid 703579] [client 20.100.187.180:37112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/images.php"] [unique_id "amuFnc637Arlr6Yb1EfxBgAAAL0"]
[Thu Jul 30 12:10:54.037612 2026] [security2:error] [pid 703393:tid 703616] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFnc637Arlr6Yb1EfxBwAA4jc"], referer: https://www.spececigarette.com/wp-content/plugins/c4d-plugin-manager/README.txt
[Thu Jul 30 12:10:54.095525 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:54.103815 2026] [security2:error] [pid 703393:tid 703646] [client 103.215.74.26:28154] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFns637Arlr6Yb1EfxEAAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:54.424555 2026] [security2:error] [pid 703393:tid 703461] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/blaze-ads/readme.txt"] [unique_id "amuFns637Arlr6Yb1EfxGwAAlEM"]
[Thu Jul 30 12:10:54.727517 2026] [security2:error] [pid 703393:tid 703631] [client 20.104.18.253:32361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/aafewc0k.php"] [unique_id "amuFns637Arlr6Yb1EfxHQAAAPE"]
[Thu Jul 30 12:10:54.860370 2026] [security2:error] [pid 703393:tid 703578] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFns637Arlr6Yb1EfxHAAAvA4"]
[Thu Jul 30 12:10:55.567810 2026] [security2:error] [pid 703393:tid 703554] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFn8637Arlr6Yb1EfxJAAApDQ"], referer: https://www.spececigarette.com/wp-content/plugins/blaze-ads/Readme.txt
[Thu Jul 30 12:10:55.739608 2026] [security2:error] [pid 703393:tid 703601] [client 20.100.187.180:23487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/gecko.php"] [unique_id "amuFn8637Arlr6Yb1EfxLgAAANM"]
[Thu Jul 30 12:10:55.739727 2026] [security2:error] [pid 703393:tid 703601] [client 20.100.187.180:23487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/gecko.php"] [unique_id "amuFn8637Arlr6Yb1EfxLgAAANM"]
[Thu Jul 30 12:10:56.118822 2026] [security2:error] [pid 703393:tid 703525] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFn8637Arlr6Yb1EfxLwAAh0c"]
[Thu Jul 30 12:10:56.145119 2026] [security2:error] [pid 703393:tid 703640] [client 20.52.125.110:8471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/LA.php"] [unique_id "amuFoM637Arlr6Yb1EfxNwAAAPo"]
[Thu Jul 30 12:10:56.347509 2026] [security2:error] [pid 703393:tid 703598] [client 20.104.18.253:44407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/abcd.php"] [unique_id "amuFoM637Arlr6Yb1EfxOAAAANA"]
[Thu Jul 30 12:10:56.815094 2026] [security2:error] [pid 703393:tid 703539] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFoM637Arlr6Yb1EfxOgAAlVE"], referer: https://www.spececigarette.com/wp-content/plugins/blaze-ads/README.txt
[Thu Jul 30 12:10:56.825570 2026] [security2:error] [pid 703393:tid 703629] [client 20.52.125.110:8247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/admin.php"] [unique_id "amuFoM637Arlr6Yb1EfxQAAAAO8"]
[Thu Jul 30 12:10:57.149642 2026] [security2:error] [pid 703393:tid 703647] [client 47.128.122.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuFoc637Arlr6Yb1EfxSAAAAQE"]
[Thu Jul 30 12:10:57.374278 2026] [security2:error] [pid 703393:tid 703556] [client 20.52.125.110:8082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/class_api.php"] [unique_id "amuFoc637Arlr6Yb1EfxSgAAAKY"]
[Thu Jul 30 12:10:57.424298 2026] [security2:error] [pid 703393:tid 703648] [client 20.104.18.253:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/about.php"] [unique_id "amuFoc637Arlr6Yb1EfxSwAAAQI"]
[Thu Jul 30 12:10:57.586376 2026] [security2:error] [pid 703393:tid 703633] [client 185.189.112.11:40228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuFoc637Arlr6Yb1EfxUgAAAPM"]
[Thu Jul 30 12:10:57.586461 2026] [security2:error] [pid 703393:tid 703633] [client 185.189.112.11:40228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuFoc637Arlr6Yb1EfxUgAAAPM"]
[Thu Jul 30 12:10:57.848916 2026] [security2:error] [pid 703393:tid 703616] [client 20.52.125.110:8230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuFoc637Arlr6Yb1EfxVAAAAOI"]
[Thu Jul 30 12:10:58.645707 2026] [security2:error] [pid 703393:tid 703628] [client 20.52.125.110:8236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.tmb/wp-login.php"] [unique_id "amuFos637Arlr6Yb1EfxWwAAAO4"]
[Thu Jul 30 12:10:59.384004 2026] [security2:error] [pid 703393:tid 703492] [remote 216.73.216.152:23332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFo8637Arlr6Yb1EfxbAAAwmI"]
[Thu Jul 30 12:10:59.418079 2026] [security2:error] [pid 703393:tid 703559] [client 20.52.125.110:8217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuFo8637Arlr6Yb1EfxbQAAAKk"]
[Thu Jul 30 12:10:59.461417 2026] [security2:error] [pid 703393:tid 703595] [client 191.232.199.39:54106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/chosen.php"] [unique_id "amuFo8637Arlr6Yb1EfxbgAAAM0"]
[Thu Jul 30 12:10:59.816503 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:10:59.823714 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:28168] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFo8637Arlr6Yb1EfxdgAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:10:59.963000 2026] [security2:error] [pid 703393:tid 703626] [client 20.52.125.110:8449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/991176.php"] [unique_id "amuFo8637Arlr6Yb1EfxeQAAAOw"]
[Thu Jul 30 12:11:00.004753 2026] [security2:error] [pid 703393:tid 703641] [client 20.104.18.253:32329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/admin.php"] [unique_id "amuFpM637Arlr6Yb1EfxegAAAPs"]
[Thu Jul 30 12:11:00.176542 2026] [security2:error] [pid 703393:tid 703471] [remote 57.141.0.63:21252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuFpM637Arlr6Yb1EfxfwAAy00"]
[Thu Jul 30 12:11:00.618846 2026] [security2:error] [pid 703393:tid 703580] [client 20.52.125.110:8222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuFpM637Arlr6Yb1EfxjAAAAL4"]
[Thu Jul 30 12:11:00.658158 2026] [security2:error] [pid 703393:tid 703591] [client 20.100.187.180:37101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/82.php"] [unique_id "amuFpM637Arlr6Yb1EfxjwAAAMk"]
[Thu Jul 30 12:11:00.658265 2026] [security2:error] [pid 703393:tid 703591] [client 20.100.187.180:37101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/82.php"] [unique_id "amuFpM637Arlr6Yb1EfxjwAAAMk"]
[Thu Jul 30 12:11:01.093536 2026] [security2:error] [pid 703393:tid 703564] [client 20.52.125.110:8503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuFpc637Arlr6Yb1EfxlgAAAK4"]
[Thu Jul 30 12:11:01.633574 2026] [security2:error] [pid 703393:tid 703536] [client 191.232.199.39:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/xleet.php"] [unique_id "amuFpc637Arlr6Yb1EfxnwAAAJI"]
[Thu Jul 30 12:11:01.739851 2026] [security2:error] [pid 703393:tid 703631] [client 20.52.125.110:8210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuFpc637Arlr6Yb1EfxpAAAAPE"]
[Thu Jul 30 12:11:02.215421 2026] [security2:error] [pid 703393:tid 703511] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/suyool-payment/readme.txt"] [unique_id "amuFps637Arlr6Yb1EfxsAAAzXU"]
[Thu Jul 30 12:11:02.321770 2026] [security2:error] [pid 703393:tid 703602] [client 20.52.125.110:8096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuFps637Arlr6Yb1EfxswAAANQ"]
[Thu Jul 30 12:11:02.527690 2026] [security2:error] [pid 703393:tid 703545] [client 20.100.187.180:16405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/xstelth.php"] [unique_id "amuFps637Arlr6Yb1EfxuwAAAJs"]
[Thu Jul 30 12:11:02.527796 2026] [security2:error] [pid 703393:tid 703545] [client 20.100.187.180:16405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/xstelth.php"] [unique_id "amuFps637Arlr6Yb1EfxuwAAAJs"]
[Thu Jul 30 12:11:02.603798 2026] [security2:error] [pid 703393:tid 703614] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFpc637Arlr6Yb1EfxqwAA4Gc"]
[Thu Jul 30 12:11:02.815644 2026] [security2:error] [pid 703393:tid 703569] [client 20.104.18.253:52727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/adminfuns.php"] [unique_id "amuFps637Arlr6Yb1EfxwwAAALM"]
[Thu Jul 30 12:11:02.870713 2026] [security2:error] [pid 703393:tid 703608] [client 20.52.125.110:8198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuFps637Arlr6Yb1EfxxAAAANo"]
[Thu Jul 30 12:11:02.911572 2026] [security2:error] [pid 703393:tid 703525] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFps637Arlr6Yb1EfxugAAh2o"]
[Thu Jul 30 12:11:03.089966 2026] [security2:error] [pid 703393:tid 703641] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFps637Arlr6Yb1EfxuQAAAPs"]
[Thu Jul 30 12:11:03.342161 2026] [security2:error] [pid 703393:tid 703611] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFps637Arlr6Yb1EfxwQAAAN0"]
[Thu Jul 30 12:11:03.570973 2026] [security2:error] [pid 703393:tid 703607] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFps637Arlr6Yb1EfxywAAANk"]
[Thu Jul 30 12:11:03.572710 2026] [security2:error] [pid 703393:tid 703627] [client 20.52.125.110:14914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/011i.php"] [unique_id "amuFp8637Arlr6Yb1Efx8QAAAO0"]
[Thu Jul 30 12:11:03.580309 2026] [security2:error] [pid 703393:tid 703577] [client 20.52.125.110:8252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuFp8637Arlr6Yb1Efx8gAAALs"]
[Thu Jul 30 12:11:04.109393 2026] [security2:error] [pid 703393:tid 703567] [client 20.52.125.110:8238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuFqM637Arlr6Yb1EfyBQAAALE"]
[Thu Jul 30 12:11:04.591111 2026] [security2:error] [pid 703393:tid 703560] [client 191.232.199.39:54105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/ds.php"] [unique_id "amuFqM637Arlr6Yb1EfyFQAAAKo"]
[Thu Jul 30 12:11:04.629152 2026] [security2:error] [pid 703393:tid 703540] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFp8637Arlr6Yb1Efx-QAAlig"]
[Thu Jul 30 12:11:04.666338 2026] [security2:error] [pid 703393:tid 703565] [client 20.52.125.110:8086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuFqM637Arlr6Yb1EfyFwAAAK8"]
[Thu Jul 30 12:11:04.774830 2026] [security2:error] [pid 703393:tid 703545] [client 20.104.18.253:25760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/albin.php"] [unique_id "amuFqM637Arlr6Yb1EfyGQAAAJs"]
[Thu Jul 30 12:11:04.777548 2026] [security2:error] [pid 703393:tid 703612] [client 20.52.125.110:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/03a005685d.php"] [unique_id "amuFqM637Arlr6Yb1EfyGgAAAN4"]
[Thu Jul 30 12:11:05.246508 2026] [security2:error] [pid 703393:tid 703647] [client 20.52.125.110:8088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuFqc637Arlr6Yb1EfyJQAAAQE"]
[Thu Jul 30 12:11:05.551669 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:05.558164 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:63894] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFqc637Arlr6Yb1EfyLQAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:05.664842 2026] [security2:error] [pid 703393:tid 703586] [client 20.100.187.180:16407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/xp.php"] [unique_id "amuFqc637Arlr6Yb1EfyLgAAAMQ"]
[Thu Jul 30 12:11:05.664997 2026] [security2:error] [pid 703393:tid 703586] [client 20.100.187.180:16407] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/xp.php"] [unique_id "amuFqc637Arlr6Yb1EfyLgAAAMQ"]
[Thu Jul 30 12:11:05.796442 2026] [core:notice] [pid 703393:tid 703412] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:05.953684 2026] [security2:error] [pid 703393:tid 703627] [client 20.52.125.110:8463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuFqc637Arlr6Yb1EfyNgAAAO0"]
[Thu Jul 30 12:11:05.955170 2026] [security2:error] [pid 703393:tid 703607] [client 191.232.199.39:54109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/f5.php"] [unique_id "amuFqc637Arlr6Yb1EfyNwAAANk"]
[Thu Jul 30 12:11:06.054906 2026] [core:notice] [pid 703393:tid 703460] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:06.275245 2026] [core:notice] [pid 703393:tid 703557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:06.282580 2026] [security2:error] [pid 703393:tid 703557] [client 103.215.74.26:63914] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFqs637Arlr6Yb1EfyPAAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:06.309093 2026] [security2:error] [pid 703393:tid 703551] [client 20.226.5.174:28164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/011i.php"] [unique_id "amuFqs637Arlr6Yb1EfyPQAAAKE"]
[Thu Jul 30 12:11:06.315706 2026] [security2:error] [pid 703393:tid 703526] [client 20.52.125.110:14276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/403.php"] [unique_id "amuFqs637Arlr6Yb1EfyPgAAAIg"]
[Thu Jul 30 12:11:06.474125 2026] [security2:error] [pid 703393:tid 703606] [client 20.52.125.110:8467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuFqs637Arlr6Yb1EfyRgAAANg"]
[Thu Jul 30 12:11:06.622002 2026] [security2:error] [pid 703393:tid 703629] [client 191.232.199.39:6866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/chosen.php"] [unique_id "amuFqs637Arlr6Yb1EfyRwAAAO8"]
[Thu Jul 30 12:11:07.006715 2026] [core:notice] [pid 703393:tid 703626] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:07.012685 2026] [security2:error] [pid 703393:tid 703626] [client 103.215.74.26:63926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFq8637Arlr6Yb1EfyTQAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:07.139871 2026] [security2:error] [pid 703393:tid 703602] [client 20.52.125.110:8241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuFq8637Arlr6Yb1EfyUAAAANQ"]
[Thu Jul 30 12:11:07.255050 2026] [security2:error] [pid 703393:tid 703540] [client 20.104.18.253:25529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/amfsqvgv.php"] [unique_id "amuFq8637Arlr6Yb1EfyUQAAAJY"]
[Thu Jul 30 12:11:07.402541 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.187.180:57281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/admin.php"] [unique_id "amuFq8637Arlr6Yb1EfyUgAAALA"]
[Thu Jul 30 12:11:07.402667 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.187.180:57281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/admin.php"] [unique_id "amuFq8637Arlr6Yb1EfyUgAAALA"]
[Thu Jul 30 12:11:07.524449 2026] [security2:error] [pid 703393:tid 703593] [client 20.226.5.174:27396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/03a005685d.php"] [unique_id "amuFq8637Arlr6Yb1EfyWgAAAMs"]
[Thu Jul 30 12:11:07.620711 2026] [security2:error] [pid 703393:tid 703558] [client 20.52.125.110:8235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuFq8637Arlr6Yb1EfyXgAAAKg"]
[Thu Jul 30 12:11:07.739521 2026] [core:notice] [pid 703393:tid 703580] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:07.750284 2026] [security2:error] [pid 703393:tid 703580] [client 103.215.74.26:63940] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFq8637Arlr6Yb1EfyYAAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:07.826215 2026] [security2:error] [pid 703393:tid 703523] [client 191.232.199.39:6865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/xleet.php"] [unique_id "amuFq8637Arlr6Yb1EfyYQAAAIU"]
[Thu Jul 30 12:11:08.034066 2026] [core:notice] [pid 703393:tid 703466] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:08.102624 2026] [security2:error] [pid 703393:tid 703636] [client 191.232.199.39:54114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/god4m.php"] [unique_id "amuFrM637Arlr6Yb1EfyaQAAAPY"]
[Thu Jul 30 12:11:08.170106 2026] [security2:error] [pid 703393:tid 703564] [client 20.52.125.110:8211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/amaxx.php"] [unique_id "amuFrM637Arlr6Yb1EfyagAAAK4"]
[Thu Jul 30 12:11:08.466298 2026] [core:notice] [pid 703393:tid 703571] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:08.472199 2026] [security2:error] [pid 703393:tid 703571] [client 103.215.74.26:63964] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFrM637Arlr6Yb1EfycAAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:08.564500 2026] [security2:error] [pid 703393:tid 703527] [client 20.100.187.180:57003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.milfordauto.com"] [uri "/adminner.php"] [unique_id "amuFrM637Arlr6Yb1EfydAAAAIk"]
[Thu Jul 30 12:11:08.564624 2026] [security2:error] [pid 703393:tid 703527] [client 20.100.187.180:57003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.milfordauto.com"] [uri "/adminner.php"] [unique_id "amuFrM637Arlr6Yb1EfydAAAAIk"]
[Thu Jul 30 12:11:08.634450 2026] [security2:error] [pid 703393:tid 703615] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFrM637Arlr6Yb1EfyawAA4Vc"], referer: https://www.spececigarette.com/wp-content/plugins/suyool-payment/Readme.txt
[Thu Jul 30 12:11:08.967495 2026] [security2:error] [pid 703393:tid 703567] [client 20.52.125.110:8102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/bek.php"] [unique_id "amuFrM637Arlr6Yb1EfyegAAALE"]
[Thu Jul 30 12:11:09.022944 2026] [security2:error] [pid 703393:tid 703534] [client 20.104.18.253:35211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/ant.php"] [unique_id "amuFrc637Arlr6Yb1EfyfAAAAJA"]
[Thu Jul 30 12:11:09.033285 2026] [security2:error] [pid 703393:tid 703562] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFrM637Arlr6Yb1EfybwAAAKw"]
[Thu Jul 30 12:11:09.046520 2026] [security2:error] [pid 703393:tid 703600] [client 20.226.5.174:28179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/403.php"] [unique_id "amuFrc637Arlr6Yb1EfygAAAANI"]
[Thu Jul 30 12:11:09.142479 2026] [security2:error] [pid 703393:tid 703487] [remote 47.128.27.69:62486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-wmns-air-jordan-1-low-barb-white-black-green/"] [unique_id "amuFrc637Arlr6Yb1EfyhAAAmF0"]
[Thu Jul 30 12:11:09.193011 2026] [core:notice] [pid 703393:tid 703629] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:09.199628 2026] [security2:error] [pid 703393:tid 703629] [client 103.215.74.26:63974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFrc637Arlr6Yb1EfyhQAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:09.280644 2026] [security2:error] [pid 703393:tid 703554] [client 191.232.199.39:6854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/ds.php"] [unique_id "amuFrc637Arlr6Yb1EfyiQAAAKQ"]
[Thu Jul 30 12:11:09.325661 2026] [security2:error] [pid 703393:tid 703625] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFrc637Arlr6Yb1EfyewAA61I"]
[Thu Jul 30 12:11:09.353870 2026] [security2:error] [pid 703393:tid 703601] [client 191.232.199.39:54092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/info.php"] [unique_id "amuFrc637Arlr6Yb1EfyiwAAANM"]
[Thu Jul 30 12:11:09.390647 2026] [security2:error] [pid 703393:tid 703470] [remote 216.73.216.152:57269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFrc637Arlr6Yb1EfyjQAAtEw"]
[Thu Jul 30 12:11:09.493425 2026] [autoindex:error] [pid 703393:tid 703579] [client 43.166.136.24:44312] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:11:09.555007 2026] [security2:error] [pid 703393:tid 703569] [client 20.52.125.110:8488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuFrc637Arlr6Yb1EfyjwAAALM"]
[Thu Jul 30 12:11:09.936734 2026] [core:notice] [pid 703393:tid 703539] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:09.942932 2026] [security2:error] [pid 703393:tid 703539] [client 103.215.74.26:63990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFrc637Arlr6Yb1EfymwAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:10.013139 2026] [security2:error] [pid 703393:tid 703641] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFrc637Arlr6Yb1EfykwAA-1s"], referer: https://www.spececigarette.com/wp-content/plugins/suyool-payment/README.txt
[Thu Jul 30 12:11:10.263597 2026] [security2:error] [pid 703393:tid 703523] [client 20.52.125.110:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/404.php"] [unique_id "amuFrs637Arlr6Yb1EfyogAAAIU"]
[Thu Jul 30 12:11:10.384690 2026] [security2:error] [pid 703393:tid 703502] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/station-pro/readme.txt"] [unique_id "amuFrs637Arlr6Yb1EfypAAAzGw"]
[Thu Jul 30 12:11:10.487103 2026] [security2:error] [pid 703393:tid 703604] [client 43.159.145.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "legalsnaps.info"] [uri "/index.php"] [unique_id "amuFrc637Arlr6Yb1EfyiAAAANY"]
[Thu Jul 30 12:11:10.594457 2026] [security2:error] [pid 703393:tid 703576] [client 20.52.125.110:8195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/class.api.php"] [unique_id "amuFrs637Arlr6Yb1EfyqAAAALo"]
[Thu Jul 30 12:11:10.665469 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:10.676017 2026] [security2:error] [pid 703393:tid 703636] [client 103.215.74.26:64002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFrs637Arlr6Yb1EfyrQAAAPY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:10.805674 2026] [security2:error] [pid 703393:tid 703538] [client 191.232.199.39:6887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/f5.php"] [unique_id "amuFrs637Arlr6Yb1EfysAAAAJQ"]
[Thu Jul 30 12:11:10.818956 2026] [security2:error] [pid 703393:tid 703619] [client 20.226.5.174:27405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/404.php"] [unique_id "amuFrs637Arlr6Yb1EfysQAAAOU"]
[Thu Jul 30 12:11:10.825526 2026] [security2:error] [pid 703393:tid 703535] [client 20.52.125.110:14310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/aa.php"] [unique_id "amuFrs637Arlr6Yb1EfysgAAAJE"]
[Thu Jul 30 12:11:10.915747 2026] [security2:error] [pid 703393:tid 703496] [remote 74.7.241.60:50878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuFrs637Arlr6Yb1EfyswAA7mY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:11:10.929141 2026] [core:notice] [pid 703393:tid 703549] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:11.027823 2026] [security2:error] [pid 703393:tid 703573] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFrs637Arlr6Yb1EfyrgAAt2E"]
[Thu Jul 30 12:11:11.418622 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:11.428355 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:64008] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFr8637Arlr6Yb1EfywAAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:11.462316 2026] [security2:error] [pid 703393:tid 703607] [client 20.52.125.110:8506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/cong.php"] [unique_id "amuFr8637Arlr6Yb1EfywgAAANk"]
[Thu Jul 30 12:11:11.563763 2026] [security2:error] [pid 703393:tid 703567] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFr8637Arlr6Yb1EfyuwAAsVg"], referer: https://www.spececigarette.com/wp-content/plugins/station-pro/Readme.txt
[Thu Jul 30 12:11:11.661877 2026] [security2:error] [pid 703393:tid 703525] [client 20.104.18.253:39942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/appreciators.php"] [unique_id "amuFr8637Arlr6Yb1EfyxwAAAIc"]
[Thu Jul 30 12:11:11.668497 2026] [security2:error] [pid 703393:tid 703626] [client 20.52.125.110:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/aafewc0k.php"] [unique_id "amuFr8637Arlr6Yb1EfyyQAAAOw"]
[Thu Jul 30 12:11:11.982441 2026] [security2:error] [pid 703393:tid 703554] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFr8637Arlr6Yb1EfyyAAApG0"]
[Thu Jul 30 12:11:12.065011 2026] [security2:error] [pid 703393:tid 703597] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFr8637Arlr6Yb1EfywQAAz3U"]
[Thu Jul 30 12:11:12.086226 2026] [security2:error] [pid 703393:tid 703533] [client 20.52.125.110:8065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/content.php"] [unique_id "amuFsM637Arlr6Yb1EfyzgAAAI8"]
[Thu Jul 30 12:11:12.237773 2026] [security2:error] [pid 703393:tid 703642] [client 20.226.5.174:28171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/aa.php"] [unique_id "amuFsM637Arlr6Yb1Efy1QAAAPw"]
[Thu Jul 30 12:11:12.365091 2026] [autoindex:error] [pid 703393:tid 703641] [client 119.45.7.86:47742] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:11:12.497242 2026] [security2:error] [pid 703393:tid 703645] [client 20.52.125.110:14920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/abcd.php"] [unique_id "amuFsM637Arlr6Yb1Efy2wAAAP8"]
[Thu Jul 30 12:11:12.572280 2026] [security2:error] [pid 703393:tid 703610] [client 191.232.199.39:6849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/god4m.php"] [unique_id "amuFsM637Arlr6Yb1Efy3AAAANw"]
[Thu Jul 30 12:11:12.708396 2026] [security2:error] [pid 703393:tid 703556] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFsM637Arlr6Yb1Efy1gAApmo"], referer: https://www.spececigarette.com/wp-content/plugins/station-pro/README.txt
[Thu Jul 30 12:11:12.854680 2026] [security2:error] [pid 703393:tid 703633] [client 20.52.125.110:8007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/cwianpri.php"] [unique_id "amuFsM637Arlr6Yb1Efy4wAAAPM"]
[Thu Jul 30 12:11:13.255145 2026] [proxy:error] [pid 703393:tid 703623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:13.255197 2026] [proxy_http:error] [pid 703393:tid 703623] [client 191.232.199.39:54098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:13.255773 2026] [proxy:error] [pid 703393:tid 703623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:13.255814 2026] [proxy_http:error] [pid 703393:tid 703623] [client 191.232.199.39:54098] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:13.317151 2026] [security2:error] [pid 703393:tid 703555] [client 62.238.42.130:15180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuFrs637Arlr6Yb1EfyowAAAKU"]
[Thu Jul 30 12:11:13.400147 2026] [security2:error] [pid 703393:tid 703618] [client 20.52.125.110:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/about.php"] [unique_id "amuFsc637Arlr6Yb1Efy7gAAAOQ"]
[Thu Jul 30 12:11:13.412130 2026] [security2:error] [pid 703393:tid 703527] [client 20.52.125.110:8004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/elp.php"] [unique_id "amuFsc637Arlr6Yb1Efy7wAAAIk"]
[Thu Jul 30 12:11:13.741491 2026] [security2:error] [pid 703393:tid 703622] [client 191.232.199.39:6870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/info.php"] [unique_id "amuFsc637Arlr6Yb1Efy8AAAAOg"]
[Thu Jul 30 12:11:13.961311 2026] [core:notice] [pid 703393:tid 703567] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:14.327926 2026] [security2:error] [pid 703393:tid 703583] [client 20.52.125.110:8092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuFss637Arlr6Yb1Efy_AAAAME"]
[Thu Jul 30 12:11:14.503598 2026] [security2:error] [pid 703393:tid 703625] [client 20.52.125.110:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/admin.php"] [unique_id "amuFss637Arlr6Yb1EfzAQAAAOs"]
[Thu Jul 30 12:11:14.932139 2026] [security2:error] [pid 703393:tid 703513] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/storeman/readme.txt"] [unique_id "amuFss637Arlr6Yb1EfzCwAA4nc"]
[Thu Jul 30 12:11:14.951178 2026] [security2:error] [pid 703393:tid 703552] [client 20.52.125.110:8209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuFss637Arlr6Yb1EfzDAAAAKI"]
[Thu Jul 30 12:11:15.039377 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:20662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gmo.php"] [unique_id "amuFs8637Arlr6Yb1EfzDgAAAN0"]
[Thu Jul 30 12:11:15.346885 2026] [security2:error] [pid 703393:tid 703612] [client 213.152.187.215:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFs8637Arlr6Yb1EfzGAAAAN4"]
[Thu Jul 30 12:11:15.347001 2026] [security2:error] [pid 703393:tid 703612] [client 213.152.187.215:60558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuFs8637Arlr6Yb1EfzGAAAAN4"]
[Thu Jul 30 12:11:15.604118 2026] [security2:error] [pid 703393:tid 703529] [client 20.52.125.110:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuFs8637Arlr6Yb1EfzHAAAAIs"]
[Thu Jul 30 12:11:15.695511 2026] [security2:error] [pid 703393:tid 703591] [client 191.232.199.39:54088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/.__info.php"] [unique_id "amuFs8637Arlr6Yb1EfzHQAAAMk"]
[Thu Jul 30 12:11:15.711722 2026] [security2:error] [pid 703393:tid 703433] [remote 57.141.0.21:38718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/628583096/feed/rss2/"] [unique_id "amuFs8637Arlr6Yb1EfzHgAApyc"]
[Thu Jul 30 12:11:15.985239 2026] [core:notice] [pid 703393:tid 703415] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:16.053569 2026] [security2:error] [pid 703393:tid 703586] [client 20.52.125.110:14291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/adminfuns.php"] [unique_id "amuFtM637Arlr6Yb1EfzJgAAAMQ"]
[Thu Jul 30 12:11:16.108750 2026] [proxy:error] [pid 703393:tid 703623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:16.108798 2026] [proxy_http:error] [pid 703393:tid 703623] [client 191.232.199.39:6876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:16.109362 2026] [proxy:error] [pid 703393:tid 703623] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:16.109406 2026] [proxy_http:error] [pid 703393:tid 703623] [client 191.232.199.39:6876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:16.499393 2026] [security2:error] [pid 703393:tid 703598] [client 20.52.125.110:8459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuFtM637Arlr6Yb1EfzMwAAANA"]
[Thu Jul 30 12:11:16.723743 2026] [security2:error] [pid 703393:tid 703582] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFtM637Arlr6Yb1EfzKQAAwCM"]
[Thu Jul 30 12:11:17.092012 2026] [security2:error] [pid 703393:tid 703614] [client 20.52.125.110:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/albin.php"] [unique_id "amuFtc637Arlr6Yb1EfzPwAAAOA"]
[Thu Jul 30 12:11:17.115150 2026] [security2:error] [pid 703393:tid 703550] [client 20.52.125.110:8464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuFtc637Arlr6Yb1EfzQAAAAKA"]
[Thu Jul 30 12:11:17.153205 2026] [security2:error] [pid 703393:tid 703600] [client 20.104.18.253:32383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/archive.php"] [unique_id "amuFtc637Arlr6Yb1EfzQQAAANI"]
[Thu Jul 30 12:11:17.168615 2026] [security2:error] [pid 703393:tid 703615] [client 20.63.98.115:39059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/nakrip.php"] [unique_id "amuFtc637Arlr6Yb1EfzQgAAAOE"]
[Thu Jul 30 12:11:17.171478 2026] [core:notice] [pid 703393:tid 703632] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:17.177925 2026] [security2:error] [pid 703393:tid 703632] [client 103.215.74.26:17632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFtc637Arlr6Yb1EfzQwAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:17.243381 2026] [security2:error] [pid 703393:tid 703626] [client 191.232.199.39:54084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/0.php"] [unique_id "amuFtc637Arlr6Yb1EfzRgAAAOw"]
[Thu Jul 30 12:11:17.597817 2026] [security2:error] [pid 703393:tid 703643] [client 20.52.125.110:8242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuFtc637Arlr6Yb1EfzTQAAAP0"]
[Thu Jul 30 12:11:17.853475 2026] [security2:error] [pid 703393:tid 703609] [client 20.91.208.34:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuFtc637Arlr6Yb1EfzTgAAANs"]
[Thu Jul 30 12:11:17.853632 2026] [security2:error] [pid 703393:tid 703609] [client 20.91.208.34:55074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuFtc637Arlr6Yb1EfzTgAAANs"]
[Thu Jul 30 12:11:17.915160 2026] [core:notice] [pid 703393:tid 703576] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:17.922416 2026] [security2:error] [pid 703393:tid 703576] [client 103.215.74.26:17634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFtc637Arlr6Yb1EfzUgAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:18.031048 2026] [security2:error] [pid 703393:tid 703524] [client 20.104.18.253:38900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/as.php"] [unique_id "amuFts637Arlr6Yb1EfzVgAAAIY"]
[Thu Jul 30 12:11:18.104236 2026] [security2:error] [pid 703393:tid 703636] [client 20.63.98.115:42949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/radio.php"] [unique_id "amuFts637Arlr6Yb1EfzVwAAAPY"]
[Thu Jul 30 12:11:18.111515 2026] [security2:error] [pid 703393:tid 703628] [client 20.52.125.110:8239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuFts637Arlr6Yb1EfzWAAAAO4"]
[Thu Jul 30 12:11:18.647117 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:18.655087 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:17638] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFts637Arlr6Yb1EfzYQAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:18.670262 2026] [security2:error] [pid 703393:tid 703562] [client 20.52.125.110:8458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuFts637Arlr6Yb1EfzYgAAAKw"]
[Thu Jul 30 12:11:18.780162 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.208.34:24107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuFts637Arlr6Yb1EfzYwAAAKo"]
[Thu Jul 30 12:11:18.780275 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.208.34:24107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuFts637Arlr6Yb1EfzYwAAAKo"]
[Thu Jul 30 12:11:18.967213 2026] [security2:error] [pid 703393:tid 703638] [client 20.104.18.253:45861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/atomlib.php"] [unique_id "amuFts637Arlr6Yb1EfzZQAAAPg"]
[Thu Jul 30 12:11:19.080495 2026] [security2:error] [pid 703393:tid 703542] [client 20.63.98.115:39095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-singin.php"] [unique_id "amuFt8637Arlr6Yb1EfzagAAAJg"]
[Thu Jul 30 12:11:19.265451 2026] [security2:error] [pid 703393:tid 703634] [client 20.52.125.110:8219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuFt8637Arlr6Yb1EfzcAAAAPQ"]
[Thu Jul 30 12:11:19.382908 2026] [core:notice] [pid 703393:tid 703592] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:19.389424 2026] [security2:error] [pid 703393:tid 703592] [client 103.215.74.26:17648] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFt8637Arlr6Yb1EfzcgAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:19.399147 2026] [security2:error] [pid 703393:tid 703579] [client 20.91.208.34:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/x.php"] [unique_id "amuFt8637Arlr6Yb1EfzcwAAAL0"]
[Thu Jul 30 12:11:19.399305 2026] [security2:error] [pid 703393:tid 703579] [client 20.91.208.34:58576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/x.php"] [unique_id "amuFt8637Arlr6Yb1EfzcwAAAL0"]
[Thu Jul 30 12:11:19.538970 2026] [security2:error] [pid 703393:tid 703647] [client 57.141.0.20:52328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuFtc637Arlr6Yb1EfzRAABAQY"], referer: https://igetvape-australia.com/product-tag/alibarbar-ingot-cool-mint-9000-puffs/
[Thu Jul 30 12:11:19.573972 2026] [security2:error] [pid 703393:tid 703602] [client 20.52.125.110:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/amfsqvgv.php"] [unique_id "amuFt8637Arlr6Yb1EfzhAAAANQ"]
[Thu Jul 30 12:11:19.910576 2026] [security2:error] [pid 703393:tid 703569] [client 20.52.125.110:8476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuFt8637Arlr6Yb1EfzhQAAALM"]
[Thu Jul 30 12:11:19.946484 2026] [security2:error] [pid 703393:tid 703594] [client 20.91.208.34:10047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/mgrr.php"] [unique_id "amuFt8637Arlr6Yb1EfzhgAAAMw"]
[Thu Jul 30 12:11:19.946572 2026] [security2:error] [pid 703393:tid 703594] [client 20.91.208.34:10047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/mgrr.php"] [unique_id "amuFt8637Arlr6Yb1EfzhgAAAMw"]
[Thu Jul 30 12:11:19.963764 2026] [security2:error] [pid 703393:tid 703617] [client 20.63.98.115:21056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/as.php"] [unique_id "amuFt8637Arlr6Yb1EfzhwAAAOM"]
[Thu Jul 30 12:11:20.022705 2026] [security2:error] [pid 703393:tid 703543] [client 20.104.18.253:39963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/autoload_classmap.php"] [unique_id "amuFuM637Arlr6Yb1EfziwAAAJk"]
[Thu Jul 30 12:11:20.072357 2026] [lsapi:error] [pid 643253:tid 643370] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/shall-we-dance-vj-junior/
[Thu Jul 30 12:11:20.111993 2026] [core:error] [pid 703393:tid 703630] [client 98.85.223.94:44886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:20.112014 2026] [core:error] [pid 703393:tid 703630] [client 98.85.223.94:44886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:20.141900 2026] [core:notice] [pid 703393:tid 703577] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:20.148059 2026] [security2:error] [pid 703393:tid 703577] [client 103.215.74.26:17662] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFuM637Arlr6Yb1EfzkAAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:20.406024 2026] [security2:error] [pid 703393:tid 703636] [client 20.91.208.34:55044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/domvf.php"] [unique_id "amuFuM637Arlr6Yb1EfzlAAAAPY"]
[Thu Jul 30 12:11:20.406135 2026] [security2:error] [pid 703393:tid 703636] [client 20.91.208.34:55044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/domvf.php"] [unique_id "amuFuM637Arlr6Yb1EfzlAAAAPY"]
[Thu Jul 30 12:11:20.429872 2026] [security2:error] [pid 703393:tid 703535] [client 191.232.199.39:54087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/07.php"] [unique_id "amuFuM637Arlr6Yb1EfzlQAAAJE"]
[Thu Jul 30 12:11:20.497684 2026] [security2:error] [pid 703393:tid 703549] [client 20.52.125.110:8216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuFuM637Arlr6Yb1EfzmgAAAJ8"]
[Thu Jul 30 12:11:20.501461 2026] [autoindex:error] [pid 703393:tid 703559] [client 98.85.223.94:44888] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:11:20.578713 2026] [security2:error] [pid 703393:tid 703633] [client 20.52.125.110:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/ant.php"] [unique_id "amuFuM637Arlr6Yb1EfzngAAAPM"]
[Thu Jul 30 12:11:20.819226 2026] [security2:error] [pid 703393:tid 703541] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFuM637Arlr6Yb1EfzkgAAlxA"]
[Thu Jul 30 12:11:20.878024 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:20.885718 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:17674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFuM637Arlr6Yb1EfzoAAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:21.044662 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.208.34:55069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/yup.php"] [unique_id "amuFuc637Arlr6Yb1EfzpQAAANo"]
[Thu Jul 30 12:11:21.044869 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.208.34:55069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/yup.php"] [unique_id "amuFuc637Arlr6Yb1EfzpQAAANo"]
[Thu Jul 30 12:11:21.156571 2026] [security2:error] [pid 703393:tid 703570] [client 20.52.125.110:8084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuFuc637Arlr6Yb1EfzqQAAALQ"]
[Thu Jul 30 12:11:21.597698 2026] [security2:error] [pid 703393:tid 703571] [client 20.226.5.174:28223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/aafewc0k.php"] [unique_id "amuFuc637Arlr6Yb1EfzsgAAALU"]
[Thu Jul 30 12:11:21.680519 2026] [security2:error] [pid 703393:tid 703580] [client 20.52.125.110:14317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/appreciators.php"] [unique_id "amuFuc637Arlr6Yb1EfztAAAAL4"]
[Thu Jul 30 12:11:21.795478 2026] [security2:error] [pid 703393:tid 703614] [client 20.52.125.110:8085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuFuc637Arlr6Yb1EfztQAAAOA"]
[Thu Jul 30 12:11:21.917573 2026] [security2:error] [pid 703393:tid 703568] [client 20.91.208.34:24118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/X.php"] [unique_id "amuFuc637Arlr6Yb1EfztgAAALI"]
[Thu Jul 30 12:11:21.917685 2026] [security2:error] [pid 703393:tid 703568] [client 20.91.208.34:24118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/X.php"] [unique_id "amuFuc637Arlr6Yb1EfztgAAALI"]
[Thu Jul 30 12:11:22.307656 2026] [security2:error] [pid 703393:tid 703581] [client 20.52.125.110:14575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/archive.php"] [unique_id "amuFus637Arlr6Yb1EfzvwAAAL8"]
[Thu Jul 30 12:11:22.331358 2026] [security2:error] [pid 703393:tid 703649] [client 20.52.125.110:8075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuFus637Arlr6Yb1EfzwAAAAQM"]
[Thu Jul 30 12:11:22.765860 2026] [security2:error] [pid 703393:tid 703567] [client 20.104.18.253:25737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/bb.php"] [unique_id "amuFus637Arlr6Yb1EfzyQAAALE"]
[Thu Jul 30 12:11:22.940065 2026] [security2:error] [pid 703393:tid 703573] [client 20.52.125.110:8087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuFus637Arlr6Yb1EfzzwAAALc"]
[Thu Jul 30 12:11:22.951196 2026] [security2:error] [pid 703393:tid 703591] [client 20.52.125.110:14540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/as.php"] [unique_id "amuFus637Arlr6Yb1Efz0AAAAMk"]
[Thu Jul 30 12:11:23.292882 2026] [core:notice] [pid 703393:tid 703618] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:23.475755 2026] [security2:error] [pid 703393:tid 703595] [client 20.52.125.110:8000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuFu8637Arlr6Yb1Efz2gAAAM0"]
[Thu Jul 30 12:11:23.480177 2026] [security2:error] [pid 703393:tid 703623] [client 191.232.199.39:54108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/dropdown.php"] [unique_id "amuFu8637Arlr6Yb1Efz2wAAAOk"]
[Thu Jul 30 12:11:23.816381 2026] [security2:error] [pid 703393:tid 703583] [client 20.52.125.110:14560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/atomlib.php"] [unique_id "amuFu8637Arlr6Yb1Efz4wAAAME"]
[Thu Jul 30 12:11:23.837786 2026] [security2:error] [pid 703393:tid 703526] [client 20.63.98.115:39090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/x.php"] [unique_id "amuFu8637Arlr6Yb1Efz5AAAAIg"]
[Thu Jul 30 12:11:24.017686 2026] [security2:error] [pid 703393:tid 703612] [client 20.226.5.174:28195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/abcd.php"] [unique_id "amuFvM637Arlr6Yb1Efz5QAAAN4"]
[Thu Jul 30 12:11:24.071159 2026] [security2:error] [pid 703393:tid 703582] [client 20.52.125.110:8100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuFvM637Arlr6Yb1Efz5gAAAMA"]
[Thu Jul 30 12:11:24.080517 2026] [security2:error] [pid 703393:tid 703625] [client 20.91.208.34:9999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuFvM637Arlr6Yb1Efz5wAAAOs"]
[Thu Jul 30 12:11:24.080611 2026] [security2:error] [pid 703393:tid 703625] [client 20.91.208.34:9999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuFvM637Arlr6Yb1Efz5wAAAOs"]
[Thu Jul 30 12:11:24.403417 2026] [security2:error] [pid 703393:tid 703475] [remote 216.73.216.152:49487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuFvM637Arlr6Yb1Efz7wAA1FE"]
[Thu Jul 30 12:11:24.662370 2026] [security2:error] [pid 703393:tid 703588] [client 20.52.125.110:8115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuFvM637Arlr6Yb1Efz8AAAAMY"]
[Thu Jul 30 12:11:25.195692 2026] [security2:error] [pid 703393:tid 703556] [client 191.232.199.39:6863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.__info.php"] [unique_id "amuFvc637Arlr6Yb1Ef0AAAAAKY"]
[Thu Jul 30 12:11:25.241180 2026] [security2:error] [pid 703393:tid 703550] [client 20.226.5.174:28206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/about.php"] [unique_id "amuFvc637Arlr6Yb1Ef0BQAAAKA"]
[Thu Jul 30 12:11:25.256441 2026] [security2:error] [pid 703393:tid 703543] [client 20.52.125.110:8196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuFvc637Arlr6Yb1Ef0BgAAAJk"]
[Thu Jul 30 12:11:25.353928 2026] [security2:error] [pid 703393:tid 703617] [client 191.232.199.39:54117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/makeasmtp.php"] [unique_id "amuFvc637Arlr6Yb1Ef0CgAAAOM"]
[Thu Jul 30 12:11:25.420797 2026] [security2:error] [pid 703393:tid 703531] [client 185.191.171.4:27346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/22/fachin-rejeita-pedido-da-pgr-contra-norma-que-amplia-poder-do-tse/"] [unique_id "amuFvc637Arlr6Yb1Ef0CwAAAI0"]
[Thu Jul 30 12:11:25.421015 2026] [security2:error] [pid 703393:tid 703531] [client 185.191.171.4:27346] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/22/fachin-rejeita-pedido-da-pgr-contra-norma-que-amplia-poder-do-tse/"] [unique_id "amuFvc637Arlr6Yb1Ef0CwAAAI0"]
[Thu Jul 30 12:11:25.450676 2026] [security2:error] [pid 703393:tid 703585] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFvM637Arlr6Yb1Efz-gAAw0w"]
[Thu Jul 30 12:11:25.558643 2026] [security2:error] [pid 703393:tid 703564] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFvc637Arlr6Yb1Ef0AwAArlw"]
[Thu Jul 30 12:11:25.593375 2026] [security2:error] [pid 703393:tid 703563] [client 20.52.125.110:14582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/autoload_classmap.php"] [unique_id "amuFvc637Arlr6Yb1Ef0DgAAAK0"]
[Thu Jul 30 12:11:25.861089 2026] [security2:error] [pid 703393:tid 703636] [client 20.63.98.115:65431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/item.php"] [unique_id "amuFvc637Arlr6Yb1Ef0FQAAAPY"]
[Thu Jul 30 12:11:25.962870 2026] [security2:error] [pid 703393:tid 703628] [client 20.52.125.110:8079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuFvc637Arlr6Yb1Ef0FgAAAO4"]
[Thu Jul 30 12:11:25.985862 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.208.34:58590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/gec.php"] [unique_id "amuFvc637Arlr6Yb1Ef0FwAAAPE"]
[Thu Jul 30 12:11:25.985950 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.208.34:58590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/gec.php"] [unique_id "amuFvc637Arlr6Yb1Ef0FwAAAPE"]
[Thu Jul 30 12:11:26.155525 2026] [security2:error] [pid 703393:tid 703596] [client 20.104.18.253:42523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/bnm.php"] [unique_id "amuFvs637Arlr6Yb1Ef0GgAAAM4"]
[Thu Jul 30 12:11:26.357881 2026] [security2:error] [pid 703393:tid 703537] [client 20.226.5.174:28204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/admin.php"] [unique_id "amuFvs637Arlr6Yb1Ef0HgAAAJM"]
[Thu Jul 30 12:11:26.479749 2026] [security2:error] [pid 703393:tid 703562] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFvs637Arlr6Yb1Ef0GQAArGE"], referer: https://www.spececigarette.com/wp-content/plugins/storeman/README.txt
[Thu Jul 30 12:11:26.563532 2026] [security2:error] [pid 703393:tid 703551] [client 20.52.125.110:8487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuFvs637Arlr6Yb1Ef0IgAAAKE"]
[Thu Jul 30 12:11:26.617340 2026] [security2:error] [pid 703393:tid 703637] [client 191.232.199.39:54104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-sigunq.php"] [unique_id "amuFvs637Arlr6Yb1Ef0JAAAAPc"]
[Thu Jul 30 12:11:26.630715 2026] [core:notice] [pid 703393:tid 703534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:26.637703 2026] [security2:error] [pid 703393:tid 703534] [client 103.215.74.26:4906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFvs637Arlr6Yb1Ef0JQAAAJA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:26.860201 2026] [security2:error] [pid 703393:tid 703490] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/floating-icons/readme.txt"] [unique_id "amuFvs637Arlr6Yb1Ef0KwAApGA"]
[Thu Jul 30 12:11:27.238364 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:21069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/app.php"] [unique_id "amuFv8637Arlr6Yb1Ef0MwAAAQI"]
[Thu Jul 30 12:11:27.244149 2026] [security2:error] [pid 703393:tid 703593] [client 20.52.125.110:8081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuFv8637Arlr6Yb1Ef0NAAAAMs"]
[Thu Jul 30 12:11:27.383788 2026] [core:notice] [pid 703393:tid 703645] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:27.390298 2026] [security2:error] [pid 703393:tid 703645] [client 103.215.74.26:4922] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFv8637Arlr6Yb1Ef0OgAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:27.481273 2026] [security2:error] [pid 703393:tid 703614] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFv8637Arlr6Yb1Ef0MAAA4HU"]
[Thu Jul 30 12:11:27.513706 2026] [security2:error] [pid 703393:tid 703579] [client 191.232.199.39:6859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/0.php"] [unique_id "amuFv8637Arlr6Yb1Ef0PAAAAL0"]
[Thu Jul 30 12:11:27.880607 2026] [security2:error] [pid 703393:tid 703536] [client 20.52.125.110:8031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuFv8637Arlr6Yb1Ef0RgAAAJI"]
[Thu Jul 30 12:11:27.931030 2026] [security2:error] [pid 703393:tid 703567] [client 20.91.208.34:22690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/sky.php"] [unique_id "amuFv8637Arlr6Yb1Ef0RwAAALE"]
[Thu Jul 30 12:11:27.931138 2026] [security2:error] [pid 703393:tid 703567] [client 20.91.208.34:22690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/sky.php"] [unique_id "amuFv8637Arlr6Yb1Ef0RwAAALE"]
[Thu Jul 30 12:11:27.948096 2026] [security2:error] [pid 703393:tid 703611] [client 191.232.199.39:54107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wso112233.php"] [unique_id "amuFv8637Arlr6Yb1Ef0SAAAAN0"]
[Thu Jul 30 12:11:28.168107 2026] [security2:error] [pid 703393:tid 703643] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFv8637Arlr6Yb1Ef0PwAA_QQ"], referer: https://www.spececigarette.com/wp-content/plugins/floating-icons/Readme.txt
[Thu Jul 30 12:11:28.285158 2026] [security2:error] [pid 703393:tid 703580] [client 20.226.5.174:28168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/adminfuns.php"] [unique_id "amuFwM637Arlr6Yb1Ef0TQAAAL4"]
[Thu Jul 30 12:11:28.290143 2026] [proxy:error] [pid 703393:tid 703573] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:28.290221 2026] [proxy_http:error] [pid 703393:tid 703573] [client 94.154.43.229:63240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:28.290799 2026] [proxy:error] [pid 703393:tid 703573] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:28.290841 2026] [proxy_http:error] [pid 703393:tid 703573] [client 94.154.43.229:63240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:28.494495 2026] [security2:error] [pid 703393:tid 703586] [client 20.52.125.110:8469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuFwM637Arlr6Yb1Ef0VgAAAMQ"]
[Thu Jul 30 12:11:28.594222 2026] [security2:error] [pid 703393:tid 703546] [client 74.7.244.17:38368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "mail.jpm.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amuFwM637Arlr6Yb1Ef0VwAAAJw"]
[Thu Jul 30 12:11:28.678313 2026] [security2:error] [pid 703393:tid 703631] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFwM637Arlr6Yb1Ef0UgAA8Xw"]
[Thu Jul 30 12:11:28.744096 2026] [core:notice] [pid 703393:tid 703589] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:28.789411 2026] [security2:error] [pid 703393:tid 703532] [client 191.232.199.39:6858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/07.php"] [unique_id "amuFwM637Arlr6Yb1Ef0WgAAAI4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:11:28.833605 2026] [security2:error] [pid 703393:tid 703562] [client 74.7.244.17:38368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.jpm.tqa.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuFwM637Arlr6Yb1Ef0WwAAAKw"], referer: https://mail.jpm.tqa.temporary.site/robots.txt
[Thu Jul 30 12:11:28.862168 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.208.34:55097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/fffm.php"] [unique_id "amuFwM637Arlr6Yb1Ef0YAAAALA"]
[Thu Jul 30 12:11:28.862265 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.208.34:55097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/fffm.php"] [unique_id "amuFwM637Arlr6Yb1Ef0YAAAALA"]
[Thu Jul 30 12:11:28.863315 2026] [security2:error] [pid 703393:tid 703595] [client 35.221.246.130:35438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ahk.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuFvs637Arlr6Yb1Ef0KgAAAM0"]
[Thu Jul 30 12:11:28.863355 2026] [security2:error] [pid 703393:tid 703595] [client 35.221.246.130:35438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.ahk.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuFvs637Arlr6Yb1Ef0KgAAAM0"]
[Thu Jul 30 12:11:28.935738 2026] [security2:error] [pid 703393:tid 703621] [client 20.52.125.110:14554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/bb.php"] [unique_id "amuFwM637Arlr6Yb1Ef0ZAAAAOc"]
[Thu Jul 30 12:11:28.988597 2026] [security2:error] [pid 703393:tid 703551] [client 20.52.125.110:8080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuFwM637Arlr6Yb1Ef0ZQAAAKE"]
[Thu Jul 30 12:11:29.210081 2026] [security2:error] [pid 703393:tid 703540] [client 191.232.199.39:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/alfanew.php"] [unique_id "amuFwc637Arlr6Yb1Ef0ZwAAAJY"]
[Thu Jul 30 12:11:29.432181 2026] [security2:error] [pid 703393:tid 703554] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFwM637Arlr6Yb1Ef0ZgAApAE"], referer: https://www.spececigarette.com/wp-content/plugins/floating-icons/README.txt
[Thu Jul 30 12:11:29.509708 2026] [security2:error] [pid 703393:tid 703402] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/saber-commerce/readme.txt"] [unique_id "amuFwc637Arlr6Yb1Ef0bwAAhwg"]
[Thu Jul 30 12:11:29.511352 2026] [security2:error] [pid 703393:tid 703624] [client 20.52.125.110:8095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cAAAAOo"]
[Thu Jul 30 12:11:29.609897 2026] [security2:error] [pid 703393:tid 703645] [client 20.91.208.34:22692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/sixxis.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cQAAAP8"]
[Thu Jul 30 12:11:29.610020 2026] [security2:error] [pid 703393:tid 703645] [client 20.91.208.34:22692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/sixxis.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cQAAAP8"]
[Thu Jul 30 12:11:29.621999 2026] [security2:error] [pid 703393:tid 703571] [client 20.226.5.174:27872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/albin.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cgAAALU"]
[Thu Jul 30 12:11:29.776931 2026] [security2:error] [pid 703393:tid 703626] [client 20.63.98.115:42994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/k.php"] [unique_id "amuFwc637Arlr6Yb1Ef0dQAAAOw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:11:29.948542 2026] [security2:error] [pid 703393:tid 703572] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFwc637Arlr6Yb1Ef0cwAAthQ"]
[Thu Jul 30 12:11:30.192971 2026] [security2:error] [pid 703393:tid 703529] [client 20.91.208.34:24122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/yj09.php"] [unique_id "amuFws637Arlr6Yb1Ef0gAAAAIs"]
[Thu Jul 30 12:11:30.193094 2026] [security2:error] [pid 703393:tid 703529] [client 20.91.208.34:24122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/yj09.php"] [unique_id "amuFws637Arlr6Yb1Ef0gAAAAIs"]
[Thu Jul 30 12:11:30.198149 2026] [security2:error] [pid 703393:tid 703630] [client 20.52.125.110:8479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuFws637Arlr6Yb1Ef0gQAAAPA"]
[Thu Jul 30 12:11:30.331481 2026] [security2:error] [pid 703393:tid 703564] [client 20.52.125.110:14533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/bnm.php"] [unique_id "amuFws637Arlr6Yb1Ef0iQAAAK4"]
[Thu Jul 30 12:11:30.515402 2026] [security2:error] [pid 703393:tid 703563] [client 43.154.250.181:47990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.250.154.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/theme/darm_theme_basic01/page_html/privacy.php"] [unique_id "amuFws637Arlr6Yb1Ef0hgAAAK0"]
[Thu Jul 30 12:11:30.616315 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.208.34:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/k.php"] [unique_id "amuFws637Arlr6Yb1Ef0lAAAANo"]
[Thu Jul 30 12:11:30.616447 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.208.34:22715] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/k.php"] [unique_id "amuFws637Arlr6Yb1Ef0lAAAANo"]
[Thu Jul 30 12:11:30.722756 2026] [security2:error] [pid 703393:tid 703585] [client 191.232.199.39:54096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/fw.php"] [unique_id "amuFws637Arlr6Yb1Ef0lwAAAMM"]
[Thu Jul 30 12:11:30.869593 2026] [security2:error] [pid 703393:tid 703590] [client 20.52.125.110:14590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/bootstrap.php"] [unique_id "amuFws637Arlr6Yb1Ef0mgAAAMg"]
[Thu Jul 30 12:11:30.879679 2026] [security2:error] [pid 703393:tid 703638] [client 20.52.125.110:8126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuFws637Arlr6Yb1Ef0mwAAAPg"]
[Thu Jul 30 12:11:31.080616 2026] [security2:error] [pid 703393:tid 703582] [client 20.104.18.253:30149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/bootstrap.php"] [unique_id "amuFw8637Arlr6Yb1Ef0pAAAAMA"]
[Thu Jul 30 12:11:31.091637 2026] [security2:error] [pid 703393:tid 703642] [client 20.91.208.34:58572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/k2.php"] [unique_id "amuFw8637Arlr6Yb1Ef0pQAAAPw"]
[Thu Jul 30 12:11:31.091737 2026] [security2:error] [pid 703393:tid 703642] [client 20.91.208.34:58572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/k2.php"] [unique_id "amuFw8637Arlr6Yb1Ef0pQAAAPw"]
[Thu Jul 30 12:11:31.258889 2026] [security2:error] [pid 703393:tid 703596] [client 20.226.5.174:27897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/amfsqvgv.php"] [unique_id "amuFw8637Arlr6Yb1Ef0qQAAAM4"]
[Thu Jul 30 12:11:31.307538 2026] [security2:error] [pid 703393:tid 703643] [client 182.239.122.251:4200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuFws637Arlr6Yb1Ef0jgAA_SM"]
[Thu Jul 30 12:11:31.361883 2026] [security2:error] [pid 703393:tid 703643] [client 182.239.122.251:4200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuFws637Arlr6Yb1Ef0jwAA_RE"]
[Thu Jul 30 12:11:31.452787 2026] [security2:error] [pid 703393:tid 703632] [client 20.52.125.110:8509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuFw8637Arlr6Yb1Ef0uwAAAPI"]
[Thu Jul 30 12:11:31.482159 2026] [security2:error] [pid 703393:tid 703615] [client 20.52.125.110:14591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/buy.php"] [unique_id "amuFw8637Arlr6Yb1Ef0vgAAAOE"]
[Thu Jul 30 12:11:31.659661 2026] [security2:error] [pid 703393:tid 703530] [client 191.232.199.39:6878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/dropdown.php"] [unique_id "amuFw8637Arlr6Yb1Ef02wAAAIw"]
[Thu Jul 30 12:11:31.755924 2026] [security2:error] [pid 703393:tid 703542] [client 20.63.98.115:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-fmfile.php"] [unique_id "amuFw8637Arlr6Yb1Ef03gAAAJg"]
[Thu Jul 30 12:11:31.960298 2026] [security2:error] [pid 703393:tid 703527] [client 20.52.125.110:8233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuFw8637Arlr6Yb1Ef05wAAAIk"]
[Thu Jul 30 12:11:31.995462 2026] [security2:error] [pid 703393:tid 703611] [client 20.104.18.253:41083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/buy.php"] [unique_id "amuFw8637Arlr6Yb1Ef06QAAAN0"]
[Thu Jul 30 12:11:32.064775 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:10040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/w.php"] [unique_id "amuFxM637Arlr6Yb1Ef07wAAAOU"]
[Thu Jul 30 12:11:32.064920 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:10040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/w.php"] [unique_id "amuFxM637Arlr6Yb1Ef07wAAAOU"]
[Thu Jul 30 12:11:32.104821 2026] [security2:error] [pid 703393:tid 703650] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFw8637Arlr6Yb1Ef0ugABBDk"]
[Thu Jul 30 12:11:32.248950 2026] [security2:error] [pid 703393:tid 703477] [remote 97.74.93.24:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dov.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amuFxM637Arlr6Yb1Ef09AAA7lM"]
[Thu Jul 30 12:11:32.546581 2026] [security2:error] [pid 703393:tid 703597] [client 20.52.125.110:8249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuFxM637Arlr6Yb1Ef0-wAAAM8"]
[Thu Jul 30 12:11:32.656756 2026] [security2:error] [pid 703393:tid 703638] [client 20.226.5.174:27856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/ant.php"] [unique_id "amuFxM637Arlr6Yb1Ef0_wAAAPg"]
[Thu Jul 30 12:11:32.714823 2026] [security2:error] [pid 703393:tid 703629] [client 20.63.98.115:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wi.php"] [unique_id "amuFxM637Arlr6Yb1Ef1AAAAAO8"]
[Thu Jul 30 12:11:33.104783 2026] [core:notice] [pid 703393:tid 703538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:33.111595 2026] [security2:error] [pid 703393:tid 703538] [client 103.215.74.26:48958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFxc637Arlr6Yb1Ef1BwAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:33.120536 2026] [security2:error] [pid 703393:tid 703639] [client 20.52.125.110:8098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuFxc637Arlr6Yb1Ef1CQAAAPk"]
[Thu Jul 30 12:11:33.127698 2026] [security2:error] [pid 703393:tid 703601] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFxM637Arlr6Yb1Ef09wAAANM"]
[Thu Jul 30 12:11:33.184446 2026] [security2:error] [pid 703393:tid 703600] [client 20.52.125.110:14529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/chosen.php"] [unique_id "amuFxc637Arlr6Yb1Ef1DQAAANI"]
[Thu Jul 30 12:11:33.294086 2026] [security2:error] [pid 703393:tid 703553] [client 191.232.199.39:6857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/makeasmtp.php"] [unique_id "amuFxc637Arlr6Yb1Ef1DgAAAKM"]
[Thu Jul 30 12:11:33.637808 2026] [core:notice] [pid 703393:tid 703627] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:33.789195 2026] [security2:error] [pid 703393:tid 703572] [client 20.63.98.115:44109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/php8.php"] [unique_id "amuFxc637Arlr6Yb1Ef1GQAAALY"]
[Thu Jul 30 12:11:33.893967 2026] [core:notice] [pid 703393:tid 703536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:33.900425 2026] [security2:error] [pid 703393:tid 703536] [client 103.215.74.26:48970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFxc637Arlr6Yb1Ef1GgAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:33.946912 2026] [security2:error] [pid 703393:tid 703557] [client 20.52.125.110:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/class-wp-image.php"] [unique_id "amuFxc637Arlr6Yb1Ef1GwAAAKc"]
[Thu Jul 30 12:11:34.175683 2026] [security2:error] [pid 703393:tid 703618] [client 20.91.208.34:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/fpwch.php"] [unique_id "amuFxs637Arlr6Yb1Ef1IAAAAOQ"]
[Thu Jul 30 12:11:34.175824 2026] [security2:error] [pid 703393:tid 703618] [client 20.91.208.34:22703] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/fpwch.php"] [unique_id "amuFxs637Arlr6Yb1Ef1IAAAAOQ"]
[Thu Jul 30 12:11:34.424077 2026] [security2:error] [pid 703393:tid 703564] [client 20.226.5.174:27844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/appreciators.php"] [unique_id "amuFxs637Arlr6Yb1Ef1KAAAAK4"]
[Thu Jul 30 12:11:34.645410 2026] [core:notice] [pid 703393:tid 703631] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:34.651511 2026] [security2:error] [pid 703393:tid 703631] [client 103.215.74.26:48982] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFxs637Arlr6Yb1Ef1LAAAAPE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:34.714379 2026] [security2:error] [pid 703393:tid 703636] [client 191.232.199.39:6869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-sigunq.php"] [unique_id "amuFxs637Arlr6Yb1Ef1LQAAAPY"]
[Thu Jul 30 12:11:34.797691 2026] [security2:error] [pid 703393:tid 703597] [client 20.104.18.253:42510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/chosen.php"] [unique_id "amuFxs637Arlr6Yb1Ef1MgAAAM8"]
[Thu Jul 30 12:11:34.806248 2026] [security2:error] [pid 703393:tid 703585] [client 191.232.199.39:54140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-login.php"] [unique_id "amuFxs637Arlr6Yb1Ef1MQAAAMM"]
[Thu Jul 30 12:11:35.038028 2026] [security2:error] [pid 703393:tid 703623] [client 20.63.98.115:20600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/tes.php"] [unique_id "amuFx8637Arlr6Yb1Ef1MwAAAOk"]
[Thu Jul 30 12:11:35.084554 2026] [security2:error] [pid 703393:tid 703544] [client 20.52.125.110:14548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/classsmtps.php"] [unique_id "amuFx8637Arlr6Yb1Ef1NAAAAJo"]
[Thu Jul 30 12:11:35.403459 2026] [core:notice] [pid 703393:tid 703648] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:35.410101 2026] [security2:error] [pid 703393:tid 703648] [client 103.215.74.26:48984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFx8637Arlr6Yb1Ef1PQAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:35.498414 2026] [security2:error] [pid 703393:tid 703601] [client 20.52.125.110:8472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuFx8637Arlr6Yb1Ef1PgAAANM"]
[Thu Jul 30 12:11:35.535396 2026] [security2:error] [pid 703393:tid 703632] [client 20.91.208.34:24098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/w2025.php"] [unique_id "amuFx8637Arlr6Yb1Ef1PwAAAPI"]
[Thu Jul 30 12:11:35.535537 2026] [security2:error] [pid 703393:tid 703632] [client 20.91.208.34:24098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/w2025.php"] [unique_id "amuFx8637Arlr6Yb1Ef1PwAAAPI"]
[Thu Jul 30 12:11:35.601111 2026] [security2:error] [pid 703393:tid 703626] [client 20.104.18.253:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/class-wp-image.php"] [unique_id "amuFx8637Arlr6Yb1Ef1QAAAAOw"]
[Thu Jul 30 12:11:35.641564 2026] [security2:error] [pid 703393:tid 703624] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFx8637Arlr6Yb1Ef1OAAA6mU"], referer: https://www.spececigarette.com/wp-content/plugins/saber-commerce/Readme.txt
[Thu Jul 30 12:11:35.779789 2026] [security2:error] [pid 703393:tid 703643] [client 20.52.125.110:14918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/classwithtostring.php"] [unique_id "amuFx8637Arlr6Yb1Ef1RwAAAP0"]
[Thu Jul 30 12:11:35.976959 2026] [security2:error] [pid 703393:tid 703525] [client 20.226.5.174:27979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/archive.php"] [unique_id "amuFx8637Arlr6Yb1Ef1TAAAAIc"]
[Thu Jul 30 12:11:36.125710 2026] [core:notice] [pid 703393:tid 703609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:36.132527 2026] [security2:error] [pid 703393:tid 703609] [client 103.215.74.26:48994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFyM637Arlr6Yb1Ef1TwAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:36.164541 2026] [security2:error] [pid 703393:tid 703496] [remote 57.141.0.54:54078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/626900273/feed/rss2/"] [unique_id "amuFyM637Arlr6Yb1Ef1UAAAsWY"]
[Thu Jul 30 12:11:36.205736 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:20597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/about.php"] [unique_id "amuFyM637Arlr6Yb1Ef1UgAAAKU"]
[Thu Jul 30 12:11:36.358404 2026] [core:error] [pid 703393:tid 703536] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:36.358429 2026] [core:error] [pid 703393:tid 703536] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:36.380704 2026] [security2:error] [pid 703393:tid 703641] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFyM637Arlr6Yb1Ef1TQAA-18"]
[Thu Jul 30 12:11:36.472616 2026] [security2:error] [pid 703393:tid 703629] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuFx8637Arlr6Yb1Ef1SAAA72w"]
[Thu Jul 30 12:11:36.478181 2026] [security2:error] [pid 703393:tid 703565] [client 20.52.125.110:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/config.php"] [unique_id "amuFyM637Arlr6Yb1Ef1WgAAAK8"]
[Thu Jul 30 12:11:36.908722 2026] [security2:error] [pid 703393:tid 703532] [client 20.91.208.34:58578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/FWAZ.php"] [unique_id "amuFyM637Arlr6Yb1Ef1YgAAAI4"]
[Thu Jul 30 12:11:36.908843 2026] [security2:error] [pid 703393:tid 703532] [client 20.91.208.34:58578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/FWAZ.php"] [unique_id "amuFyM637Arlr6Yb1Ef1YgAAAI4"]
[Thu Jul 30 12:11:37.054447 2026] [security2:error] [pid 703393:tid 703611] [client 20.104.18.253:41089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/classsmtps.php"] [unique_id "amuFyc637Arlr6Yb1Ef1ZQAAAN0"]
[Thu Jul 30 12:11:37.205032 2026] [security2:error] [pid 703393:tid 703631] [client 89.238.167.166:43404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuFyc637Arlr6Yb1Ef1ZgAAAPE"]
[Thu Jul 30 12:11:37.205162 2026] [security2:error] [pid 703393:tid 703631] [client 89.238.167.166:43404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuFyc637Arlr6Yb1Ef1ZgAAAPE"]
[Thu Jul 30 12:11:37.225612 2026] [security2:error] [pid 703393:tid 703584] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuFyM637Arlr6Yb1Ef1XQAAAMI"]
[Thu Jul 30 12:11:37.407700 2026] [security2:error] [pid 703393:tid 703592] [client 20.91.208.34:55075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/qterm.php"] [unique_id "amuFyc637Arlr6Yb1Ef1agAAAMo"]
[Thu Jul 30 12:11:37.407807 2026] [security2:error] [pid 703393:tid 703592] [client 20.91.208.34:55075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/qterm.php"] [unique_id "amuFyc637Arlr6Yb1Ef1agAAAMo"]
[Thu Jul 30 12:11:37.786659 2026] [security2:error] [pid 703393:tid 703571] [client 20.91.208.34:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/blurbs.php"] [unique_id "amuFyc637Arlr6Yb1Ef1dgAAALU"]
[Thu Jul 30 12:11:37.786746 2026] [security2:error] [pid 703393:tid 703571] [client 20.91.208.34:55076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/blurbs.php"] [unique_id "amuFyc637Arlr6Yb1Ef1dgAAALU"]
[Thu Jul 30 12:11:37.972793 2026] [security2:error] [pid 703393:tid 703523] [client 20.104.18.253:31191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/classwithtostring.php"] [unique_id "amuFyc637Arlr6Yb1Ef1ewAAAIU"]
[Thu Jul 30 12:11:38.404606 2026] [security2:error] [pid 703393:tid 703600] [client 20.91.208.34:55087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-ws68.php"] [unique_id "amuFys637Arlr6Yb1Ef1gAAAANI"]
[Thu Jul 30 12:11:38.404717 2026] [security2:error] [pid 703393:tid 703600] [client 20.91.208.34:55087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-ws68.php"] [unique_id "amuFys637Arlr6Yb1Ef1gAAAANI"]
[Thu Jul 30 12:11:38.501335 2026] [security2:error] [pid 703393:tid 703606] [client 20.52.125.110:14541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/core.php"] [unique_id "amuFys637Arlr6Yb1Ef1hAAAANg"]
[Thu Jul 30 12:11:38.749432 2026] [security2:error] [pid 703393:tid 703511] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFys637Arlr6Yb1Ef1fAAAoHU"]
[Thu Jul 30 12:11:38.749660 2026] [security2:error] [pid 703393:tid 703550] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuFys637Arlr6Yb1Ef1fAAAoHU"]
[Thu Jul 30 12:11:38.837196 2026] [security2:error] [pid 703393:tid 703580] [client 20.91.208.34:58621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/xyn.php"] [unique_id "amuFys637Arlr6Yb1Ef1iAAAAL4"]
[Thu Jul 30 12:11:38.837275 2026] [security2:error] [pid 703393:tid 703580] [client 20.91.208.34:58621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/xyn.php"] [unique_id "amuFys637Arlr6Yb1Ef1iAAAAL4"]
[Thu Jul 30 12:11:38.950480 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/headers.php"] [unique_id "amuFys637Arlr6Yb1Ef1iwAAAQM"]
[Thu Jul 30 12:11:39.129537 2026] [security2:error] [pid 703393:tid 703577] [client 20.104.18.253:42535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/config.php"] [unique_id "amuFy8637Arlr6Yb1Ef1jwAAALs"]
[Thu Jul 30 12:11:39.240616 2026] [security2:error] [pid 703393:tid 703567] [client 213.163.206.91:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuFys637Arlr6Yb1Ef1iQAAALE"]
[Thu Jul 30 12:11:39.324356 2026] [security2:error] [pid 703393:tid 703564] [client 20.226.5.174:28231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/as.php"] [unique_id "amuFy8637Arlr6Yb1Ef1kwAAAK4"]
[Thu Jul 30 12:11:39.336713 2026] [security2:error] [pid 703393:tid 703650] [client 20.91.208.34:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ccc.php"] [unique_id "amuFy8637Arlr6Yb1Ef1lAAAAQQ"]
[Thu Jul 30 12:11:39.336799 2026] [security2:error] [pid 703393:tid 703650] [client 20.91.208.34:56128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/ccc.php"] [unique_id "amuFy8637Arlr6Yb1Ef1lAAAAQQ"]
[Thu Jul 30 12:11:39.373249 2026] [security2:error] [pid 703393:tid 703603] [client 191.232.199.39:54111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/simple.php"] [unique_id "amuFy8637Arlr6Yb1Ef1lQAAANU"]
[Thu Jul 30 12:11:39.486597 2026] [core:notice] [pid 703393:tid 703517] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:39.803038 2026] [security2:error] [pid 703393:tid 703637] [client 20.52.125.110:14278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/css.php"] [unique_id "amuFy8637Arlr6Yb1Ef1oAAAAPc"]
[Thu Jul 30 12:11:39.925509 2026] [security2:error] [pid 703393:tid 703595] [client 20.91.208.34:10017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/get.php"] [unique_id "amuFy8637Arlr6Yb1Ef1pAAAAM0"]
[Thu Jul 30 12:11:39.925612 2026] [security2:error] [pid 703393:tid 703595] [client 20.91.208.34:10017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/get.php"] [unique_id "amuFy8637Arlr6Yb1Ef1pAAAAM0"]
[Thu Jul 30 12:11:40.101891 2026] [security2:error] [pid 703393:tid 703533] [client 20.104.18.253:36809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/core.php"] [unique_id "amuFzM637Arlr6Yb1Ef1qAAAAI8"]
[Thu Jul 30 12:11:40.437628 2026] [security2:error] [pid 703393:tid 703596] [client 20.91.208.34:55103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/images.php"] [unique_id "amuFzM637Arlr6Yb1Ef1rAAAAM4"]
[Thu Jul 30 12:11:40.437770 2026] [security2:error] [pid 703393:tid 703596] [client 20.91.208.34:55103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/images.php"] [unique_id "amuFzM637Arlr6Yb1Ef1rAAAAM4"]
[Thu Jul 30 12:11:40.618591 2026] [security2:error] [pid 703393:tid 703568] [client 20.226.5.174:28233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/atomlib.php"] [unique_id "amuFzM637Arlr6Yb1Ef1sgAAALI"]
[Thu Jul 30 12:11:40.765067 2026] [security2:error] [pid 703393:tid 703594] [client 213.163.206.91:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuFzM637Arlr6Yb1Ef1rQAAAMw"]
[Thu Jul 30 12:11:40.851400 2026] [security2:error] [pid 703393:tid 703624] [client 20.91.208.34:55086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/alls.php"] [unique_id "amuFzM637Arlr6Yb1Ef1tQAAAOo"]
[Thu Jul 30 12:11:40.851503 2026] [security2:error] [pid 703393:tid 703624] [client 20.91.208.34:55086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/alls.php"] [unique_id "amuFzM637Arlr6Yb1Ef1tQAAAOo"]
[Thu Jul 30 12:11:41.494386 2026] [security2:error] [pid 703393:tid 703649] [client 20.91.208.34:24096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/coffexium.php"] [unique_id "amuFzc637Arlr6Yb1Ef1vwAAAQM"]
[Thu Jul 30 12:11:41.494505 2026] [security2:error] [pid 703393:tid 703649] [client 20.91.208.34:24096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/coffexium.php"] [unique_id "amuFzc637Arlr6Yb1Ef1vwAAAQM"]
[Thu Jul 30 12:11:41.684408 2026] [security2:error] [pid 703393:tid 703643] [client 20.226.5.174:28248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/autoload_classmap.php"] [unique_id "amuFzc637Arlr6Yb1Ef1xQAAAP0"]
[Thu Jul 30 12:11:41.760461 2026] [security2:error] [pid 703393:tid 703639] [client 191.232.199.39:54081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/classsmtps.php"] [unique_id "amuFzc637Arlr6Yb1Ef1xgAAAPk"]
[Thu Jul 30 12:11:41.862146 2026] [core:notice] [pid 703393:tid 703641] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:41.869266 2026] [security2:error] [pid 703393:tid 703641] [client 103.215.74.26:49006] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFzc637Arlr6Yb1Ef1xwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:42.060684 2026] [security2:error] [pid 703393:tid 703578] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFzc637Arlr6Yb1Ef1xAAAvH8"], referer: https://www.spececigarette.com/wp-content/plugins/saber-commerce/README.txt
[Thu Jul 30 12:11:42.174600 2026] [security2:error] [pid 703393:tid 703537] [client 20.91.208.34:10044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/red.php"] [unique_id "amuFzs637Arlr6Yb1Ef1zgAAAJM"]
[Thu Jul 30 12:11:42.174710 2026] [security2:error] [pid 703393:tid 703537] [client 20.91.208.34:10044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/red.php"] [unique_id "amuFzs637Arlr6Yb1Ef1zgAAAJM"]
[Thu Jul 30 12:11:42.472815 2026] [security2:error] [pid 703393:tid 703426] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/sellbery/readme.txt"] [unique_id "amuFzs637Arlr6Yb1Ef11QAA7iA"]
[Thu Jul 30 12:11:42.611838 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:42.618689 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:49018] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFzs637Arlr6Yb1Ef11gAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:42.759163 2026] [security2:error] [pid 703393:tid 703622] [client 20.226.5.174:28234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/bb.php"] [unique_id "amuFzs637Arlr6Yb1Ef12wAAAOg"]
[Thu Jul 30 12:11:42.993923 2026] [security2:error] [pid 703393:tid 703583] [client 20.63.98.115:65416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin.php"] [unique_id "amuFzs637Arlr6Yb1Ef13wAAAME"]
[Thu Jul 30 12:11:43.028101 2026] [security2:error] [pid 703393:tid 703548] [client 20.91.208.34:58608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuFz8637Arlr6Yb1Ef14AAAAJ4"]
[Thu Jul 30 12:11:43.060738 2026] [security2:error] [pid 703393:tid 703642] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuFzs637Arlr6Yb1Ef12gAA_H0"]
[Thu Jul 30 12:11:43.186407 2026] [security2:error] [pid 703393:tid 703588] [client 20.91.208.34:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuFz8637Arlr6Yb1Ef14gAAAMY"]
[Thu Jul 30 12:11:43.186533 2026] [security2:error] [pid 703393:tid 703588] [client 20.91.208.34:58608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuFz8637Arlr6Yb1Ef14gAAAMY"]
[Thu Jul 30 12:11:43.371208 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:43.377899 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:32958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuFz8637Arlr6Yb1Ef15gAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:43.845055 2026] [security2:error] [pid 703393:tid 703646] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuFz8637Arlr6Yb1Ef15wABAHY"], referer: https://www.spececigarette.com/wp-content/plugins/sellbery/Readme.txt
[Thu Jul 30 12:11:43.885840 2026] [security2:error] [pid 703393:tid 703584] [client 20.52.125.110:14581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/database.php"] [unique_id "amuFz8637Arlr6Yb1Ef18QAAAMI"]
[Thu Jul 30 12:11:44.011377 2026] [security2:error] [pid 703393:tid 703606] [client 20.91.208.34:22699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF0M637Arlr6Yb1Ef19QAAANg"]
[Thu Jul 30 12:11:44.090942 2026] [core:notice] [pid 703393:tid 703535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:44.098207 2026] [security2:error] [pid 703393:tid 703535] [client 103.215.74.26:32972] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF0M637Arlr6Yb1Ef19wAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:44.120145 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:20734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/flower.php"] [unique_id "amuF0M637Arlr6Yb1Ef1-AAAAQI"]
[Thu Jul 30 12:11:44.173792 2026] [security2:error] [pid 703393:tid 703529] [client 20.91.208.34:22699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF0M637Arlr6Yb1Ef1-QAAAIs"]
[Thu Jul 30 12:11:44.255834 2026] [security2:error] [pid 703393:tid 703563] [client 191.232.199.39:6892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wso112233.php"] [unique_id "amuF0M637Arlr6Yb1Ef1-gAAAK0"]
[Thu Jul 30 12:11:44.328469 2026] [security2:error] [pid 703393:tid 703573] [client 20.91.208.34:22699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-content/index.php"] [unique_id "amuF0M637Arlr6Yb1Ef1_gAAALc"]
[Thu Jul 30 12:11:44.328576 2026] [security2:error] [pid 703393:tid 703573] [client 20.91.208.34:22699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-content/index.php"] [unique_id "amuF0M637Arlr6Yb1Ef1_gAAALc"]
[Thu Jul 30 12:11:44.332686 2026] [security2:error] [pid 703393:tid 703605] [client 20.226.5.174:28265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/bnm.php"] [unique_id "amuF0M637Arlr6Yb1Ef1_wAAANc"]
[Thu Jul 30 12:11:44.356522 2026] [security2:error] [pid 703393:tid 703604] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF0M637Arlr6Yb1Ef19gAA1hY"]
[Thu Jul 30 12:11:44.538699 2026] [security2:error] [pid 703393:tid 703568] [client 191.232.199.39:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-blog-header.php"] [unique_id "amuF0M637Arlr6Yb1Ef2BgAAALI"]
[Thu Jul 30 12:11:44.754616 2026] [security2:error] [pid 703393:tid 703643] [client 20.52.125.110:14550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/db.php"] [unique_id "amuF0M637Arlr6Yb1Ef2CAAAAP0"]
[Thu Jul 30 12:11:44.857882 2026] [core:notice] [pid 703393:tid 703546] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:44.865199 2026] [security2:error] [pid 703393:tid 703546] [client 103.215.74.26:32974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF0M637Arlr6Yb1Ef2DQAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:45.112650 2026] [security2:error] [pid 703393:tid 703575] [client 20.91.208.34:22683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/admin.php"] [unique_id "amuF0c637Arlr6Yb1Ef2EQAAALk"]
[Thu Jul 30 12:11:45.112751 2026] [security2:error] [pid 703393:tid 703575] [client 20.91.208.34:22683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/admin.php"] [unique_id "amuF0c637Arlr6Yb1Ef2EQAAALk"]
[Thu Jul 30 12:11:45.122079 2026] [security2:error] [pid 703393:tid 703507] [remote 65.181.111.156:49562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.111.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuF0c637Arlr6Yb1Ef2EgAA2nE"]
[Thu Jul 30 12:11:45.241204 2026] [security2:error] [pid 703393:tid 703650] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF0M637Arlr6Yb1Ef2DAABBBk"], referer: https://www.spececigarette.com/wp-content/plugins/sellbery/README.txt
[Thu Jul 30 12:11:45.337466 2026] [security2:error] [pid 703393:tid 703443] [remote 175.157.35.242:34875] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/http.wbxml"] [severity "WARNING"] [hostname "mail.nimna.lk"] [uri "/outlookgatewayb2/hxservice/getiploc"] [unique_id "amuF0c637Arlr6Yb1Ef2FgAAwzE"]
[Thu Jul 30 12:11:45.342621 2026] [core:error] [pid 703393:tid 703423] [remote 175.157.35.242:22054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:45.342644 2026] [core:error] [pid 703393:tid 703423] [remote 175.157.35.242:22054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:45.405848 2026] [security2:error] [pid 703393:tid 703439] [remote 175.157.35.242:34875] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/http.wbxml"] [severity "WARNING"] [hostname "mail.nimna.lk"] [uri "/outlookgatewayb2/hxservice/getiploc"] [unique_id "amuF0c637Arlr6Yb1Ef2GgAA_i0"]
[Thu Jul 30 12:11:45.452384 2026] [security2:error] [pid 703393:tid 703447] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "amuF0c637Arlr6Yb1Ef2GwAApDU"]
[Thu Jul 30 12:11:45.473325 2026] [security2:error] [pid 703393:tid 703400] [remote 175.157.35.242:34875] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/http.wbxml"] [severity "WARNING"] [hostname "mail.nimna.lk"] [uri "/outlookgatewayb2/hxservice/getiploc"] [unique_id "amuF0c637Arlr6Yb1Ef2HAAA9gY"]
[Thu Jul 30 12:11:45.537244 2026] [security2:error] [pid 703393:tid 703422] [remote 175.157.35.242:34875] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/http.wbxml"] [severity "WARNING"] [hostname "mail.nimna.lk"] [uri "/outlookgatewayb2/hxservice/getiploc"] [unique_id "amuF0c637Arlr6Yb1Ef2IAAAlBw"]
[Thu Jul 30 12:11:45.842233 2026] [security2:error] [pid 703393:tid 703611] [client 191.232.199.39:6881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/alfanew.php"] [unique_id "amuF0c637Arlr6Yb1Ef2IgAAAN0"]
[Thu Jul 30 12:11:45.942186 2026] [security2:error] [pid 703393:tid 703588] [client 191.232.199.39:51798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-trackback.php"] [unique_id "amuF0c637Arlr6Yb1Ef2JgAAAMY"]
[Thu Jul 30 12:11:46.074341 2026] [security2:error] [pid 703393:tid 703571] [client 20.104.18.253:45746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/css.php"] [unique_id "amuF0s637Arlr6Yb1Ef2KAAAALU"]
[Thu Jul 30 12:11:46.423162 2026] [security2:error] [pid 703393:tid 703607] [client 20.226.5.174:27981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/bootstrap.php"] [unique_id "amuF0s637Arlr6Yb1Ef2LgAAANk"]
[Thu Jul 30 12:11:46.815489 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.208.34:55080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/177.php"] [unique_id "amuF0s637Arlr6Yb1Ef2NQAAAMk"]
[Thu Jul 30 12:11:46.815601 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.208.34:55080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/177.php"] [unique_id "amuF0s637Arlr6Yb1Ef2NQAAAMk"]
[Thu Jul 30 12:11:46.964517 2026] [security2:error] [pid 703393:tid 703579] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuF0s637Arlr6Yb1Ef2LQAAAL0"]
[Thu Jul 30 12:11:47.042765 2026] [core:error] [pid 703393:tid 703457] [remote 175.157.35.242:22054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:47.042809 2026] [core:error] [pid 703393:tid 703457] [remote 175.157.35.242:22054] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:11:47.071711 2026] [security2:error] [pid 703393:tid 703573] [client 191.232.199.39:6855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/fw.php"] [unique_id "amuF08637Arlr6Yb1Ef2PQAAALc"]
[Thu Jul 30 12:11:47.904942 2026] [security2:error] [pid 703393:tid 703553] [client 20.52.125.110:14283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/default.php"] [unique_id "amuF08637Arlr6Yb1Ef2RAAAAKM"]
[Thu Jul 30 12:11:47.952022 2026] [security2:error] [pid 703393:tid 703546] [client 20.91.208.34:22710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/199.php"] [unique_id "amuF08637Arlr6Yb1Ef2RQAAAJw"]
[Thu Jul 30 12:11:47.952116 2026] [security2:error] [pid 703393:tid 703546] [client 20.91.208.34:22710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/199.php"] [unique_id "amuF08637Arlr6Yb1Ef2RQAAAJw"]
[Thu Jul 30 12:11:48.111964 2026] [security2:error] [pid 703393:tid 703545] [client 20.226.5.174:27790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/buy.php"] [unique_id "amuF1M637Arlr6Yb1Ef2TAAAAJs"]
[Thu Jul 30 12:11:48.452377 2026] [security2:error] [pid 703393:tid 703589] [client 191.232.199.39:6867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-login.php"] [unique_id "amuF1M637Arlr6Yb1Ef2TQAAAMc"]
[Thu Jul 30 12:11:48.543871 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:21393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuF1M637Arlr6Yb1Ef2UAAAAQM"]
[Thu Jul 30 12:11:48.649257 2026] [security2:error] [pid 703393:tid 703568] [client 20.104.18.253:45825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/database.php"] [unique_id "amuF1M637Arlr6Yb1Ef2VgAAALI"]
[Thu Jul 30 12:11:48.715940 2026] [security2:error] [pid 703393:tid 703587] [client 20.91.208.34:55041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/file52.php"] [unique_id "amuF1M637Arlr6Yb1Ef2VwAAAMU"]
[Thu Jul 30 12:11:48.716102 2026] [security2:error] [pid 703393:tid 703587] [client 20.91.208.34:55041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/file52.php"] [unique_id "amuF1M637Arlr6Yb1Ef2VwAAAMU"]
[Thu Jul 30 12:11:48.933805 2026] [security2:error] [pid 703393:tid 703640] [client 20.52.125.110:14564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/dropdown.php"] [unique_id "amuF1M637Arlr6Yb1Ef2WAAAAPo"]
[Thu Jul 30 12:11:49.350010 2026] [security2:error] [pid 703393:tid 703544] [client 20.226.5.174:27813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/chosen.php"] [unique_id "amuF1c637Arlr6Yb1Ef2XwAAAJo"]
[Thu Jul 30 12:11:49.771352 2026] [security2:error] [pid 703393:tid 703625] [client 20.52.125.110:14583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/edit.php"] [unique_id "amuF1c637Arlr6Yb1Ef2aQAAAOs"]
[Thu Jul 30 12:11:50.053440 2026] [security2:error] [pid 703393:tid 703636] [client 191.232.199.39:54089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-signup.php"] [unique_id "amuF1s637Arlr6Yb1Ef2agAAAPY"]
[Thu Jul 30 12:11:50.135270 2026] [security2:error] [pid 703393:tid 703615] [client 20.63.98.115:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content.php"] [unique_id "amuF1s637Arlr6Yb1Ef2awAAAOE"]
[Thu Jul 30 12:11:50.276393 2026] [security2:error] [pid 703393:tid 703594] [client 20.104.18.253:54810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/db.php"] [unique_id "amuF1s637Arlr6Yb1Ef2dgAAAMw"]
[Thu Jul 30 12:11:50.357083 2026] [security2:error] [pid 703393:tid 703563] [client 20.226.5.174:28236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/class-wp-image.php"] [unique_id "amuF1s637Arlr6Yb1Ef2dwAAAK0"]
[Thu Jul 30 12:11:50.392429 2026] [security2:error] [pid 703393:tid 703525] [client 20.52.125.110:14537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/f35.php"] [unique_id "amuF1s637Arlr6Yb1Ef2eAAAAIc"]
[Thu Jul 30 12:11:50.655018 2026] [core:notice] [pid 703393:tid 703573] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:50.661533 2026] [security2:error] [pid 703393:tid 703573] [client 103.215.74.26:32978] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF1s637Arlr6Yb1Ef2egAAALc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:50.957923 2026] [proxy:error] [pid 703393:tid 703448] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:50.957995 2026] [proxy_http:error] [pid 703393:tid 703448] [remote 74.7.175.147:51390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:50.958672 2026] [proxy:error] [pid 703393:tid 703448] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:11:50.958716 2026] [proxy_http:error] [pid 703393:tid 703448] [remote 74.7.175.147:51390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:11:51.173616 2026] [security2:error] [pid 703393:tid 703619] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF1s637Arlr6Yb1Ef2gQAA5UU"]
[Thu Jul 30 12:11:51.392355 2026] [core:notice] [pid 703393:tid 703628] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:51.398724 2026] [security2:error] [pid 703393:tid 703628] [client 103.215.74.26:32984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF18637Arlr6Yb1Ef2igAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:51.405919 2026] [security2:error] [pid 703393:tid 703545] [client 20.226.5.174:27793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/classsmtps.php"] [unique_id "amuF18637Arlr6Yb1Ef2iwAAAJs"]
[Thu Jul 30 12:11:51.633430 2026] [security2:error] [pid 703393:tid 703595] [client 20.52.125.110:14536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/f7.php"] [unique_id "amuF18637Arlr6Yb1Ef2jgAAAM0"]
[Thu Jul 30 12:11:51.689357 2026] [security2:error] [pid 703393:tid 703592] [client 20.104.18.253:26323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/default.php"] [unique_id "amuF18637Arlr6Yb1Ef2kQAAAMo"]
[Thu Jul 30 12:11:51.721407 2026] [core:error] [pid 703393:tid 703562] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 12:11:51.721431 2026] [core:error] [pid 703393:tid 703562] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 12:11:51.740828 2026] [security2:error] [pid 703393:tid 703566] [client 20.63.98.115:20569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/function.php"] [unique_id "amuF18637Arlr6Yb1Ef2mQAAALA"]
[Thu Jul 30 12:11:51.923281 2026] [security2:error] [pid 703393:tid 703469] [remote 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF18637Arlr6Yb1Ef2jQAAsks"], referer: https://www.spececigarette.com/wp-content/plugins/jetpack/Readme.txt
[Thu Jul 30 12:11:52.111633 2026] [security2:error] [pid 703393:tid 703598] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuF18637Arlr6Yb1Ef2jAAA0AI"]
[Thu Jul 30 12:11:52.122948 2026] [core:notice] [pid 703393:tid 703543] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:52.129530 2026] [security2:error] [pid 703393:tid 703543] [client 103.215.74.26:32992] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF2M637Arlr6Yb1Ef2nQAAAJk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:52.199202 2026] [security2:error] [pid 703393:tid 703540] [client 191.232.199.39:54132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-comments-post.php"] [unique_id "amuF2M637Arlr6Yb1Ef2nwAAAJY"]
[Thu Jul 30 12:11:52.252282 2026] [security2:error] [pid 703393:tid 703648] [client 20.91.208.34:10046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/geck.php"] [unique_id "amuF2M637Arlr6Yb1Ef2owAAAQI"]
[Thu Jul 30 12:11:52.252416 2026] [security2:error] [pid 703393:tid 703648] [client 20.91.208.34:10046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/geck.php"] [unique_id "amuF2M637Arlr6Yb1Ef2owAAAQI"]
[Thu Jul 30 12:11:52.446855 2026] [security2:error] [pid 703393:tid 703571] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF2M637Arlr6Yb1Ef2ngAAtUc"]
[Thu Jul 30 12:11:52.453951 2026] [security2:error] [pid 703393:tid 703584] [client 20.226.5.174:27789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/classwithtostring.php"] [unique_id "amuF2M637Arlr6Yb1Ef2qAAAAMI"]
[Thu Jul 30 12:11:52.768470 2026] [security2:error] [pid 703393:tid 703591] [client 20.104.18.253:54819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/dropdown.php"] [unique_id "amuF2M637Arlr6Yb1Ef2qwAAAMk"]
[Thu Jul 30 12:11:52.895403 2026] [core:notice] [pid 703393:tid 703549] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:52.902786 2026] [security2:error] [pid 703393:tid 703549] [client 103.215.74.26:33002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF2M637Arlr6Yb1Ef2swAAAJ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:52.959449 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.208.34:58610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/biufile.php"] [unique_id "amuF2M637Arlr6Yb1Ef2tAAAAIY"]
[Thu Jul 30 12:11:52.959566 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.208.34:58610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/biufile.php"] [unique_id "amuF2M637Arlr6Yb1Ef2tAAAAIY"]
[Thu Jul 30 12:11:53.192851 2026] [security2:error] [pid 703393:tid 703528] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF2M637Arlr6Yb1Ef2rAAAikg"], referer: https://www.spececigarette.com/wp-content/plugins/jetpack/README.txt
[Thu Jul 30 12:11:53.592494 2026] [security2:error] [pid 703393:tid 703630] [client 20.104.18.253:26064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/edit.php"] [unique_id "amuF2c637Arlr6Yb1Ef2xAAAAPA"]
[Thu Jul 30 12:11:53.625832 2026] [security2:error] [pid 703393:tid 703534] [client 20.226.5.174:28109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/config.php"] [unique_id "amuF2c637Arlr6Yb1Ef2xQAAAJA"]
[Thu Jul 30 12:11:53.636235 2026] [core:notice] [pid 703393:tid 703532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:53.642551 2026] [security2:error] [pid 703393:tid 703532] [client 103.215.74.26:17402] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF2c637Arlr6Yb1Ef2xgAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:53.785096 2026] [security2:error] [pid 703393:tid 703575] [client 74.7.230.6:35660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-e66db2d4.sby.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuF2c637Arlr6Yb1Ef2xwAAALk"]
[Thu Jul 30 12:11:53.842963 2026] [security2:error] [pid 703393:tid 703495] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/deepcore/readme.txt"] [unique_id "amuF2c637Arlr6Yb1Ef2zQABA2U"]
[Thu Jul 30 12:11:54.047863 2026] [security2:error] [pid 703393:tid 703523] [client 20.91.208.34:58613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/dejavu.php"] [unique_id "amuF2s637Arlr6Yb1Ef20wAAAIU"]
[Thu Jul 30 12:11:54.047966 2026] [security2:error] [pid 703393:tid 703523] [client 20.91.208.34:58613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/dejavu.php"] [unique_id "amuF2s637Arlr6Yb1Ef20wAAAIU"]
[Thu Jul 30 12:11:54.315244 2026] [security2:error] [pid 703393:tid 703538] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF2c637Arlr6Yb1Ef2zgAAlEw"]
[Thu Jul 30 12:11:54.355062 2026] [security2:error] [pid 703393:tid 703622] [client 20.104.18.253:30542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/f35.php"] [unique_id "amuF2s637Arlr6Yb1Ef22QAAAOg"]
[Thu Jul 30 12:11:54.752830 2026] [security2:error] [pid 703393:tid 703625] [client 20.91.208.34:55073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/aaf.php"] [unique_id "amuF2s637Arlr6Yb1Ef27wAAAOs"]
[Thu Jul 30 12:11:54.753010 2026] [security2:error] [pid 703393:tid 703625] [client 20.91.208.34:55073] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/aaf.php"] [unique_id "amuF2s637Arlr6Yb1Ef27wAAAOs"]
[Thu Jul 30 12:11:54.939170 2026] [security2:error] [pid 703393:tid 703581] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF2s637Arlr6Yb1Ef24AAAv18"], referer: https://www.spececigarette.com/wp-content/plugins/deepcore/Readme.txt
[Thu Jul 30 12:11:55.176457 2026] [security2:error] [pid 703393:tid 703564] [client 20.104.18.253:26063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/f7.php"] [unique_id "amuF28637Arlr6Yb1Ef2-gAAAK4"]
[Thu Jul 30 12:11:55.210322 2026] [security2:error] [pid 703393:tid 703604] [client 20.63.98.115:21413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/chosen.php"] [unique_id "amuF28637Arlr6Yb1Ef2-wAAANY"]
[Thu Jul 30 12:11:55.254404 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:33785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/anonsec.php"] [unique_id "amuF28637Arlr6Yb1Ef2_AAAAMg"]
[Thu Jul 30 12:11:55.254534 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:33785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/anonsec.php"] [unique_id "amuF28637Arlr6Yb1Ef2_AAAAMg"]
[Thu Jul 30 12:11:55.373354 2026] [security2:error] [pid 703393:tid 703634] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF28637Arlr6Yb1Ef29wAA9Go"]
[Thu Jul 30 12:11:55.485484 2026] [security2:error] [pid 703393:tid 703548] [client 20.91.208.34:10043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ha.php"] [unique_id "amuF28637Arlr6Yb1Ef3BAAAAJ4"]
[Thu Jul 30 12:11:55.485623 2026] [security2:error] [pid 703393:tid 703548] [client 20.91.208.34:10043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/ha.php"] [unique_id "amuF28637Arlr6Yb1Ef3BAAAAJ4"]
[Thu Jul 30 12:11:55.710717 2026] [security2:error] [pid 703393:tid 703636] [client 20.226.5.174:28127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/core.php"] [unique_id "amuF28637Arlr6Yb1Ef3BwAAAPY"]
[Thu Jul 30 12:11:56.025189 2026] [security2:error] [pid 703393:tid 703624] [client 191.232.199.39:6895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/simple.php"] [unique_id "amuF3M637Arlr6Yb1Ef3DwAAAOo"]
[Thu Jul 30 12:11:56.129587 2026] [security2:error] [pid 703393:tid 703574] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF28637Arlr6Yb1Ef3BgAAuHU"], referer: https://www.spececigarette.com/wp-content/plugins/deepcore/README.txt
[Thu Jul 30 12:11:56.178771 2026] [security2:error] [pid 703393:tid 703561] [client 146.190.89.220:34966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuF28637Arlr6Yb1Ef3CAAAAKs"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:11:57.033675 2026] [security2:error] [pid 703393:tid 703588] [client 146.190.89.220:34982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuF3M637Arlr6Yb1Ef3IQAAAMY"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:11:57.238050 2026] [security2:error] [pid 703393:tid 703591] [client 191.232.199.39:60748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/classsmtps.php"] [unique_id "amuF3c637Arlr6Yb1Ef3LQAAAMk"]
[Thu Jul 30 12:11:57.264992 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.208.34:24086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/hur.php"] [unique_id "amuF3c637Arlr6Yb1Ef3LgAAAPE"]
[Thu Jul 30 12:11:57.265129 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.208.34:24086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/hur.php"] [unique_id "amuF3c637Arlr6Yb1Ef3LgAAAPE"]
[Thu Jul 30 12:11:57.609213 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuF3c637Arlr6Yb1Ef3OQAAAI4"]
[Thu Jul 30 12:11:57.609347 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuF3c637Arlr6Yb1Ef3OQAAAI4"]
[Thu Jul 30 12:11:57.709138 2026] [security2:error] [pid 703393:tid 703557] [client 191.232.199.39:54110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-mail.php"] [unique_id "amuF3c637Arlr6Yb1Ef3PQAAAKc"]
[Thu Jul 30 12:11:57.748904 2026] [security2:error] [pid 703393:tid 703553] [client 85.208.96.195:52588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/25/joao-inaugura-obras-e-participa-de-plenaria-do-orcamento-democratico-no-sertao/"] [unique_id "amuF3c637Arlr6Yb1Ef3PgAAAKM"]
[Thu Jul 30 12:11:57.749113 2026] [security2:error] [pid 703393:tid 703553] [client 85.208.96.195:52588] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/25/joao-inaugura-obras-e-participa-de-plenaria-do-orcamento-democratico-no-sertao/"] [unique_id "amuF3c637Arlr6Yb1Ef3PgAAAKM"]
[Thu Jul 30 12:11:58.106010 2026] [security2:error] [pid 703393:tid 703600] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuF3s637Arlr6Yb1Ef3RwAAANI"]
[Thu Jul 30 12:11:58.106152 2026] [security2:error] [pid 703393:tid 703600] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuF3s637Arlr6Yb1Ef3RwAAANI"]
[Thu Jul 30 12:11:58.632162 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wicked.php"] [unique_id "amuF3s637Arlr6Yb1Ef3VAAAAPA"]
[Thu Jul 30 12:11:58.632313 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wicked.php"] [unique_id "amuF3s637Arlr6Yb1Ef3VAAAAPA"]
[Thu Jul 30 12:11:59.015230 2026] [security2:error] [pid 703393:tid 703526] [client 20.91.208.34:58619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/h02ugyh.php"] [unique_id "amuF38637Arlr6Yb1Ef3WQAAAIg"]
[Thu Jul 30 12:11:59.015370 2026] [security2:error] [pid 703393:tid 703526] [client 20.91.208.34:58619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/h02ugyh.php"] [unique_id "amuF38637Arlr6Yb1Ef3WQAAAIg"]
[Thu Jul 30 12:11:59.067753 2026] [security2:error] [pid 703393:tid 703589] [client 20.226.5.174:28096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/css.php"] [unique_id "amuF38637Arlr6Yb1Ef3WgAAAMc"]
[Thu Jul 30 12:11:59.155225 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wpx.php"] [unique_id "amuF38637Arlr6Yb1Ef3XgAAANM"]
[Thu Jul 30 12:11:59.155341 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wpx.php"] [unique_id "amuF38637Arlr6Yb1Ef3XgAAANM"]
[Thu Jul 30 12:11:59.360557 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:11:59.368072 2026] [security2:error] [pid 703393:tid 703523] [client 103.215.74.26:17412] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF38637Arlr6Yb1Ef3YgAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:11:59.491997 2026] [security2:error] [pid 703393:tid 703568] [client 20.91.208.34:58579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/155.php"] [unique_id "amuF38637Arlr6Yb1Ef3YwAAALI"]
[Thu Jul 30 12:11:59.492107 2026] [security2:error] [pid 703393:tid 703568] [client 20.91.208.34:58579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/155.php"] [unique_id "amuF38637Arlr6Yb1Ef3YwAAALI"]
[Thu Jul 30 12:11:59.694775 2026] [security2:error] [pid 703393:tid 703529] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/images.php"] [unique_id "amuF38637Arlr6Yb1Ef3aQAAAIs"]
[Thu Jul 30 12:11:59.694872 2026] [security2:error] [pid 703393:tid 703529] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/images.php"] [unique_id "amuF38637Arlr6Yb1Ef3aQAAAIs"]
[Thu Jul 30 12:12:00.091171 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:24088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ops.php"] [unique_id "amuF4M637Arlr6Yb1Ef3bAAAAOU"]
[Thu Jul 30 12:12:00.091268 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:24088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/ops.php"] [unique_id "amuF4M637Arlr6Yb1Ef3bAAAAOU"]
[Thu Jul 30 12:12:00.114278 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:00.120991 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:17420] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF4M637Arlr6Yb1Ef3bQAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:00.174035 2026] [security2:error] [pid 703393:tid 703598] [client 191.232.199.39:54101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-activate.php"] [unique_id "amuF4M637Arlr6Yb1Ef3bwAAANA"]
[Thu Jul 30 12:12:00.210411 2026] [security2:error] [pid 703393:tid 703550] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/1xmomo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3dQAAAKA"]
[Thu Jul 30 12:12:00.210516 2026] [security2:error] [pid 703393:tid 703550] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/1xmomo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3dQAAAKA"]
[Thu Jul 30 12:12:00.493106 2026] [security2:error] [pid 703393:tid 703628] [client 20.91.208.34:10006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/ingfo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3eQAAAO4"]
[Thu Jul 30 12:12:00.493200 2026] [security2:error] [pid 703393:tid 703628] [client 20.91.208.34:10006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/ingfo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3eQAAAO4"]
[Thu Jul 30 12:12:00.718281 2026] [security2:error] [pid 703393:tid 703613] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/1revo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3fQAAAN8"]
[Thu Jul 30 12:12:00.718413 2026] [security2:error] [pid 703393:tid 703613] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/1revo.php"] [unique_id "amuF4M637Arlr6Yb1Ef3fQAAAN8"]
[Thu Jul 30 12:12:00.780092 2026] [security2:error] [pid 703393:tid 703576] [client 20.226.5.174:28108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/database.php"] [unique_id "amuF4M637Arlr6Yb1Ef3gQAAALo"]
[Thu Jul 30 12:12:00.860688 2026] [core:notice] [pid 703393:tid 703612] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:00.867760 2026] [security2:error] [pid 703393:tid 703612] [client 103.215.74.26:17428] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF4M637Arlr6Yb1Ef3ggAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:00.963396 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:20862] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jesus.claims"] [uri "/1.php"] [unique_id "amuF4M637Arlr6Yb1Ef3gwAAAI8"]
[Thu Jul 30 12:12:00.963524 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:20862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/1.php"] [unique_id "amuF4M637Arlr6Yb1Ef3gwAAAI8"]
[Thu Jul 30 12:12:01.231275 2026] [security2:error] [pid 703393:tid 703622] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/cong.php"] [unique_id "amuF4c637Arlr6Yb1Ef3igAAAOg"]
[Thu Jul 30 12:12:01.231408 2026] [security2:error] [pid 703393:tid 703622] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/cong.php"] [unique_id "amuF4c637Arlr6Yb1Ef3igAAAOg"]
[Thu Jul 30 12:12:01.358278 2026] [security2:error] [pid 703393:tid 703566] [client 191.232.199.39:54094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/post.php"] [unique_id "amuF4c637Arlr6Yb1Ef3jwAAALA"]
[Thu Jul 30 12:12:01.508829 2026] [security2:error] [pid 703393:tid 703428] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/jetpack-search/readme.txt"] [unique_id "amuF4c637Arlr6Yb1Ef3kAAAviI"]
[Thu Jul 30 12:12:01.596725 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:01.603777 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:17434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF4c637Arlr6Yb1Ef3kQAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:01.736206 2026] [security2:error] [pid 703393:tid 703586] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/a.php"] [unique_id "amuF4c637Arlr6Yb1Ef3kwAAAMQ"]
[Thu Jul 30 12:12:01.736324 2026] [security2:error] [pid 703393:tid 703586] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/a.php"] [unique_id "amuF4c637Arlr6Yb1Ef3kwAAAMQ"]
[Thu Jul 30 12:12:01.940966 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/lv.php"] [unique_id "amuF4c637Arlr6Yb1Ef3nQAAAQI"]
[Thu Jul 30 12:12:01.959822 2026] [security2:error] [pid 703393:tid 703620] [client 20.226.5.174:27908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/db.php"] [unique_id "amuF4c637Arlr6Yb1Ef3ngAAAOY"]
[Thu Jul 30 12:12:02.207293 2026] [security2:error] [pid 703393:tid 703639] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF4c637Arlr6Yb1Ef3mQAA-S0"]
[Thu Jul 30 12:12:02.216805 2026] [security2:error] [pid 703393:tid 703549] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/srontol.php"] [unique_id "amuF4s637Arlr6Yb1Ef3oQAAAJ8"]
[Thu Jul 30 12:12:02.216910 2026] [security2:error] [pid 703393:tid 703549] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/srontol.php"] [unique_id "amuF4s637Arlr6Yb1Ef3oQAAAJ8"]
[Thu Jul 30 12:12:02.349452 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:02.355933 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:17438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF4s637Arlr6Yb1Ef3qAAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:02.459092 2026] [security2:error] [pid 703393:tid 703623] [client 191.232.199.39:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-blog-header.php"] [unique_id "amuF4s637Arlr6Yb1Ef3qQAAAOk"]
[Thu Jul 30 12:12:02.703381 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.208.34:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/error_log.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rAAAAKo"]
[Thu Jul 30 12:12:02.703525 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.208.34:55078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/error_log.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rAAAAKo"]
[Thu Jul 30 12:12:02.707937 2026] [security2:error] [pid 703393:tid 703608] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/reop3.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rQAAANo"]
[Thu Jul 30 12:12:02.708056 2026] [security2:error] [pid 703393:tid 703608] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/reop3.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rQAAANo"]
[Thu Jul 30 12:12:02.715705 2026] [security2:error] [pid 703393:tid 703583] [client 20.63.98.115:32902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/css.php"] [unique_id "amuF4s637Arlr6Yb1Ef3rgAAAME"]
[Thu Jul 30 12:12:02.757204 2026] [security2:error] [pid 703393:tid 703541] [client 191.232.199.39:54116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/wp-2019.php"] [unique_id "amuF4s637Arlr6Yb1Ef3sAAAAJc"]
[Thu Jul 30 12:12:03.086642 2026] [core:notice] [pid 703393:tid 703640] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:03.093436 2026] [security2:error] [pid 703393:tid 703640] [client 103.215.74.26:21654] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF48637Arlr6Yb1Ef3twAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:03.219897 2026] [security2:error] [pid 703393:tid 703596] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/file5.php"] [unique_id "amuF48637Arlr6Yb1Ef3uQAAAM4"]
[Thu Jul 30 12:12:03.220016 2026] [security2:error] [pid 703393:tid 703596] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/file5.php"] [unique_id "amuF48637Arlr6Yb1Ef3uQAAAM4"]
[Thu Jul 30 12:12:03.259868 2026] [security2:error] [pid 703393:tid 703457] [remote 20.54.134.42:2238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuF48637Arlr6Yb1Ef3ugAArD8"]
[Thu Jul 30 12:12:03.313945 2026] [security2:error] [pid 703393:tid 703409] [remote 57.141.0.19:21950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amuF48637Arlr6Yb1Ef3uwAA_A8"]
[Thu Jul 30 12:12:03.356679 2026] [security2:error] [pid 703393:tid 703649] [client 20.226.5.174:27966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/default.php"] [unique_id "amuF48637Arlr6Yb1Ef3vwAAAQM"]
[Thu Jul 30 12:12:03.727827 2026] [security2:error] [pid 703393:tid 703609] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/domvf.php"] [unique_id "amuF48637Arlr6Yb1Ef3xAAAANs"]
[Thu Jul 30 12:12:03.727938 2026] [security2:error] [pid 703393:tid 703609] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/domvf.php"] [unique_id "amuF48637Arlr6Yb1Ef3xAAAANs"]
[Thu Jul 30 12:12:03.782751 2026] [security2:error] [pid 703393:tid 703598] [client 185.189.112.11:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuF48637Arlr6Yb1Ef3xgAAANA"]
[Thu Jul 30 12:12:03.782841 2026] [security2:error] [pid 703393:tid 703598] [client 185.189.112.11:59580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuF48637Arlr6Yb1Ef3xgAAANA"]
[Thu Jul 30 12:12:03.795842 2026] [security2:error] [pid 703393:tid 703599] [client 191.232.199.39:6882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-trackback.php"] [unique_id "amuF48637Arlr6Yb1Ef3xwAAANE"]
[Thu Jul 30 12:12:03.830591 2026] [core:notice] [pid 703393:tid 703542] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:03.836911 2026] [security2:error] [pid 703393:tid 703542] [client 103.215.74.26:21658] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF48637Arlr6Yb1Ef3yAAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:03.874359 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.208.34:22662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/koala.php"] [unique_id "amuF48637Arlr6Yb1Ef3ywAAANc"]
[Thu Jul 30 12:12:03.874451 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.208.34:22662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/koala.php"] [unique_id "amuF48637Arlr6Yb1Ef3ywAAANc"]
[Thu Jul 30 12:12:04.207121 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/zero.php"] [unique_id "amuF5M637Arlr6Yb1Ef30QAAAMg"]
[Thu Jul 30 12:12:04.207227 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/zero.php"] [unique_id "amuF5M637Arlr6Yb1Ef30QAAAMg"]
[Thu Jul 30 12:12:04.471025 2026] [security2:error] [pid 703393:tid 703602] [client 20.63.98.115:21200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gecko.php"] [unique_id "amuF5M637Arlr6Yb1Ef32wAAANQ"]
[Thu Jul 30 12:12:04.490334 2026] [security2:error] [pid 703393:tid 703595] [client 20.91.208.34:22674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/mac.php"] [unique_id "amuF5M637Arlr6Yb1Ef33QAAAM0"]
[Thu Jul 30 12:12:04.490470 2026] [security2:error] [pid 703393:tid 703595] [client 20.91.208.34:22674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/mac.php"] [unique_id "amuF5M637Arlr6Yb1Ef33QAAAM0"]
[Thu Jul 30 12:12:04.571790 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:04.578552 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:21676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF5M637Arlr6Yb1Ef33gAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:04.717124 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/002.php"] [unique_id "amuF5M637Arlr6Yb1Ef34AAAAI4"]
[Thu Jul 30 12:12:04.717231 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/002.php"] [unique_id "amuF5M637Arlr6Yb1Ef34AAAAI4"]
[Thu Jul 30 12:12:04.863553 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.208.34:55051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wefile.php"] [unique_id "amuF5M637Arlr6Yb1Ef36gAAAKI"]
[Thu Jul 30 12:12:04.863638 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.208.34:55051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wefile.php"] [unique_id "amuF5M637Arlr6Yb1Ef36gAAAKI"]
[Thu Jul 30 12:12:04.959868 2026] [security2:error] [pid 703393:tid 703549] [client 191.232.199.39:54133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/hoot.php"] [unique_id "amuF5M637Arlr6Yb1Ef38AAAAJ8"]
[Thu Jul 30 12:12:05.184497 2026] [security2:error] [pid 703393:tid 703557] [client 119.157.28.214:53864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuF5M637Arlr6Yb1Ef37wAAAKc"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:12:05.224129 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/thoms.php"] [unique_id "amuF5c637Arlr6Yb1Ef39gAAAKk"]
[Thu Jul 30 12:12:05.224297 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/thoms.php"] [unique_id "amuF5c637Arlr6Yb1Ef39gAAAKk"]
[Thu Jul 30 12:12:05.310532 2026] [core:notice] [pid 703393:tid 703558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:05.317907 2026] [security2:error] [pid 703393:tid 703558] [client 103.215.74.26:21728] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF5c637Arlr6Yb1Ef39wAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:05.348591 2026] [security2:error] [pid 703393:tid 703586] [client 20.91.208.34:55102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF5c637Arlr6Yb1Ef3-QAAAMQ"]
[Thu Jul 30 12:12:05.387087 2026] [security2:error] [pid 703393:tid 703541] [client 191.232.199.39:6875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-signup.php"] [unique_id "amuF5c637Arlr6Yb1Ef3-gAAAJc"]
[Thu Jul 30 12:12:05.494606 2026] [security2:error] [pid 703393:tid 703610] [client 20.226.5.174:28153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/dropdown.php"] [unique_id "amuF5c637Arlr6Yb1Ef3_wAAANw"]
[Thu Jul 30 12:12:05.553305 2026] [security2:error] [pid 703393:tid 703629] [client 20.91.208.34:55102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF5c637Arlr6Yb1Ef4BAAAAO8"]
[Thu Jul 30 12:12:05.583878 2026] [security2:error] [pid 703393:tid 703627] [client 20.63.98.115:20827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xmlrpc.php"] [unique_id "amuF5c637Arlr6Yb1Ef3-AAAAO0"]
[Thu Jul 30 12:12:05.707144 2026] [security2:error] [pid 703393:tid 703617] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fi22.php"] [unique_id "amuF5c637Arlr6Yb1Ef4BQAAAOM"]
[Thu Jul 30 12:12:05.707243 2026] [security2:error] [pid 703393:tid 703617] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fi22.php"] [unique_id "amuF5c637Arlr6Yb1Ef4BQAAAOM"]
[Thu Jul 30 12:12:05.721260 2026] [security2:error] [pid 703393:tid 703537] [client 20.91.208.34:55102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/makeasmtp.php"] [unique_id "amuF5c637Arlr6Yb1Ef4BgAAAJM"]
[Thu Jul 30 12:12:05.721350 2026] [security2:error] [pid 703393:tid 703537] [client 20.91.208.34:55102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/makeasmtp.php"] [unique_id "amuF5c637Arlr6Yb1Ef4BgAAAJM"]
[Thu Jul 30 12:12:06.056644 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.208.34:24064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/2P.php"] [unique_id "amuF5s637Arlr6Yb1Ef4FgAAAKI"]
[Thu Jul 30 12:12:06.056732 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.208.34:24064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/2P.php"] [unique_id "amuF5s637Arlr6Yb1Ef4FgAAAKI"]
[Thu Jul 30 12:12:06.220206 2026] [security2:error] [pid 703393:tid 703620] [client 185.191.171.16:31308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/14/ministro-do-stf-proibe-uso-do-disque-100-para-denuncias-contra-passaporte-da-vacina/"] [unique_id "amuF5s637Arlr6Yb1Ef4HQAAAOY"]
[Thu Jul 30 12:12:06.220312 2026] [security2:error] [pid 703393:tid 703620] [client 185.191.171.16:31308] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/14/ministro-do-stf-proibe-uso-do-disque-100-para-denuncias-contra-passaporte-da-vacina/"] [unique_id "amuF5s637Arlr6Yb1Ef4HQAAAOY"]
[Thu Jul 30 12:12:06.414822 2026] [security2:error] [pid 703393:tid 703626] [client 20.91.208.34:9991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/.well-known/about.php"] [unique_id "amuF5s637Arlr6Yb1Ef4IAAAAOw"]
[Thu Jul 30 12:12:06.414927 2026] [security2:error] [pid 703393:tid 703626] [client 20.91.208.34:9991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/.well-known/about.php"] [unique_id "amuF5s637Arlr6Yb1Ef4IAAAAOw"]
[Thu Jul 30 12:12:06.760411 2026] [security2:error] [pid 703393:tid 703568] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuF5s637Arlr6Yb1Ef4HAAAALI"]
[Thu Jul 30 12:12:06.830589 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:32919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/f35.php"] [unique_id "amuF5s637Arlr6Yb1Ef4LAAAAMU"]
[Thu Jul 30 12:12:06.852920 2026] [security2:error] [pid 703393:tid 703607] [client 20.91.208.34:55101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuF5s637Arlr6Yb1Ef4LQAAANk"]
[Thu Jul 30 12:12:06.853045 2026] [security2:error] [pid 703393:tid 703607] [client 20.91.208.34:55101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuF5s637Arlr6Yb1Ef4LQAAANk"]
[Thu Jul 30 12:12:07.031604 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/82.php"] [unique_id "amuF58637Arlr6Yb1Ef4OgAAAMo"]
[Thu Jul 30 12:12:07.031689 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/82.php"] [unique_id "amuF58637Arlr6Yb1Ef4OgAAAMo"]
[Thu Jul 30 12:12:07.495686 2026] [security2:error] [pid 703393:tid 703565] [client 20.226.5.174:27924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/edit.php"] [unique_id "amuF58637Arlr6Yb1Ef4SgAAAK8"]
[Thu Jul 30 12:12:07.534881 2026] [security2:error] [pid 703393:tid 703636] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sx.php"] [unique_id "amuF58637Arlr6Yb1Ef4TgAAAPY"]
[Thu Jul 30 12:12:07.535016 2026] [security2:error] [pid 703393:tid 703636] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sx.php"] [unique_id "amuF58637Arlr6Yb1Ef4TgAAAPY"]
[Thu Jul 30 12:12:07.583174 2026] [security2:error] [pid 703393:tid 703545] [client 20.91.208.34:24110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/system_log.php"] [unique_id "amuF58637Arlr6Yb1Ef4UAAAAJs"]
[Thu Jul 30 12:12:07.583296 2026] [security2:error] [pid 703393:tid 703545] [client 20.91.208.34:24110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/system_log.php"] [unique_id "amuF58637Arlr6Yb1Ef4UAAAAJs"]
[Thu Jul 30 12:12:07.702206 2026] [security2:error] [pid 703393:tid 703628] [client 191.232.199.39:6904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-comments-post.php"] [unique_id "amuF58637Arlr6Yb1Ef4XwAAAO4"]
[Thu Jul 30 12:12:07.880970 2026] [security2:error] [pid 703393:tid 703535] [client 191.232.199.39:54121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/log.php"] [unique_id "amuF58637Arlr6Yb1Ef4eQAAAJE"]
[Thu Jul 30 12:12:08.036595 2026] [security2:error] [pid 703393:tid 703521] [remote 208.122.213.225:60874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jgp.fxh.temporary.site"] [uri "/wp-login.php"] [unique_id "amuF6M637Arlr6Yb1Ef4fgAAvn8"]
[Thu Jul 30 12:12:08.047562 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/dex.php"] [unique_id "amuF6M637Arlr6Yb1Ef4lAAAALU"]
[Thu Jul 30 12:12:08.047644 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/dex.php"] [unique_id "amuF6M637Arlr6Yb1Ef4lAAAALU"]
[Thu Jul 30 12:12:08.226746 2026] [core:notice] [pid 703393:tid 703419] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:08.446163 2026] [security2:error] [pid 703393:tid 703542] [client 20.91.208.34:24087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF6M637Arlr6Yb1Ef4owAAAJg"]
[Thu Jul 30 12:12:08.480485 2026] [security2:error] [pid 703393:tid 703551] [client 172.237.109.114:10147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF58637Arlr6Yb1Ef4egAAAKE"]
[Thu Jul 30 12:12:08.527120 2026] [security2:error] [pid 703393:tid 703534] [client 20.226.5.174:27956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/f35.php"] [unique_id "amuF6M637Arlr6Yb1Ef4pwAAAJA"]
[Thu Jul 30 12:12:08.582861 2026] [security2:error] [pid 703393:tid 703617] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fpwch.php"] [unique_id "amuF6M637Arlr6Yb1Ef4qgAAAOM"]
[Thu Jul 30 12:12:08.582960 2026] [security2:error] [pid 703393:tid 703617] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fpwch.php"] [unique_id "amuF6M637Arlr6Yb1Ef4qgAAAOM"]
[Thu Jul 30 12:12:08.597057 2026] [security2:error] [pid 703393:tid 703644] [client 20.63.98.115:36839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/autoload_classmap.php"] [unique_id "amuF6M637Arlr6Yb1Ef4rQAAAP4"]
[Thu Jul 30 12:12:08.744526 2026] [security2:error] [pid 703393:tid 703623] [client 20.91.208.34:24087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF6M637Arlr6Yb1Ef4sgAAAOk"]
[Thu Jul 30 12:12:08.950333 2026] [security2:error] [pid 703393:tid 703527] [client 191.232.199.39:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-mail.php"] [unique_id "amuF6M637Arlr6Yb1Ef4uQAAAIk"]
[Thu Jul 30 12:12:08.997239 2026] [security2:error] [pid 703393:tid 703614] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4qAAA4DU"], referer: https://www.spececigarette.com/wp-content/plugins/jetpack-search/Readme.txt
[Thu Jul 30 12:12:09.113693 2026] [security2:error] [pid 703393:tid 703605] [client 187.208.91.78:47318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4tAAAANc"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:12:09.115282 2026] [security2:error] [pid 703393:tid 703606] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/black.php"] [unique_id "amuF6c637Arlr6Yb1Ef4wQAAANg"]
[Thu Jul 30 12:12:09.115376 2026] [security2:error] [pid 703393:tid 703606] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/black.php"] [unique_id "amuF6c637Arlr6Yb1Ef4wQAAANg"]
[Thu Jul 30 12:12:09.121010 2026] [security2:error] [pid 703393:tid 703533] [client 20.91.208.34:24087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/crgio.php"] [unique_id "amuF6c637Arlr6Yb1Ef4wgAAAI8"]
[Thu Jul 30 12:12:09.121107 2026] [security2:error] [pid 703393:tid 703533] [client 20.91.208.34:24087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/crgio.php"] [unique_id "amuF6c637Arlr6Yb1Ef4wgAAAI8"]
[Thu Jul 30 12:12:09.471354 2026] [security2:error] [pid 703393:tid 703553] [client 191.232.199.39:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/bak.php"] [unique_id "amuF6c637Arlr6Yb1Ef40QAAAKM"]
[Thu Jul 30 12:12:09.540943 2026] [security2:error] [pid 703393:tid 703549] [client 172.237.109.114:41359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4ugAAAJ8"]
[Thu Jul 30 12:12:09.595738 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/loader.php"] [unique_id "amuF6c637Arlr6Yb1Ef40gAAAMo"]
[Thu Jul 30 12:12:09.595857 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/loader.php"] [unique_id "amuF6c637Arlr6Yb1Ef40gAAAMo"]
[Thu Jul 30 12:12:09.603164 2026] [security2:error] [pid 703393:tid 703640] [client 172.237.109.114:23523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4uwAAAPo"]
[Thu Jul 30 12:12:09.603996 2026] [security2:error] [pid 703393:tid 703642] [client 172.237.109.114:44166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF6c637Arlr6Yb1Ef4vQAAAPw"]
[Thu Jul 30 12:12:09.624031 2026] [security2:error] [pid 703393:tid 703562] [client 172.237.109.114:29276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuF6M637Arlr6Yb1Ef4vAAAAKw"]
[Thu Jul 30 12:12:09.697034 2026] [security2:error] [pid 703393:tid 703611] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF6c637Arlr6Yb1Ef4ywAA3T4"]
[Thu Jul 30 12:12:09.768164 2026] [security2:error] [pid 703393:tid 703581] [client 20.226.5.174:28113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rodneyleesmith.com"] [uri "/f7.php"] [unique_id "amuF6c637Arlr6Yb1Ef42QAAAL8"]
[Thu Jul 30 12:12:10.052837 2026] [security2:error] [pid 703393:tid 703635] [client 20.91.208.34:10014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/pucci.php"] [unique_id "amuF6s637Arlr6Yb1Ef43gAAAPU"]
[Thu Jul 30 12:12:10.052989 2026] [security2:error] [pid 703393:tid 703635] [client 20.91.208.34:10014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/pucci.php"] [unique_id "amuF6s637Arlr6Yb1Ef43gAAAPU"]
[Thu Jul 30 12:12:10.086312 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/file61.php"] [unique_id "amuF6s637Arlr6Yb1Ef43wAAAPA"]
[Thu Jul 30 12:12:10.086473 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/file61.php"] [unique_id "amuF6s637Arlr6Yb1Ef43wAAAPA"]
[Thu Jul 30 12:12:10.143073 2026] [security2:error] [pid 703393:tid 703608] [client 74.7.241.168:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.club4.au"] [uri "/index.php"] [unique_id "amuF58637Arlr6Yb1Ef4VwAAANo"]
[Thu Jul 30 12:12:10.143112 2026] [security2:error] [pid 703393:tid 703608] [client 74.7.241.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.club4.au"] [uri "/index.php"] [unique_id "amuF58637Arlr6Yb1Ef4VwAAANo"]
[Thu Jul 30 12:12:10.143736 2026] [security2:error] [pid 703393:tid 703585] [client 74.7.241.168:56588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.club4.au"] [uri "/robots.txt"] [unique_id "amuF58637Arlr6Yb1Ef4UwAAw2E"]
[Thu Jul 30 12:12:10.255037 2026] [security2:error] [pid 703393:tid 703607] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuF6c637Arlr6Yb1Ef4ygAAANk"], referer: https://smoke-tfhk.com/seven-stars-ruanbai-vs-heibiao/
[Thu Jul 30 12:12:10.418611 2026] [security2:error] [pid 703393:tid 703639] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF6c637Arlr6Yb1Ef43AAA-RA"], referer: https://www.spececigarette.com/wp-content/plugins/jetpack-search/README.txt
[Thu Jul 30 12:12:10.442464 2026] [security2:error] [pid 703393:tid 703578] [client 185.191.171.4:48760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/16/copa-do-catar-tera-a-cerveja-mais-cara-da-historia-r-73-o-copo-de-meio-litro/"] [unique_id "amuF6s637Arlr6Yb1Ef46AAAALw"]
[Thu Jul 30 12:12:10.442601 2026] [security2:error] [pid 703393:tid 703578] [client 185.191.171.4:48760] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/16/copa-do-catar-tera-a-cerveja-mais-cara-da-historia-r-73-o-copo-de-meio-litro/"] [unique_id "amuF6s637Arlr6Yb1Ef46AAAALw"]
[Thu Jul 30 12:12:10.581213 2026] [security2:error] [pid 703393:tid 703649] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-css.php"] [unique_id "amuF6s637Arlr6Yb1Ef46gAAAQM"]
[Thu Jul 30 12:12:10.581347 2026] [security2:error] [pid 703393:tid 703649] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-css.php"] [unique_id "amuF6s637Arlr6Yb1Ef46gAAAQM"]
[Thu Jul 30 12:12:10.638634 2026] [security2:error] [pid 703393:tid 703533] [client 20.91.208.34:10022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF6s637Arlr6Yb1Ef46wAAAI8"]
[Thu Jul 30 12:12:10.795802 2026] [security2:error] [pid 703393:tid 703650] [client 20.91.208.34:10022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alshateeintl.com"] [uri "/cgi-sys/404.html"] [unique_id "amuF6s637Arlr6Yb1Ef48gAAAQQ"]
[Thu Jul 30 12:12:10.804205 2026] [security2:error] [pid 703393:tid 703421] [remote 27.124.10.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.spececigarette.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "amuF6s637Arlr6Yb1Ef49QAA7hs"]
[Thu Jul 30 12:12:10.950925 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:10022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-temp.php"] [unique_id "amuF6s637Arlr6Yb1Ef4-AAAAOU"]
[Thu Jul 30 12:12:10.951057 2026] [security2:error] [pid 703393:tid 703619] [client 20.91.208.34:10022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-temp.php"] [unique_id "amuF6s637Arlr6Yb1Ef4-AAAAOU"]
[Thu Jul 30 12:12:11.026005 2026] [security2:error] [pid 703393:tid 703557] [client 74.7.241.168:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "club4.au"] [uri "/index.php"] [unique_id "amuF6s637Arlr6Yb1Ef49wAAAKc"], referer: https://www.club4.au/robots.txt
[Thu Jul 30 12:12:11.027067 2026] [security2:error] [pid 703393:tid 703605] [client 74.7.241.168:56590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "club4.au"] [uri "/robots.txt"] [unique_id "amuF6s637Arlr6Yb1Ef49AAA10A"], referer: https://www.club4.au/robots.txt
[Thu Jul 30 12:12:11.048116 2026] [core:notice] [pid 703393:tid 703616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:11.054434 2026] [security2:error] [pid 703393:tid 703616] [client 103.215.74.26:21844] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF68637Arlr6Yb1Ef4-gAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:11.090090 2026] [security2:error] [pid 703393:tid 703629] [client 191.232.199.39:60747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-activate.php"] [unique_id "amuF68637Arlr6Yb1Ef4_AAAAO8"]
[Thu Jul 30 12:12:11.111614 2026] [security2:error] [pid 703393:tid 703574] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-blink.php"] [unique_id "amuF68637Arlr6Yb1Ef4_gAAALg"]
[Thu Jul 30 12:12:11.111719 2026] [security2:error] [pid 703393:tid 703574] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-blink.php"] [unique_id "amuF68637Arlr6Yb1Ef4_gAAALg"]
[Thu Jul 30 12:12:11.135674 2026] [security2:error] [pid 703393:tid 703524] [client 20.63.98.115:36861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/NewFile.php"] [unique_id "amuF68637Arlr6Yb1Ef4_wAAAIY"]
[Thu Jul 30 12:12:11.264730 2026] [security2:error] [pid 703393:tid 703448] [remote 74.7.241.60:43672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuF68637Arlr6Yb1Ef5BQAAsTY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:12:11.416832 2026] [security2:error] [pid 703393:tid 703577] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF68637Arlr6Yb1Ef4-wAAu0I"]
[Thu Jul 30 12:12:11.544744 2026] [security2:error] [pid 703393:tid 703554] [client 20.91.208.34:58594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuF68637Arlr6Yb1Ef5CQAAAKQ"]
[Thu Jul 30 12:12:11.544876 2026] [security2:error] [pid 703393:tid 703554] [client 20.91.208.34:58594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuF68637Arlr6Yb1Ef5CQAAAKQ"]
[Thu Jul 30 12:12:11.602428 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/txets.php"] [unique_id "amuF68637Arlr6Yb1Ef5CwAAAIg"]
[Thu Jul 30 12:12:11.602540 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/txets.php"] [unique_id "amuF68637Arlr6Yb1Ef5CwAAAIg"]
[Thu Jul 30 12:12:11.699005 2026] [security2:error] [pid 703393:tid 703570] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuF68637Arlr6Yb1Ef4_QAAtCE"]
[Thu Jul 30 12:12:11.798818 2026] [core:notice] [pid 703393:tid 703609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:11.805088 2026] [security2:error] [pid 703393:tid 703609] [client 103.215.74.26:21860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF68637Arlr6Yb1Ef5EAAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:11.971275 2026] [security2:error] [pid 703393:tid 703613] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF68637Arlr6Yb1Ef5CAAA30U"], referer: https://www.spececigarette.com/wp-content/plugins/contact-form-7/Readme.txt
[Thu Jul 30 12:12:12.088774 2026] [security2:error] [pid 703393:tid 703558] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/pucci.php"] [unique_id "amuF7M637Arlr6Yb1Ef5GAAAAKg"]
[Thu Jul 30 12:12:12.088873 2026] [security2:error] [pid 703393:tid 703558] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/pucci.php"] [unique_id "amuF7M637Arlr6Yb1Ef5GAAAAKg"]
[Thu Jul 30 12:12:12.106791 2026] [security2:error] [pid 703393:tid 703468] [remote 74.7.241.59:58120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuF7M637Arlr6Yb1Ef5GQAAnUo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:12:12.184178 2026] [security2:error] [pid 703393:tid 703634] [client 20.91.208.34:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/puc.php"] [unique_id "amuF7M637Arlr6Yb1Ef5HAAAAPQ"]
[Thu Jul 30 12:12:12.184277 2026] [security2:error] [pid 703393:tid 703634] [client 20.91.208.34:55058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/puc.php"] [unique_id "amuF7M637Arlr6Yb1Ef5HAAAAPQ"]
[Thu Jul 30 12:12:12.411057 2026] [security2:error] [pid 703393:tid 703571] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuF7M637Arlr6Yb1Ef5FwAAtU8"]
[Thu Jul 30 12:12:12.435827 2026] [security2:error] [pid 703393:tid 703626] [client 191.232.199.39:6851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/post.php"] [unique_id "amuF7M637Arlr6Yb1Ef5JAAAAOw"]
[Thu Jul 30 12:12:12.534560 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:12.544527 2026] [security2:error] [pid 703393:tid 703624] [client 103.215.74.26:21878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF7M637Arlr6Yb1Ef5JgAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:12.573844 2026] [security2:error] [pid 703393:tid 703641] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xwpg.php"] [unique_id "amuF7M637Arlr6Yb1Ef5JwAAAPs"]
[Thu Jul 30 12:12:12.573940 2026] [security2:error] [pid 703393:tid 703641] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xwpg.php"] [unique_id "amuF7M637Arlr6Yb1Ef5JwAAAPs"]
[Thu Jul 30 12:12:13.067430 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ops.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MQAAAKI"]
[Thu Jul 30 12:12:13.067553 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ops.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MQAAAKI"]
[Thu Jul 30 12:12:13.090686 2026] [security2:error] [pid 703393:tid 703527] [client 20.91.208.34:10027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/dx.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MgAAAIk"]
[Thu Jul 30 12:12:13.090788 2026] [security2:error] [pid 703393:tid 703527] [client 20.91.208.34:10027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alshateeintl.com"] [uri "/dx.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MgAAAIk"]
[Thu Jul 30 12:12:13.214837 2026] [security2:error] [pid 703393:tid 703532] [client 94.154.43.187:56250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fireworkskenya.co.ke"] [uri "/.env"] [unique_id "amuF7c637Arlr6Yb1Ef5NAAAAI4"]
[Thu Jul 30 12:12:13.220160 2026] [security2:error] [pid 703393:tid 703599] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuF7M637Arlr6Yb1Ef5KAAA0VU"]
[Thu Jul 30 12:12:13.290301 2026] [security2:error] [pid 703393:tid 703595] [client 27.124.10.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuF7M637Arlr6Yb1Ef5MAAAzUY"], referer: https://www.spececigarette.com/wp-content/plugins/contact-form-7/README.txt
[Thu Jul 30 12:12:13.572283 2026] [security2:error] [pid 703393:tid 703547] [client 20.48.234.177:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "reviewbyjook.com"] [uri "/1.php"] [unique_id "amuF7c637Arlr6Yb1Ef5PgAAAJ0"]
[Thu Jul 30 12:12:13.572420 2026] [security2:error] [pid 703393:tid 703547] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/1.php"] [unique_id "amuF7c637Arlr6Yb1Ef5PgAAAJ0"]
[Thu Jul 30 12:12:13.572534 2026] [security2:error] [pid 703393:tid 703547] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/1.php"] [unique_id "amuF7c637Arlr6Yb1Ef5PgAAAJ0"]
[Thu Jul 30 12:12:14.097175 2026] [security2:error] [pid 703393:tid 703621] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/mac.php"] [unique_id "amuF7s637Arlr6Yb1Ef5SwAAAOc"]
[Thu Jul 30 12:12:14.097303 2026] [security2:error] [pid 703393:tid 703621] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/mac.php"] [unique_id "amuF7s637Arlr6Yb1Ef5SwAAAOc"]
[Thu Jul 30 12:12:14.116609 2026] [security2:error] [pid 703393:tid 703605] [client 191.232.199.39:51779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/content.php"] [unique_id "amuF7s637Arlr6Yb1Ef5TAAAANc"]
[Thu Jul 30 12:12:14.252095 2026] [security2:error] [pid 703393:tid 703569] [client 216.244.66.243:41108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/slmh4f/gloria-williams-demetress-bell-mother"] [unique_id "amuF7s637Arlr6Yb1Ef5TQAAALM"]
[Thu Jul 30 12:12:14.252210 2026] [security2:error] [pid 703393:tid 703569] [client 216.244.66.243:41108] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arabiandubaisafari.com"] [uri "/slmh4f/gloria-williams-demetress-bell-mother"] [unique_id "amuF7s637Arlr6Yb1Ef5TQAAALM"]
[Thu Jul 30 12:12:14.438421 2026] [security2:error] [pid 703393:tid 703600] [client 5.161.113.195:41918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuF7c637Arlr6Yb1Ef5MwAAANI"], referer: https://globalmarks.pk/
[Thu Jul 30 12:12:14.651341 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuF7s637Arlr6Yb1Ef5VgAAAJk"]
[Thu Jul 30 12:12:14.651433 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuF7s637Arlr6Yb1Ef5VgAAAJk"]
[Thu Jul 30 12:12:14.774413 2026] [core:notice] [pid 703393:tid 703499] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:15.094209 2026] [core:notice] [pid 703393:tid 703570] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:15.103838 2026] [security2:error] [pid 703393:tid 703628] [client 191.232.199.39:6860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-2019.php"] [unique_id "amuF78637Arlr6Yb1Ef5aQAAAO4"]
[Thu Jul 30 12:12:15.193730 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/aa.php"] [unique_id "amuF78637Arlr6Yb1Ef5awAAAMo"]
[Thu Jul 30 12:12:15.193842 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/aa.php"] [unique_id "amuF78637Arlr6Yb1Ef5awAAAMo"]
[Thu Jul 30 12:12:15.654428 2026] [security2:error] [pid 703393:tid 703572] [client 191.232.199.39:51669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/upfile.php"] [unique_id "amuF78637Arlr6Yb1Ef5fgAAALY"]
[Thu Jul 30 12:12:15.709022 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xyn.php"] [unique_id "amuF78637Arlr6Yb1Ef5gQAAAMM"]
[Thu Jul 30 12:12:15.709168 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xyn.php"] [unique_id "amuF78637Arlr6Yb1Ef5gQAAAMM"]
[Thu Jul 30 12:12:16.229200 2026] [security2:error] [pid 703393:tid 703632] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-wp.php"] [unique_id "amuF8M637Arlr6Yb1Ef5jAAAAPI"]
[Thu Jul 30 12:12:16.229323 2026] [security2:error] [pid 703393:tid 703632] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-wp.php"] [unique_id "amuF8M637Arlr6Yb1Ef5jAAAAPI"]
[Thu Jul 30 12:12:16.739252 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/aw.php"] [unique_id "amuF8M637Arlr6Yb1Ef5rAAAAKM"]
[Thu Jul 30 12:12:16.739350 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/aw.php"] [unique_id "amuF8M637Arlr6Yb1Ef5rAAAAKM"]
[Thu Jul 30 12:12:17.239019 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/classwithtostring.php"] [unique_id "amuF8c637Arlr6Yb1Ef5uwAAAMI"]
[Thu Jul 30 12:12:17.239146 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/classwithtostring.php"] [unique_id "amuF8c637Arlr6Yb1Ef5uwAAAMI"]
[Thu Jul 30 12:12:17.463519 2026] [security2:error] [pid 703393:tid 703563] [client 191.232.199.39:54103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/bypass.php"] [unique_id "amuF8c637Arlr6Yb1Ef5vQAAAK0"]
[Thu Jul 30 12:12:17.725825 2026] [security2:error] [pid 703393:tid 703650] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/yawa.php"] [unique_id "amuF8c637Arlr6Yb1Ef6BQAAAQQ"]
[Thu Jul 30 12:12:17.725918 2026] [security2:error] [pid 703393:tid 703650] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/yawa.php"] [unique_id "amuF8c637Arlr6Yb1Ef6BQAAAQQ"]
[Thu Jul 30 12:12:18.246510 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sym403.php"] [unique_id "amuF8s637Arlr6Yb1Ef6LQAAAKI"]
[Thu Jul 30 12:12:18.246610 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sym403.php"] [unique_id "amuF8s637Arlr6Yb1Ef6LQAAAKI"]
[Thu Jul 30 12:12:18.311888 2026] [core:notice] [pid 703393:tid 703610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:18.318564 2026] [security2:error] [pid 703393:tid 703610] [client 103.215.74.26:45336] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF8s637Arlr6Yb1Ef6MgAAANw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:18.593262 2026] [security2:error] [pid 703393:tid 703553] [client 20.63.98.115:21441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xx.php"] [unique_id "amuF8s637Arlr6Yb1Ef6OAAAAKM"]
[Thu Jul 30 12:12:19.091899 2026] [core:notice] [pid 703393:tid 703616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:19.098371 2026] [security2:error] [pid 703393:tid 703616] [client 103.215.74.26:45352] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF88637Arlr6Yb1Ef6RwAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:19.314791 2026] [security2:error] [pid 703393:tid 703628] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuF8s637Arlr6Yb1Ef6PgAAAO4"]
[Thu Jul 30 12:12:19.592631 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/adminner.php"] [unique_id "amuF88637Arlr6Yb1Ef6XgAAAKs"]
[Thu Jul 30 12:12:19.592735 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/adminner.php"] [unique_id "amuF88637Arlr6Yb1Ef6XgAAAKs"]
[Thu Jul 30 12:12:19.629312 2026] [security2:error] [pid 703393:tid 703608] [client 191.232.199.39:45074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/updates.php"] [unique_id "amuF88637Arlr6Yb1Ef6XwAAANo"]
[Thu Jul 30 12:12:19.863536 2026] [core:notice] [pid 703393:tid 703573] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:19.869934 2026] [security2:error] [pid 703393:tid 703573] [client 103.215.74.26:45364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF88637Arlr6Yb1Ef6ZwAAALc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:19.898457 2026] [security2:error] [pid 703393:tid 703489] [remote 100.42.191.181:46322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.191.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuF88637Arlr6Yb1Ef6aQAAnl8"]
[Thu Jul 30 12:12:20.117271 2026] [security2:error] [pid 703393:tid 703551] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/yup.php"] [unique_id "amuF9M637Arlr6Yb1Ef6cgAAAKE"]
[Thu Jul 30 12:12:20.117376 2026] [security2:error] [pid 703393:tid 703551] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/yup.php"] [unique_id "amuF9M637Arlr6Yb1Ef6cgAAAKE"]
[Thu Jul 30 12:12:20.124855 2026] [security2:error] [pid 703393:tid 703521] [remote 208.109.9.173:59842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuF9M637Arlr6Yb1Ef6dQAAxn8"]
[Thu Jul 30 12:12:20.208677 2026] [security2:error] [pid 703393:tid 703617] [client 20.63.98.115:20800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/plugins.php"] [unique_id "amuF9M637Arlr6Yb1Ef6fQAAAOM"]
[Thu Jul 30 12:12:20.599395 2026] [core:notice] [pid 703393:tid 703585] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:20.605877 2026] [security2:error] [pid 703393:tid 703585] [client 103.215.74.26:45376] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF9M637Arlr6Yb1Ef6hAAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:20.627868 2026] [security2:error] [pid 703393:tid 703546] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/config.json.php"] [unique_id "amuF9M637Arlr6Yb1Ef6hQAAAJw"]
[Thu Jul 30 12:12:20.627991 2026] [security2:error] [pid 703393:tid 703546] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/config.json.php"] [unique_id "amuF9M637Arlr6Yb1Ef6hQAAAJw"]
[Thu Jul 30 12:12:20.797557 2026] [security2:error] [pid 703393:tid 703643] [client 191.232.199.39:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/xmrlpc.php"] [unique_id "amuF9M637Arlr6Yb1Ef6kgAAAP0"]
[Thu Jul 30 12:12:20.819816 2026] [security2:error] [pid 703393:tid 703541] [client 127.0.0.1:27552] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuF9M637Arlr6Yb1Ef6kAAAAJc"]
[Thu Jul 30 12:12:20.819860 2026] [security2:error] [pid 703393:tid 703604] [client 127.0.0.1:27536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.plumbingplumb.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuF9M637Arlr6Yb1Ef6jwAAANY"]
[Thu Jul 30 12:12:20.819942 2026] [security2:error] [pid 703393:tid 703561] [client 74.7.228.58:37716] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.plumbingplumb.com"] [uri "/robots.txt"] [unique_id "amuF9M637Arlr6Yb1Ef6jgAAqzs"]
[Thu Jul 30 12:12:21.327910 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:21.335448 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:45382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF9c637Arlr6Yb1Ef6oAAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:21.603550 2026] [security2:error] [pid 703393:tid 703611] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuF9c637Arlr6Yb1Ef6mQAAAN0"]
[Thu Jul 30 12:12:21.850432 2026] [security2:error] [pid 703393:tid 703583] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/2.php"] [unique_id "amuF9c637Arlr6Yb1Ef6qAAAAME"]
[Thu Jul 30 12:12:21.850534 2026] [security2:error] [pid 703393:tid 703583] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/2.php"] [unique_id "amuF9c637Arlr6Yb1Ef6qAAAAME"]
[Thu Jul 30 12:12:22.072679 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:22.079264 2026] [security2:error] [pid 703393:tid 703624] [client 103.215.74.26:45384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF9s637Arlr6Yb1Ef6qgAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:22.330150 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/f35.update.php"] [unique_id "amuF9s637Arlr6Yb1Ef6sgAAAKM"]
[Thu Jul 30 12:12:22.330265 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/f35.update.php"] [unique_id "amuF9s637Arlr6Yb1Ef6sgAAAKM"]
[Thu Jul 30 12:12:22.487843 2026] [security2:error] [pid 703393:tid 703564] [client 191.232.199.39:45092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/ae.php"] [unique_id "amuF9s637Arlr6Yb1Ef6swAAAK4"]
[Thu Jul 30 12:12:22.719946 2026] [security2:error] [pid 703393:tid 703635] [client 20.63.98.115:20749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xxx.php"] [unique_id "amuF9s637Arlr6Yb1Ef6twAAAPU"]
[Thu Jul 30 12:12:22.841135 2026] [security2:error] [pid 703393:tid 703570] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/k.php"] [unique_id "amuF9s637Arlr6Yb1Ef6uQAAALQ"]
[Thu Jul 30 12:12:22.841242 2026] [security2:error] [pid 703393:tid 703570] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/k.php"] [unique_id "amuF9s637Arlr6Yb1Ef6uQAAALQ"]
[Thu Jul 30 12:12:22.870255 2026] [security2:error] [pid 703393:tid 703525] [client 191.232.199.39:6868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/hoot.php"] [unique_id "amuF9s637Arlr6Yb1Ef6uwAAAIc"]
[Thu Jul 30 12:12:23.194246 2026] [core:notice] [pid 703393:tid 703398] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:23.863831 2026] [security2:error] [pid 703393:tid 703637] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuF98637Arlr6Yb1Ef6wgAAAPc"]
[Thu Jul 30 12:12:24.109012 2026] [security2:error] [pid 703393:tid 703549] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/spadex.php"] [unique_id "amuF-M637Arlr6Yb1Ef6zwAAAJ8"]
[Thu Jul 30 12:12:24.109125 2026] [security2:error] [pid 703393:tid 703549] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/spadex.php"] [unique_id "amuF-M637Arlr6Yb1Ef6zwAAAJ8"]
[Thu Jul 30 12:12:24.410284 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:39174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/css.php"] [unique_id "amuF-M637Arlr6Yb1Ef61AAAAKU"]
[Thu Jul 30 12:12:24.593770 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/mg.php"] [unique_id "amuF-M637Arlr6Yb1Ef62gAAAPQ"]
[Thu Jul 30 12:12:24.593880 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/mg.php"] [unique_id "amuF-M637Arlr6Yb1Ef62gAAAPQ"]
[Thu Jul 30 12:12:24.688660 2026] [security2:error] [pid 703393:tid 703609] [client 191.232.199.39:45088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/moon.php"] [unique_id "amuF-M637Arlr6Yb1Ef62wAAANs"]
[Thu Jul 30 12:12:25.105800 2026] [security2:error] [pid 703393:tid 703594] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fnstall.php"] [unique_id "amuF-c637Arlr6Yb1Ef65gAAAMw"]
[Thu Jul 30 12:12:25.105914 2026] [security2:error] [pid 703393:tid 703594] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fnstall.php"] [unique_id "amuF-c637Arlr6Yb1Ef65gAAAMw"]
[Thu Jul 30 12:12:25.498829 2026] [security2:error] [pid 703393:tid 703625] [client 20.63.98.115:32937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuF-c637Arlr6Yb1Ef67QAAAOs"]
[Thu Jul 30 12:12:25.617804 2026] [security2:error] [pid 703393:tid 703556] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ortasekerli1.php"] [unique_id "amuF-c637Arlr6Yb1Ef67gAAAKY"]
[Thu Jul 30 12:12:25.617962 2026] [security2:error] [pid 703393:tid 703556] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ortasekerli1.php"] [unique_id "amuF-c637Arlr6Yb1Ef67gAAAKY"]
[Thu Jul 30 12:12:25.920844 2026] [security2:error] [pid 703393:tid 703572] [client 66.249.73.98:40113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuF-c637Arlr6Yb1Ef67wAAALY"]
[Thu Jul 30 12:12:26.102512 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sump1.php"] [unique_id "amuF-s637Arlr6Yb1Ef6-QAAAKI"]
[Thu Jul 30 12:12:26.102633 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sump1.php"] [unique_id "amuF-s637Arlr6Yb1Ef6-QAAAKI"]
[Thu Jul 30 12:12:26.585619 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ops.php"] [unique_id "amuF-s637Arlr6Yb1Ef7AwAAANM"]
[Thu Jul 30 12:12:26.585706 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ops.php"] [unique_id "amuF-s637Arlr6Yb1Ef7AwAAANM"]
[Thu Jul 30 12:12:26.688346 2026] [security2:error] [pid 703393:tid 703540] [client 191.232.199.39:6852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/log.php"] [unique_id "amuF-s637Arlr6Yb1Ef7BAAAAJY"]
[Thu Jul 30 12:12:26.815459 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:39190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuF-s637Arlr6Yb1Ef7CAAAAQM"]
[Thu Jul 30 12:12:27.108051 2026] [security2:error] [pid 703393:tid 703627] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-post-data.php"] [unique_id "amuF-8637Arlr6Yb1Ef7DwAAAO0"]
[Thu Jul 30 12:12:27.108149 2026] [security2:error] [pid 703393:tid 703627] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-post-data.php"] [unique_id "amuF-8637Arlr6Yb1Ef7DwAAAO0"]
[Thu Jul 30 12:12:27.114079 2026] [security2:error] [pid 703393:tid 703555] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuF-s637Arlr6Yb1Ef6_gAApQ0"]
[Thu Jul 30 12:12:27.177122 2026] [security2:error] [pid 703393:tid 703523] [client 66.249.73.97:41860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuF-s637Arlr6Yb1Ef7BgAAAIU"]
[Thu Jul 30 12:12:27.399908 2026] [security2:error] [pid 703393:tid 703583] [client 191.232.199.39:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/blog.php"] [unique_id "amuF-8637Arlr6Yb1Ef7EAAAAME"]
[Thu Jul 30 12:12:27.607539 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/root.php"] [unique_id "amuF-8637Arlr6Yb1Ef7GAAAAJk"]
[Thu Jul 30 12:12:27.607651 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/root.php"] [unique_id "amuF-8637Arlr6Yb1Ef7GAAAAJk"]
[Thu Jul 30 12:12:27.794723 2026] [core:notice] [pid 703393:tid 703563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:27.802099 2026] [security2:error] [pid 703393:tid 703563] [client 103.215.74.26:13632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF-8637Arlr6Yb1Ef7GQAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:28.112712 2026] [security2:error] [pid 703393:tid 703525] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/v543.php"] [unique_id "amuF_M637Arlr6Yb1Ef7HQAAAIc"]
[Thu Jul 30 12:12:28.113078 2026] [security2:error] [pid 703393:tid 703525] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/v543.php"] [unique_id "amuF_M637Arlr6Yb1Ef7HQAAAIc"]
[Thu Jul 30 12:12:28.328245 2026] [security2:error] [pid 703393:tid 703591] [client 185.189.112.11:58628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuF_M637Arlr6Yb1Ef7KQAAAMk"]
[Thu Jul 30 12:12:28.328347 2026] [security2:error] [pid 703393:tid 703591] [client 185.189.112.11:58628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuF_M637Arlr6Yb1Ef7KQAAAMk"]
[Thu Jul 30 12:12:28.527094 2026] [core:notice] [pid 703393:tid 703603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:28.533261 2026] [security2:error] [pid 703393:tid 703603] [client 103.215.74.26:13646] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_M637Arlr6Yb1Ef7LQAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:28.574810 2026] [security2:error] [pid 703393:tid 703632] [client 191.232.199.39:6850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/bak.php"] [unique_id "amuF_M637Arlr6Yb1Ef7LgAAAPI"]
[Thu Jul 30 12:12:28.592075 2026] [security2:error] [pid 703393:tid 703556] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sixxis.php"] [unique_id "amuF_M637Arlr6Yb1Ef7MAAAAKY"]
[Thu Jul 30 12:12:28.592187 2026] [security2:error] [pid 703393:tid 703556] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sixxis.php"] [unique_id "amuF_M637Arlr6Yb1Ef7MAAAAKY"]
[Thu Jul 30 12:12:28.868661 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:49785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/index.php"] [unique_id "amuF_M637Arlr6Yb1Ef7NAAAAQI"]
[Thu Jul 30 12:12:29.075343 2026] [security2:error] [pid 703393:tid 703557] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ip.php"] [unique_id "amuF_c637Arlr6Yb1Ef7OQAAAKc"]
[Thu Jul 30 12:12:29.075435 2026] [security2:error] [pid 703393:tid 703557] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ip.php"] [unique_id "amuF_c637Arlr6Yb1Ef7OQAAAKc"]
[Thu Jul 30 12:12:29.174070 2026] [core:error] [pid 703393:tid 703563] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:12:29.174095 2026] [core:error] [pid 703393:tid 703563] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:12:29.256681 2026] [core:notice] [pid 703393:tid 703639] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:29.264122 2026] [security2:error] [pid 703393:tid 703639] [client 103.215.74.26:13660] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_c637Arlr6Yb1Ef7RAAAAPk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:29.606123 2026] [security2:error] [pid 703393:tid 703616] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/kq1.php"] [unique_id "amuF_c637Arlr6Yb1Ef7TwAAAOI"]
[Thu Jul 30 12:12:29.606245 2026] [security2:error] [pid 703393:tid 703616] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/kq1.php"] [unique_id "amuF_c637Arlr6Yb1Ef7TwAAAOI"]
[Thu Jul 30 12:12:29.811183 2026] [security2:error] [pid 703393:tid 703420] [remote 47.128.60.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tuwaiq-sa.tech"] [uri "/robots.txt"] [unique_id "amuF_c637Arlr6Yb1Ef7VAAAmBo"]
[Thu Jul 30 12:12:30.022926 2026] [core:notice] [pid 703393:tid 703649] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:30.029200 2026] [security2:error] [pid 703393:tid 703649] [client 103.215.74.26:13676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_s637Arlr6Yb1Ef7WgAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:30.121266 2026] [security2:error] [pid 703393:tid 703555] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fw/faiyy.php"] [unique_id "amuF_s637Arlr6Yb1Ef7XgAAAKU"]
[Thu Jul 30 12:12:30.121399 2026] [security2:error] [pid 703393:tid 703555] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fw/faiyy.php"] [unique_id "amuF_s637Arlr6Yb1Ef7XgAAAKU"]
[Thu Jul 30 12:12:30.213299 2026] [security2:error] [pid 703393:tid 703613] [client 85.204.70.116:37764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuF_s637Arlr6Yb1Ef7XwAAAN8"]
[Thu Jul 30 12:12:30.213610 2026] [security2:error] [pid 703393:tid 703531] [client 191.232.199.39:45077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/ini.php"] [unique_id "amuF_s637Arlr6Yb1Ef7YAAAAI0"]
[Thu Jul 30 12:12:30.473375 2026] [security2:error] [pid 703393:tid 703526] [client 85.204.70.116:47849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuF_s637Arlr6Yb1Ef7ZAAAAIg"]
[Thu Jul 30 12:12:30.630062 2026] [security2:error] [pid 703393:tid 703639] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/h02ugyh.php"] [unique_id "amuF_s637Arlr6Yb1Ef7awAAAPk"]
[Thu Jul 30 12:12:30.630198 2026] [security2:error] [pid 703393:tid 703639] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/h02ugyh.php"] [unique_id "amuF_s637Arlr6Yb1Ef7awAAAPk"]
[Thu Jul 30 12:12:30.793190 2026] [core:notice] [pid 703393:tid 703579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:30.800929 2026] [security2:error] [pid 703393:tid 703579] [client 103.215.74.26:13688] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_s637Arlr6Yb1Ef7bgAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:31.119686 2026] [security2:error] [pid 703393:tid 703540] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-temp.php"] [unique_id "amuF_8637Arlr6Yb1Ef7cwAAAJY"]
[Thu Jul 30 12:12:31.119793 2026] [security2:error] [pid 703393:tid 703540] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-temp.php"] [unique_id "amuF_8637Arlr6Yb1Ef7cwAAAJY"]
[Thu Jul 30 12:12:31.527077 2026] [core:notice] [pid 703393:tid 703588] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:31.533612 2026] [security2:error] [pid 703393:tid 703588] [client 103.215.74.26:13692] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuF_8637Arlr6Yb1Ef7eQAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:31.607253 2026] [security2:error] [pid 703393:tid 703632] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-content/cong.php"] [unique_id "amuF_8637Arlr6Yb1Ef7fQAAAPI"]
[Thu Jul 30 12:12:31.607361 2026] [security2:error] [pid 703393:tid 703632] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-content/cong.php"] [unique_id "amuF_8637Arlr6Yb1Ef7fQAAAPI"]
[Thu Jul 30 12:12:31.693113 2026] [security2:error] [pid 703393:tid 703636] [client 85.204.70.116:37780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuF_8637Arlr6Yb1Ef7gwAAAPY"]
[Thu Jul 30 12:12:31.778954 2026] [security2:error] [pid 703393:tid 703562] [client 191.232.199.39:45063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/admin-ajax.php"] [unique_id "amuF_8637Arlr6Yb1Ef7hAAAAKw"]
[Thu Jul 30 12:12:31.864570 2026] [security2:error] [pid 703393:tid 703592] [client 178.205.100.18:41350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/administrator/index.php"] [unique_id "amuF_8637Arlr6Yb1Ef7egAAAMo"], referer: https://www.toscanamall.com/administrator/
[Thu Jul 30 12:12:31.959677 2026] [security2:error] [pid 703393:tid 703607] [client 85.204.70.116:37782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuF_8637Arlr6Yb1Ef7hQAAANk"]
[Thu Jul 30 12:12:32.230691 2026] [security2:error] [pid 703393:tid 703602] [client 85.204.70.116:37786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuGAM637Arlr6Yb1Ef7jAAAANQ"]
[Thu Jul 30 12:12:32.297486 2026] [core:notice] [pid 703393:tid 703530] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:32.303850 2026] [security2:error] [pid 703393:tid 703530] [client 103.215.74.26:13706] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGAM637Arlr6Yb1Ef7jwAAAIw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:32.539467 2026] [security2:error] [pid 703393:tid 703579] [client 85.204.70.116:57510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuGAM637Arlr6Yb1Ef7kAAAAL0"]
[Thu Jul 30 12:12:32.600917 2026] [security2:error] [pid 703393:tid 703553] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuGAM637Arlr6Yb1Ef7hgAAAKM"]
[Thu Jul 30 12:12:32.706142 2026] [security2:error] [pid 703393:tid 703571] [client 178.205.100.18:41356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/wp-login.php"] [unique_id "amuGAM637Arlr6Yb1Ef7lAAAALU"]
[Thu Jul 30 12:12:32.807267 2026] [security2:error] [pid 703393:tid 703631] [client 85.204.70.116:57520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuGAM637Arlr6Yb1Ef7mAAAAPE"]
[Thu Jul 30 12:12:32.841037 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuGAM637Arlr6Yb1Ef7mQAAAOs"]
[Thu Jul 30 12:12:32.841138 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuGAM637Arlr6Yb1Ef7mQAAAOs"]
[Thu Jul 30 12:12:32.940077 2026] [security2:error] [pid 703393:tid 703606] [client 191.232.199.39:6901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/content.php"] [unique_id "amuGAM637Arlr6Yb1Ef7mwAAANg"]
[Thu Jul 30 12:12:33.052073 2026] [core:notice] [pid 703393:tid 703623] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:33.062078 2026] [security2:error] [pid 703393:tid 703623] [client 103.215.74.26:8746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGAc637Arlr6Yb1Ef7nAAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:33.096263 2026] [security2:error] [pid 703393:tid 703555] [client 85.204.70.116:57524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuGAc637Arlr6Yb1Ef7nQAAAKU"]
[Thu Jul 30 12:12:33.167660 2026] [security2:error] [pid 703393:tid 703551] [client 191.232.199.39:45058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/akc.php"] [unique_id "amuGAc637Arlr6Yb1Ef7ngAAAKE"]
[Thu Jul 30 12:12:33.311368 2026] [security2:error] [pid 703393:tid 703545] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/jj.php"] [unique_id "amuGAc637Arlr6Yb1Ef7pQAAAJs"]
[Thu Jul 30 12:12:33.311456 2026] [security2:error] [pid 703393:tid 703545] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/jj.php"] [unique_id "amuGAc637Arlr6Yb1Ef7pQAAAJs"]
[Thu Jul 30 12:12:33.408845 2026] [security2:error] [pid 703393:tid 703593] [client 85.204.70.116:57526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuGAc637Arlr6Yb1Ef7pgAAAMs"]
[Thu Jul 30 12:12:33.542993 2026] [security2:error] [pid 703393:tid 703531] [client 20.63.98.115:32936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/network/about.php"] [unique_id "amuGAc637Arlr6Yb1Ef7pwAAAI0"]
[Thu Jul 30 12:12:33.713075 2026] [security2:error] [pid 703393:tid 703580] [client 85.204.70.116:1681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuGAc637Arlr6Yb1Ef7qAAAAL4"]
[Thu Jul 30 12:12:33.801970 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:33.802929 2026] [security2:error] [pid 703393:tid 703560] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amuGAc637Arlr6Yb1Ef7rQAAAKo"]
[Thu Jul 30 12:12:33.803064 2026] [security2:error] [pid 703393:tid 703560] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amuGAc637Arlr6Yb1Ef7rQAAAKo"]
[Thu Jul 30 12:12:33.808262 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:8750] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGAc637Arlr6Yb1Ef7rAAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:33.813756 2026] [security2:error] [pid 703393:tid 703473] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGAc637Arlr6Yb1Ef7rwAAqE8"]
[Thu Jul 30 12:12:33.813897 2026] [security2:error] [pid 703393:tid 703558] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGAc637Arlr6Yb1Ef7rwAAqE8"]
[Thu Jul 30 12:12:34.009091 2026] [security2:error] [pid 703393:tid 703605] [client 85.204.70.116:57542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuGAs637Arlr6Yb1Ef7tAAAANc"]
[Thu Jul 30 12:12:34.163287 2026] [security2:error] [pid 703393:tid 703563] [client 191.232.199.39:6903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/upfile.php"] [unique_id "amuGAs637Arlr6Yb1Ef7tgAAAK0"]
[Thu Jul 30 12:12:34.306811 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xpwer1.php"] [unique_id "amuGAs637Arlr6Yb1Ef7ugAAAJE"]
[Thu Jul 30 12:12:34.306913 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xpwer1.php"] [unique_id "amuGAs637Arlr6Yb1Ef7ugAAAJE"]
[Thu Jul 30 12:12:34.319785 2026] [security2:error] [pid 703393:tid 703630] [client 85.204.70.116:8511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuGAs637Arlr6Yb1Ef7vAAAAPA"]
[Thu Jul 30 12:12:34.412289 2026] [autoindex:error] [pid 703393:tid 703552] [client 66.132.186.204:58184] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:12:34.619469 2026] [security2:error] [pid 703393:tid 703592] [client 85.204.70.116:57560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuGAs637Arlr6Yb1Ef7xgAAAMo"]
[Thu Jul 30 12:12:34.799679 2026] [security2:error] [pid 703393:tid 703614] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/flox.php"] [unique_id "amuGAs637Arlr6Yb1Ef7xwAAAOA"]
[Thu Jul 30 12:12:34.799775 2026] [security2:error] [pid 703393:tid 703614] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/flox.php"] [unique_id "amuGAs637Arlr6Yb1Ef7xwAAAOA"]
[Thu Jul 30 12:12:34.816628 2026] [security2:error] [pid 703393:tid 703603] [client 20.63.98.115:21444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xpw.php"] [unique_id "amuGAs637Arlr6Yb1Ef7yQAAANU"]
[Thu Jul 30 12:12:34.916196 2026] [security2:error] [pid 703393:tid 703531] [client 85.204.70.116:40850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuGAs637Arlr6Yb1Ef7zwAAAI0"]
[Thu Jul 30 12:12:35.084830 2026] [security2:error] [pid 703393:tid 703633] [client 178.205.100.18:41362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/admin.php"] [unique_id "amuGA8637Arlr6Yb1Ef70AAAAPM"]
[Thu Jul 30 12:12:35.213309 2026] [security2:error] [pid 703393:tid 703596] [client 85.204.70.116:57576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuGA8637Arlr6Yb1Ef70QAAAM4"]
[Thu Jul 30 12:12:35.294529 2026] [security2:error] [pid 703393:tid 703544] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/popo.php"] [unique_id "amuGA8637Arlr6Yb1Ef70gAAAJo"]
[Thu Jul 30 12:12:35.294632 2026] [security2:error] [pid 703393:tid 703544] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/popo.php"] [unique_id "amuGA8637Arlr6Yb1Ef70gAAAJo"]
[Thu Jul 30 12:12:35.331372 2026] [security2:error] [pid 703393:tid 703634] [client 103.82.26.211:50080] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.saifalkhaleejest.com"] [uri "/"] [unique_id "amuGA8637Arlr6Yb1Ef71QAAAPQ"]
[Thu Jul 30 12:12:35.511733 2026] [security2:error] [pid 703393:tid 703570] [client 85.204.70.116:49491] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.zmr.gpl.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuGA8637Arlr6Yb1Ef73AAAALQ"]
[Thu Jul 30 12:12:35.658302 2026] [security2:error] [pid 703393:tid 703586] [client 103.82.26.211:50119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.saifalkhaleejest.com"] [uri "/wp-json/batch/v1"] [unique_id "amuGA8637Arlr6Yb1Ef73gAAAMQ"]
[Thu Jul 30 12:12:35.774936 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/yas.php"] [unique_id "amuGA8637Arlr6Yb1Ef73wAAAMg"]
[Thu Jul 30 12:12:35.775058 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/yas.php"] [unique_id "amuGA8637Arlr6Yb1Ef73wAAAMg"]
[Thu Jul 30 12:12:35.882167 2026] [security2:error] [pid 703393:tid 703622] [client 191.232.199.39:45091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/akcc.php"] [unique_id "amuGA8637Arlr6Yb1Ef74wAAAOg"]
[Thu Jul 30 12:12:36.098255 2026] [security2:error] [pid 703393:tid 703646] [client 20.63.98.115:39182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-cron.php"] [unique_id "amuGBM637Arlr6Yb1Ef75wAAAQA"]
[Thu Jul 30 12:12:36.260583 2026] [security2:error] [pid 703393:tid 703607] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/water.php"] [unique_id "amuGBM637Arlr6Yb1Ef76QAAANk"]
[Thu Jul 30 12:12:36.260688 2026] [security2:error] [pid 703393:tid 703607] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/water.php"] [unique_id "amuGBM637Arlr6Yb1Ef76QAAANk"]
[Thu Jul 30 12:12:36.779900 2026] [core:notice] [pid 703393:tid 703478] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:36.779937 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/nano.php"] [unique_id "amuGBM637Arlr6Yb1Ef79QAAANM"]
[Thu Jul 30 12:12:36.780072 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/nano.php"] [unique_id "amuGBM637Arlr6Yb1Ef79QAAANM"]
[Thu Jul 30 12:12:37.276198 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/moon.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_gAAAKQ"]
[Thu Jul 30 12:12:37.276306 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/moon.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_gAAAKQ"]
[Thu Jul 30 12:12:37.715275 2026] [security2:error] [pid 703393:tid 703536] [client 191.232.199.39:45082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/asasx.php"] [unique_id "amuGBc637Arlr6Yb1Ef8BgAAAJI"]
[Thu Jul 30 12:12:37.723776 2026] [security2:error] [pid 703393:tid 703560] [client 54.183.198.160:14188] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_QAAAKo"]
[Thu Jul 30 12:12:37.793692 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-info.php"] [unique_id "amuGBc637Arlr6Yb1Ef8BwAAAI4"]
[Thu Jul 30 12:12:37.793801 2026] [security2:error] [pid 703393:tid 703532] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-info.php"] [unique_id "amuGBc637Arlr6Yb1Ef8BwAAAI4"]
[Thu Jul 30 12:12:37.836309 2026] [security2:error] [pid 703393:tid 703560] [client 54.183.198.160:14188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_QAAAKo"]
[Thu Jul 30 12:12:37.836387 2026] [security2:error] [pid 703393:tid 703560] [client 54.183.198.160:14188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lilyinspires.com"] [uri "/wp-comments-post.php"] [unique_id "amuGBc637Arlr6Yb1Ef7_QAAAKo"]
[Thu Jul 30 12:12:38.238178 2026] [security2:error] [pid 703393:tid 703553] [client 20.63.98.115:39207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cah.php"] [unique_id "amuGBs637Arlr6Yb1Ef8EAAAAKM"]
[Thu Jul 30 12:12:38.288964 2026] [security2:error] [pid 703393:tid 703603] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/file5.php"] [unique_id "amuGBs637Arlr6Yb1Ef8EQAAANU"]
[Thu Jul 30 12:12:38.289112 2026] [security2:error] [pid 703393:tid 703603] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/file5.php"] [unique_id "amuGBs637Arlr6Yb1Ef8EQAAANU"]
[Thu Jul 30 12:12:38.521859 2026] [core:notice] [pid 703393:tid 703511] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:38.718664 2026] [security2:error] [pid 703393:tid 703500] [remote 179.43.134.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-login.php"] [unique_id "amuGBs637Arlr6Yb1Ef8FQAA1Go"]
[Thu Jul 30 12:12:38.777597 2026] [security2:error] [pid 703393:tid 703540] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/2000.php"] [unique_id "amuGBs637Arlr6Yb1Ef8GwAAAJY"]
[Thu Jul 30 12:12:38.777692 2026] [security2:error] [pid 703393:tid 703540] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/2000.php"] [unique_id "amuGBs637Arlr6Yb1Ef8GwAAAJY"]
[Thu Jul 30 12:12:39.121127 2026] [security2:error] [pid 703393:tid 703520] [remote 220.181.108.159:17800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/06/25/soldes-ete-2009/"] [unique_id "amuGB8637Arlr6Yb1Ef8IwAAmH4"]
[Thu Jul 30 12:12:39.258185 2026] [security2:error] [pid 703393:tid 703576] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/122.php"] [unique_id "amuGB8637Arlr6Yb1Ef8JAAAALo"]
[Thu Jul 30 12:12:39.258345 2026] [security2:error] [pid 703393:tid 703576] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/122.php"] [unique_id "amuGB8637Arlr6Yb1Ef8JAAAALo"]
[Thu Jul 30 12:12:39.287389 2026] [security2:error] [pid 703393:tid 703535] [client 20.203.156.12:46994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/bypas.php"] [unique_id "amuGB8637Arlr6Yb1Ef8JgAAAJE"]
[Thu Jul 30 12:12:39.287476 2026] [security2:error] [pid 703393:tid 703535] [client 20.203.156.12:46994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/bypas.php"] [unique_id "amuGB8637Arlr6Yb1Ef8JgAAAJE"]
[Thu Jul 30 12:12:39.465035 2026] [security2:error] [pid 703393:tid 703525] [client 20.63.98.115:21220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cong.php"] [unique_id "amuGB8637Arlr6Yb1Ef8KAAAAIc"]
[Thu Jul 30 12:12:39.519129 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:39.525220 2026] [security2:error] [pid 703393:tid 703565] [client 103.215.74.26:8764] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGB8637Arlr6Yb1Ef8LAAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:39.735795 2026] [security2:error] [pid 703393:tid 703579] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/mds.php"] [unique_id "amuGB8637Arlr6Yb1Ef8NQAAAL0"]
[Thu Jul 30 12:12:39.735879 2026] [security2:error] [pid 703393:tid 703579] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/mds.php"] [unique_id "amuGB8637Arlr6Yb1Ef8NQAAAL0"]
[Thu Jul 30 12:12:39.761965 2026] [core:notice] [pid 703393:tid 703492] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:39.896409 2026] [security2:error] [pid 703393:tid 703560] [client 20.203.156.12:50019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/ucen.php"] [unique_id "amuGB8637Arlr6Yb1Ef8OQAAAKo"]
[Thu Jul 30 12:12:39.896540 2026] [security2:error] [pid 703393:tid 703560] [client 20.203.156.12:50019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/ucen.php"] [unique_id "amuGB8637Arlr6Yb1Ef8OQAAAKo"]
[Thu Jul 30 12:12:40.225229 2026] [security2:error] [pid 703393:tid 703642] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/zc-208.php"] [unique_id "amuGCM637Arlr6Yb1Ef8QQAAAPw"]
[Thu Jul 30 12:12:40.225357 2026] [security2:error] [pid 703393:tid 703642] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/zc-208.php"] [unique_id "amuGCM637Arlr6Yb1Ef8QQAAAPw"]
[Thu Jul 30 12:12:40.252894 2026] [security2:error] [pid 703393:tid 703608] [client 20.203.156.12:58213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/miya.php"] [unique_id "amuGCM637Arlr6Yb1Ef8QgAAANo"]
[Thu Jul 30 12:12:40.253004 2026] [security2:error] [pid 703393:tid 703608] [client 20.203.156.12:58213] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/miya.php"] [unique_id "amuGCM637Arlr6Yb1Ef8QgAAANo"]
[Thu Jul 30 12:12:40.276263 2026] [core:notice] [pid 703393:tid 703595] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:40.282609 2026] [security2:error] [pid 703393:tid 703595] [client 103.215.74.26:8766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGCM637Arlr6Yb1Ef8QwAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:40.329438 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:21260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/Sanskrit.php"] [unique_id "amuGCM637Arlr6Yb1Ef8RAAAAN0"]
[Thu Jul 30 12:12:40.342645 2026] [core:notice] [pid 703393:tid 703417] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:40.508733 2026] [core:notice] [pid 703393:tid 703515] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:40.513239 2026] [core:notice] [pid 703393:tid 703471] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:40.619251 2026] [security2:error] [pid 703393:tid 703548] [client 20.203.156.12:35768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/error.php"] [unique_id "amuGCM637Arlr6Yb1Ef8SwAAAJ4"]
[Thu Jul 30 12:12:40.619338 2026] [security2:error] [pid 703393:tid 703548] [client 20.203.156.12:35768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/error.php"] [unique_id "amuGCM637Arlr6Yb1Ef8SwAAAJ4"]
[Thu Jul 30 12:12:40.716067 2026] [security2:error] [pid 703393:tid 703616] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sid4.php"] [unique_id "amuGCM637Arlr6Yb1Ef8UQAAAOI"]
[Thu Jul 30 12:12:40.716203 2026] [security2:error] [pid 703393:tid 703616] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sid4.php"] [unique_id "amuGCM637Arlr6Yb1Ef8UQAAAOI"]
[Thu Jul 30 12:12:41.006951 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:41.013305 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:8778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGCc637Arlr6Yb1Ef8UgAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:41.026888 2026] [security2:error] [pid 703393:tid 703604] [client 20.203.156.12:40216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/alfav.php"] [unique_id "amuGCc637Arlr6Yb1Ef8UwAAANY"]
[Thu Jul 30 12:12:41.026999 2026] [security2:error] [pid 703393:tid 703604] [client 20.203.156.12:40216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/alfav.php"] [unique_id "amuGCc637Arlr6Yb1Ef8UwAAANY"]
[Thu Jul 30 12:12:41.347013 2026] [security2:error] [pid 703393:tid 703576] [client 20.203.156.12:53229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/alpas.php"] [unique_id "amuGCc637Arlr6Yb1Ef8WwAAALo"]
[Thu Jul 30 12:12:41.347164 2026] [security2:error] [pid 703393:tid 703576] [client 20.203.156.12:53229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/alpas.php"] [unique_id "amuGCc637Arlr6Yb1Ef8WwAAALo"]
[Thu Jul 30 12:12:41.396399 2026] [core:notice] [pid 703393:tid 703405] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:41.670266 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:49790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ms-edit.php"] [unique_id "amuGCc637Arlr6Yb1Ef8YQAAAPo"]
[Thu Jul 30 12:12:41.729910 2026] [core:notice] [pid 703393:tid 703632] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:41.730044 2026] [security2:error] [pid 703393:tid 703568] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuGCc637Arlr6Yb1Ef8WgAAALI"]
[Thu Jul 30 12:12:41.736093 2026] [security2:error] [pid 703393:tid 703632] [client 103.215.74.26:8792] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGCc637Arlr6Yb1Ef8ZQAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:41.833298 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:40196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/alfa.php"] [unique_id "amuGCc637Arlr6Yb1Ef8ZgAAAPE"]
[Thu Jul 30 12:12:41.833407 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:40196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/alfa.php"] [unique_id "amuGCc637Arlr6Yb1Ef8ZgAAAPE"]
[Thu Jul 30 12:12:42.010839 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wmore1.php"] [unique_id "amuGCs637Arlr6Yb1Ef8ZwAAAMo"]
[Thu Jul 30 12:12:42.010943 2026] [security2:error] [pid 703393:tid 703592] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wmore1.php"] [unique_id "amuGCs637Arlr6Yb1Ef8ZwAAAMo"]
[Thu Jul 30 12:12:42.191250 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/0byte.php"] [unique_id "amuGCs637Arlr6Yb1Ef8awAAAJs"]
[Thu Jul 30 12:12:42.191373 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:52702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/0byte.php"] [unique_id "amuGCs637Arlr6Yb1Ef8awAAAJs"]
[Thu Jul 30 12:12:42.231366 2026] [core:notice] [pid 703393:tid 703509] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:42.254377 2026] [core:notice] [pid 703393:tid 703415] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:42.503814 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/solo1.php"] [unique_id "amuGCs637Arlr6Yb1Ef8cwAAAPQ"]
[Thu Jul 30 12:12:42.503943 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/solo1.php"] [unique_id "amuGCs637Arlr6Yb1Ef8cwAAAPQ"]
[Thu Jul 30 12:12:42.597692 2026] [security2:error] [pid 703393:tid 703530] [client 20.63.98.115:58062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/function.php"] [unique_id "amuGCs637Arlr6Yb1Ef8dAAAAIw"]
[Thu Jul 30 12:12:42.637036 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:35757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/index3.php"] [unique_id "amuGCs637Arlr6Yb1Ef8dQAAAKg"]
[Thu Jul 30 12:12:42.637127 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:35757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/index3.php"] [unique_id "amuGCs637Arlr6Yb1Ef8dQAAAKg"]
[Thu Jul 30 12:12:43.001672 2026] [security2:error] [pid 703393:tid 703540] [client 20.203.156.12:52693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/index2.php"] [unique_id "amuGC8637Arlr6Yb1Ef8fQAAAJY"]
[Thu Jul 30 12:12:43.001768 2026] [security2:error] [pid 703393:tid 703540] [client 20.203.156.12:52693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/index2.php"] [unique_id "amuGC8637Arlr6Yb1Ef8fQAAAJY"]
[Thu Jul 30 12:12:43.136214 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:43.390624 2026] [security2:error] [pid 703393:tid 703613] [client 20.203.156.12:52711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/index1.php"] [unique_id "amuGC8637Arlr6Yb1Ef8hQAAAN8"]
[Thu Jul 30 12:12:43.390720 2026] [security2:error] [pid 703393:tid 703613] [client 20.203.156.12:52711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/index1.php"] [unique_id "amuGC8637Arlr6Yb1Ef8hQAAAN8"]
[Thu Jul 30 12:12:43.488988 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuGCs637Arlr6Yb1Ef8fAAAAKQ"]
[Thu Jul 30 12:12:43.507513 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:39173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ee.php"] [unique_id "amuGC8637Arlr6Yb1Ef8hgAAAOg"]
[Thu Jul 30 12:12:43.639402 2026] [security2:error] [pid 703393:tid 703524] [client 191.232.199.39:45107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/axx.php"] [unique_id "amuGC8637Arlr6Yb1Ef8hwAAAIY"]
[Thu Jul 30 12:12:43.841070 2026] [security2:error] [pid 703393:tid 703627] [client 20.203.156.12:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/303.php"] [unique_id "amuGC8637Arlr6Yb1Ef8kAAAAO0"]
[Thu Jul 30 12:12:43.841202 2026] [security2:error] [pid 703393:tid 703627] [client 20.203.156.12:50045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/303.php"] [unique_id "amuGC8637Arlr6Yb1Ef8kAAAAO0"]
[Thu Jul 30 12:12:43.849297 2026] [security2:error] [pid 703393:tid 703600] [client 191.232.199.39:6894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/bypass.php"] [unique_id "amuGC8637Arlr6Yb1Ef8kQAAANI"]
[Thu Jul 30 12:12:44.238044 2026] [security2:error] [pid 703393:tid 703614] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "reviewbyjook.com"] [uri "/index.cgi"] [unique_id "amuGC8637Arlr6Yb1Ef8iQAAAOA"]
[Thu Jul 30 12:12:44.257507 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:52680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/505.php"] [unique_id "amuGDM637Arlr6Yb1Ef8lAAAAKg"]
[Thu Jul 30 12:12:44.257598 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:52680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/505.php"] [unique_id "amuGDM637Arlr6Yb1Ef8lAAAAKg"]
[Thu Jul 30 12:12:44.422274 2026] [security2:error] [pid 703393:tid 703631] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGC8637Arlr6Yb1Ef8iAAA8QU"]
[Thu Jul 30 12:12:44.484217 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/public/css.php"] [unique_id "amuGDM637Arlr6Yb1Ef8ngAAAPA"]
[Thu Jul 30 12:12:44.484329 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/public/css.php"] [unique_id "amuGDM637Arlr6Yb1Ef8ngAAAPA"]
[Thu Jul 30 12:12:44.751128 2026] [security2:error] [pid 703393:tid 703643] [client 20.203.156.12:52684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/500.php"] [unique_id "amuGDM637Arlr6Yb1Ef8oAAAAP0"]
[Thu Jul 30 12:12:44.751244 2026] [security2:error] [pid 703393:tid 703643] [client 20.203.156.12:52684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/500.php"] [unique_id "amuGDM637Arlr6Yb1Ef8oAAAAP0"]
[Thu Jul 30 12:12:44.976348 2026] [security2:error] [pid 703393:tid 703645] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/output.php"] [unique_id "amuGDM637Arlr6Yb1Ef8xwAAAP8"]
[Thu Jul 30 12:12:44.976445 2026] [security2:error] [pid 703393:tid 703645] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/output.php"] [unique_id "amuGDM637Arlr6Yb1Ef8xwAAAP8"]
[Thu Jul 30 12:12:44.994673 2026] [security2:error] [pid 703393:tid 703525] [client 20.63.98.115:58079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/new.php"] [unique_id "amuGDM637Arlr6Yb1Ef8yAAAAIc"]
[Thu Jul 30 12:12:45.223864 2026] [security2:error] [pid 703393:tid 703592] [client 20.203.156.12:40218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/77.php"] [unique_id "amuGDc637Arlr6Yb1Ef8yQAAAMo"]
[Thu Jul 30 12:12:45.223971 2026] [security2:error] [pid 703393:tid 703592] [client 20.203.156.12:40218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/77.php"] [unique_id "amuGDc637Arlr6Yb1Ef8yQAAAMo"]
[Thu Jul 30 12:12:45.465242 2026] [security2:error] [pid 703393:tid 703608] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-file-120.php"] [unique_id "amuGDc637Arlr6Yb1Ef81AAAANo"]
[Thu Jul 30 12:12:45.465352 2026] [security2:error] [pid 703393:tid 703608] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-file-120.php"] [unique_id "amuGDc637Arlr6Yb1Ef81AAAANo"]
[Thu Jul 30 12:12:45.556817 2026] [security2:error] [pid 703393:tid 703615] [client 20.203.156.12:52673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/76.php"] [unique_id "amuGDc637Arlr6Yb1Ef81QAAAOE"]
[Thu Jul 30 12:12:45.556959 2026] [security2:error] [pid 703393:tid 703615] [client 20.203.156.12:52673] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/76.php"] [unique_id "amuGDc637Arlr6Yb1Ef81QAAAOE"]
[Thu Jul 30 12:12:45.949253 2026] [security2:error] [pid 703393:tid 703602] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/special.php"] [unique_id "amuGDc637Arlr6Yb1Ef83gAAANQ"]
[Thu Jul 30 12:12:45.949390 2026] [security2:error] [pid 703393:tid 703602] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/special.php"] [unique_id "amuGDc637Arlr6Yb1Ef83gAAANQ"]
[Thu Jul 30 12:12:46.000245 2026] [security2:error] [pid 703393:tid 703537] [client 20.203.156.12:35770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/74.php"] [unique_id "amuGDc637Arlr6Yb1Ef84QAAAJM"]
[Thu Jul 30 12:12:46.000392 2026] [security2:error] [pid 703393:tid 703537] [client 20.203.156.12:35770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/74.php"] [unique_id "amuGDc637Arlr6Yb1Ef84QAAAJM"]
[Thu Jul 30 12:12:46.103479 2026] [security2:error] [pid 703393:tid 703529] [client 191.232.199.39:6879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/updates.php"] [unique_id "amuGDs637Arlr6Yb1Ef84gAAAIs"]
[Thu Jul 30 12:12:46.362888 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:43429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/wp-config.php"] [unique_id "amuGDs637Arlr6Yb1Ef85QAAAPE"]
[Thu Jul 30 12:12:46.362998 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:43429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/wp-config.php"] [unique_id "amuGDs637Arlr6Yb1Ef85QAAAPE"]
[Thu Jul 30 12:12:46.450933 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/as.php"] [unique_id "amuGDs637Arlr6Yb1Ef87AAAAOs"]
[Thu Jul 30 12:12:46.451065 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/as.php"] [unique_id "amuGDs637Arlr6Yb1Ef87AAAAOs"]
[Thu Jul 30 12:12:46.574810 2026] [security2:error] [pid 703393:tid 703448] [remote 57.141.0.48:32126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/407345907/feed/rss2/"] [unique_id "amuGDs637Arlr6Yb1Ef87gAA8jY"]
[Thu Jul 30 12:12:46.630771 2026] [security2:error] [pid 703393:tid 703573] [client 20.63.98.115:21408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-config.php"] [unique_id "amuGDs637Arlr6Yb1Ef88AAAALc"]
[Thu Jul 30 12:12:46.658840 2026] [security2:error] [pid 703393:tid 703579] [client 20.203.156.12:58238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/75.php"] [unique_id "amuGDs637Arlr6Yb1Ef88QAAAL0"]
[Thu Jul 30 12:12:46.658924 2026] [security2:error] [pid 703393:tid 703579] [client 20.203.156.12:58238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/75.php"] [unique_id "amuGDs637Arlr6Yb1Ef88QAAAL0"]
[Thu Jul 30 12:12:46.925146 2026] [security2:error] [pid 703393:tid 703566] [client 185.193.49.79:61966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/zip"] [severity "WARNING"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuGDs637Arlr6Yb1Ef8_wAAALA"]
[Thu Jul 30 12:12:46.925249 2026] [security2:error] [pid 703393:tid 703566] [client 185.193.49.79:61966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuGDs637Arlr6Yb1Ef8_wAAALA"]
[Thu Jul 30 12:12:46.936477 2026] [security2:error] [pid 703393:tid 703531] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/cgi-bin/index.php"] [unique_id "amuGDs637Arlr6Yb1Ef9AQAAAI0"]
[Thu Jul 30 12:12:46.936600 2026] [security2:error] [pid 703393:tid 703531] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/cgi-bin/index.php"] [unique_id "amuGDs637Arlr6Yb1Ef9AQAAAI0"]
[Thu Jul 30 12:12:47.043527 2026] [security2:error] [pid 703393:tid 703641] [client 191.232.199.39:45075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/berax.php"] [unique_id "amuGD8637Arlr6Yb1Ef9DgAAAPs"]
[Thu Jul 30 12:12:47.053549 2026] [security2:error] [pid 703393:tid 703526] [client 20.203.156.12:58185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/71.php"] [unique_id "amuGD8637Arlr6Yb1Ef9DwAAAIg"]
[Thu Jul 30 12:12:47.053622 2026] [security2:error] [pid 703393:tid 703526] [client 20.203.156.12:58185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/71.php"] [unique_id "amuGD8637Arlr6Yb1Ef9DwAAAIg"]
[Thu Jul 30 12:12:47.203837 2026] [security2:error] [pid 703393:tid 703464] [remote 34.62.86.130:53116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuGDs637Arlr6Yb1Ef8-QAA-EY"], referer: http://jwcpartners.org/
[Thu Jul 30 12:12:47.368551 2026] [security2:error] [pid 703393:tid 703455] [remote 34.62.86.130:53116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuGDM637Arlr6Yb1Ef8vQAAiT0"], referer: http://jwcpartners.org/
[Thu Jul 30 12:12:47.375267 2026] [security2:error] [pid 703393:tid 703601] [client 20.203.156.12:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/72.php"] [unique_id "amuGD8637Arlr6Yb1Ef9GgAAANM"]
[Thu Jul 30 12:12:47.375372 2026] [security2:error] [pid 703393:tid 703601] [client 20.203.156.12:58239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/72.php"] [unique_id "amuGD8637Arlr6Yb1Ef9GgAAANM"]
[Thu Jul 30 12:12:47.452568 2026] [security2:error] [pid 703393:tid 703619] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/w1px.php"] [unique_id "amuGD8637Arlr6Yb1Ef9GwAAAOU"]
[Thu Jul 30 12:12:47.452673 2026] [security2:error] [pid 703393:tid 703619] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/w1px.php"] [unique_id "amuGD8637Arlr6Yb1Ef9GwAAAOU"]
[Thu Jul 30 12:12:47.457156 2026] [security2:error] [pid 703393:tid 703548] [client 20.63.98.115:20779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-conflg.php"] [unique_id "amuGD8637Arlr6Yb1Ef9HQAAAJ4"]
[Thu Jul 30 12:12:47.512869 2026] [core:notice] [pid 703393:tid 703539] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:47.522539 2026] [security2:error] [pid 703393:tid 703539] [client 103.215.74.26:57890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGD8637Arlr6Yb1Ef9IAAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:47.679515 2026] [security2:error] [pid 703393:tid 703649] [client 191.232.199.39:6899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/xmrlpc.php"] [unique_id "amuGD8637Arlr6Yb1Ef9LAAAAQM"]
[Thu Jul 30 12:12:47.752196 2026] [security2:error] [pid 703393:tid 703623] [client 20.203.156.12:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/70.php"] [unique_id "amuGD8637Arlr6Yb1Ef9LgAAAOk"]
[Thu Jul 30 12:12:47.752323 2026] [security2:error] [pid 703393:tid 703623] [client 20.203.156.12:39650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/70.php"] [unique_id "amuGD8637Arlr6Yb1Ef9LgAAAOk"]
[Thu Jul 30 12:12:47.965909 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/js.php"] [unique_id "amuGD8637Arlr6Yb1Ef9NAAAAMI"]
[Thu Jul 30 12:12:47.966025 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/js.php"] [unique_id "amuGD8637Arlr6Yb1Ef9NAAAAMI"]
[Thu Jul 30 12:12:48.246004 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:48.252168 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:57900] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGEM637Arlr6Yb1Ef9RwAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:48.263865 2026] [security2:error] [pid 703393:tid 703615] [client 20.203.156.12:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/69.php"] [unique_id "amuGEM637Arlr6Yb1Ef9SAAAAOE"]
[Thu Jul 30 12:12:48.263946 2026] [security2:error] [pid 703393:tid 703615] [client 20.203.156.12:51826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/69.php"] [unique_id "amuGEM637Arlr6Yb1Ef9SAAAAOE"]
[Thu Jul 30 12:12:48.413689 2026] [security2:error] [pid 703393:tid 703573] [client 66.249.65.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGD8637Arlr6Yb1Ef9MQAAALc"]
[Thu Jul 30 12:12:48.496660 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/core.php"] [unique_id "amuGEM637Arlr6Yb1Ef9TQAAAPQ"]
[Thu Jul 30 12:12:48.496760 2026] [security2:error] [pid 703393:tid 703634] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/core.php"] [unique_id "amuGEM637Arlr6Yb1Ef9TQAAAPQ"]
[Thu Jul 30 12:12:48.631793 2026] [security2:error] [pid 703393:tid 703609] [client 20.203.156.12:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/68.php"] [unique_id "amuGEM637Arlr6Yb1Ef9VQAAANs"]
[Thu Jul 30 12:12:48.631908 2026] [security2:error] [pid 703393:tid 703609] [client 20.203.156.12:39618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/68.php"] [unique_id "amuGEM637Arlr6Yb1Ef9VQAAANs"]
[Thu Jul 30 12:12:48.657277 2026] [lsapi:error] [pid 643253:tid 643275] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/about-time-vj-junior/
[Thu Jul 30 12:12:49.002065 2026] [security2:error] [pid 703393:tid 703550] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fffm.php"] [unique_id "amuGEc637Arlr6Yb1Ef9VwAAAKA"]
[Thu Jul 30 12:12:49.002206 2026] [security2:error] [pid 703393:tid 703550] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fffm.php"] [unique_id "amuGEc637Arlr6Yb1Ef9VwAAAKA"]
[Thu Jul 30 12:12:49.137630 2026] [security2:error] [pid 703393:tid 703565] [client 20.203.156.12:51816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/66.php"] [unique_id "amuGEc637Arlr6Yb1Ef9XwAAAK8"]
[Thu Jul 30 12:12:49.137759 2026] [security2:error] [pid 703393:tid 703565] [client 20.203.156.12:51816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/66.php"] [unique_id "amuGEc637Arlr6Yb1Ef9XwAAAK8"]
[Thu Jul 30 12:12:49.288863 2026] [security2:error] [pid 703393:tid 703553] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGEM637Arlr6Yb1Ef9VAAAo38"]
[Thu Jul 30 12:12:49.480107 2026] [security2:error] [pid 703393:tid 703569] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ww.php"] [unique_id "amuGEc637Arlr6Yb1Ef9YAAAALM"]
[Thu Jul 30 12:12:49.480244 2026] [security2:error] [pid 703393:tid 703569] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ww.php"] [unique_id "amuGEc637Arlr6Yb1Ef9YAAAALM"]
[Thu Jul 30 12:12:49.577209 2026] [security2:error] [pid 703393:tid 703618] [client 20.203.156.12:40243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/67.php"] [unique_id "amuGEc637Arlr6Yb1Ef9YQAAAOQ"]
[Thu Jul 30 12:12:49.577361 2026] [security2:error] [pid 703393:tid 703618] [client 20.203.156.12:40243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/67.php"] [unique_id "amuGEc637Arlr6Yb1Ef9YQAAAOQ"]
[Thu Jul 30 12:12:49.818148 2026] [security2:error] [pid 703393:tid 703625] [client 191.232.199.39:45104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/build.php"] [unique_id "amuGEc637Arlr6Yb1Ef9aAAAAOs"]
[Thu Jul 30 12:12:49.820812 2026] [security2:error] [pid 703393:tid 703587] [client 191.232.199.39:6853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/ae.php"] [unique_id "amuGEc637Arlr6Yb1Ef9aQAAAMU"]
[Thu Jul 30 12:12:49.962021 2026] [security2:error] [pid 703393:tid 703580] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/domvf.php"] [unique_id "amuGEc637Arlr6Yb1Ef9awAAAL4"]
[Thu Jul 30 12:12:49.962183 2026] [security2:error] [pid 703393:tid 703580] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/domvf.php"] [unique_id "amuGEc637Arlr6Yb1Ef9awAAAL4"]
[Thu Jul 30 12:12:50.149542 2026] [security2:error] [pid 703393:tid 703530] [client 20.203.156.12:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/65.php"] [unique_id "amuGEs637Arlr6Yb1Ef9bQAAAIw"]
[Thu Jul 30 12:12:50.149646 2026] [security2:error] [pid 703393:tid 703530] [client 20.203.156.12:40249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/65.php"] [unique_id "amuGEs637Arlr6Yb1Ef9bQAAAIw"]
[Thu Jul 30 12:12:50.451744 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/echkm.php"] [unique_id "amuGEs637Arlr6Yb1Ef9dgAAAJE"]
[Thu Jul 30 12:12:50.451864 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/echkm.php"] [unique_id "amuGEs637Arlr6Yb1Ef9dgAAAJE"]
[Thu Jul 30 12:12:50.575886 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:55579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/64.php"] [unique_id "amuGEs637Arlr6Yb1Ef9eAAAAMg"]
[Thu Jul 30 12:12:50.576014 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:55579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/64.php"] [unique_id "amuGEs637Arlr6Yb1Ef9eAAAAMg"]
[Thu Jul 30 12:12:50.935719 2026] [security2:error] [pid 703393:tid 703612] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ano.php"] [unique_id "amuGEs637Arlr6Yb1Ef9hAAAAN4"]
[Thu Jul 30 12:12:50.935829 2026] [security2:error] [pid 703393:tid 703612] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ano.php"] [unique_id "amuGEs637Arlr6Yb1Ef9hAAAAN4"]
[Thu Jul 30 12:12:50.999915 2026] [security2:error] [pid 703393:tid 703646] [client 20.203.156.12:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/63.php"] [unique_id "amuGEs637Arlr6Yb1Ef9hQAAAQA"]
[Thu Jul 30 12:12:51.000052 2026] [security2:error] [pid 703393:tid 703646] [client 20.203.156.12:53187] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/63.php"] [unique_id "amuGEs637Arlr6Yb1Ef9hQAAAQA"]
[Thu Jul 30 12:12:51.065526 2026] [security2:error] [pid 703393:tid 703555] [client 191.232.199.39:6896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/moon.php"] [unique_id "amuGE8637Arlr6Yb1Ef9hwAAAKU"]
[Thu Jul 30 12:12:51.262841 2026] [security2:error] [pid 703393:tid 703595] [client 127.0.0.1:33986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuGE8637Arlr6Yb1Ef9jAAAAM0"]
[Thu Jul 30 12:12:51.262927 2026] [security2:error] [pid 703393:tid 703553] [client 74.7.175.147:53796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.aptlaw.kr"] [uri "/robots.txt"] [unique_id "amuGE8637Arlr6Yb1Ef9iwAAoyQ"]
[Thu Jul 30 12:12:51.345376 2026] [security2:error] [pid 703393:tid 703647] [client 20.203.156.12:48718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/62.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kAAAAQE"]
[Thu Jul 30 12:12:51.345479 2026] [security2:error] [pid 703393:tid 703647] [client 20.203.156.12:48718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/62.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kAAAAQE"]
[Thu Jul 30 12:12:51.418857 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:39202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kQAAAKc"]
[Thu Jul 30 12:12:51.420507 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ah25.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kgAAAOs"]
[Thu Jul 30 12:12:51.420578 2026] [security2:error] [pid 703393:tid 703625] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ah25.php"] [unique_id "amuGE8637Arlr6Yb1Ef9kgAAAOs"]
[Thu Jul 30 12:12:51.728156 2026] [security2:error] [pid 703393:tid 703534] [client 20.203.156.12:52335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/61.php"] [unique_id "amuGE8637Arlr6Yb1Ef9lQAAAJA"]
[Thu Jul 30 12:12:51.728254 2026] [security2:error] [pid 703393:tid 703534] [client 20.203.156.12:52335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/61.php"] [unique_id "amuGE8637Arlr6Yb1Ef9lQAAAJA"]
[Thu Jul 30 12:12:51.913769 2026] [security2:error] [pid 703393:tid 703631] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/term.php"] [unique_id "amuGE8637Arlr6Yb1Ef9mgAAAPE"]
[Thu Jul 30 12:12:51.913876 2026] [security2:error] [pid 703393:tid 703631] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/term.php"] [unique_id "amuGE8637Arlr6Yb1Ef9mgAAAPE"]
[Thu Jul 30 12:12:52.217303 2026] [security2:error] [pid 703393:tid 703576] [client 20.203.156.12:54473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/60.php"] [unique_id "amuGFM637Arlr6Yb1Ef9nwAAALo"]
[Thu Jul 30 12:12:52.217405 2026] [security2:error] [pid 703393:tid 703576] [client 20.203.156.12:54473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/60.php"] [unique_id "amuGFM637Arlr6Yb1Ef9nwAAALo"]
[Thu Jul 30 12:12:52.316826 2026] [security2:error] [pid 703393:tid 703597] [client 191.232.199.39:46467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/buy.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pAAAAM8"]
[Thu Jul 30 12:12:52.399572 2026] [security2:error] [pid 703393:tid 703596] [client 20.63.98.115:21339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pQAAAM4"]
[Thu Jul 30 12:12:52.415905 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/we.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pgAAAQA"]
[Thu Jul 30 12:12:52.416021 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/we.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pgAAAQA"]
[Thu Jul 30 12:12:52.527823 2026] [security2:error] [pid 703393:tid 703524] [client 20.203.156.12:26033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/58.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pwAAAIY"]
[Thu Jul 30 12:12:52.527924 2026] [security2:error] [pid 703393:tid 703524] [client 20.203.156.12:26033] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/58.php"] [unique_id "amuGFM637Arlr6Yb1Ef9pwAAAIY"]
[Thu Jul 30 12:12:52.845694 2026] [security2:error] [pid 703393:tid 703600] [client 20.203.156.12:40198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/59.php"] [unique_id "amuGFM637Arlr6Yb1Ef9swAAANI"]
[Thu Jul 30 12:12:52.845846 2026] [security2:error] [pid 703393:tid 703600] [client 20.203.156.12:40198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/59.php"] [unique_id "amuGFM637Arlr6Yb1Ef9swAAANI"]
[Thu Jul 30 12:12:52.915324 2026] [security2:error] [pid 703393:tid 703580] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/zip-onee.php"] [unique_id "amuGFM637Arlr6Yb1Ef9twAAAL4"]
[Thu Jul 30 12:12:52.915444 2026] [security2:error] [pid 703393:tid 703580] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/zip-onee.php"] [unique_id "amuGFM637Arlr6Yb1Ef9twAAAL4"]
[Thu Jul 30 12:12:53.185855 2026] [security2:error] [pid 703393:tid 703602] [client 20.203.156.12:58180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/57.php/56.php"] [unique_id "amuGFc637Arlr6Yb1Ef9uQAAANQ"]
[Thu Jul 30 12:12:53.185970 2026] [security2:error] [pid 703393:tid 703602] [client 20.203.156.12:58180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/57.php/56.php"] [unique_id "amuGFc637Arlr6Yb1Ef9uQAAANQ"]
[Thu Jul 30 12:12:53.403930 2026] [security2:error] [pid 703393:tid 703636] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/il.php"] [unique_id "amuGFc637Arlr6Yb1Ef9wAAAAPY"]
[Thu Jul 30 12:12:53.404028 2026] [security2:error] [pid 703393:tid 703636] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/il.php"] [unique_id "amuGFc637Arlr6Yb1Ef9wAAAAPY"]
[Thu Jul 30 12:12:53.707950 2026] [security2:error] [pid 703393:tid 703597] [client 20.203.156.12:26047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/55.php"] [unique_id "amuGFc637Arlr6Yb1Ef9wQAAAM8"]
[Thu Jul 30 12:12:53.708067 2026] [security2:error] [pid 703393:tid 703597] [client 20.203.156.12:26047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/55.php"] [unique_id "amuGFc637Arlr6Yb1Ef9wQAAAM8"]
[Thu Jul 30 12:12:53.887765 2026] [security2:error] [pid 703393:tid 703527] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/one.php"] [unique_id "amuGFc637Arlr6Yb1Ef9xQAAAIk"]
[Thu Jul 30 12:12:53.887875 2026] [security2:error] [pid 703393:tid 703527] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/one.php"] [unique_id "amuGFc637Arlr6Yb1Ef9xQAAAIk"]
[Thu Jul 30 12:12:53.967885 2026] [core:notice] [pid 703393:tid 703613] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:53.974050 2026] [security2:error] [pid 703393:tid 703613] [client 103.215.74.26:50194] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGFc637Arlr6Yb1Ef9yQAAAN8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:54.141086 2026] [security2:error] [pid 703393:tid 703642] [client 20.203.156.12:26027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/54.php"] [unique_id "amuGFs637Arlr6Yb1Ef9zQAAAPw"]
[Thu Jul 30 12:12:54.141188 2026] [security2:error] [pid 703393:tid 703642] [client 20.203.156.12:26027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/54.php"] [unique_id "amuGFs637Arlr6Yb1Ef9zQAAAPw"]
[Thu Jul 30 12:12:54.332570 2026] [security2:error] [pid 703393:tid 703590] [client 20.63.98.115:43905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuGFs637Arlr6Yb1Ef9zgAAAMg"]
[Thu Jul 30 12:12:54.399374 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/002.php"] [unique_id "amuGFs637Arlr6Yb1Ef90wAAAKk"]
[Thu Jul 30 12:12:54.399469 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/002.php"] [unique_id "amuGFs637Arlr6Yb1Ef90wAAAKk"]
[Thu Jul 30 12:12:54.513033 2026] [security2:error] [pid 703393:tid 703548] [client 20.203.156.12:37022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/53.php"] [unique_id "amuGFs637Arlr6Yb1Ef91gAAAJ4"]
[Thu Jul 30 12:12:54.513153 2026] [security2:error] [pid 703393:tid 703548] [client 20.203.156.12:37022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/53.php"] [unique_id "amuGFs637Arlr6Yb1Ef91gAAAJ4"]
[Thu Jul 30 12:12:54.695508 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:12:54.701851 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:50198] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGFs637Arlr6Yb1Ef91wAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:12:54.929338 2026] [security2:error] [pid 703393:tid 703577] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/file1.php"] [unique_id "amuGFs637Arlr6Yb1Ef93gAAALs"]
[Thu Jul 30 12:12:54.929449 2026] [security2:error] [pid 703393:tid 703577] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/file1.php"] [unique_id "amuGFs637Arlr6Yb1Ef93gAAALs"]
[Thu Jul 30 12:12:55.059082 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/52.php"] [unique_id "amuGF8637Arlr6Yb1Ef94wAAANk"]
[Thu Jul 30 12:12:55.059180 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:48726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/52.php"] [unique_id "amuGF8637Arlr6Yb1Ef94wAAANk"]
[Thu Jul 30 12:12:55.372621 2026] [security2:error] [pid 703393:tid 703643] [client 20.63.98.115:43965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuGF8637Arlr6Yb1Ef95QAAAP0"]
[Thu Jul 30 12:12:55.410943 2026] [security2:error] [pid 703393:tid 703565] [client 191.232.199.39:46484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/checkbox.php"] [unique_id "amuGF8637Arlr6Yb1Ef96QAAAK8"]
[Thu Jul 30 12:12:55.443473 2026] [security2:error] [pid 703393:tid 703568] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/akimet.php"] [unique_id "amuGF8637Arlr6Yb1Ef96gAAALI"]
[Thu Jul 30 12:12:55.443557 2026] [security2:error] [pid 703393:tid 703568] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/akimet.php"] [unique_id "amuGF8637Arlr6Yb1Ef96gAAALI"]
[Thu Jul 30 12:12:55.506180 2026] [security2:error] [pid 703393:tid 703587] [client 20.203.156.12:40203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/51.php"] [unique_id "amuGF8637Arlr6Yb1Ef97gAAAMU"]
[Thu Jul 30 12:12:55.506266 2026] [security2:error] [pid 703393:tid 703587] [client 20.203.156.12:40203] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/51.php"] [unique_id "amuGF8637Arlr6Yb1Ef97gAAAMU"]
[Thu Jul 30 12:12:55.863550 2026] [security2:error] [pid 703393:tid 703533] [client 20.203.156.12:52349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/50.php"] [unique_id "amuGF8637Arlr6Yb1Ef98gAAAI8"]
[Thu Jul 30 12:12:55.863670 2026] [security2:error] [pid 703393:tid 703533] [client 20.203.156.12:52349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/50.php"] [unique_id "amuGF8637Arlr6Yb1Ef98gAAAI8"]
[Thu Jul 30 12:12:55.923122 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/reop3.php"] [unique_id "amuGF8637Arlr6Yb1Ef99gAAAKs"]
[Thu Jul 30 12:12:55.923246 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/reop3.php"] [unique_id "amuGF8637Arlr6Yb1Ef99gAAAKs"]
[Thu Jul 30 12:12:56.059966 2026] [security2:error] [pid 703393:tid 703626] [client 191.232.199.39:6877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/blog.php"] [unique_id "amuGGM637Arlr6Yb1Ef9-gAAAOw"]
[Thu Jul 30 12:12:56.368870 2026] [security2:error] [pid 703393:tid 703628] [client 172.236.9.101:38196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.bak"] [unique_id "amuGGM637Arlr6Yb1Ef9_gAAAO4"]
[Thu Jul 30 12:12:56.385294 2026] [security2:error] [pid 703393:tid 703622] [client 172.236.9.101:25133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.backup"] [unique_id "amuGGM637Arlr6Yb1Ef-BAAAAOg"]
[Thu Jul 30 12:12:56.403047 2026] [security2:error] [pid 703393:tid 703550] [client 172.236.9.101:50835] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amuGGM637Arlr6Yb1Ef-BgAAAKA"]
[Thu Jul 30 12:12:56.406029 2026] [security2:error] [pid 703393:tid 703585] [client 172.236.9.101:64909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amuGGM637Arlr6Yb1Ef-CQAAAMM"]
[Thu Jul 30 12:12:56.435150 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/h.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DwAAAJk"]
[Thu Jul 30 12:12:56.435256 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/h.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DwAAAJk"]
[Thu Jul 30 12:12:56.440484 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:54465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/49.php"] [unique_id "amuGGM637Arlr6Yb1Ef-EAAAAJs"]
[Thu Jul 30 12:12:56.440670 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:54465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/49.php"] [unique_id "amuGGM637Arlr6Yb1Ef-EAAAAJs"]
[Thu Jul 30 12:12:56.576100 2026] [core:error] [pid 703393:tid 703562] [client 74.7.175.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:12:56.576135 2026] [core:error] [pid 703393:tid 703562] [client 74.7.175.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:12:56.576358 2026] [security2:error] [pid 703393:tid 703562] [client 74.7.175.183:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-GQAAAKw"]
[Thu Jul 30 12:12:56.577146 2026] [security2:error] [pid 703393:tid 703524] [client 74.7.175.183:34786] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuGGM637Arlr6Yb1Ef-FwAAhmE"]
[Thu Jul 30 12:12:56.713398 2026] [security2:error] [pid 703393:tid 703623] [client 191.232.199.39:46495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/cong.php"] [unique_id "amuGGM637Arlr6Yb1Ef-GgAAAOk"]
[Thu Jul 30 12:12:56.883606 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:52719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/48.php"] [unique_id "amuGGM637Arlr6Yb1Ef-GwAAAMg"]
[Thu Jul 30 12:12:56.883710 2026] [security2:error] [pid 703393:tid 703590] [client 20.203.156.12:52719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/48.php"] [unique_id "amuGGM637Arlr6Yb1Ef-GwAAAMg"]
[Thu Jul 30 12:12:56.988986 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/2x.php"] [unique_id "amuGGM637Arlr6Yb1Ef-HQAAANM"]
[Thu Jul 30 12:12:56.989130 2026] [security2:error] [pid 703393:tid 703601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/2x.php"] [unique_id "amuGGM637Arlr6Yb1Ef-HQAAANM"]
[Thu Jul 30 12:12:57.371363 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:41580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/47.php"] [unique_id "amuGGc637Arlr6Yb1Ef-KAAAAPE"]
[Thu Jul 30 12:12:57.371600 2026] [security2:error] [pid 703393:tid 703631] [client 20.203.156.12:41580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/47.php"] [unique_id "amuGGc637Arlr6Yb1Ef-KAAAAPE"]
[Thu Jul 30 12:12:57.506629 2026] [security2:error] [pid 703393:tid 703640] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/petx.php"] [unique_id "amuGGc637Arlr6Yb1Ef-LAAAAPo"]
[Thu Jul 30 12:12:57.506821 2026] [security2:error] [pid 703393:tid 703640] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/petx.php"] [unique_id "amuGGc637Arlr6Yb1Ef-LAAAAPo"]
[Thu Jul 30 12:12:57.564564 2026] [security2:error] [pid 703393:tid 703632] [client 172.236.9.101:5953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef9-wAAAPI"]
[Thu Jul 30 12:12:57.567030 2026] [security2:error] [pid 703393:tid 703535] [client 172.236.9.101:37057] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef9_AAAAJE"]
[Thu Jul 30 12:12:57.567030 2026] [security2:error] [pid 703393:tid 703547] [client 172.236.9.101:28685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-AQAAAJ0"]
[Thu Jul 30 12:12:57.581704 2026] [security2:error] [pid 703393:tid 703584] [client 172.236.9.101:22765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-AwAAAMI"]
[Thu Jul 30 12:12:57.587358 2026] [security2:error] [pid 703393:tid 703583] [client 172.236.9.101:2014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef9_wAAAME"]
[Thu Jul 30 12:12:57.595707 2026] [security2:error] [pid 703393:tid 703586] [client 172.236.9.101:65064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef9_QAAAMQ"]
[Thu Jul 30 12:12:57.599763 2026] [security2:error] [pid 703393:tid 703637] [client 172.236.9.101:25293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-AgAAAPc"]
[Thu Jul 30 12:12:57.600663 2026] [security2:error] [pid 703393:tid 703552] [client 172.236.9.101:57331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-AAAAAKI"]
[Thu Jul 30 12:12:57.611070 2026] [security2:error] [pid 703393:tid 703579] [client 172.236.9.101:21877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-BwAAAL0"]
[Thu Jul 30 12:12:57.616583 2026] [security2:error] [pid 703393:tid 703617] [client 172.236.9.101:54969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-BQAAAOM"]
[Thu Jul 30 12:12:57.626678 2026] [security2:error] [pid 703393:tid 703560] [client 172.236.9.101:31783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-CAAAAKo"]
[Thu Jul 30 12:12:57.651356 2026] [security2:error] [pid 703393:tid 703555] [client 172.236.9.101:37981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DQAAAKU"]
[Thu Jul 30 12:12:57.652705 2026] [security2:error] [pid 703393:tid 703553] [client 172.236.9.101:22041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DAAAAKM"]
[Thu Jul 30 12:12:57.657112 2026] [security2:error] [pid 703393:tid 703612] [client 172.236.9.101:62889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-CgAAAN4"]
[Thu Jul 30 12:12:57.668516 2026] [security2:error] [pid 703393:tid 703596] [client 172.236.9.101:22581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-CwAAAM4"]
[Thu Jul 30 12:12:57.679708 2026] [security2:error] [pid 703393:tid 703645] [client 172.236.9.101:40809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGGM637Arlr6Yb1Ef-DgAAAP8"]
[Thu Jul 30 12:12:57.767213 2026] [security2:error] [pid 703393:tid 703646] [client 20.203.156.12:40234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/46.php"] [unique_id "amuGGc637Arlr6Yb1Ef-MQAAAQA"]
[Thu Jul 30 12:12:57.767345 2026] [security2:error] [pid 703393:tid 703646] [client 20.203.156.12:40234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/46.php"] [unique_id "amuGGc637Arlr6Yb1Ef-MQAAAQA"]
[Thu Jul 30 12:12:57.991273 2026] [security2:error] [pid 703393:tid 703563] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/zxz.php"] [unique_id "amuGGc637Arlr6Yb1Ef-MgAAAK0"]
[Thu Jul 30 12:12:57.991386 2026] [security2:error] [pid 703393:tid 703563] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/zxz.php"] [unique_id "amuGGc637Arlr6Yb1Ef-MgAAAK0"]
[Thu Jul 30 12:12:58.172550 2026] [security2:error] [pid 703393:tid 703572] [client 20.203.156.12:52289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/44.php"] [unique_id "amuGGs637Arlr6Yb1Ef-OgAAALY"]
[Thu Jul 30 12:12:58.172652 2026] [security2:error] [pid 703393:tid 703572] [client 20.203.156.12:52289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/44.php"] [unique_id "amuGGs637Arlr6Yb1Ef-OgAAALY"]
[Thu Jul 30 12:12:58.220091 2026] [security2:error] [pid 703393:tid 703633] [client 154.57.218.68:44211] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuGGs637Arlr6Yb1Ef-NgAA8zo"], referer: https://trello.com/
[Thu Jul 30 12:12:58.238681 2026] [autoindex:error] [pid 703393:tid 703605] [client 64.69.216.78:59076] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:12:58.376381 2026] [security2:error] [pid 703393:tid 703456] [remote 157.66.26.183:35136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/wp-login.php"] [unique_id "amuGGs637Arlr6Yb1Ef-PQAAyj4"]
[Thu Jul 30 12:12:58.400532 2026] [security2:error] [pid 703393:tid 703634] [client 20.63.98.115:39206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/manager.php"] [unique_id "amuGGs637Arlr6Yb1Ef-PgAAAPQ"]
[Thu Jul 30 12:12:58.516272 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/2.php"] [unique_id "amuGGs637Arlr6Yb1Ef-PwAAALU"]
[Thu Jul 30 12:12:58.516446 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/2.php"] [unique_id "amuGGs637Arlr6Yb1Ef-PwAAALU"]
[Thu Jul 30 12:12:58.794681 2026] [security2:error] [pid 703393:tid 703582] [client 191.232.199.39:46469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/file4.php"] [unique_id "amuGGs637Arlr6Yb1Ef-RgAAAMA"]
[Thu Jul 30 12:12:59.065048 2026] [security2:error] [pid 703393:tid 703538] [client 191.232.199.39:6874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/ini.php"] [unique_id "amuGG8637Arlr6Yb1Ef-SgAAAJQ"]
[Thu Jul 30 12:12:59.065394 2026] [security2:error] [pid 703393:tid 703596] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/op.php"] [unique_id "amuGG8637Arlr6Yb1Ef-SwAAAM4"]
[Thu Jul 30 12:12:59.065464 2026] [security2:error] [pid 703393:tid 703596] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/op.php"] [unique_id "amuGG8637Arlr6Yb1Ef-SwAAAM4"]
[Thu Jul 30 12:12:59.106698 2026] [security2:error] [pid 703393:tid 703427] [remote 152.53.37.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.37.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oceanscout.com"] [uri "/wp-login.php"] [unique_id "amuGG8637Arlr6Yb1Ef-TgAAwSE"]
[Thu Jul 30 12:12:59.330313 2026] [security2:error] [pid 703393:tid 703645] [client 66.249.74.4:49030] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "abudhabifurnituremoverspackers.com"] [uri "/robots.txt"] [unique_id "amuGG8637Arlr6Yb1Ef-UgAAAP8"]
[Thu Jul 30 12:12:59.331120 2026] [security2:error] [pid 703393:tid 703647] [client 20.203.156.12:26114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/43.php"] [unique_id "amuGG8637Arlr6Yb1Ef-UwAAAQE"]
[Thu Jul 30 12:12:59.331202 2026] [security2:error] [pid 703393:tid 703647] [client 20.203.156.12:26114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/43.php"] [unique_id "amuGG8637Arlr6Yb1Ef-UwAAAQE"]
[Thu Jul 30 12:12:59.576515 2026] [security2:error] [pid 703393:tid 703600] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/a5.php"] [unique_id "amuGG8637Arlr6Yb1Ef-VQAAANI"]
[Thu Jul 30 12:12:59.576668 2026] [security2:error] [pid 703393:tid 703600] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/a5.php"] [unique_id "amuGG8637Arlr6Yb1Ef-VQAAANI"]
[Thu Jul 30 12:12:59.747304 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:21253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-links.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YQAAAKU"]
[Thu Jul 30 12:12:59.760630 2026] [security2:error] [pid 703393:tid 703528] [client 20.203.156.12:26045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/42.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YgAAAIo"]
[Thu Jul 30 12:12:59.760717 2026] [security2:error] [pid 703393:tid 703528] [client 20.203.156.12:26045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/42.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YgAAAIo"]
[Thu Jul 30 12:13:00.079588 2026] [security2:error] [pid 703393:tid 703534] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ws80.php"] [unique_id "amuGHM637Arlr6Yb1Ef-ZwAAAJA"]
[Thu Jul 30 12:13:00.079695 2026] [security2:error] [pid 703393:tid 703534] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ws80.php"] [unique_id "amuGHM637Arlr6Yb1Ef-ZwAAAJA"]
[Thu Jul 30 12:13:00.102828 2026] [security2:error] [pid 703393:tid 703614] [client 20.203.156.12:54503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/41.php"] [unique_id "amuGHM637Arlr6Yb1Ef-aAAAAOA"]
[Thu Jul 30 12:13:00.102917 2026] [security2:error] [pid 703393:tid 703614] [client 20.203.156.12:54503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/41.php"] [unique_id "amuGHM637Arlr6Yb1Ef-aAAAAOA"]
[Thu Jul 30 12:13:00.183859 2026] [security2:error] [pid 703393:tid 703563] [client 191.232.199.39:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/flower.php"] [unique_id "amuGHM637Arlr6Yb1Ef-bAAAAK0"]
[Thu Jul 30 12:13:00.332795 2026] [autoindex:error] [pid 703393:tid 703604] [client 64.69.216.78:59142] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:13:00.496237 2026] [core:notice] [pid 703393:tid 703635] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:00.503611 2026] [security2:error] [pid 703393:tid 703635] [client 103.215.74.26:50216] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGHM637Arlr6Yb1Ef-dAAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:00.530149 2026] [security2:error] [pid 703393:tid 703549] [client 66.249.73.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuGG8637Arlr6Yb1Ef-XQAAAJ8"]
[Thu Jul 30 12:13:00.608810 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:47527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/40.php"] [unique_id "amuGHM637Arlr6Yb1Ef-dgAAAJs"]
[Thu Jul 30 12:13:00.608924 2026] [security2:error] [pid 703393:tid 703545] [client 20.203.156.12:47527] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/40.php"] [unique_id "amuGHM637Arlr6Yb1Ef-dgAAAJs"]
[Thu Jul 30 12:13:00.616964 2026] [security2:error] [pid 703393:tid 703582] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xa.php"] [unique_id "amuGHM637Arlr6Yb1Ef-dwAAAMA"]
[Thu Jul 30 12:13:00.617080 2026] [security2:error] [pid 703393:tid 703582] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xa.php"] [unique_id "amuGHM637Arlr6Yb1Ef-dwAAAMA"]
[Thu Jul 30 12:13:00.632150 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:21288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/fi2.php"] [unique_id "amuGHM637Arlr6Yb1Ef-eAAAAJY"]
[Thu Jul 30 12:13:00.937349 2026] [security2:error] [pid 703393:tid 703629] [client 191.232.199.39:60739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/admin-ajax.php"] [unique_id "amuGHM637Arlr6Yb1Ef-ggAAAO8"]
[Thu Jul 30 12:13:01.128998 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/asd67.php"] [unique_id "amuGHc637Arlr6Yb1Ef-gwAAAMg"]
[Thu Jul 30 12:13:01.129109 2026] [security2:error] [pid 703393:tid 703590] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/asd67.php"] [unique_id "amuGHc637Arlr6Yb1Ef-gwAAAMg"]
[Thu Jul 30 12:13:01.167535 2026] [security2:error] [pid 703393:tid 703568] [client 74.7.241.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.mskabir.com"] [uri "/index.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YwAAsjQ"]
[Thu Jul 30 12:13:01.167563 2026] [security2:error] [pid 703393:tid 703568] [client 74.7.241.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mskabir.com"] [uri "/index.php"] [unique_id "amuGG8637Arlr6Yb1Ef-YwAAsjQ"]
[Thu Jul 30 12:13:01.227664 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:33855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/39.php"] [unique_id "amuGHc637Arlr6Yb1Ef-iQAAAKg"]
[Thu Jul 30 12:13:01.227750 2026] [security2:error] [pid 703393:tid 703558] [client 20.203.156.12:33855] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/39.php"] [unique_id "amuGHc637Arlr6Yb1Ef-iQAAAKg"]
[Thu Jul 30 12:13:01.273127 2026] [core:notice] [pid 703393:tid 703623] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:01.279545 2026] [security2:error] [pid 703393:tid 703623] [client 103.215.74.26:50230] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGHc637Arlr6Yb1Ef-iwAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:01.516540 2026] [security2:error] [pid 703393:tid 703555] [client 191.232.199.39:46477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/form.php"] [unique_id "amuGHc637Arlr6Yb1Ef-kAAAAKU"]
[Thu Jul 30 12:13:01.616791 2026] [security2:error] [pid 703393:tid 703611] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/bk.php"] [unique_id "amuGHc637Arlr6Yb1Ef-kgAAAN0"]
[Thu Jul 30 12:13:01.616893 2026] [security2:error] [pid 703393:tid 703611] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/bk.php"] [unique_id "amuGHc637Arlr6Yb1Ef-kgAAAN0"]
[Thu Jul 30 12:13:01.782874 2026] [security2:error] [pid 703393:tid 703584] [client 20.203.156.12:47522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/38.php"] [unique_id "amuGHc637Arlr6Yb1Ef-mgAAAMI"]
[Thu Jul 30 12:13:01.782987 2026] [security2:error] [pid 703393:tid 703584] [client 20.203.156.12:47522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/38.php"] [unique_id "amuGHc637Arlr6Yb1Ef-mgAAAMI"]
[Thu Jul 30 12:13:01.996226 2026] [core:notice] [pid 703393:tid 703567] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:02.005312 2026] [security2:error] [pid 703393:tid 703567] [client 103.215.74.26:50238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGHc637Arlr6Yb1Ef-mwAAALE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:02.099543 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-links.php"] [unique_id "amuGHs637Arlr6Yb1Ef-nQAAAQA"]
[Thu Jul 30 12:13:02.099688 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-links.php"] [unique_id "amuGHs637Arlr6Yb1Ef-nQAAAQA"]
[Thu Jul 30 12:13:02.271334 2026] [security2:error] [pid 703393:tid 703546] [client 74.7.241.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mskabir.com"] [uri "/index.php"] [unique_id "amuGHs637Arlr6Yb1Ef-ngAAnEk"], referer: https://www.mskabir.com/robots.txt
[Thu Jul 30 12:13:02.283025 2026] [security2:error] [pid 703393:tid 703618] [client 20.203.156.12:47430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/37.php"] [unique_id "amuGHs637Arlr6Yb1Ef-pQAAAOQ"]
[Thu Jul 30 12:13:02.283147 2026] [security2:error] [pid 703393:tid 703618] [client 20.203.156.12:47430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/37.php"] [unique_id "amuGHs637Arlr6Yb1Ef-pQAAAOQ"]
[Thu Jul 30 12:13:02.363593 2026] [security2:error] [pid 703393:tid 703579] [client 191.232.199.39:6880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/akc.php"] [unique_id "amuGHs637Arlr6Yb1Ef-pwAAAL0"]
[Thu Jul 30 12:13:02.582884 2026] [security2:error] [pid 703393:tid 703528] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/mosty.php"] [unique_id "amuGHs637Arlr6Yb1Ef-qAAAAIo"]
[Thu Jul 30 12:13:02.583005 2026] [security2:error] [pid 703393:tid 703528] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/mosty.php"] [unique_id "amuGHs637Arlr6Yb1Ef-qAAAAIo"]
[Thu Jul 30 12:13:02.716125 2026] [core:notice] [pid 703393:tid 703559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:02.724213 2026] [security2:error] [pid 703393:tid 703559] [client 103.215.74.26:50242] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGHs637Arlr6Yb1Ef-rAAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:02.896700 2026] [security2:error] [pid 703393:tid 703636] [client 20.203.156.12:56139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/36.php"] [unique_id "amuGHs637Arlr6Yb1Ef-sQAAAPY"]
[Thu Jul 30 12:13:02.896822 2026] [security2:error] [pid 703393:tid 703636] [client 20.203.156.12:56139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/36.php"] [unique_id "amuGHs637Arlr6Yb1Ef-sQAAAPY"]
[Thu Jul 30 12:13:03.070359 2026] [security2:error] [pid 703393:tid 703531] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/sump3.php"] [unique_id "amuGH8637Arlr6Yb1Ef-sgAAAI0"]
[Thu Jul 30 12:13:03.070462 2026] [security2:error] [pid 703393:tid 703531] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/sump3.php"] [unique_id "amuGH8637Arlr6Yb1Ef-sgAAAI0"]
[Thu Jul 30 12:13:03.231280 2026] [security2:error] [pid 703393:tid 703560] [client 20.203.156.12:56178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/35.php"] [unique_id "amuGH8637Arlr6Yb1Ef-tQAAAKo"]
[Thu Jul 30 12:13:03.231383 2026] [security2:error] [pid 703393:tid 703560] [client 20.203.156.12:56178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/35.php"] [unique_id "amuGH8637Arlr6Yb1Ef-tQAAAKo"]
[Thu Jul 30 12:13:03.387095 2026] [security2:error] [pid 703393:tid 703606] [client 191.232.199.39:46479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/gecko.php"] [unique_id "amuGH8637Arlr6Yb1Ef-uwAAANg"]
[Thu Jul 30 12:13:03.423004 2026] [security2:error] [pid 703393:tid 703635] [client 20.63.98.115:21313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/0x.php"] [unique_id "amuGH8637Arlr6Yb1Ef-vgAAAPU"]
[Thu Jul 30 12:13:03.457692 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:03.464082 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:20782] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGH8637Arlr6Yb1Ef-vwAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:03.556178 2026] [security2:error] [pid 703393:tid 703581] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/first.php"] [unique_id "amuGH8637Arlr6Yb1Ef-wAAAAL8"]
[Thu Jul 30 12:13:03.556293 2026] [security2:error] [pid 703393:tid 703581] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/first.php"] [unique_id "amuGH8637Arlr6Yb1Ef-wAAAAL8"]
[Thu Jul 30 12:13:03.565247 2026] [security2:error] [pid 703393:tid 703600] [client 20.203.156.12:56165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/34.php"] [unique_id "amuGH8637Arlr6Yb1Ef-wQAAANI"]
[Thu Jul 30 12:13:03.565330 2026] [security2:error] [pid 703393:tid 703600] [client 20.203.156.12:56165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/34.php"] [unique_id "amuGH8637Arlr6Yb1Ef-wQAAANI"]
[Thu Jul 30 12:13:03.873015 2026] [security2:error] [pid 703393:tid 703595] [client 191.232.199.39:6856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/akcc.php"] [unique_id "amuGH8637Arlr6Yb1Ef-yQAAAM0"]
[Thu Jul 30 12:13:03.964965 2026] [security2:error] [pid 703393:tid 703614] [client 20.203.156.12:44337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/33.php"] [unique_id "amuGH8637Arlr6Yb1Ef-ygAAAOA"]
[Thu Jul 30 12:13:03.965098 2026] [security2:error] [pid 703393:tid 703614] [client 20.203.156.12:44337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/33.php"] [unique_id "amuGH8637Arlr6Yb1Ef-ygAAAOA"]
[Thu Jul 30 12:13:04.057432 2026] [security2:error] [pid 703393:tid 703602] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/acp.php"] [unique_id "amuGIM637Arlr6Yb1Ef-ywAAANQ"]
[Thu Jul 30 12:13:04.057560 2026] [security2:error] [pid 703393:tid 703602] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/acp.php"] [unique_id "amuGIM637Arlr6Yb1Ef-ywAAANQ"]
[Thu Jul 30 12:13:04.079303 2026] [security2:error] [pid 703393:tid 703639] [client 109.172.91.206:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.91.172.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.remoteworksit.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuGIM637Arlr6Yb1Ef-zAAAAPk"], referer: https://www.remoteworksit.com/contact-us/
[Thu Jul 30 12:13:04.191704 2026] [core:notice] [pid 703393:tid 703634] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:04.197831 2026] [security2:error] [pid 703393:tid 703634] [client 103.215.74.26:20796] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGIM637Arlr6Yb1Ef-zgAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:04.238238 2026] [security2:error] [pid 703393:tid 703621] [client 20.203.156.12:41547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/25.php"] [unique_id "amuGIM637Arlr6Yb1Ef-zwAAAOc"]
[Thu Jul 30 12:13:04.238356 2026] [security2:error] [pid 703393:tid 703621] [client 20.203.156.12:41547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/25.php"] [unique_id "amuGIM637Arlr6Yb1Ef-zwAAAOc"]
[Thu Jul 30 12:13:04.394263 2026] [security2:error] [pid 703393:tid 703523] [client 20.63.98.115:36889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/k.php"] [unique_id "amuGIM637Arlr6Yb1Ef-1gAAAIU"]
[Thu Jul 30 12:13:04.523363 2026] [security2:error] [pid 703393:tid 703584] [client 20.203.156.12:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/24.php"] [unique_id "amuGIM637Arlr6Yb1Ef-1wAAAMI"]
[Thu Jul 30 12:13:04.523469 2026] [security2:error] [pid 703393:tid 703584] [client 20.203.156.12:60449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/24.php"] [unique_id "amuGIM637Arlr6Yb1Ef-1wAAAMI"]
[Thu Jul 30 12:13:04.536121 2026] [security2:error] [pid 703393:tid 703574] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-good.php"] [unique_id "amuGIM637Arlr6Yb1Ef-2AAAALg"]
[Thu Jul 30 12:13:04.536199 2026] [security2:error] [pid 703393:tid 703574] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-good.php"] [unique_id "amuGIM637Arlr6Yb1Ef-2AAAALg"]
[Thu Jul 30 12:13:04.845820 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:47940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/15.php"] [unique_id "amuGIM637Arlr6Yb1Ef-3wAAANk"]
[Thu Jul 30 12:13:04.845921 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:47940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/15.php"] [unique_id "amuGIM637Arlr6Yb1Ef-3wAAANk"]
[Thu Jul 30 12:13:04.912569 2026] [core:notice] [pid 703393:tid 703582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:04.918837 2026] [security2:error] [pid 703393:tid 703582] [client 103.215.74.26:20798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGIM637Arlr6Yb1Ef-5gAAAMA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:05.029088 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/daerl3.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6AAAAIg"]
[Thu Jul 30 12:13:05.029194 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/daerl3.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6AAAAIg"]
[Thu Jul 30 12:13:05.224517 2026] [security2:error] [pid 703393:tid 703645] [client 20.63.98.115:49238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gecko-new.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6QAAAP8"]
[Thu Jul 30 12:13:05.298407 2026] [security2:error] [pid 703393:tid 703573] [client 20.203.156.12:44347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/123456.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6gAAALc"]
[Thu Jul 30 12:13:05.298509 2026] [security2:error] [pid 703393:tid 703573] [client 20.203.156.12:44347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/123456.php"] [unique_id "amuGIc637Arlr6Yb1Ef-6gAAALc"]
[Thu Jul 30 12:13:05.489781 2026] [core:notice] [pid 703393:tid 703557] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:05.506498 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/php5.php"] [unique_id "amuGIc637Arlr6Yb1Ef-8wAAAKs"]
[Thu Jul 30 12:13:05.506581 2026] [security2:error] [pid 703393:tid 703561] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/php5.php"] [unique_id "amuGIc637Arlr6Yb1Ef-8wAAAKs"]
[Thu Jul 30 12:13:05.643085 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:05.649429 2026] [security2:error] [pid 703393:tid 703633] [client 103.215.74.26:20804] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGIc637Arlr6Yb1Ef-9AAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:05.912021 2026] [security2:error] [pid 703393:tid 703632] [client 20.203.156.12:47441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/12345.php"] [unique_id "amuGIc637Arlr6Yb1Ef--QAAAPI"]
[Thu Jul 30 12:13:05.912139 2026] [security2:error] [pid 703393:tid 703632] [client 20.203.156.12:47441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/12345.php"] [unique_id "amuGIc637Arlr6Yb1Ef--QAAAPI"]
[Thu Jul 30 12:13:06.007774 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xoot.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_QAAAJE"]
[Thu Jul 30 12:13:06.007875 2026] [security2:error] [pid 703393:tid 703535] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/xoot.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_QAAAJE"]
[Thu Jul 30 12:13:06.310695 2026] [security2:error] [pid 703393:tid 703622] [client 20.203.156.12:56154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/1234.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_wAAAOg"]
[Thu Jul 30 12:13:06.310877 2026] [security2:error] [pid 703393:tid 703622] [client 20.203.156.12:56154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/1234.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_wAAAOg"]
[Thu Jul 30 12:13:06.394704 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:06.401130 2026] [security2:error] [pid 703393:tid 703523] [client 103.215.74.26:20816] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGIs637Arlr6Yb1Ef_AwAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:06.533890 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/clxcc.php"] [unique_id "amuGIs637Arlr6Yb1Ef_CAAAAQA"]
[Thu Jul 30 12:13:06.534025 2026] [security2:error] [pid 703393:tid 703646] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/clxcc.php"] [unique_id "amuGIs637Arlr6Yb1Ef_CAAAAQA"]
[Thu Jul 30 12:13:06.549083 2026] [security2:error] [pid 703393:tid 703584] [client 43.173.179.190:56350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuGIs637Arlr6Yb1Ef-_gAAAMI"]
[Thu Jul 30 12:13:06.788224 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:60473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.156.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.toscanamall.com"] [uri "/10.php"] [unique_id "amuGIs637Arlr6Yb1Ef_CQAAANk"]
[Thu Jul 30 12:13:06.788369 2026] [security2:error] [pid 703393:tid 703607] [client 20.203.156.12:60473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.toscanamall.com"] [uri "/10.php"] [unique_id "amuGIs637Arlr6Yb1Ef_CQAAANk"]
[Thu Jul 30 12:13:07.024358 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ai.php"] [unique_id "amuGI8637Arlr6Yb1Ef_EAAAAIg"]
[Thu Jul 30 12:13:07.024491 2026] [security2:error] [pid 703393:tid 703526] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ai.php"] [unique_id "amuGI8637Arlr6Yb1Ef_EAAAAIg"]
[Thu Jul 30 12:13:07.131849 2026] [core:notice] [pid 703393:tid 703615] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:07.138294 2026] [security2:error] [pid 703393:tid 703615] [client 103.215.74.26:20832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGI8637Arlr6Yb1Ef_EQAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:07.513227 2026] [security2:error] [pid 703393:tid 703563] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/nwflm.php"] [unique_id "amuGI8637Arlr6Yb1Ef_HQAAAK0"]
[Thu Jul 30 12:13:07.513351 2026] [security2:error] [pid 703393:tid 703563] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/nwflm.php"] [unique_id "amuGI8637Arlr6Yb1Ef_HQAAAK0"]
[Thu Jul 30 12:13:07.609794 2026] [security2:error] [pid 703393:tid 703537] [client 191.232.199.39:46466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/kyami.php"] [unique_id "amuGI8637Arlr6Yb1Ef_HwAAAJM"]
[Thu Jul 30 12:13:07.883551 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:07.889842 2026] [security2:error] [pid 703393:tid 703619] [client 103.215.74.26:20836] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGI8637Arlr6Yb1Ef_JwAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:08.002767 2026] [security2:error] [pid 703393:tid 703545] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/hypo.php"] [unique_id "amuGJM637Arlr6Yb1Ef_KwAAAJs"]
[Thu Jul 30 12:13:08.002867 2026] [security2:error] [pid 703393:tid 703545] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/hypo.php"] [unique_id "amuGJM637Arlr6Yb1Ef_KwAAAJs"]
[Thu Jul 30 12:13:08.064601 2026] [security2:error] [pid 703393:tid 703624] [client 20.63.98.115:57171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/alfanew.php"] [unique_id "amuGJM637Arlr6Yb1Ef_LwAAAOo"]
[Thu Jul 30 12:13:08.095957 2026] [security2:error] [pid 703393:tid 703561] [client 185.191.171.17:59064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/26/tre-pb-cassa-chapa-de-vereadores-de-cubati-por-fraude-a-cota-de-genero/"] [unique_id "amuGJM637Arlr6Yb1Ef_MAAAAKs"]
[Thu Jul 30 12:13:08.096077 2026] [security2:error] [pid 703393:tid 703561] [client 185.191.171.17:59064] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/26/tre-pb-cassa-chapa-de-vereadores-de-cubati-por-fraude-a-cota-de-genero/"] [unique_id "amuGJM637Arlr6Yb1Ef_MAAAAKs"]
[Thu Jul 30 12:13:08.270504 2026] [core:notice] [pid 703393:tid 703403] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:08.311447 2026] [security2:error] [pid 703393:tid 703565] [client 20.91.140.156:29859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/opts.php"] [unique_id "amuGJM637Arlr6Yb1Ef_MwAAAK8"]
[Thu Jul 30 12:13:08.311549 2026] [security2:error] [pid 703393:tid 703565] [client 20.91.140.156:29859] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/opts.php"] [unique_id "amuGJM637Arlr6Yb1Ef_MwAAAK8"]
[Thu Jul 30 12:13:08.333764 2026] [core:error] [pid 703393:tid 703584] [client 66.249.74.108:43735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:08.333789 2026] [core:error] [pid 703393:tid 703584] [client 66.249.74.108:43735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:08.487401 2026] [security2:error] [pid 703393:tid 703618] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/w3llscc.php"] [unique_id "amuGJM637Arlr6Yb1Ef_OAAAAOQ"]
[Thu Jul 30 12:13:08.487508 2026] [security2:error] [pid 703393:tid 703618] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/w3llscc.php"] [unique_id "amuGJM637Arlr6Yb1Ef_OAAAAOQ"]
[Thu Jul 30 12:13:08.620089 2026] [core:notice] [pid 703393:tid 703583] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:08.626385 2026] [security2:error] [pid 703393:tid 703583] [client 103.215.74.26:20846] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJM637Arlr6Yb1Ef_PAAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:08.690026 2026] [security2:error] [pid 703393:tid 703551] [client 20.91.140.156:29852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/filer.php"] [unique_id "amuGJM637Arlr6Yb1Ef_PQAAAKE"]
[Thu Jul 30 12:13:08.690126 2026] [security2:error] [pid 703393:tid 703551] [client 20.91.140.156:29852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/filer.php"] [unique_id "amuGJM637Arlr6Yb1Ef_PQAAAKE"]
[Thu Jul 30 12:13:09.028709 2026] [security2:error] [pid 703393:tid 703621] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuGJc637Arlr6Yb1Ef_QgAAAOc"]
[Thu Jul 30 12:13:09.028799 2026] [security2:error] [pid 703393:tid 703621] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuGJc637Arlr6Yb1Ef_QgAAAOc"]
[Thu Jul 30 12:13:09.041885 2026] [security2:error] [pid 703393:tid 703611] [client 191.232.199.39:46517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/manager.php"] [unique_id "amuGJc637Arlr6Yb1Ef_RAAAAN0"]
[Thu Jul 30 12:13:09.070926 2026] [security2:error] [pid 703393:tid 703554] [client 20.91.140.156:32219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/lites.php"] [unique_id "amuGJc637Arlr6Yb1Ef_RwAAAKQ"]
[Thu Jul 30 12:13:09.071090 2026] [security2:error] [pid 703393:tid 703554] [client 20.91.140.156:32219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/lites.php"] [unique_id "amuGJc637Arlr6Yb1Ef_RwAAAKQ"]
[Thu Jul 30 12:13:09.192420 2026] [security2:error] [pid 703393:tid 703563] [client 20.63.98.115:64894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/text.php"] [unique_id "amuGJc637Arlr6Yb1Ef_SAAAAK0"]
[Thu Jul 30 12:13:09.362126 2026] [core:notice] [pid 703393:tid 703627] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:09.368877 2026] [security2:error] [pid 703393:tid 703627] [client 103.215.74.26:20860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJc637Arlr6Yb1Ef_SgAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:09.387460 2026] [core:notice] [pid 703393:tid 703501] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:09.562667 2026] [security2:error] [pid 703393:tid 703637] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/8.php"] [unique_id "amuGJc637Arlr6Yb1Ef_UAAAAPc"]
[Thu Jul 30 12:13:09.562756 2026] [security2:error] [pid 703393:tid 703637] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/8.php"] [unique_id "amuGJc637Arlr6Yb1Ef_UAAAAPc"]
[Thu Jul 30 12:13:09.577226 2026] [security2:error] [pid 703393:tid 703417] [remote 74.7.241.59:48960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuGJc637Arlr6Yb1Ef_UwAAoBc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:13:09.613160 2026] [security2:error] [pid 703393:tid 703561] [client 20.91.140.156:32808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/0x.php"] [unique_id "amuGJc637Arlr6Yb1Ef_VQAAAKs"]
[Thu Jul 30 12:13:09.613277 2026] [security2:error] [pid 703393:tid 703561] [client 20.91.140.156:32808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/0x.php"] [unique_id "amuGJc637Arlr6Yb1Ef_VQAAAKs"]
[Thu Jul 30 12:13:09.780632 2026] [security2:error] [pid 703393:tid 703537] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGJc637Arlr6Yb1Ef_QQAAk2I"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 12:13:09.993267 2026] [security2:error] [pid 703393:tid 703582] [client 20.91.140.156:32192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/bless3.php"] [unique_id "amuGJc637Arlr6Yb1Ef_WgAAAMA"]
[Thu Jul 30 12:13:09.993374 2026] [security2:error] [pid 703393:tid 703582] [client 20.91.140.156:32192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/bless3.php"] [unique_id "amuGJc637Arlr6Yb1Ef_WgAAAMA"]
[Thu Jul 30 12:13:10.084272 2026] [security2:error] [pid 703393:tid 703536] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fnstall.php"] [unique_id "amuGJs637Arlr6Yb1Ef_XgAAAJI"]
[Thu Jul 30 12:13:10.084367 2026] [security2:error] [pid 703393:tid 703536] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fnstall.php"] [unique_id "amuGJs637Arlr6Yb1Ef_XgAAAJI"]
[Thu Jul 30 12:13:10.102893 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:10.109081 2026] [security2:error] [pid 703393:tid 703565] [client 103.215.74.26:20868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJs637Arlr6Yb1Ef_XwAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:10.140433 2026] [security2:error] [pid 703393:tid 703597] [client 20.63.98.115:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/f.php"] [unique_id "amuGJs637Arlr6Yb1Ef_YwAAAM8"]
[Thu Jul 30 12:13:10.295266 2026] [security2:error] [pid 703393:tid 703453] [remote 47.128.118.133:28824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/blog/"] [unique_id "amuGJs637Arlr6Yb1Ef_ZAAAujs"]
[Thu Jul 30 12:13:10.397145 2026] [security2:error] [pid 703393:tid 703556] [client 191.232.199.39:46483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/mari.php"] [unique_id "amuGJs637Arlr6Yb1Ef_ZQAAAKY"]
[Thu Jul 30 12:13:10.449438 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.140.156:38837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/wsd.php"] [unique_id "amuGJs637Arlr6Yb1Ef_ZgAAAMk"]
[Thu Jul 30 12:13:10.449534 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.140.156:38837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/wsd.php"] [unique_id "amuGJs637Arlr6Yb1Ef_ZgAAAMk"]
[Thu Jul 30 12:13:10.578073 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/edorxrr.php"] [unique_id "amuGJs637Arlr6Yb1Ef_aAAAAKk"]
[Thu Jul 30 12:13:10.578168 2026] [security2:error] [pid 703393:tid 703559] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/edorxrr.php"] [unique_id "amuGJs637Arlr6Yb1Ef_aAAAAKk"]
[Thu Jul 30 12:13:10.784995 2026] [security2:error] [pid 703393:tid 703611] [client 20.91.140.156:32794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/f6.php"] [unique_id "amuGJs637Arlr6Yb1Ef_bwAAAN0"]
[Thu Jul 30 12:13:10.785099 2026] [security2:error] [pid 703393:tid 703611] [client 20.91.140.156:32794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/f6.php"] [unique_id "amuGJs637Arlr6Yb1Ef_bwAAAN0"]
[Thu Jul 30 12:13:10.831536 2026] [core:notice] [pid 703393:tid 703630] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:10.837782 2026] [security2:error] [pid 703393:tid 703630] [client 103.215.74.26:20882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJs637Arlr6Yb1Ef_cQAAAPA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:11.061535 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/setup.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_dQAAAMM"]
[Thu Jul 30 12:13:11.061648 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/setup.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_dQAAAMM"]
[Thu Jul 30 12:13:11.148562 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.140.156:38819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/he.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_eQAAAKo"]
[Thu Jul 30 12:13:11.148655 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.140.156:38819] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/he.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_eQAAAKo"]
[Thu Jul 30 12:13:11.354069 2026] [security2:error] [pid 703393:tid 703424] [remote 74.7.241.60:34174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_fgAAhR4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:13:11.530164 2026] [security2:error] [pid 703393:tid 703606] [client 20.91.140.156:38825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/aves.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_fwAAANg"]
[Thu Jul 30 12:13:11.530277 2026] [security2:error] [pid 703393:tid 703606] [client 20.91.140.156:38825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/aves.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_fwAAANg"]
[Thu Jul 30 12:13:11.552796 2026] [core:notice] [pid 703393:tid 703566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:11.559429 2026] [security2:error] [pid 703393:tid 703566] [client 103.215.74.26:20884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGJ8637Arlr6Yb1Ef_gAAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:11.581129 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/6.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_gQAAAKI"]
[Thu Jul 30 12:13:11.581232 2026] [security2:error] [pid 703393:tid 703552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/6.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_gQAAAKI"]
[Thu Jul 30 12:13:11.628737 2026] [security2:error] [pid 703393:tid 703650] [client 20.215.216.94:35295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_gwAAAQQ"]
[Thu Jul 30 12:13:11.628847 2026] [security2:error] [pid 703393:tid 703650] [client 20.215.216.94:35295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_gwAAAQQ"]
[Thu Jul 30 12:13:11.633792 2026] [security2:error] [pid 703393:tid 703539] [client 20.63.98.115:57161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_hQAAAJU"]
[Thu Jul 30 12:13:11.876028 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.140.156:32201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_jAAAANc"]
[Thu Jul 30 12:13:11.876125 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.140.156:32201] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_jAAAANc"]
[Thu Jul 30 12:13:11.938742 2026] [security2:error] [pid 703393:tid 703641] [client 191.232.199.39:6862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/asasx.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_jwAAAPs"]
[Thu Jul 30 12:13:12.088865 2026] [security2:error] [pid 703393:tid 703528] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/w3lls.php"] [unique_id "amuGKM637Arlr6Yb1Ef_kAAAAIo"]
[Thu Jul 30 12:13:12.088972 2026] [security2:error] [pid 703393:tid 703528] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/w3lls.php"] [unique_id "amuGKM637Arlr6Yb1Ef_kAAAAIo"]
[Thu Jul 30 12:13:12.212036 2026] [security2:error] [pid 703393:tid 703634] [client 20.91.140.156:39458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/gorila.php"] [unique_id "amuGKM637Arlr6Yb1Ef_lwAAAPQ"]
[Thu Jul 30 12:13:12.212123 2026] [security2:error] [pid 703393:tid 703634] [client 20.91.140.156:39458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/gorila.php"] [unique_id "amuGKM637Arlr6Yb1Ef_lwAAAPQ"]
[Thu Jul 30 12:13:12.283885 2026] [core:notice] [pid 703393:tid 703614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:12.290079 2026] [security2:error] [pid 703393:tid 703614] [client 103.215.74.26:20896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGKM637Arlr6Yb1Ef_mAAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:12.323275 2026] [core:notice] [pid 703393:tid 703437] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:12.435702 2026] [security2:error] [pid 703393:tid 703525] [client 94.103.90.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGJ8637Arlr6Yb1Ef_jgAAhxU"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 12:13:12.595832 2026] [security2:error] [pid 703393:tid 703577] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/99.php"] [unique_id "amuGKM637Arlr6Yb1Ef_mgAAALs"]
[Thu Jul 30 12:13:12.595946 2026] [security2:error] [pid 703393:tid 703577] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/99.php"] [unique_id "amuGKM637Arlr6Yb1Ef_mgAAALs"]
[Thu Jul 30 12:13:12.666062 2026] [security2:error] [pid 703393:tid 703588] [client 20.91.140.156:38845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/vanta.php"] [unique_id "amuGKM637Arlr6Yb1Ef_nAAAAMY"]
[Thu Jul 30 12:13:12.666177 2026] [security2:error] [pid 703393:tid 703588] [client 20.91.140.156:38845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/vanta.php"] [unique_id "amuGKM637Arlr6Yb1Ef_nAAAAMY"]
[Thu Jul 30 12:13:13.049551 2026] [security2:error] [pid 703393:tid 703643] [client 191.232.199.39:46465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.laduchessecollections.com"] [uri "/nc4.php"] [unique_id "amuGKc637Arlr6Yb1Ef_owAAAP0"]
[Thu Jul 30 12:13:13.059830 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:13.066224 2026] [security2:error] [pid 703393:tid 703633] [client 103.215.74.26:10852] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGKc637Arlr6Yb1Ef_pAAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:13.114106 2026] [security2:error] [pid 703393:tid 703573] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-content/admin.php"] [unique_id "amuGKc637Arlr6Yb1Ef_pQAAALc"]
[Thu Jul 30 12:13:13.114204 2026] [security2:error] [pid 703393:tid 703573] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-content/admin.php"] [unique_id "amuGKc637Arlr6Yb1Ef_pQAAALc"]
[Thu Jul 30 12:13:13.133184 2026] [security2:error] [pid 703393:tid 703599] [client 20.91.140.156:29862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/sh3ll.php"] [unique_id "amuGKc637Arlr6Yb1Ef_pgAAANE"]
[Thu Jul 30 12:13:13.133262 2026] [security2:error] [pid 703393:tid 703599] [client 20.91.140.156:29862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/sh3ll.php"] [unique_id "amuGKc637Arlr6Yb1Ef_pgAAANE"]
[Thu Jul 30 12:13:13.518298 2026] [security2:error] [pid 703393:tid 703580] [client 20.91.140.156:29637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/cabs.php"] [unique_id "amuGKc637Arlr6Yb1Ef_rgAAAL4"]
[Thu Jul 30 12:13:13.518422 2026] [security2:error] [pid 703393:tid 703580] [client 20.91.140.156:29637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/cabs.php"] [unique_id "amuGKc637Arlr6Yb1Ef_rgAAAL4"]
[Thu Jul 30 12:13:13.631153 2026] [security2:error] [pid 703393:tid 703541] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/media.php"] [unique_id "amuGKc637Arlr6Yb1Ef_rwAAAJc"]
[Thu Jul 30 12:13:13.631275 2026] [security2:error] [pid 703393:tid 703541] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/media.php"] [unique_id "amuGKc637Arlr6Yb1Ef_rwAAAJc"]
[Thu Jul 30 12:13:13.787910 2026] [core:notice] [pid 703393:tid 703626] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:13.793954 2026] [security2:error] [pid 703393:tid 703626] [client 103.215.74.26:10860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGKc637Arlr6Yb1Ef_tAAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:13.863366 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.140.156:39437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/filesss.php"] [unique_id "amuGKc637Arlr6Yb1Ef_tQAAAPE"]
[Thu Jul 30 12:13:13.863469 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.140.156:39437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/filesss.php"] [unique_id "amuGKc637Arlr6Yb1Ef_tQAAAPE"]
[Thu Jul 30 12:13:14.142828 2026] [security2:error] [pid 703393:tid 703628] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuGKs637Arlr6Yb1Ef_uQAAAO4"]
[Thu Jul 30 12:13:14.142940 2026] [security2:error] [pid 703393:tid 703628] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuGKs637Arlr6Yb1Ef_uQAAAO4"]
[Thu Jul 30 12:13:14.266456 2026] [security2:error] [pid 703393:tid 703649] [client 213.152.187.215:42330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuGKs637Arlr6Yb1Ef_vQAAAQM"]
[Thu Jul 30 12:13:14.266573 2026] [security2:error] [pid 703393:tid 703649] [client 213.152.187.215:42330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuGKs637Arlr6Yb1Ef_vQAAAQM"]
[Thu Jul 30 12:13:14.300310 2026] [proxy:error] [pid 703393:tid 703542] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:13:14.300387 2026] [proxy_http:error] [pid 703393:tid 703542] [client 191.232.199.39:46497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:13:14.301040 2026] [proxy:error] [pid 703393:tid 703542] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:13:14.301087 2026] [proxy_http:error] [pid 703393:tid 703542] [client 191.232.199.39:46497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:13:14.307778 2026] [security2:error] [pid 703393:tid 703543] [client 20.91.140.156:38809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/wp-aaa.php"] [unique_id "amuGKs637Arlr6Yb1Ef_wQAAAJk"]
[Thu Jul 30 12:13:14.307952 2026] [security2:error] [pid 703393:tid 703543] [client 20.91.140.156:38809] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/wp-aaa.php"] [unique_id "amuGKs637Arlr6Yb1Ef_wQAAAJk"]
[Thu Jul 30 12:13:14.573518 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:14.580572 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:10868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGKs637Arlr6Yb1Ef_wgAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:14.625849 2026] [security2:error] [pid 703393:tid 703619] [client 20.63.98.115:57202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/hehe.php"] [unique_id "amuGKs637Arlr6Yb1Ef_wwAAAOU"]
[Thu Jul 30 12:13:14.655229 2026] [security2:error] [pid 703393:tid 703578] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/222.php"] [unique_id "amuGKs637Arlr6Yb1Ef_xAAAALw"]
[Thu Jul 30 12:13:14.655329 2026] [security2:error] [pid 703393:tid 703578] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/222.php"] [unique_id "amuGKs637Arlr6Yb1Ef_xAAAALw"]
[Thu Jul 30 12:13:14.715484 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.140.156:38795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/css.php"] [unique_id "amuGKs637Arlr6Yb1Ef_yQAAALA"]
[Thu Jul 30 12:13:14.715607 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.140.156:38795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/css.php"] [unique_id "amuGKs637Arlr6Yb1Ef_yQAAALA"]
[Thu Jul 30 12:13:15.097798 2026] [security2:error] [pid 703393:tid 703565] [client 20.91.140.156:29844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/ioxi-o.php"] [unique_id "amuGK8637Arlr6Yb1Ef_0AAAAK8"]
[Thu Jul 30 12:13:15.097906 2026] [security2:error] [pid 703393:tid 703565] [client 20.91.140.156:29844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/ioxi-o.php"] [unique_id "amuGK8637Arlr6Yb1Ef_0AAAAK8"]
[Thu Jul 30 12:13:15.144288 2026] [security2:error] [pid 703393:tid 703612] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-load.php"] [unique_id "amuGK8637Arlr6Yb1Ef_0QAAAN4"]
[Thu Jul 30 12:13:15.144437 2026] [security2:error] [pid 703393:tid 703612] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-load.php"] [unique_id "amuGK8637Arlr6Yb1Ef_0QAAAN4"]
[Thu Jul 30 12:13:15.322273 2026] [core:notice] [pid 703393:tid 703593] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:15.328804 2026] [security2:error] [pid 703393:tid 703593] [client 103.215.74.26:10870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGK8637Arlr6Yb1Ef_2QAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:15.425812 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.140.156:32236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/classwithtostring.php"] [unique_id "amuGK8637Arlr6Yb1Ef_2gAAAMk"]
[Thu Jul 30 12:13:15.425928 2026] [security2:error] [pid 703393:tid 703591] [client 20.91.140.156:32236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/classwithtostring.php"] [unique_id "amuGK8637Arlr6Yb1Ef_2gAAAMk"]
[Thu Jul 30 12:13:15.469549 2026] [security2:error] [pid 703393:tid 703551] [client 20.63.98.115:64858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/options.php"] [unique_id "amuGK8637Arlr6Yb1Ef_2wAAAKE"]
[Thu Jul 30 12:13:15.639555 2026] [security2:error] [pid 703393:tid 703644] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuGK8637Arlr6Yb1Ef_3AAAAP4"]
[Thu Jul 30 12:13:15.639675 2026] [security2:error] [pid 703393:tid 703644] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuGK8637Arlr6Yb1Ef_3AAAAP4"]
[Thu Jul 30 12:13:15.798841 2026] [security2:error] [pid 703393:tid 703594] [client 20.91.140.156:38785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "amuGK8637Arlr6Yb1Ef_4AAAAMw"]
[Thu Jul 30 12:13:15.798936 2026] [security2:error] [pid 703393:tid 703594] [client 20.91.140.156:38785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "amuGK8637Arlr6Yb1Ef_4AAAAMw"]
[Thu Jul 30 12:13:15.948185 2026] [security2:error] [pid 703393:tid 703623] [client 191.232.199.39:6897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/axx.php"] [unique_id "amuGK8637Arlr6Yb1Ef_5AAAAOk"]
[Thu Jul 30 12:13:16.052312 2026] [core:notice] [pid 703393:tid 703639] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:16.058008 2026] [security2:error] [pid 703393:tid 703639] [client 103.215.74.26:10874] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGLM637Arlr6Yb1Ef_5gAAAPk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:16.144532 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuGLM637Arlr6Yb1Ef_5wAAAKQ"]
[Thu Jul 30 12:13:16.144700 2026] [security2:error] [pid 703393:tid 703554] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuGLM637Arlr6Yb1Ef_5wAAAKQ"]
[Thu Jul 30 12:13:16.214823 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.140.156:32807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/fm.php"] [unique_id "amuGLM637Arlr6Yb1Ef_6AAAAPE"]
[Thu Jul 30 12:13:16.214932 2026] [security2:error] [pid 703393:tid 703631] [client 20.91.140.156:32807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/fm.php"] [unique_id "amuGLM637Arlr6Yb1Ef_6AAAAPE"]
[Thu Jul 30 12:13:16.595494 2026] [security2:error] [pid 703393:tid 703637] [client 20.91.140.156:32827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/403.php"] [unique_id "amuGLM637Arlr6Yb1Ef_7wAAAPc"]
[Thu Jul 30 12:13:16.595608 2026] [security2:error] [pid 703393:tid 703637] [client 20.91.140.156:32827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/403.php"] [unique_id "amuGLM637Arlr6Yb1Ef_7wAAAPc"]
[Thu Jul 30 12:13:16.668899 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/memberfuns.php"] [unique_id "amuGLM637Arlr6Yb1Ef_8AAAAMM"]
[Thu Jul 30 12:13:16.669020 2026] [security2:error] [pid 703393:tid 703585] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/memberfuns.php"] [unique_id "amuGLM637Arlr6Yb1Ef_8AAAAMM"]
[Thu Jul 30 12:13:16.946517 2026] [security2:error] [pid 703393:tid 703618] [client 20.91.140.156:39433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/admin.php"] [unique_id "amuGLM637Arlr6Yb1Ef_9wAAAOQ"]
[Thu Jul 30 12:13:16.946620 2026] [security2:error] [pid 703393:tid 703618] [client 20.91.140.156:39433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/admin.php"] [unique_id "amuGLM637Arlr6Yb1Ef_9wAAAOQ"]
[Thu Jul 30 12:13:17.177128 2026] [security2:error] [pid 703393:tid 703524] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/orange3.php"] [unique_id "amuGLc637Arlr6Yb1Ef_-QAAAIY"]
[Thu Jul 30 12:13:17.177247 2026] [security2:error] [pid 703393:tid 703524] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/orange3.php"] [unique_id "amuGLc637Arlr6Yb1Ef_-QAAAIY"]
[Thu Jul 30 12:13:17.342811 2026] [security2:error] [pid 703393:tid 703581] [client 20.91.140.156:29641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.140.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/lv.php"] [unique_id "amuGLc637Arlr6Yb1Ef_-wAAAL8"]
[Thu Jul 30 12:13:17.342956 2026] [security2:error] [pid 703393:tid 703581] [client 20.91.140.156:29641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/lv.php"] [unique_id "amuGLc637Arlr6Yb1Ef_-wAAAL8"]
[Thu Jul 30 12:13:17.582919 2026] [security2:error] [pid 703393:tid 703608] [client 191.232.199.39:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/berax.php"] [unique_id "amuGLc637Arlr6Yb1EcAAwAAANo"]
[Thu Jul 30 12:13:17.668658 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuGLc637Arlr6Yb1EcABAAAALU"]
[Thu Jul 30 12:13:17.668778 2026] [security2:error] [pid 703393:tid 703571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuGLc637Arlr6Yb1EcABAAAALU"]
[Thu Jul 30 12:13:17.854572 2026] [security2:error] [pid 703393:tid 703583] [client 20.215.216.94:35291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuGLc637Arlr6Yb1EcABwAAAME"]
[Thu Jul 30 12:13:17.854672 2026] [security2:error] [pid 703393:tid 703583] [client 20.215.216.94:35291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuGLc637Arlr6Yb1EcABwAAAME"]
[Thu Jul 30 12:13:17.867287 2026] [core:notice] [pid 703393:tid 703449] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:18.169115 2026] [security2:error] [pid 703393:tid 703570] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/wp-the.php"] [unique_id "amuGLs637Arlr6Yb1EcAEAAAALQ"]
[Thu Jul 30 12:13:18.169227 2026] [security2:error] [pid 703393:tid 703570] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/wp-the.php"] [unique_id "amuGLs637Arlr6Yb1EcAEAAAALQ"]
[Thu Jul 30 12:13:18.199702 2026] [security2:error] [pid 703393:tid 703598] [client 20.63.98.115:62455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuGLs637Arlr6Yb1EcAEQAAANA"]
[Thu Jul 30 12:13:18.468530 2026] [core:notice] [pid 703393:tid 703491] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:18.684807 2026] [security2:error] [pid 703393:tid 703609] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/crgio.php"] [unique_id "amuGLs637Arlr6Yb1EcAHwAAANs"]
[Thu Jul 30 12:13:18.684946 2026] [security2:error] [pid 703393:tid 703609] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/crgio.php"] [unique_id "amuGLs637Arlr6Yb1EcAHwAAANs"]
[Thu Jul 30 12:13:19.239678 2026] [security2:error] [pid 703393:tid 703623] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ws13.php"] [unique_id "amuGL8637Arlr6Yb1EcAKAAAAOk"]
[Thu Jul 30 12:13:19.239806 2026] [security2:error] [pid 703393:tid 703623] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ws13.php"] [unique_id "amuGL8637Arlr6Yb1EcAKAAAAOk"]
[Thu Jul 30 12:13:19.261110 2026] [core:error] [pid 703393:tid 703626] [client 74.7.175.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:19.261133 2026] [core:error] [pid 703393:tid 703626] [client 74.7.175.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:19.261256 2026] [security2:error] [pid 703393:tid 703626] [client 74.7.175.159:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuGL8637Arlr6Yb1EcAKwAAAOw"]
[Thu Jul 30 12:13:19.261828 2026] [security2:error] [pid 703393:tid 703594] [client 74.7.175.159:56720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuGL8637Arlr6Yb1EcAKQAAzBA"]
[Thu Jul 30 12:13:19.747342 2026] [security2:error] [pid 703393:tid 703525] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/srontol.php"] [unique_id "amuGL8637Arlr6Yb1EcAMgAAAIc"]
[Thu Jul 30 12:13:19.747460 2026] [security2:error] [pid 703393:tid 703525] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/srontol.php"] [unique_id "amuGL8637Arlr6Yb1EcAMgAAAIc"]
[Thu Jul 30 12:13:20.231379 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/miru3.php"] [unique_id "amuGMM637Arlr6Yb1EcAPwAAAMI"]
[Thu Jul 30 12:13:20.231507 2026] [security2:error] [pid 703393:tid 703584] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/miru3.php"] [unique_id "amuGMM637Arlr6Yb1EcAPwAAAMI"]
[Thu Jul 30 12:13:20.396233 2026] [security2:error] [pid 703393:tid 703568] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAPgAAALI"]
[Thu Jul 30 12:13:20.682795 2026] [autoindex:error] [pid 703393:tid 703472] [remote 45.33.110.19:60260] AH01276: Cannot serve directory /home1/uixgzjte/public_html/chicago-mfg.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:13:20.728334 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ingfo.php"] [unique_id "amuGMM637Arlr6Yb1EcASgAAAJk"]
[Thu Jul 30 12:13:20.728447 2026] [security2:error] [pid 703393:tid 703543] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ingfo.php"] [unique_id "amuGMM637Arlr6Yb1EcASgAAAJk"]
[Thu Jul 30 12:13:21.164469 2026] [security2:error] [pid 703393:tid 703612] [client 20.215.216.94:35708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuGMc637Arlr6Yb1EcAZQAAAN4"]
[Thu Jul 30 12:13:21.164660 2026] [security2:error] [pid 703393:tid 703612] [client 20.215.216.94:35708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuGMc637Arlr6Yb1EcAZQAAAN4"]
[Thu Jul 30 12:13:21.219582 2026] [security2:error] [pid 703393:tid 703581] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/ey5.php"] [unique_id "amuGMc637Arlr6Yb1EcAZgAAAL8"]
[Thu Jul 30 12:13:21.219801 2026] [security2:error] [pid 703393:tid 703581] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/ey5.php"] [unique_id "amuGMc637Arlr6Yb1EcAZgAAAL8"]
[Thu Jul 30 12:13:21.394365 2026] [security2:error] [pid 703393:tid 703404] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGMM637Arlr6Yb1EcASAAA-Ao"]
[Thu Jul 30 12:13:21.394792 2026] [security2:error] [pid 703393:tid 703638] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGMM637Arlr6Yb1EcASAAA-Ao"]
[Thu Jul 30 12:13:21.710159 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/fine.php"] [unique_id "amuGMc637Arlr6Yb1EcAcAAAAPA"]
[Thu Jul 30 12:13:21.710252 2026] [security2:error] [pid 703393:tid 703630] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "reviewbyjook.com"] [uri "/fine.php"] [unique_id "amuGMc637Arlr6Yb1EcAcAAAAPA"]
[Thu Jul 30 12:13:21.756391 2026] [security2:error] [pid 703393:tid 703647] [client 191.232.199.39:6898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/build.php"] [unique_id "amuGMc637Arlr6Yb1EcAcQAAAQE"]
[Thu Jul 30 12:13:21.790324 2026] [core:notice] [pid 703393:tid 703601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:21.796636 2026] [security2:error] [pid 703393:tid 703601] [client 103.215.74.26:10884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGMc637Arlr6Yb1EcAcgAAANM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:21.834072 2026] [security2:error] [pid 703393:tid 703544] [client 20.63.98.115:38949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/images/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAdgAAAJo"]
[Thu Jul 30 12:13:22.361142 2026] [security2:error] [pid 703393:tid 703646] [client 172.237.109.114:7060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcASwAAAQA"]
[Thu Jul 30 12:13:22.409767 2026] [security2:error] [pid 703393:tid 703594] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAbwAAAMw"]
[Thu Jul 30 12:13:22.446740 2026] [security2:error] [pid 703393:tid 703586] [client 172.237.109.114:50036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcATQAAAMQ"]
[Thu Jul 30 12:13:22.468072 2026] [security2:error] [pid 703393:tid 703607] [client 172.237.109.114:16217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcATwAAANk"]
[Thu Jul 30 12:13:22.468071 2026] [security2:error] [pid 703393:tid 703525] [client 172.237.109.114:24173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAUgAAAIc"]
[Thu Jul 30 12:13:22.471716 2026] [security2:error] [pid 703393:tid 703648] [client 172.237.109.114:11892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAUwAAAQI"]
[Thu Jul 30 12:13:22.489464 2026] [security2:error] [pid 703393:tid 703531] [client 172.237.109.114:1707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAUAAAAI0"]
[Thu Jul 30 12:13:22.494023 2026] [security2:error] [pid 703393:tid 703621] [client 172.237.109.114:9703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAVwAAAOc"]
[Thu Jul 30 12:13:22.498212 2026] [security2:error] [pid 703393:tid 703577] [client 172.237.109.114:30994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcATgAAALs"]
[Thu Jul 30 12:13:22.509416 2026] [security2:error] [pid 703393:tid 703618] [client 172.237.109.114:28924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAVgAAAOQ"]
[Thu Jul 30 12:13:22.521331 2026] [security2:error] [pid 703393:tid 703603] [client 172.237.109.114:59920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAVAAAANU"]
[Thu Jul 30 12:13:22.521731 2026] [security2:error] [pid 703393:tid 703552] [client 172.237.109.114:43404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAXgAAAKI"]
[Thu Jul 30 12:13:22.540115 2026] [security2:error] [pid 703393:tid 703562] [client 172.237.109.114:43281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAWwAAAKw"]
[Thu Jul 30 12:13:22.541000 2026] [security2:error] [pid 703393:tid 703523] [client 172.237.109.114:65343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAUQAAAIU"]
[Thu Jul 30 12:13:22.543330 2026] [security2:error] [pid 703393:tid 703566] [client 172.237.109.114:20729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAWQAAALA"]
[Thu Jul 30 12:13:22.550577 2026] [security2:error] [pid 703393:tid 703570] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAeQAAALQ"]
[Thu Jul 30 12:13:22.551834 2026] [security2:error] [pid 703393:tid 703537] [client 172.237.109.114:14974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcATAAAAJM"]
[Thu Jul 30 12:13:22.560166 2026] [security2:error] [pid 703393:tid 703649] [client 172.237.109.114:60680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAWAAAAQM"]
[Thu Jul 30 12:13:22.561243 2026] [security2:error] [pid 703393:tid 703596] [client 172.237.109.114:21369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAWgAAAM4"]
[Thu Jul 30 12:13:22.577188 2026] [security2:error] [pid 703393:tid 703559] [client 172.237.109.114:47889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMM637Arlr6Yb1EcAVQAAAKk"]
[Thu Jul 30 12:13:22.584716 2026] [security2:error] [pid 703393:tid 703549] [client 172.237.109.114:41397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAXAAAAJ8"]
[Thu Jul 30 12:13:22.631679 2026] [security2:error] [pid 703393:tid 703546] [client 172.237.109.114:41736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGMc637Arlr6Yb1EcAXQAAAJw"]
[Thu Jul 30 12:13:23.040204 2026] [security2:error] [pid 703393:tid 703622] [client 191.232.199.39:6906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/buy.php"] [unique_id "amuGM8637Arlr6Yb1EcAiQAAAOg"]
[Thu Jul 30 12:13:23.922811 2026] [security2:error] [pid 703393:tid 703533] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGM8637Arlr6Yb1EcAkwAAAI8"]
[Thu Jul 30 12:13:24.004438 2026] [security2:error] [pid 703393:tid 703605] [client 20.63.98.115:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/index.php"] [unique_id "amuGNM637Arlr6Yb1EcAmgAAANc"]
[Thu Jul 30 12:13:24.290868 2026] [security2:error] [pid 703393:tid 703540] [client 20.215.216.94:35279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/err.php"] [unique_id "amuGNM637Arlr6Yb1EcAowAAAJY"]
[Thu Jul 30 12:13:24.291001 2026] [security2:error] [pid 703393:tid 703540] [client 20.215.216.94:35279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/err.php"] [unique_id "amuGNM637Arlr6Yb1EcAowAAAJY"]
[Thu Jul 30 12:13:25.163414 2026] [security2:error] [pid 703393:tid 703608] [client 185.189.112.11:56158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuGNc637Arlr6Yb1EcAqwAAANo"]
[Thu Jul 30 12:13:25.163520 2026] [security2:error] [pid 703393:tid 703608] [client 185.189.112.11:56158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuGNc637Arlr6Yb1EcAqwAAANo"]
[Thu Jul 30 12:13:25.195231 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:63124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/13.php"] [unique_id "amuGNc637Arlr6Yb1EcArQAAAMU"]
[Thu Jul 30 12:13:25.868131 2026] [security2:error] [pid 703393:tid 703550] [client 20.215.216.94:35650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/img.php"] [unique_id "amuGNc637Arlr6Yb1EcAuQAAAKA"]
[Thu Jul 30 12:13:25.868224 2026] [security2:error] [pid 703393:tid 703550] [client 20.215.216.94:35650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/img.php"] [unique_id "amuGNc637Arlr6Yb1EcAuQAAAKA"]
[Thu Jul 30 12:13:26.052718 2026] [security2:error] [pid 703393:tid 703553] [client 85.208.96.200:53718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/25/veneziano-reforca-compromisso-com-agricultura-familiar-e-parcerias-para-construcao-e-reestruturacao-de-mercados-publicos/"] [unique_id "amuGNs637Arlr6Yb1EcAugAAAKM"]
[Thu Jul 30 12:13:26.052880 2026] [security2:error] [pid 703393:tid 703553] [client 85.208.96.200:53718] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/25/veneziano-reforca-compromisso-com-agricultura-familiar-e-parcerias-para-construcao-e-reestruturacao-de-mercados-publicos/"] [unique_id "amuGNs637Arlr6Yb1EcAugAAAKM"]
[Thu Jul 30 12:13:26.687641 2026] [security2:error] [pid 703393:tid 703548] [client 20.215.216.94:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/aa.php"] [unique_id "amuGNs637Arlr6Yb1EcAvwAAAJ4"]
[Thu Jul 30 12:13:26.687742 2026] [security2:error] [pid 703393:tid 703548] [client 20.215.216.94:35698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/aa.php"] [unique_id "amuGNs637Arlr6Yb1EcAvwAAAJ4"]
[Thu Jul 30 12:13:27.428722 2026] [security2:error] [pid 703393:tid 703559] [client 20.63.98.115:57200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/inputs.php"] [unique_id "amuGN8637Arlr6Yb1EcAzAAAAKk"]
[Thu Jul 30 12:13:27.538735 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:27.545023 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:19328] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGN8637Arlr6Yb1EcAzgAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:28.015688 2026] [security2:error] [pid 703393:tid 703645] [client 20.215.216.94:35695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/av.php"] [unique_id "amuGOM637Arlr6Yb1EcA1wAAAP8"]
[Thu Jul 30 12:13:28.015783 2026] [security2:error] [pid 703393:tid 703645] [client 20.215.216.94:35695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/av.php"] [unique_id "amuGOM637Arlr6Yb1EcA1wAAAP8"]
[Thu Jul 30 12:13:28.261732 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:28.269236 2026] [security2:error] [pid 703393:tid 703633] [client 103.215.74.26:19342] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGOM637Arlr6Yb1EcA3wAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:29.032588 2026] [core:notice] [pid 703393:tid 703533] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:29.038405 2026] [security2:error] [pid 703393:tid 703533] [client 103.215.74.26:19356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGOc637Arlr6Yb1EcA9gAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:29.442637 2026] [security2:error] [pid 703393:tid 703627] [client 20.215.216.94:35666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/xa.php"] [unique_id "amuGOc637Arlr6Yb1EcBDgAAAO0"]
[Thu Jul 30 12:13:29.442740 2026] [security2:error] [pid 703393:tid 703627] [client 20.215.216.94:35666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/xa.php"] [unique_id "amuGOc637Arlr6Yb1EcBDgAAAO0"]
[Thu Jul 30 12:13:29.777292 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:29.783473 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:19370] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGOc637Arlr6Yb1EcBFgAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:30.536482 2026] [core:notice] [pid 703393:tid 703628] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:30.542408 2026] [security2:error] [pid 703393:tid 703628] [client 103.215.74.26:19376] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGOs637Arlr6Yb1EcBIwAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:30.599226 2026] [security2:error] [pid 703393:tid 703527] [client 20.215.216.94:35707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/media.php"] [unique_id "amuGOs637Arlr6Yb1EcBJAAAAIk"]
[Thu Jul 30 12:13:30.599371 2026] [security2:error] [pid 703393:tid 703527] [client 20.215.216.94:35707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/media.php"] [unique_id "amuGOs637Arlr6Yb1EcBJAAAAIk"]
[Thu Jul 30 12:13:31.122938 2026] [security2:error] [pid 703393:tid 703537] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGOs637Arlr6Yb1EcBIgAAAJM"]
[Thu Jul 30 12:13:31.273671 2026] [core:notice] [pid 703393:tid 703572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:31.280440 2026] [security2:error] [pid 703393:tid 703572] [client 103.215.74.26:19386] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGO8637Arlr6Yb1EcBMQAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:31.673023 2026] [security2:error] [pid 703393:tid 703622] [client 191.232.199.39:60741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/checkbox.php"] [unique_id "amuGO8637Arlr6Yb1EcBRQAAAOg"]
[Thu Jul 30 12:13:31.952897 2026] [security2:error] [pid 703393:tid 703563] [client 20.215.216.94:35677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/images.php"] [unique_id "amuGO8637Arlr6Yb1EcBYgAAAK0"]
[Thu Jul 30 12:13:31.953047 2026] [security2:error] [pid 703393:tid 703563] [client 20.215.216.94:35677] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/images.php"] [unique_id "amuGO8637Arlr6Yb1EcBYgAAAK0"]
[Thu Jul 30 12:13:31.981685 2026] [security2:error] [pid 703393:tid 703560] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGO8637Arlr6Yb1EcBNwAAqhw"]
[Thu Jul 30 12:13:32.030267 2026] [core:notice] [pid 703393:tid 703596] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:32.036845 2026] [security2:error] [pid 703393:tid 703596] [client 103.215.74.26:19390] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPM637Arlr6Yb1EcBYwAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:32.148186 2026] [security2:error] [pid 703393:tid 703535] [client 20.63.98.115:63469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/jquery.php"] [unique_id "amuGPM637Arlr6Yb1EcBZAAAAJE"]
[Thu Jul 30 12:13:32.762768 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:32.773255 2026] [security2:error] [pid 703393:tid 703565] [client 103.215.74.26:19400] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPM637Arlr6Yb1EcBcAAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:32.944696 2026] [security2:error] [pid 703393:tid 703526] [client 191.232.199.39:6890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/cong.php"] [unique_id "amuGPM637Arlr6Yb1EcBdAAAAIg"]
[Thu Jul 30 12:13:33.349190 2026] [security2:error] [pid 703393:tid 703592] [client 20.215.216.94:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/gecko.php"] [unique_id "amuGPc637Arlr6Yb1EcBeAAAAMo"]
[Thu Jul 30 12:13:33.349278 2026] [security2:error] [pid 703393:tid 703592] [client 20.215.216.94:35304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/gecko.php"] [unique_id "amuGPc637Arlr6Yb1EcBeAAAAMo"]
[Thu Jul 30 12:13:33.502682 2026] [core:notice] [pid 703393:tid 703552] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:33.509132 2026] [security2:error] [pid 703393:tid 703552] [client 103.215.74.26:33072] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPc637Arlr6Yb1EcBfAAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:34.244761 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:34.251153 2026] [security2:error] [pid 703393:tid 703621] [client 103.215.74.26:33084] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPs637Arlr6Yb1EcBhQAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:34.526185 2026] [security2:error] [pid 703393:tid 703564] [client 191.232.199.39:60771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/file4.php"] [unique_id "amuGPs637Arlr6Yb1EcBjAAAAK4"]
[Thu Jul 30 12:13:34.969074 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:34.976100 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:33092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGPs637Arlr6Yb1EcBlgAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:35.038481 2026] [security2:error] [pid 703393:tid 703551] [client 20.215.216.94:35702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/82.php"] [unique_id "amuGP8637Arlr6Yb1EcBmgAAAKE"]
[Thu Jul 30 12:13:35.038569 2026] [security2:error] [pid 703393:tid 703551] [client 20.215.216.94:35702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/82.php"] [unique_id "amuGP8637Arlr6Yb1EcBmgAAAKE"]
[Thu Jul 30 12:13:35.724276 2026] [core:notice] [pid 703393:tid 703578] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:35.730504 2026] [security2:error] [pid 703393:tid 703578] [client 103.215.74.26:33098] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGP8637Arlr6Yb1EcBowAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:35.920790 2026] [security2:error] [pid 703393:tid 703467] [remote 51.195.183.133:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "saiqon.net"] [uri "/contact/"] [unique_id "amuGP8637Arlr6Yb1EcBpwAAhkk"]
[Thu Jul 30 12:13:35.920930 2026] [security2:error] [pid 703393:tid 703524] [client 51.195.183.133:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "saiqon.net"] [uri "/contact/"] [unique_id "amuGP8637Arlr6Yb1EcBpwAAhkk"]
[Thu Jul 30 12:13:36.207830 2026] [security2:error] [pid 703393:tid 703569] [client 191.232.199.39:60749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/flower.php"] [unique_id "amuGQM637Arlr6Yb1EcBrgAAALM"]
[Thu Jul 30 12:13:36.448609 2026] [core:notice] [pid 703393:tid 703611] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:36.454926 2026] [security2:error] [pid 703393:tid 703611] [client 103.215.74.26:33108] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQM637Arlr6Yb1EcBtQAAAN0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:36.894453 2026] [security2:error] [pid 703393:tid 703642] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGQM637Arlr6Yb1EcBsQAAAPw"]
[Thu Jul 30 12:13:37.083756 2026] [security2:error] [pid 703393:tid 703570] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGQM637Arlr6Yb1EcBtgAAtGU"]
[Thu Jul 30 12:13:37.197529 2026] [core:notice] [pid 703393:tid 703538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:37.208157 2026] [security2:error] [pid 703393:tid 703538] [client 103.215.74.26:33110] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQc637Arlr6Yb1EcBxAAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:37.509478 2026] [security2:error] [pid 703393:tid 703594] [client 20.215.216.94:35688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/xstelth.php"] [unique_id "amuGQc637Arlr6Yb1EcByAAAAMw"]
[Thu Jul 30 12:13:37.509591 2026] [security2:error] [pid 703393:tid 703594] [client 20.215.216.94:35688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/xstelth.php"] [unique_id "amuGQc637Arlr6Yb1EcByAAAAMw"]
[Thu Jul 30 12:13:37.621120 2026] [security2:error] [pid 703393:tid 703591] [client 191.232.199.39:6886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/form.php"] [unique_id "amuGQc637Arlr6Yb1EcBzwAAAMk"]
[Thu Jul 30 12:13:37.962369 2026] [core:notice] [pid 703393:tid 703528] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:37.973080 2026] [security2:error] [pid 703393:tid 703528] [client 103.215.74.26:33120] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQc637Arlr6Yb1EcB1QAAAIo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:38.066837 2026] [security2:error] [pid 703393:tid 703616] [client 20.63.98.115:63460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/doc.php"] [unique_id "amuGQs637Arlr6Yb1EcB3AAAAOI"]
[Thu Jul 30 12:13:38.461446 2026] [security2:error] [pid 703393:tid 703527] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGQc637Arlr6Yb1EcB1AAAAIk"]
[Thu Jul 30 12:13:38.695326 2026] [core:notice] [pid 703393:tid 703626] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:38.701630 2026] [security2:error] [pid 703393:tid 703626] [client 103.215.74.26:33130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQs637Arlr6Yb1EcB5wAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:39.324195 2026] [security2:error] [pid 703393:tid 703598] [client 191.232.199.39:6902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/gecko.php"] [unique_id "amuGQ8637Arlr6Yb1EcB8QAAANA"]
[Thu Jul 30 12:13:39.464740 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:39.471307 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:33132] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGQ8637Arlr6Yb1EcB8gAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:40.198864 2026] [core:notice] [pid 703393:tid 703553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:40.205219 2026] [security2:error] [pid 703393:tid 703553] [client 103.215.74.26:33144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGRM637Arlr6Yb1EcCAgAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:40.518596 2026] [security2:error] [pid 703393:tid 703578] [client 20.63.98.115:65282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/02.php"] [unique_id "amuGRM637Arlr6Yb1EcCBgAAALw"]
[Thu Jul 30 12:13:40.937589 2026] [core:notice] [pid 703393:tid 703524] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:40.944033 2026] [security2:error] [pid 703393:tid 703524] [client 103.215.74.26:33146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGRM637Arlr6Yb1EcCDgAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:41.219047 2026] [security2:error] [pid 703393:tid 703619] [client 191.232.199.39:6900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/kyami.php"] [unique_id "amuGRc637Arlr6Yb1EcCFQAAAOU"]
[Thu Jul 30 12:13:41.520261 2026] [security2:error] [pid 703393:tid 703536] [client 20.63.98.115:49128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/well-known/admin.php"] [unique_id "amuGRc637Arlr6Yb1EcCHgAAAJI"]
[Thu Jul 30 12:13:41.676989 2026] [core:notice] [pid 703393:tid 703637] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:41.683328 2026] [security2:error] [pid 703393:tid 703637] [client 103.215.74.26:33156] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGRc637Arlr6Yb1EcCHwAAAPc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:41.738832 2026] [security2:error] [pid 703393:tid 703521] [remote 40.77.167.67:5174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/pbb/article/download/7395/index_php/index/index_php/JGST"] [unique_id "amuGRc637Arlr6Yb1EcCIwAA7n8"]
[Thu Jul 30 12:13:42.426766 2026] [core:notice] [pid 703393:tid 703525] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:42.433173 2026] [security2:error] [pid 703393:tid 703525] [client 103.215.74.26:33162] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGRs637Arlr6Yb1EcCLgAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:42.860231 2026] [autoindex:error] [pid 703393:tid 703543] [client 20.63.98.115:47173] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:13:43.045642 2026] [autoindex:error] [pid 703393:tid 703593] [client 66.132.172.202:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:13:43.063768 2026] [security2:error] [pid 703393:tid 703625] [client 20.63.98.115:47173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/v.php"] [unique_id "amuGR8637Arlr6Yb1EcCPAAAAOs"]
[Thu Jul 30 12:13:43.161395 2026] [core:notice] [pid 703393:tid 703557] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:43.168480 2026] [security2:error] [pid 703393:tid 703557] [client 103.215.74.26:59326] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGR8637Arlr6Yb1EcCPQAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:43.857681 2026] [security2:error] [pid 703393:tid 703578] [client 20.215.216.94:35685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/xp.php"] [unique_id "amuGR8637Arlr6Yb1EcCSgAAALw"]
[Thu Jul 30 12:13:43.857776 2026] [security2:error] [pid 703393:tid 703578] [client 20.215.216.94:35685] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/xp.php"] [unique_id "amuGR8637Arlr6Yb1EcCSgAAALw"]
[Thu Jul 30 12:13:43.886571 2026] [core:notice] [pid 703393:tid 703561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:43.892952 2026] [security2:error] [pid 703393:tid 703561] [client 103.215.74.26:59330] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGR8637Arlr6Yb1EcCTgAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:44.507734 2026] [security2:error] [pid 703393:tid 703612] [client 20.63.98.115:47199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/main.php"] [unique_id "amuGSM637Arlr6Yb1EcCWAAAAN4"]
[Thu Jul 30 12:13:44.557376 2026] [security2:error] [pid 703393:tid 703594] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGR8637Arlr6Yb1EcCUQAAAMw"]
[Thu Jul 30 12:13:44.623291 2026] [security2:error] [pid 703393:tid 703558] [client 191.232.199.39:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/manager.php"] [unique_id "amuGSM637Arlr6Yb1EcCWQAAAKg"]
[Thu Jul 30 12:13:44.671441 2026] [core:notice] [pid 703393:tid 703593] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:44.677652 2026] [security2:error] [pid 703393:tid 703593] [client 103.215.74.26:59344] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGSM637Arlr6Yb1EcCWwAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:45.317988 2026] [core:notice] [pid 703393:tid 703627] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:45.388173 2026] [core:notice] [pid 703393:tid 703530] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:45.394205 2026] [security2:error] [pid 703393:tid 703530] [client 103.215.74.26:59378] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGSc637Arlr6Yb1EcCagAAAIw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:46.127819 2026] [core:notice] [pid 703393:tid 703594] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:46.134305 2026] [security2:error] [pid 703393:tid 703594] [client 103.215.74.26:59394] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGSs637Arlr6Yb1EcCdwAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:46.353417 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:63450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/file.php"] [unique_id "amuGSs637Arlr6Yb1EcCewAAAMU"]
[Thu Jul 30 12:13:46.451351 2026] [core:notice] [pid 703393:tid 703439] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:46.800221 2026] [security2:error] [pid 703393:tid 703601] [client 185.191.171.9:38924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/26/petrobras-reduz-preco-do-diesel-em-4-e-o-da-gasolina-em-5/"] [unique_id "amuGSs637Arlr6Yb1EcChAAAANM"]
[Thu Jul 30 12:13:46.800367 2026] [security2:error] [pid 703393:tid 703601] [client 185.191.171.9:38924] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/26/petrobras-reduz-preco-do-diesel-em-4-e-o-da-gasolina-em-5/"] [unique_id "amuGSs637Arlr6Yb1EcChAAAANM"]
[Thu Jul 30 12:13:46.854080 2026] [core:notice] [pid 703393:tid 703643] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:46.860473 2026] [security2:error] [pid 703393:tid 703643] [client 103.215.74.26:59428] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGSs637Arlr6Yb1EcChQAAAP0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:46.956955 2026] [core:notice] [pid 703393:tid 703441] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:47.047350 2026] [security2:error] [pid 703393:tid 703644] [client 20.215.216.94:35668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/admin.php"] [unique_id "amuGS8637Arlr6Yb1EcCjQAAAP4"]
[Thu Jul 30 12:13:47.047446 2026] [security2:error] [pid 703393:tid 703644] [client 20.215.216.94:35668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/admin.php"] [unique_id "amuGS8637Arlr6Yb1EcCjQAAAP4"]
[Thu Jul 30 12:13:47.607075 2026] [core:notice] [pid 703393:tid 703558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:47.613890 2026] [security2:error] [pid 703393:tid 703558] [client 103.215.74.26:59436] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGS8637Arlr6Yb1EcCmAAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:47.942476 2026] [security2:error] [pid 703393:tid 703648] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCkQABAjU"]
[Thu Jul 30 12:13:48.093645 2026] [security2:error] [pid 703393:tid 703523] [client 20.63.98.115:47188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuGTM637Arlr6Yb1EcCpAAAAIU"]
[Thu Jul 30 12:13:48.350183 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:48.361008 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:59460] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGTM637Arlr6Yb1EcCpQAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:48.445546 2026] [core:notice] [pid 703393:tid 703457] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:48.613633 2026] [security2:error] [pid 703393:tid 703564] [client 146.103.115.7:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.103.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/my-account/"] [unique_id "amuGTM637Arlr6Yb1EcCrgAAAK4"], referer: https://online-hope.com/
[Thu Jul 30 12:13:48.714128 2026] [security2:error] [pid 703393:tid 703600] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGTM637Arlr6Yb1EcCowAA0g0"]
[Thu Jul 30 12:13:48.862141 2026] [core:notice] [pid 703393:tid 703490] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:49.094718 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:49.101155 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:59472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGTc637Arlr6Yb1EcCtwAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:49.450789 2026] [security2:error] [pid 703393:tid 703586] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCkAAAAMQ"]
[Thu Jul 30 12:13:49.720493 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:20866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuGTc637Arlr6Yb1EcCwgAAAKU"]
[Thu Jul 30 12:13:49.742174 2026] [security2:error] [pid 703393:tid 703588] [client 81.255.2.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "espairsa.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCmwAAxhI"]
[Thu Jul 30 12:13:49.812453 2026] [core:notice] [pid 703393:tid 703561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:49.819058 2026] [security2:error] [pid 703393:tid 703561] [client 103.215.74.26:59520] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGTc637Arlr6Yb1EcCwwAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:50.256531 2026] [security2:error] [pid 703393:tid 703552] [client 81.255.2.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "espairsa.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCmQAAojg"]
[Thu Jul 30 12:13:50.302207 2026] [security2:error] [pid 703393:tid 703542] [client 81.255.2.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "espairsa.com"] [uri "/index.php"] [unique_id "amuGS8637Arlr6Yb1EcCnQAAmCg"]
[Thu Jul 30 12:13:50.539460 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:50.545945 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:59526] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGTs637Arlr6Yb1EcC1gAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:51.266800 2026] [security2:error] [pid 703393:tid 703524] [client 20.63.98.115:20869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/file.php"] [unique_id "amuGT8637Arlr6Yb1EcC6AAAAIY"]
[Thu Jul 30 12:13:51.272671 2026] [core:notice] [pid 703393:tid 703556] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:51.279253 2026] [security2:error] [pid 703393:tid 703556] [client 103.215.74.26:59564] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGT8637Arlr6Yb1EcC6QAAAKY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:51.445906 2026] [security2:error] [pid 703393:tid 703554] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGTs637Arlr6Yb1EcC3wAAAKQ"]
[Thu Jul 30 12:13:52.029792 2026] [core:notice] [pid 703393:tid 703550] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:52.036436 2026] [security2:error] [pid 703393:tid 703550] [client 103.215.74.26:59568] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGUM637Arlr6Yb1EcC9gAAAKA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:52.491809 2026] [security2:error] [pid 703393:tid 703547] [client 68.67.112.200:64927] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuGUM637Arlr6Yb1EcDAAAAAJ0"]
[Thu Jul 30 12:13:52.762572 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:52.773339 2026] [security2:error] [pid 703393:tid 703644] [client 103.215.74.26:59614] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGUM637Arlr6Yb1EcDBwAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:53.088377 2026] [security2:error] [pid 703393:tid 703587] [client 146.103.110.13:61998] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.110.13" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "online-hope.com"] [uri "/wp-comments-post.php"] [unique_id "amuGUc637Arlr6Yb1EcDCQAAAMU"], referer: https://online-hope.com/hello-world/
[Thu Jul 30 12:13:53.088498 2026] [security2:error] [pid 703393:tid 703587] [client 146.103.110.13:61998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/wp-comments-post.php"] [unique_id "amuGUc637Arlr6Yb1EcDCQAAAMU"], referer: https://online-hope.com/hello-world/
[Thu Jul 30 12:13:53.549524 2026] [core:notice] [pid 703393:tid 703588] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:53.555542 2026] [security2:error] [pid 703393:tid 703588] [client 103.215.74.26:9556] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGUc637Arlr6Yb1EcDEwAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:53.768213 2026] [core:error] [pid 703393:tid 703600] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:53.768234 2026] [core:error] [pid 703393:tid 703600] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:13:54.164240 2026] [security2:error] [pid 703393:tid 703581] [client 191.232.199.39:6864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/mari.php"] [unique_id "amuGUs637Arlr6Yb1EcDHAAAAL8"]
[Thu Jul 30 12:13:54.281852 2026] [core:notice] [pid 703393:tid 703640] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:54.288899 2026] [security2:error] [pid 703393:tid 703640] [client 103.215.74.26:9564] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGUs637Arlr6Yb1EcDIgAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:55.044860 2026] [core:notice] [pid 703393:tid 703598] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:55.051427 2026] [security2:error] [pid 703393:tid 703598] [client 103.215.74.26:9574] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGU8637Arlr6Yb1EcDMAAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:55.084793 2026] [core:notice] [pid 703393:tid 703541] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:55.303937 2026] [security2:error] [pid 703393:tid 703597] [client 20.63.98.115:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-signup.php"] [unique_id "amuGU8637Arlr6Yb1EcDNgAAAM8"]
[Thu Jul 30 12:13:55.762774 2026] [security2:error] [pid 703393:tid 703624] [client 191.232.199.39:60755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/nc4.php"] [unique_id "amuGU8637Arlr6Yb1EcDOwAAAOo"]
[Thu Jul 30 12:13:55.793370 2026] [core:notice] [pid 703393:tid 703573] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:55.799896 2026] [security2:error] [pid 703393:tid 703573] [client 103.215.74.26:9576] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGU8637Arlr6Yb1EcDQAAAALc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:56.450327 2026] [security2:error] [pid 703393:tid 703620] [client 20.63.98.115:57218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/css/index.php"] [unique_id "amuGVM637Arlr6Yb1EcDXQAAAOY"]
[Thu Jul 30 12:13:56.529636 2026] [core:notice] [pid 703393:tid 703531] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:56.535505 2026] [security2:error] [pid 703393:tid 703531] [client 103.215.74.26:9580] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGVM637Arlr6Yb1EcDgwAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:57.059954 2026] [proxy:error] [pid 703393:tid 703569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:13:57.060052 2026] [proxy_http:error] [pid 703393:tid 703569] [client 191.232.199.39:60743] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:13:57.060767 2026] [proxy:error] [pid 703393:tid 703569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:13:57.060816 2026] [proxy_http:error] [pid 703393:tid 703569] [client 191.232.199.39:60743] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:13:57.270940 2026] [core:notice] [pid 703393:tid 703559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:57.277615 2026] [security2:error] [pid 703393:tid 703559] [client 103.215.74.26:9588] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGVc637Arlr6Yb1EcDnQAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:58.054661 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:58.060722 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:9590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGVs637Arlr6Yb1EcDtQAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:58.358394 2026] [security2:error] [pid 703393:tid 703407] [remote 57.141.0.54:33120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuGVs637Arlr6Yb1EcDtwAAxQ0"]
[Thu Jul 30 12:13:58.547663 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:20885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ge.php"] [unique_id "amuGVs637Arlr6Yb1EcDuwAAAKU"]
[Thu Jul 30 12:13:58.618308 2026] [core:notice] [pid 703393:tid 703639] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:58.643219 2026] [security2:error] [pid 703393:tid 703541] [client 146.103.115.7:54563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuGVM637Arlr6Yb1EcDjQAAAJc"], referer: https://online-hope.com/xmlrpc.php
[Thu Jul 30 12:13:58.774483 2026] [security2:error] [pid 703393:tid 703643] [client 89.238.167.166:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuGVs637Arlr6Yb1EcDwwAAAP0"]
[Thu Jul 30 12:13:58.774588 2026] [security2:error] [pid 703393:tid 703643] [client 89.238.167.166:51762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuGVs637Arlr6Yb1EcDwwAAAP0"]
[Thu Jul 30 12:13:58.802442 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:58.809920 2026] [security2:error] [pid 703393:tid 703621] [client 103.215.74.26:9602] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGVs637Arlr6Yb1EcDxAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:59.554778 2026] [core:notice] [pid 703393:tid 703563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:13:59.561366 2026] [security2:error] [pid 703393:tid 703563] [client 103.215.74.26:9606] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGV8637Arlr6Yb1EcD0AAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:13:59.618512 2026] [security2:error] [pid 703393:tid 703594] [client 20.63.98.115:20886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/goods.php"] [unique_id "amuGV8637Arlr6Yb1EcD0gAAAMw"]
[Thu Jul 30 12:13:59.730266 2026] [security2:error] [pid 703393:tid 703586] [client 20.215.216.94:35704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/adminner.php"] [unique_id "amuGV8637Arlr6Yb1EcD1gAAAMQ"]
[Thu Jul 30 12:13:59.730359 2026] [security2:error] [pid 703393:tid 703586] [client 20.215.216.94:35704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/adminner.php"] [unique_id "amuGV8637Arlr6Yb1EcD1gAAAMQ"]
[Thu Jul 30 12:13:59.817621 2026] [security2:error] [pid 703393:tid 703597] [client 87.201.220.126:60239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amuGV8637Arlr6Yb1EcD0QAAzyk"], referer: https://skcarrental.ae/car-type/monthly-car/?gad_source=1&gad_campaignid=23407362884&gbraid=0AAAABCcUrdmCj2hdePFXzuK89ExS49TME&gclid=CjwKCAjw7KvTBhA6EiwAWnutYT7TM1e7sTtzf3_4glgZsj6VbtVzH6Yz9lo4i36-pSHqaqej9B_nqRoCh3AQAvD_BwE
[Thu Jul 30 12:13:59.928717 2026] [core:notice] [pid 703393:tid 703626] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:00.201663 2026] [security2:error] [pid 703393:tid 703450] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGWM637Arlr6Yb1EcD4gAAkzg"]
[Thu Jul 30 12:14:00.201835 2026] [security2:error] [pid 703393:tid 703537] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGWM637Arlr6Yb1EcD4gAAkzg"]
[Thu Jul 30 12:14:00.290310 2026] [core:notice] [pid 703393:tid 703538] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:00.296945 2026] [security2:error] [pid 703393:tid 703538] [client 103.215.74.26:9618] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGWM637Arlr6Yb1EcD5QAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:00.799227 2026] [security2:error] [pid 703393:tid 703612] [client 146.103.115.7:54864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuGV8637Arlr6Yb1EcDyAAAAN4"], referer: https://online-hope.com/xmlrpc.php
[Thu Jul 30 12:14:01.053959 2026] [core:notice] [pid 703393:tid 703604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:01.060277 2026] [security2:error] [pid 703393:tid 703604] [client 103.215.74.26:9624] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGWc637Arlr6Yb1EcD8QAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:01.133910 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:47210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/403.php"] [unique_id "amuGWc637Arlr6Yb1EcD9QAAAQM"]
[Thu Jul 30 12:14:01.320048 2026] [security2:error] [pid 703393:tid 703410] [remote 157.55.39.58:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/-/media/Files/OGB/Soumu/article.php"] [unique_id "amuGWc637Arlr6Yb1EcD_gAAtxA"]
[Thu Jul 30 12:14:01.784108 2026] [core:notice] [pid 703393:tid 703614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:01.790103 2026] [security2:error] [pid 703393:tid 703614] [client 103.215.74.26:9632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGWc637Arlr6Yb1EcEAwAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:02.520849 2026] [core:notice] [pid 703393:tid 703527] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:02.527147 2026] [security2:error] [pid 703393:tid 703527] [client 103.215.74.26:9634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGWs637Arlr6Yb1EcEDgAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:03.276454 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:03.282857 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:10724] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGW8637Arlr6Yb1EcEGwAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:03.935560 2026] [security2:error] [pid 703393:tid 703584] [client 20.215.216.94:35659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/a.php"] [unique_id "amuGW8637Arlr6Yb1EcEJwAAAMI"]
[Thu Jul 30 12:14:03.935653 2026] [security2:error] [pid 703393:tid 703584] [client 20.215.216.94:35659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/a.php"] [unique_id "amuGW8637Arlr6Yb1EcEJwAAAMI"]
[Thu Jul 30 12:14:04.034694 2026] [core:notice] [pid 703393:tid 703629] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:04.041421 2026] [security2:error] [pid 703393:tid 703629] [client 103.215.74.26:10730] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXM637Arlr6Yb1EcEKQAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:04.778220 2026] [core:notice] [pid 703393:tid 703650] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:04.784279 2026] [security2:error] [pid 703393:tid 703650] [client 103.215.74.26:10732] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXM637Arlr6Yb1EcEMgAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:05.507346 2026] [core:notice] [pid 703393:tid 703595] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:05.513409 2026] [security2:error] [pid 703393:tid 703595] [client 103.215.74.26:10738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXc637Arlr6Yb1EcETAAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:05.532882 2026] [security2:error] [pid 703393:tid 703552] [client 146.103.115.7:55443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "online-hope.com"] [uri "/wp-admin/post-new.php"] [unique_id "amuGW8637Arlr6Yb1EcEHwAAAKI"], referer: https://online-hope.com/my-account/?action=register&xoo_el_reg_email=gb_caitlyntarenorerer%40falderewonek.site&xoo_el_reg_fname=Judy&xoo_el_reg_lname=Handcock&xoo_el_reg_pass=uFSL5SYn290x*5&xoo_el_reg_pass_again=uFSL5SYn290x*5&xoo_el_reg_terms=yes&_xoo_el_form=register&xoo_el_redirect=%2Fmy-account%2F%3Faction%3Dregister
[Thu Jul 30 12:14:06.238248 2026] [core:notice] [pid 703393:tid 703641] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:06.244657 2026] [security2:error] [pid 703393:tid 703641] [client 103.215.74.26:10750] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXs637Arlr6Yb1EcEVwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:06.355005 2026] [security2:error] [pid 703393:tid 703529] [client 20.215.216.94:35327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/k.php"] [unique_id "amuGXs637Arlr6Yb1EcEWAAAAIs"]
[Thu Jul 30 12:14:06.355116 2026] [security2:error] [pid 703393:tid 703529] [client 20.215.216.94:35327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/k.php"] [unique_id "amuGXs637Arlr6Yb1EcEWAAAAIs"]
[Thu Jul 30 12:14:06.530296 2026] [core:notice] [pid 703393:tid 703615] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:06.551974 2026] [security2:error] [pid 703393:tid 703474] [remote 57.141.0.6:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amuGXs637Arlr6Yb1EcEYAAAzFA"]
[Thu Jul 30 12:14:06.963261 2026] [core:notice] [pid 703393:tid 703642] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:06.969662 2026] [security2:error] [pid 703393:tid 703642] [client 103.215.74.26:10754] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGXs637Arlr6Yb1EcEZgAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:07.241557 2026] [security2:error] [pid 703393:tid 703485] [remote 160.191.139.115:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.139.191.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nfh.udi.temporary.site"] [uri "/wp-login.php"] [unique_id "amuGX8637Arlr6Yb1EcEawAAu1s"]
[Thu Jul 30 12:14:07.270438 2026] [security2:error] [pid 703393:tid 703611] [client 213.152.187.215:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuGX8637Arlr6Yb1EcEbQAAAN0"]
[Thu Jul 30 12:14:07.270521 2026] [security2:error] [pid 703393:tid 703611] [client 213.152.187.215:48840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuGX8637Arlr6Yb1EcEbQAAAN0"]
[Thu Jul 30 12:14:07.274815 2026] [security2:error] [pid 703393:tid 703554] [client 185.200.117.131:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGX8637Arlr6Yb1EcEbAAAAKQ"]
[Thu Jul 30 12:14:07.274899 2026] [security2:error] [pid 703393:tid 703554] [client 185.200.117.131:60416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGX8637Arlr6Yb1EcEbAAAAKQ"]
[Thu Jul 30 12:14:07.353216 2026] [security2:error] [pid 703393:tid 703621] [client 72.13.46.9:40584] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kbsgg.click"] [uri "/robots.txt"] [unique_id "amuGX8637Arlr6Yb1EcEbgAAAOc"]
[Thu Jul 30 12:14:07.697049 2026] [core:notice] [pid 703393:tid 703598] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:07.703422 2026] [security2:error] [pid 703393:tid 703598] [client 103.215.74.26:10766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGX8637Arlr6Yb1EcEdgAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:08.807685 2026] [security2:error] [pid 703393:tid 703480] [remote 97.74.93.24:42712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuGYM637Arlr6Yb1EcEgwAA7FY"]
[Thu Jul 30 12:14:09.021908 2026] [security2:error] [pid 703393:tid 703526] [client 20.215.216.94:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/222.php"] [unique_id "amuGYc637Arlr6Yb1EcEhwAAAIg"]
[Thu Jul 30 12:14:09.022030 2026] [security2:error] [pid 703393:tid 703526] [client 20.215.216.94:35296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/222.php"] [unique_id "amuGYc637Arlr6Yb1EcEhwAAAIg"]
[Thu Jul 30 12:14:10.909715 2026] [security2:error] [pid 703393:tid 703596] [client 20.63.98.115:20927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/public/makeasmtp.php"] [unique_id "amuGYs637Arlr6Yb1EcErQAAAM4"]
[Thu Jul 30 12:14:10.964043 2026] [security2:error] [pid 703393:tid 703554] [client 57.141.0.20:28756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuGYs637Arlr6Yb1EcEogAApE0"], referer: https://igetvape-australia.com/product/alibarbar-rich-8000-puffs-8/?add-to-cart=1055
[Thu Jul 30 12:14:11.136418 2026] [security2:error] [pid 703393:tid 703515] [remote 74.7.241.59:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuGY8637Arlr6Yb1EcEsQAAink"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:14:11.647854 2026] [security2:error] [pid 703393:tid 703545] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGY8637Arlr6Yb1EcEsAAAAJs"]
[Thu Jul 30 12:14:12.348738 2026] [security2:error] [pid 703393:tid 703605] [client 20.63.98.115:57270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mar.php"] [unique_id "amuGZM637Arlr6Yb1EcExAAAANc"]
[Thu Jul 30 12:14:12.566961 2026] [security2:error] [pid 703393:tid 703562] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGY8637Arlr6Yb1EcEwAAAAKw"]
[Thu Jul 30 12:14:13.054278 2026] [security2:error] [pid 703393:tid 703531] [client 20.215.216.94:35286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.womenclothingbox.com"] [uri "/mac.php"] [unique_id "amuGZc637Arlr6Yb1EcEzgAAAI0"]
[Thu Jul 30 12:14:13.054405 2026] [security2:error] [pid 703393:tid 703531] [client 20.215.216.94:35286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.womenclothingbox.com"] [uri "/mac.php"] [unique_id "amuGZc637Arlr6Yb1EcEzgAAAI0"]
[Thu Jul 30 12:14:13.427173 2026] [core:notice] [pid 703393:tid 703585] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:13.433411 2026] [security2:error] [pid 703393:tid 703585] [client 103.215.74.26:6336] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGZc637Arlr6Yb1EcE1QAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:13.859125 2026] [security2:error] [pid 703393:tid 703520] [remote 57.141.0.68:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuGZc637Arlr6Yb1EcE2gAAzX4"]
[Thu Jul 30 12:14:13.901515 2026] [security2:error] [pid 703393:tid 703559] [client 20.63.98.115:43288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/system.php"] [unique_id "amuGZc637Arlr6Yb1EcE3QAAAKk"]
[Thu Jul 30 12:14:14.033577 2026] [security2:error] [pid 703393:tid 703511] [remote 74.7.241.60:48972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuGZs637Arlr6Yb1EcE3wAAxnU"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:14:14.151151 2026] [core:notice] [pid 703393:tid 703601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:14.157493 2026] [security2:error] [pid 703393:tid 703601] [client 103.215.74.26:6342] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGZs637Arlr6Yb1EcE4QAAANM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:14.567013 2026] [security2:error] [pid 703393:tid 703546] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGZc637Arlr6Yb1EcE3gAAnHQ"]
[Thu Jul 30 12:14:14.889928 2026] [core:notice] [pid 703393:tid 703563] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:14.896231 2026] [security2:error] [pid 703393:tid 703563] [client 103.215.74.26:6346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGZs637Arlr6Yb1EcE7AAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:15.368813 2026] [security2:error] [pid 703393:tid 703597] [client 20.63.98.115:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/lock360.php"] [unique_id "amuGZ8637Arlr6Yb1EcE9gAAAM8"]
[Thu Jul 30 12:14:15.634002 2026] [core:notice] [pid 703393:tid 703634] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:15.640192 2026] [security2:error] [pid 703393:tid 703634] [client 103.215.74.26:6354] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGZ8637Arlr6Yb1EcE-gAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:16.391273 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:16.397394 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:6370] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGaM637Arlr6Yb1EcFBAAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:17.120273 2026] [core:notice] [pid 703393:tid 703532] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:17.126213 2026] [security2:error] [pid 703393:tid 703532] [client 103.215.74.26:6372] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGac637Arlr6Yb1EcFDgAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:17.325518 2026] [core:notice] [pid 703393:tid 703443] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:17.865833 2026] [core:notice] [pid 703393:tid 703627] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:17.872188 2026] [security2:error] [pid 703393:tid 703627] [client 103.215.74.26:6380] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGac637Arlr6Yb1EcFHwAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:17.938907 2026] [core:error] [pid 703393:tid 703590] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:14:17.938927 2026] [core:error] [pid 703393:tid 703590] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:14:18.075584 2026] [security2:error] [pid 703393:tid 703539] [client 20.63.98.115:31862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amuGas637Arlr6Yb1EcFKQAAAJU"]
[Thu Jul 30 12:14:18.365444 2026] [security2:error] [pid 703393:tid 703577] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGac637Arlr6Yb1EcFHgAAuw8"]
[Thu Jul 30 12:14:18.604514 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:18.611043 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:6388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGas637Arlr6Yb1EcFNQAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:18.726792 2026] [security2:error] [pid 703393:tid 703423] [remote 67.207.94.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.94.207.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "totalwebsite.biz"] [uri "/wp-login.php"] [unique_id "amuGas637Arlr6Yb1EcFNAAA_h0"]
[Thu Jul 30 12:14:19.230398 2026] [security2:error] [pid 703393:tid 703567] [client 85.107.110.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGa8637Arlr6Yb1EcFSQAAALE"], referer: https://cnpinyin.com
[Thu Jul 30 12:14:19.288755 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:31865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mah.php"] [unique_id "amuGa8637Arlr6Yb1EcFUQAAAKc"]
[Thu Jul 30 12:14:19.328354 2026] [lsapi:error] [pid 703393:tid 703397] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/love-hurts-vj-junior/
[Thu Jul 30 12:14:19.915622 2026] [security2:error] [pid 703393:tid 703634] [client 216.244.66.196:44122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGa8637Arlr6Yb1EcFXQAAAPQ"]
[Thu Jul 30 12:14:19.915716 2026] [security2:error] [pid 703393:tid 703634] [client 216.244.66.196:44122] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGa8637Arlr6Yb1EcFXQAAAPQ"]
[Thu Jul 30 12:14:20.317429 2026] [autoindex:error] [pid 703393:tid 703554] [client 20.63.98.115:20899] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:14:20.605641 2026] [security2:error] [pid 703393:tid 703582] [client 20.63.98.115:20899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-class.php"] [unique_id "amuGbM637Arlr6Yb1EcFbQAAAMA"]
[Thu Jul 30 12:14:21.165571 2026] [security2:error] [pid 703393:tid 703558] [client 185.200.117.131:44872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuGbc637Arlr6Yb1EcFeAAAAKg"]
[Thu Jul 30 12:14:21.165670 2026] [security2:error] [pid 703393:tid 703558] [client 185.200.117.131:44872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuGbc637Arlr6Yb1EcFeAAAAKg"]
[Thu Jul 30 12:14:22.240550 2026] [security2:error] [pid 703393:tid 703577] [client 20.63.98.115:31861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/backup.php"] [unique_id "amuGbs637Arlr6Yb1EcFiQAAALs"]
[Thu Jul 30 12:14:22.732514 2026] [security2:error] [pid 703393:tid 703504] [remote 57.141.0.46:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuGbs637Arlr6Yb1EcFmwAAxm4"]
[Thu Jul 30 12:14:23.074191 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:31849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/default.php"] [unique_id "amuGb8637Arlr6Yb1EcFogAAAOg"]
[Thu Jul 30 12:14:24.164832 2026] [security2:error] [pid 703393:tid 703525] [client 20.63.98.115:62804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/maint/about.php"] [unique_id "amuGcM637Arlr6Yb1EcFvQAAAIc"]
[Thu Jul 30 12:14:24.371701 2026] [core:notice] [pid 703393:tid 703584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:24.378210 2026] [security2:error] [pid 703393:tid 703584] [client 103.215.74.26:2660] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGcM637Arlr6Yb1EcFwQAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:24.928653 2026] [security2:error] [pid 703393:tid 703632] [client 20.63.98.115:57298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amuGcM637Arlr6Yb1EcFyQAAAPI"]
[Thu Jul 30 12:14:25.104465 2026] [core:notice] [pid 703393:tid 703635] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:25.111045 2026] [security2:error] [pid 703393:tid 703635] [client 103.215.74.26:2664] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGcc637Arlr6Yb1EcFzgAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:25.835991 2026] [core:notice] [pid 703393:tid 703529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:25.846567 2026] [security2:error] [pid 703393:tid 703529] [client 103.215.74.26:2666] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGcc637Arlr6Yb1EcF4AAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:26.079114 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ty.php"] [unique_id "amuGcs637Arlr6Yb1EcF6AAAAPo"]
[Thu Jul 30 12:14:26.585264 2026] [core:notice] [pid 703393:tid 703597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:26.591724 2026] [security2:error] [pid 703393:tid 703597] [client 103.215.74.26:2674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGcs637Arlr6Yb1EcF7wAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:26.786943 2026] [security2:error] [pid 703393:tid 703480] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGcs637Arlr6Yb1EcF8QAAxFY"]
[Thu Jul 30 12:14:26.787154 2026] [security2:error] [pid 703393:tid 703586] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGcs637Arlr6Yb1EcF8QAAxFY"]
[Thu Jul 30 12:14:27.340468 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:27.346734 2026] [security2:error] [pid 703393:tid 703621] [client 103.215.74.26:2684] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGc8637Arlr6Yb1EcF_AAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:27.383509 2026] [security2:error] [pid 703393:tid 703582] [client 20.63.98.115:38003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/readme.php"] [unique_id "amuGc8637Arlr6Yb1EcF_wAAAMA"]
[Thu Jul 30 12:14:28.085297 2026] [core:notice] [pid 703393:tid 703607] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:28.091297 2026] [security2:error] [pid 703393:tid 703607] [client 103.215.74.26:2692] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGdM637Arlr6Yb1EcGCQAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:28.801328 2026] [security2:error] [pid 703393:tid 703646] [client 20.63.98.115:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/options.php"] [unique_id "amuGdM637Arlr6Yb1EcGGAAAAQA"]
[Thu Jul 30 12:14:28.821990 2026] [core:notice] [pid 703393:tid 703564] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:28.828668 2026] [security2:error] [pid 703393:tid 703564] [client 103.215.74.26:2700] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGdM637Arlr6Yb1EcGGQAAAK4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:28.897800 2026] [security2:error] [pid 703393:tid 703643] [client 127.0.0.1:12210] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuGdM637Arlr6Yb1EcGHgAAAP0"]
[Thu Jul 30 12:14:28.897889 2026] [security2:error] [pid 703393:tid 703578] [client 74.7.228.35:56120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.dov.dtn.temporary.site"] [uri "/robots.txt"] [unique_id "amuGdM637Arlr6Yb1EcGHQAAvH8"]
[Thu Jul 30 12:14:28.997672 2026] [security2:error] [pid 703393:tid 703648] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGdM637Arlr6Yb1EcGEwAAAQI"]
[Thu Jul 30 12:14:29.550569 2026] [security2:error] [pid 703393:tid 703561] [client 220.181.108.113:61903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9466"] [unique_id "amuGdc637Arlr6Yb1EcGLAAAAKs"]
[Thu Jul 30 12:14:29.557272 2026] [core:notice] [pid 703393:tid 703547] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:29.563811 2026] [security2:error] [pid 703393:tid 703547] [client 103.215.74.26:2724] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGdc637Arlr6Yb1EcGLQAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:30.025778 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin.php7"] [unique_id "amuGds637Arlr6Yb1EcGOgAAAJY"]
[Thu Jul 30 12:14:30.297211 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:30.303636 2026] [security2:error] [pid 703393:tid 703581] [client 103.215.74.26:2744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGds637Arlr6Yb1EcGQwAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:30.308625 2026] [security2:error] [pid 703393:tid 703616] [client 17.246.23.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGds637Arlr6Yb1EcGQQAAAOI"]
[Thu Jul 30 12:14:30.534024 2026] [core:notice] [pid 703393:tid 703541] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:30.573223 2026] [core:notice] [pid 703393:tid 703529] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:31.021222 2026] [core:notice] [pid 703393:tid 703648] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:31.026787 2026] [security2:error] [pid 703393:tid 703648] [client 103.215.74.26:2760] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGd8637Arlr6Yb1EcGgAAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:31.716777 2026] [security2:error] [pid 703393:tid 703625] [client 20.63.98.115:57325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/wp-login.php"] [unique_id "amuGd8637Arlr6Yb1EcGoAAAAOs"]
[Thu Jul 30 12:14:31.764404 2026] [core:notice] [pid 703393:tid 703620] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:31.770916 2026] [security2:error] [pid 703393:tid 703620] [client 103.215.74.26:2768] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGd8637Arlr6Yb1EcGoQAAAOY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:32.171617 2026] [security2:error] [pid 703393:tid 703576] [client 136.114.127.127:35034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.shop-peace.com"] [uri "/index.cgi"] [unique_id "amuGeM637Arlr6Yb1EcGsgAAALo"]
[Thu Jul 30 12:14:32.507354 2026] [security2:error] [pid 703393:tid 703528] [client 20.63.98.115:57293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuGeM637Arlr6Yb1EcGtQAAAIo"]
[Thu Jul 30 12:14:32.513508 2026] [core:notice] [pid 703393:tid 703572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:32.519753 2026] [security2:error] [pid 703393:tid 703572] [client 103.215.74.26:2782] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGeM637Arlr6Yb1EcGtgAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:33.252518 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:33.258783 2026] [security2:error] [pid 703393:tid 703636] [client 103.215.74.26:2260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGec637Arlr6Yb1EcGwwAAAPY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:34.024621 2026] [core:notice] [pid 703393:tid 703560] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:34.031201 2026] [security2:error] [pid 703393:tid 703560] [client 103.215.74.26:2268] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGes637Arlr6Yb1EcGzgAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:34.321257 2026] [security2:error] [pid 703393:tid 703556] [client 20.63.98.115:37996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/file.php"] [unique_id "amuGes637Arlr6Yb1EcG1QAAAKY"]
[Thu Jul 30 12:14:34.474413 2026] [core:notice] [pid 703393:tid 703474] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:34.770874 2026] [core:notice] [pid 703393:tid 703540] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:34.777294 2026] [security2:error] [pid 703393:tid 703540] [client 103.215.74.26:2278] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGes637Arlr6Yb1EcG4QAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:35.165013 2026] [security2:error] [pid 703393:tid 703562] [client 20.63.98.115:37980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/bak.php"] [unique_id "amuGe8637Arlr6Yb1EcG6AAAAKw"]
[Thu Jul 30 12:14:35.988357 2026] [core:notice] [pid 703393:tid 703487] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:36.377200 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:36.838303 2026] [security2:error] [pid 703393:tid 703538] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGfM637Arlr6Yb1EcG-gAAAJQ"]
[Thu Jul 30 12:14:37.167309 2026] [security2:error] [pid 703393:tid 703614] [client 20.63.98.115:62667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/config.php"] [unique_id "amuGfc637Arlr6Yb1EcHBgAAAOA"]
[Thu Jul 30 12:14:37.936173 2026] [security2:error] [pid 703393:tid 703616] [client 20.63.98.115:31809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amuGfc637Arlr6Yb1EcHFwAAAOI"]
[Thu Jul 30 12:14:38.677653 2026] [core:error] [pid 703393:tid 703512] (36)File name too long: [remote 173.214.181.134:51584] AH00036: access to />","sale_flash_html":""},{"attributes":{"attribute_size":"44"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N/A","display_price":209.9,"display_regular_price":209.9,"image":{"title":"8765f1ca-scaled-1.jpg","caption":"","url":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1.jpg","alt":"8765f1ca-scaled-1.jpg","src":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1-600x400.jpg","srcset":"https:/kicksity.com/wp-content/uploads/2024/08/8765f1ca-scaled-1-600x400.jpg failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/>","sale_flash_html":""},{"attributes":{"attribute_size":"44"},"availability_html":"","backorders_allowed":false,"dimensions":{"length":"","width":"","height":""},"dimensions_html":"N'), referer: https://kicksity.com/product/nike-air-jordan-4-mushroom/
[Thu Jul 30 12:14:39.235371 2026] [security2:error] [pid 703393:tid 703636] [client 3.79.134.69:12992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuGf8637Arlr6Yb1EcHKgAAAPY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:14:39.470760 2026] [security2:error] [pid 703393:tid 703515] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGfs637Arlr6Yb1EcHIwAA8Xk"]
[Thu Jul 30 12:14:39.470997 2026] [security2:error] [pid 703393:tid 703631] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGfs637Arlr6Yb1EcHIwAA8Xk"]
[Thu Jul 30 12:14:39.775410 2026] [security2:error] [pid 703393:tid 703638] [client 20.63.98.115:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-activate.php"] [unique_id "amuGf8637Arlr6Yb1EcHMgAAAPg"]
[Thu Jul 30 12:14:39.829721 2026] [core:notice] [pid 703393:tid 703605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:39.833994 2026] [security2:error] [pid 703393:tid 703605] [client 3.79.134.69:12994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGf8637Arlr6Yb1EcHMwAAANc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:14:40.500105 2026] [core:notice] [pid 703393:tid 703632] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:40.506449 2026] [security2:error] [pid 703393:tid 703632] [client 103.215.74.26:2292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGgM637Arlr6Yb1EcHQAAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:40.616226 2026] [security2:error] [pid 703393:tid 703589] [client 3.79.134.69:12998] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuGgM637Arlr6Yb1EcHSQAAAMc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:14:40.687821 2026] [security2:error] [pid 703393:tid 703536] [client 103.133.205.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGgM637Arlr6Yb1EcHSAAAAJI"], referer: http://cnpinyin.com
[Thu Jul 30 12:14:41.204266 2026] [security2:error] [pid 703393:tid 703550] [client 121.229.156.119:45888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product-category/sneaker/louis-vuitton/"] [unique_id "amuGgc637Arlr6Yb1EcHUQAAAKA"]
[Thu Jul 30 12:14:41.204396 2026] [security2:error] [pid 703393:tid 703550] [client 121.229.156.119:45888] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product-category/sneaker/louis-vuitton/"] [unique_id "amuGgc637Arlr6Yb1EcHUQAAAKA"]
[Thu Jul 30 12:14:41.257008 2026] [core:notice] [pid 703393:tid 703572] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:41.263270 2026] [security2:error] [pid 703393:tid 703572] [client 103.215.74.26:2302] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGgc637Arlr6Yb1EcHUgAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:41.365035 2026] [security2:error] [pid 703393:tid 703608] [client 20.63.98.115:57339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-file.php"] [unique_id "amuGgc637Arlr6Yb1EcHUwAAANo"]
[Thu Jul 30 12:14:41.795479 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:41.999216 2026] [core:notice] [pid 703393:tid 703590] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:42.005099 2026] [security2:error] [pid 703393:tid 703590] [client 103.215.74.26:2316] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGgc637Arlr6Yb1EcHXQAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:42.129439 2026] [security2:error] [pid 703393:tid 703542] [client 20.63.98.115:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/12.php"] [unique_id "amuGgs637Arlr6Yb1EcHYgAAAJg"]
[Thu Jul 30 12:14:42.433347 2026] [security2:error] [pid 703393:tid 703629] [client 40.77.167.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuGgM637Arlr6Yb1EcHPgAAAO8"]
[Thu Jul 30 12:14:42.707585 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:42.741076 2026] [core:notice] [pid 703393:tid 703526] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:42.747335 2026] [security2:error] [pid 703393:tid 703526] [client 103.215.74.26:2318] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGgs637Arlr6Yb1EcHbwAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:43.348306 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:61358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/epinyins.php"] [unique_id "amuGg8637Arlr6Yb1EcHeQAAAQM"]
[Thu Jul 30 12:14:43.370662 2026] [security2:error] [pid 703393:tid 703615] [client 40.77.167.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuGg8637Arlr6Yb1EcHcwAAAOE"]
[Thu Jul 30 12:14:43.483589 2026] [core:notice] [pid 703393:tid 703623] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:43.489887 2026] [security2:error] [pid 703393:tid 703623] [client 103.215.74.26:31954] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGg8637Arlr6Yb1EcHegAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:43.746454 2026] [security2:error] [pid 703393:tid 703570] [client 185.200.117.131:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuGg8637Arlr6Yb1EcHgQAAALQ"]
[Thu Jul 30 12:14:43.746567 2026] [security2:error] [pid 703393:tid 703570] [client 185.200.117.131:57732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuGg8637Arlr6Yb1EcHgQAAALQ"]
[Thu Jul 30 12:14:44.233482 2026] [core:notice] [pid 703393:tid 703562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:44.239599 2026] [security2:error] [pid 703393:tid 703562] [client 103.215.74.26:31966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGhM637Arlr6Yb1EcHhgAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:44.973274 2026] [core:notice] [pid 703393:tid 703529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:44.979513 2026] [security2:error] [pid 703393:tid 703529] [client 103.215.74.26:31980] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGhM637Arlr6Yb1EcHjwAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:45.252628 2026] [security2:error] [pid 703393:tid 703587] [client 185.200.117.131:57746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGhc637Arlr6Yb1EcHnAAAAMU"]
[Thu Jul 30 12:14:45.252733 2026] [security2:error] [pid 703393:tid 703587] [client 185.200.117.131:57746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGhc637Arlr6Yb1EcHnAAAAMU"]
[Thu Jul 30 12:14:45.352768 2026] [security2:error] [pid 703393:tid 703547] [client 185.189.112.11:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuGhc637Arlr6Yb1EcHngAAAJ0"]
[Thu Jul 30 12:14:45.352874 2026] [security2:error] [pid 703393:tid 703547] [client 185.189.112.11:50856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuGhc637Arlr6Yb1EcHngAAAJ0"]
[Thu Jul 30 12:14:45.421273 2026] [security2:error] [pid 703393:tid 703635] [client 40.77.167.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuGhc637Arlr6Yb1EcHlQAAAPU"]
[Thu Jul 30 12:14:45.702340 2026] [core:notice] [pid 703393:tid 703535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:45.712772 2026] [security2:error] [pid 703393:tid 703535] [client 103.215.74.26:31992] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGhc637Arlr6Yb1EcHpQAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:45.952084 2026] [security2:error] [pid 703393:tid 703538] [client 20.63.98.115:39120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amuGhc637Arlr6Yb1EcHqQAAAJQ"]
[Thu Jul 30 12:14:46.431421 2026] [security2:error] [pid 703393:tid 703534] [client 172.236.9.101:43223] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/api/.env"] [unique_id "amuGhs637Arlr6Yb1EcHsgAAAJA"]
[Thu Jul 30 12:14:46.727669 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/system_log.php"] [unique_id "amuGhs637Arlr6Yb1EcHtQAAAPo"]
[Thu Jul 30 12:14:47.370591 2026] [core:notice] [pid 703393:tid 703420] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:47.746290 2026] [security2:error] [pid 703393:tid 703625] [client 172.236.9.101:50165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuGhs637Arlr6Yb1EcHsQAAAOs"]
[Thu Jul 30 12:14:48.211827 2026] [security2:error] [pid 703393:tid 703642] [client 20.63.98.115:44003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuGiM637Arlr6Yb1EcHygAAAPw"]
[Thu Jul 30 12:14:49.079639 2026] [security2:error] [pid 703393:tid 703569] [client 77.75.78.165:14381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuGic637Arlr6Yb1EcH2wAAALM"]
[Thu Jul 30 12:14:49.079761 2026] [security2:error] [pid 703393:tid 703569] [client 77.75.78.165:14381] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuGic637Arlr6Yb1EcH2wAAALM"]
[Thu Jul 30 12:14:49.124842 2026] [security2:error] [pid 703393:tid 703596] [client 77.75.78.165:23829] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/contact/"] [unique_id "amuGic637Arlr6Yb1EcH3AAAAM4"]
[Thu Jul 30 12:14:49.124946 2026] [security2:error] [pid 703393:tid 703596] [client 77.75.78.165:23829] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/contact/"] [unique_id "amuGic637Arlr6Yb1EcH3AAAAM4"]
[Thu Jul 30 12:14:49.131897 2026] [security2:error] [pid 703393:tid 703454] [remote 15.235.27.14:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "spececigarette.com"] [uri "/brand/mond/"] [unique_id "amuGic637Arlr6Yb1EcH3QAA8Tw"]
[Thu Jul 30 12:14:49.132030 2026] [security2:error] [pid 703393:tid 703631] [client 15.235.27.14:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spececigarette.com"] [uri "/brand/mond/"] [unique_id "amuGic637Arlr6Yb1EcH3QAA8Tw"]
[Thu Jul 30 12:14:49.171898 2026] [security2:error] [pid 703393:tid 703641] [client 77.75.78.165:31262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuGic637Arlr6Yb1EcH3gAAAPs"]
[Thu Jul 30 12:14:49.172008 2026] [security2:error] [pid 703393:tid 703641] [client 77.75.78.165:31262] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuGic637Arlr6Yb1EcH3gAAAPs"]
[Thu Jul 30 12:14:51.161408 2026] [security2:error] [pid 703393:tid 703609] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGis637Arlr6Yb1EcIAQAAANs"]
[Thu Jul 30 12:14:51.372247 2026] [core:error] [pid 703393:tid 703601] [client 40.77.167.219:33486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:14:51.372272 2026] [core:error] [pid 703393:tid 703601] [client 40.77.167.219:33486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:14:51.523539 2026] [core:notice] [pid 703393:tid 703619] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:51.529443 2026] [security2:error] [pid 703393:tid 703619] [client 103.215.74.26:32006] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGi8637Arlr6Yb1EcIDwAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:51.827113 2026] [security2:error] [pid 703393:tid 703425] [remote 250.49.135.140:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGi8637Arlr6Yb1EcIEQAAkx8"]
[Thu Jul 30 12:14:51.827268 2026] [security2:error] [pid 703393:tid 703537] [client 250.49.135.140:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuGi8637Arlr6Yb1EcIEQAAkx8"]
[Thu Jul 30 12:14:51.862211 2026] [core:notice] [pid 703393:tid 703396] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:52.124240 2026] [security2:error] [pid 703393:tid 703649] [client 74.7.230.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.xyu.gpl.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuGjM637Arlr6Yb1EcIHQAAAQM"]
[Thu Jul 30 12:14:52.124905 2026] [security2:error] [pid 703393:tid 703631] [client 74.7.230.42:44934] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.xyu.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuGjM637Arlr6Yb1EcIGwAA8VI"]
[Thu Jul 30 12:14:52.279313 2026] [core:notice] [pid 703393:tid 703647] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:52.285403 2026] [security2:error] [pid 703393:tid 703647] [client 103.215.74.26:32012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGjM637Arlr6Yb1EcIIQAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:54.524676 2026] [security2:error] [pid 703393:tid 703480] [remote 57.141.0.16:48008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuGjs637Arlr6Yb1EcIVgABAVY"]
[Thu Jul 30 12:14:54.838190 2026] [security2:error] [pid 703393:tid 703639] [client 85.208.96.200:38878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/17/na-radio-rural-todo-sabado-das-13h-as-15h-o-paraiba-em-debate-entra-no-ar-com-o-bom-jornalismo/"] [unique_id "amuGjs637Arlr6Yb1EcIXQAAAPk"]
[Thu Jul 30 12:14:54.838302 2026] [security2:error] [pid 703393:tid 703639] [client 85.208.96.200:38878] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/17/na-radio-rural-todo-sabado-das-13h-as-15h-o-paraiba-em-debate-entra-no-ar-com-o-bom-jornalismo/"] [unique_id "amuGjs637Arlr6Yb1EcIXQAAAPk"]
[Thu Jul 30 12:14:55.711652 2026] [security2:error] [pid 703393:tid 703650] [client 20.63.98.115:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ini.php"] [unique_id "amuGj8637Arlr6Yb1EcIcgAAAQQ"]
[Thu Jul 30 12:14:56.484660 2026] [security2:error] [pid 703393:tid 703508] [remote 57.141.0.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuGkM637Arlr6Yb1EcIfgAAy3I"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=desigual&filter_materials=aluminum,carbon,denim,nylon,polyester,silicon,steel,linen&filter_size=small&rating=5&status=instock&unfilter=1
[Thu Jul 30 12:14:56.545613 2026] [security2:error] [pid 703393:tid 703518] [remote 57.141.0.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuGkM637Arlr6Yb1EcIfwAAvnw"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=desigual&filter_materials=aluminum,carbon,denim,nylon,polyester,silicon,steel,linen&filter_size=small&rating=5&status=instock&unfilter=1
[Thu Jul 30 12:14:57.148407 2026] [security2:error] [pid 703393:tid 703536] [client 47.128.121.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGkc637Arlr6Yb1EcIigAAAJI"]
[Thu Jul 30 12:14:57.462153 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:27224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ok.php"] [unique_id "amuGkc637Arlr6Yb1EcIkQAAAJY"]
[Thu Jul 30 12:14:57.865505 2026] [security2:error] [pid 703393:tid 703552] [client 188.129.154.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGkc637Arlr6Yb1EcIlwAAAKI"], referer: http://cnpinyin.com
[Thu Jul 30 12:14:58.009331 2026] [core:notice] [pid 703393:tid 703625] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:58.015791 2026] [security2:error] [pid 703393:tid 703625] [client 103.215.74.26:11450] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGks637Arlr6Yb1EcImwAAAOs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:58.142149 2026] [security2:error] [pid 703393:tid 703599] [client 213.152.187.215:45678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGks637Arlr6Yb1EcInwAAANE"]
[Thu Jul 30 12:14:58.142287 2026] [security2:error] [pid 703393:tid 703599] [client 213.152.187.215:45678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuGks637Arlr6Yb1EcInwAAANE"]
[Thu Jul 30 12:14:58.315731 2026] [core:notice] [pid 703393:tid 703546] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:58.761411 2026] [core:notice] [pid 703393:tid 703537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:58.770776 2026] [security2:error] [pid 703393:tid 703537] [client 103.215.74.26:11458] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGks637Arlr6Yb1EcIrAAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:14:59.279238 2026] [security2:error] [pid 703393:tid 703571] [client 20.63.98.115:32445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/includes/about.php"] [unique_id "amuGk8637Arlr6Yb1EcItQAAALU"]
[Thu Jul 30 12:14:59.496951 2026] [core:notice] [pid 703393:tid 703577] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:14:59.503261 2026] [security2:error] [pid 703393:tid 703577] [client 103.215.74.26:11460] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGk8637Arlr6Yb1EcIuQAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:00.269054 2026] [core:notice] [pid 703393:tid 703544] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:00.275696 2026] [security2:error] [pid 703393:tid 703544] [client 103.215.74.26:11472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGlM637Arlr6Yb1EcIwgAAAJo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:00.473309 2026] [security2:error] [pid 703393:tid 703611] [client 185.191.171.8:53030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/12/setor-de-servicos-recua-02-em-fevereiro-e-tem-2a-queda-seguida/"] [unique_id "amuGlM637Arlr6Yb1EcIxgAAAN0"]
[Thu Jul 30 12:15:00.473484 2026] [security2:error] [pid 703393:tid 703611] [client 185.191.171.8:53030] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/12/setor-de-servicos-recua-02-em-fevereiro-e-tem-2a-queda-seguida/"] [unique_id "amuGlM637Arlr6Yb1EcIxgAAAN0"]
[Thu Jul 30 12:15:00.860944 2026] [security2:error] [pid 703393:tid 703414] [remote 57.141.0.14:32802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuGlM637Arlr6Yb1EcIzAAAnBQ"]
[Thu Jul 30 12:15:01.015255 2026] [core:notice] [pid 703393:tid 703574] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:01.020942 2026] [security2:error] [pid 703393:tid 703574] [client 103.215.74.26:11484] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGlc637Arlr6Yb1EcI0gAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:01.773560 2026] [core:notice] [pid 703393:tid 703647] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:01.779912 2026] [security2:error] [pid 703393:tid 703647] [client 103.215.74.26:11488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGlc637Arlr6Yb1EcI5AAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:02.506259 2026] [core:notice] [pid 703393:tid 703579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:02.512592 2026] [security2:error] [pid 703393:tid 703579] [client 103.215.74.26:11498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGls637Arlr6Yb1EcI8AAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:02.818411 2026] [security2:error] [pid 703393:tid 703642] [client 216.244.66.236:54594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGls637Arlr6Yb1EcI-AAAAPw"]
[Thu Jul 30 12:15:02.818523 2026] [security2:error] [pid 703393:tid 703642] [client 216.244.66.236:54594] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGls637Arlr6Yb1EcI-AAAAPw"]
[Thu Jul 30 12:15:02.828786 2026] [security2:error] [pid 703393:tid 703615] [client 216.244.66.236:54608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGls637Arlr6Yb1EcI-QAAAOE"]
[Thu Jul 30 12:15:02.828877 2026] [security2:error] [pid 703393:tid 703615] [client 216.244.66.236:54608] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuGls637Arlr6Yb1EcI-QAAAOE"]
[Thu Jul 30 12:15:03.266171 2026] [core:notice] [pid 703393:tid 703620] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:03.276522 2026] [security2:error] [pid 703393:tid 703620] [client 103.215.74.26:48050] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGl8637Arlr6Yb1EcJAwAAAOY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:03.372447 2026] [core:notice] [pid 703393:tid 703452] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:03.769380 2026] [core:notice] [pid 703393:tid 703423] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:04.002048 2026] [core:notice] [pid 703393:tid 703558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:04.008266 2026] [security2:error] [pid 703393:tid 703558] [client 103.215.74.26:48052] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGmM637Arlr6Yb1EcJGAAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:04.294513 2026] [autoindex:error] [pid 703393:tid 703582] [client 20.63.98.115:32386] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:15:04.497830 2026] [security2:error] [pid 703393:tid 703647] [client 20.63.98.115:32386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-configs.php"] [unique_id "amuGmM637Arlr6Yb1EcJHwAAAQE"]
[Thu Jul 30 12:15:04.739558 2026] [core:notice] [pid 703393:tid 703585] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:04.745269 2026] [security2:error] [pid 703393:tid 703585] [client 103.215.74.26:48056] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuGmM637Arlr6Yb1EcJJwAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:15:05.450946 2026] [core:notice] [pid 703393:tid 703564] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:07.147927 2026] [security2:error] [pid 703393:tid 703559] [client 74.7.244.10:43740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.cwf.djb.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuGm8637Arlr6Yb1EcJVAAAAKk"]
[Thu Jul 30 12:15:07.224104 2026] [security2:error] [pid 703393:tid 703596] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGms637Arlr6Yb1EcJTQAAAM4"]
[Thu Jul 30 12:15:09.354234 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:53840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/01.php"] [unique_id "amuGnc637Arlr6Yb1EcJeQAAAKc"]
[Thu Jul 30 12:15:09.390158 2026] [security2:error] [pid 703393:tid 703478] [remote 47.128.27.80:32722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/search/Nike/page/107/"] [unique_id "amuGnc637Arlr6Yb1EcJfQAArFQ"]
[Thu Jul 30 12:15:09.710969 2026] [security2:error] [pid 703393:tid 703480] [remote 57.141.0.7:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amuGnc637Arlr6Yb1EcJkQAA8lY"]
[Thu Jul 30 12:15:10.439752 2026] [security2:error] [pid 703393:tid 703582] [client 20.63.98.115:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amuGns637Arlr6Yb1EcJpwAAAMA"]
[Thu Jul 30 12:15:12.385038 2026] [security2:error] [pid 703393:tid 703650] [client 20.63.98.115:38203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amuGoM637Arlr6Yb1EcJzgAAAQQ"]
[Thu Jul 30 12:15:12.856173 2026] [security2:error] [pid 703393:tid 703511] [remote 57.141.0.15:33424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/3981330618/feed/rss2/"] [unique_id "amuGoM637Arlr6Yb1EcJ2AAA4nU"]
[Thu Jul 30 12:15:13.213507 2026] [security2:error] [pid 703393:tid 703614] [client 20.63.98.115:62057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuGoc637Arlr6Yb1EcJ3AAAAOA"]
[Thu Jul 30 12:15:15.263139 2026] [security2:error] [pid 703393:tid 703398] [remote 74.7.241.59:57000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuGo8637Arlr6Yb1EcJ9wAArAQ"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:15:15.331772 2026] [security2:error] [pid 703393:tid 703439] [remote 74.7.241.60:56254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuGo8637Arlr6Yb1EcJ-wAAhi0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:15:15.941490 2026] [security2:error] [pid 703393:tid 703647] [client 20.63.98.115:47263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/db.php"] [unique_id "amuGo8637Arlr6Yb1EcKBgAAAQE"]
[Thu Jul 30 12:15:16.912820 2026] [security2:error] [pid 703393:tid 703574] [client 209.35.163.56:55499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuGpM637Arlr6Yb1EcKCwAAuCI"]
[Thu Jul 30 12:15:17.003525 2026] [security2:error] [pid 703393:tid 703589] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGpM637Arlr6Yb1EcKEgAAAMc"]
[Thu Jul 30 12:15:17.373753 2026] [security2:error] [pid 703393:tid 703549] [client 20.63.98.115:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/pages.php"] [unique_id "amuGpc637Arlr6Yb1EcKIQAAAJ8"]
[Thu Jul 30 12:15:18.294712 2026] [security2:error] [pid 703393:tid 703526] [client 20.63.98.115:47289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/admin.php"] [unique_id "amuGps637Arlr6Yb1EcKLgAAAIg"]
[Thu Jul 30 12:15:19.347147 2026] [core:error] [pid 703393:tid 703416] [remote 216.73.216.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:19.347172 2026] [core:error] [pid 703393:tid 703416] [remote 216.73.216.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:19.865412 2026] [security2:error] [pid 703393:tid 703583] [client 20.63.98.115:61941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-load.php"] [unique_id "amuGp8637Arlr6Yb1EcKTQAAAME"]
[Thu Jul 30 12:15:19.972762 2026] [core:error] [pid 703393:tid 703421] [remote 216.73.216.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:19.972785 2026] [core:error] [pid 703393:tid 703421] [remote 216.73.216.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:20.267192 2026] [security2:error] [pid 703393:tid 703496] [remote 216.73.216.152:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuGqM637Arlr6Yb1EcKWAAA5WY"]
[Thu Jul 30 12:15:20.315566 2026] [security2:error] [pid 703393:tid 703590] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGp8637Arlr6Yb1EcKTAAAAMg"]
[Thu Jul 30 12:15:20.745094 2026] [security2:error] [pid 703393:tid 703544] [client 20.63.98.115:51799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/as/function.php"] [unique_id "amuGqM637Arlr6Yb1EcKZAAAAJo"]
[Thu Jul 30 12:15:22.212805 2026] [security2:error] [pid 703393:tid 703538] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thesounddepot.com"] [uri "/index.php"] [unique_id "amuGp8637Arlr6Yb1EcKQgAAlDA"]
[Thu Jul 30 12:15:22.903056 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:62041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/filter.php"] [unique_id "amuGqs637Arlr6Yb1EcKmAAAAJY"]
[Thu Jul 30 12:15:24.496679 2026] [core:notice] [pid 703393:tid 703527] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:25.079818 2026] [security2:error] [pid 703393:tid 703532] [client 172.237.109.114:21980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/alseermarine.com:443.sql"] [unique_id "amuGrc637Arlr6Yb1EcKywAAAI4"]
[Thu Jul 30 12:15:25.088422 2026] [security2:error] [pid 703393:tid 703579] [client 172.237.109.114:18579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/database.sql"] [unique_id "amuGrc637Arlr6Yb1EcKzAAAAL0"]
[Thu Jul 30 12:15:25.103756 2026] [security2:error] [pid 703393:tid 703626] [client 172.237.109.114:26058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backup.sql"] [unique_id "amuGrc637Arlr6Yb1EcKzQAAAOw"]
[Thu Jul 30 12:15:25.121854 2026] [security2:error] [pid 703393:tid 703574] [client 172.237.109.114:6118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/database.sql"] [unique_id "amuGrc637Arlr6Yb1EcKzgAAALg"]
[Thu Jul 30 12:15:25.122290 2026] [security2:error] [pid 703393:tid 703637] [client 172.237.109.114:63687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/db.sql"] [unique_id "amuGrc637Arlr6Yb1EcKzwAAAPc"]
[Thu Jul 30 12:15:25.123300 2026] [security2:error] [pid 703393:tid 703644] [client 172.237.109.114:44734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/alseermarine.com:443.sql"] [unique_id "amuGrc637Arlr6Yb1EcK0AAAAP4"]
[Thu Jul 30 12:15:25.123800 2026] [security2:error] [pid 703393:tid 703624] [client 172.237.109.114:62415] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/backups/database.sql"] [unique_id "amuGrc637Arlr6Yb1EcK0QAAAOo"]
[Thu Jul 30 12:15:25.149290 2026] [security2:error] [pid 703393:tid 703612] [client 172.237.109.114:54317] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "amuGrc637Arlr6Yb1EcK0gAAAN4"]
[Thu Jul 30 12:15:25.149683 2026] [security2:error] [pid 703393:tid 703531] [client 172.237.109.114:54819] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/database.sql"] [unique_id "amuGrc637Arlr6Yb1EcK0wAAAI0"]
[Thu Jul 30 12:15:25.150678 2026] [security2:error] [pid 703393:tid 703605] [client 172.237.109.114:51180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/mysql.sql"] [unique_id "amuGrc637Arlr6Yb1EcK1AAAANc"]
[Thu Jul 30 12:15:25.150842 2026] [security2:error] [pid 703393:tid 703524] [client 172.237.109.114:56885] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/dump.sql"] [unique_id "amuGrc637Arlr6Yb1EcK1QAAAIY"]
[Thu Jul 30 12:15:25.151098 2026] [security2:error] [pid 703393:tid 703553] [client 172.237.109.114:28741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "amuGrc637Arlr6Yb1EcK1gAAAKM"]
[Thu Jul 30 12:15:25.160747 2026] [core:notice] [pid 703393:tid 703546] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:25.826262 2026] [core:notice] [pid 703393:tid 703523] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:26.593659 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:57107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/he.php"] [unique_id "amuGrs637Arlr6Yb1EcK8QAAAKU"]
[Thu Jul 30 12:15:27.656422 2026] [security2:error] [pid 703393:tid 703532] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGr8637Arlr6Yb1EcK-QAAjnM"]
[Thu Jul 30 12:15:28.532484 2026] [security2:error] [pid 703393:tid 703604] [client 20.63.98.115:60815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/setup-config.php"] [unique_id "amuGsM637Arlr6Yb1EcLEAAAANY"]
[Thu Jul 30 12:15:29.604566 2026] [security2:error] [pid 703393:tid 703595] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuGsc637Arlr6Yb1EcLHQAAAM0"]
[Thu Jul 30 12:15:29.604679 2026] [security2:error] [pid 703393:tid 703595] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuGsc637Arlr6Yb1EcLHQAAAM0"]
[Thu Jul 30 12:15:30.110764 2026] [security2:error] [pid 703393:tid 703541] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuGss637Arlr6Yb1EcLKAAAAJc"]
[Thu Jul 30 12:15:30.110848 2026] [security2:error] [pid 703393:tid 703541] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuGss637Arlr6Yb1EcLKAAAAJc"]
[Thu Jul 30 12:15:30.204474 2026] [security2:error] [pid 703393:tid 703589] [client 20.63.98.115:60824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amuGss637Arlr6Yb1EcLKwAAAMc"]
[Thu Jul 30 12:15:30.518249 2026] [core:notice] [pid 703393:tid 703530] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:30.630717 2026] [security2:error] [pid 703393:tid 703553] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/bootstrap.php"] [unique_id "amuGss637Arlr6Yb1EcLMwAAAKM"]
[Thu Jul 30 12:15:30.630825 2026] [security2:error] [pid 703393:tid 703553] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/bootstrap.php"] [unique_id "amuGss637Arlr6Yb1EcLMwAAAKM"]
[Thu Jul 30 12:15:31.131740 2026] [security2:error] [pid 703393:tid 703590] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-blog-header.php"] [unique_id "amuGs8637Arlr6Yb1EcLPAAAAMg"]
[Thu Jul 30 12:15:31.131846 2026] [security2:error] [pid 703393:tid 703590] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-blog-header.php"] [unique_id "amuGs8637Arlr6Yb1EcLPAAAAMg"]
[Thu Jul 30 12:15:31.155350 2026] [security2:error] [pid 703393:tid 703542] [client 20.63.98.115:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuGs8637Arlr6Yb1EcLPwAAAJg"]
[Thu Jul 30 12:15:31.685050 2026] [security2:error] [pid 703393:tid 703582] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-load.php"] [unique_id "amuGs8637Arlr6Yb1EcLRwAAAMA"]
[Thu Jul 30 12:15:31.685137 2026] [security2:error] [pid 703393:tid 703582] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-load.php"] [unique_id "amuGs8637Arlr6Yb1EcLRwAAAMA"]
[Thu Jul 30 12:15:32.238584 2026] [security2:error] [pid 703393:tid 703527] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/edit.php"] [unique_id "amuGtM637Arlr6Yb1EcLUgAAAIk"]
[Thu Jul 30 12:15:32.238693 2026] [security2:error] [pid 703393:tid 703527] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/edit.php"] [unique_id "amuGtM637Arlr6Yb1EcLUgAAAIk"]
[Thu Jul 30 12:15:32.753534 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/cgi-bin"] [unique_id "amuGtM637Arlr6Yb1EcLWwAAAJU"]
[Thu Jul 30 12:15:33.150436 2026] [security2:error] [pid 703393:tid 703550] [client 20.63.98.115:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "amuGtc637Arlr6Yb1EcLXwAAAKA"]
[Thu Jul 30 12:15:33.417864 2026] [security2:error] [pid 703393:tid 703592] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/mah.php"] [unique_id "amuGtc637Arlr6Yb1EcLZwAAAMo"]
[Thu Jul 30 12:15:33.417966 2026] [security2:error] [pid 703393:tid 703592] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/mah.php"] [unique_id "amuGtc637Arlr6Yb1EcLZwAAAMo"]
[Thu Jul 30 12:15:33.673283 2026] [core:notice] [pid 703393:tid 703415] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:33.681829 2026] [security2:error] [pid 703393:tid 703632] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/archive.php"] [unique_id "amuGtc637Arlr6Yb1EcLaQAAAPI"]
[Thu Jul 30 12:15:33.681913 2026] [security2:error] [pid 703393:tid 703632] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/archive.php"] [unique_id "amuGtc637Arlr6Yb1EcLaQAAAPI"]
[Thu Jul 30 12:15:33.985311 2026] [security2:error] [pid 703393:tid 703565] [client 20.63.98.115:54539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/atomlib.php"] [unique_id "amuGtc637Arlr6Yb1EcLcAAAAK8"]
[Thu Jul 30 12:15:34.167151 2026] [security2:error] [pid 703393:tid 703542] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/hosty.php"] [unique_id "amuGts637Arlr6Yb1EcLcQAAAJg"]
[Thu Jul 30 12:15:34.167263 2026] [security2:error] [pid 703393:tid 703542] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/hosty.php"] [unique_id "amuGts637Arlr6Yb1EcLcQAAAJg"]
[Thu Jul 30 12:15:34.735484 2026] [security2:error] [pid 703393:tid 703540] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/Diff/"] [unique_id "amuGts637Arlr6Yb1EcLeQAAAJY"]
[Thu Jul 30 12:15:35.289367 2026] [security2:error] [pid 703393:tid 703628] [client 20.63.98.115:20653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuGt8637Arlr6Yb1EcLhgAAAO4"]
[Thu Jul 30 12:15:35.749160 2026] [security2:error] [pid 703393:tid 703618] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/admin.php"] [unique_id "amuGt8637Arlr6Yb1EcLjgAAAOQ"]
[Thu Jul 30 12:15:35.749299 2026] [security2:error] [pid 703393:tid 703618] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/admin.php"] [unique_id "amuGt8637Arlr6Yb1EcLjgAAAOQ"]
[Thu Jul 30 12:15:36.301604 2026] [security2:error] [pid 703393:tid 703612] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/av.php"] [unique_id "amuGuM637Arlr6Yb1EcLmQAAAN4"]
[Thu Jul 30 12:15:36.301707 2026] [security2:error] [pid 703393:tid 703612] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/av.php"] [unique_id "amuGuM637Arlr6Yb1EcLmQAAAN4"]
[Thu Jul 30 12:15:36.788664 2026] [security2:error] [pid 703393:tid 703649] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/shell.php"] [unique_id "amuGuM637Arlr6Yb1EcLngAAAQM"]
[Thu Jul 30 12:15:36.788783 2026] [security2:error] [pid 703393:tid 703649] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/shell.php"] [unique_id "amuGuM637Arlr6Yb1EcLngAAAQM"]
[Thu Jul 30 12:15:36.973000 2026] [security2:error] [pid 703393:tid 703594] [client 172.237.109.114:58046] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/WEB_VMS/LEVEL15/"] [unique_id "amuGuM637Arlr6Yb1EcLowAAAMw"]
[Thu Jul 30 12:15:37.251531 2026] [core:notice] [pid 703393:tid 703420] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:37.330466 2026] [security2:error] [pid 703393:tid 703591] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/storage/index.php"] [unique_id "amuGuc637Arlr6Yb1EcLqwAAAMk"]
[Thu Jul 30 12:15:37.330595 2026] [security2:error] [pid 703393:tid 703591] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/storage/index.php"] [unique_id "amuGuc637Arlr6Yb1EcLqwAAAMk"]
[Thu Jul 30 12:15:37.870378 2026] [security2:error] [pid 703393:tid 703585] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/w.php"] [unique_id "amuGuc637Arlr6Yb1EcLsgAAAMM"]
[Thu Jul 30 12:15:37.870469 2026] [security2:error] [pid 703393:tid 703585] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/w.php"] [unique_id "amuGuc637Arlr6Yb1EcLsgAAAMM"]
[Thu Jul 30 12:15:37.921739 2026] [core:notice] [pid 703393:tid 703571] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:37.996436 2026] [core:notice] [pid 703393:tid 703576] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:38.369209 2026] [security2:error] [pid 703393:tid 703600] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/jp.php"] [unique_id "amuGus637Arlr6Yb1EcLvAAAANI"]
[Thu Jul 30 12:15:38.369294 2026] [security2:error] [pid 703393:tid 703600] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/jp.php"] [unique_id "amuGus637Arlr6Yb1EcLvAAAANI"]
[Thu Jul 30 12:15:38.675672 2026] [security2:error] [pid 703393:tid 703575] [client 20.63.98.115:63377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gebase.php"] [unique_id "amuGus637Arlr6Yb1EcLwAAAALk"]
[Thu Jul 30 12:15:38.874971 2026] [security2:error] [pid 703393:tid 703642] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/php.ini"] [unique_id "amuGus637Arlr6Yb1EcLxQAAAPw"]
[Thu Jul 30 12:15:39.139596 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws77.php"] [unique_id "amuGu8637Arlr6Yb1EcLyQAAANc"]
[Thu Jul 30 12:15:39.139717 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws77.php"] [unique_id "amuGu8637Arlr6Yb1EcLyQAAANc"]
[Thu Jul 30 12:15:39.680073 2026] [security2:error] [pid 703393:tid 703621] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/blass.php"] [unique_id "amuGu8637Arlr6Yb1EcL0wAAAOc"]
[Thu Jul 30 12:15:39.680181 2026] [security2:error] [pid 703393:tid 703621] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/blass.php"] [unique_id "amuGu8637Arlr6Yb1EcL0wAAAOc"]
[Thu Jul 30 12:15:39.719764 2026] [security2:error] [pid 703393:tid 703546] [client 20.63.98.115:20616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/xl.php"] [unique_id "amuGu8637Arlr6Yb1EcL1AAAAJw"]
[Thu Jul 30 12:15:40.519631 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:63400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/2.php"] [unique_id "amuGvM637Arlr6Yb1EcL4QAAAKc"]
[Thu Jul 30 12:15:40.567793 2026] [security2:error] [pid 703393:tid 703609] [client 89.238.167.166:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuGvM637Arlr6Yb1EcL4gAAANs"]
[Thu Jul 30 12:15:40.567891 2026] [security2:error] [pid 703393:tid 703609] [client 89.238.167.166:51896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuGvM637Arlr6Yb1EcL4gAAANs"]
[Thu Jul 30 12:15:40.973397 2026] [security2:error] [pid 703393:tid 703440] [remote 216.73.216.152:8129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuGvM637Arlr6Yb1EcL6AAAvC4"]
[Thu Jul 30 12:15:41.576868 2026] [security2:error] [pid 703393:tid 703572] [client 20.63.98.115:60820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/baxa1.php"] [unique_id "amuGvc637Arlr6Yb1EcL9AAAALY"]
[Thu Jul 30 12:15:41.669101 2026] [core:notice] [pid 703393:tid 703635] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:42.503458 2026] [security2:error] [pid 703393:tid 703535] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-info.php"] [unique_id "amuGvs637Arlr6Yb1EcMAAAAAJE"]
[Thu Jul 30 12:15:42.503589 2026] [security2:error] [pid 703393:tid 703535] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-info.php"] [unique_id "amuGvs637Arlr6Yb1EcMAAAAAJE"]
[Thu Jul 30 12:15:42.915142 2026] [security2:error] [pid 703393:tid 703594] [client 117.5.152.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuGvs637Arlr6Yb1EcMEgAAAMw"]
[Thu Jul 30 12:15:43.076610 2026] [security2:error] [pid 703393:tid 703567] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/CDX1.php"] [unique_id "amuGv8637Arlr6Yb1EcMFQAAALE"]
[Thu Jul 30 12:15:43.076744 2026] [security2:error] [pid 703393:tid 703567] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/CDX1.php"] [unique_id "amuGv8637Arlr6Yb1EcMFQAAALE"]
[Thu Jul 30 12:15:43.617769 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wpc.php"] [unique_id "amuGv8637Arlr6Yb1EcMHAAAAKg"]
[Thu Jul 30 12:15:43.617862 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wpc.php"] [unique_id "amuGv8637Arlr6Yb1EcMHAAAAKg"]
[Thu Jul 30 12:15:44.096565 2026] [security2:error] [pid 703393:tid 703576] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/jga.php"] [unique_id "amuGwM637Arlr6Yb1EcMIAAAALo"]
[Thu Jul 30 12:15:44.096677 2026] [security2:error] [pid 703393:tid 703576] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/jga.php"] [unique_id "amuGwM637Arlr6Yb1EcMIAAAALo"]
[Thu Jul 30 12:15:44.594213 2026] [security2:error] [pid 703393:tid 703579] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/666.php"] [unique_id "amuGwM637Arlr6Yb1EcMKwAAAL0"]
[Thu Jul 30 12:15:44.594326 2026] [security2:error] [pid 703393:tid 703579] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/666.php"] [unique_id "amuGwM637Arlr6Yb1EcMKwAAAL0"]
[Thu Jul 30 12:15:44.769642 2026] [core:notice] [pid 703393:tid 703476] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:44.805033 2026] [security2:error] [pid 703393:tid 703583] [client 20.63.98.115:63409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/settings.php"] [unique_id "amuGwM637Arlr6Yb1EcMMAAAAME"]
[Thu Jul 30 12:15:45.136422 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/htaccess.php"] [unique_id "amuGwc637Arlr6Yb1EcMNwAAANc"]
[Thu Jul 30 12:15:45.136554 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/htaccess.php"] [unique_id "amuGwc637Arlr6Yb1EcMNwAAANc"]
[Thu Jul 30 12:15:45.523884 2026] [core:notice] [pid 703393:tid 703620] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:45.661723 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/m.php"] [unique_id "amuGwc637Arlr6Yb1EcMSgAAAPQ"]
[Thu Jul 30 12:15:45.661821 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/m.php"] [unique_id "amuGwc637Arlr6Yb1EcMSgAAAPQ"]
[Thu Jul 30 12:15:46.157409 2026] [security2:error] [pid 703393:tid 703531] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file.php"] [unique_id "amuGws637Arlr6Yb1EcMUgAAAI0"]
[Thu Jul 30 12:15:46.157530 2026] [security2:error] [pid 703393:tid 703531] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file.php"] [unique_id "amuGws637Arlr6Yb1EcMUgAAAI0"]
[Thu Jul 30 12:15:46.407776 2026] [security2:error] [pid 703393:tid 703631] [client 85.208.96.193:26084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/25/bancos-fecham-no-carnaval-e-reabrem-na-quarta-feira-de-cinzas/"] [unique_id "amuGws637Arlr6Yb1EcMVwAAAPE"]
[Thu Jul 30 12:15:46.407936 2026] [security2:error] [pid 703393:tid 703631] [client 85.208.96.193:26084] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/25/bancos-fecham-no-carnaval-e-reabrem-na-quarta-feira-de-cinzas/"] [unique_id "amuGws637Arlr6Yb1EcMVwAAAPE"]
[Thu Jul 30 12:15:46.669620 2026] [security2:error] [pid 703393:tid 703625] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/.dj/index.php"] [unique_id "amuGws637Arlr6Yb1EcMXQAAAOs"]
[Thu Jul 30 12:15:46.669748 2026] [security2:error] [pid 703393:tid 703625] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/.dj/index.php"] [unique_id "amuGws637Arlr6Yb1EcMXQAAAOs"]
[Thu Jul 30 12:15:47.172137 2026] [security2:error] [pid 703393:tid 703595] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-admin/maint/index.php"] [unique_id "amuGw8637Arlr6Yb1EcMZgAAAM0"]
[Thu Jul 30 12:15:47.172290 2026] [security2:error] [pid 703393:tid 703595] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-admin/maint/index.php"] [unique_id "amuGw8637Arlr6Yb1EcMZgAAAM0"]
[Thu Jul 30 12:15:47.671069 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/pages.php"] [unique_id "amuGw8637Arlr6Yb1EcMcAAAANc"]
[Thu Jul 30 12:15:47.671218 2026] [security2:error] [pid 703393:tid 703605] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/pages.php"] [unique_id "amuGw8637Arlr6Yb1EcMcAAAANc"]
[Thu Jul 30 12:15:47.759991 2026] [security2:error] [pid 703393:tid 703589] [client 46.6.123.252:61208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGw8637Arlr6Yb1EcMbgAAAMc"], referer: http://pkf.jo
[Thu Jul 30 12:15:47.926782 2026] [security2:error] [pid 703393:tid 703638] [client 154.160.2.71:5939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGw8637Arlr6Yb1EcMbwAAAPg"], referer: http://pkf.jo
[Thu Jul 30 12:15:48.150929 2026] [security2:error] [pid 703393:tid 703586] [client 223.109.252.236:41570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/x-travis-scott-x-nike-air-jordan-1-low-black/"] [unique_id "amuGxM637Arlr6Yb1EcMeAAAAMQ"]
[Thu Jul 30 12:15:48.151060 2026] [security2:error] [pid 703393:tid 703586] [client 223.109.252.236:41570] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/x-travis-scott-x-nike-air-jordan-1-low-black/"] [unique_id "amuGxM637Arlr6Yb1EcMeAAAAMQ"]
[Thu Jul 30 12:15:48.199026 2026] [security2:error] [pid 703393:tid 703630] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/adminfuns.php"] [unique_id "amuGxM637Arlr6Yb1EcMeQAAAPA"]
[Thu Jul 30 12:15:48.199137 2026] [security2:error] [pid 703393:tid 703630] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/adminfuns.php"] [unique_id "amuGxM637Arlr6Yb1EcMeQAAAPA"]
[Thu Jul 30 12:15:48.427265 2026] [security2:error] [pid 703393:tid 703565] [client 41.105.24.105:42582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGxM637Arlr6Yb1EcMdwAAAK8"], referer: http://pkf.jo
[Thu Jul 30 12:15:48.718331 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/aa.php"] [unique_id "amuGxM637Arlr6Yb1EcMgQAAAJA"]
[Thu Jul 30 12:15:48.718450 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/aa.php"] [unique_id "amuGxM637Arlr6Yb1EcMgQAAAJA"]
[Thu Jul 30 12:15:48.724670 2026] [security2:error] [pid 703393:tid 703641] [client 196.191.240.134:37590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGxM637Arlr6Yb1EcMfAAAAPs"], referer: http://pkf.jo
[Thu Jul 30 12:15:49.266307 2026] [security2:error] [pid 703393:tid 703618] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/Diff/Engine/"] [unique_id "amuGxc637Arlr6Yb1EcMiQAAAOQ"]
[Thu Jul 30 12:15:49.331347 2026] [core:notice] [pid 703393:tid 703426] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:15:49.432294 2026] [security2:error] [pid 703393:tid 703648] [client 20.63.98.115:63382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/dropdown.php"] [unique_id "amuGxc637Arlr6Yb1EcMiwAAAQI"]
[Thu Jul 30 12:15:49.520244 2026] [security2:error] [pid 703393:tid 703529] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/classwithtostring.php"] [unique_id "amuGxc637Arlr6Yb1EcMjwAAAIs"]
[Thu Jul 30 12:15:49.520356 2026] [security2:error] [pid 703393:tid 703529] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/classwithtostring.php"] [unique_id "amuGxc637Arlr6Yb1EcMjwAAAIs"]
[Thu Jul 30 12:15:50.029382 2026] [security2:error] [pid 703393:tid 703589] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/about.php"] [unique_id "amuGxs637Arlr6Yb1EcMlgAAAMc"]
[Thu Jul 30 12:15:50.029487 2026] [security2:error] [pid 703393:tid 703589] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/about.php"] [unique_id "amuGxs637Arlr6Yb1EcMlgAAAMc"]
[Thu Jul 30 12:15:50.521064 2026] [security2:error] [pid 703393:tid 703586] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/goods.php"] [unique_id "amuGxs637Arlr6Yb1EcMoAAAAMQ"]
[Thu Jul 30 12:15:50.521175 2026] [security2:error] [pid 703393:tid 703586] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/goods.php"] [unique_id "amuGxs637Arlr6Yb1EcMoAAAAMQ"]
[Thu Jul 30 12:15:51.047301 2026] [security2:error] [pid 703393:tid 703646] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/php8.php"] [unique_id "amuGx8637Arlr6Yb1EcMqAAAAQA"]
[Thu Jul 30 12:15:51.047403 2026] [security2:error] [pid 703393:tid 703646] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/php8.php"] [unique_id "amuGx8637Arlr6Yb1EcMqAAAAQA"]
[Thu Jul 30 12:15:51.069789 2026] [autoindex:error] [pid 703393:tid 703547] [client 20.63.98.115:21112] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:15:51.273267 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:21112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin.php"] [unique_id "amuGx8637Arlr6Yb1EcMrQAAAKc"]
[Thu Jul 30 12:15:51.592370 2026] [security2:error] [pid 703393:tid 703571] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/info.php"] [unique_id "amuGx8637Arlr6Yb1EcMsQAAALU"]
[Thu Jul 30 12:15:51.592469 2026] [security2:error] [pid 703393:tid 703571] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/info.php"] [unique_id "amuGx8637Arlr6Yb1EcMsQAAALU"]
[Thu Jul 30 12:15:52.075568 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:60266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/buy.php"] [unique_id "amuGyM637Arlr6Yb1EcMuAAAAOg"]
[Thu Jul 30 12:15:52.142759 2026] [security2:error] [pid 703393:tid 703648] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/class-t.api.php"] [unique_id "amuGyM637Arlr6Yb1EcMuQAAAQI"]
[Thu Jul 30 12:15:52.142871 2026] [security2:error] [pid 703393:tid 703648] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/class-t.api.php"] [unique_id "amuGyM637Arlr6Yb1EcMuQAAAQI"]
[Thu Jul 30 12:15:52.636663 2026] [security2:error] [pid 703393:tid 703538] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/simple.php"] [unique_id "amuGyM637Arlr6Yb1EcMwAAAAJQ"]
[Thu Jul 30 12:15:52.636760 2026] [security2:error] [pid 703393:tid 703538] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/simple.php"] [unique_id "amuGyM637Arlr6Yb1EcMwAAAAJQ"]
[Thu Jul 30 12:15:52.917460 2026] [security2:error] [pid 703393:tid 703608] [client 20.63.98.115:54548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mini.php"] [unique_id "amuGyM637Arlr6Yb1EcMxAAAANo"]
[Thu Jul 30 12:15:53.163240 2026] [security2:error] [pid 703393:tid 703636] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ioxi-o.php"] [unique_id "amuGyc637Arlr6Yb1EcMyAAAAPY"]
[Thu Jul 30 12:15:53.163351 2026] [security2:error] [pid 703393:tid 703636] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ioxi-o.php"] [unique_id "amuGyc637Arlr6Yb1EcMyAAAAPY"]
[Thu Jul 30 12:15:53.725220 2026] [security2:error] [pid 703393:tid 703524] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/wp-admin"] [unique_id "amuGyc637Arlr6Yb1EcM0AAAAIY"]
[Thu Jul 30 12:15:53.987408 2026] [security2:error] [pid 703393:tid 703546] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp.php"] [unique_id "amuGyc637Arlr6Yb1EcM1AAAAJw"]
[Thu Jul 30 12:15:53.987516 2026] [security2:error] [pid 703393:tid 703546] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp.php"] [unique_id "amuGyc637Arlr6Yb1EcM1AAAAJw"]
[Thu Jul 30 12:15:54.736909 2026] [security2:error] [pid 703393:tid 703614] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGys637Arlr6Yb1EcM6QAA4H4"]
[Thu Jul 30 12:15:55.083194 2026] [security2:error] [pid 703393:tid 703615] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file2.php"] [unique_id "amuGy8637Arlr6Yb1EcM9wAAAOE"]
[Thu Jul 30 12:15:55.083321 2026] [security2:error] [pid 703393:tid 703615] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file2.php"] [unique_id "amuGy8637Arlr6Yb1EcM9wAAAOE"]
[Thu Jul 30 12:15:55.285874 2026] [security2:error] [pid 703393:tid 703562] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGys637Arlr6Yb1EcM8AAArC0"]
[Thu Jul 30 12:15:55.615436 2026] [security2:error] [pid 703393:tid 703541] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/images/class-config.php"] [unique_id "amuGy8637Arlr6Yb1EcNCQAAAJc"]
[Thu Jul 30 12:15:55.615558 2026] [security2:error] [pid 703393:tid 703541] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/images/class-config.php"] [unique_id "amuGy8637Arlr6Yb1EcNCQAAAJc"]
[Thu Jul 30 12:15:55.892265 2026] [security2:error] [pid 703393:tid 703635] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuGy8637Arlr6Yb1EcM_gAAAPU"]
[Thu Jul 30 12:15:56.166791 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amuGzM637Arlr6Yb1EcNGQAAAPQ"]
[Thu Jul 30 12:15:56.166908 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amuGzM637Arlr6Yb1EcNGQAAAPQ"]
[Thu Jul 30 12:15:56.167014 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amuGzM637Arlr6Yb1EcNGQAAAPQ"]
[Thu Jul 30 12:15:56.311451 2026] [security2:error] [pid 703393:tid 703603] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuGy8637Arlr6Yb1EcM-AAA1RU"]
[Thu Jul 30 12:15:56.653985 2026] [core:error] [pid 703393:tid 703645] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:56.654008 2026] [core:error] [pid 703393:tid 703645] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:15:56.666733 2026] [security2:error] [pid 703393:tid 703632] [client 20.63.98.115:60235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cd.php"] [unique_id "amuGzM637Arlr6Yb1EcNJQAAAPI"]
[Thu Jul 30 12:15:56.695696 2026] [security2:error] [pid 703393:tid 703621] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/222.php"] [unique_id "amuGzM637Arlr6Yb1EcNJgAAAOc"]
[Thu Jul 30 12:15:56.695801 2026] [security2:error] [pid 703393:tid 703621] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/222.php"] [unique_id "amuGzM637Arlr6Yb1EcNJgAAAOc"]
[Thu Jul 30 12:15:57.199890 2026] [security2:error] [pid 703393:tid 703596] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/themes.php"] [unique_id "amuGzc637Arlr6Yb1EcNNQAAAM4"]
[Thu Jul 30 12:15:57.200032 2026] [security2:error] [pid 703393:tid 703596] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/themes.php"] [unique_id "amuGzc637Arlr6Yb1EcNNQAAAM4"]
[Thu Jul 30 12:15:57.724703 2026] [security2:error] [pid 703393:tid 703564] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/admin.php"] [unique_id "amuGzc637Arlr6Yb1EcNQQAAAK4"]
[Thu Jul 30 12:15:57.724822 2026] [security2:error] [pid 703393:tid 703564] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/admin.php"] [unique_id "amuGzc637Arlr6Yb1EcNQQAAAK4"]
[Thu Jul 30 12:15:58.222785 2026] [security2:error] [pid 703393:tid 703599] [client 20.63.98.115:60270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/admin.php"] [unique_id "amuGzs637Arlr6Yb1EcNSQAAANE"]
[Thu Jul 30 12:15:58.288038 2026] [security2:error] [pid 703393:tid 703569] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/dropdown.php"] [unique_id "amuGzs637Arlr6Yb1EcNSgAAALM"]
[Thu Jul 30 12:15:58.288201 2026] [security2:error] [pid 703393:tid 703569] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/dropdown.php"] [unique_id "amuGzs637Arlr6Yb1EcNSgAAALM"]
[Thu Jul 30 12:15:58.849932 2026] [security2:error] [pid 703393:tid 703526] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/inputs.php"] [unique_id "amuGzs637Arlr6Yb1EcNVAAAAIg"]
[Thu Jul 30 12:15:58.850074 2026] [security2:error] [pid 703393:tid 703526] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/inputs.php"] [unique_id "amuGzs637Arlr6Yb1EcNVAAAAIg"]
[Thu Jul 30 12:15:59.399850 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/100.php"] [unique_id "amuGz8637Arlr6Yb1EcNXgAAAJA"]
[Thu Jul 30 12:15:59.400049 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/100.php"] [unique_id "amuGz8637Arlr6Yb1EcNXgAAAJA"]
[Thu Jul 30 12:15:59.427742 2026] [security2:error] [pid 703393:tid 703570] [client 98.6.138.186:35237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuGz8637Arlr6Yb1EcNWwAAALQ"], referer: http://pkf.jo
[Thu Jul 30 12:15:59.452177 2026] [security2:error] [pid 703393:tid 703607] [client 20.63.98.115:21089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/batm.php"] [unique_id "amuGz8637Arlr6Yb1EcNXwAAANk"]
[Thu Jul 30 12:15:59.890046 2026] [security2:error] [pid 703393:tid 703588] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/autoload_classmap/function.php"] [unique_id "amuGz8637Arlr6Yb1EcNaQAAAMY"]
[Thu Jul 30 12:15:59.890145 2026] [security2:error] [pid 703393:tid 703588] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/autoload_classmap/function.php"] [unique_id "amuGz8637Arlr6Yb1EcNaQAAAMY"]
[Thu Jul 30 12:16:00.216626 2026] [security2:error] [pid 703393:tid 703573] [client 20.63.98.115:21091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/hehehehe.php"] [unique_id "amuG0M637Arlr6Yb1EcNcAAAALc"]
[Thu Jul 30 12:16:00.763591 2026] [security2:error] [pid 703393:tid 703532] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/php.php"] [unique_id "amuG0M637Arlr6Yb1EcNewAAAI4"]
[Thu Jul 30 12:16:00.763690 2026] [security2:error] [pid 703393:tid 703532] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/php.php"] [unique_id "amuG0M637Arlr6Yb1EcNewAAAI4"]
[Thu Jul 30 12:16:01.203123 2026] [security2:error] [pid 703393:tid 703475] [remote 103.255.134.61:57572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/wp-login.php"] [unique_id "amuG0c637Arlr6Yb1EcNfwABBFE"]
[Thu Jul 30 12:16:01.243427 2026] [security2:error] [pid 703393:tid 703535] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/t.php"] [unique_id "amuG0c637Arlr6Yb1EcNgwAAAJE"]
[Thu Jul 30 12:16:01.243521 2026] [security2:error] [pid 703393:tid 703535] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/t.php"] [unique_id "amuG0c637Arlr6Yb1EcNgwAAAJE"]
[Thu Jul 30 12:16:01.413873 2026] [security2:error] [pid 703393:tid 703601] [client 20.63.98.115:21084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/sim.php/wp-includes/certificates/plugins.php"] [unique_id "amuG0c637Arlr6Yb1EcNhAAAANM"]
[Thu Jul 30 12:16:01.764776 2026] [security2:error] [pid 703393:tid 703570] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-blink.php"] [unique_id "amuG0c637Arlr6Yb1EcNkAAAALQ"]
[Thu Jul 30 12:16:01.764914 2026] [security2:error] [pid 703393:tid 703570] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-blink.php"] [unique_id "amuG0c637Arlr6Yb1EcNkAAAALQ"]
[Thu Jul 30 12:16:01.765739 2026] [core:notice] [pid 703393:tid 703621] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:02.473482 2026] [security2:error] [pid 703393:tid 703564] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/xfun.php"] [unique_id "amuG0s637Arlr6Yb1EcNrgAAAK4"]
[Thu Jul 30 12:16:02.473674 2026] [security2:error] [pid 703393:tid 703564] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/xfun.php"] [unique_id "amuG0s637Arlr6Yb1EcNrgAAAK4"]
[Thu Jul 30 12:16:02.535024 2026] [core:notice] [pid 703393:tid 703616] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:02.744244 2026] [core:error] [pid 703393:tid 703552] [client 74.7.175.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:16:02.744269 2026] [core:error] [pid 703393:tid 703552] [client 74.7.175.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:16:02.744404 2026] [security2:error] [pid 703393:tid 703552] [client 74.7.175.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.xyt.gzj.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNtgAAAKI"]
[Thu Jul 30 12:16:02.745027 2026] [security2:error] [pid 703393:tid 703644] [client 74.7.175.158:36270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.xyt.gzj.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuG0s637Arlr6Yb1EcNtAAA_gI"]
[Thu Jul 30 12:16:02.853946 2026] [security2:error] [pid 703393:tid 703544] [client 20.63.98.115:60234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-seo.php"] [unique_id "amuG0s637Arlr6Yb1EcNugAAAJo"]
[Thu Jul 30 12:16:02.906865 2026] [security2:error] [pid 703393:tid 703442] [remote 40.77.167.67:5155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/camic/article/view/9080"] [unique_id "amuG0s637Arlr6Yb1EcNuwAAszA"]
[Thu Jul 30 12:16:02.967054 2026] [security2:error] [pid 703393:tid 703599] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/p.php"] [unique_id "amuG0s637Arlr6Yb1EcNvAAAANE"]
[Thu Jul 30 12:16:02.967170 2026] [security2:error] [pid 703393:tid 703599] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/p.php"] [unique_id "amuG0s637Arlr6Yb1EcNvAAAANE"]
[Thu Jul 30 12:16:03.042403 2026] [core:notice] [pid 703393:tid 703551] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:03.499369 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/themes/admin.php"] [unique_id "amuG08637Arlr6Yb1EcNxwAAAKg"]
[Thu Jul 30 12:16:03.499539 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/themes/admin.php"] [unique_id "amuG08637Arlr6Yb1EcNxwAAAKg"]
[Thu Jul 30 12:16:03.510950 2026] [security2:error] [pid 703393:tid 703611] [client 172.237.109.114:12869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNlAAAAN0"]
[Thu Jul 30 12:16:03.517096 2026] [security2:error] [pid 703393:tid 703600] [client 172.237.109.114:17910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNnwAAANI"]
[Thu Jul 30 12:16:03.519329 2026] [security2:error] [pid 703393:tid 703614] [client 172.237.109.114:1927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNlQAAAOA"]
[Thu Jul 30 12:16:03.530585 2026] [security2:error] [pid 703393:tid 703548] [client 172.237.109.114:28182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNkwAAAJ4"]
[Thu Jul 30 12:16:03.531174 2026] [security2:error] [pid 703393:tid 703582] [client 172.237.109.114:56117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNoAAAAMA"]
[Thu Jul 30 12:16:03.531249 2026] [security2:error] [pid 703393:tid 703595] [client 172.237.109.114:40416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNoQAAAM0"]
[Thu Jul 30 12:16:03.534029 2026] [security2:error] [pid 703393:tid 703617] [client 172.237.109.114:13885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNmwAAAOM"]
[Thu Jul 30 12:16:03.535450 2026] [security2:error] [pid 703393:tid 703622] [client 172.237.109.114:44221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNlgAAAOg"]
[Thu Jul 30 12:16:03.544137 2026] [security2:error] [pid 703393:tid 703536] [client 172.237.109.114:1784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNmQAAAJI"]
[Thu Jul 30 12:16:03.544516 2026] [security2:error] [pid 703393:tid 703596] [client 172.237.109.114:27669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNlwAAAM4"]
[Thu Jul 30 12:16:03.550304 2026] [security2:error] [pid 703393:tid 703593] [client 172.237.109.114:9468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNnAAAAMs"]
[Thu Jul 30 12:16:03.555527 2026] [security2:error] [pid 703393:tid 703613] [client 172.237.109.114:47285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNnQAAAN8"]
[Thu Jul 30 12:16:03.559838 2026] [security2:error] [pid 703393:tid 703597] [client 172.237.109.114:7431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNpQAAAM8"]
[Thu Jul 30 12:16:03.559955 2026] [security2:error] [pid 703393:tid 703615] [client 172.237.109.114:43483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNmgAAAOE"]
[Thu Jul 30 12:16:03.563971 2026] [security2:error] [pid 703393:tid 703527] [client 172.237.109.114:14723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNmAAAAIk"]
[Thu Jul 30 12:16:03.594547 2026] [security2:error] [pid 703393:tid 703618] [client 172.237.109.114:8234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNngAAAOQ"]
[Thu Jul 30 12:16:03.618501 2026] [security2:error] [pid 703393:tid 703628] [client 172.237.109.114:46366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNpAAAAO4"]
[Thu Jul 30 12:16:03.647120 2026] [security2:error] [pid 703393:tid 703588] [client 172.237.109.114:56155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0c637Arlr6Yb1EcNogAAAMY"]
[Thu Jul 30 12:16:03.658368 2026] [security2:error] [pid 703393:tid 703647] [client 172.237.109.114:25599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNpwAAAQE"]
[Thu Jul 30 12:16:03.659871 2026] [security2:error] [pid 703393:tid 703623] [client 172.237.109.114:50747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuG0s637Arlr6Yb1EcNpgAAAOk"]
[Thu Jul 30 12:16:03.665089 2026] [security2:error] [pid 703393:tid 703565] [client 223.109.255.141:44372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "marlboro-shop.com"] [uri "/"] [unique_id "amuG08637Arlr6Yb1EcNzAAAAK8"]
[Thu Jul 30 12:16:03.665197 2026] [security2:error] [pid 703393:tid 703565] [client 223.109.255.141:44372] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marlboro-shop.com"] [uri "/"] [unique_id "amuG08637Arlr6Yb1EcNzAAAAK8"]
[Thu Jul 30 12:16:03.778351 2026] [security2:error] [pid 703393:tid 703554] [client 74.7.175.131:49662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "helper.adtop.net"] [uri "/robots.txt"] [unique_id "amuG08637Arlr6Yb1EcN0gAApEk"]
[Thu Jul 30 12:16:04.023439 2026] [security2:error] [pid 703393:tid 703579] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/aaa.php"] [unique_id "amuG1M637Arlr6Yb1EcN1gAAAL0"]
[Thu Jul 30 12:16:04.023556 2026] [security2:error] [pid 703393:tid 703579] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/aaa.php"] [unique_id "amuG1M637Arlr6Yb1EcN1gAAAL0"]
[Thu Jul 30 12:16:04.035668 2026] [security2:error] [pid 703393:tid 703526] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuG08637Arlr6Yb1EcNxgAAAIg"]
[Thu Jul 30 12:16:04.389489 2026] [security2:error] [pid 703393:tid 703643] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuG08637Arlr6Yb1EcN1AAAAP0"]
[Thu Jul 30 12:16:04.575190 2026] [security2:error] [pid 703393:tid 703644] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/7.php"] [unique_id "amuG1M637Arlr6Yb1EcN3QAAAP4"]
[Thu Jul 30 12:16:04.575312 2026] [security2:error] [pid 703393:tid 703644] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/7.php"] [unique_id "amuG1M637Arlr6Yb1EcN3QAAAP4"]
[Thu Jul 30 12:16:05.114944 2026] [security2:error] [pid 703393:tid 703646] [client 20.63.98.115:42950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/zwso.php"] [unique_id "amuG1c637Arlr6Yb1EcN5QAAAQA"]
[Thu Jul 30 12:16:05.158379 2026] [security2:error] [pid 703393:tid 703546] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file5.php"] [unique_id "amuG1c637Arlr6Yb1EcN6AAAAJw"]
[Thu Jul 30 12:16:05.158494 2026] [security2:error] [pid 703393:tid 703546] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/file5.php"] [unique_id "amuG1c637Arlr6Yb1EcN6AAAAJw"]
[Thu Jul 30 12:16:05.176644 2026] [core:notice] [pid 703393:tid 703456] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:05.764389 2026] [security2:error] [pid 703393:tid 703593] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/makeasmtp.php"] [unique_id "amuG1c637Arlr6Yb1EcN9AAAAMs"]
[Thu Jul 30 12:16:05.764505 2026] [security2:error] [pid 703393:tid 703593] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/makeasmtp.php"] [unique_id "amuG1c637Arlr6Yb1EcN9AAAAMs"]
[Thu Jul 30 12:16:06.297298 2026] [security2:error] [pid 703393:tid 703604] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/index.php"] [unique_id "amuG1s637Arlr6Yb1EcN_gAAANY"]
[Thu Jul 30 12:16:06.297402 2026] [security2:error] [pid 703393:tid 703604] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/index.php"] [unique_id "amuG1s637Arlr6Yb1EcN_gAAANY"]
[Thu Jul 30 12:16:06.791450 2026] [security2:error] [pid 703393:tid 703573] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/atomlib.php"] [unique_id "amuG1s637Arlr6Yb1EcOBQAAALc"]
[Thu Jul 30 12:16:06.791565 2026] [security2:error] [pid 703393:tid 703573] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/atomlib.php"] [unique_id "amuG1s637Arlr6Yb1EcOBQAAALc"]
[Thu Jul 30 12:16:07.002021 2026] [security2:error] [pid 703393:tid 703571] [client 20.63.98.115:44096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/user.php"] [unique_id "amuG18637Arlr6Yb1EcOCgAAALU"]
[Thu Jul 30 12:16:07.330466 2026] [security2:error] [pid 703393:tid 703624] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/min.php"] [unique_id "amuG18637Arlr6Yb1EcODgAAAOo"]
[Thu Jul 30 12:16:07.330590 2026] [security2:error] [pid 703393:tid 703624] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/min.php"] [unique_id "amuG18637Arlr6Yb1EcODgAAAOo"]
[Thu Jul 30 12:16:08.039343 2026] [security2:error] [pid 703393:tid 703544] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/moon.php"] [unique_id "amuG2M637Arlr6Yb1EcOGAAAAJo"]
[Thu Jul 30 12:16:08.039463 2026] [security2:error] [pid 703393:tid 703544] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/moon.php"] [unique_id "amuG2M637Arlr6Yb1EcOGAAAAJo"]
[Thu Jul 30 12:16:08.047629 2026] [security2:error] [pid 703393:tid 703635] [client 20.63.98.115:42996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/assets/index.php"] [unique_id "amuG2M637Arlr6Yb1EcOGgAAAPU"]
[Thu Jul 30 12:16:08.561249 2026] [security2:error] [pid 703393:tid 703537] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws83.php"] [unique_id "amuG2M637Arlr6Yb1EcOIwAAAJM"]
[Thu Jul 30 12:16:08.561352 2026] [security2:error] [pid 703393:tid 703537] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws83.php"] [unique_id "amuG2M637Arlr6Yb1EcOIwAAAJM"]
[Thu Jul 30 12:16:08.865785 2026] [security2:error] [pid 703393:tid 703498] [remote 74.7.242.7:49830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuG2M637Arlr6Yb1EcOJwAAwGg"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:16:09.073998 2026] [security2:error] [pid 703393:tid 703613] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/403.php"] [unique_id "amuG2c637Arlr6Yb1EcOKAAAAN8"]
[Thu Jul 30 12:16:09.074112 2026] [security2:error] [pid 703393:tid 703613] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/403.php"] [unique_id "amuG2c637Arlr6Yb1EcOKAAAAN8"]
[Thu Jul 30 12:16:09.116630 2026] [security2:error] [pid 703393:tid 703600] [client 20.63.98.115:39085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/byp.php"] [unique_id "amuG2c637Arlr6Yb1EcOLAAAANI"]
[Thu Jul 30 12:16:09.263015 2026] [core:notice] [pid 703393:tid 703485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:09.582597 2026] [security2:error] [pid 703393:tid 703531] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/api.php"] [unique_id "amuG2c637Arlr6Yb1EcOMwAAAI0"]
[Thu Jul 30 12:16:09.582725 2026] [security2:error] [pid 703393:tid 703531] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/api.php"] [unique_id "amuG2c637Arlr6Yb1EcOMwAAAI0"]
[Thu Jul 30 12:16:09.985123 2026] [autoindex:error] [pid 703393:tid 703579] [client 34.195.23.187:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:16:10.067727 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/3.php"] [unique_id "amuG2s637Arlr6Yb1EcOPAAAAJU"]
[Thu Jul 30 12:16:10.067844 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/3.php"] [unique_id "amuG2s637Arlr6Yb1EcOPAAAAJU"]
[Thu Jul 30 12:16:11.532198 2026] [core:notice] [pid 703393:tid 703508] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:11.591256 2026] [autoindex:error] [pid 703393:tid 703614] [client 32.193.141.171:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:16:11.976971 2026] [security2:error] [pid 703393:tid 703600] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/wp-includes/PHPMailer/"] [unique_id "amuG28637Arlr6Yb1EcOYQAAANI"]
[Thu Jul 30 12:16:13.767953 2026] [security2:error] [pid 703393:tid 703583] [client 114.119.156.131:53941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.azureskyfilms.com"] [uri "/dsc4-2.html"] [unique_id "amuG3c637Arlr6Yb1EcOfAAAAME"], referer: https://www.azureskyfilms.com/dsc4-2.html
[Thu Jul 30 12:16:15.070303 2026] [security2:error] [pid 703393:tid 703586] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuG3s637Arlr6Yb1EcOjgAAxCM"]
[Thu Jul 30 12:16:15.220856 2026] [security2:error] [pid 703393:tid 703600] [client 223.109.255.161:36288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-mid-black-gold/"] [unique_id "amuG38637Arlr6Yb1EcOngAAANI"]
[Thu Jul 30 12:16:15.220970 2026] [security2:error] [pid 703393:tid 703600] [client 223.109.255.161:36288] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-mid-black-gold/"] [unique_id "amuG38637Arlr6Yb1EcOngAAANI"]
[Thu Jul 30 12:16:15.317654 2026] [security2:error] [pid 703393:tid 703554] [client 20.63.98.115:58178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/bs1.php"] [unique_id "amuG38637Arlr6Yb1EcOowAAAKQ"]
[Thu Jul 30 12:16:16.427076 2026] [security2:error] [pid 703393:tid 703585] [client 20.63.98.115:39042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/IXR/allez.php"] [unique_id "amuG4M637Arlr6Yb1EcOtgAAAMM"]
[Thu Jul 30 12:16:16.796496 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws77.php"] [unique_id "amuG4M637Arlr6Yb1EcOxQAAAPQ"]
[Thu Jul 30 12:16:16.796591 2026] [security2:error] [pid 703393:tid 703634] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/ws77.php"] [unique_id "amuG4M637Arlr6Yb1EcOxQAAAPQ"]
[Thu Jul 30 12:16:17.028863 2026] [security2:error] [pid 703393:tid 703496] [remote 74.7.241.59:46250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuG4c637Arlr6Yb1EcO0gAAxWY"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:16:17.343597 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/nc4.php"] [unique_id "amuG4c637Arlr6Yb1EcO2QAAAJA"]
[Thu Jul 30 12:16:17.343685 2026] [security2:error] [pid 703393:tid 703534] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/nc4.php"] [unique_id "amuG4c637Arlr6Yb1EcO2QAAAJA"]
[Thu Jul 30 12:16:17.478547 2026] [security2:error] [pid 703393:tid 703443] [remote 198.244.168.162:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "filmtvyap.com"] [uri "/barbie-film/"] [unique_id "amuG4c637Arlr6Yb1EcO3QAAujE"]
[Thu Jul 30 12:16:17.478794 2026] [security2:error] [pid 703393:tid 703576] [client 198.244.168.162:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "filmtvyap.com"] [uri "/barbie-film/"] [unique_id "amuG4c637Arlr6Yb1EcO3QAAujE"]
[Thu Jul 30 12:16:17.510195 2026] [security2:error] [pid 703393:tid 703645] [client 20.63.98.115:42961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/load.php"] [unique_id "amuG4c637Arlr6Yb1EcO3gAAAP8"]
[Thu Jul 30 12:16:17.528071 2026] [security2:error] [pid 703393:tid 703615] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuG4M637Arlr6Yb1EcOzQAAAOE"]
[Thu Jul 30 12:16:17.756430 2026] [security2:error] [pid 703393:tid 703567] [client 51.120.69.65:16264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/alpas.php"] [unique_id "amuG4c637Arlr6Yb1EcO5AAAALE"]
[Thu Jul 30 12:16:17.756544 2026] [security2:error] [pid 703393:tid 703567] [client 51.120.69.65:16264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/alpas.php"] [unique_id "amuG4c637Arlr6Yb1EcO5AAAALE"]
[Thu Jul 30 12:16:17.824808 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/as.php"] [unique_id "amuG4c637Arlr6Yb1EcO5gAAAJU"]
[Thu Jul 30 12:16:17.824915 2026] [security2:error] [pid 703393:tid 703539] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/as.php"] [unique_id "amuG4c637Arlr6Yb1EcO5gAAAJU"]
[Thu Jul 30 12:16:18.341688 2026] [security2:error] [pid 703393:tid 703524] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/k.php"] [unique_id "amuG4s637Arlr6Yb1EcO8AAAAIY"]
[Thu Jul 30 12:16:18.341781 2026] [security2:error] [pid 703393:tid 703524] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/k.php"] [unique_id "amuG4s637Arlr6Yb1EcO8AAAAIY"]
[Thu Jul 30 12:16:18.365660 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:16275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/alfa.php"] [unique_id "amuG4s637Arlr6Yb1EcO8QAAAL4"]
[Thu Jul 30 12:16:18.365742 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:16275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/alfa.php"] [unique_id "amuG4s637Arlr6Yb1EcO8QAAAL4"]
[Thu Jul 30 12:16:18.559066 2026] [security2:error] [pid 703393:tid 703404] [remote 74.7.241.60:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuG4s637Arlr6Yb1EcO9QAA8Qo"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:16:18.809652 2026] [security2:error] [pid 703393:tid 703629] [client 51.120.69.65:16350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/0byte.php"] [unique_id "amuG4s637Arlr6Yb1EcO9gAAAO8"]
[Thu Jul 30 12:16:18.809763 2026] [security2:error] [pid 703393:tid 703629] [client 51.120.69.65:16350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/0byte.php"] [unique_id "amuG4s637Arlr6Yb1EcO9gAAAO8"]
[Thu Jul 30 12:16:18.842530 2026] [security2:error] [pid 703393:tid 703602] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/system_log.php"] [unique_id "amuG4s637Arlr6Yb1EcO-gAAANQ"]
[Thu Jul 30 12:16:18.842694 2026] [security2:error] [pid 703393:tid 703602] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/system_log.php"] [unique_id "amuG4s637Arlr6Yb1EcO-gAAANQ"]
[Thu Jul 30 12:16:19.269969 2026] [security2:error] [pid 703393:tid 703614] [client 51.120.69.65:16289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/index3.php"] [unique_id "amuG48637Arlr6Yb1EcPAgAAAOA"]
[Thu Jul 30 12:16:19.270096 2026] [security2:error] [pid 703393:tid 703614] [client 51.120.69.65:16289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/index3.php"] [unique_id "amuG48637Arlr6Yb1EcPAgAAAOA"]
[Thu Jul 30 12:16:19.380972 2026] [security2:error] [pid 703393:tid 703598] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/x.php"] [unique_id "amuG48637Arlr6Yb1EcPCQAAANA"]
[Thu Jul 30 12:16:19.381154 2026] [security2:error] [pid 703393:tid 703598] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/x.php"] [unique_id "amuG48637Arlr6Yb1EcPCQAAANA"]
[Thu Jul 30 12:16:19.665831 2026] [security2:error] [pid 703393:tid 703543] [client 20.63.98.115:20707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/privacy.php"] [unique_id "amuG48637Arlr6Yb1EcPEAAAAJk"]
[Thu Jul 30 12:16:19.739469 2026] [security2:error] [pid 703393:tid 703615] [client 51.120.69.65:16281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/index2.php"] [unique_id "amuG48637Arlr6Yb1EcPEQAAAOE"]
[Thu Jul 30 12:16:19.739593 2026] [security2:error] [pid 703393:tid 703615] [client 51.120.69.65:16281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/index2.php"] [unique_id "amuG48637Arlr6Yb1EcPEQAAAOE"]
[Thu Jul 30 12:16:19.808306 2026] [security2:error] [pid 703393:tid 703542] [client 46.16.148.94:47950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG48637Arlr6Yb1EcPCwAAAJg"], referer: http://pkf.jo
[Thu Jul 30 12:16:19.815741 2026] [security2:error] [pid 703393:tid 703647] [client 109.198.225.117:6124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG48637Arlr6Yb1EcPCgAAAQE"], referer: http://pkf.jo
[Thu Jul 30 12:16:19.979993 2026] [security2:error] [pid 703393:tid 703601] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/autoload_classmap.php"] [unique_id "amuG48637Arlr6Yb1EcPHAAAANM"]
[Thu Jul 30 12:16:19.980094 2026] [security2:error] [pid 703393:tid 703601] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/autoload_classmap.php"] [unique_id "amuG48637Arlr6Yb1EcPHAAAANM"]
[Thu Jul 30 12:16:20.191613 2026] [security2:error] [pid 703393:tid 703630] [client 51.120.69.65:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/index1.php"] [unique_id "amuG5M637Arlr6Yb1EcPIAAAAPA"]
[Thu Jul 30 12:16:20.191728 2026] [security2:error] [pid 703393:tid 703630] [client 51.120.69.65:16286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/index1.php"] [unique_id "amuG5M637Arlr6Yb1EcPIAAAAPA"]
[Thu Jul 30 12:16:20.374517 2026] [security2:error] [pid 703393:tid 703584] [client 157.51.194.171:46013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG5M637Arlr6Yb1EcPHwAAAMI"], referer: http://pkf.jo
[Thu Jul 30 12:16:20.548291 2026] [security2:error] [pid 703393:tid 703585] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/test1.php"] [unique_id "amuG5M637Arlr6Yb1EcPKgAAAMM"]
[Thu Jul 30 12:16:20.548428 2026] [security2:error] [pid 703393:tid 703585] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/test1.php"] [unique_id "amuG5M637Arlr6Yb1EcPKgAAAMM"]
[Thu Jul 30 12:16:20.665360 2026] [security2:error] [pid 703393:tid 703530] [client 51.120.69.65:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/303.php"] [unique_id "amuG5M637Arlr6Yb1EcPLwAAAIw"]
[Thu Jul 30 12:16:20.665467 2026] [security2:error] [pid 703393:tid 703530] [client 51.120.69.65:16364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/303.php"] [unique_id "amuG5M637Arlr6Yb1EcPLwAAAIw"]
[Thu Jul 30 12:16:20.818995 2026] [security2:error] [pid 703393:tid 703646] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "baytalhuboob.com"] [uri "/.well-known/about.php"] [unique_id "amuG5M637Arlr6Yb1EcPMAAAAQA"]
[Thu Jul 30 12:16:20.819104 2026] [security2:error] [pid 703393:tid 703646] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "baytalhuboob.com"] [uri "/.well-known/about.php"] [unique_id "amuG5M637Arlr6Yb1EcPMAAAAQA"]
[Thu Jul 30 12:16:20.943093 2026] [security2:error] [pid 703393:tid 703566] [client 38.41.27.135:42528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG5M637Arlr6Yb1EcPLgAAALA"], referer: http://pkf.jo
[Thu Jul 30 12:16:21.057197 2026] [security2:error] [pid 703393:tid 703558] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webdisk/mini"] [unique_id "amuG5c637Arlr6Yb1EcPNAAAAKg"]
[Thu Jul 30 12:16:21.086964 2026] [security2:error] [pid 703393:tid 703644] [client 51.120.69.65:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/505.php"] [unique_id "amuG5c637Arlr6Yb1EcPNQAAAP4"]
[Thu Jul 30 12:16:21.087076 2026] [security2:error] [pid 703393:tid 703644] [client 51.120.69.65:16360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/505.php"] [unique_id "amuG5c637Arlr6Yb1EcPNQAAAP4"]
[Thu Jul 30 12:16:21.297149 2026] [security2:error] [pid 703393:tid 703546] [client 20.63.98.115:60238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-cli.php"] [unique_id "amuG5c637Arlr6Yb1EcPOgAAAJw"]
[Thu Jul 30 12:16:21.308159 2026] [security2:error] [pid 703393:tid 703598] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-signin.php"] [unique_id "amuG5c637Arlr6Yb1EcPOwAAANA"]
[Thu Jul 30 12:16:21.308306 2026] [security2:error] [pid 703393:tid 703598] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-signin.php"] [unique_id "amuG5c637Arlr6Yb1EcPOwAAANA"]
[Thu Jul 30 12:16:21.580469 2026] [security2:error] [pid 703393:tid 703625] [client 51.120.69.65:16325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/500.php"] [unique_id "amuG5c637Arlr6Yb1EcPRgAAAOs"]
[Thu Jul 30 12:16:21.580577 2026] [security2:error] [pid 703393:tid 703625] [client 51.120.69.65:16325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/500.php"] [unique_id "amuG5c637Arlr6Yb1EcPRgAAAOs"]
[Thu Jul 30 12:16:21.805851 2026] [security2:error] [pid 703393:tid 703623] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/gg.php"] [unique_id "amuG5c637Arlr6Yb1EcPSAAAAOk"]
[Thu Jul 30 12:16:21.805961 2026] [security2:error] [pid 703393:tid 703623] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/gg.php"] [unique_id "amuG5c637Arlr6Yb1EcPSAAAAOk"]
[Thu Jul 30 12:16:22.083789 2026] [security2:error] [pid 703393:tid 703549] [client 51.120.69.65:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/77.php"] [unique_id "amuG5s637Arlr6Yb1EcPTAAAAJ8"]
[Thu Jul 30 12:16:22.083896 2026] [security2:error] [pid 703393:tid 703549] [client 51.120.69.65:16258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/77.php"] [unique_id "amuG5s637Arlr6Yb1EcPTAAAAJ8"]
[Thu Jul 30 12:16:22.295857 2026] [security2:error] [pid 703393:tid 703608] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/class.php"] [unique_id "amuG5s637Arlr6Yb1EcPUAAAANo"]
[Thu Jul 30 12:16:22.295968 2026] [security2:error] [pid 703393:tid 703608] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/class.php"] [unique_id "amuG5s637Arlr6Yb1EcPUAAAANo"]
[Thu Jul 30 12:16:22.607608 2026] [security2:error] [pid 703393:tid 703553] [client 51.120.69.65:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/76.php"] [unique_id "amuG5s637Arlr6Yb1EcPVAAAAKM"]
[Thu Jul 30 12:16:22.607691 2026] [security2:error] [pid 703393:tid 703553] [client 51.120.69.65:16356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/76.php"] [unique_id "amuG5s637Arlr6Yb1EcPVAAAAKM"]
[Thu Jul 30 12:16:22.805567 2026] [security2:error] [pid 703393:tid 703533] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/404.php"] [unique_id "amuG5s637Arlr6Yb1EcPWgAAAI8"]
[Thu Jul 30 12:16:22.805683 2026] [security2:error] [pid 703393:tid 703533] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/404.php"] [unique_id "amuG5s637Arlr6Yb1EcPWgAAAI8"]
[Thu Jul 30 12:16:22.903248 2026] [security2:error] [pid 703393:tid 703624] [client 20.63.98.115:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cc.php"] [unique_id "amuG5s637Arlr6Yb1EcPWwAAAOo"]
[Thu Jul 30 12:16:23.048851 2026] [security2:error] [pid 703393:tid 703603] [client 51.120.69.65:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/74.php"] [unique_id "amuG58637Arlr6Yb1EcPYAAAANU"]
[Thu Jul 30 12:16:23.048995 2026] [security2:error] [pid 703393:tid 703603] [client 51.120.69.65:16380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/74.php"] [unique_id "amuG58637Arlr6Yb1EcPYAAAANU"]
[Thu Jul 30 12:16:23.362595 2026] [security2:error] [pid 703393:tid 703597] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/lite.php"] [unique_id "amuG58637Arlr6Yb1EcPZAAAAM8"]
[Thu Jul 30 12:16:23.362709 2026] [security2:error] [pid 703393:tid 703597] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/lite.php"] [unique_id "amuG58637Arlr6Yb1EcPZAAAAM8"]
[Thu Jul 30 12:16:23.463225 2026] [security2:error] [pid 703393:tid 703546] [client 51.120.69.65:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/wp-config.php"] [unique_id "amuG58637Arlr6Yb1EcPZgAAAJw"]
[Thu Jul 30 12:16:23.463340 2026] [security2:error] [pid 703393:tid 703546] [client 51.120.69.65:16357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/wp-config.php"] [unique_id "amuG58637Arlr6Yb1EcPZgAAAJw"]
[Thu Jul 30 12:16:23.928563 2026] [security2:error] [pid 703393:tid 703586] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/lock360.php"] [unique_id "amuG58637Arlr6Yb1EcPbgAAAMQ"]
[Thu Jul 30 12:16:23.928701 2026] [security2:error] [pid 703393:tid 703586] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/lock360.php"] [unique_id "amuG58637Arlr6Yb1EcPbgAAAMQ"]
[Thu Jul 30 12:16:23.955502 2026] [security2:error] [pid 703393:tid 703618] [client 51.120.69.65:16260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/75.php"] [unique_id "amuG58637Arlr6Yb1EcPbwAAAOQ"]
[Thu Jul 30 12:16:23.955649 2026] [security2:error] [pid 703393:tid 703618] [client 51.120.69.65:16260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/75.php"] [unique_id "amuG58637Arlr6Yb1EcPbwAAAOQ"]
[Thu Jul 30 12:16:24.484382 2026] [security2:error] [pid 703393:tid 703570] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuG6M637Arlr6Yb1EcPeAAAALQ"]
[Thu Jul 30 12:16:24.484527 2026] [security2:error] [pid 703393:tid 703570] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuG6M637Arlr6Yb1EcPeAAAALQ"]
[Thu Jul 30 12:16:24.516353 2026] [security2:error] [pid 703393:tid 703529] [client 51.120.69.65:16371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/71.php"] [unique_id "amuG6M637Arlr6Yb1EcPeQAAAIs"]
[Thu Jul 30 12:16:24.516462 2026] [security2:error] [pid 703393:tid 703529] [client 51.120.69.65:16371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/71.php"] [unique_id "amuG6M637Arlr6Yb1EcPeQAAAIs"]
[Thu Jul 30 12:16:24.744869 2026] [autoindex:error] [pid 703393:tid 703541] [client 43.140.247.223:33368] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:16:24.803242 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:44140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/media-new.php"] [unique_id "amuG6M637Arlr6Yb1EcPgQAAAPo"]
[Thu Jul 30 12:16:24.893394 2026] [security2:error] [pid 703393:tid 703552] [client 51.120.69.65:16272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/72.php"] [unique_id "amuG6M637Arlr6Yb1EcPggAAAKI"]
[Thu Jul 30 12:16:24.893492 2026] [security2:error] [pid 703393:tid 703552] [client 51.120.69.65:16272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/72.php"] [unique_id "amuG6M637Arlr6Yb1EcPggAAAKI"]
[Thu Jul 30 12:16:24.973334 2026] [security2:error] [pid 703393:tid 703584] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-links-opml.php"] [unique_id "amuG6M637Arlr6Yb1EcPgwAAAMI"]
[Thu Jul 30 12:16:24.973435 2026] [security2:error] [pid 703393:tid 703584] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-links-opml.php"] [unique_id "amuG6M637Arlr6Yb1EcPgwAAAMI"]
[Thu Jul 30 12:16:25.400694 2026] [security2:error] [pid 703393:tid 703631] [client 51.120.69.65:15617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/70.php"] [unique_id "amuG6c637Arlr6Yb1EcPjgAAAPE"]
[Thu Jul 30 12:16:25.400790 2026] [security2:error] [pid 703393:tid 703631] [client 51.120.69.65:15617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/70.php"] [unique_id "amuG6c637Arlr6Yb1EcPjgAAAPE"]
[Thu Jul 30 12:16:25.467824 2026] [security2:error] [pid 703393:tid 703551] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/uploads/min.php"] [unique_id "amuG6c637Arlr6Yb1EcPjwAAAKE"]
[Thu Jul 30 12:16:25.467927 2026] [security2:error] [pid 703393:tid 703551] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prolineroofingservices.homes"] [uri "/wp-content/uploads/min.php"] [unique_id "amuG6c637Arlr6Yb1EcPjwAAAKE"]
[Thu Jul 30 12:16:25.774326 2026] [security2:error] [pid 703393:tid 703526] [client 20.63.98.115:44150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-blog.php"] [unique_id "amuG6c637Arlr6Yb1EcPkwAAAIg"]
[Thu Jul 30 12:16:26.186622 2026] [security2:error] [pid 703393:tid 703563] [client 51.120.69.65:16279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/69.php"] [unique_id "amuG6s637Arlr6Yb1EcPnQAAAK0"]
[Thu Jul 30 12:16:26.186732 2026] [security2:error] [pid 703393:tid 703563] [client 51.120.69.65:16279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/69.php"] [unique_id "amuG6s637Arlr6Yb1EcPnQAAAK0"]
[Thu Jul 30 12:16:26.591857 2026] [core:notice] [pid 703393:tid 703613] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:27.006212 2026] [security2:error] [pid 703393:tid 703642] [client 51.120.69.65:16278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/68.php"] [unique_id "amuG68637Arlr6Yb1EcPrAAAAPw"]
[Thu Jul 30 12:16:27.006368 2026] [security2:error] [pid 703393:tid 703642] [client 51.120.69.65:16278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/68.php"] [unique_id "amuG68637Arlr6Yb1EcPrAAAAPw"]
[Thu Jul 30 12:16:27.493790 2026] [security2:error] [pid 703393:tid 703628] [client 51.120.69.65:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/66.php"] [unique_id "amuG68637Arlr6Yb1EcPugAAAO4"]
[Thu Jul 30 12:16:27.493894 2026] [security2:error] [pid 703393:tid 703628] [client 51.120.69.65:16341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/66.php"] [unique_id "amuG68637Arlr6Yb1EcPugAAAO4"]
[Thu Jul 30 12:16:28.042428 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/67.php"] [unique_id "amuG7M637Arlr6Yb1EcPwQAAAKA"]
[Thu Jul 30 12:16:28.042525 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/67.php"] [unique_id "amuG7M637Arlr6Yb1EcPwQAAAKA"]
[Thu Jul 30 12:16:28.068511 2026] [security2:error] [pid 703393:tid 703632] [client 20.63.98.115:42981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-2019.php"] [unique_id "amuG7M637Arlr6Yb1EcPwgAAAPI"]
[Thu Jul 30 12:16:28.329785 2026] [security2:error] [pid 703393:tid 703519] [remote 72.167.132.114:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-login.php"] [unique_id "amuG7M637Arlr6Yb1EcPywAAtH0"]
[Thu Jul 30 12:16:28.516691 2026] [security2:error] [pid 703393:tid 703634] [client 51.120.69.65:16296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/65.php"] [unique_id "amuG7M637Arlr6Yb1EcPzwAAAPQ"]
[Thu Jul 30 12:16:28.516869 2026] [security2:error] [pid 703393:tid 703634] [client 51.120.69.65:16296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/65.php"] [unique_id "amuG7M637Arlr6Yb1EcPzwAAAPQ"]
[Thu Jul 30 12:16:28.824566 2026] [security2:error] [pid 703393:tid 703646] [client 184.75.223.195:53234] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuG7M637Arlr6Yb1EcP1AAAAQA"]
[Thu Jul 30 12:16:28.824665 2026] [security2:error] [pid 703393:tid 703646] [client 184.75.223.195:53234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuG7M637Arlr6Yb1EcP1AAAAQA"]
[Thu Jul 30 12:16:28.988999 2026] [security2:error] [pid 703393:tid 703624] [client 51.120.69.65:16287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/64.php"] [unique_id "amuG7M637Arlr6Yb1EcP2QAAAOo"]
[Thu Jul 30 12:16:28.989143 2026] [security2:error] [pid 703393:tid 703624] [client 51.120.69.65:16287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/64.php"] [unique_id "amuG7M637Arlr6Yb1EcP2QAAAOo"]
[Thu Jul 30 12:16:29.376065 2026] [security2:error] [pid 703393:tid 703560] [client 51.120.69.65:15618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/63.php"] [unique_id "amuG7c637Arlr6Yb1EcP3QAAAKo"]
[Thu Jul 30 12:16:29.376173 2026] [security2:error] [pid 703393:tid 703560] [client 51.120.69.65:15618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/63.php"] [unique_id "amuG7c637Arlr6Yb1EcP3QAAAKo"]
[Thu Jul 30 12:16:29.481204 2026] [security2:error] [pid 703393:tid 703578] [client 20.104.18.253:7095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/n9z13o5s.php"] [unique_id "amuG7c637Arlr6Yb1EcP4QAAALw"]
[Thu Jul 30 12:16:29.757105 2026] [security2:error] [pid 703393:tid 703545] [client 51.120.69.65:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/62.php"] [unique_id "amuG7c637Arlr6Yb1EcP5QAAAJs"]
[Thu Jul 30 12:16:29.757207 2026] [security2:error] [pid 703393:tid 703545] [client 51.120.69.65:16266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/62.php"] [unique_id "amuG7c637Arlr6Yb1EcP5QAAAJs"]
[Thu Jul 30 12:16:29.767552 2026] [core:notice] [pid 703393:tid 703613] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:30.174262 2026] [security2:error] [pid 703393:tid 703534] [client 51.120.69.65:16370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/61.php"] [unique_id "amuG7s637Arlr6Yb1EcP6gAAAJA"]
[Thu Jul 30 12:16:30.174390 2026] [security2:error] [pid 703393:tid 703534] [client 51.120.69.65:16370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/61.php"] [unique_id "amuG7s637Arlr6Yb1EcP6gAAAJA"]
[Thu Jul 30 12:16:30.329923 2026] [security2:error] [pid 703393:tid 703554] [client 20.104.18.253:7071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/uploads/2014/03/smile.php"] [unique_id "amuG7s637Arlr6Yb1EcP8AAAAKQ"]
[Thu Jul 30 12:16:30.460071 2026] [security2:error] [pid 703393:tid 703526] [client 20.63.98.115:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/menu.php"] [unique_id "amuG7s637Arlr6Yb1EcP8wAAAIg"]
[Thu Jul 30 12:16:30.655111 2026] [security2:error] [pid 703393:tid 703573] [client 51.120.69.65:15622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/60.php"] [unique_id "amuG7s637Arlr6Yb1EcP-AAAALc"]
[Thu Jul 30 12:16:30.655210 2026] [security2:error] [pid 703393:tid 703573] [client 51.120.69.65:15622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/60.php"] [unique_id "amuG7s637Arlr6Yb1EcP-AAAALc"]
[Thu Jul 30 12:16:31.047535 2026] [security2:error] [pid 703393:tid 703557] [client 20.104.18.253:7064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ini.php"] [unique_id "amuG78637Arlr6Yb1EcQAAAAAKc"]
[Thu Jul 30 12:16:31.069780 2026] [security2:error] [pid 703393:tid 703600] [client 51.120.69.65:16352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/58.php"] [unique_id "amuG78637Arlr6Yb1EcQAQAAANI"]
[Thu Jul 30 12:16:31.069863 2026] [security2:error] [pid 703393:tid 703600] [client 51.120.69.65:16352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/58.php"] [unique_id "amuG78637Arlr6Yb1EcQAQAAANI"]
[Thu Jul 30 12:16:31.459922 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:16274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/59.php"] [unique_id "amuG78637Arlr6Yb1EcQCAAAAPg"]
[Thu Jul 30 12:16:31.460089 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:16274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/59.php"] [unique_id "amuG78637Arlr6Yb1EcQCAAAAPg"]
[Thu Jul 30 12:16:31.501527 2026] [security2:error] [pid 703393:tid 703587] [client 43.134.69.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuG78637Arlr6Yb1EcQBAAAAMU"]
[Thu Jul 30 12:16:31.510194 2026] [security2:error] [pid 703393:tid 703636] [client 20.63.98.115:20819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-crons.php"] [unique_id "amuG78637Arlr6Yb1EcQDQAAAPY"]
[Thu Jul 30 12:16:31.680571 2026] [security2:error] [pid 703393:tid 703599] [client 87.101.92.171:43482] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuG78637Arlr6Yb1EcQDgAAANE"]
[Thu Jul 30 12:16:31.680677 2026] [security2:error] [pid 703393:tid 703599] [client 87.101.92.171:43482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuG78637Arlr6Yb1EcQDgAAANE"]
[Thu Jul 30 12:16:31.882787 2026] [security2:error] [pid 703393:tid 703566] [client 51.120.69.65:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/57.php/56.php"] [unique_id "amuG78637Arlr6Yb1EcQGQAAALA"]
[Thu Jul 30 12:16:31.882934 2026] [security2:error] [pid 703393:tid 703566] [client 51.120.69.65:16375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/57.php/56.php"] [unique_id "amuG78637Arlr6Yb1EcQGQAAALA"]
[Thu Jul 30 12:16:32.300795 2026] [security2:error] [pid 703393:tid 703610] [client 51.120.69.65:16293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/55.php"] [unique_id "amuG8M637Arlr6Yb1EcQJQAAANw"]
[Thu Jul 30 12:16:32.300914 2026] [security2:error] [pid 703393:tid 703610] [client 51.120.69.65:16293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/55.php"] [unique_id "amuG8M637Arlr6Yb1EcQJQAAANw"]
[Thu Jul 30 12:16:32.743737 2026] [security2:error] [pid 703393:tid 703534] [client 20.63.98.115:65449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/class.php"] [unique_id "amuG8M637Arlr6Yb1EcQOAAAAJA"]
[Thu Jul 30 12:16:33.115372 2026] [security2:error] [pid 703393:tid 703525] [client 14.191.108.32:20538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG8M637Arlr6Yb1EcQOQAAAIc"], referer: http://pkf.jo
[Thu Jul 30 12:16:33.153288 2026] [security2:error] [pid 703393:tid 703530] [client 20.104.18.253:6830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/img/xleet.php"] [unique_id "amuG8c637Arlr6Yb1EcQQgAAAIw"]
[Thu Jul 30 12:16:33.227714 2026] [security2:error] [pid 703393:tid 703565] [client 51.120.69.65:16257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/54.php"] [unique_id "amuG8c637Arlr6Yb1EcQRAAAAK8"]
[Thu Jul 30 12:16:33.227809 2026] [security2:error] [pid 703393:tid 703565] [client 51.120.69.65:16257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/54.php"] [unique_id "amuG8c637Arlr6Yb1EcQRAAAAK8"]
[Thu Jul 30 12:16:33.657456 2026] [security2:error] [pid 703393:tid 703600] [client 51.120.69.65:16321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/53.php"] [unique_id "amuG8c637Arlr6Yb1EcQTQAAANI"]
[Thu Jul 30 12:16:33.657561 2026] [security2:error] [pid 703393:tid 703600] [client 51.120.69.65:16321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/53.php"] [unique_id "amuG8c637Arlr6Yb1EcQTQAAANI"]
[Thu Jul 30 12:16:33.770367 2026] [security2:error] [pid 703393:tid 703529] [client 20.63.98.115:65450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/login.php"] [unique_id "amuG8c637Arlr6Yb1EcQTgAAAIs"]
[Thu Jul 30 12:16:33.897124 2026] [proxy:error] [pid 703393:tid 703557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:33.897176 2026] [proxy_http:error] [pid 703393:tid 703557] [client 20.104.18.253:6841] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:33.897736 2026] [proxy:error] [pid 703393:tid 703557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:33.897777 2026] [proxy_http:error] [pid 703393:tid 703557] [client 20.104.18.253:6841] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:34.040832 2026] [security2:error] [pid 703393:tid 703587] [client 51.120.69.65:16362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/52.php"] [unique_id "amuG8s637Arlr6Yb1EcQVwAAAMU"]
[Thu Jul 30 12:16:34.040931 2026] [security2:error] [pid 703393:tid 703587] [client 51.120.69.65:16362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/52.php"] [unique_id "amuG8s637Arlr6Yb1EcQVwAAAMU"]
[Thu Jul 30 12:16:34.417306 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/51.php"] [unique_id "amuG8s637Arlr6Yb1EcQWAAAAOU"]
[Thu Jul 30 12:16:34.417431 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/51.php"] [unique_id "amuG8s637Arlr6Yb1EcQWAAAAOU"]
[Thu Jul 30 12:16:34.565843 2026] [security2:error] [pid 703393:tid 703532] [client 85.208.96.194:33916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/copy-of-32-weeks-coaching"] [unique_id "amuG8s637Arlr6Yb1EcQXAAAAI4"]
[Thu Jul 30 12:16:34.566011 2026] [security2:error] [pid 703393:tid 703532] [client 85.208.96.194:33916] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/copy-of-32-weeks-coaching"] [unique_id "amuG8s637Arlr6Yb1EcQXAAAAI4"]
[Thu Jul 30 12:16:34.663516 2026] [security2:error] [pid 703393:tid 703551] [client 20.104.18.253:6802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/server.php"] [unique_id "amuG8s637Arlr6Yb1EcQYAAAAKE"]
[Thu Jul 30 12:16:34.783279 2026] [security2:error] [pid 703393:tid 703650] [client 51.120.69.65:16285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/50.php"] [unique_id "amuG8s637Arlr6Yb1EcQYQAAAQQ"]
[Thu Jul 30 12:16:34.783397 2026] [security2:error] [pid 703393:tid 703650] [client 51.120.69.65:16285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/50.php"] [unique_id "amuG8s637Arlr6Yb1EcQYQAAAQQ"]
[Thu Jul 30 12:16:35.187912 2026] [security2:error] [pid 703393:tid 703610] [client 51.120.69.65:16298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/49.php"] [unique_id "amuG88637Arlr6Yb1EcQaQAAANw"]
[Thu Jul 30 12:16:35.188047 2026] [security2:error] [pid 703393:tid 703610] [client 51.120.69.65:16298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/49.php"] [unique_id "amuG88637Arlr6Yb1EcQaQAAANw"]
[Thu Jul 30 12:16:35.462049 2026] [security2:error] [pid 703393:tid 703617] [client 20.104.18.253:7078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/pki-validation/wp-config.php"] [unique_id "amuG88637Arlr6Yb1EcQbgAAAOM"]
[Thu Jul 30 12:16:35.585567 2026] [security2:error] [pid 703393:tid 703631] [client 51.120.69.65:16282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/48.php"] [unique_id "amuG88637Arlr6Yb1EcQcgAAAPE"]
[Thu Jul 30 12:16:35.585668 2026] [security2:error] [pid 703393:tid 703631] [client 51.120.69.65:16282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/48.php"] [unique_id "amuG88637Arlr6Yb1EcQcgAAAPE"]
[Thu Jul 30 12:16:35.648039 2026] [security2:error] [pid 703393:tid 703625] [client 20.63.98.115:43006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/aged.php"] [unique_id "amuG88637Arlr6Yb1EcQdQAAAOs"]
[Thu Jul 30 12:16:35.975897 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:15712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/47.php"] [unique_id "amuG88637Arlr6Yb1EcQeQAAAKQ"]
[Thu Jul 30 12:16:35.976038 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:15712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/47.php"] [unique_id "amuG88637Arlr6Yb1EcQeQAAAKQ"]
[Thu Jul 30 12:16:36.367307 2026] [security2:error] [pid 703393:tid 703525] [client 20.104.18.253:7045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/twentytwentyfive/flower.php"] [unique_id "amuG9M637Arlr6Yb1EcQggAAAIc"]
[Thu Jul 30 12:16:36.613616 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/46.php"] [unique_id "amuG9M637Arlr6Yb1EcQhwAAAKA"]
[Thu Jul 30 12:16:36.613721 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/46.php"] [unique_id "amuG9M637Arlr6Yb1EcQhwAAAKA"]
[Thu Jul 30 12:16:37.061305 2026] [security2:error] [pid 703393:tid 703556] [client 51.120.69.65:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/44.php"] [unique_id "amuG9c637Arlr6Yb1EcQjAAAAKY"]
[Thu Jul 30 12:16:37.061433 2026] [security2:error] [pid 703393:tid 703556] [client 51.120.69.65:15646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/44.php"] [unique_id "amuG9c637Arlr6Yb1EcQjAAAAKY"]
[Thu Jul 30 12:16:37.442373 2026] [security2:error] [pid 703393:tid 703601] [client 20.63.98.115:20734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/vv.php"] [unique_id "amuG9c637Arlr6Yb1EcQkwAAANM"]
[Thu Jul 30 12:16:37.527209 2026] [security2:error] [pid 703393:tid 703585] [client 51.120.69.65:15625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/43.php"] [unique_id "amuG9c637Arlr6Yb1EcQlAAAAMM"]
[Thu Jul 30 12:16:37.527329 2026] [security2:error] [pid 703393:tid 703585] [client 51.120.69.65:15625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/43.php"] [unique_id "amuG9c637Arlr6Yb1EcQlAAAAMM"]
[Thu Jul 30 12:16:37.938609 2026] [security2:error] [pid 703393:tid 703646] [client 20.104.18.253:6674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuG9c637Arlr6Yb1EcQnwAAAQA"]
[Thu Jul 30 12:16:38.001357 2026] [security2:error] [pid 703393:tid 703577] [client 51.120.69.65:16351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/42.php"] [unique_id "amuG9s637Arlr6Yb1EcQoAAAALs"]
[Thu Jul 30 12:16:38.001458 2026] [security2:error] [pid 703393:tid 703577] [client 51.120.69.65:16351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/42.php"] [unique_id "amuG9s637Arlr6Yb1EcQoAAAALs"]
[Thu Jul 30 12:16:38.522089 2026] [security2:error] [pid 703393:tid 703547] [client 20.63.98.115:20590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/user-edit.php"] [unique_id "amuG9s637Arlr6Yb1EcQpwAAAJ0"]
[Thu Jul 30 12:16:38.566601 2026] [security2:error] [pid 703393:tid 703561] [client 51.120.69.65:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/41.php"] [unique_id "amuG9s637Arlr6Yb1EcQqAAAAKs"]
[Thu Jul 30 12:16:38.566711 2026] [security2:error] [pid 703393:tid 703561] [client 51.120.69.65:16328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/41.php"] [unique_id "amuG9s637Arlr6Yb1EcQqAAAAKs"]
[Thu Jul 30 12:16:38.860916 2026] [security2:error] [pid 703393:tid 703598] [client 20.104.18.253:6666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/shell1.php"] [unique_id "amuG9s637Arlr6Yb1EcQsgAAANA"]
[Thu Jul 30 12:16:38.880104 2026] [core:notice] [pid 703393:tid 703463] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:38.881492 2026] [security2:error] [pid 703393:tid 703590] [client 74.7.241.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "teknomalay.com"] [uri "/category/tutorial/"] [unique_id "amuG9s637Arlr6Yb1EcQswAAyEU"], referer: https://aleorestaurant.com/robots.txt
[Thu Jul 30 12:16:38.908759 2026] [security2:error] [pid 703393:tid 703527] [client 51.120.69.65:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/40.php"] [unique_id "amuG9s637Arlr6Yb1EcQtAAAAIk"]
[Thu Jul 30 12:16:38.908856 2026] [security2:error] [pid 703393:tid 703527] [client 51.120.69.65:16322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/40.php"] [unique_id "amuG9s637Arlr6Yb1EcQtAAAAIk"]
[Thu Jul 30 12:16:39.259127 2026] [security2:error] [pid 703393:tid 703531] [client 51.120.69.65:16318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/39.php"] [unique_id "amuG98637Arlr6Yb1EcQuAAAAI0"]
[Thu Jul 30 12:16:39.259279 2026] [security2:error] [pid 703393:tid 703531] [client 51.120.69.65:16318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/39.php"] [unique_id "amuG98637Arlr6Yb1EcQuAAAAI0"]
[Thu Jul 30 12:16:39.616721 2026] [core:notice] [pid 703393:tid 703468] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:39.698657 2026] [security2:error] [pid 703393:tid 703623] [client 51.120.69.65:16377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/38.php"] [unique_id "amuG98637Arlr6Yb1EcQwAAAAOk"]
[Thu Jul 30 12:16:39.698759 2026] [security2:error] [pid 703393:tid 703623] [client 51.120.69.65:16377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/38.php"] [unique_id "amuG98637Arlr6Yb1EcQwAAAAOk"]
[Thu Jul 30 12:16:39.719333 2026] [security2:error] [pid 703393:tid 703575] [client 20.104.18.253:6683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-set.php"] [unique_id "amuG98637Arlr6Yb1EcQwQAAALk"]
[Thu Jul 30 12:16:40.085777 2026] [security2:error] [pid 703393:tid 703628] [client 74.7.241.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amuG98637Arlr6Yb1EcQvwAA7ko"], referer: https://teknomalay.com/category/tutorial/
[Thu Jul 30 12:16:40.110664 2026] [security2:error] [pid 703393:tid 703639] [client 51.120.69.65:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/37.php"] [unique_id "amuG-M637Arlr6Yb1EcQzAAAAPk"]
[Thu Jul 30 12:16:40.110764 2026] [security2:error] [pid 703393:tid 703639] [client 51.120.69.65:16324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/37.php"] [unique_id "amuG-M637Arlr6Yb1EcQzAAAAPk"]
[Thu Jul 30 12:16:40.451144 2026] [security2:error] [pid 703393:tid 703548] [client 51.120.69.65:15623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/36.php"] [unique_id "amuG-M637Arlr6Yb1EcQ2QAAAJ4"]
[Thu Jul 30 12:16:40.451255 2026] [security2:error] [pid 703393:tid 703548] [client 51.120.69.65:15623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/36.php"] [unique_id "amuG-M637Arlr6Yb1EcQ2QAAAJ4"]
[Thu Jul 30 12:16:40.800872 2026] [security2:error] [pid 703393:tid 703646] [client 113.189.29.160:33770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuG-M637Arlr6Yb1EcQ2gAAAQA"], referer: http://pkf.jo
[Thu Jul 30 12:16:41.223785 2026] [security2:error] [pid 703393:tid 703617] [client 51.120.69.65:16304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/35.php"] [unique_id "amuG-c637Arlr6Yb1EcQ5wAAAOM"]
[Thu Jul 30 12:16:41.223943 2026] [security2:error] [pid 703393:tid 703617] [client 51.120.69.65:16304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/35.php"] [unique_id "amuG-c637Arlr6Yb1EcQ5wAAAOM"]
[Thu Jul 30 12:16:41.326558 2026] [security2:error] [pid 703393:tid 703613] [client 20.63.98.115:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuG-c637Arlr6Yb1EcQ6AAAAN8"]
[Thu Jul 30 12:16:41.787489 2026] [security2:error] [pid 703393:tid 703573] [client 51.120.69.65:16311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/34.php"] [unique_id "amuG-c637Arlr6Yb1EcQ8AAAALc"]
[Thu Jul 30 12:16:41.787609 2026] [security2:error] [pid 703393:tid 703573] [client 51.120.69.65:16311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/34.php"] [unique_id "amuG-c637Arlr6Yb1EcQ8AAAALc"]
[Thu Jul 30 12:16:42.266386 2026] [security2:error] [pid 703393:tid 703529] [client 51.120.69.65:15673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/33.php"] [unique_id "amuG-s637Arlr6Yb1EcQ-wAAAIs"]
[Thu Jul 30 12:16:42.266536 2026] [security2:error] [pid 703393:tid 703529] [client 51.120.69.65:15673] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/33.php"] [unique_id "amuG-s637Arlr6Yb1EcQ-wAAAIs"]
[Thu Jul 30 12:16:42.709332 2026] [security2:error] [pid 703393:tid 703624] [client 51.120.69.65:16383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/25.php"] [unique_id "amuG-s637Arlr6Yb1EcRBAAAAOo"]
[Thu Jul 30 12:16:42.709482 2026] [security2:error] [pid 703393:tid 703624] [client 51.120.69.65:16383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/25.php"] [unique_id "amuG-s637Arlr6Yb1EcRBAAAAOo"]
[Thu Jul 30 12:16:42.893156 2026] [lsapi:error] [pid 703393:tid 703413] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/captain-america-brave-new-world-vj-junior/
[Thu Jul 30 12:16:43.041838 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/engine.php"] [unique_id "amuG-8637Arlr6Yb1EcRDgAAAI8"]
[Thu Jul 30 12:16:43.140177 2026] [security2:error] [pid 703393:tid 703620] [client 20.104.18.253:6676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuG-8637Arlr6Yb1EcREQAAAOY"]
[Thu Jul 30 12:16:43.270566 2026] [security2:error] [pid 703393:tid 703587] [client 51.120.69.65:15657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/24.php"] [unique_id "amuG-8637Arlr6Yb1EcRGAAAAMU"]
[Thu Jul 30 12:16:43.270672 2026] [security2:error] [pid 703393:tid 703587] [client 51.120.69.65:15657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/24.php"] [unique_id "amuG-8637Arlr6Yb1EcRGAAAAMU"]
[Thu Jul 30 12:16:43.729024 2026] [security2:error] [pid 703393:tid 703543] [client 51.120.69.65:16292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/15.php"] [unique_id "amuG-8637Arlr6Yb1EcRKQAAAJk"]
[Thu Jul 30 12:16:43.729140 2026] [security2:error] [pid 703393:tid 703543] [client 51.120.69.65:16292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/15.php"] [unique_id "amuG-8637Arlr6Yb1EcRKQAAAJk"]
[Thu Jul 30 12:16:43.858579 2026] [security2:error] [pid 703393:tid 703581] [client 20.104.18.253:6469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/oauth.php"] [unique_id "amuG-8637Arlr6Yb1EcRKgAAAL8"]
[Thu Jul 30 12:16:43.902493 2026] [security2:error] [pid 703393:tid 703570] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuG-8637Arlr6Yb1EcRGwAAALQ"]
[Thu Jul 30 12:16:44.150393 2026] [security2:error] [pid 703393:tid 703594] [client 20.63.98.115:20553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/edit-comments.php"] [unique_id "amuG_M637Arlr6Yb1EcRMwAAAMw"]
[Thu Jul 30 12:16:44.210032 2026] [security2:error] [pid 703393:tid 703559] [client 51.120.69.65:16326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/123456.php"] [unique_id "amuG_M637Arlr6Yb1EcRNAAAAKk"]
[Thu Jul 30 12:16:44.210150 2026] [security2:error] [pid 703393:tid 703559] [client 51.120.69.65:16326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/123456.php"] [unique_id "amuG_M637Arlr6Yb1EcRNAAAAKk"]
[Thu Jul 30 12:16:44.663759 2026] [proxy:error] [pid 703393:tid 703640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:44.663845 2026] [proxy_http:error] [pid 703393:tid 703640] [client 20.104.18.253:6525] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:44.664415 2026] [proxy:error] [pid 703393:tid 703640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:44.664461 2026] [proxy_http:error] [pid 703393:tid 703640] [client 20.104.18.253:6525] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:44.695216 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/12345.php"] [unique_id "amuG_M637Arlr6Yb1EcRQgAAAKA"]
[Thu Jul 30 12:16:44.695342 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/12345.php"] [unique_id "amuG_M637Arlr6Yb1EcRQgAAAKA"]
[Thu Jul 30 12:16:45.157239 2026] [security2:error] [pid 703393:tid 703532] [client 51.120.69.65:16302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/1234.php"] [unique_id "amuG_c637Arlr6Yb1EcRSwAAAI4"]
[Thu Jul 30 12:16:45.157339 2026] [security2:error] [pid 703393:tid 703532] [client 51.120.69.65:16302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/1234.php"] [unique_id "amuG_c637Arlr6Yb1EcRSwAAAI4"]
[Thu Jul 30 12:16:45.387932 2026] [security2:error] [pid 703393:tid 703553] [client 20.104.18.253:6470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cgi-bin/upfile.php"] [unique_id "amuG_c637Arlr6Yb1EcRUAAAAKM"]
[Thu Jul 30 12:16:45.525615 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:36817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-blog-header.php"] [unique_id "amuG_c637Arlr6Yb1EcRVAAAAJY"]
[Thu Jul 30 12:16:45.753395 2026] [security2:error] [pid 703393:tid 703578] [client 51.120.69.65:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/10.php"] [unique_id "amuG_c637Arlr6Yb1EcRWAAAALw"]
[Thu Jul 30 12:16:45.753515 2026] [security2:error] [pid 703393:tid 703578] [client 51.120.69.65:16270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/10.php"] [unique_id "amuG_c637Arlr6Yb1EcRWAAAALw"]
[Thu Jul 30 12:16:46.222110 2026] [security2:error] [pid 703393:tid 703561] [client 20.104.18.253:6526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/upload_file1.php"] [unique_id "amuG_s637Arlr6Yb1EcRYgAAAKs"]
[Thu Jul 30 12:16:46.244305 2026] [security2:error] [pid 703393:tid 703581] [client 51.120.69.65:16343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/9.php"] [unique_id "amuG_s637Arlr6Yb1EcRYwAAAL8"]
[Thu Jul 30 12:16:46.244402 2026] [security2:error] [pid 703393:tid 703581] [client 51.120.69.65:16343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/9.php"] [unique_id "amuG_s637Arlr6Yb1EcRYwAAAL8"]
[Thu Jul 30 12:16:46.560655 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:20831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/alfa-rex.php7"] [unique_id "amuG_s637Arlr6Yb1EcRZAAAAN0"]
[Thu Jul 30 12:16:46.798851 2026] [security2:error] [pid 703393:tid 703625] [client 51.120.69.65:15621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/8.php"] [unique_id "amuG_s637Arlr6Yb1EcRawAAAOs"]
[Thu Jul 30 12:16:46.798999 2026] [security2:error] [pid 703393:tid 703625] [client 51.120.69.65:15621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/8.php"] [unique_id "amuG_s637Arlr6Yb1EcRawAAAOs"]
[Thu Jul 30 12:16:47.277000 2026] [security2:error] [pid 703393:tid 703546] [client 20.104.18.253:6521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/rafa.php"] [unique_id "amuG_8637Arlr6Yb1EcRcwAAAJw"]
[Thu Jul 30 12:16:47.304017 2026] [security2:error] [pid 703393:tid 703579] [client 51.120.69.65:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/7.php"] [unique_id "amuG_8637Arlr6Yb1EcRdAAAAL0"]
[Thu Jul 30 12:16:47.304104 2026] [security2:error] [pid 703393:tid 703579] [client 51.120.69.65:16335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/7.php"] [unique_id "amuG_8637Arlr6Yb1EcRdAAAAL0"]
[Thu Jul 30 12:16:48.094251 2026] [security2:error] [pid 703393:tid 703557] [client 20.104.18.253:6472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/maint/src_api.php"] [unique_id "amuHAM637Arlr6Yb1EcRfQAAAKc"]
[Thu Jul 30 12:16:48.191709 2026] [security2:error] [pid 703393:tid 703564] [client 20.63.98.115:36825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/pomo/fgertreyersd.php"] [unique_id "amuHAM637Arlr6Yb1EcRgQAAAK4"]
[Thu Jul 30 12:16:48.469525 2026] [security2:error] [pid 703393:tid 703635] [client 51.120.69.65:16284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/6.php"] [unique_id "amuHAM637Arlr6Yb1EcRiQAAAPU"]
[Thu Jul 30 12:16:48.469637 2026] [security2:error] [pid 703393:tid 703635] [client 51.120.69.65:16284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/6.php"] [unique_id "amuHAM637Arlr6Yb1EcRiQAAAPU"]
[Thu Jul 30 12:16:48.609174 2026] [core:notice] [pid 703393:tid 703624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:49.175387 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:16283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/5.php"] [unique_id "amuHAc637Arlr6Yb1EcRkgAAAPg"]
[Thu Jul 30 12:16:49.175531 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:16283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/5.php"] [unique_id "amuHAc637Arlr6Yb1EcRkgAAAPg"]
[Thu Jul 30 12:16:49.315581 2026] [security2:error] [pid 703393:tid 703605] [client 20.104.18.253:6519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/atomlib.php"] [unique_id "amuHAc637Arlr6Yb1EcRmQAAANc"]
[Thu Jul 30 12:16:49.399535 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:21382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/css/xmrlpc.php"] [unique_id "amuHAc637Arlr6Yb1EcRmgAAAI8"]
[Thu Jul 30 12:16:49.407554 2026] [security2:error] [pid 703393:tid 703604] [client 213.152.161.118:49342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuHAc637Arlr6Yb1EcRmwAAANY"]
[Thu Jul 30 12:16:49.407640 2026] [security2:error] [pid 703393:tid 703604] [client 213.152.161.118:49342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuHAc637Arlr6Yb1EcRmwAAANY"]
[Thu Jul 30 12:16:49.608018 2026] [core:notice] [pid 703393:tid 703644] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:49.736721 2026] [security2:error] [pid 703393:tid 703642] [client 51.120.69.65:16319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/4.php"] [unique_id "amuHAc637Arlr6Yb1EcRoAAAAPw"]
[Thu Jul 30 12:16:49.736812 2026] [security2:error] [pid 703393:tid 703642] [client 51.120.69.65:16319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/4.php"] [unique_id "amuHAc637Arlr6Yb1EcRoAAAAPw"]
[Thu Jul 30 12:16:50.240115 2026] [security2:error] [pid 703393:tid 703591] [client 51.120.69.65:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/3.php"] [unique_id "amuHAs637Arlr6Yb1EcRqAAAAMk"]
[Thu Jul 30 12:16:50.240225 2026] [security2:error] [pid 703393:tid 703591] [client 51.120.69.65:16331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/3.php"] [unique_id "amuHAs637Arlr6Yb1EcRqAAAAMk"]
[Thu Jul 30 12:16:50.365457 2026] [security2:error] [pid 703393:tid 703558] [client 20.63.98.115:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/classsmtps.php"] [unique_id "amuHAs637Arlr6Yb1EcRsgAAAKg"]
[Thu Jul 30 12:16:50.727779 2026] [security2:error] [pid 703393:tid 703576] [client 20.104.18.253:6667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-trackback.php"] [unique_id "amuHAs637Arlr6Yb1EcRtQAAALo"]
[Thu Jul 30 12:16:50.742994 2026] [security2:error] [pid 703393:tid 703630] [client 51.120.69.65:16263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/2.php"] [unique_id "amuHAs637Arlr6Yb1EcRtgAAAPA"]
[Thu Jul 30 12:16:50.743109 2026] [security2:error] [pid 703393:tid 703630] [client 51.120.69.65:16263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/2.php"] [unique_id "amuHAs637Arlr6Yb1EcRtgAAAPA"]
[Thu Jul 30 12:16:50.881377 2026] [security2:error] [pid 703393:tid 703525] [client 168.144.252.192:61999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.252.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.emj.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuHAs637Arlr6Yb1EcRvgAAAIc"], referer: https://www.bing.com/
[Thu Jul 30 12:16:51.046990 2026] [security2:error] [pid 703393:tid 703549] [client 103.76.148.17:4759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuHAs637Arlr6Yb1EcRtwAAAJ8"], referer: http://pkf.jo
[Thu Jul 30 12:16:51.234071 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16330] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.guardian-heir.com"] [uri "/1.php"] [unique_id "amuHA8637Arlr6Yb1EcRwAAAAOU"]
[Thu Jul 30 12:16:51.234196 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/1.php"] [unique_id "amuHA8637Arlr6Yb1EcRwAAAAOU"]
[Thu Jul 30 12:16:51.234291 2026] [security2:error] [pid 703393:tid 703619] [client 51.120.69.65:16330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/1.php"] [unique_id "amuHA8637Arlr6Yb1EcRwAAAAOU"]
[Thu Jul 30 12:16:51.329056 2026] [security2:error] [pid 703393:tid 703636] [client 139.47.26.50:59256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuHA8637Arlr6Yb1EcRvwAAAPY"], referer: http://pkf.jo
[Thu Jul 30 12:16:51.432216 2026] [security2:error] [pid 703393:tid 703643] [client 185.191.171.7:38628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/14/semana-santa-gestores-gastam-quase-r-4-milhoes-em-peixes-e-outros-produtos-para-doacoes/"] [unique_id "amuHA8637Arlr6Yb1EcRxwAAAP0"]
[Thu Jul 30 12:16:51.432362 2026] [security2:error] [pid 703393:tid 703643] [client 185.191.171.7:38628] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/14/semana-santa-gestores-gastam-quase-r-4-milhoes-em-peixes-e-outros-produtos-para-doacoes/"] [unique_id "amuHA8637Arlr6Yb1EcRxwAAAP0"]
[Thu Jul 30 12:16:51.748714 2026] [security2:error] [pid 703393:tid 703528] [client 51.120.69.65:15619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/0.php"] [unique_id "amuHA8637Arlr6Yb1EcRyAAAAIo"]
[Thu Jul 30 12:16:51.748832 2026] [security2:error] [pid 703393:tid 703528] [client 51.120.69.65:15619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/0.php"] [unique_id "amuHA8637Arlr6Yb1EcRyAAAAIo"]
[Thu Jul 30 12:16:51.753444 2026] [security2:error] [pid 703393:tid 703599] [client 20.104.18.253:6659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuHA8637Arlr6Yb1EcRyQAAANE"]
[Thu Jul 30 12:16:52.232572 2026] [security2:error] [pid 703393:tid 703524] [client 20.63.98.115:20801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/themes/zMousse/otuz1.php"] [unique_id "amuHBM637Arlr6Yb1EcR0AAAAIY"]
[Thu Jul 30 12:16:52.243103 2026] [security2:error] [pid 703393:tid 703605] [client 51.120.69.65:16291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/z.php"] [unique_id "amuHBM637Arlr6Yb1EcR0QAAANc"]
[Thu Jul 30 12:16:52.243272 2026] [security2:error] [pid 703393:tid 703605] [client 51.120.69.65:16291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/z.php"] [unique_id "amuHBM637Arlr6Yb1EcR0QAAANc"]
[Thu Jul 30 12:16:52.725051 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:16315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/y.php"] [unique_id "amuHBM637Arlr6Yb1EcR3gAAAKQ"]
[Thu Jul 30 12:16:52.725166 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:16315] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/y.php"] [unique_id "amuHBM637Arlr6Yb1EcR3gAAAKQ"]
[Thu Jul 30 12:16:52.733006 2026] [core:notice] [pid 703393:tid 703439] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:52.753329 2026] [security2:error] [pid 703393:tid 703570] [client 20.104.18.253:6490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/doc.php/"] [unique_id "amuHBM637Arlr6Yb1EcR4AAAALQ"]
[Thu Jul 30 12:16:52.952636 2026] [core:notice] [pid 703393:tid 703501] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:52.966405 2026] [security2:error] [pid 703393:tid 703609] [client 160.191.208.12:21981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuHBM637Arlr6Yb1EcR3QAAANs"], referer: http://pkf.jo
[Thu Jul 30 12:16:53.006441 2026] [security2:error] [pid 703393:tid 703615] [client 168.144.252.192:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.252.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.emj.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuHBc637Arlr6Yb1EcR6gAAAOE"]
[Thu Jul 30 12:16:53.184635 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:15659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/x.php"] [unique_id "amuHBc637Arlr6Yb1EcR7gAAAL4"]
[Thu Jul 30 12:16:53.184742 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:15659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/x.php"] [unique_id "amuHBc637Arlr6Yb1EcR7gAAAL4"]
[Thu Jul 30 12:16:53.236633 2026] [security2:error] [pid 703393:tid 703418] [remote 190.92.174.21:48232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amuHBM637Arlr6Yb1EcR6AAAlRg"]
[Thu Jul 30 12:16:53.684928 2026] [security2:error] [pid 703393:tid 703535] [client 51.120.69.65:16372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/w.php"] [unique_id "amuHBc637Arlr6Yb1EcR-wAAAJE"]
[Thu Jul 30 12:16:53.685056 2026] [security2:error] [pid 703393:tid 703535] [client 51.120.69.65:16372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/w.php"] [unique_id "amuHBc637Arlr6Yb1EcR-wAAAJE"]
[Thu Jul 30 12:16:54.172801 2026] [security2:error] [pid 703393:tid 703602] [client 51.120.69.65:16337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/v.php"] [unique_id "amuHBs637Arlr6Yb1EcSBgAAANQ"]
[Thu Jul 30 12:16:54.172919 2026] [security2:error] [pid 703393:tid 703602] [client 51.120.69.65:16337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/v.php"] [unique_id "amuHBs637Arlr6Yb1EcSBgAAANQ"]
[Thu Jul 30 12:16:54.666489 2026] [security2:error] [pid 703393:tid 703536] [client 51.120.69.65:16379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/u.php"] [unique_id "amuHBs637Arlr6Yb1EcSFgAAAJI"]
[Thu Jul 30 12:16:54.666599 2026] [security2:error] [pid 703393:tid 703536] [client 51.120.69.65:16379] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/u.php"] [unique_id "amuHBs637Arlr6Yb1EcSFgAAAJI"]
[Thu Jul 30 12:16:55.254390 2026] [security2:error] [pid 703393:tid 703558] [client 51.120.69.65:15629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/s.php"] [unique_id "amuHB8637Arlr6Yb1EcSKgAAAKg"]
[Thu Jul 30 12:16:55.254532 2026] [security2:error] [pid 703393:tid 703558] [client 51.120.69.65:15629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/s.php"] [unique_id "amuHB8637Arlr6Yb1EcSKgAAAKg"]
[Thu Jul 30 12:16:55.401734 2026] [core:notice] [pid 703393:tid 703454] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:55.881830 2026] [security2:error] [pid 703393:tid 703557] [client 20.104.18.253:6486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/error_exception.php"] [unique_id "amuHB8637Arlr6Yb1EcSNQAAAKc"]
[Thu Jul 30 12:16:56.016942 2026] [core:error] [pid 703393:tid 703564] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:16:56.016967 2026] [core:error] [pid 703393:tid 703564] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:16:56.099765 2026] [core:notice] [pid 703393:tid 703529] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:56.119285 2026] [security2:error] [pid 703393:tid 703636] [client 51.120.69.65:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/t.php"] [unique_id "amuHCM637Arlr6Yb1EcSPgAAAPY"]
[Thu Jul 30 12:16:56.119372 2026] [security2:error] [pid 703393:tid 703636] [client 51.120.69.65:16354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/t.php"] [unique_id "amuHCM637Arlr6Yb1EcSPgAAAPY"]
[Thu Jul 30 12:16:56.618152 2026] [security2:error] [pid 703393:tid 703649] [client 51.120.69.65:16259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/r.php"] [unique_id "amuHCM637Arlr6Yb1EcSRQAAAQM"]
[Thu Jul 30 12:16:56.618257 2026] [security2:error] [pid 703393:tid 703649] [client 51.120.69.65:16259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/r.php"] [unique_id "amuHCM637Arlr6Yb1EcSRQAAAQM"]
[Thu Jul 30 12:16:56.669283 2026] [security2:error] [pid 703393:tid 703643] [client 20.104.18.253:6481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/infos.php"] [unique_id "amuHCM637Arlr6Yb1EcSRwAAAP0"]
[Thu Jul 30 12:16:57.233024 2026] [security2:error] [pid 703393:tid 703548] [client 20.63.98.115:20584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/123.php"] [unique_id "amuHCc637Arlr6Yb1EcSUgAAAJ4"]
[Thu Jul 30 12:16:57.280237 2026] [security2:error] [pid 703393:tid 703531] [client 51.120.69.65:16256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/q.php"] [unique_id "amuHCc637Arlr6Yb1EcSWAAAAI0"]
[Thu Jul 30 12:16:57.280370 2026] [security2:error] [pid 703393:tid 703531] [client 51.120.69.65:16256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/q.php"] [unique_id "amuHCc637Arlr6Yb1EcSWAAAAI0"]
[Thu Jul 30 12:16:57.791260 2026] [core:notice] [pid 703393:tid 703468] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:16:57.830582 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/p.php"] [unique_id "amuHCc637Arlr6Yb1EcSaAAAAKA"]
[Thu Jul 30 12:16:57.830721 2026] [security2:error] [pid 703393:tid 703550] [client 51.120.69.65:16381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/p.php"] [unique_id "amuHCc637Arlr6Yb1EcSaAAAAKA"]
[Thu Jul 30 12:16:58.473515 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:16290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/n.php"] [unique_id "amuHCs637Arlr6Yb1EcSeAAAAMA"]
[Thu Jul 30 12:16:58.473636 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:16290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/n.php"] [unique_id "amuHCs637Arlr6Yb1EcSeAAAAMA"]
[Thu Jul 30 12:16:58.489802 2026] [security2:error] [pid 703393:tid 703627] [client 20.63.98.115:21427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuHCs637Arlr6Yb1EcSeQAAAO0"]
[Thu Jul 30 12:16:58.719850 2026] [security2:error] [pid 703393:tid 703543] [client 20.104.18.253:6465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/contact.php"] [unique_id "amuHCs637Arlr6Yb1EcSfQAAAJk"]
[Thu Jul 30 12:16:58.983641 2026] [security2:error] [pid 703393:tid 703567] [client 51.120.69.65:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/o.php"] [unique_id "amuHCs637Arlr6Yb1EcSjgAAALE"]
[Thu Jul 30 12:16:58.983763 2026] [security2:error] [pid 703393:tid 703567] [client 51.120.69.65:16347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/o.php"] [unique_id "amuHCs637Arlr6Yb1EcSjgAAALE"]
[Thu Jul 30 12:16:59.445623 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:15713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/m.php"] [unique_id "amuHC8637Arlr6Yb1EcSlgAAAKQ"]
[Thu Jul 30 12:16:59.445709 2026] [security2:error] [pid 703393:tid 703554] [client 51.120.69.65:15713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/m.php"] [unique_id "amuHC8637Arlr6Yb1EcSlgAAAKQ"]
[Thu Jul 30 12:16:59.506303 2026] [proxy:error] [pid 703393:tid 703614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:59.506382 2026] [proxy_http:error] [pid 703393:tid 703614] [client 20.104.18.253:6493] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:59.506945 2026] [proxy:error] [pid 703393:tid 703614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:16:59.507010 2026] [proxy_http:error] [pid 703393:tid 703614] [client 20.104.18.253:6493] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:16:59.566135 2026] [security2:error] [pid 703393:tid 703551] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHCs637Arlr6Yb1EcSigAAoQ4"]
[Thu Jul 30 12:16:59.992084 2026] [security2:error] [pid 703393:tid 703621] [client 51.120.69.65:16294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/l.php"] [unique_id "amuHC8637Arlr6Yb1EcSqQAAAOc"]
[Thu Jul 30 12:16:59.992195 2026] [security2:error] [pid 703393:tid 703621] [client 51.120.69.65:16294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/l.php"] [unique_id "amuHC8637Arlr6Yb1EcSqQAAAOc"]
[Thu Jul 30 12:17:00.124636 2026] [security2:error] [pid 703393:tid 703582] [client 168.144.252.192:64237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.252.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.remoteworksit.com"] [uri "/wp-login.php"] [unique_id "amuHDM637Arlr6Yb1EcSrAAAAMA"], referer: https://wordpress.org/
[Thu Jul 30 12:17:00.270607 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:20575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/filebrowser.php"] [unique_id "amuHDM637Arlr6Yb1EcStgAAAN0"]
[Thu Jul 30 12:17:00.341848 2026] [security2:error] [pid 703393:tid 703643] [client 20.104.18.253:6474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/user.php"] [unique_id "amuHDM637Arlr6Yb1EcSuQAAAP0"]
[Thu Jul 30 12:17:00.488773 2026] [security2:error] [pid 703393:tid 703495] [remote 57.141.0.11:24360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4627290655/feed/rss2/"] [unique_id "amuHDM637Arlr6Yb1EcSwgAAvGU"]
[Thu Jul 30 12:17:00.709565 2026] [security2:error] [pid 703393:tid 703537] [client 51.120.69.65:15680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/k.php"] [unique_id "amuHDM637Arlr6Yb1EcS0AAAAJM"]
[Thu Jul 30 12:17:00.709704 2026] [security2:error] [pid 703393:tid 703537] [client 51.120.69.65:15680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/k.php"] [unique_id "amuHDM637Arlr6Yb1EcS0AAAAJM"]
[Thu Jul 30 12:17:01.138588 2026] [security2:error] [pid 703393:tid 703540] [client 51.120.69.65:16374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/j.php"] [unique_id "amuHDc637Arlr6Yb1EcS4wAAAJY"]
[Thu Jul 30 12:17:01.138728 2026] [security2:error] [pid 703393:tid 703540] [client 51.120.69.65:16374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/j.php"] [unique_id "amuHDc637Arlr6Yb1EcS4wAAAJY"]
[Thu Jul 30 12:17:01.300474 2026] [security2:error] [pid 703393:tid 703588] [client 20.104.18.253:6705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/env.php"] [unique_id "amuHDc637Arlr6Yb1EcS5wAAAMY"]
[Thu Jul 30 12:17:01.716860 2026] [security2:error] [pid 703393:tid 703578] [client 51.120.69.65:15658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/i.php"] [unique_id "amuHDc637Arlr6Yb1EcTMwAAALw"]
[Thu Jul 30 12:17:01.717074 2026] [security2:error] [pid 703393:tid 703578] [client 51.120.69.65:15658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/i.php"] [unique_id "amuHDc637Arlr6Yb1EcTMwAAALw"]
[Thu Jul 30 12:17:02.037471 2026] [security2:error] [pid 703393:tid 703633] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHDc637Arlr6Yb1EcS_gAAAPM"]
[Thu Jul 30 12:17:02.123482 2026] [security2:error] [pid 703393:tid 703605] [client 20.63.98.115:21503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/makeasmtp.php"] [unique_id "amuHDs637Arlr6Yb1EcTUgAAANc"]
[Thu Jul 30 12:17:02.135171 2026] [security2:error] [pid 703393:tid 703626] [client 20.104.18.253:6503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/uploads/de_fb_uploads/b.php"] [unique_id "amuHDs637Arlr6Yb1EcTUwAAAOw"]
[Thu Jul 30 12:17:02.250176 2026] [security2:error] [pid 703393:tid 703560] [client 51.120.69.65:15645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/h.php"] [unique_id "amuHDs637Arlr6Yb1EcTVQAAAKo"]
[Thu Jul 30 12:17:02.250376 2026] [security2:error] [pid 703393:tid 703560] [client 51.120.69.65:15645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/h.php"] [unique_id "amuHDs637Arlr6Yb1EcTVQAAAKo"]
[Thu Jul 30 12:17:02.983826 2026] [security2:error] [pid 703393:tid 703591] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHDs637Arlr6Yb1EcTWgAAAMk"]
[Thu Jul 30 12:17:03.021140 2026] [security2:error] [pid 703393:tid 703611] [client 20.104.18.253:6495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known//index.php"] [unique_id "amuHD8637Arlr6Yb1EcTcAAAAN0"]
[Thu Jul 30 12:17:03.430579 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:20816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/bypass.php"] [unique_id "amuHD8637Arlr6Yb1EcTegAAAKU"]
[Thu Jul 30 12:17:03.499800 2026] [security2:error] [pid 703393:tid 703613] [client 51.120.69.65:16273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/g.php"] [unique_id "amuHD8637Arlr6Yb1EcTfQAAAN8"]
[Thu Jul 30 12:17:03.499914 2026] [security2:error] [pid 703393:tid 703613] [client 51.120.69.65:16273] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/g.php"] [unique_id "amuHD8637Arlr6Yb1EcTfQAAAN8"]
[Thu Jul 30 12:17:03.844885 2026] [security2:error] [pid 703393:tid 703543] [client 58.69.103.164:43632] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.remoteworksit.com"] [uri "/wp-comments-post.php"] [unique_id "amuHD8637Arlr6Yb1EcTeQAAAJk"]
[Thu Jul 30 12:17:03.979183 2026] [security2:error] [pid 703393:tid 703552] [client 20.104.18.253:6511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/blog/wp-content/plugins/ubh/up.php"] [unique_id "amuHD8637Arlr6Yb1EcThgAAAKI"]
[Thu Jul 30 12:17:04.001091 2026] [security2:error] [pid 703393:tid 703543] [client 58.69.103.164:43632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.remoteworksit.com"] [uri "/wp-comments-post.php"] [unique_id "amuHD8637Arlr6Yb1EcTeQAAAJk"]
[Thu Jul 30 12:17:04.039946 2026] [security2:error] [pid 703393:tid 703612] [client 51.120.69.65:16314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/f.php"] [unique_id "amuHEM637Arlr6Yb1EcThwAAAN4"]
[Thu Jul 30 12:17:04.040071 2026] [security2:error] [pid 703393:tid 703612] [client 51.120.69.65:16314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/f.php"] [unique_id "amuHEM637Arlr6Yb1EcThwAAAN4"]
[Thu Jul 30 12:17:04.521455 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/e.php"] [unique_id "amuHEM637Arlr6Yb1EcTjwAAAMA"]
[Thu Jul 30 12:17:04.521569 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:16332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/e.php"] [unique_id "amuHEM637Arlr6Yb1EcTjwAAAMA"]
[Thu Jul 30 12:17:04.906377 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:15721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/d.php"] [unique_id "amuHEM637Arlr6Yb1EcTmgAAAPg"]
[Thu Jul 30 12:17:04.906517 2026] [security2:error] [pid 703393:tid 703638] [client 51.120.69.65:15721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/d.php"] [unique_id "amuHEM637Arlr6Yb1EcTmgAAAPg"]
[Thu Jul 30 12:17:05.148532 2026] [security2:error] [pid 703393:tid 703583] [client 20.104.18.253:6665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/edit.php"] [unique_id "amuHEc637Arlr6Yb1EcTmwAAAME"]
[Thu Jul 30 12:17:05.251420 2026] [core:notice] [pid 703393:tid 703526] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:05.473434 2026] [security2:error] [pid 703393:tid 703644] [client 51.120.69.65:16309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/c.php"] [unique_id "amuHEc637Arlr6Yb1EcTpgAAAP4"]
[Thu Jul 30 12:17:05.473536 2026] [security2:error] [pid 703393:tid 703644] [client 51.120.69.65:16309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/c.php"] [unique_id "amuHEc637Arlr6Yb1EcTpgAAAP4"]
[Thu Jul 30 12:17:05.945172 2026] [proxy:error] [pid 703393:tid 703539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:05.945254 2026] [proxy_http:error] [pid 703393:tid 703539] [client 20.104.18.253:6477] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:05.945806 2026] [proxy:error] [pid 703393:tid 703539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:05.945848 2026] [proxy_http:error] [pid 703393:tid 703539] [client 20.104.18.253:6477] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:06.289310 2026] [security2:error] [pid 703393:tid 703626] [client 51.120.69.65:16271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/b.php"] [unique_id "amuHEs637Arlr6Yb1EcTtQAAAOw"]
[Thu Jul 30 12:17:06.289413 2026] [security2:error] [pid 703393:tid 703626] [client 51.120.69.65:16271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/b.php"] [unique_id "amuHEs637Arlr6Yb1EcTtQAAAOw"]
[Thu Jul 30 12:17:06.710468 2026] [security2:error] [pid 703393:tid 703587] [client 20.104.18.253:6510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/locks.php"] [unique_id "amuHEs637Arlr6Yb1EcTvgAAAMU"]
[Thu Jul 30 12:17:06.711437 2026] [security2:error] [pid 703393:tid 703565] [client 20.63.98.115:21499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/pi.php"] [unique_id "amuHEs637Arlr6Yb1EcTvwAAAK8"]
[Thu Jul 30 12:17:06.751253 2026] [security2:error] [pid 703393:tid 703478] [remote 144.79.133.30:52248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahm.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuHEs637Arlr6Yb1EcTwAAA5lQ"]
[Thu Jul 30 12:17:06.783811 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:15665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/indexc.php"] [unique_id "amuHEs637Arlr6Yb1EcTxAAAAMA"]
[Thu Jul 30 12:17:06.783913 2026] [security2:error] [pid 703393:tid 703582] [client 51.120.69.65:15665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/indexc.php"] [unique_id "amuHEs637Arlr6Yb1EcTxAAAAMA"]
[Thu Jul 30 12:17:07.328096 2026] [security2:error] [pid 703393:tid 703634] [client 51.120.69.65:16301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuHE8637Arlr6Yb1EcTzwAAAPQ"]
[Thu Jul 30 12:17:07.328197 2026] [security2:error] [pid 703393:tid 703634] [client 51.120.69.65:16301] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuHE8637Arlr6Yb1EcTzwAAAPQ"]
[Thu Jul 30 12:17:07.583109 2026] [security2:error] [pid 703393:tid 703638] [client 20.104.18.253:6478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfa-rex1.php"] [unique_id "amuHE8637Arlr6Yb1EcT1wAAAPg"]
[Thu Jul 30 12:17:07.726034 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:16355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuHE8637Arlr6Yb1EcT2AAAAL4"]
[Thu Jul 30 12:17:07.726173 2026] [security2:error] [pid 703393:tid 703580] [client 51.120.69.65:16355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuHE8637Arlr6Yb1EcT2AAAAL4"]
[Thu Jul 30 12:17:08.257401 2026] [security2:error] [pid 703393:tid 703576] [client 51.120.69.65:16329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuHFM637Arlr6Yb1EcT3QAAALo"]
[Thu Jul 30 12:17:08.257518 2026] [security2:error] [pid 703393:tid 703576] [client 51.120.69.65:16329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuHFM637Arlr6Yb1EcT3QAAALo"]
[Thu Jul 30 12:17:08.348523 2026] [security2:error] [pid 703393:tid 703550] [client 20.104.18.253:6514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/uploads/gfwisone.php"] [unique_id "amuHFM637Arlr6Yb1EcT4AAAAKA"]
[Thu Jul 30 12:17:08.936699 2026] [security2:error] [pid 703393:tid 703551] [client 51.120.69.65:16316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/.561988674612251.php"] [unique_id "amuHFM637Arlr6Yb1EcT6AAAAKE"]
[Thu Jul 30 12:17:08.936830 2026] [security2:error] [pid 703393:tid 703551] [client 51.120.69.65:16316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/.561988674612251.php"] [unique_id "amuHFM637Arlr6Yb1EcT6AAAAKE"]
[Thu Jul 30 12:17:09.152545 2026] [security2:error] [pid 703393:tid 703626] [client 20.104.18.253:6803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/rex/l/flower.php"] [unique_id "amuHFc637Arlr6Yb1EcT7QAAAOw"]
[Thu Jul 30 12:17:09.771756 2026] [security2:error] [pid 703393:tid 703618] [client 51.120.69.65:15701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/indexw.php"] [unique_id "amuHFc637Arlr6Yb1EcT_QAAAOQ"]
[Thu Jul 30 12:17:09.771903 2026] [security2:error] [pid 703393:tid 703618] [client 51.120.69.65:15701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/indexw.php"] [unique_id "amuHFc637Arlr6Yb1EcT_QAAAOQ"]
[Thu Jul 30 12:17:10.141477 2026] [proxy:error] [pid 703393:tid 703535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:10.141565 2026] [proxy_http:error] [pid 703393:tid 703535] [client 20.104.18.253:6669] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:10.142128 2026] [proxy:error] [pid 703393:tid 703535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:10.142172 2026] [proxy_http:error] [pid 703393:tid 703535] [client 20.104.18.253:6669] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:10.440942 2026] [security2:error] [pid 703393:tid 703622] [client 51.120.69.65:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/.284214373991941.php"] [unique_id "amuHFs637Arlr6Yb1EcUBgAAAOg"]
[Thu Jul 30 12:17:10.441072 2026] [security2:error] [pid 703393:tid 703622] [client 51.120.69.65:16368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/.284214373991941.php"] [unique_id "amuHFs637Arlr6Yb1EcUBgAAAOg"]
[Thu Jul 30 12:17:10.608604 2026] [security2:error] [pid 703393:tid 703530] [client 20.63.98.115:21497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-seo.php"] [unique_id "amuHFs637Arlr6Yb1EcUDQAAAIw"]
[Thu Jul 30 12:17:11.227136 2026] [proxy:error] [pid 703393:tid 703632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:11.227224 2026] [proxy_http:error] [pid 703393:tid 703632] [client 20.104.18.253:6691] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:11.227787 2026] [proxy:error] [pid 703393:tid 703632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:11.227830 2026] [proxy_http:error] [pid 703393:tid 703632] [client 20.104.18.253:6691] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:11.365837 2026] [security2:error] [pid 703393:tid 703539] [client 51.120.69.65:15651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/.109753674214724.php"] [unique_id "amuHF8637Arlr6Yb1EcUFQAAAJU"]
[Thu Jul 30 12:17:11.366011 2026] [security2:error] [pid 703393:tid 703539] [client 51.120.69.65:15651] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/.109753674214724.php"] [unique_id "amuHF8637Arlr6Yb1EcUFQAAAJU"]
[Thu Jul 30 12:17:11.546485 2026] [security2:error] [pid 703393:tid 703538] [client 20.63.98.115:21471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/gebase.php69"] [unique_id "amuHF8637Arlr6Yb1EcUGgAAAJQ"]
[Thu Jul 30 12:17:11.931199 2026] [security2:error] [pid 703393:tid 703552] [client 51.120.69.65:14020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/kjihe.php"] [unique_id "amuHF8637Arlr6Yb1EcUHgAAAKI"]
[Thu Jul 30 12:17:11.931307 2026] [security2:error] [pid 703393:tid 703552] [client 51.120.69.65:14020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/kjihe.php"] [unique_id "amuHF8637Arlr6Yb1EcUHgAAAKI"]
[Thu Jul 30 12:17:12.048758 2026] [security2:error] [pid 703393:tid 703599] [client 20.104.18.253:6500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/user/post.php"] [unique_id "amuHGM637Arlr6Yb1EcUIgAAANE"]
[Thu Jul 30 12:17:12.563923 2026] [security2:error] [pid 703393:tid 703616] [client 51.120.69.65:15630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.69.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guardian-heir.com"] [uri "/Uploading.php"] [unique_id "amuHGM637Arlr6Yb1EcUKgAAAOI"]
[Thu Jul 30 12:17:12.564051 2026] [security2:error] [pid 703393:tid 703616] [client 51.120.69.65:15630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.guardian-heir.com"] [uri "/Uploading.php"] [unique_id "amuHGM637Arlr6Yb1EcUKgAAAOI"]
[Thu Jul 30 12:17:13.557747 2026] [security2:error] [pid 703393:tid 703618] [client 50.6.43.217:47026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuHGM637Arlr6Yb1EcUNwAAAOQ"]
[Thu Jul 30 12:17:13.604826 2026] [security2:error] [pid 703393:tid 703584] [client 20.63.98.115:58080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/config.php"] [unique_id "amuHGc637Arlr6Yb1EcURAAAAMI"]
[Thu Jul 30 12:17:13.638686 2026] [proxy:error] [pid 703393:tid 703559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:13.638753 2026] [proxy_http:error] [pid 703393:tid 703559] [client 20.104.18.253:6494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:13.639496 2026] [proxy:error] [pid 703393:tid 703559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:13.639547 2026] [proxy_http:error] [pid 703393:tid 703559] [client 20.104.18.253:6494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:13.802339 2026] [security2:error] [pid 703393:tid 703576] [client 184.75.223.195:33100] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuHGc637Arlr6Yb1EcUTgAAALo"]
[Thu Jul 30 12:17:13.802448 2026] [security2:error] [pid 703393:tid 703576] [client 184.75.223.195:33100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuHGc637Arlr6Yb1EcUTgAAALo"]
[Thu Jul 30 12:17:14.308422 2026] [security2:error] [pid 703393:tid 703594] [client 50.6.43.217:47068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuHGc637Arlr6Yb1EcUQAAAAMw"]
[Thu Jul 30 12:17:14.475832 2026] [security2:error] [pid 703393:tid 703597] [client 74.7.244.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "owz.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuHGs637Arlr6Yb1EcUZQAAAM8"]
[Thu Jul 30 12:17:14.476581 2026] [security2:error] [pid 703393:tid 703602] [client 74.7.244.25:59308] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "owz.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuHGs637Arlr6Yb1EcUYwAA1E4"]
[Thu Jul 30 12:17:14.670424 2026] [security2:error] [pid 703393:tid 703571] [client 209.35.163.56:55557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuHGs637Arlr6Yb1EcUbwAAtQs"]
[Thu Jul 30 12:17:14.711616 2026] [security2:error] [pid 703393:tid 703563] [client 20.63.98.115:20551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ws.php"] [unique_id "amuHGs637Arlr6Yb1EcUcwAAAK0"]
[Thu Jul 30 12:17:14.927085 2026] [security2:error] [pid 703393:tid 703645] [client 20.104.18.253:6523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/file5.php"] [unique_id "amuHGs637Arlr6Yb1EcUfgAAAP8"]
[Thu Jul 30 12:17:15.098283 2026] [security2:error] [pid 703393:tid 703490] [remote 40.77.167.55:63183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/agro_sintesa/article/view/2911/1555"] [unique_id "amuHG8637Arlr6Yb1EcUgQAAwmA"]
[Thu Jul 30 12:17:15.166455 2026] [proxy:error] [pid 703393:tid 703511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:15.166519 2026] [proxy_http:error] [pid 703393:tid 703511] [remote 74.7.244.12:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:15.167103 2026] [proxy:error] [pid 703393:tid 703511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:15.167152 2026] [proxy_http:error] [pid 703393:tid 703511] [remote 74.7.244.12:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:15.398413 2026] [security2:error] [pid 703393:tid 703635] [client 74.7.244.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.vietnambitcoin.app"] [uri "/index.php"] [unique_id "amuHGs637Arlr6Yb1EcUawAAAPU"]
[Thu Jul 30 12:17:15.399190 2026] [security2:error] [pid 703393:tid 703649] [client 74.7.244.42:44034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.vietnambitcoin.app"] [uri "/robots.txt"] [unique_id "amuHGs637Arlr6Yb1EcUaQABAzI"]
[Thu Jul 30 12:17:15.639892 2026] [security2:error] [pid 703393:tid 703548] [client 74.7.241.155:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.kool-shop.com"] [uri "/index.php"] [unique_id "amuHGs637Arlr6Yb1EcUeQAAAJ4"]
[Thu Jul 30 12:17:15.640625 2026] [security2:error] [pid 703393:tid 703615] [client 74.7.241.155:36894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.kool-shop.com"] [uri "/robots.txt"] [unique_id "amuHGs637Arlr6Yb1EcUdwAA4RQ"]
[Thu Jul 30 12:17:16.245915 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:20604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin/function.php"] [unique_id "amuHHM637Arlr6Yb1EcUogAAAI8"]
[Thu Jul 30 12:17:16.824206 2026] [proxy:error] [pid 703393:tid 703626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:16.824293 2026] [proxy_http:error] [pid 703393:tid 703626] [client 20.104.18.253:6479] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:16.824851 2026] [proxy:error] [pid 703393:tid 703626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:16.824894 2026] [proxy_http:error] [pid 703393:tid 703626] [client 20.104.18.253:6479] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:17.825735 2026] [proxy:error] [pid 703393:tid 703638] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:17.825821 2026] [proxy_http:error] [pid 703393:tid 703638] [client 20.104.18.253:6476] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:17.826419 2026] [proxy:error] [pid 703393:tid 703638] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:17.826467 2026] [proxy_http:error] [pid 703393:tid 703638] [client 20.104.18.253:6476] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:17.961324 2026] [security2:error] [pid 703393:tid 703579] [client 195.113.175.167:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/index.php"] [unique_id "amuHHc637Arlr6Yb1EcUtAAAAL0"]
[Thu Jul 30 12:17:18.135959 2026] [security2:error] [pid 703393:tid 703531] [client 57.141.0.29:26336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuHHc637Arlr6Yb1EcUtgAAjTM"], referer: https://igetvape-australia.com/store/?product-page=1&add-to-cart=108
[Thu Jul 30 12:17:18.651253 2026] [proxy:error] [pid 703393:tid 703633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:18.651351 2026] [proxy_http:error] [pid 703393:tid 703633] [client 20.104.18.253:6706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:18.651895 2026] [proxy:error] [pid 703393:tid 703633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:18.651938 2026] [proxy_http:error] [pid 703393:tid 703633] [client 20.104.18.253:6706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:19.207630 2026] [core:notice] [pid 703393:tid 703590] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:19.481434 2026] [security2:error] [pid 703393:tid 703634] [client 20.104.18.253:6695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/query-standard-post.php"] [unique_id "amuHH8637Arlr6Yb1EcU5AAAAPQ"]
[Thu Jul 30 12:17:19.613244 2026] [security2:error] [pid 703393:tid 703547] [client 68.235.38.2:59194] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuHH8637Arlr6Yb1EcU5QAAAJ0"]
[Thu Jul 30 12:17:19.613371 2026] [security2:error] [pid 703393:tid 703547] [client 68.235.38.2:59194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuHH8637Arlr6Yb1EcU5QAAAJ0"]
[Thu Jul 30 12:17:20.114004 2026] [core:notice] [pid 703393:tid 703491] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:20.294957 2026] [security2:error] [pid 703393:tid 703565] [client 5.161.117.52:1442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuHHs637Arlr6Yb1EcU1wAAAK8"], referer: https://globalmarks.pk/
[Thu Jul 30 12:17:20.414245 2026] [security2:error] [pid 703393:tid 703600] [client 20.104.18.253:6719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/images/include.php"] [unique_id "amuHIM637Arlr6Yb1EcVAAAAANI"]
[Thu Jul 30 12:17:20.775922 2026] [security2:error] [pid 703393:tid 703539] [client 77.83.36.161:1869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuHIM637Arlr6Yb1EcVAQAAAJU"]
[Thu Jul 30 12:17:20.808594 2026] [core:notice] [pid 703393:tid 703435] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:21.331610 2026] [security2:error] [pid 703393:tid 703617] [client 77.83.36.161:2379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuHIc637Arlr6Yb1EcVCgAAAOM"]
[Thu Jul 30 12:17:21.673902 2026] [security2:error] [pid 703393:tid 703618] [client 20.63.98.115:58088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "amuHIc637Arlr6Yb1EcVEQAAAOQ"]
[Thu Jul 30 12:17:21.880625 2026] [security2:error] [pid 703393:tid 703554] [client 20.104.18.253:6527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/--wp-lgj.php"] [unique_id "amuHIc637Arlr6Yb1EcVFQAAAKQ"]
[Thu Jul 30 12:17:21.894559 2026] [security2:error] [pid 703393:tid 703584] [client 77.83.36.161:2710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuHIc637Arlr6Yb1EcVFgAAAMI"]
[Thu Jul 30 12:17:21.931599 2026] [security2:error] [pid 703393:tid 703467] [remote 74.7.241.59:50424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuHIc637Arlr6Yb1EcVFwAAx0k"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:17:22.541513 2026] [security2:error] [pid 703393:tid 703614] [client 20.63.98.115:43925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/about.php"] [unique_id "amuHIs637Arlr6Yb1EcVIQAAAOA"]
[Thu Jul 30 12:17:22.676516 2026] [security2:error] [pid 703393:tid 703538] [client 20.104.18.253:6671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-p.php"] [unique_id "amuHIs637Arlr6Yb1EcVJQAAAJQ"]
[Thu Jul 30 12:17:23.482281 2026] [proxy:error] [pid 703393:tid 703528] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:23.482379 2026] [proxy_http:error] [pid 703393:tid 703528] [client 20.104.18.253:6466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:23.482933 2026] [proxy:error] [pid 703393:tid 703528] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:23.482990 2026] [proxy_http:error] [pid 703393:tid 703528] [client 20.104.18.253:6466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:23.495743 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:58066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuHI8637Arlr6Yb1EcVMgAAAMU"]
[Thu Jul 30 12:17:23.777288 2026] [security2:error] [pid 703393:tid 703488] [remote 74.7.241.60:36938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/article.php"] [unique_id "amuHI8637Arlr6Yb1EcVNgAAoV4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 12:17:23.864734 2026] [autoindex:error] [pid 703393:tid 703573] [client 43.166.226.57:33622] AH01276: Cannot serve directory /home2/evmudite/public_html/wp/wp-content/plugins/wp-google-map-plugin/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:17:24.348931 2026] [security2:error] [pid 703393:tid 703639] [client 20.104.18.253:6517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/ectoplasm/flower.php"] [unique_id "amuHJM637Arlr6Yb1EcVQgAAAPk"]
[Thu Jul 30 12:17:24.934321 2026] [security2:error] [pid 703393:tid 703627] [client 177.230.27.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVPgAAAO0"]
[Thu Jul 30 12:17:25.085644 2026] [security2:error] [pid 703393:tid 703640] [client 20.63.98.115:21220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/2024/index.php"] [unique_id "amuHJc637Arlr6Yb1EcVVwAAAPo"]
[Thu Jul 30 12:17:25.229263 2026] [security2:error] [pid 703393:tid 703537] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVSgAAkxM"]
[Thu Jul 30 12:17:25.251905 2026] [security2:error] [pid 703393:tid 703585] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVSQAAAMM"]
[Thu Jul 30 12:17:25.385649 2026] [security2:error] [pid 703393:tid 703568] [client 20.104.18.253:6660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuHJc637Arlr6Yb1EcVXwAAALI"]
[Thu Jul 30 12:17:25.546601 2026] [security2:error] [pid 703393:tid 703603] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVUgAAANU"]
[Thu Jul 30 12:17:25.698761 2026] [security2:error] [pid 703393:tid 703606] [client 131.226.103.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "palmtreepools.ca"] [uri "/index.php"] [unique_id "amuHJM637Arlr6Yb1EcVRgAAANg"]
[Thu Jul 30 12:17:26.304195 2026] [security2:error] [pid 703393:tid 703591] [client 20.104.18.253:6485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/autoload_classmap.php"] [unique_id "amuHJs637Arlr6Yb1EcVbgAAAMk"]
[Thu Jul 30 12:17:27.012904 2026] [security2:error] [pid 703393:tid 703546] [client 185.191.171.19:19482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inmobiliariadia.com"] [uri "/robots.txt"] [unique_id "amuHJ8637Arlr6Yb1EcVewAAAJw"]
[Thu Jul 30 12:17:27.013062 2026] [security2:error] [pid 703393:tid 703546] [client 185.191.171.19:19482] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "inmobiliariadia.com"] [uri "/robots.txt"] [unique_id "amuHJ8637Arlr6Yb1EcVewAAAJw"]
[Thu Jul 30 12:17:27.028721 2026] [proxy:error] [pid 703393:tid 703576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:27.028815 2026] [proxy_http:error] [pid 703393:tid 703576] [client 20.104.18.253:6468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:27.029571 2026] [proxy:error] [pid 703393:tid 703576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:17:27.029620 2026] [proxy_http:error] [pid 703393:tid 703576] [client 20.104.18.253:6468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:17:27.896883 2026] [security2:error] [pid 703393:tid 703568] [client 85.208.96.205:41042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inmobiliariadia.com"] [uri "/"] [unique_id "amuHJ8637Arlr6Yb1EcViQAAALI"]
[Thu Jul 30 12:17:27.897003 2026] [security2:error] [pid 703393:tid 703568] [client 85.208.96.205:41042] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "inmobiliariadia.com"] [uri "/"] [unique_id "amuHJ8637Arlr6Yb1EcViQAAALI"]
[Thu Jul 30 12:17:27.947645 2026] [security2:error] [pid 703393:tid 703593] [client 20.63.98.115:21189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/cong.php"] [unique_id "amuHJ8637Arlr6Yb1EcVigAAAMs"]
[Thu Jul 30 12:17:28.251454 2026] [security2:error] [pid 703393:tid 703637] [client 20.104.18.253:6506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/rxxdfx/xleet.php"] [unique_id "amuHKM637Arlr6Yb1EcVlAAAAPc"]
[Thu Jul 30 12:17:28.875684 2026] [core:notice] [pid 703393:tid 703512] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:28.914955 2026] [security2:error] [pid 703393:tid 703617] [client 114.119.144.15:45283] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "globalmarks.pk"] [uri "/wp-content/uploads/2021/08/Mission-icon-1.png"] [unique_id "amuHKM637Arlr6Yb1EcVowAAAOM"], referer: https://globalmarks.pk/wp-content/uploads/2021/08/Mission-icon-1.png
[Thu Jul 30 12:17:29.095149 2026] [security2:error] [pid 703393:tid 703641] [client 20.104.18.253:6522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/module.tag.idv1.php"] [unique_id "amuHKc637Arlr6Yb1EcVpQAAAPs"]
[Thu Jul 30 12:17:29.179957 2026] [security2:error] [pid 703393:tid 703587] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHKM637Arlr6Yb1EcVmwAAAMU"]
[Thu Jul 30 12:17:29.342197 2026] [security2:error] [pid 703393:tid 703569] [client 20.63.98.115:49226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/languages/about.php"] [unique_id "amuHKc637Arlr6Yb1EcVrQAAALM"]
[Thu Jul 30 12:17:29.418731 2026] [core:notice] [pid 703393:tid 703646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:29.849937 2026] [core:notice] [pid 703393:tid 703579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:29.999033 2026] [security2:error] [pid 703393:tid 703550] [client 20.104.18.253:6670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/packed.php"] [unique_id "amuHKc637Arlr6Yb1EcVvgAAAKA"]
[Thu Jul 30 12:17:30.846513 2026] [lsapi:error] [pid 703393:tid 703461] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/wolf-man-vj-junior/
[Thu Jul 30 12:17:30.950251 2026] [security2:error] [pid 703393:tid 703608] [client 20.104.18.253:6707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/css/F0x.php"] [unique_id "amuHKs637Arlr6Yb1EcV1gAAANo"]
[Thu Jul 30 12:17:31.826409 2026] [security2:error] [pid 703393:tid 703575] [client 20.104.18.253:6825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/view.php"] [unique_id "amuHK8637Arlr6Yb1EcV5wAAALk"]
[Thu Jul 30 12:17:31.893507 2026] [core:notice] [pid 703393:tid 703597] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:32.380917 2026] [security2:error] [pid 703393:tid 703405] [remote 5.56.58.49:40450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.56.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/wp-login.php"] [unique_id "amuHLM637Arlr6Yb1EcV9AAA9Qs"]
[Thu Jul 30 12:17:32.561871 2026] [security2:error] [pid 703393:tid 703603] [client 50.6.43.217:32490] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuHLM637Arlr6Yb1EcWAAAAANU"]
[Thu Jul 30 12:17:32.594057 2026] [security2:error] [pid 703393:tid 703625] [client 50.6.43.217:32498] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuHLM637Arlr6Yb1EcWBAAAAOs"]
[Thu Jul 30 12:17:32.789009 2026] [security2:error] [pid 703393:tid 703647] [client 20.63.98.115:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/edit.php"] [unique_id "amuHLM637Arlr6Yb1EcWCwAAAQE"]
[Thu Jul 30 12:17:33.333353 2026] [security2:error] [pid 703393:tid 703552] [client 20.104.18.253:6812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/blocks/site-title/index.php"] [unique_id "amuHLc637Arlr6Yb1EcWFQAAAKI"]
[Thu Jul 30 12:17:33.408822 2026] [security2:error] [pid 703393:tid 703571] [client 74.7.244.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-32717c4b.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHLM637Arlr6Yb1EcWAwAAALU"]
[Thu Jul 30 12:17:33.409641 2026] [security2:error] [pid 703393:tid 703593] [client 74.7.244.42:42142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-32717c4b.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuHLM637Arlr6Yb1EcWAQAAyxE"]
[Thu Jul 30 12:17:34.142947 2026] [security2:error] [pid 703393:tid 703589] [client 20.104.18.253:6491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/GOD.php"] [unique_id "amuHLs637Arlr6Yb1EcWIQAAAMc"]
[Thu Jul 30 12:17:34.783100 2026] [security2:error] [pid 703393:tid 703546] [client 213.152.161.118:56932] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuHLs637Arlr6Yb1EcWKgAAAJw"]
[Thu Jul 30 12:17:34.783207 2026] [security2:error] [pid 703393:tid 703546] [client 213.152.161.118:56932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuHLs637Arlr6Yb1EcWKgAAAJw"]
[Thu Jul 30 12:17:35.199841 2026] [security2:error] [pid 703393:tid 703629] [client 20.104.18.253:6488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuHL8637Arlr6Yb1EcWMQAAAO8"]
[Thu Jul 30 12:17:35.788705 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:21292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/about/function.php"] [unique_id "amuHL8637Arlr6Yb1EcWPQAAAJY"]
[Thu Jul 30 12:17:35.959454 2026] [security2:error] [pid 703393:tid 703591] [client 20.104.18.253:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-configs.php"] [unique_id "amuHL8637Arlr6Yb1EcWQgAAAMk"]
[Thu Jul 30 12:17:36.941100 2026] [security2:error] [pid 703393:tid 703610] [client 20.104.18.253:6484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/contrjibus.php"] [unique_id "amuHMM637Arlr6Yb1EcWTwAAANw"]
[Thu Jul 30 12:17:37.054725 2026] [security2:error] [pid 703393:tid 703587] [client 20.63.98.115:43941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/simple/function.php"] [unique_id "amuHMc637Arlr6Yb1EcWUwAAAMU"]
[Thu Jul 30 12:17:37.964394 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:21248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mah/function.php"] [unique_id "amuHMc637Arlr6Yb1EcWXgAAAOg"]
[Thu Jul 30 12:17:38.045972 2026] [security2:error] [pid 703393:tid 703579] [client 20.104.18.253:6662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/contentloader1.php"] [unique_id "amuHMs637Arlr6Yb1EcWXwAAAL0"]
[Thu Jul 30 12:17:38.943597 2026] [security2:error] [pid 703393:tid 703551] [client 20.63.98.115:36866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/go.php"] [unique_id "amuHMs637Arlr6Yb1EcWbQAAAKE"]
[Thu Jul 30 12:17:38.968219 2026] [security2:error] [pid 703393:tid 703532] [client 20.104.18.253:6658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/F0x.php"] [unique_id "amuHMs637Arlr6Yb1EcWbgAAAI4"]
[Thu Jul 30 12:17:39.678550 2026] [security2:error] [pid 703393:tid 703570] [client 20.104.18.253:6675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/item.php"] [unique_id "amuHM8637Arlr6Yb1EcWewAAALQ"]
[Thu Jul 30 12:17:39.846230 2026] [security2:error] [pid 703393:tid 703524] [client 20.63.98.115:32954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/buy.php"] [unique_id "amuHM8637Arlr6Yb1EcWgAAAAIY"]
[Thu Jul 30 12:17:41.717075 2026] [security2:error] [pid 703393:tid 703607] [client 20.63.98.115:39173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/astra/inc/ki1k.php"] [unique_id "amuHNc637Arlr6Yb1EcWogAAANk"]
[Thu Jul 30 12:17:42.639145 2026] [core:notice] [pid 703393:tid 703524] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:44.161770 2026] [core:notice] [pid 703393:tid 703565] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:44.406863 2026] [core:notice] [pid 703393:tid 703620] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:45.599877 2026] [core:notice] [pid 703393:tid 703636] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:45.845827 2026] [core:notice] [pid 703393:tid 703581] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:17:47.718479 2026] [security2:error] [pid 703393:tid 703650] [client 20.63.98.115:47332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wq.php7"] [unique_id "amuHO8637Arlr6Yb1EcXAQAAAQQ"]
[Thu Jul 30 12:17:50.612919 2026] [security2:error] [pid 703393:tid 703536] [client 20.91.199.21:46517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/LA.php"] [unique_id "amuHPs637Arlr6Yb1EcXKQAAAJI"]
[Thu Jul 30 12:17:51.060070 2026] [security2:error] [pid 703393:tid 703563] [client 20.63.98.115:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/forum.php"] [unique_id "amuHP8637Arlr6Yb1EcXMAAAAK0"]
[Thu Jul 30 12:17:51.801488 2026] [security2:error] [pid 703393:tid 703540] [client 20.91.199.21:40328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/admin.php"] [unique_id "amuHP8637Arlr6Yb1EcXQQAAAJY"]
[Thu Jul 30 12:17:51.903231 2026] [security2:error] [pid 703393:tid 703633] [client 20.63.98.115:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/5index.php"] [unique_id "amuHP8637Arlr6Yb1EcXQgAAAPM"]
[Thu Jul 30 12:17:52.505987 2026] [core:error] [pid 703393:tid 703523] [client 4.240.96.129:61453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Thu Jul 30 12:17:52.506011 2026] [core:error] [pid 703393:tid 703523] [client 4.240.96.129:61453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Thu Jul 30 12:17:53.471296 2026] [security2:error] [pid 703393:tid 703598] [client 20.91.199.21:32962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/class_api.php"] [unique_id "amuHQc637Arlr6Yb1EcXYgAAANA"]
[Thu Jul 30 12:17:54.240694 2026] [security2:error] [pid 703393:tid 703546] [client 20.91.199.21:34154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuHQs637Arlr6Yb1EcXawAAAJw"]
[Thu Jul 30 12:17:55.110241 2026] [security2:error] [pid 703393:tid 703550] [client 20.63.98.115:47354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cookie.php"] [unique_id "amuHQ8637Arlr6Yb1EcXegAAAKA"]
[Thu Jul 30 12:17:55.597088 2026] [security2:error] [pid 703393:tid 703417] [remote 72.167.132.114:40044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.zjp.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuHQ8637Arlr6Yb1EcXhAAA8Rc"]
[Thu Jul 30 12:17:55.804471 2026] [security2:error] [pid 703393:tid 703558] [client 20.91.199.21:32984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuHQ8637Arlr6Yb1EcXhwAAAKg"]
[Thu Jul 30 12:17:56.032152 2026] [security2:error] [pid 703393:tid 703607] [client 49.51.253.26:54416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.253.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/theme/darm_theme_basic01/page_html/company_organization.php"] [unique_id "amuHQ8637Arlr6Yb1EcXhgAAANk"]
[Thu Jul 30 12:17:56.431610 2026] [security2:error] [pid 703393:tid 703593] [client 20.91.199.21:46478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuHRM637Arlr6Yb1EcXkAAAAMs"]
[Thu Jul 30 12:17:56.526716 2026] [security2:error] [pid 703393:tid 703535] [client 20.63.98.115:62408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/edit-form.php"] [unique_id "amuHRM637Arlr6Yb1EcXlgAAAJE"]
[Thu Jul 30 12:17:57.172763 2026] [security2:error] [pid 703393:tid 703527] [client 20.91.199.21:34159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/991176.php"] [unique_id "amuHRc637Arlr6Yb1EcXngAAAIk"]
[Thu Jul 30 12:17:57.571265 2026] [security2:error] [pid 703393:tid 703614] [client 185.191.171.10:51514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/18/tudo-muito-magico-diz-ivete-sangalo-sobre-final-do-masked-singer/"] [unique_id "amuHRc637Arlr6Yb1EcXpQAAAOA"]
[Thu Jul 30 12:17:57.571390 2026] [security2:error] [pid 703393:tid 703614] [client 185.191.171.10:51514] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/18/tudo-muito-magico-diz-ivete-sangalo-sobre-final-do-masked-singer/"] [unique_id "amuHRc637Arlr6Yb1EcXpQAAAOA"]
[Thu Jul 30 12:17:58.462653 2026] [security2:error] [pid 703393:tid 703605] [client 20.63.98.115:38942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/aleXus.php"] [unique_id "amuHRs637Arlr6Yb1EcXtQAAANc"]
[Thu Jul 30 12:17:58.518340 2026] [security2:error] [pid 703393:tid 703557] [client 20.91.199.21:40381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuHRs637Arlr6Yb1EcXtgAAAKc"]
[Thu Jul 30 12:17:58.541695 2026] [core:error] [pid 703393:tid 703611] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.541727 2026] [core:error] [pid 703393:tid 703611] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.649416 2026] [core:error] [pid 703393:tid 703637] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.649436 2026] [core:error] [pid 703393:tid 703637] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.674016 2026] [core:error] [pid 703393:tid 703533] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.674036 2026] [core:error] [pid 703393:tid 703533] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.707773 2026] [core:error] [pid 703393:tid 703619] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.707794 2026] [core:error] [pid 703393:tid 703619] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.730971 2026] [core:error] [pid 703393:tid 703569] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:58.731012 2026] [core:error] [pid 703393:tid 703569] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:17:59.341684 2026] [security2:error] [pid 703393:tid 703538] [client 20.63.98.115:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/user.php"] [unique_id "amuHR8637Arlr6Yb1EcX6AAAAJQ"]
[Thu Jul 30 12:17:59.866597 2026] [security2:error] [pid 703393:tid 703531] [client 20.91.199.21:46483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuHR8637Arlr6Yb1EcYBwAAAI0"]
[Thu Jul 30 12:18:00.202480 2026] [core:error] [pid 703393:tid 703583] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:00.202525 2026] [core:error] [pid 703393:tid 703583] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:00.309274 2026] [security2:error] [pid 703393:tid 703568] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHR8637Arlr6Yb1EcYAgAAsgI"]
[Thu Jul 30 12:18:00.851418 2026] [lsapi:error] [pid 703393:tid 703460] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/about-time-vj-junior/
[Thu Jul 30 12:18:00.938416 2026] [security2:error] [pid 703393:tid 703575] [client 20.91.199.21:34123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuHSM637Arlr6Yb1EcYNQAAALk"]
[Thu Jul 30 12:18:01.729173 2026] [security2:error] [pid 703393:tid 703613] [client 20.91.199.21:35170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuHSc637Arlr6Yb1EcYQAAAAN8"]
[Thu Jul 30 12:18:01.928730 2026] [security2:error] [pid 703393:tid 703622] [client 216.244.66.243:38406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/louis-vuitton/oc2-outrigger-canoe-for-sale"] [unique_id "amuHSc637Arlr6Yb1EcYSAAAAOg"]
[Thu Jul 30 12:18:01.928890 2026] [security2:error] [pid 703393:tid 703622] [client 216.244.66.243:38406] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arabiandubaisafari.com"] [uri "/louis-vuitton/oc2-outrigger-canoe-for-sale"] [unique_id "amuHSc637Arlr6Yb1EcYSAAAAOg"]
[Thu Jul 30 12:18:02.942231 2026] [security2:error] [pid 703393:tid 703563] [client 57.141.0.43:40058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuHSs637Arlr6Yb1EcYTwAArWg"], referer: https://igetvape-australia.com/product/alibarbar-pandora-7000-puffs-12/?add-to-cart=1016
[Thu Jul 30 12:18:03.337878 2026] [core:notice] [pid 703393:tid 703631] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.340852 2026] [core:notice] [pid 703393:tid 703542] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.345563 2026] [core:notice] [pid 703393:tid 703580] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.350148 2026] [core:notice] [pid 703393:tid 703633] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.350148 2026] [core:notice] [pid 703393:tid 703586] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.357931 2026] [core:notice] [pid 703393:tid 703578] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.378239 2026] [core:notice] [pid 703393:tid 703540] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.380627 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:62448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ab1ux1ft.php"] [unique_id "amuHS8637Arlr6Yb1EcYZwAAAI8"]
[Thu Jul 30 12:18:03.386252 2026] [core:notice] [pid 703393:tid 703587] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:03.449390 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.199.21:34116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuHS8637Arlr6Yb1EcYagAAAIY"]
[Thu Jul 30 12:18:03.721727 2026] [security2:error] [pid 703393:tid 703572] [client 74.7.244.35:57974] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pvl.djb.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuHS8637Arlr6Yb1EcYbgAAtj0"]
[Thu Jul 30 12:18:04.512030 2026] [core:notice] [pid 703393:tid 703538] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:06.570719 2026] [security2:error] [pid 703393:tid 703541] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHTM637Arlr6Yb1EcYhQAAAJc"]
[Thu Jul 30 12:18:06.829473 2026] [security2:error] [pid 703393:tid 703532] [client 20.91.199.21:32626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuHTc637Arlr6Yb1EcYkwAAAI4"]
[Thu Jul 30 12:18:06.984594 2026] [security2:error] [pid 703393:tid 703645] [client 20.91.199.21:32626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuHTs637Arlr6Yb1EcYrAAAAP8"]
[Thu Jul 30 12:18:07.559033 2026] [security2:error] [pid 703393:tid 703620] [client 172.237.109.114:56849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYrQAAAOY"]
[Thu Jul 30 12:18:07.560804 2026] [security2:error] [pid 703393:tid 703548] [client 172.237.109.114:55493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYrgAAAJ4"]
[Thu Jul 30 12:18:07.563291 2026] [security2:error] [pid 703393:tid 703592] [client 172.237.109.114:5473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYrwAAAMo"]
[Thu Jul 30 12:18:07.570163 2026] [security2:error] [pid 703393:tid 703546] [client 172.237.109.114:54750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYqgAAAJw"]
[Thu Jul 30 12:18:07.571575 2026] [security2:error] [pid 703393:tid 703629] [client 20.91.199.21:46473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuHT8637Arlr6Yb1EcYvAAAAO8"]
[Thu Jul 30 12:18:07.576108 2026] [security2:error] [pid 703393:tid 703526] [client 172.237.109.114:19855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuHTs637Arlr6Yb1EcYqwAAAIg"]
[Thu Jul 30 12:18:07.897421 2026] [security2:error] [pid 703393:tid 703557] [client 20.63.98.115:49124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/home/function.php"] [unique_id "amuHT8637Arlr6Yb1EcYwAAAAKc"]
[Thu Jul 30 12:18:07.931053 2026] [security2:error] [pid 703393:tid 703619] [client 20.215.186.36:12550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/coba.php"] [unique_id "amuHT8637Arlr6Yb1EcYwQAAAOU"]
[Thu Jul 30 12:18:07.931172 2026] [security2:error] [pid 703393:tid 703619] [client 20.215.186.36:12550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/coba.php"] [unique_id "amuHT8637Arlr6Yb1EcYwQAAAOU"]
[Thu Jul 30 12:18:08.161547 2026] [security2:error] [pid 703393:tid 703617] [client 20.151.221.234:35105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wk/index.php"] [unique_id "amuHUM637Arlr6Yb1EcYyAAAAOM"]
[Thu Jul 30 12:18:08.242674 2026] [security2:error] [pid 703393:tid 703576] [client 20.215.186.36:12568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/replace.php"] [unique_id "amuHUM637Arlr6Yb1EcYyQAAALo"]
[Thu Jul 30 12:18:08.242781 2026] [security2:error] [pid 703393:tid 703576] [client 20.215.186.36:12568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/replace.php"] [unique_id "amuHUM637Arlr6Yb1EcYyQAAALo"]
[Thu Jul 30 12:18:08.464167 2026] [security2:error] [pid 703393:tid 703439] [remote 52.167.144.217:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/issue/view/16"] [unique_id "amuHUM637Arlr6Yb1EcY0gAA8C0"]
[Thu Jul 30 12:18:08.577940 2026] [security2:error] [pid 703393:tid 703638] [client 20.215.186.36:12436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/echo.php"] [unique_id "amuHUM637Arlr6Yb1EcY1gAAAPg"]
[Thu Jul 30 12:18:08.578076 2026] [security2:error] [pid 703393:tid 703638] [client 20.215.186.36:12436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/echo.php"] [unique_id "amuHUM637Arlr6Yb1EcY1gAAAPg"]
[Thu Jul 30 12:18:08.669040 2026] [security2:error] [pid 703393:tid 703605] [client 20.91.199.21:34471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuHUM637Arlr6Yb1EcY2wAAANc"]
[Thu Jul 30 12:18:08.853791 2026] [security2:error] [pid 703393:tid 703580] [client 20.63.98.115:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-login.php"] [unique_id "amuHUM637Arlr6Yb1EcY1wAAAL4"]
[Thu Jul 30 12:18:08.917266 2026] [security2:error] [pid 703393:tid 703614] [client 20.215.186.36:12580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/haxor.php"] [unique_id "amuHUM637Arlr6Yb1EcY3QAAAOA"]
[Thu Jul 30 12:18:08.917383 2026] [security2:error] [pid 703393:tid 703614] [client 20.215.186.36:12580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/haxor.php"] [unique_id "amuHUM637Arlr6Yb1EcY3QAAAOA"]
[Thu Jul 30 12:18:09.230686 2026] [security2:error] [pid 703393:tid 703613] [client 20.215.186.36:12421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/sym.php"] [unique_id "amuHUc637Arlr6Yb1EcY5QAAAN8"]
[Thu Jul 30 12:18:09.230845 2026] [security2:error] [pid 703393:tid 703613] [client 20.215.186.36:12421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/sym.php"] [unique_id "amuHUc637Arlr6Yb1EcY5QAAAN8"]
[Thu Jul 30 12:18:09.260682 2026] [security2:error] [pid 703393:tid 703541] [client 20.91.199.21:35178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuHUc637Arlr6Yb1EcY5gAAAJc"]
[Thu Jul 30 12:18:09.336292 2026] [security2:error] [pid 703393:tid 703591] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHUM637Arlr6Yb1EcY3AAAySw"]
[Thu Jul 30 12:18:09.541795 2026] [security2:error] [pid 703393:tid 703564] [client 20.215.186.36:12602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/symlink.php"] [unique_id "amuHUc637Arlr6Yb1EcY7AAAAK4"]
[Thu Jul 30 12:18:09.541901 2026] [security2:error] [pid 703393:tid 703564] [client 20.215.186.36:12602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/symlink.php"] [unique_id "amuHUc637Arlr6Yb1EcY7AAAAK4"]
[Thu Jul 30 12:18:09.634506 2026] [security2:error] [pid 703393:tid 703645] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHUc637Arlr6Yb1EcY6QAAAP8"]
[Thu Jul 30 12:18:09.715490 2026] [security2:error] [pid 703393:tid 703594] [client 20.151.221.234:35094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/av.php"] [unique_id "amuHUc637Arlr6Yb1EcY8wAAAMw"]
[Thu Jul 30 12:18:09.905805 2026] [security2:error] [pid 703393:tid 703568] [client 20.215.186.36:12420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/sym403.php"] [unique_id "amuHUc637Arlr6Yb1EcY9QAAALI"]
[Thu Jul 30 12:18:09.905931 2026] [security2:error] [pid 703393:tid 703568] [client 20.215.186.36:12420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/sym403.php"] [unique_id "amuHUc637Arlr6Yb1EcY9QAAALI"]
[Thu Jul 30 12:18:09.979014 2026] [security2:error] [pid 703393:tid 703527] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHUc637Arlr6Yb1EcY6gAAiXQ"]
[Thu Jul 30 12:18:10.039511 2026] [security2:error] [pid 703393:tid 703595] [client 20.63.98.115:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/upgrade/about.php"] [unique_id "amuHUs637Arlr6Yb1EcY9gAAAM0"]
[Thu Jul 30 12:18:10.066242 2026] [security2:error] [pid 703393:tid 703523] [client 20.91.199.21:33959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuHUs637Arlr6Yb1EcY9wAAAIU"]
[Thu Jul 30 12:18:10.219215 2026] [security2:error] [pid 703393:tid 703604] [client 20.215.186.36:12459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/fw.php"] [unique_id "amuHUs637Arlr6Yb1EcY-wAAANY"]
[Thu Jul 30 12:18:10.219310 2026] [security2:error] [pid 703393:tid 703604] [client 20.215.186.36:12459] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/fw.php"] [unique_id "amuHUs637Arlr6Yb1EcY-wAAANY"]
[Thu Jul 30 12:18:10.538300 2026] [security2:error] [pid 703393:tid 703586] [client 20.215.186.36:12430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/xyz.php"] [unique_id "amuHUs637Arlr6Yb1EcZAgAAAMQ"]
[Thu Jul 30 12:18:10.538426 2026] [security2:error] [pid 703393:tid 703586] [client 20.215.186.36:12430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/xyz.php"] [unique_id "amuHUs637Arlr6Yb1EcZAgAAAMQ"]
[Thu Jul 30 12:18:10.930996 2026] [security2:error] [pid 703393:tid 703553] [client 20.215.186.36:12437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.186.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ai-kr.com"] [uri "/tolol.php"] [unique_id "amuHUs637Arlr6Yb1EcZCQAAAKM"]
[Thu Jul 30 12:18:10.931114 2026] [security2:error] [pid 703393:tid 703553] [client 20.215.186.36:12437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.ai-kr.com"] [uri "/tolol.php"] [unique_id "amuHUs637Arlr6Yb1EcZCQAAAKM"]
[Thu Jul 30 12:18:11.303951 2026] [security2:error] [pid 703393:tid 703578] [client 20.91.199.21:10801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuHU8637Arlr6Yb1EcZEAAAALw"]
[Thu Jul 30 12:18:11.356117 2026] [core:error] [pid 703393:tid 703445] [remote 216.73.217.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:11.356138 2026] [core:error] [pid 703393:tid 703445] [remote 216.73.217.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:12.016479 2026] [security2:error] [pid 703393:tid 703542] [client 20.151.221.234:35451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/mini.php"] [unique_id "amuHVM637Arlr6Yb1EcZHAAAAJg"]
[Thu Jul 30 12:18:12.134715 2026] [security2:error] [pid 703393:tid 703613] [client 77.83.36.161:30044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amuHVM637Arlr6Yb1EcZHQAAAN8"]
[Thu Jul 30 12:18:12.494514 2026] [security2:error] [pid 703393:tid 703544] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHU8637Arlr6Yb1EcZGgAAmjg"]
[Thu Jul 30 12:18:12.556587 2026] [security2:error] [pid 703393:tid 703629] [client 202.21.121.117:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.121.21.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vertexroofsolutions.com"] [uri "/xmlrpc.php"] [unique_id "amuHVM637Arlr6Yb1EcZJwAAAO8"]
[Thu Jul 30 12:18:12.556702 2026] [security2:error] [pid 703393:tid 703629] [client 202.21.121.117:63931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vertexroofsolutions.com"] [uri "/xmlrpc.php"] [unique_id "amuHVM637Arlr6Yb1EcZJwAAAO8"]
[Thu Jul 30 12:18:12.792291 2026] [security2:error] [pid 703393:tid 703538] [client 77.83.36.161:30355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amuHVM637Arlr6Yb1EcZLAAAAJQ"]
[Thu Jul 30 12:18:12.973660 2026] [security2:error] [pid 703393:tid 703568] [client 20.63.98.115:62435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp.php"] [unique_id "amuHVM637Arlr6Yb1EcZMQAAALI"]
[Thu Jul 30 12:18:13.371534 2026] [security2:error] [pid 703393:tid 703551] [client 77.83.36.161:30694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amuHVc637Arlr6Yb1EcZNQAAAKE"]
[Thu Jul 30 12:18:13.392678 2026] [security2:error] [pid 703393:tid 703639] [client 20.151.221.234:35519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/aa.php"] [unique_id "amuHVc637Arlr6Yb1EcZNgAAAPk"]
[Thu Jul 30 12:18:14.148150 2026] [security2:error] [pid 703393:tid 703553] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHVc637Arlr6Yb1EcZPAAAAKM"]
[Thu Jul 30 12:18:14.296407 2026] [security2:error] [pid 703393:tid 703642] [client 20.63.98.115:62442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Requests/library/about.php"] [unique_id "amuHVs637Arlr6Yb1EcZQAAAAPw"]
[Thu Jul 30 12:18:14.638383 2026] [security2:error] [pid 703393:tid 703616] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHVs637Arlr6Yb1EcZQwAAAOI"]
[Thu Jul 30 12:18:14.765732 2026] [security2:error] [pid 703393:tid 703640] [client 20.151.221.234:35487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/w.php"] [unique_id "amuHVs637Arlr6Yb1EcZSgAAAPo"]
[Thu Jul 30 12:18:14.884466 2026] [security2:error] [pid 703393:tid 703615] [client 103.245.38.203:53564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "ajakholding.net"] [uri "/"] [unique_id "amuHVs637Arlr6Yb1EcZSwAAAOE"]
[Thu Jul 30 12:18:14.925822 2026] [security2:error] [pid 703393:tid 703603] [client 195.113.175.167:1400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/indexf.php"] [unique_id "amuHVs637Arlr6Yb1EcZTwAAANU"]
[Thu Jul 30 12:18:15.499270 2026] [security2:error] [pid 703393:tid 703636] [client 20.91.199.21:11029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuHV8637Arlr6Yb1EcZWwAAAPY"]
[Thu Jul 30 12:18:15.895135 2026] [security2:error] [pid 703393:tid 703591] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHV8637Arlr6Yb1EcZUwAAySk"]
[Thu Jul 30 12:18:16.215870 2026] [security2:error] [pid 703393:tid 703608] [client 20.91.199.21:11154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuHWM637Arlr6Yb1EcZaQAAANo"]
[Thu Jul 30 12:18:16.222520 2026] [security2:error] [pid 703393:tid 703619] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuHWM637Arlr6Yb1EcZagAAAOU"]
[Thu Jul 30 12:18:16.484868 2026] [security2:error] [pid 703393:tid 703589] [client 82.102.18.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lapakjitu78.com"] [uri "/xmlrpc.php"] [unique_id "amuHWM637Arlr6Yb1EcZbgAAAMc"]
[Thu Jul 30 12:18:17.079761 2026] [security2:error] [pid 703393:tid 703614] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuHWc637Arlr6Yb1EcZdgAAAOA"]
[Thu Jul 30 12:18:17.134172 2026] [security2:error] [pid 703393:tid 703570] [client 114.119.158.113:32081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltaedu.net"] [uri "/category/expense-in-china/"] [unique_id "amuHWc637Arlr6Yb1EcZegAAALQ"], referer: http://deltaedu.net/category/expense-in-china/
[Thu Jul 30 12:18:17.187780 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.199.21:10776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuHWc637Arlr6Yb1EcZewAAAIY"]
[Thu Jul 30 12:18:17.238067 2026] [security2:error] [pid 703393:tid 703577] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuHWc637Arlr6Yb1EcZfAAAALs"]
[Thu Jul 30 12:18:17.491083 2026] [security2:error] [pid 703393:tid 703562] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuHWc637Arlr6Yb1EcZfQAAAKw"]
[Thu Jul 30 12:18:17.614495 2026] [security2:error] [pid 703393:tid 703622] [client 20.63.98.115:63163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/index.php"] [unique_id "amuHWc637Arlr6Yb1EcZhAAAAOg"]
[Thu Jul 30 12:18:17.760633 2026] [security2:error] [pid 703393:tid 703525] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuHWc637Arlr6Yb1EcZhgAAAIc"]
[Thu Jul 30 12:18:18.007518 2026] [security2:error] [pid 703393:tid 703627] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuHWs637Arlr6Yb1EcZhwAAAO0"]
[Thu Jul 30 12:18:18.048208 2026] [security2:error] [pid 703393:tid 703569] [client 102.51.21.89:47669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuHWc637Arlr6Yb1EcZhQAAALM"]
[Thu Jul 30 12:18:18.257035 2026] [security2:error] [pid 703393:tid 703595] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuHWs637Arlr6Yb1EcZjwAAAM0"]
[Thu Jul 30 12:18:18.506288 2026] [security2:error] [pid 703393:tid 703538] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuHWs637Arlr6Yb1EcZkAAAAJQ"]
[Thu Jul 30 12:18:18.759227 2026] [security2:error] [pid 703393:tid 703559] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuHWs637Arlr6Yb1EcZlwAAAKk"]
[Thu Jul 30 12:18:19.006930 2026] [security2:error] [pid 703393:tid 703533] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuHW8637Arlr6Yb1EcZmQAAAI8"]
[Thu Jul 30 12:18:19.246081 2026] [security2:error] [pid 703393:tid 703611] [client 20.63.98.115:49137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/asasx.php"] [unique_id "amuHW8637Arlr6Yb1EcZoQAAAN0"]
[Thu Jul 30 12:18:19.259790 2026] [security2:error] [pid 703393:tid 703626] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuHW8637Arlr6Yb1EcZogAAAOw"]
[Thu Jul 30 12:18:19.334053 2026] [security2:error] [pid 703393:tid 703628] [client 20.91.199.21:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/bek.php"] [unique_id "amuHW8637Arlr6Yb1EcZowAAAO4"]
[Thu Jul 30 12:18:19.480905 2026] [core:notice] [pid 703393:tid 703580] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:19.520417 2026] [security2:error] [pid 703393:tid 703644] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuHW8637Arlr6Yb1EcZpgAAAP4"]
[Thu Jul 30 12:18:19.793118 2026] [security2:error] [pid 703393:tid 703602] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuHW8637Arlr6Yb1EcZsQAAANQ"]
[Thu Jul 30 12:18:20.055020 2026] [security2:error] [pid 703393:tid 703542] [client 20.91.199.21:10786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuHXM637Arlr6Yb1EcZugAAAJg"]
[Thu Jul 30 12:18:20.061716 2026] [security2:error] [pid 703393:tid 703594] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuHXM637Arlr6Yb1EcZuwAAAMw"]
[Thu Jul 30 12:18:20.388351 2026] [security2:error] [pid 703393:tid 703625] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuHXM637Arlr6Yb1EcZxAAAAOs"]
[Thu Jul 30 12:18:20.640007 2026] [security2:error] [pid 703393:tid 703581] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuHXM637Arlr6Yb1EcZyAAAAL8"]
[Thu Jul 30 12:18:20.682216 2026] [security2:error] [pid 703393:tid 703523] [client 20.91.199.21:33978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/class.api.php"] [unique_id "amuHXM637Arlr6Yb1EcZywAAAIU"]
[Thu Jul 30 12:18:20.902998 2026] [security2:error] [pid 703393:tid 703634] [client 20.63.98.115:65290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/user/wp-login.php"] [unique_id "amuHXM637Arlr6Yb1EcZ0gAAAPQ"]
[Thu Jul 30 12:18:20.913838 2026] [security2:error] [pid 703393:tid 703624] [client 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.lapakjitu78.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuHXM637Arlr6Yb1EcZ0wAAAOo"]
[Thu Jul 30 12:18:21.207794 2026] [security2:error] [pid 703393:tid 703631] [client 52.167.144.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHXM637Arlr6Yb1EcZ0QAAAPE"]
[Thu Jul 30 12:18:22.633542 2026] [security2:error] [pid 703393:tid 703618] [client 52.167.144.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHXs637Arlr6Yb1EcZ5QAAAOQ"]
[Thu Jul 30 12:18:24.144654 2026] [security2:error] [pid 703393:tid 703552] [client 20.91.199.21:10763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/cong.php"] [unique_id "amuHYM637Arlr6Yb1EcaAgAAAKI"]
[Thu Jul 30 12:18:24.251802 2026] [security2:error] [pid 703393:tid 703628] [client 20.63.98.115:63110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "amuHYM637Arlr6Yb1EcaAwAAAO4"]
[Thu Jul 30 12:18:24.341502 2026] [security2:error] [pid 703393:tid 703498] [remote 74.7.241.60:41576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuHYM637Arlr6Yb1EcaBwABAWg"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:18:24.758726 2026] [core:notice] [pid 703393:tid 703634] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:25.084966 2026] [security2:error] [pid 703393:tid 703588] [client 20.63.98.115:64863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/radio.php"] [unique_id "amuHYc637Arlr6Yb1EcaFQAAAMY"]
[Thu Jul 30 12:18:25.349614 2026] [security2:error] [pid 703393:tid 703572] [client 158.173.25.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "appliancerepairservice.one"] [uri "/index.php"] [unique_id "amuHYM637Arlr6Yb1EcaEQAAthk"]
[Thu Jul 30 12:18:25.535822 2026] [security2:error] [pid 703393:tid 703566] [client 20.91.199.21:10706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/content.php"] [unique_id "amuHYc637Arlr6Yb1EcaHQAAALA"]
[Thu Jul 30 12:18:25.941868 2026] [security2:error] [pid 703393:tid 703641] [client 40.77.167.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHYc637Arlr6Yb1EcaIwAAAPs"]
[Thu Jul 30 12:18:26.501679 2026] [security2:error] [pid 703393:tid 703546] [client 20.63.98.115:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/about.php"] [unique_id "amuHYs637Arlr6Yb1EcaMQAAAJw"]
[Thu Jul 30 12:18:26.520103 2026] [security2:error] [pid 703393:tid 703593] [client 150.223.194.180:52635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.194.223.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-login.php"] [unique_id "amuHYs637Arlr6Yb1EcaLAAAAMs"]
[Thu Jul 30 12:18:26.935588 2026] [security2:error] [pid 703393:tid 703401] [remote 74.7.241.59:37632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuHYs637Arlr6Yb1EcaNgAA8wc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:18:27.202677 2026] [security2:error] [pid 703393:tid 703622] [client 20.91.199.21:10777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuHY8637Arlr6Yb1EcaQAAAAOg"]
[Thu Jul 30 12:18:27.508184 2026] [proxy:error] [pid 703393:tid 703537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:18:27.508256 2026] [proxy_http:error] [pid 703393:tid 703537] [client 74.7.241.144:57376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:18:27.508836 2026] [proxy:error] [pid 703393:tid 703537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:18:27.508881 2026] [proxy_http:error] [pid 703393:tid 703537] [client 74.7.241.144:57376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:18:27.509012 2026] [security2:error] [pid 703393:tid 703537] [client 74.7.241.144:57376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.nmk.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuHY8637Arlr6Yb1EcaRgAAAJM"]
[Thu Jul 30 12:18:28.014824 2026] [security2:error] [pid 703393:tid 703524] [client 20.91.199.21:10692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/elp.php"] [unique_id "amuHZM637Arlr6Yb1EcaTgAAAIY"]
[Thu Jul 30 12:18:28.588149 2026] [security2:error] [pid 703393:tid 703620] [client 74.7.228.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuHZM637Arlr6Yb1EcaVAAAAOY"]
[Thu Jul 30 12:18:28.589151 2026] [security2:error] [pid 703393:tid 703550] [client 74.7.228.41:33592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tereashops.com"] [uri "/robots.txt"] [unique_id "amuHZM637Arlr6Yb1EcaUQAAoCQ"]
[Thu Jul 30 12:18:28.830262 2026] [security2:error] [pid 703393:tid 703525] [client 20.151.221.234:12847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/admin.php"] [unique_id "amuHZM637Arlr6Yb1EcaZwAAAIc"]
[Thu Jul 30 12:18:28.838844 2026] [security2:error] [pid 703393:tid 703606] [client 20.91.199.21:32600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuHZM637Arlr6Yb1EcaaAAAANg"]
[Thu Jul 30 12:18:29.163413 2026] [security2:error] [pid 703393:tid 703559] [client 20.63.98.115:65331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/st.php"] [unique_id "amuHZc637Arlr6Yb1EcacQAAAKk"]
[Thu Jul 30 12:18:29.370534 2026] [core:error] [pid 703393:tid 703553] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:29.370553 2026] [core:error] [pid 703393:tid 703553] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:18:30.292756 2026] [security2:error] [pid 703393:tid 703579] [client 20.91.199.21:10749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuHZs637Arlr6Yb1EcagwAAAL0"]
[Thu Jul 30 12:18:30.668078 2026] [security2:error] [pid 703393:tid 703569] [client 20.151.221.234:4377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuHZs637Arlr6Yb1EcakgAAALM"]
[Thu Jul 30 12:18:30.773866 2026] [security2:error] [pid 703393:tid 703596] [client 20.63.98.115:64860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/about.php"] [unique_id "amuHZs637Arlr6Yb1EcalAAAAM4"]
[Thu Jul 30 12:18:31.180569 2026] [security2:error] [pid 703393:tid 703628] [client 20.91.199.21:11140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuHZ8637Arlr6Yb1EcaoAAAAO4"]
[Thu Jul 30 12:18:31.293279 2026] [security2:error] [pid 703393:tid 703445] [remote 5.161.62.209:33244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.psz.dtn.temporary.site"] [uri "/.env"] [unique_id "amuHZ8637Arlr6Yb1EcapQAAkDM"]
[Thu Jul 30 12:18:31.697206 2026] [security2:error] [pid 703393:tid 703575] [client 20.63.98.115:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/admin.php"] [unique_id "amuHZ8637Arlr6Yb1EcasAAAALk"]
[Thu Jul 30 12:18:31.890355 2026] [security2:error] [pid 703393:tid 703623] [client 20.91.199.21:11027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuHZ8637Arlr6Yb1EcatgAAAOk"]
[Thu Jul 30 12:18:32.072090 2026] [core:error] [pid 703393:tid 703614] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:18:32.072120 2026] [core:error] [pid 703393:tid 703614] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:18:32.404099 2026] [core:notice] [pid 703393:tid 703421] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:32.946341 2026] [security2:error] [pid 703393:tid 703563] [client 20.91.199.21:11017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuHaM637Arlr6Yb1EcazgAAAK0"]
[Thu Jul 30 12:18:33.123131 2026] [security2:error] [pid 703393:tid 703553] [client 186.52.238.32:45260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuHaM637Arlr6Yb1EcazQAAAKM"]
[Thu Jul 30 12:18:33.770065 2026] [core:notice] [pid 703393:tid 703435] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:33.793913 2026] [security2:error] [pid 703393:tid 703593] [client 20.91.199.21:10774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuHac637Arlr6Yb1Eca4wAAAMs"]
[Thu Jul 30 12:18:34.126448 2026] [security2:error] [pid 703393:tid 703646] [client 213.152.161.118:35272] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuHas637Arlr6Yb1Eca5wAAAQA"]
[Thu Jul 30 12:18:34.126545 2026] [security2:error] [pid 703393:tid 703646] [client 213.152.161.118:35272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuHas637Arlr6Yb1Eca5wAAAQA"]
[Thu Jul 30 12:18:34.200134 2026] [security2:error] [pid 703393:tid 703623] [client 20.151.221.234:4399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/m.php"] [unique_id "amuHas637Arlr6Yb1Eca6gAAAOk"]
[Thu Jul 30 12:18:34.272442 2026] [security2:error] [pid 703393:tid 703555] [client 20.63.98.115:63126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/admin.php"] [unique_id "amuHas637Arlr6Yb1Eca7AAAAKU"]
[Thu Jul 30 12:18:34.673026 2026] [security2:error] [pid 703393:tid 703617] [client 52.238.199.152:1447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/gmo.php"] [unique_id "amuHas637Arlr6Yb1Eca9AAAAOM"]
[Thu Jul 30 12:18:34.758571 2026] [security2:error] [pid 703393:tid 703592] [client 20.91.199.21:10331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuHas637Arlr6Yb1Eca9QAAAMo"]
[Thu Jul 30 12:18:35.309065 2026] [security2:error] [pid 703393:tid 703539] [client 20.91.199.21:10345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuHa8637Arlr6Yb1EcbAQAAAJU"]
[Thu Jul 30 12:18:35.803545 2026] [security2:error] [pid 703393:tid 703533] [client 20.63.98.115:20997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuHa8637Arlr6Yb1EcbDQAAAI8"]
[Thu Jul 30 12:18:36.435833 2026] [security2:error] [pid 703393:tid 703638] [client 20.151.221.234:12812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuHbM637Arlr6Yb1EcbEgAAAPg"]
[Thu Jul 30 12:18:37.213618 2026] [security2:error] [pid 703393:tid 703649] [client 20.63.98.115:63426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp2.php"] [unique_id "amuHbc637Arlr6Yb1EcbKgAAAQM"]
[Thu Jul 30 12:18:37.270619 2026] [security2:error] [pid 703393:tid 703576] [client 52.238.199.152:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/nakrip.php"] [unique_id "amuHbc637Arlr6Yb1EcbMAAAALo"]
[Thu Jul 30 12:18:37.286732 2026] [security2:error] [pid 703393:tid 703595] [client 127.0.0.1:33764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHbc637Arlr6Yb1EcbLgAAAM0"]
[Thu Jul 30 12:18:37.286762 2026] [security2:error] [pid 703393:tid 703539] [client 127.0.0.1:33762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fyi.nyx.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHbc637Arlr6Yb1EcbLQAAAJU"]
[Thu Jul 30 12:18:37.286873 2026] [security2:error] [pid 703393:tid 703551] [client 74.7.228.4:56284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fyi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuHbc637Arlr6Yb1EcbLAAAoUw"]
[Thu Jul 30 12:18:37.320664 2026] [core:notice] [pid 703393:tid 703482] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:37.467806 2026] [security2:error] [pid 703393:tid 703583] [client 20.151.221.234:35462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/classwithtostring.php"] [unique_id "amuHbc637Arlr6Yb1EcbNQAAAME"]
[Thu Jul 30 12:18:38.199722 2026] [security2:error] [pid 703393:tid 703585] [client 20.100.203.84:48678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHbs637Arlr6Yb1EcbQgAAAMM"]
[Thu Jul 30 12:18:38.199829 2026] [security2:error] [pid 703393:tid 703585] [client 20.100.203.84:48678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHbs637Arlr6Yb1EcbQgAAAMM"]
[Thu Jul 30 12:18:38.265451 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.199.21:33622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuHbs637Arlr6Yb1EcbRgAAAKo"]
[Thu Jul 30 12:18:38.508864 2026] [security2:error] [pid 703393:tid 703636] [client 20.100.203.84:48652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHbs637Arlr6Yb1EcbSgAAAPY"]
[Thu Jul 30 12:18:38.509040 2026] [security2:error] [pid 703393:tid 703636] [client 20.100.203.84:48652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHbs637Arlr6Yb1EcbSgAAAPY"]
[Thu Jul 30 12:18:38.794817 2026] [security2:error] [pid 703393:tid 703566] [client 20.151.221.234:4413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/gmo.php"] [unique_id "amuHbs637Arlr6Yb1EcbTwAAALA"]
[Thu Jul 30 12:18:38.863851 2026] [security2:error] [pid 703393:tid 703627] [client 20.100.203.84:48670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/x.php"] [unique_id "amuHbs637Arlr6Yb1EcbUAAAAO0"]
[Thu Jul 30 12:18:38.863957 2026] [security2:error] [pid 703393:tid 703627] [client 20.100.203.84:48670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/x.php"] [unique_id "amuHbs637Arlr6Yb1EcbUAAAAO0"]
[Thu Jul 30 12:18:39.008194 2026] [security2:error] [pid 703393:tid 703552] [client 20.63.98.115:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/s.php"] [unique_id "amuHb8637Arlr6Yb1EcbUQAAAKI"]
[Thu Jul 30 12:18:39.200615 2026] [security2:error] [pid 703393:tid 703559] [client 20.100.203.84:43778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/mgrr.php"] [unique_id "amuHb8637Arlr6Yb1EcbVQAAAKk"]
[Thu Jul 30 12:18:39.200730 2026] [security2:error] [pid 703393:tid 703559] [client 20.100.203.84:43778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/mgrr.php"] [unique_id "amuHb8637Arlr6Yb1EcbVQAAAKk"]
[Thu Jul 30 12:18:39.404345 2026] [security2:error] [pid 703393:tid 703574] [client 20.91.199.21:10343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuHb8637Arlr6Yb1EcbWQAAALg"]
[Thu Jul 30 12:18:39.505828 2026] [security2:error] [pid 703393:tid 703530] [client 20.100.203.84:43813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/domvf.php"] [unique_id "amuHb8637Arlr6Yb1EcbXAAAAIw"]
[Thu Jul 30 12:18:39.505938 2026] [security2:error] [pid 703393:tid 703530] [client 20.100.203.84:43813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/domvf.php"] [unique_id "amuHb8637Arlr6Yb1EcbXAAAAIw"]
[Thu Jul 30 12:18:39.619826 2026] [security2:error] [pid 703393:tid 703589] [client 20.151.221.234:4403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuHb8637Arlr6Yb1EcbYAAAAMc"]
[Thu Jul 30 12:18:39.670069 2026] [security2:error] [pid 703393:tid 703498] [remote 57.141.0.40:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/snpm/user/register"] [unique_id "amuHb8637Arlr6Yb1EcbWgAA82g"]
[Thu Jul 30 12:18:39.737094 2026] [security2:error] [pid 703393:tid 703599] [client 52.238.199.152:1471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/radio.php"] [unique_id "amuHb8637Arlr6Yb1EcbYgAAANE"]
[Thu Jul 30 12:18:39.810636 2026] [security2:error] [pid 703393:tid 703619] [client 20.100.203.84:57682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/yup.php"] [unique_id "amuHb8637Arlr6Yb1EcbZgAAAOU"]
[Thu Jul 30 12:18:39.810745 2026] [security2:error] [pid 703393:tid 703619] [client 20.100.203.84:57682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/yup.php"] [unique_id "amuHb8637Arlr6Yb1EcbZgAAAOU"]
[Thu Jul 30 12:18:40.140635 2026] [security2:error] [pid 703393:tid 703531] [client 20.100.203.84:43777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/X.php"] [unique_id "amuHcM637Arlr6Yb1EcbagAAAI0"]
[Thu Jul 30 12:18:40.140743 2026] [security2:error] [pid 703393:tid 703531] [client 20.100.203.84:43777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/X.php"] [unique_id "amuHcM637Arlr6Yb1EcbagAAAI0"]
[Thu Jul 30 12:18:40.472153 2026] [security2:error] [pid 703393:tid 703528] [client 20.100.203.84:57709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHcM637Arlr6Yb1EcbcgAAAIo"]
[Thu Jul 30 12:18:40.472269 2026] [security2:error] [pid 703393:tid 703528] [client 20.100.203.84:57709] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHcM637Arlr6Yb1EcbcgAAAIo"]
[Thu Jul 30 12:18:40.554069 2026] [security2:error] [pid 703393:tid 703613] [client 20.63.98.115:21047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/help.php"] [unique_id "amuHcM637Arlr6Yb1EcbcwAAAN8"]
[Thu Jul 30 12:18:40.746534 2026] [security2:error] [pid 703393:tid 703585] [client 52.238.199.152:1479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/wp-singin.php"] [unique_id "amuHcM637Arlr6Yb1EcbeAAAAMM"]
[Thu Jul 30 12:18:40.881122 2026] [security2:error] [pid 703393:tid 703550] [client 20.100.203.84:48697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/gec.php"] [unique_id "amuHcM637Arlr6Yb1EcbegAAAKA"]
[Thu Jul 30 12:18:40.881226 2026] [security2:error] [pid 703393:tid 703550] [client 20.100.203.84:48697] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/gec.php"] [unique_id "amuHcM637Arlr6Yb1EcbegAAAKA"]
[Thu Jul 30 12:18:41.076603 2026] [security2:error] [pid 703393:tid 703603] [client 20.91.199.21:10748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuHcc637Arlr6Yb1EcbfgAAANU"]
[Thu Jul 30 12:18:41.093670 2026] [security2:error] [pid 703393:tid 703646] [client 20.151.221.234:12863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-the.php"] [unique_id "amuHcc637Arlr6Yb1EcbfwAAAQA"]
[Thu Jul 30 12:18:41.182357 2026] [security2:error] [pid 703393:tid 703610] [client 20.100.203.84:43823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/sky.php"] [unique_id "amuHcc637Arlr6Yb1EcbgwAAANw"]
[Thu Jul 30 12:18:41.182457 2026] [security2:error] [pid 703393:tid 703610] [client 20.100.203.84:43823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/sky.php"] [unique_id "amuHcc637Arlr6Yb1EcbgwAAANw"]
[Thu Jul 30 12:18:41.206785 2026] [security2:error] [pid 703393:tid 703581] [client 74.7.228.27:47644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.aetiiph.net.smo.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuHcM637Arlr6Yb1EcbdwAAvxo"]
[Thu Jul 30 12:18:41.500922 2026] [security2:error] [pid 703393:tid 703539] [client 20.100.203.84:48682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/fffm.php"] [unique_id "amuHcc637Arlr6Yb1EcbhwAAAJU"]
[Thu Jul 30 12:18:41.501036 2026] [security2:error] [pid 703393:tid 703539] [client 20.100.203.84:48682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/fffm.php"] [unique_id "amuHcc637Arlr6Yb1EcbhwAAAJU"]
[Thu Jul 30 12:18:41.820597 2026] [security2:error] [pid 703393:tid 703589] [client 20.100.203.84:43839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/sixxis.php"] [unique_id "amuHcc637Arlr6Yb1EcbjQAAAMc"]
[Thu Jul 30 12:18:41.820707 2026] [security2:error] [pid 703393:tid 703589] [client 20.100.203.84:43839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/sixxis.php"] [unique_id "amuHcc637Arlr6Yb1EcbjQAAAMc"]
[Thu Jul 30 12:18:41.887955 2026] [security2:error] [pid 703393:tid 703596] [client 52.238.199.152:1671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/as.php"] [unique_id "amuHcc637Arlr6Yb1EcbjwAAAM4"]
[Thu Jul 30 12:18:41.890721 2026] [security2:error] [pid 703393:tid 703558] [client 87.101.92.171:51364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuHcc637Arlr6Yb1EcbjgAAAKg"]
[Thu Jul 30 12:18:41.890816 2026] [security2:error] [pid 703393:tid 703558] [client 87.101.92.171:51364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuHcc637Arlr6Yb1EcbjgAAAKg"]
[Thu Jul 30 12:18:41.957910 2026] [security2:error] [pid 703393:tid 703551] [client 20.91.199.21:10734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuHcc637Arlr6Yb1EcbkwAAAKE"]
[Thu Jul 30 12:18:41.994352 2026] [security2:error] [pid 703393:tid 703530] [client 20.151.221.234:4414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/404.php"] [unique_id "amuHcc637Arlr6Yb1EcblQAAAIw"]
[Thu Jul 30 12:18:42.121038 2026] [security2:error] [pid 703393:tid 703523] [client 20.100.203.84:48690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/yj09.php"] [unique_id "amuHcs637Arlr6Yb1EcblgAAAIU"]
[Thu Jul 30 12:18:42.121153 2026] [security2:error] [pid 703393:tid 703523] [client 20.100.203.84:48690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/yj09.php"] [unique_id "amuHcs637Arlr6Yb1EcblgAAAIU"]
[Thu Jul 30 12:18:42.221740 2026] [security2:error] [pid 703393:tid 703628] [client 20.63.98.115:63441] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jesus.claims"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuHcs637Arlr6Yb1EcbmgAAAO4"]
[Thu Jul 30 12:18:42.221866 2026] [security2:error] [pid 703393:tid 703628] [client 20.63.98.115:63441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuHcs637Arlr6Yb1EcbmgAAAO4"]
[Thu Jul 30 12:18:42.464460 2026] [security2:error] [pid 703393:tid 703638] [client 20.100.203.84:57670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/k.php"] [unique_id "amuHcs637Arlr6Yb1EcbngAAAPg"]
[Thu Jul 30 12:18:42.464571 2026] [security2:error] [pid 703393:tid 703638] [client 20.100.203.84:57670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/k.php"] [unique_id "amuHcs637Arlr6Yb1EcbngAAAPg"]
[Thu Jul 30 12:18:42.757228 2026] [security2:error] [pid 703393:tid 703536] [client 20.91.199.21:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuHcs637Arlr6Yb1EcbowAAAJI"]
[Thu Jul 30 12:18:42.831382 2026] [security2:error] [pid 703393:tid 703607] [client 20.151.221.234:4405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/init.php"] [unique_id "amuHcs637Arlr6Yb1EcbpAAAANk"]
[Thu Jul 30 12:18:42.964475 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.203.84:48641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/k2.php"] [unique_id "amuHcs637Arlr6Yb1EcbpwAAALA"]
[Thu Jul 30 12:18:42.964564 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.203.84:48641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/k2.php"] [unique_id "amuHcs637Arlr6Yb1EcbpwAAALA"]
[Thu Jul 30 12:18:43.027506 2026] [security2:error] [pid 703393:tid 703621] [client 52.238.199.152:1415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/x.php"] [unique_id "amuHc8637Arlr6Yb1EcbrgAAAOc"]
[Thu Jul 30 12:18:43.700759 2026] [security2:error] [pid 703393:tid 703576] [client 20.151.221.234:12840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/file5.php"] [unique_id "amuHc8637Arlr6Yb1EcbvAAAALo"]
[Thu Jul 30 12:18:43.844998 2026] [security2:error] [pid 703393:tid 703620] [client 20.63.98.115:47228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin/upload/css.php"] [unique_id "amuHc8637Arlr6Yb1EcbvQAAAOY"]
[Thu Jul 30 12:18:43.861504 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:43796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/w.php"] [unique_id "amuHc8637Arlr6Yb1EcbvgAAAKE"]
[Thu Jul 30 12:18:43.861580 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:43796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/w.php"] [unique_id "amuHc8637Arlr6Yb1EcbvgAAAKE"]
[Thu Jul 30 12:18:44.678266 2026] [security2:error] [pid 703393:tid 703535] [client 20.151.221.234:12851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuHdM637Arlr6Yb1EcbygAAAJE"]
[Thu Jul 30 12:18:44.697156 2026] [security2:error] [pid 703393:tid 703611] [client 20.100.203.84:48689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/fpwch.php"] [unique_id "amuHdM637Arlr6Yb1EcbzgAAAN0"]
[Thu Jul 30 12:18:44.697267 2026] [security2:error] [pid 703393:tid 703611] [client 20.100.203.84:48689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/fpwch.php"] [unique_id "amuHdM637Arlr6Yb1EcbzgAAAN0"]
[Thu Jul 30 12:18:44.773232 2026] [security2:error] [pid 703393:tid 703531] [client 20.63.98.115:65301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/about.php"] [unique_id "amuHdM637Arlr6Yb1Ecb0AAAAI0"]
[Thu Jul 30 12:18:44.899970 2026] [security2:error] [pid 703393:tid 703405] [remote 74.7.242.7:46884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuHdM637Arlr6Yb1Ecb1AAAsQs"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:18:45.295842 2026] [security2:error] [pid 703393:tid 703564] [client 20.91.199.21:10336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuHdc637Arlr6Yb1Ecb3gAAAK4"]
[Thu Jul 30 12:18:45.305246 2026] [security2:error] [pid 703393:tid 703557] [client 20.100.203.84:57695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/w2025.php"] [unique_id "amuHdc637Arlr6Yb1Ecb3wAAAKc"]
[Thu Jul 30 12:18:45.305360 2026] [security2:error] [pid 703393:tid 703557] [client 20.100.203.84:57695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/w2025.php"] [unique_id "amuHdc637Arlr6Yb1Ecb3wAAAKc"]
[Thu Jul 30 12:18:45.638672 2026] [security2:error] [pid 703393:tid 703621] [client 52.167.144.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHdc637Arlr6Yb1Ecb3AAAAOc"]
[Thu Jul 30 12:18:45.733705 2026] [security2:error] [pid 703393:tid 703556] [client 20.100.203.84:48692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/FWAZ.php"] [unique_id "amuHdc637Arlr6Yb1Ecb6AAAAKY"]
[Thu Jul 30 12:18:45.733822 2026] [security2:error] [pid 703393:tid 703556] [client 20.100.203.84:48692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/FWAZ.php"] [unique_id "amuHdc637Arlr6Yb1Ecb6AAAAKY"]
[Thu Jul 30 12:18:45.742287 2026] [security2:error] [pid 703393:tid 703566] [client 20.151.221.234:12841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/shell.php"] [unique_id "amuHdc637Arlr6Yb1Ecb6QAAALA"]
[Thu Jul 30 12:18:45.847895 2026] [security2:error] [pid 703393:tid 703629] [client 20.63.98.115:62820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/autoloadclassmap.php"] [unique_id "amuHdc637Arlr6Yb1Ecb7QAAAO8"]
[Thu Jul 30 12:18:45.954261 2026] [security2:error] [pid 703393:tid 703624] [client 20.91.199.21:10350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuHdc637Arlr6Yb1Ecb7gAAAOo"]
[Thu Jul 30 12:18:46.129210 2026] [security2:error] [pid 703393:tid 703605] [client 20.100.203.84:43791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/qterm.php"] [unique_id "amuHds637Arlr6Yb1Ecb8AAAANc"]
[Thu Jul 30 12:18:46.129329 2026] [security2:error] [pid 703393:tid 703605] [client 20.100.203.84:43791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/qterm.php"] [unique_id "amuHds637Arlr6Yb1Ecb8AAAANc"]
[Thu Jul 30 12:18:46.657042 2026] [security2:error] [pid 703393:tid 703630] [client 20.63.98.115:21036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/x.php"] [unique_id "amuHds637Arlr6Yb1Ecb-QAAAPA"]
[Thu Jul 30 12:18:46.701279 2026] [security2:error] [pid 703393:tid 703562] [client 20.91.199.21:35260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuHds637Arlr6Yb1Ecb_AAAAKw"]
[Thu Jul 30 12:18:46.887344 2026] [security2:error] [pid 703393:tid 703645] [client 20.100.203.84:48676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/blurbs.php"] [unique_id "amuHds637Arlr6Yb1EccAQAAAP8"]
[Thu Jul 30 12:18:46.887460 2026] [security2:error] [pid 703393:tid 703645] [client 20.100.203.84:48676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/blurbs.php"] [unique_id "amuHds637Arlr6Yb1EccAQAAAP8"]
[Thu Jul 30 12:18:47.023913 2026] [security2:error] [pid 703393:tid 703594] [client 20.151.221.234:4354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/f35.php"] [unique_id "amuHd8637Arlr6Yb1EccAgAAAMw"]
[Thu Jul 30 12:18:47.269778 2026] [security2:error] [pid 703393:tid 703534] [client 20.100.203.84:43805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-ws68.php"] [unique_id "amuHd8637Arlr6Yb1EccBwAAAJA"]
[Thu Jul 30 12:18:47.269859 2026] [security2:error] [pid 703393:tid 703534] [client 20.100.203.84:43805] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-ws68.php"] [unique_id "amuHd8637Arlr6Yb1EccBwAAAJA"]
[Thu Jul 30 12:18:47.441933 2026] [security2:error] [pid 703393:tid 703560] [client 20.63.98.115:21007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-class.php"] [unique_id "amuHd8637Arlr6Yb1EccCwAAAKo"]
[Thu Jul 30 12:18:47.534721 2026] [security2:error] [pid 703393:tid 703526] [client 20.91.199.21:10307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuHd8637Arlr6Yb1EccDAAAAIg"]
[Thu Jul 30 12:18:47.624193 2026] [security2:error] [pid 703393:tid 703607] [client 20.100.203.84:57683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/xyn.php"] [unique_id "amuHd8637Arlr6Yb1EccDQAAANk"]
[Thu Jul 30 12:18:47.624309 2026] [security2:error] [pid 703393:tid 703607] [client 20.100.203.84:57683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/xyn.php"] [unique_id "amuHd8637Arlr6Yb1EccDQAAANk"]
[Thu Jul 30 12:18:47.634255 2026] [security2:error] [pid 703393:tid 703555] [client 144.123.76.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuHd8637Arlr6Yb1EccBgAApXE"]
[Thu Jul 30 12:18:47.710580 2026] [security2:error] [pid 703393:tid 703506] [remote 57.141.0.25:43248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuHd8637Arlr6Yb1EccDwAAlHA"]
[Thu Jul 30 12:18:47.967032 2026] [security2:error] [pid 703393:tid 703525] [client 20.100.203.84:48649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ccc.php"] [unique_id "amuHd8637Arlr6Yb1EccFwAAAIc"]
[Thu Jul 30 12:18:47.967136 2026] [security2:error] [pid 703393:tid 703525] [client 20.100.203.84:48649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ccc.php"] [unique_id "amuHd8637Arlr6Yb1EccFwAAAIc"]
[Thu Jul 30 12:18:48.339201 2026] [security2:error] [pid 703393:tid 703529] [client 20.100.203.84:34630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/get.php"] [unique_id "amuHeM637Arlr6Yb1EccGwAAAIs"]
[Thu Jul 30 12:18:48.339309 2026] [security2:error] [pid 703393:tid 703529] [client 20.100.203.84:34630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/get.php"] [unique_id "amuHeM637Arlr6Yb1EccGwAAAIs"]
[Thu Jul 30 12:18:48.399783 2026] [core:error] [pid 703393:tid 703574] [client 88.151.33.203:56330] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Jul 30 12:18:48.544887 2026] [security2:error] [pid 703393:tid 703577] [client 20.151.221.234:35510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/new.php"] [unique_id "amuHeM637Arlr6Yb1EccIAAAALs"]
[Thu Jul 30 12:18:48.653567 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:48657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/images.php"] [unique_id "amuHeM637Arlr6Yb1EccIgAAAOo"]
[Thu Jul 30 12:18:48.653669 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:48657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/images.php"] [unique_id "amuHeM637Arlr6Yb1EccIgAAAOo"]
[Thu Jul 30 12:18:48.996135 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:57718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/alls.php"] [unique_id "amuHeM637Arlr6Yb1EccJwAAAKE"]
[Thu Jul 30 12:18:48.996260 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:57718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/alls.php"] [unique_id "amuHeM637Arlr6Yb1EccJwAAAKE"]
[Thu Jul 30 12:18:49.057772 2026] [security2:error] [pid 703393:tid 703573] [client 20.91.199.21:33641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuHec637Arlr6Yb1EccKwAAALc"]
[Thu Jul 30 12:18:49.321568 2026] [security2:error] [pid 703393:tid 703545] [client 20.63.98.115:21009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/content.php"] [unique_id "amuHec637Arlr6Yb1EccLQAAAJs"]
[Thu Jul 30 12:18:49.388323 2026] [security2:error] [pid 703393:tid 703535] [client 20.100.203.84:57711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/coffexium.php"] [unique_id "amuHec637Arlr6Yb1EccMQAAAJE"]
[Thu Jul 30 12:18:49.388440 2026] [security2:error] [pid 703393:tid 703535] [client 20.100.203.84:57711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/coffexium.php"] [unique_id "amuHec637Arlr6Yb1EccMQAAAJE"]
[Thu Jul 30 12:18:49.506158 2026] [security2:error] [pid 703393:tid 703634] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHeM637Arlr6Yb1EccJgAA9Cg"]
[Thu Jul 30 12:18:49.634102 2026] [security2:error] [pid 703393:tid 703593] [client 20.151.221.234:35459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/adminfuns.php"] [unique_id "amuHec637Arlr6Yb1EccOAAAAMs"]
[Thu Jul 30 12:18:49.756557 2026] [security2:error] [pid 703393:tid 703578] [client 20.100.203.84:43811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/red.php"] [unique_id "amuHec637Arlr6Yb1EccOgAAALw"]
[Thu Jul 30 12:18:49.756713 2026] [security2:error] [pid 703393:tid 703578] [client 20.100.203.84:43811] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/red.php"] [unique_id "amuHec637Arlr6Yb1EccOgAAALw"]
[Thu Jul 30 12:18:49.941045 2026] [security2:error] [pid 703393:tid 703614] [client 20.91.199.21:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuHec637Arlr6Yb1EccPgAAAOA"]
[Thu Jul 30 12:18:50.081507 2026] [security2:error] [pid 703393:tid 703563] [client 172.213.232.128:6682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/geju.php"] [unique_id "amuHes637Arlr6Yb1EccQgAAAK0"]
[Thu Jul 30 12:18:50.200614 2026] [security2:error] [pid 703393:tid 703582] [client 20.100.203.84:48683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/sodium_compat/"] [unique_id "amuHes637Arlr6Yb1EccQwAAAMA"]
[Thu Jul 30 12:18:50.493718 2026] [security2:error] [pid 703393:tid 703570] [client 51.120.79.193:10773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHes637Arlr6Yb1EccSgAAALQ"]
[Thu Jul 30 12:18:50.493815 2026] [security2:error] [pid 703393:tid 703570] [client 51.120.79.193:10773] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHes637Arlr6Yb1EccSgAAALQ"]
[Thu Jul 30 12:18:50.495899 2026] [security2:error] [pid 703393:tid 703595] [client 20.100.203.84:48683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuHes637Arlr6Yb1EccSwAAAM0"]
[Thu Jul 30 12:18:50.495993 2026] [security2:error] [pid 703393:tid 703595] [client 20.100.203.84:48683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuHes637Arlr6Yb1EccSwAAAM0"]
[Thu Jul 30 12:18:50.740040 2026] [security2:error] [pid 703393:tid 703646] [client 20.63.98.115:47208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/acp.php"] [unique_id "amuHes637Arlr6Yb1EccUgAAAQA"]
[Thu Jul 30 12:18:50.850134 2026] [security2:error] [pid 703393:tid 703558] [client 20.91.199.21:35259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuHes637Arlr6Yb1EccVAAAAKg"]
[Thu Jul 30 12:18:50.850792 2026] [security2:error] [pid 703393:tid 703566] [client 20.100.203.84:48666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/Text/"] [unique_id "amuHes637Arlr6Yb1EccUwAAALA"]
[Thu Jul 30 12:18:51.108016 2026] [security2:error] [pid 703393:tid 703530] [client 20.151.221.234:12809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/fm.php"] [unique_id "amuHe8637Arlr6Yb1EccXAAAAIw"]
[Thu Jul 30 12:18:51.199663 2026] [security2:error] [pid 703393:tid 703551] [client 20.100.203.84:48666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-content/uploads/"] [unique_id "amuHe8637Arlr6Yb1EccYAAAAKE"]
[Thu Jul 30 12:18:51.349789 2026] [security2:error] [pid 703393:tid 703616] [client 20.100.203.84:48666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/index.php"] [unique_id "amuHe8637Arlr6Yb1EccYQAAAOI"]
[Thu Jul 30 12:18:51.349897 2026] [security2:error] [pid 703393:tid 703616] [client 20.100.203.84:48666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/index.php"] [unique_id "amuHe8637Arlr6Yb1EccYQAAAOI"]
[Thu Jul 30 12:18:51.486134 2026] [security2:error] [pid 703393:tid 703590] [client 172.213.232.128:23126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuHe8637Arlr6Yb1EccYwAAAMg"]
[Thu Jul 30 12:18:51.631112 2026] [security2:error] [pid 703393:tid 703573] [client 20.91.199.21:46419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuHe8637Arlr6Yb1EccZwAAALc"]
[Thu Jul 30 12:18:51.731409 2026] [security2:error] [pid 703393:tid 703623] [client 20.100.203.84:57678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/admin.php"] [unique_id "amuHe8637Arlr6Yb1EccawAAAOk"]
[Thu Jul 30 12:18:51.731509 2026] [security2:error] [pid 703393:tid 703623] [client 20.100.203.84:57678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/admin.php"] [unique_id "amuHe8637Arlr6Yb1EccawAAAOk"]
[Thu Jul 30 12:18:51.856173 2026] [security2:error] [pid 703393:tid 703602] [client 51.120.79.193:11211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHe8637Arlr6Yb1EccbAAAANQ"]
[Thu Jul 30 12:18:51.856331 2026] [security2:error] [pid 703393:tid 703602] [client 51.120.79.193:11211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHe8637Arlr6Yb1EccbAAAANQ"]
[Thu Jul 30 12:18:52.054849 2026] [security2:error] [pid 703393:tid 703614] [client 20.100.203.84:43833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/177.php"] [unique_id "amuHfM637Arlr6Yb1EcccAAAAOA"]
[Thu Jul 30 12:18:52.054935 2026] [security2:error] [pid 703393:tid 703614] [client 20.100.203.84:43833] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/177.php"] [unique_id "amuHfM637Arlr6Yb1EcccAAAAOA"]
[Thu Jul 30 12:18:52.101179 2026] [security2:error] [pid 703393:tid 703594] [client 20.63.98.115:37993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/g.php"] [unique_id "amuHfM637Arlr6Yb1EcccQAAAMw"]
[Thu Jul 30 12:18:52.211696 2026] [security2:error] [pid 703393:tid 703560] [client 20.91.199.21:10745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuHfM637Arlr6Yb1EccegAAAKo"]
[Thu Jul 30 12:18:52.352396 2026] [security2:error] [pid 703393:tid 703557] [client 20.151.221.234:12848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/file.php"] [unique_id "amuHfM637Arlr6Yb1EccewAAAKc"]
[Thu Jul 30 12:18:52.376581 2026] [security2:error] [pid 703393:tid 703592] [client 20.100.203.84:48643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/199.php"] [unique_id "amuHfM637Arlr6Yb1EccfAAAAMo"]
[Thu Jul 30 12:18:52.376684 2026] [security2:error] [pid 703393:tid 703592] [client 20.100.203.84:48643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/199.php"] [unique_id "amuHfM637Arlr6Yb1EccfAAAAMo"]
[Thu Jul 30 12:18:52.559790 2026] [core:notice] [pid 703393:tid 703597] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:52.764212 2026] [security2:error] [pid 703393:tid 703585] [client 20.100.203.84:43783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/file52.php"] [unique_id "amuHfM637Arlr6Yb1EcchAAAAMM"]
[Thu Jul 30 12:18:52.764379 2026] [security2:error] [pid 703393:tid 703585] [client 20.100.203.84:43783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/file52.php"] [unique_id "amuHfM637Arlr6Yb1EcchAAAAMM"]
[Thu Jul 30 12:18:52.821413 2026] [security2:error] [pid 703393:tid 703626] [client 52.238.199.152:30084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/item.php"] [unique_id "amuHfM637Arlr6Yb1EcchQAAAOw"]
[Thu Jul 30 12:18:52.983046 2026] [security2:error] [pid 703393:tid 703565] [client 184.75.223.195:43378] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuHfM637Arlr6Yb1EcchgAAAK8"]
[Thu Jul 30 12:18:52.983139 2026] [security2:error] [pid 703393:tid 703565] [client 184.75.223.195:43378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuHfM637Arlr6Yb1EcchgAAAK8"]
[Thu Jul 30 12:18:53.072127 2026] [security2:error] [pid 703393:tid 703646] [client 20.100.203.84:31806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/geck.php"] [unique_id "amuHfc637Arlr6Yb1EcchwAAAQA"]
[Thu Jul 30 12:18:53.072233 2026] [security2:error] [pid 703393:tid 703646] [client 20.100.203.84:31806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/geck.php"] [unique_id "amuHfc637Arlr6Yb1EcchwAAAQA"]
[Thu Jul 30 12:18:53.131884 2026] [security2:error] [pid 703393:tid 703539] [client 20.91.199.21:46436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuHfc637Arlr6Yb1EccjAAAAJU"]
[Thu Jul 30 12:18:53.228574 2026] [security2:error] [pid 703393:tid 703556] [client 20.63.98.115:57317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/caches.php"] [unique_id "amuHfc637Arlr6Yb1EccjwAAAKY"]
[Thu Jul 30 12:18:53.380758 2026] [security2:error] [pid 703393:tid 703569] [client 172.213.232.128:8263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp.php"] [unique_id "amuHfc637Arlr6Yb1EcckAAAALM"]
[Thu Jul 30 12:18:53.428798 2026] [security2:error] [pid 703393:tid 703609] [client 51.120.79.193:16077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuHfc637Arlr6Yb1EcckQAAANs"]
[Thu Jul 30 12:18:53.428943 2026] [security2:error] [pid 703393:tid 703609] [client 51.120.79.193:16077] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuHfc637Arlr6Yb1EcckQAAANs"]
[Thu Jul 30 12:18:53.550633 2026] [security2:error] [pid 703393:tid 703586] [client 20.100.203.84:43826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/biufile.php"] [unique_id "amuHfc637Arlr6Yb1EcckgAAAMQ"]
[Thu Jul 30 12:18:53.550749 2026] [security2:error] [pid 703393:tid 703586] [client 20.100.203.84:43826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/biufile.php"] [unique_id "amuHfc637Arlr6Yb1EcckgAAAMQ"]
[Thu Jul 30 12:18:53.872884 2026] [core:notice] [pid 703393:tid 703479] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:53.885109 2026] [security2:error] [pid 703393:tid 703602] [client 20.100.203.84:43780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/dejavu.php"] [unique_id "amuHfc637Arlr6Yb1EccmwAAANQ"]
[Thu Jul 30 12:18:53.885234 2026] [security2:error] [pid 703393:tid 703602] [client 20.100.203.84:43780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/dejavu.php"] [unique_id "amuHfc637Arlr6Yb1EccmwAAANQ"]
[Thu Jul 30 12:18:54.212403 2026] [security2:error] [pid 703393:tid 703617] [client 20.100.203.84:57684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/aaf.php"] [unique_id "amuHfs637Arlr6Yb1EccpgAAAOM"]
[Thu Jul 30 12:18:54.212494 2026] [security2:error] [pid 703393:tid 703617] [client 20.100.203.84:57684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/aaf.php"] [unique_id "amuHfs637Arlr6Yb1EccpgAAAOM"]
[Thu Jul 30 12:18:54.559334 2026] [security2:error] [pid 703393:tid 703627] [client 20.100.203.84:48645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ha.php"] [unique_id "amuHfs637Arlr6Yb1EccpwAAAO0"]
[Thu Jul 30 12:18:54.559460 2026] [security2:error] [pid 703393:tid 703627] [client 20.100.203.84:48645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ha.php"] [unique_id "amuHfs637Arlr6Yb1EccpwAAAO0"]
[Thu Jul 30 12:18:54.703680 2026] [security2:error] [pid 703393:tid 703603] [client 20.63.98.115:20889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuHfs637Arlr6Yb1EccqwAAANU"]
[Thu Jul 30 12:18:54.875590 2026] [security2:error] [pid 703393:tid 703649] [client 20.100.203.84:57664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/hur.php"] [unique_id "amuHfs637Arlr6Yb1EccrwAAAQM"]
[Thu Jul 30 12:18:54.875703 2026] [security2:error] [pid 703393:tid 703649] [client 20.100.203.84:57664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/hur.php"] [unique_id "amuHfs637Arlr6Yb1EccrwAAAQM"]
[Thu Jul 30 12:18:54.971400 2026] [security2:error] [pid 703393:tid 703541] [client 20.91.199.21:33624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuHfs637Arlr6Yb1EccsAAAAJc"]
[Thu Jul 30 12:18:55.207016 2026] [security2:error] [pid 703393:tid 703578] [client 20.100.203.84:57701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/h02ugyh.php"] [unique_id "amuHf8637Arlr6Yb1EcctgAAALw"]
[Thu Jul 30 12:18:55.207132 2026] [security2:error] [pid 703393:tid 703578] [client 20.100.203.84:57701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/h02ugyh.php"] [unique_id "amuHf8637Arlr6Yb1EcctgAAALw"]
[Thu Jul 30 12:18:55.506489 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:57684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/155.php"] [unique_id "amuHf8637Arlr6Yb1EccvQAAAOo"]
[Thu Jul 30 12:18:55.506592 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:57684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/155.php"] [unique_id "amuHf8637Arlr6Yb1EccvQAAAOo"]
[Thu Jul 30 12:18:55.615542 2026] [security2:error] [pid 703393:tid 703530] [client 51.120.79.193:11222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/media.php"] [unique_id "amuHf8637Arlr6Yb1EccvgAAAIw"]
[Thu Jul 30 12:18:55.615671 2026] [security2:error] [pid 703393:tid 703530] [client 51.120.79.193:11222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/media.php"] [unique_id "amuHf8637Arlr6Yb1EccvgAAAIw"]
[Thu Jul 30 12:18:55.892870 2026] [security2:error] [pid 703393:tid 703523] [client 20.100.203.84:43782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ops.php"] [unique_id "amuHf8637Arlr6Yb1EccxwAAAIU"]
[Thu Jul 30 12:18:55.892971 2026] [security2:error] [pid 703393:tid 703523] [client 20.100.203.84:43782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ops.php"] [unique_id "amuHf8637Arlr6Yb1EccxwAAAIU"]
[Thu Jul 30 12:18:56.233653 2026] [security2:error] [pid 703393:tid 703602] [client 20.100.203.84:57725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ingfo.php"] [unique_id "amuHgM637Arlr6Yb1EcczgAAANQ"]
[Thu Jul 30 12:18:56.233784 2026] [security2:error] [pid 703393:tid 703602] [client 20.100.203.84:57725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ingfo.php"] [unique_id "amuHgM637Arlr6Yb1EcczgAAANQ"]
[Thu Jul 30 12:18:56.437432 2026] [security2:error] [pid 703393:tid 703631] [client 20.63.98.115:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/css/about.php"] [unique_id "amuHgM637Arlr6Yb1Ecc3AAAAPE"]
[Thu Jul 30 12:18:56.510584 2026] [security2:error] [pid 703393:tid 703627] [client 20.151.221.234:4395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/bolt.php"] [unique_id "amuHgM637Arlr6Yb1Ecc3QAAAO0"]
[Thu Jul 30 12:18:56.563798 2026] [security2:error] [pid 703393:tid 703536] [client 172.213.232.128:1123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aaa.php"] [unique_id "amuHgM637Arlr6Yb1Ecc4QAAAJI"]
[Thu Jul 30 12:18:56.594700 2026] [security2:error] [pid 703393:tid 703610] [client 20.100.203.84:48688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/error_log.php"] [unique_id "amuHgM637Arlr6Yb1Ecc4gAAANw"]
[Thu Jul 30 12:18:56.594877 2026] [security2:error] [pid 703393:tid 703610] [client 20.100.203.84:48688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/error_log.php"] [unique_id "amuHgM637Arlr6Yb1Ecc4gAAANw"]
[Thu Jul 30 12:18:56.644248 2026] [security2:error] [pid 703393:tid 703505] [remote 52.167.144.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "emmanueljrodriguez.com"] [uri "/index.php"] [unique_id "amuHf8637Arlr6Yb1EccwwAAum8"]
[Thu Jul 30 12:18:56.868901 2026] [security2:error] [pid 703393:tid 703546] [client 20.91.199.21:35246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7AAAAJw"]
[Thu Jul 30 12:18:56.911402 2026] [security2:error] [pid 703393:tid 703561] [client 51.120.79.193:10686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/images.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7gAAAKs"]
[Thu Jul 30 12:18:56.911488 2026] [security2:error] [pid 703393:tid 703561] [client 51.120.79.193:10686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/images.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7gAAAKs"]
[Thu Jul 30 12:18:56.945327 2026] [security2:error] [pid 703393:tid 703629] [client 20.100.203.84:57708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/koala.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7wAAAO8"]
[Thu Jul 30 12:18:56.945428 2026] [security2:error] [pid 703393:tid 703629] [client 20.100.203.84:57708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/koala.php"] [unique_id "amuHgM637Arlr6Yb1Ecc7wAAAO8"]
[Thu Jul 30 12:18:57.201347 2026] [security2:error] [pid 703393:tid 703577] [client 172.213.232.128:8314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/hoot.php"] [unique_id "amuHgc637Arlr6Yb1Ecc8AAAALs"]
[Thu Jul 30 12:18:57.249080 2026] [security2:error] [pid 703393:tid 703619] [client 20.100.203.84:48679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/mac.php"] [unique_id "amuHgc637Arlr6Yb1Ecc8QAAAOU"]
[Thu Jul 30 12:18:57.249195 2026] [security2:error] [pid 703393:tid 703619] [client 20.100.203.84:48679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/mac.php"] [unique_id "amuHgc637Arlr6Yb1Ecc8QAAAOU"]
[Thu Jul 30 12:18:57.475945 2026] [security2:error] [pid 703393:tid 703560] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHgM637Arlr6Yb1Ecc6AAAqkw"]
[Thu Jul 30 12:18:57.523754 2026] [security2:error] [pid 703393:tid 703533] [client 20.151.221.234:44151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/3.php"] [unique_id "amuHgc637Arlr6Yb1Ecc-gAAAI8"]
[Thu Jul 30 12:18:57.551241 2026] [security2:error] [pid 703393:tid 703615] [client 20.100.203.84:57675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wefile.php"] [unique_id "amuHgc637Arlr6Yb1Ecc-wAAAOE"]
[Thu Jul 30 12:18:57.551336 2026] [security2:error] [pid 703393:tid 703615] [client 20.100.203.84:57675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wefile.php"] [unique_id "amuHgc637Arlr6Yb1Ecc-wAAAOE"]
[Thu Jul 30 12:18:57.680924 2026] [security2:error] [pid 703393:tid 703620] [client 43.173.181.200:56552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/14/soldes-ete-2012-30-paires-de-chaussures-a-moins-de-100e/feed/"] [unique_id "amuHgc637Arlr6Yb1Ecc-AAAAOY"]
[Thu Jul 30 12:18:57.710536 2026] [security2:error] [pid 703393:tid 703543] [client 43.173.173.140:48750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2017/03/12/sostrene-grene-printemps-2017/"] [unique_id "amuHgc637Arlr6Yb1Ecc-QAAAJk"]
[Thu Jul 30 12:18:57.894399 2026] [security2:error] [pid 703393:tid 703613] [client 20.100.203.84:57720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/blocks/post-comments-form/"] [unique_id "amuHgc637Arlr6Yb1EcdCAAAAN8"]
[Thu Jul 30 12:18:57.946916 2026] [security2:error] [pid 703393:tid 703638] [client 47.128.121.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuHgc637Arlr6Yb1EcdAQAAAPg"]
[Thu Jul 30 12:18:58.184598 2026] [core:notice] [pid 703393:tid 703591] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:58.189196 2026] [security2:error] [pid 703393:tid 703591] [client 43.172.198.9:34386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/14/soldes-ete-2012-30-paires-de-chaussures-a-moins-de-100e/feed/"] [unique_id "amuHgs637Arlr6Yb1EcdCgAAAMk"], referer: https://carnetdeshopping.com/index.php/2012/07/14/soldes-ete-2012-30-paires-de-chaussures-a-moins-de-100e/feed/
[Thu Jul 30 12:18:58.227442 2026] [security2:error] [pid 703393:tid 703542] [client 20.100.203.84:57720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-admin/js/"] [unique_id "amuHgs637Arlr6Yb1EcdCwAAAJg"]
[Thu Jul 30 12:18:58.380340 2026] [security2:error] [pid 703393:tid 703597] [client 20.100.203.84:57720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/makeasmtp.php"] [unique_id "amuHgs637Arlr6Yb1EcdDwAAAM8"]
[Thu Jul 30 12:18:58.380422 2026] [security2:error] [pid 703393:tid 703597] [client 20.100.203.84:57720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/makeasmtp.php"] [unique_id "amuHgs637Arlr6Yb1EcdDwAAAM8"]
[Thu Jul 30 12:18:58.397245 2026] [core:notice] [pid 703393:tid 703643] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:18:58.401844 2026] [security2:error] [pid 703393:tid 703643] [client 43.173.177.180:51950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2017/03/12/sostrene-grene-printemps-2017/"] [unique_id "amuHgs637Arlr6Yb1EcdEAAAAP0"], referer: https://carnetdeshopping.com/index.php/2017/03/12/sostrene-grene-printemps-2017/
[Thu Jul 30 12:18:58.423374 2026] [security2:error] [pid 703393:tid 703570] [client 4.225.166.222:29222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHgs637Arlr6Yb1EcdEQAAALQ"]
[Thu Jul 30 12:18:58.423479 2026] [security2:error] [pid 703393:tid 703570] [client 4.225.166.222:29222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHgs637Arlr6Yb1EcdEQAAALQ"]
[Thu Jul 30 12:18:58.579811 2026] [security2:error] [pid 703393:tid 703592] [client 20.151.221.234:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/222.php"] [unique_id "amuHgs637Arlr6Yb1EcdFQAAAMo"]
[Thu Jul 30 12:18:58.732264 2026] [security2:error] [pid 703393:tid 703574] [client 20.100.203.84:57713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/2P.php"] [unique_id "amuHgs637Arlr6Yb1EcdFgAAALg"]
[Thu Jul 30 12:18:58.732394 2026] [security2:error] [pid 703393:tid 703574] [client 20.100.203.84:57713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/2P.php"] [unique_id "amuHgs637Arlr6Yb1EcdFgAAALg"]
[Thu Jul 30 12:18:58.764144 2026] [security2:error] [pid 703393:tid 703626] [client 51.120.79.193:11251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/adminner.php"] [unique_id "amuHgs637Arlr6Yb1EcdFwAAAOw"]
[Thu Jul 30 12:18:58.764235 2026] [security2:error] [pid 703393:tid 703626] [client 51.120.79.193:11251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/adminner.php"] [unique_id "amuHgs637Arlr6Yb1EcdFwAAAOw"]
[Thu Jul 30 12:18:58.845637 2026] [security2:error] [pid 703393:tid 703554] [client 20.63.98.115:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/files/index.php"] [unique_id "amuHgs637Arlr6Yb1EcdHAAAAKQ"]
[Thu Jul 30 12:18:58.886244 2026] [security2:error] [pid 703393:tid 703561] [client 4.225.166.222:46286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHgs637Arlr6Yb1EcdHQAAAKs"]
[Thu Jul 30 12:18:58.886345 2026] [security2:error] [pid 703393:tid 703561] [client 4.225.166.222:46286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHgs637Arlr6Yb1EcdHQAAAKs"]
[Thu Jul 30 12:18:59.038520 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:34659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/.well-known/about.php"] [unique_id "amuHg8637Arlr6Yb1EcdIQAAAOo"]
[Thu Jul 30 12:18:59.038629 2026] [security2:error] [pid 703393:tid 703624] [client 20.100.203.84:34659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/.well-known/about.php"] [unique_id "amuHg8637Arlr6Yb1EcdIQAAAOo"]
[Thu Jul 30 12:18:59.170470 2026] [security2:error] [pid 703393:tid 703589] [client 20.91.199.21:46443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuHg8637Arlr6Yb1EcdJwAAAMc"]
[Thu Jul 30 12:18:59.204998 2026] [security2:error] [pid 703393:tid 703644] [client 4.225.166.222:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/x.php"] [unique_id "amuHg8637Arlr6Yb1EcdKAAAAP4"]
[Thu Jul 30 12:18:59.205132 2026] [security2:error] [pid 703393:tid 703644] [client 4.225.166.222:59013] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/x.php"] [unique_id "amuHg8637Arlr6Yb1EcdKAAAAP4"]
[Thu Jul 30 12:18:59.217669 2026] [security2:error] [pid 703393:tid 703599] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuHg8637Arlr6Yb1EcdJAAAANE"]
[Thu Jul 30 12:18:59.349453 2026] [security2:error] [pid 703393:tid 703618] [client 20.100.203.84:34668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHg8637Arlr6Yb1EcdKwAAAOQ"]
[Thu Jul 30 12:18:59.349552 2026] [security2:error] [pid 703393:tid 703618] [client 20.100.203.84:34668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHg8637Arlr6Yb1EcdKwAAAOQ"]
[Thu Jul 30 12:18:59.589747 2026] [security2:error] [pid 703393:tid 703635] [client 4.225.166.222:29189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/mgrr.php"] [unique_id "amuHg8637Arlr6Yb1EcdMQAAAPU"]
[Thu Jul 30 12:18:59.589847 2026] [security2:error] [pid 703393:tid 703635] [client 4.225.166.222:29189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/mgrr.php"] [unique_id "amuHg8637Arlr6Yb1EcdMQAAAPU"]
[Thu Jul 30 12:18:59.699352 2026] [security2:error] [pid 703393:tid 703617] [client 20.100.203.84:57689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/system_log.php"] [unique_id "amuHg8637Arlr6Yb1EcdNAAAAOM"]
[Thu Jul 30 12:18:59.699450 2026] [security2:error] [pid 703393:tid 703617] [client 20.100.203.84:57689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/system_log.php"] [unique_id "amuHg8637Arlr6Yb1EcdNAAAAOM"]
[Thu Jul 30 12:19:00.054716 2026] [security2:error] [pid 703393:tid 703567] [client 20.100.203.84:48700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/"] [unique_id "amuHhM637Arlr6Yb1EcdOgAAALE"]
[Thu Jul 30 12:19:00.118658 2026] [security2:error] [pid 703393:tid 703627] [client 4.225.166.222:29216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/domvf.php"] [unique_id "amuHhM637Arlr6Yb1EcdPQAAAO0"]
[Thu Jul 30 12:19:00.118758 2026] [security2:error] [pid 703393:tid 703627] [client 4.225.166.222:29216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/domvf.php"] [unique_id "amuHhM637Arlr6Yb1EcdPQAAAO0"]
[Thu Jul 30 12:19:00.332879 2026] [security2:error] [pid 703393:tid 703603] [client 51.120.79.193:11242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/admin.php"] [unique_id "amuHhM637Arlr6Yb1EcdPwAAANU"]
[Thu Jul 30 12:19:00.333012 2026] [security2:error] [pid 703393:tid 703603] [client 51.120.79.193:11242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/admin.php"] [unique_id "amuHhM637Arlr6Yb1EcdPwAAANU"]
[Thu Jul 30 12:19:00.396396 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:48700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/modern/"] [unique_id "amuHhM637Arlr6Yb1EcdQAAAALI"]
[Thu Jul 30 12:19:00.535718 2026] [security2:error] [pid 703393:tid 703592] [client 4.225.166.222:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/yup.php"] [unique_id "amuHhM637Arlr6Yb1EcdSAAAAMo"]
[Thu Jul 30 12:19:00.535826 2026] [security2:error] [pid 703393:tid 703592] [client 4.225.166.222:59068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/yup.php"] [unique_id "amuHhM637Arlr6Yb1EcdSAAAAMo"]
[Thu Jul 30 12:19:00.547017 2026] [security2:error] [pid 703393:tid 703622] [client 20.100.203.84:48700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/crgio.php"] [unique_id "amuHhM637Arlr6Yb1EcdSQAAAOg"]
[Thu Jul 30 12:19:00.547175 2026] [security2:error] [pid 703393:tid 703622] [client 20.100.203.84:48700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/crgio.php"] [unique_id "amuHhM637Arlr6Yb1EcdSQAAAOg"]
[Thu Jul 30 12:19:00.564647 2026] [security2:error] [pid 703393:tid 703640] [client 20.151.221.234:44750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuHhM637Arlr6Yb1EcdTAAAAPo"]
[Thu Jul 30 12:19:00.815971 2026] [security2:error] [pid 703393:tid 703639] [client 52.238.199.152:30131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/app.php"] [unique_id "amuHhM637Arlr6Yb1EcdTwAAAPk"]
[Thu Jul 30 12:19:00.851232 2026] [security2:error] [pid 703393:tid 703621] [client 20.100.203.84:48668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/pucci.php"] [unique_id "amuHhM637Arlr6Yb1EcdUAAAAOc"]
[Thu Jul 30 12:19:00.851324 2026] [security2:error] [pid 703393:tid 703621] [client 20.100.203.84:48668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/pucci.php"] [unique_id "amuHhM637Arlr6Yb1EcdUAAAAOc"]
[Thu Jul 30 12:19:01.075826 2026] [security2:error] [pid 703393:tid 703539] [client 51.120.79.193:10796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/ops.php"] [unique_id "amuHhc637Arlr6Yb1EcdVQAAAJU"]
[Thu Jul 30 12:19:01.075924 2026] [security2:error] [pid 703393:tid 703539] [client 51.120.79.193:10796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/ops.php"] [unique_id "amuHhc637Arlr6Yb1EcdVQAAAJU"]
[Thu Jul 30 12:19:01.195303 2026] [security2:error] [pid 703393:tid 703606] [client 20.100.203.84:34628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/blocks/details/"] [unique_id "amuHhc637Arlr6Yb1EcdWgAAANg"]
[Thu Jul 30 12:19:01.208058 2026] [security2:error] [pid 703393:tid 703588] [client 4.225.166.222:59018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/X.php"] [unique_id "amuHhc637Arlr6Yb1EcdXAAAAMY"]
[Thu Jul 30 12:19:01.208165 2026] [security2:error] [pid 703393:tid 703588] [client 4.225.166.222:59018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/X.php"] [unique_id "amuHhc637Arlr6Yb1EcdXAAAAMY"]
[Thu Jul 30 12:19:01.432231 2026] [security2:error] [pid 703393:tid 703604] [client 20.91.199.21:33605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuHhc637Arlr6Yb1EcdYQAAANY"]
[Thu Jul 30 12:19:01.525998 2026] [security2:error] [pid 703393:tid 703623] [client 4.225.166.222:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHhc637Arlr6Yb1EcdZwAAAOk"]
[Thu Jul 30 12:19:01.526103 2026] [security2:error] [pid 703393:tid 703623] [client 4.225.166.222:59071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHhc637Arlr6Yb1EcdZwAAAOk"]
[Thu Jul 30 12:19:01.531605 2026] [security2:error] [pid 703393:tid 703635] [client 20.100.203.84:34628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/blocks/audio/"] [unique_id "amuHhc637Arlr6Yb1EcdZQAAAPU"]
[Thu Jul 30 12:19:01.588130 2026] [security2:error] [pid 703393:tid 703533] [client 20.151.221.234:44100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuHhc637Arlr6Yb1EcdaQAAAI8"]
[Thu Jul 30 12:19:01.682815 2026] [security2:error] [pid 703393:tid 703631] [client 20.100.203.84:34628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-temp.php"] [unique_id "amuHhc637Arlr6Yb1EcdbAAAAPE"]
[Thu Jul 30 12:19:01.682955 2026] [security2:error] [pid 703393:tid 703631] [client 20.100.203.84:34628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-temp.php"] [unique_id "amuHhc637Arlr6Yb1EcdbAAAAPE"]
[Thu Jul 30 12:19:01.777349 2026] [security2:error] [pid 703393:tid 703587] [client 38.190.144.4:58079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuHhc637Arlr6Yb1EcdZgAAAMU"]
[Thu Jul 30 12:19:01.777565 2026] [security2:error] [pid 703393:tid 703587] [client 38.190.144.4:58079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuHhc637Arlr6Yb1EcdZgAAAMU"]
[Thu Jul 30 12:19:01.829479 2026] [security2:error] [pid 703393:tid 703611] [client 52.167.144.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHhc637Arlr6Yb1EcdZAAAAN0"]
[Thu Jul 30 12:19:01.850456 2026] [security2:error] [pid 703393:tid 703534] [client 195.113.175.167:35785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aboutf.php"] [unique_id "amuHhc637Arlr6Yb1EcdbQAAAJA"]
[Thu Jul 30 12:19:01.941212 2026] [security2:error] [pid 703393:tid 703536] [client 4.225.166.222:46294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/gec.php"] [unique_id "amuHhc637Arlr6Yb1EcddAAAAJI"]
[Thu Jul 30 12:19:01.941330 2026] [security2:error] [pid 703393:tid 703536] [client 4.225.166.222:46294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/gec.php"] [unique_id "amuHhc637Arlr6Yb1EcddAAAAJI"]
[Thu Jul 30 12:19:02.021182 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuHhs637Arlr6Yb1EcddQAAALI"]
[Thu Jul 30 12:19:02.021302 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:43790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuHhs637Arlr6Yb1EcddQAAALI"]
[Thu Jul 30 12:19:02.060269 2026] [security2:error] [pid 703393:tid 703627] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuHhc637Arlr6Yb1EcdcwAAAO0"]
[Thu Jul 30 12:19:02.252290 2026] [security2:error] [pid 703393:tid 703615] [client 20.63.98.115:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuHhs637Arlr6Yb1EcdfAAAAOE"]
[Thu Jul 30 12:19:02.282819 2026] [security2:error] [pid 703393:tid 703578] [client 4.225.166.222:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/sky.php"] [unique_id "amuHhs637Arlr6Yb1EcdfQAAALw"]
[Thu Jul 30 12:19:02.282931 2026] [security2:error] [pid 703393:tid 703578] [client 4.225.166.222:59028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/sky.php"] [unique_id "amuHhs637Arlr6Yb1EcdfQAAALw"]
[Thu Jul 30 12:19:02.407177 2026] [security2:error] [pid 703393:tid 703579] [client 20.100.203.84:48665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/puc.php"] [unique_id "amuHhs637Arlr6Yb1EcdfgAAAL0"]
[Thu Jul 30 12:19:02.407304 2026] [security2:error] [pid 703393:tid 703579] [client 20.100.203.84:48665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/puc.php"] [unique_id "amuHhs637Arlr6Yb1EcdfgAAAL0"]
[Thu Jul 30 12:19:02.634512 2026] [security2:error] [pid 703393:tid 703556] [client 51.120.79.193:10810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/mac.php"] [unique_id "amuHhs637Arlr6Yb1EcdhAAAAKY"]
[Thu Jul 30 12:19:02.634605 2026] [security2:error] [pid 703393:tid 703556] [client 51.120.79.193:10810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/mac.php"] [unique_id "amuHhs637Arlr6Yb1EcdhAAAAKY"]
[Thu Jul 30 12:19:02.649121 2026] [security2:error] [pid 703393:tid 703551] [client 4.225.166.222:59051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/fffm.php"] [unique_id "amuHhs637Arlr6Yb1EcdhQAAAKE"]
[Thu Jul 30 12:19:02.649200 2026] [security2:error] [pid 703393:tid 703551] [client 4.225.166.222:59051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/fffm.php"] [unique_id "amuHhs637Arlr6Yb1EcdhQAAAKE"]
[Thu Jul 30 12:19:02.734215 2026] [security2:error] [pid 703393:tid 703644] [client 20.100.203.84:43824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/dx.php"] [unique_id "amuHhs637Arlr6Yb1EcdiQAAAP4"]
[Thu Jul 30 12:19:02.734363 2026] [security2:error] [pid 703393:tid 703644] [client 20.100.203.84:43824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/dx.php"] [unique_id "amuHhs637Arlr6Yb1EcdiQAAAP4"]
[Thu Jul 30 12:19:02.743034 2026] [security2:error] [pid 703393:tid 703619] [client 20.151.221.234:44752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/admin.php"] [unique_id "amuHhs637Arlr6Yb1EcdigAAAOU"]
[Thu Jul 30 12:19:02.950555 2026] [security2:error] [pid 703393:tid 703586] [client 20.91.199.21:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuHhs637Arlr6Yb1EcdiwAAAMQ"]
[Thu Jul 30 12:19:03.139698 2026] [security2:error] [pid 703393:tid 703623] [client 20.100.203.84:43803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/Requests/"] [unique_id "amuHh8637Arlr6Yb1EcdkgAAAOk"]
[Thu Jul 30 12:19:03.178971 2026] [security2:error] [pid 703393:tid 703533] [client 4.225.166.222:46276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/sixxis.php"] [unique_id "amuHh8637Arlr6Yb1EcdkwAAAI8"]
[Thu Jul 30 12:19:03.179076 2026] [security2:error] [pid 703393:tid 703533] [client 4.225.166.222:46276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/sixxis.php"] [unique_id "amuHh8637Arlr6Yb1EcdkwAAAI8"]
[Thu Jul 30 12:19:03.444664 2026] [security2:error] [pid 703393:tid 703611] [client 20.100.203.84:43803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/7.php"] [unique_id "amuHh8637Arlr6Yb1EcdmAAAAN0"]
[Thu Jul 30 12:19:03.444778 2026] [security2:error] [pid 703393:tid 703611] [client 20.100.203.84:43803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/7.php"] [unique_id "amuHh8637Arlr6Yb1EcdmAAAAN0"]
[Thu Jul 30 12:19:03.512041 2026] [security2:error] [pid 703393:tid 703572] [client 66.249.68.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.dapperdangolf.com"] [uri "/index.php"] [unique_id "amuHhc637Arlr6Yb1EcdVAAAALY"]
[Thu Jul 30 12:19:03.575918 2026] [security2:error] [pid 703393:tid 703608] [client 20.151.221.234:44119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-configs.php"] [unique_id "amuHh8637Arlr6Yb1EcdnQAAANo"]
[Thu Jul 30 12:19:03.576517 2026] [security2:error] [pid 703393:tid 703625] [client 4.225.166.222:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/yj09.php"] [unique_id "amuHh8637Arlr6Yb1EcdngAAAOs"]
[Thu Jul 30 12:19:03.576632 2026] [security2:error] [pid 703393:tid 703625] [client 4.225.166.222:59035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/yj09.php"] [unique_id "amuHh8637Arlr6Yb1EcdngAAAOs"]
[Thu Jul 30 12:19:03.686056 2026] [security2:error] [pid 703393:tid 703557] [client 87.101.92.171:36314] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuHh8637Arlr6Yb1EcdnwAAAKc"]
[Thu Jul 30 12:19:03.686158 2026] [security2:error] [pid 703393:tid 703557] [client 87.101.92.171:36314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuHh8637Arlr6Yb1EcdnwAAAKc"]
[Thu Jul 30 12:19:03.719301 2026] [security2:error] [pid 703393:tid 703540] [client 20.63.98.115:61366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/network/admin.php"] [unique_id "amuHh8637Arlr6Yb1EcdoAAAAJY"]
[Thu Jul 30 12:19:03.737330 2026] [security2:error] [pid 703393:tid 703600] [client 43.173.181.235:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/01/19/sarah-jessica-parker-devoile-sa-premiere-collection-de-chaussures/"] [unique_id "amuHh8637Arlr6Yb1EcdnAAAANI"]
[Thu Jul 30 12:19:03.791770 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:43806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/8.php"] [unique_id "amuHh8637Arlr6Yb1EcdpAAAALI"]
[Thu Jul 30 12:19:03.791898 2026] [security2:error] [pid 703393:tid 703568] [client 20.100.203.84:43806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/8.php"] [unique_id "amuHh8637Arlr6Yb1EcdpAAAALI"]
[Thu Jul 30 12:19:03.890269 2026] [security2:error] [pid 703393:tid 703527] [client 4.225.166.222:46299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/k.php"] [unique_id "amuHh8637Arlr6Yb1EcdpQAAAIk"]
[Thu Jul 30 12:19:03.890377 2026] [security2:error] [pid 703393:tid 703527] [client 4.225.166.222:46299] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/k.php"] [unique_id "amuHh8637Arlr6Yb1EcdpQAAAIk"]
[Thu Jul 30 12:19:04.018393 2026] [security2:error] [pid 703393:tid 703607] [client 20.91.199.21:34997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuHiM637Arlr6Yb1EcdqQAAANk"]
[Thu Jul 30 12:19:04.179037 2026] [security2:error] [pid 703393:tid 703581] [client 52.238.199.152:30113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/k.php"] [unique_id "amuHiM637Arlr6Yb1EcdrQAAAL8"]
[Thu Jul 30 12:19:04.191893 2026] [security2:error] [pid 703393:tid 703633] [client 20.100.203.84:43799] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.heatstickhk.com"] [uri "/1.php"] [unique_id "amuHiM637Arlr6Yb1EcdsAAAAPM"]
[Thu Jul 30 12:19:04.192003 2026] [security2:error] [pid 703393:tid 703633] [client 20.100.203.84:43799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/1.php"] [unique_id "amuHiM637Arlr6Yb1EcdsAAAAPM"]
[Thu Jul 30 12:19:04.192080 2026] [security2:error] [pid 703393:tid 703633] [client 20.100.203.84:43799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/1.php"] [unique_id "amuHiM637Arlr6Yb1EcdsAAAAPM"]
[Thu Jul 30 12:19:04.192745 2026] [security2:error] [pid 703393:tid 703583] [client 51.120.79.193:10664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "progroup.jo"] [uri "/cgi-sys/404.html"] [unique_id "amuHiM637Arlr6Yb1EcdrwAAAME"]
[Thu Jul 30 12:19:04.508851 2026] [http2:info] [pid 727775:tid 727775] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:19:04.524253 2026] [security2:error] [pid 727775:tid 727905] [client 20.100.203.84:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/about.php"] [unique_id "amuHiMDCZkc4BvDXnoC2pAAAAAA"]
[Thu Jul 30 12:19:04.524462 2026] [security2:error] [pid 727775:tid 727905] [client 20.100.203.84:57676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/about.php"] [unique_id "amuHiMDCZkc4BvDXnoC2pAAAAAA"]
[Thu Jul 30 12:19:04.583039 2026] [core:notice] [pid 727775:tid 727909] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:04.590668 2026] [security2:error] [pid 727775:tid 727909] [client 43.173.174.253:37836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/01/19/sarah-jessica-parker-devoile-sa-premiere-collection-de-chaussures/"] [unique_id "amuHiMDCZkc4BvDXnoC2pwAAAAQ"], referer: https://carnetdeshopping.com/index.php/2014/01/19/sarah-jessica-parker-devoile-sa-premiere-collection-de-chaussures/?replytocom=1041
[Thu Jul 30 12:19:04.622100 2026] [security2:error] [pid 727775:tid 727913] [client 4.225.166.222:29204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/k2.php"] [unique_id "amuHiMDCZkc4BvDXnoC2qAAAAAg"]
[Thu Jul 30 12:19:04.622435 2026] [security2:error] [pid 727775:tid 727913] [client 4.225.166.222:29204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/k2.php"] [unique_id "amuHiMDCZkc4BvDXnoC2qAAAAAg"]
[Thu Jul 30 12:19:04.847696 2026] [security2:error] [pid 727775:tid 727926] [client 20.100.203.84:43786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/admin.php"] [unique_id "amuHiMDCZkc4BvDXnoC2sAAAABU"]
[Thu Jul 30 12:19:04.848122 2026] [security2:error] [pid 727775:tid 727926] [client 20.100.203.84:43786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/admin.php"] [unique_id "amuHiMDCZkc4BvDXnoC2sAAAABU"]
[Thu Jul 30 12:19:04.966999 2026] [security2:error] [pid 727775:tid 727911] [client 20.91.199.21:46444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuHiMDCZkc4BvDXnoC2sQAAAAY"]
[Thu Jul 30 12:19:05.012265 2026] [security2:error] [pid 727775:tid 727906] [client 20.151.221.234:44761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/php.php"] [unique_id "amuHiMDCZkc4BvDXnoC2tAAAAAE"]
[Thu Jul 30 12:19:05.190434 2026] [security2:error] [pid 727775:tid 727912] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHiMDCZkc4BvDXnoC2pgAAAAc"]
[Thu Jul 30 12:19:05.229780 2026] [security2:error] [pid 727775:tid 727950] [client 20.100.203.84:57705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/edit.php"] [unique_id "amuHicDCZkc4BvDXnoC2uwAAAC0"]
[Thu Jul 30 12:19:05.229920 2026] [security2:error] [pid 727775:tid 727950] [client 20.100.203.84:57705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/edit.php"] [unique_id "amuHicDCZkc4BvDXnoC2uwAAAC0"]
[Thu Jul 30 12:19:05.279189 2026] [security2:error] [pid 727775:tid 727951] [client 4.225.166.222:29200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/w.php"] [unique_id "amuHicDCZkc4BvDXnoC2vAAAAC4"]
[Thu Jul 30 12:19:05.279323 2026] [security2:error] [pid 727775:tid 727951] [client 4.225.166.222:29200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/w.php"] [unique_id "amuHicDCZkc4BvDXnoC2vAAAAC4"]
[Thu Jul 30 12:19:05.439437 2026] [security2:error] [pid 727775:tid 727907] [client 20.63.98.115:20512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuHicDCZkc4BvDXnoC2xAAAAAI"]
[Thu Jul 30 12:19:05.533262 2026] [security2:error] [pid 727775:tid 727967] [client 20.100.203.84:48693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/admin.php"] [unique_id "amuHicDCZkc4BvDXnoC2xQAAAD4"]
[Thu Jul 30 12:19:05.533529 2026] [security2:error] [pid 727775:tid 727967] [client 20.100.203.84:48693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/admin.php"] [unique_id "amuHicDCZkc4BvDXnoC2xQAAAD4"]
[Thu Jul 30 12:19:05.607648 2026] [security2:error] [pid 727775:tid 727972] [client 4.225.166.222:59058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/fpwch.php"] [unique_id "amuHicDCZkc4BvDXnoC2yQAAAEM"]
[Thu Jul 30 12:19:05.607828 2026] [security2:error] [pid 727775:tid 727972] [client 4.225.166.222:59058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/fpwch.php"] [unique_id "amuHicDCZkc4BvDXnoC2yQAAAEM"]
[Thu Jul 30 12:19:05.652968 2026] [security2:error] [pid 727775:tid 727935] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHicDCZkc4BvDXnoC2uAAAAB4"]
[Thu Jul 30 12:19:05.770258 2026] [security2:error] [pid 727775:tid 727971] [client 20.151.221.234:12860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/index.php"] [unique_id "amuHicDCZkc4BvDXnoC2zgAAAEI"]
[Thu Jul 30 12:19:05.775556 2026] [security2:error] [pid 727775:tid 727986] [client 51.120.79.193:10683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/pucci.php"] [unique_id "amuHicDCZkc4BvDXnoC2zwAAAFE"]
[Thu Jul 30 12:19:05.775664 2026] [security2:error] [pid 727775:tid 727986] [client 51.120.79.193:10683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/pucci.php"] [unique_id "amuHicDCZkc4BvDXnoC2zwAAAFE"]
[Thu Jul 30 12:19:05.891480 2026] [security2:error] [pid 727775:tid 727996] [client 20.100.203.84:57672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/inputs.php"] [unique_id "amuHicDCZkc4BvDXnoC21wAAAFs"]
[Thu Jul 30 12:19:05.891639 2026] [security2:error] [pid 727775:tid 727996] [client 20.100.203.84:57672] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/inputs.php"] [unique_id "amuHicDCZkc4BvDXnoC21wAAAFs"]
[Thu Jul 30 12:19:05.937784 2026] [security2:error] [pid 727775:tid 727927] [client 172.213.232.128:23134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/about.php"] [unique_id "amuHicDCZkc4BvDXnoC22wAAABY"]
[Thu Jul 30 12:19:05.970992 2026] [security2:error] [pid 727775:tid 728007] [client 4.225.166.222:46292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/w2025.php"] [unique_id "amuHicDCZkc4BvDXnoC23QAAAGY"]
[Thu Jul 30 12:19:05.971090 2026] [security2:error] [pid 727775:tid 728007] [client 4.225.166.222:46292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/w2025.php"] [unique_id "amuHicDCZkc4BvDXnoC23QAAAGY"]
[Thu Jul 30 12:19:06.023214 2026] [core:notice] [pid 727775:tid 727789] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:06.028748 2026] [security2:error] [pid 727775:tid 728011] [client 127.0.0.1:18848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHisDCZkc4BvDXnoC23wAAAGo"]
[Thu Jul 30 12:19:06.028831 2026] [security2:error] [pid 727775:tid 727987] [client 74.7.241.192:57958] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.nuk.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuHicDCZkc4BvDXnoC23gAAUgw"]
[Thu Jul 30 12:19:06.047302 2026] [security2:error] [pid 727775:tid 727968] [client 20.91.199.21:46413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuHisDCZkc4BvDXnoC25AAAAD8"]
[Thu Jul 30 12:19:06.230704 2026] [security2:error] [pid 727775:tid 728024] [client 20.100.203.84:43794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/av.php"] [unique_id "amuHisDCZkc4BvDXnoC25gAAAHc"]
[Thu Jul 30 12:19:06.230839 2026] [security2:error] [pid 727775:tid 728024] [client 20.100.203.84:43794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/av.php"] [unique_id "amuHisDCZkc4BvDXnoC25gAAAHc"]
[Thu Jul 30 12:19:06.250688 2026] [security2:error] [pid 727775:tid 727982] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHicDCZkc4BvDXnoC2zQAAAE0"]
[Thu Jul 30 12:19:06.395877 2026] [security2:error] [pid 727775:tid 728016] [client 40.77.167.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHisDCZkc4BvDXnoC24wAAAG8"]
[Thu Jul 30 12:19:06.456778 2026] [security2:error] [pid 727775:tid 727926] [client 4.225.166.222:46317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/FWAZ.php"] [unique_id "amuHisDCZkc4BvDXnoC26gAAABU"]
[Thu Jul 30 12:19:06.456888 2026] [security2:error] [pid 727775:tid 727926] [client 4.225.166.222:46317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/FWAZ.php"] [unique_id "amuHisDCZkc4BvDXnoC26gAAABU"]
[Thu Jul 30 12:19:06.512907 2026] [security2:error] [pid 727775:tid 728028] [client 20.151.221.234:44780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/a.php"] [unique_id "amuHisDCZkc4BvDXnoC27gAAAHs"]
[Thu Jul 30 12:19:06.529541 2026] [security2:error] [pid 727775:tid 727970] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuHicDCZkc4BvDXnoC2yAAAAEE"]
[Thu Jul 30 12:19:06.631806 2026] [security2:error] [pid 727775:tid 727936] [client 20.100.203.84:57679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/classwithtostring.php"] [unique_id "amuHisDCZkc4BvDXnoC28wAAAB8"]
[Thu Jul 30 12:19:06.631956 2026] [security2:error] [pid 727775:tid 727936] [client 20.100.203.84:57679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/classwithtostring.php"] [unique_id "amuHisDCZkc4BvDXnoC28wAAAB8"]
[Thu Jul 30 12:19:06.773604 2026] [security2:error] [pid 727775:tid 727912] [client 4.225.166.222:56118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/qterm.php"] [unique_id "amuHisDCZkc4BvDXnoC29AAAAAc"]
[Thu Jul 30 12:19:06.773717 2026] [security2:error] [pid 727775:tid 727912] [client 4.225.166.222:56118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/qterm.php"] [unique_id "amuHisDCZkc4BvDXnoC29AAAAAc"]
[Thu Jul 30 12:19:07.088948 2026] [security2:error] [pid 727775:tid 727960] [client 20.100.203.84:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC2_gAAADc"]
[Thu Jul 30 12:19:07.089113 2026] [security2:error] [pid 727775:tid 727960] [client 20.100.203.84:43800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC2_gAAADc"]
[Thu Jul 30 12:19:07.122010 2026] [security2:error] [pid 727775:tid 727967] [client 4.225.166.222:29223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/blurbs.php"] [unique_id "amuHi8DCZkc4BvDXnoC2_wAAAD4"]
[Thu Jul 30 12:19:07.122132 2026] [security2:error] [pid 727775:tid 727967] [client 4.225.166.222:29223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/blurbs.php"] [unique_id "amuHi8DCZkc4BvDXnoC2_wAAAD4"]
[Thu Jul 30 12:19:07.414527 2026] [security2:error] [pid 727775:tid 727984] [client 20.100.203.84:34669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-blog.php"] [unique_id "amuHi8DCZkc4BvDXnoC3BwAAAE8"]
[Thu Jul 30 12:19:07.414649 2026] [security2:error] [pid 727775:tid 727984] [client 20.100.203.84:34669] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-blog.php"] [unique_id "amuHi8DCZkc4BvDXnoC3BwAAAE8"]
[Thu Jul 30 12:19:07.525531 2026] [security2:error] [pid 727775:tid 727986] [client 4.225.166.222:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/wp-ws68.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CQAAAFE"]
[Thu Jul 30 12:19:07.525647 2026] [security2:error] [pid 727775:tid 727986] [client 4.225.166.222:59062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/wp-ws68.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CQAAAFE"]
[Thu Jul 30 12:19:07.542571 2026] [security2:error] [pid 727775:tid 727996] [client 51.120.79.193:16127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/js/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CgAAAFs"]
[Thu Jul 30 12:19:07.542724 2026] [security2:error] [pid 727775:tid 727996] [client 51.120.79.193:16127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/wp-admin/js/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CgAAAFs"]
[Thu Jul 30 12:19:07.857814 2026] [security2:error] [pid 727775:tid 727973] [client 20.100.203.84:48644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/wp-includes/js/jquery/"] [unique_id "amuHi8DCZkc4BvDXnoC3DQAAAEQ"]
[Thu Jul 30 12:19:07.862488 2026] [security2:error] [pid 727775:tid 728000] [client 4.225.166.222:46311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/xyn.php"] [unique_id "amuHi8DCZkc4BvDXnoC3DwAAAF8"]
[Thu Jul 30 12:19:07.862644 2026] [security2:error] [pid 727775:tid 728000] [client 4.225.166.222:46311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/xyn.php"] [unique_id "amuHi8DCZkc4BvDXnoC3DwAAAF8"]
[Thu Jul 30 12:19:08.039648 2026] [security2:error] [pid 727775:tid 728007] [client 20.151.221.234:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuHjMDCZkc4BvDXnoC3FwAAAGY"]
[Thu Jul 30 12:19:08.039688 2026] [security2:error] [pid 727775:tid 727985] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC3CAAAUBc"]
[Thu Jul 30 12:19:08.100971 2026] [security2:error] [pid 727775:tid 727918] [client 172.213.232.128:8800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/admin.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GAAAAA0"]
[Thu Jul 30 12:19:08.158894 2026] [security2:error] [pid 727775:tid 728012] [client 20.100.203.84:48644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/admin.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GQAAAGs"]
[Thu Jul 30 12:19:08.159036 2026] [security2:error] [pid 727775:tid 728012] [client 20.100.203.84:48644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/wp-content/admin.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GQAAAGs"]
[Thu Jul 30 12:19:08.199736 2026] [security2:error] [pid 727775:tid 727987] [client 4.225.166.222:29224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/ccc.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GgAAAFI"]
[Thu Jul 30 12:19:08.199845 2026] [security2:error] [pid 727775:tid 727987] [client 4.225.166.222:29224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/ccc.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GgAAAFI"]
[Thu Jul 30 12:19:08.217664 2026] [security2:error] [pid 727775:tid 727999] [client 20.91.199.21:35209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuHjMDCZkc4BvDXnoC3GwAAAF4"]
[Thu Jul 30 12:19:08.250754 2026] [security2:error] [pid 727775:tid 727989] [client 51.120.79.193:10807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/8.php"] [unique_id "amuHjMDCZkc4BvDXnoC3HAAAAFQ"]
[Thu Jul 30 12:19:08.250877 2026] [security2:error] [pid 727775:tid 727989] [client 51.120.79.193:10807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "progroup.jo"] [uri "/8.php"] [unique_id "amuHjMDCZkc4BvDXnoC3HAAAAFQ"]
[Thu Jul 30 12:19:08.490660 2026] [security2:error] [pid 727775:tid 727983] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHi8DCZkc4BvDXnoC3DAAAThg"]
[Thu Jul 30 12:19:08.502804 2026] [security2:error] [pid 727775:tid 728026] [client 4.225.166.222:29214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/get.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JAAAAHk"]
[Thu Jul 30 12:19:08.502918 2026] [security2:error] [pid 727775:tid 728026] [client 4.225.166.222:29214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/get.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JAAAAHk"]
[Thu Jul 30 12:19:08.504749 2026] [security2:error] [pid 727775:tid 727981] [client 20.100.203.84:43785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/adminfuns.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JQAAAEw"]
[Thu Jul 30 12:19:08.504851 2026] [security2:error] [pid 727775:tid 727981] [client 20.100.203.84:43785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/adminfuns.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JQAAAEw"]
[Thu Jul 30 12:19:08.751350 2026] [security2:error] [pid 727775:tid 727983] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHjMDCZkc4BvDXnoC3FgAAThs"]
[Thu Jul 30 12:19:08.794665 2026] [security2:error] [pid 727775:tid 727807] [remote 57.141.0.33:28174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/94764231632/feed/rss2/"] [unique_id "amuHjMDCZkc4BvDXnoC3JgAAeh8"]
[Thu Jul 30 12:19:08.823208 2026] [security2:error] [pid 727775:tid 727905] [client 20.100.203.84:48651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/goods.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JwAAAAA"]
[Thu Jul 30 12:19:08.823375 2026] [security2:error] [pid 727775:tid 727905] [client 20.100.203.84:48651] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/goods.php"] [unique_id "amuHjMDCZkc4BvDXnoC3JwAAAAA"]
[Thu Jul 30 12:19:08.840040 2026] [security2:error] [pid 727775:tid 727913] [client 4.225.166.222:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/images.php"] [unique_id "amuHjMDCZkc4BvDXnoC3KAAAAAg"]
[Thu Jul 30 12:19:08.840158 2026] [security2:error] [pid 727775:tid 727913] [client 4.225.166.222:59060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/images.php"] [unique_id "amuHjMDCZkc4BvDXnoC3KAAAAAg"]
[Thu Jul 30 12:19:09.149765 2026] [security2:error] [pid 727775:tid 727906] [client 4.225.166.222:29235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/alls.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MAAAAAE"]
[Thu Jul 30 12:19:09.149872 2026] [security2:error] [pid 727775:tid 727906] [client 4.225.166.222:29235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/alls.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MAAAAAE"]
[Thu Jul 30 12:19:09.162707 2026] [security2:error] [pid 727775:tid 727969] [client 20.100.203.84:34679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/ms-edit.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MQAAAEA"]
[Thu Jul 30 12:19:09.162841 2026] [security2:error] [pid 727775:tid 727969] [client 20.100.203.84:34679] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/ms-edit.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MQAAAEA"]
[Thu Jul 30 12:19:09.379320 2026] [security2:error] [pid 727775:tid 728014] [client 20.151.221.234:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin.php"] [unique_id "amuHjcDCZkc4BvDXnoC3MgAAAG0"]
[Thu Jul 30 12:19:09.381696 2026] [security2:error] [pid 727775:tid 727924] [client 20.91.199.21:46411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuHjcDCZkc4BvDXnoC3LwAAABM"]
[Thu Jul 30 12:19:09.394916 2026] [security2:error] [pid 727775:tid 727970] [client 172.213.232.128:9115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuHjcDCZkc4BvDXnoC3NAAAAEE"]
[Thu Jul 30 12:19:09.462677 2026] [security2:error] [pid 727775:tid 727941] [client 20.100.203.84:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.heatstickhk.com"] [uri "/222.php"] [unique_id "amuHjcDCZkc4BvDXnoC3OAAAACQ"]
[Thu Jul 30 12:19:09.462771 2026] [security2:error] [pid 727775:tid 727941] [client 20.100.203.84:57692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.heatstickhk.com"] [uri "/222.php"] [unique_id "amuHjcDCZkc4BvDXnoC3OAAAACQ"]
[Thu Jul 30 12:19:09.571714 2026] [security2:error] [pid 727775:tid 727949] [client 4.225.166.222:29244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.05.adtop.net"] [uri "/coffexium.php"] [unique_id "amuHjcDCZkc4BvDXnoC3PAAAACw"]
[Thu Jul 30 12:19:09.571821 2026] [security2:error] [pid 727775:tid 727949] [client 4.225.166.222:29244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.05.adtop.net"] [uri "/coffexium.php"] [unique_id "amuHjcDCZkc4BvDXnoC3PAAAACw"]
[Thu Jul 30 12:19:09.813409 2026] [security2:error] [pid 727775:tid 727813] [remote 47.128.28.101:46408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-retro-high-og-chenille/"] [unique_id "amuHjcDCZkc4BvDXnoC3PgAAOiU"]
[Thu Jul 30 12:19:10.111116 2026] [security2:error] [pid 727775:tid 727964] [client 172.213.232.128:1541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuHjsDCZkc4BvDXnoC3RgAAADs"]
[Thu Jul 30 12:19:10.388448 2026] [autoindex:error] [pid 727775:tid 727923] [client 87.236.176.79:0] AH01276: Cannot serve directory /home2/mbmudite/ok.koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.koidomino.click:8880
[Thu Jul 30 12:19:10.411185 2026] [security2:error] [pid 727775:tid 727956] [client 20.151.221.234:4358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/size.php"] [unique_id "amuHjsDCZkc4BvDXnoC3SgAAADM"]
[Thu Jul 30 12:19:10.664637 2026] [security2:error] [pid 727775:tid 727986] [client 172.213.232.128:16232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuHjsDCZkc4BvDXnoC3UwAAAFE"]
[Thu Jul 30 12:19:10.784801 2026] [security2:error] [pid 727775:tid 727958] [client 2a03:2880:f800:46:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHjsDCZkc4BvDXnoC3RwAANSk"]
[Thu Jul 30 12:19:11.445205 2026] [security2:error] [pid 727775:tid 728029] [client 20.63.98.115:54188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuHj8DCZkc4BvDXnoC3XwAAAHw"]
[Thu Jul 30 12:19:11.527886 2026] [security2:error] [pid 727775:tid 728005] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHjsDCZkc4BvDXnoC3VgAAAGQ"]
[Thu Jul 30 12:19:12.296242 2026] [security2:error] [pid 727775:tid 728023] [client 20.151.221.234:44747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuHkMDCZkc4BvDXnoC3bQAAAHY"]
[Thu Jul 30 12:19:12.474454 2026] [core:error] [pid 727775:tid 727952] [client 74.7.230.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:12.474481 2026] [core:error] [pid 727775:tid 727952] [client 74.7.230.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:12.474640 2026] [security2:error] [pid 727775:tid 727952] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.elitegaragedoorrepairservices.us"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuHkMDCZkc4BvDXnoC3cAAAAC8"]
[Thu Jul 30 12:19:12.475161 2026] [security2:error] [pid 727775:tid 727930] [client 74.7.230.63:34086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.elitegaragedoorrepairservices.us"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuHkMDCZkc4BvDXnoC3bgAAGTY"]
[Thu Jul 30 12:19:12.750924 2026] [security2:error] [pid 727775:tid 727924] [client 20.63.98.115:44013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/fonts/wp-login.php"] [unique_id "amuHkMDCZkc4BvDXnoC3dwAAABM"]
[Thu Jul 30 12:19:13.085436 2026] [security2:error] [pid 727775:tid 727835] [remote 104.238.222.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuHkcDCZkc4BvDXnoC3fAAALjs"], referer: https://t.co/
[Thu Jul 30 12:19:13.241061 2026] [security2:error] [pid 727775:tid 727950] [client 20.151.221.234:4378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/403.php"] [unique_id "amuHkcDCZkc4BvDXnoC3gwAAAC0"]
[Thu Jul 30 12:19:13.360073 2026] [security2:error] [pid 727775:tid 728020] [client 172.213.232.128:18101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuHkcDCZkc4BvDXnoC3hAAAAHM"]
[Thu Jul 30 12:19:13.431909 2026] [security2:error] [pid 727775:tid 727944] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHkMDCZkc4BvDXnoC3egAAACc"]
[Thu Jul 30 12:19:13.570296 2026] [security2:error] [pid 727775:tid 727966] [client 20.63.98.115:54149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/themes.php"] [unique_id "amuHkcDCZkc4BvDXnoC3hQAAAD0"]
[Thu Jul 30 12:19:13.810511 2026] [security2:error] [pid 727775:tid 727840] [remote 104.238.222.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuHkcDCZkc4BvDXnoC3jAAAXUA"], referer: https://www.google.com/
[Thu Jul 30 12:19:14.113420 2026] [security2:error] [pid 727775:tid 727992] [client 20.151.221.234:35495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuHksDCZkc4BvDXnoC3jwAAAFc"]
[Thu Jul 30 12:19:14.119061 2026] [security2:error] [pid 727775:tid 727996] [client 172.213.232.128:13828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuHksDCZkc4BvDXnoC3kAAAAFs"]
[Thu Jul 30 12:19:14.417007 2026] [security2:error] [pid 727775:tid 727995] [client 20.63.98.115:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/if.php"] [unique_id "amuHksDCZkc4BvDXnoC3mAAAAFo"]
[Thu Jul 30 12:19:14.954239 2026] [security2:error] [pid 727775:tid 728019] [client 20.151.221.234:44144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/as.php"] [unique_id "amuHksDCZkc4BvDXnoC3owAAAHI"]
[Thu Jul 30 12:19:14.955890 2026] [security2:error] [pid 727775:tid 727850] [remote 104.238.222.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuHksDCZkc4BvDXnoC3pAAATEo"]
[Thu Jul 30 12:19:15.112555 2026] [security2:error] [pid 727775:tid 728011] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHksDCZkc4BvDXnoC3mwAAAGo"]
[Thu Jul 30 12:19:16.315693 2026] [security2:error] [pid 727775:tid 728024] [client 20.63.98.115:57235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/editor.php"] [unique_id "amuHlMDCZkc4BvDXnoC3vQAAAHc"]
[Thu Jul 30 12:19:16.817877 2026] [security2:error] [pid 727775:tid 727950] [client 20.151.221.234:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuHlMDCZkc4BvDXnoC3xAAAAC0"]
[Thu Jul 30 12:19:16.975515 2026] [security2:error] [pid 727775:tid 727944] [client 172.213.232.128:1552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuHlMDCZkc4BvDXnoC3yAAAACc"]
[Thu Jul 30 12:19:17.203772 2026] [security2:error] [pid 727775:tid 727964] [client 74.7.241.139:35798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "google-search.org"] [uri "/robots.txt"] [unique_id "amuHlcDCZkc4BvDXnoC3yQAAO1Y"]
[Thu Jul 30 12:19:17.574047 2026] [security2:error] [pid 727775:tid 727934] [client 20.63.98.115:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/click.php"] [unique_id "amuHlcDCZkc4BvDXnoC30gAAAB0"]
[Thu Jul 30 12:19:17.620360 2026] [security2:error] [pid 727775:tid 727991] [client 20.151.221.234:4357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuHlcDCZkc4BvDXnoC30wAAAFY"]
[Thu Jul 30 12:19:17.804911 2026] [security2:error] [pid 727775:tid 727958] [client 172.213.232.128:7754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuHlcDCZkc4BvDXnoC31AAAADU"]
[Thu Jul 30 12:19:18.507401 2026] [security2:error] [pid 727775:tid 727968] [client 20.151.221.234:44744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/plugins.php"] [unique_id "amuHlsDCZkc4BvDXnoC35QAAAD8"]
[Thu Jul 30 12:19:18.604736 2026] [core:error] [pid 727775:tid 727916] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.604762 2026] [core:error] [pid 727775:tid 727916] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.699205 2026] [core:error] [pid 727775:tid 728023] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.699221 2026] [core:error] [pid 727775:tid 727906] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.699228 2026] [core:error] [pid 727775:tid 728023] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.699237 2026] [core:error] [pid 727775:tid 727906] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.709162 2026] [security2:error] [pid 727775:tid 727981] [client 172.213.232.128:23136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/content.php"] [unique_id "amuHlsDCZkc4BvDXnoC39gAAAEw"]
[Thu Jul 30 12:19:18.715427 2026] [core:error] [pid 727775:tid 727937] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.715448 2026] [core:error] [pid 727775:tid 727937] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.757611 2026] [core:error] [pid 727775:tid 727945] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.757631 2026] [core:error] [pid 727775:tid 727945] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:18.784329 2026] [security2:error] [pid 727775:tid 728022] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHlsDCZkc4BvDXnoC33gAAAHU"]
[Thu Jul 30 12:19:19.476999 2026] [security2:error] [pid 727775:tid 727976] [client 20.151.221.234:44757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuHl8DCZkc4BvDXnoC4DAAAAEc"]
[Thu Jul 30 12:19:20.267820 2026] [security2:error] [pid 727775:tid 727988] [client 20.63.98.115:57248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/test.php7"] [unique_id "amuHmMDCZkc4BvDXnoC4GQAAAFM"]
[Thu Jul 30 12:19:20.304478 2026] [security2:error] [pid 727775:tid 728018] [client 87.101.92.171:43646] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuHmMDCZkc4BvDXnoC4GgAAAHE"]
[Thu Jul 30 12:19:20.304582 2026] [security2:error] [pid 727775:tid 728018] [client 87.101.92.171:43646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuHmMDCZkc4BvDXnoC4GgAAAHE"]
[Thu Jul 30 12:19:20.473079 2026] [security2:error] [pid 727775:tid 728001] [client 20.151.221.234:44741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/go.php"] [unique_id "amuHmMDCZkc4BvDXnoC4JQAAAGA"]
[Thu Jul 30 12:19:20.840251 2026] [security2:error] [pid 727775:tid 727989] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHmMDCZkc4BvDXnoC4GAAAAFQ"]
[Thu Jul 30 12:19:21.598274 2026] [security2:error] [pid 727775:tid 728020] [client 172.213.232.128:39193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuHmcDCZkc4BvDXnoC4PQAAAHM"]
[Thu Jul 30 12:19:22.371834 2026] [security2:error] [pid 727775:tid 727936] [client 20.151.221.234:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/test1.php"] [unique_id "amuHmsDCZkc4BvDXnoC4RQAAAB8"]
[Thu Jul 30 12:19:22.385686 2026] [security2:error] [pid 727775:tid 728024] [client 172.213.232.128:1131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuHmsDCZkc4BvDXnoC4RgAAAHc"]
[Thu Jul 30 12:19:23.322061 2026] [security2:error] [pid 727775:tid 728002] [client 172.213.232.128:1090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuHm8DCZkc4BvDXnoC4WgAAAGE"]
[Thu Jul 30 12:19:23.933524 2026] [core:notice] [pid 727775:tid 727794] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:24.340781 2026] [security2:error] [pid 727775:tid 727937] [client 213.152.161.118:40076] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuHnMDCZkc4BvDXnoC4bgAAACA"]
[Thu Jul 30 12:19:24.340876 2026] [security2:error] [pid 727775:tid 727937] [client 213.152.161.118:40076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuHnMDCZkc4BvDXnoC4bgAAACA"]
[Thu Jul 30 12:19:24.502152 2026] [security2:error] [pid 727775:tid 728014] [client 20.151.221.234:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/images/index.php"] [unique_id "amuHnMDCZkc4BvDXnoC4bwAAAG0"]
[Thu Jul 30 12:19:24.703924 2026] [security2:error] [pid 727775:tid 727994] [client 20.63.98.115:57228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuHnMDCZkc4BvDXnoC4dQAAAFk"]
[Thu Jul 30 12:19:24.752953 2026] [security2:error] [pid 727775:tid 727906] [client 172.213.232.128:23117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuHnMDCZkc4BvDXnoC4eAAAAAE"]
[Thu Jul 30 12:19:25.006935 2026] [security2:error] [pid 727775:tid 728029] [client 174.138.89.209:47568] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuHncDCZkc4BvDXnoC4eQAAAHw"]
[Thu Jul 30 12:19:25.197032 2026] [security2:error] [pid 727775:tid 727957] [client 114.119.155.153:35323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mediaspawn.com"] [uri "/robots.txt"] [unique_id "amuHncDCZkc4BvDXnoC4gQAAADQ"], referer: http://www.mediaspawn.com/robots.txt
[Thu Jul 30 12:19:25.234003 2026] [security2:error] [pid 727775:tid 727949] [client 174.138.89.209:37054] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuHncDCZkc4BvDXnoC4hQAAACw"]
[Thu Jul 30 12:19:25.537854 2026] [security2:error] [pid 727775:tid 727963] [client 20.63.98.115:57220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/content.php"] [unique_id "amuHncDCZkc4BvDXnoC4iQAAADo"]
[Thu Jul 30 12:19:25.560521 2026] [security2:error] [pid 727775:tid 727936] [client 172.213.232.128:18623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuHncDCZkc4BvDXnoC4iwAAAB8"]
[Thu Jul 30 12:19:25.949713 2026] [security2:error] [pid 727775:tid 727964] [client 47.128.56.189:22946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.northyorksheridanmall.com"] [uri "/robots.txt"] [unique_id "amuHncDCZkc4BvDXnoC4mAAAADs"]
[Thu Jul 30 12:19:26.329015 2026] [security2:error] [pid 727775:tid 727988] [client 172.213.232.128:1585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuHnsDCZkc4BvDXnoC4owAAAFM"]
[Thu Jul 30 12:19:26.789948 2026] [security2:error] [pid 727775:tid 727958] [client 20.63.98.115:57278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known.php"] [unique_id "amuHnsDCZkc4BvDXnoC4rQAAADU"]
[Thu Jul 30 12:19:27.028328 2026] [security2:error] [pid 727775:tid 727913] [client 20.151.221.234:4352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/asd.php"] [unique_id "amuHn8DCZkc4BvDXnoC4rwAAAAg"]
[Thu Jul 30 12:19:27.337804 2026] [security2:error] [pid 727775:tid 727816] [remote 74.7.241.60:50634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/article.php"] [unique_id "amuHn8DCZkc4BvDXnoC4tgAAIig"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 12:19:27.654110 2026] [security2:error] [pid 727775:tid 727922] [client 20.63.98.115:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuHn8DCZkc4BvDXnoC4uwAAABE"]
[Thu Jul 30 12:19:27.927096 2026] [security2:error] [pid 727775:tid 727957] [client 20.151.221.234:12839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuHn8DCZkc4BvDXnoC4xAAAADQ"]
[Thu Jul 30 12:19:28.720514 2026] [security2:error] [pid 727775:tid 727956] [client 20.63.98.115:54777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/twenty/twenty.php"] [unique_id "amuHoMDCZkc4BvDXnoC40gAAADM"]
[Thu Jul 30 12:19:28.743074 2026] [security2:error] [pid 727775:tid 727998] [client 20.151.221.234:44111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuHoMDCZkc4BvDXnoC40wAAAF0"]
[Thu Jul 30 12:19:29.424677 2026] [core:notice] [pid 727775:tid 727982] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:29.585237 2026] [security2:error] [pid 727775:tid 727821] [remote 66.249.88.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuHoMDCZkc4BvDXnoC40AAAHi0"]
[Thu Jul 30 12:19:29.591824 2026] [security2:error] [pid 727775:tid 728009] [client 20.63.98.115:27243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuHocDCZkc4BvDXnoC43wAAAGg"]
[Thu Jul 30 12:19:29.760897 2026] [security2:error] [pid 727775:tid 727927] [client 158.158.105.63:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHocDCZkc4BvDXnoC44wAAABY"]
[Thu Jul 30 12:19:29.761017 2026] [security2:error] [pid 727775:tid 727927] [client 158.158.105.63:52240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuHocDCZkc4BvDXnoC44wAAABY"]
[Thu Jul 30 12:19:30.061799 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.105.63:19623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHosDCZkc4BvDXnoC46AAAAAk"]
[Thu Jul 30 12:19:30.061883 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.105.63:19623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuHosDCZkc4BvDXnoC46AAAAAk"]
[Thu Jul 30 12:19:30.189648 2026] [security2:error] [pid 727775:tid 727911] [client 172.213.232.128:7772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuHosDCZkc4BvDXnoC47AAAAAY"]
[Thu Jul 30 12:19:30.330430 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.105.63:19620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/x.php"] [unique_id "amuHosDCZkc4BvDXnoC47gAAAG8"]
[Thu Jul 30 12:19:30.330563 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.105.63:19620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/x.php"] [unique_id "amuHosDCZkc4BvDXnoC47gAAAG8"]
[Thu Jul 30 12:19:30.536705 2026] [core:notice] [pid 727775:tid 727937] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:30.627829 2026] [security2:error] [pid 727775:tid 728006] [client 20.63.98.115:32429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/about.php"] [unique_id "amuHosDCZkc4BvDXnoC49gAAAGU"]
[Thu Jul 30 12:19:30.641182 2026] [security2:error] [pid 727775:tid 728005] [client 158.158.105.63:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/mgrr.php"] [unique_id "amuHosDCZkc4BvDXnoC49wAAAGQ"]
[Thu Jul 30 12:19:30.641266 2026] [security2:error] [pid 727775:tid 728005] [client 158.158.105.63:52226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/mgrr.php"] [unique_id "amuHosDCZkc4BvDXnoC49wAAAGQ"]
[Thu Jul 30 12:19:30.716364 2026] [security2:error] [pid 727775:tid 727837] [remote 74.7.241.59:53642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuHosDCZkc4BvDXnoC4-AAACD0"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:19:30.911592 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/domvf.php"] [unique_id "amuHosDCZkc4BvDXnoC4_QAAAFU"]
[Thu Jul 30 12:19:30.911757 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/domvf.php"] [unique_id "amuHosDCZkc4BvDXnoC4_QAAAFU"]
[Thu Jul 30 12:19:31.138513 2026] [security2:error] [pid 727775:tid 727939] [client 172.213.232.128:1536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuHo8DCZkc4BvDXnoC5AwAAACI"]
[Thu Jul 30 12:19:31.177564 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.105.63:19611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/yup.php"] [unique_id "amuHo8DCZkc4BvDXnoC5BAAAAA8"]
[Thu Jul 30 12:19:31.177673 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.105.63:19611] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/yup.php"] [unique_id "amuHo8DCZkc4BvDXnoC5BAAAAA8"]
[Thu Jul 30 12:19:31.442916 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.105.63:19633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/X.php"] [unique_id "amuHo8DCZkc4BvDXnoC5CgAAAGc"]
[Thu Jul 30 12:19:31.443074 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.105.63:19633] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/X.php"] [unique_id "amuHo8DCZkc4BvDXnoC5CgAAAGc"]
[Thu Jul 30 12:19:31.690332 2026] [security2:error] [pid 727775:tid 727987] [client 216.73.217.139:31341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tmrfsl.com"] [uri "/index.php"] [unique_id "amuHo8DCZkc4BvDXnoC5DgAAUkU"]
[Thu Jul 30 12:19:31.747545 2026] [security2:error] [pid 727775:tid 727998] [client 158.158.105.63:19613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHo8DCZkc4BvDXnoC5DwAAAF0"]
[Thu Jul 30 12:19:31.747656 2026] [security2:error] [pid 727775:tid 727998] [client 158.158.105.63:19613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuHo8DCZkc4BvDXnoC5DwAAAF0"]
[Thu Jul 30 12:19:31.780289 2026] [security2:error] [pid 727775:tid 728001] [client 20.151.221.234:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/atomlib.php"] [unique_id "amuHo8DCZkc4BvDXnoC5EQAAAGA"]
[Thu Jul 30 12:19:31.886853 2026] [security2:error] [pid 727775:tid 727997] [client 172.213.232.128:16209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuHo8DCZkc4BvDXnoC5EgAAAFw"]
[Thu Jul 30 12:19:31.980623 2026] [security2:error] [pid 727775:tid 727957] [client 20.63.98.115:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/customize/about.php"] [unique_id "amuHo8DCZkc4BvDXnoC5FQAAADQ"]
[Thu Jul 30 12:19:31.981086 2026] [security2:error] [pid 727775:tid 727931] [client 216.73.217.139:31341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tmrfsl.com"] [uri "/index.php"] [unique_id "amuHo8DCZkc4BvDXnoC5EwAAGkE"], referer: https://tmrfsl.com/sitemap.xml
[Thu Jul 30 12:19:32.019486 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:52261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/gec.php"] [unique_id "amuHpMDCZkc4BvDXnoC5GAAAAGM"]
[Thu Jul 30 12:19:32.019619 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:52261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/gec.php"] [unique_id "amuHpMDCZkc4BvDXnoC5GAAAAGM"]
[Thu Jul 30 12:19:32.318224 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/sky.php"] [unique_id "amuHpMDCZkc4BvDXnoC5HAAAAFA"]
[Thu Jul 30 12:19:32.318344 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/sky.php"] [unique_id "amuHpMDCZkc4BvDXnoC5HAAAAFA"]
[Thu Jul 30 12:19:32.586763 2026] [security2:error] [pid 727775:tid 727925] [client 158.158.105.63:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/fffm.php"] [unique_id "amuHpMDCZkc4BvDXnoC5IAAAABQ"]
[Thu Jul 30 12:19:32.586894 2026] [security2:error] [pid 727775:tid 727925] [client 158.158.105.63:52258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/fffm.php"] [unique_id "amuHpMDCZkc4BvDXnoC5IAAAABQ"]
[Thu Jul 30 12:19:32.884919 2026] [security2:error] [pid 727775:tid 727952] [client 158.158.105.63:19603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/sixxis.php"] [unique_id "amuHpMDCZkc4BvDXnoC5JwAAAC8"]
[Thu Jul 30 12:19:32.885052 2026] [security2:error] [pid 727775:tid 727952] [client 158.158.105.63:19603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/sixxis.php"] [unique_id "amuHpMDCZkc4BvDXnoC5JwAAAC8"]
[Thu Jul 30 12:19:32.924107 2026] [core:error] [pid 727775:tid 727905] [client 74.7.175.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:32.924137 2026] [core:error] [pid 727775:tid 727905] [client 74.7.175.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:32.924301 2026] [security2:error] [pid 727775:tid 727905] [client 74.7.175.188:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.kax.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuHpMDCZkc4BvDXnoC5KgAAAAA"]
[Thu Jul 30 12:19:32.924859 2026] [security2:error] [pid 727775:tid 728015] [client 74.7.175.188:41304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.kax.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuHpMDCZkc4BvDXnoC5KAAAbks"]
[Thu Jul 30 12:19:33.151084 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.105.63:19628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/yj09.php"] [unique_id "amuHpcDCZkc4BvDXnoC5KwAAACM"]
[Thu Jul 30 12:19:33.151231 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.105.63:19628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/yj09.php"] [unique_id "amuHpcDCZkc4BvDXnoC5KwAAACM"]
[Thu Jul 30 12:19:33.425503 2026] [security2:error] [pid 727775:tid 727913] [client 158.158.105.63:18442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/k.php"] [unique_id "amuHpcDCZkc4BvDXnoC5NAAAAAg"]
[Thu Jul 30 12:19:33.425611 2026] [security2:error] [pid 727775:tid 727913] [client 158.158.105.63:18442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/k.php"] [unique_id "amuHpcDCZkc4BvDXnoC5NAAAAAg"]
[Thu Jul 30 12:19:33.452661 2026] [security2:error] [pid 727775:tid 727946] [client 172.213.232.128:12437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuHpcDCZkc4BvDXnoC5NQAAACk"]
[Thu Jul 30 12:19:33.777025 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.105.63:52243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/k2.php"] [unique_id "amuHpcDCZkc4BvDXnoC5PwAAAAE"]
[Thu Jul 30 12:19:33.777142 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.105.63:52243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/k2.php"] [unique_id "amuHpcDCZkc4BvDXnoC5PwAAAAE"]
[Thu Jul 30 12:19:33.842289 2026] [security2:error] [pid 727775:tid 727944] [client 20.151.221.234:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuHpcDCZkc4BvDXnoC5QAAAACc"]
[Thu Jul 30 12:19:34.005485 2026] [security2:error] [pid 727775:tid 727927] [client 20.63.98.115:32384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "amuHpsDCZkc4BvDXnoC5VAAAABY"]
[Thu Jul 30 12:19:34.043997 2026] [security2:error] [pid 727775:tid 727971] [client 158.158.105.63:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/w.php"] [unique_id "amuHpsDCZkc4BvDXnoC5VQAAAEI"]
[Thu Jul 30 12:19:34.044098 2026] [security2:error] [pid 727775:tid 727971] [client 158.158.105.63:52257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/w.php"] [unique_id "amuHpsDCZkc4BvDXnoC5VQAAAEI"]
[Thu Jul 30 12:19:34.304867 2026] [security2:error] [pid 727775:tid 727966] [client 158.158.105.63:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/fpwch.php"] [unique_id "amuHpsDCZkc4BvDXnoC5XQAAAD0"]
[Thu Jul 30 12:19:34.304959 2026] [security2:error] [pid 727775:tid 727966] [client 158.158.105.63:52234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/fpwch.php"] [unique_id "amuHpsDCZkc4BvDXnoC5XQAAAD0"]
[Thu Jul 30 12:19:34.665833 2026] [security2:error] [pid 727775:tid 728026] [client 158.158.105.63:19589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/w2025.php"] [unique_id "amuHpsDCZkc4BvDXnoC5fQAAAHk"]
[Thu Jul 30 12:19:34.665944 2026] [security2:error] [pid 727775:tid 728026] [client 158.158.105.63:19589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/w2025.php"] [unique_id "amuHpsDCZkc4BvDXnoC5fQAAAHk"]
[Thu Jul 30 12:19:34.680895 2026] [core:notice] [pid 727775:tid 727920] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:34.776414 2026] [security2:error] [pid 727775:tid 727779] [remote 103.164.173.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.173.164.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/wp-login.php"] [unique_id "amuHpsDCZkc4BvDXnoC5fwAAcQM"]
[Thu Jul 30 12:19:34.985817 2026] [security2:error] [pid 727775:tid 728021] [client 158.158.105.63:52263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/FWAZ.php"] [unique_id "amuHpsDCZkc4BvDXnoC5hAAAAHQ"]
[Thu Jul 30 12:19:34.985932 2026] [security2:error] [pid 727775:tid 728021] [client 158.158.105.63:52263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/FWAZ.php"] [unique_id "amuHpsDCZkc4BvDXnoC5hAAAAHQ"]
[Thu Jul 30 12:19:35.034233 2026] [security2:error] [pid 727775:tid 727964] [client 20.63.98.115:62332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/files.php"] [unique_id "amuHp8DCZkc4BvDXnoC5iAAAADs"]
[Thu Jul 30 12:19:35.247538 2026] [security2:error] [pid 727775:tid 727919] [client 158.158.105.63:19596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/qterm.php"] [unique_id "amuHp8DCZkc4BvDXnoC5jwAAAA4"]
[Thu Jul 30 12:19:35.247642 2026] [security2:error] [pid 727775:tid 727919] [client 158.158.105.63:19596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/qterm.php"] [unique_id "amuHp8DCZkc4BvDXnoC5jwAAAA4"]
[Thu Jul 30 12:19:35.308028 2026] [security2:error] [pid 727775:tid 727986] [client 20.151.221.234:41660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/inputs.php"] [unique_id "amuHp8DCZkc4BvDXnoC5kAAAAFE"]
[Thu Jul 30 12:19:35.574057 2026] [security2:error] [pid 727775:tid 727983] [client 158.158.105.63:52274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/blurbs.php"] [unique_id "amuHp8DCZkc4BvDXnoC5mAAAAE4"]
[Thu Jul 30 12:19:35.574148 2026] [security2:error] [pid 727775:tid 727983] [client 158.158.105.63:52274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/blurbs.php"] [unique_id "amuHp8DCZkc4BvDXnoC5mAAAAE4"]
[Thu Jul 30 12:19:35.878507 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.105.63:19614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-ws68.php"] [unique_id "amuHp8DCZkc4BvDXnoC5nAAAACE"]
[Thu Jul 30 12:19:35.878595 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.105.63:19614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-ws68.php"] [unique_id "amuHp8DCZkc4BvDXnoC5nAAAACE"]
[Thu Jul 30 12:19:36.144809 2026] [security2:error] [pid 727775:tid 727951] [client 158.158.105.63:19637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/xyn.php"] [unique_id "amuHqMDCZkc4BvDXnoC5oAAAAC4"]
[Thu Jul 30 12:19:36.144909 2026] [security2:error] [pid 727775:tid 727951] [client 158.158.105.63:19637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/xyn.php"] [unique_id "amuHqMDCZkc4BvDXnoC5oAAAAC4"]
[Thu Jul 30 12:19:36.323531 2026] [security2:error] [pid 727775:tid 727992] [client 20.151.221.234:44748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/index.php"] [unique_id "amuHqMDCZkc4BvDXnoC5pAAAAFc"]
[Thu Jul 30 12:19:36.419388 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:52248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ccc.php"] [unique_id "amuHqMDCZkc4BvDXnoC5qQAAABs"]
[Thu Jul 30 12:19:36.419497 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:52248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ccc.php"] [unique_id "amuHqMDCZkc4BvDXnoC5qQAAABs"]
[Thu Jul 30 12:19:36.616781 2026] [security2:error] [pid 727775:tid 727939] [client 172.213.232.128:8815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuHqMDCZkc4BvDXnoC5rQAAACI"]
[Thu Jul 30 12:19:36.757092 2026] [security2:error] [pid 727775:tid 727979] [client 158.158.105.63:19597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/get.php"] [unique_id "amuHqMDCZkc4BvDXnoC5rgAAAEo"]
[Thu Jul 30 12:19:36.757243 2026] [security2:error] [pid 727775:tid 727979] [client 158.158.105.63:19597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/get.php"] [unique_id "amuHqMDCZkc4BvDXnoC5rgAAAEo"]
[Thu Jul 30 12:19:36.909970 2026] [security2:error] [pid 727775:tid 727994] [client 20.63.98.115:54752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Text/index.php"] [unique_id "amuHqMDCZkc4BvDXnoC5sgAAAFk"]
[Thu Jul 30 12:19:37.019333 2026] [security2:error] [pid 727775:tid 727956] [client 158.158.105.63:19626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/images.php"] [unique_id "amuHqcDCZkc4BvDXnoC5uAAAADM"]
[Thu Jul 30 12:19:37.019422 2026] [security2:error] [pid 727775:tid 727956] [client 158.158.105.63:19626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/images.php"] [unique_id "amuHqcDCZkc4BvDXnoC5uAAAADM"]
[Thu Jul 30 12:19:37.255645 2026] [security2:error] [pid 727775:tid 728000] [client 20.151.221.234:41753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuHqcDCZkc4BvDXnoC5vQAAAF8"]
[Thu Jul 30 12:19:37.284228 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:19584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/alls.php"] [unique_id "amuHqcDCZkc4BvDXnoC5vgAAADQ"]
[Thu Jul 30 12:19:37.284363 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:19584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/alls.php"] [unique_id "amuHqcDCZkc4BvDXnoC5vgAAADQ"]
[Thu Jul 30 12:19:37.422497 2026] [security2:error] [pid 727775:tid 727997] [client 172.213.232.128:23109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/about.php"] [unique_id "amuHqcDCZkc4BvDXnoC5wgAAAFw"]
[Thu Jul 30 12:19:37.543811 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/coffexium.php"] [unique_id "amuHqcDCZkc4BvDXnoC5wwAAAFA"]
[Thu Jul 30 12:19:37.543917 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/coffexium.php"] [unique_id "amuHqcDCZkc4BvDXnoC5wwAAAFA"]
[Thu Jul 30 12:19:37.802549 2026] [security2:error] [pid 727775:tid 727971] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHqcDCZkc4BvDXnoC5vAAAQhk"]
[Thu Jul 30 12:19:37.864132 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:18434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/red.php"] [unique_id "amuHqcDCZkc4BvDXnoC5ygAAADk"]
[Thu Jul 30 12:19:37.864235 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:18434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/red.php"] [unique_id "amuHqcDCZkc4BvDXnoC5ygAAADk"]
[Thu Jul 30 12:19:38.021543 2026] [security2:error] [pid 727775:tid 728015] [client 20.63.98.115:54741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuHqsDCZkc4BvDXnoC51gAAAG4"]
[Thu Jul 30 12:19:38.062723 2026] [security2:error] [pid 727775:tid 728028] [client 172.213.232.128:18590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/about.php"] [unique_id "amuHqsDCZkc4BvDXnoC51wAAAHs"]
[Thu Jul 30 12:19:38.139713 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.105.63:52238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuHqsDCZkc4BvDXnoC52AAAAAA"]
[Thu Jul 30 12:19:38.222354 2026] [core:error] [pid 727775:tid 728016] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:38.222397 2026] [core:error] [pid 727775:tid 728016] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:38.269628 2026] [security2:error] [pid 727775:tid 727937] [client 158.158.105.63:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuHqsDCZkc4BvDXnoC53QAAACA"]
[Thu Jul 30 12:19:38.269719 2026] [security2:error] [pid 727775:tid 727937] [client 158.158.105.63:52238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuHqsDCZkc4BvDXnoC53QAAACA"]
[Thu Jul 30 12:19:38.544251 2026] [security2:error] [pid 727775:tid 728006] [client 158.158.105.63:19625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/"] [unique_id "amuHqsDCZkc4BvDXnoC54gAAAGU"]
[Thu Jul 30 12:19:38.684113 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuHqsDCZkc4BvDXnoC55QAAAFU"]
[Thu Jul 30 12:19:38.705941 2026] [security2:error] [pid 727775:tid 727945] [client 20.151.221.234:41638] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/1.php"] [unique_id "amuHqsDCZkc4BvDXnoC55gAAACg"]
[Thu Jul 30 12:19:38.706070 2026] [security2:error] [pid 727775:tid 727945] [client 20.151.221.234:41638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/1.php"] [unique_id "amuHqsDCZkc4BvDXnoC55gAAACg"]
[Thu Jul 30 12:19:38.812834 2026] [security2:error] [pid 727775:tid 727970] [client 158.158.105.63:19625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/index.php"] [unique_id "amuHqsDCZkc4BvDXnoC57QAAAEE"]
[Thu Jul 30 12:19:38.812921 2026] [security2:error] [pid 727775:tid 727970] [client 158.158.105.63:19625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/index.php"] [unique_id "amuHqsDCZkc4BvDXnoC57QAAAEE"]
[Thu Jul 30 12:19:39.080122 2026] [security2:error] [pid 727775:tid 727933] [client 158.158.105.63:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHq8DCZkc4BvDXnoC59AAAABw"]
[Thu Jul 30 12:19:39.080246 2026] [security2:error] [pid 727775:tid 727933] [client 158.158.105.63:52275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHq8DCZkc4BvDXnoC59AAAABw"]
[Thu Jul 30 12:19:39.341030 2026] [security2:error] [pid 727775:tid 727907] [client 158.158.105.63:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/177.php"] [unique_id "amuHq8DCZkc4BvDXnoC5-gAAAAI"]
[Thu Jul 30 12:19:39.341138 2026] [security2:error] [pid 727775:tid 727907] [client 158.158.105.63:52239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/177.php"] [unique_id "amuHq8DCZkc4BvDXnoC5-gAAAAI"]
[Thu Jul 30 12:19:39.566831 2026] [security2:error] [pid 727775:tid 727820] [remote 74.7.242.7:33248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuHq8DCZkc4BvDXnoC5_wAAAyw"], referer: https://www.thdinfinity.com/
[Thu Jul 30 12:19:39.600086 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:52281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/199.php"] [unique_id "amuHq8DCZkc4BvDXnoC6AAAAADQ"]
[Thu Jul 30 12:19:39.600193 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:52281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/199.php"] [unique_id "amuHq8DCZkc4BvDXnoC6AAAAADQ"]
[Thu Jul 30 12:19:39.862521 2026] [core:error] [pid 727775:tid 727929] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:39.862542 2026] [core:error] [pid 727775:tid 727929] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:19:39.930151 2026] [security2:error] [pid 727775:tid 727988] [client 158.158.105.63:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file52.php"] [unique_id "amuHq8DCZkc4BvDXnoC6CwAAAFM"]
[Thu Jul 30 12:19:39.930278 2026] [security2:error] [pid 727775:tid 727988] [client 158.158.105.63:52228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file52.php"] [unique_id "amuHq8DCZkc4BvDXnoC6CwAAAFM"]
[Thu Jul 30 12:19:40.281609 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:18476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/geck.php"] [unique_id "amuHrMDCZkc4BvDXnoC6EQAAAGY"]
[Thu Jul 30 12:19:40.281717 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:18476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/geck.php"] [unique_id "amuHrMDCZkc4BvDXnoC6EQAAAGY"]
[Thu Jul 30 12:19:40.540575 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.105.63:19629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/biufile.php"] [unique_id "amuHrMDCZkc4BvDXnoC6FQAAACM"]
[Thu Jul 30 12:19:40.540694 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.105.63:19629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/biufile.php"] [unique_id "amuHrMDCZkc4BvDXnoC6FQAAACM"]
[Thu Jul 30 12:19:40.783090 2026] [security2:error] [pid 727775:tid 728009] [client 172.213.232.128:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuHrMDCZkc4BvDXnoC6HgAAAGg"]
[Thu Jul 30 12:19:40.835025 2026] [security2:error] [pid 727775:tid 727951] [client 158.158.105.63:19627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dejavu.php"] [unique_id "amuHrMDCZkc4BvDXnoC6HwAAAC4"]
[Thu Jul 30 12:19:40.835125 2026] [security2:error] [pid 727775:tid 727951] [client 158.158.105.63:19627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dejavu.php"] [unique_id "amuHrMDCZkc4BvDXnoC6HwAAAC4"]
[Thu Jul 30 12:19:41.179918 2026] [security2:error] [pid 727775:tid 728003] [client 158.158.105.63:18457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/aaf.php"] [unique_id "amuHrcDCZkc4BvDXnoC6KAAAAGI"]
[Thu Jul 30 12:19:41.180042 2026] [security2:error] [pid 727775:tid 728003] [client 158.158.105.63:18457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/aaf.php"] [unique_id "amuHrcDCZkc4BvDXnoC6KAAAAGI"]
[Thu Jul 30 12:19:41.288863 2026] [security2:error] [pid 727775:tid 727942] [client 20.63.98.115:38151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuHrcDCZkc4BvDXnoC6KQAAACU"]
[Thu Jul 30 12:19:41.382218 2026] [security2:error] [pid 727775:tid 728014] [client 20.151.221.234:41632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/plugin.php"] [unique_id "amuHrcDCZkc4BvDXnoC6KwAAAG0"]
[Thu Jul 30 12:19:41.503034 2026] [security2:error] [pid 727775:tid 727923] [client 158.158.105.63:52287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ha.php"] [unique_id "amuHrcDCZkc4BvDXnoC6LwAAABI"]
[Thu Jul 30 12:19:41.503134 2026] [security2:error] [pid 727775:tid 727923] [client 158.158.105.63:52287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ha.php"] [unique_id "amuHrcDCZkc4BvDXnoC6LwAAABI"]
[Thu Jul 30 12:19:41.783507 2026] [security2:error] [pid 727775:tid 727953] [client 158.158.105.63:18473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/hur.php"] [unique_id "amuHrcDCZkc4BvDXnoC6OwAAADA"]
[Thu Jul 30 12:19:41.783612 2026] [security2:error] [pid 727775:tid 727953] [client 158.158.105.63:18473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/hur.php"] [unique_id "amuHrcDCZkc4BvDXnoC6OwAAADA"]
[Thu Jul 30 12:19:42.176194 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/h02ugyh.php"] [unique_id "amuHrsDCZkc4BvDXnoC6RwAAADs"]
[Thu Jul 30 12:19:42.176293 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/h02ugyh.php"] [unique_id "amuHrsDCZkc4BvDXnoC6RwAAADs"]
[Thu Jul 30 12:19:42.203522 2026] [security2:error] [pid 727775:tid 727908] [client 20.151.221.234:44751] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "arabiandubaisafari.com"] [uri "/1.php"] [unique_id "amuHrsDCZkc4BvDXnoC6SQAAAAM"]
[Thu Jul 30 12:19:42.203654 2026] [security2:error] [pid 727775:tid 727908] [client 20.151.221.234:44751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/1.php"] [unique_id "amuHrsDCZkc4BvDXnoC6SQAAAAM"]
[Thu Jul 30 12:19:42.436672 2026] [security2:error] [pid 727775:tid 727930] [client 158.158.105.63:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/155.php"] [unique_id "amuHrsDCZkc4BvDXnoC6TQAAABk"]
[Thu Jul 30 12:19:42.436773 2026] [security2:error] [pid 727775:tid 727930] [client 158.158.105.63:52269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/155.php"] [unique_id "amuHrsDCZkc4BvDXnoC6TQAAABk"]
[Thu Jul 30 12:19:42.696403 2026] [security2:error] [pid 727775:tid 728015] [client 158.158.105.63:19639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ops.php"] [unique_id "amuHrsDCZkc4BvDXnoC6UgAAAG4"]
[Thu Jul 30 12:19:42.696515 2026] [security2:error] [pid 727775:tid 728015] [client 158.158.105.63:19639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ops.php"] [unique_id "amuHrsDCZkc4BvDXnoC6UgAAAG4"]
[Thu Jul 30 12:19:42.781165 2026] [security2:error] [pid 727775:tid 727912] [client 172.213.232.128:1596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHrsDCZkc4BvDXnoC6VAAAAAc"]
[Thu Jul 30 12:19:43.071915 2026] [security2:error] [pid 727775:tid 727989] [client 158.158.105.63:19634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ingfo.php"] [unique_id "amuHr8DCZkc4BvDXnoC6WAAAAFQ"]
[Thu Jul 30 12:19:43.072039 2026] [security2:error] [pid 727775:tid 727989] [client 158.158.105.63:19634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ingfo.php"] [unique_id "amuHr8DCZkc4BvDXnoC6WAAAAFQ"]
[Thu Jul 30 12:19:43.372943 2026] [security2:error] [pid 727775:tid 727913] [client 158.158.105.63:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/error_log.php"] [unique_id "amuHr8DCZkc4BvDXnoC6YwAAAAg"]
[Thu Jul 30 12:19:43.373066 2026] [security2:error] [pid 727775:tid 727913] [client 158.158.105.63:52256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/error_log.php"] [unique_id "amuHr8DCZkc4BvDXnoC6YwAAAAg"]
[Thu Jul 30 12:19:43.582270 2026] [ssl:error] [pid 727775:tid 728010] [client 66.132.195.52:45374] AH02032: Hostname sh00085.hostgator.com (default host as no SNI was provided) and hostname mail.megasuppliesdistrict.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Thu Jul 30 12:19:43.645094 2026] [security2:error] [pid 727775:tid 727977] [client 158.158.105.63:19622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/koala.php"] [unique_id "amuHr8DCZkc4BvDXnoC6aAAAAEg"]
[Thu Jul 30 12:19:43.645198 2026] [security2:error] [pid 727775:tid 727977] [client 158.158.105.63:19622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/koala.php"] [unique_id "amuHr8DCZkc4BvDXnoC6aAAAAEg"]
[Thu Jul 30 12:19:43.702376 2026] [security2:error] [pid 727775:tid 727951] [client 20.63.98.115:20885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ws.php"] [unique_id "amuHr8DCZkc4BvDXnoC6aQAAAC4"]
[Thu Jul 30 12:19:43.792102 2026] [security2:error] [pid 727775:tid 727986] [client 172.213.232.128:12430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/img/about.php"] [unique_id "amuHr8DCZkc4BvDXnoC6cQAAAFE"]
[Thu Jul 30 12:19:44.051534 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/mac.php"] [unique_id "amuHsMDCZkc4BvDXnoC6dwAAAGM"]
[Thu Jul 30 12:19:44.051651 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:52232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/mac.php"] [unique_id "amuHsMDCZkc4BvDXnoC6dwAAAGM"]
[Thu Jul 30 12:19:44.310797 2026] [security2:error] [pid 727775:tid 727918] [client 158.158.105.63:19607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wefile.php"] [unique_id "amuHsMDCZkc4BvDXnoC6fgAAAA0"]
[Thu Jul 30 12:19:44.310961 2026] [security2:error] [pid 727775:tid 727918] [client 158.158.105.63:19607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wefile.php"] [unique_id "amuHsMDCZkc4BvDXnoC6fgAAAA0"]
[Thu Jul 30 12:19:44.590889 2026] [security2:error] [pid 727775:tid 728006] [client 74.7.230.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pkv.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuHr8DCZkc4BvDXnoC6WwAAAGU"]
[Thu Jul 30 12:19:44.592034 2026] [security2:error] [pid 727775:tid 728022] [client 74.7.230.33:36206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pkv.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amuHr8DCZkc4BvDXnoC6WQAAdUY"]
[Thu Jul 30 12:19:44.596734 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.105.63:18458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/post-comments-form/"] [unique_id "amuHsMDCZkc4BvDXnoC6hAAAAGc"]
[Thu Jul 30 12:19:44.719478 2026] [security2:error] [pid 727775:tid 727998] [client 20.63.98.115:38179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-config-sample.php"] [unique_id "amuHsMDCZkc4BvDXnoC6hQAAAF0"]
[Thu Jul 30 12:19:44.739349 2026] [security2:error] [pid 727775:tid 727988] [client 158.158.105.63:18458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/"] [unique_id "amuHsMDCZkc4BvDXnoC6hgAAAFM"]
[Thu Jul 30 12:19:44.868663 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:18458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/makeasmtp.php"] [unique_id "amuHsMDCZkc4BvDXnoC6igAAADk"]
[Thu Jul 30 12:19:44.868778 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:18458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/makeasmtp.php"] [unique_id "amuHsMDCZkc4BvDXnoC6igAAADk"]
[Thu Jul 30 12:19:45.142602 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:18446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/2P.php"] [unique_id "amuHscDCZkc4BvDXnoC6kQAAAGY"]
[Thu Jul 30 12:19:45.142697 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:18446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/2P.php"] [unique_id "amuHscDCZkc4BvDXnoC6kQAAAGY"]
[Thu Jul 30 12:19:45.357231 2026] [security2:error] [pid 727775:tid 727937] [client 195.113.175.167:12606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/misionf.php"] [unique_id "amuHscDCZkc4BvDXnoC6lAAAACA"]
[Thu Jul 30 12:19:45.409948 2026] [security2:error] [pid 727775:tid 727921] [client 158.158.105.63:19606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/.well-known/about.php"] [unique_id "amuHscDCZkc4BvDXnoC6lwAAABA"]
[Thu Jul 30 12:19:45.410059 2026] [security2:error] [pid 727775:tid 727921] [client 158.158.105.63:19606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/.well-known/about.php"] [unique_id "amuHscDCZkc4BvDXnoC6lwAAABA"]
[Thu Jul 30 12:19:45.435719 2026] [security2:error] [pid 727775:tid 727972] [client 20.151.221.234:41731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/gg.php"] [unique_id "amuHscDCZkc4BvDXnoC6mwAAAEM"]
[Thu Jul 30 12:19:45.734340 2026] [security2:error] [pid 727775:tid 728019] [client 74.7.241.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "evermed-med-sa.com"] [uri "/cgi-sys/404.html"] [unique_id "amuHscDCZkc4BvDXnoC6owAAclY"]
[Thu Jul 30 12:19:45.798025 2026] [security2:error] [pid 727775:tid 727942] [client 158.158.105.63:18453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHscDCZkc4BvDXnoC6pAAAACU"]
[Thu Jul 30 12:19:45.798129 2026] [security2:error] [pid 727775:tid 727942] [client 158.158.105.63:18453] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuHscDCZkc4BvDXnoC6pAAAACU"]
[Thu Jul 30 12:19:46.085523 2026] [security2:error] [pid 727775:tid 727986] [client 158.158.105.63:18485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/system_log.php"] [unique_id "amuHssDCZkc4BvDXnoC6rQAAAFE"]
[Thu Jul 30 12:19:46.085683 2026] [security2:error] [pid 727775:tid 727986] [client 158.158.105.63:18485] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/system_log.php"] [unique_id "amuHssDCZkc4BvDXnoC6rQAAAFE"]
[Thu Jul 30 12:19:46.342426 2026] [security2:error] [pid 727775:tid 727944] [client 74.7.228.16:54050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bss.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHr8DCZkc4BvDXnoC6bwAAJ04"]
[Thu Jul 30 12:19:46.342463 2026] [security2:error] [pid 727775:tid 727944] [client 74.7.228.16:54050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bss.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHr8DCZkc4BvDXnoC6bwAAJ04"]
[Thu Jul 30 12:19:46.355023 2026] [security2:error] [pid 727775:tid 728026] [client 74.7.230.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-3a7cf4bc.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHsMDCZkc4BvDXnoC6fQAAAHk"]
[Thu Jul 30 12:19:46.356090 2026] [security2:error] [pid 727775:tid 728001] [client 74.7.230.30:46260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-3a7cf4bc.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuHsMDCZkc4BvDXnoC6ewAAYFU"]
[Thu Jul 30 12:19:46.454604 2026] [security2:error] [pid 727775:tid 728006] [client 20.151.221.234:41735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp.php"] [unique_id "amuHssDCZkc4BvDXnoC6ugAAAGU"]
[Thu Jul 30 12:19:46.529887 2026] [security2:error] [pid 727775:tid 727936] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHssDCZkc4BvDXnoC6swAAAB8"]
[Thu Jul 30 12:19:46.550051 2026] [security2:error] [pid 727775:tid 727926] [client 157.90.155.240:3748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuHssDCZkc4BvDXnoC6vQAAABU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:19:46.613353 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.105.63:52279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/"] [unique_id "amuHssDCZkc4BvDXnoC6vgAAAFo"]
[Thu Jul 30 12:19:46.830304 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:52279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amuHssDCZkc4BvDXnoC6xgAAAAs"]
[Thu Jul 30 12:19:46.960107 2026] [security2:error] [pid 727775:tid 727968] [client 158.158.105.63:52279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/crgio.php"] [unique_id "amuHssDCZkc4BvDXnoC6ygAAAD8"]
[Thu Jul 30 12:19:46.960222 2026] [security2:error] [pid 727775:tid 727968] [client 158.158.105.63:52279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/crgio.php"] [unique_id "amuHssDCZkc4BvDXnoC6ygAAAD8"]
[Thu Jul 30 12:19:47.029681 2026] [security2:error] [pid 727775:tid 728008] [client 20.63.98.115:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wso.php"] [unique_id "amuHs8DCZkc4BvDXnoC60QAAAGc"]
[Thu Jul 30 12:19:47.094501 2026] [security2:error] [pid 727775:tid 727910] [client 74.7.228.16:34452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bss.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuHssDCZkc4BvDXnoC6zAAABXg"], referer: https://www.bss.nyx.temporary.site/robots.txt
[Thu Jul 30 12:19:47.113747 2026] [core:notice] [pid 727775:tid 727993] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:47.121796 2026] [security2:error] [pid 727775:tid 727993] [client 157.90.155.240:3758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuHs8DCZkc4BvDXnoC60gAAAFg"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:19:47.320308 2026] [security2:error] [pid 727775:tid 727960] [client 158.158.105.63:19638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/pucci.php"] [unique_id "amuHs8DCZkc4BvDXnoC64AAAADc"]
[Thu Jul 30 12:19:47.320432 2026] [security2:error] [pid 727775:tid 727960] [client 158.158.105.63:19638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/pucci.php"] [unique_id "amuHs8DCZkc4BvDXnoC64AAAADc"]
[Thu Jul 30 12:19:47.443865 2026] [security2:error] [pid 727775:tid 727907] [client 20.151.221.234:44739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuHs8DCZkc4BvDXnoC65AAAAAI"]
[Thu Jul 30 12:19:47.604579 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/details/"] [unique_id "amuHs8DCZkc4BvDXnoC66wAAAEk"]
[Thu Jul 30 12:19:47.610322 2026] [security2:error] [pid 727775:tid 728028] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHssDCZkc4BvDXnoC6zQAAe3w"]
[Thu Jul 30 12:19:47.684012 2026] [security2:error] [pid 727775:tid 728010] [client 157.90.155.240:24706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuHs8DCZkc4BvDXnoC67wAAAGk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:19:47.746179 2026] [security2:error] [pid 727775:tid 727943] [client 158.158.105.63:56069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/audio/"] [unique_id "amuHs8DCZkc4BvDXnoC68AAAACY"]
[Thu Jul 30 12:19:47.874828 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:56069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-temp.php"] [unique_id "amuHs8DCZkc4BvDXnoC69QAAADQ"]
[Thu Jul 30 12:19:47.874956 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.105.63:56069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-temp.php"] [unique_id "amuHs8DCZkc4BvDXnoC69QAAADQ"]
[Thu Jul 30 12:19:48.089059 2026] [security2:error] [pid 727775:tid 727999] [client 172.213.232.128:18596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuHtMDCZkc4BvDXnoC6_gAAAF4"]
[Thu Jul 30 12:19:48.146938 2026] [security2:error] [pid 727775:tid 727911] [client 158.158.105.63:18465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuHtMDCZkc4BvDXnoC7AAAAAAY"]
[Thu Jul 30 12:19:48.147063 2026] [security2:error] [pid 727775:tid 727911] [client 158.158.105.63:18465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuHtMDCZkc4BvDXnoC7AAAAAAY"]
[Thu Jul 30 12:19:48.172089 2026] [core:notice] [pid 727775:tid 727935] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:48.468275 2026] [security2:error] [pid 727775:tid 727959] [client 20.151.221.234:44127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/file.php"] [unique_id "amuHtMDCZkc4BvDXnoC7DQAAADY"]
[Thu Jul 30 12:19:48.604708 2026] [core:notice] [pid 727775:tid 728027] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:48.699341 2026] [security2:error] [pid 727775:tid 727983] [client 158.158.105.63:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/puc.php"] [unique_id "amuHtMDCZkc4BvDXnoC7GwAAAE4"]
[Thu Jul 30 12:19:48.699468 2026] [security2:error] [pid 727775:tid 727983] [client 158.158.105.63:52278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/puc.php"] [unique_id "amuHtMDCZkc4BvDXnoC7GwAAAE4"]
[Thu Jul 30 12:19:48.707529 2026] [security2:error] [pid 727775:tid 727931] [client 20.63.98.115:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/sh.php"] [unique_id "amuHtMDCZkc4BvDXnoC7HAAAABo"]
[Thu Jul 30 12:19:48.993871 2026] [security2:error] [pid 727775:tid 727938] [client 172.213.232.128:23105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuHtMDCZkc4BvDXnoC7JAAAACE"]
[Thu Jul 30 12:19:49.056866 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dx.php"] [unique_id "amuHtcDCZkc4BvDXnoC7KgAAAEk"]
[Thu Jul 30 12:19:49.056965 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dx.php"] [unique_id "amuHtcDCZkc4BvDXnoC7KgAAAEk"]
[Thu Jul 30 12:19:49.400214 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:18464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amuHtcDCZkc4BvDXnoC7MQAAABs"]
[Thu Jul 30 12:19:49.540747 2026] [security2:error] [pid 727775:tid 727987] [client 158.158.105.63:18464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/7.php"] [unique_id "amuHtcDCZkc4BvDXnoC7NgAAAFI"]
[Thu Jul 30 12:19:49.540846 2026] [security2:error] [pid 727775:tid 727987] [client 158.158.105.63:18464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/7.php"] [unique_id "amuHtcDCZkc4BvDXnoC7NgAAAFI"]
[Thu Jul 30 12:19:49.720173 2026] [security2:error] [pid 727775:tid 727944] [client 172.213.232.128:16222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuHtcDCZkc4BvDXnoC7OAAAACc"]
[Thu Jul 30 12:19:49.759073 2026] [core:notice] [pid 727775:tid 727946] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:49.853974 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/8.php"] [unique_id "amuHtcDCZkc4BvDXnoC7OwAAAFA"]
[Thu Jul 30 12:19:49.854096 2026] [security2:error] [pid 727775:tid 727985] [client 158.158.105.63:52285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/8.php"] [unique_id "amuHtcDCZkc4BvDXnoC7OwAAAFA"]
[Thu Jul 30 12:19:50.063360 2026] [security2:error] [pid 727775:tid 727950] [client 20.63.98.115:51807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/send.php"] [unique_id "amuHtsDCZkc4BvDXnoC7QgAAAC0"]
[Thu Jul 30 12:19:50.083383 2026] [security2:error] [pid 727775:tid 727934] [client 20.151.221.234:41661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuHtsDCZkc4BvDXnoC7QwAAAB0"]
[Thu Jul 30 12:19:50.158392 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52237] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/1.php"] [unique_id "amuHtsDCZkc4BvDXnoC7RAAAADs"]
[Thu Jul 30 12:19:50.158512 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/1.php"] [unique_id "amuHtsDCZkc4BvDXnoC7RAAAADs"]
[Thu Jul 30 12:19:50.158605 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:52237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/1.php"] [unique_id "amuHtsDCZkc4BvDXnoC7RAAAADs"]
[Thu Jul 30 12:19:50.490414 2026] [security2:error] [pid 727775:tid 727912] [client 158.158.105.63:19605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/about.php"] [unique_id "amuHtsDCZkc4BvDXnoC7UwAAAAc"]
[Thu Jul 30 12:19:50.490505 2026] [security2:error] [pid 727775:tid 727912] [client 158.158.105.63:19605] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/about.php"] [unique_id "amuHtsDCZkc4BvDXnoC7UwAAAAc"]
[Thu Jul 30 12:19:50.874175 2026] [security2:error] [pid 727775:tid 727945] [client 158.158.105.63:19586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHtsDCZkc4BvDXnoC7WgAAACg"]
[Thu Jul 30 12:19:50.874285 2026] [security2:error] [pid 727775:tid 727945] [client 158.158.105.63:19586] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHtsDCZkc4BvDXnoC7WgAAACg"]
[Thu Jul 30 12:19:51.338968 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/edit.php"] [unique_id "amuHt8DCZkc4BvDXnoC7YgAAAEk"]
[Thu Jul 30 12:19:51.339128 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.105.63:56096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/edit.php"] [unique_id "amuHt8DCZkc4BvDXnoC7YgAAAEk"]
[Thu Jul 30 12:19:51.616212 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:19619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/admin.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bQAAAAs"]
[Thu Jul 30 12:19:51.616329 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:19619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/admin.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bQAAAAs"]
[Thu Jul 30 12:19:51.697846 2026] [security2:error] [pid 727775:tid 727991] [client 172.213.232.128:6708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bgAAAFY"]
[Thu Jul 30 12:19:51.878347 2026] [security2:error] [pid 727775:tid 727961] [client 158.158.105.63:19598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/inputs.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bwAAADg"]
[Thu Jul 30 12:19:51.878449 2026] [security2:error] [pid 727775:tid 727961] [client 158.158.105.63:19598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/inputs.php"] [unique_id "amuHt8DCZkc4BvDXnoC7bwAAADg"]
[Thu Jul 30 12:19:52.165688 2026] [security2:error] [pid 727775:tid 727934] [client 158.158.105.63:19599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/av.php"] [unique_id "amuHuMDCZkc4BvDXnoC7egAAAB0"]
[Thu Jul 30 12:19:52.165789 2026] [security2:error] [pid 727775:tid 727934] [client 158.158.105.63:19599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/av.php"] [unique_id "amuHuMDCZkc4BvDXnoC7egAAAB0"]
[Thu Jul 30 12:19:52.175155 2026] [security2:error] [pid 727775:tid 728000] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHt8DCZkc4BvDXnoC7aAAAXyc"]
[Thu Jul 30 12:19:52.457612 2026] [security2:error] [pid 727775:tid 727997] [client 158.158.105.63:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/classwithtostring.php"] [unique_id "amuHuMDCZkc4BvDXnoC7fQAAAFw"]
[Thu Jul 30 12:19:52.457738 2026] [security2:error] [pid 727775:tid 727997] [client 158.158.105.63:52252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/classwithtostring.php"] [unique_id "amuHuMDCZkc4BvDXnoC7fQAAAFw"]
[Thu Jul 30 12:19:52.680266 2026] [security2:error] [pid 727775:tid 727955] [client 20.151.221.234:41785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuHuMDCZkc4BvDXnoC7hwAAADI"]
[Thu Jul 30 12:19:52.778374 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.105.63:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuHuMDCZkc4BvDXnoC7iAAAAAk"]
[Thu Jul 30 12:19:52.778507 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.105.63:52284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuHuMDCZkc4BvDXnoC7iAAAAAk"]
[Thu Jul 30 12:19:52.956290 2026] [security2:error] [pid 727775:tid 727956] [client 172.213.232.128:1772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuHuMDCZkc4BvDXnoC7iQAAADM"]
[Thu Jul 30 12:19:53.188752 2026] [security2:error] [pid 727775:tid 727942] [client 158.158.105.63:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-blog.php"] [unique_id "amuHucDCZkc4BvDXnoC7kAAAACU"]
[Thu Jul 30 12:19:53.188838 2026] [security2:error] [pid 727775:tid 727942] [client 158.158.105.63:52272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-blog.php"] [unique_id "amuHucDCZkc4BvDXnoC7kAAAACU"]
[Thu Jul 30 12:19:53.785606 2026] [security2:error] [pid 727775:tid 728028] [client 158.158.105.63:19617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/js/jquery/"] [unique_id "amuHucDCZkc4BvDXnoC7mAAAAHs"]
[Thu Jul 30 12:19:53.891159 2026] [security2:error] [pid 727775:tid 728019] [client 20.151.221.234:44743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/index/function.php"] [unique_id "amuHucDCZkc4BvDXnoC7mQAAAHI"]
[Thu Jul 30 12:19:53.915056 2026] [security2:error] [pid 727775:tid 727927] [client 158.158.105.63:19617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/admin.php"] [unique_id "amuHucDCZkc4BvDXnoC7mgAAABY"]
[Thu Jul 30 12:19:53.915224 2026] [security2:error] [pid 727775:tid 727927] [client 158.158.105.63:19617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/admin.php"] [unique_id "amuHucDCZkc4BvDXnoC7mgAAABY"]
[Thu Jul 30 12:19:54.193768 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:19594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/adminfuns.php"] [unique_id "amuHusDCZkc4BvDXnoC7owAAABs"]
[Thu Jul 30 12:19:54.193899 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:19594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/adminfuns.php"] [unique_id "amuHusDCZkc4BvDXnoC7owAAABs"]
[Thu Jul 30 12:19:54.237141 2026] [security2:error] [pid 727775:tid 728024] [client 172.213.232.128:12447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuHusDCZkc4BvDXnoC7pQAAAHc"]
[Thu Jul 30 12:19:54.499302 2026] [security2:error] [pid 727775:tid 727954] [client 158.158.105.63:19587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/goods.php"] [unique_id "amuHusDCZkc4BvDXnoC7pwAAADE"]
[Thu Jul 30 12:19:54.499417 2026] [security2:error] [pid 727775:tid 727954] [client 158.158.105.63:19587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/goods.php"] [unique_id "amuHusDCZkc4BvDXnoC7pwAAADE"]
[Thu Jul 30 12:19:54.797288 2026] [security2:error] [pid 727775:tid 728023] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHusDCZkc4BvDXnoC7oQAAAHY"]
[Thu Jul 30 12:19:54.894785 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.105.63:19602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ms-edit.php"] [unique_id "amuHusDCZkc4BvDXnoC7rgAAAF4"]
[Thu Jul 30 12:19:54.894902 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.105.63:19602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ms-edit.php"] [unique_id "amuHusDCZkc4BvDXnoC7rgAAAF4"]
[Thu Jul 30 12:19:55.168685 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.105.63:19624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/222.php"] [unique_id "amuHu8DCZkc4BvDXnoC7sgAAAF8"]
[Thu Jul 30 12:19:55.168788 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.105.63:19624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/222.php"] [unique_id "amuHu8DCZkc4BvDXnoC7sgAAAF8"]
[Thu Jul 30 12:19:55.290117 2026] [security2:error] [pid 727775:tid 727959] [client 20.63.98.115:62035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ds.php"] [unique_id "amuHu8DCZkc4BvDXnoC7tgAAADY"]
[Thu Jul 30 12:19:55.437668 2026] [security2:error] [pid 727775:tid 727995] [client 172.213.232.128:8803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuHu8DCZkc4BvDXnoC7twAAAFo"]
[Thu Jul 30 12:19:55.462684 2026] [security2:error] [pid 727775:tid 728011] [client 158.158.105.63:19635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin/index.php"] [unique_id "amuHu8DCZkc4BvDXnoC7uAAAAGo"]
[Thu Jul 30 12:19:55.462829 2026] [security2:error] [pid 727775:tid 728011] [client 158.158.105.63:19635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin/index.php"] [unique_id "amuHu8DCZkc4BvDXnoC7uAAAAGo"]
[Thu Jul 30 12:19:55.788287 2026] [security2:error] [pid 727775:tid 727909] [client 158.158.105.63:18445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/dist/"] [unique_id "amuHu8DCZkc4BvDXnoC7wQAAAAQ"]
[Thu Jul 30 12:19:55.917260 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.105.63:18445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/BDKR28WP.php"] [unique_id "amuHu8DCZkc4BvDXnoC7wgAAAAA"]
[Thu Jul 30 12:19:55.917395 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.105.63:18445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/BDKR28WP.php"] [unique_id "amuHu8DCZkc4BvDXnoC7wgAAAAA"]
[Thu Jul 30 12:19:56.236784 2026] [security2:error] [pid 727775:tid 728007] [client 158.158.105.63:19612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuHvMDCZkc4BvDXnoC7xwAAAGY"]
[Thu Jul 30 12:19:56.379974 2026] [security2:error] [pid 727775:tid 727915] [client 158.158.105.63:19612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuHvMDCZkc4BvDXnoC7ywAAAAo"]
[Thu Jul 30 12:19:56.509621 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp.php"] [unique_id "amuHvMDCZkc4BvDXnoC7zAAAAFU"]
[Thu Jul 30 12:19:56.509776 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.105.63:19612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp.php"] [unique_id "amuHvMDCZkc4BvDXnoC7zAAAAFU"]
[Thu Jul 30 12:19:56.742093 2026] [security2:error] [pid 727775:tid 727944] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHvMDCZkc4BvDXnoC7wwAAJz8"]
[Thu Jul 30 12:19:56.885282 2026] [core:notice] [pid 727775:tid 727955] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:19:57.060425 2026] [security2:error] [pid 727775:tid 728032] [client 158.158.105.63:18438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/abcd.php"] [unique_id "amuHvcDCZkc4BvDXnoC71QAAAH8"]
[Thu Jul 30 12:19:57.060545 2026] [security2:error] [pid 727775:tid 728032] [client 158.158.105.63:18438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/abcd.php"] [unique_id "amuHvcDCZkc4BvDXnoC71QAAAH8"]
[Thu Jul 30 12:19:57.379482 2026] [security2:error] [pid 727775:tid 728024] [client 158.158.105.63:19641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/a1.php"] [unique_id "amuHvcDCZkc4BvDXnoC74AAAAHc"]
[Thu Jul 30 12:19:57.379589 2026] [security2:error] [pid 727775:tid 728024] [client 158.158.105.63:19641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/a1.php"] [unique_id "amuHvcDCZkc4BvDXnoC74AAAAHc"]
[Thu Jul 30 12:19:57.389574 2026] [security2:error] [pid 727775:tid 727914] [client 20.63.98.115:47472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wso112233.php"] [unique_id "amuHvcDCZkc4BvDXnoC74QAAAAk"]
[Thu Jul 30 12:19:57.428822 2026] [security2:error] [pid 727775:tid 727916] [client 20.151.221.234:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/aaa.php"] [unique_id "amuHvcDCZkc4BvDXnoC74gAAAAs"]
[Thu Jul 30 12:19:57.796288 2026] [security2:error] [pid 727775:tid 728022] [client 158.158.105.63:18452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuHvcDCZkc4BvDXnoC75gAAAHU"]
[Thu Jul 30 12:19:57.796398 2026] [security2:error] [pid 727775:tid 728022] [client 158.158.105.63:18452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuHvcDCZkc4BvDXnoC75gAAAHU"]
[Thu Jul 30 12:19:58.488871 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.105.63:33996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin/admin.php"] [unique_id "amuHvsDCZkc4BvDXnoC79AAAAFo"]
[Thu Jul 30 12:19:58.488994 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.105.63:33996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin/admin.php"] [unique_id "amuHvsDCZkc4BvDXnoC79AAAAFo"]
[Thu Jul 30 12:19:59.020366 2026] [security2:error] [pid 727775:tid 727924] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuHvsDCZkc4BvDXnoC7_QAAABM"]
[Thu Jul 30 12:19:59.048781 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.105.63:18449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuHv8DCZkc4BvDXnoC8AQAAAA8"]
[Thu Jul 30 12:19:59.177792 2026] [security2:error] [pid 727775:tid 728017] [client 158.158.105.63:18449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/simple.php"] [unique_id "amuHv8DCZkc4BvDXnoC8AgAAAHA"]
[Thu Jul 30 12:19:59.177925 2026] [security2:error] [pid 727775:tid 728017] [client 158.158.105.63:18449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/simple.php"] [unique_id "amuHv8DCZkc4BvDXnoC8AgAAAHA"]
[Thu Jul 30 12:19:59.560456 2026] [security2:error] [pid 727775:tid 728021] [client 20.151.221.234:41605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/getid3-core.php"] [unique_id "amuHv8DCZkc4BvDXnoC8CwAAAHQ"]
[Thu Jul 30 12:19:59.562142 2026] [security2:error] [pid 727775:tid 727939] [client 158.158.105.63:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/xxx.php"] [unique_id "amuHv8DCZkc4BvDXnoC8DAAAACI"]
[Thu Jul 30 12:19:59.562221 2026] [security2:error] [pid 727775:tid 727939] [client 158.158.105.63:52286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/xxx.php"] [unique_id "amuHv8DCZkc4BvDXnoC8DAAAACI"]
[Thu Jul 30 12:19:59.834610 2026] [security2:error] [pid 727775:tid 727982] [client 20.63.98.115:47477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/images/wp-login.php"] [unique_id "amuHv8DCZkc4BvDXnoC8DQAAAE0"]
[Thu Jul 30 12:19:59.867187 2026] [security2:error] [pid 727775:tid 728031] [client 172.213.232.128:9685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuHv8DCZkc4BvDXnoC8DgAAAH4"]
[Thu Jul 30 12:19:59.934074 2026] [security2:error] [pid 727775:tid 727917] [client 158.158.105.63:56065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/hypo.php"] [unique_id "amuHv8DCZkc4BvDXnoC8EgAAAAw"]
[Thu Jul 30 12:19:59.934167 2026] [security2:error] [pid 727775:tid 727917] [client 158.158.105.63:56065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/hypo.php"] [unique_id "amuHv8DCZkc4BvDXnoC8EgAAAAw"]
[Thu Jul 30 12:20:00.529209 2026] [security2:error] [pid 727775:tid 727932] [client 158.158.105.63:18468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuHwMDCZkc4BvDXnoC8HQAAABs"]
[Thu Jul 30 12:20:00.657741 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:18468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/chosen.php"] [unique_id "amuHwMDCZkc4BvDXnoC8IAAAAAs"]
[Thu Jul 30 12:20:00.657869 2026] [security2:error] [pid 727775:tid 727916] [client 158.158.105.63:18468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/chosen.php"] [unique_id "amuHwMDCZkc4BvDXnoC8IAAAAAs"]
[Thu Jul 30 12:20:00.716727 2026] [security2:error] [pid 727775:tid 727871] [remote 57.141.0.49:36352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuHwMDCZkc4BvDXnoC8IgAAaV8"]
[Thu Jul 30 12:20:00.967913 2026] [security2:error] [pid 727775:tid 727994] [client 172.213.232.128:13827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuHwMDCZkc4BvDXnoC8JwAAAFk"]
[Thu Jul 30 12:20:01.041598 2026] [security2:error] [pid 727775:tid 727976] [client 158.158.105.63:18436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/block-bindings/"] [unique_id "amuHwcDCZkc4BvDXnoC8KwAAAEc"]
[Thu Jul 30 12:20:01.171220 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:18436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/als.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LQAAADs"]
[Thu Jul 30 12:20:01.171341 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.105.63:18436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/als.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LQAAADs"]
[Thu Jul 30 12:20:01.184790 2026] [security2:error] [pid 727775:tid 728028] [client 20.151.221.234:41649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/adminer.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LgAAAHs"]
[Thu Jul 30 12:20:01.285344 2026] [security2:error] [pid 727775:tid 727985] [client 20.63.98.115:60802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LwAAAFA"]
[Thu Jul 30 12:20:01.498739 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:19590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/pol.php"] [unique_id "amuHwcDCZkc4BvDXnoC8MwAAADk"]
[Thu Jul 30 12:20:01.498852 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.105.63:19590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/pol.php"] [unique_id "amuHwcDCZkc4BvDXnoC8MwAAADk"]
[Thu Jul 30 12:20:01.694774 2026] [security2:error] [pid 727775:tid 727867] [remote 52.167.144.147:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/buy_guide/misionf.php"] [unique_id "amuHwcDCZkc4BvDXnoC8OAAAels"]
[Thu Jul 30 12:20:01.734726 2026] [security2:error] [pid 727775:tid 728009] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuHwcDCZkc4BvDXnoC8LAAAaF0"]
[Thu Jul 30 12:20:01.790228 2026] [security2:error] [pid 727775:tid 727969] [client 158.158.105.63:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file5.php"] [unique_id "amuHwcDCZkc4BvDXnoC8OgAAAEA"]
[Thu Jul 30 12:20:01.790414 2026] [security2:error] [pid 727775:tid 727969] [client 158.158.105.63:52233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file5.php"] [unique_id "amuHwcDCZkc4BvDXnoC8OgAAAEA"]
[Thu Jul 30 12:20:02.270089 2026] [security2:error] [pid 727775:tid 727956] [client 158.158.105.63:18441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file.php"] [unique_id "amuHwsDCZkc4BvDXnoC8QQAAADM"]
[Thu Jul 30 12:20:02.270199 2026] [security2:error] [pid 727775:tid 727956] [client 158.158.105.63:18441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/file.php"] [unique_id "amuHwsDCZkc4BvDXnoC8QQAAADM"]
[Thu Jul 30 12:20:02.385280 2026] [security2:error] [pid 727775:tid 727911] [client 172.213.232.128:1752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuHwsDCZkc4BvDXnoC8QgAAAAY"]
[Thu Jul 30 12:20:02.454102 2026] [security2:error] [pid 727775:tid 727989] [client 20.63.98.115:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/mail.php"] [unique_id "amuHwsDCZkc4BvDXnoC8RAAAAFQ"]
[Thu Jul 30 12:20:02.561102 2026] [security2:error] [pid 727775:tid 728005] [client 158.158.105.63:18475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHwsDCZkc4BvDXnoC8SAAAAGQ"]
[Thu Jul 30 12:20:02.561182 2026] [security2:error] [pid 727775:tid 728005] [client 158.158.105.63:18475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuHwsDCZkc4BvDXnoC8SAAAAGQ"]
[Thu Jul 30 12:20:02.597001 2026] [security2:error] [pid 727775:tid 727990] [client 20.151.221.234:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/alfa.php"] [unique_id "amuHwsDCZkc4BvDXnoC8TAAAAFU"]
[Thu Jul 30 12:20:02.916058 2026] [security2:error] [pid 727775:tid 727982] [client 158.158.105.63:19636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/aa2.php"] [unique_id "amuHwsDCZkc4BvDXnoC8TQAAAE0"]
[Thu Jul 30 12:20:02.916174 2026] [security2:error] [pid 727775:tid 727982] [client 158.158.105.63:19636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/aa2.php"] [unique_id "amuHwsDCZkc4BvDXnoC8TQAAAE0"]
[Thu Jul 30 12:20:03.301641 2026] [security2:error] [pid 727775:tid 728012] [client 158.158.105.63:19644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ccou.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VQAAAGs"]
[Thu Jul 30 12:20:03.301746 2026] [security2:error] [pid 727775:tid 728012] [client 158.158.105.63:19644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/ccou.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VQAAAGs"]
[Thu Jul 30 12:20:03.365373 2026] [security2:error] [pid 727775:tid 727965] [client 172.213.232.128:13881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VwAAADw"]
[Thu Jul 30 12:20:03.499896 2026] [security2:error] [pid 727775:tid 727881] [remote 57.141.0.49:36366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuHw8DCZkc4BvDXnoC8WAAAbWk"]
[Thu Jul 30 12:20:03.580362 2026] [security2:error] [pid 727775:tid 727943] [client 20.63.98.115:47428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-mail.php"] [unique_id "amuHw8DCZkc4BvDXnoC8YQAAACY"]
[Thu Jul 30 12:20:03.595506 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:19593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dr.php"] [unique_id "amuHw8DCZkc4BvDXnoC8YwAAAGM"]
[Thu Jul 30 12:20:03.595609 2026] [security2:error] [pid 727775:tid 728004] [client 158.158.105.63:19593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.austriavisaapplicationcenterinislamabad.site"] [uri "/dr.php"] [unique_id "amuHw8DCZkc4BvDXnoC8YwAAAGM"]
[Thu Jul 30 12:20:03.605944 2026] [security2:error] [pid 727775:tid 727947] [client 68.235.38.2:39218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VgAAACo"]
[Thu Jul 30 12:20:03.606061 2026] [security2:error] [pid 727775:tid 727947] [client 68.235.38.2:39218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuHw8DCZkc4BvDXnoC8VgAAACo"]
[Thu Jul 30 12:20:05.042054 2026] [security2:error] [pid 727775:tid 727958] [client 172.213.232.128:8812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuHxcDCZkc4BvDXnoC8dQAAADU"]
[Thu Jul 30 12:20:05.269189 2026] [security2:error] [pid 727775:tid 727906] [client 20.151.221.234:44785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuHxcDCZkc4BvDXnoC8fwAAAAE"]
[Thu Jul 30 12:20:05.342012 2026] [security2:error] [pid 727775:tid 727908] [client 20.63.98.115:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-trackback.php"] [unique_id "amuHxcDCZkc4BvDXnoC8ggAAAAM"]
[Thu Jul 30 12:20:05.756221 2026] [security2:error] [pid 727775:tid 727911] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuHxcDCZkc4BvDXnoC8hQAAAAY"]
[Thu Jul 30 12:20:06.058094 2026] [security2:error] [pid 727775:tid 727978] [client 20.151.221.234:41769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuHxsDCZkc4BvDXnoC8lQAAAEk"]
[Thu Jul 30 12:20:06.884823 2026] [core:notice] [pid 727775:tid 727929] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:06.888576 2026] [security2:error] [pid 727775:tid 727987] [client 172.213.232.128:8828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuHxsDCZkc4BvDXnoC8pQAAAFI"]
[Thu Jul 30 12:20:07.365713 2026] [security2:error] [pid 727775:tid 727963] [client 20.63.98.115:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/uploads/cong.php"] [unique_id "amuHx8DCZkc4BvDXnoC8sAAAADo"]
[Thu Jul 30 12:20:07.441294 2026] [security2:error] [pid 727775:tid 727946] [client 20.151.221.234:44746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuHx8DCZkc4BvDXnoC8sQAAACk"]
[Thu Jul 30 12:20:08.246965 2026] [security2:error] [pid 727775:tid 727998] [client 172.213.232.128:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/images/about.php"] [unique_id "amuHyMDCZkc4BvDXnoC8wgAAAF0"]
[Thu Jul 30 12:20:08.340505 2026] [security2:error] [pid 727775:tid 728011] [client 20.63.98.115:61909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuHyMDCZkc4BvDXnoC8xgAAAGo"]
[Thu Jul 30 12:20:08.389265 2026] [security2:error] [pid 727775:tid 728007] [client 20.151.221.234:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/edit.php"] [unique_id "amuHyMDCZkc4BvDXnoC8ygAAAGY"]
[Thu Jul 30 12:20:09.539779 2026] [security2:error] [pid 727775:tid 727984] [client 68.235.38.2:56952] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuHycDCZkc4BvDXnoC84wAAAE8"]
[Thu Jul 30 12:20:09.539890 2026] [security2:error] [pid 727775:tid 727984] [client 68.235.38.2:56952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuHycDCZkc4BvDXnoC84wAAAE8"]
[Thu Jul 30 12:20:09.624428 2026] [security2:error] [pid 727775:tid 727970] [client 172.213.232.128:1766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuHycDCZkc4BvDXnoC85AAAAEE"]
[Thu Jul 30 12:20:09.645582 2026] [core:notice] [pid 727775:tid 727997] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:09.860035 2026] [security2:error] [pid 727775:tid 727943] [client 38.190.144.4:61288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuHycDCZkc4BvDXnoC86QAAACY"]
[Thu Jul 30 12:20:09.862332 2026] [security2:error] [pid 727775:tid 727943] [client 38.190.144.4:61288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuHycDCZkc4BvDXnoC86QAAACY"]
[Thu Jul 30 12:20:09.897340 2026] [security2:error] [pid 727775:tid 727979] [client 20.63.98.115:62058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/webadmin.php"] [unique_id "amuHycDCZkc4BvDXnoC87QAAAEo"]
[Thu Jul 30 12:20:10.032658 2026] [security2:error] [pid 727775:tid 727962] [client 127.0.0.1:47862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHysDCZkc4BvDXnoC88wAAADk"]
[Thu Jul 30 12:20:10.032673 2026] [security2:error] [pid 727775:tid 727950] [client 127.0.0.1:47858] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.embassyofitalyislamabad.vip"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuHysDCZkc4BvDXnoC88gAAAC0"]
[Thu Jul 30 12:20:10.032786 2026] [security2:error] [pid 727775:tid 727930] [client 74.7.175.140:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.embassyofitalyislamabad.vip"] [uri "/robots.txt"] [unique_id "amuHysDCZkc4BvDXnoC88QAAGR4"]
[Thu Jul 30 12:20:10.485419 2026] [security2:error] [pid 727775:tid 727805] [remote 162.0.217.83:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.217.0.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/wp-login.php"] [unique_id "amuHysDCZkc4BvDXnoC8-QAASx0"]
[Thu Jul 30 12:20:10.610264 2026] [core:error] [pid 727775:tid 727909] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:10.610301 2026] [core:error] [pid 727775:tid 727909] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:10.639765 2026] [security2:error] [pid 727775:tid 727919] [client 172.213.232.128:8287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuHysDCZkc4BvDXnoC8_QAAAA4"]
[Thu Jul 30 12:20:10.970940 2026] [security2:error] [pid 727775:tid 728029] [client 20.151.221.234:4353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/sf.php"] [unique_id "amuHysDCZkc4BvDXnoC9BgAAAHw"]
[Thu Jul 30 12:20:11.030859 2026] [security2:error] [pid 727775:tid 727907] [client 20.63.98.115:57136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/link.php"] [unique_id "amuHy8DCZkc4BvDXnoC9CgAAAAI"]
[Thu Jul 30 12:20:11.369909 2026] [core:notice] [pid 727775:tid 728018] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:12.160511 2026] [security2:error] [pid 727775:tid 727984] [client 20.151.221.234:41754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wso.php"] [unique_id "amuHzMDCZkc4BvDXnoC9HQAAAE8"]
[Thu Jul 30 12:20:12.224421 2026] [security2:error] [pid 727775:tid 728019] [client 172.213.232.128:1791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/about.php"] [unique_id "amuHzMDCZkc4BvDXnoC9HgAAAHI"]
[Thu Jul 30 12:20:12.678901 2026] [security2:error] [pid 727775:tid 728022] [client 20.63.98.115:60844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ova.php"] [unique_id "amuHzMDCZkc4BvDXnoC9JwAAAHU"]
[Thu Jul 30 12:20:13.314652 2026] [security2:error] [pid 727775:tid 728008] [client 172.213.232.128:15689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cgi-bin/about.php"] [unique_id "amuHzcDCZkc4BvDXnoC9MQAAAGc"]
[Thu Jul 30 12:20:13.738079 2026] [security2:error] [pid 727775:tid 727980] [client 20.63.98.115:20643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/coffee/about.php"] [unique_id "amuHzcDCZkc4BvDXnoC9OQAAAEs"]
[Thu Jul 30 12:20:13.833187 2026] [security2:error] [pid 727775:tid 727985] [client 20.151.221.234:41636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/ioxi-o.php"] [unique_id "amuHzcDCZkc4BvDXnoC9OgAAAFA"]
[Thu Jul 30 12:20:14.425784 2026] [security2:error] [pid 727775:tid 727924] [client 172.213.232.128:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuHzsDCZkc4BvDXnoC9RQAAABM"]
[Thu Jul 30 12:20:15.162750 2026] [security2:error] [pid 727775:tid 727913] [client 20.151.221.234:44754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/file56.php"] [unique_id "amuHz8DCZkc4BvDXnoC9WAAAAAg"]
[Thu Jul 30 12:20:15.170414 2026] [security2:error] [pid 727775:tid 728030] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuHzsDCZkc4BvDXnoC9SAAAAH0"]
[Thu Jul 30 12:20:15.358239 2026] [security2:error] [pid 727775:tid 727999] [client 139.28.219.70:46454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "exploringchanges.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuHz8DCZkc4BvDXnoC9XQAAAF4"]
[Thu Jul 30 12:20:15.388859 2026] [security2:error] [pid 727775:tid 728010] [client 172.213.232.128:1774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuHz8DCZkc4BvDXnoC9XgAAAGk"]
[Thu Jul 30 12:20:15.654350 2026] [security2:error] [pid 727775:tid 727842] [remote 216.73.216.152:54907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuHz8DCZkc4BvDXnoC9YgAAd0I"]
[Thu Jul 30 12:20:16.002436 2026] [security2:error] [pid 727775:tid 728022] [client 139.28.219.70:46470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/xmlrpc.php"] [unique_id "amuHz8DCZkc4BvDXnoC9agAAAHU"]
[Thu Jul 30 12:20:16.252621 2026] [security2:error] [pid 727775:tid 727979] [client 20.63.98.115:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuH0MDCZkc4BvDXnoC9cgAAAEo"]
[Thu Jul 30 12:20:16.346752 2026] [security2:error] [pid 727775:tid 727983] [client 172.213.232.128:13828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuH0MDCZkc4BvDXnoC9dAAAAE4"]
[Thu Jul 30 12:20:16.481298 2026] [security2:error] [pid 727775:tid 727940] [client 20.151.221.234:41611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuH0MDCZkc4BvDXnoC9dQAAACM"]
[Thu Jul 30 12:20:17.811551 2026] [security2:error] [pid 727775:tid 727915] [client 20.151.221.234:41758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuH0cDCZkc4BvDXnoC9kgAAAAo"]
[Thu Jul 30 12:20:18.460378 2026] [security2:error] [pid 727775:tid 727965] [client 74.7.241.129:58654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.website-d29d2608.vdb.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuH0sDCZkc4BvDXnoC9ogAAPEw"]
[Thu Jul 30 12:20:18.716061 2026] [security2:error] [pid 727775:tid 727941] [client 172.213.232.128:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuH0sDCZkc4BvDXnoC9owAAACQ"]
[Thu Jul 30 12:20:18.866323 2026] [security2:error] [pid 727775:tid 727946] [client 139.28.219.70:46478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/xmlrpc.php"] [unique_id "amuH0sDCZkc4BvDXnoC9qgAAACk"]
[Thu Jul 30 12:20:18.866425 2026] [security2:error] [pid 727775:tid 727946] [client 139.28.219.70:46478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "exploringchanges.com"] [uri "/xmlrpc.php"] [unique_id "amuH0sDCZkc4BvDXnoC9qgAAACk"]
[Thu Jul 30 12:20:19.035300 2026] [security2:error] [pid 727775:tid 727987] [client 20.63.98.115:57127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/users.php"] [unique_id "amuH08DCZkc4BvDXnoC9rAAAAFI"]
[Thu Jul 30 12:20:19.647749 2026] [core:notice] [pid 727775:tid 727873] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:19.730240 2026] [security2:error] [pid 727775:tid 727936] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuH08DCZkc4BvDXnoC9sAAAH0Y"]
[Thu Jul 30 12:20:19.895960 2026] [security2:error] [pid 727775:tid 727980] [client 20.63.98.115:61903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/defaults.php"] [unique_id "amuH08DCZkc4BvDXnoC9xgAAAEs"]
[Thu Jul 30 12:20:19.934614 2026] [security2:error] [pid 727775:tid 727998] [client 172.213.232.128:25056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuH08DCZkc4BvDXnoC9xwAAAF0"]
[Thu Jul 30 12:20:21.057914 2026] [security2:error] [pid 727775:tid 727913] [client 172.213.232.128:10446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuH1cDCZkc4BvDXnoC91wAAAAg"]
[Thu Jul 30 12:20:21.314106 2026] [security2:error] [pid 727775:tid 727949] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.dl.happymod-apk.com.mx"] [uri "/"] [unique_id "amuH1cDCZkc4BvDXnoC92AAAACw"]
[Thu Jul 30 12:20:22.340409 2026] [security2:error] [pid 727775:tid 727999] [client 172.213.232.128:6658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuH1sDCZkc4BvDXnoC97wAAAF4"]
[Thu Jul 30 12:20:23.432171 2026] [security2:error] [pid 727775:tid 728007] [client 172.213.232.128:18685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cloud.php"] [unique_id "amuH18DCZkc4BvDXnoC9_QAAAGY"]
[Thu Jul 30 12:20:23.554877 2026] [core:notice] [pid 727775:tid 728015] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:24.036595 2026] [core:notice] [pid 727775:tid 727911] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:24.086990 2026] [security2:error] [pid 727775:tid 728013] [client 172.213.232.128:7762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuH2MDCZkc4BvDXnoC-DwAAAGw"]
[Thu Jul 30 12:20:24.233958 2026] [security2:error] [pid 727775:tid 728000] [client 20.151.221.234:49632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/edit.php"] [unique_id "amuH2MDCZkc4BvDXnoC-EAAAAF8"]
[Thu Jul 30 12:20:24.528686 2026] [core:notice] [pid 727775:tid 727899] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:24.704969 2026] [security2:error] [pid 727775:tid 727970] [client 172.213.232.128:10482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/updates.php"] [unique_id "amuH2MDCZkc4BvDXnoC-GwAAAEE"]
[Thu Jul 30 12:20:24.980308 2026] [security2:error] [pid 727775:tid 727947] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH2MDCZkc4BvDXnoC-EwAAKmI"]
[Thu Jul 30 12:20:25.105935 2026] [security2:error] [pid 727775:tid 727914] [client 20.151.221.234:50126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/2.php"] [unique_id "amuH2cDCZkc4BvDXnoC-HwAAAAk"]
[Thu Jul 30 12:20:25.278893 2026] [security2:error] [pid 727775:tid 728010] [client 172.213.232.128:1528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/css/cloud.php"] [unique_id "amuH2cDCZkc4BvDXnoC-IwAAAGk"]
[Thu Jul 30 12:20:25.576329 2026] [security2:error] [pid 727775:tid 728006] [client 184.75.223.195:60748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuH2cDCZkc4BvDXnoC-JAAAAGU"]
[Thu Jul 30 12:20:25.576493 2026] [security2:error] [pid 727775:tid 728006] [client 184.75.223.195:60748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuH2cDCZkc4BvDXnoC-JAAAAGU"]
[Thu Jul 30 12:20:26.147260 2026] [security2:error] [pid 727775:tid 727988] [client 20.63.98.115:60859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Text/about.php"] [unique_id "amuH2sDCZkc4BvDXnoC-NAAAAFM"]
[Thu Jul 30 12:20:26.766862 2026] [security2:error] [pid 727775:tid 727966] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH2sDCZkc4BvDXnoC-OQAAPQE"]
[Thu Jul 30 12:20:27.150989 2026] [security2:error] [pid 727775:tid 727788] [remote 156.59.198.136:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nafmedical.com"] [uri "/wp-content/uploads/2025/06/image-placeholder-5-uai-1706x1280.jpg"] [unique_id "amuH28DCZkc4BvDXnoC-TQAAegw"], referer: https://nafmedical.com/features/row-animations/
[Thu Jul 30 12:20:27.519014 2026] [security2:error] [pid 727775:tid 727960] [client 57.129.81.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuH28DCZkc4BvDXnoC-UwAAADc"]
[Thu Jul 30 12:20:27.562637 2026] [security2:error] [pid 727775:tid 727979] [client 20.151.221.234:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuH28DCZkc4BvDXnoC-WAAAAEo"]
[Thu Jul 30 12:20:28.475479 2026] [security2:error] [pid 727775:tid 727954] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH3MDCZkc4BvDXnoC-YwAAMQQ"]
[Thu Jul 30 12:20:28.543679 2026] [security2:error] [pid 727775:tid 727999] [client 87.101.92.171:33188] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuH3MDCZkc4BvDXnoC-cwAAAF4"]
[Thu Jul 30 12:20:28.543780 2026] [security2:error] [pid 727775:tid 727999] [client 87.101.92.171:33188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuH3MDCZkc4BvDXnoC-cwAAAF4"]
[Thu Jul 30 12:20:28.621634 2026] [security2:error] [pid 727775:tid 727798] [remote 54.39.210.105:21866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.urwru.club"] [uri "/sitemap.xml"] [unique_id "amuH3MDCZkc4BvDXnoC-dQAAGxY"]
[Thu Jul 30 12:20:28.621827 2026] [security2:error] [pid 727775:tid 727932] [client 54.39.210.105:21866] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/sitemap.xml"] [unique_id "amuH3MDCZkc4BvDXnoC-dQAAGxY"]
[Thu Jul 30 12:20:28.630042 2026] [security2:error] [pid 727775:tid 728022] [client 20.151.221.234:49623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/mah.php"] [unique_id "amuH3MDCZkc4BvDXnoC-dgAAAHU"]
[Thu Jul 30 12:20:29.005611 2026] [core:notice] [pid 727775:tid 727801] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:29.131941 2026] [security2:error] [pid 727775:tid 727966] [client 195.113.175.167:1655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/valuef.php"] [unique_id "amuH3cDCZkc4BvDXnoC-gwAAAD0"]
[Thu Jul 30 12:20:29.229392 2026] [security2:error] [pid 727775:tid 727908] [client 172.213.232.128:22651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuH3cDCZkc4BvDXnoC-hQAAAAM"]
[Thu Jul 30 12:20:29.357345 2026] [security2:error] [pid 727775:tid 728003] [client 54.38.214.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuH3cDCZkc4BvDXnoC-iQAAAGI"]
[Thu Jul 30 12:20:29.632062 2026] [security2:error] [pid 727775:tid 728027] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH3cDCZkc4BvDXnoC-jAAAeiA"]
[Thu Jul 30 12:20:29.735139 2026] [security2:error] [pid 727775:tid 727805] [remote 57.141.0.12:42830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/619183613/feed/rss2/"] [unique_id "amuH3cDCZkc4BvDXnoC-kQAAXx0"]
[Thu Jul 30 12:20:29.914740 2026] [security2:error] [pid 727775:tid 727928] [client 20.151.221.234:50149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/send.php"] [unique_id "amuH3cDCZkc4BvDXnoC-mAAAABc"]
[Thu Jul 30 12:20:29.961260 2026] [security2:error] [pid 727775:tid 728026] [client 172.213.232.128:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/img/cloud.php"] [unique_id "amuH3cDCZkc4BvDXnoC-mwAAAHk"]
[Thu Jul 30 12:20:30.093441 2026] [security2:error] [pid 727775:tid 727937] [client 20.63.98.115:62069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "amuH3sDCZkc4BvDXnoC-nAAAACA"]
[Thu Jul 30 12:20:30.461656 2026] [security2:error] [pid 727775:tid 727811] [remote 77.95.113.183:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.113.95.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuH3sDCZkc4BvDXnoC-pAAAKiM"]
[Thu Jul 30 12:20:30.573416 2026] [security2:error] [pid 727775:tid 728030] [client 172.213.232.128:6669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuH3sDCZkc4BvDXnoC-pQAAAH0"]
[Thu Jul 30 12:20:30.760680 2026] [security2:error] [pid 727775:tid 728025] [client 213.32.68.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuH3sDCZkc4BvDXnoC-qAAAAHg"]
[Thu Jul 30 12:20:30.806649 2026] [security2:error] [pid 727775:tid 727965] [client 20.151.221.234:49634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuH3sDCZkc4BvDXnoC-sAAAADw"]
[Thu Jul 30 12:20:31.130282 2026] [security2:error] [pid 727775:tid 727976] [client 172.213.232.128:21661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuH38DCZkc4BvDXnoC-vQAAAEc"]
[Thu Jul 30 12:20:31.235185 2026] [security2:error] [pid 727775:tid 727995] [client 51.38.115.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuH38DCZkc4BvDXnoC-vAAAAFo"]
[Thu Jul 30 12:20:31.330884 2026] [security2:error] [pid 727775:tid 728014] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuH3sDCZkc4BvDXnoC-rAAAbSo"]
[Thu Jul 30 12:20:31.829810 2026] [security2:error] [pid 727775:tid 727957] [client 20.63.98.115:63364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/plugins.php"] [unique_id "amuH38DCZkc4BvDXnoC-xAAAADQ"]
[Thu Jul 30 12:20:32.134580 2026] [security2:error] [pid 727775:tid 727981] [client 172.213.232.128:19642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/avaa.php"] [unique_id "amuH4MDCZkc4BvDXnoC-zAAAAEw"]
[Thu Jul 30 12:20:32.299224 2026] [security2:error] [pid 727775:tid 727939] [client 20.151.221.234:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/about.php"] [unique_id "amuH4MDCZkc4BvDXnoC-zQAAACI"]
[Thu Jul 30 12:20:32.831899 2026] [security2:error] [pid 727775:tid 727944] [client 20.63.98.115:27168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/upgrade/wp-login.php"] [unique_id "amuH4MDCZkc4BvDXnoC-1QAAACc"]
[Thu Jul 30 12:20:33.003304 2026] [security2:error] [pid 727775:tid 727959] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH4MDCZkc4BvDXnoC-1AAANis"]
[Thu Jul 30 12:20:33.221906 2026] [security2:error] [pid 727775:tid 728026] [client 20.151.221.234:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/options.php"] [unique_id "amuH4cDCZkc4BvDXnoC-3wAAAHk"]
[Thu Jul 30 12:20:33.497161 2026] [security2:error] [pid 727775:tid 728012] [client 172.213.232.128:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/images/cloud.php"] [unique_id "amuH4cDCZkc4BvDXnoC-4wAAAGs"]
[Thu Jul 30 12:20:34.020694 2026] [security2:error] [pid 727775:tid 727965] [client 20.63.98.115:54562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/certificates/wp-login.php"] [unique_id "amuH4sDCZkc4BvDXnoC-7gAAADw"]
[Thu Jul 30 12:20:34.072834 2026] [core:notice] [pid 727775:tid 727836] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:34.095086 2026] [security2:error] [pid 727775:tid 728001] [client 20.151.221.234:49639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuH4sDCZkc4BvDXnoC-8wAAAGA"]
[Thu Jul 30 12:20:34.145716 2026] [core:notice] [pid 727775:tid 727975] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:34.308584 2026] [core:notice] [pid 727775:tid 727829] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:34.352474 2026] [security2:error] [pid 727775:tid 727833] [remote 57.141.0.6:50810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuH4sDCZkc4BvDXnoC-9QAAMDk"]
[Thu Jul 30 12:20:34.899170 2026] [security2:error] [pid 727775:tid 727946] [client 20.151.221.234:50135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-file.php"] [unique_id "amuH4sDCZkc4BvDXnoC-_gAAACk"]
[Thu Jul 30 12:20:35.004931 2026] [security2:error] [pid 727775:tid 727986] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH4sDCZkc4BvDXnoC-_QAAUUI"]
[Thu Jul 30 12:20:35.095378 2026] [security2:error] [pid 727775:tid 727834] [remote 74.7.241.59:46718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuH48DCZkc4BvDXnoC_AgAALTo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:20:35.745961 2026] [security2:error] [pid 727775:tid 727990] [client 20.63.98.115:21060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/network.php"] [unique_id "amuH48DCZkc4BvDXnoC_EAAAAFU"]
[Thu Jul 30 12:20:35.876042 2026] [security2:error] [pid 727775:tid 727984] [client 20.151.221.234:49636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/sid3.php"] [unique_id "amuH48DCZkc4BvDXnoC_EgAAAE8"]
[Thu Jul 30 12:20:36.216276 2026] [security2:error] [pid 727775:tid 727844] [remote 216.73.216.152:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuH5MDCZkc4BvDXnoC_GQAAdEQ"]
[Thu Jul 30 12:20:36.629092 2026] [security2:error] [pid 727775:tid 727934] [client 172.213.232.128:1400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuH5MDCZkc4BvDXnoC_IwAAAB0"]
[Thu Jul 30 12:20:36.823281 2026] [security2:error] [pid 727775:tid 728024] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH5MDCZkc4BvDXnoC_GwAAd0g"]
[Thu Jul 30 12:20:36.840601 2026] [core:notice] [pid 727775:tid 728020] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:37.250298 2026] [security2:error] [pid 727775:tid 727988] [client 172.213.232.128:1880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuH5cDCZkc4BvDXnoC_MwAAAFM"]
[Thu Jul 30 12:20:37.356118 2026] [security2:error] [pid 727775:tid 727937] [client 43.166.237.57:55288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.237.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/index/user/register"] [unique_id "amuH5cDCZkc4BvDXnoC_NAAAACA"], referer: https://ejournalugj.com/index_php/index/user/register
[Thu Jul 30 12:20:38.625937 2026] [security2:error] [pid 727775:tid 727958] [client 20.63.98.115:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-cron.php"] [unique_id "amuH5sDCZkc4BvDXnoC_QwAAADU"]
[Thu Jul 30 12:20:39.162221 2026] [security2:error] [pid 727775:tid 727938] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH5sDCZkc4BvDXnoC_RwAAIVw"]
[Thu Jul 30 12:20:39.520831 2026] [security2:error] [pid 727775:tid 727944] [client 20.63.98.115:54555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/acp.php"] [unique_id "amuH58DCZkc4BvDXnoC_VQAAACc"]
[Thu Jul 30 12:20:39.801940 2026] [core:notice] [pid 727775:tid 727996] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:40.670570 2026] [security2:error] [pid 727775:tid 727978] [client 20.63.98.115:39052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/assets/bypass.php"] [unique_id "amuH6MDCZkc4BvDXnoC_ZwAAAEk"]
[Thu Jul 30 12:20:42.024453 2026] [security2:error] [pid 727775:tid 727906] [client 20.63.98.115:54561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/sx.php"] [unique_id "amuH6sDCZkc4BvDXnoC_gAAAAAE"]
[Thu Jul 30 12:20:42.326108 2026] [security2:error] [pid 727775:tid 727886] [remote 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH6cDCZkc4BvDXnoC_fwAATW4"]
[Thu Jul 30 12:20:42.788338 2026] [security2:error] [pid 727775:tid 727948] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuH6sDCZkc4BvDXnoC_gwAAACs"]
[Thu Jul 30 12:20:43.046231 2026] [security2:error] [pid 727775:tid 728000] [client 20.63.98.115:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/adminfuns.php"] [unique_id "amuH68DCZkc4BvDXnoC_kgAAAF8"]
[Thu Jul 30 12:20:43.812425 2026] [core:error] [pid 727775:tid 727924] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:43.812452 2026] [core:error] [pid 727775:tid 727924] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:43.885173 2026] [security2:error] [pid 727775:tid 727996] [client 20.63.98.115:63381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/about.php"] [unique_id "amuH68DCZkc4BvDXnoC_lwAAAFs"]
[Thu Jul 30 12:20:45.197622 2026] [security2:error] [pid 727775:tid 727999] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH7MDCZkc4BvDXnoC_qgAAXnA"]
[Thu Jul 30 12:20:45.530656 2026] [core:notice] [pid 727775:tid 728002] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:45.711744 2026] [security2:error] [pid 727775:tid 727782] [remote 216.73.216.152:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuH7cDCZkc4BvDXnoC_ugAAcQY"]
[Thu Jul 30 12:20:45.819987 2026] [security2:error] [pid 727775:tid 728023] [client 68.67.112.136:46180] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuH7cDCZkc4BvDXnoC_wQAAAHY"]
[Thu Jul 30 12:20:46.021680 2026] [core:notice] [pid 727775:tid 727927] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:20:46.346021 2026] [autoindex:error] [pid 727775:tid 727953] [client 20.63.98.115:57095] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:20:46.584666 2026] [security2:error] [pid 727775:tid 727997] [client 20.63.98.115:57095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/images/chosen.php"] [unique_id "amuH7sDCZkc4BvDXnoC_zQAAAFw"]
[Thu Jul 30 12:20:46.796799 2026] [security2:error] [pid 727775:tid 727785] [remote 54.87.95.7:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/"] [unique_id "amuH7sDCZkc4BvDXnoC_1wAAVQk"]
[Thu Jul 30 12:20:47.658866 2026] [security2:error] [pid 727775:tid 727957] [client 223.109.255.159:45484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2024/05/28/ricardo-coutinho-alfineta-cicero-lucena-e-diz-que-decisao-do-pt-mexeu-com-emocional-do-prefeito/"] [unique_id "amuH78DCZkc4BvDXnoDADQAAADQ"]
[Thu Jul 30 12:20:47.658945 2026] [security2:error] [pid 727775:tid 727957] [client 223.109.255.159:45484] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2024/05/28/ricardo-coutinho-alfineta-cicero-lucena-e-diz-que-decisao-do-pt-mexeu-com-emocional-do-prefeito/"] [unique_id "amuH78DCZkc4BvDXnoDADQAAADQ"]
[Thu Jul 30 12:20:48.077448 2026] [security2:error] [pid 727775:tid 728017] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH78DCZkc4BvDXnoDAEAAAcCE"]
[Thu Jul 30 12:20:48.629500 2026] [security2:error] [pid 727775:tid 727925] [client 87.101.92.171:41462] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuH8MDCZkc4BvDXnoDAHgAAABQ"]
[Thu Jul 30 12:20:48.629609 2026] [security2:error] [pid 727775:tid 727925] [client 87.101.92.171:41462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuH8MDCZkc4BvDXnoDAHgAAABQ"]
[Thu Jul 30 12:20:48.971018 2026] [security2:error] [pid 727775:tid 727944] [client 20.63.98.115:39066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/wp-class.php"] [unique_id "amuH8MDCZkc4BvDXnoDAJQAAACc"]
[Thu Jul 30 12:20:49.404944 2026] [core:error] [pid 727775:tid 728010] [client 34.139.111.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:49.404967 2026] [core:error] [pid 727775:tid 728010] [client 34.139.111.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:50.623613 2026] [security2:error] [pid 727775:tid 728022] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuH8sDCZkc4BvDXnoDAOQAAdTA"]
[Thu Jul 30 12:20:51.099128 2026] [security2:error] [pid 727775:tid 727905] [client 20.63.98.115:27197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/install.php"] [unique_id "amuH88DCZkc4BvDXnoDAUAAAAAA"]
[Thu Jul 30 12:20:51.607327 2026] [security2:error] [pid 727775:tid 727960] [client 27.17.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuH88DCZkc4BvDXnoDAUQAANzk"]
[Thu Jul 30 12:20:52.122132 2026] [security2:error] [pid 727775:tid 727933] [client 172.213.232.128:20658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuH9MDCZkc4BvDXnoDAXwAAABw"]
[Thu Jul 30 12:20:52.806897 2026] [security2:error] [pid 727775:tid 727911] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuH9MDCZkc4BvDXnoDAYAAABjo"]
[Thu Jul 30 12:20:53.302105 2026] [security2:error] [pid 727775:tid 727844] [remote 190.92.174.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "embassyofitalyislamabad.vip"] [uri "/wp-login.php"] [unique_id "amuH9cDCZkc4BvDXnoDAdQAAfEQ"]
[Thu Jul 30 12:20:53.848771 2026] [core:error] [pid 727775:tid 727913] [client 34.139.111.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:53.848793 2026] [core:error] [pid 727775:tid 727913] [client 34.139.111.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:20:54.154691 2026] [security2:error] [pid 727775:tid 727908] [client 172.213.232.128:9205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuH9sDCZkc4BvDXnoDAiQAAAAM"]
[Thu Jul 30 12:20:55.076690 2026] [security2:error] [pid 727775:tid 727990] [client 172.213.232.128:23064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuH98DCZkc4BvDXnoDAlAAAAFU"]
[Thu Jul 30 12:20:55.690337 2026] [security2:error] [pid 727775:tid 727935] [client 172.213.232.128:9175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuH98DCZkc4BvDXnoDAnAAAAB4"]
[Thu Jul 30 12:20:55.908227 2026] [security2:error] [pid 727775:tid 728030] [client 57.141.0.41:21246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuH98DCZkc4BvDXnoDAmAAAfV8"], referer: https://igetvape-australia.com/product/iget-moon-passion-fruit-lychee/?add-to-cart=138
[Thu Jul 30 12:20:56.357766 2026] [security2:error] [pid 727775:tid 727975] [client 172.213.232.128:22131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/updates.php"] [unique_id "amuH-MDCZkc4BvDXnoDApgAAAEY"]
[Thu Jul 30 12:20:56.821307 2026] [security2:error] [pid 727775:tid 728006] [client 172.213.232.128:23063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuH-MDCZkc4BvDXnoDAsgAAAGU"]
[Thu Jul 30 12:20:57.464563 2026] [security2:error] [pid 727775:tid 727986] [client 172.213.232.128:9212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuH-cDCZkc4BvDXnoDAwAAAAFE"]
[Thu Jul 30 12:20:58.152028 2026] [security2:error] [pid 727775:tid 727905] [client 172.213.232.128:46959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuH-sDCZkc4BvDXnoDAzAAAAAA"]
[Thu Jul 30 12:20:59.632504 2026] [security2:error] [pid 727775:tid 727956] [client 172.213.232.128:15635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfa-rex.php7"] [unique_id "amuH-8DCZkc4BvDXnoDBDgAAADM"]
[Thu Jul 30 12:21:00.160215 2026] [security2:error] [pid 727775:tid 727976] [client 172.213.232.128:9199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfanew.php"] [unique_id "amuH_MDCZkc4BvDXnoDBHQAAAEc"]
[Thu Jul 30 12:21:00.662906 2026] [security2:error] [pid 727775:tid 727778] [remote 57.141.0.35:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuH_MDCZkc4BvDXnoDBKAAAVQI"]
[Thu Jul 30 12:21:00.758362 2026] [security2:error] [pid 727775:tid 727998] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuH_MDCZkc4BvDXnoDBIAAAAF0"]
[Thu Jul 30 12:21:00.775578 2026] [security2:error] [pid 727775:tid 727925] [client 38.190.144.4:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuH_MDCZkc4BvDXnoDBKgAAABQ"]
[Thu Jul 30 12:21:00.775684 2026] [security2:error] [pid 727775:tid 727925] [client 38.190.144.4:49369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuH_MDCZkc4BvDXnoDBKgAAABQ"]
[Thu Jul 30 12:21:00.779481 2026] [security2:error] [pid 727775:tid 727984] [client 74.7.244.13:52528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lark-shop.com"] [uri "/robots.txt"] [unique_id "amuH_MDCZkc4BvDXnoDBKQAATwA"]
[Thu Jul 30 12:21:00.993654 2026] [security2:error] [pid 727775:tid 727933] [client 172.213.232.128:25317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuH_MDCZkc4BvDXnoDBNAAAABw"]
[Thu Jul 30 12:21:01.176223 2026] [security2:error] [pid 727775:tid 727949] [client 151.242.181.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuH_MDCZkc4BvDXnoDBLgAAACw"], referer: https://tereashops.com/product-category/ploom-x/page/2/
[Thu Jul 30 12:21:02.479214 2026] [security2:error] [pid 727775:tid 727981] [client 20.63.98.115:21063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/cgi-bin/about.php"] [unique_id "amuH_sDCZkc4BvDXnoDBVAAAAEw"]
[Thu Jul 30 12:21:02.887029 2026] [core:error] [pid 727775:tid 727920] [client 66.249.65.101:63421] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:02.887054 2026] [core:error] [pid 727775:tid 727920] [client 66.249.65.101:63421] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:03.595517 2026] [security2:error] [pid 727775:tid 728016] [client 20.63.98.115:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/about.php"] [unique_id "amuH_8DCZkc4BvDXnoDBbQAAAG8"]
[Thu Jul 30 12:21:04.819569 2026] [security2:error] [pid 727775:tid 728008] [client 20.63.98.115:61451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/classwithtostring.php"] [unique_id "amuIAMDCZkc4BvDXnoDBhwAAAGc"]
[Thu Jul 30 12:21:05.350201 2026] [security2:error] [pid 727775:tid 728010] [client 68.235.38.2:53340] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuIAcDCZkc4BvDXnoDBjgAAAGk"]
[Thu Jul 30 12:21:05.350305 2026] [security2:error] [pid 727775:tid 728010] [client 68.235.38.2:53340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuIAcDCZkc4BvDXnoDBjgAAAGk"]
[Thu Jul 30 12:21:06.434241 2026] [core:notice] [pid 727775:tid 727951] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:08.451390 2026] [security2:error] [pid 727775:tid 728004] [client 20.203.148.31:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/011i.php"] [unique_id "amuIBMDCZkc4BvDXnoDBvAAAAGM"]
[Thu Jul 30 12:21:08.542548 2026] [core:notice] [pid 727775:tid 728006] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:08.591042 2026] [security2:error] [pid 727775:tid 727949] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIBMDCZkc4BvDXnoDBuwAAACw"]
[Thu Jul 30 12:21:09.503934 2026] [security2:error] [pid 727775:tid 728010] [client 172.213.232.128:15637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuIBcDCZkc4BvDXnoDB2gAAAGk"]
[Thu Jul 30 12:21:09.590602 2026] [core:error] [pid 727775:tid 727838] [remote 74.7.230.55:57978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:09.590622 2026] [core:error] [pid 727775:tid 727838] [remote 74.7.230.55:57978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:09.590852 2026] [security2:error] [pid 727775:tid 727970] [client 74.7.230.55:57978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-9bd961c9.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuIBcDCZkc4BvDXnoDB2wAAQT4"]
[Thu Jul 30 12:21:10.065565 2026] [security2:error] [pid 727775:tid 727951] [client 20.203.148.31:49074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/03a005685d.php"] [unique_id "amuIBsDCZkc4BvDXnoDB6AAAAC4"]
[Thu Jul 30 12:21:10.775914 2026] [security2:error] [pid 727775:tid 727954] [client 172.213.232.128:23383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-p.php7"] [unique_id "amuIBsDCZkc4BvDXnoDCAAAAADE"]
[Thu Jul 30 12:21:11.191724 2026] [security2:error] [pid 727775:tid 728002] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIBsDCZkc4BvDXnoDB9gAAAGE"]
[Thu Jul 30 12:21:11.197737 2026] [security2:error] [pid 727775:tid 727926] [client 195.113.175.167:15593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aprochef.php"] [unique_id "amuIB8DCZkc4BvDXnoDCNQAAABU"]
[Thu Jul 30 12:21:11.257656 2026] [core:notice] [pid 727775:tid 727973] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:11.334620 2026] [security2:error] [pid 727775:tid 727983] [client 172.213.232.128:52883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuIB8DCZkc4BvDXnoDCOgAAAE4"]
[Thu Jul 30 12:21:11.539480 2026] [security2:error] [pid 727775:tid 727960] [client 20.63.98.115:39094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/js/about.php"] [unique_id "amuIB8DCZkc4BvDXnoDCQgAAADc"]
[Thu Jul 30 12:21:12.096295 2026] [security2:error] [pid 727775:tid 727918] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIB8DCZkc4BvDXnoDCQQAADVg"]
[Thu Jul 30 12:21:12.295655 2026] [security2:error] [pid 727775:tid 727948] [client 20.203.148.31:42587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/403.php"] [unique_id "amuICMDCZkc4BvDXnoDCUQAAACs"]
[Thu Jul 30 12:21:12.762136 2026] [security2:error] [pid 727775:tid 727881] [remote 144.79.133.30:39336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/wp-login.php"] [unique_id "amuICMDCZkc4BvDXnoDCWQAAKWk"]
[Thu Jul 30 12:21:13.239069 2026] [security2:error] [pid 727775:tid 727983] [client 20.203.148.31:42457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/404.php"] [unique_id "amuICcDCZkc4BvDXnoDCjQAAAE4"]
[Thu Jul 30 12:21:13.285230 2026] [security2:error] [pid 727775:tid 727973] [client 20.63.98.115:58211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/comfunctions.php"] [unique_id "amuICcDCZkc4BvDXnoDCjgAAAEQ"]
[Thu Jul 30 12:21:13.377065 2026] [security2:error] [pid 727775:tid 727967] [client 172.213.232.128:52890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuICcDCZkc4BvDXnoDCkAAAAD4"]
[Thu Jul 30 12:21:14.034781 2026] [security2:error] [pid 727775:tid 727985] [client 172.213.232.128:25398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/repeater.php"] [unique_id "amuICsDCZkc4BvDXnoDCnQAAAFA"]
[Thu Jul 30 12:21:14.915547 2026] [security2:error] [pid 727775:tid 728007] [client 35.226.21.59:16384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuICsDCZkc4BvDXnoDCrQAAAGY"]
[Thu Jul 30 12:21:14.969925 2026] [security2:error] [pid 727775:tid 727998] [client 43.135.142.7:50010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.142.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/mediaf.php"] [unique_id "amuICsDCZkc4BvDXnoDCswAAAF0"]
[Thu Jul 30 12:21:15.351950 2026] [security2:error] [pid 727775:tid 728030] [client 20.203.148.31:49085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/aa.php"] [unique_id "amuIC8DCZkc4BvDXnoDCwQAAAH0"]
[Thu Jul 30 12:21:16.616377 2026] [security2:error] [pid 727775:tid 727976] [client 35.226.21.59:16386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIDMDCZkc4BvDXnoDC1AAARww"]
[Thu Jul 30 12:21:16.647362 2026] [security2:error] [pid 727775:tid 727969] [client 20.203.148.31:37265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/aafewc0k.php"] [unique_id "amuIDMDCZkc4BvDXnoDC2wAAAEA"]
[Thu Jul 30 12:21:17.832973 2026] [security2:error] [pid 727775:tid 727978] [client 20.63.98.115:61486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/images/class-config.php"] [unique_id "amuIDcDCZkc4BvDXnoDC9AAAAEk"]
[Thu Jul 30 12:21:18.395626 2026] [security2:error] [pid 727775:tid 728010] [client 20.203.148.31:42491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/abcd.php"] [unique_id "amuIDsDCZkc4BvDXnoDDCQAAAGk"]
[Thu Jul 30 12:21:18.411216 2026] [security2:error] [pid 727775:tid 728011] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIDcDCZkc4BvDXnoDC8QAAAGo"]
[Thu Jul 30 12:21:18.905865 2026] [security2:error] [pid 727775:tid 727956] [client 20.63.98.115:61455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/widgets/include.php"] [unique_id "amuIDsDCZkc4BvDXnoDDEgAAADM"]
[Thu Jul 30 12:21:18.938965 2026] [security2:error] [pid 727775:tid 727815] [remote 103.211.202.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.202.211.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kbtfinancezambia.com"] [uri "/wp-login.php"] [unique_id "amuIDsDCZkc4BvDXnoDDGQAAAic"]
[Thu Jul 30 12:21:18.954411 2026] [security2:error] [pid 727775:tid 727953] [client 127.0.0.1:50534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIDsDCZkc4BvDXnoDDGAAAADA"]
[Thu Jul 30 12:21:18.954537 2026] [security2:error] [pid 727775:tid 727938] [client 74.7.241.142:57696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ecre.ae"] [uri "/robots.txt"] [unique_id "amuIDsDCZkc4BvDXnoDDFQAAISM"]
[Thu Jul 30 12:21:19.725623 2026] [security2:error] [pid 727775:tid 727986] [client 20.203.148.31:42452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/about.php"] [unique_id "amuID8DCZkc4BvDXnoDDLQAAAFE"]
[Thu Jul 30 12:21:22.110466 2026] [security2:error] [pid 727775:tid 727961] [client 20.203.148.31:37301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/admin.php"] [unique_id "amuIEsDCZkc4BvDXnoDDmQAAADg"]
[Thu Jul 30 12:21:22.122709 2026] [security2:error] [pid 727775:tid 727952] [client 20.63.98.115:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/install.php"] [unique_id "amuIEsDCZkc4BvDXnoDDmgAAAC8"]
[Thu Jul 30 12:21:22.482944 2026] [core:notice] [pid 727775:tid 727864] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:22.585042 2026] [security2:error] [pid 727775:tid 727854] [remote 216.73.216.152:36496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIEsDCZkc4BvDXnoDDogAAeE4"]
[Thu Jul 30 12:21:23.044235 2026] [security2:error] [pid 727775:tid 727929] [client 20.63.98.115:42948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuIE8DCZkc4BvDXnoDDrAAAABg"]
[Thu Jul 30 12:21:23.885856 2026] [security2:error] [pid 727775:tid 727989] [client 20.203.148.31:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/adminfuns.php"] [unique_id "amuIE8DCZkc4BvDXnoDDvAAAAFQ"]
[Thu Jul 30 12:21:23.984149 2026] [security2:error] [pid 727775:tid 727915] [client 20.63.98.115:39079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/SimplePie/gzdecodes.php"] [unique_id "amuIE8DCZkc4BvDXnoDDwgAAAAo"]
[Thu Jul 30 12:21:25.023814 2026] [security2:error] [pid 727775:tid 728022] [client 20.63.98.115:20706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-back.php"] [unique_id "amuIFcDCZkc4BvDXnoDD2QAAAHU"]
[Thu Jul 30 12:21:25.056092 2026] [security2:error] [pid 727775:tid 727928] [client 2a03:2880:f800:11:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIFMDCZkc4BvDXnoDDzAAAF30"]
[Thu Jul 30 12:21:25.377354 2026] [security2:error] [pid 727775:tid 727993] [client 68.235.38.2:54256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuIFcDCZkc4BvDXnoDD4QAAAFg"]
[Thu Jul 30 12:21:25.377479 2026] [security2:error] [pid 727775:tid 727993] [client 68.235.38.2:54256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuIFcDCZkc4BvDXnoDD4QAAAFg"]
[Thu Jul 30 12:21:25.567451 2026] [proxy:error] [pid 727775:tid 727936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:25.567504 2026] [proxy_http:error] [pid 727775:tid 727936] [client 143.244.57.82:60344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:25.568208 2026] [proxy:error] [pid 727775:tid 727936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:25.568254 2026] [proxy_http:error] [pid 727775:tid 727936] [client 143.244.57.82:60344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:25.834598 2026] [security2:error] [pid 727775:tid 727917] [client 20.63.98.115:20721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "amuIFcDCZkc4BvDXnoDD7wAAAAw"]
[Thu Jul 30 12:21:25.855300 2026] [proxy:error] [pid 727775:tid 727950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:25.855403 2026] [proxy_http:error] [pid 727775:tid 727950] [client 143.244.57.82:60346] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:25.856244 2026] [proxy:error] [pid 727775:tid 727950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:25.856303 2026] [proxy_http:error] [pid 727775:tid 727950] [client 143.244.57.82:60346] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:26.145101 2026] [security2:error] [pid 727775:tid 727942] [client 143.244.57.82:60360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuIFsDCZkc4BvDXnoDD9wAAACU"]
[Thu Jul 30 12:21:26.327264 2026] [security2:error] [pid 727775:tid 727935] [client 68.235.38.2:48292] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuIFsDCZkc4BvDXnoDD-wAAAB4"]
[Thu Jul 30 12:21:26.327352 2026] [security2:error] [pid 727775:tid 727935] [client 68.235.38.2:48292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuIFsDCZkc4BvDXnoDD-wAAAB4"]
[Thu Jul 30 12:21:26.430767 2026] [security2:error] [pid 727775:tid 728013] [client 143.244.57.82:60376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuIFsDCZkc4BvDXnoDD_AAAAGw"]
[Thu Jul 30 12:21:26.466062 2026] [security2:error] [pid 727775:tid 728030] [client 20.203.148.31:48249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/albin.php"] [unique_id "amuIFsDCZkc4BvDXnoDD_QAAAH0"]
[Thu Jul 30 12:21:26.711158 2026] [proxy:error] [pid 727775:tid 727974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:26.711237 2026] [proxy_http:error] [pid 727775:tid 727974] [client 143.244.57.82:60378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:26.711802 2026] [proxy:error] [pid 727775:tid 727974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:26.711845 2026] [proxy_http:error] [pid 727775:tid 727974] [client 143.244.57.82:60378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:26.820337 2026] [security2:error] [pid 727775:tid 727943] [client 74.7.242.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuIFcDCZkc4BvDXnoDD6wAAACY"], referer: https://lark-shop.com/product/mevius-13/
[Thu Jul 30 12:21:27.012819 2026] [security2:error] [pid 727775:tid 727964] [client 143.244.57.82:57994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuIF8DCZkc4BvDXnoDECwAAADs"]
[Thu Jul 30 12:21:27.287525 2026] [security2:error] [pid 727775:tid 727906] [client 143.244.57.82:57998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuIF8DCZkc4BvDXnoDEEwAAAAE"]
[Thu Jul 30 12:21:27.567639 2026] [security2:error] [pid 727775:tid 727920] [client 143.244.57.82:58008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuIF8DCZkc4BvDXnoDEHAAAAA8"]
[Thu Jul 30 12:21:27.608487 2026] [security2:error] [pid 727775:tid 728006] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIFsDCZkc4BvDXnoDECgAAZQo"]
[Thu Jul 30 12:21:27.855410 2026] [security2:error] [pid 727775:tid 727949] [client 143.244.57.82:58020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuIF8DCZkc4BvDXnoDEPAAAACw"]
[Thu Jul 30 12:21:28.145427 2026] [security2:error] [pid 727775:tid 728012] [client 143.244.57.82:58022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuIGMDCZkc4BvDXnoDEVgAAAGs"]
[Thu Jul 30 12:21:28.379488 2026] [security2:error] [pid 727775:tid 727911] [client 20.63.98.115:36861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/themes/index.php"] [unique_id "amuIGMDCZkc4BvDXnoDEXQAAAAY"]
[Thu Jul 30 12:21:28.418161 2026] [security2:error] [pid 727775:tid 727926] [client 143.244.57.82:58036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuIGMDCZkc4BvDXnoDEYgAAABU"]
[Thu Jul 30 12:21:28.701498 2026] [security2:error] [pid 727775:tid 727999] [client 143.244.57.82:58038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuIGMDCZkc4BvDXnoDEawAAAF4"]
[Thu Jul 30 12:21:28.965719 2026] [security2:error] [pid 727775:tid 727908] [client 20.203.148.31:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/amfsqvgv.php"] [unique_id "amuIGMDCZkc4BvDXnoDEbwAAAAM"]
[Thu Jul 30 12:21:28.998906 2026] [security2:error] [pid 727775:tid 727941] [client 143.244.57.82:58054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuIGMDCZkc4BvDXnoDEcgAAACQ"]
[Thu Jul 30 12:21:29.316921 2026] [security2:error] [pid 727775:tid 728028] [client 143.244.57.82:58056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuIGcDCZkc4BvDXnoDEewAAAHs"]
[Thu Jul 30 12:21:29.372938 2026] [security2:error] [pid 727775:tid 727821] [remote 74.7.241.60:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuIGcDCZkc4BvDXnoDEdgAAZy0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:21:29.460411 2026] [security2:error] [pid 727775:tid 727969] [client 112.86.225.93:60230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/lanvin-classic-2/"] [unique_id "amuIGcDCZkc4BvDXnoDEgQAAAEA"]
[Thu Jul 30 12:21:29.460525 2026] [security2:error] [pid 727775:tid 727969] [client 112.86.225.93:60230] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/lanvin-classic-2/"] [unique_id "amuIGcDCZkc4BvDXnoDEgQAAAEA"]
[Thu Jul 30 12:21:29.561385 2026] [security2:error] [pid 727775:tid 727918] [client 20.203.148.31:48499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/ant.php"] [unique_id "amuIGcDCZkc4BvDXnoDEgwAAAA0"]
[Thu Jul 30 12:21:29.612918 2026] [security2:error] [pid 727775:tid 728029] [client 104.238.222.26:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuIGcDCZkc4BvDXnoDEhQAAAHw"]
[Thu Jul 30 12:21:29.649733 2026] [security2:error] [pid 727775:tid 727956] [client 143.244.57.82:58070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuIGcDCZkc4BvDXnoDEiAAAADM"]
[Thu Jul 30 12:21:29.980370 2026] [security2:error] [pid 727775:tid 728024] [client 143.244.57.82:58074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuIGcDCZkc4BvDXnoDEkgAAAHc"]
[Thu Jul 30 12:21:30.052270 2026] [security2:error] [pid 727775:tid 727996] [client 104.238.222.26:61810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuIGsDCZkc4BvDXnoDEkwAAAFs"]
[Thu Jul 30 12:21:30.149373 2026] [security2:error] [pid 727775:tid 727950] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIGcDCZkc4BvDXnoDEggAALTM"]
[Thu Jul 30 12:21:30.254065 2026] [security2:error] [pid 727775:tid 727960] [client 143.244.57.82:58080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mza.djb.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuIGsDCZkc4BvDXnoDEmAAAADc"]
[Thu Jul 30 12:21:30.346034 2026] [security2:error] [pid 727775:tid 727905] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIGcDCZkc4BvDXnoDEjQAAAAA"]
[Thu Jul 30 12:21:30.539336 2026] [core:notice] [pid 727775:tid 727978] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:31.637837 2026] [core:notice] [pid 727775:tid 728003] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:31.676420 2026] [security2:error] [pid 727775:tid 727923] [client 142.93.53.183:61161] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "toscanamall.com"] [uri "/"] [unique_id "amuIG8DCZkc4BvDXnoDEugAAABI"]
[Thu Jul 30 12:21:31.899655 2026] [security2:error] [pid 727775:tid 727945] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIG8DCZkc4BvDXnoDEswAAACg"]
[Thu Jul 30 12:21:32.236361 2026] [core:notice] [pid 727775:tid 727924] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:32.372966 2026] [security2:error] [pid 727775:tid 727952] [client 143.244.57.86:55604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuIHMDCZkc4BvDXnoDEyAAAAC8"]
[Thu Jul 30 12:21:32.600908 2026] [security2:error] [pid 727775:tid 727844] [remote 216.73.216.152:63752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIHMDCZkc4BvDXnoDE0AAAfUQ"]
[Thu Jul 30 12:21:32.721164 2026] [security2:error] [pid 727775:tid 727917] [client 20.63.98.115:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/user.php"] [unique_id "amuIHMDCZkc4BvDXnoDE1AAAAAw"]
[Thu Jul 30 12:21:32.821702 2026] [security2:error] [pid 727775:tid 727992] [client 20.203.148.31:48222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/appreciators.php"] [unique_id "amuIHMDCZkc4BvDXnoDE1QAAAFc"]
[Thu Jul 30 12:21:33.211380 2026] [security2:error] [pid 727775:tid 727948] [client 142.93.53.183:61412] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ERENUSE/Erencgiapi/perl.Eren"] [unique_id "amuIHcDCZkc4BvDXnoDE4gAAACs"]
[Thu Jul 30 12:21:33.247475 2026] [security2:error] [pid 727775:tid 727997] [client 143.244.57.86:55608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuIHMDCZkc4BvDXnoDE2wAAAFw"]
[Thu Jul 30 12:21:33.487428 2026] [security2:error] [pid 727775:tid 727911] [client 104.238.222.26:62027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuIHcDCZkc4BvDXnoDE5wAAAAY"]
[Thu Jul 30 12:21:33.594085 2026] [security2:error] [pid 727775:tid 728021] [client 142.93.53.183:61474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/lib/pkp/lib/vendor/voku/portable-ascii/src/voku/helper/data/ERENUSE/Erencgiapi/perl.Eren"] [unique_id "amuIHcDCZkc4BvDXnoDE6AAAAHQ"]
[Thu Jul 30 12:21:33.961143 2026] [security2:error] [pid 727775:tid 727963] [client 143.244.57.86:55612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuIHcDCZkc4BvDXnoDE8AAAADo"]
[Thu Jul 30 12:21:33.968364 2026] [security2:error] [pid 727775:tid 727925] [client 142.93.53.183:61548] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIHcDCZkc4BvDXnoDE8QAAABQ"]
[Thu Jul 30 12:21:34.196519 2026] [security2:error] [pid 727775:tid 727987] [client 20.203.148.31:36594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/archive.php"] [unique_id "amuIHsDCZkc4BvDXnoDE9wAAAFI"]
[Thu Jul 30 12:21:34.346157 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:61602] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIHsDCZkc4BvDXnoDE-AAAABE"]
[Thu Jul 30 12:21:34.507713 2026] [security2:error] [pid 727775:tid 728032] [client 143.244.57.86:55622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuIHsDCZkc4BvDXnoDE_AAAAH8"]
[Thu Jul 30 12:21:34.595516 2026] [security2:error] [pid 727775:tid 727975] [client 20.63.98.115:21423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "amuIHsDCZkc4BvDXnoDE_QAAAEY"]
[Thu Jul 30 12:21:34.723608 2026] [security2:error] [pid 727775:tid 728017] [client 142.93.53.183:61641] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIHsDCZkc4BvDXnoDFAAAAAHA"]
[Thu Jul 30 12:21:35.073956 2026] [security2:error] [pid 727775:tid 728010] [client 20.203.148.31:36521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/as.php"] [unique_id "amuIH8DCZkc4BvDXnoDFBQAAAGk"]
[Thu Jul 30 12:21:35.101475 2026] [security2:error] [pid 727775:tid 727933] [client 142.93.53.183:61677] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIH8DCZkc4BvDXnoDFBgAAABw"]
[Thu Jul 30 12:21:35.104121 2026] [security2:error] [pid 727775:tid 727930] [client 143.244.57.86:55630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuIH8DCZkc4BvDXnoDFBwAAABk"]
[Thu Jul 30 12:21:35.491764 2026] [security2:error] [pid 727775:tid 727917] [client 142.93.53.183:61737] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIH8DCZkc4BvDXnoDFDwAAAAw"]
[Thu Jul 30 12:21:35.696513 2026] [security2:error] [pid 727775:tid 728025] [client 143.244.57.86:55634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuIH8DCZkc4BvDXnoDFEAAAAHg"]
[Thu Jul 30 12:21:35.804415 2026] [core:error] [pid 727775:tid 727965] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:35.804447 2026] [core:error] [pid 727775:tid 727965] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:21:35.871264 2026] [security2:error] [pid 727775:tid 727966] [client 142.93.53.183:61801] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/cache/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIH8DCZkc4BvDXnoDFFwAAAD0"]
[Thu Jul 30 12:21:35.901832 2026] [security2:error] [pid 727775:tid 728002] [client 20.203.148.31:36545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/atomlib.php"] [unique_id "amuIH8DCZkc4BvDXnoDFGAAAAGE"]
[Thu Jul 30 12:21:36.256696 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:61860] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/wflogs/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIMDCZkc4BvDXnoDFIAAAAHE"]
[Thu Jul 30 12:21:36.298599 2026] [security2:error] [pid 727775:tid 727997] [client 143.244.57.86:55644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuIIMDCZkc4BvDXnoDFIwAAAFw"]
[Thu Jul 30 12:21:36.637763 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:61915] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/wpo-cache/ALFA_DATA/alfacgiapi/perl.alfa/"] [unique_id "amuIIMDCZkc4BvDXnoDFJwAAAHU"]
[Thu Jul 30 12:21:36.903173 2026] [security2:error] [pid 727775:tid 727939] [client 143.244.57.86:55656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuIIMDCZkc4BvDXnoDFLAAAACI"]
[Thu Jul 30 12:21:36.913833 2026] [security2:error] [pid 727775:tid 727944] [client 20.203.148.31:42861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/autoload_classmap.php"] [unique_id "amuIIMDCZkc4BvDXnoDFLQAAACc"]
[Thu Jul 30 12:21:37.020329 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:61979] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/wpo-cache/config/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIcDCZkc4BvDXnoDFLwAAABE"]
[Thu Jul 30 12:21:37.403331 2026] [security2:error] [pid 727775:tid 727924] [client 142.93.53.183:62039] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/updraft/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIcDCZkc4BvDXnoDFNwAAABM"]
[Thu Jul 30 12:21:37.442963 2026] [security2:error] [pid 727775:tid 727932] [client 20.63.98.115:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuIIcDCZkc4BvDXnoDFOAAAABs"]
[Thu Jul 30 12:21:37.498428 2026] [security2:error] [pid 727775:tid 727940] [client 143.244.57.86:54672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuIIcDCZkc4BvDXnoDFOQAAACM"]
[Thu Jul 30 12:21:37.602788 2026] [security2:error] [pid 727775:tid 727881] [remote 216.73.216.152:63752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIIcDCZkc4BvDXnoDFOgAAP2k"]
[Thu Jul 30 12:21:37.776401 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:62100] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/mu-plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIcDCZkc4BvDXnoDFPgAAABY"]
[Thu Jul 30 12:21:38.104002 2026] [security2:error] [pid 727775:tid 727918] [client 143.244.57.86:54684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuIIsDCZkc4BvDXnoDFQgAAAA0"]
[Thu Jul 30 12:21:38.150300 2026] [security2:error] [pid 727775:tid 727985] [client 142.93.53.183:62158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/backups-dup-lite/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIsDCZkc4BvDXnoDFRgAAAFA"]
[Thu Jul 30 12:21:38.538633 2026] [security2:error] [pid 727775:tid 727988] [client 142.93.53.183:62221] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/backups-dup-lite/tmp/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIIsDCZkc4BvDXnoDFTAAAAFM"]
[Thu Jul 30 12:21:38.695902 2026] [security2:error] [pid 727775:tid 727957] [client 143.244.57.86:54696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuIIsDCZkc4BvDXnoDFUAAAADQ"]
[Thu Jul 30 12:21:38.787101 2026] [security2:error] [pid 727775:tid 727991] [client 20.203.148.31:35818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/bb.php"] [unique_id "amuIIsDCZkc4BvDXnoDFUQAAAFY"]
[Thu Jul 30 12:21:38.919946 2026] [security2:error] [pid 727775:tid 728020] [client 142.93.53.183:62278] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/alfacgiapi/perl.alfa"] [unique_id "amuIIsDCZkc4BvDXnoDFVQAAAHM"]
[Thu Jul 30 12:21:38.952950 2026] [security2:error] [pid 727775:tid 727921] [client 114.119.145.110:52397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bisbeewalk.com"] [uri "/images/bisbee-postoffice-10112003.jpg"] [unique_id "amuIIsDCZkc4BvDXnoDFVgAAABA"], referer: http://www.bisbeewalk.com/Bisbee_panoramas_from_off_the_wall.htm
[Thu Jul 30 12:21:39.240489 2026] [core:notice] [pid 727775:tid 727997] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:21:39.303047 2026] [security2:error] [pid 727775:tid 728019] [client 142.93.53.183:62323] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/libraries/smartslider3/GODEST/zestcgiapi/py.zest"] [unique_id "amuII8DCZkc4BvDXnoDFWwAAAHI"]
[Thu Jul 30 12:21:39.306908 2026] [security2:error] [pid 727775:tid 727960] [client 143.244.57.86:54710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuII8DCZkc4BvDXnoDFXAAAADc"]
[Thu Jul 30 12:21:39.459903 2026] [security2:error] [pid 727775:tid 728012] [client 20.63.98.115:21221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/hehe.php"] [unique_id "amuII8DCZkc4BvDXnoDFYAAAAGs"]
[Thu Jul 30 12:21:39.694746 2026] [security2:error] [pid 727775:tid 727967] [client 142.93.53.183:62363] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/libraries/smartslider3/GODEST/zestcgiapi/perl.zest"] [unique_id "amuII8DCZkc4BvDXnoDFYwAAAD4"]
[Thu Jul 30 12:21:39.899623 2026] [security2:error] [pid 727775:tid 728011] [client 143.244.57.86:54714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuII8DCZkc4BvDXnoDFZwAAAGo"]
[Thu Jul 30 12:21:40.073012 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:62406] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/libraries/smartslider3/GODEST/zestcgiapi/bash.zest"] [unique_id "amuIJMDCZkc4BvDXnoDFawAAABE"]
[Thu Jul 30 12:21:40.319920 2026] [security2:error] [pid 727775:tid 727981] [client 20.203.148.31:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/bnm.php"] [unique_id "amuIJMDCZkc4BvDXnoDFbwAAAEw"]
[Thu Jul 30 12:21:40.455515 2026] [security2:error] [pid 727775:tid 727975] [client 142.93.53.183:62439] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.tmb/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIJMDCZkc4BvDXnoDFcAAAAEY"]
[Thu Jul 30 12:21:40.474138 2026] [security2:error] [pid 727775:tid 727941] [client 20.63.98.115:21426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/webadmin.php"] [unique_id "amuIJMDCZkc4BvDXnoDFcgAAACQ"]
[Thu Jul 30 12:21:40.497197 2026] [security2:error] [pid 727775:tid 727949] [client 143.244.57.86:54716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuIJMDCZkc4BvDXnoDFeAAAACw"]
[Thu Jul 30 12:21:40.715343 2026] [security2:error] [pid 727775:tid 727782] [remote 74.7.241.59:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuIJMDCZkc4BvDXnoDFeQAAIQY"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates
[Thu Jul 30 12:21:40.850898 2026] [security2:error] [pid 727775:tid 727993] [client 142.93.53.183:62486] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIJMDCZkc4BvDXnoDFfQAAAFg"]
[Thu Jul 30 12:21:41.102433 2026] [security2:error] [pid 727775:tid 727933] [client 143.244.57.86:54728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuIJcDCZkc4BvDXnoDFgQAAABw"]
[Thu Jul 30 12:21:41.239298 2026] [security2:error] [pid 727775:tid 727969] [client 142.93.53.183:62536] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/acme-challenge/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIJcDCZkc4BvDXnoDFggAAAEA"]
[Thu Jul 30 12:21:41.601664 2026] [security2:error] [pid 727775:tid 727985] [client 20.63.98.115:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/backup.php"] [unique_id "amuIJcDCZkc4BvDXnoDFiQAAAFA"]
[Thu Jul 30 12:21:41.614175 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:62576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/pki-validation/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIJcDCZkc4BvDXnoDFigAAAG0"]
[Thu Jul 30 12:21:41.666357 2026] [security2:error] [pid 727775:tid 727989] [client 143.244.57.86:54744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuIJcDCZkc4BvDXnoDFiwAAAFQ"]
[Thu Jul 30 12:21:41.703340 2026] [security2:error] [pid 727775:tid 727917] [client 20.203.148.31:37101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/bootstrap.php"] [unique_id "amuIJcDCZkc4BvDXnoDFjAAAAAw"]
[Thu Jul 30 12:21:41.991876 2026] [security2:error] [pid 727775:tid 727953] [client 142.93.53.183:62611] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/word/alfacgiapi/perl.alfa"] [unique_id "amuIJcDCZkc4BvDXnoDFkAAAADA"]
[Thu Jul 30 12:21:42.293871 2026] [security2:error] [pid 727775:tid 727996] [client 143.244.57.86:54756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuIJsDCZkc4BvDXnoDFlwAAAFs"]
[Thu Jul 30 12:21:42.382190 2026] [security2:error] [pid 727775:tid 727986] [client 142.93.53.183:62654] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/word/alfacgiapi/py.alfa"] [unique_id "amuIJsDCZkc4BvDXnoDFnAAAAFE"]
[Thu Jul 30 12:21:42.756512 2026] [security2:error] [pid 727775:tid 727984] [client 142.93.53.183:62693] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/word/alfacgiapi/bash.alfa"] [unique_id "amuIJsDCZkc4BvDXnoDFpAAAAE8"]
[Thu Jul 30 12:21:43.137808 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:62730] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dist/editor/ckfinder/core/connector/RIMURU/rimurucgiapi/perl.rimuru"] [unique_id "amuIJ8DCZkc4BvDXnoDFqQAAAHU"]
[Thu Jul 30 12:21:43.296604 2026] [security2:error] [pid 727775:tid 727783] [remote 216.73.216.152:14669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIJ8DCZkc4BvDXnoDFrQAAagc"]
[Thu Jul 30 12:21:43.343072 2026] [security2:error] [pid 727775:tid 728027] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIJsDCZkc4BvDXnoDFowAAAHo"]
[Thu Jul 30 12:21:43.381009 2026] [security2:error] [pid 727775:tid 728016] [client 127.0.0.1:20600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIJ8DCZkc4BvDXnoDFsAAAAG8"]
[Thu Jul 30 12:21:43.381064 2026] [security2:error] [pid 727775:tid 727922] [client 127.0.0.1:20592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tgv.gzj.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIJ8DCZkc4BvDXnoDFrwAAABE"]
[Thu Jul 30 12:21:43.381177 2026] [security2:error] [pid 727775:tid 728001] [client 74.7.175.187:51048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tgv.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuIJ8DCZkc4BvDXnoDFrgAAYAQ"]
[Thu Jul 30 12:21:43.524615 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:62781] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dist/editor/ckfinder/core/connector/RIMURU/rimurucgiapi/py.rimuru"] [unique_id "amuIJ8DCZkc4BvDXnoDFtAAAAB8"]
[Thu Jul 30 12:21:43.903809 2026] [security2:error] [pid 727775:tid 727935] [client 142.93.53.183:62837] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dist/editor/ckfinder/core/connector/RIMURU/rimurucgiapi/bash.rimuru"] [unique_id "amuIJ8DCZkc4BvDXnoDFuAAAAB4"]
[Thu Jul 30 12:21:44.281018 2026] [security2:error] [pid 727775:tid 727929] [client 142.93.53.183:62886] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIKMDCZkc4BvDXnoDFxQAAABg"]
[Thu Jul 30 12:21:44.660817 2026] [security2:error] [pid 727775:tid 727945] [client 142.93.53.183:62943] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIKMDCZkc4BvDXnoDFyQAAACg"]
[Thu Jul 30 12:21:44.809378 2026] [security2:error] [pid 727775:tid 727913] [client 20.203.148.31:44914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/buy.php"] [unique_id "amuIKMDCZkc4BvDXnoDFzQAAAAg"]
[Thu Jul 30 12:21:44.938216 2026] [security2:error] [pid 727775:tid 727802] [remote 57.141.0.53:33646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/73667776610/feed/rss2/"] [unique_id "amuIKMDCZkc4BvDXnoDFzwAAJho"]
[Thu Jul 30 12:21:45.037914 2026] [security2:error] [pid 727775:tid 727980] [client 142.93.53.183:62995] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuIKcDCZkc4BvDXnoDF1AAAAEs"]
[Thu Jul 30 12:21:45.305812 2026] [security2:error] [pid 727775:tid 727914] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIKMDCZkc4BvDXnoDF0AAAAAk"]
[Thu Jul 30 12:21:45.417471 2026] [security2:error] [pid 727775:tid 727973] [client 142.93.53.183:63049] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuIKcDCZkc4BvDXnoDF2QAAAEQ"]
[Thu Jul 30 12:21:45.515806 2026] [security2:error] [pid 727775:tid 727915] [client 20.203.148.31:36471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/chosen.php"] [unique_id "amuIKcDCZkc4BvDXnoDF3QAAAAo"]
[Thu Jul 30 12:21:45.801570 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:63103] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuIKcDCZkc4BvDXnoDF4gAAACc"]
[Thu Jul 30 12:21:45.951380 2026] [security2:error] [pid 727775:tid 728007] [client 20.63.98.115:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/atomlib.php"] [unique_id "amuIKcDCZkc4BvDXnoDF5AAAAGY"]
[Thu Jul 30 12:21:46.022699 2026] [security2:error] [pid 727775:tid 727939] [client 20.203.148.31:43123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/class-wp-image.php"] [unique_id "amuIKsDCZkc4BvDXnoDF6AAAACI"]
[Thu Jul 30 12:21:46.180180 2026] [security2:error] [pid 727775:tid 727983] [client 142.93.53.183:63144] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuIKsDCZkc4BvDXnoDF6QAAAE4"]
[Thu Jul 30 12:21:46.559385 2026] [security2:error] [pid 727775:tid 728017] [client 142.93.53.183:63193] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIKsDCZkc4BvDXnoDF9AAAAHA"]
[Thu Jul 30 12:21:46.581224 2026] [security2:error] [pid 727775:tid 727981] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIKsDCZkc4BvDXnoDF6gAAAEw"]
[Thu Jul 30 12:21:46.791649 2026] [security2:error] [pid 727775:tid 728028] [client 20.63.98.115:61393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/epinyins.php"] [unique_id "amuIKsDCZkc4BvDXnoDF9QAAAHs"]
[Thu Jul 30 12:21:46.939756 2026] [security2:error] [pid 727775:tid 727930] [client 142.93.53.183:63229] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIKsDCZkc4BvDXnoDF-QAAABk"]
[Thu Jul 30 12:21:47.299071 2026] [security2:error] [pid 727775:tid 727972] [client 20.203.148.31:44921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/classsmtps.php"] [unique_id "amuIK8DCZkc4BvDXnoDF_gAAAEM"]
[Thu Jul 30 12:21:47.314587 2026] [security2:error] [pid 727775:tid 728013] [client 142.93.53.183:63274] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIK8DCZkc4BvDXnoDF_wAAAGw"]
[Thu Jul 30 12:21:47.531265 2026] [security2:error] [pid 727775:tid 727916] [client 20.40.58.237:63611] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuIK8DCZkc4BvDXnoDGBAAAAAs"]
[Thu Jul 30 12:21:47.695403 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:63313] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIK8DCZkc4BvDXnoDGCAAAADw"]
[Thu Jul 30 12:21:47.836729 2026] [security2:error] [pid 727775:tid 727979] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIK8DCZkc4BvDXnoDGAwAAAEo"]
[Thu Jul 30 12:21:48.026856 2026] [security2:error] [pid 727775:tid 728002] [client 20.63.98.115:58057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuILMDCZkc4BvDXnoDGDAAAAGE"]
[Thu Jul 30 12:21:48.084013 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:63373] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/dist/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuILMDCZkc4BvDXnoDGDQAAAFY"]
[Thu Jul 30 12:21:48.463427 2026] [security2:error] [pid 727775:tid 727948] [client 142.93.53.183:63430] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/dist/css/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuILMDCZkc4BvDXnoDGFAAAACs"]
[Thu Jul 30 12:21:48.750036 2026] [security2:error] [pid 727775:tid 727926] [client 20.203.148.31:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/classwithtostring.php"] [unique_id "amuILMDCZkc4BvDXnoDGHAAAABU"]
[Thu Jul 30 12:21:48.846194 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:63474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/dist/css/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuILMDCZkc4BvDXnoDGHQAAADo"]
[Thu Jul 30 12:21:48.972173 2026] [security2:error] [pid 727775:tid 727986] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuILMDCZkc4BvDXnoDGGAAAAFE"]
[Thu Jul 30 12:21:49.010154 2026] [security2:error] [pid 727775:tid 727918] [client 20.40.58.237:63687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuILcDCZkc4BvDXnoDGIQAAAA0"]
[Thu Jul 30 12:21:49.237124 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:63512] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuILcDCZkc4BvDXnoDGJgAAAGo"]
[Thu Jul 30 12:21:49.616944 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:63554] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuILcDCZkc4BvDXnoDGLAAAAGA"]
[Thu Jul 30 12:21:49.936290 2026] [security2:error] [pid 727775:tid 727922] [client 43.248.108.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuILcDCZkc4BvDXnoDGKwAAETY"]
[Thu Jul 30 12:21:50.002505 2026] [security2:error] [pid 727775:tid 727931] [client 142.93.53.183:63596] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/help/en_US/bibliography/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuILsDCZkc4BvDXnoDGMQAAABo"]
[Thu Jul 30 12:21:50.395373 2026] [security2:error] [pid 727775:tid 728028] [client 142.93.53.183:63641] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/default/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuILsDCZkc4BvDXnoDGOAAAAHs"]
[Thu Jul 30 12:21:50.406605 2026] [proxy:error] [pid 727775:tid 727821] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:50.406668 2026] [proxy_http:error] [pid 727775:tid 727821] [remote 74.7.175.185:54946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:50.407306 2026] [proxy:error] [pid 727775:tid 727821] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:50.407358 2026] [proxy_http:error] [pid 727775:tid 727821] [remote 74.7.175.185:54946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:50.782867 2026] [security2:error] [pid 727775:tid 728010] [client 142.93.53.183:63683] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/.../LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuILsDCZkc4BvDXnoDGQQAAAGk"]
[Thu Jul 30 12:21:50.930840 2026] [security2:error] [pid 727775:tid 727962] [client 184.75.223.195:58610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuILsDCZkc4BvDXnoDGQgAAADk"]
[Thu Jul 30 12:21:50.930942 2026] [security2:error] [pid 727775:tid 727962] [client 184.75.223.195:58610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuILsDCZkc4BvDXnoDGQgAAADk"]
[Thu Jul 30 12:21:51.159555 2026] [security2:error] [pid 727775:tid 727945] [client 142.93.53.183:63718] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/help/en_US/bibliography/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIL8DCZkc4BvDXnoDGRgAAACg"]
[Thu Jul 30 12:21:51.471652 2026] [security2:error] [pid 727775:tid 727976] [client 130.49.115.193:55959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "raad.pk"] [uri "/xmlrpc.php"] [unique_id "amuIL8DCZkc4BvDXnoDGRwAARzU"]
[Thu Jul 30 12:21:51.540067 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:63755] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/default/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIL8DCZkc4BvDXnoDGTAAAAGE"]
[Thu Jul 30 12:21:51.919576 2026] [security2:error] [pid 727775:tid 727997] [client 142.93.53.183:63800] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/.../LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuIL8DCZkc4BvDXnoDGVAAAAFw"]
[Thu Jul 30 12:21:52.108366 2026] [proxy:error] [pid 727775:tid 727910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:52.108438 2026] [proxy_http:error] [pid 727775:tid 727910] [client 74.7.241.135:49764] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:52.109750 2026] [proxy:error] [pid 727775:tid 727910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:21:52.109805 2026] [proxy_http:error] [pid 727775:tid 727910] [client 74.7.241.135:49764] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:21:52.109991 2026] [security2:error] [pid 727775:tid 727910] [client 74.7.241.135:49764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.asd.fyv.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuIMMDCZkc4BvDXnoDGWAAAAAU"]
[Thu Jul 30 12:21:52.315969 2026] [security2:error] [pid 727775:tid 727995] [client 142.93.53.183:63853] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/help/en_US/bibliography/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIMMDCZkc4BvDXnoDGXQAAAFo"]
[Thu Jul 30 12:21:52.583196 2026] [security2:error] [pid 727775:tid 728022] [client 195.113.175.167:38641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/stafff.php"] [unique_id "amuIMMDCZkc4BvDXnoDGYQAAAHU"]
[Thu Jul 30 12:21:52.723678 2026] [security2:error] [pid 727775:tid 727958] [client 142.93.53.183:63905] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/default/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIMMDCZkc4BvDXnoDGZQAAADU"]
[Thu Jul 30 12:21:53.098623 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:63954] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/.../LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuIMcDCZkc4BvDXnoDGawAAAGA"]
[Thu Jul 30 12:21:53.446379 2026] [security2:error] [pid 727775:tid 727998] [client 20.203.148.31:43076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/config.php"] [unique_id "amuIMcDCZkc4BvDXnoDGcwAAAF0"]
[Thu Jul 30 12:21:53.471880 2026] [security2:error] [pid 727775:tid 727946] [client 142.93.53.183:64003] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cgi-bin/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIMcDCZkc4BvDXnoDGdAAAACk"]
[Thu Jul 30 12:21:53.768616 2026] [lsapi:error] [pid 703393:tid 703432] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/captain-america-brave-new-world-vj-junior/
[Thu Jul 30 12:21:53.862237 2026] [security2:error] [pid 727775:tid 727969] [client 142.93.53.183:64053] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/image/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIMcDCZkc4BvDXnoDGgQAAAEA"]
[Thu Jul 30 12:21:53.996963 2026] [security2:error] [pid 727775:tid 727870] [remote 51.89.129.221:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "filmtvyap.com"] [uri "/newsletter/"] [unique_id "amuIMcDCZkc4BvDXnoDGhAAAbF4"]
[Thu Jul 30 12:21:53.997215 2026] [security2:error] [pid 727775:tid 728013] [client 51.89.129.221:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "filmtvyap.com"] [uri "/newsletter/"] [unique_id "amuIMcDCZkc4BvDXnoDGhAAAbF4"]
[Thu Jul 30 12:21:54.119277 2026] [security2:error] [pid 727775:tid 727981] [client 130.49.115.193:50535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "raad.pk"] [uri "/xmlrpc.php"] [unique_id "amuIMcDCZkc4BvDXnoDGgwAATEw"]
[Thu Jul 30 12:21:54.250289 2026] [security2:error] [pid 727775:tid 727979] [client 142.93.53.183:64098] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIMsDCZkc4BvDXnoDGiAAAAEo"]
[Thu Jul 30 12:21:54.608357 2026] [security2:error] [pid 727775:tid 727929] [client 38.190.144.4:51822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIMsDCZkc4BvDXnoDGjAAAABg"]
[Thu Jul 30 12:21:54.608571 2026] [security2:error] [pid 727775:tid 727929] [client 38.190.144.4:51822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIMsDCZkc4BvDXnoDGjAAAABg"]
[Thu Jul 30 12:21:54.632148 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:64153] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIMsDCZkc4BvDXnoDGjQAAAGE"]
[Thu Jul 30 12:21:55.017196 2026] [security2:error] [pid 727775:tid 727973] [client 142.93.53.183:64204] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIM8DCZkc4BvDXnoDGmAAAAEQ"]
[Thu Jul 30 12:21:55.409559 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:64254] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pub/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIM8DCZkc4BvDXnoDGnwAAAGo"]
[Thu Jul 30 12:21:55.786664 2026] [security2:error] [pid 727775:tid 728032] [client 142.93.53.183:64306] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIM8DCZkc4BvDXnoDGpwAAAH8"]
[Thu Jul 30 12:21:56.016735 2026] [security2:error] [pid 727775:tid 727953] [client 20.203.148.31:44906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/core.php"] [unique_id "amuINMDCZkc4BvDXnoDGqwAAADA"]
[Thu Jul 30 12:21:56.167117 2026] [security2:error] [pid 727775:tid 727970] [client 142.93.53.183:64348] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/js/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINMDCZkc4BvDXnoDGrAAAAEE"]
[Thu Jul 30 12:21:56.544955 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:64398] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINMDCZkc4BvDXnoDGswAAAC8"]
[Thu Jul 30 12:21:56.922911 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:64447] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINMDCZkc4BvDXnoDGtwAAABY"]
[Thu Jul 30 12:21:57.297183 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:64498] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wordpress/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINcDCZkc4BvDXnoDGvQAAAFc"]
[Thu Jul 30 12:21:57.676465 2026] [security2:error] [pid 727775:tid 727979] [client 142.93.53.183:64547] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blog/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINcDCZkc4BvDXnoDGxQAAAEo"]
[Thu Jul 30 12:21:57.877383 2026] [security2:error] [pid 727775:tid 727935] [client 20.203.148.31:44907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/css.php"] [unique_id "amuINcDCZkc4BvDXnoDGyQAAAB4"]
[Thu Jul 30 12:21:58.060919 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:64598] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINsDCZkc4BvDXnoDGzgAAAFY"]
[Thu Jul 30 12:21:58.451747 2026] [security2:error] [pid 727775:tid 728019] [client 142.93.53.183:64651] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINsDCZkc4BvDXnoDG0wAAAHI"]
[Thu Jul 30 12:21:58.581586 2026] [security2:error] [pid 727775:tid 727874] [remote 57.141.0.42:27176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuINsDCZkc4BvDXnoDG1QAAdmI"]
[Thu Jul 30 12:21:58.831138 2026] [security2:error] [pid 727775:tid 728006] [client 142.93.53.183:64703] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/beez3/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuINsDCZkc4BvDXnoDG3wAAAGU"]
[Thu Jul 30 12:21:59.139970 2026] [security2:error] [pid 727775:tid 727950] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuINsDCZkc4BvDXnoDG1AAALVg"]
[Thu Jul 30 12:21:59.222161 2026] [security2:error] [pid 727775:tid 727923] [client 142.93.53.183:64755] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/administrator/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIN8DCZkc4BvDXnoDG5QAAABI"]
[Thu Jul 30 12:21:59.281257 2026] [security2:error] [pid 727775:tid 728000] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuINsDCZkc4BvDXnoDG2AAAAF8"]
[Thu Jul 30 12:21:59.610961 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:64818] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.tmb/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIN8DCZkc4BvDXnoDG6QAAAGA"]
[Thu Jul 30 12:21:59.890027 2026] [security2:error] [pid 727775:tid 727938] [client 82.21.185.32:51068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG7QAAACE"]
[Thu Jul 30 12:21:59.943946 2026] [security2:error] [pid 727775:tid 727937] [client 82.21.185.32:51061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG8gAAACA"]
[Thu Jul 30 12:21:59.974107 2026] [security2:error] [pid 727775:tid 728026] [client 82.21.185.32:51060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG8wAAAHk"]
[Thu Jul 30 12:21:59.984965 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:64887] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIN8DCZkc4BvDXnoDG9AAAAC8"]
[Thu Jul 30 12:22:00.038147 2026] [security2:error] [pid 727775:tid 727970] [client 82.21.185.32:51064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG9QAAAEE"]
[Thu Jul 30 12:22:00.043598 2026] [security2:error] [pid 727775:tid 727907] [client 82.21.185.32:51063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIN8DCZkc4BvDXnoDG9gAAAAI"]
[Thu Jul 30 12:22:00.059466 2026] [security2:error] [pid 727775:tid 727959] [client 82.21.185.32:51062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG9wAAADY"]
[Thu Jul 30 12:22:00.110424 2026] [security2:error] [pid 727775:tid 727946] [client 82.21.185.32:51067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG-QAAACk"]
[Thu Jul 30 12:22:00.124402 2026] [security2:error] [pid 727775:tid 728017] [client 82.21.185.32:51066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG-gAAAHA"]
[Thu Jul 30 12:22:00.154596 2026] [security2:error] [pid 727775:tid 727998] [client 82.21.185.32:51065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG-wAAAF0"]
[Thu Jul 30 12:22:00.210280 2026] [security2:error] [pid 727775:tid 727942] [client 82.21.185.32:51069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDG_QAAACU"]
[Thu Jul 30 12:22:00.363947 2026] [security2:error] [pid 727775:tid 728030] [client 142.93.53.183:64958] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dashboard/images/bitnami-xampp/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuIOMDCZkc4BvDXnoDHCgAAAH0"]
[Thu Jul 30 12:22:00.570972 2026] [security2:error] [pid 727775:tid 727971] [client 82.21.185.32:51070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIOMDCZkc4BvDXnoDHDAAAAEI"]
[Thu Jul 30 12:22:00.743368 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:65014] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dashboard/images/bitnami-xampp/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuIOMDCZkc4BvDXnoDHDQAAADw"]
[Thu Jul 30 12:22:01.051079 2026] [core:notice] [pid 727775:tid 727861] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:01.126193 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:65069] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dashboard/images/bitnami-xampp/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuIOcDCZkc4BvDXnoDHFgAAAHE"]
[Thu Jul 30 12:22:01.507474 2026] [security2:error] [pid 727775:tid 727925] [client 142.93.53.183:65134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/GODEST/zestcgiapi/perl.zest"] [unique_id "amuIOcDCZkc4BvDXnoDHHwAAABQ"]
[Thu Jul 30 12:22:01.898174 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:65195] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/GODEST/zestcgiapi/py.zest"] [unique_id "amuIOcDCZkc4BvDXnoDHIwAAAC0"]
[Thu Jul 30 12:22:02.286811 2026] [security2:error] [pid 727775:tid 728000] [client 142.93.53.183:65262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/GODEST/zestcgiapi/bash.zest"] [unique_id "amuIOsDCZkc4BvDXnoDHKQAAAF8"]
[Thu Jul 30 12:22:02.332331 2026] [security2:error] [pid 727775:tid 727960] [client 20.203.148.31:43833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/database.php"] [unique_id "amuIOsDCZkc4BvDXnoDHKgAAADc"]
[Thu Jul 30 12:22:02.340016 2026] [security2:error] [pid 727775:tid 727920] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIOcDCZkc4BvDXnoDHJAAAAA8"]
[Thu Jul 30 12:22:02.623595 2026] [autoindex:error] [pid 727775:tid 727934] [client 34.195.23.187:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:02.676716 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:65316] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/acme-challenge/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIOsDCZkc4BvDXnoDHNQAAABE"]
[Thu Jul 30 12:22:03.065297 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:65373] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/pki-validation/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIO8DCZkc4BvDXnoDHPAAAAC8"]
[Thu Jul 30 12:22:03.400950 2026] [autoindex:error] [pid 727775:tid 727933] [client 34.195.23.187:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:03.438128 2026] [security2:error] [pid 727775:tid 727956] [client 142.93.53.183:65427] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/js/tinymce/ONIC_ESPORT/haxorcgiapi/perl.haxor"] [unique_id "amuIO8DCZkc4BvDXnoDHRgAAADM"]
[Thu Jul 30 12:22:03.543012 2026] [security2:error] [pid 727775:tid 727942] [client 20.203.148.31:43597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/db.php"] [unique_id "amuIO8DCZkc4BvDXnoDHRwAAACU"]
[Thu Jul 30 12:22:03.652083 2026] [security2:error] [pid 727775:tid 728008] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIO8DCZkc4BvDXnoDHQAAAAGc"]
[Thu Jul 30 12:22:03.814110 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:65481] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/admin/js/tinymce/ONIC_ESPORT/haxorcgiapi/perl.haxor"] [unique_id "amuIO8DCZkc4BvDXnoDHTgAAAG0"]
[Thu Jul 30 12:22:03.916586 2026] [security2:error] [pid 727775:tid 727940] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIO8DCZkc4BvDXnoDHQQAAI3k"]
[Thu Jul 30 12:22:04.187427 2026] [security2:error] [pid 727775:tid 728009] [client 142.93.53.183:49155] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cgi-bin/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIPMDCZkc4BvDXnoDHVQAAAGg"]
[Thu Jul 30 12:22:04.578395 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:49215] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPMDCZkc4BvDXnoDHWgAAACY"]
[Thu Jul 30 12:22:04.687778 2026] [core:notice] [pid 727775:tid 727965] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:04.868693 2026] [security2:error] [pid 727775:tid 728019] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIPMDCZkc4BvDXnoDHWQAAAHI"]
[Thu Jul 30 12:22:04.971955 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:49270] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.tmb/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPMDCZkc4BvDXnoDHYgAAAA0"]
[Thu Jul 30 12:22:05.344894 2026] [security2:error] [pid 727775:tid 728031] [client 142.93.53.183:49322] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ijosi/files/contexts/1/library/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPcDCZkc4BvDXnoDHbgAAAH4"]
[Thu Jul 30 12:22:05.722698 2026] [security2:error] [pid 727775:tid 727934] [client 142.93.53.183:49381] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ijosi/files/contexts/1/library/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuIPcDCZkc4BvDXnoDHtQAAAB0"]
[Thu Jul 30 12:22:05.888868 2026] [security2:error] [pid 727775:tid 728003] [client 20.203.148.31:43600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/default.php"] [unique_id "amuIPcDCZkc4BvDXnoDHtwAAAGI"]
[Thu Jul 30 12:22:06.112298 2026] [security2:error] [pid 727775:tid 727975] [client 142.93.53.183:49436] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ijosi/files/contexts/1/library/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuIPsDCZkc4BvDXnoDHuwAAAEY"]
[Thu Jul 30 12:22:06.493800 2026] [security2:error] [pid 727775:tid 727930] [client 142.93.53.183:49494] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPsDCZkc4BvDXnoDHvwAAABk"]
[Thu Jul 30 12:22:06.871304 2026] [security2:error] [pid 727775:tid 727941] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIPsDCZkc4BvDXnoDHwwAAACQ"]
[Thu Jul 30 12:22:06.874101 2026] [security2:error] [pid 727775:tid 727962] [client 142.93.53.183:49551] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/acme-challenge/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIPsDCZkc4BvDXnoDHxwAAADk"]
[Thu Jul 30 12:22:07.250106 2026] [security2:error] [pid 727775:tid 727919] [client 142.93.53.183:49617] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/pki-validation/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIP8DCZkc4BvDXnoDHzwAAAA4"]
[Thu Jul 30 12:22:07.645342 2026] [security2:error] [pid 727775:tid 727905] [client 142.93.53.183:49680] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cgi-bin/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIP8DCZkc4BvDXnoDH1QAAAAA"]
[Thu Jul 30 12:22:08.034576 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:49745] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/image/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQMDCZkc4BvDXnoDH2QAAADw"]
[Thu Jul 30 12:22:08.191646 2026] [core:notice] [pid 727775:tid 727996] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:08.404601 2026] [security2:error] [pid 727775:tid 728018] [client 38.190.144.4:6929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIQMDCZkc4BvDXnoDH4wAAAHE"]
[Thu Jul 30 12:22:08.404723 2026] [security2:error] [pid 727775:tid 728018] [client 38.190.144.4:6929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIQMDCZkc4BvDXnoDH4wAAAHE"]
[Thu Jul 30 12:22:08.426395 2026] [security2:error] [pid 727775:tid 727960] [client 142.93.53.183:49838] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQMDCZkc4BvDXnoDH5AAAADc"]
[Thu Jul 30 12:22:08.622483 2026] [security2:error] [pid 727775:tid 727968] [client 20.203.148.31:42555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/dropdown.php"] [unique_id "amuIQMDCZkc4BvDXnoDH5QAAAD8"]
[Thu Jul 30 12:22:08.707056 2026] [security2:error] [pid 727775:tid 727909] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIQMDCZkc4BvDXnoDH4gAAAAQ"]
[Thu Jul 30 12:22:08.806292 2026] [security2:error] [pid 727775:tid 727920] [client 142.93.53.183:49933] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQMDCZkc4BvDXnoDH7AAAAA8"]
[Thu Jul 30 12:22:09.179970 2026] [security2:error] [pid 727775:tid 727995] [client 142.93.53.183:50025] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/zoro/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIQcDCZkc4BvDXnoDH8AAAAFo"]
[Thu Jul 30 12:22:09.438482 2026] [security2:error] [pid 727775:tid 727983] [client 44.192.50.231:42330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.northyorksheridanmall.com"] [uri "/"] [unique_id "amuIQcDCZkc4BvDXnoDH-QAAAE4"]
[Thu Jul 30 12:22:09.556308 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:50111] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/916c19cf/ui/minified/i18n/-/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIQcDCZkc4BvDXnoDH-gAAAB8"]
[Thu Jul 30 12:22:09.579938 2026] [security2:error] [pid 727775:tid 728000] [client 20.203.148.31:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/edit.php"] [unique_id "amuIQcDCZkc4BvDXnoDH-wAAAF8"]
[Thu Jul 30 12:22:09.940808 2026] [security2:error] [pid 727775:tid 727961] [client 142.93.53.183:50188] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/916c19cf/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIQcDCZkc4BvDXnoDIAwAAADg"]
[Thu Jul 30 12:22:10.331489 2026] [security2:error] [pid 727775:tid 727978] [client 142.93.53.183:50281] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/security/class/data/User/admin/recycle_kod/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIQsDCZkc4BvDXnoDICQAAAEk"]
[Thu Jul 30 12:22:10.477424 2026] [security2:error] [pid 727775:tid 727942] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIQsDCZkc4BvDXnoDIBQAAACU"]
[Thu Jul 30 12:22:10.717499 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:50381] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/tes/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQsDCZkc4BvDXnoDIDQAAACY"]
[Thu Jul 30 12:22:11.097825 2026] [security2:error] [pid 727775:tid 727986] [client 142.93.53.183:50497] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/berita/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQ8DCZkc4BvDXnoDIFAAAAFE"]
[Thu Jul 30 12:22:11.202555 2026] [security2:error] [pid 727775:tid 727966] [client 20.203.148.31:44565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/f35.php"] [unique_id "amuIQ8DCZkc4BvDXnoDIFgAAAD0"]
[Thu Jul 30 12:22:11.485728 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:50602] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/berita/LEVIATHAN/haxorcgiapi/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIQ8DCZkc4BvDXnoDIGgAAAG4"]
[Thu Jul 30 12:22:11.866394 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:50714] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIQ8DCZkc4BvDXnoDIJQAAAF4"]
[Thu Jul 30 12:22:11.985057 2026] [security2:error] [pid 727775:tid 727923] [client 127.0.0.1:34276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIQ8DCZkc4BvDXnoDIKAAAABI"]
[Thu Jul 30 12:22:11.985153 2026] [security2:error] [pid 727775:tid 728011] [client 74.7.228.3:44506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.guethleentertainment.com"] [uri "/robots.txt"] [unique_id "amuIQ8DCZkc4BvDXnoDIJwAAamY"]
[Thu Jul 30 12:22:12.114584 2026] [security2:error] [pid 727775:tid 728032] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIQ8DCZkc4BvDXnoDIHgAAAH8"]
[Thu Jul 30 12:22:12.169386 2026] [security2:error] [pid 727775:tid 728021] [client 51.116.238.8:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuIQ8DCZkc4BvDXnoDIJgAAAHQ"]
[Thu Jul 30 12:22:12.169542 2026] [security2:error] [pid 727775:tid 728021] [client 51.116.238.8:5058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuIQ8DCZkc4BvDXnoDIJgAAAHQ"]
[Thu Jul 30 12:22:12.247130 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:50797] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pub/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRMDCZkc4BvDXnoDILAAAAC8"]
[Thu Jul 30 12:22:12.615404 2026] [security2:error] [pid 727775:tid 727956] [client 51.116.238.8:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuIRMDCZkc4BvDXnoDIMwAAADM"]
[Thu Jul 30 12:22:12.615501 2026] [security2:error] [pid 727775:tid 727956] [client 51.116.238.8:5071] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuIRMDCZkc4BvDXnoDIMwAAADM"]
[Thu Jul 30 12:22:12.643385 2026] [security2:error] [pid 727775:tid 727961] [client 142.93.53.183:50876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRMDCZkc4BvDXnoDINQAAADg"]
[Thu Jul 30 12:22:12.788700 2026] [security2:error] [pid 727775:tid 728031] [client 20.203.148.31:43589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oceanscout.com"] [uri "/f7.php"] [unique_id "amuIRMDCZkc4BvDXnoDINgAAAH4"]
[Thu Jul 30 12:22:13.022908 2026] [security2:error] [pid 727775:tid 727981] [client 142.93.53.183:50959] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/js/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRcDCZkc4BvDXnoDIPAAAAEw"]
[Thu Jul 30 12:22:13.044516 2026] [security2:error] [pid 727775:tid 727978] [client 51.116.238.8:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuIRcDCZkc4BvDXnoDIPQAAAEk"]
[Thu Jul 30 12:22:13.044606 2026] [security2:error] [pid 727775:tid 727978] [client 51.116.238.8:5102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuIRcDCZkc4BvDXnoDIPQAAAEk"]
[Thu Jul 30 12:22:13.409204 2026] [security2:error] [pid 727775:tid 727994] [client 142.93.53.183:51044] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRcDCZkc4BvDXnoDIRAAAAFk"]
[Thu Jul 30 12:22:13.530882 2026] [security2:error] [pid 727775:tid 728002] [client 51.116.238.8:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/err.php"] [unique_id "amuIRcDCZkc4BvDXnoDIRgAAAGE"]
[Thu Jul 30 12:22:13.531004 2026] [security2:error] [pid 727775:tid 728002] [client 51.116.238.8:5091] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/err.php"] [unique_id "amuIRcDCZkc4BvDXnoDIRgAAAGE"]
[Thu Jul 30 12:22:13.797114 2026] [security2:error] [pid 727775:tid 728019] [client 142.93.53.183:51111] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRcDCZkc4BvDXnoDIUAAAAHI"]
[Thu Jul 30 12:22:13.860219 2026] [security2:error] [pid 727775:tid 727988] [client 123.245.84.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIRcDCZkc4BvDXnoDIRQAAAFM"]
[Thu Jul 30 12:22:14.171962 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:51180] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wordpress/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRsDCZkc4BvDXnoDIXAAAAD8"]
[Thu Jul 30 12:22:14.269946 2026] [security2:error] [pid 727775:tid 727944] [client 51.116.238.8:5003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/img.php"] [unique_id "amuIRsDCZkc4BvDXnoDIXQAAACc"]
[Thu Jul 30 12:22:14.270070 2026] [security2:error] [pid 727775:tid 727944] [client 51.116.238.8:5003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/img.php"] [unique_id "amuIRsDCZkc4BvDXnoDIXQAAACc"]
[Thu Jul 30 12:22:14.418072 2026] [core:error] [pid 727775:tid 727920] [client 74.7.244.16:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:22:14.418092 2026] [core:error] [pid 727775:tid 727920] [client 74.7.244.16:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:22:14.418243 2026] [security2:error] [pid 727775:tid 727920] [client 74.7.244.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuIRsDCZkc4BvDXnoDIYwAAAA8"]
[Thu Jul 30 12:22:14.418917 2026] [security2:error] [pid 727775:tid 728015] [client 74.7.244.16:51124] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuIRsDCZkc4BvDXnoDIXwAAbnI"]
[Thu Jul 30 12:22:14.551458 2026] [security2:error] [pid 727775:tid 727964] [client 142.93.53.183:51241] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blog/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRsDCZkc4BvDXnoDIZAAAADs"]
[Thu Jul 30 12:22:14.939573 2026] [security2:error] [pid 727775:tid 727924] [client 142.93.53.183:51313] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIRsDCZkc4BvDXnoDIaAAAABM"]
[Thu Jul 30 12:22:15.124766 2026] [security2:error] [pid 727775:tid 727983] [client 51.116.238.8:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/aa.php"] [unique_id "amuIR8DCZkc4BvDXnoDIbwAAAE4"]
[Thu Jul 30 12:22:15.124867 2026] [security2:error] [pid 727775:tid 727983] [client 51.116.238.8:5080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/aa.php"] [unique_id "amuIR8DCZkc4BvDXnoDIbwAAAE4"]
[Thu Jul 30 12:22:15.330999 2026] [security2:error] [pid 727775:tid 728028] [client 142.93.53.183:51376] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIR8DCZkc4BvDXnoDIcwAAAHs"]
[Thu Jul 30 12:22:15.724228 2026] [security2:error] [pid 727775:tid 727969] [client 142.93.53.183:51447] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/beez3/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuIR8DCZkc4BvDXnoDIewAAAEA"]
[Thu Jul 30 12:22:16.047124 2026] [security2:error] [pid 727775:tid 728008] [client 51.116.238.8:5014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/av.php"] [unique_id "amuISMDCZkc4BvDXnoDIfwAAAGc"]
[Thu Jul 30 12:22:16.047212 2026] [security2:error] [pid 727775:tid 728008] [client 51.116.238.8:5014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/av.php"] [unique_id "amuISMDCZkc4BvDXnoDIfwAAAGc"]
[Thu Jul 30 12:22:16.106258 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:51524] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/administrator/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuISMDCZkc4BvDXnoDIgAAAAG0"]
[Thu Jul 30 12:22:16.414544 2026] [security2:error] [pid 727775:tid 727979] [client 51.116.238.8:4992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xa.php"] [unique_id "amuISMDCZkc4BvDXnoDIhAAAAEo"]
[Thu Jul 30 12:22:16.414707 2026] [security2:error] [pid 727775:tid 727979] [client 51.116.238.8:4992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/xa.php"] [unique_id "amuISMDCZkc4BvDXnoDIhAAAAEo"]
[Thu Jul 30 12:22:16.488050 2026] [security2:error] [pid 727775:tid 727974] [client 142.93.53.183:51589] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/album/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuISMDCZkc4BvDXnoDIhQAAAEU"]
[Thu Jul 30 12:22:16.879814 2026] [security2:error] [pid 727775:tid 727911] [client 142.93.53.183:51674] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SASKRA/alfacgiapi/perl.alfa"] [unique_id "amuISMDCZkc4BvDXnoDIjAAAAAY"]
[Thu Jul 30 12:22:17.160397 2026] [security2:error] [pid 727775:tid 727921] [client 38.190.144.4:52797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIScDCZkc4BvDXnoDIkQAAABA"]
[Thu Jul 30 12:22:17.160527 2026] [security2:error] [pid 727775:tid 727921] [client 38.190.144.4:52797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIScDCZkc4BvDXnoDIkQAAABA"]
[Thu Jul 30 12:22:17.253555 2026] [security2:error] [pid 727775:tid 727996] [client 142.93.53.183:51766] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SASKRA/alfacgiapi/bash.alfa"] [unique_id "amuIScDCZkc4BvDXnoDIkgAAAFs"]
[Thu Jul 30 12:22:17.342068 2026] [security2:error] [pid 727775:tid 727966] [client 51.116.238.8:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/media.php"] [unique_id "amuIScDCZkc4BvDXnoDIlgAAAD0"]
[Thu Jul 30 12:22:17.342165 2026] [security2:error] [pid 727775:tid 727966] [client 51.116.238.8:5081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/media.php"] [unique_id "amuIScDCZkc4BvDXnoDIlgAAAD0"]
[Thu Jul 30 12:22:17.639522 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:51855] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SASKRA/alfacgiapi/py.alfa"] [unique_id "amuIScDCZkc4BvDXnoDInQAAAGY"]
[Thu Jul 30 12:22:17.925470 2026] [security2:error] [pid 727775:tid 727939] [client 51.116.238.8:5008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/images.php"] [unique_id "amuIScDCZkc4BvDXnoDIoQAAACI"]
[Thu Jul 30 12:22:17.925625 2026] [security2:error] [pid 727775:tid 727939] [client 51.116.238.8:5008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/images.php"] [unique_id "amuIScDCZkc4BvDXnoDIoQAAACI"]
[Thu Jul 30 12:22:18.034576 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:51918] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/SASKRA/alfacgiapi/perl.alfa"] [unique_id "amuISsDCZkc4BvDXnoDIogAAAF4"]
[Thu Jul 30 12:22:18.262127 2026] [security2:error] [pid 727775:tid 728021] [client 51.116.238.8:5006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/gecko.php"] [unique_id "amuISsDCZkc4BvDXnoDIpwAAAHQ"]
[Thu Jul 30 12:22:18.262248 2026] [security2:error] [pid 727775:tid 728021] [client 51.116.238.8:5006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/gecko.php"] [unique_id "amuISsDCZkc4BvDXnoDIpwAAAHQ"]
[Thu Jul 30 12:22:18.415823 2026] [security2:error] [pid 727775:tid 727983] [client 142.93.53.183:52013] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/SASKRA/alfacgiapi/py.alfa"] [unique_id "amuISsDCZkc4BvDXnoDIqwAAAE4"]
[Thu Jul 30 12:22:18.672601 2026] [security2:error] [pid 727775:tid 728017] [client 51.116.238.8:5000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/82.php"] [unique_id "amuISsDCZkc4BvDXnoDIsQAAAHA"]
[Thu Jul 30 12:22:18.672710 2026] [security2:error] [pid 727775:tid 728017] [client 51.116.238.8:5000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/82.php"] [unique_id "amuISsDCZkc4BvDXnoDIsQAAAHA"]
[Thu Jul 30 12:22:18.794738 2026] [security2:error] [pid 727775:tid 727990] [client 142.93.53.183:52098] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/SASKRA/alfacgiapi/bash.alfa"] [unique_id "amuISsDCZkc4BvDXnoDIuAAAAFU"]
[Thu Jul 30 12:22:19.128056 2026] [security2:error] [pid 727775:tid 728024] [client 51.116.238.8:5109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xstelth.php"] [unique_id "amuIS8DCZkc4BvDXnoDIvgAAAHc"]
[Thu Jul 30 12:22:19.128171 2026] [security2:error] [pid 727775:tid 728024] [client 51.116.238.8:5109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/xstelth.php"] [unique_id "amuIS8DCZkc4BvDXnoDIvgAAAHc"]
[Thu Jul 30 12:22:19.181531 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:52231] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1999_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIS8DCZkc4BvDXnoDIvwAAAGc"]
[Thu Jul 30 12:22:19.440059 2026] [security2:error] [pid 727775:tid 727957] [client 51.116.238.8:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xp.php"] [unique_id "amuIS8DCZkc4BvDXnoDIyAAAADQ"]
[Thu Jul 30 12:22:19.440168 2026] [security2:error] [pid 727775:tid 727957] [client 51.116.238.8:5067] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/xp.php"] [unique_id "amuIS8DCZkc4BvDXnoDIyAAAADQ"]
[Thu Jul 30 12:22:19.556195 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:52372] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1999_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIS8DCZkc4BvDXnoDIygAAAAg"]
[Thu Jul 30 12:22:19.771467 2026] [security2:error] [pid 727775:tid 727943] [client 51.116.238.8:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuIS8DCZkc4BvDXnoDIzwAAACY"]
[Thu Jul 30 12:22:19.771610 2026] [security2:error] [pid 727775:tid 727943] [client 51.116.238.8:5113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuIS8DCZkc4BvDXnoDIzwAAACY"]
[Thu Jul 30 12:22:19.936178 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:52493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1999_DATA/alfacgiapi/py.alfa"] [unique_id "amuIS8DCZkc4BvDXnoDI1AAAAHE"]
[Thu Jul 30 12:22:20.222051 2026] [security2:error] [pid 727775:tid 727966] [client 51.116.238.8:5114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/adminner.php"] [unique_id "amuITMDCZkc4BvDXnoDI1wAAAD0"]
[Thu Jul 30 12:22:20.222174 2026] [security2:error] [pid 727775:tid 727966] [client 51.116.238.8:5114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/adminner.php"] [unique_id "amuITMDCZkc4BvDXnoDI1wAAAD0"]
[Thu Jul 30 12:22:20.331760 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:52602] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/easing/1999_DATA/alfacgiapi/perl.alfa"] [unique_id "amuITMDCZkc4BvDXnoDI3AAAAA0"]
[Thu Jul 30 12:22:20.555857 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/a.php"] [unique_id "amuITMDCZkc4BvDXnoDI4wAAADs"]
[Thu Jul 30 12:22:20.555935 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/a.php"] [unique_id "amuITMDCZkc4BvDXnoDI4wAAADs"]
[Thu Jul 30 12:22:20.597319 2026] [core:error] [pid 727775:tid 727923] [client 74.7.175.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:22:20.597358 2026] [core:error] [pid 727775:tid 727923] [client 74.7.175.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:22:20.597506 2026] [security2:error] [pid 727775:tid 727923] [client 74.7.175.129:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.sharjahfurnituremoversandpackers.space"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuITMDCZkc4BvDXnoDI5gAAABI"]
[Thu Jul 30 12:22:20.598212 2026] [security2:error] [pid 727775:tid 727948] [client 74.7.175.129:46910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.sharjahfurnituremoversandpackers.space"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuITMDCZkc4BvDXnoDI5AAAKx0"]
[Thu Jul 30 12:22:20.712251 2026] [security2:error] [pid 727775:tid 727924] [client 142.93.53.183:52705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/easing/1999_DATA/alfacgiapi/bash.alfa"] [unique_id "amuITMDCZkc4BvDXnoDI6AAAABM"]
[Thu Jul 30 12:22:20.897895 2026] [security2:error] [pid 727775:tid 727932] [client 51.116.238.8:5007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/k.php"] [unique_id "amuITMDCZkc4BvDXnoDI7AAAABs"]
[Thu Jul 30 12:22:20.898030 2026] [security2:error] [pid 727775:tid 727932] [client 51.116.238.8:5007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/k.php"] [unique_id "amuITMDCZkc4BvDXnoDI7AAAABs"]
[Thu Jul 30 12:22:21.013035 2026] [security2:error] [pid 727775:tid 727920] [client 57.141.0.11:31160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuITMDCZkc4BvDXnoDI5wAADyE"], referer: https://igetvape-australia.com/store/?product-page=2&add-to-cart=137
[Thu Jul 30 12:22:21.021095 2026] [security2:error] [pid 727775:tid 727818] [remote 146.88.232.46:40549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.232.88.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lld.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuITcDCZkc4BvDXnoDI8AAAfyo"]
[Thu Jul 30 12:22:21.095518 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:52824] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/easing/1999_DATA/alfacgiapi/py.alfa"] [unique_id "amuITcDCZkc4BvDXnoDI8QAAACA"]
[Thu Jul 30 12:22:21.221405 2026] [security2:error] [pid 727775:tid 727998] [client 51.116.238.8:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/222.php"] [unique_id "amuITcDCZkc4BvDXnoDI8gAAAF0"]
[Thu Jul 30 12:22:21.221524 2026] [security2:error] [pid 727775:tid 727998] [client 51.116.238.8:5082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/222.php"] [unique_id "amuITcDCZkc4BvDXnoDI8gAAAF0"]
[Thu Jul 30 12:22:21.489132 2026] [security2:error] [pid 727775:tid 727941] [client 142.93.53.183:52925] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/RIMURU/rimurucgiapi/perl.rimuru"] [unique_id "amuITcDCZkc4BvDXnoDI9wAAACQ"]
[Thu Jul 30 12:22:21.687991 2026] [security2:error] [pid 727775:tid 727989] [client 51.116.238.8:5064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/mac.php"] [unique_id "amuITcDCZkc4BvDXnoDI_QAAAFQ"]
[Thu Jul 30 12:22:21.688099 2026] [security2:error] [pid 727775:tid 727989] [client 51.116.238.8:5064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/mac.php"] [unique_id "amuITcDCZkc4BvDXnoDI_QAAAFQ"]
[Thu Jul 30 12:22:21.705246 2026] [core:notice] [pid 727775:tid 728027] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:21.866925 2026] [security2:error] [pid 727775:tid 727919] [client 142.93.53.183:53004] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/RIMURU/rimurucgiapi/py.rimuru"] [unique_id "amuITcDCZkc4BvDXnoDJAwAAAA4"]
[Thu Jul 30 12:22:22.107548 2026] [security2:error] [pid 727775:tid 727905] [client 51.116.238.8:5017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "milfordauto.com"] [uri "/cgi-sys/404.html"] [unique_id "amuITsDCZkc4BvDXnoDJBwAAAAA"]
[Thu Jul 30 12:22:22.239873 2026] [security2:error] [pid 727775:tid 727957] [client 51.116.238.8:5017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "milfordauto.com"] [uri "/cgi-sys/404.html"] [unique_id "amuITsDCZkc4BvDXnoDJCAAAADQ"]
[Thu Jul 30 12:22:22.246415 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:53092] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/RIMURU/rimurucgiapi/bash.rimuru"] [unique_id "amuITsDCZkc4BvDXnoDJCQAAAAg"]
[Thu Jul 30 12:22:22.370235 2026] [security2:error] [pid 727775:tid 727980] [client 51.116.238.8:5017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ops.php"] [unique_id "amuITsDCZkc4BvDXnoDJDwAAAEs"]
[Thu Jul 30 12:22:22.370337 2026] [security2:error] [pid 727775:tid 727980] [client 51.116.238.8:5017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/ops.php"] [unique_id "amuITsDCZkc4BvDXnoDJDwAAAEs"]
[Thu Jul 30 12:22:22.627256 2026] [security2:error] [pid 727775:tid 728023] [client 142.93.53.183:53183] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/kkn/bimbingan/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuITsDCZkc4BvDXnoDJEwAAAHY"]
[Thu Jul 30 12:22:22.800603 2026] [security2:error] [pid 727775:tid 727914] [client 51.116.238.8:5092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/8.php"] [unique_id "amuITsDCZkc4BvDXnoDJFgAAAAk"]
[Thu Jul 30 12:22:22.800731 2026] [security2:error] [pid 727775:tid 727914] [client 51.116.238.8:5092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/8.php"] [unique_id "amuITsDCZkc4BvDXnoDJFgAAAAk"]
[Thu Jul 30 12:22:23.005327 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:53277] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/kkn/bimbingan/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIT8DCZkc4BvDXnoDJHgAAACc"]
[Thu Jul 30 12:22:23.393749 2026] [security2:error] [pid 727775:tid 727987] [client 142.93.53.183:53356] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/kkn/bimbingan/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIT8DCZkc4BvDXnoDJJgAAAFI"]
[Thu Jul 30 12:22:23.492187 2026] [security2:error] [pid 727775:tid 727968] [client 51.116.238.8:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/FWAZ.php"] [unique_id "amuIT8DCZkc4BvDXnoDJJwAAAD8"]
[Thu Jul 30 12:22:23.492284 2026] [security2:error] [pid 727775:tid 727968] [client 51.116.238.8:5066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/FWAZ.php"] [unique_id "amuIT8DCZkc4BvDXnoDJJwAAAD8"]
[Thu Jul 30 12:22:23.594352 2026] [security2:error] [pid 727775:tid 728022] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuITsDCZkc4BvDXnoDJHQAAAHU"]
[Thu Jul 30 12:22:23.768794 2026] [security2:error] [pid 727775:tid 727932] [client 142.93.53.183:53453] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/attachment_uet/ori/1337_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIT8DCZkc4BvDXnoDJMQAAABs"]
[Thu Jul 30 12:22:23.974420 2026] [security2:error] [pid 727775:tid 727949] [client 51.116.238.8:5002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/biufile.php"] [unique_id "amuIT8DCZkc4BvDXnoDJNgAAACw"]
[Thu Jul 30 12:22:23.974527 2026] [security2:error] [pid 727775:tid 727949] [client 51.116.238.8:5002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/biufile.php"] [unique_id "amuIT8DCZkc4BvDXnoDJNgAAACw"]
[Thu Jul 30 12:22:24.159567 2026] [security2:error] [pid 727775:tid 728025] [client 142.93.53.183:53550] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/attachment_uet/ori/1337_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIUMDCZkc4BvDXnoDJPQAAAHg"]
[Thu Jul 30 12:22:24.213841 2026] [core:notice] [pid 727775:tid 727834] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:24.549777 2026] [security2:error] [pid 727775:tid 728013] [client 142.93.53.183:53661] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/file/attachment_uet/ori/1337_DATA/alfacgiapi/py.alfa"] [unique_id "amuIUMDCZkc4BvDXnoDJQwAAAGw"]
[Thu Jul 30 12:22:24.929758 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:53775] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/application/controllers/bpm/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIUMDCZkc4BvDXnoDJSAAAAG0"]
[Thu Jul 30 12:22:25.047638 2026] [security2:error] [pid 727775:tid 728000] [client 51.116.238.8:4995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/coffexium.php"] [unique_id "amuIUcDCZkc4BvDXnoDJTAAAAF8"]
[Thu Jul 30 12:22:25.047743 2026] [security2:error] [pid 727775:tid 728000] [client 51.116.238.8:4995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/coffexium.php"] [unique_id "amuIUcDCZkc4BvDXnoDJTAAAAF8"]
[Thu Jul 30 12:22:25.307763 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:53890] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/application/controllers/bpm/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIUcDCZkc4BvDXnoDJWgAAAGE"]
[Thu Jul 30 12:22:25.688829 2026] [security2:error] [pid 727775:tid 727909] [client 142.93.53.183:54043] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/application/controllers/bpm/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIUcDCZkc4BvDXnoDJYgAAAAQ"]
[Thu Jul 30 12:22:25.879426 2026] [security2:error] [pid 727775:tid 727963] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIUcDCZkc4BvDXnoDJWAAAADo"]
[Thu Jul 30 12:22:25.923443 2026] [security2:error] [pid 727775:tid 727996] [client 51.116.238.8:5103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/simple.php"] [unique_id "amuIUcDCZkc4BvDXnoDJYwAAAFs"]
[Thu Jul 30 12:22:25.923582 2026] [security2:error] [pid 727775:tid 727996] [client 51.116.238.8:5103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/simple.php"] [unique_id "amuIUcDCZkc4BvDXnoDJYwAAAFs"]
[Thu Jul 30 12:22:26.014114 2026] [security2:error] [pid 727775:tid 727915] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIUcDCZkc4BvDXnoDJWwAAClM"]
[Thu Jul 30 12:22:26.071088 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:54202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pages/manageIssues/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIUsDCZkc4BvDXnoDJawAAAGo"]
[Thu Jul 30 12:22:26.463400 2026] [security2:error] [pid 727775:tid 727977] [client 142.93.53.183:54349] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pages/manageIssues/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIUsDCZkc4BvDXnoDJdwAAAEg"]
[Thu Jul 30 12:22:26.790356 2026] [security2:error] [pid 727775:tid 727961] [client 51.116.238.8:5106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/fpwch.php"] [unique_id "amuIUsDCZkc4BvDXnoDJgQAAADg"]
[Thu Jul 30 12:22:26.790494 2026] [security2:error] [pid 727775:tid 727961] [client 51.116.238.8:5106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/fpwch.php"] [unique_id "amuIUsDCZkc4BvDXnoDJgQAAADg"]
[Thu Jul 30 12:22:26.846724 2026] [security2:error] [pid 727775:tid 728031] [client 142.93.53.183:54490] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pages/manageIssues/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIUsDCZkc4BvDXnoDJgwAAAH4"]
[Thu Jul 30 12:22:27.217838 2026] [security2:error] [pid 727775:tid 727989] [client 51.116.238.8:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/dex.php"] [unique_id "amuIU8DCZkc4BvDXnoDJjAAAAFQ"]
[Thu Jul 30 12:22:27.217938 2026] [security2:error] [pid 727775:tid 727989] [client 51.116.238.8:5078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/dex.php"] [unique_id "amuIU8DCZkc4BvDXnoDJjAAAAFQ"]
[Thu Jul 30 12:22:27.225718 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:54648] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/image/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIU8DCZkc4BvDXnoDJjwAAAGc"]
[Thu Jul 30 12:22:27.347102 2026] [security2:error] [pid 727775:tid 727875] [remote 47.128.125.48:48040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "black-devil-shop.com"] [uri "/robots.txt"] [unique_id "amuIU8DCZkc4BvDXnoDJkQAAbWM"]
[Thu Jul 30 12:22:27.606100 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:54781] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIU8DCZkc4BvDXnoDJnAAAADw"]
[Thu Jul 30 12:22:27.615102 2026] [security2:error] [pid 727775:tid 728018] [client 54.87.112.51:24794] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuIUsDCZkc4BvDXnoDJcQAAAHE"], referer: https://globalmarks.pk/
[Thu Jul 30 12:22:27.687043 2026] [security2:error] [pid 727775:tid 727943] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuIU8DCZkc4BvDXnoDJlwAAACY"]
[Thu Jul 30 12:22:27.909241 2026] [security2:error] [pid 727775:tid 727896] [remote 74.7.241.60:49484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuIU8DCZkc4BvDXnoDJogAAc3g"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:22:27.993040 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:54917] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIU8DCZkc4BvDXnoDJowAAADo"]
[Thu Jul 30 12:22:27.993424 2026] [security2:error] [pid 727775:tid 728000] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIU8DCZkc4BvDXnoDJlAAAAF8"]
[Thu Jul 30 12:22:28.195559 2026] [security2:error] [pid 727775:tid 727984] [client 195.113.175.167:38420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/humanitariaf.php"] [unique_id "amuIVMDCZkc4BvDXnoDJqwAAAE8"]
[Thu Jul 30 12:22:28.268712 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5057] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "milfordauto.com"] [uri "/1.php"] [unique_id "amuIVMDCZkc4BvDXnoDJswAAADs"]
[Thu Jul 30 12:22:28.268852 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/1.php"] [unique_id "amuIVMDCZkc4BvDXnoDJswAAADs"]
[Thu Jul 30 12:22:28.268999 2026] [security2:error] [pid 727775:tid 727964] [client 51.116.238.8:5057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/1.php"] [unique_id "amuIVMDCZkc4BvDXnoDJswAAADs"]
[Thu Jul 30 12:22:28.440790 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:55082] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVMDCZkc4BvDXnoDJtgAAAA0"]
[Thu Jul 30 12:22:28.529935 2026] [security2:error] [pid 727775:tid 727952] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIUsDCZkc4BvDXnoDJfQAAAC8"]
[Thu Jul 30 12:22:28.681420 2026] [security2:error] [pid 727775:tid 727932] [client 74.7.244.51:39390] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "lms-aetiiph-net.smo.zzt.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuIVMDCZkc4BvDXnoDJvgAAG24"]
[Thu Jul 30 12:22:28.817632 2026] [security2:error] [pid 727775:tid 727933] [client 142.93.53.183:55210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/pub/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVMDCZkc4BvDXnoDJwgAAABw"]
[Thu Jul 30 12:22:29.045436 2026] [security2:error] [pid 727775:tid 728010] [client 74.7.228.15:36610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amuIVcDCZkc4BvDXnoDJwwAAaXQ"]
[Thu Jul 30 12:22:29.200013 2026] [security2:error] [pid 727775:tid 727994] [client 142.93.53.183:55338] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVcDCZkc4BvDXnoDJzAAAAFk"]
[Thu Jul 30 12:22:29.303225 2026] [security2:error] [pid 727775:tid 727957] [client 51.116.238.8:5001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "milfordauto.com"] [uri "/cgi-sys/404.html"] [unique_id "amuIVcDCZkc4BvDXnoDJ0gAAADQ"]
[Thu Jul 30 12:22:29.435066 2026] [security2:error] [pid 727775:tid 727965] [client 51.116.238.8:5001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/config.json.php"] [unique_id "amuIVcDCZkc4BvDXnoDJ1QAAADw"]
[Thu Jul 30 12:22:29.435181 2026] [security2:error] [pid 727775:tid 727965] [client 51.116.238.8:5001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/config.json.php"] [unique_id "amuIVcDCZkc4BvDXnoDJ1QAAADw"]
[Thu Jul 30 12:22:29.447137 2026] [security2:error] [pid 727775:tid 728013] [client 52.167.144.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIVcDCZkc4BvDXnoDJywAAAGw"]
[Thu Jul 30 12:22:29.501473 2026] [autoindex:error] [pid 727775:tid 727888] [remote 74.7.227.130:59116] AH01276: Cannot serve directory /home2/smozztte/public_html/new/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:29.617662 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:55474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/js/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVcDCZkc4BvDXnoDJ1wAAAGE"]
[Thu Jul 30 12:22:29.801758 2026] [security2:error] [pid 727775:tid 727934] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIVcDCZkc4BvDXnoDJzwAAAB0"]
[Thu Jul 30 12:22:30.013376 2026] [security2:error] [pid 727775:tid 727954] [client 142.93.53.183:55587] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVsDCZkc4BvDXnoDJ4AAAADE"]
[Thu Jul 30 12:22:30.452778 2026] [security2:error] [pid 727775:tid 727984] [client 142.93.53.183:55720] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVsDCZkc4BvDXnoDJ5wAAAE8"]
[Thu Jul 30 12:22:30.597150 2026] [security2:error] [pid 727775:tid 727928] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIVcDCZkc4BvDXnoDJ3wAAFws"]
[Thu Jul 30 12:22:30.796175 2026] [security2:error] [pid 727775:tid 727986] [client 51.116.238.8:5059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/k2.php"] [unique_id "amuIVsDCZkc4BvDXnoDJ7AAAAFE"]
[Thu Jul 30 12:22:30.796295 2026] [security2:error] [pid 727775:tid 727986] [client 51.116.238.8:5059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/k2.php"] [unique_id "amuIVsDCZkc4BvDXnoDJ7AAAAFE"]
[Thu Jul 30 12:22:30.862026 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:55856] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wordpress/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIVsDCZkc4BvDXnoDJ8QAAAA0"]
[Thu Jul 30 12:22:31.247162 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:55965] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blog/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIV8DCZkc4BvDXnoDJ9wAAACw"]
[Thu Jul 30 12:22:31.695729 2026] [security2:error] [pid 727775:tid 727942] [client 142.93.53.183:56112] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIV8DCZkc4BvDXnoDKAAAAACU"]
[Thu Jul 30 12:22:32.089467 2026] [security2:error] [pid 727775:tid 727972] [client 142.93.53.183:56260] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWMDCZkc4BvDXnoDKCAAAAEM"]
[Thu Jul 30 12:22:32.397922 2026] [security2:error] [pid 727775:tid 728014] [client 51.116.238.8:5054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/raw.php"] [unique_id "amuIWMDCZkc4BvDXnoDKDQAAAG0"]
[Thu Jul 30 12:22:32.398077 2026] [security2:error] [pid 727775:tid 728014] [client 51.116.238.8:5054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/raw.php"] [unique_id "amuIWMDCZkc4BvDXnoDKDQAAAG0"]
[Thu Jul 30 12:22:32.471842 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:56408] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/beez3/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWMDCZkc4BvDXnoDKEgAAACY"]
[Thu Jul 30 12:22:32.651926 2026] [security2:error] [pid 727775:tid 727974] [client 50.6.43.217:52052] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuIWMDCZkc4BvDXnoDKEwAAAEU"]
[Thu Jul 30 12:22:32.684916 2026] [security2:error] [pid 727775:tid 727945] [client 50.6.43.217:52062] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuIWMDCZkc4BvDXnoDKFAAAACg"]
[Thu Jul 30 12:22:32.854804 2026] [security2:error] [pid 727775:tid 727912] [client 142.93.53.183:56565] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/administrator/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWMDCZkc4BvDXnoDKGQAAAAc"]
[Thu Jul 30 12:22:33.235278 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:56712] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWcDCZkc4BvDXnoDKHQAAACI"]
[Thu Jul 30 12:22:33.624477 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:56850] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/alfacgiapi/perl.alfa"] [unique_id "amuIWcDCZkc4BvDXnoDKJQAAAF4"]
[Thu Jul 30 12:22:34.002082 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:56983] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWsDCZkc4BvDXnoDKLAAAAF0"]
[Thu Jul 30 12:22:34.389483 2026] [security2:error] [pid 727775:tid 727916] [client 142.93.53.183:57118] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/alfacgiapi/perl.alfa"] [unique_id "amuIWsDCZkc4BvDXnoDKMgAAAAs"]
[Thu Jul 30 12:22:34.631958 2026] [security2:error] [pid 727775:tid 727951] [client 172.213.232.128:28878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/geju.php"] [unique_id "amuIWsDCZkc4BvDXnoDKOQAAAC4"]
[Thu Jul 30 12:22:34.766426 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:57242] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIWsDCZkc4BvDXnoDKOgAAAFY"]
[Thu Jul 30 12:22:34.827444 2026] [core:notice] [pid 727775:tid 727959] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:34.855856 2026] [security2:error] [pid 727775:tid 727808] [remote 216.73.216.152:4013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIWsDCZkc4BvDXnoDKPQAASSA"]
[Thu Jul 30 12:22:34.864694 2026] [security2:error] [pid 727775:tid 727919] [client 51.116.238.8:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp.php"] [unique_id "amuIWsDCZkc4BvDXnoDKQAAAAA4"]
[Thu Jul 30 12:22:34.864777 2026] [security2:error] [pid 727775:tid 727919] [client 51.116.238.8:5104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/wp.php"] [unique_id "amuIWsDCZkc4BvDXnoDKQAAAAA4"]
[Thu Jul 30 12:22:35.303134 2026] [security2:error] [pid 727775:tid 727906] [client 142.93.53.183:57421] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/alfacgiapi/perl.alfa"] [unique_id "amuIW8DCZkc4BvDXnoDKRQAAAAE"]
[Thu Jul 30 12:22:35.559310 2026] [autoindex:error] [pid 727775:tid 727985] [client 45.153.159.21:32204] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_b63f1d3b/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:35.698597 2026] [security2:error] [pid 727775:tid 727926] [client 142.93.53.183:57567] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/images/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIW8DCZkc4BvDXnoDKUwAAABU"]
[Thu Jul 30 12:22:35.942097 2026] [security2:error] [pid 727775:tid 727819] [remote 40.77.167.74:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/issue/view/2"] [unique_id "amuIW8DCZkc4BvDXnoDKWAAASis"]
[Thu Jul 30 12:22:36.035915 2026] [security2:error] [pid 727775:tid 728007] [client 184.75.223.195:48750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuIXMDCZkc4BvDXnoDKXAAAAGY"]
[Thu Jul 30 12:22:36.036075 2026] [security2:error] [pid 727775:tid 728007] [client 184.75.223.195:48750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuIXMDCZkc4BvDXnoDKXAAAAGY"]
[Thu Jul 30 12:22:36.078824 2026] [security2:error] [pid 727775:tid 727928] [client 142.93.53.183:57706] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/images/alfacgiapi/perl.alfa"] [unique_id "amuIXMDCZkc4BvDXnoDKXQAAABc"]
[Thu Jul 30 12:22:36.459107 2026] [security2:error] [pid 727775:tid 727958] [client 142.93.53.183:57837] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/includes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIXMDCZkc4BvDXnoDKYgAAADU"]
[Thu Jul 30 12:22:36.837427 2026] [security2:error] [pid 727775:tid 728016] [client 142.93.53.183:57969] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/includes/alfacgiapi/perl.alfa"] [unique_id "amuIXMDCZkc4BvDXnoDKZwAAAG8"]
[Thu Jul 30 12:22:36.843061 2026] [security2:error] [pid 727775:tid 727920] [client 51.116.238.8:5016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/fffm.php"] [unique_id "amuIXMDCZkc4BvDXnoDKaAAAAA8"]
[Thu Jul 30 12:22:36.843152 2026] [security2:error] [pid 727775:tid 727920] [client 51.116.238.8:5016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/fffm.php"] [unique_id "amuIXMDCZkc4BvDXnoDKaAAAAA8"]
[Thu Jul 30 12:22:37.044172 2026] [core:notice] [pid 727775:tid 727829] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:37.239331 2026] [security2:error] [pid 727775:tid 727932] [client 142.93.53.183:58102] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/js/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIXcDCZkc4BvDXnoDKcQAAABs"]
[Thu Jul 30 12:22:37.246757 2026] [core:notice] [pid 727775:tid 727816] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:37.319746 2026] [security2:error] [pid 727775:tid 728013] [client 172.213.232.128:17440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/about.php"] [unique_id "amuIXcDCZkc4BvDXnoDKdAAAAGw"]
[Thu Jul 30 12:22:37.643724 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:58253] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/js/alfacgiapi/perl.alfa"] [unique_id "amuIXcDCZkc4BvDXnoDKewAAAFc"]
[Thu Jul 30 12:22:37.897192 2026] [security2:error] [pid 727775:tid 727925] [client 38.190.144.4:53750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIXcDCZkc4BvDXnoDKfAAAABQ"]
[Thu Jul 30 12:22:37.897328 2026] [security2:error] [pid 727775:tid 727925] [client 38.190.144.4:53750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIXcDCZkc4BvDXnoDKfAAAABQ"]
[Thu Jul 30 12:22:38.032008 2026] [security2:error] [pid 727775:tid 728025] [client 142.93.53.183:58404] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/maint/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIXsDCZkc4BvDXnoDKfQAAAHg"]
[Thu Jul 30 12:22:38.407819 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:58568] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/maint/alfacgiapi/perl.alfa"] [unique_id "amuIXsDCZkc4BvDXnoDKhgAAAGc"]
[Thu Jul 30 12:22:38.409653 2026] [security2:error] [pid 727775:tid 727965] [client 213.152.161.118:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuIXsDCZkc4BvDXnoDKhQAAADw"]
[Thu Jul 30 12:22:38.409732 2026] [security2:error] [pid 727775:tid 727965] [client 213.152.161.118:45324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuIXsDCZkc4BvDXnoDKhQAAADw"]
[Thu Jul 30 12:22:38.800015 2026] [security2:error] [pid 727775:tid 727989] [client 142.93.53.183:58722] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/network/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIXsDCZkc4BvDXnoDKkgAAAFQ"]
[Thu Jul 30 12:22:38.812938 2026] [security2:error] [pid 727775:tid 727937] [client 51.116.238.8:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/111.php"] [unique_id "amuIXsDCZkc4BvDXnoDKkwAAACA"]
[Thu Jul 30 12:22:38.813041 2026] [security2:error] [pid 727775:tid 727937] [client 51.116.238.8:5072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/111.php"] [unique_id "amuIXsDCZkc4BvDXnoDKkwAAACA"]
[Thu Jul 30 12:22:38.984406 2026] [security2:error] [pid 727775:tid 727960] [client 172.213.232.128:21622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp.php"] [unique_id "amuIXsDCZkc4BvDXnoDKlAAAADc"]
[Thu Jul 30 12:22:39.179287 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:58882] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/network/alfacgiapi/perl.alfa"] [unique_id "amuIX8DCZkc4BvDXnoDKmAAAAGE"]
[Thu Jul 30 12:22:39.412039 2026] [security2:error] [pid 727775:tid 727836] [remote 216.73.216.152:4013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIX8DCZkc4BvDXnoDKnAAAWDw"]
[Thu Jul 30 12:22:39.547958 2026] [security2:error] [pid 727775:tid 727987] [client 172.213.232.128:17499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/aaa.php"] [unique_id "amuIX8DCZkc4BvDXnoDKngAAAFI"]
[Thu Jul 30 12:22:39.565212 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:59034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/fonts/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIX8DCZkc4BvDXnoDKnwAAAGY"]
[Thu Jul 30 12:22:39.742056 2026] [core:error] [pid 727775:tid 727999] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 12:22:39.742089 2026] [core:error] [pid 727775:tid 727999] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://airevoduct.ltd/
[Thu Jul 30 12:22:39.945032 2026] [security2:error] [pid 727775:tid 727983] [client 142.93.53.183:59201] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/fonts/alfacgiapi/perl.alfa"] [unique_id "amuIX8DCZkc4BvDXnoDKqwAAAE4"]
[Thu Jul 30 12:22:40.026969 2026] [security2:error] [pid 727775:tid 727998] [client 51.116.238.8:5107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "milfordauto.com"] [uri "/cgi-sys/404.html"] [unique_id "amuIYMDCZkc4BvDXnoDKrAAAAF0"]
[Thu Jul 30 12:22:40.156470 2026] [security2:error] [pid 727775:tid 727995] [client 51.116.238.8:5107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ws.php"] [unique_id "amuIYMDCZkc4BvDXnoDKrQAAAFo"]
[Thu Jul 30 12:22:40.156580 2026] [security2:error] [pid 727775:tid 727995] [client 51.116.238.8:5107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/ws.php"] [unique_id "amuIYMDCZkc4BvDXnoDKrQAAAFo"]
[Thu Jul 30 12:22:40.325321 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:59361] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIYMDCZkc4BvDXnoDKtQAAAD8"]
[Thu Jul 30 12:22:40.704720 2026] [security2:error] [pid 727775:tid 727956] [client 142.93.53.183:59528] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/alfacgiapi/perl.alfa"] [unique_id "amuIYMDCZkc4BvDXnoDKugAAADM"]
[Thu Jul 30 12:22:41.087372 2026] [security2:error] [pid 727775:tid 727946] [client 142.93.53.183:59685] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/litespeed/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIYcDCZkc4BvDXnoDKwgAAACk"]
[Thu Jul 30 12:22:41.152515 2026] [lsapi:error] [pid 703393:tid 703473] [remote 102.209.111.62:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/wolf-man-vj-junior/
[Thu Jul 30 12:22:41.204169 2026] [security2:error] [pid 727775:tid 728008] [client 51.116.238.8:5069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/coffee.php"] [unique_id "amuIYcDCZkc4BvDXnoDKxwAAAGc"]
[Thu Jul 30 12:22:41.204271 2026] [security2:error] [pid 727775:tid 728008] [client 51.116.238.8:5069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/coffee.php"] [unique_id "amuIYcDCZkc4BvDXnoDKxwAAAGc"]
[Thu Jul 30 12:22:41.398577 2026] [proxy:error] [pid 727775:tid 728006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.398650 2026] [proxy_http:error] [pid 727775:tid 728006] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:41.399614 2026] [proxy:error] [pid 727775:tid 728006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.399670 2026] [proxy_http:error] [pid 727775:tid 728006] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:41.407471 2026] [proxy:error] [pid 727775:tid 727974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.407541 2026] [proxy_http:error] [pid 727775:tid 727974] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:41.408249 2026] [proxy:error] [pid 727775:tid 727974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.408302 2026] [proxy_http:error] [pid 727775:tid 727974] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:41.459151 2026] [proxy:error] [pid 727775:tid 727989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.459230 2026] [proxy_http:error] [pid 727775:tid 727989] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.nexiummedication.store.
[Thu Jul 30 12:22:41.459791 2026] [proxy:error] [pid 727775:tid 727989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.459834 2026] [proxy_http:error] [pid 727775:tid 727989] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.nexiummedication.store.
[Thu Jul 30 12:22:41.465544 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:59850] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/litespeed/alfacgiapi/perl.alfa"] [unique_id "amuIYcDCZkc4BvDXnoDK2QAAACc"]
[Thu Jul 30 12:22:41.537665 2026] [proxy:error] [pid 727775:tid 727909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.537734 2026] [proxy_http:error] [pid 727775:tid 727909] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.nexiummedication.store.
[Thu Jul 30 12:22:41.538331 2026] [proxy:error] [pid 727775:tid 727909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:41.538375 2026] [proxy_http:error] [pid 727775:tid 727909] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.nexiummedication.store.
[Thu Jul 30 12:22:41.841777 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:60007] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIYcDCZkc4BvDXnoDK8AAAAA0"]
[Thu Jul 30 12:22:42.172127 2026] [security2:error] [pid 727775:tid 727975] [client 172.213.232.128:21026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/hoot.php"] [unique_id "amuIYsDCZkc4BvDXnoDK9QAAAEY"]
[Thu Jul 30 12:22:42.219043 2026] [security2:error] [pid 727775:tid 728016] [client 51.116.238.8:5105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/goods.php"] [unique_id "amuIYsDCZkc4BvDXnoDK9gAAAG8"]
[Thu Jul 30 12:22:42.219137 2026] [security2:error] [pid 727775:tid 728016] [client 51.116.238.8:5105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/goods.php"] [unique_id "amuIYsDCZkc4BvDXnoDK9gAAAG8"]
[Thu Jul 30 12:22:42.222948 2026] [security2:error] [pid 727775:tid 727955] [client 142.93.53.183:60155] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/alfacgiapi/perl.alfa"] [unique_id "amuIYsDCZkc4BvDXnoDK9wAAADI"]
[Thu Jul 30 12:22:42.368752 2026] [security2:error] [pid 727775:tid 728004] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIYsDCZkc4BvDXnoDK9AAAAGM"]
[Thu Jul 30 12:22:42.619741 2026] [security2:error] [pid 727775:tid 727956] [client 142.93.53.183:60326] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/akismet/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIYsDCZkc4BvDXnoDK_wAAADM"]
[Thu Jul 30 12:22:43.000540 2026] [security2:error] [pid 727775:tid 728003] [client 142.93.53.183:60493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/akismet/alfacgiapi/perl.alfa"] [unique_id "amuIY8DCZkc4BvDXnoDLBgAAAGI"]
[Thu Jul 30 12:22:43.354116 2026] [proxy:error] [pid 727775:tid 727905] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.354192 2026] [proxy_http:error] [pid 727775:tid 727905] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:43.354969 2026] [proxy:error] [pid 727775:tid 727905] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.355043 2026] [proxy_http:error] [pid 727775:tid 727905] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:43.373123 2026] [security2:error] [pid 727775:tid 727863] [remote 74.7.241.59:47612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuIY8DCZkc4BvDXnoDLDgAADlc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/widgets
[Thu Jul 30 12:22:43.393423 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:60653] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIY8DCZkc4BvDXnoDLEgAAAG0"]
[Thu Jul 30 12:22:43.457735 2026] [proxy:error] [pid 727775:tid 728019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.457805 2026] [proxy_http:error] [pid 727775:tid 728019] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.koinjp189.com.
[Thu Jul 30 12:22:43.458401 2026] [proxy:error] [pid 727775:tid 728019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.458446 2026] [proxy_http:error] [pid 727775:tid 728019] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.koinjp189.com.
[Thu Jul 30 12:22:43.544331 2026] [proxy:error] [pid 727775:tid 727910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.544399 2026] [proxy_http:error] [pid 727775:tid 727910] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:43.544954 2026] [proxy:error] [pid 727775:tid 727910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.545008 2026] [proxy_http:error] [pid 727775:tid 727910] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:43.613638 2026] [proxy:error] [pid 727775:tid 727937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.613716 2026] [proxy_http:error] [pid 727775:tid 727937] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com.
[Thu Jul 30 12:22:43.614644 2026] [proxy:error] [pid 727775:tid 727937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:43.614701 2026] [proxy_http:error] [pid 727775:tid 727937] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com.
[Thu Jul 30 12:22:43.744549 2026] [security2:error] [pid 727775:tid 727912] [client 51.116.238.8:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuIY8DCZkc4BvDXnoDLKgAAAAc"]
[Thu Jul 30 12:22:43.744658 2026] [security2:error] [pid 727775:tid 727912] [client 51.116.238.8:5094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuIY8DCZkc4BvDXnoDLKgAAAAc"]
[Thu Jul 30 12:22:43.783212 2026] [security2:error] [pid 727775:tid 727929] [client 142.93.53.183:60814] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/alfacgiapi/perl.alfa"] [unique_id "amuIY8DCZkc4BvDXnoDLKwAAABg"]
[Thu Jul 30 12:22:44.174804 2026] [security2:error] [pid 727775:tid 727977] [client 142.93.53.183:60992] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/contact-form-7/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZMDCZkc4BvDXnoDLNwAAAEg"]
[Thu Jul 30 12:22:44.518949 2026] [security2:error] [pid 727775:tid 727952] [client 20.91.199.21:47241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/json.php"] [unique_id "amuIZMDCZkc4BvDXnoDLQAAAAC8"]
[Thu Jul 30 12:22:44.550375 2026] [security2:error] [pid 727775:tid 727984] [client 172.237.109.114:28138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIY8DCZkc4BvDXnoDLMwAAAE8"]
[Thu Jul 30 12:22:44.556493 2026] [security2:error] [pid 727775:tid 727947] [client 142.93.53.183:61156] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/contact-form-7/alfacgiapi/perl.alfa"] [unique_id "amuIZMDCZkc4BvDXnoDLQgAAACo"]
[Thu Jul 30 12:22:44.561504 2026] [security2:error] [pid 727775:tid 727964] [client 172.237.109.114:25853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIY8DCZkc4BvDXnoDLNAAAADs"]
[Thu Jul 30 12:22:44.616564 2026] [security2:error] [pid 727775:tid 727923] [client 51.116.238.8:5039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuIZMDCZkc4BvDXnoDLQwAAABI"]
[Thu Jul 30 12:22:44.616681 2026] [security2:error] [pid 727775:tid 727923] [client 51.116.238.8:5039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuIZMDCZkc4BvDXnoDLQwAAABI"]
[Thu Jul 30 12:22:44.830422 2026] [proxy:error] [pid 727775:tid 728028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.830489 2026] [proxy_http:error] [pid 727775:tid 728028] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:44.831044 2026] [proxy:error] [pid 727775:tid 728028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.831088 2026] [proxy_http:error] [pid 727775:tid 728028] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:44.845958 2026] [autoindex:error] [pid 727775:tid 728025] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:44.850092 2026] [autoindex:error] [pid 727775:tid 727942] [client 2a09:bac0:1000:c48::21e:147:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:44.852030 2026] [proxy:error] [pid 727775:tid 727913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.852117 2026] [proxy_http:error] [pid 727775:tid 727913] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:44.852547 2026] [autoindex:error] [pid 727775:tid 728010] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:44.852878 2026] [proxy:error] [pid 727775:tid 727913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.852937 2026] [proxy_http:error] [pid 727775:tid 727913] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:44.859050 2026] [autoindex:error] [pid 727775:tid 727925] [client 2a09:bac0:1000:c48::4:2ec:0] AH01276: Cannot serve directory /home2/mbmudite/ok.melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:44.923324 2026] [autoindex:error] [pid 727775:tid 727978] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.melatipkr.xyz.
[Thu Jul 30 12:22:44.924119 2026] [autoindex:error] [pid 727775:tid 727927] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://melatipkr.xyz.
[Thu Jul 30 12:22:44.931476 2026] [autoindex:error] [pid 727775:tid 728029] [client 2a09:bac0:1000:c48::4:2ec:0] AH01276: Cannot serve directory /home2/mbmudite/ok.melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.melatipkr.xyz.
[Thu Jul 30 12:22:44.933943 2026] [security2:error] [pid 727775:tid 727905] [client 142.93.53.183:61348] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZMDCZkc4BvDXnoDLbgAAAAA"]
[Thu Jul 30 12:22:44.940767 2026] [proxy:error] [pid 727775:tid 727980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.940840 2026] [proxy_http:error] [pid 727775:tid 727980] [client 2a09:bac0:1000:c48::4:2ec:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.melatipkr.xyz.
[Thu Jul 30 12:22:44.941416 2026] [proxy:error] [pid 727775:tid 727980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.941464 2026] [proxy_http:error] [pid 727775:tid 727980] [client 2a09:bac0:1000:c48::4:2ec:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.melatipkr.xyz.
[Thu Jul 30 12:22:44.943882 2026] [proxy:error] [pid 727775:tid 727943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.943938 2026] [proxy_http:error] [pid 727775:tid 727943] [client 2a09:bac0:1000:c48::4:2ec:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.melatipkr.xyz.
[Thu Jul 30 12:22:44.944529 2026] [proxy:error] [pid 727775:tid 727943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:44.944584 2026] [proxy_http:error] [pid 727775:tid 727943] [client 2a09:bac0:1000:c48::4:2ec:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.melatipkr.xyz.
[Thu Jul 30 12:22:44.953303 2026] [autoindex:error] [pid 727775:tid 728014] [client 2a09:bac0:1000:c48::4:2ec:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.melatipkr.xyz.
[Thu Jul 30 12:22:45.095277 2026] [security2:error] [pid 727775:tid 728018] [client 172.213.232.128:10320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/about.php"] [unique_id "amuIZcDCZkc4BvDXnoDLhgAAAHE"]
[Thu Jul 30 12:22:45.314723 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:61529] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor/alfacgiapi/perl.alfa"] [unique_id "amuIZcDCZkc4BvDXnoDLiAAAAG4"]
[Thu Jul 30 12:22:45.376252 2026] [proxy:error] [pid 727775:tid 727960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:45.376373 2026] [proxy_http:error] [pid 727775:tid 727960] [client 74.7.230.52:49010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:45.377955 2026] [proxy:error] [pid 727775:tid 727960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:45.378048 2026] [proxy_http:error] [pid 727775:tid 727960] [client 74.7.230.52:49010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:45.378256 2026] [security2:error] [pid 727775:tid 727960] [client 74.7.230.52:49010] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.bgk.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuIZcDCZkc4BvDXnoDLiQAAADc"]
[Thu Jul 30 12:22:45.414163 2026] [autoindex:error] [pid 727775:tid 727950] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:45.460915 2026] [autoindex:error] [pid 727775:tid 728000] [client 2a09:bac0:1000:c48::1c:350:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:45.463685 2026] [autoindex:error] [pid 727775:tid 727924] [client 2a09:bac0:1000:c48::1c:350:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:22:45.470326 2026] [autoindex:error] [pid 727775:tid 727954] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.n1rmalabet88.com.
[Thu Jul 30 12:22:45.496901 2026] [autoindex:error] [pid 727775:tid 728012] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.n1rmalabet88.com.
[Thu Jul 30 12:22:45.507732 2026] [autoindex:error] [pid 727775:tid 728004] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://n1rmalabet88.com.
[Thu Jul 30 12:22:45.537764 2026] [security2:error] [pid 727775:tid 727916] [client 51.116.238.8:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuIZcDCZkc4BvDXnoDLsgAAAAs"]
[Thu Jul 30 12:22:45.537926 2026] [security2:error] [pid 727775:tid 727916] [client 51.116.238.8:5083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/admin.php"] [unique_id "amuIZcDCZkc4BvDXnoDLsgAAAAs"]
[Thu Jul 30 12:22:45.580677 2026] [security2:error] [pid 727775:tid 728013] [client 87.101.92.171:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuIZcDCZkc4BvDXnoDLtQAAAGw"]
[Thu Jul 30 12:22:45.580866 2026] [security2:error] [pid 727775:tid 728013] [client 87.101.92.171:56606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuIZcDCZkc4BvDXnoDLtQAAAGw"]
[Thu Jul 30 12:22:45.614202 2026] [security2:error] [pid 727775:tid 727972] [client 172.237.109.114:60493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLdAAAAEM"]
[Thu Jul 30 12:22:45.616243 2026] [security2:error] [pid 727775:tid 727926] [client 20.91.199.21:47248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/mini.php"] [unique_id "amuIZcDCZkc4BvDXnoDLtgAAABU"]
[Thu Jul 30 12:22:45.650812 2026] [security2:error] [pid 727775:tid 727934] [client 172.237.109.114:37563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLeAAAAB0"]
[Thu Jul 30 12:22:45.701604 2026] [security2:error] [pid 727775:tid 728021] [client 142.93.53.183:61698] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor-pro/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZcDCZkc4BvDXnoDLtwAAAHQ"]
[Thu Jul 30 12:22:45.705201 2026] [security2:error] [pid 727775:tid 727937] [client 172.237.109.114:23359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLgQAAACA"]
[Thu Jul 30 12:22:45.714417 2026] [security2:error] [pid 727775:tid 727945] [client 172.237.109.114:54742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLfwAAACg"]
[Thu Jul 30 12:22:45.714586 2026] [security2:error] [pid 727775:tid 727973] [client 172.237.109.114:41773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLewAAAEQ"]
[Thu Jul 30 12:22:45.714731 2026] [security2:error] [pid 727775:tid 727914] [client 172.237.109.114:9938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLfQAAAAk"]
[Thu Jul 30 12:22:45.715727 2026] [security2:error] [pid 727775:tid 728006] [client 172.237.109.114:13889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLeQAAAGU"]
[Thu Jul 30 12:22:45.719168 2026] [security2:error] [pid 727775:tid 727974] [client 172.237.109.114:56414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLfgAAAEU"]
[Thu Jul 30 12:22:45.721414 2026] [security2:error] [pid 727775:tid 727935] [client 172.237.109.114:51632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLegAAAB4"]
[Thu Jul 30 12:22:45.730780 2026] [security2:error] [pid 727775:tid 727966] [client 172.237.109.114:22527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLggAAAD0"]
[Thu Jul 30 12:22:45.760026 2026] [security2:error] [pid 727775:tid 727989] [client 172.237.109.114:13511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIZMDCZkc4BvDXnoDLgAAAAFQ"]
[Thu Jul 30 12:22:46.081630 2026] [security2:error] [pid 727775:tid 727962] [client 142.93.53.183:61870] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor-pro/alfacgiapi/perl.alfa"] [unique_id "amuIZsDCZkc4BvDXnoDLwgAAADk"]
[Thu Jul 30 12:22:46.113861 2026] [security2:error] [pid 727775:tid 727781] [remote 216.73.216.152:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIZsDCZkc4BvDXnoDLwwAAVwU"]
[Thu Jul 30 12:22:46.181142 2026] [security2:error] [pid 727775:tid 727946] [client 47.128.49.182:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.buyfluoxetine.store"] [uri "/robots.txt"] [unique_id "amuIZsDCZkc4BvDXnoDLxQAAACk"]
[Thu Jul 30 12:22:46.396071 2026] [security2:error] [pid 727775:tid 727931] [client 20.91.199.21:47257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/chosen.php"] [unique_id "amuIZsDCZkc4BvDXnoDLyAAAABo"]
[Thu Jul 30 12:22:46.464631 2026] [security2:error] [pid 727775:tid 727929] [client 142.93.53.183:62036] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/litespeed-cache/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZsDCZkc4BvDXnoDLzAAAABg"]
[Thu Jul 30 12:22:46.557026 2026] [security2:error] [pid 727775:tid 728031] [client 172.213.232.128:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/admin.php"] [unique_id "amuIZsDCZkc4BvDXnoDL0AAAAH4"]
[Thu Jul 30 12:22:46.788956 2026] [security2:error] [pid 727775:tid 727953] [client 51.116.238.8:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/inputs.php"] [unique_id "amuIZsDCZkc4BvDXnoDL1gAAADA"]
[Thu Jul 30 12:22:46.789088 2026] [security2:error] [pid 727775:tid 727953] [client 51.116.238.8:5112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/inputs.php"] [unique_id "amuIZsDCZkc4BvDXnoDL1gAAADA"]
[Thu Jul 30 12:22:46.789606 2026] [security2:error] [pid 727775:tid 727782] [remote 62.210.185.4:49084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahm.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuIZsDCZkc4BvDXnoDL1QAAegY"]
[Thu Jul 30 12:22:46.845798 2026] [security2:error] [pid 727775:tid 727932] [client 142.93.53.183:62185] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/importexport/medra/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIZsDCZkc4BvDXnoDL1wAAABs"]
[Thu Jul 30 12:22:46.890107 2026] [security2:error] [pid 727775:tid 727921] [client 52.167.144.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIZsDCZkc4BvDXnoDLywAAABA"]
[Thu Jul 30 12:22:47.226773 2026] [security2:error] [pid 727775:tid 727925] [client 142.93.53.183:62343] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/importexport/medra/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIZ8DCZkc4BvDXnoDL4wAAABQ"]
[Thu Jul 30 12:22:47.232292 2026] [security2:error] [pid 727775:tid 727941] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuIZsDCZkc4BvDXnoDL2wAAACQ"]
[Thu Jul 30 12:22:47.437470 2026] [security2:error] [pid 727775:tid 728028] [client 172.213.232.128:21616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuIZ8DCZkc4BvDXnoDL6QAAAHs"]
[Thu Jul 30 12:22:47.520571 2026] [security2:error] [pid 727775:tid 728006] [client 20.91.199.21:47278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/kj.php"] [unique_id "amuIZ8DCZkc4BvDXnoDL6gAAAGU"]
[Thu Jul 30 12:22:47.553955 2026] [proxy:error] [pid 727775:tid 727991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.554043 2026] [proxy_http:error] [pid 727775:tid 727991] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:47.554632 2026] [proxy:error] [pid 727775:tid 727991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.554675 2026] [proxy_http:error] [pid 727775:tid 727991] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:47.579823 2026] [proxy:error] [pid 727775:tid 727931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.579891 2026] [proxy_http:error] [pid 727775:tid 727931] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:47.580458 2026] [proxy:error] [pid 727775:tid 727931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.580504 2026] [proxy_http:error] [pid 727775:tid 727931] [client 2a09:bac0:1000:c48::1c:350:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:47.604097 2026] [proxy:error] [pid 727775:tid 727957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.604163 2026] [proxy_http:error] [pid 727775:tid 727957] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.buyfluoxetine.store.
[Thu Jul 30 12:22:47.604782 2026] [proxy:error] [pid 727775:tid 727957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.604837 2026] [proxy_http:error] [pid 727775:tid 727957] [client 2a09:bac0:1000:c48::1c:2a1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.buyfluoxetine.store.
[Thu Jul 30 12:22:47.631799 2026] [proxy:error] [pid 727775:tid 728022] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.631872 2026] [proxy_http:error] [pid 727775:tid 728022] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.buyfluoxetine.store.
[Thu Jul 30 12:22:47.632497 2026] [proxy:error] [pid 727775:tid 728022] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:47.632550 2026] [proxy_http:error] [pid 727775:tid 728022] [client 2a09:bac0:1000:c48::2e9:aa:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.buyfluoxetine.store.
[Thu Jul 30 12:22:47.633615 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:62507] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/importexport/medra/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIZ8DCZkc4BvDXnoDMBAAAADo"]
[Thu Jul 30 12:22:48.032403 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:62705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dokumen/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIaMDCZkc4BvDXnoDMFQAAAF0"]
[Thu Jul 30 12:22:48.163576 2026] [proxy:error] [pid 727775:tid 728016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.163654 2026] [proxy_http:error] [pid 727775:tid 728016] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:48.164263 2026] [proxy:error] [pid 727775:tid 728016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.164310 2026] [proxy_http:error] [pid 727775:tid 728016] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:48.197921 2026] [security2:error] [pid 727775:tid 727995] [client 172.213.232.128:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/db-cache.php"] [unique_id "amuIaMDCZkc4BvDXnoDMIQAAAFo"]
[Thu Jul 30 12:22:48.276946 2026] [proxy:error] [pid 727775:tid 727935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.277023 2026] [proxy_http:error] [pid 727775:tid 727935] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lapakjitu78.com.
[Thu Jul 30 12:22:48.277658 2026] [proxy:error] [pid 727775:tid 727935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.277704 2026] [proxy_http:error] [pid 727775:tid 727935] [client 2a09:bac0:1000:c48::4d0:3e:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lapakjitu78.com.
[Thu Jul 30 12:22:48.287026 2026] [proxy:error] [pid 727775:tid 727989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.287087 2026] [proxy_http:error] [pid 727775:tid 727989] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:48.287652 2026] [proxy:error] [pid 727775:tid 727989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.287694 2026] [proxy_http:error] [pid 727775:tid 727989] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:22:48.343890 2026] [security2:error] [pid 727775:tid 727993] [client 38.190.144.4:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIaMDCZkc4BvDXnoDMMgAAAFg"]
[Thu Jul 30 12:22:48.344024 2026] [security2:error] [pid 727775:tid 727993] [client 38.190.144.4:54225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIaMDCZkc4BvDXnoDMMgAAAFg"]
[Thu Jul 30 12:22:48.354816 2026] [proxy:error] [pid 727775:tid 727926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.354891 2026] [proxy_http:error] [pid 727775:tid 727926] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.lapakjitu78.com.
[Thu Jul 30 12:22:48.355786 2026] [proxy:error] [pid 727775:tid 727926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:22:48.355850 2026] [proxy_http:error] [pid 727775:tid 727926] [client 2a09:bac0:1000:c48::21e:147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.lapakjitu78.com.
[Thu Jul 30 12:22:48.425486 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:62891] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dokumen/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIaMDCZkc4BvDXnoDMPAAAACM"]
[Thu Jul 30 12:22:48.482609 2026] [security2:error] [pid 727775:tid 727947] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIaMDCZkc4BvDXnoDMGgAAKiI"]
[Thu Jul 30 12:22:48.496802 2026] [security2:error] [pid 727775:tid 728025] [client 20.91.199.21:47255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-files.php"] [unique_id "amuIaMDCZkc4BvDXnoDMPwAAAHg"]
[Thu Jul 30 12:22:48.610808 2026] [security2:error] [pid 727775:tid 727931] [client 51.116.238.8:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/inputs.php"] [unique_id "amuIaMDCZkc4BvDXnoDMRgAAABo"]
[Thu Jul 30 12:22:48.610894 2026] [security2:error] [pid 727775:tid 727931] [client 51.116.238.8:5097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/inputs.php"] [unique_id "amuIaMDCZkc4BvDXnoDMRgAAABo"]
[Thu Jul 30 12:22:48.808433 2026] [security2:error] [pid 727775:tid 727938] [client 142.93.53.183:63058] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/dokumen/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIaMDCZkc4BvDXnoDMTQAAACE"]
[Thu Jul 30 12:22:49.201736 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:63227] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/perpustakaan/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIacDCZkc4BvDXnoDMVwAAAHc"]
[Thu Jul 30 12:22:49.601585 2026] [security2:error] [pid 727775:tid 727953] [client 142.93.53.183:63401] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/perpustakaan/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIacDCZkc4BvDXnoDMWwAAADA"]
[Thu Jul 30 12:22:49.763518 2026] [security2:error] [pid 727775:tid 727923] [client 172.213.232.128:4456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuIacDCZkc4BvDXnoDMZQAAABI"]
[Thu Jul 30 12:22:49.991825 2026] [security2:error] [pid 727775:tid 727990] [client 142.93.53.183:63567] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/perpustakaan/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIacDCZkc4BvDXnoDMZwAAAFU"]
[Thu Jul 30 12:22:50.230259 2026] [security2:error] [pid 727775:tid 727938] [client 51.116.238.8:5005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/adminfuns.php"] [unique_id "amuIasDCZkc4BvDXnoDMcgAAACE"]
[Thu Jul 30 12:22:50.230372 2026] [security2:error] [pid 727775:tid 727938] [client 51.116.238.8:5005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/adminfuns.php"] [unique_id "amuIasDCZkc4BvDXnoDMcgAAACE"]
[Thu Jul 30 12:22:50.373115 2026] [security2:error] [pid 727775:tid 727910] [client 142.93.53.183:63729] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIasDCZkc4BvDXnoDMdAAAAAU"]
[Thu Jul 30 12:22:50.561725 2026] [security2:error] [pid 727775:tid 727970] [client 20.91.199.21:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-setup.php"] [unique_id "amuIasDCZkc4BvDXnoDMdQAAAEE"]
[Thu Jul 30 12:22:50.626276 2026] [security2:error] [pid 727775:tid 728009] [client 172.213.232.128:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuIasDCZkc4BvDXnoDMdgAAAGg"]
[Thu Jul 30 12:22:50.757938 2026] [security2:error] [pid 727775:tid 727942] [client 142.93.53.183:63893] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIasDCZkc4BvDXnoDMfwAAACU"]
[Thu Jul 30 12:22:50.930251 2026] [security2:error] [pid 727775:tid 727992] [client 51.116.238.8:5022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/404.php"] [unique_id "amuIasDCZkc4BvDXnoDMgAAAAFc"]
[Thu Jul 30 12:22:50.930369 2026] [security2:error] [pid 727775:tid 727992] [client 51.116.238.8:5022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/404.php"] [unique_id "amuIasDCZkc4BvDXnoDMgAAAAFc"]
[Thu Jul 30 12:22:51.145123 2026] [security2:error] [pid 727775:tid 727957] [client 142.93.53.183:64057] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Classes/PHPExcel/Shared/Escher/DggContainer/BstoreContainer/BSE/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIa8DCZkc4BvDXnoDMgQAAADQ"]
[Thu Jul 30 12:22:51.350188 2026] [security2:error] [pid 727775:tid 727912] [client 172.213.232.128:21613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuIa8DCZkc4BvDXnoDMiAAAAAc"]
[Thu Jul 30 12:22:51.540697 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:64233] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/html2pdf/_tcpdf_5.0.002/fonts/freefont-20090104/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIa8DCZkc4BvDXnoDMiQAAAGo"]
[Thu Jul 30 12:22:51.917286 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:64386] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/html2pdf/_tcpdf_5.0.002/fonts/freefont-20090104/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIa8DCZkc4BvDXnoDMlAAAACw"]
[Thu Jul 30 12:22:52.299454 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:64550] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/html2pdf/_tcpdf_5.0.002/fonts/freefont-20090104/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIbMDCZkc4BvDXnoDMmQAAAHc"]
[Thu Jul 30 12:22:52.542756 2026] [security2:error] [pid 727775:tid 727954] [client 218.60.174.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuIa8DCZkc4BvDXnoDMjQAAADE"]
[Thu Jul 30 12:22:52.892490 2026] [security2:error] [pid 727775:tid 727985] [client 142.93.53.183:64802] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/foto_alumni/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIbMDCZkc4BvDXnoDMqQAAAFA"]
[Thu Jul 30 12:22:53.392058 2026] [security2:error] [pid 727775:tid 728001] [client 51.116.238.8:5038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xxx.php"] [unique_id "amuIbcDCZkc4BvDXnoDMtAAAAGA"]
[Thu Jul 30 12:22:53.392192 2026] [security2:error] [pid 727775:tid 728001] [client 51.116.238.8:5038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/xxx.php"] [unique_id "amuIbcDCZkc4BvDXnoDMtAAAAGA"]
[Thu Jul 30 12:22:53.484346 2026] [security2:error] [pid 727775:tid 727972] [client 142.93.53.183:65088] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/foto_alumni/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIbcDCZkc4BvDXnoDMtQAAAEM"]
[Thu Jul 30 12:22:53.866460 2026] [security2:error] [pid 727775:tid 727962] [client 142.93.53.183:65299] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/test/journals/1/issues/ALFA_HAXOR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIbcDCZkc4BvDXnoDMvgAAADk"]
[Thu Jul 30 12:22:53.997472 2026] [security2:error] [pid 727775:tid 727982] [client 172.213.232.128:4254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuIbcDCZkc4BvDXnoDMwAAAAE0"]
[Thu Jul 30 12:22:54.014399 2026] [security2:error] [pid 727775:tid 727997] [client 51.116.238.8:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/classwithtostring.php"] [unique_id "amuIbsDCZkc4BvDXnoDMwQAAAFw"]
[Thu Jul 30 12:22:54.014543 2026] [security2:error] [pid 727775:tid 727997] [client 51.116.238.8:5089] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/classwithtostring.php"] [unique_id "amuIbsDCZkc4BvDXnoDMwQAAAFw"]
[Thu Jul 30 12:22:54.273010 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:65496] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/test/journals/1/issues/ALFA_HAXOR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIbsDCZkc4BvDXnoDMwgAAAHE"]
[Thu Jul 30 12:22:54.296738 2026] [core:notice] [pid 727775:tid 727989] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:54.432796 2026] [security2:error] [pid 727775:tid 727847] [remote 216.73.216.152:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIbsDCZkc4BvDXnoDM0wAAU0c"]
[Thu Jul 30 12:22:54.653568 2026] [security2:error] [pid 727775:tid 728030] [client 142.93.53.183:49321] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/test/journals/1/issues/ALFA_HAXOR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIbsDCZkc4BvDXnoDM3QAAAH0"]
[Thu Jul 30 12:22:55.008582 2026] [security2:error] [pid 727775:tid 727975] [client 172.213.232.128:4454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuIb8DCZkc4BvDXnoDM5QAAAEY"]
[Thu Jul 30 12:22:55.222175 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:49630] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/composer/MiawSecurity_DATA/MiawSecuritycgiapi/perl.MiawSecurity"] [unique_id "amuIb8DCZkc4BvDXnoDM6gAAAHc"]
[Thu Jul 30 12:22:55.347041 2026] [security2:error] [pid 727775:tid 727917] [client 51.116.238.8:5088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/234ff.php"] [unique_id "amuIb8DCZkc4BvDXnoDNAAAAAAw"]
[Thu Jul 30 12:22:55.347147 2026] [security2:error] [pid 727775:tid 727917] [client 51.116.238.8:5088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/234ff.php"] [unique_id "amuIb8DCZkc4BvDXnoDNAAAAAAw"]
[Thu Jul 30 12:22:55.569189 2026] [security2:error] [pid 727775:tid 727933] [client 172.213.232.128:4817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/content.php"] [unique_id "amuIb8DCZkc4BvDXnoDNCAAAABw"]
[Thu Jul 30 12:22:55.637144 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:49821] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/composer/MiawSecurity_DATA/MiawSecuritycgiapi/py.MiawSecurity"] [unique_id "amuIb8DCZkc4BvDXnoDNDAAAACI"]
[Thu Jul 30 12:22:55.825549 2026] [security2:error] [pid 727775:tid 727921] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIb8DCZkc4BvDXnoDM6QAAABA"]
[Thu Jul 30 12:22:55.927009 2026] [security2:error] [pid 727775:tid 727888] [remote 216.73.216.152:14970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIb8DCZkc4BvDXnoDNFgAAVnA"]
[Thu Jul 30 12:22:56.021277 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:50027] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/composer/MiawSecurity_DATA/MiawSecuritycgiapi/bash.MiawSecurity"] [unique_id "amuIcMDCZkc4BvDXnoDNGgAAAGc"]
[Thu Jul 30 12:22:56.160365 2026] [security2:error] [pid 727775:tid 728006] [client 51.116.238.8:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/133.php"] [unique_id "amuIcMDCZkc4BvDXnoDNHQAAAGU"]
[Thu Jul 30 12:22:56.160472 2026] [security2:error] [pid 727775:tid 728006] [client 51.116.238.8:5087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/133.php"] [unique_id "amuIcMDCZkc4BvDXnoDNHQAAAGU"]
[Thu Jul 30 12:22:56.328887 2026] [security2:error] [pid 727775:tid 727962] [client 172.213.232.128:21016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuIcMDCZkc4BvDXnoDNHgAAADk"]
[Thu Jul 30 12:22:56.450417 2026] [security2:error] [pid 727775:tid 727955] [client 142.93.53.183:50228] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/foto_alumni/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIcMDCZkc4BvDXnoDNIgAAADI"]
[Thu Jul 30 12:22:56.831330 2026] [security2:error] [pid 727775:tid 727920] [client 142.93.53.183:50422] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/editor/themes/advanced/docs/en/images/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIcMDCZkc4BvDXnoDNLAAAAA8"]
[Thu Jul 30 12:22:56.929766 2026] [security2:error] [pid 727775:tid 727938] [client 51.116.238.8:4996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-ws68.php"] [unique_id "amuIcMDCZkc4BvDXnoDNLQAAACE"]
[Thu Jul 30 12:22:56.929915 2026] [security2:error] [pid 727775:tid 727938] [client 51.116.238.8:4996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/wp-ws68.php"] [unique_id "amuIcMDCZkc4BvDXnoDNLQAAACE"]
[Thu Jul 30 12:22:57.181890 2026] [security2:error] [pid 727775:tid 728011] [client 172.213.232.128:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuIccDCZkc4BvDXnoDNNQAAAGo"]
[Thu Jul 30 12:22:57.208168 2026] [security2:error] [pid 727775:tid 727928] [client 142.93.53.183:50643] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/editor/themes/advanced/docs/en/images/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIccDCZkc4BvDXnoDNNgAAABc"]
[Thu Jul 30 12:22:57.447224 2026] [security2:error] [pid 727775:tid 728013] [client 51.116.238.8:5030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/mgrr.php"] [unique_id "amuIccDCZkc4BvDXnoDNNwAAAGw"]
[Thu Jul 30 12:22:57.447377 2026] [security2:error] [pid 727775:tid 728013] [client 51.116.238.8:5030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/mgrr.php"] [unique_id "amuIccDCZkc4BvDXnoDNNwAAAGw"]
[Thu Jul 30 12:22:57.532213 2026] [security2:error] [pid 727775:tid 727978] [client 20.91.199.21:47244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/defaults.php"] [unique_id "amuIccDCZkc4BvDXnoDNPAAAAEk"]
[Thu Jul 30 12:22:57.596876 2026] [security2:error] [pid 727775:tid 727954] [client 142.93.53.183:50838] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/editor/themes/advanced/docs/en/images/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIccDCZkc4BvDXnoDNQAAAADE"]
[Thu Jul 30 12:22:57.665012 2026] [security2:error] [pid 727775:tid 727937] [client 195.113.175.167:58021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.175.113.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/youthf.php"] [unique_id "amuIccDCZkc4BvDXnoDNQQAAACA"]
[Thu Jul 30 12:22:57.994768 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:51043] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIccDCZkc4BvDXnoDNRgAAAAg"]
[Thu Jul 30 12:22:58.057745 2026] [security2:error] [pid 727775:tid 727951] [client 47.128.121.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuIccDCZkc4BvDXnoDNRQAAAC4"]
[Thu Jul 30 12:22:58.271400 2026] [security2:error] [pid 727775:tid 727925] [client 51.116.238.8:5051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/55.php"] [unique_id "amuIcsDCZkc4BvDXnoDNTwAAABQ"]
[Thu Jul 30 12:22:58.271504 2026] [security2:error] [pid 727775:tid 727925] [client 51.116.238.8:5051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "milfordauto.com"] [uri "/55.php"] [unique_id "amuIcsDCZkc4BvDXnoDNTwAAABQ"]
[Thu Jul 30 12:22:58.459388 2026] [security2:error] [pid 727775:tid 728025] [client 20.91.199.21:47283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/gtc.php"] [unique_id "amuIcsDCZkc4BvDXnoDNUAAAAHg"]
[Thu Jul 30 12:22:58.506904 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:51317] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIcsDCZkc4BvDXnoDNUQAAAF0"]
[Thu Jul 30 12:22:58.535638 2026] [security2:error] [pid 727775:tid 727990] [client 68.67.112.68:17096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alseermarine.com"] [uri "/robots.txt"] [unique_id "amuIcsDCZkc4BvDXnoDNUgAAAFU"]
[Thu Jul 30 12:22:58.864252 2026] [core:notice] [pid 727775:tid 727802] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:22:59.000217 2026] [security2:error] [pid 727775:tid 728010] [client 172.213.232.128:21027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuIcsDCZkc4BvDXnoDNWgAAAGk"]
[Thu Jul 30 12:22:59.010242 2026] [security2:error] [pid 727775:tid 728014] [client 142.93.53.183:51577] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIc8DCZkc4BvDXnoDNWwAAAG0"]
[Thu Jul 30 12:22:59.417225 2026] [security2:error] [pid 727775:tid 727915] [client 142.93.53.183:51737] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/librari/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIc8DCZkc4BvDXnoDNYgAAAAo"]
[Thu Jul 30 12:22:59.809419 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:51948] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/librari/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIc8DCZkc4BvDXnoDNbAAAAG4"]
[Thu Jul 30 12:22:59.817410 2026] [security2:error] [pid 727775:tid 727929] [client 20.91.199.21:47264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/import.php"] [unique_id "amuIc8DCZkc4BvDXnoDNbQAAABg"]
[Thu Jul 30 12:23:00.210324 2026] [security2:error] [pid 727775:tid 728026] [client 142.93.53.183:52132] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/librari/PHPExcel/Documentation/markdown/CalculationEngine/FunctionReference/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIdMDCZkc4BvDXnoDNcwAAAHk"]
[Thu Jul 30 12:23:00.258518 2026] [autoindex:error] [pid 727775:tid 727928] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:23:00.258881 2026] [autoindex:error] [pid 727775:tid 728022] [client 2a09:bac0:1000:c48::2db:d9:0] AH01276: Cannot serve directory /home2/mbmudite/ok.tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:23:00.271678 2026] [autoindex:error] [pid 727775:tid 727978] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:23:00.272106 2026] [autoindex:error] [pid 727775:tid 727972] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:23:00.333744 2026] [autoindex:error] [pid 727775:tid 727993] [client 2a09:bac0:1000:c48::2db:d9:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.tiger388.shop.
[Thu Jul 30 12:23:00.340095 2026] [autoindex:error] [pid 727775:tid 728032] [client 2a09:bac0:1000:c48::2db:d9:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.tiger388.shop.
[Thu Jul 30 12:23:00.352762 2026] [autoindex:error] [pid 727775:tid 727973] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://tiger388.shop.
[Thu Jul 30 12:23:00.366783 2026] [autoindex:error] [pid 727775:tid 728027] [client 2a09:bac0:1000:c48::2e9:73:0] AH01276: Cannot serve directory /home2/mbmudite/ok.tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.tiger388.shop.
[Thu Jul 30 12:23:00.510630 2026] [security2:error] [pid 727775:tid 727800] [remote 216.73.216.152:14970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIdMDCZkc4BvDXnoDNkQAALhg"]
[Thu Jul 30 12:23:00.590757 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:52308] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/seboettg/citeproc-php/src/Seboettg/CiteProc/Rendering/Choose/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIdMDCZkc4BvDXnoDNkgAAAD8"]
[Thu Jul 30 12:23:00.985686 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:52495] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/seboettg/citeproc-php/src/Seboettg/CiteProc/Rendering/Choose/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIdMDCZkc4BvDXnoDNnAAAAHc"]
[Thu Jul 30 12:23:01.213073 2026] [security2:error] [pid 727775:tid 727918] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIdMDCZkc4BvDXnoDNmQAADSI"]
[Thu Jul 30 12:23:01.380579 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:52696] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/citationStyleLanguage/lib/vendor/seboettg/citeproc-php/src/Seboettg/CiteProc/Rendering/Choose/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIdcDCZkc4BvDXnoDNpwAAABY"]
[Thu Jul 30 12:23:01.760813 2026] [security2:error] [pid 727775:tid 727998] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIdcDCZkc4BvDXnoDNoAAAAF0"]
[Thu Jul 30 12:23:01.795079 2026] [security2:error] [pid 727775:tid 727931] [client 142.93.53.183:52862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/OJS/files/temp/505/alfacgiapi/perl.alfa"] [unique_id "amuIdcDCZkc4BvDXnoDNsAAAABo"]
[Thu Jul 30 12:23:02.278483 2026] [security2:error] [pid 727775:tid 727908] [client 142.93.53.183:53072] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/temp/505/alfacgiapi/perl.alfa"] [unique_id "amuIdsDCZkc4BvDXnoDNtgAAAAM"]
[Thu Jul 30 12:23:02.483050 2026] [security2:error] [pid 727775:tid 727957] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIdsDCZkc4BvDXnoDNsgAANB0"]
[Thu Jul 30 12:23:02.517222 2026] [security2:error] [pid 727775:tid 727913] [client 20.91.199.21:47295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/lufix.php"] [unique_id "amuIdsDCZkc4BvDXnoDNuwAAAAg"]
[Thu Jul 30 12:23:02.687807 2026] [security2:error] [pid 727775:tid 728019] [client 176.29.242.55:2139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fi/product.php"] [unique_id "amuIdsDCZkc4BvDXnoDNugAAAHI"]
[Thu Jul 30 12:23:02.688326 2026] [security2:error] [pid 727775:tid 727920] [client 142.93.53.183:53256] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/OJS/files/temp/505/alfacgiapi/bash.alfa"] [unique_id "amuIdsDCZkc4BvDXnoDNvQAAAA8"]
[Thu Jul 30 12:23:03.072627 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:53424] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/temp/505/alfacgiapi/bash.alfa"] [unique_id "amuId8DCZkc4BvDXnoDNxAAAAB8"]
[Thu Jul 30 12:23:03.150264 2026] [security2:error] [pid 727775:tid 727986] [client 20.91.199.21:47643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/Geforce.php"] [unique_id "amuId8DCZkc4BvDXnoDNxwAAAFE"]
[Thu Jul 30 12:23:03.259901 2026] [security2:error] [pid 727775:tid 728001] [client 3.229.164.203:4795] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/88ab90a4828189a2b222831bbe60a3fd-400x196@2x.jpg"] [unique_id "amuId8DCZkc4BvDXnoDNyAAAAGA"]
[Thu Jul 30 12:23:03.486933 2026] [security2:error] [pid 727775:tid 727949] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuId8DCZkc4BvDXnoDNxgAALCo"]
[Thu Jul 30 12:23:03.529233 2026] [security2:error] [pid 727775:tid 728032] [client 142.93.53.183:53607] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/OJS/files/temp/505/alfacgiapi/py.alfa"] [unique_id "amuId8DCZkc4BvDXnoDN0QAAAH8"]
[Thu Jul 30 12:23:03.911665 2026] [security2:error] [pid 727775:tid 727914] [client 142.93.53.183:53765] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/temp/505/alfacgiapi/py.alfa"] [unique_id "amuId8DCZkc4BvDXnoDN1QAAAAk"]
[Thu Jul 30 12:23:04.113827 2026] [security2:error] [pid 727775:tid 727973] [client 20.91.199.21:47253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/a4.php"] [unique_id "amuIeMDCZkc4BvDXnoDN2gAAAEQ"]
[Thu Jul 30 12:23:04.291188 2026] [security2:error] [pid 727775:tid 728005] [client 142.93.53.183:53921] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/themes/bootstrap3/bootstrap/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIeMDCZkc4BvDXnoDN3AAAAGQ"]
[Thu Jul 30 12:23:04.665066 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:54080] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/themes/bootstrap3/bootstrap/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIeMDCZkc4BvDXnoDN5AAAAFY"]
[Thu Jul 30 12:23:05.043025 2026] [security2:error] [pid 727775:tid 728028] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIeMDCZkc4BvDXnoDN5QAAeyw"]
[Thu Jul 30 12:23:05.046875 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:54249] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/themes/bootstrap3/bootstrap/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIecDCZkc4BvDXnoDN7AAAAF0"]
[Thu Jul 30 12:23:05.335528 2026] [security2:error] [pid 727775:tid 727985] [client 20.91.199.21:47294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/accueil.php"] [unique_id "amuIecDCZkc4BvDXnoDN7QAAAFA"]
[Thu Jul 30 12:23:05.425667 2026] [security2:error] [pid 727775:tid 727988] [client 142.93.53.183:54413] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIecDCZkc4BvDXnoDN8QAAAFM"]
[Thu Jul 30 12:23:05.942967 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:54663] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIecDCZkc4BvDXnoDN_gAAAD8"]
[Thu Jul 30 12:23:05.980549 2026] [security2:error] [pid 727775:tid 728009] [client 20.91.199.21:46722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/dashboard.php"] [unique_id "amuIecDCZkc4BvDXnoDN_wAAAGg"]
[Thu Jul 30 12:23:06.015783 2026] [security2:error] [pid 727775:tid 728026] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIecDCZkc4BvDXnoDN-AAAeTI"]
[Thu Jul 30 12:23:06.044880 2026] [core:notice] [pid 727775:tid 728027] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:06.323701 2026] [security2:error] [pid 727775:tid 727821] [remote 216.73.216.152:25630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuIesDCZkc4BvDXnoDOBwAAIi0"]
[Thu Jul 30 12:23:06.338723 2026] [security2:error] [pid 727775:tid 727906] [client 142.93.53.183:54829] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIesDCZkc4BvDXnoDOCAAAAAE"]
[Thu Jul 30 12:23:06.548631 2026] [core:notice] [pid 727775:tid 727924] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:06.729659 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:54985] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jurnal/files/contexts/3/library/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIesDCZkc4BvDXnoDOEwAAACY"]
[Thu Jul 30 12:23:06.757961 2026] [security2:error] [pid 727775:tid 727921] [client 213.152.161.118:39154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuIesDCZkc4BvDXnoDOFAAAABA"]
[Thu Jul 30 12:23:06.758070 2026] [security2:error] [pid 727775:tid 727921] [client 213.152.161.118:39154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuIesDCZkc4BvDXnoDOFAAAABA"]
[Thu Jul 30 12:23:07.062721 2026] [security2:error] [pid 727775:tid 727909] [client 185.191.171.12:13284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/14/beneficiarios-com-nis-final-3-recebem-nesta-quarta-14-auxilio-brasil/"] [unique_id "amuIe8DCZkc4BvDXnoDOGwAAAAQ"]
[Thu Jul 30 12:23:07.062859 2026] [security2:error] [pid 727775:tid 727909] [client 185.191.171.12:13284] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/14/beneficiarios-com-nis-final-3-recebem-nesta-quarta-14-auxilio-brasil/"] [unique_id "amuIe8DCZkc4BvDXnoDOGwAAAAQ"]
[Thu Jul 30 12:23:07.112756 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:55154] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jurnal/files/contexts/3/library/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuIe8DCZkc4BvDXnoDOHwAAAC0"]
[Thu Jul 30 12:23:07.436555 2026] [security2:error] [pid 727775:tid 727985] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIe8DCZkc4BvDXnoDOIAAAUEk"]
[Thu Jul 30 12:23:07.501528 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:55301] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jurnal/files/contexts/3/library/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIe8DCZkc4BvDXnoDOJQAAAG4"]
[Thu Jul 30 12:23:07.900092 2026] [security2:error] [pid 727775:tid 727986] [client 142.93.53.183:55487] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuIe8DCZkc4BvDXnoDOKgAAAFE"]
[Thu Jul 30 12:23:07.957281 2026] [security2:error] [pid 727775:tid 727970] [client 172.213.232.128:4824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuIe8DCZkc4BvDXnoDOLgAAAEE"]
[Thu Jul 30 12:23:08.279485 2026] [security2:error] [pid 727775:tid 727976] [client 142.93.53.183:55665] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuIfMDCZkc4BvDXnoDOMgAAAEc"]
[Thu Jul 30 12:23:08.645524 2026] [security2:error] [pid 727775:tid 727959] [client 20.91.199.21:47620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/radio.php"] [unique_id "amuIfMDCZkc4BvDXnoDOOAAAADY"]
[Thu Jul 30 12:23:08.676322 2026] [security2:error] [pid 727775:tid 728026] [client 142.93.53.183:55842] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuIfMDCZkc4BvDXnoDOPAAAAHk"]
[Thu Jul 30 12:23:08.677671 2026] [security2:error] [pid 727775:tid 727993] [client 172.213.232.128:8400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuIfMDCZkc4BvDXnoDOPQAAAFg"]
[Thu Jul 30 12:23:09.060437 2026] [security2:error] [pid 727775:tid 727911] [client 142.93.53.183:56016] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIfcDCZkc4BvDXnoDOQQAAAAY"]
[Thu Jul 30 12:23:09.419414 2026] [security2:error] [pid 727775:tid 728031] [client 172.202.44.182:48415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wk/index.php"] [unique_id "amuIfcDCZkc4BvDXnoDORwAAAH4"]
[Thu Jul 30 12:23:09.451064 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:56188] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIfcDCZkc4BvDXnoDOSAAAACM"]
[Thu Jul 30 12:23:09.489825 2026] [security2:error] [pid 727775:tid 728021] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIfcDCZkc4BvDXnoDOQgAAdEU"]
[Thu Jul 30 12:23:09.839062 2026] [security2:error] [pid 727775:tid 727962] [client 142.93.53.183:56370] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/header/.tmb/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIfcDCZkc4BvDXnoDOTwAAADk"]
[Thu Jul 30 12:23:10.079619 2026] [security2:error] [pid 727775:tid 727851] [remote 47.128.28.104:16464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moncler-jacket-39/"] [unique_id "amuIfsDCZkc4BvDXnoDOVQAAA0s"]
[Thu Jul 30 12:23:10.123556 2026] [security2:error] [pid 727775:tid 728020] [client 172.237.109.114:20205] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amuIfsDCZkc4BvDXnoDOXQAAAHM"]
[Thu Jul 30 12:23:10.150737 2026] [security2:error] [pid 727775:tid 727947] [client 172.237.109.114:49833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amuIfsDCZkc4BvDXnoDOYQAAACo"]
[Thu Jul 30 12:23:10.234361 2026] [security2:error] [pid 727775:tid 727979] [client 142.93.53.183:56531] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/litespeed-cache/alfacgiapi/perl.alfa"] [unique_id "amuIfsDCZkc4BvDXnoDOYgAAAEo"]
[Thu Jul 30 12:23:10.502521 2026] [core:notice] [pid 727775:tid 727919] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:10.628436 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:56705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIfsDCZkc4BvDXnoDOagAAAB8"]
[Thu Jul 30 12:23:10.676172 2026] [security2:error] [pid 727775:tid 727956] [client 172.237.109.114:56185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOVAAAADM"]
[Thu Jul 30 12:23:10.749505 2026] [security2:error] [pid 727775:tid 727981] [client 172.237.109.114:41784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOXAAAAEw"]
[Thu Jul 30 12:23:10.758156 2026] [security2:error] [pid 727775:tid 728007] [client 172.237.109.114:23833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOWAAAAGY"]
[Thu Jul 30 12:23:10.765441 2026] [security2:error] [pid 727775:tid 727944] [client 172.237.109.114:34614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOVwAAACc"]
[Thu Jul 30 12:23:10.773383 2026] [security2:error] [pid 727775:tid 727997] [client 172.237.109.114:55271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOWQAAAFw"]
[Thu Jul 30 12:23:10.775576 2026] [security2:error] [pid 727775:tid 727955] [client 172.237.109.114:43117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOVgAAADI"]
[Thu Jul 30 12:23:10.775617 2026] [security2:error] [pid 727775:tid 727915] [client 172.237.109.114:51749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOWwAAAAo"]
[Thu Jul 30 12:23:10.792808 2026] [security2:error] [pid 727775:tid 728003] [client 172.237.109.114:62701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOWgAAAGI"]
[Thu Jul 30 12:23:10.833378 2026] [security2:error] [pid 727775:tid 727909] [client 172.237.109.114:41327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOYAAAAAQ"]
[Thu Jul 30 12:23:10.840078 2026] [security2:error] [pid 727775:tid 727905] [client 172.237.109.114:56569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOXgAAAAA"]
[Thu Jul 30 12:23:11.014817 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:56876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/WOLFSHELL/razorcgiapi/perl.haxor"] [unique_id "amuIf8DCZkc4BvDXnoDOcgAAAA0"]
[Thu Jul 30 12:23:11.033241 2026] [security2:error] [pid 727775:tid 727983] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIfsDCZkc4BvDXnoDOawAATmU"]
[Thu Jul 30 12:23:11.438247 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:57075] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/WOLFSHELL/razorcgiapi/py.haxor"] [unique_id "amuIf8DCZkc4BvDXnoDOegAAADo"]
[Thu Jul 30 12:23:11.664049 2026] [security2:error] [pid 727775:tid 727971] [client 172.213.232.128:23030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuIf8DCZkc4BvDXnoDOfwAAAEI"]
[Thu Jul 30 12:23:11.775689 2026] [security2:error] [pid 727775:tid 727995] [client 91.92.41.115:52131] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ojq.udi.temporary.site"] [uri "/.env"] [unique_id "amuIf8DCZkc4BvDXnoDOgAAAAFo"]
[Thu Jul 30 12:23:11.840814 2026] [security2:error] [pid 727775:tid 728021] [client 142.93.53.183:57251] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/WOLFSHELL/razorcgiapi/bash.haxor"] [unique_id "amuIf8DCZkc4BvDXnoDOhAAAAHQ"]
[Thu Jul 30 12:23:12.227400 2026] [security2:error] [pid 727775:tid 727990] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIf8DCZkc4BvDXnoDOiAAAVXY"]
[Thu Jul 30 12:23:12.241097 2026] [security2:error] [pid 727775:tid 728023] [client 142.93.53.183:57429] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/fields/WOLFSHELL/razorcgiapi/perl.haxor"] [unique_id "amuIgMDCZkc4BvDXnoDOjQAAAHY"]
[Thu Jul 30 12:23:12.483888 2026] [security2:error] [pid 727775:tid 728014] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIf8DCZkc4BvDXnoDOhwAAAG0"]
[Thu Jul 30 12:23:12.492088 2026] [security2:error] [pid 727775:tid 728028] [client 192.178.15.67:42505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuIgMDCZkc4BvDXnoDOkQAAAHs"]
[Thu Jul 30 12:23:12.625655 2026] [security2:error] [pid 727775:tid 727957] [client 142.93.53.183:57593] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/fields/WOLFSHELL/razorcgiapi/py.haxor"] [unique_id "amuIgMDCZkc4BvDXnoDOlAAAADQ"]
[Thu Jul 30 12:23:12.897694 2026] [security2:error] [pid 727775:tid 727927] [client 20.91.199.21:47242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wpsml-sys.php"] [unique_id "amuIgMDCZkc4BvDXnoDOnAAAABY"]
[Thu Jul 30 12:23:12.907764 2026] [security2:error] [pid 727775:tid 727908] [client 172.202.44.182:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/av.php"] [unique_id "amuIgMDCZkc4BvDXnoDOngAAAAM"]
[Thu Jul 30 12:23:13.007196 2026] [security2:error] [pid 727775:tid 727981] [client 142.93.53.183:57754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/fields/WOLFSHELL/razorcgiapi/bash.haxor"] [unique_id "amuIgcDCZkc4BvDXnoDOnwAAAEw"]
[Thu Jul 30 12:23:13.239036 2026] [security2:error] [pid 727775:tid 727938] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIgMDCZkc4BvDXnoDOnQAAIWY"]
[Thu Jul 30 12:23:13.545105 2026] [security2:error] [pid 727775:tid 727972] [client 142.93.53.183:57957] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/alfacgiapi/perl.alfa"] [unique_id "amuIgcDCZkc4BvDXnoDOqQAAAEM"]
[Thu Jul 30 12:23:13.757305 2026] [security2:error] [pid 727775:tid 727955] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIgcDCZkc4BvDXnoDOogAAADI"]
[Thu Jul 30 12:23:13.780122 2026] [security2:error] [pid 727775:tid 728001] [client 20.91.199.21:47669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/02.php"] [unique_id "amuIgcDCZkc4BvDXnoDOqgAAAGA"]
[Thu Jul 30 12:23:13.926218 2026] [security2:error] [pid 727775:tid 727974] [client 142.93.53.183:58129] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/hello-elementor/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIgcDCZkc4BvDXnoDOsAAAAEU"]
[Thu Jul 30 12:23:13.957777 2026] [security2:error] [pid 727775:tid 727931] [client 172.213.232.128:7918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuIgcDCZkc4BvDXnoDOsQAAABo"]
[Thu Jul 30 12:23:14.016115 2026] [security2:error] [pid 727775:tid 727886] [remote 54.37.118.86:22126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dhowcruisedinner.com"] [uri "/marina-glass-boat.html"] [unique_id "amuIgsDCZkc4BvDXnoDOswAAIG4"]
[Thu Jul 30 12:23:14.016275 2026] [security2:error] [pid 727775:tid 727937] [client 54.37.118.86:22126] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dhowcruisedinner.com"] [uri "/marina-glass-boat.html"] [unique_id "amuIgsDCZkc4BvDXnoDOswAAIG4"]
[Thu Jul 30 12:23:14.308131 2026] [security2:error] [pid 727775:tid 728013] [client 142.93.53.183:58305] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/hello-elementor/alfacgiapi/perl.alfa"] [unique_id "amuIgsDCZkc4BvDXnoDOuwAAAGw"]
[Thu Jul 30 12:23:14.363195 2026] [security2:error] [pid 727775:tid 728009] [client 20.91.199.21:47262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/infos.php"] [unique_id "amuIgsDCZkc4BvDXnoDOvQAAAGg"]
[Thu Jul 30 12:23:14.702765 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:58482] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyone/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIgsDCZkc4BvDXnoDOxQAAAFc"]
[Thu Jul 30 12:23:15.061819 2026] [security2:error] [pid 727775:tid 727940] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIgsDCZkc4BvDXnoDOxgAAI2M"]
[Thu Jul 30 12:23:15.112430 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:58665] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyone/alfacgiapi/perl.alfa"] [unique_id "amuIg8DCZkc4BvDXnoDOywAAAC0"]
[Thu Jul 30 12:23:15.187326 2026] [security2:error] [pid 727775:tid 727968] [client 172.202.44.182:48387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/mini.php"] [unique_id "amuIg8DCZkc4BvDXnoDOzwAAAD8"]
[Thu Jul 30 12:23:15.466604 2026] [security2:error] [pid 727775:tid 727960] [client 185.191.171.2:16088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/30/policia-prende-grupo-suspeito-de-traficar-drogas-da-bolivia-em-joao-pessoa/"] [unique_id "amuIg8DCZkc4BvDXnoDO1AAAADc"]
[Thu Jul 30 12:23:15.466761 2026] [security2:error] [pid 727775:tid 727960] [client 185.191.171.2:16088] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/30/policia-prende-grupo-suspeito-de-traficar-drogas-da-bolivia-em-joao-pessoa/"] [unique_id "amuIg8DCZkc4BvDXnoDO1AAAADc"]
[Thu Jul 30 12:23:15.508551 2026] [security2:error] [pid 727775:tid 727920] [client 142.93.53.183:58841] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentythree/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIg8DCZkc4BvDXnoDO1QAAAA8"]
[Thu Jul 30 12:23:15.908737 2026] [security2:error] [pid 727775:tid 727915] [client 142.93.53.183:59012] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentythree/alfacgiapi/perl.alfa"] [unique_id "amuIg8DCZkc4BvDXnoDO4wAAAAo"]
[Thu Jul 30 12:23:16.052746 2026] [security2:error] [pid 727775:tid 727913] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIg8DCZkc4BvDXnoDO2QAACHk"]
[Thu Jul 30 12:23:16.180543 2026] [security2:error] [pid 727775:tid 727978] [client 172.213.232.128:7924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuIhMDCZkc4BvDXnoDO6wAAAEk"]
[Thu Jul 30 12:23:16.312208 2026] [security2:error] [pid 727775:tid 727931] [client 142.93.53.183:59191] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentytwo/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIhMDCZkc4BvDXnoDO7wAAABo"]
[Thu Jul 30 12:23:16.692431 2026] [security2:error] [pid 727775:tid 727966] [client 142.93.53.183:59367] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentytwo/alfacgiapi/perl.alfa"] [unique_id "amuIhMDCZkc4BvDXnoDO-QAAAD0"]
[Thu Jul 30 12:23:16.806520 2026] [security2:error] [pid 727775:tid 727941] [client 172.213.232.128:8841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuIhMDCZkc4BvDXnoDO-gAAACQ"]
[Thu Jul 30 12:23:16.863333 2026] [security2:error] [pid 727775:tid 727989] [client 20.91.199.21:47636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/updates.php"] [unique_id "amuIhMDCZkc4BvDXnoDO_gAAAFQ"]
[Thu Jul 30 12:23:17.084771 2026] [security2:error] [pid 727775:tid 727971] [client 142.93.53.183:59545] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/upgrade/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIhcDCZkc4BvDXnoDO_wAAAEI"]
[Thu Jul 30 12:23:17.302114 2026] [security2:error] [pid 727775:tid 728013] [client 172.202.44.182:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/aa.php"] [unique_id "amuIhcDCZkc4BvDXnoDPBQAAAGw"]
[Thu Jul 30 12:23:17.462354 2026] [security2:error] [pid 727775:tid 727982] [client 142.93.53.183:59716] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/upgrade/alfacgiapi/perl.alfa"] [unique_id "amuIhcDCZkc4BvDXnoDPCwAAAE0"]
[Thu Jul 30 12:23:17.509441 2026] [security2:error] [pid 727775:tid 728024] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIhcDCZkc4BvDXnoDPAAAAdyc"]
[Thu Jul 30 12:23:17.742428 2026] [security2:error] [pid 727775:tid 727991] [client 20.91.199.21:47281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/user.php"] [unique_id "amuIhcDCZkc4BvDXnoDPDwAAAFY"]
[Thu Jul 30 12:23:18.077807 2026] [security2:error] [pid 727775:tid 727961] [client 142.93.53.183:59993] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIhsDCZkc4BvDXnoDPFAAAADg"]
[Thu Jul 30 12:23:18.461746 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:60171] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/alfacgiapi/perl.alfa"] [unique_id "amuIhsDCZkc4BvDXnoDPHQAAAGY"]
[Thu Jul 30 12:23:18.492298 2026] [security2:error] [pid 727775:tid 727957] [client 20.91.199.21:47666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/admin-ajax.php"] [unique_id "amuIhsDCZkc4BvDXnoDPHwAAADQ"]
[Thu Jul 30 12:23:18.494336 2026] [security2:error] [pid 727775:tid 728028] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIhsDCZkc4BvDXnoDPFQAAexg"]
[Thu Jul 30 12:23:18.501689 2026] [security2:error] [pid 727775:tid 727979] [client 172.202.44.182:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/w.php"] [unique_id "amuIhsDCZkc4BvDXnoDPIAAAAEo"]
[Thu Jul 30 12:23:18.863945 2026] [security2:error] [pid 727775:tid 727958] [client 142.93.53.183:60347] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/01/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIhsDCZkc4BvDXnoDPJQAAADU"]
[Thu Jul 30 12:23:19.092578 2026] [security2:error] [pid 727775:tid 727977] [client 20.91.199.21:47240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/alfa.php"] [unique_id "amuIh8DCZkc4BvDXnoDPKQAAAEg"]
[Thu Jul 30 12:23:19.244832 2026] [security2:error] [pid 727775:tid 727930] [client 172.213.232.128:23005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuIh8DCZkc4BvDXnoDPKwAAABk"]
[Thu Jul 30 12:23:19.366747 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:60590] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/01/alfacgiapi/perl.alfa"] [unique_id "amuIh8DCZkc4BvDXnoDPLwAAAF4"]
[Thu Jul 30 12:23:19.750893 2026] [security2:error] [pid 727775:tid 727916] [client 142.93.53.183:60755] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/02/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIh8DCZkc4BvDXnoDPNAAAAAs"]
[Thu Jul 30 12:23:19.974403 2026] [security2:error] [pid 727775:tid 727949] [client 172.213.232.128:22668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/banners/about.php"] [unique_id "amuIh8DCZkc4BvDXnoDPOAAAACw"]
[Thu Jul 30 12:23:20.109372 2026] [security2:error] [pid 727775:tid 727952] [client 172.202.44.182:53137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/admin.php"] [unique_id "amuIiMDCZkc4BvDXnoDPPgAAAC8"]
[Thu Jul 30 12:23:20.138181 2026] [security2:error] [pid 727775:tid 727973] [client 142.93.53.183:60913] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/02/alfacgiapi/perl.alfa"] [unique_id "amuIiMDCZkc4BvDXnoDPPwAAAEQ"]
[Thu Jul 30 12:23:20.456676 2026] [security2:error] [pid 727775:tid 727954] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIiMDCZkc4BvDXnoDPQAAAMSA"]
[Thu Jul 30 12:23:20.517043 2026] [security2:error] [pid 727775:tid 728006] [client 142.93.53.183:61105] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/03/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIiMDCZkc4BvDXnoDPSAAAAGU"]
[Thu Jul 30 12:23:20.899525 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:61294] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/03/alfacgiapi/perl.alfa"] [unique_id "amuIiMDCZkc4BvDXnoDPVAAAAD8"]
[Thu Jul 30 12:23:21.095415 2026] [security2:error] [pid 727775:tid 728017] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuIicDCZkc4BvDXnoDPWgAAAHA"]
[Thu Jul 30 12:23:21.095510 2026] [security2:error] [pid 727775:tid 728017] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuIicDCZkc4BvDXnoDPWgAAAHA"]
[Thu Jul 30 12:23:21.295537 2026] [security2:error] [pid 727775:tid 727979] [client 142.93.53.183:61476] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/04/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIicDCZkc4BvDXnoDPWwAAAEo"]
[Thu Jul 30 12:23:21.337698 2026] [security2:error] [pid 727775:tid 728003] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuIicDCZkc4BvDXnoDPXQAAAGI"]
[Thu Jul 30 12:23:21.337786 2026] [security2:error] [pid 727775:tid 728003] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuIicDCZkc4BvDXnoDPXQAAAGI"]
[Thu Jul 30 12:23:21.359419 2026] [security2:error] [pid 727775:tid 727820] [remote 57.141.0.54:55820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuIicDCZkc4BvDXnoDPXwAAFiw"]
[Thu Jul 30 12:23:21.586608 2026] [security2:error] [pid 727775:tid 728019] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/xstelth.php"] [unique_id "amuIicDCZkc4BvDXnoDPZwAAAHI"]
[Thu Jul 30 12:23:21.586717 2026] [security2:error] [pid 727775:tid 728019] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/xstelth.php"] [unique_id "amuIicDCZkc4BvDXnoDPZwAAAHI"]
[Thu Jul 30 12:23:21.589400 2026] [security2:error] [pid 727775:tid 728025] [client 172.202.44.182:52775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuIicDCZkc4BvDXnoDPaAAAAHg"]
[Thu Jul 30 12:23:21.687081 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:61647] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/04/alfacgiapi/perl.alfa"] [unique_id "amuIicDCZkc4BvDXnoDPagAAACc"]
[Thu Jul 30 12:23:21.820263 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuIicDCZkc4BvDXnoDPawAAAF4"]
[Thu Jul 30 12:23:21.820423 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuIicDCZkc4BvDXnoDPawAAAF4"]
[Thu Jul 30 12:23:22.077389 2026] [security2:error] [pid 727775:tid 727932] [client 142.93.53.183:61825] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/05/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIisDCZkc4BvDXnoDPcAAAABs"]
[Thu Jul 30 12:23:22.092479 2026] [security2:error] [pid 727775:tid 728031] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/newfile.php"] [unique_id "amuIisDCZkc4BvDXnoDPcQAAAH4"]
[Thu Jul 30 12:23:22.092574 2026] [security2:error] [pid 727775:tid 728031] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/newfile.php"] [unique_id "amuIisDCZkc4BvDXnoDPcQAAAH4"]
[Thu Jul 30 12:23:22.327337 2026] [security2:error] [pid 727775:tid 727966] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tBEZGQz.php"] [unique_id "amuIisDCZkc4BvDXnoDPdwAAAD0"]
[Thu Jul 30 12:23:22.327449 2026] [security2:error] [pid 727775:tid 727966] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tBEZGQz.php"] [unique_id "amuIisDCZkc4BvDXnoDPdwAAAD0"]
[Thu Jul 30 12:23:22.460605 2026] [security2:error] [pid 727775:tid 727989] [client 142.93.53.183:62005] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/05/alfacgiapi/perl.alfa"] [unique_id "amuIisDCZkc4BvDXnoDPeAAAAFQ"]
[Thu Jul 30 12:23:22.471138 2026] [security2:error] [pid 727775:tid 727934] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIisDCZkc4BvDXnoDPdgAAHT8"]
[Thu Jul 30 12:23:22.592014 2026] [core:error] [pid 727775:tid 727984] [client 20.91.199.21:47239] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:23:22.592034 2026] [core:error] [pid 727775:tid 727984] [client 20.91.199.21:47239] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:23:22.644372 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/phpinfo"] [unique_id "amuIisDCZkc4BvDXnoDPgQAAAG8"]
[Thu Jul 30 12:23:22.775572 2026] [security2:error] [pid 727775:tid 727946] [client 172.213.232.128:8321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/about.php"] [unique_id "amuIisDCZkc4BvDXnoDPggAAACk"]
[Thu Jul 30 12:23:22.838865 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:62177] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/06/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIisDCZkc4BvDXnoDPgwAAAFc"]
[Thu Jul 30 12:23:22.898903 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/drykl.php"] [unique_id "amuIisDCZkc4BvDXnoDPhAAAADs"]
[Thu Jul 30 12:23:22.899014 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/drykl.php"] [unique_id "amuIisDCZkc4BvDXnoDPhAAAADs"]
[Thu Jul 30 12:23:23.080824 2026] [security2:error] [pid 727775:tid 727969] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/blue/"] [unique_id "amuIi8DCZkc4BvDXnoDPiAAAAEA"]
[Thu Jul 30 12:23:23.232780 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:62344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/06/alfacgiapi/perl.alfa"] [unique_id "amuIi8DCZkc4BvDXnoDPjQAAAC0"]
[Thu Jul 30 12:23:23.349474 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ls.php"] [unique_id "amuIi8DCZkc4BvDXnoDPjgAAACM"]
[Thu Jul 30 12:23:23.349625 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ls.php"] [unique_id "amuIi8DCZkc4BvDXnoDPjgAAACM"]
[Thu Jul 30 12:23:23.510501 2026] [security2:error] [pid 727775:tid 728014] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/dx.php"] [unique_id "amuIi8DCZkc4BvDXnoDPkgAAAG0"]
[Thu Jul 30 12:23:23.510599 2026] [security2:error] [pid 727775:tid 728014] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/dx.php"] [unique_id "amuIi8DCZkc4BvDXnoDPkgAAAG0"]
[Thu Jul 30 12:23:23.617623 2026] [security2:error] [pid 727775:tid 727929] [client 142.93.53.183:62529] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/07/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIi8DCZkc4BvDXnoDPlwAAABg"]
[Thu Jul 30 12:23:23.727673 2026] [security2:error] [pid 727775:tid 727947] [client 172.213.232.128:8330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/.well-known/about.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmAAAACo"]
[Thu Jul 30 12:23:23.780039 2026] [security2:error] [pid 727775:tid 727987] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmQAAAFI"]
[Thu Jul 30 12:23:23.780142 2026] [security2:error] [pid 727775:tid 727987] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmQAAAFI"]
[Thu Jul 30 12:23:23.922516 2026] [security2:error] [pid 727775:tid 728003] [client 213.152.161.118:36648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmgAAAGI"]
[Thu Jul 30 12:23:23.922612 2026] [security2:error] [pid 727775:tid 728003] [client 213.152.161.118:36648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIi8DCZkc4BvDXnoDPmgAAAGI"]
[Thu Jul 30 12:23:24.037221 2026] [security2:error] [pid 727775:tid 727957] [client 20.91.199.21:47273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/hehe.php"] [unique_id "amuIjMDCZkc4BvDXnoDPngAAADQ"]
[Thu Jul 30 12:23:24.077464 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/485.php"] [unique_id "amuIjMDCZkc4BvDXnoDPnwAAACE"]
[Thu Jul 30 12:23:24.077583 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/485.php"] [unique_id "amuIjMDCZkc4BvDXnoDPnwAAACE"]
[Thu Jul 30 12:23:24.191099 2026] [security2:error] [pid 727775:tid 727955] [client 142.93.53.183:62820] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/07/alfacgiapi/perl.alfa"] [unique_id "amuIjMDCZkc4BvDXnoDPowAAADI"]
[Thu Jul 30 12:23:24.314321 2026] [security2:error] [pid 727775:tid 728011] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gelio1.php"] [unique_id "amuIjMDCZkc4BvDXnoDPpgAAAGo"]
[Thu Jul 30 12:23:24.314433 2026] [security2:error] [pid 727775:tid 728011] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gelio1.php"] [unique_id "amuIjMDCZkc4BvDXnoDPpgAAAGo"]
[Thu Jul 30 12:23:24.578047 2026] [security2:error] [pid 727775:tid 727905] [client 142.93.53.183:62970] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/08/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIjMDCZkc4BvDXnoDPrAAAAAA"]
[Thu Jul 30 12:23:24.641496 2026] [security2:error] [pid 727775:tid 727974] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/lp6.php"] [unique_id "amuIjMDCZkc4BvDXnoDPrgAAAEU"]
[Thu Jul 30 12:23:24.641609 2026] [security2:error] [pid 727775:tid 727974] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/lp6.php"] [unique_id "amuIjMDCZkc4BvDXnoDPrgAAAEU"]
[Thu Jul 30 12:23:24.870794 2026] [security2:error] [pid 727775:tid 727981] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIjMDCZkc4BvDXnoDPqwAATFQ"]
[Thu Jul 30 12:23:24.876838 2026] [security2:error] [pid 727775:tid 727959] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuIjMDCZkc4BvDXnoDPsgAAADY"]
[Thu Jul 30 12:23:24.876956 2026] [security2:error] [pid 727775:tid 727959] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuIjMDCZkc4BvDXnoDPsgAAADY"]
[Thu Jul 30 12:23:24.914443 2026] [security2:error] [pid 727775:tid 728025] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIjMDCZkc4BvDXnoDPpQAAeEw"]
[Thu Jul 30 12:23:24.971070 2026] [security2:error] [pid 727775:tid 727917] [client 142.93.53.183:63161] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/08/alfacgiapi/perl.alfa"] [unique_id "amuIjMDCZkc4BvDXnoDPswAAAAw"]
[Thu Jul 30 12:23:25.205755 2026] [security2:error] [pid 727775:tid 727984] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/sodium_compat/"] [unique_id "amuIjcDCZkc4BvDXnoDPuwAAAE8"]
[Thu Jul 30 12:23:25.355684 2026] [security2:error] [pid 727775:tid 728006] [client 142.93.53.183:63353] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/09/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIjcDCZkc4BvDXnoDPwAAAAGU"]
[Thu Jul 30 12:23:25.370261 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuIjcDCZkc4BvDXnoDPwQAAAFU"]
[Thu Jul 30 12:23:25.370361 2026] [security2:error] [pid 727775:tid 727990] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuIjcDCZkc4BvDXnoDPwQAAAFU"]
[Thu Jul 30 12:23:25.505053 2026] [security2:error] [pid 727775:tid 728005] [client 20.91.199.21:47256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/rk2.php"] [unique_id "amuIjcDCZkc4BvDXnoDPwgAAAGQ"]
[Thu Jul 30 12:23:25.603101 2026] [security2:error] [pid 727775:tid 727973] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuIjcDCZkc4BvDXnoDPxwAAAEQ"]
[Thu Jul 30 12:23:25.603190 2026] [security2:error] [pid 727775:tid 727973] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuIjcDCZkc4BvDXnoDPxwAAAEQ"]
[Thu Jul 30 12:23:25.741386 2026] [security2:error] [pid 727775:tid 727935] [client 142.93.53.183:63553] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/09/alfacgiapi/perl.alfa"] [unique_id "amuIjcDCZkc4BvDXnoDPzQAAAB4"]
[Thu Jul 30 12:23:25.861418 2026] [security2:error] [pid 727775:tid 727929] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/autoload_classmap.php"] [unique_id "amuIjcDCZkc4BvDXnoDPzwAAABg"]
[Thu Jul 30 12:23:25.861551 2026] [security2:error] [pid 727775:tid 727929] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/autoload_classmap.php"] [unique_id "amuIjcDCZkc4BvDXnoDPzwAAABg"]
[Thu Jul 30 12:23:25.877642 2026] [security2:error] [pid 727775:tid 727948] [client 172.213.232.128:22978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/Text/about.php"] [unique_id "amuIjcDCZkc4BvDXnoDP0gAAACs"]
[Thu Jul 30 12:23:25.981081 2026] [security2:error] [pid 727775:tid 727921] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIjcDCZkc4BvDXnoDPyAAAEEs"]
[Thu Jul 30 12:23:26.181283 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:63754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/10/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIjsDCZkc4BvDXnoDP2AAAADw"]
[Thu Jul 30 12:23:26.581175 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:63941] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/10/alfacgiapi/perl.alfa"] [unique_id "amuIjsDCZkc4BvDXnoDP4gAAACA"]
[Thu Jul 30 12:23:26.978296 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:64134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/11/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIjsDCZkc4BvDXnoDP6gAAACw"]
[Thu Jul 30 12:23:27.331739 2026] [security2:error] [pid 727775:tid 727941] [client 20.91.199.21:47247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/setup-config.php"] [unique_id "amuIj8DCZkc4BvDXnoDP9wAAACQ"]
[Thu Jul 30 12:23:27.359318 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:64325] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/11/alfacgiapi/perl.alfa"] [unique_id "amuIj8DCZkc4BvDXnoDP-AAAAGc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:23:27.765751 2026] [security2:error] [pid 727775:tid 728002] [client 142.93.53.183:64494] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/12/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIj8DCZkc4BvDXnoDP_gAAAGE"]
[Thu Jul 30 12:23:28.150201 2026] [security2:error] [pid 727775:tid 727948] [client 172.213.232.128:8351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuIkMDCZkc4BvDXnoDQBQAAACs"]
[Thu Jul 30 12:23:28.160886 2026] [security2:error] [pid 727775:tid 727960] [client 142.93.53.183:64729] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2024/12/alfacgiapi/perl.alfa"] [unique_id "amuIkMDCZkc4BvDXnoDQBgAAADc"]
[Thu Jul 30 12:23:28.396360 2026] [security2:error] [pid 727775:tid 727972] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wp-content/"] [unique_id "amuIkMDCZkc4BvDXnoDQEQAAAEM"]
[Thu Jul 30 12:23:28.542029 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuIkMDCZkc4BvDXnoDQFAAAACE"]
[Thu Jul 30 12:23:28.542161 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuIkMDCZkc4BvDXnoDQFAAAACE"]
[Thu Jul 30 12:23:28.548027 2026] [security2:error] [pid 727775:tid 727970] [client 142.93.53.183:64938] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIkMDCZkc4BvDXnoDQFQAAAEE"]
[Thu Jul 30 12:23:28.774054 2026] [security2:error] [pid 727775:tid 728028] [client 20.91.199.21:47626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/a7.php"] [unique_id "amuIkMDCZkc4BvDXnoDQGwAAAHs"]
[Thu Jul 30 12:23:28.787401 2026] [security2:error] [pid 727775:tid 727965] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIkMDCZkc4BvDXnoDQEwAAPE4"]
[Thu Jul 30 12:23:28.824426 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/av.php"] [unique_id "amuIkMDCZkc4BvDXnoDQHQAAAAA"]
[Thu Jul 30 12:23:28.824510 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/av.php"] [unique_id "amuIkMDCZkc4BvDXnoDQHQAAAAA"]
[Thu Jul 30 12:23:28.938168 2026] [security2:error] [pid 727775:tid 727985] [client 142.93.53.183:65132] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/alfacgiapi/perl.alfa"] [unique_id "amuIkMDCZkc4BvDXnoDQIQAAAFA"]
[Thu Jul 30 12:23:29.054804 2026] [core:notice] [pid 727775:tid 727991] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:29.118628 2026] [security2:error] [pid 727775:tid 727975] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/l10n/"] [unique_id "amuIkcDCZkc4BvDXnoDQJAAAAEY"]
[Thu Jul 30 12:23:29.289678 2026] [security2:error] [pid 727775:tid 727959] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wordpress/wp-admin/maint/"] [unique_id "amuIkcDCZkc4BvDXnoDQKAAAADY"]
[Thu Jul 30 12:23:29.328734 2026] [security2:error] [pid 727775:tid 727989] [client 142.93.53.183:65328] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIkcDCZkc4BvDXnoDQLAAAAFQ"]
[Thu Jul 30 12:23:29.438486 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tiny.php"] [unique_id "amuIkcDCZkc4BvDXnoDQMgAAAAE"]
[Thu Jul 30 12:23:29.438577 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tiny.php"] [unique_id "amuIkcDCZkc4BvDXnoDQMgAAAAE"]
[Thu Jul 30 12:23:29.642451 2026] [security2:error] [pid 727775:tid 727919] [client 172.202.44.182:55808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/m.php"] [unique_id "amuIkcDCZkc4BvDXnoDQNQAAAA4"]
[Thu Jul 30 12:23:29.674787 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuIkcDCZkc4BvDXnoDQNwAAADs"]
[Thu Jul 30 12:23:29.674870 2026] [security2:error] [pid 727775:tid 727964] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuIkcDCZkc4BvDXnoDQNwAAADs"]
[Thu Jul 30 12:23:29.727747 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:49153] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/ID3/alfacgiapi/perl.alfa"] [unique_id "amuIkcDCZkc4BvDXnoDQOAAAAHU"]
[Thu Jul 30 12:23:29.820917 2026] [security2:error] [pid 727775:tid 727925] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIkcDCZkc4BvDXnoDQNAAAFHQ"]
[Thu Jul 30 12:23:29.912165 2026] [security2:error] [pid 727775:tid 727994] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/zrrhj.php"] [unique_id "amuIkcDCZkc4BvDXnoDQQgAAAFk"]
[Thu Jul 30 12:23:29.912263 2026] [security2:error] [pid 727775:tid 727994] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/zrrhj.php"] [unique_id "amuIkcDCZkc4BvDXnoDQQgAAAFk"]
[Thu Jul 30 12:23:29.917232 2026] [security2:error] [pid 727775:tid 727984] [client 20.91.199.21:47638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/f7.php"] [unique_id "amuIkcDCZkc4BvDXnoDQQwAAAE8"]
[Thu Jul 30 12:23:30.089055 2026] [core:error] [pid 727775:tid 727887] [remote 216.73.216.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:23:30.089082 2026] [core:error] [pid 727775:tid 727887] [remote 216.73.216.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:23:30.112650 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:49383] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/IXR/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIksDCZkc4BvDXnoDQRQAAACM"]
[Thu Jul 30 12:23:30.181538 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuIksDCZkc4BvDXnoDQRgAAADk"]
[Thu Jul 30 12:23:30.181650 2026] [security2:error] [pid 727775:tid 727962] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuIksDCZkc4BvDXnoDQRgAAADk"]
[Thu Jul 30 12:23:30.414966 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wpgum.php"] [unique_id "amuIksDCZkc4BvDXnoDQTgAAADQ"]
[Thu Jul 30 12:23:30.415067 2026] [security2:error] [pid 727775:tid 727957] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wpgum.php"] [unique_id "amuIksDCZkc4BvDXnoDQTgAAADQ"]
[Thu Jul 30 12:23:30.490906 2026] [security2:error] [pid 727775:tid 728004] [client 142.93.53.183:49590] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/IXR/alfacgiapi/perl.alfa"] [unique_id "amuIksDCZkc4BvDXnoDQUAAAAGM"]
[Thu Jul 30 12:23:30.494134 2026] [security2:error] [pid 727775:tid 727956] [client 23.23.214.190:9493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/03/distribuidora-e-interditada-e-mais-de-700-botijoes-de-gas-de-cozinha-sao-apreendidos-em-jp-90x60.png"] [unique_id "amuIksDCZkc4BvDXnoDQUQAAADM"]
[Thu Jul 30 12:23:30.715104 2026] [security2:error] [pid 727775:tid 727910] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ywwbf.php"] [unique_id "amuIksDCZkc4BvDXnoDQUgAAAAU"]
[Thu Jul 30 12:23:30.715229 2026] [security2:error] [pid 727775:tid 727910] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ywwbf.php"] [unique_id "amuIksDCZkc4BvDXnoDQUgAAAAU"]
[Thu Jul 30 12:23:30.871004 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:49767] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/PHPMailer/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIksDCZkc4BvDXnoDQVQAAAB8"]
[Thu Jul 30 12:23:31.060223 2026] [security2:error] [pid 727775:tid 727974] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/xoldj.php"] [unique_id "amuIk8DCZkc4BvDXnoDQXQAAAEU"]
[Thu Jul 30 12:23:31.060343 2026] [security2:error] [pid 727775:tid 727974] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/xoldj.php"] [unique_id "amuIk8DCZkc4BvDXnoDQXQAAAEU"]
[Thu Jul 30 12:23:31.265308 2026] [security2:error] [pid 727775:tid 727991] [client 142.93.53.183:49937] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/PHPMailer/alfacgiapi/perl.alfa"] [unique_id "amuIk8DCZkc4BvDXnoDQYQAAAFY"]
[Thu Jul 30 12:23:31.324460 2026] [security2:error] [pid 727775:tid 727907] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/f35.php"] [unique_id "amuIk8DCZkc4BvDXnoDQYgAAAAI"]
[Thu Jul 30 12:23:31.324591 2026] [security2:error] [pid 727775:tid 727907] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/f35.php"] [unique_id "amuIk8DCZkc4BvDXnoDQYgAAAAI"]
[Thu Jul 30 12:23:31.519929 2026] [security2:error] [pid 727775:tid 728030] [client 172.213.232.128:7391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/img/about.php"] [unique_id "amuIk8DCZkc4BvDXnoDQawAAAH0"]
[Thu Jul 30 12:23:31.558649 2026] [security2:error] [pid 727775:tid 727934] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gk.php"] [unique_id "amuIk8DCZkc4BvDXnoDQbQAAAB0"]
[Thu Jul 30 12:23:31.558808 2026] [security2:error] [pid 727775:tid 727934] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gk.php"] [unique_id "amuIk8DCZkc4BvDXnoDQbQAAAB0"]
[Thu Jul 30 12:23:31.647101 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:50144] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Requests/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIk8DCZkc4BvDXnoDQbgAAACw"]
[Thu Jul 30 12:23:31.678157 2026] [security2:error] [pid 727775:tid 727930] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIk8DCZkc4BvDXnoDQZAAAGQE"]
[Thu Jul 30 12:23:31.797752 2026] [security2:error] [pid 727775:tid 727946] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuIk8DCZkc4BvDXnoDQcAAAACk"]
[Thu Jul 30 12:23:31.797886 2026] [security2:error] [pid 727775:tid 727946] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuIk8DCZkc4BvDXnoDQcAAAACk"]
[Thu Jul 30 12:23:32.065447 2026] [security2:error] [pid 727775:tid 727912] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wper3.php"] [unique_id "amuIlMDCZkc4BvDXnoDQeAAAAAc"]
[Thu Jul 30 12:23:32.065564 2026] [security2:error] [pid 727775:tid 727912] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wper3.php"] [unique_id "amuIlMDCZkc4BvDXnoDQeAAAAAc"]
[Thu Jul 30 12:23:32.156126 2026] [security2:error] [pid 727775:tid 727798] [remote 74.7.241.60:43142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuIlMDCZkc4BvDXnoDQeQAAMRY"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:23:32.275765 2026] [security2:error] [pid 727775:tid 727916] [client 172.213.232.128:8362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/languages/about.php"] [unique_id "amuIlMDCZkc4BvDXnoDQegAAAAs"]
[Thu Jul 30 12:23:32.327274 2026] [security2:error] [pid 727775:tid 727967] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bthil.php"] [unique_id "amuIlMDCZkc4BvDXnoDQfAAAAD4"]
[Thu Jul 30 12:23:32.327395 2026] [security2:error] [pid 727775:tid 727967] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bthil.php"] [unique_id "amuIlMDCZkc4BvDXnoDQfAAAAD4"]
[Thu Jul 30 12:23:32.386077 2026] [security2:error] [pid 727775:tid 727924] [client 142.93.53.183:50521] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Requests/alfacgiapi/perl.alfa"] [unique_id "amuIlMDCZkc4BvDXnoDQfQAAABM"]
[Thu Jul 30 12:23:32.561049 2026] [security2:error] [pid 727775:tid 728012] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wyzer1.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhQAAAGs"]
[Thu Jul 30 12:23:32.561179 2026] [security2:error] [pid 727775:tid 728012] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wyzer1.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhQAAAGs"]
[Thu Jul 30 12:23:32.641319 2026] [security2:error] [pid 727775:tid 727927] [client 20.91.199.21:47623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/nw.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhgAAABY"]
[Thu Jul 30 12:23:32.643958 2026] [security2:error] [pid 727775:tid 728005] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIlMDCZkc4BvDXnoDQewAAZHE"]
[Thu Jul 30 12:23:32.796990 2026] [security2:error] [pid 727775:tid 728018] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/mh.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhwAAAHE"]
[Thu Jul 30 12:23:32.797104 2026] [security2:error] [pid 727775:tid 728018] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/mh.php"] [unique_id "amuIlMDCZkc4BvDXnoDQhwAAAHE"]
[Thu Jul 30 12:23:32.811480 2026] [security2:error] [pid 727775:tid 727960] [client 142.93.53.183:50715] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIlMDCZkc4BvDXnoDQiAAAADc"]
[Thu Jul 30 12:23:32.850114 2026] [security2:error] [pid 727775:tid 728003] [client 172.213.232.128:22693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/customize/about.php"] [unique_id "amuIlMDCZkc4BvDXnoDQiQAAAGI"]
[Thu Jul 30 12:23:33.063101 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuIlcDCZkc4BvDXnoDQkQAAACE"]
[Thu Jul 30 12:23:33.063212 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuIlcDCZkc4BvDXnoDQkQAAACE"]
[Thu Jul 30 12:23:33.192460 2026] [security2:error] [pid 727775:tid 728011] [client 142.93.53.183:50939] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/alfacgiapi/perl.alfa"] [unique_id "amuIlcDCZkc4BvDXnoDQkwAAAGo"]
[Thu Jul 30 12:23:33.321897 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.45.59:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuIlcDCZkc4BvDXnoDQlAAAAF8"]
[Thu Jul 30 12:23:33.322039 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuIlcDCZkc4BvDXnoDQlAAAAF8"]
[Thu Jul 30 12:23:33.322156 2026] [security2:error] [pid 727775:tid 728000] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuIlcDCZkc4BvDXnoDQlAAAAF8"]
[Thu Jul 30 12:23:33.428021 2026] [security2:error] [pid 727775:tid 727928] [client 172.213.232.128:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuIlcDCZkc4BvDXnoDQlgAAABc"]
[Thu Jul 30 12:23:33.575489 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:51130] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Cache/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIlcDCZkc4BvDXnoDQnAAAACA"]
[Thu Jul 30 12:23:33.575658 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/chosen.php"] [unique_id "amuIlcDCZkc4BvDXnoDQmwAAAEk"]
[Thu Jul 30 12:23:33.575761 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/chosen.php"] [unique_id "amuIlcDCZkc4BvDXnoDQmwAAAEk"]
[Thu Jul 30 12:23:33.845162 2026] [security2:error] [pid 727775:tid 728027] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/sd.php"] [unique_id "amuIlcDCZkc4BvDXnoDQnwAAAHo"]
[Thu Jul 30 12:23:33.845282 2026] [security2:error] [pid 727775:tid 728027] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/sd.php"] [unique_id "amuIlcDCZkc4BvDXnoDQnwAAAHo"]
[Thu Jul 30 12:23:33.964832 2026] [security2:error] [pid 727775:tid 727951] [client 142.93.53.183:51330] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Cache/alfacgiapi/perl.alfa"] [unique_id "amuIlcDCZkc4BvDXnoDQoQAAAC4"]
[Thu Jul 30 12:23:34.080184 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/z60.php"] [unique_id "amuIlsDCZkc4BvDXnoDQpQAAAAE"]
[Thu Jul 30 12:23:34.080284 2026] [security2:error] [pid 727775:tid 727906] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/z60.php"] [unique_id "amuIlsDCZkc4BvDXnoDQpQAAAAE"]
[Thu Jul 30 12:23:34.129322 2026] [security2:error] [pid 727775:tid 727943] [client 172.213.232.128:22717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuIlsDCZkc4BvDXnoDQqQAAACY"]
[Thu Jul 30 12:23:34.344030 2026] [security2:error] [pid 727775:tid 727941] [client 142.93.53.183:51548] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Content/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIlsDCZkc4BvDXnoDQqwAAACQ"]
[Thu Jul 30 12:23:34.359063 2026] [security2:error] [pid 727775:tid 727933] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/home.php"] [unique_id "amuIlsDCZkc4BvDXnoDQrAAAABw"]
[Thu Jul 30 12:23:34.359206 2026] [security2:error] [pid 727775:tid 727933] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/home.php"] [unique_id "amuIlsDCZkc4BvDXnoDQrAAAABw"]
[Thu Jul 30 12:23:34.525757 2026] [security2:error] [pid 727775:tid 727934] [client 175.30.48.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIlsDCZkc4BvDXnoDQqgAAHQw"]
[Thu Jul 30 12:23:34.601342 2026] [security2:error] [pid 727775:tid 727998] [client 20.91.199.21:47280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/ova.php"] [unique_id "amuIlsDCZkc4BvDXnoDQrQAAAF0"]
[Thu Jul 30 12:23:34.610791 2026] [security2:error] [pid 727775:tid 727950] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ws58.php"] [unique_id "amuIlsDCZkc4BvDXnoDQsAAAAC0"]
[Thu Jul 30 12:23:34.610871 2026] [security2:error] [pid 727775:tid 727950] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ws58.php"] [unique_id "amuIlsDCZkc4BvDXnoDQsAAAAC0"]
[Thu Jul 30 12:23:34.720875 2026] [security2:error] [pid 727775:tid 727983] [client 142.93.53.183:51732] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Content/alfacgiapi/perl.alfa"] [unique_id "amuIlsDCZkc4BvDXnoDQtgAAAE4"]
[Thu Jul 30 12:23:34.748456 2026] [security2:error] [pid 727775:tid 727925] [client 172.213.232.128:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuIlsDCZkc4BvDXnoDQtwAAABQ"]
[Thu Jul 30 12:23:34.847627 2026] [security2:error] [pid 727775:tid 728021] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gulu.php"] [unique_id "amuIlsDCZkc4BvDXnoDQuQAAAHQ"]
[Thu Jul 30 12:23:34.847719 2026] [security2:error] [pid 727775:tid 728021] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/gulu.php"] [unique_id "amuIlsDCZkc4BvDXnoDQuQAAAHQ"]
[Thu Jul 30 12:23:35.102461 2026] [security2:error] [pid 727775:tid 727996] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuIl8DCZkc4BvDXnoDQugAAAFs"]
[Thu Jul 30 12:23:35.102598 2026] [security2:error] [pid 727775:tid 727996] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuIl8DCZkc4BvDXnoDQugAAAFs"]
[Thu Jul 30 12:23:35.103856 2026] [security2:error] [pid 727775:tid 727948] [client 142.93.53.183:51926] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Content/Type/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIl8DCZkc4BvDXnoDQuwAAACs"]
[Thu Jul 30 12:23:35.335390 2026] [security2:error] [pid 727775:tid 727908] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wpls.php"] [unique_id "amuIl8DCZkc4BvDXnoDQxAAAAAM"]
[Thu Jul 30 12:23:35.335532 2026] [security2:error] [pid 727775:tid 727908] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wpls.php"] [unique_id "amuIl8DCZkc4BvDXnoDQxAAAAAM"]
[Thu Jul 30 12:23:35.493949 2026] [security2:error] [pid 727775:tid 727955] [client 142.93.53.183:52126] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Content/Type/alfacgiapi/perl.alfa"] [unique_id "amuIl8DCZkc4BvDXnoDQxgAAADI"]
[Thu Jul 30 12:23:35.496214 2026] [security2:error] [pid 727775:tid 727988] [client 123.245.84.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuIl8DCZkc4BvDXnoDQwQAAUxQ"]
[Thu Jul 30 12:23:35.506684 2026] [security2:error] [pid 727775:tid 727963] [client 172.202.44.182:52768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuIl8DCZkc4BvDXnoDQwwAAADo"]
[Thu Jul 30 12:23:35.574252 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/php.php"] [unique_id "amuIl8DCZkc4BvDXnoDQyAAAACE"]
[Thu Jul 30 12:23:35.574408 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/php.php"] [unique_id "amuIl8DCZkc4BvDXnoDQyAAAACE"]
[Thu Jul 30 12:23:35.724378 2026] [security2:error] [pid 727775:tid 727962] [client 20.91.199.21:47625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/robots.php"] [unique_id "amuIl8DCZkc4BvDXnoDQ0AAAADk"]
[Thu Jul 30 12:23:35.882898 2026] [security2:error] [pid 727775:tid 727937] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/100.php"] [unique_id "amuIl8DCZkc4BvDXnoDQ1QAAACA"]
[Thu Jul 30 12:23:35.883034 2026] [security2:error] [pid 727775:tid 727937] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/100.php"] [unique_id "amuIl8DCZkc4BvDXnoDQ1QAAACA"]
[Thu Jul 30 12:23:35.883409 2026] [security2:error] [pid 727775:tid 727978] [client 142.93.53.183:52324] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Decode/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIl8DCZkc4BvDXnoDQ1gAAAEk"]
[Thu Jul 30 12:23:36.120480 2026] [security2:error] [pid 727775:tid 727931] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/BDKR28WP.php"] [unique_id "amuImMDCZkc4BvDXnoDQ1wAAABo"]
[Thu Jul 30 12:23:36.120595 2026] [security2:error] [pid 727775:tid 727931] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/BDKR28WP.php"] [unique_id "amuImMDCZkc4BvDXnoDQ1wAAABo"]
[Thu Jul 30 12:23:36.258810 2026] [core:notice] [pid 727775:tid 728014] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:36.281309 2026] [security2:error] [pid 727775:tid 727951] [client 142.93.53.183:52509] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Decode/alfacgiapi/perl.alfa"] [unique_id "amuImMDCZkc4BvDXnoDQ4AAAAC4"]
[Thu Jul 30 12:23:36.372062 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/browse.php"] [unique_id "amuImMDCZkc4BvDXnoDQ4gAAAF4"]
[Thu Jul 30 12:23:36.372170 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/browse.php"] [unique_id "amuImMDCZkc4BvDXnoDQ4gAAAF4"]
[Thu Jul 30 12:23:36.636102 2026] [security2:error] [pid 727775:tid 727946] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuImMDCZkc4BvDXnoDQ5gAAACk"]
[Thu Jul 30 12:23:36.636273 2026] [security2:error] [pid 727775:tid 727946] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuImMDCZkc4BvDXnoDQ5gAAACk"]
[Thu Jul 30 12:23:36.677289 2026] [security2:error] [pid 727775:tid 727930] [client 142.93.53.183:52690] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Decode/HTML/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuImMDCZkc4BvDXnoDQ6gAAABk"]
[Thu Jul 30 12:23:36.736472 2026] [security2:error] [pid 727775:tid 727906] [client 172.213.232.128:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/js/about.php"] [unique_id "amuImMDCZkc4BvDXnoDQ7QAAAAE"]
[Thu Jul 30 12:23:36.894534 2026] [security2:error] [pid 727775:tid 727973] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/8573.php"] [unique_id "amuImMDCZkc4BvDXnoDQ7wAAAEQ"]
[Thu Jul 30 12:23:36.894640 2026] [security2:error] [pid 727775:tid 727973] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/8573.php"] [unique_id "amuImMDCZkc4BvDXnoDQ7wAAAEQ"]
[Thu Jul 30 12:23:37.078101 2026] [security2:error] [pid 727775:tid 727922] [client 142.93.53.183:52896] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Decode/HTML/alfacgiapi/perl.alfa"] [unique_id "amuImcDCZkc4BvDXnoDQ8wAAABE"]
[Thu Jul 30 12:23:37.148150 2026] [security2:error] [pid 727775:tid 727967] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/install.php"] [unique_id "amuImcDCZkc4BvDXnoDQ9AAAAD4"]
[Thu Jul 30 12:23:37.148267 2026] [security2:error] [pid 727775:tid 727967] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/install.php"] [unique_id "amuImcDCZkc4BvDXnoDQ9AAAAD4"]
[Thu Jul 30 12:23:37.381116 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuImcDCZkc4BvDXnoDQ-wAAAA8"]
[Thu Jul 30 12:23:37.381233 2026] [security2:error] [pid 727775:tid 727920] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuImcDCZkc4BvDXnoDQ-wAAAA8"]
[Thu Jul 30 12:23:37.461261 2026] [security2:error] [pid 727775:tid 727984] [client 142.93.53.183:53073] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/HTTP/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuImcDCZkc4BvDXnoDQ_AAAAE8"]
[Thu Jul 30 12:23:37.614859 2026] [security2:error] [pid 727775:tid 727921] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ohct.php"] [unique_id "amuImcDCZkc4BvDXnoDRAAAAABA"]
[Thu Jul 30 12:23:37.614967 2026] [security2:error] [pid 727775:tid 727921] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ohct.php"] [unique_id "amuImcDCZkc4BvDXnoDRAAAAABA"]
[Thu Jul 30 12:23:37.641205 2026] [security2:error] [pid 727775:tid 727949] [client 43.166.247.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuImMDCZkc4BvDXnoDQ5QAAACw"]
[Thu Jul 30 12:23:37.643042 2026] [security2:error] [pid 727775:tid 727950] [client 20.91.199.21:47290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/alf.php"] [unique_id "amuImcDCZkc4BvDXnoDRAgAAAC0"]
[Thu Jul 30 12:23:37.714413 2026] [security2:error] [pid 727775:tid 728018] [client 172.213.232.128:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuImcDCZkc4BvDXnoDRBwAAAHE"]
[Thu Jul 30 12:23:37.935045 2026] [security2:error] [pid 727775:tid 727910] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bless.php"] [unique_id "amuImcDCZkc4BvDXnoDRDAAAAAU"]
[Thu Jul 30 12:23:37.935174 2026] [security2:error] [pid 727775:tid 727910] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bless.php"] [unique_id "amuImcDCZkc4BvDXnoDRDAAAAAU"]
[Thu Jul 30 12:23:37.937454 2026] [security2:error] [pid 727775:tid 728028] [client 142.93.53.183:53285] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/HTTP/alfacgiapi/perl.alfa"] [unique_id "amuImcDCZkc4BvDXnoDRDQAAAHs"]
[Thu Jul 30 12:23:38.170504 2026] [security2:error] [pid 727775:tid 727944] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/about.php"] [unique_id "amuImsDCZkc4BvDXnoDRDgAAACc"]
[Thu Jul 30 12:23:38.170618 2026] [security2:error] [pid 727775:tid 727944] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/about.php"] [unique_id "amuImsDCZkc4BvDXnoDRDgAAACc"]
[Thu Jul 30 12:23:38.314647 2026] [security2:error] [pid 727775:tid 727911] [client 142.93.53.183:53450] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Net/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuImsDCZkc4BvDXnoDRFQAAAAY"]
[Thu Jul 30 12:23:38.376306 2026] [security2:error] [pid 727775:tid 727965] [client 20.91.199.21:47292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/feedback.php"] [unique_id "amuImsDCZkc4BvDXnoDRFgAAADw"]
[Thu Jul 30 12:23:38.401762 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuImsDCZkc4BvDXnoDRFwAAAAA"]
[Thu Jul 30 12:23:38.401878 2026] [security2:error] [pid 727775:tid 727905] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuImsDCZkc4BvDXnoDRFwAAAAA"]
[Thu Jul 30 12:23:38.613888 2026] [security2:error] [pid 727775:tid 728032] [client 172.213.232.128:15557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuImsDCZkc4BvDXnoDRGAAAAH8"]
[Thu Jul 30 12:23:38.639328 2026] [security2:error] [pid 727775:tid 728025] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ta0ol.php"] [unique_id "amuImsDCZkc4BvDXnoDRGQAAAHg"]
[Thu Jul 30 12:23:38.639449 2026] [security2:error] [pid 727775:tid 728025] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ta0ol.php"] [unique_id "amuImsDCZkc4BvDXnoDRGQAAAHg"]
[Thu Jul 30 12:23:38.717512 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:53607] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Net/alfacgiapi/perl.alfa"] [unique_id "amuImsDCZkc4BvDXnoDRGgAAAA0"]
[Thu Jul 30 12:23:38.875689 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/sa.php7"] [unique_id "amuImsDCZkc4BvDXnoDRIQAAAF4"]
[Thu Jul 30 12:23:38.875770 2026] [security2:error] [pid 727775:tid 727999] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/sa.php7"] [unique_id "amuImsDCZkc4BvDXnoDRIQAAAF4"]
[Thu Jul 30 12:23:39.095596 2026] [security2:error] [pid 727775:tid 727971] [client 142.93.53.183:53780] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Parse/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIm8DCZkc4BvDXnoDRIgAAAEI"]
[Thu Jul 30 12:23:39.134805 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-class.php"] [unique_id "amuIm8DCZkc4BvDXnoDRIwAAAG8"]
[Thu Jul 30 12:23:39.134908 2026] [security2:error] [pid 727775:tid 728016] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-class.php"] [unique_id "amuIm8DCZkc4BvDXnoDRIwAAAG8"]
[Thu Jul 30 12:23:39.311429 2026] [security2:error] [pid 727775:tid 727995] [client 172.213.232.128:4183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuIm8DCZkc4BvDXnoDRJgAAAFo"]
[Thu Jul 30 12:23:39.401764 2026] [security2:error] [pid 727775:tid 728006] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuIm8DCZkc4BvDXnoDRLwAAAGU"]
[Thu Jul 30 12:23:39.401863 2026] [security2:error] [pid 727775:tid 728006] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuIm8DCZkc4BvDXnoDRLwAAAGU"]
[Thu Jul 30 12:23:39.475214 2026] [security2:error] [pid 727775:tid 727967] [client 142.93.53.183:53923] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/Parse/alfacgiapi/perl.alfa"] [unique_id "amuIm8DCZkc4BvDXnoDRMAAAAD4"]
[Thu Jul 30 12:23:39.637000 2026] [security2:error] [pid 727775:tid 728010] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bootstrap.php"] [unique_id "amuIm8DCZkc4BvDXnoDRNwAAAGk"]
[Thu Jul 30 12:23:39.637091 2026] [security2:error] [pid 727775:tid 728010] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/bootstrap.php"] [unique_id "amuIm8DCZkc4BvDXnoDRNwAAAGk"]
[Thu Jul 30 12:23:39.859157 2026] [security2:error] [pid 727775:tid 727996] [client 142.93.53.183:54078] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/XML/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIm8DCZkc4BvDXnoDROQAAAFs"]
[Thu Jul 30 12:23:40.240457 2026] [security2:error] [pid 727775:tid 727956] [client 142.93.53.183:54245] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/SimplePie/XML/alfacgiapi/perl.alfa"] [unique_id "amuInMDCZkc4BvDXnoDRQwAAADM"]
[Thu Jul 30 12:23:40.270872 2026] [security2:error] [pid 727775:tid 727986] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-blog-header.php"] [unique_id "amuInMDCZkc4BvDXnoDRRAAAAFE"]
[Thu Jul 30 12:23:40.270987 2026] [security2:error] [pid 727775:tid 727986] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-blog-header.php"] [unique_id "amuInMDCZkc4BvDXnoDRRAAAAFE"]
[Thu Jul 30 12:23:40.295433 2026] [security2:error] [pid 727775:tid 728018] [client 172.202.44.182:53167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/classwithtostring.php"] [unique_id "amuInMDCZkc4BvDXnoDRRQAAAHE"]
[Thu Jul 30 12:23:40.503092 2026] [security2:error] [pid 727775:tid 728001] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuInMDCZkc4BvDXnoDRTQAAAGA"]
[Thu Jul 30 12:23:40.503203 2026] [security2:error] [pid 727775:tid 728001] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuInMDCZkc4BvDXnoDRTQAAAGA"]
[Thu Jul 30 12:23:40.653776 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuInMDCZkc4BvDXnoDRTwAAAAg"]
[Thu Jul 30 12:23:40.744672 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tx79.php"] [unique_id "amuInMDCZkc4BvDXnoDRUAAAACM"]
[Thu Jul 30 12:23:40.744821 2026] [security2:error] [pid 727775:tid 727940] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tx79.php"] [unique_id "amuInMDCZkc4BvDXnoDRUAAAACM"]
[Thu Jul 30 12:23:40.978657 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/motu.php"] [unique_id "amuInMDCZkc4BvDXnoDRVQAAAEk"]
[Thu Jul 30 12:23:40.978756 2026] [security2:error] [pid 727775:tid 727978] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/motu.php"] [unique_id "amuInMDCZkc4BvDXnoDRVQAAAEk"]
[Thu Jul 30 12:23:41.046169 2026] [security2:error] [pid 727775:tid 727965] [client 142.93.53.183:54591] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/alfacgiapi/perl.alfa"] [unique_id "amuIncDCZkc4BvDXnoDRWQAAADw"]
[Thu Jul 30 12:23:41.212925 2026] [security2:error] [pid 727775:tid 727918] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-head.php"] [unique_id "amuIncDCZkc4BvDXnoDRWwAAAA0"]
[Thu Jul 30 12:23:41.213042 2026] [security2:error] [pid 727775:tid 727918] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-head.php"] [unique_id "amuIncDCZkc4BvDXnoDRWwAAAA0"]
[Thu Jul 30 12:23:41.281040 2026] [security2:error] [pid 727775:tid 727952] [client 20.91.199.21:47282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/gettest.php"] [unique_id "amuIncDCZkc4BvDXnoDRXAAAAC8"]
[Thu Jul 30 12:23:41.439345 2026] [security2:error] [pid 727775:tid 727914] [client 142.93.53.183:54745] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIncDCZkc4BvDXnoDRXQAAAAk"]
[Thu Jul 30 12:23:41.449822 2026] [security2:error] [pid 727775:tid 728027] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuIncDCZkc4BvDXnoDRXgAAAHo"]
[Thu Jul 30 12:23:41.449907 2026] [security2:error] [pid 727775:tid 728027] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuIncDCZkc4BvDXnoDRXgAAAHo"]
[Thu Jul 30 12:23:41.645719 2026] [security2:error] [pid 727775:tid 728025] [client 172.202.44.182:53179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/gmo.php"] [unique_id "amuIncDCZkc4BvDXnoDRZQAAAHg"]
[Thu Jul 30 12:23:41.680653 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/60856e3a4findex.php"] [unique_id "amuIncDCZkc4BvDXnoDRZgAAAFo"]
[Thu Jul 30 12:23:41.680748 2026] [security2:error] [pid 727775:tid 727995] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/60856e3a4findex.php"] [unique_id "amuIncDCZkc4BvDXnoDRZgAAAFo"]
[Thu Jul 30 12:23:41.819169 2026] [security2:error] [pid 727775:tid 727964] [client 142.93.53.183:54899] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/alfacgiapi/perl.alfa"] [unique_id "amuIncDCZkc4BvDXnoDRZwAAADs"]
[Thu Jul 30 12:23:41.919027 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuIncDCZkc4BvDXnoDRaAAAAGc"]
[Thu Jul 30 12:23:41.919138 2026] [security2:error] [pid 727775:tid 728008] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuIncDCZkc4BvDXnoDRaAAAAGc"]
[Thu Jul 30 12:23:42.150974 2026] [security2:error] [pid 727775:tid 727930] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp.php"] [unique_id "amuInsDCZkc4BvDXnoDRcAAAABk"]
[Thu Jul 30 12:23:42.151099 2026] [security2:error] [pid 727775:tid 727930] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wp.php"] [unique_id "amuInsDCZkc4BvDXnoDRcAAAABk"]
[Thu Jul 30 12:23:42.219202 2026] [security2:error] [pid 727775:tid 728015] [client 142.93.53.183:55074] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/Engine/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuInsDCZkc4BvDXnoDRcgAAAG4"]
[Thu Jul 30 12:23:42.231595 2026] [security2:error] [pid 727775:tid 727919] [client 38.190.144.4:56620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuInsDCZkc4BvDXnoDRcwAAAA4"]
[Thu Jul 30 12:23:42.231713 2026] [security2:error] [pid 727775:tid 727919] [client 38.190.144.4:56620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuInsDCZkc4BvDXnoDRcwAAAA4"]
[Thu Jul 30 12:23:42.357139 2026] [security2:error] [pid 727775:tid 727924] [client 20.91.199.21:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/maint.php"] [unique_id "amuInsDCZkc4BvDXnoDRdAAAABM"]
[Thu Jul 30 12:23:42.385412 2026] [security2:error] [pid 727775:tid 728010] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/users.php"] [unique_id "amuInsDCZkc4BvDXnoDRdQAAAGk"]
[Thu Jul 30 12:23:42.385528 2026] [security2:error] [pid 727775:tid 728010] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/users.php"] [unique_id "amuInsDCZkc4BvDXnoDRdQAAAGk"]
[Thu Jul 30 12:23:42.611232 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:55253] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/Engine/alfacgiapi/perl.alfa"] [unique_id "amuInsDCZkc4BvDXnoDRfAAAABY"]
[Thu Jul 30 12:23:42.618422 2026] [security2:error] [pid 727775:tid 727948] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tinysd.php"] [unique_id "amuInsDCZkc4BvDXnoDRfQAAACs"]
[Thu Jul 30 12:23:42.618546 2026] [security2:error] [pid 727775:tid 727948] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/tinysd.php"] [unique_id "amuInsDCZkc4BvDXnoDRfQAAACs"]
[Thu Jul 30 12:23:42.865792 2026] [security2:error] [pid 727775:tid 727977] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ws78.php"] [unique_id "amuInsDCZkc4BvDXnoDRfgAAAEg"]
[Thu Jul 30 12:23:42.865907 2026] [security2:error] [pid 727775:tid 727977] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ws78.php"] [unique_id "amuInsDCZkc4BvDXnoDRfgAAAEg"]
[Thu Jul 30 12:23:42.877900 2026] [security2:error] [pid 727775:tid 727921] [client 172.202.44.182:52793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuInsDCZkc4BvDXnoDRfwAAABA"]
[Thu Jul 30 12:23:43.021039 2026] [security2:error] [pid 727775:tid 728026] [client 142.93.53.183:55421] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/Renderer/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIn8DCZkc4BvDXnoDRgAAAAHk"]
[Thu Jul 30 12:23:43.072656 2026] [security2:error] [pid 727775:tid 727925] [client 20.91.199.21:46724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/files.php"] [unique_id "amuIn8DCZkc4BvDXnoDRhAAAABQ"]
[Thu Jul 30 12:23:43.101353 2026] [security2:error] [pid 727775:tid 728003] [client 172.213.232.128:22313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/updraft/about.php"] [unique_id "amuIn8DCZkc4BvDXnoDRhQAAAGI"]
[Thu Jul 30 12:23:43.136563 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/elp.php"] [unique_id "amuIn8DCZkc4BvDXnoDRhgAAACE"]
[Thu Jul 30 12:23:43.136686 2026] [security2:error] [pid 727775:tid 727938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/elp.php"] [unique_id "amuIn8DCZkc4BvDXnoDRhgAAACE"]
[Thu Jul 30 12:23:43.406336 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:55589] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/Diff/Renderer/alfacgiapi/perl.alfa"] [unique_id "amuIn8DCZkc4BvDXnoDRigAAACM"]
[Thu Jul 30 12:23:43.430423 2026] [security2:error] [pid 727775:tid 727944] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/atomlib.php"] [unique_id "amuIn8DCZkc4BvDXnoDRiwAAACc"]
[Thu Jul 30 12:23:43.430540 2026] [security2:error] [pid 727775:tid 727944] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/atomlib.php"] [unique_id "amuIn8DCZkc4BvDXnoDRiwAAACc"]
[Thu Jul 30 12:23:43.686348 2026] [security2:error] [pid 727775:tid 727931] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wyzer3.php"] [unique_id "amuIn8DCZkc4BvDXnoDRmQAAABo"]
[Thu Jul 30 12:23:43.686426 2026] [security2:error] [pid 727775:tid 727931] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/wyzer3.php"] [unique_id "amuIn8DCZkc4BvDXnoDRmQAAABo"]
[Thu Jul 30 12:23:43.797235 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:55750] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIn8DCZkc4BvDXnoDRnQAAAA0"]
[Thu Jul 30 12:23:43.923095 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/max.php"] [unique_id "amuIn8DCZkc4BvDXnoDRnwAAAAk"]
[Thu Jul 30 12:23:43.923207 2026] [security2:error] [pid 727775:tid 727914] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/max.php"] [unique_id "amuIn8DCZkc4BvDXnoDRnwAAAAk"]
[Thu Jul 30 12:23:43.963404 2026] [security2:error] [pid 727775:tid 727966] [client 172.237.109.114:27453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.backup"] [unique_id "amuIn8DCZkc4BvDXnoDRoQAAAD0"]
[Thu Jul 30 12:23:43.974579 2026] [security2:error] [pid 727775:tid 727997] [client 172.237.109.114:49465] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amuIn8DCZkc4BvDXnoDRpQAAAFw"]
[Thu Jul 30 12:23:43.993541 2026] [security2:error] [pid 727775:tid 728029] [client 172.237.109.114:33213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.bak"] [unique_id "amuIn8DCZkc4BvDXnoDRrAAAAHw"]
[Thu Jul 30 12:23:44.011828 2026] [security2:error] [pid 727775:tid 727906] [client 172.237.109.114:11779] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amuIoMDCZkc4BvDXnoDRrwAAAAE"]
[Thu Jul 30 12:23:44.135264 2026] [security2:error] [pid 727775:tid 727985] [client 172.202.44.182:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-the.php"] [unique_id "amuIoMDCZkc4BvDXnoDRuAAAAFA"]
[Thu Jul 30 12:23:44.161829 2026] [security2:error] [pid 727775:tid 727968] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ftde.php"] [unique_id "amuIoMDCZkc4BvDXnoDRuwAAAD8"]
[Thu Jul 30 12:23:44.161987 2026] [security2:error] [pid 727775:tid 727968] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/ftde.php"] [unique_id "amuIoMDCZkc4BvDXnoDRuwAAAD8"]
[Thu Jul 30 12:23:44.193110 2026] [security2:error] [pid 727775:tid 727992] [client 142.93.53.183:55924] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/assets/alfacgiapi/perl.alfa"] [unique_id "amuIoMDCZkc4BvDXnoDRvQAAAFc"]
[Thu Jul 30 12:23:44.235475 2026] [security2:error] [pid 727775:tid 728011] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRjwAAAGo"]
[Thu Jul 30 12:23:44.579651 2026] [security2:error] [pid 727775:tid 728012] [client 142.93.53.183:56104] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIoMDCZkc4BvDXnoDRwQAAAGs"]
[Thu Jul 30 12:23:44.585133 2026] [core:notice] [pid 727775:tid 727844] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:44.688756 2026] [security2:error] [pid 727775:tid 728007] [client 172.213.232.128:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuIoMDCZkc4BvDXnoDRyAAAAGY"]
[Thu Jul 30 12:23:44.956419 2026] [security2:error] [pid 727775:tid 727938] [client 142.93.53.183:56297] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/alfacgiapi/perl.alfa"] [unique_id "amuIoMDCZkc4BvDXnoDRygAAACE"]
[Thu Jul 30 12:23:45.080867 2026] [security2:error] [pid 727775:tid 728020] [client 20.91.199.21:46760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/gecko.php"] [unique_id "amuIocDCZkc4BvDXnoDRywAAAHM"]
[Thu Jul 30 12:23:45.333711 2026] [security2:error] [pid 727775:tid 727991] [client 172.237.109.114:31797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRowAAAFY"]
[Thu Jul 30 12:23:45.337577 2026] [security2:error] [pid 727775:tid 728014] [client 172.237.109.114:15072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRogAAAG0"]
[Thu Jul 30 12:23:45.345642 2026] [security2:error] [pid 727775:tid 728009] [client 172.237.109.114:1721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRpgAAAGg"]
[Thu Jul 30 12:23:45.345764 2026] [security2:error] [pid 727775:tid 727928] [client 142.93.53.183:56472] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-supports/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIocDCZkc4BvDXnoDR1AAAABc"]
[Thu Jul 30 12:23:45.348100 2026] [security2:error] [pid 727775:tid 728027] [client 172.237.109.114:35325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRoAAAAHo"]
[Thu Jul 30 12:23:45.350854 2026] [security2:error] [pid 727775:tid 727959] [client 172.237.109.114:46760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRpwAAADY"]
[Thu Jul 30 12:23:45.358541 2026] [security2:error] [pid 727775:tid 728016] [client 172.237.109.114:7270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRqQAAAG8"]
[Thu Jul 30 12:23:45.364643 2026] [security2:error] [pid 727775:tid 727999] [client 172.237.109.114:50626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRpAAAAF4"]
[Thu Jul 30 12:23:45.371359 2026] [security2:error] [pid 727775:tid 727936] [client 172.237.109.114:53708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRqAAAAB8"]
[Thu Jul 30 12:23:45.374885 2026] [security2:error] [pid 727775:tid 727953] [client 172.237.109.114:15664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRqwAAADA"]
[Thu Jul 30 12:23:45.376132 2026] [security2:error] [pid 727775:tid 727982] [client 172.237.109.114:2287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRsQAAAE0"]
[Thu Jul 30 12:23:45.378202 2026] [security2:error] [pid 727775:tid 727951] [client 172.237.109.114:56722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRqgAAAC4"]
[Thu Jul 30 12:23:45.379525 2026] [security2:error] [pid 727775:tid 728008] [client 172.237.109.114:64240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRsgAAAGc"]
[Thu Jul 30 12:23:45.379757 2026] [security2:error] [pid 727775:tid 727964] [client 172.237.109.114:35237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRsAAAADs"]
[Thu Jul 30 12:23:45.380016 2026] [security2:error] [pid 727775:tid 728025] [client 172.237.109.114:27337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIn8DCZkc4BvDXnoDRrQAAAHg"]
[Thu Jul 30 12:23:45.393621 2026] [security2:error] [pid 727775:tid 727995] [client 172.237.109.114:51352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRrgAAAFo"]
[Thu Jul 30 12:23:45.395065 2026] [security2:error] [pid 727775:tid 728013] [client 172.237.109.114:24801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuIoMDCZkc4BvDXnoDRswAAAGw"]
[Thu Jul 30 12:23:45.751564 2026] [security2:error] [pid 727775:tid 727967] [client 142.93.53.183:56645] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-supports/alfacgiapi/perl.alfa"] [unique_id "amuIocDCZkc4BvDXnoDR3AAAAD4"]
[Thu Jul 30 12:23:45.929633 2026] [security2:error] [pid 727775:tid 727981] [client 172.213.232.128:9874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/about.php"] [unique_id "amuIocDCZkc4BvDXnoDR4wAAAEw"]
[Thu Jul 30 12:23:46.001232 2026] [core:notice] [pid 727775:tid 727993] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:46.058447 2026] [security2:error] [pid 727775:tid 727945] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIocDCZkc4BvDXnoDR2AAAACg"]
[Thu Jul 30 12:23:46.138088 2026] [security2:error] [pid 727775:tid 727970] [client 142.93.53.183:56812] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIosDCZkc4BvDXnoDR5QAAAEE"]
[Thu Jul 30 12:23:46.445324 2026] [security2:error] [pid 727775:tid 727916] [client 20.91.199.21:47291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/zwso.php"] [unique_id "amuIosDCZkc4BvDXnoDR7AAAAAs"]
[Thu Jul 30 12:23:46.665255 2026] [security2:error] [pid 727775:tid 727923] [client 172.213.232.128:15561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/includes/about.php"] [unique_id "amuIosDCZkc4BvDXnoDR7QAAABI"]
[Thu Jul 30 12:23:46.691419 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:57069] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/alfacgiapi/perl.alfa"] [unique_id "amuIosDCZkc4BvDXnoDR7gAAAC0"]
[Thu Jul 30 12:23:46.826159 2026] [security2:error] [pid 727775:tid 727938] [client 3.221.222.168:59368] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2019/07/47c2cb97-e98a-4382-9285-6ea8f9d72211-560x420.jpg"] [unique_id "amuIosDCZkc4BvDXnoDR-AAAACE"]
[Thu Jul 30 12:23:47.106612 2026] [security2:error] [pid 727775:tid 727957] [client 142.93.53.183:57241] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/archives/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIo8DCZkc4BvDXnoDR-QAAADQ"]
[Thu Jul 30 12:23:47.237837 2026] [security2:error] [pid 727775:tid 728011] [client 172.202.44.182:35797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/404.php"] [unique_id "amuIo8DCZkc4BvDXnoDR_QAAAGo"]
[Thu Jul 30 12:23:47.498617 2026] [security2:error] [pid 727775:tid 728031] [client 142.93.53.183:57427] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/archives/alfacgiapi/perl.alfa"] [unique_id "amuIo8DCZkc4BvDXnoDSAQAAAH4"]
[Thu Jul 30 12:23:47.930493 2026] [core:error] [pid 727775:tid 727989] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:23:47.930515 2026] [core:error] [pid 727775:tid 727989] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:23:48.042257 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:57670] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/audio/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIpMDCZkc4BvDXnoDSFwAAACc"]
[Thu Jul 30 12:23:48.206156 2026] [security2:error] [pid 727775:tid 728027] [client 20.91.199.21:47285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/13.php"] [unique_id "amuIpMDCZkc4BvDXnoDSIAAAAHo"]
[Thu Jul 30 12:23:48.266445 2026] [security2:error] [pid 727775:tid 728029] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIpMDCZkc4BvDXnoDSFAAAAHw"]
[Thu Jul 30 12:23:48.427462 2026] [security2:error] [pid 727775:tid 727994] [client 142.93.53.183:57837] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/audio/alfacgiapi/perl.alfa"] [unique_id "amuIpMDCZkc4BvDXnoDSJwAAAFk"]
[Thu Jul 30 12:23:48.530152 2026] [security2:error] [pid 727775:tid 727930] [client 172.213.232.128:22340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/images/about.php"] [unique_id "amuIpMDCZkc4BvDXnoDSKAAAABk"]
[Thu Jul 30 12:23:48.793621 2026] [security2:error] [pid 727775:tid 728005] [client 17.22.237.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuIpMDCZkc4BvDXnoDSLAAAAGQ"]
[Thu Jul 30 12:23:48.811490 2026] [security2:error] [pid 727775:tid 727950] [client 142.93.53.183:57999] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/avatar/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIpMDCZkc4BvDXnoDSMAAAAC0"]
[Thu Jul 30 12:23:48.967494 2026] [security2:error] [pid 727775:tid 727927] [client 20.91.199.21:47660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/ava.php"] [unique_id "amuIpMDCZkc4BvDXnoDSNQAAABY"]
[Thu Jul 30 12:23:49.136146 2026] [security2:error] [pid 727775:tid 728023] [client 184.75.223.195:33762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIpcDCZkc4BvDXnoDSNwAAAHY"]
[Thu Jul 30 12:23:49.136252 2026] [security2:error] [pid 727775:tid 728023] [client 184.75.223.195:33762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIpcDCZkc4BvDXnoDSNwAAAHY"]
[Thu Jul 30 12:23:49.187467 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:58170] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/avatar/alfacgiapi/perl.alfa"] [unique_id "amuIpcDCZkc4BvDXnoDSOAAAAGA"]
[Thu Jul 30 12:23:49.519858 2026] [security2:error] [pid 727775:tid 727938] [client 172.213.232.128:4979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuIpcDCZkc4BvDXnoDSRQAAACE"]
[Thu Jul 30 12:23:49.562836 2026] [security2:error] [pid 727775:tid 727999] [client 142.93.53.183:58335] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/block/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIpcDCZkc4BvDXnoDSRgAAAF4"]
[Thu Jul 30 12:23:49.566350 2026] [security2:error] [pid 727775:tid 727920] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIpMDCZkc4BvDXnoDSNAAAD1U"]
[Thu Jul 30 12:23:49.749136 2026] [security2:error] [pid 727775:tid 727890] [remote 57.141.0.58:36064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7374488921/feed/rss2/"] [unique_id "amuIpcDCZkc4BvDXnoDSSgAAH3I"]
[Thu Jul 30 12:23:49.827531 2026] [security2:error] [pid 727775:tid 727995] [client 20.91.199.21:46737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/main.php"] [unique_id "amuIpcDCZkc4BvDXnoDSSwAAAFo"]
[Thu Jul 30 12:23:49.891834 2026] [security2:error] [pid 727775:tid 727975] [client 172.202.44.182:42001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/init.php"] [unique_id "amuIpcDCZkc4BvDXnoDSUwAAAEY"]
[Thu Jul 30 12:23:49.935769 2026] [security2:error] [pid 727775:tid 727907] [client 142.93.53.183:58474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/block/alfacgiapi/perl.alfa"] [unique_id "amuIpcDCZkc4BvDXnoDSVwAAAAI"]
[Thu Jul 30 12:23:50.330249 2026] [security2:error] [pid 727775:tid 727973] [client 142.93.53.183:58633] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/button/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIpsDCZkc4BvDXnoDSXAAAAEQ"]
[Thu Jul 30 12:23:50.458598 2026] [security2:error] [pid 727775:tid 727968] [client 20.91.199.21:47272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-file.php"] [unique_id "amuIpsDCZkc4BvDXnoDSYwAAAD8"]
[Thu Jul 30 12:23:50.486406 2026] [security2:error] [pid 727775:tid 727970] [client 85.204.70.116:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bkv.gpl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuIpsDCZkc4BvDXnoDSZAAAAEE"]
[Thu Jul 30 12:23:50.486489 2026] [security2:error] [pid 727775:tid 727970] [client 85.204.70.116:64896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bkv.gpl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuIpsDCZkc4BvDXnoDSZAAAAEE"]
[Thu Jul 30 12:23:50.722762 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:58796] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/button/alfacgiapi/perl.alfa"] [unique_id "amuIpsDCZkc4BvDXnoDSZQAAAF0"]
[Thu Jul 30 12:23:51.125120 2026] [security2:error] [pid 727775:tid 728018] [client 142.93.53.183:58935] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/buttons/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIp8DCZkc4BvDXnoDScAAAAHE"]
[Thu Jul 30 12:23:51.435919 2026] [security2:error] [pid 727775:tid 728004] [client 20.91.199.21:47258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-signin.php"] [unique_id "amuIp8DCZkc4BvDXnoDScgAAAGM"]
[Thu Jul 30 12:23:51.522060 2026] [security2:error] [pid 727775:tid 727957] [client 142.93.53.183:59105] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/buttons/alfacgiapi/perl.alfa"] [unique_id "amuIp8DCZkc4BvDXnoDSeQAAADQ"]
[Thu Jul 30 12:23:51.920410 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:59240] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/calendar/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIp8DCZkc4BvDXnoDSegAAACM"]
[Thu Jul 30 12:23:51.991000 2026] [core:notice] [pid 727775:tid 727947] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:52.243773 2026] [security2:error] [pid 727775:tid 727916] [client 172.213.232.128:4982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/images/about.php"] [unique_id "amuIqMDCZkc4BvDXnoDSggAAAAs"]
[Thu Jul 30 12:23:52.301185 2026] [security2:error] [pid 727775:tid 727911] [client 142.93.53.183:59364] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/calendar/alfacgiapi/perl.alfa"] [unique_id "amuIqMDCZkc4BvDXnoDSgwAAAAY"]
[Thu Jul 30 12:23:52.383948 2026] [security2:error] [pid 727775:tid 727943] [client 172.202.44.182:35779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/file5.php"] [unique_id "amuIqMDCZkc4BvDXnoDShAAAACY"]
[Thu Jul 30 12:23:52.535048 2026] [security2:error] [pid 727775:tid 728009] [client 20.91.199.21:47234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/simi.php"] [unique_id "amuIqMDCZkc4BvDXnoDSigAAAGg"]
[Thu Jul 30 12:23:52.724640 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:59512] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/categories/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIqMDCZkc4BvDXnoDSjAAAAB8"]
[Thu Jul 30 12:23:53.124958 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:59634] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/categories/alfacgiapi/perl.alfa"] [unique_id "amuIqcDCZkc4BvDXnoDSkwAAAC8"]
[Thu Jul 30 12:23:53.172572 2026] [security2:error] [pid 727775:tid 727908] [client 172.213.232.128:16358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/about.php"] [unique_id "amuIqcDCZkc4BvDXnoDSlAAAAAM"]
[Thu Jul 30 12:23:53.531464 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:59781] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/code/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIqcDCZkc4BvDXnoDSmQAAAA0"]
[Thu Jul 30 12:23:53.761599 2026] [security2:error] [pid 727775:tid 727973] [client 172.213.232.128:38941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/cgi-bin/about.php"] [unique_id "amuIqcDCZkc4BvDXnoDSoAAAAEQ"]
[Thu Jul 30 12:23:53.842629 2026] [security2:error] [pid 727775:tid 727785] [remote 47.128.112.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.112.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/98"] [unique_id "amuIqcDCZkc4BvDXnoDSnQAAPQk"]
[Thu Jul 30 12:23:53.910386 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:59931] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/code/alfacgiapi/perl.alfa"] [unique_id "amuIqcDCZkc4BvDXnoDSoQAAAD8"]
[Thu Jul 30 12:23:54.068452 2026] [core:notice] [pid 727775:tid 727815] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.288947 2026] [security2:error] [pid 727775:tid 727960] [client 142.93.53.183:60073] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/column/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIqsDCZkc4BvDXnoDSqQAAADc"]
[Thu Jul 30 12:23:54.384196 2026] [core:notice] [pid 727775:tid 727804] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.391700 2026] [security2:error] [pid 727775:tid 727791] [remote 47.128.112.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.112.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/---call---/page/page/css-name-font.css"] [unique_id "amuIqsDCZkc4BvDXnoDSqwAALA8"], referer: https://www.jipkl.com/index.php/JIPKL/article/view/98
[Thu Jul 30 12:23:54.494927 2026] [security2:error] [pid 727775:tid 727990] [client 20.91.199.21:47631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/wp-conf.php"] [unique_id "amuIqsDCZkc4BvDXnoDSrwAAAFU"]
[Thu Jul 30 12:23:54.610699 2026] [core:notice] [pid 727775:tid 727793] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.634011 2026] [core:notice] [pid 727775:tid 727813] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.652936 2026] [core:notice] [pid 727775:tid 727800] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:54.687457 2026] [security2:error] [pid 727775:tid 727947] [client 142.93.53.183:60224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/column/alfacgiapi/perl.alfa"] [unique_id "amuIqsDCZkc4BvDXnoDSuQAAACo"]
[Thu Jul 30 12:23:54.968114 2026] [core:notice] [pid 727775:tid 727796] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:55.032286 2026] [core:notice] [pid 727775:tid 727982] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:55.093413 2026] [security2:error] [pid 727775:tid 728013] [client 142.93.53.183:60352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/columns/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIq8DCZkc4BvDXnoDSvwAAAGw"]
[Thu Jul 30 12:23:55.281368 2026] [core:notice] [pid 727775:tid 727790] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:55.476283 2026] [security2:error] [pid 727775:tid 727995] [client 142.93.53.183:60493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/columns/alfacgiapi/perl.alfa"] [unique_id "amuIq8DCZkc4BvDXnoDSyAAAAFo"]
[Thu Jul 30 12:23:55.556664 2026] [security2:error] [pid 727775:tid 728014] [client 172.213.232.128:4627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/gallery/about.php"] [unique_id "amuIq8DCZkc4BvDXnoDSyQAAAG0"]
[Thu Jul 30 12:23:55.692094 2026] [security2:error] [pid 727775:tid 727958] [client 172.202.44.182:42013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuIq8DCZkc4BvDXnoDSzwAAADU"]
[Thu Jul 30 12:23:55.722484 2026] [core:notice] [pid 727775:tid 727969] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:55.862196 2026] [security2:error] [pid 727775:tid 727919] [client 142.93.53.183:60625] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-author-name/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIq8DCZkc4BvDXnoDS0gAAAA4"]
[Thu Jul 30 12:23:55.874872 2026] [security2:error] [pid 727775:tid 727799] [remote 97.74.87.194:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-468361c2.glb.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuIq8DCZkc4BvDXnoDS1AAAHxc"]
[Thu Jul 30 12:23:56.006341 2026] [core:notice] [pid 727775:tid 727805] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:56.242411 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:60783] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-author-name/alfacgiapi/perl.alfa"] [unique_id "amuIrMDCZkc4BvDXnoDS3gAAAHU"]
[Thu Jul 30 12:23:56.654810 2026] [core:notice] [pid 727775:tid 727948] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:56.720289 2026] [security2:error] [pid 727775:tid 727984] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuIrMDCZkc4BvDXnoDS4QAAAE8"]
[Thu Jul 30 12:23:56.736796 2026] [security2:error] [pid 727775:tid 727977] [client 142.93.53.183:60971] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-content/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIrMDCZkc4BvDXnoDS5wAAAEg"]
[Thu Jul 30 12:23:57.164698 2026] [security2:error] [pid 727775:tid 727974] [client 142.93.53.183:61132] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-content/alfacgiapi/perl.alfa"] [unique_id "amuIrcDCZkc4BvDXnoDS7AAAAEU"]
[Thu Jul 30 12:23:57.352171 2026] [core:notice] [pid 727775:tid 727926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:57.574383 2026] [security2:error] [pid 727775:tid 727980] [client 172.202.44.182:17481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/shell.php"] [unique_id "amuIrcDCZkc4BvDXnoDS9AAAAEs"]
[Thu Jul 30 12:23:57.647818 2026] [core:notice] [pid 727775:tid 727922] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:57.709038 2026] [security2:error] [pid 727775:tid 728000] [client 142.93.53.183:61326] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-date/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIrcDCZkc4BvDXnoDS9gAAAF8"]
[Thu Jul 30 12:23:58.030910 2026] [security2:error] [pid 727775:tid 727963] [client 20.91.199.21:47266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuIrsDCZkc4BvDXnoDS_QAAADo"]
[Thu Jul 30 12:23:58.064078 2026] [core:notice] [pid 727775:tid 727838] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:58.087125 2026] [core:notice] [pid 727775:tid 727931] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:58.090711 2026] [security2:error] [pid 727775:tid 728025] [client 142.93.53.183:61443] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-date/alfacgiapi/perl.alfa"] [unique_id "amuIrsDCZkc4BvDXnoDTAgAAAHg"]
[Thu Jul 30 12:23:58.463119 2026] [security2:error] [pid 727775:tid 727971] [client 142.93.53.183:61600] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-edit-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIrsDCZkc4BvDXnoDTCgAAAEI"]
[Thu Jul 30 12:23:58.574623 2026] [security2:error] [pid 727775:tid 727909] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIrsDCZkc4BvDXnoDS_gAABDk"]
[Thu Jul 30 12:23:58.678567 2026] [security2:error] [pid 727775:tid 727964] [client 20.91.199.21:47642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/bala.php"] [unique_id "amuIrsDCZkc4BvDXnoDTDgAAADs"]
[Thu Jul 30 12:23:58.839927 2026] [security2:error] [pid 727775:tid 727933] [client 142.93.53.183:61721] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-edit-link/alfacgiapi/perl.alfa"] [unique_id "amuIrsDCZkc4BvDXnoDTEgAAABw"]
[Thu Jul 30 12:23:59.121334 2026] [core:notice] [pid 727775:tid 728030] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:23:59.219576 2026] [security2:error] [pid 727775:tid 727968] [client 142.93.53.183:61858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-reply-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIr8DCZkc4BvDXnoDTFwAAAD8"]
[Thu Jul 30 12:23:59.497823 2026] [security2:error] [pid 727775:tid 727835] [remote 57.141.0.33:29298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/63798190810/feed/rss2/"] [unique_id "amuIr8DCZkc4BvDXnoDTHwAAaTs"]
[Thu Jul 30 12:23:59.606654 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:61989] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-reply-link/alfacgiapi/perl.alfa"] [unique_id "amuIr8DCZkc4BvDXnoDTIAAAAGY"]
[Thu Jul 30 12:23:59.669610 2026] [security2:error] [pid 727775:tid 727935] [client 20.91.199.21:47618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/bk.php"] [unique_id "amuIr8DCZkc4BvDXnoDTIQAAAB4"]
[Thu Jul 30 12:23:59.995049 2026] [security2:error] [pid 727775:tid 728004] [client 142.93.53.183:62103] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-template/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIr8DCZkc4BvDXnoDTKAAAAGM"]
[Thu Jul 30 12:24:00.000342 2026] [security2:error] [pid 727775:tid 728020] [client 87.101.92.171:56294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIr8DCZkc4BvDXnoDTKQAAAHM"]
[Thu Jul 30 12:24:00.000429 2026] [security2:error] [pid 727775:tid 728020] [client 87.101.92.171:56294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuIr8DCZkc4BvDXnoDTKQAAAHM"]
[Thu Jul 30 12:24:00.110251 2026] [security2:error] [pid 727775:tid 727826] [remote 57.141.0.67:64552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/view/9398/4174"] [unique_id "amuIsMDCZkc4BvDXnoDTKgAACjI"]
[Thu Jul 30 12:24:00.113538 2026] [security2:error] [pid 727775:tid 727925] [client 172.202.44.182:42037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/f35.php"] [unique_id "amuIsMDCZkc4BvDXnoDTKwAAABQ"]
[Thu Jul 30 12:24:00.392386 2026] [security2:error] [pid 727775:tid 728024] [client 142.93.53.183:62229] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comment-template/alfacgiapi/perl.alfa"] [unique_id "amuIsMDCZkc4BvDXnoDTLwAAAHc"]
[Thu Jul 30 12:24:00.410403 2026] [security2:error] [pid 727775:tid 727972] [client 20.91.199.21:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.svcambodia.com"] [uri "/ahax.php"] [unique_id "amuIsMDCZkc4BvDXnoDTMAAAAEM"]
[Thu Jul 30 12:24:00.843595 2026] [security2:error] [pid 727775:tid 728009] [client 142.93.53.183:62362] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIsMDCZkc4BvDXnoDTNQAAAGg"]
[Thu Jul 30 12:24:01.136281 2026] [core:notice] [pid 727775:tid 727926] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:01.311758 2026] [security2:error] [pid 727775:tid 727936] [client 142.93.53.183:62492] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments/alfacgiapi/perl.alfa"] [unique_id "amuIscDCZkc4BvDXnoDTRAAAAB8"]
[Thu Jul 30 12:24:01.344206 2026] [security2:error] [pid 727775:tid 728031] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuIsMDCZkc4BvDXnoDTNAAAfjE"]
[Thu Jul 30 12:24:01.701442 2026] [security2:error] [pid 727775:tid 728032] [client 142.93.53.183:62599] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIscDCZkc4BvDXnoDTTQAAAH8"]
[Thu Jul 30 12:24:02.147889 2026] [security2:error] [pid 727775:tid 727998] [client 142.93.53.183:62743] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination/alfacgiapi/perl.alfa"] [unique_id "amuIssDCZkc4BvDXnoDTVwAAAF0"]
[Thu Jul 30 12:24:02.496925 2026] [security2:error] [pid 727775:tid 727921] [client 23.21.250.48:60806] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2018/09/mae-romulo.jpg"] [unique_id "amuIssDCZkc4BvDXnoDTWQAAABA"]
[Thu Jul 30 12:24:02.533753 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:62858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-next/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIssDCZkc4BvDXnoDTWwAAACw"]
[Thu Jul 30 12:24:02.924209 2026] [security2:error] [pid 727775:tid 728004] [client 142.93.53.183:62962] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-next/alfacgiapi/perl.alfa"] [unique_id "amuIssDCZkc4BvDXnoDTZQAAAGM"]
[Thu Jul 30 12:24:03.022423 2026] [security2:error] [pid 727775:tid 727993] [client 172.213.232.128:16366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuIs8DCZkc4BvDXnoDTZgAAAFg"]
[Thu Jul 30 12:24:03.272786 2026] [core:notice] [pid 727775:tid 728017] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:03.310266 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:63051] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-numbers/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIs8DCZkc4BvDXnoDTbwAAACA"]
[Thu Jul 30 12:24:03.693070 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:63167] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-numbers/alfacgiapi/perl.alfa"] [unique_id "amuIs8DCZkc4BvDXnoDTgAAAAGc"]
[Thu Jul 30 12:24:03.705184 2026] [security2:error] [pid 727775:tid 727982] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuIs8DCZkc4BvDXnoDTcwAAAE0"]
[Thu Jul 30 12:24:03.751694 2026] [core:notice] [pid 727775:tid 727975] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:03.753548 2026] [security2:error] [pid 727775:tid 727975] [client 34.165.207.64:1024] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/category/brasil/feed/"] [unique_id "amuIs8DCZkc4BvDXnoDTgQAAAEY"]
[Thu Jul 30 12:24:03.812042 2026] [security2:error] [pid 727775:tid 728009] [client 172.213.232.128:10283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/about.php"] [unique_id "amuIs8DCZkc4BvDXnoDTggAAAGg"]
[Thu Jul 30 12:24:04.075109 2026] [security2:error] [pid 727775:tid 727934] [client 142.93.53.183:63274] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-previous/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuItMDCZkc4BvDXnoDThQAAAB0"]
[Thu Jul 30 12:24:04.091627 2026] [core:notice] [pid 727775:tid 728000] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:04.313949 2026] [security2:error] [pid 727775:tid 728030] [client 172.202.44.182:17511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/new.php"] [unique_id "amuItMDCZkc4BvDXnoDTjgAAAH0"]
[Thu Jul 30 12:24:04.314416 2026] [core:notice] [pid 727775:tid 727952] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:04.471074 2026] [security2:error] [pid 727775:tid 727918] [client 142.93.53.183:63403] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-pagination-previous/alfacgiapi/perl.alfa"] [unique_id "amuItMDCZkc4BvDXnoDTkAAAAA0"]
[Thu Jul 30 12:24:04.570016 2026] [security2:error] [pid 727775:tid 727936] [client 95.108.213.97:64518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuItMDCZkc4BvDXnoDTjQAAAB8"]
[Thu Jul 30 12:24:04.857683 2026] [security2:error] [pid 727775:tid 727930] [client 142.93.53.183:63529] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-title/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuItMDCZkc4BvDXnoDTnQAAABk"]
[Thu Jul 30 12:24:05.103677 2026] [security2:error] [pid 727775:tid 727864] [remote 198.38.94.67:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.zjp.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuItcDCZkc4BvDXnoDTowAAdFg"]
[Thu Jul 30 12:24:05.327603 2026] [security2:error] [pid 727775:tid 728020] [client 142.93.53.183:63689] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/comments-title/alfacgiapi/perl.alfa"] [unique_id "amuItcDCZkc4BvDXnoDTqwAAAHM"]
[Thu Jul 30 12:24:05.781595 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:63858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/cover/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuItcDCZkc4BvDXnoDTswAAACA"]
[Thu Jul 30 12:24:06.174283 2026] [security2:error] [pid 727775:tid 728001] [client 142.93.53.183:63989] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content-new/ai1wm-backups/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuItsDCZkc4BvDXnoDTuAAAAGA"]
[Thu Jul 30 12:24:06.555047 2026] [security2:error] [pid 727775:tid 727976] [client 142.93.53.183:64097] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content-new/ai1wm-backups/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuItsDCZkc4BvDXnoDTzQAAAEc"]
[Thu Jul 30 12:24:06.859451 2026] [security2:error] [pid 727775:tid 727997] [client 172.202.44.182:17518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/adminfuns.php"] [unique_id "amuItsDCZkc4BvDXnoDT1wAAAFw"]
[Thu Jul 30 12:24:06.969966 2026] [security2:error] [pid 727775:tid 727919] [client 142.93.53.183:64243] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content-new/ai1wm-backups/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuItsDCZkc4BvDXnoDT2AAAAA4"]
[Thu Jul 30 12:24:07.014375 2026] [security2:error] [pid 727775:tid 727942] [client 66.249.73.97:59578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuItsDCZkc4BvDXnoDTzgAAACU"]
[Thu Jul 30 12:24:07.123863 2026] [core:notice] [pid 727775:tid 727963] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:07.327772 2026] [security2:error] [pid 727775:tid 727992] [client 66.249.79.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.legalsnaps.info"] [uri "/index.php"] [unique_id "amuIt8DCZkc4BvDXnoDT3AAAAFc"]
[Thu Jul 30 12:24:07.359743 2026] [security2:error] [pid 727775:tid 728032] [client 142.93.53.183:64378] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ai1wm-backups/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIt8DCZkc4BvDXnoDT4QAAAH8"]
[Thu Jul 30 12:24:07.741281 2026] [security2:error] [pid 727775:tid 728022] [client 142.93.53.183:64522] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ai1wm-backups/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuIt8DCZkc4BvDXnoDT5wAAAHU"]
[Thu Jul 30 12:24:08.123576 2026] [security2:error] [pid 727775:tid 728012] [client 142.93.53.183:64666] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ai1wm-backups/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuIuMDCZkc4BvDXnoDT8QAAAGs"]
[Thu Jul 30 12:24:08.306902 2026] [security2:error] [pid 727775:tid 728025] [client 172.213.232.128:10251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/images/about.php"] [unique_id "amuIuMDCZkc4BvDXnoDT8wAAAHg"]
[Thu Jul 30 12:24:08.573192 2026] [security2:error] [pid 727775:tid 728006] [client 142.93.53.183:64831] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/cover/alfacgiapi/perl.alfa"] [unique_id "amuIuMDCZkc4BvDXnoDT-wAAAGU"]
[Thu Jul 30 12:24:08.573858 2026] [security2:error] [pid 727775:tid 727792] [remote 57.141.0.52:61770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/640974427/feed/rss2/"] [unique_id "amuIuMDCZkc4BvDXnoDT_AAAMxA"]
[Thu Jul 30 12:24:08.776672 2026] [security2:error] [pid 727775:tid 727986] [client 172.202.44.182:42039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/fm.php"] [unique_id "amuIuMDCZkc4BvDXnoDT_QAAAFE"]
[Thu Jul 30 12:24:08.950684 2026] [security2:error] [pid 727775:tid 727925] [client 142.93.53.183:64945] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/details/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIuMDCZkc4BvDXnoDUAgAAABQ"]
[Thu Jul 30 12:24:09.330194 2026] [security2:error] [pid 727775:tid 727909] [client 142.93.53.183:65065] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/details/alfacgiapi/perl.alfa"] [unique_id "amuIucDCZkc4BvDXnoDUCQAAAAQ"]
[Thu Jul 30 12:24:09.816821 2026] [security2:error] [pid 727775:tid 727946] [client 142.93.53.183:65221] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/embed/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIucDCZkc4BvDXnoDUEgAAACk"]
[Thu Jul 30 12:24:10.172708 2026] [core:notice] [pid 727775:tid 728008] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:10.204588 2026] [security2:error] [pid 727775:tid 727969] [client 142.93.53.183:65341] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/embed/alfacgiapi/perl.alfa"] [unique_id "amuIusDCZkc4BvDXnoDUHwAAAEA"]
[Thu Jul 30 12:24:10.305085 2026] [security2:error] [pid 727775:tid 727793] [remote 40.77.167.28:42509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/12812638002258/indexf.php"] [unique_id "amuIusDCZkc4BvDXnoDUHAAAGRE"]
[Thu Jul 30 12:24:10.593891 2026] [security2:error] [pid 727775:tid 727954] [client 142.93.53.183:65470] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/file/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIusDCZkc4BvDXnoDUJgAAADE"]
[Thu Jul 30 12:24:10.957368 2026] [core:notice] [pid 727775:tid 728025] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:10.989443 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:49210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/file/alfacgiapi/perl.alfa"] [unique_id "amuIusDCZkc4BvDXnoDULAAAABY"]
[Thu Jul 30 12:24:11.407168 2026] [security2:error] [pid 727775:tid 727940] [client 142.93.53.183:49339] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/footnotes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIu8DCZkc4BvDXnoDUMwAAACM"]
[Thu Jul 30 12:24:11.440369 2026] [security2:error] [pid 727775:tid 727973] [client 172.202.44.182:17639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/file.php"] [unique_id "amuIu8DCZkc4BvDXnoDUNAAAAEQ"]
[Thu Jul 30 12:24:11.794223 2026] [security2:error] [pid 727775:tid 727905] [client 142.93.53.183:49473] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/footnotes/alfacgiapi/perl.alfa"] [unique_id "amuIu8DCZkc4BvDXnoDUOwAAAAA"]
[Thu Jul 30 12:24:12.191124 2026] [security2:error] [pid 727775:tid 727982] [client 142.93.53.183:49602] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/freeform/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIvMDCZkc4BvDXnoDUQgAAAE0"]
[Thu Jul 30 12:24:12.576280 2026] [security2:error] [pid 727775:tid 727934] [client 142.93.53.183:49739] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/freeform/alfacgiapi/perl.alfa"] [unique_id "amuIvMDCZkc4BvDXnoDURgAAAB0"]
[Thu Jul 30 12:24:12.977213 2026] [core:notice] [pid 727775:tid 727805] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:13.172948 2026] [security2:error] [pid 727775:tid 727985] [client 142.93.53.183:49946] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/gallery/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIvcDCZkc4BvDXnoDUTgAAAFA"]
[Thu Jul 30 12:24:13.201141 2026] [core:notice] [pid 727775:tid 727941] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:13.559819 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:50070] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/gallery/alfacgiapi/perl.alfa"] [unique_id "amuIvcDCZkc4BvDXnoDUVgAAACI"]
[Thu Jul 30 12:24:13.960189 2026] [security2:error] [pid 727775:tid 727994] [client 142.93.53.183:50195] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/group/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIvcDCZkc4BvDXnoDUXgAAAFk"]
[Thu Jul 30 12:24:14.343101 2026] [security2:error] [pid 727775:tid 728026] [client 142.93.53.183:50323] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/group/alfacgiapi/perl.alfa"] [unique_id "amuIvsDCZkc4BvDXnoDUZgAAAHk"]
[Thu Jul 30 12:24:14.556758 2026] [security2:error] [pid 727775:tid 727818] [remote 157.55.39.49:40193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/183299856812/indexf.php"] [unique_id "amuIvsDCZkc4BvDXnoDUZQAAMSo"]
[Thu Jul 30 12:24:14.721510 2026] [security2:error] [pid 727775:tid 728003] [client 142.93.53.183:50453] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/heading/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIvsDCZkc4BvDXnoDUawAAAGI"]
[Thu Jul 30 12:24:15.125569 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:50583] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/heading/alfacgiapi/perl.alfa"] [unique_id "amuIv8DCZkc4BvDXnoDUcgAAACY"]
[Thu Jul 30 12:24:15.499371 2026] [security2:error] [pid 727775:tid 727972] [client 142.93.53.183:50722] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/home-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIv8DCZkc4BvDXnoDUeQAAAEM"]
[Thu Jul 30 12:24:15.763147 2026] [security2:error] [pid 727775:tid 727911] [client 172.202.44.182:42004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/bolt.php"] [unique_id "amuIv8DCZkc4BvDXnoDUfgAAAAY"]
[Thu Jul 30 12:24:15.890923 2026] [security2:error] [pid 727775:tid 727926] [client 142.93.53.183:50841] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/home-link/alfacgiapi/perl.alfa"] [unique_id "amuIv8DCZkc4BvDXnoDUhAAAABU"]
[Thu Jul 30 12:24:16.123890 2026] [security2:error] [pid 727775:tid 727942] [client 87.101.92.171:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuIwMDCZkc4BvDXnoDUhgAAACU"]
[Thu Jul 30 12:24:16.124022 2026] [security2:error] [pid 727775:tid 727942] [client 87.101.92.171:45290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuIwMDCZkc4BvDXnoDUhgAAACU"]
[Thu Jul 30 12:24:16.158233 2026] [core:notice] [pid 727775:tid 727916] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:16.250001 2026] [core:notice] [pid 727775:tid 727999] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:16.289886 2026] [security2:error] [pid 727775:tid 727963] [client 142.93.53.183:50981] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/html/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIwMDCZkc4BvDXnoDUjAAAADo"]
[Thu Jul 30 12:24:16.583510 2026] [security2:error] [pid 727775:tid 727931] [client 172.213.232.128:7341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuIwMDCZkc4BvDXnoDUkAAAABo"]
[Thu Jul 30 12:24:16.665766 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:51117] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/html/alfacgiapi/perl.alfa"] [unique_id "amuIwMDCZkc4BvDXnoDUkQAAACI"]
[Thu Jul 30 12:24:16.909570 2026] [security2:error] [pid 727775:tid 728022] [client 87.101.92.171:56244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuIwMDCZkc4BvDXnoDUmAAAAHU"]
[Thu Jul 30 12:24:16.909677 2026] [security2:error] [pid 727775:tid 728022] [client 87.101.92.171:56244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuIwMDCZkc4BvDXnoDUmAAAAHU"]
[Thu Jul 30 12:24:16.941673 2026] [security2:error] [pid 727775:tid 727952] [client 172.202.44.182:17528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/3.php"] [unique_id "amuIwMDCZkc4BvDXnoDUmQAAAC8"]
[Thu Jul 30 12:24:17.046695 2026] [security2:error] [pid 727775:tid 727935] [client 142.93.53.183:51251] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/image/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIwcDCZkc4BvDXnoDUmgAAAB4"]
[Thu Jul 30 12:24:17.424620 2026] [security2:error] [pid 727775:tid 727958] [client 142.93.53.183:51374] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/image/alfacgiapi/perl.alfa"] [unique_id "amuIwcDCZkc4BvDXnoDUoQAAADU"]
[Thu Jul 30 12:24:17.827868 2026] [security2:error] [pid 727775:tid 728028] [client 142.93.53.183:51481] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/latest-comments/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIwcDCZkc4BvDXnoDUpQAAAHs"]
[Thu Jul 30 12:24:17.998144 2026] [security2:error] [pid 727775:tid 727984] [client 38.190.144.4:58339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIwcDCZkc4BvDXnoDUqQAAAE8"]
[Thu Jul 30 12:24:17.998270 2026] [security2:error] [pid 727775:tid 727984] [client 38.190.144.4:58339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIwcDCZkc4BvDXnoDUqQAAAE8"]
[Thu Jul 30 12:24:18.205393 2026] [security2:error] [pid 727775:tid 727996] [client 142.93.53.183:51590] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/latest-comments/alfacgiapi/perl.alfa"] [unique_id "amuIwsDCZkc4BvDXnoDUqgAAAFs"]
[Thu Jul 30 12:24:18.587561 2026] [security2:error] [pid 727775:tid 727943] [client 142.93.53.183:51695] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/latest-posts/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIwsDCZkc4BvDXnoDUsgAAACY"]
[Thu Jul 30 12:24:18.978091 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:51810] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/latest-posts/alfacgiapi/perl.alfa"] [unique_id "amuIwsDCZkc4BvDXnoDUvQAAABY"]
[Thu Jul 30 12:24:19.372230 2026] [security2:error] [pid 727775:tid 727909] [client 74.7.241.137:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webdisk.meg.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/cgi-sys/404.html"] [unique_id "amuIw8DCZkc4BvDXnoDUxAAAAAQ"]
[Thu Jul 30 12:24:19.373933 2026] [security2:error] [pid 727775:tid 727913] [client 74.7.241.137:43856] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webdisk.meg.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuIw8DCZkc4BvDXnoDUwgAACDQ"]
[Thu Jul 30 12:24:19.390171 2026] [security2:error] [pid 727775:tid 727908] [client 142.93.53.183:51936] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/legacy-widget/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIw8DCZkc4BvDXnoDUxQAAAAM"]
[Thu Jul 30 12:24:19.891990 2026] [security2:error] [pid 727775:tid 728030] [client 142.93.53.183:52072] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/legacy-widget/alfacgiapi/perl.alfa"] [unique_id "amuIw8DCZkc4BvDXnoDU0QAAAH0"]
[Thu Jul 30 12:24:20.274348 2026] [security2:error] [pid 727775:tid 728008] [client 142.93.53.183:52201] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/list/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIxMDCZkc4BvDXnoDU2QAAAGc"]
[Thu Jul 30 12:24:20.669657 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:52320] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/list/alfacgiapi/perl.alfa"] [unique_id "amuIxMDCZkc4BvDXnoDU4AAAAGY"]
[Thu Jul 30 12:24:21.078565 2026] [security2:error] [pid 727775:tid 727994] [client 172.213.232.128:22371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuIxcDCZkc4BvDXnoDU7AAAAFk"]
[Thu Jul 30 12:24:21.100440 2026] [security2:error] [pid 727775:tid 728025] [client 142.93.53.183:52444] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/list-item/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIxcDCZkc4BvDXnoDU7QAAAHg"]
[Thu Jul 30 12:24:21.285566 2026] [security2:error] [pid 727775:tid 727926] [client 172.202.44.182:42026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/222.php"] [unique_id "amuIxcDCZkc4BvDXnoDU7gAAABU"]
[Thu Jul 30 12:24:21.488224 2026] [security2:error] [pid 727775:tid 727947] [client 142.93.53.183:52560] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/list-item/alfacgiapi/perl.alfa"] [unique_id "amuIxcDCZkc4BvDXnoDU7wAAACo"]
[Thu Jul 30 12:24:21.535808 2026] [security2:error] [pid 727775:tid 727851] [remote 57.141.0.22:20936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuIxcDCZkc4BvDXnoDU8gAAK0s"]
[Thu Jul 30 12:24:21.737629 2026] [security2:error] [pid 727775:tid 727973] [client 172.213.232.128:20492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuIxcDCZkc4BvDXnoDU9wAAAEQ"]
[Thu Jul 30 12:24:21.900613 2026] [security2:error] [pid 727775:tid 727937] [client 142.93.53.183:52687] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/loginout/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIxcDCZkc4BvDXnoDU-AAAACA"]
[Thu Jul 30 12:24:22.272853 2026] [security2:error] [pid 727775:tid 727914] [client 142.93.53.183:52797] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/loginout/alfacgiapi/perl.alfa"] [unique_id "amuIxsDCZkc4BvDXnoDVAgAAAAk"]
[Thu Jul 30 12:24:22.362652 2026] [security2:error] [pid 727775:tid 727986] [client 20.203.148.31:45833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/011i.php"] [unique_id "amuIxsDCZkc4BvDXnoDVAwAAAFE"]
[Thu Jul 30 12:24:22.541089 2026] [security2:error] [pid 727775:tid 727912] [client 172.213.232.128:22364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/cloud.php"] [unique_id "amuIxsDCZkc4BvDXnoDVBAAAAAc"]
[Thu Jul 30 12:24:22.657709 2026] [security2:error] [pid 727775:tid 727944] [client 142.93.53.183:52903] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/media-text/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIxsDCZkc4BvDXnoDVDAAAACc"]
[Thu Jul 30 12:24:23.047534 2026] [security2:error] [pid 727775:tid 727972] [client 172.202.44.182:17600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuIx8DCZkc4BvDXnoDVDQAAAEM"]
[Thu Jul 30 12:24:23.072698 2026] [security2:error] [pid 727775:tid 727916] [client 142.93.53.183:53014] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/media-text/alfacgiapi/perl.alfa"] [unique_id "amuIx8DCZkc4BvDXnoDVDgAAAAs"]
[Thu Jul 30 12:24:23.456070 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:53118] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/missing/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIx8DCZkc4BvDXnoDVGQAAACI"]
[Thu Jul 30 12:24:23.842823 2026] [security2:error] [pid 727775:tid 727952] [client 142.93.53.183:53220] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/missing/alfacgiapi/perl.alfa"] [unique_id "amuIx8DCZkc4BvDXnoDVIAAAAC8"]
[Thu Jul 30 12:24:23.889270 2026] [security2:error] [pid 727775:tid 727960] [client 20.203.148.31:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/03a005685d.php"] [unique_id "amuIx8DCZkc4BvDXnoDVIQAAADc"]
[Thu Jul 30 12:24:24.123346 2026] [security2:error] [pid 727775:tid 727855] [remote 157.55.39.49:14554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/column/shibutanijisseki/article.php"] [unique_id "amuIyMDCZkc4BvDXnoDVIgAAf08"]
[Thu Jul 30 12:24:24.219145 2026] [security2:error] [pid 727775:tid 727923] [client 172.202.44.182:17630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuIyMDCZkc4BvDXnoDVJgAAABI"]
[Thu Jul 30 12:24:24.225901 2026] [security2:error] [pid 727775:tid 727949] [client 142.93.53.183:53331] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/more/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIyMDCZkc4BvDXnoDVJwAAACw"]
[Thu Jul 30 12:24:24.548391 2026] [security2:error] [pid 727775:tid 728012] [client 20.203.148.31:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/403.php"] [unique_id "amuIyMDCZkc4BvDXnoDVLAAAAGs"]
[Thu Jul 30 12:24:24.628031 2026] [security2:error] [pid 727775:tid 727990] [client 142.93.53.183:53444] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/more/alfacgiapi/perl.alfa"] [unique_id "amuIyMDCZkc4BvDXnoDVLQAAAFU"]
[Thu Jul 30 12:24:25.030022 2026] [security2:error] [pid 727775:tid 727993] [client 142.93.53.183:53565] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIycDCZkc4BvDXnoDVNgAAAFg"]
[Thu Jul 30 12:24:25.104015 2026] [security2:error] [pid 727775:tid 727957] [client 127.0.0.1:31236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIycDCZkc4BvDXnoDVOQAAADQ"]
[Thu Jul 30 12:24:25.104026 2026] [security2:error] [pid 727775:tid 727978] [client 127.0.0.1:31232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.aws.gzj.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuIycDCZkc4BvDXnoDVOAAAAEk"]
[Thu Jul 30 12:24:25.104106 2026] [security2:error] [pid 727775:tid 727947] [client 74.7.244.37:42700] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.aws.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuIycDCZkc4BvDXnoDVNwAAKmk"]
[Thu Jul 30 12:24:25.421844 2026] [security2:error] [pid 727775:tid 727927] [client 142.93.53.183:53677] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation/alfacgiapi/perl.alfa"] [unique_id "amuIycDCZkc4BvDXnoDVRAAAABY"]
[Thu Jul 30 12:24:25.747999 2026] [security2:error] [pid 727775:tid 727967] [client 172.202.44.182:17635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-content/admin.php"] [unique_id "amuIycDCZkc4BvDXnoDVSwAAAD4"]
[Thu Jul 30 12:24:25.830190 2026] [security2:error] [pid 727775:tid 727913] [client 142.93.53.183:53783] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIycDCZkc4BvDXnoDVTQAAAAg"]
[Thu Jul 30 12:24:25.895343 2026] [security2:error] [pid 727775:tid 727995] [client 172.213.232.128:15519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/cgi-bin/cloud.php"] [unique_id "amuIycDCZkc4BvDXnoDVUwAAAFo"]
[Thu Jul 30 12:24:25.981224 2026] [security2:error] [pid 727775:tid 727964] [client 20.203.148.31:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/404.php"] [unique_id "amuIycDCZkc4BvDXnoDVWAAAADs"]
[Thu Jul 30 12:24:26.216074 2026] [security2:error] [pid 727775:tid 727939] [client 142.93.53.183:53912] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation-link/alfacgiapi/perl.alfa"] [unique_id "amuIysDCZkc4BvDXnoDVWQAAACI"]
[Thu Jul 30 12:24:26.268007 2026] [core:notice] [pid 727775:tid 727854] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:26.438544 2026] [security2:error] [pid 727775:tid 728022] [client 172.213.232.128:4658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/updates.php"] [unique_id "amuIysDCZkc4BvDXnoDVYgAAAHU"]
[Thu Jul 30 12:24:26.596393 2026] [security2:error] [pid 727775:tid 728007] [client 142.93.53.183:54034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation-submenu/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuIysDCZkc4BvDXnoDVZAAAAGY"]
[Thu Jul 30 12:24:26.666743 2026] [security2:error] [pid 727775:tid 727952] [client 20.203.148.31:44745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/aa.php"] [unique_id "amuIysDCZkc4BvDXnoDVZQAAAC8"]
[Thu Jul 30 12:24:26.915501 2026] [security2:error] [pid 727775:tid 727971] [client 38.190.144.4:58831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIysDCZkc4BvDXnoDVbAAAAEI"]
[Thu Jul 30 12:24:26.915638 2026] [security2:error] [pid 727775:tid 727971] [client 38.190.144.4:58831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuIysDCZkc4BvDXnoDVbAAAAEI"]
[Thu Jul 30 12:24:26.970960 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00493: SIGUSR1 received.  Doing graceful restart
[Thu Jul 30 12:24:28.057593 2026] [:notice] [pid 642290:tid 642290] [host root@sh00085.hostgator.com] mod_lsapi:  Selfstarter 642290 stopped
[Thu Jul 30 12:24:30.384724 2026] [lsapi:notice] [pid 8929:tid 8929] mod_lsapi:  version 1.1-92
[Thu Jul 30 12:24:30.387771 2026] [:notice] [pid 738754:tid 738754] [host root@sh00085.hostgator.com] mod_lsapi:  Selfstarter 738754 started
[Thu Jul 30 12:24:30.760582 2026] [ssl:warn] [pid 8929:tid 8929] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Jul 30 12:24:30.767823 2026] [qos:notice] [pid 8929:tid 8929] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Jul 30 12:24:30.946963 2026] [http2:info] [pid 8929:tid 8929] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Thu Jul 30 12:24:30.950485 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Jul 30 12:24:30.950509 2026] [core:notice] [pid 8929:tid 8929] AH00094: Command line: '/usr/sbin/httpd'
[Thu Jul 30 12:24:31.996044 2026] [http2:info] [pid 738779:tid 738779] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:24:32.009624 2026] [security2:error] [pid 738779:tid 738909] [client 142.93.53.183:54165] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/navigation-submenu/alfacgiapi/perl.alfa"] [unique_id "amuI0Pxa4UbeLxj1SWW0BAAAAIU"]
[Thu Jul 30 12:24:32.179257 2026] [security2:error] [pid 738779:tid 738913] [client 172.213.232.128:16012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/css/cloud.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0EwAAAIk"]
[Thu Jul 30 12:24:32.399467 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:55708] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/nextpage/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0Pxa4UbeLxj1SWW0LwAAAMI"]
[Thu Jul 30 12:24:32.598081 2026] [core:notice] [pid 738779:tid 738989] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:32.781162 2026] [security2:error] [pid 738779:tid 738997] [client 142.93.53.183:55807] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/nextpage/alfacgiapi/perl.alfa"] [unique_id "amuI0Pxa4UbeLxj1SWW0NwAAAN0"]
[Thu Jul 30 12:24:32.873945 2026] [security2:error] [pid 738779:tid 738959] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0JgAAALc"]
[Thu Jul 30 12:24:32.880422 2026] [security2:error] [pid 738779:tid 738960] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0KQAAALg"]
[Thu Jul 30 12:24:33.160065 2026] [security2:error] [pid 738779:tid 739020] [client 142.93.53.183:55929] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/page-list/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0fxa4UbeLxj1SWW0QQAAAPQ"]
[Thu Jul 30 12:24:33.175902 2026] [security2:error] [pid 738779:tid 739019] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuI0fxa4UbeLxj1SWW0QAAAAPM"]
[Thu Jul 30 12:24:33.236382 2026] [security2:error] [pid 738779:tid 738798] [remote 74.7.241.60:54004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuI0fxa4UbeLxj1SWW0QgAA8BI"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:24:33.257494 2026] [security2:error] [pid 738779:tid 739015] [client 172.213.232.128:20049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuI0fxa4UbeLxj1SWW0QwAAAO8"]
[Thu Jul 30 12:24:33.469118 2026] [security2:error] [pid 738779:tid 738929] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0MgAAmQ0"]
[Thu Jul 30 12:24:33.538830 2026] [security2:error] [pid 738779:tid 739023] [client 146.103.110.13:50914] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.110.13" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "seven-stars-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuI0fxa4UbeLxj1SWW0SgAAAPc"], referer: https://seven-stars-shop.com/hello-world/
[Thu Jul 30 12:24:33.538998 2026] [security2:error] [pid 738779:tid 739023] [client 146.103.110.13:50914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuI0fxa4UbeLxj1SWW0SgAAAPc"], referer: https://seven-stars-shop.com/hello-world/
[Thu Jul 30 12:24:33.539476 2026] [security2:error] [pid 738779:tid 738910] [client 142.93.53.183:56034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/page-list/alfacgiapi/perl.alfa"] [unique_id "amuI0fxa4UbeLxj1SWW0SwAAAIY"]
[Thu Jul 30 12:24:33.763692 2026] [security2:error] [pid 738779:tid 738927] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI0Pxa4UbeLxj1SWW0NgAAlw4"]
[Thu Jul 30 12:24:33.922144 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:56131] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/page-list-item/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0fxa4UbeLxj1SWW0TwAAAI0"]
[Thu Jul 30 12:24:34.311459 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:56213] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/page-list-item/alfacgiapi/perl.alfa"] [unique_id "amuI0vxa4UbeLxj1SWW0XAAAAMc"]
[Thu Jul 30 12:24:34.491047 2026] [security2:error] [pid 738779:tid 738980] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuI0vxa4UbeLxj1SWW0YgAAAMw"]
[Thu Jul 30 12:24:34.491210 2026] [security2:error] [pid 738779:tid 738980] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuI0vxa4UbeLxj1SWW0YgAAAMw"]
[Thu Jul 30 12:24:34.691137 2026] [security2:error] [pid 738779:tid 738985] [client 142.93.53.183:56292] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/paragraph/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0vxa4UbeLxj1SWW0ZwAAANE"]
[Thu Jul 30 12:24:34.847040 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuI0vxa4UbeLxj1SWW0agAAALM"]
[Thu Jul 30 12:24:34.847152 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuI0vxa4UbeLxj1SWW0agAAALM"]
[Thu Jul 30 12:24:35.072354 2026] [security2:error] [pid 738779:tid 738992] [client 142.93.53.183:56378] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/paragraph/alfacgiapi/perl.alfa"] [unique_id "amuI0_xa4UbeLxj1SWW0cQAAANg"]
[Thu Jul 30 12:24:35.216427 2026] [security2:error] [pid 738779:tid 738999] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/x.php"] [unique_id "amuI0_xa4UbeLxj1SWW0cgAAAN8"]
[Thu Jul 30 12:24:35.216560 2026] [security2:error] [pid 738779:tid 738999] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/x.php"] [unique_id "amuI0_xa4UbeLxj1SWW0cgAAAN8"]
[Thu Jul 30 12:24:35.244125 2026] [security2:error] [pid 738779:tid 738914] [client 20.203.148.31:47142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/aafewc0k.php"] [unique_id "amuI0_xa4UbeLxj1SWW0cwAAAIo"]
[Thu Jul 30 12:24:35.320990 2026] [security2:error] [pid 727775:tid 728010] [client 172.202.44.182:35776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-configs.php"] [unique_id "amuI08DCZkc4BvDXnoDVbQAAAGk"]
[Thu Jul 30 12:24:35.321165 2026] [log_config:warn] [pid 727775:tid 728010] (32)Broken pipe: [client 172.202.44.182:35776] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:24:35.321177 2026] [log_config:warn] [pid 727775:tid 728010] (32)Broken pipe: [client 172.202.44.182:35776] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:24:35.450453 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:56474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/pattern/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI0_xa4UbeLxj1SWW0eAAAAOQ"]
[Thu Jul 30 12:24:35.524682 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/mgrr.php"] [unique_id "amuI0_xa4UbeLxj1SWW0fAAAAOA"]
[Thu Jul 30 12:24:35.524801 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/mgrr.php"] [unique_id "amuI0_xa4UbeLxj1SWW0fAAAAOA"]
[Thu Jul 30 12:24:35.632248 2026] [core:notice] [pid 738779:tid 738815] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:35.829240 2026] [security2:error] [pid 738779:tid 739018] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/domvf.php"] [unique_id "amuI0_xa4UbeLxj1SWW0ggAAAPI"]
[Thu Jul 30 12:24:35.829352 2026] [security2:error] [pid 738779:tid 739018] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/domvf.php"] [unique_id "amuI0_xa4UbeLxj1SWW0ggAAAPI"]
[Thu Jul 30 12:24:35.842119 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:56572] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/pattern/alfacgiapi/perl.alfa"] [unique_id "amuI0_xa4UbeLxj1SWW0gwAAAPY"]
[Thu Jul 30 12:24:36.162208 2026] [security2:error] [pid 738779:tid 739036] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/yup.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0jQAAAQQ"]
[Thu Jul 30 12:24:36.162320 2026] [security2:error] [pid 738779:tid 739036] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/yup.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0jQAAAQQ"]
[Thu Jul 30 12:24:36.215800 2026] [security2:error] [pid 738779:tid 738937] [client 142.93.53.183:56675] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1Pxa4UbeLxj1SWW0jgAAAKE"]
[Thu Jul 30 12:24:36.445220 2026] [security2:error] [pid 738779:tid 738927] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/X.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0jwAAAJc"]
[Thu Jul 30 12:24:36.445361 2026] [security2:error] [pid 738779:tid 738927] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/X.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0jwAAAJc"]
[Thu Jul 30 12:24:36.492777 2026] [security2:error] [pid 738779:tid 738958] [client 172.213.232.128:43624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/img/cloud.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0kAAAALY"]
[Thu Jul 30 12:24:36.596931 2026] [security2:error] [pid 738779:tid 738943] [client 142.93.53.183:56775] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author/alfacgiapi/perl.alfa"] [unique_id "amuI1Pxa4UbeLxj1SWW0lAAAAKc"]
[Thu Jul 30 12:24:36.622158 2026] [security2:error] [pid 738779:tid 739031] [client 38.190.144.4:33419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0mAAAAP8"]
[Thu Jul 30 12:24:36.622276 2026] [security2:error] [pid 738779:tid 739031] [client 38.190.144.4:33419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0mAAAAP8"]
[Thu Jul 30 12:24:36.725094 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0nAAAALw"]
[Thu Jul 30 12:24:36.725215 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0nAAAALw"]
[Thu Jul 30 12:24:36.975343 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:56876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author-biography/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1Pxa4UbeLxj1SWW0nQAAAKk"]
[Thu Jul 30 12:24:37.025665 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/gec.php"] [unique_id "amuI1fxa4UbeLxj1SWW0nwAAAKo"]
[Thu Jul 30 12:24:37.025791 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/gec.php"] [unique_id "amuI1fxa4UbeLxj1SWW0nwAAAKo"]
[Thu Jul 30 12:24:37.318113 2026] [security2:error] [pid 738779:tid 738985] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/sky.php"] [unique_id "amuI1fxa4UbeLxj1SWW0qQAAANE"]
[Thu Jul 30 12:24:37.318230 2026] [security2:error] [pid 738779:tid 738985] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/sky.php"] [unique_id "amuI1fxa4UbeLxj1SWW0qQAAANE"]
[Thu Jul 30 12:24:37.351588 2026] [security2:error] [pid 738779:tid 738986] [client 142.93.53.183:56964] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author-biography/alfacgiapi/perl.alfa"] [unique_id "amuI1fxa4UbeLxj1SWW0qgAAANI"]
[Thu Jul 30 12:24:37.590182 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fffm.php"] [unique_id "amuI1fxa4UbeLxj1SWW0rwAAANc"]
[Thu Jul 30 12:24:37.590362 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fffm.php"] [unique_id "amuI1fxa4UbeLxj1SWW0rwAAANc"]
[Thu Jul 30 12:24:37.639762 2026] [security2:error] [pid 738779:tid 738966] [client 146.103.110.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuI1Pxa4UbeLxj1SWW0mwAAAL4"], referer: http://smoke-tfhk.com/hello-world/
[Thu Jul 30 12:24:37.734179 2026] [security2:error] [pid 738779:tid 739000] [client 142.93.53.183:57035] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author-name/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1fxa4UbeLxj1SWW0tAAAAOA"]
[Thu Jul 30 12:24:37.871928 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/sixxis.php"] [unique_id "amuI1fxa4UbeLxj1SWW0tQAAAOU"]
[Thu Jul 30 12:24:37.872078 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/sixxis.php"] [unique_id "amuI1fxa4UbeLxj1SWW0tQAAAOU"]
[Thu Jul 30 12:24:37.919150 2026] [core:notice] [pid 738779:tid 738978] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:37.974918 2026] [security2:error] [pid 738779:tid 738981] [client 185.191.171.14:58486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/02/walber-virgolino-avisa-que-preferencias-de-bolsonaro-na-paraiba-nao-dividem-nem-enfraquecem-direita-votamos-no-projeto/"] [unique_id "amuI1fxa4UbeLxj1SWW0twAAAM0"]
[Thu Jul 30 12:24:37.975108 2026] [security2:error] [pid 738779:tid 738981] [client 185.191.171.14:58486] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/02/walber-virgolino-avisa-que-preferencias-de-bolsonaro-na-paraiba-nao-dividem-nem-enfraquecem-direita-votamos-no-projeto/"] [unique_id "amuI1fxa4UbeLxj1SWW0twAAAM0"]
[Thu Jul 30 12:24:38.124707 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:57075] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-author-name/alfacgiapi/perl.alfa"] [unique_id "amuI1vxa4UbeLxj1SWW0uwAAAOk"]
[Thu Jul 30 12:24:38.150029 2026] [security2:error] [pid 738779:tid 739021] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/yj09.php"] [unique_id "amuI1vxa4UbeLxj1SWW0vAAAAPU"]
[Thu Jul 30 12:24:38.150142 2026] [security2:error] [pid 738779:tid 739021] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/yj09.php"] [unique_id "amuI1vxa4UbeLxj1SWW0vAAAAPU"]
[Thu Jul 30 12:24:38.178223 2026] [security2:error] [pid 738779:tid 739034] [client 20.203.148.31:47800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/abcd.php"] [unique_id "amuI1vxa4UbeLxj1SWW0vgAAAQI"]
[Thu Jul 30 12:24:38.468111 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/k.php"] [unique_id "amuI1vxa4UbeLxj1SWW0wgAAAP4"]
[Thu Jul 30 12:24:38.468238 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/k.php"] [unique_id "amuI1vxa4UbeLxj1SWW0wgAAAP4"]
[Thu Jul 30 12:24:38.512834 2026] [security2:error] [pid 738779:tid 739023] [client 142.93.53.183:57122] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-comments-form/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1vxa4UbeLxj1SWW0wwAAAPc"]
[Thu Jul 30 12:24:38.567693 2026] [security2:error] [pid 738779:tid 739028] [client 172.202.44.182:14132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/php.php"] [unique_id "amuI1vxa4UbeLxj1SWW0xAAAAPw"]
[Thu Jul 30 12:24:38.753255 2026] [security2:error] [pid 738779:tid 738952] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/k2.php"] [unique_id "amuI1vxa4UbeLxj1SWW0ywAAALA"]
[Thu Jul 30 12:24:38.753350 2026] [security2:error] [pid 738779:tid 738952] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/k2.php"] [unique_id "amuI1vxa4UbeLxj1SWW0ywAAALA"]
[Thu Jul 30 12:24:38.886596 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:57156] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-comments-form/alfacgiapi/perl.alfa"] [unique_id "amuI1vxa4UbeLxj1SWW0zgAAALo"]
[Thu Jul 30 12:24:39.025667 2026] [security2:error] [pid 738779:tid 738969] [client 172.213.232.128:14252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuI1_xa4UbeLxj1SWW00AAAAME"]
[Thu Jul 30 12:24:39.064281 2026] [security2:error] [pid 738779:tid 738923] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/w.php"] [unique_id "amuI1_xa4UbeLxj1SWW01AAAAJM"]
[Thu Jul 30 12:24:39.064429 2026] [security2:error] [pid 738779:tid 738923] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/w.php"] [unique_id "amuI1_xa4UbeLxj1SWW01AAAAJM"]
[Thu Jul 30 12:24:39.221357 2026] [security2:error] [pid 738779:tid 739036] [client 52.167.144.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itrnetwork.org"] [uri "/index.php"] [unique_id "amuI1vxa4UbeLxj1SWW0zwABBDM"], referer: https://itrnetwork.org/category/photography/
[Thu Jul 30 12:24:39.266337 2026] [security2:error] [pid 738779:tid 738930] [client 142.93.53.183:57202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-content/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI1_xa4UbeLxj1SWW03gAAAJo"]
[Thu Jul 30 12:24:39.351093 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fpwch.php"] [unique_id "amuI1_xa4UbeLxj1SWW03wAAANM"]
[Thu Jul 30 12:24:39.351215 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fpwch.php"] [unique_id "amuI1_xa4UbeLxj1SWW03wAAANM"]
[Thu Jul 30 12:24:39.646503 2026] [security2:error] [pid 738779:tid 738994] [client 142.93.53.183:57244] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-content/alfacgiapi/perl.alfa"] [unique_id "amuI1_xa4UbeLxj1SWW04AAAANo"]
[Thu Jul 30 12:24:39.700078 2026] [security2:error] [pid 738779:tid 738997] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/w2025.php"] [unique_id "amuI1_xa4UbeLxj1SWW05AAAAN0"]
[Thu Jul 30 12:24:39.700175 2026] [security2:error] [pid 738779:tid 738997] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/w2025.php"] [unique_id "amuI1_xa4UbeLxj1SWW05AAAAN0"]
[Thu Jul 30 12:24:39.984724 2026] [security2:error] [pid 738779:tid 738992] [client 172.213.232.128:4704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuI1_xa4UbeLxj1SWW06wAAANg"]
[Thu Jul 30 12:24:39.986490 2026] [security2:error] [pid 738779:tid 739011] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/FWAZ.php"] [unique_id "amuI1_xa4UbeLxj1SWW07AAAAOs"]
[Thu Jul 30 12:24:39.986587 2026] [security2:error] [pid 738779:tid 739011] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/FWAZ.php"] [unique_id "amuI1_xa4UbeLxj1SWW07AAAAOs"]
[Thu Jul 30 12:24:40.028586 2026] [security2:error] [pid 738779:tid 738948] [client 142.93.53.183:57281] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-date/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2Pxa4UbeLxj1SWW07QAAAKw"]
[Thu Jul 30 12:24:40.057701 2026] [security2:error] [pid 738779:tid 738918] [client 20.203.148.31:47806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/about.php"] [unique_id "amuI2Pxa4UbeLxj1SWW07gAAAI4"]
[Thu Jul 30 12:24:40.078318 2026] [security2:error] [pid 738779:tid 739003] [client 220.181.108.101:41423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aded-a-accompagne-et-appuye-le-comite-de-pilotage-rbc-de-la-zs-duvira-dans-le-processus-delaboration-et-de-la-mise-en-oeuvre-dun-plan-daction-2024/index.php"] [unique_id "amuI1_xa4UbeLxj1SWW06QAAAOM"]
[Thu Jul 30 12:24:40.272640 2026] [security2:error] [pid 738779:tid 739012] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/qterm.php"] [unique_id "amuI2Pxa4UbeLxj1SWW08wAAAOw"]
[Thu Jul 30 12:24:40.272751 2026] [security2:error] [pid 738779:tid 739012] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/qterm.php"] [unique_id "amuI2Pxa4UbeLxj1SWW08wAAAOw"]
[Thu Jul 30 12:24:40.422101 2026] [security2:error] [pid 738779:tid 739008] [client 142.93.53.183:57321] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-date/alfacgiapi/perl.alfa"] [unique_id "amuI2Pxa4UbeLxj1SWW09wAAAOg"]
[Thu Jul 30 12:24:40.507416 2026] [security2:error] [pid 738779:tid 739030] [client 119.249.100.53:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aded-a-accompagne-et-appuye-le-comite-de-pilotage-rbc-de-la-zs-duvira-dans-le-processus-delaboration-et-de-la-mise-en-oeuvre-dun-plan-daction-2024/index.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0-AAAAP4"]
[Thu Jul 30 12:24:40.546221 2026] [security2:error] [pid 738779:tid 739033] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/blurbs.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0-QAAAQE"]
[Thu Jul 30 12:24:40.546340 2026] [security2:error] [pid 738779:tid 739033] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/blurbs.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0-QAAAQE"]
[Thu Jul 30 12:24:40.638534 2026] [security2:error] [pid 738779:tid 739027] [client 172.213.232.128:4713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/avaa.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0-wAAAPs"]
[Thu Jul 30 12:24:40.668810 2026] [security2:error] [pid 738779:tid 739009] [client 172.202.44.182:17498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/index.php"] [unique_id "amuI2Pxa4UbeLxj1SWW0_AAAAOk"]
[Thu Jul 30 12:24:40.812692 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:57362] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-excerpt/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2Pxa4UbeLxj1SWW1AQAAAI0"]
[Thu Jul 30 12:24:40.832705 2026] [security2:error] [pid 738779:tid 738958] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-ws68.php"] [unique_id "amuI2Pxa4UbeLxj1SWW1BAAAALY"]
[Thu Jul 30 12:24:40.832781 2026] [security2:error] [pid 738779:tid 738958] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-ws68.php"] [unique_id "amuI2Pxa4UbeLxj1SWW1BAAAALY"]
[Thu Jul 30 12:24:40.869867 2026] [security2:error] [pid 738779:tid 739031] [client 119.249.100.116:35182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aded-a-accompagne-et-appuye-le-comite-de-pilotage-rbc-de-la-zs-duvira-dans-le-processus-delaboration-et-de-la-mise-en-oeuvre-dun-plan-daction-2024/index.php"] [unique_id "amuI2Pxa4UbeLxj1SWW1BQAAAP8"]
[Thu Jul 30 12:24:40.999718 2026] [security2:error] [pid 738779:tid 738843] [remote 57.141.0.49:50322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuI2Pxa4UbeLxj1SWW1CQAAhT8"]
[Thu Jul 30 12:24:41.104079 2026] [security2:error] [pid 738779:tid 738965] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xyn.php"] [unique_id "amuI2fxa4UbeLxj1SWW1CgAAAL0"]
[Thu Jul 30 12:24:41.104223 2026] [security2:error] [pid 738779:tid 738965] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xyn.php"] [unique_id "amuI2fxa4UbeLxj1SWW1CgAAAL0"]
[Thu Jul 30 12:24:41.202730 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:57408] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-excerpt/alfacgiapi/perl.alfa"] [unique_id "amuI2fxa4UbeLxj1SWW1CwAAAMU"]
[Thu Jul 30 12:24:41.386678 2026] [security2:error] [pid 738779:tid 738979] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ccc.php"] [unique_id "amuI2fxa4UbeLxj1SWW1EgAAAMs"]
[Thu Jul 30 12:24:41.386796 2026] [security2:error] [pid 738779:tid 738979] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ccc.php"] [unique_id "amuI2fxa4UbeLxj1SWW1EgAAAMs"]
[Thu Jul 30 12:24:41.593793 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:57442] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-featured-image/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2fxa4UbeLxj1SWW1FAAAAM8"]
[Thu Jul 30 12:24:41.728558 2026] [security2:error] [pid 738779:tid 738977] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/get.php"] [unique_id "amuI2fxa4UbeLxj1SWW1GAAAAMk"]
[Thu Jul 30 12:24:41.728717 2026] [security2:error] [pid 738779:tid 738977] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/get.php"] [unique_id "amuI2fxa4UbeLxj1SWW1GAAAAMk"]
[Thu Jul 30 12:24:41.967252 2026] [security2:error] [pid 738779:tid 738996] [client 142.93.53.183:57486] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-featured-image/alfacgiapi/perl.alfa"] [unique_id "amuI2fxa4UbeLxj1SWW1IAAAANw"]
[Thu Jul 30 12:24:42.058922 2026] [security2:error] [pid 738779:tid 738953] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/images.php"] [unique_id "amuI2vxa4UbeLxj1SWW1IQAAALE"]
[Thu Jul 30 12:24:42.059055 2026] [security2:error] [pid 738779:tid 738953] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/images.php"] [unique_id "amuI2vxa4UbeLxj1SWW1IQAAALE"]
[Thu Jul 30 12:24:42.317387 2026] [security2:error] [pid 738779:tid 738968] [client 172.202.44.182:17503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin/a.php"] [unique_id "amuI2vxa4UbeLxj1SWW1KQAAAMA"]
[Thu Jul 30 12:24:42.339923 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/alls.php"] [unique_id "amuI2vxa4UbeLxj1SWW1KgAAAOA"]
[Thu Jul 30 12:24:42.340064 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/alls.php"] [unique_id "amuI2vxa4UbeLxj1SWW1KgAAAOA"]
[Thu Jul 30 12:24:42.358781 2026] [security2:error] [pid 738779:tid 739011] [client 142.93.53.183:57520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-navigation-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2vxa4UbeLxj1SWW1KwAAAOs"]
[Thu Jul 30 12:24:42.506334 2026] [security2:error] [pid 738779:tid 738970] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI2fxa4UbeLxj1SWW1HwAAwkY"]
[Thu Jul 30 12:24:42.659420 2026] [security2:error] [pid 738779:tid 739012] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/coffexium.php"] [unique_id "amuI2vxa4UbeLxj1SWW1MwAAAOw"]
[Thu Jul 30 12:24:42.659530 2026] [security2:error] [pid 738779:tid 739012] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/coffexium.php"] [unique_id "amuI2vxa4UbeLxj1SWW1MwAAAOw"]
[Thu Jul 30 12:24:42.660411 2026] [core:notice] [pid 738779:tid 738981] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:42.734205 2026] [security2:error] [pid 738779:tid 739021] [client 142.93.53.183:57557] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-navigation-link/alfacgiapi/perl.alfa"] [unique_id "amuI2vxa4UbeLxj1SWW1NAAAAPU"]
[Thu Jul 30 12:24:42.744956 2026] [security2:error] [pid 738779:tid 739002] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI2vxa4UbeLxj1SWW1JQAAAOI"]
[Thu Jul 30 12:24:42.948993 2026] [security2:error] [pid 738779:tid 739028] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/red.php"] [unique_id "amuI2vxa4UbeLxj1SWW1OwAAAPw"]
[Thu Jul 30 12:24:42.949113 2026] [security2:error] [pid 738779:tid 739028] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/red.php"] [unique_id "amuI2vxa4UbeLxj1SWW1OwAAAPw"]
[Thu Jul 30 12:24:43.067101 2026] [security2:error] [pid 738779:tid 738957] [client 172.213.232.128:12338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/images/cloud.php"] [unique_id "amuI2_xa4UbeLxj1SWW1PAAAALU"]
[Thu Jul 30 12:24:43.124464 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:57582] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-template/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2_xa4UbeLxj1SWW1PQAAAIs"]
[Thu Jul 30 12:24:43.220997 2026] [security2:error] [pid 738779:tid 739008] [client 20.203.148.31:45273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/admin.php"] [unique_id "amuI2_xa4UbeLxj1SWW1PwAAAOg"]
[Thu Jul 30 12:24:43.356058 2026] [security2:error] [pid 738779:tid 738944] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuI2_xa4UbeLxj1SWW1QAAAAKg"]
[Thu Jul 30 12:24:43.497817 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:57616] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-template/alfacgiapi/perl.alfa"] [unique_id "amuI2_xa4UbeLxj1SWW1SAAAAJE"]
[Thu Jul 30 12:24:43.526750 2026] [security2:error] [pid 738779:tid 738969] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuI2_xa4UbeLxj1SWW1SgAAAME"]
[Thu Jul 30 12:24:43.526852 2026] [security2:error] [pid 738779:tid 738969] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuI2_xa4UbeLxj1SWW1SgAAAME"]
[Thu Jul 30 12:24:43.781183 2026] [core:notice] [pid 738779:tid 738861] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:43.814504 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/"] [unique_id "amuI2_xa4UbeLxj1SWW1TwAAAKo"]
[Thu Jul 30 12:24:43.867794 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.232.128:23332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuI2_xa4UbeLxj1SWW1UAAAAMU"]
[Thu Jul 30 12:24:43.875471 2026] [security2:error] [pid 738779:tid 738919] [client 142.93.53.183:57641] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-terms/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI2_xa4UbeLxj1SWW1UQAAAI8"]
[Thu Jul 30 12:24:43.983187 2026] [security2:error] [pid 738779:tid 739036] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuI2_xa4UbeLxj1SWW1VgAAAQQ"]
[Thu Jul 30 12:24:44.011502 2026] [security2:error] [pid 738779:tid 738967] [client 20.203.148.31:46510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/adminfuns.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1WgAAAL8"]
[Thu Jul 30 12:24:44.125972 2026] [security2:error] [pid 738779:tid 738956] [client 172.202.44.182:42035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1WwAAALQ"]
[Thu Jul 30 12:24:44.144915 2026] [security2:error] [pid 738779:tid 738990] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/index.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1XAAAANY"]
[Thu Jul 30 12:24:44.145101 2026] [security2:error] [pid 738779:tid 738990] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/index.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1XAAAANY"]
[Thu Jul 30 12:24:44.249852 2026] [security2:error] [pid 738779:tid 738950] [client 142.93.53.183:57680] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-terms/alfacgiapi/perl.alfa"] [unique_id "amuI3Pxa4UbeLxj1SWW1XgAAAK4"]
[Thu Jul 30 12:24:44.432376 2026] [security2:error] [pid 738779:tid 738997] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1YAAAAN0"]
[Thu Jul 30 12:24:44.432490 2026] [security2:error] [pid 738779:tid 738997] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1YAAAAN0"]
[Thu Jul 30 12:24:44.640500 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:57706] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-title/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3Pxa4UbeLxj1SWW1ZwAAAOc"]
[Thu Jul 30 12:24:44.680186 2026] [security2:error] [pid 738779:tid 738991] [client 172.213.232.128:36347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1aAAAANc"]
[Thu Jul 30 12:24:44.715872 2026] [security2:error] [pid 738779:tid 738992] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/177.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1agAAANg"]
[Thu Jul 30 12:24:44.715966 2026] [security2:error] [pid 738779:tid 738992] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/177.php"] [unique_id "amuI3Pxa4UbeLxj1SWW1agAAANg"]
[Thu Jul 30 12:24:45.016895 2026] [security2:error] [pid 738779:tid 738978] [client 142.93.53.183:57741] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/post-title/alfacgiapi/perl.alfa"] [unique_id "amuI3fxa4UbeLxj1SWW1cQAAAMo"]
[Thu Jul 30 12:24:45.023777 2026] [security2:error] [pid 738779:tid 738981] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/199.php"] [unique_id "amuI3fxa4UbeLxj1SWW1cwAAAM0"]
[Thu Jul 30 12:24:45.023864 2026] [security2:error] [pid 738779:tid 738981] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/199.php"] [unique_id "amuI3fxa4UbeLxj1SWW1cwAAAM0"]
[Thu Jul 30 12:24:45.255879 2026] [security2:error] [pid 738779:tid 738989] [client 172.213.232.128:36334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuI3fxa4UbeLxj1SWW1eAAAANU"]
[Thu Jul 30 12:24:45.329489 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file52.php"] [unique_id "amuI3fxa4UbeLxj1SWW1fAAAAP4"]
[Thu Jul 30 12:24:45.329612 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file52.php"] [unique_id "amuI3fxa4UbeLxj1SWW1fAAAAP4"]
[Thu Jul 30 12:24:45.354137 2026] [security2:error] [pid 738779:tid 738994] [client 20.203.148.31:39643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/albin.php"] [unique_id "amuI3fxa4UbeLxj1SWW1fQAAANo"]
[Thu Jul 30 12:24:45.406015 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:57775] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/preformatted/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3fxa4UbeLxj1SWW1fgAAAOk"]
[Thu Jul 30 12:24:45.411740 2026] [security2:error] [pid 738779:tid 739019] [client 40.77.167.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itrnetwork.org"] [uri "/index.php"] [unique_id "amuI3fxa4UbeLxj1SWW1dgAA81s"], referer: https://itrnetwork.org/category/photography/
[Thu Jul 30 12:24:45.677099 2026] [security2:error] [pid 738779:tid 739018] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/geck.php"] [unique_id "amuI3fxa4UbeLxj1SWW1hgAAAPI"]
[Thu Jul 30 12:24:45.677216 2026] [security2:error] [pid 738779:tid 739018] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/geck.php"] [unique_id "amuI3fxa4UbeLxj1SWW1hgAAAPI"]
[Thu Jul 30 12:24:45.798153 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:57812] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/preformatted/alfacgiapi/perl.alfa"] [unique_id "amuI3fxa4UbeLxj1SWW1iAAAAK0"]
[Thu Jul 30 12:24:45.970499 2026] [security2:error] [pid 738779:tid 738932] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/biufile.php"] [unique_id "amuI3fxa4UbeLxj1SWW1jAAAAJw"]
[Thu Jul 30 12:24:45.970625 2026] [security2:error] [pid 738779:tid 738932] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/biufile.php"] [unique_id "amuI3fxa4UbeLxj1SWW1jAAAAJw"]
[Thu Jul 30 12:24:46.171493 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:57846] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/pullquote/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3vxa4UbeLxj1SWW1lAAAAM8"]
[Thu Jul 30 12:24:46.246534 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dejavu.php"] [unique_id "amuI3vxa4UbeLxj1SWW1lQAAALM"]
[Thu Jul 30 12:24:46.246639 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dejavu.php"] [unique_id "amuI3vxa4UbeLxj1SWW1lQAAALM"]
[Thu Jul 30 12:24:46.345580 2026] [security2:error] [pid 738779:tid 739029] [client 172.202.44.182:13510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-admin.php"] [unique_id "amuI3vxa4UbeLxj1SWW1lgAAAP0"]
[Thu Jul 30 12:24:46.511078 2026] [security2:error] [pid 738779:tid 738954] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuI3vxa4UbeLxj1SWW1mQAAALI"]
[Thu Jul 30 12:24:46.531662 2026] [security2:error] [pid 738779:tid 738951] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/aaf.php"] [unique_id "amuI3vxa4UbeLxj1SWW1mgAAAK8"]
[Thu Jul 30 12:24:46.531780 2026] [security2:error] [pid 738779:tid 738951] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/aaf.php"] [unique_id "amuI3vxa4UbeLxj1SWW1mgAAAK8"]
[Thu Jul 30 12:24:46.552643 2026] [security2:error] [pid 738779:tid 738912] [client 142.93.53.183:57865] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/pullquote/alfacgiapi/perl.alfa"] [unique_id "amuI3vxa4UbeLxj1SWW1nQAAAIg"]
[Thu Jul 30 12:24:46.832803 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ha.php"] [unique_id "amuI3vxa4UbeLxj1SWW1ogAAAOQ"]
[Thu Jul 30 12:24:46.832900 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ha.php"] [unique_id "amuI3vxa4UbeLxj1SWW1ogAAAOQ"]
[Thu Jul 30 12:24:46.875212 2026] [security2:error] [pid 738779:tid 738961] [client 172.213.232.128:12306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuI3vxa4UbeLxj1SWW1owAAALk"]
[Thu Jul 30 12:24:46.929654 2026] [security2:error] [pid 738779:tid 739006] [client 142.93.53.183:57892] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3vxa4UbeLxj1SWW1pAAAAOY"]
[Thu Jul 30 12:24:47.123755 2026] [security2:error] [pid 738779:tid 738993] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/hur.php"] [unique_id "amuI3_xa4UbeLxj1SWW1qAAAANk"]
[Thu Jul 30 12:24:47.123865 2026] [security2:error] [pid 738779:tid 738993] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/hur.php"] [unique_id "amuI3_xa4UbeLxj1SWW1qAAAANk"]
[Thu Jul 30 12:24:47.271791 2026] [security2:error] [pid 738779:tid 738930] [client 20.203.148.31:47747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/amfsqvgv.php"] [unique_id "amuI3_xa4UbeLxj1SWW1rAAAAJo"]
[Thu Jul 30 12:24:47.279715 2026] [security2:error] [pid 738779:tid 739001] [client 172.202.44.182:17500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/size.php"] [unique_id "amuI3_xa4UbeLxj1SWW1rQAAAOE"]
[Thu Jul 30 12:24:47.310856 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:57920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query/alfacgiapi/perl.alfa"] [unique_id "amuI3_xa4UbeLxj1SWW1rgAAAMI"]
[Thu Jul 30 12:24:47.346276 2026] [security2:error] [pid 738779:tid 738959] [client 66.249.66.8:44373] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "mogomogolessons4.com"] [uri "/robots.txt"] [unique_id "amuI3_xa4UbeLxj1SWW1rwAAALc"]
[Thu Jul 30 12:24:47.403737 2026] [security2:error] [pid 738779:tid 738978] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/h02ugyh.php"] [unique_id "amuI3_xa4UbeLxj1SWW1sAAAAMo"]
[Thu Jul 30 12:24:47.403847 2026] [security2:error] [pid 738779:tid 738978] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/h02ugyh.php"] [unique_id "amuI3_xa4UbeLxj1SWW1sAAAAMo"]
[Thu Jul 30 12:24:47.704000 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:57954] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-no-results/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI3_xa4UbeLxj1SWW1uAAAANU"]
[Thu Jul 30 12:24:47.715740 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/155.php"] [unique_id "amuI3_xa4UbeLxj1SWW1uQAAAP4"]
[Thu Jul 30 12:24:47.715820 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/155.php"] [unique_id "amuI3_xa4UbeLxj1SWW1uQAAAP4"]
[Thu Jul 30 12:24:47.985498 2026] [security2:error] [pid 738779:tid 738913] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ops.php"] [unique_id "amuI3_xa4UbeLxj1SWW1ugAAAIk"]
[Thu Jul 30 12:24:47.985650 2026] [security2:error] [pid 738779:tid 738913] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ops.php"] [unique_id "amuI3_xa4UbeLxj1SWW1ugAAAIk"]
[Thu Jul 30 12:24:48.091618 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:57982] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-no-results/alfacgiapi/perl.alfa"] [unique_id "amuI4Pxa4UbeLxj1SWW1vAAAAPk"]
[Thu Jul 30 12:24:48.254191 2026] [security2:error] [pid 738779:tid 738936] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ingfo.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xAAAAKA"]
[Thu Jul 30 12:24:48.254299 2026] [security2:error] [pid 738779:tid 738936] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ingfo.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xAAAAKA"]
[Thu Jul 30 12:24:48.321149 2026] [security2:error] [pid 738779:tid 738926] [client 172.213.232.128:14260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xQAAAJY"]
[Thu Jul 30 12:24:48.397082 2026] [security2:error] [pid 738779:tid 738890] [remote 165.101.188.2:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.188.101.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "echomemoversalain.casa"] [uri "/wp/wp-login.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1wAABAW4"]
[Thu Jul 30 12:24:48.470411 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:58009] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4Pxa4UbeLxj1SWW1xgAAAJE"]
[Thu Jul 30 12:24:48.528168 2026] [security2:error] [pid 738779:tid 738971] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/error_log.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xwAAAMM"]
[Thu Jul 30 12:24:48.528297 2026] [security2:error] [pid 738779:tid 738971] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/error_log.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1xwAAAMM"]
[Thu Jul 30 12:24:48.852412 2026] [security2:error] [pid 738779:tid 738975] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/koala.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1zgAAAMc"]
[Thu Jul 30 12:24:48.852534 2026] [security2:error] [pid 738779:tid 738975] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/koala.php"] [unique_id "amuI4Pxa4UbeLxj1SWW1zgAAAMc"]
[Thu Jul 30 12:24:48.858827 2026] [security2:error] [pid 738779:tid 738933] [client 142.93.53.183:58039] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination/alfacgiapi/perl.alfa"] [unique_id "amuI4Pxa4UbeLxj1SWW1zwAAAJ0"]
[Thu Jul 30 12:24:49.015361 2026] [security2:error] [pid 738779:tid 738909] [client 172.213.232.128:18971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/cloud.php"] [unique_id "amuI4fxa4UbeLxj1SWW10AAAAIU"]
[Thu Jul 30 12:24:49.025360 2026] [security2:error] [pid 738779:tid 738924] [client 38.190.144.4:59900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI4fxa4UbeLxj1SWW10QAAAJQ"]
[Thu Jul 30 12:24:49.025512 2026] [security2:error] [pid 738779:tid 738924] [client 38.190.144.4:59900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI4fxa4UbeLxj1SWW10QAAAJQ"]
[Thu Jul 30 12:24:49.173458 2026] [security2:error] [pid 738779:tid 738979] [client 172.202.44.182:17605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuI4fxa4UbeLxj1SWW11AAAAMs"]
[Thu Jul 30 12:24:49.175233 2026] [security2:error] [pid 738779:tid 738910] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/mac.php"] [unique_id "amuI4fxa4UbeLxj1SWW11QAAAIY"]
[Thu Jul 30 12:24:49.175330 2026] [security2:error] [pid 738779:tid 738910] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/mac.php"] [unique_id "amuI4fxa4UbeLxj1SWW11QAAAIY"]
[Thu Jul 30 12:24:49.201466 2026] [security2:error] [pid 738779:tid 738940] [client 20.226.5.174:4612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/n9z13o5s.php"] [unique_id "amuI4fxa4UbeLxj1SWW11wAAAKQ"]
[Thu Jul 30 12:24:49.232219 2026] [security2:error] [pid 738779:tid 738956] [client 142.93.53.183:58067] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-next/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4fxa4UbeLxj1SWW12QAAALQ"]
[Thu Jul 30 12:24:49.499048 2026] [security2:error] [pid 738779:tid 738966] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wefile.php"] [unique_id "amuI4fxa4UbeLxj1SWW13QAAAL4"]
[Thu Jul 30 12:24:49.499159 2026] [security2:error] [pid 738779:tid 738966] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wefile.php"] [unique_id "amuI4fxa4UbeLxj1SWW13QAAAL4"]
[Thu Jul 30 12:24:49.625043 2026] [security2:error] [pid 738779:tid 738914] [client 142.93.53.183:58089] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-next/alfacgiapi/perl.alfa"] [unique_id "amuI4fxa4UbeLxj1SWW14QAAAIo"]
[Thu Jul 30 12:24:49.885326 2026] [security2:error] [pid 738779:tid 738978] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/post-comments-form/"] [unique_id "amuI4fxa4UbeLxj1SWW16AAAAMo"]
[Thu Jul 30 12:24:50.013148 2026] [security2:error] [pid 738779:tid 738928] [client 142.93.53.183:58112] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-numbers/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4vxa4UbeLxj1SWW16QAAAJg"]
[Thu Jul 30 12:24:50.092117 2026] [security2:error] [pid 738779:tid 738931] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/"] [unique_id "amuI4vxa4UbeLxj1SWW16gAAAJs"]
[Thu Jul 30 12:24:50.173277 2026] [security2:error] [pid 738779:tid 739005] [client 47.128.32.123:31642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "club4.au"] [uri "/robots.txt"] [unique_id "amuI4vxa4UbeLxj1SWW17gAAAOU"]
[Thu Jul 30 12:24:50.275884 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/makeasmtp.php"] [unique_id "amuI4vxa4UbeLxj1SWW19gAAAPY"]
[Thu Jul 30 12:24:50.276006 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/makeasmtp.php"] [unique_id "amuI4vxa4UbeLxj1SWW19gAAAPY"]
[Thu Jul 30 12:24:50.406130 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:58138] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-numbers/alfacgiapi/perl.alfa"] [unique_id "amuI4vxa4UbeLxj1SWW1-AAAAPE"]
[Thu Jul 30 12:24:50.406494 2026] [security2:error] [pid 738779:tid 739020] [client 20.226.5.174:4621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/uploads/2014/03/smile.php"] [unique_id "amuI4vxa4UbeLxj1SWW19wAAAPQ"]
[Thu Jul 30 12:24:50.565165 2026] [security2:error] [pid 738779:tid 738959] [client 172.202.44.182:14087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/403.php"] [unique_id "amuI4vxa4UbeLxj1SWW1-QAAALc"]
[Thu Jul 30 12:24:50.567075 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/2P.php"] [unique_id "amuI4vxa4UbeLxj1SWW1-gAAAPc"]
[Thu Jul 30 12:24:50.567149 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/2P.php"] [unique_id "amuI4vxa4UbeLxj1SWW1-gAAAPc"]
[Thu Jul 30 12:24:50.739004 2026] [security2:error] [pid 738779:tid 739036] [client 20.203.148.31:46485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/ant.php"] [unique_id "amuI4vxa4UbeLxj1SWW1_gAAAQQ"]
[Thu Jul 30 12:24:50.796629 2026] [security2:error] [pid 738779:tid 738943] [client 142.93.53.183:58168] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-previous/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4vxa4UbeLxj1SWW2AwAAAKc"]
[Thu Jul 30 12:24:50.867141 2026] [security2:error] [pid 738779:tid 739033] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/.well-known/about.php"] [unique_id "amuI4vxa4UbeLxj1SWW2BAAAAQE"]
[Thu Jul 30 12:24:50.867250 2026] [security2:error] [pid 738779:tid 739033] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/.well-known/about.php"] [unique_id "amuI4vxa4UbeLxj1SWW2BAAAAQE"]
[Thu Jul 30 12:24:51.149100 2026] [security2:error] [pid 738779:tid 738947] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuI4_xa4UbeLxj1SWW2BgAAAKs"]
[Thu Jul 30 12:24:51.149219 2026] [security2:error] [pid 738779:tid 738947] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuI4_xa4UbeLxj1SWW2BgAAAKs"]
[Thu Jul 30 12:24:51.187712 2026] [security2:error] [pid 738779:tid 738969] [client 142.93.53.183:58188] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-pagination-previous/alfacgiapi/perl.alfa"] [unique_id "amuI4_xa4UbeLxj1SWW2CgAAAME"]
[Thu Jul 30 12:24:51.428009 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/system_log.php"] [unique_id "amuI4_xa4UbeLxj1SWW2EQAAAKQ"]
[Thu Jul 30 12:24:51.428115 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/system_log.php"] [unique_id "amuI4_xa4UbeLxj1SWW2EQAAAKQ"]
[Thu Jul 30 12:24:51.580563 2026] [security2:error] [pid 738779:tid 738988] [client 142.93.53.183:58213] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-title/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI4_xa4UbeLxj1SWW2EgAAANQ"]
[Thu Jul 30 12:24:51.713620 2026] [security2:error] [pid 738779:tid 738985] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/"] [unique_id "amuI4_xa4UbeLxj1SWW2EwAAANE"]
[Thu Jul 30 12:24:51.867668 2026] [security2:error] [pid 738779:tid 738954] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amuI4_xa4UbeLxj1SWW2FwAAALI"]
[Thu Jul 30 12:24:51.971374 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:58239] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/query-title/alfacgiapi/perl.alfa"] [unique_id "amuI4_xa4UbeLxj1SWW2GwAAALs"]
[Thu Jul 30 12:24:52.024687 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/crgio.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2HwAAAOQ"]
[Thu Jul 30 12:24:52.024789 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/crgio.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2HwAAAOQ"]
[Thu Jul 30 12:24:52.127297 2026] [security2:error] [pid 738779:tid 739029] [client 20.226.5.174:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/ini.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2IAAAAP0"]
[Thu Jul 30 12:24:52.306717 2026] [security2:error] [pid 738779:tid 738993] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/pucci.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2IQAAANk"]
[Thu Jul 30 12:24:52.306828 2026] [security2:error] [pid 738779:tid 738993] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/pucci.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2IQAAANk"]
[Thu Jul 30 12:24:52.429334 2026] [security2:error] [pid 738779:tid 739003] [client 172.213.232.128:23343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/updates.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2KAAAAOM"]
[Thu Jul 30 12:24:52.557100 2026] [security2:error] [pid 738779:tid 738928] [client 142.93.53.183:58266] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/quote/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5Pxa4UbeLxj1SWW2KQAAAJg"]
[Thu Jul 30 12:24:52.594514 2026] [security2:error] [pid 738779:tid 738982] [client 20.203.148.31:46521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/appreciators.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2KwAAAM4"]
[Thu Jul 30 12:24:52.601715 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/details/"] [unique_id "amuI5Pxa4UbeLxj1SWW2KgAAAOU"]
[Thu Jul 30 12:24:52.759632 2026] [security2:error] [pid 738779:tid 739021] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/audio/"] [unique_id "amuI5Pxa4UbeLxj1SWW2LwAAAPU"]
[Thu Jul 30 12:24:52.918835 2026] [security2:error] [pid 738779:tid 739010] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-temp.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2NQAAAOo"]
[Thu Jul 30 12:24:52.918923 2026] [security2:error] [pid 738779:tid 739010] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-temp.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2NQAAAOo"]
[Thu Jul 30 12:24:52.930958 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:58292] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/quote/alfacgiapi/perl.alfa"] [unique_id "amuI5Pxa4UbeLxj1SWW2NwAAAPE"]
[Thu Jul 30 12:24:52.991547 2026] [security2:error] [pid 738779:tid 738929] [client 49.13.24.81:45962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuI5Pxa4UbeLxj1SWW2PQAAAJk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:24:53.069539 2026] [security2:error] [pid 738779:tid 738983] [client 172.202.44.182:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "artisanlandscapeinc.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuI5fxa4UbeLxj1SWW2RgAAAM8"]
[Thu Jul 30 12:24:53.248788 2026] [security2:error] [pid 738779:tid 739008] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuI5fxa4UbeLxj1SWW2RwAAAOg"]
[Thu Jul 30 12:24:53.248919 2026] [security2:error] [pid 738779:tid 739008] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuI5fxa4UbeLxj1SWW2RwAAAOg"]
[Thu Jul 30 12:24:53.313039 2026] [security2:error] [pid 738779:tid 739033] [client 142.93.53.183:58313] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/read-more/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5fxa4UbeLxj1SWW2SAAAAQE"]
[Thu Jul 30 12:24:53.401939 2026] [core:notice] [pid 738779:tid 738926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:24:53.410222 2026] [security2:error] [pid 738779:tid 738926] [client 49.13.24.81:45964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuI5fxa4UbeLxj1SWW2SgAAAJY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:24:53.533353 2026] [security2:error] [pid 738779:tid 738909] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/puc.php"] [unique_id "amuI5fxa4UbeLxj1SWW2UQAAAIU"]
[Thu Jul 30 12:24:53.533479 2026] [security2:error] [pid 738779:tid 738909] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/puc.php"] [unique_id "amuI5fxa4UbeLxj1SWW2UQAAAIU"]
[Thu Jul 30 12:24:53.629727 2026] [security2:error] [pid 738779:tid 738944] [client 172.237.109.114:47264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2QAAAAKg"]
[Thu Jul 30 12:24:53.635310 2026] [security2:error] [pid 738779:tid 739036] [client 172.237.109.114:50213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2PwAAAQQ"]
[Thu Jul 30 12:24:53.639209 2026] [security2:error] [pid 738779:tid 739009] [client 172.237.109.114:29712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2PAAAAOk"]
[Thu Jul 30 12:24:53.648262 2026] [security2:error] [pid 738779:tid 739035] [client 172.237.109.114:15279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2OAAAAQM"]
[Thu Jul 30 12:24:53.650171 2026] [security2:error] [pid 738779:tid 738916] [client 172.237.109.114:14663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2QQAAAIw"]
[Thu Jul 30 12:24:53.652515 2026] [security2:error] [pid 738779:tid 739025] [client 172.237.109.114:54793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2QgAAAPk"]
[Thu Jul 30 12:24:53.656964 2026] [security2:error] [pid 738779:tid 738959] [client 172.237.109.114:29255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2OQAAALc"]
[Thu Jul 30 12:24:53.664392 2026] [security2:error] [pid 738779:tid 739023] [client 172.237.109.114:41250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuI5Pxa4UbeLxj1SWW2OgAAAPc"]
[Thu Jul 30 12:24:53.705752 2026] [security2:error] [pid 738779:tid 738967] [client 142.93.53.183:58341] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/read-more/alfacgiapi/perl.alfa"] [unique_id "amuI5fxa4UbeLxj1SWW2UgAAAL8"]
[Thu Jul 30 12:24:53.801627 2026] [security2:error] [pid 738779:tid 738979] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dx.php"] [unique_id "amuI5fxa4UbeLxj1SWW2UwAAAMs"]
[Thu Jul 30 12:24:53.801741 2026] [security2:error] [pid 738779:tid 738979] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dx.php"] [unique_id "amuI5fxa4UbeLxj1SWW2UwAAAMs"]
[Thu Jul 30 12:24:53.878182 2026] [security2:error] [pid 738779:tid 738937] [client 185.191.171.15:62466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/21/lula-tem-alta-apos-internacao-para-retirada-de-lesao-na-laringe-no-domingo-20/"] [unique_id "amuI5fxa4UbeLxj1SWW2VQAAAKE"]
[Thu Jul 30 12:24:53.878381 2026] [security2:error] [pid 738779:tid 738937] [client 185.191.171.15:62466] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/21/lula-tem-alta-apos-internacao-para-retirada-de-lesao-na-laringe-no-domingo-20/"] [unique_id "amuI5fxa4UbeLxj1SWW2VQAAAKE"]
[Thu Jul 30 12:24:54.029378 2026] [security2:error] [pid 738779:tid 738985] [client 49.13.24.81:45972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuI5vxa4UbeLxj1SWW2XAAAANE"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:24:54.091942 2026] [security2:error] [pid 738779:tid 738965] [client 20.203.148.31:39651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/archive.php"] [unique_id "amuI5vxa4UbeLxj1SWW2XgAAAL0"]
[Thu Jul 30 12:24:54.096329 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:58364] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/rss/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5vxa4UbeLxj1SWW2XwAAAOQ"]
[Thu Jul 30 12:24:54.104448 2026] [security2:error] [pid 738779:tid 738963] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amuI5vxa4UbeLxj1SWW2XQAAALs"]
[Thu Jul 30 12:24:54.259230 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/7.php"] [unique_id "amuI5vxa4UbeLxj1SWW2YQAAAOA"]
[Thu Jul 30 12:24:54.259386 2026] [security2:error] [pid 738779:tid 739000] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/7.php"] [unique_id "amuI5vxa4UbeLxj1SWW2YQAAAOA"]
[Thu Jul 30 12:24:54.486887 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:58388] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/rss/alfacgiapi/perl.alfa"] [unique_id "amuI5vxa4UbeLxj1SWW2aAAAAOM"]
[Thu Jul 30 12:24:54.493501 2026] [security2:error] [pid 738779:tid 738994] [client 172.213.232.128:36299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/libraries/legacy/updates.php"] [unique_id "amuI5vxa4UbeLxj1SWW2aQAAANo"]
[Thu Jul 30 12:24:54.537134 2026] [security2:error] [pid 738779:tid 738928] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/8.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cAAAAJg"]
[Thu Jul 30 12:24:54.537258 2026] [security2:error] [pid 738779:tid 738928] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/8.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cAAAAJg"]
[Thu Jul 30 12:24:54.816358 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.heiakujawir.com"] [uri "/1.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cQAAAO4"]
[Thu Jul 30 12:24:54.816474 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cQAAAO4"]
[Thu Jul 30 12:24:54.816577 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1.php"] [unique_id "amuI5vxa4UbeLxj1SWW2cQAAAO4"]
[Thu Jul 30 12:24:54.866706 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:58407] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/search/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5vxa4UbeLxj1SWW2cgAAAPA"]
[Thu Jul 30 12:24:55.044748 2026] [security2:error] [pid 738779:tid 739022] [client 172.213.232.128:8841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuI5_xa4UbeLxj1SWW2eQAAAPY"]
[Thu Jul 30 12:24:55.093853 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/about.php"] [unique_id "amuI5_xa4UbeLxj1SWW2ewAAAKc"]
[Thu Jul 30 12:24:55.093953 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/about.php"] [unique_id "amuI5_xa4UbeLxj1SWW2ewAAAKc"]
[Thu Jul 30 12:24:55.238145 2026] [security2:error] [pid 738779:tid 738913] [client 20.203.148.31:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/as.php"] [unique_id "amuI5_xa4UbeLxj1SWW2fAAAAIk"]
[Thu Jul 30 12:24:55.254114 2026] [security2:error] [pid 738779:tid 738941] [client 142.93.53.183:58437] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/search/alfacgiapi/perl.alfa"] [unique_id "amuI5_xa4UbeLxj1SWW2fQAAAKU"]
[Thu Jul 30 12:24:55.420655 2026] [security2:error] [pid 738779:tid 738936] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI5_xa4UbeLxj1SWW2fwAAAKA"]
[Thu Jul 30 12:24:55.420765 2026] [security2:error] [pid 738779:tid 738936] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI5_xa4UbeLxj1SWW2fwAAAKA"]
[Thu Jul 30 12:24:55.643497 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:58454] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/separator/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI5_xa4UbeLxj1SWW2hgAAAK0"]
[Thu Jul 30 12:24:55.710777 2026] [security2:error] [pid 738779:tid 738962] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/edit.php"] [unique_id "amuI5_xa4UbeLxj1SWW2hwAAALo"]
[Thu Jul 30 12:24:55.710883 2026] [security2:error] [pid 738779:tid 738962] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/edit.php"] [unique_id "amuI5_xa4UbeLxj1SWW2hwAAALo"]
[Thu Jul 30 12:24:55.988679 2026] [security2:error] [pid 738779:tid 739035] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/admin.php"] [unique_id "amuI5_xa4UbeLxj1SWW2jAAAAQM"]
[Thu Jul 30 12:24:55.988797 2026] [security2:error] [pid 738779:tid 739035] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/admin.php"] [unique_id "amuI5_xa4UbeLxj1SWW2jAAAAQM"]
[Thu Jul 30 12:24:56.034045 2026] [security2:error] [pid 738779:tid 738959] [client 142.93.53.183:58476] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/separator/alfacgiapi/perl.alfa"] [unique_id "amuI6Pxa4UbeLxj1SWW2jQAAALc"]
[Thu Jul 30 12:24:56.072559 2026] [security2:error] [pid 738779:tid 738925] [client 172.213.232.128:8910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/libraries/vendor/updates.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2jgAAAJU"]
[Thu Jul 30 12:24:56.268034 2026] [security2:error] [pid 738779:tid 738937] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/inputs.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2kgAAAKE"]
[Thu Jul 30 12:24:56.268166 2026] [security2:error] [pid 738779:tid 738937] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/inputs.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2kgAAAKE"]
[Thu Jul 30 12:24:56.424521 2026] [security2:error] [pid 738779:tid 738987] [client 142.93.53.183:58501] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/shortcode/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6Pxa4UbeLxj1SWW2kwAAANM"]
[Thu Jul 30 12:24:56.538610 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/av.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2mgAAAOQ"]
[Thu Jul 30 12:24:56.538696 2026] [security2:error] [pid 738779:tid 739004] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/av.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2mgAAAOQ"]
[Thu Jul 30 12:24:56.751778 2026] [security2:error] [pid 738779:tid 738966] [client 20.203.148.31:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/atomlib.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2ngAAAL4"]
[Thu Jul 30 12:24:56.809971 2026] [security2:error] [pid 738779:tid 738918] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/classwithtostring.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2nwAAAI4"]
[Thu Jul 30 12:24:56.810123 2026] [security2:error] [pid 738779:tid 738918] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/classwithtostring.php"] [unique_id "amuI6Pxa4UbeLxj1SWW2nwAAAI4"]
[Thu Jul 30 12:24:56.812093 2026] [security2:error] [pid 738779:tid 738968] [client 142.93.53.183:58520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/shortcode/alfacgiapi/perl.alfa"] [unique_id "amuI6Pxa4UbeLxj1SWW2oAAAAMA"]
[Thu Jul 30 12:24:57.068512 2026] [security2:error] [pid 738779:tid 738947] [client 20.226.5.174:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/img/xleet.php"] [unique_id "amuI6fxa4UbeLxj1SWW2pAAAAKs"]
[Thu Jul 30 12:24:57.088870 2026] [security2:error] [pid 738779:tid 738930] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuI6fxa4UbeLxj1SWW2pQAAAJo"]
[Thu Jul 30 12:24:57.088955 2026] [security2:error] [pid 738779:tid 738930] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuI6fxa4UbeLxj1SWW2pQAAAJo"]
[Thu Jul 30 12:24:57.187395 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:58550] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-logo/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6fxa4UbeLxj1SWW2rAAAAN4"]
[Thu Jul 30 12:24:57.382107 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-blog.php"] [unique_id "amuI6fxa4UbeLxj1SWW2rQAAAO4"]
[Thu Jul 30 12:24:57.382223 2026] [security2:error] [pid 738779:tid 739014] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-blog.php"] [unique_id "amuI6fxa4UbeLxj1SWW2rQAAAO4"]
[Thu Jul 30 12:24:57.580108 2026] [security2:error] [pid 738779:tid 739029] [client 20.203.148.31:39663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/autoload_classmap.php"] [unique_id "amuI6fxa4UbeLxj1SWW2sQAAAP0"]
[Thu Jul 30 12:24:57.580821 2026] [security2:error] [pid 738779:tid 738960] [client 142.93.53.183:58569] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-logo/alfacgiapi/perl.alfa"] [unique_id "amuI6fxa4UbeLxj1SWW2sgAAALg"]
[Thu Jul 30 12:24:57.601873 2026] [security2:error] [pid 738779:tid 738964] [client 172.213.232.128:6886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/alfa-rex.php7"] [unique_id "amuI6fxa4UbeLxj1SWW2tQAAALw"]
[Thu Jul 30 12:24:57.681430 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/js/jquery/"] [unique_id "amuI6fxa4UbeLxj1SWW2twAAAP4"]
[Thu Jul 30 12:24:57.828500 2026] [security2:error] [pid 738779:tid 738911] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/admin.php"] [unique_id "amuI6fxa4UbeLxj1SWW2uAAAAIc"]
[Thu Jul 30 12:24:57.828646 2026] [security2:error] [pid 738779:tid 738911] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/admin.php"] [unique_id "amuI6fxa4UbeLxj1SWW2uAAAAIc"]
[Thu Jul 30 12:24:57.971463 2026] [security2:error] [pid 738779:tid 738941] [client 142.93.53.183:58592] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-tagline/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6fxa4UbeLxj1SWW2uQAAAKU"]
[Thu Jul 30 12:24:58.099175 2026] [security2:error] [pid 738779:tid 738926] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/adminfuns.php"] [unique_id "amuI6vxa4UbeLxj1SWW2vgAAAJY"]
[Thu Jul 30 12:24:58.099286 2026] [security2:error] [pid 738779:tid 738926] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/adminfuns.php"] [unique_id "amuI6vxa4UbeLxj1SWW2vgAAAJY"]
[Thu Jul 30 12:24:58.257356 2026] [security2:error] [pid 738779:tid 738942] [client 20.203.148.31:47944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/bb.php"] [unique_id "amuI6vxa4UbeLxj1SWW2wgAAAKY"]
[Thu Jul 30 12:24:58.347353 2026] [security2:error] [pid 738779:tid 738952] [client 172.213.232.128:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/alfanew.php"] [unique_id "amuI6vxa4UbeLxj1SWW2wwAAALA"]
[Thu Jul 30 12:24:58.359560 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:58612] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-tagline/alfacgiapi/perl.alfa"] [unique_id "amuI6vxa4UbeLxj1SWW2xAAAALo"]
[Thu Jul 30 12:24:58.408599 2026] [security2:error] [pid 738779:tid 739031] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/goods.php"] [unique_id "amuI6vxa4UbeLxj1SWW2xQAAAP8"]
[Thu Jul 30 12:24:58.408699 2026] [security2:error] [pid 738779:tid 739031] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/goods.php"] [unique_id "amuI6vxa4UbeLxj1SWW2xQAAAP8"]
[Thu Jul 30 12:24:58.693438 2026] [security2:error] [pid 738779:tid 738910] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ms-edit.php"] [unique_id "amuI6vxa4UbeLxj1SWW20QAAAIY"]
[Thu Jul 30 12:24:58.693546 2026] [security2:error] [pid 738779:tid 738910] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ms-edit.php"] [unique_id "amuI6vxa4UbeLxj1SWW20QAAAIY"]
[Thu Jul 30 12:24:58.738960 2026] [security2:error] [pid 738779:tid 738955] [client 142.93.53.183:58638] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-title/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6vxa4UbeLxj1SWW20wAAALM"]
[Thu Jul 30 12:24:58.877755 2026] [core:error] [pid 738779:tid 738956] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:24:58.877777 2026] [core:error] [pid 738779:tid 738956] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:24:58.877912 2026] [security2:error] [pid 738779:tid 738956] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kfo.lku.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuI6vxa4UbeLxj1SWW21gAAALQ"]
[Thu Jul 30 12:24:58.878487 2026] [security2:error] [pid 738779:tid 738944] [client 74.7.244.51:60864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kfo.lku.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuI6vxa4UbeLxj1SWW21AAAqCo"]
[Thu Jul 30 12:24:58.978787 2026] [security2:error] [pid 738779:tid 738954] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/222.php"] [unique_id "amuI6vxa4UbeLxj1SWW21wAAALI"]
[Thu Jul 30 12:24:58.978935 2026] [security2:error] [pid 738779:tid 738954] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/222.php"] [unique_id "amuI6vxa4UbeLxj1SWW21wAAALI"]
[Thu Jul 30 12:24:59.058130 2026] [security2:error] [pid 738779:tid 739023] [client 20.203.148.31:39633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/bnm.php"] [unique_id "amuI6_xa4UbeLxj1SWW22AAAAPc"]
[Thu Jul 30 12:24:59.081199 2026] [security2:error] [pid 738779:tid 738975] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI6vxa4UbeLxj1SWW2yAAAAMc"]
[Thu Jul 30 12:24:59.112394 2026] [security2:error] [pid 738779:tid 739026] [client 127.0.0.1:35972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.mth.gzj.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuI6_xa4UbeLxj1SWW22gAAAPo"]
[Thu Jul 30 12:24:59.112394 2026] [security2:error] [pid 738779:tid 738999] [client 127.0.0.1:35978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuI6_xa4UbeLxj1SWW22wAAAN8"]
[Thu Jul 30 12:24:59.112480 2026] [security2:error] [pid 738779:tid 738988] [client 74.7.175.129:43344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.mth.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuI6_xa4UbeLxj1SWW22QAA1Cs"]
[Thu Jul 30 12:24:59.116863 2026] [security2:error] [pid 738779:tid 738937] [client 172.213.232.128:12300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuI6_xa4UbeLxj1SWW23AAAAKE"]
[Thu Jul 30 12:24:59.128095 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:58661] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/site-title/alfacgiapi/perl.alfa"] [unique_id "amuI6_xa4UbeLxj1SWW23QAAAL0"]
[Thu Jul 30 12:24:59.194135 2026] [security2:error] [pid 738779:tid 739032] [client 74.7.175.191:57160] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bnd.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuI6_xa4UbeLxj1SWW24QAAAQA"]
[Thu Jul 30 12:24:59.264308 2026] [security2:error] [pid 738779:tid 738994] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/cgi-bin/index.php"] [unique_id "amuI6_xa4UbeLxj1SWW26AAAANo"]
[Thu Jul 30 12:24:59.264395 2026] [security2:error] [pid 738779:tid 738994] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/cgi-bin/index.php"] [unique_id "amuI6_xa4UbeLxj1SWW26AAAANo"]
[Thu Jul 30 12:24:59.519606 2026] [security2:error] [pid 738779:tid 739005] [client 142.93.53.183:58686] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/social-link/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI6_xa4UbeLxj1SWW26gAAAOU"]
[Thu Jul 30 12:24:59.564786 2026] [security2:error] [pid 738779:tid 739013] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/dist/"] [unique_id "amuI6_xa4UbeLxj1SWW26wAAAO0"]
[Thu Jul 30 12:24:59.698916 2026] [security2:error] [pid 738779:tid 739029] [client 20.226.5.174:4295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/server.php"] [unique_id "amuI6_xa4UbeLxj1SWW28gAAAP0"]
[Thu Jul 30 12:24:59.718553 2026] [security2:error] [pid 738779:tid 739017] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/BDKR28WP.php"] [unique_id "amuI6_xa4UbeLxj1SWW29gAAAPE"]
[Thu Jul 30 12:24:59.718634 2026] [security2:error] [pid 738779:tid 739017] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/BDKR28WP.php"] [unique_id "amuI6_xa4UbeLxj1SWW29gAAAPE"]
[Thu Jul 30 12:24:59.909198 2026] [security2:error] [pid 738779:tid 738939] [client 142.93.53.183:58707] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/social-link/alfacgiapi/perl.alfa"] [unique_id "amuI6_xa4UbeLxj1SWW29wAAAKM"]
[Thu Jul 30 12:25:00.007206 2026] [security2:error] [pid 738779:tid 739030] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuI6_xa4UbeLxj1SWW2-AAAAP4"]
[Thu Jul 30 12:25:00.160918 2026] [security2:error] [pid 738779:tid 738911] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuI7Pxa4UbeLxj1SWW2-QAAAIc"]
[Thu Jul 30 12:25:00.296760 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:58733] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/social-links/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7Pxa4UbeLxj1SWW3AwAAAPM"]
[Thu Jul 30 12:25:00.302393 2026] [security2:error] [pid 738779:tid 738971] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BAAAAMM"]
[Thu Jul 30 12:25:00.302470 2026] [security2:error] [pid 738779:tid 738971] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BAAAAMM"]
[Thu Jul 30 12:25:00.536274 2026] [security2:error] [pid 738779:tid 738930] [client 20.203.148.31:47891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/bootstrap.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BQAAAJo"]
[Thu Jul 30 12:25:00.637102 2026] [security2:error] [pid 738779:tid 738974] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/abcd.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BgAAAMY"]
[Thu Jul 30 12:25:00.637275 2026] [security2:error] [pid 738779:tid 738974] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/abcd.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3BgAAAMY"]
[Thu Jul 30 12:25:00.647227 2026] [security2:error] [pid 738779:tid 738952] [client 172.213.232.128:36300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuI7Pxa4UbeLxj1SWW3BwAAALA"]
[Thu Jul 30 12:25:00.672219 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:58758] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/social-links/alfacgiapi/perl.alfa"] [unique_id "amuI7Pxa4UbeLxj1SWW3CAAAAP8"]
[Thu Jul 30 12:25:00.914698 2026] [security2:error] [pid 738779:tid 738986] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/a1.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3EAAAANI"]
[Thu Jul 30 12:25:00.914841 2026] [security2:error] [pid 738779:tid 738986] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/a1.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3EAAAANI"]
[Thu Jul 30 12:25:01.021078 2026] [security2:error] [pid 738779:tid 738962] [client 20.226.5.174:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/.well-known/pki-validation/wp-config.php"] [unique_id "amuI7fxa4UbeLxj1SWW3EQAAALo"]
[Thu Jul 30 12:25:01.046859 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:58783] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/spacer/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7fxa4UbeLxj1SWW3EgAAAKk"]
[Thu Jul 30 12:25:01.147124 2026] [security2:error] [pid 738779:tid 738967] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI7Pxa4UbeLxj1SWW3DgAAAL8"]
[Thu Jul 30 12:25:01.150629 2026] [security2:error] [pid 738779:tid 738990] [client 172.213.232.128:18950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-p.php7"] [unique_id "amuI7fxa4UbeLxj1SWW3FgAAANY"]
[Thu Jul 30 12:25:01.193970 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuI7fxa4UbeLxj1SWW3FwAAANM"]
[Thu Jul 30 12:25:01.194106 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuI7fxa4UbeLxj1SWW3FwAAANM"]
[Thu Jul 30 12:25:01.440126 2026] [security2:error] [pid 738779:tid 739006] [client 142.93.53.183:58802] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/spacer/alfacgiapi/perl.alfa"] [unique_id "amuI7fxa4UbeLxj1SWW3HwAAAOY"]
[Thu Jul 30 12:25:01.507475 2026] [security2:error] [pid 738779:tid 738966] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuI7fxa4UbeLxj1SWW3JAAAAL4"]
[Thu Jul 30 12:25:01.507588 2026] [security2:error] [pid 738779:tid 738966] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuI7fxa4UbeLxj1SWW3JAAAAL4"]
[Thu Jul 30 12:25:01.698604 2026] [security2:error] [pid 738779:tid 738944] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI7fxa4UbeLxj1SWW3FQAAAKg"]
[Thu Jul 30 12:25:01.798440 2026] [security2:error] [pid 738779:tid 739003] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuI7fxa4UbeLxj1SWW3KQAAAOM"]
[Thu Jul 30 12:25:01.815113 2026] [security2:error] [pid 738779:tid 738997] [client 142.93.53.183:58829] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/table/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7fxa4UbeLxj1SWW3KgAAAN0"]
[Thu Jul 30 12:25:01.938257 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/simple.php"] [unique_id "amuI7fxa4UbeLxj1SWW3LgAAAOU"]
[Thu Jul 30 12:25:01.938363 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/simple.php"] [unique_id "amuI7fxa4UbeLxj1SWW3LgAAAOU"]
[Thu Jul 30 12:25:02.196425 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:58854] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/table/alfacgiapi/perl.alfa"] [unique_id "amuI7vxa4UbeLxj1SWW3LwAAAN4"]
[Thu Jul 30 12:25:02.240533 2026] [security2:error] [pid 738779:tid 738982] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xxx.php"] [unique_id "amuI7vxa4UbeLxj1SWW3MAAAAM4"]
[Thu Jul 30 12:25:02.240648 2026] [security2:error] [pid 738779:tid 738982] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xxx.php"] [unique_id "amuI7vxa4UbeLxj1SWW3MAAAAM4"]
[Thu Jul 30 12:25:02.476766 2026] [security2:error] [pid 738779:tid 738956] [client 20.203.148.31:46498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/buy.php"] [unique_id "amuI7vxa4UbeLxj1SWW3NwAAALQ"]
[Thu Jul 30 12:25:02.562184 2026] [security2:error] [pid 738779:tid 738960] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/hypo.php"] [unique_id "amuI7vxa4UbeLxj1SWW3OAAAALg"]
[Thu Jul 30 12:25:02.562288 2026] [security2:error] [pid 738779:tid 738960] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/hypo.php"] [unique_id "amuI7vxa4UbeLxj1SWW3OAAAALg"]
[Thu Jul 30 12:25:02.580551 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:58878] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/tag-cloud/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7vxa4UbeLxj1SWW3OQAAANU"]
[Thu Jul 30 12:25:02.760469 2026] [security2:error] [pid 738779:tid 739028] [client 172.213.232.128:19005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/repeater.php"] [unique_id "amuI7vxa4UbeLxj1SWW3OwAAAPw"]
[Thu Jul 30 12:25:02.865335 2026] [security2:error] [pid 738779:tid 738913] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuI7vxa4UbeLxj1SWW3PwAAAIk"]
[Thu Jul 30 12:25:02.955256 2026] [security2:error] [pid 738779:tid 738953] [client 142.93.53.183:58912] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/paymethod/manual/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI7vxa4UbeLxj1SWW3QwAAALE"]
[Thu Jul 30 12:25:03.058890 2026] [security2:error] [pid 738779:tid 739008] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/chosen.php"] [unique_id "amuI7_xa4UbeLxj1SWW3RAAAAOg"]
[Thu Jul 30 12:25:03.059032 2026] [security2:error] [pid 738779:tid 739008] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/chosen.php"] [unique_id "amuI7_xa4UbeLxj1SWW3RAAAAOg"]
[Thu Jul 30 12:25:03.136950 2026] [security2:error] [pid 738779:tid 738935] [client 20.203.148.31:44967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/chosen.php"] [unique_id "amuI7_xa4UbeLxj1SWW3RQAAAJ8"]
[Thu Jul 30 12:25:03.282186 2026] [security2:error] [pid 738779:tid 738921] [client 213.180.203.82:38612] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/robots.txt"] [unique_id "amuI7_xa4UbeLxj1SWW3SgAAAJE"]
[Thu Jul 30 12:25:03.347616 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:58932] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/paymethod/manual/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI7_xa4UbeLxj1SWW3TAAAAOc"]
[Thu Jul 30 12:25:03.406291 2026] [security2:error] [pid 738779:tid 738924] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/block-bindings/"] [unique_id "amuI7_xa4UbeLxj1SWW3TwAAAJQ"]
[Thu Jul 30 12:25:03.578675 2026] [security2:error] [pid 738779:tid 738962] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/als.php"] [unique_id "amuI7_xa4UbeLxj1SWW3VgAAALo"]
[Thu Jul 30 12:25:03.578795 2026] [security2:error] [pid 738779:tid 738962] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/als.php"] [unique_id "amuI7_xa4UbeLxj1SWW3VgAAALo"]
[Thu Jul 30 12:25:03.673425 2026] [security2:error] [pid 738779:tid 739015] [client 20.226.5.174:4314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/themes/twentytwentyfive/flower.php"] [unique_id "amuI7_xa4UbeLxj1SWW3VwAAAO8"]
[Thu Jul 30 12:25:03.734519 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:58959] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/paymethod/manual/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuI7_xa4UbeLxj1SWW3WAAAAKk"]
[Thu Jul 30 12:25:03.844248 2026] [security2:error] [pid 738779:tid 738926] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI7_xa4UbeLxj1SWW3SAAAlkE"]
[Thu Jul 30 12:25:03.862854 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/pol.php"] [unique_id "amuI7_xa4UbeLxj1SWW3XAAAAPc"]
[Thu Jul 30 12:25:03.862959 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/pol.php"] [unique_id "amuI7_xa4UbeLxj1SWW3XAAAAPc"]
[Thu Jul 30 12:25:04.102266 2026] [core:notice] [pid 738779:tid 738910] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:04.113567 2026] [security2:error] [pid 738779:tid 738966] [client 142.93.53.183:58981] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/home/jancox/alfacgiapi/perl.alfa"] [unique_id "amuI8Pxa4UbeLxj1SWW3YQAAAL4"]
[Thu Jul 30 12:25:04.114077 2026] [security2:error] [pid 738779:tid 738999] [client 172.213.232.128:23324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/repeater.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3YgAAAN8"]
[Thu Jul 30 12:25:04.135145 2026] [security2:error] [pid 738779:tid 739001] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file5.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3YwAAAOE"]
[Thu Jul 30 12:25:04.135238 2026] [security2:error] [pid 738779:tid 739001] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file5.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3YwAAAOE"]
[Thu Jul 30 12:25:04.445321 2026] [security2:error] [pid 738779:tid 739002] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3cQAAAOI"]
[Thu Jul 30 12:25:04.445419 2026] [security2:error] [pid 738779:tid 739002] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3cQAAAOI"]
[Thu Jul 30 12:25:04.500121 2026] [security2:error] [pid 738779:tid 739014] [client 142.93.53.183:59017] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/home/jancox/alfacgiapi/bash.alfa"] [unique_id "amuI8Pxa4UbeLxj1SWW3cgAAAO4"]
[Thu Jul 30 12:25:04.742434 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3cwAAAPY"]
[Thu Jul 30 12:25:04.742541 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3cwAAAPY"]
[Thu Jul 30 12:25:04.878808 2026] [security2:error] [pid 738779:tid 738963] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3aQAAALs"]
[Thu Jul 30 12:25:04.893279 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:59046] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/home/jancox/alfacgiapi/py.alfa"] [unique_id "amuI8Pxa4UbeLxj1SWW3dwAAAPE"]
[Thu Jul 30 12:25:04.978467 2026] [security2:error] [pid 738779:tid 738992] [client 20.226.5.174:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuI8Pxa4UbeLxj1SWW3eAAAANg"]
[Thu Jul 30 12:25:05.025784 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/aa2.php"] [unique_id "amuI8fxa4UbeLxj1SWW3fAAAAKc"]
[Thu Jul 30 12:25:05.025870 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/aa2.php"] [unique_id "amuI8fxa4UbeLxj1SWW3fAAAAKc"]
[Thu Jul 30 12:25:05.195875 2026] [security2:error] [pid 738779:tid 738982] [client 20.203.148.31:43472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/class-wp-image.php"] [unique_id "amuI8fxa4UbeLxj1SWW3fgAAAM4"]
[Thu Jul 30 12:25:05.281281 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:59081] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cms/wp-content/jancox/alfacgiapi/perl.alfa"] [unique_id "amuI8fxa4UbeLxj1SWW3fwAAAIs"]
[Thu Jul 30 12:25:05.301631 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ccou.php"] [unique_id "amuI8fxa4UbeLxj1SWW3gAAAAKo"]
[Thu Jul 30 12:25:05.301716 2026] [security2:error] [pid 738779:tid 738946] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ccou.php"] [unique_id "amuI8fxa4UbeLxj1SWW3gAAAAKo"]
[Thu Jul 30 12:25:05.579782 2026] [security2:error] [pid 738779:tid 738974] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dr.php"] [unique_id "amuI8fxa4UbeLxj1SWW3iAAAAMY"]
[Thu Jul 30 12:25:05.579921 2026] [security2:error] [pid 738779:tid 738974] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dr.php"] [unique_id "amuI8fxa4UbeLxj1SWW3iAAAAMY"]
[Thu Jul 30 12:25:05.656361 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:59111] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cms/wp-content/jancox/alfacgiapi/bash.alfa"] [unique_id "amuI8fxa4UbeLxj1SWW3iQAAAOc"]
[Thu Jul 30 12:25:05.919302 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xamp.php"] [unique_id "amuI8fxa4UbeLxj1SWW3jgAAAKQ"]
[Thu Jul 30 12:25:05.919443 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xamp.php"] [unique_id "amuI8fxa4UbeLxj1SWW3jgAAAKQ"]
[Thu Jul 30 12:25:06.048321 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:59139] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cms/wp-content/jancox/alfacgiapi/py.alfa"] [unique_id "amuI8vxa4UbeLxj1SWW3kQAAAPI"]
[Thu Jul 30 12:25:06.181230 2026] [security2:error] [pid 738779:tid 739036] [client 20.226.5.174:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/shell1.php"] [unique_id "amuI8vxa4UbeLxj1SWW3lgAAAQQ"]
[Thu Jul 30 12:25:06.200618 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/bless.php"] [unique_id "amuI8vxa4UbeLxj1SWW3lwAAAPc"]
[Thu Jul 30 12:25:06.200728 2026] [security2:error] [pid 738779:tid 739023] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/bless.php"] [unique_id "amuI8vxa4UbeLxj1SWW3lwAAAPc"]
[Thu Jul 30 12:25:06.440467 2026] [security2:error] [pid 738779:tid 738937] [client 142.93.53.183:59164] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/crm_documents/expenses/10/cache/alfacgiapi/perl.alfa"] [unique_id "amuI8vxa4UbeLxj1SWW3mQAAAKE"]
[Thu Jul 30 12:25:06.484616 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.232.128:8932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/repeater.php"] [unique_id "amuI8vxa4UbeLxj1SWW3nwAAAMU"]
[Thu Jul 30 12:25:06.488432 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file25.php"] [unique_id "amuI8vxa4UbeLxj1SWW3oAAAANM"]
[Thu Jul 30 12:25:06.488523 2026] [security2:error] [pid 738779:tid 738987] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file25.php"] [unique_id "amuI8vxa4UbeLxj1SWW3oAAAANM"]
[Thu Jul 30 12:25:06.809098 2026] [security2:error] [pid 738779:tid 738922] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file6.php"] [unique_id "amuI8vxa4UbeLxj1SWW3pQAAAJI"]
[Thu Jul 30 12:25:06.809214 2026] [security2:error] [pid 738779:tid 738922] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file6.php"] [unique_id "amuI8vxa4UbeLxj1SWW3pQAAAJI"]
[Thu Jul 30 12:25:06.832360 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:59188] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/crm_documents/expenses/10/cache/alfacgiapi/bash.alfa"] [unique_id "amuI8vxa4UbeLxj1SWW3pwAAAMI"]
[Thu Jul 30 12:25:07.111432 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/a2.php"] [unique_id "amuI8_xa4UbeLxj1SWW3qwAAAOU"]
[Thu Jul 30 12:25:07.111540 2026] [security2:error] [pid 738779:tid 739005] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/a2.php"] [unique_id "amuI8_xa4UbeLxj1SWW3qwAAAOU"]
[Thu Jul 30 12:25:07.221186 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:59217] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/crm_documents/expenses/10/cache/alfacgiapi/py.alfa"] [unique_id "amuI8_xa4UbeLxj1SWW3rwAAAPY"]
[Thu Jul 30 12:25:07.388065 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file15.php"] [unique_id "amuI8_xa4UbeLxj1SWW3sgAAANc"]
[Thu Jul 30 12:25:07.388186 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file15.php"] [unique_id "amuI8_xa4UbeLxj1SWW3sgAAANc"]
[Thu Jul 30 12:25:07.611919 2026] [security2:error] [pid 738779:tid 738941] [client 142.93.53.183:59245] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PJPSQ_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI8_xa4UbeLxj1SWW3uwAAAKU"]
[Thu Jul 30 12:25:07.672498 2026] [security2:error] [pid 738779:tid 738939] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/f35.php"] [unique_id "amuI8_xa4UbeLxj1SWW3vAAAAKM"]
[Thu Jul 30 12:25:07.672610 2026] [security2:error] [pid 738779:tid 738939] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/f35.php"] [unique_id "amuI8_xa4UbeLxj1SWW3vAAAAKM"]
[Thu Jul 30 12:25:07.737879 2026] [security2:error] [pid 738779:tid 738993] [client 20.226.5.174:4290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-set.php"] [unique_id "amuI8_xa4UbeLxj1SWW3wQAAANk"]
[Thu Jul 30 12:25:07.932409 2026] [security2:error] [pid 738779:tid 739017] [client 20.203.148.31:48083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/classsmtps.php"] [unique_id "amuI8_xa4UbeLxj1SWW3wgAAAPE"]
[Thu Jul 30 12:25:07.977735 2026] [security2:error] [pid 738779:tid 738923] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-load.php"] [unique_id "amuI8_xa4UbeLxj1SWW3wwAAAJM"]
[Thu Jul 30 12:25:07.977829 2026] [security2:error] [pid 738779:tid 738923] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-load.php"] [unique_id "amuI8_xa4UbeLxj1SWW3wwAAAJM"]
[Thu Jul 30 12:25:08.002393 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:59272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PJPSQ_DATA/alfacgiapi/py.alfa"] [unique_id "amuI9Pxa4UbeLxj1SWW3xAAAAK0"]
[Thu Jul 30 12:25:08.247492 2026] [security2:error] [pid 738779:tid 738959] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xwpg.php"] [unique_id "amuI9Pxa4UbeLxj1SWW3ywAAALc"]
[Thu Jul 30 12:25:08.247637 2026] [security2:error] [pid 738779:tid 738959] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xwpg.php"] [unique_id "amuI9Pxa4UbeLxj1SWW3ywAAALc"]
[Thu Jul 30 12:25:08.393252 2026] [security2:error] [pid 738779:tid 738986] [client 142.93.53.183:59301] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/PJPSQ_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI9Pxa4UbeLxj1SWW3zAAAANI"]
[Thu Jul 30 12:25:08.528373 2026] [security2:error] [pid 738779:tid 738930] [client 20.203.148.31:48620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/classwithtostring.php"] [unique_id "amuI9Pxa4UbeLxj1SWW3zQAAAJo"]
[Thu Jul 30 12:25:08.582012 2026] [security2:error] [pid 738779:tid 738967] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/assets/"] [unique_id "amuI9Pxa4UbeLxj1SWW30QAAAL8"]
[Thu Jul 30 12:25:08.657111 2026] [security2:error] [pid 738779:tid 738933] [client 47.98.96.52:57434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/03/logo-light-1.png"] [unique_id "amuI9Pxa4UbeLxj1SWW30gAAAJ0"]
[Thu Jul 30 12:25:08.758645 2026] [security2:error] [pid 738779:tid 738954] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/sunrise/"] [unique_id "amuI9Pxa4UbeLxj1SWW31wAAALI"]
[Thu Jul 30 12:25:08.772447 2026] [security2:error] [pid 738779:tid 738937] [client 142.93.53.183:59324] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/journal/files/PJPSQ_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI9Pxa4UbeLxj1SWW32AAAAKE"]
[Thu Jul 30 12:25:08.926796 2026] [security2:error] [pid 738779:tid 738912] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xstelth.php"] [unique_id "amuI9Pxa4UbeLxj1SWW32QAAAIg"]
[Thu Jul 30 12:25:08.926920 2026] [security2:error] [pid 738779:tid 738912] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xstelth.php"] [unique_id "amuI9Pxa4UbeLxj1SWW32QAAAIg"]
[Thu Jul 30 12:25:08.951310 2026] [security2:error] [pid 738779:tid 739015] [client 20.226.5.174:4324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuI9Pxa4UbeLxj1SWW32gAAAO8"]
[Thu Jul 30 12:25:09.151235 2026] [security2:error] [pid 738779:tid 738968] [client 142.93.53.183:59352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/journal/files/PJPSQ_DATA/alfacgiapi/py.alfa"] [unique_id "amuI9fxa4UbeLxj1SWW33wAAAMA"]
[Thu Jul 30 12:25:09.202814 2026] [security2:error] [pid 738779:tid 738984] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuI9fxa4UbeLxj1SWW34AAAANA"]
[Thu Jul 30 12:25:09.202948 2026] [security2:error] [pid 738779:tid 738984] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuI9fxa4UbeLxj1SWW34AAAANA"]
[Thu Jul 30 12:25:09.291107 2026] [security2:error] [pid 738779:tid 738958] [client 20.203.148.31:43969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/config.php"] [unique_id "amuI9fxa4UbeLxj1SWW35AAAALY"]
[Thu Jul 30 12:25:09.489923 2026] [security2:error] [pid 738779:tid 738931] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/aaa.php"] [unique_id "amuI9fxa4UbeLxj1SWW35gAAAJs"]
[Thu Jul 30 12:25:09.490072 2026] [security2:error] [pid 738779:tid 738931] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/aaa.php"] [unique_id "amuI9fxa4UbeLxj1SWW35gAAAJs"]
[Thu Jul 30 12:25:09.528940 2026] [security2:error] [pid 738779:tid 738997] [client 142.93.53.183:59379] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/journal/files/PJPSQ_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI9fxa4UbeLxj1SWW35wAAAN0"]
[Thu Jul 30 12:25:09.763394 2026] [security2:error] [pid 738779:tid 738947] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/gecko.php"] [unique_id "amuI9fxa4UbeLxj1SWW37QAAAKs"]
[Thu Jul 30 12:25:09.763493 2026] [security2:error] [pid 738779:tid 738947] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/gecko.php"] [unique_id "amuI9fxa4UbeLxj1SWW37QAAAKs"]
[Thu Jul 30 12:25:09.805203 2026] [security2:error] [pid 738779:tid 739032] [client 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI9fxa4UbeLxj1SWW33gABAGw"]
[Thu Jul 30 12:25:09.908623 2026] [security2:error] [pid 738779:tid 738996] [client 142.93.53.183:59409] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/jancox/alfacgiapi/perl.alfa"] [unique_id "amuI9fxa4UbeLxj1SWW38wAAANw"]
[Thu Jul 30 12:25:10.038528 2026] [security2:error] [pid 738779:tid 739011] [client 20.226.5.174:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/oauth.php"] [unique_id "amuI9vxa4UbeLxj1SWW39AAAAOs"]
[Thu Jul 30 12:25:10.059150 2026] [security2:error] [pid 738779:tid 739022] [client 20.203.148.31:45037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/core.php"] [unique_id "amuI9vxa4UbeLxj1SWW39QAAAPY"]
[Thu Jul 30 12:25:10.092083 2026] [security2:error] [pid 738779:tid 738960] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/pbck.php"] [unique_id "amuI9vxa4UbeLxj1SWW39wAAALg"]
[Thu Jul 30 12:25:10.092163 2026] [security2:error] [pid 738779:tid 738960] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/pbck.php"] [unique_id "amuI9vxa4UbeLxj1SWW39wAAALg"]
[Thu Jul 30 12:25:10.156894 2026] [security2:error] [pid 738779:tid 739005] [client 38.190.144.4:60947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI9vxa4UbeLxj1SWW3-gAAAOU"]
[Thu Jul 30 12:25:10.157043 2026] [security2:error] [pid 738779:tid 739005] [client 38.190.144.4:60947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuI9vxa4UbeLxj1SWW3-gAAAOU"]
[Thu Jul 30 12:25:10.299278 2026] [security2:error] [pid 738779:tid 739033] [client 142.93.53.183:59435] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/jancox/alfacgiapi/bash.alfa"] [unique_id "amuI9vxa4UbeLxj1SWW3-wAAAQE"]
[Thu Jul 30 12:25:10.363052 2026] [security2:error] [pid 738779:tid 738935] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xiugai.php"] [unique_id "amuI9vxa4UbeLxj1SWW3_wAAAJ8"]
[Thu Jul 30 12:25:10.363150 2026] [security2:error] [pid 738779:tid 738935] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xiugai.php"] [unique_id "amuI9vxa4UbeLxj1SWW3_wAAAJ8"]
[Thu Jul 30 12:25:10.688523 2026] [security2:error] [pid 738779:tid 738911] [client 142.93.53.183:59468] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asoee/alfacgiapi/perl.alfa"] [unique_id "amuI9vxa4UbeLxj1SWW4BgAAAIc"]
[Thu Jul 30 12:25:10.700087 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/e.php"] [unique_id "amuI9vxa4UbeLxj1SWW4BwAAAKQ"]
[Thu Jul 30 12:25:10.700164 2026] [security2:error] [pid 738779:tid 738940] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/e.php"] [unique_id "amuI9vxa4UbeLxj1SWW4BwAAAKQ"]
[Thu Jul 30 12:25:11.040245 2026] [security2:error] [pid 738779:tid 738945] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/adminner.php"] [unique_id "amuI9_xa4UbeLxj1SWW4DAAAAKk"]
[Thu Jul 30 12:25:11.040351 2026] [security2:error] [pid 738779:tid 738945] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/adminner.php"] [unique_id "amuI9_xa4UbeLxj1SWW4DAAAAKk"]
[Thu Jul 30 12:25:11.068460 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:59492] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asoee/alfacgiapi/py.alfa"] [unique_id "amuI9_xa4UbeLxj1SWW4DQAAANY"]
[Thu Jul 30 12:25:11.165131 2026] [core:notice] [pid 738779:tid 738903] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:11.269555 2026] [security2:error] [pid 738779:tid 738915] [client 20.52.54.143:10218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wk/index.php"] [unique_id "amuI9_xa4UbeLxj1SWW4FgAAAIs"]
[Thu Jul 30 12:25:11.383632 2026] [security2:error] [pid 738779:tid 738984] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/file1221.php"] [unique_id "amuI9_xa4UbeLxj1SWW4JAAAANA"]
[Thu Jul 30 12:25:11.383733 2026] [security2:error] [pid 738779:tid 738984] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/file1221.php"] [unique_id "amuI9_xa4UbeLxj1SWW4JAAAANA"]
[Thu Jul 30 12:25:11.447131 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:59518] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asoee/alfacgiapi/bash.alfa"] [unique_id "amuI9_xa4UbeLxj1SWW4JwAAAMI"]
[Thu Jul 30 12:25:11.480769 2026] [security2:error] [pid 738779:tid 738926] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI9_xa4UbeLxj1SWW4DgAAAJY"]
[Thu Jul 30 12:25:11.641456 2026] [security2:error] [pid 738779:tid 739030] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuI9_xa4UbeLxj1SWW4CwAA_nw"]
[Thu Jul 30 12:25:11.662065 2026] [security2:error] [pid 738779:tid 738996] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/inx.php"] [unique_id "amuI9_xa4UbeLxj1SWW4MQAAANw"]
[Thu Jul 30 12:25:11.662166 2026] [security2:error] [pid 738779:tid 738996] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/inx.php"] [unique_id "amuI9_xa4UbeLxj1SWW4MQAAANw"]
[Thu Jul 30 12:25:11.778534 2026] [security2:error] [pid 738779:tid 738985] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI9_xa4UbeLxj1SWW4FQAAANE"]
[Thu Jul 30 12:25:11.832157 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:59546] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/jancox/alfacgiapi/py.alfa"] [unique_id "amuI9_xa4UbeLxj1SWW4MgAAAPg"]
[Thu Jul 30 12:25:11.939778 2026] [autoindex:error] [pid 738779:tid 738983] [client 20.226.5.174:0] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:25:11.951192 2026] [security2:error] [pid 738779:tid 739027] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/qqqa.php"] [unique_id "amuI9_xa4UbeLxj1SWW4OgAAAPs"]
[Thu Jul 30 12:25:11.951279 2026] [security2:error] [pid 738779:tid 739027] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/qqqa.php"] [unique_id "amuI9_xa4UbeLxj1SWW4OgAAAPs"]
[Thu Jul 30 12:25:12.082462 2026] [security2:error] [pid 738779:tid 738932] [client 20.203.148.31:48139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/css.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4OwAAAJw"]
[Thu Jul 30 12:25:12.221654 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:59569] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/src/scss/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuI-Pxa4UbeLxj1SWW4QgAAAI0"]
[Thu Jul 30 12:25:12.249126 2026] [security2:error] [pid 738779:tid 738940] [client 20.226.5.174:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/cgi-bin/upfile.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4QwAAAKQ"]
[Thu Jul 30 12:25:12.288905 2026] [security2:error] [pid 738779:tid 738924] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/reviall.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4RAAAAJQ"]
[Thu Jul 30 12:25:12.289023 2026] [security2:error] [pid 738779:tid 738924] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/reviall.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4RAAAAJQ"]
[Thu Jul 30 12:25:12.568564 2026] [security2:error] [pid 738779:tid 738933] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/404.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4SQAAAJ0"]
[Thu Jul 30 12:25:12.568706 2026] [security2:error] [pid 738779:tid 738933] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/404.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4SQAAAJ0"]
[Thu Jul 30 12:25:12.613836 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:59593] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/src/scss/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuI-Pxa4UbeLxj1SWW4SgAAAMc"]
[Thu Jul 30 12:25:12.670465 2026] [security2:error] [pid 738779:tid 738982] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4RQAAAM4"]
[Thu Jul 30 12:25:12.840954 2026] [security2:error] [pid 738779:tid 738958] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/bolt.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4VwAAALY"]
[Thu Jul 30 12:25:12.841088 2026] [security2:error] [pid 738779:tid 738958] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/bolt.php"] [unique_id "amuI-Pxa4UbeLxj1SWW4VwAAALY"]
[Thu Jul 30 12:25:12.988873 2026] [security2:error] [pid 738779:tid 738914] [client 142.93.53.183:59612] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/src/scss/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuI-Pxa4UbeLxj1SWW4WAAAAIo"]
[Thu Jul 30 12:25:13.152945 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/File.php"] [unique_id "amuI-fxa4UbeLxj1SWW4YgAAALw"]
[Thu Jul 30 12:25:13.153075 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/File.php"] [unique_id "amuI-fxa4UbeLxj1SWW4YgAAALw"]
[Thu Jul 30 12:25:13.380686 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:59638] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/classes/article/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI-fxa4UbeLxj1SWW4ZwAAANk"]
[Thu Jul 30 12:25:13.426534 2026] [security2:error] [pid 738779:tid 738949] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fi22.php"] [unique_id "amuI-fxa4UbeLxj1SWW4aAAAAK0"]
[Thu Jul 30 12:25:13.426646 2026] [security2:error] [pid 738779:tid 738949] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fi22.php"] [unique_id "amuI-fxa4UbeLxj1SWW4aAAAAK0"]
[Thu Jul 30 12:25:13.436926 2026] [security2:error] [pid 738779:tid 738970] [client 20.226.5.174:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/upload_file1.php"] [unique_id "amuI-fxa4UbeLxj1SWW4aQAAAMI"]
[Thu Jul 30 12:25:13.580655 2026] [security2:error] [pid 738779:tid 738989] [client 20.52.54.143:10216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/av.php"] [unique_id "amuI-fxa4UbeLxj1SWW4gAAAANU"]
[Thu Jul 30 12:25:13.660952 2026] [security2:error] [pid 738779:tid 738948] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI-fxa4UbeLxj1SWW4ZgAAAKw"]
[Thu Jul 30 12:25:13.702717 2026] [security2:error] [pid 738779:tid 739001] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/zero.php"] [unique_id "amuI-fxa4UbeLxj1SWW4hAAAAOE"]
[Thu Jul 30 12:25:13.702803 2026] [security2:error] [pid 738779:tid 739001] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/zero.php"] [unique_id "amuI-fxa4UbeLxj1SWW4hAAAAOE"]
[Thu Jul 30 12:25:13.768653 2026] [security2:error] [pid 738779:tid 738987] [client 142.93.53.183:59663] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/classes/article/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuI-fxa4UbeLxj1SWW4iQAAANM"]
[Thu Jul 30 12:25:13.995201 2026] [security2:error] [pid 738779:tid 739013] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1xmomo.php"] [unique_id "amuI-fxa4UbeLxj1SWW4kQAAAO0"]
[Thu Jul 30 12:25:13.995285 2026] [security2:error] [pid 738779:tid 739013] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1xmomo.php"] [unique_id "amuI-fxa4UbeLxj1SWW4kQAAAO0"]
[Thu Jul 30 12:25:14.141670 2026] [security2:error] [pid 738779:tid 738913] [client 142.93.53.183:59698] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/classes/article/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI-vxa4UbeLxj1SWW4nQAAAIk"]
[Thu Jul 30 12:25:14.180925 2026] [security2:error] [pid 738779:tid 739034] [client 20.52.54.143:9348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/mini.php"] [unique_id "amuI-vxa4UbeLxj1SWW4nwAAAQI"]
[Thu Jul 30 12:25:14.282304 2026] [security2:error] [pid 738779:tid 738917] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fmws.php"] [unique_id "amuI-vxa4UbeLxj1SWW4rwAAAI0"]
[Thu Jul 30 12:25:14.282394 2026] [security2:error] [pid 738779:tid 738917] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fmws.php"] [unique_id "amuI-vxa4UbeLxj1SWW4rwAAAI0"]
[Thu Jul 30 12:25:14.497197 2026] [security2:error] [pid 738779:tid 738970] [client 20.226.5.174:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/rafa.php"] [unique_id "amuI-vxa4UbeLxj1SWW4swAAAMI"]
[Thu Jul 30 12:25:14.537222 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:59727] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jancox/alfacgiapi/perl.alfa"] [unique_id "amuI-vxa4UbeLxj1SWW4tAAAAL0"]
[Thu Jul 30 12:25:14.550760 2026] [security2:error] [pid 738779:tid 738968] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuI-vxa4UbeLxj1SWW4tgAAAMA"]
[Thu Jul 30 12:25:14.550845 2026] [security2:error] [pid 738779:tid 738968] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuI-vxa4UbeLxj1SWW4tgAAAMA"]
[Thu Jul 30 12:25:14.836666 2026] [security2:error] [pid 738779:tid 738992] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/hp2.php"] [unique_id "amuI-vxa4UbeLxj1SWW40wAAANg"]
[Thu Jul 30 12:25:14.836772 2026] [security2:error] [pid 738779:tid 738992] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/hp2.php"] [unique_id "amuI-vxa4UbeLxj1SWW40wAAANg"]
[Thu Jul 30 12:25:14.881621 2026] [security2:error] [pid 738779:tid 738950] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI-vxa4UbeLxj1SWW4tQAAAK4"]
[Thu Jul 30 12:25:14.927346 2026] [security2:error] [pid 738779:tid 739028] [client 142.93.53.183:59749] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jancox/alfacgiapi/bash.alfa"] [unique_id "amuI-vxa4UbeLxj1SWW41QAAAPw"]
[Thu Jul 30 12:25:14.971520 2026] [security2:error] [pid 738779:tid 738986] [client 20.203.148.31:48107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/database.php"] [unique_id "amuI-vxa4UbeLxj1SWW41gAAANI"]
[Thu Jul 30 12:25:14.997649 2026] [security2:error] [pid 738779:tid 739005] [client 98.84.60.17:22273] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2018/06/WhatsApp-Image-2018-06-30-at-21.42.37-1-768x1024.jpeg"] [unique_id "amuI-vxa4UbeLxj1SWW42AAAAOU"]
[Thu Jul 30 12:25:15.107127 2026] [security2:error] [pid 738779:tid 738948] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/aabb.php"] [unique_id "amuI-_xa4UbeLxj1SWW43AAAAKw"]
[Thu Jul 30 12:25:15.107260 2026] [security2:error] [pid 738779:tid 738948] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/aabb.php"] [unique_id "amuI-_xa4UbeLxj1SWW43AAAAKw"]
[Thu Jul 30 12:25:15.266595 2026] [security2:error] [pid 738779:tid 739031] [client 20.52.54.143:10198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aa.php"] [unique_id "amuI-_xa4UbeLxj1SWW43gAAAP8"]
[Thu Jul 30 12:25:15.315261 2026] [security2:error] [pid 738779:tid 738927] [client 142.93.53.183:59780] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/jancox/alfacgiapi/py.alfa"] [unique_id "amuI-_xa4UbeLxj1SWW46AAAAJc"]
[Thu Jul 30 12:25:15.404531 2026] [security2:error] [pid 738779:tid 738926] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1254xx.php"] [unique_id "amuI-_xa4UbeLxj1SWW48wAAAJY"]
[Thu Jul 30 12:25:15.404627 2026] [security2:error] [pid 738779:tid 738926] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1254xx.php"] [unique_id "amuI-_xa4UbeLxj1SWW48wAAAJY"]
[Thu Jul 30 12:25:15.690615 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:59801] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/vendors/jquery.sparkline/src/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI-_xa4UbeLxj1SWW4_AAAANk"]
[Thu Jul 30 12:25:15.752632 2026] [security2:error] [pid 738779:tid 738943] [client 20.203.148.31:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/db.php"] [unique_id "amuI-_xa4UbeLxj1SWW4_gAAAKc"]
[Thu Jul 30 12:25:15.756063 2026] [security2:error] [pid 738779:tid 738938] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuI-_xa4UbeLxj1SWW4_wAAAKI"]
[Thu Jul 30 12:25:15.756149 2026] [security2:error] [pid 738779:tid 738938] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuI-_xa4UbeLxj1SWW4_wAAAKI"]
[Thu Jul 30 12:25:15.888542 2026] [security2:error] [pid 738779:tid 739021] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI-_xa4UbeLxj1SWW4-AAAAPU"]
[Thu Jul 30 12:25:15.929748 2026] [security2:error] [pid 738779:tid 738989] [client 20.52.54.143:10234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/w.php"] [unique_id "amuI-_xa4UbeLxj1SWW5CAAAANU"]
[Thu Jul 30 12:25:16.028624 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/pms297.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5CQAAALM"]
[Thu Jul 30 12:25:16.028731 2026] [security2:error] [pid 738779:tid 738955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/pms297.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5CQAAALM"]
[Thu Jul 30 12:25:16.083762 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:59823] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/vendors/jquery.sparkline/src/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI_Pxa4UbeLxj1SWW5CgAAAKk"]
[Thu Jul 30 12:25:16.299300 2026] [security2:error] [pid 738779:tid 738933] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5FQAAAJ0"]
[Thu Jul 30 12:25:16.299445 2026] [security2:error] [pid 738779:tid 738933] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5FQAAAJ0"]
[Thu Jul 30 12:25:16.387139 2026] [security2:error] [pid 738779:tid 738952] [client 20.203.148.31:46645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/default.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5HAAAALA"]
[Thu Jul 30 12:25:16.474281 2026] [security2:error] [pid 738779:tid 738937] [client 142.93.53.183:59851] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/client_assets/vendors/jquery.sparkline/src/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuI_Pxa4UbeLxj1SWW5HgAAAKE"]
[Thu Jul 30 12:25:16.545539 2026] [core:notice] [pid 738779:tid 738829] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:16.575079 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5IwAAALw"]
[Thu Jul 30 12:25:16.575186 2026] [security2:error] [pid 738779:tid 738964] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5IwAAALw"]
[Thu Jul 30 12:25:16.711372 2026] [security2:error] [pid 738779:tid 739009] [client 20.52.54.143:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/admin.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5KAAAAOk"]
[Thu Jul 30 12:25:16.859961 2026] [security2:error] [pid 738779:tid 738932] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5LQAAAJw"]
[Thu Jul 30 12:25:16.860125 2026] [security2:error] [pid 738779:tid 738932] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5LQAAAJw"]
[Thu Jul 30 12:25:16.862406 2026] [security2:error] [pid 738779:tid 738992] [client 142.93.53.183:59877] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuI_Pxa4UbeLxj1SWW5LwAAANg"]
[Thu Jul 30 12:25:17.100530 2026] [security2:error] [pid 738779:tid 739035] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuI_Pxa4UbeLxj1SWW5LAAAAQM"]
[Thu Jul 30 12:25:17.138961 2026] [security2:error] [pid 738779:tid 738999] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuI_fxa4UbeLxj1SWW5PQAAAN8"]
[Thu Jul 30 12:25:17.139093 2026] [security2:error] [pid 738779:tid 738999] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuI_fxa4UbeLxj1SWW5PQAAAN8"]
[Thu Jul 30 12:25:17.255629 2026] [security2:error] [pid 738779:tid 738916] [client 142.93.53.183:59901] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuI_fxa4UbeLxj1SWW5RgAAAIw"]
[Thu Jul 30 12:25:17.345502 2026] [security2:error] [pid 738779:tid 738986] [client 20.226.5.174:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-admin/maint/src_api.php"] [unique_id "amuI_fxa4UbeLxj1SWW5SwAAANI"]
[Thu Jul 30 12:25:17.410264 2026] [security2:error] [pid 738779:tid 738963] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dyui.php"] [unique_id "amuI_fxa4UbeLxj1SWW5UgAAALs"]
[Thu Jul 30 12:25:17.410390 2026] [security2:error] [pid 738779:tid 738963] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dyui.php"] [unique_id "amuI_fxa4UbeLxj1SWW5UgAAALs"]
[Thu Jul 30 12:25:17.509588 2026] [core:notice] [pid 738779:tid 739008] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:17.643180 2026] [security2:error] [pid 738779:tid 738910] [client 142.93.53.183:59931] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuI_fxa4UbeLxj1SWW5XQAAAIY"]
[Thu Jul 30 12:25:17.682785 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ho.php"] [unique_id "amuI_fxa4UbeLxj1SWW5YgAAANc"]
[Thu Jul 30 12:25:17.682898 2026] [security2:error] [pid 738779:tid 738991] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ho.php"] [unique_id "amuI_fxa4UbeLxj1SWW5YgAAANc"]
[Thu Jul 30 12:25:17.765225 2026] [security2:error] [pid 738779:tid 739019] [client 20.52.54.143:10223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuI_fxa4UbeLxj1SWW5ZgAAAPM"]
[Thu Jul 30 12:25:17.971204 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/66b867516c8f01.php"] [unique_id "amuI_fxa4UbeLxj1SWW5agAAAPY"]
[Thu Jul 30 12:25:17.971298 2026] [security2:error] [pid 738779:tid 739022] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/66b867516c8f01.php"] [unique_id "amuI_fxa4UbeLxj1SWW5agAAAPY"]
[Thu Jul 30 12:25:18.035222 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:59956] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuI_vxa4UbeLxj1SWW5bwAAAPk"]
[Thu Jul 30 12:25:18.241758 2026] [security2:error] [pid 738779:tid 738989] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ext.php"] [unique_id "amuI_vxa4UbeLxj1SWW5cwAAANU"]
[Thu Jul 30 12:25:18.241856 2026] [security2:error] [pid 738779:tid 738989] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ext.php"] [unique_id "amuI_vxa4UbeLxj1SWW5cwAAANU"]
[Thu Jul 30 12:25:18.322592 2026] [security2:error] [pid 738779:tid 738942] [client 20.203.148.31:46642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/dropdown.php"] [unique_id "amuI_vxa4UbeLxj1SWW5dwAAAKY"]
[Thu Jul 30 12:25:18.428046 2026] [security2:error] [pid 738779:tid 738967] [client 142.93.53.183:59980] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuI_vxa4UbeLxj1SWW5ewAAAL8"]
[Thu Jul 30 12:25:18.525853 2026] [security2:error] [pid 738779:tid 739017] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuI_vxa4UbeLxj1SWW5fwAAAPE"]
[Thu Jul 30 12:25:18.525952 2026] [security2:error] [pid 738779:tid 739017] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuI_vxa4UbeLxj1SWW5fwAAAPE"]
[Thu Jul 30 12:25:18.799397 2026] [security2:error] [pid 738779:tid 738983] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuI_vxa4UbeLxj1SWW5jAAAAM8"]
[Thu Jul 30 12:25:18.799498 2026] [security2:error] [pid 738779:tid 738983] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuI_vxa4UbeLxj1SWW5jAAAAM8"]
[Thu Jul 30 12:25:18.819737 2026] [security2:error] [pid 738779:tid 739013] [client 142.93.53.183:60002] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuI_vxa4UbeLxj1SWW5jgAAAO0"]
[Thu Jul 30 12:25:19.000079 2026] [security2:error] [pid 738779:tid 739028] [client 20.203.148.31:43953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/edit.php"] [unique_id "amuI_vxa4UbeLxj1SWW5mAAAAPw"]
[Thu Jul 30 12:25:19.065047 2026] [security2:error] [pid 738779:tid 738926] [client 20.226.5.174:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/atomlib.php"] [unique_id "amuI__xa4UbeLxj1SWW5mQAAAJY"]
[Thu Jul 30 12:25:19.074030 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/584062352875874akp.php"] [unique_id "amuI__xa4UbeLxj1SWW5mwAAAKc"]
[Thu Jul 30 12:25:19.074162 2026] [security2:error] [pid 738779:tid 738943] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/584062352875874akp.php"] [unique_id "amuI__xa4UbeLxj1SWW5mwAAAKc"]
[Thu Jul 30 12:25:19.209092 2026] [security2:error] [pid 738779:tid 738951] [client 142.93.53.183:60026] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuI__xa4UbeLxj1SWW5pgAAAK8"]
[Thu Jul 30 12:25:19.390677 2026] [security2:error] [pid 738779:tid 738967] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/diidi.php"] [unique_id "amuI__xa4UbeLxj1SWW5rgAAAL8"]
[Thu Jul 30 12:25:19.390758 2026] [security2:error] [pid 738779:tid 738967] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/diidi.php"] [unique_id "amuI__xa4UbeLxj1SWW5rgAAAL8"]
[Thu Jul 30 12:25:19.443417 2026] [security2:error] [pid 738779:tid 738855] [remote 57.141.0.34:49946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/390124662/feed/rss2/"] [unique_id "amuI__xa4UbeLxj1SWW5rwAAk0s"]
[Thu Jul 30 12:25:19.599390 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:60056] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuI__xa4UbeLxj1SWW5tAAAAMU"]
[Thu Jul 30 12:25:19.668944 2026] [security2:error] [pid 738779:tid 739006] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/clarebypas.php"] [unique_id "amuI__xa4UbeLxj1SWW5tgAAAOY"]
[Thu Jul 30 12:25:19.669062 2026] [security2:error] [pid 738779:tid 739006] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/clarebypas.php"] [unique_id "amuI__xa4UbeLxj1SWW5tgAAAOY"]
[Thu Jul 30 12:25:19.990128 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:60081] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/volunteers/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuI__xa4UbeLxj1SWW5xQAAANc"]
[Thu Jul 30 12:25:20.001397 2026] [security2:error] [pid 738779:tid 738939] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuI__xa4UbeLxj1SWW5rQAAAKM"]
[Thu Jul 30 12:25:20.017820 2026] [core:notice] [pid 738779:tid 738862] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:20.021489 2026] [security2:error] [pid 738779:tid 738910] [client 195.63.29.16:14456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuI__xa4UbeLxj1SWW5wwAAhk4"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:25:20.150746 2026] [security2:error] [pid 738779:tid 739002] [client 20.203.148.31:43961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/f35.php"] [unique_id "amuJAPxa4UbeLxj1SWW5ywAAAOI"]
[Thu Jul 30 12:25:20.363540 2026] [security2:error] [pid 738779:tid 739033] [client 142.93.53.183:60110] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuJAPxa4UbeLxj1SWW50wAAAQE"]
[Thu Jul 30 12:25:20.449774 2026] [security2:error] [pid 738779:tid 739013] [client 20.226.5.174:4338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-trackback.php"] [unique_id "amuJAPxa4UbeLxj1SWW53wAAAO0"]
[Thu Jul 30 12:25:20.597008 2026] [core:notice] [pid 738779:tid 738850] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:20.740668 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:60134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuJAPxa4UbeLxj1SWW5_AAAAPA"]
[Thu Jul 30 12:25:21.130362 2026] [security2:error] [pid 738779:tid 738925] [client 142.93.53.183:60158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuJAfxa4UbeLxj1SWW6DAAAAJU"]
[Thu Jul 30 12:25:21.482606 2026] [security2:error] [pid 738779:tid 738986] [client 20.52.54.143:10210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/m.php"] [unique_id "amuJAfxa4UbeLxj1SWW6JwAAANI"]
[Thu Jul 30 12:25:21.521115 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:60186] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuJAfxa4UbeLxj1SWW6KgAAAPM"]
[Thu Jul 30 12:25:21.910752 2026] [security2:error] [pid 738779:tid 738948] [client 142.93.53.183:60211] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuJAfxa4UbeLxj1SWW6NwAAAKw"]
[Thu Jul 30 12:25:22.209109 2026] [security2:error] [pid 738779:tid 739005] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJAfxa4UbeLxj1SWW6NAAAAOU"]
[Thu Jul 30 12:25:22.302180 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:60236] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/hvp/data-manual/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuJAvxa4UbeLxj1SWW6UQAAAPY"]
[Thu Jul 30 12:25:22.420174 2026] [security2:error] [pid 738779:tid 738946] [client 20.226.5.174:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuJAvxa4UbeLxj1SWW6VQAAAKo"]
[Thu Jul 30 12:25:22.566214 2026] [security2:error] [pid 738779:tid 738944] [client 20.52.54.143:9358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuJAvxa4UbeLxj1SWW6UAAAAKg"]
[Thu Jul 30 12:25:22.693640 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:60267] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuJAvxa4UbeLxj1SWW6agAAAMc"]
[Thu Jul 30 12:25:23.073830 2026] [security2:error] [pid 738779:tid 738922] [client 20.203.148.31:46634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/f7.php"] [unique_id "amuJA_xa4UbeLxj1SWW6fgAAAJI"]
[Thu Jul 30 12:25:23.083855 2026] [security2:error] [pid 738779:tid 738929] [client 142.93.53.183:60295] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuJA_xa4UbeLxj1SWW6fwAAAJk"]
[Thu Jul 30 12:25:23.474482 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:60309] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuJA_xa4UbeLxj1SWW6lQAAAMM"]
[Thu Jul 30 12:25:23.530841 2026] [security2:error] [pid 738779:tid 739023] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJA_xa4UbeLxj1SWW6iAAAAPc"]
[Thu Jul 30 12:25:23.864969 2026] [security2:error] [pid 738779:tid 739014] [client 142.93.53.183:60326] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJA_xa4UbeLxj1SWW6oQAAAO4"]
[Thu Jul 30 12:25:24.179360 2026] [security2:error] [pid 738779:tid 738912] [client 38.190.144.4:61445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJBPxa4UbeLxj1SWW6rgAAAIg"]
[Thu Jul 30 12:25:24.179457 2026] [security2:error] [pid 738779:tid 738912] [client 38.190.144.4:61445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJBPxa4UbeLxj1SWW6rgAAAIg"]
[Thu Jul 30 12:25:24.255216 2026] [security2:error] [pid 738779:tid 738911] [client 142.93.53.183:60341] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJBPxa4UbeLxj1SWW6tAAAAIc"]
[Thu Jul 30 12:25:24.539286 2026] [security2:error] [pid 738779:tid 739035] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJBPxa4UbeLxj1SWW6rwAAAQM"]
[Thu Jul 30 12:25:24.646154 2026] [security2:error] [pid 738779:tid 738919] [client 142.93.53.183:60358] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/volunteers/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJBPxa4UbeLxj1SWW6vgAAAI8"]
[Thu Jul 30 12:25:24.906549 2026] [core:notice] [pid 738779:tid 738966] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:25.037202 2026] [security2:error] [pid 738779:tid 738913] [client 142.93.53.183:60375] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuJBfxa4UbeLxj1SWW6yQAAAIk"]
[Thu Jul 30 12:25:25.427418 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:60388] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuJBfxa4UbeLxj1SWW6zwAAAN4"]
[Thu Jul 30 12:25:25.706508 2026] [security2:error] [pid 738779:tid 738992] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJBfxa4UbeLxj1SWW6zgAAANg"]
[Thu Jul 30 12:25:25.819500 2026] [security2:error] [pid 738779:tid 738977] [client 142.93.53.183:60400] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/.well-known/acme-challenge/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuJBfxa4UbeLxj1SWW61gAAAMk"]
[Thu Jul 30 12:25:25.826458 2026] [security2:error] [pid 738779:tid 738954] [client 20.226.5.174:4309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/doc.php/"] [unique_id "amuJBfxa4UbeLxj1SWW61wAAALI"]
[Thu Jul 30 12:25:26.209125 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:60418] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/tag-cloud/alfacgiapi/perl.alfa"] [unique_id "amuJBvxa4UbeLxj1SWW62wAAAMc"]
[Thu Jul 30 12:25:26.599553 2026] [security2:error] [pid 738779:tid 738951] [client 142.93.53.183:60430] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/template-part/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJBvxa4UbeLxj1SWW64wAAAK8"]
[Thu Jul 30 12:25:26.762304 2026] [security2:error] [pid 738779:tid 738955] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJBvxa4UbeLxj1SWW64QAAALM"]
[Thu Jul 30 12:25:26.913375 2026] [security2:error] [pid 738779:tid 738909] [client 20.226.5.174:4304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/error_exception.php"] [unique_id "amuJBvxa4UbeLxj1SWW68wAAAIU"]
[Thu Jul 30 12:25:26.986443 2026] [security2:error] [pid 738779:tid 738919] [client 142.93.53.183:60441] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/template-part/alfacgiapi/perl.alfa"] [unique_id "amuJBvxa4UbeLxj1SWW69AAAAI8"]
[Thu Jul 30 12:25:27.131796 2026] [security2:error] [pid 738779:tid 738934] [client 57.141.0.9:60022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJBvxa4UbeLxj1SWW67gAAnhc"], referer: https://igetvape-australia.com/product/iget-bar-pro-blackberry-pomegranate-cherry/?add-to-cart=102
[Thu Jul 30 12:25:27.379162 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:60459] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/term-description/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJB_xa4UbeLxj1SWW6_wAAAPY"]
[Thu Jul 30 12:25:27.766414 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:60474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/term-description/alfacgiapi/perl.alfa"] [unique_id "amuJB_xa4UbeLxj1SWW7CwAAANk"]
[Thu Jul 30 12:25:27.924143 2026] [proxy:error] [pid 738779:tid 738967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:27.924194 2026] [proxy_http:error] [pid 738779:tid 738967] [client 20.52.54.143:10220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:27.924962 2026] [proxy:error] [pid 738779:tid 738967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:27.925026 2026] [proxy_http:error] [pid 738779:tid 738967] [client 20.52.54.143:10220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:27.930580 2026] [security2:error] [pid 738779:tid 739009] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJB_xa4UbeLxj1SWW7BwAAAOk"]
[Thu Jul 30 12:25:28.126835 2026] [security2:error] [pid 738779:tid 739016] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJB_xa4UbeLxj1SWW7AgAAAPA"]
[Thu Jul 30 12:25:28.146169 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:60484] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/text-columns/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJCPxa4UbeLxj1SWW7FgAAAOM"]
[Thu Jul 30 12:25:28.518684 2026] [security2:error] [pid 738779:tid 738934] [client 142.93.53.183:60498] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/text-columns/alfacgiapi/perl.alfa"] [unique_id "amuJCPxa4UbeLxj1SWW7KgAAAJ4"]
[Thu Jul 30 12:25:28.763488 2026] [security2:error] [pid 738779:tid 738930] [client 20.226.5.174:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/infos.php"] [unique_id "amuJCPxa4UbeLxj1SWW7OAAAAJo"]
[Thu Jul 30 12:25:28.894057 2026] [security2:error] [pid 738779:tid 739011] [client 142.93.53.183:60517] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/verse/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJCPxa4UbeLxj1SWW7OQAAAOs"]
[Thu Jul 30 12:25:28.959990 2026] [security2:error] [pid 738779:tid 738947] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJCPxa4UbeLxj1SWW7MQAAAKs"]
[Thu Jul 30 12:25:29.051445 2026] [security2:error] [pid 738779:tid 738987] [client 20.52.54.143:9347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/classwithtostring.php"] [unique_id "amuJCfxa4UbeLxj1SWW7PwAAANM"]
[Thu Jul 30 12:25:29.287336 2026] [security2:error] [pid 738779:tid 738943] [client 142.93.53.183:60531] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/verse/alfacgiapi/perl.alfa"] [unique_id "amuJCfxa4UbeLxj1SWW7RAAAAKc"]
[Thu Jul 30 12:25:29.591940 2026] [security2:error] [pid 738779:tid 739027] [client 20.52.54.143:10205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gmo.php"] [unique_id "amuJCfxa4UbeLxj1SWW7SQAAAPs"]
[Thu Jul 30 12:25:29.677402 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:60546] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/video/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJCfxa4UbeLxj1SWW7SwAAANc"]
[Thu Jul 30 12:25:30.067077 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:60562] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/video/alfacgiapi/perl.alfa"] [unique_id "amuJCvxa4UbeLxj1SWW7VAAAAPg"]
[Thu Jul 30 12:25:30.085167 2026] [security2:error] [pid 738779:tid 738968] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJCfxa4UbeLxj1SWW7TwAAAMA"]
[Thu Jul 30 12:25:30.239786 2026] [security2:error] [pid 738779:tid 738956] [client 20.226.5.174:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/contact.php"] [unique_id "amuJCvxa4UbeLxj1SWW7VgAAALQ"]
[Thu Jul 30 12:25:30.297104 2026] [security2:error] [pid 738779:tid 739028] [client 20.52.54.143:9359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuJCvxa4UbeLxj1SWW7WgAAAPw"]
[Thu Jul 30 12:25:30.455067 2026] [security2:error] [pid 738779:tid 738982] [client 142.93.53.183:60579] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/widget-group/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJCvxa4UbeLxj1SWW7XAAAAM4"]
[Thu Jul 30 12:25:30.788885 2026] [security2:error] [pid 738779:tid 738997] [client 20.52.54.143:10196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-the.php"] [unique_id "amuJCvxa4UbeLxj1SWW7ZQAAAN0"]
[Thu Jul 30 12:25:30.849874 2026] [security2:error] [pid 738779:tid 738972] [client 142.93.53.183:60593] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/blocks/widget-group/alfacgiapi/perl.alfa"] [unique_id "amuJCvxa4UbeLxj1SWW7ZgAAAMQ"]
[Thu Jul 30 12:25:31.092807 2026] [security2:error] [pid 738779:tid 738966] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJCvxa4UbeLxj1SWW7YQAAAL4"]
[Thu Jul 30 12:25:31.240102 2026] [security2:error] [pid 738779:tid 738944] [client 142.93.53.183:60608] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/certificates/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJC_xa4UbeLxj1SWW7bQAAAKg"]
[Thu Jul 30 12:25:31.311267 2026] [security2:error] [pid 738779:tid 738981] [client 20.52.54.143:9362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/404.php"] [unique_id "amuJC_xa4UbeLxj1SWW7dwAAAM0"]
[Thu Jul 30 12:25:31.519198 2026] [security2:error] [pid 738779:tid 738926] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJC_xa4UbeLxj1SWW7cAAAAJY"]
[Thu Jul 30 12:25:31.629004 2026] [security2:error] [pid 738779:tid 739032] [client 142.93.53.183:60624] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/certificates/alfacgiapi/perl.alfa"] [unique_id "amuJC_xa4UbeLxj1SWW7fwAAAQA"]
[Thu Jul 30 12:25:32.002642 2026] [security2:error] [pid 738779:tid 738994] [client 142.93.53.183:60640] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJDPxa4UbeLxj1SWW7hAAAANo"]
[Thu Jul 30 12:25:32.135287 2026] [security2:error] [pid 738779:tid 738961] [client 20.226.5.174:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/user.php"] [unique_id "amuJDPxa4UbeLxj1SWW7iAAAALk"]
[Thu Jul 30 12:25:32.168243 2026] [security2:error] [pid 738779:tid 738984] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJC_xa4UbeLxj1SWW7gwAAANA"]
[Thu Jul 30 12:25:32.232275 2026] [security2:error] [pid 738779:tid 738843] [remote 57.141.0.12:57332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuJDPxa4UbeLxj1SWW7jAAApD8"]
[Thu Jul 30 12:25:32.380774 2026] [security2:error] [pid 738779:tid 738974] [client 142.93.53.183:60652] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/css/alfacgiapi/perl.alfa"] [unique_id "amuJDPxa4UbeLxj1SWW7jQAAAMY"]
[Thu Jul 30 12:25:32.771279 2026] [security2:error] [pid 738779:tid 738960] [client 142.93.53.183:60667] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/customize/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJDPxa4UbeLxj1SWW7lgAAALg"]
[Thu Jul 30 12:25:33.162340 2026] [security2:error] [pid 738779:tid 738939] [client 142.93.53.183:60683] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/customize/alfacgiapi/perl.alfa"] [unique_id "amuJDfxa4UbeLxj1SWW7oAAAAKM"]
[Thu Jul 30 12:25:33.208538 2026] [security2:error] [pid 738779:tid 738945] [client 121.29.149.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJDPxa4UbeLxj1SWW7mQAAAKk"]
[Thu Jul 30 12:25:33.549912 2026] [security2:error] [pid 738779:tid 738977] [client 142.93.53.183:60703] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJDfxa4UbeLxj1SWW7qgAAAMk"]
[Thu Jul 30 12:25:33.584261 2026] [security2:error] [pid 738779:tid 739017] [client 20.52.54.143:9345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/init.php"] [unique_id "amuJDfxa4UbeLxj1SWW7rAAAAPE"]
[Thu Jul 30 12:25:33.609095 2026] [security2:error] [pid 738779:tid 739026] [client 87.101.92.171:53760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJDfxa4UbeLxj1SWW7rQAAAPo"]
[Thu Jul 30 12:25:33.609183 2026] [security2:error] [pid 738779:tid 739026] [client 87.101.92.171:53760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJDfxa4UbeLxj1SWW7rQAAAPo"]
[Thu Jul 30 12:25:33.728429 2026] [security2:error] [pid 738779:tid 739022] [client 20.226.5.174:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/env.php"] [unique_id "amuJDfxa4UbeLxj1SWW7sQAAAPY"]
[Thu Jul 30 12:25:33.930618 2026] [security2:error] [pid 738779:tid 738986] [client 142.93.53.183:60721] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/fonts/alfacgiapi/perl.alfa"] [unique_id "amuJDfxa4UbeLxj1SWW7sgAAANI"]
[Thu Jul 30 12:25:34.318350 2026] [security2:error] [pid 738779:tid 738956] [client 142.93.53.183:60736] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/html-api/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJDvxa4UbeLxj1SWW7wAAAALQ"]
[Thu Jul 30 12:25:34.482425 2026] [security2:error] [pid 738779:tid 738963] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJDvxa4UbeLxj1SWW7twAAALs"]
[Thu Jul 30 12:25:34.544120 2026] [security2:error] [pid 738779:tid 738917] [client 20.52.54.143:10192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/file5.php"] [unique_id "amuJDvxa4UbeLxj1SWW7xQAAAI0"]
[Thu Jul 30 12:25:34.701819 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:60751] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/html-api/alfacgiapi/perl.alfa"] [unique_id "amuJDvxa4UbeLxj1SWW7xgAAAL0"]
[Thu Jul 30 12:25:34.854194 2026] [security2:error] [pid 738779:tid 739036] [client 20.226.5.174:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/uploads/de_fb_uploads/b.php"] [unique_id "amuJDvxa4UbeLxj1SWW7ygAAAQQ"]
[Thu Jul 30 12:25:35.096273 2026] [security2:error] [pid 738779:tid 738987] [client 142.93.53.183:60769] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/images/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJD_xa4UbeLxj1SWW70gAAANM"]
[Thu Jul 30 12:25:35.162932 2026] [security2:error] [pid 738779:tid 739023] [client 20.52.54.143:10215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuJD_xa4UbeLxj1SWW71AAAAPc"]
[Thu Jul 30 12:25:35.216534 2026] [security2:error] [pid 738779:tid 738860] [remote 74.7.241.60:45446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuJD_xa4UbeLxj1SWW71QAAmFA"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:25:35.484079 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:60780] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/images/alfacgiapi/perl.alfa"] [unique_id "amuJD_xa4UbeLxj1SWW73QAAAPk"]
[Thu Jul 30 12:25:35.540595 2026] [security2:error] [pid 738779:tid 738966] [client 57.141.0.32:46190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJD_xa4UbeLxj1SWW72QAAvlI"], referer: https://igetvape-australia.com/product/alibarbar-ingot-mango-magic-9000-puffs/?add-to-cart=934
[Thu Jul 30 12:25:35.873694 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:60793] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/js/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJD_xa4UbeLxj1SWW75QAAAOM"]
[Thu Jul 30 12:25:35.901857 2026] [security2:error] [pid 738779:tid 739006] [client 20.226.5.174:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/.well-known//index.php"] [unique_id "amuJD_xa4UbeLxj1SWW75gAAAOY"]
[Thu Jul 30 12:25:36.204602 2026] [security2:error] [pid 738779:tid 738991] [client 74.7.241.167:43316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.tereasshop.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuJEPxa4UbeLxj1SWW77AAAANc"]
[Thu Jul 30 12:25:36.266734 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:60811] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/js/alfacgiapi/perl.alfa"] [unique_id "amuJEPxa4UbeLxj1SWW77wAAAPI"]
[Thu Jul 30 12:25:36.423937 2026] [security2:error] [pid 738779:tid 738943] [client 20.52.54.143:9363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/shell.php"] [unique_id "amuJEPxa4UbeLxj1SWW78gAAAKc"]
[Thu Jul 30 12:25:36.657382 2026] [security2:error] [pid 738779:tid 738979] [client 142.93.53.183:60827] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/php-compat/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJEPxa4UbeLxj1SWW7-wAAAMs"]
[Thu Jul 30 12:25:37.048535 2026] [security2:error] [pid 738779:tid 738916] [client 142.93.53.183:60845] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/php-compat/alfacgiapi/perl.alfa"] [unique_id "amuJEfxa4UbeLxj1SWW8BQAAAIw"]
[Thu Jul 30 12:25:37.168014 2026] [security2:error] [pid 738779:tid 738972] [client 20.52.54.143:9406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/f35.php"] [unique_id "amuJEfxa4UbeLxj1SWW8EQAAAMQ"]
[Thu Jul 30 12:25:37.420743 2026] [security2:error] [pid 738779:tid 738871] [remote 57.141.0.12:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuJEfxa4UbeLxj1SWW8FQAAwls"]
[Thu Jul 30 12:25:37.438758 2026] [security2:error] [pid 738779:tid 739032] [client 142.93.53.183:60864] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/pomo/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJEfxa4UbeLxj1SWW8FgAAAQA"]
[Thu Jul 30 12:25:37.831017 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:60880] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/pomo/alfacgiapi/perl.alfa"] [unique_id "amuJEfxa4UbeLxj1SWW8GwAAAJE"]
[Thu Jul 30 12:25:37.853401 2026] [security2:error] [pid 738779:tid 738938] [client 20.226.5.174:4335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/blog/wp-content/plugins/ubh/up.php"] [unique_id "amuJEfxa4UbeLxj1SWW8HAAAAKI"]
[Thu Jul 30 12:25:38.051071 2026] [security2:error] [pid 738779:tid 738914] [client 20.52.54.143:10204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/new.php"] [unique_id "amuJEvxa4UbeLxj1SWW8IQAAAIo"]
[Thu Jul 30 12:25:38.221258 2026] [security2:error] [pid 738779:tid 738976] [client 142.93.53.183:60898] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJEvxa4UbeLxj1SWW8JQAAAMg"]
[Thu Jul 30 12:25:38.414695 2026] [security2:error] [pid 738779:tid 738918] [client 3.212.219.113:23257] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/189/d78ded98b499c41640a963a2c580e3f6.jpg"] [unique_id "amuJEvxa4UbeLxj1SWW8JwAAAI4"]
[Thu Jul 30 12:25:38.600190 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:60915] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/rest-api/alfacgiapi/perl.alfa"] [unique_id "amuJEvxa4UbeLxj1SWW8MQAAALo"]
[Thu Jul 30 12:25:38.985614 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:60932] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/sitemaps/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJEvxa4UbeLxj1SWW8QwAAAO8"]
[Thu Jul 30 12:25:38.991605 2026] [security2:error] [pid 738779:tid 738927] [client 172.237.109.114:54763] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/api/.env"] [unique_id "amuJEvxa4UbeLxj1SWW8RAAAAJc"]
[Thu Jul 30 12:25:39.077024 2026] [security2:error] [pid 738779:tid 738925] [client 20.226.5.174:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/edit.php"] [unique_id "amuJE_xa4UbeLxj1SWW8RQAAAJU"]
[Thu Jul 30 12:25:39.091951 2026] [security2:error] [pid 738779:tid 738998] [client 20.52.54.143:9349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/adminfuns.php"] [unique_id "amuJE_xa4UbeLxj1SWW8RgAAAN4"]
[Thu Jul 30 12:25:39.347384 2026] [security2:error] [pid 738779:tid 738947] [client 172.237.109.114:51618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJEvxa4UbeLxj1SWW8QgAAAKs"]
[Thu Jul 30 12:25:39.374709 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:60948] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/sitemaps/alfacgiapi/perl.alfa"] [unique_id "amuJE_xa4UbeLxj1SWW8TgAAAOk"]
[Thu Jul 30 12:25:39.618643 2026] [core:notice] [pid 738779:tid 738873] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:39.766613 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:60964] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/sodium_compat/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJE_xa4UbeLxj1SWW8VwAAANY"]
[Thu Jul 30 12:25:39.836810 2026] [proxy:error] [pid 738779:tid 738910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:39.836890 2026] [proxy_http:error] [pid 738779:tid 738910] [client 20.52.54.143:10203] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:39.837489 2026] [proxy:error] [pid 738779:tid 738910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:39.837537 2026] [proxy_http:error] [pid 738779:tid 738910] [client 20.52.54.143:10203] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:39.878703 2026] [core:notice] [pid 738779:tid 738891] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:40.155939 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:60984] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/sodium_compat/alfacgiapi/perl.alfa"] [unique_id "amuJFPxa4UbeLxj1SWW8dgAAAOc"]
[Thu Jul 30 12:25:40.530088 2026] [security2:error] [pid 738779:tid 739032] [client 142.93.53.183:60999] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/style-engine/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJFPxa4UbeLxj1SWW8gAAAAQA"]
[Thu Jul 30 12:25:40.545139 2026] [security2:error] [pid 738779:tid 739001] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJFPxa4UbeLxj1SWW8fQAAAOE"]
[Thu Jul 30 12:25:40.586194 2026] [security2:error] [pid 738779:tid 738959] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.dl.truckersofeuropes3mod.com"] [uri "/"] [unique_id "amuJFPxa4UbeLxj1SWW8hAAAALc"]
[Thu Jul 30 12:25:40.923122 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:61020] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/style-engine/alfacgiapi/perl.alfa"] [unique_id "amuJFPxa4UbeLxj1SWW8oQAAAI0"]
[Thu Jul 30 12:25:41.164326 2026] [security2:error] [pid 738779:tid 738941] [client 20.226.5.174:4162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/locks.php"] [unique_id "amuJFfxa4UbeLxj1SWW8qwAAAKU"]
[Thu Jul 30 12:25:41.313751 2026] [security2:error] [pid 738779:tid 738926] [client 142.93.53.183:61037] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/theme-compat/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJFfxa4UbeLxj1SWW8sAAAAJY"]
[Thu Jul 30 12:25:41.706423 2026] [security2:error] [pid 738779:tid 738951] [client 142.93.53.183:61056] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/theme-compat/alfacgiapi/perl.alfa"] [unique_id "amuJFfxa4UbeLxj1SWW8wQAAAK8"]
[Thu Jul 30 12:25:41.711652 2026] [proxy:error] [pid 738779:tid 739016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:41.711737 2026] [proxy_http:error] [pid 738779:tid 739016] [client 20.52.54.143:10229] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:41.712300 2026] [proxy:error] [pid 738779:tid 739016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:41.712351 2026] [proxy_http:error] [pid 738779:tid 739016] [client 20.52.54.143:10229] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:41.845063 2026] [security2:error] [pid 738779:tid 738953] [client 17.241.227.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJFfxa4UbeLxj1SWW8wAAAALE"]
[Thu Jul 30 12:25:41.847654 2026] [security2:error] [pid 738779:tid 738976] [client 68.235.38.2:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuJFfxa4UbeLxj1SWW8xQAAAMg"]
[Thu Jul 30 12:25:41.847753 2026] [security2:error] [pid 738779:tid 738976] [client 68.235.38.2:32976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuJFfxa4UbeLxj1SWW8xQAAAMg"]
[Thu Jul 30 12:25:42.091870 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:61071] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/widgets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJFvxa4UbeLxj1SWW81wAAAL0"]
[Thu Jul 30 12:25:42.156404 2026] [core:notice] [pid 738779:tid 738928] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:42.396377 2026] [security2:error] [pid 738779:tid 738998] [client 20.52.54.143:10226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/fm.php"] [unique_id "amuJFvxa4UbeLxj1SWW87AAAAN4"]
[Thu Jul 30 12:25:42.485244 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:61090] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/widgets/alfacgiapi/perl.alfa"] [unique_id "amuJFvxa4UbeLxj1SWW87gAAAJE"]
[Thu Jul 30 12:25:42.508207 2026] [security2:error] [pid 738779:tid 738937] [client 38.190.144.4:64405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJFvxa4UbeLxj1SWW87wAAAKE"]
[Thu Jul 30 12:25:42.508339 2026] [security2:error] [pid 738779:tid 738937] [client 38.190.144.4:64405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJFvxa4UbeLxj1SWW87wAAAKE"]
[Thu Jul 30 12:25:42.863078 2026] [security2:error] [pid 738779:tid 738910] [client 87.101.92.171:46536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.92.101.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuJFvxa4UbeLxj1SWW89QAAAIY"]
[Thu Jul 30 12:25:42.863185 2026] [security2:error] [pid 738779:tid 738910] [client 87.101.92.171:46536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuJFvxa4UbeLxj1SWW89QAAAIY"]
[Thu Jul 30 12:25:42.876322 2026] [security2:error] [pid 738779:tid 738952] [client 142.93.53.183:61109] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2020/12/alfacgiapi/perl.alfa"] [unique_id "amuJFvxa4UbeLxj1SWW89gAAALA"]
[Thu Jul 30 12:25:43.222918 2026] [security2:error] [pid 738779:tid 738919] [client 20.226.5.174:4165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/alfa-rex1.php"] [unique_id "amuJF_xa4UbeLxj1SWW8_wAAAI8"]
[Thu Jul 30 12:25:43.264226 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:61121] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJF_xa4UbeLxj1SWW9AAAAAL0"]
[Thu Jul 30 12:25:43.608050 2026] [security2:error] [pid 738779:tid 739005] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJF_xa4UbeLxj1SWW9AQAAAOU"]
[Thu Jul 30 12:25:43.657414 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:61136] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/updraft/alfacgiapi/perl.alfa"] [unique_id "amuJF_xa4UbeLxj1SWW9BwAAANk"]
[Thu Jul 30 12:25:44.048005 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:61150] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/library/alfacgiapi/perl.alfa"] [unique_id "amuJGPxa4UbeLxj1SWW9EwAAAMM"]
[Thu Jul 30 12:25:44.435995 2026] [security2:error] [pid 738779:tid 739026] [client 142.93.53.183:61168] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/library/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGPxa4UbeLxj1SWW9GwAAAPo"]
[Thu Jul 30 12:25:44.829602 2026] [security2:error] [pid 738779:tid 738978] [client 142.93.53.183:61185] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGPxa4UbeLxj1SWW9JQAAAMo"]
[Thu Jul 30 12:25:45.039911 2026] [core:notice] [pid 738779:tid 738794] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:45.065865 2026] [proxy:error] [pid 738779:tid 738933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:45.065936 2026] [proxy_http:error] [pid 738779:tid 738933] [client 20.52.54.143:10219] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:45.066508 2026] [proxy:error] [pid 738779:tid 738933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:45.066554 2026] [proxy_http:error] [pid 738779:tid 738933] [client 20.52.54.143:10219] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:45.134828 2026] [security2:error] [pid 738779:tid 738941] [client 20.226.5.174:4178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/uploads/gfwisone.php"] [unique_id "amuJGfxa4UbeLxj1SWW9LwAAAKU"]
[Thu Jul 30 12:25:45.218650 2026] [security2:error] [pid 738779:tid 739029] [client 142.93.53.183:61197] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGfxa4UbeLxj1SWW9MgAAAP0"]
[Thu Jul 30 12:25:45.324388 2026] [core:notice] [pid 738779:tid 738805] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:45.610489 2026] [security2:error] [pid 738779:tid 739013] [client 142.93.53.183:61211] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGfxa4UbeLxj1SWW9PAAAAO0"]
[Thu Jul 30 12:25:45.908267 2026] [security2:error] [pid 738779:tid 738980] [client 20.52.54.143:9366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/file.php"] [unique_id "amuJGfxa4UbeLxj1SWW9QwAAAMw"]
[Thu Jul 30 12:25:45.999468 2026] [security2:error] [pid 738779:tid 738925] [client 142.93.53.183:61237] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/alfacgiapi/perl.alfa"] [unique_id "amuJGfxa4UbeLxj1SWW9RQAAAJU"]
[Thu Jul 30 12:25:46.389412 2026] [security2:error] [pid 738779:tid 738931] [client 142.93.53.183:61249] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/-/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGvxa4UbeLxj1SWW9UQAAAJs"]
[Thu Jul 30 12:25:46.511851 2026] [security2:error] [pid 738779:tid 738987] [client 20.226.5.174:4204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/rex/l/flower.php"] [unique_id "amuJGvxa4UbeLxj1SWW9WQAAANM"]
[Thu Jul 30 12:25:46.783050 2026] [security2:error] [pid 738779:tid 738933] [client 142.93.53.183:61261] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/-/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJGvxa4UbeLxj1SWW9XwAAAJ0"]
[Thu Jul 30 12:25:46.962283 2026] [proxy:error] [pid 738779:tid 739002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:46.962370 2026] [proxy_http:error] [pid 738779:tid 739002] [client 20.52.54.143:9350] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:46.963071 2026] [proxy:error] [pid 738779:tid 739002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:46.963121 2026] [proxy_http:error] [pid 738779:tid 739002] [client 20.52.54.143:9350] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:47.172795 2026] [security2:error] [pid 738779:tid 738994] [client 142.93.53.183:61273] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/alfacgiapi/perl.alfa"] [unique_id "amuJG_xa4UbeLxj1SWW9ZwAAANo"]
[Thu Jul 30 12:25:47.563713 2026] [security2:error] [pid 738779:tid 739005] [client 142.93.53.183:61288] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/upload/alfacgiapi/perl.alfa"] [unique_id "amuJG_xa4UbeLxj1SWW9cQAAAOU"]
[Thu Jul 30 12:25:47.633789 2026] [security2:error] [pid 738779:tid 738969] [client 20.52.54.143:9354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/bolt.php"] [unique_id "amuJG_xa4UbeLxj1SWW9cgAAAME"]
[Thu Jul 30 12:25:47.926138 2026] [security2:error] [pid 738779:tid 738966] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJG_xa4UbeLxj1SWW9eQAAAL4"]
[Thu Jul 30 12:25:47.951884 2026] [security2:error] [pid 738779:tid 739021] [client 142.93.53.183:61304] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/upload/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJG_xa4UbeLxj1SWW9egAAAPU"]
[Thu Jul 30 12:25:48.001216 2026] [security2:error] [pid 738779:tid 738928] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJG_xa4UbeLxj1SWW9awAAAJg"]
[Thu Jul 30 12:25:48.345601 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:61316] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJHPxa4UbeLxj1SWW9gQAAAOE"]
[Thu Jul 30 12:25:48.546285 2026] [security2:error] [pid 738779:tid 738954] [client 20.52.54.143:10237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/3.php"] [unique_id "amuJHPxa4UbeLxj1SWW9hgAAALI"]
[Thu Jul 30 12:25:48.735883 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:61329] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJHPxa4UbeLxj1SWW9jQAAAM8"]
[Thu Jul 30 12:25:48.819862 2026] [security2:error] [pid 738779:tid 738948] [client 213.152.161.118:51756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuJHPxa4UbeLxj1SWW9jgAAAKw"]
[Thu Jul 30 12:25:48.819970 2026] [security2:error] [pid 738779:tid 738948] [client 213.152.161.118:51756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuJHPxa4UbeLxj1SWW9jgAAAKw"]
[Thu Jul 30 12:25:49.116399 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:61336] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/upload/alfacgiapi/perl.alfa"] [unique_id "amuJHfxa4UbeLxj1SWW9kgAAAIs"]
[Thu Jul 30 12:25:49.123733 2026] [security2:error] [pid 738779:tid 739008] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJHPxa4UbeLxj1SWW9hQAAAOg"]
[Thu Jul 30 12:25:49.471391 2026] [security2:error] [pid 738779:tid 738995] [client 20.226.5.174:4189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-admin/user/post.php"] [unique_id "amuJHfxa4UbeLxj1SWW9lgAAANs"]
[Thu Jul 30 12:25:49.516740 2026] [security2:error] [pid 738779:tid 738922] [client 142.93.53.183:61353] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/upload/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJHfxa4UbeLxj1SWW9lwAAAJI"]
[Thu Jul 30 12:25:49.670462 2026] [security2:error] [pid 738779:tid 738982] [client 20.52.54.143:9390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/222.php"] [unique_id "amuJHfxa4UbeLxj1SWW9nAAAAM4"]
[Thu Jul 30 12:25:49.907505 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:61362] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJHfxa4UbeLxj1SWW9oQAAAJA"]
[Thu Jul 30 12:25:50.298145 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:61373] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJHvxa4UbeLxj1SWW9qwAAAPg"]
[Thu Jul 30 12:25:50.303254 2026] [security2:error] [pid 738779:tid 739007] [client 20.52.54.143:9388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuJHvxa4UbeLxj1SWW9rAAAAOc"]
[Thu Jul 30 12:25:50.689048 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:61380] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/alfacgiapi/perl.alfa"] [unique_id "amuJHvxa4UbeLxj1SWW9sQAAALs"]
[Thu Jul 30 12:25:50.737049 2026] [security2:error] [pid 738779:tid 738964] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJHvxa4UbeLxj1SWW9owAAvDE"]
[Thu Jul 30 12:25:50.869951 2026] [security2:error] [pid 738779:tid 738980] [client 114.119.149.92:28495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/bg_home"] [unique_id "amuJHvxa4UbeLxj1SWW9tgAAAMw"], referer: https://www.jesus.claims/bg_home
[Thu Jul 30 12:25:51.079359 2026] [security2:error] [pid 738779:tid 738959] [client 142.93.53.183:61388] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJH_xa4UbeLxj1SWW9twAAALc"]
[Thu Jul 30 12:25:51.256848 2026] [security2:error] [pid 738779:tid 738942] [client 20.52.54.143:9954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuJH_xa4UbeLxj1SWW9vwAAAKY"]
[Thu Jul 30 12:25:51.470363 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:61400] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJH_xa4UbeLxj1SWW9wwAAAJM"]
[Thu Jul 30 12:25:51.699549 2026] [security2:error] [pid 738779:tid 738839] [remote 57.141.0.25:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuJH_xa4UbeLxj1SWW9ygAA4Ds"]
[Thu Jul 30 12:25:51.737464 2026] [security2:error] [pid 738779:tid 738930] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJH_xa4UbeLxj1SWW9vQAAAJo"]
[Thu Jul 30 12:25:51.859359 2026] [security2:error] [pid 738779:tid 738914] [client 142.93.53.183:61407] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJH_xa4UbeLxj1SWW90AAAAIo"]
[Thu Jul 30 12:25:52.248674 2026] [security2:error] [pid 738779:tid 738913] [client 142.93.53.183:61418] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/plugins/alfacgiapi/perl.alfa"] [unique_id "amuJIPxa4UbeLxj1SWW93AAAAIk"]
[Thu Jul 30 12:25:52.357224 2026] [proxy:error] [pid 738779:tid 738949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:52.357304 2026] [proxy_http:error] [pid 738779:tid 738949] [client 20.52.54.143:9943] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:52.357863 2026] [proxy:error] [pid 738779:tid 738949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:52.357907 2026] [proxy_http:error] [pid 738779:tid 738949] [client 20.52.54.143:9943] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:25:52.428625 2026] [security2:error] [pid 738779:tid 738994] [client 20.226.5.174:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/file5.php"] [unique_id "amuJIPxa4UbeLxj1SWW94gAAANo"]
[Thu Jul 30 12:25:52.641772 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:61425] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJIPxa4UbeLxj1SWW95QAAAJA"]
[Thu Jul 30 12:25:53.022843 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:61436] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/themes/alfacgiapi/perl.alfa"] [unique_id "amuJIfxa4UbeLxj1SWW97AAAAP8"]
[Thu Jul 30 12:25:53.407259 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:61444] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/themes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJIfxa4UbeLxj1SWW-BQAAAPA"]
[Thu Jul 30 12:25:53.798162 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:61457] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/upgrade/alfacgiapi/perl.alfa"] [unique_id "amuJIfxa4UbeLxj1SWW-DQAAAKA"]
[Thu Jul 30 12:25:53.862001 2026] [autoindex:error] [pid 738779:tid 738933] [client 20.226.5.174:0] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:25:54.186437 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:61471] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/upgrade/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJIvxa4UbeLxj1SWW-FAAAAOQ"]
[Thu Jul 30 12:25:54.281937 2026] [autoindex:error] [pid 738779:tid 738965] [client 20.226.5.174:0] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:25:54.331855 2026] [security2:error] [pid 738779:tid 738967] [client 38.190.144.4:64897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJIvxa4UbeLxj1SWW-GwAAAL8"]
[Thu Jul 30 12:25:54.333270 2026] [security2:error] [pid 738779:tid 738967] [client 38.190.144.4:64897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJIvxa4UbeLxj1SWW-GwAAAL8"]
[Thu Jul 30 12:25:54.579429 2026] [security2:error] [pid 738779:tid 738957] [client 142.93.53.183:61482] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/updraft/alfacgiapi/perl.alfa"] [unique_id "amuJIvxa4UbeLxj1SWW-HwAAALU"]
[Thu Jul 30 12:25:54.957431 2026] [security2:error] [pid 738779:tid 738950] [client 142.93.53.183:61495] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/updraft/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJIvxa4UbeLxj1SWW-JwAAAK4"]
[Thu Jul 30 12:25:55.239948 2026] [security2:error] [pid 738779:tid 738920] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJIvxa4UbeLxj1SWW-IgAAAJA"]
[Thu Jul 30 12:25:55.344778 2026] [security2:error] [pid 738779:tid 738980] [client 142.93.53.183:61503] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/plugins/library/alfacgiapi/perl.alfa"] [unique_id "amuJI_xa4UbeLxj1SWW-LgAAAMw"]
[Thu Jul 30 12:25:55.735593 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:61512] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/js/plugins/library/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJI_xa4UbeLxj1SWW-NwAAAMM"]
[Thu Jul 30 12:25:55.854929 2026] [security2:error] [pid 738779:tid 739020] [client 20.226.5.174:4120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/query-standard-post.php"] [unique_id "amuJI_xa4UbeLxj1SWW-OwAAAPQ"]
[Thu Jul 30 12:25:56.003012 2026] [security2:error] [pid 738779:tid 739025] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJI_xa4UbeLxj1SWW-MQAAAPk"]
[Thu Jul 30 12:25:56.111259 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:61523] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/alfacgiapi/perl.alfa"] [unique_id "amuJJPxa4UbeLxj1SWW-PwAAAM8"]
[Thu Jul 30 12:25:56.501126 2026] [security2:error] [pid 738779:tid 739014] [client 142.93.53.183:61530] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJPxa4UbeLxj1SWW-SAAAAO4"]
[Thu Jul 30 12:25:56.891359 2026] [security2:error] [pid 738779:tid 738979] [client 142.93.53.183:61537] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/uploads/alfacgiapi/perl.alfa"] [unique_id "amuJJPxa4UbeLxj1SWW-VAAAAMs"]
[Thu Jul 30 12:25:57.111078 2026] [security2:error] [pid 738779:tid 738913] [client 50.6.43.217:57590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuJJfxa4UbeLxj1SWW-VgAAAIk"]
[Thu Jul 30 12:25:57.121661 2026] [security2:error] [pid 738779:tid 739028] [client 50.6.43.217:57596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuJJfxa4UbeLxj1SWW-VwAAAPw"]
[Thu Jul 30 12:25:57.131698 2026] [security2:error] [pid 738779:tid 738967] [client 50.6.43.217:57606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuJJfxa4UbeLxj1SWW-WAAAAL8"]
[Thu Jul 30 12:25:57.268664 2026] [security2:error] [pid 738779:tid 738991] [client 52.238.199.152:51376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/gmo.php"] [unique_id "amuJJfxa4UbeLxj1SWW-XAAAANc"]
[Thu Jul 30 12:25:57.279949 2026] [security2:error] [pid 738779:tid 738972] [client 142.93.53.183:61548] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/uploads/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJfxa4UbeLxj1SWW-XQAAAMQ"]
[Thu Jul 30 12:25:57.673068 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:61553] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/plugins/alfacgiapi/perl.alfa"] [unique_id "amuJJfxa4UbeLxj1SWW-YwAAANU"]
[Thu Jul 30 12:25:58.065103 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:61560] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJvxa4UbeLxj1SWW-agAAALs"]
[Thu Jul 30 12:25:58.427589 2026] [security2:error] [pid 738779:tid 738921] [client 20.226.5.174:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/images/include.php"] [unique_id "amuJJvxa4UbeLxj1SWW-cAAAAJE"]
[Thu Jul 30 12:25:58.454646 2026] [security2:error] [pid 738779:tid 738929] [client 142.93.53.183:61567] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/themes/alfacgiapi/perl.alfa"] [unique_id "amuJJvxa4UbeLxj1SWW-cQAAAJk"]
[Thu Jul 30 12:25:58.511930 2026] [security2:error] [pid 738779:tid 738927] [client 111.113.88.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJJvxa4UbeLxj1SWW-awAAAJc"]
[Thu Jul 30 12:25:58.670860 2026] [security2:error] [pid 738779:tid 738946] [client 52.238.199.152:51359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/nakrip.php"] [unique_id "amuJJvxa4UbeLxj1SWW-dgAAAKo"]
[Thu Jul 30 12:25:58.769714 2026] [core:notice] [pid 738779:tid 738925] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:25:58.846491 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:61570] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/themes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJvxa4UbeLxj1SWW-ewAAAMU"]
[Thu Jul 30 12:25:59.232899 2026] [security2:error] [pid 738779:tid 738948] [client 142.93.53.183:61579] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/upgrade/alfacgiapi/perl.alfa"] [unique_id "amuJJ_xa4UbeLxj1SWW-gAAAAKw"]
[Thu Jul 30 12:25:59.240115 2026] [proxy:error] [pid 738779:tid 738976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:59.240167 2026] [proxy_http:error] [pid 738779:tid 738976] [client 185.247.137.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:2052
[Thu Jul 30 12:25:59.240733 2026] [proxy:error] [pid 738779:tid 738976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:25:59.240775 2026] [proxy_http:error] [pid 738779:tid 738976] [client 185.247.137.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:2052
[Thu Jul 30 12:25:59.265535 2026] [security2:error] [pid 738779:tid 738958] [client 20.52.54.143:10191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/admin.php"] [unique_id "amuJJ_xa4UbeLxj1SWW-ggAAALY"]
[Thu Jul 30 12:25:59.366761 2026] [security2:error] [pid 738779:tid 738953] [client 20.226.5.174:4124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/--wp-lgj.php"] [unique_id "amuJJ_xa4UbeLxj1SWW-hgAAALE"]
[Thu Jul 30 12:25:59.626095 2026] [security2:error] [pid 738779:tid 738941] [client 142.93.53.183:61582] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/upgrade/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJJ_xa4UbeLxj1SWW-iwAAAKU"]
[Thu Jul 30 12:25:59.802069 2026] [security2:error] [pid 738779:tid 738933] [client 52.238.199.152:18238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/radio.php"] [unique_id "amuJJ_xa4UbeLxj1SWW-jwAAAJ0"]
[Thu Jul 30 12:26:00.016808 2026] [security2:error] [pid 738779:tid 738918] [client 142.93.53.183:61587] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/updraft/alfacgiapi/perl.alfa"] [unique_id "amuJKPxa4UbeLxj1SWW-kAAAAI4"]
[Thu Jul 30 12:26:00.089890 2026] [security2:error] [pid 738779:tid 739028] [client 20.52.54.143:9965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-configs.php"] [unique_id "amuJKPxa4UbeLxj1SWW-lQAAAPw"]
[Thu Jul 30 12:26:00.149685 2026] [security2:error] [pid 738779:tid 738894] [remote 198.38.94.67:52924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/wp-login.php"] [unique_id "amuJKPxa4UbeLxj1SWW-lgAA_nI"]
[Thu Jul 30 12:26:00.407546 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:61593] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/updraft/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJKPxa4UbeLxj1SWW-mgAAALw"]
[Thu Jul 30 12:26:00.779721 2026] [security2:error] [pid 738779:tid 738924] [client 142.93.53.183:61598] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/plugins/library/alfacgiapi/perl.alfa"] [unique_id "amuJKPxa4UbeLxj1SWW-oAAAAJQ"]
[Thu Jul 30 12:26:01.173058 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:61605] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/assets/css/plugins/library/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJKfxa4UbeLxj1SWW-qAAAAJM"]
[Thu Jul 30 12:26:01.446829 2026] [security2:error] [pid 738779:tid 739005] [client 20.52.54.143:9936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/php.php"] [unique_id "amuJKfxa4UbeLxj1SWW-sgAAAOU"]
[Thu Jul 30 12:26:01.564074 2026] [security2:error] [pid 738779:tid 739000] [client 142.93.53.183:61610] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/alfacgiapi/perl.alfa"] [unique_id "amuJKfxa4UbeLxj1SWW-tgAAAOA"]
[Thu Jul 30 12:26:01.916776 2026] [security2:error] [pid 738779:tid 739020] [client 20.226.5.174:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-p.php"] [unique_id "amuJKfxa4UbeLxj1SWW-vgAAAPQ"]
[Thu Jul 30 12:26:01.954535 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:61614] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/acme-challenge/alfacgiapi/perl.alfa"] [unique_id "amuJKfxa4UbeLxj1SWW-vwAAAKA"]
[Thu Jul 30 12:26:02.172615 2026] [security2:error] [pid 738779:tid 738987] [client 52.238.199.152:51339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-singin.php"] [unique_id "amuJKvxa4UbeLxj1SWW-xAAAANM"]
[Thu Jul 30 12:26:02.344995 2026] [security2:error] [pid 738779:tid 738974] [client 142.93.53.183:61616] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.well-known/pki-validation/alfacgiapi/perl.alfa"] [unique_id "amuJKvxa4UbeLxj1SWW-xQAAAMY"]
[Thu Jul 30 12:26:02.735644 2026] [security2:error] [pid 738779:tid 739002] [client 142.93.53.183:61620] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.tmb/alfacgiapi/perl.alfa"] [unique_id "amuJKvxa4UbeLxj1SWW-zAAAAOI"]
[Thu Jul 30 12:26:02.946154 2026] [security2:error] [pid 738779:tid 739028] [client 74.7.244.42:33686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bitcoinfungibletoken.com"] [uri "/robots.txt"] [unique_id "amuJKvxa4UbeLxj1SWW-0gAA_H8"]
[Thu Jul 30 12:26:03.116463 2026] [security2:error] [pid 738779:tid 738980] [client 142.93.53.183:61623] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.quarantine/alfacgiapi/perl.alfa"] [unique_id "amuJK_xa4UbeLxj1SWW-2gAAAMw"]
[Thu Jul 30 12:26:03.497494 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:61625] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/.quarantine/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJK_xa4UbeLxj1SWW-6AAAAOE"]
[Thu Jul 30 12:26:03.722897 2026] [security2:error] [pid 738779:tid 738917] [client 20.226.5.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJK_xa4UbeLxj1SWW-3QAAAI0"]
[Thu Jul 30 12:26:03.819517 2026] [core:notice] [pid 738779:tid 738796] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:03.876039 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:61630] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cgi-bin/alfacgiapi/perl.alfa"] [unique_id "amuJK_xa4UbeLxj1SWW-8AAAAPA"]
[Thu Jul 30 12:26:04.107910 2026] [security2:error] [pid 738779:tid 738952] [client 20.52.54.143:9945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/index.php"] [unique_id "amuJLPxa4UbeLxj1SWW--AAAALA"]
[Thu Jul 30 12:26:04.266941 2026] [security2:error] [pid 738779:tid 738910] [client 142.93.53.183:61636] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/alfacgiapi/perl.alfa"] [unique_id "amuJLPxa4UbeLxj1SWW--gAAAIY"]
[Thu Jul 30 12:26:04.276828 2026] [security2:error] [pid 738779:tid 739000] [client 43.172.197.47:40546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/10/19/bon-plan-shopping-braderie-kookai-automne-2013-23-au-26-oct/"] [unique_id "amuJLPxa4UbeLxj1SWW-9QAAAOA"]
[Thu Jul 30 12:26:04.326014 2026] [security2:error] [pid 738779:tid 738976] [client 20.226.5.174:4110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-admin/css/colors/ectoplasm/flower.php"] [unique_id "amuJLPxa4UbeLxj1SWW--wAAAMg"]
[Thu Jul 30 12:26:04.658841 2026] [security2:error] [pid 738779:tid 738982] [client 142.93.53.183:61639] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/components/alfacgiapi/perl.alfa"] [unique_id "amuJLPxa4UbeLxj1SWW_AgAAAM4"]
[Thu Jul 30 12:26:04.837205 2026] [security2:error] [pid 738779:tid 739008] [client 52.238.199.152:51330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/as.php"] [unique_id "amuJLPxa4UbeLxj1SWW_BQAAAOg"]
[Thu Jul 30 12:26:04.934040 2026] [security2:error] [pid 738779:tid 738913] [client 20.52.54.143:9950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/a.php"] [unique_id "amuJLPxa4UbeLxj1SWW_CQAAAIk"]
[Thu Jul 30 12:26:05.048351 2026] [security2:error] [pid 738779:tid 738956] [client 142.93.53.183:61643] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/components/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJLfxa4UbeLxj1SWW_DwAAALQ"]
[Thu Jul 30 12:26:05.063996 2026] [core:notice] [pid 738779:tid 738949] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:05.073207 2026] [security2:error] [pid 738779:tid 738949] [client 43.173.174.21:43830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/10/19/bon-plan-shopping-braderie-kookai-automne-2013-23-au-26-oct/"] [unique_id "amuJLfxa4UbeLxj1SWW_EAAAAK0"], referer: https://carnetdeshopping.com/index.php/2013/10/19/bon-plan-shopping-braderie-kookai-automne-2013-23-au-26-oct/
[Thu Jul 30 12:26:05.198230 2026] [security2:error] [pid 738779:tid 738933] [client 38.190.144.4:65387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJLfxa4UbeLxj1SWW_EQAAAJ0"]
[Thu Jul 30 12:26:05.198435 2026] [security2:error] [pid 738779:tid 738933] [client 38.190.144.4:65387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJLfxa4UbeLxj1SWW_EQAAAJ0"]
[Thu Jul 30 12:26:05.273858 2026] [core:notice] [pid 738779:tid 738981] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:05.436443 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:61648] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wordpress/alfacgiapi/perl.alfa"] [unique_id "amuJLfxa4UbeLxj1SWW_FwAAALs"]
[Thu Jul 30 12:26:05.644357 2026] [security2:error] [pid 738779:tid 739013] [client 20.226.5.174:4123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuJLfxa4UbeLxj1SWW_HAAAAO0"]
[Thu Jul 30 12:26:05.827735 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:61651] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp/alfacgiapi/perl.alfa"] [unique_id "amuJLfxa4UbeLxj1SWW_HgAAALI"]
[Thu Jul 30 12:26:06.203909 2026] [security2:error] [pid 738779:tid 739005] [client 50.6.43.217:34162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuJLvxa4UbeLxj1SWW_LQAAAOU"]
[Thu Jul 30 12:26:06.207567 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:61659] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blog/alfacgiapi/perl.alfa"] [unique_id "amuJLvxa4UbeLxj1SWW_LwAAAOM"]
[Thu Jul 30 12:26:06.213139 2026] [security2:error] [pid 738779:tid 739016] [client 50.6.43.217:34168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuJLvxa4UbeLxj1SWW_MAAAAPA"]
[Thu Jul 30 12:26:06.222621 2026] [security2:error] [pid 738779:tid 738973] [client 50.6.43.217:34172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuJLvxa4UbeLxj1SWW_MQAAAMU"]
[Thu Jul 30 12:26:06.477136 2026] [security2:error] [pid 738779:tid 738929] [client 52.238.199.152:18218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/x.php"] [unique_id "amuJLvxa4UbeLxj1SWW_OAAAAJk"]
[Thu Jul 30 12:26:06.594684 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:61663] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/new/alfacgiapi/perl.alfa"] [unique_id "amuJLvxa4UbeLxj1SWW_QgAAAOQ"]
[Thu Jul 30 12:26:06.743183 2026] [proxy:error] [pid 738779:tid 738988] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:06.743257 2026] [proxy_http:error] [pid 738779:tid 738988] [client 20.52.54.143:10177] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:06.743885 2026] [proxy:error] [pid 738779:tid 738988] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:06.743929 2026] [proxy_http:error] [pid 738779:tid 738988] [client 20.52.54.143:10177] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:06.943217 2026] [security2:error] [pid 738779:tid 738925] [client 20.226.5.174:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/autoload_classmap.php"] [unique_id "amuJLvxa4UbeLxj1SWW_SAAAAJU"]
[Thu Jul 30 12:26:06.983847 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:61669] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/new/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJLvxa4UbeLxj1SWW_SgAAAN4"]
[Thu Jul 30 12:26:07.376223 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:61676] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/old/alfacgiapi/perl.alfa"] [unique_id "amuJL_xa4UbeLxj1SWW_TwAAAOc"]
[Thu Jul 30 12:26:07.766967 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:61685] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/old/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJL_xa4UbeLxj1SWW_VwAAAMM"]
[Thu Jul 30 12:26:08.157686 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:61691] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/backup/alfacgiapi/perl.alfa"] [unique_id "amuJMPxa4UbeLxj1SWW_XgAAAI0"]
[Thu Jul 30 12:26:08.233563 2026] [autoindex:error] [pid 738779:tid 739035] [client 20.226.5.174:4100] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:08.531155 2026] [security2:error] [pid 738779:tid 738930] [client 20.226.5.174:4100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/plugins/rxxdfx/xleet.php"] [unique_id "amuJMPxa4UbeLxj1SWW_aAAAAJo"]
[Thu Jul 30 12:26:08.540462 2026] [security2:error] [pid 738779:tid 739010] [client 142.93.53.183:61705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/backup/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMPxa4UbeLxj1SWW_aQAAAOo"]
[Thu Jul 30 12:26:08.677053 2026] [security2:error] [pid 738779:tid 738997] [client 74.7.175.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-26e591d8.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuJMPxa4UbeLxj1SWW_YwAAAN0"]
[Thu Jul 30 12:26:08.677820 2026] [security2:error] [pid 738779:tid 738926] [client 74.7.175.130:52994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-26e591d8.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuJMPxa4UbeLxj1SWW_YQAAlio"]
[Thu Jul 30 12:26:08.916568 2026] [security2:error] [pid 738779:tid 739020] [client 142.93.53.183:61712] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ojs/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMPxa4UbeLxj1SWW_cwAAAPQ"]
[Thu Jul 30 12:26:09.297376 2026] [security2:error] [pid 738779:tid 738925] [client 142.93.53.183:61722] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ojs/alfacgiapi/perl.alfa"] [unique_id "amuJMfxa4UbeLxj1SWW_fwAAAJU"]
[Thu Jul 30 12:26:09.627483 2026] [security2:error] [pid 738779:tid 739019] [client 20.226.5.174:4126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/module.tag.idv1.php"] [unique_id "amuJMfxa4UbeLxj1SWW_iQAAAPM"]
[Thu Jul 30 12:26:09.672343 2026] [security2:error] [pid 738779:tid 738981] [client 142.93.53.183:61730] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/laravel/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMfxa4UbeLxj1SWW_iwAAAM0"]
[Thu Jul 30 12:26:10.062966 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:61739] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/laravel/alfacgiapi/perl.alfa"] [unique_id "amuJMvxa4UbeLxj1SWW_kwAAAOE"]
[Thu Jul 30 12:26:10.451462 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:61744] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/-/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMvxa4UbeLxj1SWW_mAAAAJM"]
[Thu Jul 30 12:26:10.465494 2026] [proxy:error] [pid 738779:tid 738927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:10.465579 2026] [proxy_http:error] [pid 738779:tid 738927] [client 20.52.54.143:9928] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:10.466503 2026] [proxy:error] [pid 738779:tid 738927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:10.466573 2026] [proxy_http:error] [pid 738779:tid 738927] [client 20.52.54.143:9928] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:10.728375 2026] [core:notice] [pid 738779:tid 738844] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:10.844376 2026] [security2:error] [pid 738779:tid 738930] [client 142.93.53.183:61754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/includes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJMvxa4UbeLxj1SWW_oQAAAJo"]
[Thu Jul 30 12:26:11.196137 2026] [security2:error] [pid 738779:tid 739021] [client 20.240.254.167:11824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/71.php"] [unique_id "amuJM_xa4UbeLxj1SWW_qgAAAPU"]
[Thu Jul 30 12:26:11.196276 2026] [security2:error] [pid 738779:tid 739021] [client 20.240.254.167:11824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/71.php"] [unique_id "amuJM_xa4UbeLxj1SWW_qgAAAPU"]
[Thu Jul 30 12:26:11.235335 2026] [security2:error] [pid 738779:tid 738926] [client 142.93.53.183:61758] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/alfacgiapi/perl.alfa"] [unique_id "amuJM_xa4UbeLxj1SWW_qwAAAJY"]
[Thu Jul 30 12:26:11.292763 2026] [security2:error] [pid 738779:tid 738924] [client 50.6.43.217:55350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuJMvxa4UbeLxj1SWW_lwAAAJQ"]
[Thu Jul 30 12:26:11.510396 2026] [security2:error] [pid 738779:tid 738961] [client 20.240.254.167:11528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/72.php"] [unique_id "amuJM_xa4UbeLxj1SWW_sgAAALk"]
[Thu Jul 30 12:26:11.510494 2026] [security2:error] [pid 738779:tid 738961] [client 20.240.254.167:11528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/72.php"] [unique_id "amuJM_xa4UbeLxj1SWW_sgAAALk"]
[Thu Jul 30 12:26:11.611785 2026] [security2:error] [pid 738779:tid 739030] [client 20.226.5.174:4121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/packed.php"] [unique_id "amuJM_xa4UbeLxj1SWW_tAAAAP4"]
[Thu Jul 30 12:26:11.626300 2026] [security2:error] [pid 738779:tid 738929] [client 142.93.53.183:61768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/app/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJM_xa4UbeLxj1SWW_tQAAAJk"]
[Thu Jul 30 12:26:11.735890 2026] [security2:error] [pid 738779:tid 738948] [client 20.52.54.143:9947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuJM_xa4UbeLxj1SWW_uQAAAKw"]
[Thu Jul 30 12:26:11.820613 2026] [security2:error] [pid 738779:tid 739008] [client 20.240.254.167:11835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/70.php"] [unique_id "amuJM_xa4UbeLxj1SWW_vgAAAOg"]
[Thu Jul 30 12:26:11.820703 2026] [security2:error] [pid 738779:tid 739008] [client 20.240.254.167:11835] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/70.php"] [unique_id "amuJM_xa4UbeLxj1SWW_vgAAAOg"]
[Thu Jul 30 12:26:12.013582 2026] [security2:error] [pid 738779:tid 738918] [client 142.93.53.183:61774] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/app/alfacgiapi/perl.alfa"] [unique_id "amuJNPxa4UbeLxj1SWW_vwAAAI4"]
[Thu Jul 30 12:26:12.036110 2026] [security2:error] [pid 738779:tid 738952] [client 50.6.43.217:58904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuJM_xa4UbeLxj1SWW_rwAAALA"]
[Thu Jul 30 12:26:12.149924 2026] [security2:error] [pid 738779:tid 738909] [client 20.240.254.167:11834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/69.php"] [unique_id "amuJNPxa4UbeLxj1SWW_wwAAAIU"]
[Thu Jul 30 12:26:12.150038 2026] [security2:error] [pid 738779:tid 738909] [client 20.240.254.167:11834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/69.php"] [unique_id "amuJNPxa4UbeLxj1SWW_wwAAAIU"]
[Thu Jul 30 12:26:12.348163 2026] [security2:error] [pid 738779:tid 738933] [client 52.238.199.152:51353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/item.php"] [unique_id "amuJNPxa4UbeLxj1SWW_ygAAAJ0"]
[Thu Jul 30 12:26:12.388544 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:61783] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/image/alfacgiapi/perl.alfa"] [unique_id "amuJNPxa4UbeLxj1SWW_ywAAANU"]
[Thu Jul 30 12:26:12.506272 2026] [security2:error] [pid 738779:tid 739015] [client 20.240.254.167:11526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/68.php"] [unique_id "amuJNPxa4UbeLxj1SWW_zAAAAO8"]
[Thu Jul 30 12:26:12.506384 2026] [security2:error] [pid 738779:tid 739015] [client 20.240.254.167:11526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/68.php"] [unique_id "amuJNPxa4UbeLxj1SWW_zAAAAO8"]
[Thu Jul 30 12:26:12.783567 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:61795] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/alfacgiapi/perl.alfa"] [unique_id "amuJNPxa4UbeLxj1SWW_0wAAALI"]
[Thu Jul 30 12:26:12.862225 2026] [security2:error] [pid 738779:tid 738934] [client 20.240.254.167:11832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/66.php"] [unique_id "amuJNPxa4UbeLxj1SWW_1gAAAJ4"]
[Thu Jul 30 12:26:12.862338 2026] [security2:error] [pid 738779:tid 738934] [client 20.240.254.167:11832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/66.php"] [unique_id "amuJNPxa4UbeLxj1SWW_1gAAAJ4"]
[Thu Jul 30 12:26:12.984873 2026] [security2:error] [pid 738779:tid 738920] [client 20.226.5.174:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/css/F0x.php"] [unique_id "amuJNPxa4UbeLxj1SWW_2AAAAJA"]
[Thu Jul 30 12:26:13.172948 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:61804] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJNfxa4UbeLxj1SWW_3QAAAI0"]
[Thu Jul 30 12:26:13.178386 2026] [security2:error] [pid 738779:tid 738985] [client 20.240.254.167:11792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/67.php"] [unique_id "amuJNfxa4UbeLxj1SWW_3gAAANE"]
[Thu Jul 30 12:26:13.178472 2026] [security2:error] [pid 738779:tid 738985] [client 20.240.254.167:11792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/67.php"] [unique_id "amuJNfxa4UbeLxj1SWW_3gAAANE"]
[Thu Jul 30 12:26:13.501295 2026] [security2:error] [pid 738779:tid 739014] [client 20.240.254.167:11800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/65.php"] [unique_id "amuJNfxa4UbeLxj1SWW_5QAAAO4"]
[Thu Jul 30 12:26:13.501389 2026] [security2:error] [pid 738779:tid 739014] [client 20.240.254.167:11800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/65.php"] [unique_id "amuJNfxa4UbeLxj1SWW_5QAAAO4"]
[Thu Jul 30 12:26:13.519381 2026] [security2:error] [pid 738779:tid 738975] [client 52.238.199.152:51337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/app.php"] [unique_id "amuJNfxa4UbeLxj1SWW_5gAAAMc"]
[Thu Jul 30 12:26:13.563383 2026] [security2:error] [pid 738779:tid 738946] [client 142.93.53.183:61817] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/css/alfacgiapi/perl.alfa"] [unique_id "amuJNfxa4UbeLxj1SWW_6AAAAKo"]
[Thu Jul 30 12:26:13.835217 2026] [security2:error] [pid 738779:tid 738976] [client 20.240.254.167:11777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/64.php"] [unique_id "amuJNfxa4UbeLxj1SWW_7AAAAMg"]
[Thu Jul 30 12:26:13.835319 2026] [security2:error] [pid 738779:tid 738976] [client 20.240.254.167:11777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/64.php"] [unique_id "amuJNfxa4UbeLxj1SWW_7AAAAMg"]
[Thu Jul 30 12:26:13.953893 2026] [security2:error] [pid 738779:tid 738953] [client 142.93.53.183:61828] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/media/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJNfxa4UbeLxj1SWW_7wAAALE"]
[Thu Jul 30 12:26:14.153610 2026] [security2:error] [pid 738779:tid 739021] [client 20.226.5.174:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/view.php"] [unique_id "amuJNvxa4UbeLxj1SWW_8QAAAPU"]
[Thu Jul 30 12:26:14.196094 2026] [security2:error] [pid 738779:tid 738988] [client 20.240.254.167:11789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/63.php"] [unique_id "amuJNvxa4UbeLxj1SWW_8gAAANQ"]
[Thu Jul 30 12:26:14.196190 2026] [security2:error] [pid 738779:tid 738988] [client 20.240.254.167:11789] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/63.php"] [unique_id "amuJNvxa4UbeLxj1SWW_8gAAANQ"]
[Thu Jul 30 12:26:14.231380 2026] [core:notice] [pid 738779:tid 738854] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:14.326028 2026] [security2:error] [pid 738779:tid 738948] [client 52.238.199.152:18239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/k.php"] [unique_id "amuJNvxa4UbeLxj1SWW_-AAAAKw"]
[Thu Jul 30 12:26:14.344249 2026] [security2:error] [pid 738779:tid 739005] [client 142.93.53.183:61844] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/asset/media/alfacgiapi/perl.alfa"] [unique_id "amuJNvxa4UbeLxj1SWW_-QAAAOU"]
[Thu Jul 30 12:26:14.462905 2026] [core:notice] [pid 738779:tid 738877] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:14.556217 2026] [security2:error] [pid 738779:tid 739012] [client 20.240.254.167:11828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/62.php"] [unique_id "amuJNvxa4UbeLxj1SWW__wAAAOw"]
[Thu Jul 30 12:26:14.556327 2026] [security2:error] [pid 738779:tid 739012] [client 20.240.254.167:11828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/62.php"] [unique_id "amuJNvxa4UbeLxj1SWW__wAAAOw"]
[Thu Jul 30 12:26:14.735397 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:61858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/js/alfacgiapi/perl.alfa"] [unique_id "amuJNvxa4UbeLxj1SWXAAAAAAO8"]
[Thu Jul 30 12:26:14.879186 2026] [security2:error] [pid 738779:tid 739029] [client 74.7.230.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.airevoduct.ltd"] [uri "/index.php"] [unique_id "amuJNvxa4UbeLxj1SWW__gAA_V4"]
[Thu Jul 30 12:26:14.879234 2026] [security2:error] [pid 738779:tid 739029] [client 74.7.230.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.airevoduct.ltd"] [uri "/index.php"] [unique_id "amuJNvxa4UbeLxj1SWW__gAA_V4"]
[Thu Jul 30 12:26:14.955816 2026] [security2:error] [pid 738779:tid 739001] [client 20.240.254.167:11782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/61.php"] [unique_id "amuJNvxa4UbeLxj1SWXABAAAAOE"]
[Thu Jul 30 12:26:14.955938 2026] [security2:error] [pid 738779:tid 739001] [client 20.240.254.167:11782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/61.php"] [unique_id "amuJNvxa4UbeLxj1SWXABAAAAOE"]
[Thu Jul 30 12:26:15.126110 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:61870] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/alfacgiapi/perl.alfa"] [unique_id "amuJN_xa4UbeLxj1SWXACAAAANk"]
[Thu Jul 30 12:26:15.200087 2026] [security2:error] [pid 738779:tid 738989] [client 38.190.144.4:40789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJN_xa4UbeLxj1SWXACQAAANU"]
[Thu Jul 30 12:26:15.200216 2026] [security2:error] [pid 738779:tid 738989] [client 38.190.144.4:40789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJN_xa4UbeLxj1SWXACQAAANU"]
[Thu Jul 30 12:26:15.285996 2026] [security2:error] [pid 738779:tid 739033] [client 52.238.199.152:51349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-fmfile.php"] [unique_id "amuJN_xa4UbeLxj1SWXACwAAAQE"]
[Thu Jul 30 12:26:15.307270 2026] [security2:error] [pid 738779:tid 738917] [client 20.240.254.167:11793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.254.240.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/60.php"] [unique_id "amuJN_xa4UbeLxj1SWXADAAAAI0"]
[Thu Jul 30 12:26:15.307363 2026] [security2:error] [pid 738779:tid 738917] [client 20.240.254.167:11793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.emmanueljrodriguez.com"] [uri "/60.php"] [unique_id "amuJN_xa4UbeLxj1SWXADAAAAI0"]
[Thu Jul 30 12:26:15.328924 2026] [security2:error] [pid 738779:tid 738928] [client 20.226.5.174:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/blocks/site-title/index.php"] [unique_id "amuJN_xa4UbeLxj1SWXADQAAAJg"]
[Thu Jul 30 12:26:15.506618 2026] [security2:error] [pid 738779:tid 738945] [client 20.52.54.143:10182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin.php"] [unique_id "amuJN_xa4UbeLxj1SWXAFAAAAKk"]
[Thu Jul 30 12:26:15.516613 2026] [security2:error] [pid 738779:tid 738930] [client 142.93.53.183:61878] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/images/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJN_xa4UbeLxj1SWXAFQAAAJo"]
[Thu Jul 30 12:26:15.819566 2026] [security2:error] [pid 738779:tid 738919] [client 158.158.76.106:25279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJN_xa4UbeLxj1SWXAGQAAAI8"]
[Thu Jul 30 12:26:15.819683 2026] [security2:error] [pid 738779:tid 738919] [client 158.158.76.106:25279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJN_xa4UbeLxj1SWXAGQAAAI8"]
[Thu Jul 30 12:26:15.907186 2026] [security2:error] [pid 738779:tid 738926] [client 142.93.53.183:61887] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/images/alfacgiapi/perl.alfa"] [unique_id "amuJN_xa4UbeLxj1SWXAGgAAAJY"]
[Thu Jul 30 12:26:16.049036 2026] [security2:error] [pid 738779:tid 738959] [client 74.7.230.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "airevoduct.ltd"] [uri "/index.php"] [unique_id "amuJN_xa4UbeLxj1SWXAGAAAt2A"], referer: https://www.airevoduct.ltd/robots.txt
[Thu Jul 30 12:26:16.064547 2026] [autoindex:error] [pid 738779:tid 738958] [client 139.28.219.70:48380] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:16.206567 2026] [autoindex:error] [pid 738779:tid 738961] [client 139.28.219.70:48380] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:16.297862 2026] [security2:error] [pid 738779:tid 738953] [client 142.93.53.183:61899] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/themes/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJOPxa4UbeLxj1SWXAIwAAALE"]
[Thu Jul 30 12:26:16.344623 2026] [security2:error] [pid 738779:tid 739006] [client 139.28.219.70:48380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuJOPxa4UbeLxj1SWXAJAAAAOY"]
[Thu Jul 30 12:26:16.617262 2026] [core:notice] [pid 738779:tid 739030] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:16.656135 2026] [security2:error] [pid 738779:tid 738918] [client 139.28.219.70:48384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spadealist.com"] [uri "/xmlrpc.php"] [unique_id "amuJOPxa4UbeLxj1SWXALAAAAI4"]
[Thu Jul 30 12:26:16.687996 2026] [security2:error] [pid 738779:tid 738972] [client 142.93.53.183:61908] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/css/themes/alfacgiapi/perl.alfa"] [unique_id "amuJOPxa4UbeLxj1SWXALQAAAMQ"]
[Thu Jul 30 12:26:16.826666 2026] [security2:error] [pid 738779:tid 738943] [client 158.158.76.106:4278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJOPxa4UbeLxj1SWXALgAAAKc"]
[Thu Jul 30 12:26:16.826775 2026] [security2:error] [pid 738779:tid 738943] [client 158.158.76.106:4278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJOPxa4UbeLxj1SWXALgAAAKc"]
[Thu Jul 30 12:26:16.861649 2026] [core:notice] [pid 738779:tid 739025] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:16.986791 2026] [autoindex:error] [pid 738779:tid 739036] [client 139.28.219.70:48396] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:17.067928 2026] [security2:error] [pid 738779:tid 738980] [client 142.93.53.183:61919] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/administrator/alfacgiapi/perl.alfa"] [unique_id "amuJOfxa4UbeLxj1SWXANwAAAMw"]
[Thu Jul 30 12:26:17.146365 2026] [security2:error] [pid 738779:tid 738955] [client 139.28.219.70:48396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuJOfxa4UbeLxj1SWXAPQAAALM"]
[Thu Jul 30 12:26:17.436940 2026] [security2:error] [pid 738779:tid 739004] [client 52.238.199.152:18206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wi.php"] [unique_id "amuJOfxa4UbeLxj1SWXAQgAAAOQ"]
[Thu Jul 30 12:26:17.451461 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:61928] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/ALFA_DATA/perl.alfa"] [unique_id "amuJOfxa4UbeLxj1SWXAQwAAAJM"]
[Thu Jul 30 12:26:17.468756 2026] [security2:error] [pid 738779:tid 739008] [client 139.28.219.70:48404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuJOfxa4UbeLxj1SWXARAAAAOg"]
[Thu Jul 30 12:26:17.492403 2026] [security2:error] [pid 738779:tid 738890] [remote 216.73.216.152:25997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuJOfxa4UbeLxj1SWXASAAAwW4"]
[Thu Jul 30 12:26:17.589655 2026] [security2:error] [pid 738779:tid 739005] [client 20.52.54.143:9971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/size.php"] [unique_id "amuJOfxa4UbeLxj1SWXASQAAAOU"]
[Thu Jul 30 12:26:17.735294 2026] [security2:error] [pid 738779:tid 738966] [client 139.28.219.70:48408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuJOfxa4UbeLxj1SWXATQAAAL4"]
[Thu Jul 30 12:26:17.742813 2026] [security2:error] [pid 738779:tid 738888] [remote 57.141.0.65:26454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/56555984686/feed/rss2/"] [unique_id "amuJOfxa4UbeLxj1SWXATgAAkGw"]
[Thu Jul 30 12:26:17.842429 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:61936] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/alfacgiapi/alfacgiapi/perl.alfa"] [unique_id "amuJOfxa4UbeLxj1SWXATwAAAPg"]
[Thu Jul 30 12:26:17.952217 2026] [security2:error] [pid 738779:tid 738951] [client 74.7.244.37:45720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amuJN_xa4UbeLxj1SWXAFgAAr2I"]
[Thu Jul 30 12:26:17.996166 2026] [security2:error] [pid 738779:tid 739011] [client 139.28.219.70:48416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuJOfxa4UbeLxj1SWXAUAAAAOs"]
[Thu Jul 30 12:26:18.233691 2026] [security2:error] [pid 738779:tid 738959] [client 142.93.53.183:61945] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJOvxa4UbeLxj1SWXAVwAAALc"]
[Thu Jul 30 12:26:18.256955 2026] [security2:error] [pid 738779:tid 738958] [client 139.28.219.70:48430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuJOvxa4UbeLxj1SWXAWAAAALY"]
[Thu Jul 30 12:26:18.316732 2026] [security2:error] [pid 738779:tid 739023] [client 85.208.96.208:48314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/09/analise-selecao-brasileira-nao-entendeu-o-jogo-e-fez-tudo-o-que-a-croacia-quis/"] [unique_id "amuJOvxa4UbeLxj1SWXAWQAAAPc"]
[Thu Jul 30 12:26:18.316893 2026] [security2:error] [pid 738779:tid 739023] [client 85.208.96.208:48314] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/09/analise-selecao-brasileira-nao-entendeu-o-jogo-e-fez-tudo-o-que-a-croacia-quis/"] [unique_id "amuJOvxa4UbeLxj1SWXAWQAAAPc"]
[Thu Jul 30 12:26:18.527558 2026] [security2:error] [pid 738779:tid 738961] [client 139.28.219.70:48446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuJOvxa4UbeLxj1SWXAWwAAALk"]
[Thu Jul 30 12:26:18.618252 2026] [security2:error] [pid 738779:tid 738996] [client 142.93.53.183:61956] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/alfacgiapi/perl.alfa"] [unique_id "amuJOvxa4UbeLxj1SWXAYQAAANw"]
[Thu Jul 30 12:26:18.703939 2026] [security2:error] [pid 738779:tid 739014] [client 20.52.54.143:9977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuJOvxa4UbeLxj1SWXAYwAAAO4"]
[Thu Jul 30 12:26:18.809017 2026] [security2:error] [pid 738779:tid 738916] [client 139.28.219.70:48460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuJOvxa4UbeLxj1SWXAZAAAAIw"]
[Thu Jul 30 12:26:19.011897 2026] [security2:error] [pid 738779:tid 739030] [client 142.93.53.183:61968] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpspec/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJO_xa4UbeLxj1SWXAZgAAAP4"]
[Thu Jul 30 12:26:19.064492 2026] [security2:error] [pid 738779:tid 738972] [client 139.28.219.70:48466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuJO_xa4UbeLxj1SWXAagAAAMQ"]
[Thu Jul 30 12:26:19.310364 2026] [security2:error] [pid 738779:tid 738999] [client 20.52.54.143:9381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/403.php"] [unique_id "amuJO_xa4UbeLxj1SWXAbwAAAN8"]
[Thu Jul 30 12:26:19.320604 2026] [security2:error] [pid 738779:tid 738942] [client 139.28.219.70:48478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuJO_xa4UbeLxj1SWXAcAAAAKY"]
[Thu Jul 30 12:26:19.401788 2026] [security2:error] [pid 738779:tid 738978] [client 142.93.53.183:61977] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpspec/alfacgiapi/perl.alfa"] [unique_id "amuJO_xa4UbeLxj1SWXAcQAAAMo"]
[Thu Jul 30 12:26:19.519007 2026] [security2:error] [pid 738779:tid 738994] [client 158.158.76.106:40099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-login.php"] [unique_id "amuJO_xa4UbeLxj1SWXAbgAAANo"]
[Thu Jul 30 12:26:19.519269 2026] [security2:error] [pid 738779:tid 738994] [client 158.158.76.106:40099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/wp-login.php"] [unique_id "amuJO_xa4UbeLxj1SWXAbgAAANo"]
[Thu Jul 30 12:26:19.595754 2026] [security2:error] [pid 738779:tid 739028] [client 139.28.219.70:48480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuJO_xa4UbeLxj1SWXAdAAAAPw"]
[Thu Jul 30 12:26:19.793137 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:61990] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/mpdf/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJO_xa4UbeLxj1SWXAegAAAOE"]
[Thu Jul 30 12:26:19.872218 2026] [security2:error] [pid 738779:tid 738971] [client 139.28.219.70:48494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuJO_xa4UbeLxj1SWXAewAAAMM"]
[Thu Jul 30 12:26:20.132125 2026] [security2:error] [pid 738779:tid 739004] [client 37.120.155.179:33478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJPPxa4UbeLxj1SWXAfAAAAOQ"]
[Thu Jul 30 12:26:20.132228 2026] [security2:error] [pid 738779:tid 739004] [client 37.120.155.179:33478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJPPxa4UbeLxj1SWXAfAAAAOQ"]
[Thu Jul 30 12:26:20.136871 2026] [security2:error] [pid 738779:tid 738964] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJO_xa4UbeLxj1SWXAcgAAvAU"]
[Thu Jul 30 12:26:20.141296 2026] [security2:error] [pid 738779:tid 738969] [client 139.28.219.70:48496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "spadealist.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuJPPxa4UbeLxj1SWXAfwAAAME"]
[Thu Jul 30 12:26:20.183171 2026] [security2:error] [pid 738779:tid 738927] [client 142.93.53.183:62001] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/mpdf/alfacgiapi/perl.alfa"] [unique_id "amuJPPxa4UbeLxj1SWXAgQAAAJc"]
[Thu Jul 30 12:26:20.231512 2026] [security2:error] [pid 738779:tid 739013] [client 20.52.54.143:10179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuJPPxa4UbeLxj1SWXAhQAAAO0"]
[Thu Jul 30 12:26:20.573904 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:62010] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2022/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJPPxa4UbeLxj1SWXAigAAAPg"]
[Thu Jul 30 12:26:20.633263 2026] [security2:error] [pid 738779:tid 739026] [client 52.238.199.152:38855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/php8.php"] [unique_id "amuJPPxa4UbeLxj1SWXAiwAAAPo"]
[Thu Jul 30 12:26:20.912709 2026] [core:notice] [pid 738779:tid 739005] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:20.965117 2026] [security2:error] [pid 738779:tid 738924] [client 142.93.53.183:62019] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2022/alfacgiapi/perl.alfa"] [unique_id "amuJPPxa4UbeLxj1SWXAlgAAAJQ"]
[Thu Jul 30 12:26:21.039163 2026] [security2:error] [pid 738779:tid 738975] [client 20.52.54.143:9980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/as.php"] [unique_id "amuJPfxa4UbeLxj1SWXAlwAAAMc"]
[Thu Jul 30 12:26:21.355243 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:62030] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2023/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJPfxa4UbeLxj1SWXAnwAAAJE"]
[Thu Jul 30 12:26:21.745739 2026] [security2:error] [pid 738779:tid 738925] [client 142.93.53.183:62044] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2023/alfacgiapi/perl.alfa"] [unique_id "amuJPfxa4UbeLxj1SWXApAAAAJU"]
[Thu Jul 30 12:26:21.994334 2026] [security2:error] [pid 738779:tid 739021] [client 20.52.54.143:9952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuJPfxa4UbeLxj1SWXAqAAAAPU"]
[Thu Jul 30 12:26:22.038388 2026] [security2:error] [pid 738779:tid 738957] [client 52.238.199.152:18199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/tes.php"] [unique_id "amuJPvxa4UbeLxj1SWXAqwAAALU"]
[Thu Jul 30 12:26:22.133941 2026] [security2:error] [pid 738779:tid 738956] [client 142.93.53.183:62051] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/build/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJPvxa4UbeLxj1SWXArQAAALQ"]
[Thu Jul 30 12:26:22.512818 2026] [security2:error] [pid 738779:tid 738944] [client 142.93.53.183:62063] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/build/assets/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJPvxa4UbeLxj1SWXAuAAAAKg"]
[Thu Jul 30 12:26:22.658008 2026] [security2:error] [pid 738779:tid 738931] [client 158.158.76.106:40124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/red.php"] [unique_id "amuJPvxa4UbeLxj1SWXAuQAAAJs"]
[Thu Jul 30 12:26:22.658126 2026] [security2:error] [pid 738779:tid 738931] [client 158.158.76.106:40124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/red.php"] [unique_id "amuJPvxa4UbeLxj1SWXAuQAAAJs"]
[Thu Jul 30 12:26:22.902253 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:62070] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/build/assets/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJPvxa4UbeLxj1SWXAwAAAANY"]
[Thu Jul 30 12:26:23.291198 2026] [security2:error] [pid 738779:tid 738977] [client 142.93.53.183:62084] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/KITABISACOM1337/kitabisacom1337api/perl.haxor"] [unique_id "amuJP_xa4UbeLxj1SWXAxQAAAMk"]
[Thu Jul 30 12:26:23.684688 2026] [security2:error] [pid 738779:tid 738993] [client 142.93.53.183:62091] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/KITABISACOM1337/kitabisacom1337api/py.haxor"] [unique_id "amuJP_xa4UbeLxj1SWXAygAAANk"]
[Thu Jul 30 12:26:23.701805 2026] [security2:error] [pid 738779:tid 738920] [client 20.52.54.143:9932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuJP_xa4UbeLxj1SWXAywAAAJA"]
[Thu Jul 30 12:26:24.073908 2026] [security2:error] [pid 738779:tid 738968] [client 142.93.53.183:62101] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/KITABISACOM1337/kitabisacom1337api/bash.haxor"] [unique_id "amuJQPxa4UbeLxj1SWXA1AAAAMA"]
[Thu Jul 30 12:26:24.197136 2026] [core:error] [pid 738779:tid 738937] [client 74.7.228.43:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:24.197171 2026] [core:error] [pid 738779:tid 738937] [client 74.7.228.43:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:24.197309 2026] [security2:error] [pid 738779:tid 738937] [client 74.7.228.43:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.fnm.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuJQPxa4UbeLxj1SWXA1wAAAKE"]
[Thu Jul 30 12:26:24.197840 2026] [security2:error] [pid 738779:tid 738997] [client 74.7.228.43:49164] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.fnm.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuJQPxa4UbeLxj1SWXA1QAA3Rg"]
[Thu Jul 30 12:26:24.219061 2026] [security2:error] [pid 738779:tid 739018] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJP_xa4UbeLxj1SWXAyQAA8gQ"]
[Thu Jul 30 12:26:24.462198 2026] [security2:error] [pid 738779:tid 739027] [client 142.93.53.183:62112] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/storage/files/shares/KITABISACOM1337/kitabisacom1337api/perl.haxor"] [unique_id "amuJQPxa4UbeLxj1SWXA2wAAAPs"]
[Thu Jul 30 12:26:24.482050 2026] [security2:error] [pid 738779:tid 739009] [client 20.52.54.143:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/plugins.php"] [unique_id "amuJQPxa4UbeLxj1SWXA3AAAAOk"]
[Thu Jul 30 12:26:24.579259 2026] [security2:error] [pid 738779:tid 738961] [client 46.232.235.5:41006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.greensparkle.net"] [uri "/.env"] [unique_id "amuJQPxa4UbeLxj1SWXA4AAAALk"]
[Thu Jul 30 12:26:24.853562 2026] [security2:error] [pid 738779:tid 738984] [client 142.93.53.183:62122] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/storage/files/shares/KITABISACOM1337/kitabisacom1337api/py.haxor"] [unique_id "amuJQPxa4UbeLxj1SWXA5AAAANA"]
[Thu Jul 30 12:26:25.246021 2026] [security2:error] [pid 738779:tid 739021] [client 142.93.53.183:62131] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/storage/files/shares/KITABISACOM1337/kitabisacom1337api/bash.haxor"] [unique_id "amuJQfxa4UbeLxj1SWXA6gAAAPU"]
[Thu Jul 30 12:26:25.572218 2026] [security2:error] [pid 738779:tid 738988] [client 20.52.54.143:9955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuJQfxa4UbeLxj1SWXA9wAAANQ"]
[Thu Jul 30 12:26:25.633752 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:62139] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SUPERBONE/perl.alfa"] [unique_id "amuJQfxa4UbeLxj1SWXA-QAAANc"]
[Thu Jul 30 12:26:25.669714 2026] [authz_core:error] [pid 738779:tid 738995] [client 46.232.235.5:41032] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:25.689171 2026] [authz_core:error] [pid 738779:tid 739015] [client 46.232.235.5:41044] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:25.999194 2026] [authz_core:error] [pid 738779:tid 738949] [client 46.232.235.5:41058] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:26.009866 2026] [security2:error] [pid 738779:tid 738927] [client 142.93.53.183:62152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SUPERBONE/py.alfa"] [unique_id "amuJQvxa4UbeLxj1SWXBBAAAAJc"]
[Thu Jul 30 12:26:26.026645 2026] [authz_core:error] [pid 738779:tid 738964] [client 46.232.235.5:41072] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:26.295153 2026] [security2:error] [pid 738779:tid 738977] [client 20.52.54.143:9960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/go.php"] [unique_id "amuJQvxa4UbeLxj1SWXBBgAAAMk"]
[Thu Jul 30 12:26:26.388007 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:62161] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SUPERBONE/bash.alfa"] [unique_id "amuJQvxa4UbeLxj1SWXBBwAAAI0"]
[Thu Jul 30 12:26:26.477550 2026] [security2:error] [pid 738779:tid 738989] [client 38.190.144.4:50003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJQvxa4UbeLxj1SWXBCwAAANU"]
[Thu Jul 30 12:26:26.477660 2026] [security2:error] [pid 738779:tid 738989] [client 38.190.144.4:50003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJQvxa4UbeLxj1SWXBCwAAANU"]
[Thu Jul 30 12:26:26.777144 2026] [security2:error] [pid 738779:tid 738946] [client 142.93.53.183:62171] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Mr-G4cor/haxorcgiapi/perl.haxor"] [unique_id "amuJQvxa4UbeLxj1SWXBEQAAAKo"]
[Thu Jul 30 12:26:26.982342 2026] [authz_core:error] [pid 738779:tid 738992] [client 46.232.235.5:41076] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:27.058509 2026] [authz_core:error] [pid 738779:tid 739003] [client 46.232.235.5:41082] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:27.168038 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:62180] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Mr-G4cor/haxorcgiapi/py.haxor"] [unique_id "amuJQ_xa4UbeLxj1SWXBHQAAAKk"]
[Thu Jul 30 12:26:27.319158 2026] [security2:error] [pid 738779:tid 738970] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJQvxa4UbeLxj1SWXBEAAAwiI"]
[Thu Jul 30 12:26:27.490133 2026] [security2:error] [pid 738779:tid 739009] [client 20.52.54.143:10187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/test1.php"] [unique_id "amuJQ_xa4UbeLxj1SWXBIwAAAOk"]
[Thu Jul 30 12:26:27.558478 2026] [security2:error] [pid 738779:tid 738987] [client 142.93.53.183:62190] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/AZZ_DATA/hackermancgiapi/perl.hackerman"] [unique_id "amuJQ_xa4UbeLxj1SWXBJwAAANM"]
[Thu Jul 30 12:26:27.937070 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:62200] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/AZZ_DATA/hackermancgiapi/bash.hackerman"] [unique_id "amuJQ_xa4UbeLxj1SWXBLgAAANc"]
[Thu Jul 30 12:26:28.324088 2026] [security2:error] [pid 738779:tid 738969] [client 142.93.53.183:62208] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/D0R4H4X0R/haxorcgiapi/perl.haxor"] [unique_id "amuJRPxa4UbeLxj1SWXBOgAAAME"]
[Thu Jul 30 12:26:28.401663 2026] [security2:error] [pid 738779:tid 738916] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJQ_xa4UbeLxj1SWXBLQAAAIw"]
[Thu Jul 30 12:26:28.697716 2026] [security2:error] [pid 738779:tid 738919] [client 142.93.53.183:62215] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/D0R4H4X0R/haxorcgiapi/bash.haxor"] [unique_id "amuJRPxa4UbeLxj1SWXBRgAAAI8"]
[Thu Jul 30 12:26:29.087193 2026] [security2:error] [pid 738779:tid 738997] [client 142.93.53.183:62222] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/Mr-G4cor/haxorcgiapi/bash.haxor"] [unique_id "amuJRfxa4UbeLxj1SWXBSgAAAN0"]
[Thu Jul 30 12:26:29.394399 2026] [security2:error] [pid 738779:tid 738920] [client 52.238.199.152:38880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/about.php"] [unique_id "amuJRfxa4UbeLxj1SWXBUAAAAJA"]
[Thu Jul 30 12:26:29.480101 2026] [security2:error] [pid 738779:tid 738945] [client 142.93.53.183:62236] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/WOLFSHELL/razorcgiapi/perl.haxor"] [unique_id "amuJRfxa4UbeLxj1SWXBUQAAAKk"]
[Thu Jul 30 12:26:29.534330 2026] [core:notice] [pid 738779:tid 738836] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:29.812609 2026] [core:notice] [pid 738779:tid 738849] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:29.886369 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62245] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/WOLFSHELL/razorcgiapi/py.haxor"] [unique_id "amuJRfxa4UbeLxj1SWXBXAAAAKA"]
[Thu Jul 30 12:26:30.276759 2026] [security2:error] [pid 738779:tid 739030] [client 142.93.53.183:62253] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/WOLFSHELL/razorcgiapi/bash.haxor"] [unique_id "amuJRvxa4UbeLxj1SWXBZQAAAP4"]
[Thu Jul 30 12:26:30.381218 2026] [proxy:error] [pid 738779:tid 738938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:30.381307 2026] [proxy_http:error] [pid 738779:tid 738938] [client 20.52.54.143:9922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:30.381863 2026] [proxy:error] [pid 738779:tid 738938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:30.381905 2026] [proxy_http:error] [pid 738779:tid 738938] [client 20.52.54.143:9922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:30.666043 2026] [security2:error] [pid 738779:tid 738981] [client 142.93.53.183:62262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/includes/1337_DATA/perl.alfa"] [unique_id "amuJRvxa4UbeLxj1SWXBagAAAM0"]
[Thu Jul 30 12:26:31.058734 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:62271] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/blocks/badges/db/1337_DATA/perl.alfa"] [unique_id "amuJR_xa4UbeLxj1SWXBcQAAAPE"]
[Thu Jul 30 12:26:31.439154 2026] [security2:error] [pid 738779:tid 739008] [client 142.93.53.183:62278] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1337_DATA/perl.alfa"] [unique_id "amuJR_xa4UbeLxj1SWXBegAAAOg"]
[Thu Jul 30 12:26:31.822359 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:62287] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/section/1337_DATA/perl.alfa"] [unique_id "amuJR_xa4UbeLxj1SWXBjQAAAMU"]
[Thu Jul 30 12:26:32.156864 2026] [security2:error] [pid 738779:tid 738958] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJR_xa4UbeLxj1SWXBgQAAALY"]
[Thu Jul 30 12:26:32.212294 2026] [security2:error] [pid 738779:tid 738985] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJR_xa4UbeLxj1SWXBhwAAANE"]
[Thu Jul 30 12:26:32.214344 2026] [security2:error] [pid 738779:tid 739023] [client 142.93.53.183:62292] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/1337_DATA/perl.alfa"] [unique_id "amuJSPxa4UbeLxj1SWXBnAAAAPc"]
[Thu Jul 30 12:26:32.281846 2026] [security2:error] [pid 738779:tid 738916] [client 20.52.54.143:10208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/images/index.php"] [unique_id "amuJSPxa4UbeLxj1SWXBnQAAAIw"]
[Thu Jul 30 12:26:32.605126 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62300] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1337_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJSPxa4UbeLxj1SWXBpAAAAKA"]
[Thu Jul 30 12:26:32.748862 2026] [security2:error] [pid 738779:tid 739000] [client 123.232.132.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJSPxa4UbeLxj1SWXBnwAA4Fo"]
[Thu Jul 30 12:26:32.859498 2026] [security2:error] [pid 738779:tid 738877] [remote 167.71.218.184:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wce.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuJSPxa4UbeLxj1SWXBrAAAlWE"]
[Thu Jul 30 12:26:32.995851 2026] [security2:error] [pid 738779:tid 739028] [client 142.93.53.183:62309] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1337_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJSPxa4UbeLxj1SWXBrwAAAPw"]
[Thu Jul 30 12:26:33.230654 2026] [proxy:error] [pid 738779:tid 738933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:33.230733 2026] [proxy_http:error] [pid 738779:tid 738933] [client 20.52.54.143:9975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:33.231520 2026] [proxy:error] [pid 738779:tid 738933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:33.231574 2026] [proxy_http:error] [pid 738779:tid 738933] [client 20.52.54.143:9975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:33.386382 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:62318] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/1337_DATA/alfacgiapi/py.alfa"] [unique_id "amuJSfxa4UbeLxj1SWXBuQAAANY"]
[Thu Jul 30 12:26:33.486742 2026] [security2:error] [pid 738779:tid 738991] [client 157.49.37.179:56362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJRvxa4UbeLxj1SWXBcAAAANc"], referer: http://pkf.jo
[Thu Jul 30 12:26:33.487431 2026] [security2:error] [pid 738779:tid 739026] [client 102.66.149.193:52815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJR_xa4UbeLxj1SWXBiwAAAPo"], referer: http://pkf.jo
[Thu Jul 30 12:26:33.487731 2026] [security2:error] [pid 738779:tid 738982] [client 203.223.89.75:39336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJRvxa4UbeLxj1SWXBYAAAAM4"], referer: http://pkf.jo
[Thu Jul 30 12:26:33.681600 2026] [core:error] [pid 738779:tid 738939] [client 74.7.228.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:33.681622 2026] [core:error] [pid 738779:tid 738939] [client 74.7.228.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:33.681770 2026] [security2:error] [pid 738779:tid 738939] [client 74.7.228.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.emberleafweeddeliverydispensary.delivery"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuJSfxa4UbeLxj1SWXBwwAAAKM"]
[Thu Jul 30 12:26:33.682370 2026] [security2:error] [pid 738779:tid 738912] [client 74.7.228.33:36364] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.emberleafweeddeliverydispensary.delivery"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuJSfxa4UbeLxj1SWXBwQAAiGo"]
[Thu Jul 30 12:26:33.777234 2026] [security2:error] [pid 738779:tid 738973] [client 142.93.53.183:62326] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOKIDATA/hokicgiapi/perl.hoki"] [unique_id "amuJSfxa4UbeLxj1SWXBxwAAAMU"]
[Thu Jul 30 12:26:34.165298 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:62336] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOKIDATA/hokicgiapi/bash.hoki"] [unique_id "amuJSvxa4UbeLxj1SWXBzgAAAPI"]
[Thu Jul 30 12:26:34.174382 2026] [security2:error] [pid 738779:tid 739022] [client 20.52.54.143:10236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/asd.php"] [unique_id "amuJSvxa4UbeLxj1SWXBzwAAAPY"]
[Thu Jul 30 12:26:34.192825 2026] [security2:error] [pid 738779:tid 738955] [client 52.238.199.152:38862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/headers.php"] [unique_id "amuJSvxa4UbeLxj1SWXB0AAAALM"]
[Thu Jul 30 12:26:34.558082 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:62343] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SEOBARBAR_1337/barbarpride/bash.alfa"] [unique_id "amuJSvxa4UbeLxj1SWXB2AAAAJA"]
[Thu Jul 30 12:26:34.830260 2026] [security2:error] [pid 738779:tid 738891] [remote 74.7.241.59:46426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuJSvxa4UbeLxj1SWXB3gAAjG8"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:26:34.837816 2026] [security2:error] [pid 738779:tid 739009] [client 20.52.54.143:9958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuJSvxa4UbeLxj1SWXB4AAAAOk"]
[Thu Jul 30 12:26:34.950226 2026] [security2:error] [pid 738779:tid 738932] [client 142.93.53.183:62349] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SEOBARBAR_1337/barbarpride/perl.alfa"] [unique_id "amuJSvxa4UbeLxj1SWXB5AAAAJw"]
[Thu Jul 30 12:26:35.073137 2026] [security2:error] [pid 738779:tid 739006] [client 74.7.230.38:40884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.newyorkgiantsfootball.live.qsv.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuJS_xa4UbeLxj1SWXB5gAAAOY"]
[Thu Jul 30 12:26:35.212677 2026] [authz_core:error] [pid 738779:tid 738972] [client 46.232.235.5:44112] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:35.329409 2026] [security2:error] [pid 738779:tid 739029] [client 142.93.53.183:62355] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/SEOBARBAR_1337/barbarpride/py.alfa"] [unique_id "amuJS_xa4UbeLxj1SWXB6QAAAP0"]
[Thu Jul 30 12:26:35.359801 2026] [authz_core:error] [pid 738779:tid 738938] [client 46.232.235.5:44122] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:26:35.714558 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:62360] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuJS_xa4UbeLxj1SWXB8gAAAN4"]
[Thu Jul 30 12:26:36.056147 2026] [security2:error] [pid 738779:tid 738903] [remote 74.7.241.60:48418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuJTPxa4UbeLxj1SWXB-gAAw3s"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:26:36.083103 2026] [security2:error] [pid 738779:tid 738947] [client 52.238.199.152:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/admin.php"] [unique_id "amuJTPxa4UbeLxj1SWXB_AAAAKs"]
[Thu Jul 30 12:26:36.085709 2026] [autoindex:error] [pid 738779:tid 738918] [client 150.109.119.38:56288] AH01276: Cannot serve directory /home2/evmudite/public_html/wp/wp-content/plugins/wp-google-map-plugin/assets/images/icons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:26:36.095078 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:62363] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuJTPxa4UbeLxj1SWXB_QAAANc"]
[Thu Jul 30 12:26:36.481715 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:62367] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuJTPxa4UbeLxj1SWXCAwAAALI"]
[Thu Jul 30 12:26:36.487655 2026] [security2:error] [pid 738779:tid 738963] [client 20.52.54.143:9951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuJTPxa4UbeLxj1SWXCBQAAALs"]
[Thu Jul 30 12:26:36.857955 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:62369] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOST_DATA/kucrutcgiapi/perl.kucrut"] [unique_id "amuJTPxa4UbeLxj1SWXCBwAAALw"]
[Thu Jul 30 12:26:36.950692 2026] [authz_core:error] [pid 738779:tid 739033] [client 46.232.235.5:44144] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:36.966427 2026] [authz_core:error] [pid 738779:tid 739026] [client 46.232.235.5:44138] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 12:26:37.029881 2026] [security2:error] [pid 738779:tid 738906] [remote 216.73.216.152:25997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuJTfxa4UbeLxj1SWXCEQAAwX4"]
[Thu Jul 30 12:26:37.231885 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:62374] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOST_DATA/kucrutcgiapi/py.kucrut"] [unique_id "amuJTfxa4UbeLxj1SWXCEwAAAI0"]
[Thu Jul 30 12:26:37.391624 2026] [security2:error] [pid 738779:tid 738783] [remote 57.141.0.27:44234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuJTfxa4UbeLxj1SWXCFwAA0gM"]
[Thu Jul 30 12:26:37.426677 2026] [security2:error] [pid 738779:tid 739016] [client 20.52.54.143:9969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/atomlib.php"] [unique_id "amuJTfxa4UbeLxj1SWXCGAAAAPA"]
[Thu Jul 30 12:26:37.613149 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:62375] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/HOST_DATA/kucrutcgiapi/bash.kucrut"] [unique_id "amuJTfxa4UbeLxj1SWXCHwAAAOk"]
[Thu Jul 30 12:26:37.996489 2026] [security2:error] [pid 738779:tid 739012] [client 142.93.53.183:62381] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuJTfxa4UbeLxj1SWXCJgAAAOw"]
[Thu Jul 30 12:26:38.153131 2026] [security2:error] [pid 738779:tid 738929] [client 38.190.144.4:50492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJTvxa4UbeLxj1SWXCLQAAAJk"]
[Thu Jul 30 12:26:38.153286 2026] [security2:error] [pid 738779:tid 738929] [client 38.190.144.4:50492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJTvxa4UbeLxj1SWXCLQAAAJk"]
[Thu Jul 30 12:26:38.386706 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:62383] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuJTvxa4UbeLxj1SWXCLgAAAPk"]
[Thu Jul 30 12:26:38.396048 2026] [proxy:error] [pid 738779:tid 738999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:38.396126 2026] [proxy_http:error] [pid 738779:tid 738999] [client 20.52.54.143:9968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:38.396764 2026] [proxy:error] [pid 738779:tid 738999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:38.396810 2026] [proxy_http:error] [pid 738779:tid 738999] [client 20.52.54.143:9968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:38.465364 2026] [security2:error] [pid 738779:tid 738932] [client 52.238.199.152:38796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/flower.php"] [unique_id "amuJTvxa4UbeLxj1SWXCMAAAAJw"]
[Thu Jul 30 12:26:38.571535 2026] [security2:error] [pid 738779:tid 739031] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJTfxa4UbeLxj1SWXCIgAA_3M"]
[Thu Jul 30 12:26:38.778670 2026] [security2:error] [pid 738779:tid 739021] [client 142.93.53.183:62387] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuJTvxa4UbeLxj1SWXCNwAAAPU"]
[Thu Jul 30 12:26:38.845672 2026] [security2:error] [pid 738779:tid 738990] [client 74.7.175.166:43560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amuJTvxa4UbeLxj1SWXCOAAA1go"]
[Thu Jul 30 12:26:39.167402 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:62395] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/controller/extension/extension/ALFA_DATA/perl.alfa"] [unique_id "amuJT_xa4UbeLxj1SWXCPgAAAPM"]
[Thu Jul 30 12:26:39.524938 2026] [proxy:error] [pid 738779:tid 738954] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:39.525037 2026] [proxy_http:error] [pid 738779:tid 738954] [client 20.52.54.143:9923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:39.525847 2026] [proxy:error] [pid 738779:tid 738954] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:39.525896 2026] [proxy_http:error] [pid 738779:tid 738954] [client 20.52.54.143:9923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:39.539876 2026] [security2:error] [pid 738779:tid 739005] [client 142.93.53.183:62396] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJT_xa4UbeLxj1SWXCRQAAAOU"]
[Thu Jul 30 12:26:39.806791 2026] [security2:error] [pid 738779:tid 738909] [client 158.158.76.106:54537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/log.php"] [unique_id "amuJT_xa4UbeLxj1SWXCTAAAAIU"]
[Thu Jul 30 12:26:39.806894 2026] [security2:error] [pid 738779:tid 738909] [client 158.158.76.106:54537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/log.php"] [unique_id "amuJT_xa4UbeLxj1SWXCTAAAAIU"]
[Thu Jul 30 12:26:39.928510 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:62403] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/templates/beez3/ALFA_DATA/perl.alfa"] [unique_id "amuJT_xa4UbeLxj1SWXCTQAAAPI"]
[Thu Jul 30 12:26:40.000442 2026] [security2:error] [pid 738779:tid 739010] [client 52.238.199.152:62659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuJT_xa4UbeLxj1SWXCTgAAAOo"]
[Thu Jul 30 12:26:40.339470 2026] [security2:error] [pid 738779:tid 738959] [client 142.93.53.183:62407] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/tmp_images/alfacgiapi/perl"] [unique_id "amuJUPxa4UbeLxj1SWXCWQAAALc"]
[Thu Jul 30 12:26:40.731499 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:62412] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/cgialfa/perl.alfa"] [unique_id "amuJUPxa4UbeLxj1SWXCYgAAAL0"]
[Thu Jul 30 12:26:40.860818 2026] [core:notice] [pid 738779:tid 738804] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.036586 2026] [core:notice] [pid 738779:tid 738901] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.036734 2026] [core:notice] [pid 738779:tid 738806] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.036734 2026] [core:notice] [pid 738779:tid 738809] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.036896 2026] [core:notice] [pid 738779:tid 738807] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.037058 2026] [core:notice] [pid 738779:tid 738808] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.092242 2026] [security2:error] [pid 738779:tid 738942] [client 103.122.66.226:33908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJUPxa4UbeLxj1SWXCYwAAAKY"], referer: http://pkf.jo
[Thu Jul 30 12:26:41.120667 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:62415] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploaded/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuJUfxa4UbeLxj1SWXCbgAAAPk"]
[Thu Jul 30 12:26:41.147370 2026] [core:notice] [pid 738779:tid 738813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147486 2026] [core:notice] [pid 738779:tid 738823] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147522 2026] [core:notice] [pid 738779:tid 738815] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147619 2026] [core:notice] [pid 738779:tid 738818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147670 2026] [core:notice] [pid 738779:tid 738816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.147711 2026] [core:notice] [pid 738779:tid 738817] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.148617 2026] [core:notice] [pid 738779:tid 738819] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.367793 2026] [core:notice] [pid 738779:tid 738821] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.373183 2026] [security2:error] [pid 738779:tid 738946] [client 150.109.73.51:60594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/$$$call$$$/page/page/css"] [unique_id "amuJUfxa4UbeLxj1SWXCfAAAqik"], referer: https://www.ejournalugj.com/
[Thu Jul 30 12:26:41.511090 2026] [security2:error] [pid 738779:tid 738991] [client 142.93.53.183:62418] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploaded/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuJUfxa4UbeLxj1SWXCfgAAANc"]
[Thu Jul 30 12:26:41.542037 2026] [core:notice] [pid 738779:tid 738820] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:41.595229 2026] [security2:error] [pid 738779:tid 738979] [client 52.238.199.152:64301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content.php"] [unique_id "amuJUfxa4UbeLxj1SWXCgAAAAMs"]
[Thu Jul 30 12:26:41.902410 2026] [security2:error] [pid 738779:tid 738934] [client 142.93.53.183:62425] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/uploaded/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuJUfxa4UbeLxj1SWXChwAAAJ4"]
[Thu Jul 30 12:26:42.292464 2026] [security2:error] [pid 738779:tid 738958] [client 142.93.53.183:62430] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuJUvxa4UbeLxj1SWXCjAAAALY"]
[Thu Jul 30 12:26:42.379130 2026] [proxy:error] [pid 738779:tid 738964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:42.379363 2026] [proxy_http:error] [pid 738779:tid 738964] [client 74.7.175.169:46656] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:42.379922 2026] [proxy:error] [pid 738779:tid 738964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:42.379964 2026] [proxy_http:error] [pid 738779:tid 738964] [client 74.7.175.169:46656] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:42.380114 2026] [security2:error] [pid 738779:tid 738964] [client 74.7.175.169:46656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.abudhabifurnituremoverspackers.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuJUvxa4UbeLxj1SWXCkAAAALw"]
[Thu Jul 30 12:26:42.559654 2026] [security2:error] [pid 738779:tid 738937] [client 52.238.199.152:38846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/function.php"] [unique_id "amuJUvxa4UbeLxj1SWXCkQAAAKE"]
[Thu Jul 30 12:26:42.666014 2026] [security2:error] [pid 738779:tid 739027] [client 142.93.53.183:62435] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuJUvxa4UbeLxj1SWXCkgAAAPs"]
[Thu Jul 30 12:26:42.745175 2026] [security2:error] [pid 738779:tid 739003] [client 145.239.10.137:34896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/Jcrop.php"] [unique_id "amuJUvxa4UbeLxj1SWXClAAAAOM"], referer: http://dhowcruisedinner.com/Jcrop.php
[Thu Jul 30 12:26:42.873869 2026] [security2:error] [pid 738779:tid 739032] [client 20.52.54.143:9970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuJUvxa4UbeLxj1SWXCmwAAAQA"]
[Thu Jul 30 12:26:43.039689 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:62438] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuJU_xa4UbeLxj1SWXCnAAAAIs"]
[Thu Jul 30 12:26:43.267290 2026] [core:notice] [pid 738779:tid 738829] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:43.418015 2026] [security2:error] [pid 738779:tid 738996] [client 142.93.53.183:62441] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuJU_xa4UbeLxj1SWXCpAAAANw"]
[Thu Jul 30 12:26:43.496457 2026] [proxy:error] [pid 738779:tid 738956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:43.496535 2026] [proxy_http:error] [pid 738779:tid 738956] [client 20.52.54.143:10217] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:43.497100 2026] [proxy:error] [pid 738779:tid 738956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:43.497146 2026] [proxy_http:error] [pid 738779:tid 738956] [client 20.52.54.143:10217] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:43.809891 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62445] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuJU_xa4UbeLxj1SWXCpwAAAKA"]
[Thu Jul 30 12:26:44.199483 2026] [security2:error] [pid 738779:tid 738998] [client 142.93.53.183:62449] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/tinymce/langs/j/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJVPxa4UbeLxj1SWXCsQAAAN4"]
[Thu Jul 30 12:26:44.388935 2026] [security2:error] [pid 738779:tid 739030] [client 57.141.0.53:62386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJVPxa4UbeLxj1SWXCsAAA_jk"], referer: https://igetvape-australia.com/product/iget-bar-strawberry-lychee-ice/?add-to-cart=132
[Thu Jul 30 12:26:44.390398 2026] [security2:error] [pid 738779:tid 739001] [client 20.100.169.152:44141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJVPxa4UbeLxj1SWXCtgAAAOE"]
[Thu Jul 30 12:26:44.390493 2026] [security2:error] [pid 738779:tid 739001] [client 20.100.169.152:44141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJVPxa4UbeLxj1SWXCtgAAAOE"]
[Thu Jul 30 12:26:44.453662 2026] [security2:error] [pid 738779:tid 738918] [client 37.120.155.179:54988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuJVPxa4UbeLxj1SWXCugAAAI4"]
[Thu Jul 30 12:26:44.453743 2026] [security2:error] [pid 738779:tid 738918] [client 37.120.155.179:54988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuJVPxa4UbeLxj1SWXCugAAAI4"]
[Thu Jul 30 12:26:44.481720 2026] [proxy:error] [pid 738779:tid 738994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:44.481786 2026] [proxy_http:error] [pid 738779:tid 738994] [client 20.52.54.143:9959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:44.482362 2026] [proxy:error] [pid 738779:tid 738994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:44.482406 2026] [proxy_http:error] [pid 738779:tid 738994] [client 20.52.54.143:9959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:44.589258 2026] [security2:error] [pid 738779:tid 738982] [client 142.93.53.183:62452] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/tinymce/langs/j/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJVPxa4UbeLxj1SWXCvAAAAM4"]
[Thu Jul 30 12:26:44.712944 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:62985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJVPxa4UbeLxj1SWXCvQAAAKM"]
[Thu Jul 30 12:26:44.713077 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:62985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJVPxa4UbeLxj1SWXCvQAAAKM"]
[Thu Jul 30 12:26:44.977478 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:62456] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/generic/tinymce/langs/j/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJVPxa4UbeLxj1SWXCxAAAAMM"]
[Thu Jul 30 12:26:45.014575 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:44097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/x.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxQAAAIc"]
[Thu Jul 30 12:26:45.014659 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:44097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/x.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxQAAAIc"]
[Thu Jul 30 12:26:45.295178 2026] [security2:error] [pid 738779:tid 738973] [client 52.238.199.152:55067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/chosen.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxgAAAMU"]
[Thu Jul 30 12:26:45.317138 2026] [security2:error] [pid 738779:tid 738969] [client 20.100.169.152:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/mgrr.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxwAAAME"]
[Thu Jul 30 12:26:45.317225 2026] [security2:error] [pid 738779:tid 738969] [client 20.100.169.152:63025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/mgrr.php"] [unique_id "amuJVfxa4UbeLxj1SWXCxwAAAME"]
[Thu Jul 30 12:26:45.352571 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:62458] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/SASKRA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJVfxa4UbeLxj1SWXCyAAAALw"]
[Thu Jul 30 12:26:45.452194 2026] [core:notice] [pid 738779:tid 738844] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:45.570743 2026] [security2:error] [pid 738779:tid 738842] [remote 97.74.87.194:36524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/wp-login.php"] [unique_id "amuJVfxa4UbeLxj1SWXC0QAA6z4"]
[Thu Jul 30 12:26:45.616069 2026] [security2:error] [pid 738779:tid 738961] [client 20.100.169.152:62998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/domvf.php"] [unique_id "amuJVfxa4UbeLxj1SWXC0wAAALk"]
[Thu Jul 30 12:26:45.616155 2026] [security2:error] [pid 738779:tid 738961] [client 20.100.169.152:62998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/domvf.php"] [unique_id "amuJVfxa4UbeLxj1SWXC0wAAALk"]
[Thu Jul 30 12:26:45.638166 2026] [proxy:error] [pid 738779:tid 738968] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:45.638233 2026] [proxy_http:error] [pid 738779:tid 738968] [client 20.52.54.143:9962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:45.638778 2026] [proxy:error] [pid 738779:tid 738968] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:45.638821 2026] [proxy_http:error] [pid 738779:tid 738968] [client 20.52.54.143:9962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:45.733868 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:62463] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/SASKRA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJVfxa4UbeLxj1SWXC2gAAAMI"]
[Thu Jul 30 12:26:45.741300 2026] [security2:error] [pid 738779:tid 738959] [client 158.158.76.106:13410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/edit.php"] [unique_id "amuJVfxa4UbeLxj1SWXC2wAAALc"]
[Thu Jul 30 12:26:45.741404 2026] [security2:error] [pid 738779:tid 738959] [client 158.158.76.106:13410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/edit.php"] [unique_id "amuJVfxa4UbeLxj1SWXC2wAAALc"]
[Thu Jul 30 12:26:45.928165 2026] [security2:error] [pid 738779:tid 738972] [client 20.100.169.152:44121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/yup.php"] [unique_id "amuJVfxa4UbeLxj1SWXC3gAAAMQ"]
[Thu Jul 30 12:26:45.928255 2026] [security2:error] [pid 738779:tid 738972] [client 20.100.169.152:44121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/yup.php"] [unique_id "amuJVfxa4UbeLxj1SWXC3gAAAMQ"]
[Thu Jul 30 12:26:45.951569 2026] [security2:error] [pid 738779:tid 738983] [client 47.128.52.103:42800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nordeste1.com"] [uri "/robots.txt"] [unique_id "amuJVfxa4UbeLxj1SWXC4AAAAM8"]
[Thu Jul 30 12:26:46.121218 2026] [security2:error] [pid 738779:tid 738995] [client 142.93.53.183:62468] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/SASKRA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJVvxa4UbeLxj1SWXC5gAAANs"]
[Thu Jul 30 12:26:46.238020 2026] [security2:error] [pid 738779:tid 738933] [client 20.100.169.152:63005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/X.php"] [unique_id "amuJVvxa4UbeLxj1SWXC6gAAAJ0"]
[Thu Jul 30 12:26:46.238104 2026] [security2:error] [pid 738779:tid 738933] [client 20.100.169.152:63005] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/X.php"] [unique_id "amuJVvxa4UbeLxj1SWXC6gAAAJ0"]
[Thu Jul 30 12:26:46.439595 2026] [core:notice] [pid 738779:tid 738910] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:46.442187 2026] [security2:error] [pid 738779:tid 739031] [client 20.52.54.143:9931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/inputs.php"] [unique_id "amuJVvxa4UbeLxj1SWXC7AAAAP8"]
[Thu Jul 30 12:26:46.511260 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:62470] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/cache/SASKRA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJVvxa4UbeLxj1SWXC8wAAAOc"]
[Thu Jul 30 12:26:46.537276 2026] [security2:error] [pid 738779:tid 738946] [client 20.100.169.152:48852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuJVvxa4UbeLxj1SWXC9AAAAKo"]
[Thu Jul 30 12:26:46.537414 2026] [security2:error] [pid 738779:tid 738946] [client 20.100.169.152:48852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuJVvxa4UbeLxj1SWXC9AAAAKo"]
[Thu Jul 30 12:26:46.618763 2026] [security2:error] [pid 738779:tid 739036] [client 52.238.199.152:38869] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "womenclothingbox.com"] [uri "/1.php"] [unique_id "amuJVvxa4UbeLxj1SWXC9QAAAQQ"]
[Thu Jul 30 12:26:46.618896 2026] [security2:error] [pid 738779:tid 739036] [client 52.238.199.152:38869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/1.php"] [unique_id "amuJVvxa4UbeLxj1SWXC9QAAAQQ"]
[Thu Jul 30 12:26:46.840202 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:63036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/gec.php"] [unique_id "amuJVvxa4UbeLxj1SWXC-gAAAKM"]
[Thu Jul 30 12:26:46.840320 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:63036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/gec.php"] [unique_id "amuJVvxa4UbeLxj1SWXC-gAAAKM"]
[Thu Jul 30 12:26:46.899074 2026] [security2:error] [pid 738779:tid 738989] [client 142.93.53.183:62472] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/cache/SASKRA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJVvxa4UbeLxj1SWXC-wAAANU"]
[Thu Jul 30 12:26:46.905759 2026] [proxy:error] [pid 738779:tid 739019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:46.905830 2026] [proxy_http:error] [pid 738779:tid 739019] [client 158.173.77.34:36469] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:46.906411 2026] [proxy:error] [pid 738779:tid 739019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:46.906455 2026] [proxy_http:error] [pid 738779:tid 739019] [client 158.173.77.34:36469] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:46.906525 2026] [security2:error] [pid 738779:tid 739019] [client 158.173.77.34:36469] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.seven-stars-shop.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuJVvxa4UbeLxj1SWXC_AAAAPM"]
[Thu Jul 30 12:26:47.145292 2026] [security2:error] [pid 738779:tid 739018] [client 20.100.169.152:44153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/sky.php"] [unique_id "amuJV_xa4UbeLxj1SWXDBgAAAPI"]
[Thu Jul 30 12:26:47.145461 2026] [security2:error] [pid 738779:tid 739018] [client 20.100.169.152:44153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/sky.php"] [unique_id "amuJV_xa4UbeLxj1SWXDBgAAAPI"]
[Thu Jul 30 12:26:47.281291 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:62474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/cache/cache/SASKRA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJV_xa4UbeLxj1SWXDBwAAALw"]
[Thu Jul 30 12:26:47.446479 2026] [security2:error] [pid 738779:tid 738924] [client 20.100.169.152:63003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/fffm.php"] [unique_id "amuJV_xa4UbeLxj1SWXDCwAAAJQ"]
[Thu Jul 30 12:26:47.446597 2026] [security2:error] [pid 738779:tid 738924] [client 20.100.169.152:63003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/fffm.php"] [unique_id "amuJV_xa4UbeLxj1SWXDCwAAAJQ"]
[Thu Jul 30 12:26:47.667861 2026] [security2:error] [pid 738779:tid 738950] [client 142.93.53.183:62476] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/fonts/ALOK_DATA/alokcgiapi/perl.alfa"] [unique_id "amuJV_xa4UbeLxj1SWXDFAAAAK4"]
[Thu Jul 30 12:26:47.747766 2026] [security2:error] [pid 738779:tid 738973] [client 38.190.144.4:50981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFQAAAMU"]
[Thu Jul 30 12:26:47.747921 2026] [security2:error] [pid 738779:tid 738973] [client 38.190.144.4:50981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFQAAAMU"]
[Thu Jul 30 12:26:47.755965 2026] [security2:error] [pid 738779:tid 738976] [client 20.100.169.152:63011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/sixxis.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFgAAAMg"]
[Thu Jul 30 12:26:47.756069 2026] [security2:error] [pid 738779:tid 738976] [client 20.100.169.152:63011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/sixxis.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFgAAAMg"]
[Thu Jul 30 12:26:47.761953 2026] [security2:error] [pid 738779:tid 738909] [client 52.238.199.152:18209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/lv.php"] [unique_id "amuJV_xa4UbeLxj1SWXDFwAAAIU"]
[Thu Jul 30 12:26:47.984369 2026] [core:error] [pid 738779:tid 738927] [client 13.222.80.67:46772] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:47.984396 2026] [core:error] [pid 738779:tid 738927] [client 13.222.80.67:46772] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:26:48.046800 2026] [security2:error] [pid 738779:tid 739006] [client 142.93.53.183:62480] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/fonts/ALOK_DATA/alokcgiapi/bash.alfa"] [unique_id "amuJWPxa4UbeLxj1SWXDHAAAAOY"]
[Thu Jul 30 12:26:48.082255 2026] [security2:error] [pid 738779:tid 738922] [client 20.100.169.152:63018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/yj09.php"] [unique_id "amuJWPxa4UbeLxj1SWXDHgAAAJI"]
[Thu Jul 30 12:26:48.082348 2026] [security2:error] [pid 738779:tid 738922] [client 20.100.169.152:63018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/yj09.php"] [unique_id "amuJWPxa4UbeLxj1SWXDHgAAAJI"]
[Thu Jul 30 12:26:48.382834 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/k.php"] [unique_id "amuJWPxa4UbeLxj1SWXDIgAAANA"]
[Thu Jul 30 12:26:48.382955 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:44112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/k.php"] [unique_id "amuJWPxa4UbeLxj1SWXDIgAAANA"]
[Thu Jul 30 12:26:48.433512 2026] [security2:error] [pid 738779:tid 739028] [client 142.93.53.183:62483] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/fonts/ALOK_DATA/alokcgiapi/py.alfa"] [unique_id "amuJWPxa4UbeLxj1SWXDIwAAAPw"]
[Thu Jul 30 12:26:48.509863 2026] [security2:error] [pid 738779:tid 738929] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/.env"] [unique_id "amuJWPxa4UbeLxj1SWXDJAAAAJk"]
[Thu Jul 30 12:26:48.684824 2026] [security2:error] [pid 738779:tid 738938] [client 20.100.169.152:62979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/k2.php"] [unique_id "amuJWPxa4UbeLxj1SWXDLgAAAKI"]
[Thu Jul 30 12:26:48.684907 2026] [security2:error] [pid 738779:tid 738938] [client 20.100.169.152:62979] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/k2.php"] [unique_id "amuJWPxa4UbeLxj1SWXDLgAAAKI"]
[Thu Jul 30 12:26:48.823627 2026] [security2:error] [pid 738779:tid 739017] [client 142.93.53.183:62488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJWPxa4UbeLxj1SWXDMAAAAPE"]
[Thu Jul 30 12:26:48.839631 2026] [security2:error] [pid 738779:tid 738998] [client 52.238.199.152:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/css.php"] [unique_id "amuJWPxa4UbeLxj1SWXDMQAAAN4"]
[Thu Jul 30 12:26:48.908023 2026] [core:notice] [pid 738779:tid 738879] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:49.007363 2026] [security2:error] [pid 738779:tid 738944] [client 20.100.169.152:62983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/w.php"] [unique_id "amuJWfxa4UbeLxj1SWXDMwAAAKg"]
[Thu Jul 30 12:26:49.007480 2026] [security2:error] [pid 738779:tid 738944] [client 20.100.169.152:62983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/w.php"] [unique_id "amuJWfxa4UbeLxj1SWXDMwAAAKg"]
[Thu Jul 30 12:26:49.176887 2026] [core:notice] [pid 738779:tid 738880] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:26:49.214462 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:62493] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJWfxa4UbeLxj1SWXDPAAAAPM"]
[Thu Jul 30 12:26:49.321852 2026] [security2:error] [pid 738779:tid 738928] [client 20.100.169.152:44105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/fpwch.php"] [unique_id "amuJWfxa4UbeLxj1SWXDPQAAAJg"]
[Thu Jul 30 12:26:49.321997 2026] [security2:error] [pid 738779:tid 738928] [client 20.100.169.152:44105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/fpwch.php"] [unique_id "amuJWfxa4UbeLxj1SWXDPQAAAJg"]
[Thu Jul 30 12:26:49.593658 2026] [security2:error] [pid 738779:tid 738960] [client 142.93.53.183:62499] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/jancox/alfacgiapi/perl.alfa"] [unique_id "amuJWfxa4UbeLxj1SWXDRAAAALg"]
[Thu Jul 30 12:26:49.621429 2026] [security2:error] [pid 738779:tid 739033] [client 20.100.169.152:63017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/w2025.php"] [unique_id "amuJWfxa4UbeLxj1SWXDRQAAAQE"]
[Thu Jul 30 12:26:49.621530 2026] [security2:error] [pid 738779:tid 739033] [client 20.100.169.152:63017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/w2025.php"] [unique_id "amuJWfxa4UbeLxj1SWXDRQAAAQE"]
[Thu Jul 30 12:26:49.697859 2026] [security2:error] [pid 738779:tid 739015] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJWfxa4UbeLxj1SWXDNAAA71g"]
[Thu Jul 30 12:26:49.921531 2026] [security2:error] [pid 738779:tid 739035] [client 20.100.169.152:44159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/FWAZ.php"] [unique_id "amuJWfxa4UbeLxj1SWXDSQAAAQM"]
[Thu Jul 30 12:26:49.921645 2026] [security2:error] [pid 738779:tid 739035] [client 20.100.169.152:44159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/FWAZ.php"] [unique_id "amuJWfxa4UbeLxj1SWXDSQAAAQM"]
[Thu Jul 30 12:26:49.980531 2026] [security2:error] [pid 738779:tid 739022] [client 142.93.53.183:62503] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/jancox/alfacgiapi/py.alfa"] [unique_id "amuJWfxa4UbeLxj1SWXDSgAAAPY"]
[Thu Jul 30 12:26:50.220970 2026] [security2:error] [pid 738779:tid 739000] [client 20.100.169.152:63028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/qterm.php"] [unique_id "amuJWvxa4UbeLxj1SWXDVAAAAOA"]
[Thu Jul 30 12:26:50.221078 2026] [security2:error] [pid 738779:tid 739000] [client 20.100.169.152:63028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/qterm.php"] [unique_id "amuJWvxa4UbeLxj1SWXDVAAAAOA"]
[Thu Jul 30 12:26:50.292452 2026] [security2:error] [pid 738779:tid 738951] [client 52.238.199.152:38882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/gecko.php"] [unique_id "amuJWvxa4UbeLxj1SWXDVQAAAK8"]
[Thu Jul 30 12:26:50.305755 2026] [security2:error] [pid 738779:tid 739014] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/.env.backup"] [unique_id "amuJWvxa4UbeLxj1SWXDVgAAAO4"]
[Thu Jul 30 12:26:50.370719 2026] [security2:error] [pid 738779:tid 739012] [client 142.93.53.183:62506] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-includes/block-patterns/jancox/alfacgiapi/bash.alfa"] [unique_id "amuJWvxa4UbeLxj1SWXDWAAAAOw"]
[Thu Jul 30 12:26:50.373062 2026] [security2:error] [pid 738779:tid 738972] [client 139.28.219.70:50620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "supreme-hydraulics.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuJWvxa4UbeLxj1SWXDWQAAAMQ"]
[Thu Jul 30 12:26:50.533122 2026] [security2:error] [pid 738779:tid 738996] [client 20.100.169.152:61558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/blurbs.php"] [unique_id "amuJWvxa4UbeLxj1SWXDWgAAANw"]
[Thu Jul 30 12:26:50.533230 2026] [security2:error] [pid 738779:tid 738996] [client 20.100.169.152:61558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/blurbs.php"] [unique_id "amuJWvxa4UbeLxj1SWXDWgAAANw"]
[Thu Jul 30 12:26:50.699415 2026] [security2:error] [pid 738779:tid 738950] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJWvxa4UbeLxj1SWXDTgAAAK4"]
[Thu Jul 30 12:26:50.761477 2026] [security2:error] [pid 738779:tid 738942] [client 142.93.53.183:62509] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyfive/assets/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJWvxa4UbeLxj1SWXDYwAAAKY"]
[Thu Jul 30 12:26:50.911953 2026] [security2:error] [pid 738779:tid 738936] [client 158.158.76.106:13384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/plugins.php"] [unique_id "amuJWvxa4UbeLxj1SWXDZgAAAKA"]
[Thu Jul 30 12:26:50.912072 2026] [security2:error] [pid 738779:tid 738936] [client 158.158.76.106:13384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/plugins.php"] [unique_id "amuJWvxa4UbeLxj1SWXDZgAAAKA"]
[Thu Jul 30 12:26:50.978756 2026] [security2:error] [pid 738779:tid 738949] [client 20.100.169.152:62977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-ws68.php"] [unique_id "amuJWvxa4UbeLxj1SWXDZwAAAK0"]
[Thu Jul 30 12:26:50.978864 2026] [security2:error] [pid 738779:tid 738949] [client 20.100.169.152:62977] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-ws68.php"] [unique_id "amuJWvxa4UbeLxj1SWXDZwAAAK0"]
[Thu Jul 30 12:26:51.081257 2026] [security2:error] [pid 738779:tid 738940] [client 20.52.54.143:10232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/index.php"] [unique_id "amuJW_xa4UbeLxj1SWXDaAAAAKQ"]
[Thu Jul 30 12:26:51.151967 2026] [security2:error] [pid 738779:tid 739007] [client 142.93.53.183:62514] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyfive/assets/css/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJW_xa4UbeLxj1SWXDagAAAOc"]
[Thu Jul 30 12:26:51.441117 2026] [security2:error] [pid 738779:tid 738930] [client 20.100.169.152:63031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/xyn.php"] [unique_id "amuJW_xa4UbeLxj1SWXDdAAAAJo"]
[Thu Jul 30 12:26:51.441225 2026] [security2:error] [pid 738779:tid 738930] [client 20.100.169.152:63031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/xyn.php"] [unique_id "amuJW_xa4UbeLxj1SWXDdAAAAJo"]
[Thu Jul 30 12:26:51.541437 2026] [security2:error] [pid 738779:tid 739033] [client 142.93.53.183:62517] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/themes/twentytwentyfive/assets/css/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJW_xa4UbeLxj1SWXDdQAAAQE"]
[Thu Jul 30 12:26:51.758688 2026] [security2:error] [pid 738779:tid 738911] [client 20.52.54.143:9941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuJW_xa4UbeLxj1SWXDgAAAAIc"]
[Thu Jul 30 12:26:51.809083 2026] [security2:error] [pid 738779:tid 738973] [client 20.100.169.152:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ccc.php"] [unique_id "amuJW_xa4UbeLxj1SWXDgQAAAMU"]
[Thu Jul 30 12:26:51.809187 2026] [security2:error] [pid 738779:tid 738973] [client 20.100.169.152:63023] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ccc.php"] [unique_id "amuJW_xa4UbeLxj1SWXDgQAAAMU"]
[Thu Jul 30 12:26:51.933367 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:62521] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2016/09/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJW_xa4UbeLxj1SWXDgwAAAMI"]
[Thu Jul 30 12:26:52.297989 2026] [security2:error] [pid 738779:tid 738995] [client 139.28.219.70:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDkAAAANs"]
[Thu Jul 30 12:26:52.298087 2026] [security2:error] [pid 738779:tid 738995] [client 139.28.219.70:54240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "supreme-hydraulics.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDkAAAANs"]
[Thu Jul 30 12:26:52.324070 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:62524] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2016/09/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJXPxa4UbeLxj1SWXDkQAAAPk"]
[Thu Jul 30 12:26:52.408240 2026] [security2:error] [pid 738779:tid 738936] [client 20.100.169.152:62999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/get.php"] [unique_id "amuJXPxa4UbeLxj1SWXDkgAAAKA"]
[Thu Jul 30 12:26:52.408353 2026] [security2:error] [pid 738779:tid 738936] [client 20.100.169.152:62999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/get.php"] [unique_id "amuJXPxa4UbeLxj1SWXDkgAAAKA"]
[Thu Jul 30 12:26:52.521810 2026] [security2:error] [pid 738779:tid 738938] [client 37.120.155.179:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDlAAAAKI"]
[Thu Jul 30 12:26:52.521887 2026] [security2:error] [pid 738779:tid 738938] [client 37.120.155.179:51614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDlAAAAKI"]
[Thu Jul 30 12:26:52.568949 2026] [security2:error] [pid 738779:tid 738950] [client 20.52.54.143:10221] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/1.php"] [unique_id "amuJXPxa4UbeLxj1SWXDlgAAAK4"]
[Thu Jul 30 12:26:52.569095 2026] [security2:error] [pid 738779:tid 738950] [client 20.52.54.143:10221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/1.php"] [unique_id "amuJXPxa4UbeLxj1SWXDlgAAAK4"]
[Thu Jul 30 12:26:52.711264 2026] [security2:error] [pid 738779:tid 739009] [client 142.93.53.183:62529] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2016/09/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJXPxa4UbeLxj1SWXDmgAAAOk"]
[Thu Jul 30 12:26:52.770878 2026] [security2:error] [pid 738779:tid 738965] [client 52.238.199.152:64288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/xmlrpc.php"] [unique_id "amuJXPxa4UbeLxj1SWXDnQAAAL0"]
[Thu Jul 30 12:26:52.986859 2026] [security2:error] [pid 738779:tid 738918] [client 20.100.169.152:63027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/images.php"] [unique_id "amuJXPxa4UbeLxj1SWXDoAAAAI4"]
[Thu Jul 30 12:26:52.987022 2026] [security2:error] [pid 738779:tid 738918] [client 20.100.169.152:63027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/images.php"] [unique_id "amuJXPxa4UbeLxj1SWXDoAAAAI4"]
[Thu Jul 30 12:26:52.988206 2026] [security2:error] [pid 738779:tid 738964] [client 162.141.167.36:53026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nxt.udi.temporary.site"] [uri "/index.php"] [unique_id "amuJXPxa4UbeLxj1SWXDnwAAALw"]
[Thu Jul 30 12:26:53.105240 2026] [security2:error] [pid 738779:tid 739029] [client 142.93.53.183:62533] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2018/11/1337_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJXfxa4UbeLxj1SWXDoQAAAP0"]
[Thu Jul 30 12:26:53.422535 2026] [security2:error] [pid 738779:tid 739005] [client 20.100.169.152:44108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/alls.php"] [unique_id "amuJXfxa4UbeLxj1SWXDqgAAAOU"]
[Thu Jul 30 12:26:53.422687 2026] [security2:error] [pid 738779:tid 739005] [client 20.100.169.152:44108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/alls.php"] [unique_id "amuJXfxa4UbeLxj1SWXDqgAAAOU"]
[Thu Jul 30 12:26:53.493218 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:62536] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2018/11/1337_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJXfxa4UbeLxj1SWXDqwAAALs"]
[Thu Jul 30 12:26:53.808281 2026] [security2:error] [pid 738779:tid 739036] [client 185.191.171.2:57984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/08/11/saque-do-auxilio-emergencial-e-liberado-para-nascidos-em-julho/"] [unique_id "amuJXfxa4UbeLxj1SWXDrwAAAQQ"]
[Thu Jul 30 12:26:53.808429 2026] [security2:error] [pid 738779:tid 739036] [client 185.191.171.2:57984] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/08/11/saque-do-auxilio-emergencial-e-liberado-para-nascidos-em-julho/"] [unique_id "amuJXfxa4UbeLxj1SWXDrwAAAQQ"]
[Thu Jul 30 12:26:53.886578 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:62543] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/uploads/2018/11/1337_DATA/alfacgiapi/py.alfa"] [unique_id "amuJXfxa4UbeLxj1SWXDtAAAALI"]
[Thu Jul 30 12:26:54.007067 2026] [security2:error] [pid 738779:tid 739034] [client 20.100.169.152:63020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/coffexium.php"] [unique_id "amuJXvxa4UbeLxj1SWXDtQAAAQI"]
[Thu Jul 30 12:26:54.007209 2026] [security2:error] [pid 738779:tid 739034] [client 20.100.169.152:63020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/coffexium.php"] [unique_id "amuJXvxa4UbeLxj1SWXDtQAAAQI"]
[Thu Jul 30 12:26:54.074069 2026] [security2:error] [pid 738779:tid 738939] [client 20.52.54.143:9948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/plugin.php"] [unique_id "amuJXvxa4UbeLxj1SWXDtgAAAKM"]
[Thu Jul 30 12:26:54.276854 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:62549] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/wp-file-manager/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJXvxa4UbeLxj1SWXDugAAAJA"]
[Thu Jul 30 12:26:54.324045 2026] [security2:error] [pid 738779:tid 738937] [client 20.100.169.152:63024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/red.php"] [unique_id "amuJXvxa4UbeLxj1SWXDuwAAAKE"]
[Thu Jul 30 12:26:54.324138 2026] [security2:error] [pid 738779:tid 738937] [client 20.100.169.152:63024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/red.php"] [unique_id "amuJXvxa4UbeLxj1SWXDuwAAAKE"]
[Thu Jul 30 12:26:54.668959 2026] [security2:error] [pid 738779:tid 738970] [client 142.93.53.183:62554] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/wp-file-manager/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJXvxa4UbeLxj1SWXDvwAAAMI"]
[Thu Jul 30 12:26:54.873581 2026] [security2:error] [pid 738779:tid 738952] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/.env.bak"] [unique_id "amuJXvxa4UbeLxj1SWXDxwAAALA"]
[Thu Jul 30 12:26:54.879532 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:44119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/sodium_compat/"] [unique_id "amuJXvxa4UbeLxj1SWXDwwAAALc"]
[Thu Jul 30 12:26:54.955215 2026] [security2:error] [pid 738779:tid 738905] [remote 103.57.220.209:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.57.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "laduchessecollections.com"] [uri "/wp-login.php"] [unique_id "amuJXvxa4UbeLxj1SWXDyQAArH0"]
[Thu Jul 30 12:26:55.058361 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:62558] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/wp-file-manager/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJX_xa4UbeLxj1SWXDygAAAM8"]
[Thu Jul 30 12:26:55.288124 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:44119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuJX_xa4UbeLxj1SWXDywAAANA"]
[Thu Jul 30 12:26:55.288247 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:44119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuJX_xa4UbeLxj1SWXDywAAANA"]
[Thu Jul 30 12:26:55.447367 2026] [security2:error] [pid 738779:tid 738988] [client 142.93.53.183:62560] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/media/uploads/Events/2022/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJX_xa4UbeLxj1SWXD0gAAANQ"]
[Thu Jul 30 12:26:55.718782 2026] [security2:error] [pid 738779:tid 738953] [client 20.52.54.143:9946] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.lilyinspires.com"] [uri "/1.php"] [unique_id "amuJX_xa4UbeLxj1SWXD1AAAALE"]
[Thu Jul 30 12:26:55.718924 2026] [security2:error] [pid 738779:tid 738953] [client 20.52.54.143:9946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/1.php"] [unique_id "amuJX_xa4UbeLxj1SWXD1AAAALE"]
[Thu Jul 30 12:26:55.826811 2026] [security2:error] [pid 738779:tid 738913] [client 142.93.53.183:62563] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/media/uploads/Events/2022/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJX_xa4UbeLxj1SWXD1QAAAIk"]
[Thu Jul 30 12:26:55.965381 2026] [security2:error] [pid 738779:tid 738991] [client 20.100.169.152:44111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/Text/"] [unique_id "amuJX_xa4UbeLxj1SWXD2QAAANc"]
[Thu Jul 30 12:26:56.003136 2026] [security2:error] [pid 738779:tid 738786] [remote 5.39.1.234:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "portugalvisaapplicationcenterinislamabad.site"] [uri "/"] [unique_id "amuJYPxa4UbeLxj1SWXD3QAAugY"]
[Thu Jul 30 12:26:56.003303 2026] [security2:error] [pid 738779:tid 738962] [client 5.39.1.234:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portugalvisaapplicationcenterinislamabad.site"] [uri "/"] [unique_id "amuJYPxa4UbeLxj1SWXD3QAAugY"]
[Thu Jul 30 12:26:56.208784 2026] [security2:error] [pid 738779:tid 739003] [client 142.93.53.183:62565] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/media/uploads/Events/2022/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJYPxa4UbeLxj1SWXD3gAAAOM"]
[Thu Jul 30 12:26:56.479647 2026] [security2:error] [pid 738779:tid 738994] [client 20.100.169.152:44111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-content/uploads/"] [unique_id "amuJYPxa4UbeLxj1SWXD5QAAANo"]
[Thu Jul 30 12:26:56.589799 2026] [security2:error] [pid 738779:tid 738947] [client 142.93.53.183:62569] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/imce/src/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJYPxa4UbeLxj1SWXD6QAAAKs"]
[Thu Jul 30 12:26:56.629102 2026] [security2:error] [pid 738779:tid 738963] [client 20.100.169.152:44111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-content/index.php"] [unique_id "amuJYPxa4UbeLxj1SWXD6gAAALs"]
[Thu Jul 30 12:26:56.629246 2026] [security2:error] [pid 738779:tid 738963] [client 20.100.169.152:44111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-content/index.php"] [unique_id "amuJYPxa4UbeLxj1SWXD6gAAALs"]
[Thu Jul 30 12:26:56.980023 2026] [security2:error] [pid 738779:tid 738926] [client 142.93.53.183:62570] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/imce/src/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJYPxa4UbeLxj1SWXD7gAAAJY"]
[Thu Jul 30 12:26:57.306287 2026] [security2:error] [pid 738779:tid 739035] [client 20.100.169.152:63039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/admin.php"] [unique_id "amuJYfxa4UbeLxj1SWXD8gAAAQM"]
[Thu Jul 30 12:26:57.306410 2026] [security2:error] [pid 738779:tid 739035] [client 20.100.169.152:63039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/admin.php"] [unique_id "amuJYfxa4UbeLxj1SWXD8gAAAQM"]
[Thu Jul 30 12:26:57.330437 2026] [security2:error] [pid 738779:tid 738997] [client 3.86.177.101:50762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mediaspawn.com"] [uri "/"] [unique_id "amuJYfxa4UbeLxj1SWXD8wAAAN0"]
[Thu Jul 30 12:26:57.353280 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:62574] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/imce/src/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJYfxa4UbeLxj1SWXD9AAAAJA"]
[Thu Jul 30 12:26:57.413818 2026] [security2:error] [pid 738779:tid 738919] [client 52.238.199.152:38833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/f35.php"] [unique_id "amuJYfxa4UbeLxj1SWXD9QAAAI8"]
[Thu Jul 30 12:26:57.744085 2026] [security2:error] [pid 738779:tid 738976] [client 142.93.53.183:62577] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/ctools/modules/ctools_entity_mask/tests/modules/entity_mask_test/config/install/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJYfxa4UbeLxj1SWXD_QAAAMg"]
[Thu Jul 30 12:26:58.124278 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:62579] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/ctools/modules/ctools_entity_mask/tests/modules/entity_mask_test/config/install/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJYvxa4UbeLxj1SWXECgAAAK0"]
[Thu Jul 30 12:26:58.359060 2026] [security2:error] [pid 738779:tid 738967] [client 20.100.169.152:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/177.php"] [unique_id "amuJYvxa4UbeLxj1SWXEDAAAAL8"]
[Thu Jul 30 12:26:58.359174 2026] [security2:error] [pid 738779:tid 738967] [client 20.100.169.152:62982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/177.php"] [unique_id "amuJYvxa4UbeLxj1SWXEDAAAAL8"]
[Thu Jul 30 12:26:58.372717 2026] [security2:error] [pid 738779:tid 738988] [client 52.238.199.152:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/autoload_classmap.php"] [unique_id "amuJYvxa4UbeLxj1SWXEDQAAANQ"]
[Thu Jul 30 12:26:58.508889 2026] [security2:error] [pid 738779:tid 738940] [client 142.93.53.183:62581] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/modules/ctools/modules/ctools_entity_mask/tests/modules/entity_mask_test/config/install/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJYvxa4UbeLxj1SWXEEQAAAKQ"]
[Thu Jul 30 12:26:58.510200 2026] [security2:error] [pid 738779:tid 738996] [client 38.190.144.4:51479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJYvxa4UbeLxj1SWXEEgAAANw"]
[Thu Jul 30 12:26:58.510346 2026] [security2:error] [pid 738779:tid 738996] [client 38.190.144.4:51479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJYvxa4UbeLxj1SWXEEgAAANw"]
[Thu Jul 30 12:26:58.552678 2026] [security2:error] [pid 738779:tid 739028] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJYfxa4UbeLxj1SWXEAwAAAPw"]
[Thu Jul 30 12:26:58.621409 2026] [security2:error] [pid 738779:tid 738975] [client 127.0.0.1:56934] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJYvxa4UbeLxj1SWXEFwAAAMc"]
[Thu Jul 30 12:26:58.621467 2026] [security2:error] [pid 738779:tid 739031] [client 74.7.175.157:40260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.greensparkle.net"] [uri "/robots.txt"] [unique_id "amuJYvxa4UbeLxj1SWXEFgAA_xc"]
[Thu Jul 30 12:26:58.642460 2026] [security2:error] [pid 738779:tid 739017] [client 158.158.76.106:54007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/style.php"] [unique_id "amuJYvxa4UbeLxj1SWXEGAAAAPE"]
[Thu Jul 30 12:26:58.642545 2026] [security2:error] [pid 738779:tid 739017] [client 158.158.76.106:54007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/style.php"] [unique_id "amuJYvxa4UbeLxj1SWXEGAAAAPE"]
[Thu Jul 30 12:26:58.778217 2026] [security2:error] [pid 738779:tid 738953] [client 20.52.54.143:9967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/gg.php"] [unique_id "amuJYvxa4UbeLxj1SWXEGgAAALE"]
[Thu Jul 30 12:26:58.882667 2026] [security2:error] [pid 738779:tid 738982] [client 142.93.53.183:62582] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/themes/xve/templates/content/news/LEVIATHAN/cgihaxor/perl.haxor"] [unique_id "amuJYvxa4UbeLxj1SWXEHgAAAM4"]
[Thu Jul 30 12:26:59.026759 2026] [security2:error] [pid 738779:tid 738917] [client 47.128.122.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJYvxa4UbeLxj1SWXEHQAAAI0"]
[Thu Jul 30 12:26:59.276766 2026] [security2:error] [pid 738779:tid 739018] [client 142.93.53.183:62588] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/themes/xve/templates/content/news/LEVIATHAN/cgihaxor/py.haxor"] [unique_id "amuJY_xa4UbeLxj1SWXEOwAAAPI"]
[Thu Jul 30 12:26:59.406444 2026] [proxy:error] [pid 738779:tid 739004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:59.406516 2026] [proxy_http:error] [pid 738779:tid 739004] [client 20.52.54.143:9976] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:59.407070 2026] [proxy:error] [pid 738779:tid 739004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:26:59.407116 2026] [proxy_http:error] [pid 738779:tid 739004] [client 20.52.54.143:9976] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:26:59.632882 2026] [security2:error] [pid 738779:tid 739013] [client 52.238.199.152:48514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/NewFile.php"] [unique_id "amuJY_xa4UbeLxj1SWXESAAAAO0"]
[Thu Jul 30 12:26:59.667957 2026] [security2:error] [pid 738779:tid 738911] [client 142.93.53.183:62592] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/themes/xve/templates/content/news/LEVIATHAN/cgihaxor/bash.haxor"] [unique_id "amuJY_xa4UbeLxj1SWXESQAAAIc"]
[Thu Jul 30 12:27:00.049944 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:62596] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/templates/blogus/bootstrap/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJZPxa4UbeLxj1SWXEUAAAAO8"]
[Thu Jul 30 12:27:00.301300 2026] [security2:error] [pid 738779:tid 738915] [client 20.52.54.143:10194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp.php"] [unique_id "amuJZPxa4UbeLxj1SWXEUQAAAIs"]
[Thu Jul 30 12:27:00.433124 2026] [security2:error] [pid 738779:tid 738951] [client 142.93.53.183:62600] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/templates/blogus/bootstrap/css/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJZPxa4UbeLxj1SWXEVQAAAK8"]
[Thu Jul 30 12:27:00.733556 2026] [security2:error] [pid 738779:tid 739032] [client 52.238.199.152:38878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/xx.php"] [unique_id "amuJZPxa4UbeLxj1SWXEWQAAAQA"]
[Thu Jul 30 12:27:00.823911 2026] [security2:error] [pid 738779:tid 739025] [client 142.93.53.183:62603] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/templates/blogus/bootstrap/css/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJZPxa4UbeLxj1SWXEWgAAAPk"]
[Thu Jul 30 12:27:00.900450 2026] [security2:error] [pid 738779:tid 738980] [client 20.100.169.152:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/199.php"] [unique_id "amuJZPxa4UbeLxj1SWXEXgAAAMw"]
[Thu Jul 30 12:27:00.900532 2026] [security2:error] [pid 738779:tid 738980] [client 20.100.169.152:44146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/199.php"] [unique_id "amuJZPxa4UbeLxj1SWXEXgAAAMw"]
[Thu Jul 30 12:27:01.099158 2026] [security2:error] [pid 738779:tid 738991] [client 158.158.76.106:44926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/plugins.php"] [unique_id "amuJZfxa4UbeLxj1SWXEYgAAANc"]
[Thu Jul 30 12:27:01.099268 2026] [security2:error] [pid 738779:tid 738991] [client 158.158.76.106:44926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "shorewooddaycare.com"] [uri "/plugins.php"] [unique_id "amuJZfxa4UbeLxj1SWXEYgAAANc"]
[Thu Jul 30 12:27:01.172234 2026] [core:notice] [pid 738779:tid 738940] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:01.200238 2026] [security2:error] [pid 738779:tid 739008] [client 142.93.53.183:62608] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/xxxTYPOxxx/typocgiapi/perl.typo"] [unique_id "amuJZfxa4UbeLxj1SWXEZAAAAOg"]
[Thu Jul 30 12:27:01.308624 2026] [security2:error] [pid 738779:tid 738913] [client 20.52.54.143:10193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuJZfxa4UbeLxj1SWXEZQAAAIk"]
[Thu Jul 30 12:27:01.577479 2026] [security2:error] [pid 738779:tid 739030] [client 142.93.53.183:62611] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/xxxTYPOxxx/typocgiapi/bash.typo"] [unique_id "amuJZfxa4UbeLxj1SWXEbQAAAP4"]
[Thu Jul 30 12:27:01.729296 2026] [security2:error] [pid 738779:tid 738987] [client 20.100.169.152:44101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/file52.php"] [unique_id "amuJZfxa4UbeLxj1SWXEbwAAANM"]
[Thu Jul 30 12:27:01.729441 2026] [security2:error] [pid 738779:tid 738987] [client 20.100.169.152:44101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/file52.php"] [unique_id "amuJZfxa4UbeLxj1SWXEbwAAANM"]
[Thu Jul 30 12:27:01.966352 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:62617] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-admin/user/xxxTYPOxxx/typocgiapi/py.typo"] [unique_id "amuJZfxa4UbeLxj1SWXEdAAAAI0"]
[Thu Jul 30 12:27:02.285004 2026] [security2:error] [pid 738779:tid 739006] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/.env.old"] [unique_id "amuJZvxa4UbeLxj1SWXEewAAAOY"]
[Thu Jul 30 12:27:02.322760 2026] [security2:error] [pid 738779:tid 738855] [remote 52.54.95.127:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "flixon.net"] [uri "/"] [unique_id "amuJZvxa4UbeLxj1SWXEfAAA9Es"]
[Thu Jul 30 12:27:02.337673 2026] [security2:error] [pid 738779:tid 739033] [client 20.100.169.152:44143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/geck.php"] [unique_id "amuJZvxa4UbeLxj1SWXEfQAAAQE"]
[Thu Jul 30 12:27:02.337765 2026] [security2:error] [pid 738779:tid 739033] [client 20.100.169.152:44143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/geck.php"] [unique_id "amuJZvxa4UbeLxj1SWXEfQAAAQE"]
[Thu Jul 30 12:27:02.355083 2026] [security2:error] [pid 738779:tid 738971] [client 142.93.53.183:62620] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/phpunit/build/bin/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuJZvxa4UbeLxj1SWXEfgAAAMM"]
[Thu Jul 30 12:27:02.412159 2026] [security2:error] [pid 738779:tid 738914] [client 20.52.54.143:9360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/file.php"] [unique_id "amuJZvxa4UbeLxj1SWXEggAAAIo"]
[Thu Jul 30 12:27:02.742971 2026] [security2:error] [pid 738779:tid 738924] [client 142.93.53.183:62624] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/phpunit/build/bin/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuJZvxa4UbeLxj1SWXEigAAAJQ"]
[Thu Jul 30 12:27:02.748106 2026] [security2:error] [pid 738779:tid 738979] [client 20.100.169.152:63001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/biufile.php"] [unique_id "amuJZvxa4UbeLxj1SWXEiwAAAMs"]
[Thu Jul 30 12:27:02.748216 2026] [security2:error] [pid 738779:tid 738979] [client 20.100.169.152:63001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/biufile.php"] [unique_id "amuJZvxa4UbeLxj1SWXEiwAAAMs"]
[Thu Jul 30 12:27:02.823707 2026] [security2:error] [pid 738779:tid 739035] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJZvxa4UbeLxj1SWXEiAAAAQM"]
[Thu Jul 30 12:27:02.823845 2026] [security2:error] [pid 738779:tid 739035] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJZvxa4UbeLxj1SWXEiAAAAQM"]
[Thu Jul 30 12:27:03.026603 2026] [security2:error] [pid 738779:tid 738845] [remote 40.77.167.51:56206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JPA"] [unique_id "amuJZ_xa4UbeLxj1SWXEjwAA6kE"]
[Thu Jul 30 12:27:03.079661 2026] [security2:error] [pid 738779:tid 739014] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJZ_xa4UbeLxj1SWXElQAAAO4"]
[Thu Jul 30 12:27:03.079762 2026] [security2:error] [pid 738779:tid 739014] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJZ_xa4UbeLxj1SWXElQAAAO4"]
[Thu Jul 30 12:27:03.136376 2026] [security2:error] [pid 738779:tid 738952] [client 142.93.53.183:62626] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/phpunit/phpunit/build/bin/7Syndicate/oxnixcgiapi/py.oxnix"] [unique_id "amuJZ_xa4UbeLxj1SWXElgAAALA"]
[Thu Jul 30 12:27:03.178703 2026] [security2:error] [pid 738779:tid 738941] [client 20.100.169.152:44150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dejavu.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEmAAAAKU"]
[Thu Jul 30 12:27:03.178792 2026] [security2:error] [pid 738779:tid 738941] [client 20.100.169.152:44150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dejavu.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEmAAAAKU"]
[Thu Jul 30 12:27:03.328166 2026] [security2:error] [pid 738779:tid 739022] [client 43.173.174.201:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/10/carnet-de-shopping-fete-ses-3-ans-et-vous-gate-la-semaine-prochaine/"] [unique_id "amuJZ_xa4UbeLxj1SWXElAAAAPY"]
[Thu Jul 30 12:27:03.335077 2026] [security2:error] [pid 738779:tid 738968] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/xstelth.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEmQAAAMA"]
[Thu Jul 30 12:27:03.335155 2026] [security2:error] [pid 738779:tid 738968] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/xstelth.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEmQAAAMA"]
[Thu Jul 30 12:27:03.394055 2026] [security2:error] [pid 738779:tid 738976] [client 43.173.173.236:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/02/17/au-hasard-de-la-toile-15/"] [unique_id "amuJZ_xa4UbeLxj1SWXElwAAAMg"]
[Thu Jul 30 12:27:03.500198 2026] [security2:error] [pid 738779:tid 738980] [client 20.100.169.152:63037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/aaf.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEnAAAAMw"]
[Thu Jul 30 12:27:03.500310 2026] [security2:error] [pid 738779:tid 738980] [client 20.100.169.152:63037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/aaf.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEnAAAAMw"]
[Thu Jul 30 12:27:03.527049 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62628] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/packet/7Syndicate/oxnixcgiapi/perl.oxnix"] [unique_id "amuJZ_xa4UbeLxj1SWXEnwAAAKA"]
[Thu Jul 30 12:27:03.605530 2026] [security2:error] [pid 738779:tid 738988] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/584062352875874akp.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEowAAANQ"]
[Thu Jul 30 12:27:03.605635 2026] [security2:error] [pid 738779:tid 738988] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/584062352875874akp.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEowAAANQ"]
[Thu Jul 30 12:27:03.741295 2026] [security2:error] [pid 738779:tid 738922] [client 20.52.54.143:10224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEpwAAAJI"]
[Thu Jul 30 12:27:03.817235 2026] [security2:error] [pid 738779:tid 738948] [client 20.100.169.152:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ha.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEqAAAAKw"]
[Thu Jul 30 12:27:03.817339 2026] [security2:error] [pid 738779:tid 738948] [client 20.100.169.152:44102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ha.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEqAAAAKw"]
[Thu Jul 30 12:27:03.917774 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:62631] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/uploads/packet/7Syndicate/oxnixcgiapi/bash.oxnix"] [unique_id "amuJZ_xa4UbeLxj1SWXEqQAAAP8"]
[Thu Jul 30 12:27:04.052413 2026] [core:notice] [pid 738779:tid 739003] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:04.058008 2026] [security2:error] [pid 738779:tid 739003] [client 43.173.174.253:51130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/10/carnet-de-shopping-fete-ses-3-ans-et-vous-gate-la-semaine-prochaine/"] [unique_id "amuJaPxa4UbeLxj1SWXErQAAAOM"], referer: https://carnetdeshopping.com/index.php/2012/03/10/carnet-de-shopping-fete-ses-3-ans-et-vous-gate-la-semaine-prochaine/
[Thu Jul 30 12:27:04.059731 2026] [core:notice] [pid 738779:tid 738953] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:04.065785 2026] [security2:error] [pid 738779:tid 738953] [client 43.172.198.222:44844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/02/17/au-hasard-de-la-toile-15/"] [unique_id "amuJaPxa4UbeLxj1SWXErgAAALE"], referer: https://carnetdeshopping.com/index.php/2014/02/17/au-hasard-de-la-toile-15/
[Thu Jul 30 12:27:04.140503 2026] [security2:error] [pid 738779:tid 738982] [client 20.100.169.152:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/hur.php"] [unique_id "amuJaPxa4UbeLxj1SWXErwAAAM4"]
[Thu Jul 30 12:27:04.140619 2026] [security2:error] [pid 738779:tid 738982] [client 20.100.169.152:62993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/hur.php"] [unique_id "amuJaPxa4UbeLxj1SWXErwAAAM4"]
[Thu Jul 30 12:27:04.180200 2026] [security2:error] [pid 738779:tid 738909] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJZ_xa4UbeLxj1SWXEogAAAIU"]
[Thu Jul 30 12:27:04.305800 2026] [security2:error] [pid 738779:tid 739001] [client 142.93.53.183:62636] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/lib/lang/locale/th_TH/LC_MESSAGES/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJaPxa4UbeLxj1SWXEtQAAAOE"]
[Thu Jul 30 12:27:04.488707 2026] [security2:error] [pid 738779:tid 738918] [client 20.100.169.152:62990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/h02ugyh.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtgAAAI4"]
[Thu Jul 30 12:27:04.488860 2026] [security2:error] [pid 738779:tid 738918] [client 20.100.169.152:62990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/h02ugyh.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtgAAAI4"]
[Thu Jul 30 12:27:04.511495 2026] [security2:error] [pid 738779:tid 738925] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/newfile.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtwAAAJU"]
[Thu Jul 30 12:27:04.511593 2026] [security2:error] [pid 738779:tid 738925] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/newfile.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtwAAAJU"]
[Thu Jul 30 12:27:04.588740 2026] [security2:error] [pid 738779:tid 739007] [client 103.188.52.54:42010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJaPxa4UbeLxj1SWXEtAAAAOc"], referer: http://pkf.jo
[Thu Jul 30 12:27:04.699019 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:62639] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/lib/lang/locale/th_TH/LC_MESSAGES/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJaPxa4UbeLxj1SWXEvgAAAPg"]
[Thu Jul 30 12:27:04.779258 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/tBEZGQz.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwQAAAKc"]
[Thu Jul 30 12:27:04.779350 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/tBEZGQz.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwQAAAKc"]
[Thu Jul 30 12:27:04.800907 2026] [security2:error] [pid 738779:tid 738954] [client 20.100.169.152:44107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/155.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwgAAALI"]
[Thu Jul 30 12:27:04.801008 2026] [security2:error] [pid 738779:tid 738954] [client 20.100.169.152:44107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/155.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwgAAALI"]
[Thu Jul 30 12:27:05.015661 2026] [proxy:error] [pid 738779:tid 738917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:05.015757 2026] [proxy_http:error] [pid 738779:tid 738917] [client 20.52.54.143:9920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:05.016474 2026] [proxy:error] [pid 738779:tid 738917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:05.016525 2026] [proxy_http:error] [pid 738779:tid 738917] [client 20.52.54.143:9920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:05.036257 2026] [security2:error] [pid 738779:tid 738956] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJafxa4UbeLxj1SWXExQAAALQ"]
[Thu Jul 30 12:27:05.089549 2026] [security2:error] [pid 738779:tid 739004] [client 142.93.53.183:62641] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/lib/lang/locale/th_TH/LC_MESSAGES/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJafxa4UbeLxj1SWXEyQAAAOQ"]
[Thu Jul 30 12:27:05.106083 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:63007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ops.php"] [unique_id "amuJafxa4UbeLxj1SWXEygAAAIc"]
[Thu Jul 30 12:27:05.106182 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:63007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ops.php"] [unique_id "amuJafxa4UbeLxj1SWXEygAAAIc"]
[Thu Jul 30 12:27:05.146666 2026] [security2:error] [pid 738779:tid 738969] [client 223.184.237.53:22596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJaPxa4UbeLxj1SWXEwwAAAME"], referer: http://pkf.jo
[Thu Jul 30 12:27:05.235734 2026] [security2:error] [pid 738779:tid 738859] [remote 103.255.134.61:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuJafxa4UbeLxj1SWXEywAA608"]
[Thu Jul 30 12:27:05.309362 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/drykl.php"] [unique_id "amuJafxa4UbeLxj1SWXEzwAAAMU"]
[Thu Jul 30 12:27:05.309453 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/drykl.php"] [unique_id "amuJafxa4UbeLxj1SWXEzwAAAMU"]
[Thu Jul 30 12:27:05.474808 2026] [security2:error] [pid 738779:tid 738935] [client 20.100.169.152:63010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ingfo.php"] [unique_id "amuJafxa4UbeLxj1SWXE0AAAAJ8"]
[Thu Jul 30 12:27:05.474911 2026] [security2:error] [pid 738779:tid 738935] [client 20.100.169.152:63010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/ingfo.php"] [unique_id "amuJafxa4UbeLxj1SWXE0AAAAJ8"]
[Thu Jul 30 12:27:05.479959 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:62645] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/admin_template/default/assets/fonts/ONIC_ESPORT/haxorcgiapi/perl.haxor"] [unique_id "amuJafxa4UbeLxj1SWXE0QAAAO8"]
[Thu Jul 30 12:27:05.617212 2026] [security2:error] [pid 738779:tid 739000] [client 20.52.54.143:9957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuJafxa4UbeLxj1SWXE1AAAAOA"]
[Thu Jul 30 12:27:05.723356 2026] [security2:error] [pid 738779:tid 739032] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJafxa4UbeLxj1SWXE2wAAAQA"]
[Thu Jul 30 12:27:05.783429 2026] [security2:error] [pid 738779:tid 738999] [client 20.100.169.152:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/error_log.php"] [unique_id "amuJafxa4UbeLxj1SWXE3AAAAN8"]
[Thu Jul 30 12:27:05.783582 2026] [security2:error] [pid 738779:tid 738999] [client 20.100.169.152:44104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/error_log.php"] [unique_id "amuJafxa4UbeLxj1SWXE3AAAAN8"]
[Thu Jul 30 12:27:05.797906 2026] [security2:error] [pid 738779:tid 738915] [client 75.174.89.119:60784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJafxa4UbeLxj1SWXE0gAAAIs"], referer: http://pkf.jo
[Thu Jul 30 12:27:05.858223 2026] [security2:error] [pid 738779:tid 738949] [client 142.93.53.183:62648] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/admin_template/default/assets/fonts/ONIC_ESPORT/haxorcgiapi/py.haxor"] [unique_id "amuJafxa4UbeLxj1SWXE3QAAAK0"]
[Thu Jul 30 12:27:06.021946 2026] [security2:error] [pid 738779:tid 738940] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ls.php"] [unique_id "amuJavxa4UbeLxj1SWXE5AAAAKQ"]
[Thu Jul 30 12:27:06.022057 2026] [security2:error] [pid 738779:tid 738940] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ls.php"] [unique_id "amuJavxa4UbeLxj1SWXE5AAAAKQ"]
[Thu Jul 30 12:27:06.092283 2026] [security2:error] [pid 738779:tid 738910] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJafxa4UbeLxj1SWXE4AAAAIY"]
[Thu Jul 30 12:27:06.102642 2026] [security2:error] [pid 738779:tid 738962] [client 20.100.169.152:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/koala.php"] [unique_id "amuJavxa4UbeLxj1SWXE6AAAALo"]
[Thu Jul 30 12:27:06.102789 2026] [security2:error] [pid 738779:tid 738962] [client 20.100.169.152:44129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/koala.php"] [unique_id "amuJavxa4UbeLxj1SWXE6AAAALo"]
[Thu Jul 30 12:27:06.254828 2026] [security2:error] [pid 738779:tid 738953] [client 74.7.175.176:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.progroup.jo"] [uri "/cgi-sys/404.html"] [unique_id "amuJavxa4UbeLxj1SWXE6wAAALE"]
[Thu Jul 30 12:27:06.255450 2026] [security2:error] [pid 738779:tid 738985] [client 74.7.175.176:45734] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.progroup.jo"] [uri "/robots.txt"] [unique_id "amuJavxa4UbeLxj1SWXE6QAA0WM"]
[Thu Jul 30 12:27:06.261536 2026] [security2:error] [pid 738779:tid 738967] [client 142.93.53.183:62653] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/admin/admin_template/default/assets/fonts/ONIC_ESPORT/haxorcgiapi/bash.haxor"] [unique_id "amuJavxa4UbeLxj1SWXE7QAAAL8"]
[Thu Jul 30 12:27:06.411794 2026] [security2:error] [pid 738779:tid 738965] [client 20.100.169.152:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/mac.php"] [unique_id "amuJavxa4UbeLxj1SWXE8QAAAL0"]
[Thu Jul 30 12:27:06.411892 2026] [security2:error] [pid 738779:tid 738965] [client 20.100.169.152:44157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/mac.php"] [unique_id "amuJavxa4UbeLxj1SWXE8QAAAL0"]
[Thu Jul 30 12:27:06.465343 2026] [security2:error] [pid 738779:tid 738975] [client 20.52.54.143:9399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/index/function.php"] [unique_id "amuJavxa4UbeLxj1SWXE8gAAAMc"]
[Thu Jul 30 12:27:06.476519 2026] [security2:error] [pid 738779:tid 738918] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/dx.php"] [unique_id "amuJavxa4UbeLxj1SWXE8wAAAI4"]
[Thu Jul 30 12:27:06.476597 2026] [security2:error] [pid 738779:tid 738918] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/dx.php"] [unique_id "amuJavxa4UbeLxj1SWXE8wAAAI4"]
[Thu Jul 30 12:27:06.651802 2026] [security2:error] [pid 738779:tid 739020] [client 142.93.53.183:62654] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/config/1337_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJavxa4UbeLxj1SWXE9wAAAPQ"]
[Thu Jul 30 12:27:06.717181 2026] [security2:error] [pid 738779:tid 738944] [client 20.100.169.152:63029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wefile.php"] [unique_id "amuJavxa4UbeLxj1SWXE-AAAAKg"]
[Thu Jul 30 12:27:06.717283 2026] [security2:error] [pid 738779:tid 738944] [client 20.100.169.152:63029] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wefile.php"] [unique_id "amuJavxa4UbeLxj1SWXE-AAAAKg"]
[Thu Jul 30 12:27:06.860878 2026] [security2:error] [pid 738779:tid 739010] [client 74.7.244.19:44216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.uqr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuJafxa4UbeLxj1SWXE0wAA6lw"]
[Thu Jul 30 12:27:06.877819 2026] [security2:error] [pid 738779:tid 738876] [remote 159.223.76.255:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.76.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vanguardlegalassociates.team"] [uri "/wp-login.php"] [unique_id "amuJavxa4UbeLxj1SWXE_QAA5WA"]
[Thu Jul 30 12:27:07.040842 2026] [security2:error] [pid 738779:tid 738917] [client 142.93.53.183:62656] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/config/1337_DATA/alfacgiapi/py.alfa"] [unique_id "amuJa_xa4UbeLxj1SWXE_wAAAI0"]
[Thu Jul 30 12:27:07.054852 2026] [security2:error] [pid 738779:tid 738934] [client 20.100.169.152:62981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/post-comments-form/"] [unique_id "amuJa_xa4UbeLxj1SWXE_gAAAJ4"]
[Thu Jul 30 12:27:07.391062 2026] [security2:error] [pid 738779:tid 739015] [client 20.100.169.152:62981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-admin/js/"] [unique_id "amuJa_xa4UbeLxj1SWXFDgAAAO8"]
[Thu Jul 30 12:27:07.433339 2026] [security2:error] [pid 738779:tid 739000] [client 142.93.53.183:62657] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/config/1337_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJa_xa4UbeLxj1SWXFEAAAAOA"]
[Thu Jul 30 12:27:07.542575 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:62981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/makeasmtp.php"] [unique_id "amuJa_xa4UbeLxj1SWXFEQAAALc"]
[Thu Jul 30 12:27:07.542687 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:62981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/makeasmtp.php"] [unique_id "amuJa_xa4UbeLxj1SWXFEQAAALc"]
[Thu Jul 30 12:27:07.820972 2026] [security2:error] [pid 738779:tid 738980] [client 142.93.53.183:62662] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJa_xa4UbeLxj1SWXFFwAAAMw"]
[Thu Jul 30 12:27:07.827293 2026] [security2:error] [pid 738779:tid 738976] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/mac.php"] [unique_id "amuJa_xa4UbeLxj1SWXFGQAAAMg"]
[Thu Jul 30 12:27:07.827401 2026] [security2:error] [pid 738779:tid 738976] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/mac.php"] [unique_id "amuJa_xa4UbeLxj1SWXFGQAAAMg"]
[Thu Jul 30 12:27:07.955490 2026] [security2:error] [pid 738779:tid 738983] [client 20.100.169.152:44110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/2P.php"] [unique_id "amuJa_xa4UbeLxj1SWXFHAAAAM8"]
[Thu Jul 30 12:27:07.955600 2026] [security2:error] [pid 738779:tid 738983] [client 20.100.169.152:44110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/2P.php"] [unique_id "amuJa_xa4UbeLxj1SWXFHAAAAM8"]
[Thu Jul 30 12:27:08.020598 2026] [security2:error] [pid 738779:tid 738893] [remote 57.141.0.62:24728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuJa_xa4UbeLxj1SWXFFgAAnHE"]
[Thu Jul 30 12:27:08.073110 2026] [security2:error] [pid 738779:tid 738981] [client 144.172.94.198:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "buyfluoxetine.store"] [uri "/backup/.env"] [unique_id "amuJbPxa4UbeLxj1SWXFHQAAAM0"]
[Thu Jul 30 12:27:08.114191 2026] [security2:error] [pid 738779:tid 739008] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/485.php"] [unique_id "amuJbPxa4UbeLxj1SWXFHgAAAOg"]
[Thu Jul 30 12:27:08.114287 2026] [security2:error] [pid 738779:tid 739008] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/485.php"] [unique_id "amuJbPxa4UbeLxj1SWXFHgAAAOg"]
[Thu Jul 30 12:27:08.193956 2026] [security2:error] [pid 738779:tid 739032] [client 85.208.96.206:34138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/11/lula-sera-diplomado-nesta-segunda-no-tse-com-discurso-e-280-convidados/"] [unique_id "amuJbPxa4UbeLxj1SWXFIgAAAQA"]
[Thu Jul 30 12:27:08.194071 2026] [security2:error] [pid 738779:tid 739032] [client 85.208.96.206:34138] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/11/lula-sera-diplomado-nesta-segunda-no-tse-com-discurso-e-280-convidados/"] [unique_id "amuJbPxa4UbeLxj1SWXFIgAAAQA"]
[Thu Jul 30 12:27:08.212886 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:62664] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/images/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJbPxa4UbeLxj1SWXFJAAAAP8"]
[Thu Jul 30 12:27:08.259186 2026] [security2:error] [pid 738779:tid 738964] [client 20.100.169.152:44142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/.well-known/about.php"] [unique_id "amuJbPxa4UbeLxj1SWXFJwAAALw"]
[Thu Jul 30 12:27:08.259298 2026] [security2:error] [pid 738779:tid 738964] [client 20.100.169.152:44142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/.well-known/about.php"] [unique_id "amuJbPxa4UbeLxj1SWXFJwAAALw"]
[Thu Jul 30 12:27:08.364305 2026] [security2:error] [pid 738779:tid 738990] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gelio1.php"] [unique_id "amuJbPxa4UbeLxj1SWXFKwAAANY"]
[Thu Jul 30 12:27:08.364421 2026] [security2:error] [pid 738779:tid 738990] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gelio1.php"] [unique_id "amuJbPxa4UbeLxj1SWXFKwAAANY"]
[Thu Jul 30 12:27:08.375440 2026] [security2:error] [pid 738779:tid 739026] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJbPxa4UbeLxj1SWXFJgAAAPo"]
[Thu Jul 30 12:27:08.564759 2026] [security2:error] [pid 738779:tid 738912] [client 20.100.169.152:63006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuJbPxa4UbeLxj1SWXFLgAAAIg"]
[Thu Jul 30 12:27:08.564879 2026] [security2:error] [pid 738779:tid 738912] [client 20.100.169.152:63006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuJbPxa4UbeLxj1SWXFLgAAAIg"]
[Thu Jul 30 12:27:08.605017 2026] [security2:error] [pid 738779:tid 738931] [client 142.93.53.183:62668] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJbPxa4UbeLxj1SWXFLwAAAJs"]
[Thu Jul 30 12:27:08.646586 2026] [security2:error] [pid 738779:tid 738965] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/lp6.php"] [unique_id "amuJbPxa4UbeLxj1SWXFMAAAAL0"]
[Thu Jul 30 12:27:08.646683 2026] [security2:error] [pid 738779:tid 738965] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/lp6.php"] [unique_id "amuJbPxa4UbeLxj1SWXFMAAAAL0"]
[Thu Jul 30 12:27:08.865237 2026] [security2:error] [pid 738779:tid 738926] [client 20.100.169.152:44149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/system_log.php"] [unique_id "amuJbPxa4UbeLxj1SWXFOQAAAJY"]
[Thu Jul 30 12:27:08.865368 2026] [security2:error] [pid 738779:tid 738926] [client 20.100.169.152:44149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/system_log.php"] [unique_id "amuJbPxa4UbeLxj1SWXFOQAAAJY"]
[Thu Jul 30 12:27:08.896495 2026] [security2:error] [pid 738779:tid 739030] [client 52.238.199.152:38861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/plugins.php"] [unique_id "amuJbPxa4UbeLxj1SWXFOgAAAP4"]
[Thu Jul 30 12:27:08.995515 2026] [security2:error] [pid 738779:tid 738943] [client 142.93.53.183:62672] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/assets/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJbPxa4UbeLxj1SWXFOwAAAKc"]
[Thu Jul 30 12:27:09.200453 2026] [security2:error] [pid 738779:tid 738928] [client 20.100.169.152:63014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-admin/css/"] [unique_id "amuJbfxa4UbeLxj1SWXFPwAAAJg"]
[Thu Jul 30 12:27:09.226912 2026] [core:notice] [pid 738779:tid 738781] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:09.276058 2026] [security2:error] [pid 738779:tid 738939] [client 216.73.216.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ciunews.com"] [uri "/index.php"] [unique_id "amuJbfxa4UbeLxj1SWXFPgAAAKM"]
[Thu Jul 30 12:27:09.312007 2026] [proxy:error] [pid 738779:tid 738914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:09.312095 2026] [proxy_http:error] [pid 738779:tid 738914] [client 20.52.54.143:9974] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:09.312645 2026] [proxy:error] [pid 738779:tid 738914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:09.312688 2026] [proxy_http:error] [pid 738779:tid 738914] [client 20.52.54.143:9974] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:09.386563 2026] [security2:error] [pid 738779:tid 739027] [client 142.93.53.183:62681] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/assets/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJbfxa4UbeLxj1SWXFSQAAAPs"]
[Thu Jul 30 12:27:09.417693 2026] [security2:error] [pid 738779:tid 739000] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuJbfxa4UbeLxj1SWXFSwAAAOA"]
[Thu Jul 30 12:27:09.417785 2026] [security2:error] [pid 738779:tid 739000] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuJbfxa4UbeLxj1SWXFSwAAAOA"]
[Thu Jul 30 12:27:09.544358 2026] [core:notice] [pid 738779:tid 738941] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:09.559501 2026] [security2:error] [pid 738779:tid 739036] [client 20.100.169.152:63014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/modern/"] [unique_id "amuJbfxa4UbeLxj1SWXFTAAAAQQ"]
[Thu Jul 30 12:27:09.692889 2026] [security2:error] [pid 738779:tid 738999] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJbfxa4UbeLxj1SWXFUQAAAN8"]
[Thu Jul 30 12:27:09.720233 2026] [security2:error] [pid 738779:tid 738995] [client 20.100.169.152:63014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/crgio.php"] [unique_id "amuJbfxa4UbeLxj1SWXFVQAAANs"]
[Thu Jul 30 12:27:09.720341 2026] [security2:error] [pid 738779:tid 738995] [client 20.100.169.152:63014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/crgio.php"] [unique_id "amuJbfxa4UbeLxj1SWXFVQAAANs"]
[Thu Jul 30 12:27:09.756757 2026] [security2:error] [pid 738779:tid 738959] [client 52.238.199.152:38860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/xxx.php"] [unique_id "amuJbfxa4UbeLxj1SWXFVgAAALc"]
[Thu Jul 30 12:27:09.774406 2026] [security2:error] [pid 738779:tid 738983] [client 142.93.53.183:62688] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/vendor/phpunit/php-code-coverage/src/Report/Html/Renderer/Template/js/cache/GUNDAMAPI/perl.alfa"] [unique_id "amuJbfxa4UbeLxj1SWXFVwAAAM8"]
[Thu Jul 30 12:27:09.838235 2026] [security2:error] [pid 738779:tid 738932] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/w3llscc.php"] [unique_id "amuJbfxa4UbeLxj1SWXFWAAAAJw"]
[Thu Jul 30 12:27:09.838355 2026] [security2:error] [pid 738779:tid 738932] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/w3llscc.php"] [unique_id "amuJbfxa4UbeLxj1SWXFWAAAAJw"]
[Thu Jul 30 12:27:09.958937 2026] [core:notice] [pid 738779:tid 738906] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:10.084059 2026] [security2:error] [pid 738779:tid 739017] [client 20.100.169.152:44133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/pucci.php"] [unique_id "amuJbvxa4UbeLxj1SWXFXQAAAPE"]
[Thu Jul 30 12:27:10.084173 2026] [security2:error] [pid 738779:tid 739017] [client 20.100.169.152:44133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/pucci.php"] [unique_id "amuJbvxa4UbeLxj1SWXFXQAAAPE"]
[Thu Jul 30 12:27:10.099817 2026] [security2:error] [pid 738779:tid 738946] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/miru3.php"] [unique_id "amuJbvxa4UbeLxj1SWXFXgAAAKo"]
[Thu Jul 30 12:27:10.099952 2026] [security2:error] [pid 738779:tid 738946] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/miru3.php"] [unique_id "amuJbvxa4UbeLxj1SWXFXgAAAKo"]
[Thu Jul 30 12:27:10.133295 2026] [core:notice] [pid 738779:tid 739032] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:10.164799 2026] [security2:error] [pid 738779:tid 738964] [client 142.93.53.183:62690] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/vendor/phpunit/php-code-coverage/src/Report/Html/Renderer/Template/js/cache/GUNDAMAPI/py.alfa"] [unique_id "amuJbvxa4UbeLxj1SWXFYAAAALw"]
[Thu Jul 30 12:27:10.371635 2026] [security2:error] [pid 738779:tid 738929] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/autoload_classmap.php"] [unique_id "amuJbvxa4UbeLxj1SWXFZQAAAJk"]
[Thu Jul 30 12:27:10.371731 2026] [security2:error] [pid 738779:tid 738929] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/autoload_classmap.php"] [unique_id "amuJbvxa4UbeLxj1SWXFZQAAAJk"]
[Thu Jul 30 12:27:10.517951 2026] [security2:error] [pid 738779:tid 738917] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJbfxa4UbeLxj1SWXFSAAAjXc"]
[Thu Jul 30 12:27:10.536469 2026] [security2:error] [pid 738779:tid 738984] [client 20.100.169.152:48892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/details/"] [unique_id "amuJbvxa4UbeLxj1SWXFaAAAANA"]
[Thu Jul 30 12:27:10.559785 2026] [security2:error] [pid 738779:tid 738912] [client 142.93.53.183:62692] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/v1/vendor/phpunit/php-code-coverage/src/Report/Html/Renderer/Template/js/cache/GUNDAMAPI/bash.alfa"] [unique_id "amuJbvxa4UbeLxj1SWXFaQAAAIg"]
[Thu Jul 30 12:27:10.562213 2026] [proxy:error] [pid 738779:tid 739031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:10.562287 2026] [proxy_http:error] [pid 738779:tid 739031] [client 20.52.54.143:10231] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:10.562827 2026] [proxy:error] [pid 738779:tid 739031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:10.562869 2026] [proxy_http:error] [pid 738779:tid 739031] [client 20.52.54.143:10231] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:10.869986 2026] [security2:error] [pid 738779:tid 739021] [client 20.100.169.152:48892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/audio/"] [unique_id "amuJbvxa4UbeLxj1SWXFbwAAAPU"]
[Thu Jul 30 12:27:10.945764 2026] [security2:error] [pid 738779:tid 739011] [client 142.93.53.183:62697] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/build/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJbvxa4UbeLxj1SWXFcwAAAOs"]
[Thu Jul 30 12:27:11.023663 2026] [security2:error] [pid 738779:tid 738962] [client 20.100.169.152:48892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-temp.php"] [unique_id "amuJb_xa4UbeLxj1SWXFdAAAALo"]
[Thu Jul 30 12:27:11.023808 2026] [security2:error] [pid 738779:tid 738962] [client 20.100.169.152:48892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-temp.php"] [unique_id "amuJb_xa4UbeLxj1SWXFdAAAALo"]
[Thu Jul 30 12:27:11.043379 2026] [security2:error] [pid 738779:tid 738782] [remote 47.128.27.46:37386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-aj1-air-jordan-1-low-christmas-white-red/"] [unique_id "amuJb_xa4UbeLxj1SWXFdgAAwwI"]
[Thu Jul 30 12:27:11.045168 2026] [security2:error] [pid 738779:tid 739010] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJb_xa4UbeLxj1SWXFdQAAAOo"]
[Thu Jul 30 12:27:11.194167 2026] [security2:error] [pid 738779:tid 739005] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-content/themes/index.php"] [unique_id "amuJb_xa4UbeLxj1SWXFdwAAAOU"]
[Thu Jul 30 12:27:11.194326 2026] [security2:error] [pid 738779:tid 739005] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-content/themes/index.php"] [unique_id "amuJb_xa4UbeLxj1SWXFdwAAAOU"]
[Thu Jul 30 12:27:11.225651 2026] [security2:error] [pid 738779:tid 738975] [client 52.238.199.152:17759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/css.php"] [unique_id "amuJb_xa4UbeLxj1SWXFeAAAAMc"]
[Thu Jul 30 12:27:11.288939 2026] [security2:error] [pid 738779:tid 738960] [client 20.52.54.143:9224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aaa.php"] [unique_id "amuJb_xa4UbeLxj1SWXFfAAAALg"]
[Thu Jul 30 12:27:11.339579 2026] [security2:error] [pid 738779:tid 738934] [client 142.93.53.183:62699] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/build/assets/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJb_xa4UbeLxj1SWXFfgAAAJ4"]
[Thu Jul 30 12:27:11.462530 2026] [security2:error] [pid 738779:tid 739013] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/av.php"] [unique_id "amuJb_xa4UbeLxj1SWXFggAAAO0"]
[Thu Jul 30 12:27:11.462632 2026] [security2:error] [pid 738779:tid 739013] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/av.php"] [unique_id "amuJb_xa4UbeLxj1SWXFggAAAO0"]
[Thu Jul 30 12:27:11.465179 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-admin/js/index.php"] [unique_id "amuJb_xa4UbeLxj1SWXFgwAAAIc"]
[Thu Jul 30 12:27:11.465254 2026] [security2:error] [pid 738779:tid 738911] [client 20.100.169.152:44158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/wp-admin/js/index.php"] [unique_id "amuJb_xa4UbeLxj1SWXFgwAAAIc"]
[Thu Jul 30 12:27:11.714197 2026] [security2:error] [pid 738779:tid 738997] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJb_xa4UbeLxj1SWXFhAAAAN0"]
[Thu Jul 30 12:27:11.727386 2026] [security2:error] [pid 738779:tid 738935] [client 142.93.53.183:62705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/build/assets/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJb_xa4UbeLxj1SWXFhQAAAJ8"]
[Thu Jul 30 12:27:11.815389 2026] [security2:error] [pid 738779:tid 739015] [client 20.100.169.152:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/puc.php"] [unique_id "amuJb_xa4UbeLxj1SWXFiQAAAO8"]
[Thu Jul 30 12:27:11.815492 2026] [security2:error] [pid 738779:tid 739015] [client 20.100.169.152:44126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/puc.php"] [unique_id "amuJb_xa4UbeLxj1SWXFiQAAAO8"]
[Thu Jul 30 12:27:11.852221 2026] [security2:error] [pid 738779:tid 738972] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "tiger388.shop"] [uri "/cgi-sys/404.html"] [unique_id "amuJb_xa4UbeLxj1SWXFigAAAMQ"]
[Thu Jul 30 12:27:11.991806 2026] [security2:error] [pid 738779:tid 739002] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/tiny.php"] [unique_id "amuJb_xa4UbeLxj1SWXFjgAAAOI"]
[Thu Jul 30 12:27:11.991921 2026] [security2:error] [pid 738779:tid 739002] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/tiny.php"] [unique_id "amuJb_xa4UbeLxj1SWXFjgAAAOI"]
[Thu Jul 30 12:27:12.120864 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:62709] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/swagger-api/swagger-ui/src/core/presets/base/plugins/form-components/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJcPxa4UbeLxj1SWXFkAAAAIs"]
[Thu Jul 30 12:27:12.145275 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:44144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dx.php"] [unique_id "amuJcPxa4UbeLxj1SWXFkQAAALc"]
[Thu Jul 30 12:27:12.145369 2026] [security2:error] [pid 738779:tid 738959] [client 20.100.169.152:44144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/dx.php"] [unique_id "amuJcPxa4UbeLxj1SWXFkQAAALc"]
[Thu Jul 30 12:27:12.437723 2026] [security2:error] [pid 738779:tid 738941] [client 20.52.54.143:9964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/getid3-core.php"] [unique_id "amuJcPxa4UbeLxj1SWXFlQAAAKU"]
[Thu Jul 30 12:27:12.500637 2026] [security2:error] [pid 738779:tid 738981] [client 20.100.169.152:48861] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webmail/wp-includes/Requests/"] [unique_id "amuJcPxa4UbeLxj1SWXFlwAAAM0"]
[Thu Jul 30 12:27:12.511679 2026] [security2:error] [pid 738779:tid 738933] [client 142.93.53.183:62714] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/swagger-api/swagger-ui/src/core/presets/base/plugins/form-components/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJcPxa4UbeLxj1SWXFnQAAAJ0"]
[Thu Jul 30 12:27:12.705637 2026] [security2:error] [pid 738779:tid 738966] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuJcPxa4UbeLxj1SWXFngAAAL4"]
[Thu Jul 30 12:27:12.705785 2026] [security2:error] [pid 738779:tid 738966] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuJcPxa4UbeLxj1SWXFngAAAL4"]
[Thu Jul 30 12:27:12.799012 2026] [security2:error] [pid 738779:tid 739029] [client 20.100.169.152:48861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/7.php"] [unique_id "amuJcPxa4UbeLxj1SWXFowAAAP0"]
[Thu Jul 30 12:27:12.799131 2026] [security2:error] [pid 738779:tid 739029] [client 20.100.169.152:48861] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/7.php"] [unique_id "amuJcPxa4UbeLxj1SWXFowAAAP0"]
[Thu Jul 30 12:27:12.878809 2026] [security2:error] [pid 738779:tid 738895] [remote 57.141.0.3:22556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/4627290655/feed/rss2/"] [unique_id "amuJcPxa4UbeLxj1SWXFqAAAsXM"]
[Thu Jul 30 12:27:12.903722 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:62717] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/vendor/swagger-api/swagger-ui/src/core/presets/base/plugins/form-components/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJcPxa4UbeLxj1SWXFqQAAAP8"]
[Thu Jul 30 12:27:12.987509 2026] [security2:error] [pid 738779:tid 738918] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/zrrhj.php"] [unique_id "amuJcPxa4UbeLxj1SWXFqgAAAI4"]
[Thu Jul 30 12:27:12.987630 2026] [security2:error] [pid 738779:tid 738918] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/zrrhj.php"] [unique_id "amuJcPxa4UbeLxj1SWXFqgAAAI4"]
[Thu Jul 30 12:27:13.068754 2026] [security2:error] [pid 738779:tid 738988] [client 20.52.54.143:9935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/adminer.php"] [unique_id "amuJcfxa4UbeLxj1SWXFrgAAANQ"]
[Thu Jul 30 12:27:13.107666 2026] [security2:error] [pid 738779:tid 739007] [client 20.100.169.152:48876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/8.php"] [unique_id "amuJcfxa4UbeLxj1SWXFrwAAAOc"]
[Thu Jul 30 12:27:13.107754 2026] [security2:error] [pid 738779:tid 739007] [client 20.100.169.152:48876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/8.php"] [unique_id "amuJcfxa4UbeLxj1SWXFrwAAAOc"]
[Thu Jul 30 12:27:13.137498 2026] [security2:error] [pid 738779:tid 739003] [client 169.224.38.239:20408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJcPxa4UbeLxj1SWXFpAAAAOM"], referer: http://pkf.jo
[Thu Jul 30 12:27:13.172406 2026] [security2:error] [pid 738779:tid 739026] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJcPxa4UbeLxj1SWXFnwAA-go"]
[Thu Jul 30 12:27:13.241641 2026] [security2:error] [pid 738779:tid 739018] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuJcfxa4UbeLxj1SWXFsAAAAPI"]
[Thu Jul 30 12:27:13.241750 2026] [security2:error] [pid 738779:tid 739018] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuJcfxa4UbeLxj1SWXFsAAAAPI"]
[Thu Jul 30 12:27:13.282691 2026] [security2:error] [pid 738779:tid 738963] [client 142.93.53.183:62721] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJcfxa4UbeLxj1SWXFsQAAALs"]
[Thu Jul 30 12:27:13.413180 2026] [security2:error] [pid 738779:tid 738952] [client 52.238.199.152:38908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuJcfxa4UbeLxj1SWXFtQAAALA"]
[Thu Jul 30 12:27:13.470623 2026] [security2:error] [pid 738779:tid 738975] [client 20.100.169.152:48884] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/1.php"] [unique_id "amuJcfxa4UbeLxj1SWXFtgAAAMc"]
[Thu Jul 30 12:27:13.470752 2026] [security2:error] [pid 738779:tid 738975] [client 20.100.169.152:48884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/1.php"] [unique_id "amuJcfxa4UbeLxj1SWXFtgAAAMc"]
[Thu Jul 30 12:27:13.470845 2026] [security2:error] [pid 738779:tid 738975] [client 20.100.169.152:48884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/1.php"] [unique_id "amuJcfxa4UbeLxj1SWXFtgAAAMc"]
[Thu Jul 30 12:27:13.490750 2026] [core:notice] [pid 738779:tid 738922] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:13.495894 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wpgum.php"] [unique_id "amuJcfxa4UbeLxj1SWXFuAAAAKc"]
[Thu Jul 30 12:27:13.495967 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wpgum.php"] [unique_id "amuJcfxa4UbeLxj1SWXFuAAAAKc"]
[Thu Jul 30 12:27:13.669152 2026] [security2:error] [pid 738779:tid 739013] [client 142.93.53.183:62727] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJcfxa4UbeLxj1SWXFvAAAAO0"]
[Thu Jul 30 12:27:13.758875 2026] [proxy:error] [pid 738779:tid 738986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:13.758964 2026] [proxy_http:error] [pid 738779:tid 738986] [client 20.52.54.143:10227] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:13.759525 2026] [proxy:error] [pid 738779:tid 738986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:13.759570 2026] [proxy_http:error] [pid 738779:tid 738986] [client 20.52.54.143:10227] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:13.826557 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:48865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/about.php"] [unique_id "amuJcfxa4UbeLxj1SWXFvgAAAKM"]
[Thu Jul 30 12:27:13.826667 2026] [security2:error] [pid 738779:tid 738939] [client 20.100.169.152:48865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/about.php"] [unique_id "amuJcfxa4UbeLxj1SWXFvgAAAKM"]
[Thu Jul 30 12:27:14.058524 2026] [security2:error] [pid 738779:tid 739016] [client 142.93.53.183:62736] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/livewire/plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJcvxa4UbeLxj1SWXFxAAAAPA"]
[Thu Jul 30 12:27:14.215462 2026] [security2:error] [pid 738779:tid 738935] [client 52.238.199.152:38848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuJcvxa4UbeLxj1SWXFxgAAAJ8"]
[Thu Jul 30 12:27:14.238110 2026] [security2:error] [pid 738779:tid 738945] [client 20.100.169.152:44138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/admin.php"] [unique_id "amuJcvxa4UbeLxj1SWXFxwAAAKk"]
[Thu Jul 30 12:27:14.238198 2026] [security2:error] [pid 738779:tid 738945] [client 20.100.169.152:44138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/admin.php"] [unique_id "amuJcvxa4UbeLxj1SWXFxwAAAKk"]
[Thu Jul 30 12:27:14.448175 2026] [security2:error] [pid 738779:tid 738936] [client 142.93.53.183:62740] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/livewire/plugins/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuJcvxa4UbeLxj1SWXFywAAAKA"]
[Thu Jul 30 12:27:14.552862 2026] [security2:error] [pid 738779:tid 738983] [client 20.100.169.152:61538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/edit.php"] [unique_id "amuJcvxa4UbeLxj1SWXFzAAAAM8"]
[Thu Jul 30 12:27:14.552991 2026] [security2:error] [pid 738779:tid 738983] [client 20.100.169.152:61538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.trustedmoversandpackersabudhabi.online"] [uri "/edit.php"] [unique_id "amuJcvxa4UbeLxj1SWXFzAAAAM8"]
[Thu Jul 30 12:27:14.839897 2026] [security2:error] [pid 738779:tid 738990] [client 142.93.53.183:62746] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/public/vendor/livewire/plugins/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJcvxa4UbeLxj1SWXF0AAAANY"]
[Thu Jul 30 12:27:15.048529 2026] [security2:error] [pid 738779:tid 738805] [remote 192.250.239.173:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.239.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "azeempinksalt.com"] [uri "/wp-login.php"] [unique_id "amuJc_xa4UbeLxj1SWXF1AAAhhk"]
[Thu Jul 30 12:27:15.230403 2026] [security2:error] [pid 738779:tid 739019] [client 142.93.53.183:62748] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/lightweight/fonts/Raleway/ONIC_ESPORT/haxorcgiapi/perl.haxor"] [unique_id "amuJc_xa4UbeLxj1SWXF2AAAAPM"]
[Thu Jul 30 12:27:15.487851 2026] [security2:error] [pid 738779:tid 738965] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ywwbf.php"] [unique_id "amuJc_xa4UbeLxj1SWXF3wAAAL0"]
[Thu Jul 30 12:27:15.487939 2026] [security2:error] [pid 738779:tid 738965] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ywwbf.php"] [unique_id "amuJc_xa4UbeLxj1SWXF3wAAAL0"]
[Thu Jul 30 12:27:15.622068 2026] [security2:error] [pid 738779:tid 738950] [client 142.93.53.183:62752] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/lightweight/fonts/Raleway/ONIC_ESPORT/haxorcgiapi/py.haxor"] [unique_id "amuJc_xa4UbeLxj1SWXF4AAAAK4"]
[Thu Jul 30 12:27:15.660420 2026] [security2:error] [pid 738779:tid 738929] [client 52.238.199.152:38899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuJc_xa4UbeLxj1SWXF5AAAAJk"]
[Thu Jul 30 12:27:16.012794 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:62753] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/template/lightweight/fonts/Raleway/ONIC_ESPORT/haxorcgiapi/bash.haxor"] [unique_id "amuJdPxa4UbeLxj1SWXF5wAAALo"]
[Thu Jul 30 12:27:16.218946 2026] [security2:error] [pid 738779:tid 738931] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJc_xa4UbeLxj1SWXF5QAAmx0"]
[Thu Jul 30 12:27:16.341168 2026] [security2:error] [pid 738779:tid 738917] [client 20.52.54.143:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/alfa.php"] [unique_id "amuJdPxa4UbeLxj1SWXF7gAAAI0"]
[Thu Jul 30 12:27:16.400794 2026] [security2:error] [pid 738779:tid 739024] [client 142.93.53.183:62757] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/tmp_images/alfacgiapi/perl.alfa"] [unique_id "amuJdPxa4UbeLxj1SWXF7wAAAPg"]
[Thu Jul 30 12:27:16.782267 2026] [security2:error] [pid 738779:tid 738954] [client 142.93.53.183:62761] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/elementor/includes/elements/cache/mr_skk/alfacgiapi/perl.alfa"] [unique_id "amuJdPxa4UbeLxj1SWXF-AAAALI"]
[Thu Jul 30 12:27:17.023971 2026] [security2:error] [pid 738779:tid 738958] [client 103.215.74.26:41722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amuJdPxa4UbeLxj1SWXF9wAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:27:17.165088 2026] [security2:error] [pid 738779:tid 738935] [client 142.93.53.183:62764] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/plugins/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJdfxa4UbeLxj1SWXF_wAAAJ8"]
[Thu Jul 30 12:27:17.215271 2026] [security2:error] [pid 738779:tid 738911] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJdPxa4UbeLxj1SWXF8wAAhxs"]
[Thu Jul 30 12:27:17.267905 2026] [security2:error] [pid 738779:tid 738995] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/xoldj.php"] [unique_id "amuJdfxa4UbeLxj1SWXGAwAAANs"]
[Thu Jul 30 12:27:17.268031 2026] [security2:error] [pid 738779:tid 738995] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/xoldj.php"] [unique_id "amuJdfxa4UbeLxj1SWXGAwAAANs"]
[Thu Jul 30 12:27:17.558301 2026] [security2:error] [pid 738779:tid 738915] [client 142.93.53.183:62766] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/plugins/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuJdfxa4UbeLxj1SWXGBAAAAIs"]
[Thu Jul 30 12:27:17.646382 2026] [security2:error] [pid 738779:tid 739036] [client 52.238.199.152:17777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/network/about.php"] [unique_id "amuJdfxa4UbeLxj1SWXGCAAAAQQ"]
[Thu Jul 30 12:27:17.786918 2026] [security2:error] [pid 738779:tid 738942] [client 103.215.74.26:41730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/blog/wp-login.php"] [unique_id "amuJdfxa4UbeLxj1SWXGDAAAAKY"], referer: https://carnetdeshopping.com/blog/
[Thu Jul 30 12:27:17.875183 2026] [security2:error] [pid 738779:tid 739028] [client 52.91.80.94:50078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "milfordauto.com"] [uri "/"] [unique_id "amuJdfxa4UbeLxj1SWXGDQAAAPw"]
[Thu Jul 30 12:27:17.949038 2026] [security2:error] [pid 738779:tid 738933] [client 142.93.53.183:62769] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/languages/plugins/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJdfxa4UbeLxj1SWXGDgAAAJ0"]
[Thu Jul 30 12:27:18.021135 2026] [core:error] [pid 738779:tid 738966] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:27:18.021158 2026] [core:error] [pid 738779:tid 738966] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:27:18.336484 2026] [security2:error] [pid 738779:tid 738965] [client 142.93.53.183:62771] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/timeline-awesome/public/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuJdvxa4UbeLxj1SWXGGAAAAL0"]
[Thu Jul 30 12:27:18.535479 2026] [security2:error] [pid 738779:tid 739001] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/f35.php"] [unique_id "amuJdvxa4UbeLxj1SWXGGgAAAOE"]
[Thu Jul 30 12:27:18.535600 2026] [security2:error] [pid 738779:tid 739001] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/f35.php"] [unique_id "amuJdvxa4UbeLxj1SWXGGgAAAOE"]
[Thu Jul 30 12:27:18.552595 2026] [security2:error] [pid 738779:tid 738953] [client 103.215.74.26:41740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wordpress/wp-login.php"] [unique_id "amuJdvxa4UbeLxj1SWXGGwAAALE"], referer: https://carnetdeshopping.com/wordpress/
[Thu Jul 30 12:27:18.574267 2026] [proxy:error] [pid 738779:tid 738984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:18.574341 2026] [proxy_http:error] [pid 738779:tid 738984] [client 20.52.54.143:10176] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:18.574884 2026] [proxy:error] [pid 738779:tid 738984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:18.574927 2026] [proxy_http:error] [pid 738779:tid 738984] [client 20.52.54.143:10176] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:18.634045 2026] [security2:error] [pid 738779:tid 739031] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJdvxa4UbeLxj1SWXGFQAA_zQ"]
[Thu Jul 30 12:27:18.730254 2026] [security2:error] [pid 738779:tid 739011] [client 142.93.53.183:62772] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/timeline-awesome/public/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuJdvxa4UbeLxj1SWXGIAAAAOs"]
[Thu Jul 30 12:27:18.774777 2026] [core:notice] [pid 738779:tid 738959] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:18.864429 2026] [security2:error] [pid 738779:tid 738926] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gk.php"] [unique_id "amuJdvxa4UbeLxj1SWXGIgAAAJY"]
[Thu Jul 30 12:27:18.864573 2026] [security2:error] [pid 738779:tid 738926] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gk.php"] [unique_id "amuJdvxa4UbeLxj1SWXGIgAAAJY"]
[Thu Jul 30 12:27:19.021804 2026] [security2:error] [pid 738779:tid 738957] [client 52.238.199.152:59076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/xpw.php"] [unique_id "amuJd_xa4UbeLxj1SWXGJgAAALU"]
[Thu Jul 30 12:27:19.120897 2026] [security2:error] [pid 738779:tid 738952] [client 142.93.53.183:62777] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/wp-content/plugins/timeline-awesome/public/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuJd_xa4UbeLxj1SWXGJwAAALA"]
[Thu Jul 30 12:27:19.165050 2026] [security2:error] [pid 738779:tid 738931] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/584062352875874akp.php"] [unique_id "amuJd_xa4UbeLxj1SWXGKAAAAJs"]
[Thu Jul 30 12:27:19.165148 2026] [security2:error] [pid 738779:tid 738931] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/584062352875874akp.php"] [unique_id "amuJd_xa4UbeLxj1SWXGKAAAAJs"]
[Thu Jul 30 12:27:19.335596 2026] [security2:error] [pid 738779:tid 739010] [client 103.215.74.26:41744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp/wp-login.php"] [unique_id "amuJd_xa4UbeLxj1SWXGLAAAAOo"], referer: https://carnetdeshopping.com/wp/
[Thu Jul 30 12:27:19.439714 2026] [security2:error] [pid 738779:tid 739006] [client 20.52.54.143:9983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuJd_xa4UbeLxj1SWXGMAAAAOY"]
[Thu Jul 30 12:27:19.463575 2026] [security2:error] [pid 738779:tid 738986] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wper3.php"] [unique_id "amuJd_xa4UbeLxj1SWXGMQAAANI"]
[Thu Jul 30 12:27:19.463670 2026] [security2:error] [pid 738779:tid 738986] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wper3.php"] [unique_id "amuJd_xa4UbeLxj1SWXGMQAAANI"]
[Thu Jul 30 12:27:19.494039 2026] [security2:error] [pid 738779:tid 738934] [client 142.93.53.183:62780] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/pubIds/doi/locale/cs_CZ/ERENUSE/Erencgiapi/perl.Eren"] [unique_id "amuJd_xa4UbeLxj1SWXGMgAAAJ4"]
[Thu Jul 30 12:27:19.731440 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/bthil.php"] [unique_id "amuJd_xa4UbeLxj1SWXGNgAAAMU"]
[Thu Jul 30 12:27:19.731539 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/bthil.php"] [unique_id "amuJd_xa4UbeLxj1SWXGNgAAAMU"]
[Thu Jul 30 12:27:19.884725 2026] [security2:error] [pid 738779:tid 739015] [client 142.93.53.183:62786] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/pubIds/doi/locale/cs_CZ/ERENUSE/Erencgiapi/py.Eren"] [unique_id "amuJd_xa4UbeLxj1SWXGNwAAAO8"]
[Thu Jul 30 12:27:20.013044 2026] [security2:error] [pid 738779:tid 738911] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wyzer1.php"] [unique_id "amuJePxa4UbeLxj1SWXGPgAAAIc"]
[Thu Jul 30 12:27:20.013151 2026] [security2:error] [pid 738779:tid 738911] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wyzer1.php"] [unique_id "amuJePxa4UbeLxj1SWXGPgAAAIc"]
[Thu Jul 30 12:27:20.101460 2026] [security2:error] [pid 738779:tid 738978] [client 103.215.74.26:41760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/cms/wp-login.php"] [unique_id "amuJePxa4UbeLxj1SWXGQgAAAMo"], referer: https://carnetdeshopping.com/cms/
[Thu Jul 30 12:27:20.258661 2026] [security2:error] [pid 738779:tid 739008] [client 142.93.53.183:62791] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/plugins/pubIds/doi/locale/cs_CZ/ERENUSE/Erencgiapi/bash.Eren"] [unique_id "amuJePxa4UbeLxj1SWXGRgAAAOg"]
[Thu Jul 30 12:27:20.307960 2026] [security2:error] [pid 738779:tid 739025] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/mh.php"] [unique_id "amuJePxa4UbeLxj1SWXGRwAAAPk"]
[Thu Jul 30 12:27:20.308080 2026] [security2:error] [pid 738779:tid 739025] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/mh.php"] [unique_id "amuJePxa4UbeLxj1SWXGRwAAAPk"]
[Thu Jul 30 12:27:20.395296 2026] [security2:error] [pid 738779:tid 738935] [client 20.52.54.143:9953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuJePxa4UbeLxj1SWXGSQAAAJ8"]
[Thu Jul 30 12:27:20.651826 2026] [security2:error] [pid 738779:tid 738927] [client 142.93.53.183:62792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/journals/2/articles/566/submission/LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuJePxa4UbeLxj1SWXGTgAAAJc"]
[Thu Jul 30 12:27:20.697499 2026] [security2:error] [pid 738779:tid 738812] [remote 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJePxa4UbeLxj1SWXGSAABACA"]
[Thu Jul 30 12:27:20.863595 2026] [security2:error] [pid 738779:tid 738933] [client 103.215.74.26:41764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/site/wp-login.php"] [unique_id "amuJePxa4UbeLxj1SWXGUgAAAJ0"], referer: https://carnetdeshopping.com/site/
[Thu Jul 30 12:27:21.040275 2026] [security2:error] [pid 738779:tid 738955] [client 142.93.53.183:62797] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/journals/2/articles/566/submission/LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuJefxa4UbeLxj1SWXGVgAAALM"]
[Thu Jul 30 12:27:21.072002 2026] [security2:error] [pid 738779:tid 738909] [client 20.52.54.143:9355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuJefxa4UbeLxj1SWXGVwAAAIU"]
[Thu Jul 30 12:27:21.268560 2026] [security2:error] [pid 738779:tid 738970] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuJefxa4UbeLxj1SWXGWgAAAMI"]
[Thu Jul 30 12:27:21.268660 2026] [security2:error] [pid 738779:tid 738970] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuJefxa4UbeLxj1SWXGWgAAAMI"]
[Thu Jul 30 12:27:21.412325 2026] [security2:error] [pid 738779:tid 738999] [client 52.238.199.152:38864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-cron.php"] [unique_id "amuJefxa4UbeLxj1SWXGXgAAAN8"]
[Thu Jul 30 12:27:21.433111 2026] [security2:error] [pid 738779:tid 739031] [client 142.93.53.183:62799] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "toscanamall.com"] [uri "/files/journals/2/articles/566/submission/LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuJefxa4UbeLxj1SWXGXwAAAP8"]
[Thu Jul 30 12:27:21.518759 2026] [security2:error] [pid 738779:tid 739011] [client 172.213.244.85:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tiger388.shop"] [uri "/1.php"] [unique_id "amuJefxa4UbeLxj1SWXGYAAAAOs"]
[Thu Jul 30 12:27:21.518890 2026] [security2:error] [pid 738779:tid 739011] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/1.php"] [unique_id "amuJefxa4UbeLxj1SWXGYAAAAOs"]
[Thu Jul 30 12:27:21.519039 2026] [security2:error] [pid 738779:tid 739011] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/1.php"] [unique_id "amuJefxa4UbeLxj1SWXGYAAAAOs"]
[Thu Jul 30 12:27:21.590782 2026] [core:notice] [pid 738779:tid 738981] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:21.613230 2026] [security2:error] [pid 738779:tid 739016] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "journeywomenscenter.org"] [uri "/index.php"] [unique_id "amuJd_xa4UbeLxj1SWXGPQAAAPA"]
[Thu Jul 30 12:27:21.629400 2026] [security2:error] [pid 738779:tid 738953] [client 103.215.74.26:41774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/main/wp-login.php"] [unique_id "amuJefxa4UbeLxj1SWXGZQAAALE"], referer: https://carnetdeshopping.com/main/
[Thu Jul 30 12:27:21.814246 2026] [security2:error] [pid 738779:tid 738971] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/chosen.php"] [unique_id "amuJefxa4UbeLxj1SWXGaQAAAMM"]
[Thu Jul 30 12:27:21.814352 2026] [security2:error] [pid 738779:tid 738971] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/chosen.php"] [unique_id "amuJefxa4UbeLxj1SWXGaQAAAMM"]
[Thu Jul 30 12:27:22.063596 2026] [security2:error] [pid 738779:tid 738917] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJefxa4UbeLxj1SWXGbQAAAI0"]
[Thu Jul 30 12:27:22.066565 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/sd.php"] [unique_id "amuJevxa4UbeLxj1SWXGcgAAAKc"]
[Thu Jul 30 12:27:22.066653 2026] [security2:error] [pid 738779:tid 738943] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/sd.php"] [unique_id "amuJevxa4UbeLxj1SWXGcgAAAKc"]
[Thu Jul 30 12:27:22.086043 2026] [security2:error] [pid 738779:tid 738952] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/kcfinder/upload.php"] [unique_id "amuJefxa4UbeLxj1SWXGagAAALA"]
[Thu Jul 30 12:27:22.189276 2026] [security2:error] [pid 738779:tid 738958] [client 62.102.148.166:59484] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuJevxa4UbeLxj1SWXGcwAAALY"]
[Thu Jul 30 12:27:22.189389 2026] [security2:error] [pid 738779:tid 738958] [client 62.102.148.166:59484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuJevxa4UbeLxj1SWXGcwAAALY"]
[Thu Jul 30 12:27:22.279944 2026] [security2:error] [pid 738779:tid 738923] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/admin/kcfinder/upload.php"] [unique_id "amuJevxa4UbeLxj1SWXGdAAAAJM"]
[Thu Jul 30 12:27:22.342820 2026] [security2:error] [pid 738779:tid 738914] [client 103.215.74.26:41778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/new/wp-login.php"] [unique_id "amuJevxa4UbeLxj1SWXGeAAAAIo"], referer: https://carnetdeshopping.com/new/
[Thu Jul 30 12:27:22.356236 2026] [security2:error] [pid 738779:tid 738997] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/z60.php"] [unique_id "amuJevxa4UbeLxj1SWXGeQAAAN0"]
[Thu Jul 30 12:27:22.356330 2026] [security2:error] [pid 738779:tid 738997] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/z60.php"] [unique_id "amuJevxa4UbeLxj1SWXGeQAAAN0"]
[Thu Jul 30 12:27:22.473030 2026] [security2:error] [pid 738779:tid 738911] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/js/kcfinder/upload.php"] [unique_id "amuJevxa4UbeLxj1SWXGegAAAIc"]
[Thu Jul 30 12:27:22.619060 2026] [security2:error] [pid 738779:tid 739010] [client 20.52.54.143:9933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/edit.php"] [unique_id "amuJevxa4UbeLxj1SWXGfgAAAOo"]
[Thu Jul 30 12:27:22.640721 2026] [security2:error] [pid 738779:tid 738951] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/home.php"] [unique_id "amuJevxa4UbeLxj1SWXGfwAAAK8"]
[Thu Jul 30 12:27:22.640814 2026] [security2:error] [pid 738779:tid 738951] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/home.php"] [unique_id "amuJevxa4UbeLxj1SWXGfwAAAK8"]
[Thu Jul 30 12:27:22.667106 2026] [security2:error] [pid 738779:tid 738948] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/lists/admin/plugins/CKEditorPlugin/kcfinder/upload.php"] [unique_id "amuJevxa4UbeLxj1SWXGgAAAAKw"]
[Thu Jul 30 12:27:22.804106 2026] [security2:error] [pid 738779:tid 738940] [client 37.120.155.179:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuJevxa4UbeLxj1SWXGgQAAAKQ"]
[Thu Jul 30 12:27:22.804234 2026] [security2:error] [pid 738779:tid 738940] [client 37.120.155.179:59944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuJevxa4UbeLxj1SWXGgQAAAKQ"]
[Thu Jul 30 12:27:22.819019 2026] [security2:error] [pid 738779:tid 738841] [remote 74.7.241.59:35652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuJevxa4UbeLxj1SWXGggAA6D0"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:27:22.859081 2026] [security2:error] [pid 738779:tid 738942] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/css/kcfinder/upload.php"] [unique_id "amuJevxa4UbeLxj1SWXGhAAAAKY"]
[Thu Jul 30 12:27:22.877579 2026] [security2:error] [pid 738779:tid 738976] [client 103.215.74.26:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amuJevxa4UbeLxj1SWXGhQAAAMg"], referer: http://carnetdeshopping.com/
[Thu Jul 30 12:27:23.052295 2026] [security2:error] [pid 738779:tid 739028] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/assets/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGiQAAAPw"]
[Thu Jul 30 12:27:23.245543 2026] [security2:error] [pid 738779:tid 738921] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/vendor/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGjQAAAJE"]
[Thu Jul 30 12:27:23.325757 2026] [proxy:error] [pid 738779:tid 739032] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:23.325836 2026] [proxy_http:error] [pid 738779:tid 739032] [client 20.52.54.143:10123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:23.326405 2026] [proxy:error] [pid 738779:tid 739032] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:23.326450 2026] [proxy_http:error] [pid 738779:tid 739032] [client 20.52.54.143:10123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:23.377810 2026] [security2:error] [pid 738779:tid 738955] [client 103.215.74.26:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/blog/wp-login.php"] [unique_id "amuJe_xa4UbeLxj1SWXGkAAAALM"], referer: http://carnetdeshopping.com/blog/
[Thu Jul 30 12:27:23.438138 2026] [security2:error] [pid 738779:tid 738912] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/js/vendor/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGkwAAAIg"]
[Thu Jul 30 12:27:23.484045 2026] [security2:error] [pid 738779:tid 739025] [client 38.190.144.4:52477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJe_xa4UbeLxj1SWXGlgAAAPk"]
[Thu Jul 30 12:27:23.484167 2026] [security2:error] [pid 738779:tid 739025] [client 38.190.144.4:52477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJe_xa4UbeLxj1SWXGlgAAAPk"]
[Thu Jul 30 12:27:23.632129 2026] [security2:error] [pid 738779:tid 738947] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/ckeditor/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGlwAAAKs"]
[Thu Jul 30 12:27:23.712490 2026] [security2:error] [pid 738779:tid 738929] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ws58.php"] [unique_id "amuJe_xa4UbeLxj1SWXGnAAAAJk"]
[Thu Jul 30 12:27:23.712591 2026] [security2:error] [pid 738779:tid 738929] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ws58.php"] [unique_id "amuJe_xa4UbeLxj1SWXGnAAAAJk"]
[Thu Jul 30 12:27:23.825702 2026] [security2:error] [pid 738779:tid 738920] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/webboard/plugins/editors/kcfinder/upload.php"] [unique_id "amuJe_xa4UbeLxj1SWXGngAAAJA"]
[Thu Jul 30 12:27:23.871530 2026] [security2:error] [pid 738779:tid 739016] [client 103.215.74.26:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wordpress/wp-login.php"] [unique_id "amuJe_xa4UbeLxj1SWXGnwAAAPA"], referer: http://carnetdeshopping.com/wordpress/
[Thu Jul 30 12:27:23.963355 2026] [security2:error] [pid 738779:tid 738860] [remote 151.158.180.11:47826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.180.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuJe_xa4UbeLxj1SWXGpgAAqFA"]
[Thu Jul 30 12:27:23.981564 2026] [core:notice] [pid 738779:tid 738845] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:23.986359 2026] [security2:error] [pid 738779:tid 738963] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/gulu.php"] [unique_id "amuJe_xa4UbeLxj1SWXGqAAAALs"]
[Thu Jul 30 12:27:23.986440 2026] [security2:error] [pid 738779:tid 738963] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/gulu.php"] [unique_id "amuJe_xa4UbeLxj1SWXGqAAAALs"]
[Thu Jul 30 12:27:24.011708 2026] [security2:error] [pid 738779:tid 739019] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJe_xa4UbeLxj1SWXGmwAA800"]
[Thu Jul 30 12:27:24.019449 2026] [security2:error] [pid 738779:tid 738930] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/admin/editor/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGqQAAAJo"]
[Thu Jul 30 12:27:24.025456 2026] [security2:error] [pid 738779:tid 738858] [remote 65.60.36.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.36.60.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "megasuppliesdistrict.com"] [uri "/wp-login.php"] [unique_id "amuJfPxa4UbeLxj1SWXGqgAAzU4"]
[Thu Jul 30 12:27:24.085182 2026] [core:notice] [pid 738779:tid 738985] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:24.212779 2026] [security2:error] [pid 738779:tid 738975] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/ckeditor/plugins/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGrwAAAMc"]
[Thu Jul 30 12:27:24.289415 2026] [security2:error] [pid 738779:tid 738917] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuJfPxa4UbeLxj1SWXGsAAAAI0"]
[Thu Jul 30 12:27:24.289526 2026] [security2:error] [pid 738779:tid 738917] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuJfPxa4UbeLxj1SWXGsAAAAI0"]
[Thu Jul 30 12:27:24.350123 2026] [security2:error] [pid 738779:tid 738986] [client 103.215.74.26:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp/wp-login.php"] [unique_id "amuJfPxa4UbeLxj1SWXGsQAAANI"], referer: http://carnetdeshopping.com/wp/
[Thu Jul 30 12:27:24.406556 2026] [security2:error] [pid 738779:tid 738962] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/admin-panel/vendor/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGsgAAALo"]
[Thu Jul 30 12:27:24.567775 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wpls.php"] [unique_id "amuJfPxa4UbeLxj1SWXGtwAAAMU"]
[Thu Jul 30 12:27:24.567873 2026] [security2:error] [pid 738779:tid 738973] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wpls.php"] [unique_id "amuJfPxa4UbeLxj1SWXGtwAAAMU"]
[Thu Jul 30 12:27:24.599614 2026] [security2:error] [pid 738779:tid 738958] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/assets/plugin/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGuAAAALY"]
[Thu Jul 30 12:27:24.792579 2026] [security2:error] [pid 738779:tid 739035] [client 142.93.53.183:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toscanamall.com"] [uri "/plugins/kcfinder/upload.php"] [unique_id "amuJfPxa4UbeLxj1SWXGvwAAAQM"]
[Thu Jul 30 12:27:24.807577 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00493: SIGUSR1 received.  Doing graceful restart
[Thu Jul 30 12:27:24.859827 2026] [security2:error] [pid 738779:tid 738924] [client 52.238.199.152:41254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/cah.php"] [unique_id "amuJfPxa4UbeLxj1SWXGwAAAAJQ"]
[Thu Jul 30 12:27:25.398904 2026] [security2:error] [pid 738779:tid 738863] [remote 57.141.0.17:49066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJffxa4UbeLxj1SWXGwQAAoVM"], referer: https://igetvape-australia.com/product-category/iget-bar-pro/?add-to-cart=112
[Thu Jul 30 12:27:25.891011 2026] [:notice] [pid 738754:tid 738754] [host root@sh00085.hostgator.com] mod_lsapi:  Selfstarter 738754 stopped
[Thu Jul 30 12:27:28.220860 2026] [lsapi:notice] [pid 8929:tid 8929] mod_lsapi:  version 1.1-92
[Thu Jul 30 12:27:28.223609 2026] [:notice] [pid 751894:tid 751894] [host root@sh00085.hostgator.com] mod_lsapi:  Selfstarter 751894 started
[Thu Jul 30 12:27:28.615653 2026] [ssl:warn] [pid 8929:tid 8929] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Jul 30 12:27:28.623001 2026] [qos:notice] [pid 8929:tid 8929] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Jul 30 12:27:28.790809 2026] [http2:info] [pid 8929:tid 8929] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Thu Jul 30 12:27:28.794153 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Jul 30 12:27:28.794172 2026] [core:notice] [pid 8929:tid 8929] AH00094: Command line: '/usr/sbin/httpd'
[Thu Jul 30 12:27:29.840411 2026] [http2:info] [pid 751901:tid 751901] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:27:29.868502 2026] [security2:error] [pid 751901:tid 752032] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/php.php"] [unique_id "amuJgSrT982lovRn7gmxCAAAAAE"]
[Thu Jul 30 12:27:29.868814 2026] [security2:error] [pid 751901:tid 752031] [client 103.215.74.26:62856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/cms/wp-login.php"] [unique_id "amuJgSrT982lovRn7gmxBwAAAAA"], referer: http://carnetdeshopping.com/cms/
[Thu Jul 30 12:27:29.868882 2026] [security2:error] [pid 751901:tid 752032] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/php.php"] [unique_id "amuJgSrT982lovRn7gmxCAAAAAE"]
[Thu Jul 30 12:27:29.869809 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:29.870624 2026] [security2:error] [pid 751901:tid 752039] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJgSrT982lovRn7gmxCwAAAAg"]
[Thu Jul 30 12:27:29.870763 2026] [security2:error] [pid 751901:tid 752039] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuJgSrT982lovRn7gmxCwAAAAg"]
[Thu Jul 30 12:27:29.964844 2026] [security2:error] [pid 751901:tid 752048] [client 103.82.26.211:55527] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.tereasshop.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amuJgSrT982lovRn7gmxEAAAABE"]
[Thu Jul 30 12:27:30.060727 2026] [security2:error] [pid 751901:tid 751908] [remote 216.73.216.152:40909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuJgirT982lovRn7gmxFgAAGQY"]
[Thu Jul 30 12:27:30.120360 2026] [security2:error] [pid 751901:tid 752042] [client 52.238.199.152:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/cong.php"] [unique_id "amuJgirT982lovRn7gmxIgAAAAs"]
[Thu Jul 30 12:27:30.121229 2026] [security2:error] [pid 751901:tid 752083] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/100.php"] [unique_id "amuJgirT982lovRn7gmxKAAAADQ"]
[Thu Jul 30 12:27:30.121294 2026] [security2:error] [pid 751901:tid 752080] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJgirT982lovRn7gmxKQAAADE"]
[Thu Jul 30 12:27:30.121456 2026] [security2:error] [pid 751901:tid 752083] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/100.php"] [unique_id "amuJgirT982lovRn7gmxKAAAADQ"]
[Thu Jul 30 12:27:30.121633 2026] [security2:error] [pid 751901:tid 752080] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuJgirT982lovRn7gmxKQAAADE"]
[Thu Jul 30 12:27:30.123158 2026] [core:notice] [pid 751901:tid 751917] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:30.317295 2026] [security2:error] [pid 751901:tid 752100] [client 103.82.26.211:55982] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.tereasshop.com"] [uri "/___proxy_subdomain_cpcalendars/wp-json/batch/v1"] [unique_id "amuJgirT982lovRn7gmxOQAAAEU"]
[Thu Jul 30 12:27:30.352702 2026] [security2:error] [pid 751901:tid 752114] [client 103.215.74.26:62858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/site/wp-login.php"] [unique_id "amuJgirT982lovRn7gmxOgAAAFM"], referer: http://carnetdeshopping.com/site/
[Thu Jul 30 12:27:30.375706 2026] [security2:error] [pid 751901:tid 752118] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuJgirT982lovRn7gmxPQAAAFc"]
[Thu Jul 30 12:27:30.375816 2026] [security2:error] [pid 751901:tid 752118] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuJgirT982lovRn7gmxPQAAAFc"]
[Thu Jul 30 12:27:30.380784 2026] [security2:error] [pid 751901:tid 751918] [remote 57.141.0.5:37904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/index/login"] [unique_id "amuJgirT982lovRn7gmxJwAAGxA"]
[Thu Jul 30 12:27:30.392005 2026] [security2:error] [pid 751901:tid 752043] [client 220.181.108.103:45077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/user/register"] [unique_id "amuJgSrT982lovRn7gmxDAAAAAw"]
[Thu Jul 30 12:27:30.483374 2026] [security2:error] [pid 751901:tid 752040] [client 36.32.3.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJgirT982lovRn7gmxJAAACQ4"]
[Thu Jul 30 12:27:30.611334 2026] [security2:error] [pid 751901:tid 752146] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/media.php"] [unique_id "amuJgirT982lovRn7gmxSwAAAHM"]
[Thu Jul 30 12:27:30.611472 2026] [security2:error] [pid 751901:tid 752146] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/media.php"] [unique_id "amuJgirT982lovRn7gmxSwAAAHM"]
[Thu Jul 30 12:27:30.692889 2026] [proxy:error] [pid 751901:tid 752045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:30.692954 2026] [proxy_http:error] [pid 751901:tid 752045] [client 20.52.54.143:10201] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:30.693593 2026] [proxy:error] [pid 751901:tid 752045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:30.693638 2026] [proxy_http:error] [pid 751901:tid 752045] [client 20.52.54.143:10201] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:30.781498 2026] [security2:error] [pid 751901:tid 752091] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJgirT982lovRn7gmxMAAAADw"]
[Thu Jul 30 12:27:30.868658 2026] [security2:error] [pid 751901:tid 752039] [client 103.215.74.26:62864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/main/wp-login.php"] [unique_id "amuJgirT982lovRn7gmxTwAAAAg"], referer: http://carnetdeshopping.com/main/
[Thu Jul 30 12:27:31.014748 2026] [security2:error] [pid 751901:tid 752119] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJgirT982lovRn7gmxPgAAAFg"]
[Thu Jul 30 12:27:31.097214 2026] [security2:error] [pid 751901:tid 752031] [client 119.249.100.110:27400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/user/register"] [unique_id "amuJgirT982lovRn7gmxTgAAAAA"]
[Thu Jul 30 12:27:31.149887 2026] [security2:error] [pid 751901:tid 752076] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/images.php"] [unique_id "amuJgyrT982lovRn7gmxVwAAAC0"]
[Thu Jul 30 12:27:31.150012 2026] [security2:error] [pid 751901:tid 752076] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/images.php"] [unique_id "amuJgyrT982lovRn7gmxVwAAAC0"]
[Thu Jul 30 12:27:31.209161 2026] [security2:error] [pid 751901:tid 752149] [client 38.190.144.4:52975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJgyrT982lovRn7gmxWAAAAHY"]
[Thu Jul 30 12:27:31.210593 2026] [security2:error] [pid 751901:tid 752149] [client 38.190.144.4:52975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJgyrT982lovRn7gmxWAAAAHY"]
[Thu Jul 30 12:27:31.404632 2026] [security2:error] [pid 751901:tid 752081] [client 103.215.74.26:62876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/new/wp-login.php"] [unique_id "amuJgyrT982lovRn7gmxWgAAADI"], referer: http://carnetdeshopping.com/new/
[Thu Jul 30 12:27:31.606512 2026] [security2:error] [pid 751901:tid 752065] [client 20.52.54.143:10178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/sf.php"] [unique_id "amuJgyrT982lovRn7gmxYgAAACI"]
[Thu Jul 30 12:27:31.987165 2026] [security2:error] [pid 751901:tid 752083] [client 119.249.100.177:21305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/user/register"] [unique_id "amuJgyrT982lovRn7gmxWwAAADQ"]
[Thu Jul 30 12:27:32.128923 2026] [core:notice] [pid 751901:tid 751937] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:32.147364 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:32.354134 2026] [security2:error] [pid 751901:tid 751941] [remote 216.73.216.152:40909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuJhCrT982lovRn7gmxcwAADCc"]
[Thu Jul 30 12:27:32.373659 2026] [security2:error] [pid 751901:tid 752099] [client 85.208.96.211:44350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/01/22/comunicado-streaming-das-radios-rural-e-cultura-passam-por-manutencao-e-ficam-fora-do-ar/"] [unique_id "amuJhCrT982lovRn7gmxdAAAAEQ"]
[Thu Jul 30 12:27:32.373827 2026] [security2:error] [pid 751901:tid 752099] [client 85.208.96.211:44350] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/01/22/comunicado-streaming-das-radios-rural-e-cultura-passam-por-manutencao-e-ficam-fora-do-ar/"] [unique_id "amuJhCrT982lovRn7gmxdAAAAEQ"]
[Thu Jul 30 12:27:32.465579 2026] [proxy:error] [pid 751901:tid 752103] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:32.465674 2026] [proxy_http:error] [pid 751901:tid 752103] [client 20.52.54.143:9387] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:32.466611 2026] [proxy:error] [pid 751901:tid 752103] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:32.466683 2026] [proxy_http:error] [pid 751901:tid 752103] [client 20.52.54.143:9387] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:32.621799 2026] [security2:error] [pid 751901:tid 752100] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJhCrT982lovRn7gmxcgAARSY"]
[Thu Jul 30 12:27:32.642445 2026] [security2:error] [pid 751901:tid 752137] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/BDKR28WP.php"] [unique_id "amuJhCrT982lovRn7gmxfgAAAGo"]
[Thu Jul 30 12:27:32.642573 2026] [security2:error] [pid 751901:tid 752137] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/BDKR28WP.php"] [unique_id "amuJhCrT982lovRn7gmxfgAAAGo"]
[Thu Jul 30 12:27:32.934967 2026] [security2:error] [pid 751901:tid 752142] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/browse.php"] [unique_id "amuJhCrT982lovRn7gmxgAAAAG8"]
[Thu Jul 30 12:27:32.935376 2026] [security2:error] [pid 751901:tid 752142] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/browse.php"] [unique_id "amuJhCrT982lovRn7gmxgAAAAG8"]
[Thu Jul 30 12:27:33.243557 2026] [security2:error] [pid 751901:tid 752057] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-good.php"] [unique_id "amuJhSrT982lovRn7gmxhwAAABo"]
[Thu Jul 30 12:27:33.243696 2026] [security2:error] [pid 751901:tid 752057] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-good.php"] [unique_id "amuJhSrT982lovRn7gmxhwAAABo"]
[Thu Jul 30 12:27:33.267384 2026] [security2:error] [pid 751901:tid 752062] [client 20.52.54.143:9978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wso.php"] [unique_id "amuJhSrT982lovRn7gmxiAAAAB8"]
[Thu Jul 30 12:27:33.557236 2026] [security2:error] [pid 751901:tid 752085] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/8573.php"] [unique_id "amuJhSrT982lovRn7gmxigAAADY"]
[Thu Jul 30 12:27:33.557382 2026] [security2:error] [pid 751901:tid 752085] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/8573.php"] [unique_id "amuJhSrT982lovRn7gmxigAAADY"]
[Thu Jul 30 12:27:33.830005 2026] [security2:error] [pid 751901:tid 752069] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-admin/install.php"] [unique_id "amuJhSrT982lovRn7gmxkgAAACY"]
[Thu Jul 30 12:27:33.830128 2026] [security2:error] [pid 751901:tid 752069] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-admin/install.php"] [unique_id "amuJhSrT982lovRn7gmxkgAAACY"]
[Thu Jul 30 12:27:33.930476 2026] [security2:error] [pid 751901:tid 752125] [client 5.161.75.7:29620] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuJhCrT982lovRn7gmxegAAAF4"], referer: https://globalmarks.pk/
[Thu Jul 30 12:27:34.060305 2026] [security2:error] [pid 751901:tid 752035] [client 20.52.54.143:9979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ioxi-o.php"] [unique_id "amuJhirT982lovRn7gmxkwAAAAQ"]
[Thu Jul 30 12:27:34.135449 2026] [core:notice] [pid 751901:tid 752119] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:34.143823 2026] [security2:error] [pid 751901:tid 752039] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJhSrT982lovRn7gmxkQAACC4"]
[Thu Jul 30 12:27:34.216863 2026] [security2:error] [pid 751901:tid 752068] [client 52.238.199.152:59085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/Sanskrit.php"] [unique_id "amuJhirT982lovRn7gmxnAAAACU"]
[Thu Jul 30 12:27:34.295330 2026] [security2:error] [pid 751901:tid 752042] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/classwithtostring.php"] [unique_id "amuJhirT982lovRn7gmxnQAAAAs"]
[Thu Jul 30 12:27:34.295432 2026] [security2:error] [pid 751901:tid 752042] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/classwithtostring.php"] [unique_id "amuJhirT982lovRn7gmxnQAAAAs"]
[Thu Jul 30 12:27:34.570771 2026] [security2:error] [pid 751901:tid 752075] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ohct.php"] [unique_id "amuJhirT982lovRn7gmxngAAACw"]
[Thu Jul 30 12:27:34.570938 2026] [security2:error] [pid 751901:tid 752075] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ohct.php"] [unique_id "amuJhirT982lovRn7gmxngAAACw"]
[Thu Jul 30 12:27:34.860853 2026] [security2:error] [pid 751901:tid 752088] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/bless.php"] [unique_id "amuJhirT982lovRn7gmxpQAAADk"]
[Thu Jul 30 12:27:34.860994 2026] [security2:error] [pid 751901:tid 752088] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/bless.php"] [unique_id "amuJhirT982lovRn7gmxpQAAADk"]
[Thu Jul 30 12:27:35.138694 2026] [security2:error] [pid 751901:tid 752140] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/about.php"] [unique_id "amuJhyrT982lovRn7gmxpwAAAG0"]
[Thu Jul 30 12:27:35.138801 2026] [security2:error] [pid 751901:tid 752140] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/about.php"] [unique_id "amuJhyrT982lovRn7gmxpwAAAG0"]
[Thu Jul 30 12:27:35.355822 2026] [security2:error] [pid 751901:tid 752078] [client 52.238.199.152:59087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ms-edit.php"] [unique_id "amuJhyrT982lovRn7gmxrwAAAC8"]
[Thu Jul 30 12:27:35.386386 2026] [security2:error] [pid 751901:tid 752107] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuJhyrT982lovRn7gmxsAAAAEw"]
[Thu Jul 30 12:27:35.386470 2026] [security2:error] [pid 751901:tid 752107] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuJhyrT982lovRn7gmxsAAAAEw"]
[Thu Jul 30 12:27:35.444423 2026] [security2:error] [pid 751901:tid 751955] [remote 68.67.112.200:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "fantasynamelist.com"] [uri "/robots.txt"] [unique_id "amuJhyrT982lovRn7gmxsQAAEzU"]
[Thu Jul 30 12:27:35.654663 2026] [security2:error] [pid 751901:tid 752103] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ta0ol.php"] [unique_id "amuJhyrT982lovRn7gmxtAAAAEg"]
[Thu Jul 30 12:27:35.654805 2026] [security2:error] [pid 751901:tid 752103] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ta0ol.php"] [unique_id "amuJhyrT982lovRn7gmxtAAAAEg"]
[Thu Jul 30 12:27:35.875630 2026] [security2:error] [pid 751901:tid 752060] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJhyrT982lovRn7gmxsgAAHTY"]
[Thu Jul 30 12:27:36.105969 2026] [core:notice] [pid 751901:tid 752148] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:36.708430 2026] [security2:error] [pid 751901:tid 752062] [client 20.52.54.143:9966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/file56.php"] [unique_id "amuJiCrT982lovRn7gmxxAAAAB8"]
[Thu Jul 30 12:27:36.757728 2026] [security2:error] [pid 751901:tid 752054] [client 103.143.50.219:39072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJiCrT982lovRn7gmxwgAAABc"], referer: http://pkf.jo
[Thu Jul 30 12:27:37.208883 2026] [security2:error] [pid 751901:tid 751967] [remote 74.7.241.60:52164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuJiSrT982lovRn7gmx0AAAI0E"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:27:37.280933 2026] [security2:error] [pid 751901:tid 752081] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/sa.php7"] [unique_id "amuJiSrT982lovRn7gmx1AAAADI"]
[Thu Jul 30 12:27:37.281112 2026] [security2:error] [pid 751901:tid 752081] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/sa.php7"] [unique_id "amuJiSrT982lovRn7gmx1AAAADI"]
[Thu Jul 30 12:27:37.283837 2026] [security2:error] [pid 751901:tid 752033] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJiCrT982lovRn7gmxygAAAj8"]
[Thu Jul 30 12:27:37.351527 2026] [security2:error] [pid 751901:tid 752068] [client 94.205.206.193:57324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJiSrT982lovRn7gmxzgAAACU"], referer: http://pkf.jo
[Thu Jul 30 12:27:37.440061 2026] [security2:error] [pid 751901:tid 752079] [client 52.238.199.152:18288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/function.php"] [unique_id "amuJiSrT982lovRn7gmx2QAAADA"]
[Thu Jul 30 12:27:37.471257 2026] [security2:error] [pid 751901:tid 752064] [client 20.52.54.143:9352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuJiSrT982lovRn7gmx2gAAACE"]
[Thu Jul 30 12:27:37.542870 2026] [security2:error] [pid 751901:tid 752092] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-class.php"] [unique_id "amuJiSrT982lovRn7gmx3gAAAD0"]
[Thu Jul 30 12:27:37.542992 2026] [security2:error] [pid 751901:tid 752092] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-class.php"] [unique_id "amuJiSrT982lovRn7gmx3gAAAD0"]
[Thu Jul 30 12:27:37.813295 2026] [security2:error] [pid 751901:tid 752037] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJiSrT982lovRn7gmxzwAABkA"]
[Thu Jul 30 12:27:37.829392 2026] [security2:error] [pid 751901:tid 752115] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/8.php"] [unique_id "amuJiSrT982lovRn7gmx5AAAAFQ"]
[Thu Jul 30 12:27:37.829508 2026] [security2:error] [pid 751901:tid 752115] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/8.php"] [unique_id "amuJiSrT982lovRn7gmx5AAAAFQ"]
[Thu Jul 30 12:27:37.894128 2026] [security2:error] [pid 751901:tid 752114] [client 127.0.0.1:25514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJiSrT982lovRn7gmx5gAAAFM"]
[Thu Jul 30 12:27:37.894264 2026] [security2:error] [pid 751901:tid 752098] [client 74.7.228.39:41338] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.progroupdoha.com"] [uri "/robots.txt"] [unique_id "amuJiSrT982lovRn7gmx5QAAQ0g"]
[Thu Jul 30 12:27:38.096753 2026] [security2:error] [pid 751901:tid 752129] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/bootstrap.php"] [unique_id "amuJiirT982lovRn7gmx7QAAAGI"]
[Thu Jul 30 12:27:38.096883 2026] [security2:error] [pid 751901:tid 752129] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/bootstrap.php"] [unique_id "amuJiirT982lovRn7gmx7QAAAGI"]
[Thu Jul 30 12:27:38.133866 2026] [security2:error] [pid 751901:tid 752058] [client 103.215.74.26:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-login.php"] [unique_id "amuJiirT982lovRn7gmx7gAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:27:38.317941 2026] [security2:error] [pid 751901:tid 752128] [client 46.191.152.215:55655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJiirT982lovRn7gmx7AAAAGE"], referer: http://pkf.jo
[Thu Jul 30 12:27:38.568690 2026] [security2:error] [pid 751901:tid 752040] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJiirT982lovRn7gmx7wAACUs"]
[Thu Jul 30 12:27:38.615390 2026] [security2:error] [pid 751901:tid 752136] [client 52.238.199.152:51546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ee.php"] [unique_id "amuJiirT982lovRn7gmx9gAAAGk"]
[Thu Jul 30 12:27:38.629136 2026] [security2:error] [pid 751901:tid 752083] [client 74.7.244.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-a21e6513.evk.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuJiSrT982lovRn7gmx3QAAADQ"]
[Thu Jul 30 12:27:38.629857 2026] [security2:error] [pid 751901:tid 752080] [client 74.7.244.15:51520] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-a21e6513.evk.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuJiSrT982lovRn7gmx2wAAMUU"]
[Thu Jul 30 12:27:38.687788 2026] [security2:error] [pid 751901:tid 752148] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-blog-header.php"] [unique_id "amuJiirT982lovRn7gmx9wAAAHU"]
[Thu Jul 30 12:27:38.687903 2026] [security2:error] [pid 751901:tid 752148] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-blog-header.php"] [unique_id "amuJiirT982lovRn7gmx9wAAAHU"]
[Thu Jul 30 12:27:38.885163 2026] [core:notice] [pid 751901:tid 752150] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:38.966567 2026] [security2:error] [pid 751901:tid 752091] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/aa.php"] [unique_id "amuJiirT982lovRn7gmyAAAAADw"]
[Thu Jul 30 12:27:38.966678 2026] [security2:error] [pid 751901:tid 752091] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/aa.php"] [unique_id "amuJiirT982lovRn7gmyAAAAADw"]
[Thu Jul 30 12:27:39.246289 2026] [security2:error] [pid 751901:tid 752117] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/tx79.php"] [unique_id "amuJiyrT982lovRn7gmyBAAAAFY"]
[Thu Jul 30 12:27:39.246444 2026] [security2:error] [pid 751901:tid 752117] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/tx79.php"] [unique_id "amuJiyrT982lovRn7gmyBAAAAFY"]
[Thu Jul 30 12:27:39.528695 2026] [security2:error] [pid 751901:tid 752076] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/motu.php"] [unique_id "amuJiyrT982lovRn7gmyCAAAAC0"]
[Thu Jul 30 12:27:39.528789 2026] [security2:error] [pid 751901:tid 752076] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/motu.php"] [unique_id "amuJiyrT982lovRn7gmyCAAAAC0"]
[Thu Jul 30 12:27:39.616823 2026] [security2:error] [pid 751901:tid 752103] [client 20.52.54.143:9942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuJiyrT982lovRn7gmyDAAAAEg"]
[Thu Jul 30 12:27:39.827798 2026] [security2:error] [pid 751901:tid 752073] [client 127.0.0.1:25554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJiyrT982lovRn7gmyEAAAACo"]
[Thu Jul 30 12:27:39.827825 2026] [security2:error] [pid 751901:tid 752084] [client 127.0.0.1:25540] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ghggeneralcontracting.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJiyrT982lovRn7gmyDwAAADU"]
[Thu Jul 30 12:27:39.828228 2026] [security2:error] [pid 751901:tid 752042] [client 74.7.228.58:33806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ghggeneralcontracting.com"] [uri "/robots.txt"] [unique_id "amuJiyrT982lovRn7gmyDgAAC1Q"]
[Thu Jul 30 12:27:39.910895 2026] [security2:error] [pid 751901:tid 752094] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-head.php"] [unique_id "amuJiyrT982lovRn7gmyFgAAAD8"]
[Thu Jul 30 12:27:39.911009 2026] [security2:error] [pid 751901:tid 752094] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-head.php"] [unique_id "amuJiyrT982lovRn7gmyFgAAAD8"]
[Thu Jul 30 12:27:40.162402 2026] [security2:error] [pid 751901:tid 752104] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuJjCrT982lovRn7gmyHgAAAEk"]
[Thu Jul 30 12:27:40.162537 2026] [security2:error] [pid 751901:tid 752104] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuJjCrT982lovRn7gmyHgAAAEk"]
[Thu Jul 30 12:27:40.164901 2026] [security2:error] [pid 751901:tid 752075] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJiyrT982lovRn7gmyEQAALFU"]
[Thu Jul 30 12:27:40.417942 2026] [security2:error] [pid 751901:tid 752110] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/60856e3a4findex.php"] [unique_id "amuJjCrT982lovRn7gmyHwAAAE8"]
[Thu Jul 30 12:27:40.418087 2026] [security2:error] [pid 751901:tid 752110] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/60856e3a4findex.php"] [unique_id "amuJjCrT982lovRn7gmyHwAAAE8"]
[Thu Jul 30 12:27:40.687761 2026] [security2:error] [pid 751901:tid 752098] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-the.php"] [unique_id "amuJjCrT982lovRn7gmyJgAAAEM"]
[Thu Jul 30 12:27:40.687929 2026] [security2:error] [pid 751901:tid 752098] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp-the.php"] [unique_id "amuJjCrT982lovRn7gmyJgAAAEM"]
[Thu Jul 30 12:27:40.927558 2026] [core:notice] [pid 751901:tid 752059] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:40.937617 2026] [security2:error] [pid 751901:tid 752106] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp.php"] [unique_id "amuJjCrT982lovRn7gmyKAAAAEs"]
[Thu Jul 30 12:27:40.937710 2026] [security2:error] [pid 751901:tid 752106] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wp.php"] [unique_id "amuJjCrT982lovRn7gmyKAAAAEs"]
[Thu Jul 30 12:27:41.204111 2026] [core:error] [pid 751901:tid 752083] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.204140 2026] [core:error] [pid 751901:tid 752083] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.208392 2026] [security2:error] [pid 751901:tid 752151] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/users.php"] [unique_id "amuJjSrT982lovRn7gmyOAAAAHg"]
[Thu Jul 30 12:27:41.208489 2026] [security2:error] [pid 751901:tid 752151] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/users.php"] [unique_id "amuJjSrT982lovRn7gmyOAAAAHg"]
[Thu Jul 30 12:27:41.226342 2026] [core:error] [pid 751901:tid 752152] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.226359 2026] [core:error] [pid 751901:tid 752152] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.259497 2026] [core:error] [pid 751901:tid 752046] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.259517 2026] [core:error] [pid 751901:tid 752046] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:27:41.450573 2026] [core:notice] [pid 751901:tid 752072] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:41.469884 2026] [security2:error] [pid 751901:tid 752093] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/tinysd.php"] [unique_id "amuJjSrT982lovRn7gmySAAAAD4"]
[Thu Jul 30 12:27:41.470004 2026] [security2:error] [pid 751901:tid 752093] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/tinysd.php"] [unique_id "amuJjSrT982lovRn7gmySAAAAD4"]
[Thu Jul 30 12:27:41.700558 2026] [security2:error] [pid 751901:tid 752141] [client 220.167.233.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJjSrT982lovRn7gmyQwAAbl8"]
[Thu Jul 30 12:27:41.759559 2026] [security2:error] [pid 751901:tid 752051] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ws78.php"] [unique_id "amuJjSrT982lovRn7gmyUQAAABQ"]
[Thu Jul 30 12:27:41.759679 2026] [security2:error] [pid 751901:tid 752051] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ws78.php"] [unique_id "amuJjSrT982lovRn7gmyUQAAABQ"]
[Thu Jul 30 12:27:42.009217 2026] [security2:error] [pid 751901:tid 752068] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/elp.php"] [unique_id "amuJjirT982lovRn7gmyVQAAACU"]
[Thu Jul 30 12:27:42.009343 2026] [security2:error] [pid 751901:tid 752068] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/elp.php"] [unique_id "amuJjirT982lovRn7gmyVQAAACU"]
[Thu Jul 30 12:27:42.164495 2026] [security2:error] [pid 751901:tid 752035] [client 38.190.144.4:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJjirT982lovRn7gmyXAAAAAQ"]
[Thu Jul 30 12:27:42.165991 2026] [security2:error] [pid 751901:tid 752035] [client 38.190.144.4:53470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJjirT982lovRn7gmyXAAAAAQ"]
[Thu Jul 30 12:27:42.264804 2026] [security2:error] [pid 751901:tid 752102] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/atomlib.php"] [unique_id "amuJjirT982lovRn7gmyXQAAAEc"]
[Thu Jul 30 12:27:42.264907 2026] [security2:error] [pid 751901:tid 752102] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/atomlib.php"] [unique_id "amuJjirT982lovRn7gmyXQAAAEc"]
[Thu Jul 30 12:27:42.311797 2026] [core:notice] [pid 751901:tid 752005] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:42.564228 2026] [security2:error] [pid 751901:tid 752113] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wyzer3.php"] [unique_id "amuJjirT982lovRn7gmyYwAAAFI"]
[Thu Jul 30 12:27:42.564346 2026] [security2:error] [pid 751901:tid 752113] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/wyzer3.php"] [unique_id "amuJjirT982lovRn7gmyYwAAAFI"]
[Thu Jul 30 12:27:42.791582 2026] [security2:error] [pid 751901:tid 752109] [client 20.52.54.143:9934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/edit.php"] [unique_id "amuJjirT982lovRn7gmyagAAAE4"]
[Thu Jul 30 12:27:42.844961 2026] [security2:error] [pid 751901:tid 752122] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/max.php"] [unique_id "amuJjirT982lovRn7gmyawAAAFs"]
[Thu Jul 30 12:27:42.845094 2026] [security2:error] [pid 751901:tid 752122] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/max.php"] [unique_id "amuJjirT982lovRn7gmyawAAAFs"]
[Thu Jul 30 12:27:42.905481 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:43.121194 2026] [security2:error] [pid 751901:tid 752152] [client 172.213.244.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/ftde.php"] [unique_id "amuJjyrT982lovRn7gmycQAAAHk"]
[Thu Jul 30 12:27:43.121301 2026] [security2:error] [pid 751901:tid 752152] [client 172.213.244.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "tiger388.shop"] [uri "/ftde.php"] [unique_id "amuJjyrT982lovRn7gmycQAAAHk"]
[Thu Jul 30 12:27:44.053504 2026] [security2:error] [pid 751901:tid 752036] [client 20.52.54.143:10195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/2.php"] [unique_id "amuJkCrT982lovRn7gmyhgAAAAU"]
[Thu Jul 30 12:27:45.348628 2026] [security2:error] [pid 751901:tid 752123] [client 20.52.54.143:9961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuJkSrT982lovRn7gmypQAAAFw"]
[Thu Jul 30 12:27:45.700214 2026] [security2:error] [pid 751901:tid 752060] [client 52.238.199.152:48525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/new.php"] [unique_id "amuJkSrT982lovRn7gmyqAAAAB0"]
[Thu Jul 30 12:27:45.897206 2026] [security2:error] [pid 751901:tid 752151] [client 20.52.54.143:9929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/mah.php"] [unique_id "amuJkSrT982lovRn7gmysgAAAHg"]
[Thu Jul 30 12:27:45.985112 2026] [security2:error] [pid 751901:tid 752155] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJkSrT982lovRn7gmyrwAAAHw"]
[Thu Jul 30 12:27:46.591514 2026] [core:notice] [pid 751901:tid 751915] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:46.995202 2026] [security2:error] [pid 751901:tid 752119] [client 38.250.241.96:60726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJkirT982lovRn7gmyvQAAAFg"], referer: http://pkf.jo
[Thu Jul 30 12:27:47.161758 2026] [security2:error] [pid 751901:tid 752093] [client 34.44.142.114:43616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuJkirT982lovRn7gmyvgAAPg8"]
[Thu Jul 30 12:27:47.706684 2026] [security2:error] [pid 751901:tid 752044] [client 20.52.54.143:9356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/send.php"] [unique_id "amuJkyrT982lovRn7gmy1QAAAA0"]
[Thu Jul 30 12:27:47.819435 2026] [security2:error] [pid 751901:tid 751925] [remote 216.73.216.152:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuJkyrT982lovRn7gmy0gAAGhc"]
[Thu Jul 30 12:27:48.127493 2026] [security2:error] [pid 751901:tid 752107] [client 34.44.142.114:43616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuJkyrT982lovRn7gmyzQAATBU"]
[Thu Jul 30 12:27:48.306958 2026] [security2:error] [pid 751901:tid 752116] [client 20.52.54.143:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuJlCrT982lovRn7gmy4wAAAFU"]
[Thu Jul 30 12:27:48.882550 2026] [proxy:error] [pid 751901:tid 752136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:48.882645 2026] [proxy_http:error] [pid 751901:tid 752136] [client 20.52.54.143:10181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:48.883507 2026] [proxy:error] [pid 751901:tid 752136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:27:48.883566 2026] [proxy_http:error] [pid 751901:tid 752136] [client 20.52.54.143:10181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:27:49.931697 2026] [core:notice] [pid 751901:tid 752073] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:50.086016 2026] [security2:error] [pid 751901:tid 752056] [client 34.44.142.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuJlSrT982lovRn7gmy-AAAABk"]
[Thu Jul 30 12:27:50.347369 2026] [security2:error] [pid 751901:tid 752049] [client 52.238.199.152:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-config.php"] [unique_id "amuJlirT982lovRn7gmzCwAAABI"]
[Thu Jul 30 12:27:50.909642 2026] [security2:error] [pid 751901:tid 752082] [client 20.52.54.143:10184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/about.php"] [unique_id "amuJlirT982lovRn7gmzFQAAADM"]
[Thu Jul 30 12:27:51.314911 2026] [security2:error] [pid 751901:tid 752106] [client 52.238.199.152:17807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-conflg.php"] [unique_id "amuJlyrT982lovRn7gmzHgAAAEs"]
[Thu Jul 30 12:27:51.455501 2026] [security2:error] [pid 751901:tid 752060] [client 37.120.155.179:54720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuJlyrT982lovRn7gmzIAAAAB0"]
[Thu Jul 30 12:27:51.455610 2026] [security2:error] [pid 751901:tid 752060] [client 37.120.155.179:54720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuJlyrT982lovRn7gmzIAAAAB0"]
[Thu Jul 30 12:27:51.505131 2026] [security2:error] [pid 751901:tid 752035] [client 23.251.146.115:2385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuJlirT982lovRn7gmzDAAABAM"]
[Thu Jul 30 12:27:51.872858 2026] [core:notice] [pid 751901:tid 752154] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:52.311252 2026] [security2:error] [pid 751901:tid 752135] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJlyrT982lovRn7gmzJwAAaCQ"]
[Thu Jul 30 12:27:52.555159 2026] [core:notice] [pid 751901:tid 752083] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:52.863133 2026] [security2:error] [pid 751901:tid 752054] [client 23.251.146.115:2385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuJlyrT982lovRn7gmzKwAAFyc"]
[Thu Jul 30 12:27:53.127453 2026] [core:notice] [pid 751901:tid 752051] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:53.834300 2026] [security2:error] [pid 751901:tid 752032] [client 20.52.54.143:9217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/options.php"] [unique_id "amuJmSrT982lovRn7gmzVAAAAAE"]
[Thu Jul 30 12:27:53.997107 2026] [security2:error] [pid 751901:tid 752052] [client 38.190.144.4:53959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJmSrT982lovRn7gmzVgAAABU"]
[Thu Jul 30 12:27:53.999281 2026] [security2:error] [pid 751901:tid 752052] [client 38.190.144.4:53959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJmSrT982lovRn7gmzVgAAABU"]
[Thu Jul 30 12:27:54.445624 2026] [security2:error] [pid 751901:tid 752053] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuJmSrT982lovRn7gmzSgAAABY"]
[Thu Jul 30 12:27:55.243622 2026] [security2:error] [pid 751901:tid 752137] [client 74.7.244.31:36788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "greensparkle.net"] [uri "/robots.txt"] [unique_id "amuJmyrT982lovRn7gmzbwAAakM"]
[Thu Jul 30 12:27:55.268022 2026] [security2:error] [pid 751901:tid 752145] [client 127.0.0.1:57494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJmyrT982lovRn7gmzcAAAAHI"]
[Thu Jul 30 12:27:55.268096 2026] [security2:error] [pid 751901:tid 752048] [client 127.0.0.1:57488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bio.djb.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuJmyrT982lovRn7gmzbgAAABE"]
[Thu Jul 30 12:27:55.268156 2026] [security2:error] [pid 751901:tid 752098] [client 74.7.228.39:40622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bio.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuJmyrT982lovRn7gmzbQAAQz8"]
[Thu Jul 30 12:27:55.291536 2026] [security2:error] [pid 751901:tid 752121] [client 20.52.54.143:10180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuJmyrT982lovRn7gmzcQAAAFo"]
[Thu Jul 30 12:27:55.714328 2026] [security2:error] [pid 751901:tid 751974] [remote 184.168.126.180:41414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/wp-login.php"] [unique_id "amuJmyrT982lovRn7gmzeAAAJ0g"]
[Thu Jul 30 12:27:56.076648 2026] [security2:error] [pid 751901:tid 752133] [client 20.52.54.143:9377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/wp-file.php"] [unique_id "amuJnCrT982lovRn7gmzfwAAAGY"]
[Thu Jul 30 12:27:56.487595 2026] [security2:error] [pid 751901:tid 751981] [remote 5.161.62.209:23090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "arabiandubaisafari.com.khw.nyx.temporary.site"] [uri "/.env"] [unique_id "amuJnCrT982lovRn7gmzigAAGU8"]
[Thu Jul 30 12:27:56.698329 2026] [security2:error] [pid 751901:tid 752135] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJnCrT982lovRn7gmzgAAAaEw"]
[Thu Jul 30 12:27:57.150422 2026] [security2:error] [pid 751901:tid 751984] [remote 5.161.62.209:23098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "arabiantourz.com.khw.nyx.temporary.site"] [uri "/.env"] [unique_id "amuJnSrT982lovRn7gmzlgAAW1I"]
[Thu Jul 30 12:27:57.165386 2026] [security2:error] [pid 751901:tid 751985] [remote 5.161.62.209:23094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "arabiantourz.com"] [uri "/.env"] [unique_id "amuJnSrT982lovRn7gmzlwAAa1M"]
[Thu Jul 30 12:27:57.569923 2026] [security2:error] [pid 751901:tid 752045] [client 52.238.199.152:40172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuJnSrT982lovRn7gmzpAAAAA4"]
[Thu Jul 30 12:27:57.816501 2026] [security2:error] [pid 751901:tid 752100] [client 20.52.54.143:10139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/sid3.php"] [unique_id "amuJnSrT982lovRn7gmzpgAAAEU"]
[Thu Jul 30 12:27:58.244776 2026] [security2:error] [pid 751901:tid 752080] [client 57.141.0.27:29820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuJnSrT982lovRn7gmzrQAAMVU"]
[Thu Jul 30 12:27:58.714252 2026] [core:notice] [pid 751901:tid 751994] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:58.843559 2026] [core:notice] [pid 751901:tid 752141] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:27:59.115761 2026] [security2:error] [pid 751901:tid 752059] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJnirT982lovRn7gmzuQAAHF0"]
[Thu Jul 30 12:27:59.351177 2026] [security2:error] [pid 751901:tid 752023] [remote 208.109.9.173:42618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuJnyrT982lovRn7gmz2gAAAnk"]
[Thu Jul 30 12:28:00.631571 2026] [security2:error] [pid 751901:tid 751903] [remote 57.141.0.32:26922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5033157679/feed/rss2/"] [unique_id "amuJoCrT982lovRn7gm0AgAAFAE"]
[Thu Jul 30 12:28:00.801798 2026] [core:notice] [pid 751901:tid 752074] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:02.775522 2026] [core:notice] [pid 751901:tid 752068] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:03.312948 2026] [core:notice] [pid 751901:tid 751950] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:03.334771 2026] [security2:error] [pid 751901:tid 752088] [client 52.238.199.152:17972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuJoyrT982lovRn7gm0PAAAADk"]
[Thu Jul 30 12:28:03.754493 2026] [security2:error] [pid 751901:tid 752118] [client 38.190.144.4:54456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJoyrT982lovRn7gm0RAAAAFc"]
[Thu Jul 30 12:28:03.754613 2026] [security2:error] [pid 751901:tid 752118] [client 38.190.144.4:54456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJoyrT982lovRn7gm0RAAAAFc"]
[Thu Jul 30 12:28:04.422872 2026] [security2:error] [pid 751901:tid 752130] [client 52.238.199.152:17426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuJpCrT982lovRn7gm0SwAAAGM"]
[Thu Jul 30 12:28:04.489625 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:04.764489 2026] [security2:error] [pid 751901:tid 752144] [client 103.215.74.26:28298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuJpCrT982lovRn7gm0UwAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:05.013165 2026] [security2:error] [pid 751901:tid 752077] [client 43.173.180.41:33726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/01/03/bonne-annee-2012/"] [unique_id "amuJpCrT982lovRn7gm0VAAAAC4"]
[Thu Jul 30 12:28:05.500986 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:05.554275 2026] [core:notice] [pid 751901:tid 752158] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:05.559667 2026] [security2:error] [pid 751901:tid 752158] [client 43.172.194.119:57926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/01/03/bonne-annee-2012/"] [unique_id "amuJpSrT982lovRn7gm0YgAAAH8"], referer: https://carnetdeshopping.com/index.php/2012/01/03/bonne-annee-2012/
[Thu Jul 30 12:28:05.727542 2026] [security2:error] [pid 751901:tid 752051] [client 52.238.199.152:18091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuJpSrT982lovRn7gm0aQAAABQ"]
[Thu Jul 30 12:28:06.769971 2026] [security2:error] [pid 751901:tid 752090] [client 52.238.199.152:18084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/manager.php"] [unique_id "amuJpirT982lovRn7gm0ewAAADs"]
[Thu Jul 30 12:28:07.525882 2026] [security2:error] [pid 751901:tid 752042] [client 85.208.96.195:24396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/02/20/robo-perseverance-envia-primeiras-fotos-coloridas-de-marte/"] [unique_id "amuJpyrT982lovRn7gm0gwAAAAs"]
[Thu Jul 30 12:28:07.526026 2026] [security2:error] [pid 751901:tid 752042] [client 85.208.96.195:24396] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/02/20/robo-perseverance-envia-primeiras-fotos-coloridas-de-marte/"] [unique_id "amuJpyrT982lovRn7gm0gwAAAAs"]
[Thu Jul 30 12:28:08.336698 2026] [security2:error] [pid 751901:tid 752097] [client 52.238.199.152:17408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-links.php"] [unique_id "amuJqCrT982lovRn7gm0lAAAAEI"]
[Thu Jul 30 12:28:08.840893 2026] [security2:error] [pid 751901:tid 751982] [remote 57.141.0.71:65038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/407345907/feed/rss2/"] [unique_id "amuJqCrT982lovRn7gm0nQAAeVA"]
[Thu Jul 30 12:28:09.866286 2026] [core:notice] [pid 751901:tid 752103] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:10.932939 2026] [security2:error] [pid 751901:tid 752081] [client 57.141.0.2:61608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJqirT982lovRn7gm0vgAAMls"], referer: https://igetvape-australia.com/?add-to-cart=919
[Thu Jul 30 12:28:11.121165 2026] [security2:error] [pid 751901:tid 752108] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJqyrT982lovRn7gm0ygAAAE0"]
[Thu Jul 30 12:28:11.121285 2026] [security2:error] [pid 751901:tid 752108] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJqyrT982lovRn7gm0ygAAAE0"]
[Thu Jul 30 12:28:11.686334 2026] [security2:error] [pid 751901:tid 752140] [client 52.238.199.152:17593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/fi2.php"] [unique_id "amuJqyrT982lovRn7gm02QAAAG0"]
[Thu Jul 30 12:28:12.473673 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:12.477575 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:28320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJrCrT982lovRn7gm05wAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:12.591873 2026] [security2:error] [pid 751901:tid 752009] [remote 216.73.216.152:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuJrCrT982lovRn7gm07gAABWs"]
[Thu Jul 30 12:28:13.053273 2026] [security2:error] [pid 751901:tid 752092] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/ops.php"] [unique_id "amuJrSrT982lovRn7gm09gAAAD0"]
[Thu Jul 30 12:28:13.053389 2026] [security2:error] [pid 751901:tid 752092] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/ops.php"] [unique_id "amuJrSrT982lovRn7gm09gAAAD0"]
[Thu Jul 30 12:28:13.176413 2026] [security2:error] [pid 751901:tid 752012] [remote 151.158.48.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.48.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aakmiddleast.com"] [uri "/wp-login.php"] [unique_id "amuJrSrT982lovRn7gm09wAANm4"]
[Thu Jul 30 12:28:13.210142 2026] [core:notice] [pid 751901:tid 752103] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:13.214393 2026] [security2:error] [pid 751901:tid 752103] [client 103.215.74.26:45498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJrSrT982lovRn7gm0-AAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:13.298068 2026] [security2:error] [pid 751901:tid 752078] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amuJrSrT982lovRn7gm0-QAAAC8"]
[Thu Jul 30 12:28:13.298222 2026] [security2:error] [pid 751901:tid 752078] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amuJrSrT982lovRn7gm0-QAAAC8"]
[Thu Jul 30 12:28:13.468933 2026] [security2:error] [pid 751901:tid 752098] [client 52.238.199.152:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/0x.php"] [unique_id "amuJrSrT982lovRn7gm0-wAAAEM"]
[Thu Jul 30 12:28:13.567780 2026] [security2:error] [pid 751901:tid 752038] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amuJrSrT982lovRn7gm1AgAAAAc"]
[Thu Jul 30 12:28:13.695699 2026] [security2:error] [pid 751901:tid 752096] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/pucci.php"] [unique_id "amuJrSrT982lovRn7gm1BAAAAEE"]
[Thu Jul 30 12:28:13.695815 2026] [security2:error] [pid 751901:tid 752096] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/pucci.php"] [unique_id "amuJrSrT982lovRn7gm1BAAAAEE"]
[Thu Jul 30 12:28:13.935514 2026] [security2:error] [pid 751901:tid 752095] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-admin/js/index.php"] [unique_id "amuJrSrT982lovRn7gm1BgAAAEA"]
[Thu Jul 30 12:28:13.935622 2026] [security2:error] [pid 751901:tid 752095] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-admin/js/index.php"] [unique_id "amuJrSrT982lovRn7gm1BgAAAEA"]
[Thu Jul 30 12:28:15.080867 2026] [security2:error] [pid 751901:tid 752158] [client 38.190.144.4:54971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJryrT982lovRn7gm1KgAAAH8"]
[Thu Jul 30 12:28:15.082995 2026] [security2:error] [pid 751901:tid 752158] [client 38.190.144.4:54971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJryrT982lovRn7gm1KgAAAH8"]
[Thu Jul 30 12:28:15.425594 2026] [security2:error] [pid 751901:tid 752120] [client 172.237.109.114:38705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1DQAAAFk"]
[Thu Jul 30 12:28:15.432514 2026] [security2:error] [pid 751901:tid 752082] [client 172.237.109.114:13889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1EAAAADM"]
[Thu Jul 30 12:28:15.432926 2026] [security2:error] [pid 751901:tid 752112] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amuJryrT982lovRn7gm1LwAAAFE"]
[Thu Jul 30 12:28:15.433097 2026] [security2:error] [pid 751901:tid 752112] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amuJryrT982lovRn7gm1LwAAAFE"]
[Thu Jul 30 12:28:15.440842 2026] [security2:error] [pid 751901:tid 752042] [client 172.237.109.114:17250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1DgAAAAs"]
[Thu Jul 30 12:28:15.460369 2026] [security2:error] [pid 751901:tid 752081] [client 172.237.109.114:57984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1EQAAADI"]
[Thu Jul 30 12:28:15.465154 2026] [security2:error] [pid 751901:tid 752132] [client 172.237.109.114:6210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrirT982lovRn7gm1GQAAAGU"]
[Thu Jul 30 12:28:15.502085 2026] [security2:error] [pid 751901:tid 752074] [client 172.237.109.114:46665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1DwAAACs"]
[Thu Jul 30 12:28:15.514375 2026] [security2:error] [pid 751901:tid 752124] [client 172.237.109.114:49170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrirT982lovRn7gm1GwAAAF0"]
[Thu Jul 30 12:28:15.522699 2026] [security2:error] [pid 751901:tid 752064] [client 172.237.109.114:58122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1GAAAACE"]
[Thu Jul 30 12:28:15.525238 2026] [security2:error] [pid 751901:tid 752056] [client 172.237.109.114:19638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1EwAAABk"]
[Thu Jul 30 12:28:15.546224 2026] [security2:error] [pid 751901:tid 752157] [client 172.237.109.114:63403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1CgAAAH4"]
[Thu Jul 30 12:28:15.548723 2026] [security2:error] [pid 751901:tid 752118] [client 172.237.109.114:6070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1CwAAAFc"]
[Thu Jul 30 12:28:15.552928 2026] [security2:error] [pid 751901:tid 752104] [client 172.237.109.114:16096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1FAAAAEk"]
[Thu Jul 30 12:28:15.567573 2026] [security2:error] [pid 751901:tid 752134] [client 172.237.109.114:27618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1DAAAAGc"]
[Thu Jul 30 12:28:15.594572 2026] [security2:error] [pid 751901:tid 752093] [client 172.237.109.114:11741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrirT982lovRn7gm1GgAAAD4"]
[Thu Jul 30 12:28:15.603506 2026] [security2:error] [pid 751901:tid 752033] [client 172.237.109.114:41053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1EgAAAAI"]
[Thu Jul 30 12:28:15.612805 2026] [security2:error] [pid 751901:tid 752108] [client 172.237.109.114:7701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1FwAAAE0"]
[Thu Jul 30 12:28:15.627178 2026] [security2:error] [pid 751901:tid 752109] [client 172.237.109.114:49659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1CQAAAE4"]
[Thu Jul 30 12:28:15.631258 2026] [security2:error] [pid 751901:tid 752152] [client 52.238.199.152:63373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/k.php"] [unique_id "amuJryrT982lovRn7gm1MwAAAHk"]
[Thu Jul 30 12:28:15.643011 2026] [security2:error] [pid 751901:tid 752057] [client 172.237.109.114:51836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1CAAAABo"]
[Thu Jul 30 12:28:15.666544 2026] [security2:error] [pid 751901:tid 752122] [client 172.237.109.114:25537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1FQAAAFs"]
[Thu Jul 30 12:28:15.683518 2026] [security2:error] [pid 751901:tid 752058] [client 172.237.109.114:25186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJrSrT982lovRn7gm1FgAAABs"]
[Thu Jul 30 12:28:15.684681 2026] [security2:error] [pid 751901:tid 752115] [client 20.203.133.142:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuJryrT982lovRn7gm1NwAAAFQ"]
[Thu Jul 30 12:28:15.684790 2026] [security2:error] [pid 751901:tid 752115] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuJryrT982lovRn7gm1NwAAAFQ"]
[Thu Jul 30 12:28:15.684896 2026] [security2:error] [pid 751901:tid 752115] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/1.php"] [unique_id "amuJryrT982lovRn7gm1NwAAAFQ"]
[Thu Jul 30 12:28:15.939493 2026] [security2:error] [pid 751901:tid 752102] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/admin.php"] [unique_id "amuJryrT982lovRn7gm1OwAAAEc"]
[Thu Jul 30 12:28:15.939593 2026] [security2:error] [pid 751901:tid 752102] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/admin.php"] [unique_id "amuJryrT982lovRn7gm1OwAAAEc"]
[Thu Jul 30 12:28:16.605680 2026] [security2:error] [pid 751901:tid 752123] [client 52.238.199.152:42952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/gecko-new.php"] [unique_id "amuJsCrT982lovRn7gm1TwAAAFw"]
[Thu Jul 30 12:28:17.589562 2026] [security2:error] [pid 751901:tid 751912] [remote 216.73.216.152:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuJsSrT982lovRn7gm1XQAAKwo"]
[Thu Jul 30 12:28:17.980726 2026] [security2:error] [pid 751901:tid 752082] [client 52.238.199.152:51665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/alfanew.php"] [unique_id "amuJsSrT982lovRn7gm1YQAAADM"]
[Thu Jul 30 12:28:18.437443 2026] [security2:error] [pid 751901:tid 752104] [client 85.208.96.211:64146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/29/bolsonaro-afirma-que-vai-respeitar-o-resultado-das-urnas-no-segundo-turno-quem-tiver-mais-voto-leva/"] [unique_id "amuJsirT982lovRn7gm1aQAAAEk"]
[Thu Jul 30 12:28:18.437598 2026] [security2:error] [pid 751901:tid 752104] [client 85.208.96.211:64146] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/29/bolsonaro-afirma-que-vai-respeitar-o-resultado-das-urnas-no-segundo-turno-quem-tiver-mais-voto-leva/"] [unique_id "amuJsirT982lovRn7gm1aQAAAEk"]
[Thu Jul 30 12:28:18.928465 2026] [core:notice] [pid 751901:tid 752049] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:18.933518 2026] [security2:error] [pid 751901:tid 752049] [client 103.215.74.26:45508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJsirT982lovRn7gm1cwAAABI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:19.648191 2026] [security2:error] [pid 751901:tid 752043] [client 104.254.90.251:33444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuJsyrT982lovRn7gm1gQAAAAw"]
[Thu Jul 30 12:28:19.648323 2026] [security2:error] [pid 751901:tid 752043] [client 104.254.90.251:33444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuJsyrT982lovRn7gm1gQAAAAw"]
[Thu Jul 30 12:28:19.663489 2026] [core:notice] [pid 751901:tid 752138] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:19.669862 2026] [security2:error] [pid 751901:tid 752138] [client 103.215.74.26:45512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJsyrT982lovRn7gm1ggAAAGs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:19.822586 2026] [security2:error] [pid 751901:tid 752143] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/themes/index.php"] [unique_id "amuJsyrT982lovRn7gm1hgAAAHA"]
[Thu Jul 30 12:28:19.822684 2026] [security2:error] [pid 751901:tid 752143] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-content/themes/index.php"] [unique_id "amuJsyrT982lovRn7gm1hgAAAHA"]
[Thu Jul 30 12:28:20.057391 2026] [security2:error] [pid 751901:tid 752066] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/222.php"] [unique_id "amuJtCrT982lovRn7gm1hwAAACM"]
[Thu Jul 30 12:28:20.057506 2026] [security2:error] [pid 751901:tid 752066] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/222.php"] [unique_id "amuJtCrT982lovRn7gm1hwAAACM"]
[Thu Jul 30 12:28:20.191460 2026] [security2:error] [pid 751901:tid 752142] [client 52.238.199.152:51666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/text.php"] [unique_id "amuJtCrT982lovRn7gm1jQAAAG8"]
[Thu Jul 30 12:28:20.310173 2026] [security2:error] [pid 751901:tid 752048] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/cgi-bin/index.php"] [unique_id "amuJtCrT982lovRn7gm1jwAAABE"]
[Thu Jul 30 12:28:20.310305 2026] [security2:error] [pid 751901:tid 752048] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/cgi-bin/index.php"] [unique_id "amuJtCrT982lovRn7gm1jwAAABE"]
[Thu Jul 30 12:28:20.458860 2026] [core:notice] [pid 751901:tid 752080] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:20.463048 2026] [security2:error] [pid 751901:tid 752080] [client 103.215.74.26:45514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtCrT982lovRn7gm1kAAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:20.565668 2026] [security2:error] [pid 751901:tid 752132] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/dist/"] [unique_id "amuJtCrT982lovRn7gm1kQAAAGU"]
[Thu Jul 30 12:28:20.705047 2026] [security2:error] [pid 751901:tid 752034] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuJtCrT982lovRn7gm1mQAAAAM"]
[Thu Jul 30 12:28:20.840960 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:20.845624 2026] [security2:error] [pid 751901:tid 752046] [client 182.8.249.15:20146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/article/view/9098"] [unique_id "amuJtCrT982lovRn7gm1kgAAAA8"]
[Thu Jul 30 12:28:20.846081 2026] [security2:error] [pid 751901:tid 752040] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuJtCrT982lovRn7gm1ngAAAAk"]
[Thu Jul 30 12:28:20.932264 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:20.999491 2026] [security2:error] [pid 751901:tid 752036] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/raw.php"] [unique_id "amuJtCrT982lovRn7gm1oAAAAAU"]
[Thu Jul 30 12:28:20.999622 2026] [security2:error] [pid 751901:tid 752036] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/raw.php"] [unique_id "amuJtCrT982lovRn7gm1oAAAAAU"]
[Thu Jul 30 12:28:21.089727 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:21.194408 2026] [core:notice] [pid 751901:tid 752057] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:21.198665 2026] [security2:error] [pid 751901:tid 752057] [client 103.215.74.26:45520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtSrT982lovRn7gm1pQAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:21.258449 2026] [security2:error] [pid 751901:tid 752104] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuJtSrT982lovRn7gm1pgAAAEk"]
[Thu Jul 30 12:28:21.383385 2026] [security2:error] [pid 751901:tid 752067] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/simple.php"] [unique_id "amuJtSrT982lovRn7gm1qwAAACQ"]
[Thu Jul 30 12:28:21.383544 2026] [security2:error] [pid 751901:tid 752067] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/simple.php"] [unique_id "amuJtSrT982lovRn7gm1qwAAACQ"]
[Thu Jul 30 12:28:21.638970 2026] [security2:error] [pid 751901:tid 752031] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/xxx.php"] [unique_id "amuJtSrT982lovRn7gm1rAAAAAA"]
[Thu Jul 30 12:28:21.639105 2026] [security2:error] [pid 751901:tid 752031] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/xxx.php"] [unique_id "amuJtSrT982lovRn7gm1rAAAAAA"]
[Thu Jul 30 12:28:21.842280 2026] [security2:error] [pid 751901:tid 752119] [client 52.238.199.152:59076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/f.php"] [unique_id "amuJtSrT982lovRn7gm1swAAAFg"]
[Thu Jul 30 12:28:21.938536 2026] [core:notice] [pid 751901:tid 752068] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:21.943071 2026] [security2:error] [pid 751901:tid 752068] [client 103.215.74.26:45536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtSrT982lovRn7gm1tQAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:22.678764 2026] [core:notice] [pid 751901:tid 752099] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:22.682825 2026] [security2:error] [pid 751901:tid 752099] [client 103.215.74.26:45542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtirT982lovRn7gm1xQAAAEQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:22.898662 2026] [security2:error] [pid 751901:tid 752047] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/file.php"] [unique_id "amuJtirT982lovRn7gm1zAAAABA"]
[Thu Jul 30 12:28:22.898746 2026] [security2:error] [pid 751901:tid 752047] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/file.php"] [unique_id "amuJtirT982lovRn7gm1zAAAABA"]
[Thu Jul 30 12:28:23.170531 2026] [security2:error] [pid 751901:tid 752132] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-load.php"] [unique_id "amuJtyrT982lovRn7gm10QAAAGU"]
[Thu Jul 30 12:28:23.170641 2026] [security2:error] [pid 751901:tid 752132] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-load.php"] [unique_id "amuJtyrT982lovRn7gm10QAAAGU"]
[Thu Jul 30 12:28:23.408105 2026] [security2:error] [pid 751901:tid 752108] [client 139.28.219.70:53388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kamiliacademy.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuJtyrT982lovRn7gm13AAAAE0"]
[Thu Jul 30 12:28:23.410341 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:23.415726 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:32860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJtyrT982lovRn7gm13QAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:23.462709 2026] [security2:error] [pid 751901:tid 752134] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-includes/assets/"] [unique_id "amuJtyrT982lovRn7gm13gAAAGc"]
[Thu Jul 30 12:28:23.572493 2026] [security2:error] [pid 751901:tid 751944] [remote 74.7.241.59:52372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuJtyrT982lovRn7gm13wAAbio"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 12:28:23.639629 2026] [security2:error] [pid 751901:tid 752036] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/sunrise/"] [unique_id "amuJtyrT982lovRn7gm14QAAAAU"]
[Thu Jul 30 12:28:23.758733 2026] [security2:error] [pid 751901:tid 751945] [remote 57.141.0.6:40418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuJtyrT982lovRn7gm14gAAAis"]
[Thu Jul 30 12:28:23.801519 2026] [security2:error] [pid 751901:tid 752155] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuJtyrT982lovRn7gm14wAAAHw"]
[Thu Jul 30 12:28:23.801643 2026] [security2:error] [pid 751901:tid 752155] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuJtyrT982lovRn7gm14wAAAHw"]
[Thu Jul 30 12:28:23.931742 2026] [security2:error] [pid 751901:tid 752109] [client 139.28.219.70:53400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJtyrT982lovRn7gm16wAAAE4"]
[Thu Jul 30 12:28:24.042502 2026] [security2:error] [pid 751901:tid 752049] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/a.php"] [unique_id "amuJuCrT982lovRn7gm17wAAABI"]
[Thu Jul 30 12:28:24.042649 2026] [security2:error] [pid 751901:tid 752049] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/a.php"] [unique_id "amuJuCrT982lovRn7gm17wAAABI"]
[Thu Jul 30 12:28:24.143550 2026] [core:notice] [pid 751901:tid 752067] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:24.148527 2026] [security2:error] [pid 751901:tid 752067] [client 103.215.74.26:32876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuCrT982lovRn7gm18AAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:24.296943 2026] [security2:error] [pid 751901:tid 752119] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuJuCrT982lovRn7gm18QAAAFg"]
[Thu Jul 30 12:28:24.297086 2026] [security2:error] [pid 751901:tid 752119] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuJuCrT982lovRn7gm18QAAAFg"]
[Thu Jul 30 12:28:24.381747 2026] [security2:error] [pid 751901:tid 752034] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJtyrT982lovRn7gm12wAAAyQ"]
[Thu Jul 30 12:28:24.531992 2026] [security2:error] [pid 751901:tid 752101] [client 180.253.34.69:63253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "toscanamall.com"] [uri "/admin/login"] [unique_id "amuJuCrT982lovRn7gm1-wAAAEY"]
[Thu Jul 30 12:28:24.671922 2026] [security2:error] [pid 751901:tid 751952] [remote 57.141.0.48:20018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuJuCrT982lovRn7gm1_AAAYTI"]
[Thu Jul 30 12:28:24.835364 2026] [security2:error] [pid 751901:tid 752055] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/aa.php"] [unique_id "amuJuCrT982lovRn7gm1_QAAABg"]
[Thu Jul 30 12:28:24.835490 2026] [security2:error] [pid 751901:tid 752055] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/aa.php"] [unique_id "amuJuCrT982lovRn7gm1_QAAABg"]
[Thu Jul 30 12:28:24.888246 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:24.892242 2026] [security2:error] [pid 751901:tid 752123] [client 103.215.74.26:32892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuCrT982lovRn7gm2AQAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:24.980093 2026] [security2:error] [pid 751901:tid 752121] [client 52.238.199.152:51659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuJuCrT982lovRn7gm2BQAAAFo"]
[Thu Jul 30 12:28:25.090571 2026] [security2:error] [pid 751901:tid 752139] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/177.php"] [unique_id "amuJuSrT982lovRn7gm2BwAAAGw"]
[Thu Jul 30 12:28:25.090669 2026] [security2:error] [pid 751901:tid 752139] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/177.php"] [unique_id "amuJuSrT982lovRn7gm2BwAAAGw"]
[Thu Jul 30 12:28:25.302385 2026] [security2:error] [pid 751901:tid 752092] [client 74.7.230.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.met.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuJtirT982lovRn7gm1wQAAAD0"]
[Thu Jul 30 12:28:25.302414 2026] [security2:error] [pid 751901:tid 752092] [client 74.7.230.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.met.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuJtirT982lovRn7gm1wQAAAD0"]
[Thu Jul 30 12:28:25.303111 2026] [security2:error] [pid 751901:tid 752053] [client 74.7.230.50:55582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.met.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuJtirT982lovRn7gm1vQAAFh0"]
[Thu Jul 30 12:28:25.345897 2026] [security2:error] [pid 751901:tid 752084] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/coffexium.php"] [unique_id "amuJuSrT982lovRn7gm2CQAAADU"]
[Thu Jul 30 12:28:25.346010 2026] [security2:error] [pid 751901:tid 752084] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/coffexium.php"] [unique_id "amuJuSrT982lovRn7gm2CQAAADU"]
[Thu Jul 30 12:28:25.619385 2026] [security2:error] [pid 751901:tid 752093] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/fffm.php"] [unique_id "amuJuSrT982lovRn7gm2FAAAAD4"]
[Thu Jul 30 12:28:25.619539 2026] [security2:error] [pid 751901:tid 752093] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/fffm.php"] [unique_id "amuJuSrT982lovRn7gm2FAAAAD4"]
[Thu Jul 30 12:28:25.636960 2026] [core:notice] [pid 751901:tid 752151] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:25.641587 2026] [security2:error] [pid 751901:tid 752151] [client 103.215.74.26:32894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuSrT982lovRn7gm2FQAAAHg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:25.854208 2026] [security2:error] [pid 751901:tid 752076] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/82.php"] [unique_id "amuJuSrT982lovRn7gm2GQAAAC0"]
[Thu Jul 30 12:28:25.854342 2026] [security2:error] [pid 751901:tid 752076] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/82.php"] [unique_id "amuJuSrT982lovRn7gm2GQAAAC0"]
[Thu Jul 30 12:28:26.002182 2026] [security2:error] [pid 751901:tid 752140] [client 52.238.199.152:42964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/hehe.php"] [unique_id "amuJuirT982lovRn7gm2IwAAAG0"]
[Thu Jul 30 12:28:26.004816 2026] [security2:error] [pid 751901:tid 752042] [client 38.190.144.4:55475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJuirT982lovRn7gm2JAAAAAs"]
[Thu Jul 30 12:28:26.004921 2026] [security2:error] [pid 751901:tid 752042] [client 38.190.144.4:55475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJuirT982lovRn7gm2JAAAAAs"]
[Thu Jul 30 12:28:26.095133 2026] [security2:error] [pid 751901:tid 752104] [client 74.7.230.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "met.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuJuSrT982lovRn7gm2IQAAAEk"], referer: https://www.met.nyx.temporary.site/robots.txt
[Thu Jul 30 12:28:26.095922 2026] [security2:error] [pid 751901:tid 752152] [client 74.7.230.50:55592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "met.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuJuSrT982lovRn7gm2HQAAeTc"], referer: https://www.met.nyx.temporary.site/robots.txt
[Thu Jul 30 12:28:26.118481 2026] [security2:error] [pid 751901:tid 752127] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/config.json.php"] [unique_id "amuJuirT982lovRn7gm2JQAAAGA"]
[Thu Jul 30 12:28:26.118569 2026] [security2:error] [pid 751901:tid 752127] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/config.json.php"] [unique_id "amuJuirT982lovRn7gm2JQAAAGA"]
[Thu Jul 30 12:28:26.358639 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:26.359391 2026] [security2:error] [pid 751901:tid 752057] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/fpwch.php"] [unique_id "amuJuirT982lovRn7gm2KgAAABo"]
[Thu Jul 30 12:28:26.359500 2026] [security2:error] [pid 751901:tid 752057] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/fpwch.php"] [unique_id "amuJuirT982lovRn7gm2KgAAABo"]
[Thu Jul 30 12:28:26.362789 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:32896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuirT982lovRn7gm2KAAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:26.608437 2026] [security2:error] [pid 751901:tid 752113] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/xp.php"] [unique_id "amuJuirT982lovRn7gm2NAAAAFI"]
[Thu Jul 30 12:28:26.608572 2026] [security2:error] [pid 751901:tid 752113] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/xp.php"] [unique_id "amuJuirT982lovRn7gm2NAAAAFI"]
[Thu Jul 30 12:28:26.659936 2026] [security2:error] [pid 751901:tid 752097] [client 74.7.244.26:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.lapakjitu78.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuJuirT982lovRn7gm2NQAAAEI"]
[Thu Jul 30 12:28:27.097232 2026] [core:notice] [pid 751901:tid 752055] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:27.102119 2026] [security2:error] [pid 751901:tid 752055] [client 103.215.74.26:32902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuyrT982lovRn7gm2QwAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:27.656628 2026] [security2:error] [pid 751901:tid 752064] [client 139.28.219.70:53416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJuyrT982lovRn7gm2TgAAACE"]
[Thu Jul 30 12:28:27.656731 2026] [security2:error] [pid 751901:tid 752064] [client 139.28.219.70:53416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJuyrT982lovRn7gm2TgAAACE"]
[Thu Jul 30 12:28:27.826900 2026] [core:notice] [pid 751901:tid 752080] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:27.832158 2026] [security2:error] [pid 751901:tid 752080] [client 103.215.74.26:32912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJuyrT982lovRn7gm2TwAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:27.871441 2026] [security2:error] [pid 751901:tid 752118] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/reop3.php"] [unique_id "amuJuyrT982lovRn7gm2UAAAAFc"]
[Thu Jul 30 12:28:27.871592 2026] [security2:error] [pid 751901:tid 752118] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/reop3.php"] [unique_id "amuJuyrT982lovRn7gm2UAAAAFc"]
[Thu Jul 30 12:28:28.133928 2026] [security2:error] [pid 751901:tid 752151] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amuJvCrT982lovRn7gm2WQAAAHg"]
[Thu Jul 30 12:28:28.183445 2026] [security2:error] [pid 751901:tid 752130] [client 139.28.219.70:53428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJvCrT982lovRn7gm2WgAAAGM"]
[Thu Jul 30 12:28:28.183551 2026] [security2:error] [pid 751901:tid 752130] [client 139.28.219.70:53428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kamiliacademy.com"] [uri "/xmlrpc.php"] [unique_id "amuJvCrT982lovRn7gm2WgAAAGM"]
[Thu Jul 30 12:28:28.267274 2026] [security2:error] [pid 751901:tid 752125] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp.php"] [unique_id "amuJvCrT982lovRn7gm2XwAAAF4"]
[Thu Jul 30 12:28:28.267389 2026] [security2:error] [pid 751901:tid 752125] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/wp.php"] [unique_id "amuJvCrT982lovRn7gm2XwAAAF4"]
[Thu Jul 30 12:28:28.550686 2026] [security2:error] [pid 751901:tid 752127] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/dex.php"] [unique_id "amuJvCrT982lovRn7gm2ZQAAAGA"]
[Thu Jul 30 12:28:28.550781 2026] [security2:error] [pid 751901:tid 752127] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/dex.php"] [unique_id "amuJvCrT982lovRn7gm2ZQAAAGA"]
[Thu Jul 30 12:28:28.583440 2026] [core:notice] [pid 751901:tid 752059] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:28.587534 2026] [security2:error] [pid 751901:tid 752059] [client 103.215.74.26:32914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvCrT982lovRn7gm2ZwAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:28.810243 2026] [security2:error] [pid 751901:tid 752049] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/biufile.php"] [unique_id "amuJvCrT982lovRn7gm2aQAAABI"]
[Thu Jul 30 12:28:28.810395 2026] [security2:error] [pid 751901:tid 752049] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/biufile.php"] [unique_id "amuJvCrT982lovRn7gm2aQAAABI"]
[Thu Jul 30 12:28:29.065837 2026] [security2:error] [pid 751901:tid 752103] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/inputs.php"] [unique_id "amuJvSrT982lovRn7gm2dQAAAEg"]
[Thu Jul 30 12:28:29.065916 2026] [security2:error] [pid 751901:tid 752103] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/inputs.php"] [unique_id "amuJvSrT982lovRn7gm2dQAAAEg"]
[Thu Jul 30 12:28:29.322372 2026] [core:notice] [pid 751901:tid 752101] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:29.323053 2026] [security2:error] [pid 751901:tid 752034] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/inputs.php"] [unique_id "amuJvSrT982lovRn7gm2egAAAAM"]
[Thu Jul 30 12:28:29.323188 2026] [security2:error] [pid 751901:tid 752034] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/inputs.php"] [unique_id "amuJvSrT982lovRn7gm2egAAAAM"]
[Thu Jul 30 12:28:29.326815 2026] [security2:error] [pid 751901:tid 752101] [client 103.215.74.26:32920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvSrT982lovRn7gm2eQAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:29.565689 2026] [security2:error] [pid 751901:tid 752137] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/adminfuns.php"] [unique_id "amuJvSrT982lovRn7gm2fwAAAGo"]
[Thu Jul 30 12:28:29.565799 2026] [security2:error] [pid 751901:tid 752137] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/adminfuns.php"] [unique_id "amuJvSrT982lovRn7gm2fwAAAGo"]
[Thu Jul 30 12:28:29.614211 2026] [security2:error] [pid 751901:tid 752041] [client 52.238.199.152:18143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/options.php"] [unique_id "amuJvSrT982lovRn7gm2gAAAAAo"]
[Thu Jul 30 12:28:29.808792 2026] [security2:error] [pid 751901:tid 752143] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/goods.php"] [unique_id "amuJvSrT982lovRn7gm2hAAAAHA"]
[Thu Jul 30 12:28:29.808915 2026] [security2:error] [pid 751901:tid 752143] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/goods.php"] [unique_id "amuJvSrT982lovRn7gm2hAAAAHA"]
[Thu Jul 30 12:28:30.053908 2026] [core:notice] [pid 751901:tid 752055] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:30.059165 2026] [security2:error] [pid 751901:tid 752055] [client 103.215.74.26:32932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvirT982lovRn7gm2hwAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:30.063865 2026] [security2:error] [pid 751901:tid 752142] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuJvirT982lovRn7gm2iQAAAG8"]
[Thu Jul 30 12:28:30.063958 2026] [security2:error] [pid 751901:tid 752142] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuJvirT982lovRn7gm2iQAAAG8"]
[Thu Jul 30 12:28:30.315692 2026] [security2:error] [pid 751901:tid 752056] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuJvirT982lovRn7gm2jwAAABk"]
[Thu Jul 30 12:28:30.315804 2026] [security2:error] [pid 751901:tid 752056] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/about.php"] [unique_id "amuJvirT982lovRn7gm2jwAAABk"]
[Thu Jul 30 12:28:30.485667 2026] [security2:error] [pid 751901:tid 752081] [client 52.238.199.152:42996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuJvirT982lovRn7gm2kAAAADI"]
[Thu Jul 30 12:28:30.539046 2026] [autoindex:error] [pid 751901:tid 752132] [client 43.153.58.28:53984] AH01276: Cannot serve directory /home2/meggzjte/adbacklink.com/bbs/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://adbacklink.com/bbs
[Thu Jul 30 12:28:30.580042 2026] [security2:error] [pid 751901:tid 752064] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJvirT982lovRn7gm2kgAAACE"]
[Thu Jul 30 12:28:30.580137 2026] [security2:error] [pid 751901:tid 752064] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJvirT982lovRn7gm2kgAAACE"]
[Thu Jul 30 12:28:30.799106 2026] [core:notice] [pid 751901:tid 752053] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:30.804682 2026] [security2:error] [pid 751901:tid 752053] [client 103.215.74.26:32948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvirT982lovRn7gm2mQAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:30.814695 2026] [security2:error] [pid 751901:tid 752151] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJvirT982lovRn7gm2mgAAAHg"]
[Thu Jul 30 12:28:30.814783 2026] [security2:error] [pid 751901:tid 752151] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/admin.php"] [unique_id "amuJvirT982lovRn7gm2mgAAAHg"]
[Thu Jul 30 12:28:31.065261 2026] [security2:error] [pid 751901:tid 752141] [client 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/chosen.php"] [unique_id "amuJvyrT982lovRn7gm2nAAAAG4"]
[Thu Jul 30 12:28:31.065377 2026] [security2:error] [pid 751901:tid 752141] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.prestigemassagestudio.cfd"] [uri "/chosen.php"] [unique_id "amuJvyrT982lovRn7gm2nAAAAG4"]
[Thu Jul 30 12:28:31.532361 2026] [core:notice] [pid 751901:tid 752061] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:31.537320 2026] [security2:error] [pid 751901:tid 752061] [client 103.215.74.26:32964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJvyrT982lovRn7gm2owAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:31.871523 2026] [core:notice] [pid 751901:tid 752090] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:32.000003 2026] [security2:error] [pid 751901:tid 752062] [client 188.163.72.169:46516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.72.163.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voyagegetaways.com"] [uri "/xmlrpc.php"] [unique_id "amuJvyrT982lovRn7gm2rAAAAB8"]
[Thu Jul 30 12:28:32.000151 2026] [security2:error] [pid 751901:tid 752062] [client 188.163.72.169:46516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "voyagegetaways.com"] [uri "/xmlrpc.php"] [unique_id "amuJvyrT982lovRn7gm2rAAAAB8"]
[Thu Jul 30 12:28:32.113701 2026] [security2:error] [pid 751901:tid 752059] [client 52.238.199.152:17939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/images/index.php"] [unique_id "amuJwCrT982lovRn7gm2rwAAABw"]
[Thu Jul 30 12:28:32.290012 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:32.294141 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:32978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwCrT982lovRn7gm2uQAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:32.595431 2026] [security2:error] [pid 751901:tid 751996] [remote 216.73.216.152:5122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuJwCrT982lovRn7gm2vAAAB14"]
[Thu Jul 30 12:28:33.033464 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:33.037512 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:42048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwSrT982lovRn7gm2wwAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:33.757239 2026] [core:notice] [pid 751901:tid 752132] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:33.762006 2026] [security2:error] [pid 751901:tid 752132] [client 103.215.74.26:42058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwSrT982lovRn7gm20gAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:34.035786 2026] [security2:error] [pid 751901:tid 752143] [client 52.238.199.152:43000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amuJwirT982lovRn7gm22wAAAHA"]
[Thu Jul 30 12:28:34.500488 2026] [core:notice] [pid 751901:tid 752156] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:34.505050 2026] [security2:error] [pid 751901:tid 752156] [client 103.215.74.26:42060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwirT982lovRn7gm24wAAAH0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:34.945251 2026] [security2:error] [pid 751901:tid 752129] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJwirT982lovRn7gm25AAAAGI"]
[Thu Jul 30 12:28:35.022746 2026] [proxy:error] [pid 751901:tid 752059] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:28:35.022807 2026] [proxy_http:error] [pid 751901:tid 752059] [client 18.211.55.47:29157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:28:35.023963 2026] [proxy:error] [pid 751901:tid 752059] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:28:35.024036 2026] [proxy_http:error] [pid 751901:tid 752059] [client 18.211.55.47:29157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:28:35.027869 2026] [proxy:error] [pid 751901:tid 752052] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:28:35.027932 2026] [proxy_http:error] [pid 751901:tid 752052] [client 18.211.55.47:54773] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:28:35.028581 2026] [proxy:error] [pid 751901:tid 752052] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:28:35.028634 2026] [proxy_http:error] [pid 751901:tid 752052] [client 18.211.55.47:54773] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:28:35.244934 2026] [core:notice] [pid 751901:tid 752068] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:35.251424 2026] [security2:error] [pid 751901:tid 752068] [client 103.215.74.26:42066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwyrT982lovRn7gm29AAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:35.610854 2026] [security2:error] [pid 751901:tid 752103] [client 52.238.199.152:17926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/13.php"] [unique_id "amuJwyrT982lovRn7gm2_AAAAEg"]
[Thu Jul 30 12:28:35.994717 2026] [core:notice] [pid 751901:tid 752075] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:36.002514 2026] [security2:error] [pid 751901:tid 752075] [client 103.215.74.26:42078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJwyrT982lovRn7gm3BAAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:36.295324 2026] [security2:error] [pid 751901:tid 752146] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJwyrT982lovRn7gm3AAAAAHM"]
[Thu Jul 30 12:28:36.731349 2026] [core:notice] [pid 751901:tid 752147] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:36.735477 2026] [security2:error] [pid 751901:tid 752147] [client 103.215.74.26:42086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJxCrT982lovRn7gm3DQAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:37.102637 2026] [security2:error] [pid 751901:tid 752040] [client 37.120.155.179:45812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuJxSrT982lovRn7gm3GwAAAAk"]
[Thu Jul 30 12:28:37.102732 2026] [security2:error] [pid 751901:tid 752040] [client 37.120.155.179:45812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuJxSrT982lovRn7gm3GwAAAAk"]
[Thu Jul 30 12:28:37.310790 2026] [security2:error] [pid 751901:tid 752050] [client 52.238.199.152:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/inputs.php"] [unique_id "amuJxSrT982lovRn7gm3HgAAABM"]
[Thu Jul 30 12:28:37.454308 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:37.458540 2026] [security2:error] [pid 751901:tid 752076] [client 103.215.74.26:42102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJxSrT982lovRn7gm3IAAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:37.823461 2026] [security2:error] [pid 751901:tid 752025] [remote 74.7.241.60:41994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuJxSrT982lovRn7gm3KgAAe3s"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:28:38.047826 2026] [security2:error] [pid 751901:tid 752125] [client 38.190.144.4:55987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJxirT982lovRn7gm3LgAAAF4"]
[Thu Jul 30 12:28:38.047949 2026] [security2:error] [pid 751901:tid 752125] [client 38.190.144.4:55987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJxirT982lovRn7gm3LgAAAF4"]
[Thu Jul 30 12:28:38.196386 2026] [core:notice] [pid 751901:tid 752129] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:38.202887 2026] [security2:error] [pid 751901:tid 752129] [client 103.215.74.26:42106] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJxirT982lovRn7gm3MwAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:39.828266 2026] [security2:error] [pid 751901:tid 752099] [client 52.238.199.152:49485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/jquery.php"] [unique_id "amuJxyrT982lovRn7gm3UgAAAEQ"]
[Thu Jul 30 12:28:40.295863 2026] [core:notice] [pid 751901:tid 752134] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:40.383900 2026] [autoindex:error] [pid 751901:tid 752093] [client 135.235.139.114:65016] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6041258f/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 12:28:40.458692 2026] [security2:error] [pid 751901:tid 752095] [client 74.7.175.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-a97a7679.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuJxyrT982lovRn7gm3SwAAAEA"]
[Thu Jul 30 12:28:40.459570 2026] [security2:error] [pid 751901:tid 752090] [client 74.7.175.157:34026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-a97a7679.dlr.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuJxyrT982lovRn7gm3SQAAOw8"]
[Thu Jul 30 12:28:40.874017 2026] [security2:error] [pid 751901:tid 752039] [client 52.238.199.152:49526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/doc.php"] [unique_id "amuJyCrT982lovRn7gm3ZgAAAAg"]
[Thu Jul 30 12:28:41.651938 2026] [security2:error] [pid 751901:tid 752078] [client 57.141.0.51:45114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuJySrT982lovRn7gm3bgAALwE"], referer: https://igetvape-australia.com/product-tag/iget-moon-strawberry-watermelon-ice-5000-puffs/
[Thu Jul 30 12:28:41.959395 2026] [security2:error] [pid 751901:tid 752110] [client 52.238.199.152:49490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/02.php"] [unique_id "amuJySrT982lovRn7gm3dwAAAE8"]
[Thu Jul 30 12:28:42.008600 2026] [security2:error] [pid 751901:tid 752096] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJySrT982lovRn7gm3bwAAAEE"]
[Thu Jul 30 12:28:43.322753 2026] [security2:error] [pid 751901:tid 752083] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJyirT982lovRn7gm3igAAADQ"]
[Thu Jul 30 12:28:43.992184 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:43.997594 2026] [security2:error] [pid 751901:tid 752157] [client 103.215.74.26:43586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJyyrT982lovRn7gm3oAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:44.664222 2026] [security2:error] [pid 751901:tid 752067] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJzCrT982lovRn7gm3pAAAACQ"]
[Thu Jul 30 12:28:44.716485 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:44.720464 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:43594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzCrT982lovRn7gm3qwAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:45.451327 2026] [core:notice] [pid 751901:tid 752060] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:45.455643 2026] [security2:error] [pid 751901:tid 752060] [client 103.215.74.26:43606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzSrT982lovRn7gm3tgAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:45.965822 2026] [security2:error] [pid 751901:tid 752137] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJzSrT982lovRn7gm3ugAAAGo"]
[Thu Jul 30 12:28:46.192842 2026] [core:notice] [pid 751901:tid 752124] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:46.196955 2026] [security2:error] [pid 751901:tid 752124] [client 103.215.74.26:43608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzirT982lovRn7gm3wQAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:46.934218 2026] [core:notice] [pid 751901:tid 752151] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:46.941299 2026] [security2:error] [pid 751901:tid 752151] [client 103.215.74.26:43620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzirT982lovRn7gm3zAAAAHg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:47.267787 2026] [security2:error] [pid 751901:tid 752141] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJzirT982lovRn7gm3zQAAAG4"]
[Thu Jul 30 12:28:47.658389 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:47.662477 2026] [security2:error] [pid 751901:tid 752106] [client 103.215.74.26:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJzyrT982lovRn7gm32wAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:47.721824 2026] [security2:error] [pid 751901:tid 752050] [client 38.190.144.4:56481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJzyrT982lovRn7gm33AAAABM"]
[Thu Jul 30 12:28:47.722053 2026] [security2:error] [pid 751901:tid 752050] [client 38.190.144.4:56481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJzyrT982lovRn7gm33AAAABM"]
[Thu Jul 30 12:28:48.384629 2026] [core:notice] [pid 751901:tid 752145] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:48.389621 2026] [security2:error] [pid 751901:tid 752145] [client 103.215.74.26:43640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0CrT982lovRn7gm35gAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:48.889417 2026] [security2:error] [pid 751901:tid 752144] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ0CrT982lovRn7gm35QAAcTk"]
[Thu Jul 30 12:28:49.130716 2026] [core:notice] [pid 751901:tid 752052] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:49.135366 2026] [security2:error] [pid 751901:tid 752052] [client 103.215.74.26:43646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0SrT982lovRn7gm38AAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:49.866248 2026] [core:notice] [pid 751901:tid 752038] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:49.870991 2026] [security2:error] [pid 751901:tid 752038] [client 103.215.74.26:43660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0SrT982lovRn7gm3_AAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:50.272807 2026] [security2:error] [pid 751901:tid 751969] [remote 152.228.213.32:40522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-login.php"] [unique_id "amuJ0irT982lovRn7gm4BgAAKkM"]
[Thu Jul 30 12:28:50.604522 2026] [core:notice] [pid 751901:tid 752114] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:50.608904 2026] [security2:error] [pid 751901:tid 752114] [client 103.215.74.26:43676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0irT982lovRn7gm4CwAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:51.395533 2026] [core:notice] [pid 751901:tid 752077] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:51.400123 2026] [security2:error] [pid 751901:tid 752077] [client 103.215.74.26:43690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ0yrT982lovRn7gm4FgAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:52.010912 2026] [security2:error] [pid 751901:tid 752130] [client 52.238.199.152:17502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/well-known/admin.php"] [unique_id "amuJ1CrT982lovRn7gm4JQAAAGM"]
[Thu Jul 30 12:28:52.118967 2026] [core:notice] [pid 751901:tid 752109] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:52.123467 2026] [security2:error] [pid 751901:tid 752109] [client 103.215.74.26:43698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ1CrT982lovRn7gm4KAAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:52.138491 2026] [security2:error] [pid 751901:tid 752141] [client 87.248.116.215:38182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuJ0yrT982lovRn7gm4HQAAAG4"]
[Thu Jul 30 12:28:52.550341 2026] [security2:error] [pid 751901:tid 752058] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ0yrT982lovRn7gm4IwAAABs"]
[Thu Jul 30 12:28:52.855890 2026] [core:notice] [pid 751901:tid 752068] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:52.860354 2026] [security2:error] [pid 751901:tid 752068] [client 103.215.74.26:43700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ1CrT982lovRn7gm4OQAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:53.024213 2026] [security2:error] [pid 751901:tid 752078] [client 87.248.116.215:38184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ1CrT982lovRn7gm4MQAAAC8"]
[Thu Jul 30 12:28:53.572700 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:53.577168 2026] [security2:error] [pid 751901:tid 752121] [client 103.215.74.26:36300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ1SrT982lovRn7gm4SwAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:54.314200 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:28:54.318517 2026] [security2:error] [pid 751901:tid 752149] [client 103.215.74.26:36308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ1irT982lovRn7gm4WAAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:28:54.333096 2026] [security2:error] [pid 751901:tid 752132] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ1SrT982lovRn7gm4VQAAAGU"]
[Thu Jul 30 12:28:54.586096 2026] [security2:error] [pid 751901:tid 752090] [client 52.238.199.152:18130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/v.php"] [unique_id "amuJ1irT982lovRn7gm4YwAAADs"]
[Thu Jul 30 12:28:55.007046 2026] [security2:error] [pid 751901:tid 751990] [remote 97.74.87.194:33376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koriusa.info"] [uri "/wp-login.php"] [unique_id "amuJ1yrT982lovRn7gm4aAAAc1g"]
[Thu Jul 30 12:28:55.523031 2026] [security2:error] [pid 751901:tid 752151] [client 83.38.36.245:39550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amuJ1irT982lovRn7gm4XAAAAHg"]
[Thu Jul 30 12:28:55.540472 2026] [security2:error] [pid 751901:tid 752033] [client 52.238.199.152:40135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/main.php"] [unique_id "amuJ1yrT982lovRn7gm4cgAAAAI"]
[Thu Jul 30 12:28:55.551947 2026] [security2:error] [pid 751901:tid 752040] [client 62.102.148.166:46340] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuJ1yrT982lovRn7gm4dAAAAAk"]
[Thu Jul 30 12:28:55.552048 2026] [security2:error] [pid 751901:tid 752040] [client 62.102.148.166:46340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuJ1yrT982lovRn7gm4dAAAAAk"]
[Thu Jul 30 12:28:55.678702 2026] [security2:error] [pid 751901:tid 752141] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ1yrT982lovRn7gm4bQAAAG4"]
[Thu Jul 30 12:28:57.058062 2026] [security2:error] [pid 751901:tid 752065] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ2CrT982lovRn7gm4hQAAACI"]
[Thu Jul 30 12:28:57.628168 2026] [security2:error] [pid 751901:tid 752010] [remote 216.73.216.152:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuJ2SrT982lovRn7gm4kwAAMGw"]
[Thu Jul 30 12:28:58.380020 2026] [security2:error] [pid 751901:tid 752120] [client 38.190.144.4:56971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ2irT982lovRn7gm4ngAAAFk"]
[Thu Jul 30 12:28:58.380172 2026] [security2:error] [pid 751901:tid 752120] [client 38.190.144.4:56971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ2irT982lovRn7gm4ngAAAFk"]
[Thu Jul 30 12:28:58.831755 2026] [security2:error] [pid 751901:tid 752072] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ2irT982lovRn7gm4mgAAKXA"]
[Thu Jul 30 12:28:58.959740 2026] [security2:error] [pid 751901:tid 752153] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ2irT982lovRn7gm4nQAAAHo"]
[Thu Jul 30 12:28:58.974173 2026] [security2:error] [pid 751901:tid 752036] [client 52.238.199.152:40150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/file.php"] [unique_id "amuJ2irT982lovRn7gm4pQAAAAU"]
[Thu Jul 30 12:28:59.438962 2026] [security2:error] [pid 751901:tid 752104] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ2yrT982lovRn7gm4qQAAAEk"]
[Thu Jul 30 12:29:00.105430 2026] [core:notice] [pid 751901:tid 752054] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:00.110863 2026] [security2:error] [pid 751901:tid 752054] [client 103.215.74.26:36310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ3CrT982lovRn7gm4tAAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:00.834236 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:00.834462 2026] [security2:error] [pid 751901:tid 752067] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ3CrT982lovRn7gm4vQAAACQ"]
[Thu Jul 30 12:29:00.839273 2026] [security2:error] [pid 751901:tid 752037] [client 103.215.74.26:36320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ3CrT982lovRn7gm4xAAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:01.368246 2026] [security2:error] [pid 751901:tid 752119] [client 66.249.66.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ3CrT982lovRn7gm4vAAAWHs"]
[Thu Jul 30 12:29:01.562061 2026] [core:notice] [pid 751901:tid 752158] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:01.566124 2026] [security2:error] [pid 751901:tid 752158] [client 103.215.74.26:36328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ3SrT982lovRn7gm40AAAAH8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:02.071112 2026] [security2:error] [pid 751901:tid 752066] [client 52.238.199.152:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuJ3irT982lovRn7gm42QAAACM"]
[Thu Jul 30 12:29:02.195097 2026] [security2:error] [pid 751901:tid 752082] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ3SrT982lovRn7gm41wAAADM"]
[Thu Jul 30 12:29:02.447147 2026] [core:notice] [pid 751901:tid 751912] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:02.452404 2026] [security2:error] [pid 751901:tid 752124] [client 45.38.206.95:63392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/low-boots/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/bottines-\\xc3\\xa0-enfiler-aimee-topshop.jpg"] [unique_id "amuJ3irT982lovRn7gm42gAAXQo"], referer: https://carnetdeshopping.com/index.php/tag/low-boots/
[Thu Jul 30 12:29:02.521482 2026] [core:notice] [pid 751901:tid 751909] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:02.527184 2026] [security2:error] [pid 751901:tid 752136] [client 45.38.206.95:63406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/low-boots/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/boots-regane_bocage.jpg"] [unique_id "amuJ3irT982lovRn7gm43gAAaQc"], referer: https://carnetdeshopping.com/index.php/tag/low-boots/
[Thu Jul 30 12:29:02.690037 2026] [core:notice] [pid 751901:tid 751920] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:02.695726 2026] [security2:error] [pid 751901:tid 752147] [client 45.38.206.95:63416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/low-boots/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/bottines-tryane-mellow-yellow.jpg"] [unique_id "amuJ3irT982lovRn7gm44gAAdBI"], referer: https://carnetdeshopping.com/index.php/tag/low-boots/
[Thu Jul 30 12:29:03.009240 2026] [security2:error] [pid 751901:tid 751921] [remote 57.141.0.19:51306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/589953950/feed/rss2/"] [unique_id "amuJ3yrT982lovRn7gm46QAAcBM"]
[Thu Jul 30 12:29:03.557774 2026] [security2:error] [pid 751901:tid 752109] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ3yrT982lovRn7gm46gAAAE4"]
[Thu Jul 30 12:29:04.867423 2026] [security2:error] [pid 751901:tid 752062] [client 52.238.199.152:40177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuJ4CrT982lovRn7gm5EAAAAB8"]
[Thu Jul 30 12:29:04.956497 2026] [security2:error] [pid 751901:tid 752098] [client 118.212.121.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuJ4CrT982lovRn7gm5DAAAAEM"]
[Thu Jul 30 12:29:06.630429 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:06.747098 2026] [security2:error] [pid 751901:tid 752040] [client 43.166.1.243:49366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.1.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/article.php"] [unique_id "amuJ4irT982lovRn7gm5LwAAAAk"]
[Thu Jul 30 12:29:06.890689 2026] [security2:error] [pid 751901:tid 752085] [client 52.238.199.152:56026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/file.php"] [unique_id "amuJ4irT982lovRn7gm5OAAAADY"]
[Thu Jul 30 12:29:07.305750 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:07.309694 2026] [security2:error] [pid 751901:tid 752037] [client 103.215.74.26:5966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ4yrT982lovRn7gm5QgAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:07.430610 2026] [security2:error] [pid 751901:tid 752071] [client 86.206.72.201:33152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ4yrT982lovRn7gm5PQAAACg"], referer: http://pkf.jo
[Thu Jul 30 12:29:07.739900 2026] [security2:error] [pid 751901:tid 752075] [client 52.238.199.152:18138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-signup.php"] [unique_id "amuJ4yrT982lovRn7gm5UQAAACw"]
[Thu Jul 30 12:29:07.838722 2026] [security2:error] [pid 751901:tid 752121] [client 201.173.67.215:55509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ4yrT982lovRn7gm5SQAAAFo"], referer: http://pkf.jo
[Thu Jul 30 12:29:08.048793 2026] [core:notice] [pid 751901:tid 752084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:08.054088 2026] [security2:error] [pid 751901:tid 752084] [client 103.215.74.26:5980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ5CrT982lovRn7gm5VgAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:08.076086 2026] [security2:error] [pid 751901:tid 752139] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ4yrT982lovRn7gm5SAAAAGw"]
[Thu Jul 30 12:29:08.330235 2026] [security2:error] [pid 751901:tid 752118] [client 103.167.233.58:31008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ5CrT982lovRn7gm5VQAAAFc"], referer: http://pkf.jo
[Thu Jul 30 12:29:08.598017 2026] [security2:error] [pid 751901:tid 752074] [client 52.238.199.152:45471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuJ5CrT982lovRn7gm5XwAAACs"]
[Thu Jul 30 12:29:08.638782 2026] [core:notice] [pid 751901:tid 751931] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:08.643997 2026] [security2:error] [pid 751901:tid 752117] [client 48.44.107.214:13277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/low-boots/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/boots-rosilda-bocage.jpg"] [unique_id "amuJ5CrT982lovRn7gm5WgAAVh0"], referer: https://carnetdeshopping.com/index.php/tag/low-boots/
[Thu Jul 30 12:29:08.779523 2026] [core:notice] [pid 751901:tid 752090] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:08.786594 2026] [security2:error] [pid 751901:tid 752090] [client 103.215.74.26:5990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ5CrT982lovRn7gm5ZgAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:08.902602 2026] [security2:error] [pid 751901:tid 752106] [client 169.224.125.65:25238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ5CrT982lovRn7gm5YAAAAEs"], referer: http://pkf.jo
[Thu Jul 30 12:29:09.462121 2026] [security2:error] [pid 751901:tid 752033] [client 197.244.73.187:46386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ5SrT982lovRn7gm5cQAAAAI"], referer: http://pkf.jo
[Thu Jul 30 12:29:09.535560 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:09.543279 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:6002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ5SrT982lovRn7gm5ewAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:10.276164 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:10.280224 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:6004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ5irT982lovRn7gm5pAAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:11.932768 2026] [core:notice] [pid 751901:tid 751916] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:12.286643 2026] [security2:error] [pid 751901:tid 752035] [client 52.238.199.152:40144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ge.php"] [unique_id "amuJ6CrT982lovRn7gm6AQAAAAQ"]
[Thu Jul 30 12:29:12.542587 2026] [security2:error] [pid 751901:tid 752107] [client 172.237.109.114:56610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm51QAAAEw"]
[Thu Jul 30 12:29:12.545523 2026] [security2:error] [pid 751901:tid 752154] [client 172.237.109.114:50967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm52AAAAHs"]
[Thu Jul 30 12:29:12.548239 2026] [security2:error] [pid 751901:tid 752113] [client 172.237.109.114:31255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm53AAAAFI"]
[Thu Jul 30 12:29:12.609593 2026] [security2:error] [pid 751901:tid 752089] [client 172.237.109.114:8582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm54gAAADo"]
[Thu Jul 30 12:29:12.624796 2026] [security2:error] [pid 751901:tid 752091] [client 172.237.109.114:63064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm55gAAADw"]
[Thu Jul 30 12:29:12.629919 2026] [core:notice] [pid 751901:tid 751928] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:12.633960 2026] [security2:error] [pid 751901:tid 752115] [client 172.237.109.114:29570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm50wAAAFQ"]
[Thu Jul 30 12:29:12.649846 2026] [security2:error] [pid 751901:tid 752039] [client 172.237.109.114:22448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm51AAAAAg"]
[Thu Jul 30 12:29:12.654698 2026] [security2:error] [pid 751901:tid 752108] [client 172.237.109.114:22804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm56AAAAE0"]
[Thu Jul 30 12:29:12.655948 2026] [security2:error] [pid 751901:tid 752050] [client 172.237.109.114:30201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm53wAAABM"]
[Thu Jul 30 12:29:13.082571 2026] [core:error] [pid 751901:tid 752130] [client 74.7.244.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:29:13.082592 2026] [core:error] [pid 751901:tid 752130] [client 74.7.244.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:29:13.082696 2026] [security2:error] [pid 751901:tid 752130] [client 74.7.244.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.gfy.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuJ6SrT982lovRn7gm6FAAAAGM"]
[Thu Jul 30 12:29:13.083403 2026] [security2:error] [pid 751901:tid 752093] [client 74.7.244.15:40296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.gfy.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuJ6SrT982lovRn7gm6EgAAPn8"]
[Thu Jul 30 12:29:13.229180 2026] [security2:error] [pid 751901:tid 752106] [client 172.237.109.114:43285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm54wAAAEs"]
[Thu Jul 30 12:29:13.232798 2026] [security2:error] [pid 751901:tid 752046] [client 172.237.109.114:10490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm52QAAAA8"]
[Thu Jul 30 12:29:13.260250 2026] [security2:error] [pid 751901:tid 752143] [client 172.237.109.114:24123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm54AAAAHA"]
[Thu Jul 30 12:29:13.261541 2026] [security2:error] [pid 751901:tid 752104] [client 172.237.109.114:55768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm51wAAAEk"]
[Thu Jul 30 12:29:13.272280 2026] [security2:error] [pid 751901:tid 752111] [client 172.237.109.114:41251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm55QAAAFA"]
[Thu Jul 30 12:29:13.282708 2026] [security2:error] [pid 751901:tid 752156] [client 172.237.109.114:9166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm52gAAAH0"]
[Thu Jul 30 12:29:13.283103 2026] [security2:error] [pid 751901:tid 752076] [client 172.237.109.114:33311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm53gAAAC0"]
[Thu Jul 30 12:29:13.420126 2026] [security2:error] [pid 751901:tid 752059] [client 172.237.109.114:63638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm56QAAABw"]
[Thu Jul 30 12:29:13.468295 2026] [security2:error] [pid 751901:tid 752048] [client 172.237.109.114:55169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm56wAAABE"]
[Thu Jul 30 12:29:13.476837 2026] [security2:error] [pid 751901:tid 752042] [client 172.237.109.114:25497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ5yrT982lovRn7gm56gAAAAs"]
[Thu Jul 30 12:29:13.619548 2026] [security2:error] [pid 751901:tid 752158] [client 172.237.109.114:5522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuJ6CrT982lovRn7gm5_QAAAH8"]
[Thu Jul 30 12:29:13.758846 2026] [security2:error] [pid 751901:tid 752105] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ6SrT982lovRn7gm6FwAAAEo"]
[Thu Jul 30 12:29:14.085059 2026] [security2:error] [pid 751901:tid 752045] [client 212.237.119.48:24191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ6SrT982lovRn7gm6IwAAAA4"], referer: http://pkf.jo
[Thu Jul 30 12:29:15.436331 2026] [security2:error] [pid 751901:tid 752152] [client 52.238.199.152:18115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/goods.php"] [unique_id "amuJ6yrT982lovRn7gm6PAAAAHk"]
[Thu Jul 30 12:29:15.839816 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:16.059518 2026] [core:notice] [pid 751901:tid 752059] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:16.063725 2026] [security2:error] [pid 751901:tid 752059] [client 103.215.74.26:37478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7CrT982lovRn7gm6YgAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:16.399242 2026] [security2:error] [pid 751901:tid 752042] [client 52.238.199.152:57015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/403.php"] [unique_id "amuJ7CrT982lovRn7gm6cAAAAAs"]
[Thu Jul 30 12:29:16.518690 2026] [proxy:error] [pid 751901:tid 751979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:29:16.518746 2026] [proxy_http:error] [pid 751901:tid 751979] [remote 158.173.67.31:10833] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:29:16.519354 2026] [proxy:error] [pid 751901:tid 751979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:29:16.519398 2026] [proxy_http:error] [pid 751901:tid 751979] [remote 158.173.67.31:10833] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:29:16.787373 2026] [core:notice] [pid 751901:tid 752129] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:16.794460 2026] [security2:error] [pid 751901:tid 752129] [client 103.215.74.26:37490] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7CrT982lovRn7gm6dgAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:16.798088 2026] [security2:error] [pid 751901:tid 752126] [client 66.249.90.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ7CrT982lovRn7gm6ZQAAAF8"]
[Thu Jul 30 12:29:17.002546 2026] [core:error] [pid 751901:tid 751978] [remote 74.7.175.155:52242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:29:17.002573 2026] [core:error] [pid 751901:tid 751978] [remote 74.7.175.155:52242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:29:17.002784 2026] [security2:error] [pid 751901:tid 752031] [client 74.7.175.155:52242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.ampcloudku.com"] [uri "/index.php"] [unique_id "amuJ7CrT982lovRn7gm6egAAAEw"]
[Thu Jul 30 12:29:17.346526 2026] [security2:error] [pid 751901:tid 752146] [client 52.238.199.152:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/public/makeasmtp.php"] [unique_id "amuJ7SrT982lovRn7gm6gAAAAHM"]
[Thu Jul 30 12:29:17.521994 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:17.526010 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:37506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7SrT982lovRn7gm6hAAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:18.252541 2026] [core:notice] [pid 751901:tid 752074] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:18.256451 2026] [security2:error] [pid 751901:tid 752074] [client 103.215.74.26:37514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7irT982lovRn7gm6kQAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:18.977043 2026] [core:notice] [pid 751901:tid 752067] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:18.983999 2026] [security2:error] [pid 751901:tid 752067] [client 103.215.74.26:37520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7irT982lovRn7gm6ngAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:19.112493 2026] [security2:error] [pid 751901:tid 752033] [client 43.173.71.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuJ7irT982lovRn7gm6mwAAAAI"], referer: http://cnpinyin.com/dict1?search=%e9%9f%b3
[Thu Jul 30 12:29:19.702893 2026] [core:notice] [pid 751901:tid 752150] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:19.706865 2026] [security2:error] [pid 751901:tid 752150] [client 103.215.74.26:37526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ7yrT982lovRn7gm6rAAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:20.390997 2026] [security2:error] [pid 751901:tid 752078] [client 52.238.199.152:17404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/mar.php"] [unique_id "amuJ8CrT982lovRn7gm6tgAAAC8"]
[Thu Jul 30 12:29:20.432148 2026] [core:notice] [pid 751901:tid 752126] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:20.436454 2026] [security2:error] [pid 751901:tid 752126] [client 103.215.74.26:37540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ8CrT982lovRn7gm6twAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:21.175210 2026] [core:notice] [pid 751901:tid 752146] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:21.181877 2026] [security2:error] [pid 751901:tid 752146] [client 103.215.74.26:37544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ8SrT982lovRn7gm6wgAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:21.492610 2026] [security2:error] [pid 751901:tid 752089] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ8CrT982lovRn7gm6vAAAOmg"]
[Thu Jul 30 12:29:21.556511 2026] [security2:error] [pid 751901:tid 752082] [client 52.238.199.152:57004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/system.php"] [unique_id "amuJ8SrT982lovRn7gm6yAAAADM"]
[Thu Jul 30 12:29:21.611417 2026] [security2:error] [pid 751901:tid 752124] [client 5.29.12.166:1025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ8SrT982lovRn7gm6wwAAAF0"], referer: http://pkf.jo
[Thu Jul 30 12:29:21.908662 2026] [core:notice] [pid 751901:tid 752083] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:21.912704 2026] [security2:error] [pid 751901:tid 752083] [client 103.215.74.26:37552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ8SrT982lovRn7gm6zQAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:22.162416 2026] [security2:error] [pid 751901:tid 752145] [client 185.244.152.158:27304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ8SrT982lovRn7gm6zAAAAHI"], referer: http://pkf.jo
[Thu Jul 30 12:29:22.573089 2026] [security2:error] [pid 751901:tid 752130] [client 197.248.125.7:52258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ8irT982lovRn7gm61AAAAGM"], referer: http://pkf.jo
[Thu Jul 30 12:29:22.802666 2026] [security2:error] [pid 751901:tid 752131] [client 102.68.141.243:56928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ8irT982lovRn7gm61QAAAGQ"], referer: http://pkf.jo
[Thu Jul 30 12:29:23.036816 2026] [security2:error] [pid 751901:tid 752109] [client 100.26.182.244:41576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "northyorksheridanmall.com"] [uri "/"] [unique_id "amuJ8yrT982lovRn7gm63wAAAE4"]
[Thu Jul 30 12:29:23.285202 2026] [security2:error] [pid 751901:tid 752065] [client 38.190.144.4:58179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ8yrT982lovRn7gm66gAAACI"]
[Thu Jul 30 12:29:23.288657 2026] [security2:error] [pid 751901:tid 752065] [client 38.190.144.4:58179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ8yrT982lovRn7gm66gAAACI"]
[Thu Jul 30 12:29:23.685875 2026] [security2:error] [pid 751901:tid 752057] [client 52.238.199.152:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/lock360.php"] [unique_id "amuJ8yrT982lovRn7gm69AAAABo"]
[Thu Jul 30 12:29:23.997399 2026] [security2:error] [pid 751901:tid 752035] [client 62.102.148.166:40518] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuJ8yrT982lovRn7gm6-AAAAAQ"]
[Thu Jul 30 12:29:23.997526 2026] [security2:error] [pid 751901:tid 752035] [client 62.102.148.166:40518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuJ8yrT982lovRn7gm6-AAAAAQ"]
[Thu Jul 30 12:29:24.538499 2026] [security2:error] [pid 751901:tid 752158] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ8yrT982lovRn7gm64gAAf2w"]
[Thu Jul 30 12:29:25.191019 2026] [security2:error] [pid 751901:tid 752146] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ9CrT982lovRn7gm6_wAAc0I"]
[Thu Jul 30 12:29:25.502867 2026] [security2:error] [pid 751901:tid 752116] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ9CrT982lovRn7gm7CQAAAFU"]
[Thu Jul 30 12:29:27.665149 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:27.670170 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:8652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ9yrT982lovRn7gm7RQAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:27.709828 2026] [security2:error] [pid 751901:tid 752095] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuJ9yrT982lovRn7gm7NwAAAEA"]
[Thu Jul 30 12:29:27.822469 2026] [security2:error] [pid 751901:tid 751925] [remote 192.250.239.173:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.239.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kbtfinancezambia.com"] [uri "/wp-login.php"] [unique_id "amuJ9yrT982lovRn7gm7TQAAXhc"]
[Thu Jul 30 12:29:28.338355 2026] [security2:error] [pid 751901:tid 752029] [remote 74.7.241.59:55138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuJ-CrT982lovRn7gm7ZAAAOn8"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:29:28.407571 2026] [core:notice] [pid 751901:tid 752043] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:28.412173 2026] [security2:error] [pid 751901:tid 752043] [client 103.215.74.26:8664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-CrT982lovRn7gm7ZQAAAAw"], referer: https://carnetdeshopping.com/
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:29:29.132170 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:29.138046 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:8668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-SrT982lovRn7gm7gQAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:29.249250 2026] [security2:error] [pid 751901:tid 752081] [client 52.238.199.152:17345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amuJ-SrT982lovRn7gm7iAAAADI"]
[Thu Jul 30 12:29:29.884370 2026] [core:notice] [pid 751901:tid 752147] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:29.892267 2026] [security2:error] [pid 751901:tid 752147] [client 103.215.74.26:8672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-SrT982lovRn7gm7oQAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:30.622813 2026] [core:notice] [pid 751901:tid 752094] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:30.627236 2026] [security2:error] [pid 751901:tid 752094] [client 103.215.74.26:8682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-irT982lovRn7gm7tgAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:30.919188 2026] [security2:error] [pid 751901:tid 752044] [client 66.249.93.1:35407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuJ-irT982lovRn7gm7tQAAAA0"]
[Thu Jul 30 12:29:30.932545 2026] [security2:error] [pid 751901:tid 752129] [client 52.238.199.152:64430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/mah.php"] [unique_id "amuJ-irT982lovRn7gm7wgAAAGI"]
[Thu Jul 30 12:29:30.970423 2026] [security2:error] [pid 751901:tid 752042] [client 38.190.144.4:58727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ-irT982lovRn7gm7wwAAAAs"]
[Thu Jul 30 12:29:30.970551 2026] [security2:error] [pid 751901:tid 752042] [client 38.190.144.4:58727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuJ-irT982lovRn7gm7wwAAAAs"]
[Thu Jul 30 12:29:31.269349 2026] [security2:error] [pid 751901:tid 752035] [client 129.222.147.151:57194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuJ-irT982lovRn7gm7wQAAAAQ"], referer: http://pkf.jo
[Thu Jul 30 12:29:31.345441 2026] [core:notice] [pid 751901:tid 752039] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:31.351018 2026] [security2:error] [pid 751901:tid 752039] [client 103.215.74.26:8694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ-yrT982lovRn7gm71wAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:31.487416 2026] [proxy:error] [pid 751901:tid 752146] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:29:31.487468 2026] [proxy_http:error] [pid 751901:tid 752146] [client 195.96.139.12:41529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:29:31.488100 2026] [proxy:error] [pid 751901:tid 752146] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:29:31.488158 2026] [proxy_http:error] [pid 751901:tid 752146] [client 195.96.139.12:41529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:29:32.072824 2026] [core:notice] [pid 751901:tid 752134] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:32.077236 2026] [security2:error] [pid 751901:tid 752134] [client 103.215.74.26:8708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_CrT982lovRn7gm75AAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:32.324063 2026] [security2:error] [pid 751901:tid 752045] [client 52.238.199.152:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-class.php"] [unique_id "amuJ_CrT982lovRn7gm76wAAAA4"]
[Thu Jul 30 12:29:32.808436 2026] [core:notice] [pid 751901:tid 752154] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:32.812583 2026] [security2:error] [pid 751901:tid 752154] [client 103.215.74.26:8710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_CrT982lovRn7gm7-gAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:33.101057 2026] [security2:error] [pid 751901:tid 752051] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ_CrT982lovRn7gm77QAAFEw"]
[Thu Jul 30 12:29:33.535871 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:33.540389 2026] [security2:error] [pid 751901:tid 752063] [client 103.215.74.26:37466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_SrT982lovRn7gm8DAAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:34.244680 2026] [security2:error] [pid 751901:tid 752125] [client 52.238.199.152:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/backup.php"] [unique_id "amuJ_irT982lovRn7gm8HgAAAF4"]
[Thu Jul 30 12:29:34.274535 2026] [core:notice] [pid 751901:tid 752070] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:34.278758 2026] [security2:error] [pid 751901:tid 752070] [client 103.215.74.26:37468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_irT982lovRn7gm8HwAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:34.296030 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:34.442548 2026] [core:notice] [pid 751901:tid 752130] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:34.844487 2026] [core:notice] [pid 751901:tid 752101] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:34.972794 2026] [security2:error] [pid 751901:tid 752083] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuJ_irT982lovRn7gm8JAAANGM"]
[Thu Jul 30 12:29:35.013282 2026] [core:notice] [pid 751901:tid 752096] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:35.017443 2026] [security2:error] [pid 751901:tid 752096] [client 103.215.74.26:37472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_yrT982lovRn7gm8OAAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:35.755030 2026] [core:notice] [pid 751901:tid 752060] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:35.760750 2026] [security2:error] [pid 751901:tid 752060] [client 103.215.74.26:37482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuJ_yrT982lovRn7gm8RwAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:35.956063 2026] [security2:error] [pid 751901:tid 752034] [client 52.238.199.152:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/default.php"] [unique_id "amuJ_yrT982lovRn7gm8TgAAAAM"]
[Thu Jul 30 12:29:36.487148 2026] [core:notice] [pid 751901:tid 752084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:36.492383 2026] [security2:error] [pid 751901:tid 752084] [client 103.215.74.26:37498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKACrT982lovRn7gm8VgAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:37.336743 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:37.343138 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:37506] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKASrT982lovRn7gm8ZwAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:37.619395 2026] [security2:error] [pid 751901:tid 752092] [client 52.238.199.152:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/maint/about.php"] [unique_id "amuKASrT982lovRn7gm8bAAAAD0"]
[Thu Jul 30 12:29:37.727934 2026] [security2:error] [pid 751901:tid 752056] [client 62.102.148.166:50040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuKASrT982lovRn7gm8cwAAABk"]
[Thu Jul 30 12:29:37.728044 2026] [security2:error] [pid 751901:tid 752056] [client 62.102.148.166:50040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuKASrT982lovRn7gm8cwAAABk"]
[Thu Jul 30 12:29:37.820100 2026] [security2:error] [pid 751901:tid 752102] [client 20.215.211.95:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKASrT982lovRn7gm8awAAAEc"]
[Thu Jul 30 12:29:37.820237 2026] [security2:error] [pid 751901:tid 752102] [client 20.215.211.95:60370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKASrT982lovRn7gm8awAAAEc"]
[Thu Jul 30 12:29:38.073276 2026] [core:notice] [pid 751901:tid 752057] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:38.080110 2026] [security2:error] [pid 751901:tid 752057] [client 103.215.74.26:37508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKAirT982lovRn7gm8egAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:38.405966 2026] [security2:error] [pid 751901:tid 752062] [client 102.210.43.122:46984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKAirT982lovRn7gm8ewAAAB8"], referer: http://pkf.jo
[Thu Jul 30 12:29:38.823763 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:38.827547 2026] [security2:error] [pid 751901:tid 752046] [client 103.215.74.26:37512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKAirT982lovRn7gm8iQAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:38.893501 2026] [security2:error] [pid 751901:tid 752066] [client 89.211.182.169:39378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKAirT982lovRn7gm8gwAAACM"], referer: http://pkf.jo
[Thu Jul 30 12:29:39.024149 2026] [security2:error] [pid 751901:tid 752156] [client 200.8.79.115:51650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKAirT982lovRn7gm8hAAAAH0"], referer: http://pkf.jo
[Thu Jul 30 12:29:39.083361 2026] [security2:error] [pid 751901:tid 752114] [client 52.238.199.152:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amuKAyrT982lovRn7gm8kAAAAFM"]
[Thu Jul 30 12:29:39.598358 2026] [core:notice] [pid 751901:tid 752118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:39.602810 2026] [security2:error] [pid 751901:tid 752118] [client 103.215.74.26:37518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKAyrT982lovRn7gm8lwAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:39.944062 2026] [security2:error] [pid 751901:tid 752054] [client 52.238.199.152:17537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ty.php"] [unique_id "amuKAyrT982lovRn7gm8nAAAABc"]
[Thu Jul 30 12:29:40.331159 2026] [core:notice] [pid 751901:tid 752119] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:40.337746 2026] [security2:error] [pid 751901:tid 752119] [client 103.215.74.26:37528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKBCrT982lovRn7gm8oAAAAFg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:40.930321 2026] [security2:error] [pid 751901:tid 752126] [client 31.22.56.56:61882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKBCrT982lovRn7gm8pAAAAF8"], referer: http://pkf.jo
[Thu Jul 30 12:29:41.257746 2026] [security2:error] [pid 751901:tid 752073] [client 20.215.211.95:61234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKBSrT982lovRn7gm8sQAAACo"]
[Thu Jul 30 12:29:41.257868 2026] [security2:error] [pid 751901:tid 752073] [client 20.215.211.95:61234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKBSrT982lovRn7gm8sQAAACo"]
[Thu Jul 30 12:29:41.308006 2026] [security2:error] [pid 751901:tid 751925] [remote 74.7.241.60:59436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuKBSrT982lovRn7gm8sgAAABc"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:29:41.391677 2026] [security2:error] [pid 751901:tid 752095] [client 151.244.158.232:8468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKBSrT982lovRn7gm8rAAAAEA"], referer: http://pkf.jo
[Thu Jul 30 12:29:42.094218 2026] [security2:error] [pid 751901:tid 752127] [client 38.190.144.4:59302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKBirT982lovRn7gm8vgAAAGA"]
[Thu Jul 30 12:29:42.094363 2026] [security2:error] [pid 751901:tid 752127] [client 38.190.144.4:59302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKBirT982lovRn7gm8vgAAAGA"]
[Thu Jul 30 12:29:42.645332 2026] [security2:error] [pid 751901:tid 751906] [remote 216.73.216.152:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuKBirT982lovRn7gm8zAAAPgQ"]
[Thu Jul 30 12:29:43.075788 2026] [security2:error] [pid 751901:tid 752065] [client 52.238.199.152:55536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/readme.php"] [unique_id "amuKByrT982lovRn7gm81wAAACI"]
[Thu Jul 30 12:29:43.344203 2026] [security2:error] [pid 751901:tid 751946] [remote 57.141.0.47:22150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuKByrT982lovRn7gm85AAAViw"]
[Thu Jul 30 12:29:43.804937 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:44.384512 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:45.819433 2026] [security2:error] [pid 751901:tid 752034] [client 20.215.211.95:45154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/xstelth.php"] [unique_id "amuKCSrT982lovRn7gm9EQAAAAM"]
[Thu Jul 30 12:29:45.819578 2026] [security2:error] [pid 751901:tid 752034] [client 20.215.211.95:45154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/xstelth.php"] [unique_id "amuKCSrT982lovRn7gm9EQAAAAM"]
[Thu Jul 30 12:29:45.853058 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.052860 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.059431 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:35220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKCirT982lovRn7gm9GQAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:46.298696 2026] [security2:error] [pid 751901:tid 752126] [client 20.215.211.95:45160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/584062352875874akp.php"] [unique_id "amuKCirT982lovRn7gm9HQAAAF8"]
[Thu Jul 30 12:29:46.298793 2026] [security2:error] [pid 751901:tid 752126] [client 20.215.211.95:45160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/584062352875874akp.php"] [unique_id "amuKCirT982lovRn7gm9HQAAAF8"]
[Thu Jul 30 12:29:46.366782 2026] [security2:error] [pid 751901:tid 752092] [client 102.180.136.138:56334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKCirT982lovRn7gm9GAAAAD0"], referer: http://pkf.jo
[Thu Jul 30 12:29:46.366814 2026] [core:notice] [pid 751901:tid 751962] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.493163 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.784794 2026] [core:notice] [pid 751901:tid 752057] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:46.788500 2026] [security2:error] [pid 751901:tid 752057] [client 103.215.74.26:35236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKCirT982lovRn7gm9KAAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:46.871623 2026] [core:notice] [pid 751901:tid 752100] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:47.520521 2026] [core:notice] [pid 751901:tid 752116] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:47.525492 2026] [security2:error] [pid 751901:tid 752116] [client 103.215.74.26:35250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKCyrT982lovRn7gm9OgAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:47.574485 2026] [security2:error] [pid 751901:tid 752082] [client 20.215.211.95:4640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/newfile.php"] [unique_id "amuKCyrT982lovRn7gm9OwAAADM"]
[Thu Jul 30 12:29:47.574585 2026] [security2:error] [pid 751901:tid 752082] [client 20.215.211.95:4640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/newfile.php"] [unique_id "amuKCyrT982lovRn7gm9OwAAADM"]
[Thu Jul 30 12:29:47.871736 2026] [security2:error] [pid 751901:tid 752130] [client 52.238.199.152:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/options.php"] [unique_id "amuKCyrT982lovRn7gm9QgAAAGM"]
[Thu Jul 30 12:29:48.267180 2026] [core:notice] [pid 751901:tid 752071] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:48.272401 2026] [security2:error] [pid 751901:tid 752071] [client 103.215.74.26:35262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDCrT982lovRn7gm9SAAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:48.942748 2026] [security2:error] [pid 751901:tid 752103] [client 62.102.148.166:49088] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuKDCrT982lovRn7gm9WQAAAEg"]
[Thu Jul 30 12:29:48.942847 2026] [security2:error] [pid 751901:tid 752103] [client 62.102.148.166:49088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuKDCrT982lovRn7gm9WQAAAEg"]
[Thu Jul 30 12:29:49.000286 2026] [core:notice] [pid 751901:tid 752109] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:49.005343 2026] [security2:error] [pid 751901:tid 752109] [client 103.215.74.26:35276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDCrT982lovRn7gm9XQAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:49.767461 2026] [core:notice] [pid 751901:tid 752116] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:49.774151 2026] [security2:error] [pid 751901:tid 752116] [client 103.215.74.26:35282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDSrT982lovRn7gm9bQAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:49.972574 2026] [security2:error] [pid 751901:tid 752031] [client 52.238.199.152:51551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/admin.php7"] [unique_id "amuKDSrT982lovRn7gm9cQAAAAA"]
[Thu Jul 30 12:29:50.508878 2026] [core:notice] [pid 751901:tid 752048] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:50.513020 2026] [security2:error] [pid 751901:tid 752048] [client 103.215.74.26:35296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDirT982lovRn7gm9eAAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:51.182901 2026] [security2:error] [pid 751901:tid 752132] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKDirT982lovRn7gm9ewAAAGU"]
[Thu Jul 30 12:29:51.242295 2026] [core:notice] [pid 751901:tid 752117] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:51.251138 2026] [security2:error] [pid 751901:tid 752117] [client 103.215.74.26:35310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDyrT982lovRn7gm9hQAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:51.843985 2026] [core:notice] [pid 751901:tid 751998] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:51.984555 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:51.989721 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:35326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKDyrT982lovRn7gm9nwAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:52.300583 2026] [security2:error] [pid 751901:tid 752082] [client 17.241.227.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuKECrT982lovRn7gm9pQAAADM"]
[Thu Jul 30 12:29:52.714281 2026] [core:notice] [pid 751901:tid 752086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:52.718516 2026] [security2:error] [pid 751901:tid 752086] [client 103.215.74.26:35340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKECrT982lovRn7gm9swAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:52.743639 2026] [security2:error] [pid 751901:tid 752054] [client 20.215.211.95:43122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/tBEZGQz.php"] [unique_id "amuKECrT982lovRn7gm9tQAAABc"]
[Thu Jul 30 12:29:52.743754 2026] [security2:error] [pid 751901:tid 752054] [client 20.215.211.95:43122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/tBEZGQz.php"] [unique_id "amuKECrT982lovRn7gm9tQAAABc"]
[Thu Jul 30 12:29:53.460664 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:53.465119 2026] [security2:error] [pid 751901:tid 752092] [client 103.215.74.26:36816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKESrT982lovRn7gm9wQAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:53.500530 2026] [core:notice] [pid 751901:tid 752104] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:53.568300 2026] [security2:error] [pid 751901:tid 752150] [client 172.202.44.182:44362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/chosen.php"] [unique_id "amuKESrT982lovRn7gm9xgAAAHc"]
[Thu Jul 30 12:29:54.038627 2026] [security2:error] [pid 751901:tid 752117] [client 38.190.144.4:24584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKEirT982lovRn7gm9zwAAAFY"]
[Thu Jul 30 12:29:54.038788 2026] [security2:error] [pid 751901:tid 752117] [client 38.190.144.4:24584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKEirT982lovRn7gm9zwAAAFY"]
[Thu Jul 30 12:29:54.187152 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:54.191200 2026] [security2:error] [pid 751901:tid 752121] [client 103.215.74.26:36824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKEirT982lovRn7gm90AAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:29:54.249495 2026] [security2:error] [pid 751901:tid 752043] [client 52.238.199.152:51557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/.well-known/wp-login.php"] [unique_id "amuKESrT982lovRn7gm9zgAAAAw"]
[Thu Jul 30 12:29:55.181615 2026] [security2:error] [pid 751901:tid 752038] [client 172.202.44.182:18697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/xleet.php"] [unique_id "amuKEyrT982lovRn7gm93gAAAAc"]
[Thu Jul 30 12:29:55.488693 2026] [security2:error] [pid 751901:tid 752078] [client 52.238.199.152:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuKEyrT982lovRn7gm95gAAAC8"]
[Thu Jul 30 12:29:56.917468 2026] [security2:error] [pid 751901:tid 752031] [client 172.202.44.182:37201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/ds.php"] [unique_id "amuKFCrT982lovRn7gm99wAAAAA"]
[Thu Jul 30 12:29:56.919038 2026] [security2:error] [pid 751901:tid 752048] [client 85.208.96.194:14002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/12/covid-19-brasil-tem-3116-milhoes-de-casos-e-6613-mil-mortes/"] [unique_id "amuKFCrT982lovRn7gm9-QAAABE"]
[Thu Jul 30 12:29:56.919121 2026] [security2:error] [pid 751901:tid 752048] [client 85.208.96.194:14002] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/12/covid-19-brasil-tem-3116-milhoes-de-casos-e-6613-mil-mortes/"] [unique_id "amuKFCrT982lovRn7gm9-QAAABE"]
[Thu Jul 30 12:29:57.262874 2026] [security2:error] [pid 751901:tid 752070] [client 52.238.199.152:41121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/file.php"] [unique_id "amuKFSrT982lovRn7gm9_AAAACc"]
[Thu Jul 30 12:29:58.752840 2026] [security2:error] [pid 751901:tid 752094] [client 172.202.44.182:18733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/f5.php"] [unique_id "amuKFirT982lovRn7gm-KgAAAD8"]
[Thu Jul 30 12:29:58.774616 2026] [security2:error] [pid 751901:tid 752046] [client 52.238.199.152:51580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/bak.php"] [unique_id "amuKFirT982lovRn7gm-KwAAAA8"]
[Thu Jul 30 12:29:58.825681 2026] [security2:error] [pid 751901:tid 752148] [client 50.6.43.217:44384] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuKFirT982lovRn7gm-LAAAAHU"]
[Thu Jul 30 12:29:58.944872 2026] [security2:error] [pid 751901:tid 752036] [client 50.6.43.217:44398] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuKFirT982lovRn7gm-MAAAAAU"]
[Thu Jul 30 12:29:58.948700 2026] [security2:error] [pid 751901:tid 752140] [client 20.215.211.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "black-devil-shop.com"] [uri "/index.php"] [unique_id "amuKFirT982lovRn7gm-FAAAAG0"]
[Thu Jul 30 12:29:58.948730 2026] [security2:error] [pid 751901:tid 752140] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "black-devil-shop.com"] [uri "/index.php"] [unique_id "amuKFirT982lovRn7gm-FAAAAG0"]
[Thu Jul 30 12:29:59.221635 2026] [security2:error] [pid 751901:tid 752126] [client 20.215.211.95:36587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "black-devil-shop.com"] [uri "/phpinfo"] [unique_id "amuKFirT982lovRn7gm-EgAAADg"]
[Thu Jul 30 12:29:59.484876 2026] [security2:error] [pid 751901:tid 752065] [client 49.13.164.148:45448] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuKFyrT982lovRn7gm-PQAAACI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:29:59.546141 2026] [security2:error] [pid 751901:tid 752068] [client 20.215.211.95:36587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/drykl.php"] [unique_id "amuKFyrT982lovRn7gm-QAAAACU"]
[Thu Jul 30 12:29:59.546255 2026] [security2:error] [pid 751901:tid 752068] [client 20.215.211.95:36587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/drykl.php"] [unique_id "amuKFyrT982lovRn7gm-QAAAACU"]
[Thu Jul 30 12:29:59.895849 2026] [core:notice] [pid 751901:tid 752079] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:59.900029 2026] [security2:error] [pid 751901:tid 752079] [client 49.13.164.148:45452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKFyrT982lovRn7gm-TQAAADA"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:29:59.931845 2026] [core:notice] [pid 751901:tid 752040] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:29:59.936613 2026] [security2:error] [pid 751901:tid 752040] [client 103.215.74.26:36830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKFyrT982lovRn7gm-TgAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:00.548913 2026] [security2:error] [pid 751901:tid 752154] [client 49.13.164.148:45458] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuKGCrT982lovRn7gm-YAAAAHs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:30:00.656490 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:00.660882 2026] [security2:error] [pid 751901:tid 752076] [client 103.215.74.26:36846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKGCrT982lovRn7gm-ZQAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:00.810918 2026] [security2:error] [pid 751901:tid 752096] [client 172.202.44.182:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/god4m.php"] [unique_id "amuKGCrT982lovRn7gm-bgAAAEE"]
[Thu Jul 30 12:30:01.228338 2026] [security2:error] [pid 751901:tid 752085] [client 52.238.199.152:63263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/config.php"] [unique_id "amuKGSrT982lovRn7gm-eQAAADY"]
[Thu Jul 30 12:30:01.380099 2026] [core:notice] [pid 751901:tid 752086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:01.384545 2026] [security2:error] [pid 751901:tid 752086] [client 103.215.74.26:36854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKGSrT982lovRn7gm-egAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:01.966447 2026] [security2:error] [pid 751901:tid 751977] [remote 107.23.62.75:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "fantasynamelist.com"] [uri "/gods/norse-gods-name-generator/"] [unique_id "amuKGSrT982lovRn7gm-gwAAGUs"]
[Thu Jul 30 12:30:02.135051 2026] [security2:error] [pid 751901:tid 752143] [client 52.238.199.152:41116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amuKGirT982lovRn7gm-igAAAHA"]
[Thu Jul 30 12:30:03.189356 2026] [core:notice] [pid 751901:tid 751980] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:04.141801 2026] [autoindex:error] [pid 751901:tid 752042] [client 20.215.211.95:21355] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_aa23bb9f/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:30:04.142532 2026] [security2:error] [pid 751901:tid 752042] [client 20.215.211.95:21355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "black-devil-shop.com"] [uri "/cgi-sys/403.html"] [unique_id "amuKHCrT982lovRn7gm-rAAAAAs"]
[Thu Jul 30 12:30:04.304339 2026] [security2:error] [pid 751901:tid 752081] [client 20.215.211.95:21355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "black-devil-shop.com"] [uri "/ls.php"] [unique_id "amuKHCrT982lovRn7gm-tAAAADI"]
[Thu Jul 30 12:30:04.304482 2026] [security2:error] [pid 751901:tid 752081] [client 20.215.211.95:21355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "black-devil-shop.com"] [uri "/ls.php"] [unique_id "amuKHCrT982lovRn7gm-tAAAADI"]
[Thu Jul 30 12:30:04.488080 2026] [core:notice] [pid 751901:tid 752133] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:04.536519 2026] [security2:error] [pid 751901:tid 752136] [client 66.249.73.97:44191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKHCrT982lovRn7gm-rQAAAGk"]
[Thu Jul 30 12:30:04.744890 2026] [security2:error] [pid 751901:tid 752110] [client 172.202.44.182:37226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/info.php"] [unique_id "amuKHCrT982lovRn7gm-ugAAAE8"]
[Thu Jul 30 12:30:06.003188 2026] [security2:error] [pid 751901:tid 752139] [client 52.238.199.152:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-activate.php"] [unique_id "amuKHirT982lovRn7gm-1AAAAGw"]
[Thu Jul 30 12:30:06.239791 2026] [security2:error] [pid 751901:tid 752097] [client 38.190.144.4:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKHirT982lovRn7gm-2AAAAEI"]
[Thu Jul 30 12:30:06.239931 2026] [security2:error] [pid 751901:tid 752097] [client 38.190.144.4:60354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKHirT982lovRn7gm-2AAAAEI"]
[Thu Jul 30 12:30:07.141799 2026] [security2:error] [pid 751901:tid 752063] [client 52.238.199.152:51581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-file.php"] [unique_id "amuKHyrT982lovRn7gm-5wAAACA"]
[Thu Jul 30 12:30:07.179962 2026] [security2:error] [pid 751901:tid 752146] [client 172.202.44.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuKHirT982lovRn7gm-1wAAAHM"]
[Thu Jul 30 12:30:07.194341 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:07.198676 2026] [security2:error] [pid 751901:tid 752149] [client 103.215.74.26:46688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKHyrT982lovRn7gm-6QAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:07.437920 2026] [security2:error] [pid 751901:tid 752085] [client 172.202.44.182:44393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/.__info.php"] [unique_id "amuKHyrT982lovRn7gm-8QAAADY"]
[Thu Jul 30 12:30:07.924827 2026] [core:notice] [pid 751901:tid 752133] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:07.928826 2026] [security2:error] [pid 751901:tid 752133] [client 103.215.74.26:46704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKHyrT982lovRn7gm--gAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:08.428234 2026] [security2:error] [pid 751901:tid 752107] [client 172.202.44.182:4848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/0.php"] [unique_id "amuKICrT982lovRn7gm_CwAAAEw"]
[Thu Jul 30 12:30:08.629458 2026] [security2:error] [pid 751901:tid 752092] [client 172.237.109.114:33123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm-_AAAAD0"]
[Thu Jul 30 12:30:08.630736 2026] [security2:error] [pid 751901:tid 752090] [client 172.237.109.114:64875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm-_QAAADs"]
[Thu Jul 30 12:30:08.655772 2026] [core:notice] [pid 751901:tid 752137] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:08.659830 2026] [security2:error] [pid 751901:tid 752137] [client 103.215.74.26:46706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKICrT982lovRn7gm_EAAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:09.267240 2026] [security2:error] [pid 751901:tid 752147] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_DQAAdGE"]
[Thu Jul 30 12:30:09.393071 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:09.400677 2026] [security2:error] [pid 751901:tid 752123] [client 103.215.74.26:46712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKISrT982lovRn7gm_KwAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:09.673939 2026] [security2:error] [pid 751901:tid 752033] [client 172.202.44.182:44396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/07.php"] [unique_id "amuKISrT982lovRn7gm_NQAAAAI"]
[Thu Jul 30 12:30:09.743064 2026] [security2:error] [pid 751901:tid 752127] [client 52.238.199.152:51575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/12.php"] [unique_id "amuKISrT982lovRn7gm_NgAAAGA"]
[Thu Jul 30 12:30:10.132445 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:10.137811 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:46714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKIirT982lovRn7gm_QAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:10.313968 2026] [security2:error] [pid 751901:tid 752066] [client 172.237.109.114:44796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_FQAAACM"]
[Thu Jul 30 12:30:10.402354 2026] [security2:error] [pid 751901:tid 752055] [client 172.237.109.114:34975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_FgAAABg"]
[Thu Jul 30 12:30:10.413247 2026] [security2:error] [pid 751901:tid 752106] [client 172.237.109.114:60286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKISrT982lovRn7gm_KQAAAEs"]
[Thu Jul 30 12:30:10.415361 2026] [security2:error] [pid 751901:tid 752098] [client 172.237.109.114:27311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_GAAAAEM"]
[Thu Jul 30 12:30:10.416158 2026] [security2:error] [pid 751901:tid 752120] [client 172.237.109.114:54732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_HQAAAFk"]
[Thu Jul 30 12:30:10.421698 2026] [security2:error] [pid 751901:tid 752105] [client 172.237.109.114:18182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_GwAAAEo"]
[Thu Jul 30 12:30:10.421913 2026] [security2:error] [pid 751901:tid 752077] [client 172.237.109.114:32678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_GQAAAC4"]
[Thu Jul 30 12:30:10.422493 2026] [security2:error] [pid 751901:tid 752038] [client 172.237.109.114:23478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_HAAAAAc"]
[Thu Jul 30 12:30:10.430294 2026] [security2:error] [pid 751901:tid 752059] [client 172.237.109.114:27488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_HgAAABw"]
[Thu Jul 30 12:30:10.446514 2026] [security2:error] [pid 751901:tid 752109] [client 172.237.109.114:51421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_FwAAAE4"]
[Thu Jul 30 12:30:10.453992 2026] [security2:error] [pid 751901:tid 752039] [client 172.237.109.114:61687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_IQAAAAg"]
[Thu Jul 30 12:30:10.459496 2026] [security2:error] [pid 751901:tid 752067] [client 172.237.109.114:40039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_GgAAACQ"]
[Thu Jul 30 12:30:10.463027 2026] [security2:error] [pid 751901:tid 752035] [client 172.237.109.114:28526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKISrT982lovRn7gm_KAAAAAQ"]
[Thu Jul 30 12:30:10.463767 2026] [security2:error] [pid 751901:tid 752061] [client 172.237.109.114:51807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_HwAAAB4"]
[Thu Jul 30 12:30:10.476953 2026] [security2:error] [pid 751901:tid 752128] [client 172.237.109.114:19121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_JAAAAGE"]
[Thu Jul 30 12:30:10.498376 2026] [security2:error] [pid 751901:tid 752117] [client 172.237.109.114:10603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_IwAAAFY"]
[Thu Jul 30 12:30:10.499752 2026] [security2:error] [pid 751901:tid 752063] [client 172.237.109.114:65188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKISrT982lovRn7gm_JwAAACA"]
[Thu Jul 30 12:30:10.527014 2026] [security2:error] [pid 751901:tid 752082] [client 172.237.109.114:40736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKICrT982lovRn7gm_JQAAADM"]
[Thu Jul 30 12:30:10.855150 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:10.862059 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:46726] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKIirT982lovRn7gm_SwAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:10.865872 2026] [security2:error] [pid 751901:tid 752095] [client 52.238.199.152:51533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/epinyins.php"] [unique_id "amuKIirT982lovRn7gm_TAAAAEA"]
[Thu Jul 30 12:30:11.426680 2026] [security2:error] [pid 751901:tid 752089] [client 172.202.44.182:44369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/dropdown.php"] [unique_id "amuKIyrT982lovRn7gm_WgAAADo"]
[Thu Jul 30 12:30:11.578987 2026] [core:notice] [pid 751901:tid 752084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:11.585182 2026] [security2:error] [pid 751901:tid 752084] [client 103.215.74.26:46736] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKIyrT982lovRn7gm_YAAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:11.918885 2026] [core:error] [pid 751901:tid 752040] [client 74.7.244.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:11.918915 2026] [core:error] [pid 751901:tid 752040] [client 74.7.244.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:11.919059 2026] [security2:error] [pid 751901:tid 752040] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuKIyrT982lovRn7gm_ZAAAAAk"]
[Thu Jul 30 12:30:11.919755 2026] [security2:error] [pid 751901:tid 752081] [client 74.7.244.59:60960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.mhh.zzt.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuKIyrT982lovRn7gm_YgAAMg8"]
[Thu Jul 30 12:30:12.323910 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:12.327922 2026] [security2:error] [pid 751901:tid 752037] [client 103.215.74.26:46752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJCrT982lovRn7gm_cAAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:12.493559 2026] [core:error] [pid 751901:tid 751923] [remote 74.7.175.140:39556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:12.493583 2026] [core:error] [pid 751901:tid 751923] [remote 74.7.175.140:39556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:12.493829 2026] [security2:error] [pid 751901:tid 752055] [client 74.7.175.140:39556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-78cdf888.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuKJCrT982lovRn7gm_cQAAGBU"]
[Thu Jul 30 12:30:12.497071 2026] [security2:error] [pid 751901:tid 752133] [client 85.208.96.200:17264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/01/26/bandidos-roubam-bancos-e-aterrorizam-cidade-na-pb/"] [unique_id "amuKJCrT982lovRn7gm_cgAAAGY"]
[Thu Jul 30 12:30:12.497167 2026] [security2:error] [pid 751901:tid 752133] [client 85.208.96.200:17264] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/01/26/bandidos-roubam-bancos-e-aterrorizam-cidade-na-pb/"] [unique_id "amuKJCrT982lovRn7gm_cgAAAGY"]
[Thu Jul 30 12:30:12.517549 2026] [security2:error] [pid 751901:tid 752152] [client 172.202.44.182:37200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/makeasmtp.php"] [unique_id "amuKJCrT982lovRn7gm_cwAAAHk"]
[Thu Jul 30 12:30:13.062963 2026] [core:notice] [pid 751901:tid 752042] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:13.067490 2026] [security2:error] [pid 751901:tid 752042] [client 103.215.74.26:47636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJSrT982lovRn7gm_ggAAAAs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:13.620330 2026] [security2:error] [pid 751901:tid 752104] [client 149.22.81.181:12776] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKJSrT982lovRn7gm_hgAAAEk"]
[Thu Jul 30 12:30:13.735076 2026] [security2:error] [pid 751901:tid 752100] [client 172.202.44.182:40392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-sigunq.php"] [unique_id "amuKJSrT982lovRn7gm_kwAAAEU"]
[Thu Jul 30 12:30:13.739785 2026] [security2:error] [pid 751901:tid 752104] [client 149.22.81.181:12776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKJSrT982lovRn7gm_hgAAAEk"]
[Thu Jul 30 12:30:13.739852 2026] [security2:error] [pid 751901:tid 752104] [client 149.22.81.181:12776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKJSrT982lovRn7gm_hgAAAEk"]
[Thu Jul 30 12:30:13.816380 2026] [core:notice] [pid 751901:tid 752102] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:13.823452 2026] [security2:error] [pid 751901:tid 752102] [client 103.215.74.26:47644] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJSrT982lovRn7gm_lAAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:14.558533 2026] [core:notice] [pid 751901:tid 752136] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:14.562658 2026] [security2:error] [pid 751901:tid 752136] [client 103.215.74.26:47650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJirT982lovRn7gm_oQAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:14.564083 2026] [security2:error] [pid 751901:tid 752153] [client 52.238.199.152:17628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amuKJirT982lovRn7gm_ogAAAHo"]
[Thu Jul 30 12:30:15.033647 2026] [security2:error] [pid 751901:tid 752075] [client 172.202.44.182:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wso112233.php"] [unique_id "amuKJyrT982lovRn7gm_rQAAACw"]
[Thu Jul 30 12:30:15.289321 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:15.293362 2026] [security2:error] [pid 751901:tid 752152] [client 103.215.74.26:47666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKJyrT982lovRn7gm_tAAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:16.016093 2026] [core:notice] [pid 751901:tid 752121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:16.020079 2026] [security2:error] [pid 751901:tid 752121] [client 103.215.74.26:47682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKKCrT982lovRn7gm_wAAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:16.149440 2026] [security2:error] [pid 751901:tid 752065] [client 172.202.44.182:4810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/alfanew.php"] [unique_id "amuKKCrT982lovRn7gm_wQAAACI"]
[Thu Jul 30 12:30:16.423357 2026] [security2:error] [pid 751901:tid 752107] [client 149.22.81.181:12780] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKKCrT982lovRn7gm_yAAAAEw"]
[Thu Jul 30 12:30:16.538610 2026] [security2:error] [pid 751901:tid 752107] [client 149.22.81.181:12780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKKCrT982lovRn7gm_yAAAAEw"]
[Thu Jul 30 12:30:16.733744 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:16.737521 2026] [security2:error] [pid 751901:tid 752149] [client 103.215.74.26:47684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKKCrT982lovRn7gm_zQAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:17.589822 2026] [security2:error] [pid 751901:tid 752113] [client 50.6.43.217:21034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amuKGirT982lovRn7gm-hAAAAFI"]
[Thu Jul 30 12:30:17.837142 2026] [security2:error] [pid 751901:tid 752033] [client 172.202.44.182:4812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/fw.php"] [unique_id "amuKKSrT982lovRn7gm_4gAAAAI"]
[Thu Jul 30 12:30:18.327712 2026] [security2:error] [pid 751901:tid 752075] [client 149.22.81.181:2102] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKKirT982lovRn7gm_7AAAACw"]
[Thu Jul 30 12:30:18.447873 2026] [security2:error] [pid 751901:tid 752075] [client 149.22.81.181:2102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "globalmarks.pk"] [uri "/wp-comments-post.php"] [unique_id "amuKKirT982lovRn7gm_7AAAACw"]
[Thu Jul 30 12:30:19.081000 2026] [security2:error] [pid 751901:tid 752104] [client 40.77.167.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKKCrT982lovRn7gm_ywAAAEk"]
[Thu Jul 30 12:30:19.180000 2026] [security2:error] [pid 751901:tid 752129] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKKirT982lovRn7gm_-wAAYjA"]
[Thu Jul 30 12:30:19.458672 2026] [core:notice] [pid 751901:tid 752099] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:19.553122 2026] [security2:error] [pid 751901:tid 752033] [client 40.77.167.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKKyrT982lovRn7gnAFQAAAAI"]
[Thu Jul 30 12:30:19.657108 2026] [security2:error] [pid 751901:tid 752096] [client 52.238.199.152:17553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/system_log.php"] [unique_id "amuKKyrT982lovRn7gnAHgAAAEE"]
[Thu Jul 30 12:30:19.900798 2026] [security2:error] [pid 751901:tid 752062] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKKyrT982lovRn7gnAFgAAHzo"]
[Thu Jul 30 12:30:20.711475 2026] [security2:error] [pid 751901:tid 752068] [client 172.202.44.182:37194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-login.php"] [unique_id "amuKLCrT982lovRn7gnAQAAAACU"]
[Thu Jul 30 12:30:21.080746 2026] [security2:error] [pid 751901:tid 752148] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKLCrT982lovRn7gnAPgAAAHU"]
[Thu Jul 30 12:30:21.142530 2026] [security2:error] [pid 751901:tid 752146] [client 52.238.199.152:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuKLSrT982lovRn7gnATgAAAHM"]
[Thu Jul 30 12:30:21.674497 2026] [security2:error] [pid 751901:tid 752110] [client 38.190.144.4:60866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKLSrT982lovRn7gnAWQAAAE8"]
[Thu Jul 30 12:30:21.674603 2026] [security2:error] [pid 751901:tid 752110] [client 38.190.144.4:60866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKLSrT982lovRn7gnAWQAAAE8"]
[Thu Jul 30 12:30:22.464686 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:22.469118 2026] [security2:error] [pid 751901:tid 752139] [client 103.215.74.26:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKLirT982lovRn7gnAZAAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:22.500694 2026] [security2:error] [pid 751901:tid 752075] [client 52.238.199.152:45329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ini.php"] [unique_id "amuKLirT982lovRn7gnAZQAAACw"]
[Thu Jul 30 12:30:22.696271 2026] [security2:error] [pid 751901:tid 752109] [client 172.202.44.182:18690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/simple.php"] [unique_id "amuKLirT982lovRn7gnAcQAAAE4"]
[Thu Jul 30 12:30:23.203303 2026] [core:notice] [pid 751901:tid 752155] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:23.207292 2026] [security2:error] [pid 751901:tid 752155] [client 103.215.74.26:30676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKLyrT982lovRn7gnAegAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:23.726252 2026] [security2:error] [pid 751901:tid 752138] [client 172.202.44.182:37185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/classsmtps.php"] [unique_id "amuKLyrT982lovRn7gnAhAAAAGs"]
[Thu Jul 30 12:30:23.930095 2026] [core:notice] [pid 751901:tid 752140] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:23.934964 2026] [security2:error] [pid 751901:tid 752140] [client 103.215.74.26:30692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKLyrT982lovRn7gnAhgAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:24.657510 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:24.662579 2026] [security2:error] [pid 751901:tid 752143] [client 103.215.74.26:30704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMCrT982lovRn7gnAlAAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:25.266796 2026] [security2:error] [pid 751901:tid 752127] [client 172.202.44.182:37184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-blog-header.php"] [unique_id "amuKMSrT982lovRn7gnApAAAAGA"]
[Thu Jul 30 12:30:25.274617 2026] [core:notice] [pid 751901:tid 752090] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:25.344032 2026] [security2:error] [pid 751901:tid 752097] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKMCrT982lovRn7gnAmgAAAEI"]
[Thu Jul 30 12:30:25.402468 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:25.407665 2026] [security2:error] [pid 751901:tid 752139] [client 103.215.74.26:30710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMSrT982lovRn7gnApgAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:26.033621 2026] [security2:error] [pid 751901:tid 752112] [client 52.238.199.152:17644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/ok.php"] [unique_id "amuKMirT982lovRn7gnAsQAAAFE"]
[Thu Jul 30 12:30:26.131243 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:26.135664 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:30716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMirT982lovRn7gnAsgAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:26.234574 2026] [security2:error] [pid 751901:tid 752070] [client 172.202.44.182:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-trackback.php"] [unique_id "amuKMirT982lovRn7gnAtgAAACc"]
[Thu Jul 30 12:30:26.418628 2026] [security2:error] [pid 751901:tid 752107] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKMSrT982lovRn7gnArAAATGY"]
[Thu Jul 30 12:30:26.447479 2026] [core:notice] [pid 751901:tid 752015] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:26.862288 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:26.867650 2026] [security2:error] [pid 751901:tid 752106] [client 103.215.74.26:30722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMirT982lovRn7gnAygAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:26.958556 2026] [security2:error] [pid 751901:tid 752016] [remote 57.141.0.52:47542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuKMirT982lovRn7gnAywAARHI"]
[Thu Jul 30 12:30:27.173221 2026] [security2:error] [pid 751901:tid 752077] [client 52.238.199.152:17554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuKMyrT982lovRn7gnAzAAAAC4"]
[Thu Jul 30 12:30:27.582356 2026] [security2:error] [pid 751901:tid 752064] [client 172.202.44.182:40435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-signup.php"] [unique_id "amuKMyrT982lovRn7gnA2AAAACE"]
[Thu Jul 30 12:30:27.582924 2026] [core:notice] [pid 751901:tid 752072] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:27.587264 2026] [security2:error] [pid 751901:tid 752072] [client 103.215.74.26:30732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKMyrT982lovRn7gnA1wAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:28.311379 2026] [core:notice] [pid 751901:tid 752104] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:28.315744 2026] [security2:error] [pid 751901:tid 752104] [client 103.215.74.26:30744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKNCrT982lovRn7gnA7QAAAEk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:28.563199 2026] [core:notice] [pid 751901:tid 752093] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:29.043423 2026] [core:notice] [pid 751901:tid 752115] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:29.047746 2026] [security2:error] [pid 751901:tid 752115] [client 103.215.74.26:30750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKNSrT982lovRn7gnBAgAAAFQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:29.633950 2026] [security2:error] [pid 751901:tid 752071] [client 52.238.199.152:45334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-configs.php"] [unique_id "amuKNSrT982lovRn7gnBDAAAACg"]
[Thu Jul 30 12:30:29.682291 2026] [security2:error] [pid 751901:tid 752081] [client 217.181.85.93:44234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKNSrT982lovRn7gnBCwAAMgA"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:30:29.750634 2026] [security2:error] [pid 751901:tid 752036] [client 172.202.44.182:44378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuKNSrT982lovRn7gnBDQAAAAU"]
[Thu Jul 30 12:30:29.836675 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:29.840756 2026] [security2:error] [pid 751901:tid 752076] [client 103.215.74.26:30760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKNSrT982lovRn7gnBDgAAAC0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:29.989990 2026] [security2:error] [pid 751901:tid 752152] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKNSrT982lovRn7gnBBgAAeQU"]
[Thu Jul 30 12:30:30.144633 2026] [security2:error] [pid 751901:tid 752072] [client 195.63.26.171:13792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKNirT982lovRn7gnBFQAAKQ8"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:30:30.520463 2026] [security2:error] [pid 751901:tid 752034] [client 52.238.199.152:17619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/01.php"] [unique_id "amuKNirT982lovRn7gnBIQAAAAM"]
[Thu Jul 30 12:30:30.626108 2026] [security2:error] [pid 751901:tid 752127] [client 114.119.131.46:22815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.northyorksheridanmall.com"] [uri "/events"] [unique_id "amuKNirT982lovRn7gnBJAAAAGA"], referer: https://www.northyorksheridanmall.com/events
[Thu Jul 30 12:30:31.105137 2026] [security2:error] [pid 751901:tid 752097] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKNirT982lovRn7gnBIgAAAEI"]
[Thu Jul 30 12:30:31.303411 2026] [security2:error] [pid 751901:tid 752078] [client 172.202.44.182:18731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-mail.php"] [unique_id "amuKNyrT982lovRn7gnBLgAAAC8"]
[Thu Jul 30 12:30:32.156486 2026] [security2:error] [pid 751901:tid 752122] [client 52.238.199.152:53673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amuKOCrT982lovRn7gnBTQAAAFs"]
[Thu Jul 30 12:30:32.292539 2026] [core:notice] [pid 751901:tid 752148] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:32.363109 2026] [security2:error] [pid 751901:tid 752058] [client 172.202.44.182:40393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-activate.php"] [unique_id "amuKOCrT982lovRn7gnBUAAAABs"]
[Thu Jul 30 12:30:32.965371 2026] [security2:error] [pid 751901:tid 752092] [client 20.215.191.139:11306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/geju.php"] [unique_id "amuKOCrT982lovRn7gnBWgAAAD0"]
[Thu Jul 30 12:30:33.248087 2026] [security2:error] [pid 751901:tid 752118] [client 52.238.199.152:17614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amuKOSrT982lovRn7gnBcQAAAFc"]
[Thu Jul 30 12:30:33.317608 2026] [core:notice] [pid 751901:tid 751973] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:33.560172 2026] [security2:error] [pid 751901:tid 752084] [client 172.202.44.182:18738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/post.php"] [unique_id "amuKOSrT982lovRn7gnBfgAAADU"]
[Thu Jul 30 12:30:33.971843 2026] [security2:error] [pid 751901:tid 752052] [client 20.215.191.139:7965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuKOSrT982lovRn7gnBggAAABU"]
[Thu Jul 30 12:30:33.994168 2026] [security2:error] [pid 751901:tid 751984] [remote 216.73.216.152:23441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuKOSrT982lovRn7gnBhAAAaFI"]
[Thu Jul 30 12:30:34.787680 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:34.948018 2026] [security2:error] [pid 751901:tid 752143] [client 172.202.44.182:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-2019.php"] [unique_id "amuKOirT982lovRn7gnBlwAAAHA"]
[Thu Jul 30 12:30:35.386928 2026] [core:notice] [pid 751901:tid 752073] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:35.553588 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:35.557924 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:34416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKOyrT982lovRn7gnBoAAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:35.716871 2026] [security2:error] [pid 751901:tid 752049] [client 85.208.96.195:62438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/24/mulher-descobre-gravidez-na-hora-de-dar-a-luz-e-crianca-nasce-com-quase-5-kg-achava-que-era-pedra-nos-rins/"] [unique_id "amuKOyrT982lovRn7gnBqAAAABI"]
[Thu Jul 30 12:30:35.717040 2026] [security2:error] [pid 751901:tid 752049] [client 85.208.96.195:62438] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/24/mulher-descobre-gravidez-na-hora-de-dar-a-luz-e-crianca-nasce-com-quase-5-kg-achava-que-era-pedra-nos-rins/"] [unique_id "amuKOyrT982lovRn7gnBqAAAABI"]
[Thu Jul 30 12:30:35.725345 2026] [security2:error] [pid 751901:tid 752036] [client 38.190.144.4:61394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKOyrT982lovRn7gnBqQAAAAU"]
[Thu Jul 30 12:30:35.725638 2026] [security2:error] [pid 751901:tid 752036] [client 38.190.144.4:61394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKOyrT982lovRn7gnBqQAAAAU"]
[Thu Jul 30 12:30:36.086173 2026] [security2:error] [pid 751901:tid 752140] [client 52.238.199.152:17638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuKPCrT982lovRn7gnBqgAAAG0"]
[Thu Jul 30 12:30:36.269012 2026] [security2:error] [pid 751901:tid 752068] [client 172.202.44.182:18735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/hoot.php"] [unique_id "amuKPCrT982lovRn7gnBsgAAACU"]
[Thu Jul 30 12:30:36.280686 2026] [core:notice] [pid 751901:tid 752127] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:36.284762 2026] [security2:error] [pid 751901:tid 752127] [client 103.215.74.26:34420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKPCrT982lovRn7gnBswAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:37.006606 2026] [core:notice] [pid 751901:tid 752048] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:37.010566 2026] [security2:error] [pid 751901:tid 752048] [client 103.215.74.26:34430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKPSrT982lovRn7gnBvgAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:38.240505 2026] [security2:error] [pid 751901:tid 752006] [remote 97.74.87.194:45118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuKPirT982lovRn7gnB2gAAXWg"]
[Thu Jul 30 12:30:38.344929 2026] [security2:error] [pid 751901:tid 752031] [client 52.238.199.152:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/db.php"] [unique_id "amuKPirT982lovRn7gnB4QAAAAA"]
[Thu Jul 30 12:30:38.582932 2026] [security2:error] [pid 751901:tid 752019] [remote 216.73.216.152:23441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuKPirT982lovRn7gnB4gAAf3U"]
[Thu Jul 30 12:30:39.091657 2026] [security2:error] [pid 751901:tid 752081] [client 172.202.44.182:18730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/log.php"] [unique_id "amuKPyrT982lovRn7gnB6gAAADI"]
[Thu Jul 30 12:30:39.339300 2026] [security2:error] [pid 751901:tid 752075] [client 20.215.191.139:60660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp.php"] [unique_id "amuKPyrT982lovRn7gnB9gAAACw"]
[Thu Jul 30 12:30:39.687644 2026] [security2:error] [pid 751901:tid 752034] [client 160.20.40.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuKPyrT982lovRn7gnB_AAAAAM"]
[Thu Jul 30 12:30:39.899606 2026] [security2:error] [pid 751901:tid 752112] [client 172.202.44.182:44372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/bak.php"] [unique_id "amuKPyrT982lovRn7gnCAgAAAFE"]
[Thu Jul 30 12:30:39.926666 2026] [security2:error] [pid 751901:tid 752065] [client 52.238.199.152:17607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/pages.php"] [unique_id "amuKPyrT982lovRn7gnCBgAAACI"]
[Thu Jul 30 12:30:41.063072 2026] [security2:error] [pid 751901:tid 752146] [client 20.215.191.139:7029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/aaa.php"] [unique_id "amuKQSrT982lovRn7gnCFgAAAHM"]
[Thu Jul 30 12:30:41.391216 2026] [security2:error] [pid 751901:tid 752116] [client 172.202.44.182:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/content.php"] [unique_id "amuKQSrT982lovRn7gnCGgAAAFU"]
[Thu Jul 30 12:30:41.631272 2026] [security2:error] [pid 751901:tid 752117] [client 20.215.191.139:9029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/hoot.php"] [unique_id "amuKQSrT982lovRn7gnCIQAAAFY"]
[Thu Jul 30 12:30:42.257326 2026] [security2:error] [pid 751901:tid 752114] [client 20.215.191.139:8523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/about.php"] [unique_id "amuKQirT982lovRn7gnCMAAAAFM"]
[Thu Jul 30 12:30:42.502018 2026] [security2:error] [pid 751901:tid 751920] [remote 74.7.241.60:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuKQirT982lovRn7gnCNQAAYBI"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:30:42.798749 2026] [core:notice] [pid 751901:tid 752155] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:42.803421 2026] [security2:error] [pid 751901:tid 752155] [client 103.215.74.26:34444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKQirT982lovRn7gnCQgAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:43.212333 2026] [security2:error] [pid 751901:tid 752061] [client 52.238.199.152:18229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/admin.php"] [unique_id "amuKQyrT982lovRn7gnCSgAAAB4"]
[Thu Jul 30 12:30:43.217215 2026] [security2:error] [pid 751901:tid 752103] [client 20.215.191.139:6991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/admin.php"] [unique_id "amuKQyrT982lovRn7gnCTAAAAEg"]
[Thu Jul 30 12:30:43.238559 2026] [security2:error] [pid 751901:tid 752091] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKQyrT982lovRn7gnCTwAAADw"]
[Thu Jul 30 12:30:43.238647 2026] [security2:error] [pid 751901:tid 752091] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKQyrT982lovRn7gnCTwAAADw"]
[Thu Jul 30 12:30:43.526947 2026] [core:notice] [pid 751901:tid 752096] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:43.531192 2026] [security2:error] [pid 751901:tid 752096] [client 103.215.74.26:12248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKQyrT982lovRn7gnCWAAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:43.577396 2026] [security2:error] [pid 751901:tid 752080] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKQyrT982lovRn7gnCXgAAADE"]
[Thu Jul 30 12:30:43.577495 2026] [security2:error] [pid 751901:tid 752080] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKQyrT982lovRn7gnCXgAAADE"]
[Thu Jul 30 12:30:43.758497 2026] [security2:error] [pid 751901:tid 752058] [client 172.202.44.182:45045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/upfile.php"] [unique_id "amuKQyrT982lovRn7gnCYwAAABs"]
[Thu Jul 30 12:30:43.908135 2026] [security2:error] [pid 751901:tid 752081] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuKQyrT982lovRn7gnCZAAAADI"]
[Thu Jul 30 12:30:43.908224 2026] [security2:error] [pid 751901:tid 752081] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuKQyrT982lovRn7gnCZAAAADI"]
[Thu Jul 30 12:30:44.050565 2026] [security2:error] [pid 751901:tid 752056] [client 20.215.191.139:8211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuKRCrT982lovRn7gnCZwAAABk"]
[Thu Jul 30 12:30:44.159791 2026] [security2:error] [pid 751901:tid 752108] [client 52.238.199.152:51351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-load.php"] [unique_id "amuKRCrT982lovRn7gnCawAAAE0"]
[Thu Jul 30 12:30:44.212208 2026] [security2:error] [pid 751901:tid 752034] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/err.php"] [unique_id "amuKRCrT982lovRn7gnCbwAAAAM"]
[Thu Jul 30 12:30:44.212307 2026] [security2:error] [pid 751901:tid 752034] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/err.php"] [unique_id "amuKRCrT982lovRn7gnCbwAAAAM"]
[Thu Jul 30 12:30:44.252762 2026] [core:notice] [pid 751901:tid 752134] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.259502 2026] [security2:error] [pid 751901:tid 752134] [client 103.215.74.26:12258] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRCrT982lovRn7gnCcQAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:44.510334 2026] [security2:error] [pid 751901:tid 752066] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/img.php"] [unique_id "amuKRCrT982lovRn7gnCcwAAACM"]
[Thu Jul 30 12:30:44.510451 2026] [security2:error] [pid 751901:tid 752066] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/img.php"] [unique_id "amuKRCrT982lovRn7gnCcwAAACM"]
[Thu Jul 30 12:30:44.750710 2026] [security2:error] [pid 751901:tid 752059] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/aa.php"] [unique_id "amuKRCrT982lovRn7gnCewAAABw"]
[Thu Jul 30 12:30:44.750815 2026] [security2:error] [pid 751901:tid 752059] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/aa.php"] [unique_id "amuKRCrT982lovRn7gnCewAAABw"]
[Thu Jul 30 12:30:44.828712 2026] [core:notice] [pid 751901:tid 752052] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.839186 2026] [core:notice] [pid 751901:tid 752130] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.839961 2026] [security2:error] [pid 751901:tid 752084] [client 172.202.44.182:44377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/bypass.php"] [unique_id "amuKRCrT982lovRn7gnCfgAAADU"]
[Thu Jul 30 12:30:44.854195 2026] [core:notice] [pid 751901:tid 752102] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.860878 2026] [core:notice] [pid 751901:tid 752088] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.982249 2026] [core:notice] [pid 751901:tid 752050] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:44.989114 2026] [security2:error] [pid 751901:tid 752050] [client 103.215.74.26:12266] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRCrT982lovRn7gnCgwAAABM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:45.050485 2026] [security2:error] [pid 751901:tid 752147] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/av.php"] [unique_id "amuKRSrT982lovRn7gnChAAAAHQ"]
[Thu Jul 30 12:30:45.050593 2026] [security2:error] [pid 751901:tid 752147] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/av.php"] [unique_id "amuKRSrT982lovRn7gnChAAAAHQ"]
[Thu Jul 30 12:30:45.300259 2026] [security2:error] [pid 751901:tid 752040] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xa.php"] [unique_id "amuKRSrT982lovRn7gnCkAAAAAk"]
[Thu Jul 30 12:30:45.300385 2026] [security2:error] [pid 751901:tid 752040] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xa.php"] [unique_id "amuKRSrT982lovRn7gnCkAAAAAk"]
[Thu Jul 30 12:30:45.541637 2026] [security2:error] [pid 751901:tid 752073] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/media.php"] [unique_id "amuKRSrT982lovRn7gnCkQAAACo"]
[Thu Jul 30 12:30:45.541750 2026] [security2:error] [pid 751901:tid 752073] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/media.php"] [unique_id "amuKRSrT982lovRn7gnCkQAAACo"]
[Thu Jul 30 12:30:45.551547 2026] [security2:error] [pid 751901:tid 752031] [client 20.215.191.139:7035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuKRSrT982lovRn7gnCkgAAAAA"]
[Thu Jul 30 12:30:45.616292 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:45.642293 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:45.671849 2026] [core:notice] [pid 751901:tid 752117] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:45.737566 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:45.741355 2026] [security2:error] [pid 751901:tid 752046] [client 103.215.74.26:12274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRSrT982lovRn7gnCnQAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:45.780152 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/images.php"] [unique_id "amuKRSrT982lovRn7gnCnwAAABo"]
[Thu Jul 30 12:30:45.780239 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/images.php"] [unique_id "amuKRSrT982lovRn7gnCnwAAABo"]
[Thu Jul 30 12:30:45.904906 2026] [security2:error] [pid 751901:tid 752121] [client 172.202.44.182:45024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/updates.php"] [unique_id "amuKRSrT982lovRn7gnCoQAAAFo"]
[Thu Jul 30 12:30:45.914839 2026] [core:notice] [pid 751901:tid 752099] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:46.015188 2026] [security2:error] [pid 751901:tid 752140] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/gecko.php"] [unique_id "amuKRirT982lovRn7gnCowAAAG0"]
[Thu Jul 30 12:30:46.015298 2026] [security2:error] [pid 751901:tid 752140] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/gecko.php"] [unique_id "amuKRirT982lovRn7gnCowAAAG0"]
[Thu Jul 30 12:30:46.276588 2026] [security2:error] [pid 751901:tid 752144] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/82.php"] [unique_id "amuKRirT982lovRn7gnCrQAAAHE"]
[Thu Jul 30 12:30:46.276698 2026] [security2:error] [pid 751901:tid 752144] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/82.php"] [unique_id "amuKRirT982lovRn7gnCrQAAAHE"]
[Thu Jul 30 12:30:46.286486 2026] [security2:error] [pid 751901:tid 752081] [client 20.215.191.139:9031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuKRirT982lovRn7gnCrgAAADI"]
[Thu Jul 30 12:30:46.474916 2026] [core:notice] [pid 751901:tid 752079] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:46.478841 2026] [security2:error] [pid 751901:tid 752079] [client 103.215.74.26:12290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRirT982lovRn7gnCuAAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:46.511904 2026] [security2:error] [pid 751901:tid 752048] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xstelth.php"] [unique_id "amuKRirT982lovRn7gnCuQAAABE"]
[Thu Jul 30 12:30:46.512013 2026] [security2:error] [pid 751901:tid 752048] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xstelth.php"] [unique_id "amuKRirT982lovRn7gnCuQAAABE"]
[Thu Jul 30 12:30:46.560334 2026] [security2:error] [pid 751901:tid 752036] [client 52.238.199.152:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/as/function.php"] [unique_id "amuKRirT982lovRn7gnCugAAAAU"]
[Thu Jul 30 12:30:46.763927 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xp.php"] [unique_id "amuKRirT982lovRn7gnCwQAAADg"]
[Thu Jul 30 12:30:46.764098 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xp.php"] [unique_id "amuKRirT982lovRn7gnCwQAAADg"]
[Thu Jul 30 12:30:46.921767 2026] [core:error] [pid 751901:tid 752040] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.921790 2026] [core:error] [pid 751901:tid 752040] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.939763 2026] [core:error] [pid 751901:tid 752132] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.939788 2026] [core:error] [pid 751901:tid 752132] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.945716 2026] [core:error] [pid 751901:tid 752058] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.945734 2026] [core:error] [pid 751901:tid 752058] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.951204 2026] [core:error] [pid 751901:tid 752090] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.951223 2026] [core:error] [pid 751901:tid 752090] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.973147 2026] [core:error] [pid 751901:tid 752063] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:46.973167 2026] [core:error] [pid 751901:tid 752063] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:47.045825 2026] [security2:error] [pid 751901:tid 752051] [client 38.190.144.4:61921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKRyrT982lovRn7gnC3gAAABQ"]
[Thu Jul 30 12:30:47.047859 2026] [security2:error] [pid 751901:tid 752051] [client 38.190.144.4:61921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKRyrT982lovRn7gnC3gAAABQ"]
[Thu Jul 30 12:30:47.053614 2026] [security2:error] [pid 751901:tid 752085] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuKRyrT982lovRn7gnC3wAAADY"]
[Thu Jul 30 12:30:47.053730 2026] [security2:error] [pid 751901:tid 752085] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuKRyrT982lovRn7gnC3wAAADY"]
[Thu Jul 30 12:30:47.196800 2026] [core:notice] [pid 751901:tid 752089] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:47.203812 2026] [security2:error] [pid 751901:tid 752089] [client 103.215.74.26:12292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRyrT982lovRn7gnC4AAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:47.243298 2026] [security2:error] [pid 751901:tid 752057] [client 43.131.26.226:39194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.26.131.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuKRirT982lovRn7gnC3QAAABo"]
[Thu Jul 30 12:30:47.295226 2026] [security2:error] [pid 751901:tid 752060] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/adminner.php"] [unique_id "amuKRyrT982lovRn7gnC5AAAAB0"]
[Thu Jul 30 12:30:47.295345 2026] [security2:error] [pid 751901:tid 752060] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/adminner.php"] [unique_id "amuKRyrT982lovRn7gnC5AAAAB0"]
[Thu Jul 30 12:30:47.538217 2026] [security2:error] [pid 751901:tid 752127] [client 172.202.44.182:44367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/xmrlpc.php"] [unique_id "amuKRyrT982lovRn7gnC7QAAAGA"]
[Thu Jul 30 12:30:47.545043 2026] [security2:error] [pid 751901:tid 752074] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/a.php"] [unique_id "amuKRyrT982lovRn7gnC7gAAACs"]
[Thu Jul 30 12:30:47.545134 2026] [security2:error] [pid 751901:tid 752074] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/a.php"] [unique_id "amuKRyrT982lovRn7gnC7gAAACs"]
[Thu Jul 30 12:30:47.551564 2026] [security2:error] [pid 751901:tid 752067] [client 20.215.191.139:2410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuKRyrT982lovRn7gnC7wAAACQ"]
[Thu Jul 30 12:30:47.786248 2026] [security2:error] [pid 751901:tid 752061] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/k.php"] [unique_id "amuKRyrT982lovRn7gnC_wAAAB4"]
[Thu Jul 30 12:30:47.786357 2026] [security2:error] [pid 751901:tid 752061] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/k.php"] [unique_id "amuKRyrT982lovRn7gnC_wAAAB4"]
[Thu Jul 30 12:30:47.796631 2026] [core:notice] [pid 751901:tid 751959] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:47.951711 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:47.955885 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:12300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKRyrT982lovRn7gnDBQAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:48.046450 2026] [security2:error] [pid 751901:tid 752106] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/222.php"] [unique_id "amuKSCrT982lovRn7gnDDAAAAEs"]
[Thu Jul 30 12:30:48.046558 2026] [security2:error] [pid 751901:tid 752106] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/222.php"] [unique_id "amuKSCrT982lovRn7gnDDAAAAEs"]
[Thu Jul 30 12:30:48.136105 2026] [core:notice] [pid 751901:tid 751973] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:48.303550 2026] [security2:error] [pid 751901:tid 752085] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/mac.php"] [unique_id "amuKSCrT982lovRn7gnDEgAAADY"]
[Thu Jul 30 12:30:48.303665 2026] [security2:error] [pid 751901:tid 752085] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/mac.php"] [unique_id "amuKSCrT982lovRn7gnDEgAAADY"]
[Thu Jul 30 12:30:48.548475 2026] [security2:error] [pid 751901:tid 752083] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuKSCrT982lovRn7gnDFgAAADQ"]
[Thu Jul 30 12:30:48.588171 2026] [security2:error] [pid 751901:tid 751947] [remote 216.73.216.152:26249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuKSCrT982lovRn7gnDFwAAOi0"]
[Thu Jul 30 12:30:48.618900 2026] [security2:error] [pid 751901:tid 752111] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKSCrT982lovRn7gnDCwAAAFA"]
[Thu Jul 30 12:30:48.672630 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:48.676619 2026] [security2:error] [pid 751901:tid 752143] [client 103.215.74.26:12312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSCrT982lovRn7gnDGAAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:48.718797 2026] [security2:error] [pid 751901:tid 752054] [client 172.202.44.182:18747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/ae.php"] [unique_id "amuKSCrT982lovRn7gnDGQAAABc"]
[Thu Jul 30 12:30:48.790248 2026] [security2:error] [pid 751901:tid 752144] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuKSCrT982lovRn7gnDGgAAAHE"]
[Thu Jul 30 12:30:48.926341 2026] [security2:error] [pid 751901:tid 752042] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/ops.php"] [unique_id "amuKSCrT982lovRn7gnDIQAAAAs"]
[Thu Jul 30 12:30:48.926471 2026] [security2:error] [pid 751901:tid 752042] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/ops.php"] [unique_id "amuKSCrT982lovRn7gnDIQAAAAs"]
[Thu Jul 30 12:30:49.073115 2026] [security2:error] [pid 751901:tid 752127] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/8.php"] [unique_id "amuKSSrT982lovRn7gnDIgAAAGA"]
[Thu Jul 30 12:30:49.073221 2026] [security2:error] [pid 751901:tid 752127] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/8.php"] [unique_id "amuKSSrT982lovRn7gnDIgAAAGA"]
[Thu Jul 30 12:30:49.366234 2026] [security2:error] [pid 751901:tid 752079] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/FWAZ.php"] [unique_id "amuKSSrT982lovRn7gnDJwAAADA"]
[Thu Jul 30 12:30:49.366334 2026] [security2:error] [pid 751901:tid 752079] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/FWAZ.php"] [unique_id "amuKSSrT982lovRn7gnDJwAAADA"]
[Thu Jul 30 12:30:49.401122 2026] [core:notice] [pid 751901:tid 752067] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:49.404876 2026] [security2:error] [pid 751901:tid 752067] [client 103.215.74.26:12324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSSrT982lovRn7gnDKQAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:49.612964 2026] [security2:error] [pid 751901:tid 752102] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/biufile.php"] [unique_id "amuKSSrT982lovRn7gnDLwAAAEc"]
[Thu Jul 30 12:30:49.613089 2026] [security2:error] [pid 751901:tid 752102] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/biufile.php"] [unique_id "amuKSSrT982lovRn7gnDLwAAAEc"]
[Thu Jul 30 12:30:49.918908 2026] [security2:error] [pid 751901:tid 752113] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/coffexium.php"] [unique_id "amuKSSrT982lovRn7gnDNAAAAFI"]
[Thu Jul 30 12:30:49.919018 2026] [security2:error] [pid 751901:tid 752113] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/coffexium.php"] [unique_id "amuKSSrT982lovRn7gnDNAAAAFI"]
[Thu Jul 30 12:30:50.058678 2026] [security2:error] [pid 751901:tid 752037] [client 52.238.199.152:35968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/filter.php"] [unique_id "amuKSirT982lovRn7gnDOwAAAAY"]
[Thu Jul 30 12:30:50.133725 2026] [core:notice] [pid 751901:tid 752053] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:50.137644 2026] [security2:error] [pid 751901:tid 752053] [client 103.215.74.26:12326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSirT982lovRn7gnDPAAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:50.163834 2026] [security2:error] [pid 751901:tid 752107] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/simple.php"] [unique_id "amuKSirT982lovRn7gnDPQAAAEw"]
[Thu Jul 30 12:30:50.163919 2026] [security2:error] [pid 751901:tid 752107] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/simple.php"] [unique_id "amuKSirT982lovRn7gnDPQAAAEw"]
[Thu Jul 30 12:30:50.301423 2026] [security2:error] [pid 751901:tid 752148] [client 172.202.44.182:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/moon.php"] [unique_id "amuKSirT982lovRn7gnDPwAAAHU"]
[Thu Jul 30 12:30:50.401699 2026] [security2:error] [pid 751901:tid 752047] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/fpwch.php"] [unique_id "amuKSirT982lovRn7gnDQAAAABA"]
[Thu Jul 30 12:30:50.401809 2026] [security2:error] [pid 751901:tid 752047] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/fpwch.php"] [unique_id "amuKSirT982lovRn7gnDQAAAABA"]
[Thu Jul 30 12:30:50.659596 2026] [security2:error] [pid 751901:tid 752064] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/dex.php"] [unique_id "amuKSirT982lovRn7gnDSwAAACE"]
[Thu Jul 30 12:30:50.659688 2026] [security2:error] [pid 751901:tid 752064] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/dex.php"] [unique_id "amuKSirT982lovRn7gnDSwAAACE"]
[Thu Jul 30 12:30:50.886629 2026] [core:notice] [pid 751901:tid 752051] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:50.890670 2026] [security2:error] [pid 751901:tid 752051] [client 103.215.74.26:12332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSirT982lovRn7gnDUgAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:50.983338 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "markmocek.com"] [uri "/1.php"] [unique_id "amuKSirT982lovRn7gnDWQAAABo"]
[Thu Jul 30 12:30:50.983434 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/1.php"] [unique_id "amuKSirT982lovRn7gnDWQAAABo"]
[Thu Jul 30 12:30:50.983503 2026] [security2:error] [pid 751901:tid 752057] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/1.php"] [unique_id "amuKSirT982lovRn7gnDWQAAABo"]
[Thu Jul 30 12:30:51.010642 2026] [security2:error] [pid 751901:tid 752092] [client 20.215.191.139:7027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuKSyrT982lovRn7gnDWgAAAD0"]
[Thu Jul 30 12:30:51.171218 2026] [security2:error] [pid 751901:tid 752082] [client 216.73.216.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.designmenow.net"] [uri "/public/index.php"] [unique_id "amuKSirT982lovRn7gnDPgAAM08"]
[Thu Jul 30 12:30:51.286491 2026] [security2:error] [pid 751901:tid 752050] [client 172.202.44.182:37218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/blog.php"] [unique_id "amuKSyrT982lovRn7gnDYQAAABM"]
[Thu Jul 30 12:30:51.303185 2026] [security2:error] [pid 751901:tid 752033] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuKSyrT982lovRn7gnDYgAAAAI"]
[Thu Jul 30 12:30:51.563323 2026] [security2:error] [pid 751901:tid 752079] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/config.json.php"] [unique_id "amuKSyrT982lovRn7gnDZwAAADA"]
[Thu Jul 30 12:30:51.563420 2026] [security2:error] [pid 751901:tid 752079] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/config.json.php"] [unique_id "amuKSyrT982lovRn7gnDZwAAADA"]
[Thu Jul 30 12:30:51.607261 2026] [core:notice] [pid 751901:tid 752070] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:51.611165 2026] [security2:error] [pid 751901:tid 752070] [client 103.215.74.26:12342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKSyrT982lovRn7gnDagAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:51.725907 2026] [security2:error] [pid 751901:tid 752100] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/k2.php"] [unique_id "amuKSyrT982lovRn7gnDbwAAAEU"]
[Thu Jul 30 12:30:51.726010 2026] [security2:error] [pid 751901:tid 752100] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/k2.php"] [unique_id "amuKSyrT982lovRn7gnDbwAAAEU"]
[Thu Jul 30 12:30:51.807756 2026] [security2:error] [pid 751901:tid 752127] [client 20.215.191.139:11580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuKSyrT982lovRn7gnDcAAAAGA"]
[Thu Jul 30 12:30:51.826734 2026] [core:error] [pid 751901:tid 751942] [remote 74.7.244.17:41216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:51.826766 2026] [core:error] [pid 751901:tid 751942] [remote 74.7.244.17:41216] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:30:51.826968 2026] [security2:error] [pid 751901:tid 752084] [client 74.7.244.17:41216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-55933577.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuKSyrT982lovRn7gnDcQAANSg"]
[Thu Jul 30 12:30:52.039333 2026] [security2:error] [pid 751901:tid 752145] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/raw.php"] [unique_id "amuKTCrT982lovRn7gnDcwAAAHI"]
[Thu Jul 30 12:30:52.039440 2026] [security2:error] [pid 751901:tid 752145] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/raw.php"] [unique_id "amuKTCrT982lovRn7gnDcwAAAHI"]
[Thu Jul 30 12:30:52.286738 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp.php"] [unique_id "amuKTCrT982lovRn7gnDeQAAADg"]
[Thu Jul 30 12:30:52.286845 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp.php"] [unique_id "amuKTCrT982lovRn7gnDeQAAADg"]
[Thu Jul 30 12:30:52.339638 2026] [core:notice] [pid 751901:tid 752103] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:52.343683 2026] [security2:error] [pid 751901:tid 752103] [client 103.215.74.26:12344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTCrT982lovRn7gnDegAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:52.526732 2026] [security2:error] [pid 751901:tid 752141] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/fffm.php"] [unique_id "amuKTCrT982lovRn7gnDgQAAAG4"]
[Thu Jul 30 12:30:52.526827 2026] [security2:error] [pid 751901:tid 752141] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/fffm.php"] [unique_id "amuKTCrT982lovRn7gnDgQAAAG4"]
[Thu Jul 30 12:30:52.779879 2026] [security2:error] [pid 751901:tid 752049] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/111.php"] [unique_id "amuKTCrT982lovRn7gnDhwAAABI"]
[Thu Jul 30 12:30:52.780041 2026] [security2:error] [pid 751901:tid 752049] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/111.php"] [unique_id "amuKTCrT982lovRn7gnDhwAAABI"]
[Thu Jul 30 12:30:52.858445 2026] [security2:error] [pid 751901:tid 752037] [client 20.215.191.139:11535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuKTCrT982lovRn7gnDiAAAAAY"]
[Thu Jul 30 12:30:53.001638 2026] [security2:error] [pid 751901:tid 752038] [client 172.202.44.182:4818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/ini.php"] [unique_id "amuKTSrT982lovRn7gnDigAAAAc"]
[Thu Jul 30 12:30:53.079204 2026] [core:notice] [pid 751901:tid 752098] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:53.083070 2026] [security2:error] [pid 751901:tid 752098] [client 103.215.74.26:56714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTSrT982lovRn7gnDjgAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:53.094484 2026] [security2:error] [pid 751901:tid 752083] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuKTSrT982lovRn7gnDjwAAADQ"]
[Thu Jul 30 12:30:53.234938 2026] [security2:error] [pid 751901:tid 752040] [client 52.238.199.152:17589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/he.php"] [unique_id "amuKTSrT982lovRn7gnDmAAAAAk"]
[Thu Jul 30 12:30:53.260764 2026] [security2:error] [pid 751901:tid 752065] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/ws.php"] [unique_id "amuKTSrT982lovRn7gnDmgAAACI"]
[Thu Jul 30 12:30:53.260898 2026] [security2:error] [pid 751901:tid 752065] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/ws.php"] [unique_id "amuKTSrT982lovRn7gnDmgAAACI"]
[Thu Jul 30 12:30:53.584545 2026] [security2:error] [pid 751901:tid 752135] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/coffee.php"] [unique_id "amuKTSrT982lovRn7gnDngAAAGg"]
[Thu Jul 30 12:30:53.584681 2026] [security2:error] [pid 751901:tid 752135] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/coffee.php"] [unique_id "amuKTSrT982lovRn7gnDngAAAGg"]
[Thu Jul 30 12:30:53.816904 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:53.820850 2026] [security2:error] [pid 751901:tid 752139] [client 103.215.74.26:56724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTSrT982lovRn7gnDogAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:53.839877 2026] [security2:error] [pid 751901:tid 752158] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/goods.php"] [unique_id "amuKTSrT982lovRn7gnDowAAAH8"]
[Thu Jul 30 12:30:53.840029 2026] [security2:error] [pid 751901:tid 752158] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/goods.php"] [unique_id "amuKTSrT982lovRn7gnDowAAAH8"]
[Thu Jul 30 12:30:53.840055 2026] [security2:error] [pid 751901:tid 752093] [client 172.202.44.182:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/admin-ajax.php"] [unique_id "amuKTSrT982lovRn7gnDpAAAAD4"]
[Thu Jul 30 12:30:53.862497 2026] [security2:error] [pid 751901:tid 752074] [client 20.215.191.139:8517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/content.php"] [unique_id "amuKTSrT982lovRn7gnDpQAAACs"]
[Thu Jul 30 12:30:54.079086 2026] [security2:error] [pid 751901:tid 752059] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuKTirT982lovRn7gnDqAAAABw"]
[Thu Jul 30 12:30:54.079203 2026] [security2:error] [pid 751901:tid 752059] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuKTirT982lovRn7gnDqAAAABw"]
[Thu Jul 30 12:30:54.080861 2026] [security2:error] [pid 751901:tid 752109] [client 37.120.155.179:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuKTirT982lovRn7gnDpwAAAE4"]
[Thu Jul 30 12:30:54.080935 2026] [security2:error] [pid 751901:tid 752109] [client 37.120.155.179:56394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuKTirT982lovRn7gnDpwAAAE4"]
[Thu Jul 30 12:30:54.370805 2026] [security2:error] [pid 751901:tid 752148] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuKTirT982lovRn7gnDtAAAAHU"]
[Thu Jul 30 12:30:54.370904 2026] [security2:error] [pid 751901:tid 752148] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuKTirT982lovRn7gnDtAAAAHU"]
[Thu Jul 30 12:30:54.512060 2026] [security2:error] [pid 751901:tid 752100] [client 52.238.199.152:17549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amuKTirT982lovRn7gnDtgAAAEU"]
[Thu Jul 30 12:30:54.571903 2026] [core:notice] [pid 751901:tid 752141] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:54.576215 2026] [security2:error] [pid 751901:tid 752141] [client 103.215.74.26:56738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTirT982lovRn7gnDtwAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:54.609762 2026] [security2:error] [pid 751901:tid 752157] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuKTirT982lovRn7gnDuAAAAH4"]
[Thu Jul 30 12:30:54.609863 2026] [security2:error] [pid 751901:tid 752157] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuKTirT982lovRn7gnDuAAAAH4"]
[Thu Jul 30 12:30:54.709292 2026] [security2:error] [pid 751901:tid 752047] [client 172.202.44.182:18723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/akc.php"] [unique_id "amuKTirT982lovRn7gnDwAAAABA"]
[Thu Jul 30 12:30:54.784594 2026] [security2:error] [pid 751901:tid 752073] [client 38.190.144.4:64407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKTirT982lovRn7gnDwQAAACo"]
[Thu Jul 30 12:30:54.784743 2026] [security2:error] [pid 751901:tid 752073] [client 38.190.144.4:64407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKTirT982lovRn7gnDwQAAACo"]
[Thu Jul 30 12:30:54.852050 2026] [security2:error] [pid 751901:tid 752063] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuKTirT982lovRn7gnDxQAAACA"]
[Thu Jul 30 12:30:54.852159 2026] [security2:error] [pid 751901:tid 752063] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuKTirT982lovRn7gnDxQAAACA"]
[Thu Jul 30 12:30:55.100471 2026] [security2:error] [pid 751901:tid 752092] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuKTyrT982lovRn7gnDxwAAAD0"]
[Thu Jul 30 12:30:55.100583 2026] [security2:error] [pid 751901:tid 752092] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuKTyrT982lovRn7gnDxwAAAD0"]
[Thu Jul 30 12:30:55.303278 2026] [core:notice] [pid 751901:tid 752057] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:55.308098 2026] [security2:error] [pid 751901:tid 752057] [client 103.215.74.26:56742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKTyrT982lovRn7gnDzgAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:55.343864 2026] [security2:error] [pid 751901:tid 752134] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuKTyrT982lovRn7gnDzwAAAGc"]
[Thu Jul 30 12:30:55.343953 2026] [security2:error] [pid 751901:tid 752134] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuKTyrT982lovRn7gnDzwAAAGc"]
[Thu Jul 30 12:30:55.585747 2026] [security2:error] [pid 751901:tid 752078] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/404.php"] [unique_id "amuKTyrT982lovRn7gnD0wAAAC8"]
[Thu Jul 30 12:30:55.585887 2026] [security2:error] [pid 751901:tid 752078] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/404.php"] [unique_id "amuKTyrT982lovRn7gnD0wAAAC8"]
[Thu Jul 30 12:30:55.685433 2026] [security2:error] [pid 751901:tid 752042] [client 172.202.44.182:18732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/akcc.php"] [unique_id "amuKTyrT982lovRn7gnD2AAAAAs"]
[Thu Jul 30 12:30:55.822879 2026] [security2:error] [pid 751901:tid 752048] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xxx.php"] [unique_id "amuKTyrT982lovRn7gnD3QAAABE"]
[Thu Jul 30 12:30:55.823003 2026] [security2:error] [pid 751901:tid 752048] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xxx.php"] [unique_id "amuKTyrT982lovRn7gnD3QAAABE"]
[Thu Jul 30 12:30:55.823411 2026] [security2:error] [pid 751901:tid 752094] [client 52.238.199.152:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amuKTyrT982lovRn7gnD3gAAAD8"]
[Thu Jul 30 12:30:56.043707 2026] [core:notice] [pid 751901:tid 752067] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:56.047705 2026] [security2:error] [pid 751901:tid 752067] [client 103.215.74.26:56758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKUCrT982lovRn7gnD5AAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:56.312524 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuKUCrT982lovRn7gnD8AAAADg"]
[Thu Jul 30 12:30:56.312636 2026] [security2:error] [pid 751901:tid 752087] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuKUCrT982lovRn7gnD8AAAADg"]
[Thu Jul 30 12:30:56.370536 2026] [security2:error] [pid 751901:tid 752040] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKTyrT982lovRn7gnD3AAACUI"]
[Thu Jul 30 12:30:56.507131 2026] [security2:error] [pid 751901:tid 752107] [client 20.215.191.139:11578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuKUCrT982lovRn7gnD8gAAAEw"]
[Thu Jul 30 12:30:56.557009 2026] [security2:error] [pid 751901:tid 752053] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/234ff.php"] [unique_id "amuKUCrT982lovRn7gnD9gAAABY"]
[Thu Jul 30 12:30:56.557093 2026] [security2:error] [pid 751901:tid 752053] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/234ff.php"] [unique_id "amuKUCrT982lovRn7gnD9gAAABY"]
[Thu Jul 30 12:30:56.769297 2026] [core:notice] [pid 751901:tid 752096] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:56.773624 2026] [security2:error] [pid 751901:tid 752096] [client 103.215.74.26:56772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKUCrT982lovRn7gnD_QAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:30:56.866037 2026] [security2:error] [pid 751901:tid 752136] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/133.php"] [unique_id "amuKUCrT982lovRn7gnD_gAAAGk"]
[Thu Jul 30 12:30:56.866142 2026] [security2:error] [pid 751901:tid 752136] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/133.php"] [unique_id "amuKUCrT982lovRn7gnD_gAAAGk"]
[Thu Jul 30 12:30:56.972008 2026] [security2:error] [pid 751901:tid 752116] [client 172.202.44.182:37212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/asasx.php"] [unique_id "amuKUCrT982lovRn7gnD_wAAAFU"]
[Thu Jul 30 12:30:57.135731 2026] [security2:error] [pid 751901:tid 752041] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-ws68.php"] [unique_id "amuKUSrT982lovRn7gnEBgAAAAo"]
[Thu Jul 30 12:30:57.135820 2026] [security2:error] [pid 751901:tid 752041] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-ws68.php"] [unique_id "amuKUSrT982lovRn7gnEBgAAAAo"]
[Thu Jul 30 12:30:57.141301 2026] [core:notice] [pid 751901:tid 752038] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:30:57.215139 2026] [security2:error] [pid 751901:tid 752063] [client 20.215.191.139:8552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuKUSrT982lovRn7gnEDgAAACA"]
[Thu Jul 30 12:30:57.412217 2026] [security2:error] [pid 751901:tid 752065] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/mgrr.php"] [unique_id "amuKUSrT982lovRn7gnEEgAAACI"]
[Thu Jul 30 12:30:57.412359 2026] [security2:error] [pid 751901:tid 752065] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/mgrr.php"] [unique_id "amuKUSrT982lovRn7gnEEgAAACI"]
[Thu Jul 30 12:30:57.648988 2026] [security2:error] [pid 751901:tid 752035] [client 51.116.238.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.238.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/55.php"] [unique_id "amuKUSrT982lovRn7gnEFwAAAAQ"]
[Thu Jul 30 12:30:57.649135 2026] [security2:error] [pid 751901:tid 752035] [client 51.116.238.8:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/55.php"] [unique_id "amuKUSrT982lovRn7gnEFwAAAAQ"]
[Thu Jul 30 12:30:57.781933 2026] [security2:error] [pid 751901:tid 752105] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKUSrT982lovRn7gnECgAAAEo"]
[Thu Jul 30 12:30:57.964114 2026] [security2:error] [pid 751901:tid 752079] [client 20.215.191.139:12295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuKUSrT982lovRn7gnEHwAAADA"]
[Thu Jul 30 12:30:58.459192 2026] [security2:error] [pid 751901:tid 752125] [client 172.202.44.182:4801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/axx.php"] [unique_id "amuKUirT982lovRn7gnELQAAAF4"]
[Thu Jul 30 12:30:58.654305 2026] [security2:error] [pid 751901:tid 752062] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKUSrT982lovRn7gnEHgAAHww"]
[Thu Jul 30 12:30:58.711098 2026] [security2:error] [pid 751901:tid 752103] [client 20.215.191.139:13444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuKUirT982lovRn7gnEMgAAAEg"]
[Thu Jul 30 12:30:59.031950 2026] [autoindex:error] [pid 751901:tid 752073] [client 43.163.206.70:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.n1rmalabet88.com
[Thu Jul 30 12:30:59.377835 2026] [security2:error] [pid 751901:tid 752117] [client 172.202.44.182:18717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/berax.php"] [unique_id "amuKUyrT982lovRn7gnESwAAAFY"]
[Thu Jul 30 12:30:59.790644 2026] [security2:error] [pid 751901:tid 751931] [remote 154.38.175.180:55478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.175.38.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKUyrT982lovRn7gnEWAAAQB0"]
[Thu Jul 30 12:30:59.825426 2026] [security2:error] [pid 751901:tid 752042] [client 47.128.121.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuKUyrT982lovRn7gnETwAAAAs"]
[Thu Jul 30 12:31:00.219548 2026] [security2:error] [pid 751901:tid 752155] [client 172.202.44.182:37197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/build.php"] [unique_id "amuKVCrT982lovRn7gnEXAAAAHw"]
[Thu Jul 30 12:31:01.063942 2026] [security2:error] [pid 751901:tid 751945] [remote 57.141.0.53:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKVSrT982lovRn7gnEfAAAXSs"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,polyester,plastic,linen,wood,nylon,lycra,titanium&min_price=300&orderby=rating&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 12:31:01.065030 2026] [security2:error] [pid 751901:tid 751962] [remote 57.141.0.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKVSrT982lovRn7gnEewAAFjw"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,polyester,plastic,linen,wood,nylon,lycra,titanium&min_price=300&orderby=rating&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 12:31:01.352764 2026] [security2:error] [pid 751901:tid 752075] [client 172.202.44.182:44374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/buy.php"] [unique_id "amuKVSrT982lovRn7gnEgAAAACw"]
[Thu Jul 30 12:31:01.398601 2026] [security2:error] [pid 751901:tid 752136] [client 20.215.191.139:12619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuKVSrT982lovRn7gnEiAAAAGk"]
[Thu Jul 30 12:31:01.871275 2026] [core:notice] [pid 751901:tid 752140] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:02.248435 2026] [security2:error] [pid 751901:tid 752082] [client 20.215.191.139:12351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuKVirT982lovRn7gnEvQAAADM"]
[Thu Jul 30 12:31:02.562751 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:02.567346 2026] [security2:error] [pid 751901:tid 752157] [client 103.215.74.26:56784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKVirT982lovRn7gnEyAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:02.693202 2026] [security2:error] [pid 751901:tid 752062] [client 172.202.44.182:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/checkbox.php"] [unique_id "amuKVirT982lovRn7gnEyQAAAB8"]
[Thu Jul 30 12:31:03.158795 2026] [security2:error] [pid 751901:tid 752020] [remote 103.28.36.200:35088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuKVirT982lovRn7gnEzQAALHY"]
[Thu Jul 30 12:31:03.303767 2026] [core:notice] [pid 751901:tid 752097] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:03.307952 2026] [security2:error] [pid 751901:tid 752097] [client 103.215.74.26:38168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKVyrT982lovRn7gnE2AAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:04.952635 2026] [security2:error] [pid 751901:tid 752118] [client 172.202.44.182:4833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/cong.php"] [unique_id "amuKWCrT982lovRn7gnFCgAAAFc"]
[Thu Jul 30 12:31:05.265546 2026] [security2:error] [pid 751901:tid 752082] [client 172.237.109.114:28921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE-gAAADM"]
[Thu Jul 30 12:31:05.278384 2026] [security2:error] [pid 751901:tid 752074] [client 172.237.109.114:1331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE8wAAACs"]
[Thu Jul 30 12:31:05.280493 2026] [security2:error] [pid 751901:tid 752115] [client 172.237.109.114:7798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE9QAAAFQ"]
[Thu Jul 30 12:31:05.280517 2026] [security2:error] [pid 751901:tid 752113] [client 172.237.109.114:2077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE9AAAAFI"]
[Thu Jul 30 12:31:05.284105 2026] [security2:error] [pid 751901:tid 752132] [client 172.237.109.114:44109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE-wAAAGU"]
[Thu Jul 30 12:31:05.290455 2026] [security2:error] [pid 751901:tid 752031] [client 172.237.109.114:25677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE-QAAAAA"]
[Thu Jul 30 12:31:05.301101 2026] [security2:error] [pid 751901:tid 752076] [client 172.237.109.114:52333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE9gAAAC0"]
[Thu Jul 30 12:31:05.305524 2026] [security2:error] [pid 751901:tid 752093] [client 172.237.109.114:18986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE-AAAAD4"]
[Thu Jul 30 12:31:05.315627 2026] [security2:error] [pid 751901:tid 752086] [client 172.237.109.114:44494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE9wAAADc"]
[Thu Jul 30 12:31:05.324152 2026] [security2:error] [pid 751901:tid 752116] [client 172.237.109.114:4963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE_QAAAFU"]
[Thu Jul 30 12:31:05.330849 2026] [security2:error] [pid 751901:tid 752150] [client 172.237.109.114:38831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWCrT982lovRn7gnE_AAAAHc"]
[Thu Jul 30 12:31:05.594205 2026] [security2:error] [pid 751901:tid 752048] [client 38.190.144.4:64902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKWSrT982lovRn7gnFIwAAABE"]
[Thu Jul 30 12:31:05.594390 2026] [security2:error] [pid 751901:tid 752048] [client 38.190.144.4:64902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKWSrT982lovRn7gnFIwAAABE"]
[Thu Jul 30 12:31:06.107133 2026] [security2:error] [pid 751901:tid 752127] [client 172.202.44.182:37210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/file4.php"] [unique_id "amuKWirT982lovRn7gnFQAAAAGA"]
[Thu Jul 30 12:31:06.306396 2026] [security2:error] [pid 751901:tid 752105] [client 172.237.109.114:7409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFFwAAAEo"]
[Thu Jul 30 12:31:06.329542 2026] [security2:error] [pid 751901:tid 752075] [client 172.237.109.114:60667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFDQAAACw"]
[Thu Jul 30 12:31:06.333005 2026] [security2:error] [pid 751901:tid 752070] [client 172.237.109.114:9447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFDgAAACc"]
[Thu Jul 30 12:31:06.338840 2026] [security2:error] [pid 751901:tid 752097] [client 172.237.109.114:21927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFEwAAAEI"]
[Thu Jul 30 12:31:06.346128 2026] [security2:error] [pid 751901:tid 752114] [client 172.237.109.114:20008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFCwAAAFM"]
[Thu Jul 30 12:31:06.346817 2026] [security2:error] [pid 751901:tid 752050] [client 172.237.109.114:46616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFFgAAABM"]
[Thu Jul 30 12:31:06.350938 2026] [security2:error] [pid 751901:tid 752037] [client 172.237.109.114:54567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFDwAAAAY"]
[Thu Jul 30 12:31:06.354555 2026] [security2:error] [pid 751901:tid 752123] [client 172.237.109.114:7545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFDAAAAFw"]
[Thu Jul 30 12:31:06.362855 2026] [security2:error] [pid 751901:tid 752092] [client 172.237.109.114:54134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKWSrT982lovRn7gnFGAAAAD0"]
[Thu Jul 30 12:31:06.718838 2026] [security2:error] [pid 751901:tid 752138] [client 43.172.198.133:48938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/02/08/au-hasard-de-la-toile-32/"] [unique_id "amuKWirT982lovRn7gnFTwAAAGs"]
[Thu Jul 30 12:31:06.924189 2026] [security2:error] [pid 751901:tid 752104] [client 172.202.44.182:4834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/flower.php"] [unique_id "amuKWirT982lovRn7gnFXAAAAEk"]
[Thu Jul 30 12:31:07.086941 2026] [security2:error] [pid 751901:tid 752048] [client 20.215.191.139:42459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuKWyrT982lovRn7gnFYgAAABE"]
[Thu Jul 30 12:31:07.434738 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:07.443043 2026] [security2:error] [pid 751901:tid 752157] [client 43.173.181.164:49624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/02/08/au-hasard-de-la-toile-32/"] [unique_id "amuKWyrT982lovRn7gnFcQAAAH4"], referer: https://carnetdeshopping.com/index.php/2015/02/08/au-hasard-de-la-toile-32/?replytocom=1438
[Thu Jul 30 12:31:07.770430 2026] [security2:error] [pid 751901:tid 752143] [client 172.202.44.182:18708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/form.php"] [unique_id "amuKWyrT982lovRn7gnFeQAAAHA"]
[Thu Jul 30 12:31:07.800120 2026] [security2:error] [pid 751901:tid 752116] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKWyrT982lovRn7gnFbwAAVQc"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:31:08.163299 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:08.168909 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:08.336158 2026] [security2:error] [pid 751901:tid 752032] [client 20.215.191.139:11094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuKXCrT982lovRn7gnFiQAAAAE"]
[Thu Jul 30 12:31:08.424700 2026] [security2:error] [pid 751901:tid 752034] [client 74.7.175.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rvi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuKWirT982lovRn7gnFYQAAAAM"]
[Thu Jul 30 12:31:08.425453 2026] [security2:error] [pid 751901:tid 752065] [client 74.7.175.164:54242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rvi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuKWirT982lovRn7gnFXwAAIgg"]
[Thu Jul 30 12:31:08.723360 2026] [security2:error] [pid 751901:tid 752147] [client 172.202.44.182:40388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/gecko.php"] [unique_id "amuKXCrT982lovRn7gnFkQAAAHQ"]
[Thu Jul 30 12:31:08.907469 2026] [security2:error] [pid 751901:tid 752064] [client 20.215.191.139:30824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuKXCrT982lovRn7gnFpAAAACE"]
[Thu Jul 30 12:31:09.033204 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:09.040090 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:38176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKXSrT982lovRn7gnFqAAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:09.666898 2026] [security2:error] [pid 751901:tid 752084] [client 20.215.191.139:30795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuKXSrT982lovRn7gnFxwAAADU"]
[Thu Jul 30 12:31:10.333520 2026] [security2:error] [pid 751901:tid 752130] [client 45.180.149.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKXSrT982lovRn7gnFwgAAY0Q"], referer: https://allmontecristi.com
[Thu Jul 30 12:31:10.357290 2026] [security2:error] [pid 751901:tid 752051] [client 50.6.43.217:11626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuKXirT982lovRn7gnF6AAAABQ"]
[Thu Jul 30 12:31:10.368220 2026] [security2:error] [pid 751901:tid 752098] [client 50.6.43.217:11640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuKXirT982lovRn7gnF6gAAAEM"]
[Thu Jul 30 12:31:10.381485 2026] [security2:error] [pid 751901:tid 752153] [client 50.6.43.217:11652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuKXirT982lovRn7gnF7QAAAHo"]
[Thu Jul 30 12:31:11.136788 2026] [security2:error] [pid 751901:tid 752000] [remote 47.128.27.35:30148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-4-retro-leair-max-95-neon/"] [unique_id "amuKXyrT982lovRn7gnGBwAAf2I"]
[Thu Jul 30 12:31:11.170615 2026] [security2:error] [pid 751901:tid 752157] [client 20.215.191.139:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuKXyrT982lovRn7gnGCAAAAH4"]
[Thu Jul 30 12:31:12.164286 2026] [security2:error] [pid 751901:tid 752061] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKXyrT982lovRn7gnGFgAAHmQ"]
[Thu Jul 30 12:31:12.796175 2026] [proxy:error] [pid 751901:tid 752088] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:12.796271 2026] [proxy_http:error] [pid 751901:tid 752088] [client 34.233.129.35:65044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:12.796834 2026] [proxy:error] [pid 751901:tid 752088] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:12.796875 2026] [proxy_http:error] [pid 751901:tid 752088] [client 34.233.129.35:65044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:12.817658 2026] [proxy:error] [pid 751901:tid 752135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:12.817722 2026] [proxy_http:error] [pid 751901:tid 752135] [client 34.224.175.62:62181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:12.818296 2026] [proxy:error] [pid 751901:tid 752135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:12.818349 2026] [proxy_http:error] [pid 751901:tid 752135] [client 34.224.175.62:62181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:13.002445 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:13.282754 2026] [fcgid:warn] [pid 751901:tid 752072] (70014)End of file found: [client 152.32.207.42:53114] mod_fcgid: can't get data from http client
[Thu Jul 30 12:31:13.499236 2026] [security2:error] [pid 751901:tid 752150] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKYSrT982lovRn7gnGQwAAd28"]
[Thu Jul 30 12:31:13.829382 2026] [proxy:error] [pid 751901:tid 752121] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:13.829447 2026] [proxy_http:error] [pid 751901:tid 752121] [client 152.32.207.42:53122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:13.830308 2026] [proxy:error] [pid 751901:tid 752121] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:13.830370 2026] [proxy_http:error] [pid 751901:tid 752121] [client 152.32.207.42:53122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:13.867034 2026] [security2:error] [pid 751901:tid 752079] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKYSrT982lovRn7gnGRwAAADA"]
[Thu Jul 30 12:31:14.583250 2026] [security2:error] [pid 751901:tid 752077] [client 20.215.191.139:15016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/about.php"] [unique_id "amuKYirT982lovRn7gnGYQAAAC4"]
[Thu Jul 30 12:31:14.695326 2026] [proxy:error] [pid 751901:tid 752134] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:14.695396 2026] [proxy_http:error] [pid 751901:tid 752134] [client 152.32.207.42:53126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:14.695942 2026] [proxy:error] [pid 751901:tid 752134] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:14.695998 2026] [proxy_http:error] [pid 751901:tid 752134] [client 152.32.207.42:53126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:14.763953 2026] [core:notice] [pid 751901:tid 752071] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:14.768431 2026] [security2:error] [pid 751901:tid 752071] [client 103.215.74.26:5578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKYirT982lovRn7gnGZwAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:14.822549 2026] [core:notice] [pid 751901:tid 752082] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:15.893497 2026] [security2:error] [pid 751901:tid 752037] [client 172.202.44.182:4852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/kyami.php"] [unique_id "amuKYyrT982lovRn7gnGgAAAAAY"]
[Thu Jul 30 12:31:15.949323 2026] [security2:error] [pid 751901:tid 751911] [remote 114.119.130.27:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/robots.txt"] [unique_id "amuKYyrT982lovRn7gnGgQAAXQk"], referer: https://spececigarette.com/robots.txt
[Thu Jul 30 12:31:15.950929 2026] [security2:error] [pid 751901:tid 752093] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKYyrT982lovRn7gnGeAAAAD4"]
[Thu Jul 30 12:31:16.096570 2026] [proxy:error] [pid 751901:tid 752068] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:16.096650 2026] [proxy_http:error] [pid 751901:tid 752068] [client 152.32.207.42:53132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:16.097226 2026] [proxy:error] [pid 751901:tid 752068] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:16.097270 2026] [proxy_http:error] [pid 751901:tid 752068] [client 152.32.207.42:53132] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:16.387970 2026] [security2:error] [pid 751901:tid 752150] [client 38.190.144.4:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKZCrT982lovRn7gnGjAAAAHc"]
[Thu Jul 30 12:31:16.388106 2026] [security2:error] [pid 751901:tid 752150] [client 38.190.144.4:65412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKZCrT982lovRn7gnGjAAAAHc"]
[Thu Jul 30 12:31:16.784914 2026] [security2:error] [pid 751901:tid 752038] [client 172.202.44.182:40389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/manager.php"] [unique_id "amuKZCrT982lovRn7gnGlgAAAAc"]
[Thu Jul 30 12:31:16.855033 2026] [security2:error] [pid 751901:tid 751968] [remote 45.146.192.214:27506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.192.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuKZCrT982lovRn7gnGlwAANUI"]
[Thu Jul 30 12:31:17.599558 2026] [proxy:error] [pid 751901:tid 752099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:17.599654 2026] [proxy_http:error] [pid 751901:tid 752099] [client 152.32.207.42:53136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:17.600238 2026] [proxy:error] [pid 751901:tid 752099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:17.600288 2026] [proxy_http:error] [pid 751901:tid 752099] [client 152.32.207.42:53136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:17.635515 2026] [security2:error] [pid 751901:tid 752132] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKZSrT982lovRn7gnGmQAAZQU"]
[Thu Jul 30 12:31:17.703874 2026] [security2:error] [pid 751901:tid 752153] [client 172.202.44.182:31881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/mari.php"] [unique_id "amuKZSrT982lovRn7gnGrAAAAHo"]
[Thu Jul 30 12:31:17.858171 2026] [security2:error] [pid 751901:tid 752106] [client 20.215.191.139:2063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.well-known/about.php"] [unique_id "amuKZSrT982lovRn7gnGswAAAEs"]
[Thu Jul 30 12:31:17.954626 2026] [security2:error] [pid 751901:tid 752036] [client 87.250.224.218:47690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKZSrT982lovRn7gnGpwAAAAU"]
[Thu Jul 30 12:31:18.286928 2026] [security2:error] [pid 751901:tid 752097] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKZSrT982lovRn7gnGqAAAAEI"]
[Thu Jul 30 12:31:18.428758 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:18.850816 2026] [security2:error] [pid 751901:tid 752037] [client 161.248.56.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKZirT982lovRn7gnGtQAABhw"], referer: https://allmontecristi.com
[Thu Jul 30 12:31:18.968653 2026] [security2:error] [pid 751901:tid 752079] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKZirT982lovRn7gnGwQAAADA"]
[Thu Jul 30 12:31:18.991734 2026] [security2:error] [pid 751901:tid 752053] [client 20.215.191.139:9564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuKZirT982lovRn7gnG0AAAABY"]
[Thu Jul 30 12:31:19.021619 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:19.035127 2026] [core:error] [pid 751901:tid 751903] [remote 74.7.175.132:60538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:31:19.035143 2026] [core:error] [pid 751901:tid 751903] [remote 74.7.175.132:60538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:31:19.035384 2026] [security2:error] [pid 751901:tid 752156] [client 74.7.175.132:60538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuKZyrT982lovRn7gnG0gAAfQE"]
[Thu Jul 30 12:31:19.434750 2026] [core:notice] [pid 751901:tid 752116] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:19.609142 2026] [security2:error] [pid 751901:tid 752071] [client 172.202.44.182:18692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/nc4.php"] [unique_id "amuKZyrT982lovRn7gnG3gAAACg"]
[Thu Jul 30 12:31:20.164427 2026] [security2:error] [pid 751901:tid 752126] [client 20.215.191.139:9565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuKaCrT982lovRn7gnG7gAAAF8"]
[Thu Jul 30 12:31:20.488931 2026] [core:notice] [pid 751901:tid 752085] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:20.493490 2026] [security2:error] [pid 751901:tid 752085] [client 103.215.74.26:5584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKaCrT982lovRn7gnG-AAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:20.640904 2026] [cgid:error] [pid 751901:tid 752138] [client 172.202.44.182:0] AH01265: stderr from /home2/dlrdjbte/public_html/website_b749bff5/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:31:20.703843 2026] [security2:error] [pid 751901:tid 752122] [client 20.215.191.139:9578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/img/about.php"] [unique_id "amuKaCrT982lovRn7gnG_gAAAFs"]
[Thu Jul 30 12:31:21.231624 2026] [core:notice] [pid 751901:tid 752091] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:21.236948 2026] [security2:error] [pid 751901:tid 752091] [client 103.215.74.26:5586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKaSrT982lovRn7gnHCQAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:21.530510 2026] [security2:error] [pid 751901:tid 752119] [client 20.215.191.139:7803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuKaSrT982lovRn7gnHEAAAAFg"]
[Thu Jul 30 12:31:21.859755 2026] [security2:error] [pid 751901:tid 752154] [client 91.92.41.115:55041] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.azureskyfilms.com"] [uri "/.env"] [unique_id "amuKaSrT982lovRn7gnHFwAAAHs"]
[Thu Jul 30 12:31:21.956033 2026] [core:notice] [pid 751901:tid 752101] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:21.960338 2026] [security2:error] [pid 751901:tid 752101] [client 103.215.74.26:5596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKaSrT982lovRn7gnHGwAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:22.691158 2026] [core:notice] [pid 751901:tid 752086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:22.695550 2026] [security2:error] [pid 751901:tid 752086] [client 103.215.74.26:5610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKairT982lovRn7gnHMgAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:23.205541 2026] [security2:error] [pid 751901:tid 752135] [client 91.92.41.115:55130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.azureskyfilms.com"] [uri "/.env"] [unique_id "amuKayrT982lovRn7gnHPQAAAGg"]
[Thu Jul 30 12:31:23.420262 2026] [core:notice] [pid 751901:tid 752146] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:23.424235 2026] [security2:error] [pid 751901:tid 752146] [client 103.215.74.26:3024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKayrT982lovRn7gnHQQAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:23.829378 2026] [security2:error] [pid 751901:tid 752157] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKayrT982lovRn7gnHQAAAAH4"]
[Thu Jul 30 12:31:24.051723 2026] [security2:error] [pid 751901:tid 752051] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKayrT982lovRn7gnHTQAAABQ"]
[Thu Jul 30 12:31:24.146579 2026] [core:notice] [pid 751901:tid 752033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:24.151483 2026] [security2:error] [pid 751901:tid 752033] [client 103.215.74.26:3030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbCrT982lovRn7gnHYAAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:24.402647 2026] [security2:error] [pid 751901:tid 752143] [client 20.215.191.139:7695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuKbCrT982lovRn7gnHZQAAAHA"]
[Thu Jul 30 12:31:24.864202 2026] [core:notice] [pid 751901:tid 752074] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:24.868770 2026] [security2:error] [pid 751901:tid 752074] [client 103.215.74.26:3036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbCrT982lovRn7gnHcgAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:25.113523 2026] [core:notice] [pid 751901:tid 751978] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:25.602774 2026] [core:notice] [pid 751901:tid 752077] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:25.607201 2026] [security2:error] [pid 751901:tid 752077] [client 103.215.74.26:3040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbSrT982lovRn7gnHgwAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:25.736220 2026] [security2:error] [pid 751901:tid 752078] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKbSrT982lovRn7gnHewAAL0U"]
[Thu Jul 30 12:31:26.027222 2026] [security2:error] [pid 751901:tid 752084] [client 194.26.202.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kbaagency.com"] [uri "/index.php"] [unique_id "amuKbSrT982lovRn7gnHjgAANVY"], referer: https://kbaagency.com/
[Thu Jul 30 12:31:26.225488 2026] [proxy:error] [pid 751901:tid 752002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:26.225541 2026] [proxy_http:error] [pid 751901:tid 752002] [remote 74.7.244.29:48220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:26.226112 2026] [proxy:error] [pid 751901:tid 752002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:31:26.226157 2026] [proxy_http:error] [pid 751901:tid 752002] [remote 74.7.244.29:48220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:31:26.246330 2026] [security2:error] [pid 751901:tid 752072] [client 20.215.191.139:31189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuKbirT982lovRn7gnHnAAAACk"]
[Thu Jul 30 12:31:26.338227 2026] [core:notice] [pid 751901:tid 752033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:26.344877 2026] [security2:error] [pid 751901:tid 752033] [client 103.215.74.26:3046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbirT982lovRn7gnHnQAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:26.788875 2026] [security2:error] [pid 751901:tid 752096] [client 216.73.216.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.investigations.worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuKbSrT982lovRn7gnHkAAAQVk"]
[Thu Jul 30 12:31:27.070761 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:27.077504 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:3056] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbyrT982lovRn7gnHqwAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:27.162371 2026] [security2:error] [pid 751901:tid 752050] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKbirT982lovRn7gnHoAAAABM"]
[Thu Jul 30 12:31:27.213276 2026] [security2:error] [pid 751901:tid 752085] [client 37.65.175.59:9624] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuKbyrT982lovRn7gnHrwAAADY"]
[Thu Jul 30 12:31:27.256927 2026] [security2:error] [pid 751901:tid 752089] [client 5.59.109.28:47654] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuKbyrT982lovRn7gnHswAAADo"]
[Thu Jul 30 12:31:27.400602 2026] [security2:error] [pid 751901:tid 752138] [client 81.34.140.222:46642] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuKbyrT982lovRn7gnHtwAAAGs"]
[Thu Jul 30 12:31:27.411916 2026] [security2:error] [pid 751901:tid 752103] [client 92.40.176.6:57037] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuKbyrT982lovRn7gnHuAAAAEg"]
[Thu Jul 30 12:31:27.444939 2026] [security2:error] [pid 751901:tid 752109] [client 38.190.144.4:49532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKbyrT982lovRn7gnHuQAAAE4"]
[Thu Jul 30 12:31:27.445160 2026] [security2:error] [pid 751901:tid 752109] [client 38.190.144.4:49532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKbyrT982lovRn7gnHuQAAAE4"]
[Thu Jul 30 12:31:27.829521 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:27.837287 2026] [security2:error] [pid 751901:tid 752063] [client 103.215.74.26:3058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKbyrT982lovRn7gnHxwAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:28.123386 2026] [security2:error] [pid 751901:tid 752043] [client 40.77.167.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuKbyrT982lovRn7gnHwgAAAAw"]
[Thu Jul 30 12:31:28.175971 2026] [security2:error] [pid 751901:tid 752040] [client 24.57.181.146:42820] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuKcCrT982lovRn7gnH0gAAAAk"]
[Thu Jul 30 12:31:28.435556 2026] [security2:error] [pid 751901:tid 752141] [client 20.215.191.139:42898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuKcCrT982lovRn7gnH4AAAAG4"]
[Thu Jul 30 12:31:28.555969 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:28.560027 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:3068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcCrT982lovRn7gnH4gAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:28.749095 2026] [security2:error] [pid 751901:tid 752042] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKcCrT982lovRn7gnH0QAAAAs"]
[Thu Jul 30 12:31:29.000188 2026] [core:notice] [pid 751901:tid 751912] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:29.297210 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:29.303809 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:3078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcSrT982lovRn7gnICQAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:29.306323 2026] [security2:error] [pid 751901:tid 752102] [client 85.208.98.18:33752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuKcSrT982lovRn7gnIDAAAAEc"]
[Thu Jul 30 12:31:29.306397 2026] [security2:error] [pid 751901:tid 752102] [client 85.208.98.18:33752] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuKcSrT982lovRn7gnIDAAAAEc"]
[Thu Jul 30 12:31:29.600671 2026] [security2:error] [pid 751901:tid 752031] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKcSrT982lovRn7gnH9AAAAAA"]
[Thu Jul 30 12:31:29.604622 2026] [security2:error] [pid 751901:tid 752154] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKcSrT982lovRn7gnICwAAewc"]
[Thu Jul 30 12:31:29.801355 2026] [security2:error] [pid 751901:tid 751935] [remote 40.77.167.2:30073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/view/4847"] [unique_id "amuKcSrT982lovRn7gnIGgAASSE"]
[Thu Jul 30 12:31:29.888372 2026] [security2:error] [pid 751901:tid 752154] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKcSrT982lovRn7gnIEwAAexw"]
[Thu Jul 30 12:31:30.054513 2026] [core:notice] [pid 751901:tid 751934] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:30.070687 2026] [core:notice] [pid 751901:tid 752115] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:30.074872 2026] [security2:error] [pid 751901:tid 752115] [client 103.215.74.26:3094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "775"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcirT982lovRn7gnILAAAAFQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:30.110124 2026] [security2:error] [pid 751901:tid 752151] [client 62.34.17.16:50392] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuKcirT982lovRn7gnILgAAAHg"]
[Thu Jul 30 12:31:30.360029 2026] [security2:error] [pid 751901:tid 752094] [client 62.34.88.147:18334] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuKcirT982lovRn7gnINgAAAD8"]
[Thu Jul 30 12:31:30.417291 2026] [security2:error] [pid 751901:tid 752133] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKcSrT982lovRn7gnIIQAAAGY"]
[Thu Jul 30 12:31:30.432545 2026] [security2:error] [pid 751901:tid 752077] [client 119.73.97.132:29775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuKcirT982lovRn7gnIMQAALhA"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:31:30.800826 2026] [core:notice] [pid 751901:tid 752142] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:30.805517 2026] [security2:error] [pid 751901:tid 752142] [client 103.215.74.26:3106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcirT982lovRn7gnIQQAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:31.010915 2026] [security2:error] [pid 751901:tid 752129] [client 216.73.216.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.investigations.worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuKcirT982lovRn7gnISAAAYik"]
[Thu Jul 30 12:31:31.177750 2026] [security2:error] [pid 751901:tid 752124] [client 78.197.69.176:33932] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuKcyrT982lovRn7gnITAAAAF0"]
[Thu Jul 30 12:31:31.217060 2026] [security2:error] [pid 751901:tid 752075] [client 31.111.178.5:38782] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuKcyrT982lovRn7gnITgAAACw"]
[Thu Jul 30 12:31:31.541609 2026] [core:notice] [pid 751901:tid 752065] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:31.545562 2026] [security2:error] [pid 751901:tid 752065] [client 103.215.74.26:3114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKcyrT982lovRn7gnIWwAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:31.648414 2026] [security2:error] [pid 751901:tid 752115] [client 139.28.219.70:59822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuKcyrT982lovRn7gnIXAAAAFQ"]
[Thu Jul 30 12:31:31.833264 2026] [security2:error] [pid 751901:tid 752155] [client 85.86.58.213:51149] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuKcyrT982lovRn7gnIXQAAAHw"]
[Thu Jul 30 12:31:31.912814 2026] [security2:error] [pid 751901:tid 752153] [client 170.246.191.69:16883] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuKcyrT982lovRn7gnIYgAAAHo"]
[Thu Jul 30 12:31:32.065462 2026] [security2:error] [pid 751901:tid 752092] [client 95.27.206.97:2651] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuKdCrT982lovRn7gnIbgAAAD0"]
[Thu Jul 30 12:31:32.149363 2026] [security2:error] [pid 751901:tid 752112] [client 89.29.175.168:40730] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuKdCrT982lovRn7gnIbwAAAFE"]
[Thu Jul 30 12:31:32.205219 2026] [security2:error] [pid 751901:tid 752077] [client 139.28.219.70:59832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuKdCrT982lovRn7gnIcQAAAC4"]
[Thu Jul 30 12:31:32.298998 2026] [core:notice] [pid 751901:tid 752156] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:32.303208 2026] [security2:error] [pid 751901:tid 752156] [client 103.215.74.26:3124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKdCrT982lovRn7gnIcgAAAH0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:32.521030 2026] [security2:error] [pid 751901:tid 752032] [client 139.28.219.70:59848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuKdCrT982lovRn7gnIegAAAAE"]
[Thu Jul 30 12:31:32.554052 2026] [security2:error] [pid 751901:tid 752081] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKcyrT982lovRn7gnIZQAAMjA"]
[Thu Jul 30 12:31:32.854245 2026] [security2:error] [pid 751901:tid 752129] [client 139.28.219.70:59864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuKdCrT982lovRn7gnIfgAAAGI"]
[Thu Jul 30 12:31:32.951431 2026] [security2:error] [pid 751901:tid 752033] [client 20.215.191.139:7027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuKdCrT982lovRn7gnIgwAAAAI"]
[Thu Jul 30 12:31:33.127193 2026] [security2:error] [pid 751901:tid 752075] [client 139.28.219.70:59876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuKdSrT982lovRn7gnIhwAAACw"]
[Thu Jul 30 12:31:33.399699 2026] [security2:error] [pid 751901:tid 752135] [client 139.28.219.70:59884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuKdSrT982lovRn7gnIjwAAAGg"]
[Thu Jul 30 12:31:33.713916 2026] [security2:error] [pid 751901:tid 752157] [client 139.28.219.70:59890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuKdSrT982lovRn7gnImgAAAH4"]
[Thu Jul 30 12:31:33.989686 2026] [security2:error] [pid 751901:tid 752036] [client 139.28.219.70:59892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuKdSrT982lovRn7gnIoAAAAAU"]
[Thu Jul 30 12:31:34.060430 2026] [security2:error] [pid 751901:tid 752071] [client 69.51.242.122:59674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuKdirT982lovRn7gnIogAAACg"]
[Thu Jul 30 12:31:34.124344 2026] [security2:error] [pid 751901:tid 752057] [client 99.246.175.62:40882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuKdirT982lovRn7gnIpgAAABo"]
[Thu Jul 30 12:31:34.254905 2026] [security2:error] [pid 751901:tid 752098] [client 139.28.219.70:59896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuKdirT982lovRn7gnIqgAAAEM"]
[Thu Jul 30 12:31:34.525774 2026] [security2:error] [pid 751901:tid 752114] [client 139.28.219.70:59904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuKdirT982lovRn7gnIsAAAAFM"]
[Thu Jul 30 12:31:34.706170 2026] [security2:error] [pid 751901:tid 752038] [client 20.215.191.139:7174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuKdirT982lovRn7gnIuAAAAAc"]
[Thu Jul 30 12:31:34.793055 2026] [security2:error] [pid 751901:tid 752033] [client 139.28.219.70:59918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuKdirT982lovRn7gnIuQAAAAI"]
[Thu Jul 30 12:31:35.138003 2026] [security2:error] [pid 751901:tid 752131] [client 139.28.219.70:59922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuKdyrT982lovRn7gnIxgAAAGQ"]
[Thu Jul 30 12:31:35.407392 2026] [security2:error] [pid 751901:tid 752031] [client 139.28.219.70:59936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuKdyrT982lovRn7gnIzAAAAAA"]
[Thu Jul 30 12:31:35.680523 2026] [security2:error] [pid 751901:tid 752117] [client 139.28.219.70:59948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuKdyrT982lovRn7gnI0AAAAFY"]
[Thu Jul 30 12:31:35.839529 2026] [security2:error] [pid 751901:tid 752108] [client 20.215.191.139:10789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuKdyrT982lovRn7gnI2gAAAE0"]
[Thu Jul 30 12:31:35.946511 2026] [security2:error] [pid 751901:tid 752119] [client 139.28.219.70:59954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuKdyrT982lovRn7gnI2wAAAFg"]
[Thu Jul 30 12:31:35.988547 2026] [security2:error] [pid 751901:tid 751989] [remote 74.7.241.59:32932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuKdyrT982lovRn7gnI3AAAHlc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/actions
[Thu Jul 30 12:31:36.212920 2026] [security2:error] [pid 751901:tid 752126] [client 139.28.219.70:59970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuKeCrT982lovRn7gnI4wAAAF8"]
[Thu Jul 30 12:31:36.485480 2026] [security2:error] [pid 751901:tid 752033] [client 139.28.219.70:59974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nobleinternationals.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuKeCrT982lovRn7gnI5wAAAAI"]
[Thu Jul 30 12:31:36.706673 2026] [security2:error] [pid 751901:tid 752146] [client 20.215.191.139:42940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuKeCrT982lovRn7gnI6wAAAHM"]
[Thu Jul 30 12:31:37.332278 2026] [security2:error] [pid 751901:tid 752095] [client 20.215.191.139:13105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuKeSrT982lovRn7gnI_AAAAEA"]
[Thu Jul 30 12:31:38.030663 2026] [core:notice] [pid 751901:tid 752112] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:38.036079 2026] [security2:error] [pid 751901:tid 752112] [client 103.215.74.26:57650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKeirT982lovRn7gnJCwAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:38.248913 2026] [security2:error] [pid 751901:tid 752106] [client 38.190.144.4:34883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKeirT982lovRn7gnJDwAAAEs"]
[Thu Jul 30 12:31:38.249048 2026] [security2:error] [pid 751901:tid 752106] [client 38.190.144.4:34883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKeirT982lovRn7gnJDwAAAEs"]
[Thu Jul 30 12:31:38.281271 2026] [security2:error] [pid 751901:tid 752061] [client 91.92.41.115:56202] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "mail.azureskyfilms.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuKeirT982lovRn7gnJEQAAAB4"]
[Thu Jul 30 12:31:38.758161 2026] [core:notice] [pid 751901:tid 752034] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:38.762203 2026] [security2:error] [pid 751901:tid 752034] [client 103.215.74.26:57658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKeirT982lovRn7gnJGgAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:38.903702 2026] [security2:error] [pid 751901:tid 752136] [client 20.215.191.139:42939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuKeirT982lovRn7gnJIQAAAGk"]
[Thu Jul 30 12:31:39.497306 2026] [core:notice] [pid 751901:tid 752147] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:39.501327 2026] [security2:error] [pid 751901:tid 752147] [client 103.215.74.26:57666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKeyrT982lovRn7gnJLAAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:39.620602 2026] [security2:error] [pid 751901:tid 752004] [remote 69.57.172.212:54840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.172.57.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amuKeyrT982lovRn7gnJKAAAMWY"]
[Thu Jul 30 12:31:39.626431 2026] [core:notice] [pid 751901:tid 752065] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.017414 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.225864 2026] [core:notice] [pid 751901:tid 752088] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.230340 2026] [security2:error] [pid 751901:tid 752088] [client 103.215.74.26:57678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKfCrT982lovRn7gnJOQAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:40.251148 2026] [core:notice] [pid 751901:tid 752129] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.399892 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.656860 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.941879 2026] [core:notice] [pid 751901:tid 752094] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:40.946198 2026] [security2:error] [pid 751901:tid 752094] [client 103.215.74.26:57682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKfCrT982lovRn7gnJTwAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:41.529476 2026] [security2:error] [pid 751901:tid 752091] [client 20.215.191.139:42891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuKfSrT982lovRn7gnJXQAAADw"]
[Thu Jul 30 12:31:41.686458 2026] [core:notice] [pid 751901:tid 752084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:41.694694 2026] [security2:error] [pid 751901:tid 752084] [client 103.215.74.26:57694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKfSrT982lovRn7gnJXgAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:42.081367 2026] [security2:error] [pid 751901:tid 752082] [client 20.215.191.139:12159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuKfirT982lovRn7gnJbAAAADM"]
[Thu Jul 30 12:31:42.766529 2026] [security2:error] [pid 751901:tid 752054] [client 51.77.211.229:32932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.211.77.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuKfirT982lovRn7gnJeQAAABc"]
[Thu Jul 30 12:31:43.384857 2026] [security2:error] [pid 751901:tid 752062] [client 20.215.191.139:2839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuKfyrT982lovRn7gnJiAAAAB8"]
[Thu Jul 30 12:31:43.653122 2026] [security2:error] [pid 751901:tid 752117] [client 141.95.54.132:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.54.95.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuKfyrT982lovRn7gnJiQAAAFY"]
[Thu Jul 30 12:31:43.819093 2026] [security2:error] [pid 751901:tid 752061] [client 84.54.44.19:54554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.44.54.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/email-now.php"] [unique_id "amuKfyrT982lovRn7gnJlAAAAB4"], referer: http://arabiandubaisafari.com/contact.html
[Thu Jul 30 12:31:44.123599 2026] [security2:error] [pid 751901:tid 752144] [client 20.215.191.139:4022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/images/about.php"] [unique_id "amuKgCrT982lovRn7gnJnAAAAHE"]
[Thu Jul 30 12:31:44.756949 2026] [security2:error] [pid 751901:tid 752070] [client 20.215.191.139:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuKgCrT982lovRn7gnJqAAAACc"]
[Thu Jul 30 12:31:44.876173 2026] [security2:error] [pid 751901:tid 751928] [remote 74.7.241.60:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuKgCrT982lovRn7gnJqQAAGRo"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:31:45.115261 2026] [security2:error] [pid 751901:tid 752073] [client 151.80.133.238:58992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.133.80.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuKgSrT982lovRn7gnJsAAAACo"]
[Thu Jul 30 12:31:45.528757 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:45.786334 2026] [security2:error] [pid 751901:tid 752054] [client 50.16.216.166:10945] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "sellvia.womenclothingbox.com"] [uri "/"] [unique_id "amuKgSrT982lovRn7gnJxAAAABc"]
[Thu Jul 30 12:31:45.856085 2026] [security2:error] [pid 751901:tid 752080] [client 51.75.24.242:57768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.24.75.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuKgSrT982lovRn7gnJugAAADE"]
[Thu Jul 30 12:31:45.880205 2026] [security2:error] [pid 751901:tid 752050] [client 20.215.191.139:2851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuKgSrT982lovRn7gnJxQAAABM"]
[Thu Jul 30 12:31:46.242539 2026] [core:notice] [pid 751901:tid 752047] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:46.553458 2026] [security2:error] [pid 751901:tid 752158] [client 20.215.191.139:6352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/about.php"] [unique_id "amuKgirT982lovRn7gnJ1wAAAH8"]
[Thu Jul 30 12:31:47.307940 2026] [security2:error] [pid 751901:tid 752093] [client 20.215.191.139:6775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/cgi-bin/about.php"] [unique_id "amuKgyrT982lovRn7gnJ6QAAAD4"]
[Thu Jul 30 12:31:47.315151 2026] [security2:error] [pid 751901:tid 752108] [client 185.191.171.12:57502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/22/covid-brasil-registra-2-027-mortes-e-45-178-novos-casos-em-24-horas/"] [unique_id "amuKgyrT982lovRn7gnJ6gAAAE0"]
[Thu Jul 30 12:31:47.315289 2026] [security2:error] [pid 751901:tid 752108] [client 185.191.171.12:57502] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/22/covid-brasil-registra-2-027-mortes-e-45-178-novos-casos-em-24-horas/"] [unique_id "amuKgyrT982lovRn7gnJ6gAAAE0"]
[Thu Jul 30 12:31:47.418303 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:47.422721 2026] [security2:error] [pid 751901:tid 752139] [client 103.215.74.26:57550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKgyrT982lovRn7gnJ7gAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:47.680600 2026] [security2:error] [pid 751901:tid 752032] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKgyrT982lovRn7gnJ4gAAATQ"]
[Thu Jul 30 12:31:48.131637 2026] [core:notice] [pid 751901:tid 752095] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:48.136357 2026] [security2:error] [pid 751901:tid 752095] [client 103.215.74.26:57564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhCrT982lovRn7gnJ_gAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:48.435169 2026] [security2:error] [pid 751901:tid 752074] [client 20.215.191.139:11624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuKhCrT982lovRn7gnKCAAAACs"]
[Thu Jul 30 12:31:48.886618 2026] [core:notice] [pid 751901:tid 752062] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:48.890801 2026] [security2:error] [pid 751901:tid 752062] [client 103.215.74.26:57588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhCrT982lovRn7gnKEQAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:48.995837 2026] [security2:error] [pid 751901:tid 752068] [client 149.202.51.38:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.51.202.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/login.php"] [unique_id "amuKhCrT982lovRn7gnKDQAAACU"]
[Thu Jul 30 12:31:49.578352 2026] [security2:error] [pid 751901:tid 752117] [client 20.215.191.139:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuKhSrT982lovRn7gnKJQAAAFY"]
[Thu Jul 30 12:31:49.626780 2026] [core:notice] [pid 751901:tid 752052] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:49.631203 2026] [security2:error] [pid 751901:tid 752052] [client 103.215.74.26:57616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhSrT982lovRn7gnKJgAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:49.741633 2026] [security2:error] [pid 751901:tid 752119] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKhSrT982lovRn7gnKFwAAAFg"]
[Thu Jul 30 12:31:49.954089 2026] [security2:error] [pid 751901:tid 752155] [client 38.190.144.4:50548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKhSrT982lovRn7gnKLQAAAHw"]
[Thu Jul 30 12:31:49.954205 2026] [security2:error] [pid 751901:tid 752155] [client 38.190.144.4:50548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKhSrT982lovRn7gnKLQAAAHw"]
[Thu Jul 30 12:31:50.159272 2026] [security2:error] [pid 751901:tid 752101] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKhSrT982lovRn7gnKJAAARjI"]
[Thu Jul 30 12:31:50.376416 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:50.384813 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:57648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhirT982lovRn7gnKNgAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:50.940381 2026] [security2:error] [pid 751901:tid 752055] [client 185.191.171.12:53350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2023/01/02/lula-assume-com-o-apoio-de-11-governadores-e-oposicao-de-14/"] [unique_id "amuKhirT982lovRn7gnKRgAAABg"]
[Thu Jul 30 12:31:50.940556 2026] [security2:error] [pid 751901:tid 752055] [client 185.191.171.12:53350] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2023/01/02/lula-assume-com-o-apoio-de-11-governadores-e-oposicao-de-14/"] [unique_id "amuKhirT982lovRn7gnKRgAAABg"]
[Thu Jul 30 12:31:51.004284 2026] [security2:error] [pid 751901:tid 751940] [remote 57.141.0.61:25428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/610298834/feed/rss2/"] [unique_id "amuKhyrT982lovRn7gnKRwAAYCY"]
[Thu Jul 30 12:31:51.131703 2026] [core:notice] [pid 751901:tid 752077] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:51.136120 2026] [security2:error] [pid 751901:tid 752077] [client 103.215.74.26:57672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhyrT982lovRn7gnKSAAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:51.865877 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:51.870989 2026] [security2:error] [pid 751901:tid 752106] [client 103.215.74.26:57678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKhyrT982lovRn7gnKVQAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:52.579802 2026] [core:notice] [pid 751901:tid 752052] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:52.583775 2026] [security2:error] [pid 751901:tid 752052] [client 103.215.74.26:57690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKiCrT982lovRn7gnKYwAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:52.920457 2026] [security2:error] [pid 751901:tid 752070] [client 20.215.191.139:4770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuKiCrT982lovRn7gnKZAAAACc"]
[Thu Jul 30 12:31:53.319926 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:53.326435 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:38278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKiSrT982lovRn7gnKcQAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:53.745352 2026] [core:error] [pid 751901:tid 752080] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:31:53.745375 2026] [core:error] [pid 751901:tid 752080] [client 158.173.25.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://appliancerepairservice.one/
[Thu Jul 30 12:31:53.841453 2026] [core:notice] [pid 751901:tid 752050] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:53.927298 2026] [security2:error] [pid 751901:tid 752095] [client 20.215.191.139:3265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuKiSrT982lovRn7gnKfQAAAEA"]
[Thu Jul 30 12:31:54.065337 2026] [core:notice] [pid 751901:tid 752151] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:54.070562 2026] [security2:error] [pid 751901:tid 752151] [client 103.215.74.26:38314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKiirT982lovRn7gnKhAAAAHg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:54.630413 2026] [security2:error] [pid 751901:tid 751994] [remote 57.141.0.49:32368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuKiirT982lovRn7gnKlAAAVlw"]
[Thu Jul 30 12:31:54.745632 2026] [security2:error] [pid 751901:tid 751942] [remote 8.217.108.67:62888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuKiirT982lovRn7gnKlQAAFCg"]
[Thu Jul 30 12:31:54.795673 2026] [core:notice] [pid 751901:tid 752089] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:31:54.803257 2026] [security2:error] [pid 751901:tid 752089] [client 103.215.74.26:38346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKiirT982lovRn7gnKlgAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:31:56.447737 2026] [security2:error] [pid 751901:tid 752060] [client 20.215.191.139:4328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuKjCrT982lovRn7gnKvAAAAB0"]
[Thu Jul 30 12:31:57.446926 2026] [security2:error] [pid 751901:tid 752064] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKjCrT982lovRn7gnK1AAAACE"]
[Thu Jul 30 12:31:57.864060 2026] [security2:error] [pid 751901:tid 752072] [client 20.215.191.139:4739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuKjSrT982lovRn7gnK6gAAACk"]
[Thu Jul 30 12:31:59.577480 2026] [security2:error] [pid 751901:tid 752061] [client 172.237.109.114:34523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjirT982lovRn7gnK_wAAAB4"]
[Thu Jul 30 12:31:59.579494 2026] [security2:error] [pid 751901:tid 752156] [client 172.237.109.114:50976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjirT982lovRn7gnK_gAAAH0"]
[Thu Jul 30 12:31:59.660608 2026] [security2:error] [pid 751901:tid 752118] [client 20.215.191.139:2551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuKjyrT982lovRn7gnLDgAAAFc"]
[Thu Jul 30 12:32:00.408654 2026] [security2:error] [pid 751901:tid 752076] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLBQAALXw"]
[Thu Jul 30 12:32:00.534740 2026] [core:notice] [pid 751901:tid 752065] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:00.543086 2026] [security2:error] [pid 751901:tid 752065] [client 103.215.74.26:38364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKkCrT982lovRn7gnLKgAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:00.547187 2026] [security2:error] [pid 751901:tid 752047] [client 172.237.109.114:4640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLGAAAABA"]
[Thu Jul 30 12:32:00.548044 2026] [security2:error] [pid 751901:tid 752086] [client 172.237.109.114:5397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLFwAAADc"]
[Thu Jul 30 12:32:00.557942 2026] [security2:error] [pid 751901:tid 752093] [client 172.237.109.114:32149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLGwAAAD4"]
[Thu Jul 30 12:32:00.580254 2026] [security2:error] [pid 751901:tid 752145] [client 172.237.109.114:48753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLGQAAAHI"]
[Thu Jul 30 12:32:00.651013 2026] [security2:error] [pid 751901:tid 752155] [client 172.237.109.114:55284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKjyrT982lovRn7gnLHgAAAHw"]
[Thu Jul 30 12:32:00.662871 2026] [security2:error] [pid 751901:tid 752154] [client 172.237.109.114:41622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkCrT982lovRn7gnLIQAAAHs"]
[Thu Jul 30 12:32:00.664390 2026] [security2:error] [pid 751901:tid 752067] [client 172.237.109.114:40387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkCrT982lovRn7gnLHwAAACQ"]
[Thu Jul 30 12:32:00.682009 2026] [security2:error] [pid 751901:tid 752038] [client 172.237.109.114:17730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkCrT982lovRn7gnLIAAAAAc"]
[Thu Jul 30 12:32:00.990429 2026] [security2:error] [pid 751901:tid 752045] [client 20.215.191.139:3288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/cloud.php"] [unique_id "amuKkCrT982lovRn7gnLNwAAAA4"]
[Thu Jul 30 12:32:01.285100 2026] [core:notice] [pid 751901:tid 752062] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:01.295514 2026] [security2:error] [pid 751901:tid 752062] [client 103.215.74.26:38376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKkSrT982lovRn7gnLTwAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:01.933835 2026] [security2:error] [pid 751901:tid 752098] [client 20.215.191.139:13379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuKkSrT982lovRn7gnLWgAAAEM"]
[Thu Jul 30 12:32:02.126248 2026] [core:error] [pid 751901:tid 752103] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.126270 2026] [core:error] [pid 751901:tid 752103] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.152387 2026] [core:error] [pid 751901:tid 752093] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.152406 2026] [core:error] [pid 751901:tid 752093] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.179461 2026] [core:error] [pid 751901:tid 752153] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.179487 2026] [core:error] [pid 751901:tid 752153] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:02.401372 2026] [security2:error] [pid 751901:tid 752074] [client 172.237.109.114:10633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLPQAAACs"]
[Thu Jul 30 12:32:02.401502 2026] [security2:error] [pid 751901:tid 752111] [client 172.237.109.114:4743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLQgAAAFA"]
[Thu Jul 30 12:32:02.443710 2026] [security2:error] [pid 751901:tid 752151] [client 172.237.109.114:64980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLPgAAAHg"]
[Thu Jul 30 12:32:02.490889 2026] [security2:error] [pid 751901:tid 752077] [client 172.237.109.114:33682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLQAAAAC4"]
[Thu Jul 30 12:32:02.510010 2026] [security2:error] [pid 751901:tid 752121] [client 172.237.109.114:22972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLPAAAAFo"]
[Thu Jul 30 12:32:02.533808 2026] [security2:error] [pid 751901:tid 752083] [client 172.237.109.114:1682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLQQAAADQ"]
[Thu Jul 30 12:32:02.546677 2026] [security2:error] [pid 751901:tid 752031] [client 172.237.109.114:3414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLQwAAAAA"]
[Thu Jul 30 12:32:02.572522 2026] [security2:error] [pid 751901:tid 752058] [client 172.237.109.114:35357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLSAAAABs"]
[Thu Jul 30 12:32:02.589391 2026] [security2:error] [pid 751901:tid 752055] [client 172.237.109.114:47522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLOwAAABg"]
[Thu Jul 30 12:32:02.719937 2026] [security2:error] [pid 751901:tid 752140] [client 20.215.191.139:6912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/updates.php"] [unique_id "amuKkirT982lovRn7gnLewAAAG0"]
[Thu Jul 30 12:32:03.024344 2026] [security2:error] [pid 751901:tid 752087] [client 38.190.144.4:51051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKkyrT982lovRn7gnLfgAAADg"]
[Thu Jul 30 12:32:03.024474 2026] [security2:error] [pid 751901:tid 752087] [client 38.190.144.4:51051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKkyrT982lovRn7gnLfgAAADg"]
[Thu Jul 30 12:32:03.216665 2026] [security2:error] [pid 751901:tid 752144] [client 172.237.109.114:2186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLSQAAAHE"]
[Thu Jul 30 12:32:03.218054 2026] [security2:error] [pid 751901:tid 752068] [client 172.237.109.114:23207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLRgAAACU"]
[Thu Jul 30 12:32:03.231342 2026] [security2:error] [pid 751901:tid 752130] [client 172.237.109.114:15582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLRQAAAGM"]
[Thu Jul 30 12:32:03.234592 2026] [security2:error] [pid 751901:tid 752060] [client 172.237.109.114:9835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLPwAAAB0"]
[Thu Jul 30 12:32:03.256882 2026] [security2:error] [pid 751901:tid 752059] [client 172.237.109.114:53673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLSwAAABw"]
[Thu Jul 30 12:32:03.268364 2026] [security2:error] [pid 751901:tid 752137] [client 172.237.109.114:13190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLTQAAAGo"]
[Thu Jul 30 12:32:03.269698 2026] [security2:error] [pid 751901:tid 752113] [client 172.237.109.114:65312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLTgAAAFI"]
[Thu Jul 30 12:32:03.271827 2026] [security2:error] [pid 751901:tid 752071] [client 172.237.109.114:50525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLRwAAACg"]
[Thu Jul 30 12:32:03.287238 2026] [security2:error] [pid 751901:tid 752158] [client 172.237.109.114:64426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLSgAAAH8"]
[Thu Jul 30 12:32:03.287931 2026] [security2:error] [pid 751901:tid 752112] [client 172.237.109.114:51700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLRAAAAFE"]
[Thu Jul 30 12:32:03.320049 2026] [security2:error] [pid 751901:tid 752134] [client 172.237.109.114:61440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKkSrT982lovRn7gnLTAAAAGc"]
[Thu Jul 30 12:32:03.968005 2026] [security2:error] [pid 751901:tid 752105] [client 20.215.191.139:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/css/cloud.php"] [unique_id "amuKkyrT982lovRn7gnLlgAAAEo"]
[Thu Jul 30 12:32:04.089404 2026] [security2:error] [pid 751901:tid 751953] [remote 57.141.0.26:57170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuKlCrT982lovRn7gnLmgAALzM"]
[Thu Jul 30 12:32:05.518341 2026] [security2:error] [pid 751901:tid 752097] [client 74.7.244.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-2f97271e.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuKlSrT982lovRn7gnLuQAAAEI"]
[Thu Jul 30 12:32:05.519194 2026] [security2:error] [pid 751901:tid 752087] [client 74.7.244.45:48134] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-2f97271e.ear.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuKlSrT982lovRn7gnLtwAAOD4"]
[Thu Jul 30 12:32:06.972146 2026] [security2:error] [pid 751901:tid 752095] [client 20.215.191.139:3545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuKlirT982lovRn7gnL5QAAAEA"]
[Thu Jul 30 12:32:07.083845 2026] [core:notice] [pid 751901:tid 752118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:07.090745 2026] [security2:error] [pid 751901:tid 752118] [client 103.215.74.26:34184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKlyrT982lovRn7gnL5gAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:07.197103 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:07.841241 2026] [core:notice] [pid 751901:tid 752037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:07.847453 2026] [security2:error] [pid 751901:tid 752037] [client 103.215.74.26:34186] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKlyrT982lovRn7gnMCAAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:08.574531 2026] [core:notice] [pid 751901:tid 752138] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:08.578635 2026] [security2:error] [pid 751901:tid 752138] [client 103.215.74.26:34198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "775"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKmCrT982lovRn7gnMGQAAAGs"], referer: https://carnetdeshopping.com/
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:32:09.311905 2026] [core:notice] [pid 751901:tid 752144] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:09.315793 2026] [security2:error] [pid 751901:tid 752144] [client 103.215.74.26:34204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKmSrT982lovRn7gnMPAAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:10.068053 2026] [core:notice] [pid 751901:tid 752074] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:10.071897 2026] [security2:error] [pid 751901:tid 752074] [client 103.215.74.26:34212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKmirT982lovRn7gnMXgAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:10.441420 2026] [security2:error] [pid 751901:tid 752017] [remote 97.74.87.194:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-login.php"] [unique_id "amuKmirT982lovRn7gnMYQAAeHM"]
[Thu Jul 30 12:32:10.479455 2026] [security2:error] [pid 751901:tid 752125] [client 20.215.191.139:2521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/img/cloud.php"] [unique_id "amuKmirT982lovRn7gnMZwAAAF4"]
[Thu Jul 30 12:32:10.786673 2026] [core:notice] [pid 751901:tid 752045] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:10.790725 2026] [security2:error] [pid 751901:tid 752045] [client 103.215.74.26:34224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKmirT982lovRn7gnMcQAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:11.670452 2026] [security2:error] [pid 751901:tid 752150] [client 20.215.191.139:2542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuKmyrT982lovRn7gnMlwAAAHc"]
[Thu Jul 30 12:32:12.137116 2026] [security2:error] [pid 751901:tid 752033] [client 34.143.178.95:57810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dhowcruisedinner.com"] [uri "/"] [unique_id "amuKnCrT982lovRn7gnMqQAAAAI"]
[Thu Jul 30 12:32:13.559557 2026] [security2:error] [pid 751901:tid 752146] [client 20.215.191.139:14650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuKnSrT982lovRn7gnMwAAAAHM"]
[Thu Jul 30 12:32:14.772635 2026] [security2:error] [pid 751901:tid 752150] [client 20.215.191.139:13393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/avaa.php"] [unique_id "amuKnirT982lovRn7gnM5AAAAHc"]
[Thu Jul 30 12:32:15.863957 2026] [security2:error] [pid 751901:tid 752072] [client 20.215.191.139:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/images/cloud.php"] [unique_id "amuKnyrT982lovRn7gnM-AAAACk"]
[Thu Jul 30 12:32:15.943110 2026] [security2:error] [pid 751901:tid 752046] [client 109.172.91.206:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.91.172.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuKnyrT982lovRn7gnM_AAAAA8"], referer: https://supreme-hydraulics.com/contact/
[Thu Jul 30 12:32:16.517643 2026] [core:notice] [pid 751901:tid 752036] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:16.522211 2026] [security2:error] [pid 751901:tid 752036] [client 103.215.74.26:21624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoCrT982lovRn7gnNKgAAAAU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:17.167434 2026] [security2:error] [pid 751901:tid 752091] [client 94.154.43.179:37516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "online-hope.com"] [uri "/.env"] [unique_id "amuKoSrT982lovRn7gnNOgAAADw"]
[Thu Jul 30 12:32:17.234715 2026] [core:notice] [pid 751901:tid 752142] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:17.238773 2026] [security2:error] [pid 751901:tid 752142] [client 103.215.74.26:21626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoSrT982lovRn7gnNPAAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:17.597413 2026] [core:notice] [pid 751901:tid 752013] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:17.751309 2026] [core:notice] [pid 751901:tid 752016] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:17.870817 2026] [security2:error] [pid 751901:tid 752034] [client 20.215.191.139:8035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuKoSrT982lovRn7gnNUwAAAAM"]
[Thu Jul 30 12:32:17.982909 2026] [core:notice] [pid 751901:tid 752140] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:17.987035 2026] [security2:error] [pid 751901:tid 752140] [client 103.215.74.26:21656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoSrT982lovRn7gnNWgAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:18.206377 2026] [proxy:error] [pid 751901:tid 752087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:18.206463 2026] [proxy_http:error] [pid 751901:tid 752087] [client 143.244.57.82:52426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:18.207035 2026] [proxy:error] [pid 751901:tid 752087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:18.207079 2026] [proxy_http:error] [pid 751901:tid 752087] [client 143.244.57.82:52426] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:18.493650 2026] [proxy:error] [pid 751901:tid 752148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:18.493729 2026] [proxy_http:error] [pid 751901:tid 752148] [client 143.244.57.82:52442] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:18.494316 2026] [proxy:error] [pid 751901:tid 752148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:18.494360 2026] [proxy_http:error] [pid 751901:tid 752148] [client 143.244.57.82:52442] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:18.548777 2026] [security2:error] [pid 751901:tid 752101] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKoSrT982lovRn7gnNVgAAAEY"]
[Thu Jul 30 12:32:18.729965 2026] [core:notice] [pid 751901:tid 752077] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:18.737600 2026] [security2:error] [pid 751901:tid 752077] [client 103.215.74.26:21662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoirT982lovRn7gnNbgAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:18.777800 2026] [security2:error] [pid 751901:tid 752128] [client 143.244.57.82:52450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuKoirT982lovRn7gnNbwAAAGE"]
[Thu Jul 30 12:32:19.051367 2026] [security2:error] [pid 751901:tid 752001] [remote 172.93.219.170:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.219.93.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amuKoyrT982lovRn7gnNeAAAWWM"]
[Thu Jul 30 12:32:19.070854 2026] [security2:error] [pid 751901:tid 752094] [client 143.244.57.82:52452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuKoyrT982lovRn7gnNewAAAD8"]
[Thu Jul 30 12:32:19.357154 2026] [proxy:error] [pid 751901:tid 752045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:19.357245 2026] [proxy_http:error] [pid 751901:tid 752045] [client 143.244.57.82:52468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:19.357824 2026] [proxy:error] [pid 751901:tid 752045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:19.357866 2026] [proxy_http:error] [pid 751901:tid 752045] [client 143.244.57.82:52468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:19.450018 2026] [core:notice] [pid 751901:tid 752041] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:19.457399 2026] [security2:error] [pid 751901:tid 752041] [client 103.215.74.26:21674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKoyrT982lovRn7gnNigAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:19.560468 2026] [security2:error] [pid 751901:tid 752115] [client 104.254.90.251:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuKoyrT982lovRn7gnNjwAAAFQ"]
[Thu Jul 30 12:32:19.560569 2026] [security2:error] [pid 751901:tid 752115] [client 104.254.90.251:56348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuKoyrT982lovRn7gnNjwAAAFQ"]
[Thu Jul 30 12:32:19.645400 2026] [security2:error] [pid 751901:tid 752153] [client 143.244.57.82:52482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuKoyrT982lovRn7gnNlAAAAHo"]
[Thu Jul 30 12:32:19.666989 2026] [security2:error] [pid 751901:tid 752034] [client 74.7.175.165:54172] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.ampere.us.cc"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuKoyrT982lovRn7gnNlQAAAAM"]
[Thu Jul 30 12:32:19.883062 2026] [security2:error] [pid 751901:tid 752152] [client 20.215.191.139:33541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuKoyrT982lovRn7gnNmQAAAHk"]
[Thu Jul 30 12:32:19.935523 2026] [security2:error] [pid 751901:tid 752093] [client 143.244.57.82:52488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuKoyrT982lovRn7gnNmwAAAD4"]
[Thu Jul 30 12:32:20.180024 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:20.187507 2026] [security2:error] [pid 751901:tid 752143] [client 103.215.74.26:21684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpCrT982lovRn7gnNpAAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:20.217210 2026] [security2:error] [pid 751901:tid 752148] [client 143.244.57.82:52498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuKpCrT982lovRn7gnNpQAAAHU"]
[Thu Jul 30 12:32:20.498191 2026] [security2:error] [pid 751901:tid 752128] [client 143.244.57.82:52512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuKpCrT982lovRn7gnNrQAAAGE"]
[Thu Jul 30 12:32:20.774112 2026] [security2:error] [pid 751901:tid 752119] [client 143.244.57.82:52516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuKpCrT982lovRn7gnNswAAAFg"]
[Thu Jul 30 12:32:20.784987 2026] [security2:error] [pid 751901:tid 752050] [client 20.215.191.139:13553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuKpCrT982lovRn7gnNtAAAABM"]
[Thu Jul 30 12:32:20.940538 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:20.947473 2026] [security2:error] [pid 751901:tid 752157] [client 103.215.74.26:21688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpCrT982lovRn7gnNugAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:21.058038 2026] [security2:error] [pid 751901:tid 752060] [client 143.244.57.82:52522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuKpSrT982lovRn7gnNvwAAAB0"]
[Thu Jul 30 12:32:21.340701 2026] [security2:error] [pid 751901:tid 752039] [client 143.244.57.82:52534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuKpSrT982lovRn7gnNxQAAAAg"]
[Thu Jul 30 12:32:21.597236 2026] [security2:error] [pid 751901:tid 752113] [client 179.43.134.114:16478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKpSrT982lovRn7gnNxAAAAFI"]
[Thu Jul 30 12:32:21.616245 2026] [security2:error] [pid 751901:tid 752047] [client 143.244.57.82:52542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuKpSrT982lovRn7gnNzAAAABA"]
[Thu Jul 30 12:32:21.710161 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:21.714500 2026] [security2:error] [pid 751901:tid 752122] [client 103.215.74.26:21704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpSrT982lovRn7gnN0AAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:21.895725 2026] [security2:error] [pid 751901:tid 752044] [client 143.244.57.82:52550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuKpSrT982lovRn7gnN0QAAAA0"]
[Thu Jul 30 12:32:22.108823 2026] [security2:error] [pid 751901:tid 752058] [client 20.215.191.139:9007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuKpirT982lovRn7gnN2QAAABs"]
[Thu Jul 30 12:32:22.165801 2026] [security2:error] [pid 751901:tid 751914] [remote 216.73.216.152:41909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuKpirT982lovRn7gnN3wAAbAw"]
[Thu Jul 30 12:32:22.181481 2026] [security2:error] [pid 751901:tid 752101] [client 143.244.57.82:52552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuKpirT982lovRn7gnN4gAAAEY"]
[Thu Jul 30 12:32:22.449951 2026] [core:notice] [pid 751901:tid 752083] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:22.454421 2026] [security2:error] [pid 751901:tid 752083] [client 103.215.74.26:21710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpirT982lovRn7gnN5wAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:22.455949 2026] [security2:error] [pid 751901:tid 752067] [client 143.244.57.82:52554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuKpirT982lovRn7gnN6gAAACQ"]
[Thu Jul 30 12:32:22.644886 2026] [security2:error] [pid 751901:tid 752125] [client 179.43.134.114:16480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKpirT982lovRn7gnN8AAAAF4"], referer: https://saifalkhaleejest.com/wp-admin/
[Thu Jul 30 12:32:22.743521 2026] [security2:error] [pid 751901:tid 752069] [client 143.244.57.82:52570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuKpirT982lovRn7gnN9AAAACY"]
[Thu Jul 30 12:32:22.804642 2026] [security2:error] [pid 751901:tid 752050] [client 20.215.191.139:42611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuKpirT982lovRn7gnN9QAAABM"]
[Thu Jul 30 12:32:23.031523 2026] [security2:error] [pid 751901:tid 752136] [client 143.244.57.82:52580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nuk.gzj.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuKpyrT982lovRn7gnN-wAAAGk"]
[Thu Jul 30 12:32:23.032840 2026] [security2:error] [pid 751901:tid 751931] [remote 57.141.0.70:36632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuKpyrT982lovRn7gnN-gAAHB0"]
[Thu Jul 30 12:32:23.059124 2026] [security2:error] [pid 751901:tid 752070] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKpirT982lovRn7gnN6wAAJyU"]
[Thu Jul 30 12:32:23.195997 2026] [core:notice] [pid 751901:tid 752094] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:23.200366 2026] [security2:error] [pid 751901:tid 752094] [client 103.215.74.26:28232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpyrT982lovRn7gnN_wAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:23.616167 2026] [security2:error] [pid 751901:tid 752037] [client 200.80.186.239:26718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKoyrT982lovRn7gnNiwAAAAY"], referer: http://pkf.jo
[Thu Jul 30 12:32:23.865668 2026] [security2:error] [pid 751901:tid 752100] [client 24.115.81.177:35867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKoirT982lovRn7gnNbQAAAEU"], referer: http://pkf.jo
[Thu Jul 30 12:32:23.887763 2026] [security2:error] [pid 751901:tid 752127] [client 138.219.238.58:28941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKoyrT982lovRn7gnNggAAAGA"], referer: http://pkf.jo
[Thu Jul 30 12:32:23.933073 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:23.937680 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:28248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKpyrT982lovRn7gnOEgAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:24.383244 2026] [security2:error] [pid 751901:tid 752057] [client 152.59.57.196:56264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKpyrT982lovRn7gnOBwAAABo"], referer: http://pkf.jo
[Thu Jul 30 12:32:24.614738 2026] [core:notice] [pid 751901:tid 752138] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:24.667214 2026] [core:notice] [pid 751901:tid 752150] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:24.672287 2026] [security2:error] [pid 751901:tid 752150] [client 103.215.74.26:28260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKqCrT982lovRn7gnOKQAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:24.712598 2026] [security2:error] [pid 751901:tid 752067] [client 118.194.233.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fnm.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuKqCrT982lovRn7gnOHgAAACQ"]
[Thu Jul 30 12:32:24.900770 2026] [security2:error] [pid 751901:tid 752131] [client 20.215.191.139:48281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuKqCrT982lovRn7gnOPQAAAGQ"]
[Thu Jul 30 12:32:25.273850 2026] [security2:error] [pid 751901:tid 752081] [client 216.73.217.138:63115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.upns.ca"] [uri "/index.php"] [unique_id "amuKqSrT982lovRn7gnOUAAAMlM"]
[Thu Jul 30 12:32:25.402241 2026] [core:notice] [pid 751901:tid 752073] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:25.406107 2026] [security2:error] [pid 751901:tid 752073] [client 103.215.74.26:28266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKqSrT982lovRn7gnOVgAAACo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:25.413203 2026] [security2:error] [pid 751901:tid 752069] [client 38.190.144.4:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKqSrT982lovRn7gnOVwAAACY"]
[Thu Jul 30 12:32:25.413301 2026] [security2:error] [pid 751901:tid 752069] [client 38.190.144.4:52060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKqSrT982lovRn7gnOVwAAACY"]
[Thu Jul 30 12:32:25.542937 2026] [security2:error] [pid 751901:tid 752110] [client 20.215.191.139:2562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/updates.php"] [unique_id "amuKqSrT982lovRn7gnOWAAAAE8"]
[Thu Jul 30 12:32:26.164012 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:26.168040 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:28280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKqirT982lovRn7gnOagAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:26.493141 2026] [security2:error] [pid 751901:tid 752079] [client 20.215.191.139:3542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuKqirT982lovRn7gnOdQAAADA"]
[Thu Jul 30 12:32:26.920263 2026] [core:notice] [pid 751901:tid 752128] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:26.925290 2026] [security2:error] [pid 751901:tid 752128] [client 103.215.74.26:28292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKqirT982lovRn7gnOhgAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:27.027357 2026] [security2:error] [pid 751901:tid 752097] [client 216.73.217.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.embassyofbelgiumislamabad.cc"] [uri "/index.php"] [unique_id "amuKqSrT982lovRn7gnOXAAAQkQ"]
[Thu Jul 30 12:32:29.020529 2026] [security2:error] [pid 751901:tid 752058] [client 20.215.191.139:11019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuKrSrT982lovRn7gnOtwAAABs"]
[Thu Jul 30 12:32:29.124562 2026] [autoindex:error] [pid 751901:tid 751908] [remote 45.33.110.19:53876] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:32:31.145219 2026] [security2:error] [pid 751901:tid 752086] [client 20.215.191.139:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuKryrT982lovRn7gnO9QAAADc"]
[Thu Jul 30 12:32:31.866338 2026] [security2:error] [pid 751901:tid 752126] [client 127.0.0.1:10468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuKryrT982lovRn7gnPBAAAAF8"]
[Thu Jul 30 12:32:31.866363 2026] [security2:error] [pid 751901:tid 752054] [client 127.0.0.1:10458] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.lucky-strike-shop.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuKryrT982lovRn7gnPAwAAABc"]
[Thu Jul 30 12:32:31.866448 2026] [security2:error] [pid 751901:tid 752105] [client 74.7.244.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.lucky-strike-shop.com"] [uri "/robots.txt"] [unique_id "amuKryrT982lovRn7gnPAgAASiU"]
[Thu Jul 30 12:32:32.625965 2026] [security2:error] [pid 751901:tid 752128] [client 104.28.155.129:63883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKsCrT982lovRn7gnPFwAAAGE"], referer: http://pkf.jo
[Thu Jul 30 12:32:32.660153 2026] [core:notice] [pid 751901:tid 752059] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:32.667407 2026] [security2:error] [pid 751901:tid 752059] [client 103.215.74.26:28300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsCrT982lovRn7gnPIgAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:32.887663 2026] [security2:error] [pid 751901:tid 752120] [client 20.52.54.143:1606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.alshateealazraqtours.com"] [uri "/wp-login.php"] [unique_id "amuKsCrT982lovRn7gnPIQAAAFk"]
[Thu Jul 30 12:32:32.887809 2026] [security2:error] [pid 751901:tid 752120] [client 20.52.54.143:1606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.alshateealazraqtours.com"] [uri "/wp-login.php"] [unique_id "amuKsCrT982lovRn7gnPIQAAAFk"]
[Thu Jul 30 12:32:33.131089 2026] [security2:error] [pid 751901:tid 752074] [client 40.77.167.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nafmedical.com"] [uri "/index.php"] [unique_id "amuKsCrT982lovRn7gnPJgAAKxQ"]
[Thu Jul 30 12:32:33.328226 2026] [core:error] [pid 751901:tid 752069] [client 66.249.68.33:40617] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:33.328250 2026] [core:error] [pid 751901:tid 752069] [client 66.249.68.33:40617] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:32:33.413880 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:33.420298 2026] [security2:error] [pid 751901:tid 752122] [client 103.215.74.26:18042] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsSrT982lovRn7gnPMwAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:33.555280 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:33.647374 2026] [core:notice] [pid 751901:tid 752158] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:33.916538 2026] [security2:error] [pid 751901:tid 752087] [client 20.215.191.139:11354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/alfa-rex.php7"] [unique_id "amuKsSrT982lovRn7gnPTQAAADg"]
[Thu Jul 30 12:32:34.053095 2026] [core:notice] [pid 751901:tid 752056] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:34.187821 2026] [core:notice] [pid 751901:tid 752091] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:34.197528 2026] [security2:error] [pid 751901:tid 752091] [client 103.215.74.26:18052] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsirT982lovRn7gnPWAAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:34.507994 2026] [security2:error] [pid 751901:tid 752062] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKsSrT982lovRn7gnPTAAAAB8"]
[Thu Jul 30 12:32:34.917203 2026] [core:notice] [pid 751901:tid 752039] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:34.921228 2026] [security2:error] [pid 751901:tid 752039] [client 103.215.74.26:18064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsirT982lovRn7gnPagAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:34.966299 2026] [security2:error] [pid 751901:tid 752046] [client 20.215.191.139:42573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/alfanew.php"] [unique_id "amuKsirT982lovRn7gnPawAAAA8"]
[Thu Jul 30 12:32:35.508183 2026] [security2:error] [pid 751901:tid 752143] [client 62.102.148.166:36886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuKsyrT982lovRn7gnPfAAAAHA"]
[Thu Jul 30 12:32:35.508317 2026] [security2:error] [pid 751901:tid 752143] [client 62.102.148.166:36886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuKsyrT982lovRn7gnPfAAAAHA"]
[Thu Jul 30 12:32:35.654282 2026] [core:notice] [pid 751901:tid 752058] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:35.658324 2026] [security2:error] [pid 751901:tid 752058] [client 103.215.74.26:18068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKsyrT982lovRn7gnPgwAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:35.797018 2026] [security2:error] [pid 751901:tid 752048] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKsyrT982lovRn7gnPdQAAABE"]
[Thu Jul 30 12:32:36.159171 2026] [security2:error] [pid 751901:tid 752102] [client 20.215.191.139:61200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuKtCrT982lovRn7gnPkAAAAEc"]
[Thu Jul 30 12:32:36.396206 2026] [core:notice] [pid 751901:tid 752112] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:36.404326 2026] [security2:error] [pid 751901:tid 752112] [client 103.215.74.26:18074] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtCrT982lovRn7gnPlAAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:37.134910 2026] [core:notice] [pid 751901:tid 752043] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:37.138791 2026] [security2:error] [pid 751901:tid 752043] [client 103.215.74.26:18076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "774"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtSrT982lovRn7gnPpgAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:37.476865 2026] [core:notice] [pid 751901:tid 752011] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:37.554522 2026] [security2:error] [pid 751901:tid 752156] [client 20.215.191.139:8058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuKtSrT982lovRn7gnPrwAAAH0"]
[Thu Jul 30 12:32:37.722683 2026] [core:notice] [pid 751901:tid 752013] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:37.839590 2026] [security2:error] [pid 751901:tid 752019] [remote 40.77.167.2:30035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/euclid/article/download/9214/4037"] [unique_id "amuKtSrT982lovRn7gnPuQAAYHU"]
[Thu Jul 30 12:32:37.862261 2026] [core:notice] [pid 751901:tid 752051] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:37.866332 2026] [security2:error] [pid 751901:tid 752051] [client 103.215.74.26:18086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtSrT982lovRn7gnPugAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:38.599031 2026] [core:notice] [pid 751901:tid 752086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:38.603136 2026] [security2:error] [pid 751901:tid 752086] [client 103.215.74.26:18100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtirT982lovRn7gnPygAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:38.728911 2026] [security2:error] [pid 751901:tid 752146] [client 20.215.191.139:33090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-p.php7"] [unique_id "amuKtirT982lovRn7gnPzgAAAHM"]
[Thu Jul 30 12:32:39.191862 2026] [security2:error] [pid 751901:tid 752088] [client 54.87.112.51:46804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuKtyrT982lovRn7gnP2AAAADk"], referer: https://globalmarks.pk/
[Thu Jul 30 12:32:39.331240 2026] [core:notice] [pid 751901:tid 752152] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:39.336682 2026] [security2:error] [pid 751901:tid 752152] [client 103.215.74.26:18112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKtyrT982lovRn7gnP4AAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:40.009628 2026] [security2:error] [pid 751901:tid 752156] [client 20.215.191.139:11386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuKuCrT982lovRn7gnP6gAAAH0"]
[Thu Jul 30 12:32:40.054041 2026] [core:notice] [pid 751901:tid 752143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:40.058475 2026] [security2:error] [pid 751901:tid 752143] [client 103.215.74.26:18116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuCrT982lovRn7gnP6wAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:40.826743 2026] [core:notice] [pid 751901:tid 752096] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:40.830680 2026] [security2:error] [pid 751901:tid 752096] [client 103.215.74.26:18120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuCrT982lovRn7gnP_AAAAEE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:41.037596 2026] [security2:error] [pid 751901:tid 752102] [client 20.215.191.139:42603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuKuSrT982lovRn7gnQAAAAAEc"]
[Thu Jul 30 12:32:41.386895 2026] [proxy:error] [pid 751901:tid 752071] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:41.386972 2026] [proxy_http:error] [pid 751901:tid 752071] [client 143.244.57.82:37676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:41.387629 2026] [proxy:error] [pid 751901:tid 752071] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:41.387674 2026] [proxy_http:error] [pid 751901:tid 752071] [client 143.244.57.82:37676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:41.568105 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:41.572115 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:18132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuSrT982lovRn7gnQDgAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:41.688942 2026] [proxy:error] [pid 751901:tid 752093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:41.689028 2026] [proxy_http:error] [pid 751901:tid 752093] [client 143.244.57.82:37690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:41.689593 2026] [proxy:error] [pid 751901:tid 752093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:41.689634 2026] [proxy_http:error] [pid 751901:tid 752093] [client 143.244.57.82:37690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:41.804766 2026] [core:notice] [pid 751901:tid 752076] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:42.009557 2026] [security2:error] [pid 751901:tid 752111] [client 143.244.57.82:37698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuKuirT982lovRn7gnQGwAAAFA"]
[Thu Jul 30 12:32:42.026638 2026] [core:notice] [pid 751901:tid 752025] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:42.286407 2026] [proxy:error] [pid 751901:tid 752149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:42.286477 2026] [proxy_http:error] [pid 751901:tid 752149] [client 143.244.57.82:37704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:42.287074 2026] [proxy:error] [pid 751901:tid 752149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:32:42.287126 2026] [proxy_http:error] [pid 751901:tid 752149] [client 143.244.57.82:37704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:32:42.335759 2026] [core:notice] [pid 751901:tid 752051] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:42.340247 2026] [security2:error] [pid 751901:tid 752051] [client 103.215.74.26:18142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuirT982lovRn7gnQKAAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:42.576626 2026] [security2:error] [pid 751901:tid 752150] [client 143.244.57.82:37708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuKuirT982lovRn7gnQLwAAAHc"]
[Thu Jul 30 12:32:42.855908 2026] [security2:error] [pid 751901:tid 752154] [client 143.244.57.82:9972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuKuirT982lovRn7gnQMwAAAHs"]
[Thu Jul 30 12:32:43.081534 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:43.086557 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:37394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuyrT982lovRn7gnQQAAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:43.144374 2026] [security2:error] [pid 751901:tid 752141] [client 143.244.57.82:37724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuKuyrT982lovRn7gnQQQAAAG4"]
[Thu Jul 30 12:32:43.332001 2026] [security2:error] [pid 751901:tid 752097] [client 40.77.167.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amuKuyrT982lovRn7gnQPAAAQhE"]
[Thu Jul 30 12:32:43.426508 2026] [security2:error] [pid 751901:tid 752042] [client 143.244.57.82:37726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuKuyrT982lovRn7gnQRgAAAAs"]
[Thu Jul 30 12:32:43.433912 2026] [security2:error] [pid 751901:tid 752120] [client 20.203.221.142:23478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKuyrT982lovRn7gnQRwAAAFk"]
[Thu Jul 30 12:32:43.434030 2026] [security2:error] [pid 751901:tid 752120] [client 20.203.221.142:23478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuKuyrT982lovRn7gnQRwAAAFk"]
[Thu Jul 30 12:32:43.709076 2026] [security2:error] [pid 751901:tid 752046] [client 143.244.57.82:37736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuKuyrT982lovRn7gnQUQAAAA8"]
[Thu Jul 30 12:32:43.813928 2026] [core:notice] [pid 751901:tid 752049] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:43.818306 2026] [security2:error] [pid 751901:tid 752049] [client 103.215.74.26:37402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKuyrT982lovRn7gnQVQAAABI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:43.841791 2026] [security2:error] [pid 751901:tid 752066] [client 20.215.191.139:13567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-content/repeater.php"] [unique_id "amuKuyrT982lovRn7gnQVgAAACM"]
[Thu Jul 30 12:32:43.993790 2026] [security2:error] [pid 751901:tid 752055] [client 143.244.57.82:37744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuKuyrT982lovRn7gnQWgAAABg"]
[Thu Jul 30 12:32:44.282136 2026] [security2:error] [pid 751901:tid 752100] [client 143.244.57.82:37758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuKvCrT982lovRn7gnQYQAAAEU"]
[Thu Jul 30 12:32:44.560204 2026] [core:notice] [pid 751901:tid 752031] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:44.564885 2026] [security2:error] [pid 751901:tid 752031] [client 103.215.74.26:37418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKvCrT982lovRn7gnQZgAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:44.564909 2026] [security2:error] [pid 751901:tid 752092] [client 143.244.57.82:37762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuKvCrT982lovRn7gnQZwAAAD0"]
[Thu Jul 30 12:32:44.844164 2026] [security2:error] [pid 751901:tid 752123] [client 143.244.57.82:37768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuKvCrT982lovRn7gnQbgAAAFw"]
[Thu Jul 30 12:32:45.151805 2026] [security2:error] [pid 751901:tid 752136] [client 143.244.57.82:37770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuKvSrT982lovRn7gnQdAAAAGk"]
[Thu Jul 30 12:32:45.177864 2026] [security2:error] [pid 751901:tid 752105] [client 20.203.221.142:4384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKvSrT982lovRn7gnQdgAAAEo"]
[Thu Jul 30 12:32:45.178003 2026] [security2:error] [pid 751901:tid 752105] [client 20.203.221.142:4384] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuKvSrT982lovRn7gnQdgAAAEo"]
[Thu Jul 30 12:32:45.426393 2026] [security2:error] [pid 751901:tid 752071] [client 143.244.57.82:37784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuKvSrT982lovRn7gnQfAAAACg"]
[Thu Jul 30 12:32:45.608838 2026] [security2:error] [pid 751901:tid 752157] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKvCrT982lovRn7gnQcAAAfhw"]
[Thu Jul 30 12:32:45.714568 2026] [security2:error] [pid 751901:tid 752120] [client 143.244.57.82:37792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuKvSrT982lovRn7gnQhgAAAFk"]
[Thu Jul 30 12:32:45.999579 2026] [security2:error] [pid 751901:tid 752044] [client 143.244.57.82:37798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuKvSrT982lovRn7gnQiwAAAA0"]
[Thu Jul 30 12:32:46.283382 2026] [security2:error] [pid 751901:tid 752069] [client 143.244.57.82:37812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuKvirT982lovRn7gnQmAAAACY"]
[Thu Jul 30 12:32:46.563288 2026] [security2:error] [pid 751901:tid 752095] [client 143.244.57.82:37816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.xru.gzj.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuKvirT982lovRn7gnQnAAAAEA"]
[Thu Jul 30 12:32:47.077137 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:47.568753 2026] [core:notice] [pid 751901:tid 752114] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:47.594042 2026] [security2:error] [pid 751901:tid 752058] [client 38.190.144.4:53061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKvyrT982lovRn7gnQtwAAABs"]
[Thu Jul 30 12:32:47.595764 2026] [security2:error] [pid 751901:tid 752058] [client 38.190.144.4:53061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKvyrT982lovRn7gnQtwAAABs"]
[Thu Jul 30 12:32:48.184776 2026] [security2:error] [pid 751901:tid 752122] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuKvyrT982lovRn7gnQtgAAWxk"]
[Thu Jul 30 12:32:48.730232 2026] [security2:error] [pid 751901:tid 752139] [client 20.203.221.142:40589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKwCrT982lovRn7gnQzQAAAGw"]
[Thu Jul 30 12:32:48.730360 2026] [security2:error] [pid 751901:tid 752139] [client 20.203.221.142:40589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuKwCrT982lovRn7gnQzQAAAGw"]
[Thu Jul 30 12:32:49.235117 2026] [security2:error] [pid 751901:tid 751969] [remote 74.7.241.60:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuKwSrT982lovRn7gnQ3wAAZ0M"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:32:49.842458 2026] [security2:error] [pid 751901:tid 752105] [client 20.203.221.142:1435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/red.php"] [unique_id "amuKwSrT982lovRn7gnQ7QAAAEo"]
[Thu Jul 30 12:32:49.842606 2026] [security2:error] [pid 751901:tid 752105] [client 20.203.221.142:1435] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/red.php"] [unique_id "amuKwSrT982lovRn7gnQ7QAAAEo"]
[Thu Jul 30 12:32:50.304594 2026] [core:notice] [pid 751901:tid 752142] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:50.308880 2026] [security2:error] [pid 751901:tid 752142] [client 103.215.74.26:37430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKwirT982lovRn7gnQ9AAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:50.397123 2026] [security2:error] [pid 751901:tid 752054] [client 31.56.58.134:42504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.env"] [unique_id "amuKwirT982lovRn7gnQ-AAAABc"]
[Thu Jul 30 12:32:50.496487 2026] [core:notice] [pid 751901:tid 751996] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:51.071753 2026] [core:notice] [pid 751901:tid 752042] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:51.075882 2026] [security2:error] [pid 751901:tid 752042] [client 103.215.74.26:37442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKwyrT982lovRn7gnRBwAAAAs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:51.815022 2026] [core:notice] [pid 751901:tid 752135] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:51.819368 2026] [security2:error] [pid 751901:tid 752135] [client 103.215.74.26:37448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKwyrT982lovRn7gnRFAAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:52.310859 2026] [core:notice] [pid 751901:tid 752008] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:52.567069 2026] [core:notice] [pid 751901:tid 752107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:52.574148 2026] [security2:error] [pid 751901:tid 752107] [client 103.215.74.26:37462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxCrT982lovRn7gnRJwAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:52.578191 2026] [core:notice] [pid 751901:tid 751970] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:53.306797 2026] [core:notice] [pid 751901:tid 752091] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:53.311146 2026] [security2:error] [pid 751901:tid 752091] [client 103.215.74.26:2152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxSrT982lovRn7gnROQAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:54.056184 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:54.060170 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:2164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxirT982lovRn7gnRSQAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:54.288772 2026] [security2:error] [pid 751901:tid 752048] [client 31.56.58.134:42534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.env"] [unique_id "amuKxirT982lovRn7gnRYAAAABE"]
[Thu Jul 30 12:32:54.636198 2026] [security2:error] [pid 751901:tid 752145] [client 38.190.144.4:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKxirT982lovRn7gnRagAAAHI"]
[Thu Jul 30 12:32:54.636334 2026] [security2:error] [pid 751901:tid 752145] [client 38.190.144.4:53560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuKxirT982lovRn7gnRagAAAHI"]
[Thu Jul 30 12:32:54.783330 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:54.787304 2026] [security2:error] [pid 751901:tid 752092] [client 103.215.74.26:2172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxirT982lovRn7gnRawAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:55.225649 2026] [security2:error] [pid 751901:tid 752121] [client 85.208.96.197:64670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/04/eua-anunciam-us-400-milhoes-em-novo-pacote-de-ajuda-militar-a-ucrania/"] [unique_id "amuKxyrT982lovRn7gnRfQAAAFo"]
[Thu Jul 30 12:32:55.225926 2026] [security2:error] [pid 751901:tid 752121] [client 85.208.96.197:64670] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/04/eua-anunciam-us-400-milhoes-em-novo-pacote-de-ajuda-militar-a-ucrania/"] [unique_id "amuKxyrT982lovRn7gnRfQAAAFo"]
[Thu Jul 30 12:32:55.544386 2026] [core:notice] [pid 751901:tid 752102] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:55.552222 2026] [security2:error] [pid 751901:tid 752102] [client 103.215.74.26:2178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKxyrT982lovRn7gnRggAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:55.565441 2026] [security2:error] [pid 751901:tid 752109] [client 172.237.109.114:29705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRTAAAAE4"]
[Thu Jul 30 12:32:55.881915 2026] [security2:error] [pid 751901:tid 752096] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRfAAAAEE"]
[Thu Jul 30 12:32:55.931405 2026] [security2:error] [pid 751901:tid 752157] [client 79.117.189.155:45144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRhQAAAH4"], referer: http://pkf.jo
[Thu Jul 30 12:32:56.225481 2026] [security2:error] [pid 751901:tid 752042] [client 67.206.207.234:46606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRiQAAAAs"], referer: http://pkf.jo
[Thu Jul 30 12:32:56.238202 2026] [security2:error] [pid 751901:tid 752049] [client 172.237.109.114:59281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRVAAAABI"]
[Thu Jul 30 12:32:56.246358 2026] [security2:error] [pid 751901:tid 752046] [client 172.237.109.114:37106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRUgAAAA8"]
[Thu Jul 30 12:32:56.254948 2026] [security2:error] [pid 751901:tid 752035] [client 172.237.109.114:61161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRTgAAAAQ"]
[Thu Jul 30 12:32:56.284610 2026] [security2:error] [pid 751901:tid 752111] [client 172.237.109.114:44724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRUwAAAFA"]
[Thu Jul 30 12:32:56.304147 2026] [core:notice] [pid 751901:tid 752095] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:32:56.308565 2026] [security2:error] [pid 751901:tid 752140] [client 172.237.109.114:18255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRSwAAAG0"]
[Thu Jul 30 12:32:56.312165 2026] [security2:error] [pid 751901:tid 752095] [client 103.215.74.26:2188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKyCrT982lovRn7gnRmAAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:32:56.340903 2026] [security2:error] [pid 751901:tid 752057] [client 172.237.109.114:52815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRTwAAABo"]
[Thu Jul 30 12:32:56.341098 2026] [security2:error] [pid 751901:tid 752040] [client 172.237.109.114:16965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRVQAAAAk"]
[Thu Jul 30 12:32:56.365235 2026] [security2:error] [pid 751901:tid 752124] [client 172.237.109.114:58684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRTQAAAF0"]
[Thu Jul 30 12:32:56.386132 2026] [security2:error] [pid 751901:tid 752099] [client 172.237.109.114:45904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRXgAAAEQ"]
[Thu Jul 30 12:32:56.390293 2026] [security2:error] [pid 751901:tid 752078] [client 172.237.109.114:9030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRWgAAAC8"]
[Thu Jul 30 12:32:56.401166 2026] [security2:error] [pid 751901:tid 752133] [client 172.237.109.114:46370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRSgAAAGY"]
[Thu Jul 30 12:32:56.413760 2026] [security2:error] [pid 751901:tid 752126] [client 172.237.109.114:36101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRVwAAAF8"]
[Thu Jul 30 12:32:56.420204 2026] [security2:error] [pid 751901:tid 752080] [client 172.237.109.114:21830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRWQAAADE"]
[Thu Jul 30 12:32:56.427040 2026] [security2:error] [pid 751901:tid 752084] [client 172.237.109.114:42518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRWAAAADU"]
[Thu Jul 30 12:32:56.427050 2026] [security2:error] [pid 751901:tid 752066] [client 172.237.109.114:20129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRXAAAACM"]
[Thu Jul 30 12:32:56.436224 2026] [security2:error] [pid 751901:tid 752079] [client 172.237.109.114:36354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRUAAAADA"]
[Thu Jul 30 12:32:56.477932 2026] [security2:error] [pid 751901:tid 752108] [client 172.237.109.114:34072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRUQAAAE0"]
[Thu Jul 30 12:32:56.484403 2026] [security2:error] [pid 751901:tid 752139] [client 172.237.109.114:22475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRXQAAAGw"]
[Thu Jul 30 12:32:56.562856 2026] [security2:error] [pid 751901:tid 752069] [client 172.237.109.114:14912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRWwAAACY"]
[Thu Jul 30 12:32:56.594927 2026] [security2:error] [pid 751901:tid 752056] [client 172.237.109.114:19708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxirT982lovRn7gnRXwAAABk"]
[Thu Jul 30 12:32:56.667551 2026] [security2:error] [pid 751901:tid 752089] [client 200.24.99.234:11613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKyCrT982lovRn7gnRmQAAADo"], referer: http://pkf.jo
[Thu Jul 30 12:32:56.681223 2026] [security2:error] [pid 751901:tid 752136] [client 172.237.109.114:24554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRdQAAAGk"]
[Thu Jul 30 12:32:56.752164 2026] [security2:error] [pid 751901:tid 752053] [client 172.237.109.114:60008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnReQAAABY"]
[Thu Jul 30 12:32:56.753512 2026] [security2:error] [pid 751901:tid 752075] [client 172.237.109.114:11154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnReAAAACw"]
[Thu Jul 30 12:32:56.779629 2026] [security2:error] [pid 751901:tid 752058] [client 172.237.109.114:19302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuKxyrT982lovRn7gnRdwAAABs"]
[Thu Jul 30 12:32:57.747365 2026] [security2:error] [pid 751901:tid 752133] [client 20.203.221.142:40166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/cc.php"] [unique_id "amuKySrT982lovRn7gnRvAAAAGY"]
[Thu Jul 30 12:32:57.747462 2026] [security2:error] [pid 751901:tid 752133] [client 20.203.221.142:40166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/cc.php"] [unique_id "amuKySrT982lovRn7gnRvAAAAGY"]
[Thu Jul 30 12:32:58.225298 2026] [security2:error] [pid 751901:tid 752047] [client 168.228.85.104:15888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuKySrT982lovRn7gnRugAAABA"], referer: http://pkf.jo
[Thu Jul 30 12:32:58.245808 2026] [security2:error] [pid 751901:tid 752040] [client 57.141.0.38:42010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuKySrT982lovRn7gnRvQAACSE"], referer: https://igetvape-australia.com/product/iget-bar-pro-grape-ice/
[Thu Jul 30 12:32:59.017578 2026] [security2:error] [pid 751901:tid 752097] [client 114.119.144.64:21697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inmobiliariadia.com"] [uri "/hello-world/"] [unique_id "amuKyyrT982lovRn7gnR0QAAAEI"], referer: http://inmobiliariadia.com/beautiful-lighting-effects/
[Thu Jul 30 12:33:00.953718 2026] [security2:error] [pid 751901:tid 752128] [client 95.108.213.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuKzCrT982lovRn7gnR_wAAAGE"]
[Thu Jul 30 12:33:01.760824 2026] [security2:error] [pid 751901:tid 752085] [client 20.203.221.142:24802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/log.php"] [unique_id "amuKzSrT982lovRn7gnSHQAAADY"]
[Thu Jul 30 12:33:01.760944 2026] [security2:error] [pid 751901:tid 752085] [client 20.203.221.142:24802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/log.php"] [unique_id "amuKzSrT982lovRn7gnSHQAAADY"]
[Thu Jul 30 12:33:02.056644 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:02.064524 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:2204] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKzirT982lovRn7gnSJwAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:02.807087 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:02.813825 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:2220] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKzirT982lovRn7gnSMgAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:03.562009 2026] [core:notice] [pid 751901:tid 752127] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:03.565915 2026] [security2:error] [pid 751901:tid 752127] [client 103.215.74.26:25430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuKzyrT982lovRn7gnSRQAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:04.304089 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:04.308150 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:25440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK0CrT982lovRn7gnSUQAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:04.816308 2026] [security2:error] [pid 751901:tid 752096] [client 20.203.221.142:59828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/edit.php"] [unique_id "amuK0CrT982lovRn7gnSYQAAAEE"]
[Thu Jul 30 12:33:04.816445 2026] [security2:error] [pid 751901:tid 752096] [client 20.203.221.142:59828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/edit.php"] [unique_id "amuK0CrT982lovRn7gnSYQAAAEE"]
[Thu Jul 30 12:33:04.913302 2026] [security2:error] [pid 751901:tid 752144] [client 51.9.41.235:39270] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuK0CrT982lovRn7gnSYwAAAHE"]
[Thu Jul 30 12:33:04.914814 2026] [security2:error] [pid 751901:tid 752058] [client 49.230.121.51:8933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK0CrT982lovRn7gnSXgAAABs"], referer: http://pkf.jo
[Thu Jul 30 12:33:05.018839 2026] [core:notice] [pid 751901:tid 752118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:05.025321 2026] [security2:error] [pid 751901:tid 752118] [client 103.215.74.26:25442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK0SrT982lovRn7gnSaAAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:05.064791 2026] [core:notice] [pid 751901:tid 752071] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:05.270081 2026] [security2:error] [pid 751901:tid 752088] [client 88.169.23.86:43833] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuK0SrT982lovRn7gnScQAAADk"]
[Thu Jul 30 12:33:05.428412 2026] [security2:error] [pid 751901:tid 752122] [client 89.12.23.34:33738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuK0SrT982lovRn7gnScgAAAFs"]
[Thu Jul 30 12:33:05.442661 2026] [security2:error] [pid 751901:tid 752085] [client 46.44.223.63:64388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuK0SrT982lovRn7gnScwAAADY"]
[Thu Jul 30 12:33:05.474277 2026] [security2:error] [pid 751901:tid 752109] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuK0CrT982lovRn7gnSTwAATkc"]
[Thu Jul 30 12:33:05.480462 2026] [security2:error] [pid 751901:tid 752031] [client 90.103.129.45:37592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuK0SrT982lovRn7gnSdAAAAAA"]
[Thu Jul 30 12:33:05.578343 2026] [security2:error] [pid 751901:tid 752100] [client 38.190.144.4:54069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK0SrT982lovRn7gnSfgAAAEU"]
[Thu Jul 30 12:33:05.578638 2026] [security2:error] [pid 751901:tid 752100] [client 38.190.144.4:54069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK0SrT982lovRn7gnSfgAAAEU"]
[Thu Jul 30 12:33:05.609298 2026] [security2:error] [pid 751901:tid 752119] [client 85.222.250.226:54230] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuK0SrT982lovRn7gnSfwAAAFg"]
[Thu Jul 30 12:33:05.725717 2026] [security2:error] [pid 751901:tid 752123] [client 103.192.152.144:52438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuK0SrT982lovRn7gnShQAAAFw"]
[Thu Jul 30 12:33:05.763702 2026] [security2:error] [pid 751901:tid 752064] [client 99.217.44.60:54760] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuK0SrT982lovRn7gnShgAAACE"]
[Thu Jul 30 12:33:05.814248 2026] [security2:error] [pid 751901:tid 752038] [client 192.81.202.237:35408] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuK0SrT982lovRn7gnShwAAAAc"]
[Thu Jul 30 12:33:05.972704 2026] [security2:error] [pid 751901:tid 752137] [client 95.26.138.15:13168] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuK0SrT982lovRn7gnSigAAAGo"]
[Thu Jul 30 12:33:05.993170 2026] [security2:error] [pid 751901:tid 752034] [client 86.180.65.33:58226] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuK0SrT982lovRn7gnSjAAAAAM"]
[Thu Jul 30 12:33:06.026686 2026] [security2:error] [pid 751901:tid 752102] [client 82.20.152.180:49796] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuK0irT982lovRn7gnSjQAAAEc"]
[Thu Jul 30 12:33:06.110102 2026] [security2:error] [pid 751901:tid 752084] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK0SrT982lovRn7gnSegAAADU"]
[Thu Jul 30 12:33:06.124135 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:06.172152 2026] [security2:error] [pid 751901:tid 752054] [client 20.203.221.142:56212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/plugins.php"] [unique_id "amuK0irT982lovRn7gnSlgAAABc"]
[Thu Jul 30 12:33:06.172241 2026] [security2:error] [pid 751901:tid 752054] [client 20.203.221.142:56212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/plugins.php"] [unique_id "amuK0irT982lovRn7gnSlgAAABc"]
[Thu Jul 30 12:33:06.503476 2026] [security2:error] [pid 751901:tid 752121] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuK0CrT982lovRn7gnSVwAAWkA"]
[Thu Jul 30 12:33:06.648121 2026] [security2:error] [pid 751901:tid 752135] [client 20.203.221.142:41417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/style.php"] [unique_id "amuK0irT982lovRn7gnSqQAAAGg"]
[Thu Jul 30 12:33:06.648217 2026] [security2:error] [pid 751901:tid 752135] [client 20.203.221.142:41417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/style.php"] [unique_id "amuK0irT982lovRn7gnSqQAAAGg"]
[Thu Jul 30 12:33:06.839700 2026] [security2:error] [pid 751901:tid 752065] [client 45.236.103.184:51737] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuK0irT982lovRn7gnSqgAAACI"]
[Thu Jul 30 12:33:07.385694 2026] [security2:error] [pid 751901:tid 752104] [client 24.76.188.15:48592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuK0yrT982lovRn7gnSugAAAEk"]
[Thu Jul 30 12:33:07.832904 2026] [security2:error] [pid 751901:tid 752133] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuK0yrT982lovRn7gnSsgAAZmQ"]
[Thu Jul 30 12:33:09.059695 2026] [security2:error] [pid 751901:tid 752093] [client 43.172.196.156:41108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/06/29/organisez-une-journee-shopping-a-londres/"] [unique_id "amuK1CrT982lovRn7gnS2wAAAD4"]
[Thu Jul 30 12:33:09.332987 2026] [security2:error] [pid 751901:tid 752114] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK1CrT982lovRn7gnS2gAAAFM"]
[Thu Jul 30 12:33:09.427489 2026] [security2:error] [pid 751901:tid 752070] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK1CrT982lovRn7gnS4QAAACc"]
[Thu Jul 30 12:33:09.705448 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:09.709780 2026] [security2:error] [pid 751901:tid 752122] [client 43.173.179.206:55852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/06/29/organisez-une-journee-shopping-a-londres/"] [unique_id "amuK1SrT982lovRn7gnS8wAAAFs"], referer: https://carnetdeshopping.com/index.php/2009/06/29/organisez-une-journee-shopping-a-londres/
[Thu Jul 30 12:33:10.162473 2026] [core:notice] [pid 751901:tid 752089] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:10.831174 2026] [security2:error] [pid 751901:tid 752084] [client 20.203.221.142:59777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/plugins.php"] [unique_id "amuK1irT982lovRn7gnTDQAAADU"]
[Thu Jul 30 12:33:10.831299 2026] [security2:error] [pid 751901:tid 752084] [client 20.203.221.142:59777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "saifalkhaleejest.com"] [uri "/plugins.php"] [unique_id "amuK1irT982lovRn7gnTDQAAADU"]
[Thu Jul 30 12:33:10.838809 2026] [core:notice] [pid 751901:tid 752131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:10.842718 2026] [security2:error] [pid 751901:tid 752131] [client 103.215.74.26:25452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "776"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK1irT982lovRn7gnTDgAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:11.325468 2026] [security2:error] [pid 751901:tid 752074] [client 170.106.180.139:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.180.106.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/book.php"] [unique_id "amuK1yrT982lovRn7gnTGgAAACs"]
[Thu Jul 30 12:33:11.345593 2026] [security2:error] [pid 751901:tid 751997] [remote 69.57.172.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.172.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannyplatoncuevas.com"] [uri "/wp-login.php"] [unique_id "amuK1yrT982lovRn7gnTEgAAQV8"]
[Thu Jul 30 12:33:11.533141 2026] [core:error] [pid 751901:tid 752063] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.533162 2026] [core:error] [pid 751901:tid 752063] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.566617 2026] [core:notice] [pid 751901:tid 752093] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:11.574233 2026] [security2:error] [pid 751901:tid 752093] [client 103.215.74.26:25462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK1yrT982lovRn7gnTMAAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:11.576002 2026] [core:error] [pid 751901:tid 752126] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.576024 2026] [core:error] [pid 751901:tid 752126] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.616240 2026] [core:error] [pid 751901:tid 752067] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.616260 2026] [core:error] [pid 751901:tid 752067] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.625025 2026] [core:error] [pid 751901:tid 752069] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.625043 2026] [core:error] [pid 751901:tid 752069] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.625091 2026] [core:error] [pid 751901:tid 752119] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:11.625107 2026] [core:error] [pid 751901:tid 752119] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:12.091424 2026] [security2:error] [pid 751901:tid 752032] [client 157.35.45.167:43635] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuK2CrT982lovRn7gnTRgAAAAE"]
[Thu Jul 30 12:33:12.331881 2026] [core:notice] [pid 751901:tid 752035] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:12.336012 2026] [security2:error] [pid 751901:tid 752035] [client 103.215.74.26:25472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2CrT982lovRn7gnTTAAAAAQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:13.068045 2026] [core:notice] [pid 751901:tid 752046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:13.072152 2026] [security2:error] [pid 751901:tid 752046] [client 103.215.74.26:34656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2SrT982lovRn7gnTXQAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:13.799006 2026] [core:notice] [pid 751901:tid 752033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:13.803353 2026] [security2:error] [pid 751901:tid 752033] [client 103.215.74.26:34660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2SrT982lovRn7gnTcAAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:13.864915 2026] [security2:error] [pid 751901:tid 751914] [remote 57.141.0.45:55852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/589953950/feed/rss2/"] [unique_id "amuK2SrT982lovRn7gnTcQAATww"]
[Thu Jul 30 12:33:14.523847 2026] [core:notice] [pid 751901:tid 752097] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:14.528167 2026] [security2:error] [pid 751901:tid 752097] [client 103.215.74.26:34670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2irT982lovRn7gnTgQAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:14.752646 2026] [core:notice] [pid 751901:tid 752112] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:14.763530 2026] [core:notice] [pid 751901:tid 752139] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:15.253298 2026] [core:notice] [pid 751901:tid 752130] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:15.257303 2026] [security2:error] [pid 751901:tid 752130] [client 103.215.74.26:34686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK2yrT982lovRn7gnTnAAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:15.551166 2026] [security2:error] [pid 751901:tid 752147] [client 8.217.152.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuK2yrT982lovRn7gnTnwAAAHQ"]
[Thu Jul 30 12:33:16.478643 2026] [security2:error] [pid 751901:tid 752123] [client 38.190.144.4:54570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK3CrT982lovRn7gnTvQAAAFw"]
[Thu Jul 30 12:33:16.478764 2026] [security2:error] [pid 751901:tid 752123] [client 38.190.144.4:54570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK3CrT982lovRn7gnTvQAAAFw"]
[Thu Jul 30 12:33:17.874318 2026] [security2:error] [pid 751901:tid 752141] [client 74.7.230.16:35332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-19437fac.xdi.djb.temporary.site"] [uri "/index.php"] [unique_id "amuK3CrT982lovRn7gnTtQAAbjY"]
[Thu Jul 30 12:33:19.676402 2026] [security2:error] [pid 751901:tid 752103] [client 102.204.4.28:30787] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuK3yrT982lovRn7gnUEgAAAEg"]
[Thu Jul 30 12:33:20.400996 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:20.973015 2026] [core:notice] [pid 751901:tid 752118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:20.977295 2026] [security2:error] [pid 751901:tid 752118] [client 103.215.74.26:34700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4CrT982lovRn7gnUPwAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:21.729871 2026] [core:notice] [pid 751901:tid 752104] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:21.734275 2026] [security2:error] [pid 751901:tid 752104] [client 103.215.74.26:34712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4SrT982lovRn7gnUWQAAAEk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:22.477908 2026] [core:notice] [pid 751901:tid 752106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:22.482162 2026] [security2:error] [pid 751901:tid 752106] [client 103.215.74.26:34726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4irT982lovRn7gnUdQAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:23.217461 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:23.221598 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:46710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4yrT982lovRn7gnUjwAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:23.507906 2026] [security2:error] [pid 751901:tid 752081] [client 43.173.179.40:36802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuK4yrT982lovRn7gnUkwAAADI"]
[Thu Jul 30 12:33:23.954054 2026] [core:notice] [pid 751901:tid 752102] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:23.959061 2026] [security2:error] [pid 751901:tid 752102] [client 103.215.74.26:46760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK4yrT982lovRn7gnUrAAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:24.698058 2026] [core:notice] [pid 751901:tid 752140] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:24.702532 2026] [security2:error] [pid 751901:tid 752140] [client 103.215.74.26:46772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5CrT982lovRn7gnUwQAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:25.422494 2026] [core:notice] [pid 751901:tid 752040] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:25.426917 2026] [security2:error] [pid 751901:tid 752040] [client 103.215.74.26:46830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5SrT982lovRn7gnU0wAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:25.529280 2026] [autoindex:error] [pid 751901:tid 752106] [client 82.102.18.188:47270] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:25.685058 2026] [autoindex:error] [pid 751901:tid 752115] [client 82.102.18.188:47270] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:25.840361 2026] [security2:error] [pid 751901:tid 752158] [client 82.102.18.188:47270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuK5SrT982lovRn7gnU4gAAAH8"]
[Thu Jul 30 12:33:26.176222 2026] [security2:error] [pid 751901:tid 752093] [client 82.102.18.188:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.hello-pal.com"] [uri "/xmlrpc.php"] [unique_id "amuK5irT982lovRn7gnU7gAAAD4"]
[Thu Jul 30 12:33:26.199913 2026] [core:notice] [pid 751901:tid 752095] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:26.204148 2026] [security2:error] [pid 751901:tid 752095] [client 103.215.74.26:46850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5irT982lovRn7gnU7wAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:26.529220 2026] [autoindex:error] [pid 751901:tid 752033] [client 82.102.18.188:47290] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:26.892808 2026] [security2:error] [pid 751901:tid 752125] [client 82.102.18.188:47290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuK5irT982lovRn7gnVAgAAAF4"]
[Thu Jul 30 12:33:26.927123 2026] [core:notice] [pid 751901:tid 752066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:26.931536 2026] [security2:error] [pid 751901:tid 752066] [client 103.215.74.26:46858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5irT982lovRn7gnVAwAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:27.111382 2026] [security2:error] [pid 751901:tid 752112] [client 66.249.64.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.reliablehomeappliancerepair.store"] [uri "/index.php"] [unique_id "amuK5irT982lovRn7gnU9gAAAFE"]
[Thu Jul 30 12:33:27.204363 2026] [security2:error] [pid 751901:tid 752117] [client 82.102.18.188:47294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuK5yrT982lovRn7gnVDQAAAFY"]
[Thu Jul 30 12:33:27.534003 2026] [security2:error] [pid 751901:tid 752120] [client 82.102.18.188:47306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuK5yrT982lovRn7gnVFwAAAFk"]
[Thu Jul 30 12:33:27.650495 2026] [core:notice] [pid 751901:tid 752058] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:27.654464 2026] [security2:error] [pid 751901:tid 752058] [client 103.215.74.26:46916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK5yrT982lovRn7gnVHQAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:27.806417 2026] [security2:error] [pid 751901:tid 752034] [client 155.35.46.151:55200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK5yrT982lovRn7gnVFAAAAAM"], referer: http://pkf.jo
[Thu Jul 30 12:33:28.537132 2026] [security2:error] [pid 751901:tid 752128] [client 5.111.46.83:1495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK6CrT982lovRn7gnVMgAAAGE"], referer: http://pkf.jo
[Thu Jul 30 12:33:28.594739 2026] [security2:error] [pid 751901:tid 752070] [client 49.51.72.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuK6CrT982lovRn7gnVJgAAACc"]
[Thu Jul 30 12:33:28.824492 2026] [security2:error] [pid 751901:tid 752105] [client 82.102.18.188:47310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuK6CrT982lovRn7gnVRgAAAEo"]
[Thu Jul 30 12:33:29.124812 2026] [security2:error] [pid 751901:tid 752143] [client 82.102.18.188:47312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuK6SrT982lovRn7gnVTgAAAHA"]
[Thu Jul 30 12:33:29.133542 2026] [core:error] [pid 751901:tid 752145] [client 74.7.241.156:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:29.133567 2026] [core:error] [pid 751901:tid 752145] [client 74.7.241.156:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:29.133733 2026] [security2:error] [pid 751901:tid 752145] [client 74.7.241.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.glowspakarachi.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuK6SrT982lovRn7gnVTwAAAHI"]
[Thu Jul 30 12:33:29.134282 2026] [security2:error] [pid 751901:tid 752115] [client 74.7.241.156:50290] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.glowspakarachi.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuK6SrT982lovRn7gnVTAAAVAc"]
[Thu Jul 30 12:33:29.222335 2026] [proxy:error] [pid 751901:tid 752026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:33:29.222389 2026] [proxy_http:error] [pid 751901:tid 752026] [remote 74.7.244.30:52156] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:33:29.222948 2026] [proxy:error] [pid 751901:tid 752026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:33:29.223008 2026] [proxy_http:error] [pid 751901:tid 752026] [remote 74.7.244.30:52156] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:33:29.450782 2026] [security2:error] [pid 751901:tid 752093] [client 82.102.18.188:47326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuK6SrT982lovRn7gnVWgAAAD4"]
[Thu Jul 30 12:33:29.591048 2026] [security2:error] [pid 751901:tid 752059] [client 74.7.241.128:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-55f007f0.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuK6CrT982lovRn7gnVPQAAABw"]
[Thu Jul 30 12:33:29.591789 2026] [security2:error] [pid 751901:tid 752132] [client 74.7.241.128:39546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-55f007f0.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuK6CrT982lovRn7gnVOwAAZXs"]
[Thu Jul 30 12:33:29.796112 2026] [security2:error] [pid 751901:tid 752039] [client 82.102.18.188:47336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuK6SrT982lovRn7gnVYQAAAAg"]
[Thu Jul 30 12:33:29.812055 2026] [security2:error] [pid 751901:tid 752073] [client 43.172.198.169:51646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuK6SrT982lovRn7gnVWwAAACo"]
[Thu Jul 30 12:33:30.153285 2026] [security2:error] [pid 751901:tid 752056] [client 82.102.18.188:47352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuK6irT982lovRn7gnVbAAAABk"]
[Thu Jul 30 12:33:30.410060 2026] [security2:error] [pid 751901:tid 752101] [client 82.102.18.188:47368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuK6irT982lovRn7gnVdAAAAEY"]
[Thu Jul 30 12:33:30.552687 2026] [security2:error] [pid 751901:tid 752037] [client 113.168.236.221:55041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK6SrT982lovRn7gnVawAAAAY"], referer: http://pkf.jo
[Thu Jul 30 12:33:30.628608 2026] [security2:error] [pid 751901:tid 752130] [client 34.21.248.151:5657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2013/02/ile-petite-terre-guadeloupe_13-300x225.jpg"] [unique_id "amuK6irT982lovRn7gnVigAAAGM"]
[Thu Jul 30 12:33:30.719221 2026] [security2:error] [pid 751901:tid 752143] [client 82.102.18.188:47374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuK6irT982lovRn7gnVmQAAAHA"]
[Thu Jul 30 12:33:30.812091 2026] [security2:error] [pid 751901:tid 752058] [client 51.68.107.137:32075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.radiojelli.com"] [uri "/robots.txt"] [unique_id "amuK6irT982lovRn7gnVnQAAABs"]
[Thu Jul 30 12:33:30.812209 2026] [security2:error] [pid 751901:tid 752058] [client 51.68.107.137:32075] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.radiojelli.com"] [uri "/robots.txt"] [unique_id "amuK6irT982lovRn7gnVnQAAABs"]
[Thu Jul 30 12:33:31.048329 2026] [security2:error] [pid 751901:tid 752050] [client 82.102.18.188:47376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuK6yrT982lovRn7gnVqAAAABM"]
[Thu Jul 30 12:33:31.389767 2026] [security2:error] [pid 751901:tid 752148] [client 82.102.18.188:47386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.hello-pal.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuK6yrT982lovRn7gnVsQAAAHU"]
[Thu Jul 30 12:33:31.449262 2026] [security2:error] [pid 751901:tid 752132] [client 102.23.36.49:55938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuK6yrT982lovRn7gnVqQAAAGU"], referer: http://pkf.jo
[Thu Jul 30 12:33:32.400184 2026] [security2:error] [pid 751901:tid 752040] [client 51.68.107.137:12603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.radiojelli.com"] [uri "/robots.txt"] [unique_id "amuK7CrT982lovRn7gnVxwAAAAk"]
[Thu Jul 30 12:33:32.400320 2026] [security2:error] [pid 751901:tid 752040] [client 51.68.107.137:12603] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.radiojelli.com"] [uri "/robots.txt"] [unique_id "amuK7CrT982lovRn7gnVxwAAAAk"]
[Thu Jul 30 12:33:32.639007 2026] [core:notice] [pid 751901:tid 752119] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:33.224127 2026] [core:notice] [pid 751901:tid 752035] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:33.397054 2026] [core:notice] [pid 751901:tid 752109] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:33.401001 2026] [security2:error] [pid 751901:tid 752109] [client 103.215.74.26:3758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK7SrT982lovRn7gnV5gAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:33.482464 2026] [security2:error] [pid 751901:tid 752088] [client 114.119.150.9:49627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/share-price-look-up/"] [unique_id "amuK7SrT982lovRn7gnV6gAAADk"], referer: https://alseermarine.com/investor-relations-2/share-graph
[Thu Jul 30 12:33:33.659323 2026] [core:notice] [pid 751901:tid 752032] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:34.108379 2026] [security2:error] [pid 751901:tid 752076] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK7SrT982lovRn7gnV6QAAAC0"]
[Thu Jul 30 12:33:34.134180 2026] [core:notice] [pid 751901:tid 752128] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:34.138334 2026] [security2:error] [pid 751901:tid 752128] [client 103.215.74.26:3770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "736"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK7irT982lovRn7gnV-QAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:34.348460 2026] [core:error] [pid 751901:tid 752143] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.348483 2026] [core:error] [pid 751901:tid 752143] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.354433 2026] [core:error] [pid 751901:tid 752085] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.354459 2026] [core:error] [pid 751901:tid 752085] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.381124 2026] [core:error] [pid 751901:tid 752051] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.381141 2026] [core:error] [pid 751901:tid 752051] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.427909 2026] [core:error] [pid 751901:tid 752118] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.427935 2026] [core:error] [pid 751901:tid 752118] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.434604 2026] [core:error] [pid 751901:tid 752035] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.434621 2026] [core:error] [pid 751901:tid 752035] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:33:34.645820 2026] [security2:error] [pid 751901:tid 752133] [client 85.208.96.210:59664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/11/terremoto-de-magnitude-73-causa-alerta-de-tsunami-em-tonga-na-oceania/"] [unique_id "amuK7irT982lovRn7gnWHgAAAGY"]
[Thu Jul 30 12:33:34.645958 2026] [security2:error] [pid 751901:tid 752133] [client 85.208.96.210:59664] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/11/terremoto-de-magnitude-73-causa-alerta-de-tsunami-em-tonga-na-oceania/"] [unique_id "amuK7irT982lovRn7gnWHgAAAGY"]
[Thu Jul 30 12:33:34.858272 2026] [core:notice] [pid 751901:tid 752043] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:34.862672 2026] [security2:error] [pid 751901:tid 752043] [client 103.215.74.26:3784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK7irT982lovRn7gnWJQAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:35.755070 2026] [security2:error] [pid 751901:tid 752067] [client 114.119.134.206:34781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2023/01/067.jpeg"] [unique_id "amuK7yrT982lovRn7gnWRgAAACQ"], referer: https://www.nordeste1.com/2023/01/17/joao-azevedo-anuncia-rafaela-camaraense-para-assumir-secretaria-de-meio-ambiente/
[Thu Jul 30 12:33:37.818181 2026] [core:notice] [pid 751901:tid 752145] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:38.347328 2026] [security2:error] [pid 751901:tid 752097] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuK8SrT982lovRn7gnWZQAAQg0"]
[Thu Jul 30 12:33:38.420519 2026] [security2:error] [pid 751901:tid 752125] [client 38.190.144.4:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK8irT982lovRn7gnWjQAAAF4"]
[Thu Jul 30 12:33:38.420627 2026] [security2:error] [pid 751901:tid 752125] [client 38.190.144.4:55576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK8irT982lovRn7gnWjQAAAF4"]
[Thu Jul 30 12:33:38.561862 2026] [security2:error] [pid 751901:tid 752121] [client 114.119.130.237:29131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sv.radiojelli.com"] [uri "/where-are-all-the-single-men"] [unique_id "amuK8irT982lovRn7gnWjgAAAFo"], referer: https://sv.radiojelli.com/sitemaps/sitemap1.xml
[Thu Jul 30 12:33:38.601967 2026] [security2:error] [pid 751901:tid 752113] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuK8irT982lovRn7gnWfQAAAFI"]
[Thu Jul 30 12:33:40.586103 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:40.592564 2026] [security2:error] [pid 751901:tid 752123] [client 103.215.74.26:3788] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK9CrT982lovRn7gnWyQAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:41.322507 2026] [core:notice] [pid 751901:tid 752087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:41.329125 2026] [security2:error] [pid 751901:tid 752087] [client 103.215.74.26:3800] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK9SrT982lovRn7gnW4AAAADg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:42.307511 2026] [security2:error] [pid 751901:tid 752078] [client 114.119.156.86:33935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/tendance-la-chemise-en-jean-must-have-printemps-ete-2013"] [unique_id "amuK9irT982lovRn7gnW-wAAAC8"], referer: https://www.carnetdeshopping.com/author/sabrina/page/66
[Thu Jul 30 12:33:43.219450 2026] [security2:error] [pid 751901:tid 752076] [client 34.139.111.28:49404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amuK9CrT982lovRn7gnWwAAAAC0"]
[Thu Jul 30 12:33:44.654414 2026] [security2:error] [pid 751901:tid 752129] [client 37.120.155.179:44156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuK-CrT982lovRn7gnXNwAAAGI"]
[Thu Jul 30 12:33:44.654510 2026] [security2:error] [pid 751901:tid 752129] [client 37.120.155.179:44156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuK-CrT982lovRn7gnXNwAAAGI"]
[Thu Jul 30 12:33:44.967294 2026] [security2:error] [pid 751901:tid 752142] [client 104.254.90.251:42112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuK-CrT982lovRn7gnXOwAAAG8"]
[Thu Jul 30 12:33:44.967402 2026] [security2:error] [pid 751901:tid 752142] [client 104.254.90.251:42112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuK-CrT982lovRn7gnXOwAAAG8"]
[Thu Jul 30 12:33:44.985986 2026] [security2:error] [pid 751901:tid 751970] [remote 57.141.0.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuK-CrT982lovRn7gnXPAAAakQ"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,polyester,cotton,denim,aluminum,plastic,nylon,wood&orderby=menu_order&rating=5&status=sale&filter_brand=desigual&unfilter=1
[Thu Jul 30 12:33:45.762331 2026] [security2:error] [pid 751901:tid 752011] [remote 57.141.0.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuK-SrT982lovRn7gnXRgAASm0"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,polyester,cotton,denim,aluminum,plastic,nylon,wood&orderby=menu_order&rating=5&status=sale&filter_brand=desigual&unfilter=1
[Thu Jul 30 12:33:47.062350 2026] [core:notice] [pid 751901:tid 752111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:47.067752 2026] [security2:error] [pid 751901:tid 752111] [client 103.215.74.26:39026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK-yrT982lovRn7gnXZgAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:47.584399 2026] [core:notice] [pid 751901:tid 752108] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:47.634824 2026] [security2:error] [pid 751901:tid 752034] [client 20.63.98.115:54756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gmo.php"] [unique_id "amuK-yrT982lovRn7gnXhAAAAAM"]
[Thu Jul 30 12:33:47.812933 2026] [core:notice] [pid 751901:tid 752123] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:47.817076 2026] [security2:error] [pid 751901:tid 752123] [client 103.215.74.26:39032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK-yrT982lovRn7gnXiwAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:48.454274 2026] [security2:error] [pid 751901:tid 752042] [client 20.63.98.115:55308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/nakrip.php"] [unique_id "amuK_CrT982lovRn7gnXlwAAAAs"]
[Thu Jul 30 12:33:48.550955 2026] [core:notice] [pid 751901:tid 752079] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:48.557421 2026] [security2:error] [pid 751901:tid 752079] [client 103.215.74.26:39036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_CrT982lovRn7gnXmQAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:48.710047 2026] [security2:error] [pid 751901:tid 752087] [client 74.7.241.183:59906] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hris.rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amuK_CrT982lovRn7gnXoAAAOAU"]
[Thu Jul 30 12:33:49.201244 2026] [security2:error] [pid 751901:tid 752116] [client 38.190.144.4:56068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK_SrT982lovRn7gnXqwAAAFU"]
[Thu Jul 30 12:33:49.201375 2026] [security2:error] [pid 751901:tid 752116] [client 38.190.144.4:56068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuK_SrT982lovRn7gnXqwAAAFU"]
[Thu Jul 30 12:33:49.302110 2026] [core:notice] [pid 751901:tid 752155] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:49.306016 2026] [security2:error] [pid 751901:tid 752155] [client 103.215.74.26:39046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_SrT982lovRn7gnXrwAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:49.316535 2026] [security2:error] [pid 751901:tid 752032] [client 20.63.98.115:64876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/radio.php"] [unique_id "amuK_SrT982lovRn7gnXsAAAAAE"]
[Thu Jul 30 12:33:49.361278 2026] [core:notice] [pid 751901:tid 752122] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:49.618326 2026] [autoindex:error] [pid 751901:tid 751909] [remote 74.7.242.5:56540] AH01276: Cannot serve directory /home2/qnjgzjte/hris.rgserve.ph/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:50.043819 2026] [core:notice] [pid 751901:tid 752034] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:50.047781 2026] [security2:error] [pid 751901:tid 752034] [client 103.215.74.26:39052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_irT982lovRn7gnXvwAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:50.194522 2026] [security2:error] [pid 751901:tid 752037] [client 20.63.98.115:55303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-singin.php"] [unique_id "amuK_irT982lovRn7gnXwwAAAAY"]
[Thu Jul 30 12:33:50.795340 2026] [core:notice] [pid 751901:tid 752153] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:50.799455 2026] [security2:error] [pid 751901:tid 752153] [client 103.215.74.26:39064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_irT982lovRn7gnXzgAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:51.519050 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:51.522889 2026] [security2:error] [pid 751901:tid 752063] [client 103.215.74.26:39074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuK_yrT982lovRn7gnX4wAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:51.904086 2026] [security2:error] [pid 751901:tid 752142] [client 114.119.144.17:42595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/search"] [unique_id "amuK_yrT982lovRn7gnX5wAAAG8"], referer: https://www.kendarikomputer.com/search?updated-max=2023-05-30T13%3A12%3A00%2B08%3A00&max-results=10&reverse-paginate=true&m=1
[Thu Jul 30 12:33:51.939195 2026] [security2:error] [pid 751901:tid 752051] [client 20.63.98.115:59036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/as.php"] [unique_id "amuK_yrT982lovRn7gnX6AAAABQ"]
[Thu Jul 30 12:33:52.285150 2026] [core:notice] [pid 751901:tid 752060] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:52.289059 2026] [security2:error] [pid 751901:tid 752060] [client 103.215.74.26:39088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLACrT982lovRn7gnX8gAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:52.471968 2026] [core:notice] [pid 751901:tid 752136] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:53.006260 2026] [core:notice] [pid 751901:tid 752085] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:53.010385 2026] [security2:error] [pid 751901:tid 752085] [client 103.215.74.26:42766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLASrT982lovRn7gnYAgAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:53.113240 2026] [security2:error] [pid 751901:tid 752034] [client 20.63.98.115:20953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/x.php"] [unique_id "amuLASrT982lovRn7gnYBgAAAAM"]
[Thu Jul 30 12:33:53.762195 2026] [core:notice] [pid 751901:tid 752154] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:53.766254 2026] [security2:error] [pid 751901:tid 752154] [client 103.215.74.26:42782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLASrT982lovRn7gnYIAAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:54.163819 2026] [autoindex:error] [pid 751901:tid 752107] [client 52.4.19.39:23296] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:33:54.224358 2026] [security2:error] [pid 751901:tid 751949] [remote 74.7.241.60:56114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuLAirT982lovRn7gnYLAAAZS8"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:33:54.540594 2026] [core:notice] [pid 751901:tid 752063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:54.544606 2026] [security2:error] [pid 751901:tid 752063] [client 103.215.74.26:42784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLAirT982lovRn7gnYMAAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:55.072222 2026] [security2:error] [pid 751901:tid 752093] [client 20.63.98.115:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/item.php"] [unique_id "amuLAyrT982lovRn7gnYQQAAAD4"]
[Thu Jul 30 12:33:55.290841 2026] [core:notice] [pid 751901:tid 752092] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:55.294808 2026] [security2:error] [pid 751901:tid 752092] [client 103.215.74.26:42796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLAyrT982lovRn7gnYSQAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:55.623464 2026] [security2:error] [pid 751901:tid 752069] [client 114.119.158.118:20187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/2026/03/"] [unique_id "amuLAyrT982lovRn7gnYUQAAACY"], referer: https://saifalkhaleejest.com/when-to-use-rotation-chain-hoists-over-standard-chain-hoists/
[Thu Jul 30 12:33:55.776605 2026] [security2:error] [pid 751901:tid 751955] [remote 114.119.156.134:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/get/vancouver"] [unique_id "amuLAyrT982lovRn7gnYVgAAWTU"], referer: https://www.jipkl.com/index.php/JIPKL/article/view/6/version/6
[Thu Jul 30 12:33:55.860399 2026] [security2:error] [pid 751901:tid 752140] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLAyrT982lovRn7gnYSAAAAG0"]
[Thu Jul 30 12:33:56.047366 2026] [core:notice] [pid 751901:tid 752044] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:56.048808 2026] [security2:error] [pid 751901:tid 752042] [client 20.63.98.115:59010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/app.php"] [unique_id "amuLBCrT982lovRn7gnYXAAAAAs"]
[Thu Jul 30 12:33:56.052474 2026] [security2:error] [pid 751901:tid 752044] [client 103.215.74.26:42804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBCrT982lovRn7gnYWwAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:56.102479 2026] [security2:error] [pid 751901:tid 751983] [remote 5.181.134.118:36868] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "serverkr.com"] [uri "/"] [unique_id "amuLBCrT982lovRn7gnYYQAAVFE"]
[Thu Jul 30 12:33:56.717152 2026] [security2:error] [pid 751901:tid 752047] [client 20.63.98.115:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/k.php"] [unique_id "amuLBCrT982lovRn7gnYcgAAABA"]
[Thu Jul 30 12:33:56.781013 2026] [core:notice] [pid 751901:tid 752135] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:56.785085 2026] [security2:error] [pid 751901:tid 752135] [client 103.215.74.26:42806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBCrT982lovRn7gnYdgAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:57.531178 2026] [core:notice] [pid 751901:tid 752056] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:57.535165 2026] [security2:error] [pid 751901:tid 752056] [client 103.215.74.26:42812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBSrT982lovRn7gnYhQAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:57.919170 2026] [security2:error] [pid 751901:tid 752123] [client 20.63.98.115:55313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-fmfile.php"] [unique_id "amuLBSrT982lovRn7gnYlQAAAFw"]
[Thu Jul 30 12:33:58.256569 2026] [core:notice] [pid 751901:tid 752065] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:58.260858 2026] [security2:error] [pid 751901:tid 752065] [client 103.215.74.26:42820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBirT982lovRn7gnYnAAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:58.808873 2026] [core:notice] [pid 751901:tid 752033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:58.977931 2026] [core:notice] [pid 751901:tid 752078] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:58.982404 2026] [security2:error] [pid 751901:tid 752078] [client 103.215.74.26:42836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLBirT982lovRn7gnYrAAAAC8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:59.556333 2026] [security2:error] [pid 751901:tid 752098] [client 114.119.137.64:21581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiantourz.com"] [uri "/soldes/homme-aigle-cytise-marine-manteaux/"] [unique_id "amuLByrT982lovRn7gnYvQAAAEM"], referer: http://www.arabiantourz.com/soldes/homme-pierre-cardin-danton-grisrougerose-chemises/
[Thu Jul 30 12:33:59.715340 2026] [core:notice] [pid 751901:tid 752149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:33:59.719655 2026] [security2:error] [pid 751901:tid 752149] [client 103.215.74.26:42844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLByrT982lovRn7gnYwwAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:33:59.729476 2026] [security2:error] [pid 751901:tid 752088] [client 20.63.98.115:54783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wi.php"] [unique_id "amuLByrT982lovRn7gnYxAAAADk"]
[Thu Jul 30 12:34:00.863742 2026] [core:error] [pid 751901:tid 752095] [client 74.7.244.12:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:00.863764 2026] [core:error] [pid 751901:tid 752095] [client 74.7.244.12:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:00.863860 2026] [security2:error] [pid 751901:tid 752095] [client 74.7.244.12:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.jta.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuLCCrT982lovRn7gnY3wAAAEA"]
[Thu Jul 30 12:34:00.864584 2026] [security2:error] [pid 751901:tid 752140] [client 74.7.244.12:58354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.jta.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuLCCrT982lovRn7gnY3QAAbXo"]
[Thu Jul 30 12:34:01.004703 2026] [security2:error] [pid 751901:tid 752065] [client 114.119.132.248:39343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kingstarenterprises.com"] [uri "/product-category/gym-club-accessories/versa-grips"] [unique_id "amuLCSrT982lovRn7gnY4gAAACI"], referer: https://www.kingstarenterprises.com/product-category/gym-club-accessories/versa-grips?wc_view_mode=masonry_grid
[Thu Jul 30 12:34:01.285088 2026] [core:notice] [pid 751901:tid 752061] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:02.068592 2026] [security2:error] [pid 751901:tid 752062] [client 20.215.191.139:58721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/011i.php"] [unique_id "amuLCirT982lovRn7gnY_wAAAB8"]
[Thu Jul 30 12:34:02.312252 2026] [security2:error] [pid 751901:tid 752129] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLCSrT982lovRn7gnY9QAAYn8"]
[Thu Jul 30 12:34:02.437831 2026] [security2:error] [pid 751901:tid 752040] [client 114.119.136.138:46687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/docs/5cfb7b-portsmouth-kit-20/5cfb7b-where-was-david-stirling-born"] [unique_id "amuLCirT982lovRn7gnZDAAAAAk"], referer: https://arabiandubaisafari.com/docs/5cfb7b-portsmouth-kit-20/5cfb7b-where-was-david-stirling-born
[Thu Jul 30 12:34:03.668131 2026] [security2:error] [pid 751901:tid 752130] [client 20.215.191.139:58939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/03a005685d.php"] [unique_id "amuLCyrT982lovRn7gnZLAAAAGM"]
[Thu Jul 30 12:34:03.804836 2026] [core:notice] [pid 751901:tid 752124] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:04.051291 2026] [core:error] [pid 751901:tid 752041] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.051318 2026] [core:error] [pid 751901:tid 752041] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.078649 2026] [core:error] [pid 751901:tid 752144] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.078675 2026] [core:error] [pid 751901:tid 752144] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.080370 2026] [core:error] [pid 751901:tid 752136] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.080390 2026] [core:error] [pid 751901:tid 752136] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:04.497669 2026] [security2:error] [pid 751901:tid 752075] [client 20.215.191.139:58936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/403.php"] [unique_id "amuLDCrT982lovRn7gnZVQAAACw"]
[Thu Jul 30 12:34:04.924302 2026] [security2:error] [pid 751901:tid 752126] [client 119.73.97.132:30603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLDCrT982lovRn7gnZXQAAXys"]
[Thu Jul 30 12:34:04.935744 2026] [security2:error] [pid 751901:tid 752126] [client 119.73.97.132:30603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLDCrT982lovRn7gnZXgAAXyM"]
[Thu Jul 30 12:34:05.573322 2026] [core:notice] [pid 751901:tid 752157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:05.577342 2026] [security2:error] [pid 751901:tid 752157] [client 103.215.74.26:41284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLDSrT982lovRn7gnZdAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:05.808629 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00493: SIGUSR1 received.  Doing graceful restart
[Thu Jul 30 12:34:06.093501 2026] [security2:error] [pid 751901:tid 752049] [client 20.63.98.115:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/php8.php"] [unique_id "amuLDirT982lovRn7gnZeQAAABI"]
[Thu Jul 30 12:34:06.893540 2026] [:notice] [pid 751894:tid 751894] [host root@sh00085.hostgator.com] mod_lsapi:  Selfstarter 751894 stopped
[Thu Jul 30 12:34:09.254541 2026] [lsapi:notice] [pid 8929:tid 8929] mod_lsapi:  version 1.1-92
[Thu Jul 30 12:34:09.257965 2026] [:notice] [pid 765150:tid 765150] [host root@sh00085.hostgator.com] mod_lsapi:  Selfstarter 765150 started
[Thu Jul 30 12:34:09.639517 2026] [ssl:warn] [pid 8929:tid 8929] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Thu Jul 30 12:34:09.646791 2026] [qos:notice] [pid 8929:tid 8929] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Thu Jul 30 12:34:09.817305 2026] [http2:info] [pid 8929:tid 8929] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Thu Jul 30 12:34:09.820631 2026] [mpm_event:notice] [pid 8929:tid 8929] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Thu Jul 30 12:34:09.820658 2026] [core:notice] [pid 8929:tid 8929] AH00094: Command line: '/usr/sbin/httpd'
[Thu Jul 30 12:34:10.865952 2026] [http2:info] [pid 765155:tid 765155] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:34:11.115343 2026] [security2:error] [pid 765155:tid 765292] [client 114.119.150.252:63021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabian-tours.com"] [uri "/site/mercedes-a-class-2020-56216b"] [unique_id "amuLE-T5hFAbD-LhWHh5hwAAAIw"], referer: https://arabian-tours.com/site/wli-waterfalls-56216b
[Thu Jul 30 12:34:11.130329 2026] [security2:error] [pid 765155:tid 765164] [remote 57.141.0.36:37218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuLE-T5hFAbD-LhWHh5jAAAlwg"]
[Thu Jul 30 12:34:11.133582 2026] [security2:error] [pid 765155:tid 765165] [remote 57.141.0.3:27846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuLE-T5hFAbD-LhWHh5igAAmwk"]
[Thu Jul 30 12:34:11.133754 2026] [core:notice] [pid 765155:tid 765288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:11.146363 2026] [security2:error] [pid 765155:tid 765288] [client 103.215.74.26:41300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLE-T5hFAbD-LhWHh5jwAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:11.342449 2026] [security2:error] [pid 765155:tid 765290] [client 20.215.191.139:56991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/404.php"] [unique_id "amuLE-T5hFAbD-LhWHh5ogAAAIo"]
[Thu Jul 30 12:34:11.501635 2026] [security2:error] [pid 765155:tid 765311] [client 38.190.144.4:57079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLE-T5hFAbD-LhWHh5qgAAAJ8"]
[Thu Jul 30 12:34:11.501848 2026] [security2:error] [pid 765155:tid 765311] [client 38.190.144.4:57079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLE-T5hFAbD-LhWHh5qgAAAJ8"]
[Thu Jul 30 12:34:11.542289 2026] [security2:error] [pid 765155:tid 765296] [client 119.73.97.132:30657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5ggAAkAI"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:11.845028 2026] [log_config:warn] [pid 751901:tid 752055] (32)Broken pipe: [client 52.4.19.39:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:11.845054 2026] [log_config:warn] [pid 751901:tid 752055] (32)Broken pipe: [client 52.4.19.39:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:11.845675 2026] [log_config:warn] [pid 751901:tid 752093] (32)Broken pipe: [client 127.0.0.1:33678] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:11.845697 2026] [log_config:warn] [pid 751901:tid 752093] (32)Broken pipe: [client 127.0.0.1:33678] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:11.846024 2026] [log_config:warn] [pid 751901:tid 752137] (32)Broken pipe: [client 52.4.19.39:26859] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:11.846043 2026] [log_config:warn] [pid 751901:tid 752137] (32)Broken pipe: [client 52.4.19.39:26859] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:11.876331 2026] [core:notice] [pid 765155:tid 765391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:11.884467 2026] [security2:error] [pid 765155:tid 765391] [client 103.215.74.26:41314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLE-T5hFAbD-LhWHh5vAAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:11.960364 2026] [security2:error] [pid 765155:tid 765357] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5mgAAAM0"]
[Thu Jul 30 12:34:11.981146 2026] [log_config:warn] [pid 751901:tid 752149] (32)Broken pipe: [client 44.213.206.96:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:11.981169 2026] [log_config:warn] [pid 751901:tid 752149] (32)Broken pipe: [client 44.213.206.96:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:11.996205 2026] [security2:error] [pid 765155:tid 765404] [client 20.215.191.139:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/aa.php"] [unique_id "amuLE-T5hFAbD-LhWHh5vgAAAPw"]
[Thu Jul 30 12:34:12.013366 2026] [log_config:warn] [pid 751901:tid 752098] (32)Broken pipe: [client 127.0.0.1:33694] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:12.013390 2026] [log_config:warn] [pid 751901:tid 752098] (32)Broken pipe: [client 127.0.0.1:33694] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:12.048247 2026] [security2:error] [pid 765155:tid 765339] [client 114.119.156.165:63545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/4/"] [unique_id "amuLFOT5hFAbD-LhWHh5vwAAALs"], referer: https://kicksity.com/shop/?min_price=140&max_price=280&filtering=1&filter_product_cat=166%2C210%2C192%2C236%2C137%2C146
[Thu Jul 30 12:34:12.340263 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 44.213.206.96:41876] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log
[Thu Jul 30 12:34:12.340293 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 44.213.206.96:41876] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log
[Thu Jul 30 12:34:12.398538 2026] [security2:error] [pid 765155:tid 765298] [client 172.237.109.114:37443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5cgAAAJI"]
[Thu Jul 30 12:34:12.416946 2026] [security2:error] [pid 765155:tid 765312] [client 172.237.109.114:17228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5dQAAAKA"]
[Thu Jul 30 12:34:12.448557 2026] [security2:error] [pid 765155:tid 765304] [client 172.237.109.114:42931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLEuT5hFAbD-LhWHh5cAAAAJg"]
[Thu Jul 30 12:34:12.459939 2026] [security2:error] [pid 765155:tid 765322] [client 172.237.109.114:36859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5egAAAKo"]
[Thu Jul 30 12:34:12.524113 2026] [security2:error] [pid 765155:tid 765308] [client 172.237.109.114:60661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5cQAAAJw"]
[Thu Jul 30 12:34:12.602020 2026] [security2:error] [pid 765155:tid 765315] [client 172.237.109.114:2955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5eQAAAKM"]
[Thu Jul 30 12:34:12.609175 2026] [core:notice] [pid 765155:tid 765294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:12.612575 2026] [security2:error] [pid 765155:tid 765320] [client 172.237.109.114:59971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5cwAAAKg"]
[Thu Jul 30 12:34:12.612812 2026] [security2:error] [pid 765155:tid 765323] [client 172.237.109.114:19417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5ewAAAKs"]
[Thu Jul 30 12:34:12.618939 2026] [security2:error] [pid 765155:tid 765294] [client 103.215.74.26:41324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLFOT5hFAbD-LhWHh5zQAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:12.659090 2026] [security2:error] [pid 765155:tid 765306] [client 172.237.109.114:48409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLEuT5hFAbD-LhWHh5bwAAAJo"]
[Thu Jul 30 12:34:12.673681 2026] [security2:error] [pid 765155:tid 765329] [client 172.237.109.114:58263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5fgAAALE"]
[Thu Jul 30 12:34:12.682748 2026] [security2:error] [pid 765155:tid 765302] [client 172.237.109.114:58604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLEuT5hFAbD-LhWHh5bgAAAJY"]
[Thu Jul 30 12:34:12.683947 2026] [security2:error] [pid 765155:tid 765316] [client 172.237.109.114:56570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5eAAAAKQ"]
[Thu Jul 30 12:34:12.737102 2026] [security2:error] [pid 765155:tid 765351] [client 14.116.236.91:18907] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/static/favicon.ico"] [unique_id "amuLFOT5hFAbD-LhWHh51QAAAMc"]
[Thu Jul 30 12:34:12.796439 2026] [security2:error] [pid 765155:tid 765354] [client 20.215.191.139:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/aafewc0k.php"] [unique_id "amuLFOT5hFAbD-LhWHh52AAAAMo"]
[Thu Jul 30 12:34:13.088232 2026] [security2:error] [pid 765155:tid 765392] [client 14.116.236.91:35617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/icon/favicon.ico"] [unique_id "amuLFeT5hFAbD-LhWHh53AAAAPA"]
[Thu Jul 30 12:34:13.091227 2026] [security2:error] [pid 765155:tid 765401] [client 14.116.236.91:58139] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/img/favicon.ico"] [unique_id "amuLFeT5hFAbD-LhWHh53QAAAPk"]
[Thu Jul 30 12:34:13.092963 2026] [security2:error] [pid 765155:tid 765406] [client 14.116.236.91:35615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/favicon.ico"] [unique_id "amuLFeT5hFAbD-LhWHh53gAAAP4"]
[Thu Jul 30 12:34:13.093759 2026] [security2:error] [pid 765155:tid 765398] [client 14.116.236.91:58138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/favicon.png"] [unique_id "amuLFeT5hFAbD-LhWHh53wAAAPY"]
[Thu Jul 30 12:34:13.117949 2026] [security2:error] [pid 765155:tid 765407] [client 14.116.236.91:13472] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/images/favicon.ico"] [unique_id "amuLFeT5hFAbD-LhWHh54AAAAP8"]
[Thu Jul 30 12:34:13.242439 2026] [security2:error] [pid 765155:tid 765321] [client 172.237.109.114:25290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5dgAAAKk"]
[Thu Jul 30 12:34:13.243055 2026] [security2:error] [pid 765155:tid 765314] [client 172.237.109.114:5514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5dwAAAKI"]
[Thu Jul 30 12:34:13.248286 2026] [security2:error] [pid 765155:tid 765336] [client 172.237.109.114:55148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5iAAAALg"]
[Thu Jul 30 12:34:13.250446 2026] [security2:error] [pid 765155:tid 765317] [client 172.237.109.114:40842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5fAAAAKU"]
[Thu Jul 30 12:34:13.281542 2026] [security2:error] [pid 765155:tid 765310] [client 172.237.109.114:22794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5dAAAAJ4"]
[Thu Jul 30 12:34:13.306629 2026] [security2:error] [pid 765155:tid 765333] [client 172.237.109.114:38839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5gwAAALU"]
[Thu Jul 30 12:34:13.338230 2026] [core:notice] [pid 765155:tid 765408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:13.340131 2026] [security2:error] [pid 765155:tid 765300] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5mwAAlAs"]
[Thu Jul 30 12:34:13.346785 2026] [security2:error] [pid 765155:tid 765408] [client 103.215.74.26:18598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLFeT5hFAbD-LhWHh56gAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:13.375490 2026] [security2:error] [pid 765155:tid 765332] [client 172.237.109.114:22079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5gAAAALQ"]
[Thu Jul 30 12:34:13.384108 2026] [security2:error] [pid 765155:tid 765330] [client 172.237.109.114:1410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5fwAAALI"]
[Thu Jul 30 12:34:13.500107 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:13.500953 2026] [security2:error] [pid 765155:tid 765353] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLE-T5hFAbD-LhWHh5qwAAyQ4"]
[Thu Jul 30 12:34:13.736957 2026] [security2:error] [pid 765155:tid 765345] [client 20.215.191.139:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/abcd.php"] [unique_id "amuLFeT5hFAbD-LhWHh59QAAAME"]
[Thu Jul 30 12:34:13.778048 2026] [security2:error] [pid 765155:tid 765326] [client 77.54.86.207:42294] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuLFeT5hFAbD-LhWHh5-QAAAK4"]
[Thu Jul 30 12:34:13.838842 2026] [security2:error] [pid 765155:tid 765325] [client 77.183.60.157:52966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuLFeT5hFAbD-LhWHh5-gAAAK0"]
[Thu Jul 30 12:34:13.839815 2026] [security2:error] [pid 765155:tid 765331] [client 43.173.182.51:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/11/22/a-ne-pas-manquer-ce-week-end-le-salon-creations-savoir-faire-marie-claire-idees/"] [unique_id "amuLFeT5hFAbD-LhWHh57AAAALM"]
[Thu Jul 30 12:34:13.918319 2026] [security2:error] [pid 765155:tid 765295] [client 86.183.74.14:36748] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuLFeT5hFAbD-LhWHh5-wAAAI8"]
[Thu Jul 30 12:34:13.953141 2026] [core:error] [pid 765155:tid 765379] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:13.953165 2026] [core:error] [pid 765155:tid 765379] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:13.955434 2026] [core:error] [pid 765155:tid 765297] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:13.955456 2026] [core:error] [pid 765155:tid 765297] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:14.029934 2026] [core:error] [pid 765155:tid 765389] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:14.029962 2026] [core:error] [pid 765155:tid 765389] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:14.056738 2026] [security2:error] [pid 765155:tid 765304] [client 49.230.178.14:5826] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLFuT5hFAbD-LhWHh6DgAAAJg"]
[Thu Jul 30 12:34:14.060186 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:14.065324 2026] [security2:error] [pid 765155:tid 765377] [client 103.215.74.26:18608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLFuT5hFAbD-LhWHh6DwAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:14.148079 2026] [security2:error] [pid 765155:tid 765393] [client 14.116.236.91:35616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/assets/favicon.ico"] [unique_id "amuLFuT5hFAbD-LhWHh6EQAAAPE"]
[Thu Jul 30 12:34:14.260141 2026] [security2:error] [pid 765155:tid 765344] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLFeT5hFAbD-LhWHh57wAAAMA"]
[Thu Jul 30 12:34:14.402783 2026] [security2:error] [pid 765155:tid 765359] [client 99.232.160.131:50866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLFuT5hFAbD-LhWHh6HAAAAM8"]
[Thu Jul 30 12:34:14.488380 2026] [security2:error] [pid 765155:tid 765299] [client 20.63.98.115:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/tes.php"] [unique_id "amuLFuT5hFAbD-LhWHh6IAAAAJM"]
[Thu Jul 30 12:34:14.527799 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:14.533668 2026] [security2:error] [pid 765155:tid 765328] [client 43.173.182.74:59750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/11/22/a-ne-pas-manquer-ce-week-end-le-salon-creations-savoir-faire-marie-claire-idees/"] [unique_id "amuLFuT5hFAbD-LhWHh6IQAAALA"], referer: https://carnetdeshopping.com/index.php/2012/11/22/a-ne-pas-manquer-ce-week-end-le-salon-creations-savoir-faire-marie-claire-idees/
[Thu Jul 30 12:34:14.636970 2026] [security2:error] [pid 765155:tid 765367] [client 93.45.55.61:33994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLFuT5hFAbD-LhWHh6JAAAANc"]
[Thu Jul 30 12:34:14.758410 2026] [security2:error] [pid 765155:tid 765383] [client 85.86.218.110:3038] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuLFuT5hFAbD-LhWHh6KgAAAOc"]
[Thu Jul 30 12:34:14.804035 2026] [core:notice] [pid 765155:tid 765327] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:14.809177 2026] [security2:error] [pid 765155:tid 765327] [client 103.215.74.26:18620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLFuT5hFAbD-LhWHh6LgAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:14.943780 2026] [security2:error] [pid 765155:tid 765293] [client 82.39.7.236:53208] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLFuT5hFAbD-LhWHh6MgAAAI0"]
[Thu Jul 30 12:34:15.068347 2026] [security2:error] [pid 765155:tid 765330] [client 90.195.134.120:56748] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuLF-T5hFAbD-LhWHh6MwAAALI"]
[Thu Jul 30 12:34:15.153236 2026] [security2:error] [pid 765155:tid 765302] [client 114.119.128.5:39751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/careers"] [unique_id "amuLF-T5hFAbD-LhWHh6NQAAAJY"], referer: https://pkf.jo/careers?id=6023&ltid=4
[Thu Jul 30 12:34:15.246814 2026] [proxy:error] [pid 765155:tid 765287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:15.247032 2026] [proxy_http:error] [pid 765155:tid 765287] [client 52.4.19.39:57687] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:15.247601 2026] [proxy:error] [pid 765155:tid 765287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:15.247644 2026] [proxy_http:error] [pid 765155:tid 765287] [client 52.4.19.39:57687] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:15.294719 2026] [proxy:error] [pid 765155:tid 765296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:15.294792 2026] [proxy_http:error] [pid 765155:tid 765296] [client 3.225.222.228:55949] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:15.295558 2026] [proxy:error] [pid 765155:tid 765296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:15.295610 2026] [proxy_http:error] [pid 765155:tid 765296] [client 3.225.222.228:55949] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:15.471304 2026] [security2:error] [pid 765155:tid 765325] [client 88.182.238.108:22763] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLF-T5hFAbD-LhWHh6QQAAAK0"]
[Thu Jul 30 12:34:15.545338 2026] [core:notice] [pid 765155:tid 765384] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:15.553353 2026] [security2:error] [pid 765155:tid 765384] [client 103.215.74.26:18630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLF-T5hFAbD-LhWHh6RAAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:15.631965 2026] [security2:error] [pid 765155:tid 765373] [client 46.189.233.91:56768] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuLF-T5hFAbD-LhWHh6RQAAAN0"]
[Thu Jul 30 12:34:15.698266 2026] [security2:error] [pid 765155:tid 765311] [client 77.54.239.38:38500] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLF-T5hFAbD-LhWHh6RgAAAJ8"]
[Thu Jul 30 12:34:15.871478 2026] [security2:error] [pid 765155:tid 765306] [client 71.17.135.58:37210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLF-T5hFAbD-LhWHh6TgAAAJo"]
[Thu Jul 30 12:34:16.077685 2026] [security2:error] [pid 765155:tid 765297] [client 86.52.147.166:29823] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLGOT5hFAbD-LhWHh6VQAAAJE"]
[Thu Jul 30 12:34:16.161133 2026] [security2:error] [pid 765155:tid 765400] [client 178.121.27.193:5006] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLGOT5hFAbD-LhWHh6WAAAAPg"]
[Thu Jul 30 12:34:16.285572 2026] [security2:error] [pid 765155:tid 765403] [client 159.0.44.24:36882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuLGOT5hFAbD-LhWHh6XQAAAPs"]
[Thu Jul 30 12:34:16.289781 2026] [core:notice] [pid 765155:tid 765349] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:16.296393 2026] [security2:error] [pid 765155:tid 765349] [client 103.215.74.26:18634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLGOT5hFAbD-LhWHh6XgAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:16.513488 2026] [security2:error] [pid 765155:tid 765397] [client 156.206.158.45:46408] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuLGOT5hFAbD-LhWHh6bAAAAPU"]
[Thu Jul 30 12:34:16.644520 2026] [security2:error] [pid 765155:tid 765398] [client 105.165.10.218:41688] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuLGOT5hFAbD-LhWHh6cAAAAPY"]
[Thu Jul 30 12:34:16.703616 2026] [security2:error] [pid 765155:tid 765328] [client 103.26.86.38:61414] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLGOT5hFAbD-LhWHh6cgAAALA"]
[Thu Jul 30 12:34:16.873574 2026] [security2:error] [pid 765155:tid 765291] [client 203.145.36.214:54980] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuLGOT5hFAbD-LhWHh6eQAAAIs"]
[Thu Jul 30 12:34:16.987778 2026] [security2:error] [pid 765155:tid 765391] [client 177.162.106.40:42904] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLGOT5hFAbD-LhWHh6gQAAAO8"]
[Thu Jul 30 12:34:17.028827 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:17.033774 2026] [security2:error] [pid 765155:tid 765332] [client 103.215.74.26:18648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLGeT5hFAbD-LhWHh6gwAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:17.064593 2026] [security2:error] [pid 765155:tid 765392] [client 169.224.1.197:15382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLGeT5hFAbD-LhWHh6hAAAAPA"]
[Thu Jul 30 12:34:17.158036 2026] [security2:error] [pid 765155:tid 765402] [client 213.230.87.113:10791] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLGeT5hFAbD-LhWHh6hQAAAPo"]
[Thu Jul 30 12:34:17.173331 2026] [security2:error] [pid 765155:tid 765288] [client 200.141.34.83:35032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLGeT5hFAbD-LhWHh6hgAAAIg"]
[Thu Jul 30 12:34:17.346219 2026] [security2:error] [pid 765155:tid 765303] [client 193.47.62.167:41648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuLGOT5hFAbD-LhWHh6VwAAAJc"]
[Thu Jul 30 12:34:17.419525 2026] [security2:error] [pid 765155:tid 765362] [client 138.121.3.240:35895] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuLGeT5hFAbD-LhWHh6jwAAANI"]
[Thu Jul 30 12:34:17.464528 2026] [security2:error] [pid 765155:tid 765318] [client 88.241.178.129:37476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLGeT5hFAbD-LhWHh6kwAAAKY"]
[Thu Jul 30 12:34:17.724539 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 119.73.97.132:30603] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log, referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:17.724561 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 119.73.97.132:30603] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log, referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:17.786341 2026] [core:notice] [pid 765155:tid 765358] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:17.793556 2026] [security2:error] [pid 765155:tid 765358] [client 103.215.74.26:18652] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLGeT5hFAbD-LhWHh6lQAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:17.841931 2026] [core:error] [pid 765155:tid 765389] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:17.841952 2026] [core:error] [pid 765155:tid 765389] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:17.961384 2026] [security2:error] [pid 765155:tid 765360] [client 201.141.29.93:34442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuLGeT5hFAbD-LhWHh6nQAAANA"]
[Thu Jul 30 12:34:17.982282 2026] [security2:error] [pid 765155:tid 765229] [remote 40.77.167.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/view/107/105"] [unique_id "amuLGeT5hFAbD-LhWHh6ogAAsUk"]
[Thu Jul 30 12:34:18.021194 2026] [security2:error] [pid 765155:tid 765336] [client 31.206.13.16:54368] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuLGuT5hFAbD-LhWHh6pQAAALg"]
[Thu Jul 30 12:34:18.088581 2026] [security2:error] [pid 765155:tid 765405] [client 20.215.191.139:50199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/about.php"] [unique_id "amuLGuT5hFAbD-LhWHh6pwAAAP0"]
[Thu Jul 30 12:34:18.525274 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:18.533037 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:18658] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLGuT5hFAbD-LhWHh6tQAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:18.895193 2026] [security2:error] [pid 765155:tid 765347] [client 216.234.209.67:40379] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuLGuT5hFAbD-LhWHh6wAAAAMM"]
[Thu Jul 30 12:34:19.248118 2026] [core:notice] [pid 765155:tid 765366] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:19.252386 2026] [security2:error] [pid 765155:tid 765366] [client 103.215.74.26:18660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLG-T5hFAbD-LhWHh6ywAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:19.890316 2026] [security2:error] [pid 765155:tid 765324] [client 188.253.218.64:15811] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuLG-T5hFAbD-LhWHh66QAAAKw"]
[Thu Jul 30 12:34:20.146563 2026] [security2:error] [pid 765155:tid 765402] [client 20.215.191.139:59086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/admin.php"] [unique_id "amuLHOT5hFAbD-LhWHh69gAAAPo"]
[Thu Jul 30 12:34:20.412260 2026] [security2:error] [pid 765155:tid 765303] [client 130.193.252.121:34618] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuLHOT5hFAbD-LhWHh6-QAAAJc"]
[Thu Jul 30 12:34:20.431834 2026] [security2:error] [pid 765155:tid 765405] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLG-T5hFAbD-LhWHh66AAAAP0"]
[Thu Jul 30 12:34:20.712099 2026] [security2:error] [pid 765155:tid 765401] [client 88.224.16.100:43458] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuLHOT5hFAbD-LhWHh7BAAAAPk"]
[Thu Jul 30 12:34:20.844689 2026] [security2:error] [pid 765155:tid 765407] [client 20.215.191.139:50179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/adminfuns.php"] [unique_id "amuLHOT5hFAbD-LhWHh7BgAAAP8"]
[Thu Jul 30 12:34:21.221007 2026] [security2:error] [pid 765155:tid 765378] [client 20.63.98.115:57239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/about.php"] [unique_id "amuLHeT5hFAbD-LhWHh7DgAAAOI"]
[Thu Jul 30 12:34:21.423704 2026] [security2:error] [pid 765155:tid 765290] [client 114.119.135.199:35539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product-tag/marlboro%E8%90%AC%E5%AF%B6%E8%B7%AF%E9%A6%99%E7%85%99%E4%B8%AD%E7%B4%94%E7%B4%85%E8%90%AC%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/"] [unique_id "amuLHeT5hFAbD-LhWHh7GgAAAIo"], referer: https://online-hope.com/product-tag/marlboro%E8%90%AC%E5%AF%B6%E8%B7%AF%E9%A6%99%E7%85%99%E4%B8%AD%E7%B4%94%E7%B4%85%E8%90%AC%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/
[Thu Jul 30 12:34:21.624902 2026] [security2:error] [pid 765155:tid 765272] [remote 57.141.0.1:40806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuLHeT5hFAbD-LhWHh7EgAA53Q"]
[Thu Jul 30 12:34:21.805612 2026] [core:notice] [pid 765155:tid 765355] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:22.096371 2026] [security2:error] [pid 765155:tid 765320] [client 20.215.191.139:59076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/albin.php"] [unique_id "amuLHuT5hFAbD-LhWHh7JQAAAKg"]
[Thu Jul 30 12:34:22.156323 2026] [security2:error] [pid 765155:tid 765304] [client 20.63.98.115:63471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/headers.php"] [unique_id "amuLHuT5hFAbD-LhWHh7JgAAAJg"]
[Thu Jul 30 12:34:23.303666 2026] [security2:error] [pid 765155:tid 765359] [client 20.215.191.139:50184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/amfsqvgv.php"] [unique_id "amuLH-T5hFAbD-LhWHh7RQAAAM8"]
[Thu Jul 30 12:34:23.425241 2026] [security2:error] [pid 765155:tid 765354] [client 82.132.233.218:23292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuLH-T5hFAbD-LhWHh7SAAAAMo"]
[Thu Jul 30 12:34:23.437745 2026] [security2:error] [pid 765155:tid 765410] [client 114.119.128.5:41775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/hz/reviews-render/report-review"] [unique_id "amuLH-T5hFAbD-LhWHh7SQAAAQI"], referer: http://www.bedandbreakfast-skye.com/
[Thu Jul 30 12:34:23.468167 2026] [core:error] [pid 765155:tid 765160] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.468188 2026] [core:error] [pid 765155:tid 765160] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.505545 2026] [core:error] [pid 765155:tid 765164] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.505563 2026] [core:error] [pid 765155:tid 765164] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.561867 2026] [core:error] [pid 765155:tid 765171] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.561887 2026] [core:error] [pid 765155:tid 765171] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.568090 2026] [core:error] [pid 765155:tid 765174] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.568110 2026] [core:error] [pid 765155:tid 765174] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.620655 2026] [core:error] [pid 765155:tid 765172] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.620681 2026] [core:error] [pid 765155:tid 765172] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.664293 2026] [core:error] [pid 765155:tid 765175] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:23.664326 2026] [core:error] [pid 765155:tid 765175] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:24.092960 2026] [security2:error] [pid 765155:tid 765340] [client 20.215.191.139:59089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/ant.php"] [unique_id "amuLIOT5hFAbD-LhWHh7XwAAALw"]
[Thu Jul 30 12:34:24.872726 2026] [security2:error] [pid 765155:tid 765373] [client 107.170.60.13:33548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.vertexroofsolutions.com"] [uri "/.env"] [unique_id "amuLIOT5hFAbD-LhWHh7cQAAAN0"]
[Thu Jul 30 12:34:24.961293 2026] [core:notice] [pid 765155:tid 765344] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:24.965697 2026] [security2:error] [pid 765155:tid 765344] [client 103.215.74.26:7176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "772"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLIOT5hFAbD-LhWHh7dgAAAMA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:25.331802 2026] [security2:error] [pid 765155:tid 765301] [client 20.63.98.115:20923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/admin.php"] [unique_id "amuLIeT5hFAbD-LhWHh7fQAAAJU"]
[Thu Jul 30 12:34:25.685361 2026] [core:notice] [pid 765155:tid 765285] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:25.693065 2026] [security2:error] [pid 765155:tid 765285] [client 103.215.74.26:7180] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLIeT5hFAbD-LhWHh7gwAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:25.832239 2026] [security2:error] [pid 765155:tid 765377] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLIeT5hFAbD-LhWHh7fAAAAOE"]
[Thu Jul 30 12:34:26.265418 2026] [security2:error] [pid 765155:tid 765375] [client 20.215.191.139:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/appreciators.php"] [unique_id "amuLIuT5hFAbD-LhWHh7jQAAAN8"]
[Thu Jul 30 12:34:26.420476 2026] [core:notice] [pid 765155:tid 765323] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:26.425458 2026] [security2:error] [pid 765155:tid 765323] [client 103.215.74.26:7188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "785"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLIuT5hFAbD-LhWHh7lAAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:26.960385 2026] [security2:error] [pid 765155:tid 765319] [client 20.215.191.139:50198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/archive.php"] [unique_id "amuLIuT5hFAbD-LhWHh7qAAAAKc"]
[Thu Jul 30 12:34:27.164018 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:27.168909 2026] [security2:error] [pid 765155:tid 765336] [client 103.215.74.26:7194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLI-T5hFAbD-LhWHh7sAAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:28.170707 2026] [security2:error] [pid 765155:tid 765402] [client 20.215.191.139:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/as.php"] [unique_id "amuLJOT5hFAbD-LhWHh7yAAAAPo"]
[Thu Jul 30 12:34:28.461454 2026] [security2:error] [pid 765155:tid 765353] [client 20.63.98.115:20881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/flower.php"] [unique_id "amuLJOT5hFAbD-LhWHh70QAAAMk"]
[Thu Jul 30 12:34:28.787773 2026] [security2:error] [pid 765155:tid 765352] [client 20.215.191.139:59116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/atomlib.php"] [unique_id "amuLJOT5hFAbD-LhWHh73AAAAMg"]
[Thu Jul 30 12:34:29.311732 2026] [security2:error] [pid 765155:tid 765336] [client 20.63.98.115:20904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuLJeT5hFAbD-LhWHh73gAAALg"]
[Thu Jul 30 12:34:30.025538 2026] [core:notice] [pid 765155:tid 765225] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:30.254032 2026] [security2:error] [pid 765155:tid 765223] [remote 14.116.236.91:55064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/static/favicon.ico"] [unique_id "amuLJuT5hFAbD-LhWHh79gAAoUM"]
[Thu Jul 30 12:34:30.254128 2026] [security2:error] [pid 765155:tid 765228] [remote 14.116.236.91:55064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/favicon.png"] [unique_id "amuLJuT5hFAbD-LhWHh79QAAoUg"]
[Thu Jul 30 12:34:30.682721 2026] [security2:error] [pid 765155:tid 765296] [client 20.63.98.115:20917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content.php"] [unique_id "amuLJuT5hFAbD-LhWHh8KgAAAJA"]
[Thu Jul 30 12:34:30.697560 2026] [security2:error] [pid 765155:tid 765277] [remote 114.119.147.137:53307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dhowcruisedinner.com"] [uri "/JbcYdA/where-is-fox-sports-undisputed-filmed"] [unique_id "amuLJuT5hFAbD-LhWHh8KwAAmnk"]
[Thu Jul 30 12:34:30.729413 2026] [fcgid:warn] [pid 765155:tid 765400] (70014)End of file found: [client 152.32.142.138:33464] mod_fcgid: can't get data from http client
[Thu Jul 30 12:34:32.632627 2026] [security2:error] [pid 765155:tid 765371] [client 38.190.144.4:58275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLKOT5hFAbD-LhWHh8XAAAANs"]
[Thu Jul 30 12:34:32.633182 2026] [security2:error] [pid 765155:tid 765371] [client 38.190.144.4:58275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLKOT5hFAbD-LhWHh8XAAAANs"]
[Thu Jul 30 12:34:32.939800 2026] [core:notice] [pid 765155:tid 765389] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:32.944834 2026] [security2:error] [pid 765155:tid 765389] [client 103.215.74.26:7204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLKOT5hFAbD-LhWHh8YwAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:32.955639 2026] [security2:error] [pid 765155:tid 765306] [client 114.119.149.65:58219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/helicopters/"] [unique_id "amuLKOT5hFAbD-LhWHh8ZAAAAJo"], referer: https://fireworkskenya.co.ke/our-products/consumer-fireworks/helicopters/
[Thu Jul 30 12:34:33.167823 2026] [autoindex:error] [pid 765155:tid 765356] [client 49.51.180.2:34764] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:34:33.676014 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:33.681147 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:33898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLKeT5hFAbD-LhWHh8cwAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:34.180535 2026] [core:error] [pid 765155:tid 765382] [client 74.7.244.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:34.180557 2026] [core:error] [pid 765155:tid 765382] [client 74.7.244.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:34:34.180678 2026] [security2:error] [pid 765155:tid 765382] [client 74.7.244.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.brx.dtn.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuLKuT5hFAbD-LhWHh8fwAAAOY"]
[Thu Jul 30 12:34:34.181224 2026] [security2:error] [pid 765155:tid 765398] [client 74.7.244.62:51902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.brx.dtn.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuLKuT5hFAbD-LhWHh8fQAA9gY"]
[Thu Jul 30 12:34:34.419711 2026] [core:notice] [pid 765155:tid 765331] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:34.424246 2026] [security2:error] [pid 765155:tid 765331] [client 103.215.74.26:33900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLKuT5hFAbD-LhWHh8hQAAALM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:34.939562 2026] [lsapi:error] [pid 751901:tid 751993] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:34:34.941045 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 41.210.167.242:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:34:34.941061 2026] [log_config:warn] [pid 751901:tid 752058] (32)Broken pipe: [client 41.210.167.242:0] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:34:35.144780 2026] [core:notice] [pid 765155:tid 765371] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:35.149877 2026] [security2:error] [pid 765155:tid 765371] [client 103.215.74.26:33916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLK-T5hFAbD-LhWHh8mwAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:35.271956 2026] [security2:error] [pid 765155:tid 765378] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-26e591d8.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuLKuT5hFAbD-LhWHh8kwAAAOI"]
[Thu Jul 30 12:34:35.272653 2026] [security2:error] [pid 765155:tid 765367] [client 74.7.228.15:37978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-26e591d8.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuLKuT5hFAbD-LhWHh8kQAA1wc"]
[Thu Jul 30 12:34:35.400995 2026] [security2:error] [pid 765155:tid 765390] [client 20.215.191.139:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/autoload_classmap.php"] [unique_id "amuLK-T5hFAbD-LhWHh8oAAAAO4"]
[Thu Jul 30 12:34:35.556759 2026] [log_config:warn] [pid 751901:tid 752155] (32)Broken pipe: [client 119.73.97.132:30603] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --suffix=-bytes_log, referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:35.556782 2026] [log_config:warn] [pid 751901:tid 752155] (32)Broken pipe: [client 119.73.97.132:30603] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=sh00085.hostgator.com --mainout=/etc/apache2/logs/access_log, referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:34:35.885520 2026] [core:notice] [pid 765155:tid 765364] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:35.890524 2026] [security2:error] [pid 765155:tid 765364] [client 103.215.74.26:33918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLK-T5hFAbD-LhWHh8qAAAANQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:36.487471 2026] [security2:error] [pid 765155:tid 765403] [client 20.215.191.139:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/bb.php"] [unique_id "amuLLOT5hFAbD-LhWHh8uAAAAPs"]
[Thu Jul 30 12:34:36.556631 2026] [core:notice] [pid 765155:tid 765381] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:36.602721 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:36.608175 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:33922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLLOT5hFAbD-LhWHh8vgAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:36.729834 2026] [core:notice] [pid 765155:tid 765195] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:37.031687 2026] [security2:error] [pid 765155:tid 765311] [client 114.119.145.102:41027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/leatherflower/darkmans1814402.html"] [unique_id "amuLLeT5hFAbD-LhWHh8yQAAAJ8"], referer: https://www.shorewooddaycare.com/leatherflower/darkmans1814402.html
[Thu Jul 30 12:34:37.192234 2026] [security2:error] [pid 765155:tid 765372] [client 20.215.191.139:49872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/bnm.php"] [unique_id "amuLLeT5hFAbD-LhWHh80AAAANw"]
[Thu Jul 30 12:34:37.208122 2026] [security2:error] [pid 765155:tid 765400] [client 114.119.150.65:52879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/wp-content/uploads/2025/04/%E4%B8%8B%E8%BD%BD_%E5%89%AF%E6%9C%AC.png"] [unique_id "amuLLeT5hFAbD-LhWHh80gAAAPg"], referer: https://lark-shop.com/product/peel/
[Thu Jul 30 12:34:37.333691 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:37.338358 2026] [security2:error] [pid 765155:tid 765359] [client 103.215.74.26:33938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLLeT5hFAbD-LhWHh80wAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:37.762611 2026] [security2:error] [pid 765155:tid 765294] [client 20.215.191.139:61770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/bootstrap.php"] [unique_id "amuLLeT5hFAbD-LhWHh83gAAAI4"]
[Thu Jul 30 12:34:38.051524 2026] [core:notice] [pid 765155:tid 765405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:38.055984 2026] [security2:error] [pid 765155:tid 765405] [client 103.215.74.26:33954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLLuT5hFAbD-LhWHh84wAAAP0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:38.297586 2026] [security2:error] [pid 765155:tid 765355] [client 20.63.98.115:47485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/function.php"] [unique_id "amuLLuT5hFAbD-LhWHh86gAAAMs"]
[Thu Jul 30 12:34:38.434333 2026] [security2:error] [pid 765155:tid 765402] [client 20.215.191.139:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/buy.php"] [unique_id "amuLLuT5hFAbD-LhWHh89gAAAPo"]
[Thu Jul 30 12:34:38.794079 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:38.800014 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:33956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLLuT5hFAbD-LhWHh9AgAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:39.518192 2026] [core:notice] [pid 765155:tid 765291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:39.523299 2026] [security2:error] [pid 765155:tid 765291] [client 103.215.74.26:33964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLL-T5hFAbD-LhWHh9EgAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:39.689643 2026] [security2:error] [pid 765155:tid 765409] [client 20.63.98.115:49974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/chosen.php"] [unique_id "amuLL-T5hFAbD-LhWHh9FgAAAQE"]
[Thu Jul 30 12:34:40.115032 2026] [security2:error] [pid 765155:tid 765236] [remote 57.141.0.68:60988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuLMOT5hFAbD-LhWHh9IAAA3VA"]
[Thu Jul 30 12:34:40.242886 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:40.248062 2026] [security2:error] [pid 765155:tid 765367] [client 103.215.74.26:33980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLMOT5hFAbD-LhWHh9JwAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:40.606113 2026] [proxy:error] [pid 765155:tid 765404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:40.606165 2026] [proxy_http:error] [pid 765155:tid 765404] [client 18.211.55.47:41427] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:40.606739 2026] [proxy:error] [pid 765155:tid 765404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:40.606781 2026] [proxy_http:error] [pid 765155:tid 765404] [client 18.211.55.47:41427] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:41.140209 2026] [security2:error] [pid 765155:tid 765352] [client 114.119.132.68:34221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cnpinyin.com"] [uri "/study/Chinese-grammar/%E5%8F%A5%2B"] [unique_id "amuLMeT5hFAbD-LhWHh9QQAAAMg"], referer: https://cnpinyin.com/wp-sitemap-posts-post-1.xml
[Thu Jul 30 12:34:42.185029 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:60838] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "svcambodia.com"] [uri "/1.php"] [unique_id "amuLMuT5hFAbD-LhWHh9ZAAAAKk"]
[Thu Jul 30 12:34:42.185160 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:60838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/1.php"] [unique_id "amuLMuT5hFAbD-LhWHh9ZAAAAKk"]
[Thu Jul 30 12:34:43.216795 2026] [security2:error] [pid 765155:tid 765401] [client 92.119.36.164:43213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guethleentertainment.com"] [uri "/"] [unique_id "amuLM-T5hFAbD-LhWHh9gwAAAPk"]
[Thu Jul 30 12:34:43.385344 2026] [security2:error] [pid 765155:tid 765290] [client 20.215.191.139:62512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/chosen.php"] [unique_id "amuLM-T5hFAbD-LhWHh9igAAAIo"]
[Thu Jul 30 12:34:43.499435 2026] [security2:error] [pid 765155:tid 765277] [remote 5.56.58.49:38724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.56.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuLM-T5hFAbD-LhWHh9iwAAqnk"]
[Thu Jul 30 12:34:43.581398 2026] [security2:error] [pid 765155:tid 765366] [client 20.63.98.115:47190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/lv.php"] [unique_id "amuLM-T5hFAbD-LhWHh9jwAAANY"]
[Thu Jul 30 12:34:43.983103 2026] [security2:error] [pid 765155:tid 765303] [client 38.190.144.4:58815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLM-T5hFAbD-LhWHh9pAAAAJc"]
[Thu Jul 30 12:34:43.983226 2026] [security2:error] [pid 765155:tid 765303] [client 38.190.144.4:58815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLM-T5hFAbD-LhWHh9pAAAAJc"]
[Thu Jul 30 12:34:44.128459 2026] [security2:error] [pid 765155:tid 765374] [client 20.215.191.139:49896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/class-wp-image.php"] [unique_id "amuLNOT5hFAbD-LhWHh9qQAAAN4"]
[Thu Jul 30 12:34:44.571227 2026] [security2:error] [pid 765155:tid 765406] [client 20.63.98.115:47260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/css.php"] [unique_id "amuLNOT5hFAbD-LhWHh9tAAAAP4"]
[Thu Jul 30 12:34:45.182296 2026] [security2:error] [pid 765155:tid 765288] [client 20.215.191.139:57253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/classsmtps.php"] [unique_id "amuLNeT5hFAbD-LhWHh9xgAAAIg"]
[Thu Jul 30 12:34:45.568820 2026] [proxy:error] [pid 765155:tid 765315] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:45.568897 2026] [proxy_http:error] [pid 765155:tid 765315] [client 44.216.125.112:61636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:45.569484 2026] [proxy:error] [pid 765155:tid 765315] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:45.569532 2026] [proxy_http:error] [pid 765155:tid 765315] [client 44.216.125.112:61636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:45.571669 2026] [security2:error] [pid 765155:tid 765382] [client 92.119.36.162:65185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guethleentertainment.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuLNeT5hFAbD-LhWHh90gAAAOY"]
[Thu Jul 30 12:34:45.579395 2026] [autoindex:error] [pid 765155:tid 765310] [client 34.233.129.35:16665] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:34:45.723281 2026] [security2:error] [pid 765155:tid 765319] [client 114.119.146.98:24647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/events/retreat-dates/eventsbyday/2026/5/15/-"] [unique_id "amuLNeT5hFAbD-LhWHh92gAAAKc"], referer: https://www.hmhs.ph/events/retreat-dates/monthcalendar/2026/5/-
[Thu Jul 30 12:34:45.970337 2026] [security2:error] [pid 765155:tid 765329] [client 104.254.90.251:56148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuLNeT5hFAbD-LhWHh95QAAALE"]
[Thu Jul 30 12:34:45.970431 2026] [security2:error] [pid 765155:tid 765329] [client 104.254.90.251:56148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuLNeT5hFAbD-LhWHh95QAAALE"]
[Thu Jul 30 12:34:45.985085 2026] [core:notice] [pid 765155:tid 765297] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:45.990356 2026] [security2:error] [pid 765155:tid 765297] [client 103.215.74.26:12730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLNeT5hFAbD-LhWHh95gAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:46.366528 2026] [security2:error] [pid 765155:tid 765357] [client 20.63.98.115:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gecko.php"] [unique_id "amuLNuT5hFAbD-LhWHh97AAAAM0"]
[Thu Jul 30 12:34:46.450365 2026] [security2:error] [pid 765155:tid 765373] [client 216.24.212.251:51351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guethleentertainment.com"] [uri "/media/system/js/core.js"] [unique_id "amuLNuT5hFAbD-LhWHh98AAAAN0"]
[Thu Jul 30 12:34:46.554788 2026] [core:notice] [pid 765155:tid 765285] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:46.722612 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:46.727943 2026] [security2:error] [pid 765155:tid 765367] [client 103.215.74.26:12744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLNuT5hFAbD-LhWHh9_AAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:47.075716 2026] [fcgid:warn] [pid 765155:tid 765375] (70014)End of file found: [client 156.232.100.95:60036] mod_fcgid: can't get data from http client
[Thu Jul 30 12:34:47.252631 2026] [security2:error] [pid 765155:tid 765401] [client 103.59.161.168:63884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.afropakmedical.com"] [uri "/"] [unique_id "amuLN-T5hFAbD-LhWHh-CwAAAPk"]
[Thu Jul 30 12:34:47.473382 2026] [core:notice] [pid 765155:tid 765402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:47.473999 2026] [security2:error] [pid 765155:tid 765335] [client 103.59.161.168:63912] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.afropakmedical.com"] [uri "/wp-json/batch/v1"] [unique_id "amuLN-T5hFAbD-LhWHh-DwAAALc"]
[Thu Jul 30 12:34:47.477868 2026] [security2:error] [pid 765155:tid 765402] [client 103.215.74.26:12752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLN-T5hFAbD-LhWHh-EAAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:47.881049 2026] [security2:error] [pid 765155:tid 765352] [client 20.63.98.115:47198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xmlrpc.php"] [unique_id "amuLN-T5hFAbD-LhWHh-JwAAAMg"]
[Thu Jul 30 12:34:48.091609 2026] [autoindex:error] [pid 765155:tid 765385] [client 32.194.121.99:52363] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:34:48.137950 2026] [autoindex:error] [pid 765155:tid 765358] [client 34.224.175.62:37774] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:34:48.216128 2026] [core:notice] [pid 765155:tid 765289] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:48.220435 2026] [security2:error] [pid 765155:tid 765289] [client 103.215.74.26:12768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLOOT5hFAbD-LhWHh-OAAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:48.465204 2026] [security2:error] [pid 765155:tid 765302] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLN-T5hFAbD-LhWHh-JgAAAJY"]
[Thu Jul 30 12:34:48.965900 2026] [core:notice] [pid 765155:tid 765333] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:48.970935 2026] [security2:error] [pid 765155:tid 765333] [client 103.215.74.26:12770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLOOT5hFAbD-LhWHh-ggAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:49.039913 2026] [security2:error] [pid 765155:tid 765392] [client 20.215.191.139:55472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/classwithtostring.php"] [unique_id "amuLOeT5hFAbD-LhWHh-iQAAAPA"]
[Thu Jul 30 12:34:49.349695 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:49.422149 2026] [security2:error] [pid 765155:tid 765402] [client 152.32.142.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.kfo.lku.temporary.site"] [uri "/index.php"] [unique_id "amuLOeT5hFAbD-LhWHh-mAAAAPo"]
[Thu Jul 30 12:34:49.702442 2026] [core:notice] [pid 765155:tid 765319] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:49.706540 2026] [security2:error] [pid 765155:tid 765319] [client 103.215.74.26:12778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLOeT5hFAbD-LhWHh-pAAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:50.350408 2026] [security2:error] [pid 765155:tid 765303] [client 20.63.98.115:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/f35.php"] [unique_id "amuLOuT5hFAbD-LhWHh-swAAAJc"]
[Thu Jul 30 12:34:50.438539 2026] [core:notice] [pid 765155:tid 765308] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:50.444529 2026] [security2:error] [pid 765155:tid 765308] [client 103.215.74.26:12790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLOuT5hFAbD-LhWHh-tAAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:51.008954 2026] [security2:error] [pid 765155:tid 765396] [client 20.63.98.115:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/autoload_classmap.php"] [unique_id "amuLO-T5hFAbD-LhWHh-vwAAAPQ"]
[Thu Jul 30 12:34:51.172648 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:51.179068 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:12792] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLO-T5hFAbD-LhWHh-xQAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:51.909122 2026] [core:notice] [pid 765155:tid 765405] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:51.915927 2026] [security2:error] [pid 765155:tid 765405] [client 103.215.74.26:12800] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLO-T5hFAbD-LhWHh-1QAAAP0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:51.940350 2026] [security2:error] [pid 765155:tid 765382] [client 20.215.191.139:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/config.php"] [unique_id "amuLO-T5hFAbD-LhWHh-2QAAAOY"]
[Thu Jul 30 12:34:52.618790 2026] [security2:error] [pid 765155:tid 765358] [client 20.215.191.139:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/core.php"] [unique_id "amuLPOT5hFAbD-LhWHh-5wAAAM4"]
[Thu Jul 30 12:34:53.490013 2026] [security2:error] [pid 765155:tid 765187] [remote 144.76.32.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/29"] [unique_id "amuLPeT5hFAbD-LhWHh-9wAA3B8"]
[Thu Jul 30 12:34:53.518341 2026] [security2:error] [pid 765155:tid 765296] [client 20.215.191.139:56720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/css.php"] [unique_id "amuLPeT5hFAbD-LhWHh_AwAAAJA"]
[Thu Jul 30 12:34:53.591794 2026] [security2:error] [pid 765155:tid 765373] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLPeT5hFAbD-LhWHh-9gAAAN0"]
[Thu Jul 30 12:34:54.133670 2026] [security2:error] [pid 765155:tid 765398] [client 20.63.98.115:47224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/NewFile.php"] [unique_id "amuLPuT5hFAbD-LhWHh_FQAAAPY"]
[Thu Jul 30 12:34:54.366190 2026] [security2:error] [pid 765155:tid 765348] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLPeT5hFAbD-LhWHh_CwAAxDA"]
[Thu Jul 30 12:34:55.829726 2026] [security2:error] [pid 765155:tid 765299] [client 94.3.73.66:60254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuLP-T5hFAbD-LhWHh_PwAAAJM"]
[Thu Jul 30 12:34:55.923606 2026] [security2:error] [pid 765155:tid 765266] [remote 74.7.241.60:47250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuLP-T5hFAbD-LhWHh_RAAAyW4"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:34:56.267141 2026] [security2:error] [pid 765155:tid 765285] [client 62.158.137.186:34088] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLQOT5hFAbD-LhWHh_UAAAAIU"]
[Thu Jul 30 12:34:56.755880 2026] [proxy:error] [pid 765155:tid 765305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:56.755937 2026] [proxy_http:error] [pid 765155:tid 765305] [client 143.244.57.82:46758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:56.756837 2026] [proxy:error] [pid 765155:tid 765305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:56.756890 2026] [proxy_http:error] [pid 765155:tid 765305] [client 143.244.57.82:46758] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:56.757570 2026] [security2:error] [pid 765155:tid 765368] [client 85.209.75.95:39024] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLQOT5hFAbD-LhWHh_ZQAAANg"]
[Thu Jul 30 12:34:56.788506 2026] [security2:error] [pid 765155:tid 765296] [client 70.67.96.40:39508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLQOT5hFAbD-LhWHh_ZgAAAJA"]
[Thu Jul 30 12:34:57.047400 2026] [proxy:error] [pid 765155:tid 765360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.047481 2026] [proxy_http:error] [pid 765155:tid 765360] [client 143.244.57.82:50259] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.048441 2026] [proxy:error] [pid 765155:tid 765360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.048503 2026] [proxy_http:error] [pid 765155:tid 765360] [client 143.244.57.82:50259] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.328960 2026] [security2:error] [pid 765155:tid 765389] [client 143.244.57.82:50350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuLQeT5hFAbD-LhWHh_dgAAAO0"]
[Thu Jul 30 12:34:57.517065 2026] [proxy:error] [pid 765155:tid 765286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.517123 2026] [proxy_http:error] [pid 765155:tid 765286] [client 44.213.206.96:46263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.517694 2026] [proxy:error] [pid 765155:tid 765286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.517738 2026] [proxy_http:error] [pid 765155:tid 765286] [client 44.213.206.96:46263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.611359 2026] [security2:error] [pid 765155:tid 765399] [client 143.244.57.82:50356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuLQeT5hFAbD-LhWHh_gwAAAPc"]
[Thu Jul 30 12:34:57.627153 2026] [security2:error] [pid 765155:tid 765322] [client 20.215.191.139:62006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/database.php"] [unique_id "amuLQeT5hFAbD-LhWHh_hwAAAKo"]
[Thu Jul 30 12:34:57.636205 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:57.637416 2026] [proxy:error] [pid 765155:tid 765359] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.637490 2026] [proxy_http:error] [pid 765155:tid 765359] [client 44.213.206.96:64786] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.638057 2026] [proxy:error] [pid 765155:tid 765359] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.638104 2026] [proxy_http:error] [pid 765155:tid 765359] [client 44.213.206.96:64786] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.642596 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:23810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLQeT5hFAbD-LhWHh_iAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:57.647738 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:57.652746 2026] [security2:error] [pid 765155:tid 765341] [client 62.57.122.34:49100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuLQeT5hFAbD-LhWHh_jQAAAL0"]
[Thu Jul 30 12:34:57.690719 2026] [security2:error] [pid 765155:tid 765395] [client 131.100.100.69:39894] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuLQeT5hFAbD-LhWHh_jwAAAPM"]
[Thu Jul 30 12:34:57.692246 2026] [security2:error] [pid 765155:tid 765402] [client 20.63.98.115:61393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xx.php"] [unique_id "amuLQeT5hFAbD-LhWHh_kAAAAPo"]
[Thu Jul 30 12:34:57.896246 2026] [proxy:error] [pid 765155:tid 765364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.896357 2026] [proxy_http:error] [pid 765155:tid 765364] [client 143.244.57.82:50372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.897210 2026] [proxy:error] [pid 765155:tid 765364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:34:57.897272 2026] [proxy_http:error] [pid 765155:tid 765364] [client 143.244.57.82:50372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:34:57.916797 2026] [security2:error] [pid 765155:tid 765297] [client 88.15.18.73:45995] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLQeT5hFAbD-LhWHh_kgAAAJE"]
[Thu Jul 30 12:34:58.061115 2026] [security2:error] [pid 765155:tid 765321] [client 38.190.144.4:59395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLQuT5hFAbD-LhWHh_lgAAAKk"]
[Thu Jul 30 12:34:58.061242 2026] [security2:error] [pid 765155:tid 765321] [client 38.190.144.4:59395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLQuT5hFAbD-LhWHh_lgAAAKk"]
[Thu Jul 30 12:34:58.174282 2026] [security2:error] [pid 765155:tid 765348] [client 143.244.57.82:50388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuLQuT5hFAbD-LhWHh_mgAAAMQ"]
[Thu Jul 30 12:34:58.370470 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:58.374927 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:23822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "772"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLQuT5hFAbD-LhWHh_owAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:58.455788 2026] [security2:error] [pid 765155:tid 765325] [client 143.244.57.82:7097] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuLQuT5hFAbD-LhWHh_qwAAAK0"]
[Thu Jul 30 12:34:58.572726 2026] [security2:error] [pid 765155:tid 765335] [client 87.212.154.26:51078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLQuT5hFAbD-LhWHh_sAAAALc"]
[Thu Jul 30 12:34:58.599951 2026] [security2:error] [pid 765155:tid 765318] [client 81.133.118.137:44392] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuLQuT5hFAbD-LhWHh_sQAAAKY"]
[Thu Jul 30 12:34:58.728679 2026] [security2:error] [pid 765155:tid 765407] [client 143.244.57.82:50418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuLQuT5hFAbD-LhWHh_uAAAAP8"]
[Thu Jul 30 12:34:58.898372 2026] [security2:error] [pid 765155:tid 765291] [client 77.32.13.48:1676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLQuT5hFAbD-LhWHh_uQAAAIs"]
[Thu Jul 30 12:34:59.007288 2026] [security2:error] [pid 765155:tid 765286] [client 143.244.57.82:50426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuLQ-T5hFAbD-LhWHh_uwAAAIY"]
[Thu Jul 30 12:34:59.095021 2026] [core:notice] [pid 765155:tid 765390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:59.101604 2026] [security2:error] [pid 765155:tid 765390] [client 103.215.74.26:23836] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLQ-T5hFAbD-LhWHh_wAAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:59.115963 2026] [security2:error] [pid 765155:tid 765323] [client 20.215.191.139:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/db.php"] [unique_id "amuLQ-T5hFAbD-LhWHh_wwAAAKs"]
[Thu Jul 30 12:34:59.141153 2026] [security2:error] [pid 765155:tid 765339] [client 20.63.98.115:42957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/plugins.php"] [unique_id "amuLQ-T5hFAbD-LhWHh_xAAAALs"]
[Thu Jul 30 12:34:59.267130 2026] [security2:error] [pid 765155:tid 765374] [client 81.222.178.170:12362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuLQ-T5hFAbD-LhWHh_yAAAAN4"]
[Thu Jul 30 12:34:59.291960 2026] [security2:error] [pid 765155:tid 765313] [client 143.244.57.82:50434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuLQ-T5hFAbD-LhWHh_yQAAAKE"]
[Thu Jul 30 12:34:59.471341 2026] [security2:error] [pid 765155:tid 765377] [client 114.119.151.174:58259] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ejournalugj.com"] [uri "/index_php/jdui/index"] [unique_id "amuLQ-T5hFAbD-LhWHh_1QAAAOE"], referer: https://www.ejournalugj.com/index_php/jdui/issue/current
[Thu Jul 30 12:34:59.573197 2026] [security2:error] [pid 765155:tid 765348] [client 143.244.57.82:50438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuLQ-T5hFAbD-LhWHh_2AAAAMQ"]
[Thu Jul 30 12:34:59.815109 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:34:59.823348 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:23842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "785"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLQ-T5hFAbD-LhWHh_5AAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:34:59.856533 2026] [security2:error] [pid 765155:tid 765312] [client 143.244.57.82:50454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuLQ-T5hFAbD-LhWHh_5QAAAKA"]
[Thu Jul 30 12:35:00.043560 2026] [security2:error] [pid 765155:tid 765337] [client 20.215.191.139:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/default.php"] [unique_id "amuLROT5hFAbD-LhWHh_5wAAALk"]
[Thu Jul 30 12:35:00.113844 2026] [security2:error] [pid 765155:tid 765327] [client 143.198.88.13:63575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuLROT5hFAbD-LhWHh_8AAAAK8"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:00.141391 2026] [security2:error] [pid 765155:tid 765370] [client 143.244.57.82:50468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuLROT5hFAbD-LhWHh_-QAAANo"]
[Thu Jul 30 12:35:00.415514 2026] [security2:error] [pid 765155:tid 765315] [client 143.244.57.82:50484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuLROT5hFAbD-LhWHiABQAAAKM"]
[Thu Jul 30 12:35:00.433442 2026] [security2:error] [pid 765155:tid 765400] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiABAAAAPg"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:00.562364 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:00.570501 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:23858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLROT5hFAbD-LhWHiACgAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:00.705138 2026] [security2:error] [pid 765155:tid 765388] [client 143.198.88.13:53390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiACAAAAOw"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:00.719188 2026] [security2:error] [pid 765155:tid 765387] [client 143.244.57.82:50486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuLROT5hFAbD-LhWHiAFAAAAOs"]
[Thu Jul 30 12:35:00.835208 2026] [core:error] [pid 765155:tid 765172] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.835232 2026] [core:error] [pid 765155:tid 765172] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.838600 2026] [security2:error] [pid 765155:tid 765297] [client 47.128.121.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiAEAAAAJE"]
[Thu Jul 30 12:35:00.840023 2026] [core:error] [pid 765155:tid 765174] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.840039 2026] [core:error] [pid 765155:tid 765174] [remote 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.898794 2026] [security2:error] [pid 765155:tid 765305] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiAGgAAAJk"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:00.942886 2026] [core:error] [pid 765155:tid 765175] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:00.942907 2026] [core:error] [pid 765155:tid 765175] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:01.003028 2026] [security2:error] [pid 765155:tid 765335] [client 143.244.57.82:50492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuLReT5hFAbD-LhWHiAIgAAALc"]
[Thu Jul 30 12:35:01.076467 2026] [security2:error] [pid 765155:tid 765289] [client 143.198.88.13:53390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHiAIAAAAIk"], referer: www.yjb.slj.mybluehost.me/blog//wp-login.php
[Thu Jul 30 12:35:01.139593 2026] [security2:error] [pid 765155:tid 765303] [client 143.198.88.13:53390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/blog//xmlrpc.php"] [unique_id "amuLReT5hFAbD-LhWHiAKgAAAJc"]
[Thu Jul 30 12:35:01.139690 2026] [security2:error] [pid 765155:tid 765303] [client 143.198.88.13:53390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ylw.gpl.temporary.site"] [uri "/blog//xmlrpc.php"] [unique_id "amuLReT5hFAbD-LhWHiAKgAAAJc"]
[Thu Jul 30 12:35:01.170090 2026] [security2:error] [pid 765155:tid 765378] [client 92.172.161.248:48634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuLReT5hFAbD-LhWHiALQAAAOI"]
[Thu Jul 30 12:35:01.262040 2026] [security2:error] [pid 765155:tid 765299] [client 143.198.88.13:60165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/blog//wp-login.php"] [unique_id "amuLReT5hFAbD-LhWHiALwAAAJM"], referer: http://ylw.gpl.temporary.site//blog//wp-login.php
[Thu Jul 30 12:35:01.271918 2026] [security2:error] [pid 765155:tid 765350] [client 20.215.191.139:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/dropdown.php"] [unique_id "amuLReT5hFAbD-LhWHiAMQAAAMY"]
[Thu Jul 30 12:35:01.308121 2026] [security2:error] [pid 765155:tid 765308] [client 143.244.57.82:50502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuLReT5hFAbD-LhWHiAMwAAAJw"]
[Thu Jul 30 12:35:01.346951 2026] [core:notice] [pid 765155:tid 765319] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:01.355552 2026] [security2:error] [pid 765155:tid 765319] [client 103.215.74.26:23862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLReT5hFAbD-LhWHiANgAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:01.439595 2026] [security2:error] [pid 765155:tid 765338] [client 172.237.109.114:30762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_6QAAALo"]
[Thu Jul 30 12:35:01.453257 2026] [security2:error] [pid 765155:tid 765315] [client 50.6.43.217:18568] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-cron.php"] [unique_id "amuLReT5hFAbD-LhWHiAOgAAAKM"]
[Thu Jul 30 12:35:01.459301 2026] [security2:error] [pid 765155:tid 765358] [client 172.237.109.114:15907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_7AAAAM4"]
[Thu Jul 30 12:35:01.460849 2026] [security2:error] [pid 765155:tid 765393] [client 172.237.109.114:27334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_6AAAAPE"]
[Thu Jul 30 12:35:01.469444 2026] [security2:error] [pid 765155:tid 765346] [client 172.237.109.114:25785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_7QAAAMI"]
[Thu Jul 30 12:35:01.480997 2026] [security2:error] [pid 765155:tid 765366] [client 172.237.109.114:63973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_8gAAANY"]
[Thu Jul 30 12:35:01.481264 2026] [security2:error] [pid 765155:tid 765345] [client 172.237.109.114:24586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_9QAAAME"]
[Thu Jul 30 12:35:01.489931 2026] [security2:error] [pid 765155:tid 765408] [client 172.237.109.114:21358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_8wAAAQA"]
[Thu Jul 30 12:35:01.493182 2026] [security2:error] [pid 765155:tid 765293] [client 172.237.109.114:27442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_-wAAAI0"]
[Thu Jul 30 12:35:01.496796 2026] [security2:error] [pid 765155:tid 765291] [client 172.237.109.114:38398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_9gAAAIs"]
[Thu Jul 30 12:35:01.509296 2026] [security2:error] [pid 765155:tid 765407] [client 172.237.109.114:52916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_8QAAAP8"]
[Thu Jul 30 12:35:01.518591 2026] [security2:error] [pid 765155:tid 765347] [client 172.237.109.114:41596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_9wAAAMM"]
[Thu Jul 30 12:35:01.520422 2026] [security2:error] [pid 765155:tid 765389] [client 172.237.109.114:10836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_7gAAAO0"]
[Thu Jul 30 12:35:01.522487 2026] [security2:error] [pid 765155:tid 765286] [client 172.237.109.114:1142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh__AAAAIY"]
[Thu Jul 30 12:35:01.537470 2026] [security2:error] [pid 765155:tid 765332] [client 172.237.109.114:20627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLROT5hFAbD-LhWHh_9AAAALQ"]
[Thu Jul 30 12:35:01.613966 2026] [security2:error] [pid 765155:tid 765355] [client 143.244.57.82:50510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuLReT5hFAbD-LhWHiAPAAAAMs"]
[Thu Jul 30 12:35:01.710811 2026] [security2:error] [pid 765155:tid 765397] [client 90.76.35.109:54798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLReT5hFAbD-LhWHiAQAAAAPU"]
[Thu Jul 30 12:35:01.910577 2026] [security2:error] [pid 765155:tid 765411] [client 143.244.57.82:50526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.hck.nyx.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuLReT5hFAbD-LhWHiASwAAAQM"]
[Thu Jul 30 12:35:02.040349 2026] [core:notice] [pid 765155:tid 765287] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:02.272673 2026] [security2:error] [pid 765155:tid 765392] [client 87.20.247.37:33244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuLRuT5hFAbD-LhWHiAUQAAAPA"]
[Thu Jul 30 12:35:02.275625 2026] [security2:error] [pid 765155:tid 765354] [client 83.196.0.255:33434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuLRuT5hFAbD-LhWHiAUwAAAMo"]
[Thu Jul 30 12:35:02.476118 2026] [security2:error] [pid 765155:tid 765391] [client 172.237.109.114:34631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAIwAAAO8"]
[Thu Jul 30 12:35:02.486484 2026] [security2:error] [pid 765155:tid 765318] [client 172.237.109.114:18139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAJwAAAKY"]
[Thu Jul 30 12:35:02.506781 2026] [security2:error] [pid 765155:tid 765371] [client 172.237.109.114:7804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAKAAAANs"]
[Thu Jul 30 12:35:02.532839 2026] [security2:error] [pid 765155:tid 765336] [client 172.237.109.114:53529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiALAAAALg"]
[Thu Jul 30 12:35:02.539038 2026] [security2:error] [pid 765155:tid 765311] [client 172.237.109.114:52647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAKwAAAJ8"]
[Thu Jul 30 12:35:02.541522 2026] [security2:error] [pid 765155:tid 765324] [client 172.237.109.114:19413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLReT5hFAbD-LhWHiAKQAAAKw"]
[Thu Jul 30 12:35:02.677916 2026] [security2:error] [pid 765155:tid 765186] [remote 57.141.0.27:57076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuLRuT5hFAbD-LhWHiAXwAAox4"]
[Thu Jul 30 12:35:03.064663 2026] [security2:error] [pid 765155:tid 765386] [client 20.215.191.139:50799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/edit.php"] [unique_id "amuLR-T5hFAbD-LhWHiAbQAAAOo"]
[Thu Jul 30 12:35:03.117373 2026] [security2:error] [pid 765155:tid 765390] [client 152.59.185.22:48176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuLR-T5hFAbD-LhWHiAbwAAAO4"]
[Thu Jul 30 12:35:05.842115 2026] [security2:error] [pid 765155:tid 765298] [client 38.190.144.4:59913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLSeT5hFAbD-LhWHiArQAAAJI"]
[Thu Jul 30 12:35:05.844584 2026] [security2:error] [pid 765155:tid 765298] [client 38.190.144.4:59913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLSeT5hFAbD-LhWHiArQAAAJI"]
[Thu Jul 30 12:35:06.018351 2026] [security2:error] [pid 765155:tid 765360] [client 74.7.241.145:53332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "prednisolonetablets.store.qsv.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuLSuT5hFAbD-LhWHiAsgAAANA"]
[Thu Jul 30 12:35:06.242962 2026] [security2:error] [pid 765155:tid 765329] [client 20.63.98.115:54587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xxx.php"] [unique_id "amuLSuT5hFAbD-LhWHiAtgAAALE"]
[Thu Jul 30 12:35:06.484794 2026] [security2:error] [pid 765155:tid 765380] [client 50.6.43.217:43950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLSeT5hFAbD-LhWHiAqgAAAOQ"]
[Thu Jul 30 12:35:06.694004 2026] [security2:error] [pid 765155:tid 765350] [client 88.99.80.227:20622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuLSuT5hFAbD-LhWHiAwQAAAMY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:35:06.907783 2026] [security2:error] [pid 765155:tid 765382] [client 20.215.191.139:53696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/f35.php"] [unique_id "amuLSuT5hFAbD-LhWHiAxQAAAOY"]
[Thu Jul 30 12:35:07.060843 2026] [core:notice] [pid 765155:tid 765341] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:07.066385 2026] [security2:error] [pid 765155:tid 765341] [client 88.99.80.227:20630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLS-T5hFAbD-LhWHiAxwAAAL0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:35:07.084698 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:07.088790 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:16278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLS-T5hFAbD-LhWHiAyAAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:07.213799 2026] [security2:error] [pid 765155:tid 765392] [client 50.6.43.217:43964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLSuT5hFAbD-LhWHiAugAAAPA"]
[Thu Jul 30 12:35:07.317576 2026] [security2:error] [pid 765155:tid 765336] [client 20.63.98.115:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/css.php"] [unique_id "amuLS-T5hFAbD-LhWHiAzwAAALg"]
[Thu Jul 30 12:35:07.439701 2026] [security2:error] [pid 765155:tid 765403] [client 88.99.80.227:20640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuLS-T5hFAbD-LhWHiA0wAAAPs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:35:07.767221 2026] [security2:error] [pid 765155:tid 765379] [client 51.15.232.53:39234] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLS-T5hFAbD-LhWHiA3QAAAOM"]
[Thu Jul 30 12:35:07.832090 2026] [core:notice] [pid 765155:tid 765340] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:07.837787 2026] [security2:error] [pid 765155:tid 765340] [client 103.215.74.26:16290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLS-T5hFAbD-LhWHiA4AAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:08.025216 2026] [security2:error] [pid 765155:tid 765320] [client 123.202.189.111:9503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2015/12/id%C3%A9es-cadeaux-homme_beaute-2-300x210.png"] [unique_id "amuLTOT5hFAbD-LhWHiA5wAAAKg"]
[Thu Jul 30 12:35:08.299935 2026] [security2:error] [pid 765155:tid 765289] [client 20.63.98.115:61388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuLTOT5hFAbD-LhWHiA6gAAAIk"]
[Thu Jul 30 12:35:08.560429 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:08.565460 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:16294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLTOT5hFAbD-LhWHiA9gAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:08.593639 2026] [security2:error] [pid 765155:tid 765378] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLS-T5hFAbD-LhWHiA5gAAAOI"]
[Thu Jul 30 12:35:09.039942 2026] [security2:error] [pid 765155:tid 765168] [remote 190.92.174.131:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuLTeT5hFAbD-LhWHiBAQAAjQw"]
[Thu Jul 30 12:35:09.260292 2026] [security2:error] [pid 765155:tid 765285] [client 20.215.191.139:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/f7.php"] [unique_id "amuLTeT5hFAbD-LhWHiBBQAAAIU"]
[Thu Jul 30 12:35:09.298525 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:09.302350 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:16296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLTeT5hFAbD-LhWHiBCQAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:09.632038 2026] [security2:error] [pid 765155:tid 765366] [client 20.63.98.115:20556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuLTeT5hFAbD-LhWHiBDwAAANY"]
[Thu Jul 30 12:35:10.036757 2026] [core:notice] [pid 765155:tid 765390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:10.042092 2026] [security2:error] [pid 765155:tid 765390] [client 103.215.74.26:16298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLTuT5hFAbD-LhWHiBGQAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:10.580692 2026] [security2:error] [pid 765155:tid 765405] [client 20.63.98.115:62071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuLTuT5hFAbD-LhWHiBJgAAAP0"]
[Thu Jul 30 12:35:11.815068 2026] [security2:error] [pid 765155:tid 765269] [remote 47.128.27.84:45476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moose-knuckles-jacket-olive/"] [unique_id "amuLT-T5hFAbD-LhWHiBQwAA4HE"]
[Thu Jul 30 12:35:12.397054 2026] [security2:error] [pid 765155:tid 765366] [client 20.63.98.115:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/network/about.php"] [unique_id "amuLUOT5hFAbD-LhWHiBWAAAANY"]
[Thu Jul 30 12:35:12.983658 2026] [core:notice] [pid 765155:tid 765372] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:13.340341 2026] [autoindex:error] [pid 765155:tid 765362] [client 52.4.19.39:32641] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:35:13.443610 2026] [autoindex:error] [pid 765155:tid 765352] [client 52.4.19.39:6221] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:35:13.565862 2026] [security2:error] [pid 765155:tid 765356] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLUeT5hFAbD-LhWHiBdQAAzHU"]
[Thu Jul 30 12:35:13.584152 2026] [security2:error] [pid 765155:tid 765356] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLUeT5hFAbD-LhWHiBeAAAzBE"]
[Thu Jul 30 12:35:13.898508 2026] [security2:error] [pid 765155:tid 765378] [client 20.63.98.115:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xpw.php"] [unique_id "amuLUeT5hFAbD-LhWHiBkwAAAOI"]
[Thu Jul 30 12:35:14.322329 2026] [security2:error] [pid 765155:tid 765366] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLUuT5hFAbD-LhWHiBmgAA1hk"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:35:15.411001 2026] [security2:error] [pid 765155:tid 765407] [client 45.221.5.168:47478] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/jquery-plugin-collection.js"] [unique_id "amuLU-T5hFAbD-LhWHiBtQAAAP8"]
[Thu Jul 30 12:35:15.613625 2026] [security2:error] [pid 765155:tid 765346] [client 74.7.230.33:54876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hhmoaf.org.wrl.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuLU-T5hFAbD-LhWHiBvQAAwh4"]
[Thu Jul 30 12:35:15.727036 2026] [autoindex:error] [pid 765155:tid 765188] [remote 74.7.242.27:55578] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:35:15.778947 2026] [core:notice] [pid 765155:tid 765354] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:15.784372 2026] [security2:error] [pid 765155:tid 765354] [client 103.215.74.26:31408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLU-T5hFAbD-LhWHiBwwAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:16.522552 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:16.526937 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:31420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLVOT5hFAbD-LhWHiB0gAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:16.706277 2026] [security2:error] [pid 765155:tid 765343] [client 50.6.43.217:20098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuLVOT5hFAbD-LhWHiB1gAAAL8"]
[Thu Jul 30 12:35:16.827684 2026] [security2:error] [pid 765155:tid 765305] [client 50.6.43.217:20102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuLVOT5hFAbD-LhWHiB2gAAAJk"]
[Thu Jul 30 12:35:17.088047 2026] [core:notice] [pid 765155:tid 765392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:17.255347 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:17.260065 2026] [security2:error] [pid 765155:tid 765409] [client 103.215.74.26:31436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLVeT5hFAbD-LhWHiB6AAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:17.680536 2026] [core:notice] [pid 765155:tid 765393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:17.864370 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLVeT5hFAbD-LhWHiB9gAAANc"]
[Thu Jul 30 12:35:17.864515 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:60442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLVeT5hFAbD-LhWHiB9gAAANc"]
[Thu Jul 30 12:35:18.009860 2026] [core:notice] [pid 765155:tid 765300] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:18.014436 2026] [security2:error] [pid 765155:tid 765300] [client 103.215.74.26:31452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLVuT5hFAbD-LhWHiB-gAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:18.405181 2026] [security2:error] [pid 765155:tid 765289] [client 66.249.74.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kamiliacademy.com"] [uri "/index.php"] [unique_id "amuLU-T5hFAbD-LhWHiBwgAAAIk"]
[Thu Jul 30 12:35:18.787504 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:18.791784 2026] [security2:error] [pid 765155:tid 765377] [client 103.215.74.26:31460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLVuT5hFAbD-LhWHiCCwAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:18.900352 2026] [security2:error] [pid 765155:tid 765203] [remote 82.130.249.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.249.130.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ciunews.com"] [uri "/wp-login.php"] [unique_id "amuLVuT5hFAbD-LhWHiCDAAAwy8"]
[Thu Jul 30 12:35:19.206020 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:19.440381 2026] [core:notice] [pid 765155:tid 765327] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:19.508727 2026] [security2:error] [pid 765155:tid 765304] [client 20.63.98.115:20550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-cron.php"] [unique_id "amuLV-T5hFAbD-LhWHiCHAAAAJg"]
[Thu Jul 30 12:35:19.567246 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:19.572737 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:31462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLV-T5hFAbD-LhWHiCIAAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:20.299227 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:20.304221 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:31470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLWOT5hFAbD-LhWHiCOQAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:20.406042 2026] [security2:error] [pid 765155:tid 765346] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLWOT5hFAbD-LhWHiCLgAAwkU"]
[Thu Jul 30 12:35:20.615024 2026] [security2:error] [pid 765155:tid 765346] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLWOT5hFAbD-LhWHiCOgAAwkE"]
[Thu Jul 30 12:35:20.782756 2026] [security2:error] [pid 765155:tid 765346] [client 119.73.97.132:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLWOT5hFAbD-LhWHiCPAAAwk4"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:35:20.997317 2026] [security2:error] [pid 765155:tid 765360] [client 20.63.98.115:21081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cah.php"] [unique_id "amuLWOT5hFAbD-LhWHiCRwAAANA"]
[Thu Jul 30 12:35:21.023468 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:21.028001 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:31484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLWeT5hFAbD-LhWHiCSAAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:21.766734 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:21.770731 2026] [security2:error] [pid 765155:tid 765394] [client 103.215.74.26:31492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLWeT5hFAbD-LhWHiCYQAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:22.220942 2026] [security2:error] [pid 765155:tid 765334] [client 20.63.98.115:21088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cong.php"] [unique_id "amuLWuT5hFAbD-LhWHiCZwAAALY"]
[Thu Jul 30 12:35:22.499945 2026] [core:notice] [pid 765155:tid 765301] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:22.507033 2026] [security2:error] [pid 765155:tid 765301] [client 103.215.74.26:31500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLWuT5hFAbD-LhWHiCcQAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:22.701207 2026] [core:notice] [pid 765155:tid 765380] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:22.756415 2026] [core:notice] [pid 765155:tid 765341] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:22.911848 2026] [proxy:error] [pid 765155:tid 765408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:22.911915 2026] [proxy_http:error] [pid 765155:tid 765408] [client 54.87.222.253:64667] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:22.912581 2026] [proxy:error] [pid 765155:tid 765408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:22.912627 2026] [proxy_http:error] [pid 765155:tid 765408] [client 54.87.222.253:64667] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:23.035547 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:23.066383 2026] [proxy:error] [pid 765155:tid 765310] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:23.066457 2026] [proxy_http:error] [pid 765155:tid 765310] [client 3.228.112.215:9963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:23.067021 2026] [proxy:error] [pid 765155:tid 765310] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:23.067070 2026] [proxy_http:error] [pid 765155:tid 765310] [client 3.228.112.215:9963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:23.119552 2026] [security2:error] [pid 765155:tid 765398] [client 42.105.179.169:29964] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/jquery-plugin-collection.js"] [unique_id "amuLW-T5hFAbD-LhWHiCiQAAAPY"]
[Thu Jul 30 12:35:23.253813 2026] [core:notice] [pid 765155:tid 765294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:23.260489 2026] [security2:error] [pid 765155:tid 765294] [client 103.215.74.26:12946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLW-T5hFAbD-LhWHiCkAAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:23.372281 2026] [security2:error] [pid 765155:tid 765345] [client 20.63.98.115:65462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/Sanskrit.php"] [unique_id "amuLW-T5hFAbD-LhWHiClQAAAME"]
[Thu Jul 30 12:35:23.597329 2026] [security2:error] [pid 765155:tid 765333] [client 208.98.222.15:44627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuLW-T5hFAbD-LhWHiCmQAAtVs"], referer: https://www.northyorksheridanmall.com/mall-map/
[Thu Jul 30 12:35:23.990941 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:23.996421 2026] [security2:error] [pid 765155:tid 765394] [client 103.215.74.26:12956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLW-T5hFAbD-LhWHiCpgAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:24.303930 2026] [fcgid:warn] [pid 765155:tid 765306] (70014)End of file found: [client 118.194.233.182:35336] mod_fcgid: can't get data from http client
[Thu Jul 30 12:35:24.699323 2026] [security2:error] [pid 765155:tid 765405] [client 20.63.98.115:63420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ms-edit.php"] [unique_id "amuLXOT5hFAbD-LhWHiCvQAAAP0"]
[Thu Jul 30 12:35:24.761126 2026] [core:notice] [pid 765155:tid 765401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:24.767250 2026] [security2:error] [pid 765155:tid 765401] [client 103.215.74.26:12960] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLXOT5hFAbD-LhWHiCwQAAAPk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:24.947038 2026] [security2:error] [pid 765155:tid 765307] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLW-T5hFAbD-LhWHiCngAAAJs"]
[Thu Jul 30 12:35:25.214099 2026] [security2:error] [pid 765155:tid 765388] [client 89.181.223.51:49456] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLXeT5hFAbD-LhWHiCyQAAAOw"]
[Thu Jul 30 12:35:25.295126 2026] [security2:error] [pid 765155:tid 765387] [client 80.30.87.122:45718] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuLXeT5hFAbD-LhWHiCywAAAOs"]
[Thu Jul 30 12:35:25.375303 2026] [security2:error] [pid 765155:tid 765316] [client 83.42.52.45:56280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuLXeT5hFAbD-LhWHiC0gAAAKQ"]
[Thu Jul 30 12:35:25.488884 2026] [core:notice] [pid 765155:tid 765345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:25.498867 2026] [security2:error] [pid 765155:tid 765345] [client 103.215.74.26:12970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLXeT5hFAbD-LhWHiC1wAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:25.543447 2026] [security2:error] [pid 765155:tid 765289] [client 85.243.150.4:46170] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuLXeT5hFAbD-LhWHiC3QAAAIk"]
[Thu Jul 30 12:35:26.117923 2026] [security2:error] [pid 765155:tid 765368] [client 108.172.254.208:45938] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuLXuT5hFAbD-LhWHiC7QAAANg"]
[Thu Jul 30 12:35:26.196599 2026] [security2:error] [pid 765155:tid 765367] [client 128.2.204.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLXuT5hFAbD-LhWHiC7AAAANc"]
[Thu Jul 30 12:35:26.224293 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:26.228267 2026] [security2:error] [pid 765155:tid 765303] [client 103.215.74.26:12982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLXuT5hFAbD-LhWHiC7gAAAJc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:26.952359 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:26.956337 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:12986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLXuT5hFAbD-LhWHiDAQAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:27.670428 2026] [core:notice] [pid 765155:tid 765347] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:27.682941 2026] [security2:error] [pid 765155:tid 765347] [client 103.215.74.26:12996] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLX-T5hFAbD-LhWHiDGQAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:27.776936 2026] [security2:error] [pid 765155:tid 765387] [client 44.255.204.121:53320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLX-T5hFAbD-LhWHiDCwAA6xM"]
[Thu Jul 30 12:35:28.235025 2026] [security2:error] [pid 765155:tid 765370] [client 20.63.98.115:21101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/function.php"] [unique_id "amuLYOT5hFAbD-LhWHiDLAAAANo"]
[Thu Jul 30 12:35:28.298748 2026] [security2:error] [pid 765155:tid 765308] [client 216.73.216.176:1939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mediaspawn.com"] [uri "/index.php"] [unique_id "amuLX-T5hFAbD-LhWHiDGgAAnBE"]
[Thu Jul 30 12:35:28.335831 2026] [security2:error] [pid 765155:tid 765379] [client 86.205.97.104:40934] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuLYOT5hFAbD-LhWHiDLwAAAOM"]
[Thu Jul 30 12:35:28.403051 2026] [core:notice] [pid 765155:tid 765315] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:28.407290 2026] [security2:error] [pid 765155:tid 765315] [client 103.215.74.26:13010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "784"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLYOT5hFAbD-LhWHiDMQAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:28.415276 2026] [security2:error] [pid 765155:tid 765314] [client 86.2.135.66:45668] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLYOT5hFAbD-LhWHiDMgAAAKI"]
[Thu Jul 30 12:35:28.446995 2026] [security2:error] [pid 765155:tid 765358] [client 50.6.43.217:29206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amuLYOT5hFAbD-LhWHiDMAAAAM4"]
[Thu Jul 30 12:35:28.501100 2026] [security2:error] [pid 765155:tid 765375] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLX-T5hFAbD-LhWHiDFAAA3wU"]
[Thu Jul 30 12:35:28.548923 2026] [security2:error] [pid 765155:tid 765361] [client 94.161.14.62:35296] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuLYOT5hFAbD-LhWHiDOAAAANE"]
[Thu Jul 30 12:35:28.548942 2026] [security2:error] [pid 765155:tid 765407] [client 50.6.43.217:29222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amuLYOT5hFAbD-LhWHiDNwAAAP8"]
[Thu Jul 30 12:35:28.610483 2026] [security2:error] [pid 765155:tid 765393] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLYOT5hFAbD-LhWHiDIQAAAPE"]
[Thu Jul 30 12:35:28.746962 2026] [security2:error] [pid 765155:tid 765302] [client 86.2.71.239:57996] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLYOT5hFAbD-LhWHiDRAAAAJY"]
[Thu Jul 30 12:35:28.750810 2026] [security2:error] [pid 765155:tid 765394] [client 80.41.184.212:56516] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuLYOT5hFAbD-LhWHiDRQAAAPI"]
[Thu Jul 30 12:35:28.832816 2026] [security2:error] [pid 765155:tid 765285] [client 38.190.144.4:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLYOT5hFAbD-LhWHiDSAAAAIU"]
[Thu Jul 30 12:35:28.832925 2026] [security2:error] [pid 765155:tid 765285] [client 38.190.144.4:60976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLYOT5hFAbD-LhWHiDSAAAAIU"]
[Thu Jul 30 12:35:29.124068 2026] [security2:error] [pid 765155:tid 765313] [client 102.212.189.63:36275] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuLYeT5hFAbD-LhWHiDUQAAAKE"]
[Thu Jul 30 12:35:29.157113 2026] [core:notice] [pid 765155:tid 765343] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:29.161333 2026] [security2:error] [pid 765155:tid 765343] [client 103.215.74.26:13026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLYeT5hFAbD-LhWHiDUgAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:29.161866 2026] [security2:error] [pid 765155:tid 765338] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLYOT5hFAbD-LhWHiDPAAAALo"]
[Thu Jul 30 12:35:29.530969 2026] [security2:error] [pid 765155:tid 765412] [client 83.52.236.69:33794] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLYeT5hFAbD-LhWHiDXAAAAQQ"]
[Thu Jul 30 12:35:29.820514 2026] [security2:error] [pid 765155:tid 765399] [client 152.58.60.211:48266] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuLYeT5hFAbD-LhWHiDYQAAAPc"]
[Thu Jul 30 12:35:29.877768 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:29.885150 2026] [security2:error] [pid 765155:tid 765367] [client 103.215.74.26:13030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLYeT5hFAbD-LhWHiDZQAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:29.888441 2026] [security2:error] [pid 765155:tid 765406] [client 20.63.98.115:20580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ee.php"] [unique_id "amuLYeT5hFAbD-LhWHiDZgAAAP4"]
[Thu Jul 30 12:35:30.058649 2026] [security2:error] [pid 765155:tid 765288] [client 99.229.28.199:53196] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuLYuT5hFAbD-LhWHiDagAAAIg"]
[Thu Jul 30 12:35:30.063174 2026] [security2:error] [pid 765155:tid 765388] [client 104.11.180.142:46798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuLYuT5hFAbD-LhWHiDawAAAOw"]
[Thu Jul 30 12:35:30.595676 2026] [core:notice] [pid 765155:tid 765403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:30.599704 2026] [security2:error] [pid 765155:tid 765403] [client 103.215.74.26:13034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLYuT5hFAbD-LhWHiDdQAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:30.749921 2026] [core:error] [pid 765155:tid 765285] [client 74.7.241.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:30.749944 2026] [core:error] [pid 765155:tid 765285] [client 74.7.241.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:30.750076 2026] [security2:error] [pid 765155:tid 765285] [client 74.7.241.136:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.rry.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuLYuT5hFAbD-LhWHiDeQAAAIU"]
[Thu Jul 30 12:35:30.750613 2026] [security2:error] [pid 765155:tid 765377] [client 74.7.241.136:35924] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.rry.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuLYuT5hFAbD-LhWHiDdwAA4TY"]
[Thu Jul 30 12:35:30.803583 2026] [security2:error] [pid 765155:tid 765339] [client 79.45.13.177:32948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuLYuT5hFAbD-LhWHiDegAAALs"]
[Thu Jul 30 12:35:31.315388 2026] [security2:error] [pid 765155:tid 765309] [client 72.38.57.2:50106] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuLY-T5hFAbD-LhWHiDhAAAAJ0"]
[Thu Jul 30 12:35:31.329194 2026] [core:notice] [pid 765155:tid 765408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:31.334462 2026] [security2:error] [pid 765155:tid 765408] [client 103.215.74.26:13040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLY-T5hFAbD-LhWHiDhQAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:31.843495 2026] [security2:error] [pid 765155:tid 765394] [client 20.63.98.115:36857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/new.php"] [unique_id "amuLY-T5hFAbD-LhWHiDkwAAAPI"]
[Thu Jul 30 12:35:32.061719 2026] [core:notice] [pid 765155:tid 765400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:32.065946 2026] [security2:error] [pid 765155:tid 765400] [client 103.215.74.26:13042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLZOT5hFAbD-LhWHiDnQAAAPg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:32.210219 2026] [core:error] [pid 765155:tid 765382] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:32.210252 2026] [core:error] [pid 765155:tid 765382] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:32.421195 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:32.793098 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:32.797095 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:13054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLZOT5hFAbD-LhWHiDtAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:32.889179 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:35.519079 2026] [security2:error] [pid 765155:tid 765290] [client 74.7.230.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "qsq.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuLZ-T5hFAbD-LhWHiD7wAAAIo"]
[Thu Jul 30 12:35:35.519694 2026] [security2:error] [pid 765155:tid 765403] [client 74.7.230.32:57268] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "qsq.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuLZ-T5hFAbD-LhWHiD7QAA-0o"]
[Thu Jul 30 12:35:35.761209 2026] [core:error] [pid 765155:tid 765287] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:35.761236 2026] [core:error] [pid 765155:tid 765287] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:35.987802 2026] [security2:error] [pid 765155:tid 765338] [client 20.52.125.110:6866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/LA.php"] [unique_id "amuLZ-T5hFAbD-LhWHiD_QAAALo"]
[Thu Jul 30 12:35:36.051770 2026] [security2:error] [pid 765155:tid 765326] [client 20.63.98.115:63366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-config.php"] [unique_id "amuLaOT5hFAbD-LhWHiD_gAAAK4"]
[Thu Jul 30 12:35:36.579392 2026] [security2:error] [pid 765155:tid 765357] [client 20.52.125.110:6732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/admin.php"] [unique_id "amuLaOT5hFAbD-LhWHiECwAAAM0"]
[Thu Jul 30 12:35:36.606072 2026] [core:notice] [pid 765155:tid 765238] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:37.132638 2026] [core:notice] [pid 765155:tid 765168] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:37.137299 2026] [security2:error] [pid 765155:tid 765329] [client 20.52.125.110:6875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/class_api.php"] [unique_id "amuLaeT5hFAbD-LhWHiEGAAAALE"]
[Thu Jul 30 12:35:37.168173 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:37.648882 2026] [core:notice] [pid 765155:tid 765295] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:37.707554 2026] [security2:error] [pid 765155:tid 765395] [client 20.52.125.110:6886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuLaeT5hFAbD-LhWHiEJgAAAPM"]
[Thu Jul 30 12:35:38.042607 2026] [security2:error] [pid 765155:tid 765403] [client 20.63.98.115:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-conflg.php"] [unique_id "amuLauT5hFAbD-LhWHiEMAAAAPs"]
[Thu Jul 30 12:35:38.632526 2026] [core:notice] [pid 765155:tid 765330] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:38.636837 2026] [security2:error] [pid 765155:tid 765330] [client 103.215.74.26:43724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLauT5hFAbD-LhWHiERAAAALI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:38.705333 2026] [security2:error] [pid 765155:tid 765336] [client 20.52.125.110:6884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuLauT5hFAbD-LhWHiEPgAAALg"]
[Thu Jul 30 12:35:38.810741 2026] [core:error] [pid 765155:tid 765405] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:38.810774 2026] [core:error] [pid 765155:tid 765405] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:39.139626 2026] [core:error] [pid 765155:tid 765344] [client 20.63.98.115:58184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:39.139656 2026] [core:error] [pid 765155:tid 765344] [client 20.63.98.115:58184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:39.306597 2026] [security2:error] [pid 765155:tid 765373] [client 20.52.125.110:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuLa-T5hFAbD-LhWHiEXwAAAN0"]
[Thu Jul 30 12:35:39.364423 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:39.369501 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:43738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLa-T5hFAbD-LhWHiEYwAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:39.527627 2026] [security2:error] [pid 765155:tid 765364] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLauT5hFAbD-LhWHiETwAA1Ew"]
[Thu Jul 30 12:35:39.842954 2026] [security2:error] [pid 765155:tid 765320] [client 20.52.125.110:6721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/991176.php"] [unique_id "amuLa-T5hFAbD-LhWHiEcgAAAKg"]
[Thu Jul 30 12:35:40.096398 2026] [core:notice] [pid 765155:tid 765287] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:40.101109 2026] [security2:error] [pid 765155:tid 765287] [client 103.215.74.26:43752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLbOT5hFAbD-LhWHiEegAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:40.379384 2026] [security2:error] [pid 765155:tid 765391] [client 20.52.125.110:6856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuLbOT5hFAbD-LhWHiEgAAAAO8"]
[Thu Jul 30 12:35:40.830925 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:40.835366 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:43766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLbOT5hFAbD-LhWHiEmQAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:40.948191 2026] [security2:error] [pid 765155:tid 765358] [client 20.52.125.110:6907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuLbOT5hFAbD-LhWHiEngAAAM4"]
[Thu Jul 30 12:35:41.511574 2026] [security2:error] [pid 765155:tid 765311] [client 20.52.125.110:6889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuLbeT5hFAbD-LhWHiErgAAAJ8"]
[Thu Jul 30 12:35:41.585490 2026] [core:notice] [pid 765155:tid 765402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:41.589889 2026] [security2:error] [pid 765155:tid 765402] [client 103.215.74.26:43776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLbeT5hFAbD-LhWHiEsgAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:41.737680 2026] [security2:error] [pid 765155:tid 765163] [remote 216.38.28.47:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amuLbeT5hFAbD-LhWHiEtQAA7gc"]
[Thu Jul 30 12:35:41.744849 2026] [core:error] [pid 765155:tid 765328] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:41.744866 2026] [core:error] [pid 765155:tid 765328] [client 152.32.207.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:42.071768 2026] [security2:error] [pid 765155:tid 765403] [client 20.52.125.110:7372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuLbuT5hFAbD-LhWHiEwgAAAPs"]
[Thu Jul 30 12:35:42.317087 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:42.321283 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:43778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLbuT5hFAbD-LhWHiExAAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:42.352494 2026] [security2:error] [pid 765155:tid 765334] [client 20.63.98.115:65430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuLbuT5hFAbD-LhWHiExQAAALY"]
[Thu Jul 30 12:35:42.640553 2026] [security2:error] [pid 765155:tid 765301] [client 20.52.125.110:6877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuLbuT5hFAbD-LhWHiE0QAAAJU"]
[Thu Jul 30 12:35:42.954736 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:43.067062 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:43.070094 2026] [security2:error] [pid 765155:tid 765293] [client 20.63.98.115:65429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuLb-T5hFAbD-LhWHiE3gAAAI0"]
[Thu Jul 30 12:35:43.071958 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:12752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLb-T5hFAbD-LhWHiE3AAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:43.205191 2026] [proxy:error] [pid 765155:tid 765371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:43.205251 2026] [proxy_http:error] [pid 765155:tid 765371] [client 20.52.125.110:6892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:43.205814 2026] [proxy:error] [pid 765155:tid 765371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:43.205856 2026] [proxy_http:error] [pid 765155:tid 765371] [client 20.52.125.110:6892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:43.261011 2026] [proxy:error] [pid 765155:tid 765400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:43.261093 2026] [proxy_http:error] [pid 765155:tid 765400] [client 32.194.121.99:50553] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:43.261652 2026] [proxy:error] [pid 765155:tid 765400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:43.261694 2026] [proxy_http:error] [pid 765155:tid 765400] [client 32.194.121.99:50553] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:43.695250 2026] [security2:error] [pid 765155:tid 765354] [client 20.52.125.110:6868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuLb-T5hFAbD-LhWHiFCwAAAMo"]
[Thu Jul 30 12:35:43.792385 2026] [core:notice] [pid 765155:tid 765320] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:43.796760 2026] [security2:error] [pid 765155:tid 765320] [client 103.215.74.26:12766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLb-T5hFAbD-LhWHiFEgAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:44.220715 2026] [security2:error] [pid 765155:tid 765405] [client 20.52.125.110:6726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuLcOT5hFAbD-LhWHiFLwAAAP0"]
[Thu Jul 30 12:35:44.469383 2026] [core:error] [pid 765155:tid 765383] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.469408 2026] [core:error] [pid 765155:tid 765383] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.510131 2026] [core:error] [pid 765155:tid 765328] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.510158 2026] [core:error] [pid 765155:tid 765328] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.531347 2026] [core:error] [pid 765155:tid 765349] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.531367 2026] [core:error] [pid 765155:tid 765349] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.543484 2026] [core:error] [pid 765155:tid 765295] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.543502 2026] [core:error] [pid 765155:tid 765295] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.545950 2026] [core:error] [pid 765155:tid 765353] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.545989 2026] [core:error] [pid 765155:tid 765353] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:44.549859 2026] [core:notice] [pid 765155:tid 765340] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:44.554168 2026] [security2:error] [pid 765155:tid 765340] [client 103.215.74.26:12780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLcOT5hFAbD-LhWHiFWAAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:44.792761 2026] [security2:error] [pid 765155:tid 765404] [client 20.52.125.110:6848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuLcOT5hFAbD-LhWHiFWwAAAPw"]
[Thu Jul 30 12:35:45.255514 2026] [security2:error] [pid 765155:tid 765329] [client 20.52.125.110:6735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuLceT5hFAbD-LhWHiFZQAAALE"]
[Thu Jul 30 12:35:45.288668 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:45.292706 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:12792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLceT5hFAbD-LhWHiFZgAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:45.803954 2026] [security2:error] [pid 765155:tid 765345] [client 20.52.125.110:6727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuLceT5hFAbD-LhWHiFdQAAAME"]
[Thu Jul 30 12:35:46.008787 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:46.012851 2026] [security2:error] [pid 765155:tid 765328] [client 103.215.74.26:12806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLcuT5hFAbD-LhWHiFeQAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:46.062839 2026] [proxy:error] [pid 765155:tid 765371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:46.062913 2026] [proxy_http:error] [pid 765155:tid 765371] [client 3.228.112.215:17611] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:46.063733 2026] [proxy:error] [pid 765155:tid 765371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:35:46.063779 2026] [proxy_http:error] [pid 765155:tid 765371] [client 3.228.112.215:17611] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:35:46.124640 2026] [security2:error] [pid 765155:tid 765351] [client 20.63.98.115:20678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuLcuT5hFAbD-LhWHiFhAAAAMc"]
[Thu Jul 30 12:35:46.370904 2026] [security2:error] [pid 765155:tid 765340] [client 20.52.125.110:6894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuLcuT5hFAbD-LhWHiFhgAAALw"]
[Thu Jul 30 12:35:46.747263 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:46.751274 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:12810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLcuT5hFAbD-LhWHiFmAAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:46.920766 2026] [security2:error] [pid 765155:tid 765292] [client 20.52.125.110:6733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuLcuT5hFAbD-LhWHiFmQAAAIw"]
[Thu Jul 30 12:35:47.129168 2026] [security2:error] [pid 765155:tid 765389] [client 20.63.98.115:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuLc-T5hFAbD-LhWHiFoQAAAO0"]
[Thu Jul 30 12:35:47.463916 2026] [core:notice] [pid 765155:tid 765406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:47.468286 2026] [security2:error] [pid 765155:tid 765406] [client 103.215.74.26:12820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLc-T5hFAbD-LhWHiFpwAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:47.487547 2026] [security2:error] [pid 765155:tid 765290] [client 20.52.125.110:6731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuLc-T5hFAbD-LhWHiFqgAAAIo"]
[Thu Jul 30 12:35:47.997322 2026] [security2:error] [pid 765155:tid 765374] [client 20.52.125.110:6869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuLc-T5hFAbD-LhWHiFtAAAAN4"]
[Thu Jul 30 12:35:48.189939 2026] [core:notice] [pid 765155:tid 765369] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:48.198988 2026] [security2:error] [pid 765155:tid 765369] [client 103.215.74.26:12822] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLdOT5hFAbD-LhWHiFvwAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:48.348899 2026] [security2:error] [pid 765155:tid 765295] [client 20.63.98.115:20548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/manager.php"] [unique_id "amuLdOT5hFAbD-LhWHiFwwAAAI8"]
[Thu Jul 30 12:35:48.609894 2026] [security2:error] [pid 765155:tid 765395] [client 74.7.244.42:59884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-c5bc3a80.qgb.djb.temporary.site"] [uri "/index.php"] [unique_id "amuLc-T5hFAbD-LhWHiFsQAA8yA"]
[Thu Jul 30 12:35:48.756932 2026] [security2:error] [pid 765155:tid 765412] [client 20.52.125.110:6872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/bek.php"] [unique_id "amuLdOT5hFAbD-LhWHiF0AAAAQQ"]
[Thu Jul 30 12:35:48.932855 2026] [core:notice] [pid 765155:tid 765315] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:48.939646 2026] [security2:error] [pid 765155:tid 765315] [client 103.215.74.26:12832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLdOT5hFAbD-LhWHiF0gAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:48.943108 2026] [core:notice] [pid 765155:tid 765382] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:49.342929 2026] [security2:error] [pid 765155:tid 765365] [client 20.52.125.110:6878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuLdeT5hFAbD-LhWHiF3QAAANU"]
[Thu Jul 30 12:35:49.665298 2026] [core:notice] [pid 765155:tid 765339] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:49.669322 2026] [security2:error] [pid 765155:tid 765339] [client 103.215.74.26:12840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLdeT5hFAbD-LhWHiF4QAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:49.951906 2026] [security2:error] [pid 765155:tid 765290] [client 20.52.125.110:6778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/class.api.php"] [unique_id "amuLdeT5hFAbD-LhWHiF6AAAAIo"]
[Thu Jul 30 12:35:50.400533 2026] [core:notice] [pid 765155:tid 765398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:50.404505 2026] [security2:error] [pid 765155:tid 765398] [client 103.215.74.26:12850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLduT5hFAbD-LhWHiF8gAAAPY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:50.412401 2026] [core:error] [pid 765155:tid 765200] [remote 74.7.244.29:59842] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:50.412429 2026] [core:error] [pid 765155:tid 765200] [remote 74.7.244.29:59842] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:50.412593 2026] [security2:error] [pid 765155:tid 765372] [client 74.7.244.29:59842] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-e5d39057.jst.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuLduT5hFAbD-LhWHiF8wAA3Cw"]
[Thu Jul 30 12:35:50.504163 2026] [security2:error] [pid 765155:tid 765411] [client 20.52.125.110:6728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/cong.php"] [unique_id "amuLduT5hFAbD-LhWHiF9AAAAQM"]
[Thu Jul 30 12:35:50.694357 2026] [core:notice] [pid 765155:tid 765371] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:50.870514 2026] [security2:error] [pid 765155:tid 765394] [client 20.63.98.115:65408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-links.php"] [unique_id "amuLduT5hFAbD-LhWHiF_wAAAPI"]
[Thu Jul 30 12:35:51.059222 2026] [security2:error] [pid 765155:tid 765362] [client 20.52.125.110:6860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/content.php"] [unique_id "amuLd-T5hFAbD-LhWHiGAAAAANI"]
[Thu Jul 30 12:35:51.144247 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:51.151174 2026] [security2:error] [pid 765155:tid 765370] [client 103.215.74.26:12862] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLd-T5hFAbD-LhWHiGAQAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:51.341546 2026] [security2:error] [pid 765155:tid 765319] [client 185.191.171.15:64988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuLd-T5hFAbD-LhWHiGCAAAAKc"]
[Thu Jul 30 12:35:51.341657 2026] [security2:error] [pid 765155:tid 765319] [client 185.191.171.15:64988] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuLd-T5hFAbD-LhWHiGCAAAAKc"]
[Thu Jul 30 12:35:51.542904 2026] [security2:error] [pid 765155:tid 765315] [client 20.52.125.110:6897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuLd-T5hFAbD-LhWHiGDQAAAKM"]
[Thu Jul 30 12:35:51.671537 2026] [core:notice] [pid 765155:tid 765317] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:51.864707 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:51.869480 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:12866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "786"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLd-T5hFAbD-LhWHiGFQAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:51.977283 2026] [security2:error] [pid 765155:tid 765307] [client 49.47.10.252:34278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLd-T5hFAbD-LhWHiGDgAAAJs"], referer: http://pkf.jo
[Thu Jul 30 12:35:52.055658 2026] [security2:error] [pid 765155:tid 765311] [client 20.52.125.110:6725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/elp.php"] [unique_id "amuLeOT5hFAbD-LhWHiGGgAAAJ8"]
[Thu Jul 30 12:35:52.347183 2026] [security2:error] [pid 765155:tid 765401] [client 20.63.98.115:58219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/fi2.php"] [unique_id "amuLeOT5hFAbD-LhWHiGIgAAAPk"]
[Thu Jul 30 12:35:52.499547 2026] [security2:error] [pid 765155:tid 765372] [client 20.52.125.110:6870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuLeOT5hFAbD-LhWHiGIwAAANw"]
[Thu Jul 30 12:35:52.523321 2026] [security2:error] [pid 765155:tid 765355] [client 185.191.171.1:54944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2023/09/cara-menghilangkan-internet-baik"] [unique_id "amuLeOT5hFAbD-LhWHiGJAAAAMs"]
[Thu Jul 30 12:35:52.523461 2026] [security2:error] [pid 765155:tid 765355] [client 185.191.171.1:54944] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2023/09/cara-menghilangkan-internet-baik"] [unique_id "amuLeOT5hFAbD-LhWHiGJAAAAMs"]
[Thu Jul 30 12:35:52.585827 2026] [core:notice] [pid 765155:tid 765227] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:52.592736 2026] [security2:error] [pid 765155:tid 765384] [client 83.44.180.240:54216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLeOT5hFAbD-LhWHiGHwAAAOg"], referer: http://pkf.jo
[Thu Jul 30 12:35:52.632263 2026] [core:notice] [pid 765155:tid 765354] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:52.636231 2026] [security2:error] [pid 765155:tid 765354] [client 103.215.74.26:12878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLeOT5hFAbD-LhWHiGJwAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:53.064206 2026] [security2:error] [pid 765155:tid 765328] [client 20.52.125.110:6730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuLeeT5hFAbD-LhWHiGNAAAALA"]
[Thu Jul 30 12:35:53.366701 2026] [core:notice] [pid 765155:tid 765404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:53.370761 2026] [security2:error] [pid 765155:tid 765404] [client 103.215.74.26:12954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLeeT5hFAbD-LhWHiGPAAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:53.558200 2026] [security2:error] [pid 765155:tid 765368] [client 20.63.98.115:20735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/0x.php"] [unique_id "amuLeeT5hFAbD-LhWHiGQQAAANg"]
[Thu Jul 30 12:35:53.660814 2026] [security2:error] [pid 765155:tid 765367] [client 20.52.125.110:6906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuLeeT5hFAbD-LhWHiGQwAAANc"]
[Thu Jul 30 12:35:54.115633 2026] [core:notice] [pid 765155:tid 765373] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:54.120633 2026] [security2:error] [pid 765155:tid 765373] [client 103.215.74.26:12958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLeuT5hFAbD-LhWHiGTQAAAN0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:54.243372 2026] [core:notice] [pid 765155:tid 765347] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:54.326697 2026] [security2:error] [pid 765155:tid 765324] [client 20.52.125.110:6741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuLeuT5hFAbD-LhWHiGUwAAAKw"]
[Thu Jul 30 12:35:54.541293 2026] [core:error] [pid 765155:tid 765231] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.541322 2026] [core:error] [pid 765155:tid 765231] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.544841 2026] [core:error] [pid 765155:tid 765235] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.544858 2026] [core:error] [pid 765155:tid 765235] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.615111 2026] [core:error] [pid 765155:tid 765253] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.615152 2026] [core:error] [pid 765155:tid 765253] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.631778 2026] [core:error] [pid 765155:tid 765168] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.631795 2026] [core:error] [pid 765155:tid 765168] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.646877 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:54.672860 2026] [core:error] [pid 765155:tid 765249] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.672884 2026] [core:error] [pid 765155:tid 765249] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.690536 2026] [core:error] [pid 765155:tid 765228] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.690559 2026] [core:error] [pid 765155:tid 765228] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:35:54.768903 2026] [security2:error] [pid 765155:tid 765296] [client 20.63.98.115:44099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/k.php"] [unique_id "amuLeuT5hFAbD-LhWHiGbgAAAJA"]
[Thu Jul 30 12:35:54.853935 2026] [security2:error] [pid 765155:tid 765340] [client 37.120.155.179:37948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.155.120.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuLeuT5hFAbD-LhWHiGcQAAALw"]
[Thu Jul 30 12:35:54.854048 2026] [security2:error] [pid 765155:tid 765340] [client 37.120.155.179:37948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuLeuT5hFAbD-LhWHiGcQAAALw"]
[Thu Jul 30 12:35:54.896027 2026] [core:notice] [pid 765155:tid 765295] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:54.900648 2026] [security2:error] [pid 765155:tid 765295] [client 103.215.74.26:12960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLeuT5hFAbD-LhWHiGcgAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:54.914241 2026] [security2:error] [pid 765155:tid 765387] [client 20.52.125.110:6909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuLeuT5hFAbD-LhWHiGcwAAAOs"]
[Thu Jul 30 12:35:55.508722 2026] [security2:error] [pid 765155:tid 765382] [client 20.52.125.110:6867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuLe-T5hFAbD-LhWHiGgQAAAOY"]
[Thu Jul 30 12:35:55.615545 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:55.620147 2026] [security2:error] [pid 765155:tid 765304] [client 103.215.74.26:12962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLe-T5hFAbD-LhWHiGhgAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:55.669994 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:56.115120 2026] [security2:error] [pid 765155:tid 765324] [client 20.52.125.110:6768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuLfOT5hFAbD-LhWHiGmAAAAKw"]
[Thu Jul 30 12:35:56.121621 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:56.335992 2026] [security2:error] [pid 765155:tid 765241] [remote 74.7.241.60:42332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amuLfOT5hFAbD-LhWHiGnQAA21U"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:35:56.359333 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:56.363410 2026] [security2:error] [pid 765155:tid 765356] [client 103.215.74.26:12976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLfOT5hFAbD-LhWHiGngAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:56.442494 2026] [security2:error] [pid 765155:tid 765357] [client 20.63.98.115:20718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gecko-new.php"] [unique_id "amuLfOT5hFAbD-LhWHiGnwAAAM0"]
[Thu Jul 30 12:35:56.692841 2026] [security2:error] [pid 765155:tid 765376] [client 20.52.125.110:6853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuLfOT5hFAbD-LhWHiGrAAAAOA"]
[Thu Jul 30 12:35:56.819870 2026] [security2:error] [pid 765155:tid 765411] [client 196.191.176.201:14475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLfOT5hFAbD-LhWHiGpAAAAQM"], referer: http://pkf.jo
[Thu Jul 30 12:35:57.101574 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:57.106105 2026] [security2:error] [pid 765155:tid 765314] [client 103.215.74.26:12992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLfeT5hFAbD-LhWHiGtgAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:57.209602 2026] [security2:error] [pid 765155:tid 765327] [client 20.52.125.110:6874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuLfeT5hFAbD-LhWHiGugAAAK8"]
[Thu Jul 30 12:35:57.786141 2026] [security2:error] [pid 765155:tid 765409] [client 20.52.125.110:7363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuLfeT5hFAbD-LhWHiGygAAAQE"]
[Thu Jul 30 12:35:57.808724 2026] [security2:error] [pid 765155:tid 765361] [client 74.7.175.190:43974] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "moswey.com"] [uri "/robots.txt"] [unique_id "amuLfeT5hFAbD-LhWHiGywAA0X0"]
[Thu Jul 30 12:35:57.827382 2026] [core:notice] [pid 765155:tid 765346] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:57.831746 2026] [security2:error] [pid 765155:tid 765346] [client 103.215.74.26:12996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLfeT5hFAbD-LhWHiGzAAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:58.020383 2026] [security2:error] [pid 765155:tid 765408] [client 85.208.96.205:24796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/20/parceria-entre-creci-pb-e-tj-facilitara-prestacao-jurisdicional/"] [unique_id "amuLfuT5hFAbD-LhWHiGzQAAAQA"]
[Thu Jul 30 12:35:58.020518 2026] [security2:error] [pid 765155:tid 765408] [client 85.208.96.205:24796] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/20/parceria-entre-creci-pb-e-tj-facilitara-prestacao-jurisdicional/"] [unique_id "amuLfuT5hFAbD-LhWHiGzQAAAQA"]
[Thu Jul 30 12:35:58.247418 2026] [security2:error] [pid 765155:tid 765345] [client 20.52.125.110:7380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuLfuT5hFAbD-LhWHiG1gAAAME"]
[Thu Jul 30 12:35:58.413388 2026] [core:notice] [pid 765155:tid 765164] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:58.569468 2026] [core:notice] [pid 765155:tid 765354] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:58.573682 2026] [security2:error] [pid 765155:tid 765354] [client 103.215.74.26:13006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLfuT5hFAbD-LhWHiG3QAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:58.785702 2026] [security2:error] [pid 765155:tid 765360] [client 20.52.125.110:6739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuLfuT5hFAbD-LhWHiG4QAAANA"]
[Thu Jul 30 12:35:59.311847 2026] [security2:error] [pid 765155:tid 765286] [client 20.52.125.110:7367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuLf-T5hFAbD-LhWHiG6wAAAIY"]
[Thu Jul 30 12:35:59.315028 2026] [core:notice] [pid 765155:tid 765348] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:35:59.320408 2026] [security2:error] [pid 765155:tid 765348] [client 103.215.74.26:13020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLf-T5hFAbD-LhWHiG7AAAAMQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:35:59.357665 2026] [security2:error] [pid 765155:tid 765398] [client 20.63.98.115:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/alfanew.php"] [unique_id "amuLf-T5hFAbD-LhWHiG7wAAAPY"]
[Thu Jul 30 12:36:00.046243 2026] [core:notice] [pid 765155:tid 765368] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:00.050967 2026] [security2:error] [pid 765155:tid 765368] [client 103.215.74.26:13036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLgOT5hFAbD-LhWHiG_QAAANg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:00.070685 2026] [security2:error] [pid 765155:tid 765317] [client 20.52.125.110:6890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuLgOT5hFAbD-LhWHiG_gAAAKU"]
[Thu Jul 30 12:36:00.447016 2026] [security2:error] [pid 765155:tid 765405] [client 38.190.144.4:64472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLgOT5hFAbD-LhWHiHCQAAAP0"]
[Thu Jul 30 12:36:00.447148 2026] [security2:error] [pid 765155:tid 765405] [client 38.190.144.4:64472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLgOT5hFAbD-LhWHiHCQAAAP0"]
[Thu Jul 30 12:36:00.638431 2026] [security2:error] [pid 765155:tid 765318] [client 20.52.125.110:6895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuLgOT5hFAbD-LhWHiHCgAAAKY"]
[Thu Jul 30 12:36:01.215690 2026] [core:error] [pid 765155:tid 765395] [client 74.7.228.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:01.215711 2026] [core:error] [pid 765155:tid 765395] [client 74.7.228.15:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:01.215839 2026] [security2:error] [pid 765155:tid 765395] [client 74.7.228.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.vvr.hfl.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuLgeT5hFAbD-LhWHiHFgAAAPM"]
[Thu Jul 30 12:36:01.216381 2026] [security2:error] [pid 765155:tid 765376] [client 74.7.228.15:57074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.vvr.hfl.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuLgeT5hFAbD-LhWHiHFAAA4Ak"]
[Thu Jul 30 12:36:01.227714 2026] [security2:error] [pid 765155:tid 765316] [client 20.63.98.115:58202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/text.php"] [unique_id "amuLgeT5hFAbD-LhWHiHFwAAAKQ"]
[Thu Jul 30 12:36:01.349869 2026] [security2:error] [pid 765155:tid 765364] [client 20.52.125.110:6861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuLgeT5hFAbD-LhWHiHHgAAANQ"]
[Thu Jul 30 12:36:02.014231 2026] [security2:error] [pid 765155:tid 765367] [client 20.52.125.110:6900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuLguT5hFAbD-LhWHiHMAAAANc"]
[Thu Jul 30 12:36:02.338997 2026] [security2:error] [pid 765155:tid 765304] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLgeT5hFAbD-LhWHiHJQAAmAI"]
[Thu Jul 30 12:36:02.457965 2026] [security2:error] [pid 765155:tid 765410] [client 68.221.69.72:38391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuLguT5hFAbD-LhWHiHOgAAAQI"]
[Thu Jul 30 12:36:02.458109 2026] [security2:error] [pid 765155:tid 765410] [client 68.221.69.72:38391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuLguT5hFAbD-LhWHiHOgAAAQI"]
[Thu Jul 30 12:36:03.044741 2026] [security2:error] [pid 765155:tid 765288] [client 20.52.125.110:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuLg-T5hFAbD-LhWHiHRwAAAIg"]
[Thu Jul 30 12:36:03.329502 2026] [security2:error] [pid 765155:tid 765342] [client 68.221.69.72:64775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuLg-T5hFAbD-LhWHiHTwAAAL4"]
[Thu Jul 30 12:36:03.329610 2026] [security2:error] [pid 765155:tid 765342] [client 68.221.69.72:64775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuLg-T5hFAbD-LhWHiHTwAAAL4"]
[Thu Jul 30 12:36:03.623925 2026] [security2:error] [pid 765155:tid 765382] [client 20.52.125.110:7470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuLg-T5hFAbD-LhWHiHWwAAAOY"]
[Thu Jul 30 12:36:03.680537 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/f.php"] [unique_id "amuLg-T5hFAbD-LhWHiHXAAAAKk"]
[Thu Jul 30 12:36:04.072283 2026] [security2:error] [pid 765155:tid 765327] [client 74.7.241.128:58928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.mobileblooddrawservices-com.aws.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuLg-T5hFAbD-LhWHiHWAAArxw"]
[Thu Jul 30 12:36:04.157670 2026] [security2:error] [pid 765155:tid 765361] [client 138.186.20.11:44572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLg-T5hFAbD-LhWHiHYQAAANE"], referer: http://pkf.jo
[Thu Jul 30 12:36:04.398872 2026] [security2:error] [pid 765155:tid 765392] [client 20.52.125.110:6862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuLhOT5hFAbD-LhWHiHbgAAAPA"]
[Thu Jul 30 12:36:04.546926 2026] [security2:error] [pid 765155:tid 765410] [client 20.63.98.115:21203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuLhOT5hFAbD-LhWHiHcwAAAQI"]
[Thu Jul 30 12:36:04.748667 2026] [security2:error] [pid 765155:tid 765362] [client 68.221.69.72:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuLhOT5hFAbD-LhWHiHdwAAANI"]
[Thu Jul 30 12:36:04.748777 2026] [security2:error] [pid 765155:tid 765362] [client 68.221.69.72:14604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuLhOT5hFAbD-LhWHiHdwAAANI"]
[Thu Jul 30 12:36:04.936992 2026] [security2:error] [pid 765155:tid 765387] [client 20.52.125.110:7463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuLhOT5hFAbD-LhWHiHggAAAOs"]
[Thu Jul 30 12:36:05.467125 2026] [security2:error] [pid 765155:tid 765206] [remote 151.158.180.11:59620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.180.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuLheT5hFAbD-LhWHiHnQAAwjI"]
[Thu Jul 30 12:36:05.576428 2026] [security2:error] [pid 765155:tid 765302] [client 20.52.125.110:7456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuLheT5hFAbD-LhWHiHoQAAAJY"]
[Thu Jul 30 12:36:05.855546 2026] [core:notice] [pid 765155:tid 765326] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:05.861003 2026] [security2:error] [pid 765155:tid 765326] [client 103.215.74.26:29056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLheT5hFAbD-LhWHiHrgAAAK4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:06.005643 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:21495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/hehe.php"] [unique_id "amuLhuT5hFAbD-LhWHiHswAAAKk"]
[Thu Jul 30 12:36:06.234316 2026] [security2:error] [pid 765155:tid 765357] [client 20.52.125.110:7486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuLhuT5hFAbD-LhWHiHuwAAAM0"]
[Thu Jul 30 12:36:06.411670 2026] [security2:error] [pid 765155:tid 765319] [client 68.221.69.72:64796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/err.php"] [unique_id "amuLhuT5hFAbD-LhWHiHvgAAAKc"]
[Thu Jul 30 12:36:06.411764 2026] [security2:error] [pid 765155:tid 765319] [client 68.221.69.72:64796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/err.php"] [unique_id "amuLhuT5hFAbD-LhWHiHvgAAAKc"]
[Thu Jul 30 12:36:06.587302 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:06.591666 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:29066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLhuT5hFAbD-LhWHiHxwAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:06.744258 2026] [security2:error] [pid 765155:tid 765379] [client 20.63.98.115:21501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/options.php"] [unique_id "amuLhuT5hFAbD-LhWHiHywAAAOM"]
[Thu Jul 30 12:36:06.849607 2026] [security2:error] [pid 765155:tid 765356] [client 20.52.125.110:7458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuLhuT5hFAbD-LhWHiHzQAAAMw"]
[Thu Jul 30 12:36:07.314146 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:07.318599 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:29082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLh-T5hFAbD-LhWHiH2AAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:07.432019 2026] [security2:error] [pid 765155:tid 765350] [client 20.52.125.110:6855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuLh-T5hFAbD-LhWHiH3AAAAMY"]
[Thu Jul 30 12:36:08.025007 2026] [security2:error] [pid 765155:tid 765318] [client 20.52.125.110:7465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuLiOT5hFAbD-LhWHiH6QAAAKY"]
[Thu Jul 30 12:36:08.062247 2026] [core:notice] [pid 765155:tid 765369] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:08.066910 2026] [security2:error] [pid 765155:tid 765369] [client 103.215.74.26:29086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLiOT5hFAbD-LhWHiH6gAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:08.089299 2026] [security2:error] [pid 765155:tid 765287] [client 50.6.43.217:21580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuLiOT5hFAbD-LhWHiH6wAAAIc"]
[Thu Jul 30 12:36:08.098957 2026] [security2:error] [pid 765155:tid 765340] [client 50.6.43.217:21590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuLiOT5hFAbD-LhWHiH7AAAALw"]
[Thu Jul 30 12:36:08.108294 2026] [security2:error] [pid 765155:tid 765311] [client 50.6.43.217:21598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuLiOT5hFAbD-LhWHiH7QAAAJ8"]
[Thu Jul 30 12:36:08.467796 2026] [security2:error] [pid 765155:tid 765357] [client 216.73.216.110:17171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ajakholding.net"] [uri "/index.php"] [unique_id "amuLiOT5hFAbD-LhWHiH-AAAzV4"]
[Thu Jul 30 12:36:08.685702 2026] [security2:error] [pid 765155:tid 765337] [client 20.52.125.110:7462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuLiOT5hFAbD-LhWHiIAQAAALk"]
[Thu Jul 30 12:36:08.792098 2026] [core:notice] [pid 765155:tid 765403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:08.795998 2026] [security2:error] [pid 765155:tid 765403] [client 103.215.74.26:29094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLiOT5hFAbD-LhWHiICQAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:08.807609 2026] [security2:error] [pid 765155:tid 765312] [client 68.221.69.72:38354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/img.php"] [unique_id "amuLiOT5hFAbD-LhWHiICgAAAKA"]
[Thu Jul 30 12:36:08.807750 2026] [security2:error] [pid 765155:tid 765312] [client 68.221.69.72:38354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/img.php"] [unique_id "amuLiOT5hFAbD-LhWHiICgAAAKA"]
[Thu Jul 30 12:36:09.098509 2026] [security2:error] [pid 765155:tid 765307] [client 80.79.150.22:7058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLiOT5hFAbD-LhWHiIBwAAAJs"], referer: http://pkf.jo
[Thu Jul 30 12:36:09.286972 2026] [security2:error] [pid 765155:tid 765363] [client 20.52.125.110:7464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuLieT5hFAbD-LhWHiIEwAAANM"]
[Thu Jul 30 12:36:09.520866 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:09.528562 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:29110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLieT5hFAbD-LhWHiIGAAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:09.720248 2026] [security2:error] [pid 765155:tid 765292] [client 172.237.109.114:16270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiICwAAAIw"]
[Thu Jul 30 12:36:09.730540 2026] [security2:error] [pid 765155:tid 765406] [client 172.237.109.114:45394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiIDgAAAP4"]
[Thu Jul 30 12:36:09.734687 2026] [security2:error] [pid 765155:tid 765373] [client 172.237.109.114:10341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiIDQAAAN0"]
[Thu Jul 30 12:36:09.734793 2026] [security2:error] [pid 765155:tid 765325] [client 172.237.109.114:55013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiIDAAAAK0"]
[Thu Jul 30 12:36:09.742804 2026] [security2:error] [pid 765155:tid 765382] [client 172.237.109.114:18747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLieT5hFAbD-LhWHiIDwAAAOY"]
[Thu Jul 30 12:36:09.851569 2026] [security2:error] [pid 765155:tid 765401] [client 20.52.125.110:6865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuLieT5hFAbD-LhWHiIJQAAAPk"]
[Thu Jul 30 12:36:10.246605 2026] [security2:error] [pid 765155:tid 765385] [client 20.63.98.115:21215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuLiuT5hFAbD-LhWHiIMAAAAOk"]
[Thu Jul 30 12:36:10.256318 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:10.260272 2026] [security2:error] [pid 765155:tid 765377] [client 103.215.74.26:29126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "746"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLiuT5hFAbD-LhWHiIMQAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:10.445028 2026] [security2:error] [pid 765155:tid 765347] [client 20.52.125.110:7439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuLiuT5hFAbD-LhWHiINQAAAMM"]
[Thu Jul 30 12:36:10.749389 2026] [security2:error] [pid 765155:tid 765397] [client 68.221.69.72:38394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/aa.php"] [unique_id "amuLiuT5hFAbD-LhWHiIPAAAAPU"]
[Thu Jul 30 12:36:10.749524 2026] [security2:error] [pid 765155:tid 765397] [client 68.221.69.72:38394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/aa.php"] [unique_id "amuLiuT5hFAbD-LhWHiIPAAAAPU"]
[Thu Jul 30 12:36:11.003720 2026] [core:notice] [pid 765155:tid 765292] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:11.008428 2026] [security2:error] [pid 765155:tid 765292] [client 103.215.74.26:29138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLi-T5hFAbD-LhWHiIQAAAAIw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:11.045965 2026] [security2:error] [pid 765155:tid 765402] [client 20.52.125.110:7470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuLi-T5hFAbD-LhWHiIQQAAAPo"]
[Thu Jul 30 12:36:11.099750 2026] [security2:error] [pid 765155:tid 765340] [client 20.63.98.115:62424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/images/index.php"] [unique_id "amuLi-T5hFAbD-LhWHiIQgAAALw"]
[Thu Jul 30 12:36:11.284777 2026] [security2:error] [pid 765155:tid 765345] [client 38.190.144.4:64975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLi-T5hFAbD-LhWHiITAAAAME"]
[Thu Jul 30 12:36:11.284884 2026] [security2:error] [pid 765155:tid 765345] [client 38.190.144.4:64975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLi-T5hFAbD-LhWHiITAAAAME"]
[Thu Jul 30 12:36:11.637735 2026] [security2:error] [pid 765155:tid 765289] [client 20.52.125.110:7484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuLi-T5hFAbD-LhWHiIUQAAAIk"]
[Thu Jul 30 12:36:11.737639 2026] [core:error] [pid 765155:tid 765337] [client 199.45.154.158:50956] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:11.737659 2026] [core:error] [pid 765155:tid 765337] [client 199.45.154.158:50956] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:11.738074 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:11.744108 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:29144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLi-T5hFAbD-LhWHiIWQAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:11.845084 2026] [core:error] [pid 765155:tid 765411] [client 74.7.230.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:11.845111 2026] [core:error] [pid 765155:tid 765411] [client 74.7.230.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:11.845230 2026] [security2:error] [pid 765155:tid 765411] [client 74.7.230.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.rru.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuLi-T5hFAbD-LhWHiIXAAAAQM"]
[Thu Jul 30 12:36:11.845831 2026] [security2:error] [pid 765155:tid 765403] [client 74.7.230.30:32984] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.rru.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuLi-T5hFAbD-LhWHiIWgAA-3o"]
[Thu Jul 30 12:36:12.174789 2026] [security2:error] [pid 765155:tid 765407] [client 74.7.230.0:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-468361c2.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuLi-T5hFAbD-LhWHiIXwAAAP8"]
[Thu Jul 30 12:36:12.175744 2026] [security2:error] [pid 765155:tid 765390] [client 74.7.230.0:48470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-468361c2.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuLi-T5hFAbD-LhWHiIXQAA7g8"]
[Thu Jul 30 12:36:12.279185 2026] [security2:error] [pid 765155:tid 765384] [client 68.221.69.72:38375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/av.php"] [unique_id "amuLjOT5hFAbD-LhWHiIawAAAOg"]
[Thu Jul 30 12:36:12.279302 2026] [security2:error] [pid 765155:tid 765384] [client 68.221.69.72:38375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/av.php"] [unique_id "amuLjOT5hFAbD-LhWHiIawAAAOg"]
[Thu Jul 30 12:36:12.490737 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:12.497518 2026] [security2:error] [pid 765155:tid 765361] [client 103.215.74.26:29148] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLjOT5hFAbD-LhWHiIcwAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:12.516059 2026] [security2:error] [pid 765155:tid 765391] [client 20.52.125.110:6898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.progroupdoha.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuLjOT5hFAbD-LhWHiIdAAAAO8"]
[Thu Jul 30 12:36:12.770731 2026] [security2:error] [pid 765155:tid 765353] [client 20.63.98.115:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amuLjOT5hFAbD-LhWHiIewAAAMk"]
[Thu Jul 30 12:36:13.197999 2026] [security2:error] [pid 765155:tid 765401] [client 41.251.191.60:60624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLjOT5hFAbD-LhWHiIfgAAAPk"], referer: http://pkf.jo
[Thu Jul 30 12:36:13.239458 2026] [core:notice] [pid 765155:tid 765316] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:13.243712 2026] [security2:error] [pid 765155:tid 765316] [client 103.215.74.26:58130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLjeT5hFAbD-LhWHiIhAAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:13.497241 2026] [security2:error] [pid 765155:tid 765295] [client 185.182.217.177:37154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLjeT5hFAbD-LhWHiIgwAAAI8"], referer: http://pkf.jo
[Thu Jul 30 12:36:13.786670 2026] [security2:error] [pid 765155:tid 765329] [client 68.221.69.72:64768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/xa.php"] [unique_id "amuLjeT5hFAbD-LhWHiIlwAAALE"]
[Thu Jul 30 12:36:13.786777 2026] [security2:error] [pid 765155:tid 765329] [client 68.221.69.72:64768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/xa.php"] [unique_id "amuLjeT5hFAbD-LhWHiIlwAAALE"]
[Thu Jul 30 12:36:13.789955 2026] [security2:error] [pid 765155:tid 765358] [client 20.63.98.115:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/13.php"] [unique_id "amuLjeT5hFAbD-LhWHiImAAAAM4"]
[Thu Jul 30 12:36:13.958072 2026] [core:notice] [pid 765155:tid 765293] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:13.963121 2026] [security2:error] [pid 765155:tid 765293] [client 103.215.74.26:58146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLjeT5hFAbD-LhWHiInAAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:14.479719 2026] [fcgid:warn] [pid 765155:tid 765309] (70014)End of file found: [client 165.154.138.79:35748] mod_fcgid: can't get data from http client
[Thu Jul 30 12:36:14.696097 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:14.703463 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:58160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLjuT5hFAbD-LhWHiIqwAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:14.789046 2026] [security2:error] [pid 765155:tid 765363] [client 72.255.16.111:17799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLjuT5hFAbD-LhWHiIpwAAANM"], referer: http://pkf.jo
[Thu Jul 30 12:36:15.257487 2026] [security2:error] [pid 765155:tid 765392] [client 43.172.194.170:46664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2010/08/09/mon-sac-de-plage-ideal-le-beach-shoulder-bag-folli-follie/"] [unique_id "amuLj-T5hFAbD-LhWHiIsgAAAPA"]
[Thu Jul 30 12:36:15.437295 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:15.441201 2026] [security2:error] [pid 765155:tid 765361] [client 103.215.74.26:58174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "778"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLj-T5hFAbD-LhWHiIvgAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:15.484484 2026] [security2:error] [pid 765155:tid 765349] [client 68.221.69.72:14603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/media.php"] [unique_id "amuLj-T5hFAbD-LhWHiIvwAAAMU"]
[Thu Jul 30 12:36:15.484598 2026] [security2:error] [pid 765155:tid 765349] [client 68.221.69.72:14603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/media.php"] [unique_id "amuLj-T5hFAbD-LhWHiIvwAAAMU"]
[Thu Jul 30 12:36:15.565077 2026] [security2:error] [pid 765155:tid 765340] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuLj-T5hFAbD-LhWHiIxgAAALw"]
[Thu Jul 30 12:36:15.565184 2026] [security2:error] [pid 765155:tid 765340] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuLj-T5hFAbD-LhWHiIxgAAALw"]
[Thu Jul 30 12:36:15.755005 2026] [security2:error] [pid 765155:tid 765341] [client 193.47.62.167:35356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ssa.djb.temporary.site"] [uri "/index.php"] [unique_id "amuLj-T5hFAbD-LhWHiIxwAAAL0"]
[Thu Jul 30 12:36:15.921268 2026] [core:error] [pid 765155:tid 765384] [client 20.63.98.115:20827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:15.921288 2026] [core:error] [pid 765155:tid 765384] [client 20.63.98.115:20827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:16.026417 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:16.031073 2026] [security2:error] [pid 765155:tid 765314] [client 43.173.173.8:56220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2010/08/09/mon-sac-de-plage-ideal-le-beach-shoulder-bag-folli-follie/"] [unique_id "amuLkOT5hFAbD-LhWHiIzwAAAKI"], referer: https://carnetdeshopping.com/index.php/2010/08/09/mon-sac-de-plage-ideal-le-beach-shoulder-bag-folli-follie/
[Thu Jul 30 12:36:16.068322 2026] [security2:error] [pid 765155:tid 765337] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuLkOT5hFAbD-LhWHiI0gAAALk"]
[Thu Jul 30 12:36:16.068426 2026] [security2:error] [pid 765155:tid 765337] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuLkOT5hFAbD-LhWHiI0gAAALk"]
[Thu Jul 30 12:36:16.171572 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:16.175614 2026] [security2:error] [pid 765155:tid 765378] [client 103.215.74.26:58190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLkOT5hFAbD-LhWHiI1QAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:16.272807 2026] [security2:error] [pid 765155:tid 765356] [client 68.221.69.72:38363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/images.php"] [unique_id "amuLkOT5hFAbD-LhWHiI1gAAAMw"]
[Thu Jul 30 12:36:16.272912 2026] [security2:error] [pid 765155:tid 765356] [client 68.221.69.72:38363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/images.php"] [unique_id "amuLkOT5hFAbD-LhWHiI1gAAAMw"]
[Thu Jul 30 12:36:16.604798 2026] [security2:error] [pid 765155:tid 765407] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/inputs.php"] [unique_id "amuLkOT5hFAbD-LhWHiI4AAAAP8"]
[Thu Jul 30 12:36:16.604924 2026] [security2:error] [pid 765155:tid 765407] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/inputs.php"] [unique_id "amuLkOT5hFAbD-LhWHiI4AAAAP8"]
[Thu Jul 30 12:36:16.753001 2026] [security2:error] [pid 765155:tid 765301] [client 20.63.98.115:62786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/inputs.php"] [unique_id "amuLkOT5hFAbD-LhWHiI6QAAAJU"]
[Thu Jul 30 12:36:16.887567 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:16.891338 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:58200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLkOT5hFAbD-LhWHiI7QAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:17.035765 2026] [security2:error] [pid 765155:tid 765400] [client 68.221.69.72:14616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/gecko.php"] [unique_id "amuLkeT5hFAbD-LhWHiI8gAAAPg"]
[Thu Jul 30 12:36:17.035890 2026] [security2:error] [pid 765155:tid 765400] [client 68.221.69.72:14616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/gecko.php"] [unique_id "amuLkeT5hFAbD-LhWHiI8gAAAPg"]
[Thu Jul 30 12:36:17.132145 2026] [security2:error] [pid 765155:tid 765327] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amuLkeT5hFAbD-LhWHiI-AAAAK8"]
[Thu Jul 30 12:36:17.132253 2026] [security2:error] [pid 765155:tid 765327] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amuLkeT5hFAbD-LhWHiI-AAAAK8"]
[Thu Jul 30 12:36:17.325100 2026] [security2:error] [pid 765155:tid 765325] [client 156.194.169.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLkeT5hFAbD-LhWHiI-wAAAK0"], referer: https://cnpinyin.com
[Thu Jul 30 12:36:17.577515 2026] [security2:error] [pid 765155:tid 765345] [client 68.221.69.72:65466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/82.php"] [unique_id "amuLkeT5hFAbD-LhWHiJCgAAAME"]
[Thu Jul 30 12:36:17.577627 2026] [security2:error] [pid 765155:tid 765345] [client 68.221.69.72:65466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/82.php"] [unique_id "amuLkeT5hFAbD-LhWHiJCgAAAME"]
[Thu Jul 30 12:36:17.650973 2026] [core:notice] [pid 765155:tid 765316] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:17.655072 2026] [security2:error] [pid 765155:tid 765316] [client 103.215.74.26:58216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLkeT5hFAbD-LhWHiJCwAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:17.663580 2026] [security2:error] [pid 765155:tid 765338] [client 20.63.98.115:62816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/jquery.php"] [unique_id "amuLkeT5hFAbD-LhWHiJDAAAALo"]
[Thu Jul 30 12:36:17.911999 2026] [security2:error] [pid 765155:tid 765344] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/goods.php"] [unique_id "amuLkeT5hFAbD-LhWHiJEwAAAMA"]
[Thu Jul 30 12:36:17.912085 2026] [security2:error] [pid 765155:tid 765344] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/goods.php"] [unique_id "amuLkeT5hFAbD-LhWHiJEwAAAMA"]
[Thu Jul 30 12:36:18.007108 2026] [security2:error] [pid 765155:tid 765402] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLkeT5hFAbD-LhWHiJAgAAAPo"]
[Thu Jul 30 12:36:18.393813 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:18.397794 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:58230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLkuT5hFAbD-LhWHiJHwAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:18.416841 2026] [security2:error] [pid 765155:tid 765380] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/file.php"] [unique_id "amuLkuT5hFAbD-LhWHiJIgAAAOQ"]
[Thu Jul 30 12:36:18.416924 2026] [security2:error] [pid 765155:tid 765380] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/file.php"] [unique_id "amuLkuT5hFAbD-LhWHiJIgAAAOQ"]
[Thu Jul 30 12:36:18.606643 2026] [security2:error] [pid 765155:tid 765399] [client 20.63.98.115:62846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/doc.php"] [unique_id "amuLkuT5hFAbD-LhWHiJJQAAAPc"]
[Thu Jul 30 12:36:18.609807 2026] [security2:error] [pid 765155:tid 765362] [client 68.221.69.72:64776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/xstelth.php"] [unique_id "amuLkuT5hFAbD-LhWHiJJgAAANI"]
[Thu Jul 30 12:36:18.609888 2026] [security2:error] [pid 765155:tid 765362] [client 68.221.69.72:64776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/xstelth.php"] [unique_id "amuLkuT5hFAbD-LhWHiJJgAAANI"]
[Thu Jul 30 12:36:18.895611 2026] [security2:error] [pid 765155:tid 765359] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/adminfuns.php"] [unique_id "amuLkuT5hFAbD-LhWHiJLgAAAM8"]
[Thu Jul 30 12:36:18.895708 2026] [security2:error] [pid 765155:tid 765359] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/adminfuns.php"] [unique_id "amuLkuT5hFAbD-LhWHiJLgAAAM8"]
[Thu Jul 30 12:36:19.114137 2026] [core:notice] [pid 765155:tid 765320] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:19.118076 2026] [security2:error] [pid 765155:tid 765320] [client 103.215.74.26:58238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLk-T5hFAbD-LhWHiJMgAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:19.389412 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/404.php"] [unique_id "amuLk-T5hFAbD-LhWHiJOgAAAJ8"]
[Thu Jul 30 12:36:19.389558 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/404.php"] [unique_id "amuLk-T5hFAbD-LhWHiJOgAAAJ8"]
[Thu Jul 30 12:36:19.831510 2026] [security2:error] [pid 765155:tid 765292] [client 105.165.75.222:38094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJPgAAAIw"], referer: http://pkf.jo
[Thu Jul 30 12:36:19.850758 2026] [security2:error] [pid 765155:tid 765371] [client 68.221.69.72:38365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/xp.php"] [unique_id "amuLk-T5hFAbD-LhWHiJRAAAANs"]
[Thu Jul 30 12:36:19.850922 2026] [security2:error] [pid 765155:tid 765371] [client 68.221.69.72:38365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/xp.php"] [unique_id "amuLk-T5hFAbD-LhWHiJRAAAANs"]
[Thu Jul 30 12:36:19.975134 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wk/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJTgAAAPM"]
[Thu Jul 30 12:36:19.975221 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wk/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJTgAAAPM"]
[Thu Jul 30 12:36:20.358599 2026] [fcgid:warn] [pid 765155:tid 765402] (70014)End of file found: [client 156.229.16.165:38084] mod_fcgid: can't get data from http client
[Thu Jul 30 12:36:20.367336 2026] [security2:error] [pid 765155:tid 765348] [client 119.73.97.132:31239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJSAAAxEI"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:36:20.367466 2026] [security2:error] [pid 765155:tid 765348] [client 119.73.97.132:31239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJQQAAxE8"]
[Thu Jul 30 12:36:20.367550 2026] [security2:error] [pid 765155:tid 765348] [client 119.73.97.132:31239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuLk-T5hFAbD-LhWHiJQgAAxGE"]
[Thu Jul 30 12:36:20.534848 2026] [security2:error] [pid 765155:tid 765389] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/about.php"] [unique_id "amuLlOT5hFAbD-LhWHiJXwAAAO0"]
[Thu Jul 30 12:36:20.534987 2026] [security2:error] [pid 765155:tid 765389] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/about.php"] [unique_id "amuLlOT5hFAbD-LhWHiJXwAAAO0"]
[Thu Jul 30 12:36:20.646562 2026] [security2:error] [pid 765155:tid 765306] [client 20.63.98.115:65429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/02.php"] [unique_id "amuLlOT5hFAbD-LhWHiJYgAAAJo"]
[Thu Jul 30 12:36:21.071039 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/term.php"] [unique_id "amuLleT5hFAbD-LhWHiJcAAAAQA"]
[Thu Jul 30 12:36:21.071145 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/term.php"] [unique_id "amuLleT5hFAbD-LhWHiJcAAAAQA"]
[Thu Jul 30 12:36:21.282150 2026] [proxy:error] [pid 765155:tid 765410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:21.282234 2026] [proxy_http:error] [pid 765155:tid 765410] [client 156.229.16.165:38094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:21.282815 2026] [proxy:error] [pid 765155:tid 765410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:21.282858 2026] [proxy_http:error] [pid 765155:tid 765410] [client 156.229.16.165:38094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:21.457704 2026] [security2:error] [pid 765155:tid 765327] [client 82.194.28.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLleT5hFAbD-LhWHiJeAAAAK8"], referer: https://cnpinyin.com
[Thu Jul 30 12:36:21.601820 2026] [security2:error] [pid 765155:tid 765375] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ioxi-o.php"] [unique_id "amuLleT5hFAbD-LhWHiJgwAAAN8"]
[Thu Jul 30 12:36:21.601992 2026] [security2:error] [pid 765155:tid 765375] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ioxi-o.php"] [unique_id "amuLleT5hFAbD-LhWHiJgwAAAN8"]
[Thu Jul 30 12:36:21.766372 2026] [security2:error] [pid 765155:tid 765311] [client 20.63.98.115:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/well-known/admin.php"] [unique_id "amuLleT5hFAbD-LhWHiJjQAAAJ8"]
[Thu Jul 30 12:36:21.768871 2026] [core:notice] [pid 765155:tid 765363] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:21.989682 2026] [security2:error] [pid 765155:tid 765304] [client 172.236.9.101:54281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLleT5hFAbD-LhWHiJegAAAJg"]
[Thu Jul 30 12:36:22.025677 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:57868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLleT5hFAbD-LhWHiJewAAAKM"]
[Thu Jul 30 12:36:22.115739 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amuLluT5hFAbD-LhWHiJxAAAAMs"]
[Thu Jul 30 12:36:22.115851 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amuLluT5hFAbD-LhWHiJxAAAAMs"]
[Thu Jul 30 12:36:22.115947 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amuLluT5hFAbD-LhWHiJxAAAAMs"]
[Thu Jul 30 12:36:22.210892 2026] [security2:error] [pid 765155:tid 765290] [client 39.63.38.93:48410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLleT5hFAbD-LhWHiJvQAAAIo"], referer: http://pkf.jo
[Thu Jul 30 12:36:22.229114 2026] [security2:error] [pid 765155:tid 765292] [client 38.190.144.4:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLluT5hFAbD-LhWHiJywAAAIw"]
[Thu Jul 30 12:36:22.229215 2026] [security2:error] [pid 765155:tid 765292] [client 38.190.144.4:65480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLluT5hFAbD-LhWHiJywAAAIw"]
[Thu Jul 30 12:36:22.393329 2026] [security2:error] [pid 765155:tid 765319] [client 178.20.45.159:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.45.20.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/register"] [unique_id "amuLluT5hFAbD-LhWHiJxQAAAKc"], referer: https://cnpinyin.com/register
[Thu Jul 30 12:36:22.496733 2026] [security2:error] [pid 765155:tid 765343] [client 68.221.69.72:38381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/admin.php"] [unique_id "amuLluT5hFAbD-LhWHiJ9gAAAL8"]
[Thu Jul 30 12:36:22.496895 2026] [security2:error] [pid 765155:tid 765343] [client 68.221.69.72:38381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/admin.php"] [unique_id "amuLluT5hFAbD-LhWHiJ9gAAAL8"]
[Thu Jul 30 12:36:22.595529 2026] [security2:error] [pid 765155:tid 765360] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/alfa.php"] [unique_id "amuLluT5hFAbD-LhWHiJ-wAAANA"]
[Thu Jul 30 12:36:22.595706 2026] [security2:error] [pid 765155:tid 765360] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/alfa.php"] [unique_id "amuLluT5hFAbD-LhWHiJ-wAAANA"]
[Thu Jul 30 12:36:22.854253 2026] [core:error] [pid 765155:tid 765333] [client 20.63.98.115:49759] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:22.854279 2026] [core:error] [pid 765155:tid 765333] [client 20.63.98.115:49759] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:22.921638 2026] [proxy:error] [pid 765155:tid 765411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:22.921738 2026] [proxy_http:error] [pid 765155:tid 765411] [client 156.229.16.165:38108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:22.922837 2026] [proxy:error] [pid 765155:tid 765411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:22.922899 2026] [proxy_http:error] [pid 765155:tid 765411] [client 156.229.16.165:38108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:23.033511 2026] [security2:error] [pid 765155:tid 765215] [remote 157.55.39.58:6634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/offres-demploi/article.php"] [unique_id "amuLl-T5hFAbD-LhWHiKBAAAvTs"]
[Thu Jul 30 12:36:23.097276 2026] [security2:error] [pid 765155:tid 765357] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/edit.php"] [unique_id "amuLl-T5hFAbD-LhWHiKCwAAAM0"]
[Thu Jul 30 12:36:23.097400 2026] [security2:error] [pid 765155:tid 765357] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/edit.php"] [unique_id "amuLl-T5hFAbD-LhWHiKCwAAAM0"]
[Thu Jul 30 12:36:23.216224 2026] [security2:error] [pid 765155:tid 765384] [client 178.20.45.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuLl-T5hFAbD-LhWHiKCgAAAOg"], referer: https://cnpinyin.com/register
[Thu Jul 30 12:36:23.490407 2026] [security2:error] [pid 765155:tid 765381] [client 172.236.9.101:5601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ2gAAAOU"]
[Thu Jul 30 12:36:23.605710 2026] [security2:error] [pid 765155:tid 765302] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/elp.php"] [unique_id "amuLl-T5hFAbD-LhWHiKGgAAAJY"]
[Thu Jul 30 12:36:23.605884 2026] [security2:error] [pid 765155:tid 765302] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/elp.php"] [unique_id "amuLl-T5hFAbD-LhWHiKGgAAAJY"]
[Thu Jul 30 12:36:23.654072 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:45037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ5AAAANg"]
[Thu Jul 30 12:36:23.671488 2026] [security2:error] [pid 765155:tid 765365] [client 172.236.9.101:65290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ2QAAANU"]
[Thu Jul 30 12:36:23.801094 2026] [security2:error] [pid 765155:tid 765391] [client 68.221.69.72:14629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/adminner.php"] [unique_id "amuLl-T5hFAbD-LhWHiKHAAAAO8"]
[Thu Jul 30 12:36:23.801243 2026] [security2:error] [pid 765155:tid 765391] [client 68.221.69.72:14629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/adminner.php"] [unique_id "amuLl-T5hFAbD-LhWHiKHAAAAO8"]
[Thu Jul 30 12:36:24.244704 2026] [security2:error] [pid 765155:tid 765285] [client 172.236.9.101:46315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ8QAAAIU"]
[Thu Jul 30 12:36:24.247801 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:53822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ2wAAAJo"]
[Thu Jul 30 12:36:24.253325 2026] [security2:error] [pid 765155:tid 765383] [client 172.236.9.101:42578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ3QAAAOc"]
[Thu Jul 30 12:36:24.267795 2026] [security2:error] [pid 765155:tid 765296] [client 172.236.9.101:11546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ5QAAAJA"]
[Thu Jul 30 12:36:24.272318 2026] [security2:error] [pid 765155:tid 765291] [client 172.236.9.101:36710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ4gAAAIs"]
[Thu Jul 30 12:36:24.282380 2026] [security2:error] [pid 765155:tid 765309] [client 172.236.9.101:9475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ5wAAAJ0"]
[Thu Jul 30 12:36:24.305143 2026] [security2:error] [pid 765155:tid 765407] [client 172.236.9.101:28791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ6AAAAP8"]
[Thu Jul 30 12:36:24.328230 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:65228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ4AAAANc"]
[Thu Jul 30 12:36:24.338412 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:11871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ3AAAAMM"]
[Thu Jul 30 12:36:24.349469 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:48412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ4wAAAQE"]
[Thu Jul 30 12:36:24.376465 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:22725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ5gAAAPE"]
[Thu Jul 30 12:36:24.405047 2026] [security2:error] [pid 765155:tid 765351] [client 172.236.9.101:63530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ7wAAAMc"]
[Thu Jul 30 12:36:24.408487 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:1498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ4QAAANI"]
[Thu Jul 30 12:36:24.423545 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:4290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ8AAAAJU"]
[Thu Jul 30 12:36:24.486087 2026] [proxy:error] [pid 765155:tid 765396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:24.486160 2026] [proxy_http:error] [pid 765155:tid 765396] [client 156.229.16.165:38112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:24.486732 2026] [proxy:error] [pid 765155:tid 765396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:24.486782 2026] [proxy_http:error] [pid 765155:tid 765396] [client 156.229.16.165:38112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:24.543858 2026] [security2:error] [pid 765155:tid 765324] [client 172.236.9.101:34912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLluT5hFAbD-LhWHiJ7gAAAKw"]
[Thu Jul 30 12:36:24.854926 2026] [core:notice] [pid 765155:tid 765404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:24.859237 2026] [security2:error] [pid 765155:tid 765404] [client 103.215.74.26:8782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLmOT5hFAbD-LhWHiKMwAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:24.894534 2026] [security2:error] [pid 765155:tid 765377] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/classwithtostring.php"] [unique_id "amuLmOT5hFAbD-LhWHiKNAAAAOE"]
[Thu Jul 30 12:36:24.894640 2026] [security2:error] [pid 765155:tid 765377] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/classwithtostring.php"] [unique_id "amuLmOT5hFAbD-LhWHiKNAAAAOE"]
[Thu Jul 30 12:36:24.997826 2026] [security2:error] [pid 765155:tid 765378] [client 68.221.69.72:64769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/a.php"] [unique_id "amuLmOT5hFAbD-LhWHiKOAAAAOI"]
[Thu Jul 30 12:36:24.997951 2026] [security2:error] [pid 765155:tid 765378] [client 68.221.69.72:64769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/a.php"] [unique_id "amuLmOT5hFAbD-LhWHiKOAAAAOI"]
[Thu Jul 30 12:36:25.045128 2026] [security2:error] [pid 765155:tid 765307] [client 20.63.98.115:58061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/v.php"] [unique_id "amuLmeT5hFAbD-LhWHiKOgAAAJs"]
[Thu Jul 30 12:36:25.417030 2026] [security2:error] [pid 765155:tid 765352] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/666.php"] [unique_id "amuLmeT5hFAbD-LhWHiKQwAAAMg"]
[Thu Jul 30 12:36:25.417158 2026] [security2:error] [pid 765155:tid 765352] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/666.php"] [unique_id "amuLmeT5hFAbD-LhWHiKQwAAAMg"]
[Thu Jul 30 12:36:25.479844 2026] [proxy:error] [pid 765155:tid 765391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:25.479941 2026] [proxy_http:error] [pid 765155:tid 765391] [client 156.229.16.165:60460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:25.480569 2026] [proxy:error] [pid 765155:tid 765391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:36:25.480617 2026] [proxy_http:error] [pid 765155:tid 765391] [client 156.229.16.165:60460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:36:25.598241 2026] [security2:error] [pid 765155:tid 765361] [client 194.187.251.163:48910] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuLmeT5hFAbD-LhWHiKSAAAANE"]
[Thu Jul 30 12:36:25.598353 2026] [security2:error] [pid 765155:tid 765361] [client 194.187.251.163:48910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuLmeT5hFAbD-LhWHiKSAAAANE"]
[Thu Jul 30 12:36:25.754126 2026] [security2:error] [pid 765155:tid 765294] [client 68.221.69.72:64792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/k.php"] [unique_id "amuLmeT5hFAbD-LhWHiKTwAAAI4"]
[Thu Jul 30 12:36:25.754236 2026] [security2:error] [pid 765155:tid 765294] [client 68.221.69.72:64792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/k.php"] [unique_id "amuLmeT5hFAbD-LhWHiKTwAAAI4"]
[Thu Jul 30 12:36:25.850337 2026] [security2:error] [pid 765155:tid 765287] [client 20.63.98.115:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/main.php"] [unique_id "amuLmeT5hFAbD-LhWHiKUQAAAIc"]
[Thu Jul 30 12:36:25.933841 2026] [security2:error] [pid 765155:tid 765375] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/"] [unique_id "amuLmeT5hFAbD-LhWHiKUgAAAN8"]
[Thu Jul 30 12:36:26.173163 2026] [security2:error] [pid 765155:tid 765347] [client 68.221.69.72:14644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/222.php"] [unique_id "amuLmuT5hFAbD-LhWHiKVgAAAMM"]
[Thu Jul 30 12:36:26.173316 2026] [security2:error] [pid 765155:tid 765347] [client 68.221.69.72:14644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/222.php"] [unique_id "amuLmuT5hFAbD-LhWHiKVgAAAMM"]
[Thu Jul 30 12:36:26.179520 2026] [security2:error] [pid 765155:tid 765363] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ws54.php"] [unique_id "amuLmuT5hFAbD-LhWHiKWAAAANM"]
[Thu Jul 30 12:36:26.179607 2026] [security2:error] [pid 765155:tid 765363] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ws54.php"] [unique_id "amuLmuT5hFAbD-LhWHiKWAAAANM"]
[Thu Jul 30 12:36:26.689368 2026] [security2:error] [pid 765155:tid 765316] [client 68.221.69.72:38344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/mac.php"] [unique_id "amuLmuT5hFAbD-LhWHiKaAAAAKQ"]
[Thu Jul 30 12:36:26.689470 2026] [security2:error] [pid 765155:tid 765316] [client 68.221.69.72:38344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/mac.php"] [unique_id "amuLmuT5hFAbD-LhWHiKaAAAAKQ"]
[Thu Jul 30 12:36:26.700965 2026] [security2:error] [pid 765155:tid 765337] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/deepseek_d.php"] [unique_id "amuLmuT5hFAbD-LhWHiKaQAAALk"]
[Thu Jul 30 12:36:26.701057 2026] [security2:error] [pid 765155:tid 765337] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/deepseek_d.php"] [unique_id "amuLmuT5hFAbD-LhWHiKaQAAALk"]
[Thu Jul 30 12:36:27.121088 2026] [security2:error] [pid 765155:tid 765305] [client 172.237.109.114:28491] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/WEB_VMS/LEVEL15/"] [unique_id "amuLm-T5hFAbD-LhWHiKeAAAAJk"]
[Thu Jul 30 12:36:27.238940 2026] [security2:error] [pid 765155:tid 765288] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/function/function.php"] [unique_id "amuLm-T5hFAbD-LhWHiKewAAAIg"]
[Thu Jul 30 12:36:27.239083 2026] [security2:error] [pid 765155:tid 765288] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/function/function.php"] [unique_id "amuLm-T5hFAbD-LhWHiKewAAAIg"]
[Thu Jul 30 12:36:27.289361 2026] [core:notice] [pid 765155:tid 765360] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:27.290789 2026] [security2:error] [pid 765155:tid 765360] [client 68.221.69.72:14610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "radiojelli.com"] [uri "/wp-content/uploads.html"] [unique_id "amuLm-T5hFAbD-LhWHiKfgAAANA"]
[Thu Jul 30 12:36:27.399528 2026] [core:notice] [pid 765155:tid 765254] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:27.426873 2026] [security2:error] [pid 765155:tid 765257] [remote 216.73.216.152:3161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuLm-T5hFAbD-LhWHiKhgAA4GU"]
[Thu Jul 30 12:36:27.754760 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/nw.php"] [unique_id "amuLm-T5hFAbD-LhWHiKjAAAANI"]
[Thu Jul 30 12:36:27.754873 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/nw.php"] [unique_id "amuLm-T5hFAbD-LhWHiKjAAAANI"]
[Thu Jul 30 12:36:27.967397 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:28.263255 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/xleet.php"] [unique_id "amuLnOT5hFAbD-LhWHiKngAAAKA"]
[Thu Jul 30 12:36:28.263381 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/xleet.php"] [unique_id "amuLnOT5hFAbD-LhWHiKngAAAKA"]
[Thu Jul 30 12:36:28.356097 2026] [security2:error] [pid 765155:tid 765370] [client 68.221.69.72:14614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuLm-T5hFAbD-LhWHiKkwAAANo"]
[Thu Jul 30 12:36:28.761331 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp.php"] [unique_id "amuLnOT5hFAbD-LhWHiKwgAAAPU"]
[Thu Jul 30 12:36:28.761526 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp.php"] [unique_id "amuLnOT5hFAbD-LhWHiKwgAAAPU"]
[Thu Jul 30 12:36:28.780762 2026] [core:notice] [pid 765155:tid 765369] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:28.785290 2026] [security2:error] [pid 765155:tid 765369] [client 68.221.69.72:14610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "radiojelli.com"] [uri "/wp-includes/Text.html"] [unique_id "amuLnOT5hFAbD-LhWHiKxAAAANk"]
[Thu Jul 30 12:36:28.915501 2026] [core:notice] [pid 765155:tid 765353] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:28.919045 2026] [security2:error] [pid 765155:tid 765353] [client 68.221.69.72:14614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuLnOT5hFAbD-LhWHiKyAAAAMk"]
[Thu Jul 30 12:36:28.926517 2026] [security2:error] [pid 765155:tid 765345] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKoAAAAME"]
[Thu Jul 30 12:36:29.271448 2026] [security2:error] [pid 765155:tid 765396] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/155.php"] [unique_id "amuLneT5hFAbD-LhWHiKzgAAAPQ"]
[Thu Jul 30 12:36:29.271640 2026] [security2:error] [pid 765155:tid 765396] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/155.php"] [unique_id "amuLneT5hFAbD-LhWHiKzgAAAPQ"]
[Thu Jul 30 12:36:29.283169 2026] [security2:error] [pid 765155:tid 765315] [client 20.63.98.115:49761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/file.php"] [unique_id "amuLneT5hFAbD-LhWHiKzwAAAKM"]
[Thu Jul 30 12:36:29.314941 2026] [security2:error] [pid 765155:tid 765314] [client 68.221.69.72:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/ops.php"] [unique_id "amuLneT5hFAbD-LhWHiK0AAAAKI"]
[Thu Jul 30 12:36:29.315137 2026] [security2:error] [pid 765155:tid 765314] [client 68.221.69.72:14610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/ops.php"] [unique_id "amuLneT5hFAbD-LhWHiK0AAAAKI"]
[Thu Jul 30 12:36:29.331515 2026] [security2:error] [pid 765155:tid 765382] [client 37.236.210.189:41543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKyQAAAOY"], referer: http://pkf.jo
[Thu Jul 30 12:36:29.601812 2026] [security2:error] [pid 765155:tid 765316] [client 172.236.9.101:21885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKpwAAAKQ"]
[Thu Jul 30 12:36:29.679788 2026] [security2:error] [pid 765155:tid 765385] [client 57.141.0.43:36538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiKygAA6Ws"], referer: https://igetvape-australia.com/product-category/iget-moon/?add-to-cart=177
[Thu Jul 30 12:36:29.893661 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/96i.php"] [unique_id "amuLneT5hFAbD-LhWHiK7gAAAPU"]
[Thu Jul 30 12:36:29.893744 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/96i.php"] [unique_id "amuLneT5hFAbD-LhWHiK7gAAAPU"]
[Thu Jul 30 12:36:30.351942 2026] [security2:error] [pid 765155:tid 765355] [client 172.236.9.101:15694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKqgAAAMs"]
[Thu Jul 30 12:36:30.359325 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:24102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKpQAAALE"]
[Thu Jul 30 12:36:30.362760 2026] [security2:error] [pid 765155:tid 765340] [client 172.236.9.101:1617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKpAAAALw"]
[Thu Jul 30 12:36:30.396251 2026] [security2:error] [pid 765155:tid 765391] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/as.php"] [unique_id "amuLnuT5hFAbD-LhWHiLAwAAAO8"]
[Thu Jul 30 12:36:30.396438 2026] [security2:error] [pid 765155:tid 765391] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/as.php"] [unique_id "amuLnuT5hFAbD-LhWHiLAwAAAO8"]
[Thu Jul 30 12:36:30.478654 2026] [security2:error] [pid 765155:tid 765304] [client 172.236.9.101:14176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKswAAAJg"]
[Thu Jul 30 12:36:30.524273 2026] [security2:error] [pid 765155:tid 765321] [client 68.221.69.72:38350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/8.php"] [unique_id "amuLnuT5hFAbD-LhWHiLBwAAAKk"]
[Thu Jul 30 12:36:30.524450 2026] [security2:error] [pid 765155:tid 765321] [client 68.221.69.72:38350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/8.php"] [unique_id "amuLnuT5hFAbD-LhWHiLBwAAAKk"]
[Thu Jul 30 12:36:30.531490 2026] [security2:error] [pid 765155:tid 765399] [client 172.236.9.101:27793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKrAAAAPc"]
[Thu Jul 30 12:36:30.532347 2026] [security2:error] [pid 765155:tid 765388] [client 172.236.9.101:22274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKpgAAAOw"]
[Thu Jul 30 12:36:30.536591 2026] [security2:error] [pid 765155:tid 765404] [client 172.236.9.101:2729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKsQAAAPw"]
[Thu Jul 30 12:36:30.538337 2026] [security2:error] [pid 765155:tid 765386] [client 172.236.9.101:33007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKrQAAAOo"]
[Thu Jul 30 12:36:30.540876 2026] [security2:error] [pid 765155:tid 765334] [client 172.236.9.101:11947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKsAAAALY"]
[Thu Jul 30 12:36:30.663056 2026] [core:notice] [pid 765155:tid 765371] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:30.667922 2026] [security2:error] [pid 765155:tid 765371] [client 103.215.74.26:8852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLnuT5hFAbD-LhWHiLCgAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:30.835365 2026] [security2:error] [pid 765155:tid 765305] [client 145.239.10.137:57698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/le.php"] [unique_id "amuLnuT5hFAbD-LhWHiLEgAAAJk"], referer: http://deltaedu.net/le.php
[Thu Jul 30 12:36:30.867536 2026] [security2:error] [pid 765155:tid 765382] [client 150.107.232.194:27283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLnuT5hFAbD-LhWHiLCQAAAOY"]
[Thu Jul 30 12:36:30.867697 2026] [security2:error] [pid 765155:tid 765382] [client 150.107.232.194:27283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLnuT5hFAbD-LhWHiLCQAAAOY"]
[Thu Jul 30 12:36:30.885094 2026] [security2:error] [pid 765155:tid 765293] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/min.php"] [unique_id "amuLnuT5hFAbD-LhWHiLEwAAAI0"]
[Thu Jul 30 12:36:30.885178 2026] [security2:error] [pid 765155:tid 765293] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/min.php"] [unique_id "amuLnuT5hFAbD-LhWHiLEwAAAI0"]
[Thu Jul 30 12:36:31.145064 2026] [security2:error] [pid 765155:tid 765369] [client 204.8.98.25:35104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuLn-T5hFAbD-LhWHiLGAAAANk"]
[Thu Jul 30 12:36:31.145173 2026] [security2:error] [pid 765155:tid 765369] [client 204.8.98.25:35104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuLn-T5hFAbD-LhWHiLGAAAANk"]
[Thu Jul 30 12:36:31.218673 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:31090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKtwAAAOE"]
[Thu Jul 30 12:36:31.231638 2026] [security2:error] [pid 765155:tid 765379] [client 20.63.98.115:58070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLGwAAAOM"]
[Thu Jul 30 12:36:31.233823 2026] [security2:error] [pid 765155:tid 765300] [client 172.236.9.101:16317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKrgAAAJQ"]
[Thu Jul 30 12:36:31.236224 2026] [security2:error] [pid 765155:tid 765412] [client 172.236.9.101:17389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKtAAAAQQ"]
[Thu Jul 30 12:36:31.237927 2026] [security2:error] [pid 765155:tid 765335] [client 172.236.9.101:2492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKrwAAALc"]
[Thu Jul 30 12:36:31.269174 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:10264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKqAAAALs"]
[Thu Jul 30 12:36:31.287693 2026] [security2:error] [pid 765155:tid 765406] [client 172.236.9.101:45015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKqwAAAP4"]
[Thu Jul 30 12:36:31.370745 2026] [security2:error] [pid 765155:tid 765387] [client 172.236.9.101:64637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKtgAAAOs"]
[Thu Jul 30 12:36:31.374921 2026] [security2:error] [pid 765155:tid 765380] [client 172.236.9.101:41551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKsgAAAOQ"]
[Thu Jul 30 12:36:31.402360 2026] [security2:error] [pid 765155:tid 765285] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/.well-known/"] [unique_id "amuLn-T5hFAbD-LhWHiLIgAAAIU"]
[Thu Jul 30 12:36:31.421454 2026] [core:notice] [pid 765155:tid 765327] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:31.430778 2026] [security2:error] [pid 765155:tid 765327] [client 103.215.74.26:8876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLn-T5hFAbD-LhWHiLJAAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:31.514106 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:33638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKtQAAAOI"]
[Thu Jul 30 12:36:31.624489 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:35531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK1gAAANc"]
[Thu Jul 30 12:36:31.649019 2026] [security2:error] [pid 765155:tid 765399] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/php8.php"] [unique_id "amuLn-T5hFAbD-LhWHiLKQAAAPc"]
[Thu Jul 30 12:36:31.649191 2026] [security2:error] [pid 765155:tid 765399] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/php8.php"] [unique_id "amuLn-T5hFAbD-LhWHiLKQAAAPc"]
[Thu Jul 30 12:36:31.920232 2026] [security2:error] [pid 765155:tid 765408] [client 50.6.43.217:18876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLFwAAAQA"]
[Thu Jul 30 12:36:31.982124 2026] [security2:error] [pid 765155:tid 765342] [client 51.68.111.208:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "totalwebsite.biz"] [uri "/robots.txt"] [unique_id "amuLn-T5hFAbD-LhWHiLNQAAAL4"]
[Thu Jul 30 12:36:31.982237 2026] [security2:error] [pid 765155:tid 765342] [client 51.68.111.208:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "totalwebsite.biz"] [uri "/robots.txt"] [unique_id "amuLn-T5hFAbD-LhWHiLNQAAAL4"]
[Thu Jul 30 12:36:32.128973 2026] [security2:error] [pid 765155:tid 765352] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/admin.php"] [unique_id "amuLoOT5hFAbD-LhWHiLNgAAAMg"]
[Thu Jul 30 12:36:32.129076 2026] [security2:error] [pid 765155:tid 765352] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/admin.php"] [unique_id "amuLoOT5hFAbD-LhWHiLNgAAAMg"]
[Thu Jul 30 12:36:32.166053 2026] [core:notice] [pid 765155:tid 765312] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:32.170695 2026] [security2:error] [pid 765155:tid 765312] [client 103.215.74.26:8886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLoOT5hFAbD-LhWHiLNwAAAKA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:32.170858 2026] [security2:error] [pid 765155:tid 765297] [client 216.73.216.104:25913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLMAAAkQQ"]
[Thu Jul 30 12:36:32.270144 2026] [security2:error] [pid 765155:tid 765351] [client 172.236.9.101:4522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK0wAAAMc"]
[Thu Jul 30 12:36:32.270845 2026] [security2:error] [pid 765155:tid 765313] [client 172.236.9.101:26648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK0gAAAKE"]
[Thu Jul 30 12:36:32.296252 2026] [security2:error] [pid 765155:tid 765337] [client 20.63.98.115:47310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuLoOT5hFAbD-LhWHiLOAAAALk"]
[Thu Jul 30 12:36:32.316482 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:15532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK1AAAANM"]
[Thu Jul 30 12:36:32.365278 2026] [security2:error] [pid 765155:tid 765402] [client 172.236.9.101:59825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnOT5hFAbD-LhWHiKqQAAAPo"]
[Thu Jul 30 12:36:32.371777 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:62946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK2AAAANI"]
[Thu Jul 30 12:36:32.397069 2026] [security2:error] [pid 765155:tid 765309] [client 172.236.9.101:3307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK2QAAAJ0"]
[Thu Jul 30 12:36:32.440885 2026] [security2:error] [pid 765155:tid 765300] [client 68.221.69.72:64780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/FWAZ.php"] [unique_id "amuLoOT5hFAbD-LhWHiLPwAAAJQ"]
[Thu Jul 30 12:36:32.441287 2026] [security2:error] [pid 765155:tid 765300] [client 68.221.69.72:64780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/FWAZ.php"] [unique_id "amuLoOT5hFAbD-LhWHiLPwAAAJQ"]
[Thu Jul 30 12:36:32.480962 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:29640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK3QAAAPg"]
[Thu Jul 30 12:36:32.488240 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:19914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK2wAAAQE"]
[Thu Jul 30 12:36:32.514742 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:57044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK4gAAAPE"]
[Thu Jul 30 12:36:32.529817 2026] [security2:error] [pid 765155:tid 765288] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLGgAAiHs"]
[Thu Jul 30 12:36:32.534460 2026] [security2:error] [pid 765155:tid 765311] [client 172.236.9.101:32077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK1wAAAJ8"]
[Thu Jul 30 12:36:32.650219 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:30706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK3gAAAJU"]
[Thu Jul 30 12:36:32.657547 2026] [security2:error] [pid 765155:tid 765341] [client 172.236.9.101:43526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK4QAAAL0"]
[Thu Jul 30 12:36:32.661113 2026] [security2:error] [pid 765155:tid 765407] [client 172.236.9.101:61983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK4wAAAP8"]
[Thu Jul 30 12:36:32.668052 2026] [security2:error] [pid 765155:tid 765345] [client 172.236.9.101:52209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnuT5hFAbD-LhWHiLBAAAAME"]
[Thu Jul 30 12:36:32.694854 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:25400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK4AAAAJo"]
[Thu Jul 30 12:36:32.705966 2026] [security2:error] [pid 765155:tid 765401] [client 172.236.9.101:27123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK3wAAAPk"]
[Thu Jul 30 12:36:32.714861 2026] [security2:error] [pid 765155:tid 765353] [client 172.236.9.101:19971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnuT5hFAbD-LhWHiLBQAAAMk"]
[Thu Jul 30 12:36:32.723106 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:24981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK5AAAALg"]
[Thu Jul 30 12:36:32.736836 2026] [security2:error] [pid 765155:tid 765394] [client 172.236.9.101:41073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLneT5hFAbD-LhWHiK3AAAAPI"]
[Thu Jul 30 12:36:32.751038 2026] [security2:error] [pid 765155:tid 765381] [client 172.236.9.101:22512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLnuT5hFAbD-LhWHiLAgAAAOU"]
[Thu Jul 30 12:36:32.817039 2026] [security2:error] [pid 765155:tid 765405] [client 174.138.89.209:60442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuLoOT5hFAbD-LhWHiLSwAAAP0"]
[Thu Jul 30 12:36:32.872373 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/222.php"] [unique_id "amuLoOT5hFAbD-LhWHiLTgAAAPM"]
[Thu Jul 30 12:36:32.872520 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/222.php"] [unique_id "amuLoOT5hFAbD-LhWHiLTgAAAPM"]
[Thu Jul 30 12:36:32.891700 2026] [security2:error] [pid 765155:tid 765290] [client 50.6.43.217:18882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuLn-T5hFAbD-LhWHiLMQAAAIo"]
[Thu Jul 30 12:36:32.895904 2026] [core:notice] [pid 765155:tid 765396] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:32.899971 2026] [security2:error] [pid 765155:tid 765396] [client 103.215.74.26:8898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLoOT5hFAbD-LhWHiLUAAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:33.064434 2026] [security2:error] [pid 765155:tid 765398] [client 174.138.89.209:45516] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuLoeT5hFAbD-LhWHiLVwAAAPY"]
[Thu Jul 30 12:36:33.290602 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:11339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLoeT5hFAbD-LhWHiLXAAAANc"]
[Thu Jul 30 12:36:33.290723 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:11339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLoeT5hFAbD-LhWHiLXAAAANc"]
[Thu Jul 30 12:36:33.366594 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuLoeT5hFAbD-LhWHiLXQAAAJ8"]
[Thu Jul 30 12:36:33.366706 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuLoeT5hFAbD-LhWHiLXQAAAJ8"]
[Thu Jul 30 12:36:33.547256 2026] [security2:error] [pid 765155:tid 765391] [client 68.221.69.72:14638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/biufile.php"] [unique_id "amuLoeT5hFAbD-LhWHiLZwAAAO8"]
[Thu Jul 30 12:36:33.547354 2026] [security2:error] [pid 765155:tid 765391] [client 68.221.69.72:14638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/biufile.php"] [unique_id "amuLoeT5hFAbD-LhWHiLZwAAAO8"]
[Thu Jul 30 12:36:33.553352 2026] [core:notice] [pid 765155:tid 765175] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:33.631491 2026] [core:notice] [pid 765155:tid 765376] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:33.635409 2026] [security2:error] [pid 765155:tid 765376] [client 103.215.74.26:1450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLoeT5hFAbD-LhWHiLaQAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:33.906713 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/info.php"] [unique_id "amuLoeT5hFAbD-LhWHiLbQAAAKI"]
[Thu Jul 30 12:36:33.906820 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/info.php"] [unique_id "amuLoeT5hFAbD-LhWHiLbQAAAKI"]
[Thu Jul 30 12:36:34.364065 2026] [core:notice] [pid 765155:tid 765338] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:34.368402 2026] [security2:error] [pid 765155:tid 765338] [client 103.215.74.26:1460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLouT5hFAbD-LhWHiLeAAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:34.446866 2026] [security2:error] [pid 765155:tid 765342] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/a.php"] [unique_id "amuLouT5hFAbD-LhWHiLfAAAAL4"]
[Thu Jul 30 12:36:34.446958 2026] [security2:error] [pid 765155:tid 765342] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/a.php"] [unique_id "amuLouT5hFAbD-LhWHiLfAAAAL4"]
[Thu Jul 30 12:36:34.469903 2026] [security2:error] [pid 765155:tid 765357] [client 68.221.69.72:38339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/coffexium.php"] [unique_id "amuLouT5hFAbD-LhWHiLfwAAAM0"]
[Thu Jul 30 12:36:34.470019 2026] [security2:error] [pid 765155:tid 765357] [client 68.221.69.72:38339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/coffexium.php"] [unique_id "amuLouT5hFAbD-LhWHiLfwAAAM0"]
[Thu Jul 30 12:36:34.657074 2026] [security2:error] [pid 765155:tid 765316] [client 20.63.98.115:47322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/file.php"] [unique_id "amuLouT5hFAbD-LhWHiLhAAAAKQ"]
[Thu Jul 30 12:36:34.989692 2026] [security2:error] [pid 765155:tid 765363] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/chosen.php"] [unique_id "amuLouT5hFAbD-LhWHiLjAAAANM"]
[Thu Jul 30 12:36:34.989788 2026] [security2:error] [pid 765155:tid 765363] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/chosen.php"] [unique_id "amuLouT5hFAbD-LhWHiLjAAAANM"]
[Thu Jul 30 12:36:35.212964 2026] [security2:error] [pid 765155:tid 765335] [client 68.221.69.72:38371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/simple.php"] [unique_id "amuLo-T5hFAbD-LhWHiLkgAAALc"]
[Thu Jul 30 12:36:35.213112 2026] [security2:error] [pid 765155:tid 765335] [client 68.221.69.72:38371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/simple.php"] [unique_id "amuLo-T5hFAbD-LhWHiLkgAAALc"]
[Thu Jul 30 12:36:35.756796 2026] [security2:error] [pid 765155:tid 765387] [client 20.63.98.115:47318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-signup.php"] [unique_id "amuLo-T5hFAbD-LhWHiLnwAAAOs"]
[Thu Jul 30 12:36:36.306879 2026] [security2:error] [pid 765155:tid 765290] [client 68.221.69.72:14593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/fpwch.php"] [unique_id "amuLpOT5hFAbD-LhWHiLrAAAAIo"]
[Thu Jul 30 12:36:36.307085 2026] [security2:error] [pid 765155:tid 765290] [client 68.221.69.72:14593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/fpwch.php"] [unique_id "amuLpOT5hFAbD-LhWHiLrAAAAIo"]
[Thu Jul 30 12:36:36.589346 2026] [security2:error] [pid 765155:tid 765389] [client 204.8.98.25:35114] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLpOT5hFAbD-LhWHiLtwAAAO0"]
[Thu Jul 30 12:36:36.589445 2026] [security2:error] [pid 765155:tid 765389] [client 204.8.98.25:35114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLpOT5hFAbD-LhWHiLtwAAAO0"]
[Thu Jul 30 12:36:37.209706 2026] [security2:error] [pid 765155:tid 765403] [client 172.213.232.128:62106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/011i.php"] [unique_id "amuLpeT5hFAbD-LhWHiLxwAAAPs"]
[Thu Jul 30 12:36:37.263921 2026] [security2:error] [pid 765155:tid 765298] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/index.php"] [unique_id "amuLpeT5hFAbD-LhWHiLyAAAAJI"]
[Thu Jul 30 12:36:37.264032 2026] [security2:error] [pid 765155:tid 765298] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/index.php"] [unique_id "amuLpeT5hFAbD-LhWHiLyAAAAJI"]
[Thu Jul 30 12:36:37.321970 2026] [security2:error] [pid 765155:tid 765288] [client 68.221.69.72:64815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/dex.php"] [unique_id "amuLpeT5hFAbD-LhWHiLyQAAAIg"]
[Thu Jul 30 12:36:37.322100 2026] [security2:error] [pid 765155:tid 765288] [client 68.221.69.72:64815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/dex.php"] [unique_id "amuLpeT5hFAbD-LhWHiLyQAAAIg"]
[Thu Jul 30 12:36:37.795169 2026] [security2:error] [pid 765155:tid 765407] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/vx.php"] [unique_id "amuLpeT5hFAbD-LhWHiL1wAAAP8"]
[Thu Jul 30 12:36:37.795267 2026] [security2:error] [pid 765155:tid 765407] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/vx.php"] [unique_id "amuLpeT5hFAbD-LhWHiL1wAAAP8"]
[Thu Jul 30 12:36:37.932289 2026] [security2:error] [pid 765155:tid 765304] [client 68.221.69.72:38373] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "radiojelli.com"] [uri "/1.php"] [unique_id "amuLpeT5hFAbD-LhWHiL2wAAAJg"]
[Thu Jul 30 12:36:37.932460 2026] [security2:error] [pid 765155:tid 765304] [client 68.221.69.72:38373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/1.php"] [unique_id "amuLpeT5hFAbD-LhWHiL2wAAAJg"]
[Thu Jul 30 12:36:37.932594 2026] [security2:error] [pid 765155:tid 765304] [client 68.221.69.72:38373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/1.php"] [unique_id "amuLpeT5hFAbD-LhWHiL2wAAAJg"]
[Thu Jul 30 12:36:38.087343 2026] [security2:error] [pid 765155:tid 765386] [client 150.107.232.194:27290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLpuT5hFAbD-LhWHiL5AAAAOo"]
[Thu Jul 30 12:36:38.087485 2026] [security2:error] [pid 765155:tid 765386] [client 150.107.232.194:27290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLpuT5hFAbD-LhWHiL5AAAAOo"]
[Thu Jul 30 12:36:38.140641 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:38.349905 2026] [security2:error] [pid 765155:tid 765290] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/admin/controller/extension/"] [unique_id "amuLpuT5hFAbD-LhWHiL6QAAAIo"]
[Thu Jul 30 12:36:38.647074 2026] [security2:error] [pid 765155:tid 765297] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wap.php"] [unique_id "amuLpuT5hFAbD-LhWHiL8AAAAJE"]
[Thu Jul 30 12:36:38.647209 2026] [security2:error] [pid 765155:tid 765297] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wap.php"] [unique_id "amuLpuT5hFAbD-LhWHiL8AAAAJE"]
[Thu Jul 30 12:36:38.772646 2026] [security2:error] [pid 765155:tid 765348] [client 172.213.232.128:53651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/03a005685d.php"] [unique_id "amuLpuT5hFAbD-LhWHiL8QAAAMQ"]
[Thu Jul 30 12:36:39.197445 2026] [security2:error] [pid 765155:tid 765398] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/wp.php"] [unique_id "amuLp-T5hFAbD-LhWHiL_AAAAPY"]
[Thu Jul 30 12:36:39.197551 2026] [security2:error] [pid 765155:tid 765398] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/wp.php"] [unique_id "amuLp-T5hFAbD-LhWHiL_AAAAPY"]
[Thu Jul 30 12:36:39.439925 2026] [security2:error] [pid 765155:tid 765377] [client 172.213.232.128:60019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/403.php"] [unique_id "amuLp-T5hFAbD-LhWHiMBgAAAOE"]
[Thu Jul 30 12:36:39.506520 2026] [security2:error] [pid 765155:tid 765319] [client 20.63.98.115:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuLp-T5hFAbD-LhWHiMCAAAAKc"]
[Thu Jul 30 12:36:39.703304 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bgymj.php"] [unique_id "amuLp-T5hFAbD-LhWHiMDAAAAP4"]
[Thu Jul 30 12:36:39.703428 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bgymj.php"] [unique_id "amuLp-T5hFAbD-LhWHiMDAAAAP4"]
[Thu Jul 30 12:36:40.130918 2026] [core:notice] [pid 765155:tid 765340] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:40.135285 2026] [security2:error] [pid 765155:tid 765340] [client 103.215.74.26:1470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLqOT5hFAbD-LhWHiMFgAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:40.199207 2026] [security2:error] [pid 765155:tid 765334] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/aa.php"] [unique_id "amuLqOT5hFAbD-LhWHiMFwAAALY"]
[Thu Jul 30 12:36:40.199326 2026] [security2:error] [pid 765155:tid 765334] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/aa.php"] [unique_id "amuLqOT5hFAbD-LhWHiMFwAAALY"]
[Thu Jul 30 12:36:40.296202 2026] [core:notice] [pid 765155:tid 765338] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:40.300364 2026] [security2:error] [pid 765155:tid 765338] [client 68.221.69.72:14605] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "radiojelli.com"] [uri "/wp-admin/css/colors/modern.html"] [unique_id "amuLqOT5hFAbD-LhWHiMGAAAALo"]
[Thu Jul 30 12:36:40.680050 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-mail.php"] [unique_id "amuLqOT5hFAbD-LhWHiMNAAAAKA"]
[Thu Jul 30 12:36:40.680198 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-mail.php"] [unique_id "amuLqOT5hFAbD-LhWHiMNAAAAKA"]
[Thu Jul 30 12:36:40.844078 2026] [core:notice] [pid 765155:tid 765297] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:40.848451 2026] [security2:error] [pid 765155:tid 765297] [client 103.215.74.26:1484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLqOT5hFAbD-LhWHiMNQAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:41.182361 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bolt.php"] [unique_id "amuLqeT5hFAbD-LhWHiMPAAAAPU"]
[Thu Jul 30 12:36:41.182474 2026] [security2:error] [pid 765155:tid 765397] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bolt.php"] [unique_id "amuLqeT5hFAbD-LhWHiMPAAAAPU"]
[Thu Jul 30 12:36:41.403656 2026] [security2:error] [pid 765155:tid 765360] [client 172.213.232.128:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/404.php"] [unique_id "amuLqeT5hFAbD-LhWHiMRAAAANA"]
[Thu Jul 30 12:36:41.571018 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:65368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMGgAAAJc"]
[Thu Jul 30 12:36:41.585650 2026] [core:notice] [pid 765155:tid 765339] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:41.586533 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:45252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMGQAAALI"]
[Thu Jul 30 12:36:41.598223 2026] [security2:error] [pid 765155:tid 765339] [client 103.215.74.26:1488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLqeT5hFAbD-LhWHiMTgAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:41.608487 2026] [security2:error] [pid 765155:tid 765394] [client 172.236.9.101:7636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMHgAAAPI"]
[Thu Jul 30 12:36:41.614467 2026] [security2:error] [pid 765155:tid 765404] [client 172.236.9.101:35653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMHAAAAPw"]
[Thu Jul 30 12:36:41.697260 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bthil.php"] [unique_id "amuLqeT5hFAbD-LhWHiMTwAAALM"]
[Thu Jul 30 12:36:41.697374 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bthil.php"] [unique_id "amuLqeT5hFAbD-LhWHiMTwAAALM"]
[Thu Jul 30 12:36:42.132504 2026] [security2:error] [pid 765155:tid 765243] [remote 57.141.0.40:37820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amuLquT5hFAbD-LhWHiMVwAA61c"]
[Thu Jul 30 12:36:42.150468 2026] [security2:error] [pid 765155:tid 765323] [client 20.63.98.115:60269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ge.php"] [unique_id "amuLquT5hFAbD-LhWHiMWQAAAKs"]
[Thu Jul 30 12:36:42.193056 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/cgi-bin/"] [unique_id "amuLquT5hFAbD-LhWHiMWgAAAQA"]
[Thu Jul 30 12:36:42.233264 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:4374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMIQAAAMM"]
[Thu Jul 30 12:36:42.234260 2026] [security2:error] [pid 765155:tid 765358] [client 172.236.9.101:47798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMIwAAAM4"]
[Thu Jul 30 12:36:42.237693 2026] [security2:error] [pid 765155:tid 765405] [client 172.236.9.101:9703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMHwAAAP0"]
[Thu Jul 30 12:36:42.238105 2026] [security2:error] [pid 765155:tid 765289] [client 172.236.9.101:28171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMJgAAAIk"]
[Thu Jul 30 12:36:42.249571 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:62838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMJAAAAOI"]
[Thu Jul 30 12:36:42.252221 2026] [core:notice] [pid 765155:tid 765296] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:42.260756 2026] [security2:error] [pid 765155:tid 765344] [client 172.236.9.101:40521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMIgAAAMA"]
[Thu Jul 30 12:36:42.267819 2026] [security2:error] [pid 765155:tid 765354] [client 172.236.9.101:45709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMJwAAAMo"]
[Thu Jul 30 12:36:42.273091 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:17196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMKwAAAOg"]
[Thu Jul 30 12:36:42.273356 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:5023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMKAAAAPQ"]
[Thu Jul 30 12:36:42.273447 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:33544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMKQAAAJo"]
[Thu Jul 30 12:36:42.286561 2026] [security2:error] [pid 765155:tid 765388] [client 172.236.9.101:48910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMJQAAAOw"]
[Thu Jul 30 12:36:42.332824 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:42.337179 2026] [security2:error] [pid 765155:tid 765304] [client 103.215.74.26:1494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLquT5hFAbD-LhWHiMYwAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:42.366380 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:8666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqOT5hFAbD-LhWHiMKgAAAO8"]
[Thu Jul 30 12:36:42.385881 2026] [security2:error] [pid 765155:tid 765395] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLquT5hFAbD-LhWHiMXQAAAPM"]
[Thu Jul 30 12:36:42.448906 2026] [security2:error] [pid 765155:tid 765390] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/x.php"] [unique_id "amuLquT5hFAbD-LhWHiMagAAAO4"]
[Thu Jul 30 12:36:42.449064 2026] [security2:error] [pid 765155:tid 765390] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/x.php"] [unique_id "amuLquT5hFAbD-LhWHiMagAAAO4"]
[Thu Jul 30 12:36:42.640617 2026] [security2:error] [pid 765155:tid 765296] [client 68.221.69.72:64800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuLquT5hFAbD-LhWHiMXwAAAJA"]
[Thu Jul 30 12:36:42.712232 2026] [security2:error] [pid 765155:tid 765412] [client 172.236.9.101:57945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqeT5hFAbD-LhWHiMQgAAAQQ"]
[Thu Jul 30 12:36:42.743943 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:34690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqeT5hFAbD-LhWHiMRQAAALg"]
[Thu Jul 30 12:36:42.745493 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:30435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqeT5hFAbD-LhWHiMRgAAAQE"]
[Thu Jul 30 12:36:42.750277 2026] [security2:error] [pid 765155:tid 765300] [client 172.236.9.101:46902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLqeT5hFAbD-LhWHiMQwAAAJQ"]
[Thu Jul 30 12:36:42.798048 2026] [security2:error] [pid 765155:tid 765328] [client 204.8.98.25:56092] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuLquT5hFAbD-LhWHiMbwAAALA"]
[Thu Jul 30 12:36:42.798146 2026] [security2:error] [pid 765155:tid 765328] [client 204.8.98.25:56092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuLquT5hFAbD-LhWHiMbwAAALA"]
[Thu Jul 30 12:36:42.952082 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/index/function.php"] [unique_id "amuLquT5hFAbD-LhWHiMdAAAALM"]
[Thu Jul 30 12:36:42.952196 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/index/function.php"] [unique_id "amuLquT5hFAbD-LhWHiMdAAAALM"]
[Thu Jul 30 12:36:43.059393 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:43.064886 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:58206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLq-T5hFAbD-LhWHiMeAAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:43.128856 2026] [security2:error] [pid 765155:tid 765330] [client 118.194.233.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fnm.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuLquT5hFAbD-LhWHiMcgAAALI"]
[Thu Jul 30 12:36:43.187910 2026] [security2:error] [pid 765155:tid 765340] [client 172.213.232.128:53793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/aa.php"] [unique_id "amuLq-T5hFAbD-LhWHiMfwAAALw"]
[Thu Jul 30 12:36:43.469684 2026] [security2:error] [pid 765155:tid 765289] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/aaa.php"] [unique_id "amuLq-T5hFAbD-LhWHiMhQAAAIk"]
[Thu Jul 30 12:36:43.469796 2026] [security2:error] [pid 765155:tid 765289] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/aaa.php"] [unique_id "amuLq-T5hFAbD-LhWHiMhQAAAIk"]
[Thu Jul 30 12:36:43.817630 2026] [core:notice] [pid 765155:tid 765306] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:43.822177 2026] [security2:error] [pid 765155:tid 765306] [client 103.215.74.26:58216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLq-T5hFAbD-LhWHiMjgAAAJo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:43.957800 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/abcd.php"] [unique_id "amuLq-T5hFAbD-LhWHiMkgAAAKA"]
[Thu Jul 30 12:36:43.957916 2026] [security2:error] [pid 765155:tid 765312] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/abcd.php"] [unique_id "amuLq-T5hFAbD-LhWHiMkgAAAKA"]
[Thu Jul 30 12:36:44.047901 2026] [security2:error] [pid 765155:tid 765395] [client 68.221.69.72:14605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/config.json.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmAAAAPM"]
[Thu Jul 30 12:36:44.048010 2026] [security2:error] [pid 765155:tid 765395] [client 68.221.69.72:14605] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/config.json.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmAAAAPM"]
[Thu Jul 30 12:36:44.298645 2026] [security2:error] [pid 765155:tid 765332] [client 38.190.144.4:50112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmwAAALQ"]
[Thu Jul 30 12:36:44.298769 2026] [security2:error] [pid 765155:tid 765332] [client 38.190.144.4:50112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmwAAALQ"]
[Thu Jul 30 12:36:44.465831 2026] [security2:error] [pid 765155:tid 765301] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-good.php"] [unique_id "amuLrOT5hFAbD-LhWHiMnwAAAJU"]
[Thu Jul 30 12:36:44.465972 2026] [security2:error] [pid 765155:tid 765301] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-good.php"] [unique_id "amuLrOT5hFAbD-LhWHiMnwAAAJU"]
[Thu Jul 30 12:36:44.559339 2026] [core:notice] [pid 765155:tid 765308] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:44.560483 2026] [security2:error] [pid 765155:tid 765241] [remote 111.225.149.236:23446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nfi.nyx.temporary.site"] [uri "/website_14d99ba9/wp-content/uploads/2025/08/fireworks23-1-1536x805.webp"] [unique_id "amuLrOT5hFAbD-LhWHiMpwABAVU"], referer: https://fireworkskenya.co.ke/
[Thu Jul 30 12:36:44.563985 2026] [security2:error] [pid 765155:tid 765308] [client 103.215.74.26:58228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLrOT5hFAbD-LhWHiMpgAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:44.682644 2026] [security2:error] [pid 765155:tid 765362] [client 172.213.232.128:60501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/aafewc0k.php"] [unique_id "amuLrOT5hFAbD-LhWHiMrQAAANI"]
[Thu Jul 30 12:36:44.924699 2026] [security2:error] [pid 765155:tid 765370] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLrOT5hFAbD-LhWHiMmgAA2mg"]
[Thu Jul 30 12:36:44.952956 2026] [security2:error] [pid 765155:tid 765363] [client 20.63.98.115:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/goods.php"] [unique_id "amuLrOT5hFAbD-LhWHiMtwAAANM"]
[Thu Jul 30 12:36:44.991454 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/simple.php"] [unique_id "amuLrOT5hFAbD-LhWHiMuAAAAKI"]
[Thu Jul 30 12:36:44.991551 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/simple.php"] [unique_id "amuLrOT5hFAbD-LhWHiMuAAAAKI"]
[Thu Jul 30 12:36:45.066386 2026] [security2:error] [pid 765155:tid 765287] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLrOT5hFAbD-LhWHiMtgAAAIc"]
[Thu Jul 30 12:36:45.286044 2026] [core:notice] [pid 765155:tid 765330] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:45.290579 2026] [security2:error] [pid 765155:tid 765330] [client 103.215.74.26:58234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLreT5hFAbD-LhWHiMvwAAALI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:45.370099 2026] [core:error] [pid 765155:tid 765338] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:45.370122 2026] [core:error] [pid 765155:tid 765338] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:45.457908 2026] [security2:error] [pid 765155:tid 765341] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMwgAAAL0"]
[Thu Jul 30 12:36:45.532057 2026] [security2:error] [pid 765155:tid 765290] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/edit-tags.php"] [unique_id "amuLreT5hFAbD-LhWHiM2AAAAIo"]
[Thu Jul 30 12:36:45.532185 2026] [security2:error] [pid 765155:tid 765290] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/edit-tags.php"] [unique_id "amuLreT5hFAbD-LhWHiM2AAAAIo"]
[Thu Jul 30 12:36:45.589236 2026] [security2:error] [pid 765155:tid 765381] [client 101.201.173.226:56930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMygAAAOU"]
[Thu Jul 30 12:36:45.598283 2026] [security2:error] [pid 765155:tid 765396] [client 101.201.173.226:56928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMyQAAAPQ"]
[Thu Jul 30 12:36:45.606328 2026] [security2:error] [pid 765155:tid 765384] [client 101.201.173.226:56919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMxwAAAOg"]
[Thu Jul 30 12:36:45.606414 2026] [security2:error] [pid 765155:tid 765358] [client 101.201.173.226:56918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMyAAAAM4"]
[Thu Jul 30 12:36:45.621333 2026] [security2:error] [pid 765155:tid 765315] [client 101.201.173.226:56926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMywAAAKM"]
[Thu Jul 30 12:36:45.626737 2026] [security2:error] [pid 765155:tid 765359] [client 101.201.173.226:56924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiM1QAAAM8"]
[Thu Jul 30 12:36:45.645852 2026] [security2:error] [pid 765155:tid 765351] [client 101.201.173.226:56862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLreT5hFAbD-LhWHiMwQAAAMc"], referer: http://adviseassociates.com/statics/images/ext/dir.gif
[Thu Jul 30 12:36:45.766092 2026] [security2:error] [pid 765155:tid 765334] [client 172.213.232.128:60532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/abcd.php"] [unique_id "amuLreT5hFAbD-LhWHiM3AAAALY"]
[Thu Jul 30 12:36:46.034415 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:46.038268 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:58246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLruT5hFAbD-LhWHiM5gAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:46.076014 2026] [security2:error] [pid 765155:tid 765377] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/u.php"] [unique_id "amuLruT5hFAbD-LhWHiM5wAAAOE"]
[Thu Jul 30 12:36:46.076103 2026] [security2:error] [pid 765155:tid 765377] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/u.php"] [unique_id "amuLruT5hFAbD-LhWHiM5wAAAOE"]
[Thu Jul 30 12:36:46.204180 2026] [security2:error] [pid 765155:tid 765344] [client 20.63.98.115:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/403.php"] [unique_id "amuLruT5hFAbD-LhWHiM6gAAAMA"]
[Thu Jul 30 12:36:46.288565 2026] [security2:error] [pid 765155:tid 765398] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM6QAAAPY"]
[Thu Jul 30 12:36:46.563686 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/admin.php"] [unique_id "amuLruT5hFAbD-LhWHiM9AAAAP4"]
[Thu Jul 30 12:36:46.563827 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/admin.php"] [unique_id "amuLruT5hFAbD-LhWHiM9AAAAP4"]
[Thu Jul 30 12:36:46.708135 2026] [security2:error] [pid 765155:tid 765322] [client 68.221.69.72:38370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/k2.php"] [unique_id "amuLruT5hFAbD-LhWHiNAgAAAKo"]
[Thu Jul 30 12:36:46.708298 2026] [security2:error] [pid 765155:tid 765322] [client 68.221.69.72:38370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/k2.php"] [unique_id "amuLruT5hFAbD-LhWHiNAgAAAKo"]
[Thu Jul 30 12:36:46.786215 2026] [core:notice] [pid 765155:tid 765299] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:46.793034 2026] [security2:error] [pid 765155:tid 765299] [client 103.215.74.26:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLruT5hFAbD-LhWHiNAwAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:46.899961 2026] [security2:error] [pid 765155:tid 765285] [client 101.201.173.226:57052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM-AAAAIU"], referer: http://adviseassociates.com/e/data/images/arrow.gif
[Thu Jul 30 12:36:46.917351 2026] [security2:error] [pid 765155:tid 765349] [client 101.201.173.226:57056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM-gAAAMU"], referer: http://adviseassociates.com/plus/img/df_dedetitle.gif
[Thu Jul 30 12:36:46.922291 2026] [security2:error] [pid 765155:tid 765374] [client 101.201.173.226:57054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM-wAAAN4"], referer: http://adviseassociates.com/public/plugins/ckeditor/images/spacer.gif
[Thu Jul 30 12:36:46.958880 2026] [security2:error] [pid 765155:tid 765399] [client 172.213.232.128:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/about.php"] [unique_id "amuLruT5hFAbD-LhWHiNCQAAAPc"]
[Thu Jul 30 12:36:47.080693 2026] [security2:error] [pid 765155:tid 765392] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/h.php"] [unique_id "amuLr-T5hFAbD-LhWHiNDgAAAPA"]
[Thu Jul 30 12:36:47.080798 2026] [security2:error] [pid 765155:tid 765392] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/h.php"] [unique_id "amuLr-T5hFAbD-LhWHiNDgAAAPA"]
[Thu Jul 30 12:36:47.219909 2026] [security2:error] [pid 765155:tid 765325] [client 101.201.173.226:57050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM_QAAAK0"], referer: http://adviseassociates.com/public/plugins/Ueditor/dialogs/attachment/images/alignicon.gif
[Thu Jul 30 12:36:47.222250 2026] [security2:error] [pid 765155:tid 765373] [client 101.201.173.226:57048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiM_wAAAN0"], referer: http://adviseassociates.com/include/ckeditor/plugins/smiley/images/angel_smile.gif
[Thu Jul 30 12:36:47.240896 2026] [security2:error] [pid 765155:tid 765287] [client 101.201.173.226:57060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiNAQAAAIc"], referer: http://adviseassociates.com/README.md
[Thu Jul 30 12:36:47.270555 2026] [security2:error] [pid 765155:tid 765314] [client 101.201.173.226:57058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuLruT5hFAbD-LhWHiNAAAAAKI"], referer: http://adviseassociates.com/apps/admin/view/default/layui/images/face/11.gif
[Thu Jul 30 12:36:47.521400 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:47.527892 2026] [security2:error] [pid 765155:tid 765388] [client 103.215.74.26:58272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLr-T5hFAbD-LhWHiNIgAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:47.551840 2026] [security2:error] [pid 765155:tid 765334] [client 101.201.173.226:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adviseassociates.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNFgAAALY"]
[Thu Jul 30 12:36:47.600410 2026] [security2:error] [pid 765155:tid 765403] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ms-edit.php"] [unique_id "amuLr-T5hFAbD-LhWHiNJgAAAPs"]
[Thu Jul 30 12:36:47.600554 2026] [security2:error] [pid 765155:tid 765403] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ms-edit.php"] [unique_id "amuLr-T5hFAbD-LhWHiNJgAAAPs"]
[Thu Jul 30 12:36:47.687030 2026] [security2:error] [pid 765155:tid 765302] [client 20.63.98.115:21157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/public/makeasmtp.php"] [unique_id "amuLr-T5hFAbD-LhWHiNKQAAAJY"]
[Thu Jul 30 12:36:47.953343 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:14440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNEgAAAPQ"]
[Thu Jul 30 12:36:47.971821 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:57829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNEwAAAOg"]
[Thu Jul 30 12:36:48.071090 2026] [security2:error] [pid 765155:tid 765348] [client 172.236.9.101:56301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNFQAAAMQ"]
[Thu Jul 30 12:36:48.075112 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:16816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNFwAAAI8"]
[Thu Jul 30 12:36:48.077156 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:27378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNGQAAAKM"]
[Thu Jul 30 12:36:48.092074 2026] [security2:error] [pid 765155:tid 765358] [client 172.236.9.101:23386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNFAAAAM4"]
[Thu Jul 30 12:36:48.106433 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:63622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNGAAAAO0"]
[Thu Jul 30 12:36:48.133096 2026] [security2:error] [pid 765155:tid 765361] [client 172.236.9.101:45073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLr-T5hFAbD-LhWHiNGgAAANE"]
[Thu Jul 30 12:36:48.165029 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/a7.php"] [unique_id "amuLsOT5hFAbD-LhWHiNMQAAAPI"]
[Thu Jul 30 12:36:48.165137 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/a7.php"] [unique_id "amuLsOT5hFAbD-LhWHiNMQAAAPI"]
[Thu Jul 30 12:36:48.283462 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:48.287933 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:58282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLsOT5hFAbD-LhWHiNNQAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:48.670638 2026] [security2:error] [pid 765155:tid 765304] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/manager.php"] [unique_id "amuLsOT5hFAbD-LhWHiNSwAAAJg"]
[Thu Jul 30 12:36:48.670824 2026] [security2:error] [pid 765155:tid 765304] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/manager.php"] [unique_id "amuLsOT5hFAbD-LhWHiNSwAAAJg"]
[Thu Jul 30 12:36:49.015260 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:49.022743 2026] [security2:error] [pid 765155:tid 765314] [client 103.215.74.26:58302] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLseT5hFAbD-LhWHiNUwAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:49.053865 2026] [security2:error] [pid 765155:tid 765402] [client 150.107.232.194:27304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLseT5hFAbD-LhWHiNVAAAAPo"]
[Thu Jul 30 12:36:49.053967 2026] [security2:error] [pid 765155:tid 765402] [client 150.107.232.194:27304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLseT5hFAbD-LhWHiNVAAAAPo"]
[Thu Jul 30 12:36:49.076043 2026] [security2:error] [pid 765155:tid 765330] [client 116.62.147.43:52568] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 43.147.62.116.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-comments-post.php"] [unique_id "amuLsOT5hFAbD-LhWHiNTwAAALI"]
[Thu Jul 30 12:36:49.076257 2026] [security2:error] [pid 765155:tid 765330] [client 116.62.147.43:52568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "themushroom.online"] [uri "/wp-comments-post.php"] [unique_id "amuLsOT5hFAbD-LhWHiNTwAAALI"]
[Thu Jul 30 12:36:49.142439 2026] [security2:error] [pid 765155:tid 765369] [client 20.63.98.115:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mar.php"] [unique_id "amuLseT5hFAbD-LhWHiNVwAAANk"]
[Thu Jul 30 12:36:49.168681 2026] [security2:error] [pid 765155:tid 765297] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/w1.php"] [unique_id "amuLseT5hFAbD-LhWHiNWQAAAJE"]
[Thu Jul 30 12:36:49.168790 2026] [security2:error] [pid 765155:tid 765297] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/w1.php"] [unique_id "amuLseT5hFAbD-LhWHiNWQAAAJE"]
[Thu Jul 30 12:36:49.283917 2026] [security2:error] [pid 765155:tid 765298] [client 172.236.9.101:17408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNOgAAAJI"]
[Thu Jul 30 12:36:49.286015 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:59676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNOwAAAK8"]
[Thu Jul 30 12:36:49.292355 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:56383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNPAAAALg"]
[Thu Jul 30 12:36:49.298557 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:17398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNOQAAALE"]
[Thu Jul 30 12:36:49.307596 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:64584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNPgAAAIY"]
[Thu Jul 30 12:36:49.313027 2026] [security2:error] [pid 765155:tid 765411] [client 172.236.9.101:55669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNPQAAAQM"]
[Thu Jul 30 12:36:49.313569 2026] [security2:error] [pid 765155:tid 765326] [client 172.236.9.101:58479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNPwAAAK4"]
[Thu Jul 30 12:36:49.332675 2026] [security2:error] [pid 765155:tid 765317] [client 172.236.9.101:14204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNQAAAAKU"]
[Thu Jul 30 12:36:49.346761 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:19301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNRgAAAKo"]
[Thu Jul 30 12:36:49.402088 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:3490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNQQAAANM"]
[Thu Jul 30 12:36:49.415509 2026] [security2:error] [pid 765155:tid 765340] [client 172.236.9.101:54716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNQgAAALw"]
[Thu Jul 30 12:36:49.419888 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:49.494379 2026] [security2:error] [pid 765155:tid 765299] [client 172.236.9.101:12598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLsOT5hFAbD-LhWHiNRwAAAJM"]
[Thu Jul 30 12:36:49.667585 2026] [security2:error] [pid 765155:tid 765328] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-includes/fonts/"] [unique_id "amuLseT5hFAbD-LhWHiNdgAAALA"]
[Thu Jul 30 12:36:49.761674 2026] [core:notice] [pid 765155:tid 765360] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:49.768827 2026] [security2:error] [pid 765155:tid 765360] [client 103.215.74.26:58316] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLseT5hFAbD-LhWHiNgAAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:50.056476 2026] [core:notice] [pid 765155:tid 765387] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:50.174553 2026] [security2:error] [pid 765155:tid 765294] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-login.php"] [unique_id "amuLseT5hFAbD-LhWHiNggAAAI4"]
[Thu Jul 30 12:36:50.174681 2026] [security2:error] [pid 765155:tid 765294] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-login.php"] [unique_id "amuLseT5hFAbD-LhWHiNggAAAI4"]
[Thu Jul 30 12:36:50.191762 2026] [security2:error] [pid 765155:tid 765366] [client 20.63.98.115:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/system.php"] [unique_id "amuLsuT5hFAbD-LhWHiNiQAAANY"]
[Thu Jul 30 12:36:50.545547 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:50.554528 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:58330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLsuT5hFAbD-LhWHiNkAAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:50.665287 2026] [security2:error] [pid 765155:tid 765333] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/default.php"] [unique_id "amuLsuT5hFAbD-LhWHiNlAAAALU"]
[Thu Jul 30 12:36:50.665384 2026] [security2:error] [pid 765155:tid 765333] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/default.php"] [unique_id "amuLsuT5hFAbD-LhWHiNlAAAALU"]
[Thu Jul 30 12:36:50.768447 2026] [security2:error] [pid 765155:tid 765336] [client 68.221.69.72:64788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/raw.php"] [unique_id "amuLsuT5hFAbD-LhWHiNmAAAALg"]
[Thu Jul 30 12:36:50.768535 2026] [security2:error] [pid 765155:tid 765336] [client 68.221.69.72:64788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/raw.php"] [unique_id "amuLsuT5hFAbD-LhWHiNmAAAALg"]
[Thu Jul 30 12:36:51.167097 2026] [security2:error] [pid 765155:tid 765342] [client 68.67.112.235:29072] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuLs-T5hFAbD-LhWHiNoAAAAL4"]
[Thu Jul 30 12:36:51.192860 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/i.php"] [unique_id "amuLs-T5hFAbD-LhWHiNogAAANI"]
[Thu Jul 30 12:36:51.192973 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/i.php"] [unique_id "amuLs-T5hFAbD-LhWHiNogAAANI"]
[Thu Jul 30 12:36:51.281631 2026] [core:notice] [pid 765155:tid 765299] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:51.291594 2026] [security2:error] [pid 765155:tid 765299] [client 103.215.74.26:58342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLs-T5hFAbD-LhWHiNpgAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:51.301120 2026] [security2:error] [pid 765155:tid 765302] [client 172.236.9.101:15271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNZQAAAJY"]
[Thu Jul 30 12:36:51.318089 2026] [security2:error] [pid 765155:tid 765365] [client 172.236.9.101:19736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNXgAAANU"]
[Thu Jul 30 12:36:51.322811 2026] [security2:error] [pid 765155:tid 765397] [client 172.236.9.101:59795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNYQAAAPU"]
[Thu Jul 30 12:36:51.339834 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:45129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNYAAAAJU"]
[Thu Jul 30 12:36:51.357671 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:60874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNXwAAALk"]
[Thu Jul 30 12:36:51.360752 2026] [security2:error] [pid 765155:tid 765383] [client 172.236.9.101:43111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNawAAAOc"]
[Thu Jul 30 12:36:51.387860 2026] [security2:error] [pid 765155:tid 765296] [client 172.236.9.101:58834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNYwAAAJA"]
[Thu Jul 30 12:36:51.390609 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:53164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNZAAAAPg"]
[Thu Jul 30 12:36:51.399721 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:56769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNXQAAANg"]
[Thu Jul 30 12:36:51.409385 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:48132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNYgAAAPs"]
[Thu Jul 30 12:36:51.429991 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:63055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNZgAAAMg"]
[Thu Jul 30 12:36:51.448848 2026] [security2:error] [pid 765155:tid 765364] [client 172.236.9.101:34400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNbQAAANQ"]
[Thu Jul 30 12:36:51.451427 2026] [security2:error] [pid 765155:tid 765332] [client 172.236.9.101:20466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNcQAAALQ"]
[Thu Jul 30 12:36:51.453580 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:60668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNaQAAAPQ"]
[Thu Jul 30 12:36:51.465947 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:25715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNbAAAAOg"]
[Thu Jul 30 12:36:51.467938 2026] [security2:error] [pid 765155:tid 765305] [client 172.236.9.101:42027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNaAAAAJk"]
[Thu Jul 30 12:36:51.484633 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:63672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNagAAAOE"]
[Thu Jul 30 12:36:51.535218 2026] [security2:error] [pid 765155:tid 765348] [client 172.236.9.101:28856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNcAAAAMQ"]
[Thu Jul 30 12:36:51.542313 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:1052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNZwAAAPE"]
[Thu Jul 30 12:36:51.610103 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:34752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLseT5hFAbD-LhWHiNcgAAAI8"]
[Thu Jul 30 12:36:51.628973 2026] [security2:error] [pid 765155:tid 765389] [client 20.63.98.115:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/lock360.php"] [unique_id "amuLs-T5hFAbD-LhWHiNqgAAAO0"]
[Thu Jul 30 12:36:51.707929 2026] [security2:error] [pid 765155:tid 765294] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuLs-T5hFAbD-LhWHiNqwAAAI4"]
[Thu Jul 30 12:36:51.964317 2026] [security2:error] [pid 765155:tid 765324] [client 152.32.142.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.kfo.lku.temporary.site"] [uri "/index.php"] [unique_id "amuLs-T5hFAbD-LhWHiNrgAAAKw"]
[Thu Jul 30 12:36:51.983666 2026] [security2:error] [pid 765155:tid 765410] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amuLs-T5hFAbD-LhWHiNuAAAAQI"]
[Thu Jul 30 12:36:51.983766 2026] [security2:error] [pid 765155:tid 765410] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amuLs-T5hFAbD-LhWHiNuAAAAQI"]
[Thu Jul 30 12:36:51.984762 2026] [security2:error] [pid 765155:tid 765388] [client 204.8.98.25:50994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLs-T5hFAbD-LhWHiNuQAAAOw"]
[Thu Jul 30 12:36:51.984840 2026] [security2:error] [pid 765155:tid 765388] [client 204.8.98.25:50994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLs-T5hFAbD-LhWHiNuQAAAOw"]
[Thu Jul 30 12:36:52.024171 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:52.030782 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:58352] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLtOT5hFAbD-LhWHiNugAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:52.458142 2026] [security2:error] [pid 765155:tid 765407] [client 172.213.232.128:57888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/admin.php"] [unique_id "amuLtOT5hFAbD-LhWHiNxwAAAP8"]
[Thu Jul 30 12:36:52.472295 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuLtOT5hFAbD-LhWHiNyAAAAPI"]
[Thu Jul 30 12:36:52.472411 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuLtOT5hFAbD-LhWHiNyAAAAPI"]
[Thu Jul 30 12:36:52.699861 2026] [security2:error] [pid 765155:tid 765372] [client 68.221.69.72:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp.php"] [unique_id "amuLtOT5hFAbD-LhWHiNyQAAANw"]
[Thu Jul 30 12:36:52.700039 2026] [security2:error] [pid 765155:tid 765372] [client 68.221.69.72:65433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/wp.php"] [unique_id "amuLtOT5hFAbD-LhWHiNyQAAANw"]
[Thu Jul 30 12:36:52.749894 2026] [core:notice] [pid 765155:tid 765385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:52.755244 2026] [security2:error] [pid 765155:tid 765385] [client 103.215.74.26:58362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLtOT5hFAbD-LhWHiNygAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:52.939668 2026] [autoindex:error] [pid 765155:tid 765305] [client 49.235.136.28:38308] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:36:52.985343 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/gecko-new.php"] [unique_id "amuLtOT5hFAbD-LhWHiN1gAAAJ8"]
[Thu Jul 30 12:36:52.985485 2026] [security2:error] [pid 765155:tid 765311] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/gecko-new.php"] [unique_id "amuLtOT5hFAbD-LhWHiN1gAAAJ8"]
[Thu Jul 30 12:36:53.074920 2026] [security2:error] [pid 765155:tid 765390] [client 20.63.98.115:54199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amuLteT5hFAbD-LhWHiN2gAAAO4"]
[Thu Jul 30 12:36:53.207246 2026] [security2:error] [pid 765155:tid 765376] [client 172.213.232.128:52946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/adminfuns.php"] [unique_id "amuLteT5hFAbD-LhWHiN3AAAAOA"]
[Thu Jul 30 12:36:53.435009 2026] [security2:error] [pid 765155:tid 765303] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLtOT5hFAbD-LhWHiNzgAAAJc"]
[Thu Jul 30 12:36:53.476097 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:53.483157 2026] [security2:error] [pid 765155:tid 765370] [client 103.215.74.26:33640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLteT5hFAbD-LhWHiN5gAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:53.520322 2026] [security2:error] [pid 765155:tid 765307] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/NewFile.php"] [unique_id "amuLteT5hFAbD-LhWHiN5wAAAJs"]
[Thu Jul 30 12:36:53.520413 2026] [security2:error] [pid 765155:tid 765307] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/NewFile.php"] [unique_id "amuLteT5hFAbD-LhWHiN5wAAAJs"]
[Thu Jul 30 12:36:53.811418 2026] [security2:error] [pid 765155:tid 765318] [client 172.213.232.128:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/albin.php"] [unique_id "amuLteT5hFAbD-LhWHiN6wAAAKY"]
[Thu Jul 30 12:36:53.929131 2026] [security2:error] [pid 765155:tid 765373] [client 20.63.98.115:21169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mah.php"] [unique_id "amuLteT5hFAbD-LhWHiN7QAAAN0"]
[Thu Jul 30 12:36:54.063528 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-Blogs.php"] [unique_id "amuLtuT5hFAbD-LhWHiN9AAAAQA"]
[Thu Jul 30 12:36:54.063616 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-Blogs.php"] [unique_id "amuLtuT5hFAbD-LhWHiN9AAAAQA"]
[Thu Jul 30 12:36:54.209578 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:54.213533 2026] [security2:error] [pid 765155:tid 765314] [client 103.215.74.26:33656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLtuT5hFAbD-LhWHiN-AAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:54.289606 2026] [core:notice] [pid 765155:tid 765297] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:54.595482 2026] [security2:error] [pid 765155:tid 765296] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-includes/fonts/index.php"] [unique_id "amuLtuT5hFAbD-LhWHiOBQAAAJA"]
[Thu Jul 30 12:36:54.595580 2026] [security2:error] [pid 765155:tid 765296] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-includes/fonts/index.php"] [unique_id "amuLtuT5hFAbD-LhWHiOBQAAAJA"]
[Thu Jul 30 12:36:54.712729 2026] [security2:error] [pid 765155:tid 765305] [client 68.221.69.72:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/fffm.php"] [unique_id "amuLtuT5hFAbD-LhWHiOBwAAAJk"]
[Thu Jul 30 12:36:54.712834 2026] [security2:error] [pid 765155:tid 765305] [client 68.221.69.72:38392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/fffm.php"] [unique_id "amuLtuT5hFAbD-LhWHiOBwAAAJk"]
[Thu Jul 30 12:36:54.784202 2026] [core:error] [pid 765155:tid 765368] [client 20.63.98.115:54159] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:54.784231 2026] [core:error] [pid 765155:tid 765368] [client 20.63.98.115:54159] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:54.943760 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:54.947737 2026] [security2:error] [pid 765155:tid 765377] [client 103.215.74.26:33658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLtuT5hFAbD-LhWHiOCQAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:55.102039 2026] [security2:error] [pid 765155:tid 765374] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/themes.php"] [unique_id "amuLt-T5hFAbD-LhWHiOEQAAAN4"]
[Thu Jul 30 12:36:55.102146 2026] [security2:error] [pid 765155:tid 765374] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/themes.php"] [unique_id "amuLt-T5hFAbD-LhWHiOEQAAAN4"]
[Thu Jul 30 12:36:55.677264 2026] [security2:error] [pid 765155:tid 765381] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/cv.php"] [unique_id "amuLt-T5hFAbD-LhWHiOHgAAAOU"]
[Thu Jul 30 12:36:55.677369 2026] [security2:error] [pid 765155:tid 765381] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/cv.php"] [unique_id "amuLt-T5hFAbD-LhWHiOHgAAAOU"]
[Thu Jul 30 12:36:55.683895 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:55.689551 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:33662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLt-T5hFAbD-LhWHiOIAAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:56.058849 2026] [security2:error] [pid 765155:tid 765318] [client 68.221.69.72:38389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/111.php"] [unique_id "amuLuOT5hFAbD-LhWHiOJAAAAKY"]
[Thu Jul 30 12:36:56.058991 2026] [security2:error] [pid 765155:tid 765318] [client 68.221.69.72:38389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/111.php"] [unique_id "amuLuOT5hFAbD-LhWHiOJAAAAKY"]
[Thu Jul 30 12:36:56.212196 2026] [security2:error] [pid 765155:tid 765351] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/"] [unique_id "amuLuOT5hFAbD-LhWHiOMAAAAMc"]
[Thu Jul 30 12:36:56.431586 2026] [core:notice] [pid 765155:tid 765391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:56.436509 2026] [security2:error] [pid 765155:tid 765391] [client 103.215.74.26:33670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLuOT5hFAbD-LhWHiOMQAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:56.476233 2026] [security2:error] [pid 765155:tid 765315] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLt-T5hFAbD-LhWHiOIwAAAKM"]
[Thu Jul 30 12:36:56.480123 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/uploads/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOMgAAAKI"]
[Thu Jul 30 12:36:56.480210 2026] [security2:error] [pid 765155:tid 765314] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-content/uploads/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOMgAAAKI"]
[Thu Jul 30 12:36:56.598816 2026] [security2:error] [pid 765155:tid 765290] [client 172.237.109.114:49948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOJQAAAIo"]
[Thu Jul 30 12:36:56.608999 2026] [security2:error] [pid 765155:tid 765340] [client 20.63.98.115:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-class.php"] [unique_id "amuLuOT5hFAbD-LhWHiOOQAAALw"]
[Thu Jul 30 12:36:56.652631 2026] [security2:error] [pid 765155:tid 765320] [client 172.237.109.114:12838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOKQAAAKg"]
[Thu Jul 30 12:36:56.741278 2026] [security2:error] [pid 765155:tid 765359] [client 172.237.109.114:46634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOKgAAAM8"]
[Thu Jul 30 12:36:56.744194 2026] [security2:error] [pid 765155:tid 765350] [client 172.237.109.114:1638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOLgAAAMY"]
[Thu Jul 30 12:36:56.755511 2026] [security2:error] [pid 765155:tid 765287] [client 172.237.109.114:23062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLuOT5hFAbD-LhWHiOLwAAAIc"]
[Thu Jul 30 12:36:56.970797 2026] [security2:error] [pid 765155:tid 765396] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ws83.php"] [unique_id "amuLuOT5hFAbD-LhWHiOPQAAAPQ"]
[Thu Jul 30 12:36:56.970919 2026] [security2:error] [pid 765155:tid 765396] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ws83.php"] [unique_id "amuLuOT5hFAbD-LhWHiOPQAAAPQ"]
[Thu Jul 30 12:36:57.093847 2026] [security2:error] [pid 765155:tid 765317] [client 172.213.232.128:59665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/amfsqvgv.php"] [unique_id "amuLueT5hFAbD-LhWHiORQAAAKU"]
[Thu Jul 30 12:36:57.142510 2026] [core:error] [pid 765155:tid 765211] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.142532 2026] [core:error] [pid 765155:tid 765211] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.159369 2026] [core:notice] [pid 765155:tid 765403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:57.163204 2026] [security2:error] [pid 765155:tid 765403] [client 103.215.74.26:33686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLueT5hFAbD-LhWHiORwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:57.185075 2026] [core:error] [pid 765155:tid 765226] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.185092 2026] [core:error] [pid 765155:tid 765226] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.230078 2026] [core:error] [pid 765155:tid 765206] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.230097 2026] [core:error] [pid 765155:tid 765206] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:36:57.504717 2026] [security2:error] [pid 765155:tid 765356] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/atex1.php"] [unique_id "amuLueT5hFAbD-LhWHiOUQAAAMw"]
[Thu Jul 30 12:36:57.504820 2026] [security2:error] [pid 765155:tid 765356] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/atex1.php"] [unique_id "amuLueT5hFAbD-LhWHiOUQAAAMw"]
[Thu Jul 30 12:36:57.532098 2026] [security2:error] [pid 765155:tid 765285] [client 20.63.98.115:58085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/backup.php"] [unique_id "amuLueT5hFAbD-LhWHiOUwAAAIU"]
[Thu Jul 30 12:36:57.887539 2026] [core:notice] [pid 765155:tid 765293] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:57.892138 2026] [security2:error] [pid 765155:tid 765293] [client 103.215.74.26:33690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLueT5hFAbD-LhWHiOXQAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:58.034410 2026] [security2:error] [pid 765155:tid 765334] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/class-t.api.php"] [unique_id "amuLuuT5hFAbD-LhWHiOXgAAALY"]
[Thu Jul 30 12:36:58.034524 2026] [security2:error] [pid 765155:tid 765334] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/class-t.api.php"] [unique_id "amuLuuT5hFAbD-LhWHiOXgAAALY"]
[Thu Jul 30 12:36:58.198303 2026] [security2:error] [pid 765155:tid 765321] [client 172.213.232.128:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/ant.php"] [unique_id "amuLuuT5hFAbD-LhWHiOYQAAAKk"]
[Thu Jul 30 12:36:58.300069 2026] [security2:error] [pid 765155:tid 765298] [client 85.208.96.195:60450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/07/26/5g-entenda-o-que-muda-com-a-chegada-do-sinal-em-joao-pessoa-nesta-sexta-feira-29/"] [unique_id "amuLuuT5hFAbD-LhWHiOaQAAAJI"]
[Thu Jul 30 12:36:58.300190 2026] [security2:error] [pid 765155:tid 765298] [client 85.208.96.195:60450] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/07/26/5g-entenda-o-que-muda-com-a-chegada-do-sinal-em-joao-pessoa-nesta-sexta-feira-29/"] [unique_id "amuLuuT5hFAbD-LhWHiOaQAAAJI"]
[Thu Jul 30 12:36:58.575849 2026] [security2:error] [pid 765155:tid 765288] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/w.php"] [unique_id "amuLuuT5hFAbD-LhWHiObwAAAIg"]
[Thu Jul 30 12:36:58.575957 2026] [security2:error] [pid 765155:tid 765288] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/w.php"] [unique_id "amuLuuT5hFAbD-LhWHiObwAAAIg"]
[Thu Jul 30 12:36:58.635635 2026] [core:notice] [pid 765155:tid 765329] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:58.640187 2026] [security2:error] [pid 765155:tid 765329] [client 103.215.74.26:33698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLuuT5hFAbD-LhWHiOcAAAALE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:58.661018 2026] [security2:error] [pid 765155:tid 765398] [client 20.63.98.115:58051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/default.php"] [unique_id "amuLuuT5hFAbD-LhWHiOcQAAAPY"]
[Thu Jul 30 12:36:58.794609 2026] [security2:error] [pid 765155:tid 765399] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLuuT5hFAbD-LhWHiOZQAAAPc"]
[Thu Jul 30 12:36:58.999063 2026] [security2:error] [pid 765155:tid 765324] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuLuuT5hFAbD-LhWHiObQAArEs"]
[Thu Jul 30 12:36:59.052934 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/archive.php"] [unique_id "amuLu-T5hFAbD-LhWHiOfwAAAMs"]
[Thu Jul 30 12:36:59.053076 2026] [security2:error] [pid 765155:tid 765355] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/archive.php"] [unique_id "amuLu-T5hFAbD-LhWHiOfwAAAMs"]
[Thu Jul 30 12:36:59.268412 2026] [core:notice] [pid 765155:tid 765237] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:59.284924 2026] [security2:error] [pid 765155:tid 765403] [client 150.107.232.194:27104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLu-T5hFAbD-LhWHiOggAAAPs"]
[Thu Jul 30 12:36:59.285039 2026] [security2:error] [pid 765155:tid 765403] [client 150.107.232.194:27104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLu-T5hFAbD-LhWHiOggAAAPs"]
[Thu Jul 30 12:36:59.376956 2026] [core:notice] [pid 765155:tid 765374] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:36:59.382505 2026] [security2:error] [pid 765155:tid 765374] [client 103.215.74.26:33712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLu-T5hFAbD-LhWHiOhgAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:36:59.558742 2026] [security2:error] [pid 765155:tid 765303] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bless.php"] [unique_id "amuLu-T5hFAbD-LhWHiOjQAAAJc"]
[Thu Jul 30 12:36:59.558860 2026] [security2:error] [pid 765155:tid 765303] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/bless.php"] [unique_id "amuLu-T5hFAbD-LhWHiOjQAAAJc"]
[Thu Jul 30 12:36:59.974281 2026] [core:notice] [pid 765155:tid 765168] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:00.058599 2026] [security2:error] [pid 765155:tid 765346] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/sagax1.php"] [unique_id "amuLvOT5hFAbD-LhWHiOmAAAAMI"]
[Thu Jul 30 12:37:00.058748 2026] [security2:error] [pid 765155:tid 765346] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/sagax1.php"] [unique_id "amuLvOT5hFAbD-LhWHiOmAAAAMI"]
[Thu Jul 30 12:37:00.124300 2026] [security2:error] [pid 765155:tid 765345] [client 20.63.98.115:47325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/maint/about.php"] [unique_id "amuLvOT5hFAbD-LhWHiOmQAAAME"]
[Thu Jul 30 12:37:00.130619 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:00.135947 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:33726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLvOT5hFAbD-LhWHiOmgAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:00.181262 2026] [security2:error] [pid 765155:tid 765307] [client 20.151.221.234:20969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wk/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOmwAAAJs"]
[Thu Jul 30 12:37:00.551655 2026] [security2:error] [pid 765155:tid 765350] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wpc.php"] [unique_id "amuLvOT5hFAbD-LhWHiOvAAAAMY"]
[Thu Jul 30 12:37:00.551862 2026] [security2:error] [pid 765155:tid 765350] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wpc.php"] [unique_id "amuLvOT5hFAbD-LhWHiOvAAAAMY"]
[Thu Jul 30 12:37:00.562105 2026] [security2:error] [pid 765155:tid 765320] [client 172.213.232.128:58231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/appreciators.php"] [unique_id "amuLvOT5hFAbD-LhWHiOvQAAAKg"]
[Thu Jul 30 12:37:00.879753 2026] [core:notice] [pid 765155:tid 765357] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:00.884940 2026] [security2:error] [pid 765155:tid 765357] [client 103.215.74.26:33736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLvOT5hFAbD-LhWHiOvgAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:01.066171 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/fone1.php"] [unique_id "amuLveT5hFAbD-LhWHiOxwAAALs"]
[Thu Jul 30 12:37:01.066281 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/fone1.php"] [unique_id "amuLveT5hFAbD-LhWHiOxwAAALs"]
[Thu Jul 30 12:37:01.157454 2026] [security2:error] [pid 765155:tid 765352] [client 20.63.98.115:49133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amuLveT5hFAbD-LhWHiOyQAAAMg"]
[Thu Jul 30 12:37:01.178710 2026] [security2:error] [pid 765155:tid 765384] [client 20.151.221.234:54039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/av.php"] [unique_id "amuLveT5hFAbD-LhWHiOygAAAOg"]
[Thu Jul 30 12:37:01.234441 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:01.237826 2026] [security2:error] [pid 765155:tid 765409] [client 68.221.69.72:14595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "radiojelli.com"] [uri "/wp-includes/Requests.html"] [unique_id "amuLveT5hFAbD-LhWHiOywAAAQE"]
[Thu Jul 30 12:37:01.489459 2026] [core:notice] [pid 765155:tid 765240] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:01.571349 2026] [security2:error] [pid 765155:tid 765389] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ncx.php"] [unique_id "amuLveT5hFAbD-LhWHiO1QAAAO0"]
[Thu Jul 30 12:37:01.571514 2026] [security2:error] [pid 765155:tid 765389] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ncx.php"] [unique_id "amuLveT5hFAbD-LhWHiO1QAAAO0"]
[Thu Jul 30 12:37:01.615622 2026] [core:notice] [pid 765155:tid 765300] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:01.620946 2026] [security2:error] [pid 765155:tid 765300] [client 103.215.74.26:33738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLveT5hFAbD-LhWHiO2AAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:01.676325 2026] [security2:error] [pid 765155:tid 765355] [client 172.213.232.128:53891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/archive.php"] [unique_id "amuLveT5hFAbD-LhWHiO2QAAAMs"]
[Thu Jul 30 12:37:02.084616 2026] [security2:error] [pid 765155:tid 765316] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuLvuT5hFAbD-LhWHiO4gAAAKQ"]
[Thu Jul 30 12:37:02.084712 2026] [security2:error] [pid 765155:tid 765316] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuLvuT5hFAbD-LhWHiO4gAAAKQ"]
[Thu Jul 30 12:37:02.136873 2026] [security2:error] [pid 765155:tid 765245] [remote 74.7.241.60:43382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuLvuT5hFAbD-LhWHiO5AAA5Vk"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:37:02.251503 2026] [security2:error] [pid 765155:tid 765292] [client 172.236.9.101:30072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOnAAAAIw"]
[Thu Jul 30 12:37:02.278679 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:36033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOnQAAAPg"]
[Thu Jul 30 12:37:02.343431 2026] [security2:error] [pid 765155:tid 765343] [client 172.236.9.101:50341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOpAAAAL8"]
[Thu Jul 30 12:37:02.343431 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:8314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOqAAAAIY"]
[Thu Jul 30 12:37:02.344628 2026] [security2:error] [pid 765155:tid 765321] [client 172.236.9.101:57894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOogAAAKk"]
[Thu Jul 30 12:37:02.350996 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:02.359164 2026] [security2:error] [pid 765155:tid 765370] [client 103.215.74.26:33754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLvuT5hFAbD-LhWHiO5QAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:02.377172 2026] [security2:error] [pid 765155:tid 765298] [client 172.236.9.101:33143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOpgAAAJI"]
[Thu Jul 30 12:37:02.383852 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:12833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOoQAAAJo"]
[Thu Jul 30 12:37:02.398754 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:42389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOsgAAANc"]
[Thu Jul 30 12:37:02.398754 2026] [security2:error] [pid 765155:tid 765411] [client 172.236.9.101:12919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOsAAAAQM"]
[Thu Jul 30 12:37:02.398754 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:10978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOpwAAALI"]
[Thu Jul 30 12:37:02.401875 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:4828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOrwAAALg"]
[Thu Jul 30 12:37:02.417549 2026] [security2:error] [pid 765155:tid 765340] [client 172.236.9.101:40714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOrgAAALw"]
[Thu Jul 30 12:37:02.428125 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:60136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOrQAAAKM"]
[Thu Jul 30 12:37:02.428125 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:26760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOnwAAAQA"]
[Thu Jul 30 12:37:02.431715 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:30720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOqQAAANM"]
[Thu Jul 30 12:37:02.439511 2026] [security2:error] [pid 765155:tid 765258] [remote 216.73.216.152:7696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuLvuT5hFAbD-LhWHiO5gAAyWY"]
[Thu Jul 30 12:37:02.444850 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:59176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOrAAAAO8"]
[Thu Jul 30 12:37:02.444948 2026] [security2:error] [pid 765155:tid 765297] [client 172.236.9.101:48947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOqgAAAJE"]
[Thu Jul 30 12:37:02.450071 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:12610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOngAAAK8"]
[Thu Jul 30 12:37:02.453134 2026] [security2:error] [pid 765155:tid 765290] [client 172.236.9.101:46667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOqwAAAIo"]
[Thu Jul 30 12:37:02.484339 2026] [security2:error] [pid 765155:tid 765326] [client 172.236.9.101:14017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLvOT5hFAbD-LhWHiOsQAAAK4"]
[Thu Jul 30 12:37:02.572884 2026] [security2:error] [pid 765155:tid 765299] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wso.php"] [unique_id "amuLvuT5hFAbD-LhWHiO6gAAAJM"]
[Thu Jul 30 12:37:02.573008 2026] [security2:error] [pid 765155:tid 765299] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wso.php"] [unique_id "amuLvuT5hFAbD-LhWHiO6gAAAJM"]
[Thu Jul 30 12:37:02.855071 2026] [security2:error] [pid 765155:tid 765317] [client 20.151.221.234:20929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mini.php"] [unique_id "amuLvuT5hFAbD-LhWHiO9AAAAKU"]
[Thu Jul 30 12:37:03.002247 2026] [core:notice] [pid 765155:tid 765233] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:03.096416 2026] [security2:error] [pid 765155:tid 765293] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/zup.php73"] [unique_id "amuLv-T5hFAbD-LhWHiO_QAAAI0"]
[Thu Jul 30 12:37:03.096548 2026] [security2:error] [pid 765155:tid 765293] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/zup.php73"] [unique_id "amuLv-T5hFAbD-LhWHiO_QAAAI0"]
[Thu Jul 30 12:37:03.653914 2026] [security2:error] [pid 765155:tid 765342] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/k.php"] [unique_id "amuLv-T5hFAbD-LhWHiPBgAAAL4"]
[Thu Jul 30 12:37:03.654073 2026] [security2:error] [pid 765155:tid 765342] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/k.php"] [unique_id "amuLv-T5hFAbD-LhWHiPBgAAAL4"]
[Thu Jul 30 12:37:04.115387 2026] [security2:error] [pid 765155:tid 765322] [client 20.151.221.234:20965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/aa.php"] [unique_id "amuLwOT5hFAbD-LhWHiPDQAAAKo"]
[Thu Jul 30 12:37:04.210148 2026] [security2:error] [pid 765155:tid 765327] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-blink.php"] [unique_id "amuLwOT5hFAbD-LhWHiPEgAAAK8"]
[Thu Jul 30 12:37:04.210251 2026] [security2:error] [pid 765155:tid 765327] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-blink.php"] [unique_id "amuLwOT5hFAbD-LhWHiPEgAAAK8"]
[Thu Jul 30 12:37:04.520072 2026] [core:notice] [pid 765155:tid 765283] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:04.766220 2026] [security2:error] [pid 765155:tid 765331] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/randkeyword.PhP7"] [unique_id "amuLwOT5hFAbD-LhWHiPIQAAALM"]
[Thu Jul 30 12:37:04.922741 2026] [security2:error] [pid 765155:tid 765309] [client 20.63.98.115:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ty.php"] [unique_id "amuLwOT5hFAbD-LhWHiPIgAAAJ0"]
[Thu Jul 30 12:37:05.029599 2026] [security2:error] [pid 765155:tid 765324] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/ectoplasm/"] [unique_id "amuLweT5hFAbD-LhWHiPIwAAAKw"]
[Thu Jul 30 12:37:05.181249 2026] [core:error] [pid 765155:tid 765278] [remote 66.249.73.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:05.181271 2026] [core:error] [pid 765155:tid 765278] [remote 66.249.73.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:05.328905 2026] [security2:error] [pid 765155:tid 765296] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuLweT5hFAbD-LhWHiPLgAAAJA"]
[Thu Jul 30 12:37:05.588684 2026] [security2:error] [pid 765155:tid 765347] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ww5.php"] [unique_id "amuLweT5hFAbD-LhWHiPLwAAAMM"]
[Thu Jul 30 12:37:05.588811 2026] [security2:error] [pid 765155:tid 765347] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/ww5.php"] [unique_id "amuLweT5hFAbD-LhWHiPLwAAAMM"]
[Thu Jul 30 12:37:05.938060 2026] [security2:error] [pid 765155:tid 765338] [client 38.190.144.4:51117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLweT5hFAbD-LhWHiPOwAAALo"]
[Thu Jul 30 12:37:05.938175 2026] [security2:error] [pid 765155:tid 765338] [client 38.190.144.4:51117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLweT5hFAbD-LhWHiPOwAAALo"]
[Thu Jul 30 12:37:06.033675 2026] [core:notice] [pid 765155:tid 765177] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:06.087740 2026] [security2:error] [pid 765155:tid 765285] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/2.php"] [unique_id "amuLwuT5hFAbD-LhWHiPPgAAAIU"]
[Thu Jul 30 12:37:06.087864 2026] [security2:error] [pid 765155:tid 765285] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/2.php"] [unique_id "amuLwuT5hFAbD-LhWHiPPgAAAIU"]
[Thu Jul 30 12:37:06.202076 2026] [security2:error] [pid 765155:tid 765369] [client 20.151.221.234:20974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/w.php"] [unique_id "amuLwuT5hFAbD-LhWHiPRQAAANk"]
[Thu Jul 30 12:37:06.285005 2026] [security2:error] [pid 765155:tid 765354] [client 201.209.116.37:59912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLweT5hFAbD-LhWHiPPAAAAMo"], referer: http://pkf.jo
[Thu Jul 30 12:37:06.503261 2026] [core:notice] [pid 765155:tid 765395] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:06.577586 2026] [security2:error] [pid 765155:tid 765355] [client 198.163.194.127:7867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPSgAAAMs"], referer: http://pkf.jo
[Thu Jul 30 12:37:06.590435 2026] [security2:error] [pid 765155:tid 765315] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuLwuT5hFAbD-LhWHiPVgAAAKM"]
[Thu Jul 30 12:37:06.590546 2026] [security2:error] [pid 765155:tid 765315] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuLwuT5hFAbD-LhWHiPVgAAAKM"]
[Thu Jul 30 12:37:06.753545 2026] [security2:error] [pid 765155:tid 765320] [client 195.63.20.72:54094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuLwuT5hFAbD-LhWHiPVwAAqBs"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:37:06.886652 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:6801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPTgAAAPg"]
[Thu Jul 30 12:37:06.887401 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:4614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPSwAAAIY"]
[Thu Jul 30 12:37:06.973546 2026] [security2:error] [pid 765155:tid 765313] [client 20.151.221.234:54031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/admin.php"] [unique_id "amuLwuT5hFAbD-LhWHiPXwAAAKE"]
[Thu Jul 30 12:37:06.980499 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:17670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPUAAAAJo"]
[Thu Jul 30 12:37:07.019499 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:40437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLwuT5hFAbD-LhWHiPUQAAALI"]
[Thu Jul 30 12:37:07.115048 2026] [security2:error] [pid 765155:tid 765404] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/atomlib.php"] [unique_id "amuLw-T5hFAbD-LhWHiPZAAAAPw"]
[Thu Jul 30 12:37:07.115127 2026] [security2:error] [pid 765155:tid 765404] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/atomlib.php"] [unique_id "amuLw-T5hFAbD-LhWHiPZAAAAPw"]
[Thu Jul 30 12:37:07.160563 2026] [core:notice] [pid 765155:tid 765297] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:07.211472 2026] [security2:error] [pid 765155:tid 765398] [client 146.103.115.7:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.103.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/my-account/"] [unique_id "amuLwuT5hFAbD-LhWHiPXgAAAPY"], referer: http://smoke-tfhk.com/
[Thu Jul 30 12:37:07.550304 2026] [core:notice] [pid 765155:tid 765189] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:07.582401 2026] [security2:error] [pid 765155:tid 765297] [client 68.221.69.72:14619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuLw-T5hFAbD-LhWHiPaQAAAJE"]
[Thu Jul 30 12:37:07.650200 2026] [security2:error] [pid 765155:tid 765345] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/rip.php"] [unique_id "amuLw-T5hFAbD-LhWHiPiQAAAME"]
[Thu Jul 30 12:37:07.650390 2026] [security2:error] [pid 765155:tid 765345] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/rip.php"] [unique_id "amuLw-T5hFAbD-LhWHiPiQAAAME"]
[Thu Jul 30 12:37:07.935639 2026] [security2:error] [pid 765155:tid 765369] [client 20.151.221.234:20980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuLw-T5hFAbD-LhWHiPkgAAANk"]
[Thu Jul 30 12:37:08.124698 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:08.129102 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:23214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLxOT5hFAbD-LhWHiPmQAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:08.151202 2026] [security2:error] [pid 765155:tid 765371] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/p.php"] [unique_id "amuLxOT5hFAbD-LhWHiPmgAAANs"]
[Thu Jul 30 12:37:08.151349 2026] [security2:error] [pid 765155:tid 765371] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/p.php"] [unique_id "amuLxOT5hFAbD-LhWHiPmgAAANs"]
[Thu Jul 30 12:37:08.290206 2026] [security2:error] [pid 765155:tid 765316] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPgwAAAKQ"]
[Thu Jul 30 12:37:08.291560 2026] [security2:error] [pid 765155:tid 765406] [client 172.213.232.128:61323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/as.php"] [unique_id "amuLxOT5hFAbD-LhWHiPqAAAAP4"]
[Thu Jul 30 12:37:08.492808 2026] [security2:error] [pid 765155:tid 765335] [client 172.236.9.101:2768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPbgAAALc"]
[Thu Jul 30 12:37:08.499281 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:43872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPcAAAAMg"]
[Thu Jul 30 12:37:08.501230 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:15474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPbQAAAOg"]
[Thu Jul 30 12:37:08.518885 2026] [security2:error] [pid 765155:tid 765291] [client 172.236.9.101:1314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPbwAAAIs"]
[Thu Jul 30 12:37:08.586527 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:30089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPcgAAAI8"]
[Thu Jul 30 12:37:08.588784 2026] [security2:error] [pid 765155:tid 765323] [client 172.236.9.101:9845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPdQAAAKs"]
[Thu Jul 30 12:37:08.602967 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:54875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPdAAAANI"]
[Thu Jul 30 12:37:08.638003 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:24564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPcQAAANg"]
[Thu Jul 30 12:37:08.640110 2026] [security2:error] [pid 765155:tid 765379] [client 172.236.9.101:13558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPcwAAAOM"]
[Thu Jul 30 12:37:08.653828 2026] [security2:error] [pid 765155:tid 765289] [client 172.236.9.101:29658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPdwAAAIk"]
[Thu Jul 30 12:37:08.656094 2026] [security2:error] [pid 765155:tid 765287] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/php.php"] [unique_id "amuLxOT5hFAbD-LhWHiPrQAAAIc"]
[Thu Jul 30 12:37:08.656284 2026] [security2:error] [pid 765155:tid 765287] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/php.php"] [unique_id "amuLxOT5hFAbD-LhWHiPrQAAAIc"]
[Thu Jul 30 12:37:08.660742 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPewAAAO0"]
[Thu Jul 30 12:37:08.665683 2026] [security2:error] [pid 765155:tid 765350] [client 172.236.9.101:17991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPfAAAAMY"]
[Thu Jul 30 12:37:08.669016 2026] [security2:error] [pid 765155:tid 765296] [client 172.236.9.101:1385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPeAAAAJA"]
[Thu Jul 30 12:37:08.669016 2026] [security2:error] [pid 765155:tid 765370] [client 172.236.9.101:1509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPeQAAANo"]
[Thu Jul 30 12:37:08.674617 2026] [security2:error] [pid 765155:tid 765305] [client 172.236.9.101:53158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPdgAAAJk"]
[Thu Jul 30 12:37:08.684053 2026] [security2:error] [pid 765155:tid 765405] [client 172.236.9.101:59557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuLw-T5hFAbD-LhWHiPegAAAP0"]
[Thu Jul 30 12:37:08.854008 2026] [core:notice] [pid 765155:tid 765308] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:08.858593 2026] [security2:error] [pid 765155:tid 765308] [client 103.215.74.26:23230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLxOT5hFAbD-LhWHiPtQAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:09.067791 2026] [core:notice] [pid 765155:tid 765210] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:09.594437 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:09.598397 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:23232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLxeT5hFAbD-LhWHiP0QAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:09.817717 2026] [security2:error] [pid 765155:tid 765380] [client 172.213.232.128:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/atomlib.php"] [unique_id "amuLxeT5hFAbD-LhWHiP1gAAAOQ"]
[Thu Jul 30 12:37:10.060051 2026] [security2:error] [pid 765155:tid 765309] [client 150.107.232.194:26957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLxuT5hFAbD-LhWHiP3gAAAJ0"]
[Thu Jul 30 12:37:10.060162 2026] [security2:error] [pid 765155:tid 765309] [client 150.107.232.194:26957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuLxuT5hFAbD-LhWHiP3gAAAJ0"]
[Thu Jul 30 12:37:10.580548 2026] [core:notice] [pid 765155:tid 765214] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:10.902582 2026] [security2:error] [pid 765155:tid 765285] [client 20.151.221.234:20989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/m.php"] [unique_id "amuLxuT5hFAbD-LhWHiP9QAAAIU"]
[Thu Jul 30 12:37:11.420629 2026] [security2:error] [pid 765155:tid 765411] [client 185.191.171.19:61512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/04/mega-sena-concurso-deste-sabado-4-tem-premio-estimado-em-r-4-milhoes/"] [unique_id "amuLx-T5hFAbD-LhWHiP_gAAAQM"]
[Thu Jul 30 12:37:11.420761 2026] [security2:error] [pid 765155:tid 765411] [client 185.191.171.19:61512] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/04/mega-sena-concurso-deste-sabado-4-tem-premio-estimado-em-r-4-milhoes/"] [unique_id "amuLx-T5hFAbD-LhWHiP_gAAAQM"]
[Thu Jul 30 12:37:11.602241 2026] [security2:error] [pid 765155:tid 765315] [client 47.128.48.166:54176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ecre.ae"] [uri "/robots.txt"] [unique_id "amuLx-T5hFAbD-LhWHiQAwAAAKM"]
[Thu Jul 30 12:37:12.064660 2026] [security2:error] [pid 765155:tid 765326] [client 20.151.221.234:20876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuLx-T5hFAbD-LhWHiQBwAAAK4"]
[Thu Jul 30 12:37:12.092324 2026] [core:notice] [pid 765155:tid 765221] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:12.381375 2026] [security2:error] [pid 765155:tid 765322] [client 20.63.98.115:21133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/readme.php"] [unique_id "amuLyOT5hFAbD-LhWHiQFQAAAKo"]
[Thu Jul 30 12:37:12.441884 2026] [security2:error] [pid 765155:tid 765238] [remote 216.73.216.152:6815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuLyOT5hFAbD-LhWHiQGgAAq1I"]
[Thu Jul 30 12:37:13.315139 2026] [security2:error] [pid 765155:tid 765390] [client 20.63.98.115:49099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/options.php"] [unique_id "amuLyeT5hFAbD-LhWHiQKQAAAO4"]
[Thu Jul 30 12:37:13.611907 2026] [core:notice] [pid 765155:tid 765249] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:14.188766 2026] [security2:error] [pid 765155:tid 765246] [remote 47.128.24.74:63974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-mevius.com"] [uri "/product/terea-13/"] [unique_id "amuLyuT5hFAbD-LhWHiQQAAAilo"]
[Thu Jul 30 12:37:14.198875 2026] [security2:error] [pid 765155:tid 765356] [client 20.63.98.115:21017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/admin.php7"] [unique_id "amuLyuT5hFAbD-LhWHiQQQAAAMw"]
[Thu Jul 30 12:37:14.229670 2026] [security2:error] [pid 765155:tid 765358] [client 172.213.232.128:58157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/autoload_classmap.php"] [unique_id "amuLyuT5hFAbD-LhWHiQQgAAAM4"]
[Thu Jul 30 12:37:15.124519 2026] [core:notice] [pid 765155:tid 765240] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:15.338296 2026] [core:notice] [pid 765155:tid 765291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:15.342011 2026] [security2:error] [pid 765155:tid 765291] [client 103.215.74.26:41332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLy-T5hFAbD-LhWHiQYQAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:15.376705 2026] [security2:error] [pid 765155:tid 765379] [client 185.244.152.228:18263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLy-T5hFAbD-LhWHiQVQAAAOM"], referer: http://pkf.jo
[Thu Jul 30 12:37:16.075623 2026] [core:notice] [pid 765155:tid 765342] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:16.079707 2026] [security2:error] [pid 765155:tid 765342] [client 103.215.74.26:41346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLzOT5hFAbD-LhWHiQcAAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:16.162683 2026] [security2:error] [pid 765155:tid 765393] [client 216.73.216.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.embassyofbelgiumislamabad.cc"] [uri "/index.php"] [unique_id "amuLzOT5hFAbD-LhWHiQbQAA8Vs"]
[Thu Jul 30 12:37:16.359456 2026] [security2:error] [pid 765155:tid 765323] [client 20.63.98.115:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/wp-login.php"] [unique_id "amuLzOT5hFAbD-LhWHiQegAAAKs"]
[Thu Jul 30 12:37:16.637935 2026] [core:notice] [pid 765155:tid 765274] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:16.844120 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:16.849149 2026] [security2:error] [pid 765155:tid 765411] [client 38.190.144.4:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLzOT5hFAbD-LhWHiQjQAAAQM"]
[Thu Jul 30 12:37:16.849279 2026] [security2:error] [pid 765155:tid 765411] [client 38.190.144.4:51620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuLzOT5hFAbD-LhWHiQjQAAAQM"]
[Thu Jul 30 12:37:16.851615 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:41348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLzOT5hFAbD-LhWHiQjgAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:17.100624 2026] [security2:error] [pid 765155:tid 765375] [client 68.221.69.72:64782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/ws.php"] [unique_id "amuLzeT5hFAbD-LhWHiQkAAAAN8"]
[Thu Jul 30 12:37:17.100738 2026] [security2:error] [pid 765155:tid 765375] [client 68.221.69.72:64782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "radiojelli.com"] [uri "/ws.php"] [unique_id "amuLzeT5hFAbD-LhWHiQkAAAAN8"]
[Thu Jul 30 12:37:17.103481 2026] [security2:error] [pid 765155:tid 765311] [client 172.213.232.128:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/bb.php"] [unique_id "amuLzeT5hFAbD-LhWHiQkgAAAJ8"]
[Thu Jul 30 12:37:17.424181 2026] [security2:error] [pid 765155:tid 765373] [client 216.73.216.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guardian-heir.com"] [uri "/index.php"] [unique_id "amuLzeT5hFAbD-LhWHiQlwAA3Wc"]
[Thu Jul 30 12:37:17.587271 2026] [core:notice] [pid 765155:tid 765324] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:17.599626 2026] [security2:error] [pid 765155:tid 765324] [client 103.215.74.26:41352] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLzeT5hFAbD-LhWHiQngAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:17.759090 2026] [security2:error] [pid 765155:tid 765363] [client 20.63.98.115:47320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuLzeT5hFAbD-LhWHiQpgAAANM"]
[Thu Jul 30 12:37:17.827118 2026] [security2:error] [pid 765155:tid 765379] [client 20.104.18.253:26164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/011i.php"] [unique_id "amuLzeT5hFAbD-LhWHiQqwAAAOM"]
[Thu Jul 30 12:37:18.158234 2026] [core:notice] [pid 765155:tid 765242] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:18.298539 2026] [security2:error] [pid 765155:tid 765399] [client 195.200.28.67:53884] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.200.28.67" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuLzuT5hFAbD-LhWHiQvgAAAPc"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:37:18.325965 2026] [core:notice] [pid 765155:tid 765392] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:18.337262 2026] [security2:error] [pid 765155:tid 765392] [client 103.215.74.26:41356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuLzuT5hFAbD-LhWHiQvwAAAPA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:18.456970 2026] [security2:error] [pid 765155:tid 765321] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLzeT5hFAbD-LhWHiQrQAAAKk"]
[Thu Jul 30 12:37:18.465521 2026] [security2:error] [pid 765155:tid 765399] [client 195.200.28.67:53884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuLzuT5hFAbD-LhWHiQvgAAAPc"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:37:18.628130 2026] [security2:error] [pid 765155:tid 765278] [remote 52.167.144.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/138/131"] [unique_id "amuLzuT5hFAbD-LhWHiQxAAAm3o"]
[Thu Jul 30 12:37:18.679517 2026] [security2:error] [pid 765155:tid 765371] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuLzuT5hFAbD-LhWHiQwgAAANs"]
[Thu Jul 30 12:37:18.783127 2026] [security2:error] [pid 765155:tid 765320] [client 20.104.18.253:25922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/03a005685d.php"] [unique_id "amuLzuT5hFAbD-LhWHiQywAAAKg"]
[Thu Jul 30 12:37:18.798032 2026] [security2:error] [pid 765155:tid 765389] [client 195.200.28.67:53910] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.200.28.67" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuLzuT5hFAbD-LhWHiQzgAAAO0"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:37:18.963519 2026] [security2:error] [pid 765155:tid 765389] [client 195.200.28.67:53910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuLzuT5hFAbD-LhWHiQzgAAAO0"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:37:19.671610 2026] [core:notice] [pid 765155:tid 765172] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:20.037102 2026] [security2:error] [pid 765155:tid 765360] [client 153.117.11.4:10144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuLz-T5hFAbD-LhWHiQ5gAAANA"], referer: http://pkf.jo
[Thu Jul 30 12:37:20.290243 2026] [security2:error] [pid 765155:tid 765298] [client 150.107.232.194:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL0OT5hFAbD-LhWHiQ8wAAAJI"]
[Thu Jul 30 12:37:20.290354 2026] [security2:error] [pid 765155:tid 765298] [client 150.107.232.194:27073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL0OT5hFAbD-LhWHiQ8wAAAJI"]
[Thu Jul 30 12:37:20.574509 2026] [security2:error] [pid 765155:tid 765393] [client 20.104.18.253:43297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/403.php"] [unique_id "amuL0OT5hFAbD-LhWHiQ_QAAAPE"]
[Thu Jul 30 12:37:20.801874 2026] [security2:error] [pid 765155:tid 765342] [client 20.63.98.115:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/file.php"] [unique_id "amuL0OT5hFAbD-LhWHiRAwAAAL4"]
[Thu Jul 30 12:37:20.844629 2026] [security2:error] [pid 765155:tid 765377] [client 146.103.115.7:55757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuLz-T5hFAbD-LhWHiQ2wAAAOE"], referer: http://smoke-tfhk.com/xmlrpc.php
[Thu Jul 30 12:37:20.870150 2026] [core:notice] [pid 765155:tid 765156] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:21.028680 2026] [security2:error] [pid 765155:tid 765313] [client 172.213.232.128:59001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/bnm.php"] [unique_id "amuL0eT5hFAbD-LhWHiRDAAAAKE"]
[Thu Jul 30 12:37:21.443998 2026] [security2:error] [pid 765155:tid 765337] [client 102.211.145.195:42338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL0eT5hFAbD-LhWHiRDgAAALk"], referer: http://pkf.jo
[Thu Jul 30 12:37:21.497929 2026] [security2:error] [pid 765155:tid 765349] [client 20.104.18.253:47751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/404.php"] [unique_id "amuL0eT5hFAbD-LhWHiRGgAAAMU"]
[Thu Jul 30 12:37:21.588040 2026] [security2:error] [pid 765155:tid 765396] [client 94.20.26.237:56440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL0eT5hFAbD-LhWHiRDwAAAPQ"], referer: http://pkf.jo
[Thu Jul 30 12:37:21.991566 2026] [core:notice] [pid 765155:tid 765161] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:22.133083 2026] [security2:error] [pid 765155:tid 765341] [client 20.63.98.115:60255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/bak.php"] [unique_id "amuL0uT5hFAbD-LhWHiRJgAAAL0"]
[Thu Jul 30 12:37:22.516474 2026] [security2:error] [pid 765155:tid 765344] [client 20.104.18.253:53757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/aa.php"] [unique_id "amuL0uT5hFAbD-LhWHiRRwAAAMA"]
[Thu Jul 30 12:37:22.742161 2026] [security2:error] [pid 765155:tid 765368] [client 146.103.115.7:55994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuL0eT5hFAbD-LhWHiRDQAAANg"], referer: http://smoke-tfhk.com/xmlrpc.php
[Thu Jul 30 12:37:23.232921 2026] [security2:error] [pid 765155:tid 765320] [client 20.63.98.115:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/config.php"] [unique_id "amuL0-T5hFAbD-LhWHiRVQAAAKg"]
[Thu Jul 30 12:37:23.646575 2026] [core:notice] [pid 765155:tid 765384] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:24.057423 2026] [core:notice] [pid 765155:tid 765347] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:24.061336 2026] [security2:error] [pid 765155:tid 765347] [client 103.215.74.26:63946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL1OT5hFAbD-LhWHiRaAAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:24.282627 2026] [security2:error] [pid 765155:tid 765331] [client 172.236.9.101:19924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRLQAAALM"]
[Thu Jul 30 12:37:24.284053 2026] [security2:error] [pid 765155:tid 765304] [client 172.236.9.101:34203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRLAAAAJg"]
[Thu Jul 30 12:37:24.310590 2026] [security2:error] [pid 765155:tid 765401] [client 172.236.9.101:5534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRMAAAAPk"]
[Thu Jul 30 12:37:24.350030 2026] [security2:error] [pid 765155:tid 765364] [client 172.236.9.101:32227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRLgAAANQ"]
[Thu Jul 30 12:37:24.353910 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:21792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRMwAAAM0"]
[Thu Jul 30 12:37:24.356405 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:25625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRMgAAAMg"]
[Thu Jul 30 12:37:24.364129 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:20001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiROgAAANc"]
[Thu Jul 30 12:37:24.364490 2026] [security2:error] [pid 765155:tid 765369] [client 172.236.9.101:45788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRNgAAANk"]
[Thu Jul 30 12:37:24.371891 2026] [security2:error] [pid 765155:tid 765334] [client 172.236.9.101:59019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiROAAAALY"]
[Thu Jul 30 12:37:24.376076 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:18277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRPgAAAK8"]
[Thu Jul 30 12:37:24.376882 2026] [security2:error] [pid 765155:tid 765366] [client 172.236.9.101:22227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRKwAAANY"]
[Thu Jul 30 12:37:24.407607 2026] [security2:error] [pid 765155:tid 765290] [client 172.236.9.101:5733] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiROwAAAIo"]
[Thu Jul 30 12:37:24.429868 2026] [security2:error] [pid 765155:tid 765288] [client 172.236.9.101:30082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRPAAAAIg"]
[Thu Jul 30 12:37:24.437229 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:27034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRLwAAALs"]
[Thu Jul 30 12:37:24.440022 2026] [security2:error] [pid 765155:tid 765387] [client 172.213.232.128:53581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/bootstrap.php"] [unique_id "amuL1OT5hFAbD-LhWHiRcQAAAOs"]
[Thu Jul 30 12:37:24.443637 2026] [security2:error] [pid 765155:tid 765298] [client 172.236.9.101:30494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRQAAAAJI"]
[Thu Jul 30 12:37:24.452277 2026] [security2:error] [pid 765155:tid 765310] [client 172.236.9.101:60060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRKgAAAJ4"]
[Thu Jul 30 12:37:24.472955 2026] [security2:error] [pid 765155:tid 765388] [client 172.236.9.101:26753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRPwAAAOw"]
[Thu Jul 30 12:37:24.500829 2026] [security2:error] [pid 765155:tid 765294] [client 172.236.9.101:14127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRNwAAAI4"]
[Thu Jul 30 12:37:24.504854 2026] [security2:error] [pid 765155:tid 765396] [client 20.63.98.115:21127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amuL1OT5hFAbD-LhWHiRdQAAAPQ"]
[Thu Jul 30 12:37:24.583567 2026] [security2:error] [pid 765155:tid 765360] [client 172.236.9.101:39444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRMQAAANA"]
[Thu Jul 30 12:37:24.634014 2026] [security2:error] [pid 765155:tid 765350] [client 172.236.9.101:28917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL0uT5hFAbD-LhWHiRPQAAAMY"]
[Thu Jul 30 12:37:24.811096 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:24.815125 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:63960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL1OT5hFAbD-LhWHiRfgAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:25.285862 2026] [security2:error] [pid 765155:tid 765351] [client 172.213.232.128:58884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/buy.php"] [unique_id "amuL1eT5hFAbD-LhWHiRiwAAAMc"]
[Thu Jul 30 12:37:25.529691 2026] [security2:error] [pid 765155:tid 765365] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuL1eT5hFAbD-LhWHiRjwAAANU"]
[Thu Jul 30 12:37:25.543855 2026] [security2:error] [pid 765155:tid 765361] [client 20.63.98.115:49128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-activate.php"] [unique_id "amuL1eT5hFAbD-LhWHiRlAAAANE"]
[Thu Jul 30 12:37:25.574193 2026] [core:notice] [pid 765155:tid 765325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:25.580344 2026] [security2:error] [pid 765155:tid 765325] [client 103.215.74.26:63968] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL1eT5hFAbD-LhWHiRlwAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:25.785819 2026] [security2:error] [pid 765155:tid 765408] [client 20.104.18.253:57239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/aafewc0k.php"] [unique_id "amuL1eT5hFAbD-LhWHiRnQAAAQA"]
[Thu Jul 30 12:37:25.932087 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:26.189861 2026] [security2:error] [pid 765155:tid 765411] [client 172.213.232.128:59200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/chosen.php"] [unique_id "amuL1uT5hFAbD-LhWHiRrAAAAQM"]
[Thu Jul 30 12:37:26.300643 2026] [security2:error] [pid 765155:tid 765352] [client 50.6.43.217:40460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "smoke-tfhk.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuL1eT5hFAbD-LhWHiRkwAAAMg"]
[Thu Jul 30 12:37:26.311743 2026] [core:notice] [pid 765155:tid 765355] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:26.316862 2026] [security2:error] [pid 765155:tid 765320] [client 146.103.115.7:56470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "smoke-tfhk.com"] [uri "/wp-admin/post-new.php"] [unique_id "amuL1OT5hFAbD-LhWHiRfAAAAKg"], referer: http://smoke-tfhk.com/my-account/?action=register&xoo_el_reg_email=gb_roxanneculbert9581%40falderewonek.site&xoo_el_reg_fname=Ada&xoo_el_reg_lname=Goodson&xoo_el_reg_pass=rRyQ1bxn2mm0uk-&xoo_el_reg_pass_again=rRyQ1bxn2mm0uk-&xoo_el_reg_terms=yes&_xoo_el_form=register&xoo_el_redirect=%2Fmy-account%2F%3Faction%3Dregister
[Thu Jul 30 12:37:26.317719 2026] [security2:error] [pid 765155:tid 765355] [client 103.215.74.26:63972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL1uT5hFAbD-LhWHiRtQAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:26.646469 2026] [security2:error] [pid 765155:tid 765402] [client 20.104.18.253:25979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/abcd.php"] [unique_id "amuL1uT5hFAbD-LhWHiRwAAAAPo"]
[Thu Jul 30 12:37:26.771393 2026] [security2:error] [pid 765155:tid 765291] [client 20.63.98.115:47356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-file.php"] [unique_id "amuL1uT5hFAbD-LhWHiRxQAAAIs"]
[Thu Jul 30 12:37:26.818541 2026] [core:notice] [pid 765155:tid 765379] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:27.444276 2026] [security2:error] [pid 765155:tid 765401] [client 20.104.18.253:47763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/about.php"] [unique_id "amuL1-T5hFAbD-LhWHiR1gAAAPk"]
[Thu Jul 30 12:37:27.450001 2026] [security2:error] [pid 765155:tid 765254] [remote 216.73.216.152:36902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuL1-T5hFAbD-LhWHiR1wAAzGI"]
[Thu Jul 30 12:37:28.022021 2026] [security2:error] [pid 765155:tid 765387] [client 38.190.144.4:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL2OT5hFAbD-LhWHiR5AAAAOs"]
[Thu Jul 30 12:37:28.022263 2026] [security2:error] [pid 765155:tid 765387] [client 38.190.144.4:52124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL2OT5hFAbD-LhWHiR5AAAAOs"]
[Thu Jul 30 12:37:28.392820 2026] [security2:error] [pid 765155:tid 765352] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuL2OT5hFAbD-LhWHiR8gAAAMg"]
[Thu Jul 30 12:37:28.747227 2026] [security2:error] [pid 765155:tid 765373] [client 20.63.98.115:21038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/12.php"] [unique_id "amuL2OT5hFAbD-LhWHiSAAAAAN0"]
[Thu Jul 30 12:37:28.848286 2026] [security2:error] [pid 765155:tid 765368] [client 20.104.18.253:26254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/admin.php"] [unique_id "amuL2OT5hFAbD-LhWHiSBAAAANg"]
[Thu Jul 30 12:37:28.980050 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:29.348921 2026] [security2:error] [pid 765155:tid 765351] [client 172.213.232.128:62145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/class-wp-image.php"] [unique_id "amuL2eT5hFAbD-LhWHiSHwAAAMc"]
[Thu Jul 30 12:37:29.675185 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.18.253:25960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/adminfuns.php"] [unique_id "amuL2eT5hFAbD-LhWHiSJwAAALs"]
[Thu Jul 30 12:37:30.063173 2026] [security2:error] [pid 765155:tid 765386] [client 20.63.98.115:20797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/epinyins.php"] [unique_id "amuL2uT5hFAbD-LhWHiSMgAAAOo"]
[Thu Jul 30 12:37:30.452183 2026] [security2:error] [pid 765155:tid 765330] [client 172.213.232.128:62168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/classsmtps.php"] [unique_id "amuL2uT5hFAbD-LhWHiSRgAAALI"]
[Thu Jul 30 12:37:30.512900 2026] [security2:error] [pid 765155:tid 765337] [client 150.107.232.194:27049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL2uT5hFAbD-LhWHiSRwAAALk"]
[Thu Jul 30 12:37:30.513093 2026] [security2:error] [pid 765155:tid 765337] [client 150.107.232.194:27049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL2uT5hFAbD-LhWHiSRwAAALk"]
[Thu Jul 30 12:37:30.915175 2026] [security2:error] [pid 765155:tid 765287] [client 41.100.124.239:40364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL2uT5hFAbD-LhWHiSSQAAAIc"], referer: http://pkf.jo
[Thu Jul 30 12:37:31.271110 2026] [security2:error] [pid 765155:tid 765382] [client 20.63.98.115:20737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amuL2-T5hFAbD-LhWHiSWgAAAOY"]
[Thu Jul 30 12:37:31.603270 2026] [security2:error] [pid 765155:tid 765325] [client 95.95.51.42:33338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL2-T5hFAbD-LhWHiSXgAAAK0"], referer: http://pkf.jo
[Thu Jul 30 12:37:32.075529 2026] [core:notice] [pid 765155:tid 765374] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:32.079503 2026] [security2:error] [pid 765155:tid 765374] [client 103.215.74.26:63988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3OT5hFAbD-LhWHiSgQAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:32.356429 2026] [security2:error] [pid 765155:tid 765360] [client 172.213.232.128:62185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/classwithtostring.php"] [unique_id "amuL3OT5hFAbD-LhWHiSiwAAANA"]
[Thu Jul 30 12:37:32.458269 2026] [core:notice] [pid 765155:tid 765215] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:32.790348 2026] [security2:error] [pid 765155:tid 765391] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL3OT5hFAbD-LhWHiShAAAAO8"]
[Thu Jul 30 12:37:32.808623 2026] [core:notice] [pid 765155:tid 765223] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:32.828957 2026] [core:notice] [pid 765155:tid 765402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:32.832971 2026] [security2:error] [pid 765155:tid 765402] [client 103.215.74.26:63998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3OT5hFAbD-LhWHiSmQAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:32.849622 2026] [security2:error] [pid 765155:tid 765399] [client 20.104.18.253:37448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/albin.php"] [unique_id "amuL3OT5hFAbD-LhWHiSmgAAAPc"]
[Thu Jul 30 12:37:33.070929 2026] [security2:error] [pid 765155:tid 765292] [client 188.245.61.191:36032] ModSecurity: Access denied with code 406 (phase 1). Match of "rx (^/administrator/)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "63"] [id "331216"] [rev "2"] [msg "Atomicorp.com WAF Rules: Wordpress DOS Attack Dropped"] [severity "CRITICAL"] [hostname "jesus.claims"] [uri "/wp-load.php"] [unique_id "amuL3eT5hFAbD-LhWHiSngAAAIw"]
[Thu Jul 30 12:37:33.461019 2026] [security2:error] [pid 765155:tid 765357] [client 20.63.98.115:21269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/system_log.php"] [unique_id "amuL3eT5hFAbD-LhWHiSqwAAAM0"]
[Thu Jul 30 12:37:33.565732 2026] [core:notice] [pid 765155:tid 765293] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:33.569767 2026] [security2:error] [pid 765155:tid 765293] [client 103.215.74.26:50212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3eT5hFAbD-LhWHiSrAAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:34.334851 2026] [core:notice] [pid 765155:tid 765307] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:34.337190 2026] [security2:error] [pid 765155:tid 765409] [client 20.104.18.253:29059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/amfsqvgv.php"] [unique_id "amuL3uT5hFAbD-LhWHiSvQAAAQE"]
[Thu Jul 30 12:37:34.339339 2026] [security2:error] [pid 765155:tid 765307] [client 103.215.74.26:50224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3uT5hFAbD-LhWHiSvAAAAJs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:35.010498 2026] [core:notice] [pid 765155:tid 765372] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.092599 2026] [core:notice] [pid 765155:tid 765324] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.096432 2026] [security2:error] [pid 765155:tid 765324] [client 103.215.74.26:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3-T5hFAbD-LhWHiS0gAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:35.230905 2026] [security2:error] [pid 765155:tid 765304] [client 135.119.63.61:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/011i.php"] [unique_id "amuL3-T5hFAbD-LhWHiS1gAAAJg"]
[Thu Jul 30 12:37:35.273850 2026] [core:notice] [pid 765155:tid 765341] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.393924 2026] [core:notice] [pid 765155:tid 765398] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.540021 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.18.253:46819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/ant.php"] [unique_id "amuL3-T5hFAbD-LhWHiS4QAAANI"]
[Thu Jul 30 12:37:35.704442 2026] [security2:error] [pid 765155:tid 765318] [client 20.63.98.115:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuL3-T5hFAbD-LhWHiS5gAAAKY"]
[Thu Jul 30 12:37:35.824805 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:35.828790 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:50238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL3-T5hFAbD-LhWHiS5wAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:35.910818 2026] [security2:error] [pid 765155:tid 765388] [client 172.236.9.101:9392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL3-T5hFAbD-LhWHiS2gAAAOw"]
[Thu Jul 30 12:37:36.151271 2026] [security2:error] [pid 765155:tid 765291] [client 172.213.232.128:53626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/config.php"] [unique_id "amuL4OT5hFAbD-LhWHiS8wAAAIs"]
[Thu Jul 30 12:37:36.302759 2026] [security2:error] [pid 765155:tid 765300] [client 135.119.63.61:46187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/03a005685d.php"] [unique_id "amuL4OT5hFAbD-LhWHiS-wAAAJQ"]
[Thu Jul 30 12:37:36.368210 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:8153] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_rsa"] [unique_id "amuL4OT5hFAbD-LhWHiS_gAAALk"]
[Thu Jul 30 12:37:36.374359 2026] [security2:error] [pid 765155:tid 765289] [client 172.236.9.101:22365] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_dsa"] [unique_id "amuL4OT5hFAbD-LhWHiS_wAAAIk"]
[Thu Jul 30 12:37:36.381491 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:47921] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_rsa"] [unique_id "amuL4OT5hFAbD-LhWHiTAQAAAQE"]
[Thu Jul 30 12:37:36.402513 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:62274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/key.pem"] [unique_id "amuL4OT5hFAbD-LhWHiTBgAAALg"]
[Thu Jul 30 12:37:36.430213 2026] [security2:error] [pid 765155:tid 765373] [client 172.236.9.101:55459] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/privatekey.key"] [unique_id "amuL4OT5hFAbD-LhWHiTCgAAAN0"]
[Thu Jul 30 12:37:36.430618 2026] [security2:error] [pid 765155:tid 765345] [client 172.236.9.101:25304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_dsa"] [unique_id "amuL4OT5hFAbD-LhWHiTDgAAAME"]
[Thu Jul 30 12:37:36.900371 2026] [core:notice] [pid 765155:tid 765342] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:36.966574 2026] [security2:error] [pid 765155:tid 765365] [client 20.63.98.115:21143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ini.php"] [unique_id "amuL4OT5hFAbD-LhWHiTIwAAANU"]
[Thu Jul 30 12:37:37.357388 2026] [security2:error] [pid 765155:tid 765395] [client 172.236.9.101:24103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiS_AAAAPM"]
[Thu Jul 30 12:37:37.435690 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:46174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTAAAAAJs"]
[Thu Jul 30 12:37:37.437075 2026] [security2:error] [pid 765155:tid 765370] [client 172.236.9.101:26404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiS_QAAANo"]
[Thu Jul 30 12:37:37.450138 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:30139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTAgAAAPg"]
[Thu Jul 30 12:37:37.451075 2026] [security2:error] [pid 765155:tid 765385] [client 172.236.9.101:37071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTAwAAAOk"]
[Thu Jul 30 12:37:37.474161 2026] [security2:error] [pid 765155:tid 765338] [client 172.236.9.101:61949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTCAAAALo"]
[Thu Jul 30 12:37:37.475744 2026] [security2:error] [pid 765155:tid 765349] [client 172.236.9.101:2043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTBAAAAMU"]
[Thu Jul 30 12:37:37.488780 2026] [security2:error] [pid 765155:tid 765323] [client 172.236.9.101:41458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTBQAAAKs"]
[Thu Jul 30 12:37:37.505209 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:50684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTDQAAAPs"]
[Thu Jul 30 12:37:37.508572 2026] [security2:error] [pid 765155:tid 765346] [client 172.236.9.101:34476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTCQAAAMI"]
[Thu Jul 30 12:37:37.520901 2026] [security2:error] [pid 765155:tid 765392] [client 172.236.9.101:59718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTDAAAAPA"]
[Thu Jul 30 12:37:37.521485 2026] [security2:error] [pid 765155:tid 765312] [client 172.236.9.101:1720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTBwAAAKA"]
[Thu Jul 30 12:37:37.525604 2026] [security2:error] [pid 765155:tid 765313] [client 172.236.9.101:4831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTCwAAAKE"]
[Thu Jul 30 12:37:37.530580 2026] [security2:error] [pid 765155:tid 765298] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL4OT5hFAbD-LhWHiTIgAAAJI"]
[Thu Jul 30 12:37:37.579792 2026] [security2:error] [pid 765155:tid 765290] [client 135.119.63.61:46100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/403.php"] [unique_id "amuL4eT5hFAbD-LhWHiTNAAAAIo"]
[Thu Jul 30 12:37:37.731289 2026] [security2:error] [pid 765155:tid 765288] [client 185.24.61.123:29108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL4eT5hFAbD-LhWHiTLQAAAIg"], referer: http://pkf.jo
[Thu Jul 30 12:37:37.869324 2026] [security2:error] [pid 765155:tid 765410] [client 172.213.232.128:58466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/core.php"] [unique_id "amuL4eT5hFAbD-LhWHiTPwAAAQI"]
[Thu Jul 30 12:37:38.317342 2026] [security2:error] [pid 765155:tid 765319] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL4eT5hFAbD-LhWHiTPgAAAKc"]
[Thu Jul 30 12:37:38.667204 2026] [security2:error] [pid 765155:tid 765353] [client 20.63.98.115:21034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ok.php"] [unique_id "amuL4uT5hFAbD-LhWHiTUwAAAMk"]
[Thu Jul 30 12:37:38.741292 2026] [core:error] [pid 765155:tid 765321] [client 74.7.230.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:38.741336 2026] [core:error] [pid 765155:tid 765321] [client 74.7.230.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:38.741486 2026] [security2:error] [pid 765155:tid 765321] [client 74.7.230.55:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuL4uT5hFAbD-LhWHiTVgAAAKk"]
[Thu Jul 30 12:37:38.742137 2026] [security2:error] [pid 765155:tid 765292] [client 74.7.230.55:46720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuL4uT5hFAbD-LhWHiTVAAAjGs"]
[Thu Jul 30 12:37:38.753503 2026] [security2:error] [pid 765155:tid 765381] [client 135.119.63.61:46172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/404.php"] [unique_id "amuL4uT5hFAbD-LhWHiTVwAAAOU"]
[Thu Jul 30 12:37:39.038837 2026] [security2:error] [pid 765155:tid 765272] [remote 57.141.0.68:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuL4-T5hFAbD-LhWHiTYgAA83Q"]
[Thu Jul 30 12:37:39.254326 2026] [core:notice] [pid 765155:tid 765311] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:39.585370 2026] [security2:error] [pid 765155:tid 765380] [client 20.63.98.115:49229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuL4-T5hFAbD-LhWHiTdwAAAOQ"]
[Thu Jul 30 12:37:39.725875 2026] [core:notice] [pid 765155:tid 765377] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:39.726480 2026] [security2:error] [pid 765155:tid 765322] [client 135.119.63.61:46121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/aa.php"] [unique_id "amuL4-T5hFAbD-LhWHiTfgAAAKo"]
[Thu Jul 30 12:37:39.950832 2026] [core:notice] [pid 765155:tid 765360] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:40.063461 2026] [core:notice] [pid 765155:tid 765162] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:40.434881 2026] [security2:error] [pid 765155:tid 765400] [client 172.213.232.128:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/css.php"] [unique_id "amuL5OT5hFAbD-LhWHiTkwAAAPg"]
[Thu Jul 30 12:37:40.988783 2026] [security2:error] [pid 765155:tid 765362] [client 150.107.232.194:27385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL5OT5hFAbD-LhWHiToAAAANI"]
[Thu Jul 30 12:37:40.988896 2026] [security2:error] [pid 765155:tid 765362] [client 150.107.232.194:27385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL5OT5hFAbD-LhWHiToAAAANI"]
[Thu Jul 30 12:37:41.335573 2026] [security2:error] [pid 765155:tid 765319] [client 135.119.63.61:45844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/aafewc0k.php"] [unique_id "amuL5eT5hFAbD-LhWHiTrAAAAKc"]
[Thu Jul 30 12:37:41.360746 2026] [security2:error] [pid 765155:tid 765287] [client 20.104.18.253:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/appreciators.php"] [unique_id "amuL5eT5hFAbD-LhWHiTrQAAAIc"]
[Thu Jul 30 12:37:41.551714 2026] [security2:error] [pid 765155:tid 765408] [client 172.213.232.128:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/database.php"] [unique_id "amuL5eT5hFAbD-LhWHiTsQAAAQA"]
[Thu Jul 30 12:37:41.574561 2026] [core:notice] [pid 765155:tid 765313] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:41.579912 2026] [security2:error] [pid 765155:tid 765313] [client 103.215.74.26:50260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL5eT5hFAbD-LhWHiTsgAAAKE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:42.127001 2026] [security2:error] [pid 765155:tid 765405] [client 135.119.63.61:45851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/abcd.php"] [unique_id "amuL5uT5hFAbD-LhWHiTvAAAAP0"]
[Thu Jul 30 12:37:42.300515 2026] [core:notice] [pid 765155:tid 765393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:42.304541 2026] [security2:error] [pid 765155:tid 765393] [client 103.215.74.26:50284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL5uT5hFAbD-LhWHiTwAAAAPE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:42.625287 2026] [core:error] [pid 765155:tid 765363] [client 20.63.98.115:49097] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:42.625313 2026] [core:error] [pid 765155:tid 765363] [client 20.63.98.115:49097] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:37:42.752077 2026] [security2:error] [pid 765155:tid 765303] [client 20.104.18.253:53341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/archive.php"] [unique_id "amuL5uT5hFAbD-LhWHiTywAAAJc"]
[Thu Jul 30 12:37:43.100698 2026] [security2:error] [pid 765155:tid 765411] [client 135.119.63.61:46133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/about.php"] [unique_id "amuL5-T5hFAbD-LhWHiT2gAAAQM"]
[Thu Jul 30 12:37:43.550320 2026] [security2:error] [pid 765155:tid 765400] [client 185.191.171.13:19926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/21/nova-sala-de-reuniao-da-camara-de-pirpirituba-tera-o-nome-do-ex-vereador-argemiro-moura/"] [unique_id "amuL5-T5hFAbD-LhWHiT4wAAAPg"]
[Thu Jul 30 12:37:43.550442 2026] [security2:error] [pid 765155:tid 765400] [client 185.191.171.13:19926] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/21/nova-sala-de-reuniao-da-camara-de-pirpirituba-tera-o-nome-do-ex-vereador-argemiro-moura/"] [unique_id "amuL5-T5hFAbD-LhWHiT4wAAAPg"]
[Thu Jul 30 12:37:43.716704 2026] [security2:error] [pid 765155:tid 765348] [client 172.213.232.128:53697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/db.php"] [unique_id "amuL5-T5hFAbD-LhWHiT5QAAAMQ"]
[Thu Jul 30 12:37:43.777885 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.18.253:34692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/as.php"] [unique_id "amuL5-T5hFAbD-LhWHiT5gAAALs"]
[Thu Jul 30 12:37:43.973421 2026] [security2:error] [pid 765155:tid 765305] [client 135.119.63.61:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/admin.php"] [unique_id "amuL5-T5hFAbD-LhWHiT7QAAAJk"]
[Thu Jul 30 12:37:45.297412 2026] [security2:error] [pid 765155:tid 765398] [client 20.63.98.115:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-configs.php"] [unique_id "amuL6eT5hFAbD-LhWHiUBwAAAPY"]
[Thu Jul 30 12:37:45.496252 2026] [security2:error] [pid 765155:tid 765368] [client 20.104.18.253:46843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/atomlib.php"] [unique_id "amuL6eT5hFAbD-LhWHiUCwAAANg"]
[Thu Jul 30 12:37:45.947691 2026] [security2:error] [pid 765155:tid 765323] [client 172.213.232.128:62342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/default.php"] [unique_id "amuL6eT5hFAbD-LhWHiUEwAAAKs"]
[Thu Jul 30 12:37:45.961833 2026] [security2:error] [pid 765155:tid 765291] [client 3.149.57.90:56214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuL6OT5hFAbD-LhWHiT-wAAAIs"], referer: https://globalmarks.pk/
[Thu Jul 30 12:37:45.994604 2026] [security2:error] [pid 765155:tid 765324] [client 216.73.216.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thesounddepot.com"] [uri "/index.php"] [unique_id "amuL5-T5hFAbD-LhWHiT1wAAAKw"]
[Thu Jul 30 12:37:46.019852 2026] [security2:error] [pid 765155:tid 765356] [client 135.119.63.61:46130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/adminfuns.php"] [unique_id "amuL6uT5hFAbD-LhWHiUFwAAAMw"]
[Thu Jul 30 12:37:46.649568 2026] [security2:error] [pid 765155:tid 765349] [client 20.104.18.253:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/autoload_classmap.php"] [unique_id "amuL6uT5hFAbD-LhWHiUJgAAAMU"]
[Thu Jul 30 12:37:48.030954 2026] [core:notice] [pid 765155:tid 765398] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:48.037963 2026] [security2:error] [pid 765155:tid 765398] [client 103.215.74.26:6532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7OT5hFAbD-LhWHiUQgAAAPY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:48.124739 2026] [security2:error] [pid 765155:tid 765383] [client 172.213.232.128:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/dropdown.php"] [unique_id "amuL7OT5hFAbD-LhWHiURgAAAOc"]
[Thu Jul 30 12:37:48.138961 2026] [security2:error] [pid 765155:tid 765405] [client 20.104.18.253:39448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/bb.php"] [unique_id "amuL7OT5hFAbD-LhWHiUSAAAAP0"]
[Thu Jul 30 12:37:48.759918 2026] [core:notice] [pid 765155:tid 765324] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:48.764431 2026] [security2:error] [pid 765155:tid 765324] [client 103.215.74.26:6546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7OT5hFAbD-LhWHiUVwAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:49.206874 2026] [core:notice] [pid 765155:tid 765312] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:49.282094 2026] [core:notice] [pid 765155:tid 765318] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:49.344665 2026] [security2:error] [pid 765155:tid 765319] [client 135.119.63.61:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/albin.php"] [unique_id "amuL7eT5hFAbD-LhWHiUbwAAAKc"]
[Thu Jul 30 12:37:49.384421 2026] [security2:error] [pid 765155:tid 765329] [client 20.63.98.115:65339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/01.php"] [unique_id "amuL7eT5hFAbD-LhWHiUcAAAALE"]
[Thu Jul 30 12:37:49.527091 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:49.531568 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:6562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7eT5hFAbD-LhWHiUcQAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:49.660131 2026] [proxy:error] [pid 765155:tid 765375] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:49.660182 2026] [proxy_http:error] [pid 765155:tid 765375] [client 3.225.222.228:30352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:49.660739 2026] [proxy:error] [pid 765155:tid 765375] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:49.660784 2026] [proxy_http:error] [pid 765155:tid 765375] [client 3.225.222.228:30352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:49.671694 2026] [proxy:error] [pid 765155:tid 765358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:49.671765 2026] [proxy_http:error] [pid 765155:tid 765358] [client 44.213.206.96:52745] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:49.672627 2026] [proxy:error] [pid 765155:tid 765358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:49.672687 2026] [proxy_http:error] [pid 765155:tid 765358] [client 44.213.206.96:52745] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:50.171673 2026] [security2:error] [pid 765155:tid 765395] [client 20.104.18.253:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/bnm.php"] [unique_id "amuL7uT5hFAbD-LhWHiUiwAAAPM"]
[Thu Jul 30 12:37:50.279137 2026] [core:notice] [pid 765155:tid 765316] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:50.283509 2026] [security2:error] [pid 765155:tid 765316] [client 103.215.74.26:6572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7uT5hFAbD-LhWHiUkQAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:50.773697 2026] [security2:error] [pid 765155:tid 765390] [client 135.119.63.61:46178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/amfsqvgv.php"] [unique_id "amuL7uT5hFAbD-LhWHiUmAAAAO4"]
[Thu Jul 30 12:37:50.879636 2026] [security2:error] [pid 765155:tid 765343] [client 172.213.232.128:53625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/edit.php"] [unique_id "amuL7uT5hFAbD-LhWHiUnAAAAL8"]
[Thu Jul 30 12:37:51.048763 2026] [core:notice] [pid 765155:tid 765321] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:51.053485 2026] [security2:error] [pid 765155:tid 765321] [client 103.215.74.26:6578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7-T5hFAbD-LhWHiUoQAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:51.268636 2026] [security2:error] [pid 765155:tid 765346] [client 74.7.230.57:37776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.tgr.fiyan.co"] [uri "/cgi-sys/404.html"] [unique_id "amuL7-T5hFAbD-LhWHiUqAAAwms"]
[Thu Jul 30 12:37:51.288659 2026] [security2:error] [pid 765155:tid 765370] [client 20.104.18.253:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/bootstrap.php"] [unique_id "amuL7-T5hFAbD-LhWHiUrAAAANo"]
[Thu Jul 30 12:37:51.460172 2026] [security2:error] [pid 765155:tid 765314] [client 119.73.97.132:29563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuL7-T5hFAbD-LhWHiUogAAomk"]
[Thu Jul 30 12:37:51.514278 2026] [security2:error] [pid 765155:tid 765302] [client 150.107.232.194:26621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL7-T5hFAbD-LhWHiUuAAAAJY"]
[Thu Jul 30 12:37:51.514438 2026] [security2:error] [pid 765155:tid 765302] [client 150.107.232.194:26621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL7-T5hFAbD-LhWHiUuAAAAJY"]
[Thu Jul 30 12:37:51.547192 2026] [security2:error] [pid 765155:tid 765314] [client 119.73.97.132:29563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuL7-T5hFAbD-LhWHiUpAAAogo"]
[Thu Jul 30 12:37:51.734025 2026] [security2:error] [pid 765155:tid 765300] [client 20.63.98.115:38872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amuL7-T5hFAbD-LhWHiUuQAAAJQ"]
[Thu Jul 30 12:37:51.758042 2026] [security2:error] [pid 765155:tid 765306] [client 135.119.63.61:46153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/ant.php"] [unique_id "amuL7-T5hFAbD-LhWHiUugAAAJo"]
[Thu Jul 30 12:37:51.809671 2026] [core:notice] [pid 765155:tid 765288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:51.817165 2026] [security2:error] [pid 765155:tid 765288] [client 103.215.74.26:6584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL7-T5hFAbD-LhWHiUvgAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:51.902713 2026] [security2:error] [pid 765155:tid 765318] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL7-T5hFAbD-LhWHiUqwAAAKY"]
[Thu Jul 30 12:37:52.214960 2026] [security2:error] [pid 765155:tid 765336] [client 20.104.18.253:29764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/buy.php"] [unique_id "amuL8OT5hFAbD-LhWHiUyQAAALg"]
[Thu Jul 30 12:37:52.542143 2026] [core:notice] [pid 765155:tid 765323] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:52.546624 2026] [security2:error] [pid 765155:tid 765323] [client 103.215.74.26:6596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8OT5hFAbD-LhWHiU1gAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:52.614104 2026] [security2:error] [pid 765155:tid 765291] [client 135.119.63.61:46203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/appreciators.php"] [unique_id "amuL8OT5hFAbD-LhWHiU1wAAAIs"]
[Thu Jul 30 12:37:53.064907 2026] [security2:error] [pid 765155:tid 765330] [client 119.73.97.132:29563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuL8OT5hFAbD-LhWHiU0QAAsng"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:37:53.113629 2026] [security2:error] [pid 765155:tid 765315] [client 20.63.98.115:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amuL8eT5hFAbD-LhWHiU4wAAAKM"]
[Thu Jul 30 12:37:53.276744 2026] [core:notice] [pid 765155:tid 765312] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:53.283896 2026] [security2:error] [pid 765155:tid 765312] [client 103.215.74.26:56954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8eT5hFAbD-LhWHiU5QAAAKA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:53.815921 2026] [security2:error] [pid 765155:tid 765344] [client 20.104.18.253:53874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/chosen.php"] [unique_id "amuL8eT5hFAbD-LhWHiU9AAAAMA"]
[Thu Jul 30 12:37:54.023526 2026] [core:notice] [pid 765155:tid 765288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:54.028046 2026] [security2:error] [pid 765155:tid 765288] [client 103.215.74.26:56956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8uT5hFAbD-LhWHiU-wAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:54.330849 2026] [security2:error] [pid 765155:tid 765306] [client 20.63.98.115:65321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuL8uT5hFAbD-LhWHiVAQAAAJo"]
[Thu Jul 30 12:37:54.688698 2026] [security2:error] [pid 765155:tid 765342] [client 172.213.232.128:53705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/f35.php"] [unique_id "amuL8uT5hFAbD-LhWHiVDAAAAL4"]
[Thu Jul 30 12:37:54.748678 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:54.752471 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:56972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8uT5hFAbD-LhWHiVDwAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:54.824129 2026] [security2:error] [pid 765155:tid 765364] [client 20.104.18.253:25736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/class-wp-image.php"] [unique_id "amuL8uT5hFAbD-LhWHiVEQAAANQ"]
[Thu Jul 30 12:37:55.160255 2026] [security2:error] [pid 765155:tid 765325] [client 135.119.63.61:46186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/archive.php"] [unique_id "amuL8-T5hFAbD-LhWHiVGwAAAK0"]
[Thu Jul 30 12:37:55.340655 2026] [security2:error] [pid 765155:tid 765299] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL8uT5hFAbD-LhWHiVEAAAAJM"]
[Thu Jul 30 12:37:55.489249 2026] [core:notice] [pid 765155:tid 765301] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:55.493381 2026] [security2:error] [pid 765155:tid 765301] [client 103.215.74.26:56980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL8-T5hFAbD-LhWHiVIAAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:55.641892 2026] [proxy:error] [pid 765155:tid 765346] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:55.641958 2026] [proxy_http:error] [pid 765155:tid 765346] [client 3.228.112.215:55466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:55.642526 2026] [proxy:error] [pid 765155:tid 765346] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:55.642569 2026] [proxy_http:error] [pid 765155:tid 765346] [client 3.228.112.215:55466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:55.676110 2026] [proxy:error] [pid 765155:tid 765406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:55.676191 2026] [proxy_http:error] [pid 765155:tid 765406] [client 3.228.112.215:42151] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:55.677021 2026] [proxy:error] [pid 765155:tid 765406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:37:55.677075 2026] [proxy_http:error] [pid 765155:tid 765406] [client 3.228.112.215:42151] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:37:55.954815 2026] [security2:error] [pid 765155:tid 765302] [client 135.119.63.61:45843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/as.php"] [unique_id "amuL8-T5hFAbD-LhWHiVMAAAAJY"]
[Thu Jul 30 12:37:55.989372 2026] [security2:error] [pid 765155:tid 765358] [client 20.104.18.253:39469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/classsmtps.php"] [unique_id "amuL8-T5hFAbD-LhWHiVNAAAAM4"]
[Thu Jul 30 12:37:56.053052 2026] [security2:error] [pid 765155:tid 765400] [client 172.213.232.128:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/f7.php"] [unique_id "amuL9OT5hFAbD-LhWHiVOAAAAPg"]
[Thu Jul 30 12:37:56.228286 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:56.235224 2026] [security2:error] [pid 765155:tid 765359] [client 103.215.74.26:56994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9OT5hFAbD-LhWHiVPAAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:56.293918 2026] [security2:error] [pid 765155:tid 765303] [client 20.63.98.115:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/db.php"] [unique_id "amuL9OT5hFAbD-LhWHiVPQAAAJc"]
[Thu Jul 30 12:37:56.955024 2026] [security2:error] [pid 765155:tid 765352] [client 38.190.144.4:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL9OT5hFAbD-LhWHiVTwAAAMg"]
[Thu Jul 30 12:37:56.955157 2026] [security2:error] [pid 765155:tid 765352] [client 38.190.144.4:53154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL9OT5hFAbD-LhWHiVTwAAAMg"]
[Thu Jul 30 12:37:56.962150 2026] [core:notice] [pid 765155:tid 765317] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:56.968897 2026] [security2:error] [pid 765155:tid 765317] [client 103.215.74.26:57002] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9OT5hFAbD-LhWHiVUAAAAKU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:56.977869 2026] [security2:error] [pid 765155:tid 765348] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL9OT5hFAbD-LhWHiVQQAAAMQ"]
[Thu Jul 30 12:37:57.019638 2026] [security2:error] [pid 765155:tid 765351] [client 135.119.63.61:46107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/atomlib.php"] [unique_id "amuL9eT5hFAbD-LhWHiVUgAAAMc"]
[Thu Jul 30 12:37:57.172733 2026] [security2:error] [pid 765155:tid 765394] [client 20.104.18.253:53836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/classwithtostring.php"] [unique_id "amuL9eT5hFAbD-LhWHiVWgAAAPI"]
[Thu Jul 30 12:37:57.708517 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:57.712498 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:57008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "738"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9eT5hFAbD-LhWHiVZwAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:58.013073 2026] [security2:error] [pid 765155:tid 765398] [client 62.102.148.158:55040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuL9uT5hFAbD-LhWHiVcQAAAPY"]
[Thu Jul 30 12:37:58.013168 2026] [security2:error] [pid 765155:tid 765398] [client 62.102.148.158:55040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuL9uT5hFAbD-LhWHiVcQAAAPY"]
[Thu Jul 30 12:37:58.095782 2026] [core:notice] [pid 765155:tid 765212] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:58.175434 2026] [security2:error] [pid 765155:tid 765406] [client 20.104.18.253:53331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/config.php"] [unique_id "amuL9uT5hFAbD-LhWHiVdwAAAP4"]
[Thu Jul 30 12:37:58.425427 2026] [core:notice] [pid 765155:tid 765379] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:58.429360 2026] [security2:error] [pid 765155:tid 765379] [client 103.215.74.26:57012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "756"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9uT5hFAbD-LhWHiVfwAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:58.634894 2026] [security2:error] [pid 765155:tid 765334] [client 195.63.22.178:33340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuL9uT5hFAbD-LhWHiVgwAAtkc"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:37:58.727940 2026] [core:notice] [pid 765155:tid 765208] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:58.768150 2026] [security2:error] [pid 765155:tid 765404] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuL9uT5hFAbD-LhWHiVdgAA_Ds"]
[Thu Jul 30 12:37:59.175545 2026] [core:notice] [pid 765155:tid 765331] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:59.186125 2026] [security2:error] [pid 765155:tid 765331] [client 103.215.74.26:57014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9-T5hFAbD-LhWHiVmQAAALM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:37:59.443365 2026] [security2:error] [pid 765155:tid 765362] [client 20.104.18.253:45219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/core.php"] [unique_id "amuL9-T5hFAbD-LhWHiVnQAAANI"]
[Thu Jul 30 12:37:59.560676 2026] [security2:error] [pid 765155:tid 765324] [client 20.63.98.115:39197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/pages.php"] [unique_id "amuL9-T5hFAbD-LhWHiVoQAAAKw"]
[Thu Jul 30 12:37:59.604400 2026] [core:notice] [pid 765155:tid 765312] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:59.933890 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:37:59.937847 2026] [security2:error] [pid 765155:tid 765388] [client 103.215.74.26:57024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "769"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL9-T5hFAbD-LhWHiVrAAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:00.180494 2026] [core:notice] [pid 765155:tid 765384] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:00.620239 2026] [security2:error] [pid 765155:tid 765339] [client 20.104.18.253:25698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/css.php"] [unique_id "amuL-OT5hFAbD-LhWHiVxwAAALs"]
[Thu Jul 30 12:38:00.725987 2026] [fcgid:warn] [pid 765155:tid 765316] (70014)End of file found: [client 156.229.16.165:46654] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:01.107585 2026] [security2:error] [pid 765155:tid 765372] [client 194.187.251.163:46446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV0QAAANw"]
[Thu Jul 30 12:38:01.107694 2026] [security2:error] [pid 765155:tid 765372] [client 194.187.251.163:46446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV0QAAANw"]
[Thu Jul 30 12:38:01.125956 2026] [security2:error] [pid 765155:tid 765404] [client 20.63.98.115:38867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/admin.php"] [unique_id "amuL-eT5hFAbD-LhWHiV1AAAAPw"]
[Thu Jul 30 12:38:01.362113 2026] [security2:error] [pid 765155:tid 765363] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuL-OT5hFAbD-LhWHiVzAAA0ww"]
[Thu Jul 30 12:38:01.716160 2026] [security2:error] [pid 765155:tid 765343] [client 66.249.73.98:51485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuL-eT5hFAbD-LhWHiV4gAAAL8"]
[Thu Jul 30 12:38:01.905955 2026] [security2:error] [pid 765155:tid 765292] [client 194.187.251.163:46458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV9wAAAIw"]
[Thu Jul 30 12:38:01.906072 2026] [security2:error] [pid 765155:tid 765292] [client 194.187.251.163:46458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV9wAAAIw"]
[Thu Jul 30 12:38:01.965660 2026] [security2:error] [pid 765155:tid 765360] [client 150.107.232.194:26745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV-gAAANA"]
[Thu Jul 30 12:38:01.965823 2026] [security2:error] [pid 765155:tid 765360] [client 150.107.232.194:26745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuL-eT5hFAbD-LhWHiV-gAAANA"]
[Thu Jul 30 12:38:02.007127 2026] [security2:error] [pid 765155:tid 765327] [client 20.63.98.115:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-load.php"] [unique_id "amuL-uT5hFAbD-LhWHiV_QAAAK8"]
[Thu Jul 30 12:38:02.105721 2026] [security2:error] [pid 765155:tid 765401] [client 20.104.18.253:33638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/database.php"] [unique_id "amuL-uT5hFAbD-LhWHiV_gAAAPk"]
[Thu Jul 30 12:38:02.354402 2026] [security2:error] [pid 765155:tid 765336] [client 85.208.96.193:31656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2022/02/download-bios-lenovo-thinkpad-t430"] [unique_id "amuL-uT5hFAbD-LhWHiWCwAAALg"]
[Thu Jul 30 12:38:02.354544 2026] [security2:error] [pid 765155:tid 765336] [client 85.208.96.193:31656] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2022/02/download-bios-lenovo-thinkpad-t430"] [unique_id "amuL-uT5hFAbD-LhWHiWCwAAALg"]
[Thu Jul 30 12:38:02.473338 2026] [autoindex:error] [pid 765155:tid 765320] [client 64.69.216.78:50864] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:38:02.568145 2026] [security2:error] [pid 765155:tid 765295] [client 20.215.191.139:11385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/geju.php"] [unique_id "amuL-uT5hFAbD-LhWHiWEQAAAI8"]
[Thu Jul 30 12:38:02.952836 2026] [security2:error] [pid 765155:tid 765316] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuL-uT5hFAbD-LhWHiWDAAAAKQ"]
[Thu Jul 30 12:38:03.298657 2026] [security2:error] [pid 765155:tid 765369] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuL-uT5hFAbD-LhWHiWEwAA2XA"]
[Thu Jul 30 12:38:03.301909 2026] [fcgid:warn] [pid 765155:tid 765393] (70014)End of file found: [client 104.28.219.195:40327] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:03.310460 2026] [fcgid:warn] [pid 765155:tid 765292] (70014)End of file found: [client 104.28.219.195:40328] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:03.376257 2026] [security2:error] [pid 765155:tid 765291] [client 20.63.98.115:38878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/as/function.php"] [unique_id "amuL--T5hFAbD-LhWHiWMAAAAIs"]
[Thu Jul 30 12:38:03.434665 2026] [security2:error] [pid 765155:tid 765357] [client 20.215.191.139:2354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuL--T5hFAbD-LhWHiWNAAAAM0"]
[Thu Jul 30 12:38:03.458113 2026] [security2:error] [pid 765155:tid 765349] [client 20.104.18.253:33652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/db.php"] [unique_id "amuL--T5hFAbD-LhWHiWNQAAAMU"]
[Thu Jul 30 12:38:03.555116 2026] [security2:error] [pid 765155:tid 765329] [client 104.28.219.195:40336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.219.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abs-sa.net"] [uri "/index.php"] [unique_id "amuL--T5hFAbD-LhWHiWKgAAALE"]
[Thu Jul 30 12:38:03.555264 2026] [security2:error] [pid 765155:tid 765329] [client 104.28.219.195:40336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "mail.abs-sa.net"] [uri "/index.php"] [unique_id "amuL--T5hFAbD-LhWHiWKgAAALE"]
[Thu Jul 30 12:38:04.128148 2026] [autoindex:error] [pid 765155:tid 765320] [client 64.69.216.78:50972] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:38:04.130442 2026] [security2:error] [pid 765155:tid 765336] [client 20.215.191.139:6981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp.php"] [unique_id "amuL_OT5hFAbD-LhWHiWRwAAALg"]
[Thu Jul 30 12:38:04.312135 2026] [security2:error] [pid 765155:tid 765321] [client 20.63.98.115:43279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/filter.php"] [unique_id "amuL_OT5hFAbD-LhWHiWSwAAAKk"]
[Thu Jul 30 12:38:04.502423 2026] [fcgid:warn] [pid 765155:tid 765384] (70014)End of file found: [client 104.28.219.195:40339] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:04.791211 2026] [security2:error] [pid 765155:tid 765333] [client 135.119.63.61:45831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/autoload_classmap.php"] [unique_id "amuL_OT5hFAbD-LhWHiWVwAAALU"]
[Thu Jul 30 12:38:04.813720 2026] [security2:error] [pid 765155:tid 765317] [client 20.104.18.253:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/default.php"] [unique_id "amuL_OT5hFAbD-LhWHiWWAAAAKU"]
[Thu Jul 30 12:38:05.154844 2026] [security2:error] [pid 765155:tid 765311] [client 20.215.191.139:2341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/aaa.php"] [unique_id "amuL_eT5hFAbD-LhWHiWYgAAAJ8"]
[Thu Jul 30 12:38:05.169475 2026] [core:notice] [pid 765155:tid 765281] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:05.548832 2026] [security2:error] [pid 765155:tid 765164] [remote 74.7.241.60:58830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amuL_eT5hFAbD-LhWHiWdAAAxgg"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 12:38:05.664403 2026] [core:notice] [pid 765155:tid 765323] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:05.668515 2026] [security2:error] [pid 765155:tid 765323] [client 103.215.74.26:17734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL_eT5hFAbD-LhWHiWdQAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:05.870109 2026] [security2:error] [pid 765155:tid 765357] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuL_eT5hFAbD-LhWHiWZwAAzW8"]
[Thu Jul 30 12:38:06.009335 2026] [security2:error] [pid 765155:tid 765406] [client 62.102.148.158:55822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuL_uT5hFAbD-LhWHiWfQAAAP4"]
[Thu Jul 30 12:38:06.009481 2026] [security2:error] [pid 765155:tid 765406] [client 62.102.148.158:55822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuL_uT5hFAbD-LhWHiWfQAAAP4"]
[Thu Jul 30 12:38:06.239092 2026] [security2:error] [pid 765155:tid 765302] [client 135.119.63.61:45835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/bb.php"] [unique_id "amuL_uT5hFAbD-LhWHiWggAAAJY"]
[Thu Jul 30 12:38:06.387943 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:06.392230 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:17738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "745"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL_uT5hFAbD-LhWHiWhgAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:06.408388 2026] [proxy:error] [pid 765155:tid 765169] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:06.408444 2026] [proxy_http:error] [pid 765155:tid 765169] [remote 143.244.47.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:06.409053 2026] [proxy:error] [pid 765155:tid 765169] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:06.409102 2026] [proxy_http:error] [pid 765155:tid 765169] [remote 143.244.47.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:06.713714 2026] [security2:error] [pid 765155:tid 765343] [client 20.63.98.115:43305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/he.php"] [unique_id "amuL_uT5hFAbD-LhWHiWkAAAAL8"]
[Thu Jul 30 12:38:07.166425 2026] [security2:error] [pid 765155:tid 765324] [client 135.119.63.61:46087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/bnm.php"] [unique_id "amuL_-T5hFAbD-LhWHiWmgAAAKw"]
[Thu Jul 30 12:38:07.188377 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.192384 2026] [security2:error] [pid 765155:tid 765394] [client 103.215.74.26:17744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL_-T5hFAbD-LhWHiWmwAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:07.336923 2026] [core:notice] [pid 765155:tid 765291] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.588924 2026] [proxy:error] [pid 765155:tid 765162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:07.589009 2026] [proxy_http:error] [pid 765155:tid 765162] [remote 143.244.47.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:07.589597 2026] [proxy:error] [pid 765155:tid 765162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:07.589639 2026] [proxy_http:error] [pid 765155:tid 765162] [remote 143.244.47.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:07.857286 2026] [core:notice] [pid 765155:tid 765382] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.926032 2026] [core:notice] [pid 765155:tid 765364] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.930397 2026] [security2:error] [pid 765155:tid 765364] [client 103.215.74.26:17754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuL_-T5hFAbD-LhWHiWqwAAANQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:07.964148 2026] [core:notice] [pid 765155:tid 765201] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:07.991255 2026] [security2:error] [pid 765155:tid 765346] [client 38.190.144.4:53657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL_-T5hFAbD-LhWHiWrQAAAMI"]
[Thu Jul 30 12:38:07.991558 2026] [security2:error] [pid 765155:tid 765346] [client 38.190.144.4:53657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuL_-T5hFAbD-LhWHiWrQAAAMI"]
[Thu Jul 30 12:38:08.124386 2026] [core:notice] [pid 765155:tid 765158] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:08.672864 2026] [core:notice] [pid 765155:tid 765348] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:08.676608 2026] [security2:error] [pid 765155:tid 765348] [client 103.215.74.26:17760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMAOT5hFAbD-LhWHiWvwAAAMQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:08.972810 2026] [security2:error] [pid 765155:tid 765354] [client 20.104.18.253:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/dropdown.php"] [unique_id "amuMAOT5hFAbD-LhWHiWxAAAAMo"]
[Thu Jul 30 12:38:09.409918 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:09.415958 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:17764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMAeT5hFAbD-LhWHiW0QAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:09.473971 2026] [core:notice] [pid 765155:tid 765327] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:09.513008 2026] [security2:error] [pid 765155:tid 765405] [client 135.119.63.61:46182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/bootstrap.php"] [unique_id "amuMAeT5hFAbD-LhWHiW0wAAAP0"]
[Thu Jul 30 12:38:10.008928 2026] [security2:error] [pid 765155:tid 765332] [client 49.0.84.125:59688] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuMAuT5hFAbD-LhWHiW3wAAALQ"]
[Thu Jul 30 12:38:10.172320 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:10.177666 2026] [security2:error] [pid 765155:tid 765356] [client 103.215.74.26:17772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMAuT5hFAbD-LhWHiW4wAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:10.245298 2026] [security2:error] [pid 765155:tid 765323] [client 49.0.84.125:45498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuMAuT5hFAbD-LhWHiW5wAAAKs"]
[Thu Jul 30 12:38:10.301444 2026] [security2:error] [pid 765155:tid 765386] [client 20.104.18.253:26431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/edit.php"] [unique_id "amuMAuT5hFAbD-LhWHiW6wAAAOo"]
[Thu Jul 30 12:38:10.359429 2026] [security2:error] [pid 765155:tid 765311] [client 20.215.191.139:2339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/hoot.php"] [unique_id "amuMAuT5hFAbD-LhWHiW7AAAAJ8"]
[Thu Jul 30 12:38:10.579889 2026] [security2:error] [pid 765155:tid 765361] [client 44.209.187.99:13134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "radiojelli.com"] [uri "/img/articles/68/famous-men-classified-by-myers-briggs-type-4.jpg"] [unique_id "amuMAuT5hFAbD-LhWHiW7QAAANE"]
[Thu Jul 30 12:38:10.694385 2026] [security2:error] [pid 765155:tid 765364] [client 135.119.63.61:46166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/buy.php"] [unique_id "amuMAuT5hFAbD-LhWHiW7gAAANQ"]
[Thu Jul 30 12:38:10.833382 2026] [security2:error] [pid 765155:tid 765212] [remote 57.141.0.58:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuMAuT5hFAbD-LhWHiW-AAAljg"]
[Thu Jul 30 12:38:10.897272 2026] [core:notice] [pid 765155:tid 765352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:10.901581 2026] [security2:error] [pid 765155:tid 765352] [client 103.215.74.26:17786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMAuT5hFAbD-LhWHiW-QAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:11.018476 2026] [security2:error] [pid 765155:tid 765408] [client 20.215.191.139:2589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/about.php"] [unique_id "amuMA-T5hFAbD-LhWHiW-gAAAQA"]
[Thu Jul 30 12:38:11.195737 2026] [security2:error] [pid 765155:tid 765390] [client 20.104.18.253:26425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/f35.php"] [unique_id "amuMA-T5hFAbD-LhWHiW-wAAAO4"]
[Thu Jul 30 12:38:11.361710 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:11.942908 2026] [security2:error] [pid 765155:tid 765163] [remote 97.74.87.194:43744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuMA-T5hFAbD-LhWHiXFAAA1Qc"]
[Thu Jul 30 12:38:12.103996 2026] [security2:error] [pid 765155:tid 765289] [client 20.104.18.253:52254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/f7.php"] [unique_id "amuMBOT5hFAbD-LhWHiXFQAAAIk"]
[Thu Jul 30 12:38:12.113816 2026] [security2:error] [pid 765155:tid 765292] [client 20.63.98.115:53832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amuMBOT5hFAbD-LhWHiXFgAAAIw"]
[Thu Jul 30 12:38:12.380540 2026] [security2:error] [pid 765155:tid 765294] [client 20.215.191.139:2338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/admin.php"] [unique_id "amuMBOT5hFAbD-LhWHiXHQAAAI4"]
[Thu Jul 30 12:38:12.443878 2026] [security2:error] [pid 765155:tid 765399] [client 150.107.232.194:27448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMBOT5hFAbD-LhWHiXIQAAAPc"]
[Thu Jul 30 12:38:12.443995 2026] [security2:error] [pid 765155:tid 765399] [client 150.107.232.194:27448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMBOT5hFAbD-LhWHiXIQAAAPc"]
[Thu Jul 30 12:38:12.500801 2026] [core:notice] [pid 765155:tid 765346] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:13.215719 2026] [security2:error] [pid 765155:tid 765354] [client 20.215.191.139:7005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuMBeT5hFAbD-LhWHiXNwAAAMo"]
[Thu Jul 30 12:38:13.227925 2026] [security2:error] [pid 765155:tid 765340] [client 20.63.98.115:53873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amuMBeT5hFAbD-LhWHiXOAAAALw"]
[Thu Jul 30 12:38:13.653806 2026] [core:notice] [pid 765155:tid 765219] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:13.925611 2026] [security2:error] [pid 765155:tid 765369] [client 172.236.9.101:1063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMBeT5hFAbD-LhWHiXQgAAANk"]
[Thu Jul 30 12:38:14.004131 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:8727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMBeT5hFAbD-LhWHiXQQAAAKc"]
[Thu Jul 30 12:38:14.904812 2026] [core:notice] [pid 765155:tid 765374] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:14.919021 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:52948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMBuT5hFAbD-LhWHiXSwAAAJU"]
[Thu Jul 30 12:38:14.943598 2026] [fcgid:warn] [pid 765155:tid 765308] (70014)End of file found: [client 118.193.58.125:54906] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:15.585710 2026] [security2:error] [pid 765155:tid 765358] [client 20.63.98.115:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuMB-T5hFAbD-LhWHiXaAAAAM4"]
[Thu Jul 30 12:38:15.916052 2026] [security2:error] [pid 765155:tid 765349] [client 172.236.9.101:28740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXYQAAAMU"]
[Thu Jul 30 12:38:15.941127 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:7296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXZAAAAPs"]
[Thu Jul 30 12:38:15.983593 2026] [core:notice] [pid 765155:tid 765387] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:16.040258 2026] [security2:error] [pid 765155:tid 765331] [client 172.236.9.101:64687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXZQAAALM"]
[Thu Jul 30 12:38:16.054658 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:43380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXYwAAAOg"]
[Thu Jul 30 12:38:16.061516 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:4544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMB-T5hFAbD-LhWHiXZgAAAPE"]
[Thu Jul 30 12:38:16.218728 2026] [security2:error] [pid 765155:tid 765293] [client 135.119.63.61:46189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/chosen.php"] [unique_id "amuMCOT5hFAbD-LhWHiXewAAAI0"]
[Thu Jul 30 12:38:16.242146 2026] [security2:error] [pid 765155:tid 765369] [client 20.215.191.139:8218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuMCOT5hFAbD-LhWHiXfAAAANk"]
[Thu Jul 30 12:38:16.664251 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:16.670542 2026] [security2:error] [pid 765155:tid 765303] [client 103.215.74.26:23710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMCOT5hFAbD-LhWHiXjwAAAJc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:16.896327 2026] [security2:error] [pid 765155:tid 765379] [client 20.215.191.139:2586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuMCOT5hFAbD-LhWHiXlAAAAOM"]
[Thu Jul 30 12:38:16.951588 2026] [security2:error] [pid 765155:tid 765356] [client 20.63.98.115:53833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "amuMCOT5hFAbD-LhWHiXlQAAAMw"]
[Thu Jul 30 12:38:17.225997 2026] [security2:error] [pid 765155:tid 765344] [client 172.236.9.101:52434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXfwAAAMA"]
[Thu Jul 30 12:38:17.293075 2026] [security2:error] [pid 765155:tid 765371] [client 172.236.9.101:64113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXfgAAANs"]
[Thu Jul 30 12:38:17.307325 2026] [security2:error] [pid 765155:tid 765370] [client 172.236.9.101:3463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXgAAAANo"]
[Thu Jul 30 12:38:17.307951 2026] [security2:error] [pid 765155:tid 765385] [client 172.236.9.101:28896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXfQAAAOk"]
[Thu Jul 30 12:38:17.313282 2026] [security2:error] [pid 765155:tid 765342] [client 172.236.9.101:65386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXgQAAAL4"]
[Thu Jul 30 12:38:17.328907 2026] [security2:error] [pid 765155:tid 765306] [client 43.172.195.68:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/09/14/trouver-sa-tenue-de-sport/"] [unique_id "amuMCeT5hFAbD-LhWHiXmQAAAJo"]
[Thu Jul 30 12:38:17.402153 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:1234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXgwAAAJs"]
[Thu Jul 30 12:38:17.411429 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:58118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXggAAALE"]
[Thu Jul 30 12:38:17.413216 2026] [core:notice] [pid 765155:tid 765366] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:17.420415 2026] [security2:error] [pid 765155:tid 765366] [client 103.215.74.26:23722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMCeT5hFAbD-LhWHiXpgAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:17.422110 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:7996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXhAAAAO8"]
[Thu Jul 30 12:38:17.425960 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:55263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXhQAAALk"]
[Thu Jul 30 12:38:17.447721 2026] [security2:error] [pid 765155:tid 765397] [client 172.236.9.101:30818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXiQAAAPU"]
[Thu Jul 30 12:38:17.459404 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:14307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXiwAAAKo"]
[Thu Jul 30 12:38:17.465830 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:62488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMCOT5hFAbD-LhWHiXigAAAIY"]
[Thu Jul 30 12:38:17.593766 2026] [security2:error] [pid 765155:tid 765350] [client 43.172.198.150:36984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/26/les-10-indispensables-de-la-semaine-9/"] [unique_id "amuMCeT5hFAbD-LhWHiXoAAAAMY"]
[Thu Jul 30 12:38:17.594696 2026] [security2:error] [pid 765155:tid 765305] [client 135.119.63.61:46145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/class-wp-image.php"] [unique_id "amuMCeT5hFAbD-LhWHiXqAAAAJk"]
[Thu Jul 30 12:38:17.756729 2026] [security2:error] [pid 765155:tid 765317] [client 20.215.191.139:10843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuMCeT5hFAbD-LhWHiXrAAAAKU"]
[Thu Jul 30 12:38:17.966516 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:17.970949 2026] [security2:error] [pid 765155:tid 765365] [client 43.173.180.29:47270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/09/14/trouver-sa-tenue-de-sport/"] [unique_id "amuMCeT5hFAbD-LhWHiXtgAAANU"], referer: https://carnetdeshopping.com/index.php/2014/09/14/trouver-sa-tenue-de-sport/
[Thu Jul 30 12:38:18.137966 2026] [core:notice] [pid 765155:tid 765288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:18.142359 2026] [security2:error] [pid 765155:tid 765288] [client 103.215.74.26:23726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMCuT5hFAbD-LhWHiXuwAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:18.216732 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:18.220915 2026] [security2:error] [pid 765155:tid 765303] [client 43.173.178.89:47920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/26/les-10-indispensables-de-la-semaine-9/"] [unique_id "amuMCuT5hFAbD-LhWHiXvAAAAJc"], referer: https://carnetdeshopping.com/index.php/2013/05/26/les-10-indispensables-de-la-semaine-9/
[Thu Jul 30 12:38:18.612337 2026] [security2:error] [pid 765155:tid 765345] [client 135.119.63.61:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/classsmtps.php"] [unique_id "amuMCuT5hFAbD-LhWHiXxwAAAME"]
[Thu Jul 30 12:38:18.645811 2026] [security2:error] [pid 765155:tid 765383] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMCuT5hFAbD-LhWHiXuQAAAOc"]
[Thu Jul 30 12:38:18.786406 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:18.859045 2026] [core:notice] [pid 765155:tid 765311] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:18.863505 2026] [security2:error] [pid 765155:tid 765311] [client 103.215.74.26:23742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMCuT5hFAbD-LhWHiXzgAAAJ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:18.940077 2026] [security2:error] [pid 765155:tid 765356] [client 20.215.191.139:2597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuMCuT5hFAbD-LhWHiX0AAAAMw"]
[Thu Jul 30 12:38:19.248270 2026] [core:notice] [pid 765155:tid 765408] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.351316 2026] [core:notice] [pid 765155:tid 765381] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.516180 2026] [security2:error] [pid 765155:tid 765354] [client 20.215.191.139:2307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuMC-T5hFAbD-LhWHiX3QAAAMo"]
[Thu Jul 30 12:38:19.600693 2026] [core:notice] [pid 765155:tid 765339] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.605666 2026] [security2:error] [pid 765155:tid 765339] [client 103.215.74.26:23750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMC-T5hFAbD-LhWHiX5AAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:19.686805 2026] [core:notice] [pid 765155:tid 765252] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.747957 2026] [security2:error] [pid 765155:tid 765350] [client 135.119.63.61:46101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/classwithtostring.php"] [unique_id "amuMC-T5hFAbD-LhWHiX5wAAAMY"]
[Thu Jul 30 12:38:19.820883 2026] [core:notice] [pid 765155:tid 765393] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:19.926718 2026] [security2:error] [pid 765155:tid 765360] [client 74.7.241.181:46592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuMC-T5hFAbD-LhWHiX8gAA0G0"], referer: https://www.bedandbreakfast-skye.com/
[Thu Jul 30 12:38:19.995373 2026] [security2:error] [pid 765155:tid 765394] [client 20.63.98.115:57334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/atomlib.php"] [unique_id "amuMC-T5hFAbD-LhWHiX8wAAAPI"]
[Thu Jul 30 12:38:20.339086 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:20.343452 2026] [security2:error] [pid 765155:tid 765336] [client 103.215.74.26:23764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMDOT5hFAbD-LhWHiX_wAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:20.498883 2026] [security2:error] [pid 765155:tid 765368] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMC-T5hFAbD-LhWHiX8QAAANg"]
[Thu Jul 30 12:38:20.591619 2026] [security2:error] [pid 765155:tid 765345] [client 135.119.63.61:46175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/config.php"] [unique_id "amuMDOT5hFAbD-LhWHiYBAAAAME"]
[Thu Jul 30 12:38:20.674024 2026] [proxy:error] [pid 765155:tid 765311] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:20.674101 2026] [proxy_http:error] [pid 765155:tid 765311] [client 100.58.154.137:39366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:20.674666 2026] [proxy:error] [pid 765155:tid 765311] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:20.674709 2026] [proxy_http:error] [pid 765155:tid 765311] [client 100.58.154.137:39366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:20.702108 2026] [security2:error] [pid 765155:tid 765367] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMDOT5hFAbD-LhWHiX9wAA12s"]
[Thu Jul 30 12:38:20.803184 2026] [security2:error] [pid 765155:tid 765404] [client 20.63.98.115:39163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuMDOT5hFAbD-LhWHiYCgAAAPw"]
[Thu Jul 30 12:38:21.065119 2026] [security2:error] [pid 765155:tid 765372] [client 74.7.241.181:46592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuMDeT5hFAbD-LhWHiYDgAA3Gk"], referer: https://www.bedandbreakfast-skye.com/
[Thu Jul 30 12:38:21.080932 2026] [core:notice] [pid 765155:tid 765366] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:21.085117 2026] [security2:error] [pid 765155:tid 765366] [client 103.215.74.26:23772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMDeT5hFAbD-LhWHiYDwAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:21.102736 2026] [core:notice] [pid 765155:tid 765259] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:21.455476 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:21.524748 2026] [security2:error] [pid 765155:tid 765378] [client 20.215.191.139:11047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuMDeT5hFAbD-LhWHiYIAAAAOI"]
[Thu Jul 30 12:38:21.611068 2026] [security2:error] [pid 765155:tid 765349] [client 135.119.63.61:46151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/core.php"] [unique_id "amuMDeT5hFAbD-LhWHiYIQAAAMU"]
[Thu Jul 30 12:38:21.644945 2026] [security2:error] [pid 765155:tid 765331] [client 20.63.98.115:20953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gebase.php"] [unique_id "amuMDeT5hFAbD-LhWHiYIgAAALM"]
[Thu Jul 30 12:38:21.812343 2026] [core:notice] [pid 765155:tid 765408] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:21.816521 2026] [security2:error] [pid 765155:tid 765408] [client 103.215.74.26:23776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMDeT5hFAbD-LhWHiYJgAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:21.896173 2026] [security2:error] [pid 765155:tid 765377] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYFwAA4RY"]
[Thu Jul 30 12:38:21.926666 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:11118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYHgAAAPs"]
[Thu Jul 30 12:38:21.936302 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:56590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYGwAAALI"]
[Thu Jul 30 12:38:22.010289 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:18838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYHQAAALs"]
[Thu Jul 30 12:38:22.034271 2026] [security2:error] [pid 765155:tid 765305] [client 172.236.9.101:44623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDeT5hFAbD-LhWHiYHAAAAJk"]
[Thu Jul 30 12:38:22.095268 2026] [security2:error] [pid 765155:tid 765271] [remote 47.128.96.185:58214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3842"] [unique_id "amuMDeT5hFAbD-LhWHiYJwAAoHM"]
[Thu Jul 30 12:38:22.165968 2026] [core:notice] [pid 765155:tid 765282] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.172070 2026] [security2:error] [pid 765155:tid 765364] [client 47.128.96.185:58214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3842"] [unique_id "amuMDuT5hFAbD-LhWHiYNAAA1H4"], referer: https://www.ejournalugj.com/index.php/Konstruksi/article/view/3842?articlesBySameAuthorPage=1
[Thu Jul 30 12:38:22.250046 2026] [security2:error] [pid 765155:tid 765402] [client 74.7.244.23:60972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuMDuT5hFAbD-LhWHiYNQAA-m8"], referer: https://www.bedandbreakfast-skye.com/robots.txt
[Thu Jul 30 12:38:22.346648 2026] [security2:error] [pid 765155:tid 765406] [client 20.215.191.139:11388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/content.php"] [unique_id "amuMDuT5hFAbD-LhWHiYNgAAAP4"]
[Thu Jul 30 12:38:22.407682 2026] [core:notice] [pid 765155:tid 765172] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.514102 2026] [core:notice] [pid 765155:tid 765276] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.514258 2026] [core:notice] [pid 765155:tid 765165] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.547890 2026] [core:notice] [pid 765155:tid 765385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.555437 2026] [security2:error] [pid 765155:tid 765385] [client 103.215.74.26:23780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMDuT5hFAbD-LhWHiYTgAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:22.688213 2026] [security2:error] [pid 765155:tid 765181] [remote 57.141.0.24:39342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuMDuT5hFAbD-LhWHiYQwAAhRk"]
[Thu Jul 30 12:38:22.768241 2026] [core:notice] [pid 765155:tid 765159] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:22.773618 2026] [security2:error] [pid 765155:tid 765386] [client 135.119.63.61:46174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/css.php"] [unique_id "amuMDuT5hFAbD-LhWHiYUwAAAOo"]
[Thu Jul 30 12:38:22.963841 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:12429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYOAAAALg"]
[Thu Jul 30 12:38:22.983572 2026] [security2:error] [pid 765155:tid 765361] [client 172.236.9.101:65290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYNwAAANE"]
[Thu Jul 30 12:38:22.994393 2026] [security2:error] [pid 765155:tid 765294] [client 172.236.9.101:46285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYOQAAAI4"]
[Thu Jul 30 12:38:23.003442 2026] [security2:error] [pid 765155:tid 765412] [client 172.236.9.101:37924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYOgAAAQQ"]
[Thu Jul 30 12:38:23.006690 2026] [autoindex:error] [pid 765155:tid 765286] [client 3.225.222.228:38543] AH01276: Cannot serve directory /home2/meggzjte/01.serverkr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:38:23.025373 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:3574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYOwAAAM8"]
[Thu Jul 30 12:38:23.098614 2026] [security2:error] [pid 765155:tid 765329] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYSgAAALE"]
[Thu Jul 30 12:38:23.099844 2026] [security2:error] [pid 765155:tid 765362] [client 20.100.187.246:61703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/json.php"] [unique_id "amuMD-T5hFAbD-LhWHiYYgAAANI"]
[Thu Jul 30 12:38:23.281396 2026] [core:notice] [pid 765155:tid 765350] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:23.286194 2026] [security2:error] [pid 765155:tid 765350] [client 103.215.74.26:61964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "739"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMD-T5hFAbD-LhWHiYZgAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:23.293554 2026] [security2:error] [pid 765155:tid 765345] [client 172.236.9.101:63019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYRAAAAME"]
[Thu Jul 30 12:38:23.294136 2026] [security2:error] [pid 765155:tid 765342] [client 172.236.9.101:58760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYPwAAAL4"]
[Thu Jul 30 12:38:23.296002 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:26444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYPAAAAOg"]
[Thu Jul 30 12:38:23.296103 2026] [security2:error] [pid 765155:tid 765347] [client 150.107.232.194:27039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMD-T5hFAbD-LhWHiYZwAAAMM"]
[Thu Jul 30 12:38:23.296202 2026] [security2:error] [pid 765155:tid 765347] [client 150.107.232.194:27039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMD-T5hFAbD-LhWHiYZwAAAMM"]
[Thu Jul 30 12:38:23.299126 2026] [security2:error] [pid 765155:tid 765370] [client 172.236.9.101:19810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYPQAAANo"]
[Thu Jul 30 12:38:23.312512 2026] [security2:error] [pid 765155:tid 765371] [client 172.236.9.101:11830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMDuT5hFAbD-LhWHiYRQAAANs"]
[Thu Jul 30 12:38:23.885440 2026] [security2:error] [pid 765155:tid 765346] [client 20.63.98.115:43319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/xl.php"] [unique_id "amuMD-T5hFAbD-LhWHiYdwAAAMI"]
[Thu Jul 30 12:38:23.965607 2026] [security2:error] [pid 765155:tid 765394] [client 172.236.9.101:63002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYaQAAAPI"]
[Thu Jul 30 12:38:23.966986 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:14752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYbQAAALs"]
[Thu Jul 30 12:38:23.967057 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:1691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYbAAAAJc"]
[Thu Jul 30 12:38:23.969954 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:30226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYawAAAKM"]
[Thu Jul 30 12:38:23.975487 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:54847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYaAAAAM0"]
[Thu Jul 30 12:38:23.978412 2026] [security2:error] [pid 765155:tid 765288] [client 172.236.9.101:31882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMD-T5hFAbD-LhWHiYagAAAIg"]
[Thu Jul 30 12:38:24.009962 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:24.014852 2026] [security2:error] [pid 765155:tid 765328] [client 103.215.74.26:61968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMEOT5hFAbD-LhWHiYfwAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:24.138456 2026] [security2:error] [pid 765155:tid 765374] [client 20.100.187.246:61173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/mini.php"] [unique_id "amuMEOT5hFAbD-LhWHiYgwAAAN4"]
[Thu Jul 30 12:38:24.622764 2026] [security2:error] [pid 765155:tid 765306] [client 20.215.191.139:11032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuMEOT5hFAbD-LhWHiYmwAAAJo"]
[Thu Jul 30 12:38:24.749019 2026] [security2:error] [pid 765155:tid 765404] [client 135.119.63.61:46149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/database.php"] [unique_id "amuMEOT5hFAbD-LhWHiYowAAAPw"]
[Thu Jul 30 12:38:24.749055 2026] [core:notice] [pid 765155:tid 765362] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:24.761062 2026] [security2:error] [pid 765155:tid 765362] [client 103.215.74.26:61974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMEOT5hFAbD-LhWHiYogAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:24.779573 2026] [security2:error] [pid 765155:tid 765377] [client 20.100.187.246:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/chosen.php"] [unique_id "amuMEOT5hFAbD-LhWHiYpAAAAOE"]
[Thu Jul 30 12:38:25.259694 2026] [security2:error] [pid 765155:tid 765332] [client 20.63.98.115:57341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/2.php"] [unique_id "amuMEeT5hFAbD-LhWHiYrAAAALQ"]
[Thu Jul 30 12:38:25.397148 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:13946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYjAAAAO0"]
[Thu Jul 30 12:38:25.397352 2026] [security2:error] [pid 765155:tid 765286] [client 172.236.9.101:20636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYkQAAAIY"]
[Thu Jul 30 12:38:25.403667 2026] [security2:error] [pid 765155:tid 765291] [client 172.236.9.101:9912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYiwAAAIs"]
[Thu Jul 30 12:38:25.403667 2026] [security2:error] [pid 765155:tid 765349] [client 172.236.9.101:26581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYigAAAMU"]
[Thu Jul 30 12:38:25.404476 2026] [security2:error] [pid 765155:tid 765387] [client 172.236.9.101:5247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYjgAAAOs"]
[Thu Jul 30 12:38:25.419747 2026] [security2:error] [pid 765155:tid 765294] [client 172.236.9.101:33376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYjwAAAI4"]
[Thu Jul 30 12:38:25.428339 2026] [security2:error] [pid 765155:tid 765361] [client 172.236.9.101:46252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYjQAAANE"]
[Thu Jul 30 12:38:25.450489 2026] [security2:error] [pid 765155:tid 765412] [client 172.236.9.101:14019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYkAAAAQQ"]
[Thu Jul 30 12:38:25.469472 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:10462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYkgAAAM8"]
[Thu Jul 30 12:38:25.472468 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:3696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYkwAAAKc"]
[Thu Jul 30 12:38:25.500168 2026] [core:notice] [pid 765155:tid 765406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:25.511103 2026] [security2:error] [pid 765155:tid 765406] [client 103.215.74.26:61978] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMEeT5hFAbD-LhWHiYtwAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:25.535645 2026] [security2:error] [pid 765155:tid 765321] [client 172.236.9.101:40203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYlAAAAKk"]
[Thu Jul 30 12:38:25.556702 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:29177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYlgAAAPE"]
[Thu Jul 30 12:38:25.558072 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:5895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYlQAAAPg"]
[Thu Jul 30 12:38:25.579656 2026] [security2:error] [pid 765155:tid 765354] [client 172.236.9.101:9296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEOT5hFAbD-LhWHiYlwAAAMo"]
[Thu Jul 30 12:38:25.617150 2026] [security2:error] [pid 765155:tid 765394] [client 135.119.63.61:46152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/db.php"] [unique_id "amuMEeT5hFAbD-LhWHiYvAAAAPI"]
[Thu Jul 30 12:38:26.019213 2026] [security2:error] [pid 765155:tid 765310] [client 20.215.191.139:61242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuMEuT5hFAbD-LhWHiYwwAAAJ4"]
[Thu Jul 30 12:38:26.266844 2026] [core:notice] [pid 765155:tid 765390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:26.273791 2026] [security2:error] [pid 765155:tid 765390] [client 103.215.74.26:61994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "740"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMEuT5hFAbD-LhWHiYxwAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:26.285670 2026] [security2:error] [pid 765155:tid 765180] [remote 198.38.94.87:55236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuMEuT5hFAbD-LhWHiYyAAAkhg"]
[Thu Jul 30 12:38:26.341002 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:2620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYsgAAANg"]
[Thu Jul 30 12:38:26.350231 2026] [security2:error] [pid 765155:tid 765346] [client 172.236.9.101:20334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYtgAAAMI"]
[Thu Jul 30 12:38:26.383360 2026] [security2:error] [pid 765155:tid 765383] [client 172.236.9.101:6946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYsQAAAOc"]
[Thu Jul 30 12:38:26.385069 2026] [security2:error] [pid 765155:tid 765353] [client 172.236.9.101:44836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYtQAAAMk"]
[Thu Jul 30 12:38:26.405029 2026] [security2:error] [pid 765155:tid 765398] [client 172.236.9.101:40397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYswAAAPY"]
[Thu Jul 30 12:38:26.405659 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:47776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMEeT5hFAbD-LhWHiYtAAAAI8"]
[Thu Jul 30 12:38:26.552323 2026] [security2:error] [pid 765155:tid 765362] [client 20.63.98.115:20983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/baxa1.php"] [unique_id "amuMEuT5hFAbD-LhWHiYzwAAANI"]
[Thu Jul 30 12:38:27.007223 2026] [core:notice] [pid 765155:tid 765349] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:27.011211 2026] [security2:error] [pid 765155:tid 765349] [client 103.215.74.26:62002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuME-T5hFAbD-LhWHiY4AAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:27.193511 2026] [security2:error] [pid 765155:tid 765208] [remote 37.59.204.153:45726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/no-sidebar-full-width/"] [unique_id "amuME-T5hFAbD-LhWHiY5AAAhTQ"]
[Thu Jul 30 12:38:27.193675 2026] [security2:error] [pid 765155:tid 765285] [client 37.59.204.153:45726] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/no-sidebar-full-width/"] [unique_id "amuME-T5hFAbD-LhWHiY5AAAhTQ"]
[Thu Jul 30 12:38:27.431436 2026] [security2:error] [pid 765155:tid 765365] [client 135.119.63.61:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/default.php"] [unique_id "amuME-T5hFAbD-LhWHiY6wAAANU"]
[Thu Jul 30 12:38:27.743026 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:27.750358 2026] [security2:error] [pid 765155:tid 765336] [client 103.215.74.26:62014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuME-T5hFAbD-LhWHiY7wAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:27.784610 2026] [security2:error] [pid 765155:tid 765348] [client 20.63.98.115:57281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/settings.php"] [unique_id "amuME-T5hFAbD-LhWHiY8AAAAMQ"]
[Thu Jul 30 12:38:28.349943 2026] [security2:error] [pid 765155:tid 765371] [client 135.119.63.61:46167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/dropdown.php"] [unique_id "amuMFOT5hFAbD-LhWHiZEgAAANs"]
[Thu Jul 30 12:38:28.482524 2026] [core:notice] [pid 765155:tid 765407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:28.486460 2026] [security2:error] [pid 765155:tid 765407] [client 103.215.74.26:62028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMFOT5hFAbD-LhWHiZGwAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:28.623249 2026] [security2:error] [pid 765155:tid 765236] [remote 57.141.0.58:40878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amuMFOT5hFAbD-LhWHiZHQAAhlA"]
[Thu Jul 30 12:38:28.894668 2026] [security2:error] [pid 765155:tid 765375] [client 38.190.144.4:54657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMFOT5hFAbD-LhWHiZLgAAAN8"]
[Thu Jul 30 12:38:28.894803 2026] [security2:error] [pid 765155:tid 765375] [client 38.190.144.4:54657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMFOT5hFAbD-LhWHiZLgAAAN8"]
[Thu Jul 30 12:38:28.896196 2026] [security2:error] [pid 765155:tid 765191] [remote 57.141.0.35:57402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4804188137/feed/rss2/"] [unique_id "amuMFOT5hFAbD-LhWHiZLwAA6yM"]
[Thu Jul 30 12:38:29.168510 2026] [security2:error] [pid 765155:tid 765384] [client 20.215.191.139:10852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuMFeT5hFAbD-LhWHiZNQAAAOg"]
[Thu Jul 30 12:38:29.201578 2026] [security2:error] [pid 765155:tid 765405] [client 69.158.246.168:53748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMFeT5hFAbD-LhWHiZNAAA_VU"], referer: https://www.northyorksheridanmall.com/store/
[Thu Jul 30 12:38:29.217387 2026] [core:notice] [pid 765155:tid 765366] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:29.221331 2026] [security2:error] [pid 765155:tid 765366] [client 103.215.74.26:62034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "733"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMFeT5hFAbD-LhWHiZNgAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:29.268810 2026] [security2:error] [pid 765155:tid 765386] [client 20.63.98.115:20959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/dropdown.php"] [unique_id "amuMFeT5hFAbD-LhWHiZOgAAAOo"]
[Thu Jul 30 12:38:29.842723 2026] [security2:error] [pid 765155:tid 765302] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMFeT5hFAbD-LhWHiZOQAAAJY"]
[Thu Jul 30 12:38:29.905902 2026] [core:notice] [pid 765155:tid 765256] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:29.954536 2026] [core:notice] [pid 765155:tid 765403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:29.958351 2026] [security2:error] [pid 765155:tid 765403] [client 103.215.74.26:62042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "737"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMFeT5hFAbD-LhWHiZUAAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:30.104254 2026] [core:error] [pid 765155:tid 765390] [client 20.63.98.115:64881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:38:30.104275 2026] [core:error] [pid 765155:tid 765390] [client 20.63.98.115:64881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:38:30.150348 2026] [security2:error] [pid 765155:tid 765392] [client 20.215.191.139:11798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuMFuT5hFAbD-LhWHiZVQAAAPA"]
[Thu Jul 30 12:38:30.717513 2026] [security2:error] [pid 765155:tid 765369] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMFuT5hFAbD-LhWHiZVAAA2Vg"]
[Thu Jul 30 12:38:30.725774 2026] [security2:error] [pid 765155:tid 765374] [client 20.100.187.246:64338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/kj.php"] [unique_id "amuMFuT5hFAbD-LhWHiZYQAAAN4"]
[Thu Jul 30 12:38:30.730763 2026] [core:notice] [pid 765155:tid 765357] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:30.734772 2026] [security2:error] [pid 765155:tid 765357] [client 103.215.74.26:62044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMFuT5hFAbD-LhWHiZYgAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:30.735175 2026] [core:notice] [pid 765155:tid 765268] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.096674 2026] [core:notice] [pid 765155:tid 765278] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.207097 2026] [security2:error] [pid 765155:tid 765328] [client 20.215.191.139:11030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuMF-T5hFAbD-LhWHiZbgAAALA"]
[Thu Jul 30 12:38:31.387265 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.425353 2026] [security2:error] [pid 765155:tid 765375] [client 20.63.98.115:21313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin.php"] [unique_id "amuMF-T5hFAbD-LhWHiZdgAAAN8"]
[Thu Jul 30 12:38:31.456790 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.460859 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:62048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMF-T5hFAbD-LhWHiZfgAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:31.564682 2026] [security2:error] [pid 765155:tid 765341] [client 20.100.187.246:61704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wp-files.php"] [unique_id "amuMF-T5hFAbD-LhWHiZgwAAAL0"]
[Thu Jul 30 12:38:31.769071 2026] [security2:error] [pid 765155:tid 765402] [client 135.119.63.61:46136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/edit.php"] [unique_id "amuMF-T5hFAbD-LhWHiZiAAAAPo"]
[Thu Jul 30 12:38:31.815737 2026] [core:notice] [pid 765155:tid 765379] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.896443 2026] [core:notice] [pid 765155:tid 765275] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:31.947363 2026] [security2:error] [pid 765155:tid 765403] [client 20.215.191.139:6977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuMF-T5hFAbD-LhWHiZjgAAAPs"]
[Thu Jul 30 12:38:32.012955 2026] [core:notice] [pid 765155:tid 765259] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:32.420995 2026] [security2:error] [pid 765155:tid 765377] [client 49.37.44.76:43084] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuMGOT5hFAbD-LhWHiZnQAAAOE"]
[Thu Jul 30 12:38:32.557337 2026] [security2:error] [pid 765155:tid 765311] [client 20.100.187.246:61722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wp-setup.php"] [unique_id "amuMGOT5hFAbD-LhWHiZnwAAAJ8"]
[Thu Jul 30 12:38:32.843568 2026] [security2:error] [pid 765155:tid 765372] [client 20.215.191.139:3069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuMGOT5hFAbD-LhWHiZqwAAANw"]
[Thu Jul 30 12:38:32.923079 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:45983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGOT5hFAbD-LhWHiZmwAAAO0"]
[Thu Jul 30 12:38:32.928831 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:41058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGOT5hFAbD-LhWHiZmgAAAJc"]
[Thu Jul 30 12:38:32.974449 2026] [security2:error] [pid 765155:tid 765338] [client 172.236.9.101:15313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGOT5hFAbD-LhWHiZnAAAALo"]
[Thu Jul 30 12:38:32.991364 2026] [security2:error] [pid 765155:tid 765292] [client 172.236.9.101:37273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGOT5hFAbD-LhWHiZngAAAIw"]
[Thu Jul 30 12:38:33.288828 2026] [security2:error] [pid 765155:tid 765391] [client 90.241.132.197:38808] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/revolution-slider/fonts/revicons/revicons.ttf"] [unique_id "amuMGeT5hFAbD-LhWHiZtgAAAO8"]
[Thu Jul 30 12:38:33.321753 2026] [security2:error] [pid 765155:tid 765324] [client 88.189.115.138:12130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZtwAAAKw"]
[Thu Jul 30 12:38:33.382023 2026] [core:notice] [pid 765155:tid 765267] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.382023 2026] [core:notice] [pid 765155:tid 765282] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.457994 2026] [security2:error] [pid 765155:tid 765371] [client 150.107.232.194:27512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMGeT5hFAbD-LhWHiZzQAAANs"]
[Thu Jul 30 12:38:33.458140 2026] [security2:error] [pid 765155:tid 765371] [client 150.107.232.194:27512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMGeT5hFAbD-LhWHiZzQAAANs"]
[Thu Jul 30 12:38:33.458530 2026] [security2:error] [pid 765155:tid 765287] [client 84.67.10.213:52926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/revolution-slider/fonts/revicons/revicons.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZzAAAAIc"]
[Thu Jul 30 12:38:33.489320 2026] [security2:error] [pid 765155:tid 765356] [client 136.158.42.51:57398] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZzgAAAMw"]
[Thu Jul 30 12:38:33.512181 2026] [core:notice] [pid 765155:tid 765183] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.523265 2026] [core:notice] [pid 765155:tid 765276] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.536754 2026] [security2:error] [pid 765155:tid 765328] [client 87.90.83.146:65506] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZ0QAAALA"]
[Thu Jul 30 12:38:33.598363 2026] [security2:error] [pid 765155:tid 765309] [client 62.166.248.70:43196] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZ1QAAAJ0"]
[Thu Jul 30 12:38:33.707044 2026] [security2:error] [pid 765155:tid 765294] [client 51.68.111.202:34937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/robots.txt"] [unique_id "amuMGeT5hFAbD-LhWHiZ2QAAAI4"]
[Thu Jul 30 12:38:33.895676 2026] [security2:error] [pid 765155:tid 765317] [client 85.189.9.119:52066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuMGeT5hFAbD-LhWHiZ3gAAAKU"]
[Thu Jul 30 12:38:33.955291 2026] [core:notice] [pid 765155:tid 765159] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:33.959269 2026] [security2:error] [pid 765155:tid 765409] [client 86.195.222.85:39770] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuMGeT5hFAbD-LhWHiZ4wAAAQE"]
[Thu Jul 30 12:38:34.022595 2026] [security2:error] [pid 765155:tid 765375] [client 76.131.96.102:58097] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuMGuT5hFAbD-LhWHiZ5QAAAN8"]
[Thu Jul 30 12:38:34.053061 2026] [security2:error] [pid 765155:tid 765367] [client 135.119.63.61:46180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/f35.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ5gAAANc"]
[Thu Jul 30 12:38:34.089067 2026] [security2:error] [pid 765155:tid 765406] [client 136.239.180.67:59516] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuMGuT5hFAbD-LhWHiZ5wAAAP4"]
[Thu Jul 30 12:38:34.097132 2026] [proxy:error] [pid 765155:tid 765277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:34.097179 2026] [proxy_http:error] [pid 765155:tid 765277] [remote 74.7.230.11:39038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:34.097755 2026] [proxy:error] [pid 765155:tid 765277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:34.097796 2026] [proxy_http:error] [pid 765155:tid 765277] [remote 74.7.230.11:39038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:34.120879 2026] [security2:error] [pid 765155:tid 765157] [remote 143.244.47.86:57901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "website-167e4a7a.vdb.nyx.temporary.site"] [uri "/cdn-cgi/rum"] [unique_id "amuMGuT5hFAbD-LhWHiZ6QAA3AE"], referer: https://website-167e4a7a.vdb.nyx.temporary.site/
[Thu Jul 30 12:38:34.191335 2026] [security2:error] [pid 765155:tid 765296] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZ1AAAAJA"]
[Thu Jul 30 12:38:34.213194 2026] [security2:error] [pid 765155:tid 765340] [client 79.30.133.179:42231] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuMGuT5hFAbD-LhWHiZ7QAAALw"]
[Thu Jul 30 12:38:34.263337 2026] [core:notice] [pid 765155:tid 765173] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:34.265926 2026] [security2:error] [pid 765155:tid 765360] [client 172.236.9.101:60729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZuAAAANA"]
[Thu Jul 30 12:38:34.281219 2026] [security2:error] [pid 765155:tid 765293] [client 172.236.9.101:11002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZuQAAAI0"]
[Thu Jul 30 12:38:34.285272 2026] [security2:error] [pid 765155:tid 765342] [client 172.236.9.101:43155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZuwAAAL4"]
[Thu Jul 30 12:38:34.300423 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:27950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZvAAAAMg"]
[Thu Jul 30 12:38:34.386051 2026] [security2:error] [pid 765155:tid 765302] [client 172.236.9.101:52673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZugAAAJY"]
[Thu Jul 30 12:38:34.407845 2026] [security2:error] [pid 765155:tid 765301] [client 172.236.9.101:1381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZywAAAJU"]
[Thu Jul 30 12:38:34.408469 2026] [security2:error] [pid 765155:tid 765398] [client 172.236.9.101:45040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZwgAAAPY"]
[Thu Jul 30 12:38:34.414116 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:19634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZxAAAANg"]
[Thu Jul 30 12:38:34.426681 2026] [security2:error] [pid 765155:tid 765346] [client 172.236.9.101:19581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZwQAAAMI"]
[Thu Jul 30 12:38:34.433370 2026] [security2:error] [pid 765155:tid 765320] [client 172.236.9.101:1784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZyAAAAKg"]
[Thu Jul 30 12:38:34.433645 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:59531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZyQAAAMM"]
[Thu Jul 30 12:38:34.447666 2026] [security2:error] [pid 765155:tid 765362] [client 20.100.187.246:61144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/defaults.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ-QAAANI"]
[Thu Jul 30 12:38:34.468918 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:20653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGeT5hFAbD-LhWHiZygAAAPQ"]
[Thu Jul 30 12:38:34.582918 2026] [security2:error] [pid 765155:tid 765358] [client 78.51.163.187:61534] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuMGuT5hFAbD-LhWHiZ-gAAAM4"]
[Thu Jul 30 12:38:34.869072 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:1452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ8gAAAOI"]
[Thu Jul 30 12:38:34.869638 2026] [security2:error] [pid 765155:tid 765338] [client 172.236.9.101:11984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ8wAAALo"]
[Thu Jul 30 12:38:34.871327 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:27483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ9AAAAQA"]
[Thu Jul 30 12:38:34.916495 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:2564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMGuT5hFAbD-LhWHiZ-AAAAK8"]
[Thu Jul 30 12:38:34.922737 2026] [security2:error] [pid 765155:tid 765389] [client 152.58.47.243:54942] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/js/revolution-slider/fonts/revicons/revicons.eot"] [unique_id "amuMGuT5hFAbD-LhWHiaBQAAAO0"]
[Thu Jul 30 12:38:35.012943 2026] [security2:error] [pid 765155:tid 765324] [client 135.119.63.61:46109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/f7.php"] [unique_id "amuMG-T5hFAbD-LhWHiaCgAAAKw"]
[Thu Jul 30 12:38:35.094934 2026] [security2:error] [pid 765155:tid 765307] [client 70.64.20.57:52958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuMG-T5hFAbD-LhWHiaCwAAAJs"]
[Thu Jul 30 12:38:35.109581 2026] [security2:error] [pid 765155:tid 765366] [client 99.237.236.213:47690] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuMG-T5hFAbD-LhWHiaDAAAANY"]
[Thu Jul 30 12:38:35.147936 2026] [security2:error] [pid 765155:tid 765310] [client 51.223.65.234:58730] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuMG-T5hFAbD-LhWHiaDQAAAJ4"]
[Thu Jul 30 12:38:35.213969 2026] [security2:error] [pid 765155:tid 765397] [client 93.47.41.144:40665] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuMG-T5hFAbD-LhWHiaDgAAAPU"]
[Thu Jul 30 12:38:35.315102 2026] [core:notice] [pid 765155:tid 765158] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.574343 2026] [security2:error] [pid 765155:tid 765184] [remote 143.244.47.86:57901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "website-167e4a7a.vdb.nyx.temporary.site"] [uri "/cdn-cgi/rum"] [unique_id "amuMG-T5hFAbD-LhWHiaGwAAphw"], referer: https://website-167e4a7a.vdb.nyx.temporary.site/
[Thu Jul 30 12:38:35.584294 2026] [security2:error] [pid 765155:tid 765354] [client 20.100.187.246:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/gtc.php"] [unique_id "amuMG-T5hFAbD-LhWHiaHAAAAMo"]
[Thu Jul 30 12:38:35.659657 2026] [core:notice] [pid 765155:tid 765187] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.659657 2026] [core:notice] [pid 765155:tid 765195] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.659670 2026] [core:notice] [pid 765155:tid 765182] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.662155 2026] [core:notice] [pid 765155:tid 765176] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.662162 2026] [core:notice] [pid 765155:tid 765188] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.662519 2026] [core:notice] [pid 765155:tid 765199] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:35.691198 2026] [security2:error] [pid 765155:tid 765197] [remote 5.161.62.209:10994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/.env"] [unique_id "amuMG-T5hFAbD-LhWHiaIwAA-Sk"]
[Thu Jul 30 12:38:35.963660 2026] [security2:error] [pid 765155:tid 765374] [client 95.20.4.203:42626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuMG-T5hFAbD-LhWHiaKgAAAN4"]
[Thu Jul 30 12:38:36.280781 2026] [security2:error] [pid 765155:tid 765299] [client 20.215.191.139:6719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuMHOT5hFAbD-LhWHiaLwAAAJM"]
[Thu Jul 30 12:38:36.314732 2026] [security2:error] [pid 765155:tid 765291] [client 20.63.98.115:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/buy.php"] [unique_id "amuMHOT5hFAbD-LhWHiaNQAAAIs"]
[Thu Jul 30 12:38:36.408886 2026] [security2:error] [pid 765155:tid 765370] [client 20.100.187.246:61142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/import.php"] [unique_id "amuMHOT5hFAbD-LhWHiaOgAAANo"]
[Thu Jul 30 12:38:37.192192 2026] [core:notice] [pid 765155:tid 765400] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:37.195956 2026] [security2:error] [pid 765155:tid 765400] [client 103.215.74.26:27374] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMHeT5hFAbD-LhWHiaRwAAAPg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:37.931762 2026] [core:notice] [pid 765155:tid 765388] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:37.935663 2026] [security2:error] [pid 765155:tid 765388] [client 103.215.74.26:27384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMHeT5hFAbD-LhWHiaWQAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:38.464047 2026] [security2:error] [pid 765155:tid 765303] [client 20.215.191.139:2488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuMHuT5hFAbD-LhWHiaZwAAAJc"]
[Thu Jul 30 12:38:38.675093 2026] [security2:error] [pid 765155:tid 765372] [client 20.100.187.246:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/lufix.php"] [unique_id "amuMHuT5hFAbD-LhWHiabAAAANw"]
[Thu Jul 30 12:38:38.676333 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:38.680686 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:27400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMHuT5hFAbD-LhWHiaawAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:38.843006 2026] [security2:error] [pid 765155:tid 765312] [client 20.63.98.115:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mini.php"] [unique_id "amuMHuT5hFAbD-LhWHiacAAAAKA"]
[Thu Jul 30 12:38:38.886263 2026] [security2:error] [pid 765155:tid 765325] [client 172.236.9.101:35805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMHuT5hFAbD-LhWHiaYwAAAK0"]
[Thu Jul 30 12:38:39.409238 2026] [core:notice] [pid 765155:tid 765344] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:39.416292 2026] [security2:error] [pid 765155:tid 765344] [client 103.215.74.26:27408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMH-T5hFAbD-LhWHiahgAAAMA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:39.914392 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:36913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiagQAAAM0"]
[Thu Jul 30 12:38:39.941962 2026] [security2:error] [pid 765155:tid 765317] [client 172.236.9.101:61882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiaggAAAKU"]
[Thu Jul 30 12:38:40.050520 2026] [security2:error] [pid 765155:tid 765324] [client 172.236.9.101:2872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiahQAAAKw"]
[Thu Jul 30 12:38:40.050806 2026] [security2:error] [pid 765155:tid 765410] [client 172.236.9.101:4589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiahAAAAQI"]
[Thu Jul 30 12:38:40.051859 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:11333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiagwAAAO0"]
[Thu Jul 30 12:38:40.060055 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:38492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiahwAAANc"]
[Thu Jul 30 12:38:40.071563 2026] [security2:error] [pid 765155:tid 765406] [client 172.236.9.101:2276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiaiAAAAP4"]
[Thu Jul 30 12:38:40.165304 2026] [core:notice] [pid 765155:tid 765320] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:40.169689 2026] [security2:error] [pid 765155:tid 765320] [client 103.215.74.26:27418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMIOT5hFAbD-LhWHiapgAAAKg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:40.188169 2026] [security2:error] [pid 765155:tid 765375] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMH-T5hFAbD-LhWHiakQAAAN8"]
[Thu Jul 30 12:38:40.359925 2026] [autoindex:error] [pid 765155:tid 765399] [client 81.215.199.165:52264] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Thu Jul 30 12:38:40.721941 2026] [autoindex:error] [pid 765155:tid 765326] [client 81.215.199.165:52278] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Thu Jul 30 12:38:40.920886 2026] [core:notice] [pid 765155:tid 765337] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:40.927781 2026] [security2:error] [pid 765155:tid 765337] [client 103.215.74.26:27432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMIOT5hFAbD-LhWHiawQAAALk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:40.929896 2026] [security2:error] [pid 765155:tid 765356] [client 172.236.9.101:14985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiasAAAAMw"]
[Thu Jul 30 12:38:40.929966 2026] [security2:error] [pid 765155:tid 765308] [client 172.236.9.101:53858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiargAAAJw"]
[Thu Jul 30 12:38:40.948343 2026] [security2:error] [pid 765155:tid 765309] [client 172.236.9.101:52303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiarwAAAJ0"]
[Thu Jul 30 12:38:40.958794 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:36767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiasQAAAKc"]
[Thu Jul 30 12:38:40.971960 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:17596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiasgAAANM"]
[Thu Jul 30 12:38:40.997794 2026] [security2:error] [pid 765155:tid 765312] [client 172.236.9.101:44755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiatAAAAKA"]
[Thu Jul 30 12:38:41.005047 2026] [security2:error] [pid 765155:tid 765328] [client 172.236.9.101:1460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiaswAAALA"]
[Thu Jul 30 12:38:41.051560 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:1352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiatgAAAOE"]
[Thu Jul 30 12:38:41.051829 2026] [security2:error] [pid 765155:tid 765325] [client 172.236.9.101:21716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIOT5hFAbD-LhWHiatQAAAK0"]
[Thu Jul 30 12:38:41.291064 2026] [security2:error] [pid 765155:tid 765395] [client 20.215.191.139:11793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuMIeT5hFAbD-LhWHiayAAAAPM"]
[Thu Jul 30 12:38:41.399025 2026] [autoindex:error] [pid 765155:tid 765364] [client 81.215.199.165:52288] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Thu Jul 30 12:38:41.533426 2026] [security2:error] [pid 765155:tid 765409] [client 20.100.187.246:64969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/Geforce.php"] [unique_id "amuMIeT5hFAbD-LhWHia0AAAAQE"]
[Thu Jul 30 12:38:41.647456 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:41.654935 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:27436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMIeT5hFAbD-LhWHia1AAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:41.751962 2026] [autoindex:error] [pid 765155:tid 765403] [client 81.215.199.165:52302] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Thu Jul 30 12:38:41.843581 2026] [security2:error] [pid 765155:tid 765398] [client 172.236.9.101:32595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIeT5hFAbD-LhWHiaywAAAPY"]
[Thu Jul 30 12:38:41.862493 2026] [security2:error] [pid 765155:tid 765346] [client 172.236.9.101:18719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIeT5hFAbD-LhWHiazQAAAMI"]
[Thu Jul 30 12:38:41.912443 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:49524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMIeT5hFAbD-LhWHiazwAAANI"]
[Thu Jul 30 12:38:42.295748 2026] [security2:error] [pid 765155:tid 765384] [client 20.215.191.139:11836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuMIuT5hFAbD-LhWHia4gAAAOg"]
[Thu Jul 30 12:38:42.403792 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:42.408608 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:27450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMIuT5hFAbD-LhWHia5gAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:42.601376 2026] [security2:error] [pid 765155:tid 765341] [client 20.63.98.115:32387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cd.php"] [unique_id "amuMIuT5hFAbD-LhWHia7wAAAL0"]
[Thu Jul 30 12:38:43.128355 2026] [security2:error] [pid 765155:tid 765326] [client 74.7.230.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ncg.udi.temporary.site"] [uri "/index.php"] [unique_id "amuMIuT5hFAbD-LhWHia6QAAAK4"]
[Thu Jul 30 12:38:43.129259 2026] [security2:error] [pid 765155:tid 765349] [client 74.7.230.57:33228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ncg.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuMIuT5hFAbD-LhWHia5wAAxWg"]
[Thu Jul 30 12:38:43.161600 2026] [core:notice] [pid 765155:tid 765333] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:43.166260 2026] [security2:error] [pid 765155:tid 765333] [client 103.215.74.26:40642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMI-T5hFAbD-LhWHibAgAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:43.709488 2026] [security2:error] [pid 765155:tid 765322] [client 20.215.191.139:8217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/about.php"] [unique_id "amuMI-T5hFAbD-LhWHibIAAAAKo"]
[Thu Jul 30 12:38:43.787929 2026] [security2:error] [pid 765155:tid 765291] [client 62.102.148.158:52376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuMI-T5hFAbD-LhWHibJAAAAIs"]
[Thu Jul 30 12:38:43.788069 2026] [security2:error] [pid 765155:tid 765291] [client 62.102.148.158:52376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuMI-T5hFAbD-LhWHibJAAAAIs"]
[Thu Jul 30 12:38:43.908144 2026] [core:notice] [pid 765155:tid 765299] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:43.912609 2026] [security2:error] [pid 765155:tid 765299] [client 103.215.74.26:40652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMI-T5hFAbD-LhWHibKAAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:43.919914 2026] [security2:error] [pid 765155:tid 765361] [client 150.107.232.194:27218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMI-T5hFAbD-LhWHibKQAAANE"]
[Thu Jul 30 12:38:43.920016 2026] [security2:error] [pid 765155:tid 765361] [client 150.107.232.194:27218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMI-T5hFAbD-LhWHibKQAAANE"]
[Thu Jul 30 12:38:44.173713 2026] [security2:error] [pid 765155:tid 765375] [client 20.63.98.115:21343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuMJOT5hFAbD-LhWHibMAAAAN8"]
[Thu Jul 30 12:38:44.438734 2026] [core:notice] [pid 765155:tid 765316] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:44.446735 2026] [security2:error] [pid 765155:tid 765316] [client 195.23.32.200:60500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/feed/atom/"] [unique_id "amuMJOT5hFAbD-LhWHibOQAAAKQ"]
[Thu Jul 30 12:38:44.522000 2026] [core:notice] [pid 765155:tid 765240] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:44.664054 2026] [core:notice] [pid 765155:tid 765387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:44.668429 2026] [security2:error] [pid 765155:tid 765387] [client 103.215.74.26:40666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJOT5hFAbD-LhWHibPQAAAOs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:45.224361 2026] [security2:error] [pid 765155:tid 765313] [client 172.236.9.101:57260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibBgAAAKE"]
[Thu Jul 30 12:38:45.232447 2026] [security2:error] [pid 765155:tid 765365] [client 172.236.9.101:38185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibCAAAANU"]
[Thu Jul 30 12:38:45.235061 2026] [security2:error] [pid 765155:tid 765324] [client 172.236.9.101:9254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibCQAAAKw"]
[Thu Jul 30 12:38:45.299617 2026] [security2:error] [pid 765155:tid 765396] [client 172.236.9.101:1693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibBwAAAPQ"]
[Thu Jul 30 12:38:45.301899 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:48363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibCgAAAMM"]
[Thu Jul 30 12:38:45.345544 2026] [security2:error] [pid 765155:tid 765389] [client 172.236.9.101:61886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibDQAAAO0"]
[Thu Jul 30 12:38:45.346430 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:8984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibDAAAANc"]
[Thu Jul 30 12:38:45.366676 2026] [security2:error] [pid 765155:tid 765364] [client 172.236.9.101:64744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibCwAAANQ"]
[Thu Jul 30 12:38:45.366732 2026] [security2:error] [pid 765155:tid 765305] [client 172.236.9.101:11561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibEgAAAJk"]
[Thu Jul 30 12:38:45.371295 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:12378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibFQAAAJc"]
[Thu Jul 30 12:38:45.378761 2026] [security2:error] [pid 765155:tid 765343] [client 172.236.9.101:38605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibEAAAAL8"]
[Thu Jul 30 12:38:45.383270 2026] [security2:error] [pid 765155:tid 765306] [client 172.236.9.101:26976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibEwAAAJo"]
[Thu Jul 30 12:38:45.391898 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:58714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibEQAAALE"]
[Thu Jul 30 12:38:45.392866 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:26477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibDgAAAQE"]
[Thu Jul 30 12:38:45.396620 2026] [core:notice] [pid 765155:tid 765380] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:45.398846 2026] [security2:error] [pid 765155:tid 765402] [client 172.236.9.101:39762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibFgAAAPo"]
[Thu Jul 30 12:38:45.400773 2026] [security2:error] [pid 765155:tid 765380] [client 103.215.74.26:40674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJeT5hFAbD-LhWHibTgAAAOQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:45.403806 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:7315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibGAAAAO8"]
[Thu Jul 30 12:38:45.403807 2026] [security2:error] [pid 765155:tid 765406] [client 172.236.9.101:23172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibDwAAAP4"]
[Thu Jul 30 12:38:45.422752 2026] [security2:error] [pid 765155:tid 765410] [client 172.236.9.101:46388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibFAAAAQI"]
[Thu Jul 30 12:38:45.459719 2026] [security2:error] [pid 765155:tid 765411] [client 172.236.9.101:54509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibFwAAAQM"]
[Thu Jul 30 12:38:45.471988 2026] [security2:error] [pid 765155:tid 765392] [client 172.236.9.101:33623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMI-T5hFAbD-LhWHibGQAAAPA"]
[Thu Jul 30 12:38:45.550528 2026] [security2:error] [pid 765155:tid 765339] [client 20.215.191.139:7984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/about.php"] [unique_id "amuMJeT5hFAbD-LhWHibUgAAALs"]
[Thu Jul 30 12:38:45.701033 2026] [core:notice] [pid 765155:tid 765287] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:45.704592 2026] [security2:error] [pid 765155:tid 765287] [client 195.23.32.200:60592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/feed/atom/"] [unique_id "amuMJeT5hFAbD-LhWHibWwAAAIc"]
[Thu Jul 30 12:38:46.136914 2026] [core:notice] [pid 765155:tid 765394] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:46.140821 2026] [security2:error] [pid 765155:tid 765394] [client 103.215.74.26:40676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "734"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJuT5hFAbD-LhWHibaAAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:46.637909 2026] [security2:error] [pid 765155:tid 765340] [client 20.215.191.139:12366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuMJuT5hFAbD-LhWHibcgAAALw"]
[Thu Jul 30 12:38:46.869596 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:46.873849 2026] [security2:error] [pid 765155:tid 765409] [client 103.215.74.26:40692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "731"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJuT5hFAbD-LhWHibdwAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:46.977855 2026] [security2:error] [pid 765155:tid 765392] [client 194.187.251.163:34364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuMJuT5hFAbD-LhWHibfAAAAPA"]
[Thu Jul 30 12:38:46.977993 2026] [security2:error] [pid 765155:tid 765392] [client 194.187.251.163:34364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuMJuT5hFAbD-LhWHibfAAAAPA"]
[Thu Jul 30 12:38:47.314729 2026] [security2:error] [pid 765155:tid 765364] [client 195.23.32.200:60676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuMJuT5hFAbD-LhWHibeAAAANQ"]
[Thu Jul 30 12:38:47.357427 2026] [security2:error] [pid 765155:tid 765391] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMJuT5hFAbD-LhWHibcwAA71Y"]
[Thu Jul 30 12:38:47.401438 2026] [security2:error] [pid 765155:tid 765370] [client 20.215.191.139:2910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuMJ-T5hFAbD-LhWHibgwAAANo"]
[Thu Jul 30 12:38:47.627245 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:47.631839 2026] [security2:error] [pid 765155:tid 765378] [client 103.215.74.26:40702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMJ-T5hFAbD-LhWHibjQAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:48.003882 2026] [security2:error] [pid 765155:tid 765310] [client 20.100.187.246:61716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/a4.php"] [unique_id "amuMKOT5hFAbD-LhWHibmQAAAJ4"]
[Thu Jul 30 12:38:48.123330 2026] [security2:error] [pid 765155:tid 765293] [client 20.215.191.139:12389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/img/about.php"] [unique_id "amuMKOT5hFAbD-LhWHibnQAAAI0"]
[Thu Jul 30 12:38:48.247004 2026] [security2:error] [pid 765155:tid 765342] [client 20.63.98.115:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/batm.php"] [unique_id "amuMKOT5hFAbD-LhWHiboQAAAL4"]
[Thu Jul 30 12:38:48.349886 2026] [core:notice] [pid 765155:tid 765404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:48.356436 2026] [security2:error] [pid 765155:tid 765404] [client 103.215.74.26:40712] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMKOT5hFAbD-LhWHibogAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:48.542914 2026] [security2:error] [pid 765155:tid 765339] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMJ-T5hFAbD-LhWHiblQAAu28"]
[Thu Jul 30 12:38:48.568040 2026] [security2:error] [pid 765155:tid 765173] [remote 57.141.0.53:64344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/63798190810/feed/rss2/"] [unique_id "amuMKOT5hFAbD-LhWHibrgAA1hE"]
[Thu Jul 30 12:38:48.832778 2026] [security2:error] [pid 765155:tid 765349] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMKOT5hFAbD-LhWHiboAAAAMU"]
[Thu Jul 30 12:38:49.095506 2026] [security2:error] [pid 765155:tid 765333] [client 20.100.187.246:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/accueil.php"] [unique_id "amuMKeT5hFAbD-LhWHibwwAAALU"]
[Thu Jul 30 12:38:49.102890 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:49.109493 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:40722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMKeT5hFAbD-LhWHibxAAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:49.578099 2026] [security2:error] [pid 765155:tid 765304] [client 20.215.191.139:13475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuMKeT5hFAbD-LhWHib0AAAAJg"]
[Thu Jul 30 12:38:49.692020 2026] [security2:error] [pid 765155:tid 765408] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMKeT5hFAbD-LhWHibwgAAAQA"]
[Thu Jul 30 12:38:49.837731 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:49.841782 2026] [security2:error] [pid 765155:tid 765356] [client 103.215.74.26:40724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "732"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMKeT5hFAbD-LhWHib2gAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:50.073715 2026] [security2:error] [pid 765155:tid 765363] [client 20.100.187.246:64356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/dashboard.php"] [unique_id "amuMKuT5hFAbD-LhWHib4wAAANM"]
[Thu Jul 30 12:38:50.314268 2026] [core:notice] [pid 765155:tid 765292] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:50.418275 2026] [security2:error] [pid 765155:tid 765397] [client 20.63.98.115:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/hehehehe.php"] [unique_id "amuMKuT5hFAbD-LhWHib6QAAAPU"]
[Thu Jul 30 12:38:50.565003 2026] [core:notice] [pid 765155:tid 765339] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:50.569917 2026] [security2:error] [pid 765155:tid 765339] [client 103.215.74.26:40740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMKuT5hFAbD-LhWHib6wAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:51.237287 2026] [security2:error] [pid 765155:tid 765374] [client 20.100.187.246:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/radio.php"] [unique_id "amuMK-T5hFAbD-LhWHib_gAAAN4"]
[Thu Jul 30 12:38:51.317116 2026] [core:notice] [pid 765155:tid 765333] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:51.323787 2026] [security2:error] [pid 765155:tid 765333] [client 103.215.74.26:40744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMK-T5hFAbD-LhWHicAgAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:51.623224 2026] [security2:error] [pid 765155:tid 765315] [client 20.215.191.139:5105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuMK-T5hFAbD-LhWHicCAAAAKM"]
[Thu Jul 30 12:38:52.062117 2026] [core:notice] [pid 765155:tid 765294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:52.066176 2026] [security2:error] [pid 765155:tid 765294] [client 103.215.74.26:40750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMLOT5hFAbD-LhWHicFAAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:52.144013 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:52.314526 2026] [security2:error] [pid 765155:tid 765376] [client 85.204.70.98:48138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jto.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuMLOT5hFAbD-LhWHicIAAAAOA"]
[Thu Jul 30 12:38:52.389852 2026] [security2:error] [pid 765155:tid 765400] [client 38.190.144.4:55677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMLOT5hFAbD-LhWHicIgAAAPg"]
[Thu Jul 30 12:38:52.389954 2026] [security2:error] [pid 765155:tid 765400] [client 38.190.144.4:55677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMLOT5hFAbD-LhWHicIgAAAPg"]
[Thu Jul 30 12:38:52.584583 2026] [security2:error] [pid 765155:tid 765292] [client 85.204.70.98:48146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jto.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuMLOT5hFAbD-LhWHicIwAAAIw"]
[Thu Jul 30 12:38:52.786586 2026] [core:notice] [pid 765155:tid 765317] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:52.790595 2026] [security2:error] [pid 765155:tid 765317] [client 103.215.74.26:40760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMLOT5hFAbD-LhWHicLQAAAKU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:53.059382 2026] [security2:error] [pid 765155:tid 765412] [client 74.7.244.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.jto.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuMLeT5hFAbD-LhWHicOwAAAQQ"]
[Thu Jul 30 12:38:53.060114 2026] [security2:error] [pid 765155:tid 765346] [client 74.7.244.5:37680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.jto.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuMLeT5hFAbD-LhWHicOQAAwkk"]
[Thu Jul 30 12:38:53.125329 2026] [security2:error] [pid 765155:tid 765411] [client 74.7.175.182:58566] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pkfye.ye"] [uri "/cgi-sys/404.html"] [unique_id "amuMLeT5hFAbD-LhWHicPAABA10"]
[Thu Jul 30 12:38:53.390350 2026] [security2:error] [pid 765155:tid 765348] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMLOT5hFAbD-LhWHicLAAAxDw"]
[Thu Jul 30 12:38:53.526739 2026] [core:notice] [pid 765155:tid 765373] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:53.530876 2026] [security2:error] [pid 765155:tid 765373] [client 103.215.74.26:18300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMLeT5hFAbD-LhWHicUAAAAN0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:53.795315 2026] [proxy:error] [pid 765155:tid 765294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:53.795368 2026] [proxy_http:error] [pid 765155:tid 765294] [client 74.7.241.191:57114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:53.795926 2026] [proxy:error] [pid 765155:tid 765294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:38:53.795967 2026] [proxy_http:error] [pid 765155:tid 765294] [client 74.7.241.191:57114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:38:53.796099 2026] [security2:error] [pid 765155:tid 765294] [client 74.7.241.191:57114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.zbj.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuMLeT5hFAbD-LhWHicXAAAAI4"]
[Thu Jul 30 12:38:53.853377 2026] [security2:error] [pid 765155:tid 765289] [client 85.204.70.98:48158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jto.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuMLeT5hFAbD-LhWHicXgAAAIk"]
[Thu Jul 30 12:38:53.853495 2026] [security2:error] [pid 765155:tid 765289] [client 85.204.70.98:48158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jto.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuMLeT5hFAbD-LhWHicXgAAAIk"]
[Thu Jul 30 12:38:53.884654 2026] [core:notice] [pid 765155:tid 765356] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:54.011722 2026] [security2:error] [pid 765155:tid 765403] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMLeT5hFAbD-LhWHicTAAA-0U"]
[Thu Jul 30 12:38:54.110215 2026] [security2:error] [pid 765155:tid 765260] [remote 57.141.0.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuMLuT5hFAbD-LhWHicZAAA-Wg"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=wood,aluminum,steel,plastic,lycra,nylon,polyester&filter_size=extra-extra-large,extra-large,small,extra-small&orderby=price&unfilter=1
[Thu Jul 30 12:38:54.116904 2026] [security2:error] [pid 765155:tid 765191] [remote 57.141.0.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuMLuT5hFAbD-LhWHicZQAAsiM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=wood,aluminum,steel,plastic,lycra,nylon,polyester&filter_size=extra-extra-large,extra-large,small,extra-small&orderby=price&unfilter=1
[Thu Jul 30 12:38:54.189729 2026] [core:notice] [pid 765155:tid 765168] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:54.294410 2026] [core:notice] [pid 765155:tid 765306] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:54.298424 2026] [security2:error] [pid 765155:tid 765306] [client 103.215.74.26:18304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMLuT5hFAbD-LhWHicbwAAAJo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:54.406556 2026] [security2:error] [pid 765155:tid 765382] [client 150.107.232.194:27325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMLuT5hFAbD-LhWHicdgAAAOY"]
[Thu Jul 30 12:38:54.406663 2026] [security2:error] [pid 765155:tid 765382] [client 150.107.232.194:27325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMLuT5hFAbD-LhWHicdgAAAOY"]
[Thu Jul 30 12:38:54.961754 2026] [security2:error] [pid 765155:tid 765350] [client 172.237.109.114:62601] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_rsa"] [unique_id "amuMLuT5hFAbD-LhWHichgAAAMY"]
[Thu Jul 30 12:38:54.972941 2026] [security2:error] [pid 765155:tid 765359] [client 172.237.109.114:9758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_dsa"] [unique_id "amuMLuT5hFAbD-LhWHicigAAAM8"]
[Thu Jul 30 12:38:54.977906 2026] [security2:error] [pid 765155:tid 765286] [client 172.237.109.114:59003] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/key.pem"] [unique_id "amuMLuT5hFAbD-LhWHicjAAAAIY"]
[Thu Jul 30 12:38:54.992789 2026] [security2:error] [pid 765155:tid 765300] [client 172.237.109.114:15601] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_dsa"] [unique_id "amuMLuT5hFAbD-LhWHicjQAAAJQ"]
[Thu Jul 30 12:38:55.009897 2026] [security2:error] [pid 765155:tid 765404] [client 172.237.109.114:47679] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_rsa"] [unique_id "amuML-T5hFAbD-LhWHickwAAAPw"]
[Thu Jul 30 12:38:55.010045 2026] [security2:error] [pid 765155:tid 765326] [client 172.237.109.114:56101] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/privatekey.key"] [unique_id "amuML-T5hFAbD-LhWHiclwAAAK4"]
[Thu Jul 30 12:38:55.034875 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:55.042097 2026] [security2:error] [pid 765155:tid 765361] [client 103.215.74.26:18314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuML-T5hFAbD-LhWHicmgAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:55.365812 2026] [core:notice] [pid 765155:tid 765329] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:55.560771 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:55.740827 2026] [security2:error] [pid 765155:tid 765305] [client 20.215.191.139:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuML-T5hFAbD-LhWHicrgAAAJk"]
[Thu Jul 30 12:38:55.788080 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:55.791992 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:18316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuML-T5hFAbD-LhWHicsgAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:56.281865 2026] [security2:error] [pid 765155:tid 765325] [client 172.237.109.114:34834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHichwAAAK0"]
[Thu Jul 30 12:38:56.370529 2026] [security2:error] [pid 765155:tid 765353] [client 172.237.109.114:36418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHicjwAAAMk"]
[Thu Jul 30 12:38:56.378198 2026] [security2:error] [pid 765155:tid 765327] [client 172.237.109.114:48270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHiciQAAAK8"]
[Thu Jul 30 12:38:56.401144 2026] [security2:error] [pid 765155:tid 765376] [client 172.237.109.114:55322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHiclQAAAOA"]
[Thu Jul 30 12:38:56.413458 2026] [security2:error] [pid 765155:tid 765328] [client 20.215.191.139:15330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuMMOT5hFAbD-LhWHicyQAAALA"]
[Thu Jul 30 12:38:56.424963 2026] [security2:error] [pid 765155:tid 765386] [client 172.237.109.114:65462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHickAAAAOo"]
[Thu Jul 30 12:38:56.425390 2026] [security2:error] [pid 765155:tid 765381] [client 172.237.109.114:33281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHiclAAAAOU"]
[Thu Jul 30 12:38:56.434926 2026] [security2:error] [pid 765155:tid 765294] [client 172.237.109.114:3703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicmAAAAI4"]
[Thu Jul 30 12:38:56.444426 2026] [security2:error] [pid 765155:tid 765387] [client 172.237.109.114:49426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHickQAAAOs"]
[Thu Jul 30 12:38:56.447722 2026] [security2:error] [pid 765155:tid 765342] [client 172.237.109.114:19989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHiclgAAAL4"]
[Thu Jul 30 12:38:56.449800 2026] [security2:error] [pid 765155:tid 765290] [client 172.237.109.114:41752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHicjgAAAIo"]
[Thu Jul 30 12:38:56.455411 2026] [security2:error] [pid 765155:tid 765310] [client 172.237.109.114:3988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHickgAAAJ4"]
[Thu Jul 30 12:38:56.489028 2026] [core:notice] [pid 765155:tid 765373] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:56.498539 2026] [security2:error] [pid 765155:tid 765318] [client 172.237.109.114:47639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHiciwAAAKY"]
[Thu Jul 30 12:38:56.503372 2026] [security2:error] [pid 765155:tid 765301] [client 172.237.109.114:22513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicmQAAAJU"]
[Thu Jul 30 12:38:56.557160 2026] [security2:error] [pid 765155:tid 765408] [client 172.237.109.114:37591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMLuT5hFAbD-LhWHiciAAAAQA"]
[Thu Jul 30 12:38:56.561012 2026] [core:notice] [pid 765155:tid 765359] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:56.567036 2026] [security2:error] [pid 765155:tid 765359] [client 103.215.74.26:18332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMMOT5hFAbD-LhWHic1AAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:56.685252 2026] [security2:error] [pid 765155:tid 765374] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHictgAA3mA"]
[Thu Jul 30 12:38:57.155860 2026] [security2:error] [pid 765155:tid 765305] [client 20.215.191.139:2919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuMMeT5hFAbD-LhWHic3wAAAJk"]
[Thu Jul 30 12:38:57.175697 2026] [security2:error] [pid 765155:tid 765334] [client 20.100.187.246:61089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wpsml-sys.php"] [unique_id "amuMMeT5hFAbD-LhWHic4AAAALY"]
[Thu Jul 30 12:38:57.288500 2026] [core:notice] [pid 765155:tid 765346] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:57.297363 2026] [security2:error] [pid 765155:tid 765346] [client 103.215.74.26:18336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMMeT5hFAbD-LhWHic5QAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:57.467135 2026] [core:notice] [pid 765155:tid 765285] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:57.517194 2026] [security2:error] [pid 765155:tid 765324] [client 172.236.9.101:60061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicoAAAAKw"]
[Thu Jul 30 12:38:57.552860 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:32877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicpAAAALs"]
[Thu Jul 30 12:38:57.573642 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:9880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicoQAAAM0"]
[Thu Jul 30 12:38:57.720028 2026] [fcgid:warn] [pid 765155:tid 765325] (70014)End of file found: [client 45.43.62.77:59364] mod_fcgid: can't get data from http client
[Thu Jul 30 12:38:58.030266 2026] [core:notice] [pid 765155:tid 765328] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:58.034438 2026] [security2:error] [pid 765155:tid 765328] [client 103.215.74.26:18346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMMuT5hFAbD-LhWHic-wAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:58.145768 2026] [security2:error] [pid 765155:tid 765323] [client 20.215.191.139:2902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuMMuT5hFAbD-LhWHic_wAAAKs"]
[Thu Jul 30 12:38:58.235742 2026] [security2:error] [pid 765155:tid 765397] [client 172.236.9.101:10394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicpQAAAPU"]
[Thu Jul 30 12:38:58.244526 2026] [security2:error] [pid 765155:tid 765298] [client 20.100.187.246:61723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/02.php"] [unique_id "amuMMuT5hFAbD-LhWHidAQAAAJI"]
[Thu Jul 30 12:38:58.246464 2026] [security2:error] [pid 765155:tid 765401] [client 172.236.9.101:41795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicqQAAAPk"]
[Thu Jul 30 12:38:58.357330 2026] [security2:error] [pid 765155:tid 765317] [client 172.236.9.101:45742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicpwAAAKU"]
[Thu Jul 30 12:38:58.399410 2026] [security2:error] [pid 765155:tid 765316] [client 172.236.9.101:40867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicwwAAAKQ"]
[Thu Jul 30 12:38:58.403680 2026] [security2:error] [pid 765155:tid 765362] [client 172.236.9.101:38510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuML-T5hFAbD-LhWHicqAAAANI"]
[Thu Jul 30 12:38:58.407337 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:14228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicxQAAAJs"]
[Thu Jul 30 12:38:58.427821 2026] [security2:error] [pid 765155:tid 765391] [client 172.236.9.101:1182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicwAAAAO8"]
[Thu Jul 30 12:38:58.430257 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicwgAAAOI"]
[Thu Jul 30 12:38:58.446125 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:57470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicyAAAAOE"]
[Thu Jul 30 12:38:58.485542 2026] [security2:error] [pid 765155:tid 765344] [client 172.236.9.101:33431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHiczQAAAMA"]
[Thu Jul 30 12:38:58.497056 2026] [security2:error] [pid 765155:tid 765352] [client 172.236.9.101:15732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHiczgAAAMg"]
[Thu Jul 30 12:38:58.501395 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:37698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicwQAAAMM"]
[Thu Jul 30 12:38:58.501411 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:64583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicvwAAAI8"]
[Thu Jul 30 12:38:58.527887 2026] [security2:error] [pid 765155:tid 765341] [client 172.236.9.101:36942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicvgAAAL0"]
[Thu Jul 30 12:38:58.530109 2026] [security2:error] [pid 765155:tid 765303] [client 172.236.9.101:47515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicxwAAAJc"]
[Thu Jul 30 12:38:58.543609 2026] [security2:error] [pid 765155:tid 765321] [client 172.236.9.101:33851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHicxAAAAKk"]
[Thu Jul 30 12:38:58.581087 2026] [security2:error] [pid 765155:tid 765348] [client 172.236.9.101:40979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMMOT5hFAbD-LhWHiczAAAAMQ"]
[Thu Jul 30 12:38:58.775304 2026] [core:notice] [pid 765155:tid 765409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:58.779798 2026] [security2:error] [pid 765155:tid 765409] [client 103.215.74.26:18354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMMuT5hFAbD-LhWHidDgAAAQE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:59.508840 2026] [core:notice] [pid 765155:tid 765289] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:38:59.512839 2026] [security2:error] [pid 765155:tid 765289] [client 103.215.74.26:18366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMM-T5hFAbD-LhWHidIgAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:38:59.740512 2026] [security2:error] [pid 765155:tid 765376] [client 20.215.191.139:12387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuMM-T5hFAbD-LhWHidKgAAAOA"]
[Thu Jul 30 12:38:59.879493 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:24073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMM-T5hFAbD-LhWHidHAAAAM8"]
[Thu Jul 30 12:38:59.893792 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:4631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMM-T5hFAbD-LhWHidHQAAAKc"]
[Thu Jul 30 12:38:59.917276 2026] [security2:error] [pid 765155:tid 765356] [client 172.236.9.101:55810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMM-T5hFAbD-LhWHidIQAAAMw"]
[Thu Jul 30 12:38:59.921154 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:7708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMM-T5hFAbD-LhWHidIAAAAQA"]
[Thu Jul 30 12:39:00.131158 2026] [security2:error] [pid 765155:tid 765173] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/app/config/local.php"] [unique_id "amuMM-T5hFAbD-LhWHidKwAAyBE"]
[Thu Jul 30 12:39:00.245650 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:00.249612 2026] [security2:error] [pid 765155:tid 765303] [client 103.215.74.26:18380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMNOT5hFAbD-LhWHidNQAAAJc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:00.344334 2026] [security2:error] [pid 765155:tid 765189] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/app/config/local.php.bak"] [unique_id "amuMNOT5hFAbD-LhWHidNgAArCE"]
[Thu Jul 30 12:39:00.567915 2026] [security2:error] [pid 765155:tid 765201] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/mautic/app/config/local.php"] [unique_id "amuMNOT5hFAbD-LhWHidQgABAS0"]
[Thu Jul 30 12:39:00.749175 2026] [security2:error] [pid 765155:tid 765360] [client 20.63.98.115:20670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/sim.php/wp-includes/certificates/plugins.php"] [unique_id "amuMNOT5hFAbD-LhWHidSQAAANA"]
[Thu Jul 30 12:39:00.752095 2026] [security2:error] [pid 765155:tid 765184] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/config/mail.php"] [unique_id "amuMNOT5hFAbD-LhWHidSgAAphw"]
[Thu Jul 30 12:39:00.907750 2026] [security2:error] [pid 765155:tid 765296] [client 172.236.9.101:30904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidOAAAAJA"]
[Thu Jul 30 12:39:00.929443 2026] [security2:error] [pid 765155:tid 765345] [client 172.236.9.101:8990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidOQAAAME"]
[Thu Jul 30 12:39:00.935963 2026] [security2:error] [pid 765155:tid 765188] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.choiceroofingservices.click"] [uri "/config/services.php"] [unique_id "amuMNOT5hFAbD-LhWHidVAAAhiA"]
[Thu Jul 30 12:39:00.937827 2026] [security2:error] [pid 765155:tid 765375] [client 172.236.9.101:13732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidNwAAAN8"]
[Thu Jul 30 12:39:00.961009 2026] [security2:error] [pid 765155:tid 765285] [client 172.236.9.101:21547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidOwAAAIU"]
[Thu Jul 30 12:39:00.961648 2026] [core:notice] [pid 765155:tid 765311] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:00.962869 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:60497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidPgAAANg"]
[Thu Jul 30 12:39:00.966002 2026] [security2:error] [pid 765155:tid 765311] [client 103.215.74.26:18382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMNOT5hFAbD-LhWHidVQAAAJ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:00.969003 2026] [security2:error] [pid 765155:tid 765365] [client 172.236.9.101:31522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidOgAAANU"]
[Thu Jul 30 12:39:00.973790 2026] [security2:error] [pid 765155:tid 765369] [client 172.236.9.101:55598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNOT5hFAbD-LhWHidPQAAANk"]
[Thu Jul 30 12:39:01.120418 2026] [security2:error] [pid 765155:tid 765372] [client 20.215.191.139:7255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuMNeT5hFAbD-LhWHidVgAAANw"]
[Thu Jul 30 12:39:01.243284 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:01.431526 2026] [security2:error] [pid 765155:tid 765356] [client 47.128.121.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidYQAAAMw"]
[Thu Jul 30 12:39:01.718356 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:01.726566 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:18396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMNeT5hFAbD-LhWHiddwAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:01.966605 2026] [security2:error] [pid 765155:tid 765332] [client 20.63.98.115:61458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-seo.php"] [unique_id "amuMNeT5hFAbD-LhWHidegAAALQ"]
[Thu Jul 30 12:39:01.992870 2026] [security2:error] [pid 765155:tid 765377] [client 172.236.9.101:52591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidYgAAAOE"]
[Thu Jul 30 12:39:02.002948 2026] [security2:error] [pid 765155:tid 765392] [client 172.236.9.101:19346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidYwAAAPA"]
[Thu Jul 30 12:39:02.020587 2026] [security2:error] [pid 765155:tid 765394] [client 172.236.9.101:37015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidZwAAAPI"]
[Thu Jul 30 12:39:02.024799 2026] [security2:error] [pid 765155:tid 765336] [client 172.236.9.101:1791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidZAAAALg"]
[Thu Jul 30 12:39:02.061126 2026] [security2:error] [pid 765155:tid 765347] [client 172.236.9.101:14016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidbQAAAMM"]
[Thu Jul 30 12:39:02.061129 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:4560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidZQAAAQA"]
[Thu Jul 30 12:39:02.061131 2026] [security2:error] [pid 765155:tid 765358] [client 172.236.9.101:8923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidZgAAAM4"]
[Thu Jul 30 12:39:02.061874 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:53606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidawAAAI8"]
[Thu Jul 30 12:39:02.068519 2026] [security2:error] [pid 765155:tid 765340] [client 172.236.9.101:50100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHidbAAAALw"]
[Thu Jul 30 12:39:02.355866 2026] [security2:error] [pid 765155:tid 765291] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMNeT5hFAbD-LhWHiddQAAAIs"]
[Thu Jul 30 12:39:02.458764 2026] [core:notice] [pid 765155:tid 765345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:02.466195 2026] [security2:error] [pid 765155:tid 765345] [client 103.215.74.26:18408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMNuT5hFAbD-LhWHidhwAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:02.803563 2026] [security2:error] [pid 765155:tid 765288] [client 20.63.98.115:63475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/zwso.php"] [unique_id "amuMNuT5hFAbD-LhWHidjwAAAIg"]
[Thu Jul 30 12:39:02.901527 2026] [security2:error] [pid 765155:tid 765334] [client 20.215.191.139:9291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuMNuT5hFAbD-LhWHidkwAAALY"]
[Thu Jul 30 12:39:03.203003 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:03.207331 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:21904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMN-T5hFAbD-LhWHidlwAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:03.223556 2026] [core:notice] [pid 765155:tid 765289] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:03.309993 2026] [security2:error] [pid 765155:tid 765357] [client 38.190.144.4:56180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMN-T5hFAbD-LhWHidnwAAAM0"]
[Thu Jul 30 12:39:03.310091 2026] [security2:error] [pid 765155:tid 765357] [client 38.190.144.4:56180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMN-T5hFAbD-LhWHidnwAAAM0"]
[Thu Jul 30 12:39:03.960908 2026] [core:notice] [pid 765155:tid 765315] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:03.965263 2026] [security2:error] [pid 765155:tid 765315] [client 103.215.74.26:21920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMN-T5hFAbD-LhWHidqQAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:04.234178 2026] [security2:error] [pid 765155:tid 765359] [client 20.215.191.139:4081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuMOOT5hFAbD-LhWHidrQAAAM8"]
[Thu Jul 30 12:39:04.339732 2026] [security2:error] [pid 765155:tid 765358] [client 20.63.98.115:49945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/user.php"] [unique_id "amuMOOT5hFAbD-LhWHidsQAAAM4"]
[Thu Jul 30 12:39:04.725159 2026] [core:notice] [pid 765155:tid 765390] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:04.729467 2026] [security2:error] [pid 765155:tid 765390] [client 103.215.74.26:21936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMOOT5hFAbD-LhWHiduAAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:04.896881 2026] [security2:error] [pid 765155:tid 765290] [client 150.107.232.194:26670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMOOT5hFAbD-LhWHiduwAAAIo"]
[Thu Jul 30 12:39:04.897001 2026] [security2:error] [pid 765155:tid 765290] [client 150.107.232.194:26670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMOOT5hFAbD-LhWHiduwAAAIo"]
[Thu Jul 30 12:39:05.081896 2026] [security2:error] [pid 765155:tid 765323] [client 20.215.191.139:7237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuMOeT5hFAbD-LhWHidxgAAAKs"]
[Thu Jul 30 12:39:05.135768 2026] [core:notice] [pid 765155:tid 765196] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:05.367551 2026] [security2:error] [pid 765155:tid 765287] [client 20.63.98.115:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/assets/index.php"] [unique_id "amuMOeT5hFAbD-LhWHidzAAAAIc"]
[Thu Jul 30 12:39:05.471693 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:05.476126 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:21952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMOeT5hFAbD-LhWHid0QAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:05.757673 2026] [security2:error] [pid 765155:tid 765289] [client 20.100.187.246:61108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/infos.php"] [unique_id "amuMOeT5hFAbD-LhWHid1wAAAIk"]
[Thu Jul 30 12:39:06.222441 2026] [core:notice] [pid 765155:tid 765402] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:06.226848 2026] [security2:error] [pid 765155:tid 765402] [client 103.215.74.26:21956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMOuT5hFAbD-LhWHid4gAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:06.532748 2026] [security2:error] [pid 765155:tid 765294] [client 20.215.191.139:11300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuMOuT5hFAbD-LhWHid6gAAAI4"]
[Thu Jul 30 12:39:06.959257 2026] [core:notice] [pid 765155:tid 765395] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:06.963540 2026] [security2:error] [pid 765155:tid 765395] [client 103.215.74.26:21960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMOuT5hFAbD-LhWHid8gAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:07.706904 2026] [core:notice] [pid 765155:tid 765349] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:07.713626 2026] [security2:error] [pid 765155:tid 765349] [client 103.215.74.26:21968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMO-T5hFAbD-LhWHieBAAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:08.436283 2026] [core:notice] [pid 765155:tid 765407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:08.440230 2026] [security2:error] [pid 765155:tid 765407] [client 103.215.74.26:21974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMPOT5hFAbD-LhWHieFQAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:08.658581 2026] [security2:error] [pid 765155:tid 765191] [remote 57.141.0.62:29102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amuMPOT5hFAbD-LhWHieHAAAoCM"]
[Thu Jul 30 12:39:08.733829 2026] [security2:error] [pid 765155:tid 765408] [client 20.215.191.139:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuMPOT5hFAbD-LhWHieHQAAAQA"]
[Thu Jul 30 12:39:09.163021 2026] [core:notice] [pid 765155:tid 765361] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:09.167048 2026] [security2:error] [pid 765155:tid 765361] [client 103.215.74.26:21976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMPeT5hFAbD-LhWHieKQAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:09.267485 2026] [core:error] [pid 765155:tid 765245] [remote 74.7.230.46:33162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:09.267505 2026] [core:error] [pid 765155:tid 765245] [remote 74.7.230.46:33162] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:09.267673 2026] [security2:error] [pid 765155:tid 765406] [client 74.7.230.46:33162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuMPeT5hFAbD-LhWHieLwAA_lk"]
[Thu Jul 30 12:39:09.559796 2026] [security2:error] [pid 765155:tid 765372] [client 20.215.191.139:9305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/images/about.php"] [unique_id "amuMPeT5hFAbD-LhWHiePAAAANw"]
[Thu Jul 30 12:39:09.583497 2026] [security2:error] [pid 765155:tid 765386] [client 20.100.187.246:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/updates.php"] [unique_id "amuMPeT5hFAbD-LhWHieQAAAAOo"]
[Thu Jul 30 12:39:09.894314 2026] [core:notice] [pid 765155:tid 765341] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:09.898556 2026] [security2:error] [pid 765155:tid 765341] [client 103.215.74.26:21984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMPeT5hFAbD-LhWHieSQAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:10.352840 2026] [security2:error] [pid 765155:tid 765351] [client 20.215.191.139:15317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuMPuT5hFAbD-LhWHieUgAAAMc"]
[Thu Jul 30 12:39:10.638961 2026] [security2:error] [pid 765155:tid 765232] [remote 74.7.241.60:41034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuMPuT5hFAbD-LhWHieVwAAw0w"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:39:10.683846 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:10.690491 2026] [security2:error] [pid 765155:tid 765332] [client 103.215.74.26:21986] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMPuT5hFAbD-LhWHieWAAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:10.741195 2026] [autoindex:error] [pid 765155:tid 765307] [client 85.204.70.114:33040] AH01276: Cannot serve directory /home2/nxtudite/public_html/riisesolution.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:39:11.045739 2026] [autoindex:error] [pid 765155:tid 765285] [client 85.204.70.114:33040] AH01276: Cannot serve directory /home2/nxtudite/public_html/riisesolution.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:39:11.074951 2026] [security2:error] [pid 765155:tid 765326] [client 20.215.191.139:9334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuMP-T5hFAbD-LhWHieZwAAAK4"]
[Thu Jul 30 12:39:11.312101 2026] [security2:error] [pid 765155:tid 765399] [client 20.100.187.246:61155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/user.php"] [unique_id "amuMP-T5hFAbD-LhWHiebgAAAPc"]
[Thu Jul 30 12:39:11.330553 2026] [security2:error] [pid 765155:tid 765366] [client 85.204.70.114:33040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuMP-T5hFAbD-LhWHiebwAAANY"]
[Thu Jul 30 12:39:11.432059 2026] [core:notice] [pid 765155:tid 765386] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:11.439018 2026] [security2:error] [pid 765155:tid 765386] [client 103.215.74.26:21998] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMP-T5hFAbD-LhWHiedQAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:11.849824 2026] [security2:error] [pid 765155:tid 765398] [client 20.215.191.139:12385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/about.php"] [unique_id "amuMP-T5hFAbD-LhWHieiQAAAPY"]
[Thu Jul 30 12:39:11.856747 2026] [security2:error] [pid 765155:tid 765348] [client 85.204.70.114:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuMP-T5hFAbD-LhWHieigAAAMQ"]
[Thu Jul 30 12:39:11.871238 2026] [security2:error] [pid 765155:tid 765361] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMP-T5hFAbD-LhWHiebQAA0X0"]
[Thu Jul 30 12:39:11.891128 2026] [security2:error] [pid 765155:tid 765290] [client 20.63.98.115:49954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/byp.php"] [unique_id "amuMP-T5hFAbD-LhWHieiwAAAIo"]
[Thu Jul 30 12:39:12.169749 2026] [core:notice] [pid 765155:tid 765360] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:12.175862 2026] [security2:error] [pid 765155:tid 765360] [client 103.215.74.26:22012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQOT5hFAbD-LhWHiejQAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:12.434516 2026] [security2:error] [pid 765155:tid 765404] [client 20.215.191.139:13350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/cgi-bin/about.php"] [unique_id "amuMQOT5hFAbD-LhWHielQAAAPw"]
[Thu Jul 30 12:39:12.473680 2026] [autoindex:error] [pid 765155:tid 765411] [client 85.204.70.114:33064] AH01276: Cannot serve directory /home2/nxtudite/public_html/riisesolution.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:39:12.829576 2026] [security2:error] [pid 765155:tid 765162] [remote 47.128.27.96:13134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/dior-jacket-brown-and-black/"] [unique_id "amuMQOT5hFAbD-LhWHiemgAA3AY"]
[Thu Jul 30 12:39:12.926524 2026] [security2:error] [pid 765155:tid 765314] [client 20.63.98.115:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/bs1.php"] [unique_id "amuMQOT5hFAbD-LhWHienwAAAKI"]
[Thu Jul 30 12:39:12.927050 2026] [core:notice] [pid 765155:tid 765310] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:12.931151 2026] [security2:error] [pid 765155:tid 765310] [client 103.215.74.26:22028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "777"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQOT5hFAbD-LhWHiengAAAJ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:13.241766 2026] [security2:error] [pid 765155:tid 765364] [client 85.204.70.114:33064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuMQeT5hFAbD-LhWHiepQAAANQ"]
[Thu Jul 30 12:39:13.710106 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:13.716846 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:38506] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQeT5hFAbD-LhWHieuAAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:13.806832 2026] [security2:error] [pid 765155:tid 765306] [client 20.63.98.115:60857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/IXR/allez.php"] [unique_id "amuMQeT5hFAbD-LhWHieuwAAAJo"]
[Thu Jul 30 12:39:13.895592 2026] [security2:error] [pid 765155:tid 765371] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMQeT5hFAbD-LhWHiepgAA2y0"]
[Thu Jul 30 12:39:13.924798 2026] [security2:error] [pid 765155:tid 765290] [client 20.215.191.139:15324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuMQeT5hFAbD-LhWHiewgAAAIo"]
[Thu Jul 30 12:39:14.266372 2026] [security2:error] [pid 765155:tid 765373] [client 38.190.144.4:56677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMQuT5hFAbD-LhWHieygAAAN0"]
[Thu Jul 30 12:39:14.266651 2026] [security2:error] [pid 765155:tid 765373] [client 38.190.144.4:56677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMQuT5hFAbD-LhWHieygAAAN0"]
[Thu Jul 30 12:39:14.305495 2026] [security2:error] [pid 765155:tid 765385] [client 85.204.70.114:33080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuMQuT5hFAbD-LhWHieywAAAOk"]
[Thu Jul 30 12:39:14.438852 2026] [core:notice] [pid 765155:tid 765318] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:14.444411 2026] [security2:error] [pid 765155:tid 765318] [client 103.215.74.26:38520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "790"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQuT5hFAbD-LhWHie3QAAAKY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:14.665749 2026] [security2:error] [pid 765155:tid 765380] [client 204.8.98.25:39030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuMQuT5hFAbD-LhWHie3wAAAOQ"]
[Thu Jul 30 12:39:14.666171 2026] [security2:error] [pid 765155:tid 765380] [client 204.8.98.25:39030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuMQuT5hFAbD-LhWHie3wAAAOQ"]
[Thu Jul 30 12:39:14.758831 2026] [security2:error] [pid 765155:tid 765375] [client 57.141.0.63:48800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie2AAA3xg"], referer: https://igetvape-australia.com/product/iget-moon-pomegranate-kiwi-ice/?add-to-cart=175
[Thu Jul 30 12:39:14.799409 2026] [security2:error] [pid 765155:tid 765362] [client 85.204.70.114:33096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuMQuT5hFAbD-LhWHie5gAAANI"]
[Thu Jul 30 12:39:15.151448 2026] [security2:error] [pid 765155:tid 765328] [client 85.204.70.114:33102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuMQ-T5hFAbD-LhWHie7gAAALA"]
[Thu Jul 30 12:39:15.170954 2026] [core:notice] [pid 765155:tid 765389] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:15.174884 2026] [security2:error] [pid 765155:tid 765389] [client 103.215.74.26:38530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQ-T5hFAbD-LhWHie7wAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:15.278972 2026] [security2:error] [pid 765155:tid 765391] [client 20.63.98.115:47188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/load.php"] [unique_id "amuMQ-T5hFAbD-LhWHie8wAAAO8"]
[Thu Jul 30 12:39:15.316972 2026] [security2:error] [pid 765155:tid 765309] [client 172.236.9.101:25567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie1QAAAJ0"]
[Thu Jul 30 12:39:15.333117 2026] [security2:error] [pid 765155:tid 765285] [client 172.236.9.101:43873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie1AAAAIU"]
[Thu Jul 30 12:39:15.345359 2026] [security2:error] [pid 765155:tid 765381] [client 172.236.9.101:4920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie1wAAAOU"]
[Thu Jul 30 12:39:15.346036 2026] [security2:error] [pid 765155:tid 765390] [client 172.236.9.101:22928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie0wAAAO4"]
[Thu Jul 30 12:39:15.346444 2026] [security2:error] [pid 765155:tid 765393] [client 172.236.9.101:60349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie0gAAAPE"]
[Thu Jul 30 12:39:15.347911 2026] [security2:error] [pid 765155:tid 765317] [client 172.236.9.101:38808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie1gAAAKU"]
[Thu Jul 30 12:39:15.353148 2026] [security2:error] [pid 765155:tid 765331] [client 172.236.9.101:49043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie2QAAALM"]
[Thu Jul 30 12:39:15.374452 2026] [security2:error] [pid 765155:tid 765311] [client 172.236.9.101:43128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie2gAAAJ8"]
[Thu Jul 30 12:39:15.375335 2026] [security2:error] [pid 765155:tid 765329] [client 172.236.9.101:32523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie3gAAALE"]
[Thu Jul 30 12:39:15.379627 2026] [security2:error] [pid 765155:tid 765343] [client 172.236.9.101:42554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie3AAAAL8"]
[Thu Jul 30 12:39:15.383043 2026] [security2:error] [pid 765155:tid 765292] [client 172.236.9.101:9267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQuT5hFAbD-LhWHie2wAAAIw"]
[Thu Jul 30 12:39:15.386034 2026] [security2:error] [pid 765155:tid 765371] [client 150.107.232.194:26602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_AAAANs"]
[Thu Jul 30 12:39:15.386168 2026] [security2:error] [pid 765155:tid 765371] [client 150.107.232.194:26602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_AAAANs"]
[Thu Jul 30 12:39:15.714593 2026] [security2:error] [pid 765155:tid 765401] [client 85.204.70.114:33112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuMQ-T5hFAbD-LhWHifDAAAAPk"]
[Thu Jul 30 12:39:15.887467 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:46226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie-gAAAKM"]
[Thu Jul 30 12:39:15.919726 2026] [core:notice] [pid 765155:tid 765322] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:15.925186 2026] [security2:error] [pid 765155:tid 765322] [client 103.215.74.26:38536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "764"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMQ-T5hFAbD-LhWHifFAAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:16.230826 2026] [security2:error] [pid 765155:tid 765299] [client 172.236.9.101:60367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie-wAAAJM"]
[Thu Jul 30 12:39:16.233949 2026] [security2:error] [pid 765155:tid 765361] [client 172.236.9.101:42043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_gAAANE"]
[Thu Jul 30 12:39:16.240552 2026] [security2:error] [pid 765155:tid 765408] [client 172.236.9.101:17508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_QAAAQA"]
[Thu Jul 30 12:39:16.242856 2026] [security2:error] [pid 765155:tid 765387] [client 172.236.9.101:36683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHifAwAAAOs"]
[Thu Jul 30 12:39:16.245381 2026] [security2:error] [pid 765155:tid 765351] [client 172.236.9.101:44287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHifBAAAAMc"]
[Thu Jul 30 12:39:16.247941 2026] [security2:error] [pid 765155:tid 765295] [client 172.236.9.101:61967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHie_wAAAI8"]
[Thu Jul 30 12:39:16.261368 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:20494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHifBgAAAM8"]
[Thu Jul 30 12:39:16.274242 2026] [security2:error] [pid 765155:tid 765338] [client 172.236.9.101:48054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMQ-T5hFAbD-LhWHifBQAAALo"]
[Thu Jul 30 12:39:16.275600 2026] [security2:error] [pid 765155:tid 765339] [client 43.173.180.222:45792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/09/09/au-hasard-de-la-toile-3/"] [unique_id "amuMROT5hFAbD-LhWHifFQAAALs"]
[Thu Jul 30 12:39:16.301553 2026] [security2:error] [pid 765155:tid 765332] [client 85.204.70.114:33124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuMROT5hFAbD-LhWHifHgAAALQ"]
[Thu Jul 30 12:39:16.399581 2026] [security2:error] [pid 765155:tid 765312] [client 43.173.182.142:41202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/12/01/noel-2013-20-idees-cadeaux-a-moins-de-5-euros/"] [unique_id "amuMROT5hFAbD-LhWHifGgAAAKA"]
[Thu Jul 30 12:39:16.758615 2026] [core:notice] [pid 765155:tid 765319] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:16.763282 2026] [security2:error] [pid 765155:tid 765319] [client 43.173.174.173:60294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/09/09/au-hasard-de-la-toile-3/"] [unique_id "amuMROT5hFAbD-LhWHifKQAAAKc"], referer: https://carnetdeshopping.com/index.php/2013/09/09/au-hasard-de-la-toile-3/
[Thu Jul 30 12:39:16.809707 2026] [core:error] [pid 765155:tid 765366] [client 74.7.228.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:16.809726 2026] [core:error] [pid 765155:tid 765366] [client 74.7.228.4:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:16.809846 2026] [security2:error] [pid 765155:tid 765366] [client 74.7.228.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.embassyofspaininpakistan.info"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuMROT5hFAbD-LhWHifLwAAANY"]
[Thu Jul 30 12:39:16.810629 2026] [security2:error] [pid 765155:tid 765404] [client 74.7.228.4:50330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.embassyofspaininpakistan.info"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuMROT5hFAbD-LhWHifLQAA_EM"]
[Thu Jul 30 12:39:16.896047 2026] [security2:error] [pid 765155:tid 765345] [client 85.204.70.114:32868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuMROT5hFAbD-LhWHifNgAAAME"]
[Thu Jul 30 12:39:16.933614 2026] [core:notice] [pid 765155:tid 765329] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:17.170354 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:17.175154 2026] [security2:error] [pid 765155:tid 765397] [client 43.172.197.93:53532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/12/01/noel-2013-20-idees-cadeaux-a-moins-de-5-euros/"] [unique_id "amuMReT5hFAbD-LhWHifPAAAAPU"], referer: https://carnetdeshopping.com/index.php/2013/12/01/noel-2013-20-idees-cadeaux-a-moins-de-5-euros/
[Thu Jul 30 12:39:17.451353 2026] [security2:error] [pid 765155:tid 765338] [client 85.204.70.114:32878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuMReT5hFAbD-LhWHifSAAAALo"]
[Thu Jul 30 12:39:17.980598 2026] [security2:error] [pid 765155:tid 765353] [client 85.204.70.114:32894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuMReT5hFAbD-LhWHifVgAAAMk"]
[Thu Jul 30 12:39:18.047835 2026] [security2:error] [pid 765155:tid 765376] [client 193.37.252.99:44096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMReT5hFAbD-LhWHifTAAAAOA"]
[Thu Jul 30 12:39:18.047963 2026] [security2:error] [pid 765155:tid 765376] [client 193.37.252.99:44096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMReT5hFAbD-LhWHifTAAAAOA"]
[Thu Jul 30 12:39:18.082609 2026] [security2:error] [pid 765155:tid 765367] [client 20.63.98.115:60837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/privacy.php"] [unique_id "amuMRuT5hFAbD-LhWHifVwAAANc"]
[Thu Jul 30 12:39:18.390527 2026] [security2:error] [pid 765155:tid 765347] [client 20.215.191.139:7282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuMRuT5hFAbD-LhWHifZQAAAMM"]
[Thu Jul 30 12:39:18.465670 2026] [security2:error] [pid 765155:tid 765337] [client 85.204.70.114:32898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuMRuT5hFAbD-LhWHifaQAAALk"]
[Thu Jul 30 12:39:18.898006 2026] [security2:error] [pid 765155:tid 765360] [client 20.100.187.246:64986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/admin-ajax.php"] [unique_id "amuMRuT5hFAbD-LhWHifcwAAANA"]
[Thu Jul 30 12:39:19.054795 2026] [security2:error] [pid 765155:tid 765329] [client 20.215.191.139:42484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuMR-T5hFAbD-LhWHifegAAALE"]
[Thu Jul 30 12:39:19.332573 2026] [security2:error] [pid 765155:tid 765290] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMRuT5hFAbD-LhWHifYgAAilE"]
[Thu Jul 30 12:39:19.521854 2026] [security2:error] [pid 765155:tid 765355] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMRuT5hFAbD-LhWHifagAAy0g"]
[Thu Jul 30 12:39:19.581580 2026] [security2:error] [pid 765155:tid 765168] [remote 57.141.0.19:35840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuMR-T5hFAbD-LhWHifjQAAzww"]
[Thu Jul 30 12:39:19.628635 2026] [security2:error] [pid 765155:tid 765304] [client 20.63.98.115:61471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-cli.php"] [unique_id "amuMR-T5hFAbD-LhWHifjgAAAJg"]
[Thu Jul 30 12:39:20.133362 2026] [security2:error] [pid 765155:tid 765337] [client 85.204.70.114:32912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuMSOT5hFAbD-LhWHifowAAALk"]
[Thu Jul 30 12:39:20.230791 2026] [security2:error] [pid 765155:tid 765410] [client 43.157.53.115:35398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.53.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/issue/current"] [unique_id "amuMR-T5hFAbD-LhWHifngAAAQI"], referer: https://ejournalugj.com/index_php/jibm/issue/current
[Thu Jul 30 12:39:20.337478 2026] [security2:error] [pid 765155:tid 765252] [remote 57.141.0.63:32306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuMSOT5hFAbD-LhWHifsAAAzWA"]
[Thu Jul 30 12:39:20.683474 2026] [security2:error] [pid 765155:tid 765316] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMSOT5hFAbD-LhWHifogAApGo"]
[Thu Jul 30 12:39:20.685840 2026] [security2:error] [pid 765155:tid 765315] [client 85.204.70.114:32918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuMSOT5hFAbD-LhWHifuwAAAKM"]
[Thu Jul 30 12:39:20.707606 2026] [core:notice] [pid 765155:tid 765234] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:21.107315 2026] [security2:error] [pid 765155:tid 765399] [client 20.215.191.139:15351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuMSeT5hFAbD-LhWHifywAAAPc"]
[Thu Jul 30 12:39:21.361448 2026] [security2:error] [pid 765155:tid 765359] [client 85.204.70.114:32920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuMSeT5hFAbD-LhWHif0AAAAM8"]
[Thu Jul 30 12:39:21.506743 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:21.542839 2026] [security2:error] [pid 765155:tid 765298] [client 20.100.187.246:61124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/alfa.php"] [unique_id "amuMSeT5hFAbD-LhWHif1AAAAJI"]
[Thu Jul 30 12:39:21.671494 2026] [core:notice] [pid 765155:tid 765345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:21.675416 2026] [security2:error] [pid 765155:tid 765345] [client 103.215.74.26:38538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMSeT5hFAbD-LhWHif3AAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:22.068163 2026] [security2:error] [pid 765155:tid 765353] [client 20.215.191.139:42534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuMSuT5hFAbD-LhWHif5gAAAMk"]
[Thu Jul 30 12:39:22.700110 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:22.806911 2026] [security2:error] [pid 765155:tid 765382] [client 85.204.70.114:32922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuMSuT5hFAbD-LhWHigAAAAAOY"]
[Thu Jul 30 12:39:23.013518 2026] [security2:error] [pid 765155:tid 765403] [client 20.215.191.139:42535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuMS-T5hFAbD-LhWHigBwAAAPs"]
[Thu Jul 30 12:39:23.476421 2026] [security2:error] [pid 765155:tid 765355] [client 85.204.70.114:32936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riisesolution.com.nxt.udi.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuMS-T5hFAbD-LhWHigHAAAAMs"]
[Thu Jul 30 12:39:23.929258 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:27997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigDwAAAJs"]
[Thu Jul 30 12:39:24.003151 2026] [security2:error] [pid 765155:tid 765399] [client 172.236.9.101:17730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigEgAAAPc"]
[Thu Jul 30 12:39:24.003936 2026] [security2:error] [pid 765155:tid 765311] [client 172.236.9.101:55263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigFwAAAJ8"]
[Thu Jul 30 12:39:24.026426 2026] [security2:error] [pid 765155:tid 765390] [client 172.236.9.101:20318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigGQAAAO4"]
[Thu Jul 30 12:39:24.034271 2026] [security2:error] [pid 765155:tid 765343] [client 172.236.9.101:24512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigGAAAAL8"]
[Thu Jul 30 12:39:24.042722 2026] [security2:error] [pid 765155:tid 765392] [client 172.236.9.101:20834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigFgAAAPA"]
[Thu Jul 30 12:39:24.052070 2026] [core:error] [pid 765155:tid 765294] [client 20.100.187.246:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:24.052098 2026] [core:error] [pid 765155:tid 765294] [client 20.100.187.246:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:24.080675 2026] [security2:error] [pid 765155:tid 765359] [client 172.236.9.101:29514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMS-T5hFAbD-LhWHigGwAAAM8"]
[Thu Jul 30 12:39:24.231186 2026] [security2:error] [pid 765155:tid 765350] [client 38.190.144.4:57197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMTOT5hFAbD-LhWHigMAAAAMY"]
[Thu Jul 30 12:39:24.231314 2026] [security2:error] [pid 765155:tid 765350] [client 38.190.144.4:57197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMTOT5hFAbD-LhWHigMAAAAMY"]
[Thu Jul 30 12:39:24.949473 2026] [security2:error] [pid 765155:tid 765316] [client 119.73.97.132:29860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigSwAApDM"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 12:39:25.245509 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:9498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigNQAAALk"]
[Thu Jul 30 12:39:25.264224 2026] [security2:error] [pid 765155:tid 765291] [client 172.236.9.101:19021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigNAAAAIs"]
[Thu Jul 30 12:39:25.285390 2026] [security2:error] [pid 765155:tid 765356] [client 172.236.9.101:44838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigOQAAAMw"]
[Thu Jul 30 12:39:25.293874 2026] [security2:error] [pid 765155:tid 765327] [client 172.236.9.101:22622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigOAAAAK8"]
[Thu Jul 30 12:39:25.306068 2026] [security2:error] [pid 765155:tid 765388] [client 72.62.248.216:46548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigUgAA7Bg"]
[Thu Jul 30 12:39:25.313274 2026] [security2:error] [pid 765155:tid 765373] [client 172.236.9.101:13719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigOwAAAN0"]
[Thu Jul 30 12:39:25.334061 2026] [security2:error] [pid 765155:tid 765364] [client 172.236.9.101:56359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigPAAAANQ"]
[Thu Jul 30 12:39:25.344699 2026] [security2:error] [pid 765155:tid 765318] [client 172.236.9.101:23221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigPQAAAKY"]
[Thu Jul 30 12:39:25.370230 2026] [security2:error] [pid 765155:tid 765308] [client 20.63.98.115:47179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cc.php"] [unique_id "amuMTeT5hFAbD-LhWHigYAAAAJw"]
[Thu Jul 30 12:39:25.404657 2026] [security2:error] [pid 765155:tid 765383] [client 172.236.9.101:53988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/ssl/private/alseermarine.com_key.pem"] [unique_id "amuMTeT5hFAbD-LhWHigYwAAAOc"]
[Thu Jul 30 12:39:25.434159 2026] [security2:error] [pid 765155:tid 765400] [client 172.236.9.101:18486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigQQAAAPg"]
[Thu Jul 30 12:39:25.436781 2026] [security2:error] [pid 765155:tid 765374] [client 172.236.9.101:35411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigPgAAAN4"]
[Thu Jul 30 12:39:25.437561 2026] [security2:error] [pid 765155:tid 765334] [client 172.236.9.101:5323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigPwAAALY"]
[Thu Jul 30 12:39:25.440104 2026] [security2:error] [pid 765155:tid 765386] [client 172.236.9.101:25414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigQAAAAOo"]
[Thu Jul 30 12:39:25.442560 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:13345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMTOT5hFAbD-LhWHigQgAAAOg"]
[Thu Jul 30 12:39:25.539098 2026] [security2:error] [pid 765155:tid 765345] [client 194.187.251.163:45144] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuMTeT5hFAbD-LhWHigXAAAAME"]
[Thu Jul 30 12:39:25.539220 2026] [security2:error] [pid 765155:tid 765345] [client 194.187.251.163:45144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuMTeT5hFAbD-LhWHigXAAAAME"]
[Thu Jul 30 12:39:25.629230 2026] [security2:error] [pid 765155:tid 765324] [client 119.73.97.132:29860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuMTeT5hFAbD-LhWHigXQAArB8"]
[Thu Jul 30 12:39:25.650036 2026] [security2:error] [pid 765155:tid 765324] [client 119.73.97.132:29860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuMTeT5hFAbD-LhWHigXgAArCs"]
[Thu Jul 30 12:39:25.797775 2026] [security2:error] [pid 765155:tid 765390] [client 72.62.248.216:46548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuMTeT5hFAbD-LhWHigZAAA7jg"]
[Thu Jul 30 12:39:25.932661 2026] [security2:error] [pid 765155:tid 765325] [client 150.107.232.194:27436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMTeT5hFAbD-LhWHigewAAAK0"]
[Thu Jul 30 12:39:25.932774 2026] [security2:error] [pid 765155:tid 765325] [client 150.107.232.194:27436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMTeT5hFAbD-LhWHigewAAAK0"]
[Thu Jul 30 12:39:26.042449 2026] [security2:error] [pid 765155:tid 765204] [remote 74.7.241.59:56376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuMTuT5hFAbD-LhWHigfwAAkzA"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/backup_1784717747
[Thu Jul 30 12:39:26.666582 2026] [security2:error] [pid 765155:tid 765309] [client 20.215.191.139:30374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuMTuT5hFAbD-LhWHigkQAAAJ0"]
[Thu Jul 30 12:39:27.023642 2026] [security2:error] [pid 765155:tid 765317] [client 20.63.98.115:47223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/media-new.php"] [unique_id "amuMT-T5hFAbD-LhWHignwAAAKU"]
[Thu Jul 30 12:39:27.025595 2026] [security2:error] [pid 765155:tid 765361] [client 20.100.187.246:60169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/hehe.php"] [unique_id "amuMT-T5hFAbD-LhWHigoAAAANE"]
[Thu Jul 30 12:39:27.334257 2026] [security2:error] [pid 765155:tid 765385] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laduchessecollections.com"] [uri "/index.php"] [unique_id "amuMTeT5hFAbD-LhWHigaAAA6Sw"]
[Thu Jul 30 12:39:27.397651 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:27.403288 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:5674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMT-T5hFAbD-LhWHigrAAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:28.159558 2026] [core:notice] [pid 765155:tid 765333] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:28.163323 2026] [security2:error] [pid 765155:tid 765333] [client 103.215.74.26:5680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMUOT5hFAbD-LhWHigxQAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:28.454809 2026] [security2:error] [pid 765155:tid 765303] [client 20.63.98.115:61931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-blog.php"] [unique_id "amuMUOT5hFAbD-LhWHig0gAAAJc"]
[Thu Jul 30 12:39:28.483411 2026] [security2:error] [pid 765155:tid 765334] [client 20.100.187.246:62390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/rk2.php"] [unique_id "amuMUOT5hFAbD-LhWHig1AAAALY"]
[Thu Jul 30 12:39:28.617834 2026] [core:notice] [pid 765155:tid 765287] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:29.457357 2026] [security2:error] [pid 765155:tid 765295] [client 20.100.187.246:62354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/setup-config.php"] [unique_id "amuMUeT5hFAbD-LhWHig8wAAAI8"]
[Thu Jul 30 12:39:30.247584 2026] [security2:error] [pid 765155:tid 765369] [client 20.215.191.139:12668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/cloud.php"] [unique_id "amuMUuT5hFAbD-LhWHihDwAAANk"]
[Thu Jul 30 12:39:31.332190 2026] [security2:error] [pid 765155:tid 765409] [client 20.100.187.246:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/a7.php"] [unique_id "amuMU-T5hFAbD-LhWHihOwAAAQE"]
[Thu Jul 30 12:39:31.667926 2026] [security2:error] [pid 765155:tid 765300] [client 20.215.191.139:14963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuMU-T5hFAbD-LhWHihSAAAAJQ"]
[Thu Jul 30 12:39:31.784133 2026] [security2:error] [pid 765155:tid 765338] [client 185.206.81.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMUuT5hFAbD-LhWHihNAAAulg"], referer: https://allmontecristi.com
[Thu Jul 30 12:39:32.184485 2026] [security2:error] [pid 765155:tid 765368] [client 20.63.98.115:57261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-2019.php"] [unique_id "amuMVOT5hFAbD-LhWHihUwAAANg"]
[Thu Jul 30 12:39:32.452405 2026] [security2:error] [pid 765155:tid 765322] [client 20.215.191.139:42507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/updates.php"] [unique_id "amuMVOT5hFAbD-LhWHihXQAAAKo"]
[Thu Jul 30 12:39:33.110291 2026] [security2:error] [pid 765155:tid 765398] [client 20.215.191.139:14947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/css/cloud.php"] [unique_id "amuMVeT5hFAbD-LhWHihcQAAAPY"]
[Thu Jul 30 12:39:33.915542 2026] [security2:error] [pid 765155:tid 765291] [client 20.63.98.115:20913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/menu.php"] [unique_id "amuMVeT5hFAbD-LhWHihiAAAAIs"]
[Thu Jul 30 12:39:33.917345 2026] [security2:error] [pid 765155:tid 765385] [client 20.215.191.139:14724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuMVeT5hFAbD-LhWHihiQAAAOk"]
[Thu Jul 30 12:39:33.930012 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:33.933881 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:61704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMVeT5hFAbD-LhWHihigAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:34.292944 2026] [security2:error] [pid 765155:tid 765172] [remote 72.167.132.114:50964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jgp.fxh.temporary.site"] [uri "/wp-login.php"] [unique_id "amuMVuT5hFAbD-LhWHihkgAArxA"]
[Thu Jul 30 12:39:34.295581 2026] [security2:error] [pid 765155:tid 765411] [client 20.100.187.246:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/f7.php"] [unique_id "amuMVuT5hFAbD-LhWHihkwAAAQM"]
[Thu Jul 30 12:39:34.649942 2026] [core:notice] [pid 765155:tid 765342] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:34.654389 2026] [security2:error] [pid 765155:tid 765342] [client 103.215.74.26:61708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMVuT5hFAbD-LhWHihnQAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:34.935854 2026] [security2:error] [pid 765155:tid 765328] [client 20.100.187.246:61174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/nw.php"] [unique_id "amuMVuT5hFAbD-LhWHihpwAAALA"]
[Thu Jul 30 12:39:35.023183 2026] [security2:error] [pid 765155:tid 765312] [client 20.215.191.139:42526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/img/cloud.php"] [unique_id "amuMV-T5hFAbD-LhWHihqAAAAKA"]
[Thu Jul 30 12:39:35.386617 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:35.390986 2026] [security2:error] [pid 765155:tid 765367] [client 103.215.74.26:61712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMV-T5hFAbD-LhWHihtAAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:35.807825 2026] [security2:error] [pid 765155:tid 765383] [client 20.63.98.115:57219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-crons.php"] [unique_id "amuMV-T5hFAbD-LhWHihvQAAAOc"]
[Thu Jul 30 12:39:36.116617 2026] [core:notice] [pid 765155:tid 765407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:36.120833 2026] [security2:error] [pid 765155:tid 765407] [client 103.215.74.26:61726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMWOT5hFAbD-LhWHihzgAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:36.464819 2026] [security2:error] [pid 765155:tid 765356] [client 150.107.232.194:26772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMWOT5hFAbD-LhWHih3QAAAMw"]
[Thu Jul 30 12:39:36.464914 2026] [security2:error] [pid 765155:tid 765356] [client 150.107.232.194:26772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMWOT5hFAbD-LhWHih3QAAAMw"]
[Thu Jul 30 12:39:36.616850 2026] [core:error] [pid 765155:tid 765364] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:36.616877 2026] [core:error] [pid 765155:tid 765364] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:36.845194 2026] [core:notice] [pid 765155:tid 765318] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:36.849545 2026] [security2:error] [pid 765155:tid 765318] [client 103.215.74.26:61730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMWOT5hFAbD-LhWHih7QAAAKY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:36.950120 2026] [security2:error] [pid 765155:tid 765305] [client 20.215.191.139:15003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuMWOT5hFAbD-LhWHih9QAAAJk"]
[Thu Jul 30 12:39:37.918085 2026] [security2:error] [pid 765155:tid 765380] [client 20.100.187.246:62364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/ova.php"] [unique_id "amuMWeT5hFAbD-LhWHiiHwAAAOQ"]
[Thu Jul 30 12:39:38.129682 2026] [security2:error] [pid 765155:tid 765356] [client 74.7.228.39:34126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cmv.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuMWuT5hFAbD-LhWHiiJwAAAMw"]
[Thu Jul 30 12:39:38.315753 2026] [security2:error] [pid 765155:tid 765293] [client 20.63.98.115:61951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/class.php"] [unique_id "amuMWuT5hFAbD-LhWHiiYwAAAI0"]
[Thu Jul 30 12:39:38.349337 2026] [security2:error] [pid 765155:tid 765288] [client 20.215.191.139:4750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuMWuT5hFAbD-LhWHiiZAAAAIg"]
[Thu Jul 30 12:39:39.174957 2026] [security2:error] [pid 765155:tid 765357] [client 20.63.98.115:21430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/login.php"] [unique_id "amuMW-T5hFAbD-LhWHiilQAAAM0"]
[Thu Jul 30 12:39:39.448134 2026] [security2:error] [pid 765155:tid 765405] [client 20.215.191.139:14740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/avaa.php"] [unique_id "amuMW-T5hFAbD-LhWHiingAAAP0"]
[Thu Jul 30 12:39:39.917598 2026] [core:error] [pid 765155:tid 765367] [client 20.63.98.115:61892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:39.917618 2026] [core:error] [pid 765155:tid 765367] [client 20.63.98.115:61892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:41.325145 2026] [core:notice] [pid 765155:tid 765203] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:41.384361 2026] [security2:error] [pid 765155:tid 765368] [client 20.100.187.246:64429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/robots.php"] [unique_id "amuMXeT5hFAbD-LhWHii4AAAANg"]
[Thu Jul 30 12:39:41.629412 2026] [core:notice] [pid 765155:tid 765187] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:41.788295 2026] [security2:error] [pid 765155:tid 765292] [client 103.98.129.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMXOT5hFAbD-LhWHii0wAAjCY"], referer: https://allmontecristi.com
[Thu Jul 30 12:39:42.031637 2026] [security2:error] [pid 765155:tid 765312] [client 20.63.98.115:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/aged.php"] [unique_id "amuMXuT5hFAbD-LhWHii8wAAAKA"]
[Thu Jul 30 12:39:42.210142 2026] [core:error] [pid 765155:tid 765379] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:42.210165 2026] [core:error] [pid 765155:tid 765379] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:42.467633 2026] [security2:error] [pid 765155:tid 765402] [client 20.215.191.139:14967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/images/cloud.php"] [unique_id "amuMXuT5hFAbD-LhWHijAAAAAPo"]
[Thu Jul 30 12:39:42.586082 2026] [core:notice] [pid 765155:tid 765397] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:42.590537 2026] [security2:error] [pid 765155:tid 765397] [client 103.215.74.26:61736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMXuT5hFAbD-LhWHijAQAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:42.886545 2026] [security2:error] [pid 765155:tid 765304] [client 20.63.98.115:61901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/vv.php"] [unique_id "amuMXuT5hFAbD-LhWHijCwAAAJg"]
[Thu Jul 30 12:39:43.327177 2026] [core:notice] [pid 765155:tid 765350] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:43.331784 2026] [security2:error] [pid 765155:tid 765350] [client 103.215.74.26:64442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMX-T5hFAbD-LhWHijHQAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:43.580323 2026] [security2:error] [pid 765155:tid 765357] [client 20.215.191.139:7756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuMX-T5hFAbD-LhWHijJAAAAM0"]
[Thu Jul 30 12:39:44.100700 2026] [core:notice] [pid 765155:tid 765286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:44.105200 2026] [security2:error] [pid 765155:tid 765286] [client 103.215.74.26:64444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMYOT5hFAbD-LhWHijMwAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:44.147214 2026] [security2:error] [pid 765155:tid 765411] [client 20.63.98.115:62019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/user-edit.php"] [unique_id "amuMYOT5hFAbD-LhWHijNwAAAQM"]
[Thu Jul 30 12:39:44.870383 2026] [core:notice] [pid 765155:tid 765338] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:44.874790 2026] [security2:error] [pid 765155:tid 765338] [client 103.215.74.26:64450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMYOT5hFAbD-LhWHijSgAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:45.125524 2026] [core:notice] [pid 765155:tid 765358] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:45.214413 2026] [security2:error] [pid 765155:tid 765388] [client 20.63.98.115:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuMYeT5hFAbD-LhWHijVwAAAOw"]
[Thu Jul 30 12:39:45.372719 2026] [security2:error] [pid 765155:tid 765342] [client 20.215.191.139:7782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuMYeT5hFAbD-LhWHijXAAAAL4"]
[Thu Jul 30 12:39:45.616482 2026] [core:notice] [pid 765155:tid 765336] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:45.624840 2026] [security2:error] [pid 765155:tid 765336] [client 103.215.74.26:64466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMYeT5hFAbD-LhWHijYwAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:45.630610 2026] [security2:error] [pid 765155:tid 765317] [client 20.100.187.246:59525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/alf.php"] [unique_id "amuMYeT5hFAbD-LhWHijZAAAAKU"]
[Thu Jul 30 12:39:45.782864 2026] [security2:error] [pid 765155:tid 765372] [client 38.190.144.4:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMYeT5hFAbD-LhWHijawAAANw"]
[Thu Jul 30 12:39:45.782986 2026] [security2:error] [pid 765155:tid 765372] [client 38.190.144.4:58352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMYeT5hFAbD-LhWHijawAAANw"]
[Thu Jul 30 12:39:46.190828 2026] [security2:error] [pid 765155:tid 765390] [client 20.215.191.139:60860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuMYuT5hFAbD-LhWHijeQAAAO4"]
[Thu Jul 30 12:39:46.385211 2026] [core:notice] [pid 765155:tid 765375] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:46.389513 2026] [security2:error] [pid 765155:tid 765375] [client 103.215.74.26:64480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMYuT5hFAbD-LhWHijggAAAN8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:46.453999 2026] [security2:error] [pid 765155:tid 765288] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMYeT5hFAbD-LhWHijbgAAAIg"]
[Thu Jul 30 12:39:46.930805 2026] [security2:error] [pid 765155:tid 765293] [client 150.107.232.194:26917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMYuT5hFAbD-LhWHijlQAAAI0"]
[Thu Jul 30 12:39:46.930935 2026] [security2:error] [pid 765155:tid 765293] [client 150.107.232.194:26917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMYuT5hFAbD-LhWHijlQAAAI0"]
[Thu Jul 30 12:39:47.005313 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:47661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMYuT5hFAbD-LhWHijgQAAAKM"]
[Thu Jul 30 12:39:47.005370 2026] [security2:error] [pid 765155:tid 765330] [client 172.236.9.101:42590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMYuT5hFAbD-LhWHijgAAAALI"]
[Thu Jul 30 12:39:47.010033 2026] [security2:error] [pid 765155:tid 765320] [client 172.236.9.101:37891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMYuT5hFAbD-LhWHijgwAAAKg"]
[Thu Jul 30 12:39:47.130169 2026] [security2:error] [pid 765155:tid 765324] [client 20.63.98.115:38867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/engine.php"] [unique_id "amuMY-T5hFAbD-LhWHijnwAAAKw"]
[Thu Jul 30 12:39:47.331842 2026] [security2:error] [pid 765155:tid 765298] [client 20.215.191.139:2696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuMY-T5hFAbD-LhWHijpwAAAJI"]
[Thu Jul 30 12:39:47.335083 2026] [security2:error] [pid 765155:tid 765310] [client 74.7.241.144:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.koinjp189.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuMY-T5hFAbD-LhWHijpgAAAJ4"]
[Thu Jul 30 12:39:47.600170 2026] [security2:error] [pid 765155:tid 765390] [client 20.100.187.246:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/feedback.php"] [unique_id "amuMY-T5hFAbD-LhWHijuQAAAO4"]
[Thu Jul 30 12:39:47.678128 2026] [lsapi:error] [pid 765155:tid 765170] [remote 41.210.167.242:0] [host flixon.net] Error receiving response: ReceiveResponse: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1009; user ID 1009), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://flixon.net/video/the-killer-vj-junior/
[Thu Jul 30 12:39:47.705770 2026] [security2:error] [pid 765155:tid 765387] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMY-T5hFAbD-LhWHijngAA63E"]
[Thu Jul 30 12:39:47.897931 2026] [security2:error] [pid 765155:tid 765409] [client 172.236.9.101:2318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMY-T5hFAbD-LhWHijqwAAAQE"]
[Thu Jul 30 12:39:47.898750 2026] [security2:error] [pid 765155:tid 765308] [client 172.236.9.101:18861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMY-T5hFAbD-LhWHijrAAAAJw"]
[Thu Jul 30 12:39:48.002323 2026] [security2:error] [pid 765155:tid 765338] [client 74.7.228.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ed9bceb3.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuMY-T5hFAbD-LhWHijuAAAALo"]
[Thu Jul 30 12:39:48.003021 2026] [security2:error] [pid 765155:tid 765309] [client 74.7.228.6:38796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ed9bceb3.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuMY-T5hFAbD-LhWHijtgAAnU4"]
[Thu Jul 30 12:39:48.296418 2026] [security2:error] [pid 765155:tid 765381] [client 20.215.191.139:60845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuMZOT5hFAbD-LhWHijzAAAAOU"]
[Thu Jul 30 12:39:48.928916 2026] [core:error] [pid 765155:tid 765298] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:48.928942 2026] [core:error] [pid 765155:tid 765298] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:48.952013 2026] [security2:error] [pid 765155:tid 765360] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMZOT5hFAbD-LhWHijzwAAANA"]
[Thu Jul 30 12:39:49.229470 2026] [security2:error] [pid 765155:tid 765344] [client 20.100.187.246:33844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/gettest.php"] [unique_id "amuMZeT5hFAbD-LhWHikAwAAAMA"]
[Thu Jul 30 12:39:49.258381 2026] [security2:error] [pid 765155:tid 765348] [client 20.215.191.139:3776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuMZeT5hFAbD-LhWHikBAAAAMQ"]
[Thu Jul 30 12:39:49.350572 2026] [security2:error] [pid 765155:tid 765347] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMZOT5hFAbD-LhWHij4AAAAMM"]
[Thu Jul 30 12:39:49.447513 2026] [security2:error] [pid 765155:tid 765342] [client 20.63.98.115:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/edit-comments.php"] [unique_id "amuMZeT5hFAbD-LhWHikEwAAAL4"]
[Thu Jul 30 12:39:49.603864 2026] [core:notice] [pid 765155:tid 765209] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:49.848638 2026] [proxy:error] [pid 765155:tid 765350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:39:49.848733 2026] [proxy_http:error] [pid 765155:tid 765350] [client 34.233.129.35:1577] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:39:49.849469 2026] [proxy:error] [pid 765155:tid 765350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:39:49.849521 2026] [proxy_http:error] [pid 765155:tid 765350] [client 34.233.129.35:1577] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:39:49.861518 2026] [proxy:error] [pid 765155:tid 765355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:39:49.861629 2026] [proxy_http:error] [pid 765155:tid 765355] [client 34.224.175.62:18202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:39:49.862504 2026] [proxy:error] [pid 765155:tid 765355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:39:49.862571 2026] [proxy_http:error] [pid 765155:tid 765355] [client 34.224.175.62:18202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:39:49.883412 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:51672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikCQAAAKo"]
[Thu Jul 30 12:39:49.883807 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:30488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikCAAAANM"]
[Thu Jul 30 12:39:49.904083 2026] [security2:error] [pid 765155:tid 765323] [client 172.236.9.101:48071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikDgAAAKs"]
[Thu Jul 30 12:39:49.919398 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:24433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikEAAAAPs"]
[Thu Jul 30 12:39:49.991523 2026] [security2:error] [pid 765155:tid 765385] [client 20.100.187.246:60589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/maint.php"] [unique_id "amuMZeT5hFAbD-LhWHikKwAAAOk"]
[Thu Jul 30 12:39:50.607097 2026] [security2:error] [pid 765155:tid 765313] [client 74.7.228.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.frontierphoenix.site"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikKgAAoTM"]
[Thu Jul 30 12:39:50.607129 2026] [security2:error] [pid 765155:tid 765313] [client 74.7.228.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.frontierphoenix.site"] [uri "/index.php"] [unique_id "amuMZeT5hFAbD-LhWHikKgAAoTM"]
[Thu Jul 30 12:39:50.758087 2026] [security2:error] [pid 765155:tid 765290] [client 20.63.98.115:61914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-blog-header.php"] [unique_id "amuMZuT5hFAbD-LhWHikSgAAAIo"]
[Thu Jul 30 12:39:50.776217 2026] [security2:error] [pid 765155:tid 765330] [client 20.215.191.139:30292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/updates.php"] [unique_id "amuMZuT5hFAbD-LhWHikSwAAALI"]
[Thu Jul 30 12:39:50.857897 2026] [security2:error] [pid 765155:tid 765411] [client 172.236.9.101:63456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZuT5hFAbD-LhWHikMwAAAQM"]
[Thu Jul 30 12:39:50.915198 2026] [security2:error] [pid 765155:tid 765300] [client 172.236.9.101:44096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZuT5hFAbD-LhWHikNAAAAJQ"]
[Thu Jul 30 12:39:51.624632 2026] [security2:error] [pid 765155:tid 765382] [client 74.7.228.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "frontierphoenix.site"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikZAAA5kY"], referer: https://www.frontierphoenix.site/robots.txt
[Thu Jul 30 12:39:51.671437 2026] [security2:error] [pid 765155:tid 765316] [client 20.63.98.115:42973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/alfa-rex.php7"] [unique_id "amuMZ-T5hFAbD-LhWHikcAAAAKQ"]
[Thu Jul 30 12:39:51.867157 2026] [security2:error] [pid 765155:tid 765307] [client 172.236.9.101:45098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikWgAAAJs"]
[Thu Jul 30 12:39:51.894512 2026] [security2:error] [pid 765155:tid 765350] [client 172.236.9.101:12116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikXwAAAMY"]
[Thu Jul 30 12:39:51.930925 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:53508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikYAAAAKo"]
[Thu Jul 30 12:39:51.981230 2026] [security2:error] [pid 765155:tid 765374] [client 20.215.191.139:3751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuMZ-T5hFAbD-LhWHikewAAAN4"]
[Thu Jul 30 12:39:52.112665 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:52.116570 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:64488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMaOT5hFAbD-LhWHikfwAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:52.431756 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:52.437937 2026] [security2:error] [pid 765155:tid 765314] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMZ-T5hFAbD-LhWHikdwAAol4"]
[Thu Jul 30 12:39:52.570276 2026] [core:error] [pid 765155:tid 765377] [client 20.63.98.115:21114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:52.570312 2026] [core:error] [pid 765155:tid 765377] [client 20.63.98.115:21114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:52.724845 2026] [security2:error] [pid 765155:tid 765342] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMaOT5hFAbD-LhWHikkgAAvlA"]
[Thu Jul 30 12:39:52.808034 2026] [core:notice] [pid 765155:tid 765330] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:52.843662 2026] [security2:error] [pid 765155:tid 765319] [client 172.236.9.101:19620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMaOT5hFAbD-LhWHikhwAAAKc"]
[Thu Jul 30 12:39:52.859321 2026] [core:notice] [pid 765155:tid 765308] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:52.863300 2026] [security2:error] [pid 765155:tid 765308] [client 103.215.74.26:64492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMaOT5hFAbD-LhWHikmwAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:53.115783 2026] [core:notice] [pid 765155:tid 765337] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:53.346562 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:53.470926 2026] [core:error] [pid 765155:tid 765288] [client 20.63.98.115:32938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:53.470948 2026] [core:error] [pid 765155:tid 765288] [client 20.63.98.115:32938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:53.605812 2026] [core:notice] [pid 765155:tid 765404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:53.609951 2026] [security2:error] [pid 765155:tid 765404] [client 103.215.74.26:45702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMaeT5hFAbD-LhWHikrwAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:53.674495 2026] [core:notice] [pid 765155:tid 765245] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:53.814022 2026] [security2:error] [pid 765155:tid 765411] [client 20.215.191.139:2974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuMaeT5hFAbD-LhWHiktwAAAQM"]
[Thu Jul 30 12:39:53.925172 2026] [security2:error] [pid 765155:tid 765313] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMaeT5hFAbD-LhWHikuwAAoV0"]
[Thu Jul 30 12:39:54.096861 2026] [core:error] [pid 765155:tid 765333] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:54.096885 2026] [core:error] [pid 765155:tid 765333] [client 156.229.16.165:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:39:54.337836 2026] [core:notice] [pid 765155:tid 765365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:54.348667 2026] [security2:error] [pid 765155:tid 765365] [client 103.215.74.26:45718] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMauT5hFAbD-LhWHik0AAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:54.588497 2026] [security2:error] [pid 765155:tid 765330] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMauT5hFAbD-LhWHik1wAAsmg"]
[Thu Jul 30 12:39:54.679785 2026] [security2:error] [pid 765155:tid 765306] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMauT5hFAbD-LhWHikwwAAAJo"]
[Thu Jul 30 12:39:54.795417 2026] [security2:error] [pid 765155:tid 765390] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMauT5hFAbD-LhWHikyQAAAO4"]
[Thu Jul 30 12:39:55.099756 2026] [core:notice] [pid 765155:tid 765381] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:55.106506 2026] [security2:error] [pid 765155:tid 765381] [client 103.215.74.26:45732] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMa-T5hFAbD-LhWHik6QAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:55.231143 2026] [security2:error] [pid 765155:tid 765287] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMa-T5hFAbD-LhWHik6gAAhz8"]
[Thu Jul 30 12:39:55.251285 2026] [security2:error] [pid 765155:tid 765334] [client 20.215.191.139:13179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuMa-T5hFAbD-LhWHik6wAAALY"]
[Thu Jul 30 12:39:55.706169 2026] [security2:error] [pid 765155:tid 765261] [remote 57.141.0.69:46530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55276018792/feed/rss2/"] [unique_id "amuMa-T5hFAbD-LhWHilAQAAyGk"]
[Thu Jul 30 12:39:55.746301 2026] [security2:error] [pid 765155:tid 765402] [client 69.158.246.168:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuMa-T5hFAbD-LhWHilAAAA-hU"]
[Thu Jul 30 12:39:55.839326 2026] [core:notice] [pid 765155:tid 765407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:55.843329 2026] [security2:error] [pid 765155:tid 765407] [client 103.215.74.26:45738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMa-T5hFAbD-LhWHilCAAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:55.866113 2026] [security2:error] [pid 765155:tid 765349] [client 20.215.191.139:31292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/alfa-rex.php7"] [unique_id "amuMa-T5hFAbD-LhWHilCQAAAMU"]
[Thu Jul 30 12:39:55.943385 2026] [security2:error] [pid 765155:tid 765359] [client 20.63.98.115:21091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/pomo/fgertreyersd.php"] [unique_id "amuMa-T5hFAbD-LhWHilDgAAAM8"]
[Thu Jul 30 12:39:56.542652 2026] [security2:error] [pid 765155:tid 765330] [client 38.190.144.4:58850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMbOT5hFAbD-LhWHilKQAAALI"]
[Thu Jul 30 12:39:56.542861 2026] [security2:error] [pid 765155:tid 765330] [client 38.190.144.4:58850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMbOT5hFAbD-LhWHilKQAAALI"]
[Thu Jul 30 12:39:56.594186 2026] [core:notice] [pid 765155:tid 765337] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:56.601244 2026] [security2:error] [pid 765155:tid 765337] [client 103.215.74.26:45754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "777"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMbOT5hFAbD-LhWHilKgAAALk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:56.896605 2026] [security2:error] [pid 765155:tid 765363] [client 172.236.9.101:39355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilGwAAANM"]
[Thu Jul 30 12:39:56.896605 2026] [security2:error] [pid 765155:tid 765403] [client 172.236.9.101:31578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilGAAAAPs"]
[Thu Jul 30 12:39:57.008785 2026] [security2:error] [pid 765155:tid 765390] [client 172.236.9.101:58060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilHQAAAO4"]
[Thu Jul 30 12:39:57.018388 2026] [security2:error] [pid 765155:tid 765299] [client 172.236.9.101:27392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilHwAAAJM"]
[Thu Jul 30 12:39:57.022802 2026] [security2:error] [pid 765155:tid 765369] [client 172.236.9.101:64491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMbOT5hFAbD-LhWHilHgAAANk"]
[Thu Jul 30 12:39:57.069183 2026] [security2:error] [pid 765155:tid 765339] [client 20.63.98.115:32912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/css/xmrlpc.php"] [unique_id "amuMbeT5hFAbD-LhWHilOAAAALs"]
[Thu Jul 30 12:39:57.331680 2026] [core:notice] [pid 765155:tid 765291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:57.338643 2026] [security2:error] [pid 765155:tid 765291] [client 103.215.74.26:45762] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMbeT5hFAbD-LhWHilOQAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:57.516714 2026] [security2:error] [pid 765155:tid 765400] [client 20.100.187.246:61558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/files.php"] [unique_id "amuMbeT5hFAbD-LhWHilRwAAAPg"]
[Thu Jul 30 12:39:57.523877 2026] [autoindex:error] [pid 765155:tid 765296] [client 43.134.163.229:0] AH01276: Cannot serve directory /home2/mbmudite/ok.otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.otbola.click
[Thu Jul 30 12:39:57.967242 2026] [security2:error] [pid 765155:tid 765319] [client 20.215.191.139:2399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/alfanew.php"] [unique_id "amuMbeT5hFAbD-LhWHilUgAAAKc"]
[Thu Jul 30 12:39:58.062742 2026] [core:notice] [pid 765155:tid 765379] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:58.066648 2026] [security2:error] [pid 765155:tid 765379] [client 103.215.74.26:45764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "790"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMbuT5hFAbD-LhWHilVgAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:58.376911 2026] [security2:error] [pid 765155:tid 765308] [client 20.63.98.115:21077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/classsmtps.php"] [unique_id "amuMbuT5hFAbD-LhWHilWQAAAJw"]
[Thu Jul 30 12:39:58.410867 2026] [security2:error] [pid 765155:tid 765381] [client 150.107.232.194:27215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMbuT5hFAbD-LhWHilWwAAAOU"]
[Thu Jul 30 12:39:58.411032 2026] [security2:error] [pid 765155:tid 765381] [client 150.107.232.194:27215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMbuT5hFAbD-LhWHilWwAAAOU"]
[Thu Jul 30 12:39:58.786655 2026] [core:notice] [pid 765155:tid 765350] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:58.790401 2026] [security2:error] [pid 765155:tid 765350] [client 103.215.74.26:45770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMbuT5hFAbD-LhWHilZwAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:59.303011 2026] [security2:error] [pid 765155:tid 765286] [client 47.128.27.194:27720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuMb-T5hFAbD-LhWHilewAAAIY"]
[Thu Jul 30 12:39:59.521586 2026] [core:notice] [pid 765155:tid 765300] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:39:59.525519 2026] [security2:error] [pid 765155:tid 765300] [client 103.215.74.26:45776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMb-T5hFAbD-LhWHilhwAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:39:59.739169 2026] [security2:error] [pid 765155:tid 765362] [client 139.28.219.70:41490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuMb-T5hFAbD-LhWHiljgAAANI"]
[Thu Jul 30 12:39:59.814179 2026] [security2:error] [pid 765155:tid 765407] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMb-T5hFAbD-LhWHilegAAAP8"]
[Thu Jul 30 12:39:59.824674 2026] [security2:error] [pid 765155:tid 765299] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMb-T5hFAbD-LhWHildgAAkwU"]
[Thu Jul 30 12:39:59.885330 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:12256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMb-T5hFAbD-LhWHilfgAAAOI"]
[Thu Jul 30 12:40:00.017374 2026] [security2:error] [pid 765155:tid 765356] [client 20.100.187.246:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/gecko.php"] [unique_id "amuMcOT5hFAbD-LhWHillQAAAMw"]
[Thu Jul 30 12:40:00.076588 2026] [security2:error] [pid 765155:tid 765369] [client 20.63.98.115:39100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/themes/zMousse/otuz1.php"] [unique_id "amuMcOT5hFAbD-LhWHilmQAAANk"]
[Thu Jul 30 12:40:00.139125 2026] [security2:error] [pid 765155:tid 765408] [client 139.28.219.70:41506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "google-search.org"] [uri "/xmlrpc.php"] [unique_id "amuMcOT5hFAbD-LhWHilmgAAAQA"]
[Thu Jul 30 12:40:00.262142 2026] [core:notice] [pid 765155:tid 765385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:00.266058 2026] [security2:error] [pid 765155:tid 765385] [client 103.215.74.26:45792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "769"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMcOT5hFAbD-LhWHilogAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:00.872969 2026] [security2:error] [pid 765155:tid 765316] [client 172.236.9.101:12877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMcOT5hFAbD-LhWHilowAAAKQ"]
[Thu Jul 30 12:40:00.898553 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:25932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMcOT5hFAbD-LhWHilpQAAALk"]
[Thu Jul 30 12:40:00.962854 2026] [security2:error] [pid 765155:tid 765292] [client 172.236.9.101:58391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMcOT5hFAbD-LhWHilpAAAAIw"]
[Thu Jul 30 12:40:00.986247 2026] [core:notice] [pid 765155:tid 765305] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:00.993665 2026] [security2:error] [pid 765155:tid 765305] [client 103.215.74.26:45798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMcOT5hFAbD-LhWHilugAAAJk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:01.015661 2026] [security2:error] [pid 765155:tid 765374] [client 172.236.9.101:51758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMcOT5hFAbD-LhWHilpgAAAN4"]
[Thu Jul 30 12:40:01.086191 2026] [security2:error] [pid 765155:tid 765302] [client 139.28.219.70:41518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuMceT5hFAbD-LhWHilwQAAAJY"]
[Thu Jul 30 12:40:01.288336 2026] [core:error] [pid 765155:tid 765163] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/
[Thu Jul 30 12:40:01.288361 2026] [core:error] [pid 765155:tid 765163] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/
[Thu Jul 30 12:40:01.396038 2026] [security2:error] [pid 765155:tid 765383] [client 139.28.219.70:45732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuMceT5hFAbD-LhWHilzgAAAOc"]
[Thu Jul 30 12:40:01.679470 2026] [security2:error] [pid 765155:tid 765381] [client 139.28.219.70:45744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuMceT5hFAbD-LhWHil2wAAAOU"]
[Thu Jul 30 12:40:01.716958 2026] [core:notice] [pid 765155:tid 765314] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:01.721035 2026] [security2:error] [pid 765155:tid 765314] [client 103.215.74.26:45804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMceT5hFAbD-LhWHil3AAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:01.780787 2026] [core:error] [pid 765155:tid 765336] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.780810 2026] [core:error] [pid 765155:tid 765336] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.814916 2026] [core:error] [pid 765155:tid 765391] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.814939 2026] [core:error] [pid 765155:tid 765391] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.838432 2026] [core:error] [pid 765155:tid 765404] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.838455 2026] [core:error] [pid 765155:tid 765404] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.941738 2026] [security2:error] [pid 765155:tid 765350] [client 139.28.219.70:45748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuMceT5hFAbD-LhWHil8wAAAMY"]
[Thu Jul 30 12:40:01.944498 2026] [core:error] [pid 765155:tid 765373] [client 158.69.117.45:20957] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:01.944516 2026] [core:error] [pid 765155:tid 765373] [client 158.69.117.45:20957] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.070507 2026] [security2:error] [pid 765155:tid 765403] [client 156.59.105.1:65163] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "jesus.claims"] [uri "/wp-json/batch/v1"] [unique_id "amuMcuT5hFAbD-LhWHil9wAAAPs"]
[Thu Jul 30 12:40:02.302746 2026] [security2:error] [pid 765155:tid 765358] [client 139.28.219.70:45754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuMcuT5hFAbD-LhWHimAgAAAM4"]
[Thu Jul 30 12:40:02.364241 2026] [security2:error] [pid 765155:tid 765347] [client 20.100.187.246:33127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/zwso.php"] [unique_id "amuMcuT5hFAbD-LhWHimAwAAAMM"]
[Thu Jul 30 12:40:02.469419 2026] [core:notice] [pid 765155:tid 765302] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:02.473392 2026] [security2:error] [pid 765155:tid 765302] [client 103.215.74.26:45816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMcuT5hFAbD-LhWHimBQAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:02.614268 2026] [security2:error] [pid 765155:tid 765354] [client 139.28.219.70:45762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuMcuT5hFAbD-LhWHimCAAAAMo"]
[Thu Jul 30 12:40:02.766411 2026] [core:error] [pid 765155:tid 765296] [client 158.69.117.45:20164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.766444 2026] [core:error] [pid 765155:tid 765296] [client 158.69.117.45:20164] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.901359 2026] [core:error] [pid 765155:tid 765330] [client 158.69.117.45:23083] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.901387 2026] [core:error] [pid 765155:tid 765330] [client 158.69.117.45:23083] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:02.906623 2026] [security2:error] [pid 765155:tid 765393] [client 139.28.219.70:45774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuMcuT5hFAbD-LhWHimFQAAAPE"]
[Thu Jul 30 12:40:03.185177 2026] [core:notice] [pid 765155:tid 765410] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:03.192104 2026] [security2:error] [pid 765155:tid 765410] [client 103.215.74.26:2126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMc-T5hFAbD-LhWHimIwAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:03.196463 2026] [proxy:error] [pid 765155:tid 765372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:03.196523 2026] [proxy_http:error] [pid 765155:tid 765372] [client 3.225.222.228:29297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:03.197345 2026] [proxy:error] [pid 765155:tid 765372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:03.197402 2026] [proxy_http:error] [pid 765155:tid 765372] [client 3.225.222.228:29297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:03.219022 2026] [security2:error] [pid 765155:tid 765373] [client 139.28.219.70:45776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuMc-T5hFAbD-LhWHimKAAAAN0"]
[Thu Jul 30 12:40:03.252585 2026] [proxy:error] [pid 765155:tid 765334] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:03.252680 2026] [proxy_http:error] [pid 765155:tid 765334] [client 3.225.222.228:15037] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:03.253265 2026] [proxy:error] [pid 765155:tid 765334] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:03.253319 2026] [proxy_http:error] [pid 765155:tid 765334] [client 3.225.222.228:15037] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:03.303865 2026] [security2:error] [pid 765155:tid 765362] [client 20.63.98.115:61424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/123.php"] [unique_id "amuMc-T5hFAbD-LhWHimMQAAANI"]
[Thu Jul 30 12:40:03.545440 2026] [security2:error] [pid 765155:tid 765412] [client 139.28.219.70:45788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuMc-T5hFAbD-LhWHimNQAAAQQ"]
[Thu Jul 30 12:40:03.634042 2026] [core:error] [pid 765155:tid 765298] [client 158.69.117.45:40399] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:03.634073 2026] [core:error] [pid 765155:tid 765298] [client 158.69.117.45:40399] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:03.873992 2026] [security2:error] [pid 765155:tid 765291] [client 20.100.187.246:33473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/13.php"] [unique_id "amuMc-T5hFAbD-LhWHimSQAAAIs"]
[Thu Jul 30 12:40:03.889859 2026] [security2:error] [pid 765155:tid 765401] [client 139.28.219.70:45792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuMc-T5hFAbD-LhWHimSgAAAPk"]
[Thu Jul 30 12:40:04.233629 2026] [security2:error] [pid 765155:tid 765379] [client 139.28.219.70:45808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuMdOT5hFAbD-LhWHimVAAAAOM"]
[Thu Jul 30 12:40:04.556676 2026] [security2:error] [pid 765155:tid 765340] [client 139.28.219.70:45810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuMdOT5hFAbD-LhWHimWwAAALw"]
[Thu Jul 30 12:40:04.782501 2026] [security2:error] [pid 765155:tid 765388] [client 20.215.191.139:31229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuMdOT5hFAbD-LhWHimXwAAAOw"]
[Thu Jul 30 12:40:04.855516 2026] [security2:error] [pid 765155:tid 765314] [client 20.100.187.246:59101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/ava.php"] [unique_id "amuMdOT5hFAbD-LhWHimYAAAAKI"]
[Thu Jul 30 12:40:04.883562 2026] [security2:error] [pid 765155:tid 765350] [client 139.28.219.70:45826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuMdOT5hFAbD-LhWHimYQAAAMY"]
[Thu Jul 30 12:40:04.910706 2026] [core:notice] [pid 765155:tid 765384] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:05.191957 2026] [security2:error] [pid 765155:tid 765356] [client 139.28.219.70:45840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "google-search.org"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuMdeT5hFAbD-LhWHimbAAAAMw"]
[Thu Jul 30 12:40:05.442264 2026] [security2:error] [pid 765155:tid 765403] [client 20.215.191.139:33601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuMdeT5hFAbD-LhWHimeAAAAPs"]
[Thu Jul 30 12:40:05.450897 2026] [core:notice] [pid 765155:tid 765243] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:05.792495 2026] [security2:error] [pid 765155:tid 765248] [remote 57.141.0.37:42446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuMdeT5hFAbD-LhWHimigAAkFw"]
[Thu Jul 30 12:40:05.913684 2026] [security2:error] [pid 765155:tid 765339] [client 172.236.9.101:44283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimcAAAALs"]
[Thu Jul 30 12:40:05.931147 2026] [security2:error] [pid 765155:tid 765313] [client 20.63.98.115:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuMdeT5hFAbD-LhWHimiwAAAKE"]
[Thu Jul 30 12:40:05.945847 2026] [security2:error] [pid 765155:tid 765310] [client 172.236.9.101:45146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimcQAAAJ4"]
[Thu Jul 30 12:40:05.980287 2026] [security2:error] [pid 765155:tid 765322] [client 172.236.9.101:23233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimdgAAAKo"]
[Thu Jul 30 12:40:06.002218 2026] [security2:error] [pid 765155:tid 765337] [client 172.236.9.101:54666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimdQAAALk"]
[Thu Jul 30 12:40:06.034388 2026] [security2:error] [pid 765155:tid 765397] [client 172.236.9.101:23726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimdwAAAPU"]
[Thu Jul 30 12:40:06.217838 2026] [security2:error] [pid 765155:tid 765392] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMdeT5hFAbD-LhWHimhQAAAPA"]
[Thu Jul 30 12:40:06.282893 2026] [security2:error] [pid 765155:tid 765319] [client 20.215.191.139:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-p.php7"] [unique_id "amuMduT5hFAbD-LhWHimlQAAAKc"]
[Thu Jul 30 12:40:06.426144 2026] [security2:error] [pid 765155:tid 765318] [client 20.100.187.246:61468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/main.php"] [unique_id "amuMduT5hFAbD-LhWHimmgAAAKY"]
[Thu Jul 30 12:40:06.577935 2026] [core:notice] [pid 765155:tid 765378] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:06.581911 2026] [security2:error] [pid 765155:tid 765378] [client 23.95.131.140:39307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/citationstylelanguage/download/bibtex"] [unique_id "amuMduT5hFAbD-LhWHimmQAAAOI"]
[Thu Jul 30 12:40:06.669908 2026] [autoindex:error] [pid 765155:tid 765316] [client 23.94.133.71:49542] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:40:06.806767 2026] [core:notice] [pid 765155:tid 765362] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:07.328028 2026] [security2:error] [pid 765155:tid 765406] [client 38.190.144.4:59403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMd-T5hFAbD-LhWHimtwAAAP4"]
[Thu Jul 30 12:40:07.330180 2026] [security2:error] [pid 765155:tid 765406] [client 38.190.144.4:59403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMd-T5hFAbD-LhWHimtwAAAP4"]
[Thu Jul 30 12:40:07.368858 2026] [security2:error] [pid 765155:tid 765344] [client 20.215.191.139:11847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuMd-T5hFAbD-LhWHimugAAAMA"]
[Thu Jul 30 12:40:07.945706 2026] [security2:error] [pid 765155:tid 765327] [client 150.107.232.194:27043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMd-T5hFAbD-LhWHimzAAAAK8"]
[Thu Jul 30 12:40:07.945865 2026] [security2:error] [pid 765155:tid 765327] [client 150.107.232.194:27043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMd-T5hFAbD-LhWHimzAAAAK8"]
[Thu Jul 30 12:40:07.952615 2026] [security2:error] [pid 765155:tid 765259] [remote 97.74.87.194:44804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuMd-T5hFAbD-LhWHimzQAAvWc"]
[Thu Jul 30 12:40:08.177602 2026] [security2:error] [pid 765155:tid 765375] [client 150.109.119.38:48554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.119.109.150.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/theme/darm_theme_basic01/page_html/company_vision.php"] [unique_id "amuMeOT5hFAbD-LhWHim1wAAAN8"]
[Thu Jul 30 12:40:08.899122 2026] [security2:error] [pid 765155:tid 765384] [client 20.215.191.139:6329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuMeOT5hFAbD-LhWHim6QAAAOg"]
[Thu Jul 30 12:40:08.966581 2026] [core:notice] [pid 765155:tid 765334] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:08.970946 2026] [security2:error] [pid 765155:tid 765334] [client 103.215.74.26:2132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMeOT5hFAbD-LhWHim7gAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:09.045234 2026] [security2:error] [pid 765155:tid 765353] [client 20.100.187.246:33120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wp-file.php"] [unique_id "amuMeeT5hFAbD-LhWHim8gAAAMk"]
[Thu Jul 30 12:40:09.703726 2026] [core:notice] [pid 765155:tid 765303] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:09.707869 2026] [security2:error] [pid 765155:tid 765303] [client 103.215.74.26:2134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMeeT5hFAbD-LhWHinBgAAAJc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:09.736849 2026] [security2:error] [pid 765155:tid 765365] [client 20.215.191.139:12125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nordeste1.com"] [uri "/wp-content/repeater.php"] [unique_id "amuMeeT5hFAbD-LhWHinCAAAANU"]
[Thu Jul 30 12:40:09.929872 2026] [core:error] [pid 765155:tid 765389] [client 20.63.98.115:54561] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:09.929897 2026] [core:error] [pid 765155:tid 765389] [client 20.63.98.115:54561] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:10.446470 2026] [core:notice] [pid 765155:tid 765294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:10.450863 2026] [security2:error] [pid 765155:tid 765294] [client 103.215.74.26:2148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMeuT5hFAbD-LhWHinGwAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:11.177986 2026] [core:notice] [pid 765155:tid 765348] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:11.183923 2026] [security2:error] [pid 765155:tid 765348] [client 103.215.74.26:2160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMe-T5hFAbD-LhWHinMgAAAMQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:11.311512 2026] [core:notice] [pid 765155:tid 765368] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:11.766387 2026] [security2:error] [pid 765155:tid 765367] [client 20.63.98.115:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/filebrowser.php"] [unique_id "amuMe-T5hFAbD-LhWHinQAAAANc"]
[Thu Jul 30 12:40:11.911133 2026] [core:notice] [pid 765155:tid 765306] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:11.915374 2026] [security2:error] [pid 765155:tid 765306] [client 103.215.74.26:2162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMe-T5hFAbD-LhWHinSAAAAJo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:12.377499 2026] [security2:error] [pid 765155:tid 765370] [client 74.7.175.130:55144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.voyagegetaways.com.met.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuMfOT5hFAbD-LhWHinWQAA2hg"]
[Thu Jul 30 12:40:12.400959 2026] [security2:error] [pid 765155:tid 765212] [remote 74.7.241.60:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuMfOT5hFAbD-LhWHinWgAA8zg"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:40:12.642806 2026] [core:notice] [pid 765155:tid 765311] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:12.647437 2026] [security2:error] [pid 765155:tid 765311] [client 103.215.74.26:2166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfOT5hFAbD-LhWHinYgAAAJ8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:12.705061 2026] [security2:error] [pid 765155:tid 765364] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMfOT5hFAbD-LhWHinTwAA1C8"]
[Thu Jul 30 12:40:12.897972 2026] [security2:error] [pid 765155:tid 765382] [client 49.13.164.148:38666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuMfOT5hFAbD-LhWHinbAAAAOY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:40:12.912316 2026] [security2:error] [pid 765155:tid 765328] [client 20.100.187.246:44091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wp-signin.php"] [unique_id "amuMfOT5hFAbD-LhWHinbQAAALA"]
[Thu Jul 30 12:40:13.163446 2026] [autoindex:error] [pid 765155:tid 765204] [remote 74.7.227.25:49252] AH01276: Cannot serve directory /home1/metnyxte/voyagegetaways.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:40:13.292680 2026] [core:notice] [pid 765155:tid 765406] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:13.297056 2026] [security2:error] [pid 765155:tid 765406] [client 49.13.164.148:38682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfeT5hFAbD-LhWHineAAAAP4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:40:13.387905 2026] [core:notice] [pid 765155:tid 765332] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:13.392093 2026] [security2:error] [pid 765155:tid 765332] [client 103.215.74.26:48364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfeT5hFAbD-LhWHinfgAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:13.733629 2026] [security2:error] [pid 765155:tid 765391] [client 49.13.164.148:38696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuMfeT5hFAbD-LhWHinlAAAAO8"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:40:13.765731 2026] [security2:error] [pid 765155:tid 765349] [client 20.63.98.115:39069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/makeasmtp.php"] [unique_id "amuMfeT5hFAbD-LhWHinlQAAAMU"]
[Thu Jul 30 12:40:13.902791 2026] [security2:error] [pid 765155:tid 765299] [client 65.20.159.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMfeT5hFAbD-LhWHincgAAkzQ"], referer: https://allmontecristi.com
[Thu Jul 30 12:40:14.128537 2026] [core:notice] [pid 765155:tid 765383] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:14.136152 2026] [security2:error] [pid 765155:tid 765383] [client 103.215.74.26:48368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfuT5hFAbD-LhWHinoAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:14.542047 2026] [core:notice] [pid 765155:tid 765172] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:14.634963 2026] [core:error] [pid 765155:tid 765380] [client 74.7.241.169:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:14.635020 2026] [core:error] [pid 765155:tid 765380] [client 74.7.241.169:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:14.635176 2026] [security2:error] [pid 765155:tid 765380] [client 74.7.241.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.yne.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuMfuT5hFAbD-LhWHin8QAAAOQ"]
[Thu Jul 30 12:40:14.635831 2026] [security2:error] [pid 765155:tid 765342] [client 74.7.241.169:43314] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.yne.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuMfuT5hFAbD-LhWHin7wAAvnk"]
[Thu Jul 30 12:40:14.854533 2026] [core:notice] [pid 765155:tid 765354] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:14.858697 2026] [security2:error] [pid 765155:tid 765354] [client 103.215.74.26:48370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMfuT5hFAbD-LhWHioBAAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:14.868526 2026] [security2:error] [pid 765155:tid 765357] [client 172.236.9.101:29878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMfuT5hFAbD-LhWHinrwAAAM0"]
[Thu Jul 30 12:40:15.567458 2026] [security2:error] [pid 765155:tid 765314] [client 20.63.98.115:36857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/bypass.php"] [unique_id "amuMf-T5hFAbD-LhWHioJAAAAKI"]
[Thu Jul 30 12:40:15.582732 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:15.586757 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:48382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMf-T5hFAbD-LhWHioJQAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:15.921698 2026] [security2:error] [pid 765155:tid 765355] [client 172.236.9.101:50453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMf-T5hFAbD-LhWHioGgAAAMs"]
[Thu Jul 30 12:40:15.965812 2026] [security2:error] [pid 765155:tid 765287] [client 172.236.9.101:18575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMf-T5hFAbD-LhWHioGwAAAIc"]
[Thu Jul 30 12:40:16.004269 2026] [security2:error] [pid 765155:tid 765405] [client 172.236.9.101:48400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMf-T5hFAbD-LhWHioHgAAAP0"]
[Thu Jul 30 12:40:16.022786 2026] [security2:error] [pid 765155:tid 765315] [client 172.236.9.101:9811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMf-T5hFAbD-LhWHioHQAAAKM"]
[Thu Jul 30 12:40:16.088808 2026] [core:notice] [pid 765155:tid 765348] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:16.485412 2026] [security2:error] [pid 765155:tid 765286] [client 185.191.171.8:63426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/12/mari-apos-pressao-e-ameaca-de-greve-prefeitura-anuncia-reajuste-para-os-professores-e-retroativo-de-janeiro/"] [unique_id "amuMgOT5hFAbD-LhWHioQQAAAIY"]
[Thu Jul 30 12:40:16.485600 2026] [security2:error] [pid 765155:tid 765286] [client 185.191.171.8:63426] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/12/mari-apos-pressao-e-ameaca-de-greve-prefeitura-anuncia-reajuste-para-os-professores-e-retroativo-de-janeiro/"] [unique_id "amuMgOT5hFAbD-LhWHioQQAAAIY"]
[Thu Jul 30 12:40:16.630568 2026] [core:notice] [pid 765155:tid 765285] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:17.065883 2026] [security2:error] [pid 765155:tid 765317] [client 20.100.187.246:33909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/simi.php"] [unique_id "amuMgeT5hFAbD-LhWHioUwAAAKU"]
[Thu Jul 30 12:40:17.485168 2026] [core:error] [pid 765155:tid 765346] [client 40.77.167.219:22156] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:17.485192 2026] [core:error] [pid 765155:tid 765346] [client 40.77.167.219:22156] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:17.637000 2026] [security2:error] [pid 765155:tid 765366] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuMgeT5hFAbD-LhWHiobgAAANY"]
[Thu Jul 30 12:40:17.875153 2026] [security2:error] [pid 765155:tid 765378] [client 172.236.9.101:62084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMgeT5hFAbD-LhWHioYQAAAOI"]
[Thu Jul 30 12:40:17.878082 2026] [security2:error] [pid 765155:tid 765323] [client 172.236.9.101:32991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMgeT5hFAbD-LhWHioYgAAAKs"]
[Thu Jul 30 12:40:17.926391 2026] [security2:error] [pid 765155:tid 765325] [client 172.236.9.101:58505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMgeT5hFAbD-LhWHioZAAAAK0"]
[Thu Jul 30 12:40:17.930296 2026] [security2:error] [pid 765155:tid 765331] [client 172.236.9.101:49636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMgeT5hFAbD-LhWHioYwAAALM"]
[Thu Jul 30 12:40:17.981659 2026] [security2:error] [pid 765155:tid 765365] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMgeT5hFAbD-LhWHioYAAAANU"]
[Thu Jul 30 12:40:18.042487 2026] [security2:error] [pid 765155:tid 765372] [client 172.236.9.101:22138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMgeT5hFAbD-LhWHioZgAAANw"]
[Thu Jul 30 12:40:18.077361 2026] [security2:error] [pid 765155:tid 765340] [client 20.100.187.246:33520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/wp-conf.php"] [unique_id "amuMguT5hFAbD-LhWHiogQAAALw"]
[Thu Jul 30 12:40:18.151902 2026] [security2:error] [pid 765155:tid 765338] [client 20.63.98.115:39098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/pi.php"] [unique_id "amuMguT5hFAbD-LhWHiogwAAALo"]
[Thu Jul 30 12:40:18.247096 2026] [security2:error] [pid 765155:tid 765387] [client 45.154.98.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.98.154.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tranquilrootsisb.space"] [uri "/xmlrpc.php"] [unique_id "amuMgeT5hFAbD-LhWHioeQAAAOs"]
[Thu Jul 30 12:40:18.431134 2026] [security2:error] [pid 765155:tid 765334] [client 38.190.144.4:59917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMguT5hFAbD-LhWHiokgAAALY"]
[Thu Jul 30 12:40:18.431510 2026] [security2:error] [pid 765155:tid 765334] [client 38.190.144.4:59917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMguT5hFAbD-LhWHiokgAAALY"]
[Thu Jul 30 12:40:18.439702 2026] [security2:error] [pid 765155:tid 765411] [client 150.107.232.194:27311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMguT5hFAbD-LhWHiokwAAAQM"]
[Thu Jul 30 12:40:18.439823 2026] [security2:error] [pid 765155:tid 765411] [client 150.107.232.194:27311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMguT5hFAbD-LhWHiokwAAAQM"]
[Thu Jul 30 12:40:18.531873 2026] [core:notice] [pid 765155:tid 765200] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:18.807489 2026] [security2:error] [pid 765155:tid 765384] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuMguT5hFAbD-LhWHiooQAAAOg"]
[Thu Jul 30 12:40:18.957392 2026] [security2:error] [pid 765155:tid 765333] [client 20.100.187.246:59135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuMguT5hFAbD-LhWHiopQAAALU"]
[Thu Jul 30 12:40:19.152150 2026] [security2:error] [pid 765155:tid 765303] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuMg-T5hFAbD-LhWHiorgAAAJc"]
[Thu Jul 30 12:40:19.499420 2026] [security2:error] [pid 765155:tid 765312] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuMg-T5hFAbD-LhWHiotQAAAKA"]
[Thu Jul 30 12:40:19.610411 2026] [security2:error] [pid 765155:tid 765358] [client 183.171.242.67:43900] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuMg-T5hFAbD-LhWHiouQAAAM4"]
[Thu Jul 30 12:40:19.725213 2026] [security2:error] [pid 765155:tid 765403] [client 45.190.187.240:53272] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuMg-T5hFAbD-LhWHiovQAAAPs"]
[Thu Jul 30 12:40:19.845994 2026] [security2:error] [pid 765155:tid 765313] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuMg-T5hFAbD-LhWHiovgAAAKE"]
[Thu Jul 30 12:40:19.966153 2026] [security2:error] [pid 765155:tid 765340] [client 88.246.106.81:40914] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuMg-T5hFAbD-LhWHioxQAAALw"]
[Thu Jul 30 12:40:19.966153 2026] [security2:error] [pid 765155:tid 765402] [client 38.51.123.152:52752] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuMg-T5hFAbD-LhWHioxgAAAPo"]
[Thu Jul 30 12:40:19.979828 2026] [security2:error] [pid 765155:tid 765347] [client 84.33.149.175:17517] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuMg-T5hFAbD-LhWHioxwAAAMM"]
[Thu Jul 30 12:40:20.184891 2026] [security2:error] [pid 765155:tid 765339] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuMhOT5hFAbD-LhWHiozwAAALs"]
[Thu Jul 30 12:40:20.311384 2026] [security2:error] [pid 765155:tid 765376] [client 20.63.98.115:63370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-seo.php"] [unique_id "amuMhOT5hFAbD-LhWHio0gAAAOA"]
[Thu Jul 30 12:40:20.353622 2026] [security2:error] [pid 765155:tid 765286] [client 189.238.0.70:54078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuMhOT5hFAbD-LhWHio0wAAAIY"]
[Thu Jul 30 12:40:20.481750 2026] [security2:error] [pid 765155:tid 765329] [client 102.208.63.122:44246] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuMhOT5hFAbD-LhWHio3wAAALE"]
[Thu Jul 30 12:40:20.521793 2026] [security2:error] [pid 765155:tid 765396] [client 43.172.198.201:54548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/11/25/black-friday-chez-oysho-20-sur-tout-le-site-et-livraison-offerte/"] [unique_id "amuMhOT5hFAbD-LhWHio0AAAAPQ"]
[Thu Jul 30 12:40:20.536123 2026] [security2:error] [pid 765155:tid 765353] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuMhOT5hFAbD-LhWHio4QAAAMk"]
[Thu Jul 30 12:40:20.593233 2026] [security2:error] [pid 765155:tid 765367] [client 102.220.20.56:53816] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuMhOT5hFAbD-LhWHio6QAAANc"]
[Thu Jul 30 12:40:20.728329 2026] [security2:error] [pid 765155:tid 765298] [client 20.100.187.246:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/bala.php"] [unique_id "amuMhOT5hFAbD-LhWHio7AAAAJI"]
[Thu Jul 30 12:40:20.847413 2026] [security2:error] [pid 765155:tid 765256] [remote 57.141.0.23:43550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/66526086350/feed/rss2/"] [unique_id "amuMhOT5hFAbD-LhWHio5wAAnWQ"]
[Thu Jul 30 12:40:20.890457 2026] [security2:error] [pid 765155:tid 765291] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuMhOT5hFAbD-LhWHio8gAAAIs"]
[Thu Jul 30 12:40:20.991462 2026] [core:notice] [pid 765155:tid 765310] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:20.996073 2026] [security2:error] [pid 765155:tid 765310] [client 43.173.174.168:55002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/11/25/black-friday-chez-oysho-20-sur-tout-le-site-et-livraison-offerte/"] [unique_id "amuMhOT5hFAbD-LhWHio9gAAAJ4"], referer: https://carnetdeshopping.com/index.php/2011/11/25/black-friday-chez-oysho-20-sur-tout-le-site-et-livraison-offerte/
[Thu Jul 30 12:40:21.187521 2026] [security2:error] [pid 765155:tid 765380] [client 186.1.185.81:11346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuMheT5hFAbD-LhWHio_gAAAOQ"]
[Thu Jul 30 12:40:21.237521 2026] [security2:error] [pid 765155:tid 765326] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuMheT5hFAbD-LhWHipAAAAAK4"]
[Thu Jul 30 12:40:21.261299 2026] [security2:error] [pid 765155:tid 765341] [client 20.63.98.115:62322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gebase.php69"] [unique_id "amuMheT5hFAbD-LhWHipAQAAAL0"]
[Thu Jul 30 12:40:21.361628 2026] [core:notice] [pid 765155:tid 765370] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:21.365654 2026] [security2:error] [pid 765155:tid 765370] [client 103.215.74.26:48386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMheT5hFAbD-LhWHipAgAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:21.577383 2026] [security2:error] [pid 765155:tid 765394] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuMheT5hFAbD-LhWHipCgAAAPI"]
[Thu Jul 30 12:40:21.913384 2026] [security2:error] [pid 765155:tid 765302] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuMheT5hFAbD-LhWHipFgAAAJY"]
[Thu Jul 30 12:40:21.930332 2026] [security2:error] [pid 765155:tid 765391] [client 103.152.101.204:55672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuMheT5hFAbD-LhWHipGAAAAO8"]
[Thu Jul 30 12:40:21.987469 2026] [security2:error] [pid 765155:tid 765286] [client 118.194.234.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jta.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuMheT5hFAbD-LhWHipEAAAAIY"]
[Thu Jul 30 12:40:22.087895 2026] [core:notice] [pid 765155:tid 765355] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:22.091923 2026] [security2:error] [pid 765155:tid 765355] [client 103.215.74.26:48402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMhuT5hFAbD-LhWHipIAAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:22.145220 2026] [security2:error] [pid 765155:tid 765337] [client 151.52.72.173:59300] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.woff"] [unique_id "amuMhuT5hFAbD-LhWHipJQAAALk"]
[Thu Jul 30 12:40:22.264858 2026] [security2:error] [pid 765155:tid 765298] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuMhuT5hFAbD-LhWHipJwAAAJI"]
[Thu Jul 30 12:40:22.571606 2026] [security2:error] [pid 765155:tid 765410] [client 190.103.245.245:51952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuMhuT5hFAbD-LhWHipMwAAAQI"]
[Thu Jul 30 12:40:22.609929 2026] [security2:error] [pid 765155:tid 765387] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuMhuT5hFAbD-LhWHipNwAAAOs"]
[Thu Jul 30 12:40:22.762067 2026] [security2:error] [pid 765155:tid 765407] [client 62.102.148.158:52024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuMhuT5hFAbD-LhWHipPQAAAP8"]
[Thu Jul 30 12:40:22.762170 2026] [security2:error] [pid 765155:tid 765407] [client 62.102.148.158:52024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuMhuT5hFAbD-LhWHipPQAAAP8"]
[Thu Jul 30 12:40:22.831043 2026] [core:notice] [pid 765155:tid 765358] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:22.837690 2026] [security2:error] [pid 765155:tid 765358] [client 103.215.74.26:48408] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMhuT5hFAbD-LhWHipPgAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:22.942901 2026] [security2:error] [pid 765155:tid 765318] [client 20.100.187.246:33917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/bk.php"] [unique_id "amuMhuT5hFAbD-LhWHipQgAAAKY"]
[Thu Jul 30 12:40:22.946332 2026] [security2:error] [pid 765155:tid 765393] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuMhuT5hFAbD-LhWHipQwAAAPE"]
[Thu Jul 30 12:40:22.972747 2026] [security2:error] [pid 765155:tid 765313] [client 20.63.98.115:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/config.php"] [unique_id "amuMhuT5hFAbD-LhWHipRgAAAKE"]
[Thu Jul 30 12:40:23.076714 2026] [security2:error] [pid 765155:tid 765322] [client 14.245.78.164:44464] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuMh-T5hFAbD-LhWHipTQAAAKo"]
[Thu Jul 30 12:40:23.086769 2026] [security2:error] [pid 765155:tid 765356] [client 176.223.185.43:46878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuMh-T5hFAbD-LhWHipTwAAAMw"]
[Thu Jul 30 12:40:23.287374 2026] [security2:error] [pid 765155:tid 765374] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuMh-T5hFAbD-LhWHipVQAAAN4"]
[Thu Jul 30 12:40:23.327830 2026] [core:error] [pid 765155:tid 765295] [client 136.114.127.127:37710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:23.327859 2026] [core:error] [pid 765155:tid 765295] [client 136.114.127.127:37710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:23.328023 2026] [security2:error] [pid 765155:tid 765295] [client 136.114.127.127:37710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.website-a59f0c15.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuMh-T5hFAbD-LhWHipVgAAAI8"]
[Thu Jul 30 12:40:23.476396 2026] [security2:error] [pid 765155:tid 765340] [client 45.160.153.211:9614] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuMh-T5hFAbD-LhWHipVwAAALw"]
[Thu Jul 30 12:40:23.565059 2026] [core:notice] [pid 765155:tid 765316] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:23.576449 2026] [security2:error] [pid 765155:tid 765316] [client 103.215.74.26:8308] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMh-T5hFAbD-LhWHipXAAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:23.624474 2026] [security2:error] [pid 765155:tid 765300] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuMh-T5hFAbD-LhWHipYwAAAJQ"]
[Thu Jul 30 12:40:23.979922 2026] [security2:error] [pid 765155:tid 765379] [client 45.154.98.52:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuMh-T5hFAbD-LhWHipZwAAAOM"]
[Thu Jul 30 12:40:24.008363 2026] [security2:error] [pid 765155:tid 765328] [client 20.100.187.246:57600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.worldofwhiskers.com"] [uri "/ahax.php"] [unique_id "amuMiOT5hFAbD-LhWHipaAAAALA"]
[Thu Jul 30 12:40:24.302428 2026] [core:notice] [pid 765155:tid 765298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:24.306439 2026] [security2:error] [pid 765155:tid 765298] [client 103.215.74.26:8314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "758"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMiOT5hFAbD-LhWHipdQAAAJI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:25.019456 2026] [core:notice] [pid 765155:tid 765395] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:25.023665 2026] [security2:error] [pid 765155:tid 765395] [client 103.215.74.26:8330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "776"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMieT5hFAbD-LhWHipiAAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:25.078151 2026] [security2:error] [pid 765155:tid 765294] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMiOT5hFAbD-LhWHipeQAAAI4"]
[Thu Jul 30 12:40:25.298749 2026] [core:error] [pid 765155:tid 765388] [client 66.249.68.36:36940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:25.298771 2026] [core:error] [pid 765155:tid 765388] [client 66.249.68.36:36940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:25.754263 2026] [core:notice] [pid 765155:tid 765302] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:25.761207 2026] [security2:error] [pid 765155:tid 765302] [client 103.215.74.26:8332] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMieT5hFAbD-LhWHip9gAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:26.343993 2026] [core:notice] [pid 765155:tid 765235] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:26.528049 2026] [core:notice] [pid 765155:tid 765348] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:26.532482 2026] [security2:error] [pid 765155:tid 765348] [client 103.215.74.26:8336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "789"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMiuT5hFAbD-LhWHiqCAAAAMQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:26.584050 2026] [core:notice] [pid 765155:tid 765367] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:27.184460 2026] [security2:error] [pid 765155:tid 765406] [client 20.63.98.115:37987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ws.php"] [unique_id "amuMi-T5hFAbD-LhWHiqXwAAAP4"]
[Thu Jul 30 12:40:27.264726 2026] [core:notice] [pid 765155:tid 765291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:27.269686 2026] [security2:error] [pid 765155:tid 765291] [client 103.215.74.26:8340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMi-T5hFAbD-LhWHiqZAAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:27.388681 2026] [security2:error] [pid 765155:tid 765237] [remote 192.250.235.18:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.235.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sama-architect.com"] [uri "/wp-login.php"] [unique_id "amuMi-T5hFAbD-LhWHiqXgAAk1E"]
[Thu Jul 30 12:40:28.015524 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:28.020859 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:8352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "765"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMjOT5hFAbD-LhWHiqewAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:28.495811 2026] [security2:error] [pid 765155:tid 765302] [client 185.191.171.17:38356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/11/prtb-registra-candidaturas-de-major-fabio-e-sergio-queiroz/"] [unique_id "amuMjOT5hFAbD-LhWHiqiQAAAJY"]
[Thu Jul 30 12:40:28.495903 2026] [security2:error] [pid 765155:tid 765302] [client 185.191.171.17:38356] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/11/prtb-registra-candidaturas-de-major-fabio-e-sergio-queiroz/"] [unique_id "amuMjOT5hFAbD-LhWHiqiQAAAJY"]
[Thu Jul 30 12:40:28.775678 2026] [core:notice] [pid 765155:tid 765287] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:28.780242 2026] [security2:error] [pid 765155:tid 765287] [client 103.215.74.26:8368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "771"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMjOT5hFAbD-LhWHiqkAAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:28.921719 2026] [security2:error] [pid 765155:tid 765331] [client 150.107.232.194:27108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMjOT5hFAbD-LhWHiqmwAAALM"]
[Thu Jul 30 12:40:28.921815 2026] [security2:error] [pid 765155:tid 765331] [client 150.107.232.194:27108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMjOT5hFAbD-LhWHiqmwAAALM"]
[Thu Jul 30 12:40:29.034464 2026] [security2:error] [pid 765155:tid 765347] [client 38.190.144.4:60427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMjeT5hFAbD-LhWHiqoQAAAMM"]
[Thu Jul 30 12:40:29.034601 2026] [security2:error] [pid 765155:tid 765347] [client 38.190.144.4:60427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMjeT5hFAbD-LhWHiqoQAAAMM"]
[Thu Jul 30 12:40:29.114371 2026] [security2:error] [pid 765155:tid 765394] [client 20.63.98.115:21186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/admin/function.php"] [unique_id "amuMjeT5hFAbD-LhWHiqpQAAAPI"]
[Thu Jul 30 12:40:29.513683 2026] [core:notice] [pid 765155:tid 765319] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:29.521172 2026] [security2:error] [pid 765155:tid 765319] [client 103.215.74.26:8372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMjeT5hFAbD-LhWHiqtQAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:29.807547 2026] [security2:error] [pid 765155:tid 765232] [remote 57.141.0.40:30488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuMjeT5hFAbD-LhWHiqugAAyEw"]
[Thu Jul 30 12:40:30.250832 2026] [core:notice] [pid 765155:tid 765350] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:30.255823 2026] [security2:error] [pid 765155:tid 765350] [client 103.215.74.26:8378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMjuT5hFAbD-LhWHiqygAAAMY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:30.831317 2026] [core:notice] [pid 765155:tid 765262] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:31.015144 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:31.022581 2026] [security2:error] [pid 765155:tid 765304] [client 103.215.74.26:8384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMj-T5hFAbD-LhWHiq4AAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:31.431267 2026] [security2:error] [pid 765155:tid 765234] [remote 57.141.0.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuMj-T5hFAbD-LhWHirAAAAzU4"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,denim,lycra,plastic,steel,titanium,silicon&min_price=300&orderby=price-desc&rating=5&unfilter=1
[Thu Jul 30 12:40:31.460174 2026] [security2:error] [pid 765155:tid 765269] [remote 57.141.0.64:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuMj-T5hFAbD-LhWHirAgAA3nE"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,denim,lycra,plastic,steel,titanium,silicon&min_price=300&orderby=price-desc&rating=5&unfilter=1
[Thu Jul 30 12:40:31.474335 2026] [security2:error] [pid 765155:tid 765305] [client 157.51.71.30:42874] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuMj-T5hFAbD-LhWHirBAAAAJk"]
[Thu Jul 30 12:40:31.637629 2026] [proxy:error] [pid 765155:tid 765360] (104)Connection reset by peer: [client 178.105.14.254:33348] AH01084: pass request body failed to 127.0.0.1:2077 (127.0.0.1)
[Thu Jul 30 12:40:31.637666 2026] [proxy_http:error] [pid 765155:tid 765360] [client 178.105.14.254:33348] AH01097: pass request body failed to 127.0.0.1:2077 (127.0.0.1) from 178.105.14.254 ()
[Thu Jul 30 12:40:31.677688 2026] [proxy:error] [pid 765155:tid 765360] (104)Connection reset by peer: [client 178.105.14.254:33348] AH01084: pass request body failed to 127.0.0.1:2077 (127.0.0.1)
[Thu Jul 30 12:40:31.677716 2026] [proxy_http:error] [pid 765155:tid 765360] [client 178.105.14.254:33348] AH01097: pass request body failed to 127.0.0.1:2077 (127.0.0.1) from 178.105.14.254 ()
[Thu Jul 30 12:40:31.774509 2026] [core:notice] [pid 765155:tid 765373] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:31.783300 2026] [security2:error] [pid 765155:tid 765373] [client 103.215.74.26:8386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMj-T5hFAbD-LhWHirEwAAAN0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:32.056687 2026] [security2:error] [pid 765155:tid 765309] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq_gAAAJ0"]
[Thu Jul 30 12:40:32.146806 2026] [proxy:error] [pid 765155:tid 765342] (32)Broken pipe: [client 178.105.14.254:33358] AH01084: pass request body failed to 127.0.0.1:2082 (127.0.0.1)
[Thu Jul 30 12:40:32.146842 2026] [proxy_http:error] [pid 765155:tid 765342] [client 178.105.14.254:33358] AH01097: pass request body failed to 127.0.0.1:2082 (127.0.0.1) from 178.105.14.254 ()
[Thu Jul 30 12:40:32.241839 2026] [security2:error] [pid 765155:tid 765332] [client 172.236.9.101:50420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq8wAAALQ"]
[Thu Jul 30 12:40:32.249830 2026] [security2:error] [pid 765155:tid 765314] [client 172.236.9.101:57701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq7wAAAKI"]
[Thu Jul 30 12:40:32.251311 2026] [security2:error] [pid 765155:tid 765388] [client 172.236.9.101:30025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq8gAAAOw"]
[Thu Jul 30 12:40:32.256844 2026] [security2:error] [pid 765155:tid 765395] [client 172.236.9.101:53996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq8AAAAPM"]
[Thu Jul 30 12:40:32.271863 2026] [security2:error] [pid 765155:tid 765399] [client 172.236.9.101:34324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq9AAAAPc"]
[Thu Jul 30 12:40:32.279453 2026] [security2:error] [pid 765155:tid 765350] [client 172.236.9.101:3478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq8QAAAMY"]
[Thu Jul 30 12:40:32.297712 2026] [security2:error] [pid 765155:tid 765384] [client 172.236.9.101:2390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq-wAAAOg"]
[Thu Jul 30 12:40:32.307735 2026] [security2:error] [pid 765155:tid 765287] [client 172.236.9.101:1289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq-gAAAIc"]
[Thu Jul 30 12:40:32.330098 2026] [security2:error] [pid 765155:tid 765376] [client 172.236.9.101:13459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHiq_wAAAOA"]
[Thu Jul 30 12:40:32.341942 2026] [security2:error] [pid 765155:tid 765369] [client 172.236.9.101:1608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMj-T5hFAbD-LhWHirAQAAANk"]
[Thu Jul 30 12:40:32.468008 2026] [security2:error] [pid 765155:tid 765242] [remote 74.7.242.7:48942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileloc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amuMkOT5hFAbD-LhWHirJgAAi1Y"], referer: https://www.thdinfinity.com/?path=//opt/bart
[Thu Jul 30 12:40:32.519206 2026] [core:notice] [pid 765155:tid 765330] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:32.524444 2026] [security2:error] [pid 765155:tid 765330] [client 103.215.74.26:8388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMkOT5hFAbD-LhWHirKAAAALI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:32.996376 2026] [proxy_http:error] [pid 765155:tid 765342] [client 178.105.14.254:33358] AH01086: read less bytes of request body than expected (got 83155, expected 131892)
[Thu Jul 30 12:40:32.996403 2026] [proxy_http:error] [pid 765155:tid 765342] [client 178.105.14.254:33358] AH01097: pass request body failed to 127.0.0.1:2082 (127.0.0.1) from 178.105.14.254 ()
[Thu Jul 30 12:40:33.270269 2026] [core:notice] [pid 765155:tid 765345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:33.275560 2026] [security2:error] [pid 765155:tid 765345] [client 103.215.74.26:48870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMkeT5hFAbD-LhWHirQwAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:33.963055 2026] [proxy:error] [pid 765155:tid 765399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:33.963140 2026] [proxy_http:error] [pid 765155:tid 765399] [client 193.47.62.167:44884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:33.963860 2026] [proxy:error] [pid 765155:tid 765399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:33.963909 2026] [proxy_http:error] [pid 765155:tid 765399] [client 193.47.62.167:44884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:34.077970 2026] [core:notice] [pid 765155:tid 765176] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:34.847761 2026] [security2:error] [pid 765155:tid 765360] [client 103.215.74.213:36442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.nka.hfl.temporary.site"] [uri "/"] [unique_id "amuMkuT5hFAbD-LhWHirawAAANA"], referer: https://mail.nka.hfl.temporary.site/
[Thu Jul 30 12:40:34.997275 2026] [core:notice] [pid 765155:tid 765338] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:35.228198 2026] [security2:error] [pid 765155:tid 765389] [client 20.63.98.115:62793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "amuMk-T5hFAbD-LhWHirdwAAAO0"]
[Thu Jul 30 12:40:35.667601 2026] [security2:error] [pid 765155:tid 765293] [client 103.215.74.213:36452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/wp-json/batch/v1"] [unique_id "amuMk-T5hFAbD-LhWHirigAAAI0"], referer: https://mail.nka.hfl.temporary.site/
[Thu Jul 30 12:40:36.024568 2026] [security2:error] [pid 765155:tid 765355] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMk-T5hFAbD-LhWHirgAAAAMs"]
[Thu Jul 30 12:40:36.308935 2026] [security2:error] [pid 765155:tid 765266] [remote 57.141.0.33:37148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/8671/3510"] [unique_id "amuMlOT5hFAbD-LhWHirmgABAG4"]
[Thu Jul 30 12:40:37.455464 2026] [autoindex:error] [pid 765155:tid 765332] [client 34.224.175.62:35036] AH01276: Cannot serve directory /home2/meggzjte/01.serverkr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:40:37.578837 2026] [core:notice] [pid 765155:tid 765196] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:38.072154 2026] [security2:error] [pid 765155:tid 765378] [client 20.63.98.115:36916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuMluT5hFAbD-LhWHirxgAAAOI"]
[Thu Jul 30 12:40:38.913094 2026] [security2:error] [pid 765155:tid 765383] [client 185.191.171.10:51878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/01/brasileiro-e-suspeito-de-matar-esposa-e-filha-no-japao-e-voltar-ao-brasil/"] [unique_id "amuMluT5hFAbD-LhWHir3gAAAOc"]
[Thu Jul 30 12:40:38.913231 2026] [security2:error] [pid 765155:tid 765383] [client 185.191.171.10:51878] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/01/brasileiro-e-suspeito-de-matar-esposa-e-filha-no-japao-e-voltar-ao-brasil/"] [unique_id "amuMluT5hFAbD-LhWHir3gAAAOc"]
[Thu Jul 30 12:40:39.010486 2026] [core:notice] [pid 765155:tid 765304] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:39.015233 2026] [security2:error] [pid 765155:tid 765304] [client 103.215.74.26:48874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMl-T5hFAbD-LhWHir3wAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:39.018072 2026] [security2:error] [pid 765155:tid 765359] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMluT5hFAbD-LhWHir0AAAAM8"]
[Thu Jul 30 12:40:39.172442 2026] [security2:error] [pid 765155:tid 765228] [remote 57.141.0.60:20990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuMl-T5hFAbD-LhWHir5wAAp0g"]
[Thu Jul 30 12:40:39.214498 2026] [security2:error] [pid 765155:tid 765352] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMluT5hFAbD-LhWHir1gAAAMg"]
[Thu Jul 30 12:40:39.371741 2026] [security2:error] [pid 765155:tid 765307] [client 150.107.232.194:26981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMl-T5hFAbD-LhWHir7AAAAJs"]
[Thu Jul 30 12:40:39.371844 2026] [security2:error] [pid 765155:tid 765307] [client 150.107.232.194:26981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMl-T5hFAbD-LhWHir7AAAAJs"]
[Thu Jul 30 12:40:39.742711 2026] [core:notice] [pid 765155:tid 765374] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:39.747901 2026] [security2:error] [pid 765155:tid 765374] [client 103.215.74.26:48890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMl-T5hFAbD-LhWHir-QAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:39.811133 2026] [security2:error] [pid 765155:tid 765389] [client 38.190.144.4:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMl-T5hFAbD-LhWHir_QAAAO0"]
[Thu Jul 30 12:40:39.811234 2026] [security2:error] [pid 765155:tid 765389] [client 38.190.144.4:60934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMl-T5hFAbD-LhWHir_QAAAO0"]
[Thu Jul 30 12:40:40.472074 2026] [core:notice] [pid 765155:tid 765301] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:40.476498 2026] [security2:error] [pid 765155:tid 765301] [client 103.215.74.26:48894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMmOT5hFAbD-LhWHisDgAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:40.704906 2026] [security2:error] [pid 765155:tid 765329] [client 20.63.98.115:36874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuMmOT5hFAbD-LhWHisGAAAALE"]
[Thu Jul 30 12:40:41.204407 2026] [core:notice] [pid 765155:tid 765308] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:41.209857 2026] [security2:error] [pid 765155:tid 765308] [client 103.215.74.26:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMmeT5hFAbD-LhWHisJQAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:41.332465 2026] [proxy:error] [pid 765155:tid 765324] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:41.332559 2026] [proxy_http:error] [pid 765155:tid 765324] [client 143.244.57.82:50058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:41.333406 2026] [proxy:error] [pid 765155:tid 765324] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:41.333475 2026] [proxy_http:error] [pid 765155:tid 765324] [client 143.244.57.82:50058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:41.640811 2026] [proxy:error] [pid 765155:tid 765364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:41.640878 2026] [proxy_http:error] [pid 765155:tid 765364] [client 143.244.57.82:50072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:41.641469 2026] [proxy:error] [pid 765155:tid 765364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:41.641515 2026] [proxy_http:error] [pid 765155:tid 765364] [client 143.244.57.82:50072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:41.681737 2026] [security2:error] [pid 765155:tid 765349] [client 74.7.241.145:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.brx.dtn.temporary.site"] [uri "/index.php"] [unique_id "amuMmOT5hFAbD-LhWHisDAAAAMU"]
[Thu Jul 30 12:40:41.682578 2026] [security2:error] [pid 765155:tid 765340] [client 74.7.241.145:34748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.brx.dtn.temporary.site"] [uri "/robots.txt"] [unique_id "amuMmOT5hFAbD-LhWHisCgAAvE0"]
[Thu Jul 30 12:40:41.927100 2026] [security2:error] [pid 765155:tid 765316] [client 172.236.9.101:41183] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMmeT5hFAbD-LhWHisLQAAAKQ"]
[Thu Jul 30 12:40:41.929901 2026] [security2:error] [pid 765155:tid 765394] [client 143.244.57.82:50084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuMmeT5hFAbD-LhWHisPgAAAPI"]
[Thu Jul 30 12:40:41.962739 2026] [security2:error] [pid 765155:tid 765387] [client 172.236.9.101:26306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMmeT5hFAbD-LhWHisLgAAAOs"]
[Thu Jul 30 12:40:42.006551 2026] [security2:error] [pid 765155:tid 765294] [client 172.236.9.101:50753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMmeT5hFAbD-LhWHisLwAAAI4"]
[Thu Jul 30 12:40:42.100770 2026] [security2:error] [pid 765155:tid 765385] [client 40.77.177.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itrnetwork.org"] [uri "/index.php"] [unique_id "amuMmOT5hFAbD-LhWHisDQAA6WA"]
[Thu Jul 30 12:40:42.217393 2026] [security2:error] [pid 765155:tid 765299] [client 143.244.57.82:50092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuMmuT5hFAbD-LhWHisQgAAAJM"]
[Thu Jul 30 12:40:42.403403 2026] [security2:error] [pid 765155:tid 765368] [client 172.236.9.101:4013] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/certificates/alseermarine.com_privkey.pem"] [unique_id "amuMmuT5hFAbD-LhWHisSgAAANg"]
[Thu Jul 30 12:40:42.526180 2026] [proxy:error] [pid 765155:tid 765401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:42.526259 2026] [proxy_http:error] [pid 765155:tid 765401] [client 143.244.57.82:50094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:42.527074 2026] [proxy:error] [pid 765155:tid 765401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:40:42.527125 2026] [proxy_http:error] [pid 765155:tid 765401] [client 143.244.57.82:50094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:40:42.829671 2026] [security2:error] [pid 765155:tid 765334] [client 143.244.57.82:50104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuMmuT5hFAbD-LhWHisWgAAALY"]
[Thu Jul 30 12:40:42.887447 2026] [security2:error] [pid 765155:tid 765386] [client 172.236.9.101:27092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMmuT5hFAbD-LhWHisSQAAAOo"]
[Thu Jul 30 12:40:42.907428 2026] [security2:error] [pid 765155:tid 765367] [client 172.236.9.101:42983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMmuT5hFAbD-LhWHisSwAAANc"]
[Thu Jul 30 12:40:42.923723 2026] [security2:error] [pid 765155:tid 765355] [client 172.236.9.101:49366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMmuT5hFAbD-LhWHisTAAAAMs"]
[Thu Jul 30 12:40:43.123995 2026] [security2:error] [pid 765155:tid 765370] [client 143.244.57.82:50108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuMm-T5hFAbD-LhWHiscwAAANo"]
[Thu Jul 30 12:40:43.409616 2026] [security2:error] [pid 765155:tid 765331] [client 143.244.57.82:50110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuMm-T5hFAbD-LhWHisggAAALM"]
[Thu Jul 30 12:40:43.563760 2026] [security2:error] [pid 765155:tid 765307] [client 204.8.98.25:59412] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuMm-T5hFAbD-LhWHisfQAAAJs"]
[Thu Jul 30 12:40:43.563969 2026] [security2:error] [pid 765155:tid 765307] [client 204.8.98.25:59412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuMm-T5hFAbD-LhWHisfQAAAJs"]
[Thu Jul 30 12:40:43.674418 2026] [security2:error] [pid 765155:tid 765285] [client 74.7.241.128:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wvq.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuMmuT5hFAbD-LhWHisUwAAAIU"]
[Thu Jul 30 12:40:43.675061 2026] [security2:error] [pid 765155:tid 765393] [client 74.7.241.128:50788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wvq.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuMmuT5hFAbD-LhWHisUQAA8Wo"]
[Thu Jul 30 12:40:43.691407 2026] [security2:error] [pid 765155:tid 765388] [client 143.244.57.82:50118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuMm-T5hFAbD-LhWHishwAAAOw"]
[Thu Jul 30 12:40:43.705064 2026] [security2:error] [pid 765155:tid 765275] [remote 52.167.144.195:2413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/piano-and-guitar/article.php"] [unique_id "amuMm-T5hFAbD-LhWHisiAAA03c"]
[Thu Jul 30 12:40:43.773732 2026] [security2:error] [pid 765155:tid 765391] [client 49.51.233.95:45828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.233.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php/communitysocial"] [unique_id "amuMm-T5hFAbD-LhWHishgAAAO8"]
[Thu Jul 30 12:40:43.970633 2026] [security2:error] [pid 765155:tid 765376] [client 143.244.57.82:50124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuMm-T5hFAbD-LhWHisigAAAOA"]
[Thu Jul 30 12:40:44.255106 2026] [security2:error] [pid 765155:tid 765382] [client 143.244.57.82:50126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuMnOT5hFAbD-LhWHisjgAAAOY"]
[Thu Jul 30 12:40:44.525254 2026] [security2:error] [pid 765155:tid 765313] [client 172.237.109.114:35146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisZwAAAKE"]
[Thu Jul 30 12:40:44.534233 2026] [security2:error] [pid 765155:tid 765368] [client 143.244.57.82:50136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuMnOT5hFAbD-LhWHiskgAAANg"]
[Thu Jul 30 12:40:44.543404 2026] [security2:error] [pid 765155:tid 765339] [client 172.237.109.114:1826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisZgAAALs"]
[Thu Jul 30 12:40:44.550767 2026] [security2:error] [pid 765155:tid 765302] [client 172.237.109.114:40044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisagAAAJY"]
[Thu Jul 30 12:40:44.551507 2026] [security2:error] [pid 765155:tid 765345] [client 172.237.109.114:12000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisaQAAAME"]
[Thu Jul 30 12:40:44.555206 2026] [security2:error] [pid 765155:tid 765338] [client 172.237.109.114:32109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisaAAAALo"]
[Thu Jul 30 12:40:44.564093 2026] [security2:error] [pid 765155:tid 765400] [client 172.237.109.114:1212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisbAAAAPg"]
[Thu Jul 30 12:40:44.568392 2026] [security2:error] [pid 765155:tid 765352] [client 172.237.109.114:15807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisbgAAAMg"]
[Thu Jul 30 12:40:44.570155 2026] [security2:error] [pid 765155:tid 765324] [client 172.237.109.114:30729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisbQAAAKw"]
[Thu Jul 30 12:40:44.817743 2026] [security2:error] [pid 765155:tid 765292] [client 143.244.57.82:50146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuMnOT5hFAbD-LhWHisnwAAAIw"]
[Thu Jul 30 12:40:44.923612 2026] [core:notice] [pid 765155:tid 765166] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:45.103549 2026] [security2:error] [pid 765155:tid 765371] [client 143.244.57.82:50152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuMneT5hFAbD-LhWHisoQAAANs"]
[Thu Jul 30 12:40:45.221168 2026] [security2:error] [pid 765155:tid 765375] [client 172.237.109.114:28292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHiseAAAAN8"]
[Thu Jul 30 12:40:45.235423 2026] [security2:error] [pid 765155:tid 765295] [client 172.237.109.114:45648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHiscgAAAI8"]
[Thu Jul 30 12:40:45.235832 2026] [security2:error] [pid 765155:tid 765303] [client 172.237.109.114:28856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHiseQAAAJc"]
[Thu Jul 30 12:40:45.289217 2026] [security2:error] [pid 765155:tid 765380] [client 172.237.109.114:63275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHiscAAAAOQ"]
[Thu Jul 30 12:40:45.289220 2026] [security2:error] [pid 765155:tid 765337] [client 172.237.109.114:52122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisawAAALk"]
[Thu Jul 30 12:40:45.299740 2026] [security2:error] [pid 765155:tid 765306] [client 172.237.109.114:38130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHiscQAAAJo"]
[Thu Jul 30 12:40:45.315667 2026] [security2:error] [pid 765155:tid 765353] [client 172.237.109.114:58286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisewAAAMk"]
[Thu Jul 30 12:40:45.319330 2026] [security2:error] [pid 765155:tid 765309] [client 172.237.109.114:63117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisZQAAAJ0"]
[Thu Jul 30 12:40:45.335913 2026] [security2:error] [pid 765155:tid 765361] [client 172.237.109.114:32859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisdwAAANE"]
[Thu Jul 30 12:40:45.346499 2026] [security2:error] [pid 765155:tid 765360] [client 172.237.109.114:12470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisdgAAANA"]
[Thu Jul 30 12:40:45.347686 2026] [security2:error] [pid 765155:tid 765323] [client 172.237.109.114:48431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisegAAAKs"]
[Thu Jul 30 12:40:45.365815 2026] [core:notice] [pid 765155:tid 765261] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:45.367621 2026] [security2:error] [pid 765155:tid 765319] [client 172.237.109.114:50665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMm-T5hFAbD-LhWHisbwAAAKc"]
[Thu Jul 30 12:40:45.385625 2026] [security2:error] [pid 765155:tid 765391] [client 143.244.57.82:50160] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuMneT5hFAbD-LhWHisqwAAAO8"]
[Thu Jul 30 12:40:45.646524 2026] [security2:error] [pid 765155:tid 765242] [remote 216.73.216.152:60491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuMneT5hFAbD-LhWHistAAA_FY"]
[Thu Jul 30 12:40:45.667606 2026] [security2:error] [pid 765155:tid 765328] [client 143.244.57.82:50170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuMneT5hFAbD-LhWHistQAAALA"]
[Thu Jul 30 12:40:45.954051 2026] [security2:error] [pid 765155:tid 765338] [client 143.244.57.82:49984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuMneT5hFAbD-LhWHisvAAAALo"]
[Thu Jul 30 12:40:46.085837 2026] [security2:error] [pid 765155:tid 765281] [remote 72.167.132.114:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuMnuT5hFAbD-LhWHisvgAAuH0"]
[Thu Jul 30 12:40:46.243763 2026] [security2:error] [pid 765155:tid 765407] [client 143.244.57.82:50184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuMnuT5hFAbD-LhWHisygAAAP8"]
[Thu Jul 30 12:40:46.525767 2026] [security2:error] [pid 765155:tid 765321] [client 143.244.57.82:50186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuMnuT5hFAbD-LhWHis0AAAAKk"]
[Thu Jul 30 12:40:46.711117 2026] [core:notice] [pid 765155:tid 765158] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:46.714333 2026] [security2:error] [pid 765155:tid 765326] [client 74.0.19.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/view/50/52"] [unique_id "amuMnuT5hFAbD-LhWHiszAAArgI"]
[Thu Jul 30 12:40:46.809311 2026] [security2:error] [pid 765155:tid 765384] [client 143.244.57.82:50196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuMnuT5hFAbD-LhWHis3AAAAOg"]
[Thu Jul 30 12:40:46.945260 2026] [core:notice] [pid 765155:tid 765307] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:46.950540 2026] [security2:error] [pid 765155:tid 765307] [client 103.215.74.26:65458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMnuT5hFAbD-LhWHis3QAAAJs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:47.092581 2026] [security2:error] [pid 765155:tid 765350] [client 143.244.57.82:36704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.zdn.djb.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuMn-T5hFAbD-LhWHis4QAAAMY"]
[Thu Jul 30 12:40:47.389330 2026] [security2:error] [pid 765155:tid 765306] [client 20.63.98.115:20858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/uploads/2024/index.php"] [unique_id "amuMn-T5hFAbD-LhWHis6wAAAJo"]
[Thu Jul 30 12:40:47.679121 2026] [core:notice] [pid 765155:tid 765340] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:47.683565 2026] [security2:error] [pid 765155:tid 765340] [client 103.215.74.26:65470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMn-T5hFAbD-LhWHis-QAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:47.777850 2026] [core:notice] [pid 765155:tid 765354] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:47.782163 2026] [security2:error] [pid 765155:tid 765354] [client 213.186.1.154:62148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuMn-T5hFAbD-LhWHis-gAAAMo"]
[Thu Jul 30 12:40:48.207340 2026] [security2:error] [pid 765155:tid 765378] [client 213.186.1.154:54777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuMoOT5hFAbD-LhWHitBAAAAOI"]
[Thu Jul 30 12:40:48.406071 2026] [core:notice] [pid 765155:tid 765342] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:48.410925 2026] [security2:error] [pid 765155:tid 765342] [client 103.215.74.26:65476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMoOT5hFAbD-LhWHitCgAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:48.749087 2026] [security2:error] [pid 765155:tid 765299] [client 43.130.72.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "legalsnaps.info"] [uri "/index.php"] [unique_id "amuMn-T5hFAbD-LhWHis7wAAAJM"]
[Thu Jul 30 12:40:48.888271 2026] [core:notice] [pid 765155:tid 765362] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:49.054940 2026] [core:notice] [pid 765155:tid 765182] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:49.174278 2026] [core:notice] [pid 765155:tid 765399] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:49.180145 2026] [security2:error] [pid 765155:tid 765399] [client 103.215.74.26:65484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "762"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMoeT5hFAbD-LhWHitIQAAAPc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:49.483434 2026] [security2:error] [pid 765155:tid 765374] [client 20.63.98.115:62809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/cong.php"] [unique_id "amuMoeT5hFAbD-LhWHitLgAAAN4"]
[Thu Jul 30 12:40:49.790752 2026] [security2:error] [pid 765155:tid 765314] [client 66.249.73.65:54381] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/robots.txt"] [unique_id "amuMoeT5hFAbD-LhWHitOAAAAKI"]
[Thu Jul 30 12:40:49.900507 2026] [security2:error] [pid 765155:tid 765356] [client 150.107.232.194:27116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMoeT5hFAbD-LhWHitOgAAAMw"]
[Thu Jul 30 12:40:49.900616 2026] [security2:error] [pid 765155:tid 765356] [client 150.107.232.194:27116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMoeT5hFAbD-LhWHitOgAAAMw"]
[Thu Jul 30 12:40:49.935823 2026] [core:notice] [pid 765155:tid 765345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:49.939666 2026] [security2:error] [pid 765155:tid 765345] [client 103.215.74.26:65508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMoeT5hFAbD-LhWHitPgAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:50.281727 2026] [security2:error] [pid 765155:tid 765187] [remote 74.7.241.59:41656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuMouT5hFAbD-LhWHitSgAA5R8"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/insert-headers-and-footers/includes
[Thu Jul 30 12:40:50.658329 2026] [core:notice] [pid 765155:tid 765407] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:50.662783 2026] [security2:error] [pid 765155:tid 765407] [client 103.215.74.26:65526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMouT5hFAbD-LhWHitTwAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:50.804629 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:61440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMouT5hFAbD-LhWHitVgAAANc"]
[Thu Jul 30 12:40:50.804770 2026] [security2:error] [pid 765155:tid 765367] [client 38.190.144.4:61440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMouT5hFAbD-LhWHitVgAAANc"]
[Thu Jul 30 12:40:50.907858 2026] [security2:error] [pid 765155:tid 765384] [client 66.249.73.64:47708] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/author/tfhk1688gmail-com/"] [unique_id "amuMouT5hFAbD-LhWHitXQAAAOg"]
[Thu Jul 30 12:40:51.151755 2026] [core:notice] [pid 765155:tid 765237] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:51.373777 2026] [core:error] [pid 765155:tid 765220] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/wp/
[Thu Jul 30 12:40:51.373806 2026] [core:error] [pid 765155:tid 765220] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/wp/
[Thu Jul 30 12:40:51.394121 2026] [core:notice] [pid 765155:tid 765309] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:51.400705 2026] [security2:error] [pid 765155:tid 765309] [client 103.215.74.26:65532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMo-T5hFAbD-LhWHitaQAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:51.435185 2026] [security2:error] [pid 765155:tid 765370] [client 102.135.173.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMouT5hFAbD-LhWHitTgAA2io"], referer: https://allmontecristi.com
[Thu Jul 30 12:40:51.796496 2026] [core:notice] [pid 765155:tid 765253] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:51.961836 2026] [core:error] [pid 765155:tid 765201] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/wp/
[Thu Jul 30 12:40:51.961864 2026] [core:error] [pid 765155:tid 765201] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/wp/
[Thu Jul 30 12:40:52.188139 2026] [security2:error] [pid 765155:tid 765361] [client 20.63.98.115:62418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuMpOT5hFAbD-LhWHitrAAAANE"]
[Thu Jul 30 12:40:52.520324 2026] [core:error] [pid 765155:tid 765181] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/wordpress/
[Thu Jul 30 12:40:52.520344 2026] [core:error] [pid 765155:tid 765181] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/wordpress/
[Thu Jul 30 12:40:52.844691 2026] [security2:error] [pid 765155:tid 765295] [client 193.37.252.99:57054] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuMpOT5hFAbD-LhWHit2QAAAI8"]
[Thu Jul 30 12:40:52.844794 2026] [security2:error] [pid 765155:tid 765295] [client 193.37.252.99:57054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuMpOT5hFAbD-LhWHit2QAAAI8"]
[Thu Jul 30 12:40:53.059483 2026] [security2:error] [pid 765155:tid 765215] [remote 167.71.218.184:51204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amuMpeT5hFAbD-LhWHit9wAAyDs"]
[Thu Jul 30 12:40:53.122282 2026] [core:error] [pid 765155:tid 765197] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/wordpress/
[Thu Jul 30 12:40:53.122312 2026] [core:error] [pid 765155:tid 765197] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/wordpress/
[Thu Jul 30 12:40:53.225946 2026] [security2:error] [pid 765155:tid 765399] [client 20.63.98.115:36881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/edit.php"] [unique_id "amuMpeT5hFAbD-LhWHit_gAAAPc"]
[Thu Jul 30 12:40:53.712691 2026] [core:error] [pid 765155:tid 765213] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/blog/
[Thu Jul 30 12:40:53.712721 2026] [core:error] [pid 765155:tid 765213] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/blog/
[Thu Jul 30 12:40:54.080260 2026] [security2:error] [pid 765155:tid 765208] [remote 47.251.82.1:45500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuMpuT5hFAbD-LhWHiuJgAApjQ"]
[Thu Jul 30 12:40:54.102127 2026] [security2:error] [pid 765155:tid 765345] [client 20.63.98.115:20574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/about/function.php"] [unique_id "amuMpuT5hFAbD-LhWHiuJwAAAME"]
[Thu Jul 30 12:40:54.267632 2026] [core:error] [pid 765155:tid 765243] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/blog/
[Thu Jul 30 12:40:54.267658 2026] [core:error] [pid 765155:tid 765243] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/blog/
[Thu Jul 30 12:40:54.512768 2026] [core:error] [pid 765155:tid 765255] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/old/
[Thu Jul 30 12:40:54.512796 2026] [core:error] [pid 765155:tid 765255] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/old/
[Thu Jul 30 12:40:54.852224 2026] [security2:error] [pid 765155:tid 765357] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.dl.truckersofeuropemod.com"] [uri "/"] [unique_id "amuMpuT5hFAbD-LhWHiuQAAAAM0"]
[Thu Jul 30 12:40:55.072923 2026] [core:error] [pid 765155:tid 765157] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/old/
[Thu Jul 30 12:40:55.072955 2026] [core:error] [pid 765155:tid 765157] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/old/
[Thu Jul 30 12:40:55.275832 2026] [core:error] [pid 765155:tid 765195] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/test/
[Thu Jul 30 12:40:55.275865 2026] [core:error] [pid 765155:tid 765195] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/test/
[Thu Jul 30 12:40:55.873228 2026] [core:error] [pid 765155:tid 765205] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/test/
[Thu Jul 30 12:40:55.873250 2026] [core:error] [pid 765155:tid 765205] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/test/
[Thu Jul 30 12:40:56.083948 2026] [core:error] [pid 765155:tid 765194] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/dev/
[Thu Jul 30 12:40:56.083973 2026] [core:error] [pid 765155:tid 765194] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/dev/
[Thu Jul 30 12:40:56.474969 2026] [security2:error] [pid 765155:tid 765369] [client 138.199.40.165:53408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuMqOT5hFAbD-LhWHiuvwAA2TU"], referer: https://trello.com/
[Thu Jul 30 12:40:56.581720 2026] [security2:error] [pid 765155:tid 765291] [client 20.63.98.115:43922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/simple/function.php"] [unique_id "amuMqOT5hFAbD-LhWHiuyQAAAIs"]
[Thu Jul 30 12:40:56.651010 2026] [core:error] [pid 765155:tid 765161] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/dev/
[Thu Jul 30 12:40:56.651030 2026] [core:error] [pid 765155:tid 765161] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/dev/
[Thu Jul 30 12:40:56.870118 2026] [core:error] [pid 765155:tid 765187] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/backup/
[Thu Jul 30 12:40:56.870138 2026] [core:error] [pid 765155:tid 765187] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/backup/
[Thu Jul 30 12:40:57.160417 2026] [core:notice] [pid 765155:tid 765412] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:57.167021 2026] [security2:error] [pid 765155:tid 765412] [client 103.215.74.26:34454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMqeT5hFAbD-LhWHiu3AAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:57.172026 2026] [security2:error] [pid 765155:tid 765213] [remote 216.73.216.152:60491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuMqeT5hFAbD-LhWHiu3QAA-jk"]
[Thu Jul 30 12:40:57.463131 2026] [core:error] [pid 765155:tid 765196] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/backup/
[Thu Jul 30 12:40:57.463154 2026] [core:error] [pid 765155:tid 765196] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/backup/
[Thu Jul 30 12:40:57.675611 2026] [security2:error] [pid 765155:tid 765200] [remote 216.73.216.152:60491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuMqeT5hFAbD-LhWHiu7QAAjCw"]
[Thu Jul 30 12:40:57.691507 2026] [core:error] [pid 765155:tid 765198] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/staging/
[Thu Jul 30 12:40:57.691530 2026] [core:error] [pid 765155:tid 765198] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/staging/
[Thu Jul 30 12:40:57.902454 2026] [core:error] [pid 765155:tid 765270] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/staging/
[Thu Jul 30 12:40:57.902477 2026] [core:error] [pid 765155:tid 765270] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/staging/
[Thu Jul 30 12:40:57.912839 2026] [core:notice] [pid 765155:tid 765351] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:57.917655 2026] [security2:error] [pid 765155:tid 765351] [client 103.215.74.26:34458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMqeT5hFAbD-LhWHiu9AAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:58.224670 2026] [security2:error] [pid 765155:tid 765387] [client 20.63.98.115:20826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mah/function.php"] [unique_id "amuMquT5hFAbD-LhWHiu-wAAAOs"]
[Thu Jul 30 12:40:58.380099 2026] [core:error] [pid 765155:tid 765239] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/
[Thu Jul 30 12:40:58.380120 2026] [core:error] [pid 765155:tid 765239] [remote 195.178.110.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://massageandspaislamabad.rest/
[Thu Jul 30 12:40:58.426259 2026] [core:error] [pid 765155:tid 765411] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:58.426284 2026] [core:error] [pid 765155:tid 765411] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:58.471759 2026] [core:error] [pid 765155:tid 765297] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:58.471784 2026] [core:error] [pid 765155:tid 765297] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:58.486503 2026] [core:error] [pid 765155:tid 765369] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:58.486529 2026] [core:error] [pid 765155:tid 765369] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:40:58.653486 2026] [core:notice] [pid 765155:tid 765346] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:58.661250 2026] [security2:error] [pid 765155:tid 765346] [client 103.215.74.26:34474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "778"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMquT5hFAbD-LhWHivIwAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:58.883662 2026] [fcgid:warn] [pid 765155:tid 765311] (70014)End of file found: [client 165.154.11.210:53512] mod_fcgid: can't get data from http client
[Thu Jul 30 12:40:59.389752 2026] [security2:error] [pid 765155:tid 765233] [remote 165.22.136.47:47166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.136.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/wp-login.php"] [unique_id "amuMq-T5hFAbD-LhWHivQgAAkE0"]
[Thu Jul 30 12:40:59.397165 2026] [core:notice] [pid 765155:tid 765375] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:40:59.403812 2026] [security2:error] [pid 765155:tid 765375] [client 103.215.74.26:34488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMq-T5hFAbD-LhWHivRAAAAN8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:40:59.731265 2026] [security2:error] [pid 765155:tid 765398] [client 40.77.167.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuMqOT5hFAbD-LhWHiu0AAAAPY"]
[Thu Jul 30 12:41:00.154899 2026] [security2:error] [pid 765155:tid 765307] [client 20.63.98.115:62432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/go.php"] [unique_id "amuMrOT5hFAbD-LhWHivRQAAAJs"]
[Thu Jul 30 12:41:00.271791 2026] [http2:info] [pid 782784:tid 782784] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:41:00.380865 2026] [security2:error] [pid 782784:tid 782923] [client 150.107.232.194:26676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMrIaApLsOvtuGcVqKXQAAAAk"]
[Thu Jul 30 12:41:00.381047 2026] [security2:error] [pid 782784:tid 782923] [client 150.107.232.194:26676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMrIaApLsOvtuGcVqKXQAAAAk"]
[Thu Jul 30 12:41:00.529074 2026] [core:notice] [pid 782784:tid 782915] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:00.536876 2026] [security2:error] [pid 782784:tid 782915] [client 103.215.74.26:34494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "791"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMrIaApLsOvtuGcVqKbQAAAAE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:00.906417 2026] [security2:error] [pid 782784:tid 782949] [client 40.77.167.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuMrIaApLsOvtuGcVqKcgAAACM"]
[Thu Jul 30 12:41:01.144907 2026] [proxy:error] [pid 782784:tid 782979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:01.144992 2026] [proxy_http:error] [pid 782784:tid 782979] [client 165.154.11.210:35222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:41:01.145847 2026] [proxy:error] [pid 782784:tid 782979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:01.145893 2026] [proxy_http:error] [pid 782784:tid 782979] [client 165.154.11.210:35222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:41:01.262286 2026] [core:notice] [pid 782784:tid 782971] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:01.267347 2026] [security2:error] [pid 782784:tid 782971] [client 103.215.74.26:34496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMrYaApLsOvtuGcVqKgQAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:01.466958 2026] [security2:error] [pid 782784:tid 782965] [client 38.190.144.4:61942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMrYaApLsOvtuGcVqKhQAAADM"]
[Thu Jul 30 12:41:01.467145 2026] [security2:error] [pid 782784:tid 782965] [client 38.190.144.4:61942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMrYaApLsOvtuGcVqKhQAAADM"]
[Thu Jul 30 12:41:01.718607 2026] [security2:error] [pid 782784:tid 782991] [client 20.63.98.115:43965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/buy.php"] [unique_id "amuMrYaApLsOvtuGcVqKjAAAAE0"]
[Thu Jul 30 12:41:01.996501 2026] [core:notice] [pid 782784:tid 783008] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:02.002446 2026] [security2:error] [pid 782784:tid 783008] [client 103.215.74.26:34512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "757"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMrYaApLsOvtuGcVqKkQAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:02.788935 2026] [core:notice] [pid 782784:tid 782926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:02.793970 2026] [security2:error] [pid 782784:tid 782926] [client 103.215.74.26:34518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "763"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMroaApLsOvtuGcVqKogAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:03.510319 2026] [core:notice] [pid 782784:tid 782955] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:03.515138 2026] [security2:error] [pid 782784:tid 782955] [client 103.215.74.26:31264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMr4aApLsOvtuGcVqKtQAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:03.770890 2026] [security2:error] [pid 782784:tid 783028] [client 20.63.98.115:37996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/astra/inc/ki1k.php"] [unique_id "amuMr4aApLsOvtuGcVqKvwAAAHI"]
[Thu Jul 30 12:41:04.251180 2026] [core:notice] [pid 782784:tid 782996] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:04.256047 2026] [security2:error] [pid 782784:tid 782996] [client 103.215.74.26:31268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMsIaApLsOvtuGcVqKzwAAAFI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:04.459846 2026] [proxy:error] [pid 782784:tid 783016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:04.459924 2026] [proxy_http:error] [pid 782784:tid 783016] [client 165.154.11.210:35232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:41:04.460508 2026] [proxy:error] [pid 782784:tid 783016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:04.460552 2026] [proxy_http:error] [pid 782784:tid 783016] [client 165.154.11.210:35232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:41:04.766993 2026] [core:error] [pid 782784:tid 783029] [client 20.63.98.115:20814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:41:04.767016 2026] [core:error] [pid 782784:tid 783029] [client 20.63.98.115:20814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:41:04.999677 2026] [core:notice] [pid 782784:tid 782916] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:05.007419 2026] [security2:error] [pid 782784:tid 782916] [client 103.215.74.26:31272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMsIaApLsOvtuGcVqK5wAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:05.113059 2026] [security2:error] [pid 782784:tid 783023] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMsIaApLsOvtuGcVqK2AAAAG0"]
[Thu Jul 30 12:41:05.752228 2026] [core:notice] [pid 782784:tid 782932] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:05.752746 2026] [security2:error] [pid 782784:tid 782967] [client 20.91.199.21:52291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/011i.php"] [unique_id "amuMsYaApLsOvtuGcVqK_gAAADU"]
[Thu Jul 30 12:41:05.757587 2026] [security2:error] [pid 782784:tid 782932] [client 103.215.74.26:31286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMsYaApLsOvtuGcVqK_wAAABI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:05.921628 2026] [security2:error] [pid 782784:tid 782954] [client 20.63.98.115:36923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wq.php7"] [unique_id "amuMsYaApLsOvtuGcVqLAAAAACg"]
[Thu Jul 30 12:41:06.481577 2026] [core:notice] [pid 782784:tid 783005] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:06.486921 2026] [security2:error] [pid 782784:tid 783005] [client 103.215.74.26:31288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMsoaApLsOvtuGcVqLEQAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:07.208837 2026] [core:notice] [pid 782784:tid 782916] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:07.213782 2026] [security2:error] [pid 782784:tid 782916] [client 103.215.74.26:31294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMs4aApLsOvtuGcVqLIwAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:07.222159 2026] [security2:error] [pid 782784:tid 782922] [client 20.63.98.115:20825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/forum.php"] [unique_id "amuMs4aApLsOvtuGcVqLKQAAAAg"]
[Thu Jul 30 12:41:07.587225 2026] [core:notice] [pid 782784:tid 782919] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:07.906854 2026] [proxy:error] [pid 782784:tid 782978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:07.906925 2026] [proxy_http:error] [pid 782784:tid 782978] [client 165.154.11.210:35242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:41:07.907522 2026] [proxy:error] [pid 782784:tid 782978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:07.907568 2026] [proxy_http:error] [pid 782784:tid 782978] [client 165.154.11.210:35242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:41:07.928709 2026] [core:notice] [pid 782784:tid 782938] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:07.933093 2026] [security2:error] [pid 782784:tid 782938] [client 103.215.74.26:31298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMs4aApLsOvtuGcVqLPAAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:07.960770 2026] [security2:error] [pid 782784:tid 783016] [client 20.91.199.21:42946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/03a005685d.php"] [unique_id "amuMs4aApLsOvtuGcVqLPgAAAGY"]
[Thu Jul 30 12:41:08.550599 2026] [security2:error] [pid 782784:tid 782981] [client 20.91.199.21:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/403.php"] [unique_id "amuMtIaApLsOvtuGcVqLTwAAAEM"]
[Thu Jul 30 12:41:08.661325 2026] [core:notice] [pid 782784:tid 782973] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:08.669626 2026] [security2:error] [pid 782784:tid 782973] [client 103.215.74.26:31310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMtIaApLsOvtuGcVqLUAAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:09.359018 2026] [security2:error] [pid 782784:tid 783031] [client 20.91.199.21:48417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/404.php"] [unique_id "amuMtYaApLsOvtuGcVqLZwAAAHU"]
[Thu Jul 30 12:41:09.383876 2026] [core:notice] [pid 782784:tid 783038] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:09.388581 2026] [security2:error] [pid 782784:tid 783038] [client 103.215.74.26:31320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMtYaApLsOvtuGcVqLaQAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:09.562520 2026] [security2:error] [pid 782784:tid 783010] [client 127.0.0.1:15456] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuMtYaApLsOvtuGcVqLbwAAAGA"]
[Thu Jul 30 12:41:09.562617 2026] [security2:error] [pid 782784:tid 782944] [client 74.7.230.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/robots.txt"] [unique_id "amuMtYaApLsOvtuGcVqLbgAAHlU"]
[Thu Jul 30 12:41:09.645854 2026] [security2:error] [pid 782784:tid 782868] [remote 103.176.179.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.179.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plumbingplumb.com"] [uri "/wp/wp-login.php"] [unique_id "amuMtYaApLsOvtuGcVqLaAAAFVM"]
[Thu Jul 30 12:41:10.133179 2026] [core:notice] [pid 782784:tid 782943] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:10.138052 2026] [security2:error] [pid 782784:tid 782943] [client 103.215.74.26:31332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMtoaApLsOvtuGcVqLfgAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:10.553652 2026] [security2:error] [pid 782784:tid 782966] [client 20.63.98.115:62822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/5index.php"] [unique_id "amuMtoaApLsOvtuGcVqLjAAAADQ"]
[Thu Jul 30 12:41:10.667944 2026] [security2:error] [pid 782784:tid 783002] [client 127.0.0.1:15474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuMtoaApLsOvtuGcVqLjwAAAFg"]
[Thu Jul 30 12:41:10.667952 2026] [security2:error] [pid 782784:tid 782994] [client 127.0.0.1:15462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.brx.dtn.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuMtoaApLsOvtuGcVqLjgAAAFA"]
[Thu Jul 30 12:41:10.668168 2026] [security2:error] [pid 782784:tid 782977] [client 74.7.230.16:33870] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.brx.dtn.temporary.site"] [uri "/robots.txt"] [unique_id "amuMtoaApLsOvtuGcVqLjQAAP18"]
[Thu Jul 30 12:41:10.870223 2026] [core:notice] [pid 782784:tid 782954] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:10.874519 2026] [security2:error] [pid 782784:tid 782954] [client 103.215.74.26:31346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMtoaApLsOvtuGcVqLnAAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:10.875471 2026] [security2:error] [pid 782784:tid 783009] [client 150.107.232.194:26818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMtoaApLsOvtuGcVqLngAAAF8"]
[Thu Jul 30 12:41:10.875571 2026] [security2:error] [pid 782784:tid 783009] [client 150.107.232.194:26818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMtoaApLsOvtuGcVqLngAAAF8"]
[Thu Jul 30 12:41:11.001810 2026] [proxy:error] [pid 782784:tid 783039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:11.001901 2026] [proxy_http:error] [pid 782784:tid 783039] [client 165.154.11.210:52902] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:41:11.002523 2026] [proxy:error] [pid 782784:tid 783039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:11.002580 2026] [proxy_http:error] [pid 782784:tid 783039] [client 165.154.11.210:52902] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:41:11.120815 2026] [security2:error] [pid 782784:tid 782981] [client 85.208.96.193:39886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/01/depois-de-mais-de-43-horas-desde-confirmada-a-vitoria-de-luiz-inacio-lula-da-silva-pt-o-presidente-jair-bolsonaro-pl-se-pronuncia-sobre-o-resultado-sobre-as-eleicoes/"] [unique_id "amuMt4aApLsOvtuGcVqLrAAAAEM"]
[Thu Jul 30 12:41:11.121051 2026] [security2:error] [pid 782784:tid 782981] [client 85.208.96.193:39886] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/01/depois-de-mais-de-43-horas-desde-confirmada-a-vitoria-de-luiz-inacio-lula-da-silva-pt-o-presidente-jair-bolsonaro-pl-se-pronuncia-sobre-o-resultado-sobre-as-eleicoes/"] [unique_id "amuMt4aApLsOvtuGcVqLrAAAAEM"]
[Thu Jul 30 12:41:11.389669 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:11.503862 2026] [security2:error] [pid 782784:tid 782934] [client 20.91.199.21:42691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/aa.php"] [unique_id "amuMt4aApLsOvtuGcVqLvQAAABQ"]
[Thu Jul 30 12:41:11.584689 2026] [security2:error] [pid 782784:tid 783030] [client 172.237.109.114:42892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMtoaApLsOvtuGcVqLpwAAAHQ"]
[Thu Jul 30 12:41:11.584889 2026] [security2:error] [pid 782784:tid 782917] [client 172.237.109.114:46483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMtoaApLsOvtuGcVqLqAAAAAM"]
[Thu Jul 30 12:41:11.602240 2026] [security2:error] [pid 782784:tid 783015] [client 172.237.109.114:40427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMtoaApLsOvtuGcVqLpQAAAGU"]
[Thu Jul 30 12:41:11.629450 2026] [security2:error] [pid 782784:tid 782915] [client 172.237.109.114:24006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMt4aApLsOvtuGcVqLqwAAAAE"]
[Thu Jul 30 12:41:11.629450 2026] [security2:error] [pid 782784:tid 783037] [client 172.237.109.114:20586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMtoaApLsOvtuGcVqLpgAAAHs"]
[Thu Jul 30 12:41:11.633770 2026] [security2:error] [pid 782784:tid 782918] [client 172.237.109.114:7959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMtoaApLsOvtuGcVqLqQAAAAQ"]
[Thu Jul 30 12:41:11.641394 2026] [core:notice] [pid 782784:tid 782965] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:11.646973 2026] [security2:error] [pid 782784:tid 782965] [client 103.215.74.26:31356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMt4aApLsOvtuGcVqLvgAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:11.850867 2026] [core:notice] [pid 782784:tid 782964] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:12.375845 2026] [core:notice] [pid 782784:tid 782966] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:12.380895 2026] [security2:error] [pid 782784:tid 782966] [client 103.215.74.26:31364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMuIaApLsOvtuGcVqL1gAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:12.537655 2026] [security2:error] [pid 782784:tid 782949] [client 38.190.144.4:64427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMuIaApLsOvtuGcVqL4QAAACM"]
[Thu Jul 30 12:41:12.537811 2026] [security2:error] [pid 782784:tid 782949] [client 38.190.144.4:64427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMuIaApLsOvtuGcVqL4QAAACM"]
[Thu Jul 30 12:41:12.646592 2026] [security2:error] [pid 782784:tid 782987] [client 20.91.199.21:42664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/aafewc0k.php"] [unique_id "amuMuIaApLsOvtuGcVqL5AAAAEk"]
[Thu Jul 30 12:41:12.986185 2026] [security2:error] [pid 782784:tid 783023] [client 172.237.109.114:62156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/ssl/private/alseermarine.com_key.pem"] [unique_id "amuMuIaApLsOvtuGcVqL8wAAAG0"]
[Thu Jul 30 12:41:13.115638 2026] [security2:error] [pid 782784:tid 782974] [client 20.63.98.115:20833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cookie.php"] [unique_id "amuMuYaApLsOvtuGcVqMAQAAADw"]
[Thu Jul 30 12:41:13.134449 2026] [core:notice] [pid 782784:tid 782930] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:13.142812 2026] [security2:error] [pid 782784:tid 782930] [client 103.215.74.26:21788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMuYaApLsOvtuGcVqMAgAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:13.559062 2026] [security2:error] [pid 782784:tid 783038] [client 172.237.109.114:64733] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL7gAAAHw"]
[Thu Jul 30 12:41:13.598620 2026] [security2:error] [pid 782784:tid 782921] [client 172.237.109.114:14909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL7QAAAAc"]
[Thu Jul 30 12:41:13.609331 2026] [security2:error] [pid 782784:tid 782944] [client 172.237.109.114:53909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL8AAAAB4"]
[Thu Jul 30 12:41:13.609473 2026] [security2:error] [pid 782784:tid 783010] [client 172.237.109.114:31054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL7wAAAGA"]
[Thu Jul 30 12:41:13.684410 2026] [security2:error] [pid 782784:tid 782936] [client 172.237.109.114:63797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL9QAAABY"]
[Thu Jul 30 12:41:13.684767 2026] [security2:error] [pid 782784:tid 782946] [client 172.237.109.114:23698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL8QAAACA"]
[Thu Jul 30 12:41:13.687321 2026] [security2:error] [pid 782784:tid 782939] [client 172.237.109.114:4591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL8gAAABk"]
[Thu Jul 30 12:41:13.698774 2026] [security2:error] [pid 782784:tid 782937] [client 172.237.109.114:34929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL9gAAABc"]
[Thu Jul 30 12:41:13.709245 2026] [security2:error] [pid 782784:tid 782951] [client 172.237.109.114:55590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL9wAAACU"]
[Thu Jul 30 12:41:13.722362 2026] [security2:error] [pid 782784:tid 782935] [client 172.237.109.114:32567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL9AAAABU"]
[Thu Jul 30 12:41:13.733646 2026] [security2:error] [pid 782784:tid 782953] [client 172.237.109.114:54204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuYaApLsOvtuGcVqL-wAAACc"]
[Thu Jul 30 12:41:13.737190 2026] [security2:error] [pid 782784:tid 783025] [client 172.237.109.114:52673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuIaApLsOvtuGcVqL-AAAAG8"]
[Thu Jul 30 12:41:13.761302 2026] [security2:error] [pid 782784:tid 782924] [client 172.237.109.114:50489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuMuYaApLsOvtuGcVqL_AAAAAo"]
[Thu Jul 30 12:41:13.868959 2026] [core:notice] [pid 782784:tid 782967] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:13.873913 2026] [security2:error] [pid 782784:tid 782967] [client 103.215.74.26:21794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMuYaApLsOvtuGcVqMFQAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:14.516805 2026] [security2:error] [pid 782784:tid 783029] [client 85.204.70.98:35724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuMuoaApLsOvtuGcVqMKgAAAHM"]
[Thu Jul 30 12:41:14.618553 2026] [core:notice] [pid 782784:tid 783036] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:14.623920 2026] [security2:error] [pid 782784:tid 783036] [client 103.215.74.26:21808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMuoaApLsOvtuGcVqMMwAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:14.692528 2026] [security2:error] [pid 782784:tid 782965] [client 20.91.199.21:42695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/abcd.php"] [unique_id "amuMuoaApLsOvtuGcVqMOgAAADM"]
[Thu Jul 30 12:41:14.953504 2026] [security2:error] [pid 782784:tid 782802] [remote 47.128.24.29:24492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-mevius.com"] [uri "/product/terea-13/"] [unique_id "amuMuoaApLsOvtuGcVqMQwAAORE"]
[Thu Jul 30 12:41:14.965451 2026] [security2:error] [pid 782784:tid 782920] [client 158.181.46.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuMuoaApLsOvtuGcVqMMgAAAAY"], referer: https://tereashops.com/product/terea-14/
[Thu Jul 30 12:41:15.232782 2026] [security2:error] [pid 782784:tid 782973] [client 85.204.70.98:35732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.pkfye.ye"] [uri "/xmlrpc.php"] [unique_id "amuMu4aApLsOvtuGcVqMUQAAADs"]
[Thu Jul 30 12:41:15.293795 2026] [security2:error] [pid 782784:tid 783028] [client 40.77.167.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuMuoaApLsOvtuGcVqMQQAAAHI"]
[Thu Jul 30 12:41:15.358125 2026] [core:notice] [pid 782784:tid 782935] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:15.365292 2026] [security2:error] [pid 782784:tid 782935] [client 103.215.74.26:21820] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMu4aApLsOvtuGcVqMVAAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:15.762999 2026] [security2:error] [pid 782784:tid 783026] [client 85.204.70.98:35740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuMu4aApLsOvtuGcVqMZQAAAHA"]
[Thu Jul 30 12:41:16.057563 2026] [security2:error] [pid 782784:tid 782945] [client 85.204.70.98:35752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuMvIaApLsOvtuGcVqMaQAAAB8"]
[Thu Jul 30 12:41:16.093134 2026] [core:notice] [pid 782784:tid 783019] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:16.100285 2026] [security2:error] [pid 782784:tid 783019] [client 103.215.74.26:21830] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMvIaApLsOvtuGcVqMagAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:16.283624 2026] [security2:error] [pid 782784:tid 782997] [client 40.77.167.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuMu4aApLsOvtuGcVqMaAAAAFM"]
[Thu Jul 30 12:41:16.320148 2026] [security2:error] [pid 782784:tid 782931] [client 85.204.70.98:35760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuMvIaApLsOvtuGcVqMdwAAABE"]
[Thu Jul 30 12:41:16.521429 2026] [security2:error] [pid 782784:tid 782930] [client 20.91.199.21:42957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/about.php"] [unique_id "amuMvIaApLsOvtuGcVqMeQAAABA"]
[Thu Jul 30 12:41:16.614289 2026] [security2:error] [pid 782784:tid 782943] [client 43.133.253.253:56792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koriusa.info"] [uri "/index.php"] [unique_id "amuMuoaApLsOvtuGcVqMLQAAAB0"]
[Thu Jul 30 12:41:16.829693 2026] [core:notice] [pid 782784:tid 782944] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:16.834991 2026] [security2:error] [pid 782784:tid 782944] [client 103.215.74.26:21838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMvIaApLsOvtuGcVqMkwAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:17.054129 2026] [security2:error] [pid 782784:tid 782973] [client 40.77.167.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuMvIaApLsOvtuGcVqMhwAAADs"]
[Thu Jul 30 12:41:17.079744 2026] [security2:error] [pid 782784:tid 782958] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMvIaApLsOvtuGcVqMeAAALCQ"]
[Thu Jul 30 12:41:17.243417 2026] [security2:error] [pid 782784:tid 782954] [client 85.204.70.98:35766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuMvYaApLsOvtuGcVqMpAAAACg"]
[Thu Jul 30 12:41:17.368342 2026] [core:notice] [pid 782784:tid 782916] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:17.524064 2026] [security2:error] [pid 782784:tid 782969] [client 85.204.70.98:18163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuMvYaApLsOvtuGcVqMrQAAADc"]
[Thu Jul 30 12:41:17.581106 2026] [core:notice] [pid 782784:tid 783035] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:17.585337 2026] [security2:error] [pid 782784:tid 783035] [client 103.215.74.26:21850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "770"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMvYaApLsOvtuGcVqMrwAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:17.804795 2026] [security2:error] [pid 782784:tid 782995] [client 85.204.70.98:35778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuMvYaApLsOvtuGcVqMugAAAFE"]
[Thu Jul 30 12:41:18.105057 2026] [security2:error] [pid 782784:tid 782924] [client 85.204.70.98:35780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuMvoaApLsOvtuGcVqMxAAAAAo"]
[Thu Jul 30 12:41:18.126480 2026] [security2:error] [pid 782784:tid 782854] [remote 74.7.241.60:38562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amuMvoaApLsOvtuGcVqMxQAAIkU"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 12:41:18.299784 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:18.306528 2026] [security2:error] [pid 782784:tid 783025] [client 103.215.74.26:21864] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMvoaApLsOvtuGcVqMzAAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:18.386950 2026] [security2:error] [pid 782784:tid 782927] [client 85.204.70.98:35782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuMvoaApLsOvtuGcVqM0wAAAA0"]
[Thu Jul 30 12:41:18.616169 2026] [security2:error] [pid 782784:tid 782956] [client 20.63.98.115:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/edit-form.php"] [unique_id "amuMvoaApLsOvtuGcVqM1AAAACo"]
[Thu Jul 30 12:41:18.678231 2026] [security2:error] [pid 782784:tid 783021] [client 85.204.70.98:35784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuMvoaApLsOvtuGcVqM1QAAAGs"]
[Thu Jul 30 12:41:18.980607 2026] [security2:error] [pid 782784:tid 783040] [client 85.204.70.98:35798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuMvoaApLsOvtuGcVqM4gAAAH4"]
[Thu Jul 30 12:41:19.045255 2026] [core:notice] [pid 782784:tid 782961] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:19.050257 2026] [security2:error] [pid 782784:tid 782961] [client 103.215.74.26:21872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "783"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMv4aApLsOvtuGcVqM5AAAAC8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:19.226815 2026] [security2:error] [pid 782784:tid 782945] [client 85.204.70.98:35810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuMv4aApLsOvtuGcVqM5QAAAB8"]
[Thu Jul 30 12:41:19.277252 2026] [core:notice] [pid 782784:tid 782865] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:19.528367 2026] [security2:error] [pid 782784:tid 782931] [client 85.204.70.98:35818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuMv4aApLsOvtuGcVqM8wAAABE"]
[Thu Jul 30 12:41:19.804152 2026] [security2:error] [pid 782784:tid 782926] [client 85.204.70.98:35828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuMv4aApLsOvtuGcVqM9wAAAAw"]
[Thu Jul 30 12:41:19.815680 2026] [core:notice] [pid 782784:tid 782960] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:19.819745 2026] [security2:error] [pid 782784:tid 782960] [client 103.215.74.26:21884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMv4aApLsOvtuGcVqM-QAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:20.106780 2026] [security2:error] [pid 782784:tid 782924] [client 85.204.70.98:56895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.pkfye.ye"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuMwIaApLsOvtuGcVqNAwAAAAo"]
[Thu Jul 30 12:41:20.268664 2026] [security2:error] [pid 782784:tid 782978] [client 20.91.199.21:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/admin.php"] [unique_id "amuMwIaApLsOvtuGcVqNBAAAAEA"]
[Thu Jul 30 12:41:20.314226 2026] [security2:error] [pid 782784:tid 782875] [remote 216.73.216.152:31339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuMwIaApLsOvtuGcVqNBgAAc1o"]
[Thu Jul 30 12:41:20.530453 2026] [core:notice] [pid 782784:tid 782951] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:20.534812 2026] [security2:error] [pid 782784:tid 782951] [client 103.215.74.26:21896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMwIaApLsOvtuGcVqNDwAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:20.797359 2026] [security2:error] [pid 782784:tid 782998] [client 20.91.199.21:52343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/adminfuns.php"] [unique_id "amuMwIaApLsOvtuGcVqNEQAAAFQ"]
[Thu Jul 30 12:41:21.035240 2026] [security2:error] [pid 782784:tid 783015] [client 20.63.98.115:43958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/aleXus.php"] [unique_id "amuMwYaApLsOvtuGcVqNHgAAAGU"]
[Thu Jul 30 12:41:21.110877 2026] [core:notice] [pid 782784:tid 782950] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:21.331753 2026] [security2:error] [pid 782784:tid 782961] [client 150.107.232.194:26995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMwYaApLsOvtuGcVqNJAAAAC8"]
[Thu Jul 30 12:41:21.331879 2026] [security2:error] [pid 782784:tid 782961] [client 150.107.232.194:26995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMwYaApLsOvtuGcVqNJAAAAC8"]
[Thu Jul 30 12:41:22.939765 2026] [security2:error] [pid 782784:tid 782894] [remote 57.141.0.56:55868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuMwoaApLsOvtuGcVqNSQAAIm0"]
[Thu Jul 30 12:41:23.272724 2026] [security2:error] [pid 782784:tid 782927] [client 38.190.144.4:64935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMw4aApLsOvtuGcVqNVgAAAA0"]
[Thu Jul 30 12:41:23.272852 2026] [security2:error] [pid 782784:tid 782927] [client 38.190.144.4:64935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMw4aApLsOvtuGcVqNVgAAAA0"]
[Thu Jul 30 12:41:23.880596 2026] [security2:error] [pid 782784:tid 782922] [client 20.63.98.115:43914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/user.php"] [unique_id "amuMw4aApLsOvtuGcVqNaQAAAAg"]
[Thu Jul 30 12:41:24.005787 2026] [security2:error] [pid 782784:tid 782997] [client 20.91.199.21:42966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/albin.php"] [unique_id "amuMxIaApLsOvtuGcVqNbgAAAFM"]
[Thu Jul 30 12:41:24.902216 2026] [security2:error] [pid 782784:tid 782964] [client 20.63.98.115:36921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ab1ux1ft.php"] [unique_id "amuMxIaApLsOvtuGcVqNiAAAADI"]
[Thu Jul 30 12:41:26.044234 2026] [security2:error] [pid 782784:tid 783019] [client 20.91.199.21:52304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/amfsqvgv.php"] [unique_id "amuMxoaApLsOvtuGcVqNpAAAAGk"]
[Thu Jul 30 12:41:26.074390 2026] [security2:error] [pid 782784:tid 782934] [client 20.63.98.115:57152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/home/function.php"] [unique_id "amuMxoaApLsOvtuGcVqNpQAAABQ"]
[Thu Jul 30 12:41:26.325104 2026] [core:notice] [pid 782784:tid 782926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:26.329174 2026] [security2:error] [pid 782784:tid 782926] [client 103.215.74.26:34544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMxoaApLsOvtuGcVqNrwAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:26.613557 2026] [core:notice] [pid 782784:tid 782804] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.059262 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.063313 2026] [security2:error] [pid 782784:tid 783025] [client 103.215.74.26:34560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMx4aApLsOvtuGcVqNwQAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:27.273486 2026] [core:notice] [pid 782784:tid 783000] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.609647 2026] [security2:error] [pid 782784:tid 782984] [client 20.91.199.21:42962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/ant.php"] [unique_id "amuMx4aApLsOvtuGcVqN0wAAAEY"]
[Thu Jul 30 12:41:27.701603 2026] [core:notice] [pid 782784:tid 782818] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.709602 2026] [core:notice] [pid 782784:tid 782816] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.713569 2026] [core:notice] [pid 782784:tid 782819] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.713767 2026] [core:notice] [pid 782784:tid 782815] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.716844 2026] [core:notice] [pid 782784:tid 782814] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.730737 2026] [core:notice] [pid 782784:tid 782820] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.735682 2026] [core:notice] [pid 782784:tid 782822] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.742177 2026] [core:notice] [pid 782784:tid 782825] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.755812 2026] [core:notice] [pid 782784:tid 782824] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.782584 2026] [core:notice] [pid 782784:tid 782826] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.820378 2026] [core:notice] [pid 782784:tid 782927] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.825265 2026] [security2:error] [pid 782784:tid 782927] [client 103.215.74.26:34570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMx4aApLsOvtuGcVqN5QAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:27.845805 2026] [core:notice] [pid 782784:tid 782917] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:27.883497 2026] [security2:error] [pid 782784:tid 783020] [client 89.124.71.45:47128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuMx4aApLsOvtuGcVqN1AAAAGo"]
[Thu Jul 30 12:41:28.084436 2026] [security2:error] [pid 782784:tid 782999] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMx4aApLsOvtuGcVqNzwAAVRs"]
[Thu Jul 30 12:41:28.162265 2026] [security2:error] [pid 782784:tid 782950] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMx4aApLsOvtuGcVqN0gAAACQ"]
[Thu Jul 30 12:41:28.441970 2026] [security2:error] [pid 782784:tid 782915] [client 20.63.98.115:43961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-login.php"] [unique_id "amuMyIaApLsOvtuGcVqOCAAAAAE"]
[Thu Jul 30 12:41:28.483327 2026] [security2:error] [pid 782784:tid 782940] [client 185.191.171.13:59988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/13/apos-venda-da-eletrobras-22-hidreletricas-vao-ter-novas-regras-de-concessao/"] [unique_id "amuMyIaApLsOvtuGcVqOCQAAABo"]
[Thu Jul 30 12:41:28.483463 2026] [security2:error] [pid 782784:tid 782940] [client 185.191.171.13:59988] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/13/apos-venda-da-eletrobras-22-hidreletricas-vao-ter-novas-regras-de-concessao/"] [unique_id "amuMyIaApLsOvtuGcVqOCQAAABo"]
[Thu Jul 30 12:41:28.524338 2026] [core:notice] [pid 782784:tid 782843] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:28.556598 2026] [security2:error] [pid 782784:tid 783002] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuMx4aApLsOvtuGcVqN8QAAWDA"]
[Thu Jul 30 12:41:28.568312 2026] [core:notice] [pid 782784:tid 782936] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:28.569011 2026] [security2:error] [pid 782784:tid 782844] [remote 176.119.210.163:50308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.210.119.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuMyIaApLsOvtuGcVqOCwAANDs"]
[Thu Jul 30 12:41:28.572660 2026] [security2:error] [pid 782784:tid 782936] [client 103.215.74.26:34582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMyIaApLsOvtuGcVqODAAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:28.802555 2026] [core:notice] [pid 782784:tid 782848] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:28.803242 2026] [core:notice] [pid 782784:tid 782846] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:28.823694 2026] [core:notice] [pid 782784:tid 782847] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:28.826525 2026] [core:notice] [pid 782784:tid 782851] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:28.827656 2026] [core:error] [pid 782784:tid 782849] [remote 74.7.244.5:59220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:41:28.827679 2026] [core:error] [pid 782784:tid 782849] [remote 74.7.244.5:59220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:41:28.827871 2026] [security2:error] [pid 782784:tid 783018] [client 74.7.244.5:59220] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-c84df7de.ooj.hfl.temporary.site"] [uri "/website_c84df7de/index.php"] [unique_id "amuMyIaApLsOvtuGcVqOFAAAaEA"]
[Thu Jul 30 12:41:29.026026 2026] [core:notice] [pid 782784:tid 782856] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.029083 2026] [core:notice] [pid 782784:tid 782855] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.030509 2026] [core:notice] [pid 782784:tid 782857] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.032934 2026] [core:notice] [pid 782784:tid 782858] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.036058 2026] [core:notice] [pid 782784:tid 782850] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.041748 2026] [core:notice] [pid 782784:tid 782859] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.045862 2026] [core:notice] [pid 782784:tid 782860] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.055338 2026] [core:notice] [pid 782784:tid 782861] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.056488 2026] [core:notice] [pid 782784:tid 782862] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.065172 2026] [core:notice] [pid 782784:tid 782865] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.079198 2026] [core:notice] [pid 782784:tid 782864] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.106008 2026] [core:notice] [pid 782784:tid 782866] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.106240 2026] [core:notice] [pid 782784:tid 782867] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.119376 2026] [core:notice] [pid 782784:tid 782869] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.142235 2026] [core:notice] [pid 782784:tid 782863] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.288531 2026] [core:notice] [pid 782784:tid 782914] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.292660 2026] [security2:error] [pid 782784:tid 782914] [client 103.215.74.26:34590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMyYaApLsOvtuGcVqOMAAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:29.591077 2026] [core:notice] [pid 782784:tid 782876] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.769115 2026] [security2:error] [pid 782784:tid 782951] [client 89.124.71.45:47150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuMyYaApLsOvtuGcVqOQAAAACU"]
[Thu Jul 30 12:41:29.935426 2026] [security2:error] [pid 782784:tid 782940] [client 20.91.199.21:48402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/appreciators.php"] [unique_id "amuMyYaApLsOvtuGcVqOSwAAABo"]
[Thu Jul 30 12:41:29.941847 2026] [core:notice] [pid 782784:tid 782880] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:29.956954 2026] [security2:error] [pid 782784:tid 782883] [remote 103.253.21.184:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.21.253.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuMyYaApLsOvtuGcVqOTQAAWmI"]
[Thu Jul 30 12:41:30.018648 2026] [core:notice] [pid 782784:tid 782966] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:30.023360 2026] [security2:error] [pid 782784:tid 782966] [client 103.215.74.26:34592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMyoaApLsOvtuGcVqOUQAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:30.753339 2026] [core:notice] [pid 782784:tid 782928] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:30.761047 2026] [security2:error] [pid 782784:tid 782928] [client 103.215.74.26:34604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMyoaApLsOvtuGcVqOYwAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:30.830051 2026] [security2:error] [pid 782784:tid 782957] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuMyoaApLsOvtuGcVqOVQAAACs"]
[Thu Jul 30 12:41:31.031364 2026] [core:notice] [pid 782784:tid 782895] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:31.255590 2026] [security2:error] [pid 782784:tid 783010] [client 89.124.71.45:35198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuMy4aApLsOvtuGcVqOdAAAAGA"]
[Thu Jul 30 12:41:31.349350 2026] [security2:error] [pid 782784:tid 782894] [remote 216.73.216.152:31339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuMy4aApLsOvtuGcVqOdQAAT20"]
[Thu Jul 30 12:41:31.397919 2026] [security2:error] [pid 782784:tid 782983] [client 193.37.252.99:45044] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuMy4aApLsOvtuGcVqOeQAAAEU"]
[Thu Jul 30 12:41:31.398061 2026] [security2:error] [pid 782784:tid 782983] [client 193.37.252.99:45044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuMy4aApLsOvtuGcVqOeQAAAEU"]
[Thu Jul 30 12:41:31.414904 2026] [core:notice] [pid 782784:tid 782898] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:31.512588 2026] [core:notice] [pid 782784:tid 782920] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:31.517600 2026] [security2:error] [pid 782784:tid 782920] [client 103.215.74.26:34616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMy4aApLsOvtuGcVqOfgAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:31.689591 2026] [security2:error] [pid 782784:tid 782969] [client 20.91.199.21:48420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/archive.php"] [unique_id "amuMy4aApLsOvtuGcVqOggAAADc"]
[Thu Jul 30 12:41:31.823385 2026] [security2:error] [pid 782784:tid 782990] [client 150.107.232.194:27122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMy4aApLsOvtuGcVqOgwAAAEw"]
[Thu Jul 30 12:41:31.823529 2026] [security2:error] [pid 782784:tid 782990] [client 150.107.232.194:27122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuMy4aApLsOvtuGcVqOgwAAAEw"]
[Thu Jul 30 12:41:32.166953 2026] [core:notice] [pid 782784:tid 782905] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:32.240952 2026] [security2:error] [pid 782784:tid 782929] [client 20.63.98.115:49752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "amuMzIaApLsOvtuGcVqOlQAAAA8"]
[Thu Jul 30 12:41:32.271527 2026] [core:notice] [pid 782784:tid 782949] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:32.275800 2026] [security2:error] [pid 782784:tid 782949] [client 103.215.74.26:34628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMzIaApLsOvtuGcVqOlgAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:32.578954 2026] [core:notice] [pid 782784:tid 783013] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:33.004266 2026] [core:notice] [pid 782784:tid 782995] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:33.009538 2026] [security2:error] [pid 782784:tid 782995] [client 103.215.74.26:34636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMzYaApLsOvtuGcVqOtAAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:33.516550 2026] [security2:error] [pid 782784:tid 782937] [client 20.91.199.21:42996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/as.php"] [unique_id "amuMzYaApLsOvtuGcVqOwAAAABc"]
[Thu Jul 30 12:41:33.647112 2026] [security2:error] [pid 782784:tid 782990] [client 193.37.252.99:45048] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuMzYaApLsOvtuGcVqOyAAAAEw"]
[Thu Jul 30 12:41:33.647205 2026] [security2:error] [pid 782784:tid 782990] [client 193.37.252.99:45048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuMzYaApLsOvtuGcVqOyAAAAEw"]
[Thu Jul 30 12:41:33.727924 2026] [core:notice] [pid 782784:tid 782977] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:33.732445 2026] [security2:error] [pid 782784:tid 782977] [client 103.215.74.26:49228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuMzYaApLsOvtuGcVqOygAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:33.951756 2026] [security2:error] [pid 782784:tid 783018] [client 20.63.98.115:57210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp.php"] [unique_id "amuMzYaApLsOvtuGcVqO0AAAAGg"]
[Thu Jul 30 12:41:34.243213 2026] [security2:error] [pid 782784:tid 783027] [client 38.190.144.4:65440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMzoaApLsOvtuGcVqO2gAAAHE"]
[Thu Jul 30 12:41:34.243354 2026] [security2:error] [pid 782784:tid 783027] [client 38.190.144.4:65440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuMzoaApLsOvtuGcVqO2gAAAHE"]
[Thu Jul 30 12:41:34.919736 2026] [security2:error] [pid 782784:tid 782995] [client 20.63.98.115:36891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/Requests/library/about.php"] [unique_id "amuMzoaApLsOvtuGcVqO9AAAAFE"]
[Thu Jul 30 12:41:35.109782 2026] [security2:error] [pid 782784:tid 783038] [client 89.124.71.45:35200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuMz4aApLsOvtuGcVqO-AAAAHw"]
[Thu Jul 30 12:41:35.678261 2026] [security2:error] [pid 782784:tid 782925] [client 20.91.199.21:52338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/atomlib.php"] [unique_id "amuMz4aApLsOvtuGcVqPCwAAAAs"]
[Thu Jul 30 12:41:36.168251 2026] [security2:error] [pid 782784:tid 782934] [client 20.63.98.115:38948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/index.php"] [unique_id "amuM0IaApLsOvtuGcVqPGAAAABQ"]
[Thu Jul 30 12:41:36.366263 2026] [security2:error] [pid 782784:tid 782824] [remote 216.73.216.152:31339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuM0IaApLsOvtuGcVqPHQAAXyc"]
[Thu Jul 30 12:41:36.539150 2026] [security2:error] [pid 782784:tid 783020] [client 20.91.199.21:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/autoload_classmap.php"] [unique_id "amuM0IaApLsOvtuGcVqPIQAAAGo"]
[Thu Jul 30 12:41:36.679572 2026] [security2:error] [pid 782784:tid 782959] [client 89.124.71.45:35202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuM0IaApLsOvtuGcVqPJwAAAC0"]
[Thu Jul 30 12:41:36.770250 2026] [security2:error] [pid 782784:tid 782919] [client 112.199.207.30:41898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM0IaApLsOvtuGcVqPIAAAAAU"], referer: http://pkf.jo
[Thu Jul 30 12:41:36.954475 2026] [security2:error] [pid 782784:tid 782988] [client 111.221.44.115:59589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "journeywomenscenter.org"] [uri "/wp-json/batch/v1"] [unique_id "amuM0IaApLsOvtuGcVqPMAAAAEo"]
[Thu Jul 30 12:41:37.033569 2026] [security2:error] [pid 782784:tid 783019] [client 20.63.98.115:20801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/asasx.php"] [unique_id "amuM0YaApLsOvtuGcVqPMQAAAGk"]
[Thu Jul 30 12:41:37.062274 2026] [security2:error] [pid 782784:tid 782917] [client 41.248.2.6:34094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM0IaApLsOvtuGcVqPLAAAAAM"], referer: http://pkf.jo
[Thu Jul 30 12:41:37.075223 2026] [security2:error] [pid 782784:tid 783040] [client 111.221.44.115:59601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "journeywomenscenter.org"] [uri "/"] [unique_id "amuM0YaApLsOvtuGcVqPMgAAAH4"]
[Thu Jul 30 12:41:37.216039 2026] [security2:error] [pid 782784:tid 782916] [client 20.91.199.21:51845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/bb.php"] [unique_id "amuM0YaApLsOvtuGcVqPPgAAAAI"]
[Thu Jul 30 12:41:37.229238 2026] [security2:error] [pid 782784:tid 782924] [client 111.221.44.115:59608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "journeywomenscenter.org"] [uri "/wp-json/batch/v1"] [unique_id "amuM0YaApLsOvtuGcVqPPwAAAAo"]
[Thu Jul 30 12:41:37.379240 2026] [security2:error] [pid 782784:tid 783005] [client 45.166.95.145:52208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM0YaApLsOvtuGcVqPMwAAAFs"], referer: http://pkf.jo
[Thu Jul 30 12:41:37.422642 2026] [security2:error] [pid 782784:tid 782931] [client 103.215.74.213:56586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/wp/"] [unique_id "amuM0YaApLsOvtuGcVqPRAAAABE"], referer: https://mail.nka.hfl.temporary.site/wp/
[Thu Jul 30 12:41:37.656859 2026] [security2:error] [pid 782784:tid 782946] [client 87.244.230.106:40551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM0YaApLsOvtuGcVqPQwAAACA"], referer: http://pkf.jo
[Thu Jul 30 12:41:37.714952 2026] [security2:error] [pid 782784:tid 782939] [client 37.237.237.3:33974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM0YaApLsOvtuGcVqPRQAAABk"], referer: http://pkf.jo
[Thu Jul 30 12:41:37.776778 2026] [security2:error] [pid 782784:tid 783025] [client 20.91.199.21:48638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/bnm.php"] [unique_id "amuM0YaApLsOvtuGcVqPUQAAAG8"]
[Thu Jul 30 12:41:38.114619 2026] [security2:error] [pid 782784:tid 783037] [client 20.63.98.115:20852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/user/wp-login.php"] [unique_id "amuM0oaApLsOvtuGcVqPVQAAAHs"]
[Thu Jul 30 12:41:38.174433 2026] [security2:error] [pid 782784:tid 783002] [client 89.124.71.45:35218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuM0oaApLsOvtuGcVqPWQAAAFg"]
[Thu Jul 30 12:41:38.334231 2026] [security2:error] [pid 782784:tid 783008] [client 202.52.40.17:47160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM0YaApLsOvtuGcVqPTQAAXjY"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxxmovies.rodeo
[Thu Jul 30 12:41:38.431377 2026] [security2:error] [pid 782784:tid 783004] [client 72.255.6.87:29158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM0YaApLsOvtuGcVqPVAAAAFo"], referer: http://pkf.jo
[Thu Jul 30 12:41:38.544316 2026] [security2:error] [pid 782784:tid 783034] [client 43.156.231.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuM0oaApLsOvtuGcVqPZQAAAHg"], referer: http://cnpinyin.com/dict1?search=%e4%b9%a1%e9%83%8a
[Thu Jul 30 12:41:38.600164 2026] [security2:error] [pid 782784:tid 783021] [client 20.91.199.21:42971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/bootstrap.php"] [unique_id "amuM0oaApLsOvtuGcVqPaAAAAGs"]
[Thu Jul 30 12:41:38.657544 2026] [security2:error] [pid 782784:tid 782938] [client 98.97.151.10:25099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM0oaApLsOvtuGcVqPZgAAABg"], referer: http://pkf.jo
[Thu Jul 30 12:41:38.691839 2026] [security2:error] [pid 782784:tid 782952] [client 194.187.251.163:53572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuM0oaApLsOvtuGcVqPbAAAACY"]
[Thu Jul 30 12:41:38.691927 2026] [security2:error] [pid 782784:tid 782952] [client 194.187.251.163:53572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuM0oaApLsOvtuGcVqPbAAAACY"]
[Thu Jul 30 12:41:38.929128 2026] [security2:error] [pid 782784:tid 783003] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuM0oaApLsOvtuGcVqPYwAAAFk"]
[Thu Jul 30 12:41:39.466426 2026] [security2:error] [pid 782784:tid 782940] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuM0oaApLsOvtuGcVqPcwAAGj4"]
[Thu Jul 30 12:41:39.470918 2026] [core:notice] [pid 782784:tid 782950] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:39.475458 2026] [security2:error] [pid 782784:tid 782950] [client 103.215.74.26:49300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM04aApLsOvtuGcVqPhAAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:39.737706 2026] [security2:error] [pid 782784:tid 782976] [client 20.91.199.21:48443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/buy.php"] [unique_id "amuM04aApLsOvtuGcVqPiAAAAD4"]
[Thu Jul 30 12:41:39.894553 2026] [security2:error] [pid 782784:tid 783005] [client 20.63.98.115:20841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "amuM04aApLsOvtuGcVqPlQAAAFs"]
[Thu Jul 30 12:41:40.070817 2026] [security2:error] [pid 782784:tid 783026] [client 89.124.71.45:35224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuM1IaApLsOvtuGcVqPlwAAAHA"]
[Thu Jul 30 12:41:40.198583 2026] [core:notice] [pid 782784:tid 782977] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:40.203036 2026] [security2:error] [pid 782784:tid 782977] [client 103.215.74.26:49306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM1IaApLsOvtuGcVqPmAAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:40.216117 2026] [security2:error] [pid 782784:tid 783037] [client 103.215.74.213:32074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/wp/wp-json/batch/v1"] [unique_id "amuM1IaApLsOvtuGcVqPmQAAAHs"], referer: https://mail.nka.hfl.temporary.site/wp/
[Thu Jul 30 12:41:40.825004 2026] [core:notice] [pid 782784:tid 782949] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:40.929546 2026] [core:notice] [pid 782784:tid 782927] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:40.933806 2026] [security2:error] [pid 782784:tid 782927] [client 103.215.74.26:49322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM1IaApLsOvtuGcVqPswAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:40.968957 2026] [security2:error] [pid 782784:tid 783004] [client 20.63.98.115:49749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/radio.php"] [unique_id "amuM1IaApLsOvtuGcVqPtwAAAFo"]
[Thu Jul 30 12:41:40.979722 2026] [security2:error] [pid 782784:tid 783009] [client 103.215.74.213:32078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/wordpress/"] [unique_id "amuM1IaApLsOvtuGcVqPuAAAAF8"], referer: https://mail.nka.hfl.temporary.site/wordpress/
[Thu Jul 30 12:41:41.596225 2026] [security2:error] [pid 782784:tid 783017] [client 89.124.71.45:60190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuM1YaApLsOvtuGcVqPygAAAGc"]
[Thu Jul 30 12:41:41.662853 2026] [core:notice] [pid 782784:tid 782916] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:41.667410 2026] [security2:error] [pid 782784:tid 782916] [client 103.215.74.26:49324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM1YaApLsOvtuGcVqPzwAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:41.778641 2026] [security2:error] [pid 782784:tid 782950] [client 103.215.74.213:32088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/wordpress/wp-json/batch/v1"] [unique_id "amuM1YaApLsOvtuGcVqP0AAAACQ"], referer: https://mail.nka.hfl.temporary.site/wordpress/
[Thu Jul 30 12:41:41.835699 2026] [security2:error] [pid 782784:tid 782998] [client 20.91.199.21:51874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/chosen.php"] [unique_id "amuM1YaApLsOvtuGcVqP1AAAAFQ"]
[Thu Jul 30 12:41:42.289323 2026] [security2:error] [pid 782784:tid 782945] [client 150.107.232.194:27330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuM1oaApLsOvtuGcVqP4AAAAB8"]
[Thu Jul 30 12:41:42.289453 2026] [security2:error] [pid 782784:tid 782945] [client 150.107.232.194:27330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuM1oaApLsOvtuGcVqP4AAAAB8"]
[Thu Jul 30 12:41:42.396999 2026] [core:notice] [pid 782784:tid 782991] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:42.401486 2026] [security2:error] [pid 782784:tid 782991] [client 103.215.74.26:49334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM1oaApLsOvtuGcVqP7QAAAE0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:42.546614 2026] [security2:error] [pid 782784:tid 782974] [client 103.215.74.213:32096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/blog/"] [unique_id "amuM1oaApLsOvtuGcVqP9wAAADw"], referer: https://mail.nka.hfl.temporary.site/blog/
[Thu Jul 30 12:41:42.592222 2026] [security2:error] [pid 782784:tid 783000] [client 37.239.225.16:50957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM1oaApLsOvtuGcVqP3wAAVl8"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fhentaihavenxxx.ru
[Thu Jul 30 12:41:43.044694 2026] [security2:error] [pid 782784:tid 782960] [client 37.236.120.176:40630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM1oaApLsOvtuGcVqP-wAALmM"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fthumbzilla.casa
[Thu Jul 30 12:41:43.137991 2026] [core:notice] [pid 782784:tid 782935] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:43.142577 2026] [security2:error] [pid 782784:tid 782935] [client 103.215.74.26:3844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM14aApLsOvtuGcVqQCwAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:43.347675 2026] [security2:error] [pid 782784:tid 783017] [client 103.215.74.213:32098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/blog/wp-json/batch/v1"] [unique_id "amuM14aApLsOvtuGcVqQDwAAAGc"], referer: https://mail.nka.hfl.temporary.site/blog/
[Thu Jul 30 12:41:43.636115 2026] [security2:error] [pid 782784:tid 782924] [client 20.91.199.21:42973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/class-wp-image.php"] [unique_id "amuM14aApLsOvtuGcVqQGwAAAAo"]
[Thu Jul 30 12:41:44.664264 2026] [security2:error] [pid 782784:tid 782962] [client 20.63.98.115:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuM2IaApLsOvtuGcVqQNQAAADA"]
[Thu Jul 30 12:41:44.918500 2026] [security2:error] [pid 782784:tid 783027] [client 38.190.144.4:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuM2IaApLsOvtuGcVqQPAAAAHE"]
[Thu Jul 30 12:41:44.918613 2026] [security2:error] [pid 782784:tid 783027] [client 38.190.144.4:49556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuM2IaApLsOvtuGcVqQPAAAAHE"]
[Thu Jul 30 12:41:45.100211 2026] [security2:error] [pid 782784:tid 782788] [remote 74.7.241.59:34906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuM2YaApLsOvtuGcVqQQAAABQM"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/insert-headers-and-footers/includes
[Thu Jul 30 12:41:45.798701 2026] [security2:error] [pid 782784:tid 782997] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuM2YaApLsOvtuGcVqQSQAAAFM"]
[Thu Jul 30 12:41:45.828901 2026] [security2:error] [pid 782784:tid 782996] [client 89.124.71.45:60194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuM2YaApLsOvtuGcVqQVgAAAFI"]
[Thu Jul 30 12:41:46.083250 2026] [security2:error] [pid 782784:tid 782978] [client 103.215.74.213:32104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/old/"] [unique_id "amuM2oaApLsOvtuGcVqQXQAAAEA"], referer: https://mail.nka.hfl.temporary.site/old/
[Thu Jul 30 12:41:46.405757 2026] [security2:error] [pid 782784:tid 782914] [client 20.63.98.115:36909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/st.php"] [unique_id "amuM2oaApLsOvtuGcVqQZQAAAAA"]
[Thu Jul 30 12:41:46.761560 2026] [security2:error] [pid 782784:tid 782991] [client 176.212.188.141:24706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM2oaApLsOvtuGcVqQZgAAAE0"], referer: http://pkf.jo
[Thu Jul 30 12:41:46.865726 2026] [security2:error] [pid 782784:tid 783006] [client 103.215.74.213:32112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/old/wp-json/batch/v1"] [unique_id "amuM2oaApLsOvtuGcVqQdwAAAFw"], referer: https://mail.nka.hfl.temporary.site/old/
[Thu Jul 30 12:41:47.001200 2026] [security2:error] [pid 782784:tid 782949] [client 169.224.91.143:13907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM2oaApLsOvtuGcVqQcAAAIxE"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxxvids.click
[Thu Jul 30 12:41:47.166262 2026] [security2:error] [pid 782784:tid 782971] [client 20.63.98.115:49770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/about.php"] [unique_id "amuM24aApLsOvtuGcVqQgQAAADk"]
[Thu Jul 30 12:41:47.864538 2026] [security2:error] [pid 782784:tid 782818] [remote 34.238.45.183:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "caflchimneysweeper.com"] [uri "/"] [unique_id "amuM24aApLsOvtuGcVqQlgAAFSE"]
[Thu Jul 30 12:41:47.955402 2026] [security2:error] [pid 782784:tid 782979] [client 20.63.98.115:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/admin.php"] [unique_id "amuM24aApLsOvtuGcVqQmQAAAEE"]
[Thu Jul 30 12:41:47.978394 2026] [security2:error] [pid 782784:tid 782950] [client 223.204.246.202:45276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM24aApLsOvtuGcVqQjwAAACQ"], referer: http://pkf.jo
[Thu Jul 30 12:41:47.981932 2026] [core:notice] [pid 782784:tid 782809] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:47.985370 2026] [core:notice] [pid 782784:tid 782815] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:48.531497 2026] [security2:error] [pid 782784:tid 782952] [client 89.124.71.45:60206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/login/index.php"] [unique_id "amuM3IaApLsOvtuGcVqQrAAAACY"]
[Thu Jul 30 12:41:48.633960 2026] [proxy:error] [pid 782784:tid 782824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:48.634028 2026] [proxy_http:error] [pid 782784:tid 782824] [remote 185.247.137.30:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.teknomalay.com:8880
[Thu Jul 30 12:41:48.634781 2026] [proxy:error] [pid 782784:tid 782824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:41:48.634825 2026] [proxy_http:error] [pid 782784:tid 782824] [remote 185.247.137.30:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.teknomalay.com:8880
[Thu Jul 30 12:41:48.871872 2026] [core:notice] [pid 782784:tid 782828] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:48.898384 2026] [core:notice] [pid 782784:tid 782974] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:48.903902 2026] [security2:error] [pid 782784:tid 782974] [client 103.215.74.26:3874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM3IaApLsOvtuGcVqQvgAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:49.074675 2026] [security2:error] [pid 782784:tid 782945] [client 20.63.98.115:36882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/admin.php"] [unique_id "amuM3YaApLsOvtuGcVqQvwAAAB8"]
[Thu Jul 30 12:41:49.107580 2026] [security2:error] [pid 782784:tid 782970] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuM3IaApLsOvtuGcVqQqwAAADg"]
[Thu Jul 30 12:41:49.249260 2026] [security2:error] [pid 782784:tid 783035] [client 20.91.199.21:48421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/classsmtps.php"] [unique_id "amuM3YaApLsOvtuGcVqQxwAAAHk"]
[Thu Jul 30 12:41:49.652435 2026] [core:notice] [pid 782784:tid 782812] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:49.687416 2026] [core:notice] [pid 782784:tid 782935] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:49.692276 2026] [security2:error] [pid 782784:tid 782935] [client 103.215.74.26:3882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM3YaApLsOvtuGcVqQ0gAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:49.714885 2026] [security2:error] [pid 782784:tid 782997] [client 204.8.98.25:34314] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuM3YaApLsOvtuGcVqQ0wAAAFM"]
[Thu Jul 30 12:41:49.714967 2026] [security2:error] [pid 782784:tid 782997] [client 204.8.98.25:34314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuM3YaApLsOvtuGcVqQ0wAAAFM"]
[Thu Jul 30 12:41:50.141394 2026] [security2:error] [pid 782784:tid 782977] [client 20.91.199.21:48428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/classwithtostring.php"] [unique_id "amuM3oaApLsOvtuGcVqQ3gAAAD8"]
[Thu Jul 30 12:41:50.213972 2026] [security2:error] [pid 782784:tid 783007] [client 103.215.74.213:34704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.nka.hfl.temporary.site"] [uri "/test/"] [unique_id "amuM3oaApLsOvtuGcVqQ4gAAAF0"], referer: https://mail.nka.hfl.temporary.site/test/
[Thu Jul 30 12:41:50.414719 2026] [core:notice] [pid 782784:tid 783015] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:50.418906 2026] [security2:error] [pid 782784:tid 783015] [client 103.215.74.26:3896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM3oaApLsOvtuGcVqQ7QAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:50.677861 2026] [security2:error] [pid 782784:tid 783006] [client 49.51.203.164:39142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.203.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuM3oaApLsOvtuGcVqQ7gAAAFw"]
[Thu Jul 30 12:41:50.949131 2026] [security2:error] [pid 782784:tid 782972] [client 103.215.74.213:34706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/test/wp-json/batch/v1"] [unique_id "amuM3oaApLsOvtuGcVqRAAAAADo"], referer: https://mail.nka.hfl.temporary.site/test/
[Thu Jul 30 12:41:51.113496 2026] [security2:error] [pid 782784:tid 782949] [client 167.100.180.245:43782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM3oaApLsOvtuGcVqQ9wAAACM"], referer: http://pkf.jo
[Thu Jul 30 12:41:51.139883 2026] [core:notice] [pid 782784:tid 782971] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:51.144476 2026] [security2:error] [pid 782784:tid 782971] [client 103.215.74.26:3938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM34aApLsOvtuGcVqRAQAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:51.746534 2026] [security2:error] [pid 782784:tid 782994] [client 103.215.74.213:34720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/dev/"] [unique_id "amuM34aApLsOvtuGcVqRFAAAAFA"], referer: https://mail.nka.hfl.temporary.site/dev/
[Thu Jul 30 12:41:51.755805 2026] [security2:error] [pid 782784:tid 782935] [client 66.249.73.64:54828] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/author/tfhk1688gmail-com/"] [unique_id "amuM34aApLsOvtuGcVqRFwAAABU"]
[Thu Jul 30 12:41:51.852326 2026] [security2:error] [pid 782784:tid 782948] [client 110.159.82.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuM34aApLsOvtuGcVqREgAAACI"], referer: https://tereashops.com/product/terea-14/
[Thu Jul 30 12:41:51.864984 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:51.869320 2026] [security2:error] [pid 782784:tid 783025] [client 103.215.74.26:3950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM34aApLsOvtuGcVqRHQAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:51.961054 2026] [core:error] [pid 782784:tid 782958] [client 103.158.210.7:45354] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:41:51.961076 2026] [core:error] [pid 782784:tid 782958] [client 103.158.210.7:45354] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:41:52.003868 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:52.061152 2026] [core:notice] [pid 782784:tid 782859] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:52.168096 2026] [security2:error] [pid 782784:tid 782927] [client 20.91.199.21:43000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/config.php"] [unique_id "amuM4IaApLsOvtuGcVqRJwAAAA0"]
[Thu Jul 30 12:41:52.231228 2026] [security2:error] [pid 782784:tid 782861] [remote 57.141.0.28:42164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuM4IaApLsOvtuGcVqRKAAAVEw"]
[Thu Jul 30 12:41:52.504041 2026] [security2:error] [pid 782784:tid 783005] [client 103.215.74.213:34726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/dev/wp-json/batch/v1"] [unique_id "amuM4IaApLsOvtuGcVqRMgAAAFs"], referer: https://mail.nka.hfl.temporary.site/dev/
[Thu Jul 30 12:41:52.621803 2026] [core:notice] [pid 782784:tid 782982] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:52.629486 2026] [security2:error] [pid 782784:tid 782982] [client 103.215.74.26:3962] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM4IaApLsOvtuGcVqRNgAAAEQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:52.636358 2026] [core:notice] [pid 782784:tid 783022] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:52.661681 2026] [security2:error] [pid 782784:tid 782942] [client 20.63.98.115:49741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuM4IaApLsOvtuGcVqROAAAABw"]
[Thu Jul 30 12:41:52.758583 2026] [security2:error] [pid 782784:tid 782980] [client 150.107.232.194:26837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuM4IaApLsOvtuGcVqROQAAAEI"]
[Thu Jul 30 12:41:52.758700 2026] [security2:error] [pid 782784:tid 782980] [client 150.107.232.194:26837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuM4IaApLsOvtuGcVqROQAAAEI"]
[Thu Jul 30 12:41:52.780650 2026] [security2:error] [pid 782784:tid 783038] [client 20.91.199.21:48613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/core.php"] [unique_id "amuM4IaApLsOvtuGcVqRPAAAAHw"]
[Thu Jul 30 12:41:53.350096 2026] [core:notice] [pid 782784:tid 783028] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:53.356606 2026] [security2:error] [pid 782784:tid 783028] [client 103.215.74.26:63810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM4YaApLsOvtuGcVqRUAAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:53.630122 2026] [security2:error] [pid 782784:tid 782936] [client 41.98.114.160:34540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM4YaApLsOvtuGcVqRTwAAABY"], referer: http://pkf.jo
[Thu Jul 30 12:41:54.087281 2026] [core:notice] [pid 782784:tid 783001] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:54.091434 2026] [security2:error] [pid 782784:tid 783001] [client 103.215.74.26:63838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM4oaApLsOvtuGcVqRcQAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:54.676532 2026] [security2:error] [pid 782784:tid 782988] [client 190.108.215.25:48246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM4oaApLsOvtuGcVqRcwAASmA"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fpussyspace.top
[Thu Jul 30 12:41:54.768537 2026] [security2:error] [pid 782784:tid 783027] [client 20.52.125.110:1666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/geju.php"] [unique_id "amuM4oaApLsOvtuGcVqRgAAAAHE"]
[Thu Jul 30 12:41:54.816086 2026] [core:notice] [pid 782784:tid 783021] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:54.821151 2026] [security2:error] [pid 782784:tid 783021] [client 103.215.74.26:63840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM4oaApLsOvtuGcVqRgQAAAGs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:54.920808 2026] [security2:error] [pid 782784:tid 782995] [client 20.63.98.115:36879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp2.php"] [unique_id "amuM4oaApLsOvtuGcVqRiQAAAFE"]
[Thu Jul 30 12:41:55.537162 2026] [core:notice] [pid 782784:tid 783028] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:55.544673 2026] [security2:error] [pid 782784:tid 783028] [client 103.215.74.26:63850] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM44aApLsOvtuGcVqRnQAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:55.605807 2026] [security2:error] [pid 782784:tid 783030] [client 20.52.125.110:1665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/plugins/about.php"] [unique_id "amuM44aApLsOvtuGcVqRpAAAAHQ"]
[Thu Jul 30 12:41:55.881189 2026] [security2:error] [pid 782784:tid 782973] [client 103.215.74.213:34758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.nka.hfl.temporary.site"] [uri "/backup/"] [unique_id "amuM44aApLsOvtuGcVqRqAAAADs"], referer: https://mail.nka.hfl.temporary.site/backup/
[Thu Jul 30 12:41:56.040284 2026] [security2:error] [pid 782784:tid 783025] [client 20.63.98.115:49791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/s.php"] [unique_id "amuM5IaApLsOvtuGcVqRsgAAAG8"]
[Thu Jul 30 12:41:56.277503 2026] [core:notice] [pid 782784:tid 782962] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:56.282831 2026] [security2:error] [pid 782784:tid 782962] [client 103.215.74.26:63870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM5IaApLsOvtuGcVqRuQAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:56.637635 2026] [security2:error] [pid 782784:tid 782922] [client 103.215.74.213:34768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/backup/wp-json/batch/v1"] [unique_id "amuM5IaApLsOvtuGcVqRwQAAAAg"], referer: https://mail.nka.hfl.temporary.site/backup/
[Thu Jul 30 12:41:56.960403 2026] [security2:error] [pid 782784:tid 782919] [client 38.190.144.4:50056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuM5IaApLsOvtuGcVqRzAAAAAU"]
[Thu Jul 30 12:41:56.960529 2026] [security2:error] [pid 782784:tid 782919] [client 38.190.144.4:50056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuM5IaApLsOvtuGcVqRzAAAAAU"]
[Thu Jul 30 12:41:57.026851 2026] [security2:error] [pid 782784:tid 782971] [client 20.63.98.115:49738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/help.php"] [unique_id "amuM5YaApLsOvtuGcVqR0AAAADk"]
[Thu Jul 30 12:41:57.037927 2026] [core:notice] [pid 782784:tid 782939] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:57.042151 2026] [security2:error] [pid 782784:tid 782939] [client 103.215.74.26:63902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM5YaApLsOvtuGcVqR0QAAABk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:57.433098 2026] [security2:error] [pid 782784:tid 782917] [client 103.215.74.213:34772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/staging/"] [unique_id "amuM5YaApLsOvtuGcVqR3AAAAAM"], referer: https://mail.nka.hfl.temporary.site/staging/
[Thu Jul 30 12:41:57.745797 2026] [security2:error] [pid 782784:tid 782924] [client 20.52.125.110:4170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp.php"] [unique_id "amuM5YaApLsOvtuGcVqR5AAAAAo"]
[Thu Jul 30 12:41:57.768113 2026] [core:notice] [pid 782784:tid 783007] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:57.773124 2026] [security2:error] [pid 782784:tid 783007] [client 103.215.74.26:63910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM5YaApLsOvtuGcVqR5QAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:58.029332 2026] [security2:error] [pid 782784:tid 783034] [client 190.60.34.227:50986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM5YaApLsOvtuGcVqR4wAAAHg"], referer: http://pkf.jo
[Thu Jul 30 12:41:58.080001 2026] [security2:error] [pid 782784:tid 782936] [client 20.63.98.115:49735] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuM5oaApLsOvtuGcVqR7wAAABY"]
[Thu Jul 30 12:41:58.080136 2026] [security2:error] [pid 782784:tid 782936] [client 20.63.98.115:49735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuM5oaApLsOvtuGcVqR7wAAABY"]
[Thu Jul 30 12:41:58.096049 2026] [security2:error] [pid 782784:tid 783020] [client 20.91.199.21:50004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/css.php"] [unique_id "amuM5oaApLsOvtuGcVqR8AAAAGo"]
[Thu Jul 30 12:41:58.170570 2026] [security2:error] [pid 782784:tid 782990] [client 103.215.74.213:33332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/staging/wp-json/batch/v1"] [unique_id "amuM5oaApLsOvtuGcVqR8QAAAEw"], referer: https://mail.nka.hfl.temporary.site/staging/
[Thu Jul 30 12:41:58.527929 2026] [core:notice] [pid 782784:tid 782968] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:58.532039 2026] [security2:error] [pid 782784:tid 782968] [client 103.215.74.26:63918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM5oaApLsOvtuGcVqR_AAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:58.594394 2026] [security2:error] [pid 782784:tid 782981] [client 195.46.129.234:61453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM5oaApLsOvtuGcVqR9QAAQwA"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fteengaysex.pro
[Thu Jul 30 12:41:58.799856 2026] [security2:error] [pid 782784:tid 782970] [client 20.91.199.21:43005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/database.php"] [unique_id "amuM5oaApLsOvtuGcVqSBAAAADg"]
[Thu Jul 30 12:41:59.253923 2026] [core:notice] [pid 782784:tid 782916] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:59.258660 2026] [security2:error] [pid 782784:tid 782916] [client 103.215.74.26:63948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM54aApLsOvtuGcVqSEgAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:59.415098 2026] [security2:error] [pid 782784:tid 783006] [client 20.52.125.110:1695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/aaa.php"] [unique_id "amuM54aApLsOvtuGcVqSFwAAAFw"]
[Thu Jul 30 12:41:59.415135 2026] [security2:error] [pid 782784:tid 782972] [client 20.63.98.115:49142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/admin/upload/css.php"] [unique_id "amuM54aApLsOvtuGcVqSGAAAADo"]
[Thu Jul 30 12:41:59.881317 2026] [security2:error] [pid 782784:tid 783011] [client 20.91.199.21:42947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/db.php"] [unique_id "amuM54aApLsOvtuGcVqSJAAAAGE"]
[Thu Jul 30 12:41:59.947513 2026] [security2:error] [pid 782784:tid 782924] [client 20.52.125.110:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/hoot.php"] [unique_id "amuM54aApLsOvtuGcVqSKAAAAAo"]
[Thu Jul 30 12:41:59.981043 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:41:59.985201 2026] [security2:error] [pid 782784:tid 782952] [client 103.215.74.26:63956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM54aApLsOvtuGcVqSKQAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:41:59.991048 2026] [security2:error] [pid 782784:tid 782927] [client 103.215.74.213:33356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.nka.hfl.temporary.site"] [uri "/"] [unique_id "amuM54aApLsOvtuGcVqSKgAAAA0"], referer: https://mail.nka.hfl.temporary.site/
[Thu Jul 30 12:42:00.104568 2026] [security2:error] [pid 782784:tid 783007] [client 20.63.98.115:54144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuM6IaApLsOvtuGcVqSLQAAAF0"]
[Thu Jul 30 12:42:00.705208 2026] [core:notice] [pid 782784:tid 782988] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:00.709097 2026] [security2:error] [pid 782784:tid 782988] [client 103.215.74.26:63962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM6IaApLsOvtuGcVqSPgAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:01.117164 2026] [security2:error] [pid 782784:tid 782940] [client 20.63.98.115:38975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/autoloadclassmap.php"] [unique_id "amuM6YaApLsOvtuGcVqSRwAAABo"]
[Thu Jul 30 12:42:01.442138 2026] [core:notice] [pid 782784:tid 782928] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:01.446389 2026] [security2:error] [pid 782784:tid 782928] [client 103.215.74.26:63978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM6YaApLsOvtuGcVqSXAAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:01.568211 2026] [security2:error] [pid 782784:tid 782945] [client 20.52.125.110:1694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/about.php"] [unique_id "amuM6YaApLsOvtuGcVqSXQAAAB8"]
[Thu Jul 30 12:42:01.586237 2026] [security2:error] [pid 782784:tid 782923] [client 20.91.199.21:42753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/default.php"] [unique_id "amuM6YaApLsOvtuGcVqSXgAAAAk"]
[Thu Jul 30 12:42:01.909451 2026] [security2:error] [pid 782784:tid 782954] [client 138.199.40.165:37314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuM6YaApLsOvtuGcVqSYgAAKC4"], referer: https://trello.com/
[Thu Jul 30 12:42:02.139908 2026] [security2:error] [pid 782784:tid 783020] [client 20.52.125.110:1681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/admin.php"] [unique_id "amuM6oaApLsOvtuGcVqScwAAAGo"]
[Thu Jul 30 12:42:02.191375 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:02.195705 2026] [security2:error] [pid 782784:tid 783025] [client 103.215.74.26:63984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM6oaApLsOvtuGcVqSdQAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:02.760632 2026] [security2:error] [pid 782784:tid 782931] [client 103.215.74.213:33358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nka.hfl.temporary.site"] [uri "/index.php/wp-json/batch/v1"] [unique_id "amuM6oaApLsOvtuGcVqSggAAABE"], referer: https://mail.nka.hfl.temporary.site/
[Thu Jul 30 12:42:02.914061 2026] [core:notice] [pid 782784:tid 783013] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:02.918238 2026] [security2:error] [pid 782784:tid 783013] [client 103.215.74.26:63994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM6oaApLsOvtuGcVqSjgAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:03.075470 2026] [security2:error] [pid 782784:tid 782916] [client 20.52.125.110:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuM64aApLsOvtuGcVqSkQAAAAI"]
[Thu Jul 30 12:42:03.086505 2026] [security2:error] [pid 782784:tid 782975] [client 82.229.104.202:56030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM6oaApLsOvtuGcVqShQAAAD0"], referer: http://pkf.jo
[Thu Jul 30 12:42:03.236768 2026] [security2:error] [pid 782784:tid 782966] [client 150.107.232.194:27417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuM64aApLsOvtuGcVqSlAAAADQ"]
[Thu Jul 30 12:42:03.236905 2026] [security2:error] [pid 782784:tid 782966] [client 150.107.232.194:27417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuM64aApLsOvtuGcVqSlAAAADQ"]
[Thu Jul 30 12:42:03.492410 2026] [security2:error] [pid 782784:tid 782942] [client 195.96.143.42:53989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM64aApLsOvtuGcVqSkwAAHEA"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Frawmpeg.com
[Thu Jul 30 12:42:03.634579 2026] [core:notice] [pid 782784:tid 783017] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:03.639068 2026] [security2:error] [pid 782784:tid 783017] [client 103.215.74.26:22248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM64aApLsOvtuGcVqSpAAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:03.667053 2026] [security2:error] [pid 782784:tid 783008] [client 20.63.98.115:54148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/x.php"] [unique_id "amuM64aApLsOvtuGcVqSpQAAAF4"]
[Thu Jul 30 12:42:04.201242 2026] [security2:error] [pid 782784:tid 782937] [client 20.52.125.110:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/db-cache.php"] [unique_id "amuM7IaApLsOvtuGcVqSvAAAABc"]
[Thu Jul 30 12:42:04.371688 2026] [core:notice] [pid 782784:tid 782967] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:04.375799 2026] [security2:error] [pid 782784:tid 782967] [client 103.215.74.26:22256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM7IaApLsOvtuGcVqSvwAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:04.567751 2026] [core:notice] [pid 782784:tid 782871] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:05.027969 2026] [core:notice] [pid 782784:tid 782885] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:05.103472 2026] [core:notice] [pid 782784:tid 782956] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:05.108200 2026] [security2:error] [pid 782784:tid 782956] [client 103.215.74.26:22264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM7YaApLsOvtuGcVqS5AAAACo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:05.206627 2026] [security2:error] [pid 782784:tid 782880] [remote 97.74.87.194:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuM7YaApLsOvtuGcVqS6QAAAV8"]
[Thu Jul 30 12:42:05.380112 2026] [core:notice] [pid 782784:tid 782891] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:05.700806 2026] [security2:error] [pid 782784:tid 782917] [client 20.63.98.115:47305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-class.php"] [unique_id "amuM7YaApLsOvtuGcVqS-QAAAAM"]
[Thu Jul 30 12:42:05.831624 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:05.838768 2026] [security2:error] [pid 782784:tid 783025] [client 103.215.74.26:22280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM7YaApLsOvtuGcVqS-gAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:05.853146 2026] [security2:error] [pid 782784:tid 782958] [client 20.52.125.110:4186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuM7YaApLsOvtuGcVqS-wAAACw"]
[Thu Jul 30 12:42:06.593732 2026] [core:notice] [pid 782784:tid 783032] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:06.598378 2026] [security2:error] [pid 782784:tid 783032] [client 103.215.74.26:22302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM7oaApLsOvtuGcVqTGAAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:06.721384 2026] [security2:error] [pid 782784:tid 783033] [client 20.63.98.115:21022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/content.php"] [unique_id "amuM7oaApLsOvtuGcVqTHwAAAHc"]
[Thu Jul 30 12:42:06.753546 2026] [security2:error] [pid 782784:tid 782933] [client 38.190.144.4:50559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuM7oaApLsOvtuGcVqTIAAAABM"]
[Thu Jul 30 12:42:06.756753 2026] [security2:error] [pid 782784:tid 782933] [client 38.190.144.4:50559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuM7oaApLsOvtuGcVqTIAAAABM"]
[Thu Jul 30 12:42:07.160131 2026] [security2:error] [pid 782784:tid 782983] [client 20.91.199.21:51870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/dropdown.php"] [unique_id "amuM74aApLsOvtuGcVqTMAAAAEU"]
[Thu Jul 30 12:42:07.237363 2026] [security2:error] [pid 782784:tid 782793] [remote 57.141.0.10:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Euclid/article/view/3294"] [unique_id "amuM74aApLsOvtuGcVqTNAAACgg"]
[Thu Jul 30 12:42:07.336384 2026] [core:notice] [pid 782784:tid 782943] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:07.341434 2026] [security2:error] [pid 782784:tid 782943] [client 103.215.74.26:22306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM74aApLsOvtuGcVqTNgAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:07.890960 2026] [security2:error] [pid 782784:tid 782947] [client 20.91.199.21:51855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/edit.php"] [unique_id "amuM74aApLsOvtuGcVqTRAAAACE"]
[Thu Jul 30 12:42:08.062702 2026] [core:notice] [pid 782784:tid 783038] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:08.066703 2026] [security2:error] [pid 782784:tid 783038] [client 103.215.74.26:22312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM8IaApLsOvtuGcVqTSwAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:08.159722 2026] [security2:error] [pid 782784:tid 783024] [client 20.63.98.115:63107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/acp.php"] [unique_id "amuM8IaApLsOvtuGcVqTTwAAAG4"]
[Thu Jul 30 12:42:09.961099 2026] [security2:error] [pid 782784:tid 782946] [client 51.120.83.160:23760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuM8YaApLsOvtuGcVqTnQAAACA"]
[Thu Jul 30 12:42:09.961247 2026] [security2:error] [pid 782784:tid 782946] [client 51.120.83.160:23760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuM8YaApLsOvtuGcVqTnQAAACA"]
[Thu Jul 30 12:42:10.028798 2026] [security2:error] [pid 782784:tid 782944] [client 109.111.122.226:44352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuM8YaApLsOvtuGcVqTlgAAAB4"], referer: http://pkf.jo
[Thu Jul 30 12:42:10.042838 2026] [security2:error] [pid 782784:tid 783027] [client 20.91.199.21:42757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/f35.php"] [unique_id "amuM8oaApLsOvtuGcVqTngAAAHE"]
[Thu Jul 30 12:42:10.315317 2026] [security2:error] [pid 782784:tid 782956] [client 20.52.125.110:1676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuM8oaApLsOvtuGcVqTrAAAACo"]
[Thu Jul 30 12:42:10.550862 2026] [security2:error] [pid 782784:tid 783017] [client 20.63.98.115:63129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/g.php"] [unique_id "amuM8oaApLsOvtuGcVqTswAAAGc"]
[Thu Jul 30 12:42:10.681702 2026] [security2:error] [pid 782784:tid 782977] [client 20.91.199.21:52578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/f7.php"] [unique_id "amuM8oaApLsOvtuGcVqTugAAAD8"]
[Thu Jul 30 12:42:10.912276 2026] [proxy:error] [pid 782784:tid 783000] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:42:10.912335 2026] [proxy_http:error] [pid 782784:tid 783000] [client 3.228.112.215:61660] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:42:10.912891 2026] [proxy:error] [pid 782784:tid 783000] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:42:10.912938 2026] [proxy_http:error] [pid 782784:tid 783000] [client 3.228.112.215:61660] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:42:10.990930 2026] [proxy:error] [pid 782784:tid 782937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:42:10.991035 2026] [proxy_http:error] [pid 782784:tid 782937] [client 3.228.112.215:15774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:42:10.991870 2026] [proxy:error] [pid 782784:tid 782937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:42:10.991930 2026] [proxy_http:error] [pid 782784:tid 782937] [client 3.228.112.215:15774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:42:11.088334 2026] [security2:error] [pid 782784:tid 782995] [client 20.52.125.110:1732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuM84aApLsOvtuGcVqT0gAAAFE"]
[Thu Jul 30 12:42:11.532275 2026] [security2:error] [pid 782784:tid 782992] [client 20.63.98.115:62711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/caches.php"] [unique_id "amuM84aApLsOvtuGcVqT4gAAAE4"]
[Thu Jul 30 12:42:12.071501 2026] [security2:error] [pid 782784:tid 782961] [client 20.52.125.110:1230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuM9IaApLsOvtuGcVqT8AAAAC8"]
[Thu Jul 30 12:42:12.698414 2026] [security2:error] [pid 782784:tid 783018] [client 20.52.125.110:1742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuM9IaApLsOvtuGcVqT_QAAAGg"]
[Thu Jul 30 12:42:13.174385 2026] [core:notice] [pid 782784:tid 782969] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:13.689817 2026] [security2:error] [pid 782784:tid 783029] [client 150.107.232.194:26686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuM9YaApLsOvtuGcVqUHQAAAHM"]
[Thu Jul 30 12:42:13.689932 2026] [security2:error] [pid 782784:tid 783029] [client 150.107.232.194:26686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuM9YaApLsOvtuGcVqUHQAAAHM"]
[Thu Jul 30 12:42:13.806211 2026] [core:notice] [pid 782784:tid 782956] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:13.811073 2026] [security2:error] [pid 782784:tid 782956] [client 103.215.74.26:27908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM9YaApLsOvtuGcVqUHgAAACo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:14.175433 2026] [security2:error] [pid 782784:tid 782959] [client 20.63.98.115:21300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuM9oaApLsOvtuGcVqULwAAAC0"]
[Thu Jul 30 12:42:14.542396 2026] [core:notice] [pid 782784:tid 782915] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:14.547120 2026] [security2:error] [pid 782784:tid 782915] [client 103.215.74.26:27922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM9oaApLsOvtuGcVqUPAAAAAE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:14.846226 2026] [security2:error] [pid 782784:tid 782949] [client 20.52.125.110:1745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/content.php"] [unique_id "amuM9oaApLsOvtuGcVqUQAAAACM"]
[Thu Jul 30 12:42:15.287855 2026] [core:notice] [pid 782784:tid 782972] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:15.292850 2026] [security2:error] [pid 782784:tid 782972] [client 103.215.74.26:27932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM94aApLsOvtuGcVqUTwAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:15.344673 2026] [security2:error] [pid 782784:tid 783019] [client 20.52.125.110:1753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuM94aApLsOvtuGcVqUUAAAAGk"]
[Thu Jul 30 12:42:15.467160 2026] [security2:error] [pid 782784:tid 782894] [remote 216.73.216.152:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuM94aApLsOvtuGcVqUXAAAcm0"]
[Thu Jul 30 12:42:16.016891 2026] [core:notice] [pid 782784:tid 782998] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:16.024441 2026] [security2:error] [pid 782784:tid 782998] [client 103.215.74.26:27936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM-IaApLsOvtuGcVqUaQAAAFQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:16.033130 2026] [security2:error] [pid 782784:tid 783017] [client 20.52.125.110:1786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuM-IaApLsOvtuGcVqUagAAAGc"]
[Thu Jul 30 12:42:16.684393 2026] [security2:error] [pid 782784:tid 782943] [client 20.52.125.110:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuM-IaApLsOvtuGcVqUgQAAAB0"]
[Thu Jul 30 12:42:16.761252 2026] [core:notice] [pid 782784:tid 782953] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:16.768418 2026] [security2:error] [pid 782784:tid 782953] [client 103.215.74.26:27940] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM-IaApLsOvtuGcVqUggAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:17.491705 2026] [core:notice] [pid 782784:tid 782941] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:17.495990 2026] [security2:error] [pid 782784:tid 782941] [client 103.215.74.26:27946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM-YaApLsOvtuGcVqUkQAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:17.521096 2026] [security2:error] [pid 782784:tid 782965] [client 38.190.144.4:51066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuM-YaApLsOvtuGcVqUkgAAADM"]
[Thu Jul 30 12:42:17.526768 2026] [security2:error] [pid 782784:tid 782965] [client 38.190.144.4:51066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuM-YaApLsOvtuGcVqUkgAAADM"]
[Thu Jul 30 12:42:17.858815 2026] [security2:error] [pid 782784:tid 782948] [client 52.167.144.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuM-YaApLsOvtuGcVqUmgAAACI"]
[Thu Jul 30 12:42:18.234276 2026] [core:notice] [pid 782784:tid 782914] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:18.241246 2026] [security2:error] [pid 782784:tid 782914] [client 103.215.74.26:27958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM-oaApLsOvtuGcVqUswAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:18.332681 2026] [security2:error] [pid 782784:tid 782970] [client 52.167.144.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuM-oaApLsOvtuGcVqUrAAAADg"]
[Thu Jul 30 12:42:18.900848 2026] [security2:error] [pid 782784:tid 782990] [client 20.52.125.110:1773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuM-oaApLsOvtuGcVqUwgAAAEw"]
[Thu Jul 30 12:42:18.979015 2026] [core:notice] [pid 782784:tid 783035] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:18.985764 2026] [security2:error] [pid 782784:tid 783035] [client 103.215.74.26:27966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM-oaApLsOvtuGcVqUxwAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:19.349098 2026] [core:notice] [pid 782784:tid 783014] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:19.351370 2026] [security2:error] [pid 782784:tid 782794] [remote 52.167.144.209:24909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA/article/view/9846"] [unique_id "amuM-4aApLsOvtuGcVqU1wAADAk"]
[Thu Jul 30 12:42:19.576185 2026] [security2:error] [pid 782784:tid 782954] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuM-oaApLsOvtuGcVqUxgAAACg"]
[Thu Jul 30 12:42:19.705046 2026] [core:notice] [pid 782784:tid 783021] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:19.709710 2026] [security2:error] [pid 782784:tid 783021] [client 103.215.74.26:27976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM-4aApLsOvtuGcVqU5AAAAGs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:19.903902 2026] [core:notice] [pid 782784:tid 782994] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:20.146859 2026] [security2:error] [pid 782784:tid 782820] [remote 74.7.241.60:41238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amuM_IaApLsOvtuGcVqU7gAACyM"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 12:42:20.430897 2026] [core:notice] [pid 782784:tid 782993] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:20.435029 2026] [security2:error] [pid 782784:tid 782993] [client 103.215.74.26:27990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM_IaApLsOvtuGcVqU-AAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:20.859196 2026] [security2:error] [pid 782784:tid 783032] [client 20.52.125.110:1225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuM_IaApLsOvtuGcVqVCAAAAHY"]
[Thu Jul 30 12:42:20.961456 2026] [security2:error] [pid 782784:tid 782981] [client 74.7.228.57:37624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aded-rdc.org"] [uri "/index.php"] [unique_id "amuM_IaApLsOvtuGcVqVCwAAQyA"]
[Thu Jul 30 12:42:20.975532 2026] [security2:error] [pid 782784:tid 782997] [client 20.63.98.115:62666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/css/about.php"] [unique_id "amuM_IaApLsOvtuGcVqVDAAAAFM"]
[Thu Jul 30 12:42:21.161719 2026] [core:notice] [pid 782784:tid 782943] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:21.165717 2026] [security2:error] [pid 782784:tid 782943] [client 103.215.74.26:27992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM_YaApLsOvtuGcVqVEAAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:21.328525 2026] [security2:error] [pid 782784:tid 783031] [client 62.102.148.158:35674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuM_YaApLsOvtuGcVqVFwAAAHU"]
[Thu Jul 30 12:42:21.328642 2026] [security2:error] [pid 782784:tid 783031] [client 62.102.148.158:35674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuM_YaApLsOvtuGcVqVFwAAAHU"]
[Thu Jul 30 12:42:21.752565 2026] [security2:error] [pid 782784:tid 782945] [client 20.52.125.110:1778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuM_YaApLsOvtuGcVqVHgAAAB8"]
[Thu Jul 30 12:42:21.884093 2026] [core:notice] [pid 782784:tid 783027] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:21.891139 2026] [security2:error] [pid 782784:tid 783027] [client 103.215.74.26:28006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM_YaApLsOvtuGcVqVKQAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:22.179455 2026] [security2:error] [pid 782784:tid 783008] [client 40.77.167.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuM_YaApLsOvtuGcVqVLAAAAF4"]
[Thu Jul 30 12:42:22.581718 2026] [security2:error] [pid 782784:tid 782973] [client 20.63.98.115:21182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/files/index.php"] [unique_id "amuM_oaApLsOvtuGcVqVPwAAADs"]
[Thu Jul 30 12:42:22.608646 2026] [core:notice] [pid 782784:tid 782999] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:22.614011 2026] [security2:error] [pid 782784:tid 782999] [client 103.215.74.26:28022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM_oaApLsOvtuGcVqVQAAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:22.884906 2026] [security2:error] [pid 782784:tid 782936] [client 20.52.125.110:1239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuM_oaApLsOvtuGcVqVRwAAABY"]
[Thu Jul 30 12:42:23.336063 2026] [core:notice] [pid 782784:tid 783037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:23.340234 2026] [security2:error] [pid 782784:tid 783037] [client 103.215.74.26:2482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuM_4aApLsOvtuGcVqVUQAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:23.459961 2026] [security2:error] [pid 782784:tid 782935] [client 20.52.125.110:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuM_4aApLsOvtuGcVqVWQAAABU"]
[Thu Jul 30 12:42:24.003021 2026] [security2:error] [pid 782784:tid 782858] [remote 216.73.216.152:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuNAIaApLsOvtuGcVqVbAAACUk"]
[Thu Jul 30 12:42:24.090660 2026] [core:notice] [pid 782784:tid 782976] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:24.095635 2026] [security2:error] [pid 782784:tid 782976] [client 103.215.74.26:2492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNAIaApLsOvtuGcVqVbQAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:24.162693 2026] [security2:error] [pid 782784:tid 783040] [client 150.107.232.194:26641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNAIaApLsOvtuGcVqVbgAAAH4"]
[Thu Jul 30 12:42:24.162807 2026] [security2:error] [pid 782784:tid 783040] [client 150.107.232.194:26641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNAIaApLsOvtuGcVqVbgAAAH4"]
[Thu Jul 30 12:42:24.413179 2026] [security2:error] [pid 782784:tid 783027] [client 20.52.125.110:1762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuNAIaApLsOvtuGcVqVegAAAHE"]
[Thu Jul 30 12:42:24.637474 2026] [security2:error] [pid 782784:tid 782864] [remote 157.55.39.58:25225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/our-services/solvent-based-coatings/valuef.php"] [unique_id "amuNAIaApLsOvtuGcVqVggAAYE8"]
[Thu Jul 30 12:42:24.748939 2026] [security2:error] [pid 782784:tid 782990] [client 51.120.83.160:23612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuNAIaApLsOvtuGcVqVhgAAAEw"]
[Thu Jul 30 12:42:24.749079 2026] [security2:error] [pid 782784:tid 782990] [client 51.120.83.160:23612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuNAIaApLsOvtuGcVqVhgAAAEw"]
[Thu Jul 30 12:42:24.816441 2026] [core:notice] [pid 782784:tid 782982] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:24.820860 2026] [security2:error] [pid 782784:tid 782982] [client 103.215.74.26:2502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNAIaApLsOvtuGcVqVhwAAAEQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:25.007345 2026] [security2:error] [pid 782784:tid 782863] [remote 216.73.216.152:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuNAYaApLsOvtuGcVqVlwAALk4"]
[Thu Jul 30 12:42:25.066167 2026] [security2:error] [pid 782784:tid 782961] [client 20.63.98.115:62684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuNAYaApLsOvtuGcVqVmAAAAC8"]
[Thu Jul 30 12:42:25.114211 2026] [security2:error] [pid 782784:tid 782964] [client 45.77.240.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNAIaApLsOvtuGcVqVkwAAADI"]
[Thu Jul 30 12:42:25.123882 2026] [security2:error] [pid 782784:tid 783037] [client 207.148.66.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNAIaApLsOvtuGcVqVlgAAAHs"]
[Thu Jul 30 12:42:25.558328 2026] [core:notice] [pid 782784:tid 782984] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:25.565614 2026] [security2:error] [pid 782784:tid 782984] [client 103.215.74.26:2516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNAYaApLsOvtuGcVqVsgAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:25.918150 2026] [core:error] [pid 782784:tid 782876] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:25.918179 2026] [core:error] [pid 782784:tid 782876] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:25.924762 2026] [core:error] [pid 782784:tid 782877] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:25.924786 2026] [core:error] [pid 782784:tid 782877] [remote 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:25.965507 2026] [core:error] [pid 782784:tid 782887] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:25.965545 2026] [core:error] [pid 782784:tid 782887] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:26.140011 2026] [security2:error] [pid 782784:tid 782993] [client 20.52.125.110:1242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuNAoaApLsOvtuGcVqV1wAAAE8"]
[Thu Jul 30 12:42:26.290087 2026] [security2:error] [pid 782784:tid 783001] [client 20.63.98.115:21282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/network/admin.php"] [unique_id "amuNAoaApLsOvtuGcVqV3wAAAFc"]
[Thu Jul 30 12:42:26.296365 2026] [security2:error] [pid 782784:tid 782961] [client 176.29.156.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNAoaApLsOvtuGcVqV3QAAAC8"]
[Thu Jul 30 12:42:26.326545 2026] [core:notice] [pid 782784:tid 782917] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:26.332030 2026] [security2:error] [pid 782784:tid 782917] [client 103.215.74.26:2518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNAoaApLsOvtuGcVqV4QAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:26.412135 2026] [security2:error] [pid 782784:tid 782981] [client 51.120.83.160:23595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/wp-login.php"] [unique_id "amuNAoaApLsOvtuGcVqV2AAAAEM"]
[Thu Jul 30 12:42:26.412317 2026] [security2:error] [pid 782784:tid 782981] [client 51.120.83.160:23595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/wp-login.php"] [unique_id "amuNAoaApLsOvtuGcVqV2AAAAEM"]
[Thu Jul 30 12:42:27.057879 2026] [core:notice] [pid 782784:tid 782982] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:27.065278 2026] [security2:error] [pid 782784:tid 782982] [client 103.215.74.26:2526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNA4aApLsOvtuGcVqWDgAAAEQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:27.293563 2026] [security2:error] [pid 782784:tid 782948] [client 20.52.125.110:1790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/banners/about.php"] [unique_id "amuNA4aApLsOvtuGcVqWEgAAACI"]
[Thu Jul 30 12:42:27.485381 2026] [security2:error] [pid 782784:tid 782922] [client 51.120.83.160:13394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/red.php"] [unique_id "amuNA4aApLsOvtuGcVqWGAAAAAg"]
[Thu Jul 30 12:42:27.485473 2026] [security2:error] [pid 782784:tid 782922] [client 51.120.83.160:13394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/red.php"] [unique_id "amuNA4aApLsOvtuGcVqWGAAAAAg"]
[Thu Jul 30 12:42:27.609334 2026] [security2:error] [pid 782784:tid 783026] [client 20.63.98.115:63388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuNA4aApLsOvtuGcVqWKwAAAHA"]
[Thu Jul 30 12:42:27.783033 2026] [core:notice] [pid 782784:tid 782994] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:27.788331 2026] [security2:error] [pid 782784:tid 782994] [client 103.215.74.26:2528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNA4aApLsOvtuGcVqWMgAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:28.168729 2026] [security2:error] [pid 782784:tid 782927] [client 38.190.144.4:51574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNBIaApLsOvtuGcVqWRgAAAA0"]
[Thu Jul 30 12:42:28.168853 2026] [security2:error] [pid 782784:tid 782927] [client 38.190.144.4:51574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNBIaApLsOvtuGcVqWRgAAAA0"]
[Thu Jul 30 12:42:28.503473 2026] [core:notice] [pid 782784:tid 782976] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:28.508810 2026] [security2:error] [pid 782784:tid 782976] [client 103.215.74.26:2536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNBIaApLsOvtuGcVqWUQAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:28.802724 2026] [security2:error] [pid 782784:tid 783040] [client 20.52.125.110:1787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/about.php"] [unique_id "amuNBIaApLsOvtuGcVqWXgAAAH4"]
[Thu Jul 30 12:42:29.239128 2026] [core:notice] [pid 782784:tid 782966] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:29.246054 2026] [security2:error] [pid 782784:tid 782966] [client 103.215.74.26:2548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNBYaApLsOvtuGcVqWbgAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:29.378872 2026] [core:notice] [pid 782784:tid 782958] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:29.382623 2026] [security2:error] [pid 782784:tid 782958] [client 66.249.74.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/index"] [unique_id "amuNBYaApLsOvtuGcVqWaAAAACw"]
[Thu Jul 30 12:42:29.479588 2026] [security2:error] [pid 782784:tid 783033] [client 20.52.125.110:1781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/about.php"] [unique_id "amuNBYaApLsOvtuGcVqWcwAAAHc"]
[Thu Jul 30 12:42:29.709332 2026] [security2:error] [pid 782784:tid 783008] [client 20.63.98.115:39228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuNBYaApLsOvtuGcVqWgQAAAF4"]
[Thu Jul 30 12:42:29.971561 2026] [core:notice] [pid 782784:tid 782985] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:29.973129 2026] [security2:error] [pid 782784:tid 782984] [client 51.120.83.160:5481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/cc.php"] [unique_id "amuNBYaApLsOvtuGcVqWlQAAAEY"]
[Thu Jul 30 12:42:29.973254 2026] [security2:error] [pid 782784:tid 782984] [client 51.120.83.160:5481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/cc.php"] [unique_id "amuNBYaApLsOvtuGcVqWlQAAAEY"]
[Thu Jul 30 12:42:29.976999 2026] [security2:error] [pid 782784:tid 782985] [client 103.215.74.26:2550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNBYaApLsOvtuGcVqWlAAAAEc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:30.349831 2026] [security2:error] [pid 782784:tid 782956] [client 20.52.125.110:1740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/Text/about.php"] [unique_id "amuNBoaApLsOvtuGcVqWowAAACo"]
[Thu Jul 30 12:42:30.702080 2026] [core:notice] [pid 782784:tid 782971] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:30.706808 2026] [security2:error] [pid 782784:tid 782971] [client 103.215.74.26:2554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNBoaApLsOvtuGcVqWsgAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:31.079740 2026] [security2:error] [pid 782784:tid 782820] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuNB4aApLsOvtuGcVqWvQAAUSM"]
[Thu Jul 30 12:42:31.079870 2026] [security2:error] [pid 782784:tid 782995] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuNB4aApLsOvtuGcVqWvQAAUSM"]
[Thu Jul 30 12:42:31.301400 2026] [security2:error] [pid 782784:tid 782931] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNBoaApLsOvtuGcVqWsQAAABE"]
[Thu Jul 30 12:42:31.301485 2026] [core:notice] [pid 782784:tid 782927] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:31.459441 2026] [security2:error] [pid 782784:tid 782835] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuNB4aApLsOvtuGcVqW3QAAMTI"]
[Thu Jul 30 12:42:31.459613 2026] [security2:error] [pid 782784:tid 782963] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuNB4aApLsOvtuGcVqW3QAAMTI"]
[Thu Jul 30 12:42:31.462884 2026] [core:notice] [pid 782784:tid 783022] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:31.470035 2026] [security2:error] [pid 782784:tid 783022] [client 103.215.74.26:2562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNB4aApLsOvtuGcVqW3gAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:31.758378 2026] [security2:error] [pid 782784:tid 782829] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuNB4aApLsOvtuGcVqW9QAAPiw"]
[Thu Jul 30 12:42:31.758548 2026] [security2:error] [pid 782784:tid 782976] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuNB4aApLsOvtuGcVqW9QAAPiw"]
[Thu Jul 30 12:42:31.911104 2026] [security2:error] [pid 782784:tid 782838] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/err.php"] [unique_id "amuNB4aApLsOvtuGcVqW_AAAZjU"]
[Thu Jul 30 12:42:31.911340 2026] [security2:error] [pid 782784:tid 783016] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/err.php"] [unique_id "amuNB4aApLsOvtuGcVqW_AAAZjU"]
[Thu Jul 30 12:42:32.197838 2026] [core:notice] [pid 782784:tid 782917] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:32.204003 2026] [security2:error] [pid 782784:tid 782917] [client 103.215.74.26:2572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNCIaApLsOvtuGcVqXEQAAAAM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:32.457345 2026] [security2:error] [pid 782784:tid 782844] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/img.php"] [unique_id "amuNCIaApLsOvtuGcVqXIAAAejs"]
[Thu Jul 30 12:42:32.457747 2026] [security2:error] [pid 782784:tid 783036] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/img.php"] [unique_id "amuNCIaApLsOvtuGcVqXIAAAejs"]
[Thu Jul 30 12:42:32.511152 2026] [security2:error] [pid 782784:tid 783032] [client 20.52.125.110:1241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuNCIaApLsOvtuGcVqXIgAAAHY"]
[Thu Jul 30 12:42:32.599036 2026] [security2:error] [pid 782784:tid 782841] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/aa.php"] [unique_id "amuNCIaApLsOvtuGcVqXNQAAUTg"]
[Thu Jul 30 12:42:32.599281 2026] [security2:error] [pid 782784:tid 782995] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/aa.php"] [unique_id "amuNCIaApLsOvtuGcVqXNQAAUTg"]
[Thu Jul 30 12:42:32.744051 2026] [security2:error] [pid 782784:tid 782837] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/av.php"] [unique_id "amuNCIaApLsOvtuGcVqXQAAAfjQ"]
[Thu Jul 30 12:42:32.744282 2026] [security2:error] [pid 782784:tid 783040] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/av.php"] [unique_id "amuNCIaApLsOvtuGcVqXQAAAfjQ"]
[Thu Jul 30 12:42:32.763210 2026] [security2:error] [pid 782784:tid 782940] [client 172.237.109.114:18867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCIaApLsOvtuGcVqXAwAAABo"]
[Thu Jul 30 12:42:32.769459 2026] [security2:error] [pid 782784:tid 782987] [client 172.237.109.114:53100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCIaApLsOvtuGcVqXAQAAAEk"]
[Thu Jul 30 12:42:32.794582 2026] [security2:error] [pid 782784:tid 783029] [client 172.237.109.114:9787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCIaApLsOvtuGcVqXAgAAAHM"]
[Thu Jul 30 12:42:32.807985 2026] [security2:error] [pid 782784:tid 783030] [client 172.237.109.114:34959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCIaApLsOvtuGcVqXCgAAAHQ"]
[Thu Jul 30 12:42:32.808169 2026] [security2:error] [pid 782784:tid 783014] [client 172.237.109.114:7800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCIaApLsOvtuGcVqXBQAAAGQ"]
[Thu Jul 30 12:42:32.826803 2026] [security2:error] [pid 782784:tid 782992] [client 172.237.109.114:18342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCIaApLsOvtuGcVqXBgAAAE4"]
[Thu Jul 30 12:42:32.827204 2026] [security2:error] [pid 782784:tid 783026] [client 172.237.109.114:6489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCIaApLsOvtuGcVqXCQAAAHA"]
[Thu Jul 30 12:42:32.827293 2026] [security2:error] [pid 782784:tid 782949] [client 172.237.109.114:61005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCIaApLsOvtuGcVqXCAAAACM"]
[Thu Jul 30 12:42:32.832947 2026] [security2:error] [pid 782784:tid 782970] [client 172.237.109.114:50120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCIaApLsOvtuGcVqXBwAAADg"]
[Thu Jul 30 12:42:32.875401 2026] [security2:error] [pid 782784:tid 782854] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/xa.php"] [unique_id "amuNCIaApLsOvtuGcVqXUgAAHkU"]
[Thu Jul 30 12:42:32.875538 2026] [security2:error] [pid 782784:tid 782944] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/xa.php"] [unique_id "amuNCIaApLsOvtuGcVqXUgAAHkU"]
[Thu Jul 30 12:42:32.935815 2026] [core:notice] [pid 782784:tid 782943] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:32.942504 2026] [security2:error] [pid 782784:tid 782943] [client 103.215.74.26:2584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNCIaApLsOvtuGcVqXVAAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:33.008335 2026] [security2:error] [pid 782784:tid 782857] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/media.php"] [unique_id "amuNCYaApLsOvtuGcVqXWAAAFEg"]
[Thu Jul 30 12:42:33.008515 2026] [security2:error] [pid 782784:tid 782934] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/media.php"] [unique_id "amuNCYaApLsOvtuGcVqXWAAAFEg"]
[Thu Jul 30 12:42:33.489273 2026] [security2:error] [pid 782784:tid 782861] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/images.php"] [unique_id "amuNCYaApLsOvtuGcVqXgAAANEw"]
[Thu Jul 30 12:42:33.489473 2026] [security2:error] [pid 782784:tid 782966] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/images.php"] [unique_id "amuNCYaApLsOvtuGcVqXgAAANEw"]
[Thu Jul 30 12:42:33.545386 2026] [security2:error] [pid 782784:tid 782970] [client 20.52.125.110:1232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/img/about.php"] [unique_id "amuNCYaApLsOvtuGcVqXhAAAADg"]
[Thu Jul 30 12:42:33.607279 2026] [security2:error] [pid 782784:tid 782960] [client 172.237.109.114:27806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCYaApLsOvtuGcVqXXAAAAC4"]
[Thu Jul 30 12:42:33.621852 2026] [security2:error] [pid 782784:tid 782856] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/gecko.php"] [unique_id "amuNCYaApLsOvtuGcVqXhwAAekc"]
[Thu Jul 30 12:42:33.622039 2026] [security2:error] [pid 782784:tid 783036] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/gecko.php"] [unique_id "amuNCYaApLsOvtuGcVqXhwAAekc"]
[Thu Jul 30 12:42:33.624345 2026] [security2:error] [pid 782784:tid 782926] [client 172.237.109.114:25006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCYaApLsOvtuGcVqXXQAAAAw"]
[Thu Jul 30 12:42:33.661191 2026] [security2:error] [pid 782784:tid 783038] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNCYaApLsOvtuGcVqXVwAAfD4"]
[Thu Jul 30 12:42:33.662685 2026] [core:notice] [pid 782784:tid 782944] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:33.667789 2026] [security2:error] [pid 782784:tid 782944] [client 103.215.74.26:58748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNCYaApLsOvtuGcVqXiQAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:33.773143 2026] [security2:error] [pid 782784:tid 782865] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/82.php"] [unique_id "amuNCYaApLsOvtuGcVqXjwAAP1A"]
[Thu Jul 30 12:42:33.773330 2026] [security2:error] [pid 782784:tid 782977] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/82.php"] [unique_id "amuNCYaApLsOvtuGcVqXjwAAP1A"]
[Thu Jul 30 12:42:33.905481 2026] [security2:error] [pid 782784:tid 782860] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/xstelth.php"] [unique_id "amuNCYaApLsOvtuGcVqXlwAAU0s"]
[Thu Jul 30 12:42:33.905689 2026] [security2:error] [pid 782784:tid 782997] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/xstelth.php"] [unique_id "amuNCYaApLsOvtuGcVqXlwAAU0s"]
[Thu Jul 30 12:42:34.043757 2026] [security2:error] [pid 782784:tid 782869] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/xp.php"] [unique_id "amuNCoaApLsOvtuGcVqXnAAAb1Q"]
[Thu Jul 30 12:42:34.043927 2026] [security2:error] [pid 782784:tid 783025] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/xp.php"] [unique_id "amuNCoaApLsOvtuGcVqXnAAAb1Q"]
[Thu Jul 30 12:42:34.071152 2026] [security2:error] [pid 782784:tid 782962] [client 51.120.83.160:14415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/log.php"] [unique_id "amuNCoaApLsOvtuGcVqXngAAADA"]
[Thu Jul 30 12:42:34.071253 2026] [security2:error] [pid 782784:tid 782962] [client 51.120.83.160:14415] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/log.php"] [unique_id "amuNCoaApLsOvtuGcVqXngAAADA"]
[Thu Jul 30 12:42:34.180739 2026] [security2:error] [pid 782784:tid 782870] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/admin.php"] [unique_id "amuNCoaApLsOvtuGcVqXqAAASVU"]
[Thu Jul 30 12:42:34.181077 2026] [security2:error] [pid 782784:tid 782987] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/admin.php"] [unique_id "amuNCoaApLsOvtuGcVqXqAAASVU"]
[Thu Jul 30 12:42:34.290761 2026] [security2:error] [pid 782784:tid 782950] [client 20.63.98.115:20780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/fonts/wp-login.php"] [unique_id "amuNCoaApLsOvtuGcVqXrwAAACQ"]
[Thu Jul 30 12:42:34.336891 2026] [security2:error] [pid 782784:tid 782875] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/adminner.php"] [unique_id "amuNCoaApLsOvtuGcVqXswAACVo"]
[Thu Jul 30 12:42:34.337373 2026] [security2:error] [pid 782784:tid 782923] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/adminner.php"] [unique_id "amuNCoaApLsOvtuGcVqXswAACVo"]
[Thu Jul 30 12:42:34.448104 2026] [core:notice] [pid 782784:tid 782965] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:34.456400 2026] [security2:error] [pid 782784:tid 782965] [client 103.215.74.26:58752] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNCoaApLsOvtuGcVqXuAAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:34.482575 2026] [security2:error] [pid 782784:tid 782877] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/a.php"] [unique_id "amuNCoaApLsOvtuGcVqXuQAAeFw"]
[Thu Jul 30 12:42:34.482889 2026] [security2:error] [pid 782784:tid 783034] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/a.php"] [unique_id "amuNCoaApLsOvtuGcVqXuQAAeFw"]
[Thu Jul 30 12:42:34.573176 2026] [security2:error] [pid 782784:tid 783031] [client 20.52.125.110:1736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/languages/about.php"] [unique_id "amuNCoaApLsOvtuGcVqXvwAAAHU"]
[Thu Jul 30 12:42:34.629765 2026] [security2:error] [pid 782784:tid 782985] [client 172.237.109.114:43151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCoaApLsOvtuGcVqXoQAAAEc"]
[Thu Jul 30 12:42:34.629820 2026] [security2:error] [pid 782784:tid 783006] [client 150.107.232.194:26655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNCoaApLsOvtuGcVqXwQAAAFw"]
[Thu Jul 30 12:42:34.629908 2026] [security2:error] [pid 782784:tid 783006] [client 150.107.232.194:26655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNCoaApLsOvtuGcVqXwQAAAFw"]
[Thu Jul 30 12:42:34.630526 2026] [security2:error] [pid 782784:tid 783010] [client 172.237.109.114:9573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCoaApLsOvtuGcVqXoAAAAGA"]
[Thu Jul 30 12:42:34.644056 2026] [security2:error] [pid 782784:tid 782887] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/k.php"] [unique_id "amuNCoaApLsOvtuGcVqXwgAAK2Y"]
[Thu Jul 30 12:42:34.644320 2026] [security2:error] [pid 782784:tid 782957] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/k.php"] [unique_id "amuNCoaApLsOvtuGcVqXwgAAK2Y"]
[Thu Jul 30 12:42:34.653260 2026] [security2:error] [pid 782784:tid 782975] [client 172.237.109.114:33233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCoaApLsOvtuGcVqXowAAAD0"]
[Thu Jul 30 12:42:34.661222 2026] [security2:error] [pid 782784:tid 782927] [client 172.237.109.114:3621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCoaApLsOvtuGcVqXpAAAAA0"]
[Thu Jul 30 12:42:34.661757 2026] [security2:error] [pid 782784:tid 782924] [client 172.237.109.114:65493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCoaApLsOvtuGcVqXogAAAAo"]
[Thu Jul 30 12:42:34.662031 2026] [security2:error] [pid 782784:tid 783037] [client 172.237.109.114:22338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCoaApLsOvtuGcVqXnwAAAHs"]
[Thu Jul 30 12:42:34.681619 2026] [security2:error] [pid 782784:tid 783019] [client 172.237.109.114:10445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCoaApLsOvtuGcVqXpQAAAGk"]
[Thu Jul 30 12:42:34.713845 2026] [security2:error] [pid 782784:tid 782993] [client 172.237.109.114:60377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCoaApLsOvtuGcVqXpwAAAE8"]
[Thu Jul 30 12:42:34.736715 2026] [security2:error] [pid 782784:tid 783000] [client 172.237.109.114:34451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNCoaApLsOvtuGcVqXpgAAAFY"]
[Thu Jul 30 12:42:34.799939 2026] [security2:error] [pid 782784:tid 782885] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/222.php"] [unique_id "amuNCoaApLsOvtuGcVqXxgAANmQ"]
[Thu Jul 30 12:42:34.800194 2026] [security2:error] [pid 782784:tid 782968] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/222.php"] [unique_id "amuNCoaApLsOvtuGcVqXxgAANmQ"]
[Thu Jul 30 12:42:34.938204 2026] [core:notice] [pid 782784:tid 782928] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:34.950410 2026] [security2:error] [pid 782784:tid 782882] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/mac.php"] [unique_id "amuNCoaApLsOvtuGcVqX2AAAOmE"]
[Thu Jul 30 12:42:34.950556 2026] [security2:error] [pid 782784:tid 782972] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/mac.php"] [unique_id "amuNCoaApLsOvtuGcVqX2AAAOmE"]
[Thu Jul 30 12:42:35.046602 2026] [security2:error] [pid 782784:tid 782878] [remote 216.73.216.152:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuNC4aApLsOvtuGcVqX2QAAC10"]
[Thu Jul 30 12:42:35.092039 2026] [core:error] [pid 782784:tid 782880] [remote 172.213.225.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:35.092061 2026] [core:error] [pid 782784:tid 782880] [remote 172.213.225.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:35.092230 2026] [security2:error] [pid 782784:tid 782962] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.allmontecristi.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuNC4aApLsOvtuGcVqX2gAAMF8"]
[Thu Jul 30 12:42:35.129831 2026] [security2:error] [pid 782784:tid 782931] [client 204.8.98.25:38536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuNC4aApLsOvtuGcVqX2wAAABE"]
[Thu Jul 30 12:42:35.129925 2026] [security2:error] [pid 782784:tid 782931] [client 204.8.98.25:38536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuNC4aApLsOvtuGcVqX2wAAABE"]
[Thu Jul 30 12:42:35.175485 2026] [core:notice] [pid 782784:tid 782986] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:35.182382 2026] [security2:error] [pid 782784:tid 782986] [client 103.215.74.26:58758] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNC4aApLsOvtuGcVqX3AAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:35.246074 2026] [core:error] [pid 782784:tid 782873] [remote 172.213.225.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:35.246092 2026] [core:error] [pid 782784:tid 782873] [remote 172.213.225.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:35.246234 2026] [security2:error] [pid 782784:tid 783009] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.allmontecristi.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuNC4aApLsOvtuGcVqX3gAAX1g"]
[Thu Jul 30 12:42:35.316335 2026] [core:notice] [pid 782784:tid 783024] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:35.398408 2026] [security2:error] [pid 782784:tid 782889] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/ops.php"] [unique_id "amuNC4aApLsOvtuGcVqX4wAABmg"]
[Thu Jul 30 12:42:35.398621 2026] [security2:error] [pid 782784:tid 782920] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/ops.php"] [unique_id "amuNC4aApLsOvtuGcVqX4wAABmg"]
[Thu Jul 30 12:42:35.674186 2026] [security2:error] [pid 782784:tid 782922] [client 20.52.125.110:1257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/customize/about.php"] [unique_id "amuNC4aApLsOvtuGcVqX7gAAAAg"]
[Thu Jul 30 12:42:35.911277 2026] [core:notice] [pid 782784:tid 782994] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:35.916034 2026] [security2:error] [pid 782784:tid 782994] [client 103.215.74.26:58772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNC4aApLsOvtuGcVqX9wAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:36.033144 2026] [security2:error] [pid 782784:tid 782898] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/8.php"] [unique_id "amuNDIaApLsOvtuGcVqX-QAAJXE"]
[Thu Jul 30 12:42:36.033394 2026] [security2:error] [pid 782784:tid 782951] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/8.php"] [unique_id "amuNDIaApLsOvtuGcVqX-QAAJXE"]
[Thu Jul 30 12:42:36.183030 2026] [security2:error] [pid 782784:tid 782900] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/FWAZ.php"] [unique_id "amuNDIaApLsOvtuGcVqYAQAAD3M"]
[Thu Jul 30 12:42:36.183206 2026] [security2:error] [pid 782784:tid 782929] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/FWAZ.php"] [unique_id "amuNDIaApLsOvtuGcVqYAQAAD3M"]
[Thu Jul 30 12:42:36.237595 2026] [security2:error] [pid 782784:tid 782924] [client 20.52.125.110:1244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuNDIaApLsOvtuGcVqYAgAAAAo"]
[Thu Jul 30 12:42:36.413645 2026] [security2:error] [pid 782784:tid 782982] [client 20.63.98.115:39188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/themes.php"] [unique_id "amuNDIaApLsOvtuGcVqYCQAAAEQ"]
[Thu Jul 30 12:42:36.576506 2026] [security2:error] [pid 782784:tid 782909] [remote 216.73.216.152:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuNDIaApLsOvtuGcVqYEQAAFXw"]
[Thu Jul 30 12:42:36.651864 2026] [core:notice] [pid 782784:tid 782944] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:36.658769 2026] [security2:error] [pid 782784:tid 782944] [client 103.215.74.26:58778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNDIaApLsOvtuGcVqYEgAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:36.908465 2026] [security2:error] [pid 782784:tid 782788] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/biufile.php"] [unique_id "amuNDIaApLsOvtuGcVqYFwAAYwM"]
[Thu Jul 30 12:42:36.908657 2026] [security2:error] [pid 782784:tid 783013] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/biufile.php"] [unique_id "amuNDIaApLsOvtuGcVqYFwAAYwM"]
[Thu Jul 30 12:42:37.053417 2026] [security2:error] [pid 782784:tid 782904] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/coffexium.php"] [unique_id "amuNDYaApLsOvtuGcVqYGwAAO3c"]
[Thu Jul 30 12:42:37.053618 2026] [security2:error] [pid 782784:tid 782973] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/coffexium.php"] [unique_id "amuNDYaApLsOvtuGcVqYGwAAO3c"]
[Thu Jul 30 12:42:37.069148 2026] [core:notice] [pid 782784:tid 782959] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:37.200786 2026] [security2:error] [pid 782784:tid 782912] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/simple.php"] [unique_id "amuNDYaApLsOvtuGcVqYIQAAJn8"]
[Thu Jul 30 12:42:37.201001 2026] [security2:error] [pid 782784:tid 782952] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/simple.php"] [unique_id "amuNDYaApLsOvtuGcVqYIQAAJn8"]
[Thu Jul 30 12:42:37.343864 2026] [security2:error] [pid 782784:tid 782903] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/fpwch.php"] [unique_id "amuNDYaApLsOvtuGcVqYKAAAbXY"]
[Thu Jul 30 12:42:37.344082 2026] [security2:error] [pid 782784:tid 783023] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/fpwch.php"] [unique_id "amuNDYaApLsOvtuGcVqYKAAAbXY"]
[Thu Jul 30 12:42:37.378429 2026] [core:notice] [pid 782784:tid 782990] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:37.385172 2026] [security2:error] [pid 782784:tid 782990] [client 103.215.74.26:58788] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNDYaApLsOvtuGcVqYLAAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:38.102568 2026] [security2:error] [pid 782784:tid 782915] [client 51.120.83.160:1297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/edit.php"] [unique_id "amuNDoaApLsOvtuGcVqYPwAAAAE"]
[Thu Jul 30 12:42:38.102672 2026] [security2:error] [pid 782784:tid 782915] [client 51.120.83.160:1297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/edit.php"] [unique_id "amuNDoaApLsOvtuGcVqYPwAAAAE"]
[Thu Jul 30 12:42:38.117116 2026] [core:notice] [pid 782784:tid 783015] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:38.121241 2026] [security2:error] [pid 782784:tid 783015] [client 103.215.74.26:58790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNDoaApLsOvtuGcVqYQAAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:38.566970 2026] [security2:error] [pid 782784:tid 782805] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/dex.php"] [unique_id "amuNDoaApLsOvtuGcVqYTgAAYxQ"]
[Thu Jul 30 12:42:38.567192 2026] [security2:error] [pid 782784:tid 783013] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/dex.php"] [unique_id "amuNDoaApLsOvtuGcVqYTgAAYxQ"]
[Thu Jul 30 12:42:38.590857 2026] [fcgid:warn] [pid 782784:tid 783041] (70014)End of file found: [client 118.194.234.29:56344] mod_fcgid: can't get data from http client
[Thu Jul 30 12:42:38.708101 2026] [security2:error] [pid 782784:tid 782936] [client 20.52.125.110:1772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuNDoaApLsOvtuGcVqYUgAAABY"]
[Thu Jul 30 12:42:38.871001 2026] [security2:error] [pid 782784:tid 782807] [remote 172.213.225.181:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.allmontecristi.com"] [uri "/1.php"] [unique_id "amuNDoaApLsOvtuGcVqYUwAAchY"]
[Thu Jul 30 12:42:38.871123 2026] [security2:error] [pid 782784:tid 782807] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/1.php"] [unique_id "amuNDoaApLsOvtuGcVqYUwAAchY"]
[Thu Jul 30 12:42:38.871317 2026] [security2:error] [pid 782784:tid 783028] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/1.php"] [unique_id "amuNDoaApLsOvtuGcVqYUwAAchY"]
[Thu Jul 30 12:42:38.899760 2026] [core:notice] [pid 782784:tid 782958] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:38.903791 2026] [security2:error] [pid 782784:tid 782958] [client 103.215.74.26:58794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNDoaApLsOvtuGcVqYVQAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:38.905057 2026] [security2:error] [pid 782784:tid 782947] [client 57.141.0.20:60984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuNDIaApLsOvtuGcVqYEwAAIXg"]
[Thu Jul 30 12:42:38.988637 2026] [security2:error] [pid 782784:tid 783012] [client 38.190.144.4:52080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNDoaApLsOvtuGcVqYWgAAAGI"]
[Thu Jul 30 12:42:38.988970 2026] [security2:error] [pid 782784:tid 783012] [client 38.190.144.4:52080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNDoaApLsOvtuGcVqYWgAAAGI"]
[Thu Jul 30 12:42:39.018677 2026] [core:error] [pid 782784:tid 782800] [remote 172.213.225.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:39.018699 2026] [core:error] [pid 782784:tid 782800] [remote 172.213.225.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:39.018878 2026] [security2:error] [pid 782784:tid 782987] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.allmontecristi.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuND4aApLsOvtuGcVqYXQAASQ8"]
[Thu Jul 30 12:42:39.092281 2026] [security2:error] [pid 782784:tid 782939] [client 20.63.98.115:20757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/if.php"] [unique_id "amuND4aApLsOvtuGcVqYYgAAABk"]
[Thu Jul 30 12:42:39.164866 2026] [security2:error] [pid 782784:tid 782809] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/config.json.php"] [unique_id "amuND4aApLsOvtuGcVqYYwAACRg"]
[Thu Jul 30 12:42:39.165095 2026] [security2:error] [pid 782784:tid 782923] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/config.json.php"] [unique_id "amuND4aApLsOvtuGcVqYYwAACRg"]
[Thu Jul 30 12:42:39.298102 2026] [security2:error] [pid 782784:tid 782811] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/k2.php"] [unique_id "amuND4aApLsOvtuGcVqYZAAATho"]
[Thu Jul 30 12:42:39.298310 2026] [security2:error] [pid 782784:tid 782992] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/k2.php"] [unique_id "amuND4aApLsOvtuGcVqYZAAATho"]
[Thu Jul 30 12:42:39.438581 2026] [security2:error] [pid 782784:tid 782794] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/raw.php"] [unique_id "amuND4aApLsOvtuGcVqYZwAAPAk"]
[Thu Jul 30 12:42:39.438743 2026] [security2:error] [pid 782784:tid 782974] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/raw.php"] [unique_id "amuND4aApLsOvtuGcVqYZwAAPAk"]
[Thu Jul 30 12:42:39.466335 2026] [security2:error] [pid 782784:tid 783030] [client 20.52.125.110:1246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuND4aApLsOvtuGcVqYaQAAAHQ"]
[Thu Jul 30 12:42:39.599537 2026] [security2:error] [pid 782784:tid 782815] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/wp.php"] [unique_id "amuND4aApLsOvtuGcVqYcAAAVB4"]
[Thu Jul 30 12:42:39.599728 2026] [security2:error] [pid 782784:tid 782998] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/wp.php"] [unique_id "amuND4aApLsOvtuGcVqYcAAAVB4"]
[Thu Jul 30 12:42:39.617868 2026] [core:notice] [pid 782784:tid 782964] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:39.622776 2026] [security2:error] [pid 782784:tid 782964] [client 103.215.74.26:58798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuND4aApLsOvtuGcVqYcQAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:39.731601 2026] [security2:error] [pid 782784:tid 782822] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/fffm.php"] [unique_id "amuND4aApLsOvtuGcVqYdQAANCU"]
[Thu Jul 30 12:42:39.731803 2026] [security2:error] [pid 782784:tid 782966] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/fffm.php"] [unique_id "amuND4aApLsOvtuGcVqYdQAANCU"]
[Thu Jul 30 12:42:39.860673 2026] [core:notice] [pid 782784:tid 782820] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:39.864745 2026] [security2:error] [pid 782784:tid 782824] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/111.php"] [unique_id "amuND4aApLsOvtuGcVqYdwAARic"]
[Thu Jul 30 12:42:39.864959 2026] [security2:error] [pid 782784:tid 782984] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/111.php"] [unique_id "amuND4aApLsOvtuGcVqYdwAARic"]
[Thu Jul 30 12:42:40.021929 2026] [core:error] [pid 782784:tid 782816] [remote 172.213.225.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:40.021955 2026] [core:error] [pid 782784:tid 782816] [remote 172.213.225.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:42:40.022178 2026] [security2:error] [pid 782784:tid 782915] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cpanel.allmontecristi.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuNEIaApLsOvtuGcVqYewAAAR8"]
[Thu Jul 30 12:42:40.131337 2026] [security2:error] [pid 782784:tid 782983] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuND4aApLsOvtuGcVqYbwAAAEU"]
[Thu Jul 30 12:42:40.132249 2026] [security2:error] [pid 782784:tid 782968] [client 20.52.125.110:1731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/js/about.php"] [unique_id "amuNEIaApLsOvtuGcVqYgAAAADY"]
[Thu Jul 30 12:42:40.174605 2026] [security2:error] [pid 782784:tid 782835] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/ws.php"] [unique_id "amuNEIaApLsOvtuGcVqYhAAAFDI"]
[Thu Jul 30 12:42:40.174782 2026] [security2:error] [pid 782784:tid 782934] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/ws.php"] [unique_id "amuNEIaApLsOvtuGcVqYhAAAFDI"]
[Thu Jul 30 12:42:40.233526 2026] [core:notice] [pid 782784:tid 782814] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:40.379998 2026] [core:notice] [pid 782784:tid 782926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:40.383953 2026] [security2:error] [pid 782784:tid 782926] [client 103.215.74.26:58800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNEIaApLsOvtuGcVqYhgAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:40.474612 2026] [core:notice] [pid 782784:tid 782830] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:40.529797 2026] [security2:error] [pid 782784:tid 782828] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/coffee.php"] [unique_id "amuNEIaApLsOvtuGcVqYiwAADis"]
[Thu Jul 30 12:42:40.529956 2026] [security2:error] [pid 782784:tid 782928] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/coffee.php"] [unique_id "amuNEIaApLsOvtuGcVqYiwAADis"]
[Thu Jul 30 12:42:40.580580 2026] [security2:error] [pid 782784:tid 782927] [client 20.63.98.115:39217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/editor.php"] [unique_id "amuNEIaApLsOvtuGcVqYkgAAAA0"]
[Thu Jul 30 12:42:40.825703 2026] [security2:error] [pid 782784:tid 782976] [client 20.52.125.110:1754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuNEIaApLsOvtuGcVqYlgAAAD4"]
[Thu Jul 30 12:42:41.137634 2026] [core:notice] [pid 782784:tid 783023] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:41.143001 2026] [security2:error] [pid 782784:tid 783023] [client 103.215.74.26:58812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNEYaApLsOvtuGcVqYoQAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:41.187770 2026] [security2:error] [pid 782784:tid 782832] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/goods.php"] [unique_id "amuNEYaApLsOvtuGcVqYogAAKC8"]
[Thu Jul 30 12:42:41.188002 2026] [security2:error] [pid 782784:tid 782954] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/goods.php"] [unique_id "amuNEYaApLsOvtuGcVqYogAAKC8"]
[Thu Jul 30 12:42:41.219693 2026] [core:notice] [pid 782784:tid 782977] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:41.332871 2026] [security2:error] [pid 782784:tid 782823] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/about.php"] [unique_id "amuNEYaApLsOvtuGcVqYqQAAWCY"]
[Thu Jul 30 12:42:41.333108 2026] [security2:error] [pid 782784:tid 783002] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/about.php"] [unique_id "amuNEYaApLsOvtuGcVqYqQAAWCY"]
[Thu Jul 30 12:42:41.368521 2026] [security2:error] [pid 782784:tid 783009] [client 57.141.0.44:58914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuNEYaApLsOvtuGcVqYnQAAXxw"]
[Thu Jul 30 12:42:41.377285 2026] [security2:error] [pid 782784:tid 783017] [client 193.37.252.99:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNEYaApLsOvtuGcVqYqgAAAGc"]
[Thu Jul 30 12:42:41.377379 2026] [security2:error] [pid 782784:tid 783017] [client 193.37.252.99:38216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNEYaApLsOvtuGcVqYqgAAAGc"]
[Thu Jul 30 12:42:41.502405 2026] [security2:error] [pid 782784:tid 782842] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/about.php"] [unique_id "amuNEYaApLsOvtuGcVqYqwAAAzk"]
[Thu Jul 30 12:42:41.502635 2026] [security2:error] [pid 782784:tid 782917] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/about.php"] [unique_id "amuNEYaApLsOvtuGcVqYqwAAAzk"]
[Thu Jul 30 12:42:41.585871 2026] [security2:error] [pid 782784:tid 783026] [client 20.52.125.110:1763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuNEYaApLsOvtuGcVqYrwAAAHA"]
[Thu Jul 30 12:42:41.634992 2026] [security2:error] [pid 782784:tid 782845] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/admin.php"] [unique_id "amuNEYaApLsOvtuGcVqYsQAAKzw"]
[Thu Jul 30 12:42:41.635210 2026] [security2:error] [pid 782784:tid 782957] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/admin.php"] [unique_id "amuNEYaApLsOvtuGcVqYsQAAKzw"]
[Thu Jul 30 12:42:41.767942 2026] [security2:error] [pid 782784:tid 782843] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/inputs.php"] [unique_id "amuNEYaApLsOvtuGcVqYtQAAVjo"]
[Thu Jul 30 12:42:41.768150 2026] [security2:error] [pid 782784:tid 783000] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/inputs.php"] [unique_id "amuNEYaApLsOvtuGcVqYtQAAVjo"]
[Thu Jul 30 12:42:41.806888 2026] [security2:error] [pid 782784:tid 782965] [client 20.63.98.115:38875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/click.php"] [unique_id "amuNEYaApLsOvtuGcVqYuAAAADM"]
[Thu Jul 30 12:42:41.882953 2026] [core:notice] [pid 782784:tid 782964] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:41.886971 2026] [security2:error] [pid 782784:tid 782964] [client 103.215.74.26:58822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNEYaApLsOvtuGcVqYuQAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:42.162055 2026] [security2:error] [pid 782784:tid 782854] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/inputs.php"] [unique_id "amuNEoaApLsOvtuGcVqYwQAAREU"]
[Thu Jul 30 12:42:42.162190 2026] [security2:error] [pid 782784:tid 782982] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/inputs.php"] [unique_id "amuNEoaApLsOvtuGcVqYwQAAREU"]
[Thu Jul 30 12:42:42.250931 2026] [core:notice] [pid 782784:tid 782951] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:42.294465 2026] [security2:error] [pid 782784:tid 782858] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/adminfuns.php"] [unique_id "amuNEoaApLsOvtuGcVqYxgAAQkk"]
[Thu Jul 30 12:42:42.294657 2026] [security2:error] [pid 782784:tid 782980] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/adminfuns.php"] [unique_id "amuNEoaApLsOvtuGcVqYxgAAQkk"]
[Thu Jul 30 12:42:42.448596 2026] [security2:error] [pid 782784:tid 782852] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/404.php"] [unique_id "amuNEoaApLsOvtuGcVqYyAAAakM"]
[Thu Jul 30 12:42:42.448836 2026] [security2:error] [pid 782784:tid 783020] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/404.php"] [unique_id "amuNEoaApLsOvtuGcVqYyAAAakM"]
[Thu Jul 30 12:42:42.501018 2026] [core:notice] [pid 782784:tid 783011] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:42.621705 2026] [core:notice] [pid 782784:tid 782934] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:42.626719 2026] [security2:error] [pid 782784:tid 782934] [client 103.215.74.26:58836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNEoaApLsOvtuGcVqYygAAABQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:42.752853 2026] [security2:error] [pid 782784:tid 782850] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/xxx.php"] [unique_id "amuNEoaApLsOvtuGcVqY0QAAQ0E"]
[Thu Jul 30 12:42:42.753028 2026] [security2:error] [pid 782784:tid 782981] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/xxx.php"] [unique_id "amuNEoaApLsOvtuGcVqY0QAAQ0E"]
[Thu Jul 30 12:42:42.885556 2026] [security2:error] [pid 782784:tid 782855] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/classwithtostring.php"] [unique_id "amuNEoaApLsOvtuGcVqY1QAAIUY"]
[Thu Jul 30 12:42:42.885771 2026] [security2:error] [pid 782784:tid 782947] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/classwithtostring.php"] [unique_id "amuNEoaApLsOvtuGcVqY1QAAIUY"]
[Thu Jul 30 12:42:42.949882 2026] [security2:error] [pid 782784:tid 782988] [client 20.52.125.110:1770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuNEoaApLsOvtuGcVqY1gAAAEo"]
[Thu Jul 30 12:42:43.018533 2026] [security2:error] [pid 782784:tid 782856] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/234ff.php"] [unique_id "amuNE4aApLsOvtuGcVqY2QAAYkc"]
[Thu Jul 30 12:42:43.018708 2026] [security2:error] [pid 782784:tid 783012] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/234ff.php"] [unique_id "amuNE4aApLsOvtuGcVqY2QAAYkc"]
[Thu Jul 30 12:42:43.164222 2026] [security2:error] [pid 782784:tid 782867] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/133.php"] [unique_id "amuNE4aApLsOvtuGcVqY4AAATFI"]
[Thu Jul 30 12:42:43.164396 2026] [security2:error] [pid 782784:tid 782990] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/133.php"] [unique_id "amuNE4aApLsOvtuGcVqY4AAATFI"]
[Thu Jul 30 12:42:43.225629 2026] [security2:error] [pid 782784:tid 783039] [client 20.63.98.115:21167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/test.php7"] [unique_id "amuNE4aApLsOvtuGcVqY4QAAAH0"]
[Thu Jul 30 12:42:43.323591 2026] [security2:error] [pid 782784:tid 782859] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/wp-ws68.php"] [unique_id "amuNE4aApLsOvtuGcVqY5QAAJEo"]
[Thu Jul 30 12:42:43.323767 2026] [security2:error] [pid 782784:tid 782950] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/wp-ws68.php"] [unique_id "amuNE4aApLsOvtuGcVqY5QAAJEo"]
[Thu Jul 30 12:42:43.359699 2026] [core:notice] [pid 782784:tid 783016] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:43.364080 2026] [security2:error] [pid 782784:tid 783016] [client 103.215.74.26:9360] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNE4aApLsOvtuGcVqY5gAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:43.505930 2026] [security2:error] [pid 782784:tid 782863] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/mgrr.php"] [unique_id "amuNE4aApLsOvtuGcVqY6gAAbU4"]
[Thu Jul 30 12:42:43.506197 2026] [security2:error] [pid 782784:tid 783023] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/mgrr.php"] [unique_id "amuNE4aApLsOvtuGcVqY6gAAbU4"]
[Thu Jul 30 12:42:43.531950 2026] [security2:error] [pid 782784:tid 782923] [client 20.52.125.110:1750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/updraft/about.php"] [unique_id "amuNE4aApLsOvtuGcVqY6wAAAAk"]
[Thu Jul 30 12:42:43.670834 2026] [security2:error] [pid 782784:tid 782871] [remote 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.allmontecristi.com"] [uri "/55.php"] [unique_id "amuNE4aApLsOvtuGcVqY7wAAMVY"]
[Thu Jul 30 12:42:43.671012 2026] [security2:error] [pid 782784:tid 782963] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.allmontecristi.com"] [uri "/55.php"] [unique_id "amuNE4aApLsOvtuGcVqY7wAAMVY"]
[Thu Jul 30 12:42:44.091246 2026] [security2:error] [pid 782784:tid 783003] [client 20.52.125.110:1791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuNFIaApLsOvtuGcVqY-AAAAFk"]
[Thu Jul 30 12:42:44.097854 2026] [core:notice] [pid 782784:tid 782918] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:44.102300 2026] [security2:error] [pid 782784:tid 782918] [client 103.215.74.26:9376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNFIaApLsOvtuGcVqY-QAAAAQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:44.659811 2026] [security2:error] [pid 782784:tid 782971] [client 45.205.1.124:58281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "myabudhabidesertsafari.com"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "amuNFIaApLsOvtuGcVqZBQAAADk"]
[Thu Jul 30 12:42:44.832683 2026] [core:notice] [pid 782784:tid 783015] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:44.837858 2026] [security2:error] [pid 782784:tid 783015] [client 103.215.74.26:9378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNFIaApLsOvtuGcVqZDgAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:45.120204 2026] [security2:error] [pid 782784:tid 782944] [client 150.107.232.194:27385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNFYaApLsOvtuGcVqZGQAAAB4"]
[Thu Jul 30 12:42:45.120354 2026] [security2:error] [pid 782784:tid 782944] [client 150.107.232.194:27385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNFYaApLsOvtuGcVqZGQAAAB4"]
[Thu Jul 30 12:42:45.252802 2026] [security2:error] [pid 782784:tid 782881] [remote 185.88.154.76:55478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.154.88.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuNFIaApLsOvtuGcVqZFAAAPWA"]
[Thu Jul 30 12:42:45.283760 2026] [core:notice] [pid 782784:tid 782997] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:45.291577 2026] [security2:error] [pid 782784:tid 782930] [client 20.52.125.110:1748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/themes/about.php"] [unique_id "amuNFYaApLsOvtuGcVqZHgAAABA"]
[Thu Jul 30 12:42:45.580244 2026] [core:notice] [pid 782784:tid 783012] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:45.584668 2026] [security2:error] [pid 782784:tid 783012] [client 103.215.74.26:9382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNFYaApLsOvtuGcVqZLgAAAGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:45.903422 2026] [security2:error] [pid 782784:tid 782940] [client 20.63.98.115:21159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuNFYaApLsOvtuGcVqZOAAAABo"]
[Thu Jul 30 12:42:46.382363 2026] [security2:error] [pid 782784:tid 782917] [client 20.52.125.110:1755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/includes/about.php"] [unique_id "amuNFoaApLsOvtuGcVqZUAAAAAM"]
[Thu Jul 30 12:42:46.512427 2026] [core:notice] [pid 782784:tid 782984] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:46.882527 2026] [core:notice] [pid 782784:tid 782892] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:47.301703 2026] [security2:error] [pid 782784:tid 783022] [client 172.237.109.114:63726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZPQAAAGw"]
[Thu Jul 30 12:42:47.302512 2026] [security2:error] [pid 782784:tid 782998] [client 172.237.109.114:35205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZPgAAAFQ"]
[Thu Jul 30 12:42:47.309592 2026] [security2:error] [pid 782784:tid 782918] [client 172.237.109.114:30533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZPAAAAAQ"]
[Thu Jul 30 12:42:47.312966 2026] [security2:error] [pid 782784:tid 783019] [client 172.237.109.114:41847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZPwAAAGk"]
[Thu Jul 30 12:42:47.324099 2026] [security2:error] [pid 782784:tid 782957] [client 172.237.109.114:45690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZQgAAACs"]
[Thu Jul 30 12:42:47.324110 2026] [security2:error] [pid 782784:tid 782942] [client 172.237.109.114:56540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZQAAAABw"]
[Thu Jul 30 12:42:47.334279 2026] [security2:error] [pid 782784:tid 782970] [client 172.237.109.114:24231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZRQAAADg"]
[Thu Jul 30 12:42:47.334509 2026] [security2:error] [pid 782784:tid 783021] [client 172.237.109.114:32540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZQQAAAGs"]
[Thu Jul 30 12:42:47.340539 2026] [security2:error] [pid 782784:tid 782985] [client 172.237.109.114:9860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZRAAAAEc"]
[Thu Jul 30 12:42:47.347435 2026] [security2:error] [pid 782784:tid 783000] [client 172.237.109.114:4347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZQwAAAFY"]
[Thu Jul 30 12:42:47.358750 2026] [security2:error] [pid 782784:tid 782994] [client 172.237.109.114:43160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZRwAAAFA"]
[Thu Jul 30 12:42:47.366366 2026] [security2:error] [pid 782784:tid 782965] [client 172.237.109.114:14366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZRgAAADM"]
[Thu Jul 30 12:42:47.372156 2026] [security2:error] [pid 782784:tid 783037] [client 172.237.109.114:18021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNFoaApLsOvtuGcVqZSAAAAHs"]
[Thu Jul 30 12:42:47.450066 2026] [security2:error] [pid 782784:tid 782968] [client 20.63.98.115:63404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/content.php"] [unique_id "amuNF4aApLsOvtuGcVqZbAAAADY"]
[Thu Jul 30 12:42:47.962122 2026] [proxy:error] [pid 782784:tid 782992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:42:47.962185 2026] [proxy_http:error] [pid 782784:tid 782992] [client 143.244.47.86:9141] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:42:47.962743 2026] [proxy:error] [pid 782784:tid 782992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:42:47.962786 2026] [proxy_http:error] [pid 782784:tid 782992] [client 143.244.47.86:9141] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:42:48.359990 2026] [security2:error] [pid 782784:tid 782980] [client 20.52.125.110:1267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/images/about.php"] [unique_id "amuNGIaApLsOvtuGcVqZfAAAAEI"]
[Thu Jul 30 12:42:48.584699 2026] [security2:error] [pid 782784:tid 782984] [client 51.120.83.160:1328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/plugins.php"] [unique_id "amuNGIaApLsOvtuGcVqZhAAAAEY"]
[Thu Jul 30 12:42:48.584809 2026] [security2:error] [pid 782784:tid 782984] [client 51.120.83.160:1328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/plugins.php"] [unique_id "amuNGIaApLsOvtuGcVqZhAAAAEY"]
[Thu Jul 30 12:42:48.989434 2026] [security2:error] [pid 782784:tid 782944] [client 194.187.251.163:49706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuNGIaApLsOvtuGcVqZjQAAAB4"]
[Thu Jul 30 12:42:48.989532 2026] [security2:error] [pid 782784:tid 782944] [client 194.187.251.163:49706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuNGIaApLsOvtuGcVqZjQAAAB4"]
[Thu Jul 30 12:42:49.002652 2026] [proxy:error] [pid 782784:tid 782979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:42:49.002723 2026] [proxy_http:error] [pid 782784:tid 782979] [client 143.244.47.86:39958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:42:49.003290 2026] [proxy:error] [pid 782784:tid 782979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:42:49.003345 2026] [proxy_http:error] [pid 782784:tid 782979] [client 143.244.47.86:39958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:42:49.390757 2026] [security2:error] [pid 782784:tid 782966] [client 20.63.98.115:38863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known.php"] [unique_id "amuNGYaApLsOvtuGcVqZnwAAADQ"]
[Thu Jul 30 12:42:49.832661 2026] [security2:error] [pid 782784:tid 782989] [client 20.52.125.110:1784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuNGYaApLsOvtuGcVqZqwAAAEs"]
[Thu Jul 30 12:42:50.503232 2026] [core:notice] [pid 782784:tid 783003] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:50.569013 2026] [security2:error] [pid 782784:tid 783010] [client 20.52.125.110:1746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/images/about.php"] [unique_id "amuNGoaApLsOvtuGcVqZxQAAAGA"]
[Thu Jul 30 12:42:50.970161 2026] [security2:error] [pid 782784:tid 783040] [client 38.190.144.4:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNGoaApLsOvtuGcVqZzAAAAH4"]
[Thu Jul 30 12:42:50.972269 2026] [security2:error] [pid 782784:tid 783040] [client 38.190.144.4:52596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNGoaApLsOvtuGcVqZzAAAAH4"]
[Thu Jul 30 12:42:51.307693 2026] [core:notice] [pid 782784:tid 782957] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:51.313159 2026] [security2:error] [pid 782784:tid 782957] [client 103.215.74.26:9390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNG4aApLsOvtuGcVqZ1AAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:51.386444 2026] [security2:error] [pid 782784:tid 783006] [client 20.52.125.110:1247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/about.php"] [unique_id "amuNG4aApLsOvtuGcVqZ1gAAAFw"]
[Thu Jul 30 12:42:51.765371 2026] [security2:error] [pid 782784:tid 783028] [client 5.161.117.52:7538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuNG4aApLsOvtuGcVqZ3gAAAHI"], referer: https://globalmarks.pk/
[Thu Jul 30 12:42:51.771871 2026] [security2:error] [pid 782784:tid 782942] [client 20.63.98.115:53870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuNG4aApLsOvtuGcVqZ2gAAABw"]
[Thu Jul 30 12:42:51.896740 2026] [core:notice] [pid 782784:tid 782986] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:52.064453 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:52.068815 2026] [security2:error] [pid 782784:tid 782952] [client 103.215.74.26:9396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNHIaApLsOvtuGcVqZ7QAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:52.218607 2026] [security2:error] [pid 782784:tid 782920] [client 20.52.125.110:1789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/cgi-bin/about.php"] [unique_id "amuNHIaApLsOvtuGcVqZ7wAAAAY"]
[Thu Jul 30 12:42:52.439523 2026] [security2:error] [pid 782784:tid 782818] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/n9z13o5s.php"] [unique_id "amuNHIaApLsOvtuGcVqZ-AAAXyE"]
[Thu Jul 30 12:42:52.517430 2026] [core:notice] [pid 782784:tid 783016] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:52.639234 2026] [security2:error] [pid 782784:tid 782992] [client 66.249.73.66:49558] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/author/tfhk1688gmail-com/"] [unique_id "amuNHIaApLsOvtuGcVqaAAAAAE4"]
[Thu Jul 30 12:42:52.706638 2026] [security2:error] [pid 782784:tid 782822] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/uploads/2014/03/smile.php"] [unique_id "amuNHIaApLsOvtuGcVqaAQAAAyU"]
[Thu Jul 30 12:42:52.763356 2026] [core:notice] [pid 782784:tid 782964] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:52.802283 2026] [core:notice] [pid 782784:tid 782967] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:52.807037 2026] [security2:error] [pid 782784:tid 782967] [client 103.215.74.26:9402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNHIaApLsOvtuGcVqaAwAAADU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:53.072544 2026] [security2:error] [pid 782784:tid 783011] [client 51.120.83.160:5486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/style.php"] [unique_id "amuNHYaApLsOvtuGcVqaCQAAAGE"]
[Thu Jul 30 12:42:53.072641 2026] [security2:error] [pid 782784:tid 783011] [client 51.120.83.160:5486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/style.php"] [unique_id "amuNHYaApLsOvtuGcVqaCQAAAGE"]
[Thu Jul 30 12:42:53.523726 2026] [security2:error] [pid 782784:tid 782966] [client 85.208.96.201:25674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/09/30/obras-de-pavimentacao-em-coremas-beneficiam-mais-de-15-mil-habitantes/"] [unique_id "amuNHYaApLsOvtuGcVqaMQAAADQ"]
[Thu Jul 30 12:42:53.523851 2026] [security2:error] [pid 782784:tid 782966] [client 85.208.96.201:25674] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/09/30/obras-de-pavimentacao-em-coremas-beneficiam-mais-de-15-mil-habitantes/"] [unique_id "amuNHYaApLsOvtuGcVqaMQAAADQ"]
[Thu Jul 30 12:42:53.539800 2026] [core:notice] [pid 782784:tid 783013] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:53.544163 2026] [security2:error] [pid 782784:tid 783013] [client 103.215.74.26:33448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNHYaApLsOvtuGcVqaMgAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:53.623386 2026] [security2:error] [pid 782784:tid 782856] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ini.php"] [unique_id "amuNHYaApLsOvtuGcVqaRAAAXEc"]
[Thu Jul 30 12:42:53.959161 2026] [security2:error] [pid 782784:tid 782871] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/img/xleet.php"] [unique_id "amuNHYaApLsOvtuGcVqaUgAAW1Y"]
[Thu Jul 30 12:42:54.347354 2026] [security2:error] [pid 782784:tid 782972] [client 20.63.98.115:39105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/twenty/twenty.php"] [unique_id "amuNHoaApLsOvtuGcVqaYAAAADo"]
[Thu Jul 30 12:42:54.413397 2026] [security2:error] [pid 782784:tid 782937] [client 74.7.228.0:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.lhcconcretecontractors.co"] [uri "/index.php"] [unique_id "amuNHYaApLsOvtuGcVqaFQAAABc"]
[Thu Jul 30 12:42:54.414273 2026] [security2:error] [pid 782784:tid 783031] [client 74.7.228.0:47032] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.lhcconcretecontractors.co"] [uri "/robots.txt"] [unique_id "amuNHYaApLsOvtuGcVqaEwAAdSk"]
[Thu Jul 30 12:42:54.593593 2026] [security2:error] [pid 782784:tid 782933] [client 118.194.234.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jta.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuNHoaApLsOvtuGcVqaWgAAABM"]
[Thu Jul 30 12:42:54.616599 2026] [security2:error] [pid 782784:tid 782882] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/server.php"] [unique_id "amuNHoaApLsOvtuGcVqabwAARGE"]
[Thu Jul 30 12:42:54.942001 2026] [security2:error] [pid 782784:tid 782996] [client 204.8.98.25:47690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuNHoaApLsOvtuGcVqaegAAAFI"]
[Thu Jul 30 12:42:54.942109 2026] [security2:error] [pid 782784:tid 782996] [client 204.8.98.25:47690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuNHoaApLsOvtuGcVqaegAAAFI"]
[Thu Jul 30 12:42:54.950268 2026] [security2:error] [pid 782784:tid 782915] [client 20.52.125.110:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/gallery/about.php"] [unique_id "amuNHoaApLsOvtuGcVqaewAAAAE"]
[Thu Jul 30 12:42:55.027252 2026] [security2:error] [pid 782784:tid 782893] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/twentytwentyfive/flower.php"] [unique_id "amuNH4aApLsOvtuGcVqafAAAHmw"]
[Thu Jul 30 12:42:55.340321 2026] [security2:error] [pid 782784:tid 782894] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuNH4aApLsOvtuGcVqahQAAM20"]
[Thu Jul 30 12:42:55.384341 2026] [security2:error] [pid 782784:tid 783040] [client 20.63.98.115:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuNH4aApLsOvtuGcVqahgAAAH4"]
[Thu Jul 30 12:42:55.567438 2026] [security2:error] [pid 782784:tid 782929] [client 150.107.232.194:26712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNH4aApLsOvtuGcVqajQAAAA8"]
[Thu Jul 30 12:42:55.567545 2026] [security2:error] [pid 782784:tid 782929] [client 150.107.232.194:26712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNH4aApLsOvtuGcVqajQAAAA8"]
[Thu Jul 30 12:42:55.647929 2026] [security2:error] [pid 782784:tid 782898] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/shell1.php"] [unique_id "amuNH4aApLsOvtuGcVqajgAANnE"]
[Thu Jul 30 12:42:55.773483 2026] [security2:error] [pid 782784:tid 782902] [remote 192.250.235.30:38684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.235.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.eow.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuNH4aApLsOvtuGcVqalAAAV3U"]
[Thu Jul 30 12:42:56.010339 2026] [security2:error] [pid 782784:tid 782906] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-set.php"] [unique_id "amuNIIaApLsOvtuGcVqangAAbXk"]
[Thu Jul 30 12:42:56.176767 2026] [security2:error] [pid 782784:tid 782947] [client 20.52.125.110:1729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuNIIaApLsOvtuGcVqanwAAACE"]
[Thu Jul 30 12:42:56.319907 2026] [security2:error] [pid 782784:tid 782788] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuNIIaApLsOvtuGcVqapQAAKQM"]
[Thu Jul 30 12:42:56.369309 2026] [security2:error] [pid 782784:tid 782940] [client 20.63.98.115:39126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuNIIaApLsOvtuGcVqaqAAAABo"]
[Thu Jul 30 12:42:56.547948 2026] [fcgid:warn] [pid 782784:tid 782993] (70014)End of file found: [client 118.193.35.202:54740] mod_fcgid: can't get data from http client
[Thu Jul 30 12:42:56.669603 2026] [security2:error] [pid 782784:tid 782904] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/oauth.php"] [unique_id "amuNIIaApLsOvtuGcVqarQAAWXc"]
[Thu Jul 30 12:42:56.825878 2026] [security2:error] [pid 782784:tid 782933] [client 20.52.125.110:1768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/css/about.php"] [unique_id "amuNIIaApLsOvtuGcVqasQAAABM"]
[Thu Jul 30 12:42:56.973849 2026] [security2:error] [pid 782784:tid 782960] [client 172.237.109.114:25463] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/certificates/alseermarine.com_privkey.pem"] [unique_id "amuNIIaApLsOvtuGcVqatwAAAC4"]
[Thu Jul 30 12:42:57.363917 2026] [security2:error] [pid 782784:tid 782897] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/upfile.php"] [unique_id "amuNIYaApLsOvtuGcVqavwAAQXA"]
[Thu Jul 30 12:42:57.417209 2026] [security2:error] [pid 782784:tid 783010] [client 20.63.98.115:43286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuNIYaApLsOvtuGcVqawgAAAGA"]
[Thu Jul 30 12:42:57.490611 2026] [security2:error] [pid 782784:tid 782916] [client 172.237.109.114:58884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNIIaApLsOvtuGcVqatQAAAAI"]
[Thu Jul 30 12:42:57.540819 2026] [security2:error] [pid 782784:tid 782967] [client 172.237.109.114:5089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNIIaApLsOvtuGcVqatgAAADU"]
[Thu Jul 30 12:42:57.544057 2026] [security2:error] [pid 782784:tid 783015] [client 172.237.109.114:17880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNIIaApLsOvtuGcVqauAAAAGU"]
[Thu Jul 30 12:42:57.627874 2026] [security2:error] [pid 782784:tid 782793] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/upload_file1.php"] [unique_id "amuNIYaApLsOvtuGcVqaywAAYwg"]
[Thu Jul 30 12:42:57.685210 2026] [security2:error] [pid 782784:tid 782944] [client 20.52.125.110:1233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/images/about.php"] [unique_id "amuNIYaApLsOvtuGcVqazQAAAB4"]
[Thu Jul 30 12:42:57.943460 2026] [security2:error] [pid 782784:tid 782805] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/rafa.php"] [unique_id "amuNIYaApLsOvtuGcVqa1QAAXhQ"]
[Thu Jul 30 12:42:58.258234 2026] [security2:error] [pid 782784:tid 782803] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/maint/src_api.php"] [unique_id "amuNIoaApLsOvtuGcVqa3QAAdxI"]
[Thu Jul 30 12:42:58.456944 2026] [security2:error] [pid 782784:tid 782950] [client 172.237.109.114:40068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNIYaApLsOvtuGcVqa1gAAACQ"]
[Thu Jul 30 12:42:58.456944 2026] [security2:error] [pid 782784:tid 783001] [client 172.237.109.114:1173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNIYaApLsOvtuGcVqa1wAAAFc"]
[Thu Jul 30 12:42:58.490681 2026] [security2:error] [pid 782784:tid 782939] [client 172.237.109.114:26935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNIYaApLsOvtuGcVqa2AAAABk"]
[Thu Jul 30 12:42:58.534358 2026] [security2:error] [pid 782784:tid 782905] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/atomlib.php"] [unique_id "amuNIoaApLsOvtuGcVqa5AAAIHg"]
[Thu Jul 30 12:42:58.656853 2026] [security2:error] [pid 782784:tid 783027] [client 20.52.125.110:1780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuNIoaApLsOvtuGcVqa6gAAAHE"]
[Thu Jul 30 12:42:58.660399 2026] [security2:error] [pid 782784:tid 782990] [client 20.63.98.115:57307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "amuNIoaApLsOvtuGcVqa6wAAAEw"]
[Thu Jul 30 12:42:58.838845 2026] [security2:error] [pid 782784:tid 782810] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-trackback.php"] [unique_id "amuNIoaApLsOvtuGcVqa7AAAKRk"]
[Thu Jul 30 12:42:59.175117 2026] [security2:error] [pid 782784:tid 782818] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuNI4aApLsOvtuGcVqa-wAAMiE"]
[Thu Jul 30 12:42:59.287857 2026] [core:notice] [pid 782784:tid 783003] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:42:59.292332 2026] [security2:error] [pid 782784:tid 783003] [client 103.215.74.26:33452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNI4aApLsOvtuGcVqa_gAAAFk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:42:59.324052 2026] [security2:error] [pid 782784:tid 782982] [client 20.52.125.110:1252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuNI4aApLsOvtuGcVqa_wAAAEQ"]
[Thu Jul 30 12:42:59.393134 2026] [security2:error] [pid 782784:tid 782993] [client 40.77.167.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuNI4aApLsOvtuGcVqa9QAAAE8"]
[Thu Jul 30 12:42:59.478548 2026] [security2:error] [pid 782784:tid 782820] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/doc.php/"] [unique_id "amuNI4aApLsOvtuGcVqbBAAAaSM"]
[Thu Jul 30 12:42:59.603284 2026] [security2:error] [pid 782784:tid 782960] [client 20.63.98.115:53881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/files.php"] [unique_id "amuNI4aApLsOvtuGcVqbCAAAAC4"]
[Thu Jul 30 12:42:59.786598 2026] [security2:error] [pid 782784:tid 782825] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/error_exception.php"] [unique_id "amuNI4aApLsOvtuGcVqbDgAAfig"]
[Thu Jul 30 12:43:00.017318 2026] [core:notice] [pid 782784:tid 783022] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:00.021037 2026] [security2:error] [pid 782784:tid 783022] [client 103.215.74.26:33458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNJIaApLsOvtuGcVqbFAAAAGw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:00.092407 2026] [security2:error] [pid 782784:tid 782831] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/infos.php"] [unique_id "amuNJIaApLsOvtuGcVqbFgAAbi4"]
[Thu Jul 30 12:43:00.278527 2026] [security2:error] [pid 782784:tid 783028] [client 20.52.125.110:1771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuNJIaApLsOvtuGcVqbGgAAAHI"]
[Thu Jul 30 12:43:00.295886 2026] [core:notice] [pid 782784:tid 782830] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:00.452782 2026] [security2:error] [pid 782784:tid 782842] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/contact.php"] [unique_id "amuNJIaApLsOvtuGcVqbHgAASTk"]
[Thu Jul 30 12:43:00.640842 2026] [security2:error] [pid 782784:tid 782995] [client 38.190.144.4:53112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNJIaApLsOvtuGcVqbLAAAAFE"]
[Thu Jul 30 12:43:00.640946 2026] [security2:error] [pid 782784:tid 782995] [client 38.190.144.4:53112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNJIaApLsOvtuGcVqbLAAAAFE"]
[Thu Jul 30 12:43:00.763693 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:00.767377 2026] [security2:error] [pid 782784:tid 782952] [client 103.215.74.26:33472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNJIaApLsOvtuGcVqbMgAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:01.107651 2026] [security2:error] [pid 782784:tid 782837] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/user.php"] [unique_id "amuNJYaApLsOvtuGcVqbQwAAJTQ"]
[Thu Jul 30 12:43:01.168065 2026] [security2:error] [pid 782784:tid 783009] [client 20.52.125.110:1235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/cloud.php"] [unique_id "amuNJYaApLsOvtuGcVqbRQAAAF8"]
[Thu Jul 30 12:43:01.370561 2026] [security2:error] [pid 782784:tid 782851] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/env.php"] [unique_id "amuNJYaApLsOvtuGcVqbUwAANUI"]
[Thu Jul 30 12:43:01.470048 2026] [security2:error] [pid 782784:tid 783030] [client 47.128.121.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNJYaApLsOvtuGcVqbUgAAAHQ"]
[Thu Jul 30 12:43:01.498716 2026] [core:notice] [pid 782784:tid 782981] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:01.502892 2026] [security2:error] [pid 782784:tid 782981] [client 103.215.74.26:33478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNJYaApLsOvtuGcVqbVAAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:01.643012 2026] [security2:error] [pid 782784:tid 782857] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/uploads/de_fb_uploads/b.php"] [unique_id "amuNJYaApLsOvtuGcVqbWwAANEg"]
[Thu Jul 30 12:43:01.913388 2026] [security2:error] [pid 782784:tid 782850] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/.well-known//index.php"] [unique_id "amuNJYaApLsOvtuGcVqbYwAAW0E"]
[Thu Jul 30 12:43:01.928719 2026] [security2:error] [pid 782784:tid 782862] [remote 40.77.167.10:42264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/column/plgakuen-jisseki/job.php"] [unique_id "amuNJYaApLsOvtuGcVqbZAAAc00"]
[Thu Jul 30 12:43:02.114352 2026] [core:notice] [pid 782784:tid 782861] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:02.167335 2026] [core:notice] [pid 782784:tid 782865] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:02.188682 2026] [security2:error] [pid 782784:tid 783022] [client 20.52.125.110:1788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/cgi-bin/cloud.php"] [unique_id "amuNJoaApLsOvtuGcVqbbgAAAGw"]
[Thu Jul 30 12:43:02.241581 2026] [core:notice] [pid 782784:tid 782958] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:02.248954 2026] [security2:error] [pid 782784:tid 782958] [client 103.215.74.26:33484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNJoaApLsOvtuGcVqbbwAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:02.277056 2026] [security2:error] [pid 782784:tid 782864] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/blog/wp-content/plugins/ubh/up.php"] [unique_id "amuNJoaApLsOvtuGcVqbcAAAUU8"]
[Thu Jul 30 12:43:02.375251 2026] [core:notice] [pid 782784:tid 782847] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:02.425416 2026] [core:notice] [pid 782784:tid 782860] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:02.567922 2026] [security2:error] [pid 782784:tid 782859] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/edit.php"] [unique_id "amuNJoaApLsOvtuGcVqbeAAAIUo"]
[Thu Jul 30 12:43:02.819070 2026] [security2:error] [pid 782784:tid 783007] [client 20.52.125.110:1234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/updates.php"] [unique_id "amuNJoaApLsOvtuGcVqbggAAAF0"]
[Thu Jul 30 12:43:02.839026 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:03.239893 2026] [security2:error] [pid 782784:tid 782849] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/locks.php"] [unique_id "amuNJ4aApLsOvtuGcVqbjwAAfkA"]
[Thu Jul 30 12:43:03.436756 2026] [security2:error] [pid 782784:tid 782926] [client 20.52.125.110:4202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/css/cloud.php"] [unique_id "amuNJ4aApLsOvtuGcVqbkwAAAAw"]
[Thu Jul 30 12:43:03.548863 2026] [security2:error] [pid 782784:tid 782877] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/alfa-rex1.php"] [unique_id "amuNJ4aApLsOvtuGcVqblAAAWFw"]
[Thu Jul 30 12:43:03.813619 2026] [security2:error] [pid 782784:tid 782872] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/uploads/gfwisone.php"] [unique_id "amuNJ4aApLsOvtuGcVqbmwAABFc"]
[Thu Jul 30 12:43:03.857415 2026] [security2:error] [pid 782784:tid 783005] [client 51.120.83.160:43988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/plugins.php"] [unique_id "amuNJ4aApLsOvtuGcVqbnwAAAFs"]
[Thu Jul 30 12:43:03.857506 2026] [security2:error] [pid 782784:tid 783005] [client 51.120.83.160:43988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/plugins.php"] [unique_id "amuNJ4aApLsOvtuGcVqbnwAAAFs"]
[Thu Jul 30 12:43:04.048150 2026] [core:notice] [pid 782784:tid 782982] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:04.082587 2026] [security2:error] [pid 782784:tid 782879] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/rex/l/flower.php"] [unique_id "amuNKIaApLsOvtuGcVqbogAAd14"]
[Thu Jul 30 12:43:04.660059 2026] [security2:error] [pid 782784:tid 783028] [client 20.63.98.115:21312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/Text/index.php"] [unique_id "amuNKIaApLsOvtuGcVqbvwAAAHI"]
[Thu Jul 30 12:43:04.949490 2026] [security2:error] [pid 782784:tid 782901] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/user/post.php"] [unique_id "amuNKIaApLsOvtuGcVqbyQAAA3Q"]
[Thu Jul 30 12:43:05.030740 2026] [core:notice] [pid 782784:tid 782943] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:05.032042 2026] [security2:error] [pid 782784:tid 782943] [client 77.68.87.67:56137] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.radiojelli.com"] [uri "/"] [unique_id "amuNKYaApLsOvtuGcVqbygAAAB0"]
[Thu Jul 30 12:43:05.223546 2026] [security2:error] [pid 782784:tid 782950] [client 20.52.125.110:1272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuNKYaApLsOvtuGcVqb0QAAACQ"]
[Thu Jul 30 12:43:05.508748 2026] [security2:error] [pid 782784:tid 782911] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/file5.php"] [unique_id "amuNKYaApLsOvtuGcVqb5QAABH4"]
[Thu Jul 30 12:43:05.966572 2026] [core:notice] [pid 782784:tid 782939] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:06.037722 2026] [security2:error] [pid 782784:tid 782955] [client 150.107.232.194:26958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNKoaApLsOvtuGcVqb-AAAACk"]
[Thu Jul 30 12:43:06.037845 2026] [security2:error] [pid 782784:tid 782955] [client 150.107.232.194:26958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNKoaApLsOvtuGcVqb-AAAACk"]
[Thu Jul 30 12:43:06.202921 2026] [security2:error] [pid 782784:tid 782995] [client 20.52.125.110:1228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/img/cloud.php"] [unique_id "amuNKoaApLsOvtuGcVqb_AAAAFE"]
[Thu Jul 30 12:43:06.601576 2026] [core:error] [pid 782784:tid 783023] [client 20.63.98.115:59010] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:06.601600 2026] [core:error] [pid 782784:tid 783023] [client 20.63.98.115:59010] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:06.655689 2026] [security2:error] [pid 782784:tid 782808] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/query-standard-post.php"] [unique_id "amuNKoaApLsOvtuGcVqcDQAARRc"]
[Thu Jul 30 12:43:06.907232 2026] [core:notice] [pid 782784:tid 783015] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:06.958218 2026] [security2:error] [pid 782784:tid 782797] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/images/include.php"] [unique_id "amuNKoaApLsOvtuGcVqcFQAAZww"]
[Thu Jul 30 12:43:07.023635 2026] [security2:error] [pid 782784:tid 782951] [client 20.52.125.110:1226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuNK4aApLsOvtuGcVqcFgAAACU"]
[Thu Jul 30 12:43:07.160841 2026] [security2:error] [pid 782784:tid 783040] [client 52.167.144.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNK4aApLsOvtuGcVqcGgAAAH4"]
[Thu Jul 30 12:43:07.251171 2026] [security2:error] [pid 782784:tid 782820] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/--wp-lgj.php"] [unique_id "amuNK4aApLsOvtuGcVqcHwAADyM"]
[Thu Jul 30 12:43:07.523111 2026] [security2:error] [pid 782784:tid 782829] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-p.php"] [unique_id "amuNK4aApLsOvtuGcVqcLAAAdyw"]
[Thu Jul 30 12:43:07.598859 2026] [core:notice] [pid 782784:tid 783006] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:07.827486 2026] [security2:error] [pid 782784:tid 782919] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuNK4aApLsOvtuGcVqcPwAAAAU"]
[Thu Jul 30 12:43:07.827576 2026] [security2:error] [pid 782784:tid 782919] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuNK4aApLsOvtuGcVqcPwAAAAU"]
[Thu Jul 30 12:43:07.975385 2026] [security2:error] [pid 782784:tid 782927] [client 20.52.125.110:1774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuNK4aApLsOvtuGcVqcQwAAAA0"]
[Thu Jul 30 12:43:08.009888 2026] [core:notice] [pid 782784:tid 782974] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:08.016347 2026] [security2:error] [pid 782784:tid 782974] [client 103.215.74.26:26766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNLIaApLsOvtuGcVqcRgAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:08.136366 2026] [security2:error] [pid 782784:tid 782947] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuNLIaApLsOvtuGcVqcTAAAACE"]
[Thu Jul 30 12:43:08.136460 2026] [security2:error] [pid 782784:tid 782947] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuNLIaApLsOvtuGcVqcTAAAACE"]
[Thu Jul 30 12:43:08.177589 2026] [security2:error] [pid 782784:tid 783014] [client 20.63.98.115:21371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuNLIaApLsOvtuGcVqcTQAAAGQ"]
[Thu Jul 30 12:43:08.190467 2026] [security2:error] [pid 782784:tid 782848] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/ectoplasm/flower.php"] [unique_id "amuNLIaApLsOvtuGcVqcTgAANj8"]
[Thu Jul 30 12:43:08.445128 2026] [security2:error] [pid 782784:tid 782943] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/x.php"] [unique_id "amuNLIaApLsOvtuGcVqcVQAAAB0"]
[Thu Jul 30 12:43:08.445224 2026] [security2:error] [pid 782784:tid 782943] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/x.php"] [unique_id "amuNLIaApLsOvtuGcVqcVQAAAB0"]
[Thu Jul 30 12:43:08.458892 2026] [security2:error] [pid 782784:tid 782844] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuNLIaApLsOvtuGcVqcWwAAATs"]
[Thu Jul 30 12:43:08.656703 2026] [core:error] [pid 782784:tid 782951] [client 74.7.244.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:08.656734 2026] [core:error] [pid 782784:tid 782951] [client 74.7.244.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:08.656854 2026] [security2:error] [pid 782784:tid 782951] [client 74.7.244.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.sua.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuNLIaApLsOvtuGcVqcZAAAACU"]
[Thu Jul 30 12:43:08.658322 2026] [security2:error] [pid 782784:tid 782973] [client 74.7.244.30:43670] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.sua.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuNLIaApLsOvtuGcVqcYgAAO0U"]
[Thu Jul 30 12:43:08.750698 2026] [security2:error] [pid 782784:tid 782998] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/mgrr.php"] [unique_id "amuNLIaApLsOvtuGcVqcaAAAAFQ"]
[Thu Jul 30 12:43:08.750800 2026] [security2:error] [pid 782784:tid 782998] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/mgrr.php"] [unique_id "amuNLIaApLsOvtuGcVqcaAAAAFQ"]
[Thu Jul 30 12:43:08.778061 2026] [core:notice] [pid 782784:tid 783031] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:08.784786 2026] [security2:error] [pid 782784:tid 783031] [client 103.215.74.26:26768] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNLIaApLsOvtuGcVqcaQAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:08.804312 2026] [security2:error] [pid 782784:tid 782855] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuNLIaApLsOvtuGcVqcagAATkY"]
[Thu Jul 30 12:43:09.053093 2026] [security2:error] [pid 782784:tid 783024] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/domvf.php"] [unique_id "amuNLYaApLsOvtuGcVqccQAAAG4"]
[Thu Jul 30 12:43:09.053218 2026] [security2:error] [pid 782784:tid 783024] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/domvf.php"] [unique_id "amuNLYaApLsOvtuGcVqccQAAAG4"]
[Thu Jul 30 12:43:09.069138 2026] [security2:error] [pid 782784:tid 783010] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNLIaApLsOvtuGcVqcWgAAAGA"]
[Thu Jul 30 12:43:09.366603 2026] [security2:error] [pid 782784:tid 782956] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/yup.php"] [unique_id "amuNLYaApLsOvtuGcVqceAAAACo"]
[Thu Jul 30 12:43:09.366717 2026] [security2:error] [pid 782784:tid 782956] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/yup.php"] [unique_id "amuNLYaApLsOvtuGcVqceAAAACo"]
[Thu Jul 30 12:43:09.425562 2026] [security2:error] [pid 782784:tid 782833] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/rxxdfx/xleet.php"] [unique_id "amuNLYaApLsOvtuGcVqcegAABjA"]
[Thu Jul 30 12:43:09.685741 2026] [security2:error] [pid 782784:tid 782864] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/module.tag.idv1.php"] [unique_id "amuNLYaApLsOvtuGcVqciAAAfU8"]
[Thu Jul 30 12:43:09.691206 2026] [security2:error] [pid 782784:tid 782997] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/X.php"] [unique_id "amuNLYaApLsOvtuGcVqciQAAAFM"]
[Thu Jul 30 12:43:09.691296 2026] [security2:error] [pid 782784:tid 782997] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/X.php"] [unique_id "amuNLYaApLsOvtuGcVqciQAAAFM"]
[Thu Jul 30 12:43:09.887136 2026] [core:notice] [pid 782784:tid 782976] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:09.991219 2026] [security2:error] [pid 782784:tid 782974] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuNLYaApLsOvtuGcVqcjgAAADw"]
[Thu Jul 30 12:43:09.991338 2026] [security2:error] [pid 782784:tid 782974] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuNLYaApLsOvtuGcVqcjgAAADw"]
[Thu Jul 30 12:43:09.992467 2026] [security2:error] [pid 782784:tid 782859] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/packed.php"] [unique_id "amuNLYaApLsOvtuGcVqcjwAAP0o"]
[Thu Jul 30 12:43:10.292986 2026] [security2:error] [pid 782784:tid 782849] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/css/F0x.php"] [unique_id "amuNLoaApLsOvtuGcVqcnQAAHUA"]
[Thu Jul 30 12:43:10.295609 2026] [security2:error] [pid 782784:tid 782915] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/gec.php"] [unique_id "amuNLoaApLsOvtuGcVqcngAAAAE"]
[Thu Jul 30 12:43:10.295696 2026] [security2:error] [pid 782784:tid 782915] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/gec.php"] [unique_id "amuNLoaApLsOvtuGcVqcngAAAAE"]
[Thu Jul 30 12:43:10.428292 2026] [fcgid:warn] [pid 782784:tid 783035] (70014)End of file found: [client 152.32.250.36:42206] mod_fcgid: can't get data from http client
[Thu Jul 30 12:43:10.430256 2026] [security2:error] [pid 782784:tid 782940] [client 20.63.98.115:59018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuNLoaApLsOvtuGcVqcoAAAABo"]
[Thu Jul 30 12:43:10.542230 2026] [security2:error] [pid 782784:tid 782957] [client 20.52.125.110:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/avaa.php"] [unique_id "amuNLoaApLsOvtuGcVqcpAAAACs"]
[Thu Jul 30 12:43:10.555360 2026] [security2:error] [pid 782784:tid 782874] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/view.php"] [unique_id "amuNLoaApLsOvtuGcVqcqAAAClk"]
[Thu Jul 30 12:43:10.596247 2026] [security2:error] [pid 782784:tid 783030] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/sky.php"] [unique_id "amuNLoaApLsOvtuGcVqcrAAAAHQ"]
[Thu Jul 30 12:43:10.596339 2026] [security2:error] [pid 782784:tid 783030] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/sky.php"] [unique_id "amuNLoaApLsOvtuGcVqcrAAAAHQ"]
[Thu Jul 30 12:43:10.756382 2026] [security2:error] [pid 782784:tid 783031] [client 51.120.83.160:1779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.upns.ca"] [uri "/file.php"] [unique_id "amuNLoaApLsOvtuGcVqcsQAAAHU"]
[Thu Jul 30 12:43:10.756468 2026] [security2:error] [pid 782784:tid 783031] [client 51.120.83.160:1779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.upns.ca"] [uri "/file.php"] [unique_id "amuNLoaApLsOvtuGcVqcsQAAAHU"]
[Thu Jul 30 12:43:10.828337 2026] [security2:error] [pid 782784:tid 782887] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/blocks/site-title/index.php"] [unique_id "amuNLoaApLsOvtuGcVqcsgAATmY"]
[Thu Jul 30 12:43:10.911910 2026] [security2:error] [pid 782784:tid 783001] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fffm.php"] [unique_id "amuNLoaApLsOvtuGcVqcswAAAFc"]
[Thu Jul 30 12:43:10.912033 2026] [security2:error] [pid 782784:tid 783001] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fffm.php"] [unique_id "amuNLoaApLsOvtuGcVqcswAAAFc"]
[Thu Jul 30 12:43:11.089927 2026] [security2:error] [pid 782784:tid 782888] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/GOD.php"] [unique_id "amuNL4aApLsOvtuGcVqcuQAABGc"]
[Thu Jul 30 12:43:11.217231 2026] [security2:error] [pid 782784:tid 783041] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/sixxis.php"] [unique_id "amuNL4aApLsOvtuGcVqcvQAAAH8"]
[Thu Jul 30 12:43:11.217383 2026] [security2:error] [pid 782784:tid 783041] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/sixxis.php"] [unique_id "amuNL4aApLsOvtuGcVqcvQAAAH8"]
[Thu Jul 30 12:43:11.387078 2026] [security2:error] [pid 782784:tid 782890] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuNL4aApLsOvtuGcVqcwQAAc2k"]
[Thu Jul 30 12:43:11.439125 2026] [security2:error] [pid 782784:tid 782959] [client 20.52.125.110:1782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/images/cloud.php"] [unique_id "amuNL4aApLsOvtuGcVqcwgAAAC0"]
[Thu Jul 30 12:43:11.458537 2026] [security2:error] [pid 782784:tid 782930] [client 20.63.98.115:20969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ws.php"] [unique_id "amuNL4aApLsOvtuGcVqcwwAAABA"]
[Thu Jul 30 12:43:11.518705 2026] [security2:error] [pid 782784:tid 783027] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/yj09.php"] [unique_id "amuNL4aApLsOvtuGcVqcxwAAAHE"]
[Thu Jul 30 12:43:11.518797 2026] [security2:error] [pid 782784:tid 783027] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/yj09.php"] [unique_id "amuNL4aApLsOvtuGcVqcxwAAAHE"]
[Thu Jul 30 12:43:11.656828 2026] [security2:error] [pid 782784:tid 782880] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-configs.php"] [unique_id "amuNL4aApLsOvtuGcVqczgAAZl8"]
[Thu Jul 30 12:43:11.817332 2026] [security2:error] [pid 782784:tid 783006] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/k.php"] [unique_id "amuNL4aApLsOvtuGcVqc1AAAAFw"]
[Thu Jul 30 12:43:11.817441 2026] [security2:error] [pid 782784:tid 783006] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/k.php"] [unique_id "amuNL4aApLsOvtuGcVqc1AAAAFw"]
[Thu Jul 30 12:43:11.922173 2026] [security2:error] [pid 782784:tid 782886] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/contrjibus.php"] [unique_id "amuNL4aApLsOvtuGcVqc1gAAEmU"]
[Thu Jul 30 12:43:12.133486 2026] [security2:error] [pid 782784:tid 783002] [client 20.52.125.110:1218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuNMIaApLsOvtuGcVqc3wAAAFg"]
[Thu Jul 30 12:43:12.143206 2026] [security2:error] [pid 782784:tid 782931] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/k2.php"] [unique_id "amuNMIaApLsOvtuGcVqc4QAAABE"]
[Thu Jul 30 12:43:12.143286 2026] [security2:error] [pid 782784:tid 782931] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/k2.php"] [unique_id "amuNMIaApLsOvtuGcVqc4QAAABE"]
[Thu Jul 30 12:43:12.247048 2026] [security2:error] [pid 782784:tid 782900] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/contentloader1.php"] [unique_id "amuNMIaApLsOvtuGcVqc5gAANnM"]
[Thu Jul 30 12:43:12.455424 2026] [security2:error] [pid 782784:tid 783023] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/w.php"] [unique_id "amuNMIaApLsOvtuGcVqc7gAAAG0"]
[Thu Jul 30 12:43:12.455541 2026] [security2:error] [pid 782784:tid 783023] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/w.php"] [unique_id "amuNMIaApLsOvtuGcVqc7gAAAG0"]
[Thu Jul 30 12:43:12.515508 2026] [security2:error] [pid 782784:tid 782868] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/F0x.php"] [unique_id "amuNMIaApLsOvtuGcVqc7wAAE1M"]
[Thu Jul 30 12:43:12.788835 2026] [security2:error] [pid 782784:tid 783010] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fpwch.php"] [unique_id "amuNMIaApLsOvtuGcVqc_gAAAGA"]
[Thu Jul 30 12:43:12.788995 2026] [security2:error] [pid 782784:tid 783010] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fpwch.php"] [unique_id "amuNMIaApLsOvtuGcVqc_gAAAGA"]
[Thu Jul 30 12:43:12.814233 2026] [security2:error] [pid 782784:tid 782912] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/item.php"] [unique_id "amuNMIaApLsOvtuGcVqc_wAAfn8"]
[Thu Jul 30 12:43:13.103545 2026] [security2:error] [pid 782784:tid 783004] [client 38.190.144.4:53621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNMYaApLsOvtuGcVqdCAAAAFo"]
[Thu Jul 30 12:43:13.105787 2026] [security2:error] [pid 782784:tid 783004] [client 38.190.144.4:53621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNMYaApLsOvtuGcVqdCAAAAFo"]
[Thu Jul 30 12:43:13.121375 2026] [security2:error] [pid 782784:tid 782966] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/w2025.php"] [unique_id "amuNMYaApLsOvtuGcVqdCgAAADQ"]
[Thu Jul 30 12:43:13.121470 2026] [security2:error] [pid 782784:tid 782966] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/w2025.php"] [unique_id "amuNMYaApLsOvtuGcVqdCgAAADQ"]
[Thu Jul 30 12:43:13.257563 2026] [security2:error] [pid 782784:tid 782786] [remote 47.128.27.74:38506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moose-knuckles-jacket-black-10/"] [unique_id "amuNMYaApLsOvtuGcVqdDgAAHwE"]
[Thu Jul 30 12:43:13.414687 2026] [security2:error] [pid 782784:tid 782997] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/FWAZ.php"] [unique_id "amuNMYaApLsOvtuGcVqdEQAAAFM"]
[Thu Jul 30 12:43:13.414802 2026] [security2:error] [pid 782784:tid 782997] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/FWAZ.php"] [unique_id "amuNMYaApLsOvtuGcVqdEQAAAFM"]
[Thu Jul 30 12:43:13.733196 2026] [security2:error] [pid 782784:tid 782941] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/qterm.php"] [unique_id "amuNMYaApLsOvtuGcVqdGAAAABs"]
[Thu Jul 30 12:43:13.733345 2026] [security2:error] [pid 782784:tid 782941] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/qterm.php"] [unique_id "amuNMYaApLsOvtuGcVqdGAAAABs"]
[Thu Jul 30 12:43:13.801934 2026] [security2:error] [pid 782784:tid 783034] [client 20.63.98.115:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-config-sample.php"] [unique_id "amuNMYaApLsOvtuGcVqdGQAAAHg"]
[Thu Jul 30 12:43:14.048686 2026] [security2:error] [pid 782784:tid 783025] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/blurbs.php"] [unique_id "amuNMoaApLsOvtuGcVqdHQAAAG8"]
[Thu Jul 30 12:43:14.048795 2026] [security2:error] [pid 782784:tid 783025] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/blurbs.php"] [unique_id "amuNMoaApLsOvtuGcVqdHQAAAG8"]
[Thu Jul 30 12:43:14.121364 2026] [security2:error] [pid 782784:tid 782934] [client 20.52.125.110:1783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuNMoaApLsOvtuGcVqdHgAAABQ"]
[Thu Jul 30 12:43:14.379741 2026] [security2:error] [pid 782784:tid 782917] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-ws68.php"] [unique_id "amuNMoaApLsOvtuGcVqdIAAAAAM"]
[Thu Jul 30 12:43:14.379863 2026] [security2:error] [pid 782784:tid 782917] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-ws68.php"] [unique_id "amuNMoaApLsOvtuGcVqdIAAAAAM"]
[Thu Jul 30 12:43:14.581423 2026] [core:notice] [pid 782784:tid 782990] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:14.588155 2026] [security2:error] [pid 782784:tid 782990] [client 103.215.74.26:50318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNMoaApLsOvtuGcVqdLAAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:14.637495 2026] [core:notice] [pid 782784:tid 782803] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:14.702323 2026] [security2:error] [pid 782784:tid 782916] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xyn.php"] [unique_id "amuNMoaApLsOvtuGcVqdMAAAAAI"]
[Thu Jul 30 12:43:14.702495 2026] [security2:error] [pid 782784:tid 782916] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xyn.php"] [unique_id "amuNMoaApLsOvtuGcVqdMAAAAAI"]
[Thu Jul 30 12:43:14.988928 2026] [security2:error] [pid 782784:tid 782915] [client 20.52.125.110:1275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuNMoaApLsOvtuGcVqdOwAAAAE"]
[Thu Jul 30 12:43:15.017668 2026] [security2:error] [pid 782784:tid 783024] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ccc.php"] [unique_id "amuNM4aApLsOvtuGcVqdPwAAAG4"]
[Thu Jul 30 12:43:15.017761 2026] [security2:error] [pid 782784:tid 783024] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ccc.php"] [unique_id "amuNM4aApLsOvtuGcVqdPwAAAG4"]
[Thu Jul 30 12:43:15.127472 2026] [security2:error] [pid 782784:tid 782983] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNMoaApLsOvtuGcVqdKQAAAEU"]
[Thu Jul 30 12:43:15.315957 2026] [core:notice] [pid 782784:tid 783040] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:15.320219 2026] [security2:error] [pid 782784:tid 783040] [client 103.215.74.26:50332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNM4aApLsOvtuGcVqdSwAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:15.328694 2026] [security2:error] [pid 782784:tid 783005] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/get.php"] [unique_id "amuNM4aApLsOvtuGcVqdTAAAAFs"]
[Thu Jul 30 12:43:15.328779 2026] [security2:error] [pid 782784:tid 783005] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/get.php"] [unique_id "amuNM4aApLsOvtuGcVqdTAAAAFs"]
[Thu Jul 30 12:43:15.631264 2026] [security2:error] [pid 782784:tid 783003] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/images.php"] [unique_id "amuNM4aApLsOvtuGcVqdXAAAAFk"]
[Thu Jul 30 12:43:15.631405 2026] [security2:error] [pid 782784:tid 783003] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/images.php"] [unique_id "amuNM4aApLsOvtuGcVqdXAAAAFk"]
[Thu Jul 30 12:43:15.759139 2026] [security2:error] [pid 782784:tid 782945] [client 20.63.98.115:64834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wso.php"] [unique_id "amuNM4aApLsOvtuGcVqdYAAAAB8"]
[Thu Jul 30 12:43:15.952309 2026] [security2:error] [pid 782784:tid 783028] [client 193.37.252.99:43816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuNM4aApLsOvtuGcVqdYgAAAHI"]
[Thu Jul 30 12:43:15.952413 2026] [security2:error] [pid 782784:tid 783028] [client 193.37.252.99:43816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuNM4aApLsOvtuGcVqdYgAAAHI"]
[Thu Jul 30 12:43:15.962994 2026] [security2:error] [pid 782784:tid 783002] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/alls.php"] [unique_id "amuNM4aApLsOvtuGcVqdZAAAAFg"]
[Thu Jul 30 12:43:15.963095 2026] [security2:error] [pid 782784:tid 783002] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/alls.php"] [unique_id "amuNM4aApLsOvtuGcVqdZAAAAFg"]
[Thu Jul 30 12:43:16.053711 2026] [core:notice] [pid 782784:tid 782922] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:16.060941 2026] [security2:error] [pid 782784:tid 782922] [client 103.215.74.26:50342] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNNIaApLsOvtuGcVqdagAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:16.152780 2026] [security2:error] [pid 782784:tid 783006] [client 40.77.167.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuNM4aApLsOvtuGcVqdXwAAAFw"]
[Thu Jul 30 12:43:16.164210 2026] [autoindex:error] [pid 782784:tid 782923] [client 44.216.125.112:29067] AH01276: Cannot serve directory /home2/tgvgzjte/public_html/website_65bcc734/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:43:16.277881 2026] [security2:error] [pid 782784:tid 783023] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/coffexium.php"] [unique_id "amuNNIaApLsOvtuGcVqdcAAAAG0"]
[Thu Jul 30 12:43:16.278009 2026] [security2:error] [pid 782784:tid 783023] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/coffexium.php"] [unique_id "amuNNIaApLsOvtuGcVqdcAAAAG0"]
[Thu Jul 30 12:43:16.513424 2026] [security2:error] [pid 782784:tid 783036] [client 150.107.232.194:26656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNNIaApLsOvtuGcVqddAAAAHo"]
[Thu Jul 30 12:43:16.513569 2026] [security2:error] [pid 782784:tid 783036] [client 150.107.232.194:26656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNNIaApLsOvtuGcVqddAAAAHo"]
[Thu Jul 30 12:43:16.587009 2026] [security2:error] [pid 782784:tid 782940] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/red.php"] [unique_id "amuNNIaApLsOvtuGcVqdeQAAABo"]
[Thu Jul 30 12:43:16.587118 2026] [security2:error] [pid 782784:tid 782940] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/red.php"] [unique_id "amuNNIaApLsOvtuGcVqdeQAAABo"]
[Thu Jul 30 12:43:16.791087 2026] [core:notice] [pid 782784:tid 782976] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:16.794992 2026] [security2:error] [pid 782784:tid 782976] [client 103.215.74.26:50352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNNIaApLsOvtuGcVqdgAAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:16.873829 2026] [security2:error] [pid 782784:tid 782942] [client 20.52.125.110:4178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuNNIaApLsOvtuGcVqdhAAAABw"]
[Thu Jul 30 12:43:16.899640 2026] [proxy:error] [pid 782784:tid 782957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:16.899702 2026] [proxy_http:error] [pid 782784:tid 782957] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:16.900269 2026] [proxy:error] [pid 782784:tid 782957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:16.900321 2026] [proxy_http:error] [pid 782784:tid 782957] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:16.900401 2026] [security2:error] [pid 782784:tid 782957] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNNIaApLsOvtuGcVqdhQAAACs"]
[Thu Jul 30 12:43:17.125109 2026] [security2:error] [pid 782784:tid 782985] [client 40.77.167.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuNNIaApLsOvtuGcVqdfwAAAEc"]
[Thu Jul 30 12:43:17.132763 2026] [security2:error] [pid 782784:tid 783021] [client 20.63.98.115:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/sh.php"] [unique_id "amuNNYaApLsOvtuGcVqdpAAAAGs"]
[Thu Jul 30 12:43:17.214844 2026] [security2:error] [pid 782784:tid 782956] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuNNYaApLsOvtuGcVqdqAAAACo"]
[Thu Jul 30 12:43:17.214930 2026] [security2:error] [pid 782784:tid 782956] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuNNYaApLsOvtuGcVqdqAAAACo"]
[Thu Jul 30 12:43:17.540938 2026] [proxy:error] [pid 782784:tid 783027] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:17.541061 2026] [proxy_http:error] [pid 782784:tid 783027] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:17.541627 2026] [proxy:error] [pid 782784:tid 783027] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:17.541681 2026] [proxy_http:error] [pid 782784:tid 783027] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:17.541778 2026] [security2:error] [pid 782784:tid 783027] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNNYaApLsOvtuGcVqdsgAAAHE"]
[Thu Jul 30 12:43:17.544441 2026] [core:notice] [pid 782784:tid 783034] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:17.548087 2026] [security2:error] [pid 782784:tid 783034] [client 103.215.74.26:50362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNNYaApLsOvtuGcVqdtQAAAHg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:17.701284 2026] [security2:error] [pid 782784:tid 782954] [client 20.52.125.110:1258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuNNYaApLsOvtuGcVqdugAAACg"]
[Thu Jul 30 12:43:17.844690 2026] [proxy:error] [pid 782784:tid 783006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:17.844772 2026] [proxy_http:error] [pid 782784:tid 783006] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:17.845382 2026] [proxy:error] [pid 782784:tid 783006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:17.845428 2026] [proxy_http:error] [pid 782784:tid 783006] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:17.845535 2026] [security2:error] [pid 782784:tid 783006] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNNYaApLsOvtuGcVqdvgAAAFw"]
[Thu Jul 30 12:43:18.129934 2026] [security2:error] [pid 782784:tid 782995] [client 20.63.98.115:20954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/send.php"] [unique_id "amuNNoaApLsOvtuGcVqdxgAAAFE"]
[Thu Jul 30 12:43:18.150164 2026] [security2:error] [pid 782784:tid 783030] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/index.php"] [unique_id "amuNNoaApLsOvtuGcVqdygAAAHQ"]
[Thu Jul 30 12:43:18.150259 2026] [security2:error] [pid 782784:tid 783030] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/index.php"] [unique_id "amuNNoaApLsOvtuGcVqdygAAAHQ"]
[Thu Jul 30 12:43:18.310177 2026] [core:notice] [pid 782784:tid 783023] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:18.314153 2026] [security2:error] [pid 782784:tid 783023] [client 103.215.74.26:50366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNNoaApLsOvtuGcVqd1QAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:18.453824 2026] [security2:error] [pid 782784:tid 783029] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuNNoaApLsOvtuGcVqd2QAAAHM"]
[Thu Jul 30 12:43:18.453968 2026] [security2:error] [pid 782784:tid 783029] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuNNoaApLsOvtuGcVqd2QAAAHM"]
[Thu Jul 30 12:43:18.712504 2026] [security2:error] [pid 782784:tid 782985] [client 43.172.196.150:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/03/01/apercu-de-la-collection-maillots-de-bain-undiz-printemps-ete-2013/"] [unique_id "amuNNoaApLsOvtuGcVqd4gAAAEc"]
[Thu Jul 30 12:43:18.748640 2026] [security2:error] [pid 782784:tid 783039] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/177.php"] [unique_id "amuNNoaApLsOvtuGcVqd5gAAAH0"]
[Thu Jul 30 12:43:18.748755 2026] [security2:error] [pid 782784:tid 783039] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/177.php"] [unique_id "amuNNoaApLsOvtuGcVqd5gAAAH0"]
[Thu Jul 30 12:43:18.790486 2026] [security2:error] [pid 782784:tid 782991] [client 43.172.197.103:41660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/wp/v2/posts/2862"] [unique_id "amuNNoaApLsOvtuGcVqd2gAAAE0"]
[Thu Jul 30 12:43:18.961719 2026] [security2:error] [pid 782784:tid 782920] [client 20.52.125.110:1237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/cloud.php"] [unique_id "amuNNoaApLsOvtuGcVqd5wAAAAY"]
[Thu Jul 30 12:43:19.046341 2026] [security2:error] [pid 782784:tid 782981] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/199.php"] [unique_id "amuNN4aApLsOvtuGcVqd6AAAAEM"]
[Thu Jul 30 12:43:19.046486 2026] [security2:error] [pid 782784:tid 782981] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/199.php"] [unique_id "amuNN4aApLsOvtuGcVqd6AAAAEM"]
[Thu Jul 30 12:43:19.056518 2026] [core:notice] [pid 782784:tid 782914] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:19.063405 2026] [security2:error] [pid 782784:tid 782914] [client 103.215.74.26:50378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNN4aApLsOvtuGcVqd6QAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:19.207776 2026] [core:notice] [pid 782784:tid 782932] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:19.212513 2026] [security2:error] [pid 782784:tid 782932] [client 43.173.174.74:60668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/wp/v2/posts/2862"] [unique_id "amuNN4aApLsOvtuGcVqd8AAAABI"], referer: https://carnetdeshopping.com/index.php/wp-json/wp/v2/posts/2862
[Thu Jul 30 12:43:19.349328 2026] [security2:error] [pid 782784:tid 783022] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file52.php"] [unique_id "amuNN4aApLsOvtuGcVqd-AAAAGw"]
[Thu Jul 30 12:43:19.349467 2026] [security2:error] [pid 782784:tid 783022] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file52.php"] [unique_id "amuNN4aApLsOvtuGcVqd-AAAAGw"]
[Thu Jul 30 12:43:19.396822 2026] [core:notice] [pid 782784:tid 782917] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:19.401468 2026] [security2:error] [pid 782784:tid 782917] [client 43.173.178.65:58784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/03/01/apercu-de-la-collection-maillots-de-bain-undiz-printemps-ete-2013/"] [unique_id "amuNN4aApLsOvtuGcVqd-gAAAAM"], referer: https://carnetdeshopping.com/index.php/2013/03/01/apercu-de-la-collection-maillots-de-bain-undiz-printemps-ete-2013/
[Thu Jul 30 12:43:19.587457 2026] [security2:error] [pid 782784:tid 783016] [client 20.52.125.110:4195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/updates.php"] [unique_id "amuNN4aApLsOvtuGcVqd_AAAAGY"]
[Thu Jul 30 12:43:19.657132 2026] [security2:error] [pid 782784:tid 783014] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/geck.php"] [unique_id "amuNN4aApLsOvtuGcVqeAwAAAGQ"]
[Thu Jul 30 12:43:19.657249 2026] [security2:error] [pid 782784:tid 783014] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/geck.php"] [unique_id "amuNN4aApLsOvtuGcVqeAwAAAGQ"]
[Thu Jul 30 12:43:19.820259 2026] [core:notice] [pid 782784:tid 782971] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:19.824747 2026] [security2:error] [pid 782784:tid 782971] [client 103.215.74.26:50392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNN4aApLsOvtuGcVqeCwAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:19.962726 2026] [security2:error] [pid 782784:tid 782929] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/biufile.php"] [unique_id "amuNN4aApLsOvtuGcVqeFAAAAA8"]
[Thu Jul 30 12:43:19.962831 2026] [security2:error] [pid 782784:tid 782929] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/biufile.php"] [unique_id "amuNN4aApLsOvtuGcVqeFAAAAA8"]
[Thu Jul 30 12:43:20.089816 2026] [security2:error] [pid 782784:tid 782993] [client 20.52.125.110:1738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/libraries/legacy/updates.php"] [unique_id "amuNOIaApLsOvtuGcVqeFwAAAE8"]
[Thu Jul 30 12:43:20.271107 2026] [security2:error] [pid 782784:tid 782999] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dejavu.php"] [unique_id "amuNOIaApLsOvtuGcVqeIgAAAFU"]
[Thu Jul 30 12:43:20.271243 2026] [security2:error] [pid 782784:tid 782999] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dejavu.php"] [unique_id "amuNOIaApLsOvtuGcVqeIgAAAFU"]
[Thu Jul 30 12:43:20.502837 2026] [security2:error] [pid 782784:tid 782959] [client 20.63.98.115:20618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ds.php"] [unique_id "amuNOIaApLsOvtuGcVqeJgAAAC0"]
[Thu Jul 30 12:43:20.590409 2026] [security2:error] [pid 782784:tid 782981] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aaf.php"] [unique_id "amuNOIaApLsOvtuGcVqeKgAAAEM"]
[Thu Jul 30 12:43:20.590501 2026] [security2:error] [pid 782784:tid 782981] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aaf.php"] [unique_id "amuNOIaApLsOvtuGcVqeKgAAAEM"]
[Thu Jul 30 12:43:20.601970 2026] [core:notice] [pid 782784:tid 782969] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:20.606036 2026] [security2:error] [pid 782784:tid 782969] [client 103.215.74.26:50394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNOIaApLsOvtuGcVqeKwAAADc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:20.702679 2026] [security2:error] [pid 782784:tid 782939] [client 20.52.125.110:4181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuNOIaApLsOvtuGcVqeLwAAABk"]
[Thu Jul 30 12:43:20.893564 2026] [security2:error] [pid 782784:tid 783009] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ha.php"] [unique_id "amuNOIaApLsOvtuGcVqeNwAAAF8"]
[Thu Jul 30 12:43:20.893675 2026] [security2:error] [pid 782784:tid 783009] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ha.php"] [unique_id "amuNOIaApLsOvtuGcVqeNwAAAF8"]
[Thu Jul 30 12:43:21.187611 2026] [security2:error] [pid 782784:tid 782977] [client 20.52.125.110:1785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/libraries/vendor/updates.php"] [unique_id "amuNOYaApLsOvtuGcVqePQAAAD8"]
[Thu Jul 30 12:43:21.195403 2026] [security2:error] [pid 782784:tid 782990] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/hur.php"] [unique_id "amuNOYaApLsOvtuGcVqePgAAAEw"]
[Thu Jul 30 12:43:21.195482 2026] [security2:error] [pid 782784:tid 782990] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/hur.php"] [unique_id "amuNOYaApLsOvtuGcVqePgAAAEw"]
[Thu Jul 30 12:43:21.322300 2026] [core:notice] [pid 782784:tid 783014] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:21.326206 2026] [security2:error] [pid 782784:tid 783014] [client 103.215.74.26:50400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNOYaApLsOvtuGcVqeSQAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:21.511214 2026] [security2:error] [pid 782784:tid 782973] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/h02ugyh.php"] [unique_id "amuNOYaApLsOvtuGcVqeVQAAADs"]
[Thu Jul 30 12:43:21.511333 2026] [security2:error] [pid 782784:tid 782973] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/h02ugyh.php"] [unique_id "amuNOYaApLsOvtuGcVqeVQAAADs"]
[Thu Jul 30 12:43:21.822242 2026] [security2:error] [pid 782784:tid 782936] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/155.php"] [unique_id "amuNOYaApLsOvtuGcVqeYwAAABY"]
[Thu Jul 30 12:43:21.822384 2026] [security2:error] [pid 782784:tid 782936] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/155.php"] [unique_id "amuNOYaApLsOvtuGcVqeYwAAABY"]
[Thu Jul 30 12:43:21.886386 2026] [security2:error] [pid 782784:tid 782902] [remote 74.7.241.60:41028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuNOYaApLsOvtuGcVqeawAAc3U"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:43:21.973472 2026] [security2:error] [pid 782784:tid 782988] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNOYaApLsOvtuGcVqeUAAAAEo"]
[Thu Jul 30 12:43:22.020533 2026] [security2:error] [pid 782784:tid 782994] [client 20.63.98.115:64844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wso112233.php"] [unique_id "amuNOoaApLsOvtuGcVqebgAAAFA"]
[Thu Jul 30 12:43:22.102096 2026] [core:notice] [pid 782784:tid 782966] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:22.107244 2026] [security2:error] [pid 782784:tid 782966] [client 103.215.74.26:50404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNOoaApLsOvtuGcVqecgAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:22.128129 2026] [security2:error] [pid 782784:tid 782964] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ops.php"] [unique_id "amuNOoaApLsOvtuGcVqecwAAADI"]
[Thu Jul 30 12:43:22.128244 2026] [security2:error] [pid 782784:tid 782964] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ops.php"] [unique_id "amuNOoaApLsOvtuGcVqecwAAADI"]
[Thu Jul 30 12:43:22.428398 2026] [security2:error] [pid 782784:tid 782971] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ingfo.php"] [unique_id "amuNOoaApLsOvtuGcVqeiAAAADk"]
[Thu Jul 30 12:43:22.428506 2026] [security2:error] [pid 782784:tid 782971] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ingfo.php"] [unique_id "amuNOoaApLsOvtuGcVqeiAAAADk"]
[Thu Jul 30 12:43:22.451360 2026] [security2:error] [pid 782784:tid 782920] [client 136.114.127.127:51104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuNOoaApLsOvtuGcVqeiQAAAAY"]
[Thu Jul 30 12:43:22.551405 2026] [security2:error] [pid 782784:tid 782970] [client 136.114.127.127:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "dl.happymod-apk.com.mx"] [uri "/cgi-sys/404.html"] [unique_id "amuNOoaApLsOvtuGcVqeigAAOHc"]
[Thu Jul 30 12:43:22.732143 2026] [security2:error] [pid 782784:tid 782935] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/error_log.php"] [unique_id "amuNOoaApLsOvtuGcVqejwAAABU"]
[Thu Jul 30 12:43:22.732233 2026] [security2:error] [pid 782784:tid 782935] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/error_log.php"] [unique_id "amuNOoaApLsOvtuGcVqejwAAABU"]
[Thu Jul 30 12:43:22.865746 2026] [core:notice] [pid 782784:tid 782996] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:22.870270 2026] [security2:error] [pid 782784:tid 782996] [client 103.215.74.26:50416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNOoaApLsOvtuGcVqemgAAAFI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:23.039315 2026] [security2:error] [pid 782784:tid 783008] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/koala.php"] [unique_id "amuNO4aApLsOvtuGcVqeoQAAAF4"]
[Thu Jul 30 12:43:23.039434 2026] [security2:error] [pid 782784:tid 783008] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/koala.php"] [unique_id "amuNO4aApLsOvtuGcVqeoQAAAF4"]
[Thu Jul 30 12:43:23.090994 2026] [security2:error] [pid 782784:tid 782973] [client 20.63.98.115:55323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "amuNO4aApLsOvtuGcVqepAAAADs"]
[Thu Jul 30 12:43:23.353300 2026] [security2:error] [pid 782784:tid 783024] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/mac.php"] [unique_id "amuNO4aApLsOvtuGcVqetAAAAG4"]
[Thu Jul 30 12:43:23.353387 2026] [security2:error] [pid 782784:tid 783024] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/mac.php"] [unique_id "amuNO4aApLsOvtuGcVqetAAAAG4"]
[Thu Jul 30 12:43:23.460095 2026] [security2:error] [pid 782784:tid 782918] [client 20.52.125.110:1745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/alfa-rex.php7"] [unique_id "amuNO4aApLsOvtuGcVqeuAAAAAQ"]
[Thu Jul 30 12:43:23.596896 2026] [core:notice] [pid 782784:tid 782981] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:23.601629 2026] [security2:error] [pid 782784:tid 782981] [client 103.215.74.26:33646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNO4aApLsOvtuGcVqeugAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:23.656496 2026] [security2:error] [pid 782784:tid 783003] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wefile.php"] [unique_id "amuNO4aApLsOvtuGcVqewAAAAFk"]
[Thu Jul 30 12:43:23.656592 2026] [security2:error] [pid 782784:tid 783003] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wefile.php"] [unique_id "amuNO4aApLsOvtuGcVqewAAAAFk"]
[Thu Jul 30 12:43:23.968568 2026] [proxy:error] [pid 782784:tid 782916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:23.968649 2026] [proxy_http:error] [pid 782784:tid 782916] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:23.969253 2026] [proxy:error] [pid 782784:tid 782916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:23.969300 2026] [proxy_http:error] [pid 782784:tid 782916] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:23.969406 2026] [security2:error] [pid 782784:tid 782916] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNO4aApLsOvtuGcVqe0AAAAAI"]
[Thu Jul 30 12:43:24.160560 2026] [security2:error] [pid 782784:tid 782920] [client 20.52.125.110:1224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/alfanew.php"] [unique_id "amuNPIaApLsOvtuGcVqe1gAAAAY"]
[Thu Jul 30 12:43:24.273363 2026] [proxy:error] [pid 782784:tid 782998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:24.273436 2026] [proxy_http:error] [pid 782784:tid 782998] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:24.274034 2026] [proxy:error] [pid 782784:tid 782998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:24.274078 2026] [proxy_http:error] [pid 782784:tid 782998] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:24.274157 2026] [security2:error] [pid 782784:tid 782998] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNPIaApLsOvtuGcVqe2wAAAFQ"]
[Thu Jul 30 12:43:24.317910 2026] [core:notice] [pid 782784:tid 782968] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:24.322233 2026] [security2:error] [pid 782784:tid 782968] [client 103.215.74.26:33660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNPIaApLsOvtuGcVqe4QAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:24.569967 2026] [security2:error] [pid 782784:tid 783021] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/makeasmtp.php"] [unique_id "amuNPIaApLsOvtuGcVqe6gAAAGs"]
[Thu Jul 30 12:43:24.570073 2026] [security2:error] [pid 782784:tid 783021] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/makeasmtp.php"] [unique_id "amuNPIaApLsOvtuGcVqe6gAAAGs"]
[Thu Jul 30 12:43:24.668895 2026] [fcgid:warn] [pid 782784:tid 782959] (70014)End of file found: [client 152.32.217.163:51736] mod_fcgid: can't get data from http client
[Thu Jul 30 12:43:24.715270 2026] [proxy:error] [pid 782784:tid 783041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:24.715360 2026] [proxy_http:error] [pid 782784:tid 783041] [client 143.244.47.86:16906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:24.716078 2026] [proxy:error] [pid 782784:tid 783041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:24.716125 2026] [proxy_http:error] [pid 782784:tid 783041] [client 143.244.47.86:16906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:24.786854 2026] [security2:error] [pid 782784:tid 782999] [client 193.37.252.99:36428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuNPIaApLsOvtuGcVqe8gAAAFU"]
[Thu Jul 30 12:43:24.786943 2026] [security2:error] [pid 782784:tid 782999] [client 193.37.252.99:36428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuNPIaApLsOvtuGcVqe8gAAAFU"]
[Thu Jul 30 12:43:24.874299 2026] [security2:error] [pid 782784:tid 782958] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/2P.php"] [unique_id "amuNPIaApLsOvtuGcVqe9gAAACw"]
[Thu Jul 30 12:43:24.874400 2026] [security2:error] [pid 782784:tid 782958] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/2P.php"] [unique_id "amuNPIaApLsOvtuGcVqe9gAAACw"]
[Thu Jul 30 12:43:24.955033 2026] [security2:error] [pid 782784:tid 783005] [client 20.52.125.110:1251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuNPIaApLsOvtuGcVqe-wAAAFs"]
[Thu Jul 30 12:43:25.057142 2026] [core:notice] [pid 782784:tid 783039] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:25.061719 2026] [security2:error] [pid 782784:tid 783039] [client 103.215.74.26:33670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNPYaApLsOvtuGcVqe_wAAAH0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:25.068358 2026] [security2:error] [pid 782784:tid 783027] [client 20.63.98.115:64887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "amuNPYaApLsOvtuGcVqfAQAAAHE"]
[Thu Jul 30 12:43:25.170847 2026] [security2:error] [pid 782784:tid 782939] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/.well-known/about.php"] [unique_id "amuNPYaApLsOvtuGcVqfAwAAABk"]
[Thu Jul 30 12:43:25.170937 2026] [security2:error] [pid 782784:tid 782939] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/.well-known/about.php"] [unique_id "amuNPYaApLsOvtuGcVqfAwAAABk"]
[Thu Jul 30 12:43:25.469539 2026] [security2:error] [pid 782784:tid 782977] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuNPYaApLsOvtuGcVqfDgAAAD8"]
[Thu Jul 30 12:43:25.469670 2026] [security2:error] [pid 782784:tid 782977] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuNPYaApLsOvtuGcVqfDgAAAD8"]
[Thu Jul 30 12:43:25.510185 2026] [core:notice] [pid 782784:tid 782953] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:25.646878 2026] [proxy:error] [pid 782784:tid 782917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:25.647004 2026] [proxy_http:error] [pid 782784:tid 782917] [client 143.244.47.86:59908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:25.647930 2026] [proxy:error] [pid 782784:tid 782917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:25.647999 2026] [proxy_http:error] [pid 782784:tid 782917] [client 143.244.47.86:59908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:25.778775 2026] [security2:error] [pid 782784:tid 782935] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/system_log.php"] [unique_id "amuNPYaApLsOvtuGcVqfIQAAABU"]
[Thu Jul 30 12:43:25.778874 2026] [security2:error] [pid 782784:tid 782935] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/system_log.php"] [unique_id "amuNPYaApLsOvtuGcVqfIQAAABU"]
[Thu Jul 30 12:43:25.818867 2026] [core:notice] [pid 782784:tid 782965] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:25.823321 2026] [security2:error] [pid 782784:tid 782965] [client 103.215.74.26:33686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNPYaApLsOvtuGcVqfIgAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:26.076739 2026] [proxy:error] [pid 782784:tid 782950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:26.076808 2026] [proxy_http:error] [pid 782784:tid 782950] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:26.077389 2026] [proxy:error] [pid 782784:tid 782950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:26.077434 2026] [proxy_http:error] [pid 782784:tid 782950] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:26.077505 2026] [security2:error] [pid 782784:tid 782950] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNPoaApLsOvtuGcVqfUQAAACQ"]
[Thu Jul 30 12:43:26.203436 2026] [security2:error] [pid 782784:tid 782931] [client 20.52.125.110:1776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuNPoaApLsOvtuGcVqfZAAAABE"]
[Thu Jul 30 12:43:26.395392 2026] [proxy:error] [pid 782784:tid 782961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:26.395460 2026] [proxy_http:error] [pid 782784:tid 782961] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:26.396035 2026] [proxy:error] [pid 782784:tid 782961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:26.396088 2026] [proxy_http:error] [pid 782784:tid 782961] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:26.396181 2026] [security2:error] [pid 782784:tid 782961] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNPoaApLsOvtuGcVqfbAAAAC8"]
[Thu Jul 30 12:43:26.560290 2026] [core:notice] [pid 782784:tid 782958] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:26.564512 2026] [security2:error] [pid 782784:tid 782958] [client 103.215.74.26:33694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNPoaApLsOvtuGcVqfeAAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:26.709767 2026] [security2:error] [pid 782784:tid 783040] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/crgio.php"] [unique_id "amuNPoaApLsOvtuGcVqffgAAAH4"]
[Thu Jul 30 12:43:26.709877 2026] [security2:error] [pid 782784:tid 783040] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/crgio.php"] [unique_id "amuNPoaApLsOvtuGcVqffgAAAH4"]
[Thu Jul 30 12:43:26.922918 2026] [security2:error] [pid 782784:tid 782960] [client 38.190.144.4:54133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNPoaApLsOvtuGcVqfggAAAC4"]
[Thu Jul 30 12:43:26.923070 2026] [security2:error] [pid 782784:tid 782960] [client 38.190.144.4:54133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNPoaApLsOvtuGcVqfggAAAC4"]
[Thu Jul 30 12:43:26.982490 2026] [security2:error] [pid 782784:tid 782959] [client 20.63.98.115:61340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mail.php"] [unique_id "amuNPoaApLsOvtuGcVqfhgAAAC0"]
[Thu Jul 30 12:43:26.999446 2026] [security2:error] [pid 782784:tid 783009] [client 150.107.232.194:26836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNPoaApLsOvtuGcVqfhwAAAF8"]
[Thu Jul 30 12:43:26.999583 2026] [security2:error] [pid 782784:tid 783009] [client 150.107.232.194:26836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNPoaApLsOvtuGcVqfhwAAAF8"]
[Thu Jul 30 12:43:27.026173 2026] [security2:error] [pid 782784:tid 782953] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/pucci.php"] [unique_id "amuNP4aApLsOvtuGcVqfiAAAACc"]
[Thu Jul 30 12:43:27.026266 2026] [security2:error] [pid 782784:tid 782953] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/pucci.php"] [unique_id "amuNP4aApLsOvtuGcVqfiAAAACc"]
[Thu Jul 30 12:43:27.292396 2026] [core:notice] [pid 782784:tid 782954] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:27.296789 2026] [security2:error] [pid 782784:tid 782954] [client 103.215.74.26:33710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNP4aApLsOvtuGcVqfzwAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:27.312922 2026] [security2:error] [pid 782784:tid 782939] [client 20.52.125.110:1744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-p.php7"] [unique_id "amuNP4aApLsOvtuGcVqf0AAAABk"]
[Thu Jul 30 12:43:27.324259 2026] [proxy:error] [pid 782784:tid 783022] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:27.324323 2026] [proxy_http:error] [pid 782784:tid 783022] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:27.324880 2026] [proxy:error] [pid 782784:tid 783022] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:27.324923 2026] [proxy_http:error] [pid 782784:tid 783022] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:27.325014 2026] [security2:error] [pid 782784:tid 783022] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNP4aApLsOvtuGcVqf0QAAAGw"]
[Thu Jul 30 12:43:27.701447 2026] [proxy:error] [pid 782784:tid 782951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:27.701512 2026] [proxy_http:error] [pid 782784:tid 782951] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:27.702102 2026] [proxy:error] [pid 782784:tid 782951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:27.702149 2026] [proxy_http:error] [pid 782784:tid 782951] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:27.702241 2026] [security2:error] [pid 782784:tid 782951] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNP4aApLsOvtuGcVqf5gAAACU"]
[Thu Jul 30 12:43:28.012685 2026] [security2:error] [pid 782784:tid 783041] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-temp.php"] [unique_id "amuNQIaApLsOvtuGcVqf7gAAAH8"]
[Thu Jul 30 12:43:28.012762 2026] [security2:error] [pid 782784:tid 783041] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-temp.php"] [unique_id "amuNQIaApLsOvtuGcVqf7gAAAH8"]
[Thu Jul 30 12:43:28.045236 2026] [core:notice] [pid 782784:tid 783008] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:28.049540 2026] [security2:error] [pid 782784:tid 783008] [client 103.215.74.26:33726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNQIaApLsOvtuGcVqf7wAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:28.323176 2026] [security2:error] [pid 782784:tid 782914] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuNQIaApLsOvtuGcVqf-gAAAAA"]
[Thu Jul 30 12:43:28.323299 2026] [security2:error] [pid 782784:tid 782914] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuNQIaApLsOvtuGcVqf-gAAAAA"]
[Thu Jul 30 12:43:28.640778 2026] [security2:error] [pid 782784:tid 783026] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/puc.php"] [unique_id "amuNQIaApLsOvtuGcVqgBQAAAHA"]
[Thu Jul 30 12:43:28.640946 2026] [security2:error] [pid 782784:tid 783026] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/puc.php"] [unique_id "amuNQIaApLsOvtuGcVqgBQAAAHA"]
[Thu Jul 30 12:43:28.769137 2026] [core:notice] [pid 782784:tid 782960] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:28.773085 2026] [security2:error] [pid 782784:tid 782960] [client 103.215.74.26:33740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNQIaApLsOvtuGcVqgDAAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:28.949840 2026] [security2:error] [pid 782784:tid 782954] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dx.php"] [unique_id "amuNQIaApLsOvtuGcVqgDQAAACg"]
[Thu Jul 30 12:43:28.949948 2026] [security2:error] [pid 782784:tid 782954] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dx.php"] [unique_id "amuNQIaApLsOvtuGcVqgDQAAACg"]
[Thu Jul 30 12:43:29.201127 2026] [security2:error] [pid 782784:tid 782970] [client 20.52.125.110:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/repeater.php"] [unique_id "amuNQYaApLsOvtuGcVqgGAAAADg"]
[Thu Jul 30 12:43:29.265401 2026] [proxy:error] [pid 782784:tid 783001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:29.265479 2026] [proxy_http:error] [pid 782784:tid 783001] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:29.266146 2026] [proxy:error] [pid 782784:tid 783001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:29.266193 2026] [proxy_http:error] [pid 782784:tid 783001] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:29.266293 2026] [security2:error] [pid 782784:tid 783001] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNQYaApLsOvtuGcVqgHAAAAFc"]
[Thu Jul 30 12:43:29.483160 2026] [core:notice] [pid 782784:tid 782945] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:29.487264 2026] [security2:error] [pid 782784:tid 782945] [client 103.215.74.26:33760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNQYaApLsOvtuGcVqgHwAAAB8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:29.597014 2026] [security2:error] [pid 782784:tid 782983] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/7.php"] [unique_id "amuNQYaApLsOvtuGcVqgJQAAAEU"]
[Thu Jul 30 12:43:29.597119 2026] [security2:error] [pid 782784:tid 782983] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/7.php"] [unique_id "amuNQYaApLsOvtuGcVqgJQAAAEU"]
[Thu Jul 30 12:43:29.915322 2026] [security2:error] [pid 782784:tid 782985] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/8.php"] [unique_id "amuNQYaApLsOvtuGcVqgLAAAAEc"]
[Thu Jul 30 12:43:29.915439 2026] [security2:error] [pid 782784:tid 782985] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/8.php"] [unique_id "amuNQYaApLsOvtuGcVqgLAAAAEc"]
[Thu Jul 30 12:43:29.951738 2026] [security2:error] [pid 782784:tid 783008] [client 20.52.125.110:1263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/repeater.php"] [unique_id "amuNQYaApLsOvtuGcVqgLQAAAF4"]
[Thu Jul 30 12:43:30.210782 2026] [core:notice] [pid 782784:tid 782921] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:30.214845 2026] [security2:error] [pid 782784:tid 782921] [client 103.215.74.26:33770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNQoaApLsOvtuGcVqgNwAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:30.248392 2026] [security2:error] [pid 782784:tid 782918] [client 51.120.79.193:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amuNQoaApLsOvtuGcVqgOQAAAAQ"]
[Thu Jul 30 12:43:30.248519 2026] [security2:error] [pid 782784:tid 782918] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amuNQoaApLsOvtuGcVqgOQAAAAQ"]
[Thu Jul 30 12:43:30.248603 2026] [security2:error] [pid 782784:tid 782918] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amuNQoaApLsOvtuGcVqgOQAAAAQ"]
[Thu Jul 30 12:43:30.559225 2026] [security2:error] [pid 782784:tid 783009] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amuNQoaApLsOvtuGcVqgPgAAAF8"]
[Thu Jul 30 12:43:30.559371 2026] [security2:error] [pid 782784:tid 783009] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amuNQoaApLsOvtuGcVqgPgAAAF8"]
[Thu Jul 30 12:43:30.588947 2026] [security2:error] [pid 782784:tid 782922] [client 20.52.125.110:1255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/repeater.php"] [unique_id "amuNQoaApLsOvtuGcVqgQAAAAAg"]
[Thu Jul 30 12:43:30.882370 2026] [security2:error] [pid 782784:tid 782978] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuNQoaApLsOvtuGcVqgTQAAAEA"]
[Thu Jul 30 12:43:30.882489 2026] [security2:error] [pid 782784:tid 782978] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuNQoaApLsOvtuGcVqgTQAAAEA"]
[Thu Jul 30 12:43:30.950576 2026] [core:notice] [pid 782784:tid 783017] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:30.954764 2026] [security2:error] [pid 782784:tid 783017] [client 103.215.74.26:33788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNQoaApLsOvtuGcVqgTgAAAGc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:31.198546 2026] [security2:error] [pid 782784:tid 783001] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/edit.php"] [unique_id "amuNQ4aApLsOvtuGcVqgWAAAAFc"]
[Thu Jul 30 12:43:31.198650 2026] [security2:error] [pid 782784:tid 783001] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/edit.php"] [unique_id "amuNQ4aApLsOvtuGcVqgWAAAAFc"]
[Thu Jul 30 12:43:31.518395 2026] [security2:error] [pid 782784:tid 782930] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amuNQ4aApLsOvtuGcVqgYwAAABA"]
[Thu Jul 30 12:43:31.518483 2026] [security2:error] [pid 782784:tid 782930] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amuNQ4aApLsOvtuGcVqgYwAAABA"]
[Thu Jul 30 12:43:31.683790 2026] [core:notice] [pid 782784:tid 782940] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:31.692658 2026] [security2:error] [pid 782784:tid 782940] [client 103.215.74.26:33792] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNQ4aApLsOvtuGcVqgawAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:31.833809 2026] [security2:error] [pid 782784:tid 783040] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amuNQ4aApLsOvtuGcVqggwAAAH4"]
[Thu Jul 30 12:43:31.833967 2026] [security2:error] [pid 782784:tid 783040] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amuNQ4aApLsOvtuGcVqggwAAAH4"]
[Thu Jul 30 12:43:32.143048 2026] [security2:error] [pid 782784:tid 783009] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/av.php"] [unique_id "amuNRIaApLsOvtuGcVqgiwAAAF8"]
[Thu Jul 30 12:43:32.143195 2026] [security2:error] [pid 782784:tid 783009] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/av.php"] [unique_id "amuNRIaApLsOvtuGcVqgiwAAAF8"]
[Thu Jul 30 12:43:32.437002 2026] [core:notice] [pid 782784:tid 782953] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:32.443762 2026] [security2:error] [pid 782784:tid 782953] [client 103.215.74.26:33802] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNRIaApLsOvtuGcVqgmAAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:32.444581 2026] [security2:error] [pid 782784:tid 782935] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/classwithtostring.php"] [unique_id "amuNRIaApLsOvtuGcVqgmQAAABU"]
[Thu Jul 30 12:43:32.444703 2026] [security2:error] [pid 782784:tid 782935] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/classwithtostring.php"] [unique_id "amuNRIaApLsOvtuGcVqgmQAAABU"]
[Thu Jul 30 12:43:32.745439 2026] [security2:error] [pid 782784:tid 782933] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuNRIaApLsOvtuGcVqgoAAAABM"]
[Thu Jul 30 12:43:32.745575 2026] [security2:error] [pid 782784:tid 782933] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuNRIaApLsOvtuGcVqgoAAAABM"]
[Thu Jul 30 12:43:33.051084 2026] [security2:error] [pid 782784:tid 782968] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-blog.php"] [unique_id "amuNRYaApLsOvtuGcVqgqgAAADY"]
[Thu Jul 30 12:43:33.051242 2026] [security2:error] [pid 782784:tid 782968] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-blog.php"] [unique_id "amuNRYaApLsOvtuGcVqgqgAAADY"]
[Thu Jul 30 12:43:33.197381 2026] [core:notice] [pid 782784:tid 782951] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:33.201739 2026] [security2:error] [pid 782784:tid 782951] [client 103.215.74.26:50584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNRYaApLsOvtuGcVqgqwAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:33.358171 2026] [proxy:error] [pid 782784:tid 782954] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:33.358237 2026] [proxy_http:error] [pid 782784:tid 782954] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:33.358800 2026] [proxy:error] [pid 782784:tid 782954] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:33.358843 2026] [proxy_http:error] [pid 782784:tid 782954] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:33.358924 2026] [security2:error] [pid 782784:tid 782954] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNRYaApLsOvtuGcVqgsgAAACg"]
[Thu Jul 30 12:43:33.663185 2026] [security2:error] [pid 782784:tid 782969] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amuNRYaApLsOvtuGcVqgtwAAADc"]
[Thu Jul 30 12:43:33.663394 2026] [security2:error] [pid 782784:tid 782969] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amuNRYaApLsOvtuGcVqgtwAAADc"]
[Thu Jul 30 12:43:33.957937 2026] [core:notice] [pid 782784:tid 782958] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:33.961663 2026] [security2:error] [pid 782784:tid 782958] [client 103.215.74.26:50600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNRYaApLsOvtuGcVqgxgAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:33.966107 2026] [security2:error] [pid 782784:tid 782985] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/adminfuns.php"] [unique_id "amuNRYaApLsOvtuGcVqgyAAAAEc"]
[Thu Jul 30 12:43:33.966229 2026] [security2:error] [pid 782784:tid 782985] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/adminfuns.php"] [unique_id "amuNRYaApLsOvtuGcVqgyAAAAEc"]
[Thu Jul 30 12:43:34.129461 2026] [security2:error] [pid 782784:tid 782956] [client 20.63.98.115:59027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-mail.php"] [unique_id "amuNRoaApLsOvtuGcVqgzQAAACo"]
[Thu Jul 30 12:43:34.269940 2026] [security2:error] [pid 782784:tid 782947] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/goods.php"] [unique_id "amuNRoaApLsOvtuGcVqg0AAAACE"]
[Thu Jul 30 12:43:34.270064 2026] [security2:error] [pid 782784:tid 782947] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/goods.php"] [unique_id "amuNRoaApLsOvtuGcVqg0AAAACE"]
[Thu Jul 30 12:43:34.593711 2026] [security2:error] [pid 782784:tid 782953] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ms-edit.php"] [unique_id "amuNRoaApLsOvtuGcVqg3AAAACc"]
[Thu Jul 30 12:43:34.593827 2026] [security2:error] [pid 782784:tid 782953] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ms-edit.php"] [unique_id "amuNRoaApLsOvtuGcVqg3AAAACc"]
[Thu Jul 30 12:43:34.709555 2026] [core:notice] [pid 782784:tid 782965] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:34.717004 2026] [security2:error] [pid 782784:tid 782965] [client 103.215.74.26:50616] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNRoaApLsOvtuGcVqg4AAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:34.895499 2026] [security2:error] [pid 782784:tid 783017] [client 152.32.217.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fdd.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuNRoaApLsOvtuGcVqg3wAAAGc"]
[Thu Jul 30 12:43:34.922017 2026] [security2:error] [pid 782784:tid 782976] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/222.php"] [unique_id "amuNRoaApLsOvtuGcVqg6QAAAD4"]
[Thu Jul 30 12:43:34.922104 2026] [security2:error] [pid 782784:tid 782976] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/222.php"] [unique_id "amuNRoaApLsOvtuGcVqg6QAAAD4"]
[Thu Jul 30 12:43:35.228944 2026] [security2:error] [pid 782784:tid 782934] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/cgi-bin/index.php"] [unique_id "amuNR4aApLsOvtuGcVqg7AAAABQ"]
[Thu Jul 30 12:43:35.229062 2026] [security2:error] [pid 782784:tid 782934] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/cgi-bin/index.php"] [unique_id "amuNR4aApLsOvtuGcVqg7AAAABQ"]
[Thu Jul 30 12:43:35.445534 2026] [core:notice] [pid 782784:tid 782968] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:35.449548 2026] [security2:error] [pid 782784:tid 782968] [client 103.215.74.26:50622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNR4aApLsOvtuGcVqg-gAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:35.571159 2026] [proxy:error] [pid 782784:tid 782940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:35.571226 2026] [proxy_http:error] [pid 782784:tid 782940] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:35.571835 2026] [proxy:error] [pid 782784:tid 782940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:35.571879 2026] [proxy_http:error] [pid 782784:tid 782940] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:35.571997 2026] [security2:error] [pid 782784:tid 782940] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNR4aApLsOvtuGcVqhAQAAABo"]
[Thu Jul 30 12:43:35.871215 2026] [security2:error] [pid 782784:tid 782958] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/BDKR28WP.php"] [unique_id "amuNR4aApLsOvtuGcVqhCwAAACw"]
[Thu Jul 30 12:43:35.871348 2026] [security2:error] [pid 782784:tid 782958] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/BDKR28WP.php"] [unique_id "amuNR4aApLsOvtuGcVqhCwAAACw"]
[Thu Jul 30 12:43:36.198202 2026] [proxy:error] [pid 782784:tid 783030] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:36.198292 2026] [proxy_http:error] [pid 782784:tid 783030] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:36.199028 2026] [proxy:error] [pid 782784:tid 783030] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:36.199080 2026] [proxy_http:error] [pid 782784:tid 783030] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:36.199198 2026] [security2:error] [pid 782784:tid 783030] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNSIaApLsOvtuGcVqhFQAAAHQ"]
[Thu Jul 30 12:43:36.373021 2026] [core:notice] [pid 782784:tid 782898] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:36.494369 2026] [security2:error] [pid 782784:tid 783037] [client 20.63.98.115:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-trackback.php"] [unique_id "amuNSIaApLsOvtuGcVqhKQAAAHs"]
[Thu Jul 30 12:43:36.507906 2026] [proxy:error] [pid 782784:tid 782943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:36.507995 2026] [proxy_http:error] [pid 782784:tid 782943] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:36.508801 2026] [proxy:error] [pid 782784:tid 782943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:36.508855 2026] [proxy_http:error] [pid 782784:tid 782943] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:36.508967 2026] [security2:error] [pid 782784:tid 782943] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNSIaApLsOvtuGcVqhKwAAAB0"]
[Thu Jul 30 12:43:36.825287 2026] [security2:error] [pid 782784:tid 782983] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp.php"] [unique_id "amuNSIaApLsOvtuGcVqhNQAAAEU"]
[Thu Jul 30 12:43:36.825448 2026] [security2:error] [pid 782784:tid 782983] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp.php"] [unique_id "amuNSIaApLsOvtuGcVqhNQAAAEU"]
[Thu Jul 30 12:43:36.960383 2026] [core:notice] [pid 782784:tid 782992] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:36.966965 2026] [security2:error] [pid 782784:tid 782992] [client 103.215.74.26:50628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNSIaApLsOvtuGcVqhOgAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:37.139727 2026] [security2:error] [pid 782784:tid 783000] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/abcd.php"] [unique_id "amuNSYaApLsOvtuGcVqhQAAAAFY"]
[Thu Jul 30 12:43:37.139867 2026] [security2:error] [pid 782784:tid 783000] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/abcd.php"] [unique_id "amuNSYaApLsOvtuGcVqhQAAAAFY"]
[Thu Jul 30 12:43:37.448885 2026] [security2:error] [pid 782784:tid 783032] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/a1.php"] [unique_id "amuNSYaApLsOvtuGcVqhRAAAAHY"]
[Thu Jul 30 12:43:37.449023 2026] [security2:error] [pid 782784:tid 783032] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/a1.php"] [unique_id "amuNSYaApLsOvtuGcVqhRAAAAHY"]
[Thu Jul 30 12:43:37.462522 2026] [security2:error] [pid 782784:tid 783004] [client 150.107.232.194:26686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNSYaApLsOvtuGcVqhRQAAAFo"]
[Thu Jul 30 12:43:37.462649 2026] [security2:error] [pid 782784:tid 783004] [client 150.107.232.194:26686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNSYaApLsOvtuGcVqhRQAAAFo"]
[Thu Jul 30 12:43:37.589935 2026] [core:notice] [pid 782784:tid 783024] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:37.591658 2026] [security2:error] [pid 782784:tid 783005] [client 38.190.144.4:54651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNSYaApLsOvtuGcVqhTQAAAFs"]
[Thu Jul 30 12:43:37.591772 2026] [security2:error] [pid 782784:tid 783005] [client 38.190.144.4:54651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNSYaApLsOvtuGcVqhTQAAAFs"]
[Thu Jul 30 12:43:37.689492 2026] [core:notice] [pid 782784:tid 783018] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:37.693474 2026] [security2:error] [pid 782784:tid 783018] [client 103.215.74.26:50638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNSYaApLsOvtuGcVqhTgAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:37.704898 2026] [security2:error] [pid 782784:tid 782926] [client 20.63.98.115:31835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/uploads/cong.php"] [unique_id "amuNSYaApLsOvtuGcVqhTwAAAAw"]
[Thu Jul 30 12:43:37.745442 2026] [security2:error] [pid 782784:tid 783041] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuNSYaApLsOvtuGcVqhUAAAAH8"]
[Thu Jul 30 12:43:37.745538 2026] [security2:error] [pid 782784:tid 783041] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuNSYaApLsOvtuGcVqhUAAAAH8"]
[Thu Jul 30 12:43:38.038063 2026] [security2:error] [pid 782784:tid 782785] [remote 184.168.126.180:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuNSoaApLsOvtuGcVqhWgAANwA"]
[Thu Jul 30 12:43:38.063990 2026] [core:notice] [pid 782784:tid 783016] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:38.065808 2026] [security2:error] [pid 782784:tid 782997] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuNSoaApLsOvtuGcVqhXAAAAFM"]
[Thu Jul 30 12:43:38.065905 2026] [security2:error] [pid 782784:tid 782997] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuNSoaApLsOvtuGcVqhXAAAAFM"]
[Thu Jul 30 12:43:38.373374 2026] [proxy:error] [pid 782784:tid 783037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:38.373449 2026] [proxy_http:error] [pid 782784:tid 783037] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:38.374166 2026] [proxy:error] [pid 782784:tid 783037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:38.374216 2026] [proxy_http:error] [pid 782784:tid 783037] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:38.374326 2026] [security2:error] [pid 782784:tid 783037] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNSoaApLsOvtuGcVqhZAAAAHs"]
[Thu Jul 30 12:43:38.426911 2026] [core:notice] [pid 782784:tid 783038] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:38.430841 2026] [security2:error] [pid 782784:tid 783038] [client 103.215.74.26:50640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNSoaApLsOvtuGcVqhZQAAAHw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:38.690913 2026] [security2:error] [pid 782784:tid 783014] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/simple.php"] [unique_id "amuNSoaApLsOvtuGcVqhdgAAAGQ"]
[Thu Jul 30 12:43:38.691034 2026] [security2:error] [pid 782784:tid 783014] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/simple.php"] [unique_id "amuNSoaApLsOvtuGcVqhdgAAAGQ"]
[Thu Jul 30 12:43:38.890679 2026] [security2:error] [pid 782784:tid 782959] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNSoaApLsOvtuGcVqhYwAALRY"]
[Thu Jul 30 12:43:38.991817 2026] [security2:error] [pid 782784:tid 783021] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xxx.php"] [unique_id "amuNSoaApLsOvtuGcVqhegAAAGs"]
[Thu Jul 30 12:43:38.991925 2026] [security2:error] [pid 782784:tid 783021] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xxx.php"] [unique_id "amuNSoaApLsOvtuGcVqhegAAAGs"]
[Thu Jul 30 12:43:39.298613 2026] [security2:error] [pid 782784:tid 783004] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/hypo.php"] [unique_id "amuNS4aApLsOvtuGcVqhhAAAAFo"]
[Thu Jul 30 12:43:39.298720 2026] [security2:error] [pid 782784:tid 783004] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/hypo.php"] [unique_id "amuNS4aApLsOvtuGcVqhhAAAAFo"]
[Thu Jul 30 12:43:39.565130 2026] [security2:error] [pid 782784:tid 782967] [client 52.238.199.152:46160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/gmo.php"] [unique_id "amuNS4aApLsOvtuGcVqhhwAAADU"]
[Thu Jul 30 12:43:39.602717 2026] [proxy:error] [pid 782784:tid 783019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:39.602799 2026] [proxy_http:error] [pid 782784:tid 783019] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:39.603574 2026] [proxy:error] [pid 782784:tid 783019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:39.603624 2026] [proxy_http:error] [pid 782784:tid 783019] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:39.603734 2026] [security2:error] [pid 782784:tid 783019] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNS4aApLsOvtuGcVqhiAAAAGk"]
[Thu Jul 30 12:43:39.793822 2026] [security2:error] [pid 782784:tid 782918] [client 152.32.217.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fdd.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuNS4aApLsOvtuGcVqhiwAAAAQ"]
[Thu Jul 30 12:43:39.836931 2026] [security2:error] [pid 782784:tid 782971] [client 196.196.53.4:56319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.53.196.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/send_mail.php"] [unique_id "amuNS4aApLsOvtuGcVqhhQAAADk"], referer: http://asian-connect.com/
[Thu Jul 30 12:43:40.042399 2026] [security2:error] [pid 782784:tid 782964] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/chosen.php"] [unique_id "amuNTIaApLsOvtuGcVqhkgAAADI"]
[Thu Jul 30 12:43:40.042522 2026] [security2:error] [pid 782784:tid 782964] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/chosen.php"] [unique_id "amuNTIaApLsOvtuGcVqhkgAAADI"]
[Thu Jul 30 12:43:40.283879 2026] [security2:error] [pid 782784:tid 783017] [client 20.63.98.115:38194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuNTIaApLsOvtuGcVqhoQAAAGc"]
[Thu Jul 30 12:43:40.360284 2026] [proxy:error] [pid 782784:tid 782917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:40.360367 2026] [proxy_http:error] [pid 782784:tid 782917] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:40.360917 2026] [proxy:error] [pid 782784:tid 782917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:40.360958 2026] [proxy_http:error] [pid 782784:tid 782917] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:40.361061 2026] [security2:error] [pid 782784:tid 782917] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNTIaApLsOvtuGcVqhogAAAAM"]
[Thu Jul 30 12:43:40.420694 2026] [security2:error] [pid 782784:tid 782815] [remote 40.77.167.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/181"] [unique_id "amuNTIaApLsOvtuGcVqhnQAAHB4"]
[Thu Jul 30 12:43:40.672879 2026] [security2:error] [pid 782784:tid 782965] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/als.php"] [unique_id "amuNTIaApLsOvtuGcVqhsQAAADM"]
[Thu Jul 30 12:43:40.673038 2026] [security2:error] [pid 782784:tid 782965] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/als.php"] [unique_id "amuNTIaApLsOvtuGcVqhsQAAADM"]
[Thu Jul 30 12:43:40.977709 2026] [security2:error] [pid 782784:tid 783001] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/pol.php"] [unique_id "amuNTIaApLsOvtuGcVqhuQAAAFc"]
[Thu Jul 30 12:43:40.977833 2026] [security2:error] [pid 782784:tid 783001] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/pol.php"] [unique_id "amuNTIaApLsOvtuGcVqhuQAAAFc"]
[Thu Jul 30 12:43:40.993761 2026] [security2:error] [pid 782784:tid 782937] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNTIaApLsOvtuGcVqhowAAFyU"]
[Thu Jul 30 12:43:41.296172 2026] [security2:error] [pid 782784:tid 782991] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file5.php"] [unique_id "amuNTYaApLsOvtuGcVqhxgAAAE0"]
[Thu Jul 30 12:43:41.296268 2026] [security2:error] [pid 782784:tid 782991] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file5.php"] [unique_id "amuNTYaApLsOvtuGcVqhxgAAAE0"]
[Thu Jul 30 12:43:41.447667 2026] [security2:error] [pid 782784:tid 782993] [client 52.238.199.152:46191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/nakrip.php"] [unique_id "amuNTYaApLsOvtuGcVqhyAAAAE8"]
[Thu Jul 30 12:43:41.601344 2026] [security2:error] [pid 782784:tid 783005] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file.php"] [unique_id "amuNTYaApLsOvtuGcVqh0AAAAFs"]
[Thu Jul 30 12:43:41.601442 2026] [security2:error] [pid 782784:tid 783005] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file.php"] [unique_id "amuNTYaApLsOvtuGcVqh0AAAAFs"]
[Thu Jul 30 12:43:41.913214 2026] [security2:error] [pid 782784:tid 782956] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuNTYaApLsOvtuGcVqh4AAAACo"]
[Thu Jul 30 12:43:41.913350 2026] [security2:error] [pid 782784:tid 782956] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuNTYaApLsOvtuGcVqh4AAAACo"]
[Thu Jul 30 12:43:42.232341 2026] [security2:error] [pid 782784:tid 782923] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aa2.php"] [unique_id "amuNToaApLsOvtuGcVqh5AAAAAk"]
[Thu Jul 30 12:43:42.232434 2026] [security2:error] [pid 782784:tid 782923] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aa2.php"] [unique_id "amuNToaApLsOvtuGcVqh5AAAAAk"]
[Thu Jul 30 12:43:42.540852 2026] [security2:error] [pid 782784:tid 782945] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ccou.php"] [unique_id "amuNToaApLsOvtuGcVqh-AAAAB8"]
[Thu Jul 30 12:43:42.541004 2026] [security2:error] [pid 782784:tid 782945] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ccou.php"] [unique_id "amuNToaApLsOvtuGcVqh-AAAAB8"]
[Thu Jul 30 12:43:42.883575 2026] [security2:error] [pid 782784:tid 782927] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dr.php"] [unique_id "amuNToaApLsOvtuGcVqiBwAAAA0"]
[Thu Jul 30 12:43:42.883680 2026] [security2:error] [pid 782784:tid 782927] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dr.php"] [unique_id "amuNToaApLsOvtuGcVqiBwAAAA0"]
[Thu Jul 30 12:43:43.190728 2026] [security2:error] [pid 782784:tid 783004] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xamp.php"] [unique_id "amuNT4aApLsOvtuGcVqiEgAAAFo"]
[Thu Jul 30 12:43:43.190832 2026] [security2:error] [pid 782784:tid 783004] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xamp.php"] [unique_id "amuNT4aApLsOvtuGcVqiEgAAAFo"]
[Thu Jul 30 12:43:43.505189 2026] [security2:error] [pid 782784:tid 782961] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/bless.php"] [unique_id "amuNT4aApLsOvtuGcVqiKAAAAC8"]
[Thu Jul 30 12:43:43.505316 2026] [security2:error] [pid 782784:tid 782961] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/bless.php"] [unique_id "amuNT4aApLsOvtuGcVqiKAAAAC8"]
[Thu Jul 30 12:43:43.776061 2026] [security2:error] [pid 782784:tid 783025] [client 20.63.98.115:60819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/webadmin.php"] [unique_id "amuNT4aApLsOvtuGcVqiKgAAAG8"]
[Thu Jul 30 12:43:43.807800 2026] [security2:error] [pid 782784:tid 782986] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file25.php"] [unique_id "amuNT4aApLsOvtuGcVqiLQAAAEg"]
[Thu Jul 30 12:43:43.807928 2026] [security2:error] [pid 782784:tid 782986] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file25.php"] [unique_id "amuNT4aApLsOvtuGcVqiLQAAAEg"]
[Thu Jul 30 12:43:44.110060 2026] [security2:error] [pid 782784:tid 782974] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file6.php"] [unique_id "amuNUIaApLsOvtuGcVqiNAAAADw"]
[Thu Jul 30 12:43:44.110175 2026] [security2:error] [pid 782784:tid 782974] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file6.php"] [unique_id "amuNUIaApLsOvtuGcVqiNAAAADw"]
[Thu Jul 30 12:43:44.153693 2026] [core:notice] [pid 782784:tid 783036] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:44.157806 2026] [security2:error] [pid 782784:tid 783036] [client 103.215.74.26:7170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNUIaApLsOvtuGcVqiNQAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:44.182075 2026] [security2:error] [pid 782784:tid 782924] [client 74.7.175.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "amuNUIaApLsOvtuGcVqiOAAAAAo"]
[Thu Jul 30 12:43:44.182674 2026] [security2:error] [pid 782784:tid 783037] [client 74.7.175.133:33078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.gbq.rty.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuNUIaApLsOvtuGcVqiNgAAe0k"]
[Thu Jul 30 12:43:44.412522 2026] [security2:error] [pid 782784:tid 783010] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/a2.php"] [unique_id "amuNUIaApLsOvtuGcVqiSwAAAGA"]
[Thu Jul 30 12:43:44.412610 2026] [security2:error] [pid 782784:tid 783010] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/a2.php"] [unique_id "amuNUIaApLsOvtuGcVqiSwAAAGA"]
[Thu Jul 30 12:43:44.498487 2026] [security2:error] [pid 782784:tid 782896] [remote 65.181.116.253:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nfh.udi.temporary.site"] [uri "/wp-login.php"] [unique_id "amuNUIaApLsOvtuGcVqiTwAABm8"]
[Thu Jul 30 12:43:44.537633 2026] [security2:error] [pid 782784:tid 783007] [client 52.238.199.152:22871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/radio.php"] [unique_id "amuNUIaApLsOvtuGcVqiUAAAAF0"]
[Thu Jul 30 12:43:44.714293 2026] [security2:error] [pid 782784:tid 782959] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file15.php"] [unique_id "amuNUIaApLsOvtuGcVqiVAAAAC0"]
[Thu Jul 30 12:43:44.714417 2026] [security2:error] [pid 782784:tid 782959] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file15.php"] [unique_id "amuNUIaApLsOvtuGcVqiVAAAAC0"]
[Thu Jul 30 12:43:44.799972 2026] [core:error] [pid 782784:tid 782937] [client 20.63.98.115:38151] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:44.800005 2026] [core:error] [pid 782784:tid 782937] [client 20.63.98.115:38151] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:44.894702 2026] [core:notice] [pid 782784:tid 782992] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:44.898742 2026] [security2:error] [pid 782784:tid 782992] [client 103.215.74.26:7174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNUIaApLsOvtuGcVqiWQAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:45.022817 2026] [security2:error] [pid 782784:tid 782914] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/f35.php"] [unique_id "amuNUYaApLsOvtuGcVqiYAAAAAA"]
[Thu Jul 30 12:43:45.022935 2026] [security2:error] [pid 782784:tid 782914] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/f35.php"] [unique_id "amuNUYaApLsOvtuGcVqiYAAAAAA"]
[Thu Jul 30 12:43:45.148568 2026] [security2:error] [pid 782784:tid 782919] [client 38.190.144.4:55164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNUYaApLsOvtuGcVqiYgAAAAU"]
[Thu Jul 30 12:43:45.148717 2026] [security2:error] [pid 782784:tid 782919] [client 38.190.144.4:55164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNUYaApLsOvtuGcVqiYgAAAAU"]
[Thu Jul 30 12:43:45.342903 2026] [security2:error] [pid 782784:tid 782918] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-load.php"] [unique_id "amuNUYaApLsOvtuGcVqiZAAAAAQ"]
[Thu Jul 30 12:43:45.343055 2026] [security2:error] [pid 782784:tid 782918] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-load.php"] [unique_id "amuNUYaApLsOvtuGcVqiZAAAAAQ"]
[Thu Jul 30 12:43:45.615194 2026] [core:notice] [pid 782784:tid 783019] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:45.619311 2026] [security2:error] [pid 782784:tid 783019] [client 103.215.74.26:7176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNUYaApLsOvtuGcVqicQAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:45.640937 2026] [security2:error] [pid 782784:tid 783027] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xwpg.php"] [unique_id "amuNUYaApLsOvtuGcVqicgAAAHE"]
[Thu Jul 30 12:43:45.641054 2026] [security2:error] [pid 782784:tid 783027] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xwpg.php"] [unique_id "amuNUYaApLsOvtuGcVqicgAAAHE"]
[Thu Jul 30 12:43:45.942382 2026] [proxy:error] [pid 782784:tid 782929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:45.942452 2026] [proxy_http:error] [pid 782784:tid 782929] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:45.943049 2026] [proxy:error] [pid 782784:tid 782929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:45.943096 2026] [proxy_http:error] [pid 782784:tid 782929] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:45.943193 2026] [security2:error] [pid 782784:tid 782929] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNUYaApLsOvtuGcVqidgAAAA8"]
[Thu Jul 30 12:43:46.019720 2026] [security2:error] [pid 782784:tid 783000] [client 52.238.199.152:23405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-singin.php"] [unique_id "amuNUoaApLsOvtuGcVqieQAAAFY"]
[Thu Jul 30 12:43:46.252144 2026] [proxy:error] [pid 782784:tid 782978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:46.252223 2026] [proxy_http:error] [pid 782784:tid 782978] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:46.252792 2026] [proxy:error] [pid 782784:tid 782978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:43:46.252833 2026] [proxy_http:error] [pid 782784:tid 782978] [client 51.120.79.193:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:43:46.252927 2026] [security2:error] [pid 782784:tid 782978] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuNUoaApLsOvtuGcVqifgAAAEA"]
[Thu Jul 30 12:43:46.339071 2026] [core:notice] [pid 782784:tid 782944] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:46.343014 2026] [security2:error] [pid 782784:tid 782944] [client 103.215.74.26:7180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNUoaApLsOvtuGcVqigAAAAB4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:46.631283 2026] [security2:error] [pid 782784:tid 782973] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xstelth.php"] [unique_id "amuNUoaApLsOvtuGcVqiiwAAADs"]
[Thu Jul 30 12:43:46.631433 2026] [security2:error] [pid 782784:tid 782973] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xstelth.php"] [unique_id "amuNUoaApLsOvtuGcVqiiwAAADs"]
[Thu Jul 30 12:43:46.636473 2026] [security2:error] [pid 782784:tid 782965] [client 43.173.175.246:46522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuNUoaApLsOvtuGcVqigQAAADM"]
[Thu Jul 30 12:43:46.915178 2026] [security2:error] [pid 782784:tid 782977] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNUoaApLsOvtuGcVqifwAAP2M"]
[Thu Jul 30 12:43:46.925374 2026] [security2:error] [pid 782784:tid 782937] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuNUoaApLsOvtuGcVqijQAAABc"]
[Thu Jul 30 12:43:46.925478 2026] [security2:error] [pid 782784:tid 782937] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuNUoaApLsOvtuGcVqijQAAABc"]
[Thu Jul 30 12:43:47.075235 2026] [core:notice] [pid 782784:tid 782991] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:47.079103 2026] [security2:error] [pid 782784:tid 782991] [client 103.215.74.26:7196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNU4aApLsOvtuGcVqilAAAAE0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:47.226720 2026] [security2:error] [pid 782784:tid 783003] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aaa.php"] [unique_id "amuNU4aApLsOvtuGcVqimAAAAFk"]
[Thu Jul 30 12:43:47.226831 2026] [security2:error] [pid 782784:tid 783003] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aaa.php"] [unique_id "amuNU4aApLsOvtuGcVqimAAAAFk"]
[Thu Jul 30 12:43:47.347348 2026] [security2:error] [pid 782784:tid 782920] [client 20.63.98.115:60808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/link.php"] [unique_id "amuNU4aApLsOvtuGcVqimgAAAAY"]
[Thu Jul 30 12:43:47.478415 2026] [security2:error] [pid 782784:tid 783023] [client 52.238.199.152:22903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/as.php"] [unique_id "amuNU4aApLsOvtuGcVqimwAAAG0"]
[Thu Jul 30 12:43:47.542713 2026] [security2:error] [pid 782784:tid 782972] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/gecko.php"] [unique_id "amuNU4aApLsOvtuGcVqinwAAADo"]
[Thu Jul 30 12:43:47.542794 2026] [security2:error] [pid 782784:tid 782972] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/gecko.php"] [unique_id "amuNU4aApLsOvtuGcVqinwAAADo"]
[Thu Jul 30 12:43:47.804956 2026] [core:notice] [pid 782784:tid 782966] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:47.809352 2026] [security2:error] [pid 782784:tid 782966] [client 103.215.74.26:7204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNU4aApLsOvtuGcVqipgAAADQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:47.843206 2026] [security2:error] [pid 782784:tid 782964] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/pbck.php"] [unique_id "amuNU4aApLsOvtuGcVqipwAAADI"]
[Thu Jul 30 12:43:47.843300 2026] [security2:error] [pid 782784:tid 782964] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/pbck.php"] [unique_id "amuNU4aApLsOvtuGcVqipwAAADI"]
[Thu Jul 30 12:43:47.935076 2026] [security2:error] [pid 782784:tid 782936] [client 150.107.232.194:26639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNU4aApLsOvtuGcVqiqAAAABY"]
[Thu Jul 30 12:43:47.935180 2026] [security2:error] [pid 782784:tid 782936] [client 150.107.232.194:26639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNU4aApLsOvtuGcVqiqAAAABY"]
[Thu Jul 30 12:43:48.142145 2026] [security2:error] [pid 782784:tid 782960] [client 20.63.98.115:61443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ova.php"] [unique_id "amuNVIaApLsOvtuGcVqirQAAAC4"]
[Thu Jul 30 12:43:48.142723 2026] [security2:error] [pid 782784:tid 782963] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xiugai.php"] [unique_id "amuNVIaApLsOvtuGcVqirgAAADE"]
[Thu Jul 30 12:43:48.142802 2026] [security2:error] [pid 782784:tid 782963] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xiugai.php"] [unique_id "amuNVIaApLsOvtuGcVqirgAAADE"]
[Thu Jul 30 12:43:48.455437 2026] [security2:error] [pid 782784:tid 783012] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/e.php"] [unique_id "amuNVIaApLsOvtuGcVqitwAAAGI"]
[Thu Jul 30 12:43:48.455558 2026] [security2:error] [pid 782784:tid 783012] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/e.php"] [unique_id "amuNVIaApLsOvtuGcVqitwAAAGI"]
[Thu Jul 30 12:43:48.544162 2026] [core:notice] [pid 782784:tid 782976] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:48.548254 2026] [security2:error] [pid 782784:tid 782976] [client 103.215.74.26:7218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNVIaApLsOvtuGcVqiuAAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:48.580168 2026] [security2:error] [pid 782784:tid 782911] [remote 57.141.0.5:45020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuNVIaApLsOvtuGcVqiuQAAH34"]
[Thu Jul 30 12:43:48.778570 2026] [security2:error] [pid 782784:tid 782983] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/adminner.php"] [unique_id "amuNVIaApLsOvtuGcVqiwwAAAEU"]
[Thu Jul 30 12:43:48.778660 2026] [security2:error] [pid 782784:tid 782983] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/adminner.php"] [unique_id "amuNVIaApLsOvtuGcVqiwwAAAEU"]
[Thu Jul 30 12:43:49.083962 2026] [security2:error] [pid 782784:tid 782993] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file1221.php"] [unique_id "amuNVYaApLsOvtuGcVqixAAAAE8"]
[Thu Jul 30 12:43:49.084095 2026] [security2:error] [pid 782784:tid 782993] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/file1221.php"] [unique_id "amuNVYaApLsOvtuGcVqixAAAAE8"]
[Thu Jul 30 12:43:49.219812 2026] [security2:error] [pid 782784:tid 782951] [client 52.238.199.152:46202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/x.php"] [unique_id "amuNVYaApLsOvtuGcVqizwAAACU"]
[Thu Jul 30 12:43:49.283525 2026] [security2:error] [pid 782784:tid 782937] [client 20.63.98.115:47434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/colors/coffee/about.php"] [unique_id "amuNVYaApLsOvtuGcVqi0wAAABc"]
[Thu Jul 30 12:43:49.284381 2026] [core:notice] [pid 782784:tid 783008] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:49.288440 2026] [security2:error] [pid 782784:tid 783008] [client 103.215.74.26:7234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNVYaApLsOvtuGcVqi0gAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:49.376657 2026] [core:notice] [pid 782784:tid 782808] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:49.400717 2026] [security2:error] [pid 782784:tid 782957] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/inx.php"] [unique_id "amuNVYaApLsOvtuGcVqi1QAAACs"]
[Thu Jul 30 12:43:49.400826 2026] [security2:error] [pid 782784:tid 782957] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/inx.php"] [unique_id "amuNVYaApLsOvtuGcVqi1QAAACs"]
[Thu Jul 30 12:43:49.430598 2026] [fcgid:warn] [pid 782784:tid 782999] (70014)End of file found: [client 106.63.26.140:9230] mod_fcgid: can't get data from http client
[Thu Jul 30 12:43:49.509036 2026] [core:error] [pid 782784:tid 782800] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:49.509057 2026] [core:error] [pid 782784:tid 782800] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:49.724872 2026] [security2:error] [pid 782784:tid 782947] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/qqqa.php"] [unique_id "amuNVYaApLsOvtuGcVqi3gAAACE"]
[Thu Jul 30 12:43:49.725000 2026] [security2:error] [pid 782784:tid 782947] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/qqqa.php"] [unique_id "amuNVYaApLsOvtuGcVqi3gAAACE"]
[Thu Jul 30 12:43:50.023790 2026] [core:notice] [pid 782784:tid 782929] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:50.029147 2026] [security2:error] [pid 782784:tid 782929] [client 103.215.74.26:7240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNVoaApLsOvtuGcVqi4wAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:50.036959 2026] [security2:error] [pid 782784:tid 783037] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/reviall.php"] [unique_id "amuNVoaApLsOvtuGcVqi5QAAAHs"]
[Thu Jul 30 12:43:50.037049 2026] [security2:error] [pid 782784:tid 783037] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/reviall.php"] [unique_id "amuNVoaApLsOvtuGcVqi5QAAAHs"]
[Thu Jul 30 12:43:50.351569 2026] [security2:error] [pid 782784:tid 782973] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/404.php"] [unique_id "amuNVoaApLsOvtuGcVqi8wAAADs"]
[Thu Jul 30 12:43:50.351689 2026] [security2:error] [pid 782784:tid 782973] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/404.php"] [unique_id "amuNVoaApLsOvtuGcVqi8wAAADs"]
[Thu Jul 30 12:43:50.443027 2026] [security2:error] [pid 782784:tid 782942] [client 20.91.199.21:54694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/011i.php"] [unique_id "amuNVoaApLsOvtuGcVqi9QAAABw"]
[Thu Jul 30 12:43:50.443402 2026] [core:error] [pid 782784:tid 782801] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:50.443425 2026] [core:error] [pid 782784:tid 782801] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:50.506973 2026] [core:error] [pid 782784:tid 782805] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:50.507012 2026] [core:error] [pid 782784:tid 782805] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:50.678346 2026] [security2:error] [pid 782784:tid 782981] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/bolt.php"] [unique_id "amuNVoaApLsOvtuGcVqi_wAAAEM"]
[Thu Jul 30 12:43:50.678502 2026] [security2:error] [pid 782784:tid 782981] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/bolt.php"] [unique_id "amuNVoaApLsOvtuGcVqi_wAAAEM"]
[Thu Jul 30 12:43:50.752890 2026] [core:notice] [pid 782784:tid 782984] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:50.760149 2026] [security2:error] [pid 782784:tid 782984] [client 103.215.74.26:7246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNVoaApLsOvtuGcVqjAwAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:50.987153 2026] [security2:error] [pid 782784:tid 783003] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/File.php"] [unique_id "amuNVoaApLsOvtuGcVqjBwAAAFk"]
[Thu Jul 30 12:43:50.987258 2026] [security2:error] [pid 782784:tid 783003] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/File.php"] [unique_id "amuNVoaApLsOvtuGcVqjBwAAAFk"]
[Thu Jul 30 12:43:51.293149 2026] [security2:error] [pid 782784:tid 782994] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fi22.php"] [unique_id "amuNV4aApLsOvtuGcVqjDwAAAFA"]
[Thu Jul 30 12:43:51.293270 2026] [security2:error] [pid 782784:tid 782994] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fi22.php"] [unique_id "amuNV4aApLsOvtuGcVqjDwAAAFA"]
[Thu Jul 30 12:43:51.475265 2026] [core:notice] [pid 782784:tid 782918] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:51.482918 2026] [security2:error] [pid 782784:tid 782918] [client 103.215.74.26:7248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNV4aApLsOvtuGcVqjFQAAAAQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:51.602636 2026] [security2:error] [pid 782784:tid 782995] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/zero.php"] [unique_id "amuNV4aApLsOvtuGcVqjFgAAAFE"]
[Thu Jul 30 12:43:51.602742 2026] [security2:error] [pid 782784:tid 782995] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/zero.php"] [unique_id "amuNV4aApLsOvtuGcVqjFgAAAFE"]
[Thu Jul 30 12:43:51.645278 2026] [security2:error] [pid 782784:tid 782831] [remote 57.141.0.45:23094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/261"] [unique_id "amuNV4aApLsOvtuGcVqjFwAAeC4"]
[Thu Jul 30 12:43:51.688347 2026] [security2:error] [pid 782784:tid 782974] [client 52.238.199.152:23393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/item.php"] [unique_id "amuNV4aApLsOvtuGcVqjGAAAADw"]
[Thu Jul 30 12:43:51.804480 2026] [security2:error] [pid 782784:tid 782829] [remote 74.7.241.59:42940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuNV4aApLsOvtuGcVqjHAAAZCw"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/insert-headers-and-footers/includes
[Thu Jul 30 12:43:51.911046 2026] [security2:error] [pid 782784:tid 783022] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1xmomo.php"] [unique_id "amuNV4aApLsOvtuGcVqjIwAAAGw"]
[Thu Jul 30 12:43:51.911159 2026] [security2:error] [pid 782784:tid 783022] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1xmomo.php"] [unique_id "amuNV4aApLsOvtuGcVqjIwAAAGw"]
[Thu Jul 30 12:43:51.945685 2026] [security2:error] [pid 782784:tid 782923] [client 20.63.98.115:54764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuNV4aApLsOvtuGcVqjJAAAAAk"]
[Thu Jul 30 12:43:52.027075 2026] [security2:error] [pid 782784:tid 783024] [client 20.91.199.21:51837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/03a005685d.php"] [unique_id "amuNWIaApLsOvtuGcVqjKQAAAG4"]
[Thu Jul 30 12:43:52.201230 2026] [core:notice] [pid 782784:tid 783011] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:52.205911 2026] [security2:error] [pid 782784:tid 783011] [client 103.215.74.26:7250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNWIaApLsOvtuGcVqjKwAAAGE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:52.227435 2026] [security2:error] [pid 782784:tid 782975] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fmws.php"] [unique_id "amuNWIaApLsOvtuGcVqjLAAAAD0"]
[Thu Jul 30 12:43:52.227584 2026] [security2:error] [pid 782784:tid 782975] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fmws.php"] [unique_id "amuNWIaApLsOvtuGcVqjLAAAAD0"]
[Thu Jul 30 12:43:52.392249 2026] [security2:error] [pid 782784:tid 782929] [client 106.222.214.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuNWIaApLsOvtuGcVqjJwAAAA8"], referer: https://tereashops.com/product/ploom-x-aura-mevius-aromarich-reg%E8%B6%85%E6%BF%83%E5%8E%9F%E5%91%B3%E7%85%99%E5%BD%88/
[Thu Jul 30 12:43:52.532115 2026] [security2:error] [pid 782784:tid 782963] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuNWIaApLsOvtuGcVqjOQAAADE"]
[Thu Jul 30 12:43:52.532254 2026] [security2:error] [pid 782784:tid 782963] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuNWIaApLsOvtuGcVqjOQAAADE"]
[Thu Jul 30 12:43:52.789618 2026] [security2:error] [pid 782784:tid 782813] [remote 57.141.0.63:42720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuNWIaApLsOvtuGcVqjPQAAXRw"]
[Thu Jul 30 12:43:52.803021 2026] [security2:error] [pid 782784:tid 783001] [client 20.63.98.115:54720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/users.php"] [unique_id "amuNWIaApLsOvtuGcVqjPgAAAFc"]
[Thu Jul 30 12:43:52.837641 2026] [security2:error] [pid 782784:tid 783017] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/hp2.php"] [unique_id "amuNWIaApLsOvtuGcVqjQQAAAGc"]
[Thu Jul 30 12:43:52.837749 2026] [security2:error] [pid 782784:tid 783017] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/hp2.php"] [unique_id "amuNWIaApLsOvtuGcVqjQQAAAGc"]
[Thu Jul 30 12:43:52.853441 2026] [security2:error] [pid 782784:tid 783027] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNWIaApLsOvtuGcVqjKgAAcSM"]
[Thu Jul 30 12:43:52.954517 2026] [core:notice] [pid 782784:tid 782977] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:52.958712 2026] [security2:error] [pid 782784:tid 782977] [client 103.215.74.26:7258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNWIaApLsOvtuGcVqjSAAAAD8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:53.134257 2026] [security2:error] [pid 782784:tid 782983] [client 20.91.199.21:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/403.php"] [unique_id "amuNWYaApLsOvtuGcVqjSQAAAEU"]
[Thu Jul 30 12:43:53.145310 2026] [security2:error] [pid 782784:tid 782962] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aabb.php"] [unique_id "amuNWYaApLsOvtuGcVqjSgAAADA"]
[Thu Jul 30 12:43:53.145404 2026] [security2:error] [pid 782784:tid 782962] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aabb.php"] [unique_id "amuNWYaApLsOvtuGcVqjSgAAADA"]
[Thu Jul 30 12:43:53.200142 2026] [security2:error] [pid 782784:tid 783004] [client 43.173.176.35:53508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuNWIaApLsOvtuGcVqjRwAAAFo"]
[Thu Jul 30 12:43:53.459060 2026] [security2:error] [pid 782784:tid 782946] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1254xx.php"] [unique_id "amuNWYaApLsOvtuGcVqjVAAAACA"]
[Thu Jul 30 12:43:53.459236 2026] [security2:error] [pid 782784:tid 782946] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1254xx.php"] [unique_id "amuNWYaApLsOvtuGcVqjVAAAACA"]
[Thu Jul 30 12:43:53.500042 2026] [security2:error] [pid 782784:tid 783023] [client 66.249.73.65:38118] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/robots.txt"] [unique_id "amuNWYaApLsOvtuGcVqjVQAAAG0"]
[Thu Jul 30 12:43:53.503406 2026] [security2:error] [pid 782784:tid 782940] [client 66.249.73.66:35309] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/author/tfhk1688gmail-com/"] [unique_id "amuNWYaApLsOvtuGcVqjVgAAABo"]
[Thu Jul 30 12:43:53.685609 2026] [core:notice] [pid 782784:tid 782971] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:53.689899 2026] [security2:error] [pid 782784:tid 782971] [client 103.215.74.26:4018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNWYaApLsOvtuGcVqjWAAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:53.764477 2026] [security2:error] [pid 782784:tid 783041] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuNWYaApLsOvtuGcVqjWQAAAH8"]
[Thu Jul 30 12:43:53.764590 2026] [security2:error] [pid 782784:tid 783041] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuNWYaApLsOvtuGcVqjWQAAAH8"]
[Thu Jul 30 12:43:53.854736 2026] [security2:error] [pid 782784:tid 782918] [client 20.91.199.21:53032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/404.php"] [unique_id "amuNWYaApLsOvtuGcVqjXQAAAAQ"]
[Thu Jul 30 12:43:54.064040 2026] [security2:error] [pid 782784:tid 782923] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/pms297.php"] [unique_id "amuNWoaApLsOvtuGcVqjZQAAAAk"]
[Thu Jul 30 12:43:54.064145 2026] [security2:error] [pid 782784:tid 782923] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/pms297.php"] [unique_id "amuNWoaApLsOvtuGcVqjZQAAAAk"]
[Thu Jul 30 12:43:54.214146 2026] [security2:error] [pid 782784:tid 782957] [client 20.63.98.115:57216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/defaults.php"] [unique_id "amuNWoaApLsOvtuGcVqjaQAAACs"]
[Thu Jul 30 12:43:54.380297 2026] [security2:error] [pid 782784:tid 782925] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuNWoaApLsOvtuGcVqjbgAAAAs"]
[Thu Jul 30 12:43:54.380453 2026] [security2:error] [pid 782784:tid 782925] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuNWoaApLsOvtuGcVqjbgAAAAs"]
[Thu Jul 30 12:43:54.686171 2026] [security2:error] [pid 782784:tid 783028] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuNWoaApLsOvtuGcVqjdwAAAHI"]
[Thu Jul 30 12:43:54.686322 2026] [security2:error] [pid 782784:tid 783028] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuNWoaApLsOvtuGcVqjdwAAAHI"]
[Thu Jul 30 12:43:54.697345 2026] [security2:error] [pid 782784:tid 783037] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNWoaApLsOvtuGcVqjaAAAAHs"]
[Thu Jul 30 12:43:54.999246 2026] [security2:error] [pid 782784:tid 783009] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuNWoaApLsOvtuGcVqjgAAAAF8"]
[Thu Jul 30 12:43:54.999399 2026] [security2:error] [pid 782784:tid 783009] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuNWoaApLsOvtuGcVqjgAAAAF8"]
[Thu Jul 30 12:43:55.103494 2026] [security2:error] [pid 782784:tid 782965] [client 20.91.199.21:49895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/aa.php"] [unique_id "amuNW4aApLsOvtuGcVqjgwAAADM"]
[Thu Jul 30 12:43:55.321276 2026] [security2:error] [pid 782784:tid 782914] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuNW4aApLsOvtuGcVqjhAAAAAA"]
[Thu Jul 30 12:43:55.321437 2026] [security2:error] [pid 782784:tid 782914] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuNW4aApLsOvtuGcVqjhAAAAAA"]
[Thu Jul 30 12:43:55.638132 2026] [security2:error] [pid 782784:tid 782919] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dyui.php"] [unique_id "amuNW4aApLsOvtuGcVqjkQAAAAU"]
[Thu Jul 30 12:43:55.638241 2026] [security2:error] [pid 782784:tid 782919] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dyui.php"] [unique_id "amuNW4aApLsOvtuGcVqjkQAAAAU"]
[Thu Jul 30 12:43:55.949769 2026] [security2:error] [pid 782784:tid 783026] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ho.php"] [unique_id "amuNW4aApLsOvtuGcVqjlQAAAHA"]
[Thu Jul 30 12:43:55.949915 2026] [security2:error] [pid 782784:tid 783026] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ho.php"] [unique_id "amuNW4aApLsOvtuGcVqjlQAAAHA"]
[Thu Jul 30 12:43:55.958246 2026] [security2:error] [pid 782784:tid 782932] [client 52.238.199.152:42869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/app.php"] [unique_id "amuNW4aApLsOvtuGcVqjlgAAABI"]
[Thu Jul 30 12:43:56.085096 2026] [security2:error] [pid 782784:tid 783001] [client 20.63.98.115:21382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuNXIaApLsOvtuGcVqjnQAAAFc"]
[Thu Jul 30 12:43:56.291431 2026] [security2:error] [pid 782784:tid 782947] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/66b867516c8f01.php"] [unique_id "amuNXIaApLsOvtuGcVqjngAAACE"]
[Thu Jul 30 12:43:56.291584 2026] [security2:error] [pid 782784:tid 782947] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/66b867516c8f01.php"] [unique_id "amuNXIaApLsOvtuGcVqjngAAACE"]
[Thu Jul 30 12:43:56.388615 2026] [security2:error] [pid 782784:tid 782926] [client 38.190.144.4:55666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNXIaApLsOvtuGcVqjnwAAAAw"]
[Thu Jul 30 12:43:56.389382 2026] [security2:error] [pid 782784:tid 782926] [client 38.190.144.4:55666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNXIaApLsOvtuGcVqjnwAAAAw"]
[Thu Jul 30 12:43:56.440879 2026] [core:notice] [pid 782784:tid 782961] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:56.622264 2026] [security2:error] [pid 782784:tid 783018] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ext.php"] [unique_id "amuNXIaApLsOvtuGcVqjqgAAAGg"]
[Thu Jul 30 12:43:56.622388 2026] [security2:error] [pid 782784:tid 783018] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ext.php"] [unique_id "amuNXIaApLsOvtuGcVqjqgAAAGg"]
[Thu Jul 30 12:43:56.826436 2026] [core:notice] [pid 782784:tid 782934] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:56.851608 2026] [core:error] [pid 782784:tid 782915] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:56.851628 2026] [core:error] [pid 782784:tid 782915] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:56.865161 2026] [core:error] [pid 782784:tid 782941] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:56.865182 2026] [core:error] [pid 782784:tid 782941] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:56.885134 2026] [core:error] [pid 782784:tid 782982] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:56.885152 2026] [core:error] [pid 782784:tid 782982] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:56.898356 2026] [core:error] [pid 782784:tid 782993] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:56.898373 2026] [core:error] [pid 782784:tid 782993] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:56.916128 2026] [security2:error] [pid 782784:tid 782953] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuNXIaApLsOvtuGcVqjwQAAACc"]
[Thu Jul 30 12:43:56.916213 2026] [security2:error] [pid 782784:tid 782953] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuNXIaApLsOvtuGcVqjwQAAACc"]
[Thu Jul 30 12:43:56.939705 2026] [core:error] [pid 782784:tid 782984] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:56.939725 2026] [core:error] [pid 782784:tid 782984] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:43:57.026968 2026] [security2:error] [pid 782784:tid 782876] [remote 57.141.0.52:26424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amuNXYaApLsOvtuGcVqjywAAfFs"]
[Thu Jul 30 12:43:57.222811 2026] [security2:error] [pid 782784:tid 782964] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/diidi.php"] [unique_id "amuNXYaApLsOvtuGcVqj0AAAADI"]
[Thu Jul 30 12:43:57.222919 2026] [security2:error] [pid 782784:tid 782964] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/diidi.php"] [unique_id "amuNXYaApLsOvtuGcVqj0AAAADI"]
[Thu Jul 30 12:43:57.526652 2026] [security2:error] [pid 782784:tid 782948] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/clarebypas.php"] [unique_id "amuNXYaApLsOvtuGcVqj1gAAACI"]
[Thu Jul 30 12:43:57.526775 2026] [security2:error] [pid 782784:tid 782948] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/clarebypas.php"] [unique_id "amuNXYaApLsOvtuGcVqj1gAAACI"]
[Thu Jul 30 12:43:57.641650 2026] [security2:error] [pid 782784:tid 782986] [client 20.91.199.21:36662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/aafewc0k.php"] [unique_id "amuNXYaApLsOvtuGcVqj3wAAAEg"]
[Thu Jul 30 12:43:57.852193 2026] [security2:error] [pid 782784:tid 782945] [client 51.120.79.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.79.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/x402.php"] [unique_id "amuNXYaApLsOvtuGcVqj4gAAAB8"]
[Thu Jul 30 12:43:57.852314 2026] [security2:error] [pid 782784:tid 782945] [client 51.120.79.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/x402.php"] [unique_id "amuNXYaApLsOvtuGcVqj4gAAAB8"]
[Thu Jul 30 12:43:57.858324 2026] [security2:error] [pid 782784:tid 783032] [client 52.238.199.152:42877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/k.php"] [unique_id "amuNXYaApLsOvtuGcVqj4wAAAHY"]
[Thu Jul 30 12:43:58.168441 2026] [security2:error] [pid 782784:tid 783023] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNXYaApLsOvtuGcVqj1wAAbVg"]
[Thu Jul 30 12:43:58.226219 2026] [security2:error] [pid 782784:tid 783010] [client 20.63.98.115:21406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "amuNXoaApLsOvtuGcVqj7QAAAGA"]
[Thu Jul 30 12:43:58.410756 2026] [security2:error] [pid 782784:tid 782996] [client 150.107.232.194:27509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNXoaApLsOvtuGcVqj9AAAAFI"]
[Thu Jul 30 12:43:58.410887 2026] [security2:error] [pid 782784:tid 782996] [client 150.107.232.194:27509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNXoaApLsOvtuGcVqj9AAAAFI"]
[Thu Jul 30 12:43:59.417342 2026] [core:notice] [pid 782784:tid 782974] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:43:59.421663 2026] [security2:error] [pid 782784:tid 782974] [client 103.215.74.26:4030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNX4aApLsOvtuGcVqkDQAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:43:59.457713 2026] [security2:error] [pid 782784:tid 782860] [remote 77.88.47.9:65322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.47.88.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/12/15/shopping-selection-de-20-sacs-pour-lhiver-2011/"] [unique_id "amuNX4aApLsOvtuGcVqkCQAALEs"]
[Thu Jul 30 12:43:59.806924 2026] [security2:error] [pid 782784:tid 782990] [client 52.238.199.152:22625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-fmfile.php"] [unique_id "amuNX4aApLsOvtuGcVqkGAAAAEw"]
[Thu Jul 30 12:44:00.036899 2026] [security2:error] [pid 782784:tid 782891] [remote 57.141.0.18:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuNYIaApLsOvtuGcVqkGgAADWo"]
[Thu Jul 30 12:44:00.048967 2026] [security2:error] [pid 782784:tid 782960] [client 20.63.98.115:21412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/plugins.php"] [unique_id "amuNYIaApLsOvtuGcVqkGwAAAC4"]
[Thu Jul 30 12:44:00.190358 2026] [core:notice] [pid 782784:tid 782976] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:00.194985 2026] [security2:error] [pid 782784:tid 782976] [client 103.215.74.26:4032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNYIaApLsOvtuGcVqkHwAAAD4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:00.307431 2026] [security2:error] [pid 782784:tid 783015] [client 216.73.216.90:40081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuNX4aApLsOvtuGcVqkDgAAZWY"]
[Thu Jul 30 12:44:00.329713 2026] [security2:error] [pid 782784:tid 783026] [client 20.91.199.21:14260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/abcd.php"] [unique_id "amuNYIaApLsOvtuGcVqkJgAAAHA"]
[Thu Jul 30 12:44:00.923117 2026] [core:notice] [pid 782784:tid 782949] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:00.927767 2026] [security2:error] [pid 782784:tid 782949] [client 103.215.74.26:4034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNYIaApLsOvtuGcVqkMQAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:01.446018 2026] [security2:error] [pid 782784:tid 782965] [client 20.91.199.21:14236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/about.php"] [unique_id "amuNYYaApLsOvtuGcVqkPwAAADM"]
[Thu Jul 30 12:44:01.649102 2026] [core:notice] [pid 782784:tid 783040] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:01.653134 2026] [security2:error] [pid 782784:tid 783040] [client 103.215.74.26:4044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNYYaApLsOvtuGcVqkQAAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:01.734934 2026] [security2:error] [pid 782784:tid 782994] [client 20.63.98.115:20869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/upgrade/wp-login.php"] [unique_id "amuNYYaApLsOvtuGcVqkRAAAAFA"]
[Thu Jul 30 12:44:02.387706 2026] [core:notice] [pid 782784:tid 783029] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:02.391779 2026] [security2:error] [pid 782784:tid 783029] [client 103.215.74.26:4056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNYoaApLsOvtuGcVqkWAAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:02.396761 2026] [security2:error] [pid 782784:tid 782914] [client 52.238.199.152:62795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wi.php"] [unique_id "amuNYoaApLsOvtuGcVqkWQAAAAA"]
[Thu Jul 30 12:44:03.114142 2026] [core:notice] [pid 782784:tid 782929] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:03.118110 2026] [security2:error] [pid 782784:tid 782929] [client 103.215.74.26:50668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNY4aApLsOvtuGcVqkaQAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:03.224495 2026] [security2:error] [pid 782784:tid 783022] [client 20.63.98.115:57277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/certificates/wp-login.php"] [unique_id "amuNY4aApLsOvtuGcVqkagAAAGw"]
[Thu Jul 30 12:44:03.274843 2026] [core:error] [pid 782784:tid 782904] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:03.274866 2026] [core:error] [pid 782784:tid 782904] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:03.351425 2026] [security2:error] [pid 782784:tid 783009] [client 74.7.241.134:32768] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.hwjtrading.co.uk"] [uri "/cgi-sys/404.html"] [unique_id "amuNY4aApLsOvtuGcVqkbwAAX2w"]
[Thu Jul 30 12:44:03.446195 2026] [core:error] [pid 782784:tid 782826] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:03.446224 2026] [core:error] [pid 782784:tid 782826] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:03.480423 2026] [core:error] [pid 782784:tid 782791] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:03.480445 2026] [core:error] [pid 782784:tid 782791] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:03.698272 2026] [security2:error] [pid 782784:tid 782970] [client 20.91.199.21:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/admin.php"] [unique_id "amuNY4aApLsOvtuGcVqkeAAAADg"]
[Thu Jul 30 12:44:03.845234 2026] [core:notice] [pid 782784:tid 783039] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:03.849594 2026] [security2:error] [pid 782784:tid 783039] [client 103.215.74.26:50676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNY4aApLsOvtuGcVqkfQAAAH0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:03.989914 2026] [security2:error] [pid 782784:tid 783005] [client 20.63.98.115:58067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/network.php"] [unique_id "amuNY4aApLsOvtuGcVqkhAAAAFs"]
[Thu Jul 30 12:44:04.222007 2026] [security2:error] [pid 782784:tid 782930] [client 52.238.199.152:22653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/php8.php"] [unique_id "amuNZIaApLsOvtuGcVqkhwAAABA"]
[Thu Jul 30 12:44:04.235369 2026] [autoindex:error] [pid 782784:tid 782808] [remote 74.7.242.13:58948] AH01276: Cannot serve directory /home2/jjpgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:44:04.592054 2026] [core:notice] [pid 782784:tid 782931] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:04.598828 2026] [security2:error] [pid 782784:tid 782931] [client 103.215.74.26:50678] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNZIaApLsOvtuGcVqkkgAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:05.191633 2026] [security2:error] [pid 782784:tid 782942] [client 85.208.96.198:33130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuNZYaApLsOvtuGcVqknAAAABw"]
[Thu Jul 30 12:44:05.191783 2026] [security2:error] [pid 782784:tid 782942] [client 85.208.96.198:33130] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuNZYaApLsOvtuGcVqknAAAABw"]
[Thu Jul 30 12:44:05.244351 2026] [security2:error] [pid 782784:tid 782920] [client 20.91.199.21:14271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/adminfuns.php"] [unique_id "amuNZYaApLsOvtuGcVqknQAAAAY"]
[Thu Jul 30 12:44:05.319147 2026] [core:notice] [pid 782784:tid 783018] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:05.330534 2026] [security2:error] [pid 782784:tid 783018] [client 103.215.74.26:50688] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNZYaApLsOvtuGcVqkoAAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:05.688480 2026] [security2:error] [pid 782784:tid 782803] [remote 216.73.216.152:58847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuNZYaApLsOvtuGcVqkqwAALRI"]
[Thu Jul 30 12:44:05.702380 2026] [security2:error] [pid 782784:tid 783035] [client 185.191.171.10:19570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/24/acidentes-de-transito-matam-mais-de-duas-pessoas-por-dia-na-paraiba/"] [unique_id "amuNZYaApLsOvtuGcVqkrAAAAHk"]
[Thu Jul 30 12:44:05.702468 2026] [security2:error] [pid 782784:tid 783035] [client 185.191.171.10:19570] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/24/acidentes-de-transito-matam-mais-de-duas-pessoas-por-dia-na-paraiba/"] [unique_id "amuNZYaApLsOvtuGcVqkrAAAAHk"]
[Thu Jul 30 12:44:05.981218 2026] [security2:error] [pid 782784:tid 782950] [client 20.91.199.21:49916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/albin.php"] [unique_id "amuNZYaApLsOvtuGcVqksgAAACQ"]
[Thu Jul 30 12:44:06.119299 2026] [core:notice] [pid 782784:tid 783009] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:06.123470 2026] [security2:error] [pid 782784:tid 783009] [client 103.215.74.26:50690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNZoaApLsOvtuGcVqktwAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:06.844230 2026] [core:notice] [pid 782784:tid 782991] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:06.848326 2026] [security2:error] [pid 782784:tid 782991] [client 103.215.74.26:50694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNZoaApLsOvtuGcVqkwQAAAE0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:06.903751 2026] [security2:error] [pid 782784:tid 783012] [client 20.91.199.21:36626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/amfsqvgv.php"] [unique_id "amuNZoaApLsOvtuGcVqkwgAAAGI"]
[Thu Jul 30 12:44:07.105964 2026] [security2:error] [pid 782784:tid 782967] [client 20.63.98.115:21438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-cron.php"] [unique_id "amuNZ4aApLsOvtuGcVqkygAAADU"]
[Thu Jul 30 12:44:07.573585 2026] [core:notice] [pid 782784:tid 782940] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:07.580233 2026] [security2:error] [pid 782784:tid 782940] [client 103.215.74.26:50706] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNZ4aApLsOvtuGcVqk1gAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:08.311025 2026] [core:notice] [pid 782784:tid 783018] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:08.315002 2026] [security2:error] [pid 782784:tid 783018] [client 103.215.74.26:50722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNaIaApLsOvtuGcVqk5QAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:08.884623 2026] [security2:error] [pid 782784:tid 782987] [client 150.107.232.194:27035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNaIaApLsOvtuGcVqk9AAAAEk"]
[Thu Jul 30 12:44:08.884722 2026] [security2:error] [pid 782784:tid 782987] [client 150.107.232.194:27035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNaIaApLsOvtuGcVqk9AAAAEk"]
[Thu Jul 30 12:44:09.041743 2026] [core:notice] [pid 782784:tid 782949] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:09.046676 2026] [security2:error] [pid 782784:tid 782949] [client 103.215.74.26:50734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNaYaApLsOvtuGcVqk9QAAACM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:09.178465 2026] [core:error] [pid 782784:tid 782938] [client 165.154.11.210:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:09.178487 2026] [core:error] [pid 782784:tid 782938] [client 165.154.11.210:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:09.186031 2026] [security2:error] [pid 782784:tid 782991] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samirkhalifa.net"] [uri "/wp-admin/install.php"] [unique_id "amuNaYaApLsOvtuGcVqlAgAAAE0"]
[Thu Jul 30 12:44:09.788584 2026] [core:notice] [pid 782784:tid 783001] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:09.792475 2026] [security2:error] [pid 782784:tid 783001] [client 103.215.74.26:50740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNaYaApLsOvtuGcVqlFgAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:09.875105 2026] [security2:error] [pid 782784:tid 782917] [client 20.91.199.21:36670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/ant.php"] [unique_id "amuNaYaApLsOvtuGcVqlFwAAAAM"]
[Thu Jul 30 12:44:09.894803 2026] [security2:error] [pid 782784:tid 783020] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNaYaApLsOvtuGcVqlCQAAAGo"]
[Thu Jul 30 12:44:10.525437 2026] [security2:error] [pid 782784:tid 782958] [client 38.190.144.4:56183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNaoaApLsOvtuGcVqlJAAAACw"]
[Thu Jul 30 12:44:10.526881 2026] [core:notice] [pid 782784:tid 783037] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:10.527099 2026] [security2:error] [pid 782784:tid 782958] [client 38.190.144.4:56183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNaoaApLsOvtuGcVqlJAAAACw"]
[Thu Jul 30 12:44:10.533699 2026] [security2:error] [pid 782784:tid 783037] [client 103.215.74.26:50750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNaoaApLsOvtuGcVqlIwAAAHs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:11.329562 2026] [core:notice] [pid 782784:tid 782975] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:11.333895 2026] [security2:error] [pid 782784:tid 782975] [client 103.215.74.26:50758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNa4aApLsOvtuGcVqlPgAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:11.373889 2026] [security2:error] [pid 782784:tid 783009] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNaoaApLsOvtuGcVqlMgAAAF8"]
[Thu Jul 30 12:44:11.483706 2026] [security2:error] [pid 782784:tid 782986] [client 20.91.199.21:36660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/appreciators.php"] [unique_id "amuNa4aApLsOvtuGcVqlQgAAAEg"]
[Thu Jul 30 12:44:12.072484 2026] [core:notice] [pid 782784:tid 782974] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:12.076614 2026] [security2:error] [pid 782784:tid 782974] [client 103.215.74.26:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNbIaApLsOvtuGcVqlTgAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:12.641194 2026] [core:notice] [pid 782784:tid 782882] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:12.645188 2026] [security2:error] [pid 782784:tid 782940] [client 170.83.179.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/24/index.php/JIPKL/guide"] [unique_id "amuNbIaApLsOvtuGcVqlWAAAGmE"]
[Thu Jul 30 12:44:12.783180 2026] [security2:error] [pid 782784:tid 782942] [client 20.91.199.21:52763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/archive.php"] [unique_id "amuNbIaApLsOvtuGcVqlXgAAABw"]
[Thu Jul 30 12:44:12.841178 2026] [core:notice] [pid 782784:tid 782961] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:12.845007 2026] [security2:error] [pid 782784:tid 782961] [client 103.215.74.26:50778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNbIaApLsOvtuGcVqlYQAAAC8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:13.587920 2026] [core:notice] [pid 782784:tid 782996] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:13.592379 2026] [security2:error] [pid 782784:tid 782996] [client 103.215.74.26:1056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNbYaApLsOvtuGcVqldQAAAFI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:14.099338 2026] [security2:error] [pid 782784:tid 782990] [client 52.238.199.152:53708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/tes.php"] [unique_id "amuNboaApLsOvtuGcVqlgAAAAEw"]
[Thu Jul 30 12:44:14.140063 2026] [security2:error] [pid 782784:tid 782979] [client 119.73.97.132:31205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/wp-admin/post.php"] [unique_id "amuNbYaApLsOvtuGcVqlfwAAQVQ"], referer: https://www.urwru.club/wp-admin/post.php?post=1023&action=edit
[Thu Jul 30 12:44:14.317776 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:14.325075 2026] [security2:error] [pid 782784:tid 783025] [client 103.215.74.26:1062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNboaApLsOvtuGcVqliwAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:14.893553 2026] [security2:error] [pid 782784:tid 782968] [client 20.91.199.21:54465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/as.php"] [unique_id "amuNboaApLsOvtuGcVqllwAAADY"]
[Thu Jul 30 12:44:15.097438 2026] [core:notice] [pid 782784:tid 782960] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:15.101861 2026] [security2:error] [pid 782784:tid 782960] [client 103.215.74.26:1068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNb4aApLsOvtuGcVqlmwAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:15.224498 2026] [core:notice] [pid 782784:tid 782887] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:15.304709 2026] [security2:error] [pid 782784:tid 782894] [remote 143.198.3.251:56618] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuNb4aApLsOvtuGcVqlngAARG0"], referer: https://insurancecouncilinc.com/
[Thu Jul 30 12:44:15.529477 2026] [security2:error] [pid 782784:tid 782900] [remote 47.128.111.158:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "flixon.net"] [uri "/robots.txt"] [unique_id "amuNb4aApLsOvtuGcVqlqAAAC3M"]
[Thu Jul 30 12:44:15.763402 2026] [security2:error] [pid 782784:tid 783023] [client 20.91.199.21:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/atomlib.php"] [unique_id "amuNb4aApLsOvtuGcVqlrAAAAG0"]
[Thu Jul 30 12:44:15.841203 2026] [core:notice] [pid 782784:tid 783030] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:15.845759 2026] [security2:error] [pid 782784:tid 783030] [client 103.215.74.26:1074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNb4aApLsOvtuGcVqlrQAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:15.900306 2026] [security2:error] [pid 782784:tid 782958] [client 52.238.199.152:53710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/about.php"] [unique_id "amuNb4aApLsOvtuGcVqlsAAAACw"]
[Thu Jul 30 12:44:16.903834 2026] [security2:error] [pid 782784:tid 782974] [client 40.77.167.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuNcIaApLsOvtuGcVqlxgAAADw"]
[Thu Jul 30 12:44:17.097033 2026] [security2:error] [pid 782784:tid 782936] [client 52.238.199.152:62756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/headers.php"] [unique_id "amuNcYaApLsOvtuGcVqlzgAAABY"]
[Thu Jul 30 12:44:17.385178 2026] [security2:error] [pid 782784:tid 783026] [client 40.77.167.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuNcYaApLsOvtuGcVql1AAAAHA"]
[Thu Jul 30 12:44:17.561784 2026] [security2:error] [pid 782784:tid 782921] [client 20.91.199.21:51791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/autoload_classmap.php"] [unique_id "amuNcYaApLsOvtuGcVql2wAAAAc"]
[Thu Jul 30 12:44:17.756115 2026] [security2:error] [pid 782784:tid 782787] [remote 57.141.0.55:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/56555984686/feed/rss2/"] [unique_id "amuNcYaApLsOvtuGcVql4QAARAI"]
[Thu Jul 30 12:44:17.757817 2026] [core:error] [pid 782784:tid 782950] [client 165.154.11.210:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:17.757842 2026] [core:error] [pid 782784:tid 782950] [client 165.154.11.210:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:17.907414 2026] [security2:error] [pid 782784:tid 782966] [client 20.63.98.115:57218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/acp.php"] [unique_id "amuNcYaApLsOvtuGcVql4wAAADQ"]
[Thu Jul 30 12:44:18.413660 2026] [security2:error] [pid 782784:tid 782958] [client 20.91.199.21:52753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/bb.php"] [unique_id "amuNcoaApLsOvtuGcVql7QAAACw"]
[Thu Jul 30 12:44:18.690583 2026] [security2:error] [pid 782784:tid 782977] [client 20.63.98.115:62052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/assets/bypass.php"] [unique_id "amuNcoaApLsOvtuGcVql9gAAAD8"]
[Thu Jul 30 12:44:19.327911 2026] [security2:error] [pid 782784:tid 783008] [client 46.153.229.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuNcoaApLsOvtuGcVql-gAAAF4"], referer: https://tereashops.com/product/ploom-x-aura-mevius-aromarich-reg%E8%B6%85%E6%BF%83%E5%8E%9F%E5%91%B3%E7%85%99%E5%BD%88/
[Thu Jul 30 12:44:19.337231 2026] [security2:error] [pid 782784:tid 782919] [client 52.238.199.152:53701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/admin.php"] [unique_id "amuNc4aApLsOvtuGcVqmCQAAAAU"]
[Thu Jul 30 12:44:19.422792 2026] [security2:error] [pid 782784:tid 783011] [client 150.107.232.194:27463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNc4aApLsOvtuGcVqmCgAAAGE"]
[Thu Jul 30 12:44:19.422908 2026] [security2:error] [pid 782784:tid 783011] [client 150.107.232.194:27463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNc4aApLsOvtuGcVqmCgAAAGE"]
[Thu Jul 30 12:44:19.537938 2026] [security2:error] [pid 782784:tid 782931] [client 20.63.98.115:47170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/sx.php"] [unique_id "amuNc4aApLsOvtuGcVqmDgAAABE"]
[Thu Jul 30 12:44:19.572557 2026] [security2:error] [pid 782784:tid 782927] [client 20.91.199.21:53417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/bnm.php"] [unique_id "amuNc4aApLsOvtuGcVqmDwAAAA0"]
[Thu Jul 30 12:44:19.723141 2026] [security2:error] [pid 782784:tid 782940] [client 52.167.144.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuNc4aApLsOvtuGcVqmDQAAABo"]
[Thu Jul 30 12:44:19.847616 2026] [security2:error] [pid 782784:tid 782802] [remote 57.141.0.50:64430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuNc4aApLsOvtuGcVqmEAAAQBE"]
[Thu Jul 30 12:44:20.221074 2026] [security2:error] [pid 782784:tid 782926] [client 20.91.199.21:51999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/bootstrap.php"] [unique_id "amuNdIaApLsOvtuGcVqmKAAAAAw"]
[Thu Jul 30 12:44:20.687256 2026] [security2:error] [pid 782784:tid 782969] [client 172.237.109.114:54885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNdIaApLsOvtuGcVqmIQAAADc"]
[Thu Jul 30 12:44:20.688824 2026] [security2:error] [pid 782784:tid 782982] [client 172.237.109.114:6495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNdIaApLsOvtuGcVqmIAAAAEQ"]
[Thu Jul 30 12:44:20.689461 2026] [security2:error] [pid 782784:tid 782950] [client 172.237.109.114:32048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNdIaApLsOvtuGcVqmIgAAACQ"]
[Thu Jul 30 12:44:20.734606 2026] [security2:error] [pid 782784:tid 782995] [client 172.237.109.114:55198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNdIaApLsOvtuGcVqmJAAAAFE"]
[Thu Jul 30 12:44:20.740472 2026] [security2:error] [pid 782784:tid 783035] [client 172.237.109.114:19403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNdIaApLsOvtuGcVqmIwAAAHk"]
[Thu Jul 30 12:44:21.031675 2026] [security2:error] [pid 782784:tid 783003] [client 20.63.98.115:62071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/adminfuns.php"] [unique_id "amuNdYaApLsOvtuGcVqmPAAAAFk"]
[Thu Jul 30 12:44:21.358506 2026] [security2:error] [pid 782784:tid 783006] [client 38.190.144.4:56681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNdYaApLsOvtuGcVqmTAAAAFw"]
[Thu Jul 30 12:44:21.358620 2026] [security2:error] [pid 782784:tid 783006] [client 38.190.144.4:56681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNdYaApLsOvtuGcVqmTAAAAFw"]
[Thu Jul 30 12:44:21.361265 2026] [security2:error] [pid 782784:tid 783008] [client 40.77.167.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuNdYaApLsOvtuGcVqmPwAAAF4"]
[Thu Jul 30 12:44:21.534356 2026] [core:error] [pid 782784:tid 782940] [client 165.154.11.210:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:21.534381 2026] [core:error] [pid 782784:tid 782940] [client 165.154.11.210:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:21.562181 2026] [core:notice] [pid 782784:tid 783019] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:21.566462 2026] [security2:error] [pid 782784:tid 783019] [client 103.215.74.26:1080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNdYaApLsOvtuGcVqmUwAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:21.678464 2026] [security2:error] [pid 782784:tid 782945] [client 79.144.87.21:62589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.87.144.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/xmlrpc.php"] [unique_id "amuNdYaApLsOvtuGcVqmVAAAAB8"]
[Thu Jul 30 12:44:21.678584 2026] [security2:error] [pid 782784:tid 782945] [client 79.144.87.21:62589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "womenclothingbox.com"] [uri "/xmlrpc.php"] [unique_id "amuNdYaApLsOvtuGcVqmVAAAAB8"]
[Thu Jul 30 12:44:21.700485 2026] [security2:error] [pid 782784:tid 782986] [client 20.91.199.21:52029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/buy.php"] [unique_id "amuNdYaApLsOvtuGcVqmWwAAAEg"]
[Thu Jul 30 12:44:21.821323 2026] [security2:error] [pid 782784:tid 782965] [client 52.238.199.152:23379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/flower.php"] [unique_id "amuNdYaApLsOvtuGcVqmXwAAADM"]
[Thu Jul 30 12:44:22.085257 2026] [security2:error] [pid 782784:tid 782829] [remote 57.141.0.43:48072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/358522518/feed/rss2/"] [unique_id "amuNdoaApLsOvtuGcVqmZAAABiw"]
[Thu Jul 30 12:44:22.099837 2026] [security2:error] [pid 782784:tid 783017] [client 20.63.98.115:54765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/about.php"] [unique_id "amuNdoaApLsOvtuGcVqmZgAAAGc"]
[Thu Jul 30 12:44:22.280872 2026] [core:notice] [pid 782784:tid 783031] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:22.285343 2026] [security2:error] [pid 782784:tid 783031] [client 103.215.74.26:1096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNdoaApLsOvtuGcVqmagAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:23.007579 2026] [core:notice] [pid 782784:tid 782983] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:23.011970 2026] [security2:error] [pid 782784:tid 782983] [client 103.215.74.26:43626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNd4aApLsOvtuGcVqmfQAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:23.146174 2026] [core:error] [pid 782784:tid 783014] [client 20.63.98.115:62062] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:23.146199 2026] [core:error] [pid 782784:tid 783014] [client 20.63.98.115:62062] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:23.423547 2026] [security2:error] [pid 782784:tid 782930] [client 52.238.199.152:22880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuNd4aApLsOvtuGcVqmiwAAABA"]
[Thu Jul 30 12:44:23.707629 2026] [security2:error] [pid 782784:tid 782852] [remote 72.167.132.114:35032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuNd4aApLsOvtuGcVqmvAAAHUM"]
[Thu Jul 30 12:44:23.739586 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:23.739750 2026] [security2:error] [pid 782784:tid 782967] [client 198.98.54.3:52493] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuNd4aApLsOvtuGcVqm8gAAADU"]
[Thu Jul 30 12:44:23.743661 2026] [security2:error] [pid 782784:tid 782952] [client 103.215.74.26:43628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNd4aApLsOvtuGcVqm8QAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:23.932688 2026] [security2:error] [pid 782784:tid 782980] [client 198.98.54.3:52480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "797"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuNd4aApLsOvtuGcVqnKgAAAEI"]
[Thu Jul 30 12:44:24.232538 2026] [security2:error] [pid 782784:tid 783011] [client 198.98.54.3:52543] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "796"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuNeIaApLsOvtuGcVqnLgAAAGE"]
[Thu Jul 30 12:44:24.282548 2026] [security2:error] [pid 782784:tid 783032] [client 20.63.98.115:20900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/images/chosen.php"] [unique_id "amuNeIaApLsOvtuGcVqnLwAAAHY"]
[Thu Jul 30 12:44:24.294429 2026] [core:error] [pid 782784:tid 782860] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:24.294450 2026] [core:error] [pid 782784:tid 782860] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:24.313465 2026] [core:error] [pid 782784:tid 782879] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:24.313488 2026] [core:error] [pid 782784:tid 782879] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:24.441886 2026] [core:error] [pid 782784:tid 782862] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:24.441906 2026] [core:error] [pid 782784:tid 782862] [remote 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:24.511323 2026] [core:notice] [pid 782784:tid 783001] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:24.515723 2026] [security2:error] [pid 782784:tid 783001] [client 103.215.74.26:43632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNeIaApLsOvtuGcVqnQgAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:24.665421 2026] [security2:error] [pid 782784:tid 783026] [client 198.98.54.3:52572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "834"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuNeIaApLsOvtuGcVqnQwAAAHA"]
[Thu Jul 30 12:44:24.731347 2026] [security2:error] [pid 782784:tid 782975] [client 198.98.54.3:52624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "847"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuNeIaApLsOvtuGcVqnRAAAAD0"]
[Thu Jul 30 12:44:25.034946 2026] [security2:error] [pid 782784:tid 782925] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNeIaApLsOvtuGcVqnOQAACzA"]
[Thu Jul 30 12:44:25.249605 2026] [core:notice] [pid 782784:tid 782957] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:25.253662 2026] [security2:error] [pid 782784:tid 782957] [client 103.215.74.26:43636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNeYaApLsOvtuGcVqnTwAAACs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:25.350480 2026] [security2:error] [pid 782784:tid 782983] [client 20.63.98.115:62054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuNeYaApLsOvtuGcVqnUQAAAEU"]
[Thu Jul 30 12:44:25.351577 2026] [security2:error] [pid 782784:tid 782790] [remote 184.168.126.180:46718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/wp-login.php"] [unique_id "amuNeYaApLsOvtuGcVqnUgAAGAU"]
[Thu Jul 30 12:44:25.392019 2026] [security2:error] [pid 782784:tid 782992] [client 198.98.54.3:52689] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "783"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuNeYaApLsOvtuGcVqnVQAAAE4"]
[Thu Jul 30 12:44:25.972580 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:25.976521 2026] [security2:error] [pid 782784:tid 782952] [client 103.215.74.26:43638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNeYaApLsOvtuGcVqnZgAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:26.707718 2026] [core:notice] [pid 782784:tid 782920] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:26.711710 2026] [security2:error] [pid 782784:tid 782920] [client 103.215.74.26:43646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNeoaApLsOvtuGcVqneQAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:26.719407 2026] [security2:error] [pid 782784:tid 782965] [client 20.63.98.115:20920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/install.php"] [unique_id "amuNeoaApLsOvtuGcVqnegAAADM"]
[Thu Jul 30 12:44:26.914001 2026] [security2:error] [pid 782784:tid 783021] [client 52.238.199.152:22593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content.php"] [unique_id "amuNeoaApLsOvtuGcVqnfgAAAGs"]
[Thu Jul 30 12:44:27.180542 2026] [security2:error] [pid 782784:tid 782871] [remote 43.156.51.18:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lucky-strike-shop.com"] [uri "/product/mevius-10"] [unique_id "amuNe4aApLsOvtuGcVqniQAAP1Y"]
[Thu Jul 30 12:44:27.180724 2026] [security2:error] [pid 782784:tid 782977] [client 43.156.51.18:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lucky-strike-shop.com"] [uri "/product/mevius-10"] [unique_id "amuNe4aApLsOvtuGcVqniQAAP1Y"]
[Thu Jul 30 12:44:27.240707 2026] [security2:error] [pid 782784:tid 782915] [client 172.213.216.126:36915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "k2k.tech"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuNeoaApLsOvtuGcVqnggAAAAE"]
[Thu Jul 30 12:44:27.240832 2026] [security2:error] [pid 782784:tid 782915] [client 172.213.216.126:36915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "k2k.tech"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuNeoaApLsOvtuGcVqnggAAAAE"]
[Thu Jul 30 12:44:27.301420 2026] [core:notice] [pid 782784:tid 783023] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:27.399604 2026] [security2:error] [pid 782784:tid 782897] [remote 43.156.51.18:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lucky-strike-shop.com"] [uri "/favicon.ico"] [unique_id "amuNe4aApLsOvtuGcVqniwAAW3A"], referer: https://lucky-strike-shop.com/product/mevius-10
[Thu Jul 30 12:44:27.399771 2026] [security2:error] [pid 782784:tid 783005] [client 43.156.51.18:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lucky-strike-shop.com"] [uri "/favicon.ico"] [unique_id "amuNe4aApLsOvtuGcVqniwAAW3A"], referer: https://lucky-strike-shop.com/product/mevius-10
[Thu Jul 30 12:44:27.440347 2026] [core:notice] [pid 782784:tid 782964] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:27.444794 2026] [security2:error] [pid 782784:tid 782964] [client 103.215.74.26:43658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNe4aApLsOvtuGcVqnjQAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:27.484412 2026] [security2:error] [pid 782784:tid 782893] [remote 74.7.241.60:36590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amuNe4aApLsOvtuGcVqnjwAAU2w"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 12:44:27.945577 2026] [security2:error] [pid 782784:tid 783014] [client 20.63.98.115:61931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/cgi-bin/about.php"] [unique_id "amuNe4aApLsOvtuGcVqnngAAAGQ"]
[Thu Jul 30 12:44:28.159615 2026] [core:notice] [pid 782784:tid 783019] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:28.165796 2026] [security2:error] [pid 782784:tid 783019] [client 103.215.74.26:43672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNfIaApLsOvtuGcVqnrgAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:28.903795 2026] [core:notice] [pid 782784:tid 783036] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:28.910508 2026] [security2:error] [pid 782784:tid 783036] [client 103.215.74.26:43676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNfIaApLsOvtuGcVqnyQAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:29.131756 2026] [security2:error] [pid 782784:tid 782978] [client 20.63.98.115:20864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/colors/about.php"] [unique_id "amuNfYaApLsOvtuGcVqnywAAAEA"]
[Thu Jul 30 12:44:29.226142 2026] [security2:error] [pid 782784:tid 782994] [client 38.190.144.4:57235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNfYaApLsOvtuGcVqn0QAAAFA"]
[Thu Jul 30 12:44:29.227657 2026] [security2:error] [pid 782784:tid 782994] [client 38.190.144.4:57235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNfYaApLsOvtuGcVqn0QAAAFA"]
[Thu Jul 30 12:44:29.283584 2026] [core:notice] [pid 782784:tid 783041] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:29.420232 2026] [security2:error] [pid 782784:tid 782985] [client 52.238.199.152:62731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/function.php"] [unique_id "amuNfYaApLsOvtuGcVqn2wAAAEc"]
[Thu Jul 30 12:44:29.633565 2026] [core:notice] [pid 782784:tid 782915] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:29.637827 2026] [security2:error] [pid 782784:tid 782915] [client 103.215.74.26:43684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNfYaApLsOvtuGcVqn3AAAAAE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:29.890397 2026] [security2:error] [pid 782784:tid 782939] [client 150.107.232.194:27259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNfYaApLsOvtuGcVqn5gAAABk"]
[Thu Jul 30 12:44:29.890515 2026] [security2:error] [pid 782784:tid 782939] [client 150.107.232.194:27259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNfYaApLsOvtuGcVqn5gAAABk"]
[Thu Jul 30 12:44:30.316396 2026] [security2:error] [pid 782784:tid 783001] [client 74.7.244.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fdd.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuNfoaApLsOvtuGcVqn6QAAAFc"]
[Thu Jul 30 12:44:30.317164 2026] [security2:error] [pid 782784:tid 783018] [client 74.7.244.17:56972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fdd.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuNfoaApLsOvtuGcVqn5wAAaAQ"]
[Thu Jul 30 12:44:30.721592 2026] [core:error] [pid 782784:tid 782920] [client 74.7.244.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:30.721614 2026] [core:error] [pid 782784:tid 782920] [client 74.7.244.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:30.721766 2026] [security2:error] [pid 782784:tid 782920] [client 74.7.244.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.qlk.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuNfoaApLsOvtuGcVqoBAAAAAY"]
[Thu Jul 30 12:44:30.722369 2026] [security2:error] [pid 782784:tid 782924] [client 74.7.244.28:41190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.qlk.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuNfoaApLsOvtuGcVqoAQAACho"]
[Thu Jul 30 12:44:31.300812 2026] [security2:error] [pid 782784:tid 782937] [client 20.63.98.115:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/classwithtostring.php"] [unique_id "amuNf4aApLsOvtuGcVqoIAAAABc"]
[Thu Jul 30 12:44:31.911316 2026] [security2:error] [pid 782784:tid 783009] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNf4aApLsOvtuGcVqoJQAAAF8"]
[Thu Jul 30 12:44:32.129016 2026] [core:notice] [pid 782784:tid 782926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:32.309109 2026] [security2:error] [pid 782784:tid 782960] [client 139.28.219.70:48796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuNgIaApLsOvtuGcVqoSwAAAC4"]
[Thu Jul 30 12:44:32.393635 2026] [core:notice] [pid 782784:tid 782980] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:32.398731 2026] [core:notice] [pid 782784:tid 783024] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:32.407893 2026] [core:notice] [pid 782784:tid 783001] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:32.413938 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:32.466992 2026] [security2:error] [pid 782784:tid 782968] [client 20.63.98.115:43003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuNgIaApLsOvtuGcVqoXAAAADY"]
[Thu Jul 30 12:44:32.588677 2026] [security2:error] [pid 782784:tid 782930] [client 139.28.219.70:48808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/xmlrpc.php"] [unique_id "amuNgIaApLsOvtuGcVqoXwAAABA"]
[Thu Jul 30 12:44:33.154530 2026] [security2:error] [pid 782784:tid 782927] [client 216.73.216.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "palmtreepools.ca"] [uri "/index.php"] [unique_id "amuNf4aApLsOvtuGcVqoMAAAAA0"]
[Thu Jul 30 12:44:33.211801 2026] [core:notice] [pid 782784:tid 782857] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:33.217589 2026] [security2:error] [pid 782784:tid 783022] [client 104.200.74.243:35524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/category/pret-a-porter/page/2/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/09/polo-neck-shirt-massimo-dutti.jpg"] [unique_id "amuNgIaApLsOvtuGcVqobwAAbEg"], referer: https://carnetdeshopping.com/index.php/category/pret-a-porter/page/2/
[Thu Jul 30 12:44:33.240911 2026] [core:notice] [pid 782784:tid 782883] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:33.247068 2026] [security2:error] [pid 782784:tid 783035] [client 104.200.74.243:35508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/category/pret-a-porter/page/2/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/cape-\\xc3\\xa0-liser\\xc3\\xa9s-assortis-zar.jpg"] [unique_id "amuNgIaApLsOvtuGcVqocgAAeWI"], referer: https://carnetdeshopping.com/index.php/category/pret-a-porter/page/2/
[Thu Jul 30 12:44:33.455621 2026] [core:notice] [pid 782784:tid 782884] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:33.461788 2026] [core:notice] [pid 782784:tid 782881] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:33.482408 2026] [core:notice] [pid 782784:tid 782871] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:33.538309 2026] [security2:error] [pid 782784:tid 783008] [client 139.28.219.70:48824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuNgYaApLsOvtuGcVqogwAAAF4"]
[Thu Jul 30 12:44:33.576129 2026] [security2:error] [pid 782784:tid 782959] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNgIaApLsOvtuGcVqobQAALTQ"]
[Thu Jul 30 12:44:33.626598 2026] [security2:error] [pid 782784:tid 783040] [client 20.63.98.115:42946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/comfunctions.php"] [unique_id "amuNgYaApLsOvtuGcVqohQAAAH4"]
[Thu Jul 30 12:44:33.794993 2026] [core:notice] [pid 782784:tid 782893] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:33.805089 2026] [security2:error] [pid 782784:tid 782984] [client 139.28.219.70:48836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuNgYaApLsOvtuGcVqoigAAAEY"]
[Thu Jul 30 12:44:34.170099 2026] [security2:error] [pid 782784:tid 783016] [client 139.28.219.70:48840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuNgoaApLsOvtuGcVqolgAAAGY"]
[Thu Jul 30 12:44:34.320329 2026] [security2:error] [pid 782784:tid 782891] [remote 40.77.167.10:41491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/faq/youthf.php"] [unique_id "amuNgoaApLsOvtuGcVqolwAAQ2o"]
[Thu Jul 30 12:44:34.508858 2026] [security2:error] [pid 782784:tid 783013] [client 139.28.219.70:48848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuNgoaApLsOvtuGcVqongAAAGM"]
[Thu Jul 30 12:44:34.790832 2026] [security2:error] [pid 782784:tid 782956] [client 139.28.219.70:48858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuNgoaApLsOvtuGcVqoogAAACo"]
[Thu Jul 30 12:44:35.055467 2026] [security2:error] [pid 782784:tid 782954] [client 139.28.219.70:48874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuNg4aApLsOvtuGcVqoqQAAACg"]
[Thu Jul 30 12:44:35.329283 2026] [security2:error] [pid 782784:tid 783020] [client 139.28.219.70:48880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuNg4aApLsOvtuGcVqosAAAAGo"]
[Thu Jul 30 12:44:35.374504 2026] [core:notice] [pid 782784:tid 782963] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:35.379471 2026] [security2:error] [pid 782784:tid 782963] [client 103.215.74.26:35224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNg4aApLsOvtuGcVqotAAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:35.514016 2026] [security2:error] [pid 782784:tid 782922] [client 20.63.98.115:42994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/images/class-config.php"] [unique_id "amuNg4aApLsOvtuGcVqouAAAAAg"]
[Thu Jul 30 12:44:35.596061 2026] [security2:error] [pid 782784:tid 782950] [client 139.28.219.70:48890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuNg4aApLsOvtuGcVqovgAAACQ"]
[Thu Jul 30 12:44:35.854545 2026] [security2:error] [pid 782784:tid 782928] [client 139.28.219.70:48902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuNg4aApLsOvtuGcVqoxQAAAA4"]
[Thu Jul 30 12:44:36.012531 2026] [security2:error] [pid 782784:tid 783031] [client 52.238.199.152:22875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/chosen.php"] [unique_id "amuNhIaApLsOvtuGcVqoxgAAAHU"]
[Thu Jul 30 12:44:36.124627 2026] [security2:error] [pid 782784:tid 783032] [client 139.28.219.70:48914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuNhIaApLsOvtuGcVqozQAAAHY"]
[Thu Jul 30 12:44:36.437896 2026] [security2:error] [pid 782784:tid 782929] [client 139.28.219.70:48926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuNhIaApLsOvtuGcVqo1AAAAA8"]
[Thu Jul 30 12:44:36.722670 2026] [security2:error] [pid 782784:tid 782977] [client 139.28.219.70:48938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuNhIaApLsOvtuGcVqo3gAAAD8"]
[Thu Jul 30 12:44:36.775478 2026] [security2:error] [pid 782784:tid 782892] [remote 57.141.0.64:26410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuNhIaApLsOvtuGcVqo3wAAOms"]
[Thu Jul 30 12:44:36.913572 2026] [security2:error] [pid 782784:tid 782975] [client 52.238.199.152:22897] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "sv.radiojelli.com"] [uri "/1.php"] [unique_id "amuNhIaApLsOvtuGcVqo4QAAAD0"]
[Thu Jul 30 12:44:36.913738 2026] [security2:error] [pid 782784:tid 782975] [client 52.238.199.152:22897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/1.php"] [unique_id "amuNhIaApLsOvtuGcVqo4QAAAD0"]
[Thu Jul 30 12:44:37.030355 2026] [security2:error] [pid 782784:tid 783037] [client 139.28.219.70:48944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuNhYaApLsOvtuGcVqo4gAAAHs"]
[Thu Jul 30 12:44:37.316061 2026] [security2:error] [pid 782784:tid 782959] [client 139.28.219.70:48946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "shop-peace.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuNhYaApLsOvtuGcVqo7wAAAC0"]
[Thu Jul 30 12:44:37.465627 2026] [security2:error] [pid 782784:tid 782953] [client 139.28.219.70:60574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuNhYaApLsOvtuGcVqo8QAAACc"]
[Thu Jul 30 12:44:37.685591 2026] [security2:error] [pid 782784:tid 783005] [client 43.173.181.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuNhIaApLsOvtuGcVqo4AAAWxk"]
[Thu Jul 30 12:44:37.744507 2026] [security2:error] [pid 782784:tid 783031] [client 139.28.219.70:60584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/xmlrpc.php"] [unique_id "amuNhYaApLsOvtuGcVqo_QAAAHU"]
[Thu Jul 30 12:44:38.021162 2026] [security2:error] [pid 782784:tid 782932] [client 20.63.98.115:36842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/widgets/include.php"] [unique_id "amuNhoaApLsOvtuGcVqpBwAAABI"]
[Thu Jul 30 12:44:38.212240 2026] [security2:error] [pid 782784:tid 782945] [client 183.47.107.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNhoaApLsOvtuGcVqpDwAAAB8"]
[Thu Jul 30 12:44:38.405105 2026] [security2:error] [pid 782784:tid 782956] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNhoaApLsOvtuGcVqpFwAAACo"]
[Thu Jul 30 12:44:39.105476 2026] [security2:error] [pid 782784:tid 783020] [client 20.63.98.115:42968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/install.php"] [unique_id "amuNh4aApLsOvtuGcVqpNwAAAGo"]
[Thu Jul 30 12:44:39.137941 2026] [security2:error] [pid 782784:tid 782916] [client 52.238.199.152:23390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/lv.php"] [unique_id "amuNh4aApLsOvtuGcVqpOAAAAAI"]
[Thu Jul 30 12:44:40.005262 2026] [security2:error] [pid 782784:tid 783011] [client 20.63.98.115:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuNiIaApLsOvtuGcVqpVgAAAGE"]
[Thu Jul 30 12:44:40.119896 2026] [security2:error] [pid 782784:tid 782952] [client 38.190.144.4:57854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNiIaApLsOvtuGcVqpWwAAACY"]
[Thu Jul 30 12:44:40.120023 2026] [security2:error] [pid 782784:tid 782952] [client 38.190.144.4:57854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNiIaApLsOvtuGcVqpWwAAACY"]
[Thu Jul 30 12:44:40.141004 2026] [security2:error] [pid 782784:tid 783021] [client 52.238.199.152:23361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/css.php"] [unique_id "amuNiIaApLsOvtuGcVqpXAAAAGs"]
[Thu Jul 30 12:44:40.360914 2026] [security2:error] [pid 782784:tid 782983] [client 150.107.232.194:27375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNiIaApLsOvtuGcVqpZQAAAEU"]
[Thu Jul 30 12:44:40.361061 2026] [security2:error] [pid 782784:tid 782983] [client 150.107.232.194:27375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNiIaApLsOvtuGcVqpZQAAAEU"]
[Thu Jul 30 12:44:40.920812 2026] [security2:error] [pid 782784:tid 783010] [client 172.213.216.126:27976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "k2k.tech"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuNiIaApLsOvtuGcVqphQAAAGA"]
[Thu Jul 30 12:44:40.920893 2026] [security2:error] [pid 782784:tid 783010] [client 172.213.216.126:27976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "k2k.tech"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuNiIaApLsOvtuGcVqphQAAAGA"]
[Thu Jul 30 12:44:40.979527 2026] [security2:error] [pid 782784:tid 782990] [client 20.63.98.115:36802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/SimplePie/gzdecodes.php"] [unique_id "amuNiIaApLsOvtuGcVqpiAAAAEw"]
[Thu Jul 30 12:44:41.108393 2026] [core:notice] [pid 782784:tid 782950] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:41.115154 2026] [security2:error] [pid 782784:tid 782950] [client 103.215.74.26:35232] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNiYaApLsOvtuGcVqpjwAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:41.229850 2026] [core:notice] [pid 782784:tid 782879] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:41.235482 2026] [security2:error] [pid 782784:tid 782957] [client 23.230.235.177:58604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/category/pret-a-porter/page/2/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/09/cama\\xc3\\xaf_Big_sporty_chic.jpg"] [unique_id "amuNiIaApLsOvtuGcVqphwAAK14"], referer: https://carnetdeshopping.com/index.php/category/pret-a-porter/page/2/
[Thu Jul 30 12:44:41.309443 2026] [security2:error] [pid 782784:tid 782942] [client 139.28.219.70:60600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/xmlrpc.php"] [unique_id "amuNiYaApLsOvtuGcVqpmgAAABw"]
[Thu Jul 30 12:44:41.309751 2026] [security2:error] [pid 782784:tid 782942] [client 139.28.219.70:60600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "theregentsbarber.com.au"] [uri "/xmlrpc.php"] [unique_id "amuNiYaApLsOvtuGcVqpmgAAABw"]
[Thu Jul 30 12:44:41.696177 2026] [security2:error] [pid 782784:tid 782978] [client 20.63.98.115:36845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-back.php"] [unique_id "amuNiYaApLsOvtuGcVqppwAAAEA"]
[Thu Jul 30 12:44:41.702019 2026] [security2:error] [pid 782784:tid 783012] [client 172.237.109.114:64583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNiYaApLsOvtuGcVqpjQAAAGI"]
[Thu Jul 30 12:44:41.722370 2026] [security2:error] [pid 782784:tid 782923] [client 172.237.109.114:24956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNiYaApLsOvtuGcVqpjgAAAAk"]
[Thu Jul 30 12:44:41.745131 2026] [security2:error] [pid 782784:tid 782946] [client 172.237.109.114:49367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNiYaApLsOvtuGcVqpkAAAACA"]
[Thu Jul 30 12:44:41.767051 2026] [security2:error] [pid 782784:tid 783019] [client 172.237.109.114:44769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNiYaApLsOvtuGcVqpkwAAAGk"]
[Thu Jul 30 12:44:41.773762 2026] [security2:error] [pid 782784:tid 783031] [client 172.237.109.114:14465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNiYaApLsOvtuGcVqplAAAAHU"]
[Thu Jul 30 12:44:41.837545 2026] [core:notice] [pid 782784:tid 782962] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:41.841453 2026] [security2:error] [pid 782784:tid 782962] [client 103.215.74.26:35248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNiYaApLsOvtuGcVqprQAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:42.086363 2026] [core:notice] [pid 782784:tid 783041] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:42.143179 2026] [core:notice] [pid 782784:tid 782966] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:42.440183 2026] [security2:error] [pid 782784:tid 783039] [client 204.8.98.25:55826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuNioaApLsOvtuGcVqpxQAAAH0"]
[Thu Jul 30 12:44:42.440280 2026] [security2:error] [pid 782784:tid 783039] [client 204.8.98.25:55826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuNioaApLsOvtuGcVqpxQAAAH0"]
[Thu Jul 30 12:44:42.502253 2026] [core:notice] [pid 782784:tid 782995] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:42.568643 2026] [core:notice] [pid 782784:tid 783004] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:42.572642 2026] [security2:error] [pid 782784:tid 783004] [client 103.215.74.26:35262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNioaApLsOvtuGcVqpzQAAAFo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:42.594268 2026] [security2:error] [pid 782784:tid 783028] [client 172.237.109.114:13011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNioaApLsOvtuGcVqptgAAAHI"]
[Thu Jul 30 12:44:42.622345 2026] [security2:error] [pid 782784:tid 783017] [client 172.237.109.114:65393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNioaApLsOvtuGcVqpuQAAAGc"]
[Thu Jul 30 12:44:42.629007 2026] [security2:error] [pid 782784:tid 783003] [client 172.237.109.114:64312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuNioaApLsOvtuGcVqpuAAAAFk"]
[Thu Jul 30 12:44:42.973770 2026] [core:notice] [pid 782784:tid 782980] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:43.028001 2026] [core:notice] [pid 782784:tid 782928] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:43.265569 2026] [core:notice] [pid 782784:tid 782971] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:43.321142 2026] [core:notice] [pid 782784:tid 782989] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:43.336052 2026] [core:notice] [pid 782784:tid 782924] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:43.339846 2026] [security2:error] [pid 782784:tid 782924] [client 103.215.74.26:65278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNi4aApLsOvtuGcVqp8gAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:43.382868 2026] [security2:error] [pid 782784:tid 782945] [client 20.63.98.115:39086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "amuNi4aApLsOvtuGcVqp9wAAAB8"]
[Thu Jul 30 12:44:43.557077 2026] [core:notice] [pid 782784:tid 782930] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:43.614439 2026] [core:notice] [pid 782784:tid 782985] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:43.849375 2026] [core:notice] [pid 782784:tid 782947] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:43.910677 2026] [core:notice] [pid 782784:tid 782922] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:44.076503 2026] [core:notice] [pid 782784:tid 783023] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:44.080362 2026] [security2:error] [pid 782784:tid 783023] [client 103.215.74.26:65288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNjIaApLsOvtuGcVqqHQAAAG0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:44.141708 2026] [core:notice] [pid 782784:tid 782986] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:44.206824 2026] [core:notice] [pid 782784:tid 782960] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:44.336243 2026] [core:error] [pid 782784:tid 782910] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:44.336267 2026] [core:error] [pid 782784:tid 782910] [remote 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:44.366038 2026] [core:error] [pid 782784:tid 782888] [remote 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:44.366059 2026] [core:error] [pid 782784:tid 782888] [remote 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:44.386183 2026] [core:error] [pid 782784:tid 782840] [remote 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:44.386202 2026] [core:error] [pid 782784:tid 782840] [remote 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:44.433148 2026] [core:notice] [pid 782784:tid 782957] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:44.498002 2026] [security2:error] [pid 782784:tid 783017] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuNjIaApLsOvtuGcVqqHgAAZz0"]
[Thu Jul 30 12:44:44.511867 2026] [core:notice] [pid 782784:tid 782980] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:44.680717 2026] [security2:error] [pid 782784:tid 782984] [client 20.63.98.115:42978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/themes/index.php"] [unique_id "amuNjIaApLsOvtuGcVqqdgAAAEY"]
[Thu Jul 30 12:44:44.724757 2026] [core:notice] [pid 782784:tid 782945] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:44.804102 2026] [core:notice] [pid 782784:tid 782961] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:44.808282 2026] [core:notice] [pid 782784:tid 782979] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:44.808523 2026] [security2:error] [pid 782784:tid 782961] [client 103.215.74.26:65312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNjIaApLsOvtuGcVqqfQAAAC8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:44.940702 2026] [security2:error] [pid 782784:tid 782978] [client 172.213.216.126:27432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "k2k.tech"] [uri "/wp-login.php"] [unique_id "amuNjIaApLsOvtuGcVqqdQAAAEA"]
[Thu Jul 30 12:44:44.940811 2026] [security2:error] [pid 782784:tid 782978] [client 172.213.216.126:27432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "k2k.tech"] [uri "/wp-login.php"] [unique_id "amuNjIaApLsOvtuGcVqqdQAAAEA"]
[Thu Jul 30 12:44:45.018103 2026] [core:notice] [pid 782784:tid 783036] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:45.103744 2026] [core:notice] [pid 782784:tid 782997] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:45.313162 2026] [core:notice] [pid 782784:tid 782953] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:45.333274 2026] [security2:error] [pid 782784:tid 782954] [client 68.221.186.136:43150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/json.php"] [unique_id "amuNjYaApLsOvtuGcVqqjwAAACg"]
[Thu Jul 30 12:44:45.397544 2026] [core:notice] [pid 782784:tid 782931] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:45.474404 2026] [core:notice] [pid 782784:tid 783006] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:45.969317 2026] [core:notice] [pid 782784:tid 782957] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:46.244433 2026] [core:error] [pid 782784:tid 782903] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:46.244458 2026] [core:error] [pid 782784:tid 782903] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:46.274354 2026] [security2:error] [pid 782784:tid 783003] [client 68.221.186.136:44250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/mini.php"] [unique_id "amuNjoaApLsOvtuGcVqqsgAAAFk"]
[Thu Jul 30 12:44:46.300326 2026] [core:error] [pid 782784:tid 782889] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:46.300350 2026] [core:error] [pid 782784:tid 782889] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:46.483659 2026] [core:error] [pid 782784:tid 782895] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:46.483693 2026] [core:error] [pid 782784:tid 782895] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:47.392366 2026] [security2:error] [pid 782784:tid 782947] [client 52.238.199.152:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/gecko.php"] [unique_id "amuNj4aApLsOvtuGcVqq2QAAACE"]
[Thu Jul 30 12:44:47.655182 2026] [fcgid:warn] [pid 782784:tid 782992] (70014)End of file found: [client 165.154.162.193:38354] mod_fcgid: can't get data from http client
[Thu Jul 30 12:44:47.660845 2026] [security2:error] [pid 782784:tid 782954] [client 68.221.186.136:41368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/chosen.php"] [unique_id "amuNj4aApLsOvtuGcVqq5AAAACg"]
[Thu Jul 30 12:44:47.990099 2026] [security2:error] [pid 782784:tid 782995] [client 193.37.252.99:49486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuNj4aApLsOvtuGcVqq7wAAAFE"]
[Thu Jul 30 12:44:47.990247 2026] [security2:error] [pid 782784:tid 782995] [client 193.37.252.99:49486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuNj4aApLsOvtuGcVqq7wAAAFE"]
[Thu Jul 30 12:44:48.333973 2026] [core:notice] [pid 782784:tid 782926] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:48.383679 2026] [security2:error] [pid 782784:tid 782914] [client 52.238.199.152:62073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/xmlrpc.php"] [unique_id "amuNkIaApLsOvtuGcVqq-gAAAAA"]
[Thu Jul 30 12:44:48.655814 2026] [security2:error] [pid 782784:tid 782924] [client 68.221.186.136:41370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/kj.php"] [unique_id "amuNkIaApLsOvtuGcVqq_wAAAAo"]
[Thu Jul 30 12:44:48.903018 2026] [security2:error] [pid 782784:tid 782979] [client 172.213.216.126:9183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "k2k.tech"] [uri "/red.php"] [unique_id "amuNkIaApLsOvtuGcVqrBgAAAEE"]
[Thu Jul 30 12:44:48.903128 2026] [security2:error] [pid 782784:tid 782979] [client 172.213.216.126:9183] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "k2k.tech"] [uri "/red.php"] [unique_id "amuNkIaApLsOvtuGcVqrBgAAAEE"]
[Thu Jul 30 12:44:48.912914 2026] [core:notice] [pid 782784:tid 782803] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:49.375858 2026] [security2:error] [pid 782784:tid 782978] [client 52.238.199.152:62040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/f35.php"] [unique_id "amuNkYaApLsOvtuGcVqrFAAAAEA"]
[Thu Jul 30 12:44:49.893877 2026] [security2:error] [pid 782784:tid 782842] [remote 74.7.241.59:53174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuNkYaApLsOvtuGcVqrIQAARTk"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/insert-headers-and-footers/includes
[Thu Jul 30 12:44:49.901214 2026] [security2:error] [pid 782784:tid 782943] [client 68.221.186.136:41381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/wp-files.php"] [unique_id "amuNkYaApLsOvtuGcVqrIgAAAB0"]
[Thu Jul 30 12:44:49.959364 2026] [core:notice] [pid 782784:tid 782816] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:49.963399 2026] [security2:error] [pid 782784:tid 783004] [client 103.190.46.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/22"] [unique_id "amuNkYaApLsOvtuGcVqrHQAAWh8"]
[Thu Jul 30 12:44:50.120873 2026] [security2:error] [pid 782784:tid 782933] [client 74.7.175.175:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ciunews.com"] [uri "/index.php"] [unique_id "amuNkIaApLsOvtuGcVqrCQAAEyc"]
[Thu Jul 30 12:44:50.120903 2026] [security2:error] [pid 782784:tid 782933] [client 74.7.175.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ciunews.com"] [uri "/index.php"] [unique_id "amuNkIaApLsOvtuGcVqrCQAAEyc"]
[Thu Jul 30 12:44:50.173851 2026] [core:notice] [pid 782784:tid 782823] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:50.531316 2026] [core:notice] [pid 782784:tid 782928] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:50.535473 2026] [security2:error] [pid 782784:tid 782928] [client 103.215.74.26:65332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNkoaApLsOvtuGcVqrNQAAAA4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:50.569239 2026] [security2:error] [pid 782784:tid 782990] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNkYaApLsOvtuGcVqrJwAAAEw"]
[Thu Jul 30 12:44:50.709067 2026] [security2:error] [pid 782784:tid 782920] [client 52.238.199.152:22674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/autoload_classmap.php"] [unique_id "amuNkoaApLsOvtuGcVqrOAAAAAY"]
[Thu Jul 30 12:44:50.772790 2026] [security2:error] [pid 782784:tid 782914] [client 68.221.186.136:26375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/wp-setup.php"] [unique_id "amuNkoaApLsOvtuGcVqrPwAAAAA"]
[Thu Jul 30 12:44:50.821508 2026] [security2:error] [pid 782784:tid 783000] [client 150.107.232.194:27426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNkoaApLsOvtuGcVqrQwAAAFY"]
[Thu Jul 30 12:44:50.821644 2026] [security2:error] [pid 782784:tid 783000] [client 150.107.232.194:27426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNkoaApLsOvtuGcVqrQwAAAFY"]
[Thu Jul 30 12:44:50.918025 2026] [security2:error] [pid 782784:tid 782996] [client 172.213.216.126:27403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "k2k.tech"] [uri "/cc.php"] [unique_id "amuNkoaApLsOvtuGcVqrRQAAAFI"]
[Thu Jul 30 12:44:50.918134 2026] [security2:error] [pid 782784:tid 782996] [client 172.213.216.126:27403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "k2k.tech"] [uri "/cc.php"] [unique_id "amuNkoaApLsOvtuGcVqrRQAAAFI"]
[Thu Jul 30 12:44:51.146169 2026] [security2:error] [pid 782784:tid 782981] [client 74.7.175.175:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ciunews.com"] [uri "/index.php"] [unique_id "amuNkoaApLsOvtuGcVqrRgAAQyo"], referer: https://www.ciunews.com/robots.txt
[Thu Jul 30 12:44:51.161778 2026] [security2:error] [pid 782784:tid 782959] [client 20.63.98.115:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/user.php"] [unique_id "amuNk4aApLsOvtuGcVqrRwAAAC0"]
[Thu Jul 30 12:44:51.267312 2026] [core:notice] [pid 782784:tid 782962] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:51.271010 2026] [security2:error] [pid 782784:tid 782962] [client 103.215.74.26:65348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNk4aApLsOvtuGcVqrTwAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:51.903604 2026] [security2:error] [pid 782784:tid 782922] [client 38.190.144.4:58427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNk4aApLsOvtuGcVqrYgAAAAg"]
[Thu Jul 30 12:44:51.903737 2026] [security2:error] [pid 782784:tid 782922] [client 38.190.144.4:58427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNk4aApLsOvtuGcVqrYgAAAAg"]
[Thu Jul 30 12:44:51.996724 2026] [core:notice] [pid 782784:tid 783015] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:52.001016 2026] [security2:error] [pid 782784:tid 783015] [client 103.215.74.26:65358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNk4aApLsOvtuGcVqrZAAAAGU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:52.228042 2026] [security2:error] [pid 782784:tid 783034] [client 20.63.98.115:20699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "amuNlIaApLsOvtuGcVqraAAAAHg"]
[Thu Jul 30 12:44:52.738030 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:52.742431 2026] [security2:error] [pid 782784:tid 783025] [client 103.215.74.26:65362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNlIaApLsOvtuGcVqrcgAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:52.834734 2026] [security2:error] [pid 782784:tid 782989] [client 68.221.186.136:44268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/defaults.php"] [unique_id "amuNlIaApLsOvtuGcVqreQAAAEs"]
[Thu Jul 30 12:44:53.474632 2026] [core:notice] [pid 782784:tid 782918] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:53.479003 2026] [security2:error] [pid 782784:tid 782918] [client 103.215.74.26:54140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNlYaApLsOvtuGcVqriAAAAAQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:53.821418 2026] [core:notice] [pid 782784:tid 782843] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:54.205113 2026] [core:notice] [pid 782784:tid 783028] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:54.209742 2026] [security2:error] [pid 782784:tid 783028] [client 103.215.74.26:54148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNloaApLsOvtuGcVqrlQAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:54.245430 2026] [security2:error] [pid 782784:tid 782975] [client 20.63.98.115:44154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuNloaApLsOvtuGcVqrlgAAAD0"]
[Thu Jul 30 12:44:54.728955 2026] [security2:error] [pid 782784:tid 782968] [client 68.221.186.136:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/gtc.php"] [unique_id "amuNloaApLsOvtuGcVqrpAAAADY"]
[Thu Jul 30 12:44:54.816989 2026] [security2:error] [pid 782784:tid 783030] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuNloaApLsOvtuGcVqrowAAdFg"]
[Thu Jul 30 12:44:54.941992 2026] [core:notice] [pid 782784:tid 783010] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:54.946278 2026] [security2:error] [pid 782784:tid 783010] [client 103.215.74.26:54152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNloaApLsOvtuGcVqrrAAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:55.432622 2026] [security2:error] [pid 782784:tid 782996] [client 114.119.130.218:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.flixon.net"] [uri "/robots.txt"] [unique_id "amuNl4aApLsOvtuGcVqrtAAAAFI"], referer: http://www.flixon.net/robots.txt
[Thu Jul 30 12:44:55.526930 2026] [security2:error] [pid 782784:tid 782981] [client 66.249.68.163:62168] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.k2k.tech"] [uri "/robots.txt"] [unique_id "amuNl4aApLsOvtuGcVqruwAAAEM"]
[Thu Jul 30 12:44:55.668224 2026] [core:notice] [pid 782784:tid 782929] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:55.672675 2026] [security2:error] [pid 782784:tid 782929] [client 103.215.74.26:54158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNl4aApLsOvtuGcVqrvAAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:56.274330 2026] [security2:error] [pid 782784:tid 782950] [client 185.191.171.3:44194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/28/suspeito-de-trafico-e-preso-com-arma-drogas-e-material-explosivo-em-tacima/"] [unique_id "amuNmIaApLsOvtuGcVqrzgAAACQ"]
[Thu Jul 30 12:44:56.274469 2026] [security2:error] [pid 782784:tid 782950] [client 185.191.171.3:44194] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/28/suspeito-de-trafico-e-preso-com-arma-drogas-e-material-explosivo-em-tacima/"] [unique_id "amuNmIaApLsOvtuGcVqrzgAAACQ"]
[Thu Jul 30 12:44:56.390530 2026] [core:notice] [pid 782784:tid 782997] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:56.394938 2026] [security2:error] [pid 782784:tid 782997] [client 103.215.74.26:54172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNmIaApLsOvtuGcVqrzwAAAFM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:56.483170 2026] [security2:error] [pid 782784:tid 782985] [client 68.221.186.136:41372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/import.php"] [unique_id "amuNmIaApLsOvtuGcVqr0wAAAEc"]
[Thu Jul 30 12:44:56.821527 2026] [security2:error] [pid 782784:tid 782992] [client 20.203.148.31:32476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/LA.php"] [unique_id "amuNmIaApLsOvtuGcVqr3AAAAE4"]
[Thu Jul 30 12:44:57.129554 2026] [core:notice] [pid 782784:tid 782931] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:57.133843 2026] [security2:error] [pid 782784:tid 782931] [client 103.215.74.26:54176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNmYaApLsOvtuGcVqr5QAAABE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:57.155273 2026] [core:error] [pid 782784:tid 782928] [client 66.249.79.203:39411] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:57.155297 2026] [core:error] [pid 782784:tid 782928] [client 66.249.79.203:39411] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:57.456771 2026] [security2:error] [pid 782784:tid 782978] [client 20.63.98.115:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/hehe.php"] [unique_id "amuNmYaApLsOvtuGcVqr6gAAAEA"]
[Thu Jul 30 12:44:57.855906 2026] [core:notice] [pid 782784:tid 783031] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:57.860405 2026] [security2:error] [pid 782784:tid 783031] [client 103.215.74.26:54188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNmYaApLsOvtuGcVqr-AAAAHU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:58.101335 2026] [security2:error] [pid 782784:tid 783035] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNmYaApLsOvtuGcVqr8AAAAHk"]
[Thu Jul 30 12:44:58.388043 2026] [security2:error] [pid 782784:tid 782971] [client 68.221.186.136:43140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/lufix.php"] [unique_id "amuNmoaApLsOvtuGcVqsAgAAADk"]
[Thu Jul 30 12:44:58.589210 2026] [core:notice] [pid 782784:tid 783001] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:58.593095 2026] [security2:error] [pid 782784:tid 783001] [client 103.215.74.26:54204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNmoaApLsOvtuGcVqsCgAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:58.712607 2026] [security2:error] [pid 782784:tid 783013] [client 20.63.98.115:42959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/webadmin.php"] [unique_id "amuNmoaApLsOvtuGcVqsCwAAAGM"]
[Thu Jul 30 12:44:58.978565 2026] [security2:error] [pid 782784:tid 782936] [client 68.221.186.136:44267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/Geforce.php"] [unique_id "amuNmoaApLsOvtuGcVqsEAAAABY"]
[Thu Jul 30 12:44:59.257276 2026] [security2:error] [pid 782784:tid 782965] [client 172.213.216.126:52419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "k2k.tech"] [uri "/log.php"] [unique_id "amuNm4aApLsOvtuGcVqsGgAAADM"]
[Thu Jul 30 12:44:59.257391 2026] [security2:error] [pid 782784:tid 782965] [client 172.213.216.126:52419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "k2k.tech"] [uri "/log.php"] [unique_id "amuNm4aApLsOvtuGcVqsGgAAADM"]
[Thu Jul 30 12:44:59.281086 2026] [core:error] [pid 782784:tid 782898] [remote 216.73.217.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:59.281105 2026] [core:error] [pid 782784:tid 782898] [remote 216.73.217.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:44:59.320327 2026] [core:notice] [pid 782784:tid 783016] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:44:59.324371 2026] [security2:error] [pid 782784:tid 783016] [client 103.215.74.26:54216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNm4aApLsOvtuGcVqsHQAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:44:59.361862 2026] [security2:error] [pid 782784:tid 782918] [client 52.238.199.152:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/NewFile.php"] [unique_id "amuNm4aApLsOvtuGcVqsHgAAAAQ"]
[Thu Jul 30 12:44:59.408016 2026] [security2:error] [pid 782784:tid 782960] [client 20.203.148.31:33736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/admin.php"] [unique_id "amuNm4aApLsOvtuGcVqsHwAAAC4"]
[Thu Jul 30 12:44:59.653171 2026] [security2:error] [pid 782784:tid 782944] [client 20.63.98.115:20674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/backup.php"] [unique_id "amuNm4aApLsOvtuGcVqsJgAAAB4"]
[Thu Jul 30 12:45:00.051882 2026] [core:notice] [pid 782784:tid 782924] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:00.058731 2026] [security2:error] [pid 782784:tid 782924] [client 103.215.74.26:54224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNnIaApLsOvtuGcVqsMgAAAAo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:00.225124 2026] [security2:error] [pid 782784:tid 783002] [client 20.203.148.31:28910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/class_api.php"] [unique_id "amuNnIaApLsOvtuGcVqsOAAAAFg"]
[Thu Jul 30 12:45:00.795607 2026] [core:notice] [pid 782784:tid 782988] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:00.800101 2026] [security2:error] [pid 782784:tid 782988] [client 103.215.74.26:54238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNnIaApLsOvtuGcVqsSgAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:01.047908 2026] [security2:error] [pid 782784:tid 782985] [client 52.238.199.152:23161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/xx.php"] [unique_id "amuNnYaApLsOvtuGcVqsTQAAAEc"]
[Thu Jul 30 12:45:01.192272 2026] [security2:error] [pid 782784:tid 782953] [client 68.221.186.136:45523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/a4.php"] [unique_id "amuNnYaApLsOvtuGcVqsVQAAACc"]
[Thu Jul 30 12:45:01.397276 2026] [security2:error] [pid 782784:tid 782943] [client 150.107.232.194:27466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNnYaApLsOvtuGcVqsWQAAAB0"]
[Thu Jul 30 12:45:01.397448 2026] [security2:error] [pid 782784:tid 782943] [client 150.107.232.194:27466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNnYaApLsOvtuGcVqsWQAAAB0"]
[Thu Jul 30 12:45:01.516871 2026] [core:notice] [pid 782784:tid 782968] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:01.523521 2026] [security2:error] [pid 782784:tid 782968] [client 103.215.74.26:54250] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNnYaApLsOvtuGcVqsXAAAADY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:01.536627 2026] [security2:error] [pid 782784:tid 782998] [client 20.63.98.115:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/atomlib.php"] [unique_id "amuNnYaApLsOvtuGcVqsXQAAAFQ"]
[Thu Jul 30 12:45:01.599360 2026] [security2:error] [pid 782784:tid 782973] [client 94.54.25.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNnIaApLsOvtuGcVqsSQAAO34"], referer: https://allmontecristi.com
[Thu Jul 30 12:45:01.601588 2026] [security2:error] [pid 782784:tid 783015] [client 20.203.148.31:28899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuNnYaApLsOvtuGcVqsXwAAAGU"]
[Thu Jul 30 12:45:01.680375 2026] [security2:error] [pid 782784:tid 782936] [client 38.190.144.4:58949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNnYaApLsOvtuGcVqsZQAAABY"]
[Thu Jul 30 12:45:01.680490 2026] [security2:error] [pid 782784:tid 782936] [client 38.190.144.4:58949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNnYaApLsOvtuGcVqsZQAAABY"]
[Thu Jul 30 12:45:01.744880 2026] [security2:error] [pid 782784:tid 782935] [client 109.70.100.11:56948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuNnYaApLsOvtuGcVqsVAAAFWQ"], referer: https://happyspree.app/237338-2
[Thu Jul 30 12:45:01.988732 2026] [security2:error] [pid 782784:tid 783033] [client 68.221.186.136:43912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/accueil.php"] [unique_id "amuNnYaApLsOvtuGcVqsbgAAAHc"]
[Thu Jul 30 12:45:02.250089 2026] [core:notice] [pid 782784:tid 782961] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:02.256861 2026] [security2:error] [pid 782784:tid 782961] [client 103.215.74.26:54260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNnoaApLsOvtuGcVqsdQAAAC8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:02.774688 2026] [security2:error] [pid 782784:tid 783013] [client 194.187.251.163:58782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuNnoaApLsOvtuGcVqshAAAAGM"]
[Thu Jul 30 12:45:02.774786 2026] [security2:error] [pid 782784:tid 783013] [client 194.187.251.163:58782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuNnoaApLsOvtuGcVqshAAAAGM"]
[Thu Jul 30 12:45:02.834656 2026] [security2:error] [pid 782784:tid 782991] [client 68.221.186.136:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/dashboard.php"] [unique_id "amuNnoaApLsOvtuGcVqshwAAAE0"]
[Thu Jul 30 12:45:02.942277 2026] [security2:error] [pid 782784:tid 782987] [client 52.238.199.152:43879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/plugins.php"] [unique_id "amuNnoaApLsOvtuGcVqsiQAAAEk"]
[Thu Jul 30 12:45:02.979803 2026] [core:notice] [pid 782784:tid 782946] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:02.983959 2026] [security2:error] [pid 782784:tid 782946] [client 103.215.74.26:54272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNnoaApLsOvtuGcVqsigAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:03.021672 2026] [security2:error] [pid 782784:tid 783036] [client 20.203.148.31:32449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuNnoaApLsOvtuGcVqsgwAAAHo"]
[Thu Jul 30 12:45:03.227261 2026] [security2:error] [pid 782784:tid 782962] [client 74.7.228.63:50436] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mobileblooddrawservices-com.aws.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuNnoaApLsOvtuGcVqsgAAAMBg"]
[Thu Jul 30 12:45:03.399111 2026] [security2:error] [pid 782784:tid 783035] [client 20.63.98.115:44107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/epinyins.php"] [unique_id "amuNn4aApLsOvtuGcVqslAAAAHk"]
[Thu Jul 30 12:45:03.699933 2026] [core:notice] [pid 782784:tid 782919] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:03.704346 2026] [security2:error] [pid 782784:tid 782919] [client 103.215.74.26:29364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNn4aApLsOvtuGcVqsoAAAAAU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:03.942345 2026] [security2:error] [pid 782784:tid 782943] [client 68.221.186.136:45554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/radio.php"] [unique_id "amuNn4aApLsOvtuGcVqspAAAAB0"]
[Thu Jul 30 12:45:03.991422 2026] [core:notice] [pid 782784:tid 783004] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:04.426091 2026] [core:notice] [pid 782784:tid 783032] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:04.437433 2026] [security2:error] [pid 782784:tid 783032] [client 103.215.74.26:29380] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNoIaApLsOvtuGcVqssgAAAHY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:04.556528 2026] [security2:error] [pid 782784:tid 783025] [client 68.221.186.136:26985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/wpsml-sys.php"] [unique_id "amuNoIaApLsOvtuGcVqstwAAAG8"]
[Thu Jul 30 12:45:04.585110 2026] [security2:error] [pid 782784:tid 782979] [client 127.0.0.1:58082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuNoIaApLsOvtuGcVqsuQAAAEE"]
[Thu Jul 30 12:45:04.585137 2026] [security2:error] [pid 782784:tid 783002] [client 127.0.0.1:58078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.propertyspro.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuNoIaApLsOvtuGcVqsuAAAAFg"]
[Thu Jul 30 12:45:04.585289 2026] [security2:error] [pid 782784:tid 782920] [client 74.7.241.142:38232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.propertyspro.com"] [uri "/robots.txt"] [unique_id "amuNoIaApLsOvtuGcVqstgAABjI"]
[Thu Jul 30 12:45:04.711931 2026] [security2:error] [pid 782784:tid 782996] [client 20.203.148.31:28493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuNoIaApLsOvtuGcVqsugAAAFI"]
[Thu Jul 30 12:45:05.164089 2026] [core:notice] [pid 782784:tid 783024] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:05.168217 2026] [security2:error] [pid 782784:tid 783024] [client 103.215.74.26:29384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNoYaApLsOvtuGcVqsywAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:05.220192 2026] [security2:error] [pid 782784:tid 782935] [client 20.63.98.115:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuNoYaApLsOvtuGcVqszwAAABU"]
[Thu Jul 30 12:45:05.548114 2026] [security2:error] [pid 782784:tid 782947] [client 216.73.216.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "palmtreepools.ca"] [uri "/index.php"] [unique_id "amuNoYaApLsOvtuGcVqs0AAAACE"]
[Thu Jul 30 12:45:05.606413 2026] [security2:error] [pid 782784:tid 782997] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuNoYaApLsOvtuGcVqs0wAAUw0"]
[Thu Jul 30 12:45:05.631620 2026] [security2:error] [pid 782784:tid 783019] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNoYaApLsOvtuGcVqsyQAAAGk"]
[Thu Jul 30 12:45:05.812505 2026] [security2:error] [pid 782784:tid 782946] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNoYaApLsOvtuGcVqszgAAACA"]
[Thu Jul 30 12:45:05.889566 2026] [core:notice] [pid 782784:tid 782960] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:05.893500 2026] [security2:error] [pid 782784:tid 782960] [client 103.215.74.26:29396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNoYaApLsOvtuGcVqs6AAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:05.979501 2026] [core:notice] [pid 782784:tid 782965] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:06.042180 2026] [security2:error] [pid 782784:tid 783035] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNoYaApLsOvtuGcVqs2gAAAHk"]
[Thu Jul 30 12:45:06.225161 2026] [core:notice] [pid 782784:tid 782936] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:06.364685 2026] [security2:error] [pid 782784:tid 782953] [client 20.203.148.31:30036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/991176.php"] [unique_id "amuNooaApLsOvtuGcVqs8wAAACc"]
[Thu Jul 30 12:45:06.423511 2026] [security2:error] [pid 782784:tid 782923] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNooaApLsOvtuGcVqs8QAAAAk"]
[Thu Jul 30 12:45:06.612548 2026] [core:notice] [pid 782784:tid 783000] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:06.616490 2026] [security2:error] [pid 782784:tid 783000] [client 103.215.74.26:29402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNooaApLsOvtuGcVqs_QAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:07.352131 2026] [core:notice] [pid 782784:tid 782991] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:07.358112 2026] [security2:error] [pid 782784:tid 782991] [client 103.215.74.26:29412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNo4aApLsOvtuGcVqtCQAAAE0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:07.661854 2026] [security2:error] [pid 782784:tid 782939] [client 68.221.186.136:44695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/02.php"] [unique_id "amuNo4aApLsOvtuGcVqtEwAAABk"]
[Thu Jul 30 12:45:07.953444 2026] [security2:error] [pid 782784:tid 782919] [client 172.213.216.126:48583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "k2k.tech"] [uri "/edit.php"] [unique_id "amuNo4aApLsOvtuGcVqtGQAAAAU"]
[Thu Jul 30 12:45:07.953574 2026] [security2:error] [pid 782784:tid 782919] [client 172.213.216.126:48583] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "k2k.tech"] [uri "/edit.php"] [unique_id "amuNo4aApLsOvtuGcVqtGQAAAAU"]
[Thu Jul 30 12:45:08.092857 2026] [core:notice] [pid 782784:tid 782975] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:08.097008 2026] [security2:error] [pid 782784:tid 782975] [client 103.215.74.26:29420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNpIaApLsOvtuGcVqtJgAAAD0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:08.147246 2026] [security2:error] [pid 782784:tid 782997] [client 52.238.199.152:43892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/xxx.php"] [unique_id "amuNpIaApLsOvtuGcVqtKAAAAFM"]
[Thu Jul 30 12:45:08.442347 2026] [security2:error] [pid 782784:tid 782944] [client 68.221.186.136:26945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/infos.php"] [unique_id "amuNpIaApLsOvtuGcVqtLQAAAB4"]
[Thu Jul 30 12:45:08.447963 2026] [security2:error] [pid 782784:tid 782965] [client 20.203.148.31:30946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuNpIaApLsOvtuGcVqtLgAAADM"]
[Thu Jul 30 12:45:08.825872 2026] [core:notice] [pid 782784:tid 783028] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:08.832863 2026] [security2:error] [pid 782784:tid 783028] [client 103.215.74.26:29436] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNpIaApLsOvtuGcVqtOgAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:09.562475 2026] [core:notice] [pid 782784:tid 782963] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:09.566366 2026] [security2:error] [pid 782784:tid 782963] [client 103.215.74.26:29442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNpYaApLsOvtuGcVqtSQAAADE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:09.699368 2026] [security2:error] [pid 782784:tid 782830] [remote 176.31.139.10:41668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/nos-partenaires/"] [unique_id "amuNpYaApLsOvtuGcVqtUAAATS0"]
[Thu Jul 30 12:45:09.699546 2026] [security2:error] [pid 782784:tid 782991] [client 176.31.139.10:41668] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/nos-partenaires/"] [unique_id "amuNpYaApLsOvtuGcVqtUAAATS0"]
[Thu Jul 30 12:45:09.991521 2026] [security2:error] [pid 782784:tid 782932] [client 74.7.228.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.gas.djb.temporary.site"] [uri "/index.php"] [unique_id "amuNo4aApLsOvtuGcVqtGAAAABI"]
[Thu Jul 30 12:45:09.992418 2026] [security2:error] [pid 782784:tid 782937] [client 74.7.228.33:37454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.gas.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuNo4aApLsOvtuGcVqtFgAAF2E"]
[Thu Jul 30 12:45:10.065675 2026] [security2:error] [pid 782784:tid 783001] [client 20.203.148.31:28487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuNpoaApLsOvtuGcVqtVQAAAFc"]
[Thu Jul 30 12:45:10.318460 2026] [core:notice] [pid 782784:tid 783016] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:10.322794 2026] [security2:error] [pid 782784:tid 783016] [client 103.215.74.26:29452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNpoaApLsOvtuGcVqtYgAAAGY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:10.366191 2026] [security2:error] [pid 782784:tid 782946] [client 165.154.162.193:55252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.luf.owl.temporary.site"] [uri "/index.php"] [unique_id "amuNpoaApLsOvtuGcVqtXQAAACA"]
[Thu Jul 30 12:45:10.576522 2026] [security2:error] [pid 782784:tid 782983] [client 52.238.199.152:39826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/css.php"] [unique_id "amuNpoaApLsOvtuGcVqtZAAAAEU"]
[Thu Jul 30 12:45:11.061032 2026] [core:notice] [pid 782784:tid 782989] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:11.065447 2026] [security2:error] [pid 782784:tid 782989] [client 103.215.74.26:29462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNp4aApLsOvtuGcVqtdgAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:11.754570 2026] [security2:error] [pid 782784:tid 782963] [client 150.107.232.194:26951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNp4aApLsOvtuGcVqtjQAAADE"]
[Thu Jul 30 12:45:11.754683 2026] [security2:error] [pid 782784:tid 782963] [client 150.107.232.194:26951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNp4aApLsOvtuGcVqtjQAAADE"]
[Thu Jul 30 12:45:11.782209 2026] [core:notice] [pid 782784:tid 782971] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:11.786413 2026] [security2:error] [pid 782784:tid 782971] [client 103.215.74.26:29468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNp4aApLsOvtuGcVqtkQAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:12.396680 2026] [security2:error] [pid 782784:tid 782980] [client 52.238.199.152:39860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuNqIaApLsOvtuGcVqtogAAAEI"]
[Thu Jul 30 12:45:12.415672 2026] [security2:error] [pid 782784:tid 782956] [client 85.208.96.201:16568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/05/confianca-de-sape-vence-desportiva-guarabira-por-5-a-2-na-estreia-da-2a-divisao/"] [unique_id "amuNqIaApLsOvtuGcVqtowAAACo"]
[Thu Jul 30 12:45:12.415832 2026] [security2:error] [pid 782784:tid 782956] [client 85.208.96.201:16568] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/05/confianca-de-sape-vence-desportiva-guarabira-por-5-a-2-na-estreia-da-2a-divisao/"] [unique_id "amuNqIaApLsOvtuGcVqtowAAACo"]
[Thu Jul 30 12:45:12.478144 2026] [security2:error] [pid 782784:tid 782947] [client 20.203.148.31:30951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuNqIaApLsOvtuGcVqtpAAAACE"]
[Thu Jul 30 12:45:12.485157 2026] [security2:error] [pid 782784:tid 782999] [client 38.190.144.4:59507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNqIaApLsOvtuGcVqtpQAAAFU"]
[Thu Jul 30 12:45:12.487492 2026] [security2:error] [pid 782784:tid 782999] [client 38.190.144.4:59507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNqIaApLsOvtuGcVqtpQAAAFU"]
[Thu Jul 30 12:45:12.512215 2026] [core:notice] [pid 782784:tid 783040] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:12.519353 2026] [security2:error] [pid 782784:tid 783040] [client 103.215.74.26:29476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNqIaApLsOvtuGcVqtpgAAAH4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:13.273000 2026] [core:notice] [pid 782784:tid 782938] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:13.277266 2026] [security2:error] [pid 782784:tid 782938] [client 103.215.74.26:35296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNqYaApLsOvtuGcVqttwAAABg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:13.290911 2026] [security2:error] [pid 782784:tid 782953] [client 52.238.199.152:39834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuNqYaApLsOvtuGcVqtuAAAACc"]
[Thu Jul 30 12:45:13.293777 2026] [security2:error] [pid 782784:tid 782964] [client 20.203.148.31:33747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuNqYaApLsOvtuGcVqtuQAAADI"]
[Thu Jul 30 12:45:14.044536 2026] [core:notice] [pid 782784:tid 782951] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:14.048881 2026] [security2:error] [pid 782784:tid 782951] [client 103.215.74.26:35306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNqoaApLsOvtuGcVqtygAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:14.414319 2026] [security2:error] [pid 782784:tid 783021] [client 79.117.253.247:43258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNqoaApLsOvtuGcVqtywAAAGs"], referer: http://pkf.jo
[Thu Jul 30 12:45:14.442789 2026] [security2:error] [pid 782784:tid 782974] [client 52.238.199.152:39845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuNqoaApLsOvtuGcVqt2gAAADw"]
[Thu Jul 30 12:45:14.593077 2026] [security2:error] [pid 782784:tid 782935] [client 103.114.252.190:9967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNqoaApLsOvtuGcVqt0QAAABU"], referer: http://pkf.jo
[Thu Jul 30 12:45:14.760401 2026] [core:notice] [pid 782784:tid 782993] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:14.764687 2026] [security2:error] [pid 782784:tid 782993] [client 103.215.74.26:35312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNqoaApLsOvtuGcVqt5gAAAE8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:15.047246 2026] [fcgid:warn] [pid 782784:tid 782955] (70014)End of file found: [client 18.218.118.203:61084] mod_fcgid: can't get data from http client
[Thu Jul 30 12:45:15.488171 2026] [security2:error] [pid 782784:tid 782943] [client 157.100.168.90:53440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNq4aApLsOvtuGcVqt8gAAAB0"], referer: http://pkf.jo
[Thu Jul 30 12:45:15.499404 2026] [core:notice] [pid 782784:tid 783029] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:15.503742 2026] [security2:error] [pid 782784:tid 783029] [client 103.215.74.26:35326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNq4aApLsOvtuGcVquAAAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:15.520495 2026] [security2:error] [pid 782784:tid 782965] [client 157.46.0.95:38229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNq4aApLsOvtuGcVqt9AAAADM"], referer: http://pkf.jo
[Thu Jul 30 12:45:15.533827 2026] [security2:error] [pid 782784:tid 783017] [client 197.231.201.178:61002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNq4aApLsOvtuGcVqt9QAAAGc"], referer: http://pkf.jo
[Thu Jul 30 12:45:15.938148 2026] [core:notice] [pid 782784:tid 782819] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:15.947767 2026] [security2:error] [pid 782784:tid 782992] [client 165.154.162.193:32890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.luf.owl.temporary.site"] [uri "/index.php"] [unique_id "amuNq4aApLsOvtuGcVquBQAAAE4"]
[Thu Jul 30 12:45:16.230608 2026] [core:notice] [pid 782784:tid 782950] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:16.232066 2026] [security2:error] [pid 782784:tid 783015] [client 85.208.96.211:18018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/07/operacao-da-pf-investiga-fraudes-de-ate-r-10-milhoes-em-financiamentos-de-imoveis-pela-caixa-na-paraiba/"] [unique_id "amuNrIaApLsOvtuGcVquJAAAAGU"]
[Thu Jul 30 12:45:16.232182 2026] [security2:error] [pid 782784:tid 783015] [client 85.208.96.211:18018] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/07/operacao-da-pf-investiga-fraudes-de-ate-r-10-milhoes-em-financiamentos-de-imoveis-pela-caixa-na-paraiba/"] [unique_id "amuNrIaApLsOvtuGcVquJAAAAGU"]
[Thu Jul 30 12:45:16.238014 2026] [security2:error] [pid 782784:tid 782950] [client 103.215.74.26:35330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNrIaApLsOvtuGcVquIwAAACQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:16.300083 2026] [security2:error] [pid 782784:tid 782981] [client 181.16.171.73:33134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNq4aApLsOvtuGcVquAQAAAEM"], referer: http://pkf.jo
[Thu Jul 30 12:45:16.359570 2026] [security2:error] [pid 782784:tid 782970] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuNrIaApLsOvtuGcVquFgAAOCc"]
[Thu Jul 30 12:45:16.478921 2026] [security2:error] [pid 782784:tid 783005] [client 68.221.186.136:42575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/updates.php"] [unique_id "amuNrIaApLsOvtuGcVquLwAAAFs"]
[Thu Jul 30 12:45:16.798136 2026] [security2:error] [pid 782784:tid 783006] [client 20.203.148.31:30117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuNrIaApLsOvtuGcVquOAAAAFw"]
[Thu Jul 30 12:45:16.960543 2026] [core:notice] [pid 782784:tid 783013] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:16.964443 2026] [security2:error] [pid 782784:tid 783013] [client 103.215.74.26:35336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNrIaApLsOvtuGcVquPAAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:17.042060 2026] [security2:error] [pid 782784:tid 782968] [client 68.221.186.136:41396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/user.php"] [unique_id "amuNrYaApLsOvtuGcVquQAAAADY"]
[Thu Jul 30 12:45:17.450681 2026] [security2:error] [pid 782784:tid 783041] [client 52.238.199.152:39818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/network/about.php"] [unique_id "amuNrYaApLsOvtuGcVquSwAAAH8"]
[Thu Jul 30 12:45:17.714920 2026] [core:notice] [pid 782784:tid 782995] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:17.719088 2026] [security2:error] [pid 782784:tid 782995] [client 103.215.74.26:35350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNrYaApLsOvtuGcVquWwAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:17.988319 2026] [security2:error] [pid 782784:tid 782965] [client 20.203.148.31:33768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuNrYaApLsOvtuGcVquXQAAADM"]
[Thu Jul 30 12:45:18.115114 2026] [security2:error] [pid 782784:tid 782980] [client 2803:d700:92da:afd0:8573:8656:3bdd:222e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNrYaApLsOvtuGcVquSQAAQjo"], referer: https://allmontecristi.com
[Thu Jul 30 12:45:18.265484 2026] [security2:error] [pid 782784:tid 783012] [client 49.13.134.145:57108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuNroaApLsOvtuGcVquZwAAAGI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:45:18.409499 2026] [security2:error] [pid 782784:tid 783034] [client 52.238.199.152:39822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/xpw.php"] [unique_id "amuNroaApLsOvtuGcVquawAAAHg"]
[Thu Jul 30 12:45:18.442040 2026] [core:notice] [pid 782784:tid 782990] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:18.446053 2026] [security2:error] [pid 782784:tid 782990] [client 103.215.74.26:35362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNroaApLsOvtuGcVqubAAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:18.495067 2026] [security2:error] [pid 782784:tid 783000] [client 165.154.162.193:32900] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.luf.owl.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amuNroaApLsOvtuGcVqubQAAAFY"]
[Thu Jul 30 12:45:18.745565 2026] [security2:error] [pid 782784:tid 783023] [client 62.102.148.158:55238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuNroaApLsOvtuGcVqueAAAAG0"]
[Thu Jul 30 12:45:18.745653 2026] [security2:error] [pid 782784:tid 783023] [client 62.102.148.158:55238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuNroaApLsOvtuGcVqueAAAAG0"]
[Thu Jul 30 12:45:18.786689 2026] [core:notice] [pid 782784:tid 782986] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:18.790987 2026] [security2:error] [pid 782784:tid 782986] [client 49.13.134.145:57122] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNroaApLsOvtuGcVqueQAAAEg"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:45:18.840356 2026] [security2:error] [pid 782784:tid 782976] [client 20.203.148.31:30094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuNroaApLsOvtuGcVquegAAAD4"]
[Thu Jul 30 12:45:19.186177 2026] [security2:error] [pid 782784:tid 782915] [client 68.221.186.136:18988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/admin-ajax.php"] [unique_id "amuNr4aApLsOvtuGcVquiAAAAAE"]
[Thu Jul 30 12:45:19.186422 2026] [core:notice] [pid 782784:tid 782937] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:19.189850 2026] [security2:error] [pid 782784:tid 782932] [client 49.13.134.145:57130] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuNr4aApLsOvtuGcVquhgAAABI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:45:19.190770 2026] [security2:error] [pid 782784:tid 782937] [client 103.215.74.26:35368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNr4aApLsOvtuGcVquhwAAABc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:19.704911 2026] [core:notice] [pid 782784:tid 782955] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:19.842772 2026] [security2:error] [pid 782784:tid 783040] [client 68.221.186.136:44939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/alfa.php"] [unique_id "amuNr4aApLsOvtuGcVqumAAAAH4"]
[Thu Jul 30 12:45:19.920414 2026] [security2:error] [pid 782784:tid 783016] [client 74.7.228.23:47246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.ampere.us.cc"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuNr4aApLsOvtuGcVqumQAAAGY"]
[Thu Jul 30 12:45:19.939277 2026] [core:notice] [pid 782784:tid 782926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:19.945922 2026] [security2:error] [pid 782784:tid 782926] [client 103.215.74.26:35384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNr4aApLsOvtuGcVqumgAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:20.039507 2026] [security2:error] [pid 782784:tid 782971] [client 52.238.199.152:22514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-cron.php"] [unique_id "amuNsIaApLsOvtuGcVqumwAAADk"]
[Thu Jul 30 12:45:20.050968 2026] [security2:error] [pid 782784:tid 782959] [client 54.152.198.76:11932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.pkf.jo"] [uri "/index.php"] [unique_id "amuNr4aApLsOvtuGcVqulwAAAC0"]
[Thu Jul 30 12:45:20.105341 2026] [security2:error] [pid 782784:tid 782916] [client 20.203.148.31:30975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuNsIaApLsOvtuGcVqunAAAAAI"]
[Thu Jul 30 12:45:20.691879 2026] [core:notice] [pid 782784:tid 782980] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:20.698608 2026] [security2:error] [pid 782784:tid 782980] [client 103.215.74.26:35398] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNsIaApLsOvtuGcVqurQAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:21.228682 2026] [security2:error] [pid 782784:tid 783036] [client 20.203.148.31:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuNsYaApLsOvtuGcVquvQAAAHo"]
[Thu Jul 30 12:45:21.419446 2026] [core:notice] [pid 782784:tid 782981] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:21.423435 2026] [security2:error] [pid 782784:tid 782981] [client 103.215.74.26:35408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNsYaApLsOvtuGcVquwwAAAEM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:21.985078 2026] [security2:error] [pid 782784:tid 782979] [client 52.238.199.152:39839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cah.php"] [unique_id "amuNsYaApLsOvtuGcVquzQAAAEE"]
[Thu Jul 30 12:45:22.147591 2026] [core:notice] [pid 782784:tid 782946] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:22.151594 2026] [security2:error] [pid 782784:tid 782946] [client 103.215.74.26:35420] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNsoaApLsOvtuGcVquzgAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:22.228398 2026] [security2:error] [pid 782784:tid 783040] [client 150.107.232.194:27068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNsoaApLsOvtuGcVqu0gAAAH4"]
[Thu Jul 30 12:45:22.228523 2026] [security2:error] [pid 782784:tid 783040] [client 150.107.232.194:27068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNsoaApLsOvtuGcVqu0gAAAH4"]
[Thu Jul 30 12:45:22.579393 2026] [security2:error] [pid 782784:tid 782961] [client 34.224.132.215:43447] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/11075182_600494583421445_5071123810410852929_n-300x225.jpg"] [unique_id "amuNsoaApLsOvtuGcVqu2wAAAC8"]
[Thu Jul 30 12:45:22.762943 2026] [security2:error] [pid 782784:tid 782943] [client 113.191.154.67:56945] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuNsoaApLsOvtuGcVqu3wAAAB0"]
[Thu Jul 30 12:45:22.793491 2026] [security2:error] [pid 782784:tid 782918] [client 91.245.204.136:5814] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.ttf"] [unique_id "amuNsoaApLsOvtuGcVqu5QAAAAQ"]
[Thu Jul 30 12:45:22.808583 2026] [security2:error] [pid 782784:tid 782959] [client 88.138.76.191:35074] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuNsoaApLsOvtuGcVqu5wAAAC0"]
[Thu Jul 30 12:45:22.815910 2026] [security2:error] [pid 782784:tid 782808] [remote 57.141.0.14:43368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuNsoaApLsOvtuGcVqu6AAAZxc"]
[Thu Jul 30 12:45:22.827807 2026] [security2:error] [pid 782784:tid 782971] [client 88.30.70.175:35962] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuNsoaApLsOvtuGcVqu6gAAADk"]
[Thu Jul 30 12:45:22.841593 2026] [security2:error] [pid 782784:tid 783030] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNsoaApLsOvtuGcVqu0wAAdFE"]
[Thu Jul 30 12:45:22.850378 2026] [security2:error] [pid 782784:tid 782953] [client 79.252.107.17:61589] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuNsoaApLsOvtuGcVqu8AAAACc"]
[Thu Jul 30 12:45:22.966347 2026] [security2:error] [pid 782784:tid 783029] [client 81.202.7.161:46354] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.woff"] [unique_id "amuNsoaApLsOvtuGcVqu9QAAAHM"]
[Thu Jul 30 12:45:23.012502 2026] [security2:error] [pid 782784:tid 782964] [client 79.145.231.49:52432] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuNs4aApLsOvtuGcVqu9wAAADI"]
[Thu Jul 30 12:45:23.073750 2026] [security2:error] [pid 782784:tid 782954] [client 80.6.234.169:43200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.ttf"] [unique_id "amuNs4aApLsOvtuGcVqu-AAAACg"]
[Thu Jul 30 12:45:23.102652 2026] [security2:error] [pid 782784:tid 782938] [client 23.128.248.163:46290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuNsoaApLsOvtuGcVqu7wAAGHk"], referer: https://happyspree.app/about-us
[Thu Jul 30 12:45:23.169953 2026] [security2:error] [pid 782784:tid 782924] [client 2.137.32.101:55248] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuNs4aApLsOvtuGcVqu-QAAAAo"]
[Thu Jul 30 12:45:23.182020 2026] [security2:error] [pid 782784:tid 782958] [client 82.43.136.196:53696] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.eot"] [unique_id "amuNs4aApLsOvtuGcVqu-gAAACw"]
[Thu Jul 30 12:45:23.192474 2026] [security2:error] [pid 782784:tid 783014] [client 95.105.3.70:5701] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.woff"] [unique_id "amuNs4aApLsOvtuGcVqu-wAAAGQ"]
[Thu Jul 30 12:45:23.543804 2026] [security2:error] [pid 782784:tid 782952] [client 38.190.144.4:60047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNs4aApLsOvtuGcVqvBgAAACY"]
[Thu Jul 30 12:45:23.543933 2026] [security2:error] [pid 782784:tid 782952] [client 38.190.144.4:60047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNs4aApLsOvtuGcVqvBgAAACY"]
[Thu Jul 30 12:45:23.606767 2026] [security2:error] [pid 782784:tid 782972] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNsoaApLsOvtuGcVqu9gAAADo"]
[Thu Jul 30 12:45:23.867449 2026] [security2:error] [pid 782784:tid 783012] [client 93.41.125.178:63825] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/fontawesome-webfont.eot"] [unique_id "amuNs4aApLsOvtuGcVqvEAAAAGI"]
[Thu Jul 30 12:45:24.012380 2026] [security2:error] [pid 782784:tid 782974] [client 68.221.186.136:19007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/hehe.php"] [unique_id "amuNtIaApLsOvtuGcVqvFAAAADw"]
[Thu Jul 30 12:45:24.114744 2026] [security2:error] [pid 782784:tid 782921] [client 79.153.149.11:43302] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.woff2"] [unique_id "amuNtIaApLsOvtuGcVqvFQAAAAc"]
[Thu Jul 30 12:45:24.739550 2026] [security2:error] [pid 782784:tid 782982] [client 52.238.199.152:22476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cong.php"] [unique_id "amuNtIaApLsOvtuGcVqvIQAAAEQ"]
[Thu Jul 30 12:45:25.043682 2026] [security2:error] [pid 782784:tid 782969] [client 79.117.82.84:51644] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/icomoon/fonts/icomoon.eot"] [unique_id "amuNtYaApLsOvtuGcVqvKwAAADc"]
[Thu Jul 30 12:45:25.320954 2026] [security2:error] [pid 782784:tid 782931] [client 20.203.148.31:30103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuNtYaApLsOvtuGcVqvLAAAABE"]
[Thu Jul 30 12:45:25.839254 2026] [security2:error] [pid 782784:tid 783029] [client 68.221.186.136:42620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/rk2.php"] [unique_id "amuNtYaApLsOvtuGcVqvOQAAAHM"]
[Thu Jul 30 12:45:26.458518 2026] [security2:error] [pid 782784:tid 783006] [client 20.203.148.31:28482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuNtoaApLsOvtuGcVqvSAAAAFw"]
[Thu Jul 30 12:45:26.499223 2026] [security2:error] [pid 782784:tid 782955] [client 68.221.186.136:42581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/setup-config.php"] [unique_id "amuNtoaApLsOvtuGcVqvSgAAACk"]
[Thu Jul 30 12:45:26.673727 2026] [security2:error] [pid 782784:tid 782974] [client 44.221.227.90:41056] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/dupla-de-traficantes-que-atuava-em-guarabira-e-presa-com-maconha/"] [unique_id "amuNtoaApLsOvtuGcVqvTgAAADw"]
[Thu Jul 30 12:45:26.933279 2026] [security2:error] [pid 782784:tid 783030] [client 24.89.126.92:60400] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/Pe-icon-7-stroke.ttf"] [unique_id "amuNtoaApLsOvtuGcVqvWwAAAHQ"]
[Thu Jul 30 12:45:27.045832 2026] [security2:error] [pid 782784:tid 782936] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuNtoaApLsOvtuGcVqvTwAAFkw"]
[Thu Jul 30 12:45:27.479503 2026] [security2:error] [pid 782784:tid 782996] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuNtoaApLsOvtuGcVqvVwAAAFI"]
[Thu Jul 30 12:45:27.646146 2026] [core:notice] [pid 782784:tid 782950] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:27.685591 2026] [security2:error] [pid 782784:tid 782816] [remote 74.7.241.60:57978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuNt4aApLsOvtuGcVqvdgAAER8"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:45:27.688825 2026] [core:notice] [pid 782784:tid 783023] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:27.693675 2026] [core:notice] [pid 782784:tid 782969] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:27.933818 2026] [core:notice] [pid 782784:tid 782914] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:27.940567 2026] [security2:error] [pid 782784:tid 782914] [client 103.215.74.26:11508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNt4aApLsOvtuGcVqveQAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:27.975288 2026] [core:notice] [pid 782784:tid 782918] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:27.976048 2026] [core:notice] [pid 782784:tid 783019] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:27.989947 2026] [core:notice] [pid 782784:tid 782942] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:28.038571 2026] [core:notice] [pid 782784:tid 782919] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:28.045575 2026] [core:notice] [pid 782784:tid 782957] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:28.186348 2026] [core:notice] [pid 782784:tid 782988] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:28.668490 2026] [core:notice] [pid 782784:tid 782973] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:28.672490 2026] [security2:error] [pid 782784:tid 782973] [client 103.215.74.26:11514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNuIaApLsOvtuGcVqvnwAAADs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:29.163612 2026] [security2:error] [pid 782784:tid 782923] [client 52.238.199.152:22773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/Sanskrit.php"] [unique_id "amuNuYaApLsOvtuGcVqvrAAAAAk"]
[Thu Jul 30 12:45:29.169529 2026] [security2:error] [pid 782784:tid 782956] [client 37.15.78.199:55038] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "nimna.lk"] [uri "/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuNuYaApLsOvtuGcVqvrQAAACo"]
[Thu Jul 30 12:45:29.264044 2026] [security2:error] [pid 782784:tid 783033] [client 20.203.148.31:32614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuNuYaApLsOvtuGcVqvrgAAAHc"]
[Thu Jul 30 12:45:29.421084 2026] [core:notice] [pid 782784:tid 783009] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:29.425112 2026] [security2:error] [pid 782784:tid 783009] [client 103.215.74.26:11528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNuYaApLsOvtuGcVqvrwAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:30.147101 2026] [core:notice] [pid 782784:tid 782914] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:30.148866 2026] [core:notice] [pid 782784:tid 783013] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:30.152676 2026] [security2:error] [pid 782784:tid 783013] [client 103.215.74.26:11532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNuoaApLsOvtuGcVqvwgAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:30.289502 2026] [security2:error] [pid 782784:tid 782920] [client 44.208.223.68:17457] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/20150321053301-1.jpg"] [unique_id "amuNuoaApLsOvtuGcVqvxwAAAAY"]
[Thu Jul 30 12:45:30.478322 2026] [security2:error] [pid 782784:tid 782993] [client 52.238.199.152:22540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/ms-edit.php"] [unique_id "amuNuoaApLsOvtuGcVqvyAAAAE8"]
[Thu Jul 30 12:45:30.728776 2026] [security2:error] [pid 782784:tid 783037] [client 68.221.186.136:42353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/a7.php"] [unique_id "amuNuoaApLsOvtuGcVqv0wAAAHs"]
[Thu Jul 30 12:45:30.934208 2026] [security2:error] [pid 782784:tid 782934] [client 20.203.148.31:28445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuNuoaApLsOvtuGcVqv1wAAABQ"]
[Thu Jul 30 12:45:31.088263 2026] [core:notice] [pid 782784:tid 782945] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:31.229559 2026] [security2:error] [pid 782784:tid 782959] [client 68.221.186.136:44214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/f7.php"] [unique_id "amuNu4aApLsOvtuGcVqv4AAAAC0"]
[Thu Jul 30 12:45:32.264459 2026] [security2:error] [pid 782784:tid 782949] [client 52.238.199.152:22543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/function.php"] [unique_id "amuNvIaApLsOvtuGcVqv9gAAACM"]
[Thu Jul 30 12:45:32.407849 2026] [security2:error] [pid 782784:tid 783015] [client 68.221.186.136:46325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/nw.php"] [unique_id "amuNvIaApLsOvtuGcVqv_QAAAGU"]
[Thu Jul 30 12:45:32.522072 2026] [security2:error] [pid 782784:tid 783026] [client 20.203.148.31:11575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuNvIaApLsOvtuGcVqv_gAAAHA"]
[Thu Jul 30 12:45:32.692858 2026] [security2:error] [pid 782784:tid 782928] [client 150.107.232.194:27129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNvIaApLsOvtuGcVqwCgAAAA4"]
[Thu Jul 30 12:45:32.693008 2026] [security2:error] [pid 782784:tid 782928] [client 150.107.232.194:27129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNvIaApLsOvtuGcVqwCgAAAA4"]
[Thu Jul 30 12:45:33.352785 2026] [fcgid:warn] [pid 782784:tid 783012] (70014)End of file found: [client 152.32.131.245:35426] mod_fcgid: can't get data from http client
[Thu Jul 30 12:45:33.707842 2026] [security2:error] [pid 782784:tid 782994] [client 20.203.148.31:32628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/bek.php"] [unique_id "amuNvYaApLsOvtuGcVqwJQAAAFA"]
[Thu Jul 30 12:45:33.994890 2026] [security2:error] [pid 782784:tid 783011] [client 52.238.199.152:22482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/ee.php"] [unique_id "amuNvYaApLsOvtuGcVqwMAAAAGE"]
[Thu Jul 30 12:45:34.266945 2026] [security2:error] [pid 782784:tid 782986] [client 38.190.144.4:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNvoaApLsOvtuGcVqwOAAAAEg"]
[Thu Jul 30 12:45:34.267448 2026] [security2:error] [pid 782784:tid 782986] [client 38.190.144.4:60587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNvoaApLsOvtuGcVqwOAAAAEg"]
[Thu Jul 30 12:45:34.396906 2026] [security2:error] [pid 782784:tid 783001] [client 20.203.148.31:28451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuNvoaApLsOvtuGcVqwPwAAAFc"]
[Thu Jul 30 12:45:34.442071 2026] [security2:error] [pid 782784:tid 782922] [client 52.204.253.129:19909] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/20150321053301-1.jpg"] [unique_id "amuNvoaApLsOvtuGcVqwQAAAAAg"]
[Thu Jul 30 12:45:35.084560 2026] [security2:error] [pid 782784:tid 782869] [remote 62.210.185.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amuNv4aApLsOvtuGcVqwSwAAPFQ"]
[Thu Jul 30 12:45:35.084730 2026] [security2:error] [pid 782784:tid 782974] [client 62.210.185.4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amuNv4aApLsOvtuGcVqwSwAAPFQ"]
[Thu Jul 30 12:45:35.169895 2026] [security2:error] [pid 782784:tid 782916] [client 52.238.199.152:39814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/new.php"] [unique_id "amuNv4aApLsOvtuGcVqwTAAAAAI"]
[Thu Jul 30 12:45:35.925950 2026] [core:notice] [pid 782784:tid 782971] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:35.929967 2026] [security2:error] [pid 782784:tid 782971] [client 103.215.74.26:24266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNv4aApLsOvtuGcVqwZgAAADk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:36.541368 2026] [security2:error] [pid 782784:tid 782999] [client 51.68.236.93:13237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.pkf.jo"] [uri "/robots.txt"] [unique_id "amuNwIaApLsOvtuGcVqwdQAAAFU"]
[Thu Jul 30 12:45:36.584715 2026] [security2:error] [pid 782784:tid 783032] [client 20.203.148.31:28425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/class.api.php"] [unique_id "amuNwIaApLsOvtuGcVqwdgAAAHY"]
[Thu Jul 30 12:45:36.664954 2026] [core:notice] [pid 782784:tid 782962] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:36.669337 2026] [security2:error] [pid 782784:tid 782962] [client 103.215.74.26:24270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNwIaApLsOvtuGcVqwdwAAADA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:37.366880 2026] [security2:error] [pid 782784:tid 782955] [client 20.203.148.31:28479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/cong.php"] [unique_id "amuNwYaApLsOvtuGcVqwhAAAACk"]
[Thu Jul 30 12:45:37.416004 2026] [core:notice] [pid 782784:tid 782974] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:37.422445 2026] [security2:error] [pid 782784:tid 782974] [client 103.215.74.26:24278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNwYaApLsOvtuGcVqwiQAAADw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:37.757777 2026] [security2:error] [pid 782784:tid 782945] [client 68.221.186.136:42306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/ova.php"] [unique_id "amuNwYaApLsOvtuGcVqwlAAAAB8"]
[Thu Jul 30 12:45:37.826676 2026] [security2:error] [pid 782784:tid 783004] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuNwYaApLsOvtuGcVqwjQAAWlE"]
[Thu Jul 30 12:45:38.157633 2026] [core:notice] [pid 782784:tid 783034] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:38.164401 2026] [security2:error] [pid 782784:tid 783034] [client 103.215.74.26:24288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNwoaApLsOvtuGcVqwoQAAAHg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:38.259261 2026] [security2:error] [pid 782784:tid 782953] [client 20.203.148.31:11555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/content.php"] [unique_id "amuNwoaApLsOvtuGcVqwpAAAACc"]
[Thu Jul 30 12:45:38.406391 2026] [security2:error] [pid 782784:tid 782938] [client 52.71.216.196:51963] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/13374_600493996754837_3724152346085438449_n.jpg"] [unique_id "amuNwoaApLsOvtuGcVqwqgAAABg"]
[Thu Jul 30 12:45:38.555444 2026] [security2:error] [pid 782784:tid 783014] [client 68.221.186.136:44558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/robots.php"] [unique_id "amuNwoaApLsOvtuGcVqwsgAAAGQ"]
[Thu Jul 30 12:45:38.921410 2026] [core:notice] [pid 782784:tid 782922] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:38.928706 2026] [security2:error] [pid 782784:tid 782922] [client 103.215.74.26:24292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNwoaApLsOvtuGcVqwvAAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:39.238219 2026] [security2:error] [pid 782784:tid 783002] [client 20.203.148.31:11565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuNw4aApLsOvtuGcVqw3gAAAFg"]
[Thu Jul 30 12:45:39.356489 2026] [security2:error] [pid 782784:tid 783036] [client 45.84.107.76:25063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuNwoaApLsOvtuGcVqwugAAegA"], referer: https://happyspree.app/blog
[Thu Jul 30 12:45:39.460162 2026] [security2:error] [pid 782784:tid 783037] [client 68.221.186.136:44583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/alf.php"] [unique_id "amuNw4aApLsOvtuGcVqw4QAAAHs"]
[Thu Jul 30 12:45:39.664083 2026] [core:notice] [pid 782784:tid 783009] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:39.668669 2026] [security2:error] [pid 782784:tid 783009] [client 103.215.74.26:24302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNw4aApLsOvtuGcVqw6gAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:39.840260 2026] [security2:error] [pid 782784:tid 782984] [client 20.203.148.31:11776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/elp.php"] [unique_id "amuNw4aApLsOvtuGcVqw9gAAAEY"]
[Thu Jul 30 12:45:40.030652 2026] [security2:error] [pid 782784:tid 782969] [client 68.221.186.136:43454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/feedback.php"] [unique_id "amuNxIaApLsOvtuGcVqw-QAAADc"]
[Thu Jul 30 12:45:40.130760 2026] [core:error] [pid 782784:tid 782993] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.130786 2026] [core:error] [pid 782784:tid 782993] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.133337 2026] [core:error] [pid 782784:tid 782942] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.133355 2026] [core:error] [pid 782784:tid 782942] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.170396 2026] [core:error] [pid 782784:tid 782967] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.170415 2026] [core:error] [pid 782784:tid 782967] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.198723 2026] [core:error] [pid 782784:tid 782931] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.198745 2026] [core:error] [pid 782784:tid 782931] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.200843 2026] [core:error] [pid 782784:tid 782955] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.200871 2026] [core:error] [pid 782784:tid 782955] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:40.390029 2026] [core:notice] [pid 782784:tid 782946] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:40.394414 2026] [security2:error] [pid 782784:tid 782946] [client 103.215.74.26:24318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNxIaApLsOvtuGcVqxFgAAACA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:40.713737 2026] [security2:error] [pid 782784:tid 782959] [client 20.203.148.31:32588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuNxIaApLsOvtuGcVqxIQAAAC0"]
[Thu Jul 30 12:45:40.788104 2026] [security2:error] [pid 782784:tid 783033] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuNxIaApLsOvtuGcVqxCQAAd3c"]
[Thu Jul 30 12:45:40.838482 2026] [security2:error] [pid 782784:tid 782794] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/011i.php"] [unique_id "amuNxIaApLsOvtuGcVqxKAAAOwk"]
[Thu Jul 30 12:45:41.094644 2026] [security2:error] [pid 782784:tid 782872] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/03a005685d.php"] [unique_id "amuNxYaApLsOvtuGcVqxKQAAI1c"]
[Thu Jul 30 12:45:41.116723 2026] [core:notice] [pid 782784:tid 782954] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:41.121011 2026] [security2:error] [pid 782784:tid 782954] [client 103.215.74.26:24324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNxYaApLsOvtuGcVqxKwAAACg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:41.290088 2026] [security2:error] [pid 782784:tid 782939] [client 68.221.186.136:26667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/gettest.php"] [unique_id "amuNxYaApLsOvtuGcVqxMwAAABk"]
[Thu Jul 30 12:45:41.690854 2026] [core:notice] [pid 782784:tid 783018] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:41.819220 2026] [security2:error] [pid 782784:tid 782839] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/403.php"] [unique_id "amuNxYaApLsOvtuGcVqxQgAALjY"]
[Thu Jul 30 12:45:41.890367 2026] [core:notice] [pid 782784:tid 783008] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:41.894796 2026] [security2:error] [pid 782784:tid 783008] [client 103.215.74.26:24328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNxYaApLsOvtuGcVqxQwAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:42.116288 2026] [security2:error] [pid 782784:tid 782797] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/404.php"] [unique_id "amuNxoaApLsOvtuGcVqxRAAAfgw"]
[Thu Jul 30 12:45:42.177893 2026] [security2:error] [pid 782784:tid 782919] [client 54.84.147.79:58394] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/88ab90a4828189a2b222831bbe60a3fd-400x196.jpg"] [unique_id "amuNxoaApLsOvtuGcVqxSAAAAAU"]
[Thu Jul 30 12:45:42.376520 2026] [security2:error] [pid 782784:tid 782844] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/aa.php"] [unique_id "amuNxoaApLsOvtuGcVqxUAAAdDs"]
[Thu Jul 30 12:45:42.393137 2026] [security2:error] [pid 782784:tid 783006] [client 74.7.230.32:56250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nmk.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuNxoaApLsOvtuGcVqxUQAAAFw"]
[Thu Jul 30 12:45:42.630190 2026] [security2:error] [pid 782784:tid 782840] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/aafewc0k.php"] [unique_id "amuNxoaApLsOvtuGcVqxVQAAdTc"]
[Thu Jul 30 12:45:42.650407 2026] [core:notice] [pid 782784:tid 782943] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:42.655000 2026] [security2:error] [pid 782784:tid 782943] [client 103.215.74.26:24332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNxoaApLsOvtuGcVqxVgAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:42.669211 2026] [security2:error] [pid 782784:tid 782966] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNxoaApLsOvtuGcVqxVAAAADQ"]
[Thu Jul 30 12:45:42.715409 2026] [core:notice] [pid 782784:tid 783012] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:42.877732 2026] [security2:error] [pid 782784:tid 782962] [client 68.221.186.136:42994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/maint.php"] [unique_id "amuNxoaApLsOvtuGcVqxXwAAADA"]
[Thu Jul 30 12:45:42.877781 2026] [security2:error] [pid 782784:tid 782846] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/abcd.php"] [unique_id "amuNxoaApLsOvtuGcVqxYAAAej0"]
[Thu Jul 30 12:45:42.893601 2026] [security2:error] [pid 782784:tid 783015] [client 20.203.148.31:11559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuNxoaApLsOvtuGcVqxYwAAAGU"]
[Thu Jul 30 12:45:43.160569 2026] [security2:error] [pid 782784:tid 782790] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/about.php"] [unique_id "amuNx4aApLsOvtuGcVqxZAAATAU"]
[Thu Jul 30 12:45:43.163384 2026] [security2:error] [pid 782784:tid 783037] [client 150.107.232.194:27115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNx4aApLsOvtuGcVqxZQAAAHs"]
[Thu Jul 30 12:45:43.163468 2026] [security2:error] [pid 782784:tid 783037] [client 150.107.232.194:27115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuNx4aApLsOvtuGcVqxZQAAAHs"]
[Thu Jul 30 12:45:43.388807 2026] [core:notice] [pid 782784:tid 783033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:43.393265 2026] [security2:error] [pid 782784:tid 783033] [client 103.215.74.26:5076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNx4aApLsOvtuGcVqxbAAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:43.407626 2026] [security2:error] [pid 782784:tid 782890] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/admin.php"] [unique_id "amuNx4aApLsOvtuGcVqxbQAAO2k"]
[Thu Jul 30 12:45:43.460168 2026] [security2:error] [pid 782784:tid 782949] [client 194.187.251.163:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuNx4aApLsOvtuGcVqxcQAAACM"]
[Thu Jul 30 12:45:43.460248 2026] [security2:error] [pid 782784:tid 782949] [client 194.187.251.163:34782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuNx4aApLsOvtuGcVqxcQAAACM"]
[Thu Jul 30 12:45:43.520566 2026] [security2:error] [pid 782784:tid 782944] [client 68.221.186.136:43437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/files.php"] [unique_id "amuNx4aApLsOvtuGcVqxcgAAAB4"]
[Thu Jul 30 12:45:43.650650 2026] [security2:error] [pid 782784:tid 782830] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuNx4aApLsOvtuGcVqxdAAAOC0"]
[Thu Jul 30 12:45:43.892638 2026] [security2:error] [pid 782784:tid 782847] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/albin.php"] [unique_id "amuNx4aApLsOvtuGcVqxfAAAaD4"]
[Thu Jul 30 12:45:44.119055 2026] [core:notice] [pid 782784:tid 783029] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:44.126532 2026] [security2:error] [pid 782784:tid 783029] [client 103.215.74.26:5084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNyIaApLsOvtuGcVqxiAAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:44.136456 2026] [security2:error] [pid 782784:tid 782897] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/amfsqvgv.php"] [unique_id "amuNyIaApLsOvtuGcVqxjQAAU3A"]
[Thu Jul 30 12:45:44.452014 2026] [security2:error] [pid 782784:tid 782903] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ant.php"] [unique_id "amuNyIaApLsOvtuGcVqxlwAAQnY"]
[Thu Jul 30 12:45:44.698514 2026] [security2:error] [pid 782784:tid 782895] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/appreciators.php"] [unique_id "amuNyIaApLsOvtuGcVqxnAAAEG4"]
[Thu Jul 30 12:45:44.871685 2026] [core:notice] [pid 782784:tid 783020] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:44.876124 2026] [security2:error] [pid 782784:tid 783020] [client 103.215.74.26:5098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNyIaApLsOvtuGcVqxowAAAGo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:45.004371 2026] [security2:error] [pid 782784:tid 782891] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/archive.php"] [unique_id "amuNyYaApLsOvtuGcVqxpAAAbGo"]
[Thu Jul 30 12:45:45.305109 2026] [security2:error] [pid 782784:tid 782906] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/as.php"] [unique_id "amuNyYaApLsOvtuGcVqxqwAACXk"]
[Thu Jul 30 12:45:45.331268 2026] [security2:error] [pid 782784:tid 783016] [client 38.190.144.4:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNyYaApLsOvtuGcVqxrgAAAGY"]
[Thu Jul 30 12:45:45.333388 2026] [security2:error] [pid 782784:tid 783016] [client 38.190.144.4:61114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuNyYaApLsOvtuGcVqxrgAAAGY"]
[Thu Jul 30 12:45:45.536139 2026] [security2:error] [pid 782784:tid 782989] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuNyYaApLsOvtuGcVqxtQAAAEs"]
[Thu Jul 30 12:45:45.553213 2026] [security2:error] [pid 782784:tid 782787] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/atomlib.php"] [unique_id "amuNyYaApLsOvtuGcVqxtgAAewI"]
[Thu Jul 30 12:45:45.622526 2026] [core:notice] [pid 782784:tid 782837] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:45.803751 2026] [security2:error] [pid 782784:tid 782800] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuNyYaApLsOvtuGcVqxvgAARw8"]
[Thu Jul 30 12:45:45.812552 2026] [core:notice] [pid 782784:tid 782943] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:46.064496 2026] [security2:error] [pid 782784:tid 782802] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/bb.php"] [unique_id "amuNyoaApLsOvtuGcVqxxwAAGBE"]
[Thu Jul 30 12:45:46.079493 2026] [security2:error] [pid 782784:tid 783023] [client 52.6.5.24:2420] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/03/201703091000300000007046-400x225.jpg"] [unique_id "amuNyoaApLsOvtuGcVqxyAAAAG0"]
[Thu Jul 30 12:45:46.330122 2026] [security2:error] [pid 782784:tid 782925] [client 171.48.24.84:50962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNyYaApLsOvtuGcVqxxgAAAAs"], referer: http://pkf.jo
[Thu Jul 30 12:45:46.372967 2026] [security2:error] [pid 782784:tid 782911] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/bnm.php"] [unique_id "amuNyoaApLsOvtuGcVqxzwAAIX4"]
[Thu Jul 30 12:45:46.489714 2026] [security2:error] [pid 782784:tid 782994] [client 68.221.186.136:43207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/gecko.php"] [unique_id "amuNyoaApLsOvtuGcVqx1QAAAFA"]
[Thu Jul 30 12:45:46.633932 2026] [security2:error] [pid 782784:tid 782810] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/bootstrap.php"] [unique_id "amuNyoaApLsOvtuGcVqx1gAACBk"]
[Thu Jul 30 12:45:46.892393 2026] [security2:error] [pid 782784:tid 782885] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/buy.php"] [unique_id "amuNyoaApLsOvtuGcVqx2wAAAWQ"]
[Thu Jul 30 12:45:47.143651 2026] [security2:error] [pid 782784:tid 782931] [client 188.17.200.85:1417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNyoaApLsOvtuGcVqx2gAAABE"], referer: http://pkf.jo
[Thu Jul 30 12:45:47.151922 2026] [security2:error] [pid 782784:tid 782809] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/chosen.php"] [unique_id "amuNy4aApLsOvtuGcVqx5AAAPhg"]
[Thu Jul 30 12:45:47.211925 2026] [core:error] [pid 782784:tid 782962] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.211947 2026] [core:error] [pid 782784:tid 782962] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.212927 2026] [core:error] [pid 782784:tid 782961] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.212953 2026] [core:error] [pid 782784:tid 782961] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.231395 2026] [core:error] [pid 782784:tid 782989] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.231418 2026] [core:error] [pid 782784:tid 782989] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.267461 2026] [core:error] [pid 782784:tid 783037] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.267485 2026] [core:error] [pid 782784:tid 783037] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.279497 2026] [core:error] [pid 782784:tid 783033] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.279518 2026] [core:error] [pid 782784:tid 783033] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:47.407935 2026] [security2:error] [pid 782784:tid 782799] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-wp-image.php"] [unique_id "amuNy4aApLsOvtuGcVqyAwAAGg4"]
[Thu Jul 30 12:45:47.533161 2026] [security2:error] [pid 782784:tid 782816] [remote 72.167.132.114:34606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-74678686.jvc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuNy4aApLsOvtuGcVqyDQAAFx8"]
[Thu Jul 30 12:45:47.574126 2026] [security2:error] [pid 782784:tid 782955] [client 68.221.186.136:43234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/zwso.php"] [unique_id "amuNy4aApLsOvtuGcVqyDgAAACk"]
[Thu Jul 30 12:45:47.702399 2026] [security2:error] [pid 782784:tid 782829] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/classsmtps.php"] [unique_id "amuNy4aApLsOvtuGcVqyEAAAVCw"]
[Thu Jul 30 12:45:47.707937 2026] [security2:error] [pid 782784:tid 782988] [client 84.15.223.36:40476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNy4aApLsOvtuGcVqyBAAAAEo"], referer: http://pkf.jo
[Thu Jul 30 12:45:47.749496 2026] [security2:error] [pid 782784:tid 782996] [client 82.151.79.54:53761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNy4aApLsOvtuGcVqyBwAAAFI"], referer: http://pkf.jo
[Thu Jul 30 12:45:47.957230 2026] [security2:error] [pid 782784:tid 782834] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuNy4aApLsOvtuGcVqyIAAAcDE"]
[Thu Jul 30 12:45:48.222807 2026] [security2:error] [pid 782784:tid 783005] [client 123.20.9.76:38696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNy4aApLsOvtuGcVqyFAAAAFs"], referer: http://pkf.jo
[Thu Jul 30 12:45:48.248625 2026] [security2:error] [pid 782784:tid 782825] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/config.php"] [unique_id "amuNzIaApLsOvtuGcVqyJwAAfig"]
[Thu Jul 30 12:45:48.330554 2026] [security2:error] [pid 782784:tid 782935] [client 20.203.148.31:11540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuNzIaApLsOvtuGcVqyLQAAABU"]
[Thu Jul 30 12:45:48.345642 2026] [security2:error] [pid 782784:tid 783029] [client 177.20.179.50:8757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuNy4aApLsOvtuGcVqyFwAAAHM"], referer: http://pkf.jo
[Thu Jul 30 12:45:48.488390 2026] [security2:error] [pid 782784:tid 782969] [client 119.73.97.132:29518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuNzIaApLsOvtuGcVqyKAAANxo"], referer: https://www.urwru.club/wp-admin/post.php?post=1023&action=elementor
[Thu Jul 30 12:45:48.519954 2026] [security2:error] [pid 782784:tid 782821] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/core.php"] [unique_id "amuNzIaApLsOvtuGcVqyMwAABiQ"]
[Thu Jul 30 12:45:48.672816 2026] [security2:error] [pid 782784:tid 782927] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuNzIaApLsOvtuGcVqyLAAADR0"]
[Thu Jul 30 12:45:48.770380 2026] [security2:error] [pid 782784:tid 782827] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/css.php"] [unique_id "amuNzIaApLsOvtuGcVqyOAAAICo"]
[Thu Jul 30 12:45:48.869698 2026] [security2:error] [pid 782784:tid 782925] [client 68.221.186.136:26631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/13.php"] [unique_id "amuNzIaApLsOvtuGcVqyPAAAAAs"]
[Thu Jul 30 12:45:49.019685 2026] [security2:error] [pid 782784:tid 782888] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/database.php"] [unique_id "amuNzYaApLsOvtuGcVqyXgAAOGc"]
[Thu Jul 30 12:45:49.039271 2026] [security2:error] [pid 782784:tid 783037] [client 20.203.148.31:47404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuNzYaApLsOvtuGcVqyYgAAAHs"]
[Thu Jul 30 12:45:49.265104 2026] [security2:error] [pid 782784:tid 782856] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/db.php"] [unique_id "amuNzYaApLsOvtuGcVqybQAAcEc"]
[Thu Jul 30 12:45:49.469452 2026] [security2:error] [pid 782784:tid 782983] [client 52.238.199.152:22522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-config.php"] [unique_id "amuNzYaApLsOvtuGcVqycQAAAEU"]
[Thu Jul 30 12:45:49.554630 2026] [security2:error] [pid 782784:tid 783018] [client 68.221.186.136:25314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/ava.php"] [unique_id "amuNzYaApLsOvtuGcVqydgAAAGg"]
[Thu Jul 30 12:45:49.588320 2026] [security2:error] [pid 782784:tid 782871] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/default.php"] [unique_id "amuNzYaApLsOvtuGcVqyewAADlY"]
[Thu Jul 30 12:45:49.869648 2026] [security2:error] [pid 782784:tid 782903] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/dropdown.php"] [unique_id "amuNzYaApLsOvtuGcVqyfQAAOnY"]
[Thu Jul 30 12:45:50.102149 2026] [security2:error] [pid 782784:tid 782957] [client 98.83.8.142:44739] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2018/06/WhatsApp-Image-2018-06-30-at-21.42.37-1-510x680.jpeg"] [unique_id "amuNzoaApLsOvtuGcVqygwAAACs"]
[Thu Jul 30 12:45:50.146582 2026] [security2:error] [pid 782784:tid 782826] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/edit.php"] [unique_id "amuNzoaApLsOvtuGcVqyhwAAMSk"]
[Thu Jul 30 12:45:50.458995 2026] [security2:error] [pid 782784:tid 782874] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/f35.php"] [unique_id "amuNzoaApLsOvtuGcVqyjAAAFFk"]
[Thu Jul 30 12:45:50.620150 2026] [core:notice] [pid 782784:tid 782965] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:50.624329 2026] [security2:error] [pid 782784:tid 782965] [client 103.215.74.26:5106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNzoaApLsOvtuGcVqyjgAAADM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:50.736657 2026] [security2:error] [pid 782784:tid 782866] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/f7.php"] [unique_id "amuNzoaApLsOvtuGcVqylAAAbFE"]
[Thu Jul 30 12:45:51.034132 2026] [security2:error] [pid 782784:tid 782930] [client 20.203.148.31:47410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuNz4aApLsOvtuGcVqynQAAABA"]
[Thu Jul 30 12:45:51.320268 2026] [security2:error] [pid 782784:tid 782995] [client 68.221.186.136:43803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/main.php"] [unique_id "amuNz4aApLsOvtuGcVqypgAAAFE"]
[Thu Jul 30 12:45:51.344111 2026] [core:notice] [pid 782784:tid 782923] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:51.348288 2026] [security2:error] [pid 782784:tid 782923] [client 103.215.74.26:5116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuNz4aApLsOvtuGcVqypwAAAAk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:51.541431 2026] [security2:error] [pid 782784:tid 782971] [client 20.203.148.31:32523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuNz4aApLsOvtuGcVqyrQAAADk"]
[Thu Jul 30 12:45:52.028525 2026] [core:notice] [pid 782784:tid 782929] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:52.039865 2026] [security2:error] [pid 782784:tid 782933] [client 20.203.148.31:47392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuN0IaApLsOvtuGcVqyvQAAABM"]
[Thu Jul 30 12:45:52.066453 2026] [core:notice] [pid 782784:tid 782983] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:52.070430 2026] [security2:error] [pid 782784:tid 782983] [client 103.215.74.26:5118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN0IaApLsOvtuGcVqyvwAAAEU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:52.528737 2026] [core:error] [pid 782784:tid 782886] [remote 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:52.528764 2026] [core:error] [pid 782784:tid 782886] [remote 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:52.702021 2026] [core:notice] [pid 782784:tid 783036] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:52.789224 2026] [security2:error] [pid 782784:tid 782956] [client 20.203.148.31:47401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuN0IaApLsOvtuGcVqy1wAAACo"]
[Thu Jul 30 12:45:52.828312 2026] [core:notice] [pid 782784:tid 782989] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:52.832818 2026] [security2:error] [pid 782784:tid 782989] [client 103.215.74.26:5122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN0IaApLsOvtuGcVqy2AAAAEs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:52.995570 2026] [core:notice] [pid 782784:tid 782908] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:53.045689 2026] [core:error] [pid 782784:tid 782809] [remote 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:53.045712 2026] [core:error] [pid 782784:tid 782809] [remote 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:53.553478 2026] [core:notice] [pid 782784:tid 783009] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:53.560276 2026] [security2:error] [pid 782784:tid 783009] [client 103.215.74.26:56674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN0YaApLsOvtuGcVqy9gAAAF8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:53.629517 2026] [security2:error] [pid 782784:tid 783033] [client 150.107.232.194:26921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN0YaApLsOvtuGcVqy-AAAAHc"]
[Thu Jul 30 12:45:53.629640 2026] [security2:error] [pid 782784:tid 783033] [client 150.107.232.194:26921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN0YaApLsOvtuGcVqy-AAAAHc"]
[Thu Jul 30 12:45:53.973450 2026] [security2:error] [pid 782784:tid 783004] [client 52.238.199.152:23126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-conflg.php"] [unique_id "amuN0YaApLsOvtuGcVqzAAAAAFo"]
[Thu Jul 30 12:45:54.036582 2026] [core:error] [pid 782784:tid 782791] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:54.036606 2026] [core:error] [pid 782784:tid 782791] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:54.196647 2026] [security2:error] [pid 782784:tid 782957] [client 52.45.77.169:46337] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/02/vagas-na-caixa-economica-federal_578921-400x218@2x.jpg"] [unique_id "amuN0oaApLsOvtuGcVqzBgAAACs"]
[Thu Jul 30 12:45:54.236554 2026] [security2:error] [pid 782784:tid 783012] [client 74.7.230.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bkv.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuN0YaApLsOvtuGcVqy4wAAAGI"]
[Thu Jul 30 12:45:54.237234 2026] [security2:error] [pid 782784:tid 782959] [client 74.7.230.42:37236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bkv.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuN0YaApLsOvtuGcVqy4QAALQE"]
[Thu Jul 30 12:45:54.289690 2026] [core:notice] [pid 782784:tid 782972] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:54.296380 2026] [security2:error] [pid 782784:tid 782972] [client 103.215.74.26:56690] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN0oaApLsOvtuGcVqzCgAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:54.712312 2026] [security2:error] [pid 782784:tid 782946] [client 20.203.148.31:12185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuN0oaApLsOvtuGcVqzFQAAACA"]
[Thu Jul 30 12:45:55.023383 2026] [core:notice] [pid 782784:tid 782943] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:55.027431 2026] [security2:error] [pid 782784:tid 782943] [client 103.215.74.26:56700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN04aApLsOvtuGcVqzHwAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:55.142794 2026] [autoindex:error] [pid 782784:tid 782996] [client 20.226.90.242:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_3a7cf4bc/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:45:55.143472 2026] [security2:error] [pid 782784:tid 782996] [client 20.226.90.242:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "frontierphoenix.site"] [uri "/cgi-sys/403.html"] [unique_id "amuN04aApLsOvtuGcVqzIwAAAFI"]
[Thu Jul 30 12:45:55.217240 2026] [security2:error] [pid 782784:tid 782905] [remote 57.141.0.6:39708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/SYARIAH/about/submissions"] [unique_id "amuN04aApLsOvtuGcVqzJAAAZHg"]
[Thu Jul 30 12:45:55.292335 2026] [core:error] [pid 782784:tid 782997] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://chimnify.services/
[Thu Jul 30 12:45:55.292361 2026] [core:error] [pid 782784:tid 782997] [client 191.96.227.82:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://chimnify.services/
[Thu Jul 30 12:45:55.314403 2026] [core:notice] [pid 782784:tid 782825] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:55.317960 2026] [security2:error] [pid 782784:tid 783015] [client 103.190.46.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/index"] [unique_id "amuN04aApLsOvtuGcVqzKwAAZSg"], referer: https://jipkl.com/
[Thu Jul 30 12:45:55.588527 2026] [security2:error] [pid 782784:tid 782962] [client 20.215.191.139:13816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/--wp-lgj.php"] [unique_id "amuN04aApLsOvtuGcVqzMgAAADA"]
[Thu Jul 30 12:45:55.756315 2026] [core:notice] [pid 782784:tid 782951] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:55.760258 2026] [security2:error] [pid 782784:tid 782951] [client 103.215.74.26:56708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN04aApLsOvtuGcVqzNwAAACU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:55.847832 2026] [security2:error] [pid 782784:tid 782926] [client 52.238.199.152:23132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuN04aApLsOvtuGcVqzPgAAAAw"]
[Thu Jul 30 12:45:56.149426 2026] [security2:error] [pid 782784:tid 782923] [client 20.203.148.31:32534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuN1IaApLsOvtuGcVqzSQAAAAk"]
[Thu Jul 30 12:45:56.487232 2026] [core:notice] [pid 782784:tid 782941] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:56.493503 2026] [security2:error] [pid 782784:tid 782941] [client 103.215.74.26:56710] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN1IaApLsOvtuGcVqzTwAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:57.020179 2026] [security2:error] [pid 782784:tid 782995] [client 20.215.191.139:14584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuN1YaApLsOvtuGcVqzXgAAAFE"]
[Thu Jul 30 12:45:57.223957 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:57.227955 2026] [security2:error] [pid 782784:tid 783025] [client 103.215.74.26:56712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN1YaApLsOvtuGcVqzYwAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:57.282228 2026] [security2:error] [pid 782784:tid 782963] [client 38.190.144.4:61625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuN1YaApLsOvtuGcVqzZAAAADE"]
[Thu Jul 30 12:45:57.282378 2026] [security2:error] [pid 782784:tid 782963] [client 38.190.144.4:61625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuN1YaApLsOvtuGcVqzZAAAADE"]
[Thu Jul 30 12:45:57.936081 2026] [security2:error] [pid 782784:tid 783022] [client 68.221.186.136:26729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/wp-file.php"] [unique_id "amuN1YaApLsOvtuGcVqzcwAAAGw"]
[Thu Jul 30 12:45:58.113636 2026] [security2:error] [pid 782784:tid 782938] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuN1YaApLsOvtuGcVqzaAAAGEQ"]
[Thu Jul 30 12:45:58.573536 2026] [security2:error] [pid 782784:tid 782942] [client 68.221.186.136:44920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/wp-signin.php"] [unique_id "amuN1oaApLsOvtuGcVqzfQAAABw"]
[Thu Jul 30 12:45:58.894752 2026] [security2:error] [pid 782784:tid 783015] [client 165.154.162.193:44570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.luf.owl.temporary.site"] [uri "/index.php"] [unique_id "amuN1oaApLsOvtuGcVqzhgAAAGU"]
[Thu Jul 30 12:45:59.292412 2026] [security2:error] [pid 782784:tid 783028] [client 20.215.191.139:14534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/flower.php"] [unique_id "amuN14aApLsOvtuGcVqzlQAAAHI"]
[Thu Jul 30 12:45:59.300167 2026] [security2:error] [pid 782784:tid 782982] [client 52.238.199.152:22511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuN14aApLsOvtuGcVqzlwAAAEQ"]
[Thu Jul 30 12:45:59.368170 2026] [security2:error] [pid 782784:tid 783017] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuN14aApLsOvtuGcVqzjwAAZ0o"]
[Thu Jul 30 12:45:59.551333 2026] [core:notice] [pid 782784:tid 782995] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:45:59.555077 2026] [security2:error] [pid 782784:tid 782995] [client 103.215.74.26:56728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN14aApLsOvtuGcVqzoQAAAFE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:45:59.562018 2026] [core:error] [pid 782784:tid 783018] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.562035 2026] [core:error] [pid 782784:tid 783018] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.598035 2026] [core:error] [pid 782784:tid 783022] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.598055 2026] [core:error] [pid 782784:tid 783022] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.600193 2026] [core:error] [pid 782784:tid 782918] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.600216 2026] [core:error] [pid 782784:tid 782918] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.625798 2026] [core:error] [pid 782784:tid 783006] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.625822 2026] [core:error] [pid 782784:tid 783006] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.627002 2026] [core:error] [pid 782784:tid 782938] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.627016 2026] [core:error] [pid 782784:tid 782938] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:45:59.984584 2026] [security2:error] [pid 782784:tid 782923] [client 20.215.191.139:13794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/xleet.php"] [unique_id "amuN14aApLsOvtuGcVqzxwAAAAk"]
[Thu Jul 30 12:46:00.300752 2026] [core:notice] [pid 782784:tid 783021] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:00.304706 2026] [security2:error] [pid 782784:tid 783021] [client 103.215.74.26:56734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN2IaApLsOvtuGcVqzzAAAAGs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:00.329366 2026] [core:notice] [pid 782784:tid 782936] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:00.729842 2026] [security2:error] [pid 782784:tid 782994] [client 20.215.191.139:20102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuN2IaApLsOvtuGcVqz2wAAAFA"]
[Thu Jul 30 12:46:00.947327 2026] [security2:error] [pid 782784:tid 783035] [client 68.221.186.136:44639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/simi.php"] [unique_id "amuN2IaApLsOvtuGcVqz4QAAAHk"]
[Thu Jul 30 12:46:00.962934 2026] [security2:error] [pid 782784:tid 782921] [client 20.203.148.31:33060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuN2IaApLsOvtuGcVqz4gAAAAc"]
[Thu Jul 30 12:46:01.053823 2026] [core:notice] [pid 782784:tid 783029] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:01.060579 2026] [security2:error] [pid 782784:tid 783029] [client 103.215.74.26:56738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN2YaApLsOvtuGcVqz5gAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:01.528346 2026] [security2:error] [pid 782784:tid 783007] [client 68.221.186.136:44616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/wp-conf.php"] [unique_id "amuN2YaApLsOvtuGcVqz8QAAAF0"]
[Thu Jul 30 12:46:01.605377 2026] [security2:error] [pid 782784:tid 782989] [client 204.8.98.25:36670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuN2YaApLsOvtuGcVqz-AAAAEs"]
[Thu Jul 30 12:46:01.605483 2026] [security2:error] [pid 782784:tid 782989] [client 204.8.98.25:36670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuN2YaApLsOvtuGcVqz-AAAAEs"]
[Thu Jul 30 12:46:01.696845 2026] [security2:error] [pid 782784:tid 782997] [client 20.215.191.139:32090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuN2YaApLsOvtuGcVqz-QAAAFM"]
[Thu Jul 30 12:46:01.807352 2026] [core:notice] [pid 782784:tid 782961] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:01.811358 2026] [security2:error] [pid 782784:tid 782961] [client 103.215.74.26:56754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN2YaApLsOvtuGcVqz_QAAAC8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:01.864524 2026] [security2:error] [pid 782784:tid 783012] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuN2YaApLsOvtuGcVqz7QAAAGI"]
[Thu Jul 30 12:46:02.540740 2026] [core:notice] [pid 782784:tid 782988] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:02.544693 2026] [security2:error] [pid 782784:tid 782988] [client 103.215.74.26:56762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN2oaApLsOvtuGcVq0DwAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:02.903876 2026] [security2:error] [pid 782784:tid 783006] [client 23.20.241.55:39732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuN2YaApLsOvtuGcVqz5wAAAFw"]
[Thu Jul 30 12:46:02.934343 2026] [security2:error] [pid 782784:tid 783026] [client 52.238.199.152:23163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuN2oaApLsOvtuGcVq0HwAAAHA"]
[Thu Jul 30 12:46:03.144698 2026] [security2:error] [pid 782784:tid 782924] [client 20.203.148.31:32520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuN24aApLsOvtuGcVq0IwAAAAo"]
[Thu Jul 30 12:46:03.274363 2026] [core:notice] [pid 782784:tid 782921] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:03.278432 2026] [security2:error] [pid 782784:tid 782921] [client 103.215.74.26:25148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN24aApLsOvtuGcVq0JAAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:03.349176 2026] [security2:error] [pid 782784:tid 783037] [client 68.221.186.136:42715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuN24aApLsOvtuGcVq0KQAAAHs"]
[Thu Jul 30 12:46:03.711013 2026] [core:error] [pid 782784:tid 782893] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:03.711037 2026] [core:error] [pid 782784:tid 782893] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:04.207480 2026] [security2:error] [pid 782784:tid 783024] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuN24aApLsOvtuGcVq0MgAAAG4"]
[Thu Jul 30 12:46:04.288451 2026] [security2:error] [pid 782784:tid 782947] [client 150.107.232.194:27031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN3IaApLsOvtuGcVq0RgAAACE"]
[Thu Jul 30 12:46:04.288567 2026] [security2:error] [pid 782784:tid 782947] [client 150.107.232.194:27031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN3IaApLsOvtuGcVq0RgAAACE"]
[Thu Jul 30 12:46:04.382491 2026] [core:error] [pid 782784:tid 782802] [remote 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:04.382523 2026] [core:error] [pid 782784:tid 782802] [remote 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:04.419911 2026] [security2:error] [pid 782784:tid 782982] [client 20.215.191.139:32173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuN3IaApLsOvtuGcVq0SQAAAEQ"]
[Thu Jul 30 12:46:04.492796 2026] [security2:error] [pid 782784:tid 783011] [client 68.221.186.136:26695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/bala.php"] [unique_id "amuN3IaApLsOvtuGcVq0SgAAAGE"]
[Thu Jul 30 12:46:04.666867 2026] [security2:error] [pid 782784:tid 782995] [client 68.65.223.55:35067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuN3IaApLsOvtuGcVq0TgAAUVo"]
[Thu Jul 30 12:46:05.200006 2026] [security2:error] [pid 782784:tid 783029] [client 52.238.199.152:22687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuN3YaApLsOvtuGcVq0XwAAAHM"]
[Thu Jul 30 12:46:05.302591 2026] [security2:error] [pid 782784:tid 782951] [client 20.203.148.31:32695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuN3YaApLsOvtuGcVq0YwAAACU"]
[Thu Jul 30 12:46:05.462637 2026] [security2:error] [pid 782784:tid 782983] [client 68.221.186.136:45450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/bk.php"] [unique_id "amuN3YaApLsOvtuGcVq0agAAAEU"]
[Thu Jul 30 12:46:05.483454 2026] [security2:error] [pid 782784:tid 782985] [client 20.215.191.139:14565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuN3YaApLsOvtuGcVq0awAAAEc"]
[Thu Jul 30 12:46:05.541856 2026] [security2:error] [pid 782784:tid 782915] [client 136.70.106.31:59296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fireworkskenya.co.ke"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuN3YaApLsOvtuGcVq0bAAAAAE"]
[Thu Jul 30 12:46:05.855912 2026] [security2:error] [pid 782784:tid 782869] [remote 45.146.192.214:31092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.192.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuN3YaApLsOvtuGcVq0dwAAM1Q"]
[Thu Jul 30 12:46:06.200754 2026] [core:error] [pid 782784:tid 782861] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:06.200775 2026] [core:error] [pid 782784:tid 782861] [remote 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:06.203849 2026] [security2:error] [pid 782784:tid 782960] [client 68.221.186.136:42747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/ahax.php"] [unique_id "amuN3oaApLsOvtuGcVq0jAAAAC4"]
[Thu Jul 30 12:46:06.211416 2026] [security2:error] [pid 782784:tid 782922] [client 52.238.199.152:61969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/manager.php"] [unique_id "amuN3oaApLsOvtuGcVq0jQAAAAg"]
[Thu Jul 30 12:46:06.778939 2026] [security2:error] [pid 782784:tid 782966] [client 20.215.191.139:14579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuN3oaApLsOvtuGcVq0wwAAADQ"]
[Thu Jul 30 12:46:06.822345 2026] [security2:error] [pid 782784:tid 782932] [client 20.203.148.31:32650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuN3oaApLsOvtuGcVq0xAAAABI"]
[Thu Jul 30 12:46:07.015833 2026] [security2:error] [pid 782784:tid 782958] [client 38.190.144.4:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuN34aApLsOvtuGcVq0yQAAACw"]
[Thu Jul 30 12:46:07.015991 2026] [security2:error] [pid 782784:tid 782958] [client 38.190.144.4:64047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuN34aApLsOvtuGcVq0yQAAACw"]
[Thu Jul 30 12:46:07.055193 2026] [security2:error] [pid 782784:tid 783038] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuN3oaApLsOvtuGcVq0tAAAfEQ"]
[Thu Jul 30 12:46:07.174880 2026] [security2:error] [pid 782784:tid 782964] [client 136.70.106.31:61812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.106.70.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuN3oaApLsOvtuGcVq0uwAAADI"]
[Thu Jul 30 12:46:08.635972 2026] [security2:error] [pid 782784:tid 782956] [client 20.215.191.139:30568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuN4IaApLsOvtuGcVq1AQAAACo"]
[Thu Jul 30 12:46:08.643454 2026] [security2:error] [pid 782784:tid 782931] [client 52.238.199.152:43876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-links.php"] [unique_id "amuN4IaApLsOvtuGcVq1AgAAABE"]
[Thu Jul 30 12:46:09.006651 2026] [core:notice] [pid 782784:tid 782914] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:09.010700 2026] [security2:error] [pid 782784:tid 782914] [client 103.215.74.26:25160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN4YaApLsOvtuGcVq1DAAAAAA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:09.349651 2026] [security2:error] [pid 782784:tid 783015] [client 20.203.148.31:40694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuN4YaApLsOvtuGcVq1FwAAAGU"]
[Thu Jul 30 12:46:09.738107 2026] [core:notice] [pid 782784:tid 782941] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:09.742873 2026] [security2:error] [pid 782784:tid 782941] [client 103.215.74.26:25162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN4YaApLsOvtuGcVq1OAAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:10.055633 2026] [security2:error] [pid 782784:tid 782986] [client 20.215.191.139:25486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuN4oaApLsOvtuGcVq1QwAAAEg"]
[Thu Jul 30 12:46:10.134658 2026] [security2:error] [pid 782784:tid 783024] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuN4YaApLsOvtuGcVq1OQAAbhk"]
[Thu Jul 30 12:46:10.159033 2026] [security2:error] [pid 782784:tid 782963] [client 20.203.148.31:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuN4oaApLsOvtuGcVq1SAAAADE"]
[Thu Jul 30 12:46:10.472128 2026] [core:notice] [pid 782784:tid 782960] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:10.476438 2026] [security2:error] [pid 782784:tid 782960] [client 103.215.74.26:25178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN4oaApLsOvtuGcVq1WwAAAC4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:10.656532 2026] [security2:error] [pid 782784:tid 782953] [client 41.210.143.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuN4oaApLsOvtuGcVq1QgAAJwM"], referer: https://flixon.net/free-movies/
[Thu Jul 30 12:46:11.202277 2026] [security2:error] [pid 782784:tid 783010] [client 52.238.199.152:23135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/fi2.php"] [unique_id "amuN44aApLsOvtuGcVq1bQAAAGA"]
[Thu Jul 30 12:46:11.215435 2026] [core:notice] [pid 782784:tid 782999] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:11.219620 2026] [security2:error] [pid 782784:tid 782999] [client 103.215.74.26:25182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN44aApLsOvtuGcVq1bgAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:11.662132 2026] [security2:error] [pid 782784:tid 783039] [client 20.203.148.31:33072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuN44aApLsOvtuGcVq1fAAAAH0"]
[Thu Jul 30 12:46:11.956170 2026] [core:notice] [pid 782784:tid 782919] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:11.960972 2026] [security2:error] [pid 782784:tid 782919] [client 103.215.74.26:25198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN44aApLsOvtuGcVq1gQAAAAU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:12.006795 2026] [security2:error] [pid 782784:tid 782985] [client 20.215.191.139:30545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuN5IaApLsOvtuGcVq1hQAAAEc"]
[Thu Jul 30 12:46:12.323260 2026] [security2:error] [pid 782784:tid 783036] [client 50.6.43.217:35086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuN44aApLsOvtuGcVq1dwAAAHo"]
[Thu Jul 30 12:46:12.501132 2026] [security2:error] [pid 782784:tid 783040] [client 52.238.199.152:43877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/0x.php"] [unique_id "amuN5IaApLsOvtuGcVq1kQAAAH4"]
[Thu Jul 30 12:46:13.044412 2026] [security2:error] [pid 782784:tid 783025] [client 50.6.43.217:35096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuN5IaApLsOvtuGcVq1igAAAG8"]
[Thu Jul 30 12:46:13.150826 2026] [security2:error] [pid 782784:tid 782992] [client 136.70.106.31:56557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.106.70.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuN5YaApLsOvtuGcVq1owAAAE4"]
[Thu Jul 30 12:46:13.150954 2026] [security2:error] [pid 782784:tid 782992] [client 136.70.106.31:56557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuN5YaApLsOvtuGcVq1owAAAE4"]
[Thu Jul 30 12:46:13.195864 2026] [security2:error] [pid 782784:tid 782928] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuN5IaApLsOvtuGcVq1lgAAAA4"]
[Thu Jul 30 12:46:13.584267 2026] [security2:error] [pid 782784:tid 782954] [client 20.203.148.31:29687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuN5YaApLsOvtuGcVq1uAAAACg"]
[Thu Jul 30 12:46:14.265150 2026] [security2:error] [pid 782784:tid 782926] [client 136.70.106.31:49467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.106.70.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuN5oaApLsOvtuGcVq1xgAAAAw"]
[Thu Jul 30 12:46:14.265278 2026] [security2:error] [pid 782784:tid 782926] [client 136.70.106.31:49467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuN5oaApLsOvtuGcVq1xgAAAAw"]
[Thu Jul 30 12:46:14.272099 2026] [security2:error] [pid 782784:tid 782936] [client 20.203.148.31:12182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuN5oaApLsOvtuGcVq1xwAAABY"]
[Thu Jul 30 12:46:14.644120 2026] [core:error] [pid 782784:tid 782956] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.644145 2026] [core:error] [pid 782784:tid 782956] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.653858 2026] [core:error] [pid 782784:tid 782992] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.653892 2026] [core:error] [pid 782784:tid 782992] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.654056 2026] [core:error] [pid 782784:tid 782966] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.654070 2026] [core:error] [pid 782784:tid 782966] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.656286 2026] [core:error] [pid 782784:tid 782928] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.656307 2026] [core:error] [pid 782784:tid 782928] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.675462 2026] [security2:error] [pid 782784:tid 782997] [client 150.107.232.194:27443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN5oaApLsOvtuGcVq15gAAAFM"]
[Thu Jul 30 12:46:14.675544 2026] [security2:error] [pid 782784:tid 782997] [client 150.107.232.194:27443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN5oaApLsOvtuGcVq15gAAAFM"]
[Thu Jul 30 12:46:14.680847 2026] [core:error] [pid 782784:tid 783038] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.680861 2026] [core:error] [pid 782784:tid 783038] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:14.775273 2026] [security2:error] [pid 782784:tid 782914] [client 20.215.191.139:13866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuN5oaApLsOvtuGcVq16gAAAAA"]
[Thu Jul 30 12:46:14.972653 2026] [security2:error] [pid 782784:tid 783023] [client 52.238.199.152:62010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/k.php"] [unique_id "amuN5oaApLsOvtuGcVq17gAAAG0"]
[Thu Jul 30 12:46:15.265950 2026] [security2:error] [pid 782784:tid 782976] [client 136.70.106.31:49779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.106.70.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuN54aApLsOvtuGcVq19QAAAD4"]
[Thu Jul 30 12:46:15.266155 2026] [security2:error] [pid 782784:tid 782976] [client 136.70.106.31:49779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuN54aApLsOvtuGcVq19QAAAD4"]
[Thu Jul 30 12:46:15.536045 2026] [security2:error] [pid 782784:tid 782973] [client 20.203.148.31:33078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuN54aApLsOvtuGcVq2AwAAADs"]
[Thu Jul 30 12:46:16.247258 2026] [security2:error] [pid 782784:tid 782945] [client 52.238.199.152:61974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/gecko-new.php"] [unique_id "amuN6IaApLsOvtuGcVq2FgAAAB8"]
[Thu Jul 30 12:46:16.523882 2026] [security2:error] [pid 782784:tid 783040] [client 217.138.252.123:49726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.252.138.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuN6IaApLsOvtuGcVq2HQAAAH4"]
[Thu Jul 30 12:46:16.524017 2026] [security2:error] [pid 782784:tid 783040] [client 217.138.252.123:49726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuN6IaApLsOvtuGcVq2HQAAAH4"]
[Thu Jul 30 12:46:16.938271 2026] [security2:error] [pid 782784:tid 782922] [client 20.215.191.139:32937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuN6IaApLsOvtuGcVq2JAAAAAg"]
[Thu Jul 30 12:46:17.589535 2026] [security2:error] [pid 782784:tid 782999] [client 20.203.148.31:40670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuN6YaApLsOvtuGcVq2NAAAAFU"]
[Thu Jul 30 12:46:17.612330 2026] [fcgid:warn] [pid 782784:tid 782951] (70014)End of file found: [client 104.218.165.188:56636] mod_fcgid: can't get data from http client
[Thu Jul 30 12:46:17.685909 2026] [security2:error] [pid 782784:tid 782934] [client 38.190.144.4:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.144.190.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuN6YaApLsOvtuGcVq2NwAAABQ"]
[Thu Jul 30 12:46:17.686054 2026] [security2:error] [pid 782784:tid 782934] [client 38.190.144.4:64343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuN6YaApLsOvtuGcVq2NwAAABQ"]
[Thu Jul 30 12:46:17.754543 2026] [core:notice] [pid 782784:tid 782920] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:17.758745 2026] [security2:error] [pid 782784:tid 782920] [client 103.215.74.26:18474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN6YaApLsOvtuGcVq2PAAAAAY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:17.785902 2026] [security2:error] [pid 782784:tid 782914] [client 52.238.199.152:22694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/alfanew.php"] [unique_id "amuN6YaApLsOvtuGcVq2PQAAAAA"]
[Thu Jul 30 12:46:18.103376 2026] [security2:error] [pid 782784:tid 782955] [client 182.18.177.138:49484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuN6YaApLsOvtuGcVq2OwAAACk"], referer: http://pkf.jo
[Thu Jul 30 12:46:18.472823 2026] [security2:error] [pid 782784:tid 782995] [client 20.203.148.31:11387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuN6oaApLsOvtuGcVq2SgAAAFE"]
[Thu Jul 30 12:46:18.508759 2026] [core:notice] [pid 782784:tid 782929] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:18.513205 2026] [security2:error] [pid 782784:tid 782929] [client 103.215.74.26:18488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN6oaApLsOvtuGcVq2SwAAAA8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:19.412155 2026] [security2:error] [pid 782784:tid 782928] [client 20.203.148.31:11373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuN64aApLsOvtuGcVq2ZQAAAA4"]
[Thu Jul 30 12:46:19.768751 2026] [security2:error] [pid 782784:tid 782922] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuN64aApLsOvtuGcVq2XQAAAAg"]
[Thu Jul 30 12:46:19.832478 2026] [security2:error] [pid 782784:tid 782996] [client 80.234.78.123:2357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuN64aApLsOvtuGcVq2ZgAAAFI"], referer: http://pkf.jo
[Thu Jul 30 12:46:19.962654 2026] [security2:error] [pid 782784:tid 783000] [client 51.36.124.135:2207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuN64aApLsOvtuGcVq2bQAAAFY"], referer: http://pkf.jo
[Thu Jul 30 12:46:20.036749 2026] [security2:error] [pid 782784:tid 782914] [client 20.203.148.31:11338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuN7IaApLsOvtuGcVq2dAAAAAA"]
[Thu Jul 30 12:46:20.200636 2026] [security2:error] [pid 782784:tid 782989] [client 20.215.191.139:32575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuN7IaApLsOvtuGcVq2eAAAAEs"]
[Thu Jul 30 12:46:20.222557 2026] [core:error] [pid 782784:tid 782929] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.222577 2026] [core:error] [pid 782784:tid 782929] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.223101 2026] [core:error] [pid 782784:tid 782947] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.223116 2026] [core:error] [pid 782784:tid 782947] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.238924 2026] [core:error] [pid 782784:tid 782943] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.238943 2026] [core:error] [pid 782784:tid 782943] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.242851 2026] [core:error] [pid 782784:tid 783005] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.242867 2026] [core:error] [pid 782784:tid 783005] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.300736 2026] [core:error] [pid 782784:tid 783022] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.300755 2026] [core:error] [pid 782784:tid 783022] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:20.623816 2026] [security2:error] [pid 782784:tid 782921] [client 186.235.99.103:8524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuN7IaApLsOvtuGcVq2lwAAAAc"], referer: http://pkf.jo
[Thu Jul 30 12:46:20.869870 2026] [core:notice] [pid 782784:tid 783027] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:20.912514 2026] [security2:error] [pid 782784:tid 783023] [client 14.169.239.211:37780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuN7IaApLsOvtuGcVq2oQAAAG0"], referer: http://pkf.jo
[Thu Jul 30 12:46:21.004607 2026] [security2:error] [pid 782784:tid 782928] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuN7IaApLsOvtuGcVq2qAAADmA"]
[Thu Jul 30 12:46:21.430853 2026] [security2:error] [pid 782784:tid 782976] [client 20.215.191.139:43042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuN7YaApLsOvtuGcVq2xwAAAD4"]
[Thu Jul 30 12:46:21.462868 2026] [security2:error] [pid 782784:tid 782952] [client 20.203.148.31:11385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuN7YaApLsOvtuGcVq2yAAAACY"]
[Thu Jul 30 12:46:21.857915 2026] [security2:error] [pid 782784:tid 782977] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuN7YaApLsOvtuGcVq2wwAAAD8"]
[Thu Jul 30 12:46:21.915632 2026] [security2:error] [pid 782784:tid 782956] [client 52.238.199.152:22701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/text.php"] [unique_id "amuN7YaApLsOvtuGcVq21wAAACo"]
[Thu Jul 30 12:46:22.182619 2026] [security2:error] [pid 782784:tid 782930] [client 20.203.148.31:30326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuN7oaApLsOvtuGcVq22AAAABA"]
[Thu Jul 30 12:46:22.789339 2026] [security2:error] [pid 782784:tid 782991] [client 20.203.148.31:35883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuN7oaApLsOvtuGcVq26wAAAE0"]
[Thu Jul 30 12:46:23.191219 2026] [security2:error] [pid 782784:tid 783000] [client 52.238.199.152:22662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/f.php"] [unique_id "amuN74aApLsOvtuGcVq28gAAAFY"]
[Thu Jul 30 12:46:23.249797 2026] [proxy:error] [pid 782784:tid 783017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:23.249849 2026] [proxy_http:error] [pid 782784:tid 783017] [client 18.211.55.47:33508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:23.250441 2026] [proxy:error] [pid 782784:tid 783017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:23.250487 2026] [proxy_http:error] [pid 782784:tid 783017] [client 18.211.55.47:33508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:23.287597 2026] [proxy:error] [pid 782784:tid 783006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:23.287663 2026] [proxy_http:error] [pid 782784:tid 783006] [client 18.211.55.47:18871] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:23.288244 2026] [proxy:error] [pid 782784:tid 783006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:23.288291 2026] [proxy_http:error] [pid 782784:tid 783006] [client 18.211.55.47:18871] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:23.430563 2026] [security2:error] [pid 782784:tid 783013] [client 20.215.191.139:32536] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.mediaspawn.com"] [uri "/1.php"] [unique_id "amuN74aApLsOvtuGcVq3AgAAAGM"]
[Thu Jul 30 12:46:23.430666 2026] [security2:error] [pid 782784:tid 783013] [client 20.215.191.139:32536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/1.php"] [unique_id "amuN74aApLsOvtuGcVq3AgAAAGM"]
[Thu Jul 30 12:46:24.206244 2026] [security2:error] [pid 782784:tid 782963] [client 52.238.199.152:62028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuN8IaApLsOvtuGcVq3FAAAADE"]
[Thu Jul 30 12:46:24.246532 2026] [core:notice] [pid 782784:tid 782980] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:24.251001 2026] [security2:error] [pid 782784:tid 782980] [client 103.215.74.26:16258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN8IaApLsOvtuGcVq3FQAAAEI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:24.776110 2026] [security2:error] [pid 782784:tid 782951] [client 20.215.191.139:32135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/admin.php"] [unique_id "amuN8IaApLsOvtuGcVq3HwAAACU"]
[Thu Jul 30 12:46:24.967279 2026] [core:notice] [pid 782784:tid 783027] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:24.972525 2026] [security2:error] [pid 782784:tid 783027] [client 103.215.74.26:16270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN8IaApLsOvtuGcVq3IwAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:25.109309 2026] [security2:error] [pid 782784:tid 782817] [remote 57.141.0.36:34544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuN8YaApLsOvtuGcVq3KgAAdyA"]
[Thu Jul 30 12:46:25.142218 2026] [security2:error] [pid 782784:tid 782972] [client 150.107.232.194:27248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN8YaApLsOvtuGcVq3KwAAADo"]
[Thu Jul 30 12:46:25.142340 2026] [security2:error] [pid 782784:tid 782972] [client 150.107.232.194:27248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN8YaApLsOvtuGcVq3KwAAADo"]
[Thu Jul 30 12:46:25.257717 2026] [security2:error] [pid 782784:tid 783023] [client 52.238.199.152:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/hehe.php"] [unique_id "amuN8YaApLsOvtuGcVq3LAAAAG0"]
[Thu Jul 30 12:46:25.376947 2026] [security2:error] [pid 782784:tid 782943] [client 20.203.148.31:30325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuN8YaApLsOvtuGcVq3MQAAAB0"]
[Thu Jul 30 12:46:25.622596 2026] [security2:error] [pid 782784:tid 782973] [client 127.0.0.1:42512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuN8YaApLsOvtuGcVq3NwAAADs"]
[Thu Jul 30 12:46:25.622610 2026] [security2:error] [pid 782784:tid 782960] [client 127.0.0.1:42498] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.enf.gpl.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuN8YaApLsOvtuGcVq3NgAAAC4"]
[Thu Jul 30 12:46:25.622761 2026] [security2:error] [pid 782784:tid 783009] [client 74.7.230.22:34240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.enf.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuN8YaApLsOvtuGcVq3NQAAXzM"]
[Thu Jul 30 12:46:25.631707 2026] [security2:error] [pid 782784:tid 782979] [client 20.215.191.139:26442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/as.php"] [unique_id "amuN8YaApLsOvtuGcVq3OwAAAEE"]
[Thu Jul 30 12:46:25.689358 2026] [core:notice] [pid 782784:tid 783006] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:25.693751 2026] [security2:error] [pid 782784:tid 783006] [client 103.215.74.26:16282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN8YaApLsOvtuGcVq3PAAAAFw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:26.228095 2026] [security2:error] [pid 782784:tid 782997] [client 20.215.191.139:32548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/autoload_classmap.php"] [unique_id "amuN8oaApLsOvtuGcVq3TAAAAFM"]
[Thu Jul 30 12:46:26.418571 2026] [core:notice] [pid 782784:tid 782984] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:26.422931 2026] [security2:error] [pid 782784:tid 782984] [client 103.215.74.26:16292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN8oaApLsOvtuGcVq3TgAAAEY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:26.892045 2026] [security2:error] [pid 782784:tid 782993] [client 217.138.252.123:35306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.252.138.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuN8oaApLsOvtuGcVq3XQAAAE8"]
[Thu Jul 30 12:46:26.892186 2026] [security2:error] [pid 782784:tid 782993] [client 217.138.252.123:35306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuN8oaApLsOvtuGcVq3XQAAAE8"]
[Thu Jul 30 12:46:27.029136 2026] [security2:error] [pid 782784:tid 782915] [client 20.215.191.139:26474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/back.php"] [unique_id "amuN84aApLsOvtuGcVq3YgAAAAE"]
[Thu Jul 30 12:46:27.172581 2026] [core:notice] [pid 782784:tid 783003] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:27.176944 2026] [security2:error] [pid 782784:tid 783003] [client 103.215.74.26:16306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN84aApLsOvtuGcVq3ZgAAAFk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:27.206217 2026] [security2:error] [pid 782784:tid 783033] [client 93.183.94.195:64467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.183.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuN8oaApLsOvtuGcVq3YAAAAHc"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:46:27.206369 2026] [security2:error] [pid 782784:tid 783033] [client 93.183.94.195:64467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuN8oaApLsOvtuGcVq3YAAAAHc"], referer: http://deltaedu.net/2016/11/04/university-scholarship-2017/
[Thu Jul 30 12:46:27.368045 2026] [security2:error] [pid 782784:tid 782991] [client 185.129.62.62:55806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuN8oaApLsOvtuGcVq3XAAATSw"], referer: https://happyspree.app/feed
[Thu Jul 30 12:46:27.903863 2026] [core:notice] [pid 782784:tid 783013] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:27.908261 2026] [security2:error] [pid 782784:tid 783013] [client 103.215.74.26:16314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN84aApLsOvtuGcVq3dQAAAGM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:28.085428 2026] [security2:error] [pid 782784:tid 782972] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuN84aApLsOvtuGcVq3agAAOhs"]
[Thu Jul 30 12:46:28.383505 2026] [security2:error] [pid 782784:tid 782921] [client 86.106.84.166:56872] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuN9IaApLsOvtuGcVq3hgAAAAc"]
[Thu Jul 30 12:46:28.383618 2026] [security2:error] [pid 782784:tid 782921] [client 86.106.84.166:56872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuN9IaApLsOvtuGcVq3hgAAAAc"]
[Thu Jul 30 12:46:28.663189 2026] [core:notice] [pid 782784:tid 782940] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:28.667561 2026] [security2:error] [pid 782784:tid 782940] [client 103.215.74.26:16320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN9IaApLsOvtuGcVq3jgAAABo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:29.113343 2026] [autoindex:error] [pid 782784:tid 782844] [remote 172.232.181.206:39726] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:46:29.251657 2026] [security2:error] [pid 782784:tid 782968] [client 20.215.191.139:31335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuN9YaApLsOvtuGcVq3oAAAADY"]
[Thu Jul 30 12:46:29.275865 2026] [security2:error] [pid 782784:tid 783041] [client 52.238.199.152:22688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/options.php"] [unique_id "amuN9YaApLsOvtuGcVq3oQAAAH8"]
[Thu Jul 30 12:46:29.395092 2026] [core:notice] [pid 782784:tid 783028] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:29.399146 2026] [security2:error] [pid 782784:tid 783028] [client 103.215.74.26:16330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN9YaApLsOvtuGcVq3owAAAHI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:29.439530 2026] [security2:error] [pid 782784:tid 782950] [client 49.51.178.45:52298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "montageluxuryhotel.com"] [uri "/index.php"] [unique_id "amuN9IaApLsOvtuGcVq3hQAAACQ"]
[Thu Jul 30 12:46:29.949599 2026] [security2:error] [pid 782784:tid 782947] [client 20.215.191.139:33523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/c/flower.php"] [unique_id "amuN9YaApLsOvtuGcVq3sQAAACE"]
[Thu Jul 30 12:46:30.113097 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:30.116849 2026] [security2:error] [pid 782784:tid 782952] [client 103.215.74.26:16338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN9oaApLsOvtuGcVq3sgAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:30.811423 2026] [security2:error] [pid 782784:tid 782972] [client 77.83.36.161:47597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuN9oaApLsOvtuGcVq3vwAAADo"]
[Thu Jul 30 12:46:30.974684 2026] [security2:error] [pid 782784:tid 783031] [client 20.215.191.139:32939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/c/xleet.php"] [unique_id "amuN9oaApLsOvtuGcVq3zQAAAHU"]
[Thu Jul 30 12:46:31.359938 2026] [security2:error] [pid 782784:tid 782992] [client 77.83.36.161:48035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuN94aApLsOvtuGcVq31gAAAE4"]
[Thu Jul 30 12:46:31.565597 2026] [security2:error] [pid 782784:tid 782890] [remote 74.7.241.60:53904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amuN94aApLsOvtuGcVq32wAARGk"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 12:46:31.766641 2026] [security2:error] [pid 782784:tid 782962] [client 20.215.191.139:26436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/classwithtostring.php"] [unique_id "amuN94aApLsOvtuGcVq34gAAADA"]
[Thu Jul 30 12:46:31.988505 2026] [security2:error] [pid 782784:tid 782950] [client 77.83.36.161:48337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuN94aApLsOvtuGcVq36wAAACQ"]
[Thu Jul 30 12:46:31.995829 2026] [security2:error] [pid 782784:tid 783028] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuN94aApLsOvtuGcVq33AAAcgo"]
[Thu Jul 30 12:46:32.133098 2026] [security2:error] [pid 782784:tid 782974] [client 185.129.62.62:55408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuN94aApLsOvtuGcVq35QAAPFk"], referer: https://happyspree.app/password-reset
[Thu Jul 30 12:46:32.354123 2026] [security2:error] [pid 782784:tid 783015] [client 165.154.162.193:56876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.luf.owl.temporary.site"] [uri "/index.php"] [unique_id "amuN-IaApLsOvtuGcVq37AAAAGU"]
[Thu Jul 30 12:46:33.190784 2026] [security2:error] [pid 782784:tid 782924] [client 20.203.148.31:30335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuN-YaApLsOvtuGcVq4AwAAAAo"]
[Thu Jul 30 12:46:33.860500 2026] [security2:error] [pid 782784:tid 783037] [client 20.215.191.139:33483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/content.php"] [unique_id "amuN-YaApLsOvtuGcVq4EAAAAHs"]
[Thu Jul 30 12:46:33.924360 2026] [security2:error] [pid 782784:tid 782985] [client 20.100.187.246:48891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/011i.php"] [unique_id "amuN-YaApLsOvtuGcVq4FAAAAEc"]
[Thu Jul 30 12:46:33.933092 2026] [security2:error] [pid 782784:tid 783000] [client 20.203.148.31:30332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuN-YaApLsOvtuGcVq4FQAAAFY"]
[Thu Jul 30 12:46:34.363187 2026] [security2:error] [pid 782784:tid 783035] [client 52.238.199.152:61960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuN-oaApLsOvtuGcVq4HQAAAHk"]
[Thu Jul 30 12:46:34.649326 2026] [security2:error] [pid 782784:tid 782952] [client 185.129.62.62:55416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuN-oaApLsOvtuGcVq4HgAAJnM"], referer: https://happyspree.app/privacy-policy
[Thu Jul 30 12:46:34.934517 2026] [security2:error] [pid 782784:tid 782955] [client 20.215.191.139:32534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/doc.php"] [unique_id "amuN-oaApLsOvtuGcVq4MwAAACk"]
[Thu Jul 30 12:46:35.261964 2026] [security2:error] [pid 782784:tid 782984] [client 52.238.199.152:49752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/images/index.php"] [unique_id "amuN-4aApLsOvtuGcVq4OwAAAEY"]
[Thu Jul 30 12:46:35.623928 2026] [security2:error] [pid 782784:tid 782929] [client 150.107.232.194:26573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN-4aApLsOvtuGcVq4QwAAAA8"]
[Thu Jul 30 12:46:35.624074 2026] [security2:error] [pid 782784:tid 782929] [client 150.107.232.194:26573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuN-4aApLsOvtuGcVq4QwAAAA8"]
[Thu Jul 30 12:46:35.753498 2026] [security2:error] [pid 782784:tid 783024] [client 20.215.191.139:29609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/dropdown.php"] [unique_id "amuN-4aApLsOvtuGcVq4RwAAAG4"]
[Thu Jul 30 12:46:35.897381 2026] [core:notice] [pid 782784:tid 782936] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:35.901565 2026] [security2:error] [pid 782784:tid 782936] [client 103.215.74.26:12386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN-4aApLsOvtuGcVq4SAAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:36.636465 2026] [core:notice] [pid 782784:tid 783018] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:36.640991 2026] [security2:error] [pid 782784:tid 783018] [client 103.215.74.26:12396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN_IaApLsOvtuGcVq4XgAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:36.764022 2026] [security2:error] [pid 782784:tid 783022] [client 165.154.162.193:43542] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.luf.owl.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amuN_IaApLsOvtuGcVq4YwAAAGw"]
[Thu Jul 30 12:46:36.776963 2026] [security2:error] [pid 782784:tid 782786] [remote 216.73.216.152:23614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuN_IaApLsOvtuGcVq4ZgAADQE"]
[Thu Jul 30 12:46:37.178743 2026] [security2:error] [pid 782784:tid 783014] [client 20.203.148.31:28988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuN_YaApLsOvtuGcVq4cAAAAGQ"]
[Thu Jul 30 12:46:37.371488 2026] [core:notice] [pid 782784:tid 783029] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:37.378023 2026] [security2:error] [pid 782784:tid 783029] [client 103.215.74.26:12410] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN_YaApLsOvtuGcVq4dAAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:37.638056 2026] [security2:error] [pid 782784:tid 782925] [client 20.100.187.246:30430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/03a005685d.php"] [unique_id "amuN_YaApLsOvtuGcVq4eAAAAAs"]
[Thu Jul 30 12:46:37.648267 2026] [security2:error] [pid 782784:tid 782949] [client 20.215.191.139:23213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/ee.php"] [unique_id "amuN_YaApLsOvtuGcVq4eQAAACM"]
[Thu Jul 30 12:46:38.105104 2026] [core:notice] [pid 782784:tid 782947] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:38.111966 2026] [security2:error] [pid 782784:tid 782947] [client 103.215.74.26:12420] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN_oaApLsOvtuGcVq4gwAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:38.474056 2026] [security2:error] [pid 782784:tid 782950] [client 20.100.187.246:48878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/403.php"] [unique_id "amuN_oaApLsOvtuGcVq4igAAACQ"]
[Thu Jul 30 12:46:38.844043 2026] [core:notice] [pid 782784:tid 782935] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:38.847971 2026] [security2:error] [pid 782784:tid 782935] [client 103.215.74.26:12432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN_oaApLsOvtuGcVq4lwAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:38.898193 2026] [security2:error] [pid 782784:tid 782938] [client 20.203.148.31:11288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuN_oaApLsOvtuGcVq4mAAAABg"]
[Thu Jul 30 12:46:39.022269 2026] [proxy:error] [pid 782784:tid 782997] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:39.022357 2026] [proxy_http:error] [pid 782784:tid 782997] [client 143.244.57.82:39702] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:39.022918 2026] [proxy:error] [pid 782784:tid 782997] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:39.022960 2026] [proxy_http:error] [pid 782784:tid 782997] [client 143.244.57.82:39702] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:39.306379 2026] [proxy:error] [pid 782784:tid 782984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:39.306452 2026] [proxy_http:error] [pid 782784:tid 782984] [client 143.244.57.82:39708] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:39.307050 2026] [proxy:error] [pid 782784:tid 782984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:39.307102 2026] [proxy_http:error] [pid 782784:tid 782984] [client 143.244.57.82:39708] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:39.389213 2026] [security2:error] [pid 782784:tid 782977] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuN_oaApLsOvtuGcVq4kwAAAD8"]
[Thu Jul 30 12:46:39.500518 2026] [security2:error] [pid 782784:tid 782855] [remote 119.73.97.132:29963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuN_4aApLsOvtuGcVq4oQAAEkY"]
[Thu Jul 30 12:46:39.572743 2026] [core:notice] [pid 782784:tid 782933] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:39.576629 2026] [security2:error] [pid 782784:tid 782933] [client 103.215.74.26:12448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuN_4aApLsOvtuGcVq4qQAAABM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:39.588596 2026] [security2:error] [pid 782784:tid 782915] [client 143.244.57.82:39718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuN_4aApLsOvtuGcVq4rQAAAAE"]
[Thu Jul 30 12:46:39.884411 2026] [security2:error] [pid 782784:tid 782963] [client 143.244.57.82:39724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuN_4aApLsOvtuGcVq4sQAAADE"]
[Thu Jul 30 12:46:40.008212 2026] [security2:error] [pid 782784:tid 782924] [client 20.100.187.246:48895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/404.php"] [unique_id "amuOAIaApLsOvtuGcVq4tgAAAAo"]
[Thu Jul 30 12:46:40.182201 2026] [proxy:error] [pid 782784:tid 783035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:40.182284 2026] [proxy_http:error] [pid 782784:tid 783035] [client 143.244.57.82:39734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:40.182849 2026] [proxy:error] [pid 782784:tid 783035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:46:40.182893 2026] [proxy_http:error] [pid 782784:tid 783035] [client 143.244.57.82:39734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:46:40.304965 2026] [core:notice] [pid 782784:tid 783030] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:40.311643 2026] [security2:error] [pid 782784:tid 783030] [client 103.215.74.26:12464] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOAIaApLsOvtuGcVq4vAAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:40.471937 2026] [security2:error] [pid 782784:tid 783040] [client 143.244.57.82:39740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuOAIaApLsOvtuGcVq4xgAAAH4"]
[Thu Jul 30 12:46:40.612082 2026] [security2:error] [pid 782784:tid 782917] [client 20.215.191.139:26045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/flower.php"] [unique_id "amuOAIaApLsOvtuGcVq4yAAAAAM"]
[Thu Jul 30 12:46:40.759431 2026] [security2:error] [pid 782784:tid 782921] [client 143.244.57.82:39752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuOAIaApLsOvtuGcVq4zAAAAAc"]
[Thu Jul 30 12:46:40.991282 2026] [security2:error] [pid 782784:tid 783026] [client 20.100.187.246:55934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/aa.php"] [unique_id "amuOAIaApLsOvtuGcVq40wAAAHA"]
[Thu Jul 30 12:46:41.043762 2026] [security2:error] [pid 782784:tid 782953] [client 143.244.57.82:53185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuOAYaApLsOvtuGcVq41AAAACc"]
[Thu Jul 30 12:46:41.092502 2026] [core:notice] [pid 782784:tid 782916] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:41.099251 2026] [security2:error] [pid 782784:tid 782916] [client 103.215.74.26:12478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOAYaApLsOvtuGcVq41QAAAAI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:41.329202 2026] [security2:error] [pid 782784:tid 782820] [remote 216.73.216.152:23614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuOAYaApLsOvtuGcVq42gAAEyM"]
[Thu Jul 30 12:46:41.359928 2026] [security2:error] [pid 782784:tid 783029] [client 143.244.57.82:39772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuOAYaApLsOvtuGcVq42wAAAHM"]
[Thu Jul 30 12:46:41.459318 2026] [security2:error] [pid 782784:tid 783041] [client 190.2.142.78:27008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ampcloudku.com"] [uri "/wp-login.php"] [unique_id "amuOAYaApLsOvtuGcVq43wAAAH8"]
[Thu Jul 30 12:46:41.476907 2026] [security2:error] [pid 782784:tid 782992] [client 20.215.191.139:37295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/gecko-new.php"] [unique_id "amuOAYaApLsOvtuGcVq44QAAAE4"]
[Thu Jul 30 12:46:41.520939 2026] [security2:error] [pid 782784:tid 782999] [client 127.0.0.1:46162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuOAYaApLsOvtuGcVq45gAAAFU"]
[Thu Jul 30 12:46:41.521058 2026] [security2:error] [pid 782784:tid 782957] [client 74.7.244.53:39798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tlt.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuOAYaApLsOvtuGcVq45QAAKyI"]
[Thu Jul 30 12:46:41.639607 2026] [security2:error] [pid 782784:tid 782936] [client 143.244.57.82:39774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuOAYaApLsOvtuGcVq46gAAABY"]
[Thu Jul 30 12:46:41.823078 2026] [core:notice] [pid 782784:tid 783036] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:41.826998 2026] [security2:error] [pid 782784:tid 783036] [client 103.215.74.26:12484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOAYaApLsOvtuGcVq47gAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:41.835062 2026] [security2:error] [pid 782784:tid 783020] [client 20.100.187.246:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/aafewc0k.php"] [unique_id "amuOAYaApLsOvtuGcVq47wAAAGo"]
[Thu Jul 30 12:46:41.923780 2026] [security2:error] [pid 782784:tid 783016] [client 20.203.148.31:12002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuOAYaApLsOvtuGcVq46wAAAGY"]
[Thu Jul 30 12:46:41.928893 2026] [security2:error] [pid 782784:tid 782990] [client 143.244.57.82:39780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuOAYaApLsOvtuGcVq48wAAAEw"]
[Thu Jul 30 12:46:41.977082 2026] [core:error] [pid 782784:tid 782950] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:41.977108 2026] [core:error] [pid 782784:tid 782950] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:41.981075 2026] [core:error] [pid 782784:tid 783019] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:41.981107 2026] [core:error] [pid 782784:tid 783019] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:41.987037 2026] [core:error] [pid 782784:tid 782956] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:41.987054 2026] [core:error] [pid 782784:tid 782956] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:42.040494 2026] [core:error] [pid 782784:tid 782981] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:42.040518 2026] [core:error] [pid 782784:tid 782981] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:42.059088 2026] [core:error] [pid 782784:tid 782935] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:42.059107 2026] [core:error] [pid 782784:tid 782935] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:42.071967 2026] [security2:error] [pid 782784:tid 783035] [client 20.215.191.139:37261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/m.php"] [unique_id "amuOAoaApLsOvtuGcVq5CQAAAHk"]
[Thu Jul 30 12:46:42.231008 2026] [security2:error] [pid 782784:tid 782931] [client 143.244.57.82:39784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuOAoaApLsOvtuGcVq5DgAAABE"]
[Thu Jul 30 12:46:42.461143 2026] [security2:error] [pid 782784:tid 782812] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOAoaApLsOvtuGcVq5FAAAARs"]
[Thu Jul 30 12:46:42.461335 2026] [security2:error] [pid 782784:tid 782915] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOAoaApLsOvtuGcVq5FAAAARs"]
[Thu Jul 30 12:46:42.512190 2026] [security2:error] [pid 782784:tid 783041] [client 143.244.57.82:39786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuOAoaApLsOvtuGcVq5FgAAAH8"]
[Thu Jul 30 12:46:42.555671 2026] [core:notice] [pid 782784:tid 782922] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:42.560788 2026] [security2:error] [pid 782784:tid 782922] [client 103.215.74.26:12496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "754"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOAoaApLsOvtuGcVq5FwAAAAg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:42.795762 2026] [security2:error] [pid 782784:tid 782973] [client 143.244.57.82:39792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuOAoaApLsOvtuGcVq5HwAAADs"]
[Thu Jul 30 12:46:43.083043 2026] [security2:error] [pid 782784:tid 782950] [client 143.244.57.82:39808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuOA4aApLsOvtuGcVq5JgAAACQ"]
[Thu Jul 30 12:46:43.098029 2026] [security2:error] [pid 782784:tid 782937] [client 20.100.187.246:59667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/abcd.php"] [unique_id "amuOA4aApLsOvtuGcVq5JwAAABc"]
[Thu Jul 30 12:46:43.293548 2026] [core:notice] [pid 782784:tid 783025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:43.297380 2026] [security2:error] [pid 782784:tid 783025] [client 103.215.74.26:31226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOA4aApLsOvtuGcVq5KwAAAG8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:43.366669 2026] [security2:error] [pid 782784:tid 783023] [client 143.244.57.82:39824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuOA4aApLsOvtuGcVq5LAAAAG0"]
[Thu Jul 30 12:46:43.679099 2026] [security2:error] [pid 782784:tid 782981] [client 143.244.57.82:39840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuOA4aApLsOvtuGcVq5MwAAAEM"]
[Thu Jul 30 12:46:43.714918 2026] [security2:error] [pid 782784:tid 783040] [client 20.215.191.139:31314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuOA4aApLsOvtuGcVq5NAAAAH4"]
[Thu Jul 30 12:46:43.961570 2026] [security2:error] [pid 782784:tid 782927] [client 143.244.57.82:39842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuOA4aApLsOvtuGcVq5OAAAAA0"]
[Thu Jul 30 12:46:44.025473 2026] [core:notice] [pid 782784:tid 782921] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:44.029722 2026] [security2:error] [pid 782784:tid 782921] [client 103.215.74.26:31240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOBIaApLsOvtuGcVq5PAAAAAc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:44.073294 2026] [core:error] [pid 782784:tid 783027] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.073319 2026] [core:error] [pid 782784:tid 783027] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.092734 2026] [core:error] [pid 782784:tid 782968] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.092759 2026] [core:error] [pid 782784:tid 782968] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.104433 2026] [core:error] [pid 782784:tid 782918] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.104453 2026] [core:error] [pid 782784:tid 782918] [client 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.140540 2026] [core:error] [pid 782784:tid 782962] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.140563 2026] [core:error] [pid 782784:tid 782962] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.149338 2026] [core:error] [pid 782784:tid 782957] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.149356 2026] [core:error] [pid 782784:tid 782957] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:44.252456 2026] [security2:error] [pid 782784:tid 782929] [client 143.244.57.82:39854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuOBIaApLsOvtuGcVq5WAAAAA8"]
[Thu Jul 30 12:46:44.404777 2026] [security2:error] [pid 782784:tid 782944] [client 20.215.191.139:26038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/mah/flower.php"] [unique_id "amuOBIaApLsOvtuGcVq5XAAAAB4"]
[Thu Jul 30 12:46:44.526416 2026] [security2:error] [pid 782784:tid 783013] [client 143.244.57.82:39856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.xzd.nyx.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuOBIaApLsOvtuGcVq5XQAAAGM"]
[Thu Jul 30 12:46:44.598369 2026] [security2:error] [pid 782784:tid 782923] [client 20.100.187.246:30413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/about.php"] [unique_id "amuOBIaApLsOvtuGcVq5YgAAAAk"]
[Thu Jul 30 12:46:44.757500 2026] [core:notice] [pid 782784:tid 782990] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:44.761506 2026] [security2:error] [pid 782784:tid 782990] [client 103.215.74.26:31248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOBIaApLsOvtuGcVq5YwAAAEw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:45.168587 2026] [security2:error] [pid 782784:tid 782925] [client 20.215.191.139:41876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/mah/xleet.php"] [unique_id "amuOBYaApLsOvtuGcVq5bQAAAAs"]
[Thu Jul 30 12:46:45.481206 2026] [security2:error] [pid 782784:tid 782935] [client 20.100.187.246:55887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/admin.php"] [unique_id "amuOBYaApLsOvtuGcVq5eAAAABU"]
[Thu Jul 30 12:46:45.486987 2026] [core:notice] [pid 782784:tid 783018] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:45.494163 2026] [security2:error] [pid 782784:tid 783018] [client 103.215.74.26:31264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOBYaApLsOvtuGcVq5eQAAAGg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:45.968228 2026] [security2:error] [pid 782784:tid 782927] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOBYaApLsOvtuGcVq5dAAAAA0"]
[Thu Jul 30 12:46:46.037509 2026] [autoindex:error] [pid 782784:tid 783001] [client 54.87.222.253:65011] AH01276: Cannot serve directory /home2/tgvgzjte/public_html/website_65bcc734/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:46:46.037650 2026] [fcgid:warn] [pid 782784:tid 782997] (70014)End of file found: [client 18.218.118.203:47824] mod_fcgid: can't get data from http client
[Thu Jul 30 12:46:46.085371 2026] [security2:error] [pid 782784:tid 783024] [client 150.107.232.194:27320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOBoaApLsOvtuGcVq5hwAAAG4"]
[Thu Jul 30 12:46:46.085486 2026] [security2:error] [pid 782784:tid 783024] [client 150.107.232.194:27320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOBoaApLsOvtuGcVq5hwAAAG4"]
[Thu Jul 30 12:46:46.245394 2026] [core:notice] [pid 782784:tid 782992] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:46.249745 2026] [security2:error] [pid 782784:tid 782992] [client 103.215.74.26:31272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOBoaApLsOvtuGcVq5kQAAAE4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:46.643736 2026] [security2:error] [pid 782784:tid 782933] [client 20.215.191.139:31339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/mini.php"] [unique_id "amuOBoaApLsOvtuGcVq5mwAAABM"]
[Thu Jul 30 12:46:46.703860 2026] [security2:error] [pid 782784:tid 782982] [client 136.114.127.127:33874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ai-kr.com.meg.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuOBoaApLsOvtuGcVq5ngAAAEQ"]
[Thu Jul 30 12:46:46.711658 2026] [security2:error] [pid 782784:tid 782922] [client 136.114.127.127:33864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "ai-kr.com"] [uri "/cgi-sys/404.html"] [unique_id "amuOBoaApLsOvtuGcVq5nwAAAAg"]
[Thu Jul 30 12:46:46.729841 2026] [core:error] [pid 782784:tid 782995] [client 190.2.142.78:6612] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:46.729860 2026] [core:error] [pid 782784:tid 782995] [client 190.2.142.78:6612] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:46.850906 2026] [security2:error] [pid 782784:tid 782975] [client 20.104.18.253:22317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/011i.php"] [unique_id "amuOBoaApLsOvtuGcVq5pAAAAD0"]
[Thu Jul 30 12:46:46.976505 2026] [core:notice] [pid 782784:tid 783010] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:46.983876 2026] [security2:error] [pid 782784:tid 783010] [client 103.215.74.26:31276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOBoaApLsOvtuGcVq5qwAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:47.024557 2026] [autoindex:error] [pid 782784:tid 783039] [client 190.2.142.78:6620] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:46:47.432718 2026] [security2:error] [pid 782784:tid 783027] [client 20.215.191.139:26028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/moon.php"] [unique_id "amuOB4aApLsOvtuGcVq5tAAAAHE"]
[Thu Jul 30 12:46:47.573411 2026] [security2:error] [pid 782784:tid 783012] [client 20.104.18.253:22290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/03a005685d.php"] [unique_id "amuOB4aApLsOvtuGcVq5uAAAAGI"]
[Thu Jul 30 12:46:47.706165 2026] [core:notice] [pid 782784:tid 783014] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:47.710568 2026] [security2:error] [pid 782784:tid 783014] [client 103.215.74.26:31288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOB4aApLsOvtuGcVq5vAAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:47.752073 2026] [core:notice] [pid 782784:tid 782991] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:47.783106 2026] [core:error] [pid 782784:tid 782831] [remote 216.73.216.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:47.783125 2026] [core:error] [pid 782784:tid 782831] [remote 216.73.216.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:46:48.193536 2026] [security2:error] [pid 782784:tid 783002] [client 20.215.191.139:36454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/new.php"] [unique_id "amuOCIaApLsOvtuGcVq5yAAAAFg"]
[Thu Jul 30 12:46:48.404319 2026] [security2:error] [pid 782784:tid 782973] [client 20.100.187.246:44724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/adminfuns.php"] [unique_id "amuOCIaApLsOvtuGcVq5zAAAADs"]
[Thu Jul 30 12:46:48.445894 2026] [core:notice] [pid 782784:tid 783008] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:48.450291 2026] [security2:error] [pid 782784:tid 783008] [client 103.215.74.26:31296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOCIaApLsOvtuGcVq5zQAAAF4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:48.696663 2026] [security2:error] [pid 782784:tid 783040] [client 20.104.18.253:22250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/403.php"] [unique_id "amuOCIaApLsOvtuGcVq50gAAAH4"]
[Thu Jul 30 12:46:48.741145 2026] [security2:error] [pid 782784:tid 783017] [client 74.7.228.23:33376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-cb0a0f7b.jst.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuOCIaApLsOvtuGcVq51gAAZ2E"]
[Thu Jul 30 12:46:49.143294 2026] [security2:error] [pid 782784:tid 783006] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOCIaApLsOvtuGcVq5zgAAXFk"]
[Thu Jul 30 12:46:49.156058 2026] [security2:error] [pid 782784:tid 783015] [client 20.100.187.246:46186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/albin.php"] [unique_id "amuOCYaApLsOvtuGcVq53wAAAGU"]
[Thu Jul 30 12:46:49.179596 2026] [core:notice] [pid 782784:tid 783010] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:49.183938 2026] [security2:error] [pid 782784:tid 783010] [client 103.215.74.26:31302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOCYaApLsOvtuGcVq54AAAAGA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:49.391564 2026] [security2:error] [pid 782784:tid 782995] [client 20.215.191.139:21475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/radio.php"] [unique_id "amuOCYaApLsOvtuGcVq56QAAAFE"]
[Thu Jul 30 12:46:49.489663 2026] [core:notice] [pid 782784:tid 783018] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:49.612003 2026] [security2:error] [pid 782784:tid 782953] [client 20.104.18.253:28290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/404.php"] [unique_id "amuOCYaApLsOvtuGcVq57wAAACc"]
[Thu Jul 30 12:46:49.908790 2026] [security2:error] [pid 782784:tid 782955] [client 57.141.0.19:28644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuOCYaApLsOvtuGcVq56wAAKWM"], referer: https://igetvape-australia.com/product/alibarbar-pandora-7000-puffs/?add-to-cart=1043
[Thu Jul 30 12:46:49.927946 2026] [core:notice] [pid 782784:tid 782996] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:49.932319 2026] [security2:error] [pid 782784:tid 782996] [client 103.215.74.26:31306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOCYaApLsOvtuGcVq59gAAAFI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:50.225539 2026] [security2:error] [pid 782784:tid 783041] [client 20.215.191.139:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/s.php"] [unique_id "amuOCoaApLsOvtuGcVq5_AAAAH8"]
[Thu Jul 30 12:46:50.296166 2026] [security2:error] [pid 782784:tid 782988] [client 20.100.187.246:44726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/amfsqvgv.php"] [unique_id "amuOCoaApLsOvtuGcVq6AAAAAEo"]
[Thu Jul 30 12:46:50.381468 2026] [security2:error] [pid 782784:tid 782914] [client 20.104.18.253:28753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/aa.php"] [unique_id "amuOCoaApLsOvtuGcVq6BAAAAAA"]
[Thu Jul 30 12:46:50.656432 2026] [core:notice] [pid 782784:tid 782936] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:50.660911 2026] [security2:error] [pid 782784:tid 782936] [client 103.215.74.26:31316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOCoaApLsOvtuGcVq6CQAAABY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:50.890313 2026] [security2:error] [pid 782784:tid 782923] [client 20.100.187.246:44705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/ant.php"] [unique_id "amuOCoaApLsOvtuGcVq6EQAAAAk"]
[Thu Jul 30 12:46:51.333478 2026] [security2:error] [pid 782784:tid 782900] [remote 216.73.216.152:46682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuOC4aApLsOvtuGcVq6GwAANnM"]
[Thu Jul 30 12:46:51.352068 2026] [security2:error] [pid 782784:tid 782956] [client 20.215.191.139:31798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/sim.php"] [unique_id "amuOC4aApLsOvtuGcVq6HAAAACo"]
[Thu Jul 30 12:46:51.410616 2026] [core:notice] [pid 782784:tid 782972] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:51.414949 2026] [security2:error] [pid 782784:tid 782972] [client 103.215.74.26:31332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOC4aApLsOvtuGcVq6IQAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:51.576497 2026] [security2:error] [pid 782784:tid 783010] [client 20.104.18.253:43405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/aafewc0k.php"] [unique_id "amuOC4aApLsOvtuGcVq6JQAAAGA"]
[Thu Jul 30 12:46:51.812919 2026] [security2:error] [pid 782784:tid 783001] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuOC4aApLsOvtuGcVq6KwAAAFc"]
[Thu Jul 30 12:46:52.144868 2026] [core:notice] [pid 782784:tid 782943] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:52.148996 2026] [security2:error] [pid 782784:tid 782943] [client 103.215.74.26:31336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuODIaApLsOvtuGcVq6NQAAAB0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:52.382037 2026] [security2:error] [pid 782784:tid 782985] [client 20.104.18.253:52157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/abcd.php"] [unique_id "amuODIaApLsOvtuGcVq6QgAAAEc"]
[Thu Jul 30 12:46:52.483832 2026] [security2:error] [pid 782784:tid 783019] [client 20.100.187.246:47534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/appreciators.php"] [unique_id "amuODIaApLsOvtuGcVq6RAAAAGk"]
[Thu Jul 30 12:46:52.878116 2026] [security2:error] [pid 782784:tid 783013] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuODIaApLsOvtuGcVq6PwAAAGM"]
[Thu Jul 30 12:46:52.896442 2026] [core:notice] [pid 782784:tid 782958] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:52.899650 2026] [security2:error] [pid 782784:tid 782941] [client 20.215.191.139:21911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/text.php"] [unique_id "amuODIaApLsOvtuGcVq6UwAAABs"]
[Thu Jul 30 12:46:52.900544 2026] [security2:error] [pid 782784:tid 782958] [client 103.215.74.26:31338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuODIaApLsOvtuGcVq6UgAAACw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:52.993731 2026] [security2:error] [pid 782784:tid 783021] [client 74.7.228.9:46672] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuODIaApLsOvtuGcVq6RQAAa3o"]
[Thu Jul 30 12:46:53.184674 2026] [security2:error] [pid 782784:tid 782806] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuODYaApLsOvtuGcVq6YgAAFBU"]
[Thu Jul 30 12:46:53.184834 2026] [security2:error] [pid 782784:tid 782934] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuODYaApLsOvtuGcVq6YgAAFBU"]
[Thu Jul 30 12:46:53.474953 2026] [core:notice] [pid 782784:tid 782994] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:53.626780 2026] [core:notice] [pid 782784:tid 783035] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:53.630725 2026] [security2:error] [pid 782784:tid 783035] [client 103.215.74.26:50202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuODYaApLsOvtuGcVq6cgAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:53.921067 2026] [security2:error] [pid 782784:tid 782939] [client 20.104.18.253:30988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/about.php"] [unique_id "amuODYaApLsOvtuGcVq6ewAAABk"]
[Thu Jul 30 12:46:54.079786 2026] [security2:error] [pid 782784:tid 783004] [client 20.215.191.139:28304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/user.php"] [unique_id "amuODoaApLsOvtuGcVq6gQAAAFo"]
[Thu Jul 30 12:46:54.355053 2026] [core:notice] [pid 782784:tid 783007] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:54.359057 2026] [security2:error] [pid 782784:tid 783007] [client 103.215.74.26:50210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuODoaApLsOvtuGcVq6jAAAAF0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:54.485290 2026] [core:notice] [pid 782784:tid 782948] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:54.613839 2026] [security2:error] [pid 782784:tid 782921] [client 20.100.187.246:51393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/archive.php"] [unique_id "amuODoaApLsOvtuGcVq6kgAAAAc"]
[Thu Jul 30 12:46:54.754271 2026] [security2:error] [pid 782784:tid 782937] [client 20.104.18.253:22270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/admin.php"] [unique_id "amuODoaApLsOvtuGcVq6lgAAABc"]
[Thu Jul 30 12:46:54.797875 2026] [security2:error] [pid 782784:tid 783022] [client 20.215.191.139:37276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/webadmin.php"] [unique_id "amuODoaApLsOvtuGcVq6lwAAAGw"]
[Thu Jul 30 12:46:55.089789 2026] [core:notice] [pid 782784:tid 782972] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:55.094249 2026] [security2:error] [pid 782784:tid 782972] [client 103.215.74.26:50226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOD4aApLsOvtuGcVq6pQAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:55.389915 2026] [security2:error] [pid 782784:tid 782998] [client 20.215.191.139:26014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amuOD4aApLsOvtuGcVq6sQAAAFQ"]
[Thu Jul 30 12:46:55.407627 2026] [core:notice] [pid 782784:tid 783009] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:55.559834 2026] [security2:error] [pid 782784:tid 783034] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuODoaApLsOvtuGcVq6nwAAeCQ"]
[Thu Jul 30 12:46:55.663698 2026] [security2:error] [pid 782784:tid 782933] [client 20.104.18.253:46218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/adminfuns.php"] [unique_id "amuOD4aApLsOvtuGcVq6uAAAABM"]
[Thu Jul 30 12:46:55.837171 2026] [core:notice] [pid 782784:tid 783030] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:55.843835 2026] [security2:error] [pid 782784:tid 783030] [client 103.215.74.26:50230] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOD4aApLsOvtuGcVq6uwAAAHQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:56.054533 2026] [security2:error] [pid 782784:tid 783031] [client 118.26.104.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "website-2f97271e.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuOD4aApLsOvtuGcVq6wgAAAHU"]
[Thu Jul 30 12:46:56.517336 2026] [security2:error] [pid 782784:tid 783015] [client 20.215.191.139:31757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amuOEIaApLsOvtuGcVq6zwAAAGU"]
[Thu Jul 30 12:46:56.550262 2026] [security2:error] [pid 782784:tid 782932] [client 150.107.232.194:26606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOEIaApLsOvtuGcVq60wAAABI"]
[Thu Jul 30 12:46:56.550378 2026] [security2:error] [pid 782784:tid 782932] [client 150.107.232.194:26606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOEIaApLsOvtuGcVq60wAAABI"]
[Thu Jul 30 12:46:56.568419 2026] [core:notice] [pid 782784:tid 782935] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:56.572538 2026] [security2:error] [pid 782784:tid 782997] [client 20.100.187.246:44506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/as.php"] [unique_id "amuOEIaApLsOvtuGcVq61QAAAFM"]
[Thu Jul 30 12:46:56.575313 2026] [security2:error] [pid 782784:tid 782935] [client 103.215.74.26:50238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOEIaApLsOvtuGcVq61AAAABU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:56.673953 2026] [security2:error] [pid 782784:tid 782983] [client 20.104.18.253:49853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/albin.php"] [unique_id "amuOEIaApLsOvtuGcVq61gAAAEU"]
[Thu Jul 30 12:46:57.341108 2026] [core:notice] [pid 782784:tid 782953] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:57.344922 2026] [security2:error] [pid 782784:tid 782953] [client 103.215.74.26:50246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOEYaApLsOvtuGcVq65gAAACc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:57.371262 2026] [core:notice] [pid 782784:tid 783035] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:58.088139 2026] [core:notice] [pid 782784:tid 782862] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:58.090043 2026] [core:notice] [pid 782784:tid 783019] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:58.093912 2026] [security2:error] [pid 782784:tid 783019] [client 103.215.74.26:50250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "767"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOEoaApLsOvtuGcVq6_AAAAGk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:58.346735 2026] [core:notice] [pid 782784:tid 782833] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:58.410844 2026] [security2:error] [pid 782784:tid 782950] [client 20.100.187.246:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/atomlib.php"] [unique_id "amuOEoaApLsOvtuGcVq7BAAAACQ"]
[Thu Jul 30 12:46:58.490668 2026] [security2:error] [pid 782784:tid 783034] [client 20.104.18.253:30262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/amfsqvgv.php"] [unique_id "amuOEoaApLsOvtuGcVq7CQAAAHg"]
[Thu Jul 30 12:46:58.595162 2026] [security2:error] [pid 782784:tid 783031] [client 172.202.44.182:28402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/chosen.php"] [unique_id "amuOEoaApLsOvtuGcVq7CgAAAHU"]
[Thu Jul 30 12:46:58.831030 2026] [core:notice] [pid 782784:tid 783005] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:58.837995 2026] [security2:error] [pid 782784:tid 783005] [client 103.215.74.26:50252] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOEoaApLsOvtuGcVq7DgAAAFs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:59.467228 2026] [security2:error] [pid 782784:tid 782960] [client 172.202.44.182:22379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xleet.php"] [unique_id "amuOE4aApLsOvtuGcVq7GAAAAC4"]
[Thu Jul 30 12:46:59.527583 2026] [security2:error] [pid 782784:tid 782922] [client 20.100.187.246:51434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/autoload_classmap.php"] [unique_id "amuOE4aApLsOvtuGcVq7GQAAAAg"]
[Thu Jul 30 12:46:59.559855 2026] [core:notice] [pid 782784:tid 782955] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:46:59.563860 2026] [security2:error] [pid 782784:tid 782955] [client 103.215.74.26:50256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "780"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOE4aApLsOvtuGcVq7GgAAACk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:46:59.705215 2026] [security2:error] [pid 782784:tid 782860] [remote 109.70.100.11:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.100.70.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happyspree.app"] [uri "/xmlrpc.php"] [unique_id "amuOE4aApLsOvtuGcVq7HgAAIEs"], referer: https://happyspree.app/xmlrpc.php
[Thu Jul 30 12:46:59.760800 2026] [security2:error] [pid 782784:tid 782938] [client 20.215.191.139:37280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amuOE4aApLsOvtuGcVq7IwAAABg"]
[Thu Jul 30 12:47:00.296069 2026] [security2:error] [pid 782784:tid 782945] [client 20.100.187.246:47783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/bb.php"] [unique_id "amuOFIaApLsOvtuGcVq7MQAAAB8"]
[Thu Jul 30 12:47:00.402651 2026] [security2:error] [pid 782784:tid 783040] [client 172.202.44.182:22354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/ds.php"] [unique_id "amuOFIaApLsOvtuGcVq7MgAAAH4"]
[Thu Jul 30 12:47:00.733905 2026] [security2:error] [pid 782784:tid 783007] [client 20.104.18.253:30221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/ant.php"] [unique_id "amuOFIaApLsOvtuGcVq7PAAAAF0"]
[Thu Jul 30 12:47:00.773842 2026] [security2:error] [pid 782784:tid 782879] [remote 109.70.100.11:46422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.100.70.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happyspree.app"] [uri "/xmlrpc.php"] [unique_id "amuOFIaApLsOvtuGcVq7PgAAOV4"], referer: https://happyspree.app/xmlrpc.php?rsd
[Thu Jul 30 12:47:00.777656 2026] [core:notice] [pid 782784:tid 782890] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:01.038881 2026] [core:notice] [pid 782784:tid 782852] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:01.077940 2026] [security2:error] [pid 782784:tid 782983] [client 20.100.187.246:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/bnm.php"] [unique_id "amuOFYaApLsOvtuGcVq7RAAAAEU"]
[Thu Jul 30 12:47:01.099472 2026] [security2:error] [pid 782784:tid 782997] [client 20.215.191.139:28321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amuOFYaApLsOvtuGcVq7RQAAAFM"]
[Thu Jul 30 12:47:01.620161 2026] [security2:error] [pid 782784:tid 782962] [client 20.104.18.253:22296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/appreciators.php"] [unique_id "amuOFYaApLsOvtuGcVq7UwAAADA"]
[Thu Jul 30 12:47:01.936703 2026] [security2:error] [pid 782784:tid 782967] [client 172.202.44.182:22340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/f5.php"] [unique_id "amuOFYaApLsOvtuGcVq7XgAAADU"]
[Thu Jul 30 12:47:01.994186 2026] [security2:error] [pid 782784:tid 782977] [client 20.215.191.139:28334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amuOFYaApLsOvtuGcVq7XwAAAD8"]
[Thu Jul 30 12:47:02.249060 2026] [security2:error] [pid 782784:tid 783030] [client 47.128.122.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuOFoaApLsOvtuGcVq7YgAAAHQ"]
[Thu Jul 30 12:47:02.740187 2026] [security2:error] [pid 782784:tid 783019] [client 20.104.18.253:44908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/archive.php"] [unique_id "amuOFoaApLsOvtuGcVq7bgAAAGk"]
[Thu Jul 30 12:47:02.877920 2026] [security2:error] [pid 782784:tid 783040] [client 172.202.44.182:32590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/god4m.php"] [unique_id "amuOFoaApLsOvtuGcVq7cwAAAH4"]
[Thu Jul 30 12:47:03.827531 2026] [security2:error] [pid 782784:tid 783006] [client 20.104.18.253:31023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/as.php"] [unique_id "amuOF4aApLsOvtuGcVq7hQAAAFw"]
[Thu Jul 30 12:47:03.833952 2026] [security2:error] [pid 782784:tid 783005] [client 172.202.44.182:32626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/info.php"] [unique_id "amuOF4aApLsOvtuGcVq7hgAAAFs"]
[Thu Jul 30 12:47:03.854925 2026] [security2:error] [pid 782784:tid 782792] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOF4aApLsOvtuGcVq7hwAAOAc"]
[Thu Jul 30 12:47:03.855082 2026] [security2:error] [pid 782784:tid 782970] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOF4aApLsOvtuGcVq7hwAAOAc"]
[Thu Jul 30 12:47:04.594150 2026] [security2:error] [pid 782784:tid 782937] [client 20.215.191.139:21474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amuOGIaApLsOvtuGcVq7lAAAABc"]
[Thu Jul 30 12:47:05.175350 2026] [security2:error] [pid 782784:tid 782938] [client 20.104.18.253:32224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/atomlib.php"] [unique_id "amuOGYaApLsOvtuGcVq7oQAAABg"]
[Thu Jul 30 12:47:05.292619 2026] [core:notice] [pid 782784:tid 783003] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:05.296651 2026] [security2:error] [pid 782784:tid 783003] [client 103.215.74.26:58786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOGYaApLsOvtuGcVq7pQAAAFk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:05.558193 2026] [core:notice] [pid 782784:tid 782908] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:05.561638 2026] [security2:error] [pid 782784:tid 782987] [client 103.190.46.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/22/24"] [unique_id "amuOGYaApLsOvtuGcVq7pgAASXs"], referer: https://www.google.com/
[Thu Jul 30 12:47:06.011731 2026] [core:notice] [pid 782784:tid 782947] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:06.015745 2026] [security2:error] [pid 782784:tid 782947] [client 103.215.74.26:58794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOGoaApLsOvtuGcVq7uQAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:06.317736 2026] [security2:error] [pid 782784:tid 782869] [remote 168.144.81.91:47588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.81.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ldk.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuOGoaApLsOvtuGcVq7vQAADlQ"]
[Thu Jul 30 12:47:06.698879 2026] [security2:error] [pid 782784:tid 782957] [client 20.215.191.139:60972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuOGoaApLsOvtuGcVq70AAAACs"]
[Thu Jul 30 12:47:07.039477 2026] [security2:error] [pid 782784:tid 783039] [client 150.107.232.194:27118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOG4aApLsOvtuGcVq73QAAAH0"]
[Thu Jul 30 12:47:07.039607 2026] [security2:error] [pid 782784:tid 783039] [client 150.107.232.194:27118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOG4aApLsOvtuGcVq73QAAAH0"]
[Thu Jul 30 12:47:07.371792 2026] [security2:error] [pid 782784:tid 783032] [client 20.215.191.139:21450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amuOG4aApLsOvtuGcVq74gAAAHY"]
[Thu Jul 30 12:47:07.378950 2026] [security2:error] [pid 782784:tid 782927] [client 20.104.18.253:46224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/autoload_classmap.php"] [unique_id "amuOG4aApLsOvtuGcVq74wAAAA0"]
[Thu Jul 30 12:47:07.563196 2026] [security2:error] [pid 782784:tid 783009] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOGoaApLsOvtuGcVq73AAAAF8"]
[Thu Jul 30 12:47:07.842526 2026] [security2:error] [pid 782784:tid 782989] [client 172.202.44.182:32628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuOG4aApLsOvtuGcVq73gAAAEs"]
[Thu Jul 30 12:47:08.110245 2026] [security2:error] [pid 782784:tid 783019] [client 20.215.191.139:28351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amuOHIaApLsOvtuGcVq7-AAAAGk"]
[Thu Jul 30 12:47:08.194072 2026] [security2:error] [pid 782784:tid 782896] [remote 57.141.0.70:21512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/saint-valentin/"] [unique_id "amuOHIaApLsOvtuGcVq7-QAAaG8"]
[Thu Jul 30 12:47:08.550089 2026] [security2:error] [pid 782784:tid 782997] [client 172.202.44.182:32628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/.__info.php"] [unique_id "amuOHIaApLsOvtuGcVq8BQAAAFM"]
[Thu Jul 30 12:47:09.053375 2026] [security2:error] [pid 782784:tid 782968] [client 20.215.191.139:28306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amuOHYaApLsOvtuGcVq8EQAAADY"]
[Thu Jul 30 12:47:09.152628 2026] [security2:error] [pid 782784:tid 782951] [client 20.104.18.253:28081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/bb.php"] [unique_id "amuOHYaApLsOvtuGcVq8EgAAACU"]
[Thu Jul 30 12:47:09.499360 2026] [core:error] [pid 782784:tid 783039] [client 152.32.138.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:47:09.499382 2026] [core:error] [pid 782784:tid 783039] [client 152.32.138.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:47:09.543406 2026] [security2:error] [pid 782784:tid 782937] [client 172.202.44.182:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/0.php"] [unique_id "amuOHYaApLsOvtuGcVq8IAAAABc"]
[Thu Jul 30 12:47:09.845511 2026] [security2:error] [pid 782784:tid 782923] [client 74.7.241.174:37438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.jhn.zzt.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuOHYaApLsOvtuGcVq8IQAAAAk"]
[Thu Jul 30 12:47:10.159606 2026] [security2:error] [pid 782784:tid 783034] [client 127.0.0.1:59798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuOHoaApLsOvtuGcVq8LQAAAHg"]
[Thu Jul 30 12:47:10.159621 2026] [security2:error] [pid 782784:tid 782964] [client 127.0.0.1:59792] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.black-devil-shop.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuOHoaApLsOvtuGcVq8LAAAADI"]
[Thu Jul 30 12:47:10.159770 2026] [security2:error] [pid 782784:tid 782933] [client 74.7.244.19:53122] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.black-devil-shop.com"] [uri "/robots.txt"] [unique_id "amuOHoaApLsOvtuGcVq8KwAAEwk"]
[Thu Jul 30 12:47:10.361555 2026] [security2:error] [pid 782784:tid 782936] [client 20.215.191.139:22274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/flower.php"] [unique_id "amuOHoaApLsOvtuGcVq8NgAAABY"]
[Thu Jul 30 12:47:11.050257 2026] [security2:error] [pid 782784:tid 782982] [client 172.202.44.182:32612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/07.php"] [unique_id "amuOH4aApLsOvtuGcVq8TwAAAEQ"]
[Thu Jul 30 12:47:11.220088 2026] [core:notice] [pid 782784:tid 782848] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:11.227681 2026] [security2:error] [pid 782784:tid 783010] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOHoaApLsOvtuGcVq8QgAAAGA"]
[Thu Jul 30 12:47:11.264504 2026] [security2:error] [pid 782784:tid 783024] [client 111.225.149.205:42934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "black-devil-shop.com"] [uri "/robots.txt"] [unique_id "amuOH4aApLsOvtuGcVq8VAAAAG4"]
[Thu Jul 30 12:47:11.472585 2026] [core:notice] [pid 782784:tid 782854] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:11.475451 2026] [security2:error] [pid 782784:tid 783022] [client 20.215.191.139:33436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amuOH4aApLsOvtuGcVq8XwAAAGw"]
[Thu Jul 30 12:47:11.518479 2026] [core:notice] [pid 782784:tid 782827] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:11.729957 2026] [core:notice] [pid 782784:tid 782919] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:11.733935 2026] [security2:error] [pid 782784:tid 782919] [client 103.215.74.26:58806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "759"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOH4aApLsOvtuGcVq8aAAAAAU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:11.818072 2026] [security2:error] [pid 782784:tid 782851] [remote 176.123.0.55:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.123.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "openspacelab.club"] [uri "/xmlrpc.php"] [unique_id "amuOH4aApLsOvtuGcVq8ZAAATkI"]
[Thu Jul 30 12:47:11.818397 2026] [security2:error] [pid 782784:tid 782992] [client 176.123.0.55:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "openspacelab.club"] [uri "/xmlrpc.php"] [unique_id "amuOH4aApLsOvtuGcVq8ZAAATkI"]
[Thu Jul 30 12:47:12.459310 2026] [core:notice] [pid 782784:tid 782964] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:12.464044 2026] [security2:error] [pid 782784:tid 782964] [client 103.215.74.26:58818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOIIaApLsOvtuGcVq8dwAAADI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:12.867036 2026] [security2:error] [pid 782784:tid 782989] [client 20.215.191.139:13683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amuOIIaApLsOvtuGcVq8hgAAAEs"]
[Thu Jul 30 12:47:13.196780 2026] [core:notice] [pid 782784:tid 782999] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:13.201392 2026] [security2:error] [pid 782784:tid 782999] [client 103.215.74.26:26818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOIYaApLsOvtuGcVq8lAAAAFU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:13.540184 2026] [security2:error] [pid 782784:tid 782938] [client 172.202.44.182:58703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/dropdown.php"] [unique_id "amuOIYaApLsOvtuGcVq8mAAAABg"]
[Thu Jul 30 12:47:13.647970 2026] [security2:error] [pid 782784:tid 782981] [client 20.215.191.139:14459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amuOIYaApLsOvtuGcVq8nAAAAEM"]
[Thu Jul 30 12:47:13.813631 2026] [core:notice] [pid 782784:tid 782847] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:14.393757 2026] [security2:error] [pid 782784:tid 782859] [remote 47.128.27.31:21580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-victori-one-slide-2/"] [unique_id "amuOIoaApLsOvtuGcVq8sQAAHUo"]
[Thu Jul 30 12:47:14.444878 2026] [core:notice] [pid 782784:tid 782898] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:14.511075 2026] [security2:error] [pid 782784:tid 783013] [client 20.215.191.139:26933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuOIoaApLsOvtuGcVq8swAAAGM"]
[Thu Jul 30 12:47:14.559722 2026] [security2:error] [pid 782784:tid 782939] [client 172.202.44.182:32589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/makeasmtp.php"] [unique_id "amuOIoaApLsOvtuGcVq8tAAAABk"]
[Thu Jul 30 12:47:14.702238 2026] [security2:error] [pid 782784:tid 782831] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOIoaApLsOvtuGcVq8uwAAby4"]
[Thu Jul 30 12:47:14.702383 2026] [security2:error] [pid 782784:tid 783025] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOIoaApLsOvtuGcVq8uwAAby4"]
[Thu Jul 30 12:47:14.754222 2026] [security2:error] [pid 782784:tid 782952] [client 20.104.18.253:36517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/bnm.php"] [unique_id "amuOIoaApLsOvtuGcVq8vAAAACY"]
[Thu Jul 30 12:47:15.546072 2026] [security2:error] [pid 782784:tid 782935] [client 172.202.44.182:37039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-sigunq.php"] [unique_id "amuOI4aApLsOvtuGcVq81QAAABU"]
[Thu Jul 30 12:47:15.587740 2026] [security2:error] [pid 782784:tid 782990] [client 20.104.18.253:28085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/bootstrap.php"] [unique_id "amuOI4aApLsOvtuGcVq81gAAAEw"]
[Thu Jul 30 12:47:15.800500 2026] [security2:error] [pid 782784:tid 782983] [client 20.215.191.139:13905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuOI4aApLsOvtuGcVq83gAAAEU"]
[Thu Jul 30 12:47:16.568386 2026] [security2:error] [pid 782784:tid 783039] [client 20.215.191.139:60963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amuOJIaApLsOvtuGcVq87wAAAH0"]
[Thu Jul 30 12:47:16.630034 2026] [security2:error] [pid 782784:tid 782965] [client 20.104.18.253:30217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/buy.php"] [unique_id "amuOJIaApLsOvtuGcVq88AAAADM"]
[Thu Jul 30 12:47:16.674801 2026] [core:error] [pid 782784:tid 783032] [client 152.32.138.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:47:16.674824 2026] [core:error] [pid 782784:tid 783032] [client 152.32.138.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:47:17.115268 2026] [security2:error] [pid 782784:tid 782919] [client 172.202.44.182:37032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wso112233.php"] [unique_id "amuOJYaApLsOvtuGcVq8_QAAAAU"]
[Thu Jul 30 12:47:17.411361 2026] [security2:error] [pid 782784:tid 782955] [client 20.40.58.237:55495] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuOJYaApLsOvtuGcVq9CAAAACk"]
[Thu Jul 30 12:47:17.576806 2026] [security2:error] [pid 782784:tid 782948] [client 150.107.232.194:26821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOJYaApLsOvtuGcVq9DAAAACI"]
[Thu Jul 30 12:47:17.576915 2026] [security2:error] [pid 782784:tid 782948] [client 150.107.232.194:26821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOJYaApLsOvtuGcVq9DAAAACI"]
[Thu Jul 30 12:47:17.851839 2026] [security2:error] [pid 782784:tid 783007] [client 74.7.241.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.reviewbyjook.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuOJYaApLsOvtuGcVq9EAAAXXs"]
[Thu Jul 30 12:47:17.912877 2026] [security2:error] [pid 782784:tid 783002] [client 20.104.18.253:28042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/chosen.php"] [unique_id "amuOJYaApLsOvtuGcVq9EgAAAFg"]
[Thu Jul 30 12:47:18.947969 2026] [core:notice] [pid 782784:tid 783000] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:18.951894 2026] [security2:error] [pid 782784:tid 783000] [client 103.215.74.26:26826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOJoaApLsOvtuGcVq9LQAAAFY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:18.952550 2026] [security2:error] [pid 782784:tid 782950] [client 20.215.191.139:22334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuOJoaApLsOvtuGcVq9LgAAACQ"]
[Thu Jul 30 12:47:19.020606 2026] [security2:error] [pid 782784:tid 782966] [client 172.202.44.182:34074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/alfanew.php"] [unique_id "amuOJ4aApLsOvtuGcVq9MQAAADQ"]
[Thu Jul 30 12:47:19.256452 2026] [security2:error] [pid 782784:tid 782991] [client 20.104.18.253:49202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/class-wp-image.php"] [unique_id "amuOJ4aApLsOvtuGcVq9TAAAAE0"]
[Thu Jul 30 12:47:19.700722 2026] [core:notice] [pid 782784:tid 783036] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:19.708148 2026] [security2:error] [pid 782784:tid 783036] [client 103.215.74.26:26838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOJ4aApLsOvtuGcVq9XQAAAHo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:19.790109 2026] [core:error] [pid 782784:tid 782969] [client 152.32.138.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:47:19.790131 2026] [core:error] [pid 782784:tid 782969] [client 152.32.138.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:47:19.836064 2026] [security2:error] [pid 782784:tid 782836] [remote 103.187.23.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.23.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caflchimneysweeper.com"] [uri "/wp/xmlrpc.php"] [unique_id "amuOJ4aApLsOvtuGcVq9ZQAAXTM"]
[Thu Jul 30 12:47:19.836267 2026] [security2:error] [pid 782784:tid 783007] [client 103.187.23.21:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "caflchimneysweeper.com"] [uri "/wp/xmlrpc.php"] [unique_id "amuOJ4aApLsOvtuGcVq9ZQAAXTM"]
[Thu Jul 30 12:47:20.151589 2026] [security2:error] [pid 782784:tid 783002] [client 172.202.44.182:37011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/fw.php"] [unique_id "amuOKIaApLsOvtuGcVq9cAAAAFg"]
[Thu Jul 30 12:47:20.462734 2026] [core:notice] [pid 782784:tid 783035] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:20.468161 2026] [security2:error] [pid 782784:tid 783035] [client 103.215.74.26:26844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOKIaApLsOvtuGcVq9dgAAAHk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:20.572465 2026] [security2:error] [pid 782784:tid 782962] [client 20.104.18.253:30220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/classsmtps.php"] [unique_id "amuOKIaApLsOvtuGcVq9dwAAADA"]
[Thu Jul 30 12:47:21.223361 2026] [core:notice] [pid 782784:tid 783027] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:21.230837 2026] [security2:error] [pid 782784:tid 783027] [client 103.215.74.26:26858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOKYaApLsOvtuGcVq9jgAAAHE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:21.417796 2026] [core:notice] [pid 782784:tid 782964] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:21.429379 2026] [security2:error] [pid 782784:tid 783013] [client 172.202.44.182:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuOKYaApLsOvtuGcVq9hgAAAGM"]
[Thu Jul 30 12:47:21.750114 2026] [security2:error] [pid 782784:tid 782952] [client 20.104.18.253:36532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/classwithtostring.php"] [unique_id "amuOKYaApLsOvtuGcVq9nAAAACY"]
[Thu Jul 30 12:47:21.843186 2026] [security2:error] [pid 782784:tid 782933] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOKYaApLsOvtuGcVq9kAAAABM"]
[Thu Jul 30 12:47:21.922102 2026] [core:notice] [pid 782784:tid 782931] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:22.399941 2026] [security2:error] [pid 782784:tid 782984] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOKYaApLsOvtuGcVq9nwAARj8"]
[Thu Jul 30 12:47:22.406743 2026] [security2:error] [pid 782784:tid 782940] [client 172.202.44.182:34908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/simple.php"] [unique_id "amuOKoaApLsOvtuGcVq9sAAAABo"]
[Thu Jul 30 12:47:22.656440 2026] [security2:error] [pid 782784:tid 783008] [client 20.104.18.253:44878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/config.php"] [unique_id "amuOKoaApLsOvtuGcVq9sQAAAF4"]
[Thu Jul 30 12:47:23.325290 2026] [security2:error] [pid 782784:tid 782992] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOKoaApLsOvtuGcVq9ugAAAE4"]
[Thu Jul 30 12:47:23.371430 2026] [security2:error] [pid 782784:tid 783039] [client 185.191.171.17:40376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/01/16/paraiba-confirma-838-novos-casos-de-covid-19-e-11-obitos-neste-sabado/"] [unique_id "amuOK4aApLsOvtuGcVq9xQAAAH0"]
[Thu Jul 30 12:47:23.371576 2026] [security2:error] [pid 782784:tid 783039] [client 185.191.171.17:40376] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/01/16/paraiba-confirma-838-novos-casos-de-covid-19-e-11-obitos-neste-sabado/"] [unique_id "amuOK4aApLsOvtuGcVq9xQAAAH0"]
[Thu Jul 30 12:47:23.390935 2026] [security2:error] [pid 782784:tid 782966] [client 172.202.44.182:34092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/classsmtps.php"] [unique_id "amuOK4aApLsOvtuGcVq9yAAAADQ"]
[Thu Jul 30 12:47:24.272425 2026] [security2:error] [pid 782784:tid 782864] [remote 43.156.51.18:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lucky-strike-shop.com"] [uri "/product/marlboro-11"] [unique_id "amuOLIaApLsOvtuGcVq92AAAIk8"]
[Thu Jul 30 12:47:24.272621 2026] [security2:error] [pid 782784:tid 782948] [client 43.156.51.18:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lucky-strike-shop.com"] [uri "/product/marlboro-11"] [unique_id "amuOLIaApLsOvtuGcVq92AAAIk8"]
[Thu Jul 30 12:47:24.563420 2026] [security2:error] [pid 782784:tid 782997] [client 172.202.44.182:34070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-blog-header.php"] [unique_id "amuOLIaApLsOvtuGcVq94QAAAFM"]
[Thu Jul 30 12:47:24.573527 2026] [security2:error] [pid 782784:tid 782926] [client 43.173.181.201:42700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/04/30/mr-wonderful-fete-des-meres-2016/"] [unique_id "amuOLIaApLsOvtuGcVq94gAAAAw"]
[Thu Jul 30 12:47:24.776826 2026] [core:notice] [pid 782784:tid 782822] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:24.865773 2026] [core:notice] [pid 782784:tid 782858] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:25.233897 2026] [security2:error] [pid 782784:tid 783010] [client 20.104.18.253:32325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/core.php"] [unique_id "amuOLYaApLsOvtuGcVq97wAAAGA"]
[Thu Jul 30 12:47:25.384942 2026] [core:notice] [pid 782784:tid 782967] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:25.389524 2026] [security2:error] [pid 782784:tid 782967] [client 43.173.178.213:58826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/04/30/mr-wonderful-fete-des-meres-2016/"] [unique_id "amuOLYaApLsOvtuGcVq98wAAADU"], referer: https://carnetdeshopping.com/index.php/2016/04/30/mr-wonderful-fete-des-meres-2016/
[Thu Jul 30 12:47:25.513078 2026] [security2:error] [pid 782784:tid 782846] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOLYaApLsOvtuGcVq99wAASz0"]
[Thu Jul 30 12:47:25.513224 2026] [security2:error] [pid 782784:tid 782989] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOLYaApLsOvtuGcVq99wAASz0"]
[Thu Jul 30 12:47:25.767361 2026] [security2:error] [pid 782784:tid 782918] [client 172.202.44.182:34886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-trackback.php"] [unique_id "amuOLYaApLsOvtuGcVq9_AAAAAQ"]
[Thu Jul 30 12:47:26.348248 2026] [security2:error] [pid 782784:tid 782897] [remote 216.73.216.152:4521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuOLoaApLsOvtuGcVq-CgAAQnA"]
[Thu Jul 30 12:47:26.369669 2026] [security2:error] [pid 782784:tid 782919] [client 213.152.161.170:50806] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuOLoaApLsOvtuGcVq-CAAAAAU"]
[Thu Jul 30 12:47:26.369775 2026] [security2:error] [pid 782784:tid 782919] [client 213.152.161.170:50806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuOLoaApLsOvtuGcVq-CAAAAAU"]
[Thu Jul 30 12:47:26.439651 2026] [security2:error] [pid 782784:tid 782943] [client 20.104.18.253:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/css.php"] [unique_id "amuOLoaApLsOvtuGcVq-DQAAAB0"]
[Thu Jul 30 12:47:26.947725 2026] [core:notice] [pid 782784:tid 782948] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:26.952148 2026] [security2:error] [pid 782784:tid 782948] [client 103.215.74.26:63912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOLoaApLsOvtuGcVq-GQAAACI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:27.183096 2026] [security2:error] [pid 782784:tid 782958] [client 172.202.44.182:22032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-signup.php"] [unique_id "amuOL4aApLsOvtuGcVq-IAAAACw"]
[Thu Jul 30 12:47:27.419329 2026] [security2:error] [pid 782784:tid 782973] [client 20.215.191.139:26934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amuOL4aApLsOvtuGcVq-IQAAADs"]
[Thu Jul 30 12:47:27.706490 2026] [core:notice] [pid 782784:tid 783033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:27.710802 2026] [security2:error] [pid 782784:tid 783033] [client 103.215.74.26:63924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOL4aApLsOvtuGcVq-LAAAAHc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:27.904777 2026] [security2:error] [pid 782784:tid 782957] [client 20.104.18.253:32836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/database.php"] [unique_id "amuOL4aApLsOvtuGcVq-LgAAACs"]
[Thu Jul 30 12:47:28.042933 2026] [security2:error] [pid 782784:tid 782967] [client 150.107.232.194:27065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOMIaApLsOvtuGcVq-MgAAADU"]
[Thu Jul 30 12:47:28.043048 2026] [security2:error] [pid 782784:tid 782967] [client 150.107.232.194:27065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOMIaApLsOvtuGcVq-MgAAADU"]
[Thu Jul 30 12:47:28.295350 2026] [security2:error] [pid 782784:tid 782986] [client 172.202.44.182:22064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-comments-post.php"] [unique_id "amuOMIaApLsOvtuGcVq-PwAAAEg"]
[Thu Jul 30 12:47:28.462912 2026] [core:notice] [pid 782784:tid 782930] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:28.467375 2026] [security2:error] [pid 782784:tid 782930] [client 103.215.74.26:63938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOMIaApLsOvtuGcVq-RAAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:28.895380 2026] [security2:error] [pid 782784:tid 782970] [client 20.104.18.253:65061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/db.php"] [unique_id "amuOMIaApLsOvtuGcVq-UgAAADg"]
[Thu Jul 30 12:47:28.959683 2026] [security2:error] [pid 782784:tid 783040] [client 20.215.191.139:32496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amuOMIaApLsOvtuGcVq-UwAAAH4"]
[Thu Jul 30 12:47:29.221708 2026] [core:notice] [pid 782784:tid 782988] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:29.226056 2026] [security2:error] [pid 782784:tid 782988] [client 103.215.74.26:63940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOMYaApLsOvtuGcVq-YAAAAEo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:29.667991 2026] [security2:error] [pid 782784:tid 782924] [client 20.104.18.253:65032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/default.php"] [unique_id "amuOMYaApLsOvtuGcVq-aQAAAAo"]
[Thu Jul 30 12:47:29.678406 2026] [security2:error] [pid 782784:tid 783029] [client 172.202.44.182:36237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-mail.php"] [unique_id "amuOMYaApLsOvtuGcVq-agAAAHM"]
[Thu Jul 30 12:47:29.820747 2026] [security2:error] [pid 782784:tid 782940] [client 20.215.191.139:13983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuOMYaApLsOvtuGcVq-cQAAABo"]
[Thu Jul 30 12:47:29.945232 2026] [core:notice] [pid 782784:tid 782927] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:29.949396 2026] [security2:error] [pid 782784:tid 782927] [client 103.215.74.26:63946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOMYaApLsOvtuGcVq-dQAAAA0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:30.567362 2026] [security2:error] [pid 782784:tid 782999] [client 20.104.18.253:30167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/dropdown.php"] [unique_id "amuOMoaApLsOvtuGcVq-gAAAAFU"]
[Thu Jul 30 12:47:30.648497 2026] [security2:error] [pid 782784:tid 783030] [client 172.202.44.182:22049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-activate.php"] [unique_id "amuOMoaApLsOvtuGcVq-ggAAAHQ"]
[Thu Jul 30 12:47:30.699421 2026] [core:notice] [pid 782784:tid 782986] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:30.703719 2026] [security2:error] [pid 782784:tid 782986] [client 103.215.74.26:63960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOMoaApLsOvtuGcVq-gwAAAEg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:31.440435 2026] [core:notice] [pid 782784:tid 782920] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:31.463839 2026] [core:notice] [pid 782784:tid 782942] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:31.468406 2026] [security2:error] [pid 782784:tid 782942] [client 103.215.74.26:63966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOM4aApLsOvtuGcVq-nAAAABw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:31.628870 2026] [security2:error] [pid 782784:tid 782952] [client 20.104.18.253:62376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/edit.php"] [unique_id "amuOM4aApLsOvtuGcVq-oQAAACY"]
[Thu Jul 30 12:47:32.036817 2026] [security2:error] [pid 782784:tid 782921] [client 172.202.44.182:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/post.php"] [unique_id "amuONIaApLsOvtuGcVq-rQAAAAc"]
[Thu Jul 30 12:47:32.196942 2026] [core:notice] [pid 782784:tid 783029] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:32.200929 2026] [security2:error] [pid 782784:tid 783029] [client 103.215.74.26:63968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuONIaApLsOvtuGcVq-rwAAAHM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:32.575038 2026] [security2:error] [pid 782784:tid 783024] [client 20.104.18.253:39795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/f35.php"] [unique_id "amuONIaApLsOvtuGcVq-twAAAG4"]
[Thu Jul 30 12:47:32.648532 2026] [security2:error] [pid 782784:tid 782925] [client 74.7.228.53:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.elevherdigital.com"] [uri "/index.php"] [unique_id "amuOMoaApLsOvtuGcVq-hwAAAAs"]
[Thu Jul 30 12:47:32.649445 2026] [security2:error] [pid 782784:tid 782993] [client 74.7.228.53:54396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.elevherdigital.com"] [uri "/robots.txt"] [unique_id "amuOMoaApLsOvtuGcVq-hQAAT1o"]
[Thu Jul 30 12:47:32.993357 2026] [security2:error] [pid 782784:tid 782919] [client 20.215.191.139:32816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-config-sample.php"] [unique_id "amuONIaApLsOvtuGcVq-vgAAAAU"]
[Thu Jul 30 12:47:33.125914 2026] [security2:error] [pid 782784:tid 783019] [client 74.7.244.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "xyu.gpl.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuONYaApLsOvtuGcVq-ygAAAGk"]
[Thu Jul 30 12:47:33.126451 2026] [security2:error] [pid 782784:tid 782999] [client 74.7.244.4:52560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "xyu.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuONYaApLsOvtuGcVq-yAAAVQ4"]
[Thu Jul 30 12:47:33.265638 2026] [security2:error] [pid 782784:tid 783016] [client 172.202.44.182:34935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-2019.php"] [unique_id "amuONYaApLsOvtuGcVq-ywAAAGY"]
[Thu Jul 30 12:47:33.900349 2026] [security2:error] [pid 782784:tid 783026] [client 20.104.18.253:39802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/f7.php"] [unique_id "amuONYaApLsOvtuGcVq-3AAAAHA"]
[Thu Jul 30 12:47:34.161130 2026] [security2:error] [pid 782784:tid 782803] [remote 74.7.241.60:46446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuONoaApLsOvtuGcVq-4wAARhI"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:47:34.264681 2026] [security2:error] [pid 782784:tid 782953] [client 172.202.44.182:17577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/hoot.php"] [unique_id "amuONoaApLsOvtuGcVq-5AAAACc"]
[Thu Jul 30 12:47:35.252396 2026] [security2:error] [pid 782784:tid 783020] [client 172.202.44.182:56339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/log.php"] [unique_id "amuON4aApLsOvtuGcVq--AAAAGo"]
[Thu Jul 30 12:47:35.307788 2026] [security2:error] [pid 782784:tid 783025] [client 74.7.175.175:42456] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ghm.hmu.temporary.site"] [uri "/robots.txt"] [unique_id "amuON4aApLsOvtuGcVq--QAAAG8"]
[Thu Jul 30 12:47:35.963155 2026] [core:notice] [pid 782784:tid 782964] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:36.040087 2026] [security2:error] [pid 782784:tid 783019] [client 66.132.172.198:4854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amuON4aApLsOvtuGcVq_AQAAAGk"]
[Thu Jul 30 12:47:36.110249 2026] [core:notice] [pid 782784:tid 782947] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:36.241909 2026] [security2:error] [pid 782784:tid 782877] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOOIaApLsOvtuGcVq_DwAAGFw"]
[Thu Jul 30 12:47:36.242073 2026] [security2:error] [pid 782784:tid 782938] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOOIaApLsOvtuGcVq_DwAAGFw"]
[Thu Jul 30 12:47:36.537771 2026] [core:notice] [pid 782784:tid 782926] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:36.666497 2026] [core:notice] [pid 782784:tid 783008] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:36.976531 2026] [security2:error] [pid 782784:tid 783016] [client 172.202.44.182:56373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/bak.php"] [unique_id "amuOOIaApLsOvtuGcVq_KwAAAGY"]
[Thu Jul 30 12:47:37.037423 2026] [security2:error] [pid 782784:tid 783017] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOOIaApLsOvtuGcVq_FgAAAGc"]
[Thu Jul 30 12:47:37.479653 2026] [fcgid:warn] [pid 782784:tid 782929] (70014)End of file found: [client 123.58.210.106:56396] mod_fcgid: can't get data from http client
[Thu Jul 30 12:47:37.927691 2026] [core:notice] [pid 782784:tid 782994] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:37.931629 2026] [security2:error] [pid 782784:tid 782994] [client 103.215.74.26:35016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOOYaApLsOvtuGcVq_PwAAAFA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:38.096053 2026] [security2:error] [pid 782784:tid 783015] [client 172.202.44.182:36240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/content.php"] [unique_id "amuOOoaApLsOvtuGcVq_QAAAAGU"]
[Thu Jul 30 12:47:38.577024 2026] [security2:error] [pid 782784:tid 782932] [client 150.107.232.194:27461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOOoaApLsOvtuGcVq_TAAAABI"]
[Thu Jul 30 12:47:38.577134 2026] [security2:error] [pid 782784:tid 782932] [client 150.107.232.194:27461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOOoaApLsOvtuGcVq_TAAAABI"]
[Thu Jul 30 12:47:38.665268 2026] [core:notice] [pid 782784:tid 783026] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:38.671823 2026] [security2:error] [pid 782784:tid 783026] [client 103.215.74.26:35024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOOoaApLsOvtuGcVq_UAAAAHA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:39.086708 2026] [security2:error] [pid 782784:tid 782937] [client 172.202.44.182:37713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/upfile.php"] [unique_id "amuOO4aApLsOvtuGcVq_VwAAABc"]
[Thu Jul 30 12:47:39.225136 2026] [security2:error] [pid 782784:tid 782975] [client 86.106.84.166:36442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuOO4aApLsOvtuGcVq_WwAAAD0"]
[Thu Jul 30 12:47:39.225237 2026] [security2:error] [pid 782784:tid 782975] [client 86.106.84.166:36442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuOO4aApLsOvtuGcVq_WwAAAD0"]
[Thu Jul 30 12:47:39.451015 2026] [core:notice] [pid 782784:tid 783014] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:39.457739 2026] [security2:error] [pid 782784:tid 783014] [client 103.215.74.26:35034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOO4aApLsOvtuGcVq_ZQAAAGQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:40.183158 2026] [core:notice] [pid 782784:tid 782978] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:40.189997 2026] [security2:error] [pid 782784:tid 782978] [client 103.215.74.26:35036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOPIaApLsOvtuGcVq_cAAAAEA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:40.921417 2026] [core:notice] [pid 782784:tid 782952] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:40.925346 2026] [security2:error] [pid 782784:tid 782952] [client 103.215.74.26:35048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "748"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOPIaApLsOvtuGcVq_gQAAACY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:41.655958 2026] [core:notice] [pid 782784:tid 782941] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:41.659942 2026] [security2:error] [pid 782784:tid 782941] [client 103.215.74.26:35052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "766"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOPYaApLsOvtuGcVq_kQAAABs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:41.873783 2026] [security2:error] [pid 782784:tid 782929] [client 172.202.44.182:37751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/bypass.php"] [unique_id "amuOPYaApLsOvtuGcVq_lAAAAA8"]
[Thu Jul 30 12:47:42.061316 2026] [core:notice] [pid 782784:tid 782984] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:42.444064 2026] [core:notice] [pid 782784:tid 782972] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:42.449955 2026] [security2:error] [pid 782784:tid 782972] [client 103.215.74.26:35068] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOPoaApLsOvtuGcVq_pQAAADo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:42.716755 2026] [security2:error] [pid 782784:tid 782921] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOPoaApLsOvtuGcVq_nwAAB0c"]
[Thu Jul 30 12:47:43.177694 2026] [core:notice] [pid 782784:tid 782947] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:43.181758 2026] [security2:error] [pid 782784:tid 782947] [client 103.215.74.26:36770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "779"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOP4aApLsOvtuGcVq_tAAAACE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:43.273128 2026] [core:notice] [pid 782784:tid 782889] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:43.916253 2026] [core:notice] [pid 782784:tid 783024] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:43.920245 2026] [security2:error] [pid 782784:tid 783024] [client 103.215.74.26:36776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "751"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOP4aApLsOvtuGcVq_xAAAAG4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:44.199009 2026] [security2:error] [pid 782784:tid 782964] [client 172.202.44.182:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/updates.php"] [unique_id "amuOQIaApLsOvtuGcVq_zwAAADI"]
[Thu Jul 30 12:47:45.766456 2026] [security2:error] [pid 782784:tid 782960] [client 172.202.44.182:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmrlpc.php"] [unique_id "amuOQYaApLsOvtuGcVq_8wAAAC4"]
[Thu Jul 30 12:47:46.278002 2026] [security2:error] [pid 782784:tid 782934] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOQYaApLsOvtuGcVq_7wAAABQ"]
[Thu Jul 30 12:47:46.475996 2026] [core:notice] [pid 782784:tid 782901] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:46.826954 2026] [security2:error] [pid 782784:tid 783022] [client 172.202.44.182:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/ae.php"] [unique_id "amuOQoaApLsOvtuGcVrACgAAAGw"]
[Thu Jul 30 12:47:47.007013 2026] [security2:error] [pid 782784:tid 782840] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOQ4aApLsOvtuGcVrACwAAEDc"]
[Thu Jul 30 12:47:47.007180 2026] [security2:error] [pid 782784:tid 782930] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOQ4aApLsOvtuGcVrACwAAEDc"]
[Thu Jul 30 12:47:48.167822 2026] [security2:error] [pid 782784:tid 782995] [client 172.202.44.182:18378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/moon.php"] [unique_id "amuORIaApLsOvtuGcVrAKgAAAFE"]
[Thu Jul 30 12:47:48.571555 2026] [security2:error] [pid 782784:tid 782952] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kamiliacademy.com"] [uri "/index.php"] [unique_id "amuOQYaApLsOvtuGcVq_8gAAACY"]
[Thu Jul 30 12:47:48.767442 2026] [security2:error] [pid 782784:tid 782974] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuORIaApLsOvtuGcVrAKQAAPBM"]
[Thu Jul 30 12:47:49.048442 2026] [security2:error] [pid 782784:tid 782998] [client 150.107.232.194:27468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuORYaApLsOvtuGcVrAPwAAAFQ"]
[Thu Jul 30 12:47:49.048603 2026] [security2:error] [pid 782784:tid 782998] [client 150.107.232.194:27468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuORYaApLsOvtuGcVrAPwAAAFQ"]
[Thu Jul 30 12:47:49.218627 2026] [security2:error] [pid 782784:tid 783007] [client 172.202.44.182:61759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/blog.php"] [unique_id "amuORYaApLsOvtuGcVrAQAAAAF0"]
[Thu Jul 30 12:47:49.340862 2026] [security2:error] [pid 782784:tid 783031] [client 43.154.140.188:42274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.140.154.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/theme/darm_theme_basic01/page_html/company_ceo.php"] [unique_id "amuORYaApLsOvtuGcVrARwAAAHU"]
[Thu Jul 30 12:47:49.387870 2026] [security2:error] [pid 782784:tid 782828] [remote 74.7.241.59:53752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuORYaApLsOvtuGcVrASwAAdis"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/classes
[Thu Jul 30 12:47:49.653412 2026] [core:notice] [pid 782784:tid 782930] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:49.657404 2026] [security2:error] [pid 782784:tid 782930] [client 103.215.74.26:36834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "755"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuORYaApLsOvtuGcVrATQAAABA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:50.164870 2026] [security2:error] [pid 782784:tid 782955] [client 172.202.44.182:18380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/ini.php"] [unique_id "amuORoaApLsOvtuGcVrAWwAAACk"]
[Thu Jul 30 12:47:50.383247 2026] [core:notice] [pid 782784:tid 782987] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:50.387212 2026] [security2:error] [pid 782784:tid 782987] [client 103.215.74.26:36846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuORoaApLsOvtuGcVrAYwAAAEk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:50.504236 2026] [security2:error] [pid 782784:tid 782960] [client 198.44.157.146:48996] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuORoaApLsOvtuGcVrAawAAAC4"]
[Thu Jul 30 12:47:50.504341 2026] [security2:error] [pid 782784:tid 782960] [client 198.44.157.146:48996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuORoaApLsOvtuGcVrAawAAAC4"]
[Thu Jul 30 12:47:50.591590 2026] [core:notice] [pid 782784:tid 782855] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:51.108581 2026] [core:notice] [pid 782784:tid 782926] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:51.113101 2026] [security2:error] [pid 782784:tid 782926] [client 103.215.74.26:36854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOR4aApLsOvtuGcVrAeQAAAAw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:51.116024 2026] [security2:error] [pid 782784:tid 783041] [client 172.202.44.182:18393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/admin-ajax.php"] [unique_id "amuOR4aApLsOvtuGcVrAegAAAH8"]
[Thu Jul 30 12:47:51.158862 2026] [core:notice] [pid 782784:tid 782905] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:51.847242 2026] [core:notice] [pid 782784:tid 783039] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:51.851225 2026] [security2:error] [pid 782784:tid 783039] [client 103.215.74.26:36866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOR4aApLsOvtuGcVrAiwAAAH0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:52.059872 2026] [core:notice] [pid 782784:tid 782819] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:52.083822 2026] [security2:error] [pid 782784:tid 783014] [client 20.151.221.234:42934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wk/index.php"] [unique_id "amuOSIaApLsOvtuGcVrAlgAAAGQ"]
[Thu Jul 30 12:47:52.109990 2026] [security2:error] [pid 782784:tid 783025] [client 172.202.44.182:61735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/akc.php"] [unique_id "amuOSIaApLsOvtuGcVrAlwAAAG8"]
[Thu Jul 30 12:47:52.432829 2026] [core:notice] [pid 782784:tid 782845] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:52.455203 2026] [security2:error] [pid 782784:tid 783000] [client 2a03:2880:f800:a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOR4aApLsOvtuGcVrAigAAVjU"]
[Thu Jul 30 12:47:52.812988 2026] [security2:error] [pid 782784:tid 783019] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOSIaApLsOvtuGcVrAmgAAAGk"]
[Thu Jul 30 12:47:52.971543 2026] [security2:error] [pid 782784:tid 782812] [remote 97.74.87.194:33324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/wp-login.php"] [unique_id "amuOSIaApLsOvtuGcVrArwAAHhs"]
[Thu Jul 30 12:47:53.192693 2026] [security2:error] [pid 782784:tid 782960] [client 172.202.44.182:22433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/akcc.php"] [unique_id "amuOSYaApLsOvtuGcVrAtQAAAC4"]
[Thu Jul 30 12:47:53.203770 2026] [security2:error] [pid 782784:tid 783008] [client 20.151.221.234:23148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/av.php"] [unique_id "amuOSYaApLsOvtuGcVrAtgAAAF4"]
[Thu Jul 30 12:47:54.055270 2026] [proxy:error] [pid 782784:tid 782832] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:47:54.055327 2026] [proxy_http:error] [pid 782784:tid 782832] [remote 74.7.241.161:49512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:47:54.055876 2026] [proxy:error] [pid 782784:tid 782832] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:47:54.055918 2026] [proxy_http:error] [pid 782784:tid 782832] [remote 74.7.241.161:49512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:47:54.559683 2026] [security2:error] [pid 782784:tid 782846] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuOSoaApLsOvtuGcVrA7gAAcD0"]
[Thu Jul 30 12:47:54.887692 2026] [security2:error] [pid 782784:tid 782961] [client 172.202.44.182:22427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/asasx.php"] [unique_id "amuOSoaApLsOvtuGcVrA8wAAAC8"]
[Thu Jul 30 12:47:55.090462 2026] [autoindex:error] [pid 782784:tid 782970] [client 170.106.163.48:33900] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:47:55.331186 2026] [security2:error] [pid 782784:tid 783020] [client 20.151.221.234:42932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/mini.php"] [unique_id "amuOS4aApLsOvtuGcVrBBQAAAGo"]
[Thu Jul 30 12:47:55.629862 2026] [security2:error] [pid 782784:tid 782847] [remote 57.141.0.4:28024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amuOS4aApLsOvtuGcVrBDwAAET4"]
[Thu Jul 30 12:47:55.875865 2026] [security2:error] [pid 782784:tid 782951] [client 20.215.191.139:44437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/011i.php"] [unique_id "amuOS4aApLsOvtuGcVrBFAAAACU"]
[Thu Jul 30 12:47:56.140653 2026] [security2:error] [pid 782784:tid 783003] [client 172.202.44.182:61713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/axx.php"] [unique_id "amuOTIaApLsOvtuGcVrBHwAAAFk"]
[Thu Jul 30 12:47:56.350829 2026] [security2:error] [pid 782784:tid 782945] [client 20.215.191.139:64490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/03a005685d.php"] [unique_id "amuOTIaApLsOvtuGcVrBIwAAAB8"]
[Thu Jul 30 12:47:56.798723 2026] [security2:error] [pid 782784:tid 783023] [client 20.215.191.139:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/403.php"] [unique_id "amuOTIaApLsOvtuGcVrBMgAAAG0"]
[Thu Jul 30 12:47:56.908184 2026] [security2:error] [pid 782784:tid 783024] [client 20.151.221.234:42901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/aa.php"] [unique_id "amuOTIaApLsOvtuGcVrBNgAAAG4"]
[Thu Jul 30 12:47:57.181858 2026] [security2:error] [pid 782784:tid 783041] [client 5.161.113.195:47752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuOS4aApLsOvtuGcVrBFQAAAH8"], referer: https://globalmarks.pk/
[Thu Jul 30 12:47:57.248533 2026] [security2:error] [pid 782784:tid 782954] [client 20.215.191.139:64495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/404.php"] [unique_id "amuOTYaApLsOvtuGcVrBQgAAACg"]
[Thu Jul 30 12:47:57.291510 2026] [security2:error] [pid 782784:tid 783038] [client 172.202.44.182:18406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/berax.php"] [unique_id "amuOTYaApLsOvtuGcVrBRAAAAHw"]
[Thu Jul 30 12:47:57.432133 2026] [security2:error] [pid 782784:tid 782939] [client 74.7.230.24:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-99a4e2be.qhp.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuOSYaApLsOvtuGcVrAxgAAABk"]
[Thu Jul 30 12:47:57.432903 2026] [security2:error] [pid 782784:tid 782975] [client 74.7.230.24:41496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-99a4e2be.qhp.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuOSYaApLsOvtuGcVrAxAAAPQw"]
[Thu Jul 30 12:47:57.681388 2026] [http2:info] [pid 806041:tid 806041] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:47:57.694309 2026] [core:notice] [pid 782784:tid 783001] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:57.697343 2026] [security2:error] [pid 782784:tid 782918] [client 20.215.191.139:44477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/aa.php"] [unique_id "amuOTYaApLsOvtuGcVrBSwAAAAQ"]
[Thu Jul 30 12:47:57.698386 2026] [security2:error] [pid 782784:tid 783001] [client 103.215.74.26:60822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOTYaApLsOvtuGcVrBSgAAAFc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:57.803295 2026] [security2:error] [pid 806041:tid 806169] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOTULAyZ1MRInzPMb1ZwAAhn8"]
[Thu Jul 30 12:47:57.803483 2026] [security2:error] [pid 806041:tid 806172] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOTULAyZ1MRInzPMb1ZwAAhn8"]
[Thu Jul 30 12:47:58.144378 2026] [security2:error] [pid 806041:tid 806176] [client 20.215.191.139:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/aafewc0k.php"] [unique_id "amuOTkLAyZ1MRInzPMb1aAAAAIo"]
[Thu Jul 30 12:47:58.248925 2026] [security2:error] [pid 806041:tid 806175] [client 172.202.44.182:22411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/build.php"] [unique_id "amuOTkLAyZ1MRInzPMb1bwAAAIk"]
[Thu Jul 30 12:47:58.420362 2026] [core:notice] [pid 806041:tid 806179] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:58.425768 2026] [security2:error] [pid 806041:tid 806179] [client 103.215.74.26:60824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOTkLAyZ1MRInzPMb1cAAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:58.490306 2026] [security2:error] [pid 806041:tid 806193] [client 184.154.36.186:60964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ecre.ae"] [uri "/index.php"] [unique_id "amuOTkLAyZ1MRInzPMb1cQAAAJs"], referer: http://www.google.com/url?url=www.ecre.ae&yahoo.com
[Thu Jul 30 12:47:58.607636 2026] [security2:error] [pid 806041:tid 806194] [client 20.215.191.139:44450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/abcd.php"] [unique_id "amuOTkLAyZ1MRInzPMb1eAAAAJw"]
[Thu Jul 30 12:47:58.949556 2026] [fcgid:warn] [pid 806041:tid 806219] (70014)End of file found: [client 118.26.104.93:38520] mod_fcgid: can't get data from http client
[Thu Jul 30 12:47:59.058799 2026] [security2:error] [pid 806041:tid 806214] [client 20.215.191.139:44418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/about.php"] [unique_id "amuOT0LAyZ1MRInzPMb1gQAAALA"]
[Thu Jul 30 12:47:59.153532 2026] [core:notice] [pid 806041:tid 806215] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:47:59.158326 2026] [security2:error] [pid 806041:tid 806215] [client 103.215.74.26:60828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOT0LAyZ1MRInzPMb1hQAAALE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:47:59.256812 2026] [security2:error] [pid 806041:tid 806212] [client 20.151.221.234:42940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/w.php"] [unique_id "amuOT0LAyZ1MRInzPMb1iQAAAK4"]
[Thu Jul 30 12:47:59.513852 2026] [security2:error] [pid 806041:tid 806236] [client 20.215.191.139:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/admin.php"] [unique_id "amuOT0LAyZ1MRInzPMb1jQAAAMY"]
[Thu Jul 30 12:47:59.530343 2026] [security2:error] [pid 806041:tid 806247] [client 150.107.232.194:26778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOT0LAyZ1MRInzPMb1jgAAANE"]
[Thu Jul 30 12:47:59.530512 2026] [security2:error] [pid 806041:tid 806247] [client 150.107.232.194:26778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOT0LAyZ1MRInzPMb1jgAAANE"]
[Thu Jul 30 12:47:59.871239 2026] [security2:error] [pid 806041:tid 806242] [client 172.202.44.182:61706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/buy.php"] [unique_id "amuOT0LAyZ1MRInzPMb1nwAAAMw"]
[Thu Jul 30 12:47:59.970931 2026] [security2:error] [pid 806041:tid 806266] [client 20.215.191.139:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/adminfuns.php"] [unique_id "amuOT0LAyZ1MRInzPMb1oAAAAOQ"]
[Thu Jul 30 12:48:00.226885 2026] [security2:error] [pid 806041:tid 806253] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOT0LAyZ1MRInzPMb1lAAAANc"]
[Thu Jul 30 12:48:00.424139 2026] [security2:error] [pid 806041:tid 806295] [client 20.215.191.139:64460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/albin.php"] [unique_id "amuOUELAyZ1MRInzPMb1rgAAAQE"]
[Thu Jul 30 12:48:00.465884 2026] [security2:error] [pid 806041:tid 806264] [client 20.151.221.234:52262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/admin.php"] [unique_id "amuOUELAyZ1MRInzPMb1sAAAAOI"]
[Thu Jul 30 12:48:00.849564 2026] [security2:error] [pid 806041:tid 806183] [client 172.202.44.182:18389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/checkbox.php"] [unique_id "amuOUELAyZ1MRInzPMb1vQAAAJE"]
[Thu Jul 30 12:48:00.962918 2026] [security2:error] [pid 806041:tid 806197] [client 20.215.191.139:44459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/amfsqvgv.php"] [unique_id "amuOUELAyZ1MRInzPMb1wAAAAJ8"]
[Thu Jul 30 12:48:01.004149 2026] [core:notice] [pid 806041:tid 806296] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:01.266615 2026] [proxy:error] [pid 806041:tid 806209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:01.266699 2026] [proxy_http:error] [pid 806041:tid 806209] [client 52.202.41.153:63742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:01.267886 2026] [proxy:error] [pid 806041:tid 806209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:01.267944 2026] [proxy_http:error] [pid 806041:tid 806209] [client 52.202.41.153:63742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:01.317490 2026] [proxy:error] [pid 806041:tid 806214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:01.317565 2026] [proxy_http:error] [pid 806041:tid 806214] [client 52.202.41.153:8752] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:01.318312 2026] [proxy:error] [pid 806041:tid 806214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:01.318370 2026] [proxy_http:error] [pid 806041:tid 806214] [client 52.202.41.153:8752] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:01.412964 2026] [security2:error] [pid 806041:tid 806229] [client 20.215.191.139:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/ant.php"] [unique_id "amuOUULAyZ1MRInzPMb11gAAAL8"]
[Thu Jul 30 12:48:01.603965 2026] [security2:error] [pid 806041:tid 806297] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOUELAyZ1MRInzPMb1vwABAxo"]
[Thu Jul 30 12:48:01.723346 2026] [security2:error] [pid 806041:tid 806213] [client 172.202.44.182:52638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/cong.php"] [unique_id "amuOUULAyZ1MRInzPMb14AAAAK8"]
[Thu Jul 30 12:48:01.861959 2026] [security2:error] [pid 806041:tid 806196] [client 20.215.191.139:44470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/appreciators.php"] [unique_id "amuOUULAyZ1MRInzPMb15QAAAJ4"]
[Thu Jul 30 12:48:01.918985 2026] [core:notice] [pid 806041:tid 806077] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:02.308972 2026] [security2:error] [pid 806041:tid 806288] [client 20.215.191.139:43989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/archive.php"] [unique_id "amuOUkLAyZ1MRInzPMb19AAAAPo"]
[Thu Jul 30 12:48:02.757762 2026] [security2:error] [pid 806041:tid 806171] [client 20.215.191.139:44468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/as.php"] [unique_id "amuOUkLAyZ1MRInzPMb1-wAAAIU"]
[Thu Jul 30 12:48:03.230470 2026] [security2:error] [pid 806041:tid 806204] [client 20.215.191.139:64498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/atomlib.php"] [unique_id "amuOU0LAyZ1MRInzPMb2BwAAAKY"]
[Thu Jul 30 12:48:03.474783 2026] [security2:error] [pid 806041:tid 806193] [client 172.202.44.182:52615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/file4.php"] [unique_id "amuOU0LAyZ1MRInzPMb2DgAAAJs"]
[Thu Jul 30 12:48:03.702938 2026] [security2:error] [pid 806041:tid 806212] [client 20.215.191.139:64491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/autoload_classmap.php"] [unique_id "amuOU0LAyZ1MRInzPMb2GQAAAK4"]
[Thu Jul 30 12:48:03.903126 2026] [security2:error] [pid 806041:tid 806206] [client 20.151.221.234:52253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuOU0LAyZ1MRInzPMb2IAAAAKg"]
[Thu Jul 30 12:48:04.193915 2026] [security2:error] [pid 806041:tid 806263] [client 20.215.191.139:44417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/bb.php"] [unique_id "amuOVELAyZ1MRInzPMb2IgAAAOE"]
[Thu Jul 30 12:48:04.318692 2026] [security2:error] [pid 806041:tid 806214] [client 43.157.22.109:34522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.22.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/prougj/issue/current"] [unique_id "amuOVELAyZ1MRInzPMb2KgAAALA"], referer: https://ejournalugj.com/index_php/prougj/issue/current
[Thu Jul 30 12:48:04.319533 2026] [core:notice] [pid 806041:tid 806274] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:04.534233 2026] [security2:error] [pid 806041:tid 806275] [client 172.202.44.182:18371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/flower.php"] [unique_id "amuOVELAyZ1MRInzPMb2LwAAAO0"]
[Thu Jul 30 12:48:04.643194 2026] [security2:error] [pid 806041:tid 806283] [client 20.215.191.139:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/bnm.php"] [unique_id "amuOVELAyZ1MRInzPMb2MAAAAPU"]
[Thu Jul 30 12:48:04.752948 2026] [security2:error] [pid 806041:tid 806289] [client 20.151.221.234:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/m.php"] [unique_id "amuOVELAyZ1MRInzPMb2NAAAAPs"]
[Thu Jul 30 12:48:04.782903 2026] [core:notice] [pid 806041:tid 806293] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:04.925298 2026] [core:notice] [pid 806041:tid 806292] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:04.930822 2026] [security2:error] [pid 806041:tid 806292] [client 103.215.74.26:58850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOVELAyZ1MRInzPMb2OQAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:05.096770 2026] [security2:error] [pid 806041:tid 806188] [client 20.215.191.139:64508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/bootstrap.php"] [unique_id "amuOVULAyZ1MRInzPMb2QAAAAJY"]
[Thu Jul 30 12:48:05.414196 2026] [proxy:error] [pid 806041:tid 806177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:05.414261 2026] [proxy_http:error] [pid 806041:tid 806177] [client 98.87.102.177:14988] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:05.415027 2026] [proxy:error] [pid 806041:tid 806177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:05.415075 2026] [proxy_http:error] [pid 806041:tid 806177] [client 98.87.102.177:14988] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:05.446871 2026] [proxy:error] [pid 806041:tid 806208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:05.446951 2026] [proxy_http:error] [pid 806041:tid 806208] [client 18.211.55.47:20300] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:05.447610 2026] [proxy:error] [pid 806041:tid 806208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:05.447661 2026] [proxy_http:error] [pid 806041:tid 806208] [client 18.211.55.47:20300] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:05.547244 2026] [security2:error] [pid 806041:tid 806199] [client 20.215.191.139:43973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/buy.php"] [unique_id "amuOVULAyZ1MRInzPMb2VwAAAKE"]
[Thu Jul 30 12:48:05.636923 2026] [security2:error] [pid 806041:tid 806106] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known//index.php"] [unique_id "amuOVULAyZ1MRInzPMb2WAAAs0A"]
[Thu Jul 30 12:48:05.652383 2026] [core:notice] [pid 806041:tid 806215] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:05.657782 2026] [security2:error] [pid 806041:tid 806215] [client 103.215.74.26:58858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOVULAyZ1MRInzPMb2WQAAALE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:05.691143 2026] [security2:error] [pid 806041:tid 806189] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOVULAyZ1MRInzPMb2QwAAAJc"]
[Thu Jul 30 12:48:05.741464 2026] [security2:error] [pid 806041:tid 806227] [client 20.151.221.234:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuOVULAyZ1MRInzPMb2WgAAAL0"]
[Thu Jul 30 12:48:05.841929 2026] [security2:error] [pid 806041:tid 806291] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOVULAyZ1MRInzPMb2RAAA_Tw"]
[Thu Jul 30 12:48:05.997370 2026] [security2:error] [pid 806041:tid 806251] [client 20.215.191.139:44005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/chosen.php"] [unique_id "amuOVULAyZ1MRInzPMb2YgAAANU"]
[Thu Jul 30 12:48:06.384422 2026] [core:notice] [pid 806041:tid 806276] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:06.389781 2026] [security2:error] [pid 806041:tid 806276] [client 103.215.74.26:58866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOVkLAyZ1MRInzPMb2cQAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:06.462988 2026] [security2:error] [pid 806041:tid 806284] [client 20.215.191.139:44030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/class-wp-image.php"] [unique_id "amuOVkLAyZ1MRInzPMb2dAAAAPY"]
[Thu Jul 30 12:48:06.467362 2026] [security2:error] [pid 806041:tid 806200] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOVULAyZ1MRInzPMb2XgAAokI"]
[Thu Jul 30 12:48:06.911027 2026] [security2:error] [pid 806041:tid 806194] [client 20.215.191.139:44446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/classsmtps.php"] [unique_id "amuOVkLAyZ1MRInzPMb2hQAAAJw"]
[Thu Jul 30 12:48:07.136741 2026] [core:notice] [pid 806041:tid 806203] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:07.142119 2026] [security2:error] [pid 806041:tid 806203] [client 103.215.74.26:58870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOV0LAyZ1MRInzPMb2jAAAAKU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:07.219638 2026] [core:notice] [pid 806041:tid 806202] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:07.357141 2026] [core:error] [pid 806041:tid 806227] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:07.357165 2026] [core:error] [pid 806041:tid 806227] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:07.375641 2026] [core:error] [pid 806041:tid 806247] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:07.375671 2026] [core:error] [pid 806041:tid 806247] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:07.436659 2026] [core:error] [pid 806041:tid 806249] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:07.436684 2026] [core:error] [pid 806041:tid 806249] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:07.566224 2026] [security2:error] [pid 806041:tid 806248] [client 20.215.191.139:43918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/classwithtostring.php"] [unique_id "amuOV0LAyZ1MRInzPMb2owAAANI"]
[Thu Jul 30 12:48:07.809519 2026] [core:notice] [pid 806041:tid 806268] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:07.876561 2026] [core:notice] [pid 806041:tid 806280] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:07.881681 2026] [security2:error] [pid 806041:tid 806280] [client 103.215.74.26:58884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOV0LAyZ1MRInzPMb2rgAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:07.969333 2026] [security2:error] [pid 806041:tid 806178] [client 20.151.221.234:23126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/classwithtostring.php"] [unique_id "amuOV0LAyZ1MRInzPMb2swAAAIw"]
[Thu Jul 30 12:48:08.230093 2026] [security2:error] [pid 806041:tid 806184] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOV0LAyZ1MRInzPMb2pgAAklI"]
[Thu Jul 30 12:48:08.276082 2026] [security2:error] [pid 806041:tid 806283] [client 20.215.191.139:62091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/config.php"] [unique_id "amuOWELAyZ1MRInzPMb2uwAAAPU"]
[Thu Jul 30 12:48:08.565341 2026] [security2:error] [pid 806041:tid 806131] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOWELAyZ1MRInzPMb2vwAAiVk"]
[Thu Jul 30 12:48:08.565540 2026] [security2:error] [pid 806041:tid 806175] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOWELAyZ1MRInzPMb2vwAAiVk"]
[Thu Jul 30 12:48:08.636723 2026] [core:notice] [pid 806041:tid 806181] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:08.644174 2026] [security2:error] [pid 806041:tid 806181] [client 103.215.74.26:58886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOWELAyZ1MRInzPMb2xwAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:08.856004 2026] [security2:error] [pid 806041:tid 806224] [client 20.215.191.139:44423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/core.php"] [unique_id "amuOWELAyZ1MRInzPMb2yAAAALo"]
[Thu Jul 30 12:48:09.379912 2026] [security2:error] [pid 806041:tid 806247] [client 20.215.191.139:62081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/css.php"] [unique_id "amuOWULAyZ1MRInzPMb22AAAANE"]
[Thu Jul 30 12:48:09.385706 2026] [core:notice] [pid 806041:tid 806218] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:09.391446 2026] [security2:error] [pid 806041:tid 806218] [client 103.215.74.26:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOWULAyZ1MRInzPMb22QAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:09.464109 2026] [security2:error] [pid 806041:tid 806240] [client 118.26.104.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "website-2f97271e.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuOWULAyZ1MRInzPMb21wAAAMo"]
[Thu Jul 30 12:48:09.881510 2026] [security2:error] [pid 806041:tid 806255] [client 20.215.191.139:43948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/database.php"] [unique_id "amuOWULAyZ1MRInzPMb25wAAANk"]
[Thu Jul 30 12:48:09.912071 2026] [security2:error] [pid 806041:tid 806238] [client 20.151.221.234:42941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/gmo.php"] [unique_id "amuOWULAyZ1MRInzPMb26QAAAMg"]
[Thu Jul 30 12:48:09.996801 2026] [security2:error] [pid 806041:tid 806275] [client 150.107.232.194:26952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOWULAyZ1MRInzPMb27QAAAO0"]
[Thu Jul 30 12:48:09.996916 2026] [security2:error] [pid 806041:tid 806275] [client 150.107.232.194:26952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOWULAyZ1MRInzPMb27QAAAO0"]
[Thu Jul 30 12:48:10.152850 2026] [core:notice] [pid 806041:tid 806268] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:10.157729 2026] [security2:error] [pid 806041:tid 806268] [client 103.215.74.26:58906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOWkLAyZ1MRInzPMb28gAAAOY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:10.376324 2026] [security2:error] [pid 806041:tid 806173] [client 20.215.191.139:44639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/db.php"] [unique_id "amuOWkLAyZ1MRInzPMb2-QAAAIc"]
[Thu Jul 30 12:48:10.850074 2026] [security2:error] [pid 806041:tid 806210] [client 20.215.191.139:43940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/default.php"] [unique_id "amuOWkLAyZ1MRInzPMb3BgAAAKw"]
[Thu Jul 30 12:48:10.900074 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:10.904284 2026] [security2:error] [pid 806041:tid 806205] [client 103.215.74.26:58912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "752"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOWkLAyZ1MRInzPMb3BwAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:11.336273 2026] [security2:error] [pid 806041:tid 806202] [client 20.215.191.139:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/dropdown.php"] [unique_id "amuOW0LAyZ1MRInzPMb3EgAAAKQ"]
[Thu Jul 30 12:48:11.636643 2026] [core:notice] [pid 806041:tid 806247] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:11.640931 2026] [security2:error] [pid 806041:tid 806247] [client 103.215.74.26:58926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "749"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOW0LAyZ1MRInzPMb3GwAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:11.673912 2026] [security2:error] [pid 806041:tid 806296] [client 172.202.44.182:21826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/form.php"] [unique_id "amuOW0LAyZ1MRInzPMb3HAAAAQI"]
[Thu Jul 30 12:48:11.836318 2026] [security2:error] [pid 806041:tid 806214] [client 20.215.191.139:62142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/edit.php"] [unique_id "amuOW0LAyZ1MRInzPMb3IwAAALA"]
[Thu Jul 30 12:48:12.095403 2026] [security2:error] [pid 806041:tid 806218] [client 20.151.221.234:23158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuOXELAyZ1MRInzPMb3JgAAALQ"]
[Thu Jul 30 12:48:12.171269 2026] [security2:error] [pid 806041:tid 806252] [client 145.239.10.137:45365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/zatura.php"] [unique_id "amuOXELAyZ1MRInzPMb3KAAAANY"], referer: http://dhowcruisedinner.com/zatura.php
[Thu Jul 30 12:48:12.305342 2026] [security2:error] [pid 806041:tid 806178] [client 20.215.191.139:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/f35.php"] [unique_id "amuOXELAyZ1MRInzPMb3LgAAAIw"]
[Thu Jul 30 12:48:12.823086 2026] [security2:error] [pid 806041:tid 806183] [client 20.215.191.139:44642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/f7.php"] [unique_id "amuOXELAyZ1MRInzPMb3OQAAAJE"]
[Thu Jul 30 12:48:13.009876 2026] [security2:error] [pid 806041:tid 806184] [client 35.178.82.224:53642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/05/parlx-services-commercial-5.jpg"] [unique_id "amuOXELAyZ1MRInzPMb3MgAAknU"]
[Thu Jul 30 12:48:13.024294 2026] [security2:error] [pid 806041:tid 806298] [client 172.202.44.182:21661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/gecko.php"] [unique_id "amuOXULAyZ1MRInzPMb3PQAAAQQ"]
[Thu Jul 30 12:48:13.094467 2026] [core:notice] [pid 806041:tid 806163] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:13.176156 2026] [security2:error] [pid 806041:tid 806244] [client 184.154.36.186:59830] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ecre.ae"] [uri "/index.php"] [unique_id "amuOXULAyZ1MRInzPMb3QgAAAM4"]
[Thu Jul 30 12:48:13.242477 2026] [core:notice] [pid 806041:tid 806272] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:13.506036 2026] [core:notice] [pid 806041:tid 806223] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:14.905584 2026] [security2:error] [pid 806041:tid 806246] [client 86.106.84.166:51338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuOXkLAyZ1MRInzPMb3XgAAANA"]
[Thu Jul 30 12:48:14.905732 2026] [security2:error] [pid 806041:tid 806246] [client 86.106.84.166:51338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuOXkLAyZ1MRInzPMb3XgAAANA"]
[Thu Jul 30 12:48:15.472402 2026] [security2:error] [pid 806041:tid 806239] [client 172.202.44.182:18425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/kyami.php"] [unique_id "amuOX0LAyZ1MRInzPMb3bgAAAMk"]
[Thu Jul 30 12:48:16.705878 2026] [security2:error] [pid 806041:tid 806229] [client 172.202.44.182:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/manager.php"] [unique_id "amuOYELAyZ1MRInzPMb3iwAAAL8"]
[Thu Jul 30 12:48:17.359873 2026] [core:notice] [pid 806041:tid 806257] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:17.365332 2026] [security2:error] [pid 806041:tid 806257] [client 103.215.74.26:47736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOYULAyZ1MRInzPMb3nQAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:17.477125 2026] [security2:error] [pid 806041:tid 806237] [client 68.221.186.136:27926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/011i.php"] [unique_id "amuOYULAyZ1MRInzPMb3oQAAAMc"]
[Thu Jul 30 12:48:17.647645 2026] [security2:error] [pid 806041:tid 806263] [client 185.191.171.6:16414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/23/homem-e-esfaqueado-apos-briga-na-feira-livre-de-guarabira-ele-me-xingava-toda-vez-que-me-encontrava-e-hoje-nao-me-segurei/"] [unique_id "amuOYULAyZ1MRInzPMb3ogAAAOE"]
[Thu Jul 30 12:48:17.647825 2026] [security2:error] [pid 806041:tid 806263] [client 185.191.171.6:16414] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/23/homem-e-esfaqueado-apos-briga-na-feira-livre-de-guarabira-ele-me-xingava-toda-vez-que-me-encontrava-e-hoje-nao-me-segurei/"] [unique_id "amuOYULAyZ1MRInzPMb3ogAAAOE"]
[Thu Jul 30 12:48:17.659297 2026] [security2:error] [pid 806041:tid 806267] [client 20.151.221.234:42887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-the.php"] [unique_id "amuOYULAyZ1MRInzPMb3owAAAOU"]
[Thu Jul 30 12:48:17.768912 2026] [security2:error] [pid 806041:tid 806282] [client 172.202.44.182:21840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/mari.php"] [unique_id "amuOYULAyZ1MRInzPMb3pwAAAPQ"]
[Thu Jul 30 12:48:17.858111 2026] [security2:error] [pid 806041:tid 806265] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOYULAyZ1MRInzPMb3mgAA4ww"]
[Thu Jul 30 12:48:18.101348 2026] [core:notice] [pid 806041:tid 806213] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:18.113925 2026] [security2:error] [pid 806041:tid 806213] [client 103.215.74.26:47750] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOYkLAyZ1MRInzPMb3rwAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:18.457838 2026] [security2:error] [pid 806041:tid 806242] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOYULAyZ1MRInzPMb3qwAAzBs"]
[Thu Jul 30 12:48:18.656988 2026] [security2:error] [pid 806041:tid 806219] [client 20.151.221.234:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/404.php"] [unique_id "amuOYkLAyZ1MRInzPMb3vQAAALU"]
[Thu Jul 30 12:48:18.658834 2026] [security2:error] [pid 806041:tid 806293] [client 172.202.44.182:21665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/nc4.php"] [unique_id "amuOYkLAyZ1MRInzPMb3vgAAAP8"]
[Thu Jul 30 12:48:18.848868 2026] [core:notice] [pid 806041:tid 806234] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:18.856224 2026] [security2:error] [pid 806041:tid 806234] [client 103.215.74.26:47758] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOYkLAyZ1MRInzPMb3yAAAAMQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:19.390600 2026] [security2:error] [pid 806041:tid 806078] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOY0LAyZ1MRInzPMb30wAAmiQ"]
[Thu Jul 30 12:48:19.390769 2026] [security2:error] [pid 806041:tid 806192] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOY0LAyZ1MRInzPMb30wAAmiQ"]
[Thu Jul 30 12:48:19.500397 2026] [autoindex:error] [pid 806041:tid 806285] [client 43.159.62.129:49280] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:48:19.578248 2026] [core:notice] [pid 806041:tid 806266] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:19.583221 2026] [security2:error] [pid 806041:tid 806266] [client 103.215.74.26:47760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "750"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOY0LAyZ1MRInzPMb32AAAAOQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:19.919750 2026] [security2:error] [pid 806041:tid 806262] [client 20.151.221.234:44845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/init.php"] [unique_id "amuOY0LAyZ1MRInzPMb33wAAAOA"]
[Thu Jul 30 12:48:19.961970 2026] [cgid:error] [pid 806041:tid 806247] [client 172.202.44.182:18415] AH01265: stderr from /home1/nfinyxte/public_html/website_14d99ba9/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:48:20.180253 2026] [autoindex:error] [pid 806041:tid 806275] [client 20.9.4.9:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_26e591d8/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:48:20.181011 2026] [security2:error] [pid 806041:tid 806275] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "chimnify.services"] [uri "/cgi-sys/403.html"] [unique_id "amuOZELAyZ1MRInzPMb35AAAAO0"]
[Thu Jul 30 12:48:20.363396 2026] [core:notice] [pid 806041:tid 806268] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:20.367258 2026] [security2:error] [pid 806041:tid 806268] [client 103.215.74.26:47762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "768"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOZELAyZ1MRInzPMb36AAAAOY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:20.474659 2026] [security2:error] [pid 806041:tid 806186] [client 223.109.255.168:44398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carnetdeshopping.com"] [uri "/un-soir-en-ete-esthederm"] [unique_id "amuOZELAyZ1MRInzPMb37QAAAJQ"]
[Thu Jul 30 12:48:20.474744 2026] [security2:error] [pid 806041:tid 806186] [client 223.109.255.168:44398] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "carnetdeshopping.com"] [uri "/un-soir-en-ete-esthederm"] [unique_id "amuOZELAyZ1MRInzPMb37QAAAJQ"]
[Thu Jul 30 12:48:20.475334 2026] [security2:error] [pid 806041:tid 806174] [client 150.107.232.194:27405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOZELAyZ1MRInzPMb37gAAAIg"]
[Thu Jul 30 12:48:20.475415 2026] [security2:error] [pid 806041:tid 806174] [client 150.107.232.194:27405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOZELAyZ1MRInzPMb37gAAAIg"]
[Thu Jul 30 12:48:20.530416 2026] [core:notice] [pid 806041:tid 806095] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:21.094255 2026] [core:notice] [pid 806041:tid 806298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:21.101102 2026] [security2:error] [pid 806041:tid 806298] [client 103.215.74.26:47766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOZULAyZ1MRInzPMb4AgAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:21.164043 2026] [core:notice] [pid 806041:tid 806104] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:21.191831 2026] [security2:error] [pid 806041:tid 806184] [client 68.221.186.136:27930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/03a005685d.php"] [unique_id "amuOZULAyZ1MRInzPMb4BQAAAJI"]
[Thu Jul 30 12:48:21.842960 2026] [core:notice] [pid 806041:tid 806235] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:21.847160 2026] [security2:error] [pid 806041:tid 806235] [client 103.215.74.26:47776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "781"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOZULAyZ1MRInzPMb4FgAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:22.162696 2026] [core:notice] [pid 806041:tid 806281] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:22.241112 2026] [security2:error] [pid 806041:tid 806295] [client 68.221.186.136:28006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/403.php"] [unique_id "amuOZkLAyZ1MRInzPMb4JAAAAQE"]
[Thu Jul 30 12:48:22.606159 2026] [core:notice] [pid 806041:tid 806286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:22.611088 2026] [security2:error] [pid 806041:tid 806286] [client 103.215.74.26:47778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "743"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOZkLAyZ1MRInzPMb4KwAAAPg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:22.980418 2026] [security2:error] [pid 806041:tid 806240] [client 20.151.221.234:2374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wk/index.php"] [unique_id "amuOZkLAyZ1MRInzPMb4LwAAAMo"]
[Thu Jul 30 12:48:23.020348 2026] [security2:error] [pid 806041:tid 806248] [client 20.151.221.234:22663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/file5.php"] [unique_id "amuOZ0LAyZ1MRInzPMb4MwAAANI"]
[Thu Jul 30 12:48:23.337794 2026] [core:notice] [pid 806041:tid 806239] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:23.342907 2026] [security2:error] [pid 806041:tid 806239] [client 103.215.74.26:39918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "747"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOZ0LAyZ1MRInzPMb4OgAAAMk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:23.387308 2026] [security2:error] [pid 806041:tid 806120] [remote 57.141.0.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuOZ0LAyZ1MRInzPMb4OwAAlE4"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,lycra,plastic,polyester,steel,nylon&filter_size=large,small&max_price=200&min_price=125&orderby=rating&status=instock&unfilter=1
[Thu Jul 30 12:48:23.431283 2026] [security2:error] [pid 806041:tid 806111] [remote 57.141.0.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuOZ0LAyZ1MRInzPMb4PAAAo0U"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,lycra,plastic,polyester,steel,nylon&filter_size=large,small&max_price=200&min_price=125&orderby=rating&status=instock&unfilter=1
[Thu Jul 30 12:48:24.095738 2026] [core:notice] [pid 806041:tid 806290] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:24.100589 2026] [security2:error] [pid 806041:tid 806290] [client 103.215.74.26:39920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "753"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOaELAyZ1MRInzPMb4SwAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:24.544716 2026] [security2:error] [pid 806041:tid 806232] [client 20.91.199.21:43798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/json.php"] [unique_id "amuOaELAyZ1MRInzPMb4UQAAAMI"]
[Thu Jul 30 12:48:24.759777 2026] [security2:error] [pid 806041:tid 806171] [client 68.221.186.136:28019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/404.php"] [unique_id "amuOaELAyZ1MRInzPMb4WwAAAIU"]
[Thu Jul 30 12:48:24.779015 2026] [security2:error] [pid 806041:tid 806225] [client 20.151.221.234:2339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/av.php"] [unique_id "amuOaELAyZ1MRInzPMb4XAAAALs"]
[Thu Jul 30 12:48:24.843323 2026] [core:notice] [pid 806041:tid 806210] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:24.848362 2026] [security2:error] [pid 806041:tid 806210] [client 103.215.74.26:39930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOaELAyZ1MRInzPMb4XgAAAKw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:25.589516 2026] [security2:error] [pid 806041:tid 806252] [client 20.91.199.21:43393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/mini.php"] [unique_id "amuOaULAyZ1MRInzPMb4bAAAANY"]
[Thu Jul 30 12:48:25.609517 2026] [core:notice] [pid 806041:tid 806182] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:25.614528 2026] [security2:error] [pid 806041:tid 806182] [client 103.215.74.26:39936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOaULAyZ1MRInzPMb4bQAAAJA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:25.729688 2026] [security2:error] [pid 806041:tid 806183] [client 20.151.221.234:62109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/mini.php"] [unique_id "amuOaULAyZ1MRInzPMb4cQAAAJE"]
[Thu Jul 30 12:48:25.808416 2026] [core:notice] [pid 806041:tid 806195] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:26.337923 2026] [core:notice] [pid 806041:tid 806244] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:26.343102 2026] [security2:error] [pid 806041:tid 806244] [client 103.215.74.26:39950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOakLAyZ1MRInzPMb4gAAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:26.370035 2026] [security2:error] [pid 806041:tid 806219] [client 20.91.199.21:43783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/chosen.php"] [unique_id "amuOakLAyZ1MRInzPMb4gQAAALU"]
[Thu Jul 30 12:48:26.510962 2026] [security2:error] [pid 806041:tid 806233] [client 20.151.221.234:37215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuOakLAyZ1MRInzPMb4gwAAAMM"]
[Thu Jul 30 12:48:26.617450 2026] [security2:error] [pid 806041:tid 806258] [client 68.221.186.136:27997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/aa.php"] [unique_id "amuOakLAyZ1MRInzPMb4iAAAANw"]
[Thu Jul 30 12:48:26.779532 2026] [security2:error] [pid 806041:tid 806140] [remote 135.125.175.196:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.175.125.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baitultateeqmoverscompany.com"] [uri "/xmlrpc.php"] [unique_id "amuOakLAyZ1MRInzPMb4hAAA6GI"]
[Thu Jul 30 12:48:26.779739 2026] [security2:error] [pid 806041:tid 806270] [client 135.125.175.196:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "baitultateeqmoverscompany.com"] [uri "/xmlrpc.php"] [unique_id "amuOakLAyZ1MRInzPMb4hAAA6GI"]
[Thu Jul 30 12:48:27.013305 2026] [security2:error] [pid 806041:tid 806272] [client 20.151.221.234:54622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/aa.php"] [unique_id "amuOa0LAyZ1MRInzPMb4kgAAAOo"]
[Thu Jul 30 12:48:27.089962 2026] [core:notice] [pid 806041:tid 806203] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:27.095049 2026] [security2:error] [pid 806041:tid 806203] [client 103.215.74.26:39966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOa0LAyZ1MRInzPMb4kwAAAKU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:27.549523 2026] [security2:error] [pid 806041:tid 806179] [client 68.221.186.136:28008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/aafewc0k.php"] [unique_id "amuOa0LAyZ1MRInzPMb4nQAAAI0"]
[Thu Jul 30 12:48:27.841672 2026] [core:notice] [pid 806041:tid 806178] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:27.846164 2026] [security2:error] [pid 806041:tid 806178] [client 103.215.74.26:39968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOa0LAyZ1MRInzPMb4pwAAAIw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:27.956179 2026] [security2:error] [pid 806041:tid 806267] [client 20.151.221.234:49897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/w.php"] [unique_id "amuOa0LAyZ1MRInzPMb4qAAAAOU"]
[Thu Jul 30 12:48:28.074727 2026] [security2:error] [pid 806041:tid 806295] [client 20.91.199.21:43414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/kj.php"] [unique_id "amuObELAyZ1MRInzPMb4qQAAAQE"]
[Thu Jul 30 12:48:28.112512 2026] [autoindex:error] [pid 806041:tid 806151] [remote 128.14.34.135:49734] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:48:28.555310 2026] [security2:error] [pid 806041:tid 806184] [client 20.91.199.21:37398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.tmb/LA.php"] [unique_id "amuObELAyZ1MRInzPMb4uQAAAJI"]
[Thu Jul 30 12:48:28.830447 2026] [security2:error] [pid 806041:tid 806204] [client 68.221.186.136:27904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/abcd.php"] [unique_id "amuObELAyZ1MRInzPMb4xQAAAKY"]
[Thu Jul 30 12:48:28.849092 2026] [security2:error] [pid 806041:tid 806199] [client 20.91.199.21:43440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/wp-files.php"] [unique_id "amuObELAyZ1MRInzPMb4xwAAAKE"]
[Thu Jul 30 12:48:28.997596 2026] [security2:error] [pid 806041:tid 806215] [client 20.151.221.234:2307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/admin.php"] [unique_id "amuObELAyZ1MRInzPMb4ywAAALE"]
[Thu Jul 30 12:48:29.257791 2026] [security2:error] [pid 806041:tid 806235] [client 20.91.199.21:20392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.tmb/admin.php"] [unique_id "amuObULAyZ1MRInzPMb4zAAAAMU"]
[Thu Jul 30 12:48:29.434028 2026] [security2:error] [pid 806041:tid 806181] [client 2a03:2880:f800:46:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuObELAyZ1MRInzPMb4vwAAj3Y"]
[Thu Jul 30 12:48:29.569424 2026] [security2:error] [pid 806041:tid 806277] [client 68.221.186.136:27909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/about.php"] [unique_id "amuObULAyZ1MRInzPMb42QAAAO8"]
[Thu Jul 30 12:48:29.811073 2026] [autoindex:error] [pid 806041:tid 806287] [client 2600:3c06::f03c:95ff:feea:809f:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:48:30.259848 2026] [security2:error] [pid 806041:tid 806169] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuObkLAyZ1MRInzPMb45AAA1n8"]
[Thu Jul 30 12:48:30.260046 2026] [security2:error] [pid 806041:tid 806252] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuObkLAyZ1MRInzPMb45AAA1n8"]
[Thu Jul 30 12:48:30.353226 2026] [security2:error] [pid 806041:tid 806171] [client 20.91.199.21:43420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/wp-setup.php"] [unique_id "amuObkLAyZ1MRInzPMb46AAAAIU"]
[Thu Jul 30 12:48:30.405523 2026] [autoindex:error] [pid 806041:tid 806174] [client 2600:3c06::f03c:95ff:feea:809f:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:48:30.492344 2026] [fcgid:warn] [pid 806041:tid 806239] (70014)End of file found: [client 18.218.118.203:31684] mod_fcgid: can't get data from http client
[Thu Jul 30 12:48:30.718707 2026] [security2:error] [pid 806041:tid 806267] [client 20.91.199.21:37431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.tmb/class_api.php"] [unique_id "amuObkLAyZ1MRInzPMb48QAAAOU"]
[Thu Jul 30 12:48:30.934935 2026] [security2:error] [pid 806041:tid 806230] [client 150.107.232.194:27446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuObkLAyZ1MRInzPMb49wAAAMA"]
[Thu Jul 30 12:48:30.935069 2026] [security2:error] [pid 806041:tid 806230] [client 150.107.232.194:27446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuObkLAyZ1MRInzPMb49wAAAMA"]
[Thu Jul 30 12:48:31.256542 2026] [security2:error] [pid 806041:tid 806200] [client 68.221.186.136:27969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/admin.php"] [unique_id "amuOb0LAyZ1MRInzPMb4_AAAAKI"]
[Thu Jul 30 12:48:31.505213 2026] [security2:error] [pid 806041:tid 806216] [client 20.91.199.21:20393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuOb0LAyZ1MRInzPMb5AwAAALI"]
[Thu Jul 30 12:48:32.359009 2026] [security2:error] [pid 806041:tid 806248] [client 20.151.221.234:44805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/shell.php"] [unique_id "amuOcELAyZ1MRInzPMb5FgAAANI"]
[Thu Jul 30 12:48:32.599600 2026] [security2:error] [pid 806041:tid 806276] [client 20.151.221.234:54593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuOcELAyZ1MRInzPMb5IQAAAO4"]
[Thu Jul 30 12:48:32.753705 2026] [security2:error] [pid 806041:tid 806273] [client 68.221.186.136:27982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/adminfuns.php"] [unique_id "amuOcELAyZ1MRInzPMb5IgAAAOs"]
[Thu Jul 30 12:48:32.853135 2026] [security2:error] [pid 806041:tid 806203] [client 20.91.199.21:20390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuOcELAyZ1MRInzPMb5IAAAAKU"]
[Thu Jul 30 12:48:33.615205 2026] [security2:error] [pid 806041:tid 806211] [client 20.151.221.234:62135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/m.php"] [unique_id "amuOcULAyZ1MRInzPMb5PAAAAK0"]
[Thu Jul 30 12:48:33.647321 2026] [security2:error] [pid 806041:tid 806294] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOcULAyZ1MRInzPMb5KgAAAQA"]
[Thu Jul 30 12:48:33.671636 2026] [core:notice] [pid 806041:tid 806208] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:33.680227 2026] [security2:error] [pid 806041:tid 806208] [client 103.215.74.26:10024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOcULAyZ1MRInzPMb5QQAAAKo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:33.692097 2026] [security2:error] [pid 806041:tid 806186] [client 68.221.186.136:27977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/albin.php"] [unique_id "amuOcULAyZ1MRInzPMb5QgAAAJQ"]
[Thu Jul 30 12:48:33.838530 2026] [security2:error] [pid 806041:tid 806221] [client 20.91.199.21:34277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuOcULAyZ1MRInzPMb5QwAAALc"]
[Thu Jul 30 12:48:33.995641 2026] [security2:error] [pid 806041:tid 806180] [client 20.91.199.21:43809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/defaults.php"] [unique_id "amuOcULAyZ1MRInzPMb5RAAAAI4"]
[Thu Jul 30 12:48:34.378991 2026] [security2:error] [pid 806041:tid 806245] [client 74.7.228.43:43056] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "adbacklink.online"] [uri "/robots.txt"] [unique_id "amuOckLAyZ1MRInzPMb5TgAAzx8"]
[Thu Jul 30 12:48:34.411511 2026] [core:notice] [pid 806041:tid 806212] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:34.416179 2026] [security2:error] [pid 806041:tid 806212] [client 103.215.74.26:10032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOckLAyZ1MRInzPMb5TwAAAK4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:34.432285 2026] [security2:error] [pid 806041:tid 806260] [client 20.151.221.234:22713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/f35.php"] [unique_id "amuOckLAyZ1MRInzPMb5UAAAAN4"]
[Thu Jul 30 12:48:34.545532 2026] [security2:error] [pid 806041:tid 806223] [client 20.91.199.21:35396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/991176.php"] [unique_id "amuOckLAyZ1MRInzPMb5VQAAALk"]
[Thu Jul 30 12:48:34.815393 2026] [security2:error] [pid 806041:tid 806215] [client 20.91.199.21:43418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/gtc.php"] [unique_id "amuOckLAyZ1MRInzPMb5XAAAALE"]
[Thu Jul 30 12:48:35.090231 2026] [security2:error] [pid 806041:tid 806274] [client 20.151.221.234:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuOc0LAyZ1MRInzPMb5YAAAAOw"]
[Thu Jul 30 12:48:35.139187 2026] [core:notice] [pid 806041:tid 806181] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:35.144211 2026] [security2:error] [pid 806041:tid 806181] [client 103.215.74.26:10048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOc0LAyZ1MRInzPMb5ZAAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:35.269053 2026] [security2:error] [pid 806041:tid 806238] [client 20.91.199.21:35033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuOc0LAyZ1MRInzPMb5aQAAAMg"]
[Thu Jul 30 12:48:35.884611 2026] [core:notice] [pid 806041:tid 806171] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:35.889481 2026] [security2:error] [pid 806041:tid 806171] [client 103.215.74.26:10060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOc0LAyZ1MRInzPMb5cwAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:35.963179 2026] [security2:error] [pid 806041:tid 806278] [client 217.138.252.123:57660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.252.138.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuOc0LAyZ1MRInzPMb5dAAAAPA"]
[Thu Jul 30 12:48:35.963316 2026] [security2:error] [pid 806041:tid 806278] [client 217.138.252.123:57660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuOc0LAyZ1MRInzPMb5dAAAAPA"]
[Thu Jul 30 12:48:36.004090 2026] [security2:error] [pid 806041:tid 806198] [client 20.91.199.21:43400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/import.php"] [unique_id "amuOdELAyZ1MRInzPMb5dQAAAKA"]
[Thu Jul 30 12:48:36.240618 2026] [security2:error] [pid 806041:tid 806230] [client 47.128.111.66:44570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.igetvapesonline.com"] [uri "/robots.txt"] [unique_id "amuOdELAyZ1MRInzPMb5eQAAAMA"]
[Thu Jul 30 12:48:36.312635 2026] [security2:error] [pid 806041:tid 806265] [client 20.151.221.234:44844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/new.php"] [unique_id "amuOdELAyZ1MRInzPMb5fQAAAOM"]
[Thu Jul 30 12:48:36.589430 2026] [security2:error] [pid 806041:tid 806089] [remote 160.191.139.115:45124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.139.191.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amuOdELAyZ1MRInzPMb5hgAAxC8"]
[Thu Jul 30 12:48:36.618033 2026] [core:notice] [pid 806041:tid 806185] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:36.623449 2026] [security2:error] [pid 806041:tid 806185] [client 103.215.74.26:10068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOdELAyZ1MRInzPMb5hwAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:36.667261 2026] [security2:error] [pid 806041:tid 806177] [client 20.91.199.21:43805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/lufix.php"] [unique_id "amuOdELAyZ1MRInzPMb5iwAAAIs"]
[Thu Jul 30 12:48:36.803542 2026] [security2:error] [pid 806041:tid 806092] [remote 74.7.241.60:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuOdELAyZ1MRInzPMb5jwAAtTI"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:48:36.968716 2026] [security2:error] [pid 806041:tid 806190] [client 20.91.199.21:35437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuOdELAyZ1MRInzPMb5kwAAAJg"]
[Thu Jul 30 12:48:37.348175 2026] [core:notice] [pid 806041:tid 806258] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:37.353659 2026] [security2:error] [pid 806041:tid 806258] [client 103.215.74.26:10078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOdULAyZ1MRInzPMb5ngAAANw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:37.591118 2026] [security2:error] [pid 806041:tid 806247] [client 20.91.199.21:35450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuOdULAyZ1MRInzPMb5oQAAANE"]
[Thu Jul 30 12:48:38.082406 2026] [core:notice] [pid 806041:tid 806283] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:38.087170 2026] [security2:error] [pid 806041:tid 806283] [client 103.215.74.26:10080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOdkLAyZ1MRInzPMb5rQAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:38.136436 2026] [security2:error] [pid 806041:tid 806285] [client 20.151.221.234:49985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/adminfuns.php"] [unique_id "amuOdkLAyZ1MRInzPMb5rgAAAPc"]
[Thu Jul 30 12:48:38.250911 2026] [security2:error] [pid 806041:tid 806231] [client 127.0.0.1:51094] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuOdkLAyZ1MRInzPMb5tQAAAME"]
[Thu Jul 30 12:48:38.250928 2026] [security2:error] [pid 806041:tid 806213] [client 127.0.0.1:51086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.embassyofgermanypakistanllc.de"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuOdkLAyZ1MRInzPMb5swAAAK8"]
[Thu Jul 30 12:48:38.251058 2026] [security2:error] [pid 806041:tid 806173] [client 74.7.241.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.embassyofgermanypakistanllc.de"] [uri "/robots.txt"] [unique_id "amuOdkLAyZ1MRInzPMb5sgAAhzs"]
[Thu Jul 30 12:48:38.470608 2026] [security2:error] [pid 806041:tid 806210] [client 20.91.199.21:35069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuOdkLAyZ1MRInzPMb5vAAAAKw"]
[Thu Jul 30 12:48:38.809883 2026] [core:notice] [pid 806041:tid 806256] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:38.817061 2026] [security2:error] [pid 806041:tid 806256] [client 103.215.74.26:10094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOdkLAyZ1MRInzPMb5wQAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:38.886867 2026] [security2:error] [pid 806041:tid 806186] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuOdkLAyZ1MRInzPMb5xwAAAJQ"]
[Thu Jul 30 12:48:38.988050 2026] [security2:error] [pid 806041:tid 806280] [client 74.7.244.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.azeempinksalt.com"] [uri "/index.php"] [unique_id "amuOdULAyZ1MRInzPMb5pQAA8j0"]
[Thu Jul 30 12:48:38.988080 2026] [security2:error] [pid 806041:tid 806280] [client 74.7.244.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.azeempinksalt.com"] [uri "/index.php"] [unique_id "amuOdULAyZ1MRInzPMb5pQAA8j0"]
[Thu Jul 30 12:48:39.376203 2026] [core:error] [pid 806041:tid 806254] [client 20.151.221.234:41367] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:39.376222 2026] [core:error] [pid 806041:tid 806254] [client 20.151.221.234:41367] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:39.399017 2026] [security2:error] [pid 806041:tid 806193] [client 82.102.18.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reviewbyjook.com"] [uri "/xmlrpc.php"] [unique_id "amuOd0LAyZ1MRInzPMb5ywAAAJs"]
[Thu Jul 30 12:48:39.592124 2026] [core:notice] [pid 806041:tid 806177] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:39.596544 2026] [security2:error] [pid 806041:tid 806177] [client 103.215.74.26:10106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "744"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOd0LAyZ1MRInzPMb51gAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:39.744675 2026] [security2:error] [pid 806041:tid 806259] [client 20.91.199.21:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuOd0LAyZ1MRInzPMb52AAAAN0"]
[Thu Jul 30 12:48:40.076582 2026] [security2:error] [pid 806041:tid 806251] [client 74.7.244.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "azeempinksalt.com"] [uri "/index.php"] [unique_id "amuOd0LAyZ1MRInzPMb53wAA1U0"], referer: https://www.azeempinksalt.com/robots.txt
[Thu Jul 30 12:48:40.282451 2026] [security2:error] [pid 806041:tid 806199] [client 20.91.199.21:43804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/Geforce.php"] [unique_id "amuOeELAyZ1MRInzPMb56AAAAKE"]
[Thu Jul 30 12:48:40.323098 2026] [core:notice] [pid 806041:tid 806269] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:40.327223 2026] [security2:error] [pid 806041:tid 806269] [client 103.215.74.26:10108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "741"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOeELAyZ1MRInzPMb56QAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:40.391924 2026] [security2:error] [pid 806041:tid 806274] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuOeELAyZ1MRInzPMb56gAAAOw"]
[Thu Jul 30 12:48:40.392811 2026] [security2:error] [pid 806041:tid 806272] [client 20.151.221.234:62136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/classwithtostring.php"] [unique_id "amuOeELAyZ1MRInzPMb56wAAAOo"]
[Thu Jul 30 12:48:40.414479 2026] [security2:error] [pid 806041:tid 806123] [remote 74.7.241.59:51978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuOeELAyZ1MRInzPMb57AAAzlE"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/classes
[Thu Jul 30 12:48:40.651784 2026] [security2:error] [pid 806041:tid 806173] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuOeELAyZ1MRInzPMb59gAAAIc"]
[Thu Jul 30 12:48:40.913550 2026] [security2:error] [pid 806041:tid 806171] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuOeELAyZ1MRInzPMb5-wAAAIU"]
[Thu Jul 30 12:48:40.922651 2026] [security2:error] [pid 806041:tid 806124] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOeELAyZ1MRInzPMb5_AAA5VI"]
[Thu Jul 30 12:48:40.922790 2026] [security2:error] [pid 806041:tid 806267] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOeELAyZ1MRInzPMb5_AAA5VI"]
[Thu Jul 30 12:48:41.050134 2026] [core:notice] [pid 806041:tid 806239] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:41.054337 2026] [security2:error] [pid 806041:tid 806239] [client 103.215.74.26:10112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOeULAyZ1MRInzPMb6AwAAAMk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:41.176437 2026] [security2:error] [pid 806041:tid 806263] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuOeULAyZ1MRInzPMb6BwAAAOE"]
[Thu Jul 30 12:48:41.258950 2026] [security2:error] [pid 806041:tid 806278] [client 223.177.43.216:58978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.43.177.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuOeULAyZ1MRInzPMb6AAAAAPA"]
[Thu Jul 30 12:48:41.259125 2026] [security2:error] [pid 806041:tid 806278] [client 223.177.43.216:58978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuOeULAyZ1MRInzPMb6AAAAAPA"]
[Thu Jul 30 12:48:41.401175 2026] [security2:error] [pid 806041:tid 806241] [client 150.107.232.194:27192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOeULAyZ1MRInzPMb6DQAAAMs"]
[Thu Jul 30 12:48:41.401284 2026] [security2:error] [pid 806041:tid 806241] [client 150.107.232.194:27192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOeULAyZ1MRInzPMb6DQAAAMs"]
[Thu Jul 30 12:48:41.440031 2026] [security2:error] [pid 806041:tid 806216] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuOeULAyZ1MRInzPMb6DgAAALI"]
[Thu Jul 30 12:48:41.487742 2026] [security2:error] [pid 806041:tid 806207] [client 52.167.144.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuOeELAyZ1MRInzPMb54wAAqUU"]
[Thu Jul 30 12:48:41.726654 2026] [security2:error] [pid 806041:tid 806204] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuOeULAyZ1MRInzPMb6GQAAAKY"]
[Thu Jul 30 12:48:41.773681 2026] [core:notice] [pid 806041:tid 806193] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:41.780524 2026] [security2:error] [pid 806041:tid 806193] [client 103.215.74.26:10124] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOeULAyZ1MRInzPMb6GgAAAJs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:41.984682 2026] [security2:error] [pid 806041:tid 806261] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuOeULAyZ1MRInzPMb6HgAAAN8"]
[Thu Jul 30 12:48:42.239392 2026] [security2:error] [pid 806041:tid 806251] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuOekLAyZ1MRInzPMb6KAAAANU"]
[Thu Jul 30 12:48:42.286271 2026] [security2:error] [pid 806041:tid 806188] [client 20.91.199.21:20834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuOekLAyZ1MRInzPMb6LAAAAJY"]
[Thu Jul 30 12:48:42.498361 2026] [security2:error] [pid 806041:tid 806276] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuOekLAyZ1MRInzPMb6MwAAAO4"]
[Thu Jul 30 12:48:42.532477 2026] [core:notice] [pid 806041:tid 806287] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:42.539380 2026] [security2:error] [pid 806041:tid 806287] [client 103.215.74.26:10132] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOekLAyZ1MRInzPMb6NAAAAPk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:42.769279 2026] [security2:error] [pid 806041:tid 806264] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuOekLAyZ1MRInzPMb6PAAAAOI"]
[Thu Jul 30 12:48:43.044827 2026] [security2:error] [pid 806041:tid 806210] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuOe0LAyZ1MRInzPMb6QwAAAKw"]
[Thu Jul 30 12:48:43.285225 2026] [core:notice] [pid 806041:tid 806228] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:43.289469 2026] [security2:error] [pid 806041:tid 806228] [client 103.215.74.26:62928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "742"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOe0LAyZ1MRInzPMb6RwAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:43.326605 2026] [security2:error] [pid 806041:tid 806263] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuOe0LAyZ1MRInzPMb6SAAAAOE"]
[Thu Jul 30 12:48:43.583806 2026] [security2:error] [pid 806041:tid 806241] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuOe0LAyZ1MRInzPMb6UAAAAMs"]
[Thu Jul 30 12:48:43.837620 2026] [security2:error] [pid 806041:tid 806291] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuOe0LAyZ1MRInzPMb6VAAAAP0"]
[Thu Jul 30 12:48:44.018572 2026] [security2:error] [pid 806041:tid 806229] [client 20.151.221.234:49899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/gmo.php"] [unique_id "amuOfELAyZ1MRInzPMb6WwAAAL8"]
[Thu Jul 30 12:48:44.035627 2026] [core:notice] [pid 806041:tid 806227] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:44.042744 2026] [security2:error] [pid 806041:tid 806227] [client 103.215.74.26:62930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "760"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOfELAyZ1MRInzPMb6XQAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:44.095428 2026] [security2:error] [pid 806041:tid 806249] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuOfELAyZ1MRInzPMb6XwAAANM"]
[Thu Jul 30 12:48:44.102696 2026] [security2:error] [pid 806041:tid 806290] [client 20.151.221.234:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/fm.php"] [unique_id "amuOfELAyZ1MRInzPMb6YAAAAPw"]
[Thu Jul 30 12:48:44.122107 2026] [security2:error] [pid 806041:tid 806252] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOe0LAyZ1MRInzPMb6SQAA1ms"]
[Thu Jul 30 12:48:44.181452 2026] [security2:error] [pid 806041:tid 806209] [client 20.91.199.21:43451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/a4.php"] [unique_id "amuOfELAyZ1MRInzPMb6ZAAAAKs"]
[Thu Jul 30 12:48:44.182829 2026] [proxy:error] [pid 806041:tid 806161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:44.182881 2026] [proxy_http:error] [pid 806041:tid 806161] [remote 74.7.175.171:53110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:44.183491 2026] [proxy:error] [pid 806041:tid 806161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:48:44.183539 2026] [proxy_http:error] [pid 806041:tid 806161] [remote 74.7.175.171:53110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:48:44.325175 2026] [security2:error] [pid 806041:tid 806205] [client 20.91.199.21:20297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuOfELAyZ1MRInzPMb6ZgAAAKc"]
[Thu Jul 30 12:48:44.352223 2026] [security2:error] [pid 806041:tid 806266] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reviewbyjook.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuOfELAyZ1MRInzPMb6ZwAAAOQ"]
[Thu Jul 30 12:48:44.772277 2026] [core:notice] [pid 806041:tid 806196] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:44.779032 2026] [security2:error] [pid 806041:tid 806196] [client 103.215.74.26:62934] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOfELAyZ1MRInzPMb6cQAAAJ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:44.822029 2026] [security2:error] [pid 806041:tid 806225] [client 20.151.221.234:49879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuOfELAyZ1MRInzPMb6cwAAALs"]
[Thu Jul 30 12:48:44.834722 2026] [security2:error] [pid 806041:tid 806244] [client 74.7.230.61:58040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jnn.djb.temporary.site"] [uri "/index.php"] [unique_id "amuOfELAyZ1MRInzPMb6cgAAzno"]
[Thu Jul 30 12:48:45.048173 2026] [security2:error] [pid 806041:tid 806297] [client 20.91.199.21:20828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuOfULAyZ1MRInzPMb6egAAAQM"]
[Thu Jul 30 12:48:45.110141 2026] [security2:error] [pid 806041:tid 806283] [client 20.91.199.21:43807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/accueil.php"] [unique_id "amuOfULAyZ1MRInzPMb6fgAAAPU"]
[Thu Jul 30 12:48:45.329315 2026] [security2:error] [pid 806041:tid 806168] [remote 57.141.0.6:25752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuOfULAyZ1MRInzPMb6ggAAlX4"]
[Thu Jul 30 12:48:45.350872 2026] [security2:error] [pid 806041:tid 806172] [client 68.221.186.136:27917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/amfsqvgv.php"] [unique_id "amuOfULAyZ1MRInzPMb6hAAAAIY"]
[Thu Jul 30 12:48:45.521604 2026] [core:notice] [pid 806041:tid 806284] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:45.525799 2026] [security2:error] [pid 806041:tid 806284] [client 103.215.74.26:62940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "773"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOfULAyZ1MRInzPMb6hgAAAPY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:45.581295 2026] [security2:error] [pid 806041:tid 806239] [client 68.67.112.191:30672] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuOfULAyZ1MRInzPMb6igAAAMk"]
[Thu Jul 30 12:48:45.726921 2026] [security2:error] [pid 806041:tid 806263] [client 20.151.221.234:2114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-the.php"] [unique_id "amuOfULAyZ1MRInzPMb6kgAAAOE"]
[Thu Jul 30 12:48:45.811054 2026] [core:notice] [pid 806041:tid 806046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:45.909660 2026] [security2:error] [pid 806041:tid 806202] [client 68.221.186.136:28013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/ant.php"] [unique_id "amuOfULAyZ1MRInzPMb6lAAAAKQ"]
[Thu Jul 30 12:48:46.268231 2026] [core:notice] [pid 806041:tid 806214] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:46.273037 2026] [security2:error] [pid 806041:tid 806214] [client 103.215.74.26:62954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOfkLAyZ1MRInzPMb6owAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:46.584260 2026] [security2:error] [pid 806041:tid 806269] [client 198.44.157.146:58486] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuOfkLAyZ1MRInzPMb6qwAAAOc"]
[Thu Jul 30 12:48:46.584364 2026] [security2:error] [pid 806041:tid 806269] [client 198.44.157.146:58486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuOfkLAyZ1MRInzPMb6qwAAAOc"]
[Thu Jul 30 12:48:46.666795 2026] [security2:error] [pid 806041:tid 806181] [client 68.221.186.136:27913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/appreciators.php"] [unique_id "amuOfkLAyZ1MRInzPMb6uAAAAI8"]
[Thu Jul 30 12:48:46.750176 2026] [security2:error] [pid 806041:tid 806196] [client 20.151.221.234:62128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/404.php"] [unique_id "amuOfkLAyZ1MRInzPMb6wQAAAJ4"]
[Thu Jul 30 12:48:47.027390 2026] [core:notice] [pid 806041:tid 806172] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:47.031805 2026] [security2:error] [pid 806041:tid 806172] [client 103.215.74.26:62956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOf0LAyZ1MRInzPMb60wAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:47.093824 2026] [security2:error] [pid 806041:tid 806078] [remote 57.141.0.26:33030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuOf0LAyZ1MRInzPMb61AAA4yQ"]
[Thu Jul 30 12:48:47.233797 2026] [security2:error] [pid 806041:tid 806184] [client 68.221.186.136:27871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/archive.php"] [unique_id "amuOf0LAyZ1MRInzPMb63wAAAJI"]
[Thu Jul 30 12:48:47.465860 2026] [security2:error] [pid 806041:tid 806278] [client 20.91.199.21:20814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuOf0LAyZ1MRInzPMb64wAAAPA"]
[Thu Jul 30 12:48:47.586785 2026] [security2:error] [pid 806041:tid 806251] [client 20.91.199.21:43412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/dashboard.php"] [unique_id "amuOf0LAyZ1MRInzPMb65AAAANU"]
[Thu Jul 30 12:48:47.756236 2026] [core:notice] [pid 806041:tid 806229] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:47.760743 2026] [security2:error] [pid 806041:tid 806229] [client 103.215.74.26:62964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOf0LAyZ1MRInzPMb67QAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:48.397415 2026] [security2:error] [pid 806041:tid 806271] [client 20.91.199.21:45931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuOgELAyZ1MRInzPMb7KwAAAOk"]
[Thu Jul 30 12:48:48.501269 2026] [core:notice] [pid 806041:tid 806231] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:48.505835 2026] [security2:error] [pid 806041:tid 806231] [client 103.215.74.26:62980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOgELAyZ1MRInzPMb7LAAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:48.711622 2026] [security2:error] [pid 806041:tid 806178] [client 217.138.252.123:50358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.252.138.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuOgELAyZ1MRInzPMb7MgAAAIw"]
[Thu Jul 30 12:48:48.711724 2026] [security2:error] [pid 806041:tid 806178] [client 217.138.252.123:50358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuOgELAyZ1MRInzPMb7MgAAAIw"]
[Thu Jul 30 12:48:48.763836 2026] [security2:error] [pid 806041:tid 806224] [client 74.7.228.39:57488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "deltaedu.net.ssa.djb.temporary.site"] [uri "/index.php"] [unique_id "amuOgELAyZ1MRInzPMb7MQAAumE"]
[Thu Jul 30 12:48:49.306173 2026] [core:notice] [pid 806041:tid 806239] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:49.315074 2026] [security2:error] [pid 806041:tid 806239] [client 103.215.74.26:62992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOgULAyZ1MRInzPMb7UQAAAMk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:49.393819 2026] [security2:error] [pid 806041:tid 806193] [client 20.91.199.21:35400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuOgULAyZ1MRInzPMb7VQAAAJs"]
[Thu Jul 30 12:48:49.468465 2026] [security2:error] [pid 806041:tid 806290] [client 140.245.34.60:55906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "fireworkskenya.co.ke"] [uri "/wp-json/batch/v1"] [unique_id "amuOgULAyZ1MRInzPMb7WQAAAPw"]
[Thu Jul 30 12:48:49.479707 2026] [security2:error] [pid 806041:tid 806207] [client 20.91.199.21:43395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/radio.php"] [unique_id "amuOgULAyZ1MRInzPMb7WgAAAKk"]
[Thu Jul 30 12:48:49.611802 2026] [security2:error] [pid 806041:tid 806212] [client 74.7.244.55:50788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "deltaedu.net"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7WwAArnM"]
[Thu Jul 30 12:48:49.655589 2026] [security2:error] [pid 806041:tid 806235] [client 140.245.34.60:55906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "fireworkskenya.co.ke"] [uri "/"] [unique_id "amuOgULAyZ1MRInzPMb7XAAAAMU"]
[Thu Jul 30 12:48:49.847380 2026] [core:notice] [pid 806041:tid 806266] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:50.049925 2026] [core:notice] [pid 806041:tid 806202] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:50.054770 2026] [security2:error] [pid 806041:tid 806202] [client 103.215.74.26:63006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOgkLAyZ1MRInzPMb7aQAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:50.198466 2026] [security2:error] [pid 806041:tid 806199] [client 68.221.186.136:27918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/as.php"] [unique_id "amuOgkLAyZ1MRInzPMb7bQAAAKE"]
[Thu Jul 30 12:48:50.251892 2026] [security2:error] [pid 806041:tid 806232] [client 20.91.199.21:43408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/wpsml-sys.php"] [unique_id "amuOgkLAyZ1MRInzPMb7cQAAAMI"]
[Thu Jul 30 12:48:50.338164 2026] [security2:error] [pid 806041:tid 806268] [client 20.91.199.21:20325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuOgkLAyZ1MRInzPMb7dQAAAOY"]
[Thu Jul 30 12:48:50.346704 2026] [core:notice] [pid 806041:tid 806164] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:50.434150 2026] [security2:error] [pid 806041:tid 806172] [client 172.237.109.114:29786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7PQAAAIY"]
[Thu Jul 30 12:48:50.479775 2026] [security2:error] [pid 806041:tid 806173] [client 172.237.109.114:58766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7PAAAAIc"]
[Thu Jul 30 12:48:50.499742 2026] [security2:error] [pid 806041:tid 806216] [client 172.237.109.114:43329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7RAAAALI"]
[Thu Jul 30 12:48:50.525511 2026] [security2:error] [pid 806041:tid 806280] [client 172.237.109.114:54209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7QQAAAPI"]
[Thu Jul 30 12:48:50.535937 2026] [security2:error] [pid 806041:tid 806277] [client 172.237.109.114:20953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7QAAAAO8"]
[Thu Jul 30 12:48:50.536737 2026] [security2:error] [pid 806041:tid 806265] [client 172.237.109.114:35769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7PgAAAOM"]
[Thu Jul 30 12:48:50.538686 2026] [security2:error] [pid 806041:tid 806200] [client 172.237.109.114:13139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7QwAAAKI"]
[Thu Jul 30 12:48:50.555905 2026] [security2:error] [pid 806041:tid 806226] [client 172.237.109.114:41721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7RgAAALw"]
[Thu Jul 30 12:48:50.561848 2026] [security2:error] [pid 806041:tid 806243] [client 172.237.109.114:54188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7PwAAAM0"]
[Thu Jul 30 12:48:50.562109 2026] [security2:error] [pid 806041:tid 806208] [client 172.237.109.114:33696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7RQAAAKo"]
[Thu Jul 30 12:48:50.566725 2026] [security2:error] [pid 806041:tid 806298] [client 172.237.109.114:7155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7QgAAAQQ"]
[Thu Jul 30 12:48:50.575233 2026] [security2:error] [pid 806041:tid 806294] [client 172.237.109.114:13736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7RwAAAQA"]
[Thu Jul 30 12:48:50.593556 2026] [security2:error] [pid 806041:tid 806254] [client 172.237.109.114:63317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7SAAAANg"]
[Thu Jul 30 12:48:50.593623 2026] [security2:error] [pid 806041:tid 806180] [client 172.237.109.114:36086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7SwAAAI4"]
[Thu Jul 30 12:48:50.601173 2026] [security2:error] [pid 806041:tid 806186] [client 172.237.109.114:53787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7SQAAAJQ"]
[Thu Jul 30 12:48:50.613749 2026] [security2:error] [pid 806041:tid 806183] [client 172.237.109.114:18363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7TAAAAJE"]
[Thu Jul 30 12:48:50.621228 2026] [security2:error] [pid 806041:tid 806184] [client 172.237.109.114:17171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgULAyZ1MRInzPMb7TQAAAJI"]
[Thu Jul 30 12:48:50.686342 2026] [core:notice] [pid 806041:tid 806262] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:50.787600 2026] [core:notice] [pid 806041:tid 806196] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:50.792472 2026] [security2:error] [pid 806041:tid 806196] [client 103.215.74.26:63012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOgkLAyZ1MRInzPMb7gQAAAJ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:51.032749 2026] [core:notice] [pid 806041:tid 806042] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:51.048031 2026] [security2:error] [pid 806041:tid 806221] [client 20.91.199.21:43419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/02.php"] [unique_id "amuOg0LAyZ1MRInzPMb7iQAAALc"]
[Thu Jul 30 12:48:51.263624 2026] [security2:error] [pid 806041:tid 806212] [client 20.91.199.21:20333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuOg0LAyZ1MRInzPMb7kQAAAK4"]
[Thu Jul 30 12:48:51.285661 2026] [security2:error] [pid 806041:tid 806207] [client 68.221.186.136:27954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/atomlib.php"] [unique_id "amuOg0LAyZ1MRInzPMb7lAAAAKk"]
[Thu Jul 30 12:48:51.507510 2026] [security2:error] [pid 806041:tid 806214] [client 172.237.109.114:27237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgkLAyZ1MRInzPMb7agAAALA"]
[Thu Jul 30 12:48:51.522090 2026] [core:notice] [pid 806041:tid 806220] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:51.523356 2026] [security2:error] [pid 806041:tid 806258] [client 172.237.109.114:45430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgkLAyZ1MRInzPMb7bAAAANw"]
[Thu Jul 30 12:48:51.526682 2026] [security2:error] [pid 806041:tid 806220] [client 103.215.74.26:63014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOg0LAyZ1MRInzPMb7mgAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:51.541947 2026] [security2:error] [pid 806041:tid 806179] [client 172.237.109.114:25876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuOgkLAyZ1MRInzPMb7awAAAI0"]
[Thu Jul 30 12:48:51.682113 2026] [security2:error] [pid 806041:tid 806051] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOg0LAyZ1MRInzPMb7oQAA5gk"]
[Thu Jul 30 12:48:51.682276 2026] [security2:error] [pid 806041:tid 806268] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOg0LAyZ1MRInzPMb7oQAA5gk"]
[Thu Jul 30 12:48:51.874145 2026] [security2:error] [pid 806041:tid 806210] [client 150.107.232.194:26618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOg0LAyZ1MRInzPMb7qQAAAKw"]
[Thu Jul 30 12:48:51.874241 2026] [security2:error] [pid 806041:tid 806210] [client 150.107.232.194:26618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOg0LAyZ1MRInzPMb7qQAAAKw"]
[Thu Jul 30 12:48:51.937150 2026] [security2:error] [pid 806041:tid 806233] [client 20.151.221.234:41403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/init.php"] [unique_id "amuOg0LAyZ1MRInzPMb7rAAAAMM"]
[Thu Jul 30 12:48:52.145955 2026] [security2:error] [pid 806041:tid 806256] [client 20.91.199.21:20826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuOhELAyZ1MRInzPMb7sQAAANo"]
[Thu Jul 30 12:48:52.209749 2026] [security2:error] [pid 806041:tid 806180] [client 20.151.221.234:22693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/file.php"] [unique_id "amuOhELAyZ1MRInzPMb7sgAAAI4"]
[Thu Jul 30 12:48:52.277899 2026] [core:notice] [pid 806041:tid 806187] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:52.283213 2026] [security2:error] [pid 806041:tid 806187] [client 103.215.74.26:63026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOhELAyZ1MRInzPMb7swAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:52.312689 2026] [core:notice] [pid 806041:tid 806236] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:52.411531 2026] [security2:error] [pid 806041:tid 806173] [client 68.221.186.136:27987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/autoload_classmap.php"] [unique_id "amuOhELAyZ1MRInzPMb7vAAAAIc"]
[Thu Jul 30 12:48:52.641397 2026] [security2:error] [pid 806041:tid 806245] [client 20.91.199.21:33533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/infos.php"] [unique_id "amuOhELAyZ1MRInzPMb7vgAAAM8"]
[Thu Jul 30 12:48:52.925517 2026] [security2:error] [pid 806041:tid 806227] [client 20.91.199.21:20835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/bek.php"] [unique_id "amuOhELAyZ1MRInzPMb7yAAAAL0"]
[Thu Jul 30 12:48:52.959800 2026] [security2:error] [pid 806041:tid 806176] [client 68.221.186.136:27993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/bb.php"] [unique_id "amuOhELAyZ1MRInzPMb7zAAAAIo"]
[Thu Jul 30 12:48:53.029612 2026] [core:notice] [pid 806041:tid 806235] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:53.037754 2026] [security2:error] [pid 806041:tid 806235] [client 103.215.74.26:61110] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOhULAyZ1MRInzPMb7zQAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:53.109231 2026] [security2:error] [pid 806041:tid 806257] [client 20.151.221.234:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/file5.php"] [unique_id "amuOhULAyZ1MRInzPMb70AAAANs"]
[Thu Jul 30 12:48:53.156550 2026] [core:notice] [pid 806041:tid 806053] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:53.683224 2026] [security2:error] [pid 806041:tid 806182] [client 20.91.199.21:33513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/updates.php"] [unique_id "amuOhULAyZ1MRInzPMb73gAAAJA"]
[Thu Jul 30 12:48:53.801080 2026] [core:notice] [pid 806041:tid 806246] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:53.808442 2026] [security2:error] [pid 806041:tid 806246] [client 103.215.74.26:61126] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOhULAyZ1MRInzPMb75AAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:54.115791 2026] [security2:error] [pid 806041:tid 806292] [client 68.221.186.136:27973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/bnm.php"] [unique_id "amuOhkLAyZ1MRInzPMb77gAAAP4"]
[Thu Jul 30 12:48:54.336463 2026] [security2:error] [pid 806041:tid 806271] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOhULAyZ1MRInzPMb73QAA6SA"]
[Thu Jul 30 12:48:54.381411 2026] [security2:error] [pid 806041:tid 806236] [client 74.7.175.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webdisk.fiyan.co"] [uri "/___proxy_subdomain_webdisk/cgi-sys/404.html"] [unique_id "amuOhkLAyZ1MRInzPMb79QAAAMY"]
[Thu Jul 30 12:48:54.382021 2026] [security2:error] [pid 806041:tid 806183] [client 74.7.175.135:44538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webdisk.fiyan.co"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuOhkLAyZ1MRInzPMb78wAAkSM"]
[Thu Jul 30 12:48:54.532507 2026] [core:notice] [pid 806041:tid 806241] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:54.536695 2026] [security2:error] [pid 806041:tid 806241] [client 103.215.74.26:61132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOhkLAyZ1MRInzPMb7-gAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:54.673363 2026] [security2:error] [pid 806041:tid 806265] [client 20.151.221.234:62092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuOhkLAyZ1MRInzPMb7_gAAAOM"]
[Thu Jul 30 12:48:54.742885 2026] [security2:error] [pid 806041:tid 806195] [client 68.221.186.136:27999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/bootstrap.php"] [unique_id "amuOhkLAyZ1MRInzPMb8AgAAAJ0"]
[Thu Jul 30 12:48:55.276534 2026] [core:notice] [pid 806041:tid 806296] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:55.283639 2026] [security2:error] [pid 806041:tid 806296] [client 103.215.74.26:61148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOh0LAyZ1MRInzPMb8DwAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:55.450353 2026] [security2:error] [pid 806041:tid 806248] [client 20.91.199.21:43392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/user.php"] [unique_id "amuOh0LAyZ1MRInzPMb8EQAAANI"]
[Thu Jul 30 12:48:55.492344 2026] [core:error] [pid 806041:tid 806225] [client 74.7.175.171:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:55.492367 2026] [core:error] [pid 806041:tid 806225] [client 74.7.175.171:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:48:55.492497 2026] [security2:error] [pid 806041:tid 806225] [client 74.7.175.171:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.tereashops.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuOh0LAyZ1MRInzPMb8FQAAALs"]
[Thu Jul 30 12:48:55.493142 2026] [security2:error] [pid 806041:tid 806235] [client 74.7.175.171:36836] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.tereashops.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuOh0LAyZ1MRInzPMb8EwAAxS8"]
[Thu Jul 30 12:48:55.755323 2026] [security2:error] [pid 806041:tid 806207] [client 20.151.221.234:53392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/shell.php"] [unique_id "amuOh0LAyZ1MRInzPMb8IAAAAKk"]
[Thu Jul 30 12:48:56.008453 2026] [core:notice] [pid 806041:tid 806192] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:56.015193 2026] [security2:error] [pid 806041:tid 806192] [client 103.215.74.26:61150] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOiELAyZ1MRInzPMb8IgAAAJo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:56.104876 2026] [core:notice] [pid 806041:tid 806187] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:56.233400 2026] [core:notice] [pid 806041:tid 806104] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:56.274768 2026] [security2:error] [pid 806041:tid 806181] [client 20.91.199.21:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/admin-ajax.php"] [unique_id "amuOiELAyZ1MRInzPMb8LwAAAI8"]
[Thu Jul 30 12:48:56.427797 2026] [security2:error] [pid 806041:tid 806233] [client 68.221.186.136:27995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/buy.php"] [unique_id "amuOiELAyZ1MRInzPMb8MAAAAMM"]
[Thu Jul 30 12:48:56.519751 2026] [security2:error] [pid 806041:tid 806298] [client 213.152.161.170:45278] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuOiELAyZ1MRInzPMb8LgAAAQQ"]
[Thu Jul 30 12:48:56.519871 2026] [security2:error] [pid 806041:tid 806298] [client 213.152.161.170:45278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuOiELAyZ1MRInzPMb8LgAAAQQ"]
[Thu Jul 30 12:48:56.669445 2026] [security2:error] [pid 806041:tid 806208] [client 20.151.221.234:63273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/f35.php"] [unique_id "amuOiELAyZ1MRInzPMb8OAAAAKo"]
[Thu Jul 30 12:48:56.739922 2026] [core:notice] [pid 806041:tid 806228] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:56.744334 2026] [security2:error] [pid 806041:tid 806228] [client 103.215.74.26:61166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOiELAyZ1MRInzPMb8PgAAAL4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:56.793847 2026] [security2:error] [pid 806041:tid 806268] [client 20.91.199.21:20311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuOiELAyZ1MRInzPMb8QQAAAOY"]
[Thu Jul 30 12:48:56.891924 2026] [security2:error] [pid 806041:tid 806259] [client 20.91.199.21:33502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/alfa.php"] [unique_id "amuOiELAyZ1MRInzPMb8QwAAAN0"]
[Thu Jul 30 12:48:57.234403 2026] [security2:error] [pid 806041:tid 806279] [client 68.221.186.136:28000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/chosen.php"] [unique_id "amuOiULAyZ1MRInzPMb8SgAAAPE"]
[Thu Jul 30 12:48:57.484453 2026] [core:notice] [pid 806041:tid 806218] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:57.489444 2026] [security2:error] [pid 806041:tid 806218] [client 103.215.74.26:61178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOiULAyZ1MRInzPMb8UAAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:57.861660 2026] [security2:error] [pid 806041:tid 806281] [client 68.221.186.136:27925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/class-wp-image.php"] [unique_id "amuOiULAyZ1MRInzPMb8WgAAAPM"]
[Thu Jul 30 12:48:57.981559 2026] [security2:error] [pid 806041:tid 806212] [client 20.151.221.234:63248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/new.php"] [unique_id "amuOiULAyZ1MRInzPMb8XgAAAK4"]
[Thu Jul 30 12:48:58.050173 2026] [security2:error] [pid 806041:tid 806257] [client 50.6.43.217:20592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuOiULAyZ1MRInzPMb8TgAAANs"]
[Thu Jul 30 12:48:58.094489 2026] [core:notice] [pid 806041:tid 806224] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:58.194822 2026] [security2:error] [pid 806041:tid 806187] [client 20.91.199.21:43450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/hehe.php"] [unique_id "amuOikLAyZ1MRInzPMb8ZgAAAJU"]
[Thu Jul 30 12:48:58.208915 2026] [core:notice] [pid 806041:tid 806182] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:58.213640 2026] [security2:error] [pid 806041:tid 806182] [client 103.215.74.26:61180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOikLAyZ1MRInzPMb8aQAAAJA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:58.310036 2026] [core:notice] [pid 806041:tid 806105] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:58.443436 2026] [security2:error] [pid 806041:tid 806238] [client 20.91.199.21:20817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/class.api.php"] [unique_id "amuOikLAyZ1MRInzPMb8bwAAAMg"]
[Thu Jul 30 12:48:58.547689 2026] [core:notice] [pid 806041:tid 806117] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:58.748845 2026] [security2:error] [pid 806041:tid 806124] [remote 72.167.132.114:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuOikLAyZ1MRInzPMb8dwAAiFI"]
[Thu Jul 30 12:48:58.767633 2026] [security2:error] [pid 806041:tid 806247] [client 50.6.43.217:20598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuOikLAyZ1MRInzPMb8YAAAANE"]
[Thu Jul 30 12:48:58.952993 2026] [core:notice] [pid 806041:tid 806234] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:58.956884 2026] [security2:error] [pid 806041:tid 806234] [client 103.215.74.26:61192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOikLAyZ1MRInzPMb8eAAAAMQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:59.058344 2026] [security2:error] [pid 806041:tid 806239] [client 20.151.221.234:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/adminfuns.php"] [unique_id "amuOi0LAyZ1MRInzPMb8fgAAAMk"]
[Thu Jul 30 12:48:59.100097 2026] [security2:error] [pid 806041:tid 806219] [client 20.91.199.21:35419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/cong.php"] [unique_id "amuOi0LAyZ1MRInzPMb8fwAAALU"]
[Thu Jul 30 12:48:59.711847 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:48:59.716244 2026] [security2:error] [pid 806041:tid 806205] [client 103.215.74.26:61202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOi0LAyZ1MRInzPMb8jQAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:48:59.782053 2026] [security2:error] [pid 806041:tid 806285] [client 20.151.221.234:23184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/bolt.php"] [unique_id "amuOi0LAyZ1MRInzPMb8kQAAAPc"]
[Thu Jul 30 12:48:59.921119 2026] [security2:error] [pid 806041:tid 806253] [client 68.221.186.136:27905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/classsmtps.php"] [unique_id "amuOi0LAyZ1MRInzPMb8kgAAANc"]
[Thu Jul 30 12:49:00.324709 2026] [core:error] [pid 806041:tid 806248] [client 20.151.221.234:49024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:00.324733 2026] [core:error] [pid 806041:tid 806248] [client 20.151.221.234:49024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:00.368320 2026] [security2:error] [pid 806041:tid 806244] [client 20.91.199.21:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/rk2.php"] [unique_id "amuOjELAyZ1MRInzPMb8oQAAAM4"]
[Thu Jul 30 12:49:00.450284 2026] [core:notice] [pid 806041:tid 806282] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:00.457714 2026] [security2:error] [pid 806041:tid 806282] [client 103.215.74.26:61214] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOjELAyZ1MRInzPMb8ogAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:00.495089 2026] [security2:error] [pid 806041:tid 806231] [client 20.151.221.234:50033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/3.php"] [unique_id "amuOjELAyZ1MRInzPMb8pgAAAME"]
[Thu Jul 30 12:49:00.623284 2026] [security2:error] [pid 806041:tid 806200] [client 68.221.186.136:27990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/classwithtostring.php"] [unique_id "amuOjELAyZ1MRInzPMb8pwAAAKI"]
[Thu Jul 30 12:49:00.889355 2026] [autoindex:error] [pid 806041:tid 806262] [client 170.199.224.241:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:49:00.979005 2026] [security2:error] [pid 806041:tid 806178] [client 20.91.199.21:40308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/content.php"] [unique_id "amuOjELAyZ1MRInzPMb8sgAAAIw"]
[Thu Jul 30 12:49:01.179872 2026] [core:notice] [pid 806041:tid 806263] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:01.186331 2026] [security2:error] [pid 806041:tid 806263] [client 103.215.74.26:61228] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOjULAyZ1MRInzPMb8tgAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:01.187442 2026] [core:error] [pid 806041:tid 806185] [client 20.151.221.234:49040] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:01.187458 2026] [core:error] [pid 806041:tid 806185] [client 20.151.221.234:49040] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:01.346021 2026] [core:notice] [pid 806041:tid 806219] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:01.443921 2026] [security2:error] [pid 806041:tid 806242] [client 68.221.186.136:28002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/config.php"] [unique_id "amuOjULAyZ1MRInzPMb8vwAAAMw"]
[Thu Jul 30 12:49:01.584703 2026] [proxy:error] [pid 806041:tid 806150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:01.584752 2026] [proxy_http:error] [pid 806041:tid 806150] [remote 87.236.176.189:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.teknomalay.com
[Thu Jul 30 12:49:01.585369 2026] [proxy:error] [pid 806041:tid 806150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:01.585414 2026] [proxy_http:error] [pid 806041:tid 806150] [remote 87.236.176.189:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.teknomalay.com
[Thu Jul 30 12:49:01.796037 2026] [fcgid:warn] [pid 806041:tid 806190] (70014)End of file found: [client 18.218.118.203:11828] mod_fcgid: can't get data from http client
[Thu Jul 30 12:49:01.923541 2026] [core:notice] [pid 806041:tid 806227] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:01.927842 2026] [security2:error] [pid 806041:tid 806227] [client 103.215.74.26:61240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOjULAyZ1MRInzPMb82QAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:02.014491 2026] [security2:error] [pid 806041:tid 806255] [client 20.151.221.234:41344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/fm.php"] [unique_id "amuOjkLAyZ1MRInzPMb84wAAANk"]
[Thu Jul 30 12:49:02.345865 2026] [security2:error] [pid 806041:tid 806205] [client 68.221.186.136:27929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/core.php"] [unique_id "amuOjkLAyZ1MRInzPMb86wAAAKc"]
[Thu Jul 30 12:49:02.352183 2026] [security2:error] [pid 806041:tid 806274] [client 150.107.232.194:27041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOjkLAyZ1MRInzPMb86gAAAOw"]
[Thu Jul 30 12:49:02.352286 2026] [security2:error] [pid 806041:tid 806274] [client 150.107.232.194:27041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOjkLAyZ1MRInzPMb86gAAAOw"]
[Thu Jul 30 12:49:02.475711 2026] [security2:error] [pid 806041:tid 806230] [client 20.151.221.234:22545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/222.php"] [unique_id "amuOjkLAyZ1MRInzPMb89wAAAMA"]
[Thu Jul 30 12:49:02.504627 2026] [security2:error] [pid 806041:tid 806046] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOjkLAyZ1MRInzPMb8-AAA0AQ"]
[Thu Jul 30 12:49:02.504771 2026] [security2:error] [pid 806041:tid 806246] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOjkLAyZ1MRInzPMb8-AAA0AQ"]
[Thu Jul 30 12:49:02.583650 2026] [autoindex:error] [pid 806041:tid 806174] [client 216.163.199.165:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:49:02.615137 2026] [security2:error] [pid 806041:tid 806295] [client 20.91.199.21:45925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuOjkLAyZ1MRInzPMb9AgAAAQE"]
[Thu Jul 30 12:49:02.656581 2026] [core:notice] [pid 806041:tid 806240] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:02.661886 2026] [security2:error] [pid 806041:tid 806240] [client 103.215.74.26:61254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOjkLAyZ1MRInzPMb9AwAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:02.944239 2026] [core:error] [pid 806041:tid 806233] [client 20.151.221.234:63287] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:02.944262 2026] [core:error] [pid 806041:tid 806233] [client 20.151.221.234:63287] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:03.145835 2026] [autoindex:error] [pid 806041:tid 806209] [client 139.180.231.238:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:49:03.170542 2026] [security2:error] [pid 806041:tid 806242] [client 20.91.199.21:20858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/elp.php"] [unique_id "amuOj0LAyZ1MRInzPMb9FAAAAMw"]
[Thu Jul 30 12:49:03.393152 2026] [core:notice] [pid 806041:tid 806249] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:03.404989 2026] [security2:error] [pid 806041:tid 806249] [client 103.215.74.26:20582] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOj0LAyZ1MRInzPMb9GwAAANM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:03.529544 2026] [security2:error] [pid 806041:tid 806219] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOjkLAyZ1MRInzPMb9CQAAALU"]
[Thu Jul 30 12:49:03.733866 2026] [security2:error] [pid 806041:tid 806290] [client 68.221.186.136:27979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/css.php"] [unique_id "amuOj0LAyZ1MRInzPMb9JQAAAPw"]
[Thu Jul 30 12:49:03.838774 2026] [security2:error] [pid 806041:tid 806264] [client 20.151.221.234:63232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/file.php"] [unique_id "amuOj0LAyZ1MRInzPMb9JgAAAOI"]
[Thu Jul 30 12:49:03.965043 2026] [security2:error] [pid 806041:tid 806293] [client 20.151.221.234:46301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuOj0LAyZ1MRInzPMb9LQAAAP8"]
[Thu Jul 30 12:49:04.135915 2026] [core:notice] [pid 806041:tid 806297] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:04.143232 2026] [security2:error] [pid 806041:tid 806297] [client 103.215.74.26:20584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOkELAyZ1MRInzPMb9MgAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:04.616174 2026] [security2:error] [pid 806041:tid 806216] [client 68.221.186.136:28010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/database.php"] [unique_id "amuOkELAyZ1MRInzPMb9PwAAALI"]
[Thu Jul 30 12:49:04.805272 2026] [core:error] [pid 806041:tid 806243] [client 20.151.221.234:2814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:04.805310 2026] [core:error] [pid 806041:tid 806243] [client 20.151.221.234:2814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:04.880029 2026] [core:notice] [pid 806041:tid 806178] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:04.884262 2026] [security2:error] [pid 806041:tid 806178] [client 103.215.74.26:20600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOkELAyZ1MRInzPMb9RQAAAIw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:05.612560 2026] [security2:error] [pid 806041:tid 806272] [client 68.221.186.136:27989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/db.php"] [unique_id "amuOkULAyZ1MRInzPMb9UgAAAOo"]
[Thu Jul 30 12:49:05.619782 2026] [security2:error] [pid 806041:tid 806197] [client 20.91.199.21:43281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/setup-config.php"] [unique_id "amuOkULAyZ1MRInzPMb9UwAAAJ8"]
[Thu Jul 30 12:49:05.624856 2026] [core:notice] [pid 806041:tid 806289] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:05.629264 2026] [security2:error] [pid 806041:tid 806289] [client 103.215.74.26:20606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOkULAyZ1MRInzPMb9VAAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:05.890772 2026] [security2:error] [pid 806041:tid 806259] [client 20.151.221.234:47197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuOkULAyZ1MRInzPMb9XAAAAN0"]
[Thu Jul 30 12:49:05.984644 2026] [security2:error] [pid 806041:tid 806266] [client 20.91.199.21:45933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuOkULAyZ1MRInzPMb9XQAAAOQ"]
[Thu Jul 30 12:49:06.330080 2026] [security2:error] [pid 806041:tid 806220] [client 68.221.186.136:28003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/default.php"] [unique_id "amuOkkLAyZ1MRInzPMb9ZwAAALY"]
[Thu Jul 30 12:49:06.365424 2026] [core:notice] [pid 806041:tid 806273] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:06.369902 2026] [security2:error] [pid 806041:tid 806273] [client 103.215.74.26:20616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOkkLAyZ1MRInzPMb9aAAAAOs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:06.664994 2026] [security2:error] [pid 806041:tid 806192] [client 20.91.199.21:35437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuOkkLAyZ1MRInzPMb9cAAAAJo"]
[Thu Jul 30 12:49:06.780781 2026] [security2:error] [pid 806041:tid 806230] [client 172.213.232.128:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/011i.php"] [unique_id "amuOkkLAyZ1MRInzPMb9cQAAAMA"]
[Thu Jul 30 12:49:06.891114 2026] [security2:error] [pid 806041:tid 806277] [client 20.151.221.234:53431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/bolt.php"] [unique_id "amuOkkLAyZ1MRInzPMb9cgAAAO8"]
[Thu Jul 30 12:49:06.935563 2026] [security2:error] [pid 806041:tid 806198] [client 20.91.199.21:43284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/a7.php"] [unique_id "amuOkkLAyZ1MRInzPMb9dgAAAKA"]
[Thu Jul 30 12:49:06.970056 2026] [core:error] [pid 806041:tid 806189] [client 40.77.167.219:29197] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:06.970076 2026] [core:error] [pid 806041:tid 806189] [client 40.77.167.219:29197] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:07.101563 2026] [core:notice] [pid 806041:tid 806226] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:07.109138 2026] [security2:error] [pid 806041:tid 806226] [client 103.215.74.26:20618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOk0LAyZ1MRInzPMb9eQAAALw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:07.236162 2026] [security2:error] [pid 806041:tid 806291] [client 213.152.161.170:55180] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOk0LAyZ1MRInzPMb9ggAAAP0"]
[Thu Jul 30 12:49:07.236253 2026] [security2:error] [pid 806041:tid 806291] [client 213.152.161.170:55180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOk0LAyZ1MRInzPMb9ggAAAP0"]
[Thu Jul 30 12:49:07.290148 2026] [security2:error] [pid 806041:tid 806049] [remote 216.73.216.152:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuOk0LAyZ1MRInzPMb9hwAAkQc"]
[Thu Jul 30 12:49:07.297950 2026] [autoindex:error] [pid 806041:tid 806206] [client 209.163.119.192:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:49:07.534374 2026] [security2:error] [pid 806041:tid 806241] [client 20.91.199.21:40273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuOk0LAyZ1MRInzPMb9iwAAAMs"]
[Thu Jul 30 12:49:07.830471 2026] [core:notice] [pid 806041:tid 806269] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:07.836780 2026] [security2:error] [pid 806041:tid 806269] [client 103.215.74.26:20630] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOk0LAyZ1MRInzPMb9kwAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:08.126827 2026] [security2:error] [pid 806041:tid 806217] [client 20.151.221.234:41359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/3.php"] [unique_id "amuOlELAyZ1MRInzPMb9lwAAALM"]
[Thu Jul 30 12:49:08.591919 2026] [core:notice] [pid 806041:tid 806207] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:08.598624 2026] [security2:error] [pid 806041:tid 806207] [client 103.215.74.26:20646] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOlELAyZ1MRInzPMb9ogAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:08.758891 2026] [security2:error] [pid 806041:tid 806238] [client 68.221.186.136:27912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/dropdown.php"] [unique_id "amuOlELAyZ1MRInzPMb9pgAAAMg"]
[Thu Jul 30 12:49:08.983532 2026] [security2:error] [pid 806041:tid 806275] [client 20.91.199.21:43343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/f7.php"] [unique_id "amuOlELAyZ1MRInzPMb9rQAAAO0"]
[Thu Jul 30 12:49:09.009670 2026] [security2:error] [pid 806041:tid 806097] [remote 98.83.72.38:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kbtfinancezambia.com"] [uri "/"] [unique_id "amuOlULAyZ1MRInzPMb9rgAAujc"]
[Thu Jul 30 12:49:09.058908 2026] [security2:error] [pid 806041:tid 806231] [client 20.91.199.21:33738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuOlULAyZ1MRInzPMb9rwAAAME"]
[Thu Jul 30 12:49:09.366686 2026] [core:notice] [pid 806041:tid 806191] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:09.373549 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:09.375084 2026] [security2:error] [pid 806041:tid 806191] [client 103.215.74.26:20648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOlULAyZ1MRInzPMb9ugAAAJk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:09.746663 2026] [security2:error] [pid 806041:tid 806177] [client 20.151.221.234:53432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/222.php"] [unique_id "amuOlULAyZ1MRInzPMb9wwAAAIs"]
[Thu Jul 30 12:49:09.763938 2026] [core:notice] [pid 806041:tid 806228] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:09.860789 2026] [proxy:error] [pid 806041:tid 806252] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:09.860864 2026] [proxy_http:error] [pid 806041:tid 806252] [client 74.7.175.157:39392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:09.861487 2026] [proxy:error] [pid 806041:tid 806252] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:09.861536 2026] [proxy_http:error] [pid 806041:tid 806252] [client 74.7.175.157:39392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:09.861661 2026] [security2:error] [pid 806041:tid 806252] [client 74.7.175.157:39392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.qom.udi.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuOlULAyZ1MRInzPMb9zgAAANY"]
[Thu Jul 30 12:49:09.976064 2026] [security2:error] [pid 806041:tid 806278] [client 20.91.199.21:45916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuOlULAyZ1MRInzPMb90gAAAPA"]
[Thu Jul 30 12:49:10.059645 2026] [security2:error] [pid 806041:tid 806219] [client 172.213.232.128:56247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/03a005685d.php"] [unique_id "amuOlkLAyZ1MRInzPMb91gAAALU"]
[Thu Jul 30 12:49:10.084046 2026] [security2:error] [pid 806041:tid 806185] [client 66.249.73.96:59250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuOlULAyZ1MRInzPMb9wAAAAJM"]
[Thu Jul 30 12:49:10.105732 2026] [core:notice] [pid 806041:tid 806188] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:10.110131 2026] [security2:error] [pid 806041:tid 806188] [client 103.215.74.26:20650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOlkLAyZ1MRInzPMb92AAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:10.212050 2026] [security2:error] [pid 806041:tid 806209] [client 68.221.186.136:28026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/edit.php"] [unique_id "amuOlkLAyZ1MRInzPMb92gAAAKs"]
[Thu Jul 30 12:49:10.488551 2026] [core:notice] [pid 806041:tid 806114] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:10.682937 2026] [security2:error] [pid 806041:tid 806284] [client 206.135.24.10:56054] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuOlkLAyZ1MRInzPMb9_AAAAPY"]
[Thu Jul 30 12:49:10.802697 2026] [security2:error] [pid 806041:tid 806262] [client 20.91.199.21:43296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/nw.php"] [unique_id "amuOlkLAyZ1MRInzPMb9_QAAAOA"]
[Thu Jul 30 12:49:10.831641 2026] [core:notice] [pid 806041:tid 806244] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:10.837820 2026] [security2:error] [pid 806041:tid 806244] [client 103.215.74.26:20662] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOlkLAyZ1MRInzPMb-AQAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:11.006418 2026] [security2:error] [pid 806041:tid 806175] [client 20.91.199.21:35403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuOl0LAyZ1MRInzPMb-CQAAAIk"]
[Thu Jul 30 12:49:11.012465 2026] [security2:error] [pid 806041:tid 806230] [client 206.135.24.10:37698] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuOl0LAyZ1MRInzPMb-CgAAAMA"]
[Thu Jul 30 12:49:11.082670 2026] [security2:error] [pid 806041:tid 806199] [client 20.151.221.234:2784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuOl0LAyZ1MRInzPMb-CwAAAKE"]
[Thu Jul 30 12:49:11.560150 2026] [core:notice] [pid 806041:tid 806241] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:11.565330 2026] [security2:error] [pid 806041:tid 806241] [client 103.215.74.26:20674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOl0LAyZ1MRInzPMb-JAAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:11.568716 2026] [security2:error] [pid 806041:tid 806271] [client 172.213.232.128:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/403.php"] [unique_id "amuOl0LAyZ1MRInzPMb-JQAAAOk"]
[Thu Jul 30 12:49:11.709554 2026] [core:notice] [pid 806041:tid 806239] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:11.760173 2026] [security2:error] [pid 806041:tid 806211] [client 20.91.199.21:33751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuOl0LAyZ1MRInzPMb-LQAAAK0"]
[Thu Jul 30 12:49:11.807823 2026] [security2:error] [pid 806041:tid 806164] [remote 216.73.216.152:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuOl0LAyZ1MRInzPMb-LwAAnXo"]
[Thu Jul 30 12:49:11.864672 2026] [security2:error] [pid 806041:tid 806261] [client 20.151.221.234:2781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuOl0LAyZ1MRInzPMb-MAAAAN8"]
[Thu Jul 30 12:49:12.151966 2026] [core:notice] [pid 806041:tid 806267] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:12.298868 2026] [core:notice] [pid 806041:tid 806232] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:12.303227 2026] [security2:error] [pid 806041:tid 806232] [client 103.215.74.26:20688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOmELAyZ1MRInzPMb-TAAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:12.333560 2026] [security2:error] [pid 806041:tid 806277] [client 68.221.186.136:27955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/f35.php"] [unique_id "amuOmELAyZ1MRInzPMb-TQAAAO8"]
[Thu Jul 30 12:49:12.451178 2026] [security2:error] [pid 806041:tid 806274] [client 172.213.232.128:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/404.php"] [unique_id "amuOmELAyZ1MRInzPMb-UgAAAOw"]
[Thu Jul 30 12:49:12.869134 2026] [security2:error] [pid 806041:tid 806194] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOmELAyZ1MRInzPMb-SwAAnA0"]
[Thu Jul 30 12:49:12.871727 2026] [security2:error] [pid 806041:tid 806180] [client 150.107.232.194:27377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOmELAyZ1MRInzPMb-WQAAAI4"]
[Thu Jul 30 12:49:12.871813 2026] [security2:error] [pid 806041:tid 806180] [client 150.107.232.194:27377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOmELAyZ1MRInzPMb-WQAAAI4"]
[Thu Jul 30 12:49:12.895332 2026] [core:error] [pid 806041:tid 806246] [client 20.151.221.234:63242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:12.895350 2026] [core:error] [pid 806041:tid 806246] [client 20.151.221.234:63242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:12.943034 2026] [security2:error] [pid 806041:tid 806292] [client 20.91.199.21:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuOmELAyZ1MRInzPMb-XgAAAP4"]
[Thu Jul 30 12:49:12.978051 2026] [security2:error] [pid 806041:tid 806201] [client 20.113.56.22:15514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuOmELAyZ1MRInzPMb-XwAAAKM"]
[Thu Jul 30 12:49:12.978179 2026] [security2:error] [pid 806041:tid 806201] [client 20.113.56.22:15514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuOmELAyZ1MRInzPMb-XwAAAKM"]
[Thu Jul 30 12:49:13.026966 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:13.031127 2026] [security2:error] [pid 806041:tid 806205] [client 103.215.74.26:24498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOmULAyZ1MRInzPMb-YwAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:13.178632 2026] [security2:error] [pid 806041:tid 806155] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOmULAyZ1MRInzPMb-ZAAAwHE"]
[Thu Jul 30 12:49:13.178870 2026] [security2:error] [pid 806041:tid 806230] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOmULAyZ1MRInzPMb-ZAAAwHE"]
[Thu Jul 30 12:49:13.252545 2026] [security2:error] [pid 806041:tid 806196] [client 20.113.56.22:15492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuOmULAyZ1MRInzPMb-aAAAAJ4"]
[Thu Jul 30 12:49:13.252649 2026] [security2:error] [pid 806041:tid 806196] [client 20.113.56.22:15492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuOmULAyZ1MRInzPMb-aAAAAJ4"]
[Thu Jul 30 12:49:13.259589 2026] [security2:error] [pid 806041:tid 806179] [client 20.91.199.21:43301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/ova.php"] [unique_id "amuOmULAyZ1MRInzPMb-aQAAAI0"]
[Thu Jul 30 12:49:13.589250 2026] [security2:error] [pid 806041:tid 806272] [client 20.113.56.22:15591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/x.php"] [unique_id "amuOmULAyZ1MRInzPMb-cAAAAOo"]
[Thu Jul 30 12:49:13.589348 2026] [security2:error] [pid 806041:tid 806272] [client 20.113.56.22:15591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/x.php"] [unique_id "amuOmULAyZ1MRInzPMb-cAAAAOo"]
[Thu Jul 30 12:49:13.770504 2026] [core:notice] [pid 806041:tid 806289] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:13.775131 2026] [security2:error] [pid 806041:tid 806289] [client 103.215.74.26:24500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOmULAyZ1MRInzPMb-dwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:13.834549 2026] [security2:error] [pid 806041:tid 806215] [client 20.91.199.21:36899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuOmULAyZ1MRInzPMb-ewAAALE"]
[Thu Jul 30 12:49:13.844963 2026] [security2:error] [pid 806041:tid 806228] [client 20.151.221.234:63263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/admin.php"] [unique_id "amuOmULAyZ1MRInzPMb-fAAAAL4"]
[Thu Jul 30 12:49:13.856496 2026] [security2:error] [pid 806041:tid 806214] [client 20.113.56.22:15515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/mgrr.php"] [unique_id "amuOmULAyZ1MRInzPMb-fQAAALA"]
[Thu Jul 30 12:49:13.856623 2026] [security2:error] [pid 806041:tid 806214] [client 20.113.56.22:15515] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/mgrr.php"] [unique_id "amuOmULAyZ1MRInzPMb-fQAAALA"]
[Thu Jul 30 12:49:14.122805 2026] [security2:error] [pid 806041:tid 806218] [client 20.113.56.22:15503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/domvf.php"] [unique_id "amuOmkLAyZ1MRInzPMb-gwAAALQ"]
[Thu Jul 30 12:49:14.122919 2026] [security2:error] [pid 806041:tid 806218] [client 20.113.56.22:15503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/domvf.php"] [unique_id "amuOmkLAyZ1MRInzPMb-gwAAALQ"]
[Thu Jul 30 12:49:14.385583 2026] [security2:error] [pid 806041:tid 806255] [client 20.113.56.22:15496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/yup.php"] [unique_id "amuOmkLAyZ1MRInzPMb-jgAAANk"]
[Thu Jul 30 12:49:14.385722 2026] [security2:error] [pid 806041:tid 806255] [client 20.113.56.22:15496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/yup.php"] [unique_id "amuOmkLAyZ1MRInzPMb-jgAAANk"]
[Thu Jul 30 12:49:14.387483 2026] [security2:error] [pid 806041:tid 806200] [client 68.221.186.136:27928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pkf.jo"] [uri "/f7.php"] [unique_id "amuOmkLAyZ1MRInzPMb-jwAAAKI"]
[Thu Jul 30 12:49:14.476073 2026] [security2:error] [pid 806041:tid 806257] [client 172.213.232.128:60700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/aa.php"] [unique_id "amuOmkLAyZ1MRInzPMb-kAAAANs"]
[Thu Jul 30 12:49:14.515041 2026] [core:notice] [pid 806041:tid 806283] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:14.519467 2026] [security2:error] [pid 806041:tid 806283] [client 103.215.74.26:24512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOmkLAyZ1MRInzPMb-kQAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:14.568409 2026] [security2:error] [pid 806041:tid 806229] [client 20.91.199.21:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuOmkLAyZ1MRInzPMb-lQAAAL8"]
[Thu Jul 30 12:49:14.647661 2026] [security2:error] [pid 806041:tid 806212] [client 20.113.56.22:15611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/X.php"] [unique_id "amuOmkLAyZ1MRInzPMb-mQAAAK4"]
[Thu Jul 30 12:49:14.647752 2026] [security2:error] [pid 806041:tid 806212] [client 20.113.56.22:15611] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/X.php"] [unique_id "amuOmkLAyZ1MRInzPMb-mQAAAK4"]
[Thu Jul 30 12:49:14.651870 2026] [security2:error] [pid 806041:tid 806192] [client 20.151.221.234:49063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-configs.php"] [unique_id "amuOmkLAyZ1MRInzPMb-mgAAAJo"]
[Thu Jul 30 12:49:14.942352 2026] [security2:error] [pid 806041:tid 806178] [client 20.113.56.22:15558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuOmkLAyZ1MRInzPMb-owAAAIw"]
[Thu Jul 30 12:49:14.942444 2026] [security2:error] [pid 806041:tid 806178] [client 20.113.56.22:15558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuOmkLAyZ1MRInzPMb-owAAAIw"]
[Thu Jul 30 12:49:15.136555 2026] [security2:error] [pid 806041:tid 806240] [client 20.91.199.21:40294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuOm0LAyZ1MRInzPMb-qgAAAMo"]
[Thu Jul 30 12:49:15.203721 2026] [security2:error] [pid 806041:tid 806176] [client 20.113.56.22:15593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/gec.php"] [unique_id "amuOm0LAyZ1MRInzPMb-qwAAAIo"]
[Thu Jul 30 12:49:15.203872 2026] [security2:error] [pid 806041:tid 806176] [client 20.113.56.22:15593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/gec.php"] [unique_id "amuOm0LAyZ1MRInzPMb-qwAAAIo"]
[Thu Jul 30 12:49:15.282711 2026] [core:notice] [pid 806041:tid 806251] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:15.289459 2026] [security2:error] [pid 806041:tid 806251] [client 103.215.74.26:24516] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOm0LAyZ1MRInzPMb-rgAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:15.458880 2026] [security2:error] [pid 806041:tid 806188] [client 20.91.199.21:43354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/robots.php"] [unique_id "amuOm0LAyZ1MRInzPMb-sAAAAJY"]
[Thu Jul 30 12:49:15.463942 2026] [security2:error] [pid 806041:tid 806235] [client 20.113.56.22:15592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/sky.php"] [unique_id "amuOm0LAyZ1MRInzPMb-sQAAAMU"]
[Thu Jul 30 12:49:15.464072 2026] [security2:error] [pid 806041:tid 806235] [client 20.113.56.22:15592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/sky.php"] [unique_id "amuOm0LAyZ1MRInzPMb-sQAAAMU"]
[Thu Jul 30 12:49:15.726041 2026] [security2:error] [pid 806041:tid 806287] [client 20.113.56.22:15557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/fffm.php"] [unique_id "amuOm0LAyZ1MRInzPMb-ugAAAPk"]
[Thu Jul 30 12:49:15.726140 2026] [security2:error] [pid 806041:tid 806287] [client 20.113.56.22:15557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/fffm.php"] [unique_id "amuOm0LAyZ1MRInzPMb-ugAAAPk"]
[Thu Jul 30 12:49:15.947901 2026] [security2:error] [pid 806041:tid 806289] [client 20.91.199.21:33737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuOm0LAyZ1MRInzPMb-vwAAAPs"]
[Thu Jul 30 12:49:16.016278 2026] [security2:error] [pid 806041:tid 806258] [client 20.113.56.22:15495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/sixxis.php"] [unique_id "amuOnELAyZ1MRInzPMb-wQAAANw"]
[Thu Jul 30 12:49:16.016390 2026] [security2:error] [pid 806041:tid 806258] [client 20.113.56.22:15495] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/sixxis.php"] [unique_id "amuOnELAyZ1MRInzPMb-wQAAANw"]
[Thu Jul 30 12:49:16.049588 2026] [security2:error] [pid 806041:tid 806221] [client 20.151.221.234:46328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/admin.php"] [unique_id "amuOnELAyZ1MRInzPMb-xQAAALc"]
[Thu Jul 30 12:49:16.278153 2026] [security2:error] [pid 806041:tid 806255] [client 20.113.56.22:15560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/yj09.php"] [unique_id "amuOnELAyZ1MRInzPMb-zAAAANk"]
[Thu Jul 30 12:49:16.278264 2026] [security2:error] [pid 806041:tid 806255] [client 20.113.56.22:15560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/yj09.php"] [unique_id "amuOnELAyZ1MRInzPMb-zAAAANk"]
[Thu Jul 30 12:49:16.538200 2026] [security2:error] [pid 806041:tid 806181] [client 20.113.56.22:15601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/k.php"] [unique_id "amuOnELAyZ1MRInzPMb-1AAAAI8"]
[Thu Jul 30 12:49:16.538341 2026] [security2:error] [pid 806041:tid 806181] [client 20.113.56.22:15601] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/k.php"] [unique_id "amuOnELAyZ1MRInzPMb-1AAAAI8"]
[Thu Jul 30 12:49:16.565099 2026] [security2:error] [pid 806041:tid 806241] [client 20.151.221.234:53407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/php.php"] [unique_id "amuOnELAyZ1MRInzPMb-1QAAAMs"]
[Thu Jul 30 12:49:16.807064 2026] [security2:error] [pid 806041:tid 806223] [client 20.113.56.22:15573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/k2.php"] [unique_id "amuOnELAyZ1MRInzPMb-3wAAALk"]
[Thu Jul 30 12:49:16.807170 2026] [security2:error] [pid 806041:tid 806223] [client 20.113.56.22:15573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/k2.php"] [unique_id "amuOnELAyZ1MRInzPMb-3wAAALk"]
[Thu Jul 30 12:49:16.817731 2026] [security2:error] [pid 806041:tid 806244] [client 20.91.199.21:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/alf.php"] [unique_id "amuOnELAyZ1MRInzPMb-4AAAAM4"]
[Thu Jul 30 12:49:16.823079 2026] [security2:error] [pid 806041:tid 806094] [remote 57.141.0.41:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuOnELAyZ1MRInzPMb-4QAAlzQ"]
[Thu Jul 30 12:49:16.998630 2026] [security2:error] [pid 806041:tid 806283] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOnELAyZ1MRInzPMb-0gAAAPU"]
[Thu Jul 30 12:49:17.070293 2026] [security2:error] [pid 806041:tid 806279] [client 20.113.56.22:15493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/w.php"] [unique_id "amuOnULAyZ1MRInzPMb-6gAAAPE"]
[Thu Jul 30 12:49:17.070410 2026] [security2:error] [pid 806041:tid 806279] [client 20.113.56.22:15493] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/w.php"] [unique_id "amuOnULAyZ1MRInzPMb-6gAAAPE"]
[Thu Jul 30 12:49:17.330927 2026] [security2:error] [pid 806041:tid 806186] [client 20.113.56.22:15552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/fpwch.php"] [unique_id "amuOnULAyZ1MRInzPMb-9AAAAJQ"]
[Thu Jul 30 12:49:17.331054 2026] [security2:error] [pid 806041:tid 806186] [client 20.113.56.22:15552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/fpwch.php"] [unique_id "amuOnULAyZ1MRInzPMb-9AAAAJQ"]
[Thu Jul 30 12:49:17.454335 2026] [security2:error] [pid 806041:tid 806183] [client 20.151.221.234:55937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/index.php"] [unique_id "amuOnULAyZ1MRInzPMb--AAAAJE"]
[Thu Jul 30 12:49:17.578281 2026] [security2:error] [pid 806041:tid 806269] [client 20.91.199.21:43288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/feedback.php"] [unique_id "amuOnULAyZ1MRInzPMb--QAAAOc"]
[Thu Jul 30 12:49:17.585880 2026] [security2:error] [pid 806041:tid 806265] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOnELAyZ1MRInzPMb-6AAAAOM"]
[Thu Jul 30 12:49:17.590529 2026] [security2:error] [pid 806041:tid 806217] [client 20.113.56.22:15556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/w2025.php"] [unique_id "amuOnULAyZ1MRInzPMb--gAAALM"]
[Thu Jul 30 12:49:17.590610 2026] [security2:error] [pid 806041:tid 806217] [client 20.113.56.22:15556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/w2025.php"] [unique_id "amuOnULAyZ1MRInzPMb--gAAALM"]
[Thu Jul 30 12:49:17.665053 2026] [security2:error] [pid 806041:tid 806215] [client 20.91.199.21:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuOnULAyZ1MRInzPMb-_QAAALE"]
[Thu Jul 30 12:49:17.851076 2026] [security2:error] [pid 806041:tid 806294] [client 20.113.56.22:15499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/FWAZ.php"] [unique_id "amuOnULAyZ1MRInzPMb_CAAAAQA"]
[Thu Jul 30 12:49:17.851192 2026] [security2:error] [pid 806041:tid 806294] [client 20.113.56.22:15499] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/FWAZ.php"] [unique_id "amuOnULAyZ1MRInzPMb_CAAAAQA"]
[Thu Jul 30 12:49:18.113221 2026] [security2:error] [pid 806041:tid 806257] [client 20.113.56.22:15609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/qterm.php"] [unique_id "amuOnkLAyZ1MRInzPMb_DQAAANs"]
[Thu Jul 30 12:49:18.113347 2026] [security2:error] [pid 806041:tid 806257] [client 20.113.56.22:15609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/qterm.php"] [unique_id "amuOnkLAyZ1MRInzPMb_DQAAANs"]
[Thu Jul 30 12:49:18.372340 2026] [security2:error] [pid 806041:tid 806263] [client 20.113.56.22:15562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/blurbs.php"] [unique_id "amuOnkLAyZ1MRInzPMb_FwAAAOE"]
[Thu Jul 30 12:49:18.372450 2026] [security2:error] [pid 806041:tid 806263] [client 20.113.56.22:15562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/blurbs.php"] [unique_id "amuOnkLAyZ1MRInzPMb_FwAAAOE"]
[Thu Jul 30 12:49:18.520030 2026] [security2:error] [pid 806041:tid 806225] [client 172.213.232.128:62454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/aafewc0k.php"] [unique_id "amuOnkLAyZ1MRInzPMb_GQAAALs"]
[Thu Jul 30 12:49:18.558952 2026] [security2:error] [pid 806041:tid 806232] [client 20.151.221.234:22578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-configs.php"] [unique_id "amuOnkLAyZ1MRInzPMb_GgAAAMI"]
[Thu Jul 30 12:49:18.574578 2026] [security2:error] [pid 806041:tid 806255] [client 20.151.221.234:41395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/a.php"] [unique_id "amuOnkLAyZ1MRInzPMb_GwAAANk"]
[Thu Jul 30 12:49:18.631987 2026] [security2:error] [pid 806041:tid 806175] [client 20.113.56.22:15522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-ws68.php"] [unique_id "amuOnkLAyZ1MRInzPMb_HAAAAIk"]
[Thu Jul 30 12:49:18.632110 2026] [security2:error] [pid 806041:tid 806175] [client 20.113.56.22:15522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-ws68.php"] [unique_id "amuOnkLAyZ1MRInzPMb_HAAAAIk"]
[Thu Jul 30 12:49:18.862143 2026] [security2:error] [pid 806041:tid 806233] [client 20.91.199.21:36868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuOnkLAyZ1MRInzPMb_JAAAAMM"]
[Thu Jul 30 12:49:18.900046 2026] [security2:error] [pid 806041:tid 806285] [client 20.113.56.22:15517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xyn.php"] [unique_id "amuOnkLAyZ1MRInzPMb_KAAAAPc"]
[Thu Jul 30 12:49:18.900153 2026] [security2:error] [pid 806041:tid 806285] [client 20.113.56.22:15517] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xyn.php"] [unique_id "amuOnkLAyZ1MRInzPMb_KAAAAPc"]
[Thu Jul 30 12:49:19.190109 2026] [security2:error] [pid 806041:tid 806222] [client 20.113.56.22:15583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ccc.php"] [unique_id "amuOn0LAyZ1MRInzPMb_KgAAALg"]
[Thu Jul 30 12:49:19.190223 2026] [security2:error] [pid 806041:tid 806222] [client 20.113.56.22:15583] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ccc.php"] [unique_id "amuOn0LAyZ1MRInzPMb_KgAAALg"]
[Thu Jul 30 12:49:19.464569 2026] [core:error] [pid 806041:tid 806186] [client 20.151.221.234:55972] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:19.464593 2026] [core:error] [pid 806041:tid 806186] [client 20.151.221.234:55972] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:19.468539 2026] [security2:error] [pid 806041:tid 806181] [client 20.91.199.21:43264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/gettest.php"] [unique_id "amuOn0LAyZ1MRInzPMb_NQAAAI8"]
[Thu Jul 30 12:49:19.479268 2026] [security2:error] [pid 806041:tid 806217] [client 20.113.56.22:15575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/get.php"] [unique_id "amuOn0LAyZ1MRInzPMb_NgAAALM"]
[Thu Jul 30 12:49:19.479360 2026] [security2:error] [pid 806041:tid 806217] [client 20.113.56.22:15575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/get.php"] [unique_id "amuOn0LAyZ1MRInzPMb_NgAAALM"]
[Thu Jul 30 12:49:19.743911 2026] [security2:error] [pid 806041:tid 806221] [client 20.113.56.22:15572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/images.php"] [unique_id "amuOn0LAyZ1MRInzPMb_OwAAALc"]
[Thu Jul 30 12:49:19.744028 2026] [security2:error] [pid 806041:tid 806221] [client 20.113.56.22:15572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/images.php"] [unique_id "amuOn0LAyZ1MRInzPMb_OwAAALc"]
[Thu Jul 30 12:49:19.800675 2026] [security2:error] [pid 806041:tid 806215] [client 216.73.217.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.collectgabon.com"] [uri "/index.php"] [unique_id "amuOn0LAyZ1MRInzPMb_OgAAALE"]
[Thu Jul 30 12:49:19.855070 2026] [security2:error] [pid 806041:tid 806258] [client 172.213.232.128:58776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/abcd.php"] [unique_id "amuOn0LAyZ1MRInzPMb_QgAAANw"]
[Thu Jul 30 12:49:20.074100 2026] [security2:error] [pid 806041:tid 806219] [client 20.113.56.22:15594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/alls.php"] [unique_id "amuOoELAyZ1MRInzPMb_RgAAALU"]
[Thu Jul 30 12:49:20.074245 2026] [security2:error] [pid 806041:tid 806219] [client 20.113.56.22:15594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/alls.php"] [unique_id "amuOoELAyZ1MRInzPMb_RgAAALU"]
[Thu Jul 30 12:49:20.084701 2026] [security2:error] [pid 806041:tid 806281] [client 20.151.221.234:37184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/php.php"] [unique_id "amuOoELAyZ1MRInzPMb_RwAAAPM"]
[Thu Jul 30 12:49:20.336014 2026] [security2:error] [pid 806041:tid 806212] [client 20.113.56.22:15508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/coffexium.php"] [unique_id "amuOoELAyZ1MRInzPMb_TAAAAK4"]
[Thu Jul 30 12:49:20.336108 2026] [security2:error] [pid 806041:tid 806212] [client 20.113.56.22:15508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/coffexium.php"] [unique_id "amuOoELAyZ1MRInzPMb_TAAAAK4"]
[Thu Jul 30 12:49:20.363357 2026] [security2:error] [pid 806041:tid 806111] [remote 57.141.0.18:50902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuOoELAyZ1MRInzPMb_UAABBEU"]
[Thu Jul 30 12:49:20.599324 2026] [security2:error] [pid 806041:tid 806208] [client 20.113.56.22:15612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/red.php"] [unique_id "amuOoELAyZ1MRInzPMb_VAAAAKo"]
[Thu Jul 30 12:49:20.599465 2026] [security2:error] [pid 806041:tid 806208] [client 20.113.56.22:15612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/red.php"] [unique_id "amuOoELAyZ1MRInzPMb_VAAAAKo"]
[Thu Jul 30 12:49:20.681241 2026] [security2:error] [pid 806041:tid 806223] [client 172.213.232.128:49625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/about.php"] [unique_id "amuOoELAyZ1MRInzPMb_VQAAALk"]
[Thu Jul 30 12:49:20.871136 2026] [security2:error] [pid 806041:tid 806245] [client 20.113.56.22:15510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOoELAyZ1MRInzPMb_YAAAAM8"]
[Thu Jul 30 12:49:21.002905 2026] [security2:error] [pid 806041:tid 806285] [client 20.113.56.22:15510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOoULAyZ1MRInzPMb_ZAAAAPc"]
[Thu Jul 30 12:49:21.035051 2026] [security2:error] [pid 806041:tid 806198] [client 20.91.199.21:43361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/maint.php"] [unique_id "amuOoULAyZ1MRInzPMb_ZQAAAKA"]
[Thu Jul 30 12:49:21.092845 2026] [core:notice] [pid 806041:tid 806256] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:21.099202 2026] [security2:error] [pid 806041:tid 806256] [client 103.215.74.26:24532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOoULAyZ1MRInzPMb_ZgAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:21.133092 2026] [security2:error] [pid 806041:tid 806240] [client 20.113.56.22:15510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuOoULAyZ1MRInzPMb_ZwAAAMo"]
[Thu Jul 30 12:49:21.133208 2026] [security2:error] [pid 806041:tid 806240] [client 20.113.56.22:15510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuOoULAyZ1MRInzPMb_ZwAAAMo"]
[Thu Jul 30 12:49:21.406993 2026] [security2:error] [pid 806041:tid 806296] [client 20.113.56.22:15554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOoULAyZ1MRInzPMb_bwAAAQI"]
[Thu Jul 30 12:49:21.539659 2026] [security2:error] [pid 806041:tid 806261] [client 20.113.56.22:15554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOoULAyZ1MRInzPMb_dQAAAN8"]
[Thu Jul 30 12:49:21.677008 2026] [security2:error] [pid 806041:tid 806287] [client 20.113.56.22:15554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOoULAyZ1MRInzPMb_dwAAAPk"]
[Thu Jul 30 12:49:21.809021 2026] [security2:error] [pid 806041:tid 806237] [client 20.113.56.22:15554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOoULAyZ1MRInzPMb_eQAAAMc"]
[Thu Jul 30 12:49:21.828202 2026] [core:notice] [pid 806041:tid 806269] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:21.832844 2026] [security2:error] [pid 806041:tid 806269] [client 103.215.74.26:24546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOoULAyZ1MRInzPMb_fAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:21.940912 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:15554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/index.php"] [unique_id "amuOoULAyZ1MRInzPMb_hAAAANI"]
[Thu Jul 30 12:49:21.941045 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:15554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/index.php"] [unique_id "amuOoULAyZ1MRInzPMb_hAAAANI"]
[Thu Jul 30 12:49:22.210003 2026] [security2:error] [pid 806041:tid 806258] [client 20.91.199.21:20304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuOokLAyZ1MRInzPMb_iQAAANw"]
[Thu Jul 30 12:49:22.218323 2026] [security2:error] [pid 806041:tid 806281] [client 213.152.161.170:33328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuOokLAyZ1MRInzPMb_igAAAPM"]
[Thu Jul 30 12:49:22.218411 2026] [security2:error] [pid 806041:tid 806281] [client 213.152.161.170:33328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuOokLAyZ1MRInzPMb_igAAAPM"]
[Thu Jul 30 12:49:22.236054 2026] [security2:error] [pid 806041:tid 806197] [client 20.113.56.22:15569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/admin.php"] [unique_id "amuOokLAyZ1MRInzPMb_iwAAAJ8"]
[Thu Jul 30 12:49:22.236135 2026] [security2:error] [pid 806041:tid 806197] [client 20.113.56.22:15569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/admin.php"] [unique_id "amuOokLAyZ1MRInzPMb_iwAAAJ8"]
[Thu Jul 30 12:49:22.380029 2026] [security2:error] [pid 806041:tid 806250] [client 172.213.232.128:58787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/admin.php"] [unique_id "amuOokLAyZ1MRInzPMb_kgAAANQ"]
[Thu Jul 30 12:49:22.502733 2026] [security2:error] [pid 806041:tid 806192] [client 20.113.56.22:15602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/177.php"] [unique_id "amuOokLAyZ1MRInzPMb_lgAAAJo"]
[Thu Jul 30 12:49:22.502838 2026] [security2:error] [pid 806041:tid 806192] [client 20.113.56.22:15602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/177.php"] [unique_id "amuOokLAyZ1MRInzPMb_lgAAAJo"]
[Thu Jul 30 12:49:22.576150 2026] [core:notice] [pid 806041:tid 806180] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:22.584722 2026] [security2:error] [pid 806041:tid 806180] [client 103.215.74.26:24554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOokLAyZ1MRInzPMb_mwAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:22.797096 2026] [security2:error] [pid 806041:tid 806268] [client 20.113.56.22:15491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/199.php"] [unique_id "amuOokLAyZ1MRInzPMb_nAAAAOY"]
[Thu Jul 30 12:49:22.797215 2026] [security2:error] [pid 806041:tid 806268] [client 20.113.56.22:15491] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/199.php"] [unique_id "amuOokLAyZ1MRInzPMb_nAAAAOY"]
[Thu Jul 30 12:49:23.094968 2026] [core:error] [pid 806041:tid 806271] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:23.095012 2026] [core:error] [pid 806041:tid 806271] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:23.103386 2026] [security2:error] [pid 806041:tid 806178] [client 172.213.232.128:56895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/adminfuns.php"] [unique_id "amuOo0LAyZ1MRInzPMb_sAAAAIw"]
[Thu Jul 30 12:49:23.116215 2026] [security2:error] [pid 806041:tid 806177] [client 20.91.199.21:43327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/files.php"] [unique_id "amuOo0LAyZ1MRInzPMb_swAAAIs"]
[Thu Jul 30 12:49:23.126170 2026] [security2:error] [pid 806041:tid 806235] [client 20.113.56.22:15587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file52.php"] [unique_id "amuOo0LAyZ1MRInzPMb_tQAAAMU"]
[Thu Jul 30 12:49:23.126279 2026] [security2:error] [pid 806041:tid 806235] [client 20.113.56.22:15587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file52.php"] [unique_id "amuOo0LAyZ1MRInzPMb_tQAAAMU"]
[Thu Jul 30 12:49:23.297481 2026] [core:error] [pid 806041:tid 806286] [client 20.151.221.234:43722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:23.297502 2026] [core:error] [pid 806041:tid 806286] [client 20.151.221.234:43722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:23.307929 2026] [security2:error] [pid 806041:tid 806184] [client 20.91.199.21:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuOo0LAyZ1MRInzPMb_vgAAAJI"]
[Thu Jul 30 12:49:23.313948 2026] [core:notice] [pid 806041:tid 806288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:23.324331 2026] [security2:error] [pid 806041:tid 806288] [client 103.215.74.26:18042] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOo0LAyZ1MRInzPMb_vwAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:23.370243 2026] [security2:error] [pid 806041:tid 806187] [client 150.107.232.194:27138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOo0LAyZ1MRInzPMb_wQAAAJU"]
[Thu Jul 30 12:49:23.370370 2026] [security2:error] [pid 806041:tid 806187] [client 150.107.232.194:27138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOo0LAyZ1MRInzPMb_wQAAAJU"]
[Thu Jul 30 12:49:23.397786 2026] [security2:error] [pid 806041:tid 806209] [client 20.113.56.22:15608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/geck.php"] [unique_id "amuOo0LAyZ1MRInzPMb_wgAAAKs"]
[Thu Jul 30 12:49:23.397888 2026] [security2:error] [pid 806041:tid 806209] [client 20.113.56.22:15608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/geck.php"] [unique_id "amuOo0LAyZ1MRInzPMb_wgAAAKs"]
[Thu Jul 30 12:49:23.661217 2026] [security2:error] [pid 806041:tid 806226] [client 20.113.56.22:15518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/biufile.php"] [unique_id "amuOo0LAyZ1MRInzPMb_0AAAALw"]
[Thu Jul 30 12:49:23.661344 2026] [security2:error] [pid 806041:tid 806226] [client 20.113.56.22:15518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/biufile.php"] [unique_id "amuOo0LAyZ1MRInzPMb_0AAAALw"]
[Thu Jul 30 12:49:23.928042 2026] [security2:error] [pid 806041:tid 806238] [client 20.113.56.22:15502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dejavu.php"] [unique_id "amuOo0LAyZ1MRInzPMb_1AAAAMg"]
[Thu Jul 30 12:49:23.928168 2026] [security2:error] [pid 806041:tid 806238] [client 20.113.56.22:15502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dejavu.php"] [unique_id "amuOo0LAyZ1MRInzPMb_1AAAAMg"]
[Thu Jul 30 12:49:23.965725 2026] [security2:error] [pid 806041:tid 806166] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOo0LAyZ1MRInzPMb_2wAArnw"]
[Thu Jul 30 12:49:23.965956 2026] [security2:error] [pid 806041:tid 806212] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOo0LAyZ1MRInzPMb_2wAArnw"]
[Thu Jul 30 12:49:24.016784 2026] [security2:error] [pid 806041:tid 806274] [client 20.151.221.234:46308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/index.php"] [unique_id "amuOpELAyZ1MRInzPMb_3wAAAOw"]
[Thu Jul 30 12:49:24.067650 2026] [core:notice] [pid 806041:tid 806231] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:24.071942 2026] [security2:error] [pid 806041:tid 806231] [client 103.215.74.26:18054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOpELAyZ1MRInzPMb_4QAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:24.080306 2026] [security2:error] [pid 806041:tid 806241] [client 20.91.199.21:34358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuOpELAyZ1MRInzPMb_4gAAAMs"]
[Thu Jul 30 12:49:24.218560 2026] [security2:error] [pid 806041:tid 806233] [client 20.113.56.22:12243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/aaf.php"] [unique_id "amuOpELAyZ1MRInzPMb_5gAAAMM"]
[Thu Jul 30 12:49:24.218666 2026] [security2:error] [pid 806041:tid 806233] [client 20.113.56.22:12243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/aaf.php"] [unique_id "amuOpELAyZ1MRInzPMb_5gAAAMM"]
[Thu Jul 30 12:49:24.483426 2026] [security2:error] [pid 806041:tid 806214] [client 20.113.56.22:15568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ha.php"] [unique_id "amuOpELAyZ1MRInzPMb_7wAAALA"]
[Thu Jul 30 12:49:24.483520 2026] [security2:error] [pid 806041:tid 806214] [client 20.113.56.22:15568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ha.php"] [unique_id "amuOpELAyZ1MRInzPMb_7wAAALA"]
[Thu Jul 30 12:49:24.614781 2026] [security2:error] [pid 806041:tid 806286] [client 198.44.157.146:53094] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuOpELAyZ1MRInzPMb_8wAAAPg"]
[Thu Jul 30 12:49:24.614874 2026] [security2:error] [pid 806041:tid 806286] [client 198.44.157.146:53094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuOpELAyZ1MRInzPMb_8wAAAPg"]
[Thu Jul 30 12:49:24.641815 2026] [security2:error] [pid 806041:tid 806204] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOpELAyZ1MRInzPMb_4AAApgU"]
[Thu Jul 30 12:49:24.745743 2026] [security2:error] [pid 806041:tid 806257] [client 20.113.56.22:15599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/hur.php"] [unique_id "amuOpELAyZ1MRInzPMb_-gAAANs"]
[Thu Jul 30 12:49:24.745832 2026] [security2:error] [pid 806041:tid 806257] [client 20.113.56.22:15599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/hur.php"] [unique_id "amuOpELAyZ1MRInzPMb_-gAAANs"]
[Thu Jul 30 12:49:24.794381 2026] [core:notice] [pid 806041:tid 806291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:24.798694 2026] [security2:error] [pid 806041:tid 806291] [client 103.215.74.26:18058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOpELAyZ1MRInzPMb_-wAAAP0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:24.879036 2026] [security2:error] [pid 806041:tid 806195] [client 20.91.199.21:36866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuOpELAyZ1MRInzPMb__AAAAJ0"]
[Thu Jul 30 12:49:25.021218 2026] [security2:error] [pid 806041:tid 806266] [client 20.113.56.22:15494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/h02ugyh.php"] [unique_id "amuOpULAyZ1MRInzPMYAAgAAAOQ"]
[Thu Jul 30 12:49:25.021334 2026] [security2:error] [pid 806041:tid 806266] [client 20.113.56.22:15494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/h02ugyh.php"] [unique_id "amuOpULAyZ1MRInzPMYAAgAAAOQ"]
[Thu Jul 30 12:49:25.072337 2026] [security2:error] [pid 806041:tid 806280] [client 20.91.199.21:43282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/gecko.php"] [unique_id "amuOpULAyZ1MRInzPMYABwAAAPI"]
[Thu Jul 30 12:49:25.307257 2026] [core:notice] [pid 806041:tid 806278] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:25.309250 2026] [security2:error] [pid 806041:tid 806197] [client 20.113.56.22:15615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/155.php"] [unique_id "amuOpULAyZ1MRInzPMYACwAAAJ8"]
[Thu Jul 30 12:49:25.309344 2026] [security2:error] [pid 806041:tid 806197] [client 20.113.56.22:15615] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/155.php"] [unique_id "amuOpULAyZ1MRInzPMYACwAAAJ8"]
[Thu Jul 30 12:49:25.311280 2026] [security2:error] [pid 806041:tid 806278] [client 66.249.79.1:46334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/citationstylelanguage/get/acm-sig-proceedings"] [unique_id "amuOpULAyZ1MRInzPMYAAwAAAPA"]
[Thu Jul 30 12:49:25.524747 2026] [core:notice] [pid 806041:tid 806281] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:25.528891 2026] [security2:error] [pid 806041:tid 806281] [client 103.215.74.26:18074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOpULAyZ1MRInzPMYADwAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:25.555781 2026] [security2:error] [pid 806041:tid 806186] [client 20.151.221.234:45876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/a.php"] [unique_id "amuOpULAyZ1MRInzPMYAEQAAAJQ"]
[Thu Jul 30 12:49:25.585069 2026] [security2:error] [pid 806041:tid 806212] [client 20.113.56.22:15530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ops.php"] [unique_id "amuOpULAyZ1MRInzPMYAEgAAAK4"]
[Thu Jul 30 12:49:25.585152 2026] [security2:error] [pid 806041:tid 806212] [client 20.113.56.22:15530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ops.php"] [unique_id "amuOpULAyZ1MRInzPMYAEgAAAK4"]
[Thu Jul 30 12:49:25.631188 2026] [security2:error] [pid 806041:tid 806210] [client 20.91.199.21:39852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuOpULAyZ1MRInzPMYAFgAAAKw"]
[Thu Jul 30 12:49:25.731585 2026] [security2:error] [pid 806041:tid 806292] [client 4.185.41.66:15618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuOpULAyZ1MRInzPMYAGAAAAP4"]
[Thu Jul 30 12:49:25.731717 2026] [security2:error] [pid 806041:tid 806292] [client 4.185.41.66:15618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuOpULAyZ1MRInzPMYAGAAAAP4"]
[Thu Jul 30 12:49:25.875482 2026] [security2:error] [pid 806041:tid 806247] [client 20.113.56.22:15507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ingfo.php"] [unique_id "amuOpULAyZ1MRInzPMYAGwAAANE"]
[Thu Jul 30 12:49:25.875595 2026] [security2:error] [pid 806041:tid 806247] [client 20.113.56.22:15507] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ingfo.php"] [unique_id "amuOpULAyZ1MRInzPMYAGwAAANE"]
[Thu Jul 30 12:49:25.894359 2026] [security2:error] [pid 806041:tid 806216] [client 20.91.199.21:43309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/zwso.php"] [unique_id "amuOpULAyZ1MRInzPMYAHAAAALI"]
[Thu Jul 30 12:49:26.064477 2026] [security2:error] [pid 806041:tid 806260] [client 20.151.221.234:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuOpkLAyZ1MRInzPMYAIAAAAN4"]
[Thu Jul 30 12:49:26.167598 2026] [security2:error] [pid 806041:tid 806245] [client 20.113.56.22:15576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/error_log.php"] [unique_id "amuOpkLAyZ1MRInzPMYAJQAAAM8"]
[Thu Jul 30 12:49:26.167770 2026] [security2:error] [pid 806041:tid 806245] [client 20.113.56.22:15576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/error_log.php"] [unique_id "amuOpkLAyZ1MRInzPMYAJQAAAM8"]
[Thu Jul 30 12:49:26.253452 2026] [core:notice] [pid 806041:tid 806255] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:26.258831 2026] [security2:error] [pid 806041:tid 806255] [client 103.215.74.26:18086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOpkLAyZ1MRInzPMYAJwAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:26.442800 2026] [security2:error] [pid 806041:tid 806252] [client 20.113.56.22:15574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/koala.php"] [unique_id "amuOpkLAyZ1MRInzPMYAKwAAANY"]
[Thu Jul 30 12:49:26.442948 2026] [security2:error] [pid 806041:tid 806252] [client 20.113.56.22:15574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/koala.php"] [unique_id "amuOpkLAyZ1MRInzPMYAKwAAANY"]
[Thu Jul 30 12:49:26.543567 2026] [security2:error] [pid 806041:tid 806249] [client 20.91.199.21:43302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/13.php"] [unique_id "amuOpkLAyZ1MRInzPMYAMAAAANM"]
[Thu Jul 30 12:49:26.711142 2026] [security2:error] [pid 806041:tid 806206] [client 20.113.56.22:15497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/mac.php"] [unique_id "amuOpkLAyZ1MRInzPMYANAAAAKg"]
[Thu Jul 30 12:49:26.711236 2026] [security2:error] [pid 806041:tid 806206] [client 20.113.56.22:15497] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/mac.php"] [unique_id "amuOpkLAyZ1MRInzPMYANAAAAKg"]
[Thu Jul 30 12:49:26.863049 2026] [security2:error] [pid 806041:tid 806180] [client 20.91.199.21:33759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuOpkLAyZ1MRInzPMYAOAAAAI4"]
[Thu Jul 30 12:49:26.973607 2026] [security2:error] [pid 806041:tid 806175] [client 20.113.56.22:12249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wefile.php"] [unique_id "amuOpkLAyZ1MRInzPMYAPwAAAIk"]
[Thu Jul 30 12:49:26.973704 2026] [security2:error] [pid 806041:tid 806175] [client 20.113.56.22:12249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wefile.php"] [unique_id "amuOpkLAyZ1MRInzPMYAPwAAAIk"]
[Thu Jul 30 12:49:26.989107 2026] [core:notice] [pid 806041:tid 806207] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:26.993395 2026] [security2:error] [pid 806041:tid 806207] [client 103.215.74.26:18098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOpkLAyZ1MRInzPMYAQAAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:27.240594 2026] [security2:error] [pid 806041:tid 806203] [client 20.113.56.22:15528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOp0LAyZ1MRInzPMYARwAAAKU"]
[Thu Jul 30 12:49:27.372228 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:15528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOp0LAyZ1MRInzPMYASwAAANI"]
[Thu Jul 30 12:49:27.504670 2026] [security2:error] [pid 806041:tid 806202] [client 20.113.56.22:15528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/cgi-sys/404.html"] [unique_id "amuOp0LAyZ1MRInzPMYATQAAAKQ"]
[Thu Jul 30 12:49:27.635221 2026] [security2:error] [pid 806041:tid 806186] [client 20.113.56.22:15528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/makeasmtp.php"] [unique_id "amuOp0LAyZ1MRInzPMYAUQAAAJQ"]
[Thu Jul 30 12:49:27.635325 2026] [security2:error] [pid 806041:tid 806186] [client 20.113.56.22:15528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/makeasmtp.php"] [unique_id "amuOp0LAyZ1MRInzPMYAUQAAAJQ"]
[Thu Jul 30 12:49:27.720518 2026] [security2:error] [pid 806041:tid 806224] [client 172.213.232.128:49639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/albin.php"] [unique_id "amuOp0LAyZ1MRInzPMYAVQAAALo"]
[Thu Jul 30 12:49:27.720970 2026] [core:notice] [pid 806041:tid 806277] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:27.727536 2026] [security2:error] [pid 806041:tid 806277] [client 103.215.74.26:18102] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOp0LAyZ1MRInzPMYAVAAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:27.897266 2026] [security2:error] [pid 806041:tid 806232] [client 20.113.56.22:15570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/2P.php"] [unique_id "amuOp0LAyZ1MRInzPMYAXwAAAMI"]
[Thu Jul 30 12:49:27.897376 2026] [security2:error] [pid 806041:tid 806232] [client 20.113.56.22:15570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/2P.php"] [unique_id "amuOp0LAyZ1MRInzPMYAXwAAAMI"]
[Thu Jul 30 12:49:28.158297 2026] [security2:error] [pid 806041:tid 806231] [client 20.113.56.22:15578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/.well-known/about.php"] [unique_id "amuOqELAyZ1MRInzPMYAZQAAAME"]
[Thu Jul 30 12:49:28.158436 2026] [security2:error] [pid 806041:tid 806231] [client 20.113.56.22:15578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/.well-known/about.php"] [unique_id "amuOqELAyZ1MRInzPMYAZQAAAME"]
[Thu Jul 30 12:49:28.183868 2026] [security2:error] [pid 806041:tid 806283] [client 4.185.41.66:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuOqELAyZ1MRInzPMYAZgAAAPU"]
[Thu Jul 30 12:49:28.184035 2026] [security2:error] [pid 806041:tid 806283] [client 4.185.41.66:15646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuOqELAyZ1MRInzPMYAZgAAAPU"]
[Thu Jul 30 12:49:28.258038 2026] [core:notice] [pid 806041:tid 806227] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:28.276821 2026] [security2:error] [pid 806041:tid 806260] [client 172.213.232.128:58766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/amfsqvgv.php"] [unique_id "amuOqELAyZ1MRInzPMYAbwAAAN4"]
[Thu Jul 30 12:49:28.438496 2026] [security2:error] [pid 806041:tid 806249] [client 20.113.56.22:15589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuOqELAyZ1MRInzPMYAcwAAANM"]
[Thu Jul 30 12:49:28.438650 2026] [security2:error] [pid 806041:tid 806249] [client 20.113.56.22:15589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuOqELAyZ1MRInzPMYAcwAAANM"]
[Thu Jul 30 12:49:28.481071 2026] [core:notice] [pid 806041:tid 806271] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:28.488433 2026] [security2:error] [pid 806041:tid 806271] [client 103.215.74.26:18104] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOqELAyZ1MRInzPMYAdAAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:28.734336 2026] [security2:error] [pid 806041:tid 806188] [client 20.113.56.22:15532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/system_log.php"] [unique_id "amuOqELAyZ1MRInzPMYAewAAAJY"]
[Thu Jul 30 12:49:28.734442 2026] [security2:error] [pid 806041:tid 806188] [client 20.113.56.22:15532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/system_log.php"] [unique_id "amuOqELAyZ1MRInzPMYAewAAAJY"]
[Thu Jul 30 12:49:29.005026 2026] [security2:error] [pid 806041:tid 806207] [client 20.113.56.22:15596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOqELAyZ1MRInzPMYAgAAAAKk"]
[Thu Jul 30 12:49:29.122259 2026] [security2:error] [pid 806041:tid 806217] [client 20.91.199.21:43338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/ava.php"] [unique_id "amuOqULAyZ1MRInzPMYAggAAALM"]
[Thu Jul 30 12:49:29.136075 2026] [security2:error] [pid 806041:tid 806228] [client 20.113.56.22:15596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOqULAyZ1MRInzPMYAgwAAAL4"]
[Thu Jul 30 12:49:29.202336 2026] [core:notice] [pid 806041:tid 806267] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:29.209240 2026] [security2:error] [pid 806041:tid 806267] [client 66.249.79.1:46334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/citationstylelanguage/get/associacao-brasileira-de-normas-tecnicas"] [unique_id "amuOqULAyZ1MRInzPMYAhwAAAOU"]
[Thu Jul 30 12:49:29.217162 2026] [core:notice] [pid 806041:tid 806175] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:29.224634 2026] [security2:error] [pid 806041:tid 806175] [client 103.215.74.26:18120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOqULAyZ1MRInzPMYAiAAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:29.275528 2026] [security2:error] [pid 806041:tid 806218] [client 20.113.56.22:15596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOqULAyZ1MRInzPMYAiQAAALQ"]
[Thu Jul 30 12:49:29.406485 2026] [security2:error] [pid 806041:tid 806282] [client 20.113.56.22:15596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOqULAyZ1MRInzPMYAjQAAAPQ"]
[Thu Jul 30 12:49:29.535669 2026] [security2:error] [pid 806041:tid 806258] [client 20.113.56.22:15596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/crgio.php"] [unique_id "amuOqULAyZ1MRInzPMYAkwAAANw"]
[Thu Jul 30 12:49:29.535778 2026] [security2:error] [pid 806041:tid 806258] [client 20.113.56.22:15596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/crgio.php"] [unique_id "amuOqULAyZ1MRInzPMYAkwAAANw"]
[Thu Jul 30 12:49:29.692203 2026] [security2:error] [pid 806041:tid 806229] [client 139.28.219.70:58766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuOqULAyZ1MRInzPMYAmAAAAL8"]
[Thu Jul 30 12:49:29.802609 2026] [security2:error] [pid 806041:tid 806246] [client 20.113.56.22:15545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/pucci.php"] [unique_id "amuOqULAyZ1MRInzPMYAmQAAANA"]
[Thu Jul 30 12:49:29.802723 2026] [security2:error] [pid 806041:tid 806246] [client 20.113.56.22:15545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/pucci.php"] [unique_id "amuOqULAyZ1MRInzPMYAmQAAANA"]
[Thu Jul 30 12:49:29.885404 2026] [security2:error] [pid 806041:tid 806281] [client 20.91.199.21:43344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/main.php"] [unique_id "amuOqULAyZ1MRInzPMYAmgAAAPM"]
[Thu Jul 30 12:49:29.941711 2026] [security2:error] [pid 806041:tid 806298] [client 4.185.41.66:15639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuOqULAyZ1MRInzPMYAnQAAAQQ"]
[Thu Jul 30 12:49:29.941814 2026] [security2:error] [pid 806041:tid 806298] [client 4.185.41.66:15639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuOqULAyZ1MRInzPMYAnQAAAQQ"]
[Thu Jul 30 12:49:29.945326 2026] [core:notice] [pid 806041:tid 806194] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:29.950491 2026] [security2:error] [pid 806041:tid 806194] [client 103.215.74.26:18136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOqULAyZ1MRInzPMYAnwAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:29.978467 2026] [security2:error] [pid 806041:tid 806284] [client 172.213.232.128:49655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/ant.php"] [unique_id "amuOqULAyZ1MRInzPMYAowAAAPY"]
[Thu Jul 30 12:49:30.016708 2026] [security2:error] [pid 806041:tid 806244] [client 198.44.157.146:54406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuOqkLAyZ1MRInzPMYApAAAAM4"]
[Thu Jul 30 12:49:30.016784 2026] [security2:error] [pid 806041:tid 806244] [client 198.44.157.146:54406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuOqkLAyZ1MRInzPMYApAAAAM4"]
[Thu Jul 30 12:49:30.037659 2026] [security2:error] [pid 806041:tid 806216] [client 139.28.219.70:58778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/xmlrpc.php"] [unique_id "amuOqkLAyZ1MRInzPMYApQAAALI"]
[Thu Jul 30 12:49:30.070630 2026] [security2:error] [pid 806041:tid 806230] [client 20.113.56.22:12229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOqkLAyZ1MRInzPMYApgAAAMA"]
[Thu Jul 30 12:49:30.182740 2026] [security2:error] [pid 806041:tid 806234] [client 20.91.199.21:33748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuOqkLAyZ1MRInzPMYAqwAAAMQ"]
[Thu Jul 30 12:49:30.202241 2026] [security2:error] [pid 806041:tid 806185] [client 20.113.56.22:12229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOqkLAyZ1MRInzPMYArAAAAJM"]
[Thu Jul 30 12:49:30.339586 2026] [security2:error] [pid 806041:tid 806285] [client 20.113.56.22:12229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOqkLAyZ1MRInzPMYArgAAAPc"]
[Thu Jul 30 12:49:30.415785 2026] [security2:error] [pid 806041:tid 806259] [client 74.7.175.185:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.plumbingplumb.com"] [uri "/index.php"] [unique_id "amuOqULAyZ1MRInzPMYAhgAAAN0"]
[Thu Jul 30 12:49:30.416659 2026] [security2:error] [pid 806041:tid 806287] [client 74.7.175.185:49212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.plumbingplumb.com"] [uri "/robots.txt"] [unique_id "amuOqULAyZ1MRInzPMYAhAAA-S4"]
[Thu Jul 30 12:49:30.445538 2026] [security2:error] [pid 806041:tid 806177] [client 139.28.219.70:58782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuOqkLAyZ1MRInzPMYAsQAAAIs"]
[Thu Jul 30 12:49:30.470366 2026] [security2:error] [pid 806041:tid 806214] [client 20.113.56.22:12229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOqkLAyZ1MRInzPMYAswAAALA"]
[Thu Jul 30 12:49:30.498571 2026] [security2:error] [pid 806041:tid 806189] [client 20.151.221.234:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin.php"] [unique_id "amuOqkLAyZ1MRInzPMYAtAAAAJc"]
[Thu Jul 30 12:49:30.600108 2026] [security2:error] [pid 806041:tid 806265] [client 20.113.56.22:12229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-temp.php"] [unique_id "amuOqkLAyZ1MRInzPMYAuwAAAOM"]
[Thu Jul 30 12:49:30.600272 2026] [security2:error] [pid 806041:tid 806265] [client 20.113.56.22:12229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-temp.php"] [unique_id "amuOqkLAyZ1MRInzPMYAuwAAAOM"]
[Thu Jul 30 12:49:30.664437 2026] [core:notice] [pid 806041:tid 806193] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:30.670873 2026] [security2:error] [pid 806041:tid 806193] [client 103.215.74.26:18148] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOqkLAyZ1MRInzPMYAvQAAAJs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:30.752525 2026] [security2:error] [pid 806041:tid 806270] [client 20.91.199.21:43317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/wp-file.php"] [unique_id "amuOqkLAyZ1MRInzPMYAwQAAAOg"]
[Thu Jul 30 12:49:30.825404 2026] [security2:error] [pid 806041:tid 806172] [client 139.28.219.70:53198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuOqkLAyZ1MRInzPMYAwgAAAIY"]
[Thu Jul 30 12:49:30.861693 2026] [security2:error] [pid 806041:tid 806253] [client 20.113.56.22:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuOqkLAyZ1MRInzPMYAwwAAANc"]
[Thu Jul 30 12:49:30.861787 2026] [security2:error] [pid 806041:tid 806253] [client 20.113.56.22:12238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuOqkLAyZ1MRInzPMYAwwAAANc"]
[Thu Jul 30 12:49:31.113045 2026] [security2:error] [pid 806041:tid 806211] [client 20.91.199.21:40308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuOq0LAyZ1MRInzPMYAzQAAAK0"]
[Thu Jul 30 12:49:31.157405 2026] [security2:error] [pid 806041:tid 806226] [client 20.113.56.22:15516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/puc.php"] [unique_id "amuOq0LAyZ1MRInzPMYA0AAAALw"]
[Thu Jul 30 12:49:31.157586 2026] [security2:error] [pid 806041:tid 806226] [client 20.113.56.22:15516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/puc.php"] [unique_id "amuOq0LAyZ1MRInzPMYA0AAAALw"]
[Thu Jul 30 12:49:31.183290 2026] [security2:error] [pid 806041:tid 806182] [client 139.28.219.70:53200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuOq0LAyZ1MRInzPMYA0QAAAJA"]
[Thu Jul 30 12:49:31.411986 2026] [core:notice] [pid 806041:tid 806273] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:31.416312 2026] [security2:error] [pid 806041:tid 806273] [client 103.215.74.26:18160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOq0LAyZ1MRInzPMYA1QAAAOs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:31.423618 2026] [security2:error] [pid 806041:tid 806277] [client 4.185.41.66:15706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/err.php"] [unique_id "amuOq0LAyZ1MRInzPMYA1gAAAO8"]
[Thu Jul 30 12:49:31.423707 2026] [security2:error] [pid 806041:tid 806277] [client 4.185.41.66:15706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/err.php"] [unique_id "amuOq0LAyZ1MRInzPMYA1gAAAO8"]
[Thu Jul 30 12:49:31.447580 2026] [security2:error] [pid 806041:tid 806219] [client 20.113.56.22:15542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dx.php"] [unique_id "amuOq0LAyZ1MRInzPMYA1wAAALU"]
[Thu Jul 30 12:49:31.447672 2026] [security2:error] [pid 806041:tid 806219] [client 20.113.56.22:15542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dx.php"] [unique_id "amuOq0LAyZ1MRInzPMYA1wAAALU"]
[Thu Jul 30 12:49:31.450401 2026] [security2:error] [pid 806041:tid 806224] [client 139.28.219.70:53214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuOq0LAyZ1MRInzPMYA2AAAALo"]
[Thu Jul 30 12:49:31.657994 2026] [security2:error] [pid 806041:tid 806262] [client 172.213.232.128:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/appreciators.php"] [unique_id "amuOq0LAyZ1MRInzPMYA3wAAAOA"]
[Thu Jul 30 12:49:31.697477 2026] [security2:error] [pid 806041:tid 806221] [client 20.91.199.21:43350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/wp-signin.php"] [unique_id "amuOq0LAyZ1MRInzPMYA4AAAALc"]
[Thu Jul 30 12:49:31.719057 2026] [security2:error] [pid 806041:tid 806192] [client 139.28.219.70:53218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuOq0LAyZ1MRInzPMYA4QAAAJo"]
[Thu Jul 30 12:49:31.756096 2026] [security2:error] [pid 806041:tid 806284] [client 20.113.56.22:12226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOq0LAyZ1MRInzPMYA4wAAAPY"]
[Thu Jul 30 12:49:31.785546 2026] [security2:error] [pid 806041:tid 806218] [client 20.151.221.234:2192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/size.php"] [unique_id "amuOq0LAyZ1MRInzPMYA5wAAALQ"]
[Thu Jul 30 12:49:31.887449 2026] [security2:error] [pid 806041:tid 806230] [client 20.113.56.22:12226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOq0LAyZ1MRInzPMYA6AAAAMA"]
[Thu Jul 30 12:49:31.922101 2026] [security2:error] [pid 806041:tid 806229] [client 20.91.199.21:36919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuOq0LAyZ1MRInzPMYA7AAAAL8"]
[Thu Jul 30 12:49:31.932789 2026] [security2:error] [pid 806041:tid 806268] [client 198.44.157.146:42348] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuOq0LAyZ1MRInzPMYA7QAAAOY"]
[Thu Jul 30 12:49:31.932875 2026] [security2:error] [pid 806041:tid 806268] [client 198.44.157.146:42348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuOq0LAyZ1MRInzPMYA7QAAAOY"]
[Thu Jul 30 12:49:32.016971 2026] [security2:error] [pid 806041:tid 806275] [client 20.113.56.22:12226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/7.php"] [unique_id "amuOrELAyZ1MRInzPMYA7gAAAO0"]
[Thu Jul 30 12:49:32.017109 2026] [security2:error] [pid 806041:tid 806275] [client 20.113.56.22:12226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/7.php"] [unique_id "amuOrELAyZ1MRInzPMYA7gAAAO0"]
[Thu Jul 30 12:49:32.053104 2026] [security2:error] [pid 806041:tid 806245] [client 139.28.219.70:53228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuOrELAyZ1MRInzPMYA8QAAAM8"]
[Thu Jul 30 12:49:32.131900 2026] [core:notice] [pid 806041:tid 806241] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:32.138133 2026] [security2:error] [pid 806041:tid 806241] [client 103.215.74.26:18166] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOrELAyZ1MRInzPMYA9gAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:32.221701 2026] [security2:error] [pid 806041:tid 806285] [client 172.213.232.128:56881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/archive.php"] [unique_id "amuOrELAyZ1MRInzPMYA-AAAAPc"]
[Thu Jul 30 12:49:32.284195 2026] [security2:error] [pid 806041:tid 806265] [client 20.113.56.22:12254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/8.php"] [unique_id "amuOrELAyZ1MRInzPMYA_AAAAOM"]
[Thu Jul 30 12:49:32.284313 2026] [security2:error] [pid 806041:tid 806265] [client 20.113.56.22:12254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/8.php"] [unique_id "amuOrELAyZ1MRInzPMYA_AAAAOM"]
[Thu Jul 30 12:49:32.299876 2026] [security2:error] [pid 806041:tid 806188] [client 4.185.41.66:15623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/img.php"] [unique_id "amuOrELAyZ1MRInzPMYA_QAAAJY"]
[Thu Jul 30 12:49:32.299996 2026] [security2:error] [pid 806041:tid 806188] [client 4.185.41.66:15623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/img.php"] [unique_id "amuOrELAyZ1MRInzPMYA_QAAAJY"]
[Thu Jul 30 12:49:32.338296 2026] [security2:error] [pid 806041:tid 806178] [client 139.28.219.70:53242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuOrELAyZ1MRInzPMYA_gAAAIw"]
[Thu Jul 30 12:49:32.538407 2026] [security2:error] [pid 806041:tid 806189] [client 20.91.199.21:43291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/simi.php"] [unique_id "amuOrELAyZ1MRInzPMYBAQAAAJc"]
[Thu Jul 30 12:49:32.548392 2026] [security2:error] [pid 806041:tid 806261] [client 20.113.56.22:15588] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1.php"] [unique_id "amuOrELAyZ1MRInzPMYBAwAAAN8"]
[Thu Jul 30 12:49:32.548480 2026] [security2:error] [pid 806041:tid 806261] [client 20.113.56.22:15588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1.php"] [unique_id "amuOrELAyZ1MRInzPMYBAwAAAN8"]
[Thu Jul 30 12:49:32.548551 2026] [security2:error] [pid 806041:tid 806261] [client 20.113.56.22:15588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1.php"] [unique_id "amuOrELAyZ1MRInzPMYBAwAAAN8"]
[Thu Jul 30 12:49:32.631535 2026] [security2:error] [pid 806041:tid 806266] [client 139.28.219.70:53252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuOrELAyZ1MRInzPMYBBAAAAOQ"]
[Thu Jul 30 12:49:32.813150 2026] [security2:error] [pid 806041:tid 806290] [client 20.113.56.22:12232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/about.php"] [unique_id "amuOrELAyZ1MRInzPMYBDAAAAPw"]
[Thu Jul 30 12:49:32.813232 2026] [security2:error] [pid 806041:tid 806290] [client 20.113.56.22:12232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/about.php"] [unique_id "amuOrELAyZ1MRInzPMYBDAAAAPw"]
[Thu Jul 30 12:49:32.851905 2026] [core:notice] [pid 806041:tid 806253] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:32.858346 2026] [security2:error] [pid 806041:tid 806253] [client 103.215.74.26:18168] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOrELAyZ1MRInzPMYBDQAAANc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:32.898949 2026] [security2:error] [pid 806041:tid 806203] [client 139.28.219.70:53262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuOrELAyZ1MRInzPMYBDgAAAKU"]
[Thu Jul 30 12:49:33.041885 2026] [security2:error] [pid 806041:tid 806204] [client 172.213.232.128:56220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/as.php"] [unique_id "amuOrULAyZ1MRInzPMYBEQAAAKY"]
[Thu Jul 30 12:49:33.057506 2026] [security2:error] [pid 806041:tid 806270] [client 20.91.199.21:34304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuOrULAyZ1MRInzPMYBEgAAAOg"]
[Thu Jul 30 12:49:33.093139 2026] [security2:error] [pid 806041:tid 806258] [client 20.113.56.22:15597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/admin.php"] [unique_id "amuOrULAyZ1MRInzPMYBFgAAANw"]
[Thu Jul 30 12:49:33.093228 2026] [security2:error] [pid 806041:tid 806258] [client 20.113.56.22:15597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/admin.php"] [unique_id "amuOrULAyZ1MRInzPMYBFgAAANw"]
[Thu Jul 30 12:49:33.226790 2026] [security2:error] [pid 806041:tid 806298] [client 139.28.219.70:53278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuOrULAyZ1MRInzPMYBHwAAAQQ"]
[Thu Jul 30 12:49:33.353725 2026] [security2:error] [pid 806041:tid 806240] [client 20.113.56.22:15513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/edit.php"] [unique_id "amuOrULAyZ1MRInzPMYBIwAAAMo"]
[Thu Jul 30 12:49:33.353822 2026] [security2:error] [pid 806041:tid 806240] [client 20.113.56.22:15513] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/edit.php"] [unique_id "amuOrULAyZ1MRInzPMYBIwAAAMo"]
[Thu Jul 30 12:49:33.498510 2026] [security2:error] [pid 806041:tid 806191] [client 139.28.219.70:53284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuOrULAyZ1MRInzPMYBJAAAAJk"]
[Thu Jul 30 12:49:33.631833 2026] [core:notice] [pid 806041:tid 806218] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:33.638895 2026] [security2:error] [pid 806041:tid 806218] [client 103.215.74.26:63852] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOrULAyZ1MRInzPMYBKAAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:33.643601 2026] [security2:error] [pid 806041:tid 806225] [client 20.113.56.22:12243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/admin.php"] [unique_id "amuOrULAyZ1MRInzPMYBKQAAALs"]
[Thu Jul 30 12:49:33.643678 2026] [security2:error] [pid 806041:tid 806225] [client 20.113.56.22:12243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/admin.php"] [unique_id "amuOrULAyZ1MRInzPMYBKQAAALs"]
[Thu Jul 30 12:49:33.715700 2026] [security2:error] [pid 806041:tid 806247] [client 20.91.199.21:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuOrULAyZ1MRInzPMYBMAAAANE"]
[Thu Jul 30 12:49:33.824577 2026] [security2:error] [pid 806041:tid 806287] [client 150.107.232.194:27283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOrULAyZ1MRInzPMYBMwAAAPk"]
[Thu Jul 30 12:49:33.824681 2026] [security2:error] [pid 806041:tid 806287] [client 150.107.232.194:27283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOrULAyZ1MRInzPMYBMwAAAPk"]
[Thu Jul 30 12:49:33.825577 2026] [security2:error] [pid 806041:tid 806194] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOrULAyZ1MRInzPMYBHgAAAJw"]
[Thu Jul 30 12:49:33.837063 2026] [security2:error] [pid 806041:tid 806222] [client 139.28.219.70:53296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mahsudtransportandbuildingdemolition.business"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuOrULAyZ1MRInzPMYBNgAAALg"]
[Thu Jul 30 12:49:33.909266 2026] [security2:error] [pid 806041:tid 806265] [client 20.113.56.22:15607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/inputs.php"] [unique_id "amuOrULAyZ1MRInzPMYBOQAAAOM"]
[Thu Jul 30 12:49:33.909424 2026] [security2:error] [pid 806041:tid 806265] [client 20.113.56.22:15607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/inputs.php"] [unique_id "amuOrULAyZ1MRInzPMYBOQAAAOM"]
[Thu Jul 30 12:49:33.936080 2026] [security2:error] [pid 806041:tid 806256] [client 20.151.221.234:3070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuOrULAyZ1MRInzPMYBOgAAANo"]
[Thu Jul 30 12:49:33.956731 2026] [security2:error] [pid 806041:tid 806227] [client 172.213.232.128:60716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/atomlib.php"] [unique_id "amuOrULAyZ1MRInzPMYBOwAAAL0"]
[Thu Jul 30 12:49:34.118007 2026] [core:notice] [pid 806041:tid 806294] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:34.122399 2026] [security2:error] [pid 806041:tid 806294] [client 66.249.79.8:57512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/citationstylelanguage/download/bibtex"] [unique_id "amuOrULAyZ1MRInzPMYBOAAAAQA"]
[Thu Jul 30 12:49:34.169775 2026] [security2:error] [pid 806041:tid 806261] [client 20.113.56.22:15511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/av.php"] [unique_id "amuOrkLAyZ1MRInzPMYBPwAAAN8"]
[Thu Jul 30 12:49:34.169882 2026] [security2:error] [pid 806041:tid 806261] [client 20.113.56.22:15511] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/av.php"] [unique_id "amuOrkLAyZ1MRInzPMYBPwAAAN8"]
[Thu Jul 30 12:49:34.214566 2026] [security2:error] [pid 806041:tid 806296] [client 4.185.41.66:15714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/aa.php"] [unique_id "amuOrkLAyZ1MRInzPMYBRAAAAQI"]
[Thu Jul 30 12:49:34.214660 2026] [security2:error] [pid 806041:tid 806296] [client 4.185.41.66:15714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/aa.php"] [unique_id "amuOrkLAyZ1MRInzPMYBRAAAAQI"]
[Thu Jul 30 12:49:34.369487 2026] [core:notice] [pid 806041:tid 806201] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:34.376244 2026] [security2:error] [pid 806041:tid 806201] [client 103.215.74.26:63866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOrkLAyZ1MRInzPMYBTAAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:34.429515 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:15605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/classwithtostring.php"] [unique_id "amuOrkLAyZ1MRInzPMYBTQAAANI"]
[Thu Jul 30 12:49:34.429618 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:15605] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/classwithtostring.php"] [unique_id "amuOrkLAyZ1MRInzPMYBTQAAANI"]
[Thu Jul 30 12:49:34.719571 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:15505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuOrkLAyZ1MRInzPMYBUgAAAKw"]
[Thu Jul 30 12:49:34.719678 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:15505] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuOrkLAyZ1MRInzPMYBUgAAAKw"]
[Thu Jul 30 12:49:34.749973 2026] [security2:error] [pid 806041:tid 806142] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOrkLAyZ1MRInzPMYBVAAAumQ"]
[Thu Jul 30 12:49:34.750148 2026] [security2:error] [pid 806041:tid 806224] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOrkLAyZ1MRInzPMYBVAAAumQ"]
[Thu Jul 30 12:49:34.888278 2026] [security2:error] [pid 806041:tid 806204] [client 172.213.232.128:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/autoload_classmap.php"] [unique_id "amuOrkLAyZ1MRInzPMYBXgAAAKY"]
[Thu Jul 30 12:49:34.991785 2026] [security2:error] [pid 806041:tid 806231] [client 20.113.56.22:12225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-blog.php"] [unique_id "amuOrkLAyZ1MRInzPMYBXwAAAME"]
[Thu Jul 30 12:49:34.991911 2026] [security2:error] [pid 806041:tid 806231] [client 20.113.56.22:12225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-blog.php"] [unique_id "amuOrkLAyZ1MRInzPMYBXwAAAME"]
[Thu Jul 30 12:49:35.066396 2026] [security2:error] [pid 806041:tid 806297] [client 4.185.41.66:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/av.php"] [unique_id "amuOr0LAyZ1MRInzPMYBYAAAAQM"]
[Thu Jul 30 12:49:35.066510 2026] [security2:error] [pid 806041:tid 806297] [client 4.185.41.66:6082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/av.php"] [unique_id "amuOr0LAyZ1MRInzPMYBYAAAAQM"]
[Thu Jul 30 12:49:35.127085 2026] [core:notice] [pid 806041:tid 806263] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:35.133411 2026] [security2:error] [pid 806041:tid 806263] [client 103.215.74.26:63888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOr0LAyZ1MRInzPMYBYQAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:35.259635 2026] [security2:error] [pid 806041:tid 806247] [client 20.113.56.22:15613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOr0LAyZ1MRInzPMYBaQAAANE"]
[Thu Jul 30 12:49:35.390677 2026] [security2:error] [pid 806041:tid 806269] [client 20.113.56.22:15613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOr0LAyZ1MRInzPMYBbwAAAOc"]
[Thu Jul 30 12:49:35.520446 2026] [security2:error] [pid 806041:tid 806214] [client 20.113.56.22:15613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/admin.php"] [unique_id "amuOr0LAyZ1MRInzPMYBcAAAALA"]
[Thu Jul 30 12:49:35.520580 2026] [security2:error] [pid 806041:tid 806214] [client 20.113.56.22:15613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-content/admin.php"] [unique_id "amuOr0LAyZ1MRInzPMYBcAAAALA"]
[Thu Jul 30 12:49:35.788435 2026] [security2:error] [pid 806041:tid 806271] [client 20.113.56.22:15540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/adminfuns.php"] [unique_id "amuOr0LAyZ1MRInzPMYBdgAAAOk"]
[Thu Jul 30 12:49:35.788556 2026] [security2:error] [pid 806041:tid 806271] [client 20.113.56.22:15540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/adminfuns.php"] [unique_id "amuOr0LAyZ1MRInzPMYBdgAAAOk"]
[Thu Jul 30 12:49:35.885752 2026] [core:notice] [pid 806041:tid 806200] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:35.892489 2026] [security2:error] [pid 806041:tid 806200] [client 103.215.74.26:63902] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOr0LAyZ1MRInzPMYBeQAAAKI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:36.064077 2026] [security2:error] [pid 806041:tid 806294] [client 20.113.56.22:15582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/goods.php"] [unique_id "amuOsELAyZ1MRInzPMYBfQAAAQA"]
[Thu Jul 30 12:49:36.064194 2026] [security2:error] [pid 806041:tid 806294] [client 20.113.56.22:15582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/goods.php"] [unique_id "amuOsELAyZ1MRInzPMYBfQAAAQA"]
[Thu Jul 30 12:49:36.131759 2026] [security2:error] [pid 806041:tid 806212] [client 20.151.221.234:3064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/403.php"] [unique_id "amuOsELAyZ1MRInzPMYBfgAAAK4"]
[Thu Jul 30 12:49:36.355157 2026] [security2:error] [pid 806041:tid 806228] [client 20.113.56.22:15590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ms-edit.php"] [unique_id "amuOsELAyZ1MRInzPMYBhwAAAL4"]
[Thu Jul 30 12:49:36.355256 2026] [security2:error] [pid 806041:tid 806228] [client 20.113.56.22:15590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ms-edit.php"] [unique_id "amuOsELAyZ1MRInzPMYBhwAAAL4"]
[Thu Jul 30 12:49:36.606145 2026] [core:notice] [pid 806041:tid 806207] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:36.612597 2026] [security2:error] [pid 806041:tid 806207] [client 103.215.74.26:63942] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOsELAyZ1MRInzPMYBigAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:36.620118 2026] [security2:error] [pid 806041:tid 806213] [client 20.113.56.22:15525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/222.php"] [unique_id "amuOsELAyZ1MRInzPMYBiwAAAK8"]
[Thu Jul 30 12:49:36.620204 2026] [security2:error] [pid 806041:tid 806213] [client 20.113.56.22:15525] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/222.php"] [unique_id "amuOsELAyZ1MRInzPMYBiwAAAK8"]
[Thu Jul 30 12:49:36.891067 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:36.931267 2026] [security2:error] [pid 806041:tid 806256] [client 172.213.232.128:59334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/bb.php"] [unique_id "amuOsELAyZ1MRInzPMYBlwAAANo"]
[Thu Jul 30 12:49:36.944592 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:12283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/cgi-bin/index.php"] [unique_id "amuOsELAyZ1MRInzPMYBmAAAAKw"]
[Thu Jul 30 12:49:36.944676 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:12283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/cgi-bin/index.php"] [unique_id "amuOsELAyZ1MRInzPMYBmAAAAKw"]
[Thu Jul 30 12:49:37.197665 2026] [security2:error] [pid 806041:tid 806264] [client 20.91.199.21:43286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/wp-conf.php"] [unique_id "amuOsULAyZ1MRInzPMYBmwAAAOI"]
[Thu Jul 30 12:49:37.225794 2026] [security2:error] [pid 806041:tid 806220] [client 20.113.56.22:12264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOsULAyZ1MRInzPMYBnAAAALY"]
[Thu Jul 30 12:49:37.356783 2026] [security2:error] [pid 806041:tid 806244] [client 20.113.56.22:12264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOsULAyZ1MRInzPMYBowAAAM4"]
[Thu Jul 30 12:49:37.366696 2026] [core:notice] [pid 806041:tid 806286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:37.369595 2026] [security2:error] [pid 806041:tid 806253] [client 20.151.221.234:3013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuOsULAyZ1MRInzPMYBmQAAANc"]
[Thu Jul 30 12:49:37.373111 2026] [security2:error] [pid 806041:tid 806286] [client 103.215.74.26:63970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOsULAyZ1MRInzPMYBpAAAAPg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:37.387764 2026] [core:notice] [pid 806041:tid 806298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:37.443348 2026] [security2:error] [pid 806041:tid 806229] [client 127.0.0.1:30028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuOsULAyZ1MRInzPMYBqAAAAL8"]
[Thu Jul 30 12:49:37.443370 2026] [security2:error] [pid 806041:tid 806191] [client 127.0.0.1:30026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wrf.zzt.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuOsULAyZ1MRInzPMYBpwAAAJk"]
[Thu Jul 30 12:49:37.443531 2026] [security2:error] [pid 806041:tid 806277] [client 74.7.244.54:55806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wrf.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuOsULAyZ1MRInzPMYBpgAA70k"]
[Thu Jul 30 12:49:37.473462 2026] [security2:error] [pid 806041:tid 806263] [client 4.185.41.66:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/xa.php"] [unique_id "amuOsULAyZ1MRInzPMYBrAAAAOE"]
[Thu Jul 30 12:49:37.473553 2026] [security2:error] [pid 806041:tid 806263] [client 4.185.41.66:15697] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/xa.php"] [unique_id "amuOsULAyZ1MRInzPMYBrAAAAOE"]
[Thu Jul 30 12:49:37.486071 2026] [security2:error] [pid 806041:tid 806283] [client 20.113.56.22:12264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/BDKR28WP.php"] [unique_id "amuOsULAyZ1MRInzPMYBrQAAAPU"]
[Thu Jul 30 12:49:37.486190 2026] [security2:error] [pid 806041:tid 806283] [client 20.113.56.22:12264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/BDKR28WP.php"] [unique_id "amuOsULAyZ1MRInzPMYBrQAAAPU"]
[Thu Jul 30 12:49:37.763880 2026] [security2:error] [pid 806041:tid 806226] [client 20.113.56.22:15581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOsULAyZ1MRInzPMYBuAAAALw"]
[Thu Jul 30 12:49:37.893880 2026] [security2:error] [pid 806041:tid 806282] [client 20.113.56.22:15581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOsULAyZ1MRInzPMYBwgAAAPQ"]
[Thu Jul 30 12:49:38.030393 2026] [security2:error] [pid 806041:tid 806189] [client 20.113.56.22:15581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOskLAyZ1MRInzPMYBxAAAAJc"]
[Thu Jul 30 12:49:38.104821 2026] [core:notice] [pid 806041:tid 806174] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:38.111180 2026] [security2:error] [pid 806041:tid 806174] [client 103.215.74.26:63986] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOskLAyZ1MRInzPMYByQAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:38.161226 2026] [security2:error] [pid 806041:tid 806195] [client 20.113.56.22:15581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOskLAyZ1MRInzPMYBygAAAJ0"]
[Thu Jul 30 12:49:38.271270 2026] [security2:error] [pid 806041:tid 806274] [client 20.91.199.21:43270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuOskLAyZ1MRInzPMYBzQAAAOw"]
[Thu Jul 30 12:49:38.290453 2026] [security2:error] [pid 806041:tid 806217] [client 20.113.56.22:15581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp.php"] [unique_id "amuOskLAyZ1MRInzPMYBzgAAALM"]
[Thu Jul 30 12:49:38.290540 2026] [security2:error] [pid 806041:tid 806217] [client 20.113.56.22:15581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp.php"] [unique_id "amuOskLAyZ1MRInzPMYBzgAAALM"]
[Thu Jul 30 12:49:38.368289 2026] [security2:error] [pid 806041:tid 806183] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuOsULAyZ1MRInzPMYBuwAAAJE"]
[Thu Jul 30 12:49:38.463206 2026] [security2:error] [pid 806041:tid 806272] [client 20.151.221.234:3033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/as.php"] [unique_id "amuOskLAyZ1MRInzPMYB1gAAAOo"]
[Thu Jul 30 12:49:38.553262 2026] [security2:error] [pid 806041:tid 806293] [client 20.113.56.22:12266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/abcd.php"] [unique_id "amuOskLAyZ1MRInzPMYB2gAAAP8"]
[Thu Jul 30 12:49:38.553376 2026] [security2:error] [pid 806041:tid 806293] [client 20.113.56.22:12266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/abcd.php"] [unique_id "amuOskLAyZ1MRInzPMYB2gAAAP8"]
[Thu Jul 30 12:49:38.828074 2026] [security2:error] [pid 806041:tid 806215] [client 20.113.56.22:12267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/a1.php"] [unique_id "amuOskLAyZ1MRInzPMYB2wAAALE"]
[Thu Jul 30 12:49:38.828199 2026] [security2:error] [pid 806041:tid 806215] [client 20.113.56.22:12267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/a1.php"] [unique_id "amuOskLAyZ1MRInzPMYB2wAAALE"]
[Thu Jul 30 12:49:38.866700 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:38.872421 2026] [security2:error] [pid 806041:tid 806205] [client 103.215.74.26:63996] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOskLAyZ1MRInzPMYB3gAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:39.162753 2026] [security2:error] [pid 806041:tid 806191] [client 20.113.56.22:15595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuOs0LAyZ1MRInzPMYB6AAAAJk"]
[Thu Jul 30 12:49:39.162848 2026] [security2:error] [pid 806041:tid 806191] [client 20.113.56.22:15595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuOs0LAyZ1MRInzPMYB6AAAAJk"]
[Thu Jul 30 12:49:39.174649 2026] [security2:error] [pid 806041:tid 806277] [client 4.185.41.66:15725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/media.php"] [unique_id "amuOs0LAyZ1MRInzPMYB6QAAAO8"]
[Thu Jul 30 12:49:39.174769 2026] [security2:error] [pid 806041:tid 806277] [client 4.185.41.66:15725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/media.php"] [unique_id "amuOs0LAyZ1MRInzPMYB6QAAAO8"]
[Thu Jul 30 12:49:39.384324 2026] [security2:error] [pid 806041:tid 806244] [client 20.151.221.234:44203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuOs0LAyZ1MRInzPMYB8AAAAM4"]
[Thu Jul 30 12:49:39.425175 2026] [security2:error] [pid 806041:tid 806192] [client 20.113.56.22:15506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuOs0LAyZ1MRInzPMYB8QAAAJo"]
[Thu Jul 30 12:49:39.425271 2026] [security2:error] [pid 806041:tid 806192] [client 20.113.56.22:15506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuOs0LAyZ1MRInzPMYB8QAAAJo"]
[Thu Jul 30 12:49:39.694229 2026] [security2:error] [pid 806041:tid 806235] [client 20.113.56.22:12162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOs0LAyZ1MRInzPMYB-gAAAMU"]
[Thu Jul 30 12:49:39.824819 2026] [security2:error] [pid 806041:tid 806279] [client 20.113.56.22:12162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOs0LAyZ1MRInzPMYB_gAAAPE"]
[Thu Jul 30 12:49:39.839099 2026] [security2:error] [pid 806041:tid 806283] [client 20.91.199.21:43357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/bala.php"] [unique_id "amuOs0LAyZ1MRInzPMYB_wAAAPU"]
[Thu Jul 30 12:49:39.863580 2026] [security2:error] [pid 806041:tid 806199] [client 20.91.199.21:35270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuOs0LAyZ1MRInzPMYCAAAAAKE"]
[Thu Jul 30 12:49:39.898186 2026] [security2:error] [pid 806041:tid 806239] [client 20.151.221.234:55766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wk/index.php"] [unique_id "amuOs0LAyZ1MRInzPMYCAQAAAMk"]
[Thu Jul 30 12:49:39.954529 2026] [security2:error] [pid 806041:tid 806294] [client 20.113.56.22:12162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/simple.php"] [unique_id "amuOs0LAyZ1MRInzPMYCBQAAAQA"]
[Thu Jul 30 12:49:39.954622 2026] [security2:error] [pid 806041:tid 806294] [client 20.113.56.22:12162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/simple.php"] [unique_id "amuOs0LAyZ1MRInzPMYCBQAAAQA"]
[Thu Jul 30 12:49:40.230262 2026] [security2:error] [pid 806041:tid 806175] [client 20.113.56.22:15606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xxx.php"] [unique_id "amuOtELAyZ1MRInzPMYCDQAAAIk"]
[Thu Jul 30 12:49:40.230372 2026] [security2:error] [pid 806041:tid 806175] [client 20.113.56.22:15606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xxx.php"] [unique_id "amuOtELAyZ1MRInzPMYCDQAAAIk"]
[Thu Jul 30 12:49:40.259631 2026] [security2:error] [pid 806041:tid 806227] [client 172.213.232.128:56845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/bnm.php"] [unique_id "amuOtELAyZ1MRInzPMYCDgAAAL0"]
[Thu Jul 30 12:49:40.414904 2026] [security2:error] [pid 806041:tid 806282] [client 20.151.221.234:52961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuOtELAyZ1MRInzPMYCDwAAAPQ"]
[Thu Jul 30 12:49:40.523723 2026] [security2:error] [pid 806041:tid 806266] [client 20.113.56.22:15598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/hypo.php"] [unique_id "amuOtELAyZ1MRInzPMYCFgAAAOQ"]
[Thu Jul 30 12:49:40.523826 2026] [security2:error] [pid 806041:tid 806266] [client 20.113.56.22:15598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/hypo.php"] [unique_id "amuOtELAyZ1MRInzPMYCFgAAAOQ"]
[Thu Jul 30 12:49:40.756759 2026] [security2:error] [pid 806041:tid 806213] [client 20.151.221.234:60477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/av.php"] [unique_id "amuOtELAyZ1MRInzPMYCGgAAAK8"]
[Thu Jul 30 12:49:40.793987 2026] [security2:error] [pid 806041:tid 806273] [client 20.113.56.22:15565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOtELAyZ1MRInzPMYCGwAAAOs"]
[Thu Jul 30 12:49:40.925824 2026] [security2:error] [pid 806041:tid 806215] [client 20.113.56.22:15565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOtELAyZ1MRInzPMYCHAAAALE"]
[Thu Jul 30 12:49:40.938814 2026] [core:notice] [pid 806041:tid 806058] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:40.943905 2026] [security2:error] [pid 806041:tid 806197] [client 74.7.175.167:46584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuOtELAyZ1MRInzPMYCHQAAnxA"]
[Thu Jul 30 12:49:40.988776 2026] [security2:error] [pid 806041:tid 806258] [client 172.213.232.128:60719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/bootstrap.php"] [unique_id "amuOtELAyZ1MRInzPMYCIAAAANw"]
[Thu Jul 30 12:49:41.031183 2026] [core:notice] [pid 806041:tid 806069] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:41.039319 2026] [security2:error] [pid 806041:tid 806173] [client 74.7.230.46:44556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.iig.gpl.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuOtULAyZ1MRInzPMYCIwAAAIc"]
[Thu Jul 30 12:49:41.055605 2026] [security2:error] [pid 806041:tid 806186] [client 20.113.56.22:15565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/chosen.php"] [unique_id "amuOtULAyZ1MRInzPMYCJAAAAJQ"]
[Thu Jul 30 12:49:41.055690 2026] [security2:error] [pid 806041:tid 806186] [client 20.113.56.22:15565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/chosen.php"] [unique_id "amuOtULAyZ1MRInzPMYCJAAAAJQ"]
[Thu Jul 30 12:49:41.116501 2026] [security2:error] [pid 806041:tid 806248] [client 20.91.199.21:43365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/bk.php"] [unique_id "amuOtULAyZ1MRInzPMYCKwAAANI"]
[Thu Jul 30 12:49:41.128757 2026] [core:notice] [pid 806041:tid 806208] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:41.327394 2026] [security2:error] [pid 806041:tid 806263] [client 4.185.41.66:15712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/images.php"] [unique_id "amuOtULAyZ1MRInzPMYCLQAAAOE"]
[Thu Jul 30 12:49:41.327523 2026] [security2:error] [pid 806041:tid 806263] [client 4.185.41.66:15712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/images.php"] [unique_id "amuOtULAyZ1MRInzPMYCLQAAAOE"]
[Thu Jul 30 12:49:41.355607 2026] [security2:error] [pid 806041:tid 806268] [client 20.113.56.22:15489] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOtULAyZ1MRInzPMYCLwAAAOY"]
[Thu Jul 30 12:49:41.502010 2026] [security2:error] [pid 806041:tid 806196] [client 20.113.56.22:15489] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOtULAyZ1MRInzPMYCMAAAAJ4"]
[Thu Jul 30 12:49:41.526358 2026] [security2:error] [pid 806041:tid 806252] [client 20.91.199.21:39850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuOtULAyZ1MRInzPMYCMgAAANY"]
[Thu Jul 30 12:49:41.578393 2026] [core:notice] [pid 806041:tid 806081] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:41.583740 2026] [security2:error] [pid 806041:tid 806204] [client 74.7.175.167:46600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuOtULAyZ1MRInzPMYCNgAApic"], referer: https://www.carnetdeshopping.com/robots.txt
[Thu Jul 30 12:49:41.646333 2026] [security2:error] [pid 806041:tid 806245] [client 20.113.56.22:15489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/als.php"] [unique_id "amuOtULAyZ1MRInzPMYCPAAAAM8"]
[Thu Jul 30 12:49:41.646449 2026] [security2:error] [pid 806041:tid 806245] [client 20.113.56.22:15489] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/als.php"] [unique_id "amuOtULAyZ1MRInzPMYCPAAAAM8"]
[Thu Jul 30 12:49:41.891257 2026] [security2:error] [pid 806041:tid 806251] [client 116.179.32.209:41312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/issue/view/584"] [unique_id "amuOtULAyZ1MRInzPMYCOQAAANU"]
[Thu Jul 30 12:49:41.932670 2026] [core:notice] [pid 806041:tid 806083] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:41.937928 2026] [security2:error] [pid 806041:tid 806279] [client 74.7.244.47:56818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuOtULAyZ1MRInzPMYCSgAA8Sk"]
[Thu Jul 30 12:49:41.939136 2026] [security2:error] [pid 806041:tid 806223] [client 20.113.56.22:15600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/pol.php"] [unique_id "amuOtULAyZ1MRInzPMYCSwAAALk"]
[Thu Jul 30 12:49:41.939288 2026] [security2:error] [pid 806041:tid 806223] [client 20.113.56.22:15600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/pol.php"] [unique_id "amuOtULAyZ1MRInzPMYCSwAAALk"]
[Thu Jul 30 12:49:42.207423 2026] [security2:error] [pid 806041:tid 806291] [client 20.91.199.21:35299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuOtkLAyZ1MRInzPMYCVgAAAP0"]
[Thu Jul 30 12:49:42.227084 2026] [security2:error] [pid 806041:tid 806207] [client 20.113.56.22:15555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file5.php"] [unique_id "amuOtkLAyZ1MRInzPMYCVwAAAKk"]
[Thu Jul 30 12:49:42.227173 2026] [security2:error] [pid 806041:tid 806207] [client 20.113.56.22:15555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file5.php"] [unique_id "amuOtkLAyZ1MRInzPMYCVwAAAKk"]
[Thu Jul 30 12:49:42.279666 2026] [security2:error] [pid 806041:tid 806077] [remote 74.7.241.59:40058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuOtkLAyZ1MRInzPMYCTAAA3iM"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/classes
[Thu Jul 30 12:49:42.413508 2026] [security2:error] [pid 806041:tid 806085] [remote 74.7.241.60:34472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amuOtkLAyZ1MRInzPMYCXAAAzCs"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 12:49:42.451638 2026] [security2:error] [pid 806041:tid 806188] [client 74.7.175.167:46614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuOtkLAyZ1MRInzPMYCWAAAlh8"], referer: https://carnetdeshopping.com/robots.txt
[Thu Jul 30 12:49:42.510357 2026] [security2:error] [pid 806041:tid 806197] [client 20.113.56.22:12265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file.php"] [unique_id "amuOtkLAyZ1MRInzPMYCXwAAAJ8"]
[Thu Jul 30 12:49:42.510459 2026] [security2:error] [pid 806041:tid 806197] [client 20.113.56.22:12265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file.php"] [unique_id "amuOtkLAyZ1MRInzPMYCXwAAAJ8"]
[Thu Jul 30 12:49:42.543255 2026] [security2:error] [pid 806041:tid 806290] [client 20.151.221.234:55792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/mini.php"] [unique_id "amuOtkLAyZ1MRInzPMYCYAAAAPw"]
[Thu Jul 30 12:49:42.566618 2026] [security2:error] [pid 806041:tid 806227] [client 20.151.221.234:35649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/plugins.php"] [unique_id "amuOtkLAyZ1MRInzPMYCYQAAAL0"]
[Thu Jul 30 12:49:42.588175 2026] [security2:error] [pid 806041:tid 806205] [client 4.185.41.66:15644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/gecko.php"] [unique_id "amuOtkLAyZ1MRInzPMYCYgAAAKc"]
[Thu Jul 30 12:49:42.588271 2026] [security2:error] [pid 806041:tid 806205] [client 4.185.41.66:15644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/gecko.php"] [unique_id "amuOtkLAyZ1MRInzPMYCYgAAAKc"]
[Thu Jul 30 12:49:42.678496 2026] [security2:error] [pid 806041:tid 806278] [client 20.91.199.21:33473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.inmobiliariadia.com"] [uri "/ahax.php"] [unique_id "amuOtkLAyZ1MRInzPMYCZwAAAPA"]
[Thu Jul 30 12:49:42.696786 2026] [core:notice] [pid 806041:tid 806232] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:42.777336 2026] [security2:error] [pid 806041:tid 806216] [client 20.113.56.22:12184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/admin.php"] [unique_id "amuOtkLAyZ1MRInzPMYCbwAAALI"]
[Thu Jul 30 12:49:42.777439 2026] [security2:error] [pid 806041:tid 806216] [client 20.113.56.22:12184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/admin.php"] [unique_id "amuOtkLAyZ1MRInzPMYCbwAAALI"]
[Thu Jul 30 12:49:42.809573 2026] [security2:error] [pid 806041:tid 806289] [client 74.7.244.47:56820] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuOtkLAyZ1MRInzPMYCYwAA-y8"], referer: https://carnetdeshopping.com/robots.txt
[Thu Jul 30 12:49:42.832749 2026] [security2:error] [pid 806041:tid 806280] [client 20.151.221.234:40426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuOtkLAyZ1MRInzPMYCcAAAAPI"]
[Thu Jul 30 12:49:43.016417 2026] [security2:error] [pid 806041:tid 806268] [client 20.91.199.21:34338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuOt0LAyZ1MRInzPMYCcQAAAOY"]
[Thu Jul 30 12:49:43.044297 2026] [security2:error] [pid 806041:tid 806275] [client 20.113.56.22:12269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/aa2.php"] [unique_id "amuOt0LAyZ1MRInzPMYCcgAAAO0"]
[Thu Jul 30 12:49:43.044415 2026] [security2:error] [pid 806041:tid 806275] [client 20.113.56.22:12269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/aa2.php"] [unique_id "amuOt0LAyZ1MRInzPMYCcgAAAO0"]
[Thu Jul 30 12:49:43.305890 2026] [security2:error] [pid 806041:tid 806225] [client 20.113.56.22:15567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ccou.php"] [unique_id "amuOt0LAyZ1MRInzPMYCfgAAALs"]
[Thu Jul 30 12:49:43.306008 2026] [security2:error] [pid 806041:tid 806225] [client 20.113.56.22:15567] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ccou.php"] [unique_id "amuOt0LAyZ1MRInzPMYCfgAAALs"]
[Thu Jul 30 12:49:43.330033 2026] [security2:error] [pid 806041:tid 806249] [client 172.213.232.128:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/buy.php"] [unique_id "amuOt0LAyZ1MRInzPMYCfwAAANM"]
[Thu Jul 30 12:49:43.509146 2026] [core:notice] [pid 806041:tid 806288] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:43.572637 2026] [security2:error] [pid 806041:tid 806296] [client 20.113.56.22:15529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dr.php"] [unique_id "amuOt0LAyZ1MRInzPMYCggAAAQI"]
[Thu Jul 30 12:49:43.572744 2026] [security2:error] [pid 806041:tid 806296] [client 20.113.56.22:15529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dr.php"] [unique_id "amuOt0LAyZ1MRInzPMYCggAAAQI"]
[Thu Jul 30 12:49:43.631832 2026] [security2:error] [pid 806041:tid 806223] [client 4.185.41.66:15693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/82.php"] [unique_id "amuOt0LAyZ1MRInzPMYCgwAAALk"]
[Thu Jul 30 12:49:43.631933 2026] [security2:error] [pid 806041:tid 806223] [client 4.185.41.66:15693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/82.php"] [unique_id "amuOt0LAyZ1MRInzPMYCgwAAALk"]
[Thu Jul 30 12:49:43.751867 2026] [security2:error] [pid 806041:tid 806187] [client 20.91.199.21:34350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuOt0LAyZ1MRInzPMYCigAAAJU"]
[Thu Jul 30 12:49:43.816190 2026] [core:notice] [pid 806041:tid 806088] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:43.840877 2026] [security2:error] [pid 806041:tid 806291] [client 20.113.56.22:12233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xamp.php"] [unique_id "amuOt0LAyZ1MRInzPMYCjwAAAP0"]
[Thu Jul 30 12:49:43.841012 2026] [security2:error] [pid 806041:tid 806291] [client 20.113.56.22:12233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xamp.php"] [unique_id "amuOt0LAyZ1MRInzPMYCjwAAAP0"]
[Thu Jul 30 12:49:44.108332 2026] [security2:error] [pid 806041:tid 806211] [client 20.113.56.22:15577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/bless.php"] [unique_id "amuOuELAyZ1MRInzPMYCkQAAAK0"]
[Thu Jul 30 12:49:44.108442 2026] [security2:error] [pid 806041:tid 806211] [client 20.113.56.22:15577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/bless.php"] [unique_id "amuOuELAyZ1MRInzPMYCkQAAAK0"]
[Thu Jul 30 12:49:44.144596 2026] [security2:error] [pid 806041:tid 806228] [client 20.151.221.234:60339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/aa.php"] [unique_id "amuOuELAyZ1MRInzPMYCkgAAAL4"]
[Thu Jul 30 12:49:44.335958 2026] [fcgid:warn] [pid 806041:tid 806214] (70014)End of file found: [client 152.32.138.230:56606] mod_fcgid: can't get data from http client
[Thu Jul 30 12:49:44.375282 2026] [security2:error] [pid 806041:tid 806227] [client 20.113.56.22:15544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file25.php"] [unique_id "amuOuELAyZ1MRInzPMYCngAAAL0"]
[Thu Jul 30 12:49:44.375401 2026] [security2:error] [pid 806041:tid 806227] [client 20.113.56.22:15544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file25.php"] [unique_id "amuOuELAyZ1MRInzPMYCngAAAL0"]
[Thu Jul 30 12:49:44.376657 2026] [security2:error] [pid 806041:tid 806210] [client 150.107.232.194:26836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOuELAyZ1MRInzPMYCnwAAAKw"]
[Thu Jul 30 12:49:44.376770 2026] [security2:error] [pid 806041:tid 806210] [client 150.107.232.194:26836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOuELAyZ1MRInzPMYCnwAAAKw"]
[Thu Jul 30 12:49:44.443729 2026] [security2:error] [pid 806041:tid 806262] [client 4.185.41.66:15635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/xstelth.php"] [unique_id "amuOuELAyZ1MRInzPMYCoAAAAOA"]
[Thu Jul 30 12:49:44.443841 2026] [security2:error] [pid 806041:tid 806262] [client 4.185.41.66:15635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/xstelth.php"] [unique_id "amuOuELAyZ1MRInzPMYCoAAAAOA"]
[Thu Jul 30 12:49:44.618827 2026] [security2:error] [pid 806041:tid 806282] [client 172.213.232.128:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/chosen.php"] [unique_id "amuOuELAyZ1MRInzPMYCoQAAAPQ"]
[Thu Jul 30 12:49:44.636328 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:44.642625 2026] [security2:error] [pid 806041:tid 806205] [client 103.215.74.26:20168] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOuELAyZ1MRInzPMYCogAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:44.672134 2026] [security2:error] [pid 806041:tid 806232] [client 20.113.56.22:15566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file6.php"] [unique_id "amuOuELAyZ1MRInzPMYCpAAAAMI"]
[Thu Jul 30 12:49:44.672262 2026] [security2:error] [pid 806041:tid 806232] [client 20.113.56.22:15566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file6.php"] [unique_id "amuOuELAyZ1MRInzPMYCpAAAAMI"]
[Thu Jul 30 12:49:44.823846 2026] [security2:error] [pid 806041:tid 806190] [client 20.151.221.234:22943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin.php"] [unique_id "amuOuELAyZ1MRInzPMYCqwAAAJg"]
[Thu Jul 30 12:49:44.829254 2026] [security2:error] [pid 806041:tid 806294] [client 20.151.221.234:44198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuOuELAyZ1MRInzPMYCrAAAAQA"]
[Thu Jul 30 12:49:44.866281 2026] [security2:error] [pid 806041:tid 806278] [client 20.91.199.21:35294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuOuELAyZ1MRInzPMYCrgAAAPA"]
[Thu Jul 30 12:49:44.867341 2026] [security2:error] [pid 806041:tid 806246] [client 20.151.221.234:12051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/w.php"] [unique_id "amuOuELAyZ1MRInzPMYCsAAAANA"]
[Thu Jul 30 12:49:44.967961 2026] [security2:error] [pid 806041:tid 806280] [client 20.113.56.22:15521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/a2.php"] [unique_id "amuOuELAyZ1MRInzPMYCsgAAAPI"]
[Thu Jul 30 12:49:44.968096 2026] [security2:error] [pid 806041:tid 806280] [client 20.113.56.22:15521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/a2.php"] [unique_id "amuOuELAyZ1MRInzPMYCsgAAAPI"]
[Thu Jul 30 12:49:45.094292 2026] [security2:error] [pid 806041:tid 806247] [client 4.185.41.66:15743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/xp.php"] [unique_id "amuOuULAyZ1MRInzPMYCswAAANE"]
[Thu Jul 30 12:49:45.094406 2026] [security2:error] [pid 806041:tid 806247] [client 4.185.41.66:15743] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/xp.php"] [unique_id "amuOuULAyZ1MRInzPMYCswAAANE"]
[Thu Jul 30 12:49:45.235790 2026] [security2:error] [pid 806041:tid 806222] [client 20.113.56.22:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file15.php"] [unique_id "amuOuULAyZ1MRInzPMYCtQAAALg"]
[Thu Jul 30 12:49:45.235907 2026] [security2:error] [pid 806041:tid 806222] [client 20.113.56.22:12245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file15.php"] [unique_id "amuOuULAyZ1MRInzPMYCtQAAALg"]
[Thu Jul 30 12:49:45.370377 2026] [core:notice] [pid 806041:tid 806245] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:45.377237 2026] [security2:error] [pid 806041:tid 806245] [client 103.215.74.26:20178] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOuULAyZ1MRInzPMYCvwAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:45.521880 2026] [security2:error] [pid 806041:tid 806103] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOuULAyZ1MRInzPMYCwwAA2z0"]
[Thu Jul 30 12:49:45.522065 2026] [security2:error] [pid 806041:tid 806257] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOuULAyZ1MRInzPMYCwwAA2z0"]
[Thu Jul 30 12:49:45.530378 2026] [security2:error] [pid 806041:tid 806261] [client 20.113.56.22:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/f35.php"] [unique_id "amuOuULAyZ1MRInzPMYCxAAAAN8"]
[Thu Jul 30 12:49:45.530472 2026] [security2:error] [pid 806041:tid 806261] [client 20.113.56.22:15584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/f35.php"] [unique_id "amuOuULAyZ1MRInzPMYCxAAAAN8"]
[Thu Jul 30 12:49:45.551224 2026] [security2:error] [pid 806041:tid 806175] [client 213.152.161.170:48436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuOuULAyZ1MRInzPMYCxgAAAIk"]
[Thu Jul 30 12:49:45.551311 2026] [security2:error] [pid 806041:tid 806175] [client 213.152.161.170:48436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuOuULAyZ1MRInzPMYCxgAAAIk"]
[Thu Jul 30 12:49:45.690238 2026] [security2:error] [pid 806041:tid 806223] [client 20.151.221.234:52398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/go.php"] [unique_id "amuOuULAyZ1MRInzPMYCxwAAALk"]
[Thu Jul 30 12:49:45.803440 2026] [security2:error] [pid 806041:tid 806182] [client 86.106.84.166:43106] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuOuULAyZ1MRInzPMYCxQAAAJA"]
[Thu Jul 30 12:49:45.803578 2026] [security2:error] [pid 806041:tid 806182] [client 86.106.84.166:43106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuOuULAyZ1MRInzPMYCxQAAAJA"]
[Thu Jul 30 12:49:45.807203 2026] [security2:error] [pid 806041:tid 806267] [client 20.113.56.22:15490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-load.php"] [unique_id "amuOuULAyZ1MRInzPMYCywAAAOU"]
[Thu Jul 30 12:49:45.807351 2026] [security2:error] [pid 806041:tid 806267] [client 20.113.56.22:15490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-load.php"] [unique_id "amuOuULAyZ1MRInzPMYCywAAAOU"]
[Thu Jul 30 12:49:45.821349 2026] [security2:error] [pid 806041:tid 806187] [client 20.91.199.21:40302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuOuULAyZ1MRInzPMYCzAAAAJU"]
[Thu Jul 30 12:49:46.097102 2026] [security2:error] [pid 806041:tid 806188] [client 20.113.56.22:12251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xwpg.php"] [unique_id "amuOukLAyZ1MRInzPMYC1AAAAJY"]
[Thu Jul 30 12:49:46.097219 2026] [security2:error] [pid 806041:tid 806188] [client 20.113.56.22:12251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xwpg.php"] [unique_id "amuOukLAyZ1MRInzPMYC1AAAAJY"]
[Thu Jul 30 12:49:46.115270 2026] [core:notice] [pid 806041:tid 806237] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:46.121740 2026] [security2:error] [pid 806041:tid 806237] [client 103.215.74.26:20194] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOukLAyZ1MRInzPMYC1QAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:46.151621 2026] [security2:error] [pid 806041:tid 806235] [client 34.38.245.25:58476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuOukLAyZ1MRInzPMYC1gAAAMU"]
[Thu Jul 30 12:49:46.285731 2026] [security2:error] [pid 806041:tid 806210] [client 4.185.41.66:15685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/admin.php"] [unique_id "amuOukLAyZ1MRInzPMYC1wAAAKw"]
[Thu Jul 30 12:49:46.285831 2026] [security2:error] [pid 806041:tid 806210] [client 4.185.41.66:15685] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/admin.php"] [unique_id "amuOukLAyZ1MRInzPMYC1wAAAKw"]
[Thu Jul 30 12:49:46.328515 2026] [proxy:error] [pid 806041:tid 806208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:46.328575 2026] [proxy_http:error] [pid 806041:tid 806208] [client 152.32.138.230:41200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:46.329255 2026] [proxy:error] [pid 806041:tid 806208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:46.329310 2026] [proxy_http:error] [pid 806041:tid 806208] [client 152.32.138.230:41200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:46.370346 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:12240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOukLAyZ1MRInzPMYC3AAAANI"]
[Thu Jul 30 12:49:46.501317 2026] [security2:error] [pid 806041:tid 806250] [client 20.113.56.22:12240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOukLAyZ1MRInzPMYC4wAAANQ"]
[Thu Jul 30 12:49:46.638922 2026] [security2:error] [pid 806041:tid 806171] [client 20.113.56.22:12240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/index.cgi"] [unique_id "amuOukLAyZ1MRInzPMYC5AAAAIU"]
[Thu Jul 30 12:49:46.717253 2026] [core:notice] [pid 806041:tid 806121] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:46.771883 2026] [security2:error] [pid 806041:tid 806247] [client 20.113.56.22:12240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.html"] [unique_id "amuOukLAyZ1MRInzPMYC6gAAANE"]
[Thu Jul 30 12:49:46.875844 2026] [core:notice] [pid 806041:tid 806289] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:46.882324 2026] [security2:error] [pid 806041:tid 806289] [client 103.215.74.26:20202] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOukLAyZ1MRInzPMYC7wAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:46.904719 2026] [security2:error] [pid 806041:tid 806225] [client 20.113.56.22:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xstelth.php"] [unique_id "amuOukLAyZ1MRInzPMYC9gAAALs"]
[Thu Jul 30 12:49:46.904821 2026] [security2:error] [pid 806041:tid 806225] [client 20.113.56.22:12240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xstelth.php"] [unique_id "amuOukLAyZ1MRInzPMYC9gAAALs"]
[Thu Jul 30 12:49:46.943757 2026] [security2:error] [pid 806041:tid 806294] [client 20.91.199.21:34329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuOukLAyZ1MRInzPMYC5QAAAQA"]
[Thu Jul 30 12:49:47.166359 2026] [security2:error] [pid 806041:tid 806175] [client 20.113.56.22:15547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuOu0LAyZ1MRInzPMYDAAAAAIk"]
[Thu Jul 30 12:49:47.166469 2026] [security2:error] [pid 806041:tid 806175] [client 20.113.56.22:15547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuOu0LAyZ1MRInzPMYDAAAAAIk"]
[Thu Jul 30 12:49:47.427841 2026] [security2:error] [pid 806041:tid 806211] [client 20.113.56.22:12236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/aaa.php"] [unique_id "amuOu0LAyZ1MRInzPMYDCQAAAK0"]
[Thu Jul 30 12:49:47.427933 2026] [security2:error] [pid 806041:tid 806211] [client 20.113.56.22:12236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/aaa.php"] [unique_id "amuOu0LAyZ1MRInzPMYDCQAAAK0"]
[Thu Jul 30 12:49:47.616218 2026] [core:notice] [pid 806041:tid 806293] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:47.622565 2026] [security2:error] [pid 806041:tid 806293] [client 103.215.74.26:20210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOu0LAyZ1MRInzPMYDEAAAAP8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:47.716126 2026] [security2:error] [pid 806041:tid 806258] [client 20.113.56.22:15523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/gecko.php"] [unique_id "amuOu0LAyZ1MRInzPMYDEQAAANw"]
[Thu Jul 30 12:49:47.716242 2026] [security2:error] [pid 806041:tid 806258] [client 20.113.56.22:15523] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/gecko.php"] [unique_id "amuOu0LAyZ1MRInzPMYDEQAAANw"]
[Thu Jul 30 12:49:47.825573 2026] [security2:error] [pid 806041:tid 806246] [client 20.151.221.234:35659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/test1.php"] [unique_id "amuOu0LAyZ1MRInzPMYDEgAAANA"]
[Thu Jul 30 12:49:47.977866 2026] [security2:error] [pid 806041:tid 806253] [client 20.113.56.22:15546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/pbck.php"] [unique_id "amuOu0LAyZ1MRInzPMYDGQAAANc"]
[Thu Jul 30 12:49:47.977961 2026] [security2:error] [pid 806041:tid 806253] [client 20.113.56.22:15546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/pbck.php"] [unique_id "amuOu0LAyZ1MRInzPMYDGQAAANc"]
[Thu Jul 30 12:49:48.241426 2026] [security2:error] [pid 806041:tid 806247] [client 20.113.56.22:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xiugai.php"] [unique_id "amuOvELAyZ1MRInzPMYDHQAAANE"]
[Thu Jul 30 12:49:48.241599 2026] [security2:error] [pid 806041:tid 806247] [client 20.113.56.22:12231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/xiugai.php"] [unique_id "amuOvELAyZ1MRInzPMYDHQAAANE"]
[Thu Jul 30 12:49:48.343478 2026] [core:notice] [pid 806041:tid 806191] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:48.349731 2026] [security2:error] [pid 806041:tid 806191] [client 103.215.74.26:20222] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOvELAyZ1MRInzPMYDHgAAAJk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:48.595736 2026] [security2:error] [pid 806041:tid 806225] [client 20.113.56.22:15501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/e.php"] [unique_id "amuOvELAyZ1MRInzPMYDKAAAALs"]
[Thu Jul 30 12:49:48.595838 2026] [security2:error] [pid 806041:tid 806225] [client 20.113.56.22:15501] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/e.php"] [unique_id "amuOvELAyZ1MRInzPMYDKAAAALs"]
[Thu Jul 30 12:49:48.673007 2026] [security2:error] [pid 806041:tid 806271] [client 4.185.41.66:15641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/adminner.php"] [unique_id "amuOvELAyZ1MRInzPMYDKQAAAOk"]
[Thu Jul 30 12:49:48.673116 2026] [security2:error] [pid 806041:tid 806271] [client 4.185.41.66:15641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/adminner.php"] [unique_id "amuOvELAyZ1MRInzPMYDKQAAAOk"]
[Thu Jul 30 12:49:48.859308 2026] [security2:error] [pid 806041:tid 806239] [client 20.113.56.22:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/adminner.php"] [unique_id "amuOvELAyZ1MRInzPMYDKgAAAMk"]
[Thu Jul 30 12:49:48.859432 2026] [security2:error] [pid 806041:tid 806239] [client 20.113.56.22:12241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/adminner.php"] [unique_id "amuOvELAyZ1MRInzPMYDKgAAAMk"]
[Thu Jul 30 12:49:48.972450 2026] [core:error] [pid 806041:tid 806233] [client 20.151.221.234:52383] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:48.972470 2026] [core:error] [pid 806041:tid 806233] [client 20.151.221.234:52383] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:49.021513 2026] [security2:error] [pid 806041:tid 806215] [client 172.213.232.128:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/class-wp-image.php"] [unique_id "amuOvULAyZ1MRInzPMYDNgAAALE"]
[Thu Jul 30 12:49:49.075748 2026] [core:notice] [pid 806041:tid 806294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:49.082111 2026] [security2:error] [pid 806041:tid 806294] [client 103.215.74.26:20236] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOvULAyZ1MRInzPMYDNwAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:49.149082 2026] [security2:error] [pid 806041:tid 806252] [client 20.113.56.22:15531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file1221.php"] [unique_id "amuOvULAyZ1MRInzPMYDOwAAANY"]
[Thu Jul 30 12:49:49.149164 2026] [security2:error] [pid 806041:tid 806252] [client 20.113.56.22:15531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/file1221.php"] [unique_id "amuOvULAyZ1MRInzPMYDOwAAANY"]
[Thu Jul 30 12:49:49.222956 2026] [security2:error] [pid 806041:tid 806206] [client 4.185.41.66:15625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/a.php"] [unique_id "amuOvULAyZ1MRInzPMYDPAAAAKg"]
[Thu Jul 30 12:49:49.223111 2026] [security2:error] [pid 806041:tid 806206] [client 4.185.41.66:15625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/a.php"] [unique_id "amuOvULAyZ1MRInzPMYDPAAAAKg"]
[Thu Jul 30 12:49:49.417011 2026] [security2:error] [pid 806041:tid 806260] [client 20.113.56.22:12276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/inx.php"] [unique_id "amuOvULAyZ1MRInzPMYDPwAAAN4"]
[Thu Jul 30 12:49:49.417132 2026] [security2:error] [pid 806041:tid 806260] [client 20.113.56.22:12276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/inx.php"] [unique_id "amuOvULAyZ1MRInzPMYDPwAAAN4"]
[Thu Jul 30 12:49:49.496023 2026] [proxy:error] [pid 806041:tid 806265] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:49.496096 2026] [proxy_http:error] [pid 806041:tid 806265] [client 152.32.138.230:41214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:49.496670 2026] [proxy:error] [pid 806041:tid 806265] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:49.496714 2026] [proxy_http:error] [pid 806041:tid 806265] [client 152.32.138.230:41214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:49.588789 2026] [security2:error] [pid 806041:tid 806188] [client 4.185.41.66:15720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/k.php"] [unique_id "amuOvULAyZ1MRInzPMYDRwAAAJY"]
[Thu Jul 30 12:49:49.588869 2026] [security2:error] [pid 806041:tid 806188] [client 4.185.41.66:15720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/k.php"] [unique_id "amuOvULAyZ1MRInzPMYDRwAAAJY"]
[Thu Jul 30 12:49:49.682356 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:15509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/qqqa.php"] [unique_id "amuOvULAyZ1MRInzPMYDSwAAAKw"]
[Thu Jul 30 12:49:49.682455 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:15509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/qqqa.php"] [unique_id "amuOvULAyZ1MRInzPMYDSwAAAKw"]
[Thu Jul 30 12:49:49.810470 2026] [core:notice] [pid 806041:tid 806213] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:49.820645 2026] [security2:error] [pid 806041:tid 806213] [client 103.215.74.26:20242] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOvULAyZ1MRInzPMYDTAAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:49.977004 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:15586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/reviall.php"] [unique_id "amuOvULAyZ1MRInzPMYDTwAAANI"]
[Thu Jul 30 12:49:49.977128 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:15586] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/reviall.php"] [unique_id "amuOvULAyZ1MRInzPMYDTwAAANI"]
[Thu Jul 30 12:49:50.049075 2026] [security2:error] [pid 806041:tid 806176] [client 172.213.232.128:58795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/classsmtps.php"] [unique_id "amuOvkLAyZ1MRInzPMYDVAAAAIo"]
[Thu Jul 30 12:49:50.077461 2026] [security2:error] [pid 806041:tid 806231] [client 4.185.41.66:15631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/222.php"] [unique_id "amuOvkLAyZ1MRInzPMYDVQAAAME"]
[Thu Jul 30 12:49:50.077546 2026] [security2:error] [pid 806041:tid 806231] [client 4.185.41.66:15631] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/222.php"] [unique_id "amuOvkLAyZ1MRInzPMYDVQAAAME"]
[Thu Jul 30 12:49:50.173605 2026] [security2:error] [pid 806041:tid 806208] [client 20.151.221.234:64321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/size.php"] [unique_id "amuOvkLAyZ1MRInzPMYDWQAAAKo"]
[Thu Jul 30 12:49:50.206568 2026] [security2:error] [pid 806041:tid 806228] [client 20.151.221.234:52933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/images/index.php"] [unique_id "amuOvkLAyZ1MRInzPMYDWgAAAL4"]
[Thu Jul 30 12:49:50.237253 2026] [security2:error] [pid 806041:tid 806275] [client 20.113.56.22:12193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.php"] [unique_id "amuOvkLAyZ1MRInzPMYDWwAAAO0"]
[Thu Jul 30 12:49:50.237349 2026] [security2:error] [pid 806041:tid 806275] [client 20.113.56.22:12193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/404.php"] [unique_id "amuOvkLAyZ1MRInzPMYDWwAAAO0"]
[Thu Jul 30 12:49:50.425366 2026] [security2:error] [pid 806041:tid 806256] [client 4.185.41.66:15733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/mac.php"] [unique_id "amuOvkLAyZ1MRInzPMYDXQAAANo"]
[Thu Jul 30 12:49:50.425523 2026] [security2:error] [pid 806041:tid 806256] [client 4.185.41.66:15733] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/mac.php"] [unique_id "amuOvkLAyZ1MRInzPMYDXQAAANo"]
[Thu Jul 30 12:49:50.532886 2026] [security2:error] [pid 806041:tid 806287] [client 20.113.56.22:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/bolt.php"] [unique_id "amuOvkLAyZ1MRInzPMYDYQAAAPk"]
[Thu Jul 30 12:49:50.533015 2026] [security2:error] [pid 806041:tid 806287] [client 20.113.56.22:12181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/bolt.php"] [unique_id "amuOvkLAyZ1MRInzPMYDYQAAAPk"]
[Thu Jul 30 12:49:50.537890 2026] [core:notice] [pid 806041:tid 806247] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:50.544134 2026] [security2:error] [pid 806041:tid 806247] [client 103.215.74.26:20258] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOvkLAyZ1MRInzPMYDYgAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:50.714057 2026] [security2:error] [pid 806041:tid 806154] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/uploads/2025/02/cropped-%E4%B8%83%E6%98%9F-1-32x32.jpg"] [unique_id "amuOvkLAyZ1MRInzPMYDaQAA-nA"]
[Thu Jul 30 12:49:50.716128 2026] [security2:error] [pid 806041:tid 806157] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/uploads/2025/02/cropped-%E4%B8%83%E6%98%9F-1-32x32.jpg"] [unique_id "amuOvkLAyZ1MRInzPMYDagABAnM"]
[Thu Jul 30 12:49:50.842249 2026] [security2:error] [pid 806041:tid 806224] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOvkLAyZ1MRInzPMYDXAAAumk"]
[Thu Jul 30 12:49:50.857869 2026] [security2:error] [pid 806041:tid 806257] [client 20.113.56.22:15504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/File.php"] [unique_id "amuOvkLAyZ1MRInzPMYDawAAANs"]
[Thu Jul 30 12:49:50.858001 2026] [security2:error] [pid 806041:tid 806257] [client 20.113.56.22:15504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/File.php"] [unique_id "amuOvkLAyZ1MRInzPMYDawAAANs"]
[Thu Jul 30 12:49:50.967393 2026] [security2:error] [pid 806041:tid 806149] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/uploads/2025/02/cropped-%E4%B8%83%E6%98%9F-1-192x192.jpg"] [unique_id "amuOvkLAyZ1MRInzPMYDbAABAGs"]
[Thu Jul 30 12:49:50.968806 2026] [security2:error] [pid 806041:tid 806158] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/uploads/2025/02/cropped-%E4%B8%83%E6%98%9F-1-192x192.jpg"] [unique_id "amuOvkLAyZ1MRInzPMYDbQAAj3Q"]
[Thu Jul 30 12:49:51.132041 2026] [security2:error] [pid 806041:tid 806218] [client 20.113.56.22:12191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/fi22.php"] [unique_id "amuOv0LAyZ1MRInzPMYDdAAAALQ"]
[Thu Jul 30 12:49:51.132069 2026] [security2:error] [pid 806041:tid 806226] [client 172.213.232.128:56874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/classwithtostring.php"] [unique_id "amuOv0LAyZ1MRInzPMYDdQAAALw"]
[Thu Jul 30 12:49:51.132155 2026] [security2:error] [pid 806041:tid 806218] [client 20.113.56.22:12191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/fi22.php"] [unique_id "amuOv0LAyZ1MRInzPMYDdAAAALQ"]
[Thu Jul 30 12:49:51.209037 2026] [security2:error] [pid 806041:tid 806161] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/uploads/2025/02/cropped-%E4%B8%83%E6%98%9F-1-180x180.jpg"] [unique_id "amuOv0LAyZ1MRInzPMYDeQAA6nc"]
[Thu Jul 30 12:49:51.209646 2026] [security2:error] [pid 806041:tid 806152] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/uploads/2025/02/cropped-%E4%B8%83%E6%98%9F-1-180x180.jpg"] [unique_id "amuOv0LAyZ1MRInzPMYDegAAkG4"]
[Thu Jul 30 12:49:51.231765 2026] [security2:error] [pid 806041:tid 806173] [client 20.40.58.237:61156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuOv0LAyZ1MRInzPMYDewAAAIc"]
[Thu Jul 30 12:49:51.245418 2026] [autoindex:error] [pid 806041:tid 806180] [client 4.185.41.66:15638] AH01276: Cannot serve directory /home1/mszudite/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:49:51.246040 2026] [security2:error] [pid 806041:tid 806180] [client 4.185.41.66:15638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.j-nintei.com"] [uri "/cgi-sys/403.html"] [unique_id "amuOv0LAyZ1MRInzPMYDfAAAAI4"]
[Thu Jul 30 12:49:51.275826 2026] [core:notice] [pid 806041:tid 806261] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:51.282072 2026] [security2:error] [pid 806041:tid 806261] [client 103.215.74.26:20266] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOv0LAyZ1MRInzPMYDfQAAAN8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:51.334476 2026] [security2:error] [pid 806041:tid 806281] [client 172.202.44.182:23333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/chosen.php"] [unique_id "amuOv0LAyZ1MRInzPMYDfgAAAPM"]
[Thu Jul 30 12:49:51.395956 2026] [security2:error] [pid 806041:tid 806270] [client 20.113.56.22:15550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/zero.php"] [unique_id "amuOv0LAyZ1MRInzPMYDgQAAAOg"]
[Thu Jul 30 12:49:51.396080 2026] [security2:error] [pid 806041:tid 806270] [client 20.113.56.22:15550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/zero.php"] [unique_id "amuOv0LAyZ1MRInzPMYDgQAAAOg"]
[Thu Jul 30 12:49:51.402713 2026] [autoindex:error] [pid 806041:tid 806201] [client 4.185.41.66:15638] AH01276: Cannot serve directory /home1/mszudite/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:49:51.403380 2026] [security2:error] [pid 806041:tid 806201] [client 4.185.41.66:15638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.j-nintei.com"] [uri "/cgi-sys/403.html"] [unique_id "amuOv0LAyZ1MRInzPMYDgAAAAKM"]
[Thu Jul 30 12:49:51.442320 2026] [security2:error] [pid 806041:tid 806162] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/8eb3acded82fb5f8c61e89092a938b1b.css"] [unique_id "amuOv0LAyZ1MRInzPMYDgwAAkXg"]
[Thu Jul 30 12:49:51.442490 2026] [security2:error] [pid 806041:tid 806042] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/8eb3acded82fb5f8c61e89092a938b1b.css"] [unique_id "amuOv0LAyZ1MRInzPMYDhAAAkQA"]
[Thu Jul 30 12:49:51.558262 2026] [security2:error] [pid 806041:tid 806244] [client 4.185.41.66:15638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/ops.php"] [unique_id "amuOv0LAyZ1MRInzPMYDhwAAAM4"]
[Thu Jul 30 12:49:51.558376 2026] [security2:error] [pid 806041:tid 806244] [client 4.185.41.66:15638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/ops.php"] [unique_id "amuOv0LAyZ1MRInzPMYDhwAAAM4"]
[Thu Jul 30 12:49:51.664398 2026] [security2:error] [pid 806041:tid 806232] [client 20.113.56.22:15535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1xmomo.php"] [unique_id "amuOv0LAyZ1MRInzPMYDjAAAAMI"]
[Thu Jul 30 12:49:51.664545 2026] [security2:error] [pid 806041:tid 806232] [client 20.113.56.22:15535] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1xmomo.php"] [unique_id "amuOv0LAyZ1MRInzPMYDjAAAAMI"]
[Thu Jul 30 12:49:51.673074 2026] [security2:error] [pid 806041:tid 806156] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/0dff681e7cdfc4be7551522234c2fe78.css"] [unique_id "amuOv0LAyZ1MRInzPMYDjQAAtnI"]
[Thu Jul 30 12:49:51.673125 2026] [security2:error] [pid 806041:tid 806169] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/0dff681e7cdfc4be7551522234c2fe78.css"] [unique_id "amuOv0LAyZ1MRInzPMYDjgAAtn8"]
[Thu Jul 30 12:49:51.790631 2026] [proxy:error] [pid 806041:tid 806179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:51.790715 2026] [proxy_http:error] [pid 806041:tid 806179] [client 152.32.138.230:41230] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:51.791467 2026] [proxy:error] [pid 806041:tid 806179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:51.791516 2026] [proxy_http:error] [pid 806041:tid 806179] [client 152.32.138.230:41230] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:51.904951 2026] [security2:error] [pid 806041:tid 806282] [client 172.213.232.128:58009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/config.php"] [unique_id "amuOv0LAyZ1MRInzPMYDkAAAAPQ"]
[Thu Jul 30 12:49:51.910758 2026] [security2:error] [pid 806041:tid 806160] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "amuOv0LAyZ1MRInzPMYDkQAAtXY"]
[Thu Jul 30 12:49:51.910870 2026] [security2:error] [pid 806041:tid 806115] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "amuOv0LAyZ1MRInzPMYDkgAAtUk"]
[Thu Jul 30 12:49:51.939133 2026] [security2:error] [pid 806041:tid 806262] [client 20.113.56.22:12234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/fmws.php"] [unique_id "amuOv0LAyZ1MRInzPMYDkwAAAOA"]
[Thu Jul 30 12:49:51.939237 2026] [security2:error] [pid 806041:tid 806262] [client 20.113.56.22:12234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/fmws.php"] [unique_id "amuOv0LAyZ1MRInzPMYDkwAAAOA"]
[Thu Jul 30 12:49:52.012899 2026] [core:notice] [pid 806041:tid 806238] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:52.017225 2026] [security2:error] [pid 806041:tid 806202] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOv0LAyZ1MRInzPMYDggAApG8"]
[Thu Jul 30 12:49:52.019696 2026] [security2:error] [pid 806041:tid 806238] [client 103.215.74.26:20280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOwELAyZ1MRInzPMYDlAAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:52.139848 2026] [security2:error] [pid 806041:tid 806045] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "amuOwELAyZ1MRInzPMYDmAAAhQM"]
[Thu Jul 30 12:49:52.139969 2026] [security2:error] [pid 806041:tid 806043] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "amuOwELAyZ1MRInzPMYDmQAAhQE"]
[Thu Jul 30 12:49:52.145682 2026] [core:notice] [pid 806041:tid 806286] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:52.164581 2026] [security2:error] [pid 806041:tid 806253] [client 74.7.230.55:48596] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "reviewbyjook.com.mqc.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuOwELAyZ1MRInzPMYDmwAAANc"]
[Thu Jul 30 12:49:52.228740 2026] [security2:error] [pid 806041:tid 806192] [client 20.113.56.22:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuOwELAyZ1MRInzPMYDoAAAAJo"]
[Thu Jul 30 12:49:52.228823 2026] [security2:error] [pid 806041:tid 806192] [client 20.113.56.22:12244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuOwELAyZ1MRInzPMYDoAAAAJo"]
[Thu Jul 30 12:49:52.273917 2026] [core:error] [pid 806041:tid 806249] [client 20.151.221.234:52945] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:52.273937 2026] [core:error] [pid 806041:tid 806249] [client 20.151.221.234:52945] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:49:52.361782 2026] [security2:error] [pid 806041:tid 806046] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/7406f7593cc4385f97db1c83bd25ea45.css"] [unique_id "amuOwELAyZ1MRInzPMYDqQAA2AQ"]
[Thu Jul 30 12:49:52.361937 2026] [security2:error] [pid 806041:tid 806163] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/7406f7593cc4385f97db1c83bd25ea45.css"] [unique_id "amuOwELAyZ1MRInzPMYDqAAA2Hk"]
[Thu Jul 30 12:49:52.427392 2026] [security2:error] [pid 806041:tid 806239] [client 4.185.41.66:15645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/8.php"] [unique_id "amuOwELAyZ1MRInzPMYDqgAAAMk"]
[Thu Jul 30 12:49:52.427542 2026] [security2:error] [pid 806041:tid 806239] [client 4.185.41.66:15645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/8.php"] [unique_id "amuOwELAyZ1MRInzPMYDqgAAAMk"]
[Thu Jul 30 12:49:52.522082 2026] [security2:error] [pid 806041:tid 806204] [client 20.113.56.22:12200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/hp2.php"] [unique_id "amuOwELAyZ1MRInzPMYDqwAAAKY"]
[Thu Jul 30 12:49:52.522188 2026] [security2:error] [pid 806041:tid 806204] [client 20.113.56.22:12200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/hp2.php"] [unique_id "amuOwELAyZ1MRInzPMYDqwAAAKY"]
[Thu Jul 30 12:49:52.525641 2026] [security2:error] [pid 806041:tid 806196] [client 172.213.232.128:58008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/core.php"] [unique_id "amuOwELAyZ1MRInzPMYDrAAAAJ4"]
[Thu Jul 30 12:49:52.582534 2026] [security2:error] [pid 806041:tid 806166] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/0d73d368a920aca1e0749d600f85109b.css"] [unique_id "amuOwELAyZ1MRInzPMYDsAAAnHw"]
[Thu Jul 30 12:49:52.582534 2026] [security2:error] [pid 806041:tid 806048] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/0d73d368a920aca1e0749d600f85109b.css"] [unique_id "amuOwELAyZ1MRInzPMYDsQAAnAY"]
[Thu Jul 30 12:49:52.748435 2026] [core:notice] [pid 806041:tid 806240] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:52.754932 2026] [security2:error] [pid 806041:tid 806240] [client 103.215.74.26:20292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOwELAyZ1MRInzPMYDuAAAAMo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:52.756181 2026] [security2:error] [pid 806041:tid 806052] [remote 57.141.0.27:46182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuOwELAyZ1MRInzPMYDuQAAmwo"]
[Thu Jul 30 12:49:52.816035 2026] [security2:error] [pid 806041:tid 806059] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/be6ebe446934e917bc7b1e73b3ad7c7b.css"] [unique_id "amuOwELAyZ1MRInzPMYDuwAA1hE"]
[Thu Jul 30 12:49:52.816082 2026] [security2:error] [pid 806041:tid 806050] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/be6ebe446934e917bc7b1e73b3ad7c7b.css"] [unique_id "amuOwELAyZ1MRInzPMYDugAA1gg"]
[Thu Jul 30 12:49:52.834259 2026] [security2:error] [pid 806041:tid 806172] [client 20.113.56.22:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/aabb.php"] [unique_id "amuOwELAyZ1MRInzPMYDvAAAAIY"]
[Thu Jul 30 12:49:52.834370 2026] [security2:error] [pid 806041:tid 806172] [client 20.113.56.22:12260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/aabb.php"] [unique_id "amuOwELAyZ1MRInzPMYDvAAAAIY"]
[Thu Jul 30 12:49:53.037175 2026] [security2:error] [pid 806041:tid 806177] [client 172.202.44.182:45456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/xleet.php"] [unique_id "amuOwULAyZ1MRInzPMYDwAAAAIs"]
[Thu Jul 30 12:49:53.045129 2026] [security2:error] [pid 806041:tid 806209] [client 172.213.232.128:49643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/css.php"] [unique_id "amuOwULAyZ1MRInzPMYDwQAAAKs"]
[Thu Jul 30 12:49:53.060324 2026] [security2:error] [pid 806041:tid 806062] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/980c125ad77f3b59e074de5cd9ff1a0a.css"] [unique_id "amuOwULAyZ1MRInzPMYDwwAA6hQ"]
[Thu Jul 30 12:49:53.060325 2026] [security2:error] [pid 806041:tid 806060] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/980c125ad77f3b59e074de5cd9ff1a0a.css"] [unique_id "amuOwULAyZ1MRInzPMYDwgAA6hI"]
[Thu Jul 30 12:49:53.098461 2026] [security2:error] [pid 806041:tid 806173] [client 4.185.41.66:15719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/FWAZ.php"] [unique_id "amuOwULAyZ1MRInzPMYDxwAAAIc"]
[Thu Jul 30 12:49:53.098545 2026] [security2:error] [pid 806041:tid 806173] [client 4.185.41.66:15719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/FWAZ.php"] [unique_id "amuOwULAyZ1MRInzPMYDxwAAAIc"]
[Thu Jul 30 12:49:53.131397 2026] [security2:error] [pid 806041:tid 806180] [client 20.113.56.22:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1254xx.php"] [unique_id "amuOwULAyZ1MRInzPMYDyAAAAI4"]
[Thu Jul 30 12:49:53.131483 2026] [security2:error] [pid 806041:tid 806180] [client 20.113.56.22:12235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1254xx.php"] [unique_id "amuOwULAyZ1MRInzPMYDyAAAAI4"]
[Thu Jul 30 12:49:53.297221 2026] [security2:error] [pid 806041:tid 806066] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/63399b6628f054a9282c98500962a464.css"] [unique_id "amuOwULAyZ1MRInzPMYDzwAA3Bg"]
[Thu Jul 30 12:49:53.297384 2026] [security2:error] [pid 806041:tid 806064] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/63399b6628f054a9282c98500962a464.css"] [unique_id "amuOwULAyZ1MRInzPMYD0AAA3BY"]
[Thu Jul 30 12:49:53.401502 2026] [security2:error] [pid 806041:tid 806237] [client 20.113.56.22:12252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuOwULAyZ1MRInzPMYD0QAAAMc"]
[Thu Jul 30 12:49:53.401610 2026] [security2:error] [pid 806041:tid 806237] [client 20.113.56.22:12252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuOwULAyZ1MRInzPMYD0QAAAMc"]
[Thu Jul 30 12:49:53.410537 2026] [security2:error] [pid 806041:tid 806190] [client 20.151.221.234:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuOwULAyZ1MRInzPMYD0gAAAJg"]
[Thu Jul 30 12:49:53.519580 2026] [core:notice] [pid 806041:tid 806188] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:53.526051 2026] [security2:error] [pid 806041:tid 806188] [client 103.215.74.26:32220] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOwULAyZ1MRInzPMYD0wAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:53.538618 2026] [security2:error] [pid 806041:tid 806070] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/1cebc8042df2392a8dc2891605b54dc8.css"] [unique_id "amuOwULAyZ1MRInzPMYD1AAAxRw"]
[Thu Jul 30 12:49:53.539086 2026] [security2:error] [pid 806041:tid 806061] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/1cebc8042df2392a8dc2891605b54dc8.css"] [unique_id "amuOwULAyZ1MRInzPMYD1QAAxRM"]
[Thu Jul 30 12:49:53.596605 2026] [security2:error] [pid 806041:tid 806221] [client 4.185.41.66:15694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/biufile.php"] [unique_id "amuOwULAyZ1MRInzPMYD1wAAALc"]
[Thu Jul 30 12:49:53.596710 2026] [security2:error] [pid 806041:tid 806221] [client 4.185.41.66:15694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/biufile.php"] [unique_id "amuOwULAyZ1MRInzPMYD1wAAALc"]
[Thu Jul 30 12:49:53.665919 2026] [security2:error] [pid 806041:tid 806205] [client 20.113.56.22:12213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/pms297.php"] [unique_id "amuOwULAyZ1MRInzPMYD3AAAAKc"]
[Thu Jul 30 12:49:53.666026 2026] [security2:error] [pid 806041:tid 806205] [client 20.113.56.22:12213] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/pms297.php"] [unique_id "amuOwULAyZ1MRInzPMYD3AAAAKc"]
[Thu Jul 30 12:49:53.766228 2026] [security2:error] [pid 806041:tid 806057] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/bc0de534500435e639f6134b0114d128.css"] [unique_id "amuOwULAyZ1MRInzPMYD4gAAyA8"]
[Thu Jul 30 12:49:53.766244 2026] [security2:error] [pid 806041:tid 806079] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/bc0de534500435e639f6134b0114d128.css"] [unique_id "amuOwULAyZ1MRInzPMYD4AAAyCU"]
[Thu Jul 30 12:49:53.766548 2026] [security2:error] [pid 806041:tid 806198] [client 20.151.221.234:2624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/asd.php"] [unique_id "amuOwULAyZ1MRInzPMYD4QAAAKA"]
[Thu Jul 30 12:49:53.792335 2026] [security2:error] [pid 806041:tid 806243] [client 172.213.232.128:58042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/database.php"] [unique_id "amuOwULAyZ1MRInzPMYD4wAAAM0"]
[Thu Jul 30 12:49:53.801106 2026] [proxy:error] [pid 806041:tid 806216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:53.801171 2026] [proxy_http:error] [pid 806041:tid 806216] [client 152.32.138.230:41238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:53.801737 2026] [proxy:error] [pid 806041:tid 806216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:49:53.801788 2026] [proxy_http:error] [pid 806041:tid 806216] [client 152.32.138.230:41238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:49:53.971325 2026] [security2:error] [pid 806041:tid 806202] [client 172.202.44.182:45499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/ds.php"] [unique_id "amuOwULAyZ1MRInzPMYD6AAAAKQ"]
[Thu Jul 30 12:49:53.990413 2026] [security2:error] [pid 806041:tid 806069] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/fab966ca0d273ba62a74051beef5d887.css"] [unique_id "amuOwULAyZ1MRInzPMYD6gAAmRs"]
[Thu Jul 30 12:49:53.990620 2026] [security2:error] [pid 806041:tid 806054] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/fab966ca0d273ba62a74051beef5d887.css"] [unique_id "amuOwULAyZ1MRInzPMYD6QAAmQw"]
[Thu Jul 30 12:49:54.033002 2026] [security2:error] [pid 806041:tid 806275] [client 20.113.56.22:15512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuOwkLAyZ1MRInzPMYD6wAAAO0"]
[Thu Jul 30 12:49:54.033093 2026] [security2:error] [pid 806041:tid 806275] [client 20.113.56.22:15512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuOwkLAyZ1MRInzPMYD6wAAAO0"]
[Thu Jul 30 12:49:54.233112 2026] [security2:error] [pid 806041:tid 806071] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/f447769fabfac96a7b50a809aacf62b4.css"] [unique_id "amuOwkLAyZ1MRInzPMYD8wABAx0"]
[Thu Jul 30 12:49:54.233112 2026] [security2:error] [pid 806041:tid 806081] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/f447769fabfac96a7b50a809aacf62b4.css"] [unique_id "amuOwkLAyZ1MRInzPMYD8gABAyc"]
[Thu Jul 30 12:49:54.275053 2026] [core:notice] [pid 806041:tid 806222] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:54.281555 2026] [security2:error] [pid 806041:tid 806222] [client 103.215.74.26:32236] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOwkLAyZ1MRInzPMYD9AAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:54.294088 2026] [security2:error] [pid 806041:tid 806239] [client 20.113.56.22:12196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuOwkLAyZ1MRInzPMYD-AAAAMk"]
[Thu Jul 30 12:49:54.294190 2026] [security2:error] [pid 806041:tid 806239] [client 20.113.56.22:12196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuOwkLAyZ1MRInzPMYD-AAAAMk"]
[Thu Jul 30 12:49:54.390033 2026] [security2:error] [pid 806041:tid 806178] [client 4.185.41.66:15640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/coffexium.php"] [unique_id "amuOwkLAyZ1MRInzPMYD-QAAAIw"]
[Thu Jul 30 12:49:54.390144 2026] [security2:error] [pid 806041:tid 806178] [client 4.185.41.66:15640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/coffexium.php"] [unique_id "amuOwkLAyZ1MRInzPMYD-QAAAIw"]
[Thu Jul 30 12:49:54.560414 2026] [security2:error] [pid 806041:tid 806174] [client 20.113.56.22:12206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuOwkLAyZ1MRInzPMYD-gAAAIg"]
[Thu Jul 30 12:49:54.560531 2026] [security2:error] [pid 806041:tid 806174] [client 20.113.56.22:12206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuOwkLAyZ1MRInzPMYD-gAAAIg"]
[Thu Jul 30 12:49:54.754275 2026] [security2:error] [pid 806041:tid 806292] [client 20.151.221.234:22738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/403.php"] [unique_id "amuOwkLAyZ1MRInzPMYD_gAAAP4"]
[Thu Jul 30 12:49:54.808027 2026] [security2:error] [pid 806041:tid 806083] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/comments/feed/"] [unique_id "amuOwkLAyZ1MRInzPMYEAgAA1ik"]
[Thu Jul 30 12:49:54.808448 2026] [security2:error] [pid 806041:tid 806075] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/comments/feed/"] [unique_id "amuOwkLAyZ1MRInzPMYEAwAA1iE"]
[Thu Jul 30 12:49:54.839219 2026] [security2:error] [pid 806041:tid 806172] [client 150.107.232.194:27378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOwkLAyZ1MRInzPMYEBAAAAIY"]
[Thu Jul 30 12:49:54.839326 2026] [security2:error] [pid 806041:tid 806172] [client 150.107.232.194:27378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOwkLAyZ1MRInzPMYEBAAAAIY"]
[Thu Jul 30 12:49:54.851800 2026] [security2:error] [pid 806041:tid 806267] [client 20.113.56.22:15610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuOwkLAyZ1MRInzPMYEBQAAAOU"]
[Thu Jul 30 12:49:54.851886 2026] [security2:error] [pid 806041:tid 806267] [client 20.113.56.22:15610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuOwkLAyZ1MRInzPMYEBQAAAOU"]
[Thu Jul 30 12:49:55.005873 2026] [security2:error] [pid 806041:tid 806080] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/43798e32a57016c5525f2e81b8b2d22c.css"] [unique_id "amuOw0LAyZ1MRInzPMYECQAAqyY"]
[Thu Jul 30 12:49:55.006224 2026] [security2:error] [pid 806041:tid 806073] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/43798e32a57016c5525f2e81b8b2d22c.css"] [unique_id "amuOw0LAyZ1MRInzPMYECgAAqx8"]
[Thu Jul 30 12:49:55.013664 2026] [core:notice] [pid 806041:tid 806181] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:55.019915 2026] [security2:error] [pid 806041:tid 806181] [client 103.215.74.26:32244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOw0LAyZ1MRInzPMYECwAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:55.130614 2026] [security2:error] [pid 806041:tid 806272] [client 20.113.56.22:15524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dyui.php"] [unique_id "amuOw0LAyZ1MRInzPMYEDAAAAOo"]
[Thu Jul 30 12:49:55.130721 2026] [security2:error] [pid 806041:tid 806272] [client 20.113.56.22:15524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/dyui.php"] [unique_id "amuOw0LAyZ1MRInzPMYEDAAAAOo"]
[Thu Jul 30 12:49:55.214147 2026] [security2:error] [pid 806041:tid 806077] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/573753695e953950577265bda4208a40.css"] [unique_id "amuOw0LAyZ1MRInzPMYEDQAA3iM"]
[Thu Jul 30 12:49:55.214287 2026] [security2:error] [pid 806041:tid 806074] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/573753695e953950577265bda4208a40.css"] [unique_id "amuOw0LAyZ1MRInzPMYEDgAA3iA"]
[Thu Jul 30 12:49:55.346676 2026] [security2:error] [pid 806041:tid 806230] [client 4.185.41.66:15737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/simple.php"] [unique_id "amuOw0LAyZ1MRInzPMYEFQAAAMA"]
[Thu Jul 30 12:49:55.346764 2026] [security2:error] [pid 806041:tid 806230] [client 4.185.41.66:15737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/simple.php"] [unique_id "amuOw0LAyZ1MRInzPMYEFQAAAMA"]
[Thu Jul 30 12:49:55.391117 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:12221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ho.php"] [unique_id "amuOw0LAyZ1MRInzPMYEGQAAAKw"]
[Thu Jul 30 12:49:55.391219 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:12221] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ho.php"] [unique_id "amuOw0LAyZ1MRInzPMYEGQAAAKw"]
[Thu Jul 30 12:49:55.442101 2026] [security2:error] [pid 806041:tid 806087] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/b09b52238fd6e304df8bb50896340e01.css"] [unique_id "amuOw0LAyZ1MRInzPMYEGwAAmC0"]
[Thu Jul 30 12:49:55.442242 2026] [security2:error] [pid 806041:tid 806086] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/b09b52238fd6e304df8bb50896340e01.css"] [unique_id "amuOw0LAyZ1MRInzPMYEGgAAmCw"]
[Thu Jul 30 12:49:55.657042 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:15604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/66b867516c8f01.php"] [unique_id "amuOw0LAyZ1MRInzPMYEIQAAANI"]
[Thu Jul 30 12:49:55.657176 2026] [security2:error] [pid 806041:tid 806248] [client 20.113.56.22:15604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/66b867516c8f01.php"] [unique_id "amuOw0LAyZ1MRInzPMYEIQAAANI"]
[Thu Jul 30 12:49:55.679912 2026] [security2:error] [pid 806041:tid 806099] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/004ddce71c73790de3158a27851c669e.css"] [unique_id "amuOw0LAyZ1MRInzPMYEIwAApzk"]
[Thu Jul 30 12:49:55.680394 2026] [security2:error] [pid 806041:tid 806095] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/004ddce71c73790de3158a27851c669e.css"] [unique_id "amuOw0LAyZ1MRInzPMYEJAAApzU"]
[Thu Jul 30 12:49:55.707936 2026] [security2:error] [pid 806041:tid 806295] [client 172.202.44.182:22529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/f5.php"] [unique_id "amuOw0LAyZ1MRInzPMYEJQAAAQE"]
[Thu Jul 30 12:49:55.767776 2026] [core:notice] [pid 806041:tid 806221] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:55.774092 2026] [security2:error] [pid 806041:tid 806221] [client 103.215.74.26:32248] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOw0LAyZ1MRInzPMYEKQAAALc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:49:55.810192 2026] [security2:error] [pid 806041:tid 806266] [client 20.151.221.234:45041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuOw0LAyZ1MRInzPMYELwAAAOQ"]
[Thu Jul 30 12:49:55.880626 2026] [core:notice] [pid 806041:tid 806091] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:49:55.917351 2026] [security2:error] [pid 806041:tid 806078] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/2a3e332a2064a580a5c80ddb56c55c61.css"] [unique_id "amuOw0LAyZ1MRInzPMYENwAAyyQ"]
[Thu Jul 30 12:49:55.917615 2026] [security2:error] [pid 806041:tid 806097] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/2a3e332a2064a580a5c80ddb56c55c61.css"] [unique_id "amuOw0LAyZ1MRInzPMYEOAAAyzc"]
[Thu Jul 30 12:49:56.008041 2026] [security2:error] [pid 806041:tid 806263] [client 20.113.56.22:15588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ext.php"] [unique_id "amuOxELAyZ1MRInzPMYEOQAAAOE"]
[Thu Jul 30 12:49:56.008147 2026] [security2:error] [pid 806041:tid 806263] [client 20.113.56.22:15588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/ext.php"] [unique_id "amuOxELAyZ1MRInzPMYEOQAAAOE"]
[Thu Jul 30 12:49:56.159655 2026] [security2:error] [pid 806041:tid 806102] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/3019419137fbea2355a319107a9dfb31.css"] [unique_id "amuOxELAyZ1MRInzPMYEOwAA8jw"]
[Thu Jul 30 12:49:56.159812 2026] [security2:error] [pid 806041:tid 806098] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/3019419137fbea2355a319107a9dfb31.css"] [unique_id "amuOxELAyZ1MRInzPMYEOgAA8jg"]
[Thu Jul 30 12:49:56.209930 2026] [security2:error] [pid 806041:tid 806093] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOxELAyZ1MRInzPMYEPAABAzM"]
[Thu Jul 30 12:49:56.210081 2026] [security2:error] [pid 806041:tid 806297] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOxELAyZ1MRInzPMYEPAABAzM"]
[Thu Jul 30 12:49:56.300990 2026] [security2:error] [pid 806041:tid 806239] [client 20.113.56.22:15500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuOxELAyZ1MRInzPMYEQAAAAMk"]
[Thu Jul 30 12:49:56.301147 2026] [security2:error] [pid 806041:tid 806239] [client 20.113.56.22:15500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuOxELAyZ1MRInzPMYEQAAAAMk"]
[Thu Jul 30 12:49:56.402772 2026] [security2:error] [pid 806041:tid 806174] [client 4.185.41.66:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/fpwch.php"] [unique_id "amuOxELAyZ1MRInzPMYERQAAAIg"]
[Thu Jul 30 12:49:56.402877 2026] [security2:error] [pid 806041:tid 806174] [client 4.185.41.66:15696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/fpwch.php"] [unique_id "amuOxELAyZ1MRInzPMYERQAAAIg"]
[Thu Jul 30 12:49:56.406474 2026] [security2:error] [pid 806041:tid 806092] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/70661d0b66f9ed021e77f5560cba8771.css"] [unique_id "amuOxELAyZ1MRInzPMYERgAAujI"]
[Thu Jul 30 12:49:56.406473 2026] [security2:error] [pid 806041:tid 806110] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/70661d0b66f9ed021e77f5560cba8771.css"] [unique_id "amuOxELAyZ1MRInzPMYERwAAukQ"]
[Thu Jul 30 12:49:56.575813 2026] [security2:error] [pid 806041:tid 806217] [client 20.113.56.22:12275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/diidi.php"] [unique_id "amuOxELAyZ1MRInzPMYESwAAALM"]
[Thu Jul 30 12:49:56.575930 2026] [security2:error] [pid 806041:tid 806217] [client 20.113.56.22:12275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/diidi.php"] [unique_id "amuOxELAyZ1MRInzPMYESwAAALM"]
[Thu Jul 30 12:49:56.659436 2026] [security2:error] [pid 806041:tid 806108] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/054967392f898f7680d5d1fa487c0f93.css"] [unique_id "amuOxELAyZ1MRInzPMYETAAAiUI"]
[Thu Jul 30 12:49:56.659569 2026] [security2:error] [pid 806041:tid 806116] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/054967392f898f7680d5d1fa487c0f93.css"] [unique_id "amuOxELAyZ1MRInzPMYETQAAiUo"]
[Thu Jul 30 12:49:56.688029 2026] [security2:error] [pid 806041:tid 806196] [client 172.202.44.182:45481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/god4m.php"] [unique_id "amuOxELAyZ1MRInzPMYETgAAAJ4"]
[Thu Jul 30 12:49:56.734134 2026] [security2:error] [pid 806041:tid 806292] [client 20.151.221.234:34830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/admin.php"] [unique_id "amuOxELAyZ1MRInzPMYETwAAAP4"]
[Thu Jul 30 12:49:56.843223 2026] [security2:error] [pid 806041:tid 806223] [client 20.113.56.22:12176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/clarebypas.php"] [unique_id "amuOxELAyZ1MRInzPMYEUgAAALk"]
[Thu Jul 30 12:49:56.843333 2026] [security2:error] [pid 806041:tid 806223] [client 20.113.56.22:12176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/clarebypas.php"] [unique_id "amuOxELAyZ1MRInzPMYEUgAAALk"]
[Thu Jul 30 12:49:56.903181 2026] [security2:error] [pid 806041:tid 806109] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/e9e0221480d00e9b16b7bdcba3b023fe.css"] [unique_id "amuOxELAyZ1MRInzPMYEVwAAj0M"]
[Thu Jul 30 12:49:56.903315 2026] [security2:error] [pid 806041:tid 806119] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/e9e0221480d00e9b16b7bdcba3b023fe.css"] [unique_id "amuOxELAyZ1MRInzPMYEWAAAj00"]
[Thu Jul 30 12:49:56.990923 2026] [security2:error] [pid 806041:tid 806215] [client 20.151.221.234:52397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuOxELAyZ1MRInzPMYEXAAAALE"]
[Thu Jul 30 12:49:57.159489 2026] [security2:error] [pid 806041:tid 806106] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-json/"] [unique_id "amuOxULAyZ1MRInzPMYEXQAAkUA"]
[Thu Jul 30 12:49:57.159491 2026] [security2:error] [pid 806041:tid 806105] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-json/"] [unique_id "amuOxULAyZ1MRInzPMYEXgAAkT8"]
[Thu Jul 30 12:49:57.211873 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:12171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/x402.php"] [unique_id "amuOxULAyZ1MRInzPMYEXwAAAKw"]
[Thu Jul 30 12:49:57.211969 2026] [security2:error] [pid 806041:tid 806210] [client 20.113.56.22:12171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoverspackers.com"] [uri "/x402.php"] [unique_id "amuOxULAyZ1MRInzPMYEXwAAAKw"]
[Thu Jul 30 12:49:57.429732 2026] [security2:error] [pid 806041:tid 806114] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-json/wp/v2/pages/13"] [unique_id "amuOxULAyZ1MRInzPMYEcQAA5kg"]
[Thu Jul 30 12:49:57.429852 2026] [security2:error] [pid 806041:tid 806130] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-json/wp/v2/pages/13"] [unique_id "amuOxULAyZ1MRInzPMYEcgAA5lg"]
[Thu Jul 30 12:49:57.454374 2026] [security2:error] [pid 806041:tid 806252] [client 172.213.232.128:56693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/db.php"] [unique_id "amuOxULAyZ1MRInzPMYEcwAAANY"]
[Thu Jul 30 12:49:57.472532 2026] [security2:error] [pid 806041:tid 806199] [client 20.151.221.234:45052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/as.php"] [unique_id "amuOxULAyZ1MRInzPMYEdAAAAKE"]
[Thu Jul 30 12:49:57.519261 2026] [security2:error] [pid 806041:tid 806278] [client 4.185.41.66:15627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/dex.php"] [unique_id "amuOxULAyZ1MRInzPMYEeAAAAPA"]
[Thu Jul 30 12:49:57.519420 2026] [security2:error] [pid 806041:tid 806278] [client 4.185.41.66:15627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/dex.php"] [unique_id "amuOxULAyZ1MRInzPMYEeAAAAPA"]
[Thu Jul 30 12:49:57.857593 2026] [security2:error] [pid 806041:tid 806244] [client 20.151.221.234:34862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuOxULAyZ1MRInzPMYEgQAAAM4"]
[Thu Jul 30 12:49:57.938353 2026] [security2:error] [pid 806041:tid 806118] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuOxULAyZ1MRInzPMYEfQAA50w"]
[Thu Jul 30 12:49:57.949801 2026] [security2:error] [pid 806041:tid 806124] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuOxULAyZ1MRInzPMYEfgAA51I"]
[Thu Jul 30 12:49:58.148414 2026] [security2:error] [pid 806041:tid 806134] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/"] [unique_id "amuOxkLAyZ1MRInzPMYEiQAAz1w"]
[Thu Jul 30 12:49:58.159437 2026] [security2:error] [pid 806041:tid 806136] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/"] [unique_id "amuOxkLAyZ1MRInzPMYEigAA9V4"]
[Thu Jul 30 12:49:58.234556 2026] [security2:error] [pid 806041:tid 806202] [client 20.151.221.234:52366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuOxkLAyZ1MRInzPMYEiwAAAKQ"]
[Thu Jul 30 12:49:58.365916 2026] [security2:error] [pid 806041:tid 806143] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/feed/"] [unique_id "amuOxkLAyZ1MRInzPMYEjQAAymU"]
[Thu Jul 30 12:49:58.374228 2026] [security2:error] [pid 806041:tid 806140] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/feed/"] [unique_id "amuOxkLAyZ1MRInzPMYEjwAA-mI"]
[Thu Jul 30 12:49:58.467142 2026] [security2:error] [pid 806041:tid 806249] [client 172.213.232.128:58796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/default.php"] [unique_id "amuOxkLAyZ1MRInzPMYElQAAANM"]
[Thu Jul 30 12:49:59.004472 2026] [security2:error] [pid 806041:tid 806272] [client 20.151.221.234:2659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/atomlib.php"] [unique_id "amuOx0LAyZ1MRInzPMYEsAAAAOo"]
[Thu Jul 30 12:49:59.035155 2026] [security2:error] [pid 806041:tid 806258] [client 172.202.44.182:22553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/info.php"] [unique_id "amuOx0LAyZ1MRInzPMYEyAAAANw"]
[Thu Jul 30 12:49:59.064486 2026] [security2:error] [pid 806041:tid 806265] [client 172.213.232.128:56213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/dropdown.php"] [unique_id "amuOx0LAyZ1MRInzPMYEyQAAAOM"]
[Thu Jul 30 12:49:59.085082 2026] [security2:error] [pid 806041:tid 806059] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/"] [unique_id "amuOx0LAyZ1MRInzPMYEzAAArRE"]
[Thu Jul 30 12:49:59.167333 2026] [security2:error] [pid 806041:tid 806174] [client 20.151.221.234:34852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/m.php"] [unique_id "amuOx0LAyZ1MRInzPMYEzgAAAIg"]
[Thu Jul 30 12:49:59.303855 2026] [security2:error] [pid 806041:tid 806050] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/678bf1cd24fd6faa39448f394fa756db.css"] [unique_id "amuOx0LAyZ1MRInzPMYEzwAApwg"]
[Thu Jul 30 12:49:59.432368 2026] [security2:error] [pid 806041:tid 806056] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/"] [unique_id "amuOx0LAyZ1MRInzPMYE0wAAyA4"]
[Thu Jul 30 12:49:59.534372 2026] [security2:error] [pid 806041:tid 806058] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/favicon.ico"] [unique_id "amuOx0LAyZ1MRInzPMYE5AAA7hA"]
[Thu Jul 30 12:49:59.534449 2026] [security2:error] [pid 806041:tid 806069] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/img/favicon.ico"] [unique_id "amuOx0LAyZ1MRInzPMYE5QAA7hs"]
[Thu Jul 30 12:49:59.534478 2026] [security2:error] [pid 806041:tid 806054] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/assets/favicon.ico"] [unique_id "amuOx0LAyZ1MRInzPMYE5gAA7gw"]
[Thu Jul 30 12:49:59.534597 2026] [security2:error] [pid 806041:tid 806065] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/images/favicon.ico"] [unique_id "amuOx0LAyZ1MRInzPMYE5wAA7hc"]
[Thu Jul 30 12:49:59.534608 2026] [security2:error] [pid 806041:tid 806072] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/icon/favicon.ico"] [unique_id "amuOx0LAyZ1MRInzPMYE6gAA7h4"]
[Thu Jul 30 12:49:59.534659 2026] [security2:error] [pid 806041:tid 806081] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/static/favicon.ico"] [unique_id "amuOx0LAyZ1MRInzPMYE6QAA7ic"]
[Thu Jul 30 12:49:59.534708 2026] [security2:error] [pid 806041:tid 806071] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/favicon.png"] [unique_id "amuOx0LAyZ1MRInzPMYE6AAA7h0"]
[Thu Jul 30 12:49:59.621877 2026] [security2:error] [pid 806041:tid 806199] [client 165.22.180.136:53722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuOx0LAyZ1MRInzPMYE7gAAAKE"]
[Thu Jul 30 12:49:59.667608 2026] [security2:error] [pid 806041:tid 806082] [remote 27.44.125.106:23556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/wp-content/litespeed/css/678bf1cd24fd6faa39448f394fa756db.css"] [unique_id "amuOx0LAyZ1MRInzPMYE7wAA1yg"]
[Thu Jul 30 12:49:59.707615 2026] [security2:error] [pid 806041:tid 806293] [client 4.185.41.66:15735] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.j-nintei.com"] [uri "/1.php"] [unique_id "amuOx0LAyZ1MRInzPMYE8AAAAP8"]
[Thu Jul 30 12:49:59.707726 2026] [security2:error] [pid 806041:tid 806293] [client 4.185.41.66:15735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/1.php"] [unique_id "amuOx0LAyZ1MRInzPMYE8AAAAP8"]
[Thu Jul 30 12:49:59.707818 2026] [security2:error] [pid 806041:tid 806293] [client 4.185.41.66:15735] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/1.php"] [unique_id "amuOx0LAyZ1MRInzPMYE8AAAAP8"]
[Thu Jul 30 12:49:59.823577 2026] [security2:error] [pid 806041:tid 806252] [client 165.22.180.136:45316] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuOx0LAyZ1MRInzPMYE9wAAANY"]
[Thu Jul 30 12:49:59.995020 2026] [security2:error] [pid 806041:tid 806232] [client 172.213.232.128:60714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/edit.php"] [unique_id "amuOx0LAyZ1MRInzPMYFAAAAAMI"]
[Thu Jul 30 12:50:00.345828 2026] [core:error] [pid 806041:tid 806262] [client 20.151.221.234:52939] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:00.345858 2026] [core:error] [pid 806041:tid 806262] [client 20.151.221.234:52939] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:00.947426 2026] [security2:error] [pid 806041:tid 806246] [client 20.100.187.246:6169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.tmb/LA.php"] [unique_id "amuOyELAyZ1MRInzPMYFGAAAANA"]
[Thu Jul 30 12:50:01.145808 2026] [autoindex:error] [pid 806041:tid 806272] [client 4.185.41.66:15721] AH01276: Cannot serve directory /home1/mszudite/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:50:01.146598 2026] [security2:error] [pid 806041:tid 806272] [client 4.185.41.66:15721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.j-nintei.com"] [uri "/cgi-sys/403.html"] [unique_id "amuOyULAyZ1MRInzPMYFHQAAAOo"]
[Thu Jul 30 12:50:01.212145 2026] [security2:error] [pid 806041:tid 806221] [client 20.151.221.234:23419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuOyULAyZ1MRInzPMYFJgAAALc"]
[Thu Jul 30 12:50:01.275858 2026] [security2:error] [pid 806041:tid 806190] [client 4.185.41.66:15721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/config.json.php"] [unique_id "amuOyULAyZ1MRInzPMYFKAAAAJg"]
[Thu Jul 30 12:50:01.275961 2026] [security2:error] [pid 806041:tid 806190] [client 4.185.41.66:15721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/config.json.php"] [unique_id "amuOyULAyZ1MRInzPMYFKAAAAJg"]
[Thu Jul 30 12:50:01.478500 2026] [security2:error] [pid 806041:tid 806281] [client 172.202.44.182:45444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.__info.php"] [unique_id "amuOyULAyZ1MRInzPMYFKQAAAPM"]
[Thu Jul 30 12:50:01.515621 2026] [core:notice] [pid 806041:tid 806248] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:01.525602 2026] [security2:error] [pid 806041:tid 806248] [client 103.215.74.26:32254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOyULAyZ1MRInzPMYFLAAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:01.718781 2026] [core:error] [pid 806041:tid 806197] [client 20.151.221.234:36690] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:01.718817 2026] [core:error] [pid 806041:tid 806197] [client 20.151.221.234:36690] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:02.132470 2026] [security2:error] [pid 806041:tid 806173] [client 20.151.221.234:23392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuOykLAyZ1MRInzPMYFQgAAAIc"]
[Thu Jul 30 12:50:02.274342 2026] [core:notice] [pid 806041:tid 806244] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:02.280745 2026] [security2:error] [pid 806041:tid 806244] [client 103.215.74.26:32268] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOykLAyZ1MRInzPMYFRgAAAM4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:02.334110 2026] [security2:error] [pid 806041:tid 806254] [client 20.100.187.246:6175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.tmb/admin.php"] [unique_id "amuOykLAyZ1MRInzPMYFSQAAANg"]
[Thu Jul 30 12:50:02.417966 2026] [security2:error] [pid 806041:tid 806217] [client 4.185.41.66:15634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/k2.php"] [unique_id "amuOykLAyZ1MRInzPMYFSwAAALM"]
[Thu Jul 30 12:50:02.418088 2026] [security2:error] [pid 806041:tid 806217] [client 4.185.41.66:15634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/k2.php"] [unique_id "amuOykLAyZ1MRInzPMYFSwAAALM"]
[Thu Jul 30 12:50:02.673610 2026] [security2:error] [pid 806041:tid 806298] [client 172.213.232.128:56236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/f35.php"] [unique_id "amuOykLAyZ1MRInzPMYFUgAAAQQ"]
[Thu Jul 30 12:50:03.002782 2026] [security2:error] [pid 806041:tid 806201] [client 172.202.44.182:45459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/0.php"] [unique_id "amuOy0LAyZ1MRInzPMYFWwAAAKM"]
[Thu Jul 30 12:50:03.019988 2026] [core:notice] [pid 806041:tid 806275] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:03.030820 2026] [security2:error] [pid 806041:tid 806275] [client 103.215.74.26:62968] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOy0LAyZ1MRInzPMYFXAAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:03.199668 2026] [security2:error] [pid 806041:tid 806262] [client 20.151.221.234:2667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuOy0LAyZ1MRInzPMYFaQAAAOA"]
[Thu Jul 30 12:50:03.201450 2026] [security2:error] [pid 806041:tid 806214] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.myintentionalreset.com"] [uri "/index.php"] [unique_id "amuOyULAyZ1MRInzPMYFIwAAALA"]
[Thu Jul 30 12:50:03.202261 2026] [security2:error] [pid 806041:tid 806187] [client 74.7.244.52:51074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.myintentionalreset.com"] [uri "/robots.txt"] [unique_id "amuOyULAyZ1MRInzPMYFIAAAlT4"]
[Thu Jul 30 12:50:03.523485 2026] [security2:error] [pid 806041:tid 806253] [client 217.138.252.123:43426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.252.138.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuOy0LAyZ1MRInzPMYFbgAAANc"]
[Thu Jul 30 12:50:03.523618 2026] [security2:error] [pid 806041:tid 806253] [client 217.138.252.123:43426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuOy0LAyZ1MRInzPMYFbgAAANc"]
[Thu Jul 30 12:50:03.711245 2026] [security2:error] [pid 806041:tid 806212] [client 20.151.221.234:57666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuOy0LAyZ1MRInzPMYFcgAAAK4"]
[Thu Jul 30 12:50:03.718009 2026] [security2:error] [pid 806041:tid 806276] [client 172.213.232.128:49606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/f7.php"] [unique_id "amuOy0LAyZ1MRInzPMYFcwAAAO4"]
[Thu Jul 30 12:50:03.772048 2026] [core:notice] [pid 806041:tid 806171] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:03.778571 2026] [security2:error] [pid 806041:tid 806171] [client 103.215.74.26:62974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOy0LAyZ1MRInzPMYFeAAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:03.930134 2026] [security2:error] [pid 806041:tid 806180] [client 20.100.187.246:5808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.tmb/class_api.php"] [unique_id "amuOy0LAyZ1MRInzPMYFfAAAAI4"]
[Thu Jul 30 12:50:04.034209 2026] [core:error] [pid 806041:tid 806280] [client 66.249.75.229:38726] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:04.034239 2026] [core:error] [pid 806041:tid 806280] [client 66.249.75.229:38726] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:04.299598 2026] [security2:error] [pid 806041:tid 806184] [client 4.185.41.66:15710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/raw.php"] [unique_id "amuOzELAyZ1MRInzPMYFigAAAJI"]
[Thu Jul 30 12:50:04.299730 2026] [security2:error] [pid 806041:tid 806184] [client 4.185.41.66:15710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/raw.php"] [unique_id "amuOzELAyZ1MRInzPMYFigAAAJI"]
[Thu Jul 30 12:50:04.507811 2026] [core:notice] [pid 806041:tid 806245] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:04.515258 2026] [security2:error] [pid 806041:tid 806245] [client 103.215.74.26:62986] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOzELAyZ1MRInzPMYFjwAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:04.582404 2026] [core:error] [pid 806041:tid 806189] [client 20.151.221.234:52370] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:04.582429 2026] [core:error] [pid 806041:tid 806189] [client 20.151.221.234:52370] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:05.120249 2026] [security2:error] [pid 806041:tid 806191] [client 150.109.46.88:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.46.109.150.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuOzELAyZ1MRInzPMYFkQAAAJk"]
[Thu Jul 30 12:50:05.252448 2026] [core:notice] [pid 806041:tid 806183] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:05.259187 2026] [security2:error] [pid 806041:tid 806183] [client 103.215.74.26:62996] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOzULAyZ1MRInzPMYFqAAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:05.275719 2026] [security2:error] [pid 806041:tid 806199] [client 20.151.221.234:57690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/classwithtostring.php"] [unique_id "amuOzULAyZ1MRInzPMYFqQAAAKE"]
[Thu Jul 30 12:50:05.325216 2026] [security2:error] [pid 806041:tid 806223] [client 150.107.232.194:27153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOzULAyZ1MRInzPMYFrQAAALk"]
[Thu Jul 30 12:50:05.325347 2026] [security2:error] [pid 806041:tid 806223] [client 150.107.232.194:27153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuOzULAyZ1MRInzPMYFrQAAALk"]
[Thu Jul 30 12:50:05.407250 2026] [security2:error] [pid 806041:tid 806272] [client 20.151.221.234:50623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/plugins.php"] [unique_id "amuOzULAyZ1MRInzPMYFrgAAAOo"]
[Thu Jul 30 12:50:05.428379 2026] [core:error] [pid 806041:tid 806250] [client 20.151.221.234:2660] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:05.428401 2026] [core:error] [pid 806041:tid 806250] [client 20.151.221.234:2660] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:05.435118 2026] [security2:error] [pid 806041:tid 806279] [client 20.100.187.246:27931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuOzULAyZ1MRInzPMYFswAAAPE"]
[Thu Jul 30 12:50:05.881669 2026] [security2:error] [pid 806041:tid 806229] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuOzULAyZ1MRInzPMYFpwAAv14"]
[Thu Jul 30 12:50:05.992149 2026] [core:notice] [pid 806041:tid 806173] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:05.999137 2026] [security2:error] [pid 806041:tid 806173] [client 103.215.74.26:63012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOzULAyZ1MRInzPMYFvQAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:06.472354 2026] [security2:error] [pid 806041:tid 806172] [client 4.185.41.66:15636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/wp.php"] [unique_id "amuOzkLAyZ1MRInzPMYFzwAAAIY"]
[Thu Jul 30 12:50:06.472472 2026] [security2:error] [pid 806041:tid 806172] [client 4.185.41.66:15636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/wp.php"] [unique_id "amuOzkLAyZ1MRInzPMYFzwAAAIY"]
[Thu Jul 30 12:50:06.616917 2026] [security2:error] [pid 806041:tid 806251] [client 20.100.187.246:5760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuOzkLAyZ1MRInzPMYFygAAANU"]
[Thu Jul 30 12:50:06.617586 2026] [core:notice] [pid 806041:tid 806256] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:06.627751 2026] [security2:error] [pid 806041:tid 806215] [client 86.106.84.166:56766] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuOzkLAyZ1MRInzPMYF0gAAALE"]
[Thu Jul 30 12:50:06.627838 2026] [security2:error] [pid 806041:tid 806215] [client 86.106.84.166:56766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuOzkLAyZ1MRInzPMYF0gAAALE"]
[Thu Jul 30 12:50:06.732003 2026] [core:notice] [pid 806041:tid 806270] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:06.742386 2026] [security2:error] [pid 806041:tid 806270] [client 103.215.74.26:63016] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuOzkLAyZ1MRInzPMYF0wAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:06.853114 2026] [security2:error] [pid 806041:tid 806235] [client 20.151.221.234:11944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/gmo.php"] [unique_id "amuOzkLAyZ1MRInzPMYF1wAAAMU"]
[Thu Jul 30 12:50:06.877578 2026] [security2:error] [pid 806041:tid 806240] [client 20.151.221.234:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuOzkLAyZ1MRInzPMYF2AAAAMo"]
[Thu Jul 30 12:50:06.982343 2026] [security2:error] [pid 806041:tid 806147] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOzkLAyZ1MRInzPMYF3gAArWk"]
[Thu Jul 30 12:50:06.982509 2026] [security2:error] [pid 806041:tid 806211] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuOzkLAyZ1MRInzPMYF3gAArWk"]
[Thu Jul 30 12:50:07.179045 2026] [core:error] [pid 806041:tid 806265] [client 20.151.221.234:36712] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:07.179071 2026] [core:error] [pid 806041:tid 806265] [client 20.151.221.234:36712] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:07.523549 2026] [security2:error] [pid 806041:tid 806205] [client 20.100.187.246:6195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuOz0LAyZ1MRInzPMYF7wAAAKc"]
[Thu Jul 30 12:50:07.774368 2026] [security2:error] [pid 806041:tid 806238] [client 4.185.41.66:15620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/fffm.php"] [unique_id "amuOz0LAyZ1MRInzPMYF8QAAAMg"]
[Thu Jul 30 12:50:07.774489 2026] [security2:error] [pid 806041:tid 806238] [client 4.185.41.66:15620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/fffm.php"] [unique_id "amuOz0LAyZ1MRInzPMYF8QAAAMg"]
[Thu Jul 30 12:50:07.784351 2026] [security2:error] [pid 806041:tid 806230] [client 216.73.216.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kevinderarslanian.com"] [uri "/index.php"] [unique_id "amuOz0LAyZ1MRInzPMYF8AAAwFU"]
[Thu Jul 30 12:50:07.946967 2026] [security2:error] [pid 806041:tid 806212] [client 20.151.221.234:23399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/go.php"] [unique_id "amuOz0LAyZ1MRInzPMYF9QAAAK4"]
[Thu Jul 30 12:50:08.485619 2026] [security2:error] [pid 806041:tid 806293] [client 20.151.221.234:43142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/inputs.php"] [unique_id "amuO0ELAyZ1MRInzPMYGAAAAAP8"]
[Thu Jul 30 12:50:08.511656 2026] [security2:error] [pid 806041:tid 806239] [client 20.151.221.234:11950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuO0ELAyZ1MRInzPMYGAQAAAMk"]
[Thu Jul 30 12:50:08.599833 2026] [security2:error] [pid 806041:tid 806283] [client 20.100.187.246:24280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/991176.php"] [unique_id "amuO0ELAyZ1MRInzPMYGCAAAAPU"]
[Thu Jul 30 12:50:08.747058 2026] [security2:error] [pid 806041:tid 806195] [client 4.185.41.66:15734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.j-nintei.com"] [uri "/111.php"] [unique_id "amuO0ELAyZ1MRInzPMYGCgAAAJ0"]
[Thu Jul 30 12:50:08.747176 2026] [security2:error] [pid 806041:tid 806195] [client 4.185.41.66:15734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.j-nintei.com"] [uri "/111.php"] [unique_id "amuO0ELAyZ1MRInzPMYGCgAAAJ0"]
[Thu Jul 30 12:50:09.100582 2026] [security2:error] [pid 806041:tid 806218] [client 20.151.221.234:45016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/test1.php"] [unique_id "amuO0ULAyZ1MRInzPMYGEwAAALQ"]
[Thu Jul 30 12:50:09.448502 2026] [security2:error] [pid 806041:tid 806182] [client 20.151.221.234:11966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-the.php"] [unique_id "amuO0ULAyZ1MRInzPMYGGQAAAJA"]
[Thu Jul 30 12:50:09.548191 2026] [security2:error] [pid 806041:tid 806202] [client 20.151.221.234:50109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/index.php"] [unique_id "amuO0ULAyZ1MRInzPMYGIgAAAKQ"]
[Thu Jul 30 12:50:09.550827 2026] [security2:error] [pid 806041:tid 806296] [client 20.100.187.246:24276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuO0ULAyZ1MRInzPMYGIwAAAQI"]
[Thu Jul 30 12:50:09.886498 2026] [security2:error] [pid 806041:tid 806230] [client 216.244.66.242:53832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingstarenterprises.com"] [uri "/robots.txt"] [unique_id "amuO0ULAyZ1MRInzPMYGLQAAAMA"]
[Thu Jul 30 12:50:09.886678 2026] [security2:error] [pid 806041:tid 806230] [client 216.244.66.242:53832] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kingstarenterprises.com"] [uri "/robots.txt"] [unique_id "amuO0ULAyZ1MRInzPMYGLQAAAMA"]
[Thu Jul 30 12:50:10.179617 2026] [security2:error] [pid 806041:tid 806194] [client 172.202.44.182:45492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/07.php"] [unique_id "amuO0kLAyZ1MRInzPMYGQQAAAJw"]
[Thu Jul 30 12:50:10.393251 2026] [security2:error] [pid 806041:tid 806173] [client 20.151.221.234:50105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuO0kLAyZ1MRInzPMYGRAAAAIc"]
[Thu Jul 30 12:50:10.650653 2026] [security2:error] [pid 806041:tid 806064] [remote 57.141.0.37:34504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuO0kLAyZ1MRInzPMYGTQAAzBY"]
[Thu Jul 30 12:50:11.229594 2026] [security2:error] [pid 806041:tid 806249] [client 172.202.44.182:45464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/dropdown.php"] [unique_id "amuO00LAyZ1MRInzPMYGWAAAANM"]
[Thu Jul 30 12:50:11.245390 2026] [security2:error] [pid 806041:tid 806256] [client 20.151.221.234:43161] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bisbeewalk.com"] [uri "/wp-content/1.php"] [unique_id "amuO00LAyZ1MRInzPMYGXAAAANo"]
[Thu Jul 30 12:50:11.245476 2026] [security2:error] [pid 806041:tid 806256] [client 20.151.221.234:43161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/1.php"] [unique_id "amuO00LAyZ1MRInzPMYGXAAAANo"]
[Thu Jul 30 12:50:11.310271 2026] [security2:error] [pid 806041:tid 806215] [client 20.151.221.234:45032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/images/index.php"] [unique_id "amuO00LAyZ1MRInzPMYGXQAAALE"]
[Thu Jul 30 12:50:12.259255 2026] [security2:error] [pid 806041:tid 806205] [client 136.114.127.127:33752] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.spadealist.com"] [uri "/.git/config"] [unique_id "amuO1ELAyZ1MRInzPMYGeQAAAKc"]
[Thu Jul 30 12:50:12.259375 2026] [security2:error] [pid 806041:tid 806205] [client 136.114.127.127:33752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.spadealist.com"] [uri "/.git/config"] [unique_id "amuO1ELAyZ1MRInzPMYGeQAAAKc"]
[Thu Jul 30 12:50:12.269641 2026] [proxy:error] [pid 806041:tid 806250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:50:12.269704 2026] [proxy_http:error] [pid 806041:tid 806250] [client 136.114.127.127:33778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:50:12.270641 2026] [proxy:error] [pid 806041:tid 806250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:50:12.270702 2026] [proxy_http:error] [pid 806041:tid 806250] [client 136.114.127.127:33778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:50:12.303308 2026] [core:error] [pid 806041:tid 806272] [client 136.114.127.127:33762] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:12.303331 2026] [core:error] [pid 806041:tid 806272] [client 136.114.127.127:33762] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:12.303462 2026] [security2:error] [pid 806041:tid 806272] [client 136.114.127.127:33762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.website-f8c1eb2c.tvs.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuO1ELAyZ1MRInzPMYGewAAAOo"]
[Thu Jul 30 12:50:12.311664 2026] [proxy:error] [pid 806041:tid 806230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:50:12.311747 2026] [proxy_http:error] [pid 806041:tid 806230] [client 136.114.127.127:33794] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:50:12.312325 2026] [proxy:error] [pid 806041:tid 806230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:50:12.312369 2026] [proxy_http:error] [pid 806041:tid 806230] [client 136.114.127.127:33794] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:50:12.329564 2026] [security2:error] [pid 806041:tid 806226] [client 20.100.187.246:6000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuO1ELAyZ1MRInzPMYGfQAAALw"]
[Thu Jul 30 12:50:12.377109 2026] [security2:error] [pid 806041:tid 806178] [client 20.151.221.234:11886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/404.php"] [unique_id "amuO1ELAyZ1MRInzPMYGgQAAAIw"]
[Thu Jul 30 12:50:12.384331 2026] [core:error] [pid 806041:tid 806285] [client 136.114.127.127:33804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:12.384351 2026] [core:error] [pid 806041:tid 806285] [client 136.114.127.127:33804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:12.384459 2026] [security2:error] [pid 806041:tid 806285] [client 136.114.127.127:33804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "spadealist.com"] [uri "/index.php"] [unique_id "amuO1ELAyZ1MRInzPMYGggAAAPc"]
[Thu Jul 30 12:50:12.415903 2026] [security2:error] [pid 806041:tid 806225] [client 172.202.44.182:45495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/makeasmtp.php"] [unique_id "amuO1ELAyZ1MRInzPMYGgwAAALs"]
[Thu Jul 30 12:50:12.480747 2026] [core:notice] [pid 806041:tid 806294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:12.487350 2026] [security2:error] [pid 806041:tid 806294] [client 103.215.74.26:63024] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO1ELAyZ1MRInzPMYGhAAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:12.819529 2026] [autoindex:error] [pid 806041:tid 806289] [client 178.128.82.226:54375] AH01276: Cannot serve directory /home1/nfinyxte/public_html/website_14d99ba9/wp-admin/css/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 12:50:13.222744 2026] [security2:error] [pid 806041:tid 806248] [client 20.151.221.234:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/init.php"] [unique_id "amuO1ULAyZ1MRInzPMYGlwAAANI"]
[Thu Jul 30 12:50:13.998066 2026] [security2:error] [pid 806041:tid 806253] [client 20.151.221.234:2888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/plugin.php"] [unique_id "amuO1ULAyZ1MRInzPMYGrgAAANc"]
[Thu Jul 30 12:50:14.049317 2026] [security2:error] [pid 806041:tid 806252] [client 172.202.44.182:34202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-sigunq.php"] [unique_id "amuO1kLAyZ1MRInzPMYGrwAAANY"]
[Thu Jul 30 12:50:14.115323 2026] [security2:error] [pid 806041:tid 806264] [client 20.151.221.234:55807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/file5.php"] [unique_id "amuO1kLAyZ1MRInzPMYGsAAAAOI"]
[Thu Jul 30 12:50:14.278708 2026] [security2:error] [pid 806041:tid 806238] [client 20.100.187.246:25840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuO1kLAyZ1MRInzPMYGtgAAAMg"]
[Thu Jul 30 12:50:14.545809 2026] [core:notice] [pid 806041:tid 806263] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:15.125731 2026] [security2:error] [pid 806041:tid 806286] [client 20.151.221.234:57715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuO10LAyZ1MRInzPMYGywAAAPg"]
[Thu Jul 30 12:50:15.134214 2026] [security2:error] [pid 806041:tid 806298] [client 20.151.221.234:36703] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bisbeewalk.com"] [uri "/1.php"] [unique_id "amuO10LAyZ1MRInzPMYGzAAAAQQ"]
[Thu Jul 30 12:50:15.134313 2026] [security2:error] [pid 806041:tid 806298] [client 20.151.221.234:36703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/1.php"] [unique_id "amuO10LAyZ1MRInzPMYGzAAAAQQ"]
[Thu Jul 30 12:50:15.218094 2026] [security2:error] [pid 806041:tid 806091] [remote 57.141.0.59:48082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuO10LAyZ1MRInzPMYG0AAA6DE"]
[Thu Jul 30 12:50:15.354246 2026] [security2:error] [pid 806041:tid 806245] [client 172.202.44.182:22530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wso112233.php"] [unique_id "amuO10LAyZ1MRInzPMYG0QAAAM8"]
[Thu Jul 30 12:50:15.430269 2026] [security2:error] [pid 806041:tid 806258] [client 20.151.221.234:45043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/asd.php"] [unique_id "amuO10LAyZ1MRInzPMYG2AAAANw"]
[Thu Jul 30 12:50:15.868379 2026] [security2:error] [pid 806041:tid 806199] [client 150.107.232.194:27034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO10LAyZ1MRInzPMYG4QAAAKE"]
[Thu Jul 30 12:50:15.868496 2026] [security2:error] [pid 806041:tid 806199] [client 150.107.232.194:27034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO10LAyZ1MRInzPMYG4QAAAKE"]
[Thu Jul 30 12:50:16.345379 2026] [security2:error] [pid 806041:tid 806203] [client 20.151.221.234:23416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuO2ELAyZ1MRInzPMYG5wAAAKU"]
[Thu Jul 30 12:50:16.756735 2026] [security2:error] [pid 806041:tid 806194] [client 20.151.221.234:57670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/shell.php"] [unique_id "amuO2ELAyZ1MRInzPMYG7gAAAJw"]
[Thu Jul 30 12:50:16.943744 2026] [security2:error] [pid 806041:tid 806282] [client 172.202.44.182:22561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/alfanew.php"] [unique_id "amuO2ELAyZ1MRInzPMYG-wAAAPQ"]
[Thu Jul 30 12:50:16.959201 2026] [security2:error] [pid 806041:tid 806221] [client 20.151.221.234:50469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/gg.php"] [unique_id "amuO2ELAyZ1MRInzPMYG_AAAALc"]
[Thu Jul 30 12:50:17.613639 2026] [security2:error] [pid 806041:tid 806104] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuO2ULAyZ1MRInzPMYHCQAAwz4"]
[Thu Jul 30 12:50:17.613796 2026] [security2:error] [pid 806041:tid 806233] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuO2ULAyZ1MRInzPMYHCQAAwz4"]
[Thu Jul 30 12:50:17.856292 2026] [core:notice] [pid 806041:tid 806219] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:17.971153 2026] [security2:error] [pid 806041:tid 806298] [client 172.202.44.182:45461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/fw.php"] [unique_id "amuO2ULAyZ1MRInzPMYHEQAAAQQ"]
[Thu Jul 30 12:50:18.188571 2026] [security2:error] [pid 806041:tid 806187] [client 20.100.187.246:25806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuO2kLAyZ1MRInzPMYHFQAAAJU"]
[Thu Jul 30 12:50:18.227018 2026] [core:notice] [pid 806041:tid 806227] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:18.233375 2026] [security2:error] [pid 806041:tid 806227] [client 103.215.74.26:31622] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO2kLAyZ1MRInzPMYHFgAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:18.240793 2026] [core:error] [pid 806041:tid 806245] [client 20.151.221.234:38198] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:18.240822 2026] [core:error] [pid 806041:tid 806245] [client 20.151.221.234:38198] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:18.507105 2026] [security2:error] [pid 806041:tid 806195] [client 20.151.221.234:57695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/f35.php"] [unique_id "amuO2kLAyZ1MRInzPMYHHgAAAJ0"]
[Thu Jul 30 12:50:18.803065 2026] [security2:error] [pid 806041:tid 806280] [client 127.0.0.1:53944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuO2kLAyZ1MRInzPMYHIwAAAPI"]
[Thu Jul 30 12:50:18.803149 2026] [security2:error] [pid 806041:tid 806199] [client 74.7.175.157:40358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amuO2kLAyZ1MRInzPMYHIgAAoUg"]
[Thu Jul 30 12:50:18.957871 2026] [core:notice] [pid 806041:tid 806188] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:18.965297 2026] [security2:error] [pid 806041:tid 806188] [client 103.215.74.26:31638] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO2kLAyZ1MRInzPMYHKQAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:19.029539 2026] [security2:error] [pid 806041:tid 806234] [client 20.151.221.234:50600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuO20LAyZ1MRInzPMYHLgAAAMQ"]
[Thu Jul 30 12:50:19.414246 2026] [security2:error] [pid 806041:tid 806269] [client 20.151.221.234:11936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/new.php"] [unique_id "amuO20LAyZ1MRInzPMYHOAAAAOc"]
[Thu Jul 30 12:50:19.697127 2026] [core:notice] [pid 806041:tid 806282] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:19.703184 2026] [security2:error] [pid 806041:tid 806282] [client 103.215.74.26:31646] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO20LAyZ1MRInzPMYHQQAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:19.760397 2026] [security2:error] [pid 806041:tid 806277] [client 172.202.44.182:22551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-login.php"] [unique_id "amuO20LAyZ1MRInzPMYHOQAAAO8"]
[Thu Jul 30 12:50:19.769341 2026] [security2:error] [pid 806041:tid 806288] [client 20.151.221.234:50454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp.php"] [unique_id "amuO20LAyZ1MRInzPMYHQgAAAPo"]
[Thu Jul 30 12:50:20.193069 2026] [security2:error] [pid 806041:tid 806251] [client 20.151.221.234:57687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/adminfuns.php"] [unique_id "amuO3ELAyZ1MRInzPMYHTgAAANU"]
[Thu Jul 30 12:50:20.361055 2026] [security2:error] [pid 806041:tid 806221] [client 20.151.221.234:22745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/atomlib.php"] [unique_id "amuO3ELAyZ1MRInzPMYHUAAAALc"]
[Thu Jul 30 12:50:20.448035 2026] [core:notice] [pid 806041:tid 806270] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:20.454234 2026] [security2:error] [pid 806041:tid 806270] [client 103.215.74.26:31652] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO3ELAyZ1MRInzPMYHVAAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:20.659493 2026] [security2:error] [pid 806041:tid 806174] [client 20.100.187.246:24319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuO3ELAyZ1MRInzPMYHWgAAAIg"]
[Thu Jul 30 12:50:20.868119 2026] [proxy:error] [pid 806041:tid 806154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:50:20.868177 2026] [proxy_http:error] [pid 806041:tid 806154] [remote 74.7.230.12:40058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:50:20.868739 2026] [proxy:error] [pid 806041:tid 806154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:50:20.868781 2026] [proxy_http:error] [pid 806041:tid 806154] [remote 74.7.230.12:40058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:50:21.051045 2026] [security2:error] [pid 806041:tid 806224] [client 20.151.221.234:38146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuO3ULAyZ1MRInzPMYHYwAAALo"]
[Thu Jul 30 12:50:21.059002 2026] [security2:error] [pid 806041:tid 806227] [client 172.202.44.182:45448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/simple.php"] [unique_id "amuO3ULAyZ1MRInzPMYHZAAAAL0"]
[Thu Jul 30 12:50:21.180029 2026] [core:notice] [pid 806041:tid 806216] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:21.187052 2026] [security2:error] [pid 806041:tid 806216] [client 103.215.74.26:31654] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO3ULAyZ1MRInzPMYHaQAAALI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:21.373792 2026] [security2:error] [pid 806041:tid 806186] [client 20.151.221.234:11840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/fm.php"] [unique_id "amuO3ULAyZ1MRInzPMYHbQAAAJQ"]
[Thu Jul 30 12:50:21.912631 2026] [core:notice] [pid 806041:tid 806194] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:21.918742 2026] [security2:error] [pid 806041:tid 806194] [client 103.215.74.26:31666] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO3ULAyZ1MRInzPMYHegAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:22.300044 2026] [security2:error] [pid 806041:tid 806127] [remote 57.141.0.7:36860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuO3kLAyZ1MRInzPMYHlgAAs1U"]
[Thu Jul 30 12:50:22.415262 2026] [security2:error] [pid 806041:tid 806238] [client 172.202.44.182:23325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/classsmtps.php"] [unique_id "amuO3kLAyZ1MRInzPMYHnwAAAMg"]
[Thu Jul 30 12:50:22.684784 2026] [security2:error] [pid 806041:tid 806290] [client 20.100.187.246:25849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuO3kLAyZ1MRInzPMYHrgAAAPw"]
[Thu Jul 30 12:50:22.787390 2026] [security2:error] [pid 806041:tid 806179] [client 20.151.221.234:11894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/file.php"] [unique_id "amuO3kLAyZ1MRInzPMYHtAAAAI0"]
[Thu Jul 30 12:50:23.329105 2026] [security2:error] [pid 806041:tid 806280] [client 20.100.187.246:5960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuO30LAyZ1MRInzPMYHyAAAAPI"]
[Thu Jul 30 12:50:23.536335 2026] [security2:error] [pid 806041:tid 806175] [client 172.237.109.114:25437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHhQAAAIk"]
[Thu Jul 30 12:50:23.536526 2026] [security2:error] [pid 806041:tid 806242] [client 172.237.109.114:9246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHjAAAAMw"]
[Thu Jul 30 12:50:23.538189 2026] [security2:error] [pid 806041:tid 806268] [client 20.151.221.234:22732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuO30LAyZ1MRInzPMYHywAAAOY"]
[Thu Jul 30 12:50:23.549366 2026] [security2:error] [pid 806041:tid 806225] [client 172.237.109.114:57588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHgQAAALs"]
[Thu Jul 30 12:50:23.553035 2026] [security2:error] [pid 806041:tid 806254] [client 172.237.109.114:1817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHjQAAANg"]
[Thu Jul 30 12:50:23.553035 2026] [security2:error] [pid 806041:tid 806257] [client 172.237.109.114:58798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHgwAAANs"]
[Thu Jul 30 12:50:23.571314 2026] [security2:error] [pid 806041:tid 806269] [client 172.237.109.114:42766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHhAAAAOc"]
[Thu Jul 30 12:50:23.571358 2026] [security2:error] [pid 806041:tid 806220] [client 172.237.109.114:54958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHigAAALY"]
[Thu Jul 30 12:50:23.574130 2026] [security2:error] [pid 806041:tid 806184] [client 172.237.109.114:12216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHiAAAAJI"]
[Thu Jul 30 12:50:23.576675 2026] [security2:error] [pid 806041:tid 806176] [client 172.237.109.114:56342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHiwAAAIo"]
[Thu Jul 30 12:50:23.584896 2026] [security2:error] [pid 806041:tid 806189] [client 172.237.109.114:60100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHjwAAAJc"]
[Thu Jul 30 12:50:23.585568 2026] [security2:error] [pid 806041:tid 806263] [client 172.237.109.114:16010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHjgAAAOE"]
[Thu Jul 30 12:50:23.588899 2026] [security2:error] [pid 806041:tid 806227] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHtwAAAL0"]
[Thu Jul 30 12:50:23.607583 2026] [security2:error] [pid 806041:tid 806226] [client 172.237.109.114:28508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHgAAAALw"]
[Thu Jul 30 12:50:23.610735 2026] [security2:error] [pid 806041:tid 806180] [client 172.237.109.114:51529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHfwAAAI4"]
[Thu Jul 30 12:50:23.617147 2026] [security2:error] [pid 806041:tid 806173] [client 172.237.109.114:28060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHggAAAIc"]
[Thu Jul 30 12:50:23.629655 2026] [security2:error] [pid 806041:tid 806294] [client 172.237.109.114:48977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHiQAAAQA"]
[Thu Jul 30 12:50:23.640457 2026] [security2:error] [pid 806041:tid 806283] [client 172.237.109.114:27726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHhgAAAPU"]
[Thu Jul 30 12:50:23.674174 2026] [security2:error] [pid 806041:tid 806204] [client 74.7.244.28:52722] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.xfy.gzj.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuO30LAyZ1MRInzPMYH0QAAAKY"]
[Thu Jul 30 12:50:23.696440 2026] [security2:error] [pid 806041:tid 806271] [client 172.237.109.114:31625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO3kLAyZ1MRInzPMYHhwAAAOk"]
[Thu Jul 30 12:50:23.915872 2026] [core:notice] [pid 806041:tid 806249] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:24.455174 2026] [security2:error] [pid 806041:tid 806228] [client 172.202.44.182:34187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-blog-header.php"] [unique_id "amuO4ELAyZ1MRInzPMYH5gAAAL4"]
[Thu Jul 30 12:50:24.756012 2026] [security2:error] [pid 806041:tid 806266] [client 49.13.24.81:2760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuO4ELAyZ1MRInzPMYH7gAAAOQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:50:24.815929 2026] [security2:error] [pid 806041:tid 806230] [client 20.151.221.234:65303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/file.php"] [unique_id "amuO4ELAyZ1MRInzPMYH8AAAAMA"]
[Thu Jul 30 12:50:25.122663 2026] [core:notice] [pid 806041:tid 806256] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:25.127223 2026] [security2:error] [pid 806041:tid 806256] [client 49.13.24.81:19664] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO4ULAyZ1MRInzPMYH9wAAANo"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:50:25.523220 2026] [security2:error] [pid 806041:tid 806217] [client 49.13.24.81:19668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuO4ULAyZ1MRInzPMYICQAAALM"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:50:25.646614 2026] [security2:error] [pid 806041:tid 806294] [client 172.237.109.114:13899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO4ULAyZ1MRInzPMYH9QAAAQA"]
[Thu Jul 30 12:50:25.681431 2026] [security2:error] [pid 806041:tid 806267] [client 172.237.109.114:42617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO4ULAyZ1MRInzPMYH-AAAAOU"]
[Thu Jul 30 12:50:25.687096 2026] [security2:error] [pid 806041:tid 806277] [client 172.237.109.114:57580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuO4ULAyZ1MRInzPMYH-QAAAO8"]
[Thu Jul 30 12:50:25.791879 2026] [security2:error] [pid 806041:tid 806233] [client 20.151.221.234:11918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/bolt.php"] [unique_id "amuO4ULAyZ1MRInzPMYIEQAAAMM"]
[Thu Jul 30 12:50:25.799500 2026] [security2:error] [pid 806041:tid 806063] [remote 57.141.0.70:29008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuO4ULAyZ1MRInzPMYIEwABBBU"]
[Thu Jul 30 12:50:25.945003 2026] [security2:error] [pid 806041:tid 806172] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuO4ULAyZ1MRInzPMYIAwAAAIY"]
[Thu Jul 30 12:50:26.066693 2026] [security2:error] [pid 806041:tid 806224] [client 20.100.187.246:6146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuO4kLAyZ1MRInzPMYIGgAAALo"]
[Thu Jul 30 12:50:26.396056 2026] [security2:error] [pid 806041:tid 806240] [client 150.107.232.194:27024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO4kLAyZ1MRInzPMYIHwAAAMo"]
[Thu Jul 30 12:50:26.396208 2026] [security2:error] [pid 806041:tid 806240] [client 150.107.232.194:27024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO4kLAyZ1MRInzPMYIHwAAAMo"]
[Thu Jul 30 12:50:26.673166 2026] [security2:error] [pid 806041:tid 806203] [client 20.151.221.234:55386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/3.php"] [unique_id "amuO4kLAyZ1MRInzPMYIJgAAAKU"]
[Thu Jul 30 12:50:27.524851 2026] [security2:error] [pid 806041:tid 806263] [client 172.202.44.182:23299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-trackback.php"] [unique_id "amuO40LAyZ1MRInzPMYIQgAAAOE"]
[Thu Jul 30 12:50:27.640456 2026] [core:notice] [pid 806041:tid 806275] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:27.646752 2026] [security2:error] [pid 806041:tid 806275] [client 103.215.74.26:16340] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO40LAyZ1MRInzPMYIRgAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:28.158456 2026] [security2:error] [pid 806041:tid 806251] [client 74.7.175.188:37984] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.mediaspawn.com"] [uri "/robots.txt"] [unique_id "amuO5ELAyZ1MRInzPMYIUAAA1TA"]
[Thu Jul 30 12:50:28.305517 2026] [security2:error] [pid 806041:tid 806088] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuO5ELAyZ1MRInzPMYIVQABAi4"]
[Thu Jul 30 12:50:28.305703 2026] [security2:error] [pid 806041:tid 806296] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuO5ELAyZ1MRInzPMYIVQABAi4"]
[Thu Jul 30 12:50:28.392159 2026] [core:notice] [pid 806041:tid 806270] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:28.398916 2026] [security2:error] [pid 806041:tid 806270] [client 103.215.74.26:16352] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO5ELAyZ1MRInzPMYIVwAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:28.933430 2026] [security2:error] [pid 806041:tid 806219] [client 20.151.221.234:34822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/222.php"] [unique_id "amuO5ELAyZ1MRInzPMYIZAAAALU"]
[Thu Jul 30 12:50:29.114070 2026] [core:notice] [pid 806041:tid 806199] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:29.120534 2026] [security2:error] [pid 806041:tid 806199] [client 103.215.74.26:16356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO5ULAyZ1MRInzPMYIcAAAAKE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:29.546705 2026] [security2:error] [pid 806041:tid 806243] [client 20.151.221.234:33854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuO5ULAyZ1MRInzPMYIewAAAM0"]
[Thu Jul 30 12:50:29.709939 2026] [security2:error] [pid 806041:tid 806269] [client 20.100.187.246:6152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuO5ULAyZ1MRInzPMYIhwAAAOc"]
[Thu Jul 30 12:50:29.839286 2026] [security2:error] [pid 806041:tid 806230] [client 213.152.161.170:47318] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO5ULAyZ1MRInzPMYIfAAAAMA"]
[Thu Jul 30 12:50:29.839460 2026] [security2:error] [pid 806041:tid 806230] [client 213.152.161.170:47318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO5ULAyZ1MRInzPMYIfAAAAMA"]
[Thu Jul 30 12:50:29.849336 2026] [core:notice] [pid 806041:tid 806232] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:29.855800 2026] [security2:error] [pid 806041:tid 806232] [client 103.215.74.26:16372] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO5ULAyZ1MRInzPMYIigAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:29.934395 2026] [security2:error] [pid 806041:tid 806226] [client 20.151.221.234:57682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuO5ULAyZ1MRInzPMYIjAAAALw"]
[Thu Jul 30 12:50:30.175611 2026] [core:notice] [pid 806041:tid 806246] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:30.284733 2026] [core:error] [pid 806041:tid 806288] [client 20.151.221.234:38169] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:30.284755 2026] [core:error] [pid 806041:tid 806288] [client 20.151.221.234:38169] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:30.541501 2026] [security2:error] [pid 806041:tid 806251] [client 20.100.187.246:25825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuO5kLAyZ1MRInzPMYIngAAANU"]
[Thu Jul 30 12:50:30.604139 2026] [core:notice] [pid 806041:tid 806290] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:30.610210 2026] [security2:error] [pid 806041:tid 806290] [client 103.215.74.26:16380] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO5kLAyZ1MRInzPMYIpAAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:31.322420 2026] [security2:error] [pid 806041:tid 806174] [client 20.100.187.246:25539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuO50LAyZ1MRInzPMYIsQAAAIg"]
[Thu Jul 30 12:50:31.525125 2026] [security2:error] [pid 806041:tid 806171] [client 172.202.44.182:55436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-signup.php"] [unique_id "amuO50LAyZ1MRInzPMYIsgAAAIU"]
[Thu Jul 30 12:50:31.748270 2026] [security2:error] [pid 806041:tid 806265] [client 20.151.221.234:11846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuO50LAyZ1MRInzPMYIvAAAAOM"]
[Thu Jul 30 12:50:32.599678 2026] [security2:error] [pid 806041:tid 806194] [client 20.100.187.246:6173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuO6ELAyZ1MRInzPMYIzAAAAJw"]
[Thu Jul 30 12:50:32.722654 2026] [security2:error] [pid 806041:tid 806209] [client 20.151.221.234:11888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/admin.php"] [unique_id "amuO6ELAyZ1MRInzPMYI0gAAAKs"]
[Thu Jul 30 12:50:33.397895 2026] [security2:error] [pid 806041:tid 806246] [client 20.100.187.246:6002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuO6ULAyZ1MRInzPMYI4QAAANA"]
[Thu Jul 30 12:50:33.555502 2026] [core:notice] [pid 806041:tid 806290] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:33.896772 2026] [security2:error] [pid 806041:tid 806172] [client 172.202.44.182:22538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-comments-post.php"] [unique_id "amuO6ULAyZ1MRInzPMYI8gAAAIY"]
[Thu Jul 30 12:50:34.186256 2026] [security2:error] [pid 806041:tid 806297] [client 20.151.221.234:55385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-configs.php"] [unique_id "amuO6kLAyZ1MRInzPMYI-QAAAQM"]
[Thu Jul 30 12:50:34.655646 2026] [security2:error] [pid 806041:tid 806241] [client 20.151.221.234:23374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/inputs.php"] [unique_id "amuO6kLAyZ1MRInzPMYJBgAAAMs"]
[Thu Jul 30 12:50:34.942228 2026] [security2:error] [pid 806041:tid 806176] [client 172.202.44.182:23346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-mail.php"] [unique_id "amuO6kLAyZ1MRInzPMYJDQAAAIo"]
[Thu Jul 30 12:50:35.208601 2026] [security2:error] [pid 806041:tid 806232] [client 20.151.221.234:11899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/php.php"] [unique_id "amuO60LAyZ1MRInzPMYJEQAAAMI"]
[Thu Jul 30 12:50:35.402774 2026] [security2:error] [pid 806041:tid 806219] [client 20.100.187.246:25572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuO60LAyZ1MRInzPMYJGwAAALU"]
[Thu Jul 30 12:50:35.668163 2026] [core:error] [pid 806041:tid 806290] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:35.668182 2026] [core:error] [pid 806041:tid 806290] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:35.953253 2026] [security2:error] [pid 806041:tid 806270] [client 172.202.44.182:22536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-activate.php"] [unique_id "amuO60LAyZ1MRInzPMYJMgAAAOg"]
[Thu Jul 30 12:50:36.424137 2026] [core:notice] [pid 806041:tid 806242] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:36.430528 2026] [security2:error] [pid 806041:tid 806242] [client 103.215.74.26:59000] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO7ELAyZ1MRInzPMYJPAAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:36.451125 2026] [security2:error] [pid 806041:tid 806228] [client 20.100.187.246:25834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/bek.php"] [unique_id "amuO7ELAyZ1MRInzPMYJPQAAAL4"]
[Thu Jul 30 12:50:36.632149 2026] [security2:error] [pid 806041:tid 806208] [client 20.151.221.234:23455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/index.php"] [unique_id "amuO7ELAyZ1MRInzPMYJPgAAAKo"]
[Thu Jul 30 12:50:36.886621 2026] [security2:error] [pid 806041:tid 806282] [client 150.107.232.194:27083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO7ELAyZ1MRInzPMYJRQAAAPQ"]
[Thu Jul 30 12:50:36.886714 2026] [security2:error] [pid 806041:tid 806282] [client 150.107.232.194:27083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO7ELAyZ1MRInzPMYJRQAAAPQ"]
[Thu Jul 30 12:50:37.152277 2026] [core:notice] [pid 806041:tid 806194] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:37.158592 2026] [security2:error] [pid 806041:tid 806194] [client 103.215.74.26:59014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO7ULAyZ1MRInzPMYJSgAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:37.204471 2026] [security2:error] [pid 806041:tid 806231] [client 20.151.221.234:38131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuO7ULAyZ1MRInzPMYJSwAAAME"]
[Thu Jul 30 12:50:37.471521 2026] [security2:error] [pid 806041:tid 806188] [client 20.151.221.234:11891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/index.php"] [unique_id "amuO7ULAyZ1MRInzPMYJWAAAAJY"]
[Thu Jul 30 12:50:37.885899 2026] [autoindex:error] [pid 806041:tid 806279] [client 87.236.176.8:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://otbola.click:2086
[Thu Jul 30 12:50:37.896985 2026] [core:notice] [pid 806041:tid 806259] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:37.903424 2026] [security2:error] [pid 806041:tid 806259] [client 103.215.74.26:59016] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO7ULAyZ1MRInzPMYJZQAAAN0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:38.010366 2026] [security2:error] [pid 806041:tid 806214] [client 20.151.221.234:22851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuO7kLAyZ1MRInzPMYJaQAAALA"]
[Thu Jul 30 12:50:38.254802 2026] [security2:error] [pid 806041:tid 806235] [client 20.151.221.234:40939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/a.php"] [unique_id "amuO7kLAyZ1MRInzPMYJawAAAMU"]
[Thu Jul 30 12:50:38.439832 2026] [security2:error] [pid 806041:tid 806177] [client 172.202.44.182:55444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/post.php"] [unique_id "amuO7kLAyZ1MRInzPMYJcgAAAIs"]
[Thu Jul 30 12:50:38.619620 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:38.625883 2026] [security2:error] [pid 806041:tid 806205] [client 103.215.74.26:59032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO7kLAyZ1MRInzPMYJdwAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:39.077243 2026] [security2:error] [pid 806041:tid 806066] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuO70LAyZ1MRInzPMYJggAAqhg"]
[Thu Jul 30 12:50:39.077417 2026] [security2:error] [pid 806041:tid 806208] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuO70LAyZ1MRInzPMYJggAAqhg"]
[Thu Jul 30 12:50:39.347850 2026] [core:notice] [pid 806041:tid 806225] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:39.355671 2026] [security2:error] [pid 806041:tid 806225] [client 103.215.74.26:59036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO70LAyZ1MRInzPMYJgwAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:39.522637 2026] [security2:error] [pid 806041:tid 806252] [client 20.100.187.246:25850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuO70LAyZ1MRInzPMYJjQAAANY"]
[Thu Jul 30 12:50:39.629117 2026] [security2:error] [pid 806041:tid 806192] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuO7kLAyZ1MRInzPMYJgQAAmhs"]
[Thu Jul 30 12:50:40.049279 2026] [security2:error] [pid 806041:tid 806257] [client 20.151.221.234:41211] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/1.php"] [unique_id "amuO8ELAyZ1MRInzPMYJmQAAANs"]
[Thu Jul 30 12:50:40.049400 2026] [security2:error] [pid 806041:tid 806257] [client 20.151.221.234:41211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/1.php"] [unique_id "amuO8ELAyZ1MRInzPMYJmQAAANs"]
[Thu Jul 30 12:50:40.069446 2026] [security2:error] [pid 806041:tid 806200] [client 20.151.221.234:52550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/index/function.php"] [unique_id "amuO8ELAyZ1MRInzPMYJmgAAAKI"]
[Thu Jul 30 12:50:40.093737 2026] [core:notice] [pid 806041:tid 806209] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:40.100422 2026] [security2:error] [pid 806041:tid 806209] [client 103.215.74.26:59048] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO8ELAyZ1MRInzPMYJmwAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:40.135183 2026] [security2:error] [pid 806041:tid 806287] [client 20.151.221.234:40956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuO8ELAyZ1MRInzPMYJnAAAAPk"]
[Thu Jul 30 12:50:40.320097 2026] [security2:error] [pid 806041:tid 806243] [client 172.202.44.182:45452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-2019.php"] [unique_id "amuO8ELAyZ1MRInzPMYJnQAAAM0"]
[Thu Jul 30 12:50:40.757380 2026] [security2:error] [pid 806041:tid 806238] [client 74.7.175.141:44050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ef4503ec.xfy.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuO8ELAyZ1MRInzPMYJpwAAAMg"]
[Thu Jul 30 12:50:40.826831 2026] [core:notice] [pid 806041:tid 806280] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:40.833361 2026] [security2:error] [pid 806041:tid 806280] [client 103.215.74.26:59050] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO8ELAyZ1MRInzPMYJqAAAAPI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:40.911345 2026] [fcgid:warn] [pid 806041:tid 806193] (70014)End of file found: [client 128.1.32.99:38164] mod_fcgid: can't get data from http client
[Thu Jul 30 12:50:41.038176 2026] [security2:error] [pid 806041:tid 806186] [client 20.100.187.246:6154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/class.api.php"] [unique_id "amuO8ULAyZ1MRInzPMYJsAAAAJQ"]
[Thu Jul 30 12:50:41.327570 2026] [security2:error] [pid 806041:tid 806286] [client 20.151.221.234:11898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin.php"] [unique_id "amuO8ULAyZ1MRInzPMYJvgAAAPg"]
[Thu Jul 30 12:50:41.554080 2026] [security2:error] [pid 806041:tid 806222] [client 172.202.44.182:23341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/hoot.php"] [unique_id "amuO8ULAyZ1MRInzPMYJwgAAALg"]
[Thu Jul 30 12:50:41.583712 2026] [core:notice] [pid 806041:tid 806185] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:41.589373 2026] [security2:error] [pid 806041:tid 806185] [client 103.215.74.26:59058] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO8ULAyZ1MRInzPMYJxAAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:42.241565 2026] [security2:error] [pid 806041:tid 806283] [client 20.151.221.234:11866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/size.php"] [unique_id "amuO8kLAyZ1MRInzPMYJ1AAAAPU"]
[Thu Jul 30 12:50:42.294177 2026] [security2:error] [pid 806041:tid 806242] [client 20.100.187.246:6014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/cong.php"] [unique_id "amuO8kLAyZ1MRInzPMYJ1QAAAMw"]
[Thu Jul 30 12:50:42.646949 2026] [security2:error] [pid 806041:tid 806074] [remote 74.7.241.60:44344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amuO8kLAyZ1MRInzPMYJ3wAA0CA"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 12:50:42.652282 2026] [security2:error] [pid 806041:tid 806176] [client 172.202.44.182:45500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/log.php"] [unique_id "amuO8kLAyZ1MRInzPMYJ4AAAAIo"]
[Thu Jul 30 12:50:42.685853 2026] [security2:error] [pid 806041:tid 806085] [remote 57.141.0.62:55706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuO8kLAyZ1MRInzPMYJ4QAAnCs"]
[Thu Jul 30 12:50:42.921647 2026] [security2:error] [pid 806041:tid 806139] [remote 54.39.136.218:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "sharjahfurnituremoversandpackers.space"] [uri "/product-category/air-circulators/"] [unique_id "amuO8kLAyZ1MRInzPMYJ5QAA5WE"]
[Thu Jul 30 12:50:42.921882 2026] [security2:error] [pid 806041:tid 806267] [client 54.39.136.218:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sharjahfurnituremoversandpackers.space"] [uri "/product-category/air-circulators/"] [unique_id "amuO8kLAyZ1MRInzPMYJ5QAA5WE"]
[Thu Jul 30 12:50:43.026885 2026] [security2:error] [pid 806041:tid 806181] [client 20.151.221.234:23442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/plugin.php"] [unique_id "amuO80LAyZ1MRInzPMYJ5gAAAI8"]
[Thu Jul 30 12:50:43.204724 2026] [security2:error] [pid 806041:tid 806209] [client 20.151.221.234:11847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuO80LAyZ1MRInzPMYJ7wAAAKs"]
[Thu Jul 30 12:50:43.297404 2026] [security2:error] [pid 806041:tid 806273] [client 20.100.187.246:25831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/content.php"] [unique_id "amuO80LAyZ1MRInzPMYJ9QAAAOs"]
[Thu Jul 30 12:50:44.634625 2026] [security2:error] [pid 806041:tid 806177] [client 20.151.221.234:11850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/403.php"] [unique_id "amuO9ELAyZ1MRInzPMYKDAAAAIs"]
[Thu Jul 30 12:50:44.989049 2026] [core:error] [pid 806041:tid 806250] [client 20.151.221.234:38084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:44.989087 2026] [core:error] [pid 806041:tid 806250] [client 20.151.221.234:38084] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:45.812419 2026] [security2:error] [pid 806041:tid 806178] [client 20.151.221.234:40180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuO9ULAyZ1MRInzPMYKIAAAAIw"]
[Thu Jul 30 12:50:45.955708 2026] [core:error] [pid 806041:tid 806181] [client 20.151.221.234:51676] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:45.955730 2026] [core:error] [pid 806041:tid 806181] [client 20.151.221.234:51676] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:46.041899 2026] [security2:error] [pid 806041:tid 806192] [client 66.249.66.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuO9ULAyZ1MRInzPMYKIQAAmkc"]
[Thu Jul 30 12:50:46.105742 2026] [security2:error] [pid 806041:tid 806121] [remote 57.141.0.7:55270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuO9kLAyZ1MRInzPMYKLgAAyE8"]
[Thu Jul 30 12:50:46.692183 2026] [security2:error] [pid 806041:tid 806216] [client 20.100.187.246:24278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuO9kLAyZ1MRInzPMYKOgAAALI"]
[Thu Jul 30 12:50:47.048729 2026] [security2:error] [pid 806041:tid 806140] [remote 74.7.241.59:55794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuO90LAyZ1MRInzPMYKRgAAk2I"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/classes
[Thu Jul 30 12:50:47.209043 2026] [core:notice] [pid 806041:tid 806228] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:47.317061 2026] [security2:error] [pid 806041:tid 806217] [client 20.151.221.234:22862] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.laduchessecollections.com"] [uri "/1.php"] [unique_id "amuO90LAyZ1MRInzPMYKSwAAALM"]
[Thu Jul 30 12:50:47.317159 2026] [security2:error] [pid 806041:tid 806217] [client 20.151.221.234:22862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/1.php"] [unique_id "amuO90LAyZ1MRInzPMYKSwAAALM"]
[Thu Jul 30 12:50:47.349186 2026] [core:notice] [pid 806041:tid 806241] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:47.355956 2026] [security2:error] [pid 806041:tid 806241] [client 103.215.74.26:13098] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO90LAyZ1MRInzPMYKTgAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:47.423452 2026] [security2:error] [pid 806041:tid 806242] [client 150.107.232.194:26962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO90LAyZ1MRInzPMYKUwAAAMw"]
[Thu Jul 30 12:50:47.423547 2026] [security2:error] [pid 806041:tid 806242] [client 150.107.232.194:26962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuO90LAyZ1MRInzPMYKUwAAAMw"]
[Thu Jul 30 12:50:47.554965 2026] [security2:error] [pid 806041:tid 806183] [client 20.151.221.234:62191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/aaa.php"] [unique_id "amuO90LAyZ1MRInzPMYKVwAAAJE"]
[Thu Jul 30 12:50:47.725841 2026] [security2:error] [pid 806041:tid 806240] [client 20.151.221.234:55373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/as.php"] [unique_id "amuO90LAyZ1MRInzPMYKWAAAAMo"]
[Thu Jul 30 12:50:48.078653 2026] [core:notice] [pid 806041:tid 806274] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:48.085721 2026] [security2:error] [pid 806041:tid 806274] [client 103.215.74.26:13114] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO-ELAyZ1MRInzPMYKaAAAAOw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:48.108058 2026] [security2:error] [pid 806041:tid 806243] [client 20.100.187.246:24317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/elp.php"] [unique_id "amuO-ELAyZ1MRInzPMYKaQAAAM0"]
[Thu Jul 30 12:50:48.360920 2026] [security2:error] [pid 806041:tid 806293] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuO90LAyZ1MRInzPMYKXAAAAP8"]
[Thu Jul 30 12:50:48.495045 2026] [security2:error] [pid 806041:tid 806279] [client 20.151.221.234:55382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuO-ELAyZ1MRInzPMYKdAAAAPE"]
[Thu Jul 30 12:50:48.816707 2026] [core:notice] [pid 806041:tid 806270] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:48.823144 2026] [security2:error] [pid 806041:tid 806270] [client 103.215.74.26:13122] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO-ELAyZ1MRInzPMYKeAAAAOg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:49.052890 2026] [security2:error] [pid 806041:tid 806158] [remote 93.152.223.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.223.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuO-ULAyZ1MRInzPMYKggAA03Q"]
[Thu Jul 30 12:50:49.111037 2026] [security2:error] [pid 806041:tid 806216] [client 20.100.187.246:25809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuO-ULAyZ1MRInzPMYKgwAAALI"]
[Thu Jul 30 12:50:49.325766 2026] [security2:error] [pid 806041:tid 806251] [client 20.151.221.234:38129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/getid3-core.php"] [unique_id "amuO-ULAyZ1MRInzPMYKhQAAANU"]
[Thu Jul 30 12:50:49.585398 2026] [core:notice] [pid 806041:tid 806254] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:49.591689 2026] [security2:error] [pid 806041:tid 806254] [client 103.215.74.26:13132] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO-ULAyZ1MRInzPMYKkAAAANg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:49.799003 2026] [security2:error] [pid 806041:tid 806184] [client 20.151.221.234:40189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuO-ULAyZ1MRInzPMYKkgAAAJI"]
[Thu Jul 30 12:50:49.842532 2026] [security2:error] [pid 806041:tid 806168] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuO-ULAyZ1MRInzPMYKkwAAqX4"]
[Thu Jul 30 12:50:49.842741 2026] [security2:error] [pid 806041:tid 806207] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuO-ULAyZ1MRInzPMYKkwAAqX4"]
[Thu Jul 30 12:50:50.070001 2026] [security2:error] [pid 806041:tid 806221] [client 20.100.187.246:25574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuO-kLAyZ1MRInzPMYKngAAALc"]
[Thu Jul 30 12:50:50.181796 2026] [security2:error] [pid 806041:tid 806132] [remote 93.152.223.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.223.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amuO-kLAyZ1MRInzPMYKogAA8lo"]
[Thu Jul 30 12:50:50.304400 2026] [core:notice] [pid 806041:tid 806248] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:50.310635 2026] [security2:error] [pid 806041:tid 806248] [client 103.215.74.26:13146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO-kLAyZ1MRInzPMYKowAAANI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:50.499666 2026] [security2:error] [pid 806041:tid 806286] [client 20.151.221.234:11860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/plugins.php"] [unique_id "amuO-kLAyZ1MRInzPMYKpwAAAPg"]
[Thu Jul 30 12:50:50.540380 2026] [security2:error] [pid 806041:tid 806288] [client 20.151.221.234:62151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/adminer.php"] [unique_id "amuO-kLAyZ1MRInzPMYKqwAAAPo"]
[Thu Jul 30 12:50:50.971063 2026] [core:notice] [pid 806041:tid 806047] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:51.036496 2026] [core:notice] [pid 806041:tid 806267] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:51.042271 2026] [security2:error] [pid 806041:tid 806267] [client 103.215.74.26:13158] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO-0LAyZ1MRInzPMYKtQAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:51.078689 2026] [core:notice] [pid 806041:tid 806219] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:51.292846 2026] [security2:error] [pid 806041:tid 806291] [client 172.202.44.182:34223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/bak.php"] [unique_id "amuO-0LAyZ1MRInzPMYKvQAAAP0"]
[Thu Jul 30 12:50:51.308941 2026] [security2:error] [pid 806041:tid 806203] [client 20.151.221.234:40927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuO-0LAyZ1MRInzPMYKvgAAAKU"]
[Thu Jul 30 12:50:51.604787 2026] [security2:error] [pid 806041:tid 806180] [client 74.7.228.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.mbm.udi.temporary.site"] [uri "/___proxy_subdomain_cpanel/cgi-sys/404.html"] [unique_id "amuO-0LAyZ1MRInzPMYKyQAAAI4"]
[Thu Jul 30 12:50:51.605449 2026] [security2:error] [pid 806041:tid 806234] [client 74.7.228.50:40036] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.mbm.udi.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuO-0LAyZ1MRInzPMYKxQAAxBw"]
[Thu Jul 30 12:50:51.777152 2026] [core:notice] [pid 806041:tid 806225] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:51.783420 2026] [security2:error] [pid 806041:tid 806225] [client 103.215.74.26:13172] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO-0LAyZ1MRInzPMYK1AAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:52.060312 2026] [security2:error] [pid 806041:tid 806172] [client 20.100.187.246:6188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuO_ELAyZ1MRInzPMYK1wAAAIY"]
[Thu Jul 30 12:50:52.113178 2026] [security2:error] [pid 806041:tid 806207] [client 20.151.221.234:40158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/go.php"] [unique_id "amuO_ELAyZ1MRInzPMYK2QAAAKk"]
[Thu Jul 30 12:50:52.243006 2026] [security2:error] [pid 806041:tid 806282] [client 66.249.65.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuO-0LAyZ1MRInzPMYKzQAAAPQ"]
[Thu Jul 30 12:50:52.246048 2026] [security2:error] [pid 806041:tid 806258] [client 172.202.44.182:34224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/content.php"] [unique_id "amuO_ELAyZ1MRInzPMYK5gAAANw"]
[Thu Jul 30 12:50:52.513787 2026] [core:notice] [pid 806041:tid 806238] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:52.520026 2026] [security2:error] [pid 806041:tid 806238] [client 103.215.74.26:13180] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO_ELAyZ1MRInzPMYK7AAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:52.754243 2026] [security2:error] [pid 806041:tid 806276] [client 20.100.187.246:5979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuO_ELAyZ1MRInzPMYK9gAAAO4"]
[Thu Jul 30 12:50:52.788828 2026] [core:error] [pid 806041:tid 806270] [client 20.151.221.234:62178] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:52.788850 2026] [core:error] [pid 806041:tid 806270] [client 20.151.221.234:62178] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:52.810379 2026] [core:notice] [pid 806041:tid 806057] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:52.822591 2026] [security2:error] [pid 806041:tid 806204] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuO_ELAyZ1MRInzPMYK5wAAAKY"]
[Thu Jul 30 12:50:52.978914 2026] [security2:error] [pid 806041:tid 806293] [client 20.151.221.234:58101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/gg.php"] [unique_id "amuO_ELAyZ1MRInzPMYK-QAAAP8"]
[Thu Jul 30 12:50:53.238310 2026] [core:notice] [pid 806041:tid 806291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:53.244625 2026] [security2:error] [pid 806041:tid 806291] [client 103.215.74.26:28564] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO_ULAyZ1MRInzPMYLAAAAAP0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:53.481480 2026] [security2:error] [pid 806041:tid 806252] [client 20.151.221.234:40176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/test1.php"] [unique_id "amuO_ULAyZ1MRInzPMYLCAAAANY"]
[Thu Jul 30 12:50:53.964409 2026] [security2:error] [pid 806041:tid 806183] [client 172.202.44.182:45467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/upfile.php"] [unique_id "amuO_ULAyZ1MRInzPMYLEwAAAJE"]
[Thu Jul 30 12:50:53.992208 2026] [core:notice] [pid 806041:tid 806194] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:53.998770 2026] [security2:error] [pid 806041:tid 806194] [client 103.215.74.26:28572] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO_ULAyZ1MRInzPMYLFAAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:54.038771 2026] [security2:error] [pid 806041:tid 806196] [client 20.100.187.246:6148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuO_kLAyZ1MRInzPMYLFQAAAJ4"]
[Thu Jul 30 12:50:54.590536 2026] [security2:error] [pid 806041:tid 806226] [client 20.151.221.234:33811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/alfa.php"] [unique_id "amuO_kLAyZ1MRInzPMYLJAAAALw"]
[Thu Jul 30 12:50:54.717212 2026] [core:notice] [pid 806041:tid 806275] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:54.724031 2026] [security2:error] [pid 806041:tid 806275] [client 103.215.74.26:28580] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO_kLAyZ1MRInzPMYLKAAAAO0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:54.884342 2026] [security2:error] [pid 806041:tid 806290] [client 172.202.44.182:45450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/bypass.php"] [unique_id "amuO_kLAyZ1MRInzPMYLLwAAAPw"]
[Thu Jul 30 12:50:55.152694 2026] [security2:error] [pid 806041:tid 806084] [remote 57.141.0.53:44216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap13.xml"] [unique_id "amuO_0LAyZ1MRInzPMYLNQAA5io"]
[Thu Jul 30 12:50:55.453641 2026] [core:notice] [pid 806041:tid 806265] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:55.459920 2026] [security2:error] [pid 806041:tid 806265] [client 103.215.74.26:28582] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuO_0LAyZ1MRInzPMYLPwAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:55.935897 2026] [security2:error] [pid 806041:tid 806073] [remote 57.141.0.19:24036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuO_0LAyZ1MRInzPMYLSwAA2R8"]
[Thu Jul 30 12:50:56.007290 2026] [core:error] [pid 806041:tid 806201] [client 20.151.221.234:51699] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:56.007320 2026] [core:error] [pid 806041:tid 806201] [client 20.151.221.234:51699] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:50:56.078137 2026] [security2:error] [pid 806041:tid 806285] [client 20.151.221.234:40142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/images/index.php"] [unique_id "amuPAELAyZ1MRInzPMYLTQAAAPc"]
[Thu Jul 30 12:50:56.198374 2026] [core:notice] [pid 806041:tid 806172] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:56.204750 2026] [security2:error] [pid 806041:tid 806172] [client 103.215.74.26:28598] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPAELAyZ1MRInzPMYLTgAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:56.870120 2026] [security2:error] [pid 806041:tid 806214] [client 20.151.221.234:51656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuPAELAyZ1MRInzPMYLYgAAALA"]
[Thu Jul 30 12:50:56.954512 2026] [core:notice] [pid 806041:tid 806218] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:50:56.960502 2026] [security2:error] [pid 806041:tid 806218] [client 103.215.74.26:28610] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPAELAyZ1MRInzPMYLZgAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:50:57.674482 2026] [security2:error] [pid 806041:tid 806204] [client 20.151.221.234:62149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuPAULAyZ1MRInzPMYLcwAAAKY"]
[Thu Jul 30 12:50:57.885456 2026] [security2:error] [pid 806041:tid 806292] [client 150.107.232.194:27517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPAULAyZ1MRInzPMYLeAAAAP4"]
[Thu Jul 30 12:50:57.885568 2026] [security2:error] [pid 806041:tid 806292] [client 150.107.232.194:27517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPAULAyZ1MRInzPMYLeAAAAP4"]
[Thu Jul 30 12:50:58.498456 2026] [security2:error] [pid 806041:tid 806255] [client 20.151.221.234:38717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/asd.php"] [unique_id "amuPAkLAyZ1MRInzPMYLiAAAANk"]
[Thu Jul 30 12:50:58.530034 2026] [security2:error] [pid 806041:tid 806182] [client 172.202.44.182:45468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/updates.php"] [unique_id "amuPAkLAyZ1MRInzPMYLjAAAAJA"]
[Thu Jul 30 12:50:59.001893 2026] [security2:error] [pid 806041:tid 806184] [client 20.100.187.246:6171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuPA0LAyZ1MRInzPMYLlwAAAJI"]
[Thu Jul 30 12:50:59.412014 2026] [security2:error] [pid 806041:tid 806259] [client 20.151.221.234:52584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuPA0LAyZ1MRInzPMYLmgAAAN0"]
[Thu Jul 30 12:50:59.457000 2026] [security2:error] [pid 806041:tid 806280] [client 20.151.221.234:38683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuPA0LAyZ1MRInzPMYLngAAAPI"]
[Thu Jul 30 12:51:00.686724 2026] [security2:error] [pid 806041:tid 806117] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPBELAyZ1MRInzPMYLuwAA_Us"]
[Thu Jul 30 12:51:00.686866 2026] [security2:error] [pid 806041:tid 806291] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPBELAyZ1MRInzPMYLuwAA_Us"]
[Thu Jul 30 12:51:01.245474 2026] [core:error] [pid 806041:tid 806240] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.245496 2026] [core:error] [pid 806041:tid 806240] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.248960 2026] [core:error] [pid 806041:tid 806287] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.248986 2026] [core:error] [pid 806041:tid 806287] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.256118 2026] [core:error] [pid 806041:tid 806295] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.256135 2026] [core:error] [pid 806041:tid 806295] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.282724 2026] [core:error] [pid 806041:tid 806196] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.282740 2026] [core:error] [pid 806041:tid 806196] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.354646 2026] [core:error] [pid 806041:tid 806210] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.354673 2026] [core:error] [pid 806041:tid 806210] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:01.370264 2026] [security2:error] [pid 806041:tid 806251] [client 20.100.187.246:27926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuPBULAyZ1MRInzPMYL4AAAANU"]
[Thu Jul 30 12:51:01.578590 2026] [security2:error] [pid 806041:tid 806271] [client 20.151.221.234:51649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/edit.php"] [unique_id "amuPBULAyZ1MRInzPMYL5AAAAOk"]
[Thu Jul 30 12:51:02.023242 2026] [core:notice] [pid 806041:tid 806247] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:02.189283 2026] [security2:error] [pid 806041:tid 806224] [client 20.151.221.234:11752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuPBkLAyZ1MRInzPMYL9wAAALo"]
[Thu Jul 30 12:51:02.217091 2026] [security2:error] [pid 806041:tid 806297] [client 47.128.121.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuPBkLAyZ1MRInzPMYL8wAAAQM"]
[Thu Jul 30 12:51:02.700501 2026] [core:notice] [pid 806041:tid 806229] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:02.706973 2026] [security2:error] [pid 806041:tid 806229] [client 103.215.74.26:28616] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPBkLAyZ1MRInzPMYMBwAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:02.714623 2026] [security2:error] [pid 806041:tid 806206] [client 20.100.187.246:6166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuPBkLAyZ1MRInzPMYMCgAAAKg"]
[Thu Jul 30 12:51:03.166768 2026] [core:notice] [pid 806041:tid 806217] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:03.263826 2026] [security2:error] [pid 806041:tid 806240] [client 20.151.221.234:23016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp.php"] [unique_id "amuPB0LAyZ1MRInzPMYMFAAAAMo"]
[Thu Jul 30 12:51:03.425877 2026] [core:notice] [pid 806041:tid 806254] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:03.432317 2026] [security2:error] [pid 806041:tid 806254] [client 103.215.74.26:44938] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPB0LAyZ1MRInzPMYMGgAAANg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:03.734359 2026] [core:error] [pid 806041:tid 806171] [client 20.151.221.234:52579] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:03.734384 2026] [core:error] [pid 806041:tid 806171] [client 20.151.221.234:52579] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:04.188088 2026] [security2:error] [pid 806041:tid 806257] [client 20.151.221.234:52723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/atomlib.php"] [unique_id "amuPCELAyZ1MRInzPMYMLQAAANs"]
[Thu Jul 30 12:51:04.188680 2026] [core:notice] [pid 806041:tid 806218] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:04.194907 2026] [security2:error] [pid 806041:tid 806218] [client 103.215.74.26:44948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPCELAyZ1MRInzPMYMLAAAALQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:04.244435 2026] [security2:error] [pid 806041:tid 806125] [remote 57.141.0.11:35714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/56555984686/feed/rss2/"] [unique_id "amuPCELAyZ1MRInzPMYMLgAAnFM"]
[Thu Jul 30 12:51:04.910442 2026] [core:notice] [pid 806041:tid 806279] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:04.916681 2026] [security2:error] [pid 806041:tid 806279] [client 103.215.74.26:44956] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPCELAyZ1MRInzPMYMPAAAAPE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:05.598066 2026] [core:error] [pid 806041:tid 806232] [client 20.151.221.234:51662] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:05.598087 2026] [core:error] [pid 806041:tid 806232] [client 20.151.221.234:51662] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:05.644819 2026] [core:notice] [pid 806041:tid 806213] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:05.650944 2026] [security2:error] [pid 806041:tid 806213] [client 103.215.74.26:44972] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPCULAyZ1MRInzPMYMTAAAAK8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:06.069500 2026] [security2:error] [pid 806041:tid 806047] [remote 103.164.173.46:41020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.173.164.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amuPCkLAyZ1MRInzPMYMWAAA1gU"]
[Thu Jul 30 12:51:06.302582 2026] [core:notice] [pid 806041:tid 806253] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:06.378130 2026] [core:notice] [pid 806041:tid 806233] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:06.384615 2026] [security2:error] [pid 806041:tid 806233] [client 103.215.74.26:44976] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPCkLAyZ1MRInzPMYMXgAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:06.423821 2026] [security2:error] [pid 806041:tid 806214] [client 20.151.221.234:40129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuPCkLAyZ1MRInzPMYMYgAAALA"]
[Thu Jul 30 12:51:06.426788 2026] [security2:error] [pid 806041:tid 806251] [client 20.151.221.234:51693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/sf.php"] [unique_id "amuPCkLAyZ1MRInzPMYMYwAAANU"]
[Thu Jul 30 12:51:06.882405 2026] [security2:error] [pid 806041:tid 806280] [client 20.100.187.246:25919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuPCkLAyZ1MRInzPMYMcQAAAPI"]
[Thu Jul 30 12:51:07.107602 2026] [core:notice] [pid 806041:tid 806222] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:07.113869 2026] [security2:error] [pid 806041:tid 806222] [client 103.215.74.26:44978] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPC0LAyZ1MRInzPMYMewAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:07.338427 2026] [security2:error] [pid 806041:tid 806266] [client 198.44.157.146:60670] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuPC0LAyZ1MRInzPMYMeQAAAOQ"]
[Thu Jul 30 12:51:07.338559 2026] [security2:error] [pid 806041:tid 806266] [client 198.44.157.146:60670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuPC0LAyZ1MRInzPMYMeQAAAOQ"]
[Thu Jul 30 12:51:07.375692 2026] [core:error] [pid 806041:tid 806203] [client 20.151.221.234:38118] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:07.375717 2026] [core:error] [pid 806041:tid 806203] [client 20.151.221.234:38118] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:07.857061 2026] [core:notice] [pid 806041:tid 806207] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:07.863576 2026] [security2:error] [pid 806041:tid 806207] [client 103.215.74.26:44986] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPC0LAyZ1MRInzPMYMiwAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:07.863732 2026] [security2:error] [pid 806041:tid 806216] [client 20.100.187.246:25886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuPC0LAyZ1MRInzPMYMjAAAALI"]
[Thu Jul 30 12:51:08.158860 2026] [security2:error] [pid 806041:tid 806285] [client 20.151.221.234:58054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuPDELAyZ1MRInzPMYMlwAAAPc"]
[Thu Jul 30 12:51:08.290574 2026] [security2:error] [pid 806041:tid 806172] [client 20.151.221.234:2971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wso.php"] [unique_id "amuPDELAyZ1MRInzPMYMnQAAAIY"]
[Thu Jul 30 12:51:08.362119 2026] [security2:error] [pid 806041:tid 806275] [client 150.107.232.194:27355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPDELAyZ1MRInzPMYMngAAAO0"]
[Thu Jul 30 12:51:08.362245 2026] [security2:error] [pid 806041:tid 806275] [client 150.107.232.194:27355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPDELAyZ1MRInzPMYMngAAAO0"]
[Thu Jul 30 12:51:08.482339 2026] [security2:error] [pid 806041:tid 806239] [client 20.100.187.246:24282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuPDELAyZ1MRInzPMYMogAAAMk"]
[Thu Jul 30 12:51:08.613710 2026] [core:notice] [pid 806041:tid 806277] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:08.620110 2026] [security2:error] [pid 806041:tid 806277] [client 103.215.74.26:45000] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPDELAyZ1MRInzPMYMqAAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:08.810288 2026] [security2:error] [pid 806041:tid 806296] [client 20.151.221.234:11736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/inputs.php"] [unique_id "amuPDELAyZ1MRInzPMYMrQAAAQI"]
[Thu Jul 30 12:51:09.281468 2026] [security2:error] [pid 806041:tid 806228] [client 20.151.221.234:38095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/ioxi-o.php"] [unique_id "amuPDULAyZ1MRInzPMYMwAAAAL4"]
[Thu Jul 30 12:51:09.294442 2026] [security2:error] [pid 806041:tid 806203] [client 20.100.187.246:5639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuPDULAyZ1MRInzPMYMwQAAAKU"]
[Thu Jul 30 12:51:09.351249 2026] [core:notice] [pid 806041:tid 806185] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:09.357426 2026] [security2:error] [pid 806041:tid 806185] [client 103.215.74.26:45004] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPDULAyZ1MRInzPMYMxQAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:10.096805 2026] [core:notice] [pid 806041:tid 806265] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:10.102989 2026] [security2:error] [pid 806041:tid 806265] [client 103.215.74.26:45018] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPDkLAyZ1MRInzPMYM2gAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:10.132322 2026] [security2:error] [pid 806041:tid 806192] [client 20.151.221.234:51688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/file56.php"] [unique_id "amuPDkLAyZ1MRInzPMYM2wAAAJo"]
[Thu Jul 30 12:51:10.592229 2026] [security2:error] [pid 806041:tid 806184] [client 20.151.221.234:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/index.php"] [unique_id "amuPDkLAyZ1MRInzPMYM5QAAAJI"]
[Thu Jul 30 12:51:10.696110 2026] [security2:error] [pid 806041:tid 806259] [client 43.157.191.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPDkLAyZ1MRInzPMYM2QAA3So"]
[Thu Jul 30 12:51:10.840900 2026] [core:notice] [pid 806041:tid 806263] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:10.847391 2026] [security2:error] [pid 806041:tid 806263] [client 103.215.74.26:45026] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPDkLAyZ1MRInzPMYM6gAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:10.974276 2026] [security2:error] [pid 806041:tid 806288] [client 20.100.187.246:25548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuPDkLAyZ1MRInzPMYM8AAAAPo"]
[Thu Jul 30 12:51:11.064804 2026] [security2:error] [pid 806041:tid 806242] [client 20.151.221.234:61303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/file.php"] [unique_id "amuPD0LAyZ1MRInzPMYM9AAAAMw"]
[Thu Jul 30 12:51:11.313019 2026] [security2:error] [pid 806041:tid 806099] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPD0LAyZ1MRInzPMYNBQAAjzk"]
[Thu Jul 30 12:51:11.313213 2026] [security2:error] [pid 806041:tid 806181] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPD0LAyZ1MRInzPMYNBQAAjzk"]
[Thu Jul 30 12:51:11.377946 2026] [security2:error] [pid 806041:tid 806173] [client 34.139.111.28:61047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuPD0LAyZ1MRInzPMYNBgAAAIc"]
[Thu Jul 30 12:51:11.571381 2026] [security2:error] [pid 806041:tid 806176] [client 20.151.221.234:11570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuPD0LAyZ1MRInzPMYNCgAAAIo"]
[Thu Jul 30 12:51:11.597154 2026] [core:notice] [pid 806041:tid 806252] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:11.603498 2026] [security2:error] [pid 806041:tid 806252] [client 103.215.74.26:45038] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPD0LAyZ1MRInzPMYNDAAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:11.606517 2026] [security2:error] [pid 806041:tid 806190] [client 20.100.187.246:25598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuPD0LAyZ1MRInzPMYNDgAAAJg"]
[Thu Jul 30 12:51:12.230520 2026] [security2:error] [pid 806041:tid 806183] [client 20.151.221.234:23012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuPEELAyZ1MRInzPMYNHQAAAJE"]
[Thu Jul 30 12:51:12.386711 2026] [security2:error] [pid 806041:tid 806234] [client 20.100.187.246:24283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuPEELAyZ1MRInzPMYNHwAAAMQ"]
[Thu Jul 30 12:51:12.428035 2026] [security2:error] [pid 806041:tid 806250] [client 34.139.111.28:63344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.111.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stunningtouchcleaning.com"] [uri "/xmlrpc.php"] [unique_id "amuPEELAyZ1MRInzPMYNIAAAANQ"]
[Thu Jul 30 12:51:12.608492 2026] [security2:error] [pid 806041:tid 806172] [client 20.151.221.234:2992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuPEELAyZ1MRInzPMYNJwAAAIY"]
[Thu Jul 30 12:51:13.053089 2026] [security2:error] [pid 806041:tid 806279] [client 20.100.187.246:25549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuPEULAyZ1MRInzPMYNMwAAAPE"]
[Thu Jul 30 12:51:13.395409 2026] [security2:error] [pid 806041:tid 806103] [remote 57.141.0.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuPEULAyZ1MRInzPMYNPgAAzj0"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,linen,lycra,steel,wood&filter_size=extra-extra-large,extra-large,small&tax_product_cat=suit&unfilter=1
[Thu Jul 30 12:51:13.467673 2026] [security2:error] [pid 806041:tid 806293] [client 20.151.221.234:52689] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bookario.com"] [uri "/wp-content/1.php"] [unique_id "amuPEULAyZ1MRInzPMYNQAAAAP8"]
[Thu Jul 30 12:51:13.467800 2026] [security2:error] [pid 806041:tid 806293] [client 20.151.221.234:52689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/1.php"] [unique_id "amuPEULAyZ1MRInzPMYNQAAAAP8"]
[Thu Jul 30 12:51:13.478084 2026] [security2:error] [pid 806041:tid 806193] [client 34.139.111.28:54889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuPEULAyZ1MRInzPMYNQQAAAJs"]
[Thu Jul 30 12:51:13.501921 2026] [security2:error] [pid 806041:tid 806133] [remote 57.141.0.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuPEULAyZ1MRInzPMYNQwAAjFs"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,linen,lycra,steel,wood&filter_size=extra-extra-large,extra-large,small&tax_product_cat=suit&unfilter=1
[Thu Jul 30 12:51:13.952032 2026] [security2:error] [pid 806041:tid 806275] [client 140.245.34.60:54426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "deltaedu.net"] [uri "/wp-json/batch/v1"] [unique_id "amuPEULAyZ1MRInzPMYNTQAAAO0"]
[Thu Jul 30 12:51:13.956453 2026] [security2:error] [pid 806041:tid 806265] [client 45.205.1.124:55122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/bitrix/css/main/themes/0x1.php"] [unique_id "amuPEULAyZ1MRInzPMYNTgAAAOM"]
[Thu Jul 30 12:51:14.067694 2026] [security2:error] [pid 806041:tid 806271] [client 140.245.34.60:54426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuPEkLAyZ1MRInzPMYNUgAAAOk"]
[Thu Jul 30 12:51:14.296751 2026] [security2:error] [pid 806041:tid 806239] [client 20.151.221.234:51679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuPEkLAyZ1MRInzPMYNVgAAAMk"]
[Thu Jul 30 12:51:14.305198 2026] [security2:error] [pid 806041:tid 806226] [client 20.151.221.234:52685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/plugin.php"] [unique_id "amuPEkLAyZ1MRInzPMYNVwAAALw"]
[Thu Jul 30 12:51:14.491279 2026] [security2:error] [pid 806041:tid 806200] [client 20.151.221.234:23021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuPEkLAyZ1MRInzPMYNWwAAAKI"]
[Thu Jul 30 12:51:14.530789 2026] [security2:error] [pid 806041:tid 806283] [client 34.139.111.28:64806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuPEkLAyZ1MRInzPMYNXAAAAPU"]
[Thu Jul 30 12:51:14.556505 2026] [security2:error] [pid 806041:tid 806291] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPEULAyZ1MRInzPMYNPAAA_T8"], referer: https://allmontecristi.com/5-important-characteristics-to-identify-an-export-panama-hat/?srsltid=afmbooobpjslvy1dcritpm3oyoloutbopk2q0t238sboel09-jvs0f2z
[Thu Jul 30 12:51:14.985853 2026] [security2:error] [pid 806041:tid 806191] [client 172.213.232.128:33478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/--wp-lgj.php"] [unique_id "amuPEkLAyZ1MRInzPMYNZwAAAJk"]
[Thu Jul 30 12:51:15.092105 2026] [security2:error] [pid 806041:tid 806143] [remote 5.161.62.209:6672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dhowcruisedinner.com.khw.nyx.temporary.site"] [uri "/.env"] [unique_id "amuPE0LAyZ1MRInzPMYNaAAA4mU"]
[Thu Jul 30 12:51:15.092751 2026] [security2:error] [pid 806041:tid 806269] [client 20.151.221.234:2101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/edit.php"] [unique_id "amuPE0LAyZ1MRInzPMYNaQAAAOc"]
[Thu Jul 30 12:51:15.093566 2026] [security2:error] [pid 806041:tid 806124] [remote 5.161.62.209:6670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dhowcruisedinner.com"] [uri "/.env"] [unique_id "amuPE0LAyZ1MRInzPMYNagAAkFI"]
[Thu Jul 30 12:51:15.366372 2026] [security2:error] [pid 806041:tid 806146] [remote 47.128.27.73:48684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-retro-high-og-chenille/"] [unique_id "amuPE0LAyZ1MRInzPMYNcgAAr2g"]
[Thu Jul 30 12:51:15.570625 2026] [security2:error] [pid 806041:tid 806205] [client 34.139.111.28:54178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuPE0LAyZ1MRInzPMYNdwAAAKc"]
[Thu Jul 30 12:51:15.854796 2026] [security2:error] [pid 806041:tid 806248] [client 172.213.232.128:16983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuPE0LAyZ1MRInzPMYNgAAAANI"]
[Thu Jul 30 12:51:15.878002 2026] [security2:error] [pid 806041:tid 806189] [client 20.151.221.234:11722] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bookario.com"] [uri "/1.php"] [unique_id "amuPE0LAyZ1MRInzPMYNgQAAAJc"]
[Thu Jul 30 12:51:15.878104 2026] [security2:error] [pid 806041:tid 806189] [client 20.151.221.234:11722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/1.php"] [unique_id "amuPE0LAyZ1MRInzPMYNgQAAAJc"]
[Thu Jul 30 12:51:15.935855 2026] [security2:error] [pid 806041:tid 806240] [client 185.231.155.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPE0LAyZ1MRInzPMYNcwAAylc"], referer: https://allmontecristi.com/contact/
[Thu Jul 30 12:51:16.057609 2026] [security2:error] [pid 806041:tid 806231] [client 20.151.221.234:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/index/function.php"] [unique_id "amuPFELAyZ1MRInzPMYNhQAAAME"]
[Thu Jul 30 12:51:16.118038 2026] [autoindex:error] [pid 806041:tid 806186] [client 141.148.153.213:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:51:16.604250 2026] [security2:error] [pid 806041:tid 806271] [client 34.139.111.28:58245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuPFELAyZ1MRInzPMYNkwAAAOk"]
[Thu Jul 30 12:51:16.792921 2026] [security2:error] [pid 806041:tid 806296] [client 47.128.98.102:61876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amuPFELAyZ1MRInzPMYNmAAAAQI"]
[Thu Jul 30 12:51:16.922220 2026] [security2:error] [pid 806041:tid 806238] [client 172.213.232.128:33505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/flower.php"] [unique_id "amuPFELAyZ1MRInzPMYNnAAAAMg"]
[Thu Jul 30 12:51:17.055912 2026] [security2:error] [pid 806041:tid 806198] [client 20.151.221.234:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/gg.php"] [unique_id "amuPFULAyZ1MRInzPMYNnwAAAKA"]
[Thu Jul 30 12:51:17.116061 2026] [security2:error] [pid 806041:tid 806242] [client 20.151.221.234:52545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/2.php"] [unique_id "amuPFULAyZ1MRInzPMYNoQAAAMw"]
[Thu Jul 30 12:51:17.258041 2026] [security2:error] [pid 806041:tid 806211] [client 20.100.187.246:25546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuPFULAyZ1MRInzPMYNpwAAAK0"]
[Thu Jul 30 12:51:17.324123 2026] [core:notice] [pid 806041:tid 806194] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:17.330368 2026] [security2:error] [pid 806041:tid 806194] [client 103.215.74.26:43896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPFULAyZ1MRInzPMYNqQAAAJw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:17.538759 2026] [security2:error] [pid 806041:tid 806147] [remote 47.128.112.35:60308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pkf.jo"] [uri "/robots.txt"] [unique_id "amuPFULAyZ1MRInzPMYNrgAA5Gk"]
[Thu Jul 30 12:51:17.647091 2026] [core:notice] [pid 806041:tid 806182] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:17.652648 2026] [security2:error] [pid 806041:tid 806207] [client 172.213.232.128:35679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/xleet.php"] [unique_id "amuPFULAyZ1MRInzPMYNswAAAKk"]
[Thu Jul 30 12:51:17.656950 2026] [security2:error] [pid 806041:tid 806229] [client 34.139.111.28:58076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuPFULAyZ1MRInzPMYNtAAAAL8"]
[Thu Jul 30 12:51:18.032967 2026] [security2:error] [pid 806041:tid 806230] [client 20.100.187.246:5632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuPFkLAyZ1MRInzPMYNvAAAAMA"]
[Thu Jul 30 12:51:18.054536 2026] [core:notice] [pid 806041:tid 806272] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:18.061059 2026] [security2:error] [pid 806041:tid 806272] [client 103.215.74.26:43900] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPFkLAyZ1MRInzPMYNvwAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:18.069630 2026] [security2:error] [pid 806041:tid 806263] [client 20.151.221.234:2968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuPFkLAyZ1MRInzPMYNwgAAAOE"]
[Thu Jul 30 12:51:18.285964 2026] [security2:error] [pid 806041:tid 806273] [client 20.151.221.234:11551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp.php"] [unique_id "amuPFkLAyZ1MRInzPMYNxQAAAOs"]
[Thu Jul 30 12:51:18.748535 2026] [security2:error] [pid 806041:tid 806251] [client 34.139.111.28:58710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuPFkLAyZ1MRInzPMYN0QAAANU"]
[Thu Jul 30 12:51:18.785560 2026] [core:notice] [pid 806041:tid 806277] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:18.791835 2026] [security2:error] [pid 806041:tid 806277] [client 103.215.74.26:43904] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPFkLAyZ1MRInzPMYN0gAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:18.825516 2026] [security2:error] [pid 806041:tid 806280] [client 150.107.232.194:26920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPFkLAyZ1MRInzPMYN1wAAAPI"]
[Thu Jul 30 12:51:18.825622 2026] [security2:error] [pid 806041:tid 806280] [client 150.107.232.194:26920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPFkLAyZ1MRInzPMYN1wAAAPI"]
[Thu Jul 30 12:51:19.376656 2026] [security2:error] [pid 806041:tid 806284] [client 20.151.221.234:43601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/mah.php"] [unique_id "amuPF0LAyZ1MRInzPMYN4QAAAPY"]
[Thu Jul 30 12:51:19.434762 2026] [core:notice] [pid 806041:tid 806242] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:19.466094 2026] [security2:error] [pid 806041:tid 806204] [client 172.213.232.128:48700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuPF0LAyZ1MRInzPMYN5wAAAKY"]
[Thu Jul 30 12:51:19.512588 2026] [core:notice] [pid 806041:tid 806232] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:19.518893 2026] [security2:error] [pid 806041:tid 806232] [client 103.215.74.26:43916] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPF0LAyZ1MRInzPMYN6AAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:19.601897 2026] [security2:error] [pid 806041:tid 806180] [client 20.151.221.234:52683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuPF0LAyZ1MRInzPMYN6QAAAI4"]
[Thu Jul 30 12:51:19.778170 2026] [security2:error] [pid 806041:tid 806222] [client 57.141.0.58:56440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuPF0LAyZ1MRInzPMYN5AAAuAg"], referer: https://igetvape-australia.com/store/?product-page=9&add-to-cart=201
[Thu Jul 30 12:51:19.834095 2026] [security2:error] [pid 806041:tid 806212] [client 34.139.111.28:51808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuPF0LAyZ1MRInzPMYN8wAAAK4"]
[Thu Jul 30 12:51:20.215853 2026] [security2:error] [pid 806041:tid 806189] [client 172.213.232.128:41404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuPGELAyZ1MRInzPMYN_AAAAJc"]
[Thu Jul 30 12:51:20.240032 2026] [core:notice] [pid 806041:tid 806255] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:20.245951 2026] [security2:error] [pid 806041:tid 806255] [client 103.215.74.26:43932] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPGELAyZ1MRInzPMYN_gAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:20.879615 2026] [security2:error] [pid 806041:tid 806252] [client 34.139.111.28:57691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuPGELAyZ1MRInzPMYOCAAAANY"]
[Thu Jul 30 12:51:20.973572 2026] [core:notice] [pid 806041:tid 806186] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:20.980846 2026] [security2:error] [pid 806041:tid 806186] [client 103.215.74.26:43940] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPGELAyZ1MRInzPMYODAAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:20.981063 2026] [security2:error] [pid 806041:tid 806183] [client 20.151.221.234:51707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/send.php"] [unique_id "amuPGELAyZ1MRInzPMYODQAAAJE"]
[Thu Jul 30 12:51:21.058914 2026] [security2:error] [pid 806041:tid 806249] [client 172.213.232.128:16964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuPGULAyZ1MRInzPMYOEQAAANM"]
[Thu Jul 30 12:51:21.669292 2026] [security2:error] [pid 806041:tid 806269] [client 20.151.221.234:11573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/file.php"] [unique_id "amuPGULAyZ1MRInzPMYOHQAAAOc"]
[Thu Jul 30 12:51:21.727629 2026] [core:notice] [pid 806041:tid 806241] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:21.733896 2026] [security2:error] [pid 806041:tid 806241] [client 103.215.74.26:43942] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPGULAyZ1MRInzPMYOHgAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:21.903228 2026] [security2:error] [pid 806041:tid 806177] [client 34.139.111.28:60260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuPGULAyZ1MRInzPMYOIgAAAIs"]
[Thu Jul 30 12:51:21.979934 2026] [security2:error] [pid 806041:tid 806231] [client 20.100.187.246:6011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuPGULAyZ1MRInzPMYOJQAAAME"]
[Thu Jul 30 12:51:22.267099 2026] [security2:error] [pid 806041:tid 806222] [client 172.213.232.128:48687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuPGkLAyZ1MRInzPMYOKgAAALg"]
[Thu Jul 30 12:51:22.271561 2026] [security2:error] [pid 806041:tid 806202] [client 20.151.221.234:51655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuPGkLAyZ1MRInzPMYOKwAAAKQ"]
[Thu Jul 30 12:51:22.304109 2026] [security2:error] [pid 806041:tid 806066] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPGkLAyZ1MRInzPMYOLgAA-xg"]
[Thu Jul 30 12:51:22.304236 2026] [security2:error] [pid 806041:tid 806289] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPGkLAyZ1MRInzPMYOLgAA-xg"]
[Thu Jul 30 12:51:22.377359 2026] [security2:error] [pid 806041:tid 806229] [client 20.151.221.234:11728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuPGkLAyZ1MRInzPMYOMAAAAL8"]
[Thu Jul 30 12:51:22.476232 2026] [core:notice] [pid 806041:tid 806264] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:22.483541 2026] [security2:error] [pid 806041:tid 806264] [client 103.215.74.26:43954] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPGkLAyZ1MRInzPMYOMQAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:22.938271 2026] [security2:error] [pid 806041:tid 806171] [client 34.139.111.28:55099] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuPGkLAyZ1MRInzPMYORAAAAIU"]
[Thu Jul 30 12:51:22.954927 2026] [core:error] [pid 806041:tid 806235] [client 138.246.253.24:35942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:22.954970 2026] [core:error] [pid 806041:tid 806235] [client 138.246.253.24:35942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:23.201390 2026] [core:notice] [pid 806041:tid 806297] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:23.208484 2026] [security2:error] [pid 806041:tid 806297] [client 103.215.74.26:12254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPG0LAyZ1MRInzPMYOTgAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:23.217198 2026] [core:error] [pid 806041:tid 806245] [client 20.151.221.234:52556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:23.217221 2026] [core:error] [pid 806041:tid 806245] [client 20.151.221.234:52556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:51:23.255098 2026] [security2:error] [pid 806041:tid 806206] [client 20.151.221.234:22984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/aaa.php"] [unique_id "amuPG0LAyZ1MRInzPMYOUAAAAKg"]
[Thu Jul 30 12:51:23.824028 2026] [security2:error] [pid 806041:tid 806291] [client 20.100.187.246:6163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuPG0LAyZ1MRInzPMYOWwAAAP0"]
[Thu Jul 30 12:51:23.961160 2026] [core:notice] [pid 806041:tid 806292] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:23.967558 2026] [security2:error] [pid 806041:tid 806292] [client 103.215.74.26:12270] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPG0LAyZ1MRInzPMYOYgAAAP4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:24.008860 2026] [security2:error] [pid 806041:tid 806298] [client 34.139.111.28:56482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuPHELAyZ1MRInzPMYOYwAAAQQ"]
[Thu Jul 30 12:51:24.225565 2026] [security2:error] [pid 806041:tid 806289] [client 172.213.232.128:38274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuPHELAyZ1MRInzPMYObAAAAPs"]
[Thu Jul 30 12:51:24.300014 2026] [security2:error] [pid 806041:tid 806270] [client 20.151.221.234:38710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuPHELAyZ1MRInzPMYObQAAAOg"]
[Thu Jul 30 12:51:24.417084 2026] [security2:error] [pid 806041:tid 806193] [client 20.151.221.234:2100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/about.php"] [unique_id "amuPHELAyZ1MRInzPMYObgAAAJs"]
[Thu Jul 30 12:51:24.495183 2026] [core:notice] [pid 806041:tid 806209] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:24.624957 2026] [proxy:error] [pid 806041:tid 806284] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:51:24.625056 2026] [proxy_http:error] [pid 806041:tid 806284] [client 185.247.137.101:54261] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:51:24.625620 2026] [proxy:error] [pid 806041:tid 806284] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:51:24.625664 2026] [proxy_http:error] [pid 806041:tid 806284] [client 185.247.137.101:54261] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:51:24.706067 2026] [core:notice] [pid 806041:tid 806229] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:24.711823 2026] [security2:error] [pid 806041:tid 806229] [client 103.215.74.26:12280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPHELAyZ1MRInzPMYOdwAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:25.030693 2026] [security2:error] [pid 806041:tid 806176] [client 34.139.111.28:57016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuPHULAyZ1MRInzPMYOfgAAAIo"]
[Thu Jul 30 12:51:25.369127 2026] [security2:error] [pid 806041:tid 806278] [client 20.151.221.234:2098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/options.php"] [unique_id "amuPHULAyZ1MRInzPMYOhQAAAPA"]
[Thu Jul 30 12:51:25.413664 2026] [security2:error] [pid 806041:tid 806200] [client 20.151.221.234:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/index/function.php"] [unique_id "amuPHULAyZ1MRInzPMYOjAAAAKI"]
[Thu Jul 30 12:51:25.452644 2026] [core:notice] [pid 806041:tid 806252] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:25.458608 2026] [security2:error] [pid 806041:tid 806252] [client 103.215.74.26:12288] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPHULAyZ1MRInzPMYOjQAAANY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:25.463803 2026] [security2:error] [pid 806041:tid 806186] [client 198.44.157.146:44870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuPHULAyZ1MRInzPMYOjgAAAJQ"]
[Thu Jul 30 12:51:25.463885 2026] [security2:error] [pid 806041:tid 806186] [client 198.44.157.146:44870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuPHULAyZ1MRInzPMYOjgAAAJQ"]
[Thu Jul 30 12:51:25.555066 2026] [security2:error] [pid 806041:tid 806280] [client 172.213.232.128:16779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuPHULAyZ1MRInzPMYOkgAAAPI"]
[Thu Jul 30 12:51:25.880490 2026] [security2:error] [pid 806041:tid 806248] [client 20.100.187.246:24257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuPHULAyZ1MRInzPMYOnAAAANI"]
[Thu Jul 30 12:51:25.932426 2026] [security2:error] [pid 806041:tid 806262] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuPHULAyZ1MRInzPMYOmwAAAOA"]
[Thu Jul 30 12:51:26.109276 2026] [security2:error] [pid 806041:tid 806297] [client 34.139.111.28:58831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuPHkLAyZ1MRInzPMYOowAAAQM"]
[Thu Jul 30 12:51:26.184134 2026] [core:notice] [pid 806041:tid 806211] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:26.192853 2026] [security2:error] [pid 806041:tid 806211] [client 103.215.74.26:12296] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPHkLAyZ1MRInzPMYOqgAAAK0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:26.431191 2026] [security2:error] [pid 806041:tid 806232] [client 20.151.221.234:2062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuPHkLAyZ1MRInzPMYOrgAAAMI"]
[Thu Jul 30 12:51:26.904038 2026] [security2:error] [pid 806041:tid 806173] [client 172.213.232.128:33986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuPHkLAyZ1MRInzPMYOuQAAAIc"]
[Thu Jul 30 12:51:26.922306 2026] [core:notice] [pid 806041:tid 806227] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:26.928662 2026] [security2:error] [pid 806041:tid 806227] [client 103.215.74.26:12308] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPHkLAyZ1MRInzPMYOugAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:27.048883 2026] [security2:error] [pid 806041:tid 806195] [client 74.7.241.155:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rvi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuPHkLAyZ1MRInzPMYOogAAAJ0"]
[Thu Jul 30 12:51:27.049838 2026] [security2:error] [pid 806041:tid 806217] [client 74.7.241.155:47014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rvi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuPHkLAyZ1MRInzPMYOoAAAsyM"]
[Thu Jul 30 12:51:27.138254 2026] [security2:error] [pid 806041:tid 806289] [client 34.139.111.28:54714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "stunningtouchcleaning.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuPH0LAyZ1MRInzPMYOwAAAAPs"]
[Thu Jul 30 12:51:27.251316 2026] [security2:error] [pid 806041:tid 806176] [client 20.151.221.234:52715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/aaa.php"] [unique_id "amuPH0LAyZ1MRInzPMYOxAAAAIo"]
[Thu Jul 30 12:51:27.505045 2026] [security2:error] [pid 806041:tid 806279] [client 20.151.221.234:50364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/wp-file.php"] [unique_id "amuPH0LAyZ1MRInzPMYOyQAAAPE"]
[Thu Jul 30 12:51:27.629678 2026] [security2:error] [pid 806041:tid 806267] [client 172.213.232.128:16967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuPH0LAyZ1MRInzPMYO0wAAAOU"]
[Thu Jul 30 12:51:27.655580 2026] [core:notice] [pid 806041:tid 806251] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:27.663903 2026] [security2:error] [pid 806041:tid 806251] [client 103.215.74.26:12310] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPH0LAyZ1MRInzPMYO1AAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:27.817928 2026] [security2:error] [pid 806041:tid 806239] [client 152.32.178.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.kfo.lku.temporary.site"] [uri "/index.php"] [unique_id "amuPH0LAyZ1MRInzPMYOzwAAAMk"]
[Thu Jul 30 12:51:27.899913 2026] [security2:error] [pid 806041:tid 806183] [client 20.151.221.234:23014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/getid3-core.php"] [unique_id "amuPH0LAyZ1MRInzPMYO2wAAAJE"]
[Thu Jul 30 12:51:28.024721 2026] [security2:error] [pid 806041:tid 806269] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuPIELAyZ1MRInzPMYO3wAAAOc"]
[Thu Jul 30 12:51:28.024838 2026] [security2:error] [pid 806041:tid 806269] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuPIELAyZ1MRInzPMYO3wAAAOc"]
[Thu Jul 30 12:51:28.066810 2026] [security2:error] [pid 806041:tid 806293] [client 20.100.187.246:24014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuPIELAyZ1MRInzPMYO4AAAAP8"]
[Thu Jul 30 12:51:28.384770 2026] [core:notice] [pid 806041:tid 806241] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:28.391285 2026] [security2:error] [pid 806041:tid 806241] [client 103.215.74.26:12324] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPIELAyZ1MRInzPMYO6wAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:28.589713 2026] [security2:error] [pid 806041:tid 806205] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuPIELAyZ1MRInzPMYO8AAAAKc"]
[Thu Jul 30 12:51:28.589795 2026] [security2:error] [pid 806041:tid 806205] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuPIELAyZ1MRInzPMYO8AAAAKc"]
[Thu Jul 30 12:51:28.709286 2026] [security2:error] [pid 806041:tid 806196] [client 20.151.221.234:45546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/adminer.php"] [unique_id "amuPIELAyZ1MRInzPMYO8QAAAJ4"]
[Thu Jul 30 12:51:28.775710 2026] [security2:error] [pid 806041:tid 806232] [client 20.100.187.246:25563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuPIELAyZ1MRInzPMYO8gAAAMI"]
[Thu Jul 30 12:51:28.942177 2026] [core:notice] [pid 806041:tid 806246] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:29.080540 2026] [security2:error] [pid 806041:tid 806273] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/bootstrap.php"] [unique_id "amuPIULAyZ1MRInzPMYPAAAAAOs"]
[Thu Jul 30 12:51:29.080636 2026] [security2:error] [pid 806041:tid 806273] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/bootstrap.php"] [unique_id "amuPIULAyZ1MRInzPMYPAAAAAOs"]
[Thu Jul 30 12:51:29.117886 2026] [core:notice] [pid 806041:tid 806173] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:29.124126 2026] [security2:error] [pid 806041:tid 806173] [client 103.215.74.26:12328] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPIULAyZ1MRInzPMYPAQAAAIc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:29.228180 2026] [security2:error] [pid 806041:tid 806228] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuPIULAyZ1MRInzPMYO_gAAAL4"]
[Thu Jul 30 12:51:29.292119 2026] [security2:error] [pid 806041:tid 806171] [client 150.107.232.194:26648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPIULAyZ1MRInzPMYPCAAAAIU"]
[Thu Jul 30 12:51:29.292243 2026] [security2:error] [pid 806041:tid 806171] [client 150.107.232.194:26648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPIULAyZ1MRInzPMYPCAAAAIU"]
[Thu Jul 30 12:51:29.616777 2026] [security2:error] [pid 806041:tid 806252] [client 172.213.232.128:37094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuPIULAyZ1MRInzPMYPGAAAANY"]
[Thu Jul 30 12:51:29.844800 2026] [core:notice] [pid 806041:tid 806239] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:29.851163 2026] [security2:error] [pid 806041:tid 806239] [client 103.215.74.26:12338] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPIULAyZ1MRInzPMYPHgAAAMk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:30.163353 2026] [security2:error] [pid 806041:tid 806211] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-blog-header.php"] [unique_id "amuPIkLAyZ1MRInzPMYPJQAAAK0"]
[Thu Jul 30 12:51:30.163459 2026] [security2:error] [pid 806041:tid 806211] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-blog-header.php"] [unique_id "amuPIkLAyZ1MRInzPMYPJQAAAK0"]
[Thu Jul 30 12:51:30.309746 2026] [security2:error] [pid 806041:tid 806203] [client 20.151.221.234:2979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeewalk.com"] [uri "/sid3.php"] [unique_id "amuPIkLAyZ1MRInzPMYPKgAAAKU"]
[Thu Jul 30 12:51:30.510164 2026] [security2:error] [pid 806041:tid 806262] [client 20.100.187.246:5694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuPIkLAyZ1MRInzPMYPMQAAAOA"]
[Thu Jul 30 12:51:30.563936 2026] [core:notice] [pid 806041:tid 806207] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:30.569960 2026] [security2:error] [pid 806041:tid 806207] [client 103.215.74.26:12354] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPIkLAyZ1MRInzPMYPNAAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:30.698822 2026] [security2:error] [pid 806041:tid 806232] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-load.php"] [unique_id "amuPIkLAyZ1MRInzPMYPNwAAAMI"]
[Thu Jul 30 12:51:30.698919 2026] [security2:error] [pid 806041:tid 806232] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-load.php"] [unique_id "amuPIkLAyZ1MRInzPMYPNwAAAMI"]
[Thu Jul 30 12:51:30.977031 2026] [core:notice] [pid 806041:tid 806266] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:31.008089 2026] [security2:error] [pid 806041:tid 806293] [client 172.213.232.128:34000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuPI0LAyZ1MRInzPMYPQAAAAP8"]
[Thu Jul 30 12:51:31.247581 2026] [security2:error] [pid 806041:tid 806219] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/edit.php"] [unique_id "amuPI0LAyZ1MRInzPMYPQwAAALU"]
[Thu Jul 30 12:51:31.247731 2026] [security2:error] [pid 806041:tid 806219] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/edit.php"] [unique_id "amuPI0LAyZ1MRInzPMYPQwAAALU"]
[Thu Jul 30 12:51:31.335789 2026] [core:notice] [pid 806041:tid 806230] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:31.342531 2026] [security2:error] [pid 806041:tid 806230] [client 103.215.74.26:12370] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPI0LAyZ1MRInzPMYPRQAAAMA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:32.093134 2026] [core:notice] [pid 806041:tid 806199] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:32.099523 2026] [security2:error] [pid 806041:tid 806199] [client 103.215.74.26:12382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPJELAyZ1MRInzPMYPVQAAAKE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:32.114639 2026] [core:notice] [pid 806041:tid 806129] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:32.432287 2026] [security2:error] [pid 806041:tid 806281] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bestdogproductguide.com"] [uri "/___proxy_subdomain_webdisk/cgi-bin"] [unique_id "amuPJELAyZ1MRInzPMYPWwAAAPM"]
[Thu Jul 30 12:51:32.705443 2026] [security2:error] [pid 806041:tid 806211] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/mah.php"] [unique_id "amuPJELAyZ1MRInzPMYPZQAAAK0"]
[Thu Jul 30 12:51:32.705562 2026] [security2:error] [pid 806041:tid 806211] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/mah.php"] [unique_id "amuPJELAyZ1MRInzPMYPZQAAAK0"]
[Thu Jul 30 12:51:32.725641 2026] [security2:error] [pid 806041:tid 806151] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPJELAyZ1MRInzPMYPZgABAW0"]
[Thu Jul 30 12:51:32.725782 2026] [security2:error] [pid 806041:tid 806295] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPJELAyZ1MRInzPMYPZgABAW0"]
[Thu Jul 30 12:51:32.829048 2026] [core:notice] [pid 806041:tid 806229] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:32.834848 2026] [security2:error] [pid 806041:tid 806229] [client 103.215.74.26:12384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPJELAyZ1MRInzPMYPbAAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:33.239607 2026] [security2:error] [pid 806041:tid 806232] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/archive.php"] [unique_id "amuPJULAyZ1MRInzPMYPdwAAAMI"]
[Thu Jul 30 12:51:33.239719 2026] [security2:error] [pid 806041:tid 806232] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/archive.php"] [unique_id "amuPJULAyZ1MRInzPMYPdwAAAMI"]
[Thu Jul 30 12:51:33.457917 2026] [security2:error] [pid 806041:tid 806231] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPJELAyZ1MRInzPMYPagAAAME"]
[Thu Jul 30 12:51:33.466703 2026] [security2:error] [pid 806041:tid 806175] [client 114.119.131.234:47757] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mydubaidesertsafari.com"] [uri "/gas-line/matt-mccall-stock-picks"] [unique_id "amuPJULAyZ1MRInzPMYPfAAAAIk"], referer: https://tpsdevelop.com/2dfok9c8/article.php?id=do-you-think-indigenous-science-should-be-considered-science-brainly
[Thu Jul 30 12:51:33.568168 2026] [core:notice] [pid 806041:tid 806191] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:33.574480 2026] [security2:error] [pid 806041:tid 806191] [client 103.215.74.26:56646] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPJULAyZ1MRInzPMYPfQAAAJk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:33.612638 2026] [security2:error] [pid 806041:tid 806182] [client 20.151.221.234:49510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/alfa.php"] [unique_id "amuPJULAyZ1MRInzPMYPhAAAAJA"]
[Thu Jul 30 12:51:33.881264 2026] [security2:error] [pid 806041:tid 806188] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/hosty.php"] [unique_id "amuPJULAyZ1MRInzPMYPiwAAAJY"]
[Thu Jul 30 12:51:33.881380 2026] [security2:error] [pid 806041:tid 806188] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/hosty.php"] [unique_id "amuPJULAyZ1MRInzPMYPiwAAAJY"]
[Thu Jul 30 12:51:33.994308 2026] [security2:error] [pid 806041:tid 806283] [client 20.151.221.234:55402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/getid3-core.php"] [unique_id "amuPJULAyZ1MRInzPMYPjwAAAPU"]
[Thu Jul 30 12:51:34.302921 2026] [core:notice] [pid 806041:tid 806186] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:34.308740 2026] [security2:error] [pid 806041:tid 806186] [client 103.215.74.26:56660] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPJkLAyZ1MRInzPMYPlgAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:34.465133 2026] [security2:error] [pid 806041:tid 806245] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bestdogproductguide.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/Diff/"] [unique_id "amuPJkLAyZ1MRInzPMYPngAAAM8"]
[Thu Jul 30 12:51:34.534105 2026] [security2:error] [pid 806041:tid 806242] [client 172.213.232.128:37685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuPJkLAyZ1MRInzPMYPnwAAAMw"]
[Thu Jul 30 12:51:34.663135 2026] [security2:error] [pid 806041:tid 806261] [client 20.151.221.234:11741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/adminer.php"] [unique_id "amuPJkLAyZ1MRInzPMYPpAAAAN8"]
[Thu Jul 30 12:51:34.863312 2026] [security2:error] [pid 806041:tid 806241] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuPJkLAyZ1MRInzPMYPqwAAAMs"]
[Thu Jul 30 12:51:34.863395 2026] [security2:error] [pid 806041:tid 806241] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuPJkLAyZ1MRInzPMYPqwAAAMs"]
[Thu Jul 30 12:51:35.061475 2026] [core:notice] [pid 806041:tid 806201] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:35.067987 2026] [security2:error] [pid 806041:tid 806201] [client 103.215.74.26:56672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPJ0LAyZ1MRInzPMYPrAAAAKM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:35.423704 2026] [security2:error] [pid 806041:tid 806231] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/av.php"] [unique_id "amuPJ0LAyZ1MRInzPMYPuQAAAME"]
[Thu Jul 30 12:51:35.423809 2026] [security2:error] [pid 806041:tid 806231] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/av.php"] [unique_id "amuPJ0LAyZ1MRInzPMYPuQAAAME"]
[Thu Jul 30 12:51:35.431283 2026] [security2:error] [pid 806041:tid 806210] [client 172.213.232.128:16823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuPJ0LAyZ1MRInzPMYPugAAAKw"]
[Thu Jul 30 12:51:35.701372 2026] [security2:error] [pid 806041:tid 806173] [client 20.151.221.234:52672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/alfa.php"] [unique_id "amuPJ0LAyZ1MRInzPMYPvwAAAIc"]
[Thu Jul 30 12:51:35.808147 2026] [core:notice] [pid 806041:tid 806177] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:35.812454 2026] [core:notice] [pid 806041:tid 806273] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:35.814535 2026] [security2:error] [pid 806041:tid 806177] [client 103.215.74.26:56688] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPJ0LAyZ1MRInzPMYPxgAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:35.957107 2026] [security2:error] [pid 806041:tid 806271] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/shell.php"] [unique_id "amuPJ0LAyZ1MRInzPMYPywAAAOk"]
[Thu Jul 30 12:51:35.957212 2026] [security2:error] [pid 806041:tid 806271] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/shell.php"] [unique_id "amuPJ0LAyZ1MRInzPMYPywAAAOk"]
[Thu Jul 30 12:51:36.041873 2026] [security2:error] [pid 806041:tid 806264] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuPKELAyZ1MRInzPMYPzAAAAOI"]
[Thu Jul 30 12:51:36.042029 2026] [security2:error] [pid 806041:tid 806264] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuPKELAyZ1MRInzPMYPzAAAAOI"]
[Thu Jul 30 12:51:36.140256 2026] [security2:error] [pid 806041:tid 806224] [client 172.213.232.128:34027] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.mediaspawn.com"] [uri "/1.php"] [unique_id "amuPKELAyZ1MRInzPMYPzQAAALo"]
[Thu Jul 30 12:51:36.140405 2026] [security2:error] [pid 806041:tid 806224] [client 172.213.232.128:34027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/1.php"] [unique_id "amuPKELAyZ1MRInzPMYPzQAAALo"]
[Thu Jul 30 12:51:36.366788 2026] [security2:error] [pid 806041:tid 806268] [client 99.246.104.10:56986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuPKELAyZ1MRInzPMYP1QAA5g0"], referer: https://www.northyorksheridanmall.com/
[Thu Jul 30 12:51:36.368066 2026] [security2:error] [pid 806041:tid 806198] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuPKELAyZ1MRInzPMYP1gAAAKA"]
[Thu Jul 30 12:51:36.368200 2026] [security2:error] [pid 806041:tid 806198] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuPKELAyZ1MRInzPMYP1gAAAKA"]
[Thu Jul 30 12:51:36.510516 2026] [security2:error] [pid 806041:tid 806238] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/storage/index.php"] [unique_id "amuPKELAyZ1MRInzPMYP2gAAAMg"]
[Thu Jul 30 12:51:36.510615 2026] [security2:error] [pid 806041:tid 806238] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/storage/index.php"] [unique_id "amuPKELAyZ1MRInzPMYP2gAAAMg"]
[Thu Jul 30 12:51:36.563622 2026] [core:notice] [pid 806041:tid 806294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:36.569653 2026] [security2:error] [pid 806041:tid 806294] [client 103.215.74.26:56702] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPKELAyZ1MRInzPMYP3AAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:36.650611 2026] [security2:error] [pid 806041:tid 806266] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuPKELAyZ1MRInzPMYP4QAAAOQ"]
[Thu Jul 30 12:51:36.650714 2026] [security2:error] [pid 806041:tid 806266] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuPKELAyZ1MRInzPMYP4QAAAOQ"]
[Thu Jul 30 12:51:36.735179 2026] [security2:error] [pid 806041:tid 806185] [client 20.151.221.234:11538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuPKELAyZ1MRInzPMYP5AAAAJM"]
[Thu Jul 30 12:51:36.741158 2026] [security2:error] [pid 806041:tid 806245] [client 172.213.232.128:17003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/admin.php"] [unique_id "amuPKELAyZ1MRInzPMYP5QAAAM8"]
[Thu Jul 30 12:51:36.961937 2026] [security2:error] [pid 806041:tid 806194] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/media.php"] [unique_id "amuPKELAyZ1MRInzPMYP6QAAAJw"]
[Thu Jul 30 12:51:36.962075 2026] [security2:error] [pid 806041:tid 806194] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/media.php"] [unique_id "amuPKELAyZ1MRInzPMYP6QAAAJw"]
[Thu Jul 30 12:51:37.049535 2026] [security2:error] [pid 806041:tid 806256] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/w.php"] [unique_id "amuPKULAyZ1MRInzPMYP7QAAANo"]
[Thu Jul 30 12:51:37.049629 2026] [security2:error] [pid 806041:tid 806256] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/w.php"] [unique_id "amuPKULAyZ1MRInzPMYP7QAAANo"]
[Thu Jul 30 12:51:37.244407 2026] [security2:error] [pid 806041:tid 806232] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/images.php"] [unique_id "amuPKULAyZ1MRInzPMYP8gAAAMI"]
[Thu Jul 30 12:51:37.244516 2026] [security2:error] [pid 806041:tid 806232] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/images.php"] [unique_id "amuPKULAyZ1MRInzPMYP8gAAAMI"]
[Thu Jul 30 12:51:37.303204 2026] [core:notice] [pid 806041:tid 806203] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:37.309217 2026] [security2:error] [pid 806041:tid 806203] [client 103.215.74.26:56704] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPKULAyZ1MRInzPMYP9wAAAKU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:37.607491 2026] [security2:error] [pid 806041:tid 806275] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/jp.php"] [unique_id "amuPKULAyZ1MRInzPMYP_wAAAO0"]
[Thu Jul 30 12:51:37.607588 2026] [security2:error] [pid 806041:tid 806275] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/jp.php"] [unique_id "amuPKULAyZ1MRInzPMYP_wAAAO0"]
[Thu Jul 30 12:51:37.970249 2026] [security2:error] [pid 806041:tid 806277] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/adminner.php"] [unique_id "amuPKULAyZ1MRInzPMYQBgAAAO8"]
[Thu Jul 30 12:51:37.970368 2026] [security2:error] [pid 806041:tid 806277] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/adminner.php"] [unique_id "amuPKULAyZ1MRInzPMYQBgAAAO8"]
[Thu Jul 30 12:51:38.030243 2026] [core:notice] [pid 806041:tid 806179] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:38.035914 2026] [security2:error] [pid 806041:tid 806179] [client 103.215.74.26:56714] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPKkLAyZ1MRInzPMYQCgAAAI0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:38.084403 2026] [security2:error] [pid 806041:tid 806272] [client 20.151.221.234:11581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuPKkLAyZ1MRInzPMYQCwAAAOo"]
[Thu Jul 30 12:51:38.095015 2026] [security2:error] [pid 806041:tid 806241] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPKULAyZ1MRInzPMYP-QAAy3Y"]
[Thu Jul 30 12:51:38.180076 2026] [security2:error] [pid 806041:tid 806283] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bestdogproductguide.com"] [uri "/___proxy_subdomain_webdisk/php.ini"] [unique_id "amuPKkLAyZ1MRInzPMYQDAAAAPU"]
[Thu Jul 30 12:51:38.477668 2026] [security2:error] [pid 806041:tid 806268] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/ws77.php"] [unique_id "amuPKkLAyZ1MRInzPMYQEwAAAOY"]
[Thu Jul 30 12:51:38.477781 2026] [security2:error] [pid 806041:tid 806268] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/ws77.php"] [unique_id "amuPKkLAyZ1MRInzPMYQEwAAAOY"]
[Thu Jul 30 12:51:38.596678 2026] [core:notice] [pid 806041:tid 806284] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:38.765832 2026] [core:notice] [pid 806041:tid 806198] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:38.772281 2026] [security2:error] [pid 806041:tid 806198] [client 103.215.74.26:56730] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPKkLAyZ1MRInzPMYQGwAAAKA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:38.906563 2026] [security2:error] [pid 806041:tid 806269] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuPKkLAyZ1MRInzPMYQHwAAAOc"]
[Thu Jul 30 12:51:38.906675 2026] [security2:error] [pid 806041:tid 806269] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuPKkLAyZ1MRInzPMYQHwAAAOc"]
[Thu Jul 30 12:51:39.083764 2026] [security2:error] [pid 806041:tid 806244] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/blass.php"] [unique_id "amuPK0LAyZ1MRInzPMYQJwAAAM4"]
[Thu Jul 30 12:51:39.083877 2026] [security2:error] [pid 806041:tid 806244] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/blass.php"] [unique_id "amuPK0LAyZ1MRInzPMYQJwAAAM4"]
[Thu Jul 30 12:51:39.189757 2026] [security2:error] [pid 806041:tid 806194] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/ops.php"] [unique_id "amuPK0LAyZ1MRInzPMYQKgAAAJw"]
[Thu Jul 30 12:51:39.189854 2026] [security2:error] [pid 806041:tid 806194] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/ops.php"] [unique_id "amuPK0LAyZ1MRInzPMYQKgAAAJw"]
[Thu Jul 30 12:51:39.477494 2026] [security2:error] [pid 806041:tid 806296] [client 20.151.221.234:52706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuPK0LAyZ1MRInzPMYQMQAAAQI"]
[Thu Jul 30 12:51:39.493553 2026] [core:notice] [pid 806041:tid 806202] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:39.499561 2026] [security2:error] [pid 806041:tid 806202] [client 103.215.74.26:56732] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPK0LAyZ1MRInzPMYQMgAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:39.503641 2026] [security2:error] [pid 806041:tid 806197] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/mac.php"] [unique_id "amuPK0LAyZ1MRInzPMYQMwAAAJ8"]
[Thu Jul 30 12:51:39.503715 2026] [security2:error] [pid 806041:tid 806197] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/mac.php"] [unique_id "amuPK0LAyZ1MRInzPMYQMwAAAJ8"]
[Thu Jul 30 12:51:39.760319 2026] [security2:error] [pid 806041:tid 806291] [client 150.107.232.194:27158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPK0LAyZ1MRInzPMYQNwAAAP0"]
[Thu Jul 30 12:51:39.760437 2026] [security2:error] [pid 806041:tid 806291] [client 150.107.232.194:27158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPK0LAyZ1MRInzPMYQNwAAAP0"]
[Thu Jul 30 12:51:39.798099 2026] [security2:error] [pid 806041:tid 806210] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-info.php"] [unique_id "amuPK0LAyZ1MRInzPMYQOAAAAKw"]
[Thu Jul 30 12:51:39.798194 2026] [security2:error] [pid 806041:tid 806210] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-info.php"] [unique_id "amuPK0LAyZ1MRInzPMYQOAAAAKw"]
[Thu Jul 30 12:51:39.893478 2026] [core:notice] [pid 806041:tid 806182] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:40.081480 2026] [security2:error] [pid 806041:tid 806212] [client 20.151.221.234:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuPLELAyZ1MRInzPMYQQwAAAK4"]
[Thu Jul 30 12:51:40.231025 2026] [security2:error] [pid 806041:tid 806176] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPLELAyZ1MRInzPMYQRAAAAIo"]
[Thu Jul 30 12:51:40.246038 2026] [core:notice] [pid 806041:tid 806246] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:40.252166 2026] [security2:error] [pid 806041:tid 806246] [client 103.215.74.26:56734] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPLELAyZ1MRInzPMYQRQAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:40.351053 2026] [security2:error] [pid 806041:tid 806216] [client 20.151.221.234:11735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/edit.php"] [unique_id "amuPLELAyZ1MRInzPMYQRwAAALI"]
[Thu Jul 30 12:51:40.372761 2026] [security2:error] [pid 806041:tid 806219] [client 172.213.232.128:37638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/as.php"] [unique_id "amuPLELAyZ1MRInzPMYQSAAAALU"]
[Thu Jul 30 12:51:40.385516 2026] [security2:error] [pid 806041:tid 806174] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/CDX1.php"] [unique_id "amuPLELAyZ1MRInzPMYQSwAAAIg"]
[Thu Jul 30 12:51:40.385607 2026] [security2:error] [pid 806041:tid 806174] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/CDX1.php"] [unique_id "amuPLELAyZ1MRInzPMYQSwAAAIg"]
[Thu Jul 30 12:51:40.591637 2026] [security2:error] [pid 806041:tid 806264] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/pucci.php"] [unique_id "amuPLELAyZ1MRInzPMYQUAAAAOI"]
[Thu Jul 30 12:51:40.591737 2026] [security2:error] [pid 806041:tid 806264] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/pucci.php"] [unique_id "amuPLELAyZ1MRInzPMYQUAAAAOI"]
[Thu Jul 30 12:51:40.734998 2026] [security2:error] [pid 806041:tid 806206] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuPLELAyZ1MRInzPMYQVwAAAKg"]
[Thu Jul 30 12:51:40.735149 2026] [security2:error] [pid 806041:tid 806206] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuPLELAyZ1MRInzPMYQVwAAAKg"]
[Thu Jul 30 12:51:40.876047 2026] [security2:error] [pid 806041:tid 806186] [client 172.213.232.128:33000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/autoload_classmap.php"] [unique_id "amuPLELAyZ1MRInzPMYQWQAAAJQ"]
[Thu Jul 30 12:51:40.917850 2026] [security2:error] [pid 806041:tid 806175] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wpc.php"] [unique_id "amuPLELAyZ1MRInzPMYQXAAAAIk"]
[Thu Jul 30 12:51:40.917961 2026] [security2:error] [pid 806041:tid 806175] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wpc.php"] [unique_id "amuPLELAyZ1MRInzPMYQXAAAAIk"]
[Thu Jul 30 12:51:41.008896 2026] [security2:error] [pid 806041:tid 806294] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/8.php"] [unique_id "amuPLULAyZ1MRInzPMYQXgAAAQA"]
[Thu Jul 30 12:51:41.009017 2026] [security2:error] [pid 806041:tid 806294] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/8.php"] [unique_id "amuPLULAyZ1MRInzPMYQXgAAAQA"]
[Thu Jul 30 12:51:41.010502 2026] [core:notice] [pid 806041:tid 806268] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:41.016545 2026] [security2:error] [pid 806041:tid 806268] [client 103.215.74.26:56736] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPLULAyZ1MRInzPMYQXwAAAOY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:41.317401 2026] [security2:error] [pid 806041:tid 806236] [client 74.248.96.101:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "markmocek.com"] [uri "/1.php"] [unique_id "amuPLULAyZ1MRInzPMYQZgAAAMY"]
[Thu Jul 30 12:51:41.317516 2026] [security2:error] [pid 806041:tid 806236] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/1.php"] [unique_id "amuPLULAyZ1MRInzPMYQZgAAAMY"]
[Thu Jul 30 12:51:41.317612 2026] [security2:error] [pid 806041:tid 806236] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/1.php"] [unique_id "amuPLULAyZ1MRInzPMYQZgAAAMY"]
[Thu Jul 30 12:51:41.403014 2026] [security2:error] [pid 806041:tid 806178] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/jga.php"] [unique_id "amuPLULAyZ1MRInzPMYQaAAAAIw"]
[Thu Jul 30 12:51:41.403115 2026] [security2:error] [pid 806041:tid 806178] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/jga.php"] [unique_id "amuPLULAyZ1MRInzPMYQaAAAAIw"]
[Thu Jul 30 12:51:41.644664 2026] [security2:error] [pid 806041:tid 806276] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-content/admin.php"] [unique_id "amuPLULAyZ1MRInzPMYQbwAAAO4"]
[Thu Jul 30 12:51:41.644767 2026] [security2:error] [pid 806041:tid 806276] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-content/admin.php"] [unique_id "amuPLULAyZ1MRInzPMYQbwAAAO4"]
[Thu Jul 30 12:51:41.731422 2026] [security2:error] [pid 806041:tid 806245] [client 20.151.221.234:49512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuPLULAyZ1MRInzPMYQdAAAAM8"]
[Thu Jul 30 12:51:41.745665 2026] [core:notice] [pid 806041:tid 806282] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:41.751851 2026] [security2:error] [pid 806041:tid 806282] [client 103.215.74.26:56752] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPLULAyZ1MRInzPMYQdQAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:41.762184 2026] [security2:error] [pid 806041:tid 806202] [client 20.151.221.234:11838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/sf.php"] [unique_id "amuPLULAyZ1MRInzPMYQdgAAAKQ"]
[Thu Jul 30 12:51:41.825040 2026] [security2:error] [pid 806041:tid 806257] [client 172.213.232.128:33509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/back.php"] [unique_id "amuPLULAyZ1MRInzPMYQegAAANs"]
[Thu Jul 30 12:51:41.929003 2026] [security2:error] [pid 806041:tid 806298] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuPLULAyZ1MRInzPMYQewAAAQQ"]
[Thu Jul 30 12:51:41.929114 2026] [security2:error] [pid 806041:tid 806298] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuPLULAyZ1MRInzPMYQewAAAQQ"]
[Thu Jul 30 12:51:41.950433 2026] [security2:error] [pid 806041:tid 806263] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/666.php"] [unique_id "amuPLULAyZ1MRInzPMYQfAAAAOE"]
[Thu Jul 30 12:51:41.950521 2026] [security2:error] [pid 806041:tid 806263] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/666.php"] [unique_id "amuPLULAyZ1MRInzPMYQfAAAAOE"]
[Thu Jul 30 12:51:42.220686 2026] [security2:error] [pid 806041:tid 806173] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/222.php"] [unique_id "amuPLkLAyZ1MRInzPMYQgwAAAIc"]
[Thu Jul 30 12:51:42.220790 2026] [security2:error] [pid 806041:tid 806173] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/222.php"] [unique_id "amuPLkLAyZ1MRInzPMYQgwAAAIc"]
[Thu Jul 30 12:51:42.267251 2026] [core:notice] [pid 806041:tid 806097] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:42.450218 2026] [fcgid:warn] [pid 806041:tid 806228] (70014)End of file found: [client 152.32.178.47:60076] mod_fcgid: can't get data from http client
[Thu Jul 30 12:51:42.464749 2026] [security2:error] [pid 806041:tid 806260] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/htaccess.php"] [unique_id "amuPLkLAyZ1MRInzPMYQiQAAAN4"]
[Thu Jul 30 12:51:42.464842 2026] [security2:error] [pid 806041:tid 806260] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/htaccess.php"] [unique_id "amuPLkLAyZ1MRInzPMYQiQAAAN4"]
[Thu Jul 30 12:51:42.485268 2026] [core:notice] [pid 806041:tid 806289] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:42.491494 2026] [security2:error] [pid 806041:tid 806289] [client 103.215.74.26:56766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPLkLAyZ1MRInzPMYQigAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:42.502877 2026] [security2:error] [pid 806041:tid 806233] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/cgi-bin/index.php"] [unique_id "amuPLkLAyZ1MRInzPMYQiwAAAMM"]
[Thu Jul 30 12:51:42.502954 2026] [security2:error] [pid 806041:tid 806233] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/cgi-bin/index.php"] [unique_id "amuPLkLAyZ1MRInzPMYQiwAAAMM"]
[Thu Jul 30 12:51:42.688793 2026] [security2:error] [pid 806041:tid 806273] [client 172.213.232.128:17021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuPLkLAyZ1MRInzPMYQkwAAAOs"]
[Thu Jul 30 12:51:42.790308 2026] [security2:error] [pid 806041:tid 806175] [client 20.151.221.234:11792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wso.php"] [unique_id "amuPLkLAyZ1MRInzPMYQlwAAAIk"]
[Thu Jul 30 12:51:42.806999 2026] [security2:error] [pid 806041:tid 806188] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPLkLAyZ1MRInzPMYQmAAAAJY"]
[Thu Jul 30 12:51:42.974129 2026] [security2:error] [pid 806041:tid 806238] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPLkLAyZ1MRInzPMYQnAAAAMg"]
[Thu Jul 30 12:51:43.041086 2026] [security2:error] [pid 806041:tid 806280] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/m.php"] [unique_id "amuPL0LAyZ1MRInzPMYQnQAAAPI"]
[Thu Jul 30 12:51:43.041194 2026] [security2:error] [pid 806041:tid 806280] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/m.php"] [unique_id "amuPL0LAyZ1MRInzPMYQnQAAAPI"]
[Thu Jul 30 12:51:43.132015 2026] [security2:error] [pid 806041:tid 806266] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPL0LAyZ1MRInzPMYQngAAAOQ"]
[Thu Jul 30 12:51:43.225401 2026] [core:notice] [pid 806041:tid 806294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:43.231253 2026] [security2:error] [pid 806041:tid 806294] [client 103.215.74.26:37966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPL0LAyZ1MRInzPMYQogAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:43.279525 2026] [security2:error] [pid 806041:tid 806288] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/raw.php"] [unique_id "amuPL0LAyZ1MRInzPMYQowAAAPo"]
[Thu Jul 30 12:51:43.279624 2026] [security2:error] [pid 806041:tid 806288] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/raw.php"] [unique_id "amuPL0LAyZ1MRInzPMYQowAAAPo"]
[Thu Jul 30 12:51:43.320826 2026] [core:notice] [pid 806041:tid 806107] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:43.416046 2026] [security2:error] [pid 806041:tid 806218] [client 20.151.221.234:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuPL0LAyZ1MRInzPMYQqAAAALQ"]
[Thu Jul 30 12:51:43.475547 2026] [security2:error] [pid 806041:tid 806187] [client 172.213.232.128:32998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/c/flower.php"] [unique_id "amuPL0LAyZ1MRInzPMYQrAAAAJU"]
[Thu Jul 30 12:51:43.534089 2026] [security2:error] [pid 806041:tid 806108] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPL0LAyZ1MRInzPMYQsAABA0I"]
[Thu Jul 30 12:51:43.534295 2026] [security2:error] [pid 806041:tid 806297] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPL0LAyZ1MRInzPMYQsAABA0I"]
[Thu Jul 30 12:51:43.579493 2026] [security2:error] [pid 806041:tid 806245] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/file.php"] [unique_id "amuPL0LAyZ1MRInzPMYQsQAAAM8"]
[Thu Jul 30 12:51:43.579591 2026] [security2:error] [pid 806041:tid 806245] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/file.php"] [unique_id "amuPL0LAyZ1MRInzPMYQsQAAAM8"]
[Thu Jul 30 12:51:43.583047 2026] [security2:error] [pid 806041:tid 806285] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPL0LAyZ1MRInzPMYQsgAAAPc"]
[Thu Jul 30 12:51:43.735915 2026] [security2:error] [pid 806041:tid 806197] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/simple.php"] [unique_id "amuPL0LAyZ1MRInzPMYQswAAAJ8"]
[Thu Jul 30 12:51:43.736023 2026] [security2:error] [pid 806041:tid 806197] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/simple.php"] [unique_id "amuPL0LAyZ1MRInzPMYQswAAAJ8"]
[Thu Jul 30 12:51:43.943088 2026] [core:notice] [pid 806041:tid 806282] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:43.949440 2026] [security2:error] [pid 806041:tid 806282] [client 103.215.74.26:37992] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPL0LAyZ1MRInzPMYQvQAAAPQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:43.981906 2026] [core:notice] [pid 806041:tid 806240] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:44.009398 2026] [security2:error] [pid 806041:tid 806173] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xxx.php"] [unique_id "amuPMELAyZ1MRInzPMYQwQAAAIc"]
[Thu Jul 30 12:51:44.009487 2026] [security2:error] [pid 806041:tid 806173] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xxx.php"] [unique_id "amuPMELAyZ1MRInzPMYQwQAAAIc"]
[Thu Jul 30 12:51:44.159185 2026] [security2:error] [pid 806041:tid 806225] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/.dj/index.php"] [unique_id "amuPMELAyZ1MRInzPMYQwgAAALs"]
[Thu Jul 30 12:51:44.159307 2026] [security2:error] [pid 806041:tid 806225] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/.dj/index.php"] [unique_id "amuPMELAyZ1MRInzPMYQwgAAALs"]
[Thu Jul 30 12:51:44.166446 2026] [security2:error] [pid 806041:tid 806220] [client 20.151.221.234:49511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/edit.php"] [unique_id "amuPMELAyZ1MRInzPMYQwwAAALY"]
[Thu Jul 30 12:51:44.247285 2026] [security2:error] [pid 806041:tid 806275] [client 47.128.36.17:30234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/i-am-the-true-vine/"] [unique_id "amuPMELAyZ1MRInzPMYQxAAAAO0"]
[Thu Jul 30 12:51:44.290070 2026] [security2:error] [pid 806041:tid 806219] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/file.php"] [unique_id "amuPMELAyZ1MRInzPMYQyAAAALU"]
[Thu Jul 30 12:51:44.290171 2026] [security2:error] [pid 806041:tid 806219] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/file.php"] [unique_id "amuPMELAyZ1MRInzPMYQyAAAALU"]
[Thu Jul 30 12:51:44.573522 2026] [security2:error] [pid 806041:tid 806272] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-load.php"] [unique_id "amuPMELAyZ1MRInzPMYQzwAAAOo"]
[Thu Jul 30 12:51:44.573612 2026] [security2:error] [pid 806041:tid 806272] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-load.php"] [unique_id "amuPMELAyZ1MRInzPMYQzwAAAOo"]
[Thu Jul 30 12:51:44.685565 2026] [core:notice] [pid 806041:tid 806233] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:44.696081 2026] [security2:error] [pid 806041:tid 806233] [client 103.215.74.26:38012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPMELAyZ1MRInzPMYQ0QAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:44.700856 2026] [security2:error] [pid 806041:tid 806273] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuPMELAyZ1MRInzPMYQ0gAAAOs"]
[Thu Jul 30 12:51:44.700966 2026] [security2:error] [pid 806041:tid 806273] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuPMELAyZ1MRInzPMYQ0gAAAOs"]
[Thu Jul 30 12:51:44.919666 2026] [security2:error] [pid 806041:tid 806175] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPMELAyZ1MRInzPMYQ2gAAAIk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 12:51:45.097797 2026] [security2:error] [pid 806041:tid 806268] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPMULAyZ1MRInzPMYQ4QAAAOY"]
[Thu Jul 30 12:51:45.147610 2026] [security2:error] [pid 806041:tid 806212] [client 172.213.232.128:38302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/c/xleet.php"] [unique_id "amuPMULAyZ1MRInzPMYQ4gAAAK4"]
[Thu Jul 30 12:51:45.269760 2026] [security2:error] [pid 806041:tid 806239] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuPMULAyZ1MRInzPMYQ5AAAAMk"]
[Thu Jul 30 12:51:45.269946 2026] [security2:error] [pid 806041:tid 806239] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuPMULAyZ1MRInzPMYQ5AAAAMk"]
[Thu Jul 30 12:51:45.277518 2026] [security2:error] [pid 806041:tid 806211] [client 20.100.187.246:26117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuPMULAyZ1MRInzPMYQ5QAAAK0"]
[Thu Jul 30 12:51:45.295700 2026] [security2:error] [pid 806041:tid 806252] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/pages.php"] [unique_id "amuPMULAyZ1MRInzPMYQ5gAAANY"]
[Thu Jul 30 12:51:45.295796 2026] [security2:error] [pid 806041:tid 806252] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/pages.php"] [unique_id "amuPMULAyZ1MRInzPMYQ5gAAANY"]
[Thu Jul 30 12:51:45.427472 2026] [core:notice] [pid 806041:tid 806266] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:45.433547 2026] [security2:error] [pid 806041:tid 806266] [client 103.215.74.26:38042] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPMULAyZ1MRInzPMYQ7gAAAOQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:45.532993 2026] [core:notice] [pid 806041:tid 806121] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:45.544026 2026] [security2:error] [pid 806041:tid 806286] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/a.php"] [unique_id "amuPMULAyZ1MRInzPMYQ8QAAAPg"]
[Thu Jul 30 12:51:45.544129 2026] [security2:error] [pid 806041:tid 806286] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/a.php"] [unique_id "amuPMULAyZ1MRInzPMYQ8QAAAPg"]
[Thu Jul 30 12:51:45.768494 2026] [security2:error] [pid 806041:tid 806292] [client 172.213.232.128:33006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/classwithtostring.php"] [unique_id "amuPMULAyZ1MRInzPMYQ9QAAAP4"]
[Thu Jul 30 12:51:45.819908 2026] [security2:error] [pid 806041:tid 806209] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuPMULAyZ1MRInzPMYQ-QAAAKs"]
[Thu Jul 30 12:51:45.820094 2026] [security2:error] [pid 806041:tid 806209] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuPMULAyZ1MRInzPMYQ-QAAAKs"]
[Thu Jul 30 12:51:45.887041 2026] [security2:error] [pid 806041:tid 806291] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/adminfuns.php"] [unique_id "amuPMULAyZ1MRInzPMYQ_QAAAP0"]
[Thu Jul 30 12:51:45.887149 2026] [security2:error] [pid 806041:tid 806291] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/adminfuns.php"] [unique_id "amuPMULAyZ1MRInzPMYQ_QAAAP0"]
[Thu Jul 30 12:51:46.087120 2026] [security2:error] [pid 806041:tid 806103] [remote 74.7.241.60:59378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuPMkLAyZ1MRInzPMYRAgAA4T0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:51:46.102349 2026] [security2:error] [pid 806041:tid 806173] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/aa.php"] [unique_id "amuPMkLAyZ1MRInzPMYRBwAAAIc"]
[Thu Jul 30 12:51:46.102461 2026] [security2:error] [pid 806041:tid 806173] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/aa.php"] [unique_id "amuPMkLAyZ1MRInzPMYRBwAAAIc"]
[Thu Jul 30 12:51:46.152893 2026] [core:notice] [pid 806041:tid 806298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:46.163274 2026] [security2:error] [pid 806041:tid 806298] [client 103.215.74.26:38062] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPMkLAyZ1MRInzPMYRCQAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:46.188097 2026] [security2:error] [pid 806041:tid 806236] [client 20.151.221.234:11778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/ioxi-o.php"] [unique_id "amuPMkLAyZ1MRInzPMYRCgAAAMY"]
[Thu Jul 30 12:51:46.386656 2026] [security2:error] [pid 806041:tid 806246] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/177.php"] [unique_id "amuPMkLAyZ1MRInzPMYRDgAAANA"]
[Thu Jul 30 12:51:46.386770 2026] [security2:error] [pid 806041:tid 806246] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/177.php"] [unique_id "amuPMkLAyZ1MRInzPMYRDgAAANA"]
[Thu Jul 30 12:51:46.438914 2026] [security2:error] [pid 806041:tid 806205] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/aa.php"] [unique_id "amuPMkLAyZ1MRInzPMYRDwAAAKc"]
[Thu Jul 30 12:51:46.439082 2026] [security2:error] [pid 806041:tid 806205] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/aa.php"] [unique_id "amuPMkLAyZ1MRInzPMYRDwAAAKc"]
[Thu Jul 30 12:51:46.468075 2026] [security2:error] [pid 806041:tid 806275] [client 172.213.232.128:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/content.php"] [unique_id "amuPMkLAyZ1MRInzPMYREwAAAO0"]
[Thu Jul 30 12:51:46.654798 2026] [security2:error] [pid 806041:tid 806191] [client 172.237.109.114:21060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPMkLAyZ1MRInzPMYQ_wAAAJk"]
[Thu Jul 30 12:51:46.654798 2026] [security2:error] [pid 806041:tid 806207] [client 172.237.109.114:19543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPMkLAyZ1MRInzPMYRAAAAAKk"]
[Thu Jul 30 12:51:46.670561 2026] [security2:error] [pid 806041:tid 806182] [client 172.237.109.114:57770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPMkLAyZ1MRInzPMYRAQAAAJA"]
[Thu Jul 30 12:51:46.677968 2026] [security2:error] [pid 806041:tid 806217] [client 172.237.109.114:44263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPMkLAyZ1MRInzPMYRBQAAALM"]
[Thu Jul 30 12:51:46.700343 2026] [security2:error] [pid 806041:tid 806282] [client 172.237.109.114:18662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPMkLAyZ1MRInzPMYRCAAAAPQ"]
[Thu Jul 30 12:51:46.804452 2026] [fcgid:warn] [pid 806041:tid 806259] (70014)End of file found: [client 118.193.69.177:53084] mod_fcgid: can't get data from http client
[Thu Jul 30 12:51:46.868795 2026] [security2:error] [pid 806041:tid 806289] [client 20.100.187.246:26120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuPMkLAyZ1MRInzPMYRGwAAAPs"]
[Thu Jul 30 12:51:46.892543 2026] [core:notice] [pid 806041:tid 806247] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:46.894737 2026] [security2:error] [pid 806041:tid 806273] [client 20.151.221.234:11523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/file56.php"] [unique_id "amuPMkLAyZ1MRInzPMYRHwAAAOs"]
[Thu Jul 30 12:51:46.899103 2026] [security2:error] [pid 806041:tid 806247] [client 103.215.74.26:38088] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPMkLAyZ1MRInzPMYRHgAAANE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:46.925262 2026] [core:notice] [pid 806041:tid 806145] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:46.956766 2026] [security2:error] [pid 806041:tid 806274] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bestdogproductguide.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/Diff/Engine/"] [unique_id "amuPMkLAyZ1MRInzPMYRJAAAAOw"]
[Thu Jul 30 12:51:47.245866 2026] [security2:error] [pid 806041:tid 806266] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/classwithtostring.php"] [unique_id "amuPM0LAyZ1MRInzPMYRLAAAAOQ"]
[Thu Jul 30 12:51:47.245954 2026] [security2:error] [pid 806041:tid 806266] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/classwithtostring.php"] [unique_id "amuPM0LAyZ1MRInzPMYRLAAAAOQ"]
[Thu Jul 30 12:51:47.552743 2026] [security2:error] [pid 806041:tid 806149] [remote 216.73.216.152:14002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuPM0LAyZ1MRInzPMYRNAAA_ms"]
[Thu Jul 30 12:51:47.607046 2026] [security2:error] [pid 806041:tid 806276] [client 20.100.187.246:26150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuPM0LAyZ1MRInzPMYRNQAAAO4"]
[Thu Jul 30 12:51:47.627081 2026] [core:notice] [pid 806041:tid 806214] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:47.633717 2026] [security2:error] [pid 806041:tid 806214] [client 103.215.74.26:38100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPM0LAyZ1MRInzPMYRNgAAALA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:47.701825 2026] [security2:error] [pid 806041:tid 806197] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/coffexium.php"] [unique_id "amuPM0LAyZ1MRInzPMYROAAAAJ8"]
[Thu Jul 30 12:51:47.701916 2026] [security2:error] [pid 806041:tid 806197] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/coffexium.php"] [unique_id "amuPM0LAyZ1MRInzPMYROAAAAJ8"]
[Thu Jul 30 12:51:47.777753 2026] [security2:error] [pid 806041:tid 806291] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amuPM0LAyZ1MRInzPMYROwAAAP0"]
[Thu Jul 30 12:51:47.777844 2026] [security2:error] [pid 806041:tid 806291] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amuPM0LAyZ1MRInzPMYROwAAAP0"]
[Thu Jul 30 12:51:47.917481 2026] [security2:error] [pid 806041:tid 806245] [client 20.151.221.234:52695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuPM0LAyZ1MRInzPMYRPwAAAM8"]
[Thu Jul 30 12:51:47.970520 2026] [security2:error] [pid 806041:tid 806263] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/fffm.php"] [unique_id "amuPM0LAyZ1MRInzPMYRQwAAAOE"]
[Thu Jul 30 12:51:47.970625 2026] [security2:error] [pid 806041:tid 806263] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/fffm.php"] [unique_id "amuPM0LAyZ1MRInzPMYRQwAAAOE"]
[Thu Jul 30 12:51:48.243962 2026] [security2:error] [pid 806041:tid 806228] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/82.php"] [unique_id "amuPNELAyZ1MRInzPMYRSgAAAL4"]
[Thu Jul 30 12:51:48.244075 2026] [security2:error] [pid 806041:tid 806228] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/82.php"] [unique_id "amuPNELAyZ1MRInzPMYRSgAAAL4"]
[Thu Jul 30 12:51:48.301723 2026] [security2:error] [pid 806041:tid 806181] [client 20.100.187.246:5651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuPNELAyZ1MRInzPMYRSwAAAI8"]
[Thu Jul 30 12:51:48.371391 2026] [core:notice] [pid 806041:tid 806219] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:48.374466 2026] [security2:error] [pid 806041:tid 806260] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/goods.php"] [unique_id "amuPNELAyZ1MRInzPMYRTgAAAN4"]
[Thu Jul 30 12:51:48.374567 2026] [security2:error] [pid 806041:tid 806260] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/goods.php"] [unique_id "amuPNELAyZ1MRInzPMYRTgAAAN4"]
[Thu Jul 30 12:51:48.377782 2026] [security2:error] [pid 806041:tid 806219] [client 103.215.74.26:38116] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPNELAyZ1MRInzPMYRTQAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:48.529271 2026] [security2:error] [pid 806041:tid 806207] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/config.json.php"] [unique_id "amuPNELAyZ1MRInzPMYRVgAAAKk"]
[Thu Jul 30 12:51:48.529380 2026] [security2:error] [pid 806041:tid 806207] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/config.json.php"] [unique_id "amuPNELAyZ1MRInzPMYRVgAAAKk"]
[Thu Jul 30 12:51:48.646552 2026] [security2:error] [pid 806041:tid 806253] [client 172.213.232.128:32275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/doc.php"] [unique_id "amuPNELAyZ1MRInzPMYRVwAAANc"]
[Thu Jul 30 12:51:48.688521 2026] [security2:error] [pid 806041:tid 806186] [client 217.138.252.123:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.252.138.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuPNELAyZ1MRInzPMYRWAAAAJQ"]
[Thu Jul 30 12:51:48.688627 2026] [security2:error] [pid 806041:tid 806186] [client 217.138.252.123:54848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuPNELAyZ1MRInzPMYRWAAAAJQ"]
[Thu Jul 30 12:51:48.861347 2026] [security2:error] [pid 806041:tid 806281] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/fpwch.php"] [unique_id "amuPNELAyZ1MRInzPMYRXAAAAPM"]
[Thu Jul 30 12:51:48.861460 2026] [security2:error] [pid 806041:tid 806281] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/fpwch.php"] [unique_id "amuPNELAyZ1MRInzPMYRXAAAAPM"]
[Thu Jul 30 12:51:48.901214 2026] [security2:error] [pid 806041:tid 806273] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/php8.php"] [unique_id "amuPNELAyZ1MRInzPMYRXgAAAOs"]
[Thu Jul 30 12:51:48.901314 2026] [security2:error] [pid 806041:tid 806273] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/php8.php"] [unique_id "amuPNELAyZ1MRInzPMYRXgAAAOs"]
[Thu Jul 30 12:51:48.922004 2026] [security2:error] [pid 806041:tid 806241] [client 20.151.221.234:11784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuPNELAyZ1MRInzPMYRXwAAAMs"]
[Thu Jul 30 12:51:49.118620 2026] [core:notice] [pid 806041:tid 806243] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:49.125741 2026] [security2:error] [pid 806041:tid 806243] [client 103.215.74.26:38124] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPNULAyZ1MRInzPMYRZwAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:49.139367 2026] [security2:error] [pid 806041:tid 806284] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xp.php"] [unique_id "amuPNULAyZ1MRInzPMYRaQAAAPY"]
[Thu Jul 30 12:51:49.139446 2026] [security2:error] [pid 806041:tid 806284] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/xp.php"] [unique_id "amuPNULAyZ1MRInzPMYRaQAAAPY"]
[Thu Jul 30 12:51:49.362972 2026] [security2:error] [pid 806041:tid 806198] [client 20.100.187.246:24059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuPNULAyZ1MRInzPMYRcQAAAKA"]
[Thu Jul 30 12:51:49.368839 2026] [security2:error] [pid 806041:tid 806244] [client 99.246.104.10:58229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuPNULAyZ1MRInzPMYRagAAzkk"], referer: https://www.northyorksheridanmall.com/events/
[Thu Jul 30 12:51:49.393224 2026] [core:notice] [pid 806041:tid 806047] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:49.398531 2026] [core:notice] [pid 806041:tid 806044] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:49.418905 2026] [security2:error] [pid 806041:tid 806202] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/info.php"] [unique_id "amuPNULAyZ1MRInzPMYRdwAAAKQ"]
[Thu Jul 30 12:51:49.419013 2026] [security2:error] [pid 806041:tid 806202] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/info.php"] [unique_id "amuPNULAyZ1MRInzPMYRdwAAAKQ"]
[Thu Jul 30 12:51:49.423308 2026] [security2:error] [pid 806041:tid 806206] [client 20.151.221.234:53604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/sf.php"] [unique_id "amuPNULAyZ1MRInzPMYReAAAAKg"]
[Thu Jul 30 12:51:49.447359 2026] [core:notice] [pid 806041:tid 806050] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:49.514733 2026] [security2:error] [pid 806041:tid 806212] [client 172.213.232.128:37681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/dropdown.php"] [unique_id "amuPNULAyZ1MRInzPMYRegAAAK4"]
[Thu Jul 30 12:51:49.520886 2026] [security2:error] [pid 806041:tid 806292] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/reop3.php"] [unique_id "amuPNULAyZ1MRInzPMYRewAAAP4"]
[Thu Jul 30 12:51:49.520989 2026] [security2:error] [pid 806041:tid 806292] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/reop3.php"] [unique_id "amuPNULAyZ1MRInzPMYRewAAAP4"]
[Thu Jul 30 12:51:49.589400 2026] [security2:error] [pid 806041:tid 806070] [remote 57.141.0.12:55048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuPNULAyZ1MRInzPMYRgAABARw"]
[Thu Jul 30 12:51:49.794113 2026] [security2:error] [pid 806041:tid 806183] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPNULAyZ1MRInzPMYRigAAAJE"]
[Thu Jul 30 12:51:49.864056 2026] [security2:error] [pid 806041:tid 806286] [client 20.151.221.234:11744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/edit.php"] [unique_id "amuPNULAyZ1MRInzPMYRkQAAAPg"]
[Thu Jul 30 12:51:49.871794 2026] [core:notice] [pid 806041:tid 806195] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:49.878041 2026] [security2:error] [pid 806041:tid 806195] [client 103.215.74.26:38134] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPNULAyZ1MRInzPMYRkgAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:49.932914 2026] [security2:error] [pid 806041:tid 806192] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp.php"] [unique_id "amuPNULAyZ1MRInzPMYRlgAAAJo"]
[Thu Jul 30 12:51:49.933044 2026] [security2:error] [pid 806041:tid 806192] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/wp.php"] [unique_id "amuPNULAyZ1MRInzPMYRlgAAAJo"]
[Thu Jul 30 12:51:49.962456 2026] [security2:error] [pid 806041:tid 806220] [client 20.100.187.246:24045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuPNULAyZ1MRInzPMYRmQAAALY"]
[Thu Jul 30 12:51:50.228651 2026] [security2:error] [pid 806041:tid 806191] [client 150.107.232.194:27357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPNkLAyZ1MRInzPMYRpgAAAJk"]
[Thu Jul 30 12:51:50.228751 2026] [security2:error] [pid 806041:tid 806191] [client 150.107.232.194:27357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPNkLAyZ1MRInzPMYRpgAAAJk"]
[Thu Jul 30 12:51:50.247212 2026] [security2:error] [pid 806041:tid 806235] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/dex.php"] [unique_id "amuPNkLAyZ1MRInzPMYRqQAAAMU"]
[Thu Jul 30 12:51:50.247291 2026] [security2:error] [pid 806041:tid 806235] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/dex.php"] [unique_id "amuPNkLAyZ1MRInzPMYRqQAAAMU"]
[Thu Jul 30 12:51:50.516136 2026] [security2:error] [pid 806041:tid 806175] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/biufile.php"] [unique_id "amuPNkLAyZ1MRInzPMYRtAAAAIk"]
[Thu Jul 30 12:51:50.516220 2026] [security2:error] [pid 806041:tid 806175] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/biufile.php"] [unique_id "amuPNkLAyZ1MRInzPMYRtAAAAIk"]
[Thu Jul 30 12:51:50.610170 2026] [core:notice] [pid 806041:tid 806278] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:50.616458 2026] [security2:error] [pid 806041:tid 806278] [client 103.215.74.26:38146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPNkLAyZ1MRInzPMYRuAAAAPA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:50.862429 2026] [security2:error] [pid 806041:tid 806296] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuPNkLAyZ1MRInzPMYRywAAAQI"]
[Thu Jul 30 12:51:50.862529 2026] [security2:error] [pid 806041:tid 806296] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuPNkLAyZ1MRInzPMYRywAAAQI"]
[Thu Jul 30 12:51:50.968701 2026] [security2:error] [pid 806041:tid 806241] [client 20.100.187.246:23657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuPNkLAyZ1MRInzPMYRzAAAAMs"]
[Thu Jul 30 12:51:51.147463 2026] [security2:error] [pid 806041:tid 806295] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuPN0LAyZ1MRInzPMYR1QAAAQE"]
[Thu Jul 30 12:51:51.147553 2026] [security2:error] [pid 806041:tid 806295] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/inputs.php"] [unique_id "amuPN0LAyZ1MRInzPMYR1QAAAQE"]
[Thu Jul 30 12:51:51.292568 2026] [security2:error] [pid 806041:tid 806172] [client 20.151.221.234:11768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/2.php"] [unique_id "amuPN0LAyZ1MRInzPMYR3gAAAIY"]
[Thu Jul 30 12:51:51.341101 2026] [core:notice] [pid 806041:tid 806212] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:51.348990 2026] [security2:error] [pid 806041:tid 806212] [client 103.215.74.26:38160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPN0LAyZ1MRInzPMYR4gAAAK4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:51.469202 2026] [security2:error] [pid 806041:tid 806225] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuPN0LAyZ1MRInzPMYR5AAAALs"]
[Thu Jul 30 12:51:51.469317 2026] [security2:error] [pid 806041:tid 806225] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuPN0LAyZ1MRInzPMYR5AAAALs"]
[Thu Jul 30 12:51:51.518199 2026] [security2:error] [pid 806041:tid 806192] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/class-t.api.php"] [unique_id "amuPN0LAyZ1MRInzPMYR5QAAAJo"]
[Thu Jul 30 12:51:51.518289 2026] [security2:error] [pid 806041:tid 806192] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/class-t.api.php"] [unique_id "amuPN0LAyZ1MRInzPMYR5QAAAJo"]
[Thu Jul 30 12:51:51.589699 2026] [security2:error] [pid 806041:tid 806177] [client 20.100.187.246:5662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuPN0LAyZ1MRInzPMYR7gAAAIs"]
[Thu Jul 30 12:51:51.783573 2026] [security2:error] [pid 806041:tid 806217] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/goods.php"] [unique_id "amuPN0LAyZ1MRInzPMYR-AAAALM"]
[Thu Jul 30 12:51:51.783690 2026] [security2:error] [pid 806041:tid 806217] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/goods.php"] [unique_id "amuPN0LAyZ1MRInzPMYR-AAAALM"]
[Thu Jul 30 12:51:51.875429 2026] [security2:error] [pid 806041:tid 806098] [remote 5.253.84.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jipkl.com"] [uri "/wp-login.php"] [unique_id "amuPN0LAyZ1MRInzPMYR_QAAkDg"]
[Thu Jul 30 12:51:52.025016 2026] [security2:error] [pid 806041:tid 806271] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/simple.php"] [unique_id "amuPOELAyZ1MRInzPMYSAAAAAOk"]
[Thu Jul 30 12:51:52.025127 2026] [security2:error] [pid 806041:tid 806271] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/simple.php"] [unique_id "amuPOELAyZ1MRInzPMYSAAAAAOk"]
[Thu Jul 30 12:51:52.058570 2026] [security2:error] [pid 806041:tid 806278] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuPOELAyZ1MRInzPMYSAwAAAPA"]
[Thu Jul 30 12:51:52.058661 2026] [security2:error] [pid 806041:tid 806278] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuPOELAyZ1MRInzPMYSAwAAAPA"]
[Thu Jul 30 12:51:52.070875 2026] [core:notice] [pid 806041:tid 806259] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:52.077316 2026] [security2:error] [pid 806041:tid 806259] [client 103.215.74.26:38162] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPOELAyZ1MRInzPMYSBgAAAN0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:52.252308 2026] [security2:error] [pid 806041:tid 806175] [client 74.7.244.55:35228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-33cd3ca5.unj.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuPOELAyZ1MRInzPMYSDwAAiUc"]
[Thu Jul 30 12:51:52.310188 2026] [security2:error] [pid 806041:tid 806117] [remote 5.253.84.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jipkl.com"] [uri "/administrator/"] [unique_id "amuPOELAyZ1MRInzPMYSEAAA-ks"]
[Thu Jul 30 12:51:52.374469 2026] [security2:error] [pid 806041:tid 806270] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuPOELAyZ1MRInzPMYSEgAAAOg"]
[Thu Jul 30 12:51:52.374591 2026] [security2:error] [pid 806041:tid 806270] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuPOELAyZ1MRInzPMYSEgAAAOg"]
[Thu Jul 30 12:51:52.380098 2026] [security2:error] [pid 806041:tid 806204] [client 52.167.144.233:46395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amuPOELAyZ1MRInzPMYSCwAApk0"]
[Thu Jul 30 12:51:52.537754 2026] [security2:error] [pid 806041:tid 806208] [client 20.151.221.234:11815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuPOELAyZ1MRInzPMYSGgAAAKo"]
[Thu Jul 30 12:51:52.553277 2026] [security2:error] [pid 806041:tid 806296] [client 20.151.221.234:44692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wso.php"] [unique_id "amuPOELAyZ1MRInzPMYSGwAAAQI"]
[Thu Jul 30 12:51:52.555404 2026] [security2:error] [pid 806041:tid 806291] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/ioxi-o.php"] [unique_id "amuPOELAyZ1MRInzPMYSHAAAAP0"]
[Thu Jul 30 12:51:52.555480 2026] [security2:error] [pid 806041:tid 806291] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/ioxi-o.php"] [unique_id "amuPOELAyZ1MRInzPMYSHAAAAP0"]
[Thu Jul 30 12:51:52.652658 2026] [security2:error] [pid 806041:tid 806237] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuPOELAyZ1MRInzPMYSHQAAAMc"]
[Thu Jul 30 12:51:52.652771 2026] [security2:error] [pid 806041:tid 806237] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuPOELAyZ1MRInzPMYSHQAAAMc"]
[Thu Jul 30 12:51:52.807538 2026] [core:notice] [pid 806041:tid 806193] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:52.814781 2026] [security2:error] [pid 806041:tid 806193] [client 103.215.74.26:38172] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPOELAyZ1MRInzPMYSIQAAAJs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:52.934705 2026] [security2:error] [pid 806041:tid 806229] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuPOELAyZ1MRInzPMYSKAAAAL8"]
[Thu Jul 30 12:51:52.934787 2026] [security2:error] [pid 806041:tid 806229] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuPOELAyZ1MRInzPMYSKAAAAL8"]
[Thu Jul 30 12:51:53.017397 2026] [security2:error] [pid 806041:tid 806180] [client 172.213.232.128:32304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/ee.php"] [unique_id "amuPOULAyZ1MRInzPMYSKgAAAI4"]
[Thu Jul 30 12:51:53.091712 2026] [security2:error] [pid 806041:tid 806205] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bestdogproductguide.com"] [uri "/___proxy_subdomain_webdisk/wp-admin"] [unique_id "amuPOULAyZ1MRInzPMYSKwAAAKc"]
[Thu Jul 30 12:51:53.246086 2026] [security2:error] [pid 806041:tid 806275] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/chosen.php"] [unique_id "amuPOULAyZ1MRInzPMYSNQAAAO0"]
[Thu Jul 30 12:51:53.246189 2026] [security2:error] [pid 806041:tid 806275] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "markmocek.com"] [uri "/chosen.php"] [unique_id "amuPOULAyZ1MRInzPMYSNQAAAO0"]
[Thu Jul 30 12:51:53.388438 2026] [security2:error] [pid 806041:tid 806283] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp.php"] [unique_id "amuPOULAyZ1MRInzPMYSOQAAAPU"]
[Thu Jul 30 12:51:53.388555 2026] [security2:error] [pid 806041:tid 806283] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp.php"] [unique_id "amuPOULAyZ1MRInzPMYSOQAAAPU"]
[Thu Jul 30 12:51:53.562562 2026] [core:notice] [pid 806041:tid 806233] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:53.568926 2026] [security2:error] [pid 806041:tid 806233] [client 103.215.74.26:2108] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPOULAyZ1MRInzPMYSPQAAAMM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:53.770945 2026] [security2:error] [pid 806041:tid 806194] [client 20.151.221.234:11716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/mah.php"] [unique_id "amuPOULAyZ1MRInzPMYSQgAAAJw"]
[Thu Jul 30 12:51:53.893408 2026] [security2:error] [pid 806041:tid 806271] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/file2.php"] [unique_id "amuPOULAyZ1MRInzPMYSRgAAAOk"]
[Thu Jul 30 12:51:53.893512 2026] [security2:error] [pid 806041:tid 806271] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/file2.php"] [unique_id "amuPOULAyZ1MRInzPMYSRgAAAOk"]
[Thu Jul 30 12:51:54.210235 2026] [security2:error] [pid 806041:tid 806266] [client 99.246.104.10:58229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuPOkLAyZ1MRInzPMYSUAAA5Fk"], referer: https://www.northyorksheridanmall.com/contact-us/
[Thu Jul 30 12:51:54.239386 2026] [security2:error] [pid 806041:tid 806129] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPOkLAyZ1MRInzPMYSUQAA-lc"]
[Thu Jul 30 12:51:54.239532 2026] [security2:error] [pid 806041:tid 806288] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPOkLAyZ1MRInzPMYSUQAA-lc"]
[Thu Jul 30 12:51:54.304191 2026] [core:notice] [pid 806041:tid 806287] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:54.311559 2026] [security2:error] [pid 806041:tid 806287] [client 103.215.74.26:2120] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPOkLAyZ1MRInzPMYSVQAAAPk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:54.653751 2026] [security2:error] [pid 806041:tid 806175] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPOkLAyZ1MRInzPMYSTwAAAIk"]
[Thu Jul 30 12:51:54.806528 2026] [security2:error] [pid 806041:tid 806206] [client 20.151.221.234:11568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/send.php"] [unique_id "amuPOkLAyZ1MRInzPMYSZQAAAKg"]
[Thu Jul 30 12:51:54.906343 2026] [security2:error] [pid 806041:tid 806154] [remote 52.167.144.233:49002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/offres-demploi-2/article.php"] [unique_id "amuPOkLAyZ1MRInzPMYSagAA_3A"]
[Thu Jul 30 12:51:55.037513 2026] [core:notice] [pid 806041:tid 806209] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:55.045116 2026] [security2:error] [pid 806041:tid 806209] [client 103.215.74.26:2128] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPO0LAyZ1MRInzPMYScAAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:55.232010 2026] [security2:error] [pid 806041:tid 806236] [client 20.151.221.234:44698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/ioxi-o.php"] [unique_id "amuPO0LAyZ1MRInzPMYSdQAAAMY"]
[Thu Jul 30 12:51:55.284335 2026] [security2:error] [pid 806041:tid 806242] [client 20.100.187.246:26173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuPO0LAyZ1MRInzPMYSbwAAAMw"]
[Thu Jul 30 12:51:55.384950 2026] [security2:error] [pid 806041:tid 806203] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPOkLAyZ1MRInzPMYSYwAAAKU"]
[Thu Jul 30 12:51:55.455373 2026] [security2:error] [pid 806041:tid 806163] [remote 57.141.0.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuPO0LAyZ1MRInzPMYSfgAAxXk"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon%2Cdenim%2Cpolyester%2Cplastic%2Clinen%2Ctitanium%2Clycra&orderby=popularity&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 12:51:55.631316 2026] [security2:error] [pid 806041:tid 806283] [client 20.151.221.234:52691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuPO0LAyZ1MRInzPMYSgwAAAPU"]
[Thu Jul 30 12:51:55.780320 2026] [security2:error] [pid 806041:tid 806289] [client 172.213.232.128:37668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/flower.php"] [unique_id "amuPO0LAyZ1MRInzPMYSigAAAPs"]
[Thu Jul 30 12:51:55.781187 2026] [core:notice] [pid 806041:tid 806230] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:55.787260 2026] [security2:error] [pid 806041:tid 806230] [client 103.215.74.26:2144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPO0LAyZ1MRInzPMYSiwAAAMA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:55.955639 2026] [security2:error] [pid 806041:tid 806214] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/images/class-config.php"] [unique_id "amuPO0LAyZ1MRInzPMYSkgAAALA"]
[Thu Jul 30 12:51:55.955736 2026] [security2:error] [pid 806041:tid 806214] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/images/class-config.php"] [unique_id "amuPO0LAyZ1MRInzPMYSkgAAALA"]
[Thu Jul 30 12:51:55.985201 2026] [security2:error] [pid 806041:tid 806044] [remote 57.141.0.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuPO0LAyZ1MRInzPMYSlgAAiQI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon%2Cdenim%2Cpolyester%2Cplastic%2Clinen%2Ctitanium%2Clycra&orderby=popularity&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 12:51:56.452154 2026] [security2:error] [pid 806041:tid 806293] [client 172.212.190.89:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amuPPELAyZ1MRInzPMYSnwAAAP8"]
[Thu Jul 30 12:51:56.452256 2026] [security2:error] [pid 806041:tid 806293] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amuPPELAyZ1MRInzPMYSnwAAAP8"]
[Thu Jul 30 12:51:56.452357 2026] [security2:error] [pid 806041:tid 806293] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amuPPELAyZ1MRInzPMYSnwAAAP8"]
[Thu Jul 30 12:51:56.504193 2026] [core:notice] [pid 806041:tid 806298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:56.510133 2026] [security2:error] [pid 806041:tid 806298] [client 103.215.74.26:2160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPPELAyZ1MRInzPMYSpQAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:51:56.821031 2026] [security2:error] [pid 806041:tid 806232] [client 172.213.232.128:32996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/gecko-new.php"] [unique_id "amuPPELAyZ1MRInzPMYSqgAAAMI"]
[Thu Jul 30 12:51:56.970491 2026] [security2:error] [pid 806041:tid 806263] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/222.php"] [unique_id "amuPPELAyZ1MRInzPMYSrQAAAOE"]
[Thu Jul 30 12:51:56.970589 2026] [security2:error] [pid 806041:tid 806263] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/222.php"] [unique_id "amuPPELAyZ1MRInzPMYSrQAAAOE"]
[Thu Jul 30 12:51:57.477396 2026] [autoindex:error] [pid 806041:tid 806063] [remote 2a06:98c0:3600::103:0] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:51:57.481744 2026] [security2:error] [pid 806041:tid 806289] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/themes.php"] [unique_id "amuPPULAyZ1MRInzPMYSugAAAPs"]
[Thu Jul 30 12:51:57.481834 2026] [security2:error] [pid 806041:tid 806289] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/themes.php"] [unique_id "amuPPULAyZ1MRInzPMYSugAAAPs"]
[Thu Jul 30 12:51:57.797864 2026] [security2:error] [pid 806041:tid 806176] [client 20.151.221.234:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/file56.php"] [unique_id "amuPPULAyZ1MRInzPMYSywAAAIo"]
[Thu Jul 30 12:51:57.873608 2026] [security2:error] [pid 806041:tid 806239] [client 37.140.254.96:28591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amuPPULAyZ1MRInzPMYSvAAAAMk"]
[Thu Jul 30 12:51:57.899482 2026] [security2:error] [pid 806041:tid 806296] [client 172.213.232.128:34019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/m.php"] [unique_id "amuPPULAyZ1MRInzPMYSzgAAAQI"]
[Thu Jul 30 12:51:57.932435 2026] [security2:error] [pid 806041:tid 806225] [client 20.151.221.234:52697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/about.php"] [unique_id "amuPPULAyZ1MRInzPMYS0AAAALs"]
[Thu Jul 30 12:51:58.044198 2026] [security2:error] [pid 806041:tid 806189] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amuPPkLAyZ1MRInzPMYS1gAAAJc"]
[Thu Jul 30 12:51:58.044294 2026] [security2:error] [pid 806041:tid 806189] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amuPPkLAyZ1MRInzPMYS1gAAAJc"]
[Thu Jul 30 12:51:58.594413 2026] [security2:error] [pid 806041:tid 806194] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/dropdown.php"] [unique_id "amuPPkLAyZ1MRInzPMYS4QAAAJw"]
[Thu Jul 30 12:51:58.594509 2026] [security2:error] [pid 806041:tid 806194] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/dropdown.php"] [unique_id "amuPPkLAyZ1MRInzPMYS4QAAAJw"]
[Thu Jul 30 12:51:58.995452 2026] [security2:error] [pid 806041:tid 806199] [client 20.151.221.234:49505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuPPkLAyZ1MRInzPMYS6QAAAKE"]
[Thu Jul 30 12:51:59.051000 2026] [security2:error] [pid 806041:tid 806185] [client 20.151.221.234:11776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/options.php"] [unique_id "amuPP0LAyZ1MRInzPMYS6gAAAJM"]
[Thu Jul 30 12:51:59.089190 2026] [core:notice] [pid 806041:tid 806184] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:51:59.106296 2026] [security2:error] [pid 806041:tid 806292] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amuPP0LAyZ1MRInzPMYS7gAAAP4"]
[Thu Jul 30 12:51:59.106404 2026] [security2:error] [pid 806041:tid 806292] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amuPP0LAyZ1MRInzPMYS7gAAAP4"]
[Thu Jul 30 12:51:59.275026 2026] [security2:error] [pid 806041:tid 806224] [client 152.32.178.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.kfo.lku.temporary.site"] [uri "/index.php"] [unique_id "amuPP0LAyZ1MRInzPMYS7QAAALo"]
[Thu Jul 30 12:51:59.616179 2026] [security2:error] [pid 806041:tid 806211] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/100.php"] [unique_id "amuPP0LAyZ1MRInzPMYS-wAAAK0"]
[Thu Jul 30 12:51:59.616282 2026] [security2:error] [pid 806041:tid 806211] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/100.php"] [unique_id "amuPP0LAyZ1MRInzPMYS-wAAAK0"]
[Thu Jul 30 12:52:00.201094 2026] [security2:error] [pid 806041:tid 806087] [remote 87.250.224.225:48160] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/enhancing-project-management-processes-with-business-consulting/"] [unique_id "amuPQELAyZ1MRInzPMYTCAAAyC0"]
[Thu Jul 30 12:52:00.207211 2026] [security2:error] [pid 806041:tid 806189] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/autoload_classmap/function.php"] [unique_id "amuPQELAyZ1MRInzPMYTCQAAAJc"]
[Thu Jul 30 12:52:00.207289 2026] [security2:error] [pid 806041:tid 806189] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/autoload_classmap/function.php"] [unique_id "amuPQELAyZ1MRInzPMYTCQAAAJc"]
[Thu Jul 30 12:52:00.209617 2026] [security2:error] [pid 806041:tid 806297] [client 172.213.232.128:37666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuPQELAyZ1MRInzPMYTCgAAAQM"]
[Thu Jul 30 12:52:00.374906 2026] [security2:error] [pid 806041:tid 806176] [client 20.151.221.234:11721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuPQELAyZ1MRInzPMYTDgAAAIo"]
[Thu Jul 30 12:52:00.493523 2026] [fcgid:warn] [pid 806041:tid 806269] (70014)End of file found: [client 107.150.117.121:50730] mod_fcgid: can't get data from http client
[Thu Jul 30 12:52:00.499687 2026] [autoindex:error] [pid 806041:tid 806250] [client 106.51.226.166:44913] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:00.578669 2026] [autoindex:error] [pid 806041:tid 806194] [client 106.51.226.166:21957] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:00.643814 2026] [autoindex:error] [pid 806041:tid 806180] [client 106.51.226.166:14547] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:00.685186 2026] [security2:error] [pid 806041:tid 806273] [client 150.107.232.194:27373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPQELAyZ1MRInzPMYTGwAAAOs"]
[Thu Jul 30 12:52:00.685309 2026] [security2:error] [pid 806041:tid 806273] [client 150.107.232.194:27373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPQELAyZ1MRInzPMYTGwAAAOs"]
[Thu Jul 30 12:52:00.692581 2026] [autoindex:error] [pid 806041:tid 806267] [client 106.51.226.166:42449] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:00.713224 2026] [security2:error] [pid 806041:tid 806288] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/php.php"] [unique_id "amuPQELAyZ1MRInzPMYTHQAAAPo"]
[Thu Jul 30 12:52:00.713321 2026] [security2:error] [pid 806041:tid 806288] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/php.php"] [unique_id "amuPQELAyZ1MRInzPMYTHQAAAPo"]
[Thu Jul 30 12:52:01.223801 2026] [security2:error] [pid 806041:tid 806223] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/t.php"] [unique_id "amuPQULAyZ1MRInzPMYTLgAAALk"]
[Thu Jul 30 12:52:01.223915 2026] [security2:error] [pid 806041:tid 806223] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/t.php"] [unique_id "amuPQULAyZ1MRInzPMYTLgAAALk"]
[Thu Jul 30 12:52:01.427923 2026] [core:notice] [pid 806041:tid 806266] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:01.643382 2026] [security2:error] [pid 806041:tid 806258] [client 20.151.221.234:22629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuPQULAyZ1MRInzPMYTNQAAANw"]
[Thu Jul 30 12:52:01.711508 2026] [security2:error] [pid 806041:tid 806210] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-blink.php"] [unique_id "amuPQULAyZ1MRInzPMYTPAAAAKw"]
[Thu Jul 30 12:52:01.711655 2026] [security2:error] [pid 806041:tid 806210] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-blink.php"] [unique_id "amuPQULAyZ1MRInzPMYTPAAAAKw"]
[Thu Jul 30 12:52:01.884002 2026] [security2:error] [pid 806041:tid 806065] [remote 57.141.0.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuPQULAyZ1MRInzPMYTPwAAqhc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=desigual&filter_materials=carbon,linen,polyester,aluminum,plastic,nylon,wood,lycra&orderby=rating&rating=5&status=instock&min_price=125&max_price=200&unfilter=1
[Thu Jul 30 12:52:01.910374 2026] [security2:error] [pid 806041:tid 806272] [client 20.151.221.234:41038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wk/index.php"] [unique_id "amuPQULAyZ1MRInzPMYTQwAAAOo"]
[Thu Jul 30 12:52:01.935434 2026] [security2:error] [pid 806041:tid 806078] [remote 57.141.0.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuPQULAyZ1MRInzPMYTRQAAmyQ"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=desigual&filter_materials=carbon,linen,polyester,aluminum,plastic,nylon,wood,lycra&orderby=rating&rating=5&status=instock&min_price=125&max_price=200&unfilter=1
[Thu Jul 30 12:52:01.992834 2026] [security2:error] [pid 806041:tid 806254] [client 20.151.221.234:11835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/wp-file.php"] [unique_id "amuPQULAyZ1MRInzPMYTSQAAANg"]
[Thu Jul 30 12:52:02.257147 2026] [security2:error] [pid 806041:tid 806207] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/xfun.php"] [unique_id "amuPQkLAyZ1MRInzPMYTTgAAAKk"]
[Thu Jul 30 12:52:02.257291 2026] [security2:error] [pid 806041:tid 806207] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/xfun.php"] [unique_id "amuPQkLAyZ1MRInzPMYTTgAAAKk"]
[Thu Jul 30 12:52:02.276735 2026] [core:notice] [pid 806041:tid 806176] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:02.285290 2026] [security2:error] [pid 806041:tid 806176] [client 103.215.74.26:2162] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPQkLAyZ1MRInzPMYTTwAAAIo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:02.434333 2026] [core:notice] [pid 806041:tid 806286] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:02.450876 2026] [proxy:error] [pid 806041:tid 806217] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:02.450955 2026] [proxy_http:error] [pid 806041:tid 806217] [client 34.233.129.35:59016] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:02.451548 2026] [proxy:error] [pid 806041:tid 806217] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:02.451601 2026] [proxy_http:error] [pid 806041:tid 806217] [client 34.233.129.35:59016] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:02.548277 2026] [proxy:error] [pid 806041:tid 806194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:02.548344 2026] [proxy_http:error] [pid 806041:tid 806194] [client 32.194.121.99:44238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:02.548935 2026] [proxy:error] [pid 806041:tid 806194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:02.548993 2026] [proxy_http:error] [pid 806041:tid 806194] [client 32.194.121.99:44238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:02.672907 2026] [security2:error] [pid 806041:tid 806246] [client 20.151.221.234:41156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/edit.php"] [unique_id "amuPQkLAyZ1MRInzPMYTZgAAANA"]
[Thu Jul 30 12:52:02.703694 2026] [security2:error] [pid 806041:tid 806249] [client 172.213.232.128:16818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mediaspawn.com"] [uri "/mah/flower.php"] [unique_id "amuPQkLAyZ1MRInzPMYTaAAAANM"]
[Thu Jul 30 12:52:02.799841 2026] [security2:error] [pid 806041:tid 806271] [client 20.151.221.234:11577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bookario.com"] [uri "/sid3.php"] [unique_id "amuPQkLAyZ1MRInzPMYTaQAAAOk"]
[Thu Jul 30 12:52:02.851410 2026] [security2:error] [pid 806041:tid 806265] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/p.php"] [unique_id "amuPQkLAyZ1MRInzPMYTagAAAOM"]
[Thu Jul 30 12:52:02.851589 2026] [security2:error] [pid 806041:tid 806265] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/p.php"] [unique_id "amuPQkLAyZ1MRInzPMYTagAAAOM"]
[Thu Jul 30 12:52:03.009555 2026] [core:notice] [pid 806041:tid 806223] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:03.016936 2026] [security2:error] [pid 806041:tid 806223] [client 103.215.74.26:26454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPQ0LAyZ1MRInzPMYTbwAAALk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:03.439216 2026] [security2:error] [pid 806041:tid 806229] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuPQ0LAyZ1MRInzPMYTdgAAAL8"]
[Thu Jul 30 12:52:03.439333 2026] [security2:error] [pid 806041:tid 806229] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuPQ0LAyZ1MRInzPMYTdgAAAL8"]
[Thu Jul 30 12:52:03.819249 2026] [security2:error] [pid 806041:tid 806244] [client 20.151.221.234:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/av.php"] [unique_id "amuPQ0LAyZ1MRInzPMYTgwAAAM4"]
[Thu Jul 30 12:52:03.893471 2026] [security2:error] [pid 806041:tid 806220] [client 136.114.127.127:35502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ull.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuPQULAyZ1MRInzPMYTKQAAALY"]
[Thu Jul 30 12:52:03.893498 2026] [security2:error] [pid 806041:tid 806220] [client 136.114.127.127:35502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.ull.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuPQULAyZ1MRInzPMYTKQAAALY"]
[Thu Jul 30 12:52:03.991111 2026] [security2:error] [pid 806041:tid 806180] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/aaa.php"] [unique_id "amuPQ0LAyZ1MRInzPMYThQAAAI4"]
[Thu Jul 30 12:52:03.991217 2026] [security2:error] [pid 806041:tid 806180] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/aaa.php"] [unique_id "amuPQ0LAyZ1MRInzPMYThQAAAI4"]
[Thu Jul 30 12:52:04.508421 2026] [security2:error] [pid 806041:tid 806243] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/7.php"] [unique_id "amuPRELAyZ1MRInzPMYTkQAAAM0"]
[Thu Jul 30 12:52:04.508532 2026] [security2:error] [pid 806041:tid 806243] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/7.php"] [unique_id "amuPRELAyZ1MRInzPMYTkQAAAM0"]
[Thu Jul 30 12:52:04.594430 2026] [security2:error] [pid 806041:tid 806246] [client 20.151.221.234:63167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/mini.php"] [unique_id "amuPRELAyZ1MRInzPMYTlgAAANA"]
[Thu Jul 30 12:52:04.995007 2026] [security2:error] [pid 806041:tid 806171] [client 136.114.127.127:35488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ull.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuPQULAyZ1MRInzPMYTJwAAAIU"]
[Thu Jul 30 12:52:04.995034 2026] [security2:error] [pid 806041:tid 806171] [client 136.114.127.127:35488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.ull.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuPQULAyZ1MRInzPMYTJwAAAIU"]
[Thu Jul 30 12:52:05.071318 2026] [security2:error] [pid 806041:tid 806114] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPRULAyZ1MRInzPMYTogAA3Eg"]
[Thu Jul 30 12:52:05.071538 2026] [security2:error] [pid 806041:tid 806258] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPRULAyZ1MRInzPMYTogAA3Eg"]
[Thu Jul 30 12:52:05.089692 2026] [security2:error] [pid 806041:tid 806172] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/file5.php"] [unique_id "amuPRULAyZ1MRInzPMYTowAAAIY"]
[Thu Jul 30 12:52:05.089783 2026] [security2:error] [pid 806041:tid 806172] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/file5.php"] [unique_id "amuPRULAyZ1MRInzPMYTowAAAIY"]
[Thu Jul 30 12:52:05.541697 2026] [security2:error] [pid 806041:tid 806260] [client 20.151.221.234:12957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/aa.php"] [unique_id "amuPRULAyZ1MRInzPMYTrgAAAN4"]
[Thu Jul 30 12:52:05.657246 2026] [security2:error] [pid 806041:tid 806205] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/makeasmtp.php"] [unique_id "amuPRULAyZ1MRInzPMYTsgAAAKc"]
[Thu Jul 30 12:52:05.657354 2026] [security2:error] [pid 806041:tid 806205] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/makeasmtp.php"] [unique_id "amuPRULAyZ1MRInzPMYTsgAAAKc"]
[Thu Jul 30 12:52:06.166265 2026] [security2:error] [pid 806041:tid 806198] [client 198.44.157.146:43574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuPRkLAyZ1MRInzPMYTwAAAAKA"]
[Thu Jul 30 12:52:06.166405 2026] [security2:error] [pid 806041:tid 806198] [client 198.44.157.146:43574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuPRkLAyZ1MRInzPMYTwAAAAKA"]
[Thu Jul 30 12:52:06.207812 2026] [security2:error] [pid 806041:tid 806267] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/index.php"] [unique_id "amuPRkLAyZ1MRInzPMYTwQAAAOU"]
[Thu Jul 30 12:52:06.207897 2026] [security2:error] [pid 806041:tid 806267] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/index.php"] [unique_id "amuPRkLAyZ1MRInzPMYTwQAAAOU"]
[Thu Jul 30 12:52:06.316730 2026] [core:error] [pid 806041:tid 806182] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:06.316750 2026] [core:error] [pid 806041:tid 806182] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:06.317699 2026] [core:error] [pid 806041:tid 806279] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:06.317714 2026] [core:error] [pid 806041:tid 806279] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:06.371187 2026] [core:error] [pid 806041:tid 806248] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:06.371205 2026] [core:error] [pid 806041:tid 806248] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:06.700570 2026] [security2:error] [pid 806041:tid 806294] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/atomlib.php"] [unique_id "amuPRkLAyZ1MRInzPMYT3wAAAQA"]
[Thu Jul 30 12:52:06.700674 2026] [security2:error] [pid 806041:tid 806294] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/atomlib.php"] [unique_id "amuPRkLAyZ1MRInzPMYT3wAAAQA"]
[Thu Jul 30 12:52:06.786099 2026] [security2:error] [pid 806041:tid 806212] [client 20.151.221.234:63159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/w.php"] [unique_id "amuPRkLAyZ1MRInzPMYT5AAAAK4"]
[Thu Jul 30 12:52:07.234199 2026] [security2:error] [pid 806041:tid 806227] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/min.php"] [unique_id "amuPR0LAyZ1MRInzPMYT6gAAAL0"]
[Thu Jul 30 12:52:07.234324 2026] [security2:error] [pid 806041:tid 806227] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/min.php"] [unique_id "amuPR0LAyZ1MRInzPMYT6gAAAL0"]
[Thu Jul 30 12:52:07.742038 2026] [security2:error] [pid 806041:tid 806234] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/moon.php"] [unique_id "amuPR0LAyZ1MRInzPMYT-wAAAMQ"]
[Thu Jul 30 12:52:07.742194 2026] [security2:error] [pid 806041:tid 806234] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/moon.php"] [unique_id "amuPR0LAyZ1MRInzPMYT-wAAAMQ"]
[Thu Jul 30 12:52:07.783503 2026] [security2:error] [pid 806041:tid 806184] [client 50.6.43.217:32518] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "club4.au"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "amuPR0LAyZ1MRInzPMYT_gAAAJI"]
[Thu Jul 30 12:52:07.874109 2026] [security2:error] [pid 806041:tid 806197] [client 47.128.112.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "club4.au"] [uri "/index.php"] [unique_id "amuPRELAyZ1MRInzPMYTnQAAAJ8"]
[Thu Jul 30 12:52:08.898477 2026] [core:notice] [pid 806041:tid 806187] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:08.905571 2026] [security2:error] [pid 806041:tid 806187] [client 103.215.74.26:26458] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPSELAyZ1MRInzPMYUHQAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:09.476858 2026] [security2:error] [pid 806041:tid 806282] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/ws83.php"] [unique_id "amuPSULAyZ1MRInzPMYULAAAAPQ"]
[Thu Jul 30 12:52:09.476961 2026] [security2:error] [pid 806041:tid 806282] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/ws83.php"] [unique_id "amuPSULAyZ1MRInzPMYULAAAAPQ"]
[Thu Jul 30 12:52:09.651466 2026] [core:notice] [pid 806041:tid 806219] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:09.657783 2026] [security2:error] [pid 806041:tid 806219] [client 103.215.74.26:26468] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPSULAyZ1MRInzPMYUMgAAALU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:10.046993 2026] [security2:error] [pid 806041:tid 806179] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/403.php"] [unique_id "amuPSkLAyZ1MRInzPMYUPwAAAI0"]
[Thu Jul 30 12:52:10.047111 2026] [security2:error] [pid 806041:tid 806179] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/403.php"] [unique_id "amuPSkLAyZ1MRInzPMYUPwAAAI0"]
[Thu Jul 30 12:52:10.106773 2026] [security2:error] [pid 806041:tid 806172] [client 74.7.241.153:56226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.innovativefurnituretransportpackagingllc.cc.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuPSELAyZ1MRInzPMYUFgAAhnk"]
[Thu Jul 30 12:52:10.414900 2026] [core:notice] [pid 806041:tid 806235] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:10.422572 2026] [security2:error] [pid 806041:tid 806235] [client 103.215.74.26:26474] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPSkLAyZ1MRInzPMYURQAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:10.496101 2026] [security2:error] [pid 806041:tid 806245] [client 20.151.221.234:41028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amuPSkLAyZ1MRInzPMYUSQAAAM8"]
[Thu Jul 30 12:52:10.604277 2026] [security2:error] [pid 806041:tid 806214] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/api.php"] [unique_id "amuPSkLAyZ1MRInzPMYUUAAAALA"]
[Thu Jul 30 12:52:10.604376 2026] [security2:error] [pid 806041:tid 806214] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/api.php"] [unique_id "amuPSkLAyZ1MRInzPMYUUAAAALA"]
[Thu Jul 30 12:52:10.829189 2026] [security2:error] [pid 806041:tid 806201] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPSkLAyZ1MRInzPMYUQQAAo3U"]
[Thu Jul 30 12:52:10.909226 2026] [security2:error] [pid 806041:tid 806284] [client 31.128.179.202:33035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jesus.claims"] [uri "/index.php"] [unique_id "amuPSULAyZ1MRInzPMYUMQAAAPY"]
[Thu Jul 30 12:52:11.001853 2026] [security2:error] [pid 806041:tid 806252] [client 157.10.105.57:37880] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 57.105.10.157.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-comments-post.php"] [unique_id "amuPSkLAyZ1MRInzPMYUUQAAANY"]
[Thu Jul 30 12:52:11.001990 2026] [security2:error] [pid 806041:tid 806252] [client 157.10.105.57:37880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "emmelevate.club"] [uri "/wp-comments-post.php"] [unique_id "amuPSkLAyZ1MRInzPMYUUQAAANY"]
[Thu Jul 30 12:52:11.158721 2026] [core:notice] [pid 806041:tid 806195] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:11.165445 2026] [security2:error] [pid 806041:tid 806195] [client 103.215.74.26:26488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPS0LAyZ1MRInzPMYUXQAAAJ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:11.200186 2026] [security2:error] [pid 806041:tid 806265] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/3.php"] [unique_id "amuPS0LAyZ1MRInzPMYUYAAAAOM"]
[Thu Jul 30 12:52:11.200343 2026] [security2:error] [pid 806041:tid 806265] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/3.php"] [unique_id "amuPS0LAyZ1MRInzPMYUYAAAAOM"]
[Thu Jul 30 12:52:11.280728 2026] [security2:error] [pid 806041:tid 806297] [client 150.107.232.194:26755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPS0LAyZ1MRInzPMYUYQAAAQM"]
[Thu Jul 30 12:52:11.280867 2026] [security2:error] [pid 806041:tid 806297] [client 150.107.232.194:26755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPS0LAyZ1MRInzPMYUYQAAAQM"]
[Thu Jul 30 12:52:11.331813 2026] [security2:error] [pid 806041:tid 806272] [client 20.151.221.234:33957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/2.php"] [unique_id "amuPS0LAyZ1MRInzPMYUYgAAAOo"]
[Thu Jul 30 12:52:11.904863 2026] [core:notice] [pid 806041:tid 806180] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:11.911284 2026] [security2:error] [pid 806041:tid 806180] [client 103.215.74.26:26492] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPS0LAyZ1MRInzPMYUbAAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:12.429092 2026] [security2:error] [pid 806041:tid 806185] [client 20.151.221.234:33956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuPTELAyZ1MRInzPMYUfAAAAJM"]
[Thu Jul 30 12:52:12.642695 2026] [core:notice] [pid 806041:tid 806281] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:12.649304 2026] [security2:error] [pid 806041:tid 806281] [client 103.215.74.26:26504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPTELAyZ1MRInzPMYUjAAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:12.999669 2026] [security2:error] [pid 806041:tid 806187] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bestdogproductguide.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/PHPMailer/"] [unique_id "amuPTELAyZ1MRInzPMYUjQAAAJU"]
[Thu Jul 30 12:52:13.369512 2026] [core:notice] [pid 806041:tid 806193] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:13.376844 2026] [security2:error] [pid 806041:tid 806193] [client 103.215.74.26:45376] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPTULAyZ1MRInzPMYUmQAAAJs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:13.674881 2026] [security2:error] [pid 806041:tid 806276] [client 20.151.221.234:33944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/mah.php"] [unique_id "amuPTULAyZ1MRInzPMYUowAAAO4"]
[Thu Jul 30 12:52:14.167394 2026] [core:notice] [pid 806041:tid 806189] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:14.172285 2026] [security2:error] [pid 806041:tid 806275] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/ws77.php"] [unique_id "amuPTkLAyZ1MRInzPMYUqwAAAO0"]
[Thu Jul 30 12:52:14.172384 2026] [security2:error] [pid 806041:tid 806275] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/ws77.php"] [unique_id "amuPTkLAyZ1MRInzPMYUqwAAAO0"]
[Thu Jul 30 12:52:14.173844 2026] [security2:error] [pid 806041:tid 806189] [client 103.215.74.26:45390] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPTkLAyZ1MRInzPMYUqgAAAJc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:14.910060 2026] [core:notice] [pid 806041:tid 806172] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:14.916388 2026] [security2:error] [pid 806041:tid 806172] [client 103.215.74.26:45400] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPTkLAyZ1MRInzPMYUvAAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:15.143161 2026] [security2:error] [pid 806041:tid 806271] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/nc4.php"] [unique_id "amuPT0LAyZ1MRInzPMYUwQAAAOk"]
[Thu Jul 30 12:52:15.143267 2026] [security2:error] [pid 806041:tid 806271] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/nc4.php"] [unique_id "amuPT0LAyZ1MRInzPMYUwQAAAOk"]
[Thu Jul 30 12:52:15.653376 2026] [core:notice] [pid 806041:tid 806281] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:15.659682 2026] [security2:error] [pid 806041:tid 806281] [client 103.215.74.26:45406] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPT0LAyZ1MRInzPMYUzQAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:15.705111 2026] [security2:error] [pid 806041:tid 806202] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/as.php"] [unique_id "amuPT0LAyZ1MRInzPMYU0gAAAKQ"]
[Thu Jul 30 12:52:15.705211 2026] [security2:error] [pid 806041:tid 806202] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/as.php"] [unique_id "amuPT0LAyZ1MRInzPMYU0gAAAKQ"]
[Thu Jul 30 12:52:15.775016 2026] [security2:error] [pid 806041:tid 806075] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPT0LAyZ1MRInzPMYU1gAAyiE"]
[Thu Jul 30 12:52:15.775171 2026] [security2:error] [pid 806041:tid 806240] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPT0LAyZ1MRInzPMYU1gAAyiE"]
[Thu Jul 30 12:52:16.005639 2026] [security2:error] [pid 806041:tid 806270] [client 20.151.221.234:41060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuPUELAyZ1MRInzPMYU2AAAAOg"]
[Thu Jul 30 12:52:16.228657 2026] [security2:error] [pid 806041:tid 806259] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/k.php"] [unique_id "amuPUELAyZ1MRInzPMYU3wAAAN0"]
[Thu Jul 30 12:52:16.228759 2026] [security2:error] [pid 806041:tid 806259] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/k.php"] [unique_id "amuPUELAyZ1MRInzPMYU3wAAAN0"]
[Thu Jul 30 12:52:16.308366 2026] [security2:error] [pid 806041:tid 806298] [client 52.73.6.26:45982] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.ejournalugj.com"] [uri "/robots.txt"] [unique_id "amuPUELAyZ1MRInzPMYU4wAAAQQ"]
[Thu Jul 30 12:52:16.392067 2026] [core:notice] [pid 806041:tid 806265] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:16.398676 2026] [security2:error] [pid 806041:tid 806265] [client 103.215.74.26:45414] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPUELAyZ1MRInzPMYU5AAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:16.716211 2026] [security2:error] [pid 806041:tid 806208] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/system_log.php"] [unique_id "amuPUELAyZ1MRInzPMYU7gAAAKo"]
[Thu Jul 30 12:52:16.716312 2026] [security2:error] [pid 806041:tid 806208] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/system_log.php"] [unique_id "amuPUELAyZ1MRInzPMYU7gAAAKo"]
[Thu Jul 30 12:52:17.037512 2026] [security2:error] [pid 806041:tid 806249] [client 66.249.73.131:48168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuPTkLAyZ1MRInzPMYUuwAAANM"]
[Thu Jul 30 12:52:17.041212 2026] [security2:error] [pid 806041:tid 806244] [client 20.151.221.234:41062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/m.php"] [unique_id "amuPUULAyZ1MRInzPMYU9wAAAM4"]
[Thu Jul 30 12:52:17.130073 2026] [core:notice] [pid 806041:tid 806222] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:17.136607 2026] [security2:error] [pid 806041:tid 806222] [client 103.215.74.26:45426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPUULAyZ1MRInzPMYU-AAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:17.289425 2026] [security2:error] [pid 806041:tid 806218] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/x.php"] [unique_id "amuPUULAyZ1MRInzPMYU_QAAALQ"]
[Thu Jul 30 12:52:17.289523 2026] [security2:error] [pid 806041:tid 806218] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/x.php"] [unique_id "amuPUULAyZ1MRInzPMYU_QAAALQ"]
[Thu Jul 30 12:52:17.793378 2026] [security2:error] [pid 806041:tid 806258] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/autoload_classmap.php"] [unique_id "amuPUULAyZ1MRInzPMYVCwAAANw"]
[Thu Jul 30 12:52:17.793495 2026] [security2:error] [pid 806041:tid 806258] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/autoload_classmap.php"] [unique_id "amuPUULAyZ1MRInzPMYVCwAAANw"]
[Thu Jul 30 12:52:17.865871 2026] [core:notice] [pid 806041:tid 806245] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:17.872254 2026] [security2:error] [pid 806041:tid 806245] [client 103.215.74.26:45434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPUULAyZ1MRInzPMYVDwAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:18.301929 2026] [security2:error] [pid 806041:tid 806193] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/test1.php"] [unique_id "amuPUkLAyZ1MRInzPMYVFwAAAJs"]
[Thu Jul 30 12:52:18.302037 2026] [security2:error] [pid 806041:tid 806193] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/test1.php"] [unique_id "amuPUkLAyZ1MRInzPMYVFwAAAJs"]
[Thu Jul 30 12:52:18.560944 2026] [core:notice] [pid 806041:tid 806210] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:18.622271 2026] [core:notice] [pid 806041:tid 806186] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:18.628534 2026] [security2:error] [pid 806041:tid 806186] [client 103.215.74.26:45448] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPUkLAyZ1MRInzPMYVIQAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:18.752861 2026] [security2:error] [pid 806041:tid 806296] [client 20.151.221.234:22638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/send.php"] [unique_id "amuPUkLAyZ1MRInzPMYVIwAAAQI"]
[Thu Jul 30 12:52:18.857576 2026] [security2:error] [pid 806041:tid 806176] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.bestdogproductguide.com"] [uri "/___proxy_subdomain_webdisk/mini"] [unique_id "amuPUkLAyZ1MRInzPMYVJwAAAIo"]
[Thu Jul 30 12:52:19.159836 2026] [security2:error] [pid 806041:tid 806289] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-signin.php"] [unique_id "amuPU0LAyZ1MRInzPMYVNAAAAPs"]
[Thu Jul 30 12:52:19.159934 2026] [security2:error] [pid 806041:tid 806289] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-signin.php"] [unique_id "amuPU0LAyZ1MRInzPMYVNAAAAPs"]
[Thu Jul 30 12:52:19.188159 2026] [security2:error] [pid 806041:tid 806291] [client 20.151.221.234:63109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuPUkLAyZ1MRInzPMYVLAAAAP0"]
[Thu Jul 30 12:52:19.730795 2026] [security2:error] [pid 806041:tid 806218] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/gg.php"] [unique_id "amuPU0LAyZ1MRInzPMYVPwAAALQ"]
[Thu Jul 30 12:52:19.730919 2026] [security2:error] [pid 806041:tid 806218] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/gg.php"] [unique_id "amuPU0LAyZ1MRInzPMYVPwAAALQ"]
[Thu Jul 30 12:52:19.868583 2026] [core:notice] [pid 806041:tid 806244] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:20.072790 2026] [security2:error] [pid 806041:tid 806190] [client 20.151.221.234:22592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuPVELAyZ1MRInzPMYVUgAAAJg"]
[Thu Jul 30 12:52:20.292658 2026] [security2:error] [pid 806041:tid 806215] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/class.php"] [unique_id "amuPVELAyZ1MRInzPMYVVgAAALE"]
[Thu Jul 30 12:52:20.292751 2026] [security2:error] [pid 806041:tid 806215] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/class.php"] [unique_id "amuPVELAyZ1MRInzPMYVVgAAALE"]
[Thu Jul 30 12:52:20.462789 2026] [security2:error] [pid 806041:tid 806224] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPU0LAyZ1MRInzPMYVRQAAALo"]
[Thu Jul 30 12:52:20.860379 2026] [security2:error] [pid 806041:tid 806263] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/404.php"] [unique_id "amuPVELAyZ1MRInzPMYVdwAAAOE"]
[Thu Jul 30 12:52:20.860492 2026] [security2:error] [pid 806041:tid 806263] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/404.php"] [unique_id "amuPVELAyZ1MRInzPMYVdwAAAOE"]
[Thu Jul 30 12:52:20.968040 2026] [autoindex:error] [pid 806041:tid 806282] [client 20.151.221.234:46170] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:21.226514 2026] [security2:error] [pid 806041:tid 806248] [client 20.151.221.234:46170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/classwithtostring.php"] [unique_id "amuPVULAyZ1MRInzPMYVkQAAANI"]
[Thu Jul 30 12:52:21.329147 2026] [security2:error] [pid 806041:tid 806208] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPVELAyZ1MRInzPMYVdAAAAKo"]
[Thu Jul 30 12:52:21.410324 2026] [security2:error] [pid 806041:tid 806244] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/lite.php"] [unique_id "amuPVULAyZ1MRInzPMYVlgAAAM4"]
[Thu Jul 30 12:52:21.410429 2026] [security2:error] [pid 806041:tid 806244] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/lite.php"] [unique_id "amuPVULAyZ1MRInzPMYVlgAAAM4"]
[Thu Jul 30 12:52:21.627997 2026] [security2:error] [pid 806041:tid 806183] [client 150.107.232.194:27252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPVULAyZ1MRInzPMYVpAAAAJE"]
[Thu Jul 30 12:52:21.628102 2026] [security2:error] [pid 806041:tid 806183] [client 150.107.232.194:27252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPVULAyZ1MRInzPMYVpAAAAJE"]
[Thu Jul 30 12:52:21.794093 2026] [security2:error] [pid 806041:tid 806260] [client 3.220.70.171:16365] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/issue/current"] [unique_id "amuPVULAyZ1MRInzPMYVqwAAAN4"]
[Thu Jul 30 12:52:21.926913 2026] [security2:error] [pid 806041:tid 806175] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/lock360.php"] [unique_id "amuPVULAyZ1MRInzPMYVsAAAAIk"]
[Thu Jul 30 12:52:21.927025 2026] [security2:error] [pid 806041:tid 806175] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/lock360.php"] [unique_id "amuPVULAyZ1MRInzPMYVsAAAAIk"]
[Thu Jul 30 12:52:22.483590 2026] [security2:error] [pid 806041:tid 806180] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuPVkLAyZ1MRInzPMYVzgAAAI4"]
[Thu Jul 30 12:52:22.483678 2026] [security2:error] [pid 806041:tid 806180] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuPVkLAyZ1MRInzPMYVzgAAAI4"]
[Thu Jul 30 12:52:22.813474 2026] [core:notice] [pid 806041:tid 806139] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:23.053372 2026] [security2:error] [pid 806041:tid 806171] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-links-opml.php"] [unique_id "amuPV0LAyZ1MRInzPMYV6wAAAIU"]
[Thu Jul 30 12:52:23.053474 2026] [security2:error] [pid 806041:tid 806171] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-links-opml.php"] [unique_id "amuPV0LAyZ1MRInzPMYV6wAAAIU"]
[Thu Jul 30 12:52:23.557086 2026] [security2:error] [pid 806041:tid 806257] [client 172.212.190.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/uploads/min.php"] [unique_id "amuPV0LAyZ1MRInzPMYV_wAAANs"]
[Thu Jul 30 12:52:23.557173 2026] [security2:error] [pid 806041:tid 806257] [client 172.212.190.89:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.bestdogproductguide.com"] [uri "/wp-content/uploads/min.php"] [unique_id "amuPV0LAyZ1MRInzPMYV_wAAANs"]
[Thu Jul 30 12:52:23.828650 2026] [security2:error] [pid 806041:tid 806210] [client 20.151.221.234:48997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/gmo.php"] [unique_id "amuPV0LAyZ1MRInzPMYWBwAAAKw"]
[Thu Jul 30 12:52:24.423467 2026] [core:notice] [pid 806041:tid 806177] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:24.430813 2026] [security2:error] [pid 806041:tid 806177] [client 103.215.74.26:41362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPWELAyZ1MRInzPMYWEwAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:24.594576 2026] [core:notice] [pid 806041:tid 806298] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:25.023201 2026] [security2:error] [pid 806041:tid 806292] [client 20.151.221.234:16914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuPWULAyZ1MRInzPMYWHwAAAP4"]
[Thu Jul 30 12:52:25.164310 2026] [core:notice] [pid 806041:tid 806278] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:25.170533 2026] [security2:error] [pid 806041:tid 806278] [client 103.215.74.26:41410] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPWULAyZ1MRInzPMYWJgAAAPA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:25.232908 2026] [security2:error] [pid 806041:tid 806144] [remote 57.141.0.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuPWULAyZ1MRInzPMYWKgAA5mY"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,linen,nylon,plastic,polyester,steel,titanium,wood&filter_size=extra-large&rating=5&status=instock&unfilter=1
[Thu Jul 30 12:52:25.243455 2026] [security2:error] [pid 806041:tid 806136] [remote 57.141.0.64:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuPWULAyZ1MRInzPMYWKwAAzV4"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,linen,nylon,plastic,polyester,steel,titanium,wood&filter_size=extra-large&rating=5&status=instock&unfilter=1
[Thu Jul 30 12:52:25.534497 2026] [security2:error] [pid 806041:tid 806218] [client 20.151.221.234:22617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/about.php"] [unique_id "amuPWULAyZ1MRInzPMYWLAAAALQ"]
[Thu Jul 30 12:52:25.710666 2026] [core:notice] [pid 806041:tid 806250] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:25.847531 2026] [security2:error] [pid 806041:tid 806241] [client 20.151.221.234:16907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-the.php"] [unique_id "amuPWULAyZ1MRInzPMYWNwAAAMs"]
[Thu Jul 30 12:52:25.911127 2026] [core:notice] [pid 806041:tid 806256] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:25.917438 2026] [security2:error] [pid 806041:tid 806256] [client 103.215.74.26:41466] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPWULAyZ1MRInzPMYWOAAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:26.587517 2026] [security2:error] [pid 806041:tid 806140] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPWkLAyZ1MRInzPMYWRQAA8mI"]
[Thu Jul 30 12:52:26.587677 2026] [security2:error] [pid 806041:tid 806280] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPWkLAyZ1MRInzPMYWRQAA8mI"]
[Thu Jul 30 12:52:26.629234 2026] [security2:error] [pid 806041:tid 806221] [client 20.151.221.234:46215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/404.php"] [unique_id "amuPWkLAyZ1MRInzPMYWSQAAALc"]
[Thu Jul 30 12:52:26.666912 2026] [core:notice] [pid 806041:tid 806227] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:26.673241 2026] [security2:error] [pid 806041:tid 806227] [client 103.215.74.26:41512] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPWkLAyZ1MRInzPMYWSgAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:26.819083 2026] [security2:error] [pid 806041:tid 806231] [client 20.151.221.234:22808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/options.php"] [unique_id "amuPWkLAyZ1MRInzPMYWVAAAAME"]
[Thu Jul 30 12:52:27.057382 2026] [security2:error] [pid 806041:tid 806134] [remote 57.141.0.49:43710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuPW0LAyZ1MRInzPMYWVQAApVw"]
[Thu Jul 30 12:52:27.330056 2026] [security2:error] [pid 806041:tid 806259] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPWkLAyZ1MRInzPMYWRAAA3Wg"]
[Thu Jul 30 12:52:27.399935 2026] [core:notice] [pid 806041:tid 806269] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:27.406284 2026] [security2:error] [pid 806041:tid 806269] [client 103.215.74.26:41566] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPW0LAyZ1MRInzPMYWXwAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:27.954747 2026] [security2:error] [pid 806041:tid 806222] [client 20.151.221.234:13308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/init.php"] [unique_id "amuPW0LAyZ1MRInzPMYWbQAAALg"]
[Thu Jul 30 12:52:28.178349 2026] [core:notice] [pid 806041:tid 806202] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:28.184677 2026] [security2:error] [pid 806041:tid 806202] [client 103.215.74.26:41588] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPXELAyZ1MRInzPMYWbgAAAKQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:28.649449 2026] [fcgid:warn] [pid 806041:tid 806207] (70014)End of file found: [client 156.229.16.142:52066] mod_fcgid: can't get data from http client
[Thu Jul 30 12:52:28.886153 2026] [security2:error] [pid 806041:tid 806296] [client 20.151.221.234:46238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/file5.php"] [unique_id "amuPXELAyZ1MRInzPMYWgwAAAQI"]
[Thu Jul 30 12:52:28.906690 2026] [core:notice] [pid 806041:tid 806265] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:28.913761 2026] [security2:error] [pid 806041:tid 806265] [client 103.215.74.26:41598] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPXELAyZ1MRInzPMYWhwAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:30.204266 2026] [security2:error] [pid 806041:tid 806249] [client 20.151.221.234:13294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuPXkLAyZ1MRInzPMYWoAAAANM"]
[Thu Jul 30 12:52:30.292562 2026] [security2:error] [pid 806041:tid 806282] [client 121.237.36.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuPXULAyZ1MRInzPMYWmwAAAPQ"]
[Thu Jul 30 12:52:30.485058 2026] [security2:error] [pid 806041:tid 806239] [client 20.151.221.234:22786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuPXkLAyZ1MRInzPMYWrAAAAMk"]
[Thu Jul 30 12:52:31.202138 2026] [security2:error] [pid 806041:tid 806176] [client 20.151.221.234:46231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/shell.php"] [unique_id "amuPX0LAyZ1MRInzPMYWuwAAAIo"]
[Thu Jul 30 12:52:31.596494 2026] [security2:error] [pid 806041:tid 806179] [client 43.173.173.196:59346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/02/ballerines-ete-2013/"] [unique_id "amuPX0LAyZ1MRInzPMYWvAAAAI0"]
[Thu Jul 30 12:52:32.096972 2026] [security2:error] [pid 806041:tid 806289] [client 150.107.232.194:27082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPYELAyZ1MRInzPMYWzgAAAPs"]
[Thu Jul 30 12:52:32.097089 2026] [security2:error] [pid 806041:tid 806289] [client 150.107.232.194:27082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPYELAyZ1MRInzPMYWzgAAAPs"]
[Thu Jul 30 12:52:32.283463 2026] [core:notice] [pid 806041:tid 806228] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:32.288352 2026] [security2:error] [pid 806041:tid 806228] [client 43.173.178.183:57552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/02/ballerines-ete-2013/"] [unique_id "amuPYELAyZ1MRInzPMYW0AAAAL4"], referer: https://carnetdeshopping.com/index.php/2013/05/02/ballerines-ete-2013/
[Thu Jul 30 12:52:32.347726 2026] [proxy:error] [pid 806041:tid 806203] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:32.347781 2026] [proxy_http:error] [pid 806041:tid 806203] [client 98.87.102.177:53313] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:32.348463 2026] [proxy:error] [pid 806041:tid 806203] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:32.348509 2026] [proxy_http:error] [pid 806041:tid 806203] [client 98.87.102.177:53313] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:32.406523 2026] [proxy:error] [pid 806041:tid 806230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:32.406616 2026] [proxy_http:error] [pid 806041:tid 806230] [client 98.87.102.177:58856] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:32.407516 2026] [proxy:error] [pid 806041:tid 806230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:32.407573 2026] [proxy_http:error] [pid 806041:tid 806230] [client 98.87.102.177:58856] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:32.545529 2026] [security2:error] [pid 806041:tid 806246] [client 220.181.108.103:36462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Grage/about"] [unique_id "amuPYELAyZ1MRInzPMYW3QAAANA"]
[Thu Jul 30 12:52:33.502869 2026] [security2:error] [pid 806041:tid 806175] [client 20.151.221.234:16940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/f35.php"] [unique_id "amuPYULAyZ1MRInzPMYW-QAAAIk"]
[Thu Jul 30 12:52:33.537132 2026] [core:notice] [pid 806041:tid 806254] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:33.745516 2026] [proxy:error] [pid 806041:tid 806280] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:33.745598 2026] [proxy_http:error] [pid 806041:tid 806280] [client 18.211.55.47:19936] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:33.745701 2026] [proxy:error] [pid 806041:tid 806186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:33.745762 2026] [proxy_http:error] [pid 806041:tid 806186] [client 18.211.55.47:27896] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:33.746216 2026] [proxy:error] [pid 806041:tid 806280] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:33.746263 2026] [proxy_http:error] [pid 806041:tid 806280] [client 18.211.55.47:19936] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:33.746591 2026] [proxy:error] [pid 806041:tid 806186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:33.746648 2026] [proxy_http:error] [pid 806041:tid 806186] [client 18.211.55.47:27896] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:34.235103 2026] [security2:error] [pid 806041:tid 806178] [client 129.204.118.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuPYULAyZ1MRInzPMYW9gAAAIw"]
[Thu Jul 30 12:52:34.569759 2026] [security2:error] [pid 806041:tid 806081] [remote 103.82.22.235:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuPYkLAyZ1MRInzPMYXEAAA_Sc"]
[Thu Jul 30 12:52:34.721206 2026] [core:notice] [pid 806041:tid 806279] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:34.728750 2026] [security2:error] [pid 806041:tid 806279] [client 103.215.74.26:64274] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPYkLAyZ1MRInzPMYXHwAAAPE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:35.347431 2026] [security2:error] [pid 806041:tid 806214] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPYkLAyZ1MRInzPMYXIAAAALA"]
[Thu Jul 30 12:52:36.153454 2026] [security2:error] [pid 806041:tid 806243] [client 20.151.221.234:16904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/new.php"] [unique_id "amuPZELAyZ1MRInzPMYXPAAAAM0"]
[Thu Jul 30 12:52:36.289199 2026] [proxy:error] [pid 806041:tid 806179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:36.289262 2026] [proxy_http:error] [pid 806041:tid 806179] [client 3.228.112.215:32663] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:36.289817 2026] [proxy:error] [pid 806041:tid 806179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:36.289861 2026] [proxy_http:error] [pid 806041:tid 806179] [client 3.228.112.215:32663] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:36.345272 2026] [proxy:error] [pid 806041:tid 806227] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:36.345363 2026] [proxy_http:error] [pid 806041:tid 806227] [client 3.228.112.215:42332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:36.345930 2026] [proxy:error] [pid 806041:tid 806227] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:52:36.345989 2026] [proxy_http:error] [pid 806041:tid 806227] [client 3.228.112.215:42332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:52:36.386971 2026] [security2:error] [pid 806041:tid 806293] [client 20.151.221.234:33970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/wp-file.php"] [unique_id "amuPZELAyZ1MRInzPMYXRwAAAP8"]
[Thu Jul 30 12:52:37.300655 2026] [security2:error] [pid 806041:tid 806112] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPZULAyZ1MRInzPMYXbQAA9EY"]
[Thu Jul 30 12:52:37.300813 2026] [security2:error] [pid 806041:tid 806282] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPZULAyZ1MRInzPMYXbQAA9EY"]
[Thu Jul 30 12:52:37.428523 2026] [security2:error] [pid 806041:tid 806261] [client 20.151.221.234:46213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/adminfuns.php"] [unique_id "amuPZULAyZ1MRInzPMYXcQAAAN8"]
[Thu Jul 30 12:52:38.657836 2026] [security2:error] [pid 806041:tid 806221] [client 185.191.171.3:16610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/17/ministro-do-stf-decide-que-icms-de-combustiveis-deve-ser-unificado-no-pais/"] [unique_id "amuPZkLAyZ1MRInzPMYXsgAAALc"]
[Thu Jul 30 12:52:38.658016 2026] [security2:error] [pid 806041:tid 806221] [client 185.191.171.3:16610] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/17/ministro-do-stf-decide-que-icms-de-combustiveis-deve-ser-unificado-no-pais/"] [unique_id "amuPZkLAyZ1MRInzPMYXsgAAALc"]
[Thu Jul 30 12:52:39.649340 2026] [security2:error] [pid 806041:tid 806042] [remote 103.28.36.199:48418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/wp-login.php"] [unique_id "amuPZ0LAyZ1MRInzPMYX2AAA_QA"]
[Thu Jul 30 12:52:39.803934 2026] [fcgid:warn] [pid 806041:tid 806193] (70014)End of file found: [client 107.150.117.121:56176] mod_fcgid: can't get data from http client
[Thu Jul 30 12:52:39.919208 2026] [security2:error] [pid 806041:tid 806250] [client 172.236.9.101:62280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPZ0LAyZ1MRInzPMYXzQAAANQ"]
[Thu Jul 30 12:52:40.453729 2026] [autoindex:error] [pid 806041:tid 806297] [client 20.151.221.234:16924] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:40.453818 2026] [core:notice] [pid 806041:tid 806176] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:40.460007 2026] [security2:error] [pid 806041:tid 806176] [client 103.215.74.26:64278] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPaELAyZ1MRInzPMYX7gAAAIo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:40.651011 2026] [security2:error] [pid 806041:tid 806237] [client 20.151.221.234:16924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/fm.php"] [unique_id "amuPaELAyZ1MRInzPMYX8gAAAMc"]
[Thu Jul 30 12:52:41.196522 2026] [core:notice] [pid 806041:tid 806268] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:41.207626 2026] [security2:error] [pid 806041:tid 806268] [client 103.215.74.26:64292] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPaULAyZ1MRInzPMYX_AAAAOY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:41.920459 2026] [core:notice] [pid 806041:tid 806283] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:41.927109 2026] [security2:error] [pid 806041:tid 806283] [client 103.215.74.26:64294] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPaULAyZ1MRInzPMYYCwAAAPU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:42.099272 2026] [security2:error] [pid 806041:tid 806209] [client 20.151.221.234:16923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/file.php"] [unique_id "amuPakLAyZ1MRInzPMYYFQAAAKs"]
[Thu Jul 30 12:52:42.563085 2026] [security2:error] [pid 806041:tid 806297] [client 150.107.232.194:27244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPakLAyZ1MRInzPMYYHwAAAQM"]
[Thu Jul 30 12:52:42.563188 2026] [security2:error] [pid 806041:tid 806297] [client 150.107.232.194:27244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPakLAyZ1MRInzPMYYHwAAAQM"]
[Thu Jul 30 12:52:42.704639 2026] [core:notice] [pid 806041:tid 806185] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:42.711030 2026] [security2:error] [pid 806041:tid 806185] [client 103.215.74.26:64300] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPakLAyZ1MRInzPMYYJAAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:43.437411 2026] [core:notice] [pid 806041:tid 806290] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:43.443649 2026] [security2:error] [pid 806041:tid 806290] [client 103.215.74.26:25388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPa0LAyZ1MRInzPMYYMgAAAPw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:43.595659 2026] [security2:error] [pid 806041:tid 806259] [client 20.151.221.234:52245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.laduchessecollections.com"] [uri "/sid3.php"] [unique_id "amuPa0LAyZ1MRInzPMYYPgAAAN0"]
[Thu Jul 30 12:52:44.180084 2026] [core:notice] [pid 806041:tid 806198] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:44.187401 2026] [security2:error] [pid 806041:tid 806198] [client 103.215.74.26:25404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPbELAyZ1MRInzPMYYTQAAAKA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:44.253886 2026] [autoindex:error] [pid 806041:tid 806200] [client 20.151.221.234:46162] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:44.526030 2026] [security2:error] [pid 806041:tid 806193] [client 20.151.221.234:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/bolt.php"] [unique_id "amuPbELAyZ1MRInzPMYYVQAAAJs"]
[Thu Jul 30 12:52:44.850169 2026] [security2:error] [pid 806041:tid 806253] [client 156.229.16.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-137a15f9.brx.dtn.temporary.site"] [uri "/index.php"] [unique_id "amuPbELAyZ1MRInzPMYYXgAAANc"]
[Thu Jul 30 12:52:44.892816 2026] [security2:error] [pid 806041:tid 806206] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPbELAyZ1MRInzPMYYUQAAAKg"]
[Thu Jul 30 12:52:45.515715 2026] [security2:error] [pid 806041:tid 806187] [client 20.151.221.234:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/3.php"] [unique_id "amuPbULAyZ1MRInzPMYYcAAAAJU"]
[Thu Jul 30 12:52:45.791610 2026] [security2:error] [pid 806041:tid 806232] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPbULAyZ1MRInzPMYYbAAAAMI"]
[Thu Jul 30 12:52:46.206626 2026] [core:notice] [pid 806041:tid 806266] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:46.563061 2026] [security2:error] [pid 806041:tid 806278] [client 20.151.221.234:16920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/222.php"] [unique_id "amuPbkLAyZ1MRInzPMYYhwAAAPA"]
[Thu Jul 30 12:52:47.015630 2026] [core:notice] [pid 806041:tid 806094] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:47.030843 2026] [security2:error] [pid 806041:tid 806078] [remote 168.144.81.91:35348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.81.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuPb0LAyZ1MRInzPMYYlQAA3yQ"]
[Thu Jul 30 12:52:47.575648 2026] [security2:error] [pid 806041:tid 806241] [client 20.151.221.234:13279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuPb0LAyZ1MRInzPMYYoAAAAMs"]
[Thu Jul 30 12:52:48.134663 2026] [security2:error] [pid 806041:tid 806096] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPcELAyZ1MRInzPMYYsQAAhzY"]
[Thu Jul 30 12:52:48.134815 2026] [security2:error] [pid 806041:tid 806173] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPcELAyZ1MRInzPMYYsQAAhzY"]
[Thu Jul 30 12:52:48.136183 2026] [security2:error] [pid 806041:tid 806270] [client 47.128.36.197:18022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/robots.txt"] [unique_id "amuPcELAyZ1MRInzPMYYsgAAAOg"]
[Thu Jul 30 12:52:48.247968 2026] [security2:error] [pid 806041:tid 806099] [remote 74.7.241.60:42672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amuPcELAyZ1MRInzPMYYuQAAjDk"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 12:52:48.462335 2026] [security2:error] [pid 806041:tid 806228] [client 20.151.221.234:46157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuPcELAyZ1MRInzPMYYvgAAAL4"]
[Thu Jul 30 12:52:49.461373 2026] [autoindex:error] [pid 806041:tid 806192] [client 20.151.221.234:13257] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:49.905927 2026] [core:notice] [pid 806041:tid 806277] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:49.912389 2026] [security2:error] [pid 806041:tid 806277] [client 103.215.74.26:25416] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPcULAyZ1MRInzPMYY4wAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:50.031135 2026] [security2:error] [pid 806041:tid 806294] [client 20.151.221.234:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/admin.php"] [unique_id "amuPckLAyZ1MRInzPMYY5wAAAQA"]
[Thu Jul 30 12:52:50.655370 2026] [security2:error] [pid 806041:tid 806223] [client 40.77.167.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuPcELAyZ1MRInzPMYYwgAAALk"]
[Thu Jul 30 12:52:50.662385 2026] [core:notice] [pid 806041:tid 806221] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:50.668709 2026] [security2:error] [pid 806041:tid 806221] [client 103.215.74.26:25426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPckLAyZ1MRInzPMYY9gAAALc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:51.116668 2026] [core:error] [pid 806041:tid 806198] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.116689 2026] [core:error] [pid 806041:tid 806198] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.132065 2026] [core:error] [pid 806041:tid 806211] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.132082 2026] [core:error] [pid 806041:tid 806211] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.138562 2026] [core:error] [pid 806041:tid 806256] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.138578 2026] [core:error] [pid 806041:tid 806256] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.150395 2026] [core:error] [pid 806041:tid 806191] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.150415 2026] [core:error] [pid 806041:tid 806191] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.170276 2026] [core:error] [pid 806041:tid 806235] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.170295 2026] [core:error] [pid 806041:tid 806235] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:52:51.335563 2026] [security2:error] [pid 806041:tid 806189] [client 217.138.252.123:49942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.252.138.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuPc0LAyZ1MRInzPMYZHQAAAJc"]
[Thu Jul 30 12:52:51.335666 2026] [security2:error] [pid 806041:tid 806189] [client 217.138.252.123:49942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuPc0LAyZ1MRInzPMYZHQAAAJc"]
[Thu Jul 30 12:52:51.400686 2026] [core:notice] [pid 806041:tid 806225] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:51.406619 2026] [security2:error] [pid 806041:tid 806225] [client 103.215.74.26:25438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPc0LAyZ1MRInzPMYZHwAAALs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:51.848576 2026] [core:notice] [pid 806041:tid 806260] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:51.873639 2026] [core:notice] [pid 806041:tid 806197] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:52.177599 2026] [core:notice] [pid 806041:tid 806269] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:52.184338 2026] [security2:error] [pid 806041:tid 806269] [client 103.215.74.26:25448] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPdELAyZ1MRInzPMYZQAAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:52.527121 2026] [autoindex:error] [pid 806041:tid 806203] [client 82.156.34.74:48356] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:52.621973 2026] [security2:error] [pid 806041:tid 806212] [client 20.151.221.234:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-configs.php"] [unique_id "amuPdELAyZ1MRInzPMYZTwAAAK4"]
[Thu Jul 30 12:52:52.908402 2026] [core:notice] [pid 806041:tid 806245] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:52.913919 2026] [security2:error] [pid 806041:tid 806245] [client 103.215.74.26:25464] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPdELAyZ1MRInzPMYZVwAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:53.031628 2026] [security2:error] [pid 806041:tid 806233] [client 150.107.232.194:26926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPdULAyZ1MRInzPMYZWwAAAMM"]
[Thu Jul 30 12:52:53.031766 2026] [security2:error] [pid 806041:tid 806233] [client 150.107.232.194:26926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPdULAyZ1MRInzPMYZWwAAAMM"]
[Thu Jul 30 12:52:53.486790 2026] [security2:error] [pid 806041:tid 806213] [client 20.151.221.234:16937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/php.php"] [unique_id "amuPdULAyZ1MRInzPMYZYgAAAK8"]
[Thu Jul 30 12:52:53.639617 2026] [core:notice] [pid 806041:tid 806220] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:53.649924 2026] [security2:error] [pid 806041:tid 806220] [client 103.215.74.26:38216] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPdULAyZ1MRInzPMYZbAAAALY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:53.703526 2026] [security2:error] [pid 806041:tid 806268] [client 107.150.117.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "website-32717c4b.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuPdULAyZ1MRInzPMYZawAAAOY"]
[Thu Jul 30 12:52:54.391012 2026] [core:notice] [pid 806041:tid 806172] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:54.397433 2026] [security2:error] [pid 806041:tid 806172] [client 103.215.74.26:38232] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPdkLAyZ1MRInzPMYZfwAAAIY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:54.756385 2026] [security2:error] [pid 806041:tid 806226] [client 172.236.9.101:10034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPdkLAyZ1MRInzPMYZfQAAALw"]
[Thu Jul 30 12:52:55.134490 2026] [core:notice] [pid 806041:tid 806190] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:52:55.141740 2026] [security2:error] [pid 806041:tid 806190] [client 103.215.74.26:38238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPd0LAyZ1MRInzPMYZkgAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:52:56.271961 2026] [security2:error] [pid 806041:tid 806275] [client 172.236.9.101:27035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-content/w3tc/dbcache/" at Request_URI. [file "/opt/mod_security/hg_rules.conf"] [line "894"] [id "900094"] [msg "WP DB Cache Block"] [hostname "alseermarine.com"] [uri "/wp-content/w3tc/dbcache/"] [unique_id "amuPeELAyZ1MRInzPMYZqgAAAO0"]
[Thu Jul 30 12:52:56.374375 2026] [security2:error] [pid 806041:tid 806290] [client 20.151.221.234:46151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/index.php"] [unique_id "amuPeELAyZ1MRInzPMYZqwAAAPw"]
[Thu Jul 30 12:52:58.616718 2026] [security2:error] [pid 806041:tid 806233] [client 20.151.221.234:43969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/a.php"] [unique_id "amuPekLAyZ1MRInzPMYZ3QAAAMM"]
[Thu Jul 30 12:52:58.994263 2026] [security2:error] [pid 806041:tid 806060] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPekLAyZ1MRInzPMYZ5wABARI"]
[Thu Jul 30 12:52:58.994453 2026] [security2:error] [pid 806041:tid 806295] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPekLAyZ1MRInzPMYZ5wABARI"]
[Thu Jul 30 12:52:59.630874 2026] [autoindex:error] [pid 806041:tid 806280] [client 20.151.221.234:44362] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:52:59.742278 2026] [security2:error] [pid 806041:tid 806232] [client 172.236.9.101:52938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPe0LAyZ1MRInzPMYZ7gAAAMI"]
[Thu Jul 30 12:52:59.879883 2026] [autoindex:error] [pid 806041:tid 806264] [client 20.151.221.234:44362] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:00.003610 2026] [core:notice] [pid 806041:tid 806239] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:00.116683 2026] [security2:error] [pid 806041:tid 806261] [client 20.151.221.234:44362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuPfELAyZ1MRInzPMYaBQAAAN8"]
[Thu Jul 30 12:53:00.897041 2026] [security2:error] [pid 806041:tid 806244] [client 20.151.221.234:44023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin.php"] [unique_id "amuPfELAyZ1MRInzPMYaEwAAAM4"]
[Thu Jul 30 12:53:00.914823 2026] [core:notice] [pid 806041:tid 806262] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:00.921319 2026] [security2:error] [pid 806041:tid 806262] [client 103.215.74.26:38244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPfELAyZ1MRInzPMYaFQAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:01.670953 2026] [core:notice] [pid 806041:tid 806289] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:01.678283 2026] [security2:error] [pid 806041:tid 806289] [client 103.215.74.26:38260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPfULAyZ1MRInzPMYaJwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:01.742360 2026] [security2:error] [pid 806041:tid 806287] [client 172.236.9.101:29579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPfULAyZ1MRInzPMYaHwAAAPk"]
[Thu Jul 30 12:53:02.417378 2026] [core:notice] [pid 806041:tid 806242] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:02.425840 2026] [security2:error] [pid 806041:tid 806242] [client 103.215.74.26:38272] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPfkLAyZ1MRInzPMYaPQAAAMw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:02.475918 2026] [security2:error] [pid 806041:tid 806178] [client 20.151.221.234:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/size.php"] [unique_id "amuPfkLAyZ1MRInzPMYaQQAAAIw"]
[Thu Jul 30 12:53:02.593309 2026] [security2:error] [pid 806041:tid 806273] [client 172.236.9.101:30187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPfkLAyZ1MRInzPMYaOwAAAOs"]
[Thu Jul 30 12:53:02.753475 2026] [security2:error] [pid 806041:tid 806049] [remote 57.141.0.36:21784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuPfkLAyZ1MRInzPMYaSgAAhgc"]
[Thu Jul 30 12:53:03.153132 2026] [core:notice] [pid 806041:tid 806281] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:03.159421 2026] [security2:error] [pid 806041:tid 806281] [client 103.215.74.26:3486] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPf0LAyZ1MRInzPMYaUwAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:03.507017 2026] [security2:error] [pid 806041:tid 806219] [client 150.107.232.194:26698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPf0LAyZ1MRInzPMYaagAAALU"]
[Thu Jul 30 12:53:03.507183 2026] [security2:error] [pid 806041:tid 806219] [client 150.107.232.194:26698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPf0LAyZ1MRInzPMYaagAAALU"]
[Thu Jul 30 12:53:03.795311 2026] [security2:error] [pid 806041:tid 806294] [client 34.198.201.66:10680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuPf0LAyZ1MRInzPMYabQAAAQA"], referer: https://globalmarks.pk/
[Thu Jul 30 12:53:03.808675 2026] [proxy:error] [pid 806041:tid 806202] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:53:03.808758 2026] [proxy_http:error] [pid 806041:tid 806202] [client 143.244.57.82:52110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:53:03.809374 2026] [proxy:error] [pid 806041:tid 806202] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:53:03.809422 2026] [proxy_http:error] [pid 806041:tid 806202] [client 143.244.57.82:52110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:53:03.883144 2026] [core:notice] [pid 806041:tid 806186] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:03.890116 2026] [security2:error] [pid 806041:tid 806186] [client 103.215.74.26:3488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPf0LAyZ1MRInzPMYagAAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:04.084914 2026] [security2:error] [pid 806041:tid 806118] [remote 57.141.0.50:40572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuPgELAyZ1MRInzPMYahQAAn0w"]
[Thu Jul 30 12:53:04.101971 2026] [proxy:error] [pid 806041:tid 806286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:53:04.102053 2026] [proxy_http:error] [pid 806041:tid 806286] [client 143.244.57.82:52124] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:53:04.102636 2026] [proxy:error] [pid 806041:tid 806286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:53:04.102689 2026] [proxy_http:error] [pid 806041:tid 806286] [client 143.244.57.82:52124] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:53:04.259722 2026] [security2:error] [pid 806041:tid 806175] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPf0LAyZ1MRInzPMYacwAAAIk"]
[Thu Jul 30 12:53:04.392374 2026] [security2:error] [pid 806041:tid 806236] [client 143.244.57.82:52132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuPgELAyZ1MRInzPMYalAAAAMY"]
[Thu Jul 30 12:53:04.645137 2026] [security2:error] [pid 806041:tid 806191] [client 20.151.221.234:43987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuPgELAyZ1MRInzPMYangAAAJk"]
[Thu Jul 30 12:53:04.677823 2026] [security2:error] [pid 806041:tid 806276] [client 143.244.57.82:52134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuPgELAyZ1MRInzPMYanwAAAO4"]
[Thu Jul 30 12:53:04.685282 2026] [core:notice] [pid 806041:tid 806257] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:04.691262 2026] [security2:error] [pid 806041:tid 806257] [client 103.215.74.26:3492] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPgELAyZ1MRInzPMYaoQAAANs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:04.959015 2026] [proxy:error] [pid 806041:tid 806225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:53:04.959080 2026] [proxy_http:error] [pid 806041:tid 806225] [client 143.244.57.82:52146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:53:04.959642 2026] [proxy:error] [pid 806041:tid 806225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:53:04.959684 2026] [proxy_http:error] [pid 806041:tid 806225] [client 143.244.57.82:52146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:53:05.239230 2026] [security2:error] [pid 806041:tid 806220] [client 143.244.57.82:52158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuPgULAyZ1MRInzPMYarwAAALY"]
[Thu Jul 30 12:53:05.453091 2026] [core:notice] [pid 806041:tid 806207] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:05.459426 2026] [security2:error] [pid 806041:tid 806207] [client 103.215.74.26:3494] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPgULAyZ1MRInzPMYatgAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:05.571559 2026] [security2:error] [pid 806041:tid 806270] [client 143.244.57.82:52162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuPgULAyZ1MRInzPMYatwAAAOg"]
[Thu Jul 30 12:53:05.719862 2026] [security2:error] [pid 806041:tid 806193] [client 20.151.221.234:16805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/403.php"] [unique_id "amuPgULAyZ1MRInzPMYauwAAAJs"]
[Thu Jul 30 12:53:05.848150 2026] [security2:error] [pid 806041:tid 806179] [client 143.244.57.82:18344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuPgULAyZ1MRInzPMYawgAAAI0"]
[Thu Jul 30 12:53:06.126679 2026] [security2:error] [pid 806041:tid 806171] [client 143.244.57.82:52182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuPgkLAyZ1MRInzPMYaygAAAIU"]
[Thu Jul 30 12:53:06.408474 2026] [security2:error] [pid 806041:tid 806278] [client 143.244.57.82:52184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuPgkLAyZ1MRInzPMYa0AAAAPA"]
[Thu Jul 30 12:53:06.461422 2026] [security2:error] [pid 806041:tid 806201] [client 20.151.221.234:43991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuPgkLAyZ1MRInzPMYa0QAAAKM"]
[Thu Jul 30 12:53:06.519513 2026] [core:notice] [pid 806041:tid 806246] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:06.689408 2026] [security2:error] [pid 806041:tid 806291] [client 143.244.57.82:52196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuPgkLAyZ1MRInzPMYa2QAAAP0"]
[Thu Jul 30 12:53:06.995362 2026] [security2:error] [pid 806041:tid 806200] [client 143.244.57.82:51456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuPgkLAyZ1MRInzPMYa4AAAAKI"]
[Thu Jul 30 12:53:07.072629 2026] [security2:error] [pid 806041:tid 806238] [client 18.208.137.236:56998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amuPgULAyZ1MRInzPMYaqwAAAMg"]
[Thu Jul 30 12:53:07.311065 2026] [security2:error] [pid 806041:tid 806187] [client 143.244.57.82:51466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuPg0LAyZ1MRInzPMYa5wAAAJU"]
[Thu Jul 30 12:53:07.587988 2026] [security2:error] [pid 806041:tid 806209] [client 143.244.57.82:51472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuPg0LAyZ1MRInzPMYa7gAAAKs"]
[Thu Jul 30 12:53:07.862634 2026] [security2:error] [pid 806041:tid 806271] [client 143.244.57.82:51474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuPg0LAyZ1MRInzPMYa9QAAAOk"]
[Thu Jul 30 12:53:07.978794 2026] [security2:error] [pid 806041:tid 806186] [client 20.151.221.234:16830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/as.php"] [unique_id "amuPg0LAyZ1MRInzPMYa-gAAAJQ"]
[Thu Jul 30 12:53:08.143137 2026] [security2:error] [pid 806041:tid 806223] [client 143.244.57.82:51482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuPhELAyZ1MRInzPMYa_gAAALk"]
[Thu Jul 30 12:53:08.346769 2026] [core:notice] [pid 806041:tid 806183] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:08.425350 2026] [security2:error] [pid 806041:tid 806252] [client 143.244.57.82:51484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuPhELAyZ1MRInzPMYbCQAAANY"]
[Thu Jul 30 12:53:08.706352 2026] [security2:error] [pid 806041:tid 806236] [client 143.244.57.82:51486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuPhELAyZ1MRInzPMYbEQAAAMY"]
[Thu Jul 30 12:53:08.742835 2026] [security2:error] [pid 806041:tid 806233] [client 20.151.221.234:44372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuPhELAyZ1MRInzPMYbFAAAAMM"]
[Thu Jul 30 12:53:08.982218 2026] [security2:error] [pid 806041:tid 806287] [client 143.244.57.82:51494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuPhELAyZ1MRInzPMYbGAAAAPk"]
[Thu Jul 30 12:53:09.071002 2026] [security2:error] [pid 806041:tid 806258] [client 40.77.167.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuPhELAyZ1MRInzPMYbDwAAANw"]
[Thu Jul 30 12:53:09.283122 2026] [security2:error] [pid 806041:tid 806262] [client 143.244.57.82:51508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ste.nyx.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuPhULAyZ1MRInzPMYbIAAAAOA"]
[Thu Jul 30 12:53:09.412163 2026] [security2:error] [pid 806041:tid 806263] [client 145.239.10.137:35319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/shadow-bot.php"] [unique_id "amuPhULAyZ1MRInzPMYbJQAAAOE"], referer: http://dhowcruisedinner.com/shadow-bot.php
[Thu Jul 30 12:53:09.735182 2026] [security2:error] [pid 806041:tid 806163] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPhULAyZ1MRInzPMYbKQAAx3k"]
[Thu Jul 30 12:53:09.735338 2026] [security2:error] [pid 806041:tid 806237] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPhULAyZ1MRInzPMYbKQAAx3k"]
[Thu Jul 30 12:53:09.844593 2026] [security2:error] [pid 806041:tid 806277] [client 20.151.221.234:43983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuPhULAyZ1MRInzPMYbMQAAAO8"]
[Thu Jul 30 12:53:10.203431 2026] [core:notice] [pid 806041:tid 806061] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:10.270945 2026] [autoindex:error] [pid 806041:tid 806285] [client 3.225.222.228:20561] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:10.284129 2026] [autoindex:error] [pid 806041:tid 806273] [client 52.4.19.39:12357] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:10.529631 2026] [core:notice] [pid 806041:tid 806132] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:10.656044 2026] [core:notice] [pid 806041:tid 806068] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:10.656741 2026] [core:notice] [pid 806041:tid 806066] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:10.771227 2026] [core:notice] [pid 806041:tid 806165] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:10.794218 2026] [security2:error] [pid 806041:tid 806173] [client 20.151.221.234:16908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/plugins.php"] [unique_id "amuPhkLAyZ1MRInzPMYbeAAAAIc"]
[Thu Jul 30 12:53:10.841655 2026] [core:notice] [pid 806041:tid 806057] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:11.005657 2026] [core:notice] [pid 806041:tid 806069] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:11.162239 2026] [core:notice] [pid 806041:tid 806161] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:11.183724 2026] [core:notice] [pid 806041:tid 806288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:11.190105 2026] [security2:error] [pid 806041:tid 806288] [client 103.215.74.26:3498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPh0LAyZ1MRInzPMYbgAAAAPo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:11.319615 2026] [core:notice] [pid 806041:tid 806044] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:11.929910 2026] [core:notice] [pid 806041:tid 806188] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:11.936223 2026] [security2:error] [pid 806041:tid 806188] [client 103.215.74.26:3512] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPh0LAyZ1MRInzPMYbkAAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:12.674341 2026] [core:notice] [pid 806041:tid 806235] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:12.681382 2026] [security2:error] [pid 806041:tid 806235] [client 103.215.74.26:3526] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPiELAyZ1MRInzPMYbogAAAMU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:13.411835 2026] [core:notice] [pid 806041:tid 806209] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:13.417846 2026] [security2:error] [pid 806041:tid 806209] [client 103.215.74.26:26098] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPiULAyZ1MRInzPMYbswAAAKs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:13.817382 2026] [core:notice] [pid 806041:tid 806228] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:13.830187 2026] [core:notice] [pid 806041:tid 806221] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:13.875914 2026] [core:notice] [pid 806041:tid 806237] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:13.887231 2026] [core:notice] [pid 806041:tid 806251] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:13.931947 2026] [autoindex:error] [pid 806041:tid 806275] [client 141.148.153.213:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:13.966878 2026] [security2:error] [pid 806041:tid 806232] [client 20.151.221.234:44387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuPiULAyZ1MRInzPMYbwgAAAMI"]
[Thu Jul 30 12:53:13.981126 2026] [security2:error] [pid 806041:tid 806210] [client 150.107.232.194:27229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPiULAyZ1MRInzPMYbwwAAAKw"]
[Thu Jul 30 12:53:13.981242 2026] [security2:error] [pid 806041:tid 806210] [client 150.107.232.194:27229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPiULAyZ1MRInzPMYbwwAAAKw"]
[Thu Jul 30 12:53:14.005813 2026] [core:notice] [pid 806041:tid 806179] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:14.005813 2026] [core:notice] [pid 806041:tid 806243] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:14.166825 2026] [core:notice] [pid 806041:tid 806182] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:14.173146 2026] [security2:error] [pid 806041:tid 806182] [client 103.215.74.26:26104] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPikLAyZ1MRInzPMYbxgAAAJA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:14.584839 2026] [core:notice] [pid 806041:tid 806188] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:14.935622 2026] [core:notice] [pid 806041:tid 806287] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:14.941560 2026] [security2:error] [pid 806041:tid 806287] [client 103.215.74.26:26118] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPikLAyZ1MRInzPMYb2QAAAPk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:15.521495 2026] [security2:error] [pid 806041:tid 806240] [client 20.151.221.234:16794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/go.php"] [unique_id "amuPi0LAyZ1MRInzPMYb6AAAAMo"]
[Thu Jul 30 12:53:15.676673 2026] [core:notice] [pid 806041:tid 806190] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:15.683146 2026] [security2:error] [pid 806041:tid 806190] [client 103.215.74.26:26124] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPi0LAyZ1MRInzPMYb6QAAAJg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:16.006880 2026] [core:notice] [pid 806041:tid 806245] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:16.094843 2026] [core:notice] [pid 806041:tid 806214] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:16.336481 2026] [core:notice] [pid 806041:tid 806212] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:16.422944 2026] [core:error] [pid 806041:tid 806246] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.422965 2026] [core:error] [pid 806041:tid 806246] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.429409 2026] [core:error] [pid 806041:tid 806290] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.429427 2026] [core:error] [pid 806041:tid 806290] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.466846 2026] [core:error] [pid 806041:tid 806256] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.466865 2026] [core:error] [pid 806041:tid 806256] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.488550 2026] [core:error] [pid 806041:tid 806239] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.488574 2026] [core:error] [pid 806041:tid 806239] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.491417 2026] [core:notice] [pid 806041:tid 806200] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:16.502466 2026] [core:error] [pid 806041:tid 806226] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.502484 2026] [core:error] [pid 806041:tid 806226] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:16.549833 2026] [security2:error] [pid 806041:tid 806253] [client 47.128.36.176:21990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jesus.claims"] [uri "/robots.txt"] [unique_id "amuPjELAyZ1MRInzPMYcHAAAANc"]
[Thu Jul 30 12:53:16.684924 2026] [core:notice] [pid 806041:tid 806215] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:16.685864 2026] [security2:error] [pid 806041:tid 806178] [client 20.151.221.234:16824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/test1.php"] [unique_id "amuPjELAyZ1MRInzPMYcHwAAAIw"]
[Thu Jul 30 12:53:17.062890 2026] [core:notice] [pid 806041:tid 806275] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:17.634463 2026] [autoindex:error] [pid 806041:tid 806243] [client 20.151.221.234:16901] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:17.710572 2026] [security2:error] [pid 806041:tid 806172] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuPjULAyZ1MRInzPMYcQgAAAIY"]
[Thu Jul 30 12:53:17.710689 2026] [security2:error] [pid 806041:tid 806172] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuPjULAyZ1MRInzPMYcQgAAAIY"]
[Thu Jul 30 12:53:17.898212 2026] [security2:error] [pid 806041:tid 806296] [client 20.151.221.234:16901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/images/index.php"] [unique_id "amuPjULAyZ1MRInzPMYcRAAAAQI"]
[Thu Jul 30 12:53:18.008803 2026] [security2:error] [pid 806041:tid 806183] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuPjkLAyZ1MRInzPMYcSwAAAJE"]
[Thu Jul 30 12:53:18.008943 2026] [security2:error] [pid 806041:tid 806183] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuPjkLAyZ1MRInzPMYcSwAAAJE"]
[Thu Jul 30 12:53:18.195607 2026] [security2:error] [pid 806041:tid 806210] [client 20.100.187.246:26801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/LA.php"] [unique_id "amuPjkLAyZ1MRInzPMYcUwAAAKw"]
[Thu Jul 30 12:53:18.303640 2026] [security2:error] [pid 806041:tid 806187] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/xstelth.php"] [unique_id "amuPjkLAyZ1MRInzPMYcWgAAAJU"]
[Thu Jul 30 12:53:18.303749 2026] [security2:error] [pid 806041:tid 806187] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/xstelth.php"] [unique_id "amuPjkLAyZ1MRInzPMYcWgAAAJU"]
[Thu Jul 30 12:53:18.304961 2026] [security2:error] [pid 806041:tid 806175] [client 52.167.144.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuPjULAyZ1MRInzPMYcRwAAAIk"]
[Thu Jul 30 12:53:18.493027 2026] [core:notice] [pid 806041:tid 806195] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:18.603289 2026] [security2:error] [pid 806041:tid 806298] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuPjkLAyZ1MRInzPMYcZAAAAQQ"]
[Thu Jul 30 12:53:18.603395 2026] [security2:error] [pid 806041:tid 806298] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuPjkLAyZ1MRInzPMYcZAAAAQQ"]
[Thu Jul 30 12:53:18.906782 2026] [security2:error] [pid 806041:tid 806238] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/newfile.php"] [unique_id "amuPjkLAyZ1MRInzPMYcaQAAAMg"]
[Thu Jul 30 12:53:18.906900 2026] [security2:error] [pid 806041:tid 806238] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/newfile.php"] [unique_id "amuPjkLAyZ1MRInzPMYcaQAAAMg"]
[Thu Jul 30 12:53:19.048739 2026] [autoindex:error] [pid 806041:tid 806263] [client 20.151.221.234:16921] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:19.224040 2026] [security2:error] [pid 806041:tid 806247] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/tBEZGQz.php"] [unique_id "amuPj0LAyZ1MRInzPMYceQAAANE"]
[Thu Jul 30 12:53:19.224142 2026] [security2:error] [pid 806041:tid 806247] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/tBEZGQz.php"] [unique_id "amuPj0LAyZ1MRInzPMYceQAAANE"]
[Thu Jul 30 12:53:19.291213 2026] [security2:error] [pid 806041:tid 806223] [client 20.151.221.234:16921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/asd.php"] [unique_id "amuPj0LAyZ1MRInzPMYcegAAALk"]
[Thu Jul 30 12:53:19.522930 2026] [security2:error] [pid 806041:tid 806188] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPj0LAyZ1MRInzPMYcfgAAAJY"]
[Thu Jul 30 12:53:19.815714 2026] [security2:error] [pid 806041:tid 806297] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/drykl.php"] [unique_id "amuPj0LAyZ1MRInzPMYchwAAAQM"]
[Thu Jul 30 12:53:19.815829 2026] [security2:error] [pid 806041:tid 806297] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/drykl.php"] [unique_id "amuPj0LAyZ1MRInzPMYchwAAAQM"]
[Thu Jul 30 12:53:19.942026 2026] [security2:error] [pid 806041:tid 806211] [client 20.100.187.246:27749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/admin.php"] [unique_id "amuPj0LAyZ1MRInzPMYciQAAAK0"]
[Thu Jul 30 12:53:19.971955 2026] [security2:error] [pid 806041:tid 806206] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPj0LAyZ1MRInzPMYciwAAAKg"]
[Thu Jul 30 12:53:20.259914 2026] [security2:error] [pid 806041:tid 806283] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ls.php"] [unique_id "amuPkELAyZ1MRInzPMYclAAAAPU"]
[Thu Jul 30 12:53:20.260029 2026] [security2:error] [pid 806041:tid 806283] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ls.php"] [unique_id "amuPkELAyZ1MRInzPMYclAAAAPU"]
[Thu Jul 30 12:53:20.415970 2026] [security2:error] [pid 806041:tid 806264] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dx.php"] [unique_id "amuPkELAyZ1MRInzPMYclgAAAOI"]
[Thu Jul 30 12:53:20.416105 2026] [security2:error] [pid 806041:tid 806264] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/dx.php"] [unique_id "amuPkELAyZ1MRInzPMYclgAAAOI"]
[Thu Jul 30 12:53:20.463712 2026] [security2:error] [pid 806041:tid 806144] [remote 52.167.144.170:25519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/PBB/issue/archive"] [unique_id "amuPkELAyZ1MRInzPMYclwAAzmY"]
[Thu Jul 30 12:53:20.508149 2026] [security2:error] [pid 806041:tid 806129] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPkELAyZ1MRInzPMYcmAAAylc"]
[Thu Jul 30 12:53:20.508284 2026] [security2:error] [pid 806041:tid 806240] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPkELAyZ1MRInzPMYcmAAAylc"]
[Thu Jul 30 12:53:20.508962 2026] [security2:error] [pid 806041:tid 806174] [client 20.151.221.234:44016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuPkELAyZ1MRInzPMYcmgAAAIg"]
[Thu Jul 30 12:53:20.727735 2026] [security2:error] [pid 806041:tid 806219] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/mac.php"] [unique_id "amuPkELAyZ1MRInzPMYcpAAAALU"]
[Thu Jul 30 12:53:20.727833 2026] [security2:error] [pid 806041:tid 806219] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/mac.php"] [unique_id "amuPkELAyZ1MRInzPMYcpAAAALU"]
[Thu Jul 30 12:53:21.215527 2026] [security2:error] [pid 806041:tid 806288] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/485.php"] [unique_id "amuPkULAyZ1MRInzPMYcrwAAAPo"]
[Thu Jul 30 12:53:21.215631 2026] [security2:error] [pid 806041:tid 806288] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/485.php"] [unique_id "amuPkULAyZ1MRInzPMYcrwAAAPo"]
[Thu Jul 30 12:53:21.387628 2026] [security2:error] [pid 806041:tid 806271] [client 20.151.221.234:16785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuPkULAyZ1MRInzPMYctAAAAOk"]
[Thu Jul 30 12:53:21.402118 2026] [core:notice] [pid 806041:tid 806272] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:21.408577 2026] [security2:error] [pid 806041:tid 806272] [client 103.215.74.26:26130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPkULAyZ1MRInzPMYctQAAAOo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:21.502196 2026] [security2:error] [pid 806041:tid 806245] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gelio1.php"] [unique_id "amuPkULAyZ1MRInzPMYctgAAAM8"]
[Thu Jul 30 12:53:21.502313 2026] [security2:error] [pid 806041:tid 806245] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gelio1.php"] [unique_id "amuPkULAyZ1MRInzPMYctgAAAM8"]
[Thu Jul 30 12:53:21.795042 2026] [security2:error] [pid 806041:tid 806260] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/lp6.php"] [unique_id "amuPkULAyZ1MRInzPMYcxQAAAN4"]
[Thu Jul 30 12:53:21.795143 2026] [security2:error] [pid 806041:tid 806260] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/lp6.php"] [unique_id "amuPkULAyZ1MRInzPMYcxQAAAN4"]
[Thu Jul 30 12:53:21.803079 2026] [security2:error] [pid 806041:tid 806280] [client 20.100.187.246:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/class_api.php"] [unique_id "amuPkULAyZ1MRInzPMYcxwAAAPI"]
[Thu Jul 30 12:53:22.084278 2026] [security2:error] [pid 806041:tid 806211] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuPkkLAyZ1MRInzPMYcyQAAAK0"]
[Thu Jul 30 12:53:22.084413 2026] [security2:error] [pid 806041:tid 806211] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuPkkLAyZ1MRInzPMYcyQAAAK0"]
[Thu Jul 30 12:53:22.140716 2026] [core:notice] [pid 806041:tid 806291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:22.146759 2026] [security2:error] [pid 806041:tid 806291] [client 103.215.74.26:26140] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPkkLAyZ1MRInzPMYcywAAAP0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:22.422521 2026] [security2:error] [pid 806041:tid 806207] [client 20.151.221.234:44415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/atomlib.php"] [unique_id "amuPkkLAyZ1MRInzPMYc2QAAAKk"]
[Thu Jul 30 12:53:22.425314 2026] [security2:error] [pid 806041:tid 806264] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPkkLAyZ1MRInzPMYc2gAAAOI"]
[Thu Jul 30 12:53:22.476580 2026] [security2:error] [pid 806041:tid 806185] [client 20.100.187.246:50889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuPkkLAyZ1MRInzPMYc2wAAAJM"]
[Thu Jul 30 12:53:22.722386 2026] [security2:error] [pid 806041:tid 806209] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/w3llscc.php"] [unique_id "amuPkkLAyZ1MRInzPMYc4gAAAKs"]
[Thu Jul 30 12:53:22.722480 2026] [security2:error] [pid 806041:tid 806209] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/w3llscc.php"] [unique_id "amuPkkLAyZ1MRInzPMYc4gAAAKs"]
[Thu Jul 30 12:53:22.877383 2026] [security2:error] [pid 806041:tid 806228] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/miru3.php"] [unique_id "amuPkkLAyZ1MRInzPMYc6QAAAL4"]
[Thu Jul 30 12:53:22.877484 2026] [security2:error] [pid 806041:tid 806228] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/miru3.php"] [unique_id "amuPkkLAyZ1MRInzPMYc6QAAAL4"]
[Thu Jul 30 12:53:22.881695 2026] [core:notice] [pid 806041:tid 806177] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:22.888684 2026] [security2:error] [pid 806041:tid 806177] [client 103.215.74.26:26156] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPkkLAyZ1MRInzPMYc6gAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:23.180677 2026] [security2:error] [pid 806041:tid 806173] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuPk0LAyZ1MRInzPMYc7QAAAIc"]
[Thu Jul 30 12:53:23.180778 2026] [security2:error] [pid 806041:tid 806173] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuPk0LAyZ1MRInzPMYc7QAAAIc"]
[Thu Jul 30 12:53:23.618004 2026] [security2:error] [pid 806041:tid 806197] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPk0LAyZ1MRInzPMYc9wAAAJ8"]
[Thu Jul 30 12:53:23.653071 2026] [core:notice] [pid 806041:tid 806229] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:23.659503 2026] [security2:error] [pid 806041:tid 806229] [client 103.215.74.26:60304] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPk0LAyZ1MRInzPMYc-AAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:23.915804 2026] [security2:error] [pid 806041:tid 806242] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuPk0LAyZ1MRInzPMYdAwAAAMw"]
[Thu Jul 30 12:53:23.915907 2026] [security2:error] [pid 806041:tid 806242] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuPk0LAyZ1MRInzPMYdAwAAAMw"]
[Thu Jul 30 12:53:24.085010 2026] [security2:error] [pid 806041:tid 806290] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/av.php"] [unique_id "amuPlELAyZ1MRInzPMYdBgAAAPw"]
[Thu Jul 30 12:53:24.085115 2026] [security2:error] [pid 806041:tid 806290] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/av.php"] [unique_id "amuPlELAyZ1MRInzPMYdBgAAAPw"]
[Thu Jul 30 12:53:24.243679 2026] [security2:error] [pid 806041:tid 806189] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPk0LAyZ1MRInzPMYc8QAAlwk"]
[Thu Jul 30 12:53:24.360884 2026] [security2:error] [pid 806041:tid 806218] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPk0LAyZ1MRInzPMYc9gAAtAA"]
[Thu Jul 30 12:53:24.514885 2026] [security2:error] [pid 806041:tid 806253] [client 150.107.232.194:26702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPlELAyZ1MRInzPMYdFAAAANc"]
[Thu Jul 30 12:53:24.515009 2026] [security2:error] [pid 806041:tid 806253] [client 150.107.232.194:26702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPlELAyZ1MRInzPMYdFAAAANc"]
[Thu Jul 30 12:53:24.677437 2026] [security2:error] [pid 806041:tid 806258] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPlELAyZ1MRInzPMYdGAAAANw"]
[Thu Jul 30 12:53:24.919281 2026] [security2:error] [pid 806041:tid 806249] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuPlELAyZ1MRInzPMYdIwAAANM"]
[Thu Jul 30 12:53:25.083551 2026] [security2:error] [pid 806041:tid 806184] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/tiny.php"] [unique_id "amuPlULAyZ1MRInzPMYdJAAAAJI"]
[Thu Jul 30 12:53:25.083704 2026] [security2:error] [pid 806041:tid 806184] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/tiny.php"] [unique_id "amuPlULAyZ1MRInzPMYdJAAAAJI"]
[Thu Jul 30 12:53:25.235729 2026] [autoindex:error] [pid 806041:tid 806221] [client 20.151.221.234:16814] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:25.359614 2026] [core:notice] [pid 806041:tid 806188] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:25.392522 2026] [security2:error] [pid 806041:tid 806219] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuPlULAyZ1MRInzPMYdLgAAALU"]
[Thu Jul 30 12:53:25.392616 2026] [security2:error] [pid 806041:tid 806219] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuPlULAyZ1MRInzPMYdLgAAALU"]
[Thu Jul 30 12:53:25.414860 2026] [security2:error] [pid 806041:tid 806205] [client 20.100.187.246:27090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuPlULAyZ1MRInzPMYdJQAAAKc"]
[Thu Jul 30 12:53:25.496417 2026] [autoindex:error] [pid 806041:tid 806251] [client 20.151.221.234:16814] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:25.521839 2026] [security2:error] [pid 806041:tid 806187] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPlELAyZ1MRInzPMYdIgAAlQw"]
[Thu Jul 30 12:53:25.644831 2026] [security2:error] [pid 806041:tid 806231] [client 74.7.241.180:48420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.moswey.com"] [uri "/robots.txt"] [unique_id "amuPlULAyZ1MRInzPMYdNgAAwQI"]
[Thu Jul 30 12:53:25.697484 2026] [security2:error] [pid 806041:tid 806288] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/zrrhj.php"] [unique_id "amuPlULAyZ1MRInzPMYdNwAAAPo"]
[Thu Jul 30 12:53:25.697578 2026] [security2:error] [pid 806041:tid 806288] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/zrrhj.php"] [unique_id "amuPlULAyZ1MRInzPMYdNwAAAPo"]
[Thu Jul 30 12:53:25.729050 2026] [security2:error] [pid 806041:tid 806232] [client 20.151.221.234:16814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuPlULAyZ1MRInzPMYdOAAAAMI"]
[Thu Jul 30 12:53:26.007619 2026] [security2:error] [pid 806041:tid 806295] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuPlkLAyZ1MRInzPMYdQgAAAQE"]
[Thu Jul 30 12:53:26.007720 2026] [security2:error] [pid 806041:tid 806295] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuPlkLAyZ1MRInzPMYdQgAAAQE"]
[Thu Jul 30 12:53:26.309194 2026] [security2:error] [pid 806041:tid 806239] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wpgum.php"] [unique_id "amuPlkLAyZ1MRInzPMYdSAAAAMk"]
[Thu Jul 30 12:53:26.309293 2026] [security2:error] [pid 806041:tid 806239] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wpgum.php"] [unique_id "amuPlkLAyZ1MRInzPMYdSAAAAMk"]
[Thu Jul 30 12:53:26.382783 2026] [security2:error] [pid 806041:tid 806180] [client 20.100.187.246:10892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuPlkLAyZ1MRInzPMYdSQAAAI4"]
[Thu Jul 30 12:53:26.617651 2026] [security2:error] [pid 806041:tid 806172] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ywwbf.php"] [unique_id "amuPlkLAyZ1MRInzPMYdUQAAAIY"]
[Thu Jul 30 12:53:26.617761 2026] [security2:error] [pid 806041:tid 806172] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ywwbf.php"] [unique_id "amuPlkLAyZ1MRInzPMYdUQAAAIY"]
[Thu Jul 30 12:53:26.883230 2026] [security2:error] [pid 806041:tid 806282] [client 119.73.97.132:29750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuPlkLAyZ1MRInzPMYdQwAA9G4"]
[Thu Jul 30 12:53:26.928174 2026] [security2:error] [pid 806041:tid 806291] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/xoldj.php"] [unique_id "amuPlkLAyZ1MRInzPMYdVwAAAP0"]
[Thu Jul 30 12:53:26.928277 2026] [security2:error] [pid 806041:tid 806291] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/xoldj.php"] [unique_id "amuPlkLAyZ1MRInzPMYdVwAAAP0"]
[Thu Jul 30 12:53:27.142258 2026] [autoindex:error] [pid 806041:tid 806199] [client 20.151.221.234:44390] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:27.222812 2026] [security2:error] [pid 806041:tid 806283] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/f35.php"] [unique_id "amuPl0LAyZ1MRInzPMYdXgAAAPU"]
[Thu Jul 30 12:53:27.222933 2026] [security2:error] [pid 806041:tid 806283] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/f35.php"] [unique_id "amuPl0LAyZ1MRInzPMYdXgAAAPU"]
[Thu Jul 30 12:53:27.425202 2026] [autoindex:error] [pid 806041:tid 806185] [client 20.151.221.234:44390] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/blocks/block/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:27.524210 2026] [security2:error] [pid 806041:tid 806215] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gk.php"] [unique_id "amuPl0LAyZ1MRInzPMYdagAAALE"]
[Thu Jul 30 12:53:27.524385 2026] [security2:error] [pid 806041:tid 806215] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gk.php"] [unique_id "amuPl0LAyZ1MRInzPMYdagAAALE"]
[Thu Jul 30 12:53:27.703986 2026] [autoindex:error] [pid 806041:tid 806262] [client 20.151.221.234:44390] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:27.823626 2026] [security2:error] [pid 806041:tid 806209] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuPl0LAyZ1MRInzPMYdcQAAAKs"]
[Thu Jul 30 12:53:27.823740 2026] [security2:error] [pid 806041:tid 806209] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuPl0LAyZ1MRInzPMYdcQAAAKs"]
[Thu Jul 30 12:53:27.901238 2026] [security2:error] [pid 806041:tid 806219] [client 20.151.221.234:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/inputs.php"] [unique_id "amuPl0LAyZ1MRInzPMYddQAAALU"]
[Thu Jul 30 12:53:28.124287 2026] [security2:error] [pid 806041:tid 806173] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wper3.php"] [unique_id "amuPmELAyZ1MRInzPMYdfAAAAIc"]
[Thu Jul 30 12:53:28.124402 2026] [security2:error] [pid 806041:tid 806173] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wper3.php"] [unique_id "amuPmELAyZ1MRInzPMYdfAAAAIc"]
[Thu Jul 30 12:53:28.264038 2026] [security2:error] [pid 806041:tid 806213] [client 119.73.97.132:29750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuPl0LAyZ1MRInzPMYdbwAArwc"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 12:53:28.433939 2026] [security2:error] [pid 806041:tid 806277] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/bthil.php"] [unique_id "amuPmELAyZ1MRInzPMYdhQAAAO8"]
[Thu Jul 30 12:53:28.434073 2026] [security2:error] [pid 806041:tid 806277] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/bthil.php"] [unique_id "amuPmELAyZ1MRInzPMYdhQAAAO8"]
[Thu Jul 30 12:53:28.729092 2026] [security2:error] [pid 806041:tid 806278] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wyzer1.php"] [unique_id "amuPmELAyZ1MRInzPMYdkAAAAPA"]
[Thu Jul 30 12:53:28.729199 2026] [security2:error] [pid 806041:tid 806278] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wyzer1.php"] [unique_id "amuPmELAyZ1MRInzPMYdkAAAAPA"]
[Thu Jul 30 12:53:28.775197 2026] [security2:error] [pid 806041:tid 806250] [client 20.151.221.234:16963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/index.php"] [unique_id "amuPmELAyZ1MRInzPMYdlAAAANQ"]
[Thu Jul 30 12:53:29.030357 2026] [security2:error] [pid 806041:tid 806245] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/mh.php"] [unique_id "amuPmULAyZ1MRInzPMYdmgAAAM8"]
[Thu Jul 30 12:53:29.030444 2026] [security2:error] [pid 806041:tid 806245] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/mh.php"] [unique_id "amuPmULAyZ1MRInzPMYdmgAAAM8"]
[Thu Jul 30 12:53:29.381457 2026] [core:notice] [pid 806041:tid 806255] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:29.384902 2026] [security2:error] [pid 806041:tid 806181] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuPmULAyZ1MRInzPMYdogAAAI8"]
[Thu Jul 30 12:53:29.385009 2026] [security2:error] [pid 806041:tid 806181] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuPmULAyZ1MRInzPMYdogAAAI8"]
[Thu Jul 30 12:53:29.388804 2026] [security2:error] [pid 806041:tid 806255] [client 103.215.74.26:60308] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPmULAyZ1MRInzPMYdoQAAANk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:29.394691 2026] [security2:error] [pid 806041:tid 806247] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPmELAyZ1MRInzPMYdkwAAANE"]
[Thu Jul 30 12:53:29.568731 2026] [security2:error] [pid 806041:tid 806210] [client 20.100.187.246:24731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/991176.php"] [unique_id "amuPmULAyZ1MRInzPMYdqgAAAKw"]
[Thu Jul 30 12:53:29.718632 2026] [security2:error] [pid 806041:tid 806221] [client 20.91.139.111:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.markmocek.com"] [uri "/1.php"] [unique_id "amuPmULAyZ1MRInzPMYdrgAAALc"]
[Thu Jul 30 12:53:29.718741 2026] [security2:error] [pid 806041:tid 806221] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/1.php"] [unique_id "amuPmULAyZ1MRInzPMYdrgAAALc"]
[Thu Jul 30 12:53:29.718849 2026] [security2:error] [pid 806041:tid 806221] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/1.php"] [unique_id "amuPmULAyZ1MRInzPMYdrgAAALc"]
[Thu Jul 30 12:53:30.013160 2026] [security2:error] [pid 806041:tid 806219] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/chosen.php"] [unique_id "amuPmkLAyZ1MRInzPMYdsgAAALU"]
[Thu Jul 30 12:53:30.013313 2026] [security2:error] [pid 806041:tid 806219] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/chosen.php"] [unique_id "amuPmkLAyZ1MRInzPMYdsgAAALU"]
[Thu Jul 30 12:53:30.118726 2026] [security2:error] [pid 806041:tid 806244] [client 20.151.221.234:43974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuPmkLAyZ1MRInzPMYdugAAAM4"]
[Thu Jul 30 12:53:30.167935 2026] [core:notice] [pid 806041:tid 806222] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:30.173613 2026] [security2:error] [pid 806041:tid 806222] [client 103.215.74.26:60310] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPmkLAyZ1MRInzPMYdvgAAALg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:30.309672 2026] [security2:error] [pid 806041:tid 806194] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/sd.php"] [unique_id "amuPmkLAyZ1MRInzPMYdwAAAAJw"]
[Thu Jul 30 12:53:30.309810 2026] [security2:error] [pid 806041:tid 806194] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/sd.php"] [unique_id "amuPmkLAyZ1MRInzPMYdwAAAAJw"]
[Thu Jul 30 12:53:30.314088 2026] [security2:error] [pid 806041:tid 806077] [remote 57.141.0.21:42260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuPmkLAyZ1MRInzPMYdwQAA5CM"]
[Thu Jul 30 12:53:30.608436 2026] [security2:error] [pid 806041:tid 806278] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/z60.php"] [unique_id "amuPmkLAyZ1MRInzPMYdyAAAAPA"]
[Thu Jul 30 12:53:30.608576 2026] [security2:error] [pid 806041:tid 806278] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/z60.php"] [unique_id "amuPmkLAyZ1MRInzPMYdyAAAAPA"]
[Thu Jul 30 12:53:30.891080 2026] [core:notice] [pid 806041:tid 806171] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:30.897751 2026] [security2:error] [pid 806041:tid 806171] [client 103.215.74.26:60320] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPmkLAyZ1MRInzPMYd0AAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:30.898145 2026] [security2:error] [pid 806041:tid 806287] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/home.php"] [unique_id "amuPmkLAyZ1MRInzPMYd0QAAAPk"]
[Thu Jul 30 12:53:30.898232 2026] [security2:error] [pid 806041:tid 806287] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/home.php"] [unique_id "amuPmkLAyZ1MRInzPMYd0QAAAPk"]
[Thu Jul 30 12:53:31.012811 2026] [security2:error] [pid 806041:tid 806237] [client 20.100.187.246:26789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuPm0LAyZ1MRInzPMYd0wAAAMc"]
[Thu Jul 30 12:53:31.070868 2026] [security2:error] [pid 806041:tid 806243] [client 20.151.221.234:17009] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bonafideadvisors.com"] [uri "/wp-content/1.php"] [unique_id "amuPm0LAyZ1MRInzPMYd1wAAAM0"]
[Thu Jul 30 12:53:31.070996 2026] [security2:error] [pid 806041:tid 806243] [client 20.151.221.234:17009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/1.php"] [unique_id "amuPm0LAyZ1MRInzPMYd1wAAAM0"]
[Thu Jul 30 12:53:31.208818 2026] [security2:error] [pid 806041:tid 806185] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ws58.php"] [unique_id "amuPm0LAyZ1MRInzPMYd3gAAAJM"]
[Thu Jul 30 12:53:31.208926 2026] [security2:error] [pid 806041:tid 806185] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ws58.php"] [unique_id "amuPm0LAyZ1MRInzPMYd3gAAAJM"]
[Thu Jul 30 12:53:31.275793 2026] [security2:error] [pid 806041:tid 806112] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPm0LAyZ1MRInzPMYd3wAAw0Y"]
[Thu Jul 30 12:53:31.275952 2026] [security2:error] [pid 806041:tid 806233] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPm0LAyZ1MRInzPMYd3wAAw0Y"]
[Thu Jul 30 12:53:31.391574 2026] [security2:error] [pid 806041:tid 806113] [remote 101.101.97.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.97.101.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeninsabah.com"] [uri "/wp-includes/wp-login.php"] [unique_id "amuPm0LAyZ1MRInzPMYd4AAAt0c"]
[Thu Jul 30 12:53:31.503618 2026] [security2:error] [pid 806041:tid 806240] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gulu.php"] [unique_id "amuPm0LAyZ1MRInzPMYd4QAAAMo"]
[Thu Jul 30 12:53:31.503722 2026] [security2:error] [pid 806041:tid 806240] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gulu.php"] [unique_id "amuPm0LAyZ1MRInzPMYd4QAAAMo"]
[Thu Jul 30 12:53:31.670577 2026] [security2:error] [pid 806041:tid 806184] [client 20.100.187.246:50884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuPm0LAyZ1MRInzPMYd8gAAAJI"]
[Thu Jul 30 12:53:31.678641 2026] [core:notice] [pid 806041:tid 806215] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:31.684769 2026] [security2:error] [pid 806041:tid 806215] [client 103.215.74.26:60332] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPm0LAyZ1MRInzPMYd8wAAALE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:31.795309 2026] [security2:error] [pid 806041:tid 806177] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuPm0LAyZ1MRInzPMYd9wAAAIs"]
[Thu Jul 30 12:53:31.795441 2026] [security2:error] [pid 806041:tid 806177] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuPm0LAyZ1MRInzPMYd9wAAAIs"]
[Thu Jul 30 12:53:31.849441 2026] [security2:error] [pid 806041:tid 806219] [client 20.151.221.234:44019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/plugin.php"] [unique_id "amuPm0LAyZ1MRInzPMYd-AAAALU"]
[Thu Jul 30 12:53:32.114791 2026] [security2:error] [pid 806041:tid 806173] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wpls.php"] [unique_id "amuPnELAyZ1MRInzPMYeFgAAAIc"]
[Thu Jul 30 12:53:32.114870 2026] [security2:error] [pid 806041:tid 806173] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wpls.php"] [unique_id "amuPnELAyZ1MRInzPMYeFgAAAIc"]
[Thu Jul 30 12:53:32.241717 2026] [security2:error] [pid 806041:tid 806158] [remote 57.141.0.1:49696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuPnELAyZ1MRInzPMYeHQAA_3Q"]
[Thu Jul 30 12:53:32.414466 2026] [security2:error] [pid 806041:tid 806212] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/php.php"] [unique_id "amuPnELAyZ1MRInzPMYeKgAAAK4"]
[Thu Jul 30 12:53:32.414617 2026] [security2:error] [pid 806041:tid 806212] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/php.php"] [unique_id "amuPnELAyZ1MRInzPMYeKgAAAK4"]
[Thu Jul 30 12:53:32.415547 2026] [core:notice] [pid 806041:tid 806232] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:32.421656 2026] [security2:error] [pid 806041:tid 806232] [client 103.215.74.26:60344] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPnELAyZ1MRInzPMYeKwAAAMI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:32.458436 2026] [security2:error] [pid 806041:tid 806254] [client 20.100.187.246:27131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuPnELAyZ1MRInzPMYeLgAAANg"]
[Thu Jul 30 12:53:32.717404 2026] [security2:error] [pid 806041:tid 806211] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/100.php"] [unique_id "amuPnELAyZ1MRInzPMYePAAAAK0"]
[Thu Jul 30 12:53:32.717493 2026] [security2:error] [pid 806041:tid 806211] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/100.php"] [unique_id "amuPnELAyZ1MRInzPMYePAAAAK0"]
[Thu Jul 30 12:53:33.023615 2026] [security2:error] [pid 806041:tid 806253] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/BDKR28WP.php"] [unique_id "amuPnULAyZ1MRInzPMYeWgAAANc"]
[Thu Jul 30 12:53:33.023731 2026] [security2:error] [pid 806041:tid 806253] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/BDKR28WP.php"] [unique_id "amuPnULAyZ1MRInzPMYeWgAAANc"]
[Thu Jul 30 12:53:33.206465 2026] [core:notice] [pid 806041:tid 806199] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:33.212999 2026] [security2:error] [pid 806041:tid 806199] [client 103.215.74.26:8228] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPnULAyZ1MRInzPMYeXgAAAKE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:33.302506 2026] [security2:error] [pid 806041:tid 806206] [client 20.151.221.234:16979] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bonafideadvisors.com"] [uri "/1.php"] [unique_id "amuPnULAyZ1MRInzPMYeZgAAAKg"]
[Thu Jul 30 12:53:33.302615 2026] [security2:error] [pid 806041:tid 806206] [client 20.151.221.234:16979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/1.php"] [unique_id "amuPnULAyZ1MRInzPMYeZgAAAKg"]
[Thu Jul 30 12:53:33.323930 2026] [security2:error] [pid 806041:tid 806262] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/browse.php"] [unique_id "amuPnULAyZ1MRInzPMYeaQAAAOA"]
[Thu Jul 30 12:53:33.324079 2026] [security2:error] [pid 806041:tid 806262] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/browse.php"] [unique_id "amuPnULAyZ1MRInzPMYeaQAAAOA"]
[Thu Jul 30 12:53:33.711399 2026] [security2:error] [pid 806041:tid 806067] [remote 57.141.0.30:56162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/66784244892/feed/rss2/"] [unique_id "amuPnULAyZ1MRInzPMYedQAAkhk"]
[Thu Jul 30 12:53:33.725963 2026] [security2:error] [pid 806041:tid 806286] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-good.php"] [unique_id "amuPnULAyZ1MRInzPMYeeAAAAPg"]
[Thu Jul 30 12:53:33.726065 2026] [security2:error] [pid 806041:tid 806286] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-good.php"] [unique_id "amuPnULAyZ1MRInzPMYeeAAAAPg"]
[Thu Jul 30 12:53:33.765723 2026] [security2:error] [pid 806041:tid 806261] [client 185.191.171.15:25202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/29/uma-viagem-de-vida/"] [unique_id "amuPnULAyZ1MRInzPMYeegAAAN8"]
[Thu Jul 30 12:53:33.765828 2026] [security2:error] [pid 806041:tid 806261] [client 185.191.171.15:25202] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/29/uma-viagem-de-vida/"] [unique_id "amuPnULAyZ1MRInzPMYeegAAAN8"]
[Thu Jul 30 12:53:33.957369 2026] [core:notice] [pid 806041:tid 806186] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:33.963969 2026] [security2:error] [pid 806041:tid 806186] [client 103.215.74.26:8234] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPnULAyZ1MRInzPMYegAAAAJQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:34.039924 2026] [security2:error] [pid 806041:tid 806271] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/8573.php"] [unique_id "amuPnkLAyZ1MRInzPMYegQAAAOk"]
[Thu Jul 30 12:53:34.040069 2026] [security2:error] [pid 806041:tid 806271] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/8573.php"] [unique_id "amuPnkLAyZ1MRInzPMYegQAAAOk"]
[Thu Jul 30 12:53:34.348591 2026] [security2:error] [pid 806041:tid 806203] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-admin/install.php"] [unique_id "amuPnkLAyZ1MRInzPMYeiQAAAKU"]
[Thu Jul 30 12:53:34.348731 2026] [security2:error] [pid 806041:tid 806203] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-admin/install.php"] [unique_id "amuPnkLAyZ1MRInzPMYeiQAAAKU"]
[Thu Jul 30 12:53:34.408174 2026] [security2:error] [pid 806041:tid 806212] [client 20.151.221.234:17018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/gg.php"] [unique_id "amuPnkLAyZ1MRInzPMYejQAAAK4"]
[Thu Jul 30 12:53:34.665028 2026] [security2:error] [pid 806041:tid 806223] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuPnkLAyZ1MRInzPMYekQAAALk"]
[Thu Jul 30 12:53:34.665133 2026] [security2:error] [pid 806041:tid 806223] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuPnkLAyZ1MRInzPMYekQAAALk"]
[Thu Jul 30 12:53:34.961633 2026] [security2:error] [pid 806041:tid 806217] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ohct.php"] [unique_id "amuPnkLAyZ1MRInzPMYemwAAALM"]
[Thu Jul 30 12:53:34.961760 2026] [security2:error] [pid 806041:tid 806217] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ohct.php"] [unique_id "amuPnkLAyZ1MRInzPMYemwAAALM"]
[Thu Jul 30 12:53:34.998846 2026] [security2:error] [pid 806041:tid 806224] [client 150.107.232.194:26899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPnkLAyZ1MRInzPMYenAAAALo"]
[Thu Jul 30 12:53:34.998952 2026] [security2:error] [pid 806041:tid 806224] [client 150.107.232.194:26899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPnkLAyZ1MRInzPMYenAAAALo"]
[Thu Jul 30 12:53:35.541565 2026] [security2:error] [pid 806041:tid 806192] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/bless.php"] [unique_id "amuPn0LAyZ1MRInzPMYeqgAAAJo"]
[Thu Jul 30 12:53:35.541680 2026] [security2:error] [pid 806041:tid 806192] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/bless.php"] [unique_id "amuPn0LAyZ1MRInzPMYeqgAAAJo"]
[Thu Jul 30 12:53:35.829171 2026] [security2:error] [pid 806041:tid 806238] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/about.php"] [unique_id "amuPn0LAyZ1MRInzPMYeuQAAAMg"]
[Thu Jul 30 12:53:35.829275 2026] [security2:error] [pid 806041:tid 806238] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/about.php"] [unique_id "amuPn0LAyZ1MRInzPMYeuQAAAMg"]
[Thu Jul 30 12:53:36.012277 2026] [autoindex:error] [pid 806041:tid 806244] [client 20.151.221.234:16980] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/images/crystal/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:36.122876 2026] [security2:error] [pid 806041:tid 806239] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuPoELAyZ1MRInzPMYexQAAAMk"]
[Thu Jul 30 12:53:36.122992 2026] [security2:error] [pid 806041:tid 806239] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuPoELAyZ1MRInzPMYexQAAAMk"]
[Thu Jul 30 12:53:36.209939 2026] [security2:error] [pid 806041:tid 806250] [client 20.151.221.234:16980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp.php"] [unique_id "amuPoELAyZ1MRInzPMYeyQAAANQ"]
[Thu Jul 30 12:53:36.426505 2026] [security2:error] [pid 806041:tid 806260] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ta0ol.php"] [unique_id "amuPoELAyZ1MRInzPMYe0wAAAN4"]
[Thu Jul 30 12:53:36.426621 2026] [security2:error] [pid 806041:tid 806260] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ta0ol.php"] [unique_id "amuPoELAyZ1MRInzPMYe0wAAAN4"]
[Thu Jul 30 12:53:36.733935 2026] [security2:error] [pid 806041:tid 806253] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/sa.php7"] [unique_id "amuPoELAyZ1MRInzPMYe2wAAANc"]
[Thu Jul 30 12:53:36.734053 2026] [security2:error] [pid 806041:tid 806253] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/sa.php7"] [unique_id "amuPoELAyZ1MRInzPMYe2wAAANc"]
[Thu Jul 30 12:53:36.852857 2026] [autoindex:error] [pid 806041:tid 806179] [client 103.226.142.125:58708] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:37.018804 2026] [core:notice] [pid 806041:tid 806207] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:37.040227 2026] [security2:error] [pid 806041:tid 806228] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-class.php"] [unique_id "amuPoULAyZ1MRInzPMYe7QAAAL4"]
[Thu Jul 30 12:53:37.040415 2026] [security2:error] [pid 806041:tid 806228] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-class.php"] [unique_id "amuPoULAyZ1MRInzPMYe7QAAAL4"]
[Thu Jul 30 12:53:37.284332 2026] [autoindex:error] [pid 806041:tid 806289] [client 103.226.142.125:58721] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:37.358959 2026] [security2:error] [pid 806041:tid 806271] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/8.php"] [unique_id "amuPoULAyZ1MRInzPMYe-wAAAOk"]
[Thu Jul 30 12:53:37.359061 2026] [security2:error] [pid 806041:tid 806271] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/8.php"] [unique_id "amuPoULAyZ1MRInzPMYe-wAAAOk"]
[Thu Jul 30 12:53:37.465777 2026] [security2:error] [pid 806041:tid 806273] [client 20.100.187.246:27083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuPoULAyZ1MRInzPMYfBwAAAOs"]
[Thu Jul 30 12:53:37.612614 2026] [security2:error] [pid 806041:tid 806277] [client 178.105.14.254:39320] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.greensparkle.net"] [uri "/.env"] [unique_id "amuPoULAyZ1MRInzPMYfFwAAAO8"]
[Thu Jul 30 12:53:37.612699 2026] [security2:error] [pid 806041:tid 806277] [client 178.105.14.254:39320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.greensparkle.net"] [uri "/.env"] [unique_id "amuPoULAyZ1MRInzPMYfFwAAAO8"]
[Thu Jul 30 12:53:37.650261 2026] [security2:error] [pid 806041:tid 806240] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/bootstrap.php"] [unique_id "amuPoULAyZ1MRInzPMYfHgAAAMo"]
[Thu Jul 30 12:53:37.650347 2026] [security2:error] [pid 806041:tid 806240] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/bootstrap.php"] [unique_id "amuPoULAyZ1MRInzPMYfHgAAAMo"]
[Thu Jul 30 12:53:37.685203 2026] [security2:error] [pid 806041:tid 806226] [client 20.151.221.234:44414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuPoULAyZ1MRInzPMYfJgAAALw"]
[Thu Jul 30 12:53:37.686129 2026] [authz_core:error] [pid 806041:tid 806193] [client 178.105.14.254:39350] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:53:37.687428 2026] [security2:error] [pid 806041:tid 806193] [client 178.105.14.254:39350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "greensparkle.net"] [uri "/cgi-sys/403.html"] [unique_id "amuPoULAyZ1MRInzPMYfJwAAAJs"]
[Thu Jul 30 12:53:37.768830 2026] [authz_core:error] [pid 806041:tid 806175] [client 178.105.14.254:39334] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:53:37.769551 2026] [security2:error] [pid 806041:tid 806175] [client 178.105.14.254:39334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.greensparkle.net"] [uri "/cgi-sys/403.html"] [unique_id "amuPoULAyZ1MRInzPMYfLQAAAIk"]
[Thu Jul 30 12:53:37.798192 2026] [authz_core:error] [pid 806041:tid 806241] [client 178.105.14.254:39358] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.env
[Thu Jul 30 12:53:37.798863 2026] [security2:error] [pid 806041:tid 806241] [client 178.105.14.254:39358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.greensparkle.net"] [uri "/cgi-sys/403.html"] [unique_id "amuPoULAyZ1MRInzPMYfMQAAAMs"]
[Thu Jul 30 12:53:37.945232 2026] [security2:error] [pid 806041:tid 806220] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-blog-header.php"] [unique_id "amuPoULAyZ1MRInzPMYfOQAAALY"]
[Thu Jul 30 12:53:37.945340 2026] [security2:error] [pid 806041:tid 806220] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-blog-header.php"] [unique_id "amuPoULAyZ1MRInzPMYfOQAAALY"]
[Thu Jul 30 12:53:38.161822 2026] [security2:error] [pid 806041:tid 806177] [client 20.100.187.246:10905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuPokLAyZ1MRInzPMYfRQAAAIs"]
[Thu Jul 30 12:53:38.244874 2026] [security2:error] [pid 806041:tid 806253] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/aa.php"] [unique_id "amuPokLAyZ1MRInzPMYfSgAAANc"]
[Thu Jul 30 12:53:38.245002 2026] [security2:error] [pid 806041:tid 806253] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/aa.php"] [unique_id "amuPokLAyZ1MRInzPMYfSgAAANc"]
[Thu Jul 30 12:53:38.323290 2026] [cgid:error] [pid 806041:tid 806285] (32)Broken pipe: [client 127.0.0.1:38406] AH02651: Error writing request body to script /usr/local/cpanel/cgi-sys/autodiscover.cgi
[Thu Jul 30 12:53:38.449714 2026] [core:error] [pid 806041:tid 806285] (104)Connection reset by peer: [client 127.0.0.1:38406] AH00574: ap_content_length_filter: apr_bucket_read() failed
[Thu Jul 30 12:53:38.449910 2026] [proxy_http:error] [pid 806041:tid 806269] (20014)Internal error (specific information not available): [client 178.105.14.254:39370] AH01102: error reading status line from remote server 127.0.0.1:80
[Thu Jul 30 12:53:38.449923 2026] [proxy:error] [pid 806041:tid 806269] [client 178.105.14.254:39370] AH00898: Error reading from remote server returned by /aaa
[Thu Jul 30 12:53:38.554385 2026] [security2:error] [pid 806041:tid 806213] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/tx79.php"] [unique_id "amuPokLAyZ1MRInzPMYfZwAAAK8"]
[Thu Jul 30 12:53:38.554500 2026] [security2:error] [pid 806041:tid 806213] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/tx79.php"] [unique_id "amuPokLAyZ1MRInzPMYfZwAAAK8"]
[Thu Jul 30 12:53:38.651940 2026] [security2:error] [pid 806041:tid 806200] [client 74.7.230.37:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nco.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuPokLAyZ1MRInzPMYfVgAAAKI"]
[Thu Jul 30 12:53:38.652814 2026] [security2:error] [pid 806041:tid 806178] [client 74.7.230.37:50910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nco.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuPokLAyZ1MRInzPMYfUgAAjF4"]
[Thu Jul 30 12:53:38.685133 2026] [proxy:error] [pid 806041:tid 806174] (32)Broken pipe: [client 178.105.14.254:39394] AH01084: pass request body failed to 127.0.0.1:2095 (127.0.0.1)
[Thu Jul 30 12:53:38.685157 2026] [proxy_http:error] [pid 806041:tid 806174] [client 178.105.14.254:39394] AH01097: pass request body failed to 127.0.0.1:2095 (127.0.0.1) from 178.105.14.254 ()
[Thu Jul 30 12:53:38.685322 2026] [security2:error] [pid 806041:tid 806199] [client 20.151.221.234:44381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/file.php"] [unique_id "amuPokLAyZ1MRInzPMYfbwAAAKE"]
[Thu Jul 30 12:53:38.841212 2026] [security2:error] [pid 806041:tid 806295] [client 156.229.16.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-137a15f9.brx.dtn.temporary.site"] [uri "/index.php"] [unique_id "amuPokLAyZ1MRInzPMYfbAAAAQE"]
[Thu Jul 30 12:53:38.862767 2026] [security2:error] [pid 806041:tid 806190] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/motu.php"] [unique_id "amuPokLAyZ1MRInzPMYfcgAAAJg"]
[Thu Jul 30 12:53:38.862865 2026] [security2:error] [pid 806041:tid 806190] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/motu.php"] [unique_id "amuPokLAyZ1MRInzPMYfcgAAAJg"]
[Thu Jul 30 12:53:38.898129 2026] [proxy_http:error] [pid 806041:tid 806174] [client 178.105.14.254:39394] AH01086: read less bytes of request body than expected (got 83156, expected 131892)
[Thu Jul 30 12:53:38.898152 2026] [proxy_http:error] [pid 806041:tid 806174] [client 178.105.14.254:39394] AH01097: pass request body failed to 127.0.0.1:2095 (127.0.0.1) from 178.105.14.254 ()
[Thu Jul 30 12:53:39.238887 2026] [fcgid:warn] [pid 806041:tid 806257] (70014)End of file found: [client 118.194.228.167:47058] mod_fcgid: can't get data from http client
[Thu Jul 30 12:53:39.329001 2026] [security2:error] [pid 806041:tid 806285] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-head.php"] [unique_id "amuPo0LAyZ1MRInzPMYfigAAAPc"]
[Thu Jul 30 12:53:39.329128 2026] [security2:error] [pid 806041:tid 806285] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-head.php"] [unique_id "amuPo0LAyZ1MRInzPMYfigAAAPc"]
[Thu Jul 30 12:53:39.428862 2026] [core:notice] [pid 806041:tid 806135] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:39.601548 2026] [security2:error] [pid 806041:tid 806229] [client 127.0.0.1:38420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.spainvisaapplicationcenterinislamabad.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuPo0LAyZ1MRInzPMYfyAAAAL8"]
[Thu Jul 30 12:53:39.601547 2026] [security2:error] [pid 806041:tid 806173] [client 127.0.0.1:38422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuPo0LAyZ1MRInzPMYfygAAAIc"]
[Thu Jul 30 12:53:39.601670 2026] [security2:error] [pid 806041:tid 806195] [client 74.7.244.24:34656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.spainvisaapplicationcenterinislamabad.site"] [uri "/robots.txt"] [unique_id "amuPo0LAyZ1MRInzPMYfxwAAnQQ"]
[Thu Jul 30 12:53:39.612453 2026] [security2:error] [pid 806041:tid 806174] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuPo0LAyZ1MRInzPMYfzAAAAIg"]
[Thu Jul 30 12:53:39.612542 2026] [security2:error] [pid 806041:tid 806174] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuPo0LAyZ1MRInzPMYfzAAAAIg"]
[Thu Jul 30 12:53:39.658059 2026] [security2:error] [pid 806041:tid 806204] [client 20.151.221.234:63820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuPo0LAyZ1MRInzPMYfzQAAAKY"]
[Thu Jul 30 12:53:39.688946 2026] [core:notice] [pid 806041:tid 806265] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:39.695243 2026] [security2:error] [pid 806041:tid 806265] [client 103.215.74.26:8236] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPo0LAyZ1MRInzPMYfzgAAAOM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:39.922869 2026] [security2:error] [pid 806041:tid 806175] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/60856e3a4findex.php"] [unique_id "amuPo0LAyZ1MRInzPMYf7wAAAIk"]
[Thu Jul 30 12:53:39.922999 2026] [security2:error] [pid 806041:tid 806175] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/60856e3a4findex.php"] [unique_id "amuPo0LAyZ1MRInzPMYf7wAAAIk"]
[Thu Jul 30 12:53:40.124893 2026] [security2:error] [pid 806041:tid 806285] [client 119.73.97.132:29750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuPo0LAyZ1MRInzPMYf7gAA9yI"]
[Thu Jul 30 12:53:40.231312 2026] [security2:error] [pid 806041:tid 806187] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-the.php"] [unique_id "amuPpELAyZ1MRInzPMYf_QAAAJU"]
[Thu Jul 30 12:53:40.231409 2026] [security2:error] [pid 806041:tid 806187] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-the.php"] [unique_id "amuPpELAyZ1MRInzPMYf_QAAAJU"]
[Thu Jul 30 12:53:40.535525 2026] [security2:error] [pid 806041:tid 806281] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp.php"] [unique_id "amuPpELAyZ1MRInzPMYgCAAAAPM"]
[Thu Jul 30 12:53:40.535660 2026] [security2:error] [pid 806041:tid 806281] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp.php"] [unique_id "amuPpELAyZ1MRInzPMYgCAAAAPM"]
[Thu Jul 30 12:53:40.691867 2026] [security2:error] [pid 806041:tid 806240] [client 20.100.187.246:10908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuPpELAyZ1MRInzPMYgDAAAAMo"]
[Thu Jul 30 12:53:40.826869 2026] [security2:error] [pid 806041:tid 806211] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/users.php"] [unique_id "amuPpELAyZ1MRInzPMYgJAAAAK0"]
[Thu Jul 30 12:53:40.826998 2026] [security2:error] [pid 806041:tid 806211] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/users.php"] [unique_id "amuPpELAyZ1MRInzPMYgJAAAAK0"]
[Thu Jul 30 12:53:40.847649 2026] [security2:error] [pid 806041:tid 806284] [client 20.100.187.246:10908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuPpELAyZ1MRInzPMYgKAAAAPY"]
[Thu Jul 30 12:53:41.128566 2026] [security2:error] [pid 806041:tid 806262] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/tinysd.php"] [unique_id "amuPpULAyZ1MRInzPMYgNAAAAOA"]
[Thu Jul 30 12:53:41.128695 2026] [security2:error] [pid 806041:tid 806262] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/tinysd.php"] [unique_id "amuPpULAyZ1MRInzPMYgNAAAAOA"]
[Thu Jul 30 12:53:41.424469 2026] [security2:error] [pid 806041:tid 806197] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ws78.php"] [unique_id "amuPpULAyZ1MRInzPMYgPAAAAJ8"]
[Thu Jul 30 12:53:41.424564 2026] [security2:error] [pid 806041:tid 806197] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ws78.php"] [unique_id "amuPpULAyZ1MRInzPMYgPAAAAJ8"]
[Thu Jul 30 12:53:41.745659 2026] [security2:error] [pid 806041:tid 806279] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/elp.php"] [unique_id "amuPpULAyZ1MRInzPMYgZQAAAPE"]
[Thu Jul 30 12:53:41.745781 2026] [security2:error] [pid 806041:tid 806279] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/elp.php"] [unique_id "amuPpULAyZ1MRInzPMYgZQAAAPE"]
[Thu Jul 30 12:53:42.048124 2026] [security2:error] [pid 806041:tid 806285] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/atomlib.php"] [unique_id "amuPpkLAyZ1MRInzPMYgagAAAPc"]
[Thu Jul 30 12:53:42.048279 2026] [security2:error] [pid 806041:tid 806285] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/atomlib.php"] [unique_id "amuPpkLAyZ1MRInzPMYgagAAAPc"]
[Thu Jul 30 12:53:42.172092 2026] [security2:error] [pid 806041:tid 806126] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPpkLAyZ1MRInzPMYgewAA4VQ"]
[Thu Jul 30 12:53:42.172262 2026] [security2:error] [pid 806041:tid 806263] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPpkLAyZ1MRInzPMYgewAA4VQ"]
[Thu Jul 30 12:53:42.243866 2026] [security2:error] [pid 806041:tid 806255] [client 92.150.173.45:32858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPpULAyZ1MRInzPMYgRQAAANk"], referer: http://pkf.jo
[Thu Jul 30 12:53:42.373098 2026] [security2:error] [pid 806041:tid 806294] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wyzer3.php"] [unique_id "amuPpkLAyZ1MRInzPMYghAAAAQA"]
[Thu Jul 30 12:53:42.373248 2026] [security2:error] [pid 806041:tid 806294] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wyzer3.php"] [unique_id "amuPpkLAyZ1MRInzPMYghAAAAQA"]
[Thu Jul 30 12:53:42.447329 2026] [security2:error] [pid 806041:tid 806214] [client 74.7.241.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.baytalhuboob.com"] [uri "/index.php"] [unique_id "amuPpULAyZ1MRInzPMYgOQAAsDo"]
[Thu Jul 30 12:53:42.447365 2026] [security2:error] [pid 806041:tid 806214] [client 74.7.241.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.baytalhuboob.com"] [uri "/index.php"] [unique_id "amuPpULAyZ1MRInzPMYgOQAAsDo"]
[Thu Jul 30 12:53:42.512439 2026] [security2:error] [pid 806041:tid 806179] [client 107.150.117.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "website-32717c4b.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuPpkLAyZ1MRInzPMYggwAAAI0"]
[Thu Jul 30 12:53:42.672563 2026] [security2:error] [pid 806041:tid 806264] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/max.php"] [unique_id "amuPpkLAyZ1MRInzPMYgkQAAAOI"]
[Thu Jul 30 12:53:42.672646 2026] [security2:error] [pid 806041:tid 806264] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/max.php"] [unique_id "amuPpkLAyZ1MRInzPMYgkQAAAOI"]
[Thu Jul 30 12:53:42.945211 2026] [security2:error] [pid 806041:tid 806173] [client 20.100.187.246:10916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuPpkLAyZ1MRInzPMYgmQAAAIc"]
[Thu Jul 30 12:53:43.072511 2026] [security2:error] [pid 806041:tid 806275] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPpkLAyZ1MRInzPMYgiAAAAO0"]
[Thu Jul 30 12:53:43.130436 2026] [security2:error] [pid 806041:tid 806172] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ftde.php"] [unique_id "amuPp0LAyZ1MRInzPMYgmgAAAIY"]
[Thu Jul 30 12:53:43.130561 2026] [security2:error] [pid 806041:tid 806172] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ftde.php"] [unique_id "amuPp0LAyZ1MRInzPMYgmgAAAIY"]
[Thu Jul 30 12:53:43.218327 2026] [security2:error] [pid 806041:tid 806293] [client 160.191.115.114:45068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPpULAyZ1MRInzPMYgQQAAAP8"], referer: http://pkf.jo
[Thu Jul 30 12:53:43.218422 2026] [security2:error] [pid 806041:tid 806215] [client 153.117.26.0:27568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPpULAyZ1MRInzPMYgPwAAALE"], referer: http://pkf.jo
[Thu Jul 30 12:53:43.260526 2026] [security2:error] [pid 806041:tid 806259] [client 176.29.110.125:30340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPpULAyZ1MRInzPMYgZgAAAN0"], referer: http://pkf.jo
[Thu Jul 30 12:53:43.306465 2026] [security2:error] [pid 806041:tid 806298] [client 99.189.232.230:57118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPpULAyZ1MRInzPMYgaAAAAQQ"], referer: http://pkf.jo
[Thu Jul 30 12:53:43.331326 2026] [security2:error] [pid 806041:tid 806247] [client 197.207.101.239:36164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPpkLAyZ1MRInzPMYgbwAAANE"], referer: http://pkf.jo
[Thu Jul 30 12:53:43.356408 2026] [security2:error] [pid 806041:tid 806281] [client 41.210.155.154:63153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPpkLAyZ1MRInzPMYgfwAAAPM"], referer: http://pkf.jo
[Thu Jul 30 12:53:43.465870 2026] [security2:error] [pid 806041:tid 806292] [client 20.151.221.234:13164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuPp0LAyZ1MRInzPMYgqwAAAP4"]
[Thu Jul 30 12:53:44.050178 2026] [security2:error] [pid 806041:tid 806230] [client 20.100.187.246:27048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuPqELAyZ1MRInzPMYgwwAAAMA"]
[Thu Jul 30 12:53:44.460347 2026] [security2:error] [pid 806041:tid 806264] [client 20.151.221.234:13182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/index/function.php"] [unique_id "amuPqELAyZ1MRInzPMYg1wAAAOI"]
[Thu Jul 30 12:53:44.770138 2026] [security2:error] [pid 806041:tid 806293] [client 20.100.187.246:10890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuPqELAyZ1MRInzPMYg3AAAAP8"]
[Thu Jul 30 12:53:44.859913 2026] [security2:error] [pid 806041:tid 806265] [client 104.28.161.29:19715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.161.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvapesonline.com"] [uri "/wp-login.php"] [unique_id "amuPqELAyZ1MRInzPMYg4gAAAOM"]
[Thu Jul 30 12:53:45.508356 2026] [core:notice] [pid 806041:tid 806297] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:45.514731 2026] [security2:error] [pid 806041:tid 806297] [client 103.215.74.26:38418] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPqULAyZ1MRInzPMYg_QAAAQM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:45.537632 2026] [security2:error] [pid 806041:tid 806194] [client 150.107.232.194:27323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPqULAyZ1MRInzPMYg_gAAAJw"]
[Thu Jul 30 12:53:45.537771 2026] [security2:error] [pid 806041:tid 806194] [client 150.107.232.194:27323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPqULAyZ1MRInzPMYg_gAAAJw"]
[Thu Jul 30 12:53:45.714567 2026] [autoindex:error] [pid 806041:tid 806275] [client 20.151.221.234:63811] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:45.926025 2026] [autoindex:error] [pid 806041:tid 806208] [client 20.151.221.234:63811] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:46.125366 2026] [security2:error] [pid 806041:tid 806183] [client 20.151.221.234:63811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/aaa.php"] [unique_id "amuPqkLAyZ1MRInzPMYhGQAAAJE"]
[Thu Jul 30 12:53:46.227862 2026] [core:notice] [pid 806041:tid 806199] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:46.246021 2026] [core:notice] [pid 806041:tid 806176] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:46.251958 2026] [security2:error] [pid 806041:tid 806176] [client 103.215.74.26:38430] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPqkLAyZ1MRInzPMYhHAAAAIo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:46.593905 2026] [security2:error] [pid 806041:tid 806205] [client 20.100.187.246:10929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuPqkLAyZ1MRInzPMYhLAAAAKc"]
[Thu Jul 30 12:53:46.883473 2026] [security2:error] [pid 806041:tid 806204] [client 20.151.221.234:63858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/getid3-core.php"] [unique_id "amuPqkLAyZ1MRInzPMYhOQAAAKY"]
[Thu Jul 30 12:53:47.021627 2026] [core:notice] [pid 806041:tid 806180] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:47.027887 2026] [security2:error] [pid 806041:tid 806180] [client 103.215.74.26:38434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPq0LAyZ1MRInzPMYhPgAAAI4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:47.701080 2026] [security2:error] [pid 806041:tid 806223] [client 20.151.221.234:56945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/adminer.php"] [unique_id "amuPq0LAyZ1MRInzPMYhTwAAALk"]
[Thu Jul 30 12:53:47.753966 2026] [core:notice] [pid 806041:tid 806281] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:47.760499 2026] [security2:error] [pid 806041:tid 806281] [client 103.215.74.26:38444] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPq0LAyZ1MRInzPMYhUAAAAPM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:47.895662 2026] [security2:error] [pid 806041:tid 806240] [client 20.100.187.246:27152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuPq0LAyZ1MRInzPMYhWQAAAMo"]
[Thu Jul 30 12:53:48.281196 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:48.283929 2026] [core:error] [pid 806041:tid 806184] [client 118.193.69.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:48.283959 2026] [core:error] [pid 806041:tid 806184] [client 118.193.69.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:48.499998 2026] [core:notice] [pid 806041:tid 806256] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:48.506514 2026] [security2:error] [pid 806041:tid 806256] [client 103.215.74.26:38452] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPrELAyZ1MRInzPMYhbgAAANo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:48.569692 2026] [security2:error] [pid 806041:tid 806282] [client 20.100.187.246:27165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuPrELAyZ1MRInzPMYhcAAAAPQ"]
[Thu Jul 30 12:53:49.236879 2026] [core:notice] [pid 806041:tid 806262] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:49.243394 2026] [security2:error] [pid 806041:tid 806262] [client 103.215.74.26:38464] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPrULAyZ1MRInzPMYhfQAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:49.972145 2026] [security2:error] [pid 806041:tid 806280] [client 20.100.187.246:10883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuPrULAyZ1MRInzPMYhlQAAAPI"]
[Thu Jul 30 12:53:49.996528 2026] [core:notice] [pid 806041:tid 806267] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:50.003486 2026] [security2:error] [pid 806041:tid 806267] [client 103.215.74.26:38474] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPrULAyZ1MRInzPMYhlgAAAOU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:50.185256 2026] [security2:error] [pid 806041:tid 806048] [remote 74.7.241.60:45310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amuPrkLAyZ1MRInzPMYhoQAAsgY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 12:53:50.270042 2026] [autoindex:error] [pid 806041:tid 806278] [client 20.151.221.234:13177] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-content/uploads/2024/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:50.471546 2026] [security2:error] [pid 806041:tid 806290] [client 20.151.221.234:13177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/alfa.php"] [unique_id "amuPrkLAyZ1MRInzPMYhqAAAAPw"]
[Thu Jul 30 12:53:50.728018 2026] [core:notice] [pid 806041:tid 806215] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:50.735128 2026] [security2:error] [pid 806041:tid 806215] [client 103.215.74.26:38484] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPrkLAyZ1MRInzPMYhsgAAALE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:51.039635 2026] [core:error] [pid 806041:tid 806224] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:51.039666 2026] [core:error] [pid 806041:tid 806224] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:51.040005 2026] [core:error] [pid 806041:tid 806211] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:51.040023 2026] [core:error] [pid 806041:tid 806211] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:51.085130 2026] [core:error] [pid 806041:tid 806231] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:51.085149 2026] [core:error] [pid 806041:tid 806231] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:51.387219 2026] [security2:error] [pid 806041:tid 806236] [client 20.100.187.246:27064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuPr0LAyZ1MRInzPMYh2AAAAMY"]
[Thu Jul 30 12:53:51.501267 2026] [security2:error] [pid 806041:tid 806293] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPrkLAyZ1MRInzPMYhtQAAAP8"]
[Thu Jul 30 12:53:51.679740 2026] [autoindex:error] [pid 806041:tid 806272] [client 20.151.221.234:16962] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:51.898756 2026] [security2:error] [pid 806041:tid 806290] [client 20.151.221.234:16962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuPr0LAyZ1MRInzPMYh5gAAAPw"]
[Thu Jul 30 12:53:52.135325 2026] [core:error] [pid 806041:tid 806211] [client 118.193.69.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:52.135349 2026] [core:error] [pid 806041:tid 806211] [client 118.193.69.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:52.150944 2026] [security2:error] [pid 806041:tid 806202] [client 50.6.43.217:46870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuPr0LAyZ1MRInzPMYh0AAAAKQ"]
[Thu Jul 30 12:53:52.372496 2026] [security2:error] [pid 806041:tid 806263] [client 217.138.252.123:41272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.252.138.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuPsELAyZ1MRInzPMYh_QAAAOE"]
[Thu Jul 30 12:53:52.372643 2026] [security2:error] [pid 806041:tid 806263] [client 217.138.252.123:41272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuPsELAyZ1MRInzPMYh_QAAAOE"]
[Thu Jul 30 12:53:52.719990 2026] [security2:error] [pid 806041:tid 806234] [client 20.151.221.234:56902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuPsELAyZ1MRInzPMYiFgAAAMQ"]
[Thu Jul 30 12:53:52.923722 2026] [security2:error] [pid 806041:tid 806082] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPsELAyZ1MRInzPMYiHQAAzCg"]
[Thu Jul 30 12:53:52.924004 2026] [security2:error] [pid 806041:tid 806242] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPsELAyZ1MRInzPMYiHQAAzCg"]
[Thu Jul 30 12:53:53.005538 2026] [security2:error] [pid 806041:tid 806191] [client 20.100.187.246:10911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/bek.php"] [unique_id "amuPsULAyZ1MRInzPMYiHgAAAJk"]
[Thu Jul 30 12:53:53.066998 2026] [security2:error] [pid 806041:tid 806220] [client 50.6.43.217:46912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuPsELAyZ1MRInzPMYh-AAAALY"]
[Thu Jul 30 12:53:53.292665 2026] [security2:error] [pid 806041:tid 806236] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPsELAyZ1MRInzPMYiCwAAAMY"]
[Thu Jul 30 12:53:53.517548 2026] [security2:error] [pid 806041:tid 806277] [client 43.162.103.165:38136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.103.162.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amuPsULAyZ1MRInzPMYiLAAAAO8"]
[Thu Jul 30 12:53:54.375880 2026] [security2:error] [pid 806041:tid 806203] [client 20.151.221.234:13151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuPskLAyZ1MRInzPMYiUgAAAKU"]
[Thu Jul 30 12:53:54.710947 2026] [security2:error] [pid 806041:tid 806226] [client 17.241.227.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuPskLAyZ1MRInzPMYiVQAAALw"]
[Thu Jul 30 12:53:55.421132 2026] [core:notice] [pid 806041:tid 806102] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:56.000711 2026] [security2:error] [pid 806041:tid 806173] [client 150.107.232.194:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPtELAyZ1MRInzPMYifgAAAIc"]
[Thu Jul 30 12:53:56.000865 2026] [security2:error] [pid 806041:tid 806173] [client 150.107.232.194:27318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPtELAyZ1MRInzPMYifgAAAIc"]
[Thu Jul 30 12:53:56.061238 2026] [proxy:error] [pid 806041:tid 806246] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:53:56.061306 2026] [proxy_http:error] [pid 806041:tid 806246] [client 9.249.81.158:41044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:53:56.061855 2026] [proxy:error] [pid 806041:tid 806246] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:53:56.061896 2026] [proxy_http:error] [pid 806041:tid 806246] [client 9.249.81.158:41044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:53:56.131844 2026] [security2:error] [pid 806041:tid 806178] [client 20.151.221.234:63849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/edit.php"] [unique_id "amuPtELAyZ1MRInzPMYigQAAAIw"]
[Thu Jul 30 12:53:56.267131 2026] [core:error] [pid 806041:tid 806285] [client 118.193.69.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:56.267160 2026] [core:error] [pid 806041:tid 806285] [client 118.193.69.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:53:56.268356 2026] [security2:error] [pid 806041:tid 806293] [client 20.100.187.246:10904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuPtELAyZ1MRInzPMYiiAAAAP8"]
[Thu Jul 30 12:53:56.459366 2026] [core:notice] [pid 806041:tid 806264] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:56.465696 2026] [security2:error] [pid 806041:tid 806264] [client 103.215.74.26:44454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPtELAyZ1MRInzPMYikgAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:57.183009 2026] [core:notice] [pid 806041:tid 806182] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:57.189221 2026] [security2:error] [pid 806041:tid 806182] [client 103.215.74.26:44462] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPtULAyZ1MRInzPMYiogAAAJA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:57.227003 2026] [autoindex:error] [pid 806041:tid 806187] [client 20.151.221.234:63870] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:53:57.682644 2026] [security2:error] [pid 806041:tid 806200] [client 20.151.221.234:63870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/sf.php"] [unique_id "amuPtULAyZ1MRInzPMYirwAAAKI"]
[Thu Jul 30 12:53:57.950864 2026] [core:notice] [pid 806041:tid 806216] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:57.957262 2026] [security2:error] [pid 806041:tid 806216] [client 103.215.74.26:44464] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPtULAyZ1MRInzPMYitwAAALI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:58.042730 2026] [security2:error] [pid 806041:tid 806261] [client 20.100.187.246:26722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/class.api.php"] [unique_id "amuPtkLAyZ1MRInzPMYivgAAAN8"]
[Thu Jul 30 12:53:58.169008 2026] [security2:error] [pid 806041:tid 806177] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPtkLAyZ1MRInzPMYivAAAizo"]
[Thu Jul 30 12:53:58.339310 2026] [security2:error] [pid 806041:tid 806230] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPtULAyZ1MRInzPMYisAAAwEY"]
[Thu Jul 30 12:53:58.639688 2026] [security2:error] [pid 806041:tid 806271] [client 20.100.187.246:27023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/cong.php"] [unique_id "amuPtkLAyZ1MRInzPMYizAAAAOk"]
[Thu Jul 30 12:53:58.721306 2026] [core:notice] [pid 806041:tid 806298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:58.727572 2026] [security2:error] [pid 806041:tid 806298] [client 103.215.74.26:44476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPtkLAyZ1MRInzPMYizQAAAQQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:53:59.377954 2026] [security2:error] [pid 806041:tid 806179] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPt0LAyZ1MRInzPMYi2AAAjVI"]
[Thu Jul 30 12:53:59.461215 2026] [core:notice] [pid 806041:tid 806243] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:53:59.467573 2026] [security2:error] [pid 806041:tid 806243] [client 103.215.74.26:44484] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPt0LAyZ1MRInzPMYi3AAAAM0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:00.032252 2026] [access_compat:error] [pid 806041:tid 806166] [remote 157.245.105.107:0] AH01797: client denied by server configuration: /home1/glbnyxte/public_html/website_ed9bceb3/server-status
[Thu Jul 30 12:54:00.131103 2026] [autoindex:error] [pid 806041:tid 806176] [client 20.151.221.234:13129] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:54:00.184328 2026] [core:notice] [pid 806041:tid 806171] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:00.190730 2026] [security2:error] [pid 806041:tid 806171] [client 103.215.74.26:44486] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPuELAyZ1MRInzPMYi8gAAAIU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:00.329452 2026] [security2:error] [pid 806041:tid 806285] [client 20.151.221.234:13129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wso.php"] [unique_id "amuPuELAyZ1MRInzPMYi9AAAAPc"]
[Thu Jul 30 12:54:00.923613 2026] [core:notice] [pid 806041:tid 806237] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:00.930164 2026] [security2:error] [pid 806041:tid 806237] [client 103.215.74.26:44494] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPuELAyZ1MRInzPMYi_wAAAMc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:00.971109 2026] [core:error] [pid 806041:tid 806206] [client 118.193.69.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:54:00.971129 2026] [core:error] [pid 806041:tid 806206] [client 118.193.69.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:54:01.226079 2026] [security2:error] [pid 806041:tid 806282] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPuULAyZ1MRInzPMYjCgAA9G8"]
[Thu Jul 30 12:54:01.231267 2026] [security2:error] [pid 806041:tid 806289] [client 20.151.221.234:13131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/ioxi-o.php"] [unique_id "amuPuULAyZ1MRInzPMYjDgAAAPs"]
[Thu Jul 30 12:54:01.666029 2026] [core:notice] [pid 806041:tid 806277] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:01.672350 2026] [security2:error] [pid 806041:tid 806277] [client 103.215.74.26:44502] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPuULAyZ1MRInzPMYjFgAAAO8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:02.184818 2026] [security2:error] [pid 806041:tid 806244] [client 20.151.221.234:16961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/file56.php"] [unique_id "amuPukLAyZ1MRInzPMYjJwAAAM4"]
[Thu Jul 30 12:54:02.186787 2026] [security2:error] [pid 806041:tid 806200] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPukLAyZ1MRInzPMYjIAAAong"]
[Thu Jul 30 12:54:02.319693 2026] [security2:error] [pid 806041:tid 806232] [client 74.7.241.134:39270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "asd.fyv.temporary.site"] [uri "/robots.txt"] [unique_id "amuPukLAyZ1MRInzPMYjKQAAAMI"]
[Thu Jul 30 12:54:02.408218 2026] [core:notice] [pid 806041:tid 806278] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:02.414713 2026] [security2:error] [pid 806041:tid 806278] [client 103.215.74.26:44518] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPukLAyZ1MRInzPMYjKgAAAPA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:02.690566 2026] [core:notice] [pid 806041:tid 806194] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:03.161008 2026] [core:notice] [pid 806041:tid 806238] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:03.166849 2026] [security2:error] [pid 806041:tid 806238] [client 103.215.74.26:40802] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPu0LAyZ1MRInzPMYjPQAAAMg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:03.208425 2026] [security2:error] [pid 806041:tid 806218] [client 20.100.187.246:10897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/content.php"] [unique_id "amuPu0LAyZ1MRInzPMYjQQAAALQ"]
[Thu Jul 30 12:54:03.355064 2026] [security2:error] [pid 806041:tid 806173] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPukLAyZ1MRInzPMYjOAAAh18"]
[Thu Jul 30 12:54:03.798538 2026] [security2:error] [pid 806041:tid 806163] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPu0LAyZ1MRInzPMYjUAAAn3k"]
[Thu Jul 30 12:54:03.798710 2026] [security2:error] [pid 806041:tid 806197] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPu0LAyZ1MRInzPMYjUAAAn3k"]
[Thu Jul 30 12:54:03.891075 2026] [core:notice] [pid 806041:tid 806196] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:03.897699 2026] [security2:error] [pid 806041:tid 806196] [client 103.215.74.26:40810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPu0LAyZ1MRInzPMYjUQAAAJ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:04.118934 2026] [security2:error] [pid 806041:tid 806243] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPu0LAyZ1MRInzPMYjUgAAzQ4"]
[Thu Jul 30 12:54:04.257774 2026] [security2:error] [pid 806041:tid 806188] [client 20.100.187.246:26706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuPvELAyZ1MRInzPMYjXAAAAJY"]
[Thu Jul 30 12:54:04.293989 2026] [security2:error] [pid 806041:tid 806203] [client 20.151.221.234:13173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuPvELAyZ1MRInzPMYjYAAAAKU"]
[Thu Jul 30 12:54:04.622659 2026] [core:notice] [pid 806041:tid 806251] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:04.629376 2026] [security2:error] [pid 806041:tid 806251] [client 103.215.74.26:40822] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPvELAyZ1MRInzPMYjZAAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:04.630759 2026] [core:notice] [pid 806041:tid 806258] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:04.638604 2026] [security2:error] [pid 806041:tid 806257] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuPvELAyZ1MRInzPMYjUwAA23o"]
[Thu Jul 30 12:54:04.663581 2026] [security2:error] [pid 806041:tid 806165] [remote 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPvELAyZ1MRInzPMYjYwAAins"]
[Thu Jul 30 12:54:05.225935 2026] [security2:error] [pid 806041:tid 806244] [client 20.100.187.246:10491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/elp.php"] [unique_id "amuPvULAyZ1MRInzPMYjcgAAAM4"]
[Thu Jul 30 12:54:05.373463 2026] [core:notice] [pid 806041:tid 806273] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:05.379773 2026] [security2:error] [pid 806041:tid 806273] [client 103.215.74.26:40832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPvULAyZ1MRInzPMYjegAAAOs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:05.411097 2026] [security2:error] [pid 806041:tid 806220] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPvULAyZ1MRInzPMYjdQAAthU"]
[Thu Jul 30 12:54:06.052492 2026] [security2:error] [pid 806041:tid 806198] [client 223.109.255.170:49624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-shox-tl-black-white-3/"] [unique_id "amuPvkLAyZ1MRInzPMYjjQAAAKA"]
[Thu Jul 30 12:54:06.052634 2026] [security2:error] [pid 806041:tid 806198] [client 223.109.255.170:49624] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-shox-tl-black-white-3/"] [unique_id "amuPvkLAyZ1MRInzPMYjjQAAAKA"]
[Thu Jul 30 12:54:06.075431 2026] [security2:error] [pid 806041:tid 806298] [client 20.151.221.234:56930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuPvkLAyZ1MRInzPMYjjgAAAQQ"]
[Thu Jul 30 12:54:06.098286 2026] [core:notice] [pid 806041:tid 806185] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:06.104673 2026] [security2:error] [pid 806041:tid 806185] [client 103.215.74.26:40838] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPvkLAyZ1MRInzPMYjjwAAAJM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:06.197347 2026] [security2:error] [pid 806041:tid 806294] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPvkLAyZ1MRInzPMYjjAABAB4"]
[Thu Jul 30 12:54:06.342954 2026] [security2:error] [pid 806041:tid 806297] [client 20.100.187.246:42187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuPvkLAyZ1MRInzPMYjlgAAAQM"]
[Thu Jul 30 12:54:06.505477 2026] [security2:error] [pid 806041:tid 806214] [client 150.107.232.194:26594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPvkLAyZ1MRInzPMYjngAAALA"]
[Thu Jul 30 12:54:06.505579 2026] [security2:error] [pid 806041:tid 806214] [client 150.107.232.194:26594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPvkLAyZ1MRInzPMYjngAAALA"]
[Thu Jul 30 12:54:06.857560 2026] [core:notice] [pid 806041:tid 806251] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:06.863561 2026] [security2:error] [pid 806041:tid 806251] [client 103.215.74.26:40854] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPvkLAyZ1MRInzPMYjpQAAANU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:07.118205 2026] [security2:error] [pid 806041:tid 806087] [remote 157.245.105.107:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.applinex.pro"] [uri "/.env"] [unique_id "amuPv0LAyZ1MRInzPMYjqgAAzi0"]
[Thu Jul 30 12:54:07.208069 2026] [security2:error] [pid 806041:tid 806258] [client 20.151.221.234:13171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/edit.php"] [unique_id "amuPv0LAyZ1MRInzPMYjrwAAANw"]
[Thu Jul 30 12:54:07.271370 2026] [security2:error] [pid 806041:tid 806194] [client 20.100.187.246:26247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuPv0LAyZ1MRInzPMYjsAAAAJw"]
[Thu Jul 30 12:54:07.588169 2026] [core:notice] [pid 806041:tid 806262] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:07.594684 2026] [security2:error] [pid 806041:tid 806262] [client 103.215.74.26:40866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPv0LAyZ1MRInzPMYjvgAAAOA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:08.097133 2026] [security2:error] [pid 806041:tid 806249] [client 20.151.221.234:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/2.php"] [unique_id "amuPwELAyZ1MRInzPMYjyQAAANM"]
[Thu Jul 30 12:54:08.246722 2026] [security2:error] [pid 806041:tid 806245] [client 20.100.187.246:27307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuPwELAyZ1MRInzPMYjzQAAAM8"]
[Thu Jul 30 12:54:08.309762 2026] [security2:error] [pid 806041:tid 806196] [client 50.6.43.217:18186] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuPwELAyZ1MRInzPMYj0QAAAJ4"]
[Thu Jul 30 12:54:08.363310 2026] [core:notice] [pid 806041:tid 806231] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:08.374286 2026] [security2:error] [pid 806041:tid 806231] [client 103.215.74.26:40874] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPwELAyZ1MRInzPMYj0gAAAME"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:08.811904 2026] [core:notice] [pid 806041:tid 806175] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:08.902408 2026] [security2:error] [pid 806041:tid 806205] [client 20.151.221.234:13160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuPwELAyZ1MRInzPMYj4QAAAKc"]
[Thu Jul 30 12:54:09.130045 2026] [core:notice] [pid 806041:tid 806224] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:09.136628 2026] [security2:error] [pid 806041:tid 806224] [client 103.215.74.26:40878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPwULAyZ1MRInzPMYj6QAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:09.174009 2026] [security2:error] [pid 806041:tid 806286] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPwULAyZ1MRInzPMYj5QAA-Ac"]
[Thu Jul 30 12:54:09.845289 2026] [security2:error] [pid 806041:tid 806173] [client 50.6.43.217:18190] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuPwULAyZ1MRInzPMYj9wAAAIc"]
[Thu Jul 30 12:54:09.877776 2026] [core:notice] [pid 806041:tid 806221] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:09.884156 2026] [security2:error] [pid 806041:tid 806221] [client 103.215.74.26:40880] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPwULAyZ1MRInzPMYj-AAAALc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:09.985971 2026] [security2:error] [pid 806041:tid 806262] [client 20.100.187.246:27314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuPwULAyZ1MRInzPMYj_AAAAOA"]
[Thu Jul 30 12:54:10.284199 2026] [security2:error] [pid 806041:tid 806223] [client 20.151.221.234:56935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/mah.php"] [unique_id "amuPwkLAyZ1MRInzPMYkBAAAALk"]
[Thu Jul 30 12:54:10.607046 2026] [core:notice] [pid 806041:tid 806174] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:10.613672 2026] [security2:error] [pid 806041:tid 806174] [client 103.215.74.26:40894] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPwkLAyZ1MRInzPMYkDAAAAIg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:10.633413 2026] [security2:error] [pid 806041:tid 806297] [client 20.52.54.143:1609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-login.php"] [unique_id "amuPwkLAyZ1MRInzPMYkCAAAAQM"]
[Thu Jul 30 12:54:10.633570 2026] [security2:error] [pid 806041:tid 806297] [client 20.52.54.143:1609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.svcambodia.com"] [uri "/wp-login.php"] [unique_id "amuPwkLAyZ1MRInzPMYkCAAAAQM"]
[Thu Jul 30 12:54:11.151057 2026] [security2:error] [pid 806041:tid 806109] [remote 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPw0LAyZ1MRInzPMYkGAAA8EM"]
[Thu Jul 30 12:54:11.332960 2026] [core:notice] [pid 806041:tid 806175] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:11.339446 2026] [security2:error] [pid 806041:tid 806175] [client 103.215.74.26:40904] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPw0LAyZ1MRInzPMYkHAAAAIk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:11.648846 2026] [security2:error] [pid 806041:tid 806279] [client 20.151.221.234:13133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/send.php"] [unique_id "amuPw0LAyZ1MRInzPMYkKAAAAPE"]
[Thu Jul 30 12:54:11.912451 2026] [core:notice] [pid 806041:tid 806264] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:11.947257 2026] [core:notice] [pid 806041:tid 806271] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:12.074389 2026] [core:notice] [pid 806041:tid 806178] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:12.080967 2026] [security2:error] [pid 806041:tid 806178] [client 103.215.74.26:40918] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPxELAyZ1MRInzPMYkNgAAAIw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:12.130182 2026] [security2:error] [pid 806041:tid 806172] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPw0LAyZ1MRInzPMYkJAAAAIY"]
[Thu Jul 30 12:54:12.402187 2026] [security2:error] [pid 806041:tid 806185] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPxELAyZ1MRInzPMYkNwAAk0o"]
[Thu Jul 30 12:54:12.600089 2026] [security2:error] [pid 806041:tid 806196] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPxELAyZ1MRInzPMYkPgAAnlQ"]
[Thu Jul 30 12:54:12.802066 2026] [security2:error] [pid 806041:tid 806275] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPxELAyZ1MRInzPMYkRQAA7VE"]
[Thu Jul 30 12:54:12.807734 2026] [core:notice] [pid 806041:tid 806245] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:12.814339 2026] [security2:error] [pid 806041:tid 806245] [client 103.215.74.26:40926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPxELAyZ1MRInzPMYkSQAAAM8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:12.991144 2026] [security2:error] [pid 806041:tid 806180] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPxELAyZ1MRInzPMYkTQAAjjo"]
[Thu Jul 30 12:54:13.011202 2026] [security2:error] [pid 806041:tid 806223] [client 20.151.221.234:56941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuPxULAyZ1MRInzPMYkWAAAALk"]
[Thu Jul 30 12:54:13.175157 2026] [security2:error] [pid 806041:tid 806253] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPxULAyZ1MRInzPMYkWQAA11I"]
[Thu Jul 30 12:54:13.369965 2026] [security2:error] [pid 806041:tid 806222] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPxULAyZ1MRInzPMYkXwAAuD0"]
[Thu Jul 30 12:54:13.536423 2026] [core:notice] [pid 806041:tid 806246] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:13.542651 2026] [security2:error] [pid 806041:tid 806246] [client 103.215.74.26:15320] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPxULAyZ1MRInzPMYkagAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:14.288806 2026] [core:notice] [pid 806041:tid 806271] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:14.299460 2026] [security2:error] [pid 806041:tid 806271] [client 103.215.74.26:15322] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPxkLAyZ1MRInzPMYkgQAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:14.479189 2026] [security2:error] [pid 806041:tid 806267] [client 14.182.72.248:50871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPxkLAyZ1MRInzPMYkewAAAOU"], referer: http://pkf.jo
[Thu Jul 30 12:54:14.495596 2026] [security2:error] [pid 806041:tid 806264] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPxULAyZ1MRInzPMYkdwAAAOI"]
[Thu Jul 30 12:54:14.541289 2026] [security2:error] [pid 806041:tid 806105] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPxkLAyZ1MRInzPMYkjgAAnj8"]
[Thu Jul 30 12:54:14.541467 2026] [security2:error] [pid 806041:tid 806196] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuPxkLAyZ1MRInzPMYkjgAAnj8"]
[Thu Jul 30 12:54:14.560563 2026] [security2:error] [pid 806041:tid 806244] [client 20.100.187.246:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuPxkLAyZ1MRInzPMYkkQAAAM4"]
[Thu Jul 30 12:54:14.580411 2026] [security2:error] [pid 806041:tid 806197] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPxkLAyZ1MRInzPMYkjAAAn2k"]
[Thu Jul 30 12:54:15.233609 2026] [security2:error] [pid 806041:tid 806195] [client 20.100.187.246:26690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuPx0LAyZ1MRInzPMYkqwAAAJ0"]
[Thu Jul 30 12:54:15.327919 2026] [security2:error] [pid 806041:tid 806298] [client 112.202.225.125:41736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPxkLAyZ1MRInzPMYkgAAAAQQ"], referer: http://pkf.jo
[Thu Jul 30 12:54:15.344694 2026] [security2:error] [pid 806041:tid 806276] [client 180.253.166.183:50895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPxkLAyZ1MRInzPMYkfgAAAO4"], referer: http://pkf.jo
[Thu Jul 30 12:54:15.373534 2026] [security2:error] [pid 806041:tid 806172] [client 113.182.177.69:54173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPxkLAyZ1MRInzPMYkggAAAIY"], referer: http://pkf.jo
[Thu Jul 30 12:54:15.411533 2026] [security2:error] [pid 806041:tid 806211] [client 103.142.185.4:57586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPxkLAyZ1MRInzPMYkhAAAAK0"], referer: http://pkf.jo
[Thu Jul 30 12:54:15.412203 2026] [security2:error] [pid 806041:tid 806291] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPx0LAyZ1MRInzPMYkrAAA_W0"]
[Thu Jul 30 12:54:15.469419 2026] [security2:error] [pid 806041:tid 806218] [client 190.114.34.36:3496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPxkLAyZ1MRInzPMYkiQAAALQ"], referer: http://pkf.jo
[Thu Jul 30 12:54:15.551119 2026] [autoindex:error] [pid 806041:tid 806176] [client 20.151.221.234:16514] AH01276: Cannot serve directory /home2/bonafide/public_html/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:54:15.749056 2026] [security2:error] [pid 806041:tid 806279] [client 20.151.221.234:16514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/about.php"] [unique_id "amuPx0LAyZ1MRInzPMYkuAAAAPE"]
[Thu Jul 30 12:54:16.119850 2026] [security2:error] [pid 806041:tid 806205] [client 89.144.10.41:64978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.10.144.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spacexpress.africa"] [uri "/xmlrpc.php"] [unique_id "amuPx0LAyZ1MRInzPMYktAAAAKc"]
[Thu Jul 30 12:54:16.320251 2026] [security2:error] [pid 806041:tid 806273] [client 177.26.233.147:47558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuPx0LAyZ1MRInzPMYkuQAAAOs"], referer: http://pkf.jo
[Thu Jul 30 12:54:16.510873 2026] [core:notice] [pid 806041:tid 806227] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:16.536044 2026] [security2:error] [pid 806041:tid 806190] [client 20.100.187.246:50986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuPyELAyZ1MRInzPMYkywAAAJg"]
[Thu Jul 30 12:54:16.555967 2026] [security2:error] [pid 806041:tid 806051] [remote 157.245.105.107:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.105.245.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/info.php"] [unique_id "amuPyELAyZ1MRInzPMYkwwAAugk"]
[Thu Jul 30 12:54:16.769287 2026] [core:notice] [pid 806041:tid 806282] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:17.015379 2026] [security2:error] [pid 806041:tid 806197] [client 150.107.232.194:27017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPyULAyZ1MRInzPMYk1wAAAJ8"]
[Thu Jul 30 12:54:17.015504 2026] [security2:error] [pid 806041:tid 806197] [client 150.107.232.194:27017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuPyULAyZ1MRInzPMYk1wAAAJ8"]
[Thu Jul 30 12:54:18.087951 2026] [security2:error] [pid 806041:tid 806257] [client 20.151.221.234:16553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/options.php"] [unique_id "amuPykLAyZ1MRInzPMYk-AAAANs"]
[Thu Jul 30 12:54:18.091407 2026] [security2:error] [pid 806041:tid 806192] [client 20.100.187.246:10458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuPykLAyZ1MRInzPMYk-QAAAJo"]
[Thu Jul 30 12:54:18.346316 2026] [security2:error] [pid 806041:tid 806205] [client 43.133.46.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuPykLAyZ1MRInzPMYk_QAAAKc"]
[Thu Jul 30 12:54:18.392946 2026] [security2:error] [pid 806041:tid 806200] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPykLAyZ1MRInzPMYlAQAAogI"]
[Thu Jul 30 12:54:19.068367 2026] [core:notice] [pid 806041:tid 806256] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:19.084800 2026] [security2:error] [pid 806041:tid 806255] [client 20.100.187.246:26286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuPy0LAyZ1MRInzPMYlJQAAANk"]
[Thu Jul 30 12:54:19.135887 2026] [security2:error] [pid 806041:tid 806296] [client 20.151.221.234:13142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuPy0LAyZ1MRInzPMYlLAAAAQI"]
[Thu Jul 30 12:54:19.656773 2026] [security2:error] [pid 806041:tid 806175] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPy0LAyZ1MRInzPMYlNwAAiS4"]
[Thu Jul 30 12:54:19.985593 2026] [security2:error] [pid 806041:tid 806182] [client 20.151.221.234:56925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-file.php"] [unique_id "amuPy0LAyZ1MRInzPMYlQwAAAJA"]
[Thu Jul 30 12:54:20.062029 2026] [core:notice] [pid 806041:tid 806241] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:20.067692 2026] [security2:error] [pid 806041:tid 806241] [client 103.215.74.26:15326] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPzELAyZ1MRInzPMYlRgAAAMs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:20.108232 2026] [fcgid:warn] [pid 806041:tid 806273] (70014)End of file found: [client 152.32.208.9:55440] mod_fcgid: can't get data from http client
[Thu Jul 30 12:54:20.588330 2026] [security2:error] [pid 806041:tid 806247] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPzELAyZ1MRInzPMYlUQAA0TA"]
[Thu Jul 30 12:54:20.785761 2026] [security2:error] [pid 806041:tid 806233] [client 172.236.9.101:9979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuPzELAyZ1MRInzPMYlTgAAAMM"]
[Thu Jul 30 12:54:20.813609 2026] [core:notice] [pid 806041:tid 806224] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:20.820363 2026] [security2:error] [pid 806041:tid 806224] [client 103.215.74.26:15342] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuPzELAyZ1MRInzPMYlXAAAALo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:20.854253 2026] [security2:error] [pid 806041:tid 806081] [remote 57.141.0.46:40990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amuPzELAyZ1MRInzPMYlXwAA5Sc"]
[Thu Jul 30 12:54:20.874484 2026] [security2:error] [pid 806041:tid 806237] [client 20.100.187.246:50983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuPzELAyZ1MRInzPMYlYAAAAMc"]
[Thu Jul 30 12:54:21.160043 2026] [autoindex:error] [pid 806041:tid 806180] [client 34.224.175.62:37072] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:54:21.202866 2026] [autoindex:error] [pid 806041:tid 806255] [client 34.224.175.62:35802] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:54:21.424431 2026] [security2:error] [pid 806041:tid 806261] [client 20.151.221.234:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/sid3.php"] [unique_id "amuPzULAyZ1MRInzPMYldwAAAN8"]
[Thu Jul 30 12:54:21.527318 2026] [security2:error] [pid 806041:tid 806234] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuPzELAyZ1MRInzPMYlYwAAAMQ"]
[Thu Jul 30 12:54:21.590470 2026] [security2:error] [pid 806041:tid 806171] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuPzULAyZ1MRInzPMYleAAAhSI"]
[Thu Jul 30 12:54:21.749970 2026] [security2:error] [pid 806041:tid 806240] [client 27.2.151.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuPzULAyZ1MRInzPMYlgAAAAMo"], referer: https://cnpinyin.com
[Thu Jul 30 12:54:21.752911 2026] [security2:error] [pid 806041:tid 806236] [client 52.54.95.127:17797] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/02/Preso-300x225.jpg"] [unique_id "amuPzULAyZ1MRInzPMYlggAAAMY"]
[Thu Jul 30 12:54:21.951794 2026] [security2:error] [pid 806041:tid 806172] [client 57.141.0.27:60740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuPzULAyZ1MRInzPMYleQAAhnc"], referer: https://igetvape-australia.com/store/?product-page=12&add-to-cart=115
[Thu Jul 30 12:54:23.540725 2026] [security2:error] [pid 806041:tid 806278] [client 89.144.10.41:65197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.10.144.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spacexpress.africa"] [uri "/wp-login.php"] [unique_id "amuPz0LAyZ1MRInzPMYlrgAAAPA"]
[Thu Jul 30 12:54:24.513471 2026] [security2:error] [pid 806041:tid 806257] [client 20.100.187.246:10445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuP0ELAyZ1MRInzPMYlxAAAANs"]
[Thu Jul 30 12:54:24.900273 2026] [security2:error] [pid 806041:tid 806194] [client 57.141.0.14:24454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuP0ELAyZ1MRInzPMYlwAAAnDM"]
[Thu Jul 30 12:54:25.311922 2026] [security2:error] [pid 806041:tid 806071] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP0ULAyZ1MRInzPMYl1AAAnh0"]
[Thu Jul 30 12:54:25.312086 2026] [security2:error] [pid 806041:tid 806196] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP0ULAyZ1MRInzPMYl1AAAnh0"]
[Thu Jul 30 12:54:25.511134 2026] [security2:error] [pid 806041:tid 806209] [client 20.100.187.246:50956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuP0ULAyZ1MRInzPMYl3gAAAKs"]
[Thu Jul 30 12:54:25.542455 2026] [security2:error] [pid 806041:tid 806174] [client 74.7.228.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.palmtreepools.ca"] [uri "/index.php"] [unique_id "amuP0ULAyZ1MRInzPMYl0wAAiFQ"]
[Thu Jul 30 12:54:25.542483 2026] [security2:error] [pid 806041:tid 806174] [client 74.7.228.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.palmtreepools.ca"] [uri "/index.php"] [unique_id "amuP0ULAyZ1MRInzPMYl0wAAiFQ"]
[Thu Jul 30 12:54:25.545118 2026] [core:error] [pid 806041:tid 806237] [client 66.249.79.173:51034] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:54:25.545148 2026] [core:error] [pid 806041:tid 806237] [client 66.249.79.173:51034] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:54:25.833033 2026] [security2:error] [pid 806041:tid 806298] [client 18.207.89.138:39372] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/02/MATERIAL.jpg"] [unique_id "amuP0ULAyZ1MRInzPMYl6gAAAQQ"]
[Thu Jul 30 12:54:26.468314 2026] [security2:error] [pid 806041:tid 806206] [client 20.100.187.246:27279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuP0kLAyZ1MRInzPMYl-wAAAKg"]
[Thu Jul 30 12:54:26.550416 2026] [core:notice] [pid 806041:tid 806264] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:26.554351 2026] [security2:error] [pid 806041:tid 806258] [client 74.7.228.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "palmtreepools.ca"] [uri "/index.php"] [unique_id "amuP0kLAyZ1MRInzPMYl-QAA3GI"], referer: https://www.palmtreepools.ca/robots.txt
[Thu Jul 30 12:54:26.556813 2026] [security2:error] [pid 806041:tid 806264] [client 103.215.74.26:17948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP0kLAyZ1MRInzPMYl_wAAAOI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:26.727543 2026] [security2:error] [pid 806041:tid 806253] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuP0kLAyZ1MRInzPMYl9QAAANc"]
[Thu Jul 30 12:54:27.303530 2026] [core:notice] [pid 806041:tid 806227] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:27.309837 2026] [security2:error] [pid 806041:tid 806227] [client 103.215.74.26:17952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP00LAyZ1MRInzPMYmDwAAAL0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:27.514368 2026] [security2:error] [pid 806041:tid 806188] [client 150.107.232.194:26979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP00LAyZ1MRInzPMYmFwAAAJY"]
[Thu Jul 30 12:54:27.514474 2026] [security2:error] [pid 806041:tid 806188] [client 150.107.232.194:26979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP00LAyZ1MRInzPMYmFwAAAJY"]
[Thu Jul 30 12:54:28.030066 2026] [core:notice] [pid 806041:tid 806254] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:28.036578 2026] [security2:error] [pid 806041:tid 806254] [client 103.215.74.26:17958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP1ELAyZ1MRInzPMYmJAAAANg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:28.647424 2026] [security2:error] [pid 806041:tid 806146] [remote 157.230.213.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.213.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hikokigo.com"] [uri "/xmlrpc.php"] [unique_id "amuP1ELAyZ1MRInzPMYmMAAAuGg"]
[Thu Jul 30 12:54:28.647667 2026] [security2:error] [pid 806041:tid 806222] [client 157.230.213.121:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hikokigo.com"] [uri "/xmlrpc.php"] [unique_id "amuP1ELAyZ1MRInzPMYmMAAAuGg"]
[Thu Jul 30 12:54:29.297651 2026] [security2:error] [pid 806041:tid 806207] [client 20.100.187.246:26542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuP1ULAyZ1MRInzPMYmRQAAAKk"]
[Thu Jul 30 12:54:29.590933 2026] [security2:error] [pid 806041:tid 806208] [client 157.245.105.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amuP1ULAyZ1MRInzPMYmSwAAqn8"]
[Thu Jul 30 12:54:29.768148 2026] [security2:error] [pid 806041:tid 806051] [remote 57.141.18.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuP1ULAyZ1MRInzPMYmTAAA6Qk"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum%2Ccotton%2Cnylon%2Cplastic%2Csteel&filter_size=extra-extra-large%2Cextra-large%2Clarge&tax_product_cat=sweatshirts&unfilter=1&orderby=menu_order
[Thu Jul 30 12:54:29.777741 2026] [security2:error] [pid 806041:tid 806056] [remote 57.141.18.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuP1ULAyZ1MRInzPMYmTQAA9g4"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum%2Ccotton%2Cnylon%2Cplastic%2Csteel&filter_size=extra-extra-large%2Cextra-large%2Clarge&tax_product_cat=sweatshirts&unfilter=1&orderby=menu_order
[Thu Jul 30 12:54:31.018068 2026] [security2:error] [pid 806041:tid 806232] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuP1kLAyZ1MRInzPMYmaQAAAMI"]
[Thu Jul 30 12:54:31.093200 2026] [security2:error] [pid 806041:tid 806278] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuP1kLAyZ1MRInzPMYmbQAAAPA"]
[Thu Jul 30 12:54:31.166883 2026] [security2:error] [pid 806041:tid 806083] [remote 57.141.0.2:62322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55997217192/feed/rss2/"] [unique_id "amuP10LAyZ1MRInzPMYmdwAAmik"]
[Thu Jul 30 12:54:31.707886 2026] [security2:error] [pid 806041:tid 806238] [client 20.100.187.246:42235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuP10LAyZ1MRInzPMYmgQAAAMg"]
[Thu Jul 30 12:54:31.715381 2026] [core:notice] [pid 806041:tid 806200] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:32.085566 2026] [security2:error] [pid 806041:tid 806174] [client 13.140.147.206:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "appliancerepairservice.one"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuP2ELAyZ1MRInzPMYmkwAAAIg"]
[Thu Jul 30 12:54:32.211856 2026] [core:notice] [pid 806041:tid 806248] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:32.675995 2026] [security2:error] [pid 806041:tid 806245] [client 13.140.147.206:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "appliancerepairservice.one"] [uri "/media/system/js/core.js"] [unique_id "amuP2ELAyZ1MRInzPMYmpAAAAM8"]
[Thu Jul 30 12:54:33.140576 2026] [core:error] [pid 806041:tid 806182] [client 54.174.209.145:49050] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:54:33.140603 2026] [core:error] [pid 806041:tid 806182] [client 54.174.209.145:49050] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:54:33.400364 2026] [security2:error] [pid 806041:tid 806230] [client 20.100.187.246:42219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuP2ULAyZ1MRInzPMYmswAAAMA"]
[Thu Jul 30 12:54:33.774397 2026] [security2:error] [pid 806041:tid 806258] [client 172.236.9.101:20407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuP2ULAyZ1MRInzPMYmrwAAANw"]
[Thu Jul 30 12:54:33.844912 2026] [core:notice] [pid 806041:tid 806187] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:33.855639 2026] [security2:error] [pid 806041:tid 806187] [client 103.215.74.26:54426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP2ULAyZ1MRInzPMYmwAAAAJU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:33.996177 2026] [core:notice] [pid 806041:tid 806247] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:34.274320 2026] [security2:error] [pid 806041:tid 806294] [client 20.100.187.246:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuP2kLAyZ1MRInzPMYmywAAAQA"]
[Thu Jul 30 12:54:34.606255 2026] [core:notice] [pid 806041:tid 806205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:34.612287 2026] [security2:error] [pid 806041:tid 806205] [client 103.215.74.26:54432] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP2kLAyZ1MRInzPMYm1QAAAKc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:35.175239 2026] [security2:error] [pid 806041:tid 806228] [client 179.43.134.114:37514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/wp-login.php"] [unique_id "amuP2kLAyZ1MRInzPMYm2QAAAL4"]
[Thu Jul 30 12:54:35.326911 2026] [core:notice] [pid 806041:tid 806181] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:35.332992 2026] [security2:error] [pid 806041:tid 806181] [client 103.215.74.26:54448] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP20LAyZ1MRInzPMYm5gAAAI8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:35.355046 2026] [security2:error] [pid 806041:tid 806102] [remote 60.205.8.163:43404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.8.205.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/wp-login.php"] [unique_id "amuP20LAyZ1MRInzPMYm4wAAsDw"]
[Thu Jul 30 12:54:35.657569 2026] [security2:error] [pid 806041:tid 806113] [remote 74.7.241.59:53316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuP20LAyZ1MRInzPMYm8wAA4kc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/classes
[Thu Jul 30 12:54:35.817693 2026] [security2:error] [pid 806041:tid 806104] [remote 57.141.18.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuP20LAyZ1MRInzPMYm9AAA5D4"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,plastic,titanium,steel,nylon,silicon&min_price=300&orderby=popularity&rating=5&filter_brand=santa-cruz&unfilter=1
[Thu Jul 30 12:54:35.967666 2026] [core:notice] [pid 806041:tid 806249] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:36.086525 2026] [security2:error] [pid 806041:tid 806077] [remote 57.141.18.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuP20LAyZ1MRInzPMYm9QAAqSM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,plastic,titanium,steel,nylon,silicon&min_price=300&orderby=popularity&rating=5&filter_brand=santa-cruz&unfilter=1
[Thu Jul 30 12:54:36.111268 2026] [core:notice] [pid 806041:tid 806194] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:36.115551 2026] [security2:error] [pid 806041:tid 806093] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP3ELAyZ1MRInzPMYnAAAA3DM"]
[Thu Jul 30 12:54:36.115715 2026] [security2:error] [pid 806041:tid 806258] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP3ELAyZ1MRInzPMYnAAAA3DM"]
[Thu Jul 30 12:54:36.254842 2026] [core:notice] [pid 806041:tid 806209] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:36.399400 2026] [core:notice] [pid 806041:tid 806248] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:36.544747 2026] [core:notice] [pid 806041:tid 806270] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:37.129587 2026] [security2:error] [pid 806041:tid 806277] [client 20.100.187.246:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuP3ULAyZ1MRInzPMYnHAAAAO8"]
[Thu Jul 30 12:54:37.839109 2026] [security2:error] [pid 806041:tid 806238] [client 213.152.161.170:54392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuP3ULAyZ1MRInzPMYnKgAAAMg"]
[Thu Jul 30 12:54:37.839226 2026] [security2:error] [pid 806041:tid 806238] [client 213.152.161.170:54392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuP3ULAyZ1MRInzPMYnKgAAAMg"]
[Thu Jul 30 12:54:37.979870 2026] [security2:error] [pid 806041:tid 806242] [client 150.107.232.194:27347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP3ULAyZ1MRInzPMYnLAAAAMw"]
[Thu Jul 30 12:54:37.980005 2026] [security2:error] [pid 806041:tid 806242] [client 150.107.232.194:27347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP3ULAyZ1MRInzPMYnLAAAAMw"]
[Thu Jul 30 12:54:38.932912 2026] [security2:error] [pid 806041:tid 806108] [remote 72.167.132.114:33060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-eea484b2.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuP3kLAyZ1MRInzPMYnRQAAi0I"]
[Thu Jul 30 12:54:39.010404 2026] [core:notice] [pid 806041:tid 806192] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:39.842630 2026] [security2:error] [pid 806041:tid 806289] [client 172.236.9.101:49615] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuP30LAyZ1MRInzPMYnUAAAAPs"]
[Thu Jul 30 12:54:40.430228 2026] [security2:error] [pid 806041:tid 806186] [client 20.100.187.246:26545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuP4ELAyZ1MRInzPMYnawAAAJQ"]
[Thu Jul 30 12:54:41.044406 2026] [core:notice] [pid 806041:tid 806188] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:41.050994 2026] [security2:error] [pid 806041:tid 806188] [client 103.215.74.26:54462] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP4ULAyZ1MRInzPMYnfAAAAJY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:41.426873 2026] [core:notice] [pid 806041:tid 806245] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:41.779144 2026] [core:notice] [pid 806041:tid 806269] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:41.785590 2026] [security2:error] [pid 806041:tid 806269] [client 103.215.74.26:54476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP4ULAyZ1MRInzPMYniwAAAOc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:41.930853 2026] [core:notice] [pid 806041:tid 806286] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:42.093869 2026] [security2:error] [pid 806041:tid 806217] [client 152.32.208.9:53692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wce.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuP4ULAyZ1MRInzPMYnkgAAALM"]
[Thu Jul 30 12:54:44.008425 2026] [security2:error] [pid 806041:tid 806234] [client 20.100.187.246:25247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuP5ELAyZ1MRInzPMYnxwAAAMQ"]
[Thu Jul 30 12:54:45.363879 2026] [security2:error] [pid 806041:tid 806204] [client 111.221.44.115:61264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jwcpartners.org"] [uri "/wp-json/batch/v1"] [unique_id "amuP5ULAyZ1MRInzPMYn3QAAAKY"]
[Thu Jul 30 12:54:45.486550 2026] [security2:error] [pid 806041:tid 806239] [client 111.221.44.115:61270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jwcpartners.org"] [uri "/"] [unique_id "amuP5ULAyZ1MRInzPMYn4gAAAMk"]
[Thu Jul 30 12:54:45.594612 2026] [security2:error] [pid 806041:tid 806246] [client 111.221.44.115:61274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jwcpartners.org"] [uri "/wp-json/batch/v1"] [unique_id "amuP5ULAyZ1MRInzPMYn5gAAANA"]
[Thu Jul 30 12:54:45.882064 2026] [security2:error] [pid 806041:tid 806189] [client 152.32.208.9:53706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wce.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuP5ULAyZ1MRInzPMYn6AAAAJc"]
[Thu Jul 30 12:54:46.044569 2026] [security2:error] [pid 806041:tid 806260] [client 172.202.44.182:44685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amuP5kLAyZ1MRInzPMYn8gAAAN4"]
[Thu Jul 30 12:54:46.048962 2026] [security2:error] [pid 806041:tid 806247] [client 37.205.116.171:2212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuP5ULAyZ1MRInzPMYn5wAAANE"], referer: http://pkf.jo
[Thu Jul 30 12:54:46.376706 2026] [security2:error] [pid 806041:tid 806205] [client 123.20.168.68:37428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuP5kLAyZ1MRInzPMYn9gAAAKc"], referer: http://pkf.jo
[Thu Jul 30 12:54:46.700139 2026] [security2:error] [pid 806041:tid 806058] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP5kLAyZ1MRInzPMYoAgAA7hA"]
[Thu Jul 30 12:54:46.700293 2026] [security2:error] [pid 806041:tid 806276] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP5kLAyZ1MRInzPMYoAgAA7hA"]
[Thu Jul 30 12:54:46.907460 2026] [security2:error] [pid 806041:tid 806277] [client 49.207.223.158:24908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuP5kLAyZ1MRInzPMYoAQAAAO8"], referer: http://pkf.jo
[Thu Jul 30 12:54:47.001793 2026] [security2:error] [pid 806041:tid 806176] [client 172.202.44.182:26987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/xleet.php"] [unique_id "amuP50LAyZ1MRInzPMYoBwAAAIo"]
[Thu Jul 30 12:54:47.200842 2026] [security2:error] [pid 806041:tid 806292] [client 50.110.209.138:41473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuP5kLAyZ1MRInzPMYoAwAAAP4"], referer: http://pkf.jo
[Thu Jul 30 12:54:47.534279 2026] [core:notice] [pid 806041:tid 806198] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:47.543390 2026] [security2:error] [pid 806041:tid 806198] [client 103.215.74.26:24246] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP50LAyZ1MRInzPMYoDwAAAKA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:48.206609 2026] [security2:error] [pid 806041:tid 806233] [client 172.202.44.182:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/ds.php"] [unique_id "amuP6ELAyZ1MRInzPMYoHwAAAMM"]
[Thu Jul 30 12:54:48.262897 2026] [core:notice] [pid 806041:tid 806223] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:48.269170 2026] [security2:error] [pid 806041:tid 806223] [client 103.215.74.26:24260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP6ELAyZ1MRInzPMYoJAAAALk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:48.450543 2026] [security2:error] [pid 806041:tid 806242] [client 150.107.232.194:27122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP6ELAyZ1MRInzPMYoJQAAAMw"]
[Thu Jul 30 12:54:48.450737 2026] [security2:error] [pid 806041:tid 806242] [client 150.107.232.194:27122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP6ELAyZ1MRInzPMYoJQAAAMw"]
[Thu Jul 30 12:54:48.533504 2026] [security2:error] [pid 806041:tid 806186] [client 178.125.247.168:45316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuP6ELAyZ1MRInzPMYoIwAAAJQ"], referer: http://pkf.jo
[Thu Jul 30 12:54:50.153548 2026] [security2:error] [pid 806041:tid 806212] [client 46.185.169.166:48872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuP6ULAyZ1MRInzPMYoRQAAAK4"], referer: http://pkf.jo
[Thu Jul 30 12:54:50.474442 2026] [security2:error] [pid 806041:tid 806172] [client 172.202.44.182:13359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/f5.php"] [unique_id "amuP6kLAyZ1MRInzPMYoUgAAAIY"]
[Thu Jul 30 12:54:50.787150 2026] [security2:error] [pid 806041:tid 806244] [client 20.100.187.246:27385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuP6kLAyZ1MRInzPMYoVQAAAM4"]
[Thu Jul 30 12:54:51.305085 2026] [security2:error] [pid 806041:tid 806213] [client 172.202.44.182:13361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/god4m.php"] [unique_id "amuP60LAyZ1MRInzPMYoYwAAAK8"]
[Thu Jul 30 12:54:51.328027 2026] [security2:error] [pid 806041:tid 806079] [remote 5.253.84.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jipkl.com"] [uri "/wp-login.php"] [unique_id "amuP60LAyZ1MRInzPMYoZAABASU"]
[Thu Jul 30 12:54:51.389816 2026] [security2:error] [pid 806041:tid 806141] [remote 74.7.241.60:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amuP60LAyZ1MRInzPMYoaAAAomM"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 12:54:51.780801 2026] [security2:error] [pid 806041:tid 806107] [remote 5.253.84.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jipkl.com"] [uri "/administrator/"] [unique_id "amuP60LAyZ1MRInzPMYobAAA1kE"]
[Thu Jul 30 12:54:51.820509 2026] [security2:error] [pid 806041:tid 806191] [client 20.100.187.246:27362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuP60LAyZ1MRInzPMYobgAAAJk"]
[Thu Jul 30 12:54:53.041754 2026] [security2:error] [pid 806041:tid 806243] [client 172.202.44.182:43833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/info.php"] [unique_id "amuP7ULAyZ1MRInzPMYokgAAAM0"]
[Thu Jul 30 12:54:53.860567 2026] [security2:error] [pid 806041:tid 806238] [client 172.236.9.101:35051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuP7ULAyZ1MRInzPMYonAAAAMg"]
[Thu Jul 30 12:54:53.987225 2026] [core:notice] [pid 806041:tid 806260] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:53.994802 2026] [security2:error] [pid 806041:tid 806260] [client 103.215.74.26:22910] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP7ULAyZ1MRInzPMYorgAAAN4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:54.423723 2026] [core:notice] [pid 806041:tid 806291] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:54.726615 2026] [core:notice] [pid 806041:tid 806271] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:54.733079 2026] [security2:error] [pid 806041:tid 806271] [client 103.215.74.26:22918] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP7kLAyZ1MRInzPMYowAAAAOk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:55.441100 2026] [security2:error] [pid 806041:tid 806262] [client 213.152.161.170:38940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuP70LAyZ1MRInzPMYozQAAAOA"]
[Thu Jul 30 12:54:55.441201 2026] [security2:error] [pid 806041:tid 806262] [client 213.152.161.170:38940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuP70LAyZ1MRInzPMYozQAAAOA"]
[Thu Jul 30 12:54:55.458915 2026] [core:notice] [pid 806041:tid 806181] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:55.473029 2026] [core:notice] [pid 806041:tid 806263] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:55.478944 2026] [security2:error] [pid 806041:tid 806263] [client 103.215.74.26:22926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP70LAyZ1MRInzPMYozwAAAOE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:55.551062 2026] [security2:error] [pid 806041:tid 806286] [client 152.32.208.9:57902] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.wce.gzj.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amuP70LAyZ1MRInzPMYo0QAAAPg"]
[Thu Jul 30 12:54:55.952281 2026] [security2:error] [pid 806041:tid 806179] [client 172.202.44.182:34436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/.__info.php"] [unique_id "amuP70LAyZ1MRInzPMYo3AAAAI0"]
[Thu Jul 30 12:54:56.019371 2026] [security2:error] [pid 806041:tid 806219] [client 20.100.187.246:25175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuP8ELAyZ1MRInzPMYo3QAAALU"]
[Thu Jul 30 12:54:56.233158 2026] [core:notice] [pid 806041:tid 806294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:56.239588 2026] [security2:error] [pid 806041:tid 806294] [client 103.215.74.26:22938] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP8ELAyZ1MRInzPMYo6AAAAQA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:54:56.479860 2026] [core:notice] [pid 806041:tid 806193] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:54:56.751421 2026] [security2:error] [pid 806041:tid 806191] [client 172.236.9.101:37835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuP8ELAyZ1MRInzPMYo6QAAAJk"]
[Thu Jul 30 12:54:56.953486 2026] [security2:error] [pid 806041:tid 806297] [client 172.202.44.182:34492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/0.php"] [unique_id "amuP8ELAyZ1MRInzPMYo9QAAAQM"]
[Thu Jul 30 12:54:57.518587 2026] [security2:error] [pid 806041:tid 806103] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP8ULAyZ1MRInzPMYo_wAA7D0"]
[Thu Jul 30 12:54:57.518743 2026] [security2:error] [pid 806041:tid 806274] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP8ULAyZ1MRInzPMYo_wAA7D0"]
[Thu Jul 30 12:54:58.020002 2026] [security2:error] [pid 806041:tid 806229] [client 172.202.44.182:26764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/07.php"] [unique_id "amuP8kLAyZ1MRInzPMYpCgAAAL8"]
[Thu Jul 30 12:54:58.910521 2026] [security2:error] [pid 806041:tid 806226] [client 150.107.232.194:26549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP8kLAyZ1MRInzPMYpHgAAALw"]
[Thu Jul 30 12:54:58.910645 2026] [security2:error] [pid 806041:tid 806226] [client 150.107.232.194:26549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP8kLAyZ1MRInzPMYpHgAAALw"]
[Thu Jul 30 12:54:59.077172 2026] [security2:error] [pid 806041:tid 806280] [client 172.202.44.182:34451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/dropdown.php"] [unique_id "amuP80LAyZ1MRInzPMYpHwAAAPI"]
[Thu Jul 30 12:54:59.667833 2026] [security2:error] [pid 806041:tid 806194] [client 217.181.86.215:28850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuP80LAyZ1MRInzPMYpKgAAnHQ"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 12:55:00.751226 2026] [security2:error] [pid 806041:tid 806196] [client 20.100.187.246:24644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuP9ELAyZ1MRInzPMYpTgAAAJ4"]
[Thu Jul 30 12:55:00.868127 2026] [security2:error] [pid 806041:tid 806271] [client 121.237.36.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuP9ELAyZ1MRInzPMYpRAAAAOk"]
[Thu Jul 30 12:55:01.520066 2026] [security2:error] [pid 806041:tid 806232] [client 172.202.44.182:43919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/makeasmtp.php"] [unique_id "amuP9ULAyZ1MRInzPMYpbwAAAMI"]
[Thu Jul 30 12:55:01.878810 2026] [fcgid:warn] [pid 806041:tid 806195] (70014)End of file found: [client 167.94.146.49:44678] mod_fcgid: can't get data from http client
[Thu Jul 30 12:55:01.984193 2026] [core:notice] [pid 806041:tid 806207] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:01.990964 2026] [security2:error] [pid 806041:tid 806207] [client 103.215.74.26:22942] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP9ULAyZ1MRInzPMYpfAAAAKk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:02.352601 2026] [security2:error] [pid 806041:tid 806270] [client 172.202.44.182:35531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wp-sigunq.php"] [unique_id "amuP9kLAyZ1MRInzPMYpggAAAOg"]
[Thu Jul 30 12:55:02.713006 2026] [core:notice] [pid 806041:tid 806183] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:02.719563 2026] [security2:error] [pid 806041:tid 806183] [client 103.215.74.26:22952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP9kLAyZ1MRInzPMYpiQAAAJE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:02.787444 2026] [security2:error] [pid 806041:tid 806272] [client 20.100.187.246:27224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuP9kLAyZ1MRInzPMYpigAAAOo"]
[Thu Jul 30 12:55:02.967360 2026] [security2:error] [pid 806041:tid 806176] [client 47.128.122.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuP9kLAyZ1MRInzPMYpjQAAAIo"]
[Thu Jul 30 12:55:03.435466 2026] [core:notice] [pid 806041:tid 806229] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:03.441291 2026] [security2:error] [pid 806041:tid 806229] [client 103.215.74.26:46022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP90LAyZ1MRInzPMYpoAAAAL8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:03.710160 2026] [security2:error] [pid 806041:tid 806201] [client 20.100.187.246:24700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuP90LAyZ1MRInzPMYppgAAAKM"]
[Thu Jul 30 12:55:04.183628 2026] [core:notice] [pid 806041:tid 806204] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:04.190173 2026] [security2:error] [pid 806041:tid 806204] [client 103.215.74.26:46026] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP-ELAyZ1MRInzPMYpsgAAAKY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:04.791177 2026] [security2:error] [pid 806041:tid 806192] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuP-ELAyZ1MRInzPMYpsQAAmhI"]
[Thu Jul 30 12:55:04.871659 2026] [core:error] [pid 806041:tid 806174] [client 167.94.146.49:44728] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:04.871688 2026] [core:error] [pid 806041:tid 806174] [client 167.94.146.49:44728] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:04.917739 2026] [core:notice] [pid 806041:tid 806177] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:04.923973 2026] [security2:error] [pid 806041:tid 806177] [client 103.215.74.26:46032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP-ELAyZ1MRInzPMYpwAAAAIs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:05.660435 2026] [core:notice] [pid 806041:tid 806296] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:05.666933 2026] [security2:error] [pid 806041:tid 806296] [client 103.215.74.26:46062] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP-ULAyZ1MRInzPMYp2QAAAQI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:06.249443 2026] [core:notice] [pid 806041:tid 806214] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:06.399939 2026] [core:notice] [pid 806041:tid 806286] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:06.406279 2026] [security2:error] [pid 806041:tid 806286] [client 103.215.74.26:46166] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP-kLAyZ1MRInzPMYp5gAAAPg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:07.138273 2026] [core:notice] [pid 806041:tid 806246] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:07.144623 2026] [security2:error] [pid 806041:tid 806246] [client 103.215.74.26:46176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuP-0LAyZ1MRInzPMYp-wAAANA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:07.507261 2026] [autoindex:error] [pid 806041:tid 806278] [client 175.27.136.83:58668] AH01276: Cannot serve directory /home2/nxtudite/public_html/riisesolution.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:55:07.812075 2026] [security2:error] [pid 806041:tid 806200] [client 172.202.44.182:27445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wso112233.php"] [unique_id "amuP-0LAyZ1MRInzPMYqBwAAAKI"]
[Thu Jul 30 12:55:08.279658 2026] [security2:error] [pid 806041:tid 806133] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP_ELAyZ1MRInzPMYqEgAAils"]
[Thu Jul 30 12:55:08.279804 2026] [security2:error] [pid 806041:tid 806176] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuP_ELAyZ1MRInzPMYqEgAAils"]
[Thu Jul 30 12:55:08.289366 2026] [core:notice] [pid 806041:tid 806209] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:09.094012 2026] [security2:error] [pid 806041:tid 806226] [client 74.7.241.182:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuP-kLAyZ1MRInzPMYp8gAAALw"]
[Thu Jul 30 12:55:09.094038 2026] [security2:error] [pid 806041:tid 806226] [client 74.7.241.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuP-kLAyZ1MRInzPMYp8gAAALw"]
[Thu Jul 30 12:55:09.094878 2026] [security2:error] [pid 806041:tid 806215] [client 74.7.241.182:38674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ylw.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuP-kLAyZ1MRInzPMYp8AAAsTw"]
[Thu Jul 30 12:55:09.245443 2026] [security2:error] [pid 806041:tid 806217] [client 172.202.44.182:43917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/alfanew.php"] [unique_id "amuP_ULAyZ1MRInzPMYqJwAAALM"]
[Thu Jul 30 12:55:09.332837 2026] [security2:error] [pid 806041:tid 806195] [client 20.100.187.246:27343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuP_ULAyZ1MRInzPMYqKwAAAJ0"]
[Thu Jul 30 12:55:09.394087 2026] [security2:error] [pid 806041:tid 806269] [client 150.107.232.194:26729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP_ULAyZ1MRInzPMYqLQAAAOc"]
[Thu Jul 30 12:55:09.394208 2026] [security2:error] [pid 806041:tid 806269] [client 150.107.232.194:26729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuP_ULAyZ1MRInzPMYqLQAAAOc"]
[Thu Jul 30 12:55:09.511260 2026] [security2:error] [pid 806041:tid 806234] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuP_ELAyZ1MRInzPMYqHwAAAMQ"]
[Thu Jul 30 12:55:09.851899 2026] [security2:error] [pid 806041:tid 806231] [client 74.7.241.182:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ylw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuP_ULAyZ1MRInzPMYqNAAAAME"], referer: https://www.ylw.gpl.temporary.site/robots.txt
[Thu Jul 30 12:55:09.852711 2026] [security2:error] [pid 806041:tid 806232] [client 74.7.241.182:38678] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ylw.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuP_ULAyZ1MRInzPMYqMgAAwlQ"], referer: https://www.ylw.gpl.temporary.site/robots.txt
[Thu Jul 30 12:55:10.245390 2026] [security2:error] [pid 806041:tid 806238] [client 172.202.44.182:27413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/fw.php"] [unique_id "amuP_kLAyZ1MRInzPMYqPwAAAMg"]
[Thu Jul 30 12:55:10.350009 2026] [security2:error] [pid 806041:tid 806223] [client 20.100.187.246:27589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuP_kLAyZ1MRInzPMYqRgAAALk"]
[Thu Jul 30 12:55:11.541538 2026] [security2:error] [pid 806041:tid 806172] [client 172.202.44.182:27104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wp-login.php"] [unique_id "amuP_0LAyZ1MRInzPMYqYQAAAIY"]
[Thu Jul 30 12:55:11.551807 2026] [security2:error] [pid 806041:tid 806263] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuP_kLAyZ1MRInzPMYqXQAAAOE"]
[Thu Jul 30 12:55:11.616340 2026] [security2:error] [pid 806041:tid 806181] [client 20.100.187.246:24647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuP_0LAyZ1MRInzPMYqcAAAAI8"]
[Thu Jul 30 12:55:12.744219 2026] [security2:error] [pid 806041:tid 806220] [client 172.202.44.182:27079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/simple.php"] [unique_id "amuQAELAyZ1MRInzPMYqhwAAALY"]
[Thu Jul 30 12:55:12.838874 2026] [fcgid:warn] [pid 806041:tid 806285] (70014)End of file found: [client 123.58.209.112:39588] mod_fcgid: can't get data from http client
[Thu Jul 30 12:55:12.868146 2026] [core:notice] [pid 806041:tid 806276] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:12.874290 2026] [security2:error] [pid 806041:tid 806276] [client 103.215.74.26:46240] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQAELAyZ1MRInzPMYqjgAAAO4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:14.359014 2026] [security2:error] [pid 806041:tid 806290] [client 172.202.44.182:43907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/classsmtps.php"] [unique_id "amuQAkLAyZ1MRInzPMYqrQAAAPw"]
[Thu Jul 30 12:55:14.787635 2026] [core:error] [pid 806041:tid 806258] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:14.787664 2026] [core:error] [pid 806041:tid 806258] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:14.851866 2026] [core:error] [pid 806041:tid 806287] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:14.851887 2026] [core:error] [pid 806041:tid 806287] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:15.117667 2026] [http2:info] [pid 822943:tid 822943] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 12:55:15.145254 2026] [core:error] [pid 822943:tid 823078] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:15.145373 2026] [core:error] [pid 822943:tid 823078] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:15.208971 2026] [security2:error] [pid 822943:tid 823081] [client 146.103.115.7:49714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.103.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/my-account/"] [unique_id "amuQA48CCDUa19YrTu4HYgAAARI"], referer: http://smoke-tfhk.com/
[Thu Jul 30 12:55:15.395588 2026] [security2:error] [pid 822943:tid 822944] [remote 47.128.27.72:29736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moncler-jacket-39/"] [unique_id "amuQA48CCDUa19YrTu4HZgABGwA"]
[Thu Jul 30 12:55:15.997438 2026] [security2:error] [pid 822943:tid 823089] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQA48CCDUa19YrTu4HZQAAARo"]
[Thu Jul 30 12:55:16.068742 2026] [security2:error] [pid 822943:tid 822952] [remote 52.167.144.139:59365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/issue/current"] [unique_id "amuQBI8CCDUa19YrTu4HiAABWgg"]
[Thu Jul 30 12:55:16.126600 2026] [security2:error] [pid 822943:tid 823148] [client 123.58.209.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "website-6113a6a7.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuQBI8CCDUa19YrTu4HhgAAAVU"]
[Thu Jul 30 12:55:16.716011 2026] [security2:error] [pid 822943:tid 823155] [client 66.249.79.137:57932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuQBI8CCDUa19YrTu4HigAAAVw"]
[Thu Jul 30 12:55:16.824801 2026] [security2:error] [pid 822943:tid 823075] [client 172.202.44.182:43930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wp-blog-header.php"] [unique_id "amuQBI8CCDUa19YrTu4HmgAAAQw"]
[Thu Jul 30 12:55:18.176780 2026] [security2:error] [pid 822943:tid 823090] [client 66.249.68.65:48001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQBY8CCDUa19YrTu4HsQAAARs"]
[Thu Jul 30 12:55:18.712362 2026] [core:notice] [pid 822943:tid 823134] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:18.722764 2026] [security2:error] [pid 822943:tid 823134] [client 103.215.74.26:64128] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQBo8CCDUa19YrTu4HywAAAUc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:18.963818 2026] [core:notice] [pid 822943:tid 823156] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:19.072219 2026] [security2:error] [pid 822943:tid 822973] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQB48CCDUa19YrTu4H0wABYh0"]
[Thu Jul 30 12:55:19.072521 2026] [security2:error] [pid 822943:tid 823161] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQB48CCDUa19YrTu4H0wABYh0"]
[Thu Jul 30 12:55:19.228924 2026] [security2:error] [pid 822943:tid 823081] [client 65.18.189.146:56210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuQBY8CCDUa19YrTu4HpQAAARI"]
[Thu Jul 30 12:55:19.355523 2026] [security2:error] [pid 822943:tid 823146] [client 172.202.44.182:27405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wp-trackback.php"] [unique_id "amuQB48CCDUa19YrTu4H2wAAAVM"]
[Thu Jul 30 12:55:19.450652 2026] [core:notice] [pid 822943:tid 823176] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:19.458590 2026] [security2:error] [pid 822943:tid 823176] [client 103.215.74.26:64130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQB48CCDUa19YrTu4H3AAAAXE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:19.872651 2026] [security2:error] [pid 822943:tid 823198] [client 150.107.232.194:27108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQB48CCDUa19YrTu4H6QAAAYc"]
[Thu Jul 30 12:55:19.872800 2026] [security2:error] [pid 822943:tid 823198] [client 150.107.232.194:27108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQB48CCDUa19YrTu4H6QAAAYc"]
[Thu Jul 30 12:55:20.194357 2026] [core:notice] [pid 822943:tid 823166] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:20.206113 2026] [security2:error] [pid 822943:tid 823166] [client 103.215.74.26:64138] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQCI8CCDUa19YrTu4H9gAAAWc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:20.929016 2026] [core:notice] [pid 822943:tid 823138] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:20.936624 2026] [security2:error] [pid 822943:tid 823138] [client 103.215.74.26:64146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQCI8CCDUa19YrTu4IBwAAAUs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:21.112602 2026] [security2:error] [pid 822943:tid 823122] [client 172.202.44.182:27410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wp-signup.php"] [unique_id "amuQCY8CCDUa19YrTu4IDgAAATs"]
[Thu Jul 30 12:55:21.700396 2026] [core:notice] [pid 822943:tid 823182] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:21.707102 2026] [security2:error] [pid 822943:tid 823182] [client 103.215.74.26:64156] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQCY8CCDUa19YrTu4IHwAAAXc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:22.006860 2026] [security2:error] [pid 822943:tid 823078] [client 65.18.189.146:49039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "amuQCo8CCDUa19YrTu4IJgAAAQ8"]
[Thu Jul 30 12:55:22.171010 2026] [security2:error] [pid 822943:tid 823181] [client 172.202.44.182:27423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wp-comments-post.php"] [unique_id "amuQCo8CCDUa19YrTu4IKAAAAXY"]
[Thu Jul 30 12:55:22.432963 2026] [core:notice] [pid 822943:tid 823086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:22.440638 2026] [security2:error] [pid 822943:tid 823086] [client 103.215.74.26:64158] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQCo8CCDUa19YrTu4IMgAAARc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:22.822237 2026] [security2:error] [pid 822943:tid 823092] [client 65.18.189.146:49040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuQCo8CCDUa19YrTu4INgAAAR0"], referer: https://kayomanis.com/wp-login.php
[Thu Jul 30 12:55:23.130084 2026] [security2:error] [pid 822943:tid 823180] [client 146.103.115.7:50876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuQCY8CCDUa19YrTu4IGwAAAXU"], referer: http://smoke-tfhk.com/xmlrpc.php
[Thu Jul 30 12:55:23.202447 2026] [core:notice] [pid 822943:tid 823143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:23.210430 2026] [security2:error] [pid 822943:tid 823143] [client 103.215.74.26:9870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQC48CCDUa19YrTu4IQAAAAVA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:23.379855 2026] [security2:error] [pid 822943:tid 823003] [remote 74.7.241.59:33212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuQC48CCDUa19YrTu4ISQABVzs"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/classes
[Thu Jul 30 12:55:23.554372 2026] [core:notice] [pid 822943:tid 823005] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:23.618729 2026] [core:notice] [pid 822943:tid 823174] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:23.754038 2026] [security2:error] [pid 822943:tid 823168] [client 20.100.187.246:25707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuQC48CCDUa19YrTu4IVAAAAWk"]
[Thu Jul 30 12:55:23.784240 2026] [security2:error] [pid 822943:tid 823090] [client 172.202.44.182:27080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wp-mail.php"] [unique_id "amuQC48CCDUa19YrTu4IVgAAARs"]
[Thu Jul 30 12:55:23.900891 2026] [security2:error] [pid 822943:tid 823112] [client 65.18.189.146:49041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuQC48CCDUa19YrTu4IVQAAATE"], referer: https://kayomanis.com/wp-login.php
[Thu Jul 30 12:55:23.939869 2026] [core:notice] [pid 822943:tid 823158] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:23.946967 2026] [security2:error] [pid 822943:tid 823158] [client 103.215.74.26:9882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQC48CCDUa19YrTu4IXQAAAV8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:23.988334 2026] [core:notice] [pid 822943:tid 823009] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:23.993948 2026] [security2:error] [pid 822943:tid 823170] [client 135.119.63.61:50947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/011i.php"] [unique_id "amuQC48CCDUa19YrTu4IXwAAAWs"]
[Thu Jul 30 12:55:24.507907 2026] [core:notice] [pid 822943:tid 823073] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:24.518950 2026] [security2:error] [pid 822943:tid 823080] [client 20.100.187.246:10706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuQDI8CCDUa19YrTu4IawAAARE"]
[Thu Jul 30 12:55:24.702114 2026] [core:notice] [pid 822943:tid 823109] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:24.711237 2026] [security2:error] [pid 822943:tid 823109] [client 103.215.74.26:9892] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQDI8CCDUa19YrTu4IbAAAAS4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:24.902729 2026] [security2:error] [pid 822943:tid 823086] [client 65.18.189.146:49042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuQDI8CCDUa19YrTu4IcAAAARc"], referer: https://kayomanis.com/wp-login.php
[Thu Jul 30 12:55:24.965624 2026] [core:notice] [pid 822943:tid 823021] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:25.120483 2026] [security2:error] [pid 822943:tid 823147] [client 146.103.115.7:51326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuQC48CCDUa19YrTu4ISgAAAVQ"], referer: http://smoke-tfhk.com/xmlrpc.php
[Thu Jul 30 12:55:25.155874 2026] [core:notice] [pid 822943:tid 823087] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:25.352204 2026] [security2:error] [pid 822943:tid 823145] [client 20.100.187.246:10751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuQDY8CCDUa19YrTu4IiAAAAVI"]
[Thu Jul 30 12:55:25.430350 2026] [core:notice] [pid 822943:tid 823160] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:25.437138 2026] [security2:error] [pid 822943:tid 823160] [client 103.215.74.26:9908] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQDY8CCDUa19YrTu4IkgAAAWE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:25.904692 2026] [security2:error] [pid 822943:tid 823137] [client 135.119.63.61:22616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/03a005685d.php"] [unique_id "amuQDY8CCDUa19YrTu4InwAAAUo"]
[Thu Jul 30 12:55:26.166714 2026] [core:notice] [pid 822943:tid 823077] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:26.174215 2026] [security2:error] [pid 822943:tid 823077] [client 103.215.74.26:9924] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQDo8CCDUa19YrTu4IoQAAAQ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:26.592818 2026] [security2:error] [pid 822943:tid 823104] [client 65.18.189.146:49044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuQDo8CCDUa19YrTu4IrgAAASk"], referer: https://kayomanis.com/wp-login.php
[Thu Jul 30 12:55:26.670929 2026] [security2:error] [pid 822943:tid 823178] [client 20.100.187.246:26470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuQDo8CCDUa19YrTu4IqgAAAXM"]
[Thu Jul 30 12:55:26.840263 2026] [security2:error] [pid 822943:tid 823042] [remote 40.77.167.132:21138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/our-services/solvent-based-coatings/indexf.php"] [unique_id "amuQDo8CCDUa19YrTu4ItQABTWI"]
[Thu Jul 30 12:55:26.913423 2026] [core:notice] [pid 822943:tid 823128] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:26.923659 2026] [security2:error] [pid 822943:tid 823128] [client 103.215.74.26:9926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQDo8CCDUa19YrTu4IugAAAUE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:26.944542 2026] [security2:error] [pid 822943:tid 823089] [client 135.119.63.61:40723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/403.php"] [unique_id "amuQDo8CCDUa19YrTu4IuwAAARo"]
[Thu Jul 30 12:55:27.529055 2026] [security2:error] [pid 822943:tid 823156] [client 65.18.189.146:49045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amuQD48CCDUa19YrTu4IxAAAAV0"], referer: https://kayomanis.com/wp-login.php
[Thu Jul 30 12:55:27.644792 2026] [core:notice] [pid 822943:tid 823175] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:27.651413 2026] [security2:error] [pid 822943:tid 823175] [client 103.215.74.26:9938] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQD48CCDUa19YrTu4IzAAAAXA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:27.879223 2026] [core:notice] [pid 822943:tid 823188] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:27.983112 2026] [security2:error] [pid 822943:tid 823190] [client 135.119.63.61:22617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/404.php"] [unique_id "amuQD48CCDUa19YrTu4I1QAAAX8"]
[Thu Jul 30 12:55:28.368132 2026] [core:notice] [pid 822943:tid 823099] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:28.375739 2026] [security2:error] [pid 822943:tid 823099] [client 103.215.74.26:9940] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQEI8CCDUa19YrTu4I3gAAASQ"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:28.558127 2026] [security2:error] [pid 822943:tid 823135] [client 146.103.115.7:51836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "smoke-tfhk.com"] [uri "/wp-admin/post-new.php"] [unique_id "amuQDo8CCDUa19YrTu4IsgAAAUg"], referer: http://smoke-tfhk.com/my-account/?action=register&xoo_el_reg_email=gb_roxanneculbert9581%40falderewonek.site&xoo_el_reg_fname=Ada&xoo_el_reg_lname=Goodson&xoo_el_reg_pass=rRyQ1bxn2mm0uk-&xoo_el_reg_pass_again=rRyQ1bxn2mm0uk-&xoo_el_reg_terms=yes&_xoo_el_form=register&xoo_el_redirect=%2Fmy-account%2F%3Faction%3Dregister
[Thu Jul 30 12:55:28.630531 2026] [security2:error] [pid 822943:tid 823059] [remote 57.141.18.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQEI8CCDUa19YrTu4I6gABDnM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,denim,linen,nylon,polyester&tax_product_cat=suit&min_price=125&max_price=200&unfilter=1
[Thu Jul 30 12:55:28.813024 2026] [core:error] [pid 822943:tid 823097] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.813051 2026] [core:error] [pid 822943:tid 823097] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.836160 2026] [security2:error] [pid 822943:tid 823125] [client 123.58.209.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "website-6113a6a7.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuQEI8CCDUa19YrTu4I7gAAAT4"]
[Thu Jul 30 12:55:28.849549 2026] [core:error] [pid 822943:tid 823172] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.849577 2026] [core:error] [pid 822943:tid 823172] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.853713 2026] [core:error] [pid 822943:tid 823129] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.853735 2026] [core:error] [pid 822943:tid 823129] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.854085 2026] [core:error] [pid 822943:tid 823161] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.854102 2026] [core:error] [pid 822943:tid 823161] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.858614 2026] [core:error] [pid 822943:tid 823091] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.858629 2026] [core:error] [pid 822943:tid 823091] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:55:28.887227 2026] [security2:error] [pid 822943:tid 823191] [client 135.119.63.61:40734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/aa.php"] [unique_id "amuQEI8CCDUa19YrTu4JBgAAAYA"]
[Thu Jul 30 12:55:28.909653 2026] [security2:error] [pid 822943:tid 823084] [client 172.202.44.182:60711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wp-activate.php"] [unique_id "amuQEI8CCDUa19YrTu4JBwAAARU"]
[Thu Jul 30 12:55:28.968159 2026] [security2:error] [pid 822943:tid 823060] [remote 57.141.18.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQEI8CCDUa19YrTu4I7QABTXQ"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,denim,linen,nylon,polyester&tax_product_cat=suit&min_price=125&max_price=200&unfilter=1
[Thu Jul 30 12:55:29.102438 2026] [core:notice] [pid 822943:tid 823138] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:29.109449 2026] [security2:error] [pid 822943:tid 823138] [client 103.215.74.26:9956] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQEY8CCDUa19YrTu4JEQAAAUs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:29.849267 2026] [core:notice] [pid 822943:tid 823113] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:29.856826 2026] [security2:error] [pid 822943:tid 823113] [client 103.215.74.26:9958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQEY8CCDUa19YrTu4JIAAAATI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:29.874759 2026] [core:notice] [pid 822943:tid 823117] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:29.923681 2026] [security2:error] [pid 822943:tid 823068] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQEY8CCDUa19YrTu4JIgABH3w"]
[Thu Jul 30 12:55:29.923855 2026] [security2:error] [pid 822943:tid 823094] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQEY8CCDUa19YrTu4JIgABH3w"]
[Thu Jul 30 12:55:30.154700 2026] [security2:error] [pid 822943:tid 823130] [client 135.119.63.61:22598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/aafewc0k.php"] [unique_id "amuQEo8CCDUa19YrTu4JLQAAAUM"]
[Thu Jul 30 12:55:30.155295 2026] [security2:error] [pid 822943:tid 823120] [client 172.202.44.182:19133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/post.php"] [unique_id "amuQEo8CCDUa19YrTu4JLgAAATk"]
[Thu Jul 30 12:55:30.334394 2026] [security2:error] [pid 822943:tid 823104] [client 150.107.232.194:26553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQEo8CCDUa19YrTu4JMAAAASk"]
[Thu Jul 30 12:55:30.334499 2026] [security2:error] [pid 822943:tid 823104] [client 150.107.232.194:26553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQEo8CCDUa19YrTu4JMAAAASk"]
[Thu Jul 30 12:55:30.409073 2026] [security2:error] [pid 822943:tid 822945] [remote 216.73.216.152:8250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQEo8CCDUa19YrTu4JMgABWgE"]
[Thu Jul 30 12:55:30.590487 2026] [core:notice] [pid 822943:tid 823087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:30.597848 2026] [security2:error] [pid 822943:tid 823087] [client 103.215.74.26:9964] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQEo8CCDUa19YrTu4JQwAAARg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:31.071565 2026] [security2:error] [pid 822943:tid 823188] [client 167.235.143.113:4766] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuQE48CCDUa19YrTu4JTwAAAX0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:55:31.217001 2026] [security2:error] [pid 822943:tid 823189] [client 172.202.44.182:50310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/wp-2019.php"] [unique_id "amuQE48CCDUa19YrTu4JWAAAAX4"]
[Thu Jul 30 12:55:31.329222 2026] [core:notice] [pid 822943:tid 823138] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:31.336738 2026] [security2:error] [pid 822943:tid 823138] [client 103.215.74.26:9974] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQE48CCDUa19YrTu4JWQAAAUs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:31.468471 2026] [core:notice] [pid 822943:tid 823099] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:31.473698 2026] [security2:error] [pid 822943:tid 823099] [client 167.235.143.113:4776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQE48CCDUa19YrTu4JWwAAASQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:55:31.938534 2026] [security2:error] [pid 822943:tid 823143] [client 167.235.143.113:4788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuQE48CCDUa19YrTu4JaQAAAVA"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 12:55:32.069589 2026] [core:notice] [pid 822943:tid 823118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:32.077071 2026] [security2:error] [pid 822943:tid 823118] [client 103.215.74.26:9984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQFI8CCDUa19YrTu4JbQAAATc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:32.393492 2026] [security2:error] [pid 822943:tid 823132] [client 135.119.63.61:50354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/abcd.php"] [unique_id "amuQFI8CCDUa19YrTu4JdwAAAUU"]
[Thu Jul 30 12:55:32.839543 2026] [core:notice] [pid 822943:tid 823084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:32.847055 2026] [security2:error] [pid 822943:tid 823084] [client 103.215.74.26:9996] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQFI8CCDUa19YrTu4JhQAAARU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:33.030196 2026] [security2:error] [pid 822943:tid 823079] [client 85.204.70.98:48426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tdu.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuQFY8CCDUa19YrTu4JhgAAARA"]
[Thu Jul 30 12:55:33.344808 2026] [security2:error] [pid 822943:tid 823189] [client 85.204.70.98:37068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tdu.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuQFY8CCDUa19YrTu4JkgAAAX4"]
[Thu Jul 30 12:55:33.582045 2026] [core:notice] [pid 822943:tid 823137] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:33.587065 2026] [security2:error] [pid 822943:tid 823085] [client 172.202.44.182:26821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/hoot.php"] [unique_id "amuQFY8CCDUa19YrTu4JmgAAARY"]
[Thu Jul 30 12:55:33.588660 2026] [security2:error] [pid 822943:tid 823137] [client 103.215.74.26:60732] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQFY8CCDUa19YrTu4JmQAAAUo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:34.324746 2026] [core:notice] [pid 822943:tid 823129] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:34.331638 2026] [security2:error] [pid 822943:tid 823129] [client 103.215.74.26:60738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQFo8CCDUa19YrTu4JtAAAAUI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:34.367211 2026] [core:notice] [pid 822943:tid 823139] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:34.667128 2026] [security2:error] [pid 822943:tid 823173] [client 135.119.63.61:50319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/about.php"] [unique_id "amuQFo8CCDUa19YrTu4JugAAAW4"]
[Thu Jul 30 12:55:34.703005 2026] [security2:error] [pid 822943:tid 823150] [client 43.172.195.167:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/07/04/sacs-a-main-soldes-ete-2016/"] [unique_id "amuQFo8CCDUa19YrTu4JvAAAAVc"]
[Thu Jul 30 12:55:34.932812 2026] [security2:error] [pid 822943:tid 823175] [client 43.173.173.235:54036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/03/04/etam-lingerie-printemps-ete-2016/"] [unique_id "amuQFo8CCDUa19YrTu4JuwAAAXA"]
[Thu Jul 30 12:55:35.168693 2026] [security2:error] [pid 822943:tid 823167] [client 172.202.44.182:27378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/log.php"] [unique_id "amuQF48CCDUa19YrTu4JyQAAAWg"]
[Thu Jul 30 12:55:35.288761 2026] [core:notice] [pid 822943:tid 823105] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:35.293610 2026] [security2:error] [pid 822943:tid 823105] [client 43.173.182.208:46548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/07/04/sacs-a-main-soldes-ete-2016/"] [unique_id "amuQF48CCDUa19YrTu4JzgAAASo"], referer: https://carnetdeshopping.com/index.php/2016/07/04/sacs-a-main-soldes-ete-2016/
[Thu Jul 30 12:55:35.304536 2026] [security2:error] [pid 822943:tid 823186] [client 85.204.70.98:35860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tdu.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuQF48CCDUa19YrTu4JyAAAAXs"]
[Thu Jul 30 12:55:35.356876 2026] [core:notice] [pid 822943:tid 823108] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:35.361656 2026] [security2:error] [pid 822943:tid 823108] [client 43.173.182.240:59300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/03/04/etam-lingerie-printemps-ete-2016/"] [unique_id "amuQF48CCDUa19YrTu4J0gAAAS0"], referer: https://carnetdeshopping.com/index.php/2016/03/04/etam-lingerie-printemps-ete-2016/
[Thu Jul 30 12:55:35.427626 2026] [security2:error] [pid 822943:tid 823101] [client 85.204.70.98:35860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tdu.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuQF48CCDUa19YrTu4J2QAAASY"]
[Thu Jul 30 12:55:35.427728 2026] [security2:error] [pid 822943:tid 823101] [client 85.204.70.98:35860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tdu.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuQF48CCDUa19YrTu4J2QAAASY"]
[Thu Jul 30 12:55:35.966854 2026] [security2:error] [pid 822943:tid 823111] [client 135.119.63.61:50310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/admin.php"] [unique_id "amuQF48CCDUa19YrTu4J5QAAATA"]
[Thu Jul 30 12:55:36.408003 2026] [security2:error] [pid 822943:tid 823088] [client 172.202.44.182:50598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/bak.php"] [unique_id "amuQGI8CCDUa19YrTu4J-wAAARk"]
[Thu Jul 30 12:55:36.502842 2026] [security2:error] [pid 822943:tid 823163] [client 74.7.175.161:52970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.megasuppliesdistrict.com"] [uri "/index.php"] [unique_id "amuQFY8CCDUa19YrTu4JkAABZCc"]
[Thu Jul 30 12:55:36.894562 2026] [security2:error] [pid 822943:tid 823197] [client 135.119.63.61:22597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/adminfuns.php"] [unique_id "amuQGI8CCDUa19YrTu4KBAAAAYY"]
[Thu Jul 30 12:55:37.343028 2026] [autoindex:error] [pid 822943:tid 823085] [client 103.226.142.125:52259] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:55:37.565038 2026] [autoindex:error] [pid 822943:tid 823133] [client 103.226.142.125:52263] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:55:37.920812 2026] [security2:error] [pid 822943:tid 823147] [client 172.202.44.182:50591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/content.php"] [unique_id "amuQGY8CCDUa19YrTu4KJgAAAVQ"]
[Thu Jul 30 12:55:38.717696 2026] [security2:error] [pid 822943:tid 823127] [client 135.119.63.61:40721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/albin.php"] [unique_id "amuQGo8CCDUa19YrTu4KNgAAAUA"]
[Thu Jul 30 12:55:39.010412 2026] [security2:error] [pid 822943:tid 823152] [client 172.202.44.182:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/upfile.php"] [unique_id "amuQG48CCDUa19YrTu4KPwAAAVk"]
[Thu Jul 30 12:55:39.401193 2026] [security2:error] [pid 822943:tid 823050] [remote 72.167.132.114:52176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuQG48CCDUa19YrTu4KSgABWmo"]
[Thu Jul 30 12:55:39.401347 2026] [security2:error] [pid 822943:tid 823153] [client 72.167.132.114:52176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuQG48CCDUa19YrTu4KSgABWmo"]
[Thu Jul 30 12:55:39.787055 2026] [security2:error] [pid 822943:tid 823166] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQG48CCDUa19YrTu4KSAAAAWc"]
[Thu Jul 30 12:55:39.795008 2026] [security2:error] [pid 822943:tid 823116] [client 135.119.63.61:40731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/amfsqvgv.php"] [unique_id "amuQG48CCDUa19YrTu4KWAAAATU"]
[Thu Jul 30 12:55:40.039010 2026] [security2:error] [pid 822943:tid 823057] [remote 57.141.18.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQHI8CCDUa19YrTu4KXAABFHE"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=carbon,linen,polyester,cotton,denim,aluminum,steel,silicon&filter_size=large,extra-large&orderby=rating&rating=5&status=instock&unfilter=1
[Thu Jul 30 12:55:40.059201 2026] [core:notice] [pid 822943:tid 823130] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:40.066524 2026] [security2:error] [pid 822943:tid 823130] [client 103.215.74.26:60750] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQHI8CCDUa19YrTu4KXgAAAUM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:40.340583 2026] [security2:error] [pid 822943:tid 823059] [remote 57.141.18.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQHI8CCDUa19YrTu4KYQABDXM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=carbon,linen,polyester,cotton,denim,aluminum,steel,silicon&filter_size=large,extra-large&orderby=rating&rating=5&status=instock&unfilter=1
[Thu Jul 30 12:55:40.342686 2026] [security2:error] [pid 822943:tid 823192] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQG48CCDUa19YrTu4KVwAAAYE"]
[Thu Jul 30 12:55:40.475880 2026] [security2:error] [pid 822943:tid 823162] [client 172.202.44.182:53895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/bypass.php"] [unique_id "amuQHI8CCDUa19YrTu4KaAAAAWM"]
[Thu Jul 30 12:55:40.668567 2026] [security2:error] [pid 822943:tid 823154] [client 135.119.63.61:40719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/ant.php"] [unique_id "amuQHI8CCDUa19YrTu4KcwAAAVs"]
[Thu Jul 30 12:55:40.744126 2026] [security2:error] [pid 822943:tid 823065] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQHI8CCDUa19YrTu4KdAABXHk"]
[Thu Jul 30 12:55:40.744282 2026] [security2:error] [pid 822943:tid 823155] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQHI8CCDUa19YrTu4KdAABXHk"]
[Thu Jul 30 12:55:40.794901 2026] [security2:error] [pid 822943:tid 823152] [client 150.107.232.194:27281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQHI8CCDUa19YrTu4KdQAAAVk"]
[Thu Jul 30 12:55:40.795021 2026] [security2:error] [pid 822943:tid 823152] [client 150.107.232.194:27281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQHI8CCDUa19YrTu4KdQAAAVk"]
[Thu Jul 30 12:55:40.802058 2026] [core:notice] [pid 822943:tid 823150] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:40.808624 2026] [security2:error] [pid 822943:tid 823150] [client 103.215.74.26:60760] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQHI8CCDUa19YrTu4KdgAAAVc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:41.345816 2026] [security2:error] [pid 822943:tid 823090] [client 172.202.44.182:14172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/updates.php"] [unique_id "amuQHY8CCDUa19YrTu4KgwAAARs"]
[Thu Jul 30 12:55:41.395145 2026] [security2:error] [pid 822943:tid 823195] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQHI8CCDUa19YrTu4KeQAAAYQ"]
[Thu Jul 30 12:55:41.539793 2026] [core:notice] [pid 822943:tid 823080] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:41.546539 2026] [security2:error] [pid 822943:tid 823080] [client 103.215.74.26:60762] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQHY8CCDUa19YrTu4KhAAAARE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:42.273584 2026] [security2:error] [pid 822943:tid 822952] [remote 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topmoversandpackerssharjah.art"] [uri "/wp-login.php"] [unique_id "amuQHo8CCDUa19YrTu4KnAABDAg"]
[Thu Jul 30 12:55:42.314707 2026] [core:notice] [pid 822943:tid 823149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:42.321203 2026] [security2:error] [pid 822943:tid 823149] [client 103.215.74.26:60776] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQHo8CCDUa19YrTu4KnQAAAVY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:42.366352 2026] [security2:error] [pid 822943:tid 823110] [client 172.202.44.182:50572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/xmrlpc.php"] [unique_id "amuQHo8CCDUa19YrTu4KngAAAS8"]
[Thu Jul 30 12:55:42.878347 2026] [security2:error] [pid 822943:tid 823128] [client 135.119.63.61:50341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/appreciators.php"] [unique_id "amuQHo8CCDUa19YrTu4KqAAAAUE"]
[Thu Jul 30 12:55:43.055169 2026] [core:notice] [pid 822943:tid 823084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:43.062562 2026] [security2:error] [pid 822943:tid 823084] [client 103.215.74.26:63874] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQH48CCDUa19YrTu4KrAAAARU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:43.781730 2026] [core:notice] [pid 822943:tid 823143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:43.788891 2026] [security2:error] [pid 822943:tid 823143] [client 103.215.74.26:63888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQH48CCDUa19YrTu4KwwAAAVA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:43.867501 2026] [security2:error] [pid 822943:tid 823136] [client 135.119.63.61:50365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/archive.php"] [unique_id "amuQH48CCDUa19YrTu4KxAAAAUk"]
[Thu Jul 30 12:55:43.892632 2026] [security2:error] [pid 822943:tid 823074] [client 172.202.44.182:14173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/ae.php"] [unique_id "amuQH48CCDUa19YrTu4KxQAAAQs"]
[Thu Jul 30 12:55:44.532792 2026] [core:notice] [pid 822943:tid 823146] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:44.539434 2026] [security2:error] [pid 822943:tid 823146] [client 103.215.74.26:63890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQII8CCDUa19YrTu4K0wAAAVM"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:44.681100 2026] [security2:error] [pid 822943:tid 823149] [client 172.202.44.182:14201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/moon.php"] [unique_id "amuQII8CCDUa19YrTu4K2gAAAVY"]
[Thu Jul 30 12:55:45.247368 2026] [security2:error] [pid 822943:tid 823079] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQII8CCDUa19YrTu4K2QAAARA"]
[Thu Jul 30 12:55:45.297264 2026] [core:notice] [pid 822943:tid 823200] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:45.303874 2026] [security2:error] [pid 822943:tid 823200] [client 103.215.74.26:63902] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQIY8CCDUa19YrTu4K7wAAAYk"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:45.550402 2026] [core:notice] [pid 822943:tid 823109] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:45.690727 2026] [security2:error] [pid 822943:tid 823114] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQIY8CCDUa19YrTu4K5AAAATM"]
[Thu Jul 30 12:55:45.698845 2026] [security2:error] [pid 822943:tid 823125] [client 172.202.44.182:14205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/blog.php"] [unique_id "amuQIY8CCDUa19YrTu4K9QAAAT4"]
[Thu Jul 30 12:55:46.055187 2026] [core:notice] [pid 822943:tid 823166] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:46.754766 2026] [security2:error] [pid 822943:tid 823148] [client 172.202.44.182:14270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/ini.php"] [unique_id "amuQIo8CCDUa19YrTu4LCwAAAVU"]
[Thu Jul 30 12:55:47.690026 2026] [security2:error] [pid 822943:tid 823126] [client 135.119.63.61:40732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/as.php"] [unique_id "amuQI48CCDUa19YrTu4LHgAAAT8"]
[Thu Jul 30 12:55:47.969195 2026] [security2:error] [pid 822943:tid 822999] [remote 57.141.0.21:56818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuQI48CCDUa19YrTu4LKQABdjc"]
[Thu Jul 30 12:55:48.298552 2026] [security2:error] [pid 822943:tid 823002] [remote 57.141.0.40:44042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuQJI8CCDUa19YrTu4LLgABDDo"]
[Thu Jul 30 12:55:48.468713 2026] [security2:error] [pid 822943:tid 823165] [client 172.202.44.182:14178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/admin-ajax.php"] [unique_id "amuQJI8CCDUa19YrTu4LMwAAAWY"]
[Thu Jul 30 12:55:48.774181 2026] [security2:error] [pid 822943:tid 823164] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQJI8CCDUa19YrTu4LKgABZTg"]
[Thu Jul 30 12:55:48.777817 2026] [security2:error] [pid 822943:tid 823169] [client 135.119.63.61:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/atomlib.php"] [unique_id "amuQJI8CCDUa19YrTu4LOQAAAWo"]
[Thu Jul 30 12:55:49.257074 2026] [security2:error] [pid 822943:tid 823096] [client 172.202.44.182:14163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/akc.php"] [unique_id "amuQJY8CCDUa19YrTu4LSAAAASE"]
[Thu Jul 30 12:55:50.258156 2026] [security2:error] [pid 822943:tid 823149] [client 172.202.44.182:44462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/akcc.php"] [unique_id "amuQJo8CCDUa19YrTu4LXgAAAVY"]
[Thu Jul 30 12:55:50.552467 2026] [security2:error] [pid 822943:tid 823122] [client 135.119.63.61:22608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/autoload_classmap.php"] [unique_id "amuQJo8CCDUa19YrTu4LbAAAATs"]
[Thu Jul 30 12:55:51.020316 2026] [core:notice] [pid 822943:tid 823157] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:51.026404 2026] [security2:error] [pid 822943:tid 823157] [client 103.215.74.26:63910] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQJ48CCDUa19YrTu4LdQAAAV4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:51.090436 2026] [security2:error] [pid 822943:tid 823090] [client 172.202.44.182:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/asasx.php"] [unique_id "amuQJ48CCDUa19YrTu4LegAAARs"]
[Thu Jul 30 12:55:51.255386 2026] [security2:error] [pid 822943:tid 823119] [client 150.107.232.194:27032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQJ48CCDUa19YrTu4LfQAAATg"]
[Thu Jul 30 12:55:51.255551 2026] [security2:error] [pid 822943:tid 823119] [client 150.107.232.194:27032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQJ48CCDUa19YrTu4LfQAAATg"]
[Thu Jul 30 12:55:51.435620 2026] [security2:error] [pid 822943:tid 823037] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQJ48CCDUa19YrTu4LgQABOV0"]
[Thu Jul 30 12:55:51.435886 2026] [security2:error] [pid 822943:tid 823120] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQJ48CCDUa19YrTu4LgQABOV0"]
[Thu Jul 30 12:55:51.747631 2026] [core:notice] [pid 822943:tid 823144] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:51.754667 2026] [security2:error] [pid 822943:tid 823144] [client 103.215.74.26:63924] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQJ48CCDUa19YrTu4LiAAAAVE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:51.868178 2026] [security2:error] [pid 822943:tid 823147] [client 135.119.63.61:40718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/bb.php"] [unique_id "amuQJ48CCDUa19YrTu4LiQAAAVQ"]
[Thu Jul 30 12:55:52.040512 2026] [security2:error] [pid 822943:tid 823180] [client 172.202.44.182:14177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/axx.php"] [unique_id "amuQKI8CCDUa19YrTu4LkAAAAXU"]
[Thu Jul 30 12:55:52.350609 2026] [core:notice] [pid 822943:tid 823146] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:52.484408 2026] [core:notice] [pid 822943:tid 823199] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:52.490575 2026] [security2:error] [pid 822943:tid 823199] [client 103.215.74.26:63928] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQKI8CCDUa19YrTu4LnQAAAYg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:52.806526 2026] [core:notice] [pid 822943:tid 823084] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:52.835517 2026] [security2:error] [pid 822943:tid 823110] [client 135.119.63.61:22614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/bnm.php"] [unique_id "amuQKI8CCDUa19YrTu4LqAAAAS8"]
[Thu Jul 30 12:55:53.174247 2026] [security2:error] [pid 822943:tid 823048] [remote 57.141.18.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQKY8CCDUa19YrTu4LsgABW2g"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=aluminum,cotton,linen,lycra,plastic,polyester,silicon,steel,titanium&orderby=date&rating=5&status=sale&unfilter=1
[Thu Jul 30 12:55:53.225681 2026] [core:notice] [pid 822943:tid 823122] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:53.232191 2026] [security2:error] [pid 822943:tid 823122] [client 103.215.74.26:1330] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQKY8CCDUa19YrTu4LswAAATs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:53.355930 2026] [security2:error] [pid 822943:tid 823057] [remote 57.141.18.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQKY8CCDUa19YrTu4LtAABEXE"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=aluminum,cotton,linen,lycra,plastic,polyester,silicon,steel,titanium&orderby=date&rating=5&status=sale&unfilter=1
[Thu Jul 30 12:55:53.957596 2026] [core:notice] [pid 822943:tid 823171] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:53.965114 2026] [security2:error] [pid 822943:tid 823171] [client 103.215.74.26:1336] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQKY8CCDUa19YrTu4LwQAAAWw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:55:54.700318 2026] [security2:error] [pid 822943:tid 823186] [client 172.202.44.182:14227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/berax.php"] [unique_id "amuQKo8CCDUa19YrTu4L1gAAAXs"]
[Thu Jul 30 12:55:54.887506 2026] [security2:error] [pid 822943:tid 823076] [client 172.236.9.101:13590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQKo8CCDUa19YrTu4LywAAAQ0"]
[Thu Jul 30 12:55:54.929779 2026] [security2:error] [pid 822943:tid 823067] [remote 74.7.241.60:56254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/js/login.php"] [unique_id "amuQKo8CCDUa19YrTu4L3AABYHs"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 12:55:54.965766 2026] [security2:error] [pid 822943:tid 823173] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQKo8CCDUa19YrTu4LzgAAAW4"]
[Thu Jul 30 12:55:55.233459 2026] [security2:error] [pid 822943:tid 823162] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQKo8CCDUa19YrTu4L0gABY3g"]
[Thu Jul 30 12:55:57.032800 2026] [security2:error] [pid 822943:tid 823144] [client 172.202.44.182:28035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/build.php"] [unique_id "amuQLY8CCDUa19YrTu4MFwAAAVE"]
[Thu Jul 30 12:55:57.170912 2026] [security2:error] [pid 822943:tid 823082] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQLI8CCDUa19YrTu4MAwAAARM"]
[Thu Jul 30 12:55:57.585592 2026] [security2:error] [pid 822943:tid 823185] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQLI8CCDUa19YrTu4MEwAAAXo"]
[Thu Jul 30 12:55:58.251686 2026] [security2:error] [pid 822943:tid 823187] [client 172.202.44.182:14248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/buy.php"] [unique_id "amuQLo8CCDUa19YrTu4MbgAAAXw"]
[Thu Jul 30 12:55:58.712076 2026] [security2:error] [pid 822943:tid 823031] [remote 147.93.37.3:41094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.37.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dov.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amuQLo8CCDUa19YrTu4MdgABMFc"]
[Thu Jul 30 12:55:59.089253 2026] [security2:error] [pid 822943:tid 823036] [remote 57.141.0.3:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuQL48CCDUa19YrTu4MiAABZFw"]
[Thu Jul 30 12:55:59.274866 2026] [security2:error] [pid 822943:tid 823155] [client 135.119.63.61:50361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/bootstrap.php"] [unique_id "amuQL48CCDUa19YrTu4MigAAAVw"]
[Thu Jul 30 12:55:59.695862 2026] [core:notice] [pid 822943:tid 823198] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:55:59.703331 2026] [security2:error] [pid 822943:tid 823198] [client 103.215.74.26:1350] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQL48CCDUa19YrTu4MlwAAAYc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:00.448214 2026] [core:notice] [pid 822943:tid 823121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:00.454913 2026] [security2:error] [pid 822943:tid 823121] [client 103.215.74.26:1358] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQMI8CCDUa19YrTu4MqgAAATo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:00.622233 2026] [security2:error] [pid 822943:tid 823105] [client 172.202.44.182:44469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/checkbox.php"] [unique_id "amuQMI8CCDUa19YrTu4MrgAAASo"]
[Thu Jul 30 12:56:00.971591 2026] [security2:error] [pid 822943:tid 823080] [client 135.119.63.61:4195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/buy.php"] [unique_id "amuQMI8CCDUa19YrTu4MtgAAARE"]
[Thu Jul 30 12:56:01.179093 2026] [core:notice] [pid 822943:tid 823133] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:01.185667 2026] [security2:error] [pid 822943:tid 823133] [client 103.215.74.26:1374] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQMY8CCDUa19YrTu4MuwAAAUY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:01.593881 2026] [security2:error] [pid 822943:tid 823180] [client 172.202.44.182:14218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/cong.php"] [unique_id "amuQMY8CCDUa19YrTu4MxwAAAXU"]
[Thu Jul 30 12:56:01.728894 2026] [security2:error] [pid 822943:tid 823144] [client 150.107.232.194:27347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQMY8CCDUa19YrTu4MyAAAAVE"]
[Thu Jul 30 12:56:01.729043 2026] [security2:error] [pid 822943:tid 823144] [client 150.107.232.194:27347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQMY8CCDUa19YrTu4MyAAAAVE"]
[Thu Jul 30 12:56:01.924441 2026] [core:notice] [pid 822943:tid 823159] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:01.930948 2026] [security2:error] [pid 822943:tid 823159] [client 103.215.74.26:1376] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQMY8CCDUa19YrTu4MzwAAAWA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:02.279706 2026] [security2:error] [pid 822943:tid 823058] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQMo8CCDUa19YrTu4M1wABTnI"]
[Thu Jul 30 12:56:02.279876 2026] [security2:error] [pid 822943:tid 823141] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQMo8CCDUa19YrTu4M1wABTnI"]
[Thu Jul 30 12:56:02.543339 2026] [security2:error] [pid 822943:tid 823196] [client 135.119.63.61:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/chosen.php"] [unique_id "amuQMo8CCDUa19YrTu4M4AAAAYU"]
[Thu Jul 30 12:56:02.650140 2026] [core:notice] [pid 822943:tid 823090] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:02.656793 2026] [security2:error] [pid 822943:tid 823090] [client 103.215.74.26:1384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQMo8CCDUa19YrTu4M5AAAARs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:03.102508 2026] [security2:error] [pid 822943:tid 823195] [client 172.202.44.182:27298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/file4.php"] [unique_id "amuQM48CCDUa19YrTu4M7gAAAYQ"]
[Thu Jul 30 12:56:03.376128 2026] [core:notice] [pid 822943:tid 823081] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:03.382800 2026] [security2:error] [pid 822943:tid 823081] [client 103.215.74.26:23864] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQM48CCDUa19YrTu4M8gAAARI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:04.109471 2026] [core:notice] [pid 822943:tid 823111] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:04.116440 2026] [security2:error] [pid 822943:tid 823111] [client 103.215.74.26:23876] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQNI8CCDUa19YrTu4NBgAAATA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:04.849466 2026] [core:notice] [pid 822943:tid 823086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:04.855874 2026] [security2:error] [pid 822943:tid 823086] [client 103.215.74.26:23886] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQNI8CCDUa19YrTu4NFAAAARc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:05.428551 2026] [security2:error] [pid 822943:tid 822958] [remote 216.73.216.152:56907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQNY8CCDUa19YrTu4NHwABLg4"]
[Thu Jul 30 12:56:05.588122 2026] [core:notice] [pid 822943:tid 823101] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:05.594772 2026] [security2:error] [pid 822943:tid 823101] [client 103.215.74.26:23888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQNY8CCDUa19YrTu4NIAAAASY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:06.338861 2026] [core:notice] [pid 822943:tid 823171] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:06.344856 2026] [security2:error] [pid 822943:tid 823171] [client 103.215.74.26:23896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQNo8CCDUa19YrTu4NNgAAAWw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:06.345037 2026] [security2:error] [pid 822943:tid 823089] [client 172.202.44.182:27155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/flower.php"] [unique_id "amuQNo8CCDUa19YrTu4NNwAAARo"]
[Thu Jul 30 12:56:07.063065 2026] [core:notice] [pid 822943:tid 823091] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:07.069952 2026] [security2:error] [pid 822943:tid 823091] [client 103.215.74.26:23916] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQN48CCDUa19YrTu4NRwAAARw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:07.822709 2026] [core:notice] [pid 822943:tid 823138] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:07.829003 2026] [security2:error] [pid 822943:tid 823138] [client 103.215.74.26:23930] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQN48CCDUa19YrTu4NWAAAAUs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:08.068854 2026] [security2:error] [pid 822943:tid 823188] [client 172.202.44.182:28076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/form.php"] [unique_id "amuQOI8CCDUa19YrTu4NXQAAAX0"]
[Thu Jul 30 12:56:08.917865 2026] [security2:error] [pid 822943:tid 823077] [client 172.202.44.182:28083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/gecko.php"] [unique_id "amuQOI8CCDUa19YrTu4NcAAAAQ4"]
[Thu Jul 30 12:56:09.825438 2026] [security2:error] [pid 822943:tid 823103] [client 172.202.44.182:27196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/kyami.php"] [unique_id "amuQOY8CCDUa19YrTu4NfgAAASg"]
[Thu Jul 30 12:56:10.637162 2026] [security2:error] [pid 822943:tid 823091] [client 172.202.44.182:27265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/manager.php"] [unique_id "amuQOo8CCDUa19YrTu4NjwAAARw"]
[Thu Jul 30 12:56:11.108299 2026] [security2:error] [pid 822943:tid 823008] [remote 216.73.216.152:56689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQO48CCDUa19YrTu4NnQABDUA"]
[Thu Jul 30 12:56:11.625086 2026] [security2:error] [pid 822943:tid 823188] [client 172.202.44.182:27165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/mari.php"] [unique_id "amuQO48CCDUa19YrTu4NqQAAAX0"]
[Thu Jul 30 12:56:11.894369 2026] [security2:error] [pid 822943:tid 823137] [client 172.236.9.101:48612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQO48CCDUa19YrTu4NngAAAUo"]
[Thu Jul 30 12:56:11.954760 2026] [security2:error] [pid 822943:tid 823183] [client 172.236.9.101:51774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQO48CCDUa19YrTu4NpQAAAXg"]
[Thu Jul 30 12:56:12.197745 2026] [security2:error] [pid 822943:tid 823074] [client 150.107.232.194:26786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQPI8CCDUa19YrTu4NtAAAAQs"]
[Thu Jul 30 12:56:12.197872 2026] [security2:error] [pid 822943:tid 823074] [client 150.107.232.194:26786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQPI8CCDUa19YrTu4NtAAAAQs"]
[Thu Jul 30 12:56:12.419708 2026] [security2:error] [pid 822943:tid 823083] [client 172.202.44.182:28074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bonafideadvisors.com"] [uri "/nc4.php"] [unique_id "amuQPI8CCDUa19YrTu4NuAAAARQ"]
[Thu Jul 30 12:56:12.774158 2026] [security2:error] [pid 822943:tid 823127] [client 135.119.63.61:4205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/class-wp-image.php"] [unique_id "amuQPI8CCDUa19YrTu4NvwAAAUA"]
[Thu Jul 30 12:56:12.804165 2026] [proxy:error] [pid 822943:tid 823087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:56:12.804217 2026] [proxy_http:error] [pid 822943:tid 823087] [client 32.194.121.99:25259] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:56:12.805140 2026] [proxy:error] [pid 822943:tid 823087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:56:12.805191 2026] [proxy_http:error] [pid 822943:tid 823087] [client 32.194.121.99:25259] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:56:12.822128 2026] [proxy:error] [pid 822943:tid 823126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:56:12.822187 2026] [proxy_http:error] [pid 822943:tid 823126] [client 34.233.129.35:64225] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:56:12.822753 2026] [proxy:error] [pid 822943:tid 823126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 12:56:12.822798 2026] [proxy_http:error] [pid 822943:tid 823126] [client 34.233.129.35:64225] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 12:56:13.155221 2026] [security2:error] [pid 822943:tid 823010] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQPY8CCDUa19YrTu4NzwABPEI"]
[Thu Jul 30 12:56:13.155422 2026] [security2:error] [pid 822943:tid 823123] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQPY8CCDUa19YrTu4NzwABPEI"]
[Thu Jul 30 12:56:13.461693 2026] [cgid:error] [pid 822943:tid 823167] [client 172.202.44.182:28094] AH01265: stderr from /home2/bonafide/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 12:56:13.580218 2026] [core:notice] [pid 822943:tid 823117] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:13.587255 2026] [security2:error] [pid 822943:tid 823117] [client 103.215.74.26:35356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQPY8CCDUa19YrTu4N3AAAATY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:14.224570 2026] [security2:error] [pid 822943:tid 823154] [client 135.119.63.61:50807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/classsmtps.php"] [unique_id "amuQPo8CCDUa19YrTu4N-QAAAVs"]
[Thu Jul 30 12:56:14.307768 2026] [core:notice] [pid 822943:tid 823074] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:14.314161 2026] [security2:error] [pid 822943:tid 823074] [client 103.215.74.26:35372] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQPo8CCDUa19YrTu4N_gAAAQs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:14.774554 2026] [security2:error] [pid 822943:tid 823111] [client 172.236.9.101:40450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQPo8CCDUa19YrTu4N_AAAATA"]
[Thu Jul 30 12:56:14.857811 2026] [security2:error] [pid 822943:tid 823162] [client 152.32.208.9:55228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wce.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuQPo8CCDUa19YrTu4OCAAAAWM"]
[Thu Jul 30 12:56:15.036194 2026] [core:notice] [pid 822943:tid 823159] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:15.042642 2026] [security2:error] [pid 822943:tid 823159] [client 103.215.74.26:35376] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQP48CCDUa19YrTu4OEAAAAWA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:15.777597 2026] [core:notice] [pid 822943:tid 823112] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:15.783739 2026] [security2:error] [pid 822943:tid 823112] [client 103.215.74.26:35392] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQP48CCDUa19YrTu4OIwAAATE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:15.871316 2026] [security2:error] [pid 822943:tid 823056] [remote 216.73.216.152:63513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQP48CCDUa19YrTu4OJwABV3A"]
[Thu Jul 30 12:56:16.294254 2026] [security2:error] [pid 822943:tid 823108] [client 135.119.63.61:50333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/classwithtostring.php"] [unique_id "amuQQI8CCDUa19YrTu4OMwAAAS0"]
[Thu Jul 30 12:56:16.518098 2026] [core:notice] [pid 822943:tid 823096] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:16.525537 2026] [security2:error] [pid 822943:tid 823096] [client 103.215.74.26:35406] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQQI8CCDUa19YrTu4OOwAAASE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:16.809973 2026] [security2:error] [pid 822943:tid 823124] [client 172.236.9.101:46352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQQI8CCDUa19YrTu4OMgAAAT0"]
[Thu Jul 30 12:56:17.275343 2026] [core:notice] [pid 822943:tid 823180] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:17.287170 2026] [security2:error] [pid 822943:tid 823180] [client 103.215.74.26:35416] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQQY8CCDUa19YrTu4OUgAAAXU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:17.859513 2026] [security2:error] [pid 822943:tid 823113] [client 185.191.171.13:46608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/22/beneficiario-podera-usar-pix-para-movimentar-dinheiro-do-auxilio-emergencial-diz-bc/"] [unique_id "amuQQY8CCDUa19YrTu4OYAAAATI"]
[Thu Jul 30 12:56:17.859683 2026] [security2:error] [pid 822943:tid 823113] [client 185.191.171.13:46608] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/22/beneficiario-podera-usar-pix-para-movimentar-dinheiro-do-auxilio-emergencial-diz-bc/"] [unique_id "amuQQY8CCDUa19YrTu4OYAAAATI"]
[Thu Jul 30 12:56:18.025620 2026] [core:notice] [pid 822943:tid 823076] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:18.032160 2026] [security2:error] [pid 822943:tid 823076] [client 103.215.74.26:35424] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQQo8CCDUa19YrTu4OYQAAAQ0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:18.305518 2026] [security2:error] [pid 822943:tid 822961] [remote 168.144.81.91:35830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.81.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/wp-login.php"] [unique_id "amuQQo8CCDUa19YrTu4OawABLhE"]
[Thu Jul 30 12:56:18.753078 2026] [core:notice] [pid 822943:tid 823105] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:18.764447 2026] [security2:error] [pid 822943:tid 823105] [client 103.215.74.26:35426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQQo8CCDUa19YrTu4OdwAAASo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:19.127824 2026] [security2:error] [pid 822943:tid 823172] [client 112.86.225.206:56500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/21/bombeiros-encontram-cranio-durante-buscas-em-brumadinho/"] [unique_id "amuQQ48CCDUa19YrTu4OewAAAW0"]
[Thu Jul 30 12:56:19.128013 2026] [security2:error] [pid 822943:tid 823172] [client 112.86.225.206:56500] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/21/bombeiros-encontram-cranio-durante-buscas-em-brumadinho/"] [unique_id "amuQQ48CCDUa19YrTu4OewAAAW0"]
[Thu Jul 30 12:56:19.511870 2026] [security2:error] [pid 822943:tid 823168] [client 193.148.16.211:55904] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuQQ48CCDUa19YrTu4OhgAAAWk"]
[Thu Jul 30 12:56:19.512045 2026] [security2:error] [pid 822943:tid 823168] [client 193.148.16.211:55904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuQQ48CCDUa19YrTu4OhgAAAWk"]
[Thu Jul 30 12:56:20.036450 2026] [security2:error] [pid 822943:tid 823145] [client 135.119.63.61:4220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/config.php"] [unique_id "amuQRI8CCDUa19YrTu4OkAAAAVI"]
[Thu Jul 30 12:56:21.697819 2026] [core:error] [pid 822943:tid 822986] [remote 74.7.244.5:37538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:56:21.697853 2026] [core:error] [pid 822943:tid 822986] [remote 74.7.244.5:37538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:56:21.698092 2026] [security2:error] [pid 822943:tid 823082] [client 74.7.244.5:37538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-30643359.yxe.zzt.temporary.site"] [uri "/website_30643359/index.php"] [unique_id "amuQRY8CCDUa19YrTu4OuAABEyo"]
[Thu Jul 30 12:56:21.939586 2026] [security2:error] [pid 822943:tid 823177] [client 184.75.208.246:43976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuQRY8CCDUa19YrTu4OtwAAAXI"]
[Thu Jul 30 12:56:21.939713 2026] [security2:error] [pid 822943:tid 823177] [client 184.75.208.246:43976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuQRY8CCDUa19YrTu4OtwAAAXI"]
[Thu Jul 30 12:56:22.031262 2026] [security2:error] [pid 822943:tid 823174] [client 119.73.97.132:30620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuQRY8CCDUa19YrTu4OuwABbyw"], referer: https://www.urwru.club/about/
[Thu Jul 30 12:56:22.665283 2026] [security2:error] [pid 822943:tid 823117] [client 150.107.232.194:26676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQRo8CCDUa19YrTu4OzAAAATY"]
[Thu Jul 30 12:56:22.665405 2026] [security2:error] [pid 822943:tid 823117] [client 150.107.232.194:26676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQRo8CCDUa19YrTu4OzAAAATY"]
[Thu Jul 30 12:56:23.125395 2026] [security2:error] [pid 822943:tid 823175] [client 184.75.208.246:43982] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuQR48CCDUa19YrTu4O1gAAAXA"]
[Thu Jul 30 12:56:23.125488 2026] [security2:error] [pid 822943:tid 823175] [client 184.75.208.246:43982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuQR48CCDUa19YrTu4O1gAAAXA"]
[Thu Jul 30 12:56:23.357380 2026] [core:notice] [pid 822943:tid 823093] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:23.461409 2026] [security2:error] [pid 822943:tid 823000] [remote 74.7.241.59:47376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuQR48CCDUa19YrTu4O4AABazg"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/insert-headers-and-footers/includes
[Thu Jul 30 12:56:23.489064 2026] [core:notice] [pid 822943:tid 823109] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:23.786794 2026] [security2:error] [pid 822943:tid 823128] [client 135.119.63.61:50797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/core.php"] [unique_id "amuQR48CCDUa19YrTu4O5QAAAUE"]
[Thu Jul 30 12:56:23.870190 2026] [security2:error] [pid 822943:tid 823188] [client 4.184.185.91:17373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuQR48CCDUa19YrTu4O6AAAAX0"]
[Thu Jul 30 12:56:23.870313 2026] [security2:error] [pid 822943:tid 823188] [client 4.184.185.91:17373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuQR48CCDUa19YrTu4O6AAAAX0"]
[Thu Jul 30 12:56:24.009941 2026] [security2:error] [pid 822943:tid 823012] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQSI8CCDUa19YrTu4O7QABg0Q"]
[Thu Jul 30 12:56:24.010137 2026] [security2:error] [pid 822943:tid 823194] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQSI8CCDUa19YrTu4O7QABg0Q"]
[Thu Jul 30 12:56:24.520872 2026] [security2:error] [pid 822943:tid 823108] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQR48CCDUa19YrTu4O6QAAAS0"]
[Thu Jul 30 12:56:24.525109 2026] [core:notice] [pid 822943:tid 823149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:24.531663 2026] [security2:error] [pid 822943:tid 823149] [client 103.215.74.26:38572] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQSI8CCDUa19YrTu4O_AAAAVY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:24.878396 2026] [security2:error] [pid 822943:tid 823010] [remote 51.75.236.135:48150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.urwru.club"] [uri "/sitemap.xml"] [unique_id "amuQSI8CCDUa19YrTu4PBQABfkI"]
[Thu Jul 30 12:56:24.878617 2026] [security2:error] [pid 822943:tid 823189] [client 51.75.236.135:48150] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/sitemap.xml"] [unique_id "amuQSI8CCDUa19YrTu4PBQABfkI"]
[Thu Jul 30 12:56:24.987139 2026] [security2:error] [pid 822943:tid 823123] [client 135.119.63.61:50798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/css.php"] [unique_id "amuQSI8CCDUa19YrTu4PBgAAATw"]
[Thu Jul 30 12:56:25.251254 2026] [core:notice] [pid 822943:tid 823135] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:25.257877 2026] [security2:error] [pid 822943:tid 823135] [client 103.215.74.26:38584] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQSY8CCDUa19YrTu4PEQAAAUg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:25.988891 2026] [security2:error] [pid 822943:tid 823118] [client 4.184.185.91:17385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuQSY8CCDUa19YrTu4PIgAAATc"]
[Thu Jul 30 12:56:25.989001 2026] [security2:error] [pid 822943:tid 823118] [client 4.184.185.91:17385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuQSY8CCDUa19YrTu4PIgAAATc"]
[Thu Jul 30 12:56:25.992961 2026] [core:notice] [pid 822943:tid 823150] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:25.999656 2026] [security2:error] [pid 822943:tid 823150] [client 103.215.74.26:38594] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQSY8CCDUa19YrTu4PIwAAAVc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:26.742888 2026] [core:notice] [pid 822943:tid 823087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:26.749168 2026] [security2:error] [pid 822943:tid 823087] [client 103.215.74.26:38602] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQSo8CCDUa19YrTu4POAAAARg"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:26.926807 2026] [security2:error] [pid 822943:tid 823164] [client 135.119.63.61:50780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/database.php"] [unique_id "amuQSo8CCDUa19YrTu4PPAAAAWU"]
[Thu Jul 30 12:56:27.507287 2026] [core:notice] [pid 822943:tid 823107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:27.514659 2026] [security2:error] [pid 822943:tid 823107] [client 103.215.74.26:38616] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQS48CCDUa19YrTu4PSAAAASw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:27.702718 2026] [security2:error] [pid 822943:tid 823181] [client 4.184.185.91:17365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuQS48CCDUa19YrTu4PTAAAAXY"]
[Thu Jul 30 12:56:27.702815 2026] [security2:error] [pid 822943:tid 823181] [client 4.184.185.91:17365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuQS48CCDUa19YrTu4PTAAAAXY"]
[Thu Jul 30 12:56:27.841957 2026] [security2:error] [pid 822943:tid 823088] [client 172.236.9.101:9718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQS48CCDUa19YrTu4PRwAAARk"]
[Thu Jul 30 12:56:27.935682 2026] [security2:error] [pid 822943:tid 823167] [client 135.119.63.61:50413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/db.php"] [unique_id "amuQS48CCDUa19YrTu4PUwAAAWg"]
[Thu Jul 30 12:56:28.240530 2026] [core:notice] [pid 822943:tid 823084] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:28.247034 2026] [security2:error] [pid 822943:tid 823084] [client 103.215.74.26:38630] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQTI8CCDUa19YrTu4PXgAAARU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:28.300271 2026] [core:notice] [pid 822943:tid 823121] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:28.565031 2026] [security2:error] [pid 822943:tid 823132] [client 119.73.97.132:30620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuQTI8CCDUa19YrTu4PXwABRU8"]
[Thu Jul 30 12:56:28.833092 2026] [security2:error] [pid 822943:tid 823128] [client 135.119.63.61:50755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/default.php"] [unique_id "amuQTI8CCDUa19YrTu4PbgAAAUE"]
[Thu Jul 30 12:56:28.967233 2026] [security2:error] [pid 822943:tid 823169] [client 119.73.97.132:30620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuQTI8CCDUa19YrTu4PbAABalo"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 12:56:28.995844 2026] [core:notice] [pid 822943:tid 823143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:29.002191 2026] [security2:error] [pid 822943:tid 823143] [client 103.215.74.26:38632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQTI8CCDUa19YrTu4PdgAAAVA"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:29.402431 2026] [security2:error] [pid 822943:tid 823147] [client 172.236.9.101:47592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-content/w3tc/dbcache/" at Request_URI. [file "/opt/mod_security/hg_rules.conf"] [line "894"] [id "900094"] [msg "WP DB Cache Block"] [hostname "alseermarine.com"] [uri "/wp-content/w3tc/dbcache/"] [unique_id "amuQTY8CCDUa19YrTu4PgQAAAVQ"]
[Thu Jul 30 12:56:29.946172 2026] [security2:error] [pid 822943:tid 823189] [client 4.184.185.91:17364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/err.php"] [unique_id "amuQTY8CCDUa19YrTu4PiwAAAX4"]
[Thu Jul 30 12:56:29.946260 2026] [security2:error] [pid 822943:tid 823189] [client 4.184.185.91:17364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/err.php"] [unique_id "amuQTY8CCDUa19YrTu4PiwAAAX4"]
[Thu Jul 30 12:56:30.483724 2026] [security2:error] [pid 822943:tid 823123] [client 204.8.98.105:58582] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuQTo8CCDUa19YrTu4PjAAAATw"]
[Thu Jul 30 12:56:30.483860 2026] [security2:error] [pid 822943:tid 823123] [client 204.8.98.105:58582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuQTo8CCDUa19YrTu4PjAAAATw"]
[Thu Jul 30 12:56:31.030645 2026] [security2:error] [pid 822943:tid 823065] [remote 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQTo8CCDUa19YrTu4PlgABR3k"]
[Thu Jul 30 12:56:32.101993 2026] [security2:error] [pid 822943:tid 823195] [client 4.184.185.91:17293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/img.php"] [unique_id "amuQUI8CCDUa19YrTu4PugAAAYQ"]
[Thu Jul 30 12:56:32.102109 2026] [security2:error] [pid 822943:tid 823195] [client 4.184.185.91:17293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/img.php"] [unique_id "amuQUI8CCDUa19YrTu4PugAAAYQ"]
[Thu Jul 30 12:56:32.324946 2026] [security2:error] [pid 822943:tid 823160] [client 135.119.63.61:50778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/dropdown.php"] [unique_id "amuQUI8CCDUa19YrTu4PvAAAAWE"]
[Thu Jul 30 12:56:32.716779 2026] [security2:error] [pid 822943:tid 823087] [client 172.236.9.101:29140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQUI8CCDUa19YrTu4PuwAAARg"]
[Thu Jul 30 12:56:32.790630 2026] [security2:error] [pid 822943:tid 823103] [client 4.184.185.91:17397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/aa.php"] [unique_id "amuQUI8CCDUa19YrTu4PzAAAASg"]
[Thu Jul 30 12:56:32.790743 2026] [security2:error] [pid 822943:tid 823103] [client 4.184.185.91:17397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/aa.php"] [unique_id "amuQUI8CCDUa19YrTu4PzAAAASg"]
[Thu Jul 30 12:56:32.927695 2026] [security2:error] [pid 822943:tid 823130] [client 172.236.9.101:6846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQUI8CCDUa19YrTu4PwAAAAUM"]
[Thu Jul 30 12:56:33.032475 2026] [security2:error] [pid 822943:tid 823076] [client 85.208.96.201:55832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/09/empresas-de-joao-pessoa-e-campina-grande-oferecem-138-oportunidades-de-trabalho/"] [unique_id "amuQUY8CCDUa19YrTu4P1gAAAQ0"]
[Thu Jul 30 12:56:33.032599 2026] [security2:error] [pid 822943:tid 823076] [client 85.208.96.201:55832] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/09/empresas-de-joao-pessoa-e-campina-grande-oferecem-138-oportunidades-de-trabalho/"] [unique_id "amuQUY8CCDUa19YrTu4P1gAAAQ0"]
[Thu Jul 30 12:56:33.171907 2026] [security2:error] [pid 822943:tid 823114] [client 150.107.232.194:27112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQUY8CCDUa19YrTu4P1wAAATM"]
[Thu Jul 30 12:56:33.172057 2026] [security2:error] [pid 822943:tid 823114] [client 150.107.232.194:27112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQUY8CCDUa19YrTu4P1wAAATM"]
[Thu Jul 30 12:56:33.359412 2026] [security2:error] [pid 822943:tid 823094] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQUI8CCDUa19YrTu4PywAAAR8"]
[Thu Jul 30 12:56:33.711268 2026] [security2:error] [pid 822943:tid 823175] [client 135.119.63.61:24219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/edit.php"] [unique_id "amuQUY8CCDUa19YrTu4P5AAAAXA"]
[Thu Jul 30 12:56:33.846903 2026] [security2:error] [pid 822943:tid 823142] [client 4.184.185.91:17367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/av.php"] [unique_id "amuQUY8CCDUa19YrTu4P5QAAAU8"]
[Thu Jul 30 12:56:33.847021 2026] [security2:error] [pid 822943:tid 823142] [client 4.184.185.91:17367] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/av.php"] [unique_id "amuQUY8CCDUa19YrTu4P5QAAAU8"]
[Thu Jul 30 12:56:34.532732 2026] [security2:error] [pid 822943:tid 823146] [client 139.28.219.70:44000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuQUo8CCDUa19YrTu4P-wAAAVM"]
[Thu Jul 30 12:56:34.683638 2026] [security2:error] [pid 822943:tid 822969] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQUo8CCDUa19YrTu4QAgABZRk"]
[Thu Jul 30 12:56:34.683817 2026] [security2:error] [pid 822943:tid 823164] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQUo8CCDUa19YrTu4QAgABZRk"]
[Thu Jul 30 12:56:34.761204 2026] [core:notice] [pid 822943:tid 823190] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:34.767797 2026] [security2:error] [pid 822943:tid 823190] [client 103.215.74.26:13588] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQUo8CCDUa19YrTu4QAwAAAX8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:34.812985 2026] [security2:error] [pid 822943:tid 823108] [client 139.28.219.70:44014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mgstudiostore.com"] [uri "/xmlrpc.php"] [unique_id "amuQUo8CCDUa19YrTu4QBAAAAS0"]
[Thu Jul 30 12:56:34.898751 2026] [security2:error] [pid 822943:tid 823174] [client 4.184.185.91:17391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/xa.php"] [unique_id "amuQUo8CCDUa19YrTu4QBQAAAW8"]
[Thu Jul 30 12:56:34.898878 2026] [security2:error] [pid 822943:tid 823174] [client 4.184.185.91:17391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/xa.php"] [unique_id "amuQUo8CCDUa19YrTu4QBQAAAW8"]
[Thu Jul 30 12:56:35.304874 2026] [security2:error] [pid 822943:tid 823198] [client 139.28.219.70:44028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuQU48CCDUa19YrTu4QEgAAAYc"]
[Thu Jul 30 12:56:35.418127 2026] [security2:error] [pid 822943:tid 822974] [remote 40.77.167.132:21127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/offre-et-emploi/article.php"] [unique_id "amuQU48CCDUa19YrTu4QFwABeR4"]
[Thu Jul 30 12:56:35.445924 2026] [security2:error] [pid 822943:tid 823155] [client 4.184.185.91:17406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/media.php"] [unique_id "amuQU48CCDUa19YrTu4QGwAAAVw"]
[Thu Jul 30 12:56:35.446055 2026] [security2:error] [pid 822943:tid 823155] [client 4.184.185.91:17406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/media.php"] [unique_id "amuQU48CCDUa19YrTu4QGwAAAVw"]
[Thu Jul 30 12:56:35.502521 2026] [security2:error] [pid 822943:tid 823105] [client 135.119.63.61:22558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/f35.php"] [unique_id "amuQU48CCDUa19YrTu4QIwAAASo"]
[Thu Jul 30 12:56:35.504621 2026] [core:notice] [pid 822943:tid 823196] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:35.510831 2026] [security2:error] [pid 822943:tid 823196] [client 103.215.74.26:13590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQU48CCDUa19YrTu4QJAAAAYU"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:35.657039 2026] [security2:error] [pid 822943:tid 823095] [client 139.28.219.70:44036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuQU48CCDUa19YrTu4QKgAAASA"]
[Thu Jul 30 12:56:35.781417 2026] [security2:error] [pid 822943:tid 823117] [client 172.236.9.101:21984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQU48CCDUa19YrTu4QEQAAATY"]
[Thu Jul 30 12:56:35.937008 2026] [security2:error] [pid 822943:tid 823129] [client 172.236.9.101:62776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQU48CCDUa19YrTu4QGAAAAUI"]
[Thu Jul 30 12:56:35.960363 2026] [security2:error] [pid 822943:tid 823114] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQU48CCDUa19YrTu4QFQAAATM"]
[Thu Jul 30 12:56:36.011940 2026] [security2:error] [pid 822943:tid 823158] [client 139.28.219.70:44042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuQVI8CCDUa19YrTu4QLwAAAV8"]
[Thu Jul 30 12:56:36.236635 2026] [core:notice] [pid 822943:tid 823080] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:36.244163 2026] [security2:error] [pid 822943:tid 823080] [client 103.215.74.26:13596] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQVI8CCDUa19YrTu4QNgAAARE"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:36.268064 2026] [security2:error] [pid 822943:tid 823148] [client 139.28.219.70:44052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuQVI8CCDUa19YrTu4QNwAAAVU"]
[Thu Jul 30 12:56:36.412184 2026] [security2:error] [pid 822943:tid 823096] [client 135.119.63.61:22570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/f7.php"] [unique_id "amuQVI8CCDUa19YrTu4QOAAAASE"]
[Thu Jul 30 12:56:36.562640 2026] [security2:error] [pid 822943:tid 823082] [client 139.28.219.70:44054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuQVI8CCDUa19YrTu4QPQAAARM"]
[Thu Jul 30 12:56:36.718417 2026] [security2:error] [pid 822943:tid 823115] [client 172.236.9.101:41773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQVI8CCDUa19YrTu4QOQAAATQ"]
[Thu Jul 30 12:56:36.826755 2026] [security2:error] [pid 822943:tid 823190] [client 139.28.219.70:44066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuQVI8CCDUa19YrTu4QRAAAAX8"]
[Thu Jul 30 12:56:36.979034 2026] [core:notice] [pid 822943:tid 823092] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:36.985634 2026] [security2:error] [pid 822943:tid 823092] [client 103.215.74.26:13612] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQVI8CCDUa19YrTu4QRQAAAR0"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:37.013434 2026] [security2:error] [pid 822943:tid 823180] [client 4.184.185.91:17380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/images.php"] [unique_id "amuQVY8CCDUa19YrTu4QRgAAAXU"]
[Thu Jul 30 12:56:37.013523 2026] [security2:error] [pid 822943:tid 823180] [client 4.184.185.91:17380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/images.php"] [unique_id "amuQVY8CCDUa19YrTu4QRgAAAXU"]
[Thu Jul 30 12:56:37.146498 2026] [security2:error] [pid 822943:tid 823099] [client 139.28.219.70:44080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuQVY8CCDUa19YrTu4QTQAAASQ"]
[Thu Jul 30 12:56:37.474000 2026] [security2:error] [pid 822943:tid 823198] [client 139.28.219.70:44092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuQVY8CCDUa19YrTu4QUQAAAYc"]
[Thu Jul 30 12:56:37.729532 2026] [core:notice] [pid 822943:tid 823145] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:37.736039 2026] [security2:error] [pid 822943:tid 823145] [client 103.215.74.26:13626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQVY8CCDUa19YrTu4QWAAAAVI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:37.814320 2026] [security2:error] [pid 822943:tid 823196] [client 139.28.219.70:44100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuQVY8CCDUa19YrTu4QWQAAAYU"]
[Thu Jul 30 12:56:38.077633 2026] [security2:error] [pid 822943:tid 823121] [client 139.28.219.70:44106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuQVo8CCDUa19YrTu4QXgAAATo"]
[Thu Jul 30 12:56:38.398650 2026] [security2:error] [pid 822943:tid 823110] [client 4.184.185.91:17389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/gecko.php"] [unique_id "amuQVo8CCDUa19YrTu4QaQAAAS8"]
[Thu Jul 30 12:56:38.398778 2026] [security2:error] [pid 822943:tid 823110] [client 4.184.185.91:17389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/gecko.php"] [unique_id "amuQVo8CCDUa19YrTu4QaQAAAS8"]
[Thu Jul 30 12:56:38.416138 2026] [security2:error] [pid 822943:tid 823088] [client 139.28.219.70:44112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuQVo8CCDUa19YrTu4QagAAARk"]
[Thu Jul 30 12:56:38.456945 2026] [core:notice] [pid 822943:tid 823102] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:38.465026 2026] [security2:error] [pid 822943:tid 823102] [client 103.215.74.26:13640] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQVo8CCDUa19YrTu4QawAAASc"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:38.691293 2026] [security2:error] [pid 822943:tid 823192] [client 139.28.219.70:44124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuQVo8CCDUa19YrTu4QbwAAAYE"]
[Thu Jul 30 12:56:38.775289 2026] [security2:error] [pid 822943:tid 823118] [client 172.236.9.101:1875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQVo8CCDUa19YrTu4QZQAAATc"]
[Thu Jul 30 12:56:38.952348 2026] [security2:error] [pid 822943:tid 823143] [client 139.28.219.70:44140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mgstudiostore.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuQVo8CCDUa19YrTu4QdgAAAVA"]
[Thu Jul 30 12:56:39.208518 2026] [core:notice] [pid 822943:tid 823126] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:39.214940 2026] [security2:error] [pid 822943:tid 823126] [client 103.215.74.26:13652] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQV48CCDUa19YrTu4QegAAAT8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:39.254244 2026] [security2:error] [pid 822943:tid 823008] [remote 5.161.62.209:43834] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/.env"] [unique_id "amuQV48CCDUa19YrTu4QfgABQEA"]
[Thu Jul 30 12:56:39.937812 2026] [core:notice] [pid 822943:tid 823190] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:39.943599 2026] [security2:error] [pid 822943:tid 823190] [client 103.215.74.26:13660] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQV48CCDUa19YrTu4QiwAAAX8"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:40.068423 2026] [security2:error] [pid 822943:tid 823189] [client 4.184.185.91:17370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/82.php"] [unique_id "amuQWI8CCDUa19YrTu4QjQAAAX4"]
[Thu Jul 30 12:56:40.068544 2026] [security2:error] [pid 822943:tid 823189] [client 4.184.185.91:17370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/82.php"] [unique_id "amuQWI8CCDUa19YrTu4QjQAAAX4"]
[Thu Jul 30 12:56:40.674953 2026] [core:notice] [pid 822943:tid 823121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:40.681339 2026] [security2:error] [pid 822943:tid 823121] [client 103.215.74.26:13666] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQWI8CCDUa19YrTu4QrgAAATo"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:40.900777 2026] [security2:error] [pid 822943:tid 823158] [client 4.184.185.91:17315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/xstelth.php"] [unique_id "amuQWI8CCDUa19YrTu4QtQAAAV8"]
[Thu Jul 30 12:56:40.900879 2026] [security2:error] [pid 822943:tid 823158] [client 4.184.185.91:17315] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/xstelth.php"] [unique_id "amuQWI8CCDUa19YrTu4QtQAAAV8"]
[Thu Jul 30 12:56:41.084074 2026] [security2:error] [pid 822943:tid 822998] [remote 52.167.144.212:7180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/publika/article/view/8219"] [unique_id "amuQWY8CCDUa19YrTu4QuQABdzY"]
[Thu Jul 30 12:56:41.417886 2026] [core:notice] [pid 822943:tid 823101] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:41.424222 2026] [security2:error] [pid 822943:tid 823101] [client 103.215.74.26:13676] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQWY8CCDUa19YrTu4QvQAAASY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:42.175206 2026] [core:notice] [pid 822943:tid 823187] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:42.182602 2026] [security2:error] [pid 822943:tid 823187] [client 103.215.74.26:13686] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQWo8CCDUa19YrTu4Q1QAAAXw"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:42.904922 2026] [security2:error] [pid 822943:tid 823135] [client 4.184.185.91:17303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/xp.php"] [unique_id "amuQWo8CCDUa19YrTu4Q5AAAAUg"]
[Thu Jul 30 12:56:42.905043 2026] [security2:error] [pid 822943:tid 823135] [client 4.184.185.91:17303] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/xp.php"] [unique_id "amuQWo8CCDUa19YrTu4Q5AAAAUg"]
[Thu Jul 30 12:56:42.929503 2026] [security2:error] [pid 822943:tid 823199] [client 74.7.175.176:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qjl.dlq.temporary.site"] [uri "/index.php"] [unique_id "amuQWY8CCDUa19YrTu4QywAAAYg"]
[Thu Jul 30 12:56:42.930420 2026] [security2:error] [pid 822943:tid 823168] [client 74.7.175.176:35208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qjl.dlq.temporary.site"] [uri "/robots.txt"] [unique_id "amuQWY8CCDUa19YrTu4QyQABaU0"]
[Thu Jul 30 12:56:43.269638 2026] [security2:error] [pid 822943:tid 823026] [remote 209.38.221.42:51162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.221.38.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuQW48CCDUa19YrTu4Q8QABaFI"]
[Thu Jul 30 12:56:43.270791 2026] [security2:error] [pid 822943:tid 823079] [client 184.75.208.246:50112] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQW48CCDUa19YrTu4Q8gAAARA"]
[Thu Jul 30 12:56:43.270875 2026] [security2:error] [pid 822943:tid 823079] [client 184.75.208.246:50112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQW48CCDUa19YrTu4Q8gAAARA"]
[Thu Jul 30 12:56:43.636213 2026] [security2:error] [pid 822943:tid 823036] [remote 160.191.139.115:35706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.139.191.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuQW48CCDUa19YrTu4Q_AABIlw"]
[Thu Jul 30 12:56:43.643737 2026] [security2:error] [pid 822943:tid 823083] [client 150.107.232.194:27370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQW48CCDUa19YrTu4Q_QAAARQ"]
[Thu Jul 30 12:56:43.643826 2026] [security2:error] [pid 822943:tid 823083] [client 150.107.232.194:27370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQW48CCDUa19YrTu4Q_QAAARQ"]
[Thu Jul 30 12:56:45.533513 2026] [security2:error] [pid 822943:tid 823128] [client 4.184.185.91:17388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/admin.php"] [unique_id "amuQXY8CCDUa19YrTu4RKgAAAUE"]
[Thu Jul 30 12:56:45.533616 2026] [security2:error] [pid 822943:tid 823128] [client 4.184.185.91:17388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/admin.php"] [unique_id "amuQXY8CCDUa19YrTu4RKgAAAUE"]
[Thu Jul 30 12:56:45.535585 2026] [security2:error] [pid 822943:tid 823052] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQXY8CCDUa19YrTu4RKQABM2w"]
[Thu Jul 30 12:56:45.535718 2026] [security2:error] [pid 822943:tid 823114] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQXY8CCDUa19YrTu4RKQABM2w"]
[Thu Jul 30 12:56:46.249930 2026] [security2:error] [pid 822943:tid 823108] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQXY8CCDUa19YrTu4RIgABLVo"]
[Thu Jul 30 12:56:46.497605 2026] [security2:error] [pid 822943:tid 823145] [client 152.32.208.9:47444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wce.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuQXo8CCDUa19YrTu4RZgAAAVI"]
[Thu Jul 30 12:56:46.500634 2026] [security2:error] [pid 822943:tid 823159] [client 4.184.185.91:17344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/adminner.php"] [unique_id "amuQXo8CCDUa19YrTu4RagAAAWA"]
[Thu Jul 30 12:56:46.500728 2026] [security2:error] [pid 822943:tid 823159] [client 4.184.185.91:17344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/adminner.php"] [unique_id "amuQXo8CCDUa19YrTu4RagAAAWA"]
[Thu Jul 30 12:56:47.178216 2026] [security2:error] [pid 822943:tid 823150] [client 4.184.185.91:17350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/a.php"] [unique_id "amuQX48CCDUa19YrTu4RhgAAAVc"]
[Thu Jul 30 12:56:47.178343 2026] [security2:error] [pid 822943:tid 823150] [client 4.184.185.91:17350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/a.php"] [unique_id "amuQX48CCDUa19YrTu4RhgAAAVc"]
[Thu Jul 30 12:56:47.919740 2026] [core:notice] [pid 822943:tid 823085] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:47.925382 2026] [security2:error] [pid 822943:tid 823085] [client 103.215.74.26:56738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuQX48CCDUa19YrTu4RmwAAARY"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:56:48.361727 2026] [security2:error] [pid 822943:tid 823110] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQX48CCDUa19YrTu4RlQABLzQ"]
[Thu Jul 30 12:56:48.622936 2026] [security2:error] [pid 822943:tid 823076] [client 4.184.185.91:17396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/k.php"] [unique_id "amuQYI8CCDUa19YrTu4RqgAAAQ0"]
[Thu Jul 30 12:56:48.623041 2026] [security2:error] [pid 822943:tid 823076] [client 4.184.185.91:17396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/k.php"] [unique_id "amuQYI8CCDUa19YrTu4RqgAAAQ0"]
[Thu Jul 30 12:56:49.411255 2026] [core:notice] [pid 822943:tid 823123] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:50.162442 2026] [security2:error] [pid 822943:tid 823088] [client 20.171.55.167:4339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuQYo8CCDUa19YrTu4R0wAAARk"]
[Thu Jul 30 12:56:50.772661 2026] [security2:error] [pid 822943:tid 823158] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQYo8CCDUa19YrTu4R1QABX1g"]
[Thu Jul 30 12:56:50.919689 2026] [security2:error] [pid 822943:tid 823178] [client 20.171.55.167:4231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/404.php"] [unique_id "amuQYo8CCDUa19YrTu4R6gAAAXM"]
[Thu Jul 30 12:56:51.654030 2026] [security2:error] [pid 822943:tid 823152] [client 20.171.55.167:4331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-configs.php"] [unique_id "amuQY48CCDUa19YrTu4R9wAAAVk"]
[Thu Jul 30 12:56:51.866367 2026] [security2:error] [pid 822943:tid 823153] [client 4.184.185.91:17386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/222.php"] [unique_id "amuQY48CCDUa19YrTu4R_wAAAVo"]
[Thu Jul 30 12:56:51.866478 2026] [security2:error] [pid 822943:tid 823153] [client 4.184.185.91:17386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/222.php"] [unique_id "amuQY48CCDUa19YrTu4R_wAAAVo"]
[Thu Jul 30 12:56:52.168004 2026] [security2:error] [pid 822943:tid 823128] [client 184.75.208.246:41140] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuQZI8CCDUa19YrTu4SCAAAAUE"]
[Thu Jul 30 12:56:52.168111 2026] [security2:error] [pid 822943:tid 823128] [client 184.75.208.246:41140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuQZI8CCDUa19YrTu4SCAAAAUE"]
[Thu Jul 30 12:56:52.353277 2026] [security2:error] [pid 822943:tid 823121] [client 20.171.55.167:4312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/simple.php"] [unique_id "amuQZI8CCDUa19YrTu4SDAAAATo"]
[Thu Jul 30 12:56:52.822801 2026] [security2:error] [pid 822943:tid 823136] [client 152.32.208.9:51096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.wce.gzj.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amuQZI8CCDUa19YrTu4SGQAAAUk"]
[Thu Jul 30 12:56:53.055161 2026] [security2:error] [pid 822943:tid 823126] [client 20.171.55.167:4303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/themes.php"] [unique_id "amuQZY8CCDUa19YrTu4SHgAAAT8"]
[Thu Jul 30 12:56:53.608862 2026] [security2:error] [pid 822943:tid 823190] [client 4.184.185.91:17357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/mac.php"] [unique_id "amuQZY8CCDUa19YrTu4SKwAAAX8"]
[Thu Jul 30 12:56:53.608959 2026] [security2:error] [pid 822943:tid 823190] [client 4.184.185.91:17357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/mac.php"] [unique_id "amuQZY8CCDUa19YrTu4SKwAAAX8"]
[Thu Jul 30 12:56:53.789827 2026] [security2:error] [pid 822943:tid 823164] [client 20.171.55.167:4324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ini.php"] [unique_id "amuQZY8CCDUa19YrTu4SMAAAAWU"]
[Thu Jul 30 12:56:53.825843 2026] [security2:error] [pid 822943:tid 823062] [remote 57.141.18.3:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQZY8CCDUa19YrTu4SNQABUnY"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=linen,plastic,steel&filter_size=extra-extra-large,large,small&tax_product_cat=suit&unfilter=1
[Thu Jul 30 12:56:53.860106 2026] [security2:error] [pid 822943:tid 823080] [client 172.236.9.101:11807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQZY8CCDUa19YrTu4SJAAAARE"]
[Thu Jul 30 12:56:54.107531 2026] [security2:error] [pid 822943:tid 823137] [client 150.107.232.194:26557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQZo8CCDUa19YrTu4SPwAAAUo"]
[Thu Jul 30 12:56:54.107637 2026] [security2:error] [pid 822943:tid 823137] [client 150.107.232.194:26557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQZo8CCDUa19YrTu4SPwAAAUo"]
[Thu Jul 30 12:56:54.180333 2026] [security2:error] [pid 822943:tid 823055] [remote 57.141.18.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQZo8CCDUa19YrTu4SQwABNW8"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=linen,plastic,steel&filter_size=extra-extra-large,large,small&tax_product_cat=suit&unfilter=1
[Thu Jul 30 12:56:54.438852 2026] [security2:error] [pid 822943:tid 823181] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQZY8CCDUa19YrTu4SNwAAAXY"]
[Thu Jul 30 12:56:54.529925 2026] [security2:error] [pid 822943:tid 823117] [client 20.171.55.167:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/autoload_classmap.php"] [unique_id "amuQZo8CCDUa19YrTu4SSwAAATY"]
[Thu Jul 30 12:56:55.267940 2026] [security2:error] [pid 822943:tid 823101] [client 20.171.55.167:4319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/as.php"] [unique_id "amuQZ48CCDUa19YrTu4SXwAAASY"]
[Thu Jul 30 12:56:55.316908 2026] [core:notice] [pid 822943:tid 823105] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:56:55.320644 2026] [security2:error] [pid 822943:tid 823105] [client 66.249.79.1:47348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/5764/pdf"] [unique_id "amuQZ48CCDUa19YrTu4SVwAAASo"]
[Thu Jul 30 12:56:55.611964 2026] [security2:error] [pid 822943:tid 823142] [client 66.249.66.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQZ48CCDUa19YrTu4SWAABTwA"]
[Thu Jul 30 12:56:55.875285 2026] [security2:error] [pid 822943:tid 823198] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "yardex.ae"] [uri "/index.html"] [unique_id "amuQZ48CCDUa19YrTu4ScQAAAYc"]
[Thu Jul 30 12:56:55.875678 2026] [security2:error] [pid 822943:tid 823112] [client 4.184.185.91:17369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "yardex.ae"] [uri "/wp-content/uploads/"] [unique_id "amuQZ48CCDUa19YrTu4SbwAAATE"]
[Thu Jul 30 12:56:56.008937 2026] [security2:error] [pid 822943:tid 823080] [client 20.171.55.167:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/admin/upload/css.php"] [unique_id "amuQaI8CCDUa19YrTu4SdwAAARE"]
[Thu Jul 30 12:56:56.011062 2026] [security2:error] [pid 822943:tid 823155] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "yardex.ae"] [uri "/index.html"] [unique_id "amuQaI8CCDUa19YrTu4SeAAAAVw"]
[Thu Jul 30 12:56:56.011436 2026] [security2:error] [pid 822943:tid 823116] [client 4.184.185.91:17369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "yardex.ae"] [uri "/wp-includes/Text/"] [unique_id "amuQaI8CCDUa19YrTu4SdQAAATU"]
[Thu Jul 30 12:56:56.249740 2026] [security2:error] [pid 822943:tid 823071] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQaI8CCDUa19YrTu4SfwABM38"]
[Thu Jul 30 12:56:56.249878 2026] [security2:error] [pid 822943:tid 823114] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQaI8CCDUa19YrTu4SfwABM38"]
[Thu Jul 30 12:56:56.279109 2026] [security2:error] [pid 822943:tid 823092] [client 74.7.241.134:49402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.shop-peace.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuQaI8CCDUa19YrTu4SgAAAAR0"]
[Thu Jul 30 12:56:56.386890 2026] [security2:error] [pid 822943:tid 823132] [client 4.184.185.91:17369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/ops.php"] [unique_id "amuQaI8CCDUa19YrTu4ShAAAAUU"]
[Thu Jul 30 12:56:56.387020 2026] [security2:error] [pid 822943:tid 823132] [client 4.184.185.91:17369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/ops.php"] [unique_id "amuQaI8CCDUa19YrTu4ShAAAAUU"]
[Thu Jul 30 12:56:56.718085 2026] [security2:error] [pid 822943:tid 823098] [client 20.171.55.167:4507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/pki-validation/afnew.php"] [unique_id "amuQaI8CCDUa19YrTu4SiQAAASM"]
[Thu Jul 30 12:56:57.429199 2026] [security2:error] [pid 822943:tid 823105] [client 20.171.55.167:4338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/lufix.php"] [unique_id "amuQaY8CCDUa19YrTu4SnQAAASo"]
[Thu Jul 30 12:56:57.896146 2026] [security2:error] [pid 822943:tid 823090] [client 4.184.185.91:17280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/8.php"] [unique_id "amuQaY8CCDUa19YrTu4SpwAAARs"]
[Thu Jul 30 12:56:57.896250 2026] [security2:error] [pid 822943:tid 823090] [client 4.184.185.91:17280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/8.php"] [unique_id "amuQaY8CCDUa19YrTu4SpwAAARs"]
[Thu Jul 30 12:56:58.124823 2026] [security2:error] [pid 822943:tid 823140] [client 20.171.55.167:4528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/media.php"] [unique_id "amuQao8CCDUa19YrTu4SrAAAAU0"]
[Thu Jul 30 12:56:59.296126 2026] [security2:error] [pid 822943:tid 823182] [client 20.171.55.167:4501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/simple.php"] [unique_id "amuQa48CCDUa19YrTu4SwgAAAXc"]
[Thu Jul 30 12:56:59.386453 2026] [security2:error] [pid 822943:tid 823125] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQao8CCDUa19YrTu4SuAAAAT4"]
[Thu Jul 30 12:56:59.736374 2026] [security2:error] [pid 822943:tid 823132] [client 172.236.9.101:14496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQa48CCDUa19YrTu4SwAAAAUU"]
[Thu Jul 30 12:56:59.753851 2026] [security2:error] [pid 822943:tid 823143] [client 4.184.185.91:17394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/FWAZ.php"] [unique_id "amuQa48CCDUa19YrTu4SzQAAAVA"]
[Thu Jul 30 12:56:59.753939 2026] [security2:error] [pid 822943:tid 823143] [client 4.184.185.91:17394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/FWAZ.php"] [unique_id "amuQa48CCDUa19YrTu4SzQAAAVA"]
[Thu Jul 30 12:57:00.029934 2026] [security2:error] [pid 822943:tid 823127] [client 20.171.55.167:5111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/contact.php"] [unique_id "amuQbI8CCDUa19YrTu4S1wAAAUA"]
[Thu Jul 30 12:57:00.363035 2026] [security2:error] [pid 822943:tid 823200] [client 4.184.185.91:17360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/biufile.php"] [unique_id "amuQbI8CCDUa19YrTu4S2QAAAYk"]
[Thu Jul 30 12:57:00.363155 2026] [security2:error] [pid 822943:tid 823200] [client 4.184.185.91:17360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/biufile.php"] [unique_id "amuQbI8CCDUa19YrTu4S2QAAAYk"]
[Thu Jul 30 12:57:00.469311 2026] [security2:error] [pid 822943:tid 822991] [remote 74.7.241.60:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/article.php"] [unique_id "amuQbI8CCDUa19YrTu4S4wABYS8"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/bootstrap.bundle.min.js
[Thu Jul 30 12:57:00.560754 2026] [security2:error] [pid 822943:tid 823189] [client 95.108.213.215:43976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuQbI8CCDUa19YrTu4S2AAAAX4"]
[Thu Jul 30 12:57:00.734648 2026] [security2:error] [pid 822943:tid 823081] [client 20.171.55.167:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/byp.php"] [unique_id "amuQbI8CCDUa19YrTu4S5wAAARI"]
[Thu Jul 30 12:57:01.065728 2026] [security2:error] [pid 822943:tid 823124] [client 127.0.0.1:20404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuQbY8CCDUa19YrTu4S8gAAAT0"]
[Thu Jul 30 12:57:01.065836 2026] [security2:error] [pid 822943:tid 823162] [client 74.7.241.173:57672] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.pyn.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuQbY8CCDUa19YrTu4S8QABYyw"]
[Thu Jul 30 12:57:01.439351 2026] [security2:error] [pid 822943:tid 823131] [client 20.171.55.167:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/upload.php"] [unique_id "amuQbY8CCDUa19YrTu4S-AAAAUQ"]
[Thu Jul 30 12:57:01.491120 2026] [security2:error] [pid 822943:tid 823125] [client 4.184.185.91:17283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/coffexium.php"] [unique_id "amuQbY8CCDUa19YrTu4S_AAAAT4"]
[Thu Jul 30 12:57:01.491210 2026] [security2:error] [pid 822943:tid 823125] [client 4.184.185.91:17283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/coffexium.php"] [unique_id "amuQbY8CCDUa19YrTu4S_AAAAT4"]
[Thu Jul 30 12:57:02.151769 2026] [security2:error] [pid 822943:tid 823174] [client 20.171.55.167:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "amuQbo8CCDUa19YrTu4TFgAAAW8"]
[Thu Jul 30 12:57:02.599766 2026] [security2:error] [pid 822943:tid 823164] [client 4.184.185.91:17401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/simple.php"] [unique_id "amuQbo8CCDUa19YrTu4THgAAAWU"]
[Thu Jul 30 12:57:02.599854 2026] [security2:error] [pid 822943:tid 823164] [client 4.184.185.91:17401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/simple.php"] [unique_id "amuQbo8CCDUa19YrTu4THgAAAWU"]
[Thu Jul 30 12:57:02.711841 2026] [security2:error] [pid 822943:tid 823104] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQbo8CCDUa19YrTu4TFQAAASk"]
[Thu Jul 30 12:57:02.866708 2026] [security2:error] [pid 822943:tid 823103] [client 20.171.55.167:5084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cong.php"] [unique_id "amuQbo8CCDUa19YrTu4TIQAAASg"]
[Thu Jul 30 12:57:03.573920 2026] [security2:error] [pid 822943:tid 823113] [client 20.171.55.167:4485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/about/function.php"] [unique_id "amuQb48CCDUa19YrTu4TNAAAATI"]
[Thu Jul 30 12:57:03.704457 2026] [security2:error] [pid 822943:tid 823102] [client 4.184.185.91:11209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/fpwch.php"] [unique_id "amuQb48CCDUa19YrTu4TOwAAASc"]
[Thu Jul 30 12:57:03.704563 2026] [security2:error] [pid 822943:tid 823102] [client 4.184.185.91:11209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/fpwch.php"] [unique_id "amuQb48CCDUa19YrTu4TOwAAASc"]
[Thu Jul 30 12:57:04.315901 2026] [security2:error] [pid 822943:tid 823151] [client 20.171.55.167:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/filemanager/dialog.php"] [unique_id "amuQcI8CCDUa19YrTu4TSQAAAVg"]
[Thu Jul 30 12:57:04.611238 2026] [security2:error] [pid 822943:tid 823089] [client 150.107.232.194:26907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQcI8CCDUa19YrTu4TTQAAARo"]
[Thu Jul 30 12:57:04.611358 2026] [security2:error] [pid 822943:tid 823089] [client 150.107.232.194:26907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQcI8CCDUa19YrTu4TTQAAARo"]
[Thu Jul 30 12:57:05.033466 2026] [security2:error] [pid 822943:tid 823105] [client 20.171.55.167:4483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/bak.php"] [unique_id "amuQcY8CCDUa19YrTu4TVAAAASo"]
[Thu Jul 30 12:57:05.176131 2026] [security2:error] [pid 822943:tid 823085] [client 4.184.185.91:17309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/dex.php"] [unique_id "amuQcY8CCDUa19YrTu4TWAAAARY"]
[Thu Jul 30 12:57:05.176239 2026] [security2:error] [pid 822943:tid 823085] [client 4.184.185.91:17309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/dex.php"] [unique_id "amuQcY8CCDUa19YrTu4TWAAAARY"]
[Thu Jul 30 12:57:05.778741 2026] [security2:error] [pid 822943:tid 823186] [client 20.171.55.167:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-info.php"] [unique_id "amuQcY8CCDUa19YrTu4TZgAAAXs"]
[Thu Jul 30 12:57:06.015190 2026] [security2:error] [pid 822943:tid 823032] [remote 51.68.111.213:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aashlawfirm.com"] [uri "/robots.txt"] [unique_id "amuQco8CCDUa19YrTu4TagABUVg"]
[Thu Jul 30 12:57:06.015370 2026] [security2:error] [pid 822943:tid 823144] [client 51.68.111.213:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aashlawfirm.com"] [uri "/robots.txt"] [unique_id "amuQco8CCDUa19YrTu4TagABUVg"]
[Thu Jul 30 12:57:06.499260 2026] [security2:error] [pid 822943:tid 823159] [client 20.171.55.167:5074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/files/index.php"] [unique_id "amuQco8CCDUa19YrTu4TewAAAWA"]
[Thu Jul 30 12:57:06.500658 2026] [core:notice] [pid 822943:tid 823078] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:06.999941 2026] [security2:error] [pid 822943:tid 823039] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQco8CCDUa19YrTu4ThwABX18"]
[Thu Jul 30 12:57:07.000236 2026] [security2:error] [pid 822943:tid 823158] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQco8CCDUa19YrTu4ThwABX18"]
[Thu Jul 30 12:57:07.131513 2026] [security2:error] [pid 822943:tid 823088] [client 4.184.185.91:17383] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "yardex.ae"] [uri "/1.php"] [unique_id "amuQc48CCDUa19YrTu4TiAAAARk"]
[Thu Jul 30 12:57:07.131627 2026] [security2:error] [pid 822943:tid 823088] [client 4.184.185.91:17383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/1.php"] [unique_id "amuQc48CCDUa19YrTu4TiAAAARk"]
[Thu Jul 30 12:57:07.131732 2026] [security2:error] [pid 822943:tid 823088] [client 4.184.185.91:17383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/1.php"] [unique_id "amuQc48CCDUa19YrTu4TiAAAARk"]
[Thu Jul 30 12:57:07.237280 2026] [security2:error] [pid 822943:tid 823172] [client 20.171.55.167:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/css.php"] [unique_id "amuQc48CCDUa19YrTu4TiQAAAW0"]
[Thu Jul 30 12:57:07.900320 2026] [security2:error] [pid 822943:tid 823140] [client 85.204.70.116:4118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuQc48CCDUa19YrTu4TmgAAAU0"]
[Thu Jul 30 12:57:07.964388 2026] [security2:error] [pid 822943:tid 823130] [client 20.171.55.167:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/css/index.php"] [unique_id "amuQc48CCDUa19YrTu4TngAAAUM"]
[Thu Jul 30 12:57:08.099992 2026] [core:notice] [pid 822943:tid 823166] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:08.101619 2026] [core:notice] [pid 822943:tid 823080] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:08.164375 2026] [security2:error] [pid 822943:tid 823090] [client 85.204.70.116:49460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuQdI8CCDUa19YrTu4TpQAAARs"]
[Thu Jul 30 12:57:08.217468 2026] [security2:error] [pid 822943:tid 823087] [client 240.175.169.83:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amuQco8CCDUa19YrTu4TdAABGEo"]
[Thu Jul 30 12:57:08.429870 2026] [core:error] [pid 822943:tid 823058] [remote 216.73.216.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:57:08.429897 2026] [core:error] [pid 822943:tid 823058] [remote 216.73.216.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:57:08.573950 2026] [core:notice] [pid 822943:tid 823102] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:08.618610 2026] [security2:error] [pid 822943:tid 823098] [client 85.204.70.116:63235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuQdI8CCDUa19YrTu4TtgAAASM"]
[Thu Jul 30 12:57:08.620500 2026] [security2:error] [pid 822943:tid 823171] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQdI8CCDUa19YrTu4TogABbGQ"]
[Thu Jul 30 12:57:08.737750 2026] [security2:error] [pid 822943:tid 823121] [client 20.171.55.167:5086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/bak.php"] [unique_id "amuQdI8CCDUa19YrTu4TtwAAATo"]
[Thu Jul 30 12:57:08.924458 2026] [security2:error] [pid 822943:tid 823078] [client 85.204.70.116:49470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuQdI8CCDUa19YrTu4TuQAAAQ8"]
[Thu Jul 30 12:57:09.178485 2026] [security2:error] [pid 822943:tid 823149] [client 85.204.70.116:49478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuQdY8CCDUa19YrTu4TwgAAAVY"]
[Thu Jul 30 12:57:09.458740 2026] [security2:error] [pid 822943:tid 823089] [client 20.171.55.167:4488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/alfa-rex.php7"] [unique_id "amuQdY8CCDUa19YrTu4TyQAAARo"]
[Thu Jul 30 12:57:09.490458 2026] [security2:error] [pid 822943:tid 823174] [client 85.204.70.116:49488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuQdY8CCDUa19YrTu4TywAAAW8"]
[Thu Jul 30 12:57:09.753584 2026] [security2:error] [pid 822943:tid 823104] [client 85.204.70.116:49498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuQdY8CCDUa19YrTu4T0gAAASk"]
[Thu Jul 30 12:57:09.813825 2026] [security2:error] [pid 822943:tid 823184] [client 4.184.185.91:17393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "yardex.ae"] [uri "/index.html"] [unique_id "amuQdY8CCDUa19YrTu4T0wAAAXk"]
[Thu Jul 30 12:57:09.902029 2026] [security2:error] [pid 822943:tid 823076] [client 116.179.37.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amuQdY8CCDUa19YrTu4T1gABDW4"], referer: https://mannyplatoncuevas.com/wp-content/fonts/9fce748c1df0d68d5551526ee784f158.css
[Thu Jul 30 12:57:09.944125 2026] [security2:error] [pid 822943:tid 823123] [client 4.184.185.91:17393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/config.json.php"] [unique_id "amuQdY8CCDUa19YrTu4T3QAAATw"]
[Thu Jul 30 12:57:09.944267 2026] [security2:error] [pid 822943:tid 823123] [client 4.184.185.91:17393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/config.json.php"] [unique_id "amuQdY8CCDUa19YrTu4T3QAAATw"]
[Thu Jul 30 12:57:09.967184 2026] [security2:error] [pid 822943:tid 823153] [client 116.179.37.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amuQdY8CCDUa19YrTu4T2wABWns"], referer: https://mannyplatoncuevas.com/wp-content/fonts/9fce748c1df0d68d5551526ee784f158.css
[Thu Jul 30 12:57:10.008371 2026] [security2:error] [pid 822943:tid 823112] [client 85.204.70.116:29012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuQdo8CCDUa19YrTu4T4QAAATE"]
[Thu Jul 30 12:57:10.316099 2026] [security2:error] [pid 822943:tid 823113] [client 85.204.70.116:49506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuQdo8CCDUa19YrTu4T5gAAATI"]
[Thu Jul 30 12:57:10.448288 2026] [security2:error] [pid 822943:tid 823115] [client 20.171.55.167:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/wp-login.php"] [unique_id "amuQdo8CCDUa19YrTu4T5QAAATQ"]
[Thu Jul 30 12:57:10.606815 2026] [security2:error] [pid 822943:tid 823114] [client 85.204.70.116:49510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuQdo8CCDUa19YrTu4T8wAAATM"]
[Thu Jul 30 12:57:10.736821 2026] [security2:error] [pid 822943:tid 823185] [client 4.184.185.91:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yardex.ae"] [uri "/k2.php"] [unique_id "amuQdo8CCDUa19YrTu4T9AAAAXo"]
[Thu Jul 30 12:57:10.736941 2026] [security2:error] [pid 822943:tid 823185] [client 4.184.185.91:17297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "yardex.ae"] [uri "/k2.php"] [unique_id "amuQdo8CCDUa19YrTu4T9AAAAXo"]
[Thu Jul 30 12:57:10.908670 2026] [security2:error] [pid 822943:tid 823154] [client 116.179.37.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amuQdo8CCDUa19YrTu4T9QABWwA"], referer: https://mannyplatoncuevas.com/wp-content/fonts/9fce748c1df0d68d5551526ee784f158.css
[Thu Jul 30 12:57:10.915362 2026] [security2:error] [pid 822943:tid 823098] [client 85.204.70.116:49516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuQdo8CCDUa19YrTu4T-AAAASM"]
[Thu Jul 30 12:57:10.959514 2026] [security2:error] [pid 822943:tid 823148] [client 116.179.37.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amuQdo8CCDUa19YrTu4T9wABVX4"], referer: https://mannyplatoncuevas.com/wp-content/fonts/9fce748c1df0d68d5551526ee784f158.css
[Thu Jul 30 12:57:11.149597 2026] [security2:error] [pid 822943:tid 823161] [client 20.171.55.167:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/cloud.php"] [unique_id "amuQd48CCDUa19YrTu4UAgAAAWI"]
[Thu Jul 30 12:57:11.195326 2026] [security2:error] [pid 822943:tid 823119] [client 85.204.70.116:49532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuQd48CCDUa19YrTu4UAwAAATg"]
[Thu Jul 30 12:57:11.487616 2026] [security2:error] [pid 822943:tid 823149] [client 85.204.70.116:9399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuQd48CCDUa19YrTu4UBgAAAVY"]
[Thu Jul 30 12:57:11.776191 2026] [security2:error] [pid 822943:tid 823088] [client 85.204.70.116:28610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuQd48CCDUa19YrTu4UEQAAARk"]
[Thu Jul 30 12:57:11.864574 2026] [security2:error] [pid 822943:tid 823164] [client 116.179.37.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amuQd48CCDUa19YrTu4UEgABZWk"], referer: https://mannyplatoncuevas.com/wp-content/fonts/9fce748c1df0d68d5551526ee784f158.css
[Thu Jul 30 12:57:11.868577 2026] [security2:error] [pid 822943:tid 823105] [client 20.171.55.167:5065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/index.php"] [unique_id "amuQd48CCDUa19YrTu4UFwAAASo"]
[Thu Jul 30 12:57:11.979709 2026] [security2:error] [pid 822943:tid 822958] [remote 85.208.96.204:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "teknomalay.com"] [uri "/robots.txt"] [unique_id "amuQd48CCDUa19YrTu4UGQABfw4"]
[Thu Jul 30 12:57:11.979907 2026] [security2:error] [pid 822943:tid 823190] [client 85.208.96.204:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teknomalay.com"] [uri "/robots.txt"] [unique_id "amuQd48CCDUa19YrTu4UGQABfw4"]
[Thu Jul 30 12:57:12.040533 2026] [security2:error] [pid 822943:tid 822972] [remote 116.179.37.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amuQd48CCDUa19YrTu4UGAABeRw"], referer: https://mannyplatoncuevas.com/wp-content/fonts/9fce748c1df0d68d5551526ee784f158.css
[Thu Jul 30 12:57:12.086321 2026] [security2:error] [pid 822943:tid 823123] [client 85.204.70.116:14597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuQeI8CCDUa19YrTu4UIAAAATw"]
[Thu Jul 30 12:57:12.223564 2026] [core:notice] [pid 822943:tid 823169] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:12.385119 2026] [security2:error] [pid 822943:tid 823080] [client 85.204.70.116:37098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuQeI8CCDUa19YrTu4UKwAAARE"]
[Thu Jul 30 12:57:12.582032 2026] [security2:error] [pid 822943:tid 823175] [client 20.171.55.167:5103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/readme.php"] [unique_id "amuQeI8CCDUa19YrTu4ULwAAAXA"]
[Thu Jul 30 12:57:12.663110 2026] [security2:error] [pid 822943:tid 823137] [client 85.204.70.116:37102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.vpv.tqa.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuQeI8CCDUa19YrTu4UMwAAAUo"]
[Thu Jul 30 12:57:12.670790 2026] [security2:error] [pid 822943:tid 823198] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQeI8CCDUa19YrTu4UHwAAAYc"]
[Thu Jul 30 12:57:13.317726 2026] [security2:error] [pid 822943:tid 823092] [client 20.171.55.167:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/about.php"] [unique_id "amuQeY8CCDUa19YrTu4UQQAAAR0"]
[Thu Jul 30 12:57:14.022726 2026] [security2:error] [pid 822943:tid 823195] [client 20.171.55.167:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/themes/404.php"] [unique_id "amuQeo8CCDUa19YrTu4UTQAAAYQ"]
[Thu Jul 30 12:57:14.028540 2026] [security2:error] [pid 822943:tid 823153] [client 74.7.228.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nwa.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuQeI8CCDUa19YrTu4UJgAAAVo"]
[Thu Jul 30 12:57:14.029540 2026] [security2:error] [pid 822943:tid 823177] [client 74.7.228.52:46240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nwa.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuQeI8CCDUa19YrTu4UJAABchk"]
[Thu Jul 30 12:57:14.765990 2026] [security2:error] [pid 822943:tid 823093] [client 20.171.55.167:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/index.php"] [unique_id "amuQeo8CCDUa19YrTu4UZwAAAR4"]
[Thu Jul 30 12:57:15.134532 2026] [security2:error] [pid 822943:tid 823117] [client 150.107.232.194:26937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQe48CCDUa19YrTu4UaQAAATY"]
[Thu Jul 30 12:57:15.134665 2026] [security2:error] [pid 822943:tid 823117] [client 150.107.232.194:26937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQe48CCDUa19YrTu4UaQAAATY"]
[Thu Jul 30 12:57:15.452204 2026] [security2:error] [pid 822943:tid 822987] [remote 216.73.216.152:63513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQe48CCDUa19YrTu4UcgABYis"]
[Thu Jul 30 12:57:15.505992 2026] [security2:error] [pid 822943:tid 823160] [client 20.171.55.167:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/themes.php"] [unique_id "amuQe48CCDUa19YrTu4UcwAAAWE"]
[Thu Jul 30 12:57:15.814689 2026] [security2:error] [pid 822943:tid 822992] [remote 185.191.171.12:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "teknomalay.com"] [uri "/acer-service-center-melaka/"] [unique_id "amuQe48CCDUa19YrTu4UfQABejA"]
[Thu Jul 30 12:57:15.814866 2026] [security2:error] [pid 822943:tid 823185] [client 185.191.171.12:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teknomalay.com"] [uri "/acer-service-center-melaka/"] [unique_id "amuQe48CCDUa19YrTu4UfQABejA"]
[Thu Jul 30 12:57:16.217420 2026] [security2:error] [pid 822943:tid 823200] [client 20.171.55.167:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/dropdown.php"] [unique_id "amuQfI8CCDUa19YrTu4UgQAAAYk"]
[Thu Jul 30 12:57:16.445644 2026] [security2:error] [pid 822943:tid 823004] [remote 51.161.65.216:31374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kicksity.com"] [uri "/product/nike-air-force-shadow-white-pink/feed/"] [unique_id "amuQfI8CCDUa19YrTu4UigABSDw"]
[Thu Jul 30 12:57:16.445806 2026] [security2:error] [pid 822943:tid 823135] [client 51.161.65.216:31374] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-air-force-shadow-white-pink/feed/"] [unique_id "amuQfI8CCDUa19YrTu4UigABSDw"]
[Thu Jul 30 12:57:16.915931 2026] [security2:error] [pid 822943:tid 823096] [client 20.171.55.167:4493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/404.php"] [unique_id "amuQfI8CCDUa19YrTu4UlwAAASE"]
[Thu Jul 30 12:57:17.697649 2026] [security2:error] [pid 822943:tid 823007] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQfY8CCDUa19YrTu4UpAABOj8"]
[Thu Jul 30 12:57:17.697829 2026] [security2:error] [pid 822943:tid 823121] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQfY8CCDUa19YrTu4UpAABOj8"]
[Thu Jul 30 12:57:17.703666 2026] [security2:error] [pid 822943:tid 823133] [client 20.171.55.167:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuQfY8CCDUa19YrTu4UpQAAAUY"]
[Thu Jul 30 12:57:18.142604 2026] [autoindex:error] [pid 822943:tid 823172] [client 82.102.18.118:40998] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:57:18.332233 2026] [autoindex:error] [pid 822943:tid 823153] [client 82.102.18.118:40998] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:57:18.422078 2026] [security2:error] [pid 822943:tid 823200] [client 20.171.55.167:5117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/file.php"] [unique_id "amuQfo8CCDUa19YrTu4UwgAAAYk"]
[Thu Jul 30 12:57:18.518343 2026] [security2:error] [pid 822943:tid 823111] [client 82.102.18.118:40998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuQfo8CCDUa19YrTu4UwwAAATA"]
[Thu Jul 30 12:57:18.882538 2026] [security2:error] [pid 822943:tid 823120] [client 82.102.18.118:41014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hello-pal.com"] [uri "/xmlrpc.php"] [unique_id "amuQfo8CCDUa19YrTu4UxwAAATk"]
[Thu Jul 30 12:57:19.179275 2026] [autoindex:error] [pid 822943:tid 823075] [client 82.102.18.118:1291] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:57:19.318722 2026] [security2:error] [pid 822943:tid 823166] [client 82.102.18.118:1291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuQf48CCDUa19YrTu4UzwAAAWc"]
[Thu Jul 30 12:57:19.593346 2026] [security2:error] [pid 822943:tid 823122] [client 82.102.18.118:41026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuQf48CCDUa19YrTu4U3AAAATs"]
[Thu Jul 30 12:57:19.622064 2026] [security2:error] [pid 822943:tid 823150] [client 20.171.55.167:4490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/index.php"] [unique_id "amuQf48CCDUa19YrTu4U3QAAAVc"]
[Thu Jul 30 12:57:19.928467 2026] [security2:error] [pid 822943:tid 823165] [client 82.102.18.118:41028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuQf48CCDUa19YrTu4U4QAAAWY"]
[Thu Jul 30 12:57:20.208436 2026] [security2:error] [pid 822943:tid 823151] [client 82.102.18.118:41036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuQgI8CCDUa19YrTu4U6AAAAVg"]
[Thu Jul 30 12:57:20.361611 2026] [security2:error] [pid 822943:tid 823161] [client 20.171.55.167:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/cloud.php"] [unique_id "amuQgI8CCDUa19YrTu4U6gAAAWI"]
[Thu Jul 30 12:57:20.488343 2026] [security2:error] [pid 822943:tid 823078] [client 82.102.18.118:41050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuQgI8CCDUa19YrTu4U7gAAAQ8"]
[Thu Jul 30 12:57:20.802911 2026] [security2:error] [pid 822943:tid 823164] [client 82.102.18.118:41052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuQgI8CCDUa19YrTu4U-AAAAWU"]
[Thu Jul 30 12:57:20.889463 2026] [security2:error] [pid 822943:tid 823079] [client 172.236.9.101:61675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQgI8CCDUa19YrTu4U6QAAARA"]
[Thu Jul 30 12:57:21.095486 2026] [security2:error] [pid 822943:tid 823085] [client 20.171.55.167:4514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amuQgY8CCDUa19YrTu4VAgAAARY"]
[Thu Jul 30 12:57:21.114549 2026] [security2:error] [pid 822943:tid 823046] [remote 216.73.216.152:1341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQgY8CCDUa19YrTu4VAwABQGY"]
[Thu Jul 30 12:57:21.124785 2026] [security2:error] [pid 822943:tid 823111] [client 82.102.18.118:41060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuQgY8CCDUa19YrTu4VBAAAATA"]
[Thu Jul 30 12:57:21.412090 2026] [security2:error] [pid 822943:tid 823084] [client 82.102.18.118:41066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuQgY8CCDUa19YrTu4VBgAAARU"]
[Thu Jul 30 12:57:21.740497 2026] [security2:error] [pid 822943:tid 823107] [client 82.102.18.118:41076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuQgY8CCDUa19YrTu4VEQAAASw"]
[Thu Jul 30 12:57:21.824508 2026] [security2:error] [pid 822943:tid 823081] [client 20.171.55.167:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/404.php"] [unique_id "amuQgY8CCDUa19YrTu4VEwAAARI"]
[Thu Jul 30 12:57:21.866712 2026] [security2:error] [pid 822943:tid 823058] [remote 57.141.18.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQgY8CCDUa19YrTu4VEAABDXI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,lycra,plastic,steel,polyester&filter_size=large,medium&orderby=date&rating=4&status=instock&tax_product_cat=suit&unfilter=1
[Thu Jul 30 12:57:21.900107 2026] [fcgid:warn] [pid 822943:tid 823198] (70014)End of file found: [client 165.154.164.24:41856] mod_fcgid: can't get data from http client
[Thu Jul 30 12:57:22.012917 2026] [security2:error] [pid 822943:tid 823052] [remote 57.141.18.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQgY8CCDUa19YrTu4VEgABIWw"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,lycra,plastic,steel,polyester&filter_size=large,medium&orderby=date&rating=4&status=instock&tax_product_cat=suit&unfilter=1
[Thu Jul 30 12:57:22.090028 2026] [security2:error] [pid 822943:tid 823199] [client 82.102.18.118:41084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuQgo8CCDUa19YrTu4VGwAAAYg"]
[Thu Jul 30 12:57:22.558147 2026] [security2:error] [pid 822943:tid 823095] [client 20.171.55.167:4516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/function.php"] [unique_id "amuQgo8CCDUa19YrTu4VJgAAASA"]
[Thu Jul 30 12:57:22.696418 2026] [core:notice] [pid 822943:tid 823125] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:23.279676 2026] [security2:error] [pid 822943:tid 823179] [client 20.171.55.167:4290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/file.php"] [unique_id "amuQg48CCDUa19YrTu4VNAAAAXQ"]
[Thu Jul 30 12:57:23.454688 2026] [security2:error] [pid 822943:tid 823200] [client 82.102.18.118:41088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuQg48CCDUa19YrTu4VNQAAAYk"]
[Thu Jul 30 12:57:23.755192 2026] [security2:error] [pid 822943:tid 823112] [client 82.102.18.118:46421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuQg48CCDUa19YrTu4VPwAAATE"]
[Thu Jul 30 12:57:24.025197 2026] [security2:error] [pid 822943:tid 823109] [client 20.171.55.167:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/acme-challenge/autoload_classmap.php"] [unique_id "amuQhI8CCDUa19YrTu4VQAAAAS4"]
[Thu Jul 30 12:57:24.036021 2026] [security2:error] [pid 822943:tid 823113] [client 82.102.18.118:56410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuQhI8CCDUa19YrTu4VQQAAATI"]
[Thu Jul 30 12:57:24.321300 2026] [security2:error] [pid 822943:tid 823138] [client 82.102.18.118:56416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuQhI8CCDUa19YrTu4VTAAAAUs"]
[Thu Jul 30 12:57:24.357779 2026] [core:notice] [pid 822943:tid 823116] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:24.604821 2026] [security2:error] [pid 822943:tid 823165] [client 82.102.18.118:15093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hello-pal.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuQhI8CCDUa19YrTu4VVAAAAWY"]
[Thu Jul 30 12:57:24.723920 2026] [security2:error] [pid 822943:tid 823150] [client 20.171.55.167:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/themes.php"] [unique_id "amuQhI8CCDUa19YrTu4VXgAAAVc"]
[Thu Jul 30 12:57:25.133096 2026] [security2:error] [pid 822943:tid 823170] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQhI8CCDUa19YrTu4VUAABa3s"]
[Thu Jul 30 12:57:25.422358 2026] [security2:error] [pid 822943:tid 823101] [client 20.171.55.167:4494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/wp-login.php"] [unique_id "amuQhY8CCDUa19YrTu4VagAAASY"]
[Thu Jul 30 12:57:25.589678 2026] [security2:error] [pid 822943:tid 823091] [client 150.107.232.194:27218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQhY8CCDUa19YrTu4VbgAAARw"]
[Thu Jul 30 12:57:25.589788 2026] [security2:error] [pid 822943:tid 823091] [client 150.107.232.194:27218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQhY8CCDUa19YrTu4VbgAAARw"]
[Thu Jul 30 12:57:25.882594 2026] [security2:error] [pid 822943:tid 823120] [client 8.215.201.253:62572] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bep-viet.bonafideadvisors.com"] [uri "/"] [unique_id "amuQhY8CCDUa19YrTu4VeQAAATk"]
[Thu Jul 30 12:57:26.019897 2026] [security2:error] [pid 822943:tid 823109] [client 8.215.201.253:62573] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bep-viet.bonafideadvisors.com"] [uri "/wp-json/batch/v1"] [unique_id "amuQho8CCDUa19YrTu4VegAAAS4"]
[Thu Jul 30 12:57:26.170324 2026] [security2:error] [pid 822943:tid 823166] [client 20.171.55.167:4692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/file.php"] [unique_id "amuQho8CCDUa19YrTu4VfgAAAWc"]
[Thu Jul 30 12:57:26.900265 2026] [security2:error] [pid 822943:tid 823167] [client 20.171.55.167:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-trackback.php"] [unique_id "amuQho8CCDUa19YrTu4VkQAAAWg"]
[Thu Jul 30 12:57:27.645860 2026] [security2:error] [pid 822943:tid 823108] [client 20.171.55.167:4248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "amuQh48CCDUa19YrTu4VoAAAAS0"]
[Thu Jul 30 12:57:28.380790 2026] [security2:error] [pid 822943:tid 823141] [client 20.171.55.167:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/index.php"] [unique_id "amuQiI8CCDUa19YrTu4VuwAAAU4"]
[Thu Jul 30 12:57:28.393083 2026] [security2:error] [pid 822943:tid 822982] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQiI8CCDUa19YrTu4VvQABMSY"]
[Thu Jul 30 12:57:28.393332 2026] [security2:error] [pid 822943:tid 823112] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQiI8CCDUa19YrTu4VvQABMSY"]
[Thu Jul 30 12:57:28.790534 2026] [core:notice] [pid 822943:tid 823149] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:29.090889 2026] [security2:error] [pid 822943:tid 823094] [client 20.171.55.167:4268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/themes.php"] [unique_id "amuQiY8CCDUa19YrTu4VzwAAAR8"]
[Thu Jul 30 12:57:29.219475 2026] [security2:error] [pid 822943:tid 823169] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQiI8CCDUa19YrTu4VvwABahk"]
[Thu Jul 30 12:57:29.265984 2026] [security2:error] [pid 822943:tid 823145] [client 93.158.90.71:57717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.90.158.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/bbs/board.php"] [unique_id "amuQiY8CCDUa19YrTu4VzgAAAVI"]
[Thu Jul 30 12:57:29.801955 2026] [security2:error] [pid 822943:tid 823136] [client 20.171.55.167:4308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/cloud.php"] [unique_id "amuQiY8CCDUa19YrTu4V3QAAAUk"]
[Thu Jul 30 12:57:29.808396 2026] [security2:error] [pid 822943:tid 823156] [client 93.158.90.67:36353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.90.158.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/bbs/current_connect.php"] [unique_id "amuQiY8CCDUa19YrTu4V3AAAAV0"]
[Thu Jul 30 12:57:29.879109 2026] [security2:error] [pid 822943:tid 823095] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQiY8CCDUa19YrTu4V0gAAASA"]
[Thu Jul 30 12:57:29.997118 2026] [security2:error] [pid 822943:tid 823177] [client 52.167.144.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuQh48CCDUa19YrTu4VqQAAAXI"]
[Thu Jul 30 12:57:30.101308 2026] [security2:error] [pid 822943:tid 823091] [client 93.158.90.67:54787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.90.158.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/bbs/password_lost.php"] [unique_id "amuQio8CCDUa19YrTu4V6QAAARw"]
[Thu Jul 30 12:57:30.546957 2026] [security2:error] [pid 822943:tid 823127] [client 20.171.55.167:4274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/wp-load.php"] [unique_id "amuQio8CCDUa19YrTu4V9QAAAUA"]
[Thu Jul 30 12:57:30.821691 2026] [security2:error] [pid 822943:tid 823085] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQio8CCDUa19YrTu4V6gABFhM"]
[Thu Jul 30 12:57:31.267731 2026] [security2:error] [pid 822943:tid 823140] [client 20.171.55.167:4241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/file.php"] [unique_id "amuQi48CCDUa19YrTu4WAQAAAU0"]
[Thu Jul 30 12:57:31.975093 2026] [security2:error] [pid 822943:tid 823163] [client 20.171.55.167:4260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuQi48CCDUa19YrTu4WEgAAAWQ"]
[Thu Jul 30 12:57:32.691077 2026] [security2:error] [pid 822943:tid 823168] [client 20.171.55.167:4252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/index.php"] [unique_id "amuQjI8CCDUa19YrTu4WHwAAAWk"]
[Thu Jul 30 12:57:33.399151 2026] [security2:error] [pid 822943:tid 823075] [client 20.171.55.167:4684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuQjY8CCDUa19YrTu4WOAAAAQw"]
[Thu Jul 30 12:57:33.460227 2026] [security2:error] [pid 822943:tid 823158] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQjI8CCDUa19YrTu4WIwABXzo"]
[Thu Jul 30 12:57:33.682474 2026] [security2:error] [pid 822943:tid 823156] [client 204.8.98.105:46414] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuQjY8CCDUa19YrTu4WTwAAAV0"]
[Thu Jul 30 12:57:33.682549 2026] [security2:error] [pid 822943:tid 823156] [client 204.8.98.105:46414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuQjY8CCDUa19YrTu4WTwAAAV0"]
[Thu Jul 30 12:57:34.106349 2026] [security2:error] [pid 822943:tid 823190] [client 20.171.55.167:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/404.php"] [unique_id "amuQjo8CCDUa19YrTu4WbAAAAX8"]
[Thu Jul 30 12:57:34.231565 2026] [security2:error] [pid 822943:tid 823099] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQjY8CCDUa19YrTu4WQQABJE0"]
[Thu Jul 30 12:57:34.839463 2026] [security2:error] [pid 822943:tid 823194] [client 20.171.55.167:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "amuQjo8CCDUa19YrTu4WlgAAAYM"]
[Thu Jul 30 12:57:35.561018 2026] [security2:error] [pid 822943:tid 823169] [client 20.171.55.167:4295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/radio.php"] [unique_id "amuQj48CCDUa19YrTu4WsgAAAWo"]
[Thu Jul 30 12:57:36.021171 2026] [security2:error] [pid 822943:tid 823098] [client 43.172.195.15:54866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2020/10/28/bouquets-fleurs-sechees/"] [unique_id "amuQkI8CCDUa19YrTu4WvgAAASM"]
[Thu Jul 30 12:57:36.081879 2026] [security2:error] [pid 822943:tid 823120] [client 150.107.232.194:27291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQkI8CCDUa19YrTu4WwQAAATk"]
[Thu Jul 30 12:57:36.082007 2026] [security2:error] [pid 822943:tid 823120] [client 150.107.232.194:27291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQkI8CCDUa19YrTu4WwQAAATk"]
[Thu Jul 30 12:57:36.263326 2026] [security2:error] [pid 822943:tid 823084] [client 43.172.197.146:38366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/oembed/1.0/embed"] [unique_id "amuQkI8CCDUa19YrTu4WvQAAARU"]
[Thu Jul 30 12:57:36.314535 2026] [security2:error] [pid 822943:tid 823149] [client 20.171.55.167:4272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuQkI8CCDUa19YrTu4W8AAAAVY"]
[Thu Jul 30 12:57:36.473353 2026] [security2:error] [pid 822943:tid 823117] [client 138.246.253.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "remoteworksit.com"] [uri "/index.php"] [unique_id "amuQkI8CCDUa19YrTu4W7AAAATY"]
[Thu Jul 30 12:57:36.634901 2026] [core:notice] [pid 822943:tid 823196] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:36.640420 2026] [security2:error] [pid 822943:tid 823196] [client 43.173.174.246:55398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2020/10/28/bouquets-fleurs-sechees/"] [unique_id "amuQkI8CCDUa19YrTu4W9QAAAYU"], referer: https://carnetdeshopping.com/index.php/2020/10/28/bouquets-fleurs-sechees/
[Thu Jul 30 12:57:37.065665 2026] [security2:error] [pid 822943:tid 823158] [client 20.171.55.167:4282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/admin.php"] [unique_id "amuQkY8CCDUa19YrTu4XAQAAAV8"]
[Thu Jul 30 12:57:37.326044 2026] [core:notice] [pid 822943:tid 823087] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:37.331910 2026] [security2:error] [pid 822943:tid 823087] [client 43.173.175.81:39802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/oembed/1.0/embed"] [unique_id "amuQkY8CCDUa19YrTu4XCwAAARg"], referer: https://carnetdeshopping.com/index.php/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fcarnetdeshopping.com%2Findex.php%2F2015%2F10%2F30%2Fnoel-2015-nature-et-decouvertes-et-carrefour%2F&format=xml
[Thu Jul 30 12:57:37.794772 2026] [security2:error] [pid 822943:tid 823140] [client 20.171.55.167:4247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/system_log.php"] [unique_id "amuQkY8CCDUa19YrTu4XGwAAAU0"]
[Thu Jul 30 12:57:38.270215 2026] [core:notice] [pid 822943:tid 823059] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:38.280394 2026] [security2:error] [pid 822943:tid 823077] [client 43.173.175.70:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.175.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sellvia.womenclothingbox.com"] [uri "/"] [unique_id "amuQko8CCDUa19YrTu4XJAAAAQ4"], referer: https://carnetdeshopping.com/
[Thu Jul 30 12:57:38.875665 2026] [security2:error] [pid 822943:tid 823117] [client 20.171.55.167:4281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/wp-activate.php"] [unique_id "amuQko8CCDUa19YrTu4XOgAAATY"]
[Thu Jul 30 12:57:39.110215 2026] [security2:error] [pid 822943:tid 823056] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQk48CCDUa19YrTu4XQQABWHA"]
[Thu Jul 30 12:57:39.110371 2026] [security2:error] [pid 822943:tid 823151] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQk48CCDUa19YrTu4XQQABWHA"]
[Thu Jul 30 12:57:39.634100 2026] [security2:error] [pid 822943:tid 823090] [client 20.171.55.167:4278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/makeasmtp.php"] [unique_id "amuQk48CCDUa19YrTu4XTQAAARs"]
[Thu Jul 30 12:57:40.123054 2026] [core:notice] [pid 822943:tid 823077] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:40.372601 2026] [security2:error] [pid 822943:tid 823100] [client 20.171.55.167:4243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuQlI8CCDUa19YrTu4XXQAAASU"]
[Thu Jul 30 12:57:41.083381 2026] [security2:error] [pid 822943:tid 823157] [client 20.171.55.167:4266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/link.php"] [unique_id "amuQlY8CCDUa19YrTu4XeQAAAV4"]
[Thu Jul 30 12:57:41.791217 2026] [security2:error] [pid 822943:tid 823096] [client 20.171.55.167:4285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuQlY8CCDUa19YrTu4XkAAAASE"]
[Thu Jul 30 12:57:42.420206 2026] [security2:error] [pid 822943:tid 823120] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQlY8CCDUa19YrTu4XjgABOQo"]
[Thu Jul 30 12:57:42.501640 2026] [security2:error] [pid 822943:tid 823084] [client 20.171.55.167:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/themes.php"] [unique_id "amuQlo8CCDUa19YrTu4XrAAAARU"]
[Thu Jul 30 12:57:43.006965 2026] [security2:error] [pid 822943:tid 823091] [client 43.165.127.225:60036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.127.165.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/xmlrpc.php"] [unique_id "amuQlo8CCDUa19YrTu4XtwAAARw"]
[Thu Jul 30 12:57:43.096791 2026] [security2:error] [pid 822943:tid 822958] [remote 47.128.117.25:49774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuQl48CCDUa19YrTu4XxQABYQ4"]
[Thu Jul 30 12:57:43.233914 2026] [security2:error] [pid 822943:tid 823115] [client 20.171.55.167:4683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuQl48CCDUa19YrTu4XzQAAATQ"]
[Thu Jul 30 12:57:43.642265 2026] [security2:error] [pid 822943:tid 823193] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQl48CCDUa19YrTu4XwAAAAYI"]
[Thu Jul 30 12:57:43.937109 2026] [security2:error] [pid 822943:tid 823101] [client 20.171.55.167:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuQl48CCDUa19YrTu4X2AAAASY"]
[Thu Jul 30 12:57:44.673799 2026] [security2:error] [pid 822943:tid 823099] [client 20.171.55.167:4691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/function.php"] [unique_id "amuQmI8CCDUa19YrTu4X6wAAASQ"]
[Thu Jul 30 12:57:45.112287 2026] [security2:error] [pid 822943:tid 823029] [remote 57.141.0.50:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuQmY8CCDUa19YrTu4YIAABG1U"]
[Thu Jul 30 12:57:45.411353 2026] [security2:error] [pid 822943:tid 823153] [client 20.171.55.167:4273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/images/wp-login.php"] [unique_id "amuQmY8CCDUa19YrTu4YKwAAAVo"]
[Thu Jul 30 12:57:45.429705 2026] [core:error] [pid 822943:tid 823190] [client 74.7.244.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:57:45.429724 2026] [core:error] [pid 822943:tid 823190] [client 74.7.244.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:57:45.429830 2026] [security2:error] [pid 822943:tid 823190] [client 74.7.244.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.akth.com.pk"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuQmY8CCDUa19YrTu4YLgAAAX8"]
[Thu Jul 30 12:57:45.430383 2026] [security2:error] [pid 822943:tid 823112] [client 74.7.244.45:37862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.akth.com.pk"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuQmY8CCDUa19YrTu4YLAABMVg"]
[Thu Jul 30 12:57:45.575112 2026] [security2:error] [pid 822943:tid 823026] [remote 47.128.122.133:29402] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sellvia.womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amuQmY8CCDUa19YrTu4YMgABNlI"]
[Thu Jul 30 12:57:45.731896 2026] [security2:error] [pid 822943:tid 823179] [client 154.93.49.139:41978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amuQmI8CCDUa19YrTu4YEAABdE4"], referer: https://supreme-hydraulics.com/
[Thu Jul 30 12:57:45.732062 2026] [security2:error] [pid 822943:tid 823179] [client 154.93.49.139:41978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amuQmI8CCDUa19YrTu4YEQABdEc"], referer: https://supreme-hydraulics.com/
[Thu Jul 30 12:57:45.732153 2026] [security2:error] [pid 822943:tid 823179] [client 154.93.49.139:41978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amuQmY8CCDUa19YrTu4YEgABdCc"], referer: https://supreme-hydraulics.com/
[Thu Jul 30 12:57:46.067224 2026] [security2:error] [pid 822943:tid 823135] [client 114.119.150.6:23275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jesus.claims"] [uri "/robots.txt"] [unique_id "amuQmo8CCDUa19YrTu4YPQAAAUg"], referer: https://jesus.claims/robots.txt
[Thu Jul 30 12:57:46.113844 2026] [security2:error] [pid 822943:tid 823162] [client 20.171.55.167:4264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/log.php"] [unique_id "amuQmo8CCDUa19YrTu4YPwAAAWM"]
[Thu Jul 30 12:57:46.611099 2026] [security2:error] [pid 822943:tid 823111] [client 150.107.232.194:26553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQmo8CCDUa19YrTu4YhAAAATA"]
[Thu Jul 30 12:57:46.611285 2026] [security2:error] [pid 822943:tid 823111] [client 150.107.232.194:26553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQmo8CCDUa19YrTu4YhAAAATA"]
[Thu Jul 30 12:57:46.826608 2026] [security2:error] [pid 822943:tid 823190] [client 20.171.55.167:4701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "amuQmo8CCDUa19YrTu4YnAAAAX8"]
[Thu Jul 30 12:57:47.181022 2026] [security2:error] [pid 822943:tid 823183] [client 193.148.16.211:42212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuQm48CCDUa19YrTu4YsAAAAXg"]
[Thu Jul 30 12:57:47.181131 2026] [security2:error] [pid 822943:tid 823183] [client 193.148.16.211:42212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuQm48CCDUa19YrTu4YsAAAAXg"]
[Thu Jul 30 12:57:47.565166 2026] [security2:error] [pid 822943:tid 823195] [client 66.249.65.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YoQAAAYQ"]
[Thu Jul 30 12:57:47.580930 2026] [security2:error] [pid 822943:tid 823182] [client 20.171.55.167:4277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/themes/themes.php"] [unique_id "amuQm48CCDUa19YrTu4YvAAAAXc"]
[Thu Jul 30 12:57:48.210490 2026] [security2:error] [pid 822943:tid 823151] [client 184.75.208.246:36690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuQm48CCDUa19YrTu4YzAAAAVg"]
[Thu Jul 30 12:57:48.210628 2026] [security2:error] [pid 822943:tid 823151] [client 184.75.208.246:36690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuQm48CCDUa19YrTu4YzAAAAVg"]
[Thu Jul 30 12:57:48.327658 2026] [security2:error] [pid 822943:tid 823186] [client 20.171.55.167:4269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/radio.php"] [unique_id "amuQnI8CCDUa19YrTu4Y1QAAAXs"]
[Thu Jul 30 12:57:48.334230 2026] [security2:error] [pid 822943:tid 823148] [client 172.236.9.101:35843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YYAAAAVU"]
[Thu Jul 30 12:57:48.339016 2026] [security2:error] [pid 822943:tid 823147] [client 172.236.9.101:1053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YZwAAAVQ"]
[Thu Jul 30 12:57:48.350515 2026] [security2:error] [pid 822943:tid 823106] [client 172.236.9.101:55818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YXgAAASs"]
[Thu Jul 30 12:57:48.362909 2026] [security2:error] [pid 822943:tid 823103] [client 172.236.9.101:29652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YagAAASg"]
[Thu Jul 30 12:57:48.369422 2026] [security2:error] [pid 822943:tid 823142] [client 172.236.9.101:47072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YYgAAAU8"]
[Thu Jul 30 12:57:48.375867 2026] [security2:error] [pid 822943:tid 823166] [client 172.236.9.101:62986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YcAAAAWc"]
[Thu Jul 30 12:57:48.375896 2026] [security2:error] [pid 822943:tid 823181] [client 172.236.9.101:17625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YbQAAAXY"]
[Thu Jul 30 12:57:48.384929 2026] [security2:error] [pid 822943:tid 823133] [client 172.236.9.101:29767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YYQAAAUY"]
[Thu Jul 30 12:57:48.406621 2026] [security2:error] [pid 822943:tid 823149] [client 172.236.9.101:7295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YbAAAAVY"]
[Thu Jul 30 12:57:48.407411 2026] [security2:error] [pid 822943:tid 823138] [client 172.236.9.101:14659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YawAAAUs"]
[Thu Jul 30 12:57:48.408256 2026] [security2:error] [pid 822943:tid 823122] [client 172.236.9.101:11591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YbwAAATs"]
[Thu Jul 30 12:57:48.413374 2026] [security2:error] [pid 822943:tid 823073] [client 172.236.9.101:7098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YbgAAAQo"]
[Thu Jul 30 12:57:48.413919 2026] [security2:error] [pid 822943:tid 823128] [client 172.236.9.101:28240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YXQAAAUE"]
[Thu Jul 30 12:57:48.422896 2026] [security2:error] [pid 822943:tid 823169] [client 172.236.9.101:54226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YYwAAAWo"]
[Thu Jul 30 12:57:48.432796 2026] [security2:error] [pid 822943:tid 823110] [client 172.236.9.101:40712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YcQAAAS8"]
[Thu Jul 30 12:57:48.436136 2026] [security2:error] [pid 822943:tid 823079] [client 172.236.9.101:62204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YaQAAARA"]
[Thu Jul 30 12:57:48.491247 2026] [security2:error] [pid 822943:tid 823188] [client 172.236.9.101:30692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YXwAAAX0"]
[Thu Jul 30 12:57:48.493247 2026] [security2:error] [pid 822943:tid 823125] [client 172.236.9.101:15787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YaAAAAT4"]
[Thu Jul 30 12:57:48.496717 2026] [security2:error] [pid 822943:tid 823164] [client 172.236.9.101:61920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YcwAAAWU"]
[Thu Jul 30 12:57:48.541162 2026] [security2:error] [pid 822943:tid 823152] [client 172.236.9.101:7361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQmo8CCDUa19YrTu4YcgAAAVk"]
[Thu Jul 30 12:57:49.033208 2026] [security2:error] [pid 822943:tid 823159] [client 20.171.55.167:4244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-mail.php"] [unique_id "amuQnY8CCDUa19YrTu4Y7AAAAWA"]
[Thu Jul 30 12:57:49.769283 2026] [security2:error] [pid 822943:tid 823148] [client 20.171.55.167:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuQnY8CCDUa19YrTu4Y-gAAAVU"]
[Thu Jul 30 12:57:49.856617 2026] [security2:error] [pid 822943:tid 822980] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQnY8CCDUa19YrTu4ZBAABOyQ"]
[Thu Jul 30 12:57:49.856906 2026] [security2:error] [pid 822943:tid 823122] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQnY8CCDUa19YrTu4ZBAABOyQ"]
[Thu Jul 30 12:57:49.865698 2026] [core:notice] [pid 822943:tid 822979] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:57:50.499001 2026] [security2:error] [pid 822943:tid 823152] [client 20.171.55.167:4284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/admin.php"] [unique_id "amuQno8CCDUa19YrTu4ZGAAAAVk"]
[Thu Jul 30 12:57:50.573377 2026] [security2:error] [pid 822943:tid 823111] [client 213.152.161.240:52056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuQno8CCDUa19YrTu4ZHAAAATA"]
[Thu Jul 30 12:57:50.573472 2026] [security2:error] [pid 822943:tid 823111] [client 213.152.161.240:52056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuQno8CCDUa19YrTu4ZHAAAATA"]
[Thu Jul 30 12:57:51.140773 2026] [security2:error] [pid 822943:tid 823004] [remote 216.73.216.152:23908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQn48CCDUa19YrTu4ZJgABhjw"]
[Thu Jul 30 12:57:51.147806 2026] [security2:error] [pid 822943:tid 823115] [client 20.220.227.237:21639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuQn48CCDUa19YrTu4ZJwAAATQ"]
[Thu Jul 30 12:57:51.147878 2026] [security2:error] [pid 822943:tid 823115] [client 20.220.227.237:21639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuQn48CCDUa19YrTu4ZJwAAATQ"]
[Thu Jul 30 12:57:51.203873 2026] [security2:error] [pid 822943:tid 823194] [client 20.171.55.167:4680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuQn48CCDUa19YrTu4ZKQAAAYM"]
[Thu Jul 30 12:57:51.937795 2026] [security2:error] [pid 822943:tid 823083] [client 20.171.55.167:4327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-links-opml.php"] [unique_id "amuQn48CCDUa19YrTu4ZOwAAARQ"]
[Thu Jul 30 12:57:52.695889 2026] [security2:error] [pid 822943:tid 823183] [client 20.171.55.167:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/acme-challenge/radio.php"] [unique_id "amuQoI8CCDUa19YrTu4ZXQAAAXg"]
[Thu Jul 30 12:57:53.137025 2026] [security2:error] [pid 822943:tid 823134] [client 20.220.227.237:31802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuQoY8CCDUa19YrTu4ZZwAAAUc"]
[Thu Jul 30 12:57:53.137159 2026] [security2:error] [pid 822943:tid 823134] [client 20.220.227.237:31802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuQoY8CCDUa19YrTu4ZZwAAAUc"]
[Thu Jul 30 12:57:53.436101 2026] [security2:error] [pid 822943:tid 823179] [client 20.171.55.167:4251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/images/file.php"] [unique_id "amuQoY8CCDUa19YrTu4ZawAAAXQ"]
[Thu Jul 30 12:57:53.855818 2026] [security2:error] [pid 822943:tid 823099] [client 20.220.227.237:46256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/bootstrap.php"] [unique_id "amuQoY8CCDUa19YrTu4ZfwAAASQ"]
[Thu Jul 30 12:57:53.855990 2026] [security2:error] [pid 822943:tid 823099] [client 20.220.227.237:46256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/bootstrap.php"] [unique_id "amuQoY8CCDUa19YrTu4ZfwAAASQ"]
[Thu Jul 30 12:57:54.141147 2026] [security2:error] [pid 822943:tid 823122] [client 20.171.55.167:4246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/upgrade/function.php"] [unique_id "amuQoo8CCDUa19YrTu4ZkQAAATs"]
[Thu Jul 30 12:57:54.767240 2026] [core:error] [pid 822943:tid 823183] [client 74.7.241.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:57:54.767262 2026] [core:error] [pid 822943:tid 823183] [client 74.7.241.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:57:54.767374 2026] [security2:error] [pid 822943:tid 823183] [client 74.7.241.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.inj.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuQoo8CCDUa19YrTu4ZrgAAAXg"]
[Thu Jul 30 12:57:54.767917 2026] [security2:error] [pid 822943:tid 823198] [client 74.7.241.186:40494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.inj.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuQoo8CCDUa19YrTu4ZrAABhwg"]
[Thu Jul 30 12:57:54.846209 2026] [security2:error] [pid 822943:tid 823082] [client 20.171.55.167:4271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/user/themes.php"] [unique_id "amuQoo8CCDUa19YrTu4ZrwAAARM"]
[Thu Jul 30 12:57:55.356257 2026] [security2:error] [pid 822943:tid 823087] [client 18.209.7.80:37286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amuQoY8CCDUa19YrTu4ZeQAAARg"]
[Thu Jul 30 12:57:55.605373 2026] [security2:error] [pid 822943:tid 823179] [client 20.171.55.167:4275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/radio.php"] [unique_id "amuQo48CCDUa19YrTu4ZwwAAAXQ"]
[Thu Jul 30 12:57:55.711019 2026] [security2:error] [pid 822943:tid 822953] [remote 216.73.216.152:23908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQo48CCDUa19YrTu4ZxQABFAk"]
[Thu Jul 30 12:57:56.333623 2026] [security2:error] [pid 822943:tid 823149] [client 20.171.55.167:4304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/css/license.php"] [unique_id "amuQpI8CCDUa19YrTu4Z0gAAAVY"]
[Thu Jul 30 12:57:57.006081 2026] [security2:error] [pid 822943:tid 822966] [remote 198.38.94.87:45084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.zjp.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuQpI8CCDUa19YrTu4Z5AABVxY"]
[Thu Jul 30 12:57:57.033461 2026] [security2:error] [pid 822943:tid 822949] [remote 122.154.0.170:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.0.154.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.eow.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuQpY8CCDUa19YrTu4Z5QABLQU"]
[Thu Jul 30 12:57:57.041324 2026] [security2:error] [pid 822943:tid 823174] [client 20.171.55.167:4677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/pki-validation/wp-config.php"] [unique_id "amuQpY8CCDUa19YrTu4Z5gAAAW8"]
[Thu Jul 30 12:57:57.100794 2026] [security2:error] [pid 822943:tid 823118] [client 150.107.232.194:26636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQpY8CCDUa19YrTu4Z6gAAATc"]
[Thu Jul 30 12:57:57.100891 2026] [security2:error] [pid 822943:tid 823118] [client 150.107.232.194:26636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQpY8CCDUa19YrTu4Z6gAAATc"]
[Thu Jul 30 12:57:57.763023 2026] [security2:error] [pid 822943:tid 823141] [client 20.171.55.167:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/radio.php"] [unique_id "amuQpY8CCDUa19YrTu4aCQAAAU4"]
[Thu Jul 30 12:57:58.461787 2026] [security2:error] [pid 822943:tid 823132] [client 74.7.241.155:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.buyfluoxetine.store"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuQpo8CCDUa19YrTu4aGwAAAUU"]
[Thu Jul 30 12:57:58.827252 2026] [security2:error] [pid 822943:tid 823090] [client 20.171.55.167:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuQpo8CCDUa19YrTu4aIgAAARs"]
[Thu Jul 30 12:57:59.150714 2026] [core:error] [pid 822943:tid 823130] [client 74.7.175.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:57:59.150741 2026] [core:error] [pid 822943:tid 823130] [client 74.7.175.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:57:59.150861 2026] [security2:error] [pid 822943:tid 823130] [client 74.7.175.188:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.baytalhuboob.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuQp48CCDUa19YrTu4aMQAAAUM"]
[Thu Jul 30 12:57:59.151572 2026] [security2:error] [pid 822943:tid 823166] [client 74.7.175.188:36944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.baytalhuboob.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuQp48CCDUa19YrTu4aLAABZzA"]
[Thu Jul 30 12:57:59.230997 2026] [security2:error] [pid 822943:tid 823110] [client 74.7.175.143:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.germanyvisaapplicationcenterinislamabad.site"] [uri "/index.php"] [unique_id "amuQp48CCDUa19YrTu4aKwAAAS8"]
[Thu Jul 30 12:57:59.231754 2026] [security2:error] [pid 822943:tid 823192] [client 74.7.175.143:55102] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.germanyvisaapplicationcenterinislamabad.site"] [uri "/robots.txt"] [unique_id "amuQp48CCDUa19YrTu4aKQABgTk"]
[Thu Jul 30 12:57:59.532595 2026] [security2:error] [pid 822943:tid 823152] [client 20.171.55.167:4265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuQp48CCDUa19YrTu4aPAAAAVk"]
[Thu Jul 30 12:57:59.934999 2026] [core:notice] [pid 822943:tid 823079] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:00.201291 2026] [security2:error] [pid 822943:tid 823195] [client 74.7.230.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.chimnify.services"] [uri "/index.php"] [unique_id "amuQp48CCDUa19YrTu4aPQABhDw"]
[Thu Jul 30 12:58:00.201329 2026] [security2:error] [pid 822943:tid 823195] [client 74.7.230.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.chimnify.services"] [uri "/index.php"] [unique_id "amuQp48CCDUa19YrTu4aPQABhDw"]
[Thu Jul 30 12:58:00.262646 2026] [security2:error] [pid 822943:tid 823134] [client 20.171.55.167:4280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/wp-login.php"] [unique_id "amuQqI8CCDUa19YrTu4aTgAAAUc"]
[Thu Jul 30 12:58:00.297866 2026] [security2:error] [pid 822943:tid 823144] [client 20.220.227.237:10870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-blog-header.php"] [unique_id "amuQqI8CCDUa19YrTu4aTwAAAVE"]
[Thu Jul 30 12:58:00.297963 2026] [security2:error] [pid 822943:tid 823144] [client 20.220.227.237:10870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-blog-header.php"] [unique_id "amuQqI8CCDUa19YrTu4aTwAAAVE"]
[Thu Jul 30 12:58:00.599112 2026] [security2:error] [pid 822943:tid 823007] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQqI8CCDUa19YrTu4aWQABKD8"]
[Thu Jul 30 12:58:00.599257 2026] [security2:error] [pid 822943:tid 823103] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQqI8CCDUa19YrTu4aWQABKD8"]
[Thu Jul 30 12:58:01.021358 2026] [security2:error] [pid 822943:tid 823138] [client 20.171.55.167:4250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/wp-load.php"] [unique_id "amuQqY8CCDUa19YrTu4aaQAAAUs"]
[Thu Jul 30 12:58:01.370865 2026] [security2:error] [pid 822943:tid 823032] [remote 216.73.216.152:35148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuQqY8CCDUa19YrTu4acQABSlg"]
[Thu Jul 30 12:58:01.736874 2026] [security2:error] [pid 822943:tid 823156] [client 20.171.55.167:4681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/file.php"] [unique_id "amuQqY8CCDUa19YrTu4agAAAAV0"]
[Thu Jul 30 12:58:02.470193 2026] [security2:error] [pid 822943:tid 823141] [client 20.171.55.167:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/dropdown.php"] [unique_id "amuQqo8CCDUa19YrTu4akwAAAU4"]
[Thu Jul 30 12:58:03.178560 2026] [security2:error] [pid 822943:tid 823103] [client 20.171.55.167:4297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/plugins/dropdown.php"] [unique_id "amuQq48CCDUa19YrTu4aqwAAASg"]
[Thu Jul 30 12:58:03.907938 2026] [security2:error] [pid 822943:tid 823102] [client 20.171.55.167:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuQq48CCDUa19YrTu4avgAAASc"]
[Thu Jul 30 12:58:04.100702 2026] [core:notice] [pid 822943:tid 823075] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:04.656226 2026] [security2:error] [pid 822943:tid 823097] [client 20.171.55.167:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-signup.php"] [unique_id "amuQrI8CCDUa19YrTu4a0wAAASI"]
[Thu Jul 30 12:58:05.372781 2026] [security2:error] [pid 822943:tid 823200] [client 20.171.55.167:4720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/images/css.php"] [unique_id "amuQrY8CCDUa19YrTu4a6gAAAYk"]
[Thu Jul 30 12:58:05.716536 2026] [security2:error] [pid 822943:tid 823030] [remote 216.73.216.152:35148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQrY8CCDUa19YrTu4a7wABYlY"]
[Thu Jul 30 12:58:05.738232 2026] [security2:error] [pid 822943:tid 823119] [client 193.148.16.211:41364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuQrY8CCDUa19YrTu4a8wAAATg"]
[Thu Jul 30 12:58:05.738339 2026] [security2:error] [pid 822943:tid 823119] [client 193.148.16.211:41364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuQrY8CCDUa19YrTu4a8wAAATg"]
[Thu Jul 30 12:58:06.104575 2026] [security2:error] [pid 822943:tid 823172] [client 20.171.55.167:4286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/chosen.php"] [unique_id "amuQro8CCDUa19YrTu4a_gAAAW0"]
[Thu Jul 30 12:58:06.810084 2026] [security2:error] [pid 822943:tid 823187] [client 20.171.55.167:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/cong.php"] [unique_id "amuQro8CCDUa19YrTu4bGwAAAXw"]
[Thu Jul 30 12:58:07.111510 2026] [security2:error] [pid 822943:tid 823164] [client 172.236.9.101:1377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bCAAAAWU"]
[Thu Jul 30 12:58:07.135674 2026] [security2:error] [pid 822943:tid 823196] [client 172.236.9.101:40928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bCQAAAYU"]
[Thu Jul 30 12:58:07.152483 2026] [security2:error] [pid 822943:tid 823096] [client 172.236.9.101:16814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bDQAAASE"]
[Thu Jul 30 12:58:07.152484 2026] [security2:error] [pid 822943:tid 823182] [client 172.236.9.101:22906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bCwAAAXc"]
[Thu Jul 30 12:58:07.162913 2026] [security2:error] [pid 822943:tid 823150] [client 172.236.9.101:2360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bCgAAAVc"]
[Thu Jul 30 12:58:07.171415 2026] [security2:error] [pid 822943:tid 823136] [client 57.141.0.18:61548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bFwABSQM"], referer: https://igetvape-australia.com/product/iget-bar-pro-raspberry-grape/?add-to-cart=103
[Thu Jul 30 12:58:07.190616 2026] [security2:error] [pid 822943:tid 823084] [client 172.236.9.101:60251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bDwAAARU"]
[Thu Jul 30 12:58:07.190914 2026] [security2:error] [pid 822943:tid 823075] [client 172.236.9.101:50023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bEAAAAQw"]
[Thu Jul 30 12:58:07.193551 2026] [security2:error] [pid 822943:tid 823074] [client 172.236.9.101:4947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bDgAAAQs"]
[Thu Jul 30 12:58:07.415026 2026] [security2:error] [pid 822943:tid 823094] [client 40.77.177.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuQro8CCDUa19YrTu4bBgAAAR8"]
[Thu Jul 30 12:58:07.519404 2026] [security2:error] [pid 822943:tid 823181] [client 20.171.55.167:4224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/mah.php"] [unique_id "amuQr48CCDUa19YrTu4bOAAAAXY"]
[Thu Jul 30 12:58:07.639463 2026] [security2:error] [pid 822943:tid 823093] [client 150.107.232.194:27474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQr48CCDUa19YrTu4bOwAAAR4"]
[Thu Jul 30 12:58:07.639640 2026] [security2:error] [pid 822943:tid 823093] [client 150.107.232.194:27474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQr48CCDUa19YrTu4bOwAAAR4"]
[Thu Jul 30 12:58:08.241184 2026] [security2:error] [pid 822943:tid 823123] [client 20.171.55.167:4283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuQsI8CCDUa19YrTu4bSwAAATw"]
[Thu Jul 30 12:58:08.308828 2026] [security2:error] [pid 822943:tid 823147] [client 172.236.9.101:63372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bLgAAAVQ"]
[Thu Jul 30 12:58:08.319563 2026] [security2:error] [pid 822943:tid 823134] [client 172.236.9.101:50374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bKwAAAUc"]
[Thu Jul 30 12:58:08.320557 2026] [security2:error] [pid 822943:tid 823141] [client 172.236.9.101:56249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bLQAAAU4"]
[Thu Jul 30 12:58:08.324931 2026] [security2:error] [pid 822943:tid 823190] [client 172.236.9.101:18163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bKQAAAX8"]
[Thu Jul 30 12:58:08.327410 2026] [security2:error] [pid 822943:tid 823168] [client 172.236.9.101:20219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bLwAAAWk"]
[Thu Jul 30 12:58:08.346404 2026] [security2:error] [pid 822943:tid 823194] [client 172.236.9.101:30987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bKgAAAYM"]
[Thu Jul 30 12:58:08.362679 2026] [security2:error] [pid 822943:tid 823126] [client 172.236.9.101:63702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bMgAAAT8"]
[Thu Jul 30 12:58:08.369127 2026] [security2:error] [pid 822943:tid 823087] [client 172.236.9.101:28760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bMwAAARg"]
[Thu Jul 30 12:58:08.440461 2026] [security2:error] [pid 822943:tid 823165] [client 172.236.9.101:59753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bNwAAAWY"]
[Thu Jul 30 12:58:08.459204 2026] [security2:error] [pid 822943:tid 823120] [client 172.236.9.101:61026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bNgAAATk"]
[Thu Jul 30 12:58:08.472114 2026] [security2:error] [pid 822943:tid 823080] [client 172.236.9.101:27292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bNAAAARE"]
[Thu Jul 30 12:58:08.475679 2026] [security2:error] [pid 822943:tid 823104] [client 172.236.9.101:20611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQr48CCDUa19YrTu4bNQAAASk"]
[Thu Jul 30 12:58:08.882181 2026] [security2:error] [pid 822943:tid 823170] [client 3.149.57.90:13384] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuQsI8CCDUa19YrTu4bVwAAAWs"], referer: https://globalmarks.pk/
[Thu Jul 30 12:58:08.958441 2026] [security2:error] [pid 822943:tid 823136] [client 20.171.55.167:4335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ova-tools.php"] [unique_id "amuQsI8CCDUa19YrTu4bXgAAAUk"]
[Thu Jul 30 12:58:09.276007 2026] [core:notice] [pid 822943:tid 822992] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:09.359461 2026] [fcgid:warn] [pid 822943:tid 823156] (70014)End of file found: [client 135.237.126.37:38776] mod_fcgid: can't get data from http client
[Thu Jul 30 12:58:09.675426 2026] [security2:error] [pid 822943:tid 823113] [client 20.171.55.167:4292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuQsY8CCDUa19YrTu4bcgAAATI"]
[Thu Jul 30 12:58:09.896522 2026] [security2:error] [pid 822943:tid 823093] [client 209.35.163.56:28907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuQsY8CCDUa19YrTu4bYgABHjU"]
[Thu Jul 30 12:58:10.087173 2026] [core:notice] [pid 822943:tid 822974] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:10.400142 2026] [security2:error] [pid 822943:tid 823144] [client 20.171.55.167:4690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuQso8CCDUa19YrTu4bgwAAAVE"]
[Thu Jul 30 12:58:10.491990 2026] [fcgid:warn] [pid 822943:tid 823090] (70014)End of file found: [client 66.132.195.110:34716] mod_fcgid: can't get data from http client
[Thu Jul 30 12:58:11.109965 2026] [security2:error] [pid 822943:tid 823110] [client 20.171.55.167:4289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuQs48CCDUa19YrTu4blwAAAS8"]
[Thu Jul 30 12:58:11.334061 2026] [security2:error] [pid 822943:tid 823028] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQs48CCDUa19YrTu4bnAABFlQ"]
[Thu Jul 30 12:58:11.334229 2026] [security2:error] [pid 822943:tid 823085] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQs48CCDUa19YrTu4bnAABFlQ"]
[Thu Jul 30 12:58:11.366142 2026] [security2:error] [pid 822943:tid 823017] [remote 216.73.216.152:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQs48CCDUa19YrTu4bnQABJ0k"]
[Thu Jul 30 12:58:11.841702 2026] [security2:error] [pid 822943:tid 823093] [client 20.171.55.167:4687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuQs48CCDUa19YrTu4bqgAAAR4"]
[Thu Jul 30 12:58:12.548895 2026] [security2:error] [pid 822943:tid 823150] [client 20.171.55.167:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuQtI8CCDUa19YrTu4bvQAAAVc"]
[Thu Jul 30 12:58:13.271347 2026] [security2:error] [pid 822943:tid 823149] [client 20.171.55.167:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/license.php"] [unique_id "amuQtY8CCDUa19YrTu4bzAAAAVY"]
[Thu Jul 30 12:58:13.991028 2026] [security2:error] [pid 822943:tid 823146] [client 20.171.55.167:4261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/about.php"] [unique_id "amuQtY8CCDUa19YrTu4b3AAAAVM"]
[Thu Jul 30 12:58:14.109219 2026] [security2:error] [pid 822943:tid 823102] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuQtY8CCDUa19YrTu4b2wAAASc"]
[Thu Jul 30 12:58:14.775445 2026] [security2:error] [pid 822943:tid 823093] [client 20.171.55.167:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/about.php"] [unique_id "amuQto8CCDUa19YrTu4b6AAAAR4"]
[Thu Jul 30 12:58:14.906175 2026] [security2:error] [pid 822943:tid 823050] [remote 52.167.144.204:34194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/formation-des-formateurs-des-caa-et-sepj/index.php"] [unique_id "amuQto8CCDUa19YrTu4b7wABWWo"]
[Thu Jul 30 12:58:15.509840 2026] [security2:error] [pid 822943:tid 823078] [client 20.171.55.167:4256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuQt48CCDUa19YrTu4cDAAAAQ8"]
[Thu Jul 30 12:58:15.727653 2026] [security2:error] [pid 822943:tid 822956] [remote 216.73.216.152:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQt48CCDUa19YrTu4cEgABEgw"]
[Thu Jul 30 12:58:16.135906 2026] [security2:error] [pid 822943:tid 823159] [client 74.7.228.34:46594] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bookario.com"] [uri "/cgi-sys/404.html"] [unique_id "amuQuI8CCDUa19YrTu4cHQABYAE"]
[Thu Jul 30 12:58:16.265588 2026] [security2:error] [pid 822943:tid 823115] [client 20.171.55.167:4682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuQuI8CCDUa19YrTu4cHgAAATQ"]
[Thu Jul 30 12:58:16.352949 2026] [core:error] [pid 822943:tid 823066] [remote 74.7.244.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:58:16.352993 2026] [core:error] [pid 822943:tid 823066] [remote 74.7.244.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:58:16.353353 2026] [security2:error] [pid 822943:tid 823186] [client 74.7.244.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.professionalfurnituremovingcompanyllc.store"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuQuI8CCDUa19YrTu4cHwABe3o"]
[Thu Jul 30 12:58:16.974761 2026] [security2:error] [pid 822943:tid 823079] [client 20.171.55.167:4330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/img/about.php"] [unique_id "amuQuI8CCDUa19YrTu4cKwAAARA"]
[Thu Jul 30 12:58:17.102734 2026] [security2:error] [pid 822943:tid 823137] [client 172.237.109.114:27562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env"] [unique_id "amuQuY8CCDUa19YrTu4cMwAAAUo"]
[Thu Jul 30 12:58:17.124550 2026] [security2:error] [pid 822943:tid 823140] [client 172.237.109.114:34131] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.bak"] [unique_id "amuQuY8CCDUa19YrTu4cOQAAAU0"]
[Thu Jul 30 12:58:17.652109 2026] [security2:error] [pid 822943:tid 823124] [client 172.237.109.114:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuY8CCDUa19YrTu4cMgAAAT0"]
[Thu Jul 30 12:58:17.722762 2026] [security2:error] [pid 822943:tid 823077] [client 172.237.109.114:15126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuY8CCDUa19YrTu4cNAAAAQ4"]
[Thu Jul 30 12:58:17.726702 2026] [security2:error] [pid 822943:tid 823147] [client 20.171.55.167:4270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuQuY8CCDUa19YrTu4cTwAAAVQ"]
[Thu Jul 30 12:58:17.738011 2026] [security2:error] [pid 822943:tid 823173] [client 172.237.109.114:45312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuY8CCDUa19YrTu4cNwAAAW4"]
[Thu Jul 30 12:58:17.745591 2026] [security2:error] [pid 822943:tid 823086] [client 172.237.109.114:36422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuY8CCDUa19YrTu4cNQAAARc"]
[Thu Jul 30 12:58:17.759609 2026] [security2:error] [pid 822943:tid 823174] [client 172.237.109.114:29842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuY8CCDUa19YrTu4cNgAAAW8"]
[Thu Jul 30 12:58:17.767770 2026] [security2:error] [pid 822943:tid 823155] [client 172.237.109.114:47733] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuY8CCDUa19YrTu4cOAAAAVw"]
[Thu Jul 30 12:58:18.077945 2026] [security2:error] [pid 822943:tid 823105] [client 172.237.109.114:56402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.old"] [unique_id "amuQuo8CCDUa19YrTu4cVgAAASo"]
[Thu Jul 30 12:58:18.094666 2026] [security2:error] [pid 822943:tid 823132] [client 172.237.109.114:20103] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.env.backup"] [unique_id "amuQuo8CCDUa19YrTu4cWwAAAUU"]
[Thu Jul 30 12:58:18.099157 2026] [security2:error] [pid 822943:tid 823191] [client 150.107.232.194:26647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQuo8CCDUa19YrTu4cXAAAAYA"]
[Thu Jul 30 12:58:18.099266 2026] [security2:error] [pid 822943:tid 823191] [client 150.107.232.194:26647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQuo8CCDUa19YrTu4cXAAAAYA"]
[Thu Jul 30 12:58:18.439821 2026] [security2:error] [pid 822943:tid 823181] [client 20.171.55.167:4673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuQuo8CCDUa19YrTu4cZgAAAXY"]
[Thu Jul 30 12:58:18.692147 2026] [security2:error] [pid 822943:tid 823179] [client 172.237.109.114:60810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cVwAAAXQ"]
[Thu Jul 30 12:58:18.698205 2026] [security2:error] [pid 822943:tid 823150] [client 172.237.109.114:30007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cWQAAAVc"]
[Thu Jul 30 12:58:18.700634 2026] [security2:error] [pid 822943:tid 823115] [client 172.237.109.114:6928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cWgAAATQ"]
[Thu Jul 30 12:58:18.703051 2026] [security2:error] [pid 822943:tid 823084] [client 172.237.109.114:56296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cXQAAARU"]
[Thu Jul 30 12:58:18.705051 2026] [security2:error] [pid 822943:tid 823165] [client 172.237.109.114:56084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cWAAAAWY"]
[Thu Jul 30 12:58:18.747396 2026] [security2:error] [pid 822943:tid 823200] [client 172.237.109.114:60347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cXwAAAYk"]
[Thu Jul 30 12:58:18.759713 2026] [security2:error] [pid 822943:tid 823106] [client 172.237.109.114:2614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cYwAAASs"]
[Thu Jul 30 12:58:18.782398 2026] [security2:error] [pid 822943:tid 823127] [client 172.237.109.114:40422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cXgAAAUA"]
[Thu Jul 30 12:58:18.791900 2026] [security2:error] [pid 822943:tid 823195] [client 172.237.109.114:42904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cYQAAAYQ"]
[Thu Jul 30 12:58:18.807506 2026] [security2:error] [pid 822943:tid 823164] [client 172.237.109.114:56485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQuo8CCDUa19YrTu4cYAAAAWU"]
[Thu Jul 30 12:58:19.204142 2026] [security2:error] [pid 822943:tid 823118] [client 20.171.55.167:4276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuQu48CCDUa19YrTu4cegAAATc"]
[Thu Jul 30 12:58:19.716072 2026] [security2:error] [pid 822943:tid 823133] [client 216.73.217.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "j-nintei.com"] [uri "/index.php"] [unique_id "amuQu48CCDUa19YrTu4cggABRi8"]
[Thu Jul 30 12:58:19.923257 2026] [security2:error] [pid 822943:tid 823177] [client 20.171.55.167:4351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuQu48CCDUa19YrTu4cjAAAAXI"]
[Thu Jul 30 12:58:19.923799 2026] [security2:error] [pid 822943:tid 823108] [client 216.73.217.60:53639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuQu48CCDUa19YrTu4ciwABLSg"]
[Thu Jul 30 12:58:20.676115 2026] [security2:error] [pid 822943:tid 823171] [client 20.171.55.167:4311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuQvI8CCDUa19YrTu4clwAAAWw"]
[Thu Jul 30 12:58:21.323871 2026] [security2:error] [pid 822943:tid 822990] [remote 57.141.0.5:57806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuQvY8CCDUa19YrTu4crAABFy4"]
[Thu Jul 30 12:58:21.410576 2026] [security2:error] [pid 822943:tid 823089] [client 20.171.55.167:4253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuQvY8CCDUa19YrTu4csgAAARo"]
[Thu Jul 30 12:58:22.156063 2026] [security2:error] [pid 822943:tid 822963] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQvo8CCDUa19YrTu4cvwABKxM"]
[Thu Jul 30 12:58:22.156275 2026] [security2:error] [pid 822943:tid 823106] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQvo8CCDUa19YrTu4cvwABKxM"]
[Thu Jul 30 12:58:22.505211 2026] [security2:error] [pid 822943:tid 823125] [client 20.171.55.167:4711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuQvo8CCDUa19YrTu4cyQAAAT4"]
[Thu Jul 30 12:58:23.028131 2026] [core:notice] [pid 822943:tid 823150] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:23.255910 2026] [security2:error] [pid 822943:tid 823119] [client 20.171.55.167:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuQv48CCDUa19YrTu4c1wAAATg"]
[Thu Jul 30 12:58:23.992364 2026] [security2:error] [pid 822943:tid 823073] [client 20.171.55.167:4309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuQv48CCDUa19YrTu4c7QAAAQo"]
[Thu Jul 30 12:58:24.706215 2026] [security2:error] [pid 822943:tid 823160] [client 20.171.55.167:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuQwI8CCDUa19YrTu4dAQAAAWE"]
[Thu Jul 30 12:58:24.801167 2026] [security2:error] [pid 822943:tid 823106] [client 157.230.55.89:53368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuQwI8CCDUa19YrTu4c9QAAASs"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:58:25.431593 2026] [security2:error] [pid 822943:tid 823099] [client 20.171.55.167:4342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuQwY8CCDUa19YrTu4dFQAAASQ"]
[Thu Jul 30 12:58:25.751807 2026] [security2:error] [pid 822943:tid 823002] [remote 216.73.216.152:31937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQwY8CCDUa19YrTu4dHgABPzo"]
[Thu Jul 30 12:58:25.887655 2026] [security2:error] [pid 822943:tid 823116] [client 172.236.9.101:8574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQwY8CCDUa19YrTu4dEAAAATU"]
[Thu Jul 30 12:58:25.959487 2026] [security2:error] [pid 822943:tid 823108] [client 172.236.9.101:59004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQwY8CCDUa19YrTu4dEQAAAS0"]
[Thu Jul 30 12:58:26.021766 2026] [security2:error] [pid 822943:tid 823163] [client 172.236.9.101:57762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQwY8CCDUa19YrTu4dEwAAAWQ"]
[Thu Jul 30 12:58:26.121551 2026] [security2:error] [pid 822943:tid 823087] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQwY8CCDUa19YrTu4dFwABGCc"]
[Thu Jul 30 12:58:26.174934 2026] [security2:error] [pid 822943:tid 823141] [client 20.171.55.167:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuQwo8CCDUa19YrTu4dKQAAAU4"]
[Thu Jul 30 12:58:26.471819 2026] [core:notice] [pid 822943:tid 823154] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:26.914666 2026] [security2:error] [pid 822943:tid 823174] [client 172.236.9.101:48795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQwo8CCDUa19YrTu4dKwAAAW8"]
[Thu Jul 30 12:58:26.920701 2026] [security2:error] [pid 822943:tid 823132] [client 20.171.55.167:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuQwo8CCDUa19YrTu4dPAAAAUU"]
[Thu Jul 30 12:58:26.974300 2026] [security2:error] [pid 822943:tid 823196] [client 172.236.9.101:23115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQwo8CCDUa19YrTu4dLAAAAYU"]
[Thu Jul 30 12:58:27.017515 2026] [security2:error] [pid 822943:tid 823176] [client 172.236.9.101:57268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQwo8CCDUa19YrTu4dLgAAAXE"]
[Thu Jul 30 12:58:27.037637 2026] [security2:error] [pid 822943:tid 823189] [client 172.236.9.101:33463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQwo8CCDUa19YrTu4dLwAAAX4"]
[Thu Jul 30 12:58:27.040960 2026] [security2:error] [pid 822943:tid 823157] [client 172.236.9.101:52146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQwo8CCDUa19YrTu4dLQAAAV4"]
[Thu Jul 30 12:58:27.213717 2026] [security2:error] [pid 822943:tid 823199] [client 157.230.55.89:53380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuQwo8CCDUa19YrTu4dOwAAAYg"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:58:27.287367 2026] [core:error] [pid 822943:tid 823123] [client 74.7.175.191:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:58:27.287386 2026] [core:error] [pid 822943:tid 823123] [client 74.7.175.191:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:58:27.287507 2026] [security2:error] [pid 822943:tid 823123] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.xyu.gpl.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuQw48CCDUa19YrTu4dSQAAATw"]
[Thu Jul 30 12:58:27.288056 2026] [security2:error] [pid 822943:tid 823149] [client 74.7.175.191:44644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.xyu.gpl.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuQw48CCDUa19YrTu4dRwABVlk"]
[Thu Jul 30 12:58:27.300155 2026] [security2:error] [pid 822943:tid 823093] [client 74.7.241.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.mahyarjewelry.co"] [uri "/index.php"] [unique_id "amuQwI8CCDUa19YrTu4dBAAAAR4"]
[Thu Jul 30 12:58:27.300859 2026] [security2:error] [pid 822943:tid 823107] [client 74.7.241.133:40730] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.mahyarjewelry.co"] [uri "/robots.txt"] [unique_id "amuQwI8CCDUa19YrTu4dAgABLFg"]
[Thu Jul 30 12:58:27.500929 2026] [security2:error] [pid 822943:tid 823057] [remote 57.141.0.17:47088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuQw48CCDUa19YrTu4dVAABanE"]
[Thu Jul 30 12:58:27.664116 2026] [security2:error] [pid 822943:tid 823082] [client 20.171.55.167:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/images/about.php"] [unique_id "amuQw48CCDUa19YrTu4dXAAAARM"]
[Thu Jul 30 12:58:27.909525 2026] [security2:error] [pid 822943:tid 823164] [client 172.236.9.101:54309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQw48CCDUa19YrTu4dTAAAAWU"]
[Thu Jul 30 12:58:27.954649 2026] [security2:error] [pid 822943:tid 823112] [client 172.236.9.101:13818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQw48CCDUa19YrTu4dSgAAATE"]
[Thu Jul 30 12:58:27.976210 2026] [security2:error] [pid 822943:tid 823171] [client 172.236.9.101:26408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQw48CCDUa19YrTu4dSwAAAWw"]
[Thu Jul 30 12:58:28.001085 2026] [security2:error] [pid 822943:tid 823146] [client 172.236.9.101:20623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQw48CCDUa19YrTu4dTgAAAVM"]
[Thu Jul 30 12:58:28.011844 2026] [security2:error] [pid 822943:tid 823192] [client 172.236.9.101:14272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQw48CCDUa19YrTu4dTwAAAYE"]
[Thu Jul 30 12:58:28.021949 2026] [security2:error] [pid 822943:tid 823078] [client 20.220.227.237:33340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/edit.php"] [unique_id "amuQxI8CCDUa19YrTu4dYQAAAQ8"]
[Thu Jul 30 12:58:28.022075 2026] [security2:error] [pid 822943:tid 823078] [client 20.220.227.237:33340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/edit.php"] [unique_id "amuQxI8CCDUa19YrTu4dYQAAAQ8"]
[Thu Jul 30 12:58:28.062905 2026] [security2:error] [pid 822943:tid 823136] [client 40.77.167.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQw48CCDUa19YrTu4dTQABSV0"]
[Thu Jul 30 12:58:28.079329 2026] [security2:error] [pid 822943:tid 823186] [client 172.236.9.101:35930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQw48CCDUa19YrTu4dUQAAAXs"]
[Thu Jul 30 12:58:28.091240 2026] [security2:error] [pid 822943:tid 823200] [client 172.236.9.101:46485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQw48CCDUa19YrTu4dUgAAAYk"]
[Thu Jul 30 12:58:28.100860 2026] [security2:error] [pid 822943:tid 823116] [client 172.236.9.101:21026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQw48CCDUa19YrTu4dUwAAATU"]
[Thu Jul 30 12:58:28.400387 2026] [security2:error] [pid 822943:tid 823144] [client 20.171.55.167:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuQxI8CCDUa19YrTu4ddAAAAVE"]
[Thu Jul 30 12:58:28.563268 2026] [security2:error] [pid 822943:tid 823179] [client 150.107.232.194:27233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQxI8CCDUa19YrTu4ddQAAAXQ"]
[Thu Jul 30 12:58:28.563402 2026] [security2:error] [pid 822943:tid 823179] [client 150.107.232.194:27233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQxI8CCDUa19YrTu4ddQAAAXQ"]
[Thu Jul 30 12:58:28.896052 2026] [security2:error] [pid 822943:tid 823185] [client 172.236.9.101:16581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQxI8CCDUa19YrTu4dcQAAAXo"]
[Thu Jul 30 12:58:28.913110 2026] [security2:error] [pid 822943:tid 823111] [client 172.236.9.101:10969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQxI8CCDUa19YrTu4dcgAAATA"]
[Thu Jul 30 12:58:28.927989 2026] [security2:error] [pid 822943:tid 823142] [client 172.236.9.101:20518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQxI8CCDUa19YrTu4dcwAAAU8"]
[Thu Jul 30 12:58:28.940854 2026] [security2:error] [pid 822943:tid 823157] [client 172.236.9.101:39749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQxI8CCDUa19YrTu4dcAAAAV4"]
[Thu Jul 30 12:58:29.116641 2026] [security2:error] [pid 822943:tid 823188] [client 20.171.55.167:4239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuQxY8CCDUa19YrTu4dgQAAAX0"]
[Thu Jul 30 12:58:29.656957 2026] [security2:error] [pid 822943:tid 823145] [client 172.213.17.107:17778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuQxY8CCDUa19YrTu4djAAAAVI"]
[Thu Jul 30 12:58:29.657087 2026] [security2:error] [pid 822943:tid 823145] [client 172.213.17.107:17778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuQxY8CCDUa19YrTu4djAAAAVI"]
[Thu Jul 30 12:58:29.862277 2026] [security2:error] [pid 822943:tid 823075] [client 20.171.55.167:4698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/about.php"] [unique_id "amuQxY8CCDUa19YrTu4dlwAAAQw"]
[Thu Jul 30 12:58:30.413008 2026] [security2:error] [pid 822943:tid 823142] [client 172.213.17.107:21711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuQxo8CCDUa19YrTu4dqAAAAU8"]
[Thu Jul 30 12:58:30.413117 2026] [security2:error] [pid 822943:tid 823142] [client 172.213.17.107:21711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuQxo8CCDUa19YrTu4dqAAAAU8"]
[Thu Jul 30 12:58:30.573424 2026] [security2:error] [pid 822943:tid 823125] [client 20.171.55.167:4293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/about.php"] [unique_id "amuQxo8CCDUa19YrTu4dqQAAAT4"]
[Thu Jul 30 12:58:30.607507 2026] [core:notice] [pid 822943:tid 823177] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:31.321651 2026] [security2:error] [pid 822943:tid 823129] [client 20.171.55.167:4227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuQx48CCDUa19YrTu4duQAAAUI"]
[Thu Jul 30 12:58:31.457007 2026] [security2:error] [pid 822943:tid 822959] [remote 216.73.216.152:43541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQx48CCDUa19YrTu4dwwABRQ8"]
[Thu Jul 30 12:58:31.457424 2026] [security2:error] [pid 822943:tid 823166] [client 20.220.227.237:40571] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin"] [unique_id "amuQx48CCDUa19YrTu4dxAAAAWc"]
[Thu Jul 30 12:58:31.457499 2026] [security2:error] [pid 822943:tid 823166] [client 20.220.227.237:40571] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-bin"] [unique_id "amuQx48CCDUa19YrTu4dxAAAAWc"]
[Thu Jul 30 12:58:31.505880 2026] [core:notice] [pid 822943:tid 823184] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:31.979431 2026] [core:notice] [pid 822943:tid 823144] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:32.024624 2026] [security2:error] [pid 822943:tid 823168] [client 20.171.55.167:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuQyI8CCDUa19YrTu4d0wAAAWk"]
[Thu Jul 30 12:58:32.251580 2026] [security2:error] [pid 822943:tid 823140] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQx48CCDUa19YrTu4dyAAAAU0"]
[Thu Jul 30 12:58:32.351263 2026] [security2:error] [pid 822943:tid 823090] [client 202.91.40.150:57948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuQyI8CCDUa19YrTu4d1AAAARs"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 12:58:32.485569 2026] [core:notice] [pid 822943:tid 823103] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:32.727159 2026] [security2:error] [pid 822943:tid 823157] [client 20.171.55.167:4332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuQyI8CCDUa19YrTu4d5QAAAV4"]
[Thu Jul 30 12:58:32.859569 2026] [security2:error] [pid 822943:tid 823095] [client 119.73.97.132:31163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuQyI8CCDUa19YrTu4d5AABIBo"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 12:58:32.865904 2026] [security2:error] [pid 822943:tid 823171] [client 20.220.227.237:50422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/mah.php"] [unique_id "amuQyI8CCDUa19YrTu4d6AAAAWw"]
[Thu Jul 30 12:58:32.866010 2026] [security2:error] [pid 822943:tid 823171] [client 20.220.227.237:50422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/mah.php"] [unique_id "amuQyI8CCDUa19YrTu4d6AAAAWw"]
[Thu Jul 30 12:58:32.894263 2026] [core:notice] [pid 822943:tid 823164] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:33.015401 2026] [security2:error] [pid 822943:tid 822947] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQyY8CCDUa19YrTu4d9gABDwM"]
[Thu Jul 30 12:58:33.015653 2026] [security2:error] [pid 822943:tid 823078] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQyY8CCDUa19YrTu4d9gABDwM"]
[Thu Jul 30 12:58:33.297970 2026] [core:notice] [pid 822943:tid 823145] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:33.314746 2026] [security2:error] [pid 822943:tid 823166] [client 172.213.17.107:17361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuQyY8CCDUa19YrTu4d_AAAAWc"]
[Thu Jul 30 12:58:33.314838 2026] [security2:error] [pid 822943:tid 823166] [client 172.213.17.107:17361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuQyY8CCDUa19YrTu4d_AAAAWc"]
[Thu Jul 30 12:58:33.479186 2026] [security2:error] [pid 822943:tid 823160] [client 20.171.55.167:4262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuQyY8CCDUa19YrTu4eBQAAAWE"]
[Thu Jul 30 12:58:33.701155 2026] [core:notice] [pid 822943:tid 823149] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:33.812950 2026] [security2:error] [pid 822943:tid 823107] [client 20.220.227.237:1772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/archive.php"] [unique_id "amuQyY8CCDUa19YrTu4eDQAAASw"]
[Thu Jul 30 12:58:33.813084 2026] [security2:error] [pid 822943:tid 823107] [client 20.220.227.237:1772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/archive.php"] [unique_id "amuQyY8CCDUa19YrTu4eDQAAASw"]
[Thu Jul 30 12:58:33.996197 2026] [security2:error] [pid 822943:tid 823165] [client 119.73.97.132:31163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuQyY8CCDUa19YrTu4eCwABZiI"]
[Thu Jul 30 12:58:34.157430 2026] [core:notice] [pid 822943:tid 823090] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:34.194554 2026] [security2:error] [pid 822943:tid 823085] [client 20.171.55.167:4686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuQyo8CCDUa19YrTu4eGAAAARY"]
[Thu Jul 30 12:58:34.597163 2026] [core:notice] [pid 822943:tid 823186] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:34.903954 2026] [security2:error] [pid 822943:tid 823116] [client 20.171.55.167:4699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuQyo8CCDUa19YrTu4eLAAAATU"]
[Thu Jul 30 12:58:34.946836 2026] [security2:error] [pid 822943:tid 822988] [remote 57.141.0.50:58736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amuQyo8CCDUa19YrTu4eLQABRiw"]
[Thu Jul 30 12:58:35.049446 2026] [core:notice] [pid 822943:tid 823200] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:35.603826 2026] [security2:error] [pid 822943:tid 823179] [client 20.171.55.167:4678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuQy48CCDUa19YrTu4ePwAAAXQ"]
[Thu Jul 30 12:58:35.760549 2026] [security2:error] [pid 822943:tid 822994] [remote 216.73.216.152:43541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQy48CCDUa19YrTu4eQwABZDI"]
[Thu Jul 30 12:58:36.364362 2026] [security2:error] [pid 822943:tid 823178] [client 20.171.55.167:4343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cloud.php"] [unique_id "amuQzI8CCDUa19YrTu4eTgAAAXM"]
[Thu Jul 30 12:58:36.939352 2026] [security2:error] [pid 822943:tid 822999] [remote 54.37.0.138:38800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "serverkr.com"] [uri "/"] [unique_id "amuQzI8CCDUa19YrTu4eWgABeTc"]
[Thu Jul 30 12:58:37.092467 2026] [security2:error] [pid 822943:tid 823122] [client 20.171.55.167:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuQzY8CCDUa19YrTu4eXgAAATs"]
[Thu Jul 30 12:58:37.830296 2026] [security2:error] [pid 822943:tid 823137] [client 20.171.55.167:4258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/updates.php"] [unique_id "amuQzY8CCDUa19YrTu4ebwAAAUo"]
[Thu Jul 30 12:58:38.463713 2026] [security2:error] [pid 822943:tid 823147] [client 20.220.227.237:47504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/hosty.php"] [unique_id "amuQzo8CCDUa19YrTu4efAAAAVQ"]
[Thu Jul 30 12:58:38.463829 2026] [security2:error] [pid 822943:tid 823147] [client 20.220.227.237:47504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/hosty.php"] [unique_id "amuQzo8CCDUa19YrTu4efAAAAVQ"]
[Thu Jul 30 12:58:38.546024 2026] [security2:error] [pid 822943:tid 823101] [client 20.171.55.167:4345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/css/cloud.php"] [unique_id "amuQzo8CCDUa19YrTu4efQAAASY"]
[Thu Jul 30 12:58:38.905999 2026] [security2:error] [pid 822943:tid 823092] [client 172.213.17.107:21755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/media.php"] [unique_id "amuQzo8CCDUa19YrTu4ejQAAAR0"]
[Thu Jul 30 12:58:38.906137 2026] [security2:error] [pid 822943:tid 823092] [client 172.213.17.107:21755] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/media.php"] [unique_id "amuQzo8CCDUa19YrTu4ejQAAAR0"]
[Thu Jul 30 12:58:39.042792 2026] [security2:error] [pid 822943:tid 823190] [client 150.107.232.194:26612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQz48CCDUa19YrTu4ejgAAAX8"]
[Thu Jul 30 12:58:39.042967 2026] [security2:error] [pid 822943:tid 823190] [client 150.107.232.194:26612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQz48CCDUa19YrTu4ejgAAAX8"]
[Thu Jul 30 12:58:39.222277 2026] [security2:error] [pid 822943:tid 823022] [remote 57.141.18.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQz48CCDUa19YrTu4elQABDU4"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,cotton,linen,polyester,silicon,titanium&filter_size=extra-large,medium&rating=5&status=sale&tax_product_cat=sweatshirts&unfilter=1
[Thu Jul 30 12:58:39.250122 2026] [security2:error] [pid 822943:tid 823086] [client 20.171.55.167:4724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuQz48CCDUa19YrTu4elgAAARc"]
[Thu Jul 30 12:58:39.282686 2026] [core:notice] [pid 822943:tid 823117] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:39.806740 2026] [security2:error] [pid 822943:tid 823026] [remote 57.141.18.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuQz48CCDUa19YrTu4epAABWFI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,cotton,linen,polyester,silicon,titanium&filter_size=extra-large,medium&rating=5&status=sale&tax_product_cat=sweatshirts&unfilter=1
[Thu Jul 30 12:58:39.964496 2026] [security2:error] [pid 822943:tid 823110] [client 20.171.55.167:4716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/img/cloud.php"] [unique_id "amuQz48CCDUa19YrTu4epQAAAS8"]
[Thu Jul 30 12:58:39.989028 2026] [core:notice] [pid 822943:tid 823173] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:40.675172 2026] [security2:error] [pid 822943:tid 823183] [client 20.171.55.167:4484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuQ0I8CCDUa19YrTu4eswAAAXg"]
[Thu Jul 30 12:58:40.761667 2026] [security2:error] [pid 822943:tid 823045] [remote 216.73.216.152:43541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQ0I8CCDUa19YrTu4eugABHWU"]
[Thu Jul 30 12:58:41.072410 2026] [security2:error] [pid 822943:tid 823102] [client 74.7.175.180:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.shiftofy.it.com"] [uri "/robots.txt"] [unique_id "amuQ0Y8CCDUa19YrTu4ewAABJ14"]
[Thu Jul 30 12:58:41.164878 2026] [core:notice] [pid 822943:tid 823195] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:41.423351 2026] [security2:error] [pid 822943:tid 823094] [client 20.171.55.167:4279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuQ0Y8CCDUa19YrTu4eywAAAR8"]
[Thu Jul 30 12:58:41.767820 2026] [core:error] [pid 822943:tid 823050] [remote 74.7.244.1:51150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:58:41.767842 2026] [core:error] [pid 822943:tid 823050] [remote 74.7.244.1:51150] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:58:41.768063 2026] [security2:error] [pid 822943:tid 823142] [client 74.7.244.1:51150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-a94f61be.jst.nyx.temporary.site"] [uri "/website_a94f61be/index.php"] [unique_id "amuQ0Y8CCDUa19YrTu4ezwABT2o"]
[Thu Jul 30 12:58:41.812536 2026] [core:notice] [pid 822943:tid 823090] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:42.156113 2026] [security2:error] [pid 822943:tid 823128] [client 20.171.55.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/avaa.php"] [unique_id "amuQ0o8CCDUa19YrTu4e2gAAAUE"]
[Thu Jul 30 12:58:42.919549 2026] [security2:error] [pid 822943:tid 823156] [client 20.171.55.167:4710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/images/cloud.php"] [unique_id "amuQ0o8CCDUa19YrTu4e7gAAAV0"]
[Thu Jul 30 12:58:43.036146 2026] [security2:error] [pid 822943:tid 823107] [client 20.220.227.237:17017] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/Text/Diff/"] [unique_id "amuQ048CCDUa19YrTu4e7wAAASw"]
[Thu Jul 30 12:58:43.036250 2026] [security2:error] [pid 822943:tid 823107] [client 20.220.227.237:17017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/wp-includes/Text/Diff/"] [unique_id "amuQ048CCDUa19YrTu4e7wAAASw"]
[Thu Jul 30 12:58:43.632641 2026] [security2:error] [pid 822943:tid 823082] [client 20.171.55.167:4304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuQ048CCDUa19YrTu4e-QAAARM"]
[Thu Jul 30 12:58:43.815833 2026] [security2:error] [pid 822943:tid 823059] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ048CCDUa19YrTu4e-wABU3M"]
[Thu Jul 30 12:58:43.816062 2026] [security2:error] [pid 822943:tid 823146] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ048CCDUa19YrTu4e-wABU3M"]
[Thu Jul 30 12:58:43.991795 2026] [security2:error] [pid 822943:tid 823056] [remote 198.38.90.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.90.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ciunews.com"] [uri "/wp-login.php"] [unique_id "amuQ048CCDUa19YrTu4fAgABT3A"]
[Thu Jul 30 12:58:44.366078 2026] [security2:error] [pid 822943:tid 823109] [client 20.171.55.167:4685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuQ1I8CCDUa19YrTu4fCgAAAS4"]
[Thu Jul 30 12:58:44.939268 2026] [security2:error] [pid 822943:tid 823133] [client 172.236.9.101:5048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1I8CCDUa19YrTu4fCwAAAUY"]
[Thu Jul 30 12:58:44.939296 2026] [security2:error] [pid 822943:tid 823074] [client 172.236.9.101:18799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1I8CCDUa19YrTu4fCAAAAQs"]
[Thu Jul 30 12:58:44.940300 2026] [security2:error] [pid 822943:tid 823089] [client 172.236.9.101:5933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1I8CCDUa19YrTu4fDAAAARo"]
[Thu Jul 30 12:58:45.074550 2026] [security2:error] [pid 822943:tid 823134] [client 20.171.55.167:4717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuQ1Y8CCDUa19YrTu4fIwAAAUc"]
[Thu Jul 30 12:58:45.552737 2026] [security2:error] [pid 822943:tid 823195] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQ1I8CCDUa19YrTu4fHAAAAYQ"]
[Thu Jul 30 12:58:45.805501 2026] [security2:error] [pid 822943:tid 823147] [client 20.171.55.167:4695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuQ1Y8CCDUa19YrTu4fNgAAAVQ"]
[Thu Jul 30 12:58:45.865484 2026] [security2:error] [pid 822943:tid 823163] [client 172.236.9.101:7176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1Y8CCDUa19YrTu4fJAAAAWQ"]
[Thu Jul 30 12:58:45.901908 2026] [security2:error] [pid 822943:tid 823079] [client 172.236.9.101:25330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1Y8CCDUa19YrTu4fJgAAARA"]
[Thu Jul 30 12:58:45.914672 2026] [security2:error] [pid 822943:tid 823194] [client 172.236.9.101:33945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1Y8CCDUa19YrTu4fJwAAAYM"]
[Thu Jul 30 12:58:46.008112 2026] [security2:error] [pid 822943:tid 823151] [client 172.236.9.101:39293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1Y8CCDUa19YrTu4fKwAAAVg"]
[Thu Jul 30 12:58:46.017965 2026] [security2:error] [pid 822943:tid 823085] [client 172.236.9.101:15310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1Y8CCDUa19YrTu4fKgAAARY"]
[Thu Jul 30 12:58:46.430739 2026] [security2:error] [pid 822943:tid 822959] [remote 216.73.216.152:16575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQ1o8CCDUa19YrTu4fSgABXA8"]
[Thu Jul 30 12:58:46.507437 2026] [security2:error] [pid 822943:tid 823130] [client 20.171.55.167:4510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuQ1o8CCDUa19YrTu4fTQAAAUM"]
[Thu Jul 30 12:58:46.906625 2026] [security2:error] [pid 822943:tid 823181] [client 172.236.9.101:33390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1o8CCDUa19YrTu4fQQAAAXY"]
[Thu Jul 30 12:58:46.918359 2026] [security2:error] [pid 822943:tid 823132] [client 172.236.9.101:4822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1o8CCDUa19YrTu4fRAAAAUU"]
[Thu Jul 30 12:58:46.949783 2026] [security2:error] [pid 822943:tid 823096] [client 172.236.9.101:61207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1o8CCDUa19YrTu4fQgAAASE"]
[Thu Jul 30 12:58:46.952206 2026] [security2:error] [pid 822943:tid 823111] [client 172.236.9.101:29717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1o8CCDUa19YrTu4fQwAAATA"]
[Thu Jul 30 12:58:46.953863 2026] [security2:error] [pid 822943:tid 823190] [client 172.236.9.101:11036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1o8CCDUa19YrTu4fRQAAAX8"]
[Thu Jul 30 12:58:47.011703 2026] [security2:error] [pid 822943:tid 823091] [client 172.236.9.101:61565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1o8CCDUa19YrTu4fSwAAARw"]
[Thu Jul 30 12:58:47.056619 2026] [security2:error] [pid 822943:tid 823199] [client 172.236.9.101:2299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1o8CCDUa19YrTu4fRgAAAYg"]
[Thu Jul 30 12:58:47.073786 2026] [security2:error] [pid 822943:tid 823084] [client 172.236.9.101:55283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ1o8CCDUa19YrTu4fSQAAARU"]
[Thu Jul 30 12:58:47.233012 2026] [security2:error] [pid 822943:tid 823108] [client 20.171.55.167:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuQ148CCDUa19YrTu4fYQAAAS0"]
[Thu Jul 30 12:58:47.271914 2026] [security2:error] [pid 822943:tid 823093] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQ1o8CCDUa19YrTu4fVwAAAR4"]
[Thu Jul 30 12:58:47.743721 2026] [security2:error] [pid 822943:tid 823109] [client 20.220.227.237:16963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuQ148CCDUa19YrTu4fcAAAAS4"]
[Thu Jul 30 12:58:47.743830 2026] [security2:error] [pid 822943:tid 823109] [client 20.220.227.237:16963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/admin.php"] [unique_id "amuQ148CCDUa19YrTu4fcAAAAS4"]
[Thu Jul 30 12:58:47.889263 2026] [security2:error] [pid 822943:tid 823101] [client 172.236.9.101:3685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ148CCDUa19YrTu4fYwAAASY"]
[Thu Jul 30 12:58:47.896008 2026] [security2:error] [pid 822943:tid 823110] [client 172.236.9.101:9585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ148CCDUa19YrTu4fZAAAAS8"]
[Thu Jul 30 12:58:47.940928 2026] [security2:error] [pid 822943:tid 823114] [client 172.236.9.101:43994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ148CCDUa19YrTu4fZQAAATM"]
[Thu Jul 30 12:58:47.950884 2026] [security2:error] [pid 822943:tid 823178] [client 172.236.9.101:22760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ148CCDUa19YrTu4fZgAAAXM"]
[Thu Jul 30 12:58:47.967508 2026] [security2:error] [pid 822943:tid 823128] [client 20.171.55.167:4317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/updates.php"] [unique_id "amuQ148CCDUa19YrTu4fcgAAAUE"]
[Thu Jul 30 12:58:48.520097 2026] [security2:error] [pid 822943:tid 823191] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQ148CCDUa19YrTu4fcQABgB8"]
[Thu Jul 30 12:58:48.688230 2026] [security2:error] [pid 822943:tid 823137] [client 20.171.55.167:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuQ2I8CCDUa19YrTu4fggAAAUo"]
[Thu Jul 30 12:58:49.391891 2026] [security2:error] [pid 822943:tid 823081] [client 20.171.55.167:4245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuQ2Y8CCDUa19YrTu4fjwAAARI"]
[Thu Jul 30 12:58:49.576380 2026] [security2:error] [pid 822943:tid 823120] [client 150.107.232.194:27324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ2Y8CCDUa19YrTu4flwAAATk"]
[Thu Jul 30 12:58:49.576484 2026] [security2:error] [pid 822943:tid 823120] [client 150.107.232.194:27324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ2Y8CCDUa19YrTu4flwAAATk"]
[Thu Jul 30 12:58:49.805236 2026] [security2:error] [pid 822943:tid 823117] [client 156.229.21.54:56222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yxe.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuQ2Y8CCDUa19YrTu4fmwAAATY"]
[Thu Jul 30 12:58:50.040562 2026] [security2:error] [pid 822943:tid 823125] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQ2Y8CCDUa19YrTu4fkwAAAT4"]
[Thu Jul 30 12:58:50.119749 2026] [security2:error] [pid 822943:tid 823079] [client 20.171.55.167:4727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuQ2o8CCDUa19YrTu4fnwAAARA"]
[Thu Jul 30 12:58:50.146116 2026] [security2:error] [pid 822943:tid 823049] [remote 103.75.185.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "professorissa.com"] [uri "/wp-login.php"] [unique_id "amuQ2o8CCDUa19YrTu4fogABJWk"]
[Thu Jul 30 12:58:50.320736 2026] [security2:error] [pid 822943:tid 823109] [client 172.213.17.107:14371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/images.php"] [unique_id "amuQ2o8CCDUa19YrTu4fqgAAAS4"]
[Thu Jul 30 12:58:50.320840 2026] [security2:error] [pid 822943:tid 823109] [client 172.213.17.107:14371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/images.php"] [unique_id "amuQ2o8CCDUa19YrTu4fqgAAAS4"]
[Thu Jul 30 12:58:50.414603 2026] [security2:error] [pid 822943:tid 823110] [client 103.112.5.35:34806] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuQ2o8CCDUa19YrTu4fqwAAAS8"]
[Thu Jul 30 12:58:50.795187 2026] [security2:error] [pid 822943:tid 822969] [remote 216.73.216.152:16575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQ2o8CCDUa19YrTu4fsgABeBk"]
[Thu Jul 30 12:58:50.825290 2026] [security2:error] [pid 822943:tid 823178] [client 20.171.55.167:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/alfa-rex.php7"] [unique_id "amuQ2o8CCDUa19YrTu4fswAAAXM"]
[Thu Jul 30 12:58:51.063290 2026] [fcgid:warn] [pid 822943:tid 823088] (70014)End of file found: [client 165.154.179.62:46470] mod_fcgid: can't get data from http client
[Thu Jul 30 12:58:51.233348 2026] [security2:error] [pid 822943:tid 823182] [client 103.112.5.35:53364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuQ248CCDUa19YrTu4fwQAAAXc"]
[Thu Jul 30 12:58:51.535025 2026] [security2:error] [pid 822943:tid 823152] [client 20.171.55.167:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/alfanew.php"] [unique_id "amuQ248CCDUa19YrTu4fxQAAAVk"]
[Thu Jul 30 12:58:52.034518 2026] [core:notice] [pid 822943:tid 822992] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:52.239327 2026] [security2:error] [pid 822943:tid 823173] [client 20.171.55.167:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuQ3I8CCDUa19YrTu4f1AAAAW4"]
[Thu Jul 30 12:58:53.594557 2026] [security2:error] [pid 822943:tid 823161] [client 20.171.55.167:4333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuQ3Y8CCDUa19YrTu4f7wAAAWI"]
[Thu Jul 30 12:58:54.260812 2026] [core:notice] [pid 822943:tid 823076] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:54.309908 2026] [security2:error] [pid 822943:tid 823160] [client 20.171.55.167:4712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-p.php7"] [unique_id "amuQ3o8CCDUa19YrTu4f_QAAAWE"]
[Thu Jul 30 12:58:54.467804 2026] [security2:error] [pid 822943:tid 823156] [client 20.220.227.237:25454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/av.php"] [unique_id "amuQ3o8CCDUa19YrTu4f_gAAAV0"]
[Thu Jul 30 12:58:54.467943 2026] [security2:error] [pid 822943:tid 823156] [client 20.220.227.237:25454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/av.php"] [unique_id "amuQ3o8CCDUa19YrTu4f_gAAAV0"]
[Thu Jul 30 12:58:54.554808 2026] [security2:error] [pid 822943:tid 823000] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ3o8CCDUa19YrTu4gBAABVjg"]
[Thu Jul 30 12:58:54.554986 2026] [security2:error] [pid 822943:tid 823149] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ3o8CCDUa19YrTu4gBAABVjg"]
[Thu Jul 30 12:58:54.895793 2026] [security2:error] [pid 822943:tid 823133] [client 116.179.32.15:55010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9396"] [unique_id "amuQ3o8CCDUa19YrTu4gBgAAAUY"]
[Thu Jul 30 12:58:55.011493 2026] [security2:error] [pid 822943:tid 823141] [client 20.171.55.167:4341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuQ348CCDUa19YrTu4gDgAAAU4"]
[Thu Jul 30 12:58:55.307685 2026] [core:notice] [pid 822943:tid 823146] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:55.413909 2026] [security2:error] [pid 822943:tid 823017] [remote 57.141.0.64:36606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuQ348CCDUa19YrTu4gFgABakk"]
[Thu Jul 30 12:58:55.680182 2026] [security2:error] [pid 822943:tid 823106] [client 119.249.100.108:9125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9396"] [unique_id "amuQ348CCDUa19YrTu4gHwAAASs"]
[Thu Jul 30 12:58:55.717413 2026] [security2:error] [pid 822943:tid 823186] [client 20.171.55.167:4675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuQ348CCDUa19YrTu4gIAAAAXs"]
[Thu Jul 30 12:58:55.797059 2026] [security2:error] [pid 822943:tid 823015] [remote 216.73.216.152:16575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQ348CCDUa19YrTu4gIQABbEc"]
[Thu Jul 30 12:58:56.261716 2026] [security2:error] [pid 822943:tid 823140] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuQ348CCDUa19YrTu4gGgABTU0"]
[Thu Jul 30 12:58:56.368331 2026] [security2:error] [pid 822943:tid 823101] [client 20.220.227.237:7800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/shell.php"] [unique_id "amuQ4I8CCDUa19YrTu4gKwAAASY"]
[Thu Jul 30 12:58:56.368451 2026] [security2:error] [pid 822943:tid 823101] [client 20.220.227.237:7800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/shell.php"] [unique_id "amuQ4I8CCDUa19YrTu4gKwAAASY"]
[Thu Jul 30 12:58:56.379270 2026] [core:notice] [pid 822943:tid 823119] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:56.419417 2026] [security2:error] [pid 822943:tid 823129] [client 20.171.55.167:4723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/repeater.php"] [unique_id "amuQ4I8CCDUa19YrTu4gMAAAAUI"]
[Thu Jul 30 12:58:57.122849 2026] [security2:error] [pid 822943:tid 823160] [client 20.171.55.167:4504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wsoyanz.php"] [unique_id "amuQ4Y8CCDUa19YrTu4gQQAAAWE"]
[Thu Jul 30 12:58:57.383303 2026] [core:notice] [pid 822943:tid 823179] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:57.847458 2026] [autoindex:error] [pid 822943:tid 823173] [client 20.193.250.173:51188] AH01276: Cannot serve directory /home1/khwnyxte/alshateeintl.com/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 12:58:57.870087 2026] [security2:error] [pid 822943:tid 823120] [client 20.171.55.167:4707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/yanz.php"] [unique_id "amuQ4Y8CCDUa19YrTu4gUwAAATk"]
[Thu Jul 30 12:58:58.040228 2026] [core:notice] [pid 822943:tid 823117] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:58.344381 2026] [security2:error] [pid 822943:tid 823134] [client 193.148.16.211:54346] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuQ4o8CCDUa19YrTu4gXwAAAUc"]
[Thu Jul 30 12:58:58.344525 2026] [security2:error] [pid 822943:tid 823134] [client 193.148.16.211:54346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuQ4o8CCDUa19YrTu4gXwAAAUc"]
[Thu Jul 30 12:58:58.574185 2026] [security2:error] [pid 822943:tid 823174] [client 20.171.55.167:4329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "amuQ4o8CCDUa19YrTu4gYwAAAW8"]
[Thu Jul 30 12:58:58.629325 2026] [core:notice] [pid 822943:tid 823113] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:58.836421 2026] [core:notice] [pid 822943:tid 823129] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:58:58.980136 2026] [security2:error] [pid 822943:tid 823114] [client 172.213.17.107:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/adminner.php"] [unique_id "amuQ4o8CCDUa19YrTu4gbAAAATM"]
[Thu Jul 30 12:58:58.980239 2026] [security2:error] [pid 822943:tid 823114] [client 172.213.17.107:15579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/adminner.php"] [unique_id "amuQ4o8CCDUa19YrTu4gbAAAATM"]
[Thu Jul 30 12:58:59.314285 2026] [security2:error] [pid 822943:tid 823122] [client 20.171.55.167:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "amuQ448CCDUa19YrTu4gdgAAATs"]
[Thu Jul 30 12:59:00.032829 2026] [security2:error] [pid 822943:tid 823160] [client 20.171.55.167:4497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cache-compat.php"] [unique_id "amuQ5I8CCDUa19YrTu4ggQAAAWE"]
[Thu Jul 30 12:59:00.046676 2026] [security2:error] [pid 822943:tid 823096] [client 150.107.232.194:26696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ5I8CCDUa19YrTu4ggwAAASE"]
[Thu Jul 30 12:59:00.046784 2026] [security2:error] [pid 822943:tid 823096] [client 150.107.232.194:26696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ5I8CCDUa19YrTu4ggwAAASE"]
[Thu Jul 30 12:59:00.142814 2026] [core:notice] [pid 822943:tid 823141] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:00.149693 2026] [core:notice] [pid 822943:tid 823199] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:00.211415 2026] [security2:error] [pid 822943:tid 823133] [client 172.213.17.107:24934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/admin.php"] [unique_id "amuQ5I8CCDUa19YrTu4giAAAAUY"]
[Thu Jul 30 12:59:00.211521 2026] [security2:error] [pid 822943:tid 823133] [client 172.213.17.107:24934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/admin.php"] [unique_id "amuQ5I8CCDUa19YrTu4giAAAAUY"]
[Thu Jul 30 12:59:00.738444 2026] [security2:error] [pid 822943:tid 823118] [client 20.171.55.167:4713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ajax-actions.php"] [unique_id "amuQ5I8CCDUa19YrTu4glAAAATc"]
[Thu Jul 30 12:59:01.392325 2026] [security2:error] [pid 822943:tid 823058] [remote 74.7.241.60:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/feed/img/js/uploads/partners/uploads/partners/uploads/partners/partnerf.php"] [unique_id "amuQ5Y8CCDUa19YrTu4gpQABe3I"], referer: https://aded-rdc.org/feed/img/js/uploads/partners/uploads/partners/uploads/partners/login.php
[Thu Jul 30 12:59:01.456516 2026] [security2:error] [pid 822943:tid 823059] [remote 216.73.216.152:11714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQ5Y8CCDUa19YrTu4gpgABRHM"]
[Thu Jul 30 12:59:01.478624 2026] [security2:error] [pid 822943:tid 823134] [client 20.171.55.167:4257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/ajax-actions.php"] [unique_id "amuQ5Y8CCDUa19YrTu4gpwAAAUc"]
[Thu Jul 30 12:59:01.500632 2026] [security2:error] [pid 822943:tid 823077] [client 172.213.17.107:15590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/ops.php"] [unique_id "amuQ5Y8CCDUa19YrTu4gqAAAAQ4"]
[Thu Jul 30 12:59:01.500737 2026] [security2:error] [pid 822943:tid 823077] [client 172.213.17.107:15590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/ops.php"] [unique_id "amuQ5Y8CCDUa19YrTu4gqAAAAQ4"]
[Thu Jul 30 12:59:01.929546 2026] [security2:error] [pid 822943:tid 823197] [client 74.7.230.61:35754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cal-sync.co"] [uri "/cgi-sys/404.html"] [unique_id "amuQ5Y8CCDUa19YrTu4gtQABhnQ"]
[Thu Jul 30 12:59:02.188955 2026] [security2:error] [pid 822943:tid 823074] [client 20.171.55.167:4704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-consar.php"] [unique_id "amuQ5o8CCDUa19YrTu4gugAAAQs"]
[Thu Jul 30 12:59:02.829196 2026] [core:notice] [pid 822943:tid 823160] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:02.956932 2026] [security2:error] [pid 822943:tid 823094] [client 20.171.55.167:4482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/repeater.php"] [unique_id "amuQ5o8CCDUa19YrTu4gygAAAR8"]
[Thu Jul 30 12:59:03.529950 2026] [security2:error] [pid 822943:tid 823150] [client 74.7.175.129:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pna.djb.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuQ548CCDUa19YrTu4g2wAAAVc"]
[Thu Jul 30 12:59:03.530507 2026] [security2:error] [pid 822943:tid 823173] [client 74.7.175.129:54770] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pna.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuQ548CCDUa19YrTu4g2QABbgk"]
[Thu Jul 30 12:59:03.661186 2026] [security2:error] [pid 822943:tid 823090] [client 20.171.55.167:4726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/admin-post.php"] [unique_id "amuQ548CCDUa19YrTu4g3AAAARs"]
[Thu Jul 30 12:59:03.957366 2026] [security2:error] [pid 822943:tid 823126] [client 127.0.0.1:15174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuQ548CCDUa19YrTu4g4QAAAT8"]
[Thu Jul 30 12:59:03.957494 2026] [security2:error] [pid 822943:tid 823079] [client 74.7.228.62:55914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.rgserve.ph"] [uri "/robots.txt"] [unique_id "amuQ548CCDUa19YrTu4g4AABEH0"]
[Thu Jul 30 12:59:04.379360 2026] [security2:error] [pid 822943:tid 823131] [client 20.171.55.167:4515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "amuQ6I8CCDUa19YrTu4g7gAAAUQ"]
[Thu Jul 30 12:59:04.493023 2026] [autoindex:error] [pid 822943:tid 823122] [client 74.7.241.60:0] AH01276: Cannot serve directory /home1/pnadjbte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:59:04.725699 2026] [core:notice] [pid 822943:tid 823075] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:04.982163 2026] [security2:error] [pid 822943:tid 823136] [client 172.236.9.101:26155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ6I8CCDUa19YrTu4g7QAAAUk"]
[Thu Jul 30 12:59:05.002016 2026] [security2:error] [pid 822943:tid 823099] [client 172.236.9.101:12624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ6I8CCDUa19YrTu4g7wAAASQ"]
[Thu Jul 30 12:59:05.020028 2026] [security2:error] [pid 822943:tid 823198] [client 172.236.9.101:63214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ6I8CCDUa19YrTu4g8AAAAYc"]
[Thu Jul 30 12:59:05.030271 2026] [security2:error] [pid 822943:tid 823105] [client 172.236.9.101:43818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ6I8CCDUa19YrTu4g8QAAASo"]
[Thu Jul 30 12:59:05.073616 2026] [security2:error] [pid 822943:tid 823076] [client 172.236.9.101:41377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ6I8CCDUa19YrTu4g8gAAAQ0"]
[Thu Jul 30 12:59:05.089514 2026] [security2:error] [pid 822943:tid 823175] [client 20.171.55.167:4672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/dropdown.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hCgAAAXA"]
[Thu Jul 30 12:59:05.197069 2026] [security2:error] [pid 822943:tid 822954] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hDgABfwo"]
[Thu Jul 30 12:59:05.197254 2026] [security2:error] [pid 822943:tid 823190] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hDgABfwo"]
[Thu Jul 30 12:59:05.285493 2026] [security2:error] [pid 822943:tid 823117] [client 172.213.17.107:26871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/mac.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hEAAAATY"]
[Thu Jul 30 12:59:05.285628 2026] [security2:error] [pid 822943:tid 823117] [client 172.213.17.107:26871] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/mac.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hEAAAATY"]
[Thu Jul 30 12:59:05.552459 2026] [security2:error] [pid 822943:tid 823150] [client 184.75.208.246:57562] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hEgAAAVc"]
[Thu Jul 30 12:59:05.552564 2026] [security2:error] [pid 822943:tid 823150] [client 184.75.208.246:57562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hEgAAAVc"]
[Thu Jul 30 12:59:05.801812 2026] [security2:error] [pid 822943:tid 822944] [remote 216.73.216.152:11714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQ6Y8CCDUa19YrTu4hIAABKQA"]
[Thu Jul 30 12:59:05.843573 2026] [security2:error] [pid 822943:tid 823085] [client 20.171.55.167:4480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hJAAAARY"]
[Thu Jul 30 12:59:05.875255 2026] [security2:error] [pid 822943:tid 823187] [client 172.236.9.101:62021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hFAAAAXw"]
[Thu Jul 30 12:59:05.940106 2026] [security2:error] [pid 822943:tid 823165] [client 172.236.9.101:22570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hFQAAAWY"]
[Thu Jul 30 12:59:05.948940 2026] [security2:error] [pid 822943:tid 823192] [client 172.236.9.101:38686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hFgAAAYE"]
[Thu Jul 30 12:59:05.960209 2026] [security2:error] [pid 822943:tid 823118] [client 172.236.9.101:14332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ6Y8CCDUa19YrTu4hFwAAATc"]
[Thu Jul 30 12:59:06.584007 2026] [security2:error] [pid 822943:tid 823122] [client 20.171.55.167:4709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/dropdown.php"] [unique_id "amuQ6o8CCDUa19YrTu4hNAAAATs"]
[Thu Jul 30 12:59:06.737419 2026] [security2:error] [pid 822943:tid 823196] [client 20.220.227.237:25436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/storage/index.php"] [unique_id "amuQ6o8CCDUa19YrTu4hOAAAAYU"]
[Thu Jul 30 12:59:06.737531 2026] [security2:error] [pid 822943:tid 823196] [client 20.220.227.237:25436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/storage/index.php"] [unique_id "amuQ6o8CCDUa19YrTu4hOAAAAYU"]
[Thu Jul 30 12:59:07.054867 2026] [core:error] [pid 822943:tid 823105] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:07.054892 2026] [core:error] [pid 822943:tid 823105] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:07.065726 2026] [core:error] [pid 822943:tid 823141] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:07.065747 2026] [core:error] [pid 822943:tid 823141] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:07.075239 2026] [core:error] [pid 822943:tid 823097] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:07.075258 2026] [core:error] [pid 822943:tid 823097] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:07.300735 2026] [security2:error] [pid 822943:tid 823180] [client 20.171.55.167:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/about.php"] [unique_id "amuQ648CCDUa19YrTu4hUgAAAXU"]
[Thu Jul 30 12:59:08.002001 2026] [security2:error] [pid 822943:tid 823132] [client 20.171.55.167:4708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/about.php7"] [unique_id "amuQ7I8CCDUa19YrTu4hYQAAAUU"]
[Thu Jul 30 12:59:08.749959 2026] [security2:error] [pid 822943:tid 823131] [client 20.171.55.167:4511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/alfanew.php7"] [unique_id "amuQ7I8CCDUa19YrTu4hdgAAAUQ"]
[Thu Jul 30 12:59:08.964837 2026] [security2:error] [pid 822943:tid 823156] [client 20.220.227.237:51198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/w.php"] [unique_id "amuQ7I8CCDUa19YrTu4heAAAAV0"]
[Thu Jul 30 12:59:08.965018 2026] [security2:error] [pid 822943:tid 823156] [client 20.220.227.237:51198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/w.php"] [unique_id "amuQ7I8CCDUa19YrTu4heAAAAV0"]
[Thu Jul 30 12:59:09.351338 2026] [security2:error] [pid 822943:tid 823107] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQ7I8CCDUa19YrTu4hcwAAASw"]
[Thu Jul 30 12:59:09.453962 2026] [security2:error] [pid 822943:tid 823198] [client 20.171.55.167:4328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/adminfuns.php7"] [unique_id "amuQ7Y8CCDUa19YrTu4higAAAYc"]
[Thu Jul 30 12:59:10.181660 2026] [security2:error] [pid 822943:tid 823126] [client 20.171.55.167:4517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ebs.php7"] [unique_id "amuQ7o8CCDUa19YrTu4hmwAAAT8"]
[Thu Jul 30 12:59:10.539634 2026] [security2:error] [pid 822943:tid 823118] [client 150.107.232.194:27368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ7o8CCDUa19YrTu4howAAATc"]
[Thu Jul 30 12:59:10.539743 2026] [security2:error] [pid 822943:tid 823118] [client 150.107.232.194:27368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ7o8CCDUa19YrTu4howAAATc"]
[Thu Jul 30 12:59:10.884436 2026] [security2:error] [pid 822943:tid 823176] [client 20.171.55.167:4700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ws.php7"] [unique_id "amuQ7o8CCDUa19YrTu4hrQAAAXE"]
[Thu Jul 30 12:59:11.071324 2026] [core:notice] [pid 822943:tid 823168] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:11.168110 2026] [security2:error] [pid 822943:tid 823133] [client 172.213.17.107:27511] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kingstarenterprises.com"] [uri "/cgi-sys/404.html"] [unique_id "amuQ748CCDUa19YrTu4htgAAAUY"]
[Thu Jul 30 12:59:11.307322 2026] [security2:error] [pid 822943:tid 823175] [client 172.213.17.107:27511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/pucci.php"] [unique_id "amuQ748CCDUa19YrTu4hugAAAXA"]
[Thu Jul 30 12:59:11.307440 2026] [security2:error] [pid 822943:tid 823175] [client 172.213.17.107:27511] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "kingstarenterprises.com"] [uri "/pucci.php"] [unique_id "amuQ748CCDUa19YrTu4hugAAAXA"]
[Thu Jul 30 12:59:11.450035 2026] [security2:error] [pid 822943:tid 822999] [remote 216.73.216.152:6961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuQ748CCDUa19YrTu4hvgABbTc"]
[Thu Jul 30 12:59:11.592025 2026] [security2:error] [pid 822943:tid 823141] [client 20.171.55.167:4541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/alfanew2.php7"] [unique_id "amuQ748CCDUa19YrTu4hvwAAAU4"]
[Thu Jul 30 12:59:11.600098 2026] [security2:error] [pid 822943:tid 823073] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQ748CCDUa19YrTu4hsAAAAQo"]
[Thu Jul 30 12:59:11.694772 2026] [security2:error] [pid 822943:tid 823120] [client 20.220.227.237:22501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.227.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/jp.php"] [unique_id "amuQ748CCDUa19YrTu4hwwAAATk"]
[Thu Jul 30 12:59:11.694879 2026] [security2:error] [pid 822943:tid 823120] [client 20.220.227.237:22501] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/jp.php"] [unique_id "amuQ748CCDUa19YrTu4hwwAAATk"]
[Thu Jul 30 12:59:12.359542 2026] [security2:error] [pid 822943:tid 823125] [client 20.171.55.167:4346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/alfa-rex2.php7"] [unique_id "amuQ8I8CCDUa19YrTu4h2AAAAT4"]
[Thu Jul 30 12:59:13.061062 2026] [security2:error] [pid 822943:tid 823082] [client 20.171.55.167:4537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuQ8Y8CCDUa19YrTu4h5QAAARM"]
[Thu Jul 30 12:59:13.788101 2026] [security2:error] [pid 822943:tid 823174] [client 20.171.55.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "amuQ8Y8CCDUa19YrTu4h-QAAAW8"]
[Thu Jul 30 12:59:13.906854 2026] [security2:error] [pid 822943:tid 823114] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQ8Y8CCDUa19YrTu4h7wAAATM"]
[Thu Jul 30 12:59:14.440716 2026] [security2:error] [pid 822943:tid 823198] [client 103.178.136.110:57534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuQ8o8CCDUa19YrTu4iAgAAAYc"], referer: http://pkf.jo
[Thu Jul 30 12:59:14.488511 2026] [security2:error] [pid 822943:tid 823193] [client 20.171.55.167:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuQ8o8CCDUa19YrTu4iEgAAAYI"]
[Thu Jul 30 12:59:14.525429 2026] [core:notice] [pid 822943:tid 823076] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:14.642357 2026] [security2:error] [pid 822943:tid 823141] [client 182.48.211.243:36956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuQ8o8CCDUa19YrTu4h_QAAAU4"], referer: http://pkf.jo
[Thu Jul 30 12:59:15.086816 2026] [security2:error] [pid 822943:tid 823077] [client 193.148.16.211:52054] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuQ848CCDUa19YrTu4iIQAAAQ4"]
[Thu Jul 30 12:59:15.086921 2026] [security2:error] [pid 822943:tid 823077] [client 193.148.16.211:52054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuQ848CCDUa19YrTu4iIQAAAQ4"]
[Thu Jul 30 12:59:15.224435 2026] [security2:error] [pid 822943:tid 823154] [client 88.214.15.110:4393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuQ8o8CCDUa19YrTu4iEAAAAVs"], referer: http://pkf.jo
[Thu Jul 30 12:59:15.231292 2026] [security2:error] [pid 822943:tid 823177] [client 176.175.161.222:45078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuQ8o8CCDUa19YrTu4iEQAAAXI"], referer: http://pkf.jo
[Thu Jul 30 12:59:15.241715 2026] [security2:error] [pid 822943:tid 823089] [client 20.171.55.167:4334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "amuQ848CCDUa19YrTu4iJQAAARo"]
[Thu Jul 30 12:59:15.835248 2026] [security2:error] [pid 822943:tid 823057] [remote 47.128.27.96:38514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/"] [unique_id "amuQ848CCDUa19YrTu4iMgABOHE"]
[Thu Jul 30 12:59:15.946241 2026] [security2:error] [pid 822943:tid 823197] [client 20.171.55.167:4481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuQ848CCDUa19YrTu4iNwAAAYY"]
[Thu Jul 30 12:59:16.115025 2026] [security2:error] [pid 822943:tid 823023] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ9I8CCDUa19YrTu4iOAABIk8"]
[Thu Jul 30 12:59:16.115198 2026] [security2:error] [pid 822943:tid 823097] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ9I8CCDUa19YrTu4iOAABIk8"]
[Thu Jul 30 12:59:16.152459 2026] [security2:error] [pid 822943:tid 823081] [client 172.237.109.114:62599] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/api/.env"] [unique_id "amuQ9I8CCDUa19YrTu4iOgAAARI"]
[Thu Jul 30 12:59:16.216137 2026] [security2:error] [pid 822943:tid 823195] [client 184.75.208.246:45608] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ9I8CCDUa19YrTu4iPgAAAYQ"]
[Thu Jul 30 12:59:16.216267 2026] [security2:error] [pid 822943:tid 823195] [client 184.75.208.246:45608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ9I8CCDUa19YrTu4iPgAAAYQ"]
[Thu Jul 30 12:59:16.248787 2026] [security2:error] [pid 822943:tid 823109] [client 49.47.129.143:40810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuQ8o8CCDUa19YrTu4iGgAAAS4"], referer: http://pkf.jo
[Thu Jul 30 12:59:16.262290 2026] [security2:error] [pid 822943:tid 823140] [client 182.9.34.61:19635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuQ8o8CCDUa19YrTu4iIAAAAU0"], referer: http://pkf.jo
[Thu Jul 30 12:59:16.263252 2026] [security2:error] [pid 822943:tid 823159] [client 24.115.228.145:60052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuQ8o8CCDUa19YrTu4iHAAAAWA"], referer: http://pkf.jo
[Thu Jul 30 12:59:16.446406 2026] [security2:error] [pid 822943:tid 823181] [client 172.237.109.114:14798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ9I8CCDUa19YrTu4iOQAAAXY"]
[Thu Jul 30 12:59:16.506067 2026] [security2:error] [pid 822943:tid 823094] [client 200.118.80.135:2862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuQ9I8CCDUa19YrTu4iPQAAAR8"], referer: http://pkf.jo
[Thu Jul 30 12:59:16.512634 2026] [security2:error] [pid 822943:tid 823074] [client 181.46.71.237:26859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuQ848CCDUa19YrTu4iLAAAAQs"], referer: http://pkf.jo
[Thu Jul 30 12:59:16.670835 2026] [security2:error] [pid 822943:tid 823073] [client 20.171.55.167:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "amuQ9I8CCDUa19YrTu4iSQAAAQo"]
[Thu Jul 30 12:59:17.052551 2026] [core:notice] [pid 822943:tid 823087] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:17.254281 2026] [authz_core:error] [pid 822943:tid 823125] [client 172.236.9.101:48941] AH01630: client denied by server configuration: /home1/oojhflte/public_html/.htpasswd
[Thu Jul 30 12:59:17.379142 2026] [security2:error] [pid 822943:tid 823116] [client 20.171.55.167:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "amuQ9Y8CCDUa19YrTu4iZgAAATU"]
[Thu Jul 30 12:59:18.140029 2026] [security2:error] [pid 822943:tid 823187] [client 20.171.55.167:4524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/xmrlpc.php"] [unique_id "amuQ9o8CCDUa19YrTu4idgAAAXw"]
[Thu Jul 30 12:59:18.726248 2026] [security2:error] [pid 822943:tid 823200] [client 172.236.9.101:4512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ9o8CCDUa19YrTu4idwAAAYk"]
[Thu Jul 30 12:59:18.859137 2026] [security2:error] [pid 822943:tid 823176] [client 20.171.55.167:4734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuQ9o8CCDUa19YrTu4igwAAAXE"]
[Thu Jul 30 12:59:19.727161 2026] [security2:error] [pid 822943:tid 823175] [client 172.236.9.101:23385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ948CCDUa19YrTu4ijQAAAXA"]
[Thu Jul 30 12:59:20.607236 2026] [security2:error] [pid 822943:tid 823113] [client 172.213.232.128:6077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/geju.php"] [unique_id "amuQ-I8CCDUa19YrTu4iqwAAATI"]
[Thu Jul 30 12:59:21.025109 2026] [security2:error] [pid 822943:tid 823135] [client 150.107.232.194:27315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ-Y8CCDUa19YrTu4isgAAAUg"]
[Thu Jul 30 12:59:21.025208 2026] [security2:error] [pid 822943:tid 823135] [client 150.107.232.194:27315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuQ-Y8CCDUa19YrTu4isgAAAUg"]
[Thu Jul 30 12:59:21.198520 2026] [security2:error] [pid 822943:tid 822954] [remote 216.73.216.152:48801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuQ-Y8CCDUa19YrTu4itwABhAo"]
[Thu Jul 30 12:59:23.452994 2026] [security2:error] [pid 822943:tid 823193] [client 172.213.232.128:7641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuQ-48CCDUa19YrTu4i5wAAAYI"]
[Thu Jul 30 12:59:24.829491 2026] [security2:error] [pid 822943:tid 823191] [client 172.236.9.101:51899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuQ_I8CCDUa19YrTu4i-gAAAYA"]
[Thu Jul 30 12:59:25.167911 2026] [security2:error] [pid 822943:tid 823186] [client 172.213.232.128:6029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp.php"] [unique_id "amuQ_Y8CCDUa19YrTu4jDwAAAXs"]
[Thu Jul 30 12:59:26.028121 2026] [security2:error] [pid 822943:tid 823096] [client 172.213.232.128:43388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/aaa.php"] [unique_id "amuQ_o8CCDUa19YrTu4jIwAAASE"]
[Thu Jul 30 12:59:26.764909 2026] [security2:error] [pid 822943:tid 823154] [client 94.154.43.185:47130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "milfordauto.com"] [uri "/.env"] [unique_id "amuQ_o8CCDUa19YrTu4jMwAAAVs"]
[Thu Jul 30 12:59:26.774316 2026] [security2:error] [pid 822943:tid 823000] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ_o8CCDUa19YrTu4jNAABYzg"]
[Thu Jul 30 12:59:26.774495 2026] [security2:error] [pid 822943:tid 823162] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuQ_o8CCDUa19YrTu4jNAABYzg"]
[Thu Jul 30 12:59:26.800536 2026] [security2:error] [pid 822943:tid 822974] [remote 103.75.185.95:51780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahm.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuQ_o8CCDUa19YrTu4jNQABhx4"]
[Thu Jul 30 12:59:26.844042 2026] [security2:error] [pid 822943:tid 823131] [client 172.213.232.128:2749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/hoot.php"] [unique_id "amuQ_o8CCDUa19YrTu4jNgAAAUQ"]
[Thu Jul 30 12:59:27.444046 2026] [security2:error] [pid 822943:tid 823181] [client 172.213.232.128:7655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/about.php"] [unique_id "amuQ_48CCDUa19YrTu4jTgAAAXY"]
[Thu Jul 30 12:59:27.634481 2026] [security2:error] [pid 822943:tid 823160] [client 213.152.161.240:34172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuQ_48CCDUa19YrTu4jVQAAAWE"]
[Thu Jul 30 12:59:27.634588 2026] [security2:error] [pid 822943:tid 823160] [client 213.152.161.240:34172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuQ_48CCDUa19YrTu4jVQAAAWE"]
[Thu Jul 30 12:59:27.684069 2026] [security2:error] [pid 822943:tid 823120] [client 74.7.175.164:40054] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pnimanpower.net"] [uri "/cgi-sys/404.html"] [unique_id "amuQ_48CCDUa19YrTu4jVgABOT8"]
[Thu Jul 30 12:59:28.085246 2026] [security2:error] [pid 822943:tid 823092] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuQ_48CCDUa19YrTu4jUQAAAR0"]
[Thu Jul 30 12:59:28.670195 2026] [security2:error] [pid 822943:tid 823075] [client 172.213.232.128:6058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/admin.php"] [unique_id "amuRAI8CCDUa19YrTu4jcwAAAQw"]
[Thu Jul 30 12:59:29.084079 2026] [security2:error] [pid 822943:tid 823045] [remote 72.167.132.114:60916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amuRAY8CCDUa19YrTu4jeAABYGU"]
[Thu Jul 30 12:59:29.100788 2026] [security2:error] [pid 822943:tid 823077] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRAI8CCDUa19YrTu4jbgAAAQ4"]
[Thu Jul 30 12:59:30.665582 2026] [security2:error] [pid 822943:tid 823127] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jigAAAUA"]
[Thu Jul 30 12:59:30.739130 2026] [security2:error] [pid 822943:tid 823130] [client 156.229.21.54:43028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.yxe.zzt.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amuRAo8CCDUa19YrTu4jlwAAAUM"]
[Thu Jul 30 12:59:31.474410 2026] [security2:error] [pid 822943:tid 823159] [client 150.107.232.194:27270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRA48CCDUa19YrTu4jwgAAAWA"]
[Thu Jul 30 12:59:31.474641 2026] [security2:error] [pid 822943:tid 823159] [client 150.107.232.194:27270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRA48CCDUa19YrTu4jwgAAAWA"]
[Thu Jul 30 12:59:31.986922 2026] [core:error] [pid 822943:tid 823156] [client 44.195.188.79:1745] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:31.986953 2026] [core:error] [pid 822943:tid 823156] [client 44.195.188.79:1745] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:32.145494 2026] [security2:error] [pid 822943:tid 822955] [remote 74.7.241.59:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuRBI8CCDUa19YrTu4j1AABEgs"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/insert-headers-and-footers/includes
[Thu Jul 30 12:59:32.410114 2026] [security2:error] [pid 822943:tid 823102] [client 172.237.109.114:18085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jnwAAASc"]
[Thu Jul 30 12:59:32.413935 2026] [security2:error] [pid 822943:tid 823138] [client 172.213.232.128:17199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuRBI8CCDUa19YrTu4j2wAAAUs"]
[Thu Jul 30 12:59:32.418985 2026] [security2:error] [pid 822943:tid 823076] [client 172.237.109.114:27361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jpwAAAQ0"]
[Thu Jul 30 12:59:32.423816 2026] [security2:error] [pid 822943:tid 823175] [client 172.237.109.114:56789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jogAAAXA"]
[Thu Jul 30 12:59:32.430387 2026] [security2:error] [pid 822943:tid 823080] [client 172.237.109.114:44670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jpQAAARE"]
[Thu Jul 30 12:59:32.430815 2026] [security2:error] [pid 822943:tid 823183] [client 172.237.109.114:15834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4joAAAAXg"]
[Thu Jul 30 12:59:32.433971 2026] [security2:error] [pid 822943:tid 823150] [client 172.237.109.114:57713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jpAAAAVc"]
[Thu Jul 30 12:59:32.438538 2026] [security2:error] [pid 822943:tid 823074] [client 172.237.109.114:37718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4joQAAAQs"]
[Thu Jul 30 12:59:32.448206 2026] [security2:error] [pid 822943:tid 823090] [client 172.237.109.114:49814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jqQAAARs"]
[Thu Jul 30 12:59:32.457687 2026] [security2:error] [pid 822943:tid 823155] [client 172.237.109.114:33410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jrQAAAVw"]
[Thu Jul 30 12:59:32.461133 2026] [security2:error] [pid 822943:tid 823087] [client 172.237.109.114:63931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jqgAAARg"]
[Thu Jul 30 12:59:32.477634 2026] [security2:error] [pid 822943:tid 823152] [client 172.237.109.114:13933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jqAAAAVk"]
[Thu Jul 30 12:59:32.490220 2026] [security2:error] [pid 822943:tid 823121] [client 172.237.109.114:50581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRA48CCDUa19YrTu4jsQAAATo"]
[Thu Jul 30 12:59:32.493832 2026] [security2:error] [pid 822943:tid 823141] [client 172.237.109.114:47983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRA48CCDUa19YrTu4jsgAAAU4"]
[Thu Jul 30 12:59:32.494369 2026] [security2:error] [pid 822943:tid 823092] [client 172.237.109.114:29318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jpgAAAR0"]
[Thu Jul 30 12:59:32.497781 2026] [security2:error] [pid 822943:tid 823085] [client 172.237.109.114:41911] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jqwAAARY"]
[Thu Jul 30 12:59:32.499054 2026] [security2:error] [pid 822943:tid 823100] [client 172.237.109.114:32716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRA48CCDUa19YrTu4jrgAAASU"]
[Thu Jul 30 12:59:32.502726 2026] [security2:error] [pid 822943:tid 823139] [client 172.237.109.114:27281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jowAAAUw"]
[Thu Jul 30 12:59:32.554479 2026] [security2:error] [pid 822943:tid 823106] [client 172.237.109.114:35195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRA48CCDUa19YrTu4jrwAAASs"]
[Thu Jul 30 12:59:32.557546 2026] [security2:error] [pid 822943:tid 823194] [client 172.237.109.114:22047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRAo8CCDUa19YrTu4jrAAAAYM"]
[Thu Jul 30 12:59:32.568030 2026] [security2:error] [pid 822943:tid 823188] [client 172.237.109.114:50147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRA48CCDUa19YrTu4jsAAAAX0"]
[Thu Jul 30 12:59:33.339342 2026] [core:notice] [pid 822943:tid 823070] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:33.796052 2026] [security2:error] [pid 822943:tid 823128] [client 172.213.232.128:2409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuRBY8CCDUa19YrTu4kBAAAAUE"]
[Thu Jul 30 12:59:34.139500 2026] [security2:error] [pid 822943:tid 823064] [remote 57.141.0.17:21026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/24984966950/feed/rss2/"] [unique_id "amuRBo8CCDUa19YrTu4kDgABe3g"]
[Thu Jul 30 12:59:34.821285 2026] [security2:error] [pid 822943:tid 823155] [client 131.226.102.36:39342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuRBo8CCDUa19YrTu4kFQABXAo"]
[Thu Jul 30 12:59:35.274593 2026] [core:notice] [pid 822943:tid 823101] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:35.390438 2026] [security2:error] [pid 822943:tid 823158] [client 172.213.232.128:2425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuRB48CCDUa19YrTu4kLQAAAV8"]
[Thu Jul 30 12:59:36.090599 2026] [core:notice] [pid 822943:tid 823114] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:37.611608 2026] [security2:error] [pid 822943:tid 822957] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRCY8CCDUa19YrTu4kdAABYg0"]
[Thu Jul 30 12:59:37.611841 2026] [security2:error] [pid 822943:tid 823161] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRCY8CCDUa19YrTu4kdAABYg0"]
[Thu Jul 30 12:59:38.351382 2026] [security2:error] [pid 822943:tid 823077] [client 204.8.98.105:56688] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuRCo8CCDUa19YrTu4kgAAAAQ4"]
[Thu Jul 30 12:59:38.351520 2026] [security2:error] [pid 822943:tid 823077] [client 204.8.98.105:56688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuRCo8CCDUa19YrTu4kgAAAAQ4"]
[Thu Jul 30 12:59:39.075646 2026] [security2:error] [pid 822943:tid 823140] [client 43.173.177.22:51436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.177.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amuRC48CCDUa19YrTu4kmgAAAU0"]
[Thu Jul 30 12:59:39.810759 2026] [core:notice] [pid 822943:tid 823109] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:39.815223 2026] [security2:error] [pid 822943:tid 823109] [client 43.173.177.60:40652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amuRC48CCDUa19YrTu4kvQAAAS4"], referer: https://carnetdeshopping.com/index.php/typography/
[Thu Jul 30 12:59:40.271967 2026] [security2:error] [pid 822943:tid 823012] [remote 57.141.0.58:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuRDI8CCDUa19YrTu4kxwABLEQ"]
[Thu Jul 30 12:59:40.769891 2026] [core:notice] [pid 822943:tid 823092] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:40.935287 2026] [security2:error] [pid 822943:tid 823084] [client 172.213.232.128:17175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuRDI8CCDUa19YrTu4k4AAAARU"]
[Thu Jul 30 12:59:40.957525 2026] [security2:error] [pid 822943:tid 823099] [client 5.161.62.209:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koidomino.click"] [uri "/.env"] [unique_id "amuRDI8CCDUa19YrTu4k4QAAASQ"]
[Thu Jul 30 12:59:41.291729 2026] [security2:error] [pid 822943:tid 823103] [client 34.162.230.222:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuRDY8CCDUa19YrTu4k5QAAASg"]
[Thu Jul 30 12:59:41.603054 2026] [security2:error] [pid 822943:tid 823125] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRDY8CCDUa19YrTu4k5AAAAT4"]
[Thu Jul 30 12:59:41.847057 2026] [security2:error] [pid 822943:tid 823114] [client 172.213.232.128:7654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuRDY8CCDUa19YrTu4lEgAAATM"]
[Thu Jul 30 12:59:41.945668 2026] [security2:error] [pid 822943:tid 823116] [client 150.107.232.194:27488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRDY8CCDUa19YrTu4lGgAAATU"]
[Thu Jul 30 12:59:41.945773 2026] [security2:error] [pid 822943:tid 823116] [client 150.107.232.194:27488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRDY8CCDUa19YrTu4lGgAAATU"]
[Thu Jul 30 12:59:42.885182 2026] [security2:error] [pid 822943:tid 823020] [remote 57.141.18.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRDo8CCDUa19YrTu4lNAABFkw"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum,cotton,plastic,polyester,steel,nylon&filter_size=large,medium,small,extra-small&unfilter=1
[Thu Jul 30 12:59:42.911452 2026] [core:error] [pid 822943:tid 823167] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:42.911475 2026] [core:error] [pid 822943:tid 823167] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:42.918857 2026] [core:error] [pid 822943:tid 823128] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:42.918877 2026] [core:error] [pid 822943:tid 823128] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:42.955193 2026] [core:error] [pid 822943:tid 823199] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:42.955219 2026] [core:error] [pid 822943:tid 823199] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:42.968809 2026] [security2:error] [pid 822943:tid 823053] [remote 57.141.18.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRDo8CCDUa19YrTu4lRAABC20"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum,cotton,plastic,polyester,steel,nylon&filter_size=large,medium,small,extra-small&unfilter=1
[Thu Jul 30 12:59:43.086610 2026] [core:error] [pid 822943:tid 823137] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:43.086638 2026] [core:error] [pid 822943:tid 823137] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:43.104790 2026] [core:error] [pid 822943:tid 823110] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:43.104814 2026] [core:error] [pid 822943:tid 823110] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:43.128539 2026] [core:error] [pid 822943:tid 823180] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:43.128563 2026] [core:error] [pid 822943:tid 823180] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:43.287182 2026] [security2:error] [pid 822943:tid 823148] [client 172.213.232.128:13557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuRD48CCDUa19YrTu4lWQAAAVU"]
[Thu Jul 30 12:59:43.849719 2026] [core:notice] [pid 822943:tid 823056] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:43.917852 2026] [security2:error] [pid 822943:tid 823138] [client 172.213.232.128:7647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuRD48CCDUa19YrTu4lbwAAAUs"]
[Thu Jul 30 12:59:44.606259 2026] [security2:error] [pid 822943:tid 823088] [client 172.213.232.128:43339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/content.php"] [unique_id "amuREI8CCDUa19YrTu4lhwAAARk"]
[Thu Jul 30 12:59:46.461384 2026] [security2:error] [pid 822943:tid 823184] [client 172.213.232.128:2719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuREo8CCDUa19YrTu4l0wAAAXk"]
[Thu Jul 30 12:59:46.626373 2026] [security2:error] [pid 822943:tid 823179] [client 101.53.228.92:11788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuREo8CCDUa19YrTu4lyQAAAXQ"], referer: http://pkf.jo
[Thu Jul 30 12:59:46.979963 2026] [security2:error] [pid 822943:tid 823125] [client 88.230.179.16:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuREo8CCDUa19YrTu4l1gAAAT4"], referer: http://pkf.jo
[Thu Jul 30 12:59:46.992455 2026] [security2:error] [pid 822943:tid 822968] [remote 57.141.0.10:50978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/56555984686/feed/rss2/"] [unique_id "amuREo8CCDUa19YrTu4l4wABUxg"]
[Thu Jul 30 12:59:47.602092 2026] [security2:error] [pid 822943:tid 823086] [client 181.42.206.69:2988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRE48CCDUa19YrTu4l6gAAARc"], referer: http://pkf.jo
[Thu Jul 30 12:59:48.105549 2026] [core:notice] [pid 822943:tid 823118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:48.355257 2026] [security2:error] [pid 822943:tid 822951] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRFI8CCDUa19YrTu4mCgABVQc"]
[Thu Jul 30 12:59:48.355407 2026] [security2:error] [pid 822943:tid 823148] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRFI8CCDUa19YrTu4mCgABVQc"]
[Thu Jul 30 12:59:49.371736 2026] [security2:error] [pid 822943:tid 823105] [client 151.252.108.224:35951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRFY8CCDUa19YrTu4mHgAAASo"], referer: http://pkf.jo
[Thu Jul 30 12:59:49.758948 2026] [security2:error] [pid 822943:tid 823175] [client 186.121.167.19:31356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRFY8CCDUa19YrTu4mLgAAAXA"], referer: http://pkf.jo
[Thu Jul 30 12:59:50.053097 2026] [security2:error] [pid 822943:tid 823138] [client 143.208.75.221:62392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRFY8CCDUa19YrTu4mNgAAAUs"], referer: http://pkf.jo
[Thu Jul 30 12:59:50.083301 2026] [security2:error] [pid 822943:tid 823084] [client 172.213.232.128:43338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuRFo8CCDUa19YrTu4mRgAAARU"]
[Thu Jul 30 12:59:50.219885 2026] [security2:error] [pid 822943:tid 823165] [client 190.242.27.25:51822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRFY8CCDUa19YrTu4mPAAAAWY"], referer: http://pkf.jo
[Thu Jul 30 12:59:50.747182 2026] [security2:error] [pid 822943:tid 823081] [client 49.33.236.178:46358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRFo8CCDUa19YrTu4mVQAAARI"], referer: http://pkf.jo
[Thu Jul 30 12:59:50.752958 2026] [autoindex:error] [pid 822943:tid 823153] [client 20.78.152.57:1614] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:59:51.339722 2026] [security2:error] [pid 822943:tid 823083] [client 172.213.232.128:43315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuRF48CCDUa19YrTu4mdAAAARQ"]
[Thu Jul 30 12:59:51.990027 2026] [core:error] [pid 822943:tid 823099] [client 74.7.241.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:51.990049 2026] [core:error] [pid 822943:tid 823099] [client 74.7.241.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 12:59:51.990197 2026] [security2:error] [pid 822943:tid 823099] [client 74.7.241.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.jgp.fxh.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuRF48CCDUa19YrTu4mnAAAASQ"]
[Thu Jul 30 12:59:51.990847 2026] [security2:error] [pid 822943:tid 823158] [client 74.7.241.186:42758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.jgp.fxh.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuRF48CCDUa19YrTu4mmAABXxM"]
[Thu Jul 30 12:59:52.068916 2026] [security2:error] [pid 822943:tid 823151] [client 105.127.6.168:23623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRF48CCDUa19YrTu4mgQAAAVg"], referer: http://pkf.jo
[Thu Jul 30 12:59:52.226162 2026] [security2:error] [pid 822943:tid 823093] [client 172.213.232.128:2865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuRGI8CCDUa19YrTu4moQAAAR4"]
[Thu Jul 30 12:59:52.414176 2026] [security2:error] [pid 822943:tid 823148] [client 150.107.232.194:26684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRGI8CCDUa19YrTu4mpQAAAVU"]
[Thu Jul 30 12:59:52.414292 2026] [security2:error] [pid 822943:tid 823148] [client 150.107.232.194:26684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRGI8CCDUa19YrTu4mpQAAAVU"]
[Thu Jul 30 12:59:52.817569 2026] [autoindex:error] [pid 822943:tid 823162] [client 103.226.142.125:60424] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:59:53.088744 2026] [autoindex:error] [pid 822943:tid 823119] [client 103.226.142.125:60436] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:59:53.212937 2026] [security2:error] [pid 822943:tid 823156] [client 172.213.232.128:2752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuRGY8CCDUa19YrTu4mxAAAAV0"]
[Thu Jul 30 12:59:53.396653 2026] [autoindex:error] [pid 822943:tid 823022] [remote 3.225.222.228:0] AH01276: Cannot serve directory /home2/kevudite/dl.truckersofeuropemod.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 12:59:53.896758 2026] [security2:error] [pid 822943:tid 823114] [client 172.213.232.128:22150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuRGY8CCDUa19YrTu4m6QAAATM"]
[Thu Jul 30 12:59:55.325220 2026] [security2:error] [pid 822943:tid 823138] [client 172.213.232.128:22164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuRG48CCDUa19YrTu4nDgAAAUs"]
[Thu Jul 30 12:59:56.228185 2026] [security2:error] [pid 822943:tid 823161] [client 172.213.232.128:19253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuRHI8CCDUa19YrTu4nQAAAAWI"]
[Thu Jul 30 12:59:56.316999 2026] [security2:error] [pid 822943:tid 823104] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRG48CCDUa19YrTu4nGwAAASk"]
[Thu Jul 30 12:59:57.577678 2026] [security2:error] [pid 822943:tid 823095] [client 172.237.109.114:55224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nLQAAASA"]
[Thu Jul 30 12:59:57.587695 2026] [security2:error] [pid 822943:tid 823082] [client 172.237.109.114:26823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nKwAAARM"]
[Thu Jul 30 12:59:57.734300 2026] [security2:error] [pid 822943:tid 823149] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nWQABVnc"]
[Thu Jul 30 12:59:57.924882 2026] [core:notice] [pid 822943:tid 823085] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:58.155400 2026] [security2:error] [pid 822943:tid 823086] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amuRHY8CCDUa19YrTu4ncgAAARc"], referer: https://skcarrental.ae/tag/dollar-rent-car-dubai-airport-terminal-3/
[Thu Jul 30 12:59:58.217428 2026] [security2:error] [pid 822943:tid 823166] [client 172.237.109.114:21522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nMwAAAWc"]
[Thu Jul 30 12:59:58.221249 2026] [security2:error] [pid 822943:tid 823081] [client 172.237.109.114:44388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nMAAAARI"]
[Thu Jul 30 12:59:58.234124 2026] [security2:error] [pid 822943:tid 823159] [client 172.237.109.114:47990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nNgAAAWA"]
[Thu Jul 30 12:59:58.234221 2026] [security2:error] [pid 822943:tid 823089] [client 172.237.109.114:42146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nNAAAARo"]
[Thu Jul 30 12:59:58.234420 2026] [security2:error] [pid 822943:tid 823196] [client 172.237.109.114:25833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nMQAAAYU"]
[Thu Jul 30 12:59:58.241405 2026] [security2:error] [pid 822943:tid 823118] [client 172.237.109.114:36197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nNQAAATc"]
[Thu Jul 30 12:59:58.249885 2026] [security2:error] [pid 822943:tid 823198] [client 172.237.109.114:50839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nLAAAAYc"]
[Thu Jul 30 12:59:58.255585 2026] [security2:error] [pid 822943:tid 823178] [client 172.237.109.114:39909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nKQAAAXM"]
[Thu Jul 30 12:59:58.265531 2026] [security2:error] [pid 822943:tid 823132] [client 172.237.109.114:17539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nMgAAAUU"]
[Thu Jul 30 12:59:58.265610 2026] [security2:error] [pid 822943:tid 823153] [client 172.237.109.114:3114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nLgAAAVo"]
[Thu Jul 30 12:59:58.274619 2026] [security2:error] [pid 822943:tid 823130] [client 172.237.109.114:35453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nOQAAAUM"]
[Thu Jul 30 12:59:58.277100 2026] [security2:error] [pid 822943:tid 823186] [client 172.237.109.114:63586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nKgAAAXs"]
[Thu Jul 30 12:59:58.304362 2026] [security2:error] [pid 822943:tid 823145] [client 172.237.109.114:9442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nOAAAAVI"]
[Thu Jul 30 12:59:58.306507 2026] [security2:error] [pid 822943:tid 823158] [client 172.237.109.114:40291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nLwAAAV8"]
[Thu Jul 30 12:59:58.321782 2026] [security2:error] [pid 822943:tid 823094] [client 172.237.109.114:24031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nNwAAAR8"]
[Thu Jul 30 12:59:58.367940 2026] [security2:error] [pid 822943:tid 823123] [client 172.237.109.114:4338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nOwAAATw"]
[Thu Jul 30 12:59:58.391398 2026] [security2:error] [pid 822943:tid 823173] [client 172.237.109.114:44076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nOgAAAW4"]
[Thu Jul 30 12:59:58.498339 2026] [core:notice] [pid 822943:tid 823197] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:58.510518 2026] [security2:error] [pid 822943:tid 823078] [client 172.237.109.114:7507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRHI8CCDUa19YrTu4nPAAAAQ8"]
[Thu Jul 30 12:59:59.294577 2026] [security2:error] [pid 822943:tid 822961] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRH48CCDUa19YrTu4nmgABhRE"]
[Thu Jul 30 12:59:59.294734 2026] [security2:error] [pid 822943:tid 823196] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRH48CCDUa19YrTu4nmgABhRE"]
[Thu Jul 30 12:59:59.458881 2026] [security2:error] [pid 822943:tid 823171] [client 43.157.180.116:49000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.180.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuRH48CCDUa19YrTu4npAAAAWw"]
[Thu Jul 30 12:59:59.628890 2026] [core:notice] [pid 822943:tid 823192] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 12:59:59.976675 2026] [security2:error] [pid 822943:tid 823124] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRH48CCDUa19YrTu4noAAAAT0"]
[Thu Jul 30 13:00:00.773881 2026] [security2:error] [pid 822943:tid 822964] [remote 74.7.241.60:40262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/feed/img/js/uploads/partners/uploads/partners/uploads/partners/mediaf.php"] [unique_id "amuRII8CCDUa19YrTu4nyQABFhQ"], referer: https://aded-rdc.org/feed/img/js/uploads/partners/uploads/partners/uploads/partners/login.php
[Thu Jul 30 13:00:00.911590 2026] [core:notice] [pid 822943:tid 823177] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:01.178578 2026] [security2:error] [pid 822943:tid 823195] [client 172.213.232.128:2766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuRIY8CCDUa19YrTu4n0gAAAYQ"]
[Thu Jul 30 13:00:01.228647 2026] [security2:error] [pid 822943:tid 823189] [client 198.11.177.243:59176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.177.11.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serverkr.com"] [uri "/board/list.php"] [unique_id "amuRII8CCDUa19YrTu4nzgAAAX4"]
[Thu Jul 30 13:00:01.548547 2026] [security2:error] [pid 822943:tid 823134] [client 193.47.62.167:49174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "montageluxuryhotel-com.evm.udi.temporary.site"] [uri "/index.php"] [unique_id "amuRII8CCDUa19YrTu4nuQAAAUc"]
[Thu Jul 30 13:00:01.984086 2026] [security2:error] [pid 822943:tid 822986] [remote 57.141.18.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRIY8CCDUa19YrTu4n5wABNCo"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,linen,polyester,wood&rating=5&status=instock&tax_product_cat=furniture&min_price=200&max_price=300&unfilter=1
[Thu Jul 30 13:00:01.999959 2026] [security2:error] [pid 822943:tid 823175] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRIY8CCDUa19YrTu4n2QAAAXA"]
[Thu Jul 30 13:00:02.020181 2026] [security2:error] [pid 822943:tid 822978] [remote 57.141.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRIY8CCDUa19YrTu4n6QABUyI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,linen,polyester,wood&rating=5&status=instock&tax_product_cat=furniture&min_price=200&max_price=300&unfilter=1
[Thu Jul 30 13:00:02.170456 2026] [security2:error] [pid 822943:tid 823075] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRIY8CCDUa19YrTu4n4wAAAQw"]
[Thu Jul 30 13:00:02.205147 2026] [security2:error] [pid 822943:tid 823174] [client 172.213.232.128:19250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuRIo8CCDUa19YrTu4n-gAAAW8"]
[Thu Jul 30 13:00:02.586357 2026] [core:notice] [pid 822943:tid 823193] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:02.913629 2026] [security2:error] [pid 822943:tid 823120] [client 150.107.232.194:26807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRIo8CCDUa19YrTu4oEAAAATk"]
[Thu Jul 30 13:00:02.913729 2026] [security2:error] [pid 822943:tid 823120] [client 150.107.232.194:26807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRIo8CCDUa19YrTu4oEAAAATk"]
[Thu Jul 30 13:00:03.122675 2026] [core:error] [pid 822943:tid 822990] [remote 74.7.175.163:36826] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:03.122702 2026] [core:error] [pid 822943:tid 822990] [remote 74.7.175.163:36826] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:03.122921 2026] [security2:error] [pid 822943:tid 823140] [client 74.7.175.163:36826] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "blueskyroofingco.shop"] [uri "/index.php"] [unique_id "amuRI48CCDUa19YrTu4oFgABTS4"]
[Thu Jul 30 13:00:03.309115 2026] [fcgid:warn] [pid 822943:tid 823119] (70014)End of file found: [client 152.32.145.49:34938] mod_fcgid: can't get data from http client
[Thu Jul 30 13:00:03.399268 2026] [security2:error] [pid 822943:tid 823147] [client 172.213.232.128:2798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuRI48CCDUa19YrTu4oIAAAAVQ"]
[Thu Jul 30 13:00:04.178254 2026] [security2:error] [pid 822943:tid 823110] [client 172.213.232.128:7603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/about.php"] [unique_id "amuRJI8CCDUa19YrTu4oOgAAAS8"]
[Thu Jul 30 13:00:04.230961 2026] [security2:error] [pid 822943:tid 823126] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRI48CCDUa19YrTu4oKQAAAT8"]
[Thu Jul 30 13:00:04.887913 2026] [security2:error] [pid 822943:tid 823143] [client 172.213.232.128:7556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/.well-known/about.php"] [unique_id "amuRJI8CCDUa19YrTu4oSgAAAVA"]
[Thu Jul 30 13:00:05.485427 2026] [core:notice] [pid 822943:tid 823154] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:05.636006 2026] [proxy:error] [pid 822943:tid 823078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:00:05.636060 2026] [proxy_http:error] [pid 822943:tid 823078] [client 34.239.240.237:52558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:00:05.636747 2026] [proxy:error] [pid 822943:tid 823078] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:00:05.636790 2026] [proxy_http:error] [pid 822943:tid 823078] [client 34.239.240.237:52558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:00:05.763854 2026] [security2:error] [pid 822943:tid 823077] [client 172.213.232.128:2872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuRJY8CCDUa19YrTu4oZQAAAQ4"]
[Thu Jul 30 13:00:05.860873 2026] [security2:error] [pid 822943:tid 822963] [remote 57.141.0.39:50106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuRJY8CCDUa19YrTu4oZgABNBM"]
[Thu Jul 30 13:00:06.158018 2026] [security2:error] [pid 822943:tid 823104] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRJY8CCDUa19YrTu4oXwAAASk"]
[Thu Jul 30 13:00:06.744359 2026] [security2:error] [pid 822943:tid 823190] [client 172.236.9.101:21331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRJo8CCDUa19YrTu4ocAAAAX8"]
[Thu Jul 30 13:00:09.147059 2026] [security2:error] [pid 822943:tid 823126] [client 74.7.244.57:36510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ais.njr.temporary.site"] [uri "/robots.txt"] [unique_id "amuRKY8CCDUa19YrTu4opQAAAT8"]
[Thu Jul 30 13:00:10.060091 2026] [security2:error] [pid 822943:tid 823050] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRKo8CCDUa19YrTu4ovgABX2o"]
[Thu Jul 30 13:00:10.060260 2026] [security2:error] [pid 822943:tid 823158] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRKo8CCDUa19YrTu4ovgABX2o"]
[Thu Jul 30 13:00:10.588119 2026] [security2:error] [pid 822943:tid 823199] [client 51.68.111.207:20369] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "journeywomenscenter.org"] [uri "/robots.txt"] [unique_id "amuRKo8CCDUa19YrTu4oygAAAYg"]
[Thu Jul 30 13:00:10.588226 2026] [security2:error] [pid 822943:tid 823199] [client 51.68.111.207:20369] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "journeywomenscenter.org"] [uri "/robots.txt"] [unique_id "amuRKo8CCDUa19YrTu4oygAAAYg"]
[Thu Jul 30 13:00:11.795658 2026] [security2:error] [pid 822943:tid 823102] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuRK48CCDUa19YrTu4o4wAAASc"]
[Thu Jul 30 13:00:12.073564 2026] [security2:error] [pid 822943:tid 823149] [client 172.213.232.128:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuRLI8CCDUa19YrTu4o7wAAAVY"]
[Thu Jul 30 13:00:12.759673 2026] [security2:error] [pid 822943:tid 823193] [client 172.213.232.128:7575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/img/about.php"] [unique_id "amuRLI8CCDUa19YrTu4o-gAAAYI"]
[Thu Jul 30 13:00:13.337149 2026] [security2:error] [pid 822943:tid 823177] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRLI8CCDUa19YrTu4o-QABcgE"]
[Thu Jul 30 13:00:13.483410 2026] [security2:error] [pid 822943:tid 823186] [client 150.107.232.194:27011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRLY8CCDUa19YrTu4pDgAAAXs"]
[Thu Jul 30 13:00:13.483534 2026] [security2:error] [pid 822943:tid 823186] [client 150.107.232.194:27011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRLY8CCDUa19YrTu4pDgAAAXs"]
[Thu Jul 30 13:00:14.412194 2026] [security2:error] [pid 822943:tid 823174] [client 172.213.232.128:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuRLo8CCDUa19YrTu4pJQAAAW8"]
[Thu Jul 30 13:00:14.814142 2026] [security2:error] [pid 822943:tid 823181] [client 193.148.16.211:51602] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuRLo8CCDUa19YrTu4pMgAAAXY"]
[Thu Jul 30 13:00:14.814257 2026] [security2:error] [pid 822943:tid 823181] [client 193.148.16.211:51602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuRLo8CCDUa19YrTu4pMgAAAXY"]
[Thu Jul 30 13:00:15.082558 2026] [security2:error] [pid 822943:tid 823159] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuRLo8CCDUa19YrTu4pNQAAAWA"]
[Thu Jul 30 13:00:15.255812 2026] [security2:error] [pid 822943:tid 823185] [client 213.152.161.240:51892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuRL48CCDUa19YrTu4pRgAAAXo"]
[Thu Jul 30 13:00:15.255918 2026] [security2:error] [pid 822943:tid 823185] [client 213.152.161.240:51892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuRL48CCDUa19YrTu4pRgAAAXo"]
[Thu Jul 30 13:00:15.948087 2026] [security2:error] [pid 822943:tid 823116] [client 172.213.232.128:64436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuRL48CCDUa19YrTu4pUgAAATU"]
[Thu Jul 30 13:00:16.823485 2026] [security2:error] [pid 822943:tid 823115] [client 172.213.232.128:64385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuRMI8CCDUa19YrTu4pZwAAATQ"]
[Thu Jul 30 13:00:17.049848 2026] [security2:error] [pid 822943:tid 823194] [client 85.204.70.116:23708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smoke-tfhk.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuRMY8CCDUa19YrTu4paAAAAYM"]
[Thu Jul 30 13:00:17.340007 2026] [security2:error] [pid 822943:tid 823083] [client 85.204.70.116:49426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuRMY8CCDUa19YrTu4pegAAARQ"]
[Thu Jul 30 13:00:17.445856 2026] [security2:error] [pid 822943:tid 823076] [client 172.213.232.128:9519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuRMY8CCDUa19YrTu4pewAAAQ0"]
[Thu Jul 30 13:00:18.081769 2026] [security2:error] [pid 822943:tid 823167] [client 172.213.232.128:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuRMo8CCDUa19YrTu4pjgAAAWg"]
[Thu Jul 30 13:00:18.484301 2026] [security2:error] [pid 822943:tid 823144] [client 50.6.43.217:18628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amuRIo8CCDUa19YrTu4oEgAAAVE"]
[Thu Jul 30 13:00:19.001495 2026] [security2:error] [pid 822943:tid 823117] [client 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRMo8CCDUa19YrTu4pnAABNjI"]
[Thu Jul 30 13:00:19.070501 2026] [security2:error] [pid 822943:tid 823138] [client 103.205.174.57:48602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRMo8CCDUa19YrTu4ppQAAAUs"], referer: http://pkf.jo
[Thu Jul 30 13:00:19.130503 2026] [security2:error] [pid 822943:tid 823197] [client 66.249.73.96:65471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRMo8CCDUa19YrTu4ppgAAAYY"]
[Thu Jul 30 13:00:19.991404 2026] [security2:error] [pid 822943:tid 823085] [client 89.43.133.11:41688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRM48CCDUa19YrTu4pvAAAARY"], referer: http://pkf.jo
[Thu Jul 30 13:00:20.833362 2026] [fcgid:warn] [pid 822943:tid 823124] (70014)End of file found: [client 107.150.117.219:42222] mod_fcgid: can't get data from http client
[Thu Jul 30 13:00:20.879817 2026] [security2:error] [pid 822943:tid 823028] [remote 5.161.62.209:1994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.lxw.gpl.temporary.site"] [uri "/.env"] [unique_id "amuRNI8CCDUa19YrTu4p2AABiFQ"]
[Thu Jul 30 13:00:20.914573 2026] [security2:error] [pid 822943:tid 822963] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRNI8CCDUa19YrTu4p2QABRRM"]
[Thu Jul 30 13:00:20.914831 2026] [security2:error] [pid 822943:tid 823132] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRNI8CCDUa19YrTu4p2QABRRM"]
[Thu Jul 30 13:00:21.090993 2026] [security2:error] [pid 822943:tid 823119] [client 172.213.232.128:46186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuRNY8CCDUa19YrTu4p5wAAATg"]
[Thu Jul 30 13:00:21.504647 2026] [core:notice] [pid 822943:tid 823161] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:21.543012 2026] [security2:error] [pid 822943:tid 823117] [client 31.223.71.117:39366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRNY8CCDUa19YrTu4p6QAAATY"], referer: http://pkf.jo
[Thu Jul 30 13:00:21.544683 2026] [security2:error] [pid 822943:tid 823107] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRNI8CCDUa19YrTu4p1gABLEk"]
[Thu Jul 30 13:00:21.568910 2026] [security2:error] [pid 822943:tid 823127] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRNI8CCDUa19YrTu4p3wAAAUA"]
[Thu Jul 30 13:00:21.960088 2026] [core:error] [pid 822943:tid 823014] [remote 74.7.244.31:38154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:21.960112 2026] [core:error] [pid 822943:tid 823014] [remote 74.7.244.31:38154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:21.960256 2026] [security2:error] [pid 822943:tid 823160] [client 74.7.244.31:38154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "nimna.lk"] [uri "/index.php"] [unique_id "amuRNY8CCDUa19YrTu4p_AABYUY"]
[Thu Jul 30 13:00:22.000045 2026] [security2:error] [pid 822943:tid 823106] [client 172.213.232.128:9533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuRNY8CCDUa19YrTu4p_QAAASs"]
[Thu Jul 30 13:00:22.189385 2026] [security2:error] [pid 822943:tid 823128] [client 85.204.70.116:1911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuRNo8CCDUa19YrTu4qAwAAAUE"]
[Thu Jul 30 13:00:22.189484 2026] [security2:error] [pid 822943:tid 823128] [client 85.204.70.116:1911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuRNo8CCDUa19YrTu4qAwAAAUE"]
[Thu Jul 30 13:00:22.505244 2026] [security2:error] [pid 822943:tid 823087] [client 45.11.61.9:38852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRNo8CCDUa19YrTu4qBAAAARg"], referer: http://pkf.jo
[Thu Jul 30 13:00:22.801042 2026] [security2:error] [pid 822943:tid 823002] [remote 74.7.241.59:38822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuRNo8CCDUa19YrTu4qEQABUDo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/insert-headers-and-footers/includes
[Thu Jul 30 13:00:22.921671 2026] [security2:error] [pid 822943:tid 823184] [client 156.210.172.232:47614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRNo8CCDUa19YrTu4qDgAAAXk"], referer: http://pkf.jo
[Thu Jul 30 13:00:23.077569 2026] [security2:error] [pid 822943:tid 823112] [client 37.41.107.210:54536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRNo8CCDUa19YrTu4qEAAAATE"], referer: http://pkf.jo
[Thu Jul 30 13:00:23.452157 2026] [security2:error] [pid 822943:tid 823198] [client 187.223.214.198:47528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuRN48CCDUa19YrTu4qHgAAAYc"], referer: http://pkf.jo
[Thu Jul 30 13:00:23.631847 2026] [security2:error] [pid 822943:tid 823147] [client 172.213.232.128:9565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuRN48CCDUa19YrTu4qKwAAAVQ"]
[Thu Jul 30 13:00:23.942459 2026] [security2:error] [pid 822943:tid 823117] [client 150.107.232.194:27085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRN48CCDUa19YrTu4qMwAAATY"]
[Thu Jul 30 13:00:23.942573 2026] [security2:error] [pid 822943:tid 823117] [client 150.107.232.194:27085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRN48CCDUa19YrTu4qMwAAATY"]
[Thu Jul 30 13:00:24.501492 2026] [security2:error] [pid 822943:tid 823123] [client 104.210.56.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuRNo8CCDUa19YrTu4qDwABPFc"]
[Thu Jul 30 13:00:24.547753 2026] [security2:error] [pid 822943:tid 823196] [client 197.91.146.151:57186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuROI8CCDUa19YrTu4qOgAAAYU"], referer: http://pkf.jo
[Thu Jul 30 13:00:24.563050 2026] [security2:error] [pid 822943:tid 823197] [client 74.7.228.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-379a24ea.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuRN48CCDUa19YrTu4qJAAAAYY"]
[Thu Jul 30 13:00:24.563863 2026] [security2:error] [pid 822943:tid 823113] [client 74.7.228.45:33792] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-379a24ea.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuRN48CCDUa19YrTu4qIgABMmU"]
[Thu Jul 30 13:00:24.872082 2026] [security2:error] [pid 822943:tid 823127] [client 172.213.232.128:46203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuROI8CCDUa19YrTu4qRAAAAUA"]
[Thu Jul 30 13:00:24.939244 2026] [security2:error] [pid 822943:tid 823194] [client 20.151.221.234:63371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wk/index.php"] [unique_id "amuROI8CCDUa19YrTu4qRQAAAYM"]
[Thu Jul 30 13:00:25.660404 2026] [core:error] [pid 822943:tid 823117] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:25.660430 2026] [core:error] [pid 822943:tid 823117] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:25.663116 2026] [core:error] [pid 822943:tid 823105] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:25.663149 2026] [core:error] [pid 822943:tid 823105] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:25.671654 2026] [core:error] [pid 822943:tid 823096] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:25.671676 2026] [core:error] [pid 822943:tid 823096] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:25.895368 2026] [security2:error] [pid 822943:tid 823058] [remote 5.161.62.209:36146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.mahyarjewelry.co"] [uri "/.env"] [unique_id "amuROY8CCDUa19YrTu4qdgABbXI"]
[Thu Jul 30 13:00:25.915625 2026] [security2:error] [pid 822943:tid 823106] [client 172.213.232.128:9549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuROY8CCDUa19YrTu4qdwAAASs"]
[Thu Jul 30 13:00:26.052631 2026] [security2:error] [pid 822943:tid 823092] [client 20.151.221.234:22870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/av.php"] [unique_id "amuROo8CCDUa19YrTu4qewAAAR0"]
[Thu Jul 30 13:00:26.433347 2026] [security2:error] [pid 822943:tid 823111] [client 50.6.43.217:60040] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuROo8CCDUa19YrTu4qgwAAATA"]
[Thu Jul 30 13:00:26.463624 2026] [security2:error] [pid 822943:tid 823141] [client 50.6.43.217:60044] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuROo8CCDUa19YrTu4qhAAAAU4"]
[Thu Jul 30 13:00:26.569385 2026] [security2:error] [pid 822943:tid 823128] [client 43.130.139.136:43314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amuROo8CCDUa19YrTu4qfAAAAUE"]
[Thu Jul 30 13:00:26.716200 2026] [security2:error] [pid 822943:tid 823074] [client 172.213.232.128:46204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuROo8CCDUa19YrTu4qlQAAAQs"]
[Thu Jul 30 13:00:27.296892 2026] [core:error] [pid 822943:tid 823081] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:27.296915 2026] [core:error] [pid 822943:tid 823081] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:27.442839 2026] [security2:error] [pid 822943:tid 823181] [client 20.151.221.234:63369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/mini.php"] [unique_id "amuRO48CCDUa19YrTu4qqgAAAXY"]
[Thu Jul 30 13:00:27.826630 2026] [security2:error] [pid 822943:tid 823135] [client 50.6.43.217:60058] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuRO48CCDUa19YrTu4qtgAAAUg"]
[Thu Jul 30 13:00:28.428404 2026] [security2:error] [pid 822943:tid 823074] [client 20.151.221.234:63370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/aa.php"] [unique_id "amuRPI8CCDUa19YrTu4qzgAAAQs"]
[Thu Jul 30 13:00:28.569552 2026] [core:notice] [pid 822943:tid 823134] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:28.589790 2026] [security2:error] [pid 822943:tid 823173] [client 172.213.232.128:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuRPI8CCDUa19YrTu4q0QAAAW4"]
[Thu Jul 30 13:00:28.658144 2026] [core:notice] [pid 822943:tid 823084] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:29.269660 2026] [security2:error] [pid 822943:tid 823104] [client 50.6.43.217:60062] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuRPY8CCDUa19YrTu4q5AAAASk"]
[Thu Jul 30 13:00:29.284660 2026] [security2:error] [pid 822943:tid 823159] [client 172.213.232.128:9535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuRPY8CCDUa19YrTu4q5wAAAWA"]
[Thu Jul 30 13:00:29.871715 2026] [core:notice] [pid 822943:tid 822979] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:30.034940 2026] [security2:error] [pid 822943:tid 823189] [client 20.151.221.234:61256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/w.php"] [unique_id "amuRPo8CCDUa19YrTu4rAwAAAX4"]
[Thu Jul 30 13:00:30.077632 2026] [security2:error] [pid 822943:tid 823140] [client 172.213.232.128:64396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/images/about.php"] [unique_id "amuRPo8CCDUa19YrTu4rBAAAAU0"]
[Thu Jul 30 13:00:30.350477 2026] [security2:error] [pid 822943:tid 822994] [remote 57.141.18.18:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRPo8CCDUa19YrTu4rDgABIjI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,cotton,denim,lycra,nylon,polyester&max_price=75&min_price=25&rating=5&status=instock&filter_brand=american-apparel&unfilter=1
[Thu Jul 30 13:00:30.355392 2026] [security2:error] [pid 822943:tid 822997] [remote 57.141.18.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRPo8CCDUa19YrTu4rDwABJzU"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,cotton,denim,lycra,nylon,polyester&max_price=75&min_price=25&rating=5&status=instock&filter_brand=american-apparel&unfilter=1
[Thu Jul 30 13:00:31.112376 2026] [security2:error] [pid 822943:tid 823088] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRPo8CCDUa19YrTu4rEwAAARk"]
[Thu Jul 30 13:00:31.375639 2026] [security2:error] [pid 822943:tid 823000] [remote 17.22.253.68:43618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.253.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRP48CCDUa19YrTu4rIwABJDg"], referer: https://lark-shop.com/product/natural-american-spirit-5/
[Thu Jul 30 13:00:31.610392 2026] [security2:error] [pid 822943:tid 823127] [client 20.151.221.234:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/admin.php"] [unique_id "amuRP48CCDUa19YrTu4rMQAAAUA"]
[Thu Jul 30 13:00:31.684227 2026] [security2:error] [pid 822943:tid 822948] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRP48CCDUa19YrTu4rMgABOAQ"]
[Thu Jul 30 13:00:31.684452 2026] [security2:error] [pid 822943:tid 823119] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRP48CCDUa19YrTu4rMgABOAQ"]
[Thu Jul 30 13:00:32.090837 2026] [core:error] [pid 822943:tid 823176] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:32.090860 2026] [core:error] [pid 822943:tid 823176] [client 44.213.206.96:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:32.100752 2026] [core:error] [pid 822943:tid 823143] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:32.100772 2026] [core:error] [pid 822943:tid 823143] [client 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:32.121922 2026] [core:error] [pid 822943:tid 823195] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:32.121950 2026] [core:error] [pid 822943:tid 823195] [client 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:32.521318 2026] [security2:error] [pid 822943:tid 823150] [client 20.151.221.234:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuRQI8CCDUa19YrTu4rVQAAAVc"]
[Thu Jul 30 13:00:33.491938 2026] [security2:error] [pid 822943:tid 823101] [client 20.151.221.234:61264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/m.php"] [unique_id "amuRQY8CCDUa19YrTu4rigAAASY"]
[Thu Jul 30 13:00:34.430028 2026] [security2:error] [pid 822943:tid 823127] [client 172.237.109.114:56852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rbAAAAUA"]
[Thu Jul 30 13:00:34.431525 2026] [security2:error] [pid 822943:tid 823147] [client 172.237.109.114:19982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rcwAAAVQ"]
[Thu Jul 30 13:00:34.434525 2026] [security2:error] [pid 822943:tid 823112] [client 150.107.232.194:27508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRQo8CCDUa19YrTu4rnwAAATE"]
[Thu Jul 30 13:00:34.434730 2026] [security2:error] [pid 822943:tid 823112] [client 150.107.232.194:27508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRQo8CCDUa19YrTu4rnwAAATE"]
[Thu Jul 30 13:00:34.452363 2026] [security2:error] [pid 822943:tid 823080] [client 172.237.109.114:27797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rcAAAARE"]
[Thu Jul 30 13:00:34.461873 2026] [security2:error] [pid 822943:tid 823105] [client 172.237.109.114:17644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rdwAAASo"]
[Thu Jul 30 13:00:34.462137 2026] [security2:error] [pid 822943:tid 823110] [client 172.237.109.114:42967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rbwAAAS8"]
[Thu Jul 30 13:00:34.462911 2026] [security2:error] [pid 822943:tid 823153] [client 172.237.109.114:62193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rcQAAAVo"]
[Thu Jul 30 13:00:34.468710 2026] [security2:error] [pid 822943:tid 823128] [client 172.237.109.114:17119] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rbgAAAUE"]
[Thu Jul 30 13:00:34.468932 2026] [security2:error] [pid 822943:tid 823169] [client 172.237.109.114:11009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4ragAAAWo"]
[Thu Jul 30 13:00:34.470717 2026] [security2:error] [pid 822943:tid 823100] [client 172.237.109.114:53684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rawAAASU"]
[Thu Jul 30 13:00:34.483162 2026] [security2:error] [pid 822943:tid 823189] [client 172.237.109.114:35122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4raQAAAX4"]
[Thu Jul 30 13:00:34.483631 2026] [security2:error] [pid 822943:tid 823144] [client 172.237.109.114:5767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4raAAAAVE"]
[Thu Jul 30 13:00:34.484481 2026] [security2:error] [pid 822943:tid 823116] [client 172.237.109.114:43359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQY8CCDUa19YrTu4rfAAAATU"]
[Thu Jul 30 13:00:34.496926 2026] [security2:error] [pid 822943:tid 823084] [client 172.237.109.114:38104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQY8CCDUa19YrTu4regAAARU"]
[Thu Jul 30 13:00:34.502860 2026] [security2:error] [pid 822943:tid 823125] [client 172.237.109.114:27335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rdAAAAT4"]
[Thu Jul 30 13:00:34.508798 2026] [security2:error] [pid 822943:tid 823161] [client 172.237.109.114:29105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rdgAAAWI"]
[Thu Jul 30 13:00:34.508857 2026] [security2:error] [pid 822943:tid 823117] [client 172.237.109.114:54391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQY8CCDUa19YrTu4rewAAATY"]
[Thu Jul 30 13:00:34.516528 2026] [security2:error] [pid 822943:tid 823129] [client 172.237.109.114:54873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rdQAAAUI"]
[Thu Jul 30 13:00:34.538702 2026] [security2:error] [pid 822943:tid 823103] [client 172.237.109.114:30268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQI8CCDUa19YrTu4rcgAAASg"]
[Thu Jul 30 13:00:34.557935 2026] [security2:error] [pid 822943:tid 823135] [client 20.151.221.234:61306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuRQo8CCDUa19YrTu4rmwAAAUg"]
[Thu Jul 30 13:00:34.558168 2026] [security2:error] [pid 822943:tid 823133] [client 204.8.98.105:46220] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuRQo8CCDUa19YrTu4rpQAAAUY"]
[Thu Jul 30 13:00:34.558283 2026] [security2:error] [pid 822943:tid 823133] [client 204.8.98.105:46220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuRQo8CCDUa19YrTu4rpQAAAUY"]
[Thu Jul 30 13:00:34.591469 2026] [security2:error] [pid 822943:tid 823165] [client 172.237.109.114:1359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQY8CCDUa19YrTu4reQAAAWY"]
[Thu Jul 30 13:00:34.620437 2026] [security2:error] [pid 822943:tid 823173] [client 172.237.109.114:24828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRQY8CCDUa19YrTu4reAAAAW4"]
[Thu Jul 30 13:00:35.373162 2026] [security2:error] [pid 822943:tid 823155] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amuRQ48CCDUa19YrTu4rsgAAAVw"]
[Thu Jul 30 13:00:35.606600 2026] [security2:error] [pid 822943:tid 823184] [client 172.213.232.128:46146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuRQ48CCDUa19YrTu4ruwAAAXk"]
[Thu Jul 30 13:00:36.262337 2026] [security2:error] [pid 822943:tid 823099] [client 20.151.221.234:63408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuRQ48CCDUa19YrTu4rugAAASQ"]
[Thu Jul 30 13:00:36.310635 2026] [security2:error] [pid 822943:tid 823115] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRQ48CCDUa19YrTu4rwQAAATQ"]
[Thu Jul 30 13:00:36.496712 2026] [security2:error] [pid 822943:tid 823142] [client 20.151.221.234:63408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/classwithtostring.php"] [unique_id "amuRRI8CCDUa19YrTu4r1wAAAU8"]
[Thu Jul 30 13:00:36.677183 2026] [security2:error] [pid 822943:tid 823137] [client 172.213.232.128:46147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuRRI8CCDUa19YrTu4r4gAAAUo"]
[Thu Jul 30 13:00:37.456419 2026] [security2:error] [pid 822943:tid 823108] [client 78.46.215.1:47522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuRRY8CCDUa19YrTu4r8AAAAS0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:00:37.920670 2026] [security2:error] [pid 822943:tid 823187] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRRY8CCDUa19YrTu4r7AABfHM"]
[Thu Jul 30 13:00:37.957580 2026] [security2:error] [pid 822943:tid 823191] [client 172.213.232.128:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/about.php"] [unique_id "amuRRY8CCDUa19YrTu4sAAAAAYA"]
[Thu Jul 30 13:00:38.097773 2026] [core:notice] [pid 822943:tid 823149] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:38.102025 2026] [security2:error] [pid 822943:tid 823149] [client 78.46.215.1:47526] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuRRo8CCDUa19YrTu4sBAAAAVY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:00:38.489516 2026] [security2:error] [pid 822943:tid 823172] [client 78.46.215.1:47532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuRRo8CCDUa19YrTu4sCwAAAW0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:00:38.768434 2026] [security2:error] [pid 822943:tid 823166] [client 20.151.221.234:61305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/gmo.php"] [unique_id "amuRRo8CCDUa19YrTu4sFQAAAWc"]
[Thu Jul 30 13:00:38.971561 2026] [security2:error] [pid 822943:tid 823119] [client 172.213.232.128:43722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/cgi-bin/about.php"] [unique_id "amuRRo8CCDUa19YrTu4sFgAAATg"]
[Thu Jul 30 13:00:39.657815 2026] [core:error] [pid 822943:tid 823105] [client 152.32.145.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:39.657839 2026] [core:error] [pid 822943:tid 823105] [client 152.32.145.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:40.365458 2026] [security2:error] [pid 822943:tid 823200] [client 172.213.232.128:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuRSI8CCDUa19YrTu4sOwAAAYk"]
[Thu Jul 30 13:00:40.742605 2026] [security2:error] [pid 822943:tid 823135] [client 172.236.9.101:33142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRSI8CCDUa19YrTu4sMwAAAUg"]
[Thu Jul 30 13:00:41.315053 2026] [security2:error] [pid 822943:tid 823144] [client 20.151.221.234:22979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuRSY8CCDUa19YrTu4sSwAAAVE"]
[Thu Jul 30 13:00:41.426179 2026] [security2:error] [pid 822943:tid 823118] [client 193.148.16.211:57242] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuRSY8CCDUa19YrTu4sRwAAATc"]
[Thu Jul 30 13:00:41.426280 2026] [security2:error] [pid 822943:tid 823118] [client 193.148.16.211:57242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuRSY8CCDUa19YrTu4sRwAAATc"]
[Thu Jul 30 13:00:41.634339 2026] [security2:error] [pid 822943:tid 823177] [client 20.215.191.139:41083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/LA.php"] [unique_id "amuRSY8CCDUa19YrTu4sUgAAAXI"]
[Thu Jul 30 13:00:42.106312 2026] [security2:error] [pid 822943:tid 823081] [client 20.151.221.234:22989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-the.php"] [unique_id "amuRSo8CCDUa19YrTu4sXQAAARI"]
[Thu Jul 30 13:00:42.256111 2026] [security2:error] [pid 822943:tid 823155] [client 20.215.191.139:37045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/admin.php"] [unique_id "amuRSo8CCDUa19YrTu4sYQAAAVw"]
[Thu Jul 30 13:00:42.468235 2026] [security2:error] [pid 822943:tid 823142] [client 172.213.232.128:9517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuRSo8CCDUa19YrTu4saAAAAU8"]
[Thu Jul 30 13:00:42.488660 2026] [security2:error] [pid 822943:tid 822970] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRSo8CCDUa19YrTu4saQABQRo"]
[Thu Jul 30 13:00:42.488818 2026] [security2:error] [pid 822943:tid 823128] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRSo8CCDUa19YrTu4saQABQRo"]
[Thu Jul 30 13:00:42.816713 2026] [security2:error] [pid 822943:tid 823164] [client 52.167.144.219:55919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amuRSo8CCDUa19YrTu4sXAABZQA"]
[Thu Jul 30 13:00:42.914118 2026] [security2:error] [pid 822943:tid 823100] [client 85.208.96.198:58762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/robots.txt"] [unique_id "amuRSo8CCDUa19YrTu4scwAAASU"]
[Thu Jul 30 13:00:42.914239 2026] [security2:error] [pid 822943:tid 823100] [client 85.208.96.198:58762] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/robots.txt"] [unique_id "amuRSo8CCDUa19YrTu4scwAAASU"]
[Thu Jul 30 13:00:43.409650 2026] [security2:error] [pid 822943:tid 823173] [client 172.213.232.128:2293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuRS48CCDUa19YrTu4shAAAAW4"]
[Thu Jul 30 13:00:43.765657 2026] [security2:error] [pid 822943:tid 823167] [client 20.215.191.139:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/class_api.php"] [unique_id "amuRS48CCDUa19YrTu4sigAAAWg"]
[Thu Jul 30 13:00:43.885857 2026] [core:error] [pid 822943:tid 823139] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:43.885879 2026] [core:error] [pid 822943:tid 823139] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:43.943896 2026] [core:error] [pid 822943:tid 823078] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:43.943919 2026] [core:error] [pid 822943:tid 823078] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:43.999568 2026] [core:error] [pid 822943:tid 823121] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:43.999591 2026] [core:error] [pid 822943:tid 823121] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:44.048367 2026] [security2:error] [pid 822943:tid 823137] [client 172.213.232.128:9026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuRTI8CCDUa19YrTu4soAAAAUo"]
[Thu Jul 30 13:00:44.061637 2026] [security2:error] [pid 822943:tid 823117] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRS48CCDUa19YrTu4sggABNg4"]
[Thu Jul 30 13:00:44.112143 2026] [security2:error] [pid 822943:tid 823180] [client 185.191.171.12:13106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/service-page/16-weeks-coaching"] [unique_id "amuRTI8CCDUa19YrTu4soQAAAXU"]
[Thu Jul 30 13:00:44.112283 2026] [security2:error] [pid 822943:tid 823180] [client 185.191.171.12:13106] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/service-page/16-weeks-coaching"] [unique_id "amuRTI8CCDUa19YrTu4soQAAAXU"]
[Thu Jul 30 13:00:44.126026 2026] [security2:error] [pid 822943:tid 823152] [client 20.151.221.234:22992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/404.php"] [unique_id "amuRTI8CCDUa19YrTu4sogAAAVk"]
[Thu Jul 30 13:00:44.314516 2026] [security2:error] [pid 822943:tid 823105] [client 20.215.191.139:39772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuRTI8CCDUa19YrTu4spQAAASo"]
[Thu Jul 30 13:00:44.903296 2026] [security2:error] [pid 822943:tid 823159] [client 150.107.232.194:26889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRTI8CCDUa19YrTu4sswAAAWA"]
[Thu Jul 30 13:00:44.903409 2026] [security2:error] [pid 822943:tid 823159] [client 150.107.232.194:26889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRTI8CCDUa19YrTu4sswAAAWA"]
[Thu Jul 30 13:00:45.138185 2026] [security2:error] [pid 822943:tid 823086] [client 172.213.232.128:9063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuRTY8CCDUa19YrTu4sugAAARc"]
[Thu Jul 30 13:00:45.174643 2026] [security2:error] [pid 822943:tid 823106] [client 20.215.191.139:47007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/wp-login.php"] [unique_id "amuRTI8CCDUa19YrTu4stAAAASs"]
[Thu Jul 30 13:00:45.272712 2026] [core:notice] [pid 822943:tid 822990] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:45.434006 2026] [security2:error] [pid 822943:tid 823131] [client 85.208.96.209:56956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/14/nas-redes-sociais-bolsonaro-comemora-obras-na-cbtu-de-joao-pessoa-que-vao-diminuir-intervalo-entre-trens/"] [unique_id "amuRTY8CCDUa19YrTu4swwAAAUQ"]
[Thu Jul 30 13:00:45.434153 2026] [security2:error] [pid 822943:tid 823131] [client 85.208.96.209:56956] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/14/nas-redes-sociais-bolsonaro-comemora-obras-na-cbtu-de-joao-pessoa-que-vao-diminuir-intervalo-entre-trens/"] [unique_id "amuRTY8CCDUa19YrTu4swwAAAUQ"]
[Thu Jul 30 13:00:45.669447 2026] [security2:error] [pid 822943:tid 823085] [client 20.151.221.234:22985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/init.php"] [unique_id "amuRTY8CCDUa19YrTu4szAAAARY"]
[Thu Jul 30 13:00:45.895184 2026] [core:notice] [pid 822943:tid 823008] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:46.516928 2026] [core:error] [pid 822943:tid 823097] [client 152.32.145.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:46.516951 2026] [core:error] [pid 822943:tid 823097] [client 152.32.145.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:46.699062 2026] [security2:error] [pid 822943:tid 823087] [client 20.215.191.139:39294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuRTo8CCDUa19YrTu4s5wAAARg"]
[Thu Jul 30 13:00:47.009550 2026] [security2:error] [pid 822943:tid 823084] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRTo8CCDUa19YrTu4s2gABFTk"]
[Thu Jul 30 13:00:47.096001 2026] [security2:error] [pid 822943:tid 823125] [client 20.151.221.234:23463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/file5.php"] [unique_id "amuRT48CCDUa19YrTu4s6wAAAT4"]
[Thu Jul 30 13:00:47.937919 2026] [security2:error] [pid 822943:tid 823123] [client 20.215.191.139:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/991176.php"] [unique_id "amuRT48CCDUa19YrTu4tAQAAATw"]
[Thu Jul 30 13:00:48.906530 2026] [security2:error] [pid 822943:tid 823088] [client 20.215.191.139:39871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuRUI8CCDUa19YrTu4tFgAAARk"]
[Thu Jul 30 13:00:48.950941 2026] [core:notice] [pid 822943:tid 822987] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:49.030388 2026] [core:error] [pid 822943:tid 823165] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.030410 2026] [core:error] [pid 822943:tid 823165] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.045421 2026] [core:error] [pid 822943:tid 823096] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.045447 2026] [core:error] [pid 822943:tid 823096] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.045526 2026] [core:error] [pid 822943:tid 823200] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.045542 2026] [core:error] [pid 822943:tid 823200] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.066733 2026] [security2:error] [pid 822943:tid 823094] [client 20.151.221.234:61274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuRUY8CCDUa19YrTu4tIgAAAR8"]
[Thu Jul 30 13:00:49.323340 2026] [core:error] [pid 822943:tid 823140] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.323361 2026] [core:error] [pid 822943:tid 823140] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.378191 2026] [core:error] [pid 822943:tid 823153] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.378210 2026] [core:error] [pid 822943:tid 823153] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.394837 2026] [core:error] [pid 822943:tid 823132] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.394858 2026] [core:error] [pid 822943:tid 823132] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:49.999849 2026] [security2:error] [pid 822943:tid 823127] [client 20.215.191.139:39865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuRUY8CCDUa19YrTu4tSwAAAUA"]
[Thu Jul 30 13:00:50.125906 2026] [core:error] [pid 822943:tid 823075] [client 152.32.145.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.125927 2026] [core:error] [pid 822943:tid 823075] [client 152.32.145.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.402890 2026] [security2:error] [pid 822943:tid 823176] [client 217.181.89.149:37324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRUo8CCDUa19YrTu4tWAABcT8"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 13:00:50.437382 2026] [core:error] [pid 822943:tid 823074] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.437406 2026] [core:error] [pid 822943:tid 823074] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.460952 2026] [security2:error] [pid 822943:tid 823162] [client 185.191.171.15:27522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/robots.txt"] [unique_id "amuRUo8CCDUa19YrTu4tZQAAAWM"]
[Thu Jul 30 13:00:50.461138 2026] [security2:error] [pid 822943:tid 823162] [client 185.191.171.15:27522] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alseermarine.com"] [uri "/robots.txt"] [unique_id "amuRUo8CCDUa19YrTu4tZQAAAWM"]
[Thu Jul 30 13:00:50.491193 2026] [core:error] [pid 822943:tid 823130] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.491216 2026] [core:error] [pid 822943:tid 823130] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.498675 2026] [core:error] [pid 822943:tid 823185] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.498699 2026] [core:error] [pid 822943:tid 823185] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.604804 2026] [core:error] [pid 822943:tid 823093] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.604829 2026] [core:error] [pid 822943:tid 823093] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.646211 2026] [core:error] [pid 822943:tid 823186] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.646234 2026] [core:error] [pid 822943:tid 823186] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.651187 2026] [core:error] [pid 822943:tid 823117] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.651211 2026] [core:error] [pid 822943:tid 823117] [client 52.202.41.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:00:50.714618 2026] [core:notice] [pid 822943:tid 823038] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:00:50.785382 2026] [security2:error] [pid 822943:tid 823156] [client 20.151.221.234:61290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/shell.php"] [unique_id "amuRUo8CCDUa19YrTu4tiwAAAV0"]
[Thu Jul 30 13:00:51.368810 2026] [security2:error] [pid 822943:tid 823121] [client 74.7.244.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuRUo8CCDUa19YrTu4tdAAAATo"]
[Thu Jul 30 13:00:51.368844 2026] [security2:error] [pid 822943:tid 823121] [client 74.7.244.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuRUo8CCDUa19YrTu4tdAAAATo"]
[Thu Jul 30 13:00:51.369485 2026] [security2:error] [pid 822943:tid 823181] [client 74.7.244.31:52952] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.worldofwhiskers.com"] [uri "/robots.txt"] [unique_id "amuRUo8CCDUa19YrTu4tcgABdlE"]
[Thu Jul 30 13:00:51.604196 2026] [security2:error] [pid 822943:tid 823094] [client 185.191.171.8:59106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/ar/about-2/"] [unique_id "amuRU48CCDUa19YrTu4towAAAR8"]
[Thu Jul 30 13:00:51.604364 2026] [security2:error] [pid 822943:tid 823094] [client 185.191.171.8:59106] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alseermarine.com"] [uri "/ar/about-2/"] [unique_id "amuRU48CCDUa19YrTu4towAAAR8"]
[Thu Jul 30 13:00:51.722435 2026] [security2:error] [pid 822943:tid 823130] [client 20.215.191.139:47154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuRU48CCDUa19YrTu4tqAAAAUM"]
[Thu Jul 30 13:00:51.774599 2026] [security2:error] [pid 822943:tid 823135] [client 20.151.221.234:61267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/f35.php"] [unique_id "amuRU48CCDUa19YrTu4tqQAAAUg"]
[Thu Jul 30 13:00:52.216747 2026] [security2:error] [pid 822943:tid 823146] [client 74.7.244.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuRVI8CCDUa19YrTu4txQAAAVM"], referer: https://www.worldofwhiskers.com/robots.txt
[Thu Jul 30 13:00:52.217626 2026] [security2:error] [pid 822943:tid 823173] [client 74.7.244.31:52964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "worldofwhiskers.com"] [uri "/robots.txt"] [unique_id "amuRVI8CCDUa19YrTu4twwABbnM"], referer: https://www.worldofwhiskers.com/robots.txt
[Thu Jul 30 13:00:52.414537 2026] [security2:error] [pid 822943:tid 823170] [client 74.7.244.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.seven-stars-shop.com"] [uri "/index.php"] [unique_id "amuRU48CCDUa19YrTu4tpgAAAWs"]
[Thu Jul 30 13:00:52.414584 2026] [security2:error] [pid 822943:tid 823170] [client 74.7.244.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.seven-stars-shop.com"] [uri "/index.php"] [unique_id "amuRU48CCDUa19YrTu4tpgAAAWs"]
[Thu Jul 30 13:00:52.415455 2026] [security2:error] [pid 822943:tid 823154] [client 74.7.244.29:38724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.seven-stars-shop.com"] [uri "/robots.txt"] [unique_id "amuRU48CCDUa19YrTu4tpAABW0M"]
[Thu Jul 30 13:00:52.449098 2026] [security2:error] [pid 822943:tid 823133] [client 20.215.191.139:37695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuRVI8CCDUa19YrTu4tzwAAAUY"]
[Thu Jul 30 13:00:52.495357 2026] [security2:error] [pid 822943:tid 823193] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRU48CCDUa19YrTu4tsQAAAYI"]
[Thu Jul 30 13:00:52.510596 2026] [security2:error] [pid 822943:tid 823122] [client 68.67.112.200:11987] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuRVI8CCDUa19YrTu4t1QAAATs"]
[Thu Jul 30 13:00:52.705801 2026] [security2:error] [pid 822943:tid 823086] [client 20.151.221.234:63500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/new.php"] [unique_id "amuRVI8CCDUa19YrTu4t2AAAARc"]
[Thu Jul 30 13:00:53.054502 2026] [security2:error] [pid 822943:tid 823175] [client 74.7.244.29:38728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "seven-stars-shop.com"] [uri "/robots.txt"] [unique_id "amuRVY8CCDUa19YrTu4t9AABcAE"], referer: https://www.seven-stars-shop.com/robots.txt
[Thu Jul 30 13:00:53.273046 2026] [security2:error] [pid 822943:tid 822946] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRVY8CCDUa19YrTu4t-AABfwI"]
[Thu Jul 30 13:00:53.273207 2026] [security2:error] [pid 822943:tid 823190] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRVY8CCDUa19YrTu4t-AABfwI"]
[Thu Jul 30 13:00:53.454091 2026] [security2:error] [pid 822943:tid 823156] [client 20.151.221.234:23039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/adminfuns.php"] [unique_id "amuRVY8CCDUa19YrTu4t_QAAAV0"]
[Thu Jul 30 13:00:53.535075 2026] [security2:error] [pid 822943:tid 822962] [remote 57.141.18.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRVY8CCDUa19YrTu4uAQABhxI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,denim,nylon,polyester,titanium,wood,linen,steel&filter_size=medium&orderby=menu_order&status=instock&min_price=75&max_price=125&unfilter=1
[Thu Jul 30 13:00:53.708720 2026] [security2:error] [pid 822943:tid 823127] [client 20.215.191.139:47127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuRVY8CCDUa19YrTu4uBgAAAUA"]
[Thu Jul 30 13:00:53.936353 2026] [security2:error] [pid 822943:tid 823077] [client 172.236.9.101:46027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRVY8CCDUa19YrTu4t-QAAAQ4"]
[Thu Jul 30 13:00:54.085328 2026] [security2:error] [pid 822943:tid 823061] [remote 57.141.18.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRVo8CCDUa19YrTu4uDQABD3U"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,denim,nylon,polyester,titanium,wood,linen,steel&filter_size=medium&orderby=menu_order&status=instock&min_price=75&max_price=125&unfilter=1
[Thu Jul 30 13:00:54.479803 2026] [security2:error] [pid 822943:tid 823125] [client 20.151.221.234:61291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuRVo8CCDUa19YrTu4uFQAAAT4"]
[Thu Jul 30 13:00:54.721664 2026] [security2:error] [pid 822943:tid 823121] [client 172.213.232.128:6606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuRVo8CCDUa19YrTu4uJQAAATo"]
[Thu Jul 30 13:00:54.724544 2026] [security2:error] [pid 822943:tid 823138] [client 20.151.221.234:61291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuRVo8CCDUa19YrTu4uJAAAAUs"]
[Thu Jul 30 13:00:54.962404 2026] [security2:error] [pid 822943:tid 823187] [client 20.151.221.234:61291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/fm.php"] [unique_id "amuRVo8CCDUa19YrTu4uKAAAAXw"]
[Thu Jul 30 13:00:55.061309 2026] [security2:error] [pid 822943:tid 823152] [client 20.215.191.139:39233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuRV48CCDUa19YrTu4uLAAAAVk"]
[Thu Jul 30 13:00:55.373225 2026] [security2:error] [pid 822943:tid 823157] [client 150.107.232.194:26654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRV48CCDUa19YrTu4uNAAAAV4"]
[Thu Jul 30 13:00:55.373351 2026] [security2:error] [pid 822943:tid 823157] [client 150.107.232.194:26654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRV48CCDUa19YrTu4uNAAAAV4"]
[Thu Jul 30 13:00:55.480783 2026] [fcgid:warn] [pid 822943:tid 823189] (70014)End of file found: [client 156.229.21.54:57376] mod_fcgid: can't get data from http client
[Thu Jul 30 13:00:55.578843 2026] [security2:error] [pid 822943:tid 823081] [client 74.7.228.43:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.sua.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuRVo8CCDUa19YrTu4uFAAAARI"]
[Thu Jul 30 13:00:55.579532 2026] [security2:error] [pid 822943:tid 823112] [client 74.7.228.43:55372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.sua.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuRVo8CCDUa19YrTu4uEgABMVY"]
[Thu Jul 30 13:00:55.658330 2026] [security2:error] [pid 822943:tid 823147] [client 172.213.232.128:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuRV48CCDUa19YrTu4uPwAAAVQ"]
[Thu Jul 30 13:00:55.683893 2026] [security2:error] [pid 822943:tid 823110] [client 216.244.66.236:36986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuRV48CCDUa19YrTu4uQAAAAS8"]
[Thu Jul 30 13:00:55.684020 2026] [security2:error] [pid 822943:tid 823110] [client 216.244.66.236:36986] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuRV48CCDUa19YrTu4uQAAAAS8"]
[Thu Jul 30 13:00:55.685658 2026] [security2:error] [pid 822943:tid 823180] [client 216.244.66.236:36980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuRV48CCDUa19YrTu4uQQAAAXU"]
[Thu Jul 30 13:00:55.685734 2026] [security2:error] [pid 822943:tid 823180] [client 216.244.66.236:36980] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuRV48CCDUa19YrTu4uQQAAAXU"]
[Thu Jul 30 13:00:55.898930 2026] [security2:error] [pid 822943:tid 823198] [client 20.215.191.139:17224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuRV48CCDUa19YrTu4uQgAAAYc"]
[Thu Jul 30 13:00:56.418639 2026] [security2:error] [pid 822943:tid 823192] [client 172.213.232.128:9060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/cloud.php"] [unique_id "amuRWI8CCDUa19YrTu4uTwAAAYE"]
[Thu Jul 30 13:00:56.624113 2026] [security2:error] [pid 822943:tid 823109] [client 20.151.221.234:61295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuRWI8CCDUa19YrTu4uUgAAAS4"]
[Thu Jul 30 13:00:56.629698 2026] [security2:error] [pid 822943:tid 823167] [client 20.215.191.139:17258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuRWI8CCDUa19YrTu4uVAAAAWg"]
[Thu Jul 30 13:00:56.822094 2026] [security2:error] [pid 822943:tid 823085] [client 20.151.221.234:61295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/file.php"] [unique_id "amuRWI8CCDUa19YrTu4uWwAAARY"]
[Thu Jul 30 13:00:57.092860 2026] [security2:error] [pid 822943:tid 823178] [client 172.213.232.128:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuRWY8CCDUa19YrTu4uYAAAAXM"]
[Thu Jul 30 13:00:57.309599 2026] [security2:error] [pid 822943:tid 823081] [client 20.215.191.139:39288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuRWY8CCDUa19YrTu4uawAAARI"]
[Thu Jul 30 13:00:57.625649 2026] [security2:error] [pid 822943:tid 823100] [client 20.151.221.234:23480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuRWY8CCDUa19YrTu4ubAAAASU"]
[Thu Jul 30 13:00:57.724503 2026] [security2:error] [pid 822943:tid 823140] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRWY8CCDUa19YrTu4uXwABTRg"]
[Thu Jul 30 13:00:57.770968 2026] [security2:error] [pid 822943:tid 823093] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRWY8CCDUa19YrTu4uYQABHjE"]
[Thu Jul 30 13:00:57.823409 2026] [security2:error] [pid 822943:tid 823107] [client 20.151.221.234:23480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/bolt.php"] [unique_id "amuRWY8CCDUa19YrTu4uegAAASw"]
[Thu Jul 30 13:00:58.390375 2026] [security2:error] [pid 822943:tid 823165] [client 20.215.191.139:17276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuRWo8CCDUa19YrTu4uiwAAAWY"]
[Thu Jul 30 13:00:59.315718 2026] [security2:error] [pid 822943:tid 823173] [client 20.215.191.139:39820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuRW48CCDUa19YrTu4upAAAAW4"]
[Thu Jul 30 13:00:59.352805 2026] [security2:error] [pid 822943:tid 823145] [client 20.151.221.234:23014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/3.php"] [unique_id "amuRW48CCDUa19YrTu4uqAAAAVI"]
[Thu Jul 30 13:00:59.586335 2026] [security2:error] [pid 822943:tid 823101] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRWo8CCDUa19YrTu4umgAAASY"]
[Thu Jul 30 13:01:00.111551 2026] [security2:error] [pid 822943:tid 823148] [client 20.151.221.234:23430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/222.php"] [unique_id "amuRXI8CCDUa19YrTu4uswAAAVU"]
[Thu Jul 30 13:01:00.247766 2026] [security2:error] [pid 822943:tid 823177] [client 172.213.232.128:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/updates.php"] [unique_id "amuRXI8CCDUa19YrTu4utAAAAXI"]
[Thu Jul 30 13:01:00.562198 2026] [security2:error] [pid 822943:tid 823091] [client 20.215.191.139:17252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuRXI8CCDUa19YrTu4uvwAAARw"]
[Thu Jul 30 13:01:00.583505 2026] [core:notice] [pid 822943:tid 822948] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:00.789880 2026] [security2:error] [pid 822943:tid 823166] [client 172.236.9.101:15076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRXI8CCDUa19YrTu4uuAAAAWc"]
[Thu Jul 30 13:01:00.966061 2026] [security2:error] [pid 822943:tid 823104] [client 20.151.221.234:61277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuRXI8CCDUa19YrTu4uzwAAASk"]
[Thu Jul 30 13:01:01.075412 2026] [security2:error] [pid 822943:tid 823184] [client 172.213.232.128:5640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/css/cloud.php"] [unique_id "amuRXY8CCDUa19YrTu4u0QAAAXk"]
[Thu Jul 30 13:01:01.467937 2026] [security2:error] [pid 822943:tid 823116] [client 20.215.191.139:47129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuRXY8CCDUa19YrTu4u5AAAATU"]
[Thu Jul 30 13:01:01.751052 2026] [security2:error] [pid 822943:tid 823079] [client 216.244.66.196:51738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuRXY8CCDUa19YrTu4u5wAAARA"]
[Thu Jul 30 13:01:01.751194 2026] [security2:error] [pid 822943:tid 823079] [client 216.244.66.196:51738] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuRXY8CCDUa19YrTu4u5wAAARA"]
[Thu Jul 30 13:01:01.879883 2026] [security2:error] [pid 822943:tid 823086] [client 20.151.221.234:23020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuRXY8CCDUa19YrTu4u7AAAARc"]
[Thu Jul 30 13:01:02.136625 2026] [security2:error] [pid 822943:tid 823199] [client 20.215.191.139:40052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/amaxx.php"] [unique_id "amuRXo8CCDUa19YrTu4u9gAAAYg"]
[Thu Jul 30 13:01:02.317619 2026] [security2:error] [pid 822943:tid 823133] [client 172.213.232.128:11564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuRXo8CCDUa19YrTu4u9wAAAUY"]
[Thu Jul 30 13:01:02.857117 2026] [security2:error] [pid 822943:tid 823168] [client 20.151.221.234:63376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuRXo8CCDUa19YrTu4vAgAAAWk"]
[Thu Jul 30 13:01:03.021161 2026] [security2:error] [pid 822943:tid 823033] [remote 74.7.241.60:42180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/feed/img/js/uploads/partners/uploads/partners/uploads/partners/contactff.php"] [unique_id "amuRX48CCDUa19YrTu4vCgABDFk"], referer: https://aded-rdc.org/feed/img/js/uploads/partners/uploads/partners/uploads/partners/login.php
[Thu Jul 30 13:01:03.055607 2026] [security2:error] [pid 822943:tid 823134] [client 20.151.221.234:63376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-content/admin.php"] [unique_id "amuRX48CCDUa19YrTu4vDQAAAUc"]
[Thu Jul 30 13:01:03.150451 2026] [security2:error] [pid 822943:tid 823115] [client 20.215.191.139:40012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/bek.php"] [unique_id "amuRX48CCDUa19YrTu4vDwAAATQ"]
[Thu Jul 30 13:01:03.738252 2026] [security2:error] [pid 822943:tid 823198] [client 20.215.191.139:40024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuRX48CCDUa19YrTu4vHQAAAYc"]
[Thu Jul 30 13:01:03.789842 2026] [security2:error] [pid 822943:tid 823112] [client 172.213.232.128:11540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/img/cloud.php"] [unique_id "amuRX48CCDUa19YrTu4vHgAAATE"]
[Thu Jul 30 13:01:03.903753 2026] [security2:error] [pid 822943:tid 823185] [client 20.151.221.234:61308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-configs.php"] [unique_id "amuRX48CCDUa19YrTu4vHwAAAXo"]
[Thu Jul 30 13:01:04.076116 2026] [security2:error] [pid 822943:tid 823043] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRYI8CCDUa19YrTu4vIwABD2M"]
[Thu Jul 30 13:01:04.076308 2026] [security2:error] [pid 822943:tid 823078] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRYI8CCDUa19YrTu4vIwABD2M"]
[Thu Jul 30 13:01:04.465751 2026] [security2:error] [pid 822943:tid 823197] [client 20.215.191.139:17261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/class.api.php"] [unique_id "amuRYI8CCDUa19YrTu4vLQAAAYY"]
[Thu Jul 30 13:01:04.817495 2026] [security2:error] [pid 822943:tid 823051] [remote 223.109.252.167:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/"] [unique_id "amuRYI8CCDUa19YrTu4vNwABe2s"]
[Thu Jul 30 13:01:04.817699 2026] [security2:error] [pid 822943:tid 823186] [client 223.109.252.167:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spececigarette.com"] [uri "/"] [unique_id "amuRYI8CCDUa19YrTu4vNwABe2s"]
[Thu Jul 30 13:01:04.838777 2026] [security2:error] [pid 822943:tid 823102] [client 172.236.9.101:20509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYI8CCDUa19YrTu4vKwAAASc"]
[Thu Jul 30 13:01:05.190698 2026] [security2:error] [pid 822943:tid 823190] [client 20.215.191.139:40043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/cong.php"] [unique_id "amuRYY8CCDUa19YrTu4vSwAAAX8"]
[Thu Jul 30 13:01:05.637231 2026] [security2:error] [pid 822943:tid 823142] [client 172.237.109.114:47439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYY8CCDUa19YrTu4vQQAAAU8"]
[Thu Jul 30 13:01:05.639183 2026] [security2:error] [pid 822943:tid 823098] [client 172.237.109.114:25002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYY8CCDUa19YrTu4vRAAAASM"]
[Thu Jul 30 13:01:05.737455 2026] [security2:error] [pid 822943:tid 823164] [client 172.237.109.114:60559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYY8CCDUa19YrTu4vSgAAAWU"]
[Thu Jul 30 13:01:05.741195 2026] [security2:error] [pid 822943:tid 823089] [client 172.237.109.114:34237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYY8CCDUa19YrTu4vSQAAARo"]
[Thu Jul 30 13:01:05.831312 2026] [security2:error] [pid 822943:tid 823094] [client 150.107.232.194:27101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRYY8CCDUa19YrTu4vWAAAAR8"]
[Thu Jul 30 13:01:05.831456 2026] [security2:error] [pid 822943:tid 823094] [client 150.107.232.194:27101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRYY8CCDUa19YrTu4vWAAAAR8"]
[Thu Jul 30 13:01:05.903839 2026] [security2:error] [pid 822943:tid 823154] [client 20.215.191.139:40060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/content.php"] [unique_id "amuRYY8CCDUa19YrTu4vWQAAAVs"]
[Thu Jul 30 13:01:06.137064 2026] [security2:error] [pid 822943:tid 823138] [client 172.213.232.128:6578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuRYo8CCDUa19YrTu4vYgAAAUs"]
[Thu Jul 30 13:01:06.176606 2026] [core:notice] [pid 822943:tid 823059] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:06.203792 2026] [security2:error] [pid 822943:tid 823175] [client 20.151.221.234:61278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/php.php"] [unique_id "amuRYo8CCDUa19YrTu4vagAAAXA"]
[Thu Jul 30 13:01:06.625080 2026] [security2:error] [pid 822943:tid 823116] [client 172.237.109.114:63889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYo8CCDUa19YrTu4vYAAAATU"]
[Thu Jul 30 13:01:06.664424 2026] [security2:error] [pid 822943:tid 823198] [client 172.237.109.114:1543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYo8CCDUa19YrTu4vYQAAAYc"]
[Thu Jul 30 13:01:06.694087 2026] [security2:error] [pid 822943:tid 823153] [client 172.237.109.114:5268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYo8CCDUa19YrTu4vZwAAAVo"]
[Thu Jul 30 13:01:06.695532 2026] [security2:error] [pid 822943:tid 823191] [client 172.237.109.114:22456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYo8CCDUa19YrTu4vZQAAAYA"]
[Thu Jul 30 13:01:06.781631 2026] [security2:error] [pid 822943:tid 823078] [client 172.237.109.114:14594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRYo8CCDUa19YrTu4vZgAAAQ8"]
[Thu Jul 30 13:01:07.038342 2026] [security2:error] [pid 822943:tid 823105] [client 20.215.191.139:17243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/cwianpri.php"] [unique_id "amuRY48CCDUa19YrTu4veAAAASo"]
[Thu Jul 30 13:01:07.110049 2026] [security2:error] [pid 822943:tid 823141] [client 20.151.221.234:23471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-includes/index.php"] [unique_id "amuRY48CCDUa19YrTu4vgwAAAU4"]
[Thu Jul 30 13:01:07.729268 2026] [security2:error] [pid 822943:tid 823134] [client 172.237.109.114:37149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vfgAAAUc"]
[Thu Jul 30 13:01:07.730033 2026] [security2:error] [pid 822943:tid 823075] [client 172.237.109.114:43149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vfAAAAQw"]
[Thu Jul 30 13:01:07.739766 2026] [security2:error] [pid 822943:tid 823155] [client 172.237.109.114:23880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vfwAAAVw"]
[Thu Jul 30 13:01:07.744515 2026] [security2:error] [pid 822943:tid 823104] [client 172.237.109.114:41608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vfQAAASk"]
[Thu Jul 30 13:01:07.749085 2026] [security2:error] [pid 822943:tid 823079] [client 94.154.43.185:59258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guethleentertainment.com"] [uri "/.env"] [unique_id "amuRY48CCDUa19YrTu4vnAAAARA"]
[Thu Jul 30 13:01:07.749634 2026] [security2:error] [pid 822943:tid 823151] [client 172.237.109.114:9595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vgAAAAVg"]
[Thu Jul 30 13:01:07.838787 2026] [security2:error] [pid 822943:tid 823149] [client 172.237.109.114:12897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vgQAAAVY"]
[Thu Jul 30 13:01:07.849528 2026] [security2:error] [pid 822943:tid 823163] [client 172.237.109.114:63349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vhAAAAWQ"]
[Thu Jul 30 13:01:07.855800 2026] [security2:error] [pid 822943:tid 823107] [client 172.237.109.114:51232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vhgAAASw"]
[Thu Jul 30 13:01:07.873038 2026] [security2:error] [pid 822943:tid 823184] [client 172.237.109.114:40487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vhQAAAXk"]
[Thu Jul 30 13:01:07.892844 2026] [security2:error] [pid 822943:tid 823182] [client 172.237.109.114:47064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vhwAAAXc"]
[Thu Jul 30 13:01:08.169369 2026] [security2:error] [pid 822943:tid 823109] [client 172.213.232.128:6540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuRZI8CCDUa19YrTu4vrAAAAS4"]
[Thu Jul 30 13:01:08.395023 2026] [security2:error] [pid 822943:tid 823113] [client 20.215.191.139:39870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/elp.php"] [unique_id "amuRZI8CCDUa19YrTu4vswAAATI"]
[Thu Jul 30 13:01:08.477830 2026] [core:notice] [pid 822943:tid 823068] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:08.531260 2026] [security2:error] [pid 822943:tid 823125] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRY48CCDUa19YrTu4vogAAAT4"]
[Thu Jul 30 13:01:08.591188 2026] [security2:error] [pid 822943:tid 823135] [client 172.237.109.114:21614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRZI8CCDUa19YrTu4vpQAAAUg"]
[Thu Jul 30 13:01:09.247895 2026] [security2:error] [pid 822943:tid 823089] [client 74.7.228.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "magicmooncorp.com"] [uri "/index.php"] [unique_id "amuRZI8CCDUa19YrTu4vvQAAARo"]
[Thu Jul 30 13:01:09.248684 2026] [security2:error] [pid 822943:tid 823108] [client 74.7.228.7:58150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "magicmooncorp.com"] [uri "/robots.txt"] [unique_id "amuRZI8CCDUa19YrTu4vuwABLWA"]
[Thu Jul 30 13:01:09.378196 2026] [security2:error] [pid 822943:tid 823102] [client 20.215.191.139:17245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuRZY8CCDUa19YrTu4vzQAAASc"]
[Thu Jul 30 13:01:10.069420 2026] [security2:error] [pid 822943:tid 823132] [client 20.151.221.234:23012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-admin/a.php"] [unique_id "amuRZo8CCDUa19YrTu4v5wAAAUU"]
[Thu Jul 30 13:01:10.163314 2026] [security2:error] [pid 822943:tid 823131] [client 195.63.21.139:25642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRZo8CCDUa19YrTu4v5gABRBo"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 13:01:10.297889 2026] [security2:error] [pid 822943:tid 823117] [client 20.215.191.139:35607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuRZo8CCDUa19YrTu4v6wAAATY"]
[Thu Jul 30 13:01:10.346374 2026] [security2:error] [pid 822943:tid 823080] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRZY8CCDUa19YrTu4v3AAAARE"]
[Thu Jul 30 13:01:10.877614 2026] [security2:error] [pid 822943:tid 823098] [client 20.151.221.234:63509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuRZo8CCDUa19YrTu4v9wAAASM"]
[Thu Jul 30 13:01:10.983692 2026] [security2:error] [pid 822943:tid 823085] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRZo8CCDUa19YrTu4v7AABFiA"]
[Thu Jul 30 13:01:11.152705 2026] [security2:error] [pid 822943:tid 823144] [client 20.151.221.234:63509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuRZ48CCDUa19YrTu4wAQAAAVE"]
[Thu Jul 30 13:01:11.360290 2026] [security2:error] [pid 822943:tid 823163] [client 20.151.221.234:63509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuRZ48CCDUa19YrTu4wCAAAAWQ"]
[Thu Jul 30 13:01:11.569257 2026] [security2:error] [pid 822943:tid 823030] [remote 5.161.62.209:54128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.moswey.com"] [uri "/.env"] [unique_id "amuRZ48CCDUa19YrTu4wFQABgFY"]
[Thu Jul 30 13:01:12.078017 2026] [security2:error] [pid 822943:tid 823161] [client 20.151.221.234:23336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/wp-admin.php"] [unique_id "amuRaI8CCDUa19YrTu4wIAAAAWI"]
[Thu Jul 30 13:01:12.393746 2026] [security2:error] [pid 822943:tid 823084] [client 172.213.232.128:20330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/avaa.php"] [unique_id "amuRaI8CCDUa19YrTu4wLgAAARU"]
[Thu Jul 30 13:01:12.478463 2026] [security2:error] [pid 822943:tid 823174] [client 20.215.191.139:41851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuRaI8CCDUa19YrTu4wMgAAAW8"]
[Thu Jul 30 13:01:12.916196 2026] [security2:error] [pid 822943:tid 823087] [client 20.151.221.234:61248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/size.php"] [unique_id "amuRaI8CCDUa19YrTu4wQgAAARg"]
[Thu Jul 30 13:01:13.203534 2026] [security2:error] [pid 822943:tid 823158] [client 20.215.191.139:39840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuRaY8CCDUa19YrTu4wSgAAAV8"]
[Thu Jul 30 13:01:13.830919 2026] [security2:error] [pid 822943:tid 823179] [client 20.215.191.139:35646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuRaY8CCDUa19YrTu4wVAAAAXQ"]
[Thu Jul 30 13:01:14.129946 2026] [security2:error] [pid 822943:tid 823137] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuRaY8CCDUa19YrTu4wWgAAAUo"]
[Thu Jul 30 13:01:14.521137 2026] [security2:error] [pid 822943:tid 823080] [client 20.215.191.139:41792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuRao8CCDUa19YrTu4whgAAARE"]
[Thu Jul 30 13:01:14.863781 2026] [security2:error] [pid 822943:tid 823016] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRao8CCDUa19YrTu4wiwABGEg"]
[Thu Jul 30 13:01:14.863936 2026] [security2:error] [pid 822943:tid 823087] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRao8CCDUa19YrTu4wiwABGEg"]
[Thu Jul 30 13:01:15.040530 2026] [security2:error] [pid 822943:tid 823010] [remote 157.55.39.57:43988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B8%A7%E0%B8%B4%E0%B8%88%E0%B8%B1%E0%B8%A2%E0%B8%97%E0%B8%B2%E0%B8%87%E0%B8%AA%E0%B8%B2%E0%B8%98%E0%B8%B2%E0%B8%A3%E0%B8%93%E0%B8%AA%E0%B8%B8%E0%B8%82/job.php"] [unique_id "amuRa48CCDUa19YrTu4wkgABTEI"]
[Thu Jul 30 13:01:15.161305 2026] [security2:error] [pid 822943:tid 823150] [client 172.213.232.128:10106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/images/cloud.php"] [unique_id "amuRa48CCDUa19YrTu4wlwAAAVc"]
[Thu Jul 30 13:01:15.169588 2026] [security2:error] [pid 822943:tid 823112] [client 20.215.191.139:41608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuRa48CCDUa19YrTu4wmAAAATE"]
[Thu Jul 30 13:01:15.191994 2026] [security2:error] [pid 822943:tid 823133] [client 50.6.43.217:38872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wdQAAAUY"]
[Thu Jul 30 13:01:15.195455 2026] [security2:error] [pid 822943:tid 823193] [client 216.73.216.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thesounddepot.com"] [uri "/index.php"] [unique_id "amuRaI8CCDUa19YrTu4wOwAAAYI"]
[Thu Jul 30 13:01:15.420105 2026] [security2:error] [pid 822943:tid 823175] [client 204.12.208.18:64555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuRa48CCDUa19YrTu4wlgAAAXA"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 13:01:15.459602 2026] [security2:error] [pid 822943:tid 823120] [client 172.237.109.114:60615] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wXwAAATk"]
[Thu Jul 30 13:01:15.459723 2026] [security2:error] [pid 822943:tid 823195] [client 172.237.109.114:6129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wXgAAAYQ"]
[Thu Jul 30 13:01:15.533791 2026] [security2:error] [pid 822943:tid 823166] [client 172.237.109.114:37486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wZgAAAWc"]
[Thu Jul 30 13:01:15.534521 2026] [security2:error] [pid 822943:tid 823116] [client 172.237.109.114:25899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wZAAAATU"]
[Thu Jul 30 13:01:15.541033 2026] [security2:error] [pid 822943:tid 823119] [client 172.237.109.114:18446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wYQAAATg"]
[Thu Jul 30 13:01:15.559166 2026] [security2:error] [pid 822943:tid 823124] [client 172.237.109.114:48299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wZQAAAT0"]
[Thu Jul 30 13:01:15.561089 2026] [security2:error] [pid 822943:tid 823186] [client 172.237.109.114:28159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wYAAAAXs"]
[Thu Jul 30 13:01:15.604122 2026] [proxy:error] [pid 822943:tid 823160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:01:15.604204 2026] [proxy_http:error] [pid 822943:tid 823160] [client 193.47.62.167:46240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:01:15.605561 2026] [proxy:error] [pid 822943:tid 823160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:01:15.605622 2026] [proxy_http:error] [pid 822943:tid 823160] [client 193.47.62.167:46240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:01:16.007478 2026] [security2:error] [pid 822943:tid 823136] [client 204.12.208.18:64577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuRbI8CCDUa19YrTu4wqQAAAUk"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 13:01:16.013463 2026] [security2:error] [pid 822943:tid 823178] [client 20.215.191.139:16995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuRbI8CCDUa19YrTu4wqwAAAXM"]
[Thu Jul 30 13:01:16.083789 2026] [security2:error] [pid 822943:tid 823149] [client 50.6.43.217:38886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuRa48CCDUa19YrTu4wmQAAAVY"]
[Thu Jul 30 13:01:16.242385 2026] [security2:error] [pid 822943:tid 823171] [client 172.237.109.114:42030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wagAAAWw"]
[Thu Jul 30 13:01:16.246749 2026] [security2:error] [pid 822943:tid 823131] [client 172.237.109.114:61585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wcAAAAUQ"]
[Thu Jul 30 13:01:16.259257 2026] [security2:error] [pid 822943:tid 823191] [client 172.237.109.114:34986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wYwAAAYA"]
[Thu Jul 30 13:01:16.269025 2026] [security2:error] [pid 822943:tid 823161] [client 172.237.109.114:61342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wdAAAAWI"]
[Thu Jul 30 13:01:16.289024 2026] [security2:error] [pid 822943:tid 823156] [client 172.237.109.114:37680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wawAAAV0"]
[Thu Jul 30 13:01:16.290367 2026] [security2:error] [pid 822943:tid 823093] [client 172.237.109.114:40146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4waQAAAR4"]
[Thu Jul 30 13:01:16.292150 2026] [security2:error] [pid 822943:tid 823200] [client 172.237.109.114:57027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wZwAAAYk"]
[Thu Jul 30 13:01:16.314933 2026] [security2:error] [pid 822943:tid 823106] [client 172.237.109.114:48620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wbgAAASs"]
[Thu Jul 30 13:01:16.324766 2026] [security2:error] [pid 822943:tid 823127] [client 172.237.109.114:58289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wbwAAAUA"]
[Thu Jul 30 13:01:16.341368 2026] [security2:error] [pid 822943:tid 823199] [client 172.237.109.114:24595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wbAAAAYg"]
[Thu Jul 30 13:01:16.353690 2026] [security2:error] [pid 822943:tid 823130] [client 172.237.109.114:48590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wcwAAAUM"]
[Thu Jul 30 13:01:16.364966 2026] [security2:error] [pid 822943:tid 823109] [client 172.237.109.114:17276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wcQAAAS4"]
[Thu Jul 30 13:01:16.383754 2026] [security2:error] [pid 822943:tid 823198] [client 172.237.109.114:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRao8CCDUa19YrTu4wcgAAAYc"]
[Thu Jul 30 13:01:16.385230 2026] [security2:error] [pid 822943:tid 823083] [client 150.107.232.194:27078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRbI8CCDUa19YrTu4wtQAAARQ"]
[Thu Jul 30 13:01:16.385322 2026] [security2:error] [pid 822943:tid 823083] [client 150.107.232.194:27078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRbI8CCDUa19YrTu4wtQAAARQ"]
[Thu Jul 30 13:01:16.445008 2026] [security2:error] [pid 822943:tid 823154] [client 172.213.232.128:5691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuRbI8CCDUa19YrTu4wtgAAAVs"]
[Thu Jul 30 13:01:16.625540 2026] [security2:error] [pid 822943:tid 823165] [client 204.12.208.18:64597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuRbI8CCDUa19YrTu4wvQAAAWY"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 13:01:16.659174 2026] [security2:error] [pid 822943:tid 823038] [remote 5.161.62.209:54136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.mty.djb.temporary.site"] [uri "/.env"] [unique_id "amuRbI8CCDUa19YrTu4wvgABUV4"]
[Thu Jul 30 13:01:16.746858 2026] [security2:error] [pid 822943:tid 823139] [client 20.215.191.139:41659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuRbI8CCDUa19YrTu4wwgAAAUw"]
[Thu Jul 30 13:01:17.216477 2026] [security2:error] [pid 822943:tid 823129] [client 156.229.21.54:36578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.yxe.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuRbY8CCDUa19YrTu4wywAAAUI"]
[Thu Jul 30 13:01:17.303918 2026] [security2:error] [pid 822943:tid 823186] [client 172.213.232.128:10082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuRbY8CCDUa19YrTu4w0AAAAXs"]
[Thu Jul 30 13:01:17.881309 2026] [core:error] [pid 822943:tid 823050] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:17.881342 2026] [core:error] [pid 822943:tid 823050] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:17.914780 2026] [core:error] [pid 822943:tid 823053] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:17.914801 2026] [core:error] [pid 822943:tid 823053] [remote 34.233.129.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:17.973205 2026] [core:error] [pid 822943:tid 823031] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:17.973226 2026] [core:error] [pid 822943:tid 823031] [remote 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:18.039674 2026] [security2:error] [pid 822943:tid 823073] [client 172.213.232.128:22910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuRbo8CCDUa19YrTu4w6gAAAQo"]
[Thu Jul 30 13:01:18.596539 2026] [security2:error] [pid 822943:tid 823138] [client 172.213.232.128:13966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuRbo8CCDUa19YrTu4w-AAAAUs"]
[Thu Jul 30 13:01:18.692015 2026] [security2:error] [pid 822943:tid 823128] [client 20.215.191.139:16991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuRbo8CCDUa19YrTu4w-QAAAUE"]
[Thu Jul 30 13:01:19.691174 2026] [autoindex:error] [pid 822943:tid 822975] [remote 34.224.175.62:0] AH01276: Cannot serve directory /home2/kevudite/dl.truckersofeuropemod.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:01:19.800874 2026] [security2:error] [pid 822943:tid 823094] [client 20.215.191.139:16503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuRb48CCDUa19YrTu4xQgAAAR8"]
[Thu Jul 30 13:01:20.011589 2026] [security2:error] [pid 822943:tid 823171] [client 172.213.232.128:22865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuRcI8CCDUa19YrTu4xRgAAAWw"]
[Thu Jul 30 13:01:20.151421 2026] [proxy:error] [pid 822943:tid 823155] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:01:20.151507 2026] [proxy_http:error] [pid 822943:tid 823155] [client 193.47.62.167:37438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:01:20.152292 2026] [proxy:error] [pid 822943:tid 823155] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:01:20.152352 2026] [proxy_http:error] [pid 822943:tid 823155] [client 193.47.62.167:37438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:01:20.680485 2026] [security2:error] [pid 822943:tid 823101] [client 20.215.191.139:41654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuRcI8CCDUa19YrTu4xVgAAASY"]
[Thu Jul 30 13:01:21.504152 2026] [security2:error] [pid 822943:tid 822981] [remote 68.183.22.192:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.22.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuRcY8CCDUa19YrTu4xbAABRCU"]
[Thu Jul 30 13:01:21.606765 2026] [security2:error] [pid 822943:tid 823153] [client 172.213.232.128:10560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuRcY8CCDUa19YrTu4xbQAAAVo"]
[Thu Jul 30 13:01:22.165262 2026] [security2:error] [pid 822943:tid 823158] [client 156.229.21.54:36604] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.yxe.zzt.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amuRco8CCDUa19YrTu4xgAAAAV8"]
[Thu Jul 30 13:01:22.250018 2026] [security2:error] [pid 822943:tid 823176] [client 20.215.191.139:16974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuRco8CCDUa19YrTu4xhAAAAXE"]
[Thu Jul 30 13:01:22.305989 2026] [security2:error] [pid 822943:tid 823189] [client 172.213.232.128:6592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/updates.php"] [unique_id "amuRco8CCDUa19YrTu4xhwAAAX4"]
[Thu Jul 30 13:01:22.972895 2026] [security2:error] [pid 822943:tid 823151] [client 20.215.191.139:16492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuRco8CCDUa19YrTu4xlgAAAVg"]
[Thu Jul 30 13:01:23.119707 2026] [security2:error] [pid 822943:tid 823019] [remote 57.141.18.123:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRc48CCDUa19YrTu4xmgABPUs"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Ccarbon%2Clinen%2Clycra%2Cpolyester%2Csilicon%2Ctitanium%2Ccotton&orderby=menu_order&rating=5&status=sale&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 13:01:23.416379 2026] [security2:error] [pid 822943:tid 822979] [remote 57.141.18.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRc48CCDUa19YrTu4xmwABLSM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Ccarbon%2Clinen%2Clycra%2Cpolyester%2Csilicon%2Ctitanium%2Ccotton&orderby=menu_order&rating=5&status=sale&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 13:01:23.653201 2026] [security2:error] [pid 822943:tid 823147] [client 172.213.232.128:13983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuRc48CCDUa19YrTu4xpQAAAVQ"]
[Thu Jul 30 13:01:23.824451 2026] [security2:error] [pid 822943:tid 823166] [client 20.215.191.139:38172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuRc48CCDUa19YrTu4xpgAAAWc"]
[Thu Jul 30 13:01:24.333350 2026] [security2:error] [pid 822943:tid 822983] [remote 74.7.241.59:49486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuRdI8CCDUa19YrTu4xsAABGSc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/query-control/controls
[Thu Jul 30 13:01:24.467909 2026] [security2:error] [pid 822943:tid 823105] [client 20.215.191.139:38165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuRdI8CCDUa19YrTu4xugAAASo"]
[Thu Jul 30 13:01:24.544555 2026] [security2:error] [pid 822943:tid 823158] [client 172.213.232.128:22215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuRdI8CCDUa19YrTu4xvgAAAV8"]
[Thu Jul 30 13:01:24.831703 2026] [core:notice] [pid 822943:tid 823098] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:24.996286 2026] [security2:error] [pid 822943:tid 823189] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRdI8CCDUa19YrTu4xtgAAAX4"]
[Thu Jul 30 13:01:25.175620 2026] [security2:error] [pid 822943:tid 823199] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRdI8CCDUa19YrTu4xvwABiHE"]
[Thu Jul 30 13:01:25.236296 2026] [security2:error] [pid 822943:tid 823184] [client 20.215.191.139:38583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuRdY8CCDUa19YrTu4xywAAAXk"]
[Thu Jul 30 13:01:25.251305 2026] [security2:error] [pid 822943:tid 823174] [client 172.236.9.101:64260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/user_secrets.yml.old"] [unique_id "amuRdY8CCDUa19YrTu4xzAAAAW8"]
[Thu Jul 30 13:01:25.683057 2026] [security2:error] [pid 822943:tid 823050] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRdY8CCDUa19YrTu4x2gABImo"]
[Thu Jul 30 13:01:25.683252 2026] [security2:error] [pid 822943:tid 823097] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRdY8CCDUa19YrTu4x2gABImo"]
[Thu Jul 30 13:01:25.733631 2026] [security2:error] [pid 822943:tid 823119] [client 172.213.232.128:13495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuRdY8CCDUa19YrTu4x3AAAATg"]
[Thu Jul 30 13:01:26.817507 2026] [security2:error] [pid 822943:tid 823092] [client 20.215.191.139:38551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuRdo8CCDUa19YrTu4x9gAAAR0"]
[Thu Jul 30 13:01:27.049707 2026] [security2:error] [pid 822943:tid 823150] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRdo8CCDUa19YrTu4x7wAAAVc"]
[Thu Jul 30 13:01:27.236578 2026] [security2:error] [pid 822943:tid 823171] [client 172.213.232.128:20337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/alfa-rex.php7"] [unique_id "amuRd48CCDUa19YrTu4yAAAAAWw"]
[Thu Jul 30 13:01:27.300664 2026] [security2:error] [pid 822943:tid 823095] [client 150.107.232.194:26924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRd48CCDUa19YrTu4yAQAAASA"]
[Thu Jul 30 13:01:27.300783 2026] [security2:error] [pid 822943:tid 823095] [client 150.107.232.194:26924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRd48CCDUa19YrTu4yAQAAASA"]
[Thu Jul 30 13:01:27.548832 2026] [security2:error] [pid 822943:tid 823135] [client 20.215.191.139:41601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuRd48CCDUa19YrTu4yBgAAAUg"]
[Thu Jul 30 13:01:27.938414 2026] [security2:error] [pid 822943:tid 823096] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRd48CCDUa19YrTu4yAgABIWY"]
[Thu Jul 30 13:01:28.078412 2026] [security2:error] [pid 822943:tid 823119] [client 172.213.232.128:22853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/alfanew.php"] [unique_id "amuReI8CCDUa19YrTu4yFAAAATg"]
[Thu Jul 30 13:01:28.374615 2026] [security2:error] [pid 822943:tid 823195] [client 43.134.78.217:50000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.78.134.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/index/about/aboutThisPublishingSystem"] [unique_id "amuReI8CCDUa19YrTu4yFgAAAYQ"], referer: https://ejournalugj.com/index_php/index/about/aboutThisPublishingSystem
[Thu Jul 30 13:01:28.800113 2026] [security2:error] [pid 822943:tid 823127] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuReI8CCDUa19YrTu4yIgAAAUA"]
[Thu Jul 30 13:01:29.146771 2026] [security2:error] [pid 822943:tid 823107] [client 172.213.232.128:6617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuReY8CCDUa19YrTu4yOQAAASw"]
[Thu Jul 30 13:01:29.256705 2026] [security2:error] [pid 822943:tid 823145] [client 20.215.191.139:16987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuReY8CCDUa19YrTu4yQAAAAVI"]
[Thu Jul 30 13:01:30.070455 2026] [security2:error] [pid 822943:tid 823142] [client 172.213.232.128:13954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuReo8CCDUa19YrTu4yVgAAAU8"]
[Thu Jul 30 13:01:30.525184 2026] [security2:error] [pid 822943:tid 823096] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuReY8CCDUa19YrTu4yTgAAASE"]
[Thu Jul 30 13:01:30.593662 2026] [security2:error] [pid 822943:tid 823093] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuReo8CCDUa19YrTu4yUgAAAR4"]
[Thu Jul 30 13:01:30.935746 2026] [security2:error] [pid 822943:tid 823134] [client 172.236.9.101:55337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuReo8CCDUa19YrTu4yXQAAAUc"]
[Thu Jul 30 13:01:30.973397 2026] [security2:error] [pid 822943:tid 823118] [client 172.213.232.128:20339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-p.php7"] [unique_id "amuReo8CCDUa19YrTu4yaQAAATc"]
[Thu Jul 30 13:01:32.170475 2026] [security2:error] [pid 822943:tid 823123] [client 20.215.191.139:38179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuRfI8CCDUa19YrTu4yhwAAATw"]
[Thu Jul 30 13:01:32.847991 2026] [security2:error] [pid 822943:tid 823080] [client 20.215.191.139:16490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuRfI8CCDUa19YrTu4yngAAARE"]
[Thu Jul 30 13:01:33.879105 2026] [security2:error] [pid 822943:tid 823000] [remote 216.73.216.152:27109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuRfY8CCDUa19YrTu4yuAABeDg"]
[Thu Jul 30 13:01:34.100217 2026] [security2:error] [pid 822943:tid 823141] [client 172.213.232.128:13991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuRfo8CCDUa19YrTu4yvQAAAU4"]
[Thu Jul 30 13:01:34.538877 2026] [security2:error] [pid 822943:tid 823085] [client 20.215.191.139:64814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuRfo8CCDUa19YrTu4yzAAAARY"]
[Thu Jul 30 13:01:34.683636 2026] [security2:error] [pid 822943:tid 823188] [client 74.7.228.21:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kevinderarslanian.com"] [uri "/index.php"] [unique_id "amuRfY8CCDUa19YrTu4ypwABfSw"]
[Thu Jul 30 13:01:34.683677 2026] [security2:error] [pid 822943:tid 823188] [client 74.7.228.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kevinderarslanian.com"] [uri "/index.php"] [unique_id "amuRfY8CCDUa19YrTu4ypwABfSw"]
[Thu Jul 30 13:01:35.358313 2026] [security2:error] [pid 822943:tid 823098] [client 20.215.191.139:16471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuRf48CCDUa19YrTu4y3QAAASM"]
[Thu Jul 30 13:01:35.786786 2026] [security2:error] [pid 822943:tid 823101] [client 74.7.228.21:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kevinderarslanian.com"] [uri "/index.php"] [unique_id "amuRf48CCDUa19YrTu4y5QABJk0"], referer: https://www.kevinderarslanian.com/robots.txt
[Thu Jul 30 13:01:36.069634 2026] [security2:error] [pid 822943:tid 823118] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRf48CCDUa19YrTu4y3wABN0s"]
[Thu Jul 30 13:01:36.530064 2026] [security2:error] [pid 822943:tid 823047] [remote 57.141.18.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRgI8CCDUa19YrTu4y_wABGGc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Clinen%2Clycra%2Csteel&filter_size=extra-extra-large%2Cextra-large%2Clarge%2Cmedium&orderby=popularity&status=instock&unfilter=1
[Thu Jul 30 13:01:36.757101 2026] [security2:error] [pid 822943:tid 823026] [remote 57.141.18.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRgI8CCDUa19YrTu4y_gABC1I"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Clinen%2Clycra%2Csteel&filter_size=extra-extra-large%2Cextra-large%2Clarge%2Cmedium&orderby=popularity&status=instock&unfilter=1
[Thu Jul 30 13:01:36.916366 2026] [security2:error] [pid 822943:tid 823174] [client 20.215.191.139:47089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuRgI8CCDUa19YrTu4zBAAAAW8"]
[Thu Jul 30 13:01:36.996242 2026] [security2:error] [pid 822943:tid 823073] [client 172.213.232.128:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuRgI8CCDUa19YrTu4zDgAAAQo"]
[Thu Jul 30 13:01:37.257717 2026] [security2:error] [pid 822943:tid 823099] [client 119.73.97.132:30019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuRfo8CCDUa19YrTu4yvAABJDM"]
[Thu Jul 30 13:01:37.330940 2026] [security2:error] [pid 822943:tid 823175] [client 150.107.232.194:27326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRgY8CCDUa19YrTu4zFQAAAXA"]
[Thu Jul 30 13:01:37.331086 2026] [security2:error] [pid 822943:tid 823175] [client 150.107.232.194:27326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRgY8CCDUa19YrTu4zFQAAAXA"]
[Thu Jul 30 13:01:37.649207 2026] [core:notice] [pid 822943:tid 823090] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:37.653053 2026] [security2:error] [pid 822943:tid 823172] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRgI8CCDUa19YrTu4y9wABbT8"]
[Thu Jul 30 13:01:37.871521 2026] [security2:error] [pid 822943:tid 823140] [client 20.215.191.139:47051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuRgY8CCDUa19YrTu4zIwAAAU0"]
[Thu Jul 30 13:01:37.973030 2026] [security2:error] [pid 822943:tid 823198] [client 172.213.232.128:10497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.nordeste1.com"] [uri "/wp-content/repeater.php"] [unique_id "amuRgY8CCDUa19YrTu4zJAAAAYc"]
[Thu Jul 30 13:01:38.034382 2026] [autoindex:error] [pid 822943:tid 823135] [client 103.226.142.125:51625] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:01:38.326131 2026] [autoindex:error] [pid 822943:tid 823194] [client 103.226.142.125:51631] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:01:38.344940 2026] [security2:error] [pid 822943:tid 823129] [client 20.104.18.253:50900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/011i.php"] [unique_id "amuRgo8CCDUa19YrTu4zNQAAAUI"]
[Thu Jul 30 13:01:38.450728 2026] [security2:error] [pid 822943:tid 823076] [client 127.0.0.1:24460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuRgo8CCDUa19YrTu4zNwAAAQ0"]
[Thu Jul 30 13:01:38.450754 2026] [security2:error] [pid 822943:tid 823187] [client 74.7.230.51:52616] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.dws.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuRgo8CCDUa19YrTu4zNgAAAXw"]
[Thu Jul 30 13:01:38.915051 2026] [security2:error] [pid 822943:tid 823087] [client 20.215.191.139:16979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuRgo8CCDUa19YrTu4zRQAAARg"]
[Thu Jul 30 13:01:39.011991 2026] [core:notice] [pid 822943:tid 823115] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:39.131630 2026] [security2:error] [pid 822943:tid 823093] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zOgAAAR4"]
[Thu Jul 30 13:01:39.565040 2026] [core:notice] [pid 822943:tid 823075] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:39.783569 2026] [security2:error] [pid 822943:tid 823095] [client 43.173.179.6:59834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/09/09/une-paire-solidaire-avec-spartoo/"] [unique_id "amuRg48CCDUa19YrTu4zZQAAASA"]
[Thu Jul 30 13:01:40.255123 2026] [security2:error] [pid 822943:tid 823138] [client 172.237.109.114:56242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zSgAAAUs"]
[Thu Jul 30 13:01:40.270786 2026] [security2:error] [pid 822943:tid 823128] [client 172.237.109.114:9436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zSQAAAUE"]
[Thu Jul 30 13:01:40.306500 2026] [security2:error] [pid 822943:tid 823200] [client 172.237.109.114:10627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zTgAAAYk"]
[Thu Jul 30 13:01:40.332300 2026] [security2:error] [pid 822943:tid 823143] [client 172.237.109.114:21474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zTQAAAVA"]
[Thu Jul 30 13:01:40.333112 2026] [security2:error] [pid 822943:tid 823184] [client 172.237.109.114:16464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zTwAAAXk"]
[Thu Jul 30 13:01:40.346271 2026] [security2:error] [pid 822943:tid 823148] [client 172.237.109.114:1697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zVAAAAVU"]
[Thu Jul 30 13:01:40.350867 2026] [security2:error] [pid 822943:tid 823127] [client 172.237.109.114:44533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zWQAAAUA"]
[Thu Jul 30 13:01:40.350912 2026] [security2:error] [pid 822943:tid 823163] [client 172.237.109.114:30547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zSwAAAWQ"]
[Thu Jul 30 13:01:40.356657 2026] [security2:error] [pid 822943:tid 823175] [client 172.237.109.114:15600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zWAAAAXA"]
[Thu Jul 30 13:01:40.363671 2026] [security2:error] [pid 822943:tid 823099] [client 172.237.109.114:3977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zVwAAASQ"]
[Thu Jul 30 13:01:40.366632 2026] [security2:error] [pid 822943:tid 823079] [client 172.237.109.114:59075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRg48CCDUa19YrTu4zXAAAARA"]
[Thu Jul 30 13:01:40.368473 2026] [security2:error] [pid 822943:tid 823098] [client 172.237.109.114:64114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zVQAAASM"]
[Thu Jul 30 13:01:40.368703 2026] [security2:error] [pid 822943:tid 823088] [client 172.237.109.114:9083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zTAAAARk"]
[Thu Jul 30 13:01:40.369902 2026] [security2:error] [pid 822943:tid 823199] [client 172.237.109.114:16285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zUwAAAYg"]
[Thu Jul 30 13:01:40.370224 2026] [security2:error] [pid 822943:tid 823092] [client 172.237.109.114:25707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zVgAAAR0"]
[Thu Jul 30 13:01:40.380084 2026] [security2:error] [pid 822943:tid 823168] [client 172.237.109.114:46911] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRg48CCDUa19YrTu4zWgAAAWk"]
[Thu Jul 30 13:01:40.496305 2026] [core:notice] [pid 822943:tid 823174] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:40.505013 2026] [security2:error] [pid 822943:tid 823174] [client 43.172.198.107:50882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/09/09/une-paire-solidaire-avec-spartoo/"] [unique_id "amuRhI8CCDUa19YrTu4zgwAAAW8"], referer: https://carnetdeshopping.com/index.php/2012/09/09/une-paire-solidaire-avec-spartoo/
[Thu Jul 30 13:01:40.557558 2026] [security2:error] [pid 822943:tid 823125] [client 119.73.97.132:30019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuRgo8CCDUa19YrTu4zKAABPmg"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 13:01:40.664401 2026] [security2:error] [pid 822943:tid 823094] [client 43.173.181.86:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/08/06/shopping-a-miami-mode-chaussures-beaute-mes-bonnes-adresses/"] [unique_id "amuRhI8CCDUa19YrTu4ziAAAAR8"]
[Thu Jul 30 13:01:40.866011 2026] [security2:error] [pid 822943:tid 823173] [client 172.237.109.114:61201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRg48CCDUa19YrTu4zdAAAAW4"]
[Thu Jul 30 13:01:40.866051 2026] [security2:error] [pid 822943:tid 823152] [client 172.237.109.114:29156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRg48CCDUa19YrTu4zdgAAAVk"]
[Thu Jul 30 13:01:40.917589 2026] [security2:error] [pid 822943:tid 823097] [client 172.237.109.114:15416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRg48CCDUa19YrTu4zdQAAASI"]
[Thu Jul 30 13:01:40.940998 2026] [security2:error] [pid 822943:tid 823076] [client 172.237.109.114:25359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRg48CCDUa19YrTu4zdwAAAQ0"]
[Thu Jul 30 13:01:41.290155 2026] [security2:error] [pid 822943:tid 823133] [client 20.215.191.139:47053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuRhY8CCDUa19YrTu4zmQAAAUY"]
[Thu Jul 30 13:01:41.314998 2026] [core:notice] [pid 822943:tid 823160] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:41.322519 2026] [security2:error] [pid 822943:tid 823160] [client 43.173.181.208:44532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/08/06/shopping-a-miami-mode-chaussures-beaute-mes-bonnes-adresses/"] [unique_id "amuRhY8CCDUa19YrTu4zmgAAAWE"], referer: https://carnetdeshopping.com/index.php/2012/08/06/shopping-a-miami-mode-chaussures-beaute-mes-bonnes-adresses/?replytocom=648
[Thu Jul 30 13:01:41.901591 2026] [security2:error] [pid 822943:tid 823191] [client 20.215.191.139:16972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuRhY8CCDUa19YrTu4zqgAAAYA"]
[Thu Jul 30 13:01:41.946147 2026] [security2:error] [pid 822943:tid 823129] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRhY8CCDUa19YrTu4znwAAAUI"]
[Thu Jul 30 13:01:42.521861 2026] [security2:error] [pid 822943:tid 823105] [client 20.104.18.253:38396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/03a005685d.php"] [unique_id "amuRho8CCDUa19YrTu4zvQAAASo"]
[Thu Jul 30 13:01:42.834416 2026] [security2:error] [pid 822943:tid 823097] [client 20.215.191.139:17006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuRho8CCDUa19YrTu4zyAAAASI"]
[Thu Jul 30 13:01:42.930065 2026] [security2:error] [pid 822943:tid 823151] [client 172.236.9.101:33223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRho8CCDUa19YrTu4zuAAAAVg"]
[Thu Jul 30 13:01:43.340942 2026] [security2:error] [pid 822943:tid 823109] [client 20.104.18.253:44880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/403.php"] [unique_id "amuRh48CCDUa19YrTu4z1wAAAS4"]
[Thu Jul 30 13:01:43.560588 2026] [security2:error] [pid 822943:tid 823098] [client 209.35.163.56:3600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuRh48CCDUa19YrTu4z1QABIxs"]
[Thu Jul 30 13:01:43.719618 2026] [security2:error] [pid 822943:tid 823080] [client 68.67.112.191:27276] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.siatfc.com"] [uri "/robots.txt"] [unique_id "amuRh48CCDUa19YrTu4z3wAAARE"]
[Thu Jul 30 13:01:44.656358 2026] [security2:error] [pid 822943:tid 823159] [client 43.173.182.177:35686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/12/02/noel-2012-plus-de-100-idees-cadeaux-pour-elle-mode-voyage-techno-beaute-deco-et-gourmande/"] [unique_id "amuRiI8CCDUa19YrTu4z8wAAAWA"]
[Thu Jul 30 13:01:44.873916 2026] [core:notice] [pid 822943:tid 823131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:44.878895 2026] [security2:error] [pid 822943:tid 823131] [client 43.173.181.61:55494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/12/02/noel-2012-plus-de-100-idees-cadeaux-pour-elle-mode-voyage-techno-beaute-deco-et-gourmande/"] [unique_id "amuRiI8CCDUa19YrTu4z_gAAAUQ"], referer: https://carnetdeshopping.com/index.php/2012/12/02/noel-2012-plus-de-100-idees-cadeaux-pour-elle-mode-voyage-techno-beaute-deco-et-gourmande/
[Thu Jul 30 13:01:45.123168 2026] [security2:error] [pid 822943:tid 823169] [client 54.176.59.18:21106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuRiI8CCDUa19YrTu4z-QAAAWo"]
[Thu Jul 30 13:01:45.317018 2026] [core:notice] [pid 822943:tid 822986] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:46.174622 2026] [security2:error] [pid 822943:tid 823104] [client 20.104.18.253:21535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/404.php"] [unique_id "amuRio8CCDUa19YrTu40HwAAASk"]
[Thu Jul 30 13:01:46.217252 2026] [security2:error] [pid 822943:tid 823091] [client 54.176.59.18:53797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuRiY8CCDUa19YrTu40EQAAARw"]
[Thu Jul 30 13:01:46.660588 2026] [security2:error] [pid 822943:tid 823095] [client 20.215.191.139:16998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuRio8CCDUa19YrTu40KgAAASA"]
[Thu Jul 30 13:01:46.875801 2026] [security2:error] [pid 822943:tid 822957] [remote 57.141.0.29:63660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458216670/feed/rss2/"] [unique_id "amuRio8CCDUa19YrTu40LgABXw0"]
[Thu Jul 30 13:01:47.002096 2026] [core:error] [pid 822943:tid 823107] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.002115 2026] [core:error] [pid 822943:tid 823107] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.035577 2026] [core:error] [pid 822943:tid 823172] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.035596 2026] [core:error] [pid 822943:tid 823172] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.057521 2026] [core:error] [pid 822943:tid 823152] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.057547 2026] [core:error] [pid 822943:tid 823152] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.068264 2026] [core:error] [pid 822943:tid 823149] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.068283 2026] [core:error] [pid 822943:tid 823149] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.092026 2026] [core:error] [pid 822943:tid 823104] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.092046 2026] [core:error] [pid 822943:tid 823104] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.149109 2026] [core:error] [pid 822943:tid 823091] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.149135 2026] [core:error] [pid 822943:tid 823091] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.156528 2026] [security2:error] [pid 822943:tid 823073] [client 20.104.18.253:35851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/aa.php"] [unique_id "amuRi48CCDUa19YrTu40VwAAAQo"]
[Thu Jul 30 13:01:47.354087 2026] [security2:error] [pid 822943:tid 823135] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRi48CCDUa19YrTu40WAABSDY"]
[Thu Jul 30 13:01:47.589290 2026] [security2:error] [pid 822943:tid 823155] [client 20.215.191.139:35280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuRi48CCDUa19YrTu40YwAAAVw"]
[Thu Jul 30 13:01:47.773793 2026] [core:error] [pid 822943:tid 823144] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.773814 2026] [core:error] [pid 822943:tid 823144] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.782385 2026] [security2:error] [pid 822943:tid 823178] [client 150.107.232.194:27076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRi48CCDUa19YrTu40bgAAAXM"]
[Thu Jul 30 13:01:47.782485 2026] [security2:error] [pid 822943:tid 823178] [client 150.107.232.194:27076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRi48CCDUa19YrTu40bgAAAXM"]
[Thu Jul 30 13:01:47.793605 2026] [core:error] [pid 822943:tid 823103] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.793627 2026] [core:error] [pid 822943:tid 823103] [client 32.194.121.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.832826 2026] [core:error] [pid 822943:tid 823092] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:47.832847 2026] [core:error] [pid 822943:tid 823092] [client 34.224.175.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:48.078448 2026] [security2:error] [pid 822943:tid 823125] [client 119.73.97.132:30019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuRiI8CCDUa19YrTu40IAABPjU"]
[Thu Jul 30 13:01:48.412123 2026] [security2:error] [pid 822943:tid 823119] [client 20.104.18.253:34544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/aafewc0k.php"] [unique_id "amuRjI8CCDUa19YrTu40jwAAATg"]
[Thu Jul 30 13:01:48.944554 2026] [core:error] [pid 822943:tid 823185] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:48.944565 2026] [core:error] [pid 822943:tid 823182] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:48.944581 2026] [core:error] [pid 822943:tid 823185] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:48.944585 2026] [core:error] [pid 822943:tid 823182] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:48.974387 2026] [core:error] [pid 822943:tid 823091] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:48.974408 2026] [core:error] [pid 822943:tid 823091] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:49.207033 2026] [security2:error] [pid 822943:tid 823199] [client 50.6.43.217:15658] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuRjY8CCDUa19YrTu40vwAAAYg"]
[Thu Jul 30 13:01:49.274216 2026] [security2:error] [pid 822943:tid 823104] [client 20.104.18.253:32149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/abcd.php"] [unique_id "amuRjY8CCDUa19YrTu40wQAAASk"]
[Thu Jul 30 13:01:49.605386 2026] [security2:error] [pid 822943:tid 823135] [client 20.63.98.115:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/gmo.php"] [unique_id "amuRjY8CCDUa19YrTu400gAAAUg"]
[Thu Jul 30 13:01:49.716510 2026] [security2:error] [pid 822943:tid 823033] [remote 57.141.0.61:47964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33292526407/feed/rss2/"] [unique_id "amuRjY8CCDUa19YrTu400wABX1k"]
[Thu Jul 30 13:01:50.025820 2026] [security2:error] [pid 822943:tid 823186] [client 20.104.18.253:34529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/about.php"] [unique_id "amuRjo8CCDUa19YrTu401wAAAXs"]
[Thu Jul 30 13:01:50.208881 2026] [core:notice] [pid 822943:tid 823117] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:50.277416 2026] [security2:error] [pid 822943:tid 823176] [client 50.6.43.217:15702] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuRjo8CCDUa19YrTu404AAAAXE"]
[Thu Jul 30 13:01:50.722468 2026] [security2:error] [pid 822943:tid 823110] [client 20.63.98.115:57362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/nakrip.php"] [unique_id "amuRjo8CCDUa19YrTu408AAAAS8"]
[Thu Jul 30 13:01:50.801491 2026] [security2:error] [pid 822943:tid 823103] [client 20.104.18.253:55720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/admin.php"] [unique_id "amuRjo8CCDUa19YrTu408QAAASg"]
[Thu Jul 30 13:01:50.843195 2026] [security2:error] [pid 822943:tid 823124] [client 20.215.191.139:47069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuRjo8CCDUa19YrTu408gAAAT0"]
[Thu Jul 30 13:01:51.128996 2026] [security2:error] [pid 822943:tid 823037] [remote 5.161.62.209:24698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.nxt.udi.temporary.site"] [uri "/.env"] [unique_id "amuRj48CCDUa19YrTu40-wABVl0"]
[Thu Jul 30 13:01:51.834341 2026] [security2:error] [pid 822943:tid 823115] [client 172.236.9.101:34135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRj48CCDUa19YrTu40_wAAATQ"]
[Thu Jul 30 13:01:52.172045 2026] [security2:error] [pid 822943:tid 823143] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRj48CCDUa19YrTu41CAAAAVA"]
[Thu Jul 30 13:01:52.377260 2026] [security2:error] [pid 822943:tid 823077] [client 20.104.18.253:44875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/adminfuns.php"] [unique_id "amuRkI8CCDUa19YrTu41FQAAAQ4"]
[Thu Jul 30 13:01:52.665942 2026] [core:notice] [pid 822943:tid 823117] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:01:53.172077 2026] [security2:error] [pid 822943:tid 823144] [client 20.104.18.253:34541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/albin.php"] [unique_id "amuRkY8CCDUa19YrTu41MgAAAVE"]
[Thu Jul 30 13:01:53.333134 2026] [security2:error] [pid 822943:tid 822950] [remote 5.161.62.209:25648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ocl.djb.temporary.site"] [uri "/.env"] [unique_id "amuRkY8CCDUa19YrTu41NgABXQY"]
[Thu Jul 30 13:01:53.529055 2026] [security2:error] [pid 822943:tid 823119] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRkI8CCDUa19YrTu41KgAAATg"]
[Thu Jul 30 13:01:53.686655 2026] [core:error] [pid 822943:tid 823065] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:53.686677 2026] [core:error] [pid 822943:tid 823065] [remote 52.4.19.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:53.696274 2026] [core:error] [pid 822943:tid 823055] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:53.696292 2026] [core:error] [pid 822943:tid 823055] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:53.714080 2026] [core:error] [pid 822943:tid 823068] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:53.714107 2026] [core:error] [pid 822943:tid 823068] [remote 3.225.222.228:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:53.852539 2026] [security2:error] [pid 822943:tid 823114] [client 20.104.18.253:44876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/amfsqvgv.php"] [unique_id "amuRkY8CCDUa19YrTu41SAAAATM"]
[Thu Jul 30 13:01:54.410513 2026] [security2:error] [pid 822943:tid 822967] [remote 57.141.0.65:23310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/390124662/feed/rss2/"] [unique_id "amuRko8CCDUa19YrTu41WAABbxc"]
[Thu Jul 30 13:01:54.822294 2026] [security2:error] [pid 822943:tid 823096] [client 20.63.98.115:39664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/radio.php"] [unique_id "amuRko8CCDUa19YrTu41YgAAASE"]
[Thu Jul 30 13:01:54.917601 2026] [security2:error] [pid 822943:tid 823189] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRko8CCDUa19YrTu41VwAAAX4"]
[Thu Jul 30 13:01:55.698769 2026] [security2:error] [pid 822943:tid 823179] [client 74.7.230.47:49094] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.asd.fyv.temporary.site"] [uri "/robots.txt"] [unique_id "amuRk48CCDUa19YrTu41dgAAAXQ"]
[Thu Jul 30 13:01:55.708371 2026] [fcgid:warn] [pid 822943:tid 823088] (70014)End of file found: [client 165.154.11.140:48688] mod_fcgid: can't get data from http client
[Thu Jul 30 13:01:55.977302 2026] [security2:error] [pid 822943:tid 823127] [client 20.63.98.115:57402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-singin.php"] [unique_id "amuRk48CCDUa19YrTu41fgAAAUA"]
[Thu Jul 30 13:01:56.106589 2026] [core:error] [pid 822943:tid 823167] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:56.106612 2026] [core:error] [pid 822943:tid 823167] [client 44.216.125.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:56.117829 2026] [core:error] [pid 822943:tid 823118] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:56.117847 2026] [core:error] [pid 822943:tid 823118] [client 18.211.55.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:56.133232 2026] [core:error] [pid 822943:tid 823162] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:56.133254 2026] [core:error] [pid 822943:tid 823162] [client 98.87.102.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:01:56.645790 2026] [security2:error] [pid 822943:tid 823159] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRlI8CCDUa19YrTu41gQAAAWA"]
[Thu Jul 30 13:01:56.661082 2026] [security2:error] [pid 822943:tid 823081] [client 20.104.18.253:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/ant.php"] [unique_id "amuRlI8CCDUa19YrTu41ogAAARI"]
[Thu Jul 30 13:01:57.446363 2026] [security2:error] [pid 822943:tid 823096] [client 20.104.18.253:37763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/appreciators.php"] [unique_id "amuRlY8CCDUa19YrTu41vQAAASE"]
[Thu Jul 30 13:01:58.252201 2026] [security2:error] [pid 822943:tid 823172] [client 150.107.232.194:26626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRlo8CCDUa19YrTu411QAAAW0"]
[Thu Jul 30 13:01:58.252324 2026] [security2:error] [pid 822943:tid 823172] [client 150.107.232.194:26626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRlo8CCDUa19YrTu411QAAAW0"]
[Thu Jul 30 13:01:58.270258 2026] [security2:error] [pid 822943:tid 823159] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRlo8CCDUa19YrTu411AABYDI"]
[Thu Jul 30 13:01:58.575656 2026] [security2:error] [pid 822943:tid 822957] [remote 57.141.18.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRlo8CCDUa19YrTu414QABDw0"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,nylon,steel,titanium&filter_size=extra-large,large&orderby=price&unfilter=1
[Thu Jul 30 13:01:58.635755 2026] [security2:error] [pid 822943:tid 823200] [client 20.104.18.253:34559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/archive.php"] [unique_id "amuRlo8CCDUa19YrTu414gAAAYk"]
[Thu Jul 30 13:01:58.678100 2026] [security2:error] [pid 822943:tid 822996] [remote 57.141.18.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRlo8CCDUa19YrTu412QABNDQ"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,nylon,steel,titanium&filter_size=extra-large,large&orderby=price&unfilter=1
[Thu Jul 30 13:01:58.767998 2026] [security2:error] [pid 822943:tid 823167] [client 20.63.98.115:1730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/as.php"] [unique_id "amuRlo8CCDUa19YrTu414wAAAWg"]
[Thu Jul 30 13:01:59.843855 2026] [security2:error] [pid 822943:tid 823122] [client 121.229.156.56:51308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carnetdeshopping.com"] [uri "/swarovski-printemps-ete-2017"] [unique_id "amuRl48CCDUa19YrTu418QAAATs"]
[Thu Jul 30 13:01:59.843962 2026] [security2:error] [pid 822943:tid 823122] [client 121.229.156.56:51308] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "carnetdeshopping.com"] [uri "/swarovski-printemps-ete-2017"] [unique_id "amuRl48CCDUa19YrTu418QAAATs"]
[Thu Jul 30 13:02:00.050032 2026] [security2:error] [pid 822943:tid 823181] [client 20.63.98.115:46809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/x.php"] [unique_id "amuRmI8CCDUa19YrTu41_wAAAXY"]
[Thu Jul 30 13:02:00.648955 2026] [core:error] [pid 822943:tid 823163] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:00.649022 2026] [core:error] [pid 822943:tid 823163] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:00.657320 2026] [core:error] [pid 822943:tid 823074] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:00.657348 2026] [core:error] [pid 822943:tid 823074] [client 3.228.112.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:00.713718 2026] [core:error] [pid 822943:tid 823171] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:00.713739 2026] [core:error] [pid 822943:tid 823171] [client 54.87.222.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:01.599736 2026] [security2:error] [pid 822943:tid 823118] [client 20.104.18.253:44873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/as.php"] [unique_id "amuRmY8CCDUa19YrTu42LAAAATc"]
[Thu Jul 30 13:02:01.741183 2026] [core:notice] [pid 822943:tid 823029] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:02.398552 2026] [core:notice] [pid 822943:tid 822977] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:02.457066 2026] [security2:error] [pid 822943:tid 823173] [client 20.104.18.253:47835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/atomlib.php"] [unique_id "amuRmo8CCDUa19YrTu42PAAAAW4"]
[Thu Jul 30 13:02:02.682801 2026] [security2:error] [pid 822943:tid 823177] [client 74.7.228.52:53128] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kicksity.com"] [uri "/robots.txt"] [unique_id "amuRmo8CCDUa19YrTu42RgABclk"]
[Thu Jul 30 13:02:02.849313 2026] [security2:error] [pid 822943:tid 823111] [client 172.236.9.101:26539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRmo8CCDUa19YrTu42OgAAATA"]
[Thu Jul 30 13:02:02.910903 2026] [security2:error] [pid 822943:tid 823138] [client 163.7.15.212:16429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuRmo8CCDUa19YrTu42RwAAAUs"]
[Thu Jul 30 13:02:03.709007 2026] [security2:error] [pid 822943:tid 823118] [client 74.7.230.61:57926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "qzb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuRm48CCDUa19YrTu42VQABN0Y"]
[Thu Jul 30 13:02:03.840321 2026] [security2:error] [pid 822943:tid 823104] [client 172.236.9.101:26873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRm48CCDUa19YrTu42WAAAASk"]
[Thu Jul 30 13:02:04.113090 2026] [security2:error] [pid 822943:tid 823078] [client 20.104.18.253:51454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/autoload_classmap.php"] [unique_id "amuRnI8CCDUa19YrTu42agAAAQ8"]
[Thu Jul 30 13:02:04.918420 2026] [security2:error] [pid 822943:tid 823090] [client 20.104.18.253:47215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/bb.php"] [unique_id "amuRnI8CCDUa19YrTu42fAAAARs"]
[Thu Jul 30 13:02:05.511655 2026] [security2:error] [pid 822943:tid 823200] [client 20.63.98.115:39639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/item.php"] [unique_id "amuRnY8CCDUa19YrTu42igAAAYk"]
[Thu Jul 30 13:02:05.681179 2026] [security2:error] [pid 822943:tid 823118] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRnY8CCDUa19YrTu42gwAAATc"]
[Thu Jul 30 13:02:06.072606 2026] [core:notice] [pid 822943:tid 823123] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:06.344250 2026] [security2:error] [pid 822943:tid 823134] [client 177.201.141.47:40680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.raad.pk"] [uri "/index.php"] [unique_id "amuRno8CCDUa19YrTu42mQAAAUc"]
[Thu Jul 30 13:02:06.555446 2026] [security2:error] [pid 822943:tid 823112] [client 20.104.18.253:42775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/bnm.php"] [unique_id "amuRno8CCDUa19YrTu42oQAAATE"]
[Thu Jul 30 13:02:06.972678 2026] [security2:error] [pid 822943:tid 823125] [client 177.201.141.47:40724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuRno8CCDUa19YrTu42qQAAAT4"], referer: https://www.raad.pk/users/sign_in
[Thu Jul 30 13:02:07.024064 2026] [security2:error] [pid 822943:tid 823099] [client 20.63.98.115:57348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/app.php"] [unique_id "amuRn48CCDUa19YrTu42tgAAASQ"]
[Thu Jul 30 13:02:07.026137 2026] [security2:error] [pid 822943:tid 823162] [client 5.161.62.209:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.otbola.click"] [uri "/.env"] [unique_id "amuRn48CCDUa19YrTu42twAAAWM"]
[Thu Jul 30 13:02:07.171102 2026] [security2:error] [pid 822943:tid 823054] [remote 74.7.241.60:57216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/login.php"] [unique_id "amuRn48CCDUa19YrTu42uwABDG4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 13:02:07.300761 2026] [security2:error] [pid 822943:tid 823087] [client 68.67.112.242:15138] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuRn48CCDUa19YrTu42vAAAARg"]
[Thu Jul 30 13:02:07.322293 2026] [security2:error] [pid 822943:tid 823111] [client 20.104.18.253:47192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/bootstrap.php"] [unique_id "amuRn48CCDUa19YrTu42vwAAATA"]
[Thu Jul 30 13:02:07.365534 2026] [security2:error] [pid 822943:tid 823137] [client 177.201.141.47:40680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.raad.pk"] [uri "/.env"] [unique_id "amuRn48CCDUa19YrTu42wQAAAUo"]
[Thu Jul 30 13:02:07.446713 2026] [security2:error] [pid 822943:tid 823145] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRno8CCDUa19YrTu42sgAAAVI"]
[Thu Jul 30 13:02:08.197144 2026] [security2:error] [pid 822943:tid 823090] [client 20.104.18.253:28847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/buy.php"] [unique_id "amuRoI8CCDUa19YrTu422QAAARs"]
[Thu Jul 30 13:02:08.595782 2026] [security2:error] [pid 822943:tid 823185] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRn48CCDUa19YrTu421AABenY"]
[Thu Jul 30 13:02:08.779894 2026] [security2:error] [pid 822943:tid 823125] [client 150.107.232.194:27339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRoI8CCDUa19YrTu426AAAAT4"]
[Thu Jul 30 13:02:08.780020 2026] [security2:error] [pid 822943:tid 823125] [client 150.107.232.194:27339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRoI8CCDUa19YrTu426AAAAT4"]
[Thu Jul 30 13:02:09.059676 2026] [security2:error] [pid 822943:tid 823108] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRoI8CCDUa19YrTu427AABLWA"]
[Thu Jul 30 13:02:09.526590 2026] [security2:error] [pid 822943:tid 823127] [client 20.104.18.253:30278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/chosen.php"] [unique_id "amuRoY8CCDUa19YrTu42_AAAAUA"]
[Thu Jul 30 13:02:09.802733 2026] [core:notice] [pid 822943:tid 823183] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:10.140378 2026] [security2:error] [pid 822943:tid 823104] [client 177.201.141.47:40680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.raad.pk"] [uri "/index.php"] [unique_id "amuRoY8CCDUa19YrTu43BAAAASk"]
[Thu Jul 30 13:02:10.347567 2026] [security2:error] [pid 822943:tid 823159] [client 20.104.18.253:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/class-wp-image.php"] [unique_id "amuRoo8CCDUa19YrTu43CwAAAWA"]
[Thu Jul 30 13:02:10.601732 2026] [core:notice] [pid 822943:tid 823086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:10.712203 2026] [security2:error] [pid 822943:tid 823158] [client 177.201.141.47:40680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.raad.pk"] [uri "/index.php"] [unique_id "amuRoo8CCDUa19YrTu43EgAAAV8"]
[Thu Jul 30 13:02:11.100162 2026] [core:notice] [pid 822943:tid 823129] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:11.110341 2026] [security2:error] [pid 822943:tid 823117] [client 20.104.18.253:55683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/classsmtps.php"] [unique_id "amuRo48CCDUa19YrTu43IwAAATY"]
[Thu Jul 30 13:02:11.336088 2026] [security2:error] [pid 822943:tid 823145] [client 177.201.141.47:40724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuRo48CCDUa19YrTu43IgAAAVI"], referer: https://www.raad.pk/_ignition/health-check
[Thu Jul 30 13:02:11.900277 2026] [security2:error] [pid 822943:tid 823197] [client 193.148.16.211:49656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.16.148.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuRo48CCDUa19YrTu43MwAAAYY"]
[Thu Jul 30 13:02:11.900429 2026] [security2:error] [pid 822943:tid 823197] [client 193.148.16.211:49656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuRo48CCDUa19YrTu43MwAAAYY"]
[Thu Jul 30 13:02:11.905688 2026] [security2:error] [pid 822943:tid 823116] [client 177.201.141.47:40680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.raad.pk"] [uri "/index.php"] [unique_id "amuRo48CCDUa19YrTu43LwAAATU"]
[Thu Jul 30 13:02:12.171170 2026] [security2:error] [pid 822943:tid 823198] [client 20.104.18.253:42804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/classwithtostring.php"] [unique_id "amuRpI8CCDUa19YrTu43OgAAAYc"]
[Thu Jul 30 13:02:12.198620 2026] [security2:error] [pid 822943:tid 823173] [client 20.63.98.115:39635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/k.php"] [unique_id "amuRpI8CCDUa19YrTu43PQAAAW4"]
[Thu Jul 30 13:02:12.535446 2026] [security2:error] [pid 822943:tid 823084] [client 177.201.141.47:40724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuRpI8CCDUa19YrTu43PgAAARU"], referer: https://www.raad.pk/_debugbar/open
[Thu Jul 30 13:02:12.634398 2026] [security2:error] [pid 822943:tid 823178] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRpI8CCDUa19YrTu43NAABcxk"]
[Thu Jul 30 13:02:12.703865 2026] [security2:error] [pid 822943:tid 823169] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRpI8CCDUa19YrTu43OAABagU"]
[Thu Jul 30 13:02:13.073595 2026] [security2:error] [pid 822943:tid 823140] [client 20.63.98.115:46839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-fmfile.php"] [unique_id "amuRpY8CCDUa19YrTu43VQAAAU0"]
[Thu Jul 30 13:02:13.101710 2026] [security2:error] [pid 822943:tid 823150] [client 177.201.141.47:40680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.raad.pk"] [uri "/index.php"] [unique_id "amuRpI8CCDUa19YrTu43UQAAAVc"]
[Thu Jul 30 13:02:13.247997 2026] [security2:error] [pid 822943:tid 823177] [client 20.104.18.253:34535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/config.php"] [unique_id "amuRpY8CCDUa19YrTu43XAAAAXI"]
[Thu Jul 30 13:02:13.722949 2026] [security2:error] [pid 822943:tid 823133] [client 177.201.141.47:40724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuRpY8CCDUa19YrTu43YAAAAUY"], referer: https://www.raad.pk/telescope
[Thu Jul 30 13:02:13.951090 2026] [security2:error] [pid 822943:tid 822989] [remote 87.250.224.4:55656] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/category/technology/"] [unique_id "amuRpY8CCDUa19YrTu43awABcy0"]
[Thu Jul 30 13:02:13.983010 2026] [security2:error] [pid 822943:tid 823175] [client 20.63.98.115:1802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wi.php"] [unique_id "amuRpY8CCDUa19YrTu43bQAAAXA"]
[Thu Jul 30 13:02:14.409538 2026] [security2:error] [pid 822943:tid 823143] [client 20.104.18.253:53151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/core.php"] [unique_id "amuRpo8CCDUa19YrTu43fQAAAVA"]
[Thu Jul 30 13:02:14.633146 2026] [security2:error] [pid 822943:tid 823107] [client 172.237.109.114:62494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRpo8CCDUa19YrTu43bwAAASw"]
[Thu Jul 30 13:02:14.656627 2026] [security2:error] [pid 822943:tid 823139] [client 172.237.109.114:57403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRpo8CCDUa19YrTu43bgAAAUw"]
[Thu Jul 30 13:02:14.731363 2026] [security2:error] [pid 822943:tid 823080] [client 172.237.109.114:26702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRpo8CCDUa19YrTu43cQAAARE"]
[Thu Jul 30 13:02:14.735561 2026] [security2:error] [pid 822943:tid 823181] [client 172.237.109.114:28792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRpo8CCDUa19YrTu43cgAAAXY"]
[Thu Jul 30 13:02:14.856208 2026] [core:notice] [pid 822943:tid 823200] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:15.096218 2026] [security2:error] [pid 822943:tid 823090] [client 149.202.52.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuRpo8CCDUa19YrTu43kAAAARs"]
[Thu Jul 30 13:02:15.208368 2026] [security2:error] [pid 822943:tid 823147] [client 151.80.133.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuRp48CCDUa19YrTu43lgAAAVQ"]
[Thu Jul 30 13:02:15.348789 2026] [security2:error] [pid 822943:tid 823175] [client 20.104.18.253:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/css.php"] [unique_id "amuRp48CCDUa19YrTu43oAAAAXA"]
[Thu Jul 30 13:02:15.595204 2026] [security2:error] [pid 822943:tid 823106] [client 177.201.141.47:40680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.raad.pk"] [uri "/index.php"] [unique_id "amuRp48CCDUa19YrTu43ogAAASs"]
[Thu Jul 30 13:02:15.617842 2026] [security2:error] [pid 822943:tid 823098] [client 172.237.109.114:46363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRp48CCDUa19YrTu43mAAAASM"]
[Thu Jul 30 13:02:15.678598 2026] [security2:error] [pid 822943:tid 823128] [client 177.183.215.20:2047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuRp48CCDUa19YrTu43oQAAAUE"]
[Thu Jul 30 13:02:16.089584 2026] [security2:error] [pid 822943:tid 823158] [client 57.141.0.26:64112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuRp48CCDUa19YrTu43qQABXwc"], referer: https://igetvape-australia.com/product-category/iget-bar/?add-to-cart=128
[Thu Jul 30 13:02:16.171636 2026] [security2:error] [pid 822943:tid 823101] [client 177.201.141.47:40724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuRp48CCDUa19YrTu43rgAAASY"], referer: https://www.raad.pk/login/
[Thu Jul 30 13:02:16.277738 2026] [security2:error] [pid 822943:tid 823081] [client 20.104.18.253:47210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/database.php"] [unique_id "amuRqI8CCDUa19YrTu43tgAAARI"]
[Thu Jul 30 13:02:16.862574 2026] [security2:error] [pid 822943:tid 823089] [client 141.94.94.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuRqI8CCDUa19YrTu43xAAAARo"]
[Thu Jul 30 13:02:16.886348 2026] [security2:error] [pid 822943:tid 823167] [client 20.63.98.115:46841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/php8.php"] [unique_id "amuRqI8CCDUa19YrTu43yAAAAWg"]
[Thu Jul 30 13:02:17.087881 2026] [security2:error] [pid 822943:tid 823162] [client 177.201.141.47:40724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.141.201.177.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-login.php"] [unique_id "amuRqI8CCDUa19YrTu43vgAAAWM"], referer: https://raad.pk/login/
[Thu Jul 30 13:02:17.476708 2026] [security2:error] [pid 822943:tid 823102] [client 177.201.141.47:40680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.141.201.177.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.raad.pk"] [uri "/login/index.php"] [unique_id "amuRqY8CCDUa19YrTu433AAAASc"]
[Thu Jul 30 13:02:18.599389 2026] [security2:error] [pid 822943:tid 823174] [client 20.104.18.253:47190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/db.php"] [unique_id "amuRqo8CCDUa19YrTu43-QAAAW8"]
[Thu Jul 30 13:02:18.599700 2026] [security2:error] [pid 822943:tid 823114] [client 74.7.244.32:48326] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "threads-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuRqo8CCDUa19YrTu43-AABM1k"]
[Thu Jul 30 13:02:18.759530 2026] [security2:error] [pid 822943:tid 823106] [client 172.236.9.101:4779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRqo8CCDUa19YrTu438wAAASs"]
[Thu Jul 30 13:02:19.247451 2026] [security2:error] [pid 822943:tid 823118] [client 150.107.232.194:27252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRq48CCDUa19YrTu44EAAAATc"]
[Thu Jul 30 13:02:19.247555 2026] [security2:error] [pid 822943:tid 823118] [client 150.107.232.194:27252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRq48CCDUa19YrTu44EAAAATc"]
[Thu Jul 30 13:02:19.251266 2026] [security2:error] [pid 822943:tid 823084] [client 177.201.141.47:41038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.raad.pk"] [uri "/index.php"] [unique_id "amuRq48CCDUa19YrTu44BAAAARU"]
[Thu Jul 30 13:02:19.444186 2026] [autoindex:error] [pid 822943:tid 823037] [remote 74.7.241.13:51706] AH01276: Cannot serve directory /home1/yqegzjte/threads-portfolio.txend.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:02:19.584953 2026] [security2:error] [pid 822943:tid 823188] [client 20.104.18.253:38327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/default.php"] [unique_id "amuRq48CCDUa19YrTu44GAAAAX0"]
[Thu Jul 30 13:02:19.814910 2026] [security2:error] [pid 822943:tid 823175] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRq48CCDUa19YrTu44HgABcHE"]
[Thu Jul 30 13:02:20.841784 2026] [security2:error] [pid 822943:tid 823119] [client 177.201.141.47:41072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuRrI8CCDUa19YrTu44NAAAATg"], referer: https://www.raad.pk/geoserver/web/
[Thu Jul 30 13:02:21.388480 2026] [security2:error] [pid 822943:tid 823191] [client 20.104.18.253:27440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/dropdown.php"] [unique_id "amuRrY8CCDUa19YrTu44TwAAAYA"]
[Thu Jul 30 13:02:21.563942 2026] [security2:error] [pid 822943:tid 823116] [client 177.201.141.47:41038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.raad.pk"] [uri "/index.php"] [unique_id "amuRrY8CCDUa19YrTu44TgAAATU"]
[Thu Jul 30 13:02:22.193319 2026] [core:notice] [pid 822943:tid 823171] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:22.204937 2026] [security2:error] [pid 822943:tid 823137] [client 177.201.141.47:41072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuRrY8CCDUa19YrTu44hQAAAUo"], referer: https://www.raad.pk/geoserver/rest/about/version.json
[Thu Jul 30 13:02:22.843216 2026] [security2:error] [pid 822943:tid 823129] [client 20.63.98.115:37620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/tes.php"] [unique_id "amuRro8CCDUa19YrTu44mwAAAUI"]
[Thu Jul 30 13:02:23.183869 2026] [security2:error] [pid 822943:tid 822994] [remote 57.141.18.70:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRr48CCDUa19YrTu44pAABIDI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=cotton,denim,lycra,polyester,titanium&filter_size=extra-large,large,medium&orderby=rating&status=instock&tax_product_cat=suit&unfilter=1
[Thu Jul 30 13:02:23.219703 2026] [security2:error] [pid 822943:tid 822997] [remote 57.141.18.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuRr48CCDUa19YrTu44pQABXzU"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=cotton,denim,lycra,polyester,titanium&filter_size=extra-large,large,medium&orderby=rating&status=instock&tax_product_cat=suit&unfilter=1
[Thu Jul 30 13:02:23.495405 2026] [autoindex:error] [pid 822943:tid 823128] [client 192.144.148.122:40410] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:02:23.511015 2026] [security2:error] [pid 822943:tid 823099] [client 20.104.18.253:47173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/edit.php"] [unique_id "amuRr48CCDUa19YrTu44swAAASQ"]
[Thu Jul 30 13:02:24.161748 2026] [security2:error] [pid 822943:tid 823181] [client 20.63.98.115:1103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/about.php"] [unique_id "amuRsI8CCDUa19YrTu44vgAAAXY"]
[Thu Jul 30 13:02:24.355662 2026] [security2:error] [pid 822943:tid 823081] [client 204.8.98.105:49512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuRsI8CCDUa19YrTu44xwAAARI"]
[Thu Jul 30 13:02:24.355787 2026] [security2:error] [pid 822943:tid 823081] [client 204.8.98.105:49512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuRsI8CCDUa19YrTu44xwAAARI"]
[Thu Jul 30 13:02:24.723884 2026] [security2:error] [pid 822943:tid 823078] [client 193.148.16.211:32904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.16.148.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRsI8CCDUa19YrTu44zgAAAQ8"]
[Thu Jul 30 13:02:24.724018 2026] [security2:error] [pid 822943:tid 823078] [client 193.148.16.211:32904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRsI8CCDUa19YrTu44zgAAAQ8"]
[Thu Jul 30 13:02:25.415959 2026] [security2:error] [pid 822943:tid 823073] [client 202.29.220.126:21818] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuRsY8CCDUa19YrTu445gAAAQo"]
[Thu Jul 30 13:02:25.478623 2026] [security2:error] [pid 822943:tid 823190] [client 202.29.220.126:50894] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuRsY8CCDUa19YrTu445wAAAX8"]
[Thu Jul 30 13:02:25.536723 2026] [security2:error] [pid 822943:tid 823142] [client 20.104.18.253:30968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/f35.php"] [unique_id "amuRsY8CCDUa19YrTu446gAAAU8"]
[Thu Jul 30 13:02:25.632501 2026] [security2:error] [pid 822943:tid 823167] [client 172.237.109.114:48789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRsY8CCDUa19YrTu442QAAAWg"]
[Thu Jul 30 13:02:25.745137 2026] [security2:error] [pid 822943:tid 823192] [client 172.237.109.114:53579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRsY8CCDUa19YrTu442gAAAYE"]
[Thu Jul 30 13:02:25.745139 2026] [security2:error] [pid 822943:tid 823148] [client 172.237.109.114:33933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRsY8CCDUa19YrTu442wAAAVU"]
[Thu Jul 30 13:02:25.749690 2026] [security2:error] [pid 822943:tid 823186] [client 172.237.109.114:54991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRsY8CCDUa19YrTu443QAAAXs"]
[Thu Jul 30 13:02:25.778778 2026] [security2:error] [pid 822943:tid 823074] [client 172.237.109.114:53770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRsY8CCDUa19YrTu444QAAAQs"]
[Thu Jul 30 13:02:25.782416 2026] [security2:error] [pid 822943:tid 823139] [client 172.237.109.114:30178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRsY8CCDUa19YrTu443AAAAUw"]
[Thu Jul 30 13:02:25.812870 2026] [security2:error] [pid 822943:tid 823110] [client 172.237.109.114:24033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRsY8CCDUa19YrTu444gAAAS8"]
[Thu Jul 30 13:02:26.361909 2026] [security2:error] [pid 822943:tid 823010] [remote 74.7.241.59:38624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuRso8CCDUa19YrTu45CgABdkI"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/insert-headers-and-footers/includes
[Thu Jul 30 13:02:26.390942 2026] [security2:error] [pid 822943:tid 823193] [client 20.104.18.253:42806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.northyorksheridanmall.com"] [uri "/f7.php"] [unique_id "amuRso8CCDUa19YrTu45DQAAAYI"]
[Thu Jul 30 13:02:26.715304 2026] [security2:error] [pid 822943:tid 823198] [client 172.237.109.114:59725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu44-wAAAYc"]
[Thu Jul 30 13:02:26.728745 2026] [security2:error] [pid 822943:tid 823096] [client 172.237.109.114:37821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu44_QAAASE"]
[Thu Jul 30 13:02:26.729566 2026] [security2:error] [pid 822943:tid 823120] [client 172.237.109.114:23025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu44_AAAATk"]
[Thu Jul 30 13:02:26.736352 2026] [security2:error] [pid 822943:tid 823189] [client 172.237.109.114:29266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu44-gAAAX4"]
[Thu Jul 30 13:02:26.750859 2026] [security2:error] [pid 822943:tid 823126] [client 172.237.109.114:35989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu44_wAAAT8"]
[Thu Jul 30 13:02:26.764075 2026] [security2:error] [pid 822943:tid 823162] [client 172.237.109.114:28905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu45AAAAAWM"]
[Thu Jul 30 13:02:26.764879 2026] [security2:error] [pid 822943:tid 823199] [client 172.237.109.114:10014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu45BgAAAYg"]
[Thu Jul 30 13:02:27.276148 2026] [security2:error] [pid 822943:tid 823176] [client 172.237.109.114:53173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu45CAAAAXE"]
[Thu Jul 30 13:02:27.279467 2026] [security2:error] [pid 822943:tid 823083] [client 172.237.109.114:10671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu45BAAAARQ"]
[Thu Jul 30 13:02:27.296101 2026] [security2:error] [pid 822943:tid 823172] [client 172.237.109.114:14333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu45AwAAAW0"]
[Thu Jul 30 13:02:27.311387 2026] [security2:error] [pid 822943:tid 823155] [client 172.237.109.114:4796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu45BwAAAVw"]
[Thu Jul 30 13:02:27.316561 2026] [security2:error] [pid 822943:tid 823161] [client 172.237.109.114:16579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu45BQAAAWI"]
[Thu Jul 30 13:02:27.344423 2026] [security2:error] [pid 822943:tid 823124] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRso8CCDUa19YrTu45FwAAAT0"]
[Thu Jul 30 13:02:27.747016 2026] [security2:error] [pid 822943:tid 823099] [client 172.237.109.114:5447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRs48CCDUa19YrTu45IQAAASQ"]
[Thu Jul 30 13:02:27.776293 2026] [security2:error] [pid 822943:tid 823186] [client 49.51.204.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRs48CCDUa19YrTu45HgABezs"]
[Thu Jul 30 13:02:29.259236 2026] [security2:error] [pid 822943:tid 823182] [client 74.7.241.136:54286] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lgg.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuRtY8CCDUa19YrTu45YgABd18"]
[Thu Jul 30 13:02:29.508970 2026] [security2:error] [pid 822943:tid 823080] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRtI8CCDUa19YrTu45WgAAARE"]
[Thu Jul 30 13:02:29.604949 2026] [security2:error] [pid 822943:tid 823149] [client 20.63.98.115:1421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/headers.php"] [unique_id "amuRtY8CCDUa19YrTu45bgAAAVY"]
[Thu Jul 30 13:02:29.732607 2026] [security2:error] [pid 822943:tid 823184] [client 150.107.232.194:26807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.232.107.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRtY8CCDUa19YrTu45bwAAAXk"]
[Thu Jul 30 13:02:29.732747 2026] [security2:error] [pid 822943:tid 823184] [client 150.107.232.194:26807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuRtY8CCDUa19YrTu45bwAAAXk"]
[Thu Jul 30 13:02:30.666829 2026] [security2:error] [pid 822943:tid 823199] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRto8CCDUa19YrTu45iQABiHw"]
[Thu Jul 30 13:02:31.153640 2026] [security2:error] [pid 822943:tid 823159] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuRto8CCDUa19YrTu45iAABYHQ"]
[Thu Jul 30 13:02:31.305906 2026] [security2:error] [pid 822943:tid 823132] [client 20.63.98.115:37608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/admin.php"] [unique_id "amuRt48CCDUa19YrTu45nAAAAUU"]
[Thu Jul 30 13:02:32.193426 2026] [security2:error] [pid 822943:tid 823099] [client 20.63.98.115:53974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/flower.php"] [unique_id "amuRuI8CCDUa19YrTu45swAAASQ"]
[Thu Jul 30 13:02:32.853241 2026] [core:error] [pid 822943:tid 822944] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:32.853266 2026] [core:error] [pid 822943:tid 822944] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:33.183085 2026] [core:notice] [pid 822943:tid 822960] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:33.391055 2026] [core:notice] [pid 822943:tid 822978] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:33.478045 2026] [core:error] [pid 822943:tid 822969] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:33.478069 2026] [core:error] [pid 822943:tid 822969] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:02:34.367679 2026] [security2:error] [pid 822943:tid 823109] [client 20.63.98.115:37396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuRuo8CCDUa19YrTu45-QAAAS4"]
[Thu Jul 30 13:02:34.766905 2026] [security2:error] [pid 822943:tid 823180] [client 172.236.9.101:57413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRuo8CCDUa19YrTu459AAAAXU"]
[Thu Jul 30 13:02:34.826868 2026] [security2:error] [pid 822943:tid 823093] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRuo8CCDUa19YrTu458wAAAR4"]
[Thu Jul 30 13:02:35.158741 2026] [security2:error] [pid 822943:tid 823096] [client 143.44.164.177:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.164.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "xexrecords.online"] [uri "/xmlrpc.php"] [unique_id "amuRu48CCDUa19YrTu46DwAAASE"]
[Thu Jul 30 13:02:35.158925 2026] [security2:error] [pid 822943:tid 823096] [client 143.44.164.177:62283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "xexrecords.online"] [uri "/xmlrpc.php"] [unique_id "amuRu48CCDUa19YrTu46DwAAASE"]
[Thu Jul 30 13:02:35.313670 2026] [security2:error] [pid 822943:tid 823132] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuRu48CCDUa19YrTu46DgAAAUU"]
[Thu Jul 30 13:02:37.674820 2026] [security2:error] [pid 822943:tid 823105] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRvY8CCDUa19YrTu46OwAAASo"]
[Thu Jul 30 13:02:37.793090 2026] [core:notice] [pid 822943:tid 823019] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:38.496405 2026] [security2:error] [pid 822943:tid 823033] [remote 5.161.62.209:43522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.plumbingplumb.com"] [uri "/.env"] [unique_id "amuRvo8CCDUa19YrTu46XQABR1k"]
[Thu Jul 30 13:02:39.482608 2026] [security2:error] [pid 822943:tid 823114] [client 20.63.98.115:1458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content.php"] [unique_id "amuRv48CCDUa19YrTu46dQAAATM"]
[Thu Jul 30 13:02:40.776649 2026] [security2:error] [pid 822943:tid 823143] [client 172.236.9.101:37142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRwI8CCDUa19YrTu46iAAAAVA"]
[Thu Jul 30 13:02:40.921729 2026] [security2:error] [pid 822943:tid 823136] [client 20.63.98.115:1427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/function.php"] [unique_id "amuRwI8CCDUa19YrTu46mgAAAUk"]
[Thu Jul 30 13:02:41.042145 2026] [security2:error] [pid 822943:tid 823007] [remote 57.141.0.33:65424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuRwI8CCDUa19YrTu46kQABfD8"], referer: https://igetvape-australia.com/product-category/alibarbar-rich-8000-puffs/?add-to-cart=1058
[Thu Jul 30 13:02:41.445660 2026] [security2:error] [pid 822943:tid 823148] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRwY8CCDUa19YrTu46ogABVV8"]
[Thu Jul 30 13:02:42.480847 2026] [security2:error] [pid 822943:tid 823096] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuRwo8CCDUa19YrTu46wgAAASE"]
[Thu Jul 30 13:02:42.480989 2026] [security2:error] [pid 822943:tid 823096] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuRwo8CCDUa19YrTu46wgAAASE"]
[Thu Jul 30 13:02:42.511188 2026] [core:notice] [pid 822943:tid 823132] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:42.527169 2026] [core:notice] [pid 822943:tid 823134] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:42.676237 2026] [security2:error] [pid 822943:tid 823180] [client 20.63.98.115:1952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/chosen.php"] [unique_id "amuRwo8CCDUa19YrTu46xgAAAXU"]
[Thu Jul 30 13:02:42.708464 2026] [core:notice] [pid 822943:tid 823185] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:42.781343 2026] [security2:error] [pid 822943:tid 823117] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuRwo8CCDUa19YrTu46zgAAATY"]
[Thu Jul 30 13:02:42.781451 2026] [security2:error] [pid 822943:tid 823117] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuRwo8CCDUa19YrTu46zgAAATY"]
[Thu Jul 30 13:02:43.081817 2026] [security2:error] [pid 822943:tid 823116] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/xstelth.php"] [unique_id "amuRw48CCDUa19YrTu461gAAATU"]
[Thu Jul 30 13:02:43.081930 2026] [security2:error] [pid 822943:tid 823116] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/xstelth.php"] [unique_id "amuRw48CCDUa19YrTu461gAAATU"]
[Thu Jul 30 13:02:43.320738 2026] [core:notice] [pid 822943:tid 823056] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:43.365619 2026] [core:notice] [pid 822943:tid 823066] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:43.412252 2026] [security2:error] [pid 822943:tid 823105] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuRw48CCDUa19YrTu464QAAASo"]
[Thu Jul 30 13:02:43.412361 2026] [security2:error] [pid 822943:tid 823105] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuRw48CCDUa19YrTu464QAAASo"]
[Thu Jul 30 13:02:43.558391 2026] [core:notice] [pid 822943:tid 823063] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:43.594262 2026] [security2:error] [pid 822943:tid 823126] [client 20.63.98.115:37436] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "adbacklink.com"] [uri "/1.php"] [unique_id "amuRw48CCDUa19YrTu465gAAAT8"]
[Thu Jul 30 13:02:43.594411 2026] [security2:error] [pid 822943:tid 823126] [client 20.63.98.115:37436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/1.php"] [unique_id "amuRw48CCDUa19YrTu465gAAAT8"]
[Thu Jul 30 13:02:43.725576 2026] [security2:error] [pid 822943:tid 823099] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/newfile.php"] [unique_id "amuRw48CCDUa19YrTu466QAAASQ"]
[Thu Jul 30 13:02:43.725665 2026] [security2:error] [pid 822943:tid 823099] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/newfile.php"] [unique_id "amuRw48CCDUa19YrTu466QAAASQ"]
[Thu Jul 30 13:02:44.032046 2026] [security2:error] [pid 822943:tid 823123] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/tBEZGQz.php"] [unique_id "amuRxI8CCDUa19YrTu468wAAATw"]
[Thu Jul 30 13:02:44.032176 2026] [security2:error] [pid 822943:tid 823123] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/tBEZGQz.php"] [unique_id "amuRxI8CCDUa19YrTu468wAAATw"]
[Thu Jul 30 13:02:44.324751 2026] [security2:error] [pid 822943:tid 823122] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuRxI8CCDUa19YrTu46-QAAATs"]
[Thu Jul 30 13:02:44.403551 2026] [authz_core:error] [pid 822943:tid 823178] [client 172.236.9.101:42776] AH01630: client denied by server configuration: /home1/oojhflte/public_html/.htpasswd
[Thu Jul 30 13:02:44.555205 2026] [security2:error] [pid 822943:tid 823173] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/drykl.php"] [unique_id "amuRxI8CCDUa19YrTu47BgAAAW4"]
[Thu Jul 30 13:02:44.555352 2026] [security2:error] [pid 822943:tid 823173] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/drykl.php"] [unique_id "amuRxI8CCDUa19YrTu47BgAAAW4"]
[Thu Jul 30 13:02:44.868812 2026] [security2:error] [pid 822943:tid 823078] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuRxI8CCDUa19YrTu47CwAAAQ8"]
[Thu Jul 30 13:02:44.894876 2026] [security2:error] [pid 822943:tid 823149] [client 172.236.9.101:29612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRxI8CCDUa19YrTu46_AAAAVY"]
[Thu Jul 30 13:02:44.986036 2026] [security2:error] [pid 822943:tid 823115] [client 172.236.9.101:2757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRxI8CCDUa19YrTu47AAAAATQ"]
[Thu Jul 30 13:02:45.023212 2026] [security2:error] [pid 822943:tid 823111] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ls.php"] [unique_id "amuRxY8CCDUa19YrTu47EwAAATA"]
[Thu Jul 30 13:02:45.023327 2026] [security2:error] [pid 822943:tid 823111] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ls.php"] [unique_id "amuRxY8CCDUa19YrTu47EwAAATA"]
[Thu Jul 30 13:02:45.319942 2026] [security2:error] [pid 822943:tid 823107] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dx.php"] [unique_id "amuRxY8CCDUa19YrTu47FwAAASw"]
[Thu Jul 30 13:02:45.320087 2026] [security2:error] [pid 822943:tid 823107] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/dx.php"] [unique_id "amuRxY8CCDUa19YrTu47FwAAASw"]
[Thu Jul 30 13:02:45.634217 2026] [security2:error] [pid 822943:tid 823113] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/mac.php"] [unique_id "amuRxY8CCDUa19YrTu47KwAAATI"]
[Thu Jul 30 13:02:45.634321 2026] [security2:error] [pid 822943:tid 823113] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/mac.php"] [unique_id "amuRxY8CCDUa19YrTu47KwAAATI"]
[Thu Jul 30 13:02:45.935090 2026] [security2:error] [pid 822943:tid 823142] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/485.php"] [unique_id "amuRxY8CCDUa19YrTu47NQAAAU8"]
[Thu Jul 30 13:02:45.935191 2026] [security2:error] [pid 822943:tid 823142] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/485.php"] [unique_id "amuRxY8CCDUa19YrTu47NQAAAU8"]
[Thu Jul 30 13:02:46.234220 2026] [security2:error] [pid 822943:tid 823078] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gelio1.php"] [unique_id "amuRxo8CCDUa19YrTu47QQAAAQ8"]
[Thu Jul 30 13:02:46.234340 2026] [security2:error] [pid 822943:tid 823078] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gelio1.php"] [unique_id "amuRxo8CCDUa19YrTu47QQAAAQ8"]
[Thu Jul 30 13:02:46.548303 2026] [security2:error] [pid 822943:tid 823108] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/lp6.php"] [unique_id "amuRxo8CCDUa19YrTu47TAAAAS0"]
[Thu Jul 30 13:02:46.548444 2026] [security2:error] [pid 822943:tid 823108] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/lp6.php"] [unique_id "amuRxo8CCDUa19YrTu47TAAAAS0"]
[Thu Jul 30 13:02:46.805810 2026] [security2:error] [pid 822943:tid 823138] [client 20.63.98.115:37213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/lv.php"] [unique_id "amuRxo8CCDUa19YrTu47VQAAAUs"]
[Thu Jul 30 13:02:46.857691 2026] [security2:error] [pid 822943:tid 823168] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuRxo8CCDUa19YrTu47VgAAAWk"]
[Thu Jul 30 13:02:46.857804 2026] [security2:error] [pid 822943:tid 823168] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuRxo8CCDUa19YrTu47VgAAAWk"]
[Thu Jul 30 13:02:47.179442 2026] [security2:error] [pid 822943:tid 823133] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuRx48CCDUa19YrTu47YQAAAUY"]
[Thu Jul 30 13:02:47.333072 2026] [security2:error] [pid 822943:tid 823179] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/w3llscc.php"] [unique_id "amuRx48CCDUa19YrTu47ZQAAAXQ"]
[Thu Jul 30 13:02:47.333188 2026] [security2:error] [pid 822943:tid 823179] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/w3llscc.php"] [unique_id "amuRx48CCDUa19YrTu47ZQAAAXQ"]
[Thu Jul 30 13:02:47.406164 2026] [security2:error] [pid 822943:tid 822980] [remote 57.141.0.63:23804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuRx48CCDUa19YrTu47ZgABISQ"]
[Thu Jul 30 13:02:47.704731 2026] [security2:error] [pid 822943:tid 823197] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/miru3.php"] [unique_id "amuRx48CCDUa19YrTu47bwAAAYY"]
[Thu Jul 30 13:02:47.704843 2026] [security2:error] [pid 822943:tid 823197] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/miru3.php"] [unique_id "amuRx48CCDUa19YrTu47bwAAAYY"]
[Thu Jul 30 13:02:48.015970 2026] [security2:error] [pid 822943:tid 823114] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuRyI8CCDUa19YrTu47dwAAATM"]
[Thu Jul 30 13:02:48.016100 2026] [security2:error] [pid 822943:tid 823114] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuRyI8CCDUa19YrTu47dwAAATM"]
[Thu Jul 30 13:02:48.321081 2026] [security2:error] [pid 822943:tid 823195] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuRyI8CCDUa19YrTu47ggAAAYQ"]
[Thu Jul 30 13:02:48.353149 2026] [core:notice] [pid 822943:tid 823117] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:48.393674 2026] [core:notice] [pid 822943:tid 823121] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:48.413208 2026] [security2:error] [pid 822943:tid 823164] [client 20.63.98.115:1691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/css.php"] [unique_id "amuRyI8CCDUa19YrTu47iQAAAWU"]
[Thu Jul 30 13:02:48.546047 2026] [security2:error] [pid 822943:tid 823159] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuRyI8CCDUa19YrTu47iwAAAWA"]
[Thu Jul 30 13:02:48.546188 2026] [security2:error] [pid 822943:tid 823159] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuRyI8CCDUa19YrTu47iwAAAWA"]
[Thu Jul 30 13:02:48.591046 2026] [security2:error] [pid 822943:tid 823161] [client 50.6.43.217:56892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuRyI8CCDUa19YrTu47igAAAWI"]
[Thu Jul 30 13:02:48.717740 2026] [security2:error] [pid 822943:tid 823076] [client 50.6.43.217:56898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuRyI8CCDUa19YrTu47kAAAAQ0"]
[Thu Jul 30 13:02:48.883039 2026] [security2:error] [pid 822943:tid 823142] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/av.php"] [unique_id "amuRyI8CCDUa19YrTu47mwAAAU8"]
[Thu Jul 30 13:02:48.883148 2026] [security2:error] [pid 822943:tid 823142] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/av.php"] [unique_id "amuRyI8CCDUa19YrTu47mwAAAU8"]
[Thu Jul 30 13:02:48.917766 2026] [security2:error] [pid 822943:tid 823196] [client 172.236.9.101:30095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRyI8CCDUa19YrTu47iAAAAYU"]
[Thu Jul 30 13:02:49.201821 2026] [security2:error] [pid 822943:tid 823090] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuRyY8CCDUa19YrTu47owAAARs"]
[Thu Jul 30 13:02:49.205120 2026] [core:notice] [pid 822943:tid 822995] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:49.373928 2026] [security2:error] [pid 822943:tid 823149] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.markmocek.com"] [uri "/cgi-sys/404.html"] [unique_id "amuRyY8CCDUa19YrTu47qwAAAVY"]
[Thu Jul 30 13:02:49.399108 2026] [security2:error] [pid 822943:tid 823102] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuRyI8CCDUa19YrTu47mgAAASc"]
[Thu Jul 30 13:02:49.541880 2026] [security2:error] [pid 822943:tid 823141] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/tiny.php"] [unique_id "amuRyY8CCDUa19YrTu47rAAAAU4"]
[Thu Jul 30 13:02:49.542052 2026] [security2:error] [pid 822943:tid 823141] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/tiny.php"] [unique_id "amuRyY8CCDUa19YrTu47rAAAAU4"]
[Thu Jul 30 13:02:49.664441 2026] [core:notice] [pid 822943:tid 823015] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:49.873651 2026] [security2:error] [pid 822943:tid 823189] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuRyY8CCDUa19YrTu47uAAAAX4"]
[Thu Jul 30 13:02:49.873762 2026] [security2:error] [pid 822943:tid 823189] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuRyY8CCDUa19YrTu47uAAAAX4"]
[Thu Jul 30 13:02:50.214702 2026] [security2:error] [pid 822943:tid 823112] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/zrrhj.php"] [unique_id "amuRyo8CCDUa19YrTu47xQAAATE"]
[Thu Jul 30 13:02:50.214800 2026] [security2:error] [pid 822943:tid 823112] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/zrrhj.php"] [unique_id "amuRyo8CCDUa19YrTu47xQAAATE"]
[Thu Jul 30 13:02:50.389022 2026] [security2:error] [pid 822943:tid 823086] [client 127.0.0.1:27230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuRyo8CCDUa19YrTu47zQAAARc"]
[Thu Jul 30 13:02:50.389048 2026] [security2:error] [pid 822943:tid 823168] [client 74.7.244.24:42020] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.yie.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuRyo8CCDUa19YrTu47zAAAAWk"]
[Thu Jul 30 13:02:50.533740 2026] [security2:error] [pid 822943:tid 823180] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuRyo8CCDUa19YrTu470gAAAXU"]
[Thu Jul 30 13:02:50.533860 2026] [security2:error] [pid 822943:tid 823180] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuRyo8CCDUa19YrTu470gAAAXU"]
[Thu Jul 30 13:02:50.830829 2026] [security2:error] [pid 822943:tid 823183] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wpgum.php"] [unique_id "amuRyo8CCDUa19YrTu471wAAAXg"]
[Thu Jul 30 13:02:50.830988 2026] [security2:error] [pid 822943:tid 823183] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wpgum.php"] [unique_id "amuRyo8CCDUa19YrTu471wAAAXg"]
[Thu Jul 30 13:02:51.167933 2026] [security2:error] [pid 822943:tid 823198] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ywwbf.php"] [unique_id "amuRy48CCDUa19YrTu474QAAAYc"]
[Thu Jul 30 13:02:51.168039 2026] [security2:error] [pid 822943:tid 823198] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ywwbf.php"] [unique_id "amuRy48CCDUa19YrTu474QAAAYc"]
[Thu Jul 30 13:02:51.246865 2026] [security2:error] [pid 822943:tid 823156] [client 20.63.98.115:50471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/gecko.php"] [unique_id "amuRy48CCDUa19YrTu474wAAAV0"]
[Thu Jul 30 13:02:51.575919 2026] [http2:info] [pid 849392:tid 849392] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 13:02:51.591991 2026] [security2:error] [pid 849392:tid 849523] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/xoldj.php"] [unique_id "amuRywMgr4yz2OQW0xq69AAAAIU"]
[Thu Jul 30 13:02:51.592248 2026] [security2:error] [pid 849392:tid 849523] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/xoldj.php"] [unique_id "amuRywMgr4yz2OQW0xq69AAAAIU"]
[Thu Jul 30 13:02:51.897031 2026] [security2:error] [pid 849392:tid 849536] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/f35.php"] [unique_id "amuRywMgr4yz2OQW0xq6-gAAAJI"]
[Thu Jul 30 13:02:51.897160 2026] [security2:error] [pid 849392:tid 849536] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/f35.php"] [unique_id "amuRywMgr4yz2OQW0xq6-gAAAJI"]
[Thu Jul 30 13:02:52.207265 2026] [security2:error] [pid 849392:tid 849555] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gk.php"] [unique_id "amuRzAMgr4yz2OQW0xq7BAAAAKU"]
[Thu Jul 30 13:02:52.207374 2026] [security2:error] [pid 849392:tid 849555] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gk.php"] [unique_id "amuRzAMgr4yz2OQW0xq7BAAAAKU"]
[Thu Jul 30 13:02:52.213145 2026] [security2:error] [pid 849392:tid 849546] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuRzAMgr4yz2OQW0xq7AQAAnAI"]
[Thu Jul 30 13:02:52.551885 2026] [security2:error] [pid 849392:tid 849581] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuRzAMgr4yz2OQW0xq7HQAAAL8"]
[Thu Jul 30 13:02:52.552013 2026] [security2:error] [pid 849392:tid 849581] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuRzAMgr4yz2OQW0xq7HQAAAL8"]
[Thu Jul 30 13:02:52.862424 2026] [security2:error] [pid 849392:tid 849593] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wper3.php"] [unique_id "amuRzAMgr4yz2OQW0xq7JQAAAMs"]
[Thu Jul 30 13:02:52.862557 2026] [security2:error] [pid 849392:tid 849593] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wper3.php"] [unique_id "amuRzAMgr4yz2OQW0xq7JQAAAMs"]
[Thu Jul 30 13:02:52.920531 2026] [core:notice] [pid 849392:tid 849601] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:53.051272 2026] [core:notice] [pid 849392:tid 849611] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:53.220924 2026] [security2:error] [pid 849392:tid 849615] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/bthil.php"] [unique_id "amuRzQMgr4yz2OQW0xq7NQAAAOE"]
[Thu Jul 30 13:02:53.221126 2026] [security2:error] [pid 849392:tid 849615] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/bthil.php"] [unique_id "amuRzQMgr4yz2OQW0xq7NQAAAOE"]
[Thu Jul 30 13:02:53.527232 2026] [security2:error] [pid 849392:tid 849637] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wyzer1.php"] [unique_id "amuRzQMgr4yz2OQW0xq7QQAAAPc"]
[Thu Jul 30 13:02:53.527353 2026] [security2:error] [pid 849392:tid 849637] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wyzer1.php"] [unique_id "amuRzQMgr4yz2OQW0xq7QQAAAPc"]
[Thu Jul 30 13:02:53.731472 2026] [security2:error] [pid 849392:tid 849618] [client 172.236.9.101:28488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuRzQMgr4yz2OQW0xq7NgAAAOQ"]
[Thu Jul 30 13:02:53.769382 2026] [core:notice] [pid 849392:tid 849425] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:53.884744 2026] [security2:error] [pid 849392:tid 849427] [remote 212.80.9.235:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuRzQMgr4yz2OQW0xq7SAAA6SE"]
[Thu Jul 30 13:02:53.938031 2026] [security2:error] [pid 849392:tid 849528] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/mh.php"] [unique_id "amuRzQMgr4yz2OQW0xq7TAAAAIo"]
[Thu Jul 30 13:02:53.938153 2026] [security2:error] [pid 849392:tid 849528] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/mh.php"] [unique_id "amuRzQMgr4yz2OQW0xq7TAAAAIo"]
[Thu Jul 30 13:02:54.256856 2026] [security2:error] [pid 849392:tid 849532] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuRzgMgr4yz2OQW0xq7VAAAAI4"]
[Thu Jul 30 13:02:54.256970 2026] [security2:error] [pid 849392:tid 849532] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuRzgMgr4yz2OQW0xq7VAAAAI4"]
[Thu Jul 30 13:02:54.500999 2026] [core:notice] [pid 849392:tid 849494] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:02:54.612328 2026] [security2:error] [pid 849392:tid 849578] [client 20.91.139.111:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.markmocek.com"] [uri "/1.php"] [unique_id "amuRzgMgr4yz2OQW0xq7oAAAALw"]
[Thu Jul 30 13:02:54.612451 2026] [security2:error] [pid 849392:tid 849578] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/1.php"] [unique_id "amuRzgMgr4yz2OQW0xq7oAAAALw"]
[Thu Jul 30 13:02:54.612572 2026] [security2:error] [pid 849392:tid 849578] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/1.php"] [unique_id "amuRzgMgr4yz2OQW0xq7oAAAALw"]
[Thu Jul 30 13:02:54.910534 2026] [security2:error] [pid 849392:tid 849591] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/chosen.php"] [unique_id "amuRzgMgr4yz2OQW0xq7rQAAAMk"]
[Thu Jul 30 13:02:54.910656 2026] [security2:error] [pid 849392:tid 849591] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/chosen.php"] [unique_id "amuRzgMgr4yz2OQW0xq7rQAAAMk"]
[Thu Jul 30 13:02:55.225791 2026] [security2:error] [pid 849392:tid 849616] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/sd.php"] [unique_id "amuRzwMgr4yz2OQW0xq7uwAAAOI"]
[Thu Jul 30 13:02:55.225936 2026] [security2:error] [pid 849392:tid 849616] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/sd.php"] [unique_id "amuRzwMgr4yz2OQW0xq7uwAAAOI"]
[Thu Jul 30 13:02:55.524119 2026] [security2:error] [pid 849392:tid 849647] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/z60.php"] [unique_id "amuRzwMgr4yz2OQW0xq7xgAAAQE"]
[Thu Jul 30 13:02:55.524267 2026] [security2:error] [pid 849392:tid 849647] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/z60.php"] [unique_id "amuRzwMgr4yz2OQW0xq7xgAAAQE"]
[Thu Jul 30 13:02:55.539322 2026] [security2:error] [pid 849392:tid 849544] [client 20.63.98.115:46726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/xmlrpc.php"] [unique_id "amuRzwMgr4yz2OQW0xq7xwAAAJo"]
[Thu Jul 30 13:02:55.724271 2026] [security2:error] [pid 849392:tid 849531] [client 213.152.161.240:44684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuRzwMgr4yz2OQW0xq7zQAAAI0"]
[Thu Jul 30 13:02:55.724417 2026] [security2:error] [pid 849392:tid 849531] [client 213.152.161.240:44684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuRzwMgr4yz2OQW0xq7zQAAAI0"]
[Thu Jul 30 13:02:55.824134 2026] [security2:error] [pid 849392:tid 849537] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/home.php"] [unique_id "amuRzwMgr4yz2OQW0xq70AAAAJM"]
[Thu Jul 30 13:02:55.824291 2026] [security2:error] [pid 849392:tid 849537] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/home.php"] [unique_id "amuRzwMgr4yz2OQW0xq70AAAAJM"]
[Thu Jul 30 13:02:56.209110 2026] [security2:error] [pid 849392:tid 849560] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ws58.php"] [unique_id "amuR0AMgr4yz2OQW0xq74AAAAKo"]
[Thu Jul 30 13:02:56.209247 2026] [security2:error] [pid 849392:tid 849560] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ws58.php"] [unique_id "amuR0AMgr4yz2OQW0xq74AAAAKo"]
[Thu Jul 30 13:02:56.509638 2026] [security2:error] [pid 849392:tid 849591] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/gulu.php"] [unique_id "amuR0AMgr4yz2OQW0xq77AAAAMk"]
[Thu Jul 30 13:02:56.509796 2026] [security2:error] [pid 849392:tid 849591] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/gulu.php"] [unique_id "amuR0AMgr4yz2OQW0xq77AAAAMk"]
[Thu Jul 30 13:02:56.719223 2026] [security2:error] [pid 849392:tid 849581] [client 20.63.98.115:34050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/f35.php"] [unique_id "amuR0AMgr4yz2OQW0xq78QAAAL8"]
[Thu Jul 30 13:02:56.807065 2026] [security2:error] [pid 849392:tid 849599] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuR0AMgr4yz2OQW0xq78wAAANE"]
[Thu Jul 30 13:02:56.807174 2026] [security2:error] [pid 849392:tid 849599] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuR0AMgr4yz2OQW0xq78wAAANE"]
[Thu Jul 30 13:02:57.111260 2026] [security2:error] [pid 849392:tid 849626] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wpls.php"] [unique_id "amuR0QMgr4yz2OQW0xq7_gAAAOw"]
[Thu Jul 30 13:02:57.111364 2026] [security2:error] [pid 849392:tid 849626] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wpls.php"] [unique_id "amuR0QMgr4yz2OQW0xq7_gAAAOw"]
[Thu Jul 30 13:02:57.405399 2026] [security2:error] [pid 849392:tid 849618] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/php.php"] [unique_id "amuR0QMgr4yz2OQW0xq8AAAAAOQ"]
[Thu Jul 30 13:02:57.405519 2026] [security2:error] [pid 849392:tid 849618] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/php.php"] [unique_id "amuR0QMgr4yz2OQW0xq8AAAAAOQ"]
[Thu Jul 30 13:02:57.701215 2026] [security2:error] [pid 849392:tid 849531] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/100.php"] [unique_id "amuR0QMgr4yz2OQW0xq8EQAAAI0"]
[Thu Jul 30 13:02:57.701381 2026] [security2:error] [pid 849392:tid 849531] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/100.php"] [unique_id "amuR0QMgr4yz2OQW0xq8EQAAAI0"]
[Thu Jul 30 13:02:57.998165 2026] [security2:error] [pid 849392:tid 849555] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/BDKR28WP.php"] [unique_id "amuR0QMgr4yz2OQW0xq8GwAAAKU"]
[Thu Jul 30 13:02:57.998374 2026] [security2:error] [pid 849392:tid 849555] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/BDKR28WP.php"] [unique_id "amuR0QMgr4yz2OQW0xq8GwAAAKU"]
[Thu Jul 30 13:02:58.298206 2026] [security2:error] [pid 849392:tid 849579] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/browse.php"] [unique_id "amuR0gMgr4yz2OQW0xq8IgAAAL0"]
[Thu Jul 30 13:02:58.298349 2026] [security2:error] [pid 849392:tid 849579] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/browse.php"] [unique_id "amuR0gMgr4yz2OQW0xq8IgAAAL0"]
[Thu Jul 30 13:02:58.403275 2026] [security2:error] [pid 849392:tid 849420] [remote 5.161.62.209:14032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.psz.dtn.temporary.site"] [uri "/.env"] [unique_id "amuR0gMgr4yz2OQW0xq8IwAAvBo"]
[Thu Jul 30 13:02:58.599078 2026] [security2:error] [pid 849392:tid 849602] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-good.php"] [unique_id "amuR0gMgr4yz2OQW0xq8MAAAANQ"]
[Thu Jul 30 13:02:58.599176 2026] [security2:error] [pid 849392:tid 849602] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-good.php"] [unique_id "amuR0gMgr4yz2OQW0xq8MAAAANQ"]
[Thu Jul 30 13:02:58.638161 2026] [security2:error] [pid 849392:tid 849424] [remote 65.60.36.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.36.60.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemoversandpackersabudhabi.fit"] [uri "/wp-login.php"] [unique_id "amuR0gMgr4yz2OQW0xq8MQAAoh4"]
[Thu Jul 30 13:02:58.892262 2026] [security2:error] [pid 849392:tid 849617] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/8573.php"] [unique_id "amuR0gMgr4yz2OQW0xq8MgAAAOM"]
[Thu Jul 30 13:02:58.892402 2026] [security2:error] [pid 849392:tid 849617] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/8573.php"] [unique_id "amuR0gMgr4yz2OQW0xq8MgAAAOM"]
[Thu Jul 30 13:02:59.088378 2026] [security2:error] [pid 849392:tid 849632] [client 20.63.98.115:50450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/autoload_classmap.php"] [unique_id "amuR0wMgr4yz2OQW0xq8OwAAAPI"]
[Thu Jul 30 13:02:59.179128 2026] [security2:error] [pid 849392:tid 849638] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-admin/install.php"] [unique_id "amuR0wMgr4yz2OQW0xq8QAAAAPg"]
[Thu Jul 30 13:02:59.179230 2026] [security2:error] [pid 849392:tid 849638] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-admin/install.php"] [unique_id "amuR0wMgr4yz2OQW0xq8QAAAAPg"]
[Thu Jul 30 13:02:59.480962 2026] [security2:error] [pid 849392:tid 849648] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuR0wMgr4yz2OQW0xq8QwAAAQI"]
[Thu Jul 30 13:02:59.481100 2026] [security2:error] [pid 849392:tid 849648] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuR0wMgr4yz2OQW0xq8QwAAAQI"]
[Thu Jul 30 13:02:59.492698 2026] [security2:error] [pid 849392:tid 849611] [client 68.183.5.181:58432] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "globalmarks.pk"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amuR0wMgr4yz2OQW0xq8RgAAAN0"]
[Thu Jul 30 13:02:59.784542 2026] [security2:error] [pid 849392:tid 849606] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ohct.php"] [unique_id "amuR0wMgr4yz2OQW0xq8UAAAANg"]
[Thu Jul 30 13:02:59.784678 2026] [security2:error] [pid 849392:tid 849606] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ohct.php"] [unique_id "amuR0wMgr4yz2OQW0xq8UAAAANg"]
[Thu Jul 30 13:03:00.167642 2026] [security2:error] [pid 849392:tid 849554] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/bless.php"] [unique_id "amuR1AMgr4yz2OQW0xq8XQAAAKQ"]
[Thu Jul 30 13:03:00.167779 2026] [security2:error] [pid 849392:tid 849554] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/bless.php"] [unique_id "amuR1AMgr4yz2OQW0xq8XQAAAKQ"]
[Thu Jul 30 13:03:00.459492 2026] [security2:error] [pid 849392:tid 849556] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/about.php"] [unique_id "amuR1AMgr4yz2OQW0xq8YAAAAKY"]
[Thu Jul 30 13:03:00.459628 2026] [security2:error] [pid 849392:tid 849556] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/about.php"] [unique_id "amuR1AMgr4yz2OQW0xq8YAAAAKY"]
[Thu Jul 30 13:03:00.888496 2026] [security2:error] [pid 849392:tid 849534] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuR1AMgr4yz2OQW0xq8bAAAAJA"]
[Thu Jul 30 13:03:00.888627 2026] [security2:error] [pid 849392:tid 849534] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuR1AMgr4yz2OQW0xq8bAAAAJA"]
[Thu Jul 30 13:03:01.200955 2026] [security2:error] [pid 849392:tid 849604] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ta0ol.php"] [unique_id "amuR1QMgr4yz2OQW0xq8dgAAANY"]
[Thu Jul 30 13:03:01.201084 2026] [security2:error] [pid 849392:tid 849604] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ta0ol.php"] [unique_id "amuR1QMgr4yz2OQW0xq8dgAAANY"]
[Thu Jul 30 13:03:01.483885 2026] [security2:error] [pid 849392:tid 849586] [client 172.237.109.114:29928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1AMgr4yz2OQW0xq8bQAAAMQ"]
[Thu Jul 30 13:03:01.511585 2026] [security2:error] [pid 849392:tid 849620] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/sa.php7"] [unique_id "amuR1QMgr4yz2OQW0xq8fAAAAOY"]
[Thu Jul 30 13:03:01.511717 2026] [security2:error] [pid 849392:tid 849620] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/sa.php7"] [unique_id "amuR1QMgr4yz2OQW0xq8fAAAAOY"]
[Thu Jul 30 13:03:01.812727 2026] [security2:error] [pid 849392:tid 849646] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-class.php"] [unique_id "amuR1QMgr4yz2OQW0xq8iQAAAQA"]
[Thu Jul 30 13:03:01.812871 2026] [security2:error] [pid 849392:tid 849646] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-class.php"] [unique_id "amuR1QMgr4yz2OQW0xq8iQAAAQA"]
[Thu Jul 30 13:03:02.134943 2026] [security2:error] [pid 849392:tid 849553] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/8.php"] [unique_id "amuR1gMgr4yz2OQW0xq8oAAAAKM"]
[Thu Jul 30 13:03:02.135196 2026] [security2:error] [pid 849392:tid 849553] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/8.php"] [unique_id "amuR1gMgr4yz2OQW0xq8oAAAAKM"]
[Thu Jul 30 13:03:02.445636 2026] [security2:error] [pid 849392:tid 849561] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/bootstrap.php"] [unique_id "amuR1gMgr4yz2OQW0xq8rwAAAKs"]
[Thu Jul 30 13:03:02.445856 2026] [security2:error] [pid 849392:tid 849561] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/bootstrap.php"] [unique_id "amuR1gMgr4yz2OQW0xq8rwAAAKs"]
[Thu Jul 30 13:03:02.748860 2026] [security2:error] [pid 849392:tid 849590] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-blog-header.php"] [unique_id "amuR1gMgr4yz2OQW0xq8ugAAAMg"]
[Thu Jul 30 13:03:02.748967 2026] [security2:error] [pid 849392:tid 849590] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-blog-header.php"] [unique_id "amuR1gMgr4yz2OQW0xq8ugAAAMg"]
[Thu Jul 30 13:03:03.017359 2026] [security2:error] [pid 849392:tid 849627] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuR1gMgr4yz2OQW0xq8wwAA7Uo"]
[Thu Jul 30 13:03:03.041952 2026] [security2:error] [pid 849392:tid 849545] [client 20.63.98.115:34049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/NewFile.php"] [unique_id "amuR1wMgr4yz2OQW0xq8xwAAAJs"]
[Thu Jul 30 13:03:03.042744 2026] [security2:error] [pid 849392:tid 849644] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/aa.php"] [unique_id "amuR1wMgr4yz2OQW0xq8yAAAAP4"]
[Thu Jul 30 13:03:03.042830 2026] [security2:error] [pid 849392:tid 849644] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/aa.php"] [unique_id "amuR1wMgr4yz2OQW0xq8yAAAAP4"]
[Thu Jul 30 13:03:03.159474 2026] [core:notice] [pid 849392:tid 849636] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:03.359191 2026] [security2:error] [pid 849392:tid 849626] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/tx79.php"] [unique_id "amuR1wMgr4yz2OQW0xq80gAAAOw"]
[Thu Jul 30 13:03:03.359435 2026] [security2:error] [pid 849392:tid 849626] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/tx79.php"] [unique_id "amuR1wMgr4yz2OQW0xq80gAAAOw"]
[Thu Jul 30 13:03:03.406327 2026] [security2:error] [pid 849392:tid 849523] [client 172.237.109.114:4515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8jwAAAIU"]
[Thu Jul 30 13:03:03.421516 2026] [security2:error] [pid 849392:tid 849531] [client 172.237.109.114:61790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8kgAAAI0"]
[Thu Jul 30 13:03:03.430627 2026] [security2:error] [pid 849392:tid 849524] [client 172.237.109.114:22517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8jAAAAIY"]
[Thu Jul 30 13:03:03.455173 2026] [security2:error] [pid 849392:tid 849529] [client 172.237.109.114:17895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8kAAAAIs"]
[Thu Jul 30 13:03:03.457269 2026] [security2:error] [pid 849392:tid 849528] [client 172.237.109.114:63656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8jgAAAIo"]
[Thu Jul 30 13:03:03.458831 2026] [security2:error] [pid 849392:tid 849573] [client 172.237.109.114:46335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1gMgr4yz2OQW0xq8nQAAALc"]
[Thu Jul 30 13:03:03.461205 2026] [security2:error] [pid 849392:tid 849569] [client 172.237.109.114:65247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8iwAAALM"]
[Thu Jul 30 13:03:03.474753 2026] [security2:error] [pid 849392:tid 849549] [client 172.237.109.114:19876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1gMgr4yz2OQW0xq8mgAAAJ8"]
[Thu Jul 30 13:03:03.477300 2026] [security2:error] [pid 849392:tid 849606] [client 172.237.109.114:15000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8lwAAANg"]
[Thu Jul 30 13:03:03.477416 2026] [security2:error] [pid 849392:tid 849535] [client 172.237.109.114:32983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8kwAAAJE"]
[Thu Jul 30 13:03:03.484771 2026] [security2:error] [pid 849392:tid 849609] [client 172.237.109.114:10712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8mAAAANs"]
[Thu Jul 30 13:03:03.518036 2026] [security2:error] [pid 849392:tid 849565] [client 172.237.109.114:60046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1gMgr4yz2OQW0xq8nAAAAK8"]
[Thu Jul 30 13:03:03.569502 2026] [security2:error] [pid 849392:tid 849525] [client 172.237.109.114:6519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8jQAAAIc"]
[Thu Jul 30 13:03:03.569502 2026] [security2:error] [pid 849392:tid 849547] [client 172.237.109.114:52716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8lgAAAJ0"]
[Thu Jul 30 13:03:03.578269 2026] [security2:error] [pid 849392:tid 849543] [client 172.237.109.114:28221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8lQAAAJk"]
[Thu Jul 30 13:03:03.579723 2026] [security2:error] [pid 849392:tid 849550] [client 172.237.109.114:4648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1gMgr4yz2OQW0xq8mQAAAKA"]
[Thu Jul 30 13:03:03.587626 2026] [security2:error] [pid 849392:tid 849607] [client 172.237.109.114:50362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1gMgr4yz2OQW0xq8mwAAANk"]
[Thu Jul 30 13:03:03.590928 2026] [security2:error] [pid 849392:tid 849538] [client 172.237.109.114:26146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8kQAAAJQ"]
[Thu Jul 30 13:03:03.622831 2026] [security2:error] [pid 849392:tid 849542] [client 172.237.109.114:53155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR1QMgr4yz2OQW0xq8lAAAAJg"]
[Thu Jul 30 13:03:03.675645 2026] [security2:error] [pid 849392:tid 849564] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/motu.php"] [unique_id "amuR1wMgr4yz2OQW0xq81gAAAK4"]
[Thu Jul 30 13:03:03.675753 2026] [security2:error] [pid 849392:tid 849564] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/motu.php"] [unique_id "amuR1wMgr4yz2OQW0xq81gAAAK4"]
[Thu Jul 30 13:03:04.053905 2026] [security2:error] [pid 849392:tid 849587] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-head.php"] [unique_id "amuR2AMgr4yz2OQW0xq84wAAAMU"]
[Thu Jul 30 13:03:04.054017 2026] [security2:error] [pid 849392:tid 849587] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-head.php"] [unique_id "amuR2AMgr4yz2OQW0xq84wAAAMU"]
[Thu Jul 30 13:03:04.354006 2026] [security2:error] [pid 849392:tid 849552] [client 74.7.241.189:60036] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.cwf.djb.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuR2AMgr4yz2OQW0xq88gAAAKI"]
[Thu Jul 30 13:03:04.405912 2026] [security2:error] [pid 849392:tid 849636] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuR2AMgr4yz2OQW0xq89gAAAPY"]
[Thu Jul 30 13:03:04.406067 2026] [security2:error] [pid 849392:tid 849636] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuR2AMgr4yz2OQW0xq89gAAAPY"]
[Thu Jul 30 13:03:04.728705 2026] [security2:error] [pid 849392:tid 849641] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/60856e3a4findex.php"] [unique_id "amuR2AMgr4yz2OQW0xq8_AAAAPs"]
[Thu Jul 30 13:03:04.728823 2026] [security2:error] [pid 849392:tid 849641] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/60856e3a4findex.php"] [unique_id "amuR2AMgr4yz2OQW0xq8_AAAAPs"]
[Thu Jul 30 13:03:05.024107 2026] [security2:error] [pid 849392:tid 849544] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp-the.php"] [unique_id "amuR2QMgr4yz2OQW0xq9CAAAAJo"]
[Thu Jul 30 13:03:05.024235 2026] [security2:error] [pid 849392:tid 849544] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp-the.php"] [unique_id "amuR2QMgr4yz2OQW0xq9CAAAAJo"]
[Thu Jul 30 13:03:05.092577 2026] [security2:error] [pid 849392:tid 849640] [client 20.63.98.115:50439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/xx.php"] [unique_id "amuR2QMgr4yz2OQW0xq9CQAAAPo"]
[Thu Jul 30 13:03:05.370029 2026] [security2:error] [pid 849392:tid 849551] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wp.php"] [unique_id "amuR2QMgr4yz2OQW0xq9EgAAAKE"]
[Thu Jul 30 13:03:05.370170 2026] [security2:error] [pid 849392:tid 849551] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wp.php"] [unique_id "amuR2QMgr4yz2OQW0xq9EgAAAKE"]
[Thu Jul 30 13:03:05.448577 2026] [security2:error] [pid 849392:tid 849639] [client 186.0.192.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amuR2AMgr4yz2OQW0xq8-wAAAPk"], referer: https://shop-mevius.com/product/winston-2/
[Thu Jul 30 13:03:05.687745 2026] [security2:error] [pid 849392:tid 849563] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/users.php"] [unique_id "amuR2QMgr4yz2OQW0xq9HQAAAK0"]
[Thu Jul 30 13:03:05.687897 2026] [security2:error] [pid 849392:tid 849563] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/users.php"] [unique_id "amuR2QMgr4yz2OQW0xq9HQAAAK0"]
[Thu Jul 30 13:03:05.996904 2026] [security2:error] [pid 849392:tid 849539] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuR2QMgr4yz2OQW0xq9EQAAAJU"]
[Thu Jul 30 13:03:06.166800 2026] [security2:error] [pid 849392:tid 849617] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/tinysd.php"] [unique_id "amuR2gMgr4yz2OQW0xq9LQAAAOM"]
[Thu Jul 30 13:03:06.166917 2026] [security2:error] [pid 849392:tid 849617] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/tinysd.php"] [unique_id "amuR2gMgr4yz2OQW0xq9LQAAAOM"]
[Thu Jul 30 13:03:06.358109 2026] [security2:error] [pid 849392:tid 849520] [remote 57.141.18.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuR2gMgr4yz2OQW0xq9LgAA534"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon,cotton,linen,polyester,aluminum,plastic&orderby=menu_order&status=instock&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 13:03:06.472362 2026] [security2:error] [pid 849392:tid 849622] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ws78.php"] [unique_id "amuR2gMgr4yz2OQW0xq9NwAAAOg"]
[Thu Jul 30 13:03:06.472441 2026] [security2:error] [pid 849392:tid 849622] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ws78.php"] [unique_id "amuR2gMgr4yz2OQW0xq9NwAAAOg"]
[Thu Jul 30 13:03:06.604045 2026] [security2:error] [pid 849392:tid 849649] [client 158.158.32.226:14170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/madspotshell.php"] [unique_id "amuR2gMgr4yz2OQW0xq9PQAAAQM"]
[Thu Jul 30 13:03:06.604172 2026] [security2:error] [pid 849392:tid 849649] [client 158.158.32.226:14170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/madspotshell.php"] [unique_id "amuR2gMgr4yz2OQW0xq9PQAAAQM"]
[Thu Jul 30 13:03:06.752454 2026] [security2:error] [pid 849392:tid 849394] [remote 57.141.18.0:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuR2gMgr4yz2OQW0xq9OQAA1wA"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon,cotton,linen,polyester,aluminum,plastic&orderby=menu_order&status=instock&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 13:03:06.784061 2026] [security2:error] [pid 849392:tid 849569] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/elp.php"] [unique_id "amuR2gMgr4yz2OQW0xq9QAAAALM"]
[Thu Jul 30 13:03:06.784174 2026] [security2:error] [pid 849392:tid 849569] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/elp.php"] [unique_id "amuR2gMgr4yz2OQW0xq9QAAAALM"]
[Thu Jul 30 13:03:07.028932 2026] [security2:error] [pid 849392:tid 849629] [client 158.158.32.226:14182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/sa.php"] [unique_id "amuR2wMgr4yz2OQW0xq9TAAAAO8"]
[Thu Jul 30 13:03:07.029081 2026] [security2:error] [pid 849392:tid 849629] [client 158.158.32.226:14182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/sa.php"] [unique_id "amuR2wMgr4yz2OQW0xq9TAAAAO8"]
[Thu Jul 30 13:03:07.080788 2026] [security2:error] [pid 849392:tid 849550] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/atomlib.php"] [unique_id "amuR2wMgr4yz2OQW0xq9TQAAAKA"]
[Thu Jul 30 13:03:07.080942 2026] [security2:error] [pid 849392:tid 849550] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/atomlib.php"] [unique_id "amuR2wMgr4yz2OQW0xq9TQAAAKA"]
[Thu Jul 30 13:03:07.360726 2026] [security2:error] [pid 849392:tid 849639] [client 158.158.32.226:13790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/noname.php"] [unique_id "amuR2wMgr4yz2OQW0xq9TwAAAPk"]
[Thu Jul 30 13:03:07.360842 2026] [security2:error] [pid 849392:tid 849639] [client 158.158.32.226:13790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/noname.php"] [unique_id "amuR2wMgr4yz2OQW0xq9TwAAAPk"]
[Thu Jul 30 13:03:07.373116 2026] [security2:error] [pid 849392:tid 849530] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/wyzer3.php"] [unique_id "amuR2wMgr4yz2OQW0xq9UAAAAIw"]
[Thu Jul 30 13:03:07.373227 2026] [security2:error] [pid 849392:tid 849530] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/wyzer3.php"] [unique_id "amuR2wMgr4yz2OQW0xq9UAAAAIw"]
[Thu Jul 30 13:03:07.666003 2026] [security2:error] [pid 849392:tid 849580] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/max.php"] [unique_id "amuR2wMgr4yz2OQW0xq9XQAAAL4"]
[Thu Jul 30 13:03:07.666139 2026] [security2:error] [pid 849392:tid 849580] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/max.php"] [unique_id "amuR2wMgr4yz2OQW0xq9XQAAAL4"]
[Thu Jul 30 13:03:07.715180 2026] [security2:error] [pid 849392:tid 849603] [client 158.158.32.226:47509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/kntol.php"] [unique_id "amuR2wMgr4yz2OQW0xq9XgAAANU"]
[Thu Jul 30 13:03:07.715320 2026] [security2:error] [pid 849392:tid 849603] [client 158.158.32.226:47509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/kntol.php"] [unique_id "amuR2wMgr4yz2OQW0xq9XgAAANU"]
[Thu Jul 30 13:03:07.718861 2026] [security2:error] [pid 849392:tid 849410] [remote 57.141.18.2:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuR2wMgr4yz2OQW0xq9VgAArxA"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=cotton,lycra,plastic,steel,wood,nylon&filter_size=extra-extra-large,extra-large,small&max_price=200&min_price=125&orderby=date&rating=5&status=sale&tax_product_cat=suit&unfilter=1
[Thu Jul 30 13:03:07.811782 2026] [security2:error] [pid 849392:tid 849411] [remote 57.141.0.71:21922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amuR2wMgr4yz2OQW0xq9XAAAjhE"]
[Thu Jul 30 13:03:07.984230 2026] [security2:error] [pid 849392:tid 849646] [client 158.158.32.226:14202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/WSO.php"] [unique_id "amuR2wMgr4yz2OQW0xq9agAAAQA"]
[Thu Jul 30 13:03:07.984411 2026] [security2:error] [pid 849392:tid 849646] [client 158.158.32.226:14202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/WSO.php"] [unique_id "amuR2wMgr4yz2OQW0xq9agAAAQA"]
[Thu Jul 30 13:03:07.998924 2026] [security2:error] [pid 849392:tid 849545] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ftde.php"] [unique_id "amuR2wMgr4yz2OQW0xq9bQAAAJs"]
[Thu Jul 30 13:03:07.999041 2026] [security2:error] [pid 849392:tid 849545] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.markmocek.com"] [uri "/ftde.php"] [unique_id "amuR2wMgr4yz2OQW0xq9bQAAAJs"]
[Thu Jul 30 13:03:08.222126 2026] [security2:error] [pid 849392:tid 849627] [client 57.141.0.40:24608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amuR2gMgr4yz2OQW0xq9PAAA7QQ"]
[Thu Jul 30 13:03:08.406701 2026] [security2:error] [pid 849392:tid 849405] [remote 57.141.18.53:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuR3AMgr4yz2OQW0xq9cQAAzQs"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=cotton,lycra,plastic,steel,wood,nylon&filter_size=extra-extra-large,extra-large,small&max_price=200&min_price=125&orderby=date&rating=5&status=sale&tax_product_cat=suit&unfilter=1
[Thu Jul 30 13:03:08.433991 2026] [security2:error] [pid 849392:tid 849606] [client 158.158.32.226:13766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/IndoXploit.php"] [unique_id "amuR3AMgr4yz2OQW0xq9egAAANg"]
[Thu Jul 30 13:03:08.434113 2026] [security2:error] [pid 849392:tid 849606] [client 158.158.32.226:13766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/IndoXploit.php"] [unique_id "amuR3AMgr4yz2OQW0xq9egAAANg"]
[Thu Jul 30 13:03:08.952941 2026] [security2:error] [pid 849392:tid 849575] [client 158.158.32.226:55329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/bajingan.php"] [unique_id "amuR3AMgr4yz2OQW0xq9hgAAALk"]
[Thu Jul 30 13:03:08.953073 2026] [security2:error] [pid 849392:tid 849575] [client 158.158.32.226:55329] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/bajingan.php"] [unique_id "amuR3AMgr4yz2OQW0xq9hgAAALk"]
[Thu Jul 30 13:03:09.139746 2026] [core:notice] [pid 849392:tid 849591] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:09.331007 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.32.226:17808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/Good.php"] [unique_id "amuR3QMgr4yz2OQW0xq9kwAAAOE"]
[Thu Jul 30 13:03:09.331147 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.32.226:17808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/Good.php"] [unique_id "amuR3QMgr4yz2OQW0xq9kwAAAOE"]
[Thu Jul 30 13:03:09.680210 2026] [core:notice] [pid 849392:tid 849618] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:09.681829 2026] [security2:error] [pid 849392:tid 849618] [client 158.158.32.226:13772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.nordeste1.com"] [uri "/pas.phtml"] [unique_id "amuR3QMgr4yz2OQW0xq9oAAAAOQ"]
[Thu Jul 30 13:03:10.362685 2026] [security2:error] [pid 849392:tid 849600] [client 158.158.32.226:13772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/pas.php"] [unique_id "amuR3gMgr4yz2OQW0xq9sgAAANI"]
[Thu Jul 30 13:03:10.362805 2026] [security2:error] [pid 849392:tid 849600] [client 158.158.32.226:13772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/pas.php"] [unique_id "amuR3gMgr4yz2OQW0xq9sgAAANI"]
[Thu Jul 30 13:03:10.677139 2026] [security2:error] [pid 849392:tid 849541] [client 158.158.32.226:55341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/abc.php"] [unique_id "amuR3gMgr4yz2OQW0xq9vAAAAJc"]
[Thu Jul 30 13:03:10.677239 2026] [security2:error] [pid 849392:tid 849541] [client 158.158.32.226:55341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/abc.php"] [unique_id "amuR3gMgr4yz2OQW0xq9vAAAAJc"]
[Thu Jul 30 13:03:10.738714 2026] [core:notice] [pid 849392:tid 849442] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:11.003601 2026] [security2:error] [pid 849392:tid 849558] [client 158.158.32.226:15701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/indexx.php"] [unique_id "amuR3wMgr4yz2OQW0xq9xQAAAKg"]
[Thu Jul 30 13:03:11.003743 2026] [security2:error] [pid 849392:tid 849558] [client 158.158.32.226:15701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/indexx.php"] [unique_id "amuR3wMgr4yz2OQW0xq9xQAAAKg"]
[Thu Jul 30 13:03:11.301786 2026] [security2:error] [pid 849392:tid 849614] [client 158.158.32.226:14165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/browse.php"] [unique_id "amuR3wMgr4yz2OQW0xq90AAAAOA"]
[Thu Jul 30 13:03:11.301913 2026] [security2:error] [pid 849392:tid 849614] [client 158.158.32.226:14165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/browse.php"] [unique_id "amuR3wMgr4yz2OQW0xq90AAAAOA"]
[Thu Jul 30 13:03:11.621903 2026] [security2:error] [pid 849392:tid 849595] [client 20.63.98.115:37202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/plugins.php"] [unique_id "amuR3wMgr4yz2OQW0xq93AAAAM0"]
[Thu Jul 30 13:03:11.767023 2026] [security2:error] [pid 849392:tid 849569] [client 158.158.32.226:47539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/up1.php"] [unique_id "amuR3wMgr4yz2OQW0xq95AAAALM"]
[Thu Jul 30 13:03:11.767150 2026] [security2:error] [pid 849392:tid 849569] [client 158.158.32.226:47539] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/up1.php"] [unique_id "amuR3wMgr4yz2OQW0xq95AAAALM"]
[Thu Jul 30 13:03:11.900450 2026] [security2:error] [pid 849392:tid 849610] [client 172.236.9.101:56980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR3wMgr4yz2OQW0xq91AAAANw"]
[Thu Jul 30 13:03:12.140500 2026] [security2:error] [pid 849392:tid 849528] [client 158.158.32.226:15675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/haha.php"] [unique_id "amuR4AMgr4yz2OQW0xq96QAAAIo"]
[Thu Jul 30 13:03:12.140616 2026] [security2:error] [pid 849392:tid 849528] [client 158.158.32.226:15675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/haha.php"] [unique_id "amuR4AMgr4yz2OQW0xq96QAAAIo"]
[Thu Jul 30 13:03:12.527583 2026] [security2:error] [pid 849392:tid 849591] [client 158.158.32.226:14198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/sc.php"] [unique_id "amuR4AMgr4yz2OQW0xq99gAAAMk"]
[Thu Jul 30 13:03:12.527695 2026] [security2:error] [pid 849392:tid 849591] [client 158.158.32.226:14198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/sc.php"] [unique_id "amuR4AMgr4yz2OQW0xq99gAAAMk"]
[Thu Jul 30 13:03:12.653421 2026] [security2:error] [pid 849392:tid 849553] [client 20.63.98.115:1941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/xxx.php"] [unique_id "amuR4AMgr4yz2OQW0xq99wAAAKM"]
[Thu Jul 30 13:03:12.871223 2026] [security2:error] [pid 849392:tid 849585] [client 158.158.32.226:55303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/fvck.php"] [unique_id "amuR4AMgr4yz2OQW0xq-BQAAAMM"]
[Thu Jul 30 13:03:12.871319 2026] [security2:error] [pid 849392:tid 849585] [client 158.158.32.226:55303] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/fvck.php"] [unique_id "amuR4AMgr4yz2OQW0xq-BQAAAMM"]
[Thu Jul 30 13:03:13.180179 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.32.226:55359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/0x.php"] [unique_id "amuR4QMgr4yz2OQW0xq-CAAAAKw"]
[Thu Jul 30 13:03:13.180300 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.32.226:55359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/0x.php"] [unique_id "amuR4QMgr4yz2OQW0xq-CAAAAKw"]
[Thu Jul 30 13:03:13.497132 2026] [security2:error] [pid 849392:tid 849586] [client 158.158.32.226:17855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/up.php5"] [unique_id "amuR4QMgr4yz2OQW0xq-FQAAAMQ"]
[Thu Jul 30 13:03:13.497246 2026] [security2:error] [pid 849392:tid 849586] [client 158.158.32.226:17855] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/up.php5"] [unique_id "amuR4QMgr4yz2OQW0xq-FQAAAMQ"]
[Thu Jul 30 13:03:13.649451 2026] [security2:error] [pid 849392:tid 849598] [client 20.63.98.115:50440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/css.php"] [unique_id "amuR4QMgr4yz2OQW0xq-GAAAANA"]
[Thu Jul 30 13:03:13.830089 2026] [security2:error] [pid 849392:tid 849641] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuR4QMgr4yz2OQW0xq-HAAA-1g"]
[Thu Jul 30 13:03:13.835542 2026] [security2:error] [pid 849392:tid 849549] [client 158.158.32.226:13763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/shell.php5"] [unique_id "amuR4QMgr4yz2OQW0xq-IwAAAJ8"]
[Thu Jul 30 13:03:13.835633 2026] [security2:error] [pid 849392:tid 849549] [client 158.158.32.226:13763] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/shell.php5"] [unique_id "amuR4QMgr4yz2OQW0xq-IwAAAJ8"]
[Thu Jul 30 13:03:14.169066 2026] [security2:error] [pid 849392:tid 849606] [client 158.158.32.226:55321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/inc/config.php"] [unique_id "amuR4gMgr4yz2OQW0xq-JQAAANg"]
[Thu Jul 30 13:03:14.169160 2026] [security2:error] [pid 849392:tid 849606] [client 158.158.32.226:55321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/inc/config.php"] [unique_id "amuR4gMgr4yz2OQW0xq-JQAAANg"]
[Thu Jul 30 13:03:14.470378 2026] [security2:error] [pid 849392:tid 849557] [client 158.158.32.226:55328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/ix.php"] [unique_id "amuR4gMgr4yz2OQW0xq-LAAAAKc"]
[Thu Jul 30 13:03:14.470466 2026] [security2:error] [pid 849392:tid 849557] [client 158.158.32.226:55328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/ix.php"] [unique_id "amuR4gMgr4yz2OQW0xq-LAAAAKc"]
[Thu Jul 30 13:03:14.799352 2026] [security2:error] [pid 849392:tid 849559] [client 158.158.32.226:17835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/r0x.php"] [unique_id "amuR4gMgr4yz2OQW0xq-MwAAAKk"]
[Thu Jul 30 13:03:14.799503 2026] [security2:error] [pid 849392:tid 849559] [client 158.158.32.226:17835] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/r0x.php"] [unique_id "amuR4gMgr4yz2OQW0xq-MwAAAKk"]
[Thu Jul 30 13:03:14.809674 2026] [security2:error] [pid 849392:tid 849538] [client 3.20.63.178:23944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuR4gMgr4yz2OQW0xq-MgAAAJQ"], referer: https://globalmarks.pk/
[Thu Jul 30 13:03:15.085625 2026] [security2:error] [pid 849392:tid 849639] [client 20.171.55.167:5192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuR4wMgr4yz2OQW0xq-PQAAAPk"]
[Thu Jul 30 13:03:15.105304 2026] [security2:error] [pid 849392:tid 849584] [client 158.158.32.226:55346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/bn.php"] [unique_id "amuR4wMgr4yz2OQW0xq-PwAAAMI"]
[Thu Jul 30 13:03:15.105407 2026] [security2:error] [pid 849392:tid 849584] [client 158.158.32.226:55346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/bn.php"] [unique_id "amuR4wMgr4yz2OQW0xq-PwAAAMI"]
[Thu Jul 30 13:03:15.495326 2026] [security2:error] [pid 849392:tid 849590] [client 158.158.32.226:15631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/dm.php"] [unique_id "amuR4wMgr4yz2OQW0xq-SQAAAMg"]
[Thu Jul 30 13:03:15.495442 2026] [security2:error] [pid 849392:tid 849590] [client 158.158.32.226:15631] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/dm.php"] [unique_id "amuR4wMgr4yz2OQW0xq-SQAAAMg"]
[Thu Jul 30 13:03:15.813487 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.32.226:13815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/gator.php"] [unique_id "amuR4wMgr4yz2OQW0xq-TgAAAME"]
[Thu Jul 30 13:03:15.813594 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.32.226:13815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/gator.php"] [unique_id "amuR4wMgr4yz2OQW0xq-TgAAAME"]
[Thu Jul 30 13:03:15.837799 2026] [security2:error] [pid 849392:tid 849563] [client 20.63.98.115:50451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuR4wMgr4yz2OQW0xq-TwAAAK0"]
[Thu Jul 30 13:03:15.956505 2026] [security2:error] [pid 849392:tid 849618] [client 20.171.55.167:5245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/404.php"] [unique_id "amuR4wMgr4yz2OQW0xq-UgAAAOQ"]
[Thu Jul 30 13:03:16.263103 2026] [core:notice] [pid 849392:tid 849543] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:16.264694 2026] [security2:error] [pid 849392:tid 849543] [client 158.158.32.226:13786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.nordeste1.com"] [uri "/perlcgi.pl"] [unique_id "amuR5AMgr4yz2OQW0xq-YgAAAJk"]
[Thu Jul 30 13:03:16.357161 2026] [security2:error] [pid 849392:tid 849515] [remote 47.128.28.109:63672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-high-og-wmns-silver-toe/"] [unique_id "amuR5AMgr4yz2OQW0xq-ZAAAiXk"]
[Thu Jul 30 13:03:16.843416 2026] [security2:error] [pid 849392:tid 849536] [client 20.171.55.167:5224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-configs.php"] [unique_id "amuR5AMgr4yz2OQW0xq-egAAAJI"]
[Thu Jul 30 13:03:16.995625 2026] [security2:error] [pid 849392:tid 849534] [client 20.63.98.115:50454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuR5AMgr4yz2OQW0xq-fAAAAJA"]
[Thu Jul 30 13:03:17.039729 2026] [security2:error] [pid 849392:tid 849570] [client 158.158.32.226:13786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/mail.php"] [unique_id "amuR5QMgr4yz2OQW0xq-gAAAALQ"]
[Thu Jul 30 13:03:17.039839 2026] [security2:error] [pid 849392:tid 849570] [client 158.158.32.226:13786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/mail.php"] [unique_id "amuR5QMgr4yz2OQW0xq-gAAAALQ"]
[Thu Jul 30 13:03:17.345738 2026] [core:notice] [pid 849392:tid 849510] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:17.407800 2026] [security2:error] [pid 849392:tid 849621] [client 158.158.32.226:55342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/mailer.php"] [unique_id "amuR5QMgr4yz2OQW0xq-iAAAAOc"]
[Thu Jul 30 13:03:17.407905 2026] [security2:error] [pid 849392:tid 849621] [client 158.158.32.226:55342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/mailer.php"] [unique_id "amuR5QMgr4yz2OQW0xq-iAAAAOc"]
[Thu Jul 30 13:03:17.786310 2026] [security2:error] [pid 849392:tid 849579] [client 20.171.55.167:5194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/simple.php"] [unique_id "amuR5QMgr4yz2OQW0xq-lgAAAL0"]
[Thu Jul 30 13:03:17.842734 2026] [core:notice] [pid 849392:tid 849631] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:17.843721 2026] [authz_core:error] [pid 849392:tid 849631] [client 158.158.32.226:15645] AH01630: client denied by server configuration: /home1/vdbnyxte/public_html/website_2258ef87/php.ini
[Thu Jul 30 13:03:17.843823 2026] [security2:error] [pid 849392:tid 849631] [client 158.158.32.226:15645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.nordeste1.com"] [uri "/php.ini"] [unique_id "amuR5QMgr4yz2OQW0xq-lwAAAPE"]
[Thu Jul 30 13:03:17.975618 2026] [security2:error] [pid 849392:tid 849404] [remote 57.141.0.9:39648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuR5QMgr4yz2OQW0xq-mQAAjQo"]
[Thu Jul 30 13:03:18.176827 2026] [fcgid:warn] [pid 849392:tid 849628] (70014)End of file found: [client 20.84.78.51:55390] mod_fcgid: can't get data from http client
[Thu Jul 30 13:03:18.663425 2026] [security2:error] [pid 849392:tid 849529] [client 20.171.55.167:5247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/themes.php"] [unique_id "amuR5gMgr4yz2OQW0xq-sAAAAIs"]
[Thu Jul 30 13:03:18.858225 2026] [core:notice] [pid 849392:tid 849567] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:18.859923 2026] [security2:error] [pid 849392:tid 849567] [client 158.158.32.226:13793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/"] [unique_id "amuR5gMgr4yz2OQW0xq-tAAAALE"]
[Thu Jul 30 13:03:19.206928 2026] [security2:error] [pid 849392:tid 849534] [client 158.158.32.226:15645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/modul.php"] [unique_id "amuR5wMgr4yz2OQW0xq-vAAAAJA"]
[Thu Jul 30 13:03:19.207058 2026] [security2:error] [pid 849392:tid 849534] [client 158.158.32.226:15645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/modul.php"] [unique_id "amuR5wMgr4yz2OQW0xq-vAAAAJA"]
[Thu Jul 30 13:03:19.421453 2026] [security2:error] [pid 849392:tid 849537] [client 20.171.55.167:5774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/ini.php"] [unique_id "amuR5wMgr4yz2OQW0xq-wgAAAJM"]
[Thu Jul 30 13:03:19.555989 2026] [security2:error] [pid 849392:tid 849593] [client 158.158.32.226:17823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/configuration.php"] [unique_id "amuR5wMgr4yz2OQW0xq-xAAAAMs"]
[Thu Jul 30 13:03:19.556102 2026] [security2:error] [pid 849392:tid 849593] [client 158.158.32.226:17823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/configuration.php"] [unique_id "amuR5wMgr4yz2OQW0xq-xAAAAMs"]
[Thu Jul 30 13:03:19.894324 2026] [security2:error] [pid 849392:tid 849584] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuR5wMgr4yz2OQW0xq-wAAAwho"]
[Thu Jul 30 13:03:19.906397 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.32.226:13815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/tai.php"] [unique_id "amuR5wMgr4yz2OQW0xq-zwAAAME"]
[Thu Jul 30 13:03:19.906498 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.32.226:13815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/tai.php"] [unique_id "amuR5wMgr4yz2OQW0xq-zwAAAME"]
[Thu Jul 30 13:03:20.149786 2026] [security2:error] [pid 849392:tid 849427] [remote 57.141.18.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuR6AMgr4yz2OQW0xq-1QAA5CE"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Ccarbon%2Ccotton%2Cdenim%2Clinen%2Cpolyester%2Csteel&filter_size=large%2Cmedium%2Csmall%2Cextra-extra-large&rating=5&status=instock&unfilter=1&orderby=menu_order
[Thu Jul 30 13:03:20.262751 2026] [security2:error] [pid 849392:tid 849573] [client 158.158.32.226:47512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/www.php"] [unique_id "amuR6AMgr4yz2OQW0xq-3QAAALc"]
[Thu Jul 30 13:03:20.262856 2026] [security2:error] [pid 849392:tid 849573] [client 158.158.32.226:47512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/www.php"] [unique_id "amuR6AMgr4yz2OQW0xq-3QAAALc"]
[Thu Jul 30 13:03:20.350094 2026] [security2:error] [pid 849392:tid 849431] [remote 57.141.18.118:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuR6AMgr4yz2OQW0xq-4QAA_yU"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Ccarbon%2Ccotton%2Cdenim%2Clinen%2Cpolyester%2Csteel&filter_size=large%2Cmedium%2Csmall%2Cextra-extra-large&rating=5&status=instock&unfilter=1&orderby=menu_order
[Thu Jul 30 13:03:20.528606 2026] [security2:error] [pid 849392:tid 849531] [client 20.171.55.167:5775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/autoload_classmap.php"] [unique_id "amuR6AMgr4yz2OQW0xq-4wAAAI0"]
[Thu Jul 30 13:03:20.645050 2026] [security2:error] [pid 849392:tid 849576] [client 158.158.32.226:47496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/x13.php"] [unique_id "amuR6AMgr4yz2OQW0xq-5QAAALo"]
[Thu Jul 30 13:03:20.645166 2026] [security2:error] [pid 849392:tid 849576] [client 158.158.32.226:47496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/x13.php"] [unique_id "amuR6AMgr4yz2OQW0xq-5QAAALo"]
[Thu Jul 30 13:03:20.710741 2026] [security2:error] [pid 849392:tid 849549] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuR6AMgr4yz2OQW0xq-0wAAAJ8"]
[Thu Jul 30 13:03:20.945283 2026] [security2:error] [pid 849392:tid 849639] [client 158.158.32.226:15669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/ntaps.php"] [unique_id "amuR6AMgr4yz2OQW0xq--AAAAPk"]
[Thu Jul 30 13:03:20.945413 2026] [security2:error] [pid 849392:tid 849639] [client 158.158.32.226:15669] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/ntaps.php"] [unique_id "amuR6AMgr4yz2OQW0xq--AAAAPk"]
[Thu Jul 30 13:03:21.091151 2026] [security2:error] [pid 849392:tid 849450] [remote 184.168.126.180:39310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.eow.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuR6QMgr4yz2OQW0xq--QAA2Dg"]
[Thu Jul 30 13:03:21.262869 2026] [security2:error] [pid 849392:tid 849585] [client 158.158.32.226:14162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/zip.php"] [unique_id "amuR6QMgr4yz2OQW0xq-_gAAAMM"]
[Thu Jul 30 13:03:21.262968 2026] [security2:error] [pid 849392:tid 849585] [client 158.158.32.226:14162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/zip.php"] [unique_id "amuR6QMgr4yz2OQW0xq-_gAAAMM"]
[Thu Jul 30 13:03:21.311914 2026] [security2:error] [pid 849392:tid 849524] [client 20.171.55.167:5772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/as.php"] [unique_id "amuR6QMgr4yz2OQW0xq_AgAAAIY"]
[Thu Jul 30 13:03:21.636160 2026] [security2:error] [pid 849392:tid 849649] [client 158.158.32.226:17846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/@.php"] [unique_id "amuR6QMgr4yz2OQW0xq_BgAAAQM"]
[Thu Jul 30 13:03:21.636269 2026] [security2:error] [pid 849392:tid 849649] [client 158.158.32.226:17846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/@.php"] [unique_id "amuR6QMgr4yz2OQW0xq_BgAAAQM"]
[Thu Jul 30 13:03:21.935905 2026] [security2:error] [pid 849392:tid 849643] [client 158.158.32.226:14149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/ea.php"] [unique_id "amuR6QMgr4yz2OQW0xq_FgAAAP0"]
[Thu Jul 30 13:03:21.936063 2026] [security2:error] [pid 849392:tid 849643] [client 158.158.32.226:14149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/ea.php"] [unique_id "amuR6QMgr4yz2OQW0xq_FgAAAP0"]
[Thu Jul 30 13:03:22.285055 2026] [security2:error] [pid 849392:tid 849565] [client 20.171.55.167:5243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/admin/upload/css.php"] [unique_id "amuR6gMgr4yz2OQW0xq_HgAAAK8"]
[Thu Jul 30 13:03:22.344341 2026] [security2:error] [pid 849392:tid 849564] [client 158.158.32.226:55299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/aaaa.php"] [unique_id "amuR6gMgr4yz2OQW0xq_IgAAAK4"]
[Thu Jul 30 13:03:22.344430 2026] [security2:error] [pid 849392:tid 849564] [client 158.158.32.226:55299] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/aaaa.php"] [unique_id "amuR6gMgr4yz2OQW0xq_IgAAAK4"]
[Thu Jul 30 13:03:22.544942 2026] [security2:error] [pid 849392:tid 849582] [client 20.63.98.115:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuR6gMgr4yz2OQW0xq_LgAAAMA"]
[Thu Jul 30 13:03:22.654283 2026] [security2:error] [pid 849392:tid 849551] [client 158.158.32.226:47522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/cinfo.php"] [unique_id "amuR6gMgr4yz2OQW0xq_LwAAAKE"]
[Thu Jul 30 13:03:22.654401 2026] [security2:error] [pid 849392:tid 849551] [client 158.158.32.226:47522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/cinfo.php"] [unique_id "amuR6gMgr4yz2OQW0xq_LwAAAKE"]
[Thu Jul 30 13:03:22.943620 2026] [security2:error] [pid 849392:tid 849600] [client 158.158.32.226:14172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/newfile.php"] [unique_id "amuR6gMgr4yz2OQW0xq_OwAAANI"]
[Thu Jul 30 13:03:22.943769 2026] [security2:error] [pid 849392:tid 849600] [client 158.158.32.226:14172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/newfile.php"] [unique_id "amuR6gMgr4yz2OQW0xq_OwAAANI"]
[Thu Jul 30 13:03:23.004277 2026] [security2:error] [pid 849392:tid 849626] [client 165.154.62.227:53700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amuR6gMgr4yz2OQW0xq_KQAAAOw"]
[Thu Jul 30 13:03:23.270555 2026] [security2:error] [pid 849392:tid 849558] [client 20.171.55.167:5773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/pki-validation/afnew.php"] [unique_id "amuR6wMgr4yz2OQW0xq_PwAAAKg"]
[Thu Jul 30 13:03:23.404816 2026] [security2:error] [pid 849392:tid 849599] [client 158.158.32.226:15644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/pro.php"] [unique_id "amuR6wMgr4yz2OQW0xq_RAAAANE"]
[Thu Jul 30 13:03:23.404956 2026] [security2:error] [pid 849392:tid 849599] [client 158.158.32.226:15644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/pro.php"] [unique_id "amuR6wMgr4yz2OQW0xq_RAAAANE"]
[Thu Jul 30 13:03:23.624310 2026] [security2:error] [pid 849392:tid 849559] [client 74.7.230.24:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-b02404d3.gbq.rty.temporary.site"] [uri "/index.php"] [unique_id "amuR6AMgr4yz2OQW0xq-7gAAAKk"]
[Thu Jul 30 13:03:23.625250 2026] [security2:error] [pid 849392:tid 849557] [client 74.7.230.24:53414] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-b02404d3.gbq.rty.temporary.site"] [uri "/robots.txt"] [unique_id "amuR6AMgr4yz2OQW0xq-6wAApys"]
[Thu Jul 30 13:03:23.682715 2026] [security2:error] [pid 849392:tid 849607] [client 195.174.132.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amuR6gMgr4yz2OQW0xq_MwAAANk"], referer: https://shop-mevius.com/product/winston-2/
[Thu Jul 30 13:03:23.739108 2026] [security2:error] [pid 849392:tid 849646] [client 20.63.98.115:1673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/network/about.php"] [unique_id "amuR6wMgr4yz2OQW0xq_TwAAAQA"]
[Thu Jul 30 13:03:23.758921 2026] [security2:error] [pid 849392:tid 849605] [client 158.158.32.226:47541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/edit.php"] [unique_id "amuR6wMgr4yz2OQW0xq_UAAAANc"]
[Thu Jul 30 13:03:23.759045 2026] [security2:error] [pid 849392:tid 849605] [client 158.158.32.226:47541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/edit.php"] [unique_id "amuR6wMgr4yz2OQW0xq_UAAAANc"]
[Thu Jul 30 13:03:24.045898 2026] [security2:error] [pid 849392:tid 849553] [client 158.158.32.226:47533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/11.php"] [unique_id "amuR7AMgr4yz2OQW0xq_XwAAAKM"]
[Thu Jul 30 13:03:24.046001 2026] [security2:error] [pid 849392:tid 849553] [client 158.158.32.226:47533] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/11.php"] [unique_id "amuR7AMgr4yz2OQW0xq_XwAAAKM"]
[Thu Jul 30 13:03:24.052798 2026] [fcgid:warn] [pid 849392:tid 849545] (70014)End of file found: [client 165.154.62.227:39800] mod_fcgid: can't get data from http client
[Thu Jul 30 13:03:24.187793 2026] [security2:error] [pid 849392:tid 849577] [client 20.171.55.167:5768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/lufix.php"] [unique_id "amuR7AMgr4yz2OQW0xq_YQAAALs"]
[Thu Jul 30 13:03:24.295928 2026] [fcgid:warn] [pid 849392:tid 849606] (70014)End of file found: [client 165.154.62.227:39822] mod_fcgid: can't get data from http client
[Thu Jul 30 13:03:24.369472 2026] [security2:error] [pid 849392:tid 849585] [client 158.158.32.226:14191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/title.php"] [unique_id "amuR7AMgr4yz2OQW0xq_ZgAAAMM"]
[Thu Jul 30 13:03:24.369609 2026] [security2:error] [pid 849392:tid 849585] [client 158.158.32.226:14191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/title.php"] [unique_id "amuR7AMgr4yz2OQW0xq_ZgAAAMM"]
[Thu Jul 30 13:03:24.580446 2026] [security2:error] [pid 849392:tid 849630] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuR7AMgr4yz2OQW0xq_awAA8Eo"]
[Thu Jul 30 13:03:24.599634 2026] [fcgid:warn] [pid 849392:tid 849567] (70014)End of file found: [client 165.154.62.227:39852] mod_fcgid: can't get data from http client
[Thu Jul 30 13:03:24.606504 2026] [core:notice] [pid 849392:tid 849457] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:24.957129 2026] [security2:error] [pid 849392:tid 849640] [client 20.171.55.167:5809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/media.php"] [unique_id "amuR7AMgr4yz2OQW0xq_eAAAAPo"]
[Thu Jul 30 13:03:24.977076 2026] [security2:error] [pid 849392:tid 849604] [client 158.158.32.226:17838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/xmlrpc.php"] [unique_id "amuR7AMgr4yz2OQW0xq_cQAAANY"]
[Thu Jul 30 13:03:24.977179 2026] [security2:error] [pid 849392:tid 849604] [client 158.158.32.226:17838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/xmlrpc.php"] [unique_id "amuR7AMgr4yz2OQW0xq_cQAAANY"]
[Thu Jul 30 13:03:25.274714 2026] [security2:error] [pid 849392:tid 849560] [client 158.158.32.226:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/pass.php"] [unique_id "amuR7QMgr4yz2OQW0xq_fQAAAKo"]
[Thu Jul 30 13:03:25.274861 2026] [security2:error] [pid 849392:tid 849560] [client 158.158.32.226:52116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/pass.php"] [unique_id "amuR7QMgr4yz2OQW0xq_fQAAAKo"]
[Thu Jul 30 13:03:25.590620 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.32.226:15678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/Cpanel.php"] [unique_id "amuR7QMgr4yz2OQW0xq_hwAAAOE"]
[Thu Jul 30 13:03:25.590740 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.32.226:15678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/Cpanel.php"] [unique_id "amuR7QMgr4yz2OQW0xq_hwAAAOE"]
[Thu Jul 30 13:03:25.647282 2026] [core:notice] [pid 849392:tid 849578] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:25.652167 2026] [security2:error] [pid 849392:tid 849578] [client 170.83.178.165:33942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/download/27/25"] [unique_id "amuR7QMgr4yz2OQW0xq_fwAAALw"]
[Thu Jul 30 13:03:25.818744 2026] [security2:error] [pid 849392:tid 849607] [client 20.171.55.167:5777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/simple.php"] [unique_id "amuR7QMgr4yz2OQW0xq_iwAAANk"]
[Thu Jul 30 13:03:25.928069 2026] [security2:error] [pid 849392:tid 849531] [client 158.158.32.226:15674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/unknown.php"] [unique_id "amuR7QMgr4yz2OQW0xq_jQAAAI0"]
[Thu Jul 30 13:03:25.928169 2026] [security2:error] [pid 849392:tid 849531] [client 158.158.32.226:15674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/unknown.php"] [unique_id "amuR7QMgr4yz2OQW0xq_jQAAAI0"]
[Thu Jul 30 13:03:26.007231 2026] [core:notice] [pid 849392:tid 849523] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:26.201119 2026] [security2:error] [pid 849392:tid 849591] [client 158.158.32.226:13803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/sel.php"] [unique_id "amuR7gMgr4yz2OQW0xq_mAAAAMk"]
[Thu Jul 30 13:03:26.201268 2026] [security2:error] [pid 849392:tid 849591] [client 158.158.32.226:13803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/sel.php"] [unique_id "amuR7gMgr4yz2OQW0xq_mAAAAMk"]
[Thu Jul 30 13:03:26.342213 2026] [security2:error] [pid 849392:tid 849486] [remote 57.141.0.3:48498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuR7gMgr4yz2OQW0xq_mQAA9lw"]
[Thu Jul 30 13:03:26.492818 2026] [security2:error] [pid 849392:tid 849545] [client 158.158.32.226:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/14.php"] [unique_id "amuR7gMgr4yz2OQW0xq_mwAAAJs"]
[Thu Jul 30 13:03:26.492930 2026] [security2:error] [pid 849392:tid 849545] [client 158.158.32.226:52121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/14.php"] [unique_id "amuR7gMgr4yz2OQW0xq_mwAAAJs"]
[Thu Jul 30 13:03:26.683093 2026] [core:notice] [pid 849392:tid 849491] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:26.766291 2026] [security2:error] [pid 849392:tid 849526] [client 20.171.55.167:5202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/contact.php"] [unique_id "amuR7gMgr4yz2OQW0xq_pwAAAIg"]
[Thu Jul 30 13:03:26.972350 2026] [security2:error] [pid 849392:tid 849626] [client 158.158.32.226:17850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/about.php"] [unique_id "amuR7gMgr4yz2OQW0xq_qQAAAOw"]
[Thu Jul 30 13:03:26.972448 2026] [security2:error] [pid 849392:tid 849626] [client 158.158.32.226:17850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/about.php"] [unique_id "amuR7gMgr4yz2OQW0xq_qQAAAOw"]
[Thu Jul 30 13:03:27.273800 2026] [security2:error] [pid 849392:tid 849612] [client 158.158.32.226:17829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/angel.php"] [unique_id "amuR7wMgr4yz2OQW0xq_uQAAAN4"]
[Thu Jul 30 13:03:27.273958 2026] [security2:error] [pid 849392:tid 849612] [client 158.158.32.226:17829] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/angel.php"] [unique_id "amuR7wMgr4yz2OQW0xq_uQAAAN4"]
[Thu Jul 30 13:03:27.680841 2026] [security2:error] [pid 849392:tid 849556] [client 158.158.32.226:55319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/c100.php"] [unique_id "amuR7wMgr4yz2OQW0xq_wwAAAKY"]
[Thu Jul 30 13:03:27.681003 2026] [security2:error] [pid 849392:tid 849556] [client 158.158.32.226:55319] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/c100.php"] [unique_id "amuR7wMgr4yz2OQW0xq_wwAAAKY"]
[Thu Jul 30 13:03:27.684184 2026] [security2:error] [pid 849392:tid 849614] [client 172.237.109.114:27757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR7wMgr4yz2OQW0xq_sQAAAOA"]
[Thu Jul 30 13:03:27.727109 2026] [security2:error] [pid 849392:tid 849581] [client 172.237.109.114:42766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR7wMgr4yz2OQW0xq_sgAAAL8"]
[Thu Jul 30 13:03:27.727448 2026] [security2:error] [pid 849392:tid 849534] [client 172.237.109.114:42473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR7wMgr4yz2OQW0xq_swAAAJA"]
[Thu Jul 30 13:03:27.727644 2026] [security2:error] [pid 849392:tid 849532] [client 172.237.109.114:61713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR7wMgr4yz2OQW0xq_twAAAI4"]
[Thu Jul 30 13:03:27.752503 2026] [security2:error] [pid 849392:tid 849580] [client 172.237.109.114:18491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuR7wMgr4yz2OQW0xq_tQAAAL4"]
[Thu Jul 30 13:03:27.844698 2026] [security2:error] [pid 849392:tid 849589] [client 20.171.55.167:5764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/byp.php"] [unique_id "amuR7wMgr4yz2OQW0xq_xwAAAMc"]
[Thu Jul 30 13:03:28.721612 2026] [security2:error] [pid 849392:tid 849527] [client 20.171.55.167:5235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/upload.php"] [unique_id "amuR8AMgr4yz2OQW0xq_4gAAAIk"]
[Thu Jul 30 13:03:29.177491 2026] [security2:error] [pid 849392:tid 849561] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuR8AMgr4yz2OQW0xq_2QAAAKs"]
[Thu Jul 30 13:03:29.591315 2026] [security2:error] [pid 849392:tid 849608] [client 20.171.55.167:5767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "amuR8QMgr4yz2OQW0xq_8gAAANo"]
[Thu Jul 30 13:03:29.684967 2026] [security2:error] [pid 849392:tid 849612] [client 127.0.0.1:24714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuR8QMgr4yz2OQW0xq_9AAAAN4"]
[Thu Jul 30 13:03:29.685050 2026] [security2:error] [pid 849392:tid 849632] [client 74.7.228.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.reviewbyjook.com"] [uri "/robots.txt"] [unique_id "amuR8QMgr4yz2OQW0xq_8wAA8gE"]
[Thu Jul 30 13:03:30.569989 2026] [security2:error] [pid 849392:tid 849548] [client 52.167.144.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuR8gMgr4yz2OQW0xrABAAAAJ4"]
[Thu Jul 30 13:03:30.638672 2026] [security2:error] [pid 849392:tid 849643] [client 20.171.55.167:5813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cong.php"] [unique_id "amuR8gMgr4yz2OQW0xrAHQAAAP0"]
[Thu Jul 30 13:03:31.136418 2026] [core:error] [pid 849392:tid 849634] [client 74.7.241.189:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:31.136451 2026] [core:error] [pid 849392:tid 849634] [client 74.7.241.189:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:31.136576 2026] [security2:error] [pid 849392:tid 849634] [client 74.7.241.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.ssm.njr.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuR8wMgr4yz2OQW0xrALQAAAPQ"]
[Thu Jul 30 13:03:31.137181 2026] [security2:error] [pid 849392:tid 849600] [client 74.7.241.189:35484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.ssm.njr.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuR8wMgr4yz2OQW0xrAKwAA0hQ"]
[Thu Jul 30 13:03:31.181076 2026] [security2:error] [pid 849392:tid 849555] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuR8gMgr4yz2OQW0xrAHAAAAKU"]
[Thu Jul 30 13:03:31.244228 2026] [security2:error] [pid 849392:tid 849552] [client 158.158.32.226:17828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/simattacker.php"] [unique_id "amuR8wMgr4yz2OQW0xrAMQAAAKI"]
[Thu Jul 30 13:03:31.244349 2026] [security2:error] [pid 849392:tid 849552] [client 158.158.32.226:17828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/simattacker.php"] [unique_id "amuR8wMgr4yz2OQW0xrAMQAAAKI"]
[Thu Jul 30 13:03:31.467795 2026] [security2:error] [pid 849392:tid 849649] [client 20.171.55.167:5193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/about/function.php"] [unique_id "amuR8wMgr4yz2OQW0xrAOQAAAQM"]
[Thu Jul 30 13:03:31.837770 2026] [security2:error] [pid 849392:tid 849412] [remote 74.7.241.59:54688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuR8wMgr4yz2OQW0xrAQwAA6xI"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/forms/classes
[Thu Jul 30 13:03:32.288079 2026] [security2:error] [pid 849392:tid 849605] [client 95.229.106.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuR9AMgr4yz2OQW0xrATQAAANc"], referer: http://cnpinyin.com
[Thu Jul 30 13:03:32.626988 2026] [fcgid:warn] [pid 849392:tid 849631] (70014)End of file found: [client 165.154.62.227:54586] mod_fcgid: can't get data from http client
[Thu Jul 30 13:03:33.428129 2026] [security2:error] [pid 849392:tid 849442] [remote 213.55.96.154:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.96.55.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trustedmoversandpackersabudhabi.online"] [uri "/wp-login.php"] [unique_id "amuR9QMgr4yz2OQW0xrAdwAAyjA"]
[Thu Jul 30 13:03:33.460364 2026] [security2:error] [pid 849392:tid 849593] [client 20.171.55.167:5238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/filemanager/dialog.php"] [unique_id "amuR9QMgr4yz2OQW0xrAeQAAAMs"]
[Thu Jul 30 13:03:34.089185 2026] [security2:error] [pid 849392:tid 849525] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuR9QMgr4yz2OQW0xrAfgAAAIc"]
[Thu Jul 30 13:03:34.268910 2026] [core:error] [pid 849392:tid 849650] [client 74.7.230.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:34.268936 2026] [core:error] [pid 849392:tid 849650] [client 74.7.230.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:34.269083 2026] [security2:error] [pid 849392:tid 849650] [client 74.7.230.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.emberleafweeddeliverydispensary.delivery"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuR9gMgr4yz2OQW0xrAkAAAAQQ"]
[Thu Jul 30 13:03:34.269704 2026] [security2:error] [pid 849392:tid 849569] [client 74.7.230.49:47434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.emberleafweeddeliverydispensary.delivery"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuR9gMgr4yz2OQW0xrAjgAAs0U"]
[Thu Jul 30 13:03:34.387438 2026] [security2:error] [pid 849392:tid 849565] [client 20.171.55.167:5760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/bak.php"] [unique_id "amuR9gMgr4yz2OQW0xrAmgAAAK8"]
[Thu Jul 30 13:03:34.774436 2026] [core:error] [pid 849392:tid 849553] [client 74.7.241.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:34.774460 2026] [core:error] [pid 849392:tid 849553] [client 74.7.241.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:34.774600 2026] [security2:error] [pid 849392:tid 849553] [client 74.7.241.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.sharjahfurnituremoversandpackers.space"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuR9gMgr4yz2OQW0xrApgAAAKM"]
[Thu Jul 30 13:03:34.775174 2026] [security2:error] [pid 849392:tid 849585] [client 74.7.241.186:60904] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.sharjahfurnituremoversandpackers.space"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuR9gMgr4yz2OQW0xrApAAAwz0"]
[Thu Jul 30 13:03:35.220168 2026] [security2:error] [pid 849392:tid 849459] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuR9wMgr4yz2OQW0xrAtQAA70E"]
[Thu Jul 30 13:03:35.220476 2026] [security2:error] [pid 849392:tid 849629] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuR9wMgr4yz2OQW0xrAtQAA70E"]
[Thu Jul 30 13:03:35.259861 2026] [security2:error] [pid 849392:tid 849538] [client 62.201.242.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amuR9gMgr4yz2OQW0xrAmAAAAJQ"], referer: https://shop-mevius.com/product/winston-2/
[Thu Jul 30 13:03:35.273635 2026] [security2:error] [pid 849392:tid 849608] [client 20.171.55.167:5769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-info.php"] [unique_id "amuR9wMgr4yz2OQW0xrAtwAAANo"]
[Thu Jul 30 13:03:35.330876 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.32.226:55330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wsoshell.php"] [unique_id "amuR9wMgr4yz2OQW0xrAuQAAAME"]
[Thu Jul 30 13:03:35.331018 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.32.226:55330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wsoshell.php"] [unique_id "amuR9wMgr4yz2OQW0xrAuQAAAME"]
[Thu Jul 30 13:03:35.969035 2026] [security2:error] [pid 849392:tid 849475] [remote 57.141.18.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuR9wMgr4yz2OQW0xrAzAAAkVE"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=nylon,polyester,aluminum,denim,lycra,steel,titanium&filter_size=extra-large,small&orderby=popularity&filter_brand=desigual&unfilter=1
[Thu Jul 30 13:03:36.248140 2026] [security2:error] [pid 849392:tid 849579] [client 158.158.32.226:14189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/autoload_classmap.php"] [unique_id "amuR-AMgr4yz2OQW0xrA0AAAAL0"]
[Thu Jul 30 13:03:36.248266 2026] [security2:error] [pid 849392:tid 849579] [client 158.158.32.226:14189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/autoload_classmap.php"] [unique_id "amuR-AMgr4yz2OQW0xrA0AAAAL0"]
[Thu Jul 30 13:03:36.366179 2026] [security2:error] [pid 849392:tid 849565] [client 20.171.55.167:5793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/files/index.php"] [unique_id "amuR-AMgr4yz2OQW0xrA0gAAAK8"]
[Thu Jul 30 13:03:36.578155 2026] [security2:error] [pid 849392:tid 849481] [remote 57.141.18.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuR-AMgr4yz2OQW0xrA3QAApVc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=nylon,polyester,aluminum,denim,lycra,steel,titanium&filter_size=extra-large,small&orderby=popularity&filter_brand=desigual&unfilter=1
[Thu Jul 30 13:03:36.651279 2026] [security2:error] [pid 849392:tid 849533] [client 158.158.32.226:17833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/12.php"] [unique_id "amuR-AMgr4yz2OQW0xrA3gAAAI8"]
[Thu Jul 30 13:03:36.651385 2026] [security2:error] [pid 849392:tid 849533] [client 158.158.32.226:17833] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/12.php"] [unique_id "amuR-AMgr4yz2OQW0xrA3gAAAI8"]
[Thu Jul 30 13:03:36.873378 2026] [security2:error] [pid 849392:tid 849604] [client 184.75.208.246:46664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.208.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuR-AMgr4yz2OQW0xrA4QAAANY"]
[Thu Jul 30 13:03:36.873486 2026] [security2:error] [pid 849392:tid 849604] [client 184.75.208.246:46664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuR-AMgr4yz2OQW0xrA4QAAANY"]
[Thu Jul 30 13:03:37.188791 2026] [security2:error] [pid 849392:tid 849575] [client 158.158.32.226:47518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wikiindex.php"] [unique_id "amuR-QMgr4yz2OQW0xrA6wAAALk"]
[Thu Jul 30 13:03:37.188892 2026] [security2:error] [pid 849392:tid 849575] [client 158.158.32.226:47518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wikiindex.php"] [unique_id "amuR-QMgr4yz2OQW0xrA6wAAALk"]
[Thu Jul 30 13:03:37.293789 2026] [security2:error] [pid 849392:tid 849564] [client 20.171.55.167:5776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/css.php"] [unique_id "amuR-QMgr4yz2OQW0xrA7AAAAK4"]
[Thu Jul 30 13:03:37.557266 2026] [core:notice] [pid 849392:tid 849597] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:37.614414 2026] [security2:error] [pid 849392:tid 849559] [client 158.158.32.226:55297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/alex.php"] [unique_id "amuR-QMgr4yz2OQW0xrA9AAAAKk"]
[Thu Jul 30 13:03:37.614517 2026] [security2:error] [pid 849392:tid 849559] [client 158.158.32.226:55297] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/alex.php"] [unique_id "amuR-QMgr4yz2OQW0xrA9AAAAKk"]
[Thu Jul 30 13:03:37.669706 2026] [security2:error] [pid 849392:tid 849589] [client 62.238.56.140:41776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuR-AMgr4yz2OQW0xrA3wAAAI0"]
[Thu Jul 30 13:03:37.911424 2026] [security2:error] [pid 849392:tid 849600] [client 20.63.98.115:37806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/xpw.php"] [unique_id "amuR-QMgr4yz2OQW0xrA-wAAANI"]
[Thu Jul 30 13:03:38.058400 2026] [security2:error] [pid 849392:tid 849642] [client 158.158.32.226:47519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-0.php"] [unique_id "amuR-gMgr4yz2OQW0xrA_wAAAPw"]
[Thu Jul 30 13:03:38.058486 2026] [security2:error] [pid 849392:tid 849642] [client 158.158.32.226:47519] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-0.php"] [unique_id "amuR-gMgr4yz2OQW0xrA_wAAAPw"]
[Thu Jul 30 13:03:38.096725 2026] [security2:error] [pid 849392:tid 849635] [client 20.171.55.167:5765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/css/index.php"] [unique_id "amuR-gMgr4yz2OQW0xrBAwAAAPU"]
[Thu Jul 30 13:03:38.345584 2026] [core:notice] [pid 849392:tid 849535] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:38.486808 2026] [security2:error] [pid 849392:tid 849631] [client 158.158.32.226:55352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-1.php"] [unique_id "amuR-gMgr4yz2OQW0xrBCgAAAPE"]
[Thu Jul 30 13:03:38.486924 2026] [security2:error] [pid 849392:tid 849631] [client 158.158.32.226:55352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-1.php"] [unique_id "amuR-gMgr4yz2OQW0xrBCgAAAPE"]
[Thu Jul 30 13:03:38.727017 2026] [core:notice] [pid 849392:tid 849506] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:38.789268 2026] [security2:error] [pid 849392:tid 849537] [client 158.158.32.226:52099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/xindex.php"] [unique_id "amuR-gMgr4yz2OQW0xrBFgAAAJM"]
[Thu Jul 30 13:03:38.789376 2026] [security2:error] [pid 849392:tid 849537] [client 158.158.32.226:52099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/xindex.php"] [unique_id "amuR-gMgr4yz2OQW0xrBFgAAAJM"]
[Thu Jul 30 13:03:39.040237 2026] [security2:error] [pid 849392:tid 849626] [client 20.171.55.167:5770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/bak.php"] [unique_id "amuR-wMgr4yz2OQW0xrBGAAAAOw"]
[Thu Jul 30 13:03:39.164535 2026] [security2:error] [pid 849392:tid 849592] [client 158.158.32.226:55315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wiki-index.php"] [unique_id "amuR-wMgr4yz2OQW0xrBHwAAAMo"]
[Thu Jul 30 13:03:39.164650 2026] [security2:error] [pid 849392:tid 849592] [client 158.158.32.226:55315] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wiki-index.php"] [unique_id "amuR-wMgr4yz2OQW0xrBHwAAAMo"]
[Thu Jul 30 13:03:39.450920 2026] [security2:error] [pid 849392:tid 849608] [client 158.158.32.226:15637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/Bulle.php"] [unique_id "amuR-wMgr4yz2OQW0xrBJQAAANo"]
[Thu Jul 30 13:03:39.451055 2026] [security2:error] [pid 849392:tid 849608] [client 158.158.32.226:15637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/Bulle.php"] [unique_id "amuR-wMgr4yz2OQW0xrBJQAAANo"]
[Thu Jul 30 13:03:39.937293 2026] [security2:error] [pid 849392:tid 849573] [client 158.158.32.226:55349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/srx.php"] [unique_id "amuR-wMgr4yz2OQW0xrBMQAAALc"]
[Thu Jul 30 13:03:39.937407 2026] [security2:error] [pid 849392:tid 849573] [client 158.158.32.226:55349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/srx.php"] [unique_id "amuR-wMgr4yz2OQW0xrBMQAAALc"]
[Thu Jul 30 13:03:40.042283 2026] [security2:error] [pid 849392:tid 849541] [client 20.171.55.167:5217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/alfa-rex.php7"] [unique_id "amuR_AMgr4yz2OQW0xrBMgAAAJc"]
[Thu Jul 30 13:03:40.234048 2026] [security2:error] [pid 849392:tid 849644] [client 158.158.32.226:13778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-content/plugins/owfsmac/mar.php"] [unique_id "amuR_AMgr4yz2OQW0xrBPQAAAP4"]
[Thu Jul 30 13:03:40.234137 2026] [security2:error] [pid 849392:tid 849644] [client 158.158.32.226:13778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-content/plugins/owfsmac/mar.php"] [unique_id "amuR_AMgr4yz2OQW0xrBPQAAAP4"]
[Thu Jul 30 13:03:40.568083 2026] [security2:error] [pid 849392:tid 849572] [client 20.63.98.115:37812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-cron.php"] [unique_id "amuR_AMgr4yz2OQW0xrBQgAAALY"]
[Thu Jul 30 13:03:40.689852 2026] [security2:error] [pid 849392:tid 849587] [client 158.158.32.226:47516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/tersembunyi.php"] [unique_id "amuR_AMgr4yz2OQW0xrBRgAAAMU"]
[Thu Jul 30 13:03:40.689964 2026] [security2:error] [pid 849392:tid 849587] [client 158.158.32.226:47516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/tersembunyi.php"] [unique_id "amuR_AMgr4yz2OQW0xrBRgAAAMU"]
[Thu Jul 30 13:03:40.806776 2026] [core:notice] [pid 849392:tid 849495] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:40.953427 2026] [security2:error] [pid 849392:tid 849514] [remote 52.167.144.237:53757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/xmlrpc.php"] [unique_id "amuR_AMgr4yz2OQW0xrBQQAA03g"]
[Thu Jul 30 13:03:41.047444 2026] [security2:error] [pid 849392:tid 849545] [client 158.158.32.226:17832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/lab.php"] [unique_id "amuR_QMgr4yz2OQW0xrBTgAAAJs"]
[Thu Jul 30 13:03:41.047554 2026] [security2:error] [pid 849392:tid 849545] [client 158.158.32.226:17832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/lab.php"] [unique_id "amuR_QMgr4yz2OQW0xrBTgAAAJs"]
[Thu Jul 30 13:03:41.315808 2026] [security2:error] [pid 849392:tid 849565] [client 20.171.55.167:5201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/wp-login.php"] [unique_id "amuR_QMgr4yz2OQW0xrBTwAAAK8"]
[Thu Jul 30 13:03:41.428380 2026] [core:notice] [pid 849392:tid 849571] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:41.430005 2026] [security2:error] [pid 849392:tid 849571] [client 158.158.32.226:14207] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.nordeste1.com"] [uri "/1.aspx"] [unique_id "amuR_QMgr4yz2OQW0xrBWQAAALU"]
[Thu Jul 30 13:03:41.679590 2026] [core:notice] [pid 849392:tid 849560] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:41.680826 2026] [security2:error] [pid 849392:tid 849560] [client 158.158.32.226:14207] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.nordeste1.com"] [uri "/shell.aspx"] [unique_id "amuR_QMgr4yz2OQW0xrBXQAAAKo"]
[Thu Jul 30 13:03:41.863081 2026] [core:notice] [pid 849392:tid 849623] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:41.864791 2026] [security2:error] [pid 849392:tid 849623] [client 158.158.32.226:14207] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.nordeste1.com"] [uri "/a.aspx"] [unique_id "amuR_QMgr4yz2OQW0xrBZAAAAOk"]
[Thu Jul 30 13:03:42.003126 2026] [security2:error] [pid 849392:tid 849597] [client 158.158.32.226:14207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-raze.php"] [unique_id "amuR_gMgr4yz2OQW0xrBZQAAAM8"]
[Thu Jul 30 13:03:42.003249 2026] [security2:error] [pid 849392:tid 849597] [client 158.158.32.226:14207] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-raze.php"] [unique_id "amuR_gMgr4yz2OQW0xrBZQAAAM8"]
[Thu Jul 30 13:03:42.198251 2026] [security2:error] [pid 849392:tid 849531] [client 20.171.55.167:5787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/cloud.php"] [unique_id "amuR_gMgr4yz2OQW0xrBaQAAAI0"]
[Thu Jul 30 13:03:42.358150 2026] [security2:error] [pid 849392:tid 849541] [client 158.158.32.226:47510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-init.php"] [unique_id "amuR_gMgr4yz2OQW0xrBbQAAAJc"]
[Thu Jul 30 13:03:42.358298 2026] [security2:error] [pid 849392:tid 849541] [client 158.158.32.226:47510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-init.php"] [unique_id "amuR_gMgr4yz2OQW0xrBbQAAAJc"]
[Thu Jul 30 13:03:42.662619 2026] [security2:error] [pid 849392:tid 849550] [client 158.158.32.226:14152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/lyda.php"] [unique_id "amuR_gMgr4yz2OQW0xrBdAAAAKA"]
[Thu Jul 30 13:03:42.662739 2026] [security2:error] [pid 849392:tid 849550] [client 158.158.32.226:14152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/lyda.php"] [unique_id "amuR_gMgr4yz2OQW0xrBdAAAAKA"]
[Thu Jul 30 13:03:43.054222 2026] [security2:error] [pid 849392:tid 849647] [client 158.158.32.226:14157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/alfashell.php"] [unique_id "amuR_wMgr4yz2OQW0xrBfgAAAQE"]
[Thu Jul 30 13:03:43.054416 2026] [security2:error] [pid 849392:tid 849647] [client 158.158.32.226:14157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/alfashell.php"] [unique_id "amuR_wMgr4yz2OQW0xrBfgAAAQE"]
[Thu Jul 30 13:03:43.055762 2026] [security2:error] [pid 849392:tid 849636] [client 20.171.55.167:5209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/index.php"] [unique_id "amuR_wMgr4yz2OQW0xrBfwAAAPY"]
[Thu Jul 30 13:03:43.163748 2026] [security2:error] [pid 849392:tid 849530] [client 20.63.98.115:37791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/cah.php"] [unique_id "amuR_wMgr4yz2OQW0xrBgAAAAIw"]
[Thu Jul 30 13:03:43.312661 2026] [security2:error] [pid 849392:tid 849562] [client 195.245.119.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuR_wMgr4yz2OQW0xrBgwAAAKw"], referer: http://cnpinyin.com
[Thu Jul 30 13:03:43.392547 2026] [security2:error] [pid 849392:tid 849545] [client 158.158.32.226:13798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/av.php"] [unique_id "amuR_wMgr4yz2OQW0xrBjQAAAJs"]
[Thu Jul 30 13:03:43.392646 2026] [security2:error] [pid 849392:tid 849545] [client 158.158.32.226:13798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/av.php"] [unique_id "amuR_wMgr4yz2OQW0xrBjQAAAJs"]
[Thu Jul 30 13:03:43.720088 2026] [security2:error] [pid 849392:tid 849563] [client 158.158.32.226:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/upl.php"] [unique_id "amuR_wMgr4yz2OQW0xrBlAAAAK0"]
[Thu Jul 30 13:03:43.720206 2026] [security2:error] [pid 849392:tid 849563] [client 158.158.32.226:55335] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/upl.php"] [unique_id "amuR_wMgr4yz2OQW0xrBlAAAAK0"]
[Thu Jul 30 13:03:43.881663 2026] [security2:error] [pid 849392:tid 849626] [client 20.171.55.167:5214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/readme.php"] [unique_id "amuR_wMgr4yz2OQW0xrBnQAAAOw"]
[Thu Jul 30 13:03:44.059863 2026] [core:notice] [pid 849392:tid 849583] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:44.061727 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.32.226:47550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.nordeste1.com"] [uri "/login.phtml"] [unique_id "amuSAAMgr4yz2OQW0xrBoQAAAME"]
[Thu Jul 30 13:03:44.207836 2026] [security2:error] [pid 849392:tid 849614] [client 158.158.32.226:47550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/gelay.php"] [unique_id "amuSAAMgr4yz2OQW0xrBowAAAOA"]
[Thu Jul 30 13:03:44.208001 2026] [security2:error] [pid 849392:tid 849614] [client 158.158.32.226:47550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/gelay.php"] [unique_id "amuSAAMgr4yz2OQW0xrBowAAAOA"]
[Thu Jul 30 13:03:44.523193 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.32.226:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/darkshell.php"] [unique_id "amuSAAMgr4yz2OQW0xrBsQAAAPU"]
[Thu Jul 30 13:03:44.523302 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.32.226:52110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/darkshell.php"] [unique_id "amuSAAMgr4yz2OQW0xrBsQAAAPU"]
[Thu Jul 30 13:03:44.688836 2026] [security2:error] [pid 849392:tid 849615] [client 20.171.55.167:5212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/about.php"] [unique_id "amuSAAMgr4yz2OQW0xrBswAAAOE"]
[Thu Jul 30 13:03:44.799451 2026] [security2:error] [pid 849392:tid 849578] [client 158.158.32.226:15628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/gel4y.php"] [unique_id "amuSAAMgr4yz2OQW0xrBtAAAALw"]
[Thu Jul 30 13:03:44.799602 2026] [security2:error] [pid 849392:tid 849578] [client 158.158.32.226:15628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/gel4y.php"] [unique_id "amuSAAMgr4yz2OQW0xrBtAAAALw"]
[Thu Jul 30 13:03:44.906535 2026] [security2:error] [pid 849392:tid 849424] [remote 40.77.167.24:53910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/1218538192/article.php"] [unique_id "amuSAAMgr4yz2OQW0xrBsgAA0h4"]
[Thu Jul 30 13:03:45.123124 2026] [security2:error] [pid 849392:tid 849427] [remote 40.77.167.24:53910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/1377767963/article.php"] [unique_id "amuSAQMgr4yz2OQW0xrBxAAA-SE"]
[Thu Jul 30 13:03:45.128907 2026] [security2:error] [pid 849392:tid 849422] [remote 66.7.213.120:43394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.213.7.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-aa23bb9f.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuSAQMgr4yz2OQW0xrBxQAA5Rw"]
[Thu Jul 30 13:03:45.139090 2026] [security2:error] [pid 849392:tid 849587] [client 158.158.32.226:52109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/contacts.php"] [unique_id "amuSAQMgr4yz2OQW0xrBxgAAAMU"]
[Thu Jul 30 13:03:45.139212 2026] [security2:error] [pid 849392:tid 849587] [client 158.158.32.226:52109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/contacts.php"] [unique_id "amuSAQMgr4yz2OQW0xrBxgAAAMU"]
[Thu Jul 30 13:03:45.167089 2026] [security2:error] [pid 849392:tid 849611] [client 20.63.98.115:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/cong.php"] [unique_id "amuSAQMgr4yz2OQW0xrBxwAAAN0"]
[Thu Jul 30 13:03:45.423667 2026] [security2:error] [pid 849392:tid 849568] [client 158.158.32.226:15638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/yo.php"] [unique_id "amuSAQMgr4yz2OQW0xrBzAAAALI"]
[Thu Jul 30 13:03:45.423773 2026] [security2:error] [pid 849392:tid 849568] [client 158.158.32.226:15638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/yo.php"] [unique_id "amuSAQMgr4yz2OQW0xrBzAAAALI"]
[Thu Jul 30 13:03:45.590248 2026] [security2:error] [pid 849392:tid 849432] [remote 195.26.253.119:57222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuSAQMgr4yz2OQW0xrB0wAA0yY"]
[Thu Jul 30 13:03:45.655212 2026] [security2:error] [pid 849392:tid 849545] [client 20.171.55.167:5778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/themes/404.php"] [unique_id "amuSAQMgr4yz2OQW0xrB1AAAAJs"]
[Thu Jul 30 13:03:45.913396 2026] [security2:error] [pid 849392:tid 849603] [client 158.158.32.226:55326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-content/fm.php"] [unique_id "amuSAQMgr4yz2OQW0xrB3AAAANU"]
[Thu Jul 30 13:03:45.913548 2026] [security2:error] [pid 849392:tid 849603] [client 158.158.32.226:55326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-content/fm.php"] [unique_id "amuSAQMgr4yz2OQW0xrB3AAAANU"]
[Thu Jul 30 13:03:45.989521 2026] [security2:error] [pid 849392:tid 849435] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSAQMgr4yz2OQW0xrB4AAAtSk"]
[Thu Jul 30 13:03:45.989700 2026] [security2:error] [pid 849392:tid 849571] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSAQMgr4yz2OQW0xrB4AAAtSk"]
[Thu Jul 30 13:03:46.290614 2026] [security2:error] [pid 849392:tid 849609] [client 158.158.32.226:17803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-content/a.php"] [unique_id "amuSAgMgr4yz2OQW0xrB5gAAANs"]
[Thu Jul 30 13:03:46.290777 2026] [security2:error] [pid 849392:tid 849609] [client 158.158.32.226:17803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-content/a.php"] [unique_id "amuSAgMgr4yz2OQW0xrB5gAAANs"]
[Thu Jul 30 13:03:46.582459 2026] [security2:error] [pid 849392:tid 849627] [client 20.171.55.167:5204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/index.php"] [unique_id "amuSAgMgr4yz2OQW0xrB9wAAAO0"]
[Thu Jul 30 13:03:46.621971 2026] [security2:error] [pid 849392:tid 849535] [client 158.158.32.226:13820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/sym.php"] [unique_id "amuSAgMgr4yz2OQW0xrB-AAAAJE"]
[Thu Jul 30 13:03:46.622091 2026] [security2:error] [pid 849392:tid 849535] [client 158.158.32.226:13820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/sym.php"] [unique_id "amuSAgMgr4yz2OQW0xrB-AAAAJE"]
[Thu Jul 30 13:03:46.975743 2026] [security2:error] [pid 849392:tid 849624] [client 158.158.32.226:13783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/shell.php"] [unique_id "amuSAgMgr4yz2OQW0xrCAAAAAOo"]
[Thu Jul 30 13:03:46.975866 2026] [security2:error] [pid 849392:tid 849624] [client 158.158.32.226:13783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/shell.php"] [unique_id "amuSAgMgr4yz2OQW0xrCAAAAAOo"]
[Thu Jul 30 13:03:47.181812 2026] [security2:error] [pid 849392:tid 849436] [remote 65.181.116.253:54152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lld.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuSAwMgr4yz2OQW0xrCBAABASo"]
[Thu Jul 30 13:03:47.268182 2026] [security2:error] [pid 849392:tid 849530] [client 158.158.32.226:52117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/mini.php"] [unique_id "amuSAwMgr4yz2OQW0xrCCAAAAIw"]
[Thu Jul 30 13:03:47.268305 2026] [security2:error] [pid 849392:tid 849530] [client 158.158.32.226:52117] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/mini.php"] [unique_id "amuSAwMgr4yz2OQW0xrCCAAAAIw"]
[Thu Jul 30 13:03:47.621966 2026] [security2:error] [pid 849392:tid 849561] [client 20.171.55.167:5232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/themes.php"] [unique_id "amuSAwMgr4yz2OQW0xrCFQAAAKs"]
[Thu Jul 30 13:03:47.641230 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.32.226:17840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/mar.php"] [unique_id "amuSAwMgr4yz2OQW0xrCFgAAAO4"]
[Thu Jul 30 13:03:47.641352 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.32.226:17840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/mar.php"] [unique_id "amuSAwMgr4yz2OQW0xrCFgAAAO4"]
[Thu Jul 30 13:03:47.676612 2026] [security2:error] [pid 849392:tid 849460] [remote 57.141.0.38:27998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/27169508389/feed/rss2/"] [unique_id "amuSAwMgr4yz2OQW0xrCGgAAxkI"]
[Thu Jul 30 13:03:47.941762 2026] [security2:error] [pid 849392:tid 849598] [client 158.158.32.226:45897] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.nordeste1.com"] [uri "/images/1.php"] [unique_id "amuSAwMgr4yz2OQW0xrCHgAAANA"]
[Thu Jul 30 13:03:47.941912 2026] [security2:error] [pid 849392:tid 849598] [client 158.158.32.226:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/1.php"] [unique_id "amuSAwMgr4yz2OQW0xrCHgAAANA"]
[Thu Jul 30 13:03:47.942036 2026] [security2:error] [pid 849392:tid 849598] [client 158.158.32.226:45897] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/1.php"] [unique_id "amuSAwMgr4yz2OQW0xrCHgAAANA"]
[Thu Jul 30 13:03:48.244503 2026] [security2:error] [pid 849392:tid 849581] [client 158.158.32.226:52113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/imageswp-init.php"] [unique_id "amuSBAMgr4yz2OQW0xrCJwAAAL8"]
[Thu Jul 30 13:03:48.244672 2026] [security2:error] [pid 849392:tid 849581] [client 158.158.32.226:52113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/imageswp-init.php"] [unique_id "amuSBAMgr4yz2OQW0xrCJwAAAL8"]
[Thu Jul 30 13:03:48.455399 2026] [security2:error] [pid 849392:tid 849623] [client 20.63.98.115:61597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/Sanskrit.php"] [unique_id "amuSBAMgr4yz2OQW0xrCKwAAAOk"]
[Thu Jul 30 13:03:48.514513 2026] [security2:error] [pid 849392:tid 849531] [client 20.171.55.167:5230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/dropdown.php"] [unique_id "amuSBAMgr4yz2OQW0xrCLAAAAI0"]
[Thu Jul 30 13:03:48.543870 2026] [security2:error] [pid 849392:tid 849646] [client 158.158.32.226:45801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/upload.php"] [unique_id "amuSBAMgr4yz2OQW0xrCLgAAAQA"]
[Thu Jul 30 13:03:48.544011 2026] [security2:error] [pid 849392:tid 849646] [client 158.158.32.226:45801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/upload.php"] [unique_id "amuSBAMgr4yz2OQW0xrCLgAAAQA"]
[Thu Jul 30 13:03:48.807373 2026] [security2:error] [pid 849392:tid 849618] [client 43.130.91.95:38948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.91.130.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amuSBAMgr4yz2OQW0xrCNQAAAOQ"]
[Thu Jul 30 13:03:48.981358 2026] [security2:error] [pid 849392:tid 849535] [client 158.158.32.226:15654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/fox.php"] [unique_id "amuSBAMgr4yz2OQW0xrCOQAAAJE"]
[Thu Jul 30 13:03:48.981493 2026] [security2:error] [pid 849392:tid 849535] [client 158.158.32.226:15654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/fox.php"] [unique_id "amuSBAMgr4yz2OQW0xrCOQAAAJE"]
[Thu Jul 30 13:03:49.278728 2026] [security2:error] [pid 849392:tid 849631] [client 20.63.98.115:55072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ms-edit.php"] [unique_id "amuSBQMgr4yz2OQW0xrCQAAAAPE"]
[Thu Jul 30 13:03:49.304932 2026] [security2:error] [pid 849392:tid 849544] [client 158.158.32.226:55302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/fw.php"] [unique_id "amuSBQMgr4yz2OQW0xrCQQAAAJo"]
[Thu Jul 30 13:03:49.305063 2026] [security2:error] [pid 849392:tid 849544] [client 158.158.32.226:55302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/fw.php"] [unique_id "amuSBQMgr4yz2OQW0xrCQQAAAJo"]
[Thu Jul 30 13:03:49.360110 2026] [security2:error] [pid 849392:tid 849621] [client 20.171.55.167:5779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/404.php"] [unique_id "amuSBQMgr4yz2OQW0xrCQgAAAOc"]
[Thu Jul 30 13:03:49.584485 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.32.226:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/alfa.php"] [unique_id "amuSBQMgr4yz2OQW0xrCSQAAAKw"]
[Thu Jul 30 13:03:49.584593 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.32.226:55312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/alfa.php"] [unique_id "amuSBQMgr4yz2OQW0xrCSQAAAKw"]
[Thu Jul 30 13:03:49.672369 2026] [core:error] [pid 849392:tid 849523] [client 74.7.241.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:49.672396 2026] [core:error] [pid 849392:tid 849523] [client 74.7.241.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:49.672525 2026] [security2:error] [pid 849392:tid 849523] [client 74.7.241.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.nwa.zzt.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuSBQMgr4yz2OQW0xrCTAAAAIU"]
[Thu Jul 30 13:03:49.673099 2026] [security2:error] [pid 849392:tid 849640] [client 74.7.241.178:53970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.nwa.zzt.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuSBQMgr4yz2OQW0xrCSgAA-ks"]
[Thu Jul 30 13:03:49.972382 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.32.226:14144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/alfashell.php"] [unique_id "amuSBQMgr4yz2OQW0xrCUQAAAO4"]
[Thu Jul 30 13:03:49.972494 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.32.226:14144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/alfashell.php"] [unique_id "amuSBQMgr4yz2OQW0xrCUQAAAO4"]
[Thu Jul 30 13:03:50.200827 2026] [security2:error] [pid 849392:tid 849525] [client 20.171.55.167:5197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuSBgMgr4yz2OQW0xrCWgAAAIc"]
[Thu Jul 30 13:03:50.432835 2026] [security2:error] [pid 849392:tid 849607] [client 158.158.32.226:13767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/gelay.php"] [unique_id "amuSBgMgr4yz2OQW0xrCXAAAANk"]
[Thu Jul 30 13:03:50.432955 2026] [security2:error] [pid 849392:tid 849607] [client 158.158.32.226:13767] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/gelay.php"] [unique_id "amuSBgMgr4yz2OQW0xrCXAAAANk"]
[Thu Jul 30 13:03:50.936951 2026] [security2:error] [pid 849392:tid 849581] [client 158.158.32.226:15641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/byps.php"] [unique_id "amuSBgMgr4yz2OQW0xrCZgAAAL8"]
[Thu Jul 30 13:03:50.937082 2026] [security2:error] [pid 849392:tid 849581] [client 158.158.32.226:15641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/byps.php"] [unique_id "amuSBgMgr4yz2OQW0xrCZgAAAL8"]
[Thu Jul 30 13:03:51.055913 2026] [security2:error] [pid 849392:tid 849559] [client 20.171.55.167:5782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/file.php"] [unique_id "amuSBwMgr4yz2OQW0xrCawAAAKk"]
[Thu Jul 30 13:03:51.363796 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.32.226:13802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/bypass.php"] [unique_id "amuSBwMgr4yz2OQW0xrCcgAAAPU"]
[Thu Jul 30 13:03:51.363907 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.32.226:13802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/bypass.php"] [unique_id "amuSBwMgr4yz2OQW0xrCcgAAAPU"]
[Thu Jul 30 13:03:51.652233 2026] [core:error] [pid 849392:tid 849633] [client 74.7.244.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:51.652258 2026] [core:error] [pid 849392:tid 849633] [client 74.7.244.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:03:51.652389 2026] [security2:error] [pid 849392:tid 849633] [client 74.7.244.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.gfy.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuSBwMgr4yz2OQW0xrCegAAAPM"]
[Thu Jul 30 13:03:51.652985 2026] [security2:error] [pid 849392:tid 849604] [client 74.7.244.9:48256] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.gfy.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuSBwMgr4yz2OQW0xrCdgAA1k4"]
[Thu Jul 30 13:03:51.728316 2026] [security2:error] [pid 849392:tid 849540] [client 20.63.98.115:1480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/function.php"] [unique_id "amuSBwMgr4yz2OQW0xrCfwAAAJY"]
[Thu Jul 30 13:03:51.819624 2026] [security2:error] [pid 849392:tid 849532] [client 158.158.32.226:55347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/x.php"] [unique_id "amuSBwMgr4yz2OQW0xrCggAAAI4"]
[Thu Jul 30 13:03:51.819734 2026] [security2:error] [pid 849392:tid 849532] [client 158.158.32.226:55347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/x.php"] [unique_id "amuSBwMgr4yz2OQW0xrCggAAAI4"]
[Thu Jul 30 13:03:52.037923 2026] [security2:error] [pid 849392:tid 849534] [client 20.171.55.167:5206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/index.php"] [unique_id "amuSCAMgr4yz2OQW0xrChwAAAJA"]
[Thu Jul 30 13:03:52.249265 2026] [security2:error] [pid 849392:tid 849527] [client 158.158.32.226:14206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/leaf.php"] [unique_id "amuSCAMgr4yz2OQW0xrClgAAAIk"]
[Thu Jul 30 13:03:52.249365 2026] [security2:error] [pid 849392:tid 849527] [client 158.158.32.226:14206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/leaf.php"] [unique_id "amuSCAMgr4yz2OQW0xrClgAAAIk"]
[Thu Jul 30 13:03:52.599760 2026] [security2:error] [pid 849392:tid 849592] [client 158.158.32.226:47540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/wso.php"] [unique_id "amuSCAMgr4yz2OQW0xrCmAAAAMo"]
[Thu Jul 30 13:03:52.599877 2026] [security2:error] [pid 849392:tid 849592] [client 158.158.32.226:47540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/wso.php"] [unique_id "amuSCAMgr4yz2OQW0xrCmAAAAMo"]
[Thu Jul 30 13:03:52.754318 2026] [security2:error] [pid 849392:tid 849529] [client 20.63.98.115:1487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ee.php"] [unique_id "amuSCAMgr4yz2OQW0xrCnwAAAIs"]
[Thu Jul 30 13:03:52.990301 2026] [security2:error] [pid 849392:tid 849608] [client 158.158.32.226:62656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/sym403.php"] [unique_id "amuSCAMgr4yz2OQW0xrCowAAANo"]
[Thu Jul 30 13:03:52.990433 2026] [security2:error] [pid 849392:tid 849608] [client 158.158.32.226:62656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/sym403.php"] [unique_id "amuSCAMgr4yz2OQW0xrCowAAANo"]
[Thu Jul 30 13:03:53.037908 2026] [security2:error] [pid 849392:tid 849565] [client 20.171.55.167:5216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/cloud.php"] [unique_id "amuSCQMgr4yz2OQW0xrCpAAAAK8"]
[Thu Jul 30 13:03:53.290881 2026] [security2:error] [pid 849392:tid 849575] [client 158.158.32.226:47532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/leafmailer2.8.php"] [unique_id "amuSCQMgr4yz2OQW0xrCqAAAALk"]
[Thu Jul 30 13:03:53.291027 2026] [security2:error] [pid 849392:tid 849575] [client 158.158.32.226:47532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/leafmailer2.8.php"] [unique_id "amuSCQMgr4yz2OQW0xrCqAAAALk"]
[Thu Jul 30 13:03:53.574953 2026] [security2:error] [pid 849392:tid 849543] [client 158.158.32.226:17841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/images/lux.php"] [unique_id "amuSCQMgr4yz2OQW0xrCswAAAJk"]
[Thu Jul 30 13:03:53.575132 2026] [security2:error] [pid 849392:tid 849543] [client 158.158.32.226:17841] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/images/lux.php"] [unique_id "amuSCQMgr4yz2OQW0xrCswAAAJk"]
[Thu Jul 30 13:03:53.862187 2026] [security2:error] [pid 849392:tid 849606] [client 158.158.32.226:13823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/w3llstore.php"] [unique_id "amuSCQMgr4yz2OQW0xrCvQAAANg"]
[Thu Jul 30 13:03:53.862297 2026] [security2:error] [pid 849392:tid 849606] [client 158.158.32.226:13823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/w3llstore.php"] [unique_id "amuSCQMgr4yz2OQW0xrCvQAAANg"]
[Thu Jul 30 13:03:53.910842 2026] [security2:error] [pid 849392:tid 849536] [client 20.171.55.167:5220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amuSCQMgr4yz2OQW0xrCvgAAAJI"]
[Thu Jul 30 13:03:54.219160 2026] [security2:error] [pid 849392:tid 849609] [client 158.158.32.226:47515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/alfi.php"] [unique_id "amuSCgMgr4yz2OQW0xrCvwAAANs"]
[Thu Jul 30 13:03:54.219279 2026] [security2:error] [pid 849392:tid 849609] [client 158.158.32.226:47515] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/alfi.php"] [unique_id "amuSCgMgr4yz2OQW0xrCvwAAANs"]
[Thu Jul 30 13:03:54.246074 2026] [core:notice] [pid 849392:tid 849644] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:54.312158 2026] [core:notice] [pid 849392:tid 849576] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:54.562064 2026] [core:notice] [pid 849392:tid 849537] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:54.580248 2026] [security2:error] [pid 849392:tid 849572] [client 158.158.32.226:14163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/DC.php"] [unique_id "amuSCgMgr4yz2OQW0xrCzgAAALY"]
[Thu Jul 30 13:03:54.580347 2026] [security2:error] [pid 849392:tid 849572] [client 158.158.32.226:14163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/DC.php"] [unique_id "amuSCgMgr4yz2OQW0xrCzgAAALY"]
[Thu Jul 30 13:03:54.718281 2026] [security2:error] [pid 849392:tid 849647] [client 20.171.55.167:5184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/404.php"] [unique_id "amuSCgMgr4yz2OQW0xrCzwAAAQE"]
[Thu Jul 30 13:03:54.754725 2026] [security2:error] [pid 849392:tid 849631] [client 85.208.96.206:12772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/11/moraes-determina-multa-de-r-100-mil-por-hora-para-donos-de-veiculos-que-obstruirem-lugares-publicos/"] [unique_id "amuSCgMgr4yz2OQW0xrC0AAAAPE"]
[Thu Jul 30 13:03:54.754901 2026] [security2:error] [pid 849392:tid 849631] [client 85.208.96.206:12772] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/11/moraes-determina-multa-de-r-100-mil-por-hora-para-donos-de-veiculos-que-obstruirem-lugares-publicos/"] [unique_id "amuSCgMgr4yz2OQW0xrC0AAAAPE"]
[Thu Jul 30 13:03:54.951070 2026] [security2:error] [pid 849392:tid 849616] [client 158.158.32.226:13816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/DC.php"] [unique_id "amuSCgMgr4yz2OQW0xrC2wAAAOI"]
[Thu Jul 30 13:03:54.951202 2026] [security2:error] [pid 849392:tid 849616] [client 158.158.32.226:13816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/DC.php"] [unique_id "amuSCgMgr4yz2OQW0xrC2wAAAOI"]
[Thu Jul 30 13:03:55.233379 2026] [security2:error] [pid 849392:tid 849620] [client 158.158.32.226:47524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/shell.php"] [unique_id "amuSCwMgr4yz2OQW0xrC3AAAAOY"]
[Thu Jul 30 13:03:55.233493 2026] [security2:error] [pid 849392:tid 849620] [client 158.158.32.226:47524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/shell.php"] [unique_id "amuSCwMgr4yz2OQW0xrC3AAAAOY"]
[Thu Jul 30 13:03:55.543304 2026] [security2:error] [pid 849392:tid 849545] [client 20.171.55.167:5771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/function.php"] [unique_id "amuSCwMgr4yz2OQW0xrC6QAAAJs"]
[Thu Jul 30 13:03:55.543689 2026] [security2:error] [pid 849392:tid 849531] [client 158.158.32.226:14168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/fox.php"] [unique_id "amuSCwMgr4yz2OQW0xrC6gAAAI0"]
[Thu Jul 30 13:03:55.543830 2026] [security2:error] [pid 849392:tid 849531] [client 158.158.32.226:14168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/fox.php"] [unique_id "amuSCwMgr4yz2OQW0xrC6gAAAI0"]
[Thu Jul 30 13:03:55.592947 2026] [security2:error] [pid 849392:tid 849510] [remote 57.141.18.3:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSCwMgr4yz2OQW0xrC7AAA6XQ"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon,linen,polyester,cotton,denim,titanium,plastic,lycra,wood,nylon&min_price=300&orderby=price&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 13:03:55.838750 2026] [security2:error] [pid 849392:tid 849614] [client 158.158.32.226:17839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "amuSCwMgr4yz2OQW0xrC8AAAAOA"]
[Thu Jul 30 13:03:55.838869 2026] [security2:error] [pid 849392:tid 849614] [client 158.158.32.226:17839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "amuSCwMgr4yz2OQW0xrC8AAAAOA"]
[Thu Jul 30 13:03:55.858208 2026] [security2:error] [pid 849392:tid 849395] [remote 57.141.18.43:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSCwMgr4yz2OQW0xrC6wAAnAE"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon,linen,polyester,cotton,denim,titanium,plastic,lycra,wood,nylon&min_price=300&orderby=price&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 13:03:56.175688 2026] [security2:error] [pid 849392:tid 849636] [client 158.158.32.226:47531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "amuSDAMgr4yz2OQW0xrC-AAAAPY"]
[Thu Jul 30 13:03:56.175811 2026] [security2:error] [pid 849392:tid 849636] [client 158.158.32.226:47531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "amuSDAMgr4yz2OQW0xrC-AAAAPY"]
[Thu Jul 30 13:03:56.290877 2026] [security2:error] [pid 849392:tid 849544] [client 172.236.9.101:26517] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php-backup"] [unique_id "amuSDAMgr4yz2OQW0xrC-QAAAJo"]
[Thu Jul 30 13:03:56.354706 2026] [security2:error] [pid 849392:tid 849641] [client 20.63.98.115:55088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/new.php"] [unique_id "amuSDAMgr4yz2OQW0xrC_wAAAPs"]
[Thu Jul 30 13:03:56.354813 2026] [security2:error] [pid 849392:tid 849394] [remote 40.77.167.70:56899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/181976042639/humanitariaf.php"] [unique_id "amuSDAMgr4yz2OQW0xrC9wAA2AA"]
[Thu Jul 30 13:03:56.408601 2026] [core:notice] [pid 849392:tid 849618] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:56.431489 2026] [security2:error] [pid 849392:tid 849604] [client 20.171.55.167:5208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/file.php"] [unique_id "amuSDAMgr4yz2OQW0xrDAgAAANY"]
[Thu Jul 30 13:03:56.525907 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.32.226:14178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/Ninja.php"] [unique_id "amuSDAMgr4yz2OQW0xrDCQAAAOE"]
[Thu Jul 30 13:03:56.526043 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.32.226:14178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/Ninja.php"] [unique_id "amuSDAMgr4yz2OQW0xrDCQAAAOE"]
[Thu Jul 30 13:03:56.779969 2026] [security2:error] [pid 849392:tid 849408] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSDAMgr4yz2OQW0xrDDAAArA4"]
[Thu Jul 30 13:03:56.780220 2026] [security2:error] [pid 849392:tid 849562] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSDAMgr4yz2OQW0xrDDAAArA4"]
[Thu Jul 30 13:03:56.829833 2026] [security2:error] [pid 849392:tid 849572] [client 158.158.32.226:14186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-incleude.php"] [unique_id "amuSDAMgr4yz2OQW0xrDDgAAALY"]
[Thu Jul 30 13:03:56.829940 2026] [security2:error] [pid 849392:tid 849572] [client 158.158.32.226:14186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-incleude.php"] [unique_id "amuSDAMgr4yz2OQW0xrDDgAAALY"]
[Thu Jul 30 13:03:56.977036 2026] [core:notice] [pid 849392:tid 849601] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:57.174672 2026] [security2:error] [pid 849392:tid 849571] [client 158.158.32.226:15651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/fpebr.php"] [unique_id "amuSDQMgr4yz2OQW0xrDHAAAALU"]
[Thu Jul 30 13:03:57.174814 2026] [security2:error] [pid 849392:tid 849571] [client 158.158.32.226:15651] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/fpebr.php"] [unique_id "amuSDQMgr4yz2OQW0xrDHAAAALU"]
[Thu Jul 30 13:03:57.357720 2026] [security2:error] [pid 849392:tid 849560] [client 20.171.55.167:5784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/acme-challenge/autoload_classmap.php"] [unique_id "amuSDQMgr4yz2OQW0xrDHQAAAKo"]
[Thu Jul 30 13:03:57.502210 2026] [security2:error] [pid 849392:tid 849634] [client 172.237.109.114:13843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSDAMgr4yz2OQW0xrDFQAAAPQ"]
[Thu Jul 30 13:03:57.533320 2026] [security2:error] [pid 849392:tid 849616] [client 20.63.98.115:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-config.php"] [unique_id "amuSDQMgr4yz2OQW0xrDJwAAAOI"]
[Thu Jul 30 13:03:57.534915 2026] [security2:error] [pid 849392:tid 849593] [client 158.158.32.226:17821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/snd21.php"] [unique_id "amuSDQMgr4yz2OQW0xrDKAAAAMs"]
[Thu Jul 30 13:03:57.535038 2026] [security2:error] [pid 849392:tid 849593] [client 158.158.32.226:17821] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/snd21.php"] [unique_id "amuSDQMgr4yz2OQW0xrDKAAAAMs"]
[Thu Jul 30 13:03:57.554655 2026] [security2:error] [pid 849392:tid 849524] [client 172.237.109.114:47783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSDAMgr4yz2OQW0xrDFwAAAIY"]
[Thu Jul 30 13:03:57.580016 2026] [security2:error] [pid 849392:tid 849632] [client 172.237.109.114:26886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSDQMgr4yz2OQW0xrDGAAAAPI"]
[Thu Jul 30 13:03:57.851381 2026] [security2:error] [pid 849392:tid 849535] [client 158.158.32.226:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/olu.php"] [unique_id "amuSDQMgr4yz2OQW0xrDKgAAAJE"]
[Thu Jul 30 13:03:57.851536 2026] [security2:error] [pid 849392:tid 849535] [client 158.158.32.226:52108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/olu.php"] [unique_id "amuSDQMgr4yz2OQW0xrDKgAAAJE"]
[Thu Jul 30 13:03:57.927737 2026] [core:notice] [pid 849392:tid 849635] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:58.189422 2026] [security2:error] [pid 849392:tid 849639] [client 158.158.32.226:14179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/tuco.php"] [unique_id "amuSDgMgr4yz2OQW0xrDOwAAAPk"]
[Thu Jul 30 13:03:58.189549 2026] [security2:error] [pid 849392:tid 849639] [client 158.158.32.226:14179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/tuco.php"] [unique_id "amuSDgMgr4yz2OQW0xrDOwAAAPk"]
[Thu Jul 30 13:03:58.480949 2026] [security2:error] [pid 849392:tid 849550] [client 172.237.109.114:55324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSDQMgr4yz2OQW0xrDMwAAAKA"]
[Thu Jul 30 13:03:58.484988 2026] [security2:error] [pid 849392:tid 849636] [client 172.237.109.114:21326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSDQMgr4yz2OQW0xrDNAAAAPY"]
[Thu Jul 30 13:03:58.501222 2026] [security2:error] [pid 849392:tid 849633] [client 172.237.109.114:47688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSDQMgr4yz2OQW0xrDMgAAAPM"]
[Thu Jul 30 13:03:58.513120 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.32.226:15640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/ice.php"] [unique_id "amuSDgMgr4yz2OQW0xrDRQAAAKw"]
[Thu Jul 30 13:03:58.513222 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.32.226:15640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/ice.php"] [unique_id "amuSDgMgr4yz2OQW0xrDRQAAAKw"]
[Thu Jul 30 13:03:58.520081 2026] [security2:error] [pid 849392:tid 849642] [client 20.171.55.167:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/themes.php"] [unique_id "amuSDgMgr4yz2OQW0xrDRwAAAPw"]
[Thu Jul 30 13:03:58.562488 2026] [security2:error] [pid 849392:tid 849544] [client 172.237.109.114:61907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSDQMgr4yz2OQW0xrDNQAAAJo"]
[Thu Jul 30 13:03:58.584527 2026] [security2:error] [pid 849392:tid 849621] [client 172.237.109.114:47146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSDQMgr4yz2OQW0xrDNgAAAOc"]
[Thu Jul 30 13:03:58.592077 2026] [security2:error] [pid 849392:tid 849609] [client 172.237.109.114:14262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSDQMgr4yz2OQW0xrDNwAAANs"]
[Thu Jul 30 13:03:58.847891 2026] [security2:error] [pid 849392:tid 849551] [client 158.158.32.226:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/codeboy1877x.php"] [unique_id "amuSDgMgr4yz2OQW0xrDTgAAAKE"]
[Thu Jul 30 13:03:58.848064 2026] [security2:error] [pid 849392:tid 849551] [client 158.158.32.226:15646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/codeboy1877x.php"] [unique_id "amuSDgMgr4yz2OQW0xrDTgAAAKE"]
[Thu Jul 30 13:03:58.883415 2026] [security2:error] [pid 849392:tid 849644] [client 20.63.98.115:55044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-conflg.php"] [unique_id "amuSDgMgr4yz2OQW0xrDTwAAAP4"]
[Thu Jul 30 13:03:59.117553 2026] [security2:error] [pid 849392:tid 849616] [client 158.158.32.226:47515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wsanon.php"] [unique_id "amuSDwMgr4yz2OQW0xrDWgAAAOI"]
[Thu Jul 30 13:03:59.117661 2026] [security2:error] [pid 849392:tid 849616] [client 158.158.32.226:47515] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wsanon.php"] [unique_id "amuSDwMgr4yz2OQW0xrDWgAAAOI"]
[Thu Jul 30 13:03:59.348945 2026] [security2:error] [pid 849392:tid 849626] [client 20.171.55.167:5240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/wp-login.php"] [unique_id "amuSDwMgr4yz2OQW0xrDXAAAAOw"]
[Thu Jul 30 13:03:59.492473 2026] [security2:error] [pid 849392:tid 849610] [client 158.158.32.226:55340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/Alfa.php"] [unique_id "amuSDwMgr4yz2OQW0xrDYAAAANw"]
[Thu Jul 30 13:03:59.492585 2026] [security2:error] [pid 849392:tid 849610] [client 158.158.32.226:55340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/Alfa.php"] [unique_id "amuSDwMgr4yz2OQW0xrDYAAAANw"]
[Thu Jul 30 13:03:59.814791 2026] [core:notice] [pid 849392:tid 849536] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:03:59.967151 2026] [security2:error] [pid 849392:tid 849591] [client 158.158.32.226:55311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "amuSDwMgr4yz2OQW0xrDbwAAAMk"]
[Thu Jul 30 13:03:59.967261 2026] [security2:error] [pid 849392:tid 849591] [client 158.158.32.226:55311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "amuSDwMgr4yz2OQW0xrDbwAAAMk"]
[Thu Jul 30 13:04:00.389749 2026] [security2:error] [pid 849392:tid 849633] [client 20.171.55.167:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/file.php"] [unique_id "amuSEAMgr4yz2OQW0xrDfAAAAPM"]
[Thu Jul 30 13:04:00.452735 2026] [security2:error] [pid 849392:tid 849541] [client 158.158.32.226:17806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "amuSEAMgr4yz2OQW0xrDfQAAAJc"]
[Thu Jul 30 13:04:00.452869 2026] [security2:error] [pid 849392:tid 849541] [client 158.158.32.226:17806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "amuSEAMgr4yz2OQW0xrDfQAAAJc"]
[Thu Jul 30 13:04:00.842747 2026] [security2:error] [pid 849392:tid 849538] [client 158.158.32.226:13775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "amuSEAMgr4yz2OQW0xrDjgAAAJQ"]
[Thu Jul 30 13:04:00.842847 2026] [security2:error] [pid 849392:tid 849538] [client 158.158.32.226:13775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "amuSEAMgr4yz2OQW0xrDjgAAAJQ"]
[Thu Jul 30 13:04:01.132054 2026] [security2:error] [pid 849392:tid 849438] [remote 207.46.13.154:29040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/12411108298058/vloloteerf.php"] [unique_id "amuSEQMgr4yz2OQW0xrDmAAA8iw"]
[Thu Jul 30 13:04:01.165159 2026] [security2:error] [pid 849392:tid 849590] [client 158.158.32.226:47537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "amuSEQMgr4yz2OQW0xrDmQAAAMg"]
[Thu Jul 30 13:04:01.165277 2026] [security2:error] [pid 849392:tid 849590] [client 158.158.32.226:47537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "amuSEQMgr4yz2OQW0xrDmQAAAMg"]
[Thu Jul 30 13:04:01.594582 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.32.226:52155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-admin/mailer.php"] [unique_id "amuSEQMgr4yz2OQW0xrDogAAAPU"]
[Thu Jul 30 13:04:01.594715 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.32.226:52155] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-admin/mailer.php"] [unique_id "amuSEQMgr4yz2OQW0xrDogAAAPU"]
[Thu Jul 30 13:04:01.954663 2026] [security2:error] [pid 849392:tid 849611] [client 158.158.32.226:14181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-content/mailer.php"] [unique_id "amuSEQMgr4yz2OQW0xrDqQAAAN0"]
[Thu Jul 30 13:04:01.954804 2026] [security2:error] [pid 849392:tid 849611] [client 158.158.32.226:14181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-content/mailer.php"] [unique_id "amuSEQMgr4yz2OQW0xrDqQAAAN0"]
[Thu Jul 30 13:04:02.396625 2026] [security2:error] [pid 849392:tid 849567] [client 158.158.32.226:47529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/wp-includes/mailer.php"] [unique_id "amuSEgMgr4yz2OQW0xrDuAAAALE"]
[Thu Jul 30 13:04:02.396735 2026] [security2:error] [pid 849392:tid 849567] [client 158.158.32.226:47529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/wp-includes/mailer.php"] [unique_id "amuSEgMgr4yz2OQW0xrDuAAAALE"]
[Thu Jul 30 13:04:02.605871 2026] [security2:error] [pid 849392:tid 849544] [client 112.86.225.38:34952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/"] [unique_id "amuSEgMgr4yz2OQW0xrDvAAAAJo"]
[Thu Jul 30 13:04:02.606047 2026] [security2:error] [pid 849392:tid 849544] [client 112.86.225.38:34952] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/"] [unique_id "amuSEgMgr4yz2OQW0xrDvAAAAJo"]
[Thu Jul 30 13:04:02.721841 2026] [security2:error] [pid 849392:tid 849557] [client 158.158.32.226:14150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/ym.php"] [unique_id "amuSEgMgr4yz2OQW0xrDwAAAAKc"]
[Thu Jul 30 13:04:02.721942 2026] [security2:error] [pid 849392:tid 849557] [client 158.158.32.226:14150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/ym.php"] [unique_id "amuSEgMgr4yz2OQW0xrDwAAAAKc"]
[Thu Jul 30 13:04:02.845056 2026] [security2:error] [pid 849392:tid 849634] [client 20.171.55.167:5791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-trackback.php"] [unique_id "amuSEgMgr4yz2OQW0xrDxAAAAPQ"]
[Thu Jul 30 13:04:03.101330 2026] [security2:error] [pid 849392:tid 849561] [client 158.158.32.226:52106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/alfa1.php"] [unique_id "amuSEwMgr4yz2OQW0xrDyQAAAKs"]
[Thu Jul 30 13:04:03.101441 2026] [security2:error] [pid 849392:tid 849561] [client 158.158.32.226:52106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/alfa1.php"] [unique_id "amuSEwMgr4yz2OQW0xrDyQAAAKs"]
[Thu Jul 30 13:04:03.574160 2026] [security2:error] [pid 849392:tid 849632] [client 158.158.32.226:47538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/159.php"] [unique_id "amuSEwMgr4yz2OQW0xrD0gAAAPI"]
[Thu Jul 30 13:04:03.574269 2026] [security2:error] [pid 849392:tid 849632] [client 158.158.32.226:47538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/159.php"] [unique_id "amuSEwMgr4yz2OQW0xrD0gAAAPI"]
[Thu Jul 30 13:04:03.724817 2026] [security2:error] [pid 849392:tid 849615] [client 20.63.98.115:49616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuSEwMgr4yz2OQW0xrD2QAAAOE"]
[Thu Jul 30 13:04:03.762495 2026] [security2:error] [pid 849392:tid 849560] [client 20.171.55.167:5229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "amuSEwMgr4yz2OQW0xrD2wAAAKo"]
[Thu Jul 30 13:04:04.027745 2026] [security2:error] [pid 849392:tid 849530] [client 158.158.32.226:55334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nordeste1.com"] [uri "/tesla1.php"] [unique_id "amuSFAMgr4yz2OQW0xrD4QAAAIw"]
[Thu Jul 30 13:04:04.027874 2026] [security2:error] [pid 849392:tid 849530] [client 158.158.32.226:55334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.nordeste1.com"] [uri "/tesla1.php"] [unique_id "amuSFAMgr4yz2OQW0xrD4QAAAIw"]
[Thu Jul 30 13:04:04.475250 2026] [autoindex:error] [pid 849392:tid 849604] [client 150.109.10.41:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.koidomino.click
[Thu Jul 30 13:04:04.630890 2026] [security2:error] [pid 849392:tid 849571] [client 20.63.98.115:1359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuSFAMgr4yz2OQW0xrD7AAAALU"]
[Thu Jul 30 13:04:04.903889 2026] [security2:error] [pid 849392:tid 849582] [client 20.171.55.167:5223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/index.php"] [unique_id "amuSFAMgr4yz2OQW0xrD-AAAAMA"]
[Thu Jul 30 13:04:05.118308 2026] [core:notice] [pid 849392:tid 849591] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:05.728544 2026] [security2:error] [pid 849392:tid 849539] [client 172.236.9.101:59988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSFQMgr4yz2OQW0xrD_gAAAJU"]
[Thu Jul 30 13:04:05.950553 2026] [security2:error] [pid 849392:tid 849607] [client 20.171.55.167:5186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/themes.php"] [unique_id "amuSFQMgr4yz2OQW0xrEEQAAANk"]
[Thu Jul 30 13:04:06.741807 2026] [security2:error] [pid 849392:tid 849583] [client 172.236.9.101:4523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSFgMgr4yz2OQW0xrEGgAAAME"]
[Thu Jul 30 13:04:06.834618 2026] [security2:error] [pid 849392:tid 849586] [client 20.171.55.167:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/cloud.php"] [unique_id "amuSFgMgr4yz2OQW0xrEJwAAAMQ"]
[Thu Jul 30 13:04:07.444671 2026] [proxy:error] [pid 849392:tid 849558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:07.445375 2026] [proxy_http:error] [pid 849392:tid 849558] [client 98.87.102.177:1720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:07.446060 2026] [proxy:error] [pid 849392:tid 849558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:07.446110 2026] [proxy_http:error] [pid 849392:tid 849558] [client 98.87.102.177:1720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:07.474545 2026] [security2:error] [pid 849392:tid 849587] [client 20.63.98.115:36520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuSFwMgr4yz2OQW0xrEQQAAAMU"]
[Thu Jul 30 13:04:07.476291 2026] [proxy:error] [pid 849392:tid 849602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:07.476378 2026] [proxy_http:error] [pid 849392:tid 849602] [client 98.87.102.177:53322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:07.477034 2026] [proxy:error] [pid 849392:tid 849602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:07.477089 2026] [proxy_http:error] [pid 849392:tid 849602] [client 98.87.102.177:53322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:07.655905 2026] [security2:error] [pid 849392:tid 849497] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSFwMgr4yz2OQW0xrERQAAyWc"]
[Thu Jul 30 13:04:07.656076 2026] [security2:error] [pid 849392:tid 849591] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSFwMgr4yz2OQW0xrERQAAyWc"]
[Thu Jul 30 13:04:07.871134 2026] [security2:error] [pid 849392:tid 849637] [client 20.171.55.167:5215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/wp-load.php"] [unique_id "amuSFwMgr4yz2OQW0xrESgAAAPc"]
[Thu Jul 30 13:04:08.039530 2026] [security2:error] [pid 849392:tid 849561] [client 20.151.254.105:27862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuSGAMgr4yz2OQW0xrEUQAAAKs"]
[Thu Jul 30 13:04:08.039648 2026] [security2:error] [pid 849392:tid 849561] [client 20.151.254.105:27862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuSGAMgr4yz2OQW0xrEUQAAAKs"]
[Thu Jul 30 13:04:08.716001 2026] [security2:error] [pid 849392:tid 849623] [client 20.171.55.167:5189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/file.php"] [unique_id "amuSGAMgr4yz2OQW0xrEYQAAAOk"]
[Thu Jul 30 13:04:09.533670 2026] [security2:error] [pid 849392:tid 849575] [client 20.63.98.115:36503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuSGQMgr4yz2OQW0xrEegAAALk"]
[Thu Jul 30 13:04:09.692311 2026] [security2:error] [pid 849392:tid 849610] [client 20.171.55.167:5789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuSGQMgr4yz2OQW0xrEgAAAANw"]
[Thu Jul 30 13:04:09.992319 2026] [security2:error] [pid 849392:tid 849519] [remote 57.141.18.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSGQMgr4yz2OQW0xrEiQAAlH0"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,linen,lycra,plastic,polyester,silicon&rating=5&status=sale&tax_product_cat=furniture&min_price=200&max_price=300&unfilter=1
[Thu Jul 30 13:04:10.669778 2026] [security2:error] [pid 849392:tid 849616] [client 20.63.98.115:49613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/manager.php"] [unique_id "amuSGgMgr4yz2OQW0xrEmAAAAOI"]
[Thu Jul 30 13:04:10.687905 2026] [security2:error] [pid 849392:tid 849525] [client 20.171.55.167:5207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/index.php"] [unique_id "amuSGgMgr4yz2OQW0xrEmQAAAIc"]
[Thu Jul 30 13:04:10.714099 2026] [security2:error] [pid 849392:tid 849495] [remote 57.141.18.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSGgMgr4yz2OQW0xrEkwAAy2U"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,linen,lycra,plastic,polyester,silicon&rating=5&status=sale&tax_product_cat=furniture&min_price=200&max_price=300&unfilter=1
[Thu Jul 30 13:04:11.336106 2026] [security2:error] [pid 849392:tid 849553] [client 216.244.66.242:45302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingstarenterprises.com"] [uri "/vcybyb/john-swift-portsmouth"] [unique_id "amuSGwMgr4yz2OQW0xrEpgAAAKM"]
[Thu Jul 30 13:04:11.336243 2026] [security2:error] [pid 849392:tid 849553] [client 216.244.66.242:45302] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kingstarenterprises.com"] [uri "/vcybyb/john-swift-portsmouth"] [unique_id "amuSGwMgr4yz2OQW0xrEpgAAAKM"]
[Thu Jul 30 13:04:11.631081 2026] [security2:error] [pid 849392:tid 849543] [client 20.171.55.167:5221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuSGwMgr4yz2OQW0xrEtgAAAJk"]
[Thu Jul 30 13:04:11.740942 2026] [security2:error] [pid 849392:tid 849555] [client 178.20.47.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuSGwMgr4yz2OQW0xrEtQAAAKU"], referer: http://cnpinyin.com/experience/chinese-customs/the+famous+dragon+dance
[Thu Jul 30 13:04:11.843046 2026] [security2:error] [pid 849392:tid 849526] [client 57.141.0.44:28604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuSGQMgr4yz2OQW0xrEggAAiGk"]
[Thu Jul 30 13:04:12.603312 2026] [security2:error] [pid 849392:tid 849632] [client 20.171.55.167:5241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/404.php"] [unique_id "amuSHAMgr4yz2OQW0xrE1gAAAPI"]
[Thu Jul 30 13:04:12.885606 2026] [security2:error] [pid 849392:tid 849424] [remote 74.7.241.60:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/article.php"] [unique_id "amuSHAMgr4yz2OQW0xrE5AAAsx4"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:04:12.892501 2026] [autoindex:error] [pid 849392:tid 849570] [client 43.155.188.157:53044] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:13.256074 2026] [security2:error] [pid 849392:tid 849566] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSHAMgr4yz2OQW0xrE2gAAALA"]
[Thu Jul 30 13:04:13.381126 2026] [security2:error] [pid 849392:tid 849609] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuSHAMgr4yz2OQW0xrE3wAA2xI"]
[Thu Jul 30 13:04:13.525086 2026] [security2:error] [pid 849392:tid 849604] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSHAMgr4yz2OQW0xrE5wAAANY"]
[Thu Jul 30 13:04:13.674509 2026] [security2:error] [pid 849392:tid 849601] [client 20.171.55.167:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "amuSHQMgr4yz2OQW0xrE-QAAANM"]
[Thu Jul 30 13:04:14.465067 2026] [security2:error] [pid 849392:tid 849550] [client 20.63.98.115:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-links.php"] [unique_id "amuSHgMgr4yz2OQW0xrFEwAAAKA"]
[Thu Jul 30 13:04:14.563331 2026] [security2:error] [pid 849392:tid 849619] [client 20.171.55.167:5820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/radio.php"] [unique_id "amuSHgMgr4yz2OQW0xrFFgAAAOU"]
[Thu Jul 30 13:04:15.424148 2026] [security2:error] [pid 849392:tid 849452] [remote 57.141.18.3:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSHwMgr4yz2OQW0xrFMgAA4jo"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,polyester,cotton,denim,aluminum,nylon,wood,lycra&orderby=date&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 13:04:15.497403 2026] [security2:error] [pid 849392:tid 849647] [client 20.171.55.167:5213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/themes/index.php"] [unique_id "amuSHwMgr4yz2OQW0xrFMwAAAQE"]
[Thu Jul 30 13:04:15.781151 2026] [security2:error] [pid 849392:tid 849467] [remote 57.141.18.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSHwMgr4yz2OQW0xrFNAAAz0k"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,polyester,cotton,denim,aluminum,nylon,wood,lycra&orderby=date&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 13:04:16.172010 2026] [security2:error] [pid 849392:tid 849548] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSHwMgr4yz2OQW0xrFNwAAAJ4"]
[Thu Jul 30 13:04:16.547889 2026] [security2:error] [pid 849392:tid 849624] [client 20.171.55.167:5237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/admin.php"] [unique_id "amuSIAMgr4yz2OQW0xrFVQAAAOo"]
[Thu Jul 30 13:04:16.743446 2026] [security2:error] [pid 849392:tid 849571] [client 172.236.9.101:17540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSIAMgr4yz2OQW0xrFSgAAALU"]
[Thu Jul 30 13:04:17.464043 2026] [security2:error] [pid 849392:tid 849602] [client 20.171.55.167:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/system_log.php"] [unique_id "amuSIQMgr4yz2OQW0xrFbgAAANQ"]
[Thu Jul 30 13:04:17.467410 2026] [security2:error] [pid 849392:tid 849477] [remote 57.141.18.74:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSIQMgr4yz2OQW0xrFZwAAmlM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=wood,aluminum,steel,linen,plastic,cotton,polyester&filter_size=large,extra-extra-large,extra-large&orderby=rating&status=instock&tax_product_cat=suit&unfilter=1
[Thu Jul 30 13:04:17.591405 2026] [security2:error] [pid 849392:tid 849476] [remote 57.141.18.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSIQMgr4yz2OQW0xrFbwAArVI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=wood,aluminum,steel,linen,plastic,cotton,polyester&filter_size=large,extra-extra-large,extra-large&orderby=rating&status=instock&tax_product_cat=suit&unfilter=1
[Thu Jul 30 13:04:18.260808 2026] [security2:error] [pid 849392:tid 849548] [client 138.246.253.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blsspainvisacenterpakistan.site"] [uri "/index.php"] [unique_id "amuSIgMgr4yz2OQW0xrFeQAAnkw"]
[Thu Jul 30 13:04:18.340998 2026] [security2:error] [pid 849392:tid 849619] [client 20.171.55.167:5222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/wp-activate.php"] [unique_id "amuSIgMgr4yz2OQW0xrFhAAAAOU"]
[Thu Jul 30 13:04:18.375918 2026] [security2:error] [pid 849392:tid 849483] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSIgMgr4yz2OQW0xrFhQAA7Fk"]
[Thu Jul 30 13:04:18.376155 2026] [security2:error] [pid 849392:tid 849626] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSIgMgr4yz2OQW0xrFhQAA7Fk"]
[Thu Jul 30 13:04:18.510929 2026] [security2:error] [pid 849392:tid 849560] [client 20.52.125.110:12783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/json.php"] [unique_id "amuSIgMgr4yz2OQW0xrFiQAAAKo"]
[Thu Jul 30 13:04:19.240064 2026] [security2:error] [pid 849392:tid 849642] [client 20.52.125.110:12558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/mini.php"] [unique_id "amuSIwMgr4yz2OQW0xrFlwAAAPw"]
[Thu Jul 30 13:04:19.270331 2026] [security2:error] [pid 849392:tid 849500] [remote 57.141.0.55:28410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuSIwMgr4yz2OQW0xrFmAAA4mo"]
[Thu Jul 30 13:04:19.415880 2026] [security2:error] [pid 849392:tid 849557] [client 20.171.55.167:5233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/makeasmtp.php"] [unique_id "amuSIwMgr4yz2OQW0xrFnwAAAKc"]
[Thu Jul 30 13:04:19.746160 2026] [security2:error] [pid 849392:tid 849544] [client 20.52.125.110:12560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/chosen.php"] [unique_id "amuSIwMgr4yz2OQW0xrFqQAAAJo"]
[Thu Jul 30 13:04:19.983324 2026] [autoindex:error] [pid 849392:tid 849619] [client 85.204.70.102:57464] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:19.984019 2026] [security2:error] [pid 849392:tid 849619] [client 85.204.70.102:57464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSIwMgr4yz2OQW0xrFtgAAAOU"]
[Thu Jul 30 13:04:20.134500 2026] [autoindex:error] [pid 849392:tid 849562] [client 85.204.70.102:57464] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:20.135510 2026] [security2:error] [pid 849392:tid 849562] [client 85.204.70.102:57464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJAMgr4yz2OQW0xrFuAAAAKw"]
[Thu Jul 30 13:04:20.223663 2026] [core:notice] [pid 849392:tid 849588] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:20.230746 2026] [security2:error] [pid 849392:tid 849615] [client 123.139.191.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuSIwMgr4yz2OQW0xrFogAAAOE"], referer: https://smoke-tfhk.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fsmoke-tfhk.com%2Fproduct%2Fark-royal-pipe-flavour%2F
[Thu Jul 30 13:04:20.277575 2026] [autoindex:error] [pid 849392:tid 849578] [client 85.204.70.102:57464] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:20.278260 2026] [security2:error] [pid 849392:tid 849578] [client 85.204.70.102:57464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJAMgr4yz2OQW0xrFvgAAALw"]
[Thu Jul 30 13:04:20.299992 2026] [security2:error] [pid 849392:tid 849572] [client 20.171.55.167:6089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/user/index.php"] [unique_id "amuSJAMgr4yz2OQW0xrFwQAAALY"]
[Thu Jul 30 13:04:20.303797 2026] [security2:error] [pid 849392:tid 849524] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSIwMgr4yz2OQW0xrFqAAAAIY"]
[Thu Jul 30 13:04:20.431800 2026] [autoindex:error] [pid 849392:tid 849579] [client 85.204.70.102:57464] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:20.432503 2026] [security2:error] [pid 849392:tid 849579] [client 85.204.70.102:57464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJAMgr4yz2OQW0xrFyAAAAL0"]
[Thu Jul 30 13:04:20.453651 2026] [security2:error] [pid 849392:tid 849598] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSIwMgr4yz2OQW0xrFrgAAANA"]
[Thu Jul 30 13:04:20.574938 2026] [autoindex:error] [pid 849392:tid 849595] [client 85.204.70.102:57464] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:20.575640 2026] [security2:error] [pid 849392:tid 849595] [client 85.204.70.102:57464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJAMgr4yz2OQW0xrFygAAAM0"]
[Thu Jul 30 13:04:20.697751 2026] [security2:error] [pid 849392:tid 849551] [client 20.52.125.110:12767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/kj.php"] [unique_id "amuSJAMgr4yz2OQW0xrFzgAAAKE"]
[Thu Jul 30 13:04:20.729781 2026] [autoindex:error] [pid 849392:tid 849642] [client 85.204.70.102:57464] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:20.730772 2026] [security2:error] [pid 849392:tid 849642] [client 85.204.70.102:57464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJAMgr4yz2OQW0xrFzwAAAPw"]
[Thu Jul 30 13:04:20.785297 2026] [security2:error] [pid 849392:tid 849596] [client 172.236.9.101:58610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSJAMgr4yz2OQW0xrFvwAAAM4"]
[Thu Jul 30 13:04:20.875657 2026] [autoindex:error] [pid 849392:tid 849532] [client 85.204.70.102:57464] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:20.876351 2026] [security2:error] [pid 849392:tid 849532] [client 85.204.70.102:57464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJAMgr4yz2OQW0xrF0AAAAI4"]
[Thu Jul 30 13:04:20.905241 2026] [security2:error] [pid 849392:tid 849603] [client 172.236.9.101:7305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSJAMgr4yz2OQW0xrFwAAAANU"]
[Thu Jul 30 13:04:21.021573 2026] [autoindex:error] [pid 849392:tid 849617] [client 85.204.70.102:57464] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:21.022198 2026] [security2:error] [pid 849392:tid 849617] [client 85.204.70.102:57464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJQMgr4yz2OQW0xrF1wAAAOM"]
[Thu Jul 30 13:04:21.044531 2026] [autoindex:error] [pid 849392:tid 849623] [client 107.189.10.175:0] AH01276: Cannot serve directory /home2/mbmudite/ok.koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:21.154609 2026] [core:error] [pid 849392:tid 849600] [client 85.204.70.102:57464] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:21.154633 2026] [core:error] [pid 849392:tid 849600] [client 85.204.70.102:57464] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:21.154750 2026] [security2:error] [pid 849392:tid 849600] [client 85.204.70.102:57464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSJQMgr4yz2OQW0xrF4AAAANI"]
[Thu Jul 30 13:04:21.360942 2026] [security2:error] [pid 849392:tid 849614] [client 20.171.55.167:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/link.php"] [unique_id "amuSJQMgr4yz2OQW0xrF4gAAAOA"]
[Thu Jul 30 13:04:21.430477 2026] [core:error] [pid 849392:tid 849633] [client 85.204.70.102:57480] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:21.430520 2026] [core:error] [pid 849392:tid 849633] [client 85.204.70.102:57480] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:21.430700 2026] [security2:error] [pid 849392:tid 849633] [client 85.204.70.102:57480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSJQMgr4yz2OQW0xrF5gAAAPM"]
[Thu Jul 30 13:04:21.691588 2026] [core:error] [pid 849392:tid 849611] [client 85.204.70.102:57496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:21.691611 2026] [core:error] [pid 849392:tid 849611] [client 85.204.70.102:57496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:21.691712 2026] [security2:error] [pid 849392:tid 849611] [client 85.204.70.102:57496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSJQMgr4yz2OQW0xrF7QAAAN0"]
[Thu Jul 30 13:04:21.935171 2026] [security2:error] [pid 849392:tid 849563] [client 20.52.125.110:12797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/wp-files.php"] [unique_id "amuSJQMgr4yz2OQW0xrF9QAAAK0"]
[Thu Jul 30 13:04:22.007223 2026] [autoindex:error] [pid 849392:tid 849559] [client 85.204.70.102:57506] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:22.007884 2026] [security2:error] [pid 849392:tid 849559] [client 85.204.70.102:57506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJQMgr4yz2OQW0xrF-AAAAKk"]
[Thu Jul 30 13:04:22.165477 2026] [security2:error] [pid 849392:tid 849526] [client 20.171.55.167:5761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuSJgMgr4yz2OQW0xrF-wAAAIg"]
[Thu Jul 30 13:04:22.172302 2026] [autoindex:error] [pid 849392:tid 849616] [client 85.204.70.102:57506] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:22.172962 2026] [security2:error] [pid 849392:tid 849616] [client 85.204.70.102:57506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJgMgr4yz2OQW0xrF-gAAAOI"]
[Thu Jul 30 13:04:22.478218 2026] [security2:error] [pid 849392:tid 849607] [client 20.52.125.110:12763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/wp-setup.php"] [unique_id "amuSJgMgr4yz2OQW0xrGDAAAANk"]
[Thu Jul 30 13:04:22.505929 2026] [core:notice] [pid 849392:tid 849521] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:22.855753 2026] [security2:error] [pid 849392:tid 849535] [client 85.204.70.102:57506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-includes/blocks/index.php"] [unique_id "amuSJgMgr4yz2OQW0xrGBQAAAJE"]
[Thu Jul 30 13:04:22.950919 2026] [security2:error] [pid 849392:tid 849639] [client 20.52.125.110:12753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/defaults.php"] [unique_id "amuSJgMgr4yz2OQW0xrGFgAAAPk"]
[Thu Jul 30 13:04:23.018492 2026] [autoindex:error] [pid 849392:tid 849523] [client 85.204.70.102:57506] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:23.019143 2026] [security2:error] [pid 849392:tid 849523] [client 85.204.70.102:57506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJwMgr4yz2OQW0xrGGgAAAIU"]
[Thu Jul 30 13:04:23.061630 2026] [security2:error] [pid 849392:tid 849618] [client 20.171.55.167:5234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/themes.php"] [unique_id "amuSJwMgr4yz2OQW0xrGIAAAAOQ"]
[Thu Jul 30 13:04:23.182248 2026] [autoindex:error] [pid 849392:tid 849610] [client 85.204.70.102:57506] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:23.182961 2026] [security2:error] [pid 849392:tid 849610] [client 85.204.70.102:57506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJwMgr4yz2OQW0xrGIQAAANw"]
[Thu Jul 30 13:04:23.345644 2026] [autoindex:error] [pid 849392:tid 849580] [client 85.204.70.102:57506] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:23.346302 2026] [security2:error] [pid 849392:tid 849580] [client 85.204.70.102:57506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJwMgr4yz2OQW0xrGJQAAAL4"]
[Thu Jul 30 13:04:23.510322 2026] [autoindex:error] [pid 849392:tid 849566] [client 85.204.70.102:57506] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:23.510939 2026] [security2:error] [pid 849392:tid 849566] [client 85.204.70.102:57506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJwMgr4yz2OQW0xrGKQAAALA"]
[Thu Jul 30 13:04:23.621058 2026] [security2:error] [pid 849392:tid 849572] [client 20.52.125.110:12754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/gtc.php"] [unique_id "amuSJwMgr4yz2OQW0xrGLQAAALY"]
[Thu Jul 30 13:04:23.677971 2026] [autoindex:error] [pid 849392:tid 849636] [client 85.204.70.102:57506] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:23.678860 2026] [security2:error] [pid 849392:tid 849636] [client 85.204.70.102:57506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSJwMgr4yz2OQW0xrGLwAAAPY"]
[Thu Jul 30 13:04:23.829335 2026] [core:error] [pid 849392:tid 849616] [client 85.204.70.102:57506] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:23.829376 2026] [core:error] [pid 849392:tid 849616] [client 85.204.70.102:57506] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:23.829480 2026] [security2:error] [pid 849392:tid 849616] [client 85.204.70.102:57506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSJwMgr4yz2OQW0xrGMwAAAOI"]
[Thu Jul 30 13:04:23.934326 2026] [security2:error] [pid 849392:tid 849564] [client 20.171.55.167:5786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/themes/admin.php"] [unique_id "amuSJwMgr4yz2OQW0xrGNQAAAK4"]
[Thu Jul 30 13:04:24.203296 2026] [core:error] [pid 849392:tid 849536] [client 85.204.70.102:45498] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:24.203324 2026] [core:error] [pid 849392:tid 849536] [client 85.204.70.102:45498] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:24.203454 2026] [security2:error] [pid 849392:tid 849536] [client 85.204.70.102:45498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKAMgr4yz2OQW0xrGRAAAAJI"]
[Thu Jul 30 13:04:24.265283 2026] [security2:error] [pid 849392:tid 849628] [client 20.52.125.110:12799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/import.php"] [unique_id "amuSKAMgr4yz2OQW0xrGSAAAAO4"]
[Thu Jul 30 13:04:24.521299 2026] [autoindex:error] [pid 849392:tid 849544] [client 85.204.70.102:45502] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:24.522198 2026] [security2:error] [pid 849392:tid 849544] [client 85.204.70.102:45502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSKAMgr4yz2OQW0xrGTAAAAJo"]
[Thu Jul 30 13:04:24.842447 2026] [security2:error] [pid 849392:tid 849523] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuSKAMgr4yz2OQW0xrGVgAAAIU"]
[Thu Jul 30 13:04:24.859109 2026] [security2:error] [pid 849392:tid 849600] [client 20.171.55.167:5239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuSKAMgr4yz2OQW0xrGWwAAANI"]
[Thu Jul 30 13:04:24.934332 2026] [security2:error] [pid 849392:tid 849568] [client 20.63.98.115:36543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/fi2.php"] [unique_id "amuSKAMgr4yz2OQW0xrGXQAAALI"]
[Thu Jul 30 13:04:24.999246 2026] [cgid:error] [pid 849392:tid 849583] [client 85.204.70.102:45502] AH01265: stderr from /home1/muuudite/public_html/website_45622194/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 13:04:24.999874 2026] [security2:error] [pid 849392:tid 849583] [client 85.204.70.102:45502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSKAMgr4yz2OQW0xrGXgAAAME"]
[Thu Jul 30 13:04:25.119522 2026] [security2:error] [pid 849392:tid 849587] [client 20.52.125.110:12798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/lufix.php"] [unique_id "amuSKQMgr4yz2OQW0xrGbQAAAMU"]
[Thu Jul 30 13:04:25.151884 2026] [core:error] [pid 849392:tid 849636] [client 85.204.70.102:45502] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:25.151919 2026] [core:error] [pid 849392:tid 849636] [client 85.204.70.102:45502] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:25.152071 2026] [security2:error] [pid 849392:tid 849636] [client 85.204.70.102:45502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGcgAAAPY"]
[Thu Jul 30 13:04:25.226903 2026] [core:notice] [pid 849392:tid 849566] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:25.414774 2026] [core:error] [pid 849392:tid 849617] [client 85.204.70.102:45514] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:25.414808 2026] [core:error] [pid 849392:tid 849617] [client 85.204.70.102:45514] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:25.414992 2026] [security2:error] [pid 849392:tid 849617] [client 85.204.70.102:45514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGfgAAAOM"]
[Thu Jul 30 13:04:25.679569 2026] [security2:error] [pid 849392:tid 849645] [client 20.52.125.110:12777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/Geforce.php"] [unique_id "amuSKQMgr4yz2OQW0xrGiAAAAP8"]
[Thu Jul 30 13:04:25.711568 2026] [core:error] [pid 849392:tid 849555] [client 85.204.70.102:45520] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:25.711592 2026] [core:error] [pid 849392:tid 849555] [client 85.204.70.102:45520] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:25.711694 2026] [security2:error] [pid 849392:tid 849555] [client 85.204.70.102:45520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGjAAAAKU"]
[Thu Jul 30 13:04:25.801952 2026] [security2:error] [pid 849392:tid 849569] [client 20.171.55.167:5226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/function.php"] [unique_id "amuSKQMgr4yz2OQW0xrGjgAAALM"]
[Thu Jul 30 13:04:25.922056 2026] [security2:error] [pid 849392:tid 849525] [client 20.63.98.115:62888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/0x.php"] [unique_id "amuSKQMgr4yz2OQW0xrGkQAAAIc"]
[Thu Jul 30 13:04:25.976725 2026] [core:error] [pid 849392:tid 849621] [client 85.204.70.102:45528] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:25.976746 2026] [core:error] [pid 849392:tid 849621] [client 85.204.70.102:45528] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:25.976839 2026] [security2:error] [pid 849392:tid 849621] [client 85.204.70.102:45528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGkgAAAOc"]
[Thu Jul 30 13:04:26.230187 2026] [core:error] [pid 849392:tid 849587] [client 85.204.70.102:45544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:26.230219 2026] [core:error] [pid 849392:tid 849587] [client 85.204.70.102:45544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:26.230457 2026] [security2:error] [pid 849392:tid 849587] [client 85.204.70.102:45544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKgMgr4yz2OQW0xrGnQAAAMU"]
[Thu Jul 30 13:04:26.391778 2026] [security2:error] [pid 849392:tid 849624] [client 172.237.109.114:23914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGYgAAAOo"]
[Thu Jul 30 13:04:26.403760 2026] [security2:error] [pid 849392:tid 849597] [client 172.237.109.114:21193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGYwAAAM8"]
[Thu Jul 30 13:04:26.481891 2026] [security2:error] [pid 849392:tid 849644] [client 172.237.109.114:28674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGZQAAAP4"]
[Thu Jul 30 13:04:26.483509 2026] [security2:error] [pid 849392:tid 849615] [client 172.237.109.114:5955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGZAAAAOE"]
[Thu Jul 30 13:04:26.493704 2026] [core:error] [pid 849392:tid 849606] [client 85.204.70.102:45558] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:26.493744 2026] [core:error] [pid 849392:tid 849606] [client 85.204.70.102:45558] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:26.493928 2026] [security2:error] [pid 849392:tid 849606] [client 85.204.70.102:45558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKgMgr4yz2OQW0xrGoQAAANg"]
[Thu Jul 30 13:04:26.494400 2026] [security2:error] [pid 849392:tid 849604] [client 172.237.109.114:27083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGZgAAANY"]
[Thu Jul 30 13:04:26.512805 2026] [security2:error] [pid 849392:tid 849580] [client 172.237.109.114:5688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGbwAAAL4"]
[Thu Jul 30 13:04:26.527615 2026] [security2:error] [pid 849392:tid 849534] [client 172.237.109.114:20455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGZwAAAJA"]
[Thu Jul 30 13:04:26.527780 2026] [security2:error] [pid 849392:tid 849571] [client 172.237.109.114:49859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGaQAAALU"]
[Thu Jul 30 13:04:26.537291 2026] [security2:error] [pid 849392:tid 849537] [client 172.237.109.114:13099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGcAAAAJM"]
[Thu Jul 30 13:04:26.548141 2026] [security2:error] [pid 849392:tid 849611] [client 172.237.109.114:1222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGcQAAAN0"]
[Thu Jul 30 13:04:26.550098 2026] [security2:error] [pid 849392:tid 849524] [client 172.237.109.114:51027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGbgAAAIY"]
[Thu Jul 30 13:04:26.564596 2026] [security2:error] [pid 849392:tid 849642] [client 20.52.125.110:12745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/a4.php"] [unique_id "amuSKgMgr4yz2OQW0xrGogAAAPw"]
[Thu Jul 30 13:04:26.567041 2026] [security2:error] [pid 849392:tid 849567] [client 172.237.109.114:1067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGcwAAALE"]
[Thu Jul 30 13:04:26.567521 2026] [security2:error] [pid 849392:tid 849565] [client 172.237.109.114:20237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGdgAAAK8"]
[Thu Jul 30 13:04:26.570547 2026] [security2:error] [pid 849392:tid 849613] [client 172.237.109.114:48992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGdAAAAN8"]
[Thu Jul 30 13:04:26.585937 2026] [security2:error] [pid 849392:tid 849575] [client 172.237.109.114:4683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGaAAAALk"]
[Thu Jul 30 13:04:26.592772 2026] [security2:error] [pid 849392:tid 849631] [client 172.237.109.114:4316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKQMgr4yz2OQW0xrGdQAAAPE"]
[Thu Jul 30 13:04:26.685986 2026] [security2:error] [pid 849392:tid 849532] [client 20.171.55.167:5762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/images/wp-login.php"] [unique_id "amuSKgMgr4yz2OQW0xrGqAAAAI4"]
[Thu Jul 30 13:04:26.729449 2026] [security2:error] [pid 849392:tid 849528] [client 20.63.98.115:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/k.php"] [unique_id "amuSKgMgr4yz2OQW0xrGqgAAAIo"]
[Thu Jul 30 13:04:26.750949 2026] [core:error] [pid 849392:tid 849590] [client 85.204.70.102:45562] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:26.750972 2026] [core:error] [pid 849392:tid 849590] [client 85.204.70.102:45562] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:26.751083 2026] [security2:error] [pid 849392:tid 849590] [client 85.204.70.102:45562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKgMgr4yz2OQW0xrGqwAAAMg"]
[Thu Jul 30 13:04:27.009096 2026] [core:error] [pid 849392:tid 849620] [client 85.204.70.102:45572] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:27.009119 2026] [core:error] [pid 849392:tid 849620] [client 85.204.70.102:45572] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:27.009207 2026] [security2:error] [pid 849392:tid 849620] [client 85.204.70.102:45572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKwMgr4yz2OQW0xrGtgAAAOY"]
[Thu Jul 30 13:04:27.278193 2026] [core:error] [pid 849392:tid 849561] [client 85.204.70.102:45576] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:27.278223 2026] [core:error] [pid 849392:tid 849561] [client 85.204.70.102:45576] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:27.278346 2026] [security2:error] [pid 849392:tid 849561] [client 85.204.70.102:45576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKwMgr4yz2OQW0xrGwAAAAKs"]
[Thu Jul 30 13:04:27.439336 2026] [security2:error] [pid 849392:tid 849605] [client 172.237.109.114:49047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKgMgr4yz2OQW0xrGlAAAANc"]
[Thu Jul 30 13:04:27.466059 2026] [security2:error] [pid 849392:tid 849622] [client 172.237.109.114:48888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKgMgr4yz2OQW0xrGlQAAAOg"]
[Thu Jul 30 13:04:27.466059 2026] [security2:error] [pid 849392:tid 849633] [client 172.237.109.114:6727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKgMgr4yz2OQW0xrGlgAAAPM"]
[Thu Jul 30 13:04:27.489316 2026] [security2:error] [pid 849392:tid 849614] [client 172.237.109.114:10116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSKgMgr4yz2OQW0xrGkwAAAOA"]
[Thu Jul 30 13:04:27.576154 2026] [core:error] [pid 849392:tid 849567] [client 85.204.70.102:45586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:27.576177 2026] [core:error] [pid 849392:tid 849567] [client 85.204.70.102:45586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:27.576308 2026] [security2:error] [pid 849392:tid 849567] [client 85.204.70.102:45586] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKwMgr4yz2OQW0xrGxAAAALE"]
[Thu Jul 30 13:04:27.671058 2026] [security2:error] [pid 849392:tid 849615] [client 20.171.55.167:5796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/log.php"] [unique_id "amuSKwMgr4yz2OQW0xrGyAAAAOE"]
[Thu Jul 30 13:04:27.709612 2026] [security2:error] [pid 849392:tid 849564] [client 20.63.98.115:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/gecko-new.php"] [unique_id "amuSKwMgr4yz2OQW0xrGygAAAK4"]
[Thu Jul 30 13:04:27.833158 2026] [security2:error] [pid 849392:tid 849578] [client 20.52.125.110:12568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/accueil.php"] [unique_id "amuSKwMgr4yz2OQW0xrGywAAALw"]
[Thu Jul 30 13:04:27.842178 2026] [core:error] [pid 849392:tid 849536] [client 85.204.70.102:45592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:27.842201 2026] [core:error] [pid 849392:tid 849536] [client 85.204.70.102:45592] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:27.842375 2026] [security2:error] [pid 849392:tid 849536] [client 85.204.70.102:45592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSKwMgr4yz2OQW0xrGzAAAAJI"]
[Thu Jul 30 13:04:28.091544 2026] [core:error] [pid 849392:tid 849640] [client 85.204.70.102:45608] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:28.091567 2026] [core:error] [pid 849392:tid 849640] [client 85.204.70.102:45608] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:28.091667 2026] [security2:error] [pid 849392:tid 849640] [client 85.204.70.102:45608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLAMgr4yz2OQW0xrG0wAAAPo"]
[Thu Jul 30 13:04:28.352070 2026] [core:error] [pid 849392:tid 849621] [client 85.204.70.102:45620] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:28.352091 2026] [core:error] [pid 849392:tid 849621] [client 85.204.70.102:45620] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:28.352193 2026] [security2:error] [pid 849392:tid 849621] [client 85.204.70.102:45620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLAMgr4yz2OQW0xrG3gAAAOc"]
[Thu Jul 30 13:04:28.557541 2026] [security2:error] [pid 849392:tid 849574] [client 20.171.55.167:5815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/wp-signup.php"] [unique_id "amuSLAMgr4yz2OQW0xrG5QAAALg"]
[Thu Jul 30 13:04:28.649916 2026] [core:error] [pid 849392:tid 849584] [client 85.204.70.102:45632] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:28.649939 2026] [core:error] [pid 849392:tid 849584] [client 85.204.70.102:45632] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:28.650051 2026] [security2:error] [pid 849392:tid 849584] [client 85.204.70.102:45632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLAMgr4yz2OQW0xrG5wAAAMI"]
[Thu Jul 30 13:04:28.714512 2026] [security2:error] [pid 849392:tid 849630] [client 20.63.98.115:49648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/alfanew.php"] [unique_id "amuSLAMgr4yz2OQW0xrG6gAAAPA"]
[Thu Jul 30 13:04:28.901139 2026] [core:error] [pid 849392:tid 849595] [client 85.204.70.102:45638] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:28.901166 2026] [core:error] [pid 849392:tid 849595] [client 85.204.70.102:45638] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:28.901319 2026] [security2:error] [pid 849392:tid 849595] [client 85.204.70.102:45638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLAMgr4yz2OQW0xrG7wAAAM0"]
[Thu Jul 30 13:04:29.173375 2026] [core:error] [pid 849392:tid 849534] [client 85.204.70.102:45642] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:29.173406 2026] [core:error] [pid 849392:tid 849534] [client 85.204.70.102:45642] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:29.173541 2026] [security2:error] [pid 849392:tid 849534] [client 85.204.70.102:45642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLQMgr4yz2OQW0xrG8AAAAJA"]
[Thu Jul 30 13:04:29.262731 2026] [security2:error] [pid 849392:tid 849471] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSLQMgr4yz2OQW0xrG8QAAvk0"]
[Thu Jul 30 13:04:29.262896 2026] [security2:error] [pid 849392:tid 849580] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSLQMgr4yz2OQW0xrG8QAAvk0"]
[Thu Jul 30 13:04:29.424511 2026] [core:error] [pid 849392:tid 849631] [client 85.204.70.102:45652] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:29.424544 2026] [core:error] [pid 849392:tid 849631] [client 85.204.70.102:45652] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:29.424707 2026] [security2:error] [pid 849392:tid 849631] [client 85.204.70.102:45652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLQMgr4yz2OQW0xrG9QAAAPE"]
[Thu Jul 30 13:04:29.448103 2026] [security2:error] [pid 849392:tid 849524] [client 20.52.125.110:12564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/dashboard.php"] [unique_id "amuSLQMgr4yz2OQW0xrG9gAAAIY"]
[Thu Jul 30 13:04:29.702546 2026] [security2:error] [pid 849392:tid 849526] [client 20.63.98.115:59603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/text.php"] [unique_id "amuSLQMgr4yz2OQW0xrHBAAAAIg"]
[Thu Jul 30 13:04:29.720864 2026] [core:error] [pid 849392:tid 849556] [client 85.204.70.102:45664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:29.720886 2026] [core:error] [pid 849392:tid 849556] [client 85.204.70.102:45664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:29.720992 2026] [security2:error] [pid 849392:tid 849556] [client 85.204.70.102:45664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLQMgr4yz2OQW0xrHBQAAAKY"]
[Thu Jul 30 13:04:30.022491 2026] [core:error] [pid 849392:tid 849527] [client 85.204.70.102:45678] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:30.022518 2026] [core:error] [pid 849392:tid 849527] [client 85.204.70.102:45678] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:30.022623 2026] [security2:error] [pid 849392:tid 849527] [client 85.204.70.102:45678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLgMgr4yz2OQW0xrHDgAAAIk"]
[Thu Jul 30 13:04:30.320681 2026] [core:error] [pid 849392:tid 849546] [client 85.204.70.102:45682] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:30.320704 2026] [core:error] [pid 849392:tid 849546] [client 85.204.70.102:45682] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:30.320812 2026] [security2:error] [pid 849392:tid 849546] [client 85.204.70.102:45682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLgMgr4yz2OQW0xrHFgAAAJw"]
[Thu Jul 30 13:04:30.601771 2026] [core:error] [pid 849392:tid 849587] [client 85.204.70.102:45694] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:30.601797 2026] [core:error] [pid 849392:tid 849587] [client 85.204.70.102:45694] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:30.601903 2026] [security2:error] [pid 849392:tid 849587] [client 85.204.70.102:45694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLgMgr4yz2OQW0xrHGgAAAMU"]
[Thu Jul 30 13:04:30.863899 2026] [security2:error] [pid 849392:tid 849626] [client 20.171.55.167:5708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/themes/themes.php"] [unique_id "amuSLgMgr4yz2OQW0xrHJQAAAOw"]
[Thu Jul 30 13:04:30.877043 2026] [security2:error] [pid 849392:tid 849581] [client 20.52.125.110:12571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/radio.php"] [unique_id "amuSLgMgr4yz2OQW0xrHJgAAAL8"]
[Thu Jul 30 13:04:30.899137 2026] [core:error] [pid 849392:tid 849606] [client 85.204.70.102:45710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:30.899157 2026] [core:error] [pid 849392:tid 849606] [client 85.204.70.102:45710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:30.899257 2026] [security2:error] [pid 849392:tid 849606] [client 85.204.70.102:45710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLgMgr4yz2OQW0xrHJwAAANg"]
[Thu Jul 30 13:04:31.419126 2026] [security2:error] [pid 849392:tid 849600] [client 20.63.98.115:59626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/f.php"] [unique_id "amuSLwMgr4yz2OQW0xrHMgAAANI"]
[Thu Jul 30 13:04:31.519875 2026] [security2:error] [pid 849392:tid 849585] [client 20.52.125.110:12785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/wpsml-sys.php"] [unique_id "amuSLwMgr4yz2OQW0xrHNgAAAMM"]
[Thu Jul 30 13:04:31.695000 2026] [core:error] [pid 849392:tid 849536] [client 85.204.70.102:45712] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:31.695026 2026] [core:error] [pid 849392:tid 849536] [client 85.204.70.102:45712] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:31.695163 2026] [security2:error] [pid 849392:tid 849536] [client 85.204.70.102:45712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLwMgr4yz2OQW0xrHPgAAAJI"]
[Thu Jul 30 13:04:31.734118 2026] [security2:error] [pid 849392:tid 849617] [client 20.171.55.167:5810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/radio.php"] [unique_id "amuSLwMgr4yz2OQW0xrHPwAAAOM"]
[Thu Jul 30 13:04:31.998056 2026] [core:error] [pid 849392:tid 849558] [client 85.204.70.102:45724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:31.998080 2026] [core:error] [pid 849392:tid 849558] [client 85.204.70.102:45724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:31.998199 2026] [security2:error] [pid 849392:tid 849558] [client 85.204.70.102:45724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSLwMgr4yz2OQW0xrHQwAAAKg"]
[Thu Jul 30 13:04:32.099559 2026] [security2:error] [pid 849392:tid 849578] [client 20.52.125.110:12555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/02.php"] [unique_id "amuSMAMgr4yz2OQW0xrHRAAAALw"]
[Thu Jul 30 13:04:32.263484 2026] [core:error] [pid 849392:tid 849548] [client 85.204.70.102:45736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:32.263509 2026] [core:error] [pid 849392:tid 849548] [client 85.204.70.102:45736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:32.263615 2026] [security2:error] [pid 849392:tid 849548] [client 85.204.70.102:45736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSMAMgr4yz2OQW0xrHTgAAAJ4"]
[Thu Jul 30 13:04:32.526929 2026] [security2:error] [pid 849392:tid 849623] [client 20.63.98.115:62856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuSMAMgr4yz2OQW0xrHUgAAAOk"]
[Thu Jul 30 13:04:32.541657 2026] [core:error] [pid 849392:tid 849568] [client 85.204.70.102:45740] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:32.541676 2026] [core:error] [pid 849392:tid 849568] [client 85.204.70.102:45740] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:32.541765 2026] [security2:error] [pid 849392:tid 849568] [client 85.204.70.102:45740] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSMAMgr4yz2OQW0xrHUwAAALI"]
[Thu Jul 30 13:04:32.640389 2026] [security2:error] [pid 849392:tid 849619] [client 20.52.125.110:12762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/infos.php"] [unique_id "amuSMAMgr4yz2OQW0xrHVAAAAOU"]
[Thu Jul 30 13:04:32.652759 2026] [security2:error] [pid 849392:tid 849523] [client 20.171.55.167:5816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-mail.php"] [unique_id "amuSMAMgr4yz2OQW0xrHVQAAAIU"]
[Thu Jul 30 13:04:32.839627 2026] [core:error] [pid 849392:tid 849587] [client 85.204.70.102:45746] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:32.839649 2026] [core:error] [pid 849392:tid 849587] [client 85.204.70.102:45746] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:32.839760 2026] [security2:error] [pid 849392:tid 849587] [client 85.204.70.102:45746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSMAMgr4yz2OQW0xrHXwAAAMU"]
[Thu Jul 30 13:04:33.019508 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuSMQMgr4yz2OQW0xrHYwAAAOo"]
[Thu Jul 30 13:04:33.019639 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuSMQMgr4yz2OQW0xrHYwAAAOo"]
[Thu Jul 30 13:04:33.115039 2026] [core:error] [pid 849392:tid 849561] [client 85.204.70.102:39846] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:33.115067 2026] [core:error] [pid 849392:tid 849561] [client 85.204.70.102:39846] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:33.115185 2026] [security2:error] [pid 849392:tid 849561] [client 85.204.70.102:39846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSMQMgr4yz2OQW0xrHZAAAAKs"]
[Thu Jul 30 13:04:33.240489 2026] [security2:error] [pid 849392:tid 849566] [client 20.52.125.110:12749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/updates.php"] [unique_id "amuSMQMgr4yz2OQW0xrHaQAAALA"]
[Thu Jul 30 13:04:33.303661 2026] [security2:error] [pid 849392:tid 849601] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuSMQMgr4yz2OQW0xrHbgAAANM"]
[Thu Jul 30 13:04:33.303758 2026] [security2:error] [pid 849392:tid 849601] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuSMQMgr4yz2OQW0xrHbgAAANM"]
[Thu Jul 30 13:04:33.366175 2026] [core:error] [pid 849392:tid 849577] [client 85.204.70.102:39850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:33.366200 2026] [core:error] [pid 849392:tid 849577] [client 85.204.70.102:39850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:33.366323 2026] [security2:error] [pid 849392:tid 849577] [client 85.204.70.102:39850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSMQMgr4yz2OQW0xrHcAAAALs"]
[Thu Jul 30 13:04:33.585957 2026] [security2:error] [pid 849392:tid 849538] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuSMQMgr4yz2OQW0xrHcQAAAJQ"]
[Thu Jul 30 13:04:33.586108 2026] [security2:error] [pid 849392:tid 849538] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuSMQMgr4yz2OQW0xrHcQAAAJQ"]
[Thu Jul 30 13:04:33.690115 2026] [autoindex:error] [pid 849392:tid 849569] [client 85.204.70.102:39862] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:33.691394 2026] [security2:error] [pid 849392:tid 849569] [client 85.204.70.102:39862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSMQMgr4yz2OQW0xrHcgAAALM"]
[Thu Jul 30 13:04:33.699141 2026] [security2:error] [pid 849392:tid 849613] [client 20.171.55.167:5781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuSMQMgr4yz2OQW0xrHdAAAAN8"]
[Thu Jul 30 13:04:33.804491 2026] [security2:error] [pid 849392:tid 849564] [client 193.148.16.211:44912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.16.148.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuSMQMgr4yz2OQW0xrHewAAAK4"]
[Thu Jul 30 13:04:33.804568 2026] [security2:error] [pid 849392:tid 849564] [client 193.148.16.211:44912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuSMQMgr4yz2OQW0xrHewAAAK4"]
[Thu Jul 30 13:04:33.826013 2026] [core:error] [pid 849392:tid 849572] [client 85.204.70.102:39862] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:33.826042 2026] [core:error] [pid 849392:tid 849572] [client 85.204.70.102:39862] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:33.826142 2026] [security2:error] [pid 849392:tid 849572] [client 85.204.70.102:39862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSMQMgr4yz2OQW0xrHfAAAALY"]
[Thu Jul 30 13:04:33.872720 2026] [security2:error] [pid 849392:tid 849541] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/media.php"] [unique_id "amuSMQMgr4yz2OQW0xrHgAAAAJc"]
[Thu Jul 30 13:04:33.872865 2026] [security2:error] [pid 849392:tid 849541] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/media.php"] [unique_id "amuSMQMgr4yz2OQW0xrHgAAAAJc"]
[Thu Jul 30 13:04:34.142675 2026] [security2:error] [pid 849392:tid 849558] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/images.php"] [unique_id "amuSMgMgr4yz2OQW0xrHgwAAAKg"]
[Thu Jul 30 13:04:34.142786 2026] [security2:error] [pid 849392:tid 849558] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/images.php"] [unique_id "amuSMgMgr4yz2OQW0xrHgwAAAKg"]
[Thu Jul 30 13:04:34.267888 2026] [core:error] [pid 849392:tid 849591] [client 74.7.244.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:34.267912 2026] [core:error] [pid 849392:tid 849591] [client 74.7.244.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:34.268025 2026] [security2:error] [pid 849392:tid 849591] [client 74.7.244.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.alanturner.com.au"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuSMgMgr4yz2OQW0xrHjAAAAMk"]
[Thu Jul 30 13:04:34.269494 2026] [security2:error] [pid 849392:tid 849647] [client 74.7.244.13:51160] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.alanturner.com.au"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuSMgMgr4yz2OQW0xrHiQABAVc"]
[Thu Jul 30 13:04:34.335916 2026] [security2:error] [pid 849392:tid 849528] [client 20.52.125.110:12751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/user.php"] [unique_id "amuSMgMgr4yz2OQW0xrHjQAAAIo"]
[Thu Jul 30 13:04:34.535432 2026] [core:error] [pid 849392:tid 849552] [client 85.204.70.102:39864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:34.535460 2026] [core:error] [pid 849392:tid 849552] [client 85.204.70.102:39864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:34.535571 2026] [security2:error] [pid 849392:tid 849552] [client 85.204.70.102:39864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSMgMgr4yz2OQW0xrHlAAAAKI"]
[Thu Jul 30 13:04:34.557558 2026] [security2:error] [pid 849392:tid 849637] [client 20.171.55.167:5231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/admin.php"] [unique_id "amuSMgMgr4yz2OQW0xrHlQAAAPc"]
[Thu Jul 30 13:04:34.572319 2026] [core:notice] [pid 849392:tid 849563] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:34.596320 2026] [security2:error] [pid 849392:tid 849641] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/adminner.php"] [unique_id "amuSMgMgr4yz2OQW0xrHlwAAAPs"]
[Thu Jul 30 13:04:34.596472 2026] [security2:error] [pid 849392:tid 849641] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/adminner.php"] [unique_id "amuSMgMgr4yz2OQW0xrHlwAAAPs"]
[Thu Jul 30 13:04:34.876933 2026] [autoindex:error] [pid 849392:tid 849635] [client 85.204.70.102:39872] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:34.877623 2026] [security2:error] [pid 849392:tid 849635] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSMgMgr4yz2OQW0xrHngAAAPU"]
[Thu Jul 30 13:04:34.905257 2026] [security2:error] [pid 849392:tid 849581] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/admin.php"] [unique_id "amuSMgMgr4yz2OQW0xrHogAAAL8"]
[Thu Jul 30 13:04:34.905364 2026] [security2:error] [pid 849392:tid 849581] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/admin.php"] [unique_id "amuSMgMgr4yz2OQW0xrHogAAAL8"]
[Thu Jul 30 13:04:34.999803 2026] [security2:error] [pid 849392:tid 849531] [client 20.63.98.115:59620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/hehe.php"] [unique_id "amuSMgMgr4yz2OQW0xrHowAAAI0"]
[Thu Jul 30 13:04:35.004562 2026] [security2:error] [pid 849392:tid 849646] [client 74.7.228.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mskabir.com"] [uri "/index.php"] [unique_id "amuSMQMgr4yz2OQW0xrHcwABAFs"]
[Thu Jul 30 13:04:35.017909 2026] [authz_core:error] [pid 849392:tid 849606] [client 85.204.70.102:39872] AH01630: client denied by server configuration: /home1/muuudite/public_html/website_45622194/wp-content/plugins/akismet/
[Thu Jul 30 13:04:35.019440 2026] [security2:error] [pid 849392:tid 849606] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSMwMgr4yz2OQW0xrHpAAAANg"]
[Thu Jul 30 13:04:35.025067 2026] [security2:error] [pid 849392:tid 849625] [client 184.75.208.246:50732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.208.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuSMwMgr4yz2OQW0xrHpQAAAOs"]
[Thu Jul 30 13:04:35.025160 2026] [security2:error] [pid 849392:tid 849625] [client 184.75.208.246:50732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuSMwMgr4yz2OQW0xrHpQAAAOs"]
[Thu Jul 30 13:04:35.117250 2026] [core:notice] [pid 849392:tid 849598] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:35.170577 2026] [security2:error] [pid 849392:tid 849559] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuSMwMgr4yz2OQW0xrHqAAAAKk"]
[Thu Jul 30 13:04:35.170677 2026] [security2:error] [pid 849392:tid 849559] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/ops.php"] [unique_id "amuSMwMgr4yz2OQW0xrHqAAAAKk"]
[Thu Jul 30 13:04:35.171132 2026] [autoindex:error] [pid 849392:tid 849605] [client 85.204.70.102:39872] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:35.171721 2026] [security2:error] [pid 849392:tid 849605] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSMwMgr4yz2OQW0xrHpwAAANc"]
[Thu Jul 30 13:04:35.266315 2026] [core:notice] [pid 849392:tid 849601] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:35.325625 2026] [autoindex:error] [pid 849392:tid 849611] [client 85.204.70.102:39872] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:35.326364 2026] [security2:error] [pid 849392:tid 849611] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSMwMgr4yz2OQW0xrHrgAAAN0"]
[Thu Jul 30 13:04:35.407906 2026] [security2:error] [pid 849392:tid 849579] [client 20.52.125.110:12796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/admin-ajax.php"] [unique_id "amuSMwMgr4yz2OQW0xrHtAAAAL0"]
[Thu Jul 30 13:04:35.449881 2026] [core:notice] [pid 849392:tid 849642] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:35.475872 2026] [security2:error] [pid 849392:tid 849585] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/mac.php"] [unique_id "amuSMwMgr4yz2OQW0xrHtwAAAMM"]
[Thu Jul 30 13:04:35.475965 2026] [security2:error] [pid 849392:tid 849585] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/mac.php"] [unique_id "amuSMwMgr4yz2OQW0xrHtwAAAMM"]
[Thu Jul 30 13:04:35.478704 2026] [autoindex:error] [pid 849392:tid 849608] [client 85.204.70.102:39872] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:35.479290 2026] [security2:error] [pid 849392:tid 849608] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSMwMgr4yz2OQW0xrHtgAAANo"]
[Thu Jul 30 13:04:35.567855 2026] [security2:error] [pid 849392:tid 849567] [client 20.151.254.105:41574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/inputs.php"] [unique_id "amuSMwMgr4yz2OQW0xrHuAAAALE"]
[Thu Jul 30 13:04:35.568012 2026] [security2:error] [pid 849392:tid 849567] [client 20.151.254.105:41574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/inputs.php"] [unique_id "amuSMwMgr4yz2OQW0xrHuAAAALE"]
[Thu Jul 30 13:04:35.601210 2026] [security2:error] [pid 849392:tid 849577] [client 20.171.55.167:5763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuSMwMgr4yz2OQW0xrHvAAAALs"]
[Thu Jul 30 13:04:35.634732 2026] [autoindex:error] [pid 849392:tid 849575] [client 85.204.70.102:39872] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:35.635606 2026] [security2:error] [pid 849392:tid 849575] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSMwMgr4yz2OQW0xrHvQAAALk"]
[Thu Jul 30 13:04:35.801663 2026] [autoindex:error] [pid 849392:tid 849628] [client 85.204.70.102:39872] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:35.802566 2026] [security2:error] [pid 849392:tid 849628] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSMwMgr4yz2OQW0xrHwQAAAO4"]
[Thu Jul 30 13:04:35.855155 2026] [autoindex:error] [pid 849392:tid 849593] [client 74.248.96.101:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_468361c2/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:35.855906 2026] [security2:error] [pid 849392:tid 849593] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.vanguardlegalassociates.team"] [uri "/cgi-sys/403.html"] [unique_id "amuSMwMgr4yz2OQW0xrHwgAAAMs"]
[Thu Jul 30 13:04:35.954610 2026] [autoindex:error] [pid 849392:tid 849576] [client 85.204.70.102:39872] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:35.955245 2026] [security2:error] [pid 849392:tid 849576] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSMwMgr4yz2OQW0xrHzgAAALo"]
[Thu Jul 30 13:04:36.108074 2026] [autoindex:error] [pid 849392:tid 849623] [client 85.204.70.102:39872] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:36.108748 2026] [security2:error] [pid 849392:tid 849623] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNAMgr4yz2OQW0xrH1AAAAOk"]
[Thu Jul 30 13:04:36.138676 2026] [security2:error] [pid 849392:tid 849568] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/pucci.php"] [unique_id "amuSNAMgr4yz2OQW0xrH1gAAALI"]
[Thu Jul 30 13:04:36.138833 2026] [security2:error] [pid 849392:tid 849568] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/pucci.php"] [unique_id "amuSNAMgr4yz2OQW0xrH1gAAALI"]
[Thu Jul 30 13:04:36.179933 2026] [security2:error] [pid 849392:tid 849544] [client 20.52.125.110:12761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/alfa.php"] [unique_id "amuSNAMgr4yz2OQW0xrH1wAAAJo"]
[Thu Jul 30 13:04:36.207044 2026] [security2:error] [pid 849392:tid 849602] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSMwMgr4yz2OQW0xrHzwAAANQ"]
[Thu Jul 30 13:04:36.273214 2026] [autoindex:error] [pid 849392:tid 849555] [client 85.204.70.102:39872] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:36.273905 2026] [security2:error] [pid 849392:tid 849555] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNAMgr4yz2OQW0xrH2wAAAKU"]
[Thu Jul 30 13:04:36.415386 2026] [core:error] [pid 849392:tid 849554] [client 85.204.70.102:39872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:36.415413 2026] [core:error] [pid 849392:tid 849554] [client 85.204.70.102:39872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:36.415548 2026] [security2:error] [pid 849392:tid 849554] [client 85.204.70.102:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSNAMgr4yz2OQW0xrH4gAAAKQ"]
[Thu Jul 30 13:04:36.641454 2026] [security2:error] [pid 849392:tid 849586] [client 20.63.98.115:59645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/options.php"] [unique_id "amuSNAMgr4yz2OQW0xrH5AAAAMQ"]
[Thu Jul 30 13:04:36.729584 2026] [autoindex:error] [pid 849392:tid 849635] [client 85.204.70.102:39874] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:36.730229 2026] [security2:error] [pid 849392:tid 849635] [client 85.204.70.102:39874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNAMgr4yz2OQW0xrH5QAAAPU"]
[Thu Jul 30 13:04:36.741478 2026] [security2:error] [pid 849392:tid 849596] [client 213.35.108.6:55077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-login.php"] [unique_id "amuSNAMgr4yz2OQW0xrH4wAAAM4"]
[Thu Jul 30 13:04:36.810115 2026] [security2:error] [pid 849392:tid 849629] [client 20.171.55.167:5780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-links-opml.php"] [unique_id "amuSNAMgr4yz2OQW0xrH6QAAAO8"]
[Thu Jul 30 13:04:36.820598 2026] [security2:error] [pid 849392:tid 849646] [client 213.152.161.240:41702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuSNAMgr4yz2OQW0xrH6gAAAQA"]
[Thu Jul 30 13:04:36.820724 2026] [security2:error] [pid 849392:tid 849646] [client 213.152.161.240:41702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuSNAMgr4yz2OQW0xrH6gAAAQA"]
[Thu Jul 30 13:04:36.895967 2026] [autoindex:error] [pid 849392:tid 849644] [client 85.204.70.102:39874] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:36.896616 2026] [security2:error] [pid 849392:tid 849644] [client 85.204.70.102:39874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNAMgr4yz2OQW0xrH6wAAAP4"]
[Thu Jul 30 13:04:36.954803 2026] [proxy:error] [pid 849392:tid 849597] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:36.954857 2026] [proxy_http:error] [pid 849392:tid 849597] [client 20.52.125.110:12789] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:36.955443 2026] [proxy:error] [pid 849392:tid 849597] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:36.955489 2026] [proxy_http:error] [pid 849392:tid 849597] [client 20.52.125.110:12789] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:37.058817 2026] [autoindex:error] [pid 849392:tid 849565] [client 85.204.70.102:39874] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:37.059446 2026] [security2:error] [pid 849392:tid 849565] [client 85.204.70.102:39874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNQMgr4yz2OQW0xrH9wAAAK8"]
[Thu Jul 30 13:04:37.227609 2026] [autoindex:error] [pid 849392:tid 849600] [client 85.204.70.102:39874] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:37.228247 2026] [security2:error] [pid 849392:tid 849600] [client 85.204.70.102:39874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNQMgr4yz2OQW0xrH-QAAANI"]
[Thu Jul 30 13:04:37.358438 2026] [security2:error] [pid 849392:tid 849550] [client 213.35.108.6:55376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSNQMgr4yz2OQW0xrH-AAAAKA"]
[Thu Jul 30 13:04:37.391109 2026] [autoindex:error] [pid 849392:tid 849567] [client 85.204.70.102:39874] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:37.391760 2026] [security2:error] [pid 849392:tid 849567] [client 85.204.70.102:39874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNQMgr4yz2OQW0xrIAQAAALE"]
[Thu Jul 30 13:04:37.502451 2026] [security2:error] [pid 849392:tid 849624] [client 179.64.21.229:13339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSNQMgr4yz2OQW0xrH-gAAAOo"]
[Thu Jul 30 13:04:37.502591 2026] [security2:error] [pid 849392:tid 849624] [client 179.64.21.229:13339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSNQMgr4yz2OQW0xrH-gAAAOo"]
[Thu Jul 30 13:04:37.547229 2026] [security2:error] [pid 849392:tid 849529] [client 213.35.108.6:55801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "amuSNQMgr4yz2OQW0xrIDAAAAIs"]
[Thu Jul 30 13:04:37.554494 2026] [autoindex:error] [pid 849392:tid 849628] [client 85.204.70.102:39874] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:37.555104 2026] [security2:error] [pid 849392:tid 849628] [client 85.204.70.102:39874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNQMgr4yz2OQW0xrICwAAAO4"]
[Thu Jul 30 13:04:37.582585 2026] [security2:error] [pid 849392:tid 849645] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuSNQMgr4yz2OQW0xrIDQAAAP8"]
[Thu Jul 30 13:04:37.582698 2026] [security2:error] [pid 849392:tid 849645] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-admin/js/index.php"] [unique_id "amuSNQMgr4yz2OQW0xrIDQAAAP8"]
[Thu Jul 30 13:04:37.734300 2026] [security2:error] [pid 849392:tid 849617] [client 20.171.55.167:5766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/acme-challenge/radio.php"] [unique_id "amuSNQMgr4yz2OQW0xrIDwAAAOM"]
[Thu Jul 30 13:04:37.737741 2026] [security2:error] [pid 849392:tid 849612] [client 213.35.108.6:55910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-admin/load-styles.php"] [unique_id "amuSNQMgr4yz2OQW0xrIEAAAAN4"]
[Thu Jul 30 13:04:37.772422 2026] [autoindex:error] [pid 849392:tid 849593] [client 85.204.70.102:39874] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:37.773087 2026] [security2:error] [pid 849392:tid 849593] [client 85.204.70.102:39874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNQMgr4yz2OQW0xrIDgAAAMs"]
[Thu Jul 30 13:04:37.862027 2026] [security2:error] [pid 849392:tid 849542] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/8.php"] [unique_id "amuSNQMgr4yz2OQW0xrIEQAAAJg"]
[Thu Jul 30 13:04:37.862143 2026] [security2:error] [pid 849392:tid 849542] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/8.php"] [unique_id "amuSNQMgr4yz2OQW0xrIEQAAAJg"]
[Thu Jul 30 13:04:37.922178 2026] [security2:error] [pid 849392:tid 849558] [client 20.63.98.115:31744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuSNQMgr4yz2OQW0xrIGgAAAKg"]
[Thu Jul 30 13:04:37.986651 2026] [autoindex:error] [pid 849392:tid 849623] [client 85.204.70.102:39874] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:37.987350 2026] [security2:error] [pid 849392:tid 849623] [client 85.204.70.102:39874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSNQMgr4yz2OQW0xrIGQAAAOk"]
[Thu Jul 30 13:04:38.137845 2026] [core:error] [pid 849392:tid 849604] [client 85.204.70.102:39874] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:38.137865 2026] [core:error] [pid 849392:tid 849604] [client 85.204.70.102:39874] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:38.137961 2026] [security2:error] [pid 849392:tid 849604] [client 85.204.70.102:39874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSNgMgr4yz2OQW0xrIJgAAANY"]
[Thu Jul 30 13:04:38.157910 2026] [security2:error] [pid 849392:tid 849554] [client 74.248.96.101:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.vanguardlegalassociates.team"] [uri "/1.php"] [unique_id "amuSNgMgr4yz2OQW0xrIKQAAAKQ"]
[Thu Jul 30 13:04:38.158017 2026] [security2:error] [pid 849392:tid 849554] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/1.php"] [unique_id "amuSNgMgr4yz2OQW0xrIKQAAAKQ"]
[Thu Jul 30 13:04:38.158100 2026] [security2:error] [pid 849392:tid 849554] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/1.php"] [unique_id "amuSNgMgr4yz2OQW0xrIKQAAAKQ"]
[Thu Jul 30 13:04:38.206933 2026] [security2:error] [pid 849392:tid 849643] [client 213.35.108.6:56057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-includes/version.php"] [unique_id "amuSNgMgr4yz2OQW0xrIKgAAAP0"]
[Thu Jul 30 13:04:38.262772 2026] [security2:error] [pid 849392:tid 849585] [client 20.52.125.110:12577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/hehe.php"] [unique_id "amuSNgMgr4yz2OQW0xrIKwAAAMM"]
[Thu Jul 30 13:04:38.398770 2026] [security2:error] [pid 849392:tid 849596] [client 213.35.108.6:56331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-includes/functions.php"] [unique_id "amuSNgMgr4yz2OQW0xrIMQAAAM4"]
[Thu Jul 30 13:04:38.399515 2026] [core:error] [pid 849392:tid 849630] [client 85.204.70.102:39880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:38.399536 2026] [core:error] [pid 849392:tid 849630] [client 85.204.70.102:39880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:38.399638 2026] [security2:error] [pid 849392:tid 849630] [client 85.204.70.102:39880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSNgMgr4yz2OQW0xrIMAAAAPA"]
[Thu Jul 30 13:04:38.425818 2026] [security2:error] [pid 849392:tid 849609] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-content/admin.php"] [unique_id "amuSNgMgr4yz2OQW0xrINAAAANs"]
[Thu Jul 30 13:04:38.425917 2026] [security2:error] [pid 849392:tid 849609] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-content/admin.php"] [unique_id "amuSNgMgr4yz2OQW0xrINAAAANs"]
[Thu Jul 30 13:04:38.588182 2026] [security2:error] [pid 849392:tid 849545] [client 213.35.108.6:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-includes/class-wp.php"] [unique_id "amuSNgMgr4yz2OQW0xrIOgAAAJs"]
[Thu Jul 30 13:04:38.624802 2026] [security2:error] [pid 849392:tid 849581] [client 20.171.55.167:5797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/images/file.php"] [unique_id "amuSNgMgr4yz2OQW0xrIOwAAAL8"]
[Thu Jul 30 13:04:38.652560 2026] [core:error] [pid 849392:tid 849601] [client 85.204.70.102:39894] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:38.652579 2026] [core:error] [pid 849392:tid 849601] [client 85.204.70.102:39894] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:38.652675 2026] [security2:error] [pid 849392:tid 849601] [client 85.204.70.102:39894] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSNgMgr4yz2OQW0xrIPAAAANM"]
[Thu Jul 30 13:04:38.691023 2026] [security2:error] [pid 849392:tid 849580] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-content/themes/index.php"] [unique_id "amuSNgMgr4yz2OQW0xrIPQAAAL4"]
[Thu Jul 30 13:04:38.691134 2026] [security2:error] [pid 849392:tid 849580] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-content/themes/index.php"] [unique_id "amuSNgMgr4yz2OQW0xrIPQAAAL4"]
[Thu Jul 30 13:04:38.754481 2026] [security2:error] [pid 849392:tid 849559] [client 20.52.125.110:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/rk2.php"] [unique_id "amuSNgMgr4yz2OQW0xrIPgAAAKk"]
[Thu Jul 30 13:04:38.772854 2026] [core:notice] [pid 849392:tid 849497] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:38.779003 2026] [security2:error] [pid 849392:tid 849649] [client 213.35.108.6:56604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-includes/option.php"] [unique_id "amuSNgMgr4yz2OQW0xrIQAAAAQM"]
[Thu Jul 30 13:04:38.934754 2026] [autoindex:error] [pid 849392:tid 849608] [client 139.155.134.17:45972] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:38.969779 2026] [core:error] [pid 849392:tid 849564] [client 85.204.70.102:39906] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:38.969808 2026] [core:error] [pid 849392:tid 849564] [client 85.204.70.102:39906] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:38.969941 2026] [security2:error] [pid 849392:tid 849564] [client 85.204.70.102:39906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSNgMgr4yz2OQW0xrISgAAAK4"]
[Thu Jul 30 13:04:38.976515 2026] [security2:error] [pid 849392:tid 849577] [client 213.35.108.6:56721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-includes/post.php"] [unique_id "amuSNgMgr4yz2OQW0xrISwAAALs"]
[Thu Jul 30 13:04:38.977073 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/222.php"] [unique_id "amuSNgMgr4yz2OQW0xrITAAAAOo"]
[Thu Jul 30 13:04:38.977188 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/222.php"] [unique_id "amuSNgMgr4yz2OQW0xrITAAAAOo"]
[Thu Jul 30 13:04:39.165963 2026] [security2:error] [pid 849392:tid 849593] [client 213.35.108.6:56860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-includes/user.php"] [unique_id "amuSNwMgr4yz2OQW0xrIVwAAAMs"]
[Thu Jul 30 13:04:39.186267 2026] [security2:error] [pid 849392:tid 849638] [client 20.63.98.115:62969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/images/index.php"] [unique_id "amuSNwMgr4yz2OQW0xrIWAAAAPg"]
[Thu Jul 30 13:04:39.251065 2026] [core:error] [pid 849392:tid 849528] [client 85.204.70.102:39918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:39.251086 2026] [core:error] [pid 849392:tid 849528] [client 85.204.70.102:39918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:39.251201 2026] [security2:error] [pid 849392:tid 849528] [client 85.204.70.102:39918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSNwMgr4yz2OQW0xrIWQAAAIo"]
[Thu Jul 30 13:04:39.263446 2026] [security2:error] [pid 849392:tid 849647] [client 20.52.125.110:12565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/setup-config.php"] [unique_id "amuSNwMgr4yz2OQW0xrIWwAAAQE"]
[Thu Jul 30 13:04:39.264557 2026] [security2:error] [pid 849392:tid 849548] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/cgi-bin/index.php"] [unique_id "amuSNwMgr4yz2OQW0xrIXAAAAJ4"]
[Thu Jul 30 13:04:39.264669 2026] [security2:error] [pid 849392:tid 849548] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/cgi-bin/index.php"] [unique_id "amuSNwMgr4yz2OQW0xrIXAAAAJ4"]
[Thu Jul 30 13:04:39.338153 2026] [security2:error] [pid 849392:tid 849495] [remote 57.141.0.18:24972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuSNwMgr4yz2OQW0xrIVgAAlGU"]
[Thu Jul 30 13:04:39.501445 2026] [core:error] [pid 849392:tid 849582] [client 85.204.70.102:39930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:39.501464 2026] [core:error] [pid 849392:tid 849582] [client 85.204.70.102:39930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:39.501541 2026] [security2:error] [pid 849392:tid 849582] [client 85.204.70.102:39930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSNwMgr4yz2OQW0xrIZwAAAMA"]
[Thu Jul 30 13:04:39.501939 2026] [security2:error] [pid 849392:tid 849573] [client 20.171.55.167:5211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/upgrade/function.php"] [unique_id "amuSNwMgr4yz2OQW0xrIaAAAALc"]
[Thu Jul 30 13:04:39.553639 2026] [autoindex:error] [pid 849392:tid 849604] [client 74.248.96.101:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_468361c2/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:39.554334 2026] [security2:error] [pid 849392:tid 849604] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.vanguardlegalassociates.team"] [uri "/cgi-sys/403.html"] [unique_id "amuSNwMgr4yz2OQW0xrIawAAANY"]
[Thu Jul 30 13:04:39.710630 2026] [autoindex:error] [pid 849392:tid 849648] [client 74.248.96.101:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_468361c2/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:39.711282 2026] [security2:error] [pid 849392:tid 849648] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.vanguardlegalassociates.team"] [uri "/cgi-sys/403.html"] [unique_id "amuSNwMgr4yz2OQW0xrIcQAAAQI"]
[Thu Jul 30 13:04:39.733604 2026] [security2:error] [pid 849392:tid 849574] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuSNgMgr4yz2OQW0xrIRQAAuHQ"]
[Thu Jul 30 13:04:39.800536 2026] [core:error] [pid 849392:tid 849586] [client 85.204.70.102:39934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:39.800558 2026] [core:error] [pid 849392:tid 849586] [client 85.204.70.102:39934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:39.800668 2026] [security2:error] [pid 849392:tid 849586] [client 85.204.70.102:39934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSNwMgr4yz2OQW0xrIdAAAAMQ"]
[Thu Jul 30 13:04:39.883255 2026] [autoindex:error] [pid 849392:tid 849596] [client 74.248.96.101:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_468361c2/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:39.884047 2026] [security2:error] [pid 849392:tid 849596] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.vanguardlegalassociates.team"] [uri "/cgi-sys/403.html"] [unique_id "amuSNwMgr4yz2OQW0xrIdgAAAM4"]
[Thu Jul 30 13:04:39.997444 2026] [security2:error] [pid 849392:tid 849561] [client 20.52.125.110:12547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/a7.php"] [unique_id "amuSNwMgr4yz2OQW0xrIfgAAAKs"]
[Thu Jul 30 13:04:40.048367 2026] [security2:error] [pid 849392:tid 849649] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/raw.php"] [unique_id "amuSOAMgr4yz2OQW0xrIhAAAAQM"]
[Thu Jul 30 13:04:40.048453 2026] [security2:error] [pid 849392:tid 849649] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/raw.php"] [unique_id "amuSOAMgr4yz2OQW0xrIhAAAAQM"]
[Thu Jul 30 13:04:40.062139 2026] [core:error] [pid 849392:tid 849590] [client 85.204.70.102:39938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:40.062162 2026] [core:error] [pid 849392:tid 849590] [client 85.204.70.102:39938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:40.062289 2026] [security2:error] [pid 849392:tid 849590] [client 85.204.70.102:39938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSOAMgr4yz2OQW0xrIhwAAAMg"]
[Thu Jul 30 13:04:40.216356 2026] [security2:error] [pid 849392:tid 849407] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSOAMgr4yz2OQW0xrIjwAA6g0"]
[Thu Jul 30 13:04:40.216517 2026] [security2:error] [pid 849392:tid 849624] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSOAMgr4yz2OQW0xrIjwAA6g0"]
[Thu Jul 30 13:04:40.281256 2026] [security2:error] [pid 849392:tid 849611] [client 20.171.55.167:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/user/themes.php"] [unique_id "amuSOAMgr4yz2OQW0xrIkAAAAN0"]
[Thu Jul 30 13:04:40.322181 2026] [core:error] [pid 849392:tid 849622] [client 85.204.70.102:39952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:40.322207 2026] [core:error] [pid 849392:tid 849622] [client 85.204.70.102:39952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:40.322307 2026] [security2:error] [pid 849392:tid 849622] [client 85.204.70.102:39952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSOAMgr4yz2OQW0xrIlAAAAOg"]
[Thu Jul 30 13:04:40.353611 2026] [security2:error] [pid 849392:tid 849593] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-content/index.php"] [unique_id "amuSOAMgr4yz2OQW0xrIlQAAAMs"]
[Thu Jul 30 13:04:40.447081 2026] [security2:error] [pid 849392:tid 849602] [client 213.35.108.6:56970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.108.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "amuSOAMgr4yz2OQW0xrIoQAAANQ"]
[Thu Jul 30 13:04:40.490146 2026] [security2:error] [pid 849392:tid 849641] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/simple.php"] [unique_id "amuSOAMgr4yz2OQW0xrIpwAAAPs"]
[Thu Jul 30 13:04:40.490280 2026] [security2:error] [pid 849392:tid 849641] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/simple.php"] [unique_id "amuSOAMgr4yz2OQW0xrIpwAAAPs"]
[Thu Jul 30 13:04:40.583087 2026] [core:error] [pid 849392:tid 849523] [client 85.204.70.102:39964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:40.583109 2026] [core:error] [pid 849392:tid 849523] [client 85.204.70.102:39964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:40.583234 2026] [security2:error] [pid 849392:tid 849523] [client 85.204.70.102:39964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSOAMgr4yz2OQW0xrIrgAAAIU"]
[Thu Jul 30 13:04:40.675094 2026] [proxy:error] [pid 849392:tid 849547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:40.675166 2026] [proxy_http:error] [pid 849392:tid 849547] [client 52.4.19.39:47975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:40.675811 2026] [proxy:error] [pid 849392:tid 849547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:40.675863 2026] [proxy_http:error] [pid 849392:tid 849547] [client 52.4.19.39:47975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:40.676157 2026] [proxy:error] [pid 849392:tid 849629] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:40.676215 2026] [proxy_http:error] [pid 849392:tid 849629] [client 3.225.222.228:34010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:40.676787 2026] [proxy:error] [pid 849392:tid 849629] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:40.676832 2026] [proxy_http:error] [pid 849392:tid 849629] [client 3.225.222.228:34010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:40.820744 2026] [security2:error] [pid 849392:tid 849625] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/xxx.php"] [unique_id "amuSOAMgr4yz2OQW0xrIvQAAAOs"]
[Thu Jul 30 13:04:40.820834 2026] [security2:error] [pid 849392:tid 849625] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/xxx.php"] [unique_id "amuSOAMgr4yz2OQW0xrIvQAAAOs"]
[Thu Jul 30 13:04:40.833732 2026] [core:error] [pid 849392:tid 849609] [client 85.204.70.102:39970] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:40.833757 2026] [core:error] [pid 849392:tid 849609] [client 85.204.70.102:39970] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:40.833906 2026] [security2:error] [pid 849392:tid 849609] [client 85.204.70.102:39970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSOAMgr4yz2OQW0xrIvgAAANs"]
[Thu Jul 30 13:04:41.073963 2026] [security2:error] [pid 849392:tid 849597] [client 20.171.55.167:6091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/radio.php"] [unique_id "amuSOQMgr4yz2OQW0xrIzgAAAM8"]
[Thu Jul 30 13:04:41.099338 2026] [core:error] [pid 849392:tid 849628] [client 85.204.70.102:39982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:41.099367 2026] [core:error] [pid 849392:tid 849628] [client 85.204.70.102:39982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:41.099460 2026] [security2:error] [pid 849392:tid 849628] [client 85.204.70.102:39982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSOQMgr4yz2OQW0xrIzwAAAO4"]
[Thu Jul 30 13:04:41.112029 2026] [security2:error] [pid 849392:tid 849603] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/file.php"] [unique_id "amuSOQMgr4yz2OQW0xrI0gAAANU"]
[Thu Jul 30 13:04:41.112138 2026] [security2:error] [pid 849392:tid 849603] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/file.php"] [unique_id "amuSOQMgr4yz2OQW0xrI0gAAANU"]
[Thu Jul 30 13:04:41.231911 2026] [security2:error] [pid 849392:tid 849583] [client 20.52.125.110:12556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/f7.php"] [unique_id "amuSOQMgr4yz2OQW0xrI2wAAAME"]
[Thu Jul 30 13:04:41.381526 2026] [security2:error] [pid 849392:tid 849595] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-load.php"] [unique_id "amuSOQMgr4yz2OQW0xrI5gAAAM0"]
[Thu Jul 30 13:04:41.381648 2026] [security2:error] [pid 849392:tid 849595] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-load.php"] [unique_id "amuSOQMgr4yz2OQW0xrI5gAAAM0"]
[Thu Jul 30 13:04:41.409800 2026] [autoindex:error] [pid 849392:tid 849568] [client 85.204.70.102:39986] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:41.410496 2026] [security2:error] [pid 849392:tid 849568] [client 85.204.70.102:39986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSOQMgr4yz2OQW0xrI4wAAALI"]
[Thu Jul 30 13:04:41.555604 2026] [autoindex:error] [pid 849392:tid 849554] [client 85.204.70.102:39986] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:41.556235 2026] [security2:error] [pid 849392:tid 849554] [client 85.204.70.102:39986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSOQMgr4yz2OQW0xrI7QAAAKQ"]
[Thu Jul 30 13:04:41.672422 2026] [autoindex:error] [pid 849392:tid 849535] [client 74.248.96.101:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_468361c2/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:41.673215 2026] [security2:error] [pid 849392:tid 849535] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.vanguardlegalassociates.team"] [uri "/cgi-sys/403.html"] [unique_id "amuSOQMgr4yz2OQW0xrI9AAAAJE"]
[Thu Jul 30 13:04:41.704998 2026] [security2:error] [pid 849392:tid 849629] [client 85.204.70.102:39986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "amuSOQMgr4yz2OQW0xrI9QAAAO8"]
[Thu Jul 30 13:04:41.832852 2026] [core:error] [pid 849392:tid 849606] [client 85.204.70.102:39986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:41.832875 2026] [core:error] [pid 849392:tid 849606] [client 85.204.70.102:39986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:41.832973 2026] [security2:error] [pid 849392:tid 849606] [client 85.204.70.102:39986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSOQMgr4yz2OQW0xrI-gAAANg"]
[Thu Jul 30 13:04:41.899311 2026] [security2:error] [pid 849392:tid 849557] [client 20.52.125.110:13081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/nw.php"] [unique_id "amuSOQMgr4yz2OQW0xrI_AAAAKc"]
[Thu Jul 30 13:04:41.912279 2026] [autoindex:error] [pid 849392:tid 849636] [client 74.248.96.101:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_468361c2/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:41.913075 2026] [security2:error] [pid 849392:tid 849636] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.vanguardlegalassociates.team"] [uri "/cgi-sys/403.html"] [unique_id "amuSOQMgr4yz2OQW0xrI-QAAAPY"]
[Thu Jul 30 13:04:41.915419 2026] [security2:error] [pid 849392:tid 849558] [client 172.236.9.101:39319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSOQMgr4yz2OQW0xrI5QAAAKg"]
[Thu Jul 30 13:04:41.967570 2026] [security2:error] [pid 849392:tid 849588] [client 103.25.178.58:52786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hris.rgserve.ph"] [uri "/login.php"] [unique_id "amuSOQMgr4yz2OQW0xrI1wAAxh4"]
[Thu Jul 30 13:04:41.984119 2026] [security2:error] [pid 849392:tid 849648] [client 20.171.55.167:5821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/license.php"] [unique_id "amuSOQMgr4yz2OQW0xrI_gAAAQI"]
[Thu Jul 30 13:04:42.053643 2026] [security2:error] [pid 849392:tid 849614] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuSOgMgr4yz2OQW0xrJBwAAAOA"]
[Thu Jul 30 13:04:42.053765 2026] [security2:error] [pid 849392:tid 849614] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuSOgMgr4yz2OQW0xrJBwAAAOA"]
[Thu Jul 30 13:04:42.173550 2026] [core:error] [pid 849392:tid 849537] [client 85.204.70.102:39988] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:42.173591 2026] [core:error] [pid 849392:tid 849537] [client 85.204.70.102:39988] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:42.173713 2026] [security2:error] [pid 849392:tid 849537] [client 85.204.70.102:39988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSOgMgr4yz2OQW0xrJEAAAAJM"]
[Thu Jul 30 13:04:42.174426 2026] [security2:error] [pid 849392:tid 849531] [client 74.7.175.155:40106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuSOQMgr4yz2OQW0xrI9wAAAI0"]
[Thu Jul 30 13:04:42.174447 2026] [security2:error] [pid 849392:tid 849531] [client 74.7.175.155:40106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuSOQMgr4yz2OQW0xrI9wAAAI0"]
[Thu Jul 30 13:04:42.374052 2026] [security2:error] [pid 849392:tid 849529] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/a.php"] [unique_id "amuSOgMgr4yz2OQW0xrJFgAAAIs"]
[Thu Jul 30 13:04:42.374179 2026] [security2:error] [pid 849392:tid 849529] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/a.php"] [unique_id "amuSOgMgr4yz2OQW0xrJFgAAAIs"]
[Thu Jul 30 13:04:42.456719 2026] [core:error] [pid 849392:tid 849627] [client 85.204.70.102:39998] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:42.456741 2026] [core:error] [pid 849392:tid 849627] [client 85.204.70.102:39998] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:42.456861 2026] [security2:error] [pid 849392:tid 849627] [client 85.204.70.102:39998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSOgMgr4yz2OQW0xrJGAAAAO0"]
[Thu Jul 30 13:04:42.558997 2026] [security2:error] [pid 849392:tid 849603] [client 43.172.196.203:40226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/03/zara-home-une-belle-adresse-pour-votre-deco/"] [unique_id "amuSOgMgr4yz2OQW0xrJFQAAANU"]
[Thu Jul 30 13:04:42.696580 2026] [security2:error] [pid 849392:tid 849544] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuSOgMgr4yz2OQW0xrJJAAAAJo"]
[Thu Jul 30 13:04:42.696701 2026] [security2:error] [pid 849392:tid 849544] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuSOgMgr4yz2OQW0xrJJAAAAJo"]
[Thu Jul 30 13:04:42.757184 2026] [core:error] [pid 849392:tid 849571] [client 85.204.70.102:40008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:42.757212 2026] [core:error] [pid 849392:tid 849571] [client 85.204.70.102:40008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:04:42.757321 2026] [security2:error] [pid 849392:tid 849571] [client 85.204.70.102:40008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/website_45622194/index.php"] [unique_id "amuSOgMgr4yz2OQW0xrJJwAAALU"]
[Thu Jul 30 13:04:42.780675 2026] [security2:error] [pid 849392:tid 849542] [client 43.173.173.18:40206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2020/05/28/fete-des-meres-2020/feed/"] [unique_id "amuSOgMgr4yz2OQW0xrJGQAAAJg"]
[Thu Jul 30 13:04:42.802553 2026] [core:notice] [pid 849392:tid 849591] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:42.808856 2026] [security2:error] [pid 849392:tid 849591] [client 43.173.178.19:55514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/03/zara-home-une-belle-adresse-pour-votre-deco/"] [unique_id "amuSOgMgr4yz2OQW0xrJKAAAAMk"], referer: https://carnetdeshopping.com/index.php/2012/03/03/zara-home-une-belle-adresse-pour-votre-deco/
[Thu Jul 30 13:04:42.935804 2026] [security2:error] [pid 849392:tid 849583] [client 43.173.173.115:51710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/29/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/"] [unique_id "amuSOgMgr4yz2OQW0xrJIgAAAME"]
[Thu Jul 30 13:04:42.979633 2026] [security2:error] [pid 849392:tid 849551] [client 20.63.98.115:59619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amuSOgMgr4yz2OQW0xrJKgAAAKE"]
[Thu Jul 30 13:04:42.986838 2026] [security2:error] [pid 849392:tid 849573] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/aa.php"] [unique_id "amuSOgMgr4yz2OQW0xrJKwAAALc"]
[Thu Jul 30 13:04:42.986952 2026] [security2:error] [pid 849392:tid 849573] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/aa.php"] [unique_id "amuSOgMgr4yz2OQW0xrJKwAAALc"]
[Thu Jul 30 13:04:43.009779 2026] [security2:error] [pid 849392:tid 849526] [client 20.171.55.167:5807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/pki-validation/wp-config.php"] [unique_id "amuSOwMgr4yz2OQW0xrJLAAAAIg"]
[Thu Jul 30 13:04:43.062192 2026] [security2:error] [pid 849392:tid 849595] [client 74.7.175.155:54640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSOgMgr4yz2OQW0xrJJgAAAM0"], referer: http://www.alseermarine.com/robots.txt
[Thu Jul 30 13:04:43.259998 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/177.php"] [unique_id "amuSOwMgr4yz2OQW0xrJOAAAAOo"]
[Thu Jul 30 13:04:43.260113 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/177.php"] [unique_id "amuSOwMgr4yz2OQW0xrJOAAAAOo"]
[Thu Jul 30 13:04:43.383648 2026] [security2:error] [pid 849392:tid 849641] [client 20.52.125.110:12769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/ova.php"] [unique_id "amuSOwMgr4yz2OQW0xrJOwAAAPs"]
[Thu Jul 30 13:04:43.579231 2026] [core:notice] [pid 849392:tid 849618] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:43.584728 2026] [security2:error] [pid 849392:tid 849618] [client 43.173.175.64:43488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2020/05/28/fete-des-meres-2020/feed/"] [unique_id "amuSOwMgr4yz2OQW0xrJPwAAAOQ"], referer: https://carnetdeshopping.com/index.php/2020/05/28/fete-des-meres-2020/feed/
[Thu Jul 30 13:04:43.684066 2026] [core:notice] [pid 849392:tid 849605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:43.689833 2026] [security2:error] [pid 849392:tid 849605] [client 43.173.181.10:36602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/29/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/"] [unique_id "amuSOwMgr4yz2OQW0xrJRwAAANc"], referer: https://carnetdeshopping.com/index.php/2012/07/29/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/?replytocom=620
[Thu Jul 30 13:04:44.006624 2026] [security2:error] [pid 849392:tid 849524] [client 20.52.125.110:12781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/robots.php"] [unique_id "amuSPAMgr4yz2OQW0xrJTAAAAIY"]
[Thu Jul 30 13:04:44.064180 2026] [security2:error] [pid 849392:tid 849597] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/coffexium.php"] [unique_id "amuSPAMgr4yz2OQW0xrJTQAAAM8"]
[Thu Jul 30 13:04:44.064286 2026] [security2:error] [pid 849392:tid 849597] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/coffexium.php"] [unique_id "amuSPAMgr4yz2OQW0xrJTQAAAM8"]
[Thu Jul 30 13:04:44.132653 2026] [security2:error] [pid 849392:tid 849631] [client 20.171.55.167:5795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/radio.php"] [unique_id "amuSPAMgr4yz2OQW0xrJUgAAAPE"]
[Thu Jul 30 13:04:44.389297 2026] [security2:error] [pid 849392:tid 849647] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/fffm.php"] [unique_id "amuSPAMgr4yz2OQW0xrJXQAAAQE"]
[Thu Jul 30 13:04:44.389433 2026] [security2:error] [pid 849392:tid 849647] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/fffm.php"] [unique_id "amuSPAMgr4yz2OQW0xrJXQAAAQE"]
[Thu Jul 30 13:04:44.561481 2026] [security2:error] [pid 849392:tid 849446] [remote 57.141.18.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSPAMgr4yz2OQW0xrJWgAA-DQ"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,linen,lycra,polyester,titanium,plastic,steel,wood,silicon&min_price=300&rating=5&status=sale&unfilter=1
[Thu Jul 30 13:04:44.615164 2026] [security2:error] [pid 849392:tid 849445] [remote 57.141.18.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSPAMgr4yz2OQW0xrJXAAAnjM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,linen,lycra,polyester,titanium,plastic,steel,wood,silicon&min_price=300&rating=5&status=sale&unfilter=1
[Thu Jul 30 13:04:44.671749 2026] [security2:error] [pid 849392:tid 849600] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/82.php"] [unique_id "amuSPAMgr4yz2OQW0xrJYgAAANI"]
[Thu Jul 30 13:04:44.671866 2026] [security2:error] [pid 849392:tid 849600] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/82.php"] [unique_id "amuSPAMgr4yz2OQW0xrJYgAAANI"]
[Thu Jul 30 13:04:44.960927 2026] [security2:error] [pid 849392:tid 849547] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/config.json.php"] [unique_id "amuSPAMgr4yz2OQW0xrJawAAAJ0"]
[Thu Jul 30 13:04:44.961053 2026] [security2:error] [pid 849392:tid 849547] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/config.json.php"] [unique_id "amuSPAMgr4yz2OQW0xrJawAAAJ0"]
[Thu Jul 30 13:04:45.028724 2026] [security2:error] [pid 849392:tid 849637] [client 20.171.55.167:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/plugins/about.php"] [unique_id "amuSPQMgr4yz2OQW0xrJbQAAAPc"]
[Thu Jul 30 13:04:45.073413 2026] [security2:error] [pid 849392:tid 849576] [client 20.52.125.110:12774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/alf.php"] [unique_id "amuSPQMgr4yz2OQW0xrJbgAAALo"]
[Thu Jul 30 13:04:45.201596 2026] [security2:error] [pid 849392:tid 849581] [client 20.63.98.115:37499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/13.php"] [unique_id "amuSPQMgr4yz2OQW0xrJcgAAAL8"]
[Thu Jul 30 13:04:45.226423 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/fpwch.php"] [unique_id "amuSPQMgr4yz2OQW0xrJcwAAAOo"]
[Thu Jul 30 13:04:45.226538 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/fpwch.php"] [unique_id "amuSPQMgr4yz2OQW0xrJcwAAAOo"]
[Thu Jul 30 13:04:45.525637 2026] [security2:error] [pid 849392:tid 849636] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/xp.php"] [unique_id "amuSPQMgr4yz2OQW0xrJegAAAPY"]
[Thu Jul 30 13:04:45.525785 2026] [security2:error] [pid 849392:tid 849636] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/xp.php"] [unique_id "amuSPQMgr4yz2OQW0xrJegAAAPY"]
[Thu Jul 30 13:04:45.690181 2026] [security2:error] [pid 849392:tid 849558] [client 20.52.125.110:12550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/feedback.php"] [unique_id "amuSPQMgr4yz2OQW0xrJfQAAAKg"]
[Thu Jul 30 13:04:45.812832 2026] [security2:error] [pid 849392:tid 849589] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuSPQMgr4yz2OQW0xrJgwAAAMc"]
[Thu Jul 30 13:04:45.812920 2026] [security2:error] [pid 849392:tid 849589] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/reop3.php"] [unique_id "amuSPQMgr4yz2OQW0xrJgwAAAMc"]
[Thu Jul 30 13:04:45.910533 2026] [security2:error] [pid 849392:tid 849609] [client 20.171.55.167:5227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuSPQMgr4yz2OQW0xrJiwAAANs"]
[Thu Jul 30 13:04:46.110200 2026] [autoindex:error] [pid 849392:tid 849528] [client 74.248.96.101:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_468361c2/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:46.110960 2026] [security2:error] [pid 849392:tid 849528] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.vanguardlegalassociates.team"] [uri "/cgi-sys/403.html"] [unique_id "amuSPgMgr4yz2OQW0xrJjQAAAIo"]
[Thu Jul 30 13:04:46.267442 2026] [security2:error] [pid 849392:tid 849643] [client 85.204.70.102:46750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-admin/network/index.php"] [unique_id "amuSOwMgr4yz2OQW0xrJLQAAAP0"]
[Thu Jul 30 13:04:46.317244 2026] [security2:error] [pid 849392:tid 849548] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp.php"] [unique_id "amuSPgMgr4yz2OQW0xrJlQAAAJ4"]
[Thu Jul 30 13:04:46.317329 2026] [security2:error] [pid 849392:tid 849548] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/wp.php"] [unique_id "amuSPgMgr4yz2OQW0xrJlQAAAJ4"]
[Thu Jul 30 13:04:46.480139 2026] [security2:error] [pid 849392:tid 849591] [client 20.52.125.110:12552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/gettest.php"] [unique_id "amuSPgMgr4yz2OQW0xrJmwAAAMk"]
[Thu Jul 30 13:04:46.589430 2026] [security2:error] [pid 849392:tid 849615] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/dex.php"] [unique_id "amuSPgMgr4yz2OQW0xrJnwAAAOE"]
[Thu Jul 30 13:04:46.589536 2026] [security2:error] [pid 849392:tid 849615] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/dex.php"] [unique_id "amuSPgMgr4yz2OQW0xrJnwAAAOE"]
[Thu Jul 30 13:04:46.929605 2026] [security2:error] [pid 849392:tid 849633] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/biufile.php"] [unique_id "amuSPgMgr4yz2OQW0xrJrAAAAPM"]
[Thu Jul 30 13:04:46.929697 2026] [security2:error] [pid 849392:tid 849633] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/biufile.php"] [unique_id "amuSPgMgr4yz2OQW0xrJrAAAAPM"]
[Thu Jul 30 13:04:47.046557 2026] [security2:error] [pid 849392:tid 849555] [client 20.171.55.167:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/wp-login.php"] [unique_id "amuSPgMgr4yz2OQW0xrJowAAAKU"]
[Thu Jul 30 13:04:47.080420 2026] [security2:error] [pid 849392:tid 849635] [client 85.204.70.102:46332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-admin/network/index.php"] [unique_id "amuSPgMgr4yz2OQW0xrJqgAAAPU"]
[Thu Jul 30 13:04:47.272716 2026] [security2:error] [pid 849392:tid 849580] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/inputs.php"] [unique_id "amuSPwMgr4yz2OQW0xrJrwAAAL4"]
[Thu Jul 30 13:04:47.272818 2026] [security2:error] [pid 849392:tid 849580] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/inputs.php"] [unique_id "amuSPwMgr4yz2OQW0xrJrwAAAL4"]
[Thu Jul 30 13:04:47.471141 2026] [security2:error] [pid 849392:tid 849540] [client 179.64.21.229:1034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSPwMgr4yz2OQW0xrJuAAAAJY"]
[Thu Jul 30 13:04:47.478861 2026] [security2:error] [pid 849392:tid 849540] [client 179.64.21.229:1034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSPwMgr4yz2OQW0xrJuAAAAJY"]
[Thu Jul 30 13:04:47.539405 2026] [security2:error] [pid 849392:tid 849631] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/inputs.php"] [unique_id "amuSPwMgr4yz2OQW0xrJugAAAPE"]
[Thu Jul 30 13:04:47.539503 2026] [security2:error] [pid 849392:tid 849631] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/inputs.php"] [unique_id "amuSPwMgr4yz2OQW0xrJugAAAPE"]
[Thu Jul 30 13:04:47.967295 2026] [security2:error] [pid 849392:tid 849632] [client 20.171.55.167:5210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/wp-load.php"] [unique_id "amuSPwMgr4yz2OQW0xrJ0QAAAPI"]
[Thu Jul 30 13:04:47.982774 2026] [security2:error] [pid 849392:tid 849637] [client 20.63.98.115:62967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/inputs.php"] [unique_id "amuSPwMgr4yz2OQW0xrJ0gAAAPc"]
[Thu Jul 30 13:04:48.387885 2026] [security2:error] [pid 849392:tid 849529] [client 85.204.70.102:46334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muu.udi.temporary.site"] [uri "/website_45622194/wp-login.php"] [unique_id "amuSPwMgr4yz2OQW0xrJygAAAIs"]
[Thu Jul 30 13:04:48.388067 2026] [security2:error] [pid 849392:tid 849529] [client 85.204.70.102:46334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "muu.udi.temporary.site"] [uri "/website_45622194/wp-login.php"] [unique_id "amuSPwMgr4yz2OQW0xrJygAAAIs"]
[Thu Jul 30 13:04:48.611690 2026] [security2:error] [pid 849392:tid 849610] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/adminfuns.php"] [unique_id "amuSQAMgr4yz2OQW0xrJ4wAAANw"]
[Thu Jul 30 13:04:48.611829 2026] [security2:error] [pid 849392:tid 849610] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/adminfuns.php"] [unique_id "amuSQAMgr4yz2OQW0xrJ4wAAANw"]
[Thu Jul 30 13:04:48.712695 2026] [security2:error] [pid 849392:tid 849618] [client 85.204.70.102:46750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-admin/user/index.php"] [unique_id "amuSQAMgr4yz2OQW0xrJ4gAAAOQ"]
[Thu Jul 30 13:04:48.779124 2026] [security2:error] [pid 849392:tid 849587] [client 172.236.9.101:15955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSQAMgr4yz2OQW0xrJ1AAAAMU"]
[Thu Jul 30 13:04:48.851382 2026] [security2:error] [pid 849392:tid 849642] [client 20.171.55.167:5803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/file.php"] [unique_id "amuSQAMgr4yz2OQW0xrJ5wAAAPw"]
[Thu Jul 30 13:04:48.939265 2026] [security2:error] [pid 849392:tid 849540] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/goods.php"] [unique_id "amuSQAMgr4yz2OQW0xrJ7QAAAJY"]
[Thu Jul 30 13:04:48.939363 2026] [security2:error] [pid 849392:tid 849540] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/goods.php"] [unique_id "amuSQAMgr4yz2OQW0xrJ7QAAAJY"]
[Thu Jul 30 13:04:49.046325 2026] [security2:error] [pid 849392:tid 849607] [client 85.204.70.102:46332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-admin/user/index.php"] [unique_id "amuSQAMgr4yz2OQW0xrJ6AAAANk"]
[Thu Jul 30 13:04:49.084259 2026] [security2:error] [pid 849392:tid 849649] [client 20.52.125.110:12752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/maint.php"] [unique_id "amuSQQMgr4yz2OQW0xrJ8AAAAQM"]
[Thu Jul 30 13:04:49.257126 2026] [security2:error] [pid 849392:tid 849622] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/about.php"] [unique_id "amuSQQMgr4yz2OQW0xrJ8gAAAOg"]
[Thu Jul 30 13:04:49.257275 2026] [security2:error] [pid 849392:tid 849622] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/about.php"] [unique_id "amuSQQMgr4yz2OQW0xrJ8gAAAOg"]
[Thu Jul 30 13:04:49.264971 2026] [security2:error] [pid 849392:tid 849550] [client 104.210.56.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "saptora.com"] [uri "/index.php"] [unique_id "amuSPwMgr4yz2OQW0xrJtAAAoEs"]
[Thu Jul 30 13:04:49.383605 2026] [security2:error] [pid 849392:tid 849623] [client 20.63.98.115:31747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/jquery.php"] [unique_id "amuSQQMgr4yz2OQW0xrJ9wAAAOk"]
[Thu Jul 30 13:04:49.463097 2026] [security2:error] [pid 849392:tid 849528] [client 85.204.70.102:46336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muu.udi.temporary.site"] [uri "/website_45622194/wp-login.php"] [unique_id "amuSQQMgr4yz2OQW0xrJ-wAAAIo"]
[Thu Jul 30 13:04:49.463208 2026] [security2:error] [pid 849392:tid 849528] [client 85.204.70.102:46336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "muu.udi.temporary.site"] [uri "/website_45622194/wp-login.php"] [unique_id "amuSQQMgr4yz2OQW0xrJ-wAAAIo"]
[Thu Jul 30 13:04:49.551750 2026] [security2:error] [pid 849392:tid 849614] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/about.php"] [unique_id "amuSQQMgr4yz2OQW0xrKAgAAAOA"]
[Thu Jul 30 13:04:49.551868 2026] [security2:error] [pid 849392:tid 849614] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/about.php"] [unique_id "amuSQQMgr4yz2OQW0xrKAgAAAOA"]
[Thu Jul 30 13:04:49.606885 2026] [security2:error] [pid 849392:tid 849638] [client 85.204.70.102:46750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-content/index.php"] [unique_id "amuSQQMgr4yz2OQW0xrKAwAAAPg"]
[Thu Jul 30 13:04:49.751788 2026] [security2:error] [pid 849392:tid 849527] [client 85.204.70.102:46750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-content/plugins/index.php"] [unique_id "amuSQQMgr4yz2OQW0xrKBAAAAIk"]
[Thu Jul 30 13:04:49.843833 2026] [security2:error] [pid 849392:tid 849564] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuSQQMgr4yz2OQW0xrKAQAAAK4"]
[Thu Jul 30 13:04:49.851105 2026] [security2:error] [pid 849392:tid 849547] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/admin.php"] [unique_id "amuSQQMgr4yz2OQW0xrKCgAAAJ0"]
[Thu Jul 30 13:04:49.851189 2026] [security2:error] [pid 849392:tid 849547] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/admin.php"] [unique_id "amuSQQMgr4yz2OQW0xrKCgAAAJ0"]
[Thu Jul 30 13:04:49.896734 2026] [security2:error] [pid 849392:tid 849583] [client 85.204.70.102:46750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuSQQMgr4yz2OQW0xrKCwAAAME"]
[Thu Jul 30 13:04:49.909431 2026] [security2:error] [pid 849392:tid 849548] [client 20.171.55.167:5185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/dropdown.php"] [unique_id "amuSQQMgr4yz2OQW0xrKDAAAAJ4"]
[Thu Jul 30 13:04:50.090478 2026] [autoindex:error] [pid 849392:tid 849531] [client 85.204.70.102:46750] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:50.091213 2026] [security2:error] [pid 849392:tid 849531] [client 85.204.70.102:46750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSQgMgr4yz2OQW0xrKFQAAAI0"]
[Thu Jul 30 13:04:50.163693 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/admin.php"] [unique_id "amuSQgMgr4yz2OQW0xrKFwAAAOo"]
[Thu Jul 30 13:04:50.163804 2026] [security2:error] [pid 849392:tid 849624] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/admin.php"] [unique_id "amuSQgMgr4yz2OQW0xrKFwAAAOo"]
[Thu Jul 30 13:04:50.400144 2026] [security2:error] [pid 849392:tid 849641] [client 85.204.70.102:46750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-admin/index.php"] [unique_id "amuSQgMgr4yz2OQW0xrKGAAAAPs"]
[Thu Jul 30 13:04:50.713546 2026] [security2:error] [pid 849392:tid 849648] [client 85.204.70.102:46332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/wp-admin/index.php"] [unique_id "amuSQgMgr4yz2OQW0xrKJAAAAQI"]
[Thu Jul 30 13:04:50.979663 2026] [security2:error] [pid 849392:tid 849525] [client 20.171.55.167:5236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/plugins/dropdown.php"] [unique_id "amuSQgMgr4yz2OQW0xrKLwAAAIc"]
[Thu Jul 30 13:04:51.048754 2026] [security2:error] [pid 849392:tid 849498] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSQwMgr4yz2OQW0xrKMwAAz2g"]
[Thu Jul 30 13:04:51.048922 2026] [security2:error] [pid 849392:tid 849597] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSQwMgr4yz2OQW0xrKMwAAz2g"]
[Thu Jul 30 13:04:51.093256 2026] [security2:error] [pid 849392:tid 849608] [client 85.204.70.102:46342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muu.udi.temporary.site"] [uri "/website_45622194/wp-login.php"] [unique_id "amuSQwMgr4yz2OQW0xrKNAAAANo"]
[Thu Jul 30 13:04:51.093371 2026] [security2:error] [pid 849392:tid 849608] [client 85.204.70.102:46342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "muu.udi.temporary.site"] [uri "/website_45622194/wp-login.php"] [unique_id "amuSQwMgr4yz2OQW0xrKNAAAANo"]
[Thu Jul 30 13:04:51.140017 2026] [security2:error] [pid 849392:tid 849607] [client 74.248.96.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.96.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vanguardlegalassociates.team"] [uri "/chosen.php"] [unique_id "amuSQwMgr4yz2OQW0xrKNgAAANk"]
[Thu Jul 30 13:04:51.140117 2026] [security2:error] [pid 849392:tid 849607] [client 74.248.96.101:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.vanguardlegalassociates.team"] [uri "/chosen.php"] [unique_id "amuSQwMgr4yz2OQW0xrKNgAAANk"]
[Thu Jul 30 13:04:51.156603 2026] [core:notice] [pid 849392:tid 849649] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:51.236554 2026] [autoindex:error] [pid 849392:tid 849559] [client 85.204.70.102:46750] AH01276: Cannot serve directory /home1/muuudite/public_html/website_45622194/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:04:51.237207 2026] [security2:error] [pid 849392:tid 849559] [client 85.204.70.102:46750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "website-45622194.muu.udi.temporary.site"] [uri "/cgi-sys/403.html"] [unique_id "amuSQwMgr4yz2OQW0xrKOAAAAKk"]
[Thu Jul 30 13:04:51.300759 2026] [security2:error] [pid 849392:tid 849630] [client 20.63.98.115:37490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/doc.php"] [unique_id "amuSQwMgr4yz2OQW0xrKOQAAAPA"]
[Thu Jul 30 13:04:51.696555 2026] [proxy:error] [pid 849392:tid 849591] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:51.696647 2026] [proxy_http:error] [pid 849392:tid 849591] [client 52.4.19.39:15356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:51.697700 2026] [proxy:error] [pid 849392:tid 849591] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:51.697766 2026] [proxy_http:error] [pid 849392:tid 849591] [client 52.4.19.39:15356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:51.718702 2026] [proxy:error] [pid 849392:tid 849526] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:51.718797 2026] [proxy_http:error] [pid 849392:tid 849526] [client 52.4.19.39:29948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:51.719649 2026] [proxy:error] [pid 849392:tid 849526] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:04:51.719710 2026] [proxy_http:error] [pid 849392:tid 849526] [client 52.4.19.39:29948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:04:51.806924 2026] [core:notice] [pid 849392:tid 849552] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:04:51.923936 2026] [security2:error] [pid 849392:tid 849569] [client 172.236.9.101:53397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSQwMgr4yz2OQW0xrKQQAAALM"]
[Thu Jul 30 13:04:52.102697 2026] [security2:error] [pid 849392:tid 849573] [client 20.171.55.167:5798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/includes/index.php"] [unique_id "amuSRAMgr4yz2OQW0xrKXAAAALc"]
[Thu Jul 30 13:04:52.370128 2026] [security2:error] [pid 849392:tid 849618] [client 74.7.230.24:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "santaclaraimports.com"] [uri "/index.php"] [unique_id "amuSQgMgr4yz2OQW0xrKJQAAAOQ"]
[Thu Jul 30 13:04:52.632739 2026] [security2:error] [pid 849392:tid 849650] [client 20.52.125.110:12782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/files.php"] [unique_id "amuSRAMgr4yz2OQW0xrKagAAAQQ"]
[Thu Jul 30 13:04:52.910596 2026] [security2:error] [pid 849392:tid 849606] [client 172.236.9.101:1450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSRAMgr4yz2OQW0xrKYAAAANg"]
[Thu Jul 30 13:04:52.911991 2026] [security2:error] [pid 849392:tid 849558] [client 20.171.55.167:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-signup.php"] [unique_id "amuSRAMgr4yz2OQW0xrKbAAAAKg"]
[Thu Jul 30 13:04:53.362807 2026] [security2:error] [pid 849392:tid 849613] [client 20.52.125.110:12766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/gecko.php"] [unique_id "amuSRQMgr4yz2OQW0xrKfQAAAN8"]
[Thu Jul 30 13:04:54.073776 2026] [security2:error] [pid 849392:tid 849562] [client 20.63.98.115:49605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/02.php"] [unique_id "amuSRgMgr4yz2OQW0xrKjgAAAKw"]
[Thu Jul 30 13:04:54.308922 2026] [security2:error] [pid 849392:tid 849620] [client 66.249.66.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuSRQMgr4yz2OQW0xrKgwAA5gI"]
[Thu Jul 30 13:04:54.845312 2026] [security2:error] [pid 849392:tid 849619] [client 20.171.55.167:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/images/css.php"] [unique_id "amuSRgMgr4yz2OQW0xrKoAAAAOU"]
[Thu Jul 30 13:04:54.857082 2026] [security2:error] [pid 849392:tid 849546] [client 172.236.9.101:36175] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSRgMgr4yz2OQW0xrKlQAAAJw"]
[Thu Jul 30 13:04:54.898193 2026] [security2:error] [pid 849392:tid 849548] [client 43.172.195.216:46560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSRgMgr4yz2OQW0xrKmQAAAJ4"]
[Thu Jul 30 13:04:55.541500 2026] [security2:error] [pid 849392:tid 849542] [client 20.63.98.115:49601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/well-known/admin.php"] [unique_id "amuSRwMgr4yz2OQW0xrKsAAAAJg"]
[Thu Jul 30 13:04:55.630233 2026] [security2:error] [pid 849392:tid 849552] [client 20.52.125.110:12574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/zwso.php"] [unique_id "amuSRwMgr4yz2OQW0xrKtwAAAKI"]
[Thu Jul 30 13:04:55.794868 2026] [security2:error] [pid 849392:tid 849606] [client 20.171.55.167:5246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/chosen.php"] [unique_id "amuSRwMgr4yz2OQW0xrKuwAAANg"]
[Thu Jul 30 13:04:56.182926 2026] [security2:error] [pid 849392:tid 849630] [client 20.52.125.110:12750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/13.php"] [unique_id "amuSSAMgr4yz2OQW0xrKvwAAAPA"]
[Thu Jul 30 13:04:56.714960 2026] [security2:error] [pid 849392:tid 849635] [client 20.171.55.167:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/cong.php"] [unique_id "amuSSAMgr4yz2OQW0xrKywAAAPU"]
[Thu Jul 30 13:04:56.716638 2026] [security2:error] [pid 849392:tid 849602] [client 20.63.98.115:31773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/v.php"] [unique_id "amuSSAMgr4yz2OQW0xrKzAAAANQ"]
[Thu Jul 30 13:04:56.823247 2026] [security2:error] [pid 849392:tid 849591] [client 20.52.125.110:12481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/ava.php"] [unique_id "amuSSAMgr4yz2OQW0xrK0AAAAMk"]
[Thu Jul 30 13:04:57.159158 2026] [security2:error] [pid 849392:tid 849634] [client 74.7.230.45:53748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ysw.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuSSQMgr4yz2OQW0xrK1wAAAPQ"]
[Thu Jul 30 13:04:57.670113 2026] [security2:error] [pid 849392:tid 849548] [client 179.64.21.229:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSSQMgr4yz2OQW0xrK4wAAAJ4"]
[Thu Jul 30 13:04:57.677965 2026] [security2:error] [pid 849392:tid 849548] [client 179.64.21.229:28679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSSQMgr4yz2OQW0xrK4wAAAJ4"]
[Thu Jul 30 13:04:58.003497 2026] [security2:error] [pid 849392:tid 849561] [client 20.171.55.167:5812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/mah.php"] [unique_id "amuSSgMgr4yz2OQW0xrK6wAAAKs"]
[Thu Jul 30 13:04:58.387907 2026] [security2:error] [pid 849392:tid 849631] [client 20.52.125.110:12505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/main.php"] [unique_id "amuSSgMgr4yz2OQW0xrK9AAAAPE"]
[Thu Jul 30 13:04:59.032193 2026] [security2:error] [pid 849392:tid 849584] [client 20.52.125.110:12576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/wp-file.php"] [unique_id "amuSSwMgr4yz2OQW0xrLDAAAAMI"]
[Thu Jul 30 13:04:59.038845 2026] [security2:error] [pid 849392:tid 849640] [client 20.171.55.167:5800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuSSwMgr4yz2OQW0xrLDQAAAPo"]
[Thu Jul 30 13:04:59.737075 2026] [security2:error] [pid 849392:tid 849616] [client 172.236.9.101:30738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSSwMgr4yz2OQW0xrLEgAAAOI"]
[Thu Jul 30 13:04:59.877774 2026] [security2:error] [pid 849392:tid 849563] [client 20.171.55.167:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/ova-tools.php"] [unique_id "amuSSwMgr4yz2OQW0xrLHQAAAK0"]
[Thu Jul 30 13:05:00.026656 2026] [security2:error] [pid 849392:tid 849576] [client 20.52.125.110:12512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/wp-signin.php"] [unique_id "amuSTAMgr4yz2OQW0xrLJAAAALo"]
[Thu Jul 30 13:05:00.137418 2026] [security2:error] [pid 849392:tid 849474] [remote 57.141.0.48:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuSTAMgr4yz2OQW0xrLJQAAp1A"]
[Thu Jul 30 13:05:00.759308 2026] [security2:error] [pid 849392:tid 849617] [client 20.171.55.167:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuSTAMgr4yz2OQW0xrLNwAAAOM"]
[Thu Jul 30 13:05:00.764124 2026] [security2:error] [pid 849392:tid 849590] [client 85.208.96.208:43110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kayomanis.com"] [uri "/robots.txt"] [unique_id "amuSTAMgr4yz2OQW0xrLOAAAAMg"]
[Thu Jul 30 13:05:00.764213 2026] [security2:error] [pid 849392:tid 849590] [client 85.208.96.208:43110] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kayomanis.com"] [uri "/robots.txt"] [unique_id "amuSTAMgr4yz2OQW0xrLOAAAAMg"]
[Thu Jul 30 13:05:00.786560 2026] [security2:error] [pid 849392:tid 849597] [client 52.167.144.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuSTAMgr4yz2OQW0xrLMAAAAM8"]
[Thu Jul 30 13:05:00.799505 2026] [security2:error] [pid 849392:tid 849527] [client 172.236.9.101:50145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSTAMgr4yz2OQW0xrLKQAAAIk"]
[Thu Jul 30 13:05:00.976162 2026] [security2:error] [pid 849392:tid 849608] [client 20.52.125.110:12755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/simi.php"] [unique_id "amuSTAMgr4yz2OQW0xrLPwAAANo"]
[Thu Jul 30 13:05:01.400397 2026] [security2:error] [pid 849392:tid 849592] [client 52.167.144.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuSTQMgr4yz2OQW0xrLRQAAAMo"]
[Thu Jul 30 13:05:01.634299 2026] [security2:error] [pid 849392:tid 849648] [client 20.63.98.115:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/main.php"] [unique_id "amuSTQMgr4yz2OQW0xrLTwAAAQI"]
[Thu Jul 30 13:05:01.644351 2026] [security2:error] [pid 849392:tid 849475] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSTQMgr4yz2OQW0xrLUAAA_FE"]
[Thu Jul 30 13:05:01.644558 2026] [security2:error] [pid 849392:tid 849642] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSTQMgr4yz2OQW0xrLUAAA_FE"]
[Thu Jul 30 13:05:01.775890 2026] [security2:error] [pid 849392:tid 849556] [client 20.171.55.167:5818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuSTQMgr4yz2OQW0xrLVQAAAKY"]
[Thu Jul 30 13:05:01.783853 2026] [core:error] [pid 849392:tid 849626] [client 74.7.175.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:05:01.783873 2026] [core:error] [pid 849392:tid 849626] [client 74.7.175.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:05:01.784027 2026] [security2:error] [pid 849392:tid 849626] [client 74.7.175.187:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.jst.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuSTQMgr4yz2OQW0xrLVgAAAOw"]
[Thu Jul 30 13:05:01.784867 2026] [security2:error] [pid 849392:tid 849554] [client 74.7.175.187:37728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.jst.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuSTQMgr4yz2OQW0xrLUwAApE4"]
[Thu Jul 30 13:05:01.961270 2026] [security2:error] [pid 849392:tid 849570] [client 185.191.171.5:20114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kayomanis.com"] [uri "/staff/"] [unique_id "amuSTQMgr4yz2OQW0xrLXAAAALQ"]
[Thu Jul 30 13:05:01.961392 2026] [security2:error] [pid 849392:tid 849570] [client 185.191.171.5:20114] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kayomanis.com"] [uri "/staff/"] [unique_id "amuSTQMgr4yz2OQW0xrLXAAAALQ"]
[Thu Jul 30 13:05:02.215413 2026] [security2:error] [pid 849392:tid 849481] [remote 57.141.0.23:43192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/93381591101/feed/rss2/"] [unique_id "amuSTgMgr4yz2OQW0xrLZAAAt1c"]
[Thu Jul 30 13:05:02.549060 2026] [security2:error] [pid 849392:tid 849480] [remote 57.141.18.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSTgMgr4yz2OQW0xrLaAAAu1Y"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,cotton,denim,linen,plastic,titanium,nylon,wood,polyester&min_price=300&orderby=price&rating=5&status=instock&filter_brand=apple&unfilter=1
[Thu Jul 30 13:05:02.660308 2026] [security2:error] [pid 849392:tid 849601] [client 20.171.55.167:5198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuSTgMgr4yz2OQW0xrLdAAAANM"]
[Thu Jul 30 13:05:02.833972 2026] [security2:error] [pid 849392:tid 849548] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSTgMgr4yz2OQW0xrLZwAAAJ4"]
[Thu Jul 30 13:05:02.944891 2026] [security2:error] [pid 849392:tid 849636] [client 172.236.9.101:27688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSTgMgr4yz2OQW0xrLbAAAAPY"]
[Thu Jul 30 13:05:03.023094 2026] [security2:error] [pid 849392:tid 849567] [client 20.52.125.110:12764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/wp-conf.php"] [unique_id "amuSTwMgr4yz2OQW0xrLfwAAALE"]
[Thu Jul 30 13:05:03.297136 2026] [security2:error] [pid 849392:tid 849488] [remote 57.141.18.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSTwMgr4yz2OQW0xrLgAAA114"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,cotton,denim,linen,plastic,titanium,nylon,wood,polyester&min_price=300&orderby=price&rating=5&status=instock&filter_brand=apple&unfilter=1
[Thu Jul 30 13:05:03.373864 2026] [security2:error] [pid 849392:tid 849490] [remote 57.141.0.60:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amuSTwMgr4yz2OQW0xrLiwAA62A"]
[Thu Jul 30 13:05:03.527606 2026] [security2:error] [pid 849392:tid 849592] [client 20.171.55.167:6142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuSTwMgr4yz2OQW0xrLkgAAAMo"]
[Thu Jul 30 13:05:03.763155 2026] [security2:error] [pid 849392:tid 849630] [client 172.236.9.101:20739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSTwMgr4yz2OQW0xrLhwAAAPA"]
[Thu Jul 30 13:05:03.764720 2026] [proxy:error] [pid 849392:tid 849572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:03.764799 2026] [proxy_http:error] [pid 849392:tid 849572] [client 18.211.55.47:46924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:03.765766 2026] [proxy:error] [pid 849392:tid 849572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:03.765813 2026] [proxy_http:error] [pid 849392:tid 849572] [client 18.211.55.47:46924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:03.771111 2026] [proxy:error] [pid 849392:tid 849582] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:03.771186 2026] [proxy_http:error] [pid 849392:tid 849582] [client 18.211.55.47:37746] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:03.772011 2026] [proxy:error] [pid 849392:tid 849582] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:03.772064 2026] [proxy_http:error] [pid 849392:tid 849582] [client 18.211.55.47:37746] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:03.907467 2026] [security2:error] [pid 849392:tid 849638] [client 172.236.9.101:20771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSTwMgr4yz2OQW0xrLjQAAAPg"]
[Thu Jul 30 13:05:04.332560 2026] [security2:error] [pid 849392:tid 849619] [client 20.171.55.167:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/banners/about.php"] [unique_id "amuSUAMgr4yz2OQW0xrLsAAAAOU"]
[Thu Jul 30 13:05:04.943667 2026] [security2:error] [pid 849392:tid 849525] [client 20.63.98.115:1306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known/file.php"] [unique_id "amuSUAMgr4yz2OQW0xrLuwAAAIc"]
[Thu Jul 30 13:05:05.154943 2026] [security2:error] [pid 849392:tid 849530] [client 20.171.55.167:5724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/license.php"] [unique_id "amuSUQMgr4yz2OQW0xrLwQAAAIw"]
[Thu Jul 30 13:05:05.244204 2026] [security2:error] [pid 849392:tid 849635] [client 185.191.171.14:11934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/01/01/morre-na-italia-aos-83-anos-calisto-tanzi-o-fundador-da-parmalat/"] [unique_id "amuSUQMgr4yz2OQW0xrLxQAAAPU"]
[Thu Jul 30 13:05:05.244304 2026] [security2:error] [pid 849392:tid 849635] [client 185.191.171.14:11934] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/01/01/morre-na-italia-aos-83-anos-calisto-tanzi-o-fundador-da-parmalat/"] [unique_id "amuSUQMgr4yz2OQW0xrLxQAAAPU"]
[Thu Jul 30 13:05:05.261629 2026] [security2:error] [pid 849392:tid 849615] [client 20.52.125.110:12532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/WZGHHra0r3.php"] [unique_id "amuSUQMgr4yz2OQW0xrLxgAAAOE"]
[Thu Jul 30 13:05:05.316564 2026] [core:error] [pid 849392:tid 849517] [remote 34.239.166.69:40601] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:05:05.316588 2026] [core:error] [pid 849392:tid 849517] [remote 34.239.166.69:40601] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:05:05.542375 2026] [core:error] [pid 849392:tid 849496] [remote 34.239.166.69:40601] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:05:05.542397 2026] [core:error] [pid 849392:tid 849496] [remote 34.239.166.69:40601] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:05:05.782089 2026] [security2:error] [pid 849392:tid 849616] [client 43.153.58.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuSUQMgr4yz2OQW0xrL0gAAAOI"]
[Thu Jul 30 13:05:05.782743 2026] [security2:error] [pid 849392:tid 849534] [client 20.63.98.115:61955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuSUQMgr4yz2OQW0xrL2QAAAJA"]
[Thu Jul 30 13:05:05.906762 2026] [security2:error] [pid 849392:tid 849626] [client 172.236.9.101:28567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSUQMgr4yz2OQW0xrLywAAAOw"]
[Thu Jul 30 13:05:05.978508 2026] [security2:error] [pid 849392:tid 849646] [client 20.171.55.167:5190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/about.php"] [unique_id "amuSUQMgr4yz2OQW0xrL2gAAAQA"]
[Thu Jul 30 13:05:06.006752 2026] [security2:error] [pid 849392:tid 849599] [client 20.52.125.110:12494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/bala.php"] [unique_id "amuSUgMgr4yz2OQW0xrL2wAAANE"]
[Thu Jul 30 13:05:06.640365 2026] [core:notice] [pid 849392:tid 849641] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:06.880463 2026] [security2:error] [pid 849392:tid 849544] [client 20.52.125.110:12490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/bk.php"] [unique_id "amuSUgMgr4yz2OQW0xrL-AAAAJo"]
[Thu Jul 30 13:05:07.022874 2026] [security2:error] [pid 849392:tid 849602] [client 20.171.55.167:5706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/about.php"] [unique_id "amuSUwMgr4yz2OQW0xrL-gAAANQ"]
[Thu Jul 30 13:05:07.340661 2026] [core:notice] [pid 849392:tid 849509] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:07.824748 2026] [security2:error] [pid 849392:tid 849572] [client 20.171.55.167:5219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/Text/about.php"] [unique_id "amuSUwMgr4yz2OQW0xrMDgAAALY"]
[Thu Jul 30 13:05:08.161743 2026] [core:notice] [pid 849392:tid 849618] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:08.217804 2026] [security2:error] [pid 849392:tid 849626] [client 179.64.21.229:38245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSVAMgr4yz2OQW0xrMFgAAAOw"]
[Thu Jul 30 13:05:08.222186 2026] [security2:error] [pid 849392:tid 849626] [client 179.64.21.229:38245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSVAMgr4yz2OQW0xrMFgAAAOw"]
[Thu Jul 30 13:05:08.328044 2026] [core:notice] [pid 849392:tid 849559] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:08.333114 2026] [security2:error] [pid 849392:tid 849559] [client 35.240.54.252:42782] ModSecurity: Warning. Matched phrase "Dragonfly" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuSVAMgr4yz2OQW0xrMIAAAAKk"]
[Thu Jul 30 13:05:08.365155 2026] [security2:error] [pid 849392:tid 849639] [client 43.153.58.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuSVAMgr4yz2OQW0xrMGgAAAPk"], referer: https://cnpinyin.com/mycertificates
[Thu Jul 30 13:05:08.490792 2026] [core:notice] [pid 849392:tid 849403] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:08.496154 2026] [security2:error] [pid 849392:tid 849567] [client 35.240.54.252:36684] ModSecurity: Warning. Matched phrase "Dragonfly" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuSVAMgr4yz2OQW0xrMIQAAsQk"]
[Thu Jul 30 13:05:08.666138 2026] [core:notice] [pid 849392:tid 849413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:08.670429 2026] [security2:error] [pid 849392:tid 849608] [client 35.240.54.252:36684] ModSecurity: Warning. Matched phrase "Dragonfly" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuSVAMgr4yz2OQW0xrMJQAA2hM"]
[Thu Jul 30 13:05:08.842516 2026] [security2:error] [pid 849392:tid 849603] [client 20.171.55.167:6083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuSVAMgr4yz2OQW0xrMLAAAANU"]
[Thu Jul 30 13:05:08.939687 2026] [core:notice] [pid 849392:tid 849422] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:08.943967 2026] [security2:error] [pid 849392:tid 849591] [client 35.240.54.252:36684] ModSecurity: Warning. Matched phrase "Dragonfly" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuSVAMgr4yz2OQW0xrMMQAAyRw"]
[Thu Jul 30 13:05:09.263016 2026] [core:notice] [pid 849392:tid 849640] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:09.270292 2026] [security2:error] [pid 849392:tid 849640] [client 35.240.54.252:42782] ModSecurity: Warning. Matched phrase "Dragonfly" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/"] [unique_id "amuSVQMgr4yz2OQW0xrMPAAAAPo"]
[Thu Jul 30 13:05:09.582581 2026] [security2:error] [pid 849392:tid 849650] [client 20.52.125.110:12503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/ahax.php"] [unique_id "amuSVQMgr4yz2OQW0xrMRwAAAQQ"]
[Thu Jul 30 13:05:09.622827 2026] [security2:error] [pid 849392:tid 849418] [remote 57.141.18.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSVQMgr4yz2OQW0xrMSAAAwxg"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum,cotton,lycra,polyester,steel&filter_size=extra-large,extra-small,medium&status=instock&unfilter=1
[Thu Jul 30 13:05:09.647823 2026] [security2:error] [pid 849392:tid 849575] [client 43.153.58.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuSVQMgr4yz2OQW0xrMRgAAALk"], referer: https://cnpinyin.com/mycertificates/
[Thu Jul 30 13:05:09.773815 2026] [security2:error] [pid 849392:tid 849638] [client 20.171.55.167:5811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/img/about.php"] [unique_id "amuSVQMgr4yz2OQW0xrMTQAAAPg"]
[Thu Jul 30 13:05:10.067816 2026] [security2:error] [pid 849392:tid 849582] [client 2a03:2880:f800:46:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuSVQMgr4yz2OQW0xrMQgAAwCc"]
[Thu Jul 30 13:05:10.113673 2026] [security2:error] [pid 849392:tid 849432] [remote 57.141.18.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSVgMgr4yz2OQW0xrMVAAA3yY"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=nike&filter_materials=aluminum,cotton,lycra,polyester,steel&filter_size=extra-large,extra-small,medium&status=instock&unfilter=1
[Thu Jul 30 13:05:10.568481 2026] [security2:error] [pid 849392:tid 849621] [client 20.63.98.115:1290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuSVgMgr4yz2OQW0xrMXwAAAOc"]
[Thu Jul 30 13:05:10.644458 2026] [security2:error] [pid 849392:tid 849631] [client 20.171.55.167:6139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/languages/about.php"] [unique_id "amuSVgMgr4yz2OQW0xrMYAAAAPE"]
[Thu Jul 30 13:05:10.842072 2026] [security2:error] [pid 849392:tid 849623] [client 172.236.9.101:24475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSVgMgr4yz2OQW0xrMVQAAAOk"]
[Thu Jul 30 13:05:11.351531 2026] [security2:error] [pid 849392:tid 849429] [remote 74.7.241.60:53062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/article.php"] [unique_id "amuSVwMgr4yz2OQW0xrMdAAAwiM"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:05:11.352172 2026] [security2:error] [pid 849392:tid 849605] [client 20.63.98.115:31788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/file.php"] [unique_id "amuSVwMgr4yz2OQW0xrMdQAAANc"]
[Thu Jul 30 13:05:11.469992 2026] [security2:error] [pid 849392:tid 849648] [client 20.171.55.167:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/customize/about.php"] [unique_id "amuSVwMgr4yz2OQW0xrMfQAAAQI"]
[Thu Jul 30 13:05:11.767285 2026] [security2:error] [pid 849392:tid 849551] [client 172.236.9.101:56368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSVwMgr4yz2OQW0xrMbQAAAKE"]
[Thu Jul 30 13:05:12.323568 2026] [security2:error] [pid 849392:tid 849549] [client 20.63.98.115:61965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-signup.php"] [unique_id "amuSWAMgr4yz2OQW0xrMiQAAAJ8"]
[Thu Jul 30 13:05:12.372125 2026] [security2:error] [pid 849392:tid 849523] [client 20.171.55.167:5785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuSWAMgr4yz2OQW0xrMjgAAAIU"]
[Thu Jul 30 13:05:12.386145 2026] [security2:error] [pid 849392:tid 849447] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSWAMgr4yz2OQW0xrMjwAA5DU"]
[Thu Jul 30 13:05:12.386299 2026] [security2:error] [pid 849392:tid 849618] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSWAMgr4yz2OQW0xrMjwAA5DU"]
[Thu Jul 30 13:05:13.391311 2026] [security2:error] [pid 849392:tid 849562] [client 20.171.55.167:5783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuSWQMgr4yz2OQW0xrMogAAAKw"]
[Thu Jul 30 13:05:13.462355 2026] [security2:error] [pid 849392:tid 849617] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSWAMgr4yz2OQW0xrMmAAAAOM"]
[Thu Jul 30 13:05:13.879631 2026] [security2:error] [pid 849392:tid 849525] [client 172.236.9.101:37707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSWQMgr4yz2OQW0xrMowAAAIc"]
[Thu Jul 30 13:05:14.423702 2026] [security2:error] [pid 849392:tid 849551] [client 20.171.55.167:5724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuSWgMgr4yz2OQW0xrMtwAAAKE"]
[Thu Jul 30 13:05:14.715851 2026] [security2:error] [pid 849392:tid 849575] [client 172.236.9.101:37252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSWgMgr4yz2OQW0xrMtgAAALk"]
[Thu Jul 30 13:05:14.931934 2026] [security2:error] [pid 849392:tid 849610] [client 185.191.171.8:19314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/18/grupo-de-saude-da-transicao-avalia-revogar-normas-que-permitem-uso-do-cloroquina-para-covid-diz-senador/"] [unique_id "amuSWgMgr4yz2OQW0xrMwQAAANw"]
[Thu Jul 30 13:05:14.932107 2026] [security2:error] [pid 849392:tid 849610] [client 185.191.171.8:19314] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/18/grupo-de-saude-da-transicao-avalia-revogar-normas-que-permitem-uso-do-cloroquina-para-covid-diz-senador/"] [unique_id "amuSWgMgr4yz2OQW0xrMwQAAANw"]
[Thu Jul 30 13:05:15.341647 2026] [security2:error] [pid 849392:tid 849644] [client 20.171.55.167:5218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/js/about.php"] [unique_id "amuSWwMgr4yz2OQW0xrM1AAAAP4"]
[Thu Jul 30 13:05:16.277850 2026] [security2:error] [pid 849392:tid 849617] [client 20.171.55.167:5788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuSXAMgr4yz2OQW0xrM9AAAAOM"]
[Thu Jul 30 13:05:16.865450 2026] [security2:error] [pid 849392:tid 849539] [client 172.236.9.101:57105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSXAMgr4yz2OQW0xrM9QAAAJU"]
[Thu Jul 30 13:05:17.083855 2026] [security2:error] [pid 849392:tid 849632] [client 20.171.55.167:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuSXQMgr4yz2OQW0xrNAgAAAPI"]
[Thu Jul 30 13:05:17.097841 2026] [core:notice] [pid 849392:tid 849486] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:17.275428 2026] [security2:error] [pid 849392:tid 849512] [remote 192.250.227.149:56604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.227.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuSXQMgr4yz2OQW0xrNDgAArXY"]
[Thu Jul 30 13:05:17.596710 2026] [autoindex:error] [pid 849392:tid 849610] [client 43.165.195.234:37102] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:05:17.761736 2026] [core:notice] [pid 849392:tid 849519] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:17.883098 2026] [security2:error] [pid 849392:tid 849598] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuSXQMgr4yz2OQW0xrNHAAAANA"]
[Thu Jul 30 13:05:18.066432 2026] [security2:error] [pid 849392:tid 849540] [client 20.171.55.167:5718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuSXgMgr4yz2OQW0xrNHQAAAJY"]
[Thu Jul 30 13:05:18.146820 2026] [security2:error] [pid 849392:tid 849639] [client 82.102.18.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/xmlrpc.php"] [unique_id "amuSXgMgr4yz2OQW0xrNHwAAAPk"]
[Thu Jul 30 13:05:18.733333 2026] [security2:error] [pid 849392:tid 849532] [client 179.64.21.229:26072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSXgMgr4yz2OQW0xrNLQAAAI4"]
[Thu Jul 30 13:05:18.733471 2026] [security2:error] [pid 849392:tid 849532] [client 179.64.21.229:26072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSXgMgr4yz2OQW0xrNLQAAAI4"]
[Thu Jul 30 13:05:18.915303 2026] [security2:error] [pid 849392:tid 849578] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuSXgMgr4yz2OQW0xrNNAAAALw"]
[Thu Jul 30 13:05:19.053882 2026] [security2:error] [pid 849392:tid 849528] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuSXwMgr4yz2OQW0xrNNQAAAIo"]
[Thu Jul 30 13:05:19.311296 2026] [security2:error] [pid 849392:tid 849530] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuSXwMgr4yz2OQW0xrNOQAAAIw"]
[Thu Jul 30 13:05:19.619702 2026] [security2:error] [pid 849392:tid 849594] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuSXwMgr4yz2OQW0xrNRQAAAMw"]
[Thu Jul 30 13:05:19.826386 2026] [security2:error] [pid 849392:tid 849596] [client 20.171.55.167:5806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/updraft/about.php"] [unique_id "amuSXwMgr4yz2OQW0xrNSQAAAM4"]
[Thu Jul 30 13:05:19.862615 2026] [core:error] [pid 849392:tid 849407] [remote 74.7.228.8:47568] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:05:19.862638 2026] [core:error] [pid 849392:tid 849407] [remote 74.7.228.8:47568] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:05:19.862834 2026] [security2:error] [pid 849392:tid 849585] [client 74.7.228.8:47568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-976d73dd.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amuSXwMgr4yz2OQW0xrNTQAAww0"]
[Thu Jul 30 13:05:19.875419 2026] [security2:error] [pid 849392:tid 849572] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuSXwMgr4yz2OQW0xrNTgAAALY"]
[Thu Jul 30 13:05:20.138713 2026] [security2:error] [pid 849392:tid 849638] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuSYAMgr4yz2OQW0xrNUgAAAPg"]
[Thu Jul 30 13:05:20.335708 2026] [security2:error] [pid 849392:tid 849524] [client 20.151.254.105:1721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/file.php"] [unique_id "amuSYAMgr4yz2OQW0xrNVgAAAIY"]
[Thu Jul 30 13:05:20.335802 2026] [security2:error] [pid 849392:tid 849524] [client 20.151.254.105:1721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/file.php"] [unique_id "amuSYAMgr4yz2OQW0xrNVgAAAIY"]
[Thu Jul 30 13:05:20.391212 2026] [security2:error] [pid 849392:tid 849552] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuSYAMgr4yz2OQW0xrNWgAAAKI"]
[Thu Jul 30 13:05:20.650427 2026] [security2:error] [pid 849392:tid 849597] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuSYAMgr4yz2OQW0xrNXgAAAM8"]
[Thu Jul 30 13:05:20.729727 2026] [security2:error] [pid 849392:tid 849589] [client 20.171.55.167:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuSYAMgr4yz2OQW0xrNXwAAAMc"]
[Thu Jul 30 13:05:20.907098 2026] [security2:error] [pid 849392:tid 849538] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuSYAMgr4yz2OQW0xrNaQAAAJQ"]
[Thu Jul 30 13:05:21.003368 2026] [security2:error] [pid 849392:tid 849609] [client 20.63.98.115:1060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuSYQMgr4yz2OQW0xrNcAAAANs"]
[Thu Jul 30 13:05:21.210667 2026] [security2:error] [pid 849392:tid 849562] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuSYQMgr4yz2OQW0xrNcQAAAKw"]
[Thu Jul 30 13:05:21.466354 2026] [security2:error] [pid 849392:tid 849583] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuSYQMgr4yz2OQW0xrNewAAAME"]
[Thu Jul 30 13:05:21.589567 2026] [security2:error] [pid 849392:tid 849557] [client 20.171.55.167:6119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/themes/about.php"] [unique_id "amuSYQMgr4yz2OQW0xrNfwAAAKc"]
[Thu Jul 30 13:05:21.722254 2026] [security2:error] [pid 849392:tid 849607] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuSYQMgr4yz2OQW0xrNgAAAANk"]
[Thu Jul 30 13:05:21.734633 2026] [security2:error] [pid 849392:tid 849645] [client 172.236.9.101:23599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSYQMgr4yz2OQW0xrNcgAAAP8"]
[Thu Jul 30 13:05:21.979700 2026] [security2:error] [pid 849392:tid 849616] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuSYQMgr4yz2OQW0xrNigAAAOI"]
[Thu Jul 30 13:05:22.146852 2026] [security2:error] [pid 849392:tid 849648] [client 20.63.98.115:34451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ge.php"] [unique_id "amuSYgMgr4yz2OQW0xrNjAAAAQI"]
[Thu Jul 30 13:05:22.306946 2026] [security2:error] [pid 849392:tid 849551] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuSYgMgr4yz2OQW0xrNjQAAAKE"]
[Thu Jul 30 13:05:22.406610 2026] [security2:error] [pid 849392:tid 849561] [client 20.171.55.167:6129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/includes/about.php"] [unique_id "amuSYgMgr4yz2OQW0xrNkwAAAKs"]
[Thu Jul 30 13:05:22.589439 2026] [security2:error] [pid 849392:tid 849548] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuSYgMgr4yz2OQW0xrNmwAAAJ4"]
[Thu Jul 30 13:05:22.844909 2026] [security2:error] [pid 849392:tid 849601] [client 82.102.18.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nexiummedication.store"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuSYgMgr4yz2OQW0xrNnQAAANM"]
[Thu Jul 30 13:05:22.859415 2026] [security2:error] [pid 849392:tid 849596] [client 172.236.9.101:44199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSYgMgr4yz2OQW0xrNkQAAAM4"]
[Thu Jul 30 13:05:23.021203 2026] [security2:error] [pid 849392:tid 849434] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSYwMgr4yz2OQW0xrNqgAAkyg"]
[Thu Jul 30 13:05:23.021434 2026] [security2:error] [pid 849392:tid 849537] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSYwMgr4yz2OQW0xrNqgAAkyg"]
[Thu Jul 30 13:05:23.043715 2026] [core:notice] [pid 849392:tid 849624] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:23.259675 2026] [security2:error] [pid 849392:tid 849571] [client 20.171.55.167:5242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/images/about.php"] [unique_id "amuSYwMgr4yz2OQW0xrNrgAAALU"]
[Thu Jul 30 13:05:23.422297 2026] [security2:error] [pid 849392:tid 849575] [client 20.63.98.115:62773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/goods.php"] [unique_id "amuSYwMgr4yz2OQW0xrNsgAAALk"]
[Thu Jul 30 13:05:24.143336 2026] [security2:error] [pid 849392:tid 849630] [client 20.171.55.167:5244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuSZAMgr4yz2OQW0xrNzwAAAPA"]
[Thu Jul 30 13:05:24.314793 2026] [security2:error] [pid 849392:tid 849605] [client 20.63.98.115:53583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/403.php"] [unique_id "amuSZAMgr4yz2OQW0xrN0AAAANc"]
[Thu Jul 30 13:05:25.139403 2026] [security2:error] [pid 849392:tid 849577] [client 20.63.98.115:34492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/public/makeasmtp.php"] [unique_id "amuSZQMgr4yz2OQW0xrN5AAAALs"]
[Thu Jul 30 13:05:25.228043 2026] [security2:error] [pid 849392:tid 849596] [client 20.171.55.167:5799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/images/about.php"] [unique_id "amuSZQMgr4yz2OQW0xrN6QAAAM4"]
[Thu Jul 30 13:05:25.310307 2026] [security2:error] [pid 849392:tid 849643] [client 20.151.254.105:63604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/adminfuns.php"] [unique_id "amuSZQMgr4yz2OQW0xrN6wAAAP0"]
[Thu Jul 30 13:05:25.310418 2026] [security2:error] [pid 849392:tid 849643] [client 20.151.254.105:63604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/adminfuns.php"] [unique_id "amuSZQMgr4yz2OQW0xrN6wAAAP0"]
[Thu Jul 30 13:05:25.389675 2026] [security2:error] [pid 849392:tid 849440] [remote 57.141.18.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSZQMgr4yz2OQW0xrN4gAAxy4"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,polyester,cotton,denim,aluminum,nylon,steel,silicon,lycra,titanium&filter_size=extra-large,extra-small&orderby=rating&rating=5&unfilter=1
[Thu Jul 30 13:05:25.556461 2026] [security2:error] [pid 849392:tid 849465] [remote 57.141.18.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSZQMgr4yz2OQW0xrN7AAAskc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,polyester,cotton,denim,aluminum,nylon,steel,silicon,lycra,titanium&filter_size=extra-large,extra-small&orderby=rating&rating=5&unfilter=1
[Thu Jul 30 13:05:26.106285 2026] [security2:error] [pid 849392:tid 849565] [client 20.171.55.167:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/about.php"] [unique_id "amuSZgMgr4yz2OQW0xrN_AAAAK8"]
[Thu Jul 30 13:05:26.983219 2026] [security2:error] [pid 849392:tid 849472] [remote 57.141.18.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSZgMgr4yz2OQW0xrODgAAxU4"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=supreme&filter_materials=aluminum,carbon,cotton,lycra,nylon,plastic,polyester,steel,denim&orderby=menu_order&rating=5&status=instock&unfilter=1
[Thu Jul 30 13:05:26.983276 2026] [security2:error] [pid 849392:tid 849560] [client 20.171.55.167:5728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/about.php"] [unique_id "amuSZgMgr4yz2OQW0xrODwAAAKo"]
[Thu Jul 30 13:05:27.122005 2026] [security2:error] [pid 849392:tid 849475] [remote 57.141.18.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSZgMgr4yz2OQW0xrODQAAt1E"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=supreme&filter_materials=aluminum,carbon,cotton,lycra,nylon,plastic,polyester,steel,denim&orderby=menu_order&rating=5&status=instock&unfilter=1
[Thu Jul 30 13:05:27.853268 2026] [security2:error] [pid 849392:tid 849647] [client 20.171.55.167:5734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/gallery/about.php"] [unique_id "amuSZwMgr4yz2OQW0xrOIwAAAQE"]
[Thu Jul 30 13:05:27.858014 2026] [security2:error] [pid 849392:tid 849619] [client 183.134.40.82:21396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuSZwMgr4yz2OQW0xrOGQAAAOU"]
[Thu Jul 30 13:05:28.860445 2026] [security2:error] [pid 849392:tid 849595] [client 20.171.55.167:5702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuSaAMgr4yz2OQW0xrOOQAAAM0"]
[Thu Jul 30 13:05:29.502847 2026] [security2:error] [pid 849392:tid 849620] [client 179.64.21.229:46352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSaQMgr4yz2OQW0xrORwAAAOY"]
[Thu Jul 30 13:05:29.514537 2026] [security2:error] [pid 849392:tid 849620] [client 179.64.21.229:46352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSaQMgr4yz2OQW0xrORwAAAOY"]
[Thu Jul 30 13:05:29.528111 2026] [security2:error] [pid 849392:tid 849623] [client 204.8.98.105:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuSaQMgr4yz2OQW0xrOSAAAAOk"]
[Thu Jul 30 13:05:29.528224 2026] [security2:error] [pid 849392:tid 849623] [client 204.8.98.105:51076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuSaQMgr4yz2OQW0xrOSAAAAOk"]
[Thu Jul 30 13:05:29.601288 2026] [security2:error] [pid 849392:tid 849582] [client 20.63.98.115:44069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/mar.php"] [unique_id "amuSaQMgr4yz2OQW0xrOSQAAAMA"]
[Thu Jul 30 13:05:29.698727 2026] [security2:error] [pid 849392:tid 849626] [client 20.171.55.167:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/about.php"] [unique_id "amuSaQMgr4yz2OQW0xrOSgAAAOw"]
[Thu Jul 30 13:05:29.733810 2026] [security2:error] [pid 849392:tid 849633] [client 172.236.9.101:7313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSaQMgr4yz2OQW0xrOQAAAAPM"]
[Thu Jul 30 13:05:29.966825 2026] [proxy:error] [pid 849392:tid 849603] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:29.966912 2026] [proxy_http:error] [pid 849392:tid 849603] [client 44.213.206.96:23122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:29.967678 2026] [proxy:error] [pid 849392:tid 849603] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:29.967734 2026] [proxy_http:error] [pid 849392:tid 849603] [client 44.213.206.96:23122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:29.968429 2026] [proxy:error] [pid 849392:tid 849543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:29.968488 2026] [proxy_http:error] [pid 849392:tid 849543] [client 44.213.206.96:61163] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:29.969081 2026] [proxy:error] [pid 849392:tid 849543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:29.969130 2026] [proxy_http:error] [pid 849392:tid 849543] [client 44.213.206.96:61163] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:30.346916 2026] [security2:error] [pid 849392:tid 849553] [client 20.151.254.105:22615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/404.php"] [unique_id "amuSagMgr4yz2OQW0xrObwAAAKM"]
[Thu Jul 30 13:05:30.347056 2026] [security2:error] [pid 849392:tid 849553] [client 20.151.254.105:22615] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/404.php"] [unique_id "amuSagMgr4yz2OQW0xrObwAAAKM"]
[Thu Jul 30 13:05:30.517799 2026] [core:notice] [pid 849392:tid 849503] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:30.567482 2026] [security2:error] [pid 849392:tid 849563] [client 50.6.43.217:40556] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuSagMgr4yz2OQW0xrOdwAAAK0"]
[Thu Jul 30 13:05:30.585380 2026] [security2:error] [pid 849392:tid 849558] [client 50.6.43.217:40568] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuSagMgr4yz2OQW0xrOeAAAAKg"]
[Thu Jul 30 13:05:30.600335 2026] [security2:error] [pid 849392:tid 849628] [client 50.6.43.217:40570] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuSagMgr4yz2OQW0xrOeQAAAO4"]
[Thu Jul 30 13:05:30.604901 2026] [security2:error] [pid 849392:tid 849625] [client 20.171.55.167:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/images/about.php"] [unique_id "amuSagMgr4yz2OQW0xrOewAAAOs"]
[Thu Jul 30 13:05:30.605265 2026] [security2:error] [pid 849392:tid 849621] [client 74.7.175.171:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-aa23bb9f.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuSaQMgr4yz2OQW0xrOUAAAAOc"]
[Thu Jul 30 13:05:30.606064 2026] [security2:error] [pid 849392:tid 849597] [client 74.7.175.171:47178] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-aa23bb9f.dlr.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuSaQMgr4yz2OQW0xrOTgAAz2o"]
[Thu Jul 30 13:05:30.615269 2026] [security2:error] [pid 849392:tid 849525] [client 50.6.43.217:40584] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuSagMgr4yz2OQW0xrOegAAAIc"]
[Thu Jul 30 13:05:30.658882 2026] [security2:error] [pid 849392:tid 849566] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuSagMgr4yz2OQW0xrObQAAALA"]
[Thu Jul 30 13:05:30.717314 2026] [core:notice] [pid 849392:tid 849548] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:30.756584 2026] [core:notice] [pid 849392:tid 849486] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:31.173594 2026] [security2:error] [pid 849392:tid 849624] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuSagMgr4yz2OQW0xrOhAAAAOo"]
[Thu Jul 30 13:05:31.365808 2026] [security2:error] [pid 849392:tid 849538] [client 20.63.98.115:36671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/system.php"] [unique_id "amuSawMgr4yz2OQW0xrOkQAAAJQ"]
[Thu Jul 30 13:05:31.479769 2026] [security2:error] [pid 849392:tid 849531] [client 223.109.252.215:57448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuSawMgr4yz2OQW0xrOmAAAAI0"]
[Thu Jul 30 13:05:31.479860 2026] [security2:error] [pid 849392:tid 849531] [client 223.109.252.215:57448] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuSawMgr4yz2OQW0xrOmAAAAI0"]
[Thu Jul 30 13:05:31.519859 2026] [security2:error] [pid 849392:tid 849619] [client 20.171.55.167:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuSawMgr4yz2OQW0xrOmQAAAOU"]
[Thu Jul 30 13:05:31.948289 2026] [security2:error] [pid 849392:tid 849556] [client 213.152.161.240:54156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuSawMgr4yz2OQW0xrOoQAAAKY"]
[Thu Jul 30 13:05:31.948383 2026] [security2:error] [pid 849392:tid 849556] [client 213.152.161.240:54156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuSawMgr4yz2OQW0xrOoQAAAKY"]
[Thu Jul 30 13:05:32.244806 2026] [core:notice] [pid 849392:tid 849630] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:32.291492 2026] [proxy:error] [pid 849392:tid 849561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:32.291582 2026] [proxy_http:error] [pid 849392:tid 849561] [client 44.213.206.96:1790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:32.292228 2026] [proxy:error] [pid 849392:tid 849561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:32.292279 2026] [proxy_http:error] [pid 849392:tid 849561] [client 44.213.206.96:1790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:32.306535 2026] [proxy:error] [pid 849392:tid 849631] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:32.306611 2026] [proxy_http:error] [pid 849392:tid 849631] [client 52.4.19.39:42109] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:32.307366 2026] [proxy:error] [pid 849392:tid 849631] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:32.307419 2026] [proxy_http:error] [pid 849392:tid 849631] [client 52.4.19.39:42109] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:32.562526 2026] [security2:error] [pid 849392:tid 849574] [client 20.171.55.167:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuSbAMgr4yz2OQW0xrOtQAAALg"]
[Thu Jul 30 13:05:32.747377 2026] [security2:error] [pid 849392:tid 849628] [client 20.63.98.115:59530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/lock360.php"] [unique_id "amuSbAMgr4yz2OQW0xrOtwAAAO4"]
[Thu Jul 30 13:05:32.765192 2026] [security2:error] [pid 849392:tid 849650] [client 172.236.9.101:23134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSbAMgr4yz2OQW0xrOpwAAAQQ"]
[Thu Jul 30 13:05:33.490390 2026] [security2:error] [pid 849392:tid 849620] [client 20.171.55.167:5188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuSbQMgr4yz2OQW0xrOyAAAAOY"]
[Thu Jul 30 13:05:33.550394 2026] [security2:error] [pid 849392:tid 849593] [client 20.151.254.105:23961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/wk/index.php"] [unique_id "amuSbQMgr4yz2OQW0xrOzAAAAMs"]
[Thu Jul 30 13:05:33.550513 2026] [security2:error] [pid 849392:tid 849593] [client 20.151.254.105:23961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/wk/index.php"] [unique_id "amuSbQMgr4yz2OQW0xrOzAAAAMs"]
[Thu Jul 30 13:05:33.801073 2026] [security2:error] [pid 849392:tid 849499] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSbQMgr4yz2OQW0xrO0AAAxGk"]
[Thu Jul 30 13:05:33.801291 2026] [security2:error] [pid 849392:tid 849586] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSbQMgr4yz2OQW0xrO0AAAxGk"]
[Thu Jul 30 13:05:33.841634 2026] [security2:error] [pid 849392:tid 849521] [remote 94.23.188.196:59154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/nice-support/"] [unique_id "amuSbQMgr4yz2OQW0xrO0QAA4H8"]
[Thu Jul 30 13:05:33.841835 2026] [security2:error] [pid 849392:tid 849614] [client 94.23.188.196:59154] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/nice-support/"] [unique_id "amuSbQMgr4yz2OQW0xrO0QAA4H8"]
[Thu Jul 30 13:05:33.898203 2026] [security2:error] [pid 849392:tid 849623] [client 172.236.9.101:63028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSbQMgr4yz2OQW0xrOwwAAAOk"]
[Thu Jul 30 13:05:34.068965 2026] [security2:error] [pid 849392:tid 849587] [client 20.63.98.115:39570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amuSbgMgr4yz2OQW0xrO2AAAAMU"]
[Thu Jul 30 13:05:34.384630 2026] [security2:error] [pid 849392:tid 849641] [client 20.171.55.167:5817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cloud.php"] [unique_id "amuSbgMgr4yz2OQW0xrO3gAAAPs"]
[Thu Jul 30 13:05:34.982822 2026] [security2:error] [pid 849392:tid 849585] [client 20.63.98.115:37268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/mah.php"] [unique_id "amuSbgMgr4yz2OQW0xrO6AAAAMM"]
[Thu Jul 30 13:05:35.163178 2026] [security2:error] [pid 849392:tid 849542] [client 20.171.55.167:5822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/cloud.php"] [unique_id "amuSbwMgr4yz2OQW0xrO8QAAAJg"]
[Thu Jul 30 13:05:35.945275 2026] [security2:error] [pid 849392:tid 849576] [client 20.171.55.167:5814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/updates.php"] [unique_id "amuSbwMgr4yz2OQW0xrO_gAAALo"]
[Thu Jul 30 13:05:36.304067 2026] [security2:error] [pid 849392:tid 849624] [client 20.63.98.115:1542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-class.php"] [unique_id "amuScAMgr4yz2OQW0xrPCgAAAOo"]
[Thu Jul 30 13:05:36.799602 2026] [security2:error] [pid 849392:tid 849568] [client 20.151.254.105:15126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/about.php"] [unique_id "amuScAMgr4yz2OQW0xrPFAAAALI"]
[Thu Jul 30 13:05:36.799706 2026] [security2:error] [pid 849392:tid 849568] [client 20.151.254.105:15126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/about.php"] [unique_id "amuScAMgr4yz2OQW0xrPFAAAALI"]
[Thu Jul 30 13:05:36.822162 2026] [security2:error] [pid 849392:tid 849567] [client 20.171.55.167:5698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/css/cloud.php"] [unique_id "amuScAMgr4yz2OQW0xrPFQAAALE"]
[Thu Jul 30 13:05:37.682669 2026] [security2:error] [pid 849392:tid 849634] [client 20.171.55.167:6140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuScQMgr4yz2OQW0xrPKAAAAPQ"]
[Thu Jul 30 13:05:37.915635 2026] [security2:error] [pid 849392:tid 849564] [client 172.236.9.101:61485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScQMgr4yz2OQW0xrPJAAAAK4"]
[Thu Jul 30 13:05:38.553930 2026] [security2:error] [pid 849392:tid 849552] [client 20.171.55.167:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/img/cloud.php"] [unique_id "amuScgMgr4yz2OQW0xrPTAAAAKI"]
[Thu Jul 30 13:05:39.342995 2026] [security2:error] [pid 849392:tid 849637] [client 172.237.109.114:8401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPMAAAAPc"]
[Thu Jul 30 13:05:39.356763 2026] [security2:error] [pid 849392:tid 849574] [client 172.237.109.114:31795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPMQAAALg"]
[Thu Jul 30 13:05:39.379639 2026] [security2:error] [pid 849392:tid 849647] [client 20.171.55.167:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuScwMgr4yz2OQW0xrPjwAAAQE"]
[Thu Jul 30 13:05:39.468815 2026] [security2:error] [pid 849392:tid 849628] [client 172.237.109.114:37044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPNgAAAO4"]
[Thu Jul 30 13:05:39.475779 2026] [security2:error] [pid 849392:tid 849597] [client 172.237.109.114:62847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPMwAAAM8"]
[Thu Jul 30 13:05:39.478313 2026] [security2:error] [pid 849392:tid 849525] [client 172.237.109.114:22657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPNAAAAIc"]
[Thu Jul 30 13:05:39.483570 2026] [security2:error] [pid 849392:tid 849558] [client 172.237.109.114:40959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPMgAAAKg"]
[Thu Jul 30 13:05:39.488761 2026] [security2:error] [pid 849392:tid 849615] [client 172.237.109.114:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPNQAAAOE"]
[Thu Jul 30 13:05:39.488761 2026] [security2:error] [pid 849392:tid 849622] [client 172.237.109.114:19597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPOwAAAOg"]
[Thu Jul 30 13:05:39.492666 2026] [security2:error] [pid 849392:tid 849549] [client 172.237.109.114:60639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPOgAAAJ8"]
[Thu Jul 30 13:05:39.495218 2026] [security2:error] [pid 849392:tid 849579] [client 172.237.109.114:56548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPNwAAAL0"]
[Thu Jul 30 13:05:39.502865 2026] [security2:error] [pid 849392:tid 849527] [client 172.237.109.114:10369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPOAAAAIk"]
[Thu Jul 30 13:05:39.511858 2026] [security2:error] [pid 849392:tid 849629] [client 172.237.109.114:44621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPOQAAAO8"]
[Thu Jul 30 13:05:39.517732 2026] [security2:error] [pid 849392:tid 849581] [client 172.237.109.114:38877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPPgAAAL8"]
[Thu Jul 30 13:05:39.517752 2026] [security2:error] [pid 849392:tid 849610] [client 172.237.109.114:17561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPPQAAANw"]
[Thu Jul 30 13:05:39.519624 2026] [security2:error] [pid 849392:tid 849555] [client 172.237.109.114:38508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPPwAAAKU"]
[Thu Jul 30 13:05:39.521939 2026] [security2:error] [pid 849392:tid 849572] [client 172.237.109.114:64860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuScgMgr4yz2OQW0xrPPAAAALY"]
[Thu Jul 30 13:05:39.816676 2026] [security2:error] [pid 849392:tid 849641] [client 20.63.98.115:58831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/backup.php"] [unique_id "amuScwMgr4yz2OQW0xrPlAAAAPs"]
[Thu Jul 30 13:05:39.997720 2026] [proxy:error] [pid 849392:tid 849602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:39.997775 2026] [proxy_http:error] [pid 849392:tid 849602] [client 74.7.230.29:41162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:39.998357 2026] [proxy:error] [pid 849392:tid 849602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:39.998402 2026] [proxy_http:error] [pid 849392:tid 849602] [client 74.7.230.29:41162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:39.998499 2026] [security2:error] [pid 849392:tid 849602] [client 74.7.230.29:41162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.rmo.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuScwMgr4yz2OQW0xrPmwAAANQ"]
[Thu Jul 30 13:05:40.194525 2026] [security2:error] [pid 849392:tid 849483] [remote 87.250.224.4:36300] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/the-largest-container-ship-in-the-world-arrived/"] [unique_id "amuSdAMgr4yz2OQW0xrPoAAA9lk"]
[Thu Jul 30 13:05:40.250805 2026] [security2:error] [pid 849392:tid 849650] [client 20.171.55.167:6093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuSdAMgr4yz2OQW0xrPogAAAQQ"]
[Thu Jul 30 13:05:40.635603 2026] [security2:error] [pid 849392:tid 849618] [client 172.237.109.114:34308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSdAMgr4yz2OQW0xrPngAAAOQ"]
[Thu Jul 30 13:05:40.642830 2026] [security2:error] [pid 849392:tid 849551] [client 172.237.109.114:51017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSdAMgr4yz2OQW0xrPnAAAAKE"]
[Thu Jul 30 13:05:40.651556 2026] [security2:error] [pid 849392:tid 849536] [client 172.237.109.114:30676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSdAMgr4yz2OQW0xrPnQAAAJI"]
[Thu Jul 30 13:05:40.654766 2026] [security2:error] [pid 849392:tid 849638] [client 172.237.109.114:48210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSdAMgr4yz2OQW0xrPnwAAAPg"]
[Thu Jul 30 13:05:40.755431 2026] [security2:error] [pid 849392:tid 849644] [client 172.236.9.101:61839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSdAMgr4yz2OQW0xrPoQAAAP4"]
[Thu Jul 30 13:05:40.872497 2026] [security2:error] [pid 849392:tid 849545] [client 20.151.254.105:20789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/term.php"] [unique_id "amuSdAMgr4yz2OQW0xrPuAAAAJs"]
[Thu Jul 30 13:05:40.872595 2026] [security2:error] [pid 849392:tid 849545] [client 20.151.254.105:20789] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/term.php"] [unique_id "amuSdAMgr4yz2OQW0xrPuAAAAJs"]
[Thu Jul 30 13:05:41.082293 2026] [security2:error] [pid 849392:tid 849575] [client 20.171.55.167:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/avaa.php"] [unique_id "amuSdQMgr4yz2OQW0xrPvQAAALk"]
[Thu Jul 30 13:05:42.019258 2026] [core:notice] [pid 849392:tid 849625] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:42.082567 2026] [security2:error] [pid 849392:tid 849595] [client 20.171.55.167:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/images/cloud.php"] [unique_id "amuSdgMgr4yz2OQW0xrP0wAAAM0"]
[Thu Jul 30 13:05:42.391575 2026] [security2:error] [pid 849392:tid 849596] [client 20.63.98.115:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/default.php"] [unique_id "amuSdgMgr4yz2OQW0xrP1wAAAM4"]
[Thu Jul 30 13:05:42.599152 2026] [security2:error] [pid 849392:tid 849513] [remote 57.141.0.16:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/407345907/feed/rss2/"] [unique_id "amuSdgMgr4yz2OQW0xrP1AAAs3c"]
[Thu Jul 30 13:05:42.954720 2026] [security2:error] [pid 849392:tid 849636] [client 20.171.55.167:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuSdgMgr4yz2OQW0xrP4wAAAPY"]
[Thu Jul 30 13:05:43.628851 2026] [security2:error] [pid 849392:tid 849633] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSdwMgr4yz2OQW0xrP5gAAAPM"]
[Thu Jul 30 13:05:43.736015 2026] [security2:error] [pid 849392:tid 849612] [client 172.236.9.101:2746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSdwMgr4yz2OQW0xrP7QAAAN4"]
[Thu Jul 30 13:05:43.993049 2026] [security2:error] [pid 849392:tid 849529] [client 20.171.55.167:5704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuSdwMgr4yz2OQW0xrP_AAAAIs"]
[Thu Jul 30 13:05:44.173859 2026] [security2:error] [pid 849392:tid 849639] [client 20.63.98.115:1998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/maint/about.php"] [unique_id "amuSeAMgr4yz2OQW0xrP_QAAAPk"]
[Thu Jul 30 13:05:44.224235 2026] [security2:error] [pid 849392:tid 849628] [client 52.28.162.93:39502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuSeAMgr4yz2OQW0xrQAAAAAO4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:05:44.575576 2026] [security2:error] [pid 849392:tid 849406] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSeAMgr4yz2OQW0xrQCAAAoww"]
[Thu Jul 30 13:05:44.575725 2026] [security2:error] [pid 849392:tid 849553] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSeAMgr4yz2OQW0xrQCAAAoww"]
[Thu Jul 30 13:05:44.720426 2026] [core:notice] [pid 849392:tid 849555] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:44.726072 2026] [security2:error] [pid 849392:tid 849555] [client 52.28.162.93:39510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuSeAMgr4yz2OQW0xrQCQAAAKU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:05:45.377125 2026] [security2:error] [pid 849392:tid 849631] [client 20.63.98.115:2044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amuSeQMgr4yz2OQW0xrQGgAAAPE"]
[Thu Jul 30 13:05:45.431872 2026] [security2:error] [pid 849392:tid 849621] [client 52.28.162.93:39526] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuSeQMgr4yz2OQW0xrQGwAAAOc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:05:45.918699 2026] [security2:error] [pid 849392:tid 849571] [client 20.151.254.105:1867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/ioxi-o.php"] [unique_id "amuSeQMgr4yz2OQW0xrQKAAAALU"]
[Thu Jul 30 13:05:45.918863 2026] [security2:error] [pid 849392:tid 849571] [client 20.151.254.105:1867] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/ioxi-o.php"] [unique_id "amuSeQMgr4yz2OQW0xrQKAAAALU"]
[Thu Jul 30 13:05:46.113751 2026] [security2:error] [pid 849392:tid 849548] [client 20.171.55.167:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuSegMgr4yz2OQW0xrQLwAAAJ4"]
[Thu Jul 30 13:05:46.509012 2026] [security2:error] [pid 849392:tid 849536] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSeQMgr4yz2OQW0xrQKwAAAJI"]
[Thu Jul 30 13:05:46.513419 2026] [core:notice] [pid 849392:tid 849580] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:46.565761 2026] [core:notice] [pid 849392:tid 849587] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:47.042073 2026] [security2:error] [pid 849392:tid 849647] [client 20.171.55.167:5808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuSewMgr4yz2OQW0xrQRAAAAQE"]
[Thu Jul 30 13:05:47.375470 2026] [security2:error] [pid 849392:tid 849411] [remote 57.141.0.68:26936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amuSewMgr4yz2OQW0xrQTQAAzBE"]
[Thu Jul 30 13:05:47.787744 2026] [proxy:error] [pid 849392:tid 849576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:47.787811 2026] [proxy_http:error] [pid 849392:tid 849576] [client 52.4.19.39:59986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:47.788409 2026] [proxy:error] [pid 849392:tid 849576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:47.788458 2026] [proxy_http:error] [pid 849392:tid 849576] [client 52.4.19.39:59986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:47.833745 2026] [proxy:error] [pid 849392:tid 849526] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:47.833828 2026] [proxy_http:error] [pid 849392:tid 849526] [client 52.4.19.39:65126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:47.834615 2026] [proxy:error] [pid 849392:tid 849526] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:47.834669 2026] [proxy_http:error] [pid 849392:tid 849526] [client 52.4.19.39:65126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:47.945088 2026] [security2:error] [pid 849392:tid 849424] [remote 40.77.167.74:8977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/1119223232/article.php"] [unique_id "amuSewMgr4yz2OQW0xrQZAAAwB4"]
[Thu Jul 30 13:05:48.079504 2026] [security2:error] [pid 849392:tid 849641] [client 20.171.55.167:5804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuSfAMgr4yz2OQW0xrQaAAAAPs"]
[Thu Jul 30 13:05:48.432167 2026] [security2:error] [pid 849392:tid 849548] [client 172.236.9.101:25125] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/user_secrets.yml.old"] [unique_id "amuSfAMgr4yz2OQW0xrQbwAAAJ4"]
[Thu Jul 30 13:05:48.652946 2026] [security2:error] [pid 849392:tid 849633] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSfAMgr4yz2OQW0xrQbgAAAPM"]
[Thu Jul 30 13:05:48.762657 2026] [security2:error] [pid 849392:tid 849431] [remote 57.141.0.32:61746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/94764231632/feed/rss2/"] [unique_id "amuSfAMgr4yz2OQW0xrQcwAAlCU"]
[Thu Jul 30 13:05:48.765576 2026] [core:notice] [pid 849392:tid 849551] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:48.922802 2026] [security2:error] [pid 849392:tid 849529] [client 20.171.55.167:5203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/cloud.php"] [unique_id "amuSfAMgr4yz2OQW0xrQeAAAAIs"]
[Thu Jul 30 13:05:48.989873 2026] [core:notice] [pid 849392:tid 849434] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:49.371243 2026] [security2:error] [pid 849392:tid 849635] [client 20.63.98.115:58847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ty.php"] [unique_id "amuSfQMgr4yz2OQW0xrQewAAAPU"]
[Thu Jul 30 13:05:49.687777 2026] [security2:error] [pid 849392:tid 849562] [client 20.171.55.167:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/updates.php"] [unique_id "amuSfQMgr4yz2OQW0xrQhQAAAKw"]
[Thu Jul 30 13:05:49.746084 2026] [security2:error] [pid 849392:tid 849593] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuSfQMgr4yz2OQW0xrQegAAyxg"]
[Thu Jul 30 13:05:50.015766 2026] [security2:error] [pid 849392:tid 849525] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSfQMgr4yz2OQW0xrQfgAAAIc"]
[Thu Jul 30 13:05:50.347044 2026] [security2:error] [pid 849392:tid 849535] [client 52.167.144.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuSfQMgr4yz2OQW0xrQjgAAAJE"]
[Thu Jul 30 13:05:50.486435 2026] [core:notice] [pid 849392:tid 849627] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:50.503005 2026] [security2:error] [pid 849392:tid 849564] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "magicmooncorp.com"] [uri "/index.php"] [unique_id "amuSfgMgr4yz2OQW0xrQkQAAAK4"]
[Thu Jul 30 13:05:50.525856 2026] [security2:error] [pid 849392:tid 849533] [client 20.171.55.167:6017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/libraries/legacy/updates.php"] [unique_id "amuSfgMgr4yz2OQW0xrQlAAAAI8"]
[Thu Jul 30 13:05:50.609357 2026] [security2:error] [pid 849392:tid 849563] [client 20.63.98.115:38621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/readme.php"] [unique_id "amuSfgMgr4yz2OQW0xrQlQAAAK0"]
[Thu Jul 30 13:05:50.760626 2026] [proxy:error] [pid 849392:tid 849602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:50.760732 2026] [proxy_http:error] [pid 849392:tid 849602] [client 34.233.129.35:4846] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:50.761648 2026] [proxy:error] [pid 849392:tid 849602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:50.761714 2026] [proxy_http:error] [pid 849392:tid 849602] [client 34.233.129.35:4846] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:50.769184 2026] [proxy:error] [pid 849392:tid 849626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:50.769254 2026] [proxy_http:error] [pid 849392:tid 849626] [client 34.224.175.62:56013] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:50.769924 2026] [proxy:error] [pid 849392:tid 849626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:50.769971 2026] [proxy_http:error] [pid 849392:tid 849626] [client 34.224.175.62:56013] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:51.004960 2026] [security2:error] [pid 849392:tid 849560] [client 179.64.21.229:64550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSfgMgr4yz2OQW0xrQrQAAAKo"]
[Thu Jul 30 13:05:51.005113 2026] [security2:error] [pid 849392:tid 849560] [client 179.64.21.229:64550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSfgMgr4yz2OQW0xrQrQAAAKo"]
[Thu Jul 30 13:05:51.196925 2026] [security2:error] [pid 849392:tid 849571] [client 66.249.73.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuSfgMgr4yz2OQW0xrQqwAAALU"]
[Thu Jul 30 13:05:51.474090 2026] [security2:error] [pid 849392:tid 849529] [client 20.151.254.105:21830] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.ampcloudku.com"] [uri "/1.php"] [unique_id "amuSfwMgr4yz2OQW0xrQtQAAAIs"]
[Thu Jul 30 13:05:51.474213 2026] [security2:error] [pid 849392:tid 849529] [client 20.151.254.105:21830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/1.php"] [unique_id "amuSfwMgr4yz2OQW0xrQtQAAAIs"]
[Thu Jul 30 13:05:51.474317 2026] [security2:error] [pid 849392:tid 849529] [client 20.151.254.105:21830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/1.php"] [unique_id "amuSfwMgr4yz2OQW0xrQtQAAAIs"]
[Thu Jul 30 13:05:51.490385 2026] [security2:error] [pid 849392:tid 849612] [client 20.171.55.167:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuSfwMgr4yz2OQW0xrQtgAAAN4"]
[Thu Jul 30 13:05:51.536913 2026] [security2:error] [pid 849392:tid 849574] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuSfwMgr4yz2OQW0xrQugAAALg"]
[Thu Jul 30 13:05:51.537053 2026] [security2:error] [pid 849392:tid 849574] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuSfwMgr4yz2OQW0xrQugAAALg"]
[Thu Jul 30 13:05:51.743453 2026] [security2:error] [pid 849392:tid 849536] [client 52.167.144.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuSfwMgr4yz2OQW0xrQtAAAAJI"]
[Thu Jul 30 13:05:51.758004 2026] [core:notice] [pid 849392:tid 849442] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:51.845893 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuSfwMgr4yz2OQW0xrQvAAAAO4"]
[Thu Jul 30 13:05:51.846004 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuSfwMgr4yz2OQW0xrQvAAAAO4"]
[Thu Jul 30 13:05:52.012323 2026] [security2:error] [pid 849392:tid 849551] [client 20.63.98.115:53291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/options.php"] [unique_id "amuSgAMgr4yz2OQW0xrQxAAAAKE"]
[Thu Jul 30 13:05:52.238294 2026] [security2:error] [pid 849392:tid 849553] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/xstelth.php"] [unique_id "amuSgAMgr4yz2OQW0xrQxQAAAKM"]
[Thu Jul 30 13:05:52.238415 2026] [security2:error] [pid 849392:tid 849553] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/xstelth.php"] [unique_id "amuSgAMgr4yz2OQW0xrQxQAAAKM"]
[Thu Jul 30 13:05:52.344863 2026] [security2:error] [pid 849392:tid 849632] [client 20.171.55.167:5716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/libraries/vendor/updates.php"] [unique_id "amuSgAMgr4yz2OQW0xrQxgAAAPI"]
[Thu Jul 30 13:05:52.423952 2026] [core:notice] [pid 849392:tid 849432] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:52.491437 2026] [security2:error] [pid 849392:tid 849648] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuSgAMgr4yz2OQW0xrQyAAAAQI"]
[Thu Jul 30 13:05:52.491585 2026] [security2:error] [pid 849392:tid 849648] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuSgAMgr4yz2OQW0xrQyAAAAQI"]
[Thu Jul 30 13:05:52.726266 2026] [security2:error] [pid 849392:tid 849645] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/newfile.php"] [unique_id "amuSgAMgr4yz2OQW0xrQzQAAAP8"]
[Thu Jul 30 13:05:52.726421 2026] [security2:error] [pid 849392:tid 849645] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/newfile.php"] [unique_id "amuSgAMgr4yz2OQW0xrQzQAAAP8"]
[Thu Jul 30 13:05:52.936340 2026] [proxy:error] [pid 849392:tid 849627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:52.936428 2026] [proxy_http:error] [pid 849392:tid 849627] [client 44.216.125.112:2580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:52.937153 2026] [proxy:error] [pid 849392:tid 849627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:52.937215 2026] [proxy_http:error] [pid 849392:tid 849627] [client 44.216.125.112:2580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:52.944258 2026] [proxy:error] [pid 849392:tid 849539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:52.944357 2026] [proxy_http:error] [pid 849392:tid 849539] [client 44.216.125.112:1890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:52.945097 2026] [proxy:error] [pid 849392:tid 849539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:52.945150 2026] [proxy_http:error] [pid 849392:tid 849539] [client 44.216.125.112:1890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:52.960063 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/tBEZGQz.php"] [unique_id "amuSgAMgr4yz2OQW0xrQ1gAAAME"]
[Thu Jul 30 13:05:52.960168 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/tBEZGQz.php"] [unique_id "amuSgAMgr4yz2OQW0xrQ1gAAAME"]
[Thu Jul 30 13:05:53.123003 2026] [autoindex:error] [pid 849392:tid 849573] [client 89.22.101.69:58534] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:05:53.197256 2026] [security2:error] [pid 849392:tid 849596] [client 158.158.45.59:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.markmocek.com"] [uri "/phpinfo"] [unique_id "amuSgQMgr4yz2OQW0xrQ2QAAAM4"]
[Thu Jul 30 13:05:53.197408 2026] [security2:error] [pid 849392:tid 849596] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.markmocek.com"] [uri "/phpinfo"] [unique_id "amuSgQMgr4yz2OQW0xrQ2QAAAM4"]
[Thu Jul 30 13:05:53.299127 2026] [security2:error] [pid 849392:tid 849531] [client 20.63.98.115:38592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/admin.php7"] [unique_id "amuSgQMgr4yz2OQW0xrQ2gAAAI0"]
[Thu Jul 30 13:05:53.317214 2026] [security2:error] [pid 849392:tid 849563] [client 20.171.55.167:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/alfa-rex.php7"] [unique_id "amuSgQMgr4yz2OQW0xrQ2wAAAK0"]
[Thu Jul 30 13:05:53.471398 2026] [security2:error] [pid 849392:tid 849618] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/drykl.php"] [unique_id "amuSgQMgr4yz2OQW0xrQ3AAAAOQ"]
[Thu Jul 30 13:05:53.471516 2026] [security2:error] [pid 849392:tid 849618] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/drykl.php"] [unique_id "amuSgQMgr4yz2OQW0xrQ3AAAAOQ"]
[Thu Jul 30 13:05:53.708217 2026] [security2:error] [pid 849392:tid 849528] [client 158.158.45.59:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amuSgQMgr4yz2OQW0xrQ4QAAAIo"]
[Thu Jul 30 13:05:53.708327 2026] [security2:error] [pid 849392:tid 849528] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amuSgQMgr4yz2OQW0xrQ4QAAAIo"]
[Thu Jul 30 13:05:53.804569 2026] [security2:error] [pid 849392:tid 849631] [client 20.151.254.105:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/alfa.php"] [unique_id "amuSgQMgr4yz2OQW0xrQ4wAAAPE"]
[Thu Jul 30 13:05:53.804694 2026] [security2:error] [pid 849392:tid 849631] [client 20.151.254.105:4106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/alfa.php"] [unique_id "amuSgQMgr4yz2OQW0xrQ4wAAAPE"]
[Thu Jul 30 13:05:53.969625 2026] [security2:error] [pid 849392:tid 849556] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ls.php"] [unique_id "amuSgQMgr4yz2OQW0xrQ5QAAAKY"]
[Thu Jul 30 13:05:53.969740 2026] [security2:error] [pid 849392:tid 849556] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/ls.php"] [unique_id "amuSgQMgr4yz2OQW0xrQ5QAAAKY"]
[Thu Jul 30 13:05:54.194947 2026] [security2:error] [pid 849392:tid 849558] [client 20.171.55.167:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/alfanew.php"] [unique_id "amuSggMgr4yz2OQW0xrQ6wAAAKg"]
[Thu Jul 30 13:05:54.210378 2026] [security2:error] [pid 849392:tid 849619] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/dx.php"] [unique_id "amuSggMgr4yz2OQW0xrQ7AAAAOU"]
[Thu Jul 30 13:05:54.210476 2026] [security2:error] [pid 849392:tid 849619] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/dx.php"] [unique_id "amuSggMgr4yz2OQW0xrQ7AAAAOU"]
[Thu Jul 30 13:05:54.461636 2026] [security2:error] [pid 849392:tid 849650] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/mac.php"] [unique_id "amuSggMgr4yz2OQW0xrQ7gAAAQQ"]
[Thu Jul 30 13:05:54.461758 2026] [security2:error] [pid 849392:tid 849650] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/mac.php"] [unique_id "amuSggMgr4yz2OQW0xrQ7gAAAQQ"]
[Thu Jul 30 13:05:54.478275 2026] [security2:error] [pid 849392:tid 849538] [client 20.63.98.115:53260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known/wp-login.php"] [unique_id "amuSggMgr4yz2OQW0xrQ7QAAAJQ"]
[Thu Jul 30 13:05:54.738933 2026] [core:error] [pid 849392:tid 849425] [remote 34.239.166.69:32465] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://alnukhbafurnituremovers.cc/
[Thu Jul 30 13:05:54.738957 2026] [core:error] [pid 849392:tid 849425] [remote 34.239.166.69:32465] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://alnukhbafurnituremovers.cc/
[Thu Jul 30 13:05:54.774564 2026] [security2:error] [pid 849392:tid 849553] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/485.php"] [unique_id "amuSggMgr4yz2OQW0xrQ8gAAAKM"]
[Thu Jul 30 13:05:54.774670 2026] [security2:error] [pid 849392:tid 849553] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/485.php"] [unique_id "amuSggMgr4yz2OQW0xrQ8gAAAKM"]
[Thu Jul 30 13:05:54.934254 2026] [security2:error] [pid 849392:tid 849572] [client 20.171.55.167:5736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuSggMgr4yz2OQW0xrQ8wAAALY"]
[Thu Jul 30 13:05:55.016440 2026] [security2:error] [pid 849392:tid 849610] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/gelio1.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ9AAAANw"]
[Thu Jul 30 13:05:55.016550 2026] [security2:error] [pid 849392:tid 849610] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/gelio1.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ9AAAANw"]
[Thu Jul 30 13:05:55.249377 2026] [security2:error] [pid 849392:tid 849541] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/lp6.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ9QAAAJc"]
[Thu Jul 30 13:05:55.249497 2026] [security2:error] [pid 849392:tid 849541] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/lp6.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ9QAAAJc"]
[Thu Jul 30 13:05:55.285231 2026] [core:notice] [pid 849392:tid 849525] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:55.390087 2026] [security2:error] [pid 849392:tid 849458] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ9wAAsEA"]
[Thu Jul 30 13:05:55.390243 2026] [security2:error] [pid 849392:tid 849566] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ9wAAsEA"]
[Thu Jul 30 13:05:55.510843 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ-AAAAME"]
[Thu Jul 30 13:05:55.510949 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ-AAAAME"]
[Thu Jul 30 13:05:55.744494 2026] [security2:error] [pid 849392:tid 849549] [client 158.158.45.59:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amuSgwMgr4yz2OQW0xrQ_AAAAJ8"]
[Thu Jul 30 13:05:55.744660 2026] [security2:error] [pid 849392:tid 849549] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amuSgwMgr4yz2OQW0xrQ_AAAAJ8"]
[Thu Jul 30 13:05:55.870997 2026] [security2:error] [pid 849392:tid 849539] [client 20.171.55.167:5195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuSgwMgr4yz2OQW0xrQ_gAAAJU"]
[Thu Jul 30 13:05:55.921011 2026] [security2:error] [pid 849392:tid 849573] [client 20.151.254.105:1205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/edit.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ_wAAALc"]
[Thu Jul 30 13:05:55.921136 2026] [security2:error] [pid 849392:tid 849573] [client 20.151.254.105:1205] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/edit.php"] [unique_id "amuSgwMgr4yz2OQW0xrQ_wAAALc"]
[Thu Jul 30 13:05:55.977826 2026] [security2:error] [pid 849392:tid 849559] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/w3llscc.php"] [unique_id "amuSgwMgr4yz2OQW0xrRAAAAAKk"]
[Thu Jul 30 13:05:55.977942 2026] [security2:error] [pid 849392:tid 849559] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/w3llscc.php"] [unique_id "amuSgwMgr4yz2OQW0xrRAAAAAKk"]
[Thu Jul 30 13:05:56.211322 2026] [security2:error] [pid 849392:tid 849620] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/miru3.php"] [unique_id "amuShAMgr4yz2OQW0xrRAQAAAOY"]
[Thu Jul 30 13:05:56.211462 2026] [security2:error] [pid 849392:tid 849620] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/miru3.php"] [unique_id "amuShAMgr4yz2OQW0xrRAQAAAOY"]
[Thu Jul 30 13:05:56.534677 2026] [security2:error] [pid 849392:tid 849641] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuShAMgr4yz2OQW0xrRBwAAAPs"]
[Thu Jul 30 13:05:56.534800 2026] [security2:error] [pid 849392:tid 849641] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuShAMgr4yz2OQW0xrRBwAAAPs"]
[Thu Jul 30 13:05:56.567789 2026] [security2:error] [pid 849392:tid 849604] [client 20.63.98.115:53312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuShAMgr4yz2OQW0xrRCAAAANY"]
[Thu Jul 30 13:05:56.638952 2026] [core:notice] [pid 849392:tid 849601] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:56.768996 2026] [security2:error] [pid 849392:tid 849560] [client 158.158.45.59:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/"] [unique_id "amuShAMgr4yz2OQW0xrRCwAAAKo"]
[Thu Jul 30 13:05:56.769108 2026] [security2:error] [pid 849392:tid 849560] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/"] [unique_id "amuShAMgr4yz2OQW0xrRCwAAAKo"]
[Thu Jul 30 13:05:56.790698 2026] [security2:error] [pid 849392:tid 849563] [client 20.171.55.167:5196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-p.php7"] [unique_id "amuShAMgr4yz2OQW0xrRDAAAAK0"]
[Thu Jul 30 13:05:57.029616 2026] [security2:error] [pid 849392:tid 849528] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuShQMgr4yz2OQW0xrRDgAAAIo"]
[Thu Jul 30 13:05:57.029761 2026] [security2:error] [pid 849392:tid 849528] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuShQMgr4yz2OQW0xrRDgAAAIo"]
[Thu Jul 30 13:05:57.272111 2026] [security2:error] [pid 849392:tid 849448] [remote 152.228.213.32:45100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daralnaseemdxb.com"] [uri "/wp-login.php"] [unique_id "amuShQMgr4yz2OQW0xrRFwAAnjY"]
[Thu Jul 30 13:05:57.337562 2026] [security2:error] [pid 849392:tid 849650] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/av.php"] [unique_id "amuShQMgr4yz2OQW0xrRGQAAAQQ"]
[Thu Jul 30 13:05:57.337686 2026] [security2:error] [pid 849392:tid 849650] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/av.php"] [unique_id "amuShQMgr4yz2OQW0xrRGQAAAQQ"]
[Thu Jul 30 13:05:57.351869 2026] [security2:error] [pid 849392:tid 849642] [client 20.63.98.115:38593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/file.php"] [unique_id "amuShQMgr4yz2OQW0xrRGgAAAPw"]
[Thu Jul 30 13:05:57.511935 2026] [security2:error] [pid 849392:tid 849589] [client 74.7.175.167:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.kax.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuShQMgr4yz2OQW0xrRHQAAAMc"]
[Thu Jul 30 13:05:57.512698 2026] [security2:error] [pid 849392:tid 849536] [client 74.7.175.167:53288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.kax.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuShQMgr4yz2OQW0xrRGwAAkkU"]
[Thu Jul 30 13:05:57.593087 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.45.59:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/l10n/"] [unique_id "amuShQMgr4yz2OQW0xrRHgAAAO4"]
[Thu Jul 30 13:05:57.593229 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.markmocek.com"] [uri "/wp-includes/l10n/"] [unique_id "amuShQMgr4yz2OQW0xrRHgAAAO4"]
[Thu Jul 30 13:05:57.635701 2026] [security2:error] [pid 849392:tid 849530] [client 20.171.55.167:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/repeater.php"] [unique_id "amuShQMgr4yz2OQW0xrRHwAAAIw"]
[Thu Jul 30 13:05:57.725331 2026] [security2:error] [pid 849392:tid 849551] [client 20.151.254.105:29915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/elp.php"] [unique_id "amuShQMgr4yz2OQW0xrRIQAAAKE"]
[Thu Jul 30 13:05:57.725452 2026] [security2:error] [pid 849392:tid 849551] [client 20.151.254.105:29915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/elp.php"] [unique_id "amuShQMgr4yz2OQW0xrRIQAAAKE"]
[Thu Jul 30 13:05:57.832560 2026] [security2:error] [pid 849392:tid 849527] [client 158.158.45.59:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.markmocek.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amuShQMgr4yz2OQW0xrRIgAAAIk"]
[Thu Jul 30 13:05:57.832732 2026] [security2:error] [pid 849392:tid 849527] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.markmocek.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amuShQMgr4yz2OQW0xrRIgAAAIk"]
[Thu Jul 30 13:05:57.951721 2026] [core:notice] [pid 849392:tid 849553] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:58.138341 2026] [security2:error] [pid 849392:tid 849623] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/tiny.php"] [unique_id "amuShgMgr4yz2OQW0xrRJAAAAOk"]
[Thu Jul 30 13:05:58.138463 2026] [security2:error] [pid 849392:tid 849623] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/tiny.php"] [unique_id "amuShgMgr4yz2OQW0xrRJAAAAOk"]
[Thu Jul 30 13:05:58.291919 2026] [security2:error] [pid 849392:tid 849575] [client 20.63.98.115:53254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/bak.php"] [unique_id "amuShgMgr4yz2OQW0xrRJQAAALk"]
[Thu Jul 30 13:05:58.369645 2026] [security2:error] [pid 849392:tid 849645] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuShgMgr4yz2OQW0xrRJgAAAP8"]
[Thu Jul 30 13:05:58.369765 2026] [security2:error] [pid 849392:tid 849645] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuShgMgr4yz2OQW0xrRJgAAAP8"]
[Thu Jul 30 13:05:58.428288 2026] [core:notice] [pid 849392:tid 849630] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:05:58.519277 2026] [proxy:error] [pid 849392:tid 849566] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:58.519621 2026] [proxy_http:error] [pid 849392:tid 849566] [client 32.194.121.99:35629] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:58.520418 2026] [proxy:error] [pid 849392:tid 849566] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:58.520474 2026] [proxy_http:error] [pid 849392:tid 849566] [client 32.194.121.99:35629] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:58.547725 2026] [proxy:error] [pid 849392:tid 849576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:58.547819 2026] [proxy_http:error] [pid 849392:tid 849576] [client 32.194.121.99:34156] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:58.548653 2026] [proxy:error] [pid 849392:tid 849576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:58.548707 2026] [proxy_http:error] [pid 849392:tid 849576] [client 32.194.121.99:34156] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:58.570899 2026] [security2:error] [pid 849392:tid 849607] [client 20.171.55.167:5792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-includes/repeater.php"] [unique_id "amuShgMgr4yz2OQW0xrRMQAAANk"]
[Thu Jul 30 13:05:58.600704 2026] [security2:error] [pid 849392:tid 849640] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/zrrhj.php"] [unique_id "amuShgMgr4yz2OQW0xrRMwAAAPo"]
[Thu Jul 30 13:05:58.600795 2026] [security2:error] [pid 849392:tid 849640] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/zrrhj.php"] [unique_id "amuShgMgr4yz2OQW0xrRMwAAAPo"]
[Thu Jul 30 13:05:58.844427 2026] [security2:error] [pid 849392:tid 849626] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuShgMgr4yz2OQW0xrRNAAAAOw"]
[Thu Jul 30 13:05:58.844549 2026] [security2:error] [pid 849392:tid 849626] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuShgMgr4yz2OQW0xrRNAAAAOw"]
[Thu Jul 30 13:05:59.018524 2026] [proxy:error] [pid 849392:tid 849559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:59.018608 2026] [proxy_http:error] [pid 849392:tid 849559] [client 74.7.175.166:41962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:59.019292 2026] [proxy:error] [pid 849392:tid 849559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:05:59.019343 2026] [proxy_http:error] [pid 849392:tid 849559] [client 74.7.175.166:41962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:05:59.019473 2026] [security2:error] [pid 849392:tid 849559] [client 74.7.175.166:41962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.nef.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuShwMgr4yz2OQW0xrRNQAAAKk"]
[Thu Jul 30 13:05:59.126841 2026] [security2:error] [pid 849392:tid 849594] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wpgum.php"] [unique_id "amuShwMgr4yz2OQW0xrRNwAAAMw"]
[Thu Jul 30 13:05:59.126996 2026] [security2:error] [pid 849392:tid 849594] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wpgum.php"] [unique_id "amuShwMgr4yz2OQW0xrRNwAAAMw"]
[Thu Jul 30 13:05:59.380067 2026] [security2:error] [pid 849392:tid 849624] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ywwbf.php"] [unique_id "amuShwMgr4yz2OQW0xrROgAAAOo"]
[Thu Jul 30 13:05:59.380186 2026] [security2:error] [pid 849392:tid 849624] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/ywwbf.php"] [unique_id "amuShwMgr4yz2OQW0xrROgAAAOo"]
[Thu Jul 30 13:05:59.435110 2026] [security2:error] [pid 849392:tid 849592] [client 20.171.55.167:5819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/repeater.php"] [unique_id "amuShwMgr4yz2OQW0xrROwAAAMo"]
[Thu Jul 30 13:05:59.710632 2026] [security2:error] [pid 849392:tid 849534] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/xoldj.php"] [unique_id "amuShwMgr4yz2OQW0xrRPgAAAJA"]
[Thu Jul 30 13:05:59.710710 2026] [security2:error] [pid 849392:tid 849534] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/xoldj.php"] [unique_id "amuShwMgr4yz2OQW0xrRPgAAAJA"]
[Thu Jul 30 13:05:59.719805 2026] [security2:error] [pid 849392:tid 849523] [client 20.63.98.115:53267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/config.php"] [unique_id "amuShwMgr4yz2OQW0xrRPwAAAIU"]
[Thu Jul 30 13:05:59.925652 2026] [core:notice] [pid 849392:tid 849445] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:00.143539 2026] [security2:error] [pid 849392:tid 849570] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/f35.php"] [unique_id "amuSiAMgr4yz2OQW0xrRQwAAALQ"]
[Thu Jul 30 13:06:00.143655 2026] [security2:error] [pid 849392:tid 849570] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/f35.php"] [unique_id "amuSiAMgr4yz2OQW0xrRQwAAALQ"]
[Thu Jul 30 13:06:00.386717 2026] [security2:error] [pid 849392:tid 849611] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/gk.php"] [unique_id "amuSiAMgr4yz2OQW0xrRRAAAAN0"]
[Thu Jul 30 13:06:00.386827 2026] [security2:error] [pid 849392:tid 849611] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/gk.php"] [unique_id "amuSiAMgr4yz2OQW0xrRRAAAAN0"]
[Thu Jul 30 13:06:00.483904 2026] [security2:error] [pid 849392:tid 849528] [client 20.171.55.167:5735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wsoyanz.php"] [unique_id "amuSiAMgr4yz2OQW0xrRRQAAAIo"]
[Thu Jul 30 13:06:00.590560 2026] [security2:error] [pid 849392:tid 849571] [client 20.63.98.115:46625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amuSiAMgr4yz2OQW0xrRSQAAALU"]
[Thu Jul 30 13:06:00.619961 2026] [security2:error] [pid 849392:tid 849574] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuSiAMgr4yz2OQW0xrRSgAAALg"]
[Thu Jul 30 13:06:00.620097 2026] [security2:error] [pid 849392:tid 849574] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/584062352875874akp.php"] [unique_id "amuSiAMgr4yz2OQW0xrRSgAAALg"]
[Thu Jul 30 13:06:00.857814 2026] [security2:error] [pid 849392:tid 849619] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wper3.php"] [unique_id "amuSiAMgr4yz2OQW0xrRTAAAAOU"]
[Thu Jul 30 13:06:00.857972 2026] [security2:error] [pid 849392:tid 849619] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wper3.php"] [unique_id "amuSiAMgr4yz2OQW0xrRTAAAAOU"]
[Thu Jul 30 13:06:00.863971 2026] [security2:error] [pid 849392:tid 849543] [client 52.167.144.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuSiAMgr4yz2OQW0xrRSAAAAJk"]
[Thu Jul 30 13:06:01.058309 2026] [core:notice] [pid 849392:tid 849427] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:01.134328 2026] [security2:error] [pid 849392:tid 849587] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/bthil.php"] [unique_id "amuSiQMgr4yz2OQW0xrRTgAAAMU"]
[Thu Jul 30 13:06:01.134450 2026] [security2:error] [pid 849392:tid 849587] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/bthil.php"] [unique_id "amuSiQMgr4yz2OQW0xrRTgAAAMU"]
[Thu Jul 30 13:06:01.342829 2026] [security2:error] [pid 849392:tid 849609] [client 20.171.55.167:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/yanz.php"] [unique_id "amuSiQMgr4yz2OQW0xrRTwAAANs"]
[Thu Jul 30 13:06:01.365594 2026] [security2:error] [pid 849392:tid 849617] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wyzer1.php"] [unique_id "amuSiQMgr4yz2OQW0xrRUAAAAOM"]
[Thu Jul 30 13:06:01.365748 2026] [security2:error] [pid 849392:tid 849617] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wyzer1.php"] [unique_id "amuSiQMgr4yz2OQW0xrRUAAAAOM"]
[Thu Jul 30 13:06:01.600138 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/mh.php"] [unique_id "amuSiQMgr4yz2OQW0xrRVgAAAKw"]
[Thu Jul 30 13:06:01.600274 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/mh.php"] [unique_id "amuSiQMgr4yz2OQW0xrRVgAAAKw"]
[Thu Jul 30 13:06:01.844402 2026] [security2:error] [pid 849392:tid 849591] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuSiQMgr4yz2OQW0xrRXgAAAMk"]
[Thu Jul 30 13:06:01.844503 2026] [security2:error] [pid 849392:tid 849591] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuSiQMgr4yz2OQW0xrRXgAAAMk"]
[Thu Jul 30 13:06:02.002126 2026] [security2:error] [pid 849392:tid 849544] [client 179.64.21.229:14989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSigMgr4yz2OQW0xrRYgAAAJo"]
[Thu Jul 30 13:06:02.005516 2026] [security2:error] [pid 849392:tid 849544] [client 179.64.21.229:14989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSigMgr4yz2OQW0xrRYgAAAJo"]
[Thu Jul 30 13:06:02.112835 2026] [security2:error] [pid 849392:tid 849615] [client 20.171.55.167:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "amuSigMgr4yz2OQW0xrRYwAAAOE"]
[Thu Jul 30 13:06:02.178431 2026] [security2:error] [pid 849392:tid 849623] [client 158.158.45.59:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.markmocek.com"] [uri "/1.php"] [unique_id "amuSigMgr4yz2OQW0xrRZAAAAOk"]
[Thu Jul 30 13:06:02.178532 2026] [security2:error] [pid 849392:tid 849623] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/1.php"] [unique_id "amuSigMgr4yz2OQW0xrRZAAAAOk"]
[Thu Jul 30 13:06:02.178613 2026] [security2:error] [pid 849392:tid 849623] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/1.php"] [unique_id "amuSigMgr4yz2OQW0xrRZAAAAOk"]
[Thu Jul 30 13:06:02.251574 2026] [proxy:error] [pid 849392:tid 849575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:02.251742 2026] [proxy_http:error] [pid 849392:tid 849575] [client 52.202.41.153:10336] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:02.252345 2026] [proxy:error] [pid 849392:tid 849575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:02.252400 2026] [proxy_http:error] [pid 849392:tid 849575] [client 52.202.41.153:10336] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:02.253723 2026] [proxy:error] [pid 849392:tid 849555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:02.253778 2026] [proxy_http:error] [pid 849392:tid 849555] [client 54.87.222.253:37507] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:02.254377 2026] [proxy:error] [pid 849392:tid 849555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:02.254426 2026] [proxy_http:error] [pid 849392:tid 849555] [client 54.87.222.253:37507] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:02.255089 2026] [security2:error] [pid 849392:tid 849610] [client 52.167.144.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuSiQMgr4yz2OQW0xrRYQAAANw"]
[Thu Jul 30 13:06:02.427955 2026] [security2:error] [pid 849392:tid 849579] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/chosen.php"] [unique_id "amuSigMgr4yz2OQW0xrRbQAAAL0"]
[Thu Jul 30 13:06:02.428093 2026] [security2:error] [pid 849392:tid 849579] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/chosen.php"] [unique_id "amuSigMgr4yz2OQW0xrRbQAAAL0"]
[Thu Jul 30 13:06:02.674113 2026] [security2:error] [pid 849392:tid 849582] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/sd.php"] [unique_id "amuSigMgr4yz2OQW0xrRbgAAAMA"]
[Thu Jul 30 13:06:02.674222 2026] [security2:error] [pid 849392:tid 849582] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/sd.php"] [unique_id "amuSigMgr4yz2OQW0xrRbgAAAMA"]
[Thu Jul 30 13:06:02.817477 2026] [security2:error] [pid 849392:tid 849559] [client 20.151.254.105:2700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.254.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ampcloudku.com"] [uri "/classwithtostring.php"] [unique_id "amuSigMgr4yz2OQW0xrRcAAAAKk"]
[Thu Jul 30 13:06:02.817559 2026] [security2:error] [pid 849392:tid 849559] [client 20.151.254.105:2700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ampcloudku.com"] [uri "/classwithtostring.php"] [unique_id "amuSigMgr4yz2OQW0xrRcAAAAKk"]
[Thu Jul 30 13:06:02.905856 2026] [security2:error] [pid 849392:tid 849622] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/z60.php"] [unique_id "amuSigMgr4yz2OQW0xrRcQAAAOg"]
[Thu Jul 30 13:06:02.905962 2026] [security2:error] [pid 849392:tid 849622] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/z60.php"] [unique_id "amuSigMgr4yz2OQW0xrRcQAAAOg"]
[Thu Jul 30 13:06:02.947852 2026] [security2:error] [pid 849392:tid 849630] [client 20.171.55.167:5742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "amuSigMgr4yz2OQW0xrRcgAAAPA"]
[Thu Jul 30 13:06:02.952273 2026] [core:notice] [pid 849392:tid 849465] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:02.993393 2026] [security2:error] [pid 849392:tid 849573] [client 47.128.31.37:28986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alshateeintl.com"] [uri "/robots.txt"] [unique_id "amuSigMgr4yz2OQW0xrRdAAAALc"]
[Thu Jul 30 13:06:03.141837 2026] [security2:error] [pid 849392:tid 849620] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/home.php"] [unique_id "amuSiwMgr4yz2OQW0xrRdQAAAOY"]
[Thu Jul 30 13:06:03.141997 2026] [security2:error] [pid 849392:tid 849620] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/home.php"] [unique_id "amuSiwMgr4yz2OQW0xrRdQAAAOY"]
[Thu Jul 30 13:06:03.247057 2026] [security2:error] [pid 849392:tid 849628] [client 20.63.98.115:38596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-activate.php"] [unique_id "amuSiwMgr4yz2OQW0xrRdwAAAO4"]
[Thu Jul 30 13:06:03.388442 2026] [core:notice] [pid 849392:tid 849524] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:03.443574 2026] [security2:error] [pid 849392:tid 849614] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ws58.php"] [unique_id "amuSiwMgr4yz2OQW0xrRfwAAAOA"]
[Thu Jul 30 13:06:03.443704 2026] [security2:error] [pid 849392:tid 849614] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/ws58.php"] [unique_id "amuSiwMgr4yz2OQW0xrRfwAAAOA"]
[Thu Jul 30 13:06:03.685461 2026] [core:notice] [pid 849392:tid 849457] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:03.714687 2026] [security2:error] [pid 849392:tid 849613] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/gulu.php"] [unique_id "amuSiwMgr4yz2OQW0xrRgwAAAN8"]
[Thu Jul 30 13:06:03.714840 2026] [security2:error] [pid 849392:tid 849613] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/gulu.php"] [unique_id "amuSiwMgr4yz2OQW0xrRgwAAAN8"]
[Thu Jul 30 13:06:03.782840 2026] [security2:error] [pid 849392:tid 849564] [client 20.171.55.167:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cache-compat.php"] [unique_id "amuSiwMgr4yz2OQW0xrRhAAAAK4"]
[Thu Jul 30 13:06:03.950630 2026] [security2:error] [pid 849392:tid 849568] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuSiwMgr4yz2OQW0xrRhQAAALI"]
[Thu Jul 30 13:06:03.950743 2026] [security2:error] [pid 849392:tid 849568] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuSiwMgr4yz2OQW0xrRhQAAALI"]
[Thu Jul 30 13:06:04.183345 2026] [security2:error] [pid 849392:tid 849532] [client 20.63.98.115:45625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-file.php"] [unique_id "amuSjAMgr4yz2OQW0xrRhwAAAI4"]
[Thu Jul 30 13:06:04.203032 2026] [security2:error] [pid 849392:tid 849571] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wpls.php"] [unique_id "amuSjAMgr4yz2OQW0xrRiAAAALU"]
[Thu Jul 30 13:06:04.203127 2026] [security2:error] [pid 849392:tid 849571] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wpls.php"] [unique_id "amuSjAMgr4yz2OQW0xrRiAAAALU"]
[Thu Jul 30 13:06:04.483220 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/php.php"] [unique_id "amuSjAMgr4yz2OQW0xrRmAAAAPU"]
[Thu Jul 30 13:06:04.483377 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/php.php"] [unique_id "amuSjAMgr4yz2OQW0xrRmAAAAPU"]
[Thu Jul 30 13:06:04.562400 2026] [security2:error] [pid 849392:tid 849578] [client 20.171.55.167:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/ajax-actions.php"] [unique_id "amuSjAMgr4yz2OQW0xrRmgAAALw"]
[Thu Jul 30 13:06:04.720502 2026] [security2:error] [pid 849392:tid 849527] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/100.php"] [unique_id "amuSjAMgr4yz2OQW0xrRnAAAAIk"]
[Thu Jul 30 13:06:04.720611 2026] [security2:error] [pid 849392:tid 849527] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/100.php"] [unique_id "amuSjAMgr4yz2OQW0xrRnAAAAIk"]
[Thu Jul 30 13:06:04.967018 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/BDKR28WP.php"] [unique_id "amuSjAMgr4yz2OQW0xrRngAAAOE"]
[Thu Jul 30 13:06:04.967134 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/BDKR28WP.php"] [unique_id "amuSjAMgr4yz2OQW0xrRngAAAOE"]
[Thu Jul 30 13:06:05.068256 2026] [security2:error] [pid 849392:tid 849449] [remote 57.141.18.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSjQMgr4yz2OQW0xrRnwAApDc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,polyester,cotton,denim,aluminum,nylon,steel&filter_size=extra-small,medium,extra-extra-large&orderby=rating&rating=5&status=instock&unfilter=1
[Thu Jul 30 13:06:05.135688 2026] [security2:error] [pid 849392:tid 849467] [remote 57.141.18.48:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuSjQMgr4yz2OQW0xrRoAAAuUk"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,polyester,cotton,denim,aluminum,nylon,steel&filter_size=extra-small,medium,extra-extra-large&orderby=rating&rating=5&status=instock&unfilter=1
[Thu Jul 30 13:06:05.225841 2026] [security2:error] [pid 849392:tid 849645] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/browse.php"] [unique_id "amuSjQMgr4yz2OQW0xrRoQAAAP8"]
[Thu Jul 30 13:06:05.225950 2026] [security2:error] [pid 849392:tid 849645] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/browse.php"] [unique_id "amuSjQMgr4yz2OQW0xrRoQAAAP8"]
[Thu Jul 30 13:06:05.269795 2026] [security2:error] [pid 849392:tid 849608] [client 20.63.98.115:53286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/12.php"] [unique_id "amuSjQMgr4yz2OQW0xrRogAAANo"]
[Thu Jul 30 13:06:05.477342 2026] [security2:error] [pid 849392:tid 849579] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-good.php"] [unique_id "amuSjQMgr4yz2OQW0xrRpAAAAL0"]
[Thu Jul 30 13:06:05.477465 2026] [security2:error] [pid 849392:tid 849579] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-good.php"] [unique_id "amuSjQMgr4yz2OQW0xrRpAAAAL0"]
[Thu Jul 30 13:06:05.590480 2026] [security2:error] [pid 849392:tid 849459] [remote 57.141.0.14:31294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuSjQMgr4yz2OQW0xrRpQAAkkE"]
[Thu Jul 30 13:06:05.650840 2026] [security2:error] [pid 849392:tid 849553] [client 20.171.55.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/ajax-actions.php"] [unique_id "amuSjQMgr4yz2OQW0xrRpwAAAKM"]
[Thu Jul 30 13:06:05.712689 2026] [security2:error] [pid 849392:tid 849599] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/8573.php"] [unique_id "amuSjQMgr4yz2OQW0xrRqAAAANE"]
[Thu Jul 30 13:06:05.712794 2026] [security2:error] [pid 849392:tid 849599] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/8573.php"] [unique_id "amuSjQMgr4yz2OQW0xrRqAAAANE"]
[Thu Jul 30 13:06:05.989361 2026] [security2:error] [pid 849392:tid 849630] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/install.php"] [unique_id "amuSjQMgr4yz2OQW0xrRqQAAAPA"]
[Thu Jul 30 13:06:05.989481 2026] [security2:error] [pid 849392:tid 849630] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/install.php"] [unique_id "amuSjQMgr4yz2OQW0xrRqQAAAPA"]
[Thu Jul 30 13:06:06.147120 2026] [security2:error] [pid 849392:tid 849484] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSjgMgr4yz2OQW0xrRsAAAp1o"]
[Thu Jul 30 13:06:06.147296 2026] [security2:error] [pid 849392:tid 849557] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSjgMgr4yz2OQW0xrRsAAAp1o"]
[Thu Jul 30 13:06:06.244796 2026] [security2:error] [pid 849392:tid 849534] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuSjgMgr4yz2OQW0xrRsQAAAJA"]
[Thu Jul 30 13:06:06.244901 2026] [security2:error] [pid 849392:tid 849534] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuSjgMgr4yz2OQW0xrRsQAAAJA"]
[Thu Jul 30 13:06:06.485775 2026] [security2:error] [pid 849392:tid 849549] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ohct.php"] [unique_id "amuSjgMgr4yz2OQW0xrRswAAAJ8"]
[Thu Jul 30 13:06:06.485897 2026] [security2:error] [pid 849392:tid 849549] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/ohct.php"] [unique_id "amuSjgMgr4yz2OQW0xrRswAAAJ8"]
[Thu Jul 30 13:06:06.528445 2026] [security2:error] [pid 849392:tid 849588] [client 20.171.55.167:5696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-consar.php"] [unique_id "amuSjgMgr4yz2OQW0xrRtAAAAMY"]
[Thu Jul 30 13:06:06.610904 2026] [core:notice] [pid 849392:tid 849437] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:06.804837 2026] [security2:error] [pid 849392:tid 849606] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/bless.php"] [unique_id "amuSjgMgr4yz2OQW0xrRtwAAANg"]
[Thu Jul 30 13:06:06.804997 2026] [security2:error] [pid 849392:tid 849606] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/bless.php"] [unique_id "amuSjgMgr4yz2OQW0xrRtwAAANg"]
[Thu Jul 30 13:06:06.927432 2026] [security2:error] [pid 849392:tid 849603] [client 172.236.9.101:29925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSjgMgr4yz2OQW0xrRsgAAANU"]
[Thu Jul 30 13:06:07.036810 2026] [security2:error] [pid 849392:tid 849545] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/about.php"] [unique_id "amuSjwMgr4yz2OQW0xrRuAAAAJs"]
[Thu Jul 30 13:06:07.036954 2026] [security2:error] [pid 849392:tid 849545] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/about.php"] [unique_id "amuSjwMgr4yz2OQW0xrRuAAAAJs"]
[Thu Jul 30 13:06:07.257062 2026] [security2:error] [pid 849392:tid 849563] [client 20.63.98.115:46632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/epinyins.php"] [unique_id "amuSjwMgr4yz2OQW0xrRuQAAAK0"]
[Thu Jul 30 13:06:07.268422 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuSjwMgr4yz2OQW0xrRugAAAPU"]
[Thu Jul 30 13:06:07.268584 2026] [security2:error] [pid 849392:tid 849635] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuSjwMgr4yz2OQW0xrRugAAAPU"]
[Thu Jul 30 13:06:07.312084 2026] [security2:error] [pid 849392:tid 849597] [client 20.171.55.167:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/repeater.php"] [unique_id "amuSjwMgr4yz2OQW0xrRuwAAAM8"]
[Thu Jul 30 13:06:07.505258 2026] [security2:error] [pid 849392:tid 849587] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ta0ol.php"] [unique_id "amuSjwMgr4yz2OQW0xrRvgAAAMU"]
[Thu Jul 30 13:06:07.505378 2026] [security2:error] [pid 849392:tid 849587] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/ta0ol.php"] [unique_id "amuSjwMgr4yz2OQW0xrRvgAAAMU"]
[Thu Jul 30 13:06:07.795011 2026] [proxy:error] [pid 849392:tid 849551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:07.795097 2026] [proxy_http:error] [pid 849392:tid 849551] [client 52.202.41.153:48400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:07.795659 2026] [proxy:error] [pid 849392:tid 849551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:07.795701 2026] [proxy_http:error] [pid 849392:tid 849551] [client 52.202.41.153:48400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:07.822406 2026] [proxy:error] [pid 849392:tid 849649] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:07.822489 2026] [proxy_http:error] [pid 849392:tid 849649] [client 54.87.222.253:38562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:07.823058 2026] [proxy:error] [pid 849392:tid 849649] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:07.823101 2026] [proxy_http:error] [pid 849392:tid 849649] [client 54.87.222.253:38562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:07.849073 2026] [security2:error] [pid 849392:tid 849629] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/sa.php7"] [unique_id "amuSjwMgr4yz2OQW0xrRxwAAAO8"]
[Thu Jul 30 13:06:07.849186 2026] [security2:error] [pid 849392:tid 849629] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/sa.php7"] [unique_id "amuSjwMgr4yz2OQW0xrRxwAAAO8"]
[Thu Jul 30 13:06:08.139451 2026] [security2:error] [pid 849392:tid 849544] [client 20.63.98.115:46650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amuSkAMgr4yz2OQW0xrRyQAAAJo"]
[Thu Jul 30 13:06:08.295456 2026] [core:notice] [pid 849392:tid 849535] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:08.325378 2026] [security2:error] [pid 849392:tid 849615] [client 20.171.55.167:6143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/admin-post.php"] [unique_id "amuSkAMgr4yz2OQW0xrRywAAAOE"]
[Thu Jul 30 13:06:08.360809 2026] [security2:error] [pid 849392:tid 849619] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-class.php"] [unique_id "amuSkAMgr4yz2OQW0xrRzAAAAOU"]
[Thu Jul 30 13:06:08.360904 2026] [security2:error] [pid 849392:tid 849619] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-class.php"] [unique_id "amuSkAMgr4yz2OQW0xrRzAAAAOU"]
[Thu Jul 30 13:06:08.643877 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/8.php"] [unique_id "amuSkAMgr4yz2OQW0xrRzgAAAME"]
[Thu Jul 30 13:06:08.644009 2026] [security2:error] [pid 849392:tid 849583] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/8.php"] [unique_id "amuSkAMgr4yz2OQW0xrRzgAAAME"]
[Thu Jul 30 13:06:08.769499 2026] [core:notice] [pid 849392:tid 849640] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:08.878023 2026] [security2:error] [pid 849392:tid 849526] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/bootstrap.php"] [unique_id "amuSkAMgr4yz2OQW0xrR0AAAAIg"]
[Thu Jul 30 13:06:08.878140 2026] [security2:error] [pid 849392:tid 849526] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/bootstrap.php"] [unique_id "amuSkAMgr4yz2OQW0xrR0AAAAIg"]
[Thu Jul 30 13:06:08.896165 2026] [security2:error] [pid 849392:tid 849586] [client 172.236.9.101:26031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSkAMgr4yz2OQW0xrRzQAAAMQ"]
[Thu Jul 30 13:06:09.114297 2026] [security2:error] [pid 849392:tid 849630] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-blog-header.php"] [unique_id "amuSkQMgr4yz2OQW0xrR0gAAAPA"]
[Thu Jul 30 13:06:09.114426 2026] [security2:error] [pid 849392:tid 849630] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-blog-header.php"] [unique_id "amuSkQMgr4yz2OQW0xrR0gAAAPA"]
[Thu Jul 30 13:06:09.180548 2026] [security2:error] [pid 849392:tid 849626] [client 20.171.55.167:5699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "amuSkQMgr4yz2OQW0xrR0wAAAOw"]
[Thu Jul 30 13:06:09.337937 2026] [core:notice] [pid 849392:tid 849628] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:09.349450 2026] [security2:error] [pid 849392:tid 849625] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/aa.php"] [unique_id "amuSkQMgr4yz2OQW0xrR1QAAAOs"]
[Thu Jul 30 13:06:09.349572 2026] [security2:error] [pid 849392:tid 849625] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/aa.php"] [unique_id "amuSkQMgr4yz2OQW0xrR1QAAAOs"]
[Thu Jul 30 13:06:09.633945 2026] [security2:error] [pid 849392:tid 849624] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/tx79.php"] [unique_id "amuSkQMgr4yz2OQW0xrR2gAAAOo"]
[Thu Jul 30 13:06:09.634088 2026] [security2:error] [pid 849392:tid 849624] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/tx79.php"] [unique_id "amuSkQMgr4yz2OQW0xrR2gAAAOo"]
[Thu Jul 30 13:06:09.866474 2026] [security2:error] [pid 849392:tid 849601] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/motu.php"] [unique_id "amuSkQMgr4yz2OQW0xrR2wAAANM"]
[Thu Jul 30 13:06:09.866588 2026] [security2:error] [pid 849392:tid 849601] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/motu.php"] [unique_id "amuSkQMgr4yz2OQW0xrR2wAAANM"]
[Thu Jul 30 13:06:10.044332 2026] [security2:error] [pid 849392:tid 849534] [client 20.171.55.167:5707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/dropdown.php"] [unique_id "amuSkgMgr4yz2OQW0xrR3AAAAJA"]
[Thu Jul 30 13:06:10.101346 2026] [security2:error] [pid 849392:tid 849614] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSkQMgr4yz2OQW0xrR2QAAAOA"]
[Thu Jul 30 13:06:10.110120 2026] [security2:error] [pid 849392:tid 849634] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-head.php"] [unique_id "amuSkgMgr4yz2OQW0xrR3QAAAPQ"]
[Thu Jul 30 13:06:10.110203 2026] [security2:error] [pid 849392:tid 849634] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-head.php"] [unique_id "amuSkgMgr4yz2OQW0xrR3QAAAPQ"]
[Thu Jul 30 13:06:10.143950 2026] [security2:error] [pid 849392:tid 849525] [client 20.63.98.115:53304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/system_log.php"] [unique_id "amuSkgMgr4yz2OQW0xrR3gAAAIc"]
[Thu Jul 30 13:06:10.356125 2026] [security2:error] [pid 849392:tid 849523] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuSkgMgr4yz2OQW0xrR4gAAAIU"]
[Thu Jul 30 13:06:10.356249 2026] [security2:error] [pid 849392:tid 849523] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuSkgMgr4yz2OQW0xrR4gAAAIU"]
[Thu Jul 30 13:06:10.950483 2026] [security2:error] [pid 849392:tid 849548] [client 20.171.55.167:6127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/index.php"] [unique_id "amuSkgMgr4yz2OQW0xrR5wAAAJ4"]
[Thu Jul 30 13:06:10.997135 2026] [security2:error] [pid 849392:tid 849641] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/60856e3a4findex.php"] [unique_id "amuSkgMgr4yz2OQW0xrR6QAAAPs"]
[Thu Jul 30 13:06:10.997215 2026] [security2:error] [pid 849392:tid 849641] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/60856e3a4findex.php"] [unique_id "amuSkgMgr4yz2OQW0xrR6QAAAPs"]
[Thu Jul 30 13:06:11.161661 2026] [security2:error] [pid 849392:tid 849638] [client 20.63.98.115:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuSkwMgr4yz2OQW0xrR6gAAAPg"]
[Thu Jul 30 13:06:11.265966 2026] [security2:error] [pid 849392:tid 849543] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-the.php"] [unique_id "amuSkwMgr4yz2OQW0xrR7QAAAJk"]
[Thu Jul 30 13:06:11.266094 2026] [security2:error] [pid 849392:tid 849543] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp-the.php"] [unique_id "amuSkwMgr4yz2OQW0xrR7QAAAJk"]
[Thu Jul 30 13:06:11.497546 2026] [security2:error] [pid 849392:tid 849531] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp.php"] [unique_id "amuSkwMgr4yz2OQW0xrR8QAAAI0"]
[Thu Jul 30 13:06:11.497659 2026] [security2:error] [pid 849392:tid 849531] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wp.php"] [unique_id "amuSkwMgr4yz2OQW0xrR8QAAAI0"]
[Thu Jul 30 13:06:11.778238 2026] [security2:error] [pid 849392:tid 849527] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/users.php"] [unique_id "amuSkwMgr4yz2OQW0xrR8gAAAIk"]
[Thu Jul 30 13:06:11.778357 2026] [security2:error] [pid 849392:tid 849527] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/users.php"] [unique_id "amuSkwMgr4yz2OQW0xrR8gAAAIk"]
[Thu Jul 30 13:06:11.867230 2026] [security2:error] [pid 849392:tid 849584] [client 20.171.55.167:5705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/dropdown.php"] [unique_id "amuSkwMgr4yz2OQW0xrR8wAAAMI"]
[Thu Jul 30 13:06:12.013507 2026] [security2:error] [pid 849392:tid 849567] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/tinysd.php"] [unique_id "amuSlAMgr4yz2OQW0xrR9wAAALE"]
[Thu Jul 30 13:06:12.013626 2026] [security2:error] [pid 849392:tid 849567] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/tinysd.php"] [unique_id "amuSlAMgr4yz2OQW0xrR9wAAALE"]
[Thu Jul 30 13:06:12.334925 2026] [security2:error] [pid 849392:tid 849575] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ws78.php"] [unique_id "amuSlAMgr4yz2OQW0xrR-wAAALk"]
[Thu Jul 30 13:06:12.335052 2026] [security2:error] [pid 849392:tid 849575] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/ws78.php"] [unique_id "amuSlAMgr4yz2OQW0xrR-wAAALk"]
[Thu Jul 30 13:06:12.566102 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/elp.php"] [unique_id "amuSlAMgr4yz2OQW0xrR_QAAAOE"]
[Thu Jul 30 13:06:12.566229 2026] [security2:error] [pid 849392:tid 849615] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/elp.php"] [unique_id "amuSlAMgr4yz2OQW0xrR_QAAAOE"]
[Thu Jul 30 13:06:12.884657 2026] [security2:error] [pid 849392:tid 849608] [client 20.171.55.167:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/about.php"] [unique_id "amuSlAMgr4yz2OQW0xrR_gAAANo"]
[Thu Jul 30 13:06:12.916720 2026] [security2:error] [pid 849392:tid 849605] [client 172.236.9.101:16840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSlAMgr4yz2OQW0xrR_AAAANc"]
[Thu Jul 30 13:06:13.053850 2026] [security2:error] [pid 849392:tid 849576] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/atomlib.php"] [unique_id "amuSlQMgr4yz2OQW0xrSAAAAALo"]
[Thu Jul 30 13:06:13.054029 2026] [security2:error] [pid 849392:tid 849576] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/atomlib.php"] [unique_id "amuSlQMgr4yz2OQW0xrSAAAAALo"]
[Thu Jul 30 13:06:13.070219 2026] [security2:error] [pid 849392:tid 849619] [client 179.64.21.229:8879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSlQMgr4yz2OQW0xrSAQAAAOU"]
[Thu Jul 30 13:06:13.086246 2026] [security2:error] [pid 849392:tid 849619] [client 179.64.21.229:8879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSlQMgr4yz2OQW0xrSAQAAAOU"]
[Thu Jul 30 13:06:13.287123 2026] [security2:error] [pid 849392:tid 849599] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wyzer3.php"] [unique_id "amuSlQMgr4yz2OQW0xrSAwAAANE"]
[Thu Jul 30 13:06:13.287237 2026] [security2:error] [pid 849392:tid 849599] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/wyzer3.php"] [unique_id "amuSlQMgr4yz2OQW0xrSAwAAANE"]
[Thu Jul 30 13:06:13.524766 2026] [security2:error] [pid 849392:tid 849559] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/max.php"] [unique_id "amuSlQMgr4yz2OQW0xrSBwAAAKk"]
[Thu Jul 30 13:06:13.524922 2026] [security2:error] [pid 849392:tid 849559] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/max.php"] [unique_id "amuSlQMgr4yz2OQW0xrSBwAAAKk"]
[Thu Jul 30 13:06:13.720942 2026] [security2:error] [pid 849392:tid 849544] [client 20.63.98.115:46596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ini.php"] [unique_id "amuSlQMgr4yz2OQW0xrSCAAAAJo"]
[Thu Jul 30 13:06:13.746388 2026] [security2:error] [pid 849392:tid 849533] [client 20.171.55.167:5759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/about.php7"] [unique_id "amuSlQMgr4yz2OQW0xrSCQAAAI8"]
[Thu Jul 30 13:06:13.770251 2026] [security2:error] [pid 849392:tid 849630] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/ftde.php"] [unique_id "amuSlQMgr4yz2OQW0xrSCgAAAPA"]
[Thu Jul 30 13:06:13.770363 2026] [security2:error] [pid 849392:tid 849630] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.markmocek.com"] [uri "/ftde.php"] [unique_id "amuSlQMgr4yz2OQW0xrSCgAAAPA"]
[Thu Jul 30 13:06:13.849446 2026] [security2:error] [pid 849392:tid 849640] [client 172.236.9.101:1644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSlQMgr4yz2OQW0xrSBQAAAPo"]
[Thu Jul 30 13:06:14.606012 2026] [security2:error] [pid 849392:tid 849596] [client 20.171.55.167:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/alfanew.php7"] [unique_id "amuSlgMgr4yz2OQW0xrSCwAAAM4"]
[Thu Jul 30 13:06:15.391805 2026] [security2:error] [pid 849392:tid 849594] [client 20.171.55.167:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/adminfuns.php7"] [unique_id "amuSlwMgr4yz2OQW0xrSDgAAAMw"]
[Thu Jul 30 13:06:15.875918 2026] [security2:error] [pid 849392:tid 849614] [client 172.236.9.101:60558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSlwMgr4yz2OQW0xrSDwAAAOA"]
[Thu Jul 30 13:06:16.125064 2026] [security2:error] [pid 849392:tid 849547] [client 20.63.98.115:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ok.php"] [unique_id "amuSmAMgr4yz2OQW0xrSLQAAAJ0"]
[Thu Jul 30 13:06:16.278571 2026] [security2:error] [pid 849392:tid 849587] [client 20.171.55.167:5722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/ebs.php7"] [unique_id "amuSmAMgr4yz2OQW0xrSLgAAAMU"]
[Thu Jul 30 13:06:16.800171 2026] [security2:error] [pid 849392:tid 849516] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSmAMgr4yz2OQW0xrSLwAA4Xo"]
[Thu Jul 30 13:06:16.800343 2026] [security2:error] [pid 849392:tid 849615] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSmAMgr4yz2OQW0xrSLwAA4Xo"]
[Thu Jul 30 13:06:16.826846 2026] [core:notice] [pid 849392:tid 849508] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:16.999889 2026] [security2:error] [pid 849392:tid 849600] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuSmAMgr4yz2OQW0xrSKwAAANI"], referer: https://smoke-tfhk.com/product/ark-royal-sweet-chocolate/?add-to-cart=2026
[Thu Jul 30 13:06:17.532762 2026] [proxy:error] [pid 849392:tid 849613] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:17.532852 2026] [proxy_http:error] [pid 849392:tid 849613] [client 98.87.102.177:23625] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:17.533643 2026] [proxy:error] [pid 849392:tid 849613] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:17.533695 2026] [proxy_http:error] [pid 849392:tid 849613] [client 98.87.102.177:23625] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:17.547209 2026] [proxy:error] [pid 849392:tid 849534] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:17.547302 2026] [proxy_http:error] [pid 849392:tid 849534] [client 98.87.102.177:62648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:17.547872 2026] [proxy:error] [pid 849392:tid 849534] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:17.547914 2026] [proxy_http:error] [pid 849392:tid 849534] [client 98.87.102.177:62648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:18.205518 2026] [security2:error] [pid 849392:tid 849524] [client 20.171.55.167:6022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/ws.php7"] [unique_id "amuSmgMgr4yz2OQW0xrSSgAAAIY"]
[Thu Jul 30 13:06:19.182580 2026] [security2:error] [pid 849392:tid 849545] [client 20.171.55.167:5758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/alfanew2.php7"] [unique_id "amuSmwMgr4yz2OQW0xrSUQAAAJs"]
[Thu Jul 30 13:06:20.026015 2026] [security2:error] [pid 849392:tid 849590] [client 20.63.98.115:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuSnAMgr4yz2OQW0xrSVQAAAMg"]
[Thu Jul 30 13:06:20.060708 2026] [security2:error] [pid 849392:tid 849570] [client 20.171.55.167:5726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/alfa-rex2.php7"] [unique_id "amuSnAMgr4yz2OQW0xrSVgAAALQ"]
[Thu Jul 30 13:06:20.937619 2026] [security2:error] [pid 849392:tid 849646] [client 20.171.55.167:5719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/images/index.php"] [unique_id "amuSnAMgr4yz2OQW0xrSWwAAAQA"]
[Thu Jul 30 13:06:21.033563 2026] [core:notice] [pid 849392:tid 849649] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:21.829781 2026] [security2:error] [pid 849392:tid 849549] [client 20.171.55.167:5756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/colors/index.php"] [unique_id "amuSnQMgr4yz2OQW0xrSXgAAAJ8"]
[Thu Jul 30 13:06:22.385643 2026] [security2:error] [pid 849392:tid 849521] [remote 65.181.116.253:53282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amuSngMgr4yz2OQW0xrSYAAA3X8"]
[Thu Jul 30 13:06:22.622356 2026] [security2:error] [pid 849392:tid 849638] [client 20.171.55.167:5749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuSngMgr4yz2OQW0xrSZQAAAPg"]
[Thu Jul 30 13:06:22.713305 2026] [security2:error] [pid 849392:tid 849642] [client 20.63.98.115:1657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-configs.php"] [unique_id "amuSngMgr4yz2OQW0xrSZgAAAPw"]
[Thu Jul 30 13:06:22.904471 2026] [core:notice] [pid 849392:tid 849539] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:22.920587 2026] [core:notice] [pid 849392:tid 849590] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:22.978359 2026] [core:notice] [pid 849392:tid 849570] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:22.984963 2026] [core:notice] [pid 849392:tid 849636] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:22.989865 2026] [core:notice] [pid 849392:tid 849578] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:23.006633 2026] [core:notice] [pid 849392:tid 849581] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:23.037273 2026] [core:notice] [pid 849392:tid 849531] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:23.324673 2026] [security2:error] [pid 849392:tid 849593] [client 179.64.21.229:7904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSnwMgr4yz2OQW0xrScQAAAMs"]
[Thu Jul 30 13:06:23.328544 2026] [security2:error] [pid 849392:tid 849593] [client 179.64.21.229:7904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSnwMgr4yz2OQW0xrScQAAAMs"]
[Thu Jul 30 13:06:23.454342 2026] [security2:error] [pid 849392:tid 849580] [client 20.171.55.167:5756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "amuSnwMgr4yz2OQW0xrScgAAAL4"]
[Thu Jul 30 13:06:24.072037 2026] [proxy:error] [pid 849392:tid 849639] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:24.072109 2026] [proxy_http:error] [pid 849392:tid 849639] [client 44.213.206.96:35635] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:24.072681 2026] [proxy:error] [pid 849392:tid 849639] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:24.072727 2026] [proxy_http:error] [pid 849392:tid 849639] [client 44.213.206.96:35635] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:24.114038 2026] [proxy:error] [pid 849392:tid 849595] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:24.114115 2026] [proxy_http:error] [pid 849392:tid 849595] [client 44.213.206.96:64466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:24.114681 2026] [proxy:error] [pid 849392:tid 849595] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:24.114724 2026] [proxy_http:error] [pid 849392:tid 849595] [client 44.213.206.96:64466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:24.188644 2026] [security2:error] [pid 849392:tid 849632] [client 20.63.98.115:53272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/01.php"] [unique_id "amuSoAMgr4yz2OQW0xrSfgAAAPI"]
[Thu Jul 30 13:06:24.412233 2026] [security2:error] [pid 849392:tid 849537] [client 20.171.55.167:6042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuSoAMgr4yz2OQW0xrSgAAAAJM"]
[Thu Jul 30 13:06:25.034936 2026] [security2:error] [pid 849392:tid 849533] [client 20.63.98.115:1607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amuSoQMgr4yz2OQW0xrSggAAAI8"]
[Thu Jul 30 13:06:25.306025 2026] [security2:error] [pid 849392:tid 849630] [client 20.171.55.167:5228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "amuSoQMgr4yz2OQW0xrShgAAAPA"]
[Thu Jul 30 13:06:25.460047 2026] [security2:error] [pid 849392:tid 849401] [remote 77.95.113.183:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.113.95.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vietnambitcoin.app"] [uri "/wp-login.php"] [unique_id "amuSoQMgr4yz2OQW0xrSiAAA-gc"]
[Thu Jul 30 13:06:25.612701 2026] [core:notice] [pid 849392:tid 849628] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:25.809331 2026] [core:notice] [pid 849392:tid 849534] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:25.847398 2026] [security2:error] [pid 849392:tid 849602] [client 172.236.9.101:16709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSoQMgr4yz2OQW0xrShwAAANQ"]
[Thu Jul 30 13:06:26.077635 2026] [security2:error] [pid 849392:tid 849624] [client 145.223.140.90:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.140.223.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/431/585"] [unique_id "amuSoQMgr4yz2OQW0xrSjAAAAOo"]
[Thu Jul 30 13:06:26.198481 2026] [core:notice] [pid 849392:tid 849634] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:26.278186 2026] [security2:error] [pid 849392:tid 849594] [client 20.171.55.167:6021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "amuSogMgr4yz2OQW0xrSjgAAAMw"]
[Thu Jul 30 13:06:26.794034 2026] [security2:error] [pid 849392:tid 849546] [client 68.221.186.136:30826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/011i.php"] [unique_id "amuSogMgr4yz2OQW0xrSkQAAAJw"]
[Thu Jul 30 13:06:27.246961 2026] [security2:error] [pid 849392:tid 849523] [client 20.171.55.167:6041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/xmrlpc.php"] [unique_id "amuSowMgr4yz2OQW0xrSlgAAAIU"]
[Thu Jul 30 13:06:27.602392 2026] [security2:error] [pid 849392:tid 849399] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSowMgr4yz2OQW0xrSmwAAzgU"]
[Thu Jul 30 13:06:27.602543 2026] [security2:error] [pid 849392:tid 849596] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSowMgr4yz2OQW0xrSmwAAzgU"]
[Thu Jul 30 13:06:27.751716 2026] [security2:error] [pid 849392:tid 849637] [client 20.63.98.115:53326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amuSowMgr4yz2OQW0xrSnAAAAPc"]
[Thu Jul 30 13:06:27.879094 2026] [security2:error] [pid 849392:tid 849609] [client 167.88.167.87:48850] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "svcambodia.com"] [uri "/"] [unique_id "amuSowMgr4yz2OQW0xrSngAAANs"]
[Thu Jul 30 13:06:28.322536 2026] [security2:error] [pid 849392:tid 849633] [client 20.171.55.167:5720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuSpAMgr4yz2OQW0xrSpAAAAPM"]
[Thu Jul 30 13:06:28.798370 2026] [security2:error] [pid 849392:tid 849543] [client 20.63.98.115:46618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuSpAMgr4yz2OQW0xrSqAAAAJk"]
[Thu Jul 30 13:06:28.855145 2026] [security2:error] [pid 849392:tid 849578] [client 172.236.9.101:54791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSpAMgr4yz2OQW0xrSpQAAALw"]
[Thu Jul 30 13:06:28.954748 2026] [security2:error] [pid 849392:tid 849530] [client 68.221.186.136:33079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/03a005685d.php"] [unique_id "amuSpAMgr4yz2OQW0xrSrAAAAIw"]
[Thu Jul 30 13:06:29.375943 2026] [security2:error] [pid 849392:tid 849554] [client 20.171.55.167:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/css/xmrlpc.php"] [unique_id "amuSpQMgr4yz2OQW0xrSrQAAAKQ"]
[Thu Jul 30 13:06:29.705281 2026] [security2:error] [pid 849392:tid 849615] [client 68.221.186.136:33069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/403.php"] [unique_id "amuSpQMgr4yz2OQW0xrSswAAAOE"]
[Thu Jul 30 13:06:30.262194 2026] [security2:error] [pid 849392:tid 849542] [client 20.171.55.167:5710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuSpgMgr4yz2OQW0xrSuwAAAJg"]
[Thu Jul 30 13:06:30.991429 2026] [security2:error] [pid 849392:tid 849544] [client 20.63.98.115:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/db.php"] [unique_id "amuSpgMgr4yz2OQW0xrSvQAAAJo"]
[Thu Jul 30 13:06:31.165744 2026] [security2:error] [pid 849392:tid 849573] [client 20.171.55.167:5744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/img/xmrlpc.php"] [unique_id "amuSpwMgr4yz2OQW0xrSvgAAALc"]
[Thu Jul 30 13:06:31.952723 2026] [core:notice] [pid 849392:tid 849624] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:32.013395 2026] [security2:error] [pid 849392:tid 849616] [client 20.171.55.167:5701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "amuSqAMgr4yz2OQW0xrSxAAAAOI"]
[Thu Jul 30 13:06:32.509283 2026] [security2:error] [pid 849392:tid 849602] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSpwMgr4yz2OQW0xrSwQAAANQ"]
[Thu Jul 30 13:06:32.666625 2026] [security2:error] [pid 849392:tid 849577] [client 68.221.186.136:30280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/404.php"] [unique_id "amuSqAMgr4yz2OQW0xrSzgAAALs"]
[Thu Jul 30 13:06:32.872230 2026] [security2:error] [pid 849392:tid 849631] [client 20.171.55.167:5823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "amuSqAMgr4yz2OQW0xrS0AAAAPE"]
[Thu Jul 30 13:06:32.967709 2026] [security2:error] [pid 849392:tid 849613] [client 20.63.98.115:1618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/pages.php"] [unique_id "amuSqAMgr4yz2OQW0xrS1AAAAN8"]
[Thu Jul 30 13:06:33.131879 2026] [security2:error] [pid 849392:tid 849433] [remote 57.141.0.45:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45988126625/feed/rss2/"] [unique_id "amuSqQMgr4yz2OQW0xrS1QAAzic"]
[Thu Jul 30 13:06:33.193803 2026] [security2:error] [pid 849392:tid 849441] [remote 57.141.0.23:55826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6164509415/feed/rss2/"] [unique_id "amuSqQMgr4yz2OQW0xrS1gAAni8"]
[Thu Jul 30 13:06:33.770133 2026] [security2:error] [pid 849392:tid 849617] [client 20.171.55.167:5713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/images/xmrlpc.php"] [unique_id "amuSqQMgr4yz2OQW0xrS1wAAAOM"]
[Thu Jul 30 13:06:34.086287 2026] [core:notice] [pid 849392:tid 849539] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:34.147535 2026] [security2:error] [pid 849392:tid 849581] [client 179.64.21.229:55298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSqgMgr4yz2OQW0xrS2wAAAL8"]
[Thu Jul 30 13:06:34.147706 2026] [security2:error] [pid 849392:tid 849581] [client 179.64.21.229:55298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSqgMgr4yz2OQW0xrS2wAAAL8"]
[Thu Jul 30 13:06:34.249433 2026] [security2:error] [pid 849392:tid 849531] [client 185.223.152.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.152.223.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp-login.php"] [unique_id "amuSqQMgr4yz2OQW0xrS2AAAAI0"]
[Thu Jul 30 13:06:34.764749 2026] [security2:error] [pid 849392:tid 849530] [client 68.221.186.136:35983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/aa.php"] [unique_id "amuSqgMgr4yz2OQW0xrS3gAAAIw"]
[Thu Jul 30 13:06:34.771535 2026] [security2:error] [pid 849392:tid 849578] [client 20.171.55.167:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "amuSqgMgr4yz2OQW0xrS3wAAALw"]
[Thu Jul 30 13:06:34.817970 2026] [security2:error] [pid 849392:tid 849593] [client 20.63.98.115:53338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/admin.php"] [unique_id "amuSqgMgr4yz2OQW0xrS4wAAAMs"]
[Thu Jul 30 13:06:35.400585 2026] [security2:error] [pid 849392:tid 849554] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSqgMgr4yz2OQW0xrS4gAAAKQ"]
[Thu Jul 30 13:06:35.514319 2026] [security2:error] [pid 849392:tid 849623] [client 184.75.223.203:45414] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuSqwMgr4yz2OQW0xrS5wAAAOk"]
[Thu Jul 30 13:06:35.514473 2026] [security2:error] [pid 849392:tid 849623] [client 184.75.223.203:45414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuSqwMgr4yz2OQW0xrS5wAAAOk"]
[Thu Jul 30 13:06:35.646201 2026] [security2:error] [pid 849392:tid 849615] [client 20.171.55.167:5715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "amuSqwMgr4yz2OQW0xrS6AAAAOE"]
[Thu Jul 30 13:06:36.480809 2026] [security2:error] [pid 849392:tid 849632] [client 68.221.186.136:40671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/aafewc0k.php"] [unique_id "amuSrAMgr4yz2OQW0xrS6QAAAPI"]
[Thu Jul 30 13:06:36.484521 2026] [security2:error] [pid 849392:tid 849607] [client 20.171.55.167:5743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "amuSrAMgr4yz2OQW0xrS6gAAANk"]
[Thu Jul 30 13:06:37.393000 2026] [security2:error] [pid 849392:tid 849583] [client 20.171.55.167:5733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "amuSrQMgr4yz2OQW0xrS7AAAAME"]
[Thu Jul 30 13:06:37.422230 2026] [core:notice] [pid 849392:tid 849533] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:37.833696 2026] [proxy:error] [pid 849392:tid 849572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:37.833783 2026] [proxy_http:error] [pid 849392:tid 849572] [client 52.4.19.39:48601] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:37.834370 2026] [proxy:error] [pid 849392:tid 849572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:37.834415 2026] [proxy_http:error] [pid 849392:tid 849572] [client 52.4.19.39:48601] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:37.851545 2026] [proxy:error] [pid 849392:tid 849628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:37.851623 2026] [proxy_http:error] [pid 849392:tid 849628] [client 44.213.206.96:22937] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:37.852211 2026] [proxy:error] [pid 849392:tid 849628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:37.852257 2026] [proxy_http:error] [pid 849392:tid 849628] [client 44.213.206.96:22937] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:37.897596 2026] [security2:error] [pid 849392:tid 849591] [client 172.236.9.101:45869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSrQMgr4yz2OQW0xrS7QAAAMk"]
[Thu Jul 30 13:06:38.178174 2026] [security2:error] [pid 849392:tid 849611] [client 20.171.55.167:6124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/xmrlpc.php"] [unique_id "amuSrgMgr4yz2OQW0xrTBQAAAN0"]
[Thu Jul 30 13:06:38.348126 2026] [security2:error] [pid 849392:tid 849624] [client 20.63.98.115:53337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-load.php"] [unique_id "amuSrgMgr4yz2OQW0xrTBwAAAOo"]
[Thu Jul 30 13:06:38.473752 2026] [security2:error] [pid 849392:tid 849471] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSrgMgr4yz2OQW0xrTCAAAwk0"]
[Thu Jul 30 13:06:38.473913 2026] [security2:error] [pid 849392:tid 849584] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSrgMgr4yz2OQW0xrTCAAAwk0"]
[Thu Jul 30 13:06:38.848877 2026] [security2:error] [pid 849392:tid 849541] [client 68.221.186.136:30282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/abcd.php"] [unique_id "amuSrgMgr4yz2OQW0xrTHQAAAJc"]
[Thu Jul 30 13:06:39.025935 2026] [security2:error] [pid 849392:tid 849532] [client 20.171.55.167:5725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/text.php"] [unique_id "amuSrwMgr4yz2OQW0xrTIQAAAI4"]
[Thu Jul 30 13:06:39.093168 2026] [core:notice] [pid 849392:tid 849528] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:39.495507 2026] [security2:error] [pid 849392:tid 849607] [client 20.63.98.115:39668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/as/function.php"] [unique_id "amuSrwMgr4yz2OQW0xrTNgAAANk"]
[Thu Jul 30 13:06:39.508028 2026] [security2:error] [pid 849392:tid 849525] [client 184.75.223.203:55766] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuSrwMgr4yz2OQW0xrTNwAAAIc"]
[Thu Jul 30 13:06:39.508152 2026] [security2:error] [pid 849392:tid 849525] [client 184.75.223.203:55766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuSrwMgr4yz2OQW0xrTNwAAAIc"]
[Thu Jul 30 13:06:39.598367 2026] [security2:error] [pid 849392:tid 849640] [client 172.237.109.114:62815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSrwMgr4yz2OQW0xrTIwAAAPo"]
[Thu Jul 30 13:06:39.661647 2026] [security2:error] [pid 849392:tid 849580] [client 172.237.109.114:64519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSrwMgr4yz2OQW0xrTJQAAAL4"]
[Thu Jul 30 13:06:39.670539 2026] [security2:error] [pid 849392:tid 849647] [client 172.237.109.114:58482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSrwMgr4yz2OQW0xrTJAAAAQE"]
[Thu Jul 30 13:06:39.678422 2026] [security2:error] [pid 849392:tid 849572] [client 172.237.109.114:39929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSrwMgr4yz2OQW0xrTJwAAALY"]
[Thu Jul 30 13:06:39.692573 2026] [security2:error] [pid 849392:tid 849544] [client 172.237.109.114:15414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuSrwMgr4yz2OQW0xrTKAAAAJo"]
[Thu Jul 30 13:06:39.799699 2026] [security2:error] [pid 849392:tid 849547] [client 20.171.55.167:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/wp-admin/network/index.php"] [unique_id "amuSrwMgr4yz2OQW0xrTRgAAAJ0"]
[Thu Jul 30 13:06:40.398155 2026] [security2:error] [pid 849392:tid 849532] [client 20.63.98.115:53361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/filter.php"] [unique_id "amuSsAMgr4yz2OQW0xrTUgAAAI4"]
[Thu Jul 30 13:06:40.483805 2026] [security2:error] [pid 849392:tid 849611] [client 68.221.186.136:30825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/about.php"] [unique_id "amuSsAMgr4yz2OQW0xrTVAAAAN0"]
[Thu Jul 30 13:06:40.562567 2026] [security2:error] [pid 849392:tid 849549] [client 20.171.55.167:5199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/makeasmtp.php"] [unique_id "amuSsAMgr4yz2OQW0xrTVgAAAJ8"]
[Thu Jul 30 13:06:41.292544 2026] [security2:error] [pid 849392:tid 849638] [client 20.63.98.115:46614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/he.php"] [unique_id "amuSsQMgr4yz2OQW0xrTagAAAPg"]
[Thu Jul 30 13:06:41.299517 2026] [proxy:error] [pid 849392:tid 849646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:41.299575 2026] [proxy_http:error] [pid 849392:tid 849646] [client 98.87.102.177:51340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:41.300140 2026] [proxy:error] [pid 849392:tid 849646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:41.300186 2026] [proxy_http:error] [pid 849392:tid 849646] [client 98.87.102.177:51340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:42.402244 2026] [security2:error] [pid 849392:tid 849644] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuSsQMgr4yz2OQW0xrTdwAA_iw"]
[Thu Jul 30 13:06:42.732636 2026] [security2:error] [pid 849392:tid 849632] [client 20.63.98.115:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amuSsgMgr4yz2OQW0xrT3QAAAPI"]
[Thu Jul 30 13:06:43.021934 2026] [proxy:error] [pid 849392:tid 849626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:43.022020 2026] [proxy_http:error] [pid 849392:tid 849626] [client 44.213.206.96:17055] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:43.022592 2026] [proxy:error] [pid 849392:tid 849626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:43.022635 2026] [proxy_http:error] [pid 849392:tid 849626] [client 44.213.206.96:17055] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:43.035132 2026] [security2:error] [pid 849392:tid 849562] [client 85.208.96.206:53180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/11/sefaz-pb-libera-emissao-do-boleto-do-ipva-2022-para-pagamento-da-placa-com-final-3/"] [unique_id "amuSswMgr4yz2OQW0xrT8AAAAKw"]
[Thu Jul 30 13:06:43.035227 2026] [security2:error] [pid 849392:tid 849562] [client 85.208.96.206:53180] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/11/sefaz-pb-libera-emissao-do-boleto-do-ipva-2022-para-pagamento-da-placa-com-final-3/"] [unique_id "amuSswMgr4yz2OQW0xrT8AAAAKw"]
[Thu Jul 30 13:06:43.050269 2026] [proxy:error] [pid 849392:tid 849642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:43.050343 2026] [proxy_http:error] [pid 849392:tid 849642] [client 3.225.222.228:15043] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:43.050932 2026] [proxy:error] [pid 849392:tid 849642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:43.050994 2026] [proxy_http:error] [pid 849392:tid 849642] [client 3.225.222.228:15043] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:43.603589 2026] [security2:error] [pid 849392:tid 849644] [client 20.63.98.115:1661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amuSswMgr4yz2OQW0xrUHgAAAP4"]
[Thu Jul 30 13:06:43.946085 2026] [security2:error] [pid 849392:tid 849619] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSswMgr4yz2OQW0xrUAAAAAOU"]
[Thu Jul 30 13:06:44.574675 2026] [security2:error] [pid 849392:tid 849542] [client 179.64.21.229:27914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuStAMgr4yz2OQW0xrUVgAAAJg"]
[Thu Jul 30 13:06:44.574816 2026] [security2:error] [pid 849392:tid 849542] [client 179.64.21.229:27914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuStAMgr4yz2OQW0xrUVgAAAJg"]
[Thu Jul 30 13:06:44.788234 2026] [security2:error] [pid 849392:tid 849591] [client 68.221.186.136:36447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/admin.php"] [unique_id "amuStAMgr4yz2OQW0xrUYQAAAMk"]
[Thu Jul 30 13:06:45.385566 2026] [security2:error] [pid 849392:tid 849615] [client 68.221.186.136:32013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/adminfuns.php"] [unique_id "amuStQMgr4yz2OQW0xrUdQAAAOE"]
[Thu Jul 30 13:06:46.779153 2026] [fcgid:warn] [pid 849392:tid 849647] (70014)End of file found: [client 106.63.26.147:51326] mod_fcgid: can't get data from http client
[Thu Jul 30 13:06:47.431922 2026] [security2:error] [pid 849392:tid 849620] [client 68.221.186.136:37159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/albin.php"] [unique_id "amuStwMgr4yz2OQW0xrUqgAAAOY"]
[Thu Jul 30 13:06:47.598787 2026] [security2:error] [pid 849392:tid 849465] [remote 207.46.13.154:29038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/1196476238/article.php"] [unique_id "amuStwMgr4yz2OQW0xrUrAAA2Uc"]
[Thu Jul 30 13:06:48.306609 2026] [security2:error] [pid 849392:tid 849544] [client 68.221.186.136:32010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/amfsqvgv.php"] [unique_id "amuSuAMgr4yz2OQW0xrUvwAAAJo"]
[Thu Jul 30 13:06:49.014454 2026] [security2:error] [pid 849392:tid 849563] [client 68.221.186.136:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/ant.php"] [unique_id "amuSuQMgr4yz2OQW0xrUzwAAAK0"]
[Thu Jul 30 13:06:49.086183 2026] [security2:error] [pid 849392:tid 849548] [client 184.75.223.203:36732] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuSuQMgr4yz2OQW0xrU0QAAAJ4"]
[Thu Jul 30 13:06:49.086276 2026] [security2:error] [pid 849392:tid 849548] [client 184.75.223.203:36732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuSuQMgr4yz2OQW0xrU0QAAAJ4"]
[Thu Jul 30 13:06:49.311953 2026] [security2:error] [pid 849392:tid 849449] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSuQMgr4yz2OQW0xrU0gAA_zc"]
[Thu Jul 30 13:06:49.312140 2026] [security2:error] [pid 849392:tid 849645] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSuQMgr4yz2OQW0xrU0gAA_zc"]
[Thu Jul 30 13:06:50.663531 2026] [security2:error] [pid 849392:tid 849464] [remote 40.77.167.24:53929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/nouvelles-recentes/article.php"] [unique_id "amuSugMgr4yz2OQW0xrU8gAAjUY"]
[Thu Jul 30 13:06:51.513401 2026] [security2:error] [pid 849392:tid 849578] [client 20.63.98.115:1659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuSuwMgr4yz2OQW0xrU-QAAALw"]
[Thu Jul 30 13:06:51.576244 2026] [core:notice] [pid 849392:tid 849545] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:52.297149 2026] [security2:error] [pid 849392:tid 849646] [client 57.141.18.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laduchessecollections.com"] [uri "/index.php"] [unique_id "amuSugMgr4yz2OQW0xrU8AABACs"]
[Thu Jul 30 13:06:52.931070 2026] [security2:error] [pid 849392:tid 849595] [client 68.221.186.136:33063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/appreciators.php"] [unique_id "amuSvAMgr4yz2OQW0xrVDAAAAM0"]
[Thu Jul 30 13:06:53.349733 2026] [security2:error] [pid 849392:tid 849613] [client 156.225.1.44:48368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.217"] [uri "/index.cgi"] [unique_id "amuSvQMgr4yz2OQW0xrVDgAAAN8"]
[Thu Jul 30 13:06:53.544187 2026] [security2:error] [pid 849392:tid 849630] [client 156.225.1.44:48538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.217"] [uri "/index.cgi"] [unique_id "amuSvQMgr4yz2OQW0xrVFwAAAPA"]
[Thu Jul 30 13:06:53.757512 2026] [security2:error] [pid 849392:tid 849534] [client 156.225.1.44:48598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.217"] [uri "/index.cgi"] [unique_id "amuSvQMgr4yz2OQW0xrVGgAAAJA"]
[Thu Jul 30 13:06:53.938877 2026] [security2:error] [pid 849392:tid 849570] [client 156.225.1.44:48676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.217"] [uri "/index.cgi"] [unique_id "amuSvQMgr4yz2OQW0xrVIAAAALQ"]
[Thu Jul 30 13:06:54.122677 2026] [security2:error] [pid 849392:tid 849610] [client 156.225.1.44:48710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.217"] [uri "/index.cgi"] [unique_id "amuSvgMgr4yz2OQW0xrVJQAAANw"]
[Thu Jul 30 13:06:54.139996 2026] [security2:error] [pid 849392:tid 849602] [client 114.119.159.236:29085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/results-and-presentations"] [unique_id "amuSvgMgr4yz2OQW0xrVJgAAANQ"], referer: https://alseermarine.com/investor-relations/fact-sheet
[Thu Jul 30 13:06:54.343311 2026] [security2:error] [pid 849392:tid 849555] [client 68.221.186.136:46173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/archive.php"] [unique_id "amuSvgMgr4yz2OQW0xrVJwAAAKU"]
[Thu Jul 30 13:06:54.355220 2026] [security2:error] [pid 849392:tid 849528] [client 82.102.27.163:60510] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuSvgMgr4yz2OQW0xrVKAAAAIo"]
[Thu Jul 30 13:06:54.355311 2026] [security2:error] [pid 849392:tid 849528] [client 82.102.27.163:60510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuSvgMgr4yz2OQW0xrVKAAAAIo"]
[Thu Jul 30 13:06:54.847687 2026] [proxy:error] [pid 849392:tid 849569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:54.847762 2026] [proxy_http:error] [pid 849392:tid 849569] [client 32.194.121.99:16523] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:54.848508 2026] [proxy:error] [pid 849392:tid 849569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:54.848559 2026] [proxy_http:error] [pid 849392:tid 849569] [client 32.194.121.99:16523] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:54.884003 2026] [proxy:error] [pid 849392:tid 849586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:54.884070 2026] [proxy_http:error] [pid 849392:tid 849586] [client 34.224.175.62:58832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:54.884652 2026] [proxy:error] [pid 849392:tid 849586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:54.884708 2026] [proxy_http:error] [pid 849392:tid 849586] [client 34.224.175.62:58832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:55.010233 2026] [security2:error] [pid 849392:tid 849648] [client 179.64.21.229:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSvwMgr4yz2OQW0xrVSQAAAQI"]
[Thu Jul 30 13:06:55.010365 2026] [security2:error] [pid 849392:tid 849648] [client 179.64.21.229:56240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSvwMgr4yz2OQW0xrVSQAAAQI"]
[Thu Jul 30 13:06:55.086507 2026] [core:notice] [pid 849392:tid 849592] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:55.247203 2026] [security2:error] [pid 849392:tid 849609] [client 87.58.206.58:65147] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "happyspree.app"] [uri "/wp-content/plugins/wp-ticket/readme.txt"] [unique_id "amuSvwMgr4yz2OQW0xrVWwAAANs"]
[Thu Jul 30 13:06:55.313634 2026] [security2:error] [pid 849392:tid 849596] [client 68.221.186.136:36451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/as.php"] [unique_id "amuSvwMgr4yz2OQW0xrVXAAAAM4"]
[Thu Jul 30 13:06:55.702912 2026] [security2:error] [pid 849392:tid 849524] [client 87.58.206.58:65210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "happyspree.app"] [uri "/wp-content/plugins/wp-automatic/readme.txt"] [unique_id "amuSvwMgr4yz2OQW0xrVawAAAIY"]
[Thu Jul 30 13:06:55.941231 2026] [security2:error] [pid 849392:tid 849650] [client 114.119.136.3:45991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2023/01/037.webp"] [unique_id "amuSvwMgr4yz2OQW0xrVeAAAAQQ"], referer: https://portal9nordeste.com.br/salario-minimo-vai-ser-pago-normalmente-diz-haddad-nordeste-1/
[Thu Jul 30 13:06:55.954393 2026] [security2:error] [pid 849392:tid 849578] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuSvwMgr4yz2OQW0xrVdgAAALw"]
[Thu Jul 30 13:06:56.117959 2026] [security2:error] [pid 849392:tid 849583] [client 87.58.206.58:65256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "happyspree.app"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "amuSwAMgr4yz2OQW0xrVfAAAAME"]
[Thu Jul 30 13:06:56.506536 2026] [security2:error] [pid 849392:tid 849630] [client 87.58.206.58:65299] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "happyspree.app"] [uri "/wp-content/plugins/gamipress/readme.txt"] [unique_id "amuSwAMgr4yz2OQW0xrVggAAAPA"]
[Thu Jul 30 13:06:56.640336 2026] [security2:error] [pid 849392:tid 849580] [client 20.63.98.115:46811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "amuSwAMgr4yz2OQW0xrVgwAAAL4"]
[Thu Jul 30 13:06:56.931230 2026] [security2:error] [pid 849392:tid 849561] [client 68.221.186.136:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/atomlib.php"] [unique_id "amuSwAMgr4yz2OQW0xrVhwAAAKs"]
[Thu Jul 30 13:06:56.942320 2026] [security2:error] [pid 849392:tid 849581] [client 87.58.206.58:65336] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "happyspree.app"] [uri "/wp-content/plugins/userswp/readme.txt"] [unique_id "amuSwAMgr4yz2OQW0xrViAAAAL8"]
[Thu Jul 30 13:06:57.085624 2026] [security2:error] [pid 849392:tid 849615] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuSwAMgr4yz2OQW0xrVgQAAAOE"]
[Thu Jul 30 13:06:57.371614 2026] [security2:error] [pid 849392:tid 849609] [client 87.58.206.58:65391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "happyspree.app"] [uri "/wp-content/plugins/bookingpress-appointment-booking/readme.txt"] [unique_id "amuSwQMgr4yz2OQW0xrVigAAANs"]
[Thu Jul 30 13:06:57.421734 2026] [core:notice] [pid 849392:tid 849486] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:57.554903 2026] [security2:error] [pid 849392:tid 849593] [client 20.63.98.115:1451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/atomlib.php"] [unique_id "amuSwQMgr4yz2OQW0xrVjAAAAMs"]
[Thu Jul 30 13:06:57.667938 2026] [proxy:error] [pid 849392:tid 849596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:57.668038 2026] [proxy_http:error] [pid 849392:tid 849596] [client 3.228.112.215:15638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:57.668626 2026] [proxy:error] [pid 849392:tid 849596] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:57.668679 2026] [proxy_http:error] [pid 849392:tid 849596] [client 3.228.112.215:15638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:57.706137 2026] [proxy:error] [pid 849392:tid 849570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:57.706211 2026] [proxy_http:error] [pid 849392:tid 849570] [client 54.87.222.253:45889] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:57.706811 2026] [proxy:error] [pid 849392:tid 849570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:06:57.706865 2026] [proxy_http:error] [pid 849392:tid 849570] [client 54.87.222.253:45889] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:06:58.055349 2026] [core:notice] [pid 849392:tid 849517] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:06:58.652680 2026] [security2:error] [pid 849392:tid 849575] [client 101.32.60.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuSwgMgr4yz2OQW0xrVngAAALk"], referer: http://cnpinyin.com/dict1?search=%e4%b8%80%e5%88%99
[Thu Jul 30 13:06:59.147725 2026] [core:error] [pid 849392:tid 849607] [client 184.154.139.57:36308] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=abudhabicarrecoveryllc.site&yahoo.com
[Thu Jul 30 13:06:59.147752 2026] [core:error] [pid 849392:tid 849607] [client 184.154.139.57:36308] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=abudhabicarrecoveryllc.site&yahoo.com
[Thu Jul 30 13:06:59.290883 2026] [security2:error] [pid 849392:tid 849599] [client 184.75.223.203:44218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuSwwMgr4yz2OQW0xrVpQAAANE"]
[Thu Jul 30 13:06:59.290996 2026] [security2:error] [pid 849392:tid 849599] [client 184.75.223.203:44218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuSwwMgr4yz2OQW0xrVpQAAANE"]
[Thu Jul 30 13:06:59.542311 2026] [security2:error] [pid 849392:tid 849545] [client 68.221.186.136:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/autoload_classmap.php"] [unique_id "amuSwwMgr4yz2OQW0xrVpgAAAJs"]
[Thu Jul 30 13:06:59.949946 2026] [core:error] [pid 849392:tid 849516] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:06:59.949968 2026] [core:error] [pid 849392:tid 849516] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:07:00.097369 2026] [security2:error] [pid 849392:tid 849513] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSxAMgr4yz2OQW0xrVrQABAnc"]
[Thu Jul 30 13:07:00.097565 2026] [security2:error] [pid 849392:tid 849648] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSxAMgr4yz2OQW0xrVrQABAnc"]
[Thu Jul 30 13:07:00.577200 2026] [core:error] [pid 849392:tid 849394] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:07:00.577222 2026] [core:error] [pid 849392:tid 849394] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:07:00.623191 2026] [security2:error] [pid 849392:tid 849553] [client 68.221.186.136:37591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/bb.php"] [unique_id "amuSxAMgr4yz2OQW0xrVtAAAAKM"]
[Thu Jul 30 13:07:02.196071 2026] [security2:error] [pid 849392:tid 849646] [client 68.221.186.136:37575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/bnm.php"] [unique_id "amuSxgMgr4yz2OQW0xrVwQAAAQA"]
[Thu Jul 30 13:07:02.300919 2026] [security2:error] [pid 849392:tid 849520] [remote 103.253.21.184:40080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.21.253.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuSxgMgr4yz2OQW0xrVwgAAkH4"]
[Thu Jul 30 13:07:02.660866 2026] [core:notice] [pid 849392:tid 849514] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:03.026574 2026] [security2:error] [pid 849392:tid 849570] [client 114.119.129.163:20807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sv.radiojelli.com"] [uri "/when-your-kids-hit-each-other"] [unique_id "amuSxwMgr4yz2OQW0xrVxgAAALQ"], referer: https://sv.radiojelli.com/sitemaps/sitemap0.xml
[Thu Jul 30 13:07:03.608771 2026] [security2:error] [pid 849392:tid 849608] [client 20.63.98.115:1422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuSxwMgr4yz2OQW0xrVyQAAANo"]
[Thu Jul 30 13:07:04.421963 2026] [security2:error] [pid 849392:tid 849559] [client 172.213.208.20:21432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wk/index.php"] [unique_id "amuSyAMgr4yz2OQW0xrV0gAAAKk"]
[Thu Jul 30 13:07:04.916160 2026] [security2:error] [pid 849392:tid 849634] [client 68.221.186.136:33076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/bootstrap.php"] [unique_id "amuSyAMgr4yz2OQW0xrV1QAAAPQ"]
[Thu Jul 30 13:07:05.154893 2026] [security2:error] [pid 849392:tid 849401] [remote 65.181.116.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frontierphoenix.site"] [uri "/xmlrpc.php"] [unique_id "amuSyQMgr4yz2OQW0xrV1gAAowc"]
[Thu Jul 30 13:07:05.155102 2026] [security2:error] [pid 849392:tid 849553] [client 65.181.116.253:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "frontierphoenix.site"] [uri "/xmlrpc.php"] [unique_id "amuSyQMgr4yz2OQW0xrV1gAAowc"]
[Thu Jul 30 13:07:05.599967 2026] [security2:error] [pid 849392:tid 849630] [client 179.64.21.229:2030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSyQMgr4yz2OQW0xrV1wAAAPA"]
[Thu Jul 30 13:07:05.600140 2026] [security2:error] [pid 849392:tid 849630] [client 179.64.21.229:2030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuSyQMgr4yz2OQW0xrV1wAAAPA"]
[Thu Jul 30 13:07:05.869170 2026] [security2:error] [pid 849392:tid 849582] [client 172.213.208.20:15856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/av.php"] [unique_id "amuSyQMgr4yz2OQW0xrV5QAAAMA"]
[Thu Jul 30 13:07:06.314051 2026] [security2:error] [pid 849392:tid 849541] [client 20.63.98.115:53959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/gebase.php"] [unique_id "amuSygMgr4yz2OQW0xrV7AAAAJc"]
[Thu Jul 30 13:07:06.600499 2026] [security2:error] [pid 849392:tid 849633] [client 68.221.186.136:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/buy.php"] [unique_id "amuSygMgr4yz2OQW0xrV8AAAAPM"]
[Thu Jul 30 13:07:07.211060 2026] [security2:error] [pid 849392:tid 849560] [client 68.221.186.136:37578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/chosen.php"] [unique_id "amuSywMgr4yz2OQW0xrV9QAAAKo"]
[Thu Jul 30 13:07:07.411834 2026] [security2:error] [pid 849392:tid 849595] [client 114.119.156.86:42085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/soldes-ete-etsy/soldes-ete-etsy-bijoux-vict/"] [unique_id "amuSywMgr4yz2OQW0xrV-gAAAM0"], referer: https://www.carnetdeshopping.com/soldes-ete-etsy/soldes-ete-etsy-bijoux-vict/
[Thu Jul 30 13:07:07.492258 2026] [security2:error] [pid 849392:tid 849547] [client 20.63.98.115:57386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/xl.php"] [unique_id "amuSywMgr4yz2OQW0xrV-wAAAJ0"]
[Thu Jul 30 13:07:07.882862 2026] [proxy:error] [pid 849392:tid 849534] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:07.882947 2026] [proxy_http:error] [pid 849392:tid 849534] [client 34.233.129.35:51961] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:07.883581 2026] [proxy:error] [pid 849392:tid 849534] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:07.883632 2026] [proxy_http:error] [pid 849392:tid 849534] [client 34.233.129.35:51961] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:07.896156 2026] [proxy:error] [pid 849392:tid 849586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:07.896230 2026] [proxy_http:error] [pid 849392:tid 849586] [client 34.224.175.62:9494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:07.897050 2026] [proxy:error] [pid 849392:tid 849586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:07.897107 2026] [proxy_http:error] [pid 849392:tid 849586] [client 34.224.175.62:9494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:08.453437 2026] [security2:error] [pid 849392:tid 849622] [client 185.200.116.219:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuSzAMgr4yz2OQW0xrWBgAAAOg"]
[Thu Jul 30 13:07:08.453545 2026] [security2:error] [pid 849392:tid 849622] [client 185.200.116.219:51156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuSzAMgr4yz2OQW0xrWBgAAAOg"]
[Thu Jul 30 13:07:08.723830 2026] [security2:error] [pid 849392:tid 849587] [client 20.63.98.115:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/2.php"] [unique_id "amuSzAMgr4yz2OQW0xrWCgAAAMU"]
[Thu Jul 30 13:07:09.713703 2026] [security2:error] [pid 849392:tid 849635] [client 68.221.186.136:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/class-wp-image.php"] [unique_id "amuSzQMgr4yz2OQW0xrWDgAAAPU"]
[Thu Jul 30 13:07:10.145695 2026] [security2:error] [pid 849392:tid 849611] [client 20.63.98.115:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/baxa1.php"] [unique_id "amuSzgMgr4yz2OQW0xrWEwAAAN0"]
[Thu Jul 30 13:07:10.409222 2026] [proxy:error] [pid 849392:tid 849585] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:10.409294 2026] [proxy_http:error] [pid 849392:tid 849585] [client 54.87.222.253:23483] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:10.409907 2026] [proxy:error] [pid 849392:tid 849585] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:10.409956 2026] [proxy_http:error] [pid 849392:tid 849585] [client 54.87.222.253:23483] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:10.426316 2026] [proxy:error] [pid 849392:tid 849543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:10.426386 2026] [proxy_http:error] [pid 849392:tid 849543] [client 3.228.112.215:63679] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:10.426988 2026] [proxy:error] [pid 849392:tid 849543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:10.427035 2026] [proxy_http:error] [pid 849392:tid 849543] [client 3.228.112.215:63679] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:10.798736 2026] [security2:error] [pid 849392:tid 849415] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSzgMgr4yz2OQW0xrWHgAAkBU"]
[Thu Jul 30 13:07:10.798941 2026] [security2:error] [pid 849392:tid 849534] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuSzgMgr4yz2OQW0xrWHgAAkBU"]
[Thu Jul 30 13:07:11.132131 2026] [security2:error] [pid 849392:tid 849628] [client 20.63.98.115:53962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/settings.php"] [unique_id "amuSzwMgr4yz2OQW0xrWIwAAAO4"]
[Thu Jul 30 13:07:12.580867 2026] [security2:error] [pid 849392:tid 849574] [client 68.221.186.136:33025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/classsmtps.php"] [unique_id "amuS0AMgr4yz2OQW0xrWMwAAALg"]
[Thu Jul 30 13:07:12.621260 2026] [security2:error] [pid 849392:tid 849607] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuS0AMgr4yz2OQW0xrWLwAAANk"]
[Thu Jul 30 13:07:12.730923 2026] [proxy:error] [pid 849392:tid 849554] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:12.731036 2026] [proxy_http:error] [pid 849392:tid 849554] [client 34.224.175.62:12169] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:12.731611 2026] [proxy:error] [pid 849392:tid 849554] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:12.731655 2026] [proxy_http:error] [pid 849392:tid 849554] [client 34.224.175.62:12169] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:12.742319 2026] [proxy:error] [pid 849392:tid 849579] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:12.742381 2026] [proxy_http:error] [pid 849392:tid 849579] [client 34.224.175.62:21522] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:12.742929 2026] [proxy:error] [pid 849392:tid 849579] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:12.742970 2026] [proxy_http:error] [pid 849392:tid 849579] [client 34.224.175.62:21522] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:14.338587 2026] [security2:error] [pid 849392:tid 849422] [remote 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuS0QMgr4yz2OQW0xrWQgAAoBw"]
[Thu Jul 30 13:07:14.892202 2026] [security2:error] [pid 849392:tid 849400] [remote 57.141.0.28:53292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuS0gMgr4yz2OQW0xrWTwAA0wY"]
[Thu Jul 30 13:07:14.995888 2026] [security2:error] [pid 849392:tid 849632] [client 68.221.186.136:34481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/classwithtostring.php"] [unique_id "amuS0gMgr4yz2OQW0xrWUwAAAPI"]
[Thu Jul 30 13:07:15.776731 2026] [security2:error] [pid 849392:tid 849420] [remote 57.141.0.68:51236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuS0wMgr4yz2OQW0xrWXgAA0Ro"]
[Thu Jul 30 13:07:16.284893 2026] [security2:error] [pid 849392:tid 849549] [client 179.64.21.229:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuS1AMgr4yz2OQW0xrWaAAAAJ8"]
[Thu Jul 30 13:07:16.288581 2026] [security2:error] [pid 849392:tid 849549] [client 179.64.21.229:50788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuS1AMgr4yz2OQW0xrWaAAAAJ8"]
[Thu Jul 30 13:07:16.371594 2026] [security2:error] [pid 849392:tid 849636] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuS0wMgr4yz2OQW0xrWXQAA9kQ"]
[Thu Jul 30 13:07:16.855096 2026] [security2:error] [pid 849392:tid 849619] [client 20.63.98.115:37436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/dropdown.php"] [unique_id "amuS1AMgr4yz2OQW0xrWbgAAAOU"]
[Thu Jul 30 13:07:17.134285 2026] [security2:error] [pid 849392:tid 849649] [client 68.221.186.136:33075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/config.php"] [unique_id "amuS1QMgr4yz2OQW0xrWdAAAAQM"]
[Thu Jul 30 13:07:17.155554 2026] [security2:error] [pid 849392:tid 849473] [remote 47.128.27.63:17224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/search/Nike/page/59/"] [unique_id "amuS1QMgr4yz2OQW0xrWdQAAiU8"]
[Thu Jul 30 13:07:18.052136 2026] [security2:error] [pid 849392:tid 849641] [client 68.221.186.136:37579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/core.php"] [unique_id "amuS1gMgr4yz2OQW0xrWfwAAAPs"]
[Thu Jul 30 13:07:18.498679 2026] [security2:error] [pid 849392:tid 849570] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuS1QMgr4yz2OQW0xrWfQAAALQ"]
[Thu Jul 30 13:07:18.681992 2026] [security2:error] [pid 849392:tid 849533] [client 68.221.186.136:30823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/css.php"] [unique_id "amuS1gMgr4yz2OQW0xrWggAAAI8"]
[Thu Jul 30 13:07:19.113848 2026] [security2:error] [pid 849392:tid 849590] [client 172.213.208.20:21438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/mini.php"] [unique_id "amuS1wMgr4yz2OQW0xrWhgAAAMg"]
[Thu Jul 30 13:07:19.506238 2026] [security2:error] [pid 849392:tid 849546] [client 172.236.9.101:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/login.php"] [unique_id "amuS1wMgr4yz2OQW0xrWhwAAAJw"]
[Thu Jul 30 13:07:20.199125 2026] [security2:error] [pid 849392:tid 849624] [client 68.221.186.136:30275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/database.php"] [unique_id "amuS2AMgr4yz2OQW0xrWiQAAAOo"]
[Thu Jul 30 13:07:20.492595 2026] [security2:error] [pid 849392:tid 849553] [client 172.213.208.20:18189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/aa.php"] [unique_id "amuS2AMgr4yz2OQW0xrWjAAAAKM"]
[Thu Jul 30 13:07:21.334805 2026] [security2:error] [pid 849392:tid 849606] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuS2AMgr4yz2OQW0xrWjwAAANg"]
[Thu Jul 30 13:07:21.478946 2026] [security2:error] [pid 849392:tid 849445] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuS2QMgr4yz2OQW0xrWlQAAhjM"]
[Thu Jul 30 13:07:21.479102 2026] [security2:error] [pid 849392:tid 849524] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuS2QMgr4yz2OQW0xrWlQAAhjM"]
[Thu Jul 30 13:07:21.568738 2026] [security2:error] [pid 849392:tid 849594] [client 20.63.98.115:37577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin.php"] [unique_id "amuS2QMgr4yz2OQW0xrWlwAAAMw"]
[Thu Jul 30 13:07:21.701815 2026] [security2:error] [pid 849392:tid 849599] [client 172.213.208.20:21405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/w.php"] [unique_id "amuS2QMgr4yz2OQW0xrWmQAAANE"]
[Thu Jul 30 13:07:21.807424 2026] [security2:error] [pid 849392:tid 849568] [client 68.221.186.136:30818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/db.php"] [unique_id "amuS2QMgr4yz2OQW0xrWmgAAALI"]
[Thu Jul 30 13:07:22.384050 2026] [security2:error] [pid 849392:tid 849531] [client 172.213.208.20:17196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/admin.php"] [unique_id "amuS2gMgr4yz2OQW0xrWmwAAAI0"]
[Thu Jul 30 13:07:22.840250 2026] [security2:error] [pid 849392:tid 849590] [client 68.221.186.136:30326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/default.php"] [unique_id "amuS2gMgr4yz2OQW0xrWngAAAMg"]
[Thu Jul 30 13:07:23.948389 2026] [security2:error] [pid 849392:tid 849649] [client 172.213.208.20:9219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/themes/admin.php"] [unique_id "amuS2wMgr4yz2OQW0xrWpwAAAQM"]
[Thu Jul 30 13:07:24.333593 2026] [security2:error] [pid 849392:tid 849614] [client 114.119.144.17:27385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/search"] [unique_id "amuS3AMgr4yz2OQW0xrWrAAAAOA"], referer: https://www.kendarikomputer.com/search?updated-max=2023-05-20T20%3A11%3A00%2B08%3A00&max-results=10&reverse-paginate=true&m=1
[Thu Jul 30 13:07:24.565400 2026] [security2:error] [pid 849392:tid 849578] [client 20.63.98.115:37425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/buy.php"] [unique_id "amuS3AMgr4yz2OQW0xrWrgAAALw"]
[Thu Jul 30 13:07:24.852877 2026] [security2:error] [pid 849392:tid 849625] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuS3AMgr4yz2OQW0xrWqwAAAOs"]
[Thu Jul 30 13:07:25.151837 2026] [security2:error] [pid 849392:tid 849563] [client 172.213.208.20:24919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/m.php"] [unique_id "amuS3QMgr4yz2OQW0xrWrwAAAK0"]
[Thu Jul 30 13:07:25.367600 2026] [core:notice] [pid 849392:tid 849575] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:25.771998 2026] [security2:error] [pid 849392:tid 849541] [client 172.236.9.101:26378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuS3QMgr4yz2OQW0xrWsAAAAJc"]
[Thu Jul 30 13:07:26.184253 2026] [security2:error] [pid 849392:tid 849627] [client 110.249.202.191:11154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-peace.com"] [uri "/robots.txt"] [unique_id "amuS3gMgr4yz2OQW0xrWtwAAAO0"]
[Thu Jul 30 13:07:26.424285 2026] [security2:error] [pid 849392:tid 849591] [client 20.63.98.115:1832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/mini.php"] [unique_id "amuS3gMgr4yz2OQW0xrWuAAAAMk"]
[Thu Jul 30 13:07:26.555989 2026] [security2:error] [pid 849392:tid 849620] [client 179.64.21.229:55337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuS3gMgr4yz2OQW0xrWugAAAOY"]
[Thu Jul 30 13:07:26.556130 2026] [security2:error] [pid 849392:tid 849620] [client 179.64.21.229:55337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuS3gMgr4yz2OQW0xrWugAAAOY"]
[Thu Jul 30 13:07:26.919770 2026] [security2:error] [pid 849392:tid 849634] [client 172.213.208.20:18401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuS3gMgr4yz2OQW0xrWuwAAAPQ"]
[Thu Jul 30 13:07:27.324648 2026] [security2:error] [pid 849392:tid 849605] [client 20.63.98.115:1689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/cd.php"] [unique_id "amuS3wMgr4yz2OQW0xrWvQAAANc"]
[Thu Jul 30 13:07:27.779534 2026] [autoindex:error] [pid 849392:tid 849635] [client 172.213.208.20:18233] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:07:27.878216 2026] [security2:error] [pid 849392:tid 849543] [client 68.221.186.136:23490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/dropdown.php"] [unique_id "amuS3wMgr4yz2OQW0xrWxQAAAJk"]
[Thu Jul 30 13:07:27.909073 2026] [security2:error] [pid 849392:tid 849532] [client 172.213.208.20:18233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/classwithtostring.php"] [unique_id "amuS3wMgr4yz2OQW0xrWxgAAAI4"]
[Thu Jul 30 13:07:28.373727 2026] [security2:error] [pid 849392:tid 849554] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuS3wMgr4yz2OQW0xrWwgAAAKQ"]
[Thu Jul 30 13:07:28.394405 2026] [security2:error] [pid 849392:tid 849638] [client 68.221.186.136:30785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/edit.php"] [unique_id "amuS4AMgr4yz2OQW0xrWywAAAPg"]
[Thu Jul 30 13:07:28.501031 2026] [core:notice] [pid 849392:tid 849589] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:28.619545 2026] [security2:error] [pid 849392:tid 849617] [client 172.213.208.20:18176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/gmo.php"] [unique_id "amuS4AMgr4yz2OQW0xrW0QAAAOM"]
[Thu Jul 30 13:07:28.780994 2026] [security2:error] [pid 849392:tid 849629] [client 20.63.98.115:1719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuS4AMgr4yz2OQW0xrW0wAAAO8"]
[Thu Jul 30 13:07:29.199804 2026] [security2:error] [pid 849392:tid 849570] [client 82.102.27.163:44506] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuS4QMgr4yz2OQW0xrW1gAAALQ"]
[Thu Jul 30 13:07:29.199917 2026] [security2:error] [pid 849392:tid 849570] [client 82.102.27.163:44506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuS4QMgr4yz2OQW0xrW1gAAALQ"]
[Thu Jul 30 13:07:29.281062 2026] [security2:error] [pid 849392:tid 849439] [remote 114.119.142.7:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/get/vancouver"] [unique_id "amuS4QMgr4yz2OQW0xrW4AAAzi0"], referer: https://www.jipkl.com/index.php/JIPKL/article/view/59
[Thu Jul 30 13:07:29.371545 2026] [security2:error] [pid 849392:tid 849573] [client 172.213.208.20:21416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/languages/index.php"] [unique_id "amuS4QMgr4yz2OQW0xrW5gAAALc"]
[Thu Jul 30 13:07:29.693525 2026] [security2:error] [pid 849392:tid 849533] [client 20.63.98.115:1794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/batm.php"] [unique_id "amuS4QMgr4yz2OQW0xrW6AAAAI8"]
[Thu Jul 30 13:07:29.966761 2026] [security2:error] [pid 849392:tid 849627] [client 172.213.208.20:17195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-the.php"] [unique_id "amuS4QMgr4yz2OQW0xrW6QAAAO0"]
[Thu Jul 30 13:07:30.719880 2026] [security2:error] [pid 849392:tid 849618] [client 172.236.9.101:41123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuS4gMgr4yz2OQW0xrW6gAAAOQ"]
[Thu Jul 30 13:07:30.883017 2026] [security2:error] [pid 849392:tid 849537] [client 68.221.186.136:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/f35.php"] [unique_id "amuS4gMgr4yz2OQW0xrW6wAAAJM"]
[Thu Jul 30 13:07:31.131040 2026] [security2:error] [pid 849392:tid 849635] [client 172.213.208.20:24922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/404.php"] [unique_id "amuS4wMgr4yz2OQW0xrW7AAAAPU"]
[Thu Jul 30 13:07:31.257021 2026] [core:notice] [pid 849392:tid 849607] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:32.097270 2026] [core:notice] [pid 849392:tid 849642] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:32.220372 2026] [security2:error] [pid 849392:tid 849475] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuS5AMgr4yz2OQW0xrW-AAAqFE"]
[Thu Jul 30 13:07:32.220589 2026] [security2:error] [pid 849392:tid 849558] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuS5AMgr4yz2OQW0xrW-AAAqFE"]
[Thu Jul 30 13:07:32.235093 2026] [security2:error] [pid 849392:tid 849648] [client 172.213.208.20:24937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/init.php"] [unique_id "amuS5AMgr4yz2OQW0xrW-gAAAQI"]
[Thu Jul 30 13:07:32.253578 2026] [security2:error] [pid 849392:tid 849546] [client 52.167.144.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuS4wMgr4yz2OQW0xrW7wAAAJw"]
[Thu Jul 30 13:07:32.724732 2026] [security2:error] [pid 849392:tid 849555] [client 172.236.9.101:8158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuS5AMgr4yz2OQW0xrW-wAAAKU"]
[Thu Jul 30 13:07:33.108850 2026] [security2:error] [pid 849392:tid 849564] [client 172.213.208.20:22723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/file5.php"] [unique_id "amuS5QMgr4yz2OQW0xrXBAAAAK4"]
[Thu Jul 30 13:07:33.275252 2026] [security2:error] [pid 849392:tid 849601] [client 20.63.98.115:49359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/hehehehe.php"] [unique_id "amuS5QMgr4yz2OQW0xrXCAAAANM"]
[Thu Jul 30 13:07:33.651919 2026] [security2:error] [pid 849392:tid 849615] [client 68.221.186.136:36477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/f7.php"] [unique_id "amuS5QMgr4yz2OQW0xrXCQAAAOE"]
[Thu Jul 30 13:07:34.120347 2026] [security2:error] [pid 849392:tid 849569] [client 114.119.159.6:57395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kingstarenterprises.com"] [uri "/product-category/gym-club-accessories/versa-grips/"] [unique_id "amuS5gMgr4yz2OQW0xrXCwAAALM"], referer: http://www.kingstarenterprises.com/
[Thu Jul 30 13:07:35.167194 2026] [security2:error] [pid 849392:tid 849623] [client 172.213.208.20:19919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/maint/index.php"] [unique_id "amuS5wMgr4yz2OQW0xrXEAAAAOk"]
[Thu Jul 30 13:07:35.952960 2026] [security2:error] [pid 849392:tid 849645] [client 114.119.145.205:39441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/2026/02/"] [unique_id "amuS5wMgr4yz2OQW0xrXGQAAAP8"], referer: https://saifalkhaleejest.com/when-to-use-rotation-chain-hoists-over-standard-chain-hoists/
[Thu Jul 30 13:07:36.247388 2026] [security2:error] [pid 849392:tid 849578] [client 20.63.98.115:1809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/sim.php/wp-includes/certificates/plugins.php"] [unique_id "amuS6AMgr4yz2OQW0xrXGwAAALw"]
[Thu Jul 30 13:07:36.501159 2026] [security2:error] [pid 849392:tid 849635] [client 185.200.116.219:46580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuS6AMgr4yz2OQW0xrXHQAAAPU"]
[Thu Jul 30 13:07:36.501262 2026] [security2:error] [pid 849392:tid 849635] [client 185.200.116.219:46580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuS6AMgr4yz2OQW0xrXHQAAAPU"]
[Thu Jul 30 13:07:36.966719 2026] [autoindex:error] [pid 849392:tid 849626] [client 89.22.101.69:56044] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_b63f1d3b/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:07:37.019786 2026] [security2:error] [pid 849392:tid 849636] [client 172.213.208.20:21424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/shell.php"] [unique_id "amuS6QMgr4yz2OQW0xrXIQAAAPY"]
[Thu Jul 30 13:07:37.138212 2026] [security2:error] [pid 849392:tid 849480] [remote 198.38.94.87:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/wp-login.php"] [unique_id "amuS6QMgr4yz2OQW0xrXIwAApFY"]
[Thu Jul 30 13:07:37.171396 2026] [security2:error] [pid 849392:tid 849586] [client 179.64.21.229:8201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuS6QMgr4yz2OQW0xrXJAAAAMQ"]
[Thu Jul 30 13:07:37.179544 2026] [security2:error] [pid 849392:tid 849586] [client 179.64.21.229:8201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuS6QMgr4yz2OQW0xrXJAAAAMQ"]
[Thu Jul 30 13:07:37.576256 2026] [security2:error] [pid 849392:tid 849547] [client 20.63.98.115:1682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-seo.php"] [unique_id "amuS6QMgr4yz2OQW0xrXKQAAAJ0"]
[Thu Jul 30 13:07:37.749111 2026] [security2:error] [pid 849392:tid 849603] [client 172.213.208.20:19930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/f35.php"] [unique_id "amuS6QMgr4yz2OQW0xrXLQAAANU"]
[Thu Jul 30 13:07:37.781093 2026] [security2:error] [pid 849392:tid 849648] [client 172.236.9.101:19560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuS6QMgr4yz2OQW0xrXJQAAAQI"]
[Thu Jul 30 13:07:38.222488 2026] [security2:error] [pid 849392:tid 849587] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuS6QMgr4yz2OQW0xrXLAAAAMU"]
[Thu Jul 30 13:07:38.462679 2026] [security2:error] [pid 849392:tid 849544] [client 40.77.177.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuS6gMgr4yz2OQW0xrXMgAAAJo"]
[Thu Jul 30 13:07:38.912421 2026] [security2:error] [pid 849392:tid 849548] [client 20.63.98.115:53966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/zwso.php"] [unique_id "amuS6gMgr4yz2OQW0xrXMwAAAJ4"]
[Thu Jul 30 13:07:39.432351 2026] [security2:error] [pid 849392:tid 849479] [remote 198.38.94.87:50608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amuS6wMgr4yz2OQW0xrXNQAAkFU"]
[Thu Jul 30 13:07:39.747485 2026] [security2:error] [pid 849392:tid 849647] [client 172.236.9.101:11998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuS6wMgr4yz2OQW0xrXNAAAAQE"]
[Thu Jul 30 13:07:39.966191 2026] [core:notice] [pid 849392:tid 849477] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:40.242097 2026] [core:notice] [pid 849392:tid 849483] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:40.346330 2026] [security2:error] [pid 849392:tid 849594] [client 172.213.208.20:17799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/new.php"] [unique_id "amuS7AMgr4yz2OQW0xrXOgAAAMw"]
[Thu Jul 30 13:07:40.717016 2026] [security2:error] [pid 849392:tid 849640] [client 20.63.98.115:53955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/user.php"] [unique_id "amuS7AMgr4yz2OQW0xrXOwAAAPo"]
[Thu Jul 30 13:07:41.082343 2026] [security2:error] [pid 849392:tid 849600] [client 172.213.208.20:10119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/adminfuns.php"] [unique_id "amuS7QMgr4yz2OQW0xrXQAAAANI"]
[Thu Jul 30 13:07:41.462867 2026] [security2:error] [pid 849392:tid 849528] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuS7AMgr4yz2OQW0xrXPwAAAIo"]
[Thu Jul 30 13:07:42.433226 2026] [security2:error] [pid 849392:tid 849627] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuS7QMgr4yz2OQW0xrXRwAAAO0"]
[Thu Jul 30 13:07:42.510096 2026] [security2:error] [pid 849392:tid 849621] [client 20.63.98.115:37439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/assets/index.php"] [unique_id "amuS7gMgr4yz2OQW0xrXUQAAAOc"]
[Thu Jul 30 13:07:43.045834 2026] [security2:error] [pid 849392:tid 849500] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuS7wMgr4yz2OQW0xrXVwAAx2o"]
[Thu Jul 30 13:07:43.045997 2026] [security2:error] [pid 849392:tid 849589] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuS7wMgr4yz2OQW0xrXVwAAx2o"]
[Thu Jul 30 13:07:43.374184 2026] [security2:error] [pid 849392:tid 849649] [client 172.236.9.101:60537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php-backup"] [unique_id "amuS7wMgr4yz2OQW0xrXWAAAAQM"]
[Thu Jul 30 13:07:43.500182 2026] [autoindex:error] [pid 849392:tid 849557] [client 172.213.208.20:9758] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:07:43.670370 2026] [security2:error] [pid 849392:tid 849603] [client 172.213.208.20:9758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/fm.php"] [unique_id "amuS7wMgr4yz2OQW0xrXXQAAANU"]
[Thu Jul 30 13:07:44.212771 2026] [security2:error] [pid 849392:tid 849630] [client 20.63.98.115:37627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/byp.php"] [unique_id "amuS8AMgr4yz2OQW0xrXXwAAAPA"]
[Thu Jul 30 13:07:44.354061 2026] [security2:error] [pid 849392:tid 849564] [client 114.119.130.40:59065] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-peace.com"] [uri "/robots.txt"] [unique_id "amuS8AMgr4yz2OQW0xrXYAAAAK4"], referer: https://shop-peace.com/robots.txt
[Thu Jul 30 13:07:44.776378 2026] [proxy:error] [pid 849392:tid 849601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:44.776460 2026] [proxy_http:error] [pid 849392:tid 849601] [client 18.211.55.47:18793] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:44.777061 2026] [proxy:error] [pid 849392:tid 849601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:44.777107 2026] [proxy_http:error] [pid 849392:tid 849601] [client 18.211.55.47:18793] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:44.805788 2026] [proxy:error] [pid 849392:tid 849574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:44.805868 2026] [proxy_http:error] [pid 849392:tid 849574] [client 44.216.125.112:55545] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:44.806466 2026] [proxy:error] [pid 849392:tid 849574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:07:44.806513 2026] [proxy_http:error] [pid 849392:tid 849574] [client 44.216.125.112:55545] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:07:45.354059 2026] [core:notice] [pid 849392:tid 849534] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:45.625050 2026] [security2:error] [pid 849392:tid 849642] [client 172.213.208.20:9759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuS8QMgr4yz2OQW0xrXbwAAAPw"]
[Thu Jul 30 13:07:45.654225 2026] [security2:error] [pid 849392:tid 849628] [client 172.213.232.128:45107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/LA.php"] [unique_id "amuS8QMgr4yz2OQW0xrXcQAAAO4"]
[Thu Jul 30 13:07:45.906099 2026] [security2:error] [pid 849392:tid 849566] [client 172.213.208.20:9759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/file.php"] [unique_id "amuS8QMgr4yz2OQW0xrXcwAAALA"]
[Thu Jul 30 13:07:45.998232 2026] [core:notice] [pid 849392:tid 849624] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:46.172964 2026] [core:notice] [pid 849392:tid 849640] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:47.026532 2026] [security2:error] [pid 849392:tid 849528] [client 172.213.232.128:45387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/admin.php"] [unique_id "amuS8wMgr4yz2OQW0xrXewAAAIo"]
[Thu Jul 30 13:07:47.407820 2026] [security2:error] [pid 849392:tid 849563] [client 20.63.98.115:49349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/bs1.php"] [unique_id "amuS8wMgr4yz2OQW0xrXgQAAAK0"]
[Thu Jul 30 13:07:47.695293 2026] [security2:error] [pid 849392:tid 849559] [client 114.119.131.182:57085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabian-tours.com"] [uri "/site/map-of-botswana-with-cities-56216b"] [unique_id "amuS8wMgr4yz2OQW0xrXggAAAKk"], referer: https://arabian-tours.com/site/surf-report-56216b
[Thu Jul 30 13:07:48.413969 2026] [security2:error] [pid 849392:tid 849567] [client 172.213.232.128:28460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/class_api.php"] [unique_id "amuS9AMgr4yz2OQW0xrXhAAAALE"]
[Thu Jul 30 13:07:48.656527 2026] [security2:error] [pid 849392:tid 849620] [client 20.203.148.31:30146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.tmb/LA.php"] [unique_id "amuS9AMgr4yz2OQW0xrXhQAAAOY"]
[Thu Jul 30 13:07:49.100176 2026] [security2:error] [pid 849392:tid 849641] [client 114.119.153.169:50449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/docs/5cfb7b-portsmouth-kit-20/5cfb7b-where-is-the-chat-box-in-microsoft-teams"] [unique_id "amuS9QMgr4yz2OQW0xrXhgAAAPs"], referer: https://arabiandubaisafari.com/docs/5cfb7b-portsmouth-kit-20/5cfb7b-where-is-the-chat-box-in-microsoft-teams
[Thu Jul 30 13:07:49.312094 2026] [security2:error] [pid 849392:tid 849539] [client 114.119.137.64:20911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiantourz.com"] [uri "/soldes/femme-vero-moda-vmana-noir-t-shirts-polos/"] [unique_id "amuS9QMgr4yz2OQW0xrXhwAAAJU"], referer: http://arabiantourz.com/
[Thu Jul 30 13:07:49.322320 2026] [security2:error] [pid 849392:tid 849533] [client 172.213.232.128:28459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuS9QMgr4yz2OQW0xrXiAAAAI8"]
[Thu Jul 30 13:07:49.424220 2026] [security2:error] [pid 849392:tid 849635] [client 20.63.98.115:37587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/IXR/allez.php"] [unique_id "amuS9QMgr4yz2OQW0xrXiQAAAPU"]
[Thu Jul 30 13:07:49.637230 2026] [security2:error] [pid 849392:tid 849634] [client 20.203.148.31:34136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.tmb/admin.php"] [unique_id "amuS9QMgr4yz2OQW0xrXigAAAPQ"]
[Thu Jul 30 13:07:49.772155 2026] [core:notice] [pid 849392:tid 849621] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:50.335814 2026] [security2:error] [pid 849392:tid 849626] [client 20.63.98.115:1668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/load.php"] [unique_id "amuS9gMgr4yz2OQW0xrXjAAAAOw"]
[Thu Jul 30 13:07:50.702486 2026] [security2:error] [pid 849392:tid 849650] [client 20.203.148.31:38439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.tmb/class_api.php"] [unique_id "amuS9gMgr4yz2OQW0xrXjgAAAQQ"]
[Thu Jul 30 13:07:50.940414 2026] [core:notice] [pid 849392:tid 849586] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:51.272328 2026] [security2:error] [pid 849392:tid 849558] [client 172.213.232.128:45118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.tmb/wp-login.php"] [unique_id "amuS9wMgr4yz2OQW0xrXkQAAAKg"]
[Thu Jul 30 13:07:51.411471 2026] [security2:error] [pid 849392:tid 849649] [client 20.63.98.115:37405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/privacy.php"] [unique_id "amuS9wMgr4yz2OQW0xrXkwAAAQM"]
[Thu Jul 30 13:07:51.444046 2026] [core:notice] [pid 849392:tid 849515] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:52.072024 2026] [core:notice] [pid 849392:tid 849603] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:52.584070 2026] [core:notice] [pid 849392:tid 849564] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:52.683866 2026] [autoindex:error] [pid 849392:tid 849540] [client 172.213.208.20:10077] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:07:52.782418 2026] [security2:error] [pid 849392:tid 849631] [client 20.63.98.115:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-cli.php"] [unique_id "amuS-AMgr4yz2OQW0xrXmAAAAPE"]
[Thu Jul 30 13:07:52.814684 2026] [security2:error] [pid 849392:tid 849606] [client 172.213.208.20:10077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/bolt.php"] [unique_id "amuS-AMgr4yz2OQW0xrXmQAAANg"]
[Thu Jul 30 13:07:52.856098 2026] [security2:error] [pid 849392:tid 849552] [client 20.203.148.31:34172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuS-AMgr4yz2OQW0xrXmgAAAKI"]
[Thu Jul 30 13:07:53.519063 2026] [security2:error] [pid 849392:tid 849608] [client 172.213.208.20:15262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/3.php"] [unique_id "amuS-QMgr4yz2OQW0xrXnAAAANo"]
[Thu Jul 30 13:07:53.844427 2026] [security2:error] [pid 849392:tid 849574] [client 20.203.148.31:28734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuS-QMgr4yz2OQW0xrXnQAAALg"]
[Thu Jul 30 13:07:53.882465 2026] [security2:error] [pid 849392:tid 849614] [client 172.236.9.101:22328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuS-QMgr4yz2OQW0xrXmwAAAOA"]
[Thu Jul 30 13:07:53.911830 2026] [security2:error] [pid 849392:tid 849513] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuS-QMgr4yz2OQW0xrXowAAhXc"]
[Thu Jul 30 13:07:53.911994 2026] [security2:error] [pid 849392:tid 849523] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuS-QMgr4yz2OQW0xrXowAAhXc"]
[Thu Jul 30 13:07:54.237853 2026] [security2:error] [pid 849392:tid 849610] [client 20.63.98.115:37390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/cc.php"] [unique_id "amuS-gMgr4yz2OQW0xrXpAAAANw"]
[Thu Jul 30 13:07:55.097247 2026] [security2:error] [pid 849392:tid 849642] [client 172.213.232.128:28244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuS-wMgr4yz2OQW0xrXpgAAAPw"]
[Thu Jul 30 13:07:55.171880 2026] [security2:error] [pid 849392:tid 849573] [client 172.213.208.20:9729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/222.php"] [unique_id "amuS-wMgr4yz2OQW0xrXqgAAALc"]
[Thu Jul 30 13:07:55.294484 2026] [security2:error] [pid 849392:tid 849594] [client 20.203.148.31:34147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuS-wMgr4yz2OQW0xrXqwAAAMw"]
[Thu Jul 30 13:07:56.110868 2026] [security2:error] [pid 849392:tid 849628] [client 20.63.98.115:1810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/media-new.php"] [unique_id "amuS_AMgr4yz2OQW0xrXrAAAAO4"]
[Thu Jul 30 13:07:56.327523 2026] [security2:error] [pid 849392:tid 849562] [client 68.67.112.68:1226] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuS_AMgr4yz2OQW0xrXrgAAAKw"]
[Thu Jul 30 13:07:56.746304 2026] [core:notice] [pid 849392:tid 849497] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:07:57.146309 2026] [security2:error] [pid 849392:tid 849528] [client 172.213.232.128:45097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/991176.php"] [unique_id "amuS_QMgr4yz2OQW0xrXuQAAAIo"]
[Thu Jul 30 13:07:57.354963 2026] [security2:error] [pid 849392:tid 849542] [client 20.203.148.31:38411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/991176.php"] [unique_id "amuS_QMgr4yz2OQW0xrXugAAAJg"]
[Thu Jul 30 13:07:57.616793 2026] [security2:error] [pid 849392:tid 849623] [client 172.213.208.20:21434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/images/admin.php"] [unique_id "amuS_QMgr4yz2OQW0xrXuwAAAOk"]
[Thu Jul 30 13:07:57.838740 2026] [security2:error] [pid 849392:tid 849532] [client 172.213.232.128:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuS_QMgr4yz2OQW0xrXvAAAAI4"]
[Thu Jul 30 13:07:58.161318 2026] [security2:error] [pid 849392:tid 849495] [remote 45.92.108.143:33060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuS_gMgr4yz2OQW0xrXvgAAx2U"]
[Thu Jul 30 13:07:58.231206 2026] [security2:error] [pid 849392:tid 849545] [client 179.64.21.229:52578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuS_gMgr4yz2OQW0xrXvwAAAJs"]
[Thu Jul 30 13:07:58.235015 2026] [security2:error] [pid 849392:tid 849545] [client 179.64.21.229:52578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuS_gMgr4yz2OQW0xrXvwAAAJs"]
[Thu Jul 30 13:07:58.339077 2026] [security2:error] [pid 849392:tid 849621] [client 20.63.98.115:1271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-blog.php"] [unique_id "amuS_gMgr4yz2OQW0xrXwAAAAOc"]
[Thu Jul 30 13:07:59.640646 2026] [security2:error] [pid 849392:tid 849648] [client 170.106.84.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuS_wMgr4yz2OQW0xrXxgAAAQI"]
[Thu Jul 30 13:07:59.739604 2026] [security2:error] [pid 849392:tid 849536] [client 172.213.232.128:46355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuS_wMgr4yz2OQW0xrXxwAAAJI"]
[Thu Jul 30 13:07:59.913195 2026] [security2:error] [pid 849392:tid 849650] [client 20.203.148.31:30196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuS_wMgr4yz2OQW0xrXyAAAAQQ"]
[Thu Jul 30 13:08:00.144598 2026] [security2:error] [pid 849392:tid 849560] [client 20.63.98.115:37221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-2019.php"] [unique_id "amuTAAMgr4yz2OQW0xrXyQAAAKo"]
[Thu Jul 30 13:08:00.678776 2026] [security2:error] [pid 849392:tid 849587] [client 172.213.232.128:28251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuTAAMgr4yz2OQW0xrXzgAAAMU"]
[Thu Jul 30 13:08:01.504308 2026] [security2:error] [pid 849392:tid 849601] [client 172.213.208.20:15826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuTAQMgr4yz2OQW0xrX0gAAANM"]
[Thu Jul 30 13:08:01.617936 2026] [security2:error] [pid 849392:tid 849523] [client 20.63.98.115:34076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/menu.php"] [unique_id "amuTAQMgr4yz2OQW0xrX0wAAAIU"]
[Thu Jul 30 13:08:01.671810 2026] [security2:error] [pid 849392:tid 849614] [client 172.213.232.128:45058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuTAQMgr4yz2OQW0xrX1AAAAOA"]
[Thu Jul 30 13:08:01.741804 2026] [core:notice] [pid 849392:tid 849615] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:02.757034 2026] [security2:error] [pid 849392:tid 849622] [client 20.203.148.31:38412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuTAgMgr4yz2OQW0xrX2QAAAOg"]
[Thu Jul 30 13:08:02.861079 2026] [security2:error] [pid 849392:tid 849549] [client 172.213.232.128:44384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuTAgMgr4yz2OQW0xrX2gAAAJ8"]
[Thu Jul 30 13:08:02.990310 2026] [autoindex:error] [pid 849392:tid 849534] [client 172.213.208.20:18377] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:08:03.173700 2026] [security2:error] [pid 849392:tid 849599] [client 172.213.208.20:18377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/admin.php"] [unique_id "amuTAwMgr4yz2OQW0xrX3AAAANE"]
[Thu Jul 30 13:08:03.782812 2026] [security2:error] [pid 849392:tid 849640] [client 172.213.208.20:9218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-configs.php"] [unique_id "amuTAwMgr4yz2OQW0xrX4QAAAPo"]
[Thu Jul 30 13:08:03.855313 2026] [security2:error] [pid 849392:tid 849541] [client 20.63.98.115:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-crons.php"] [unique_id "amuTAwMgr4yz2OQW0xrX4gAAAJc"]
[Thu Jul 30 13:08:04.315475 2026] [proxy:error] [pid 849392:tid 849629] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:04.315544 2026] [proxy_http:error] [pid 849392:tid 849629] [client 34.233.129.35:46955] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:04.316156 2026] [proxy:error] [pid 849392:tid 849629] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:04.316212 2026] [proxy_http:error] [pid 849392:tid 849629] [client 34.233.129.35:46955] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:04.319214 2026] [proxy:error] [pid 849392:tid 849604] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:04.319277 2026] [proxy_http:error] [pid 849392:tid 849604] [client 34.233.129.35:31626] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:04.319854 2026] [proxy:error] [pid 849392:tid 849604] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:04.319902 2026] [proxy_http:error] [pid 849392:tid 849604] [client 34.233.129.35:31626] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:04.596992 2026] [security2:error] [pid 849392:tid 849406] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTBAMgr4yz2OQW0xrX7gAA8gw"]
[Thu Jul 30 13:08:04.597143 2026] [security2:error] [pid 849392:tid 849632] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTBAMgr4yz2OQW0xrX7gAA8gw"]
[Thu Jul 30 13:08:04.630435 2026] [security2:error] [pid 849392:tid 849535] [client 20.203.148.31:5705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuTBAMgr4yz2OQW0xrX7wAAAJE"]
[Thu Jul 30 13:08:04.810452 2026] [security2:error] [pid 849392:tid 849580] [client 172.213.232.128:44395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuTBAMgr4yz2OQW0xrX8QAAAL4"]
[Thu Jul 30 13:08:05.355078 2026] [security2:error] [pid 849392:tid 849595] [client 20.203.148.31:5724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuTBQMgr4yz2OQW0xrX-wAAAM0"]
[Thu Jul 30 13:08:05.466833 2026] [security2:error] [pid 849392:tid 849545] [client 172.213.232.128:47750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuTBQMgr4yz2OQW0xrX_AAAAJs"]
[Thu Jul 30 13:08:06.089520 2026] [security2:error] [pid 849392:tid 849644] [client 20.203.148.31:5729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuTBgMgr4yz2OQW0xrX_gAAAP4"]
[Thu Jul 30 13:08:06.375787 2026] [security2:error] [pid 849392:tid 849597] [client 172.213.232.128:44368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuTBgMgr4yz2OQW0xrYBQAAAM8"]
[Thu Jul 30 13:08:06.403690 2026] [security2:error] [pid 849392:tid 849578] [client 20.63.98.115:1252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/class.php"] [unique_id "amuTBgMgr4yz2OQW0xrYBgAAALw"]
[Thu Jul 30 13:08:06.551324 2026] [security2:error] [pid 849392:tid 849603] [client 114.119.128.56:30973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/4/"] [unique_id "amuTBgMgr4yz2OQW0xrYBwAAANU"], referer: https://kicksity.com/shop/?min_price=0&max_price=140&filtering=1&filter_product_cat=166%2C197%2C138%2C146%2C137%2C195
[Thu Jul 30 13:08:06.784073 2026] [security2:error] [pid 849392:tid 849539] [client 172.213.208.20:9689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/php.php"] [unique_id "amuTBgMgr4yz2OQW0xrYCgAAAJU"]
[Thu Jul 30 13:08:07.150382 2026] [security2:error] [pid 849392:tid 849523] [client 172.213.232.128:44367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuTBwMgr4yz2OQW0xrYFAAAAIU"]
[Thu Jul 30 13:08:07.602493 2026] [security2:error] [pid 849392:tid 849614] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTBwMgr4yz2OQW0xrYDwAA4BY"]
[Thu Jul 30 13:08:07.736050 2026] [security2:error] [pid 849392:tid 849615] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTBwMgr4yz2OQW0xrYEwAAAOE"]
[Thu Jul 30 13:08:07.741336 2026] [security2:error] [pid 849392:tid 849572] [client 20.63.98.115:37243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/login.php"] [unique_id "amuTBwMgr4yz2OQW0xrYGAAAALY"]
[Thu Jul 30 13:08:07.755958 2026] [security2:error] [pid 849392:tid 849574] [client 172.213.232.128:44366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuTBwMgr4yz2OQW0xrYGwAAALg"]
[Thu Jul 30 13:08:07.982031 2026] [security2:error] [pid 849392:tid 849600] [client 220.181.108.146:1443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9378"] [unique_id "amuTBwMgr4yz2OQW0xrYIAAAANI"]
[Thu Jul 30 13:08:08.181784 2026] [proxy:error] [pid 849392:tid 849637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:08.181881 2026] [proxy_http:error] [pid 849392:tid 849637] [client 54.87.222.253:17589] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:08.182681 2026] [proxy:error] [pid 849392:tid 849637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:08.182735 2026] [proxy_http:error] [pid 849392:tid 849637] [client 54.87.222.253:17589] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:08.199814 2026] [proxy:error] [pid 849392:tid 849571] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:08.199899 2026] [proxy_http:error] [pid 849392:tid 849571] [client 3.228.112.215:41614] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:08.200518 2026] [proxy:error] [pid 849392:tid 849571] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:08.202021 2026] [proxy_http:error] [pid 849392:tid 849571] [client 3.228.112.215:41614] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:08.500073 2026] [security2:error] [pid 849392:tid 849550] [client 172.213.232.128:44391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuTCAMgr4yz2OQW0xrYLAAAAKA"]
[Thu Jul 30 13:08:08.969275 2026] [core:notice] [pid 849392:tid 849632] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:09.015005 2026] [security2:error] [pid 849392:tid 849565] [client 179.64.21.229:33660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTCQMgr4yz2OQW0xrYNwAAAK8"]
[Thu Jul 30 13:08:09.018813 2026] [security2:error] [pid 849392:tid 849565] [client 179.64.21.229:33660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTCQMgr4yz2OQW0xrYNwAAAK8"]
[Thu Jul 30 13:08:09.102995 2026] [security2:error] [pid 849392:tid 849533] [client 20.63.98.115:37777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/aged.php"] [unique_id "amuTCQMgr4yz2OQW0xrYOAAAAI8"]
[Thu Jul 30 13:08:09.139631 2026] [security2:error] [pid 849392:tid 849399] [remote 95.108.213.159:63102] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/"] [unique_id "amuTCQMgr4yz2OQW0xrYOQABAAU"]
[Thu Jul 30 13:08:09.268901 2026] [security2:error] [pid 849392:tid 849584] [client 172.213.232.128:46809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuTCQMgr4yz2OQW0xrYOwAAAMI"]
[Thu Jul 30 13:08:09.936066 2026] [security2:error] [pid 849392:tid 849545] [client 114.119.155.115:53615] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/assurance-and-advisory/"] [unique_id "amuTCQMgr4yz2OQW0xrYQwAAAJs"], referer: http://pkf.jo/Home/News?id=7142&parid=0&ltid=4
[Thu Jul 30 13:08:09.951037 2026] [security2:error] [pid 849392:tid 849621] [client 172.213.232.128:47798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuTCQMgr4yz2OQW0xrYRAAAAOc"]
[Thu Jul 30 13:08:10.778438 2026] [security2:error] [pid 849392:tid 849535] [client 20.203.148.31:34157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuTCgMgr4yz2OQW0xrYSAAAAJE"]
[Thu Jul 30 13:08:11.240728 2026] [security2:error] [pid 849392:tid 849557] [client 172.213.232.128:46829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/amaxx.php"] [unique_id "amuTCwMgr4yz2OQW0xrYTQAAAKc"]
[Thu Jul 30 13:08:11.272497 2026] [core:notice] [pid 849392:tid 849536] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:11.391929 2026] [core:notice] [pid 849392:tid 849650] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:11.519267 2026] [core:notice] [pid 849392:tid 849582] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:11.539170 2026] [core:notice] [pid 849392:tid 849560] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:11.550254 2026] [core:notice] [pid 849392:tid 849608] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:11.650199 2026] [security2:error] [pid 849392:tid 849561] [client 20.63.98.115:37809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/vv.php"] [unique_id "amuTCwMgr4yz2OQW0xrYVAAAAKs"]
[Thu Jul 30 13:08:11.982269 2026] [security2:error] [pid 849392:tid 849596] [client 172.213.232.128:47748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/bek.php"] [unique_id "amuTCwMgr4yz2OQW0xrYVgAAAM4"]
[Thu Jul 30 13:08:12.032169 2026] [security2:error] [pid 849392:tid 849585] [client 20.203.148.31:34159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuTDAMgr4yz2OQW0xrYVwAAAMM"]
[Thu Jul 30 13:08:12.503625 2026] [core:notice] [pid 849392:tid 849553] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:12.562860 2026] [proxy:error] [pid 849392:tid 849544] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:12.562926 2026] [proxy_http:error] [pid 849392:tid 849544] [client 34.224.175.62:54639] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:12.563570 2026] [proxy:error] [pid 849392:tid 849544] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:12.563619 2026] [proxy_http:error] [pid 849392:tid 849544] [client 34.224.175.62:54639] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:12.775920 2026] [security2:error] [pid 849392:tid 849530] [client 20.203.148.31:5714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuTDAMgr4yz2OQW0xrYaAAAAIw"]
[Thu Jul 30 13:08:13.124217 2026] [security2:error] [pid 849392:tid 849566] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTDAMgr4yz2OQW0xrYXwAAALA"]
[Thu Jul 30 13:08:13.221892 2026] [security2:error] [pid 849392:tid 849615] [client 20.63.98.115:61619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/user-edit.php"] [unique_id "amuTDQMgr4yz2OQW0xrYagAAAOE"]
[Thu Jul 30 13:08:13.921218 2026] [security2:error] [pid 849392:tid 849637] [client 20.203.148.31:5753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuTDQMgr4yz2OQW0xrYbAAAAPc"]
[Thu Jul 30 13:08:14.571581 2026] [core:notice] [pid 849392:tid 849555] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:14.571779 2026] [core:notice] [pid 849392:tid 849590] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:14.809559 2026] [proxy:error] [pid 849392:tid 849527] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:14.809642 2026] [proxy_http:error] [pid 849392:tid 849527] [client 3.228.112.215:46895] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:14.810501 2026] [proxy:error] [pid 849392:tid 849527] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:14.810553 2026] [proxy_http:error] [pid 849392:tid 849527] [client 3.228.112.215:46895] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:14.811545 2026] [core:notice] [pid 849392:tid 849580] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:14.812834 2026] [core:notice] [pid 849392:tid 849579] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:14.817777 2026] [core:notice] [pid 849392:tid 849575] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:14.818105 2026] [proxy:error] [pid 849392:tid 849635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:14.818166 2026] [proxy_http:error] [pid 849392:tid 849635] [client 3.228.112.215:23870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:14.818740 2026] [proxy:error] [pid 849392:tid 849635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:14.818784 2026] [proxy_http:error] [pid 849392:tid 849635] [client 3.228.112.215:23870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:14.923381 2026] [core:notice] [pid 849392:tid 849646] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:14.930058 2026] [core:notice] [pid 849392:tid 849577] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:15.058575 2026] [core:notice] [pid 849392:tid 849554] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:15.160885 2026] [core:notice] [pid 849392:tid 849631] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:15.170448 2026] [core:notice] [pid 849392:tid 849540] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:15.373902 2026] [security2:error] [pid 849392:tid 849620] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTDgMgr4yz2OQW0xrYcQAAAOY"]
[Thu Jul 30 13:08:15.474603 2026] [security2:error] [pid 849392:tid 849402] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTDwMgr4yz2OQW0xrYgwAAnAg"]
[Thu Jul 30 13:08:15.474765 2026] [security2:error] [pid 849392:tid 849546] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTDwMgr4yz2OQW0xrYgwAAnAg"]
[Thu Jul 30 13:08:15.553775 2026] [security2:error] [pid 849392:tid 849595] [client 20.203.148.31:34131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuTDwMgr4yz2OQW0xrYhgAAAM0"]
[Thu Jul 30 13:08:15.649310 2026] [security2:error] [pid 849392:tid 849551] [client 20.63.98.115:46745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuTDwMgr4yz2OQW0xrYhwAAAKE"]
[Thu Jul 30 13:08:15.757816 2026] [core:notice] [pid 849392:tid 849612] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:15.764647 2026] [core:notice] [pid 849392:tid 849649] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:16.017699 2026] [core:notice] [pid 849392:tid 849641] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:16.100251 2026] [core:notice] [pid 849392:tid 849547] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:16.121183 2026] [core:notice] [pid 849392:tid 849648] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:16.195353 2026] [security2:error] [pid 849392:tid 849636] [client 172.213.232.128:47754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuTEAMgr4yz2OQW0xrYjgAAAPY"]
[Thu Jul 30 13:08:16.583638 2026] [security2:error] [pid 849392:tid 849630] [client 20.63.98.115:1917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/engine.php"] [unique_id "amuTEAMgr4yz2OQW0xrYkAAAAPA"]
[Thu Jul 30 13:08:16.794825 2026] [security2:error] [pid 849392:tid 849601] [client 172.213.232.128:47771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/class.api.php"] [unique_id "amuTEAMgr4yz2OQW0xrYkQAAANM"]
[Thu Jul 30 13:08:17.194744 2026] [security2:error] [pid 849392:tid 849650] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuTEAMgr4yz2OQW0xrYjwAAANo"]
[Thu Jul 30 13:08:17.698891 2026] [security2:error] [pid 849392:tid 849523] [client 172.213.232.128:28286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/cong.php"] [unique_id "amuTEQMgr4yz2OQW0xrYlQAAAIU"]
[Thu Jul 30 13:08:17.736121 2026] [security2:error] [pid 849392:tid 849553] [client 20.63.98.115:1892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/edit-comments.php"] [unique_id "amuTEQMgr4yz2OQW0xrYlgAAAKM"]
[Thu Jul 30 13:08:17.823369 2026] [security2:error] [pid 849392:tid 849524] [client 172.236.9.101:4340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTEQMgr4yz2OQW0xrYlAAAAIY"]
[Thu Jul 30 13:08:18.248408 2026] [security2:error] [pid 849392:tid 849639] [client 172.213.232.128:28254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/content.php"] [unique_id "amuTEgMgr4yz2OQW0xrYngAAAPk"]
[Thu Jul 30 13:08:18.248419 2026] [security2:error] [pid 849392:tid 849573] [client 20.203.148.31:5717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuTEgMgr4yz2OQW0xrYnQAAALc"]
[Thu Jul 30 13:08:18.248433 2026] [security2:error] [pid 849392:tid 849538] [client 114.119.150.16:44869] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuTEgMgr4yz2OQW0xrYnwAAAJQ"], referer: http://www.toscanamall.com/en/?s=121395701
[Thu Jul 30 13:08:18.443755 2026] [security2:error] [pid 849392:tid 849562] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuTEQMgr4yz2OQW0xrYlwAAAMw"]
[Thu Jul 30 13:08:18.867081 2026] [security2:error] [pid 849392:tid 849602] [client 20.63.98.115:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-blog-header.php"] [unique_id "amuTEgMgr4yz2OQW0xrYoAAAANQ"]
[Thu Jul 30 13:08:19.237594 2026] [security2:error] [pid 849392:tid 849566] [client 172.213.232.128:27916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/cwianpri.php"] [unique_id "amuTEwMgr4yz2OQW0xrYoQAAALA"]
[Thu Jul 30 13:08:19.608469 2026] [security2:error] [pid 849392:tid 849642] [client 179.64.21.229:47412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTEwMgr4yz2OQW0xrYogAAAPw"]
[Thu Jul 30 13:08:19.613875 2026] [security2:error] [pid 849392:tid 849642] [client 179.64.21.229:47412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTEwMgr4yz2OQW0xrYogAAAPw"]
[Thu Jul 30 13:08:19.730280 2026] [security2:error] [pid 849392:tid 849600] [client 20.63.98.115:1856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/alfa-rex.php7"] [unique_id "amuTEwMgr4yz2OQW0xrYowAAANI"]
[Thu Jul 30 13:08:19.855395 2026] [security2:error] [pid 849392:tid 849640] [client 114.119.132.170:45733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product-tag/hope-%e5%b8%8c%e6%9c%9b%e9%a6%99%e7%85%9914mg%e6%97%a5%e6%9c%ac%e6%9c%ac%e5%9c%9f%e5%85%8d%e7%a8%85%e9%a6%99%e6%b8%af%e7%8f%be%e8%b2%a8"] [unique_id "amuTEwMgr4yz2OQW0xrYpAAAAPo"], referer: https://online-hope.com/product-tag/hope-%e5%b8%8c%e6%9c%9b%e9%a6%99%e7%85%9914mg%e6%97%a5%e6%9c%ac%e6%9c%ac%e5%9c%9f%e5%85%8d%e7%a8%85%e9%a6%99%e6%b8%af%e7%8f%be%e8%b2%a8
[Thu Jul 30 13:08:19.907514 2026] [security2:error] [pid 849392:tid 849569] [client 20.203.148.31:34116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuTEwMgr4yz2OQW0xrYpQAAALM"]
[Thu Jul 30 13:08:20.075081 2026] [security2:error] [pid 849392:tid 849531] [client 52.15.147.27:1812] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuTEwMgr4yz2OQW0xrYpgAAAI0"], referer: https://globalmarks.pk/
[Thu Jul 30 13:08:20.532452 2026] [security2:error] [pid 849392:tid 849618] [client 20.203.148.31:31817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuTFAMgr4yz2OQW0xrYqAAAAOQ"]
[Thu Jul 30 13:08:21.041645 2026] [security2:error] [pid 849392:tid 849579] [client 198.23.198.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.198.23.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucky-strike-shop.com"] [uri "/phpinfo.php"] [unique_id "amuTFAMgr4yz2OQW0xrYqQAAAL0"]
[Thu Jul 30 13:08:21.296970 2026] [security2:error] [pid 849392:tid 849611] [client 172.213.232.128:27923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/elp.php"] [unique_id "amuTFQMgr4yz2OQW0xrYqwAAAN0"]
[Thu Jul 30 13:08:21.651085 2026] [security2:error] [pid 849392:tid 849411] [remote 57.141.0.17:20582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuTFQMgr4yz2OQW0xrYsAAA-BE"]
[Thu Jul 30 13:08:21.748794 2026] [security2:error] [pid 849392:tid 849567] [client 20.63.98.115:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/pomo/fgertreyersd.php"] [unique_id "amuTFQMgr4yz2OQW0xrYsgAAALE"]
[Thu Jul 30 13:08:21.774614 2026] [security2:error] [pid 849392:tid 849610] [client 172.213.208.20:22482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/index.php"] [unique_id "amuTFQMgr4yz2OQW0xrYswAAANw"]
[Thu Jul 30 13:08:22.334827 2026] [security2:error] [pid 849392:tid 849560] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuTFgMgr4yz2OQW0xrYwQAAAKo"]
[Thu Jul 30 13:08:22.378446 2026] [security2:error] [pid 849392:tid 849548] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuTFQMgr4yz2OQW0xrYsQAAAJk"]
[Thu Jul 30 13:08:22.492493 2026] [security2:error] [pid 849392:tid 849617] [client 20.203.148.31:28729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuTFgMgr4yz2OQW0xrYxwAAAOM"]
[Thu Jul 30 13:08:22.708276 2026] [security2:error] [pid 849392:tid 849585] [client 172.213.232.128:46391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuTFgMgr4yz2OQW0xrYyAAAAMM"]
[Thu Jul 30 13:08:22.951724 2026] [security2:error] [pid 849392:tid 849598] [client 198.23.198.15:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "lucky-strike-shop.com"] [uri "/.env.bak"] [unique_id "amuTFgMgr4yz2OQW0xrYzAAAANA"]
[Thu Jul 30 13:08:23.037299 2026] [security2:error] [pid 849392:tid 849603] [client 20.63.98.115:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/css/xmrlpc.php"] [unique_id "amuTFwMgr4yz2OQW0xrYzQAAANU"]
[Thu Jul 30 13:08:23.343929 2026] [security2:error] [pid 849392:tid 849647] [client 172.213.232.128:28255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuTFwMgr4yz2OQW0xrY0QAAAQE"]
[Thu Jul 30 13:08:23.515745 2026] [security2:error] [pid 849392:tid 849534] [client 198.23.198.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.198.23.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucky-strike-shop.com"] [uri "/info.php"] [unique_id "amuTFwMgr4yz2OQW0xrY0gAAAJA"]
[Thu Jul 30 13:08:23.736690 2026] [security2:error] [pid 849392:tid 849628] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTFwMgr4yz2OQW0xrY0AAAAO4"]
[Thu Jul 30 13:08:23.968790 2026] [security2:error] [pid 849392:tid 849591] [client 172.213.232.128:28652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuTFwMgr4yz2OQW0xrY2wAAAMk"]
[Thu Jul 30 13:08:24.082882 2026] [security2:error] [pid 849392:tid 849569] [client 172.213.208.20:15644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/a.php"] [unique_id "amuTGAMgr4yz2OQW0xrY3QAAALM"]
[Thu Jul 30 13:08:24.226955 2026] [security2:error] [pid 849392:tid 849573] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTFwMgr4yz2OQW0xrY0wAAtyg"]
[Thu Jul 30 13:08:24.239215 2026] [security2:error] [pid 849392:tid 849433] [remote 40.77.167.21:27053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/reponses-humanitaires/article.php"] [unique_id "amuTGAMgr4yz2OQW0xrY3wAA5Sc"]
[Thu Jul 30 13:08:24.348694 2026] [security2:error] [pid 849392:tid 849531] [client 20.63.98.115:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/classsmtps.php"] [unique_id "amuTGAMgr4yz2OQW0xrY4AAAAI0"]
[Thu Jul 30 13:08:24.367754 2026] [security2:error] [pid 849392:tid 849616] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuTFwMgr4yz2OQW0xrY1AAAAPo"]
[Thu Jul 30 13:08:24.530672 2026] [security2:error] [pid 849392:tid 849559] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTFwMgr4yz2OQW0xrY1wAAAKk"]
[Thu Jul 30 13:08:24.826222 2026] [security2:error] [pid 849392:tid 849529] [client 172.213.232.128:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuTGAMgr4yz2OQW0xrY4gAAAIs"]
[Thu Jul 30 13:08:25.283371 2026] [autoindex:error] [pid 849392:tid 849537] [client 172.213.208.20:29402] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:08:25.296999 2026] [security2:error] [pid 849392:tid 849528] [client 172.213.232.128:45100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuTGQMgr4yz2OQW0xrY5gAAAIo"]
[Thu Jul 30 13:08:25.479347 2026] [autoindex:error] [pid 849392:tid 849605] [client 172.213.208.20:29402] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:08:25.481834 2026] [security2:error] [pid 849392:tid 849527] [client 20.63.98.115:37253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/themes/zMousse/otuz1.php"] [unique_id "amuTGQMgr4yz2OQW0xrY7wAAAIk"]
[Thu Jul 30 13:08:25.577445 2026] [security2:error] [pid 849392:tid 849632] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuTGAMgr4yz2OQW0xrY4wAAAL4"]
[Thu Jul 30 13:08:25.619694 2026] [security2:error] [pid 849392:tid 849606] [client 172.213.208.20:29402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/Text/about.php"] [unique_id "amuTGQMgr4yz2OQW0xrY8AAAANg"]
[Thu Jul 30 13:08:26.036850 2026] [security2:error] [pid 849392:tid 849626] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTGQMgr4yz2OQW0xrY7QAAAOw"]
[Thu Jul 30 13:08:26.063402 2026] [security2:error] [pid 849392:tid 849597] [client 172.213.232.128:47755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuTGgMgr4yz2OQW0xrY-AAAAM8"]
[Thu Jul 30 13:08:26.232821 2026] [security2:error] [pid 849392:tid 849432] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTGgMgr4yz2OQW0xrY-gAAlSY"]
[Thu Jul 30 13:08:26.232997 2026] [security2:error] [pid 849392:tid 849539] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTGgMgr4yz2OQW0xrY-gAAlSY"]
[Thu Jul 30 13:08:26.755074 2026] [security2:error] [pid 849392:tid 849608] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuTGgMgr4yz2OQW0xrY-QAAAPA"]
[Thu Jul 30 13:08:27.211470 2026] [security2:error] [pid 849392:tid 849582] [client 172.213.232.128:47792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuTGwMgr4yz2OQW0xrY_gAAAMA"]
[Thu Jul 30 13:08:27.689335 2026] [security2:error] [pid 849392:tid 849614] [client 20.63.98.115:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/123.php"] [unique_id "amuTGwMgr4yz2OQW0xrY_wAAAOA"]
[Thu Jul 30 13:08:27.924442 2026] [security2:error] [pid 849392:tid 849639] [client 114.119.141.80:42825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/fountains"] [unique_id "amuTGwMgr4yz2OQW0xrZAQAAAPk"], referer: https://fireworkskenya.co.ke/our-products/consumer-fireworks/big-display-cakes/hangoverator-z2093-square-cake-36-shots
[Thu Jul 30 13:08:28.350478 2026] [security2:error] [pid 849392:tid 849641] [client 20.203.148.31:5756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/bek.php"] [unique_id "amuTHAMgr4yz2OQW0xrZBwAAAPs"]
[Thu Jul 30 13:08:28.424915 2026] [core:notice] [pid 849392:tid 849573] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:28.586287 2026] [security2:error] [pid 849392:tid 849591] [client 172.213.232.128:27922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuTHAMgr4yz2OQW0xrZDAAAAMk"]
[Thu Jul 30 13:08:28.733844 2026] [security2:error] [pid 849392:tid 849571] [client 20.63.98.115:54268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuTHAMgr4yz2OQW0xrZDwAAALU"]
[Thu Jul 30 13:08:28.781451 2026] [security2:error] [pid 849392:tid 849576] [client 172.236.9.101:28765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTHAMgr4yz2OQW0xrZBgAAALo"]
[Thu Jul 30 13:08:29.322744 2026] [core:notice] [pid 849392:tid 849635] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:30.051870 2026] [security2:error] [pid 849392:tid 849645] [client 179.64.21.229:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTHgMgr4yz2OQW0xrZFwAAAP8"]
[Thu Jul 30 13:08:30.052333 2026] [security2:error] [pid 849392:tid 849532] [client 20.63.98.115:55057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/filebrowser.php"] [unique_id "amuTHgMgr4yz2OQW0xrZFgAAAI4"]
[Thu Jul 30 13:08:30.059700 2026] [security2:error] [pid 849392:tid 849645] [client 179.64.21.229:41716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTHgMgr4yz2OQW0xrZFwAAAP8"]
[Thu Jul 30 13:08:30.097860 2026] [security2:error] [pid 849392:tid 849632] [client 40.77.167.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuTHQMgr4yz2OQW0xrZFQAAAPI"]
[Thu Jul 30 13:08:30.254779 2026] [security2:error] [pid 849392:tid 849541] [client 172.213.232.128:27930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuTHgMgr4yz2OQW0xrZGQAAAJc"]
[Thu Jul 30 13:08:30.567896 2026] [core:notice] [pid 849392:tid 849583] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:30.751876 2026] [security2:error] [pid 849392:tid 849545] [client 172.236.9.101:41159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTHgMgr4yz2OQW0xrZGgAAAJs"]
[Thu Jul 30 13:08:31.035823 2026] [core:notice] [pid 849392:tid 849644] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:31.038835 2026] [security2:error] [pid 849392:tid 849551] [client 20.63.98.115:55095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/makeasmtp.php"] [unique_id "amuTHwMgr4yz2OQW0xrZHQAAAKE"]
[Thu Jul 30 13:08:31.304326 2026] [core:notice] [pid 849392:tid 849611] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:31.751837 2026] [security2:error] [pid 849392:tid 849561] [client 20.63.98.115:37300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/bypass.php"] [unique_id "amuTHwMgr4yz2OQW0xrZIAAAAKs"]
[Thu Jul 30 13:08:32.205133 2026] [core:notice] [pid 849392:tid 849570] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:33.202337 2026] [security2:error] [pid 849392:tid 849560] [client 20.63.98.115:1512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/pi.php"] [unique_id "amuTIQMgr4yz2OQW0xrZIwAAAKo"]
[Thu Jul 30 13:08:33.856336 2026] [security2:error] [pid 849392:tid 849558] [client 172.213.208.20:21519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin.php"] [unique_id "amuTIQMgr4yz2OQW0xrZKAAAAKg"]
[Thu Jul 30 13:08:33.886188 2026] [security2:error] [pid 849392:tid 849592] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTIQMgr4yz2OQW0xrZJgAAAMo"]
[Thu Jul 30 13:08:34.069082 2026] [security2:error] [pid 849392:tid 849528] [client 20.203.148.31:5745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuTIgMgr4yz2OQW0xrZKQAAAIo"]
[Thu Jul 30 13:08:35.476861 2026] [security2:error] [pid 849392:tid 849467] [remote 57.141.0.3:61764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/96409857935/feed/rss2/"] [unique_id "amuTIwMgr4yz2OQW0xrZSAAA5Uk"]
[Thu Jul 30 13:08:35.733488 2026] [security2:error] [pid 849392:tid 849618] [client 20.203.148.31:31845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/class.api.php"] [unique_id "amuTIwMgr4yz2OQW0xrZSQAAAOQ"]
[Thu Jul 30 13:08:35.978808 2026] [security2:error] [pid 849392:tid 849590] [client 20.63.98.115:55044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-seo.php"] [unique_id "amuTIwMgr4yz2OQW0xrZTgAAAMg"]
[Thu Jul 30 13:08:36.274446 2026] [security2:error] [pid 849392:tid 849444] [remote 57.141.0.71:56238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuTJAMgr4yz2OQW0xrZTwAAuTI"]
[Thu Jul 30 13:08:36.494449 2026] [security2:error] [pid 849392:tid 849645] [client 20.203.148.31:34117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/cong.php"] [unique_id "amuTJAMgr4yz2OQW0xrZUQAAAP8"]
[Thu Jul 30 13:08:36.857118 2026] [security2:error] [pid 849392:tid 849629] [client 20.63.98.115:49295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/gebase.php69"] [unique_id "amuTJAMgr4yz2OQW0xrZUwAAAO8"]
[Thu Jul 30 13:08:37.027021 2026] [security2:error] [pid 849392:tid 849484] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTJQMgr4yz2OQW0xrZVAAAl1o"]
[Thu Jul 30 13:08:37.027174 2026] [security2:error] [pid 849392:tid 849541] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTJQMgr4yz2OQW0xrZVAAAl1o"]
[Thu Jul 30 13:08:37.254789 2026] [security2:error] [pid 849392:tid 849542] [client 47.128.121.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuTJQMgr4yz2OQW0xrZVwAAAJg"]
[Thu Jul 30 13:08:37.780766 2026] [security2:error] [pid 849392:tid 849540] [client 93.123.109.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuTJAMgr4yz2OQW0xrZUgAAAJY"]
[Thu Jul 30 13:08:38.147581 2026] [proxy:error] [pid 849392:tid 849545] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:38.147673 2026] [proxy_http:error] [pid 849392:tid 849545] [client 44.216.125.112:65473] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:38.148243 2026] [proxy:error] [pid 849392:tid 849545] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:38.148289 2026] [proxy_http:error] [pid 849392:tid 849545] [client 44.216.125.112:65473] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:38.181095 2026] [proxy:error] [pid 849392:tid 849551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:38.181160 2026] [proxy_http:error] [pid 849392:tid 849551] [client 44.216.125.112:65022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:38.181711 2026] [proxy:error] [pid 849392:tid 849551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:08:38.181757 2026] [proxy_http:error] [pid 849392:tid 849551] [client 44.216.125.112:65022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:08:38.338064 2026] [security2:error] [pid 849392:tid 849637] [client 20.203.148.31:38415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/content.php"] [unique_id "amuTJgMgr4yz2OQW0xrZZQAAAPc"]
[Thu Jul 30 13:08:38.367889 2026] [security2:error] [pid 849392:tid 849547] [client 93.123.109.102:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/.svn/wc.db"] [unique_id "amuTJgMgr4yz2OQW0xrZZwAAAJ0"]
[Thu Jul 30 13:08:38.600810 2026] [security2:error] [pid 849392:tid 849595] [client 20.63.98.115:34045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/config.php"] [unique_id "amuTJgMgr4yz2OQW0xrZaAAAAM0"]
[Thu Jul 30 13:08:38.679646 2026] [security2:error] [pid 849392:tid 849635] [client 172.213.208.20:19515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/size.php"] [unique_id "amuTJgMgr4yz2OQW0xrZaQAAAPU"]
[Thu Jul 30 13:08:38.724203 2026] [security2:error] [pid 849392:tid 849556] [client 93.123.109.102:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/.svn/entries"] [unique_id "amuTJgMgr4yz2OQW0xrZagAAAKY"]
[Thu Jul 30 13:08:38.827445 2026] [security2:error] [pid 849392:tid 849611] [client 172.236.9.101:50041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTJgMgr4yz2OQW0xrZZAAAAN0"]
[Thu Jul 30 13:08:39.373048 2026] [security2:error] [pid 849392:tid 849544] [client 172.213.208.20:10043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/wp-class.php"] [unique_id "amuTJwMgr4yz2OQW0xrZbwAAAJo"]
[Thu Jul 30 13:08:39.418393 2026] [security2:error] [pid 849392:tid 849525] [client 172.213.232.128:47764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuTJwMgr4yz2OQW0xrZcgAAAIc"]
[Thu Jul 30 13:08:39.460771 2026] [security2:error] [pid 849392:tid 849578] [client 93.123.109.102:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuTJwMgr4yz2OQW0xrZbgAAvCs"]
[Thu Jul 30 13:08:39.925582 2026] [core:notice] [pid 849392:tid 849587] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:39.965797 2026] [security2:error] [pid 849392:tid 849572] [client 93.123.109.102:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuTJwMgr4yz2OQW0xrZdgAAALY"]
[Thu Jul 30 13:08:40.185579 2026] [security2:error] [pid 849392:tid 849548] [client 45.51.187.186:53713] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "milfordauto.com"] [uri "/index.html"] [unique_id "amuTKAMgr4yz2OQW0xrZeAAAAJ4"]
[Thu Jul 30 13:08:40.291432 2026] [security2:error] [pid 849392:tid 849649] [client 20.63.98.115:1185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ws.php"] [unique_id "amuTKAMgr4yz2OQW0xrZeQAAAQM"]
[Thu Jul 30 13:08:40.429439 2026] [security2:error] [pid 849392:tid 849528] [client 172.213.232.128:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuTKAMgr4yz2OQW0xrZegAAAIo"]
[Thu Jul 30 13:08:40.838800 2026] [security2:error] [pid 849392:tid 849594] [client 179.64.21.229:39300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTKAMgr4yz2OQW0xrZewAAAMw"]
[Thu Jul 30 13:08:40.838945 2026] [security2:error] [pid 849392:tid 849594] [client 179.64.21.229:39300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTKAMgr4yz2OQW0xrZewAAAMw"]
[Thu Jul 30 13:08:41.142465 2026] [security2:error] [pid 849392:tid 849647] [client 172.213.232.128:47787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuTKQMgr4yz2OQW0xrZfAAAAQE"]
[Thu Jul 30 13:08:41.289012 2026] [security2:error] [pid 849392:tid 849534] [client 20.63.98.115:34035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/admin/function.php"] [unique_id "amuTKQMgr4yz2OQW0xrZfQAAAJA"]
[Thu Jul 30 13:08:42.495281 2026] [security2:error] [pid 849392:tid 849641] [client 172.213.232.128:47761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuTKgMgr4yz2OQW0xrZgAAAAPs"]
[Thu Jul 30 13:08:42.573590 2026] [security2:error] [pid 849392:tid 849553] [client 20.203.148.31:34154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuTKgMgr4yz2OQW0xrZgQAAAKM"]
[Thu Jul 30 13:08:43.044839 2026] [security2:error] [pid 849392:tid 849619] [client 172.213.232.128:28575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuTKwMgr4yz2OQW0xrZggAAAOU"]
[Thu Jul 30 13:08:43.089425 2026] [security2:error] [pid 849392:tid 849571] [client 20.203.148.31:5759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/elp.php"] [unique_id "amuTKwMgr4yz2OQW0xrZgwAAALU"]
[Thu Jul 30 13:08:43.717553 2026] [core:notice] [pid 849392:tid 849623] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:43.896633 2026] [security2:error] [pid 849392:tid 849602] [client 20.63.98.115:1382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "amuTKwMgr4yz2OQW0xrZhgAAANQ"]
[Thu Jul 30 13:08:43.901891 2026] [security2:error] [pid 849392:tid 849529] [client 172.213.232.128:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuTKwMgr4yz2OQW0xrZhwAAAIs"]
[Thu Jul 30 13:08:43.990585 2026] [core:notice] [pid 849392:tid 849485] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:44.192235 2026] [core:notice] [pid 849392:tid 849580] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:44.731658 2026] [security2:error] [pid 849392:tid 849631] [client 172.213.232.128:28588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuTLAMgr4yz2OQW0xrZjQAAAPE"]
[Thu Jul 30 13:08:44.734522 2026] [security2:error] [pid 849392:tid 849613] [client 172.213.208.20:9997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/403.php"] [unique_id "amuTLAMgr4yz2OQW0xrZjgAAAN8"]
[Thu Jul 30 13:08:44.791183 2026] [security2:error] [pid 849392:tid 849605] [client 52.167.144.172:63835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amuTLAMgr4yz2OQW0xrZiQAA11g"]
[Thu Jul 30 13:08:45.618311 2026] [security2:error] [pid 849392:tid 849540] [client 172.213.208.20:17062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuTLQMgr4yz2OQW0xrZkAAAAJY"]
[Thu Jul 30 13:08:45.898208 2026] [core:notice] [pid 849392:tid 849610] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:46.088603 2026] [security2:error] [pid 849392:tid 849612] [client 20.203.148.31:38426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuTLgMgr4yz2OQW0xrZlgAAAN4"]
[Thu Jul 30 13:08:46.383893 2026] [security2:error] [pid 849392:tid 849588] [client 114.119.147.137:32853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dhowcruisedinner.com"] [uri "/marina-yacht-brunch.html"] [unique_id "amuTLgMgr4yz2OQW0xrZlwAAAMY"]
[Thu Jul 30 13:08:46.920722 2026] [security2:error] [pid 849392:tid 849595] [client 20.203.148.31:5707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuTLgMgr4yz2OQW0xrZmQAAAM0"]
[Thu Jul 30 13:08:47.721345 2026] [security2:error] [pid 849392:tid 849487] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTLwMgr4yz2OQW0xrZoQAA610"]
[Thu Jul 30 13:08:47.721535 2026] [security2:error] [pid 849392:tid 849625] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTLwMgr4yz2OQW0xrZoQAA610"]
[Thu Jul 30 13:08:47.813818 2026] [security2:error] [pid 849392:tid 849541] [client 20.63.98.115:33984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuTLwMgr4yz2OQW0xrZogAAAJc"]
[Thu Jul 30 13:08:48.077728 2026] [security2:error] [pid 849392:tid 849558] [client 20.203.148.31:28717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuTMAMgr4yz2OQW0xrZowAAAKg"]
[Thu Jul 30 13:08:48.529711 2026] [security2:error] [pid 849392:tid 849548] [client 172.213.208.20:10218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/as.php"] [unique_id "amuTMAMgr4yz2OQW0xrZpAAAAJ4"]
[Thu Jul 30 13:08:48.540377 2026] [security2:error] [pid 849392:tid 849557] [client 172.213.232.128:28655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuTMAMgr4yz2OQW0xrZpQAAAKc"]
[Thu Jul 30 13:08:48.698969 2026] [security2:error] [pid 849392:tid 849614] [client 20.63.98.115:33713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuTMAMgr4yz2OQW0xrZpwAAAOA"]
[Thu Jul 30 13:08:49.456421 2026] [security2:error] [pid 849392:tid 849647] [client 172.213.208.20:31739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/includes/index.php"] [unique_id "amuTMQMgr4yz2OQW0xrZqwAAAQE"]
[Thu Jul 30 13:08:49.862254 2026] [security2:error] [pid 849392:tid 849640] [client 172.213.232.128:28670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuTMQMgr4yz2OQW0xrZrAAAAPo"]
[Thu Jul 30 13:08:49.864849 2026] [security2:error] [pid 849392:tid 849591] [client 20.203.148.31:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuTMQMgr4yz2OQW0xrZrQAAAMk"]
[Thu Jul 30 13:08:49.873927 2026] [core:notice] [pid 849392:tid 849555] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:50.183862 2026] [security2:error] [pid 849392:tid 849553] [client 172.213.208.20:15677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuTMgMgr4yz2OQW0xrZrwAAAKM"]
[Thu Jul 30 13:08:50.827143 2026] [security2:error] [pid 849392:tid 849627] [client 172.213.232.128:28595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuTMgMgr4yz2OQW0xrZsAAAAO0"]
[Thu Jul 30 13:08:51.086908 2026] [security2:error] [pid 849392:tid 849531] [client 20.203.148.31:28710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuTMwMgr4yz2OQW0xrZsQAAAI0"]
[Thu Jul 30 13:08:51.525696 2026] [security2:error] [pid 849392:tid 849623] [client 179.64.21.229:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTMwMgr4yz2OQW0xrZswAAAOk"]
[Thu Jul 30 13:08:51.525825 2026] [security2:error] [pid 849392:tid 849623] [client 179.64.21.229:12050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTMwMgr4yz2OQW0xrZswAAAOk"]
[Thu Jul 30 13:08:51.646404 2026] [security2:error] [pid 849392:tid 849577] [client 185.191.171.16:10948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/26/imagens-fantasticas-do-supertelescopio-james-webb-mostram-o-universo-como-nunca-antes-visto/"] [unique_id "amuTMwMgr4yz2OQW0xrZtAAAALs"]
[Thu Jul 30 13:08:51.646560 2026] [security2:error] [pid 849392:tid 849577] [client 185.191.171.16:10948] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/26/imagens-fantasticas-do-supertelescopio-james-webb-mostram-o-universo-como-nunca-antes-visto/"] [unique_id "amuTMwMgr4yz2OQW0xrZtAAAALs"]
[Thu Jul 30 13:08:51.668520 2026] [security2:error] [pid 849392:tid 849590] [client 20.203.148.31:34118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuTMwMgr4yz2OQW0xrZtQAAAMg"]
[Thu Jul 30 13:08:51.896563 2026] [security2:error] [pid 849392:tid 849618] [client 172.213.208.20:21341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/plugins.php"] [unique_id "amuTMwMgr4yz2OQW0xrZtgAAAOQ"]
[Thu Jul 30 13:08:52.016771 2026] [security2:error] [pid 849392:tid 849529] [client 172.236.9.101:18692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTMwMgr4yz2OQW0xrZsgAAAIs"]
[Thu Jul 30 13:08:52.242794 2026] [security2:error] [pid 849392:tid 849527] [client 20.203.148.31:28719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuTNAMgr4yz2OQW0xrZuAAAAIk"]
[Thu Jul 30 13:08:52.560327 2026] [security2:error] [pid 849392:tid 849537] [client 20.63.98.115:36519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/uploads/2024/index.php"] [unique_id "amuTNAMgr4yz2OQW0xrZuQAAAJM"]
[Thu Jul 30 13:08:52.635836 2026] [security2:error] [pid 849392:tid 849605] [client 172.213.208.20:30877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/js/index.php"] [unique_id "amuTNAMgr4yz2OQW0xrZugAAANc"]
[Thu Jul 30 13:08:52.769244 2026] [security2:error] [pid 849392:tid 849550] [client 172.213.232.128:28634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuTNAMgr4yz2OQW0xrZuwAAAKA"]
[Thu Jul 30 13:08:53.591001 2026] [security2:error] [pid 849392:tid 849540] [client 20.203.148.31:30194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuTNQMgr4yz2OQW0xrZvwAAAJY"]
[Thu Jul 30 13:08:53.845507 2026] [security2:error] [pid 849392:tid 849536] [client 172.213.232.128:28557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuTNQMgr4yz2OQW0xrZwAAAAJI"]
[Thu Jul 30 13:08:53.845616 2026] [security2:error] [pid 849392:tid 849579] [client 172.213.208.20:20028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/go.php"] [unique_id "amuTNQMgr4yz2OQW0xrZwQAAAL0"]
[Thu Jul 30 13:08:54.024025 2026] [security2:error] [pid 849392:tid 849551] [client 20.63.98.115:1951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known/cong.php"] [unique_id "amuTNgMgr4yz2OQW0xrZwwAAAKE"]
[Thu Jul 30 13:08:54.544816 2026] [security2:error] [pid 849392:tid 849546] [client 172.213.208.20:21317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/test1.php"] [unique_id "amuTNgMgr4yz2OQW0xrZxAAAAJw"]
[Thu Jul 30 13:08:54.859036 2026] [security2:error] [pid 849392:tid 849635] [client 213.152.161.85:51638] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuTNgMgr4yz2OQW0xrZxQAAAPU"]
[Thu Jul 30 13:08:54.859221 2026] [security2:error] [pid 849392:tid 849635] [client 213.152.161.85:51638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuTNgMgr4yz2OQW0xrZxQAAAPU"]
[Thu Jul 30 13:08:55.180639 2026] [security2:error] [pid 849392:tid 849584] [client 172.213.232.128:27953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuTNwMgr4yz2OQW0xrZzgAAAMI"]
[Thu Jul 30 13:08:55.879941 2026] [security2:error] [pid 849392:tid 849636] [client 172.236.9.101:44722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTNwMgr4yz2OQW0xrZ0AAAAPY"]
[Thu Jul 30 13:08:55.922508 2026] [security2:error] [pid 849392:tid 849556] [client 20.63.98.115:1358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuTNwMgr4yz2OQW0xrZ0wAAAKY"]
[Thu Jul 30 13:08:56.005500 2026] [autoindex:error] [pid 849392:tid 849633] [client 172.213.208.20:21370] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:08:56.135523 2026] [security2:error] [pid 849392:tid 849585] [client 172.213.208.20:21370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/images/index.php"] [unique_id "amuTOAMgr4yz2OQW0xrZ1QAAAMM"]
[Thu Jul 30 13:08:56.372689 2026] [security2:error] [pid 849392:tid 849582] [client 185.191.171.10:40866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2023/10/memperbaiki-lampu-baterai-laptop-asus"] [unique_id "amuTOAMgr4yz2OQW0xrZ1gAAAMA"]
[Thu Jul 30 13:08:56.372820 2026] [security2:error] [pid 849392:tid 849582] [client 185.191.171.10:40866] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2023/10/memperbaiki-lampu-baterai-laptop-asus"] [unique_id "amuTOAMgr4yz2OQW0xrZ1gAAAMA"]
[Thu Jul 30 13:08:56.864754 2026] [autoindex:error] [pid 849392:tid 849541] [client 172.213.208.20:27120] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:08:56.884713 2026] [core:notice] [pid 849392:tid 849603] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:08:57.004861 2026] [security2:error] [pid 849392:tid 849548] [client 172.213.208.20:27120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/asd.php"] [unique_id "amuTOQMgr4yz2OQW0xrZ2gAAAJ4"]
[Thu Jul 30 13:08:57.011147 2026] [security2:error] [pid 849392:tid 849490] [remote 77.75.79.17:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adtop.net"] [uri "/robots.txt"] [unique_id "amuTOQMgr4yz2OQW0xrZ2wAAjGA"]
[Thu Jul 30 13:08:57.011342 2026] [security2:error] [pid 849392:tid 849530] [client 77.75.79.17:0] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adtop.net"] [uri "/robots.txt"] [unique_id "amuTOQMgr4yz2OQW0xrZ2wAAjGA"]
[Thu Jul 30 13:08:57.200002 2026] [security2:error] [pid 849392:tid 849552] [client 20.203.148.31:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuTOQMgr4yz2OQW0xrZ3AAAAKI"]
[Thu Jul 30 13:08:57.250522 2026] [security2:error] [pid 849392:tid 849614] [client 185.200.116.219:33404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuTOQMgr4yz2OQW0xrZ3QAAAOA"]
[Thu Jul 30 13:08:57.250625 2026] [security2:error] [pid 849392:tid 849614] [client 185.200.116.219:33404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuTOQMgr4yz2OQW0xrZ3QAAAOA"]
[Thu Jul 30 13:08:57.472269 2026] [security2:error] [pid 849392:tid 849504] [remote 77.75.79.17:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adtop.net"] [uri "/"] [unique_id "amuTOQMgr4yz2OQW0xrZ3gAArG4"]
[Thu Jul 30 13:08:57.472465 2026] [security2:error] [pid 849392:tid 849562] [client 77.75.79.17:0] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adtop.net"] [uri "/"] [unique_id "amuTOQMgr4yz2OQW0xrZ3gAArG4"]
[Thu Jul 30 13:08:57.847151 2026] [security2:error] [pid 849392:tid 849565] [client 172.213.232.128:41890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuTOQMgr4yz2OQW0xrZ4AAAAK8"]
[Thu Jul 30 13:08:57.848494 2026] [security2:error] [pid 849392:tid 849615] [client 20.203.148.31:5709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuTOQMgr4yz2OQW0xrZ4QAAAOE"]
[Thu Jul 30 13:08:57.877459 2026] [security2:error] [pid 849392:tid 849598] [client 20.63.98.115:36543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/edit.php"] [unique_id "amuTOQMgr4yz2OQW0xrZ4gAAANA"]
[Thu Jul 30 13:08:58.556591 2026] [security2:error] [pid 849392:tid 849506] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTOgMgr4yz2OQW0xrZ6QAAv3A"]
[Thu Jul 30 13:08:58.556738 2026] [security2:error] [pid 849392:tid 849581] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTOgMgr4yz2OQW0xrZ6QAAv3A"]
[Thu Jul 30 13:08:58.598670 2026] [security2:error] [pid 849392:tid 849573] [client 20.203.148.31:28689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuTOgMgr4yz2OQW0xrZ6wAAALc"]
[Thu Jul 30 13:08:58.705859 2026] [security2:error] [pid 849392:tid 849640] [client 20.63.98.115:35208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/about/function.php"] [unique_id "amuTOgMgr4yz2OQW0xrZ7AAAAPo"]
[Thu Jul 30 13:08:59.445076 2026] [security2:error] [pid 849392:tid 849559] [client 172.213.232.128:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuTOwMgr4yz2OQW0xrZ7wAAAKk"]
[Thu Jul 30 13:08:59.788326 2026] [core:notice] [pid 849392:tid 849593] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:00.447069 2026] [security2:error] [pid 849392:tid 849602] [client 172.213.232.128:42977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuTPAMgr4yz2OQW0xrZ9gAAANQ"]
[Thu Jul 30 13:09:01.866049 2026] [security2:error] [pid 849392:tid 849627] [client 20.203.148.31:28672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuTPQMgr4yz2OQW0xrZ-gAAAO0"]
[Thu Jul 30 13:09:02.140379 2026] [security2:error] [pid 849392:tid 849567] [client 20.63.98.115:33669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/simple/function.php"] [unique_id "amuTPgMgr4yz2OQW0xrZ-wAAALE"]
[Thu Jul 30 13:09:02.197856 2026] [core:notice] [pid 849392:tid 849589] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:02.197856 2026] [core:notice] [pid 849392:tid 849550] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:02.226127 2026] [security2:error] [pid 849392:tid 849621] [client 179.64.21.229:7662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTPgMgr4yz2OQW0xrZ_gAAAOc"]
[Thu Jul 30 13:09:02.226333 2026] [security2:error] [pid 849392:tid 849621] [client 179.64.21.229:7662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTPgMgr4yz2OQW0xrZ_gAAAOc"]
[Thu Jul 30 13:09:02.599777 2026] [security2:error] [pid 849392:tid 849648] [client 20.203.148.31:38446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuTPgMgr4yz2OQW0xraAwAAAQI"]
[Thu Jul 30 13:09:02.771395 2026] [security2:error] [pid 849392:tid 849650] [client 172.213.208.20:21319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/customize/index.php"] [unique_id "amuTPgMgr4yz2OQW0xraBwAAAQQ"]
[Thu Jul 30 13:09:02.866850 2026] [security2:error] [pid 849392:tid 849535] [client 172.236.9.101:46127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTPgMgr4yz2OQW0xrZ_wAAAJE"]
[Thu Jul 30 13:09:03.179353 2026] [security2:error] [pid 849392:tid 849631] [client 172.213.232.128:41886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuTPwMgr4yz2OQW0xraCgAAAPE"]
[Thu Jul 30 13:09:03.340360 2026] [security2:error] [pid 849392:tid 849597] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTPgMgr4yz2OQW0xraBgAAAM8"]
[Thu Jul 30 13:09:03.866192 2026] [security2:error] [pid 849392:tid 849636] [client 172.213.208.20:29748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuTPwMgr4yz2OQW0xraDAAAAPY"]
[Thu Jul 30 13:09:03.919819 2026] [security2:error] [pid 849392:tid 849611] [client 172.213.232.128:41427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuTPwMgr4yz2OQW0xraDQAAAN0"]
[Thu Jul 30 13:09:04.856467 2026] [security2:error] [pid 849392:tid 849548] [client 172.213.232.128:47041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuTQAMgr4yz2OQW0xraFAAAAJ4"]
[Thu Jul 30 13:09:04.986567 2026] [security2:error] [pid 849392:tid 849541] [client 172.213.208.20:27072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/atomlib.php"] [unique_id "amuTQAMgr4yz2OQW0xraFQAAAJc"]
[Thu Jul 30 13:09:05.624529 2026] [security2:error] [pid 849392:tid 849565] [client 172.213.232.128:40983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuTQQMgr4yz2OQW0xraFwAAAK8"]
[Thu Jul 30 13:09:06.425777 2026] [autoindex:error] [pid 849392:tid 849615] [client 172.213.208.20:32443] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:06.496526 2026] [security2:error] [pid 849392:tid 849566] [client 20.63.98.115:33703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/mah/function.php"] [unique_id "amuTQgMgr4yz2OQW0xraHQAAALA"]
[Thu Jul 30 13:09:06.654217 2026] [autoindex:error] [pid 849392:tid 849576] [client 172.213.208.20:32443] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:06.737848 2026] [security2:error] [pid 849392:tid 849616] [client 172.213.232.128:41425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuTQgMgr4yz2OQW0xraIAAAAOI"]
[Thu Jul 30 13:09:06.795845 2026] [security2:error] [pid 849392:tid 849581] [client 172.213.208.20:32443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuTQgMgr4yz2OQW0xraIQAAAL8"]
[Thu Jul 30 13:09:06.869373 2026] [security2:error] [pid 849392:tid 849649] [client 172.236.9.101:5951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTQgMgr4yz2OQW0xraGgAAAQM"]
[Thu Jul 30 13:09:07.383101 2026] [security2:error] [pid 849392:tid 849596] [client 20.203.148.31:38450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuTQwMgr4yz2OQW0xraIwAAAM4"]
[Thu Jul 30 13:09:07.463337 2026] [security2:error] [pid 849392:tid 849604] [client 172.213.232.128:41423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuTQwMgr4yz2OQW0xraJAAAANY"]
[Thu Jul 30 13:09:07.496430 2026] [security2:error] [pid 849392:tid 849573] [client 2a03:2880:f800:a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTQgMgr4yz2OQW0xraIgAAt28"]
[Thu Jul 30 13:09:07.747790 2026] [autoindex:error] [pid 849392:tid 849559] [client 172.213.208.20:19348] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:07.903396 2026] [autoindex:error] [pid 849392:tid 849577] [client 172.213.208.20:19348] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/blocks/block/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:08.106506 2026] [autoindex:error] [pid 849392:tid 849607] [client 172.213.208.20:19348] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:08.168215 2026] [security2:error] [pid 849392:tid 849623] [client 172.213.232.128:40981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuTRAMgr4yz2OQW0xraKAAAAOk"]
[Thu Jul 30 13:09:08.288114 2026] [security2:error] [pid 849392:tid 849575] [client 172.213.208.20:19348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/inputs.php"] [unique_id "amuTRAMgr4yz2OQW0xraLAAAALk"]
[Thu Jul 30 13:09:08.289988 2026] [proxy:error] [pid 849392:tid 849632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:08.290054 2026] [proxy_http:error] [pid 849392:tid 849632] [client 3.225.222.228:52963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:08.290938 2026] [proxy:error] [pid 849392:tid 849632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:08.291002 2026] [proxy_http:error] [pid 849392:tid 849632] [client 3.225.222.228:52963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:08.296894 2026] [proxy:error] [pid 849392:tid 849622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:08.296951 2026] [proxy_http:error] [pid 849392:tid 849622] [client 44.213.206.96:30719] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:08.297522 2026] [proxy:error] [pid 849392:tid 849622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:08.297566 2026] [proxy_http:error] [pid 849392:tid 849622] [client 44.213.206.96:30719] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:08.317526 2026] [security2:error] [pid 849392:tid 849571] [client 20.63.98.115:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/go.php"] [unique_id "amuTRAMgr4yz2OQW0xraMgAAALU"]
[Thu Jul 30 13:09:09.122914 2026] [security2:error] [pid 849392:tid 849498] [remote 51.75.236.128:57882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/activite-generatrice-de-revenu/"] [unique_id "amuTRQMgr4yz2OQW0xraNQAA52g"]
[Thu Jul 30 13:09:09.123085 2026] [security2:error] [pid 849392:tid 849621] [client 51.75.236.128:57882] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/activite-generatrice-de-revenu/"] [unique_id "amuTRQMgr4yz2OQW0xraNQAA52g"]
[Thu Jul 30 13:09:09.399202 2026] [security2:error] [pid 849392:tid 849486] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTRQMgr4yz2OQW0xraOQAA9Fw"]
[Thu Jul 30 13:09:09.399402 2026] [security2:error] [pid 849392:tid 849634] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTRQMgr4yz2OQW0xraOQAA9Fw"]
[Thu Jul 30 13:09:09.411953 2026] [security2:error] [pid 849392:tid 849637] [client 20.63.98.115:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/buy.php"] [unique_id "amuTRQMgr4yz2OQW0xraOgAAAPc"]
[Thu Jul 30 13:09:09.644849 2026] [security2:error] [pid 849392:tid 849540] [client 172.213.232.128:42958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuTRQMgr4yz2OQW0xraNwAAAJY"]
[Thu Jul 30 13:09:10.245155 2026] [security2:error] [pid 849392:tid 849590] [client 20.203.148.31:28733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuTRgMgr4yz2OQW0xraRQAAAMg"]
[Thu Jul 30 13:09:10.293588 2026] [core:notice] [pid 849392:tid 849546] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:10.416090 2026] [security2:error] [pid 849392:tid 849620] [client 172.213.208.20:32397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/index.php"] [unique_id "amuTRgMgr4yz2OQW0xraUQAAAOY"]
[Thu Jul 30 13:09:11.189644 2026] [core:notice] [pid 849392:tid 849649] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:11.380816 2026] [security2:error] [pid 849392:tid 849642] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTRgMgr4yz2OQW0xraWAAAAPw"]
[Thu Jul 30 13:09:11.529286 2026] [security2:error] [pid 849392:tid 849581] [client 172.213.208.20:29662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/network/index.php"] [unique_id "amuTRwMgr4yz2OQW0xrabwAAAL8"]
[Thu Jul 30 13:09:11.657148 2026] [security2:error] [pid 849392:tid 849571] [client 20.63.98.115:35253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/themes/astra/inc/ki1k.php"] [unique_id "amuTRwMgr4yz2OQW0xracwAAALU"]
[Thu Jul 30 13:09:12.244495 2026] [security2:error] [pid 849392:tid 849540] [client 20.203.148.31:30157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuTSAMgr4yz2OQW0xraggAAAJY"]
[Thu Jul 30 13:09:12.283507 2026] [security2:error] [pid 849392:tid 849635] [client 184.75.223.203:51942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuTSAMgr4yz2OQW0xrafgAAAPU"]
[Thu Jul 30 13:09:12.283638 2026] [security2:error] [pid 849392:tid 849635] [client 184.75.223.203:51942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuTSAMgr4yz2OQW0xrafgAAAPU"]
[Thu Jul 30 13:09:12.524015 2026] [security2:error] [pid 849392:tid 849608] [client 179.64.21.229:3188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTSAMgr4yz2OQW0xrahQAAANo"]
[Thu Jul 30 13:09:12.527612 2026] [security2:error] [pid 849392:tid 849608] [client 179.64.21.229:3188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTSAMgr4yz2OQW0xrahQAAANo"]
[Thu Jul 30 13:09:12.582758 2026] [security2:error] [pid 849392:tid 849589] [client 172.213.208.20:16137] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "globalmarks.pk"] [uri "/wp-content/1.php"] [unique_id "amuTSAMgr4yz2OQW0xrahgAAAMc"]
[Thu Jul 30 13:09:12.582885 2026] [security2:error] [pid 849392:tid 849589] [client 172.213.208.20:16137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/1.php"] [unique_id "amuTSAMgr4yz2OQW0xrahgAAAMc"]
[Thu Jul 30 13:09:12.753454 2026] [security2:error] [pid 849392:tid 849544] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTSAMgr4yz2OQW0xragAAAmmc"]
[Thu Jul 30 13:09:12.869087 2026] [security2:error] [pid 849392:tid 849526] [client 20.203.148.31:30169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuTSAMgr4yz2OQW0xraiQAAAIg"]
[Thu Jul 30 13:09:12.964318 2026] [security2:error] [pid 849392:tid 849568] [client 20.63.98.115:38425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wq.php7"] [unique_id "amuTSAMgr4yz2OQW0xraigAAALI"]
[Thu Jul 30 13:09:12.996304 2026] [security2:error] [pid 849392:tid 849616] [client 52.167.144.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuTRgMgr4yz2OQW0xraXQAAAOI"]
[Thu Jul 30 13:09:13.252465 2026] [security2:error] [pid 849392:tid 849538] [client 172.213.208.20:14386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/plugin.php"] [unique_id "amuTSQMgr4yz2OQW0xrajQAAAJQ"]
[Thu Jul 30 13:09:13.402842 2026] [security2:error] [pid 849392:tid 849542] [client 172.236.9.101:7585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/login.php"] [unique_id "amuTSQMgr4yz2OQW0xrajgAAAJg"]
[Thu Jul 30 13:09:13.664009 2026] [security2:error] [pid 849392:tid 849639] [client 20.63.98.115:38442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/forum.php"] [unique_id "amuTSQMgr4yz2OQW0xrakAAAAPk"]
[Thu Jul 30 13:09:14.293537 2026] [security2:error] [pid 849392:tid 849619] [client 172.213.208.20:14376] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "globalmarks.pk"] [uri "/1.php"] [unique_id "amuTSgMgr4yz2OQW0xralgAAAOU"]
[Thu Jul 30 13:09:14.293637 2026] [security2:error] [pid 849392:tid 849619] [client 172.213.208.20:14376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/1.php"] [unique_id "amuTSgMgr4yz2OQW0xralgAAAOU"]
[Thu Jul 30 13:09:14.640716 2026] [security2:error] [pid 849392:tid 849598] [client 20.203.148.31:28704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuTSgMgr4yz2OQW0xramwAAANA"]
[Thu Jul 30 13:09:14.653256 2026] [core:notice] [pid 849392:tid 849587] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:14.760640 2026] [security2:error] [pid 849392:tid 849599] [client 52.167.144.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuTSgMgr4yz2OQW0xramQAAANE"]
[Thu Jul 30 13:09:15.157768 2026] [security2:error] [pid 849392:tid 849623] [client 20.63.98.115:62906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/5index.php"] [unique_id "amuTSwMgr4yz2OQW0xranwAAAOk"]
[Thu Jul 30 13:09:15.377238 2026] [security2:error] [pid 849392:tid 849583] [client 52.238.199.152:13191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuTSwMgr4yz2OQW0xrapQAAAME"]
[Thu Jul 30 13:09:15.531648 2026] [security2:error] [pid 849392:tid 849580] [client 52.167.144.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuTSwMgr4yz2OQW0xraowAAAL4"]
[Thu Jul 30 13:09:15.702074 2026] [security2:error] [pid 849392:tid 849559] [client 172.213.208.20:22362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/gg.php"] [unique_id "amuTSwMgr4yz2OQW0xrapgAAAKk"]
[Thu Jul 30 13:09:16.745724 2026] [security2:error] [pid 849392:tid 849618] [client 172.236.9.101:20140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTTAMgr4yz2OQW0xrazAAAAOQ"]
[Thu Jul 30 13:09:17.093593 2026] [security2:error] [pid 849392:tid 849523] [client 88.151.32.7:46976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adbacklink.online"] [uri "/"] [unique_id "amuTTQMgr4yz2OQW0xra6AAAAIU"]
[Thu Jul 30 13:09:17.093703 2026] [security2:error] [pid 849392:tid 849523] [client 88.151.32.7:46976] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adbacklink.online"] [uri "/"] [unique_id "amuTTQMgr4yz2OQW0xra6AAAAIU"]
[Thu Jul 30 13:09:17.625990 2026] [security2:error] [pid 849392:tid 849565] [client 20.203.148.31:30149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuTTQMgr4yz2OQW0xra7gAAAK8"]
[Thu Jul 30 13:09:18.362018 2026] [security2:error] [pid 849392:tid 849555] [client 20.63.98.115:37479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/cookie.php"] [unique_id "amuTTgMgr4yz2OQW0xra-QAAAKU"]
[Thu Jul 30 13:09:18.777179 2026] [security2:error] [pid 849392:tid 849598] [client 20.203.148.31:30183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuTTgMgr4yz2OQW0xra-wAAANA"]
[Thu Jul 30 13:09:18.834179 2026] [autoindex:error] [pid 849392:tid 849626] [client 172.213.208.20:30883] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/images/crystal/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:18.968495 2026] [security2:error] [pid 849392:tid 849575] [client 172.213.208.20:30883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp.php"] [unique_id "amuTTgMgr4yz2OQW0xrbAQAAALk"]
[Thu Jul 30 13:09:19.780728 2026] [core:notice] [pid 849392:tid 849529] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:19.870020 2026] [security2:error] [pid 849392:tid 849623] [client 20.203.148.31:30154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuTTwMgr4yz2OQW0xrbCQAAAOk"]
[Thu Jul 30 13:09:19.894792 2026] [security2:error] [pid 849392:tid 849554] [client 172.236.9.101:6213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTTwMgr4yz2OQW0xrbAgAAAKQ"]
[Thu Jul 30 13:09:19.969990 2026] [security2:error] [pid 849392:tid 849629] [client 172.236.9.101:57858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTTwMgr4yz2OQW0xrbAwAAAO8"]
[Thu Jul 30 13:09:20.056250 2026] [security2:error] [pid 849392:tid 849550] [client 20.63.98.115:38420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/edit-form.php"] [unique_id "amuTUAMgr4yz2OQW0xrbCgAAAKA"]
[Thu Jul 30 13:09:20.119774 2026] [security2:error] [pid 849392:tid 849453] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTUAMgr4yz2OQW0xrbCwAA1zs"]
[Thu Jul 30 13:09:20.119992 2026] [security2:error] [pid 849392:tid 849605] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTUAMgr4yz2OQW0xrbCwAA1zs"]
[Thu Jul 30 13:09:20.346628 2026] [security2:error] [pid 849392:tid 849547] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTTwMgr4yz2OQW0xrbBwAAAJ0"]
[Thu Jul 30 13:09:20.586712 2026] [security2:error] [pid 849392:tid 849571] [client 172.213.208.20:20126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuTUAMgr4yz2OQW0xrbEAAAALU"]
[Thu Jul 30 13:09:21.274644 2026] [security2:error] [pid 849392:tid 849608] [client 172.213.208.20:15362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/file.php"] [unique_id "amuTUQMgr4yz2OQW0xrbFwAAANo"]
[Thu Jul 30 13:09:21.416241 2026] [security2:error] [pid 849392:tid 849545] [client 20.63.98.115:44086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/aleXus.php"] [unique_id "amuTUQMgr4yz2OQW0xrbGQAAAJs"]
[Thu Jul 30 13:09:21.622499 2026] [security2:error] [pid 849392:tid 849636] [client 20.203.148.31:28726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuTUQMgr4yz2OQW0xrbHwAAAPY"]
[Thu Jul 30 13:09:21.965359 2026] [security2:error] [pid 849392:tid 849523] [client 52.167.144.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuTUQMgr4yz2OQW0xrbHgAAAIU"]
[Thu Jul 30 13:09:21.986742 2026] [security2:error] [pid 849392:tid 849576] [client 139.28.219.70:59992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuTUQMgr4yz2OQW0xrbKAAAALo"]
[Thu Jul 30 13:09:22.107623 2026] [security2:error] [pid 849392:tid 849594] [client 172.213.208.20:9544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/user/index.php"] [unique_id "amuTUgMgr4yz2OQW0xrbKQAAAMw"]
[Thu Jul 30 13:09:22.308598 2026] [security2:error] [pid 849392:tid 849642] [client 20.203.148.31:28721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuTUgMgr4yz2OQW0xrbKgAAAPw"]
[Thu Jul 30 13:09:22.329381 2026] [security2:error] [pid 849392:tid 849628] [client 139.28.219.70:59996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "388iendd.site"] [uri "/xmlrpc.php"] [unique_id "amuTUgMgr4yz2OQW0xrbKwAAAO4"]
[Thu Jul 30 13:09:22.427378 2026] [security2:error] [pid 849392:tid 849631] [client 20.63.98.115:38503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/user.php"] [unique_id "amuTUgMgr4yz2OQW0xrbLAAAAPE"]
[Thu Jul 30 13:09:22.607448 2026] [security2:error] [pid 849392:tid 849569] [client 139.28.219.70:60012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuTUgMgr4yz2OQW0xrbLgAAALM"]
[Thu Jul 30 13:09:22.628131 2026] [security2:error] [pid 849392:tid 849641] [client 185.200.116.219:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuTUgMgr4yz2OQW0xrbLwAAAPs"]
[Thu Jul 30 13:09:22.628222 2026] [security2:error] [pid 849392:tid 849641] [client 185.200.116.219:56258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuTUgMgr4yz2OQW0xrbLwAAAPs"]
[Thu Jul 30 13:09:22.868154 2026] [security2:error] [pid 849392:tid 849624] [client 139.28.219.70:60020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuTUgMgr4yz2OQW0xrbNwAAAOo"]
[Thu Jul 30 13:09:23.026324 2026] [security2:error] [pid 849392:tid 849524] [client 179.64.21.229:22886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTUwMgr4yz2OQW0xrbOAAAAIY"]
[Thu Jul 30 13:09:23.037817 2026] [security2:error] [pid 849392:tid 849524] [client 179.64.21.229:22886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTUwMgr4yz2OQW0xrbOAAAAIY"]
[Thu Jul 30 13:09:23.053887 2026] [security2:error] [pid 849392:tid 849568] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTUgMgr4yz2OQW0xrbLQAAsjM"]
[Thu Jul 30 13:09:23.140885 2026] [security2:error] [pid 849392:tid 849626] [client 139.28.219.70:60022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuTUwMgr4yz2OQW0xrbOgAAAOw"]
[Thu Jul 30 13:09:23.483261 2026] [security2:error] [pid 849392:tid 849599] [client 139.28.219.70:60024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuTUwMgr4yz2OQW0xrbPwAAANE"]
[Thu Jul 30 13:09:23.741260 2026] [security2:error] [pid 849392:tid 849567] [client 139.28.219.70:60034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuTUwMgr4yz2OQW0xrbQQAAALE"]
[Thu Jul 30 13:09:24.014397 2026] [security2:error] [pid 849392:tid 849623] [client 139.28.219.70:60040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuTVAMgr4yz2OQW0xrbQwAAAOk"]
[Thu Jul 30 13:09:24.077992 2026] [security2:error] [pid 849392:tid 849530] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTUwMgr4yz2OQW0xrbQAAAAIw"]
[Thu Jul 30 13:09:24.273856 2026] [security2:error] [pid 849392:tid 849591] [client 139.28.219.70:60050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuTVAMgr4yz2OQW0xrbRAAAAMk"]
[Thu Jul 30 13:09:24.401679 2026] [security2:error] [pid 849392:tid 849439] [remote 57.128.47.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.47.128.57.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "laduchessecollections.com"] [uri "/wp-login.php"] [unique_id "amuTVAMgr4yz2OQW0xrbRgAA1y0"]
[Thu Jul 30 13:09:24.615266 2026] [security2:error] [pid 849392:tid 849579] [client 139.28.219.70:60052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuTVAMgr4yz2OQW0xrbRwAAAL0"]
[Thu Jul 30 13:09:24.746960 2026] [security2:error] [pid 849392:tid 849638] [client 20.203.148.31:5723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuTVAMgr4yz2OQW0xrbSAAAAPg"]
[Thu Jul 30 13:09:24.814811 2026] [security2:error] [pid 849392:tid 849577] [client 20.63.98.115:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ab1ux1ft.php"] [unique_id "amuTVAMgr4yz2OQW0xrbSQAAALs"]
[Thu Jul 30 13:09:24.854266 2026] [security2:error] [pid 849392:tid 849580] [client 172.236.9.101:51701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTVAMgr4yz2OQW0xrbRQAAAL4"]
[Thu Jul 30 13:09:24.920867 2026] [security2:error] [pid 849392:tid 849572] [client 139.28.219.70:60056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuTVAMgr4yz2OQW0xrbSgAAALY"]
[Thu Jul 30 13:09:25.138058 2026] [proxy:error] [pid 849392:tid 849556] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:25.138155 2026] [proxy_http:error] [pid 849392:tid 849556] [client 32.194.121.99:22492] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:25.138474 2026] [proxy:error] [pid 849392:tid 849560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:25.138528 2026] [proxy_http:error] [pid 849392:tid 849560] [client 34.233.129.35:26742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:25.138714 2026] [proxy:error] [pid 849392:tid 849556] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:25.138756 2026] [proxy_http:error] [pid 849392:tid 849556] [client 32.194.121.99:22492] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:25.139078 2026] [proxy:error] [pid 849392:tid 849560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:25.139124 2026] [proxy_http:error] [pid 849392:tid 849560] [client 34.233.129.35:26742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:25.186461 2026] [security2:error] [pid 849392:tid 849540] [client 139.28.219.70:60064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuTVQMgr4yz2OQW0xrbVQAAAJY"]
[Thu Jul 30 13:09:25.200749 2026] [core:notice] [pid 849392:tid 849535] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:25.401404 2026] [core:notice] [pid 849392:tid 849533] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:25.519057 2026] [security2:error] [pid 849392:tid 849528] [client 139.28.219.70:60070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuTVQMgr4yz2OQW0xrbWgAAAIo"]
[Thu Jul 30 13:09:25.859290 2026] [security2:error] [pid 849392:tid 849525] [client 139.28.219.70:60074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "388iendd.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuTVQMgr4yz2OQW0xrbWwAAAIc"]
[Thu Jul 30 13:09:27.291528 2026] [security2:error] [pid 849392:tid 849628] [client 172.236.9.101:55254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/config.properties.bak"] [unique_id "amuTVwMgr4yz2OQW0xrbYQAAAO4"]
[Thu Jul 30 13:09:27.467030 2026] [security2:error] [pid 849392:tid 849601] [client 20.63.98.115:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/home/function.php"] [unique_id "amuTVwMgr4yz2OQW0xrbZAAAANM"]
[Thu Jul 30 13:09:27.804756 2026] [security2:error] [pid 849392:tid 849547] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTVwMgr4yz2OQW0xrbXwAAnVE"]
[Thu Jul 30 13:09:27.903232 2026] [security2:error] [pid 849392:tid 849642] [client 172.236.9.101:54943] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTVwMgr4yz2OQW0xrbYwAAAPw"]
[Thu Jul 30 13:09:28.229282 2026] [security2:error] [pid 849392:tid 849569] [client 37.59.21.100:48170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuTVwMgr4yz2OQW0xrbZQAAALM"]
[Thu Jul 30 13:09:28.703578 2026] [security2:error] [pid 849392:tid 849539] [client 20.63.98.115:1358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-login.php"] [unique_id "amuTWAMgr4yz2OQW0xrbbAAAAJU"]
[Thu Jul 30 13:09:29.104139 2026] [security2:error] [pid 849392:tid 849631] [client 20.203.148.31:5757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuTWQMgr4yz2OQW0xrbbwAAAPE"]
[Thu Jul 30 13:09:29.490410 2026] [security2:error] [pid 849392:tid 849588] [client 172.213.208.20:20104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuTWQMgr4yz2OQW0xrbcAAAAMY"]
[Thu Jul 30 13:09:29.512104 2026] [security2:error] [pid 849392:tid 849626] [client 20.63.98.115:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "amuTWQMgr4yz2OQW0xrbcQAAAOw"]
[Thu Jul 30 13:09:29.762044 2026] [security2:error] [pid 849392:tid 849599] [client 172.213.208.20:20104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuTWQMgr4yz2OQW0xrbcwAAANE"]
[Thu Jul 30 13:09:30.241704 2026] [security2:error] [pid 849392:tid 849604] [client 20.203.148.31:5722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuTWgMgr4yz2OQW0xrbdwAAANY"]
[Thu Jul 30 13:09:30.404921 2026] [security2:error] [pid 849392:tid 849554] [client 52.167.144.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuTWgMgr4yz2OQW0xrbdgAAAKQ"]
[Thu Jul 30 13:09:30.571385 2026] [security2:error] [pid 849392:tid 849629] [client 172.213.208.20:30622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/index/function.php"] [unique_id "amuTWgMgr4yz2OQW0xrbeQAAAO8"]
[Thu Jul 30 13:09:30.838093 2026] [security2:error] [pid 849392:tid 849605] [client 20.203.148.31:49410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuTWgMgr4yz2OQW0xrbfAAAANc"]
[Thu Jul 30 13:09:30.858889 2026] [security2:error] [pid 849392:tid 849530] [client 172.236.9.101:1777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTWgMgr4yz2OQW0xrbeAAAAIw"]
[Thu Jul 30 13:09:30.976972 2026] [security2:error] [pid 849392:tid 849480] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTWgMgr4yz2OQW0xrbfgAAoVY"]
[Thu Jul 30 13:09:30.977169 2026] [security2:error] [pid 849392:tid 849551] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTWgMgr4yz2OQW0xrbfgAAoVY"]
[Thu Jul 30 13:09:31.450282 2026] [proxy:error] [pid 849392:tid 849559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:31.450363 2026] [proxy_http:error] [pid 849392:tid 849559] [client 34.233.129.35:40064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:31.451063 2026] [proxy:error] [pid 849392:tid 849559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:31.451114 2026] [proxy_http:error] [pid 849392:tid 849559] [client 34.233.129.35:40064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:31.521356 2026] [proxy:error] [pid 849392:tid 849540] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:31.521445 2026] [proxy_http:error] [pid 849392:tid 849540] [client 34.233.129.35:20590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:31.522014 2026] [proxy:error] [pid 849392:tid 849540] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:31.522058 2026] [proxy_http:error] [pid 849392:tid 849540] [client 34.233.129.35:20590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:31.618362 2026] [security2:error] [pid 849392:tid 849648] [client 20.203.148.31:38410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuTWwMgr4yz2OQW0xrbjAAAAQI"]
[Thu Jul 30 13:09:31.811707 2026] [security2:error] [pid 849392:tid 849596] [client 20.63.98.115:59620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp.php"] [unique_id "amuTWwMgr4yz2OQW0xrbjwAAAM4"]
[Thu Jul 30 13:09:31.857915 2026] [security2:error] [pid 849392:tid 849580] [client 172.236.9.101:33506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTWwMgr4yz2OQW0xrbfwAAAL4"]
[Thu Jul 30 13:09:32.549349 2026] [autoindex:error] [pid 849392:tid 849614] [client 172.213.208.20:20151] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:32.693444 2026] [autoindex:error] [pid 849392:tid 849557] [client 172.213.208.20:20151] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:32.823071 2026] [security2:error] [pid 849392:tid 849548] [client 172.213.208.20:20151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/aaa.php"] [unique_id "amuTXAMgr4yz2OQW0xrbkgAAAJ4"]
[Thu Jul 30 13:09:33.109846 2026] [core:notice] [pid 849392:tid 849523] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:33.851199 2026] [security2:error] [pid 849392:tid 849531] [client 172.236.9.101:46640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTXQMgr4yz2OQW0xrblQAAAI0"]
[Thu Jul 30 13:09:33.967505 2026] [security2:error] [pid 849392:tid 849525] [client 20.203.148.31:38400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuTXQMgr4yz2OQW0xrblwAAAIc"]
[Thu Jul 30 13:09:33.968108 2026] [security2:error] [pid 849392:tid 849539] [client 179.64.21.229:8809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTXQMgr4yz2OQW0xrblgAAAJU"]
[Thu Jul 30 13:09:33.968201 2026] [security2:error] [pid 849392:tid 849539] [client 179.64.21.229:8809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTXQMgr4yz2OQW0xrblgAAAJU"]
[Thu Jul 30 13:09:34.325742 2026] [security2:error] [pid 849392:tid 849575] [client 172.213.208.20:36205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/getid3-core.php"] [unique_id "amuTXgMgr4yz2OQW0xrbmAAAALk"]
[Thu Jul 30 13:09:34.652853 2026] [security2:error] [pid 849392:tid 849612] [client 20.63.98.115:49603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/Requests/library/about.php"] [unique_id "amuTXgMgr4yz2OQW0xrbmwAAAN4"]
[Thu Jul 30 13:09:34.746021 2026] [security2:error] [pid 849392:tid 849543] [client 20.203.148.31:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuTXgMgr4yz2OQW0xrbnAAAAJk"]
[Thu Jul 30 13:09:34.896089 2026] [security2:error] [pid 849392:tid 849593] [client 172.213.208.20:27365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/adminer.php"] [unique_id "amuTXgMgr4yz2OQW0xrbnQAAAMs"]
[Thu Jul 30 13:09:35.794908 2026] [security2:error] [pid 849392:tid 849610] [client 172.213.208.20:20128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuTXwMgr4yz2OQW0xrbogAAANw"]
[Thu Jul 30 13:09:35.909290 2026] [security2:error] [pid 849392:tid 849644] [client 20.203.148.31:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuTXwMgr4yz2OQW0xrbowAAAP4"]
[Thu Jul 30 13:09:36.035493 2026] [security2:error] [pid 849392:tid 849648] [client 20.63.98.115:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known/index.php"] [unique_id "amuTYAMgr4yz2OQW0xrbpQAAAQI"]
[Thu Jul 30 13:09:36.124223 2026] [security2:error] [pid 849392:tid 849563] [client 172.213.208.20:20128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/alfa.php"] [unique_id "amuTYAMgr4yz2OQW0xrbpwAAAK0"]
[Thu Jul 30 13:09:36.517489 2026] [security2:error] [pid 849392:tid 849482] [remote 57.141.0.29:30596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458216670/feed/rss2/"] [unique_id "amuTYAMgr4yz2OQW0xrbqQAA8Fg"]
[Thu Jul 30 13:09:36.539121 2026] [security2:error] [pid 849392:tid 849574] [client 20.203.148.31:49467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuTYAMgr4yz2OQW0xrbqgAAALg"]
[Thu Jul 30 13:09:37.609455 2026] [security2:error] [pid 849392:tid 849578] [client 20.203.148.31:5600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuTYQMgr4yz2OQW0xrbtAAAALw"]
[Thu Jul 30 13:09:38.178561 2026] [autoindex:error] [pid 849392:tid 849647] [client 172.213.208.20:26501] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:38.307858 2026] [security2:error] [pid 849392:tid 849590] [client 172.213.208.20:26501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuTYgMgr4yz2OQW0xrbugAAAMg"]
[Thu Jul 30 13:09:38.425885 2026] [security2:error] [pid 849392:tid 849626] [client 20.63.98.115:49630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/asasx.php"] [unique_id "amuTYgMgr4yz2OQW0xrbuwAAAOw"]
[Thu Jul 30 13:09:38.490778 2026] [security2:error] [pid 849392:tid 849633] [client 23.94.216.234:49648] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "mail.jto.nyx.temporary.site"] [uri "/"] [unique_id "amuTYgMgr4yz2OQW0xrbvAAAAPM"]
[Thu Jul 30 13:09:38.701137 2026] [security2:error] [pid 849392:tid 849543] [client 172.236.9.101:8821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTYgMgr4yz2OQW0xrbuAAAAJk"]
[Thu Jul 30 13:09:39.055767 2026] [security2:error] [pid 849392:tid 849477] [remote 207.46.13.31:23693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/%E0%B8%A7%E0%B8%B4%E0%B8%98%E0%B8%B5%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B9%80%E0%B8%82%E0%B8%B5%E0%B8%A2%E0%B8%99%E0%B8%9A%E0%B8%A3%E0%B8%A3%E0%B8%93%E0%B8%B2%E0%B8%99%E0%B8%B8%E0%B8%81%E0%B8%A3%E0%B8%A1/partnerf.php"] [unique_id "amuTYgMgr4yz2OQW0xrbvQAA3FM"]
[Thu Jul 30 13:09:39.311679 2026] [security2:error] [pid 849392:tid 849533] [client 20.63.98.115:1072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/user/wp-login.php"] [unique_id "amuTYwMgr4yz2OQW0xrbvwAAAI8"]
[Thu Jul 30 13:09:39.738724 2026] [security2:error] [pid 849392:tid 849487] [remote 192.250.227.140:49140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.227.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/wp-login.php"] [unique_id "amuTYwMgr4yz2OQW0xrbwAAAil0"]
[Thu Jul 30 13:09:40.184531 2026] [security2:error] [pid 849392:tid 849618] [client 172.213.208.20:36194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuTZAMgr4yz2OQW0xrbwQAAAOQ"]
[Thu Jul 30 13:09:40.534589 2026] [security2:error] [pid 849392:tid 849574] [client 20.63.98.115:1080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "amuTZAMgr4yz2OQW0xrbwwAAALg"]
[Thu Jul 30 13:09:41.263911 2026] [security2:error] [pid 849392:tid 849598] [client 172.213.208.20:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuTZQMgr4yz2OQW0xrbzAAAANA"]
[Thu Jul 30 13:09:41.390680 2026] [security2:error] [pid 849392:tid 849534] [client 20.63.98.115:34440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/radio.php"] [unique_id "amuTZQMgr4yz2OQW0xrbzwAAAJA"]
[Thu Jul 30 13:09:41.453707 2026] [security2:error] [pid 849392:tid 849630] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTZAMgr4yz2OQW0xrbxAAA8GM"]
[Thu Jul 30 13:09:41.829605 2026] [security2:error] [pid 849392:tid 849504] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTZQMgr4yz2OQW0xrb0AAArm4"]
[Thu Jul 30 13:09:41.829816 2026] [security2:error] [pid 849392:tid 849564] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTZQMgr4yz2OQW0xrb0AAArm4"]
[Thu Jul 30 13:09:42.073412 2026] [security2:error] [pid 849392:tid 849529] [client 172.213.208.20:30636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/edit.php"] [unique_id "amuTZgMgr4yz2OQW0xrb1QAAAIs"]
[Thu Jul 30 13:09:42.832108 2026] [autoindex:error] [pid 849392:tid 849545] [client 172.213.208.20:20122] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:43.138921 2026] [security2:error] [pid 849392:tid 849552] [client 172.213.208.20:20122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/sf.php"] [unique_id "amuTZwMgr4yz2OQW0xrb2AAAAKI"]
[Thu Jul 30 13:09:43.530491 2026] [security2:error] [pid 849392:tid 849647] [client 20.63.98.115:53568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuTZwMgr4yz2OQW0xrb2QAAAQE"]
[Thu Jul 30 13:09:43.832784 2026] [autoindex:error] [pid 849392:tid 849537] [client 172.213.208.20:31307] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:09:43.982670 2026] [security2:error] [pid 849392:tid 849641] [client 172.213.208.20:31307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wso.php"] [unique_id "amuTZwMgr4yz2OQW0xrb2wAAAPs"]
[Thu Jul 30 13:09:44.632630 2026] [security2:error] [pid 849392:tid 849538] [client 179.64.21.229:28663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTaAMgr4yz2OQW0xrb3gAAAJQ"]
[Thu Jul 30 13:09:44.632774 2026] [security2:error] [pid 849392:tid 849538] [client 179.64.21.229:28663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTaAMgr4yz2OQW0xrb3gAAAJQ"]
[Thu Jul 30 13:09:45.341928 2026] [security2:error] [pid 849392:tid 849542] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTaAMgr4yz2OQW0xrb4QAAAJg"]
[Thu Jul 30 13:09:46.041286 2026] [security2:error] [pid 849392:tid 849631] [client 172.213.208.20:30638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/ioxi-o.php"] [unique_id "amuTagMgr4yz2OQW0xrb5AAAAPE"]
[Thu Jul 30 13:09:46.405332 2026] [security2:error] [pid 849392:tid 849623] [client 43.173.182.172:48684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/wp/v2/posts/31655"] [unique_id "amuTagMgr4yz2OQW0xrb5QAAAOk"]
[Thu Jul 30 13:09:46.613354 2026] [security2:error] [pid 849392:tid 849621] [client 43.173.177.239:35882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.177.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/01/07/soldes-hiver-2013-whish-list-soldes-made-in-spain/"] [unique_id "amuTagMgr4yz2OQW0xrb5gAAAOc"]
[Thu Jul 30 13:09:47.014574 2026] [security2:error] [pid 849392:tid 849554] [client 20.63.98.115:39585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/st.php"] [unique_id "amuTawMgr4yz2OQW0xrb6gAAAKQ"]
[Thu Jul 30 13:09:47.026573 2026] [core:notice] [pid 849392:tid 849539] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:47.032021 2026] [security2:error] [pid 849392:tid 849539] [client 43.172.195.149:55892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/wp/v2/posts/31655"] [unique_id "amuTawMgr4yz2OQW0xrb6wAAAJU"], referer: https://carnetdeshopping.com/index.php/wp-json/wp/v2/posts/31655
[Thu Jul 30 13:09:47.075685 2026] [security2:error] [pid 849392:tid 849613] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTagMgr4yz2OQW0xrb6QAAAN8"]
[Thu Jul 30 13:09:47.125011 2026] [core:notice] [pid 849392:tid 849568] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:47.130048 2026] [security2:error] [pid 849392:tid 849568] [client 43.173.179.224:54230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/01/07/soldes-hiver-2013-whish-list-soldes-made-in-spain/"] [unique_id "amuTawMgr4yz2OQW0xrb7AAAALI"], referer: https://carnetdeshopping.com/index.php/2013/01/07/soldes-hiver-2013-whish-list-soldes-made-in-spain/
[Thu Jul 30 13:09:47.231877 2026] [security2:error] [pid 849392:tid 849579] [client 172.213.208.20:16232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/file56.php"] [unique_id "amuTawMgr4yz2OQW0xrb7QAAAL0"]
[Thu Jul 30 13:09:47.827358 2026] [security2:error] [pid 849392:tid 849572] [client 20.63.98.115:57661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/about.php"] [unique_id "amuTawMgr4yz2OQW0xrb8AAAALY"]
[Thu Jul 30 13:09:48.121793 2026] [security2:error] [pid 849392:tid 849615] [client 172.213.208.20:15250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuTbAMgr4yz2OQW0xrb8QAAAOE"]
[Thu Jul 30 13:09:48.649931 2026] [security2:error] [pid 849392:tid 849502] [remote 40.77.167.24:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/181236424603/job.php"] [unique_id "amuTbAMgr4yz2OQW0xrb9wAA2mw"]
[Thu Jul 30 13:09:49.485139 2026] [security2:error] [pid 849392:tid 849626] [client 20.63.98.115:62091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/admin.php"] [unique_id "amuTbQMgr4yz2OQW0xrb_AAAAOw"]
[Thu Jul 30 13:09:51.036709 2026] [security2:error] [pid 849392:tid 849641] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTbgMgr4yz2OQW0xrcAwAAAPs"]
[Thu Jul 30 13:09:51.141927 2026] [proxy:error] [pid 849392:tid 849649] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:51.142038 2026] [proxy_http:error] [pid 849392:tid 849649] [client 34.233.129.35:22485] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:51.142135 2026] [proxy:error] [pid 849392:tid 849587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:51.142195 2026] [proxy_http:error] [pid 849392:tid 849587] [client 34.233.129.35:36559] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:51.142750 2026] [proxy:error] [pid 849392:tid 849587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:51.142795 2026] [proxy_http:error] [pid 849392:tid 849587] [client 34.233.129.35:36559] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:51.142891 2026] [proxy:error] [pid 849392:tid 849649] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:09:51.142966 2026] [proxy_http:error] [pid 849392:tid 849649] [client 34.233.129.35:22485] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:09:52.599733 2026] [security2:error] [pid 849392:tid 849516] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTcAMgr4yz2OQW0xrcIQAA53o"]
[Thu Jul 30 13:09:52.599941 2026] [security2:error] [pid 849392:tid 849621] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTcAMgr4yz2OQW0xrcIQAA53o"]
[Thu Jul 30 13:09:53.036316 2026] [security2:error] [pid 849392:tid 849616] [client 172.213.208.20:31320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-admin/css/index.php"] [unique_id "amuTcQMgr4yz2OQW0xrcJAAAAOI"]
[Thu Jul 30 13:09:54.938283 2026] [security2:error] [pid 849392:tid 849590] [client 20.63.98.115:62130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/css/admin.php"] [unique_id "amuTcgMgr4yz2OQW0xrcLQAAAMg"]
[Thu Jul 30 13:09:55.318244 2026] [security2:error] [pid 849392:tid 849610] [client 179.64.21.229:27224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTcwMgr4yz2OQW0xrcMAAAANw"]
[Thu Jul 30 13:09:55.321768 2026] [security2:error] [pid 849392:tid 849610] [client 179.64.21.229:27224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTcwMgr4yz2OQW0xrcMAAAANw"]
[Thu Jul 30 13:09:55.827960 2026] [security2:error] [pid 849392:tid 849626] [client 172.236.9.101:8299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTcwMgr4yz2OQW0xrcLwAAAOw"]
[Thu Jul 30 13:09:56.357358 2026] [security2:error] [pid 849392:tid 849536] [client 172.213.208.20:15259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/edit.php"] [unique_id "amuTdAMgr4yz2OQW0xrcMwAAAJI"]
[Thu Jul 30 13:09:56.411213 2026] [core:notice] [pid 849392:tid 849521] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:56.658549 2026] [security2:error] [pid 849392:tid 849618] [client 20.63.98.115:59524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuTdAMgr4yz2OQW0xrcNgAAAOQ"]
[Thu Jul 30 13:09:56.723299 2026] [security2:error] [pid 849392:tid 849557] [client 185.200.116.219:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTdAMgr4yz2OQW0xrcOgAAAKc"]
[Thu Jul 30 13:09:56.723394 2026] [security2:error] [pid 849392:tid 849557] [client 185.200.116.219:49320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTdAMgr4yz2OQW0xrcOgAAAKc"]
[Thu Jul 30 13:09:57.060001 2026] [core:notice] [pid 849392:tid 849404] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:09:57.304239 2026] [security2:error] [pid 849392:tid 849624] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTdAMgr4yz2OQW0xrcOQAAAOo"]
[Thu Jul 30 13:09:57.977413 2026] [security2:error] [pid 849392:tid 849601] [client 172.213.208.20:21319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/2.php"] [unique_id "amuTdQMgr4yz2OQW0xrcPwAAANM"]
[Thu Jul 30 13:09:58.752749 2026] [security2:error] [pid 849392:tid 849607] [client 172.213.208.20:27595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuTdgMgr4yz2OQW0xrcQQAAANk"]
[Thu Jul 30 13:09:58.759257 2026] [security2:error] [pid 849392:tid 849525] [client 20.63.98.115:50343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp2.php"] [unique_id "amuTdgMgr4yz2OQW0xrcQgAAAIc"]
[Thu Jul 30 13:09:59.570084 2026] [security2:error] [pid 849392:tid 849550] [client 172.213.208.20:9889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/mah.php"] [unique_id "amuTdwMgr4yz2OQW0xrcRgAAAKA"]
[Thu Jul 30 13:09:59.835575 2026] [security2:error] [pid 849392:tid 849630] [client 20.63.98.115:50331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/s.php"] [unique_id "amuTdwMgr4yz2OQW0xrcRwAAAPA"]
[Thu Jul 30 13:10:00.186062 2026] [security2:error] [pid 849392:tid 849621] [client 172.213.208.20:9886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/send.php"] [unique_id "amuTeAMgr4yz2OQW0xrcSAAAAOc"]
[Thu Jul 30 13:10:00.853967 2026] [security2:error] [pid 849392:tid 849616] [client 20.63.98.115:50322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/help.php"] [unique_id "amuTeAMgr4yz2OQW0xrcUQAAAOI"]
[Thu Jul 30 13:10:01.536471 2026] [security2:error] [pid 849392:tid 849539] [client 43.157.142.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuTeAMgr4yz2OQW0xrcSwAAAJU"]
[Thu Jul 30 13:10:02.625809 2026] [security2:error] [pid 849392:tid 849557] [client 172.213.208.20:25327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuTegMgr4yz2OQW0xrceAAAAKc"]
[Thu Jul 30 13:10:03.408912 2026] [autoindex:error] [pid 849392:tid 849645] [client 172.213.208.20:18919] AH01276: Cannot serve directory /home2/plsudite/public_html/old/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:10:03.486242 2026] [security2:error] [pid 849392:tid 849647] [client 20.63.98.115:40857] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "adbacklink.com"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuTewMgr4yz2OQW0xrcgwAAAQE"]
[Thu Jul 30 13:10:03.486384 2026] [security2:error] [pid 849392:tid 849647] [client 20.63.98.115:40857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuTewMgr4yz2OQW0xrcgwAAAQE"]
[Thu Jul 30 13:10:03.537934 2026] [security2:error] [pid 849392:tid 849600] [client 172.213.208.20:18919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/about.php"] [unique_id "amuTewMgr4yz2OQW0xrchAAAANI"]
[Thu Jul 30 13:10:04.295162 2026] [security2:error] [pid 849392:tid 849401] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTfAMgr4yz2OQW0xrchQAAkAc"]
[Thu Jul 30 13:10:04.295311 2026] [security2:error] [pid 849392:tid 849534] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTfAMgr4yz2OQW0xrchQAAkAc"]
[Thu Jul 30 13:10:04.564487 2026] [security2:error] [pid 849392:tid 849564] [client 20.63.98.115:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/admin/upload/css.php"] [unique_id "amuTfAMgr4yz2OQW0xrcigAAAK4"]
[Thu Jul 30 13:10:05.434465 2026] [security2:error] [pid 849392:tid 849605] [client 20.63.98.115:62124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuTfQMgr4yz2OQW0xrcjwAAANc"]
[Thu Jul 30 13:10:05.758565 2026] [security2:error] [pid 849392:tid 849586] [client 172.236.9.101:8561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTfQMgr4yz2OQW0xrcjAAAAMQ"]
[Thu Jul 30 13:10:05.787258 2026] [security2:error] [pid 849392:tid 849568] [client 172.236.9.101:53380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTfQMgr4yz2OQW0xrciwAAALI"]
[Thu Jul 30 13:10:06.085544 2026] [security2:error] [pid 849392:tid 849631] [client 185.191.171.13:48154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/13/cartorio-e-inativado-em-campina-grande-apos-justica-da-paraiba-identificar-irregularidades-na-prestacao-de-contas/"] [unique_id "amuTfgMgr4yz2OQW0xrckwAAAPE"]
[Thu Jul 30 13:10:06.085840 2026] [security2:error] [pid 849392:tid 849631] [client 185.191.171.13:48154] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/13/cartorio-e-inativado-em-campina-grande-apos-justica-da-paraiba-identificar-irregularidades-na-prestacao-de-contas/"] [unique_id "amuTfgMgr4yz2OQW0xrckwAAAPE"]
[Thu Jul 30 13:10:06.176288 2026] [security2:error] [pid 849392:tid 849577] [client 179.64.21.229:18077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTfgMgr4yz2OQW0xrclAAAALs"]
[Thu Jul 30 13:10:06.188688 2026] [security2:error] [pid 849392:tid 849577] [client 179.64.21.229:18077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTfgMgr4yz2OQW0xrclAAAALs"]
[Thu Jul 30 13:10:06.226420 2026] [security2:error] [pid 849392:tid 849575] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTfQMgr4yz2OQW0xrckQAAuR0"]
[Thu Jul 30 13:10:06.581200 2026] [security2:error] [pid 849392:tid 849554] [client 172.213.208.20:18942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/options.php"] [unique_id "amuTfgMgr4yz2OQW0xrcngAAAKQ"]
[Thu Jul 30 13:10:06.826798 2026] [security2:error] [pid 849392:tid 849593] [client 172.236.9.101:57123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTfgMgr4yz2OQW0xrclgAAAMs"]
[Thu Jul 30 13:10:07.054701 2026] [security2:error] [pid 849392:tid 849529] [client 20.63.98.115:40885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/autoloadclassmap.php"] [unique_id "amuTfwMgr4yz2OQW0xrcnwAAAIs"]
[Thu Jul 30 13:10:07.286507 2026] [security2:error] [pid 849392:tid 849610] [client 85.208.96.212:51328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amuTfwMgr4yz2OQW0xrcoAAAANw"]
[Thu Jul 30 13:10:07.286668 2026] [security2:error] [pid 849392:tid 849610] [client 85.208.96.212:51328] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amuTfwMgr4yz2OQW0xrcoAAAANw"]
[Thu Jul 30 13:10:08.023282 2026] [core:notice] [pid 849392:tid 849395] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:08.280458 2026] [security2:error] [pid 849392:tid 849622] [client 185.191.171.7:49882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/1663"] [unique_id "amuTgAMgr4yz2OQW0xrcqgAAAOg"]
[Thu Jul 30 13:10:08.280575 2026] [security2:error] [pid 849392:tid 849622] [client 185.191.171.7:49882] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/1663"] [unique_id "amuTgAMgr4yz2OQW0xrcqgAAAOg"]
[Thu Jul 30 13:10:08.301917 2026] [security2:error] [pid 849392:tid 849530] [client 20.63.98.115:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/x.php"] [unique_id "amuTgAMgr4yz2OQW0xrcqwAAAIw"]
[Thu Jul 30 13:10:09.481384 2026] [security2:error] [pid 849392:tid 849553] [client 20.63.98.115:59551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-class.php"] [unique_id "amuTgQMgr4yz2OQW0xrcugAAAKM"]
[Thu Jul 30 13:10:10.351480 2026] [security2:error] [pid 849392:tid 849647] [client 20.63.98.115:62097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/content.php"] [unique_id "amuTggMgr4yz2OQW0xrcwAAAAQE"]
[Thu Jul 30 13:10:10.941022 2026] [security2:error] [pid 849392:tid 849573] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTggMgr4yz2OQW0xrcvwAAALc"]
[Thu Jul 30 13:10:11.496874 2026] [autoindex:error] [pid 849392:tid 849548] [client 185.247.137.111:58355] AH01276: Cannot serve directory /home2/zorudite/public_html/website_041a3cce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:10:11.929590 2026] [security2:error] [pid 849392:tid 849462] [remote 47.128.37.233:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/robots.txt"] [unique_id "amuTgwMgr4yz2OQW0xrcwwAA3kQ"]
[Thu Jul 30 13:10:12.452249 2026] [security2:error] [pid 849392:tid 849621] [client 20.63.98.115:36647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/acp.php"] [unique_id "amuThAMgr4yz2OQW0xrcxAAAAOc"]
[Thu Jul 30 13:10:13.217697 2026] [security2:error] [pid 849392:tid 849535] [client 172.213.208.20:18883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content/themes/index.php"] [unique_id "amuThQMgr4yz2OQW0xrcxgAAAJE"]
[Thu Jul 30 13:10:13.404327 2026] [security2:error] [pid 849392:tid 849572] [client 20.63.98.115:49802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/g.php"] [unique_id "amuThQMgr4yz2OQW0xrcywAAALY"]
[Thu Jul 30 13:10:13.502339 2026] [security2:error] [pid 849392:tid 849432] [remote 57.141.0.13:44526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuThQMgr4yz2OQW0xrczAAAmSY"]
[Thu Jul 30 13:10:14.254630 2026] [security2:error] [pid 849392:tid 849593] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuThQMgr4yz2OQW0xrczwAAAMs"]
[Thu Jul 30 13:10:14.464464 2026] [security2:error] [pid 849392:tid 849561] [client 20.63.98.115:40855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known/caches.php"] [unique_id "amuThgMgr4yz2OQW0xrc0wAAAKs"]
[Thu Jul 30 13:10:14.717306 2026] [security2:error] [pid 849392:tid 849530] [client 172.213.208.20:25894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-file.php"] [unique_id "amuThgMgr4yz2OQW0xrc1wAAAIw"]
[Thu Jul 30 13:10:14.789135 2026] [security2:error] [pid 849392:tid 849458] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuThgMgr4yz2OQW0xrc2AAAhUA"]
[Thu Jul 30 13:10:14.789323 2026] [security2:error] [pid 849392:tid 849523] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuThgMgr4yz2OQW0xrc2AAAhUA"]
[Thu Jul 30 13:10:15.192082 2026] [security2:error] [pid 849392:tid 849538] [client 20.63.98.115:36669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuThwMgr4yz2OQW0xrc3AAAAJQ"]
[Thu Jul 30 13:10:15.355404 2026] [security2:error] [pid 849392:tid 849587] [client 172.213.208.20:25908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/sid3.php"] [unique_id "amuThwMgr4yz2OQW0xrc3wAAAMU"]
[Thu Jul 30 13:10:15.526188 2026] [core:notice] [pid 849392:tid 849582] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:15.784309 2026] [security2:error] [pid 849392:tid 849570] [client 172.236.9.101:63484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuThwMgr4yz2OQW0xrc3gAAALQ"]
[Thu Jul 30 13:10:15.786564 2026] [security2:error] [pid 849392:tid 849559] [client 172.236.9.101:24914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuThwMgr4yz2OQW0xrc3QAAAKk"]
[Thu Jul 30 13:10:16.468318 2026] [security2:error] [pid 849392:tid 849641] [client 179.64.21.229:52023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTiAMgr4yz2OQW0xrc4wAAAPs"]
[Thu Jul 30 13:10:16.475176 2026] [security2:error] [pid 849392:tid 849641] [client 179.64.21.229:52023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTiAMgr4yz2OQW0xrc4wAAAPs"]
[Thu Jul 30 13:10:16.710846 2026] [core:notice] [pid 849392:tid 849537] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:16.901351 2026] [security2:error] [pid 849392:tid 849606] [client 20.63.98.115:50050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/css/about.php"] [unique_id "amuTiAMgr4yz2OQW0xrc6AAAANg"]
[Thu Jul 30 13:10:17.119633 2026] [security2:error] [pid 849392:tid 849604] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTiAMgr4yz2OQW0xrc5gAAANY"]
[Thu Jul 30 13:10:17.724283 2026] [security2:error] [pid 849392:tid 849599] [client 172.236.9.101:53477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTiQMgr4yz2OQW0xrc6QAAANE"]
[Thu Jul 30 13:10:17.726021 2026] [core:notice] [pid 849392:tid 849597] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:17.928698 2026] [security2:error] [pid 849392:tid 849534] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTiQMgr4yz2OQW0xrc7AAAAJA"]
[Thu Jul 30 13:10:19.062047 2026] [core:notice] [pid 849392:tid 849638] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:20.733234 2026] [security2:error] [pid 849392:tid 849443] [remote 72.167.132.114:44786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuTjAMgr4yz2OQW0xrc9AAAvzE"]
[Thu Jul 30 13:10:21.842653 2026] [security2:error] [pid 849392:tid 849556] [client 20.63.98.115:59527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/files/index.php"] [unique_id "amuTjQMgr4yz2OQW0xrc-wAAAKY"]
[Thu Jul 30 13:10:22.672180 2026] [security2:error] [pid 849392:tid 849529] [client 20.63.98.115:2041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuTjgMgr4yz2OQW0xrdFAAAAIs"]
[Thu Jul 30 13:10:22.891738 2026] [security2:error] [pid 849392:tid 849595] [client 172.236.9.101:30031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTjgMgr4yz2OQW0xrdCQAAAM0"]
[Thu Jul 30 13:10:23.401774 2026] [security2:error] [pid 849392:tid 849594] [client 213.152.161.85:50232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuTjwMgr4yz2OQW0xrdGAAAAMw"]
[Thu Jul 30 13:10:23.401903 2026] [security2:error] [pid 849392:tid 849594] [client 213.152.161.85:50232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuTjwMgr4yz2OQW0xrdGAAAAMw"]
[Thu Jul 30 13:10:23.449118 2026] [security2:error] [pid 849392:tid 849547] [client 20.63.98.115:36624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/network/admin.php"] [unique_id "amuTjwMgr4yz2OQW0xrdHwAAAJ0"]
[Thu Jul 30 13:10:24.702559 2026] [security2:error] [pid 849392:tid 849606] [client 172.236.9.101:7000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTkAMgr4yz2OQW0xrdJAAAANg"]
[Thu Jul 30 13:10:24.827911 2026] [security2:error] [pid 849392:tid 849627] [client 172.236.9.101:37165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTkAMgr4yz2OQW0xrdJQAAAO0"]
[Thu Jul 30 13:10:25.359612 2026] [security2:error] [pid 849392:tid 849439] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTkQMgr4yz2OQW0xrdLAAA0i0"]
[Thu Jul 30 13:10:25.359760 2026] [security2:error] [pid 849392:tid 849600] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTkQMgr4yz2OQW0xrdLAAA0i0"]
[Thu Jul 30 13:10:25.856556 2026] [security2:error] [pid 849392:tid 849527] [client 20.63.98.115:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuTkQMgr4yz2OQW0xrdLgAAAIk"]
[Thu Jul 30 13:10:26.597206 2026] [security2:error] [pid 849392:tid 849603] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTkgMgr4yz2OQW0xrdMQAAANU"]
[Thu Jul 30 13:10:26.738880 2026] [security2:error] [pid 849392:tid 849571] [client 172.236.9.101:63319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTkgMgr4yz2OQW0xrdOQAAALU"]
[Thu Jul 30 13:10:26.767000 2026] [security2:error] [pid 849392:tid 849634] [client 20.63.98.115:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuTkgMgr4yz2OQW0xrdOgAAAPQ"]
[Thu Jul 30 13:10:26.856726 2026] [core:notice] [pid 849392:tid 849581] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:26.975216 2026] [security2:error] [pid 849392:tid 849612] [client 179.64.21.229:3389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTkgMgr4yz2OQW0xrdPAAAAN4"]
[Thu Jul 30 13:10:26.979230 2026] [security2:error] [pid 849392:tid 849612] [client 179.64.21.229:3389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTkgMgr4yz2OQW0xrdPAAAAN4"]
[Thu Jul 30 13:10:27.292365 2026] [autoindex:error] [pid 849392:tid 849575] [client 43.130.116.87:0] AH01276: Cannot serve directory /home2/mbmudite/ok.tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.tiger388.shop
[Thu Jul 30 13:10:27.661212 2026] [security2:error] [pid 849392:tid 849623] [client 158.158.32.229:23700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuTkwMgr4yz2OQW0xrdPgAAAOk"]
[Thu Jul 30 13:10:27.661362 2026] [security2:error] [pid 849392:tid 849623] [client 158.158.32.229:23700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuTkwMgr4yz2OQW0xrdPgAAAOk"]
[Thu Jul 30 13:10:28.116712 2026] [core:notice] [pid 849392:tid 849475] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:28.387178 2026] [security2:error] [pid 849392:tid 849588] [client 20.63.98.115:50109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/fonts/wp-login.php"] [unique_id "amuTlAMgr4yz2OQW0xrdRwAAAMY"]
[Thu Jul 30 13:10:29.092482 2026] [core:notice] [pid 849392:tid 849444] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:29.794466 2026] [proxy:error] [pid 849392:tid 849626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:29.794540 2026] [proxy_http:error] [pid 849392:tid 849626] [client 3.225.222.228:9077] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:29.795204 2026] [proxy:error] [pid 849392:tid 849626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:29.795262 2026] [proxy_http:error] [pid 849392:tid 849626] [client 3.225.222.228:9077] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:29.802223 2026] [proxy:error] [pid 849392:tid 849569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:29.802291 2026] [proxy_http:error] [pid 849392:tid 849569] [client 3.225.222.228:37503] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:29.802951 2026] [proxy:error] [pid 849392:tid 849569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:29.803019 2026] [proxy_http:error] [pid 849392:tid 849569] [client 3.225.222.228:37503] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:30.259467 2026] [security2:error] [pid 849392:tid 849635] [client 20.63.98.115:49815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/themes.php"] [unique_id "amuTlgMgr4yz2OQW0xrdYAAAAPU"]
[Thu Jul 30 13:10:31.123318 2026] [security2:error] [pid 849392:tid 849566] [client 20.63.98.115:50101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/if.php"] [unique_id "amuTlwMgr4yz2OQW0xrdbgAAALA"]
[Thu Jul 30 13:10:31.801616 2026] [proxy:error] [pid 849392:tid 849558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:31.801714 2026] [proxy_http:error] [pid 849392:tid 849558] [client 52.4.19.39:37622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:31.802149 2026] [autoindex:error] [pid 849392:tid 849613] [client 52.4.19.39:46226] AH01276: Cannot serve directory /home2/xncnyxte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:10:31.802521 2026] [proxy:error] [pid 849392:tid 849558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:31.802582 2026] [proxy_http:error] [pid 849392:tid 849558] [client 52.4.19.39:37622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:31.818906 2026] [proxy:error] [pid 849392:tid 849571] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:31.819020 2026] [proxy_http:error] [pid 849392:tid 849571] [client 3.225.222.228:26671] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:31.819919 2026] [proxy:error] [pid 849392:tid 849571] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:31.820015 2026] [proxy_http:error] [pid 849392:tid 849571] [client 3.225.222.228:26671] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:31.820932 2026] [autoindex:error] [pid 849392:tid 849591] [client 3.225.222.228:9473] AH01276: Cannot serve directory /home2/xncnyxte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:10:32.135232 2026] [security2:error] [pid 849392:tid 849551] [client 20.63.98.115:1993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/editor.php"] [unique_id "amuTmAMgr4yz2OQW0xrdggAAAKE"]
[Thu Jul 30 13:10:32.761556 2026] [security2:error] [pid 849392:tid 849544] [client 158.158.32.229:28259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuTmAMgr4yz2OQW0xrdgwAAAJo"]
[Thu Jul 30 13:10:32.761704 2026] [security2:error] [pid 849392:tid 849544] [client 158.158.32.229:28259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuTmAMgr4yz2OQW0xrdgwAAAJo"]
[Thu Jul 30 13:10:33.782995 2026] [security2:error] [pid 849392:tid 849630] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTmQMgr4yz2OQW0xrdjQAA8F8"]
[Thu Jul 30 13:10:33.815967 2026] [security2:error] [pid 849392:tid 849585] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTmQMgr4yz2OQW0xrdkAAAAMM"]
[Thu Jul 30 13:10:34.724967 2026] [security2:error] [pid 849392:tid 849574] [client 172.236.9.101:1109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTmgMgr4yz2OQW0xrdlwAAALg"]
[Thu Jul 30 13:10:34.742128 2026] [security2:error] [pid 849392:tid 849615] [client 20.63.98.115:49822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/click.php"] [unique_id "amuTmgMgr4yz2OQW0xrdnwAAAOE"]
[Thu Jul 30 13:10:34.805058 2026] [security2:error] [pid 849392:tid 849542] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTmgMgr4yz2OQW0xrdlgAAAJg"]
[Thu Jul 30 13:10:34.846578 2026] [security2:error] [pid 849392:tid 849649] [client 172.236.9.101:65337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTmgMgr4yz2OQW0xrdmAAAAQM"]
[Thu Jul 30 13:10:35.116594 2026] [proxy:error] [pid 849392:tid 849627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:35.116674 2026] [proxy_http:error] [pid 849392:tid 849627] [client 143.244.57.82:50870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:35.117257 2026] [proxy:error] [pid 849392:tid 849627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:35.117302 2026] [proxy_http:error] [pid 849392:tid 849627] [client 143.244.57.82:50870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:35.269495 2026] [security2:error] [pid 849392:tid 849553] [client 158.158.32.229:22765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuTmwMgr4yz2OQW0xrdoQAAAKM"]
[Thu Jul 30 13:10:35.269620 2026] [security2:error] [pid 849392:tid 849553] [client 158.158.32.229:22765] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuTmwMgr4yz2OQW0xrdoQAAAKM"]
[Thu Jul 30 13:10:35.400457 2026] [proxy:error] [pid 849392:tid 849639] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:35.400542 2026] [proxy_http:error] [pid 849392:tid 849639] [client 143.244.57.82:50882] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:35.401111 2026] [proxy:error] [pid 849392:tid 849639] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:35.401155 2026] [proxy_http:error] [pid 849392:tid 849639] [client 143.244.57.82:50882] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:35.680867 2026] [security2:error] [pid 849392:tid 849597] [client 143.244.57.82:50884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuTmwMgr4yz2OQW0xrdowAAAM8"]
[Thu Jul 30 13:10:35.956521 2026] [proxy:error] [pid 849392:tid 849523] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:35.956629 2026] [proxy_http:error] [pid 849392:tid 849523] [client 143.244.57.82:50886] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:35.957360 2026] [proxy:error] [pid 849392:tid 849523] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:10:35.957418 2026] [proxy_http:error] [pid 849392:tid 849523] [client 143.244.57.82:50886] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:10:36.015237 2026] [security2:error] [pid 849392:tid 849512] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTnAMgr4yz2OQW0xrdpgAAiXY"]
[Thu Jul 30 13:10:36.015423 2026] [security2:error] [pid 849392:tid 849527] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTnAMgr4yz2OQW0xrdpgAAiXY"]
[Thu Jul 30 13:10:36.252990 2026] [security2:error] [pid 849392:tid 849565] [client 143.244.57.82:50902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuTnAMgr4yz2OQW0xrdpwAAAK8"]
[Thu Jul 30 13:10:36.529281 2026] [security2:error] [pid 849392:tid 849622] [client 143.244.57.82:50914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuTnAMgr4yz2OQW0xrdqQAAAOg"]
[Thu Jul 30 13:10:36.774765 2026] [security2:error] [pid 849392:tid 849560] [client 172.236.9.101:22723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTnAMgr4yz2OQW0xrdqAAAAKo"]
[Thu Jul 30 13:10:36.801311 2026] [security2:error] [pid 849392:tid 849581] [client 143.244.57.82:50926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuTnAMgr4yz2OQW0xrdsAAAAL8"]
[Thu Jul 30 13:10:37.108495 2026] [security2:error] [pid 849392:tid 849623] [client 143.244.57.82:51736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuTnQMgr4yz2OQW0xrdtAAAAOk"]
[Thu Jul 30 13:10:37.131454 2026] [security2:error] [pid 849392:tid 849609] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTnAMgr4yz2OQW0xrdrAAAANs"]
[Thu Jul 30 13:10:37.390189 2026] [security2:error] [pid 849392:tid 849579] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTnAMgr4yz2OQW0xrdrwAAAL0"]
[Thu Jul 30 13:10:37.392457 2026] [security2:error] [pid 849392:tid 849637] [client 143.244.57.82:51740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuTnQMgr4yz2OQW0xrduAAAAPc"]
[Thu Jul 30 13:10:37.511916 2026] [security2:error] [pid 849392:tid 849548] [client 179.64.21.229:56212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTnQMgr4yz2OQW0xrduQAAAJ4"]
[Thu Jul 30 13:10:37.512073 2026] [security2:error] [pid 849392:tid 849548] [client 179.64.21.229:56212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTnQMgr4yz2OQW0xrduQAAAJ4"]
[Thu Jul 30 13:10:37.672799 2026] [security2:error] [pid 849392:tid 849611] [client 143.244.57.82:51744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuTnQMgr4yz2OQW0xrdugAAAN0"]
[Thu Jul 30 13:10:37.953071 2026] [security2:error] [pid 849392:tid 849552] [client 143.244.57.82:51760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuTnQMgr4yz2OQW0xrduwAAAKI"]
[Thu Jul 30 13:10:38.023308 2026] [security2:error] [pid 849392:tid 849592] [client 158.158.32.229:43279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/media.php"] [unique_id "amuTngMgr4yz2OQW0xrdvAAAAMo"]
[Thu Jul 30 13:10:38.023436 2026] [security2:error] [pid 849392:tid 849592] [client 158.158.32.229:43279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/media.php"] [unique_id "amuTngMgr4yz2OQW0xrdvAAAAMo"]
[Thu Jul 30 13:10:38.225455 2026] [core:notice] [pid 849392:tid 849486] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:38.244641 2026] [security2:error] [pid 849392:tid 849593] [client 143.244.57.82:51772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuTngMgr4yz2OQW0xrdvgAAAMs"]
[Thu Jul 30 13:10:38.527633 2026] [security2:error] [pid 849392:tid 849617] [client 143.244.57.82:51786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuTngMgr4yz2OQW0xrdvwAAAOM"]
[Thu Jul 30 13:10:38.804248 2026] [security2:error] [pid 849392:tid 849539] [client 143.244.57.82:51790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuTngMgr4yz2OQW0xrdwwAAAJU"]
[Thu Jul 30 13:10:38.865606 2026] [core:notice] [pid 849392:tid 849511] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:39.103290 2026] [security2:error] [pid 849392:tid 849585] [client 143.244.57.82:51794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuTnwMgr4yz2OQW0xrdxQAAAMM"]
[Thu Jul 30 13:10:39.376394 2026] [security2:error] [pid 849392:tid 849528] [client 143.244.57.82:51806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuTnwMgr4yz2OQW0xrdxwAAAIo"]
[Thu Jul 30 13:10:39.658394 2026] [security2:error] [pid 849392:tid 849570] [client 143.244.57.82:51820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wyt.gpl.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuTnwMgr4yz2OQW0xrdygAAALQ"]
[Thu Jul 30 13:10:40.860289 2026] [security2:error] [pid 849392:tid 849601] [client 158.158.32.229:27696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/images.php"] [unique_id "amuToAMgr4yz2OQW0xrd3AAAANM"]
[Thu Jul 30 13:10:40.860448 2026] [security2:error] [pid 849392:tid 849601] [client 158.158.32.229:27696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/images.php"] [unique_id "amuToAMgr4yz2OQW0xrd3AAAANM"]
[Thu Jul 30 13:10:41.090106 2026] [security2:error] [pid 849392:tid 849606] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuToAMgr4yz2OQW0xrd2QAAANg"]
[Thu Jul 30 13:10:43.585200 2026] [security2:error] [pid 849392:tid 849399] [remote 57.141.0.55:32294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/358522518/feed/rss2/"] [unique_id "amuTowMgr4yz2OQW0xrd6AAA2wU"]
[Thu Jul 30 13:10:44.027919 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.32.229:24304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/adminner.php"] [unique_id "amuTpAMgr4yz2OQW0xrd6QAAAO4"]
[Thu Jul 30 13:10:44.028103 2026] [security2:error] [pid 849392:tid 849628] [client 158.158.32.229:24304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/adminner.php"] [unique_id "amuTpAMgr4yz2OQW0xrd6QAAAO4"]
[Thu Jul 30 13:10:44.142751 2026] [security2:error] [pid 849392:tid 849603] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTowMgr4yz2OQW0xrd5wAAANU"]
[Thu Jul 30 13:10:44.497811 2026] [security2:error] [pid 849392:tid 849590] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuTpAMgr4yz2OQW0xrd6wAAAMg"]
[Thu Jul 30 13:10:44.498076 2026] [security2:error] [pid 849392:tid 849590] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuTpAMgr4yz2OQW0xrd6wAAAMg"]
[Thu Jul 30 13:10:44.752113 2026] [security2:error] [pid 849392:tid 849637] [client 172.236.9.101:37578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTpAMgr4yz2OQW0xrd6gAAAPc"]
[Thu Jul 30 13:10:44.805952 2026] [security2:error] [pid 849392:tid 849588] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuTpAMgr4yz2OQW0xrd7QAAAMY"]
[Thu Jul 30 13:10:44.806070 2026] [security2:error] [pid 849392:tid 849588] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuTpAMgr4yz2OQW0xrd7QAAAMY"]
[Thu Jul 30 13:10:45.137629 2026] [security2:error] [pid 849392:tid 849596] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuTpQMgr4yz2OQW0xrd9AAAAM4"]
[Thu Jul 30 13:10:45.137776 2026] [security2:error] [pid 849392:tid 849596] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuTpQMgr4yz2OQW0xrd9AAAAM4"]
[Thu Jul 30 13:10:45.455359 2026] [security2:error] [pid 849392:tid 849563] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/err.php"] [unique_id "amuTpQMgr4yz2OQW0xrd9wAAAK0"]
[Thu Jul 30 13:10:45.455488 2026] [security2:error] [pid 849392:tid 849563] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/err.php"] [unique_id "amuTpQMgr4yz2OQW0xrd9wAAAK0"]
[Thu Jul 30 13:10:45.795633 2026] [security2:error] [pid 849392:tid 849541] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/img.php"] [unique_id "amuTpQMgr4yz2OQW0xrd-AAAAJc"]
[Thu Jul 30 13:10:45.795746 2026] [security2:error] [pid 849392:tid 849541] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/img.php"] [unique_id "amuTpQMgr4yz2OQW0xrd-AAAAJc"]
[Thu Jul 30 13:10:46.136989 2026] [security2:error] [pid 849392:tid 849626] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/aa.php"] [unique_id "amuTpgMgr4yz2OQW0xrd-gAAAOw"]
[Thu Jul 30 13:10:46.137083 2026] [security2:error] [pid 849392:tid 849626] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/aa.php"] [unique_id "amuTpgMgr4yz2OQW0xrd-gAAAOw"]
[Thu Jul 30 13:10:46.255958 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.32.229:5224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/admin.php"] [unique_id "amuTpgMgr4yz2OQW0xrd_AAAAKw"]
[Thu Jul 30 13:10:46.256117 2026] [security2:error] [pid 849392:tid 849562] [client 158.158.32.229:5224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/admin.php"] [unique_id "amuTpgMgr4yz2OQW0xrd_AAAAKw"]
[Thu Jul 30 13:10:46.311651 2026] [security2:error] [pid 849392:tid 849532] [client 20.63.98.115:9266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/test.php7"] [unique_id "amuTpgMgr4yz2OQW0xrd_QAAAI4"]
[Thu Jul 30 13:10:46.456958 2026] [security2:error] [pid 849392:tid 849650] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/av.php"] [unique_id "amuTpgMgr4yz2OQW0xrd_gAAAQQ"]
[Thu Jul 30 13:10:46.457111 2026] [security2:error] [pid 849392:tid 849650] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/av.php"] [unique_id "amuTpgMgr4yz2OQW0xrd_gAAAQQ"]
[Thu Jul 30 13:10:46.733792 2026] [security2:error] [pid 849392:tid 849580] [client 172.236.9.101:12885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTpgMgr4yz2OQW0xrd-wAAAL4"]
[Thu Jul 30 13:10:46.765624 2026] [security2:error] [pid 849392:tid 849594] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/xa.php"] [unique_id "amuTpgMgr4yz2OQW0xreAgAAAMw"]
[Thu Jul 30 13:10:46.765741 2026] [security2:error] [pid 849392:tid 849594] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/xa.php"] [unique_id "amuTpgMgr4yz2OQW0xreAgAAAMw"]
[Thu Jul 30 13:10:46.791654 2026] [security2:error] [pid 849392:tid 849403] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTpgMgr4yz2OQW0xreAwAA5gk"]
[Thu Jul 30 13:10:46.791837 2026] [security2:error] [pid 849392:tid 849620] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTpgMgr4yz2OQW0xreAwAA5gk"]
[Thu Jul 30 13:10:47.074833 2026] [security2:error] [pid 849392:tid 849525] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/media.php"] [unique_id "amuTpwMgr4yz2OQW0xreCQAAAIc"]
[Thu Jul 30 13:10:47.074950 2026] [security2:error] [pid 849392:tid 849525] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/media.php"] [unique_id "amuTpwMgr4yz2OQW0xreCQAAAIc"]
[Thu Jul 30 13:10:47.400899 2026] [security2:error] [pid 849392:tid 849574] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/images.php"] [unique_id "amuTpwMgr4yz2OQW0xreCgAAALg"]
[Thu Jul 30 13:10:47.401036 2026] [security2:error] [pid 849392:tid 849574] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/images.php"] [unique_id "amuTpwMgr4yz2OQW0xreCgAAALg"]
[Thu Jul 30 13:10:47.608226 2026] [security2:error] [pid 849392:tid 849610] [client 20.63.98.115:49803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuTpwMgr4yz2OQW0xreCwAAANw"]
[Thu Jul 30 13:10:47.704150 2026] [security2:error] [pid 849392:tid 849647] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/gecko.php"] [unique_id "amuTpwMgr4yz2OQW0xreDAAAAQE"]
[Thu Jul 30 13:10:47.704266 2026] [security2:error] [pid 849392:tid 849647] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/gecko.php"] [unique_id "amuTpwMgr4yz2OQW0xreDAAAAQE"]
[Thu Jul 30 13:10:47.808651 2026] [security2:error] [pid 849392:tid 849412] [remote 62.210.185.4:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amuTpwMgr4yz2OQW0xreDQAA4hI"]
[Thu Jul 30 13:10:47.823087 2026] [core:notice] [pid 849392:tid 849598] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:47.847247 2026] [security2:error] [pid 849392:tid 849649] [client 158.158.32.229:24312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/ops.php"] [unique_id "amuTpwMgr4yz2OQW0xreEQAAAQM"]
[Thu Jul 30 13:10:47.847345 2026] [security2:error] [pid 849392:tid 849649] [client 158.158.32.229:24312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/ops.php"] [unique_id "amuTpwMgr4yz2OQW0xreEQAAAQM"]
[Thu Jul 30 13:10:48.012428 2026] [security2:error] [pid 849392:tid 849639] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/82.php"] [unique_id "amuTqAMgr4yz2OQW0xreFgAAAPk"]
[Thu Jul 30 13:10:48.012542 2026] [security2:error] [pid 849392:tid 849639] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/82.php"] [unique_id "amuTqAMgr4yz2OQW0xreFgAAAPk"]
[Thu Jul 30 13:10:48.310145 2026] [security2:error] [pid 849392:tid 849624] [client 179.64.21.229:58187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTqAMgr4yz2OQW0xreFwAAAOo"]
[Thu Jul 30 13:10:48.313955 2026] [security2:error] [pid 849392:tid 849624] [client 179.64.21.229:58187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTqAMgr4yz2OQW0xreFwAAAOo"]
[Thu Jul 30 13:10:48.338356 2026] [security2:error] [pid 849392:tid 849606] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/xstelth.php"] [unique_id "amuTqAMgr4yz2OQW0xreGAAAANg"]
[Thu Jul 30 13:10:48.338456 2026] [security2:error] [pid 849392:tid 849606] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/xstelth.php"] [unique_id "amuTqAMgr4yz2OQW0xreGAAAANg"]
[Thu Jul 30 13:10:48.348864 2026] [security2:error] [pid 849392:tid 849418] [remote 97.74.87.194:46508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-login.php"] [unique_id "amuTqAMgr4yz2OQW0xreGQAAzRg"]
[Thu Jul 30 13:10:48.660391 2026] [security2:error] [pid 849392:tid 849622] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/xp.php"] [unique_id "amuTqAMgr4yz2OQW0xreHgAAAOg"]
[Thu Jul 30 13:10:48.660510 2026] [security2:error] [pid 849392:tid 849622] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/xp.php"] [unique_id "amuTqAMgr4yz2OQW0xreHgAAAOg"]
[Thu Jul 30 13:10:48.981472 2026] [security2:error] [pid 849392:tid 849591] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/admin.php"] [unique_id "amuTqAMgr4yz2OQW0xreHwAAAMk"]
[Thu Jul 30 13:10:48.981619 2026] [security2:error] [pid 849392:tid 849591] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/admin.php"] [unique_id "amuTqAMgr4yz2OQW0xreHwAAAMk"]
[Thu Jul 30 13:10:48.985826 2026] [security2:error] [pid 849392:tid 849638] [client 158.158.32.229:49357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/mac.php"] [unique_id "amuTqAMgr4yz2OQW0xreIAAAAPg"]
[Thu Jul 30 13:10:48.985921 2026] [security2:error] [pid 849392:tid 849638] [client 158.158.32.229:49357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/mac.php"] [unique_id "amuTqAMgr4yz2OQW0xreIAAAAPg"]
[Thu Jul 30 13:10:49.192107 2026] [security2:error] [pid 849392:tid 849629] [client 20.63.98.115:9291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/content.php"] [unique_id "amuTqQMgr4yz2OQW0xreIgAAAO8"]
[Thu Jul 30 13:10:49.288159 2026] [security2:error] [pid 849392:tid 849603] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/adminner.php"] [unique_id "amuTqQMgr4yz2OQW0xreJAAAANU"]
[Thu Jul 30 13:10:49.288270 2026] [security2:error] [pid 849392:tid 849603] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/adminner.php"] [unique_id "amuTqQMgr4yz2OQW0xreJAAAANU"]
[Thu Jul 30 13:10:49.590493 2026] [security2:error] [pid 849392:tid 849567] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/a.php"] [unique_id "amuTqQMgr4yz2OQW0xreJwAAALE"]
[Thu Jul 30 13:10:49.590602 2026] [security2:error] [pid 849392:tid 849567] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/a.php"] [unique_id "amuTqQMgr4yz2OQW0xreJwAAALE"]
[Thu Jul 30 13:10:49.931610 2026] [security2:error] [pid 849392:tid 849543] [client 20.63.98.115:50102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/.well-known.php"] [unique_id "amuTqQMgr4yz2OQW0xreKQAAAJk"]
[Thu Jul 30 13:10:50.531626 2026] [autoindex:error] [pid 849392:tid 849541] [client 158.158.32.229:24298] AH01276: Cannot serve directory /home1/oojhflte/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:10:50.532387 2026] [security2:error] [pid 849392:tid 849541] [client 158.158.32.229:24298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.alseermarine.com"] [uri "/cgi-sys/403.html"] [unique_id "amuTqgMgr4yz2OQW0xreMAAAAJc"]
[Thu Jul 30 13:10:50.554702 2026] [security2:error] [pid 849392:tid 849630] [client 77.83.36.161:14935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuTqgMgr4yz2OQW0xreLwAAAPA"]
[Thu Jul 30 13:10:50.802961 2026] [security2:error] [pid 849392:tid 849570] [client 158.158.32.229:24298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/pucci.php"] [unique_id "amuTqgMgr4yz2OQW0xreMgAAALQ"]
[Thu Jul 30 13:10:50.803082 2026] [security2:error] [pid 849392:tid 849570] [client 158.158.32.229:24298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/pucci.php"] [unique_id "amuTqgMgr4yz2OQW0xreMgAAALQ"]
[Thu Jul 30 13:10:50.889680 2026] [security2:error] [pid 849392:tid 849559] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/k.php"] [unique_id "amuTqgMgr4yz2OQW0xreMwAAAKk"]
[Thu Jul 30 13:10:50.889785 2026] [security2:error] [pid 849392:tid 849559] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/k.php"] [unique_id "amuTqgMgr4yz2OQW0xreMwAAAKk"]
[Thu Jul 30 13:10:51.115219 2026] [security2:error] [pid 849392:tid 849636] [client 77.83.36.161:15430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuTqwMgr4yz2OQW0xreNwAAAPY"]
[Thu Jul 30 13:10:51.213533 2026] [security2:error] [pid 849392:tid 849614] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/222.php"] [unique_id "amuTqwMgr4yz2OQW0xreOAAAAOA"]
[Thu Jul 30 13:10:51.213676 2026] [security2:error] [pid 849392:tid 849614] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/222.php"] [unique_id "amuTqwMgr4yz2OQW0xreOAAAAOA"]
[Thu Jul 30 13:10:51.488223 2026] [security2:error] [pid 849392:tid 849525] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTqgMgr4yz2OQW0xreNgAAAIc"]
[Thu Jul 30 13:10:51.533829 2026] [security2:error] [pid 849392:tid 849576] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/mac.php"] [unique_id "amuTqwMgr4yz2OQW0xreOQAAALo"]
[Thu Jul 30 13:10:51.533927 2026] [security2:error] [pid 849392:tid 849576] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/mac.php"] [unique_id "amuTqwMgr4yz2OQW0xreOQAAALo"]
[Thu Jul 30 13:10:51.700338 2026] [security2:error] [pid 849392:tid 849624] [client 77.83.36.161:15779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuTqwMgr4yz2OQW0xreOgAAAOo"]
[Thu Jul 30 13:10:51.714363 2026] [security2:error] [pid 849392:tid 849627] [client 158.158.32.229:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuTqwMgr4yz2OQW0xrePAAAAO0"]
[Thu Jul 30 13:10:51.714453 2026] [security2:error] [pid 849392:tid 849627] [client 158.158.32.229:49874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuTqwMgr4yz2OQW0xrePAAAAO0"]
[Thu Jul 30 13:10:51.857573 2026] [security2:error] [pid 849392:tid 849558] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuTqwMgr4yz2OQW0xrePgAAAKg"]
[Thu Jul 30 13:10:51.956122 2026] [security2:error] [pid 849392:tid 849550] [client 128.140.106.114:26180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuTqwMgr4yz2OQW0xrePwAAAKA"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:10:52.036065 2026] [security2:error] [pid 849392:tid 849555] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/"] [unique_id "amuTrAMgr4yz2OQW0xreQAAAAKU"]
[Thu Jul 30 13:10:52.337842 2026] [security2:error] [pid 849392:tid 849523] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/ops.php"] [unique_id "amuTrAMgr4yz2OQW0xreQgAAAIU"]
[Thu Jul 30 13:10:52.337955 2026] [security2:error] [pid 849392:tid 849523] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/ops.php"] [unique_id "amuTrAMgr4yz2OQW0xreQgAAAIU"]
[Thu Jul 30 13:10:52.496953 2026] [security2:error] [pid 849392:tid 849551] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/8.php"] [unique_id "amuTrAMgr4yz2OQW0xreRQAAAKE"]
[Thu Jul 30 13:10:52.497095 2026] [security2:error] [pid 849392:tid 849551] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/8.php"] [unique_id "amuTrAMgr4yz2OQW0xreRQAAAKE"]
[Thu Jul 30 13:10:52.520379 2026] [security2:error] [pid 849392:tid 849580] [client 20.63.98.115:36609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuTrAMgr4yz2OQW0xreQQAAAL4"]
[Thu Jul 30 13:10:52.812008 2026] [security2:error] [pid 849392:tid 849546] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/FWAZ.php"] [unique_id "amuTrAMgr4yz2OQW0xreSAAAAJw"]
[Thu Jul 30 13:10:52.812136 2026] [security2:error] [pid 849392:tid 849546] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/FWAZ.php"] [unique_id "amuTrAMgr4yz2OQW0xreSAAAAJw"]
[Thu Jul 30 13:10:52.853624 2026] [core:notice] [pid 849392:tid 849407] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:53.149441 2026] [security2:error] [pid 849392:tid 849602] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/biufile.php"] [unique_id "amuTrQMgr4yz2OQW0xreSgAAANQ"]
[Thu Jul 30 13:10:53.149559 2026] [security2:error] [pid 849392:tid 849602] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/biufile.php"] [unique_id "amuTrQMgr4yz2OQW0xreSgAAANQ"]
[Thu Jul 30 13:10:53.284157 2026] [core:notice] [pid 849392:tid 849592] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:53.288424 2026] [security2:error] [pid 849392:tid 849592] [client 128.140.106.114:26190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuTrQMgr4yz2OQW0xreSwAAAMo"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:10:53.455128 2026] [security2:error] [pid 849392:tid 849569] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/coffexium.php"] [unique_id "amuTrQMgr4yz2OQW0xreTAAAALM"]
[Thu Jul 30 13:10:53.455249 2026] [security2:error] [pid 849392:tid 849569] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/coffexium.php"] [unique_id "amuTrQMgr4yz2OQW0xreTAAAALM"]
[Thu Jul 30 13:10:53.498343 2026] [security2:error] [pid 849392:tid 849533] [client 20.63.98.115:9240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/themes/twenty/twenty.php"] [unique_id "amuTrQMgr4yz2OQW0xreTQAAAI8"]
[Thu Jul 30 13:10:53.681190 2026] [security2:error] [pid 849392:tid 849529] [client 128.140.106.114:26206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuTrQMgr4yz2OQW0xreTgAAAIs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:10:53.767255 2026] [security2:error] [pid 849392:tid 849584] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/simple.php"] [unique_id "amuTrQMgr4yz2OQW0xreTwAAAMI"]
[Thu Jul 30 13:10:53.767419 2026] [security2:error] [pid 849392:tid 849584] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/simple.php"] [unique_id "amuTrQMgr4yz2OQW0xreTwAAAMI"]
[Thu Jul 30 13:10:53.807903 2026] [security2:error] [pid 849392:tid 849561] [client 158.158.32.229:43267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/8.php"] [unique_id "amuTrQMgr4yz2OQW0xreUAAAAKs"]
[Thu Jul 30 13:10:53.808045 2026] [security2:error] [pid 849392:tid 849561] [client 158.158.32.229:43267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/8.php"] [unique_id "amuTrQMgr4yz2OQW0xreUAAAAKs"]
[Thu Jul 30 13:10:54.062352 2026] [security2:error] [pid 849392:tid 849649] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/fpwch.php"] [unique_id "amuTrgMgr4yz2OQW0xreUwAAAQM"]
[Thu Jul 30 13:10:54.062453 2026] [security2:error] [pid 849392:tid 849649] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/fpwch.php"] [unique_id "amuTrgMgr4yz2OQW0xreUwAAAQM"]
[Thu Jul 30 13:10:54.368431 2026] [security2:error] [pid 849392:tid 849595] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/dex.php"] [unique_id "amuTrgMgr4yz2OQW0xreVQAAAM0"]
[Thu Jul 30 13:10:54.368545 2026] [security2:error] [pid 849392:tid 849595] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/dex.php"] [unique_id "amuTrgMgr4yz2OQW0xreVQAAAM0"]
[Thu Jul 30 13:10:54.599150 2026] [security2:error] [pid 849392:tid 849598] [client 20.63.98.115:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuTrgMgr4yz2OQW0xreVgAAANA"]
[Thu Jul 30 13:10:54.679202 2026] [security2:error] [pid 849392:tid 849624] [client 20.100.203.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuTrgMgr4yz2OQW0xreVwAAAOo"]
[Thu Jul 30 13:10:54.679326 2026] [security2:error] [pid 849392:tid 849624] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuTrgMgr4yz2OQW0xreVwAAAOo"]
[Thu Jul 30 13:10:54.679470 2026] [security2:error] [pid 849392:tid 849624] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuTrgMgr4yz2OQW0xreVwAAAOo"]
[Thu Jul 30 13:10:54.747313 2026] [security2:error] [pid 849392:tid 849639] [client 172.236.9.101:8755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTrgMgr4yz2OQW0xreVAAAAPk"]
[Thu Jul 30 13:10:54.973722 2026] [core:notice] [pid 849392:tid 849395] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:10:55.016723 2026] [security2:error] [pid 849392:tid 849600] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amuTrwMgr4yz2OQW0xreWgAAANI"]
[Thu Jul 30 13:10:55.171494 2026] [security2:error] [pid 849392:tid 849627] [client 158.158.32.229:24301] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.alseermarine.com"] [uri "/1.php"] [unique_id "amuTrwMgr4yz2OQW0xreWwAAAO0"]
[Thu Jul 30 13:10:55.171625 2026] [security2:error] [pid 849392:tid 849627] [client 158.158.32.229:24301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/1.php"] [unique_id "amuTrwMgr4yz2OQW0xreWwAAAO0"]
[Thu Jul 30 13:10:55.171755 2026] [security2:error] [pid 849392:tid 849627] [client 158.158.32.229:24301] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/1.php"] [unique_id "amuTrwMgr4yz2OQW0xreWwAAAO0"]
[Thu Jul 30 13:10:55.329716 2026] [security2:error] [pid 849392:tid 849530] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/config.json.php"] [unique_id "amuTrwMgr4yz2OQW0xreXwAAAIw"]
[Thu Jul 30 13:10:55.329840 2026] [security2:error] [pid 849392:tid 849530] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/config.json.php"] [unique_id "amuTrwMgr4yz2OQW0xreXwAAAIw"]
[Thu Jul 30 13:10:55.423613 2026] [security2:error] [pid 849392:tid 849606] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTrgMgr4yz2OQW0xreWAAA2HM"]
[Thu Jul 30 13:10:55.674735 2026] [security2:error] [pid 849392:tid 849548] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/k2.php"] [unique_id "amuTrwMgr4yz2OQW0xreYAAAAJ4"]
[Thu Jul 30 13:10:55.674861 2026] [security2:error] [pid 849392:tid 849548] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/k2.php"] [unique_id "amuTrwMgr4yz2OQW0xreYAAAAJ4"]
[Thu Jul 30 13:10:55.763093 2026] [security2:error] [pid 849392:tid 849603] [client 20.63.98.115:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuTrwMgr4yz2OQW0xreYQAAANU"]
[Thu Jul 30 13:10:55.979464 2026] [security2:error] [pid 849392:tid 849613] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/raw.php"] [unique_id "amuTrwMgr4yz2OQW0xreYgAAAN8"]
[Thu Jul 30 13:10:55.979584 2026] [security2:error] [pid 849392:tid 849613] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/raw.php"] [unique_id "amuTrwMgr4yz2OQW0xreYgAAAN8"]
[Thu Jul 30 13:10:56.714763 2026] [security2:error] [pid 849392:tid 849585] [client 172.236.9.101:17069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTsAMgr4yz2OQW0xreZgAAAMM"]
[Thu Jul 30 13:10:57.074234 2026] [security2:error] [pid 849392:tid 849524] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/wp.php"] [unique_id "amuTsQMgr4yz2OQW0xrebQAAAIY"]
[Thu Jul 30 13:10:57.074355 2026] [security2:error] [pid 849392:tid 849524] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/wp.php"] [unique_id "amuTsQMgr4yz2OQW0xrebQAAAIY"]
[Thu Jul 30 13:10:57.299071 2026] [security2:error] [pid 849392:tid 849569] [client 104.28.66.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuTsAMgr4yz2OQW0xreagAAALM"], referer: https://smoke-tfhk.com/product-category/iqos/page/2/
[Thu Jul 30 13:10:57.357851 2026] [security2:error] [pid 849392:tid 849619] [client 158.158.32.229:49873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/admin.php"] [unique_id "amuTsQMgr4yz2OQW0xrecQAAAOU"]
[Thu Jul 30 13:10:57.358033 2026] [security2:error] [pid 849392:tid 849619] [client 158.158.32.229:49873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/wp-content/admin.php"] [unique_id "amuTsQMgr4yz2OQW0xrecQAAAOU"]
[Thu Jul 30 13:10:57.382264 2026] [security2:error] [pid 849392:tid 849595] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/fffm.php"] [unique_id "amuTsQMgr4yz2OQW0xrecgAAAM0"]
[Thu Jul 30 13:10:57.382405 2026] [security2:error] [pid 849392:tid 849595] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/fffm.php"] [unique_id "amuTsQMgr4yz2OQW0xrecgAAAM0"]
[Thu Jul 30 13:10:57.687708 2026] [security2:error] [pid 849392:tid 849560] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/111.php"] [unique_id "amuTsQMgr4yz2OQW0xrefAAAAKo"]
[Thu Jul 30 13:10:57.687866 2026] [security2:error] [pid 849392:tid 849560] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/111.php"] [unique_id "amuTsQMgr4yz2OQW0xrefAAAAKo"]
[Thu Jul 30 13:10:57.783357 2026] [security2:error] [pid 849392:tid 849614] [client 172.236.9.101:3717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTsQMgr4yz2OQW0xrecAAAAOA"]
[Thu Jul 30 13:10:58.031097 2026] [security2:error] [pid 849392:tid 849568] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amuTsgMgr4yz2OQW0xrefgAAALI"]
[Thu Jul 30 13:10:58.048660 2026] [security2:error] [pid 849392:tid 849620] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTsQMgr4yz2OQW0xredQAAAOY"]
[Thu Jul 30 13:10:58.206477 2026] [security2:error] [pid 849392:tid 849627] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/ws.php"] [unique_id "amuTsgMgr4yz2OQW0xregAAAAO0"]
[Thu Jul 30 13:10:58.206562 2026] [security2:error] [pid 849392:tid 849627] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/ws.php"] [unique_id "amuTsgMgr4yz2OQW0xregAAAAO0"]
[Thu Jul 30 13:10:58.552560 2026] [security2:error] [pid 849392:tid 849572] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/coffee.php"] [unique_id "amuTsgMgr4yz2OQW0xreggAAALY"]
[Thu Jul 30 13:10:58.552706 2026] [security2:error] [pid 849392:tid 849572] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/coffee.php"] [unique_id "amuTsgMgr4yz2OQW0xreggAAALY"]
[Thu Jul 30 13:10:58.673942 2026] [security2:error] [pid 849392:tid 849526] [client 179.64.21.229:11063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTsgMgr4yz2OQW0xrehAAAAIg"]
[Thu Jul 30 13:10:58.685712 2026] [security2:error] [pid 849392:tid 849526] [client 179.64.21.229:11063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTsgMgr4yz2OQW0xrehAAAAIg"]
[Thu Jul 30 13:10:58.863022 2026] [security2:error] [pid 849392:tid 849552] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/goods.php"] [unique_id "amuTsgMgr4yz2OQW0xreiQAAAKI"]
[Thu Jul 30 13:10:58.863140 2026] [security2:error] [pid 849392:tid 849552] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/goods.php"] [unique_id "amuTsgMgr4yz2OQW0xreiQAAAKI"]
[Thu Jul 30 13:10:59.036850 2026] [security2:error] [pid 849392:tid 849471] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTswMgr4yz2OQW0xreigAAmU0"]
[Thu Jul 30 13:10:59.037046 2026] [security2:error] [pid 849392:tid 849543] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTswMgr4yz2OQW0xreigAAmU0"]
[Thu Jul 30 13:10:59.170404 2026] [security2:error] [pid 849392:tid 849562] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuTswMgr4yz2OQW0xreiwAAAKw"]
[Thu Jul 30 13:10:59.170516 2026] [security2:error] [pid 849392:tid 849562] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuTswMgr4yz2OQW0xreiwAAAKw"]
[Thu Jul 30 13:10:59.391842 2026] [security2:error] [pid 849392:tid 849626] [client 158.158.32.229:24296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuTswMgr4yz2OQW0xrejQAAAOw"]
[Thu Jul 30 13:10:59.392002 2026] [security2:error] [pid 849392:tid 849626] [client 158.158.32.229:24296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuTswMgr4yz2OQW0xrejQAAAOw"]
[Thu Jul 30 13:10:59.503216 2026] [security2:error] [pid 849392:tid 849585] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuTswMgr4yz2OQW0xrejwAAAMM"]
[Thu Jul 30 13:10:59.503334 2026] [security2:error] [pid 849392:tid 849585] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuTswMgr4yz2OQW0xrejwAAAMM"]
[Thu Jul 30 13:10:59.834186 2026] [security2:error] [pid 849392:tid 849538] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/admin.php"] [unique_id "amuTswMgr4yz2OQW0xrekwAAAJQ"]
[Thu Jul 30 13:10:59.834324 2026] [security2:error] [pid 849392:tid 849538] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/admin.php"] [unique_id "amuTswMgr4yz2OQW0xrekwAAAJQ"]
[Thu Jul 30 13:11:00.151450 2026] [security2:error] [pid 849392:tid 849558] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/inputs.php"] [unique_id "amuTtAMgr4yz2OQW0xrelwAAAKg"]
[Thu Jul 30 13:11:00.151637 2026] [security2:error] [pid 849392:tid 849558] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/inputs.php"] [unique_id "amuTtAMgr4yz2OQW0xrelwAAAKg"]
[Thu Jul 30 13:11:00.469487 2026] [security2:error] [pid 849392:tid 849575] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/inputs.php"] [unique_id "amuTtAMgr4yz2OQW0xremAAAALk"]
[Thu Jul 30 13:11:00.469599 2026] [security2:error] [pid 849392:tid 849575] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/inputs.php"] [unique_id "amuTtAMgr4yz2OQW0xremAAAALk"]
[Thu Jul 30 13:11:00.500915 2026] [security2:error] [pid 849392:tid 849584] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTswMgr4yz2OQW0xrelgAAAMI"]
[Thu Jul 30 13:11:00.805145 2026] [security2:error] [pid 849392:tid 849627] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/adminfuns.php"] [unique_id "amuTtAMgr4yz2OQW0xremgAAAO0"]
[Thu Jul 30 13:11:00.805268 2026] [security2:error] [pid 849392:tid 849627] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/adminfuns.php"] [unique_id "amuTtAMgr4yz2OQW0xremgAAAO0"]
[Thu Jul 30 13:11:01.118797 2026] [security2:error] [pid 849392:tid 849606] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/404.php"] [unique_id "amuTtQMgr4yz2OQW0xrengAAANg"]
[Thu Jul 30 13:11:01.118946 2026] [security2:error] [pid 849392:tid 849606] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/404.php"] [unique_id "amuTtQMgr4yz2OQW0xrengAAANg"]
[Thu Jul 30 13:11:01.437382 2026] [security2:error] [pid 849392:tid 849637] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/xxx.php"] [unique_id "amuTtQMgr4yz2OQW0xrenwAAAPc"]
[Thu Jul 30 13:11:01.437506 2026] [security2:error] [pid 849392:tid 849637] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/xxx.php"] [unique_id "amuTtQMgr4yz2OQW0xrenwAAAPc"]
[Thu Jul 30 13:11:02.127174 2026] [security2:error] [pid 849392:tid 849552] [client 158.158.32.229:24293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/222.php"] [unique_id "amuTtgMgr4yz2OQW0xrepAAAAKI"]
[Thu Jul 30 13:11:02.127321 2026] [security2:error] [pid 849392:tid 849552] [client 158.158.32.229:24293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/222.php"] [unique_id "amuTtgMgr4yz2OQW0xrepAAAAKI"]
[Thu Jul 30 13:11:02.366171 2026] [security2:error] [pid 849392:tid 849528] [client 20.63.98.115:45631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuTtgMgr4yz2OQW0xreqQAAAIo"]
[Thu Jul 30 13:11:02.758659 2026] [security2:error] [pid 849392:tid 849642] [client 172.236.9.101:12704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTtgMgr4yz2OQW0xreqAAAAPw"]
[Thu Jul 30 13:11:02.771887 2026] [proxy:error] [pid 849392:tid 849574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:02.772052 2026] [proxy_http:error] [pid 849392:tid 849574] [client 52.202.41.153:45917] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:02.772630 2026] [proxy:error] [pid 849392:tid 849574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:02.772673 2026] [proxy_http:error] [pid 849392:tid 849574] [client 52.202.41.153:45917] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:02.807241 2026] [proxy:error] [pid 849392:tid 849557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:02.807333 2026] [proxy_http:error] [pid 849392:tid 849557] [client 54.87.222.253:28432] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:02.807994 2026] [proxy:error] [pid 849392:tid 849557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:02.808049 2026] [proxy_http:error] [pid 849392:tid 849557] [client 54.87.222.253:28432] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:03.136677 2026] [security2:error] [pid 849392:tid 849623] [client 66.249.68.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.themushroom.online"] [uri "/index.php"] [unique_id "amuTtQMgr4yz2OQW0xrenQAAAOk"]
[Thu Jul 30 13:11:03.490844 2026] [core:notice] [pid 849392:tid 849630] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:03.693449 2026] [security2:error] [pid 849392:tid 849647] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/classwithtostring.php"] [unique_id "amuTtwMgr4yz2OQW0xrexAAAAQE"]
[Thu Jul 30 13:11:03.693560 2026] [security2:error] [pid 849392:tid 849647] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/classwithtostring.php"] [unique_id "amuTtwMgr4yz2OQW0xrexAAAAQE"]
[Thu Jul 30 13:11:03.772120 2026] [security2:error] [pid 849392:tid 849575] [client 172.236.9.101:42003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTtwMgr4yz2OQW0xrevwAAALk"]
[Thu Jul 30 13:11:04.024553 2026] [security2:error] [pid 849392:tid 849548] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/234ff.php"] [unique_id "amuTuAMgr4yz2OQW0xrezAAAAJ4"]
[Thu Jul 30 13:11:04.024664 2026] [security2:error] [pid 849392:tid 849548] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/234ff.php"] [unique_id "amuTuAMgr4yz2OQW0xrezAAAAJ4"]
[Thu Jul 30 13:11:04.051147 2026] [security2:error] [pid 849392:tid 849636] [client 158.158.32.229:49904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/cgi-bin/index.php"] [unique_id "amuTuAMgr4yz2OQW0xrezQAAAPY"]
[Thu Jul 30 13:11:04.051273 2026] [security2:error] [pid 849392:tid 849636] [client 158.158.32.229:49904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/cgi-bin/index.php"] [unique_id "amuTuAMgr4yz2OQW0xrezQAAAPY"]
[Thu Jul 30 13:11:04.373181 2026] [security2:error] [pid 849392:tid 849592] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/133.php"] [unique_id "amuTuAMgr4yz2OQW0xrezwAAAMo"]
[Thu Jul 30 13:11:04.373301 2026] [security2:error] [pid 849392:tid 849592] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/133.php"] [unique_id "amuTuAMgr4yz2OQW0xrezwAAAMo"]
[Thu Jul 30 13:11:04.542124 2026] [core:notice] [pid 849392:tid 849611] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:04.546133 2026] [security2:error] [pid 849392:tid 849543] [client 20.63.98.115:38603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "amuTuAMgr4yz2OQW0xre2wAAAJk"]
[Thu Jul 30 13:11:04.704268 2026] [security2:error] [pid 849392:tid 849585] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/wp-ws68.php"] [unique_id "amuTuAMgr4yz2OQW0xre3wAAAMM"]
[Thu Jul 30 13:11:04.704421 2026] [security2:error] [pid 849392:tid 849585] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/wp-ws68.php"] [unique_id "amuTuAMgr4yz2OQW0xre3wAAAMM"]
[Thu Jul 30 13:11:05.016545 2026] [security2:error] [pid 849392:tid 849582] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/mgrr.php"] [unique_id "amuTuQMgr4yz2OQW0xre4AAAAMA"]
[Thu Jul 30 13:11:05.016673 2026] [security2:error] [pid 849392:tid 849582] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/mgrr.php"] [unique_id "amuTuQMgr4yz2OQW0xre4AAAAMA"]
[Thu Jul 30 13:11:05.098735 2026] [proxy:error] [pid 849392:tid 849524] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:05.098800 2026] [proxy_http:error] [pid 849392:tid 849524] [client 18.211.55.47:24024] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:05.099394 2026] [proxy:error] [pid 849392:tid 849524] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:05.099441 2026] [proxy_http:error] [pid 849392:tid 849524] [client 18.211.55.47:24024] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:05.114346 2026] [proxy:error] [pid 849392:tid 849641] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:05.114424 2026] [proxy_http:error] [pid 849392:tid 849641] [client 18.211.55.47:63184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:05.114986 2026] [proxy:error] [pid 849392:tid 849641] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:05.115035 2026] [proxy_http:error] [pid 849392:tid 849641] [client 18.211.55.47:63184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:05.329707 2026] [security2:error] [pid 849392:tid 849538] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/55.php"] [unique_id "amuTuQMgr4yz2OQW0xre7wAAAJQ"]
[Thu Jul 30 13:11:05.329876 2026] [security2:error] [pid 849392:tid 849538] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.germanyvisasupportcenterislamabad.website"] [uri "/55.php"] [unique_id "amuTuQMgr4yz2OQW0xre7wAAAJQ"]
[Thu Jul 30 13:11:05.625192 2026] [security2:error] [pid 849392:tid 849599] [client 20.63.98.115:45596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/files.php"] [unique_id "amuTuQMgr4yz2OQW0xre8gAAANE"]
[Thu Jul 30 13:11:05.733818 2026] [security2:error] [pid 849392:tid 849616] [client 172.236.9.101:1528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTuQMgr4yz2OQW0xre7gAAAOI"]
[Thu Jul 30 13:11:06.282721 2026] [security2:error] [pid 849392:tid 849558] [client 43.159.143.139:35270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.143.159.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif"] [unique_id "amuTugMgr4yz2OQW0xre-gAAAKg"], referer: https://ejournalugj.com/index_php/Responsif
[Thu Jul 30 13:11:06.423083 2026] [proxy:error] [pid 849392:tid 849523] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:06.423166 2026] [proxy_http:error] [pid 849392:tid 849523] [client 44.216.125.112:38014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:06.423735 2026] [proxy:error] [pid 849392:tid 849523] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:06.423779 2026] [proxy_http:error] [pid 849392:tid 849523] [client 44.216.125.112:38014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:06.447288 2026] [proxy:error] [pid 849392:tid 849551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:06.447353 2026] [proxy_http:error] [pid 849392:tid 849551] [client 44.216.125.112:13821] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:06.447913 2026] [proxy:error] [pid 849392:tid 849551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:06.447958 2026] [proxy_http:error] [pid 849392:tid 849551] [client 44.216.125.112:13821] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:06.680836 2026] [autoindex:error] [pid 849392:tid 849612] [client 158.158.32.229:27705] AH01276: Cannot serve directory /home1/oojhflte/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:11:06.681490 2026] [security2:error] [pid 849392:tid 849612] [client 158.158.32.229:27705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.alseermarine.com"] [uri "/cgi-sys/403.html"] [unique_id "amuTugMgr4yz2OQW0xrfBgAAAN4"]
[Thu Jul 30 13:11:06.988116 2026] [autoindex:error] [pid 849392:tid 849638] [client 158.158.32.229:27705] AH01276: Cannot serve directory /home1/oojhflte/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:11:06.988731 2026] [security2:error] [pid 849392:tid 849638] [client 158.158.32.229:27705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.alseermarine.com"] [uri "/cgi-sys/403.html"] [unique_id "amuTugMgr4yz2OQW0xrfBwAAAPg"]
[Thu Jul 30 13:11:07.274155 2026] [autoindex:error] [pid 849392:tid 849544] [client 158.158.32.229:27705] AH01276: Cannot serve directory /home1/oojhflte/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:11:07.274839 2026] [security2:error] [pid 849392:tid 849544] [client 158.158.32.229:27705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.alseermarine.com"] [uri "/cgi-sys/403.html"] [unique_id "amuTuwMgr4yz2OQW0xrfCAAAAJo"]
[Thu Jul 30 13:11:07.307744 2026] [security2:error] [pid 849392:tid 849562] [client 20.63.98.115:9341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/Text/index.php"] [unique_id "amuTuwMgr4yz2OQW0xrfCQAAAKw"]
[Thu Jul 30 13:11:07.551768 2026] [security2:error] [pid 849392:tid 849632] [client 158.158.32.229:27705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/raw.php"] [unique_id "amuTuwMgr4yz2OQW0xrfDwAAAPI"]
[Thu Jul 30 13:11:07.551875 2026] [security2:error] [pid 849392:tid 849632] [client 158.158.32.229:27705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.alseermarine.com"] [uri "/raw.php"] [unique_id "amuTuwMgr4yz2OQW0xrfDwAAAPI"]
[Thu Jul 30 13:11:07.830947 2026] [core:notice] [pid 849392:tid 849427] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:07.864623 2026] [core:notice] [pid 849392:tid 849445] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:08.872521 2026] [core:notice] [pid 849392:tid 849451] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:09.163439 2026] [security2:error] [pid 849392:tid 849564] [client 179.64.21.229:39341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTvQMgr4yz2OQW0xrfHAAAAK4"]
[Thu Jul 30 13:11:09.163576 2026] [security2:error] [pid 849392:tid 849564] [client 179.64.21.229:39341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTvQMgr4yz2OQW0xrfHAAAAK4"]
[Thu Jul 30 13:11:09.549460 2026] [security2:error] [pid 849392:tid 849439] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTvQMgr4yz2OQW0xrfHgAAvy0"]
[Thu Jul 30 13:11:09.549632 2026] [security2:error] [pid 849392:tid 849581] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTvQMgr4yz2OQW0xrfHgAAvy0"]
[Thu Jul 30 13:11:10.797644 2026] [security2:error] [pid 849392:tid 849550] [client 20.63.98.115:53330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuTvgMgr4yz2OQW0xrfJgAAAKA"]
[Thu Jul 30 13:11:11.657651 2026] [security2:error] [pid 849392:tid 849575] [client 20.63.98.115:46612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuTvwMgr4yz2OQW0xrfKQAAALk"]
[Thu Jul 30 13:11:12.434426 2026] [security2:error] [pid 849392:tid 849537] [client 20.63.98.115:1649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ws.php"] [unique_id "amuTwAMgr4yz2OQW0xrfKgAAAJM"]
[Thu Jul 30 13:11:14.319756 2026] [security2:error] [pid 849392:tid 849612] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTwQMgr4yz2OQW0xrfLgAAAN4"]
[Thu Jul 30 13:11:14.571133 2026] [security2:error] [pid 849392:tid 849456] [remote 103.221.222.68:37026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.222.221.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-468361c2.glb.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuTwgMgr4yz2OQW0xrfLwAAzj4"]
[Thu Jul 30 13:11:14.682175 2026] [security2:error] [pid 849392:tid 849617] [client 20.63.98.115:38598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-config-sample.php"] [unique_id "amuTwgMgr4yz2OQW0xrfMQAAAOM"]
[Thu Jul 30 13:11:15.729682 2026] [security2:error] [pid 849392:tid 849535] [client 172.236.9.101:21636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTwwMgr4yz2OQW0xrfMgAAAJE"]
[Thu Jul 30 13:11:16.039162 2026] [security2:error] [pid 849392:tid 849593] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTwwMgr4yz2OQW0xrfMwAAy1E"]
[Thu Jul 30 13:11:16.067095 2026] [core:notice] [pid 849392:tid 849449] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:16.486211 2026] [core:notice] [pid 849392:tid 849459] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:16.679858 2026] [security2:error] [pid 849392:tid 849594] [client 43.134.68.29:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.68.134.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serverkr.com"] [uri "/board/list.php"] [unique_id "amuTxAMgr4yz2OQW0xrfOQAAAMw"]
[Thu Jul 30 13:11:16.809871 2026] [core:notice] [pid 849392:tid 849467] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:16.989412 2026] [security2:error] [pid 849392:tid 849632] [client 20.63.98.115:46812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wso.php"] [unique_id "amuTxAMgr4yz2OQW0xrfOwAAAPI"]
[Thu Jul 30 13:11:17.393254 2026] [security2:error] [pid 849392:tid 849589] [client 185.191.171.12:56432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/02/idoso-e-morto-a-tiros-ao-retornar-da-igreja-na-paraiba/"] [unique_id "amuTxQMgr4yz2OQW0xrfPAAAAMc"]
[Thu Jul 30 13:11:17.393399 2026] [security2:error] [pid 849392:tid 849589] [client 185.191.171.12:56432] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/02/idoso-e-morto-a-tiros-ao-retornar-da-igreja-na-paraiba/"] [unique_id "amuTxQMgr4yz2OQW0xrfPAAAAMc"]
[Thu Jul 30 13:11:18.018441 2026] [security2:error] [pid 849392:tid 849619] [client 20.63.98.115:11081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/sh.php"] [unique_id "amuTxgMgr4yz2OQW0xrfQAAAAOU"]
[Thu Jul 30 13:11:18.111533 2026] [security2:error] [pid 849392:tid 849464] [remote 47.128.27.95:45708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-13-retro-he-got-game-2018/"] [unique_id "amuTxgMgr4yz2OQW0xrfQQAA7kY"]
[Thu Jul 30 13:11:18.843199 2026] [security2:error] [pid 849392:tid 849541] [client 20.63.98.115:46819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/send.php"] [unique_id "amuTxgMgr4yz2OQW0xrfQgAAAJc"]
[Thu Jul 30 13:11:19.463892 2026] [security2:error] [pid 849392:tid 849437] [remote 57.141.0.50:58292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/589953950/feed/rss2/"] [unique_id "amuTxwMgr4yz2OQW0xrfSQAAqis"]
[Thu Jul 30 13:11:19.617031 2026] [security2:error] [pid 849392:tid 849559] [client 179.64.21.229:14593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTxwMgr4yz2OQW0xrfSgAAAKk"]
[Thu Jul 30 13:11:19.624601 2026] [security2:error] [pid 849392:tid 849559] [client 179.64.21.229:14593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuTxwMgr4yz2OQW0xrfSgAAAKk"]
[Thu Jul 30 13:11:19.922123 2026] [security2:error] [pid 849392:tid 849599] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTxwMgr4yz2OQW0xrfRQAAANE"]
[Thu Jul 30 13:11:20.348563 2026] [security2:error] [pid 849392:tid 849481] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTyAMgr4yz2OQW0xrfSwAA9Vc"]
[Thu Jul 30 13:11:20.348712 2026] [security2:error] [pid 849392:tid 849635] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuTyAMgr4yz2OQW0xrfSwAA9Vc"]
[Thu Jul 30 13:11:21.060928 2026] [core:notice] [pid 849392:tid 849490] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:21.565613 2026] [security2:error] [pid 849392:tid 849547] [client 20.63.98.115:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/ds.php"] [unique_id "amuTyQMgr4yz2OQW0xrfXQAAAJ0"]
[Thu Jul 30 13:11:21.628020 2026] [security2:error] [pid 849392:tid 849555] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTyQMgr4yz2OQW0xrfWAAAAKU"]
[Thu Jul 30 13:11:22.563260 2026] [security2:error] [pid 849392:tid 849572] [client 20.63.98.115:1607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wso112233.php"] [unique_id "amuTygMgr4yz2OQW0xrfYQAAALY"]
[Thu Jul 30 13:11:22.715364 2026] [security2:error] [pid 849392:tid 849615] [client 172.236.9.101:14191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTygMgr4yz2OQW0xrfYAAAAOE"]
[Thu Jul 30 13:11:22.980643 2026] [core:notice] [pid 849392:tid 849603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:23.562105 2026] [core:notice] [pid 849392:tid 849604] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:23.666131 2026] [security2:error] [pid 849392:tid 849566] [client 20.63.98.115:1129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "amuTywMgr4yz2OQW0xrfawAAALA"]
[Thu Jul 30 13:11:23.980841 2026] [core:notice] [pid 849392:tid 849489] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:24.213478 2026] [security2:error] [pid 849392:tid 849563] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTywMgr4yz2OQW0xrfagAAAK0"]
[Thu Jul 30 13:11:25.340119 2026] [security2:error] [pid 849392:tid 849617] [client 47.128.30.125:41970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "exploringchanges.com"] [uri "/robots.txt"] [unique_id "amuTzQMgr4yz2OQW0xrfcgAAAOM"]
[Thu Jul 30 13:11:25.754344 2026] [security2:error] [pid 849392:tid 849606] [client 172.236.9.101:23849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuTzQMgr4yz2OQW0xrfcQAAANg"]
[Thu Jul 30 13:11:25.993441 2026] [security2:error] [pid 849392:tid 849536] [client 172.59.129.244:1236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuTzQMgr4yz2OQW0xrfgQAAAJI"], referer: http://pkf.jo
[Thu Jul 30 13:11:26.163576 2026] [security2:error] [pid 849392:tid 849562] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTzQMgr4yz2OQW0xrffQAAAKw"]
[Thu Jul 30 13:11:26.183372 2026] [security2:error] [pid 849392:tid 849626] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuTzQMgr4yz2OQW0xrfgAAAAOw"]
[Thu Jul 30 13:11:26.558896 2026] [security2:error] [pid 849392:tid 849557] [client 184.54.51.113:35772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuTzgMgr4yz2OQW0xrfhwAAAKc"], referer: http://pkf.jo
[Thu Jul 30 13:11:26.685925 2026] [core:notice] [pid 849392:tid 849608] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:26.734412 2026] [security2:error] [pid 849392:tid 849546] [client 128.140.157.55:62282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuTzgMgr4yz2OQW0xrfiAAAAJw"], referer: http://pkf.jo
[Thu Jul 30 13:11:26.827263 2026] [security2:error] [pid 849392:tid 849593] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuTzgMgr4yz2OQW0xrfhgAAy3c"]
[Thu Jul 30 13:11:28.089716 2026] [security2:error] [pid 849392:tid 849629] [client 66.249.73.98:50675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuTzwMgr4yz2OQW0xrflwAAAO8"]
[Thu Jul 30 13:11:28.481265 2026] [core:notice] [pid 849392:tid 849518] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:28.977600 2026] [core:notice] [pid 849392:tid 849605] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:30.062387 2026] [security2:error] [pid 849392:tid 849588] [client 185.191.171.19:20990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/24/aesa-preve-chuvas-dentro-da-media-historica-do-periodo-para-os-proximos-quatro-meses-na-paraiba/"] [unique_id "amuT0gMgr4yz2OQW0xrftwAAAMY"]
[Thu Jul 30 13:11:30.062543 2026] [security2:error] [pid 849392:tid 849588] [client 185.191.171.19:20990] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/24/aesa-preve-chuvas-dentro-da-media-historica-do-periodo-para-os-proximos-quatro-meses-na-paraiba/"] [unique_id "amuT0gMgr4yz2OQW0xrftwAAAMY"]
[Thu Jul 30 13:11:30.319620 2026] [security2:error] [pid 849392:tid 849596] [client 179.64.21.229:11140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT0gMgr4yz2OQW0xrfuwAAAM4"]
[Thu Jul 30 13:11:30.323340 2026] [security2:error] [pid 849392:tid 849596] [client 179.64.21.229:11140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT0gMgr4yz2OQW0xrfuwAAAM4"]
[Thu Jul 30 13:11:30.800873 2026] [security2:error] [pid 849392:tid 849404] [remote 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuT0gMgr4yz2OQW0xrfvAAAiwo"]
[Thu Jul 30 13:11:30.801124 2026] [security2:error] [pid 849392:tid 849529] [client 2401:4900:27fd:2203:55ea:e226:5dea:83ef:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuT0gMgr4yz2OQW0xrfvAAAiwo"]
[Thu Jul 30 13:11:32.274533 2026] [proxy:error] [pid 849392:tid 849608] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:32.274599 2026] [proxy_http:error] [pid 849392:tid 849608] [client 18.211.55.47:37464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:32.275176 2026] [proxy:error] [pid 849392:tid 849608] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:32.275224 2026] [proxy_http:error] [pid 849392:tid 849608] [client 18.211.55.47:37464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:32.332836 2026] [proxy:error] [pid 849392:tid 849628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:32.332917 2026] [proxy_http:error] [pid 849392:tid 849628] [client 44.216.125.112:26311] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:32.333613 2026] [proxy:error] [pid 849392:tid 849628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:11:32.333667 2026] [proxy_http:error] [pid 849392:tid 849628] [client 44.216.125.112:26311] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:11:33.215152 2026] [security2:error] [pid 849392:tid 849624] [client 45.82.244.214:56232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuT1AMgr4yz2OQW0xrf0wAA6g4"]
[Thu Jul 30 13:11:33.252697 2026] [security2:error] [pid 849392:tid 849598] [client 185.200.116.219:52572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuT1QMgr4yz2OQW0xrf1AAAANA"]
[Thu Jul 30 13:11:33.252800 2026] [security2:error] [pid 849392:tid 849598] [client 185.200.116.219:52572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuT1QMgr4yz2OQW0xrf1AAAANA"]
[Thu Jul 30 13:11:34.831311 2026] [security2:error] [pid 849392:tid 849636] [client 149.57.191.59:65004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "deltaedu.net"] [uri "/index.php"] [unique_id "amuT1gMgr4yz2OQW0xrf3QAA9iA"]
[Thu Jul 30 13:11:35.770396 2026] [security2:error] [pid 849392:tid 849597] [client 172.236.9.101:40659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT1wMgr4yz2OQW0xrf3wAAAM8"]
[Thu Jul 30 13:11:35.865604 2026] [security2:error] [pid 849392:tid 849612] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT1wMgr4yz2OQW0xrf4gAAAN4"]
[Thu Jul 30 13:11:36.051104 2026] [security2:error] [pid 849392:tid 849592] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT1wMgr4yz2OQW0xrf5gAAAMo"]
[Thu Jul 30 13:11:36.348278 2026] [security2:error] [pid 849392:tid 849617] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT1wMgr4yz2OQW0xrf8gAAAOM"]
[Thu Jul 30 13:11:36.910757 2026] [security2:error] [pid 849392:tid 849545] [client 185.191.171.8:55670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/07/estao-abertas-ate-quarta-as-inscricoes-para-o-concurso-da-defensoria-publica-da-pb/"] [unique_id "amuT2AMgr4yz2OQW0xrf_wAAAJs"]
[Thu Jul 30 13:11:36.910913 2026] [security2:error] [pid 849392:tid 849545] [client 185.191.171.8:55670] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/07/estao-abertas-ate-quarta-as-inscricoes-para-o-concurso-da-defensoria-publica-da-pb/"] [unique_id "amuT2AMgr4yz2OQW0xrf_wAAAJs"]
[Thu Jul 30 13:11:37.856882 2026] [security2:error] [pid 849392:tid 849530] [client 149.57.191.59:65004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/index.php"] [unique_id "amuT2QMgr4yz2OQW0xrgBQAAjEQ"], referer: https://deltaedu.net/contact-us/
[Thu Jul 30 13:11:38.202793 2026] [security2:error] [pid 849392:tid 849540] [client 85.117.96.219:10693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuT2QMgr4yz2OQW0xrgBgAAAJY"], referer: http://pkf.jo
[Thu Jul 30 13:11:38.668305 2026] [security2:error] [pid 849392:tid 849557] [client 20.215.191.139:55901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/011i.php"] [unique_id "amuT2gMgr4yz2OQW0xrgCwAAAKc"]
[Thu Jul 30 13:11:39.646173 2026] [security2:error] [pid 849392:tid 849437] [remote 57.141.0.8:46758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuT2wMgr4yz2OQW0xrgQAAAkCs"]
[Thu Jul 30 13:11:39.682907 2026] [security2:error] [pid 849392:tid 849616] [client 20.215.191.139:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/03a005685d.php"] [unique_id "amuT2wMgr4yz2OQW0xrgQQAAAOI"]
[Thu Jul 30 13:11:40.575852 2026] [security2:error] [pid 849392:tid 849555] [client 20.215.191.139:57471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/403.php"] [unique_id "amuT3AMgr4yz2OQW0xrgTAAAAKU"]
[Thu Jul 30 13:11:40.934191 2026] [security2:error] [pid 849392:tid 849644] [client 179.64.21.229:17934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT3AMgr4yz2OQW0xrgUQAAAP4"]
[Thu Jul 30 13:11:40.938050 2026] [security2:error] [pid 849392:tid 849644] [client 179.64.21.229:17934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT3AMgr4yz2OQW0xrgUQAAAP4"]
[Thu Jul 30 13:11:41.240718 2026] [security2:error] [pid 849392:tid 849636] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT3AMgr4yz2OQW0xrgTwAAAPY"]
[Thu Jul 30 13:11:41.684412 2026] [security2:error] [pid 849392:tid 849597] [client 77.83.36.161:42934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amuT3QMgr4yz2OQW0xrgUgAAAM8"]
[Thu Jul 30 13:11:41.746873 2026] [security2:error] [pid 849392:tid 849621] [client 20.215.191.139:55884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/404.php"] [unique_id "amuT3QMgr4yz2OQW0xrgUwAAAOc"]
[Thu Jul 30 13:11:42.276960 2026] [security2:error] [pid 849392:tid 849596] [client 77.83.36.161:43237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amuT3gMgr4yz2OQW0xrgVQAAAM4"]
[Thu Jul 30 13:11:42.850516 2026] [security2:error] [pid 849392:tid 849536] [client 77.83.36.161:43544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amuT3gMgr4yz2OQW0xrgWwAAAJI"]
[Thu Jul 30 13:11:43.050223 2026] [security2:error] [pid 849392:tid 849549] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT3gMgr4yz2OQW0xrgWQAAAJ8"]
[Thu Jul 30 13:11:43.223242 2026] [security2:error] [pid 849392:tid 849544] [client 20.215.191.139:54038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/aa.php"] [unique_id "amuT3wMgr4yz2OQW0xrgXAAAAJo"]
[Thu Jul 30 13:11:44.672558 2026] [security2:error] [pid 849392:tid 849552] [client 20.215.191.139:59170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/aafewc0k.php"] [unique_id "amuT4AMgr4yz2OQW0xrgZQAAAKI"]
[Thu Jul 30 13:11:45.525773 2026] [security2:error] [pid 849392:tid 849650] [client 172.237.109.114:8515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4QMgr4yz2OQW0xrgaAAAAQQ"]
[Thu Jul 30 13:11:45.864367 2026] [security2:error] [pid 849392:tid 849623] [client 172.236.9.101:14195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4QMgr4yz2OQW0xrgagAAAOk"]
[Thu Jul 30 13:11:45.965762 2026] [security2:error] [pid 849392:tid 849571] [client 112.86.225.184:47806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "azureskyfilms.com"] [uri "/"] [unique_id "amuT4QMgr4yz2OQW0xrgcQAAALU"]
[Thu Jul 30 13:11:45.965901 2026] [security2:error] [pid 849392:tid 849571] [client 112.86.225.184:47806] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "azureskyfilms.com"] [uri "/"] [unique_id "amuT4QMgr4yz2OQW0xrgcQAAALU"]
[Thu Jul 30 13:11:47.522043 2026] [security2:error] [pid 849392:tid 849616] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuT4gMgr4yz2OQW0xrgcwAA4nY"]
[Thu Jul 30 13:11:48.025256 2026] [security2:error] [pid 849392:tid 849555] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgjAAAAKU"]
[Thu Jul 30 13:11:48.062903 2026] [security2:error] [pid 849392:tid 849612] [client 213.152.161.85:45088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuT5AMgr4yz2OQW0xrgkgAAAN4"]
[Thu Jul 30 13:11:48.063010 2026] [security2:error] [pid 849392:tid 849612] [client 213.152.161.85:45088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuT5AMgr4yz2OQW0xrgkgAAAN4"]
[Thu Jul 30 13:11:48.423347 2026] [security2:error] [pid 849392:tid 849560] [client 172.237.109.114:23347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgdgAAAKo"]
[Thu Jul 30 13:11:48.453818 2026] [security2:error] [pid 849392:tid 849631] [client 172.237.109.114:42752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgdwAAAPE"]
[Thu Jul 30 13:11:48.486320 2026] [security2:error] [pid 849392:tid 849525] [client 172.237.109.114:40817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgdQAAAIc"]
[Thu Jul 30 13:11:48.560342 2026] [security2:error] [pid 849392:tid 849640] [client 172.237.109.114:25915] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgeQAAAPo"]
[Thu Jul 30 13:11:48.568622 2026] [security2:error] [pid 849392:tid 849569] [client 172.237.109.114:20955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgewAAALM"]
[Thu Jul 30 13:11:48.651970 2026] [security2:error] [pid 849392:tid 849563] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT5AMgr4yz2OQW0xrglAAAAK0"]
[Thu Jul 30 13:11:49.226140 2026] [security2:error] [pid 849392:tid 849568] [client 172.237.109.114:37926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgfAAAALI"]
[Thu Jul 30 13:11:49.239371 2026] [security2:error] [pid 849392:tid 849537] [client 172.237.109.114:63655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgfwAAAJM"]
[Thu Jul 30 13:11:49.240301 2026] [security2:error] [pid 849392:tid 849603] [client 172.237.109.114:7677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrggQAAANU"]
[Thu Jul 30 13:11:49.244639 2026] [security2:error] [pid 849392:tid 849591] [client 172.237.109.114:14083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgfgAAAMk"]
[Thu Jul 30 13:11:49.248484 2026] [security2:error] [pid 849392:tid 849590] [client 172.237.109.114:34579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrggAAAAMg"]
[Thu Jul 30 13:11:49.252386 2026] [security2:error] [pid 849392:tid 849574] [client 172.237.109.114:65265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrghAAAALg"]
[Thu Jul 30 13:11:49.257953 2026] [security2:error] [pid 849392:tid 849575] [client 172.237.109.114:48460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgggAAALk"]
[Thu Jul 30 13:11:49.257953 2026] [security2:error] [pid 849392:tid 849572] [client 172.237.109.114:1268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgfQAAALY"]
[Thu Jul 30 13:11:49.272473 2026] [security2:error] [pid 849392:tid 849624] [client 172.237.109.114:2043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrghgAAAOo"]
[Thu Jul 30 13:11:49.283386 2026] [security2:error] [pid 849392:tid 849620] [client 172.237.109.114:5541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgiAAAAOY"]
[Thu Jul 30 13:11:49.293834 2026] [security2:error] [pid 849392:tid 849551] [client 172.237.109.114:45721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgegAAAKE"]
[Thu Jul 30 13:11:49.327172 2026] [security2:error] [pid 849392:tid 849637] [client 172.237.109.114:1220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrggwAAAPc"]
[Thu Jul 30 13:11:49.342110 2026] [security2:error] [pid 849392:tid 849619] [client 172.237.109.114:38041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrgeAAAAOU"]
[Thu Jul 30 13:11:49.362628 2026] [security2:error] [pid 849392:tid 849587] [client 184.75.223.203:44946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuT5QMgr4yz2OQW0xrgnQAAAMU"]
[Thu Jul 30 13:11:49.362731 2026] [security2:error] [pid 849392:tid 849587] [client 184.75.223.203:44946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuT5QMgr4yz2OQW0xrgnQAAAMU"]
[Thu Jul 30 13:11:49.375356 2026] [security2:error] [pid 849392:tid 849625] [client 172.237.109.114:18548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrghwAAAOs"]
[Thu Jul 30 13:11:49.389402 2026] [security2:error] [pid 849392:tid 849580] [client 172.237.109.114:7163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT4wMgr4yz2OQW0xrghQAAAL4"]
[Thu Jul 30 13:11:49.394928 2026] [security2:error] [pid 849392:tid 849579] [client 20.215.191.139:59505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/abcd.php"] [unique_id "amuT5QMgr4yz2OQW0xrgngAAAL0"]
[Thu Jul 30 13:11:49.668033 2026] [security2:error] [pid 849392:tid 849529] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuT5QMgr4yz2OQW0xrgmwAAi10"]
[Thu Jul 30 13:11:49.753209 2026] [security2:error] [pid 849392:tid 849545] [client 172.236.9.101:25001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT5QMgr4yz2OQW0xrgnAAAAJs"]
[Thu Jul 30 13:11:49.947904 2026] [security2:error] [pid 849392:tid 849561] [client 20.215.191.139:54076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/about.php"] [unique_id "amuT5QMgr4yz2OQW0xrgoAAAAKs"]
[Thu Jul 30 13:11:50.422568 2026] [security2:error] [pid 849392:tid 849608] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuT5QMgr4yz2OQW0xrgnwAA2lw"]
[Thu Jul 30 13:11:50.536618 2026] [core:notice] [pid 849392:tid 849494] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:50.539507 2026] [security2:error] [pid 849392:tid 849614] [client 47.79.1.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/261/259/516"] [unique_id "amuT5gMgr4yz2OQW0xrgowAA4GQ"]
[Thu Jul 30 13:11:51.315946 2026] [core:notice] [pid 849392:tid 849397] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:51.399798 2026] [security2:error] [pid 849392:tid 849546] [client 179.64.21.229:10165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT5wMgr4yz2OQW0xrgrgAAAJw"]
[Thu Jul 30 13:11:51.403674 2026] [security2:error] [pid 849392:tid 849546] [client 179.64.21.229:10165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT5wMgr4yz2OQW0xrgrgAAAJw"]
[Thu Jul 30 13:11:52.004851 2026] [security2:error] [pid 849392:tid 849588] [client 20.215.191.139:59473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/admin.php"] [unique_id "amuT6AMgr4yz2OQW0xrgswAAAMY"]
[Thu Jul 30 13:11:52.774939 2026] [security2:error] [pid 849392:tid 849569] [client 43.173.178.153:38402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/02/25/10-pieces-reperees-dans-la-collection-forever-21-printemps-2014/"] [unique_id "amuT6AMgr4yz2OQW0xrgtgAAALM"]
[Thu Jul 30 13:11:52.996839 2026] [core:notice] [pid 849392:tid 849626] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:53.002086 2026] [security2:error] [pid 849392:tid 849626] [client 43.173.181.207:46908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/02/25/10-pieces-reperees-dans-la-collection-forever-21-printemps-2014/"] [unique_id "amuT6AMgr4yz2OQW0xrgugAAAOw"], referer: https://carnetdeshopping.com/index.php/2014/02/25/10-pieces-reperees-dans-la-collection-forever-21-printemps-2014/
[Thu Jul 30 13:11:53.144950 2026] [security2:error] [pid 849392:tid 849638] [client 20.215.191.139:56557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/adminfuns.php"] [unique_id "amuT6QMgr4yz2OQW0xrguwAAAPg"]
[Thu Jul 30 13:11:53.328155 2026] [security2:error] [pid 849392:tid 849566] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT6AMgr4yz2OQW0xrguQAAALA"]
[Thu Jul 30 13:11:53.883548 2026] [security2:error] [pid 849392:tid 849516] [remote 57.141.0.65:39132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuT6QMgr4yz2OQW0xrgwQAAiHo"]
[Thu Jul 30 13:11:54.154318 2026] [security2:error] [pid 849392:tid 849495] [remote 213.180.203.92:32922] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/tag/supplychain/"] [unique_id "amuT6gMgr4yz2OQW0xrgxAAAsmU"]
[Thu Jul 30 13:11:55.176046 2026] [security2:error] [pid 849392:tid 849406] [remote 57.141.0.3:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/358522518/feed/rss2/"] [unique_id "amuT6wMgr4yz2OQW0xrgxwAAxww"]
[Thu Jul 30 13:11:55.420209 2026] [core:notice] [pid 849392:tid 849580] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:55.733206 2026] [security2:error] [pid 849392:tid 849579] [client 172.236.9.101:33936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT6wMgr4yz2OQW0xrgyAAAAL0"]
[Thu Jul 30 13:11:55.750829 2026] [security2:error] [pid 849392:tid 849634] [client 172.236.9.101:43996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT6wMgr4yz2OQW0xrgyQAAAPQ"]
[Thu Jul 30 13:11:56.211397 2026] [core:notice] [pid 849392:tid 849641] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:57.856459 2026] [core:notice] [pid 849392:tid 849650] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:11:57.863676 2026] [security2:error] [pid 849392:tid 849650] [client 66.249.79.8:43747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/citationstylelanguage/download/ris"] [unique_id "amuT7QMgr4yz2OQW0xrg0AAAAQQ"]
[Thu Jul 30 13:11:58.345085 2026] [security2:error] [pid 849392:tid 849410] [remote 57.141.0.23:48662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuT7gMgr4yz2OQW0xrg1wAAkBA"]
[Thu Jul 30 13:11:58.399259 2026] [security2:error] [pid 849392:tid 849558] [client 181.78.178.76:15831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuT7gMgr4yz2OQW0xrg1AAAAKg"], referer: http://pkf.jo
[Thu Jul 30 13:11:58.560994 2026] [security2:error] [pid 849392:tid 849531] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT7QMgr4yz2OQW0xrg0wAAAI0"]
[Thu Jul 30 13:11:58.579576 2026] [security2:error] [pid 849392:tid 849608] [client 88.246.14.194:33946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuT7gMgr4yz2OQW0xrg1gAAANo"], referer: http://pkf.jo
[Thu Jul 30 13:11:58.703336 2026] [security2:error] [pid 849392:tid 849529] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuT7gMgr4yz2OQW0xrg1QAAi2k"]
[Thu Jul 30 13:11:59.220503 2026] [security2:error] [pid 849392:tid 849609] [client 185.200.116.219:57524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuT7wMgr4yz2OQW0xrg4AAAANs"]
[Thu Jul 30 13:11:59.220607 2026] [security2:error] [pid 849392:tid 849609] [client 185.200.116.219:57524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuT7wMgr4yz2OQW0xrg4AAAANs"]
[Thu Jul 30 13:11:59.531794 2026] [security2:error] [pid 849392:tid 849586] [client 57.141.0.31:61946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuT7wMgr4yz2OQW0xrg3wAAxAo"], referer: https://igetvape-australia.com/product/iget-hot-aloe-vera-grape-ice-2/
[Thu Jul 30 13:11:59.662735 2026] [security2:error] [pid 849392:tid 849572] [client 20.215.191.139:57670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/albin.php"] [unique_id "amuT7wMgr4yz2OQW0xrg4wAAALY"]
[Thu Jul 30 13:11:59.739142 2026] [security2:error] [pid 849392:tid 849555] [client 172.236.9.101:48813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT7wMgr4yz2OQW0xrg4QAAAKU"]
[Thu Jul 30 13:12:00.614010 2026] [security2:error] [pid 849392:tid 849576] [client 20.215.191.139:57268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/amfsqvgv.php"] [unique_id "amuT8AMgr4yz2OQW0xrg5QAAALo"]
[Thu Jul 30 13:12:01.350268 2026] [core:notice] [pid 849392:tid 849566] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:01.381600 2026] [security2:error] [pid 849392:tid 849640] [client 20.215.191.139:55890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/ant.php"] [unique_id "amuT8QMgr4yz2OQW0xrg7wAAAPo"]
[Thu Jul 30 13:12:01.839413 2026] [security2:error] [pid 849392:tid 849569] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT8QMgr4yz2OQW0xrg6QAAALM"]
[Thu Jul 30 13:12:01.918921 2026] [security2:error] [pid 849392:tid 849426] [remote 184.168.126.180:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koriusa.info"] [uri "/wp-login.php"] [unique_id "amuT8QMgr4yz2OQW0xrg8wAArSA"]
[Thu Jul 30 13:12:02.239247 2026] [security2:error] [pid 849392:tid 849594] [client 20.215.191.139:59850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/appreciators.php"] [unique_id "amuT8gMgr4yz2OQW0xrg9AAAAMw"]
[Thu Jul 30 13:12:02.440616 2026] [security2:error] [pid 849392:tid 849643] [client 179.64.21.229:22390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT8gMgr4yz2OQW0xrg9QAAAP0"]
[Thu Jul 30 13:12:02.440778 2026] [security2:error] [pid 849392:tid 849643] [client 179.64.21.229:22390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT8gMgr4yz2OQW0xrg9QAAAP0"]
[Thu Jul 30 13:12:02.836330 2026] [security2:error] [pid 849392:tid 849624] [client 20.215.191.139:57226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/archive.php"] [unique_id "amuT8gMgr4yz2OQW0xrg-AAAAOo"]
[Thu Jul 30 13:12:03.510010 2026] [security2:error] [pid 849392:tid 849607] [client 20.215.191.139:57709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/as.php"] [unique_id "amuT8wMgr4yz2OQW0xrg-wAAANk"]
[Thu Jul 30 13:12:04.858211 2026] [security2:error] [pid 849392:tid 849619] [client 20.215.191.139:56513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/atomlib.php"] [unique_id "amuT9AMgr4yz2OQW0xrhBwAAAOU"]
[Thu Jul 30 13:12:05.474819 2026] [proxy:error] [pid 849392:tid 849547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:05.474910 2026] [proxy_http:error] [pid 849392:tid 849547] [client 3.228.112.215:60296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:05.475897 2026] [proxy:error] [pid 849392:tid 849547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:05.475958 2026] [proxy_http:error] [pid 849392:tid 849547] [client 3.228.112.215:60296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:05.479989 2026] [autoindex:error] [pid 849392:tid 849565] [client 52.202.41.153:7945] AH01276: Cannot serve directory /home2/xncnyxte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:12:05.490232 2026] [autoindex:error] [pid 849392:tid 849527] [client 52.202.41.153:7854] AH01276: Cannot serve directory /home2/xncnyxte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:12:05.503321 2026] [proxy:error] [pid 849392:tid 849616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:05.503437 2026] [proxy_http:error] [pid 849392:tid 849616] [client 54.87.222.253:59160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:05.504700 2026] [proxy:error] [pid 849392:tid 849616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:05.504761 2026] [proxy_http:error] [pid 849392:tid 849616] [client 54.87.222.253:59160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:05.784832 2026] [security2:error] [pid 849392:tid 849523] [client 172.236.9.101:22973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT9QMgr4yz2OQW0xrhCwAAAIU"]
[Thu Jul 30 13:12:06.162060 2026] [security2:error] [pid 849392:tid 849647] [client 20.215.191.139:57237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/autoload_classmap.php"] [unique_id "amuT9gMgr4yz2OQW0xrhHQAAAQE"]
[Thu Jul 30 13:12:06.236714 2026] [security2:error] [pid 849392:tid 849418] [remote 57.141.0.63:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amuT9gMgr4yz2OQW0xrhHwAAzhg"]
[Thu Jul 30 13:12:06.998370 2026] [core:notice] [pid 849392:tid 849600] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:07.087375 2026] [security2:error] [pid 849392:tid 849562] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuT9gMgr4yz2OQW0xrhIwAAAKw"]
[Thu Jul 30 13:12:07.302741 2026] [security2:error] [pid 849392:tid 849611] [client 20.215.191.139:57236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/bb.php"] [unique_id "amuT9wMgr4yz2OQW0xrhKQAAAN0"]
[Thu Jul 30 13:12:07.596015 2026] [security2:error] [pid 849392:tid 849620] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuT9wMgr4yz2OQW0xrhLQAAAOY"]
[Thu Jul 30 13:12:07.683286 2026] [security2:error] [pid 849392:tid 849398] [remote 57.141.0.53:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/610298834/feed/rss2/"] [unique_id "amuT9wMgr4yz2OQW0xrhLgAAoQQ"]
[Thu Jul 30 13:12:07.982417 2026] [security2:error] [pid 849392:tid 849603] [client 20.215.191.139:55910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/bnm.php"] [unique_id "amuT9wMgr4yz2OQW0xrhLwAAANU"]
[Thu Jul 30 13:12:09.263283 2026] [security2:error] [pid 849392:tid 849610] [client 20.215.191.139:59870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/bootstrap.php"] [unique_id "amuT-QMgr4yz2OQW0xrhQAAAANw"]
[Thu Jul 30 13:12:09.644029 2026] [security2:error] [pid 849392:tid 849598] [client 103.178.60.11:12516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuT-QMgr4yz2OQW0xrhQQAAANA"], referer: http://pkf.jo
[Thu Jul 30 13:12:09.837887 2026] [security2:error] [pid 849392:tid 849545] [client 172.236.9.101:54257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuT-QMgr4yz2OQW0xrhQgAAAJs"]
[Thu Jul 30 13:12:10.348237 2026] [security2:error] [pid 849392:tid 849577] [client 20.215.191.139:56552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/buy.php"] [unique_id "amuT-gMgr4yz2OQW0xrhRgAAALs"]
[Thu Jul 30 13:12:11.736227 2026] [autoindex:error] [pid 849392:tid 849636] [client 167.94.146.54:48792] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:12:12.002948 2026] [security2:error] [pid 849392:tid 849458] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuT_AMgr4yz2OQW0xrhTwAA10A"]
[Thu Jul 30 13:12:12.983474 2026] [security2:error] [pid 849392:tid 849632] [client 179.64.21.229:4366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT_AMgr4yz2OQW0xrhZQAAAPI"]
[Thu Jul 30 13:12:12.987346 2026] [security2:error] [pid 849392:tid 849632] [client 179.64.21.229:4366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuT_AMgr4yz2OQW0xrhZQAAAPI"]
[Thu Jul 30 13:12:14.114723 2026] [security2:error] [pid 849392:tid 849466] [remote 216.73.217.142:51968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuT_QMgr4yz2OQW0xrhaQAAz0g"]
[Thu Jul 30 13:12:14.413637 2026] [core:notice] [pid 849392:tid 849447] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:14.901797 2026] [core:notice] [pid 849392:tid 849443] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:15.975752 2026] [fcgid:warn] [pid 849392:tid 849551] (70014)End of file found: [client 66.132.172.178:16406] mod_fcgid: can't get data from http client
[Thu Jul 30 13:12:16.124845 2026] [core:error] [pid 849392:tid 849639] [client 184.154.139.57:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=germanyvisasupportcenterislamabad.website&yahoo.com
[Thu Jul 30 13:12:16.124870 2026] [core:error] [pid 849392:tid 849639] [client 184.154.139.57:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=germanyvisasupportcenterislamabad.website&yahoo.com
[Thu Jul 30 13:12:16.456097 2026] [security2:error] [pid 849392:tid 849604] [client 85.208.96.206:29528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/07/ministro-da-saude-pede-que-pais-vacinem-filhos-contra-a-poliomielite/"] [unique_id "amuUAAMgr4yz2OQW0xrhcwAAANY"]
[Thu Jul 30 13:12:16.456284 2026] [security2:error] [pid 849392:tid 849604] [client 85.208.96.206:29528] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/07/ministro-da-saude-pede-que-pais-vacinem-filhos-contra-a-poliomielite/"] [unique_id "amuUAAMgr4yz2OQW0xrhcwAAANY"]
[Thu Jul 30 13:12:16.826462 2026] [security2:error] [pid 849392:tid 849603] [client 172.236.9.101:47103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUAAMgr4yz2OQW0xrhcQAAANU"]
[Thu Jul 30 13:12:17.049958 2026] [security2:error] [pid 849392:tid 849552] [client 184.154.139.57:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/style.css"] [unique_id "amuUAQMgr4yz2OQW0xrhdQAAAKI"]
[Thu Jul 30 13:12:17.138340 2026] [security2:error] [pid 849392:tid 849564] [client 23.94.216.234:39420] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "mail.jvc.nyx.temporary.site"] [uri "/"] [unique_id "amuUAQMgr4yz2OQW0xrhdgAAAK4"]
[Thu Jul 30 13:12:17.476962 2026] [security2:error] [pid 849392:tid 849430] [remote 45.32.221.166:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "allmontecristi.com"] [uri "/wp-json/batch/v1"] [unique_id "amuUAQMgr4yz2OQW0xrhegAA7yQ"]
[Thu Jul 30 13:12:18.204528 2026] [security2:error] [pid 849392:tid 849465] [remote 45.32.221.166:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "allmontecristi.com"] [uri "/"] [unique_id "amuUAgMgr4yz2OQW0xrhewAA3Ec"]
[Thu Jul 30 13:12:18.581696 2026] [core:notice] [pid 849392:tid 849568] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:18.677687 2026] [core:notice] [pid 849392:tid 849598] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:18.952563 2026] [security2:error] [pid 849392:tid 849565] [client 20.215.191.139:57665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/chosen.php"] [unique_id "amuUAgMgr4yz2OQW0xrhfwAAAK8"]
[Thu Jul 30 13:12:18.964397 2026] [core:notice] [pid 849392:tid 849545] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:20.884587 2026] [security2:error] [pid 849392:tid 849578] [client 172.236.9.101:7534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUBAMgr4yz2OQW0xrhhQAAALw"]
[Thu Jul 30 13:12:21.153927 2026] [security2:error] [pid 849392:tid 849567] [client 66.249.73.98:55025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuUBAMgr4yz2OQW0xrhhgAAALE"]
[Thu Jul 30 13:12:23.801289 2026] [security2:error] [pid 849392:tid 849626] [client 179.64.21.229:9977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUBwMgr4yz2OQW0xrhqAAAAOw"]
[Thu Jul 30 13:12:23.801448 2026] [security2:error] [pid 849392:tid 849626] [client 179.64.21.229:9977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUBwMgr4yz2OQW0xrhqAAAAOw"]
[Thu Jul 30 13:12:23.873727 2026] [security2:error] [pid 849392:tid 849480] [remote 216.73.217.142:51968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUBwMgr4yz2OQW0xrhqQAAnlY"]
[Thu Jul 30 13:12:27.234190 2026] [security2:error] [pid 849392:tid 849540] [client 20.215.191.139:57220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/class-wp-image.php"] [unique_id "amuUCwMgr4yz2OQW0xrh1QAAAJY"]
[Thu Jul 30 13:12:27.725070 2026] [security2:error] [pid 849392:tid 849630] [client 172.236.9.101:34462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUCwMgr4yz2OQW0xrh1gAAAPA"]
[Thu Jul 30 13:12:28.076200 2026] [security2:error] [pid 849392:tid 849614] [client 20.215.191.139:55931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/classsmtps.php"] [unique_id "amuUDAMgr4yz2OQW0xrh3QAAAOA"]
[Thu Jul 30 13:12:29.567889 2026] [core:notice] [pid 849392:tid 849409] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:29.576589 2026] [security2:error] [pid 849392:tid 849545] [client 20.215.191.139:56517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/classwithtostring.php"] [unique_id "amuUDQMgr4yz2OQW0xrh7wAAAJs"]
[Thu Jul 30 13:12:29.881086 2026] [security2:error] [pid 849392:tid 849567] [client 216.73.216.30:10040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuUDQMgr4yz2OQW0xrh8AAAsRs"]
[Thu Jul 30 13:12:30.277934 2026] [security2:error] [pid 849392:tid 849549] [client 20.215.191.139:57708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/config.php"] [unique_id "amuUDgMgr4yz2OQW0xrh_QAAAJ8"]
[Thu Jul 30 13:12:30.298651 2026] [security2:error] [pid 849392:tid 849548] [client 51.68.111.217:27469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/robots.txt"] [unique_id "amuUDgMgr4yz2OQW0xrh_gAAAJ4"]
[Thu Jul 30 13:12:30.298771 2026] [security2:error] [pid 849392:tid 849548] [client 51.68.111.217:27469] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jesus.claims"] [uri "/robots.txt"] [unique_id "amuUDgMgr4yz2OQW0xrh_gAAAJ4"]
[Thu Jul 30 13:12:30.531429 2026] [security2:error] [pid 849392:tid 849606] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUDgMgr4yz2OQW0xrh_AAAANg"]
[Thu Jul 30 13:12:30.818274 2026] [security2:error] [pid 849392:tid 849553] [client 102.38.155.69:45404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuUDgMgr4yz2OQW0xrh_wAAAKM"], referer: http://pkf.jo
[Thu Jul 30 13:12:30.847298 2026] [security2:error] [pid 849392:tid 849524] [client 186.77.196.3:1111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuUDgMgr4yz2OQW0xriAQAAAIY"], referer: http://pkf.jo
[Thu Jul 30 13:12:31.223861 2026] [security2:error] [pid 849392:tid 849642] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUDgMgr4yz2OQW0xriBQAAAPw"]
[Thu Jul 30 13:12:31.349126 2026] [security2:error] [pid 849392:tid 849621] [client 20.215.191.139:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/core.php"] [unique_id "amuUDwMgr4yz2OQW0xriBwAAAOc"]
[Thu Jul 30 13:12:32.161790 2026] [security2:error] [pid 849392:tid 849589] [client 20.215.191.139:57277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/css.php"] [unique_id "amuUEAMgr4yz2OQW0xriCwAAAMc"]
[Thu Jul 30 13:12:33.113894 2026] [security2:error] [pid 849392:tid 849604] [client 20.215.191.139:59900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/database.php"] [unique_id "amuUEQMgr4yz2OQW0xriDwAAANY"]
[Thu Jul 30 13:12:34.166061 2026] [security2:error] [pid 849392:tid 849559] [client 20.215.191.139:57256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/db.php"] [unique_id "amuUEgMgr4yz2OQW0xriEwAAAKk"]
[Thu Jul 30 13:12:34.332156 2026] [core:notice] [pid 849392:tid 849424] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:34.363007 2026] [fcgid:warn] [pid 849392:tid 849614] (70014)End of file found: [client 66.132.186.159:49974] mod_fcgid: can't get data from http client
[Thu Jul 30 13:12:34.496140 2026] [security2:error] [pid 849392:tid 849570] [client 179.64.21.229:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUEgMgr4yz2OQW0xriHgAAALQ"]
[Thu Jul 30 13:12:34.496247 2026] [security2:error] [pid 849392:tid 849570] [client 179.64.21.229:61773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUEgMgr4yz2OQW0xriHgAAALQ"]
[Thu Jul 30 13:12:35.362029 2026] [security2:error] [pid 849392:tid 849649] [client 20.215.191.139:55879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/default.php"] [unique_id "amuUEwMgr4yz2OQW0xriJQAAAQM"]
[Thu Jul 30 13:12:35.965233 2026] [core:notice] [pid 849392:tid 849567] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:35.985043 2026] [security2:error] [pid 849392:tid 849576] [client 23.94.216.234:44308] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "mail.jwcpartners.org"] [uri "/"] [unique_id "amuUEwMgr4yz2OQW0xriKgAAALo"]
[Thu Jul 30 13:12:36.088908 2026] [security2:error] [pid 849392:tid 849592] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUEwMgr4yz2OQW0xriJgAAygQ"]
[Thu Jul 30 13:12:36.563404 2026] [core:notice] [pid 849392:tid 849588] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:36.830974 2026] [security2:error] [pid 849392:tid 849595] [client 101.226.10.126:45252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUFAMgr4yz2OQW0xriLwAAAM0"]
[Thu Jul 30 13:12:37.759355 2026] [security2:error] [pid 849392:tid 849624] [client 101.226.10.126:45338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUFQMgr4yz2OQW0xriTgAAAOo"]
[Thu Jul 30 13:12:37.839181 2026] [security2:error] [pid 849392:tid 849591] [client 47.128.121.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriTQAAAMk"]
[Thu Jul 30 13:12:38.419735 2026] [security2:error] [pid 849392:tid 849534] [client 172.237.109.114:49356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriOgAAAJA"]
[Thu Jul 30 13:12:38.446627 2026] [security2:error] [pid 849392:tid 849633] [client 101.226.10.126:45394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUFgMgr4yz2OQW0xriXQAAAPM"]
[Thu Jul 30 13:12:38.499519 2026] [security2:error] [pid 849392:tid 849590] [client 172.237.109.114:48018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriPwAAAMg"]
[Thu Jul 30 13:12:38.509738 2026] [security2:error] [pid 849392:tid 849643] [client 172.237.109.114:49014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriOwAAAP0"]
[Thu Jul 30 13:12:38.511165 2026] [security2:error] [pid 849392:tid 849525] [client 172.237.109.114:42736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriQAAAAIc"]
[Thu Jul 30 13:12:38.548537 2026] [security2:error] [pid 849392:tid 849642] [client 172.237.109.114:37878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriQgAAAPw"]
[Thu Jul 30 13:12:38.592956 2026] [security2:error] [pid 849392:tid 849566] [client 172.237.109.114:19730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriRQAAALA"]
[Thu Jul 30 13:12:38.595721 2026] [security2:error] [pid 849392:tid 849524] [client 172.237.109.114:17254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriPQAAAIY"]
[Thu Jul 30 13:12:38.603062 2026] [security2:error] [pid 849392:tid 849537] [client 172.237.109.114:18498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriPgAAAJM"]
[Thu Jul 30 13:12:38.606826 2026] [security2:error] [pid 849392:tid 849585] [client 172.237.109.114:42228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriRAAAAMM"]
[Thu Jul 30 13:12:38.607845 2026] [security2:error] [pid 849392:tid 849560] [client 172.237.109.114:1403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriQwAAAKo"]
[Thu Jul 30 13:12:38.618634 2026] [security2:error] [pid 849392:tid 849553] [client 172.237.109.114:23439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriPAAAAKM"]
[Thu Jul 30 13:12:38.624958 2026] [security2:error] [pid 849392:tid 849586] [client 172.237.109.114:6196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriQQAAAMQ"]
[Thu Jul 30 13:12:38.632734 2026] [security2:error] [pid 849392:tid 849563] [client 172.237.109.114:45357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriSQAAAK0"]
[Thu Jul 30 13:12:38.661867 2026] [security2:error] [pid 849392:tid 849562] [client 172.237.109.114:48494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriRwAAAKw"]
[Thu Jul 30 13:12:38.664283 2026] [security2:error] [pid 849392:tid 849637] [client 172.237.109.114:35276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriSAAAAPc"]
[Thu Jul 30 13:12:38.683786 2026] [proxy:error] [pid 849392:tid 849608] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:38.683849 2026] [proxy_http:error] [pid 849392:tid 849608] [client 34.233.129.35:10432] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:38.684438 2026] [proxy:error] [pid 849392:tid 849608] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:38.684484 2026] [proxy_http:error] [pid 849392:tid 849608] [client 34.233.129.35:10432] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:38.692969 2026] [proxy:error] [pid 849392:tid 849527] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:38.693049 2026] [proxy_http:error] [pid 849392:tid 849527] [client 32.194.121.99:37149] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:38.693607 2026] [proxy:error] [pid 849392:tid 849527] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:38.693649 2026] [proxy_http:error] [pid 849392:tid 849527] [client 32.194.121.99:37149] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:39.218075 2026] [security2:error] [pid 849392:tid 849571] [client 172.237.109.114:31896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFQMgr4yz2OQW0xriRgAAALU"]
[Thu Jul 30 13:12:39.422044 2026] [security2:error] [pid 849392:tid 849587] [client 101.226.10.126:45394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:vars[1][]. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "phpinfo(,ARGS:vars[1][]"] [severity "CRITICAL"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUFwMgr4yz2OQW0xridAAAAMU"]
[Thu Jul 30 13:12:39.422209 2026] [security2:error] [pid 849392:tid 849587] [client 101.226.10.126:45394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUFwMgr4yz2OQW0xridAAAAMU"]
[Thu Jul 30 13:12:39.531705 2026] [security2:error] [pid 849392:tid 849628] [client 172.237.109.114:34350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFgMgr4yz2OQW0xriVAAAAO4"]
[Thu Jul 30 13:12:39.560966 2026] [security2:error] [pid 849392:tid 849623] [client 172.237.109.114:21349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFgMgr4yz2OQW0xriUQAAAOk"]
[Thu Jul 30 13:12:39.592562 2026] [security2:error] [pid 849392:tid 849551] [client 172.237.109.114:55214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFgMgr4yz2OQW0xriUwAAAKE"]
[Thu Jul 30 13:12:39.599288 2026] [security2:error] [pid 849392:tid 849530] [client 172.237.109.114:25601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUFgMgr4yz2OQW0xriVQAAAIw"]
[Thu Jul 30 13:12:40.097286 2026] [security2:error] [pid 849392:tid 849583] [client 101.226.10.126:45534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUGAMgr4yz2OQW0xrifgAAAME"]
[Thu Jul 30 13:12:40.179517 2026] [security2:error] [pid 849392:tid 849606] [client 246.103.56.105:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "bensecuritylocksmith.site"] [uri "/wp-login.php"] [unique_id "amuUGAMgr4yz2OQW0xrifQAA2CM"], referer: https://bensecuritylocksmith.site/wp-login.php
[Thu Jul 30 13:12:40.269269 2026] [security2:error] [pid 849392:tid 849619] [client 185.200.116.219:59360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuUGAMgr4yz2OQW0xrigAAAAOU"]
[Thu Jul 30 13:12:40.269372 2026] [security2:error] [pid 849392:tid 849619] [client 185.200.116.219:59360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuUGAMgr4yz2OQW0xrigAAAAOU"]
[Thu Jul 30 13:12:40.453788 2026] [security2:error] [pid 849392:tid 849640] [client 112.84.177.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuUFwMgr4yz2OQW0xridwAAAPo"]
[Thu Jul 30 13:12:40.660208 2026] [autoindex:error] [pid 849392:tid 849586] [client 34.224.175.62:26069] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:12:40.666823 2026] [autoindex:error] [pid 849392:tid 849563] [client 34.224.175.62:38604] AH01276: Cannot serve directory /home1/uixgzjte/public_html/chicago-mfg.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:12:40.731029 2026] [core:notice] [pid 849392:tid 849562] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:40.800401 2026] [security2:error] [pid 849392:tid 849608] [client 101.226.10.126:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUGAMgr4yz2OQW0xriiwAAANo"]
[Thu Jul 30 13:12:40.947498 2026] [core:notice] [pid 849392:tid 849610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:41.233359 2026] [security2:error] [pid 849392:tid 849448] [remote 57.141.0.7:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuUGQMgr4yz2OQW0xrilgAA4TY"]
[Thu Jul 30 13:12:41.612179 2026] [security2:error] [pid 849392:tid 849519] [remote 57.141.0.41:35038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/610298834/feed/rss2/"] [unique_id "amuUGQMgr4yz2OQW0xrinAAA0X0"]
[Thu Jul 30 13:12:41.801107 2026] [security2:error] [pid 849392:tid 849542] [client 101.226.10.126:45598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUGQMgr4yz2OQW0xrinQAAAJg"]
[Thu Jul 30 13:12:42.141417 2026] [core:error] [pid 849392:tid 849623] [client 193.47.62.167:45452] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:12:42.141444 2026] [core:error] [pid 849392:tid 849623] [client 193.47.62.167:45452] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:12:42.484309 2026] [security2:error] [pid 849392:tid 849552] [client 101.226.10.126:45738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUGgMgr4yz2OQW0xripgAAAKI"]
[Thu Jul 30 13:12:43.102186 2026] [security2:error] [pid 849392:tid 849634] [client 112.84.177.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuUGgMgr4yz2OQW0xripAAAAPQ"]
[Thu Jul 30 13:12:43.169263 2026] [security2:error] [pid 849392:tid 849547] [client 101.226.10.126:45788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUGwMgr4yz2OQW0xriqwAAAJ0"]
[Thu Jul 30 13:12:43.356135 2026] [security2:error] [pid 849392:tid 849570] [client 184.75.223.203:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuUGwMgr4yz2OQW0xrirAAAALQ"]
[Thu Jul 30 13:12:43.356246 2026] [security2:error] [pid 849392:tid 849570] [client 184.75.223.203:55736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuUGwMgr4yz2OQW0xrirAAAALQ"]
[Thu Jul 30 13:12:43.644266 2026] [proxy:error] [pid 849392:tid 849540] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:43.644347 2026] [proxy_http:error] [pid 849392:tid 849540] [client 3.228.112.215:35454] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:43.645049 2026] [proxy:error] [pid 849392:tid 849540] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:43.645109 2026] [proxy_http:error] [pid 849392:tid 849540] [client 3.228.112.215:35454] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:43.674718 2026] [proxy:error] [pid 849392:tid 849535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:43.674797 2026] [proxy_http:error] [pid 849392:tid 849535] [client 54.87.222.253:52314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:43.675514 2026] [proxy:error] [pid 849392:tid 849535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:43.675564 2026] [proxy_http:error] [pid 849392:tid 849535] [client 54.87.222.253:52314] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:44.781603 2026] [security2:error] [pid 849392:tid 849557] [client 101.226.10.126:45788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:vars[1][]. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "phpinfo(,ARGS:vars[1][]"] [severity "CRITICAL"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUHAMgr4yz2OQW0xriyAAAAKc"]
[Thu Jul 30 13:12:44.781767 2026] [security2:error] [pid 849392:tid 849557] [client 101.226.10.126:45788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUHAMgr4yz2OQW0xriyAAAAKc"]
[Thu Jul 30 13:12:44.782580 2026] [security2:error] [pid 849392:tid 849623] [client 179.64.21.229:17827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUHAMgr4yz2OQW0xriyQAAAOk"]
[Thu Jul 30 13:12:44.790138 2026] [security2:error] [pid 849392:tid 849623] [client 179.64.21.229:17827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUHAMgr4yz2OQW0xriyQAAAOk"]
[Thu Jul 30 13:12:45.052546 2026] [security2:error] [pid 849392:tid 849628] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUHAMgr4yz2OQW0xrixgAAAO4"]
[Thu Jul 30 13:12:45.108863 2026] [security2:error] [pid 849392:tid 849633] [client 101.226.10.126:45788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:chr|fwrite|fopen|system|echr|passthru|serialize|include|php_uname|popen|proc_open|shell_exec|mysql_query|eval|str_rot13|exec|proc_nice|proc_terminate|proc_get_status|proc_close|pfsockopen|leak|apache_child_terminate|posix_kill|posix_mkfifo|posix_ ..." at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "789"] [id "340128"] [rev "25"] [msg "Atomicorp.com WAF Rules: Remote PHP command exection"] [data "<?"] [severity "CRITICAL"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUHQMgr4yz2OQW0xrizQAAAPM"]
[Thu Jul 30 13:12:45.108990 2026] [security2:error] [pid 849392:tid 849633] [client 101.226.10.126:45788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUHQMgr4yz2OQW0xrizQAAAPM"]
[Thu Jul 30 13:12:45.193267 2026] [core:notice] [pid 849392:tid 849564] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:45.649609 2026] [security2:error] [pid 849392:tid 849612] [client 20.215.191.139:56570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/dropdown.php"] [unique_id "amuUHQMgr4yz2OQW0xri0wAAAN4"]
[Thu Jul 30 13:12:45.755558 2026] [security2:error] [pid 849392:tid 849586] [client 101.226.10.126:45968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUHQMgr4yz2OQW0xri1QAAAMQ"]
[Thu Jul 30 13:12:45.891529 2026] [security2:error] [pid 849392:tid 849621] [client 112.84.177.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuUHQMgr4yz2OQW0xri0AAAAOc"], referer: http://smoke-tfhk.com/product-tag/ploom-x-aura-mevius-citrus-option%E6%AA%B8%E6%AA%AC%E7%88%86%E7%8F%A0%E7%85%99%E5%BD%88/feed/
[Thu Jul 30 13:12:46.415204 2026] [autoindex:error] [pid 849392:tid 849558] [client 32.194.121.99:47569] AH01276: Cannot serve directory /home2/zorudite/public_html/website_041a3cce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:12:46.543015 2026] [autoindex:error] [pid 849392:tid 849543] [client 104.28.156.61:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:12:46.593929 2026] [security2:error] [pid 849392:tid 849523] [client 20.215.191.139:59859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/edit.php"] [unique_id "amuUHgMgr4yz2OQW0xri2wAAAIU"]
[Thu Jul 30 13:12:46.702001 2026] [security2:error] [pid 849392:tid 849532] [client 101.226.10.126:45968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUHgMgr4yz2OQW0xri3AAAAI4"]
[Thu Jul 30 13:12:47.020555 2026] [security2:error] [pid 849392:tid 849596] [client 101.226.10.126:45968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUHwMgr4yz2OQW0xri3gAAAM4"]
[Thu Jul 30 13:12:47.152139 2026] [security2:error] [pid 849392:tid 849588] [client 154.159.252.63:13346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri4wAAxkU"], referer: https://rocket-bookkeepers.com/news
[Thu Jul 30 13:12:47.169900 2026] [security2:error] [pid 849392:tid 849588] [client 154.159.252.63:13346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri4gAAxjo"], referer: https://rocket-bookkeepers.com/news
[Thu Jul 30 13:12:47.170078 2026] [security2:error] [pid 849392:tid 849588] [client 154.159.252.63:13346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri3wAAxkg"], referer: https://rocket-bookkeepers.com/news
[Thu Jul 30 13:12:47.172063 2026] [security2:error] [pid 849392:tid 849588] [client 154.159.252.63:13346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri5AAAxiQ"], referer: https://rocket-bookkeepers.com/news
[Thu Jul 30 13:12:47.177958 2026] [security2:error] [pid 849392:tid 849588] [client 154.159.252.63:13346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri4AAAxjU"], referer: https://rocket-bookkeepers.com/news
[Thu Jul 30 13:12:47.178069 2026] [security2:error] [pid 849392:tid 849588] [client 154.159.252.63:13346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri4QAAxjE"], referer: https://rocket-bookkeepers.com/news
[Thu Jul 30 13:12:47.181186 2026] [security2:error] [pid 849392:tid 849588] [client 154.159.252.63:13346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri5QAAxkc"], referer: https://rocket-bookkeepers.com/news
[Thu Jul 30 13:12:47.189701 2026] [security2:error] [pid 849392:tid 849588] [client 154.159.252.63:13346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri5gAAxjs"], referer: https://rocket-bookkeepers.com/news
[Thu Jul 30 13:12:47.713009 2026] [security2:error] [pid 849392:tid 849557] [client 101.226.10.126:46120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUHwMgr4yz2OQW0xri7wAAAKc"]
[Thu Jul 30 13:12:47.781994 2026] [security2:error] [pid 849392:tid 849631] [client 172.236.9.101:34971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri5wAAAPE"]
[Thu Jul 30 13:12:47.789906 2026] [security2:error] [pid 849392:tid 849536] [client 195.63.25.67:25152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuUHwMgr4yz2OQW0xri7gAAkjM"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 13:12:47.890775 2026] [security2:error] [pid 849392:tid 849641] [client 172.236.9.101:22736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri6AAAAPs"]
[Thu Jul 30 13:12:48.060993 2026] [core:notice] [pid 849392:tid 849615] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:48.065045 2026] [security2:error] [pid 849392:tid 849615] [client 169.224.68.216:34560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/8711"] [unique_id "amuUHwMgr4yz2OQW0xri8AAAAOE"]
[Thu Jul 30 13:12:48.157083 2026] [security2:error] [pid 849392:tid 849589] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUHwMgr4yz2OQW0xri7QAAAMc"]
[Thu Jul 30 13:12:48.404529 2026] [security2:error] [pid 849392:tid 849537] [client 101.226.10.126:46166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUIAMgr4yz2OQW0xri8QAAAJM"]
[Thu Jul 30 13:12:48.849623 2026] [security2:error] [pid 849392:tid 849595] [client 20.215.191.139:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/f35.php"] [unique_id "amuUIAMgr4yz2OQW0xri_QAAAM0"]
[Thu Jul 30 13:12:48.881836 2026] [security2:error] [pid 849392:tid 849472] [remote 216.73.217.142:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUIAMgr4yz2OQW0xri_gAA9U4"]
[Thu Jul 30 13:12:49.030934 2026] [security2:error] [pid 849392:tid 849601] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUIAMgr4yz2OQW0xri9AAAANM"]
[Thu Jul 30 13:12:49.379959 2026] [security2:error] [pid 849392:tid 849592] [client 101.226.10.126:46166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "phpinfo(,ARGS:s"] [severity "CRITICAL"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUIQMgr4yz2OQW0xrjCQAAAMo"]
[Thu Jul 30 13:12:49.380103 2026] [security2:error] [pid 849392:tid 849592] [client 101.226.10.126:46166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUIQMgr4yz2OQW0xrjCQAAAMo"]
[Thu Jul 30 13:12:49.430626 2026] [security2:error] [pid 849392:tid 849649] [client 20.215.191.139:60073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/f7.php"] [unique_id "amuUIQMgr4yz2OQW0xrjCgAAAQM"]
[Thu Jul 30 13:12:49.439415 2026] [security2:error] [pid 849392:tid 849570] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUIAMgr4yz2OQW0xri_AAAALQ"]
[Thu Jul 30 13:12:50.021416 2026] [security2:error] [pid 849392:tid 849526] [client 101.226.10.126:46290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "rockyeahshirts.com"] [uri "/index.html"] [unique_id "amuUIgMgr4yz2OQW0xrjDAAAAIg"]
[Thu Jul 30 13:12:50.423884 2026] [security2:error] [pid 849392:tid 849491] [remote 57.141.0.34:54350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6113126855/feed/rss2/"] [unique_id "amuUIgMgr4yz2OQW0xrjHgAAs2E"]
[Thu Jul 30 13:12:50.545295 2026] [security2:error] [pid 849392:tid 849493] [remote 54.37.118.79:23850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/services-etatiques-et-paraetatiques/"] [unique_id "amuUIgMgr4yz2OQW0xrjIQAA2GM"]
[Thu Jul 30 13:12:50.545527 2026] [security2:error] [pid 849392:tid 849606] [client 54.37.118.79:23850] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/services-etatiques-et-paraetatiques/"] [unique_id "amuUIgMgr4yz2OQW0xrjIQAA2GM"]
[Thu Jul 30 13:12:50.686894 2026] [security2:error] [pid 849392:tid 849589] [client 101.226.10.126:46336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "phpinfo(,ARGS:s"] [severity "CRITICAL"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUIgMgr4yz2OQW0xrjIgAAAMc"]
[Thu Jul 30 13:12:50.687017 2026] [security2:error] [pid 849392:tid 849589] [client 101.226.10.126:46336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rockyeahshirts.com"] [uri "/"] [unique_id "amuUIgMgr4yz2OQW0xrjIgAAAMc"]
[Thu Jul 30 13:12:50.894870 2026] [security2:error] [pid 849392:tid 849546] [client 172.236.9.101:35346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUIgMgr4yz2OQW0xrjHwAAAJw"]
[Thu Jul 30 13:12:51.438938 2026] [core:notice] [pid 849392:tid 849640] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:51.628830 2026] [security2:error] [pid 849392:tid 849608] [client 101.226.10.126:46382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUIwMgr4yz2OQW0xrjKQAAANo"]
[Thu Jul 30 13:12:51.629044 2026] [security2:error] [pid 849392:tid 849608] [client 101.226.10.126:46382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUIwMgr4yz2OQW0xrjKQAAANo"]
[Thu Jul 30 13:12:51.720945 2026] [security2:error] [pid 849392:tid 849501] [remote 57.141.0.3:21360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amuUIwMgr4yz2OQW0xrjMgAAqGs"]
[Thu Jul 30 13:12:52.008364 2026] [security2:error] [pid 849392:tid 849597] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuUJAMgr4yz2OQW0xrjNAAAAM8"]
[Thu Jul 30 13:12:52.008531 2026] [security2:error] [pid 849392:tid 849597] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuUJAMgr4yz2OQW0xrjNAAAAM8"]
[Thu Jul 30 13:12:52.309923 2026] [security2:error] [pid 849392:tid 849591] [client 101.226.10.126:46458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJAMgr4yz2OQW0xrjNwAAAMk"]
[Thu Jul 30 13:12:52.310050 2026] [security2:error] [pid 849392:tid 849591] [client 101.226.10.126:46458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJAMgr4yz2OQW0xrjNwAAAMk"]
[Thu Jul 30 13:12:52.546331 2026] [security2:error] [pid 849392:tid 849619] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuUJAMgr4yz2OQW0xrjOAAAAOU"]
[Thu Jul 30 13:12:52.546454 2026] [security2:error] [pid 849392:tid 849619] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuUJAMgr4yz2OQW0xrjOAAAAOU"]
[Thu Jul 30 13:12:52.884955 2026] [core:notice] [pid 849392:tid 849650] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:53.014590 2026] [security2:error] [pid 849392:tid 849632] [client 101.226.10.126:46498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJQMgr4yz2OQW0xrjOwAAAPI"]
[Thu Jul 30 13:12:53.014736 2026] [security2:error] [pid 849392:tid 849632] [client 101.226.10.126:46498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJQMgr4yz2OQW0xrjOwAAAPI"]
[Thu Jul 30 13:12:53.059438 2026] [security2:error] [pid 849392:tid 849564] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wicked.php"] [unique_id "amuUJQMgr4yz2OQW0xrjPQAAAK4"]
[Thu Jul 30 13:12:53.059548 2026] [security2:error] [pid 849392:tid 849564] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wicked.php"] [unique_id "amuUJQMgr4yz2OQW0xrjPQAAAK4"]
[Thu Jul 30 13:12:53.428301 2026] [core:notice] [pid 849392:tid 849573] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:53.553036 2026] [core:notice] [pid 849392:tid 849512] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:53.568252 2026] [security2:error] [pid 849392:tid 849613] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wpx.php"] [unique_id "amuUJQMgr4yz2OQW0xrjQAAAAN8"]
[Thu Jul 30 13:12:53.568342 2026] [security2:error] [pid 849392:tid 849613] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wpx.php"] [unique_id "amuUJQMgr4yz2OQW0xrjQAAAAN8"]
[Thu Jul 30 13:12:53.672358 2026] [security2:error] [pid 849392:tid 849550] [client 101.226.10.126:46546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJQMgr4yz2OQW0xrjQQAAAKA"]
[Thu Jul 30 13:12:53.672517 2026] [security2:error] [pid 849392:tid 849550] [client 101.226.10.126:46546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJQMgr4yz2OQW0xrjQQAAAKA"]
[Thu Jul 30 13:12:54.094973 2026] [security2:error] [pid 849392:tid 849640] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/images.php"] [unique_id "amuUJgMgr4yz2OQW0xrjRQAAAPo"]
[Thu Jul 30 13:12:54.095102 2026] [security2:error] [pid 849392:tid 849640] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/images.php"] [unique_id "amuUJgMgr4yz2OQW0xrjRQAAAPo"]
[Thu Jul 30 13:12:54.310632 2026] [security2:error] [pid 849392:tid 849576] [client 101.226.10.126:46592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php/module/action/param1/$%7B@print%28md5%282333%29%29%7D"] [unique_id "amuUJgMgr4yz2OQW0xrjRwAAALo"]
[Thu Jul 30 13:12:54.310785 2026] [security2:error] [pid 849392:tid 849576] [client 101.226.10.126:46592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php/module/action/param1/$%7B@print%28md5%282333%29%29%7D"] [unique_id "amuUJgMgr4yz2OQW0xrjRwAAALo"]
[Thu Jul 30 13:12:54.623803 2026] [security2:error] [pid 849392:tid 849630] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/1xmomo.php"] [unique_id "amuUJgMgr4yz2OQW0xrjTAAAAPA"]
[Thu Jul 30 13:12:54.623928 2026] [security2:error] [pid 849392:tid 849630] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/1xmomo.php"] [unique_id "amuUJgMgr4yz2OQW0xrjTAAAAPA"]
[Thu Jul 30 13:12:54.735296 2026] [proxy:error] [pid 849392:tid 849592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:54.735366 2026] [proxy_http:error] [pid 849392:tid 849592] [client 3.225.222.228:39993] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:54.735920 2026] [proxy:error] [pid 849392:tid 849592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:54.735963 2026] [proxy_http:error] [pid 849392:tid 849592] [client 3.225.222.228:39993] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:54.758882 2026] [security2:error] [pid 849392:tid 849539] [client 172.236.9.101:44498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUJgMgr4yz2OQW0xrjRgAAAJU"]
[Thu Jul 30 13:12:54.783937 2026] [proxy:error] [pid 849392:tid 849559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:54.784052 2026] [proxy_http:error] [pid 849392:tid 849559] [client 3.225.222.228:1239] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:54.784623 2026] [proxy:error] [pid 849392:tid 849559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:54.784666 2026] [proxy_http:error] [pid 849392:tid 849559] [client 3.225.222.228:1239] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:54.839595 2026] [security2:error] [pid 849392:tid 849523] [client 172.236.9.101:33667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUJgMgr4yz2OQW0xrjSAAAAIU"]
[Thu Jul 30 13:12:54.958880 2026] [security2:error] [pid 849392:tid 849591] [client 101.226.10.126:46638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJgMgr4yz2OQW0xrjWgAAAMk"]
[Thu Jul 30 13:12:54.959012 2026] [security2:error] [pid 849392:tid 849591] [client 101.226.10.126:46638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJgMgr4yz2OQW0xrjWgAAAMk"]
[Thu Jul 30 13:12:55.120911 2026] [security2:error] [pid 849392:tid 849610] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/1revo.php"] [unique_id "amuUJwMgr4yz2OQW0xrjWwAAANw"]
[Thu Jul 30 13:12:55.121048 2026] [security2:error] [pid 849392:tid 849610] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/1revo.php"] [unique_id "amuUJwMgr4yz2OQW0xrjWwAAANw"]
[Thu Jul 30 13:12:55.230666 2026] [security2:error] [pid 849392:tid 849552] [client 162.243.64.70:38636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.trustedmoversandpackersabudhabi.online"] [uri "/.env"] [unique_id "amuUJwMgr4yz2OQW0xrjXAAAAKI"]
[Thu Jul 30 13:12:55.622988 2026] [security2:error] [pid 849392:tid 849642] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cong.php"] [unique_id "amuUJwMgr4yz2OQW0xrjYAAAAPw"]
[Thu Jul 30 13:12:55.623098 2026] [security2:error] [pid 849392:tid 849642] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/cong.php"] [unique_id "amuUJwMgr4yz2OQW0xrjYAAAAPw"]
[Thu Jul 30 13:12:55.628607 2026] [security2:error] [pid 849392:tid 849613] [client 101.226.10.126:46678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJwMgr4yz2OQW0xrjYQAAAN8"]
[Thu Jul 30 13:12:55.628678 2026] [security2:error] [pid 849392:tid 849613] [client 101.226.10.126:46678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUJwMgr4yz2OQW0xrjYQAAAN8"]
[Thu Jul 30 13:12:56.008738 2026] [security2:error] [pid 849392:tid 849538] [client 179.64.21.229:39916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUKAMgr4yz2OQW0xrjZgAAAJQ"]
[Thu Jul 30 13:12:56.016003 2026] [security2:error] [pid 849392:tid 849538] [client 179.64.21.229:39916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUKAMgr4yz2OQW0xrjZgAAAJQ"]
[Thu Jul 30 13:12:56.123882 2026] [security2:error] [pid 849392:tid 849605] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/a.php"] [unique_id "amuUKAMgr4yz2OQW0xrjbQAAANc"]
[Thu Jul 30 13:12:56.124098 2026] [security2:error] [pid 849392:tid 849605] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/a.php"] [unique_id "amuUKAMgr4yz2OQW0xrjbQAAANc"]
[Thu Jul 30 13:12:56.158333 2026] [autoindex:error] [pid 849392:tid 849545] [client 3.225.222.228:27857] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:12:56.167749 2026] [autoindex:error] [pid 849392:tid 849570] [client 44.213.206.96:7099] AH01276: Cannot serve directory /home1/uixgzjte/public_html/chicago-mfg.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:12:56.283555 2026] [security2:error] [pid 849392:tid 849572] [client 101.226.10.126:46732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKAMgr4yz2OQW0xrjcQAAALY"]
[Thu Jul 30 13:12:56.283659 2026] [security2:error] [pid 849392:tid 849572] [client 101.226.10.126:46732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKAMgr4yz2OQW0xrjcQAAALY"]
[Thu Jul 30 13:12:56.474363 2026] [core:notice] [pid 849392:tid 849543] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:12:56.567750 2026] [security2:error] [pid 849392:tid 849595] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUJwMgr4yz2OQW0xrjZAAAAM0"]
[Thu Jul 30 13:12:56.627756 2026] [security2:error] [pid 849392:tid 849639] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/srontol.php"] [unique_id "amuUKAMgr4yz2OQW0xrjdQAAAPk"]
[Thu Jul 30 13:12:56.627859 2026] [security2:error] [pid 849392:tid 849639] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/srontol.php"] [unique_id "amuUKAMgr4yz2OQW0xrjdQAAAPk"]
[Thu Jul 30 13:12:56.854594 2026] [security2:error] [pid 849392:tid 849630] [client 172.236.9.101:64323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUKAMgr4yz2OQW0xrjcgAAAPA"]
[Thu Jul 30 13:12:56.951863 2026] [security2:error] [pid 849392:tid 849610] [client 101.226.10.126:46784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKAMgr4yz2OQW0xrjeQAAANw"]
[Thu Jul 30 13:12:56.951952 2026] [security2:error] [pid 849392:tid 849610] [client 101.226.10.126:46784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKAMgr4yz2OQW0xrjeQAAANw"]
[Thu Jul 30 13:12:57.157477 2026] [security2:error] [pid 849392:tid 849534] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/reop3.php"] [unique_id "amuUKQMgr4yz2OQW0xrjegAAAJA"]
[Thu Jul 30 13:12:57.157592 2026] [security2:error] [pid 849392:tid 849534] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/reop3.php"] [unique_id "amuUKQMgr4yz2OQW0xrjegAAAJA"]
[Thu Jul 30 13:12:57.630680 2026] [security2:error] [pid 849392:tid 849537] [client 101.226.10.126:46832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKQMgr4yz2OQW0xrjewAAAJM"]
[Thu Jul 30 13:12:57.630835 2026] [security2:error] [pid 849392:tid 849537] [client 101.226.10.126:46832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKQMgr4yz2OQW0xrjewAAAJM"]
[Thu Jul 30 13:12:57.665236 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/file5.php"] [unique_id "amuUKQMgr4yz2OQW0xrjfAAAALc"]
[Thu Jul 30 13:12:57.665353 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/file5.php"] [unique_id "amuUKQMgr4yz2OQW0xrjfAAAALc"]
[Thu Jul 30 13:12:58.191585 2026] [security2:error] [pid 849392:tid 849624] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/domvf.php"] [unique_id "amuUKgMgr4yz2OQW0xrjgAAAAOo"]
[Thu Jul 30 13:12:58.191734 2026] [security2:error] [pid 849392:tid 849624] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/domvf.php"] [unique_id "amuUKgMgr4yz2OQW0xrjgAAAAOo"]
[Thu Jul 30 13:12:58.306118 2026] [security2:error] [pid 849392:tid 849556] [client 101.226.10.126:46902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKgMgr4yz2OQW0xrjggAAAKY"]
[Thu Jul 30 13:12:58.306225 2026] [security2:error] [pid 849392:tid 849556] [client 101.226.10.126:46902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKgMgr4yz2OQW0xrjggAAAKY"]
[Thu Jul 30 13:12:58.567347 2026] [core:error] [pid 849392:tid 849527] [client 47.253.5.130:52462] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Jul 30 13:12:58.700826 2026] [security2:error] [pid 849392:tid 849532] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/zero.php"] [unique_id "amuUKgMgr4yz2OQW0xrjhwAAAI4"]
[Thu Jul 30 13:12:58.700927 2026] [security2:error] [pid 849392:tid 849532] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/zero.php"] [unique_id "amuUKgMgr4yz2OQW0xrjhwAAAI4"]
[Thu Jul 30 13:12:58.724066 2026] [security2:error] [pid 849392:tid 849565] [client 172.236.9.101:14592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUKgMgr4yz2OQW0xrjgQAAAK8"]
[Thu Jul 30 13:12:59.005798 2026] [security2:error] [pid 849392:tid 849568] [client 101.226.10.126:46974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKwMgr4yz2OQW0xrjiQAAALI"]
[Thu Jul 30 13:12:59.005918 2026] [security2:error] [pid 849392:tid 849568] [client 101.226.10.126:46974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKwMgr4yz2OQW0xrjiQAAALI"]
[Thu Jul 30 13:12:59.203486 2026] [security2:error] [pid 849392:tid 849574] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/002.php"] [unique_id "amuUKwMgr4yz2OQW0xrjigAAALg"]
[Thu Jul 30 13:12:59.203609 2026] [security2:error] [pid 849392:tid 849574] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/002.php"] [unique_id "amuUKwMgr4yz2OQW0xrjigAAALg"]
[Thu Jul 30 13:12:59.511531 2026] [proxy:error] [pid 849392:tid 849626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:59.511608 2026] [proxy_http:error] [pid 849392:tid 849626] [client 54.87.222.253:61322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:59.512593 2026] [proxy:error] [pid 849392:tid 849626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:59.512648 2026] [proxy_http:error] [pid 849392:tid 849626] [client 54.87.222.253:61322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:59.554061 2026] [proxy:error] [pid 849392:tid 849646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:59.554156 2026] [proxy_http:error] [pid 849392:tid 849646] [client 54.87.222.253:64142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:59.555027 2026] [proxy:error] [pid 849392:tid 849646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:12:59.555090 2026] [proxy_http:error] [pid 849392:tid 849646] [client 54.87.222.253:64142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:12:59.676876 2026] [security2:error] [pid 849392:tid 849600] [client 101.226.10.126:47026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKwMgr4yz2OQW0xrjmgAAANI"]
[Thu Jul 30 13:12:59.677002 2026] [security2:error] [pid 849392:tid 849600] [client 101.226.10.126:47026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUKwMgr4yz2OQW0xrjmgAAANI"]
[Thu Jul 30 13:12:59.709508 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/thoms.php"] [unique_id "amuUKwMgr4yz2OQW0xrjmwAAAPE"]
[Thu Jul 30 13:12:59.709605 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/thoms.php"] [unique_id "amuUKwMgr4yz2OQW0xrjmwAAAPE"]
[Thu Jul 30 13:12:59.965771 2026] [security2:error] [pid 849392:tid 849486] [remote 216.73.217.142:31153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUKwMgr4yz2OQW0xrjnAAA4Vw"]
[Thu Jul 30 13:13:00.218845 2026] [security2:error] [pid 849392:tid 849602] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/fi22.php"] [unique_id "amuULAMgr4yz2OQW0xrjoAAAANQ"]
[Thu Jul 30 13:13:00.218947 2026] [security2:error] [pid 849392:tid 849602] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/fi22.php"] [unique_id "amuULAMgr4yz2OQW0xrjoAAAANQ"]
[Thu Jul 30 13:13:00.317057 2026] [security2:error] [pid 849392:tid 849585] [client 101.226.10.126:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuULAMgr4yz2OQW0xrjogAAAMM"]
[Thu Jul 30 13:13:00.317156 2026] [security2:error] [pid 849392:tid 849585] [client 101.226.10.126:47072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuULAMgr4yz2OQW0xrjogAAAMM"]
[Thu Jul 30 13:13:00.735418 2026] [security2:error] [pid 849392:tid 849547] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.markmocek.com"] [uri "/___proxy_subdomain_webmail/wp-content/"] [unique_id "amuULAMgr4yz2OQW0xrjpAAAAJ0"]
[Thu Jul 30 13:13:00.973048 2026] [security2:error] [pid 849392:tid 849609] [client 101.226.10.126:47110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuULAMgr4yz2OQW0xrjpwAAANs"]
[Thu Jul 30 13:13:00.973155 2026] [security2:error] [pid 849392:tid 849609] [client 101.226.10.126:47110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuULAMgr4yz2OQW0xrjpwAAANs"]
[Thu Jul 30 13:13:00.982636 2026] [security2:error] [pid 849392:tid 849560] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/82.php"] [unique_id "amuULAMgr4yz2OQW0xrjqQAAAKo"]
[Thu Jul 30 13:13:00.982719 2026] [security2:error] [pid 849392:tid 849560] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/82.php"] [unique_id "amuULAMgr4yz2OQW0xrjqQAAAKo"]
[Thu Jul 30 13:13:01.065580 2026] [core:notice] [pid 849392:tid 849624] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:13:01.481764 2026] [security2:error] [pid 849392:tid 849555] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/sx.php"] [unique_id "amuULQMgr4yz2OQW0xrjsQAAAKU"]
[Thu Jul 30 13:13:01.481868 2026] [security2:error] [pid 849392:tid 849555] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/sx.php"] [unique_id "amuULQMgr4yz2OQW0xrjsQAAAKU"]
[Thu Jul 30 13:13:01.706491 2026] [security2:error] [pid 849392:tid 849595] [client 101.226.10.126:47154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuULQMgr4yz2OQW0xrjswAAAM0"]
[Thu Jul 30 13:13:01.706605 2026] [security2:error] [pid 849392:tid 849595] [client 101.226.10.126:47154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuULQMgr4yz2OQW0xrjswAAAM0"]
[Thu Jul 30 13:13:01.786917 2026] [security2:error] [pid 849392:tid 849584] [client 172.213.232.128:50352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/json.php"] [unique_id "amuULQMgr4yz2OQW0xrjtAAAAMI"]
[Thu Jul 30 13:13:01.969022 2026] [security2:error] [pid 849392:tid 849617] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/dex.php"] [unique_id "amuULQMgr4yz2OQW0xrjtQAAAOM"]
[Thu Jul 30 13:13:01.969181 2026] [security2:error] [pid 849392:tid 849617] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/dex.php"] [unique_id "amuULQMgr4yz2OQW0xrjtQAAAOM"]
[Thu Jul 30 13:13:02.441957 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/fpwch.php"] [unique_id "amuULgMgr4yz2OQW0xrjuQAAAPE"]
[Thu Jul 30 13:13:02.442087 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/fpwch.php"] [unique_id "amuULgMgr4yz2OQW0xrjuQAAAPE"]
[Thu Jul 30 13:13:02.536933 2026] [security2:error] [pid 849392:tid 849623] [client 172.213.232.128:50641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/mini.php"] [unique_id "amuULgMgr4yz2OQW0xrjvgAAAOk"]
[Thu Jul 30 13:13:02.682722 2026] [proxy:error] [pid 849392:tid 849606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:13:02.682802 2026] [proxy_http:error] [pid 849392:tid 849606] [client 64.227.150.71:45442] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:13:02.683557 2026] [proxy:error] [pid 849392:tid 849606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:13:02.683610 2026] [proxy_http:error] [pid 849392:tid 849606] [client 64.227.150.71:45442] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:13:02.716903 2026] [proxy:error] [pid 849392:tid 849643] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:13:02.716989 2026] [proxy_http:error] [pid 849392:tid 849643] [client 64.227.150.71:45450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.psz.dtn.temporary.site/
[Thu Jul 30 13:13:02.717571 2026] [proxy:error] [pid 849392:tid 849643] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:13:02.717615 2026] [proxy_http:error] [pid 849392:tid 849643] [client 64.227.150.71:45450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.psz.dtn.temporary.site/
[Thu Jul 30 13:13:02.784365 2026] [proxy:error] [pid 849392:tid 849634] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:13:02.784431 2026] [proxy_http:error] [pid 849392:tid 849634] [client 64.227.150.71:36326] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:13:02.785001 2026] [proxy:error] [pid 849392:tid 849634] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:13:02.785050 2026] [proxy_http:error] [pid 849392:tid 849634] [client 64.227.150.71:36326] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:13:02.951646 2026] [security2:error] [pid 849392:tid 849533] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/black.php"] [unique_id "amuULgMgr4yz2OQW0xrjwwAAAI8"]
[Thu Jul 30 13:13:02.951758 2026] [security2:error] [pid 849392:tid 849533] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/black.php"] [unique_id "amuULgMgr4yz2OQW0xrjwwAAAI8"]
[Thu Jul 30 13:13:03.182426 2026] [proxy:error] [pid 849392:tid 849603] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:13:03.182526 2026] [proxy_http:error] [pid 849392:tid 849603] [client 64.227.150.71:36408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.psz.dtn.temporary.site/
[Thu Jul 30 13:13:03.183751 2026] [proxy:error] [pid 849392:tid 849603] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:13:03.183820 2026] [proxy_http:error] [pid 849392:tid 849603] [client 64.227.150.71:36408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.psz.dtn.temporary.site/
[Thu Jul 30 13:13:03.436636 2026] [security2:error] [pid 849392:tid 849636] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/loader.php"] [unique_id "amuULwMgr4yz2OQW0xrjzAAAAPY"]
[Thu Jul 30 13:13:03.436746 2026] [security2:error] [pid 849392:tid 849636] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/loader.php"] [unique_id "amuULwMgr4yz2OQW0xrjzAAAAPY"]
[Thu Jul 30 13:13:03.759248 2026] [security2:error] [pid 849392:tid 849563] [client 101.226.10.126:47326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuULwMgr4yz2OQW0xrj0QAAAK0"]
[Thu Jul 30 13:13:03.759374 2026] [security2:error] [pid 849392:tid 849563] [client 101.226.10.126:47326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuULwMgr4yz2OQW0xrj0QAAAK0"]
[Thu Jul 30 13:13:03.914094 2026] [security2:error] [pid 849392:tid 849561] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/file61.php"] [unique_id "amuULwMgr4yz2OQW0xrj0gAAAKs"]
[Thu Jul 30 13:13:03.914203 2026] [security2:error] [pid 849392:tid 849561] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/file61.php"] [unique_id "amuULwMgr4yz2OQW0xrj0gAAAKs"]
[Thu Jul 30 13:13:04.205828 2026] [security2:error] [pid 849392:tid 849581] [client 172.213.232.128:50374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/chosen.php"] [unique_id "amuUMAMgr4yz2OQW0xrj1wAAAL8"]
[Thu Jul 30 13:13:04.429864 2026] [security2:error] [pid 849392:tid 849574] [client 101.226.10.126:47374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUMAMgr4yz2OQW0xrj2QAAALg"]
[Thu Jul 30 13:13:04.430012 2026] [security2:error] [pid 849392:tid 849574] [client 101.226.10.126:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUMAMgr4yz2OQW0xrj2QAAALg"]
[Thu Jul 30 13:13:04.432543 2026] [security2:error] [pid 849392:tid 849576] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-css.php"] [unique_id "amuUMAMgr4yz2OQW0xrj2gAAALo"]
[Thu Jul 30 13:13:04.432663 2026] [security2:error] [pid 849392:tid 849576] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-css.php"] [unique_id "amuUMAMgr4yz2OQW0xrj2gAAALo"]
[Thu Jul 30 13:13:04.654104 2026] [autoindex:error] [pid 849392:tid 849592] [client 3.86.48.13:0] AH01276: Cannot serve directory /home2/plsudite/public_html/website_56dea235/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Thu Jul 30 13:13:04.964579 2026] [security2:error] [pid 849392:tid 849548] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-blink.php"] [unique_id "amuUMAMgr4yz2OQW0xrj5QAAAJ4"]
[Thu Jul 30 13:13:04.964704 2026] [security2:error] [pid 849392:tid 849548] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-blink.php"] [unique_id "amuUMAMgr4yz2OQW0xrj5QAAAJ4"]
[Thu Jul 30 13:13:05.081077 2026] [security2:error] [pid 849392:tid 849595] [client 101.226.10.126:47440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/public/index.php"] [unique_id "amuUMQMgr4yz2OQW0xrj6QAAAM0"]
[Thu Jul 30 13:13:05.081233 2026] [security2:error] [pid 849392:tid 849595] [client 101.226.10.126:47440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/public/index.php"] [unique_id "amuUMQMgr4yz2OQW0xrj6QAAAM0"]
[Thu Jul 30 13:13:05.133852 2026] [security2:error] [pid 849392:tid 849499] [remote 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUMAMgr4yz2OQW0xrj3gABAmk"]
[Thu Jul 30 13:13:05.393325 2026] [core:error] [pid 849392:tid 849597] [client 3.86.48.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Jul 30 13:13:05.393349 2026] [core:error] [pid 849392:tid 849597] [client 3.86.48.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Jul 30 13:13:05.481123 2026] [security2:error] [pid 849392:tid 849557] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/txets.php"] [unique_id "amuUMQMgr4yz2OQW0xrj_QAAAKc"]
[Thu Jul 30 13:13:05.481248 2026] [security2:error] [pid 849392:tid 849557] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/txets.php"] [unique_id "amuUMQMgr4yz2OQW0xrj_QAAAKc"]
[Thu Jul 30 13:13:05.731463 2026] [security2:error] [pid 849392:tid 849628] [client 101.226.10.126:47490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUMQMgr4yz2OQW0xrkAgAAAO4"]
[Thu Jul 30 13:13:05.731588 2026] [security2:error] [pid 849392:tid 849628] [client 101.226.10.126:47490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUMQMgr4yz2OQW0xrkAgAAAO4"]
[Thu Jul 30 13:13:05.783264 2026] [security2:error] [pid 849392:tid 849639] [client 172.236.9.101:16274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUMQMgr4yz2OQW0xrj-gAAAPk"]
[Thu Jul 30 13:13:05.986718 2026] [core:error] [pid 849392:tid 849643] [client 3.86.48.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Jul 30 13:13:05.986741 2026] [core:error] [pid 849392:tid 849643] [client 3.86.48.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Jul 30 13:13:06.000740 2026] [security2:error] [pid 849392:tid 849582] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/pucci.php"] [unique_id "amuUMQMgr4yz2OQW0xrkCAAAAMA"]
[Thu Jul 30 13:13:06.000889 2026] [security2:error] [pid 849392:tid 849582] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/pucci.php"] [unique_id "amuUMQMgr4yz2OQW0xrkCAAAAMA"]
[Thu Jul 30 13:13:06.402613 2026] [security2:error] [pid 849392:tid 849525] [client 101.226.10.126:47548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUMgMgr4yz2OQW0xrkCgAAAIc"]
[Thu Jul 30 13:13:06.402750 2026] [security2:error] [pid 849392:tid 849525] [client 101.226.10.126:47548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUMgMgr4yz2OQW0xrkCgAAAIc"]
[Thu Jul 30 13:13:06.491612 2026] [security2:error] [pid 849392:tid 849524] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/xwpg.php"] [unique_id "amuUMgMgr4yz2OQW0xrkCwAAAIY"]
[Thu Jul 30 13:13:06.491752 2026] [security2:error] [pid 849392:tid 849524] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/xwpg.php"] [unique_id "amuUMgMgr4yz2OQW0xrkCwAAAIY"]
[Thu Jul 30 13:13:06.509450 2026] [security2:error] [pid 849392:tid 849575] [client 179.64.21.229:51512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUMgMgr4yz2OQW0xrkDwAAALk"]
[Thu Jul 30 13:13:06.509572 2026] [security2:error] [pid 849392:tid 849575] [client 179.64.21.229:51512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUMgMgr4yz2OQW0xrkDwAAALk"]
[Thu Jul 30 13:13:06.642446 2026] [security2:error] [pid 849392:tid 849566] [client 172.213.232.128:50626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/kj.php"] [unique_id "amuUMgMgr4yz2OQW0xrkEQAAALA"]
[Thu Jul 30 13:13:06.921030 2026] [core:error] [pid 849392:tid 849609] [client 3.86.48.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Jul 30 13:13:06.921052 2026] [core:error] [pid 849392:tid 849609] [client 3.86.48.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Jul 30 13:13:06.991352 2026] [security2:error] [pid 849392:tid 849527] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ops.php"] [unique_id "amuUMgMgr4yz2OQW0xrkEwAAAIk"]
[Thu Jul 30 13:13:06.991466 2026] [security2:error] [pid 849392:tid 849527] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ops.php"] [unique_id "amuUMgMgr4yz2OQW0xrkEwAAAIk"]
[Thu Jul 30 13:13:07.104910 2026] [security2:error] [pid 849392:tid 849622] [client 101.226.10.126:47594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php/index"] [unique_id "amuUMwMgr4yz2OQW0xrkFwAAAOg"]
[Thu Jul 30 13:13:07.105031 2026] [security2:error] [pid 849392:tid 849622] [client 101.226.10.126:47594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php/index"] [unique_id "amuUMwMgr4yz2OQW0xrkFwAAAOg"]
[Thu Jul 30 13:13:07.429279 2026] [security2:error] [pid 849392:tid 849538] [client 172.213.232.128:50627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/wp-files.php"] [unique_id "amuUMwMgr4yz2OQW0xrkGwAAAJQ"]
[Thu Jul 30 13:13:07.506055 2026] [security2:error] [pid 849392:tid 849598] [client 20.48.234.177:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.markmocek.com"] [uri "/1.php"] [unique_id "amuUMwMgr4yz2OQW0xrkHgAAANA"]
[Thu Jul 30 13:13:07.506177 2026] [security2:error] [pid 849392:tid 849598] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/1.php"] [unique_id "amuUMwMgr4yz2OQW0xrkHgAAANA"]
[Thu Jul 30 13:13:07.506275 2026] [security2:error] [pid 849392:tid 849598] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/1.php"] [unique_id "amuUMwMgr4yz2OQW0xrkHgAAANA"]
[Thu Jul 30 13:13:07.786790 2026] [security2:error] [pid 849392:tid 849562] [client 101.226.10.126:47640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php/index"] [unique_id "amuUMwMgr4yz2OQW0xrkIAAAAKw"]
[Thu Jul 30 13:13:07.786954 2026] [security2:error] [pid 849392:tid 849562] [client 101.226.10.126:47640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php/index"] [unique_id "amuUMwMgr4yz2OQW0xrkIAAAAKw"]
[Thu Jul 30 13:13:08.026496 2026] [security2:error] [pid 849392:tid 849571] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/mac.php"] [unique_id "amuUNAMgr4yz2OQW0xrkJQAAALU"]
[Thu Jul 30 13:13:08.026609 2026] [security2:error] [pid 849392:tid 849571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/mac.php"] [unique_id "amuUNAMgr4yz2OQW0xrkJQAAALU"]
[Thu Jul 30 13:13:08.353259 2026] [security2:error] [pid 849392:tid 849574] [client 172.213.232.128:8229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/wp-setup.php"] [unique_id "amuUNAMgr4yz2OQW0xrkJgAAALg"]
[Thu Jul 30 13:13:08.474197 2026] [security2:error] [pid 849392:tid 849526] [client 101.226.10.126:47688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUNAMgr4yz2OQW0xrkKAAAAIg"]
[Thu Jul 30 13:13:08.474340 2026] [security2:error] [pid 849392:tid 849526] [client 101.226.10.126:47688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/index.php"] [unique_id "amuUNAMgr4yz2OQW0xrkKAAAAIg"]
[Thu Jul 30 13:13:08.565632 2026] [security2:error] [pid 849392:tid 849648] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuUNAMgr4yz2OQW0xrkKgAAAQI"]
[Thu Jul 30 13:13:08.565729 2026] [security2:error] [pid 849392:tid 849648] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuUNAMgr4yz2OQW0xrkKgAAAQI"]
[Thu Jul 30 13:13:08.662798 2026] [autoindex:error] [pid 849392:tid 849584] [client 3.225.222.228:42625] AH01276: Cannot serve directory /home2/zorudite/public_html/website_041a3cce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:13:09.080090 2026] [security2:error] [pid 849392:tid 849540] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/aa.php"] [unique_id "amuUNQMgr4yz2OQW0xrkMQAAAJY"]
[Thu Jul 30 13:13:09.080197 2026] [security2:error] [pid 849392:tid 849540] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/aa.php"] [unique_id "amuUNQMgr4yz2OQW0xrkMQAAAJY"]
[Thu Jul 30 13:13:09.211001 2026] [security2:error] [pid 849392:tid 849616] [client 101.226.10.126:47736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockyeahshirts.com"] [uri "/fju0mzu.php"] [unique_id "amuUNQMgr4yz2OQW0xrkMgAAAOI"]
[Thu Jul 30 13:13:09.211120 2026] [security2:error] [pid 849392:tid 849616] [client 101.226.10.126:47736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rockyeahshirts.com"] [uri "/fju0mzu.php"] [unique_id "amuUNQMgr4yz2OQW0xrkMgAAAOI"]
[Thu Jul 30 13:13:09.535117 2026] [security2:error] [pid 849392:tid 849539] [client 172.213.232.128:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/defaults.php"] [unique_id "amuUNQMgr4yz2OQW0xrkNwAAAJU"]
[Thu Jul 30 13:13:09.582440 2026] [security2:error] [pid 849392:tid 849641] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/xyn.php"] [unique_id "amuUNQMgr4yz2OQW0xrkOAAAAPs"]
[Thu Jul 30 13:13:09.582904 2026] [security2:error] [pid 849392:tid 849641] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/xyn.php"] [unique_id "amuUNQMgr4yz2OQW0xrkOAAAAPs"]
[Thu Jul 30 13:13:09.723928 2026] [security2:error] [pid 849392:tid 849557] [client 172.236.9.101:15482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUNQMgr4yz2OQW0xrkMwAAAKc"]
[Thu Jul 30 13:13:10.074039 2026] [security2:error] [pid 849392:tid 849628] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-wp.php"] [unique_id "amuUNgMgr4yz2OQW0xrkPAAAAO4"]
[Thu Jul 30 13:13:10.074175 2026] [security2:error] [pid 849392:tid 849628] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-wp.php"] [unique_id "amuUNgMgr4yz2OQW0xrkPAAAAO4"]
[Thu Jul 30 13:13:10.505547 2026] [security2:error] [pid 849392:tid 849509] [remote 216.73.217.142:31153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUNgMgr4yz2OQW0xrkPgAA-XM"]
[Thu Jul 30 13:13:10.509716 2026] [security2:error] [pid 849392:tid 849536] [client 172.213.232.128:50563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/gtc.php"] [unique_id "amuUNgMgr4yz2OQW0xrkPwAAAJI"]
[Thu Jul 30 13:13:10.567911 2026] [security2:error] [pid 849392:tid 849650] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/aw.php"] [unique_id "amuUNgMgr4yz2OQW0xrkQAAAAQQ"]
[Thu Jul 30 13:13:10.568087 2026] [security2:error] [pid 849392:tid 849650] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/aw.php"] [unique_id "amuUNgMgr4yz2OQW0xrkQAAAAQQ"]
[Thu Jul 30 13:13:10.621148 2026] [core:error] [pid 849392:tid 849643] [client 3.86.48.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Jul 30 13:13:10.621175 2026] [core:error] [pid 849392:tid 849643] [client 3.86.48.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.google.com/
[Thu Jul 30 13:13:11.091770 2026] [security2:error] [pid 849392:tid 849575] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuUNwMgr4yz2OQW0xrkRwAAALk"]
[Thu Jul 30 13:13:11.091866 2026] [security2:error] [pid 849392:tid 849575] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuUNwMgr4yz2OQW0xrkRwAAALk"]
[Thu Jul 30 13:13:11.613778 2026] [security2:error] [pid 849392:tid 849613] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/yawa.php"] [unique_id "amuUNwMgr4yz2OQW0xrkSwAAAN8"]
[Thu Jul 30 13:13:11.613885 2026] [security2:error] [pid 849392:tid 849613] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/yawa.php"] [unique_id "amuUNwMgr4yz2OQW0xrkSwAAAN8"]
[Thu Jul 30 13:13:12.009422 2026] [security2:error] [pid 849392:tid 849415] [remote 216.73.217.142:31153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUOAMgr4yz2OQW0xrkUAAA_hU"]
[Thu Jul 30 13:13:12.111928 2026] [security2:error] [pid 849392:tid 849560] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/sym403.php"] [unique_id "amuUOAMgr4yz2OQW0xrkUgAAAKo"]
[Thu Jul 30 13:13:12.112039 2026] [security2:error] [pid 849392:tid 849560] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/sym403.php"] [unique_id "amuUOAMgr4yz2OQW0xrkUgAAAKo"]
[Thu Jul 30 13:13:12.583472 2026] [security2:error] [pid 849392:tid 849533] [client 172.213.232.128:50636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/import.php"] [unique_id "amuUOAMgr4yz2OQW0xrkWQAAAI8"]
[Thu Jul 30 13:13:12.649858 2026] [security2:error] [pid 849392:tid 849535] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.markmocek.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/blue/"] [unique_id "amuUOAMgr4yz2OQW0xrkWgAAAJE"]
[Thu Jul 30 13:13:12.906265 2026] [security2:error] [pid 849392:tid 849578] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/adminner.php"] [unique_id "amuUOAMgr4yz2OQW0xrkXAAAALw"]
[Thu Jul 30 13:13:12.906409 2026] [security2:error] [pid 849392:tid 849578] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/adminner.php"] [unique_id "amuUOAMgr4yz2OQW0xrkXAAAALw"]
[Thu Jul 30 13:13:13.396919 2026] [security2:error] [pid 849392:tid 849558] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/yup.php"] [unique_id "amuUOQMgr4yz2OQW0xrkYAAAAKg"]
[Thu Jul 30 13:13:13.397057 2026] [security2:error] [pid 849392:tid 849558] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/yup.php"] [unique_id "amuUOQMgr4yz2OQW0xrkYAAAAKg"]
[Thu Jul 30 13:13:13.448949 2026] [security2:error] [pid 849392:tid 849627] [client 172.213.232.128:8244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/lufix.php"] [unique_id "amuUOQMgr4yz2OQW0xrkYgAAAO0"]
[Thu Jul 30 13:13:13.877834 2026] [security2:error] [pid 849392:tid 849549] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/config.json.php"] [unique_id "amuUOQMgr4yz2OQW0xrkZQAAAJ8"]
[Thu Jul 30 13:13:13.877946 2026] [security2:error] [pid 849392:tid 849549] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/config.json.php"] [unique_id "amuUOQMgr4yz2OQW0xrkZQAAAJ8"]
[Thu Jul 30 13:13:13.888933 2026] [security2:error] [pid 849392:tid 849611] [client 172.236.9.101:48323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUOQMgr4yz2OQW0xrkYQAAAN0"]
[Thu Jul 30 13:13:14.385238 2026] [security2:error] [pid 849392:tid 849621] [client 172.213.232.128:50657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/Geforce.php"] [unique_id "amuUOgMgr4yz2OQW0xrkaAAAAOc"]
[Thu Jul 30 13:13:14.410802 2026] [security2:error] [pid 849392:tid 849629] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.markmocek.com"] [uri "/___proxy_subdomain_webmail/wp-includes/block-bindings/"] [unique_id "amuUOgMgr4yz2OQW0xrkZwAAAO8"]
[Thu Jul 30 13:13:14.668203 2026] [security2:error] [pid 849392:tid 849648] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/2.php"] [unique_id "amuUOgMgr4yz2OQW0xrkaQAAAQI"]
[Thu Jul 30 13:13:14.668343 2026] [security2:error] [pid 849392:tid 849648] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/2.php"] [unique_id "amuUOgMgr4yz2OQW0xrkaQAAAQI"]
[Thu Jul 30 13:13:14.760201 2026] [core:notice] [pid 849392:tid 849584] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:13:15.176462 2026] [security2:error] [pid 849392:tid 849646] [client 172.213.232.128:50637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/a4.php"] [unique_id "amuUOwMgr4yz2OQW0xrkbwAAAQA"]
[Thu Jul 30 13:13:15.199170 2026] [security2:error] [pid 849392:tid 849559] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/f35.update.php"] [unique_id "amuUOwMgr4yz2OQW0xrkcAAAAKk"]
[Thu Jul 30 13:13:15.199291 2026] [security2:error] [pid 849392:tid 849559] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/f35.update.php"] [unique_id "amuUOwMgr4yz2OQW0xrkcAAAAKk"]
[Thu Jul 30 13:13:15.721565 2026] [security2:error] [pid 849392:tid 849583] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/k.php"] [unique_id "amuUOwMgr4yz2OQW0xrkcwAAAME"]
[Thu Jul 30 13:13:15.721691 2026] [security2:error] [pid 849392:tid 849583] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/k.php"] [unique_id "amuUOwMgr4yz2OQW0xrkcwAAAME"]
[Thu Jul 30 13:13:16.259650 2026] [security2:error] [pid 849392:tid 849641] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.markmocek.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/"] [unique_id "amuUPAMgr4yz2OQW0xrkdgAAAPs"]
[Thu Jul 30 13:13:16.530683 2026] [security2:error] [pid 849392:tid 849591] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/spadex.php"] [unique_id "amuUPAMgr4yz2OQW0xrkeQAAAMk"]
[Thu Jul 30 13:13:16.530810 2026] [security2:error] [pid 849392:tid 849591] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/spadex.php"] [unique_id "amuUPAMgr4yz2OQW0xrkeQAAAMk"]
[Thu Jul 30 13:13:16.597732 2026] [security2:error] [pid 849392:tid 849631] [client 172.213.232.128:8250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/accueil.php"] [unique_id "amuUPAMgr4yz2OQW0xrkegAAAPE"]
[Thu Jul 30 13:13:16.770473 2026] [security2:error] [pid 849392:tid 849619] [client 172.236.9.101:40145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUPAMgr4yz2OQW0xrkdwAAAOU"]
[Thu Jul 30 13:13:16.796835 2026] [security2:error] [pid 849392:tid 849604] [client 179.64.21.229:44418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUPAMgr4yz2OQW0xrkfAAAANY"]
[Thu Jul 30 13:13:16.801540 2026] [security2:error] [pid 849392:tid 849604] [client 179.64.21.229:44418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUPAMgr4yz2OQW0xrkfAAAANY"]
[Thu Jul 30 13:13:17.038838 2026] [security2:error] [pid 849392:tid 849628] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/mg.php"] [unique_id "amuUPQMgr4yz2OQW0xrkgAAAAO4"]
[Thu Jul 30 13:13:17.039042 2026] [security2:error] [pid 849392:tid 849628] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/mg.php"] [unique_id "amuUPQMgr4yz2OQW0xrkgAAAAO4"]
[Thu Jul 30 13:13:17.390903 2026] [security2:error] [pid 849392:tid 849606] [client 172.213.232.128:50618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/dashboard.php"] [unique_id "amuUPQMgr4yz2OQW0xrkgQAAANg"]
[Thu Jul 30 13:13:17.522098 2026] [security2:error] [pid 849392:tid 849465] [remote 216.73.217.142:31153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUPQMgr4yz2OQW0xrkggAA-Uc"]
[Thu Jul 30 13:13:17.534289 2026] [security2:error] [pid 849392:tid 849650] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/fnstall.php"] [unique_id "amuUPQMgr4yz2OQW0xrkgwAAAQQ"]
[Thu Jul 30 13:13:17.534451 2026] [security2:error] [pid 849392:tid 849650] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/fnstall.php"] [unique_id "amuUPQMgr4yz2OQW0xrkgwAAAQQ"]
[Thu Jul 30 13:13:17.709618 2026] [security2:error] [pid 849392:tid 849523] [client 43.167.245.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "magicmooncorp.com"] [uri "/index.php"] [unique_id "amuUOwMgr4yz2OQW0xrkbgAAAIU"]
[Thu Jul 30 13:13:18.023554 2026] [security2:error] [pid 849392:tid 849453] [remote 216.73.217.142:31153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUPgMgr4yz2OQW0xrkhgAAhzs"]
[Thu Jul 30 13:13:18.048000 2026] [security2:error] [pid 849392:tid 849553] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ortasekerli1.php"] [unique_id "amuUPgMgr4yz2OQW0xrkhwAAAKM"]
[Thu Jul 30 13:13:18.048117 2026] [security2:error] [pid 849392:tid 849553] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ortasekerli1.php"] [unique_id "amuUPgMgr4yz2OQW0xrkhwAAAKM"]
[Thu Jul 30 13:13:18.190434 2026] [core:notice] [pid 849392:tid 849575] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:13:18.525678 2026] [security2:error] [pid 849392:tid 849445] [remote 216.73.217.142:31153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUPgMgr4yz2OQW0xrkjQAAojM"]
[Thu Jul 30 13:13:18.591238 2026] [security2:error] [pid 849392:tid 849579] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/sump1.php"] [unique_id "amuUPgMgr4yz2OQW0xrkjgAAAL0"]
[Thu Jul 30 13:13:18.591339 2026] [security2:error] [pid 849392:tid 849579] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/sump1.php"] [unique_id "amuUPgMgr4yz2OQW0xrkjgAAAL0"]
[Thu Jul 30 13:13:19.120379 2026] [security2:error] [pid 849392:tid 849636] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ops.php"] [unique_id "amuUPwMgr4yz2OQW0xrkkgAAAPY"]
[Thu Jul 30 13:13:19.120520 2026] [security2:error] [pid 849392:tid 849636] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ops.php"] [unique_id "amuUPwMgr4yz2OQW0xrkkgAAAPY"]
[Thu Jul 30 13:13:19.617183 2026] [security2:error] [pid 849392:tid 849614] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-post-data.php"] [unique_id "amuUPwMgr4yz2OQW0xrkmAAAAOA"]
[Thu Jul 30 13:13:19.617307 2026] [security2:error] [pid 849392:tid 849614] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-post-data.php"] [unique_id "amuUPwMgr4yz2OQW0xrkmAAAAOA"]
[Thu Jul 30 13:13:19.866796 2026] [security2:error] [pid 849392:tid 849451] [remote 57.141.0.53:43668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuUPwMgr4yz2OQW0xrklgAA-jk"], referer: https://igetvape-australia.com/product-tag/iget-one-blueberry-raspberry-12000-puffs/
[Thu Jul 30 13:13:20.109538 2026] [security2:error] [pid 849392:tid 849624] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUPwMgr4yz2OQW0xrklQAAAOo"]
[Thu Jul 30 13:13:20.132671 2026] [security2:error] [pid 849392:tid 849528] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/root.php"] [unique_id "amuUQAMgr4yz2OQW0xrknQAAAIo"]
[Thu Jul 30 13:13:20.132773 2026] [security2:error] [pid 849392:tid 849528] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/root.php"] [unique_id "amuUQAMgr4yz2OQW0xrknQAAAIo"]
[Thu Jul 30 13:13:20.658532 2026] [security2:error] [pid 849392:tid 849625] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/v543.php"] [unique_id "amuUQAMgr4yz2OQW0xrkogAAAOs"]
[Thu Jul 30 13:13:20.658651 2026] [security2:error] [pid 849392:tid 849625] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/v543.php"] [unique_id "amuUQAMgr4yz2OQW0xrkogAAAOs"]
[Thu Jul 30 13:13:21.152602 2026] [security2:error] [pid 849392:tid 849571] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/sixxis.php"] [unique_id "amuUQQMgr4yz2OQW0xrkpAAAALU"]
[Thu Jul 30 13:13:21.152726 2026] [security2:error] [pid 849392:tid 849571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/sixxis.php"] [unique_id "amuUQQMgr4yz2OQW0xrkpAAAALU"]
[Thu Jul 30 13:13:21.649646 2026] [security2:error] [pid 849392:tid 849599] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ip.php"] [unique_id "amuUQQMgr4yz2OQW0xrkrQAAANE"]
[Thu Jul 30 13:13:21.649764 2026] [security2:error] [pid 849392:tid 849599] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ip.php"] [unique_id "amuUQQMgr4yz2OQW0xrkrQAAANE"]
[Thu Jul 30 13:13:22.070933 2026] [security2:error] [pid 849392:tid 849444] [remote 194.116.184.179:30223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amuUQgMgr4yz2OQW0xrksAAA7zI"]
[Thu Jul 30 13:13:22.085071 2026] [security2:error] [pid 849392:tid 849617] [client 82.102.27.163:57752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuUQgMgr4yz2OQW0xrksQAAAOM"]
[Thu Jul 30 13:13:22.085159 2026] [security2:error] [pid 849392:tid 849617] [client 82.102.27.163:57752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuUQgMgr4yz2OQW0xrksQAAAOM"]
[Thu Jul 30 13:13:22.137102 2026] [security2:error] [pid 849392:tid 849646] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/kq1.php"] [unique_id "amuUQgMgr4yz2OQW0xrksgAAAQA"]
[Thu Jul 30 13:13:22.137202 2026] [security2:error] [pid 849392:tid 849646] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/kq1.php"] [unique_id "amuUQgMgr4yz2OQW0xrksgAAAQA"]
[Thu Jul 30 13:13:22.386313 2026] [security2:error] [pid 849392:tid 849602] [client 172.213.232.128:8202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/radio.php"] [unique_id "amuUQgMgr4yz2OQW0xrkuAAAANQ"]
[Thu Jul 30 13:13:22.404453 2026] [security2:error] [pid 849392:tid 849471] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/file.php"] [unique_id "amuUQgMgr4yz2OQW0xrkuQAA7E0"]
[Thu Jul 30 13:13:22.645991 2026] [security2:error] [pid 849392:tid 849650] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/fw/faiyy.php"] [unique_id "amuUQgMgr4yz2OQW0xrkwQAAAQQ"]
[Thu Jul 30 13:13:22.646152 2026] [security2:error] [pid 849392:tid 849650] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/fw/faiyy.php"] [unique_id "amuUQgMgr4yz2OQW0xrkwQAAAQQ"]
[Thu Jul 30 13:13:23.047379 2026] [security2:error] [pid 849392:tid 849506] [remote 216.73.217.142:31153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUQwMgr4yz2OQW0xrk2QAAyHA"]
[Thu Jul 30 13:13:23.151489 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/h02ugyh.php"] [unique_id "amuUQwMgr4yz2OQW0xrk2gAAALc"]
[Thu Jul 30 13:13:23.151608 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/h02ugyh.php"] [unique_id "amuUQwMgr4yz2OQW0xrk2gAAALc"]
[Thu Jul 30 13:13:23.255816 2026] [security2:error] [pid 849392:tid 849504] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuUQwMgr4yz2OQW0xrk2wAAvm4"]
[Thu Jul 30 13:13:23.549992 2026] [security2:error] [pid 849392:tid 849503] [remote 216.73.217.142:31153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUQwMgr4yz2OQW0xrk3wAA9m0"]
[Thu Jul 30 13:13:23.635333 2026] [security2:error] [pid 849392:tid 849556] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-temp.php"] [unique_id "amuUQwMgr4yz2OQW0xrk4AAAAKY"]
[Thu Jul 30 13:13:23.635490 2026] [security2:error] [pid 849392:tid 849556] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-temp.php"] [unique_id "amuUQwMgr4yz2OQW0xrk4AAAAKY"]
[Thu Jul 30 13:13:23.781548 2026] [security2:error] [pid 849392:tid 849609] [client 162.243.64.70:47484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.trv.udi.temporary.site"] [uri "/.env"] [unique_id "amuUQwMgr4yz2OQW0xrk5AAAANs"]
[Thu Jul 30 13:13:24.048002 2026] [security2:error] [pid 849392:tid 849578] [client 172.213.232.128:8214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/wpsml-sys.php"] [unique_id "amuURAMgr4yz2OQW0xrk6wAAALw"]
[Thu Jul 30 13:13:24.114335 2026] [security2:error] [pid 849392:tid 849498] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuURAMgr4yz2OQW0xrk7AAA0Gg"]
[Thu Jul 30 13:13:24.135190 2026] [security2:error] [pid 849392:tid 849570] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-content/cong.php"] [unique_id "amuURAMgr4yz2OQW0xrk7QAAALQ"]
[Thu Jul 30 13:13:24.135298 2026] [security2:error] [pid 849392:tid 849570] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-content/cong.php"] [unique_id "amuURAMgr4yz2OQW0xrk7QAAALQ"]
[Thu Jul 30 13:13:24.665041 2026] [security2:error] [pid 849392:tid 849571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.markmocek.com"] [uri "/___proxy_subdomain_webmail/wp-admin/js/widget/"] [unique_id "amuURAMgr4yz2OQW0xrk8QAAALU"]
[Thu Jul 30 13:13:24.918608 2026] [security2:error] [pid 849392:tid 849629] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuURAMgr4yz2OQW0xrk-gAAAO8"]
[Thu Jul 30 13:13:24.918731 2026] [security2:error] [pid 849392:tid 849629] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuURAMgr4yz2OQW0xrk-gAAAO8"]
[Thu Jul 30 13:13:25.165893 2026] [security2:error] [pid 849392:tid 849547] [client 172.213.232.128:50683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/02.php"] [unique_id "amuURQMgr4yz2OQW0xrlDQAAAJ0"]
[Thu Jul 30 13:13:25.412437 2026] [security2:error] [pid 849392:tid 849549] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/jj.php"] [unique_id "amuURQMgr4yz2OQW0xrlDwAAAJ8"]
[Thu Jul 30 13:13:25.412616 2026] [security2:error] [pid 849392:tid 849549] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/jj.php"] [unique_id "amuURQMgr4yz2OQW0xrlDwAAAJ8"]
[Thu Jul 30 13:13:25.739027 2026] [security2:error] [pid 849392:tid 849617] [client 172.237.109.114:1741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlAAAAAOM"]
[Thu Jul 30 13:13:25.795189 2026] [security2:error] [pid 849392:tid 849559] [client 172.237.109.114:21287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlAgAAAKk"]
[Thu Jul 30 13:13:25.832966 2026] [security2:error] [pid 849392:tid 849588] [client 172.237.109.114:24909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlAwAAAMY"]
[Thu Jul 30 13:13:25.843144 2026] [security2:error] [pid 849392:tid 849567] [client 172.237.109.114:25270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlBwAAALE"]
[Thu Jul 30 13:13:25.843144 2026] [security2:error] [pid 849392:tid 849597] [client 172.237.109.114:53981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlBQAAAM8"]
[Thu Jul 30 13:13:25.849870 2026] [security2:error] [pid 849392:tid 849647] [client 172.237.109.114:21983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlAQAAAQE"]
[Thu Jul 30 13:13:25.849966 2026] [security2:error] [pid 849392:tid 849540] [client 172.237.109.114:7449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlBAAAAJY"]
[Thu Jul 30 13:13:25.860074 2026] [security2:error] [pid 849392:tid 849641] [client 172.237.109.114:46085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlCQAAAPs"]
[Thu Jul 30 13:13:25.865812 2026] [security2:error] [pid 849392:tid 849616] [client 172.237.109.114:41809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlCAAAAOI"]
[Thu Jul 30 13:13:25.897814 2026] [security2:error] [pid 849392:tid 849583] [client 172.237.109.114:21213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlCwAAAME"]
[Thu Jul 30 13:13:25.920672 2026] [security2:error] [pid 849392:tid 849632] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amuURQMgr4yz2OQW0xrlEwAAAPI"]
[Thu Jul 30 13:13:25.920791 2026] [security2:error] [pid 849392:tid 849632] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amuURQMgr4yz2OQW0xrlEwAAAPI"]
[Thu Jul 30 13:13:26.121610 2026] [security2:error] [pid 849392:tid 849639] [client 178.156.184.20:5548] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuURQMgr4yz2OQW0xrlFQAAAPk"], referer: https://globalmarks.pk/
[Thu Jul 30 13:13:26.437390 2026] [security2:error] [pid 849392:tid 849636] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/xpwer1.php"] [unique_id "amuURgMgr4yz2OQW0xrlGgAAAPY"]
[Thu Jul 30 13:13:26.437555 2026] [security2:error] [pid 849392:tid 849636] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/xpwer1.php"] [unique_id "amuURgMgr4yz2OQW0xrlGgAAAPY"]
[Thu Jul 30 13:13:26.975588 2026] [security2:error] [pid 849392:tid 849608] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/flox.php"] [unique_id "amuURgMgr4yz2OQW0xrlHQAAANo"]
[Thu Jul 30 13:13:26.975733 2026] [security2:error] [pid 849392:tid 849608] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/flox.php"] [unique_id "amuURgMgr4yz2OQW0xrlHQAAANo"]
[Thu Jul 30 13:13:27.342775 2026] [security2:error] [pid 849392:tid 849528] [client 179.64.21.229:24613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuURwMgr4yz2OQW0xrlJAAAAIo"]
[Thu Jul 30 13:13:27.358566 2026] [security2:error] [pid 849392:tid 849528] [client 179.64.21.229:24613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuURwMgr4yz2OQW0xrlJAAAAIo"]
[Thu Jul 30 13:13:27.506239 2026] [security2:error] [pid 849392:tid 849618] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/popo.php"] [unique_id "amuURwMgr4yz2OQW0xrlJgAAAOQ"]
[Thu Jul 30 13:13:27.506352 2026] [security2:error] [pid 849392:tid 849618] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/popo.php"] [unique_id "amuURwMgr4yz2OQW0xrlJgAAAOQ"]
[Thu Jul 30 13:13:27.726635 2026] [security2:error] [pid 849392:tid 849568] [client 172.236.9.101:8374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuURwMgr4yz2OQW0xrlIwAAALI"]
[Thu Jul 30 13:13:27.776824 2026] [security2:error] [pid 849392:tid 849574] [client 46.105.39.49:24785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bitcoinfungibletoken.com"] [uri "/robots.txt"] [unique_id "amuURwMgr4yz2OQW0xrlKAAAALg"]
[Thu Jul 30 13:13:27.776972 2026] [security2:error] [pid 849392:tid 849574] [client 46.105.39.49:24785] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bitcoinfungibletoken.com"] [uri "/robots.txt"] [unique_id "amuURwMgr4yz2OQW0xrlKAAAALg"]
[Thu Jul 30 13:13:28.021516 2026] [security2:error] [pid 849392:tid 849526] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/yas.php"] [unique_id "amuUSAMgr4yz2OQW0xrlKgAAAIg"]
[Thu Jul 30 13:13:28.021619 2026] [security2:error] [pid 849392:tid 849526] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/yas.php"] [unique_id "amuUSAMgr4yz2OQW0xrlKgAAAIg"]
[Thu Jul 30 13:13:28.024215 2026] [security2:error] [pid 849392:tid 849631] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuUSAMgr4yz2OQW0xrlKQAAAPE"]
[Thu Jul 30 13:13:28.024305 2026] [security2:error] [pid 849392:tid 849631] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuUSAMgr4yz2OQW0xrlKQAAAPE"]
[Thu Jul 30 13:13:28.540460 2026] [security2:error] [pid 849392:tid 849606] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/water.php"] [unique_id "amuUSAMgr4yz2OQW0xrlMQAAANg"]
[Thu Jul 30 13:13:28.540575 2026] [security2:error] [pid 849392:tid 849606] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/water.php"] [unique_id "amuUSAMgr4yz2OQW0xrlMQAAANg"]
[Thu Jul 30 13:13:28.567346 2026] [security2:error] [pid 849392:tid 849610] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuUSAMgr4yz2OQW0xrlMwAAANw"]
[Thu Jul 30 13:13:28.567464 2026] [security2:error] [pid 849392:tid 849610] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuUSAMgr4yz2OQW0xrlMwAAANw"]
[Thu Jul 30 13:13:29.075499 2026] [security2:error] [pid 849392:tid 849647] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/nano.php"] [unique_id "amuUSQMgr4yz2OQW0xrlNQAAAQE"]
[Thu Jul 30 13:13:29.075614 2026] [security2:error] [pid 849392:tid 849647] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/nano.php"] [unique_id "amuUSQMgr4yz2OQW0xrlNQAAAQE"]
[Thu Jul 30 13:13:29.086327 2026] [security2:error] [pid 849392:tid 849540] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/inputs.php"] [unique_id "amuUSQMgr4yz2OQW0xrlNgAAAJY"]
[Thu Jul 30 13:13:29.086417 2026] [security2:error] [pid 849392:tid 849540] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/inputs.php"] [unique_id "amuUSQMgr4yz2OQW0xrlNgAAAJY"]
[Thu Jul 30 13:13:29.313907 2026] [core:notice] [pid 849392:tid 849592] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:13:29.587290 2026] [security2:error] [pid 849392:tid 849582] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/admin.php"] [unique_id "amuUSQMgr4yz2OQW0xrlPAAAAMA"]
[Thu Jul 30 13:13:29.587728 2026] [security2:error] [pid 849392:tid 849582] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/admin.php"] [unique_id "amuUSQMgr4yz2OQW0xrlPAAAAMA"]
[Thu Jul 30 13:13:29.605903 2026] [security2:error] [pid 849392:tid 849530] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/moon.php"] [unique_id "amuUSQMgr4yz2OQW0xrlPQAAAIw"]
[Thu Jul 30 13:13:29.606035 2026] [security2:error] [pid 849392:tid 849530] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/moon.php"] [unique_id "amuUSQMgr4yz2OQW0xrlPQAAAIw"]
[Thu Jul 30 13:13:30.070830 2026] [security2:error] [pid 849392:tid 849615] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/goods.php"] [unique_id "amuUSgMgr4yz2OQW0xrlQgAAAOE"]
[Thu Jul 30 13:13:30.070935 2026] [security2:error] [pid 849392:tid 849615] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/goods.php"] [unique_id "amuUSgMgr4yz2OQW0xrlQgAAAOE"]
[Thu Jul 30 13:13:30.139970 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-info.php"] [unique_id "amuUSgMgr4yz2OQW0xrlQwAAALc"]
[Thu Jul 30 13:13:30.140136 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-info.php"] [unique_id "amuUSgMgr4yz2OQW0xrlQwAAALc"]
[Thu Jul 30 13:13:30.497492 2026] [security2:error] [pid 849392:tid 849554] [client 172.213.232.128:50677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/infos.php"] [unique_id "amuUSgMgr4yz2OQW0xrlRQAAAKQ"]
[Thu Jul 30 13:13:30.672530 2026] [security2:error] [pid 849392:tid 849586] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/file5.php"] [unique_id "amuUSgMgr4yz2OQW0xrlRwAAAMQ"]
[Thu Jul 30 13:13:30.672692 2026] [security2:error] [pid 849392:tid 849586] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/file5.php"] [unique_id "amuUSgMgr4yz2OQW0xrlRwAAAMQ"]
[Thu Jul 30 13:13:30.692423 2026] [security2:error] [pid 849392:tid 849556] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/file.php"] [unique_id "amuUSgMgr4yz2OQW0xrlSAAAAKY"]
[Thu Jul 30 13:13:30.692535 2026] [security2:error] [pid 849392:tid 849556] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/file.php"] [unique_id "amuUSgMgr4yz2OQW0xrlSAAAAKY"]
[Thu Jul 30 13:13:31.203351 2026] [security2:error] [pid 849392:tid 849644] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/adminfuns.php"] [unique_id "amuUSwMgr4yz2OQW0xrlSQAAAP4"]
[Thu Jul 30 13:13:31.203468 2026] [security2:error] [pid 849392:tid 849644] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/adminfuns.php"] [unique_id "amuUSwMgr4yz2OQW0xrlSQAAAP4"]
[Thu Jul 30 13:13:31.220882 2026] [security2:error] [pid 849392:tid 849545] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/2000.php"] [unique_id "amuUSwMgr4yz2OQW0xrlSgAAAJs"]
[Thu Jul 30 13:13:31.220963 2026] [security2:error] [pid 849392:tid 849545] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/2000.php"] [unique_id "amuUSwMgr4yz2OQW0xrlSgAAAJs"]
[Thu Jul 30 13:13:31.705634 2026] [security2:error] [pid 849392:tid 849581] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/404.php"] [unique_id "amuUSwMgr4yz2OQW0xrlTQAAAL8"]
[Thu Jul 30 13:13:31.705785 2026] [security2:error] [pid 849392:tid 849581] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/404.php"] [unique_id "amuUSwMgr4yz2OQW0xrlTQAAAL8"]
[Thu Jul 30 13:13:31.779995 2026] [security2:error] [pid 849392:tid 849646] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/122.php"] [unique_id "amuUSwMgr4yz2OQW0xrlTgAAAQA"]
[Thu Jul 30 13:13:31.780410 2026] [security2:error] [pid 849392:tid 849646] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/122.php"] [unique_id "amuUSwMgr4yz2OQW0xrlTgAAAQA"]
[Thu Jul 30 13:13:32.196900 2026] [security2:error] [pid 849392:tid 849578] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wk/index.php"] [unique_id "amuUTAMgr4yz2OQW0xrlTwAAALw"]
[Thu Jul 30 13:13:32.197041 2026] [security2:error] [pid 849392:tid 849578] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wk/index.php"] [unique_id "amuUTAMgr4yz2OQW0xrlTwAAALw"]
[Thu Jul 30 13:13:32.290962 2026] [security2:error] [pid 849392:tid 849598] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/mds.php"] [unique_id "amuUTAMgr4yz2OQW0xrlUAAAANA"]
[Thu Jul 30 13:13:32.291086 2026] [security2:error] [pid 849392:tid 849598] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/mds.php"] [unique_id "amuUTAMgr4yz2OQW0xrlUAAAANA"]
[Thu Jul 30 13:13:32.437201 2026] [security2:error] [pid 849392:tid 849533] [client 172.213.232.128:54843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/updates.php"] [unique_id "amuUTAMgr4yz2OQW0xrlUQAAAI8"]
[Thu Jul 30 13:13:32.730527 2026] [security2:error] [pid 849392:tid 849618] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/about.php"] [unique_id "amuUTAMgr4yz2OQW0xrlUgAAAOQ"]
[Thu Jul 30 13:13:32.730643 2026] [security2:error] [pid 849392:tid 849618] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/about.php"] [unique_id "amuUTAMgr4yz2OQW0xrlUgAAAOQ"]
[Thu Jul 30 13:13:32.787697 2026] [security2:error] [pid 849392:tid 849627] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/zc-208.php"] [unique_id "amuUTAMgr4yz2OQW0xrlVAAAAO0"]
[Thu Jul 30 13:13:32.787807 2026] [security2:error] [pid 849392:tid 849627] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/zc-208.php"] [unique_id "amuUTAMgr4yz2OQW0xrlVAAAAO0"]
[Thu Jul 30 13:13:33.247539 2026] [security2:error] [pid 849392:tid 849630] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/term.php"] [unique_id "amuUTQMgr4yz2OQW0xrlWAAAAPA"]
[Thu Jul 30 13:13:33.247635 2026] [security2:error] [pid 849392:tid 849630] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/term.php"] [unique_id "amuUTQMgr4yz2OQW0xrlWAAAAPA"]
[Thu Jul 30 13:13:33.271288 2026] [security2:error] [pid 849392:tid 849602] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/sid4.php"] [unique_id "amuUTQMgr4yz2OQW0xrlWQAAANQ"]
[Thu Jul 30 13:13:33.271378 2026] [security2:error] [pid 849392:tid 849602] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/sid4.php"] [unique_id "amuUTQMgr4yz2OQW0xrlWQAAANQ"]
[Thu Jul 30 13:13:33.739902 2026] [security2:error] [pid 849392:tid 849635] [client 172.213.232.128:54788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/user.php"] [unique_id "amuUTQMgr4yz2OQW0xrlWwAAAPU"]
[Thu Jul 30 13:13:33.740646 2026] [security2:error] [pid 849392:tid 849628] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ioxi-o.php"] [unique_id "amuUTQMgr4yz2OQW0xrlXAAAAO4"]
[Thu Jul 30 13:13:33.740721 2026] [security2:error] [pid 849392:tid 849628] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ioxi-o.php"] [unique_id "amuUTQMgr4yz2OQW0xrlXAAAAO4"]
[Thu Jul 30 13:13:33.785225 2026] [security2:error] [pid 849392:tid 849557] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.markmocek.com"] [uri "/___proxy_subdomain_webmail/wp-includes/l10n/"] [unique_id "amuUTQMgr4yz2OQW0xrlXQAAAKc"]
[Thu Jul 30 13:13:34.033084 2026] [security2:error] [pid 849392:tid 849559] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wmore1.php"] [unique_id "amuUTgMgr4yz2OQW0xrlXgAAAKk"]
[Thu Jul 30 13:13:34.033218 2026] [security2:error] [pid 849392:tid 849559] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wmore1.php"] [unique_id "amuUTgMgr4yz2OQW0xrlXgAAAKk"]
[Thu Jul 30 13:13:34.247608 2026] [security2:error] [pid 849392:tid 849647] [client 20.104.22.47:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amuUTgMgr4yz2OQW0xrlZgAAAQE"]
[Thu Jul 30 13:13:34.247719 2026] [security2:error] [pid 849392:tid 849647] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amuUTgMgr4yz2OQW0xrlZgAAAQE"]
[Thu Jul 30 13:13:34.247818 2026] [security2:error] [pid 849392:tid 849647] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amuUTgMgr4yz2OQW0xrlZgAAAQE"]
[Thu Jul 30 13:13:34.544127 2026] [security2:error] [pid 849392:tid 849588] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/solo1.php"] [unique_id "amuUTgMgr4yz2OQW0xrlaAAAAMY"]
[Thu Jul 30 13:13:34.544233 2026] [security2:error] [pid 849392:tid 849588] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/solo1.php"] [unique_id "amuUTgMgr4yz2OQW0xrlaAAAAMY"]
[Thu Jul 30 13:13:34.742145 2026] [security2:error] [pid 849392:tid 849582] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/alfa.php"] [unique_id "amuUTgMgr4yz2OQW0xrlawAAAMA"]
[Thu Jul 30 13:13:34.742289 2026] [security2:error] [pid 849392:tid 849582] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/alfa.php"] [unique_id "amuUTgMgr4yz2OQW0xrlawAAAMA"]
[Thu Jul 30 13:13:35.039591 2026] [security2:error] [pid 849392:tid 849604] [client 172.213.232.128:51885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/admin-ajax.php"] [unique_id "amuUTwMgr4yz2OQW0xrlbQAAANY"]
[Thu Jul 30 13:13:35.083039 2026] [security2:error] [pid 849392:tid 849600] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.markmocek.com"] [uri "/___proxy_subdomain_webmail/wp-includes/assets/"] [unique_id "amuUTwMgr4yz2OQW0xrlbgAAANI"]
[Thu Jul 30 13:13:35.237363 2026] [security2:error] [pid 849392:tid 849537] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/edit.php"] [unique_id "amuUTwMgr4yz2OQW0xrlcAAAAJM"]
[Thu Jul 30 13:13:35.237521 2026] [security2:error] [pid 849392:tid 849537] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/edit.php"] [unique_id "amuUTwMgr4yz2OQW0xrlcAAAAJM"]
[Thu Jul 30 13:13:35.340566 2026] [security2:error] [pid 849392:tid 849523] [client 119.73.97.132:30954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuUTwMgr4yz2OQW0xrlbwAAhQ8"], referer: https://www.urwru.club/wp-admin/edit.php?post_type=page
[Thu Jul 30 13:13:35.363376 2026] [security2:error] [pid 849392:tid 849601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.markmocek.com"] [uri "/___proxy_subdomain_webmail/wp-includes/css/"] [unique_id "amuUTwMgr4yz2OQW0xrlcQAAANM"]
[Thu Jul 30 13:13:35.610319 2026] [security2:error] [pid 849392:tid 849620] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/public/css.php"] [unique_id "amuUTwMgr4yz2OQW0xrldAAAAOY"]
[Thu Jul 30 13:13:35.610493 2026] [security2:error] [pid 849392:tid 849620] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/public/css.php"] [unique_id "amuUTwMgr4yz2OQW0xrldAAAAOY"]
[Thu Jul 30 13:13:36.100013 2026] [security2:error] [pid 849392:tid 849612] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/output.php"] [unique_id "amuUUAMgr4yz2OQW0xrldQAAAN4"]
[Thu Jul 30 13:13:36.100128 2026] [security2:error] [pid 849392:tid 849612] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/output.php"] [unique_id "amuUUAMgr4yz2OQW0xrldQAAAN4"]
[Thu Jul 30 13:13:36.222088 2026] [security2:error] [pid 849392:tid 849639] [client 94.154.43.179:48102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lilyinspires.com"] [uri "/.env"] [unique_id "amuUUAMgr4yz2OQW0xrldwAAAPk"]
[Thu Jul 30 13:13:36.271304 2026] [security2:error] [pid 849392:tid 849591] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/elp.php"] [unique_id "amuUUAMgr4yz2OQW0xrleAAAAMk"]
[Thu Jul 30 13:13:36.271424 2026] [security2:error] [pid 849392:tid 849591] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/elp.php"] [unique_id "amuUUAMgr4yz2OQW0xrleAAAAMk"]
[Thu Jul 30 13:13:36.510821 2026] [security2:error] [pid 849392:tid 849566] [client 172.213.232.128:51966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/alfa.php"] [unique_id "amuUUAMgr4yz2OQW0xrleQAAALA"]
[Thu Jul 30 13:13:36.611625 2026] [security2:error] [pid 849392:tid 849586] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-file-120.php"] [unique_id "amuUUAMgr4yz2OQW0xrlegAAAMQ"]
[Thu Jul 30 13:13:36.611777 2026] [security2:error] [pid 849392:tid 849586] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-file-120.php"] [unique_id "amuUUAMgr4yz2OQW0xrlegAAAMQ"]
[Thu Jul 30 13:13:36.699234 2026] [security2:error] [pid 849392:tid 849551] [client 103.59.160.186:57477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "388iendd.site"] [uri "/index.php"] [unique_id "amuUUAMgr4yz2OQW0xrlewAAAKE"]
[Thu Jul 30 13:13:36.786088 2026] [security2:error] [pid 849392:tid 849605] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/classwithtostring.php"] [unique_id "amuUUAMgr4yz2OQW0xrlfAAAANc"]
[Thu Jul 30 13:13:36.786237 2026] [security2:error] [pid 849392:tid 849605] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/classwithtostring.php"] [unique_id "amuUUAMgr4yz2OQW0xrlfAAAANc"]
[Thu Jul 30 13:13:37.125585 2026] [security2:error] [pid 849392:tid 849595] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/special.php"] [unique_id "amuUUQMgr4yz2OQW0xrlfQAAAM0"]
[Thu Jul 30 13:13:37.125718 2026] [security2:error] [pid 849392:tid 849595] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/special.php"] [unique_id "amuUUQMgr4yz2OQW0xrlfQAAAM0"]
[Thu Jul 30 13:13:37.280568 2026] [security2:error] [pid 849392:tid 849534] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/666.php"] [unique_id "amuUUQMgr4yz2OQW0xrlfwAAAJA"]
[Thu Jul 30 13:13:37.280670 2026] [security2:error] [pid 849392:tid 849534] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/666.php"] [unique_id "amuUUQMgr4yz2OQW0xrlfwAAAJA"]
[Thu Jul 30 13:13:37.607931 2026] [security2:error] [pid 849392:tid 849581] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/as.php"] [unique_id "amuUUQMgr4yz2OQW0xrlgQAAAL8"]
[Thu Jul 30 13:13:37.608090 2026] [security2:error] [pid 849392:tid 849581] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/as.php"] [unique_id "amuUUQMgr4yz2OQW0xrlgQAAAL8"]
[Thu Jul 30 13:13:37.801811 2026] [security2:error] [pid 849392:tid 849563] [client 172.236.9.101:35600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUUQMgr4yz2OQW0xrlfgAAAK0"]
[Thu Jul 30 13:13:37.822515 2026] [security2:error] [pid 849392:tid 849646] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/wp-admin/"] [unique_id "amuUUQMgr4yz2OQW0xrlgwAAAQA"]
[Thu Jul 30 13:13:38.099093 2026] [security2:error] [pid 849392:tid 849608] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ws54.php"] [unique_id "amuUUgMgr4yz2OQW0xrlhAAAANo"]
[Thu Jul 30 13:13:38.099255 2026] [security2:error] [pid 849392:tid 849608] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ws54.php"] [unique_id "amuUUgMgr4yz2OQW0xrlhAAAANo"]
[Thu Jul 30 13:13:38.113072 2026] [security2:error] [pid 849392:tid 849578] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cgi-bin/index.php"] [unique_id "amuUUgMgr4yz2OQW0xrlhQAAALw"]
[Thu Jul 30 13:13:38.113194 2026] [security2:error] [pid 849392:tid 849578] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/cgi-bin/index.php"] [unique_id "amuUUgMgr4yz2OQW0xrlhQAAALw"]
[Thu Jul 30 13:13:38.185353 2026] [security2:error] [pid 849392:tid 849535] [client 179.64.21.229:57879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUUgMgr4yz2OQW0xrliQAAAJE"]
[Thu Jul 30 13:13:38.193484 2026] [security2:error] [pid 849392:tid 849535] [client 179.64.21.229:57879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUUgMgr4yz2OQW0xrliQAAAJE"]
[Thu Jul 30 13:13:38.212770 2026] [security2:error] [pid 849392:tid 849561] [client 172.213.232.128:51938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/hehe.php"] [unique_id "amuUUgMgr4yz2OQW0xrligAAAKs"]
[Thu Jul 30 13:13:38.575701 2026] [security2:error] [pid 849392:tid 849627] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/deepseek_d.php"] [unique_id "amuUUgMgr4yz2OQW0xrljAAAAO0"]
[Thu Jul 30 13:13:38.575817 2026] [security2:error] [pid 849392:tid 849627] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/deepseek_d.php"] [unique_id "amuUUgMgr4yz2OQW0xrljAAAAO0"]
[Thu Jul 30 13:13:38.616449 2026] [security2:error] [pid 849392:tid 849558] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/w1px.php"] [unique_id "amuUUgMgr4yz2OQW0xrljQAAAKg"]
[Thu Jul 30 13:13:38.616553 2026] [security2:error] [pid 849392:tid 849558] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/w1px.php"] [unique_id "amuUUgMgr4yz2OQW0xrljQAAAKg"]
[Thu Jul 30 13:13:38.709299 2026] [core:notice] [pid 849392:tid 849609] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:13:39.105962 2026] [security2:error] [pid 849392:tid 849629] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/js.php"] [unique_id "amuUUwMgr4yz2OQW0xrlkwAAAO8"]
[Thu Jul 30 13:13:39.106101 2026] [security2:error] [pid 849392:tid 849629] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/js.php"] [unique_id "amuUUwMgr4yz2OQW0xrlkwAAAO8"]
[Thu Jul 30 13:13:39.106314 2026] [security2:error] [pid 849392:tid 849594] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/function/function.php"] [unique_id "amuUUwMgr4yz2OQW0xrllAAAAMw"]
[Thu Jul 30 13:13:39.106390 2026] [security2:error] [pid 849392:tid 849594] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/function/function.php"] [unique_id "amuUUwMgr4yz2OQW0xrllAAAAMw"]
[Thu Jul 30 13:13:39.115661 2026] [security2:error] [pid 849392:tid 849568] [client 172.213.232.128:51887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/rk2.php"] [unique_id "amuUUwMgr4yz2OQW0xrllQAAALI"]
[Thu Jul 30 13:13:39.587383 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/core.php"] [unique_id "amuUUwMgr4yz2OQW0xrllwAAAPE"]
[Thu Jul 30 13:13:39.587506 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/core.php"] [unique_id "amuUUwMgr4yz2OQW0xrllwAAAPE"]
[Thu Jul 30 13:13:40.083566 2026] [security2:error] [pid 849392:tid 849543] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/fffm.php"] [unique_id "amuUVAMgr4yz2OQW0xrlmgAAAJk"]
[Thu Jul 30 13:13:40.083685 2026] [security2:error] [pid 849392:tid 849543] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/fffm.php"] [unique_id "amuUVAMgr4yz2OQW0xrlmgAAAJk"]
[Thu Jul 30 13:13:40.137971 2026] [security2:error] [pid 849392:tid 849611] [client 172.213.232.128:54808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/setup-config.php"] [unique_id "amuUVAMgr4yz2OQW0xrlnAAAAN0"]
[Thu Jul 30 13:13:40.542335 2026] [security2:error] [pid 849392:tid 849559] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/nw.php"] [unique_id "amuUVAMgr4yz2OQW0xrloQAAAKk"]
[Thu Jul 30 13:13:40.542476 2026] [security2:error] [pid 849392:tid 849559] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/nw.php"] [unique_id "amuUVAMgr4yz2OQW0xrloQAAAKk"]
[Thu Jul 30 13:13:40.572331 2026] [security2:error] [pid 849392:tid 849593] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ww.php"] [unique_id "amuUVAMgr4yz2OQW0xrlogAAAMs"]
[Thu Jul 30 13:13:40.572447 2026] [security2:error] [pid 849392:tid 849593] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ww.php"] [unique_id "amuUVAMgr4yz2OQW0xrlogAAAMs"]
[Thu Jul 30 13:13:40.773291 2026] [security2:error] [pid 849392:tid 849626] [client 172.236.9.101:61178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUVAMgr4yz2OQW0xrlnQAAAOw"]
[Thu Jul 30 13:13:40.921544 2026] [security2:error] [pid 849392:tid 849617] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUVAMgr4yz2OQW0xrloAAAAOM"]
[Thu Jul 30 13:13:41.036746 2026] [security2:error] [pid 849392:tid 849643] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/xleet.php"] [unique_id "amuUVQMgr4yz2OQW0xrlrQAAAP0"]
[Thu Jul 30 13:13:41.036844 2026] [security2:error] [pid 849392:tid 849643] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/xleet.php"] [unique_id "amuUVQMgr4yz2OQW0xrlrQAAAP0"]
[Thu Jul 30 13:13:41.061189 2026] [security2:error] [pid 849392:tid 849537] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/domvf.php"] [unique_id "amuUVQMgr4yz2OQW0xrlrgAAAJM"]
[Thu Jul 30 13:13:41.061374 2026] [security2:error] [pid 849392:tid 849537] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/domvf.php"] [unique_id "amuUVQMgr4yz2OQW0xrlrgAAAJM"]
[Thu Jul 30 13:13:41.529914 2026] [security2:error] [pid 849392:tid 849632] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUVAMgr4yz2OQW0xrlqAAAAPI"]
[Thu Jul 30 13:13:41.536740 2026] [security2:error] [pid 849392:tid 849634] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp.php"] [unique_id "amuUVQMgr4yz2OQW0xrlswAAAPQ"]
[Thu Jul 30 13:13:41.536823 2026] [security2:error] [pid 849392:tid 849634] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp.php"] [unique_id "amuUVQMgr4yz2OQW0xrlswAAAPQ"]
[Thu Jul 30 13:13:41.550409 2026] [security2:error] [pid 849392:tid 849612] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/echkm.php"] [unique_id "amuUVQMgr4yz2OQW0xrltAAAAN4"]
[Thu Jul 30 13:13:41.550488 2026] [security2:error] [pid 849392:tid 849612] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/echkm.php"] [unique_id "amuUVQMgr4yz2OQW0xrltAAAAN4"]
[Thu Jul 30 13:13:41.807320 2026] [security2:error] [pid 849392:tid 849542] [client 172.213.232.128:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/a7.php"] [unique_id "amuUVQMgr4yz2OQW0xrltgAAAJg"]
[Thu Jul 30 13:13:41.899551 2026] [security2:error] [pid 849392:tid 849601] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUVQMgr4yz2OQW0xrlsgAAANM"]
[Thu Jul 30 13:13:42.055848 2026] [security2:error] [pid 849392:tid 849586] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ano.php"] [unique_id "amuUVgMgr4yz2OQW0xrluQAAAMQ"]
[Thu Jul 30 13:13:42.055968 2026] [security2:error] [pid 849392:tid 849586] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ano.php"] [unique_id "amuUVgMgr4yz2OQW0xrluQAAAMQ"]
[Thu Jul 30 13:13:42.096970 2026] [security2:error] [pid 849392:tid 849560] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/155.php"] [unique_id "amuUVgMgr4yz2OQW0xrluwAAAKo"]
[Thu Jul 30 13:13:42.097111 2026] [security2:error] [pid 849392:tid 849560] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/155.php"] [unique_id "amuUVgMgr4yz2OQW0xrluwAAAKo"]
[Thu Jul 30 13:13:42.193093 2026] [security2:error] [pid 849392:tid 849398] [remote 57.141.0.63:31706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuUVQMgr4yz2OQW0xrltwAA3wQ"], referer: https://igetvape-australia.com/store/?product-page=1&add-to-cart=116
[Thu Jul 30 13:13:42.583830 2026] [security2:error] [pid 849392:tid 849563] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ah25.php"] [unique_id "amuUVgMgr4yz2OQW0xrlxgAAAK0"]
[Thu Jul 30 13:13:42.583923 2026] [security2:error] [pid 849392:tid 849563] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ah25.php"] [unique_id "amuUVgMgr4yz2OQW0xrlxgAAAK0"]
[Thu Jul 30 13:13:42.631817 2026] [security2:error] [pid 849392:tid 849646] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/96i.php"] [unique_id "amuUVgMgr4yz2OQW0xrlzwAAAQA"]
[Thu Jul 30 13:13:42.631911 2026] [security2:error] [pid 849392:tid 849646] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/96i.php"] [unique_id "amuUVgMgr4yz2OQW0xrlzwAAAQA"]
[Thu Jul 30 13:13:42.648321 2026] [security2:error] [pid 849392:tid 849605] [client 172.213.232.128:51957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/f7.php"] [unique_id "amuUVgMgr4yz2OQW0xrl0AAAANc"]
[Thu Jul 30 13:13:42.929421 2026] [security2:error] [pid 849392:tid 849565] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUVgMgr4yz2OQW0xrlvgAAAK8"]
[Thu Jul 30 13:13:43.081554 2026] [security2:error] [pid 849392:tid 849608] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/term.php"] [unique_id "amuUVwMgr4yz2OQW0xrl0QAAANo"]
[Thu Jul 30 13:13:43.081700 2026] [security2:error] [pid 849392:tid 849608] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/term.php"] [unique_id "amuUVwMgr4yz2OQW0xrl0QAAANo"]
[Thu Jul 30 13:13:43.129454 2026] [security2:error] [pid 849392:tid 849578] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/as.php"] [unique_id "amuUVwMgr4yz2OQW0xrl0gAAALw"]
[Thu Jul 30 13:13:43.129568 2026] [security2:error] [pid 849392:tid 849578] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/as.php"] [unique_id "amuUVwMgr4yz2OQW0xrl0gAAALw"]
[Thu Jul 30 13:13:43.563343 2026] [security2:error] [pid 849392:tid 849555] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/we.php"] [unique_id "amuUVwMgr4yz2OQW0xrl2wAAAKU"]
[Thu Jul 30 13:13:43.563458 2026] [security2:error] [pid 849392:tid 849555] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/we.php"] [unique_id "amuUVwMgr4yz2OQW0xrl2wAAAKU"]
[Thu Jul 30 13:13:43.600722 2026] [security2:error] [pid 849392:tid 849618] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/min.php"] [unique_id "amuUVwMgr4yz2OQW0xrl3AAAAOQ"]
[Thu Jul 30 13:13:43.600824 2026] [security2:error] [pid 849392:tid 849618] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/min.php"] [unique_id "amuUVwMgr4yz2OQW0xrl3AAAAOQ"]
[Thu Jul 30 13:13:43.823144 2026] [security2:error] [pid 849392:tid 849473] [remote 196.12.128.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "prestigemassagestudio.cfd"] [uri "/xmlrpc.php"] [unique_id "amuUVwMgr4yz2OQW0xrl2gAAw08"]
[Thu Jul 30 13:13:43.823404 2026] [security2:error] [pid 849392:tid 849585] [client 196.12.128.158:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "prestigemassagestudio.cfd"] [uri "/xmlrpc.php"] [unique_id "amuUVwMgr4yz2OQW0xrl2gAAw08"]
[Thu Jul 30 13:13:44.074135 2026] [security2:error] [pid 849392:tid 849571] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/zip-onee.php"] [unique_id "amuUWAMgr4yz2OQW0xrl3gAAALU"]
[Thu Jul 30 13:13:44.074259 2026] [security2:error] [pid 849392:tid 849571] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/zip-onee.php"] [unique_id "amuUWAMgr4yz2OQW0xrl3gAAALU"]
[Thu Jul 30 13:13:44.126592 2026] [security2:error] [pid 849392:tid 849602] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/.well-known/"] [unique_id "amuUWAMgr4yz2OQW0xrl3wAAANQ"]
[Thu Jul 30 13:13:44.415283 2026] [security2:error] [pid 849392:tid 849637] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/php8.php"] [unique_id "amuUWAMgr4yz2OQW0xrl4QAAAPc"]
[Thu Jul 30 13:13:44.415410 2026] [security2:error] [pid 849392:tid 849637] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/php8.php"] [unique_id "amuUWAMgr4yz2OQW0xrl4QAAAPc"]
[Thu Jul 30 13:13:44.586762 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/il.php"] [unique_id "amuUWAMgr4yz2OQW0xrl4gAAAPE"]
[Thu Jul 30 13:13:44.586879 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/il.php"] [unique_id "amuUWAMgr4yz2OQW0xrl4gAAAPE"]
[Thu Jul 30 13:13:44.927049 2026] [security2:error] [pid 849392:tid 849543] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/admin.php"] [unique_id "amuUWAMgr4yz2OQW0xrl5AAAAJk"]
[Thu Jul 30 13:13:44.927163 2026] [security2:error] [pid 849392:tid 849543] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/admin.php"] [unique_id "amuUWAMgr4yz2OQW0xrl5AAAAJk"]
[Thu Jul 30 13:13:45.091273 2026] [security2:error] [pid 849392:tid 849628] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/one.php"] [unique_id "amuUWQMgr4yz2OQW0xrl5gAAAO4"]
[Thu Jul 30 13:13:45.091432 2026] [security2:error] [pid 849392:tid 849628] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/one.php"] [unique_id "amuUWQMgr4yz2OQW0xrl5gAAAO4"]
[Thu Jul 30 13:13:45.444206 2026] [core:notice] [pid 849392:tid 849635] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:13:45.465818 2026] [security2:error] [pid 849392:tid 849526] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/222.php"] [unique_id "amuUWQMgr4yz2OQW0xrl6QAAAIg"]
[Thu Jul 30 13:13:45.465968 2026] [security2:error] [pid 849392:tid 849526] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/222.php"] [unique_id "amuUWQMgr4yz2OQW0xrl6QAAAIg"]
[Thu Jul 30 13:13:45.580185 2026] [security2:error] [pid 849392:tid 849559] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/002.php"] [unique_id "amuUWQMgr4yz2OQW0xrl6gAAAKk"]
[Thu Jul 30 13:13:45.580290 2026] [security2:error] [pid 849392:tid 849559] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/002.php"] [unique_id "amuUWQMgr4yz2OQW0xrl6gAAAKk"]
[Thu Jul 30 13:13:45.987796 2026] [security2:error] [pid 849392:tid 849619] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuUWQMgr4yz2OQW0xrl7gAAAOU"]
[Thu Jul 30 13:13:45.987920 2026] [security2:error] [pid 849392:tid 849619] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuUWQMgr4yz2OQW0xrl7gAAAOU"]
[Thu Jul 30 13:13:46.052913 2026] [security2:error] [pid 849392:tid 849597] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/file1.php"] [unique_id "amuUWgMgr4yz2OQW0xrl7wAAAM8"]
[Thu Jul 30 13:13:46.053048 2026] [security2:error] [pid 849392:tid 849597] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/file1.php"] [unique_id "amuUWgMgr4yz2OQW0xrl7wAAAM8"]
[Thu Jul 30 13:13:46.475011 2026] [security2:error] [pid 849392:tid 849539] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/info.php"] [unique_id "amuUWgMgr4yz2OQW0xrl8QAAAJU"]
[Thu Jul 30 13:13:46.475171 2026] [security2:error] [pid 849392:tid 849539] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/info.php"] [unique_id "amuUWgMgr4yz2OQW0xrl8QAAAJU"]
[Thu Jul 30 13:13:46.534085 2026] [security2:error] [pid 849392:tid 849643] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/akimet.php"] [unique_id "amuUWgMgr4yz2OQW0xrl8gAAAP0"]
[Thu Jul 30 13:13:46.534189 2026] [security2:error] [pid 849392:tid 849643] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/akimet.php"] [unique_id "amuUWgMgr4yz2OQW0xrl8gAAAP0"]
[Thu Jul 30 13:13:46.961664 2026] [security2:error] [pid 849392:tid 849615] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/a.php"] [unique_id "amuUWgMgr4yz2OQW0xrl8wAAAOE"]
[Thu Jul 30 13:13:46.961787 2026] [security2:error] [pid 849392:tid 849615] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/a.php"] [unique_id "amuUWgMgr4yz2OQW0xrl8wAAAOE"]
[Thu Jul 30 13:13:47.044310 2026] [security2:error] [pid 849392:tid 849564] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/reop3.php"] [unique_id "amuUWwMgr4yz2OQW0xrl9AAAAK4"]
[Thu Jul 30 13:13:47.044429 2026] [security2:error] [pid 849392:tid 849564] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/reop3.php"] [unique_id "amuUWwMgr4yz2OQW0xrl9AAAAK4"]
[Thu Jul 30 13:13:47.469220 2026] [security2:error] [pid 849392:tid 849612] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/chosen.php"] [unique_id "amuUWwMgr4yz2OQW0xrl9wAAAN4"]
[Thu Jul 30 13:13:47.469344 2026] [security2:error] [pid 849392:tid 849612] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/chosen.php"] [unique_id "amuUWwMgr4yz2OQW0xrl9wAAAN4"]
[Thu Jul 30 13:13:47.554875 2026] [security2:error] [pid 849392:tid 849632] [client 172.213.232.128:58114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/nw.php"] [unique_id "amuUWwMgr4yz2OQW0xrl-AAAAPI"]
[Thu Jul 30 13:13:47.556584 2026] [security2:error] [pid 849392:tid 849589] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/h.php"] [unique_id "amuUWwMgr4yz2OQW0xrl-QAAAMc"]
[Thu Jul 30 13:13:47.556673 2026] [security2:error] [pid 849392:tid 849589] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/h.php"] [unique_id "amuUWwMgr4yz2OQW0xrl-QAAAMc"]
[Thu Jul 30 13:13:47.783155 2026] [security2:error] [pid 849392:tid 849525] [client 172.236.9.101:52348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUWwMgr4yz2OQW0xrl9QAAAIc"]
[Thu Jul 30 13:13:47.995321 2026] [security2:error] [pid 849392:tid 849616] [client 172.236.9.101:8229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUWwMgr4yz2OQW0xrl9gAAAOI"]
[Thu Jul 30 13:13:48.012895 2026] [security2:error] [pid 849392:tid 849542] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/index.php"] [unique_id "amuUXAMgr4yz2OQW0xrl_gAAAJg"]
[Thu Jul 30 13:13:48.013003 2026] [security2:error] [pid 849392:tid 849542] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/index.php"] [unique_id "amuUXAMgr4yz2OQW0xrl_gAAAJg"]
[Thu Jul 30 13:13:48.068830 2026] [security2:error] [pid 849392:tid 849567] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/2x.php"] [unique_id "amuUXAMgr4yz2OQW0xrl_wAAALE"]
[Thu Jul 30 13:13:48.068928 2026] [security2:error] [pid 849392:tid 849567] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/2x.php"] [unique_id "amuUXAMgr4yz2OQW0xrl_wAAALE"]
[Thu Jul 30 13:13:48.378378 2026] [security2:error] [pid 849392:tid 849552] [client 179.64.21.229:64119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUXAMgr4yz2OQW0xrmAQAAAKI"]
[Thu Jul 30 13:13:48.382201 2026] [security2:error] [pid 849392:tid 849552] [client 179.64.21.229:64119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUXAMgr4yz2OQW0xrmAQAAAKI"]
[Thu Jul 30 13:13:48.554574 2026] [security2:error] [pid 849392:tid 849579] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/vx.php"] [unique_id "amuUXAMgr4yz2OQW0xrmAgAAAL0"]
[Thu Jul 30 13:13:48.554684 2026] [security2:error] [pid 849392:tid 849579] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/vx.php"] [unique_id "amuUXAMgr4yz2OQW0xrmAgAAAL0"]
[Thu Jul 30 13:13:48.576767 2026] [security2:error] [pid 849392:tid 849586] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/petx.php"] [unique_id "amuUXAMgr4yz2OQW0xrmAwAAAMQ"]
[Thu Jul 30 13:13:48.576917 2026] [security2:error] [pid 849392:tid 849586] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/petx.php"] [unique_id "amuUXAMgr4yz2OQW0xrmAwAAAMQ"]
[Thu Jul 30 13:13:48.686763 2026] [security2:error] [pid 849392:tid 849642] [client 172.213.232.128:57945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/ova.php"] [unique_id "amuUXAMgr4yz2OQW0xrmBAAAAPw"]
[Thu Jul 30 13:13:49.086772 2026] [security2:error] [pid 849392:tid 849563] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/zxz.php"] [unique_id "amuUXQMgr4yz2OQW0xrmCAAAAK0"]
[Thu Jul 30 13:13:49.086869 2026] [security2:error] [pid 849392:tid 849563] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/zxz.php"] [unique_id "amuUXQMgr4yz2OQW0xrmCAAAAK0"]
[Thu Jul 30 13:13:49.128685 2026] [security2:error] [pid 849392:tid 849646] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/admin/controller/extension/"] [unique_id "amuUXQMgr4yz2OQW0xrmCQAAAQA"]
[Thu Jul 30 13:13:49.301785 2026] [core:notice] [pid 849392:tid 849614] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:13:49.406776 2026] [security2:error] [pid 849392:tid 849578] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wap.php"] [unique_id "amuUXQMgr4yz2OQW0xrmDgAAALw"]
[Thu Jul 30 13:13:49.407066 2026] [security2:error] [pid 849392:tid 849578] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wap.php"] [unique_id "amuUXQMgr4yz2OQW0xrmDgAAALw"]
[Thu Jul 30 13:13:49.570240 2026] [security2:error] [pid 849392:tid 849608] [client 172.213.232.128:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/robots.php"] [unique_id "amuUXQMgr4yz2OQW0xrmDwAAANo"]
[Thu Jul 30 13:13:49.603252 2026] [security2:error] [pid 849392:tid 849598] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/2.php"] [unique_id "amuUXQMgr4yz2OQW0xrmEAAAANA"]
[Thu Jul 30 13:13:49.603367 2026] [security2:error] [pid 849392:tid 849598] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/2.php"] [unique_id "amuUXQMgr4yz2OQW0xrmEAAAANA"]
[Thu Jul 30 13:13:49.927497 2026] [security2:error] [pid 849392:tid 849528] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-admin/wp.php"] [unique_id "amuUXQMgr4yz2OQW0xrmEQAAAIo"]
[Thu Jul 30 13:13:49.927619 2026] [security2:error] [pid 849392:tid 849528] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-admin/wp.php"] [unique_id "amuUXQMgr4yz2OQW0xrmEQAAAIo"]
[Thu Jul 30 13:13:50.107349 2026] [security2:error] [pid 849392:tid 849649] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/op.php"] [unique_id "amuUXgMgr4yz2OQW0xrmEwAAAQM"]
[Thu Jul 30 13:13:50.107462 2026] [security2:error] [pid 849392:tid 849649] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/op.php"] [unique_id "amuUXgMgr4yz2OQW0xrmEwAAAQM"]
[Thu Jul 30 13:13:50.429697 2026] [security2:error] [pid 849392:tid 849627] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/bgymj.php"] [unique_id "amuUXgMgr4yz2OQW0xrmGgAAAO0"]
[Thu Jul 30 13:13:50.429825 2026] [security2:error] [pid 849392:tid 849627] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/bgymj.php"] [unique_id "amuUXgMgr4yz2OQW0xrmGgAAAO0"]
[Thu Jul 30 13:13:50.631796 2026] [security2:error] [pid 849392:tid 849548] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/a5.php"] [unique_id "amuUXgMgr4yz2OQW0xrmHAAAAJ4"]
[Thu Jul 30 13:13:50.631909 2026] [security2:error] [pid 849392:tid 849548] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/a5.php"] [unique_id "amuUXgMgr4yz2OQW0xrmHAAAAJ4"]
[Thu Jul 30 13:13:50.773768 2026] [security2:error] [pid 849392:tid 849609] [client 172.236.9.101:58908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUXgMgr4yz2OQW0xrmGAAAANs"]
[Thu Jul 30 13:13:50.944814 2026] [security2:error] [pid 849392:tid 849574] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/aa.php"] [unique_id "amuUXgMgr4yz2OQW0xrmHQAAALg"]
[Thu Jul 30 13:13:50.944959 2026] [security2:error] [pid 849392:tid 849574] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/aa.php"] [unique_id "amuUXgMgr4yz2OQW0xrmHQAAALg"]
[Thu Jul 30 13:13:51.041138 2026] [security2:error] [pid 849392:tid 849621] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUXgMgr4yz2OQW0xrmFgAAAOc"]
[Thu Jul 30 13:13:51.138484 2026] [security2:error] [pid 849392:tid 849568] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ws80.php"] [unique_id "amuUXwMgr4yz2OQW0xrmHgAAALI"]
[Thu Jul 30 13:13:51.138601 2026] [security2:error] [pid 849392:tid 849568] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ws80.php"] [unique_id "amuUXwMgr4yz2OQW0xrmHgAAALI"]
[Thu Jul 30 13:13:51.463418 2026] [security2:error] [pid 849392:tid 849549] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-mail.php"] [unique_id "amuUXwMgr4yz2OQW0xrmIgAAAJ8"]
[Thu Jul 30 13:13:51.463523 2026] [security2:error] [pid 849392:tid 849549] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-mail.php"] [unique_id "amuUXwMgr4yz2OQW0xrmIgAAAJ8"]
[Thu Jul 30 13:13:51.484889 2026] [security2:error] [pid 849392:tid 849572] [client 172.213.232.128:51946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/alf.php"] [unique_id "amuUXwMgr4yz2OQW0xrmIwAAALY"]
[Thu Jul 30 13:13:51.636185 2026] [security2:error] [pid 849392:tid 849529] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/xa.php"] [unique_id "amuUXwMgr4yz2OQW0xrmJAAAAIs"]
[Thu Jul 30 13:13:51.636297 2026] [security2:error] [pid 849392:tid 849529] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/xa.php"] [unique_id "amuUXwMgr4yz2OQW0xrmJAAAAIs"]
[Thu Jul 30 13:13:52.024432 2026] [security2:error] [pid 849392:tid 849593] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/bolt.php"] [unique_id "amuUYAMgr4yz2OQW0xrmJQAAAMs"]
[Thu Jul 30 13:13:52.024548 2026] [security2:error] [pid 849392:tid 849593] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/bolt.php"] [unique_id "amuUYAMgr4yz2OQW0xrmJQAAAMs"]
[Thu Jul 30 13:13:52.140079 2026] [security2:error] [pid 849392:tid 849544] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/asd67.php"] [unique_id "amuUYAMgr4yz2OQW0xrmJgAAAJo"]
[Thu Jul 30 13:13:52.140191 2026] [security2:error] [pid 849392:tid 849544] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/asd67.php"] [unique_id "amuUYAMgr4yz2OQW0xrmJgAAAJo"]
[Thu Jul 30 13:13:52.333636 2026] [security2:error] [pid 849392:tid 849526] [client 172.213.232.128:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/feedback.php"] [unique_id "amuUYAMgr4yz2OQW0xrmJwAAAIg"]
[Thu Jul 30 13:13:52.530488 2026] [security2:error] [pid 849392:tid 849623] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/bthil.php"] [unique_id "amuUYAMgr4yz2OQW0xrmKAAAAOk"]
[Thu Jul 30 13:13:52.530614 2026] [security2:error] [pid 849392:tid 849623] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/bthil.php"] [unique_id "amuUYAMgr4yz2OQW0xrmKAAAAOk"]
[Thu Jul 30 13:13:52.641325 2026] [security2:error] [pid 849392:tid 849592] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/bk.php"] [unique_id "amuUYAMgr4yz2OQW0xrmLgAAAMo"]
[Thu Jul 30 13:13:52.641445 2026] [security2:error] [pid 849392:tid 849592] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/bk.php"] [unique_id "amuUYAMgr4yz2OQW0xrmLgAAAMo"]
[Thu Jul 30 13:13:53.086909 2026] [security2:error] [pid 849392:tid 849600] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/cgi-bin/"] [unique_id "amuUYQMgr4yz2OQW0xrmOwAAANI"]
[Thu Jul 30 13:13:53.157491 2026] [security2:error] [pid 849392:tid 849539] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-links.php"] [unique_id "amuUYQMgr4yz2OQW0xrmPAAAAJU"]
[Thu Jul 30 13:13:53.157614 2026] [security2:error] [pid 849392:tid 849539] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-links.php"] [unique_id "amuUYQMgr4yz2OQW0xrmPAAAAJU"]
[Thu Jul 30 13:13:53.690741 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/mosty.php"] [unique_id "amuUYQMgr4yz2OQW0xrmQQAAALc"]
[Thu Jul 30 13:13:53.690854 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/mosty.php"] [unique_id "amuUYQMgr4yz2OQW0xrmQQAAALc"]
[Thu Jul 30 13:13:53.997213 2026] [security2:error] [pid 849392:tid 849632] [client 172.213.232.128:51956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/gettest.php"] [unique_id "amuUYQMgr4yz2OQW0xrmSwAAAPI"]
[Thu Jul 30 13:13:54.130367 2026] [security2:error] [pid 849392:tid 849550] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/x.php"] [unique_id "amuUYgMgr4yz2OQW0xrmTAAAAKA"]
[Thu Jul 30 13:13:54.130534 2026] [security2:error] [pid 849392:tid 849550] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/x.php"] [unique_id "amuUYgMgr4yz2OQW0xrmTAAAAKA"]
[Thu Jul 30 13:13:54.198262 2026] [security2:error] [pid 849392:tid 849552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/sump3.php"] [unique_id "amuUYgMgr4yz2OQW0xrmTQAAAKI"]
[Thu Jul 30 13:13:54.198637 2026] [security2:error] [pid 849392:tid 849552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/sump3.php"] [unique_id "amuUYgMgr4yz2OQW0xrmTQAAAKI"]
[Thu Jul 30 13:13:54.358910 2026] [security2:error] [pid 849392:tid 849470] [remote 57.141.0.37:24444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/613058497/feed/rss2/"] [unique_id "amuUYgMgr4yz2OQW0xrmVgAApEw"]
[Thu Jul 30 13:13:54.619966 2026] [security2:error] [pid 849392:tid 849532] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/index/function.php"] [unique_id "amuUYgMgr4yz2OQW0xrmYwAAAI4"]
[Thu Jul 30 13:13:54.620142 2026] [security2:error] [pid 849392:tid 849532] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/index/function.php"] [unique_id "amuUYgMgr4yz2OQW0xrmYwAAAI4"]
[Thu Jul 30 13:13:54.703271 2026] [security2:error] [pid 849392:tid 849614] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/first.php"] [unique_id "amuUYgMgr4yz2OQW0xrmZAAAAOA"]
[Thu Jul 30 13:13:54.703397 2026] [security2:error] [pid 849392:tid 849614] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/first.php"] [unique_id "amuUYgMgr4yz2OQW0xrmZAAAAOA"]
[Thu Jul 30 13:13:54.945226 2026] [security2:error] [pid 849392:tid 849581] [client 172.213.232.128:57953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/maint.php"] [unique_id "amuUYgMgr4yz2OQW0xrmZgAAAL8"]
[Thu Jul 30 13:13:55.042760 2026] [security2:error] [pid 849392:tid 849479] [remote 34.195.60.66:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "palmtreepools.ca"] [uri "/"] [unique_id "amuUYwMgr4yz2OQW0xrmaAAAplU"]
[Thu Jul 30 13:13:55.132210 2026] [security2:error] [pid 849392:tid 849558] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/aaa.php"] [unique_id "amuUYwMgr4yz2OQW0xrmagAAAKg"]
[Thu Jul 30 13:13:55.132320 2026] [security2:error] [pid 849392:tid 849558] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/aaa.php"] [unique_id "amuUYwMgr4yz2OQW0xrmagAAAKg"]
[Thu Jul 30 13:13:55.212558 2026] [security2:error] [pid 849392:tid 849609] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/acp.php"] [unique_id "amuUYwMgr4yz2OQW0xrmbgAAANs"]
[Thu Jul 30 13:13:55.212679 2026] [security2:error] [pid 849392:tid 849609] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/acp.php"] [unique_id "amuUYwMgr4yz2OQW0xrmbgAAANs"]
[Thu Jul 30 13:13:55.640883 2026] [security2:error] [pid 849392:tid 849624] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/abcd.php"] [unique_id "amuUYwMgr4yz2OQW0xrmcAAAAOo"]
[Thu Jul 30 13:13:55.641030 2026] [security2:error] [pid 849392:tid 849624] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/abcd.php"] [unique_id "amuUYwMgr4yz2OQW0xrmcAAAAOo"]
[Thu Jul 30 13:13:55.697241 2026] [security2:error] [pid 849392:tid 849568] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-good.php"] [unique_id "amuUYwMgr4yz2OQW0xrmcQAAALI"]
[Thu Jul 30 13:13:55.697365 2026] [security2:error] [pid 849392:tid 849568] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-good.php"] [unique_id "amuUYwMgr4yz2OQW0xrmcQAAALI"]
[Thu Jul 30 13:13:56.159634 2026] [security2:error] [pid 849392:tid 849599] [client 172.213.232.128:57926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/files.php"] [unique_id "amuUZAMgr4yz2OQW0xrmdwAAANE"]
[Thu Jul 30 13:13:56.159725 2026] [security2:error] [pid 849392:tid 849630] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-good.php"] [unique_id "amuUZAMgr4yz2OQW0xrmeAAAAPA"]
[Thu Jul 30 13:13:56.159812 2026] [security2:error] [pid 849392:tid 849630] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-good.php"] [unique_id "amuUZAMgr4yz2OQW0xrmeAAAAPA"]
[Thu Jul 30 13:13:56.185723 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/daerl3.php"] [unique_id "amuUZAMgr4yz2OQW0xrmegAAAPE"]
[Thu Jul 30 13:13:56.185819 2026] [security2:error] [pid 849392:tid 849631] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/daerl3.php"] [unique_id "amuUZAMgr4yz2OQW0xrmegAAAPE"]
[Thu Jul 30 13:13:56.611349 2026] [security2:error] [pid 849392:tid 849647] [client 213.152.161.85:56712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuUZAMgr4yz2OQW0xrmfgAAAQE"]
[Thu Jul 30 13:13:56.611465 2026] [security2:error] [pid 849392:tid 849647] [client 213.152.161.85:56712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuUZAMgr4yz2OQW0xrmfgAAAQE"]
[Thu Jul 30 13:13:56.692290 2026] [security2:error] [pid 849392:tid 849540] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/php5.php"] [unique_id "amuUZAMgr4yz2OQW0xrmfwAAAJY"]
[Thu Jul 30 13:13:56.692408 2026] [security2:error] [pid 849392:tid 849540] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/php5.php"] [unique_id "amuUZAMgr4yz2OQW0xrmfwAAAJY"]
[Thu Jul 30 13:13:56.694065 2026] [security2:error] [pid 849392:tid 849626] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/simple.php"] [unique_id "amuUZAMgr4yz2OQW0xrmgAAAAOw"]
[Thu Jul 30 13:13:56.694150 2026] [security2:error] [pid 849392:tid 849626] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/simple.php"] [unique_id "amuUZAMgr4yz2OQW0xrmgAAAAOw"]
[Thu Jul 30 13:13:57.176949 2026] [security2:error] [pid 849392:tid 849643] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/xoot.php"] [unique_id "amuUZQMgr4yz2OQW0xrmhAAAAP0"]
[Thu Jul 30 13:13:57.177074 2026] [security2:error] [pid 849392:tid 849643] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/xoot.php"] [unique_id "amuUZQMgr4yz2OQW0xrmhAAAAP0"]
[Thu Jul 30 13:13:57.203746 2026] [security2:error] [pid 849392:tid 849537] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/edit-tags.php"] [unique_id "amuUZQMgr4yz2OQW0xrmhQAAAJM"]
[Thu Jul 30 13:13:57.203892 2026] [security2:error] [pid 849392:tid 849537] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/edit-tags.php"] [unique_id "amuUZQMgr4yz2OQW0xrmhQAAAJM"]
[Thu Jul 30 13:13:57.710539 2026] [security2:error] [pid 849392:tid 849590] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/u.php"] [unique_id "amuUZQMgr4yz2OQW0xrmiAAAAMg"]
[Thu Jul 30 13:13:57.710719 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/clxcc.php"] [unique_id "amuUZQMgr4yz2OQW0xrmiQAAALc"]
[Thu Jul 30 13:13:57.710724 2026] [security2:error] [pid 849392:tid 849590] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/u.php"] [unique_id "amuUZQMgr4yz2OQW0xrmiAAAAMg"]
[Thu Jul 30 13:13:57.710818 2026] [security2:error] [pid 849392:tid 849573] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/clxcc.php"] [unique_id "amuUZQMgr4yz2OQW0xrmiQAAALc"]
[Thu Jul 30 13:13:58.054587 2026] [security2:error] [pid 849392:tid 849615] [client 43.172.197.84:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/01/21/bottes-en-cuir/"] [unique_id "amuUZQMgr4yz2OQW0xrmiwAAAOE"]
[Thu Jul 30 13:13:58.250463 2026] [security2:error] [pid 849392:tid 849580] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ai.php"] [unique_id "amuUZgMgr4yz2OQW0xrmkAAAAL4"]
[Thu Jul 30 13:13:58.250555 2026] [security2:error] [pid 849392:tid 849580] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ai.php"] [unique_id "amuUZgMgr4yz2OQW0xrmkAAAAL4"]
[Thu Jul 30 13:13:58.258647 2026] [security2:error] [pid 849392:tid 849601] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/themes/admin.php"] [unique_id "amuUZgMgr4yz2OQW0xrmkQAAANM"]
[Thu Jul 30 13:13:58.258780 2026] [security2:error] [pid 849392:tid 849601] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/themes/admin.php"] [unique_id "amuUZgMgr4yz2OQW0xrmkQAAANM"]
[Thu Jul 30 13:13:58.406135 2026] [security2:error] [pid 849392:tid 849582] [client 172.213.232.128:57978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/gecko.php"] [unique_id "amuUZgMgr4yz2OQW0xrmkgAAAMA"]
[Thu Jul 30 13:13:58.692468 2026] [core:notice] [pid 849392:tid 849541] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:13:58.697342 2026] [security2:error] [pid 849392:tid 849541] [client 43.173.174.68:46792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/01/21/bottes-en-cuir/"] [unique_id "amuUZgMgr4yz2OQW0xrmlAAAAJc"], referer: https://carnetdeshopping.com/index.php/2014/01/21/bottes-en-cuir/
[Thu Jul 30 13:13:58.782357 2026] [security2:error] [pid 849392:tid 849552] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/nwflm.php"] [unique_id "amuUZgMgr4yz2OQW0xrmlQAAAKI"]
[Thu Jul 30 13:13:58.782484 2026] [security2:error] [pid 849392:tid 849552] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/nwflm.php"] [unique_id "amuUZgMgr4yz2OQW0xrmlQAAAKI"]
[Thu Jul 30 13:13:58.802675 2026] [security2:error] [pid 849392:tid 849633] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/h.php"] [unique_id "amuUZgMgr4yz2OQW0xrmlgAAAPM"]
[Thu Jul 30 13:13:58.802839 2026] [security2:error] [pid 849392:tid 849633] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/h.php"] [unique_id "amuUZgMgr4yz2OQW0xrmlgAAAPM"]
[Thu Jul 30 13:13:58.973640 2026] [security2:error] [pid 849392:tid 849566] [client 179.64.21.229:41104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUZgMgr4yz2OQW0xrmmAAAALA"]
[Thu Jul 30 13:13:58.973797 2026] [security2:error] [pid 849392:tid 849566] [client 179.64.21.229:41104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUZgMgr4yz2OQW0xrmmAAAALA"]
[Thu Jul 30 13:13:59.266994 2026] [security2:error] [pid 849392:tid 849527] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/hypo.php"] [unique_id "amuUZwMgr4yz2OQW0xrmnAAAAIk"]
[Thu Jul 30 13:13:59.267110 2026] [security2:error] [pid 849392:tid 849527] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/hypo.php"] [unique_id "amuUZwMgr4yz2OQW0xrmnAAAAIk"]
[Thu Jul 30 13:13:59.314173 2026] [security2:error] [pid 849392:tid 849636] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ms-edit.php"] [unique_id "amuUZwMgr4yz2OQW0xrmnQAAAPY"]
[Thu Jul 30 13:13:59.314273 2026] [security2:error] [pid 849392:tid 849636] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ms-edit.php"] [unique_id "amuUZwMgr4yz2OQW0xrmnQAAAPY"]
[Thu Jul 30 13:13:59.792122 2026] [security2:error] [pid 849392:tid 849644] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/w3llscc.php"] [unique_id "amuUZwMgr4yz2OQW0xrmngAAAP4"]
[Thu Jul 30 13:13:59.792244 2026] [security2:error] [pid 849392:tid 849644] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/w3llscc.php"] [unique_id "amuUZwMgr4yz2OQW0xrmngAAAP4"]
[Thu Jul 30 13:13:59.819132 2026] [security2:error] [pid 849392:tid 849560] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/a7.php"] [unique_id "amuUZwMgr4yz2OQW0xrmnwAAAKo"]
[Thu Jul 30 13:13:59.819276 2026] [security2:error] [pid 849392:tid 849560] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/a7.php"] [unique_id "amuUZwMgr4yz2OQW0xrmnwAAAKo"]
[Thu Jul 30 13:14:00.315971 2026] [security2:error] [pid 849392:tid 849556] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuUaAMgr4yz2OQW0xrmoQAAAKY"]
[Thu Jul 30 13:14:00.316129 2026] [security2:error] [pid 849392:tid 849556] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuUaAMgr4yz2OQW0xrmoQAAAKY"]
[Thu Jul 30 13:14:00.331466 2026] [security2:error] [pid 849392:tid 849524] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/manager.php"] [unique_id "amuUaAMgr4yz2OQW0xrmogAAAIY"]
[Thu Jul 30 13:14:00.331587 2026] [security2:error] [pid 849392:tid 849524] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/manager.php"] [unique_id "amuUaAMgr4yz2OQW0xrmogAAAIY"]
[Thu Jul 30 13:14:00.808376 2026] [security2:error] [pid 849392:tid 849609] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/w1.php"] [unique_id "amuUaAMgr4yz2OQW0xrmpwAAANs"]
[Thu Jul 30 13:14:00.808533 2026] [security2:error] [pid 849392:tid 849609] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/w1.php"] [unique_id "amuUaAMgr4yz2OQW0xrmpwAAANs"]
[Thu Jul 30 13:14:00.818237 2026] [security2:error] [pid 849392:tid 849570] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/8.php"] [unique_id "amuUaAMgr4yz2OQW0xrmqAAAALQ"]
[Thu Jul 30 13:14:00.818353 2026] [security2:error] [pid 849392:tid 849570] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/8.php"] [unique_id "amuUaAMgr4yz2OQW0xrmqAAAALQ"]
[Thu Jul 30 13:14:01.290818 2026] [security2:error] [pid 849392:tid 849642] [client 172.213.232.128:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/zwso.php"] [unique_id "amuUaQMgr4yz2OQW0xrmrQAAAPw"]
[Thu Jul 30 13:14:01.300503 2026] [security2:error] [pid 849392:tid 849568] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/fnstall.php"] [unique_id "amuUaQMgr4yz2OQW0xrmrgAAALI"]
[Thu Jul 30 13:14:01.300696 2026] [security2:error] [pid 849392:tid 849568] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/fnstall.php"] [unique_id "amuUaQMgr4yz2OQW0xrmrgAAALI"]
[Thu Jul 30 13:14:01.453696 2026] [security2:error] [pid 849392:tid 849549] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/wp-includes/fonts/"] [unique_id "amuUaQMgr4yz2OQW0xrmrwAAAJ8"]
[Thu Jul 30 13:14:01.772295 2026] [security2:error] [pid 849392:tid 849624] [client 172.236.9.101:40241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUaQMgr4yz2OQW0xrmrAAAAOo"]
[Thu Jul 30 13:14:01.783795 2026] [security2:error] [pid 849392:tid 849599] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/edorxrr.php"] [unique_id "amuUaQMgr4yz2OQW0xrmsgAAANE"]
[Thu Jul 30 13:14:01.783900 2026] [security2:error] [pid 849392:tid 849599] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/edorxrr.php"] [unique_id "amuUaQMgr4yz2OQW0xrmsgAAANE"]
[Thu Jul 30 13:14:01.966739 2026] [security2:error] [pid 849392:tid 849602] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-login.php"] [unique_id "amuUaQMgr4yz2OQW0xrmsQAAANQ"]
[Thu Jul 30 13:14:01.966926 2026] [security2:error] [pid 849392:tid 849602] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-login.php"] [unique_id "amuUaQMgr4yz2OQW0xrmsQAAANQ"]
[Thu Jul 30 13:14:02.286992 2026] [security2:error] [pid 849392:tid 849593] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/setup.php"] [unique_id "amuUagMgr4yz2OQW0xrmtwAAAMs"]
[Thu Jul 30 13:14:02.287108 2026] [security2:error] [pid 849392:tid 849593] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/setup.php"] [unique_id "amuUagMgr4yz2OQW0xrmtwAAAMs"]
[Thu Jul 30 13:14:02.289723 2026] [core:notice] [pid 849392:tid 849516] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:02.379521 2026] [core:notice] [pid 849392:tid 849544] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:02.470846 2026] [security2:error] [pid 849392:tid 849647] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/default.php"] [unique_id "amuUagMgr4yz2OQW0xrmugAAAQE"]
[Thu Jul 30 13:14:02.471089 2026] [security2:error] [pid 849392:tid 849647] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/default.php"] [unique_id "amuUagMgr4yz2OQW0xrmugAAAQE"]
[Thu Jul 30 13:14:02.587679 2026] [autoindex:error] [pid 849392:tid 849597] [client 43.130.91.95:56400] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:14:02.701590 2026] [security2:error] [pid 849392:tid 849630] [client 31.215.60.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUaQMgr4yz2OQW0xrmswAA8GY"], referer: https://allmontecristi.com
[Thu Jul 30 13:14:02.770260 2026] [security2:error] [pid 849392:tid 849537] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/6.php"] [unique_id "amuUagMgr4yz2OQW0xrmvgAAAJM"]
[Thu Jul 30 13:14:02.770412 2026] [security2:error] [pid 849392:tid 849537] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/6.php"] [unique_id "amuUagMgr4yz2OQW0xrmvgAAAJM"]
[Thu Jul 30 13:14:02.893741 2026] [security2:error] [pid 849392:tid 849559] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUagMgr4yz2OQW0xrmtgAAAKk"]
[Thu Jul 30 13:14:02.986608 2026] [security2:error] [pid 849392:tid 849588] [client 172.213.232.128:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/13.php"] [unique_id "amuUagMgr4yz2OQW0xrmwAAAAMY"]
[Thu Jul 30 13:14:03.000088 2026] [security2:error] [pid 849392:tid 849591] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/i.php"] [unique_id "amuUagMgr4yz2OQW0xrmwQAAAMk"]
[Thu Jul 30 13:14:03.000184 2026] [security2:error] [pid 849392:tid 849591] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/i.php"] [unique_id "amuUagMgr4yz2OQW0xrmwQAAAMk"]
[Thu Jul 30 13:14:03.178252 2026] [security2:error] [pid 849392:tid 849617] [client 66.249.66.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUagMgr4yz2OQW0xrmuwAA4wA"]
[Thu Jul 30 13:14:03.256938 2026] [security2:error] [pid 849392:tid 849615] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/w3lls.php"] [unique_id "amuUawMgr4yz2OQW0xrmwgAAAOE"]
[Thu Jul 30 13:14:03.257073 2026] [security2:error] [pid 849392:tid 849615] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/w3lls.php"] [unique_id "amuUawMgr4yz2OQW0xrmwgAAAOE"]
[Thu Jul 30 13:14:03.579335 2026] [security2:error] [pid 849392:tid 849536] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/wp-content/uploads/"] [unique_id "amuUawMgr4yz2OQW0xrmwwAAAJI"]
[Thu Jul 30 13:14:03.745931 2026] [security2:error] [pid 849392:tid 849546] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/99.php"] [unique_id "amuUawMgr4yz2OQW0xrmxAAAAJw"]
[Thu Jul 30 13:14:03.746071 2026] [security2:error] [pid 849392:tid 849546] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/99.php"] [unique_id "amuUawMgr4yz2OQW0xrmxAAAAJw"]
[Thu Jul 30 13:14:03.855345 2026] [security2:error] [pid 849392:tid 849634] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amuUawMgr4yz2OQW0xrmxQAAAPQ"]
[Thu Jul 30 13:14:03.855492 2026] [security2:error] [pid 849392:tid 849634] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amuUawMgr4yz2OQW0xrmxQAAAPQ"]
[Thu Jul 30 13:14:04.237940 2026] [security2:error] [pid 849392:tid 849542] [client 172.213.232.128:52052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/ava.php"] [unique_id "amuUbAMgr4yz2OQW0xrmxgAAAJg"]
[Thu Jul 30 13:14:04.279194 2026] [security2:error] [pid 849392:tid 849553] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-content/admin.php"] [unique_id "amuUbAMgr4yz2OQW0xrmyAAAAKM"]
[Thu Jul 30 13:14:04.279293 2026] [security2:error] [pid 849392:tid 849553] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-content/admin.php"] [unique_id "amuUbAMgr4yz2OQW0xrmyAAAAKM"]
[Thu Jul 30 13:14:04.409048 2026] [security2:error] [pid 849392:tid 849566] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/themes/index.php"] [unique_id "amuUbAMgr4yz2OQW0xrmzQAAALA"]
[Thu Jul 30 13:14:04.409180 2026] [security2:error] [pid 849392:tid 849566] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/themes/index.php"] [unique_id "amuUbAMgr4yz2OQW0xrmzQAAALA"]
[Thu Jul 30 13:14:04.796401 2026] [security2:error] [pid 849392:tid 849563] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/media.php"] [unique_id "amuUbAMgr4yz2OQW0xrm0wAAAK0"]
[Thu Jul 30 13:14:04.796515 2026] [security2:error] [pid 849392:tid 849563] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/media.php"] [unique_id "amuUbAMgr4yz2OQW0xrm0wAAAK0"]
[Thu Jul 30 13:14:05.054886 2026] [security2:error] [pid 849392:tid 849644] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/gecko-new.php"] [unique_id "amuUbQMgr4yz2OQW0xrm1QAAAP4"]
[Thu Jul 30 13:14:05.055031 2026] [security2:error] [pid 849392:tid 849644] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/gecko-new.php"] [unique_id "amuUbQMgr4yz2OQW0xrm1QAAAP4"]
[Thu Jul 30 13:14:05.300570 2026] [security2:error] [pid 849392:tid 849575] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuUbQMgr4yz2OQW0xrm1gAAALk"]
[Thu Jul 30 13:14:05.300682 2026] [security2:error] [pid 849392:tid 849575] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuUbQMgr4yz2OQW0xrm1gAAALk"]
[Thu Jul 30 13:14:05.334240 2026] [security2:error] [pid 849392:tid 849595] [client 172.213.232.128:58119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/main.php"] [unique_id "amuUbQMgr4yz2OQW0xrm1wAAAM0"]
[Thu Jul 30 13:14:05.618052 2026] [security2:error] [pid 849392:tid 849645] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/NewFile.php"] [unique_id "amuUbQMgr4yz2OQW0xrm3AAAAP8"]
[Thu Jul 30 13:14:05.618165 2026] [security2:error] [pid 849392:tid 849645] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/NewFile.php"] [unique_id "amuUbQMgr4yz2OQW0xrm3AAAAP8"]
[Thu Jul 30 13:14:05.799279 2026] [security2:error] [pid 849392:tid 849528] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/222.php"] [unique_id "amuUbQMgr4yz2OQW0xrm4wAAAIo"]
[Thu Jul 30 13:14:05.799443 2026] [security2:error] [pid 849392:tid 849528] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/222.php"] [unique_id "amuUbQMgr4yz2OQW0xrm4wAAAIo"]
[Thu Jul 30 13:14:06.126460 2026] [security2:error] [pid 849392:tid 849638] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-Blogs.php"] [unique_id "amuUbgMgr4yz2OQW0xrm5AAAAPg"]
[Thu Jul 30 13:14:06.126590 2026] [security2:error] [pid 849392:tid 849638] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-Blogs.php"] [unique_id "amuUbgMgr4yz2OQW0xrm5AAAAPg"]
[Thu Jul 30 13:14:06.167814 2026] [security2:error] [pid 849392:tid 849613] [client 223.109.255.170:50388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.marlboro-shop.com"] [uri "/"] [unique_id "amuUbgMgr4yz2OQW0xrm5QAAAN8"]
[Thu Jul 30 13:14:06.167941 2026] [security2:error] [pid 849392:tid 849613] [client 223.109.255.170:50388] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.marlboro-shop.com"] [uri "/"] [unique_id "amuUbgMgr4yz2OQW0xrm5QAAAN8"]
[Thu Jul 30 13:14:06.312506 2026] [security2:error] [pid 849392:tid 849627] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-load.php"] [unique_id "amuUbgMgr4yz2OQW0xrm5gAAAO0"]
[Thu Jul 30 13:14:06.312662 2026] [security2:error] [pid 849392:tid 849627] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-load.php"] [unique_id "amuUbgMgr4yz2OQW0xrm5gAAAO0"]
[Thu Jul 30 13:14:06.552244 2026] [core:notice] [pid 849392:tid 849403] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:06.660088 2026] [security2:error] [pid 849392:tid 849625] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-includes/fonts/index.php"] [unique_id "amuUbgMgr4yz2OQW0xrm6wAAAOs"]
[Thu Jul 30 13:14:06.660246 2026] [security2:error] [pid 849392:tid 849625] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-includes/fonts/index.php"] [unique_id "amuUbgMgr4yz2OQW0xrm6wAAAOs"]
[Thu Jul 30 13:14:06.677868 2026] [security2:error] [pid 849392:tid 849545] [client 66.249.70.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.saiqon.net"] [uri "/index.php"] [unique_id "amuUbQMgr4yz2OQW0xrm1AAAAJs"]
[Thu Jul 30 13:14:06.748916 2026] [core:notice] [pid 849392:tid 849555] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:06.828026 2026] [security2:error] [pid 849392:tid 849556] [client 172.213.232.128:57939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/wp-file.php"] [unique_id "amuUbgMgr4yz2OQW0xrm7gAAAKY"]
[Thu Jul 30 13:14:06.849243 2026] [security2:error] [pid 849392:tid 849609] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuUbgMgr4yz2OQW0xrm7wAAANs"]
[Thu Jul 30 13:14:06.849398 2026] [security2:error] [pid 849392:tid 849609] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuUbgMgr4yz2OQW0xrm7wAAANs"]
[Thu Jul 30 13:14:07.191857 2026] [security2:error] [pid 849392:tid 849574] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/themes.php"] [unique_id "amuUbwMgr4yz2OQW0xrm8AAAALg"]
[Thu Jul 30 13:14:07.192016 2026] [security2:error] [pid 849392:tid 849574] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/themes.php"] [unique_id "amuUbwMgr4yz2OQW0xrm8AAAALg"]
[Thu Jul 30 13:14:07.375595 2026] [security2:error] [pid 849392:tid 849585] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuUbwMgr4yz2OQW0xrm8QAAAMM"]
[Thu Jul 30 13:14:07.375722 2026] [security2:error] [pid 849392:tid 849585] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuUbwMgr4yz2OQW0xrm8QAAAMM"]
[Thu Jul 30 13:14:07.519493 2026] [fcgid:warn] [pid 849392:tid 849571] (70014)End of file found: [client 20.171.32.45:41986] mod_fcgid: can't get data from http client
[Thu Jul 30 13:14:07.725654 2026] [security2:error] [pid 849392:tid 849611] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/cv.php"] [unique_id "amuUbwMgr4yz2OQW0xrm9gAAAN0"]
[Thu Jul 30 13:14:07.725778 2026] [security2:error] [pid 849392:tid 849611] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/cv.php"] [unique_id "amuUbwMgr4yz2OQW0xrm9gAAAN0"]
[Thu Jul 30 13:14:07.887302 2026] [security2:error] [pid 849392:tid 849593] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/memberfuns.php"] [unique_id "amuUbwMgr4yz2OQW0xrm9wAAAMs"]
[Thu Jul 30 13:14:07.887438 2026] [security2:error] [pid 849392:tid 849593] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/memberfuns.php"] [unique_id "amuUbwMgr4yz2OQW0xrm9wAAAMs"]
[Thu Jul 30 13:14:08.279013 2026] [security2:error] [pid 849392:tid 849592] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/wp-admin/js/"] [unique_id "amuUcAMgr4yz2OQW0xrnAQAAAMo"]
[Thu Jul 30 13:14:08.379317 2026] [security2:error] [pid 849392:tid 849539] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/orange3.php"] [unique_id "amuUcAMgr4yz2OQW0xrnCQAAAJU"]
[Thu Jul 30 13:14:08.379422 2026] [security2:error] [pid 849392:tid 849539] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/orange3.php"] [unique_id "amuUcAMgr4yz2OQW0xrnCQAAAJU"]
[Thu Jul 30 13:14:08.485520 2026] [core:notice] [pid 849392:tid 849643] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:08.544853 2026] [security2:error] [pid 849392:tid 849559] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/uploads/index.php"] [unique_id "amuUcAMgr4yz2OQW0xrnCwAAAKk"]
[Thu Jul 30 13:14:08.544956 2026] [security2:error] [pid 849392:tid 849559] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-content/uploads/index.php"] [unique_id "amuUcAMgr4yz2OQW0xrnCwAAAKk"]
[Thu Jul 30 13:14:08.614738 2026] [core:notice] [pid 849392:tid 849564] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:08.904441 2026] [security2:error] [pid 849392:tid 849588] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuUcAMgr4yz2OQW0xrnDgAAAMY"]
[Thu Jul 30 13:14:08.904561 2026] [security2:error] [pid 849392:tid 849588] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuUcAMgr4yz2OQW0xrnDgAAAMY"]
[Thu Jul 30 13:14:09.028638 2026] [security2:error] [pid 849392:tid 849612] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ws83.php"] [unique_id "amuUcQMgr4yz2OQW0xrnDwAAAN4"]
[Thu Jul 30 13:14:09.028748 2026] [security2:error] [pid 849392:tid 849612] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ws83.php"] [unique_id "amuUcQMgr4yz2OQW0xrnDwAAAN4"]
[Thu Jul 30 13:14:09.082469 2026] [core:notice] [pid 849392:tid 849510] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:09.433661 2026] [security2:error] [pid 849392:tid 849619] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/wp-the.php"] [unique_id "amuUcQMgr4yz2OQW0xrnEwAAAOU"]
[Thu Jul 30 13:14:09.433810 2026] [security2:error] [pid 849392:tid 849619] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/wp-the.php"] [unique_id "amuUcQMgr4yz2OQW0xrnEwAAAOU"]
[Thu Jul 30 13:14:09.708272 2026] [security2:error] [pid 849392:tid 849617] [client 179.64.21.229:36530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUcQMgr4yz2OQW0xrnFAAAAOM"]
[Thu Jul 30 13:14:09.718597 2026] [security2:error] [pid 849392:tid 849617] [client 179.64.21.229:36530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUcQMgr4yz2OQW0xrnFAAAAOM"]
[Thu Jul 30 13:14:09.921871 2026] [security2:error] [pid 849392:tid 849601] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/crgio.php"] [unique_id "amuUcQMgr4yz2OQW0xrnFgAAANM"]
[Thu Jul 30 13:14:09.922023 2026] [security2:error] [pid 849392:tid 849601] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/crgio.php"] [unique_id "amuUcQMgr4yz2OQW0xrnFgAAANM"]
[Thu Jul 30 13:14:10.119910 2026] [security2:error] [pid 849392:tid 849629] [client 172.213.232.128:58161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/wp-signin.php"] [unique_id "amuUcgMgr4yz2OQW0xrnFwAAAO8"]
[Thu Jul 30 13:14:10.423894 2026] [security2:error] [pid 849392:tid 849633] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ws13.php"] [unique_id "amuUcgMgr4yz2OQW0xrnGwAAAPM"]
[Thu Jul 30 13:14:10.424054 2026] [security2:error] [pid 849392:tid 849633] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ws13.php"] [unique_id "amuUcgMgr4yz2OQW0xrnGwAAAPM"]
[Thu Jul 30 13:14:10.492961 2026] [security2:error] [pid 849392:tid 849566] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/atex1.php"] [unique_id "amuUcgMgr4yz2OQW0xrnHAAAALA"]
[Thu Jul 30 13:14:10.493161 2026] [security2:error] [pid 849392:tid 849566] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/atex1.php"] [unique_id "amuUcgMgr4yz2OQW0xrnHAAAALA"]
[Thu Jul 30 13:14:10.908890 2026] [security2:error] [pid 849392:tid 849605] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/srontol.php"] [unique_id "amuUcgMgr4yz2OQW0xrnIQAAANc"]
[Thu Jul 30 13:14:10.909029 2026] [security2:error] [pid 849392:tid 849605] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/srontol.php"] [unique_id "amuUcgMgr4yz2OQW0xrnIQAAANc"]
[Thu Jul 30 13:14:11.004829 2026] [security2:error] [pid 849392:tid 849587] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/class-t.api.php"] [unique_id "amuUcwMgr4yz2OQW0xrnIgAAAMU"]
[Thu Jul 30 13:14:11.004943 2026] [security2:error] [pid 849392:tid 849587] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/class-t.api.php"] [unique_id "amuUcwMgr4yz2OQW0xrnIgAAAMU"]
[Thu Jul 30 13:14:11.396877 2026] [security2:error] [pid 849392:tid 849560] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/miru3.php"] [unique_id "amuUcwMgr4yz2OQW0xrnJQAAAKo"]
[Thu Jul 30 13:14:11.397048 2026] [security2:error] [pid 849392:tid 849560] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/miru3.php"] [unique_id "amuUcwMgr4yz2OQW0xrnJQAAAKo"]
[Thu Jul 30 13:14:11.490281 2026] [security2:error] [pid 849392:tid 849614] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/w.php"] [unique_id "amuUcwMgr4yz2OQW0xrnJgAAAOA"]
[Thu Jul 30 13:14:11.490400 2026] [security2:error] [pid 849392:tid 849614] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/w.php"] [unique_id "amuUcwMgr4yz2OQW0xrnJgAAAOA"]
[Thu Jul 30 13:14:11.739460 2026] [security2:error] [pid 849392:tid 849538] [client 172.213.232.128:52005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/simi.php"] [unique_id "amuUcwMgr4yz2OQW0xrnJwAAAJQ"]
[Thu Jul 30 13:14:11.785684 2026] [security2:error] [pid 849392:tid 849644] [client 172.236.9.101:56626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUcwMgr4yz2OQW0xrnJAAAAP4"]
[Thu Jul 30 13:14:11.905302 2026] [security2:error] [pid 849392:tid 849528] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ingfo.php"] [unique_id "amuUcwMgr4yz2OQW0xrnKAAAAIo"]
[Thu Jul 30 13:14:11.905418 2026] [security2:error] [pid 849392:tid 849528] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ingfo.php"] [unique_id "amuUcwMgr4yz2OQW0xrnKAAAAIo"]
[Thu Jul 30 13:14:12.435645 2026] [security2:error] [pid 849392:tid 849570] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ey5.php"] [unique_id "amuUdAMgr4yz2OQW0xrnLAAAALQ"]
[Thu Jul 30 13:14:12.435753 2026] [security2:error] [pid 849392:tid 849570] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/ey5.php"] [unique_id "amuUdAMgr4yz2OQW0xrnLAAAALQ"]
[Thu Jul 30 13:14:12.464054 2026] [security2:error] [pid 849392:tid 849531] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/archive.php"] [unique_id "amuUdAMgr4yz2OQW0xrnLQAAAI0"]
[Thu Jul 30 13:14:12.464149 2026] [security2:error] [pid 849392:tid 849531] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/archive.php"] [unique_id "amuUdAMgr4yz2OQW0xrnLQAAAI0"]
[Thu Jul 30 13:14:12.943802 2026] [security2:error] [pid 849392:tid 849611] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/fine.php"] [unique_id "amuUdAMgr4yz2OQW0xrnNQAAAN0"]
[Thu Jul 30 13:14:12.943936 2026] [security2:error] [pid 849392:tid 849611] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.markmocek.com"] [uri "/fine.php"] [unique_id "amuUdAMgr4yz2OQW0xrnNQAAAN0"]
[Thu Jul 30 13:14:12.997383 2026] [security2:error] [pid 849392:tid 849419] [remote 57.141.0.56:61686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuUdAMgr4yz2OQW0xrnNgAAkRk"]
[Thu Jul 30 13:14:13.026620 2026] [security2:error] [pid 849392:tid 849637] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/bless.php"] [unique_id "amuUdQMgr4yz2OQW0xrnNwAAAPc"]
[Thu Jul 30 13:14:13.026727 2026] [security2:error] [pid 849392:tid 849637] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/bless.php"] [unique_id "amuUdQMgr4yz2OQW0xrnNwAAAPc"]
[Thu Jul 30 13:14:13.534511 2026] [security2:error] [pid 849392:tid 849631] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/sagax1.php"] [unique_id "amuUdQMgr4yz2OQW0xrnOQAAAPE"]
[Thu Jul 30 13:14:13.534618 2026] [security2:error] [pid 849392:tid 849631] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/sagax1.php"] [unique_id "amuUdQMgr4yz2OQW0xrnOQAAAPE"]
[Thu Jul 30 13:14:14.047614 2026] [security2:error] [pid 849392:tid 849573] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wpc.php"] [unique_id "amuUdgMgr4yz2OQW0xrnPQAAALc"]
[Thu Jul 30 13:14:14.047725 2026] [security2:error] [pid 849392:tid 849573] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wpc.php"] [unique_id "amuUdgMgr4yz2OQW0xrnPQAAALc"]
[Thu Jul 30 13:14:14.561499 2026] [security2:error] [pid 849392:tid 849550] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/fone1.php"] [unique_id "amuUdgMgr4yz2OQW0xrnSwAAAKA"]
[Thu Jul 30 13:14:14.561643 2026] [security2:error] [pid 849392:tid 849550] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/fone1.php"] [unique_id "amuUdgMgr4yz2OQW0xrnSwAAAKA"]
[Thu Jul 30 13:14:14.885027 2026] [proxy:error] [pid 849392:tid 849620] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:14:14.885094 2026] [proxy_http:error] [pid 849392:tid 849620] [client 18.211.55.47:29990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:14:14.885649 2026] [proxy:error] [pid 849392:tid 849620] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:14:14.885692 2026] [proxy_http:error] [pid 849392:tid 849620] [client 18.211.55.47:29990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:14:14.886297 2026] [autoindex:error] [pid 849392:tid 849634] [client 98.87.102.177:58857] AH01276: Cannot serve directory /home1/uixgzjte/public_html/chicago-mfg.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:14:14.899407 2026] [proxy:error] [pid 849392:tid 849563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:14:14.899480 2026] [proxy_http:error] [pid 849392:tid 849563] [client 44.216.125.112:1980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:14:14.900204 2026] [proxy:error] [pid 849392:tid 849563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:14:14.900254 2026] [proxy_http:error] [pid 849392:tid 849563] [client 44.216.125.112:1980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:14:14.932678 2026] [autoindex:error] [pid 849392:tid 849527] [client 18.211.55.47:44344] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:14:15.062791 2026] [security2:error] [pid 849392:tid 849605] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ncx.php"] [unique_id "amuUdwMgr4yz2OQW0xrnWQAAANc"]
[Thu Jul 30 13:14:15.062928 2026] [security2:error] [pid 849392:tid 849605] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ncx.php"] [unique_id "amuUdwMgr4yz2OQW0xrnWQAAANc"]
[Thu Jul 30 13:14:15.680725 2026] [security2:error] [pid 849392:tid 849562] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-admin/js/index.php"] [unique_id "amuUdwMgr4yz2OQW0xrnXgAAAKw"]
[Thu Jul 30 13:14:15.680848 2026] [security2:error] [pid 849392:tid 849562] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-admin/js/index.php"] [unique_id "amuUdwMgr4yz2OQW0xrnXgAAAKw"]
[Thu Jul 30 13:14:16.054265 2026] [security2:error] [pid 849392:tid 849574] [client 172.213.232.128:51989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/wp-conf.php"] [unique_id "amuUeAMgr4yz2OQW0xrnYgAAALg"]
[Thu Jul 30 13:14:16.201240 2026] [security2:error] [pid 849392:tid 849609] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wso.php"] [unique_id "amuUeAMgr4yz2OQW0xrnZgAAANs"]
[Thu Jul 30 13:14:16.201350 2026] [security2:error] [pid 849392:tid 849609] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wso.php"] [unique_id "amuUeAMgr4yz2OQW0xrnZgAAANs"]
[Thu Jul 30 13:14:16.327209 2026] [core:notice] [pid 849392:tid 849528] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:16.378589 2026] [security2:error] [pid 849392:tid 849542] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUdwMgr4yz2OQW0xrnXAAAmCU"]
[Thu Jul 30 13:14:16.722035 2026] [security2:error] [pid 849392:tid 849599] [client 172.213.232.128:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuUeAMgr4yz2OQW0xrnawAAANE"]
[Thu Jul 30 13:14:16.741833 2026] [security2:error] [pid 849392:tid 849628] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/zup.php73"] [unique_id "amuUeAMgr4yz2OQW0xrnbAAAAO4"]
[Thu Jul 30 13:14:16.741991 2026] [security2:error] [pid 849392:tid 849628] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/zup.php73"] [unique_id "amuUeAMgr4yz2OQW0xrnbAAAAO4"]
[Thu Jul 30 13:14:17.229714 2026] [security2:error] [pid 849392:tid 849555] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUeAMgr4yz2OQW0xrnaQAApSQ"]
[Thu Jul 30 13:14:17.249600 2026] [security2:error] [pid 849392:tid 849606] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/k.php"] [unique_id "amuUeQMgr4yz2OQW0xrnbwAAANg"]
[Thu Jul 30 13:14:17.249710 2026] [security2:error] [pid 849392:tid 849606] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/k.php"] [unique_id "amuUeQMgr4yz2OQW0xrnbwAAANg"]
[Thu Jul 30 13:14:17.716960 2026] [security2:error] [pid 849392:tid 849642] [client 2607:fea8:245d:5c00:843c:32d0:59fd:763b:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUeAMgr4yz2OQW0xrnagAA_C8"], referer: https://allmontecristi.com
[Thu Jul 30 13:14:17.766242 2026] [security2:error] [pid 849392:tid 849539] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-blink.php"] [unique_id "amuUeQMgr4yz2OQW0xrncQAAAJU"]
[Thu Jul 30 13:14:17.766343 2026] [security2:error] [pid 849392:tid 849539] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-blink.php"] [unique_id "amuUeQMgr4yz2OQW0xrncQAAAJU"]
[Thu Jul 30 13:14:18.341351 2026] [security2:error] [pid 849392:tid 849610] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/randkeyword.PhP7"] [unique_id "amuUegMgr4yz2OQW0xrnfwAAANw"]
[Thu Jul 30 13:14:18.656815 2026] [security2:error] [pid 849392:tid 849540] [client 172.213.232.128:58149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/bala.php"] [unique_id "amuUegMgr4yz2OQW0xrngwAAAJY"]
[Thu Jul 30 13:14:19.069079 2026] [core:notice] [pid 849392:tid 849445] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:19.448741 2026] [security2:error] [pid 849392:tid 849607] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/ectoplasm/"] [unique_id "amuUewMgr4yz2OQW0xrnhQAAANk"]
[Thu Jul 30 13:14:19.735577 2026] [security2:error] [pid 849392:tid 849614] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.prolineroofingservices.homes"] [uri "/___proxy_subdomain_webmail/wp-content/"] [unique_id "amuUewMgr4yz2OQW0xrnhwAAAOA"]
[Thu Jul 30 13:14:19.804500 2026] [security2:error] [pid 849392:tid 849532] [client 172.213.232.128:57954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/bk.php"] [unique_id "amuUewMgr4yz2OQW0xrniAAAAI4"]
[Thu Jul 30 13:14:19.962828 2026] [security2:error] [pid 849392:tid 849438] [remote 216.73.217.142:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUewMgr4yz2OQW0xrnigAAryw"]
[Thu Jul 30 13:14:19.994422 2026] [security2:error] [pid 849392:tid 849561] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ww5.php"] [unique_id "amuUewMgr4yz2OQW0xrniwAAAKs"]
[Thu Jul 30 13:14:19.994522 2026] [security2:error] [pid 849392:tid 849561] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/ww5.php"] [unique_id "amuUewMgr4yz2OQW0xrniwAAAKs"]
[Thu Jul 30 13:14:20.309950 2026] [core:notice] [pid 849392:tid 849630] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:20.316197 2026] [core:notice] [pid 849392:tid 849644] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:20.530625 2026] [core:notice] [pid 849392:tid 849467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:20.536479 2026] [security2:error] [pid 849392:tid 849645] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/2.php"] [unique_id "amuUfAMgr4yz2OQW0xrnkAAAAP8"]
[Thu Jul 30 13:14:20.536581 2026] [security2:error] [pid 849392:tid 849645] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/2.php"] [unique_id "amuUfAMgr4yz2OQW0xrnkAAAAP8"]
[Thu Jul 30 13:14:20.992648 2026] [security2:error] [pid 849392:tid 849632] [client 172.213.232.128:52008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/ahax.php"] [unique_id "amuUfAMgr4yz2OQW0xrnlAAAAPI"]
[Thu Jul 30 13:14:21.107651 2026] [security2:error] [pid 849392:tid 849545] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuUfQMgr4yz2OQW0xrnlwAAAJs"]
[Thu Jul 30 13:14:21.107767 2026] [security2:error] [pid 849392:tid 849545] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuUfQMgr4yz2OQW0xrnlwAAAJs"]
[Thu Jul 30 13:14:21.655329 2026] [security2:error] [pid 849392:tid 849528] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/atomlib.php"] [unique_id "amuUfQMgr4yz2OQW0xrnmgAAAIo"]
[Thu Jul 30 13:14:21.655450 2026] [security2:error] [pid 849392:tid 849528] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/atomlib.php"] [unique_id "amuUfQMgr4yz2OQW0xrnmgAAAIo"]
[Thu Jul 30 13:14:21.770301 2026] [security2:error] [pid 849392:tid 849574] [client 39.34.153.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUfQMgr4yz2OQW0xrnlgAAuFc"], referer: https://allmontecristi.com
[Thu Jul 30 13:14:22.204906 2026] [security2:error] [pid 849392:tid 849578] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/rip.php"] [unique_id "amuUfgMgr4yz2OQW0xrnngAAALw"]
[Thu Jul 30 13:14:22.205029 2026] [security2:error] [pid 849392:tid 849578] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/rip.php"] [unique_id "amuUfgMgr4yz2OQW0xrnngAAALw"]
[Thu Jul 30 13:14:22.717743 2026] [security2:error] [pid 849392:tid 849642] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/p.php"] [unique_id "amuUfgMgr4yz2OQW0xrnpQAAAPw"]
[Thu Jul 30 13:14:22.717942 2026] [security2:error] [pid 849392:tid 849642] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/p.php"] [unique_id "amuUfgMgr4yz2OQW0xrnpQAAAPw"]
[Thu Jul 30 13:14:23.054683 2026] [security2:error] [pid 849392:tid 849459] [remote 57.141.0.46:46302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/view/9410/4175"] [unique_id "amuUfwMgr4yz2OQW0xrntgAAqUE"]
[Thu Jul 30 13:14:23.245765 2026] [security2:error] [pid 849392:tid 849634] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/php.php"] [unique_id "amuUfwMgr4yz2OQW0xrnyAAAAPQ"]
[Thu Jul 30 13:14:23.245906 2026] [security2:error] [pid 849392:tid 849634] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.prolineroofingservices.homes"] [uri "/php.php"] [unique_id "amuUfwMgr4yz2OQW0xrnyAAAAPQ"]
[Thu Jul 30 13:14:23.259146 2026] [security2:error] [pid 849392:tid 849597] [client 179.64.21.229:43496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUfwMgr4yz2OQW0xrnygAAAM8"]
[Thu Jul 30 13:14:23.259280 2026] [security2:error] [pid 849392:tid 849597] [client 179.64.21.229:43496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUfwMgr4yz2OQW0xrnygAAAM8"]
[Thu Jul 30 13:14:23.804787 2026] [security2:error] [pid 849392:tid 849567] [client 172.236.9.101:9066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUfwMgr4yz2OQW0xrnxwAAALE"]
[Thu Jul 30 13:14:23.804786 2026] [security2:error] [pid 849392:tid 849563] [client 172.236.9.101:37832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUfwMgr4yz2OQW0xrnyQAAAK0"]
[Thu Jul 30 13:14:23.848765 2026] [security2:error] [pid 849392:tid 849620] [client 172.236.9.101:49855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUfwMgr4yz2OQW0xrnywAAAOY"]
[Thu Jul 30 13:14:24.664805 2026] [autoindex:error] [pid 849392:tid 849505] [remote 74.207.245.209:33970] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:14:25.353093 2026] [security2:error] [pid 849392:tid 849627] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUgAMgr4yz2OQW0xrn1gAAAO0"]
[Thu Jul 30 13:14:25.361295 2026] [proxy:error] [pid 849392:tid 849636] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:14:25.361375 2026] [proxy_http:error] [pid 849392:tid 849636] [client 32.194.121.99:40812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:14:25.361938 2026] [proxy:error] [pid 849392:tid 849636] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:14:25.361991 2026] [proxy_http:error] [pid 849392:tid 849636] [client 32.194.121.99:40812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:14:25.396556 2026] [proxy:error] [pid 849392:tid 849578] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:14:25.396635 2026] [proxy_http:error] [pid 849392:tid 849578] [client 34.224.175.62:49980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:14:25.397453 2026] [proxy:error] [pid 849392:tid 849578] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:14:25.397514 2026] [proxy_http:error] [pid 849392:tid 849578] [client 34.224.175.62:49980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:14:25.411843 2026] [autoindex:error] [pid 849392:tid 849547] [client 34.224.175.62:23011] AH01276: Cannot serve directory /home1/uixgzjte/public_html/chicago-mfg.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:14:25.413994 2026] [autoindex:error] [pid 849392:tid 849581] [client 34.233.129.35:7646] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:14:25.742280 2026] [security2:error] [pid 849392:tid 849497] [remote 20.54.134.42:2323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuUgQMgr4yz2OQW0xrn8AAAumc"]
[Thu Jul 30 13:14:25.765916 2026] [security2:error] [pid 849392:tid 849585] [client 172.236.9.101:45365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUgQMgr4yz2OQW0xrn3QAAAMM"]
[Thu Jul 30 13:14:28.255588 2026] [core:notice] [pid 849392:tid 849406] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:29.966361 2026] [security2:error] [pid 849392:tid 849414] [remote 216.73.217.142:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUhQMgr4yz2OQW0xroGgAAxRQ"]
[Thu Jul 30 13:14:30.810367 2026] [security2:error] [pid 849392:tid 849592] [client 179.64.21.229:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUhgMgr4yz2OQW0xroKQAAAMo"]
[Thu Jul 30 13:14:30.814625 2026] [security2:error] [pid 849392:tid 849592] [client 179.64.21.229:57454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUhgMgr4yz2OQW0xroKQAAAMo"]
[Thu Jul 30 13:14:31.276145 2026] [security2:error] [pid 849392:tid 849508] [remote 57.141.0.9:53574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/grageaku/issue/current"] [unique_id "amuUhwMgr4yz2OQW0xroLAAA0nI"]
[Thu Jul 30 13:14:32.548396 2026] [security2:error] [pid 849392:tid 849535] [client 202.163.102.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUhwMgr4yz2OQW0xroMgAAkRs"], referer: https://allmontecristi.com
[Thu Jul 30 13:14:33.010497 2026] [security2:error] [pid 849392:tid 849398] [remote 72.167.132.114:57460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuUiQMgr4yz2OQW0xroNQAAnAQ"]
[Thu Jul 30 13:14:33.518730 2026] [security2:error] [pid 849392:tid 849536] [client 52.167.144.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuUhwMgr4yz2OQW0xroMAAAAJI"]
[Thu Jul 30 13:14:34.508958 2026] [security2:error] [pid 849392:tid 849640] [client 52.167.144.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuUigMgr4yz2OQW0xroQgAAAPo"]
[Thu Jul 30 13:14:34.999249 2026] [security2:error] [pid 849392:tid 849582] [client 203.198.28.191:24389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.kendarikomputer.com"] [uri "/p/contact.html"] [unique_id "amuUigMgr4yz2OQW0xroSwAAAMA"]
[Thu Jul 30 13:14:35.103160 2026] [core:notice] [pid 849392:tid 849561] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:35.116678 2026] [core:notice] [pid 849392:tid 849528] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:35.421156 2026] [security2:error] [pid 849392:tid 849541] [client 181.230.66.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUigMgr4yz2OQW0xroSAAAlyg"], referer: https://allmontecristi.com
[Thu Jul 30 13:14:35.634270 2026] [core:notice] [pid 849392:tid 849400] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:35.657491 2026] [security2:error] [pid 849392:tid 849429] [remote 216.73.217.142:40455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUiwMgr4yz2OQW0xroUAAApSM"]
[Thu Jul 30 13:14:36.307866 2026] [security2:error] [pid 849392:tid 849539] [client 52.167.144.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuUiwMgr4yz2OQW0xroVgAAAJU"]
[Thu Jul 30 13:14:36.655189 2026] [security2:error] [pid 849392:tid 849415] [remote 62.210.185.4:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuUjAMgr4yz2OQW0xroWgAAwxU"]
[Thu Jul 30 13:14:36.695467 2026] [security2:error] [pid 849392:tid 849626] [client 184.75.223.203:36728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuUjAMgr4yz2OQW0xroXAAAAOw"]
[Thu Jul 30 13:14:36.695560 2026] [security2:error] [pid 849392:tid 849626] [client 184.75.223.203:36728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuUjAMgr4yz2OQW0xroXAAAAOw"]
[Thu Jul 30 13:14:37.336818 2026] [security2:error] [pid 849392:tid 849600] [client 85.208.96.193:62546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/12/29/paraiba-confirma-423-novos-casos-de-covid-19-e-12-obitos-nesta-terca-feira/"] [unique_id "amuUjQMgr4yz2OQW0xroXgAAANI"]
[Thu Jul 30 13:14:37.337006 2026] [security2:error] [pid 849392:tid 849600] [client 85.208.96.193:62546] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/12/29/paraiba-confirma-423-novos-casos-de-covid-19-e-12-obitos-nesta-terca-feira/"] [unique_id "amuUjQMgr4yz2OQW0xroXgAAANI"]
[Thu Jul 30 13:14:37.761660 2026] [security2:error] [pid 849392:tid 849407] [remote 216.73.217.142:9974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuUjQMgr4yz2OQW0xroXwAAkQ0"]
[Thu Jul 30 13:14:39.171648 2026] [core:notice] [pid 849392:tid 849579] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:39.774527 2026] [core:notice] [pid 849392:tid 849552] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:40.339702 2026] [core:notice] [pid 849392:tid 849565] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:41.146372 2026] [security2:error] [pid 849392:tid 849567] [client 179.64.21.229:7866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUkQMgr4yz2OQW0xrocgAAALE"]
[Thu Jul 30 13:14:41.150077 2026] [security2:error] [pid 849392:tid 849567] [client 179.64.21.229:7866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUkQMgr4yz2OQW0xrocgAAALE"]
[Thu Jul 30 13:14:41.723846 2026] [security2:error] [pid 849392:tid 849452] [remote 72.167.132.114:35922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amuUkQMgr4yz2OQW0xroeAAAhjo"]
[Thu Jul 30 13:14:41.811612 2026] [security2:error] [pid 849392:tid 849568] [client 172.236.9.101:25384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUkQMgr4yz2OQW0xrocwAAALI"]
[Thu Jul 30 13:14:42.322113 2026] [security2:error] [pid 849392:tid 849438] [remote 216.73.217.142:9974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUkgMgr4yz2OQW0xrogAAA9iw"]
[Thu Jul 30 13:14:42.615475 2026] [security2:error] [pid 849392:tid 849467] [remote 72.167.132.114:49944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mshandco.org"] [uri "/wp-login.php"] [unique_id "amuUkgMgr4yz2OQW0xroggAAm0k"]
[Thu Jul 30 13:14:43.428842 2026] [security2:error] [pid 849392:tid 849606] [client 57.141.0.70:26096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuUkwMgr4yz2OQW0xrojgAA2CE"], referer: https://igetvape-australia.com/product/alibarbar-pandora-7000-puffs-5/
[Thu Jul 30 13:14:43.987227 2026] [core:notice] [pid 849392:tid 849569] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:44.468577 2026] [security2:error] [pid 849392:tid 849642] [client 66.249.90.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUkwMgr4yz2OQW0xrolAAAAPw"]
[Thu Jul 30 13:14:45.614553 2026] [core:notice] [pid 849392:tid 849610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:14:45.835371 2026] [security2:error] [pid 849392:tid 849612] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUlQMgr4yz2OQW0xroowAA3lk"]
[Thu Jul 30 13:14:47.517013 2026] [autoindex:error] [pid 849392:tid 849627] [client 104.28.156.61:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:14:47.898616 2026] [security2:error] [pid 849392:tid 849597] [client 172.236.9.101:51266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUlwMgr4yz2OQW0xrovQAAAM8"]
[Thu Jul 30 13:14:48.640467 2026] [security2:error] [pid 849392:tid 849618] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUmAMgr4yz2OQW0xroxwAA5FY"]
[Thu Jul 30 13:14:48.762742 2026] [security2:error] [pid 849392:tid 849541] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUmAMgr4yz2OQW0xroywAAAJc"]
[Thu Jul 30 13:14:50.215310 2026] [security2:error] [pid 849392:tid 849619] [client 52.167.144.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuUmQMgr4yz2OQW0xro3wAAAOU"]
[Thu Jul 30 13:14:51.254879 2026] [security2:error] [pid 849392:tid 849632] [client 172.236.9.101:29221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/kcfinder/browse.php"] [unique_id "amuUmwMgr4yz2OQW0xrpAAAAAPI"]
[Thu Jul 30 13:14:51.837157 2026] [security2:error] [pid 849392:tid 849567] [client 179.64.21.229:7129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUmwMgr4yz2OQW0xrpBwAAALE"]
[Thu Jul 30 13:14:51.837304 2026] [security2:error] [pid 849392:tid 849567] [client 179.64.21.229:7129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUmwMgr4yz2OQW0xrpBwAAALE"]
[Thu Jul 30 13:14:51.957376 2026] [security2:error] [pid 849392:tid 849625] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuUmwMgr4yz2OQW0xrpBgAAAOs"]
[Thu Jul 30 13:14:52.498677 2026] [security2:error] [pid 849392:tid 849547] [client 31.171.130.152:62983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuUnAMgr4yz2OQW0xrpCAAAAJ0"], referer: http://pkf.jo/
[Thu Jul 30 13:14:53.285345 2026] [security2:error] [pid 849392:tid 849631] [client 31.171.130.148:65075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuUnAMgr4yz2OQW0xrpDwAAAPE"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=https://orjinalesigara.blogspot.com
[Thu Jul 30 13:14:55.147510 2026] [security2:error] [pid 849392:tid 849535] [client 52.167.144.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuUngMgr4yz2OQW0xrpGgAAAJE"]
[Thu Jul 30 13:14:55.969319 2026] [security2:error] [pid 849392:tid 849574] [client 31.171.130.120:32369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/wp-login.php"] [unique_id "amuUnwMgr4yz2OQW0xrpHQAAALg"], referer: https://pkf.jo
[Thu Jul 30 13:14:56.792240 2026] [security2:error] [pid 849392:tid 849630] [client 31.171.130.145:25817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.130.171.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-login.php"] [unique_id "amuUoAMgr4yz2OQW0xrpKAAAAPA"], referer: https://pkf.jo/wp-login.php?action=register
[Thu Jul 30 13:14:57.559099 2026] [security2:error] [pid 849392:tid 849567] [client 31.171.130.119:21241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/wp-login.php"] [unique_id "amuUoQMgr4yz2OQW0xrpLAAAALE"], referer: https://pkf.jo/wp-login.php?action=register
[Thu Jul 30 13:14:57.723462 2026] [security2:error] [pid 849392:tid 849517] [remote 57.141.0.12:36582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45988126625/feed/rss2/"] [unique_id "amuUoQMgr4yz2OQW0xrpMgAAins"]
[Thu Jul 30 13:14:58.094510 2026] [fcgid:warn] [pid 849392:tid 849602] (70014)End of file found: [client 66.132.195.66:8944] mod_fcgid: can't get data from http client
[Thu Jul 30 13:14:58.386958 2026] [security2:error] [pid 849392:tid 849624] [client 172.236.9.101:62456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/config.properties.bak"] [unique_id "amuUogMgr4yz2OQW0xrpOAAAAOo"]
[Thu Jul 30 13:14:59.605943 2026] [security2:error] [pid 849392:tid 849643] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuUowMgr4yz2OQW0xrpPAAAAP0"]
[Thu Jul 30 13:15:00.175917 2026] [security2:error] [pid 849392:tid 849585] [client 82.102.27.163:35862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuUpAMgr4yz2OQW0xrpQgAAAMM"]
[Thu Jul 30 13:15:00.176044 2026] [security2:error] [pid 849392:tid 849585] [client 82.102.27.163:35862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuUpAMgr4yz2OQW0xrpQgAAAMM"]
[Thu Jul 30 13:15:01.062738 2026] [core:notice] [pid 849392:tid 849610] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:01.249963 2026] [security2:error] [pid 849392:tid 849546] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUpAMgr4yz2OQW0xrpSwAAAJw"]
[Thu Jul 30 13:15:01.289214 2026] [security2:error] [pid 849392:tid 849646] [client 172.236.9.101:54713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/assets/kcfinder/browse.php"] [unique_id "amuUpQMgr4yz2OQW0xrpUgAAAQA"]
[Thu Jul 30 13:15:01.388909 2026] [security2:error] [pid 849392:tid 849537] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuUpQMgr4yz2OQW0xrpUQAAAJM"]
[Thu Jul 30 13:15:01.482902 2026] [core:notice] [pid 849392:tid 849590] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:01.846291 2026] [core:notice] [pid 849392:tid 849574] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:01.964108 2026] [security2:error] [pid 849392:tid 849589] [client 220.181.108.155:32009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/FocusandScope"] [unique_id "amuUpQMgr4yz2OQW0xrpVgAAAMc"]
[Thu Jul 30 13:15:02.371247 2026] [core:notice] [pid 849392:tid 849634] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:02.823759 2026] [security2:error] [pid 849392:tid 849562] [client 179.64.21.229:11367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUpgMgr4yz2OQW0xrpXAAAAKw"]
[Thu Jul 30 13:15:02.823940 2026] [security2:error] [pid 849392:tid 849562] [client 179.64.21.229:11367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUpgMgr4yz2OQW0xrpXAAAAKw"]
[Thu Jul 30 13:15:02.973686 2026] [security2:error] [pid 849392:tid 849595] [client 119.249.100.48:41236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/FocusandScope"] [unique_id "amuUpgMgr4yz2OQW0xrpWwAAAM0"]
[Thu Jul 30 13:15:03.204768 2026] [security2:error] [pid 849392:tid 849402] [remote 216.73.217.142:2820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUpwMgr4yz2OQW0xrpXQAA7Qg"]
[Thu Jul 30 13:15:03.325941 2026] [core:notice] [pid 849392:tid 849614] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:03.734289 2026] [core:notice] [pid 849392:tid 849571] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:03.921427 2026] [security2:error] [pid 849392:tid 849636] [client 119.249.100.51:35609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/FocusandScope"] [unique_id "amuUpwMgr4yz2OQW0xrpXwAAAPY"]
[Thu Jul 30 13:15:07.559090 2026] [core:notice] [pid 849392:tid 849603] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:07.765966 2026] [security2:error] [pid 849392:tid 849477] [remote 216.73.217.142:2820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUqwMgr4yz2OQW0xrpowAAvlM"]
[Thu Jul 30 13:15:08.228234 2026] [core:notice] [pid 849392:tid 849503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:08.497460 2026] [security2:error] [pid 849392:tid 849457] [remote 57.141.0.60:25956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amuUrAMgr4yz2OQW0xrpqQAAtj8"]
[Thu Jul 30 13:15:08.596770 2026] [security2:error] [pid 849392:tid 849597] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUqwMgr4yz2OQW0xrppAAAz14"]
[Thu Jul 30 13:15:08.999848 2026] [security2:error] [pid 849392:tid 849616] [client 172.236.9.101:1045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUrAMgr4yz2OQW0xrpqAAAAOI"]
[Thu Jul 30 13:15:11.292530 2026] [security2:error] [pid 849392:tid 849566] [client 172.236.9.101:21176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/lib/kcfinder/browse.php"] [unique_id "amuUrwMgr4yz2OQW0xrptAAAALA"]
[Thu Jul 30 13:15:11.483508 2026] [core:notice] [pid 849392:tid 849633] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:12.282990 2026] [core:notice] [pid 849392:tid 849574] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:13.336040 2026] [security2:error] [pid 849392:tid 849586] [client 153.117.55.3:42561] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "sh00085.hostgator.com"] [uri "/boaform/admin/formLogin"] [unique_id "amuUsQMgr4yz2OQW0xrpvQAAAMQ"]
[Thu Jul 30 13:15:13.372638 2026] [security2:error] [pid 849392:tid 849480] [remote 216.73.217.142:23791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUsQMgr4yz2OQW0xrpvgAArFY"]
[Thu Jul 30 13:15:13.419475 2026] [security2:error] [pid 849392:tid 849538] [client 179.64.21.229:53609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUsQMgr4yz2OQW0xrpvwAAAJQ"]
[Thu Jul 30 13:15:13.427365 2026] [security2:error] [pid 849392:tid 849538] [client 179.64.21.229:53609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUsQMgr4yz2OQW0xrpvwAAAJQ"]
[Thu Jul 30 13:15:13.878379 2026] [security2:error] [pid 849392:tid 849586] [client 153.117.55.3:42561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amuUsQMgr4yz2OQW0xrpvQAAAMQ"]
[Thu Jul 30 13:15:13.997097 2026] [security2:error] [pid 849392:tid 849439] [remote 43.156.39.66:65175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuUsQMgr4yz2OQW0xrpwQABAy0"]
[Thu Jul 30 13:15:13.997320 2026] [security2:error] [pid 849392:tid 849649] [client 43.156.39.66:65175] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuUsQMgr4yz2OQW0xrpwQABAy0"]
[Thu Jul 30 13:15:14.070614 2026] [security2:error] [pid 849392:tid 849479] [remote 43.156.39.66:65175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/favicon.ico"] [unique_id "amuUsgMgr4yz2OQW0xrpwgAAm1U"], referer: https://www.nordeste1.com/category/policiais/
[Thu Jul 30 13:15:14.070784 2026] [security2:error] [pid 849392:tid 849545] [client 43.156.39.66:65175] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/favicon.ico"] [unique_id "amuUsgMgr4yz2OQW0xrpwgAAm1U"], referer: https://www.nordeste1.com/category/policiais/
[Thu Jul 30 13:15:14.718055 2026] [security2:error] [pid 849392:tid 849621] [client 172.236.9.101:39005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUsgMgr4yz2OQW0xrpxgAAAOc"]
[Thu Jul 30 13:15:16.508350 2026] [security2:error] [pid 849392:tid 849606] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUswMgr4yz2OQW0xrp6AAAANg"]
[Thu Jul 30 13:15:17.771810 2026] [security2:error] [pid 849392:tid 849394] [remote 216.73.217.142:23791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUtQMgr4yz2OQW0xrp8wAA5gA"]
[Thu Jul 30 13:15:18.325275 2026] [security2:error] [pid 849392:tid 849548] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuUtgMgr4yz2OQW0xrqDgAAAJ4"]
[Thu Jul 30 13:15:18.325411 2026] [security2:error] [pid 849392:tid 849548] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuUtgMgr4yz2OQW0xrqDgAAAJ4"]
[Thu Jul 30 13:15:18.414841 2026] [security2:error] [pid 849392:tid 849539] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuUtQMgr4yz2OQW0xrp8gAAlQw"]
[Thu Jul 30 13:15:18.714148 2026] [security2:error] [pid 849392:tid 849450] [remote 47.128.27.45:48738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/gg-jacket-black-beige/"] [unique_id "amuUtgMgr4yz2OQW0xrqOgAAhjg"]
[Thu Jul 30 13:15:19.057705 2026] [security2:error] [pid 849392:tid 849527] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuUtwMgr4yz2OQW0xrqPgAAAIk"]
[Thu Jul 30 13:15:19.057831 2026] [security2:error] [pid 849392:tid 849527] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuUtwMgr4yz2OQW0xrqPgAAAIk"]
[Thu Jul 30 13:15:19.176518 2026] [security2:error] [pid 849392:tid 849627] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuUtgMgr4yz2OQW0xrqOQAAAO0"]
[Thu Jul 30 13:15:19.311693 2026] [security2:error] [pid 849392:tid 849528] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/x.php"] [unique_id "amuUtwMgr4yz2OQW0xrqQAAAAIo"]
[Thu Jul 30 13:15:19.311866 2026] [security2:error] [pid 849392:tid 849528] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/x.php"] [unique_id "amuUtwMgr4yz2OQW0xrqQAAAAIo"]
[Thu Jul 30 13:15:19.557971 2026] [security2:error] [pid 849392:tid 849541] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/mgrr.php"] [unique_id "amuUtwMgr4yz2OQW0xrqRgAAAJc"]
[Thu Jul 30 13:15:19.558106 2026] [security2:error] [pid 849392:tid 849541] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/mgrr.php"] [unique_id "amuUtwMgr4yz2OQW0xrqRgAAAJc"]
[Thu Jul 30 13:15:19.802881 2026] [security2:error] [pid 849392:tid 849625] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/domvf.php"] [unique_id "amuUtwMgr4yz2OQW0xrqRwAAAOs"]
[Thu Jul 30 13:15:19.803016 2026] [security2:error] [pid 849392:tid 849625] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/domvf.php"] [unique_id "amuUtwMgr4yz2OQW0xrqRwAAAOs"]
[Thu Jul 30 13:15:19.823703 2026] [security2:error] [pid 849392:tid 849456] [remote 97.74.93.24:47712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amuUtwMgr4yz2OQW0xrqSAAA0D4"]
[Thu Jul 30 13:15:20.053038 2026] [security2:error] [pid 849392:tid 849530] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/yup.php"] [unique_id "amuUuAMgr4yz2OQW0xrqSgAAAIw"]
[Thu Jul 30 13:15:20.053156 2026] [security2:error] [pid 849392:tid 849530] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/yup.php"] [unique_id "amuUuAMgr4yz2OQW0xrqSgAAAIw"]
[Thu Jul 30 13:15:20.227994 2026] [security2:error] [pid 849392:tid 849618] [client 119.73.97.132:31243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuUtwMgr4yz2OQW0xrqPQAA5GI"], referer: https://www.urwru.club/wp-admin/post.php?post=1023&action=elementor
[Thu Jul 30 13:15:20.299735 2026] [security2:error] [pid 849392:tid 849637] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/X.php"] [unique_id "amuUuAMgr4yz2OQW0xrqSwAAAPc"]
[Thu Jul 30 13:15:20.299851 2026] [security2:error] [pid 849392:tid 849637] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/X.php"] [unique_id "amuUuAMgr4yz2OQW0xrqSwAAAPc"]
[Thu Jul 30 13:15:20.545424 2026] [security2:error] [pid 849392:tid 849584] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuUuAMgr4yz2OQW0xrqUAAAAMI"]
[Thu Jul 30 13:15:20.545548 2026] [security2:error] [pid 849392:tid 849584] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuUuAMgr4yz2OQW0xrqUAAAAMI"]
[Thu Jul 30 13:15:21.097697 2026] [security2:error] [pid 849392:tid 849603] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/gec.php"] [unique_id "amuUuQMgr4yz2OQW0xrqWwAAANU"]
[Thu Jul 30 13:15:21.097810 2026] [security2:error] [pid 849392:tid 849603] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/gec.php"] [unique_id "amuUuQMgr4yz2OQW0xrqWwAAANU"]
[Thu Jul 30 13:15:21.253679 2026] [security2:error] [pid 849392:tid 849569] [client 172.236.9.101:30798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/admin/kcfinder/browse.php"] [unique_id "amuUuQMgr4yz2OQW0xrqXAAAALM"]
[Thu Jul 30 13:15:21.371377 2026] [security2:error] [pid 849392:tid 849551] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/sky.php"] [unique_id "amuUuQMgr4yz2OQW0xrqXwAAAKE"]
[Thu Jul 30 13:15:21.371521 2026] [security2:error] [pid 849392:tid 849551] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/sky.php"] [unique_id "amuUuQMgr4yz2OQW0xrqXwAAAKE"]
[Thu Jul 30 13:15:21.613871 2026] [security2:error] [pid 849392:tid 849591] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fffm.php"] [unique_id "amuUuQMgr4yz2OQW0xrqYgAAAMk"]
[Thu Jul 30 13:15:21.614009 2026] [security2:error] [pid 849392:tid 849591] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fffm.php"] [unique_id "amuUuQMgr4yz2OQW0xrqYgAAAMk"]
[Thu Jul 30 13:15:21.860828 2026] [security2:error] [pid 849392:tid 849646] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/sixxis.php"] [unique_id "amuUuQMgr4yz2OQW0xrqZAAAAQA"]
[Thu Jul 30 13:15:21.860950 2026] [security2:error] [pid 849392:tid 849646] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/sixxis.php"] [unique_id "amuUuQMgr4yz2OQW0xrqZAAAAQA"]
[Thu Jul 30 13:15:22.361619 2026] [security2:error] [pid 849392:tid 849537] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/yj09.php"] [unique_id "amuUugMgr4yz2OQW0xrqaQAAAJM"]
[Thu Jul 30 13:15:22.361751 2026] [security2:error] [pid 849392:tid 849537] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/yj09.php"] [unique_id "amuUugMgr4yz2OQW0xrqaQAAAJM"]
[Thu Jul 30 13:15:22.603575 2026] [security2:error] [pid 849392:tid 849588] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/k.php"] [unique_id "amuUugMgr4yz2OQW0xrqbAAAAMY"]
[Thu Jul 30 13:15:22.603683 2026] [security2:error] [pid 849392:tid 849588] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/k.php"] [unique_id "amuUugMgr4yz2OQW0xrqbAAAAMY"]
[Thu Jul 30 13:15:22.848613 2026] [security2:error] [pid 849392:tid 849566] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/k2.php"] [unique_id "amuUugMgr4yz2OQW0xrqcwAAALA"]
[Thu Jul 30 13:15:22.848721 2026] [security2:error] [pid 849392:tid 849566] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/k2.php"] [unique_id "amuUugMgr4yz2OQW0xrqcwAAALA"]
[Thu Jul 30 13:15:23.108234 2026] [security2:error] [pid 849392:tid 849620] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/w.php"] [unique_id "amuUuwMgr4yz2OQW0xrqdQAAAOY"]
[Thu Jul 30 13:15:23.108376 2026] [security2:error] [pid 849392:tid 849620] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/w.php"] [unique_id "amuUuwMgr4yz2OQW0xrqdQAAAOY"]
[Thu Jul 30 13:15:23.357245 2026] [security2:error] [pid 849392:tid 849633] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fpwch.php"] [unique_id "amuUuwMgr4yz2OQW0xrqdwAAAPM"]
[Thu Jul 30 13:15:23.357366 2026] [security2:error] [pid 849392:tid 849633] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fpwch.php"] [unique_id "amuUuwMgr4yz2OQW0xrqdwAAAPM"]
[Thu Jul 30 13:15:23.600555 2026] [security2:error] [pid 849392:tid 849562] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/w2025.php"] [unique_id "amuUuwMgr4yz2OQW0xrqegAAAKw"]
[Thu Jul 30 13:15:23.600686 2026] [security2:error] [pid 849392:tid 849562] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/w2025.php"] [unique_id "amuUuwMgr4yz2OQW0xrqegAAAKw"]
[Thu Jul 30 13:15:23.959423 2026] [security2:error] [pid 849392:tid 849548] [client 179.64.21.229:15807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUuwMgr4yz2OQW0xrqgAAAAJ4"]
[Thu Jul 30 13:15:23.967723 2026] [security2:error] [pid 849392:tid 849548] [client 179.64.21.229:15807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUuwMgr4yz2OQW0xrqgAAAAJ4"]
[Thu Jul 30 13:15:24.208911 2026] [security2:error] [pid 849392:tid 849649] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/FWAZ.php"] [unique_id "amuUvAMgr4yz2OQW0xrqgQAAAQM"]
[Thu Jul 30 13:15:24.209043 2026] [security2:error] [pid 849392:tid 849649] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/FWAZ.php"] [unique_id "amuUvAMgr4yz2OQW0xrqgQAAAQM"]
[Thu Jul 30 13:15:24.370335 2026] [core:notice] [pid 849392:tid 849540] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:24.505262 2026] [security2:error] [pid 849392:tid 849575] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/qterm.php"] [unique_id "amuUvAMgr4yz2OQW0xrqhAAAALk"]
[Thu Jul 30 13:15:24.505379 2026] [security2:error] [pid 849392:tid 849575] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/qterm.php"] [unique_id "amuUvAMgr4yz2OQW0xrqhAAAALk"]
[Thu Jul 30 13:15:24.643411 2026] [core:notice] [pid 849392:tid 849498] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:24.781740 2026] [core:notice] [pid 849392:tid 849541] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:24.833400 2026] [core:notice] [pid 849392:tid 849599] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:24.839681 2026] [core:notice] [pid 849392:tid 849454] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:24.900128 2026] [security2:error] [pid 849392:tid 849598] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/blurbs.php"] [unique_id "amuUvAMgr4yz2OQW0xrqiQAAANA"]
[Thu Jul 30 13:15:24.900235 2026] [security2:error] [pid 849392:tid 849598] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/blurbs.php"] [unique_id "amuUvAMgr4yz2OQW0xrqiQAAANA"]
[Thu Jul 30 13:15:25.174581 2026] [security2:error] [pid 849392:tid 849621] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-ws68.php"] [unique_id "amuUvQMgr4yz2OQW0xrqigAAAOc"]
[Thu Jul 30 13:15:25.174699 2026] [security2:error] [pid 849392:tid 849621] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-ws68.php"] [unique_id "amuUvQMgr4yz2OQW0xrqigAAAOc"]
[Thu Jul 30 13:15:25.243651 2026] [core:notice] [pid 849392:tid 849643] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:25.434016 2026] [security2:error] [pid 849392:tid 849613] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xyn.php"] [unique_id "amuUvQMgr4yz2OQW0xrqjwAAAN8"]
[Thu Jul 30 13:15:25.434131 2026] [security2:error] [pid 849392:tid 849613] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xyn.php"] [unique_id "amuUvQMgr4yz2OQW0xrqjwAAAN8"]
[Thu Jul 30 13:15:25.703221 2026] [security2:error] [pid 849392:tid 849642] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ccc.php"] [unique_id "amuUvQMgr4yz2OQW0xrqkgAAAPw"]
[Thu Jul 30 13:15:25.703350 2026] [security2:error] [pid 849392:tid 849642] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ccc.php"] [unique_id "amuUvQMgr4yz2OQW0xrqkgAAAPw"]
[Thu Jul 30 13:15:25.957327 2026] [security2:error] [pid 849392:tid 849564] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/get.php"] [unique_id "amuUvQMgr4yz2OQW0xrqlQAAAK4"]
[Thu Jul 30 13:15:25.957444 2026] [security2:error] [pid 849392:tid 849564] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/get.php"] [unique_id "amuUvQMgr4yz2OQW0xrqlQAAAK4"]
[Thu Jul 30 13:15:26.230655 2026] [security2:error] [pid 849392:tid 849526] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/images.php"] [unique_id "amuUvgMgr4yz2OQW0xrqlgAAAIg"]
[Thu Jul 30 13:15:26.230790 2026] [security2:error] [pid 849392:tid 849526] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/images.php"] [unique_id "amuUvgMgr4yz2OQW0xrqlgAAAIg"]
[Thu Jul 30 13:15:26.494478 2026] [security2:error] [pid 849392:tid 849543] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/alls.php"] [unique_id "amuUvgMgr4yz2OQW0xrqlwAAAJk"]
[Thu Jul 30 13:15:26.494595 2026] [security2:error] [pid 849392:tid 849543] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/alls.php"] [unique_id "amuUvgMgr4yz2OQW0xrqlwAAAJk"]
[Thu Jul 30 13:15:26.733468 2026] [security2:error] [pid 849392:tid 849572] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/coffexium.php"] [unique_id "amuUvgMgr4yz2OQW0xrqmAAAALY"]
[Thu Jul 30 13:15:26.733589 2026] [security2:error] [pid 849392:tid 849572] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/coffexium.php"] [unique_id "amuUvgMgr4yz2OQW0xrqmAAAALY"]
[Thu Jul 30 13:15:26.971633 2026] [security2:error] [pid 849392:tid 849585] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/red.php"] [unique_id "amuUvgMgr4yz2OQW0xrqmQAAAMM"]
[Thu Jul 30 13:15:26.971749 2026] [security2:error] [pid 849392:tid 849585] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/red.php"] [unique_id "amuUvgMgr4yz2OQW0xrqmQAAAMM"]
[Thu Jul 30 13:15:27.253584 2026] [proxy:error] [pid 849392:tid 849616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:27.253668 2026] [proxy_http:error] [pid 849392:tid 849616] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:27.254531 2026] [proxy:error] [pid 849392:tid 849616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:27.254585 2026] [proxy_http:error] [pid 849392:tid 849616] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:27.254698 2026] [security2:error] [pid 849392:tid 849616] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUvwMgr4yz2OQW0xrqnQAAAOI"]
[Thu Jul 30 13:15:27.505204 2026] [security2:error] [pid 849392:tid 849577] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuUvwMgr4yz2OQW0xrqngAAALs"]
[Thu Jul 30 13:15:27.505324 2026] [security2:error] [pid 849392:tid 849577] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuUvwMgr4yz2OQW0xrqngAAALs"]
[Thu Jul 30 13:15:27.753345 2026] [proxy:error] [pid 849392:tid 849648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:27.753433 2026] [proxy_http:error] [pid 849392:tid 849648] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:27.754119 2026] [proxy:error] [pid 849392:tid 849648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:27.754169 2026] [proxy_http:error] [pid 849392:tid 849648] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:27.754281 2026] [security2:error] [pid 849392:tid 849648] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUvwMgr4yz2OQW0xrqnwAAAQI"]
[Thu Jul 30 13:15:27.776464 2026] [security2:error] [pid 849392:tid 849507] [remote 216.73.217.142:5351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUvwMgr4yz2OQW0xrqoAAAnHE"]
[Thu Jul 30 13:15:28.020787 2026] [proxy:error] [pid 849392:tid 849612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:28.020860 2026] [proxy_http:error] [pid 849392:tid 849612] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:28.021447 2026] [proxy:error] [pid 849392:tid 849612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:28.021492 2026] [proxy_http:error] [pid 849392:tid 849612] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:28.021579 2026] [security2:error] [pid 849392:tid 849612] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUwAMgr4yz2OQW0xrqogAAAN4"]
[Thu Jul 30 13:15:28.268699 2026] [security2:error] [pid 849392:tid 849532] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/index.php"] [unique_id "amuUwAMgr4yz2OQW0xrqqAAAAI4"]
[Thu Jul 30 13:15:28.268833 2026] [security2:error] [pid 849392:tid 849532] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/index.php"] [unique_id "amuUwAMgr4yz2OQW0xrqqAAAAI4"]
[Thu Jul 30 13:15:28.525678 2026] [security2:error] [pid 849392:tid 849645] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amuUwAMgr4yz2OQW0xrqrAAAAP8"]
[Thu Jul 30 13:15:28.525794 2026] [security2:error] [pid 849392:tid 849645] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amuUwAMgr4yz2OQW0xrqrAAAAP8"]
[Thu Jul 30 13:15:28.776492 2026] [security2:error] [pid 849392:tid 849633] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/177.php"] [unique_id "amuUwAMgr4yz2OQW0xrqrwAAAPM"]
[Thu Jul 30 13:15:28.776631 2026] [security2:error] [pid 849392:tid 849633] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/177.php"] [unique_id "amuUwAMgr4yz2OQW0xrqrwAAAPM"]
[Thu Jul 30 13:15:29.025250 2026] [security2:error] [pid 849392:tid 849632] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/199.php"] [unique_id "amuUwQMgr4yz2OQW0xrqsQAAAPI"]
[Thu Jul 30 13:15:29.025369 2026] [security2:error] [pid 849392:tid 849632] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/199.php"] [unique_id "amuUwQMgr4yz2OQW0xrqsQAAAPI"]
[Thu Jul 30 13:15:29.049550 2026] [security2:error] [pid 849392:tid 849605] [client 44.205.180.155:61821] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuUwQMgr4yz2OQW0xrqsgAAANc"]
[Thu Jul 30 13:15:29.241607 2026] [core:notice] [pid 849392:tid 849646] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:29.266757 2026] [security2:error] [pid 849392:tid 849523] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file52.php"] [unique_id "amuUwQMgr4yz2OQW0xrqtAAAAIU"]
[Thu Jul 30 13:15:29.266847 2026] [security2:error] [pid 849392:tid 849523] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file52.php"] [unique_id "amuUwQMgr4yz2OQW0xrqtAAAAIU"]
[Thu Jul 30 13:15:29.560114 2026] [security2:error] [pid 849392:tid 849635] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/geck.php"] [unique_id "amuUwQMgr4yz2OQW0xrqtQAAAPU"]
[Thu Jul 30 13:15:29.560228 2026] [security2:error] [pid 849392:tid 849635] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/geck.php"] [unique_id "amuUwQMgr4yz2OQW0xrqtQAAAPU"]
[Thu Jul 30 13:15:29.823134 2026] [security2:error] [pid 849392:tid 849562] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/biufile.php"] [unique_id "amuUwQMgr4yz2OQW0xrqtgAAAKw"]
[Thu Jul 30 13:15:29.823267 2026] [security2:error] [pid 849392:tid 849562] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/biufile.php"] [unique_id "amuUwQMgr4yz2OQW0xrqtgAAAKw"]
[Thu Jul 30 13:15:30.120063 2026] [security2:error] [pid 849392:tid 849524] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dejavu.php"] [unique_id "amuUwgMgr4yz2OQW0xrquAAAAIY"]
[Thu Jul 30 13:15:30.120180 2026] [security2:error] [pid 849392:tid 849524] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dejavu.php"] [unique_id "amuUwgMgr4yz2OQW0xrquAAAAIY"]
[Thu Jul 30 13:15:30.397362 2026] [security2:error] [pid 849392:tid 849565] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aaf.php"] [unique_id "amuUwgMgr4yz2OQW0xrqugAAAK8"]
[Thu Jul 30 13:15:30.397522 2026] [security2:error] [pid 849392:tid 849565] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aaf.php"] [unique_id "amuUwgMgr4yz2OQW0xrqugAAAK8"]
[Thu Jul 30 13:15:30.668404 2026] [security2:error] [pid 849392:tid 849586] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ha.php"] [unique_id "amuUwgMgr4yz2OQW0xrquwAAAMQ"]
[Thu Jul 30 13:15:30.668571 2026] [security2:error] [pid 849392:tid 849586] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ha.php"] [unique_id "amuUwgMgr4yz2OQW0xrquwAAAMQ"]
[Thu Jul 30 13:15:30.932280 2026] [security2:error] [pid 849392:tid 849567] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/hur.php"] [unique_id "amuUwgMgr4yz2OQW0xrqvAAAALE"]
[Thu Jul 30 13:15:30.932432 2026] [security2:error] [pid 849392:tid 849567] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/hur.php"] [unique_id "amuUwgMgr4yz2OQW0xrqvAAAALE"]
[Thu Jul 30 13:15:31.173558 2026] [security2:error] [pid 849392:tid 849533] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/h02ugyh.php"] [unique_id "amuUwwMgr4yz2OQW0xrqvQAAAI8"]
[Thu Jul 30 13:15:31.173692 2026] [security2:error] [pid 849392:tid 849533] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/h02ugyh.php"] [unique_id "amuUwwMgr4yz2OQW0xrqvQAAAI8"]
[Thu Jul 30 13:15:31.215476 2026] [core:notice] [pid 849392:tid 849460] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:31.272967 2026] [security2:error] [pid 849392:tid 849558] [client 172.236.9.101:30537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/includes/kcfinder/browse.php"] [unique_id "amuUwwMgr4yz2OQW0xrqvwAAAKg"]
[Thu Jul 30 13:15:31.421660 2026] [security2:error] [pid 849392:tid 849602] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/155.php"] [unique_id "amuUwwMgr4yz2OQW0xrqwAAAANQ"]
[Thu Jul 30 13:15:31.421765 2026] [security2:error] [pid 849392:tid 849602] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/155.php"] [unique_id "amuUwwMgr4yz2OQW0xrqwAAAANQ"]
[Thu Jul 30 13:15:31.687702 2026] [security2:error] [pid 849392:tid 849625] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amuUwwMgr4yz2OQW0xrqwQAAAOs"]
[Thu Jul 30 13:15:31.687820 2026] [security2:error] [pid 849392:tid 849625] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amuUwwMgr4yz2OQW0xrqwQAAAOs"]
[Thu Jul 30 13:15:32.324827 2026] [security2:error] [pid 849392:tid 849549] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ingfo.php"] [unique_id "amuUxAMgr4yz2OQW0xrqwwAAAJ8"]
[Thu Jul 30 13:15:32.324956 2026] [security2:error] [pid 849392:tid 849549] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ingfo.php"] [unique_id "amuUxAMgr4yz2OQW0xrqwwAAAJ8"]
[Thu Jul 30 13:15:32.564634 2026] [security2:error] [pid 849392:tid 849621] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/error_log.php"] [unique_id "amuUxAMgr4yz2OQW0xrqxAAAAOc"]
[Thu Jul 30 13:15:32.564748 2026] [security2:error] [pid 849392:tid 849621] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/error_log.php"] [unique_id "amuUxAMgr4yz2OQW0xrqxAAAAOc"]
[Thu Jul 30 13:15:32.778465 2026] [security2:error] [pid 849392:tid 849502] [remote 216.73.217.142:5351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUxAMgr4yz2OQW0xrqxgAAp2w"]
[Thu Jul 30 13:15:32.808525 2026] [security2:error] [pid 849392:tid 849611] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/koala.php"] [unique_id "amuUxAMgr4yz2OQW0xrqxwAAAN0"]
[Thu Jul 30 13:15:32.808629 2026] [security2:error] [pid 849392:tid 849611] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/koala.php"] [unique_id "amuUxAMgr4yz2OQW0xrqxwAAAN0"]
[Thu Jul 30 13:15:33.026268 2026] [security2:error] [pid 849392:tid 849643] [client 43.156.227.240:56738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuUxAMgr4yz2OQW0xrqxQAAAP0"]
[Thu Jul 30 13:15:33.054561 2026] [security2:error] [pid 849392:tid 849571] [client 85.208.96.211:12680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/02/07/198-cidades-paraibanas-classificadas-como-bandeira-amarela-e-22-municipios-devem-ter-a-mobilidade-restrita-no-plano-novo-normal/"] [unique_id "amuUxQMgr4yz2OQW0xrq0gAAALU"]
[Thu Jul 30 13:15:33.054700 2026] [security2:error] [pid 849392:tid 849571] [client 85.208.96.211:12680] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/02/07/198-cidades-paraibanas-classificadas-como-bandeira-amarela-e-22-municipios-devem-ter-a-mobilidade-restrita-no-plano-novo-normal/"] [unique_id "amuUxQMgr4yz2OQW0xrq0gAAALU"]
[Thu Jul 30 13:15:33.061610 2026] [security2:error] [pid 849392:tid 849569] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amuUxQMgr4yz2OQW0xrq0wAAALM"]
[Thu Jul 30 13:15:33.061712 2026] [security2:error] [pid 849392:tid 849569] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amuUxQMgr4yz2OQW0xrq0wAAALM"]
[Thu Jul 30 13:15:33.230022 2026] [security2:error] [pid 849392:tid 849521] [remote 13.140.147.206:52587] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuUxQMgr4yz2OQW0xrq2AAAw38"], referer: https://historiadevenezuela.org/partido-conservador/
[Thu Jul 30 13:15:33.536389 2026] [security2:error] [pid 849392:tid 849409] [remote 13.140.147.206:52587] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuUxQMgr4yz2OQW0xrq2gAAqg8"], referer: https://historiadevenezuela.org/partido-conservador/
[Thu Jul 30 13:15:33.572202 2026] [security2:error] [pid 849392:tid 849544] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wefile.php"] [unique_id "amuUxQMgr4yz2OQW0xrq2wAAAJo"]
[Thu Jul 30 13:15:33.572310 2026] [security2:error] [pid 849392:tid 849544] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wefile.php"] [unique_id "amuUxQMgr4yz2OQW0xrq2wAAAJo"]
[Thu Jul 30 13:15:33.918782 2026] [security2:error] [pid 849392:tid 849648] [client 34.227.234.246:34299] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuUxQMgr4yz2OQW0xrq3AAAAQI"]
[Thu Jul 30 13:15:33.960924 2026] [proxy:error] [pid 849392:tid 849609] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:33.961005 2026] [proxy_http:error] [pid 849392:tid 849609] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:33.961571 2026] [proxy:error] [pid 849392:tid 849609] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:33.961613 2026] [proxy_http:error] [pid 849392:tid 849609] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:33.961713 2026] [security2:error] [pid 849392:tid 849609] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUxQMgr4yz2OQW0xrq3QAAANs"]
[Thu Jul 30 13:15:34.209654 2026] [proxy:error] [pid 849392:tid 849579] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:34.209734 2026] [proxy_http:error] [pid 849392:tid 849579] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:34.210309 2026] [proxy:error] [pid 849392:tid 849579] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:34.210354 2026] [proxy_http:error] [pid 849392:tid 849579] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:34.210452 2026] [security2:error] [pid 849392:tid 849579] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUxgMgr4yz2OQW0xrq3gAAAL0"]
[Thu Jul 30 13:15:34.422768 2026] [security2:error] [pid 849392:tid 849588] [client 179.64.21.229:21358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUxgMgr4yz2OQW0xrq4AAAAMY"]
[Thu Jul 30 13:15:34.426409 2026] [security2:error] [pid 849392:tid 849588] [client 179.64.21.229:21358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuUxgMgr4yz2OQW0xrq4AAAAMY"]
[Thu Jul 30 13:15:34.450836 2026] [security2:error] [pid 849392:tid 849536] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/makeasmtp.php"] [unique_id "amuUxgMgr4yz2OQW0xrq4QAAAJI"]
[Thu Jul 30 13:15:34.450962 2026] [security2:error] [pid 849392:tid 849536] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/makeasmtp.php"] [unique_id "amuUxgMgr4yz2OQW0xrq4QAAAJI"]
[Thu Jul 30 13:15:34.458833 2026] [security2:error] [pid 849392:tid 849499] [remote 13.140.147.206:52587] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuUxgMgr4yz2OQW0xrq4gAAsGk"], referer: https://historiadevenezuela.org/partido-conservador/
[Thu Jul 30 13:15:34.477083 2026] [core:notice] [pid 849392:tid 849404] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:35.013356 2026] [security2:error] [pid 849392:tid 849618] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/2P.php"] [unique_id "amuUxwMgr4yz2OQW0xrq5gAAAOQ"]
[Thu Jul 30 13:15:35.013536 2026] [security2:error] [pid 849392:tid 849618] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/2P.php"] [unique_id "amuUxwMgr4yz2OQW0xrq5gAAAOQ"]
[Thu Jul 30 13:15:35.251648 2026] [security2:error] [pid 849392:tid 849589] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/.well-known/about.php"] [unique_id "amuUxwMgr4yz2OQW0xrq6AAAAMc"]
[Thu Jul 30 13:15:35.251771 2026] [security2:error] [pid 849392:tid 849589] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/.well-known/about.php"] [unique_id "amuUxwMgr4yz2OQW0xrq6AAAAMc"]
[Thu Jul 30 13:15:35.498709 2026] [security2:error] [pid 849392:tid 849604] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuUxwMgr4yz2OQW0xrq7AAAANY"]
[Thu Jul 30 13:15:35.498832 2026] [security2:error] [pid 849392:tid 849604] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuUxwMgr4yz2OQW0xrq7AAAANY"]
[Thu Jul 30 13:15:35.632376 2026] [security2:error] [pid 849392:tid 849417] [remote 223.109.211.160:54927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuUxwMgr4yz2OQW0xrq7QAAhRc"]
[Thu Jul 30 13:15:35.632594 2026] [security2:error] [pid 849392:tid 849523] [client 223.109.211.160:54927] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuUxwMgr4yz2OQW0xrq7QAAhRc"]
[Thu Jul 30 13:15:35.773599 2026] [security2:error] [pid 849392:tid 849403] [remote 223.109.211.160:54927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/favicon.ico"] [unique_id "amuUxwMgr4yz2OQW0xrq7gAA4Ak"], referer: https://www.nordeste1.com/category/policiais/
[Thu Jul 30 13:15:35.773815 2026] [security2:error] [pid 849392:tid 849614] [client 223.109.211.160:54927] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/favicon.ico"] [unique_id "amuUxwMgr4yz2OQW0xrq7gAA4Ak"], referer: https://www.nordeste1.com/category/policiais/
[Thu Jul 30 13:15:35.774167 2026] [security2:error] [pid 849392:tid 849595] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/system_log.php"] [unique_id "amuUxwMgr4yz2OQW0xrq7wAAAM0"]
[Thu Jul 30 13:15:35.774252 2026] [security2:error] [pid 849392:tid 849595] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/system_log.php"] [unique_id "amuUxwMgr4yz2OQW0xrq7wAAAM0"]
[Thu Jul 30 13:15:35.849241 2026] [security2:error] [pid 849392:tid 849633] [client 172.236.9.101:4424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuUxwMgr4yz2OQW0xrq6gAAAPM"]
[Thu Jul 30 13:15:36.012481 2026] [proxy:error] [pid 849392:tid 849527] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:36.012562 2026] [proxy_http:error] [pid 849392:tid 849527] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:36.013181 2026] [proxy:error] [pid 849392:tid 849527] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:36.013227 2026] [proxy_http:error] [pid 849392:tid 849527] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:36.013337 2026] [security2:error] [pid 849392:tid 849527] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUyAMgr4yz2OQW0xrq8AAAAIk"]
[Thu Jul 30 13:15:36.275002 2026] [proxy:error] [pid 849392:tid 849565] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:36.275083 2026] [proxy_http:error] [pid 849392:tid 849565] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:36.275719 2026] [proxy:error] [pid 849392:tid 849565] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:36.275764 2026] [proxy_http:error] [pid 849392:tid 849565] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:36.275873 2026] [security2:error] [pid 849392:tid 849565] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUyAMgr4yz2OQW0xrq8QAAAK8"]
[Thu Jul 30 13:15:36.535480 2026] [security2:error] [pid 849392:tid 849586] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/crgio.php"] [unique_id "amuUyAMgr4yz2OQW0xrq9gAAAMQ"]
[Thu Jul 30 13:15:36.535635 2026] [security2:error] [pid 849392:tid 849586] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/crgio.php"] [unique_id "amuUyAMgr4yz2OQW0xrq9gAAAMQ"]
[Thu Jul 30 13:15:36.778791 2026] [security2:error] [pid 849392:tid 849636] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/pucci.php"] [unique_id "amuUyAMgr4yz2OQW0xrq-AAAAPY"]
[Thu Jul 30 13:15:36.778910 2026] [security2:error] [pid 849392:tid 849636] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/pucci.php"] [unique_id "amuUyAMgr4yz2OQW0xrq-AAAAPY"]
[Thu Jul 30 13:15:36.857016 2026] [proxy:error] [pid 849392:tid 849627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:36.857098 2026] [proxy_http:error] [pid 849392:tid 849627] [client 54.87.222.253:10598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:36.857671 2026] [proxy:error] [pid 849392:tid 849627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:36.857714 2026] [proxy_http:error] [pid 849392:tid 849627] [client 54.87.222.253:10598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:36.888750 2026] [proxy:error] [pid 849392:tid 849533] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:36.888836 2026] [proxy_http:error] [pid 849392:tid 849533] [client 3.228.112.215:12922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:36.889676 2026] [proxy:error] [pid 849392:tid 849533] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:36.889735 2026] [proxy_http:error] [pid 849392:tid 849533] [client 3.228.112.215:12922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:37.049582 2026] [proxy:error] [pid 849392:tid 849599] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:37.049656 2026] [proxy_http:error] [pid 849392:tid 849599] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:37.050229 2026] [proxy:error] [pid 849392:tid 849599] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:37.050272 2026] [proxy_http:error] [pid 849392:tid 849599] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:37.050368 2026] [security2:error] [pid 849392:tid 849599] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUyQMgr4yz2OQW0xrrBQAAANE"]
[Thu Jul 30 13:15:37.325413 2026] [proxy:error] [pid 849392:tid 849642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:37.325487 2026] [proxy_http:error] [pid 849392:tid 849642] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:37.326059 2026] [proxy:error] [pid 849392:tid 849642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:37.326104 2026] [proxy_http:error] [pid 849392:tid 849642] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:37.326209 2026] [security2:error] [pid 849392:tid 849642] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUyQMgr4yz2OQW0xrrBgAAAPw"]
[Thu Jul 30 13:15:37.601127 2026] [security2:error] [pid 849392:tid 849564] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-temp.php"] [unique_id "amuUyQMgr4yz2OQW0xrrCwAAAK4"]
[Thu Jul 30 13:15:37.601248 2026] [security2:error] [pid 849392:tid 849564] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-temp.php"] [unique_id "amuUyQMgr4yz2OQW0xrrCwAAAK4"]
[Thu Jul 30 13:15:37.901226 2026] [security2:error] [pid 849392:tid 849571] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-admin/js/index.php"] [unique_id "amuUyQMgr4yz2OQW0xrrDQAAALU"]
[Thu Jul 30 13:15:37.901352 2026] [security2:error] [pid 849392:tid 849571] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-admin/js/index.php"] [unique_id "amuUyQMgr4yz2OQW0xrrDQAAALU"]
[Thu Jul 30 13:15:38.153214 2026] [security2:error] [pid 849392:tid 849543] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/puc.php"] [unique_id "amuUygMgr4yz2OQW0xrrDgAAAJk"]
[Thu Jul 30 13:15:38.153333 2026] [security2:error] [pid 849392:tid 849543] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/puc.php"] [unique_id "amuUygMgr4yz2OQW0xrrDgAAAJk"]
[Thu Jul 30 13:15:38.390874 2026] [security2:error] [pid 849392:tid 849511] [remote 216.73.217.142:13323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuUygMgr4yz2OQW0xrrDwAA5XU"]
[Thu Jul 30 13:15:38.396414 2026] [security2:error] [pid 849392:tid 849617] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dx.php"] [unique_id "amuUygMgr4yz2OQW0xrrEAAAAOM"]
[Thu Jul 30 13:15:38.396503 2026] [security2:error] [pid 849392:tid 849617] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dx.php"] [unique_id "amuUygMgr4yz2OQW0xrrEAAAAOM"]
[Thu Jul 30 13:15:38.644250 2026] [proxy:error] [pid 849392:tid 849529] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:38.644325 2026] [proxy_http:error] [pid 849392:tid 849529] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:38.644888 2026] [proxy:error] [pid 849392:tid 849529] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:38.644929 2026] [proxy_http:error] [pid 849392:tid 849529] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:38.645030 2026] [security2:error] [pid 849392:tid 849529] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUygMgr4yz2OQW0xrrEwAAAIs"]
[Thu Jul 30 13:15:38.667835 2026] [core:notice] [pid 849392:tid 849567] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:38.855853 2026] [security2:error] [pid 849392:tid 849587] [client 43.156.227.240:56758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuUygMgr4yz2OQW0xrrEgAAAMU"]
[Thu Jul 30 13:15:38.883365 2026] [security2:error] [pid 849392:tid 849591] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/7.php"] [unique_id "amuUygMgr4yz2OQW0xrrGAAAAMk"]
[Thu Jul 30 13:15:38.883542 2026] [security2:error] [pid 849392:tid 849591] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/7.php"] [unique_id "amuUygMgr4yz2OQW0xrrGAAAAMk"]
[Thu Jul 30 13:15:39.137857 2026] [security2:error] [pid 849392:tid 849600] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amuUywMgr4yz2OQW0xrrGgAAANI"]
[Thu Jul 30 13:15:39.137998 2026] [security2:error] [pid 849392:tid 849600] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amuUywMgr4yz2OQW0xrrGgAAANI"]
[Thu Jul 30 13:15:39.792428 2026] [security2:error] [pid 849392:tid 849607] [client 20.203.205.96:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amuUywMgr4yz2OQW0xrrIAAAANk"]
[Thu Jul 30 13:15:39.792549 2026] [security2:error] [pid 849392:tid 849607] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amuUywMgr4yz2OQW0xrrIAAAANk"]
[Thu Jul 30 13:15:39.792664 2026] [security2:error] [pid 849392:tid 849607] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amuUywMgr4yz2OQW0xrrIAAAANk"]
[Thu Jul 30 13:15:40.126418 2026] [security2:error] [pid 849392:tid 849583] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amuUzAMgr4yz2OQW0xrrIQAAAME"]
[Thu Jul 30 13:15:40.126568 2026] [security2:error] [pid 849392:tid 849583] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amuUzAMgr4yz2OQW0xrrIQAAAME"]
[Thu Jul 30 13:15:40.476591 2026] [security2:error] [pid 849392:tid 849605] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amuUzAMgr4yz2OQW0xrrJQAAANc"]
[Thu Jul 30 13:15:40.476716 2026] [security2:error] [pid 849392:tid 849605] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amuUzAMgr4yz2OQW0xrrJQAAANc"]
[Thu Jul 30 13:15:40.715375 2026] [security2:error] [pid 849392:tid 849553] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/edit.php"] [unique_id "amuUzAMgr4yz2OQW0xrrJgAAAKM"]
[Thu Jul 30 13:15:40.715533 2026] [security2:error] [pid 849392:tid 849553] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/edit.php"] [unique_id "amuUzAMgr4yz2OQW0xrrJgAAAKM"]
[Thu Jul 30 13:15:40.968347 2026] [security2:error] [pid 849392:tid 849531] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amuUzAMgr4yz2OQW0xrrKAAAAI0"]
[Thu Jul 30 13:15:40.968492 2026] [security2:error] [pid 849392:tid 849531] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amuUzAMgr4yz2OQW0xrrKAAAAI0"]
[Thu Jul 30 13:15:41.321605 2026] [security2:error] [pid 849392:tid 849629] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/inputs.php"] [unique_id "amuUzQMgr4yz2OQW0xrrKgAAAO8"]
[Thu Jul 30 13:15:41.321723 2026] [security2:error] [pid 849392:tid 849629] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/inputs.php"] [unique_id "amuUzQMgr4yz2OQW0xrrKgAAAO8"]
[Thu Jul 30 13:15:41.681260 2026] [security2:error] [pid 849392:tid 849595] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/av.php"] [unique_id "amuUzQMgr4yz2OQW0xrrKwAAAM0"]
[Thu Jul 30 13:15:41.681370 2026] [security2:error] [pid 849392:tid 849595] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/av.php"] [unique_id "amuUzQMgr4yz2OQW0xrrKwAAAM0"]
[Thu Jul 30 13:15:41.937914 2026] [security2:error] [pid 849392:tid 849554] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/classwithtostring.php"] [unique_id "amuUzQMgr4yz2OQW0xrrLAAAAKQ"]
[Thu Jul 30 13:15:41.938061 2026] [security2:error] [pid 849392:tid 849554] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/classwithtostring.php"] [unique_id "amuUzQMgr4yz2OQW0xrrLAAAAKQ"]
[Thu Jul 30 13:15:42.317629 2026] [security2:error] [pid 849392:tid 849565] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/themes/index.php"] [unique_id "amuUzgMgr4yz2OQW0xrrMQAAAK8"]
[Thu Jul 30 13:15:42.317769 2026] [security2:error] [pid 849392:tid 849565] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/themes/index.php"] [unique_id "amuUzgMgr4yz2OQW0xrrMQAAAK8"]
[Thu Jul 30 13:15:42.508189 2026] [security2:error] [pid 849392:tid 849574] [client 82.102.27.163:47296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuUzgMgr4yz2OQW0xrrMgAAALg"]
[Thu Jul 30 13:15:42.508295 2026] [security2:error] [pid 849392:tid 849574] [client 82.102.27.163:47296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuUzgMgr4yz2OQW0xrrMgAAALg"]
[Thu Jul 30 13:15:42.557141 2026] [security2:error] [pid 849392:tid 849548] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-blog.php"] [unique_id "amuUzgMgr4yz2OQW0xrrNAAAAJ4"]
[Thu Jul 30 13:15:42.557237 2026] [security2:error] [pid 849392:tid 849548] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-blog.php"] [unique_id "amuUzgMgr4yz2OQW0xrrNAAAAJ4"]
[Thu Jul 30 13:15:42.775548 2026] [security2:error] [pid 849392:tid 849552] [client 104.28.159.45:35457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.159.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvape-australia.com"] [uri "/wp-login.php"] [unique_id "amuUzgMgr4yz2OQW0xrrMwAAAKI"]
[Thu Jul 30 13:15:42.819035 2026] [proxy:error] [pid 849392:tid 849575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:42.819112 2026] [proxy_http:error] [pid 849392:tid 849575] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:42.820059 2026] [proxy:error] [pid 849392:tid 849575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:42.820113 2026] [proxy_http:error] [pid 849392:tid 849575] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:42.820221 2026] [security2:error] [pid 849392:tid 849575] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuUzgMgr4yz2OQW0xrrPQAAALk"]
[Thu Jul 30 13:15:43.065258 2026] [security2:error] [pid 849392:tid 849628] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amuUzwMgr4yz2OQW0xrrPwAAAO4"]
[Thu Jul 30 13:15:43.065411 2026] [security2:error] [pid 849392:tid 849628] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amuUzwMgr4yz2OQW0xrrPwAAAO4"]
[Thu Jul 30 13:15:43.323670 2026] [security2:error] [pid 849392:tid 849564] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/adminfuns.php"] [unique_id "amuUzwMgr4yz2OQW0xrrQgAAAK4"]
[Thu Jul 30 13:15:43.323786 2026] [security2:error] [pid 849392:tid 849564] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/adminfuns.php"] [unique_id "amuUzwMgr4yz2OQW0xrrQgAAAK4"]
[Thu Jul 30 13:15:43.559920 2026] [security2:error] [pid 849392:tid 849551] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/goods.php"] [unique_id "amuUzwMgr4yz2OQW0xrrRgAAAKE"]
[Thu Jul 30 13:15:43.560022 2026] [security2:error] [pid 849392:tid 849551] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/goods.php"] [unique_id "amuUzwMgr4yz2OQW0xrrRgAAAKE"]
[Thu Jul 30 13:15:43.934607 2026] [security2:error] [pid 849392:tid 849560] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ms-edit.php"] [unique_id "amuUzwMgr4yz2OQW0xrrTwAAAKo"]
[Thu Jul 30 13:15:43.934756 2026] [security2:error] [pid 849392:tid 849560] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ms-edit.php"] [unique_id "amuUzwMgr4yz2OQW0xrrTwAAAKo"]
[Thu Jul 30 13:15:44.174337 2026] [security2:error] [pid 849392:tid 849631] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/222.php"] [unique_id "amuU0AMgr4yz2OQW0xrrUAAAAPE"]
[Thu Jul 30 13:15:44.174463 2026] [security2:error] [pid 849392:tid 849631] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/222.php"] [unique_id "amuU0AMgr4yz2OQW0xrrUAAAAPE"]
[Thu Jul 30 13:15:44.431158 2026] [security2:error] [pid 849392:tid 849587] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/cgi-bin/index.php"] [unique_id "amuU0AMgr4yz2OQW0xrrUQAAAMU"]
[Thu Jul 30 13:15:44.431272 2026] [security2:error] [pid 849392:tid 849587] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/cgi-bin/index.php"] [unique_id "amuU0AMgr4yz2OQW0xrrUQAAAMU"]
[Thu Jul 30 13:15:44.685137 2026] [proxy:error] [pid 849392:tid 849591] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:44.685229 2026] [proxy_http:error] [pid 849392:tid 849591] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:44.686044 2026] [proxy:error] [pid 849392:tid 849591] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:44.686101 2026] [proxy_http:error] [pid 849392:tid 849591] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:44.686218 2026] [security2:error] [pid 849392:tid 849591] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuU0AMgr4yz2OQW0xrrUgAAAMk"]
[Thu Jul 30 13:15:44.949548 2026] [security2:error] [pid 849392:tid 849600] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/BDKR28WP.php"] [unique_id "amuU0AMgr4yz2OQW0xrrUwAAANI"]
[Thu Jul 30 13:15:44.949675 2026] [security2:error] [pid 849392:tid 849600] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/BDKR28WP.php"] [unique_id "amuU0AMgr4yz2OQW0xrrUwAAANI"]
[Thu Jul 30 13:15:45.217505 2026] [proxy:error] [pid 849392:tid 849612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:45.217606 2026] [proxy_http:error] [pid 849392:tid 849612] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:45.218424 2026] [proxy:error] [pid 849392:tid 849612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:45.218477 2026] [proxy_http:error] [pid 849392:tid 849612] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:45.218615 2026] [security2:error] [pid 849392:tid 849612] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuU0QMgr4yz2OQW0xrrVQAAAN4"]
[Thu Jul 30 13:15:45.458134 2026] [proxy:error] [pid 849392:tid 849536] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:45.458213 2026] [proxy_http:error] [pid 849392:tid 849536] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:45.459112 2026] [proxy:error] [pid 849392:tid 849536] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:45.459165 2026] [proxy_http:error] [pid 849392:tid 849536] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:45.459270 2026] [security2:error] [pid 849392:tid 849536] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuU0QMgr4yz2OQW0xrrWAAAAJI"]
[Thu Jul 30 13:15:45.646916 2026] [security2:error] [pid 849392:tid 849610] [client 179.64.21.229:14296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU0QMgr4yz2OQW0xrrWQAAANw"]
[Thu Jul 30 13:15:45.647061 2026] [security2:error] [pid 849392:tid 849610] [client 179.64.21.229:14296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU0QMgr4yz2OQW0xrrWQAAANw"]
[Thu Jul 30 13:15:45.751489 2026] [security2:error] [pid 849392:tid 849607] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp.php"] [unique_id "amuU0QMgr4yz2OQW0xrrWgAAANk"]
[Thu Jul 30 13:15:45.751632 2026] [security2:error] [pid 849392:tid 849607] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp.php"] [unique_id "amuU0QMgr4yz2OQW0xrrWgAAANk"]
[Thu Jul 30 13:15:45.840973 2026] [security2:error] [pid 849392:tid 849616] [client 172.236.9.101:37218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU0QMgr4yz2OQW0xrrVgAAAOI"]
[Thu Jul 30 13:15:46.005872 2026] [security2:error] [pid 849392:tid 849605] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/abcd.php"] [unique_id "amuU0gMgr4yz2OQW0xrrXAAAANc"]
[Thu Jul 30 13:15:46.006039 2026] [security2:error] [pid 849392:tid 849605] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/abcd.php"] [unique_id "amuU0gMgr4yz2OQW0xrrXAAAANc"]
[Thu Jul 30 13:15:46.086472 2026] [core:notice] [pid 849392:tid 849458] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:46.244124 2026] [security2:error] [pid 849392:tid 849604] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/a1.php"] [unique_id "amuU0gMgr4yz2OQW0xrrXgAAANY"]
[Thu Jul 30 13:15:46.244242 2026] [security2:error] [pid 849392:tid 849604] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/a1.php"] [unique_id "amuU0gMgr4yz2OQW0xrrXgAAANY"]
[Thu Jul 30 13:15:46.479333 2026] [core:notice] [pid 849392:tid 849423] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:46.506744 2026] [security2:error] [pid 849392:tid 849632] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuU0gMgr4yz2OQW0xrrYAAAAPI"]
[Thu Jul 30 13:15:46.506834 2026] [security2:error] [pid 849392:tid 849632] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuU0gMgr4yz2OQW0xrrYAAAAPI"]
[Thu Jul 30 13:15:46.744968 2026] [security2:error] [pid 849392:tid 849562] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/cgi-bin/admin.php"] [unique_id "amuU0gMgr4yz2OQW0xrrYQAAAKw"]
[Thu Jul 30 13:15:46.745099 2026] [security2:error] [pid 849392:tid 849562] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/cgi-bin/admin.php"] [unique_id "amuU0gMgr4yz2OQW0xrrYQAAAKw"]
[Thu Jul 30 13:15:47.079773 2026] [proxy:error] [pid 849392:tid 849614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:47.079847 2026] [proxy_http:error] [pid 849392:tid 849614] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:47.080428 2026] [proxy:error] [pid 849392:tid 849614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:47.080472 2026] [proxy_http:error] [pid 849392:tid 849614] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:47.080583 2026] [security2:error] [pid 849392:tid 849614] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuU0wMgr4yz2OQW0xrrYgAAAOA"]
[Thu Jul 30 13:15:47.325786 2026] [security2:error] [pid 849392:tid 849556] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/simple.php"] [unique_id "amuU0wMgr4yz2OQW0xrrZwAAAKY"]
[Thu Jul 30 13:15:47.325906 2026] [security2:error] [pid 849392:tid 849556] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/simple.php"] [unique_id "amuU0wMgr4yz2OQW0xrrZwAAAKY"]
[Thu Jul 30 13:15:47.580165 2026] [security2:error] [pid 849392:tid 849524] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xxx.php"] [unique_id "amuU0wMgr4yz2OQW0xrragAAAIY"]
[Thu Jul 30 13:15:47.580274 2026] [security2:error] [pid 849392:tid 849524] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xxx.php"] [unique_id "amuU0wMgr4yz2OQW0xrragAAAIY"]
[Thu Jul 30 13:15:47.791189 2026] [core:notice] [pid 849392:tid 849548] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:47.832067 2026] [security2:error] [pid 849392:tid 849528] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/hypo.php"] [unique_id "amuU0wMgr4yz2OQW0xrrbgAAAIo"]
[Thu Jul 30 13:15:47.832210 2026] [security2:error] [pid 849392:tid 849528] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/hypo.php"] [unique_id "amuU0wMgr4yz2OQW0xrrbgAAAIo"]
[Thu Jul 30 13:15:48.073546 2026] [proxy:error] [pid 849392:tid 849547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:48.073625 2026] [proxy_http:error] [pid 849392:tid 849547] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:48.074463 2026] [proxy:error] [pid 849392:tid 849547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:48.074517 2026] [proxy_http:error] [pid 849392:tid 849547] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:48.074618 2026] [security2:error] [pid 849392:tid 849547] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuU1AMgr4yz2OQW0xrrbwAAAJ0"]
[Thu Jul 30 13:15:48.200867 2026] [core:notice] [pid 849392:tid 849598] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:48.325145 2026] [security2:error] [pid 849392:tid 849624] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/chosen.php"] [unique_id "amuU1AMgr4yz2OQW0xrrcgAAAOo"]
[Thu Jul 30 13:15:48.325269 2026] [security2:error] [pid 849392:tid 849624] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/chosen.php"] [unique_id "amuU1AMgr4yz2OQW0xrrcgAAAOo"]
[Thu Jul 30 13:15:48.579819 2026] [proxy:error] [pid 849392:tid 849557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:48.579895 2026] [proxy_http:error] [pid 849392:tid 849557] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:48.580885 2026] [proxy:error] [pid 849392:tid 849557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:48.580940 2026] [proxy_http:error] [pid 849392:tid 849557] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:48.581061 2026] [security2:error] [pid 849392:tid 849557] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuU1AMgr4yz2OQW0xrrdAAAAKc"]
[Thu Jul 30 13:15:49.118562 2026] [security2:error] [pid 849392:tid 849608] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/als.php"] [unique_id "amuU1QMgr4yz2OQW0xrrdgAAANo"]
[Thu Jul 30 13:15:49.118673 2026] [security2:error] [pid 849392:tid 849608] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/als.php"] [unique_id "amuU1QMgr4yz2OQW0xrrdgAAANo"]
[Thu Jul 30 13:15:49.358639 2026] [security2:error] [pid 849392:tid 849593] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/pol.php"] [unique_id "amuU1QMgr4yz2OQW0xrrewAAAMs"]
[Thu Jul 30 13:15:49.358758 2026] [security2:error] [pid 849392:tid 849593] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/pol.php"] [unique_id "amuU1QMgr4yz2OQW0xrrewAAAMs"]
[Thu Jul 30 13:15:49.444468 2026] [security2:error] [pid 849392:tid 849529] [client 82.102.18.188:47192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuU1QMgr4yz2OQW0xrrgQAAAIs"]
[Thu Jul 30 13:15:49.603279 2026] [security2:error] [pid 849392:tid 849622] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file5.php"] [unique_id "amuU1QMgr4yz2OQW0xrrhAAAAOg"]
[Thu Jul 30 13:15:49.603465 2026] [security2:error] [pid 849392:tid 849622] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file5.php"] [unique_id "amuU1QMgr4yz2OQW0xrrhAAAAOg"]
[Thu Jul 30 13:15:49.718896 2026] [core:notice] [pid 849392:tid 849543] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:49.882443 2026] [security2:error] [pid 849392:tid 849609] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file.php"] [unique_id "amuU1QMgr4yz2OQW0xrrhwAAANs"]
[Thu Jul 30 13:15:49.882559 2026] [security2:error] [pid 849392:tid 849609] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file.php"] [unique_id "amuU1QMgr4yz2OQW0xrrhwAAANs"]
[Thu Jul 30 13:15:50.090211 2026] [core:notice] [pid 849392:tid 849559] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:50.137494 2026] [security2:error] [pid 849392:tid 849647] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amuU1gMgr4yz2OQW0xrrigAAAQE"]
[Thu Jul 30 13:15:50.137618 2026] [security2:error] [pid 849392:tid 849647] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amuU1gMgr4yz2OQW0xrrigAAAQE"]
[Thu Jul 30 13:15:50.232521 2026] [security2:error] [pid 849392:tid 849600] [client 82.102.18.188:47208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nfh.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuU1QMgr4yz2OQW0xrriAAAANI"]
[Thu Jul 30 13:15:50.389947 2026] [security2:error] [pid 849392:tid 849610] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aa2.php"] [unique_id "amuU1gMgr4yz2OQW0xrriwAAANw"]
[Thu Jul 30 13:15:50.390083 2026] [security2:error] [pid 849392:tid 849610] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aa2.php"] [unique_id "amuU1gMgr4yz2OQW0xrriwAAANw"]
[Thu Jul 30 13:15:50.563503 2026] [security2:error] [pid 849392:tid 849640] [client 82.102.18.188:47210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuU1gMgr4yz2OQW0xrrjAAAAPo"]
[Thu Jul 30 13:15:50.745121 2026] [security2:error] [pid 849392:tid 849605] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ccou.php"] [unique_id "amuU1gMgr4yz2OQW0xrrjQAAANc"]
[Thu Jul 30 13:15:50.745299 2026] [security2:error] [pid 849392:tid 849605] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ccou.php"] [unique_id "amuU1gMgr4yz2OQW0xrrjQAAANc"]
[Thu Jul 30 13:15:50.805074 2026] [security2:error] [pid 849392:tid 849607] [client 54.159.98.248:27119] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "radiojelli.com"] [uri "/img/articles/63/15-typical-everyday-things-only-mother-baby-nurses-will-understand.jpg"] [unique_id "amuU1gMgr4yz2OQW0xrrkQAAANk"]
[Thu Jul 30 13:15:50.937910 2026] [security2:error] [pid 849392:tid 849523] [client 82.102.18.188:47220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuU1gMgr4yz2OQW0xrrlQAAAIU"]
[Thu Jul 30 13:15:50.996849 2026] [security2:error] [pid 849392:tid 849562] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dr.php"] [unique_id "amuU1gMgr4yz2OQW0xrrlwAAAKw"]
[Thu Jul 30 13:15:50.996951 2026] [security2:error] [pid 849392:tid 849562] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dr.php"] [unique_id "amuU1gMgr4yz2OQW0xrrlwAAAKw"]
[Thu Jul 30 13:15:51.237655 2026] [security2:error] [pid 849392:tid 849570] [client 82.102.18.188:39292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuU1wMgr4yz2OQW0xrrmgAAALQ"]
[Thu Jul 30 13:15:51.246157 2026] [security2:error] [pid 849392:tid 849524] [client 139.28.219.70:32856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuU1wMgr4yz2OQW0xrrmwAAAIY"]
[Thu Jul 30 13:15:51.250190 2026] [security2:error] [pid 849392:tid 849574] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xamp.php"] [unique_id "amuU1wMgr4yz2OQW0xrrnAAAALg"]
[Thu Jul 30 13:15:51.250269 2026] [security2:error] [pid 849392:tid 849574] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xamp.php"] [unique_id "amuU1wMgr4yz2OQW0xrrnAAAALg"]
[Thu Jul 30 13:15:51.496721 2026] [security2:error] [pid 849392:tid 849534] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/bless.php"] [unique_id "amuU1wMgr4yz2OQW0xrrngAAAJA"]
[Thu Jul 30 13:15:51.496840 2026] [security2:error] [pid 849392:tid 849534] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/bless.php"] [unique_id "amuU1wMgr4yz2OQW0xrrngAAAJA"]
[Thu Jul 30 13:15:51.569437 2026] [security2:error] [pid 849392:tid 849623] [client 82.102.18.188:47244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuU1wMgr4yz2OQW0xrrnwAAAOk"]
[Thu Jul 30 13:15:51.585012 2026] [security2:error] [pid 849392:tid 849425] [remote 57.141.0.66:43668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuU1wMgr4yz2OQW0xrroAABAx8"]
[Thu Jul 30 13:15:51.590569 2026] [security2:error] [pid 849392:tid 849545] [client 139.28.219.70:32880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "offthewallinbisbee.com"] [uri "/xmlrpc.php"] [unique_id "amuU1wMgr4yz2OQW0xrroQAAAJs"]
[Thu Jul 30 13:15:51.760663 2026] [security2:error] [pid 849392:tid 849578] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file25.php"] [unique_id "amuU1wMgr4yz2OQW0xrrowAAALw"]
[Thu Jul 30 13:15:51.760803 2026] [security2:error] [pid 849392:tid 849578] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file25.php"] [unique_id "amuU1wMgr4yz2OQW0xrrowAAALw"]
[Thu Jul 30 13:15:52.000665 2026] [security2:error] [pid 849392:tid 849533] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file6.php"] [unique_id "amuU1wMgr4yz2OQW0xrrpQAAAI8"]
[Thu Jul 30 13:15:52.000782 2026] [security2:error] [pid 849392:tid 849533] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file6.php"] [unique_id "amuU1wMgr4yz2OQW0xrrpQAAAI8"]
[Thu Jul 30 13:15:52.074721 2026] [security2:error] [pid 849392:tid 849636] [client 139.28.219.70:32894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuU2AMgr4yz2OQW0xrrpgAAAPY"]
[Thu Jul 30 13:15:52.142147 2026] [security2:error] [pid 849392:tid 849569] [client 82.102.18.188:65015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuU2AMgr4yz2OQW0xrrpwAAALM"]
[Thu Jul 30 13:15:52.241253 2026] [security2:error] [pid 849392:tid 849530] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/a2.php"] [unique_id "amuU2AMgr4yz2OQW0xrrqAAAAIw"]
[Thu Jul 30 13:15:52.241382 2026] [security2:error] [pid 849392:tid 849530] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/a2.php"] [unique_id "amuU2AMgr4yz2OQW0xrrqAAAAIw"]
[Thu Jul 30 13:15:52.372933 2026] [security2:error] [pid 849392:tid 849619] [client 139.28.219.70:32896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuU2AMgr4yz2OQW0xrrqQAAAOU"]
[Thu Jul 30 13:15:52.432182 2026] [security2:error] [pid 849392:tid 849525] [client 82.102.18.188:57169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuU2AMgr4yz2OQW0xrrrQAAAIc"]
[Thu Jul 30 13:15:52.460767 2026] [security2:error] [pid 849392:tid 849625] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuU1wMgr4yz2OQW0xrrogAA6wY"]
[Thu Jul 30 13:15:52.574382 2026] [autoindex:error] [pid 849392:tid 849639] [client 44.213.206.96:2536] AH01276: Cannot serve directory /home1/lomgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:15:52.582314 2026] [autoindex:error] [pid 849392:tid 849593] [client 52.4.19.39:52772] AH01276: Cannot serve directory /home1/lomgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:15:52.600757 2026] [proxy:error] [pid 849392:tid 849529] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:52.600832 2026] [proxy_http:error] [pid 849392:tid 849529] [client 52.4.19.39:5989] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:52.601411 2026] [proxy:error] [pid 849392:tid 849529] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:52.601455 2026] [proxy_http:error] [pid 849392:tid 849529] [client 52.4.19.39:5989] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:52.603616 2026] [security2:error] [pid 849392:tid 849573] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file15.php"] [unique_id "amuU2AMgr4yz2OQW0xrrtQAAALc"]
[Thu Jul 30 13:15:52.603689 2026] [security2:error] [pid 849392:tid 849573] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file15.php"] [unique_id "amuU2AMgr4yz2OQW0xrrtQAAALc"]
[Thu Jul 30 13:15:52.613613 2026] [proxy:error] [pid 849392:tid 849560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:52.613694 2026] [proxy_http:error] [pid 849392:tid 849560] [client 52.4.19.39:42687] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:52.614269 2026] [proxy:error] [pid 849392:tid 849560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:52.614315 2026] [proxy_http:error] [pid 849392:tid 849560] [client 52.4.19.39:42687] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:52.648419 2026] [security2:error] [pid 849392:tid 849542] [client 139.28.219.70:32900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuU2AMgr4yz2OQW0xrruQAAAJg"]
[Thu Jul 30 13:15:52.702187 2026] [security2:error] [pid 849392:tid 849526] [client 82.102.18.188:47276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuU2AMgr4yz2OQW0xrrugAAAIg"]
[Thu Jul 30 13:15:52.786584 2026] [security2:error] [pid 849392:tid 849441] [remote 216.73.217.142:13323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuU2AMgr4yz2OQW0xrruwAAxS8"]
[Thu Jul 30 13:15:52.874555 2026] [security2:error] [pid 849392:tid 849648] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/f35.php"] [unique_id "amuU2AMgr4yz2OQW0xrrvAAAAQI"]
[Thu Jul 30 13:15:52.874713 2026] [security2:error] [pid 849392:tid 849648] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/f35.php"] [unique_id "amuU2AMgr4yz2OQW0xrrvAAAAQI"]
[Thu Jul 30 13:15:52.926606 2026] [security2:error] [pid 849392:tid 849532] [client 139.28.219.70:32902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuU2AMgr4yz2OQW0xrrvQAAAI4"]
[Thu Jul 30 13:15:52.978106 2026] [security2:error] [pid 849392:tid 849612] [client 82.102.18.188:47284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuU2AMgr4yz2OQW0xrrvgAAAN4"]
[Thu Jul 30 13:15:53.341353 2026] [http2:info] [pid 872418:tid 872418] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 13:15:53.357012 2026] [security2:error] [pid 872418:tid 872548] [client 139.28.219.70:32916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuU2VymN6QYcoA7XB44BQAAAAA"]
[Thu Jul 30 13:15:53.357180 2026] [security2:error] [pid 872418:tid 872549] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-load.php"] [unique_id "amuU2VymN6QYcoA7XB44BgAAAAE"]
[Thu Jul 30 13:15:53.357185 2026] [security2:error] [pid 872418:tid 872550] [client 82.102.18.188:47294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuU2VymN6QYcoA7XB44BwAAAAI"]
[Thu Jul 30 13:15:53.357379 2026] [security2:error] [pid 872418:tid 872549] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-load.php"] [unique_id "amuU2VymN6QYcoA7XB44BgAAAAE"]
[Thu Jul 30 13:15:53.640681 2026] [security2:error] [pid 872418:tid 872555] [client 139.28.219.70:32922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuU2VymN6QYcoA7XB44CQAAAAc"]
[Thu Jul 30 13:15:53.676528 2026] [security2:error] [pid 872418:tid 872556] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xwpg.php"] [unique_id "amuU2VymN6QYcoA7XB44CgAAAAg"]
[Thu Jul 30 13:15:53.676763 2026] [security2:error] [pid 872418:tid 872556] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xwpg.php"] [unique_id "amuU2VymN6QYcoA7XB44CgAAAAg"]
[Thu Jul 30 13:15:53.923286 2026] [proxy:error] [pid 872418:tid 872560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:53.923352 2026] [proxy_http:error] [pid 872418:tid 872560] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:53.924049 2026] [proxy:error] [pid 872418:tid 872560] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:53.924095 2026] [proxy_http:error] [pid 872418:tid 872560] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:53.924218 2026] [security2:error] [pid 872418:tid 872560] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuU2VymN6QYcoA7XB44CwAAAAw"]
[Thu Jul 30 13:15:53.952529 2026] [security2:error] [pid 872418:tid 872561] [client 139.28.219.70:32934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuU2VymN6QYcoA7XB44DAAAAA0"]
[Thu Jul 30 13:15:54.171278 2026] [proxy:error] [pid 872418:tid 872567] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:54.171352 2026] [proxy_http:error] [pid 872418:tid 872567] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:54.172099 2026] [proxy:error] [pid 872418:tid 872567] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:54.172146 2026] [proxy_http:error] [pid 872418:tid 872567] [client 20.203.205.96:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:54.172263 2026] [security2:error] [pid 872418:tid 872567] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuU2lymN6QYcoA7XB44DQAAABM"]
[Thu Jul 30 13:15:54.286036 2026] [security2:error] [pid 872418:tid 872569] [client 139.28.219.70:32942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuU2lymN6QYcoA7XB44DgAAABU"]
[Thu Jul 30 13:15:54.423913 2026] [security2:error] [pid 872418:tid 872572] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xstelth.php"] [unique_id "amuU2lymN6QYcoA7XB44EgAAABg"]
[Thu Jul 30 13:15:54.424042 2026] [security2:error] [pid 872418:tid 872572] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xstelth.php"] [unique_id "amuU2lymN6QYcoA7XB44EgAAABg"]
[Thu Jul 30 13:15:54.424505 2026] [security2:error] [pid 872418:tid 872546] [remote 57.141.0.6:40920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amuU2lymN6QYcoA7XB44EQAAFH8"]
[Thu Jul 30 13:15:54.580767 2026] [security2:error] [pid 872418:tid 872575] [client 139.28.219.70:32962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuU2lymN6QYcoA7XB44EwAAABs"]
[Thu Jul 30 13:15:54.630138 2026] [security2:error] [pid 872418:tid 872577] [client 82.102.18.188:51234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuU2lymN6QYcoA7XB44FAAAAB0"]
[Thu Jul 30 13:15:54.645430 2026] [proxy:error] [pid 849392:tid 849549] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:54.645511 2026] [proxy_http:error] [pid 849392:tid 849549] [client 195.96.139.223:60049] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:54.646081 2026] [proxy:error] [pid 849392:tid 849549] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:54.646126 2026] [proxy_http:error] [pid 849392:tid 849549] [client 195.96.139.223:60049] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:54.667476 2026] [security2:error] [pid 872418:tid 872580] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuU2lymN6QYcoA7XB44FQAAACA"]
[Thu Jul 30 13:15:54.667584 2026] [security2:error] [pid 872418:tid 872580] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuU2lymN6QYcoA7XB44FQAAACA"]
[Thu Jul 30 13:15:54.909631 2026] [security2:error] [pid 872418:tid 872584] [client 82.102.18.188:51246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuU2lymN6QYcoA7XB44FgAAACQ"]
[Thu Jul 30 13:15:54.910702 2026] [security2:error] [pid 872418:tid 872586] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aaa.php"] [unique_id "amuU2lymN6QYcoA7XB44FwAAACY"]
[Thu Jul 30 13:15:54.910788 2026] [security2:error] [pid 872418:tid 872586] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aaa.php"] [unique_id "amuU2lymN6QYcoA7XB44FwAAACY"]
[Thu Jul 30 13:15:54.923728 2026] [security2:error] [pid 872418:tid 872587] [client 139.28.219.70:32976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuU2lymN6QYcoA7XB44GAAAACc"]
[Thu Jul 30 13:15:55.187180 2026] [security2:error] [pid 872418:tid 872592] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/gecko.php"] [unique_id "amuU21ymN6QYcoA7XB44GQAAACw"]
[Thu Jul 30 13:15:55.187308 2026] [security2:error] [pid 872418:tid 872592] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/gecko.php"] [unique_id "amuU21ymN6QYcoA7XB44GQAAACw"]
[Thu Jul 30 13:15:55.242125 2026] [security2:error] [pid 872418:tid 872593] [client 139.28.219.70:32978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuU21ymN6QYcoA7XB44GgAAAC0"]
[Thu Jul 30 13:15:55.438442 2026] [security2:error] [pid 872418:tid 872599] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/pbck.php"] [unique_id "amuU21ymN6QYcoA7XB44HQAAADM"]
[Thu Jul 30 13:15:55.438553 2026] [security2:error] [pid 872418:tid 872599] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/pbck.php"] [unique_id "amuU21ymN6QYcoA7XB44HQAAADM"]
[Thu Jul 30 13:15:55.449218 2026] [security2:error] [pid 872418:tid 872600] [client 82.102.18.188:51256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuU21ymN6QYcoA7XB44HgAAADQ"]
[Thu Jul 30 13:15:55.538221 2026] [security2:error] [pid 872418:tid 872601] [client 139.28.219.70:32984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuU21ymN6QYcoA7XB44HwAAADU"]
[Thu Jul 30 13:15:55.699565 2026] [security2:error] [pid 872418:tid 872606] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xiugai.php"] [unique_id "amuU21ymN6QYcoA7XB44IAAAADo"]
[Thu Jul 30 13:15:55.699691 2026] [security2:error] [pid 872418:tid 872606] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xiugai.php"] [unique_id "amuU21ymN6QYcoA7XB44IAAAADo"]
[Thu Jul 30 13:15:55.795686 2026] [security2:error] [pid 872418:tid 872607] [client 82.102.18.188:51258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.nfh.udi.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuU21ymN6QYcoA7XB44IQAAADs"]
[Thu Jul 30 13:15:55.880367 2026] [security2:error] [pid 872418:tid 872610] [client 139.28.219.70:32998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "offthewallinbisbee.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuU21ymN6QYcoA7XB44IgAAAD4"]
[Thu Jul 30 13:15:55.939902 2026] [security2:error] [pid 872418:tid 872611] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/e.php"] [unique_id "amuU21ymN6QYcoA7XB44IwAAAD8"]
[Thu Jul 30 13:15:55.940374 2026] [security2:error] [pid 872418:tid 872611] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/e.php"] [unique_id "amuU21ymN6QYcoA7XB44IwAAAD8"]
[Thu Jul 30 13:15:55.960054 2026] [security2:error] [pid 872418:tid 872604] [client 179.64.21.229:52712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU21ymN6QYcoA7XB44JAAAADg"]
[Thu Jul 30 13:15:55.972131 2026] [security2:error] [pid 872418:tid 872604] [client 179.64.21.229:52712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU21ymN6QYcoA7XB44JAAAADg"]
[Thu Jul 30 13:15:56.259261 2026] [security2:error] [pid 872418:tid 872618] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/adminner.php"] [unique_id "amuU3FymN6QYcoA7XB44JwAAAEY"]
[Thu Jul 30 13:15:56.259401 2026] [security2:error] [pid 872418:tid 872618] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/adminner.php"] [unique_id "amuU3FymN6QYcoA7XB44JwAAAEY"]
[Thu Jul 30 13:15:56.433348 2026] [autoindex:error] [pid 872418:tid 872620] [client 3.228.112.215:24803] AH01276: Cannot serve directory /home1/lomgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:15:56.453489 2026] [autoindex:error] [pid 872418:tid 872621] [client 54.87.222.253:48372] AH01276: Cannot serve directory /home1/lomgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:15:56.462182 2026] [proxy:error] [pid 872418:tid 872626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:56.462255 2026] [proxy_http:error] [pid 872418:tid 872626] [client 52.202.41.153:42810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:56.463006 2026] [proxy:error] [pid 872418:tid 872626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:56.463062 2026] [proxy_http:error] [pid 872418:tid 872626] [client 52.202.41.153:42810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:56.469834 2026] [proxy:error] [pid 872418:tid 872627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:56.469908 2026] [proxy_http:error] [pid 872418:tid 872627] [client 3.228.112.215:5207] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:56.470552 2026] [proxy:error] [pid 872418:tid 872627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:15:56.470605 2026] [proxy_http:error] [pid 872418:tid 872627] [client 3.228.112.215:5207] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:15:56.744766 2026] [security2:error] [pid 872418:tid 872637] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file1221.php"] [unique_id "amuU3FymN6QYcoA7XB44MQAAAFk"]
[Thu Jul 30 13:15:56.744916 2026] [security2:error] [pid 872418:tid 872637] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/file1221.php"] [unique_id "amuU3FymN6QYcoA7XB44MQAAAFk"]
[Thu Jul 30 13:15:56.993295 2026] [security2:error] [pid 872418:tid 872640] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/inx.php"] [unique_id "amuU3FymN6QYcoA7XB44MgAAAFw"]
[Thu Jul 30 13:15:56.993462 2026] [security2:error] [pid 872418:tid 872640] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/inx.php"] [unique_id "amuU3FymN6QYcoA7XB44MgAAAFw"]
[Thu Jul 30 13:15:57.407106 2026] [security2:error] [pid 872418:tid 872643] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/qqqa.php"] [unique_id "amuU3VymN6QYcoA7XB44NQAAAF8"]
[Thu Jul 30 13:15:57.407274 2026] [security2:error] [pid 872418:tid 872643] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/qqqa.php"] [unique_id "amuU3VymN6QYcoA7XB44NQAAAF8"]
[Thu Jul 30 13:15:57.646818 2026] [security2:error] [pid 872418:tid 872648] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/reviall.php"] [unique_id "amuU3VymN6QYcoA7XB44NgAAAGQ"]
[Thu Jul 30 13:15:57.647011 2026] [security2:error] [pid 872418:tid 872648] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/reviall.php"] [unique_id "amuU3VymN6QYcoA7XB44NgAAAGQ"]
[Thu Jul 30 13:15:57.886487 2026] [security2:error] [pid 872418:tid 872651] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/404.php"] [unique_id "amuU3VymN6QYcoA7XB44OAAAAGc"]
[Thu Jul 30 13:15:57.886662 2026] [security2:error] [pid 872418:tid 872651] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/404.php"] [unique_id "amuU3VymN6QYcoA7XB44OAAAAGc"]
[Thu Jul 30 13:15:58.127559 2026] [security2:error] [pid 872418:tid 872654] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/bolt.php"] [unique_id "amuU3lymN6QYcoA7XB44OQAAAGo"]
[Thu Jul 30 13:15:58.127727 2026] [security2:error] [pid 872418:tid 872654] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/bolt.php"] [unique_id "amuU3lymN6QYcoA7XB44OQAAAGo"]
[Thu Jul 30 13:15:58.231969 2026] [security2:error] [pid 872418:tid 872422] [remote 216.73.217.142:21657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuU3lymN6QYcoA7XB44OgAAaQM"]
[Thu Jul 30 13:15:58.379318 2026] [security2:error] [pid 872418:tid 872657] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/File.php"] [unique_id "amuU3lymN6QYcoA7XB44PAAAAG0"]
[Thu Jul 30 13:15:58.379486 2026] [security2:error] [pid 872418:tid 872657] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/File.php"] [unique_id "amuU3lymN6QYcoA7XB44PAAAAG0"]
[Thu Jul 30 13:15:58.576884 2026] [security2:error] [pid 872418:tid 872659] [client 168.119.123.75:57782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuU3lymN6QYcoA7XB44PQAAAG8"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:15:58.662073 2026] [security2:error] [pid 872418:tid 872661] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fi22.php"] [unique_id "amuU3lymN6QYcoA7XB44PgAAAHE"]
[Thu Jul 30 13:15:58.662232 2026] [security2:error] [pid 872418:tid 872661] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fi22.php"] [unique_id "amuU3lymN6QYcoA7XB44PgAAAHE"]
[Thu Jul 30 13:15:58.836654 2026] [security2:error] [pid 872418:tid 872656] [client 172.236.9.101:37248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU3lymN6QYcoA7XB44OwAAAGw"]
[Thu Jul 30 13:15:58.923324 2026] [security2:error] [pid 872418:tid 872665] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/zero.php"] [unique_id "amuU3lymN6QYcoA7XB44PwAAAHU"]
[Thu Jul 30 13:15:58.923503 2026] [security2:error] [pid 872418:tid 872665] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/zero.php"] [unique_id "amuU3lymN6QYcoA7XB44PwAAAHU"]
[Thu Jul 30 13:15:59.153409 2026] [core:notice] [pid 872418:tid 872666] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:15:59.158889 2026] [security2:error] [pid 872418:tid 872666] [client 168.119.123.75:57784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuU31ymN6QYcoA7XB44QAAAAHY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:15:59.232034 2026] [security2:error] [pid 872418:tid 872669] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1xmomo.php"] [unique_id "amuU31ymN6QYcoA7XB44QQAAAHk"]
[Thu Jul 30 13:15:59.232189 2026] [security2:error] [pid 872418:tid 872669] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1xmomo.php"] [unique_id "amuU31ymN6QYcoA7XB44QQAAAHk"]
[Thu Jul 30 13:15:59.474618 2026] [security2:error] [pid 872418:tid 872673] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fmws.php"] [unique_id "amuU31ymN6QYcoA7XB44QgAAAH0"]
[Thu Jul 30 13:15:59.474785 2026] [security2:error] [pid 872418:tid 872673] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fmws.php"] [unique_id "amuU31ymN6QYcoA7XB44QgAAAH0"]
[Thu Jul 30 13:15:59.753749 2026] [security2:error] [pid 872418:tid 872548] [client 168.119.123.75:9540] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuU31ymN6QYcoA7XB44RAAAAAA"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:15:59.777707 2026] [security2:error] [pid 872418:tid 872549] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuU31ymN6QYcoA7XB44RQAAAAE"]
[Thu Jul 30 13:15:59.777816 2026] [security2:error] [pid 872418:tid 872549] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuU31ymN6QYcoA7XB44RQAAAAE"]
[Thu Jul 30 13:16:00.016285 2026] [security2:error] [pid 872418:tid 872559] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/hp2.php"] [unique_id "amuU4FymN6QYcoA7XB44SQAAAAs"]
[Thu Jul 30 13:16:00.016424 2026] [security2:error] [pid 872418:tid 872559] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/hp2.php"] [unique_id "amuU4FymN6QYcoA7XB44SQAAAAs"]
[Thu Jul 30 13:16:00.254850 2026] [security2:error] [pid 872418:tid 872562] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aabb.php"] [unique_id "amuU4FymN6QYcoA7XB44SwAAAA4"]
[Thu Jul 30 13:16:00.254995 2026] [security2:error] [pid 872418:tid 872562] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aabb.php"] [unique_id "amuU4FymN6QYcoA7XB44SwAAAA4"]
[Thu Jul 30 13:16:00.695122 2026] [security2:error] [pid 872418:tid 872572] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1254xx.php"] [unique_id "amuU4FymN6QYcoA7XB44UQAAABg"]
[Thu Jul 30 13:16:00.695271 2026] [security2:error] [pid 872418:tid 872572] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1254xx.php"] [unique_id "amuU4FymN6QYcoA7XB44UQAAABg"]
[Thu Jul 30 13:16:00.939966 2026] [security2:error] [pid 872418:tid 872579] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuU4FymN6QYcoA7XB44UwAAAB8"]
[Thu Jul 30 13:16:00.940126 2026] [security2:error] [pid 872418:tid 872579] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuU4FymN6QYcoA7XB44UwAAAB8"]
[Thu Jul 30 13:16:01.199749 2026] [security2:error] [pid 872418:tid 872582] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/pms297.php"] [unique_id "amuU4VymN6QYcoA7XB44VQAAACI"]
[Thu Jul 30 13:16:01.199883 2026] [security2:error] [pid 872418:tid 872582] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/pms297.php"] [unique_id "amuU4VymN6QYcoA7XB44VQAAACI"]
[Thu Jul 30 13:16:01.355856 2026] [core:notice] [pid 872418:tid 872575] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:01.584124 2026] [security2:error] [pid 872418:tid 872585] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuU4VymN6QYcoA7XB44VgAAACU"]
[Thu Jul 30 13:16:01.584257 2026] [security2:error] [pid 872418:tid 872585] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuU4VymN6QYcoA7XB44VgAAACU"]
[Thu Jul 30 13:16:01.886804 2026] [security2:error] [pid 872418:tid 872586] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuU4VymN6QYcoA7XB44VwAAACY"]
[Thu Jul 30 13:16:01.886946 2026] [security2:error] [pid 872418:tid 872586] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuU4VymN6QYcoA7XB44VwAAACY"]
[Thu Jul 30 13:16:01.905043 2026] [security2:error] [pid 872418:tid 872588] [client 3.213.106.226:11628] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/1753/x035dc8977f7c63eb478e51895061e394.jpg.pagespeed.ic.W8vniRMa36.webp"] [unique_id "amuU4VymN6QYcoA7XB44WAAAACg"]
[Thu Jul 30 13:16:02.123031 2026] [security2:error] [pid 872418:tid 872594] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuU4lymN6QYcoA7XB44WwAAAC4"]
[Thu Jul 30 13:16:02.123158 2026] [security2:error] [pid 872418:tid 872594] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuU4lymN6QYcoA7XB44WwAAAC4"]
[Thu Jul 30 13:16:02.373291 2026] [security2:error] [pid 872418:tid 872597] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuU4lymN6QYcoA7XB44XAAAADE"]
[Thu Jul 30 13:16:02.373453 2026] [security2:error] [pid 872418:tid 872597] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuU4lymN6QYcoA7XB44XAAAADE"]
[Thu Jul 30 13:16:02.385641 2026] [core:notice] [pid 872418:tid 872587] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:02.646144 2026] [security2:error] [pid 872418:tid 872599] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dyui.php"] [unique_id "amuU4lymN6QYcoA7XB44XQAAADM"]
[Thu Jul 30 13:16:02.646277 2026] [security2:error] [pid 872418:tid 872599] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dyui.php"] [unique_id "amuU4lymN6QYcoA7XB44XQAAADM"]
[Thu Jul 30 13:16:02.893769 2026] [security2:error] [pid 872418:tid 872605] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ho.php"] [unique_id "amuU4lymN6QYcoA7XB44YgAAADk"]
[Thu Jul 30 13:16:02.893891 2026] [security2:error] [pid 872418:tid 872605] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ho.php"] [unique_id "amuU4lymN6QYcoA7XB44YgAAADk"]
[Thu Jul 30 13:16:03.178272 2026] [security2:error] [pid 872418:tid 872591] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/66b867516c8f01.php"] [unique_id "amuU41ymN6QYcoA7XB44YwAAACs"]
[Thu Jul 30 13:16:03.178449 2026] [security2:error] [pid 872418:tid 872591] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/66b867516c8f01.php"] [unique_id "amuU41ymN6QYcoA7XB44YwAAACs"]
[Thu Jul 30 13:16:03.438624 2026] [security2:error] [pid 872418:tid 872612] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ext.php"] [unique_id "amuU41ymN6QYcoA7XB44ZQAAAEA"]
[Thu Jul 30 13:16:03.438779 2026] [security2:error] [pid 872418:tid 872612] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ext.php"] [unique_id "amuU41ymN6QYcoA7XB44ZQAAAEA"]
[Thu Jul 30 13:16:03.465146 2026] [security2:error] [pid 872418:tid 872603] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuU4lymN6QYcoA7XB44YQAAADc"]
[Thu Jul 30 13:16:03.676138 2026] [security2:error] [pid 872418:tid 872620] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuU41ymN6QYcoA7XB44agAAAEg"]
[Thu Jul 30 13:16:03.676263 2026] [security2:error] [pid 872418:tid 872620] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuU41ymN6QYcoA7XB44agAAAEg"]
[Thu Jul 30 13:16:03.922885 2026] [security2:error] [pid 872418:tid 872627] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuU41ymN6QYcoA7XB44awAAAE8"]
[Thu Jul 30 13:16:03.923038 2026] [security2:error] [pid 872418:tid 872627] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuU41ymN6QYcoA7XB44awAAAE8"]
[Thu Jul 30 13:16:04.181754 2026] [security2:error] [pid 872418:tid 872625] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/584062352875874akp.php"] [unique_id "amuU5FymN6QYcoA7XB44bwAAAE0"]
[Thu Jul 30 13:16:04.181895 2026] [security2:error] [pid 872418:tid 872625] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/584062352875874akp.php"] [unique_id "amuU5FymN6QYcoA7XB44bwAAAE0"]
[Thu Jul 30 13:16:04.297691 2026] [security2:error] [pid 872418:tid 872430] [remote 152.53.211.182:57770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.211.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuU5FymN6QYcoA7XB44bAAAOws"]
[Thu Jul 30 13:16:04.451331 2026] [security2:error] [pid 872418:tid 872634] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/diidi.php"] [unique_id "amuU5FymN6QYcoA7XB44cAAAAFY"]
[Thu Jul 30 13:16:04.451526 2026] [security2:error] [pid 872418:tid 872634] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/diidi.php"] [unique_id "amuU5FymN6QYcoA7XB44cAAAAFY"]
[Thu Jul 30 13:16:04.525324 2026] [security2:error] [pid 872418:tid 872433] [remote 65.181.116.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saiqon.net"] [uri "/wp-login.php"] [unique_id "amuU5FymN6QYcoA7XB44cgAAVA4"]
[Thu Jul 30 13:16:04.700064 2026] [security2:error] [pid 872418:tid 872613] [client 20.203.205.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.205.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/clarebypas.php"] [unique_id "amuU5FymN6QYcoA7XB44cwAAAEE"]
[Thu Jul 30 13:16:04.700232 2026] [security2:error] [pid 872418:tid 872613] [client 20.203.205.96:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/clarebypas.php"] [unique_id "amuU5FymN6QYcoA7XB44cwAAAEE"]
[Thu Jul 30 13:16:04.838027 2026] [security2:error] [pid 872418:tid 872434] [remote 192.250.235.218:39838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.235.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-login.php"] [unique_id "amuU5FymN6QYcoA7XB44dAAAWg8"]
[Thu Jul 30 13:16:06.464113 2026] [proxy:error] [pid 872418:tid 872661] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:06.464204 2026] [proxy_http:error] [pid 872418:tid 872661] [client 3.225.222.228:61568] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:06.464798 2026] [proxy:error] [pid 872418:tid 872661] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:06.464840 2026] [proxy_http:error] [pid 872418:tid 872661] [client 3.225.222.228:61568] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:06.600422 2026] [security2:error] [pid 872418:tid 872658] [client 85.208.96.196:48178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/11/11/remedio-experimental-da-pfizer-contra-covid-19-sera-testado-no-brasil/"] [unique_id "amuU5lymN6QYcoA7XB44eQAAAG4"]
[Thu Jul 30 13:16:06.600613 2026] [security2:error] [pid 872418:tid 872658] [client 85.208.96.196:48178] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/11/11/remedio-experimental-da-pfizer-contra-covid-19-sera-testado-no-brasil/"] [unique_id "amuU5lymN6QYcoA7XB44eQAAAG4"]
[Thu Jul 30 13:16:07.047760 2026] [security2:error] [pid 872418:tid 872667] [client 213.152.161.85:46990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuU51ymN6QYcoA7XB44egAAAHc"]
[Thu Jul 30 13:16:07.047906 2026] [security2:error] [pid 872418:tid 872667] [client 213.152.161.85:46990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuU51ymN6QYcoA7XB44egAAAHc"]
[Thu Jul 30 13:16:07.152173 2026] [core:notice] [pid 872418:tid 872665] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:07.304752 2026] [security2:error] [pid 872418:tid 872664] [client 179.64.21.229:38564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU51ymN6QYcoA7XB44fAAAAHQ"]
[Thu Jul 30 13:16:07.314331 2026] [security2:error] [pid 872418:tid 872664] [client 179.64.21.229:38564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU51ymN6QYcoA7XB44fAAAAHQ"]
[Thu Jul 30 13:16:07.800702 2026] [security2:error] [pid 872418:tid 872438] [remote 216.73.217.142:21657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuU51ymN6QYcoA7XB44gQAABBM"]
[Thu Jul 30 13:16:07.835192 2026] [core:notice] [pid 872418:tid 872675] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:08.499552 2026] [core:notice] [pid 872418:tid 872558] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:08.929605 2026] [core:notice] [pid 872418:tid 872562] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:09.747710 2026] [security2:error] [pid 872418:tid 872566] [client 172.236.9.101:27067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU6VymN6QYcoA7XB44iQAAABI"]
[Thu Jul 30 13:16:09.828180 2026] [core:notice] [pid 872418:tid 872578] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:10.660216 2026] [core:notice] [pid 872418:tid 872593] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:10.834160 2026] [security2:error] [pid 872418:tid 872585] [client 172.236.9.101:25941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU6lymN6QYcoA7XB44kwAAACU"]
[Thu Jul 30 13:16:11.015958 2026] [security2:error] [pid 872418:tid 872442] [remote 57.141.0.68:35264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuU61ymN6QYcoA7XB44mQAALhc"]
[Thu Jul 30 13:16:11.406650 2026] [core:notice] [pid 872418:tid 872612] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:11.881570 2026] [security2:error] [pid 872418:tid 872608] [client 172.236.9.101:26099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU61ymN6QYcoA7XB44mwAAADw"]
[Thu Jul 30 13:16:12.077563 2026] [core:notice] [pid 872418:tid 872616] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:12.630064 2026] [security2:error] [pid 872418:tid 872621] [client 78.40.199.55:54920] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "78.40.199.55" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "kool-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuU7FymN6QYcoA7XB44oQAAAEk"], referer: http://kool-shop.com/hello-world/
[Thu Jul 30 13:16:12.630199 2026] [security2:error] [pid 872418:tid 872621] [client 78.40.199.55:54920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "kool-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuU7FymN6QYcoA7XB44oQAAAEk"], referer: http://kool-shop.com/hello-world/
[Thu Jul 30 13:16:12.946335 2026] [core:notice] [pid 872418:tid 872626] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:13.135854 2026] [security2:error] [pid 872418:tid 872631] [client 185.200.116.219:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuU7VymN6QYcoA7XB44pAAAAFM"]
[Thu Jul 30 13:16:13.135999 2026] [security2:error] [pid 872418:tid 872631] [client 185.200.116.219:53688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuU7VymN6QYcoA7XB44pAAAAFM"]
[Thu Jul 30 13:16:13.817354 2026] [core:notice] [pid 872418:tid 872636] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:14.288600 2026] [proxy:error] [pid 872418:tid 872638] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:14.288707 2026] [proxy_http:error] [pid 872418:tid 872638] [client 98.87.102.177:46778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:14.289489 2026] [proxy:error] [pid 872418:tid 872638] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:14.289540 2026] [proxy_http:error] [pid 872418:tid 872638] [client 98.87.102.177:46778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:14.389921 2026] [core:notice] [pid 872418:tid 872450] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:14.566133 2026] [core:notice] [pid 872418:tid 872451] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:14.679328 2026] [core:notice] [pid 872418:tid 872655] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:14.840206 2026] [security2:error] [pid 872418:tid 872641] [client 172.236.9.101:30965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU7lymN6QYcoA7XB44qgAAAF0"]
[Thu Jul 30 13:16:14.864259 2026] [proxy:error] [pid 872418:tid 872663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:14.864347 2026] [proxy_http:error] [pid 872418:tid 872663] [client 44.216.125.112:32368] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:14.865067 2026] [proxy:error] [pid 872418:tid 872663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:14.865116 2026] [proxy_http:error] [pid 872418:tid 872663] [client 44.216.125.112:32368] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:14.870172 2026] [proxy:error] [pid 872418:tid 872660] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:14.870258 2026] [proxy_http:error] [pid 872418:tid 872660] [client 98.87.102.177:13474] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:14.871226 2026] [proxy:error] [pid 872418:tid 872660] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:14.871285 2026] [proxy_http:error] [pid 872418:tid 872660] [client 98.87.102.177:13474] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:14.889703 2026] [autoindex:error] [pid 872418:tid 872666] [client 44.216.125.112:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:16:14.912889 2026] [autoindex:error] [pid 872418:tid 872549] [client 44.216.125.112:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:16:15.535570 2026] [core:notice] [pid 872418:tid 872560] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:15.873055 2026] [autoindex:error] [pid 872418:tid 872576] [client 205.169.39.192:17653] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:16:16.383216 2026] [core:notice] [pid 872418:tid 872606] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:16.384212 2026] [security2:error] [pid 872418:tid 872586] [client 50.6.43.217:59678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuU8FymN6QYcoA7XB441AAAACY"]
[Thu Jul 30 13:16:16.521343 2026] [security2:error] [pid 872418:tid 872612] [client 50.6.43.217:59682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuU8FymN6QYcoA7XB442QAAAEA"]
[Thu Jul 30 13:16:16.885464 2026] [security2:error] [pid 872418:tid 872589] [client 172.236.9.101:35132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU8FymN6QYcoA7XB442gAAACk"]
[Thu Jul 30 13:16:17.786938 2026] [security2:error] [pid 872418:tid 872613] [client 179.64.21.229:43974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU8VymN6QYcoA7XB45CgAAAEE"]
[Thu Jul 30 13:16:17.787135 2026] [security2:error] [pid 872418:tid 872613] [client 179.64.21.229:43974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU8VymN6QYcoA7XB45CgAAAEE"]
[Thu Jul 30 13:16:17.806064 2026] [security2:error] [pid 872418:tid 872496] [remote 216.73.217.142:57024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuU8VymN6QYcoA7XB45CwAAa00"]
[Thu Jul 30 13:16:17.911308 2026] [core:notice] [pid 872418:tid 872635] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:17.916366 2026] [security2:error] [pid 872418:tid 872635] [client 66.249.79.8:60056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/$$$call$$$/page/page/css"] [unique_id "amuU8VymN6QYcoA7XB45CAAAAFc"], referer: https://www.ejournalugj.com/
[Thu Jul 30 13:16:18.518463 2026] [core:notice] [pid 872418:tid 872656] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:19.855734 2026] [core:notice] [pid 872418:tid 872552] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:20.081879 2026] [security2:error] [pid 872418:tid 872675] [client 172.237.109.114:63724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/key.pem"] [unique_id "amuU9FymN6QYcoA7XB45FAAAAH8"]
[Thu Jul 30 13:16:20.093848 2026] [security2:error] [pid 872418:tid 872554] [client 172.237.109.114:42205] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_dsa"] [unique_id "amuU9FymN6QYcoA7XB45GAAAAAY"]
[Thu Jul 30 13:16:20.094113 2026] [security2:error] [pid 872418:tid 872558] [client 172.237.109.114:61211] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_rsa"] [unique_id "amuU9FymN6QYcoA7XB45GQAAAAo"]
[Thu Jul 30 13:16:20.103781 2026] [security2:error] [pid 872418:tid 872639] [client 172.237.109.114:51991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/.ssh/id_dsa"] [unique_id "amuU9FymN6QYcoA7XB45HAAAAFs"]
[Thu Jul 30 13:16:20.127041 2026] [security2:error] [pid 872418:tid 872670] [client 172.237.109.114:42361] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/privatekey.key"] [unique_id "amuU9FymN6QYcoA7XB45IAAAAHo"]
[Thu Jul 30 13:16:20.152197 2026] [security2:error] [pid 872418:tid 872572] [client 172.237.109.114:2183] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/id_rsa"] [unique_id "amuU9FymN6QYcoA7XB45JAAAABg"]
[Thu Jul 30 13:16:21.337487 2026] [security2:error] [pid 872418:tid 872671] [client 172.237.109.114:24052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45EwAAAHs"]
[Thu Jul 30 13:16:21.401478 2026] [security2:error] [pid 872418:tid 872560] [client 172.237.109.114:17879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45IQAAAAw"]
[Thu Jul 30 13:16:21.409660 2026] [security2:error] [pid 872418:tid 872555] [client 172.237.109.114:18253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45FgAAAAc"]
[Thu Jul 30 13:16:21.426356 2026] [security2:error] [pid 872418:tid 872550] [client 172.237.109.114:37394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45FwAAAAI"]
[Thu Jul 30 13:16:21.428044 2026] [security2:error] [pid 872418:tid 872557] [client 172.237.109.114:16807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45FQAAAAk"]
[Thu Jul 30 13:16:21.429137 2026] [security2:error] [pid 872418:tid 872559] [client 172.237.109.114:41289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45GwAAAAs"]
[Thu Jul 30 13:16:21.433463 2026] [security2:error] [pid 872418:tid 872562] [client 172.237.109.114:7071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45HQAAAA4"]
[Thu Jul 30 13:16:21.434597 2026] [security2:error] [pid 872418:tid 872561] [client 172.237.109.114:44788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45GgAAAA0"]
[Thu Jul 30 13:16:21.444092 2026] [security2:error] [pid 872418:tid 872664] [client 172.237.109.114:53976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45HgAAAHQ"]
[Thu Jul 30 13:16:21.446609 2026] [security2:error] [pid 872418:tid 872556] [client 172.237.109.114:64089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45JQAAAAg"]
[Thu Jul 30 13:16:21.458257 2026] [security2:error] [pid 872418:tid 872674] [client 172.237.109.114:42328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45HwAAAH4"]
[Thu Jul 30 13:16:21.462212 2026] [security2:error] [pid 872418:tid 872571] [client 172.237.109.114:1829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45IgAAABc"]
[Thu Jul 30 13:16:21.485041 2026] [security2:error] [pid 872418:tid 872563] [client 172.237.109.114:33061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45IwAAAA8"]
[Thu Jul 30 13:16:21.494892 2026] [security2:error] [pid 872418:tid 872570] [client 172.237.109.114:6795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45JgAAABY"]
[Thu Jul 30 13:16:21.551958 2026] [core:notice] [pid 872418:tid 872599] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:21.569725 2026] [security2:error] [pid 872418:tid 872576] [client 172.236.9.101:13029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuU9FymN6QYcoA7XB45JwAAABw"]
[Thu Jul 30 13:16:21.663756 2026] [core:notice] [pid 872418:tid 872502] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:21.737370 2026] [security2:error] [pid 872418:tid 872595] [client 34.231.77.232:11244] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/03/consumo-mercado-20150930-14-original-400x267.jpg"] [unique_id "amuU9VymN6QYcoA7XB45MgAAAC8"]
[Thu Jul 30 13:16:22.290693 2026] [core:notice] [pid 872418:tid 872626] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:23.457989 2026] [security2:error] [pid 872418:tid 872504] [remote 216.73.217.142:15900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuU91ymN6QYcoA7XB45NwAAVFU"]
[Thu Jul 30 13:16:23.966953 2026] [core:notice] [pid 872418:tid 872620] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:24.688235 2026] [core:notice] [pid 872418:tid 872646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:25.249367 2026] [security2:error] [pid 872418:tid 872654] [client 213.32.68.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuU-VymN6QYcoA7XB45PgAAAGo"]
[Thu Jul 30 13:16:25.729798 2026] [security2:error] [pid 872418:tid 872663] [client 143.244.57.92:49608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuU-VymN6QYcoA7XB45RAAAAHM"]
[Thu Jul 30 13:16:26.023243 2026] [security2:error] [pid 872418:tid 872666] [client 143.244.57.92:49624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jvc.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuU-lymN6QYcoA7XB45RQAAAHY"]
[Thu Jul 30 13:16:26.296675 2026] [security2:error] [pid 872418:tid 872668] [client 143.244.57.92:49640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuU-lymN6QYcoA7XB45RgAAAHg"]
[Thu Jul 30 13:16:26.568972 2026] [security2:error] [pid 872418:tid 872551] [client 143.244.57.92:49648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuU-lymN6QYcoA7XB45UgAAAAM"]
[Thu Jul 30 13:16:26.569323 2026] [core:notice] [pid 872418:tid 872553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:26.858209 2026] [security2:error] [pid 872418:tid 872639] [client 143.244.57.92:49658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuU-lymN6QYcoA7XB45UwAAAFs"]
[Thu Jul 30 13:16:27.132197 2026] [security2:error] [pid 872418:tid 872661] [client 143.244.57.92:49664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuU-1ymN6QYcoA7XB45VAAAAHE"]
[Thu Jul 30 13:16:27.405345 2026] [security2:error] [pid 872418:tid 872550] [client 143.244.57.92:49672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuU-1ymN6QYcoA7XB45WwAAAAI"]
[Thu Jul 30 13:16:27.685742 2026] [security2:error] [pid 872418:tid 872674] [client 143.244.57.92:49682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuU-1ymN6QYcoA7XB45YAAAAH4"]
[Thu Jul 30 13:16:27.811150 2026] [security2:error] [pid 872418:tid 872531] [remote 216.73.217.142:15900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuU-1ymN6QYcoA7XB45ZQAAJHA"]
[Thu Jul 30 13:16:27.975106 2026] [security2:error] [pid 872418:tid 872593] [client 143.244.57.92:49696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuU-1ymN6QYcoA7XB45ZgAAAC0"]
[Thu Jul 30 13:16:28.011431 2026] [security2:error] [pid 872418:tid 872563] [client 179.64.21.229:49545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU_FymN6QYcoA7XB45ZwAAAA8"]
[Thu Jul 30 13:16:28.015061 2026] [security2:error] [pid 872418:tid 872563] [client 179.64.21.229:49545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuU_FymN6QYcoA7XB45ZwAAAA8"]
[Thu Jul 30 13:16:28.081101 2026] [ssl:error] [pid 872418:tid 872532] [remote 46.178.228.37:42331] AH02032: Hostname womenclothingbox.com provided via SNI and hostname carnetdeshopping.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Thu Jul 30 13:16:28.254799 2026] [security2:error] [pid 872418:tid 872611] [client 143.244.57.92:49710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuU_FymN6QYcoA7XB45bQAAAD8"]
[Thu Jul 30 13:16:28.529553 2026] [security2:error] [pid 872418:tid 872590] [client 143.244.57.92:49720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuU_FymN6QYcoA7XB45bgAAACo"]
[Thu Jul 30 13:16:28.802954 2026] [security2:error] [pid 872418:tid 872618] [client 143.244.57.92:49722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuU_FymN6QYcoA7XB45cQAAAEY"]
[Thu Jul 30 13:16:28.859461 2026] [core:notice] [pid 872418:tid 872537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:28.934106 2026] [security2:error] [pid 872418:tid 872595] [client 134.19.179.147:58730] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuU_FymN6QYcoA7XB45dAAAAC8"]
[Thu Jul 30 13:16:28.934275 2026] [security2:error] [pid 872418:tid 872595] [client 134.19.179.147:58730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuU_FymN6QYcoA7XB45dAAAAC8"]
[Thu Jul 30 13:16:29.029466 2026] [security2:error] [pid 872418:tid 872621] [client 154.159.252.63:14791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuU_FymN6QYcoA7XB45dQAASXc"], referer: https://rocket-bookkeepers.com/node/3
[Thu Jul 30 13:16:29.047311 2026] [security2:error] [pid 872418:tid 872621] [client 154.159.252.63:14791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuU_FymN6QYcoA7XB45dgAASXg"], referer: https://rocket-bookkeepers.com/node/3
[Thu Jul 30 13:16:29.054650 2026] [security2:error] [pid 872418:tid 872621] [client 154.159.252.63:14791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuU_FymN6QYcoA7XB45eAAASXo"], referer: https://rocket-bookkeepers.com/node/3
[Thu Jul 30 13:16:29.054838 2026] [security2:error] [pid 872418:tid 872621] [client 154.159.252.63:14791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuU_FymN6QYcoA7XB45eQAASXs"], referer: https://rocket-bookkeepers.com/node/3
[Thu Jul 30 13:16:29.054940 2026] [security2:error] [pid 872418:tid 872621] [client 154.159.252.63:14791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuU_FymN6QYcoA7XB45egAASXw"], referer: https://rocket-bookkeepers.com/node/3
[Thu Jul 30 13:16:29.055024 2026] [security2:error] [pid 872418:tid 872621] [client 154.159.252.63:14791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuU_FymN6QYcoA7XB45ewAASX0"], referer: https://rocket-bookkeepers.com/node/3
[Thu Jul 30 13:16:29.059513 2026] [security2:error] [pid 872418:tid 872621] [client 154.159.252.63:14791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuU_FymN6QYcoA7XB45dwAASXk"], referer: https://rocket-bookkeepers.com/node/3
[Thu Jul 30 13:16:29.063142 2026] [security2:error] [pid 872418:tid 872621] [client 154.159.252.63:14791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuU_FymN6QYcoA7XB45fAAASX4"], referer: https://rocket-bookkeepers.com/node/3
[Thu Jul 30 13:16:29.094094 2026] [security2:error] [pid 872418:tid 872615] [client 143.244.57.92:49734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jvc.nyx.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuU_VymN6QYcoA7XB45fQAAAEM"]
[Thu Jul 30 13:16:29.367876 2026] [security2:error] [pid 872418:tid 872625] [client 141.94.79.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuU_VymN6QYcoA7XB45gAAAAE0"]
[Thu Jul 30 13:16:29.720046 2026] [security2:error] [pid 872418:tid 872607] [client 141.94.95.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuU_VymN6QYcoA7XB45hAAAADs"]
[Thu Jul 30 13:16:29.759659 2026] [core:notice] [pid 872418:tid 872605] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:30.140554 2026] [security2:error] [pid 872418:tid 872653] [client 51.77.211.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuU_VymN6QYcoA7XB45kAAAAGk"]
[Thu Jul 30 13:16:31.374005 2026] [ssl:error] [pid 872418:tid 872427] [remote 46.178.228.37:42255] AH02032: Hostname carnetdeshopping.com provided via SNI and hostname womenclothingbox.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Thu Jul 30 13:16:31.473922 2026] [proxy:error] [pid 872418:tid 872672] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:31.474021 2026] [proxy_http:error] [pid 872418:tid 872672] [client 98.87.102.177:40565] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:31.474677 2026] [proxy:error] [pid 872418:tid 872672] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:31.474728 2026] [proxy_http:error] [pid 872418:tid 872672] [client 98.87.102.177:40565] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:31.474907 2026] [proxy:error] [pid 872418:tid 872551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:31.475003 2026] [proxy_http:error] [pid 872418:tid 872551] [client 98.87.102.177:39795] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:31.475647 2026] [proxy:error] [pid 872418:tid 872551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:31.475696 2026] [proxy_http:error] [pid 872418:tid 872551] [client 98.87.102.177:39795] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:32.301660 2026] [core:notice] [pid 872418:tid 872429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:33.367536 2026] [core:notice] [pid 872418:tid 872433] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:33.528061 2026] [core:notice] [pid 872418:tid 872434] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:33.648865 2026] [core:notice] [pid 872418:tid 872435] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:33.709894 2026] [core:notice] [pid 872418:tid 872436] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:33.771124 2026] [core:notice] [pid 872418:tid 872438] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:34.490956 2026] [core:notice] [pid 872418:tid 872440] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:34.496380 2026] [security2:error] [pid 872418:tid 872617] [client 47.128.96.143:61102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/2708"] [unique_id "amuVAlymN6QYcoA7XB45tgAARRU"]
[Thu Jul 30 13:16:34.941731 2026] [security2:error] [pid 872418:tid 872618] [client 172.236.9.101:35636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVAlymN6QYcoA7XB45twAAAEY"]
[Thu Jul 30 13:16:34.982719 2026] [core:notice] [pid 872418:tid 872443] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:35.092734 2026] [core:notice] [pid 872418:tid 872444] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:35.092742 2026] [core:notice] [pid 872418:tid 872446] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:35.276962 2026] [core:notice] [pid 872418:tid 872629] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:16:36.222432 2026] [security2:error] [pid 872418:tid 872451] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/cong.php"] [unique_id "amuVBFymN6QYcoA7XB45zAAAdiA"]
[Thu Jul 30 13:16:36.761189 2026] [security2:error] [pid 872418:tid 872627] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVBFymN6QYcoA7XB45ywAATx8"]
[Thu Jul 30 13:16:37.813966 2026] [security2:error] [pid 872418:tid 872505] [remote 216.73.217.142:2034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuVBVymN6QYcoA7XB46DwAADVY"]
[Thu Jul 30 13:16:38.629097 2026] [security2:error] [pid 872418:tid 872611] [client 179.64.21.229:6518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVBlymN6QYcoA7XB46FQAAAD8"]
[Thu Jul 30 13:16:38.644898 2026] [security2:error] [pid 872418:tid 872611] [client 179.64.21.229:6518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVBlymN6QYcoA7XB46FQAAAD8"]
[Thu Jul 30 13:16:39.758737 2026] [security2:error] [pid 872418:tid 872609] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVB1ymN6QYcoA7XB46GgAAPVw"]
[Thu Jul 30 13:16:42.195905 2026] [security2:error] [pid 872418:tid 872657] [client 87.250.224.102:54824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuVCVymN6QYcoA7XB46MAAAAG0"]
[Thu Jul 30 13:16:43.267700 2026] [security2:error] [pid 872418:tid 872529] [remote 216.73.217.142:42814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVC1ymN6QYcoA7XB46OAAAY24"]
[Thu Jul 30 13:16:47.220756 2026] [proxy:error] [pid 872418:tid 872614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:47.220853 2026] [proxy_http:error] [pid 872418:tid 872614] [client 98.87.102.177:6477] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:47.221476 2026] [proxy:error] [pid 872418:tid 872614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:47.221525 2026] [proxy_http:error] [pid 872418:tid 872614] [client 98.87.102.177:6477] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:47.223298 2026] [proxy:error] [pid 872418:tid 872603] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:47.223351 2026] [proxy_http:error] [pid 872418:tid 872603] [client 98.87.102.177:42100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:47.223918 2026] [proxy:error] [pid 872418:tid 872603] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:16:47.223963 2026] [proxy_http:error] [pid 872418:tid 872603] [client 98.87.102.177:42100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:16:47.368295 2026] [security2:error] [pid 872418:tid 872594] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVDlymN6QYcoA7XB46VQAALgM"]
[Thu Jul 30 13:16:48.447122 2026] [security2:error] [pid 872418:tid 872665] [client 154.159.252.63:57981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuVEFymN6QYcoA7XB46dAAAdRA"], referer: https://rocket-bookkeepers.com/node/3
[Thu Jul 30 13:16:49.097891 2026] [security2:error] [pid 872418:tid 872672] [client 179.64.21.229:42665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVEVymN6QYcoA7XB46gAAAAHw"]
[Thu Jul 30 13:16:49.098094 2026] [security2:error] [pid 872418:tid 872672] [client 179.64.21.229:42665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVEVymN6QYcoA7XB46gAAAAHw"]
[Thu Jul 30 13:16:50.407150 2026] [security2:error] [pid 872418:tid 872648] [client 82.102.27.195:50232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuVElymN6QYcoA7XB46iAAAAGQ"]
[Thu Jul 30 13:16:50.407299 2026] [security2:error] [pid 872418:tid 872648] [client 82.102.27.195:50232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuVElymN6QYcoA7XB46iAAAAGQ"]
[Thu Jul 30 13:16:50.935339 2026] [security2:error] [pid 872418:tid 872550] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVElymN6QYcoA7XB46igAAAAI"]
[Thu Jul 30 13:16:50.935503 2026] [security2:error] [pid 872418:tid 872550] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVElymN6QYcoA7XB46igAAAAI"]
[Thu Jul 30 13:16:51.235925 2026] [security2:error] [pid 872418:tid 872561] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVE1ymN6QYcoA7XB46jgAAAA0"]
[Thu Jul 30 13:16:51.236073 2026] [security2:error] [pid 872418:tid 872561] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVE1ymN6QYcoA7XB46jgAAAA0"]
[Thu Jul 30 13:16:51.548765 2026] [security2:error] [pid 872418:tid 872557] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVElymN6QYcoA7XB46jQAAAAk"]
[Thu Jul 30 13:16:51.553104 2026] [security2:error] [pid 872418:tid 872600] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/xstelth.php"] [unique_id "amuVE1ymN6QYcoA7XB46kAAAADQ"]
[Thu Jul 30 13:16:51.553197 2026] [security2:error] [pid 872418:tid 872600] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/xstelth.php"] [unique_id "amuVE1ymN6QYcoA7XB46kAAAADQ"]
[Thu Jul 30 13:16:51.871874 2026] [security2:error] [pid 872418:tid 872674] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuVE1ymN6QYcoA7XB46kQAAAH4"]
[Thu Jul 30 13:16:51.872040 2026] [security2:error] [pid 872418:tid 872674] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuVE1ymN6QYcoA7XB46kQAAAH4"]
[Thu Jul 30 13:16:52.675434 2026] [security2:error] [pid 872418:tid 872603] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/newfile.php"] [unique_id "amuVFFymN6QYcoA7XB46lwAAADc"]
[Thu Jul 30 13:16:52.675583 2026] [security2:error] [pid 872418:tid 872603] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/newfile.php"] [unique_id "amuVFFymN6QYcoA7XB46lwAAADc"]
[Thu Jul 30 13:16:52.975321 2026] [security2:error] [pid 872418:tid 872604] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/tBEZGQz.php"] [unique_id "amuVFFymN6QYcoA7XB46mQAAADg"]
[Thu Jul 30 13:16:52.975444 2026] [security2:error] [pid 872418:tid 872604] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/tBEZGQz.php"] [unique_id "amuVFFymN6QYcoA7XB46mQAAADg"]
[Thu Jul 30 13:16:54.219905 2026] [security2:error] [pid 872418:tid 872642] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_webmail/phpinfo"] [unique_id "amuVFlymN6QYcoA7XB46nQAAAF4"]
[Thu Jul 30 13:16:54.523951 2026] [security2:error] [pid 872418:tid 872619] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/drykl.php"] [unique_id "amuVFlymN6QYcoA7XB46nwAAAEc"]
[Thu Jul 30 13:16:54.524117 2026] [security2:error] [pid 872418:tid 872619] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/drykl.php"] [unique_id "amuVFlymN6QYcoA7XB46nwAAAEc"]
[Thu Jul 30 13:16:54.863180 2026] [security2:error] [pid 872418:tid 872623] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/blue/"] [unique_id "amuVFlymN6QYcoA7XB46oAAAAEs"]
[Thu Jul 30 13:16:55.034354 2026] [security2:error] [pid 872418:tid 872589] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ls.php"] [unique_id "amuVF1ymN6QYcoA7XB46oQAAACk"]
[Thu Jul 30 13:16:55.034502 2026] [security2:error] [pid 872418:tid 872589] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ls.php"] [unique_id "amuVF1ymN6QYcoA7XB46oQAAACk"]
[Thu Jul 30 13:16:55.348283 2026] [security2:error] [pid 872418:tid 872598] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/dx.php"] [unique_id "amuVF1ymN6QYcoA7XB46ogAAADI"]
[Thu Jul 30 13:16:55.348411 2026] [security2:error] [pid 872418:tid 872598] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/dx.php"] [unique_id "amuVF1ymN6QYcoA7XB46ogAAADI"]
[Thu Jul 30 13:16:55.652590 2026] [security2:error] [pid 872418:tid 872630] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuVF1ymN6QYcoA7XB46owAAAFI"]
[Thu Jul 30 13:16:55.652746 2026] [security2:error] [pid 872418:tid 872630] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuVF1ymN6QYcoA7XB46owAAAFI"]
[Thu Jul 30 13:16:56.265627 2026] [security2:error] [pid 872418:tid 872646] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/485.php"] [unique_id "amuVGFymN6QYcoA7XB46pAAAAGI"]
[Thu Jul 30 13:16:56.265778 2026] [security2:error] [pid 872418:tid 872646] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/485.php"] [unique_id "amuVGFymN6QYcoA7XB46pAAAAGI"]
[Thu Jul 30 13:16:56.565061 2026] [security2:error] [pid 872418:tid 872620] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gelio1.php"] [unique_id "amuVGFymN6QYcoA7XB46pgAAAEg"]
[Thu Jul 30 13:16:56.565189 2026] [security2:error] [pid 872418:tid 872620] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gelio1.php"] [unique_id "amuVGFymN6QYcoA7XB46pgAAAEg"]
[Thu Jul 30 13:16:56.888935 2026] [security2:error] [pid 872418:tid 872665] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/lp6.php"] [unique_id "amuVGFymN6QYcoA7XB46qgAAAHU"]
[Thu Jul 30 13:16:56.889088 2026] [security2:error] [pid 872418:tid 872665] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/lp6.php"] [unique_id "amuVGFymN6QYcoA7XB46qgAAAHU"]
[Thu Jul 30 13:16:57.223240 2026] [security2:error] [pid 872418:tid 872651] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuVGVymN6QYcoA7XB46qwAAAGc"]
[Thu Jul 30 13:16:57.223388 2026] [security2:error] [pid 872418:tid 872651] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuVGVymN6QYcoA7XB46qwAAAGc"]
[Thu Jul 30 13:16:57.588751 2026] [security2:error] [pid 872418:tid 872660] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_webmail/wp-includes/sodium_compat/"] [unique_id "amuVGVymN6QYcoA7XB46rAAAAHA"]
[Thu Jul 30 13:16:57.621665 2026] [security2:error] [pid 872418:tid 872650] [client 194.187.251.163:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuVGVymN6QYcoA7XB46rQAAAGY"]
[Thu Jul 30 13:16:57.621779 2026] [security2:error] [pid 872418:tid 872650] [client 194.187.251.163:55256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuVGVymN6QYcoA7XB46rQAAAGY"]
[Thu Jul 30 13:16:57.805681 2026] [security2:error] [pid 872418:tid 872549] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuVGVymN6QYcoA7XB46rwAAAAE"]
[Thu Jul 30 13:16:57.805807 2026] [security2:error] [pid 872418:tid 872549] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuVGVymN6QYcoA7XB46rwAAAAE"]
[Thu Jul 30 13:16:58.113786 2026] [security2:error] [pid 872418:tid 872666] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuVGlymN6QYcoA7XB46tAAAAHY"]
[Thu Jul 30 13:16:58.113899 2026] [security2:error] [pid 872418:tid 872666] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuVGlymN6QYcoA7XB46tAAAAHY"]
[Thu Jul 30 13:16:58.413415 2026] [security2:error] [pid 872418:tid 872657] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/autoload_classmap.php"] [unique_id "amuVGlymN6QYcoA7XB46tQAAAG0"]
[Thu Jul 30 13:16:58.413558 2026] [security2:error] [pid 872418:tid 872657] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/autoload_classmap.php"] [unique_id "amuVGlymN6QYcoA7XB46tQAAAG0"]
[Thu Jul 30 13:16:58.770887 2026] [security2:error] [pid 872418:tid 872572] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_webmail/wp-content/"] [unique_id "amuVGlymN6QYcoA7XB46tgAAABg"]
[Thu Jul 30 13:16:58.947008 2026] [security2:error] [pid 872418:tid 872618] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuVGlymN6QYcoA7XB46twAAAEY"]
[Thu Jul 30 13:16:58.947124 2026] [security2:error] [pid 872418:tid 872618] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuVGlymN6QYcoA7XB46twAAAEY"]
[Thu Jul 30 13:16:59.290660 2026] [security2:error] [pid 872418:tid 872661] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/av.php"] [unique_id "amuVG1ymN6QYcoA7XB46uwAAAHE"]
[Thu Jul 30 13:16:59.290811 2026] [security2:error] [pid 872418:tid 872661] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/av.php"] [unique_id "amuVG1ymN6QYcoA7XB46uwAAAHE"]
[Thu Jul 30 13:16:59.669054 2026] [security2:error] [pid 872418:tid 872552] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_webmail/wp-includes/l10n/"] [unique_id "amuVG1ymN6QYcoA7XB46vAAAAAQ"]
[Thu Jul 30 13:16:59.872908 2026] [security2:error] [pid 872418:tid 872579] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_webmail/wordpress/wp-admin/maint/"] [unique_id "amuVG1ymN6QYcoA7XB46vQAAAB8"]
[Thu Jul 30 13:16:59.874536 2026] [security2:error] [pid 872418:tid 872577] [client 179.64.21.229:1188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVG1ymN6QYcoA7XB46vgAAAB0"]
[Thu Jul 30 13:16:59.874669 2026] [security2:error] [pid 872418:tid 872577] [client 179.64.21.229:1188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVG1ymN6QYcoA7XB46vgAAAB0"]
[Thu Jul 30 13:17:00.039356 2026] [security2:error] [pid 872418:tid 872567] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/tiny.php"] [unique_id "amuVHFymN6QYcoA7XB46vwAAABM"]
[Thu Jul 30 13:17:00.039490 2026] [security2:error] [pid 872418:tid 872567] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/tiny.php"] [unique_id "amuVHFymN6QYcoA7XB46vwAAABM"]
[Thu Jul 30 13:17:00.351029 2026] [security2:error] [pid 872418:tid 872548] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuVHFymN6QYcoA7XB46wQAAAAA"]
[Thu Jul 30 13:17:00.351133 2026] [security2:error] [pid 872418:tid 872548] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuVHFymN6QYcoA7XB46wQAAAAA"]
[Thu Jul 30 13:17:00.666843 2026] [security2:error] [pid 872418:tid 872580] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/zrrhj.php"] [unique_id "amuVHFymN6QYcoA7XB46xQAAACA"]
[Thu Jul 30 13:17:00.667037 2026] [security2:error] [pid 872418:tid 872580] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/zrrhj.php"] [unique_id "amuVHFymN6QYcoA7XB46xQAAACA"]
[Thu Jul 30 13:17:00.982345 2026] [security2:error] [pid 872418:tid 872560] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuVHFymN6QYcoA7XB46xgAAAAw"]
[Thu Jul 30 13:17:00.982470 2026] [security2:error] [pid 872418:tid 872560] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuVHFymN6QYcoA7XB46xgAAAAw"]
[Thu Jul 30 13:17:01.303307 2026] [security2:error] [pid 872418:tid 872671] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wpgum.php"] [unique_id "amuVHVymN6QYcoA7XB46yAAAAHs"]
[Thu Jul 30 13:17:01.303435 2026] [security2:error] [pid 872418:tid 872671] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wpgum.php"] [unique_id "amuVHVymN6QYcoA7XB46yAAAAHs"]
[Thu Jul 30 13:17:01.620194 2026] [security2:error] [pid 872418:tid 872659] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ywwbf.php"] [unique_id "amuVHVymN6QYcoA7XB46ygAAAG8"]
[Thu Jul 30 13:17:01.620307 2026] [security2:error] [pid 872418:tid 872659] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ywwbf.php"] [unique_id "amuVHVymN6QYcoA7XB46ygAAAG8"]
[Thu Jul 30 13:17:01.928708 2026] [security2:error] [pid 872418:tid 872555] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/xoldj.php"] [unique_id "amuVHVymN6QYcoA7XB46zAAAAAc"]
[Thu Jul 30 13:17:01.928825 2026] [security2:error] [pid 872418:tid 872555] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/xoldj.php"] [unique_id "amuVHVymN6QYcoA7XB46zAAAAAc"]
[Thu Jul 30 13:17:02.037791 2026] [core:notice] [pid 872418:tid 872581] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:02.270144 2026] [security2:error] [pid 872418:tid 872563] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/f35.php"] [unique_id "amuVHlymN6QYcoA7XB460QAAAA8"]
[Thu Jul 30 13:17:02.270267 2026] [security2:error] [pid 872418:tid 872563] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/f35.php"] [unique_id "amuVHlymN6QYcoA7XB460QAAAA8"]
[Thu Jul 30 13:17:02.640261 2026] [security2:error] [pid 872418:tid 872571] [client 20.52.54.143:10430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wk/index.php"] [unique_id "amuVHlymN6QYcoA7XB460wAAABc"]
[Thu Jul 30 13:17:02.800844 2026] [security2:error] [pid 872418:tid 872459] [remote 103.174.51.103:54770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.51.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amuVHlymN6QYcoA7XB461AAAOig"]
[Thu Jul 30 13:17:03.126685 2026] [security2:error] [pid 872418:tid 872599] [client 20.52.54.143:10389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/av.php"] [unique_id "amuVH1ymN6QYcoA7XB462AAAADM"]
[Thu Jul 30 13:17:03.130372 2026] [security2:error] [pid 872418:tid 872564] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gk.php"] [unique_id "amuVH1ymN6QYcoA7XB462QAAABA"]
[Thu Jul 30 13:17:03.130496 2026] [security2:error] [pid 872418:tid 872564] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gk.php"] [unique_id "amuVH1ymN6QYcoA7XB462QAAABA"]
[Thu Jul 30 13:17:03.436379 2026] [security2:error] [pid 872418:tid 872605] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuVH1ymN6QYcoA7XB462wAAADk"]
[Thu Jul 30 13:17:03.436505 2026] [security2:error] [pid 872418:tid 872605] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/584062352875874akp.php"] [unique_id "amuVH1ymN6QYcoA7XB462wAAADk"]
[Thu Jul 30 13:17:03.576991 2026] [security2:error] [pid 872418:tid 872461] [remote 216.73.217.142:21068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVH1ymN6QYcoA7XB463AAAVSo"]
[Thu Jul 30 13:17:03.609155 2026] [security2:error] [pid 872418:tid 872575] [client 20.52.54.143:10314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/mini.php"] [unique_id "amuVH1ymN6QYcoA7XB463QAAABs"]
[Thu Jul 30 13:17:03.729754 2026] [security2:error] [pid 872418:tid 872619] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wper3.php"] [unique_id "amuVH1ymN6QYcoA7XB464QAAAEc"]
[Thu Jul 30 13:17:03.729865 2026] [security2:error] [pid 872418:tid 872619] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wper3.php"] [unique_id "amuVH1ymN6QYcoA7XB464QAAAEc"]
[Thu Jul 30 13:17:04.034120 2026] [security2:error] [pid 872418:tid 872622] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/bthil.php"] [unique_id "amuVIFymN6QYcoA7XB464wAAAEo"]
[Thu Jul 30 13:17:04.034281 2026] [security2:error] [pid 872418:tid 872622] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/bthil.php"] [unique_id "amuVIFymN6QYcoA7XB464wAAAEo"]
[Thu Jul 30 13:17:04.169307 2026] [security2:error] [pid 872418:tid 872654] [client 20.52.54.143:10368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/aa.php"] [unique_id "amuVIFymN6QYcoA7XB465AAAAGo"]
[Thu Jul 30 13:17:04.333215 2026] [security2:error] [pid 872418:tid 872640] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wyzer1.php"] [unique_id "amuVIFymN6QYcoA7XB465QAAAFw"]
[Thu Jul 30 13:17:04.333370 2026] [security2:error] [pid 872418:tid 872640] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wyzer1.php"] [unique_id "amuVIFymN6QYcoA7XB465QAAAFw"]
[Thu Jul 30 13:17:04.629490 2026] [security2:error] [pid 872418:tid 872668] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/mh.php"] [unique_id "amuVIFymN6QYcoA7XB466AAAAHg"]
[Thu Jul 30 13:17:04.629636 2026] [security2:error] [pid 872418:tid 872668] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/mh.php"] [unique_id "amuVIFymN6QYcoA7XB466AAAAHg"]
[Thu Jul 30 13:17:04.779347 2026] [security2:error] [pid 872418:tid 872629] [client 20.52.54.143:10398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/w.php"] [unique_id "amuVIFymN6QYcoA7XB466QAAAFE"]
[Thu Jul 30 13:17:04.869916 2026] [security2:error] [pid 872418:tid 872665] [client 172.202.44.182:21268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/chosen.php"] [unique_id "amuVIFymN6QYcoA7XB466gAAAHU"]
[Thu Jul 30 13:17:04.915590 2026] [security2:error] [pid 872418:tid 872549] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuVIFymN6QYcoA7XB466wAAAAE"]
[Thu Jul 30 13:17:04.915702 2026] [security2:error] [pid 872418:tid 872549] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuVIFymN6QYcoA7XB466wAAAAE"]
[Thu Jul 30 13:17:05.255440 2026] [security2:error] [pid 872418:tid 872558] [client 20.91.139.111:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuVIVymN6QYcoA7XB467AAAAAo"]
[Thu Jul 30 13:17:05.255554 2026] [security2:error] [pid 872418:tid 872558] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuVIVymN6QYcoA7XB467AAAAAo"]
[Thu Jul 30 13:17:05.255677 2026] [security2:error] [pid 872418:tid 872558] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuVIVymN6QYcoA7XB467AAAAAo"]
[Thu Jul 30 13:17:05.434487 2026] [security2:error] [pid 872418:tid 872554] [client 20.52.54.143:10419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/admin.php"] [unique_id "amuVIVymN6QYcoA7XB467gAAAAY"]
[Thu Jul 30 13:17:05.857379 2026] [security2:error] [pid 872418:tid 872655] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/chosen.php"] [unique_id "amuVIVymN6QYcoA7XB468AAAAGs"]
[Thu Jul 30 13:17:05.857517 2026] [security2:error] [pid 872418:tid 872655] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/chosen.php"] [unique_id "amuVIVymN6QYcoA7XB468AAAAGs"]
[Thu Jul 30 13:17:05.977521 2026] [security2:error] [pid 872418:tid 872657] [client 20.52.54.143:10431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuVIVymN6QYcoA7XB468QAAAG0"]
[Thu Jul 30 13:17:06.015898 2026] [core:notice] [pid 872418:tid 872587] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:06.162107 2026] [security2:error] [pid 872418:tid 872553] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/sd.php"] [unique_id "amuVIlymN6QYcoA7XB468wAAAAU"]
[Thu Jul 30 13:17:06.162217 2026] [security2:error] [pid 872418:tid 872553] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/sd.php"] [unique_id "amuVIlymN6QYcoA7XB468wAAAAU"]
[Thu Jul 30 13:17:06.642227 2026] [security2:error] [pid 872418:tid 872662] [client 20.52.54.143:10387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/m.php"] [unique_id "amuVIlymN6QYcoA7XB469QAAAHI"]
[Thu Jul 30 13:17:06.684300 2026] [security2:error] [pid 872418:tid 872572] [client 172.202.44.182:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/xleet.php"] [unique_id "amuVIlymN6QYcoA7XB469gAAABg"]
[Thu Jul 30 13:17:06.909456 2026] [security2:error] [pid 872418:tid 872627] [client 172.236.9.101:42460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVIlymN6QYcoA7XB469AAAAE8"]
[Thu Jul 30 13:17:07.308188 2026] [security2:error] [pid 872418:tid 872669] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/z60.php"] [unique_id "amuVI1ymN6QYcoA7XB469wAAAHk"]
[Thu Jul 30 13:17:07.308356 2026] [security2:error] [pid 872418:tid 872669] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/z60.php"] [unique_id "amuVI1ymN6QYcoA7XB469wAAAHk"]
[Thu Jul 30 13:17:07.583131 2026] [security2:error] [pid 872418:tid 872567] [client 20.52.54.143:10427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuVI1ymN6QYcoA7XB46-AAAABM"]
[Thu Jul 30 13:17:07.638846 2026] [security2:error] [pid 872418:tid 872648] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/home.php"] [unique_id "amuVI1ymN6QYcoA7XB46-QAAAGQ"]
[Thu Jul 30 13:17:07.638950 2026] [security2:error] [pid 872418:tid 872648] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/home.php"] [unique_id "amuVI1ymN6QYcoA7XB46-QAAAGQ"]
[Thu Jul 30 13:17:07.941331 2026] [security2:error] [pid 872418:tid 872671] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ws58.php"] [unique_id "amuVI1ymN6QYcoA7XB46-wAAAHs"]
[Thu Jul 30 13:17:07.941454 2026] [security2:error] [pid 872418:tid 872671] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ws58.php"] [unique_id "amuVI1ymN6QYcoA7XB46-wAAAHs"]
[Thu Jul 30 13:17:08.254805 2026] [security2:error] [pid 872418:tid 872559] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gulu.php"] [unique_id "amuVJFymN6QYcoA7XB47AAAAAAs"]
[Thu Jul 30 13:17:08.254936 2026] [security2:error] [pid 872418:tid 872559] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/gulu.php"] [unique_id "amuVJFymN6QYcoA7XB47AAAAAAs"]
[Thu Jul 30 13:17:08.310530 2026] [security2:error] [pid 872418:tid 872569] [client 20.52.54.143:10394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/classwithtostring.php"] [unique_id "amuVJFymN6QYcoA7XB47AQAAABU"]
[Thu Jul 30 13:17:08.338893 2026] [security2:error] [pid 872418:tid 872548] [client 172.202.44.182:54615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/ds.php"] [unique_id "amuVJFymN6QYcoA7XB47AgAAAAA"]
[Thu Jul 30 13:17:08.551124 2026] [security2:error] [pid 872418:tid 872563] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuVJFymN6QYcoA7XB47AwAAAA8"]
[Thu Jul 30 13:17:08.551229 2026] [security2:error] [pid 872418:tid 872563] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuVJFymN6QYcoA7XB47AwAAAA8"]
[Thu Jul 30 13:17:08.859808 2026] [security2:error] [pid 872418:tid 872576] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wpls.php"] [unique_id "amuVJFymN6QYcoA7XB47BQAAABw"]
[Thu Jul 30 13:17:08.859925 2026] [security2:error] [pid 872418:tid 872576] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wpls.php"] [unique_id "amuVJFymN6QYcoA7XB47BQAAABw"]
[Thu Jul 30 13:17:08.931081 2026] [security2:error] [pid 872418:tid 872592] [client 20.52.54.143:10344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/gmo.php"] [unique_id "amuVJFymN6QYcoA7XB47BgAAACw"]
[Thu Jul 30 13:17:09.207029 2026] [security2:error] [pid 872418:tid 872603] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/php.php"] [unique_id "amuVJVymN6QYcoA7XB47CAAAADc"]
[Thu Jul 30 13:17:09.207224 2026] [security2:error] [pid 872418:tid 872603] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/php.php"] [unique_id "amuVJVymN6QYcoA7XB47CAAAADc"]
[Thu Jul 30 13:17:09.466784 2026] [security2:error] [pid 872418:tid 872582] [client 20.52.54.143:10380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuVJVymN6QYcoA7XB47DgAAACI"]
[Thu Jul 30 13:17:09.512881 2026] [security2:error] [pid 872418:tid 872597] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/100.php"] [unique_id "amuVJVymN6QYcoA7XB47DwAAADE"]
[Thu Jul 30 13:17:09.513049 2026] [security2:error] [pid 872418:tid 872597] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/100.php"] [unique_id "amuVJVymN6QYcoA7XB47DwAAADE"]
[Thu Jul 30 13:17:09.519462 2026] [security2:error] [pid 872418:tid 872481] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/index.php"] [unique_id "amuVJVymN6QYcoA7XB47EAAAOj4"]
[Thu Jul 30 13:17:09.820332 2026] [security2:error] [pid 872418:tid 872609] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/BDKR28WP.php"] [unique_id "amuVJVymN6QYcoA7XB47EgAAAD0"]
[Thu Jul 30 13:17:09.820478 2026] [security2:error] [pid 872418:tid 872609] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/BDKR28WP.php"] [unique_id "amuVJVymN6QYcoA7XB47EgAAAD0"]
[Thu Jul 30 13:17:09.939941 2026] [security2:error] [pid 872418:tid 872626] [client 20.52.54.143:10385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-the.php"] [unique_id "amuVJVymN6QYcoA7XB47EwAAAE4"]
[Thu Jul 30 13:17:10.112158 2026] [security2:error] [pid 872418:tid 872568] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/browse.php"] [unique_id "amuVJlymN6QYcoA7XB47FAAAABQ"]
[Thu Jul 30 13:17:10.112314 2026] [security2:error] [pid 872418:tid 872568] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/browse.php"] [unique_id "amuVJlymN6QYcoA7XB47FAAAABQ"]
[Thu Jul 30 13:17:10.420790 2026] [security2:error] [pid 872418:tid 872658] [client 179.64.21.229:44280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVJlymN6QYcoA7XB47FQAAAG4"]
[Thu Jul 30 13:17:10.432612 2026] [security2:error] [pid 872418:tid 872658] [client 179.64.21.229:44280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVJlymN6QYcoA7XB47FQAAAG4"]
[Thu Jul 30 13:17:10.543833 2026] [security2:error] [pid 872418:tid 872605] [client 20.52.54.143:10308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/404.php"] [unique_id "amuVJlymN6QYcoA7XB47FgAAADk"]
[Thu Jul 30 13:17:10.721268 2026] [security2:error] [pid 872418:tid 872607] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuVJlymN6QYcoA7XB47FwAAADs"]
[Thu Jul 30 13:17:10.721385 2026] [security2:error] [pid 872418:tid 872607] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuVJlymN6QYcoA7XB47FwAAADs"]
[Thu Jul 30 13:17:11.035875 2026] [security2:error] [pid 872418:tid 872634] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/8573.php"] [unique_id "amuVJ1ymN6QYcoA7XB47GQAAAFY"]
[Thu Jul 30 13:17:11.036007 2026] [security2:error] [pid 872418:tid 872634] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/8573.php"] [unique_id "amuVJ1ymN6QYcoA7XB47GQAAAFY"]
[Thu Jul 30 13:17:11.082237 2026] [security2:error] [pid 872418:tid 872594] [client 172.202.44.182:17656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/f5.php"] [unique_id "amuVJ1ymN6QYcoA7XB47GgAAAC4"]
[Thu Jul 30 13:17:11.170482 2026] [security2:error] [pid 872418:tid 872619] [client 20.52.54.143:10304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/init.php"] [unique_id "amuVJ1ymN6QYcoA7XB47GwAAAEc"]
[Thu Jul 30 13:17:11.333215 2026] [security2:error] [pid 872418:tid 872612] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/install.php"] [unique_id "amuVJ1ymN6QYcoA7XB47HAAAAEA"]
[Thu Jul 30 13:17:11.333335 2026] [security2:error] [pid 872418:tid 872612] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/install.php"] [unique_id "amuVJ1ymN6QYcoA7XB47HAAAAEA"]
[Thu Jul 30 13:17:11.669159 2026] [security2:error] [pid 872418:tid 872624] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/.env"] [unique_id "amuVJ1ymN6QYcoA7XB47HQAAAEw"]
[Thu Jul 30 13:17:11.722133 2026] [security2:error] [pid 872418:tid 872630] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuVJ1ymN6QYcoA7XB47HgAAAFI"]
[Thu Jul 30 13:17:11.722278 2026] [security2:error] [pid 872418:tid 872630] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuVJ1ymN6QYcoA7XB47HgAAAFI"]
[Thu Jul 30 13:17:11.806879 2026] [security2:error] [pid 872418:tid 872596] [client 20.52.54.143:10421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/file5.php"] [unique_id "amuVJ1ymN6QYcoA7XB47IAAAADA"]
[Thu Jul 30 13:17:12.020733 2026] [security2:error] [pid 872418:tid 872620] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ohct.php"] [unique_id "amuVKFymN6QYcoA7XB47IQAAAEg"]
[Thu Jul 30 13:17:12.020855 2026] [security2:error] [pid 872418:tid 872620] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ohct.php"] [unique_id "amuVKFymN6QYcoA7XB47IQAAAEg"]
[Thu Jul 30 13:17:12.323270 2026] [security2:error] [pid 872418:tid 872598] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/bless.php"] [unique_id "amuVKFymN6QYcoA7XB47IgAAADI"]
[Thu Jul 30 13:17:12.323396 2026] [security2:error] [pid 872418:tid 872598] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/bless.php"] [unique_id "amuVKFymN6QYcoA7XB47IgAAADI"]
[Thu Jul 30 13:17:12.471443 2026] [security2:error] [pid 872418:tid 872663] [client 20.52.54.143:10317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuVKFymN6QYcoA7XB47JAAAAHM"]
[Thu Jul 30 13:17:12.837097 2026] [security2:error] [pid 872418:tid 872602] [client 172.202.44.182:17663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/god4m.php"] [unique_id "amuVKFymN6QYcoA7XB47JQAAADY"]
[Thu Jul 30 13:17:12.903029 2026] [security2:error] [pid 872418:tid 872660] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/about.php"] [unique_id "amuVKFymN6QYcoA7XB47JgAAAHA"]
[Thu Jul 30 13:17:12.903241 2026] [security2:error] [pid 872418:tid 872660] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/about.php"] [unique_id "amuVKFymN6QYcoA7XB47JgAAAHA"]
[Thu Jul 30 13:17:13.062015 2026] [security2:error] [pid 872418:tid 872653] [client 20.52.54.143:10377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/shell.php"] [unique_id "amuVKVymN6QYcoA7XB47KAAAAGk"]
[Thu Jul 30 13:17:13.141290 2026] [security2:error] [pid 872418:tid 872482] [remote 216.73.217.142:21068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuVKVymN6QYcoA7XB47LwAAAz8"]
[Thu Jul 30 13:17:13.252306 2026] [security2:error] [pid 872418:tid 872554] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVKVymN6QYcoA7XB47MQAAAAY"]
[Thu Jul 30 13:17:13.252483 2026] [security2:error] [pid 872418:tid 872554] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVKVymN6QYcoA7XB47MQAAAAY"]
[Thu Jul 30 13:17:13.415539 2026] [security2:error] [pid 872418:tid 872587] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuVKVymN6QYcoA7XB47NgAAACc"]
[Thu Jul 30 13:17:13.415713 2026] [security2:error] [pid 872418:tid 872587] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuVKVymN6QYcoA7XB47NgAAACc"]
[Thu Jul 30 13:17:13.559481 2026] [security2:error] [pid 872418:tid 872662] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVKVymN6QYcoA7XB47OAAAAHI"]
[Thu Jul 30 13:17:13.559602 2026] [security2:error] [pid 872418:tid 872662] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVKVymN6QYcoA7XB47OAAAAHI"]
[Thu Jul 30 13:17:13.647327 2026] [security2:error] [pid 872418:tid 872650] [client 172.237.109.114:6608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKVymN6QYcoA7XB47KQAAAGY"]
[Thu Jul 30 13:17:13.708443 2026] [security2:error] [pid 872418:tid 872665] [client 172.237.109.114:42253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKVymN6QYcoA7XB47LAAAAHU"]
[Thu Jul 30 13:17:13.718712 2026] [security2:error] [pid 872418:tid 872613] [client 172.237.109.114:7531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKVymN6QYcoA7XB47KwAAAEE"]
[Thu Jul 30 13:17:13.719154 2026] [security2:error] [pid 872418:tid 872629] [client 172.237.109.114:11635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKVymN6QYcoA7XB47KgAAAFE"]
[Thu Jul 30 13:17:13.742594 2026] [security2:error] [pid 872418:tid 872643] [client 172.237.109.114:14893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKVymN6QYcoA7XB47LgAAAF8"]
[Thu Jul 30 13:17:13.786877 2026] [security2:error] [pid 872418:tid 872673] [client 172.237.109.114:14192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKVymN6QYcoA7XB47MAAAAH0"]
[Thu Jul 30 13:17:13.799381 2026] [security2:error] [pid 872418:tid 872618] [client 20.52.54.143:10396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/f35.php"] [unique_id "amuVKVymN6QYcoA7XB47OgAAAEY"]
[Thu Jul 30 13:17:13.853440 2026] [security2:error] [pid 872418:tid 872627] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuVKVymN6QYcoA7XB47OwAAAE8"]
[Thu Jul 30 13:17:13.853577 2026] [security2:error] [pid 872418:tid 872627] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuVKVymN6QYcoA7XB47OwAAAE8"]
[Thu Jul 30 13:17:13.965438 2026] [security2:error] [pid 872418:tid 872671] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ta0ol.php"] [unique_id "amuVKVymN6QYcoA7XB47PQAAAHs"]
[Thu Jul 30 13:17:13.965544 2026] [security2:error] [pid 872418:tid 872671] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ta0ol.php"] [unique_id "amuVKVymN6QYcoA7XB47PQAAAHs"]
[Thu Jul 30 13:17:14.123305 2026] [security2:error] [pid 872418:tid 872548] [client 172.237.109.114:35667] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/ssl/private/alseermarine.com_key.pem"] [unique_id "amuVKlymN6QYcoA7XB47SAAAAAA"]
[Thu Jul 30 13:17:14.174231 2026] [security2:error] [pid 872418:tid 872576] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/err.php"] [unique_id "amuVKlymN6QYcoA7XB47TAAAABw"]
[Thu Jul 30 13:17:14.174391 2026] [security2:error] [pid 872418:tid 872576] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/err.php"] [unique_id "amuVKlymN6QYcoA7XB47TAAAABw"]
[Thu Jul 30 13:17:14.266651 2026] [security2:error] [pid 872418:tid 872635] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/sa.php7"] [unique_id "amuVKlymN6QYcoA7XB47TQAAAFc"]
[Thu Jul 30 13:17:14.266846 2026] [security2:error] [pid 872418:tid 872635] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/sa.php7"] [unique_id "amuVKlymN6QYcoA7XB47TQAAAFc"]
[Thu Jul 30 13:17:14.473760 2026] [security2:error] [pid 872418:tid 872617] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/img.php"] [unique_id "amuVKlymN6QYcoA7XB47TwAAAEU"]
[Thu Jul 30 13:17:14.473934 2026] [security2:error] [pid 872418:tid 872617] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/img.php"] [unique_id "amuVKlymN6QYcoA7XB47TwAAAEU"]
[Thu Jul 30 13:17:14.506303 2026] [core:notice] [pid 872418:tid 872603] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:14.571181 2026] [security2:error] [pid 872418:tid 872591] [client 20.52.54.143:10372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/new.php"] [unique_id "amuVKlymN6QYcoA7XB47UgAAACs"]
[Thu Jul 30 13:17:14.593188 2026] [security2:error] [pid 872418:tid 872606] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-class.php"] [unique_id "amuVKlymN6QYcoA7XB47UwAAADo"]
[Thu Jul 30 13:17:14.593370 2026] [security2:error] [pid 872418:tid 872606] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-class.php"] [unique_id "amuVKlymN6QYcoA7XB47UwAAADo"]
[Thu Jul 30 13:17:14.704766 2026] [security2:error] [pid 872418:tid 872578] [client 172.237.109.114:19216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47QQAAAB4"]
[Thu Jul 30 13:17:14.741939 2026] [security2:error] [pid 872418:tid 872656] [client 172.202.44.182:21273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/info.php"] [unique_id "amuVKlymN6QYcoA7XB47WAAAAGw"]
[Thu Jul 30 13:17:14.779250 2026] [security2:error] [pid 872418:tid 872574] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/aa.php"] [unique_id "amuVKlymN6QYcoA7XB47WQAAABo"]
[Thu Jul 30 13:17:14.779407 2026] [security2:error] [pid 872418:tid 872574] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/aa.php"] [unique_id "amuVKlymN6QYcoA7XB47WQAAABo"]
[Thu Jul 30 13:17:14.891148 2026] [security2:error] [pid 872418:tid 872633] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuVKlymN6QYcoA7XB47WgAAAFU"]
[Thu Jul 30 13:17:14.891266 2026] [security2:error] [pid 872418:tid 872633] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuVKlymN6QYcoA7XB47WgAAAFU"]
[Thu Jul 30 13:17:15.069887 2026] [security2:error] [pid 872418:tid 872645] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/av.php"] [unique_id "amuVK1ymN6QYcoA7XB47ZQAAAGE"]
[Thu Jul 30 13:17:15.070049 2026] [security2:error] [pid 872418:tid 872645] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/av.php"] [unique_id "amuVK1ymN6QYcoA7XB47ZQAAAGE"]
[Thu Jul 30 13:17:15.208963 2026] [security2:error] [pid 872418:tid 872620] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/bootstrap.php"] [unique_id "amuVK1ymN6QYcoA7XB47ZgAAAEg"]
[Thu Jul 30 13:17:15.209101 2026] [security2:error] [pid 872418:tid 872620] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/bootstrap.php"] [unique_id "amuVK1ymN6QYcoA7XB47ZgAAAEg"]
[Thu Jul 30 13:17:15.217055 2026] [security2:error] [pid 872418:tid 872588] [client 172.237.109.114:13675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47PwAAACg"]
[Thu Jul 30 13:17:15.217409 2026] [security2:error] [pid 872418:tid 872561] [client 172.237.109.114:28285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47PgAAAA0"]
[Thu Jul 30 13:17:15.221174 2026] [security2:error] [pid 872418:tid 872659] [client 172.237.109.114:64339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47QAAAAG8"]
[Thu Jul 30 13:17:15.232356 2026] [security2:error] [pid 872418:tid 872596] [client 20.52.54.143:10349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/adminfuns.php"] [unique_id "amuVK1ymN6QYcoA7XB47ZwAAADA"]
[Thu Jul 30 13:17:15.232503 2026] [security2:error] [pid 872418:tid 872593] [client 172.237.109.114:36927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47QwAAAC0"]
[Thu Jul 30 13:17:15.279742 2026] [security2:error] [pid 872418:tid 872583] [client 172.237.109.114:12912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47QgAAACM"]
[Thu Jul 30 13:17:15.320424 2026] [security2:error] [pid 872418:tid 872562] [client 172.237.109.114:45408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47SQAAAA4"]
[Thu Jul 30 13:17:15.364517 2026] [security2:error] [pid 872418:tid 872569] [client 172.237.109.114:10723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47RgAAABU"]
[Thu Jul 30 13:17:15.364551 2026] [security2:error] [pid 872418:tid 872555] [client 172.237.109.114:58505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47RAAAAAc"]
[Thu Jul 30 13:17:15.366073 2026] [security2:error] [pid 872418:tid 872559] [client 172.237.109.114:3907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47RwAAAAs"]
[Thu Jul 30 13:17:15.366282 2026] [security2:error] [pid 872418:tid 872584] [client 172.237.109.114:43173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47RQAAACQ"]
[Thu Jul 30 13:17:15.393244 2026] [security2:error] [pid 872418:tid 872563] [client 172.237.109.114:11275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47SwAAAA8"]
[Thu Jul 30 13:17:15.399078 2026] [security2:error] [pid 872418:tid 872660] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/xa.php"] [unique_id "amuVK1ymN6QYcoA7XB47aAAAAHA"]
[Thu Jul 30 13:17:15.399240 2026] [security2:error] [pid 872418:tid 872660] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/xa.php"] [unique_id "amuVK1ymN6QYcoA7XB47aAAAAHA"]
[Thu Jul 30 13:17:15.405383 2026] [security2:error] [pid 872418:tid 872556] [client 172.237.109.114:2087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47SgAAAAg"]
[Thu Jul 30 13:17:15.499721 2026] [security2:error] [pid 872418:tid 872653] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-blog-header.php"] [unique_id "amuVK1ymN6QYcoA7XB47aQAAAGk"]
[Thu Jul 30 13:17:15.499855 2026] [security2:error] [pid 872418:tid 872653] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-blog-header.php"] [unique_id "amuVK1ymN6QYcoA7XB47aQAAAGk"]
[Thu Jul 30 13:17:15.683956 2026] [security2:error] [pid 872418:tid 872650] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/media.php"] [unique_id "amuVK1ymN6QYcoA7XB47agAAAGY"]
[Thu Jul 30 13:17:15.684100 2026] [security2:error] [pid 872418:tid 872650] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/media.php"] [unique_id "amuVK1ymN6QYcoA7XB47agAAAGY"]
[Thu Jul 30 13:17:15.820895 2026] [security2:error] [pid 872418:tid 872661] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuVK1ymN6QYcoA7XB47awAAAHE"]
[Thu Jul 30 13:17:15.821070 2026] [security2:error] [pid 872418:tid 872661] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuVK1ymN6QYcoA7XB47awAAAHE"]
[Thu Jul 30 13:17:15.974941 2026] [security2:error] [pid 872418:tid 872665] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/images.php"] [unique_id "amuVK1ymN6QYcoA7XB47bQAAAHU"]
[Thu Jul 30 13:17:15.975084 2026] [security2:error] [pid 872418:tid 872665] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/images.php"] [unique_id "amuVK1ymN6QYcoA7XB47bQAAAHU"]
[Thu Jul 30 13:17:16.117334 2026] [security2:error] [pid 872418:tid 872629] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/tx79.php"] [unique_id "amuVLFymN6QYcoA7XB47bgAAAFE"]
[Thu Jul 30 13:17:16.117489 2026] [security2:error] [pid 872418:tid 872629] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/tx79.php"] [unique_id "amuVLFymN6QYcoA7XB47bgAAAFE"]
[Thu Jul 30 13:17:16.239963 2026] [security2:error] [pid 872418:tid 872644] [client 172.237.109.114:37607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47XQAAAGA"]
[Thu Jul 30 13:17:16.241683 2026] [security2:error] [pid 872418:tid 872589] [client 172.237.109.114:36368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVK1ymN6QYcoA7XB47YwAAACk"]
[Thu Jul 30 13:17:16.244123 2026] [security2:error] [pid 872418:tid 872594] [client 172.237.109.114:44563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47WwAAAC4"]
[Thu Jul 30 13:17:16.245933 2026] [security2:error] [pid 872418:tid 872595] [client 172.237.109.114:39263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47XgAAAC8"]
[Thu Jul 30 13:17:16.268130 2026] [security2:error] [pid 872418:tid 872669] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/gecko.php"] [unique_id "amuVLFymN6QYcoA7XB47cwAAAHk"]
[Thu Jul 30 13:17:16.268272 2026] [security2:error] [pid 872418:tid 872669] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/gecko.php"] [unique_id "amuVLFymN6QYcoA7XB47cwAAAHk"]
[Thu Jul 30 13:17:16.273103 2026] [security2:error] [pid 872418:tid 872619] [client 172.237.109.114:49449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47XAAAAEc"]
[Thu Jul 30 13:17:16.310252 2026] [security2:error] [pid 872418:tid 872624] [client 172.237.109.114:30619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVK1ymN6QYcoA7XB47ZAAAAEw"]
[Thu Jul 30 13:17:16.310254 2026] [security2:error] [pid 872418:tid 872612] [client 172.237.109.114:65217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47YAAAAEA"]
[Thu Jul 30 13:17:16.310417 2026] [security2:error] [pid 872418:tid 872638] [client 172.237.109.114:46212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47XwAAAFo"]
[Thu Jul 30 13:17:16.310436 2026] [security2:error] [pid 872418:tid 872642] [client 172.237.109.114:64111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVKlymN6QYcoA7XB47YgAAAF4"]
[Thu Jul 30 13:17:16.353602 2026] [security2:error] [pid 872418:tid 872649] [client 20.52.54.143:10429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/fm.php"] [unique_id "amuVLFymN6QYcoA7XB47dAAAAGU"]
[Thu Jul 30 13:17:16.450249 2026] [security2:error] [pid 872418:tid 872553] [client 45.172.218.23:58264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVLFymN6QYcoA7XB47bwAAAAU"], referer: http://pkf.jo
[Thu Jul 30 13:17:16.572275 2026] [security2:error] [pid 872418:tid 872635] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/82.php"] [unique_id "amuVLFymN6QYcoA7XB47dwAAAFc"]
[Thu Jul 30 13:17:16.572388 2026] [security2:error] [pid 872418:tid 872635] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/82.php"] [unique_id "amuVLFymN6QYcoA7XB47dwAAAFc"]
[Thu Jul 30 13:17:16.579191 2026] [security2:error] [pid 872418:tid 872579] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/motu.php"] [unique_id "amuVLFymN6QYcoA7XB47eAAAAB8"]
[Thu Jul 30 13:17:16.579332 2026] [security2:error] [pid 872418:tid 872579] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/motu.php"] [unique_id "amuVLFymN6QYcoA7XB47eAAAAB8"]
[Thu Jul 30 13:17:16.761203 2026] [security2:error] [pid 872418:tid 872581] [client 72.94.38.118:35134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVLFymN6QYcoA7XB47dgAAACE"], referer: http://pkf.jo
[Thu Jul 30 13:17:16.874311 2026] [security2:error] [pid 872418:tid 872628] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-head.php"] [unique_id "amuVLFymN6QYcoA7XB47fAAAAFA"]
[Thu Jul 30 13:17:16.874377 2026] [security2:error] [pid 872418:tid 872603] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/xstelth.php"] [unique_id "amuVLFymN6QYcoA7XB47ewAAADc"]
[Thu Jul 30 13:17:16.874450 2026] [security2:error] [pid 872418:tid 872603] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/xstelth.php"] [unique_id "amuVLFymN6QYcoA7XB47ewAAADc"]
[Thu Jul 30 13:17:16.874443 2026] [security2:error] [pid 872418:tid 872628] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-head.php"] [unique_id "amuVLFymN6QYcoA7XB47fAAAAFA"]
[Thu Jul 30 13:17:17.121351 2026] [security2:error] [pid 872418:tid 872617] [client 160.250.255.54:2167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVLFymN6QYcoA7XB47egAAAEU"], referer: http://pkf.jo
[Thu Jul 30 13:17:17.161934 2026] [security2:error] [pid 872418:tid 872608] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuVLVymN6QYcoA7XB47gwAAADw"]
[Thu Jul 30 13:17:17.162058 2026] [security2:error] [pid 872418:tid 872608] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuVLVymN6QYcoA7XB47gwAAADw"]
[Thu Jul 30 13:17:17.173782 2026] [security2:error] [pid 872418:tid 872578] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/xp.php"] [unique_id "amuVLVymN6QYcoA7XB47hAAAAB4"]
[Thu Jul 30 13:17:17.173880 2026] [security2:error] [pid 872418:tid 872578] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/xp.php"] [unique_id "amuVLVymN6QYcoA7XB47hAAAAB4"]
[Thu Jul 30 13:17:17.344661 2026] [security2:error] [pid 872418:tid 872568] [client 20.52.54.143:10375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/file.php"] [unique_id "amuVLVymN6QYcoA7XB47hQAAABQ"]
[Thu Jul 30 13:17:17.471821 2026] [security2:error] [pid 872418:tid 872605] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/admin.php"] [unique_id "amuVLVymN6QYcoA7XB47hwAAADk"]
[Thu Jul 30 13:17:17.471934 2026] [security2:error] [pid 872418:tid 872605] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/admin.php"] [unique_id "amuVLVymN6QYcoA7XB47hwAAADk"]
[Thu Jul 30 13:17:17.694714 2026] [security2:error] [pid 872418:tid 872634] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/60856e3a4findex.php"] [unique_id "amuVLVymN6QYcoA7XB47igAAAFY"]
[Thu Jul 30 13:17:17.694838 2026] [security2:error] [pid 872418:tid 872634] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/60856e3a4findex.php"] [unique_id "amuVLVymN6QYcoA7XB47igAAAFY"]
[Thu Jul 30 13:17:17.749168 2026] [security2:error] [pid 872418:tid 872567] [client 172.202.44.182:21272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuVLFymN6QYcoA7XB47eQAAABM"]
[Thu Jul 30 13:17:17.768753 2026] [security2:error] [pid 872418:tid 872641] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/adminner.php"] [unique_id "amuVLVymN6QYcoA7XB47jAAAAF0"]
[Thu Jul 30 13:17:17.768862 2026] [security2:error] [pid 872418:tid 872641] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/adminner.php"] [unique_id "amuVLVymN6QYcoA7XB47jAAAAF0"]
[Thu Jul 30 13:17:17.949119 2026] [security2:error] [pid 872418:tid 872631] [client 45.120.122.88:30392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVLVymN6QYcoA7XB47iQAAAFM"], referer: http://pkf.jo
[Thu Jul 30 13:17:17.976105 2026] [security2:error] [pid 872418:tid 872593] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuVLVymN6QYcoA7XB47kAAAAC0"]
[Thu Jul 30 13:17:17.976212 2026] [security2:error] [pid 872418:tid 872593] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuVLVymN6QYcoA7XB47kAAAAC0"]
[Thu Jul 30 13:17:18.084648 2026] [security2:error] [pid 872418:tid 872583] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/a.php"] [unique_id "amuVLlymN6QYcoA7XB47kgAAACM"]
[Thu Jul 30 13:17:18.084762 2026] [security2:error] [pid 872418:tid 872583] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/a.php"] [unique_id "amuVLlymN6QYcoA7XB47kgAAACM"]
[Thu Jul 30 13:17:18.142333 2026] [security2:error] [pid 872418:tid 872652] [client 172.202.44.182:21272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.__info.php"] [unique_id "amuVLlymN6QYcoA7XB47kwAAAGg"]
[Thu Jul 30 13:17:18.216175 2026] [security2:error] [pid 872418:tid 872622] [client 20.52.54.143:10321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/bolt.php"] [unique_id "amuVLlymN6QYcoA7XB47lAAAAEo"]
[Thu Jul 30 13:17:18.269023 2026] [security2:error] [pid 872418:tid 872663] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp.php"] [unique_id "amuVLlymN6QYcoA7XB47lQAAAHM"]
[Thu Jul 30 13:17:18.269138 2026] [security2:error] [pid 872418:tid 872663] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wp.php"] [unique_id "amuVLlymN6QYcoA7XB47lQAAAHM"]
[Thu Jul 30 13:17:18.381337 2026] [security2:error] [pid 872418:tid 872584] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/k.php"] [unique_id "amuVLlymN6QYcoA7XB47mgAAACQ"]
[Thu Jul 30 13:17:18.381497 2026] [security2:error] [pid 872418:tid 872584] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/k.php"] [unique_id "amuVLlymN6QYcoA7XB47mgAAACQ"]
[Thu Jul 30 13:17:18.480371 2026] [security2:error] [pid 872418:tid 872588] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVLVymN6QYcoA7XB47jwAAACg"]
[Thu Jul 30 13:17:18.604792 2026] [security2:error] [pid 872418:tid 872655] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/users.php"] [unique_id "amuVLlymN6QYcoA7XB47ngAAAGs"]
[Thu Jul 30 13:17:18.604928 2026] [security2:error] [pid 872418:tid 872655] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/users.php"] [unique_id "amuVLlymN6QYcoA7XB47ngAAAGs"]
[Thu Jul 30 13:17:18.681844 2026] [security2:error] [pid 872418:tid 872587] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/222.php"] [unique_id "amuVLlymN6QYcoA7XB47nwAAACc"]
[Thu Jul 30 13:17:18.681965 2026] [security2:error] [pid 872418:tid 872587] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/222.php"] [unique_id "amuVLlymN6QYcoA7XB47nwAAACc"]
[Thu Jul 30 13:17:18.734364 2026] [security2:error] [pid 872418:tid 872556] [client 152.56.131.48:55094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVLlymN6QYcoA7XB47mwAAAAg"], referer: http://pkf.jo
[Thu Jul 30 13:17:18.768247 2026] [core:notice] [pid 872418:tid 872651] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:18.788330 2026] [security2:error] [pid 872418:tid 872496] [remote 216.73.217.142:28762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVLlymN6QYcoA7XB47oQAAbU0"]
[Thu Jul 30 13:17:18.905121 2026] [security2:error] [pid 872418:tid 872675] [client 172.202.44.182:14104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/0.php"] [unique_id "amuVLlymN6QYcoA7XB47pAAAAH8"]
[Thu Jul 30 13:17:18.906891 2026] [security2:error] [pid 872418:tid 872618] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/tinysd.php"] [unique_id "amuVLlymN6QYcoA7XB47pQAAAEY"]
[Thu Jul 30 13:17:18.907008 2026] [security2:error] [pid 872418:tid 872618] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/tinysd.php"] [unique_id "amuVLlymN6QYcoA7XB47pQAAAEY"]
[Thu Jul 30 13:17:18.910646 2026] [security2:error] [pid 872418:tid 872602] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVLlymN6QYcoA7XB47mAAAADY"]
[Thu Jul 30 13:17:18.988877 2026] [security2:error] [pid 872418:tid 872595] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/mac.php"] [unique_id "amuVLlymN6QYcoA7XB47qAAAAC8"]
[Thu Jul 30 13:17:18.988991 2026] [security2:error] [pid 872418:tid 872595] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/mac.php"] [unique_id "amuVLlymN6QYcoA7XB47qAAAAC8"]
[Thu Jul 30 13:17:19.031477 2026] [security2:error] [pid 872418:tid 872666] [client 20.52.54.143:10423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/3.php"] [unique_id "amuVL1ymN6QYcoA7XB47qQAAAHY"]
[Thu Jul 30 13:17:19.209483 2026] [security2:error] [pid 872418:tid 872648] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ws78.php"] [unique_id "amuVL1ymN6QYcoA7XB47qwAAAGQ"]
[Thu Jul 30 13:17:19.209586 2026] [security2:error] [pid 872418:tid 872648] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ws78.php"] [unique_id "amuVL1ymN6QYcoA7XB47qwAAAGQ"]
[Thu Jul 30 13:17:19.291288 2026] [security2:error] [pid 872418:tid 872553] [client 4.225.166.222:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-content/uploads/"] [unique_id "amuVL1ymN6QYcoA7XB47rAAAAAU"]
[Thu Jul 30 13:17:19.291417 2026] [security2:error] [pid 872418:tid 872553] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-content/uploads/"] [unique_id "amuVL1ymN6QYcoA7XB47rAAAAAU"]
[Thu Jul 30 13:17:19.510326 2026] [security2:error] [pid 872418:tid 872576] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/elp.php"] [unique_id "amuVL1ymN6QYcoA7XB47sAAAABw"]
[Thu Jul 30 13:17:19.510481 2026] [security2:error] [pid 872418:tid 872576] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/elp.php"] [unique_id "amuVL1ymN6QYcoA7XB47sAAAABw"]
[Thu Jul 30 13:17:19.582686 2026] [security2:error] [pid 872418:tid 872635] [client 4.225.166.222:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-includes/Text/"] [unique_id "amuVL1ymN6QYcoA7XB47swAAAFc"]
[Thu Jul 30 13:17:19.582805 2026] [security2:error] [pid 872418:tid 872635] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-includes/Text/"] [unique_id "amuVL1ymN6QYcoA7XB47swAAAFc"]
[Thu Jul 30 13:17:19.673106 2026] [security2:error] [pid 872418:tid 872611] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuVL1ymN6QYcoA7XB47rwAAAD8"]
[Thu Jul 30 13:17:19.679185 2026] [security2:error] [pid 872418:tid 872674] [client 172.202.44.182:54637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/07.php"] [unique_id "amuVL1ymN6QYcoA7XB47tQAAAH4"]
[Thu Jul 30 13:17:19.710071 2026] [security2:error] [pid 872418:tid 872548] [client 20.52.54.143:11150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/222.php"] [unique_id "amuVL1ymN6QYcoA7XB47tgAAAAA"]
[Thu Jul 30 13:17:19.819364 2026] [security2:error] [pid 872418:tid 872606] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/atomlib.php"] [unique_id "amuVL1ymN6QYcoA7XB47twAAADo"]
[Thu Jul 30 13:17:19.819490 2026] [security2:error] [pid 872418:tid 872606] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/atomlib.php"] [unique_id "amuVL1ymN6QYcoA7XB47twAAADo"]
[Thu Jul 30 13:17:19.893656 2026] [security2:error] [pid 872418:tid 872571] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/ops.php"] [unique_id "amuVL1ymN6QYcoA7XB47uAAAABc"]
[Thu Jul 30 13:17:19.893767 2026] [security2:error] [pid 872418:tid 872571] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/ops.php"] [unique_id "amuVL1ymN6QYcoA7XB47uAAAABc"]
[Thu Jul 30 13:17:19.896781 2026] [security2:error] [pid 872418:tid 872550] [client 20.52.54.143:10411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wk/index.php"] [unique_id "amuVL1ymN6QYcoA7XB47uQAAAAI"]
[Thu Jul 30 13:17:19.922075 2026] [core:notice] [pid 872418:tid 872579] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:20.123179 2026] [security2:error] [pid 872418:tid 872597] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wyzer3.php"] [unique_id "amuVMFymN6QYcoA7XB47vQAAADE"]
[Thu Jul 30 13:17:20.123303 2026] [security2:error] [pid 872418:tid 872597] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/wyzer3.php"] [unique_id "amuVMFymN6QYcoA7XB47vQAAADE"]
[Thu Jul 30 13:17:20.169647 2026] [security2:error] [pid 872418:tid 872639] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVL1ymN6QYcoA7XB47sQAAW08"]
[Thu Jul 30 13:17:20.208342 2026] [security2:error] [pid 872418:tid 872632] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/8.php"] [unique_id "amuVMFymN6QYcoA7XB47vgAAAFQ"]
[Thu Jul 30 13:17:20.208479 2026] [security2:error] [pid 872418:tid 872632] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/8.php"] [unique_id "amuVMFymN6QYcoA7XB47vgAAAFQ"]
[Thu Jul 30 13:17:20.391068 2026] [security2:error] [pid 872418:tid 872656] [client 20.52.54.143:10305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuVMFymN6QYcoA7XB47wwAAAGw"]
[Thu Jul 30 13:17:20.507877 2026] [security2:error] [pid 872418:tid 872561] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/FWAZ.php"] [unique_id "amuVMFymN6QYcoA7XB47xQAAAA0"]
[Thu Jul 30 13:17:20.508013 2026] [security2:error] [pid 872418:tid 872561] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/FWAZ.php"] [unique_id "amuVMFymN6QYcoA7XB47xQAAAA0"]
[Thu Jul 30 13:17:20.652645 2026] [security2:error] [pid 872418:tid 872583] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/max.php"] [unique_id "amuVMFymN6QYcoA7XB47xwAAACM"]
[Thu Jul 30 13:17:20.652762 2026] [security2:error] [pid 872418:tid 872583] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/max.php"] [unique_id "amuVMFymN6QYcoA7XB47xwAAACM"]
[Thu Jul 30 13:17:20.704201 2026] [security2:error] [pid 872418:tid 872567] [client 20.52.54.143:10381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/av.php"] [unique_id "amuVMFymN6QYcoA7XB47yQAAABM"]
[Thu Jul 30 13:17:20.808346 2026] [security2:error] [pid 872418:tid 872622] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/biufile.php"] [unique_id "amuVMFymN6QYcoA7XB47ygAAAEo"]
[Thu Jul 30 13:17:20.808503 2026] [security2:error] [pid 872418:tid 872622] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/biufile.php"] [unique_id "amuVMFymN6QYcoA7XB47ygAAAEo"]
[Thu Jul 30 13:17:20.909855 2026] [security2:error] [pid 872418:tid 872620] [client 179.64.21.229:41983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVMFymN6QYcoA7XB47ywAAAEg"]
[Thu Jul 30 13:17:20.910027 2026] [security2:error] [pid 872418:tid 872620] [client 179.64.21.229:41983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVMFymN6QYcoA7XB47ywAAAEg"]
[Thu Jul 30 13:17:21.037568 2026] [security2:error] [pid 872418:tid 872663] [client 20.52.54.143:10330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuVMVymN6QYcoA7XB47zAAAAHM"]
[Thu Jul 30 13:17:21.106364 2026] [security2:error] [pid 872418:tid 872549] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/coffexium.php"] [unique_id "amuVMVymN6QYcoA7XB47zgAAAAE"]
[Thu Jul 30 13:17:21.106506 2026] [security2:error] [pid 872418:tid 872549] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/coffexium.php"] [unique_id "amuVMVymN6QYcoA7XB47zgAAAAE"]
[Thu Jul 30 13:17:21.127588 2026] [security2:error] [pid 872418:tid 872653] [client 20.91.139.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.139.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ftde.php"] [unique_id "amuVMVymN6QYcoA7XB47zwAAAGk"]
[Thu Jul 30 13:17:21.127706 2026] [security2:error] [pid 872418:tid 872653] [client 20.91.139.111:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.abudhabifurnituremoversandpackers.site"] [uri "/ftde.php"] [unique_id "amuVMVymN6QYcoA7XB47zwAAAGk"]
[Thu Jul 30 13:17:21.337829 2026] [security2:error] [pid 872418:tid 872637] [client 20.52.54.143:10403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/mini.php"] [unique_id "amuVMVymN6QYcoA7XB470QAAAFk"]
[Thu Jul 30 13:17:21.398500 2026] [security2:error] [pid 872418:tid 872587] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/simple.php"] [unique_id "amuVMVymN6QYcoA7XB470gAAACc"]
[Thu Jul 30 13:17:21.398628 2026] [security2:error] [pid 872418:tid 872587] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/simple.php"] [unique_id "amuVMVymN6QYcoA7XB470gAAACc"]
[Thu Jul 30 13:17:21.687624 2026] [security2:error] [pid 872418:tid 872665] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/fpwch.php"] [unique_id "amuVMVymN6QYcoA7XB471QAAAHU"]
[Thu Jul 30 13:17:21.687725 2026] [security2:error] [pid 872418:tid 872665] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/fpwch.php"] [unique_id "amuVMVymN6QYcoA7XB471QAAAHU"]
[Thu Jul 30 13:17:21.923840 2026] [security2:error] [pid 872418:tid 872644] [client 20.52.54.143:10411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/admin.php"] [unique_id "amuVMVymN6QYcoA7XB475wAAAGA"]
[Thu Jul 30 13:17:21.955541 2026] [security2:error] [pid 872418:tid 872613] [client 20.52.54.143:10378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/aa.php"] [unique_id "amuVMVymN6QYcoA7XB476AAAAEE"]
[Thu Jul 30 13:17:22.218238 2026] [security2:error] [pid 872418:tid 872566] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/dex.php"] [unique_id "amuVMlymN6QYcoA7XB476gAAABI"]
[Thu Jul 30 13:17:22.218442 2026] [security2:error] [pid 872418:tid 872566] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/dex.php"] [unique_id "amuVMlymN6QYcoA7XB476gAAABI"]
[Thu Jul 30 13:17:22.382081 2026] [core:notice] [pid 872418:tid 872666] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:22.525306 2026] [security2:error] [pid 872418:tid 872624] [client 4.225.166.222:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/1.php"] [unique_id "amuVMlymN6QYcoA7XB477AAAAEw"]
[Thu Jul 30 13:17:22.525444 2026] [security2:error] [pid 872418:tid 872624] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/1.php"] [unique_id "amuVMlymN6QYcoA7XB477AAAAEw"]
[Thu Jul 30 13:17:22.525560 2026] [security2:error] [pid 872418:tid 872624] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/1.php"] [unique_id "amuVMlymN6QYcoA7XB477AAAAEw"]
[Thu Jul 30 13:17:22.593199 2026] [security2:error] [pid 872418:tid 872619] [client 20.52.54.143:10425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-configs.php"] [unique_id "amuVMlymN6QYcoA7XB477QAAAEc"]
[Thu Jul 30 13:17:22.607922 2026] [security2:error] [pid 872418:tid 872669] [client 20.52.54.143:10322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/w.php"] [unique_id "amuVMlymN6QYcoA7XB477wAAAHk"]
[Thu Jul 30 13:17:22.817279 2026] [security2:error] [pid 872418:tid 872590] [client 4.225.166.222:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amuVMlymN6QYcoA7XB478gAAACo"]
[Thu Jul 30 13:17:22.817393 2026] [security2:error] [pid 872418:tid 872590] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amuVMlymN6QYcoA7XB478gAAACo"]
[Thu Jul 30 13:17:22.921815 2026] [security2:error] [pid 872418:tid 872594] [client 172.202.44.182:17600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/dropdown.php"] [unique_id "amuVMlymN6QYcoA7XB478wAAAC4"]
[Thu Jul 30 13:17:22.989574 2026] [security2:error] [pid 872418:tid 872580] [client 85.107.90.142:55894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVMlymN6QYcoA7XB478QAAACA"], referer: http://pkf.jo
[Thu Jul 30 13:17:23.046931 2026] [security2:error] [pid 872418:tid 872649] [client 220.181.108.178:44586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/jibm/similarity-policy"] [unique_id "amuVM1ymN6QYcoA7XB479AAAAGU"]
[Thu Jul 30 13:17:23.113427 2026] [security2:error] [pid 872418:tid 872606] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/config.json.php"] [unique_id "amuVM1ymN6QYcoA7XB479wAAADo"]
[Thu Jul 30 13:17:23.113537 2026] [security2:error] [pid 872418:tid 872606] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/config.json.php"] [unique_id "amuVM1ymN6QYcoA7XB479wAAADo"]
[Thu Jul 30 13:17:23.147190 2026] [security2:error] [pid 872418:tid 872521] [remote 216.73.217.142:28762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuVM1ymN6QYcoA7XB47-wAAF2Y"]
[Thu Jul 30 13:17:23.202945 2026] [security2:error] [pid 872418:tid 872548] [client 20.52.54.143:10385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/admin.php"] [unique_id "amuVM1ymN6QYcoA7XB47_AAAAAA"]
[Thu Jul 30 13:17:23.410970 2026] [security2:error] [pid 872418:tid 872591] [client 46.229.60.205:42801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVM1ymN6QYcoA7XB47-gAAACs"], referer: http://pkf.jo
[Thu Jul 30 13:17:23.411698 2026] [security2:error] [pid 872418:tid 872564] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/k2.php"] [unique_id "amuVM1ymN6QYcoA7XB47_QAAABA"]
[Thu Jul 30 13:17:23.411773 2026] [security2:error] [pid 872418:tid 872564] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/k2.php"] [unique_id "amuVM1ymN6QYcoA7XB47_QAAABA"]
[Thu Jul 30 13:17:23.440351 2026] [security2:error] [pid 872418:tid 872601] [client 20.52.54.143:10307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/php.php"] [unique_id "amuVM1ymN6QYcoA7XB47_gAAADU"]
[Thu Jul 30 13:17:23.464076 2026] [security2:error] [pid 872418:tid 872520] [remote 57.141.0.65:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/24984966950/feed/rss2/"] [unique_id "amuVM1ymN6QYcoA7XB47_wAAPWU"]
[Thu Jul 30 13:17:23.730939 2026] [security2:error] [pid 872418:tid 872568] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/raw.php"] [unique_id "amuVM1ymN6QYcoA7XB48AQAAABQ"]
[Thu Jul 30 13:17:23.731121 2026] [security2:error] [pid 872418:tid 872568] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/raw.php"] [unique_id "amuVM1ymN6QYcoA7XB48AQAAABQ"]
[Thu Jul 30 13:17:23.789651 2026] [security2:error] [pid 872418:tid 872597] [client 20.52.54.143:10374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuVM1ymN6QYcoA7XB48AgAAADE"]
[Thu Jul 30 13:17:23.892804 2026] [security2:error] [pid 872418:tid 872519] [remote 5.161.62.209:37448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alshateeintl.com"] [uri "/.env"] [unique_id "amuVM1ymN6QYcoA7XB48BwAAW2Q"]
[Thu Jul 30 13:17:23.899782 2026] [security2:error] [pid 872418:tid 872517] [remote 5.161.62.209:37458] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alshateeintl.com.khw.nyx.temporary.site"] [uri "/.env"] [unique_id "amuVM1ymN6QYcoA7XB48CAAAJmI"]
[Thu Jul 30 13:17:23.923726 2026] [security2:error] [pid 872418:tid 872626] [client 172.202.44.182:17607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/makeasmtp.php"] [unique_id "amuVM1ymN6QYcoA7XB48CQAAAE4"]
[Thu Jul 30 13:17:24.044153 2026] [security2:error] [pid 872418:tid 872659] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp.php"] [unique_id "amuVNFymN6QYcoA7XB48CwAAAG8"]
[Thu Jul 30 13:17:24.044259 2026] [security2:error] [pid 872418:tid 872659] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp.php"] [unique_id "amuVNFymN6QYcoA7XB48CwAAAG8"]
[Thu Jul 30 13:17:24.113710 2026] [security2:error] [pid 872418:tid 872633] [client 49.37.2.141:38124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVM1ymN6QYcoA7XB48AwAAAFU"], referer: http://pkf.jo
[Thu Jul 30 13:17:24.324309 2026] [security2:error] [pid 872418:tid 872652] [client 20.52.54.143:10394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/m.php"] [unique_id "amuVNFymN6QYcoA7XB48DgAAAGg"]
[Thu Jul 30 13:17:24.350731 2026] [security2:error] [pid 872418:tid 872588] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/fffm.php"] [unique_id "amuVNFymN6QYcoA7XB48DwAAACg"]
[Thu Jul 30 13:17:24.350839 2026] [security2:error] [pid 872418:tid 872588] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/fffm.php"] [unique_id "amuVNFymN6QYcoA7XB48DwAAACg"]
[Thu Jul 30 13:17:24.522704 2026] [security2:error] [pid 872418:tid 872600] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuVNFymN6QYcoA7XB48EgAAADQ"]
[Thu Jul 30 13:17:24.566957 2026] [security2:error] [pid 872418:tid 872630] [client 20.52.54.143:10395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/index.php"] [unique_id "amuVNFymN6QYcoA7XB48EwAAAFI"]
[Thu Jul 30 13:17:24.669924 2026] [security2:error] [pid 872418:tid 872574] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/111.php"] [unique_id "amuVNFymN6QYcoA7XB48FQAAABo"]
[Thu Jul 30 13:17:24.670071 2026] [security2:error] [pid 872418:tid 872574] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/111.php"] [unique_id "amuVNFymN6QYcoA7XB48FQAAABo"]
[Thu Jul 30 13:17:24.897150 2026] [security2:error] [pid 872418:tid 872658] [client 43.241.193.10:39340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVNFymN6QYcoA7XB48FAAAAG4"], referer: http://pkf.jo
[Thu Jul 30 13:17:24.996395 2026] [security2:error] [pid 872418:tid 872636] [client 4.225.166.222:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-includes/Requests/"] [unique_id "amuVNFymN6QYcoA7XB48FwAAAFg"]
[Thu Jul 30 13:17:24.996566 2026] [security2:error] [pid 872418:tid 872636] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-includes/Requests/"] [unique_id "amuVNFymN6QYcoA7XB48FwAAAFg"]
[Thu Jul 30 13:17:25.027261 2026] [security2:error] [pid 872418:tid 872667] [client 20.52.54.143:10391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuVNVymN6QYcoA7XB48GAAAAHc"]
[Thu Jul 30 13:17:25.307554 2026] [security2:error] [pid 872418:tid 872673] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/ws.php"] [unique_id "amuVNVymN6QYcoA7XB48GQAAAH0"]
[Thu Jul 30 13:17:25.307674 2026] [security2:error] [pid 872418:tid 872673] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/ws.php"] [unique_id "amuVNVymN6QYcoA7XB48GQAAAH0"]
[Thu Jul 30 13:17:25.446177 2026] [security2:error] [pid 872418:tid 872552] [client 20.52.54.143:10322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/a.php"] [unique_id "amuVNVymN6QYcoA7XB48GgAAAAQ"]
[Thu Jul 30 13:17:25.603389 2026] [security2:error] [pid 872418:tid 872619] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/coffee.php"] [unique_id "amuVNVymN6QYcoA7XB48HwAAAEc"]
[Thu Jul 30 13:17:25.603512 2026] [security2:error] [pid 872418:tid 872619] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/coffee.php"] [unique_id "amuVNVymN6QYcoA7XB48HwAAAEc"]
[Thu Jul 30 13:17:25.762710 2026] [core:error] [pid 872418:tid 872647] [client 20.52.54.143:10410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:25.762734 2026] [core:error] [pid 872418:tid 872647] [client 20.52.54.143:10410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:25.895454 2026] [security2:error] [pid 872418:tid 872671] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/goods.php"] [unique_id "amuVNVymN6QYcoA7XB48KAAAAHs"]
[Thu Jul 30 13:17:25.895534 2026] [security2:error] [pid 872418:tid 872671] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/goods.php"] [unique_id "amuVNVymN6QYcoA7XB48KAAAAHs"]
[Thu Jul 30 13:17:26.202556 2026] [security2:error] [pid 872418:tid 872594] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/about.php"] [unique_id "amuVNlymN6QYcoA7XB48KgAAAC4"]
[Thu Jul 30 13:17:26.202648 2026] [security2:error] [pid 872418:tid 872594] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/about.php"] [unique_id "amuVNlymN6QYcoA7XB48KgAAAC4"]
[Thu Jul 30 13:17:26.523196 2026] [security2:error] [pid 872418:tid 872601] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/about.php"] [unique_id "amuVNlymN6QYcoA7XB48NgAAADU"]
[Thu Jul 30 13:17:26.523316 2026] [security2:error] [pid 872418:tid 872601] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/about.php"] [unique_id "amuVNlymN6QYcoA7XB48NgAAADU"]
[Thu Jul 30 13:17:26.705992 2026] [security2:error] [pid 872418:tid 872646] [client 20.52.54.143:10414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuVNlymN6QYcoA7XB48PAAAAGI"]
[Thu Jul 30 13:17:26.810427 2026] [security2:error] [pid 872418:tid 872578] [client 40.77.167.35:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/article.php"] [unique_id "amuVNlymN6QYcoA7XB48OgAAAB4"]
[Thu Jul 30 13:17:26.814522 2026] [security2:error] [pid 872418:tid 872575] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/admin.php"] [unique_id "amuVNlymN6QYcoA7XB48PQAAABs"]
[Thu Jul 30 13:17:26.814671 2026] [security2:error] [pid 872418:tid 872575] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/admin.php"] [unique_id "amuVNlymN6QYcoA7XB48PQAAABs"]
[Thu Jul 30 13:17:27.117426 2026] [security2:error] [pid 872418:tid 872664] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/inputs.php"] [unique_id "amuVN1ymN6QYcoA7XB48PwAAAHQ"]
[Thu Jul 30 13:17:27.117543 2026] [security2:error] [pid 872418:tid 872664] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/inputs.php"] [unique_id "amuVN1ymN6QYcoA7XB48PwAAAHQ"]
[Thu Jul 30 13:17:27.217134 2026] [security2:error] [pid 872418:tid 872654] [client 191.232.199.39:40688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/chosen.php"] [unique_id "amuVN1ymN6QYcoA7XB48QAAAAGo"]
[Thu Jul 30 13:17:27.219678 2026] [security2:error] [pid 872418:tid 872626] [client 20.52.54.143:10309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin.php"] [unique_id "amuVN1ymN6QYcoA7XB48QQAAAE4"]
[Thu Jul 30 13:17:27.325871 2026] [security2:error] [pid 872418:tid 872639] [client 20.52.54.143:10305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/classwithtostring.php"] [unique_id "amuVN1ymN6QYcoA7XB48QgAAAFs"]
[Thu Jul 30 13:17:27.411261 2026] [security2:error] [pid 872418:tid 872593] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/inputs.php"] [unique_id "amuVN1ymN6QYcoA7XB48QwAAAC0"]
[Thu Jul 30 13:17:27.411398 2026] [security2:error] [pid 872418:tid 872593] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/inputs.php"] [unique_id "amuVN1ymN6QYcoA7XB48QwAAAC0"]
[Thu Jul 30 13:17:27.482279 2026] [security2:error] [pid 872418:tid 872627] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVNlymN6QYcoA7XB48OwAAT3w"]
[Thu Jul 30 13:17:27.739181 2026] [security2:error] [pid 872418:tid 872560] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/adminfuns.php"] [unique_id "amuVN1ymN6QYcoA7XB48SAAAAAw"]
[Thu Jul 30 13:17:27.739299 2026] [security2:error] [pid 872418:tid 872560] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/adminfuns.php"] [unique_id "amuVN1ymN6QYcoA7XB48SAAAAAw"]
[Thu Jul 30 13:17:27.803707 2026] [security2:error] [pid 872418:tid 872559] [client 20.52.54.143:10319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/size.php"] [unique_id "amuVN1ymN6QYcoA7XB48SQAAAAs"]
[Thu Jul 30 13:17:28.045453 2026] [security2:error] [pid 872418:tid 872623] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/404.php"] [unique_id "amuVOFymN6QYcoA7XB48SgAAAEs"]
[Thu Jul 30 13:17:28.045616 2026] [security2:error] [pid 872418:tid 872623] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/404.php"] [unique_id "amuVOFymN6QYcoA7XB48SgAAAEs"]
[Thu Jul 30 13:17:28.265466 2026] [security2:error] [pid 872418:tid 872663] [client 20.52.54.143:10321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/gmo.php"] [unique_id "amuVOFymN6QYcoA7XB48UAAAAHM"]
[Thu Jul 30 13:17:28.294928 2026] [security2:error] [pid 872418:tid 872660] [client 191.232.199.39:40651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/xleet.php"] [unique_id "amuVOFymN6QYcoA7XB48UQAAAHA"]
[Thu Jul 30 13:17:28.359152 2026] [security2:error] [pid 872418:tid 872574] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/xxx.php"] [unique_id "amuVOFymN6QYcoA7XB48UgAAABo"]
[Thu Jul 30 13:17:28.359290 2026] [security2:error] [pid 872418:tid 872574] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/xxx.php"] [unique_id "amuVOFymN6QYcoA7XB48UgAAABo"]
[Thu Jul 30 13:17:28.775343 2026] [security2:error] [pid 872418:tid 872536] [remote 216.73.217.142:36307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuVOFymN6QYcoA7XB48VQAAU3U"]
[Thu Jul 30 13:17:28.971753 2026] [security2:error] [pid 872418:tid 872655] [client 172.236.9.101:30782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVOFymN6QYcoA7XB48UwAAAGs"]
[Thu Jul 30 13:17:29.021751 2026] [security2:error] [pid 872418:tid 872618] [client 20.52.54.143:10356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuVOVymN6QYcoA7XB48WQAAAEY"]
[Thu Jul 30 13:17:29.138324 2026] [security2:error] [pid 872418:tid 872551] [client 172.202.44.182:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-sigunq.php"] [unique_id "amuVOVymN6QYcoA7XB48YAAAAAM"]
[Thu Jul 30 13:17:29.181050 2026] [security2:error] [pid 872418:tid 872661] [client 20.52.54.143:10406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuVOVymN6QYcoA7XB48YQAAAHE"]
[Thu Jul 30 13:17:29.322279 2026] [security2:error] [pid 872418:tid 872635] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/classwithtostring.php"] [unique_id "amuVOVymN6QYcoA7XB48ZgAAAFc"]
[Thu Jul 30 13:17:29.322377 2026] [security2:error] [pid 872418:tid 872635] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/classwithtostring.php"] [unique_id "amuVOVymN6QYcoA7XB48ZgAAAFc"]
[Thu Jul 30 13:17:29.396073 2026] [security2:error] [pid 872418:tid 872613] [client 191.232.199.39:31055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/ds.php"] [unique_id "amuVOVymN6QYcoA7XB48ZwAAAEE"]
[Thu Jul 30 13:17:29.507077 2026] [security2:error] [pid 872418:tid 872647] [client 45.191.45.4:34410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVOVymN6QYcoA7XB48YgAAAGM"], referer: http://pkf.jo
[Thu Jul 30 13:17:29.596831 2026] [security2:error] [pid 872418:tid 872614] [client 82.102.27.195:51450] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVOVymN6QYcoA7XB48aQAAAEI"]
[Thu Jul 30 13:17:29.596939 2026] [security2:error] [pid 872418:tid 872614] [client 82.102.27.195:51450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVOVymN6QYcoA7XB48aQAAAEI"]
[Thu Jul 30 13:17:29.615617 2026] [security2:error] [pid 872418:tid 872548] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/234ff.php"] [unique_id "amuVOVymN6QYcoA7XB48agAAAAA"]
[Thu Jul 30 13:17:29.615698 2026] [security2:error] [pid 872418:tid 872548] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/234ff.php"] [unique_id "amuVOVymN6QYcoA7XB48agAAAAA"]
[Thu Jul 30 13:17:29.907680 2026] [security2:error] [pid 872418:tid 872576] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVOVymN6QYcoA7XB48ZQAAABw"]
[Thu Jul 30 13:17:29.908931 2026] [security2:error] [pid 872418:tid 872625] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/133.php"] [unique_id "amuVOVymN6QYcoA7XB48cQAAAE0"]
[Thu Jul 30 13:17:29.909079 2026] [security2:error] [pid 872418:tid 872625] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/133.php"] [unique_id "amuVOVymN6QYcoA7XB48cQAAAE0"]
[Thu Jul 30 13:17:30.208998 2026] [security2:error] [pid 872418:tid 872568] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-ws68.php"] [unique_id "amuVOlymN6QYcoA7XB48cgAAABQ"]
[Thu Jul 30 13:17:30.209130 2026] [security2:error] [pid 872418:tid 872568] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/wp-ws68.php"] [unique_id "amuVOlymN6QYcoA7XB48cgAAABQ"]
[Thu Jul 30 13:17:30.228759 2026] [security2:error] [pid 872418:tid 872592] [client 20.52.54.143:10409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-the.php"] [unique_id "amuVOlymN6QYcoA7XB48cwAAACw"]
[Thu Jul 30 13:17:30.326303 2026] [security2:error] [pid 872418:tid 872591] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVOVymN6QYcoA7XB48bgAAACs"]
[Thu Jul 30 13:17:30.409750 2026] [security2:error] [pid 872418:tid 872582] [client 172.202.44.182:21283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wso112233.php"] [unique_id "amuVOlymN6QYcoA7XB48dQAAACI"]
[Thu Jul 30 13:17:30.511376 2026] [security2:error] [pid 872418:tid 872632] [client 191.232.199.39:40690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/f5.php"] [unique_id "amuVOlymN6QYcoA7XB48eAAAAFQ"]
[Thu Jul 30 13:17:30.523769 2026] [security2:error] [pid 872418:tid 872654] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/mgrr.php"] [unique_id "amuVOlymN6QYcoA7XB48eQAAAGo"]
[Thu Jul 30 13:17:30.523888 2026] [security2:error] [pid 872418:tid 872654] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/mgrr.php"] [unique_id "amuVOlymN6QYcoA7XB48eQAAAGo"]
[Thu Jul 30 13:17:30.823963 2026] [security2:error] [pid 872418:tid 872626] [client 20.52.54.143:10373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/404.php"] [unique_id "amuVOlymN6QYcoA7XB48ewAAAE4"]
[Thu Jul 30 13:17:30.829054 2026] [security2:error] [pid 872418:tid 872579] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/55.php"] [unique_id "amuVOlymN6QYcoA7XB48fAAAAB8"]
[Thu Jul 30 13:17:30.829199 2026] [security2:error] [pid 872418:tid 872579] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/55.php"] [unique_id "amuVOlymN6QYcoA7XB48fAAAAB8"]
[Thu Jul 30 13:17:31.071581 2026] [security2:error] [pid 872418:tid 872550] [client 20.52.54.143:10316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/403.php"] [unique_id "amuVO1ymN6QYcoA7XB48fwAAAAI"]
[Thu Jul 30 13:17:31.236335 2026] [security2:error] [pid 872418:tid 872593] [client 179.64.21.229:2132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVO1ymN6QYcoA7XB48ggAAAC0"]
[Thu Jul 30 13:17:31.236468 2026] [security2:error] [pid 872418:tid 872593] [client 179.64.21.229:2132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVO1ymN6QYcoA7XB48ggAAAC0"]
[Thu Jul 30 13:17:31.627666 2026] [security2:error] [pid 872418:tid 872581] [client 20.52.54.143:10430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/init.php"] [unique_id "amuVO1ymN6QYcoA7XB48gwAAACE"]
[Thu Jul 30 13:17:31.628058 2026] [security2:error] [pid 872418:tid 872599] [client 191.232.199.39:6201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/god4m.php"] [unique_id "amuVO1ymN6QYcoA7XB48hAAAADM"]
[Thu Jul 30 13:17:32.231449 2026] [security2:error] [pid 872418:tid 872600] [client 216.98.211.28:12875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVO1ymN6QYcoA7XB48iAAAADQ"], referer: http://pkf.jo
[Thu Jul 30 13:17:32.627715 2026] [security2:error] [pid 872418:tid 872587] [client 20.52.54.143:10390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/file5.php"] [unique_id "amuVPFymN6QYcoA7XB48jwAAACc"]
[Thu Jul 30 13:17:32.683490 2026] [security2:error] [pid 872418:tid 872555] [client 20.52.54.143:11141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuVPFymN6QYcoA7XB48kAAAAAc"]
[Thu Jul 30 13:17:32.738247 2026] [security2:error] [pid 872418:tid 872630] [client 172.236.9.101:28762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVPFymN6QYcoA7XB48iQAAAFI"]
[Thu Jul 30 13:17:32.793189 2026] [security2:error] [pid 872418:tid 872637] [client 191.232.199.39:48703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/info.php"] [unique_id "amuVPFymN6QYcoA7XB48kgAAAFk"]
[Thu Jul 30 13:17:33.038017 2026] [security2:error] [pid 872418:tid 872653] [client 5.37.108.192:49794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVPFymN6QYcoA7XB48kQAAAGk"], referer: http://pkf.jo
[Thu Jul 30 13:17:33.172758 2026] [security2:error] [pid 872418:tid 872432] [remote 216.73.217.142:36307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuVPVymN6QYcoA7XB48kwAAfQ0"]
[Thu Jul 30 13:17:34.038096 2026] [security2:error] [pid 872418:tid 872629] [client 20.52.54.143:10422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/as.php"] [unique_id "amuVPlymN6QYcoA7XB48mAAAAFE"]
[Thu Jul 30 13:17:34.163833 2026] [security2:error] [pid 872418:tid 872665] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVPVymN6QYcoA7XB48lQAAdRU"]
[Thu Jul 30 13:17:34.303733 2026] [security2:error] [pid 872418:tid 872551] [client 191.232.199.39:31053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/.__info.php"] [unique_id "amuVPlymN6QYcoA7XB48mwAAAAM"]
[Thu Jul 30 13:17:34.396206 2026] [security2:error] [pid 872418:tid 872573] [client 20.52.54.143:10415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuVPlymN6QYcoA7XB48oAAAABk"]
[Thu Jul 30 13:17:34.606034 2026] [security2:error] [pid 872418:tid 872565] [client 20.52.54.143:11151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuVPlymN6QYcoA7XB48pgAAABE"]
[Thu Jul 30 13:17:34.990154 2026] [security2:error] [pid 872418:tid 872628] [client 20.52.54.143:10431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/shell.php"] [unique_id "amuVPlymN6QYcoA7XB48qwAAAFA"]
[Thu Jul 30 13:17:35.199901 2026] [security2:error] [pid 872418:tid 872444] [remote 159.89.87.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.87.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "widedaddy.com"] [uri "/wp-login.php"] [unique_id "amuVPlymN6QYcoA7XB48qgAALhk"]
[Thu Jul 30 13:17:35.548941 2026] [security2:error] [pid 872418:tid 872609] [client 20.52.54.143:10324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/f35.php"] [unique_id "amuVP1ymN6QYcoA7XB48rwAAAD0"]
[Thu Jul 30 13:17:35.722759 2026] [security2:error] [pid 872418:tid 872557] [client 191.232.199.39:6173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/0.php"] [unique_id "amuVP1ymN6QYcoA7XB48sAAAAAk"]
[Thu Jul 30 13:17:35.768874 2026] [security2:error] [pid 872418:tid 872592] [client 20.52.54.143:10318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuVP1ymN6QYcoA7XB48sQAAACw"]
[Thu Jul 30 13:17:35.813377 2026] [security2:error] [pid 872418:tid 872590] [client 172.202.44.182:21275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/alfanew.php"] [unique_id "amuVP1ymN6QYcoA7XB48sgAAACo"]
[Thu Jul 30 13:17:36.361889 2026] [security2:error] [pid 872418:tid 872582] [client 20.52.54.143:10427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/new.php"] [unique_id "amuVQFymN6QYcoA7XB48tQAAACI"]
[Thu Jul 30 13:17:36.611910 2026] [security2:error] [pid 872418:tid 872610] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/.env.backup"] [unique_id "amuVQFymN6QYcoA7XB48twAAAD4"]
[Thu Jul 30 13:17:36.785637 2026] [security2:error] [pid 872418:tid 872656] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/.env.bak"] [unique_id "amuVQFymN6QYcoA7XB48uAAAAGw"]
[Thu Jul 30 13:17:36.787458 2026] [security2:error] [pid 872418:tid 872664] [client 20.52.54.143:10315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/plugins.php"] [unique_id "amuVQFymN6QYcoA7XB48uQAAAHQ"]
[Thu Jul 30 13:17:36.860888 2026] [security2:error] [pid 872418:tid 872632] [client 172.236.9.101:38487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVQFymN6QYcoA7XB48tAAAAFQ"]
[Thu Jul 30 13:17:36.952802 2026] [security2:error] [pid 872418:tid 872668] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/.env.old"] [unique_id "amuVQFymN6QYcoA7XB48uwAAAHg"]
[Thu Jul 30 13:17:36.973510 2026] [security2:error] [pid 872418:tid 872605] [client 191.232.199.39:31044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/07.php"] [unique_id "amuVQFymN6QYcoA7XB48vAAAADk"]
[Thu Jul 30 13:17:36.988505 2026] [security2:error] [pid 872418:tid 872634] [client 20.52.54.143:10309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/adminfuns.php"] [unique_id "amuVQFymN6QYcoA7XB48vQAAAFY"]
[Thu Jul 30 13:17:37.070660 2026] [autoindex:error] [pid 872418:tid 872560] [client 43.134.62.67:53668] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:17:37.389500 2026] [security2:error] [pid 872418:tid 872599] [client 20.52.54.143:11163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuVQVymN6QYcoA7XB48wgAAADM"]
[Thu Jul 30 13:17:37.672920 2026] [core:error] [pid 872418:tid 872652] [client 20.52.54.143:10421] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:37.672949 2026] [core:error] [pid 872418:tid 872652] [client 20.52.54.143:10421] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:37.681525 2026] [security2:error] [pid 872418:tid 872581] [client 172.202.44.182:14092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/fw.php"] [unique_id "amuVQVymN6QYcoA7XB48xgAAACE"]
[Thu Jul 30 13:17:37.835898 2026] [security2:error] [pid 872418:tid 872559] [client 50.6.43.217:49444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuVQVymN6QYcoA7XB48vwAAAAs"]
[Thu Jul 30 13:17:37.911454 2026] [security2:error] [pid 872418:tid 872663] [client 147.236.231.195:29730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVQVymN6QYcoA7XB48xAAAAHM"], referer: http://pkf.jo
[Thu Jul 30 13:17:37.919747 2026] [security2:error] [pid 872418:tid 872600] [client 82.12.184.37:50612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVQVymN6QYcoA7XB48wwAAADQ"], referer: http://pkf.jo
[Thu Jul 30 13:17:38.044299 2026] [security2:error] [pid 872418:tid 872455] [remote 57.141.0.25:51170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuVQlymN6QYcoA7XB48ywAABiQ"]
[Thu Jul 30 13:17:38.129179 2026] [security2:error] [pid 872418:tid 872574] [client 191.232.199.39:31043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/dropdown.php"] [unique_id "amuVQlymN6QYcoA7XB48zAAAABo"]
[Thu Jul 30 13:17:38.215486 2026] [security2:error] [pid 872418:tid 872658] [client 20.52.54.143:10351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/go.php"] [unique_id "amuVQlymN6QYcoA7XB48zQAAAG4"]
[Thu Jul 30 13:17:38.480822 2026] [security2:error] [pid 872418:tid 872675] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/.env.copy"] [unique_id "amuVQlymN6QYcoA7XB480QAAAH8"]
[Thu Jul 30 13:17:38.589326 2026] [security2:error] [pid 872418:tid 872587] [client 50.6.43.217:49458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuVQVymN6QYcoA7XB48yAAAACc"]
[Thu Jul 30 13:17:38.600378 2026] [core:error] [pid 872418:tid 872653] [client 20.52.54.143:10368] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:38.600411 2026] [core:error] [pid 872418:tid 872653] [client 20.52.54.143:10368] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:38.665331 2026] [security2:error] [pid 872418:tid 872660] [client 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVQlymN6QYcoA7XB48ygAAcCA"]
[Thu Jul 30 13:17:38.696779 2026] [security2:error] [pid 872418:tid 872618] [client 177.202.143.1:20297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVQlymN6QYcoA7XB480AAAAEY"], referer: http://pkf.jo
[Thu Jul 30 13:17:38.744871 2026] [security2:error] [pid 872418:tid 872552] [client 172.236.9.101:53079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVQlymN6QYcoA7XB48zgAAAAQ"]
[Thu Jul 30 13:17:38.790025 2026] [security2:error] [pid 872418:tid 872448] [remote 216.73.217.142:28167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVQlymN6QYcoA7XB481QAAdx0"]
[Thu Jul 30 13:17:38.857928 2026] [security2:error] [pid 872418:tid 872595] [client 152.207.22.110:34300] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuVQlymN6QYcoA7XB481gAAAC8"]
[Thu Jul 30 13:17:39.003736 2026] [security2:error] [pid 872418:tid 872657] [client 172.236.9.101:43946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVQlymN6QYcoA7XB48zwAAAG0"]
[Thu Jul 30 13:17:39.008324 2026] [security2:error] [pid 872418:tid 872596] [client 105.69.102.60:42426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVQlymN6QYcoA7XB481AAAADA"], referer: http://pkf.jo
[Thu Jul 30 13:17:39.123277 2026] [security2:error] [pid 872418:tid 872665] [client 20.52.54.143:10383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/test1.php"] [unique_id "amuVQ1ymN6QYcoA7XB481wAAAHU"]
[Thu Jul 30 13:17:39.199791 2026] [security2:error] [pid 872418:tid 872551] [client 152.207.22.110:48264] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuVQ1ymN6QYcoA7XB482AAAAAM"]
[Thu Jul 30 13:17:39.221812 2026] [security2:error] [pid 872418:tid 872624] [client 191.232.199.39:6766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/makeasmtp.php"] [unique_id "amuVQ1ymN6QYcoA7XB482QAAAEw"]
[Thu Jul 30 13:17:39.347736 2026] [security2:error] [pid 872418:tid 872612] [client 20.52.54.143:10337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/fm.php"] [unique_id "amuVQ1ymN6QYcoA7XB482wAAAEA"]
[Thu Jul 30 13:17:39.956573 2026] [security2:error] [pid 872418:tid 872647] [client 20.52.54.143:10311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/images/index.php"] [unique_id "amuVQ1ymN6QYcoA7XB483wAAAGM"]
[Thu Jul 30 13:17:40.188736 2026] [security2:error] [pid 872418:tid 872603] [client 172.202.44.182:21242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amuVQ1ymN6QYcoA7XB483QAAADc"]
[Thu Jul 30 13:17:40.447125 2026] [security2:error] [pid 872418:tid 872614] [client 191.232.199.39:6914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-sigunq.php"] [unique_id "amuVRFymN6QYcoA7XB484QAAAEI"]
[Thu Jul 30 13:17:41.147198 2026] [security2:error] [pid 872418:tid 872649] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVRFymN6QYcoA7XB484wAAZSI"]
[Thu Jul 30 13:17:41.335369 2026] [security2:error] [pid 872418:tid 872632] [client 172.202.44.182:21206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/simple.php"] [unique_id "amuVRVymN6QYcoA7XB486AAAAFQ"]
[Thu Jul 30 13:17:41.634716 2026] [security2:error] [pid 872418:tid 872605] [client 191.232.199.39:6155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wso112233.php"] [unique_id "amuVRVymN6QYcoA7XB486QAAADk"]
[Thu Jul 30 13:17:41.640305 2026] [core:error] [pid 872418:tid 872585] [client 20.52.54.143:10429] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:41.640381 2026] [core:error] [pid 872418:tid 872585] [client 20.52.54.143:10429] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:41.838357 2026] [security2:error] [pid 872418:tid 872599] [client 20.52.54.143:10328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/asd.php"] [unique_id "amuVRVymN6QYcoA7XB487wAAADM"]
[Thu Jul 30 13:17:41.977043 2026] [security2:error] [pid 872418:tid 872567] [client 179.64.21.229:28376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVRVymN6QYcoA7XB488QAAABM"]
[Thu Jul 30 13:17:41.981059 2026] [security2:error] [pid 872418:tid 872567] [client 179.64.21.229:28376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVRVymN6QYcoA7XB488QAAABM"]
[Thu Jul 30 13:17:42.295651 2026] [proxy:error] [pid 872418:tid 872663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:17:42.295750 2026] [proxy_http:error] [pid 872418:tid 872663] [client 18.211.55.47:63278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:17:42.296546 2026] [proxy:error] [pid 872418:tid 872663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:17:42.296598 2026] [proxy_http:error] [pid 872418:tid 872663] [client 18.211.55.47:63278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:17:42.305798 2026] [security2:error] [pid 872418:tid 872652] [client 172.202.44.182:14099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/classsmtps.php"] [unique_id "amuVRlymN6QYcoA7XB48_QAAAGg"]
[Thu Jul 30 13:17:42.312397 2026] [proxy:error] [pid 872418:tid 872655] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:17:42.312467 2026] [proxy_http:error] [pid 872418:tid 872655] [client 18.211.55.47:21989] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:17:42.313054 2026] [proxy:error] [pid 872418:tid 872655] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:17:42.313105 2026] [proxy_http:error] [pid 872418:tid 872655] [client 18.211.55.47:21989] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:17:42.383448 2026] [security2:error] [pid 872418:tid 872581] [client 20.52.54.143:10417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuVRlymN6QYcoA7XB49AAAAACE"]
[Thu Jul 30 13:17:42.408797 2026] [security2:error] [pid 872418:tid 872462] [remote 57.141.0.66:61350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuVRlymN6QYcoA7XB49AQAACys"]
[Thu Jul 30 13:17:42.779269 2026] [security2:error] [pid 872418:tid 872556] [client 191.232.199.39:6726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/alfanew.php"] [unique_id "amuVRlymN6QYcoA7XB49AwAAAAg"]
[Thu Jul 30 13:17:43.111219 2026] [security2:error] [pid 872418:tid 872673] [client 20.52.54.143:10396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/file.php"] [unique_id "amuVR1ymN6QYcoA7XB49BAAAAH0"]
[Thu Jul 30 13:17:43.160878 2026] [security2:error] [pid 872418:tid 872596] [client 195.170.172.102:49966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "siatfc.com"] [uri "/"] [unique_id "amuVR1ymN6QYcoA7XB49BQAAADA"]
[Thu Jul 30 13:17:43.160989 2026] [security2:error] [pid 872418:tid 872596] [client 195.170.172.102:49966] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "siatfc.com"] [uri "/"] [unique_id "amuVR1ymN6QYcoA7XB49BQAAADA"]
[Thu Jul 30 13:17:43.191033 2026] [security2:error] [pid 872418:tid 872465] [remote 216.73.217.142:28167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVR1ymN6QYcoA7XB49BgAAGC4"]
[Thu Jul 30 13:17:43.372182 2026] [security2:error] [pid 872418:tid 872669] [client 172.202.44.182:21405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-blog-header.php"] [unique_id "amuVR1ymN6QYcoA7XB49CgAAAHk"]
[Thu Jul 30 13:17:43.409118 2026] [security2:error] [pid 872418:tid 872619] [client 20.52.54.143:10428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuVR1ymN6QYcoA7XB49CwAAAEc"]
[Thu Jul 30 13:17:43.613072 2026] [core:error] [pid 872418:tid 872612] [client 20.52.54.143:11160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:43.613094 2026] [core:error] [pid 872418:tid 872612] [client 20.52.54.143:11160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:43.805109 2026] [security2:error] [pid 872418:tid 872648] [client 172.236.9.101:64791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVR1ymN6QYcoA7XB49CAAAAGQ"]
[Thu Jul 30 13:17:43.922237 2026] [security2:error] [pid 872418:tid 872565] [client 191.232.199.39:6157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/fw.php"] [unique_id "amuVR1ymN6QYcoA7XB49EwAAABE"]
[Thu Jul 30 13:17:43.925037 2026] [security2:error] [pid 872418:tid 872624] [client 172.236.9.101:3840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVR1ymN6QYcoA7XB49DAAAAEw"]
[Thu Jul 30 13:17:44.584552 2026] [security2:error] [pid 872418:tid 872606] [client 20.52.54.143:10387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/bolt.php"] [unique_id "amuVSFymN6QYcoA7XB49FQAAADo"]
[Thu Jul 30 13:17:44.793628 2026] [security2:error] [pid 872418:tid 872457] [remote 97.74.93.24:35646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amuVSFymN6QYcoA7XB49FgAAUCY"]
[Thu Jul 30 13:17:44.881992 2026] [security2:error] [pid 872418:tid 872576] [client 172.202.44.182:21415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-trackback.php"] [unique_id "amuVSFymN6QYcoA7XB49HAAAABw"]
[Thu Jul 30 13:17:45.065307 2026] [security2:error] [pid 872418:tid 872608] [client 20.52.54.143:10426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/atomlib.php"] [unique_id "amuVSVymN6QYcoA7XB49HgAAADw"]
[Thu Jul 30 13:17:45.272964 2026] [security2:error] [pid 872418:tid 872594] [client 191.232.199.39:6971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-login.php"] [unique_id "amuVSVymN6QYcoA7XB49HQAAAC4"]
[Thu Jul 30 13:17:45.563557 2026] [security2:error] [pid 872418:tid 872641] [client 20.52.54.143:10382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/3.php"] [unique_id "amuVSVymN6QYcoA7XB49IwAAAF0"]
[Thu Jul 30 13:17:45.995804 2026] [security2:error] [pid 872418:tid 872664] [client 172.202.44.182:21192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-signup.php"] [unique_id "amuVSVymN6QYcoA7XB49JgAAAHQ"]
[Thu Jul 30 13:17:46.355547 2026] [security2:error] [pid 872418:tid 872550] [client 191.232.199.39:6774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/simple.php"] [unique_id "amuVSlymN6QYcoA7XB49LgAAAAI"]
[Thu Jul 30 13:17:46.387608 2026] [security2:error] [pid 872418:tid 872634] [client 20.52.54.143:10390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuVSlymN6QYcoA7XB49MAAAAFY"]
[Thu Jul 30 13:17:46.641595 2026] [security2:error] [pid 872418:tid 872469] [remote 144.79.133.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuVSlymN6QYcoA7XB49NQAAIzI"]
[Thu Jul 30 13:17:46.644904 2026] [proxy:error] [pid 872418:tid 872652] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:17:46.644966 2026] [proxy_http:error] [pid 872418:tid 872652] [client 18.211.55.47:51134] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:17:46.645552 2026] [proxy:error] [pid 872418:tid 872652] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:17:46.645602 2026] [proxy_http:error] [pid 872418:tid 872652] [client 18.211.55.47:51134] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:17:46.653530 2026] [proxy:error] [pid 872418:tid 872554] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:17:46.653635 2026] [proxy_http:error] [pid 872418:tid 872554] [client 18.211.55.47:43884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:17:46.654709 2026] [proxy:error] [pid 872418:tid 872554] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:17:46.654774 2026] [proxy_http:error] [pid 872418:tid 872554] [client 18.211.55.47:43884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:17:46.815805 2026] [security2:error] [pid 872418:tid 872599] [client 177.230.179.74:51804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVSlymN6QYcoA7XB49MgAAADM"], referer: http://pkf.jo
[Thu Jul 30 13:17:46.916335 2026] [security2:error] [pid 872418:tid 872581] [client 20.52.54.143:10369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/222.php"] [unique_id "amuVSlymN6QYcoA7XB49QAAAACE"]
[Thu Jul 30 13:17:46.956825 2026] [security2:error] [pid 872418:tid 872640] [client 172.202.44.182:21245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-comments-post.php"] [unique_id "amuVSlymN6QYcoA7XB49QgAAAFw"]
[Thu Jul 30 13:17:47.147825 2026] [core:notice] [pid 872418:tid 872472] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:47.555661 2026] [security2:error] [pid 872418:tid 872624] [client 20.52.54.143:10367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/inputs.php"] [unique_id "amuVS1ymN6QYcoA7XB49UwAAAEw"]
[Thu Jul 30 13:17:47.659489 2026] [security2:error] [pid 872418:tid 872580] [client 102.219.155.5:38978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVS1ymN6QYcoA7XB49TQAAACA"], referer: http://pkf.jo
[Thu Jul 30 13:17:47.739171 2026] [security2:error] [pid 872418:tid 872643] [client 191.232.199.39:6954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/classsmtps.php"] [unique_id "amuVS1ymN6QYcoA7XB49VQAAAF8"]
[Thu Jul 30 13:17:47.742111 2026] [security2:error] [pid 872418:tid 872564] [client 20.52.54.143:10408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuVS1ymN6QYcoA7XB49VgAAABA"]
[Thu Jul 30 13:17:47.777523 2026] [core:notice] [pid 872418:tid 872479] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:47.935873 2026] [security2:error] [pid 872418:tid 872566] [client 172.236.9.101:32393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVS1ymN6QYcoA7XB49UQAAABI"]
[Thu Jul 30 13:17:48.579873 2026] [security2:error] [pid 872418:tid 872575] [client 82.102.27.195:41018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVTFymN6QYcoA7XB49YQAAABs"]
[Thu Jul 30 13:17:48.579984 2026] [security2:error] [pid 872418:tid 872575] [client 82.102.27.195:41018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVTFymN6QYcoA7XB49YQAAABs"]
[Thu Jul 30 13:17:48.780500 2026] [security2:error] [pid 872418:tid 872557] [client 20.52.54.143:10567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/index.php"] [unique_id "amuVTFymN6QYcoA7XB49YgAAAAk"]
[Thu Jul 30 13:17:48.798290 2026] [security2:error] [pid 872418:tid 872478] [remote 216.73.217.142:50677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuVTFymN6QYcoA7XB49YwAAIjs"]
[Thu Jul 30 13:17:48.830773 2026] [security2:error] [pid 872418:tid 872571] [client 20.52.54.143:10418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuVTFymN6QYcoA7XB49ZAAAABc"]
[Thu Jul 30 13:17:49.033712 2026] [security2:error] [pid 872418:tid 872659] [client 191.232.199.39:6752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-blog-header.php"] [unique_id "amuVTVymN6QYcoA7XB49ZgAAAG8"]
[Thu Jul 30 13:17:49.142775 2026] [security2:error] [pid 872418:tid 872651] [client 181.208.72.81:54784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVTFymN6QYcoA7XB49ZQAAAGc"], referer: http://pkf.jo
[Thu Jul 30 13:17:49.472419 2026] [core:error] [pid 872418:tid 872641] [client 20.52.54.143:10350] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:49.472449 2026] [core:error] [pid 872418:tid 872641] [client 20.52.54.143:10350] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:49.628129 2026] [security2:error] [pid 872418:tid 872633] [client 110.249.202.118:13868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cnpinyin.com"] [uri "/robots.txt"] [unique_id "amuVTVymN6QYcoA7XB49awAAAFU"]
[Thu Jul 30 13:17:49.841804 2026] [security2:error] [pid 872418:tid 872590] [client 172.236.9.101:20388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVTVymN6QYcoA7XB49aQAAACo"]
[Thu Jul 30 13:17:49.851600 2026] [security2:error] [pid 872418:tid 872597] [client 20.52.54.143:10384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuVTVymN6QYcoA7XB49bAAAADE"]
[Thu Jul 30 13:17:50.187222 2026] [security2:error] [pid 872418:tid 872601] [client 191.232.199.39:31054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-trackback.php"] [unique_id "amuVTlymN6QYcoA7XB49cQAAADU"]
[Thu Jul 30 13:17:50.189161 2026] [security2:error] [pid 872418:tid 872593] [client 20.52.54.143:10428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/admin.php"] [unique_id "amuVTlymN6QYcoA7XB49cgAAAC0"]
[Thu Jul 30 13:17:50.388475 2026] [security2:error] [pid 872418:tid 872488] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/caches.php"] [unique_id "amuVTlymN6QYcoA7XB49dQAAMkU"]
[Thu Jul 30 13:17:50.790414 2026] [security2:error] [pid 872418:tid 872668] [client 20.52.54.143:10346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-configs.php"] [unique_id "amuVTlymN6QYcoA7XB49eQAAAHg"]
[Thu Jul 30 13:17:50.911553 2026] [security2:error] [pid 872418:tid 872639] [client 20.52.54.143:10405] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.asian-connect.com"] [uri "/wp-content/1.php"] [unique_id "amuVTlymN6QYcoA7XB49fQAAAFs"]
[Thu Jul 30 13:17:50.911678 2026] [security2:error] [pid 872418:tid 872639] [client 20.52.54.143:10405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/1.php"] [unique_id "amuVTlymN6QYcoA7XB49fQAAAFs"]
[Thu Jul 30 13:17:50.929763 2026] [security2:error] [pid 872418:tid 872550] [client 185.191.171.16:53456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/09/25/covid-19-brasil-tem-139-mil-mortes-e-465-milhoes-de-casos-acumulados/"] [unique_id "amuVTlymN6QYcoA7XB49fgAAAAI"]
[Thu Jul 30 13:17:50.929864 2026] [security2:error] [pid 872418:tid 872550] [client 185.191.171.16:53456] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/09/25/covid-19-brasil-tem-139-mil-mortes-e-465-milhoes-de-casos-acumulados/"] [unique_id "amuVTlymN6QYcoA7XB49fgAAAAI"]
[Thu Jul 30 13:17:50.959494 2026] [core:notice] [pid 872418:tid 872655] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:51.029794 2026] [core:notice] [pid 872418:tid 872485] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:51.371950 2026] [security2:error] [pid 872418:tid 872675] [client 20.52.54.143:10426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/php.php"] [unique_id "amuVT1ymN6QYcoA7XB49ggAAAH8"]
[Thu Jul 30 13:17:51.495320 2026] [security2:error] [pid 872418:tid 872559] [client 191.232.199.39:6944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-signup.php"] [unique_id "amuVT1ymN6QYcoA7XB49gwAAAAs"]
[Thu Jul 30 13:17:51.996774 2026] [security2:error] [pid 872418:tid 872653] [client 20.52.54.143:10304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/index.php"] [unique_id "amuVT1ymN6QYcoA7XB49iQAAAGk"]
[Thu Jul 30 13:17:52.470706 2026] [security2:error] [pid 872418:tid 872618] [client 179.64.21.229:32091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVUFymN6QYcoA7XB49iwAAAEY"]
[Thu Jul 30 13:17:52.477516 2026] [security2:error] [pid 872418:tid 872618] [client 179.64.21.229:32091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVUFymN6QYcoA7XB49iwAAAEY"]
[Thu Jul 30 13:17:52.793803 2026] [security2:error] [pid 872418:tid 872551] [client 191.232.199.39:6745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-comments-post.php"] [unique_id "amuVUFymN6QYcoA7XB49jQAAAAM"]
[Thu Jul 30 13:17:53.026931 2026] [security2:error] [pid 872418:tid 872669] [client 20.52.54.143:10412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/a.php"] [unique_id "amuVUVymN6QYcoA7XB49jgAAAHk"]
[Thu Jul 30 13:17:53.078416 2026] [security2:error] [pid 872418:tid 872611] [client 172.237.109.114:35465] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/certificates/alseermarine.com_privkey.pem"] [unique_id "amuVUVymN6QYcoA7XB49jwAAAD8"]
[Thu Jul 30 13:17:53.194424 2026] [security2:error] [pid 872418:tid 872490] [remote 216.73.217.142:50677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVUVymN6QYcoA7XB49lgAATEc"]
[Thu Jul 30 13:17:53.285034 2026] [core:notice] [pid 872418:tid 872491] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:53.374019 2026] [security2:error] [pid 872418:tid 872640] [client 20.52.54.143:10325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/plugin.php"] [unique_id "amuVUVymN6QYcoA7XB49mQAAAFw"]
[Thu Jul 30 13:17:53.509752 2026] [security2:error] [pid 872418:tid 872658] [client 172.202.44.182:17617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-mail.php"] [unique_id "amuVUVymN6QYcoA7XB49mwAAAG4"]
[Thu Jul 30 13:17:53.591912 2026] [security2:error] [pid 872418:tid 872616] [client 172.237.109.114:41860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVUVymN6QYcoA7XB49kAAAAEQ"]
[Thu Jul 30 13:17:53.592500 2026] [security2:error] [pid 872418:tid 872620] [client 172.237.109.114:16580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVUVymN6QYcoA7XB49kQAAAEg"]
[Thu Jul 30 13:17:53.659062 2026] [security2:error] [pid 872418:tid 872553] [client 172.237.109.114:49981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVUVymN6QYcoA7XB49kwAAAAU"]
[Thu Jul 30 13:17:53.692123 2026] [security2:error] [pid 872418:tid 872612] [client 172.237.109.114:46781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVUVymN6QYcoA7XB49kgAAAEA"]
[Thu Jul 30 13:17:53.751177 2026] [security2:error] [pid 872418:tid 872570] [client 172.237.109.114:40564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVUVymN6QYcoA7XB49lAAAABY"]
[Thu Jul 30 13:17:53.773136 2026] [security2:error] [pid 872418:tid 872562] [client 172.237.109.114:43700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVUVymN6QYcoA7XB49lQAAAA4"]
[Thu Jul 30 13:17:53.904022 2026] [core:error] [pid 872418:tid 872564] [client 20.52.54.143:10365] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:53.904050 2026] [core:error] [pid 872418:tid 872564] [client 20.52.54.143:10365] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:54.109134 2026] [security2:error] [pid 872418:tid 872647] [client 20.52.54.143:10334] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.asian-connect.com"] [uri "/1.php"] [unique_id "amuVUlymN6QYcoA7XB49oQAAAGM"]
[Thu Jul 30 13:17:54.109293 2026] [security2:error] [pid 872418:tid 872647] [client 20.52.54.143:10334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/1.php"] [unique_id "amuVUlymN6QYcoA7XB49oQAAAGM"]
[Thu Jul 30 13:17:54.111463 2026] [security2:error] [pid 872418:tid 872663] [client 191.232.199.39:6923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-mail.php"] [unique_id "amuVUlymN6QYcoA7XB49ogAAAHM"]
[Thu Jul 30 13:17:54.163996 2026] [security2:error] [pid 872418:tid 872642] [client 43.173.182.70:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amuVUVymN6QYcoA7XB49nwAAAF4"]
[Thu Jul 30 13:17:54.416146 2026] [security2:error] [pid 872418:tid 872492] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuVUlymN6QYcoA7XB49pAAAYkk"]
[Thu Jul 30 13:17:54.628797 2026] [security2:error] [pid 872418:tid 872578] [client 172.202.44.182:14131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-activate.php"] [unique_id "amuVUlymN6QYcoA7XB49pwAAAB4"]
[Thu Jul 30 13:17:54.814180 2026] [core:notice] [pid 872418:tid 872610] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:17:54.821544 2026] [security2:error] [pid 872418:tid 872610] [client 43.172.195.51:48362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amuVUlymN6QYcoA7XB49qAAAAD4"], referer: https://carnetdeshopping.com/index.php/typography/
[Thu Jul 30 13:17:54.905948 2026] [security2:error] [pid 872418:tid 872608] [client 172.236.9.101:52245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVUlymN6QYcoA7XB49pQAAADw"]
[Thu Jul 30 13:17:55.108271 2026] [security2:error] [pid 872418:tid 872582] [client 20.52.54.143:10407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/gg.php"] [unique_id "amuVU1ymN6QYcoA7XB49qQAAACI"]
[Thu Jul 30 13:17:55.596270 2026] [security2:error] [pid 872418:tid 872593] [client 191.232.199.39:31085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-activate.php"] [unique_id "amuVU1ymN6QYcoA7XB49xgAAAC0"]
[Thu Jul 30 13:17:55.956076 2026] [core:error] [pid 872418:tid 872615] [client 20.52.54.143:10317] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:55.956100 2026] [core:error] [pid 872418:tid 872615] [client 20.52.54.143:10317] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:17:56.306888 2026] [security2:error] [pid 872418:tid 872558] [client 172.202.44.182:14093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/post.php"] [unique_id "amuVVFymN6QYcoA7XB490QAAAAo"]
[Thu Jul 30 13:17:56.951773 2026] [security2:error] [pid 872418:tid 872525] [remote 57.141.0.10:25058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuVVFymN6QYcoA7XB491wAAQGo"]
[Thu Jul 30 13:17:57.139351 2026] [security2:error] [pid 872418:tid 872604] [client 191.232.199.39:6161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/post.php"] [unique_id "amuVVVymN6QYcoA7XB492wAAADg"]
[Thu Jul 30 13:17:57.175952 2026] [security2:error] [pid 872418:tid 872600] [client 20.52.54.143:10420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp.php"] [unique_id "amuVVVymN6QYcoA7XB493AAAADQ"]
[Thu Jul 30 13:17:57.304093 2026] [security2:error] [pid 872418:tid 872606] [client 172.202.44.182:21377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-2019.php"] [unique_id "amuVVVymN6QYcoA7XB493gAAADo"]
[Thu Jul 30 13:17:57.695907 2026] [security2:error] [pid 872418:tid 872594] [client 20.52.54.143:11153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuVVVymN6QYcoA7XB493wAAAC4"]
[Thu Jul 30 13:17:57.962791 2026] [security2:error] [pid 872418:tid 872628] [client 20.52.54.143:10388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuVVVymN6QYcoA7XB494gAAAFA"]
[Thu Jul 30 13:17:58.196541 2026] [security2:error] [pid 872418:tid 872527] [remote 216.73.217.142:50677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVVlymN6QYcoA7XB495QAAKmw"]
[Thu Jul 30 13:17:58.362781 2026] [security2:error] [pid 872418:tid 872610] [client 191.232.199.39:6741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-2019.php"] [unique_id "amuVVlymN6QYcoA7XB495wAAAD4"]
[Thu Jul 30 13:17:58.478859 2026] [security2:error] [pid 872418:tid 872597] [client 20.52.54.143:10327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/file.php"] [unique_id "amuVVlymN6QYcoA7XB496QAAADE"]
[Thu Jul 30 13:17:58.757357 2026] [security2:error] [pid 872418:tid 872656] [client 20.52.54.143:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin.php"] [unique_id "amuVVlymN6QYcoA7XB497QAAAGw"]
[Thu Jul 30 13:17:58.856807 2026] [security2:error] [pid 872418:tid 872651] [client 172.236.9.101:60660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVVlymN6QYcoA7XB496AAAAGc"]
[Thu Jul 30 13:17:58.864881 2026] [security2:error] [pid 872418:tid 872659] [client 172.202.44.182:21344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/hoot.php"] [unique_id "amuVVlymN6QYcoA7XB497gAAAG8"]
[Thu Jul 30 13:17:59.105694 2026] [security2:error] [pid 872418:tid 872579] [client 20.52.54.143:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuVV1ymN6QYcoA7XB497wAAAB8"]
[Thu Jul 30 13:17:59.218917 2026] [security2:error] [pid 872418:tid 872571] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVVlymN6QYcoA7XB497AAAF28"]
[Thu Jul 30 13:17:59.586467 2026] [security2:error] [pid 872418:tid 872639] [client 191.232.199.39:6200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/hoot.php"] [unique_id "amuVV1ymN6QYcoA7XB498QAAAFs"]
[Thu Jul 30 13:18:00.159274 2026] [security2:error] [pid 872418:tid 872672] [client 172.202.44.182:57775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/log.php"] [unique_id "amuVWFymN6QYcoA7XB499QAAAHw"]
[Thu Jul 30 13:18:00.637123 2026] [security2:error] [pid 872418:tid 872628] [client 20.52.54.143:10361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuVWFymN6QYcoA7XB49_wAAAFA"]
[Thu Jul 30 13:18:00.816161 2026] [security2:error] [pid 872418:tid 872559] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVWFymN6QYcoA7XB499gAAC2M"]
[Thu Jul 30 13:18:00.872333 2026] [security2:error] [pid 872418:tid 872657] [client 172.236.9.101:26955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVWFymN6QYcoA7XB499wAAAG0"]
[Thu Jul 30 13:18:00.950195 2026] [security2:error] [pid 872418:tid 872591] [client 191.232.199.39:31095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/log.php"] [unique_id "amuVWFymN6QYcoA7XB4-AgAAACs"]
[Thu Jul 30 13:18:01.086489 2026] [security2:error] [pid 872418:tid 872663] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVWFymN6QYcoA7XB49-gAAAHM"]
[Thu Jul 30 13:18:01.144098 2026] [core:notice] [pid 872418:tid 872533] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:01.471722 2026] [security2:error] [pid 872418:tid 872664] [client 20.52.54.143:10392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/index/function.php"] [unique_id "amuVWVymN6QYcoA7XB4-BgAAAHQ"]
[Thu Jul 30 13:18:01.575331 2026] [security2:error] [pid 872418:tid 872666] [client 20.52.54.143:10400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/size.php"] [unique_id "amuVWVymN6QYcoA7XB4-CAAAAHY"]
[Thu Jul 30 13:18:02.282809 2026] [security2:error] [pid 872418:tid 872605] [client 191.232.199.39:6146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/bak.php"] [unique_id "amuVWlymN6QYcoA7XB4-CwAAADk"]
[Thu Jul 30 13:18:02.535820 2026] [security2:error] [pid 872418:tid 872561] [client 172.202.44.182:57753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/bak.php"] [unique_id "amuVWlymN6QYcoA7XB4-FQAAAA0"]
[Thu Jul 30 13:18:02.587330 2026] [security2:error] [pid 872418:tid 872567] [client 20.52.54.143:11142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/aaa.php"] [unique_id "amuVWlymN6QYcoA7XB4-FwAAABM"]
[Thu Jul 30 13:18:02.772145 2026] [security2:error] [pid 872418:tid 872549] [client 172.236.9.101:42431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVWlymN6QYcoA7XB4-DAAAAAE"]
[Thu Jul 30 13:18:02.823924 2026] [security2:error] [pid 872418:tid 872589] [client 179.64.21.229:1703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVWlymN6QYcoA7XB4-GAAAACk"]
[Thu Jul 30 13:18:02.824115 2026] [security2:error] [pid 872418:tid 872589] [client 179.64.21.229:1703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVWlymN6QYcoA7XB4-GAAAACk"]
[Thu Jul 30 13:18:02.874786 2026] [security2:error] [pid 872418:tid 872655] [client 20.52.54.143:10404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuVWlymN6QYcoA7XB4-GQAAAGs"]
[Thu Jul 30 13:18:03.123369 2026] [security2:error] [pid 872418:tid 872615] [client 82.102.27.195:55298] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuVW1ymN6QYcoA7XB4-GwAAAEM"]
[Thu Jul 30 13:18:03.123477 2026] [security2:error] [pid 872418:tid 872615] [client 82.102.27.195:55298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuVW1ymN6QYcoA7XB4-GwAAAEM"]
[Thu Jul 30 13:18:03.286646 2026] [security2:error] [pid 872418:tid 872541] [remote 57.141.0.58:56532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/PBB/about/contact"] [unique_id "amuVW1ymN6QYcoA7XB4-HAAAGXo"]
[Thu Jul 30 13:18:03.434298 2026] [security2:error] [pid 872418:tid 872662] [client 172.202.44.182:21383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/content.php"] [unique_id "amuVW1ymN6QYcoA7XB4-HQAAAHI"]
[Thu Jul 30 13:18:03.471124 2026] [security2:error] [pid 872418:tid 872572] [client 191.232.199.39:6145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/content.php"] [unique_id "amuVW1ymN6QYcoA7XB4-HgAAABg"]
[Thu Jul 30 13:18:03.624262 2026] [security2:error] [pid 872418:tid 872669] [client 20.52.54.143:10403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/getid3-core.php"] [unique_id "amuVW1ymN6QYcoA7XB4-HwAAAHk"]
[Thu Jul 30 13:18:03.648197 2026] [security2:error] [pid 872418:tid 872611] [client 20.52.54.143:10398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/403.php"] [unique_id "amuVW1ymN6QYcoA7XB4-IAAAAD8"]
[Thu Jul 30 13:18:03.849277 2026] [security2:error] [pid 872418:tid 872543] [remote 216.73.217.142:52571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVW1ymN6QYcoA7XB4-JQAAIHw"]
[Thu Jul 30 13:18:04.279590 2026] [security2:error] [pid 872418:tid 872637] [client 20.52.54.143:10410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/adminer.php"] [unique_id "amuVXFymN6QYcoA7XB4-LAAAAFk"]
[Thu Jul 30 13:18:04.319617 2026] [security2:error] [pid 872418:tid 872604] [client 20.52.54.143:10392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuVXFymN6QYcoA7XB4-LQAAADg"]
[Thu Jul 30 13:18:04.658489 2026] [security2:error] [pid 872418:tid 872646] [client 191.232.199.39:31091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/upfile.php"] [unique_id "amuVXFymN6QYcoA7XB4-MwAAAGI"]
[Thu Jul 30 13:18:04.853068 2026] [security2:error] [pid 872418:tid 872610] [client 20.52.54.143:10366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/as.php"] [unique_id "amuVXFymN6QYcoA7XB4-OAAAAD4"]
[Thu Jul 30 13:18:04.907139 2026] [security2:error] [pid 872418:tid 872585] [client 172.236.9.101:33254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVXFymN6QYcoA7XB4-LwAAACU"]
[Thu Jul 30 13:18:04.975299 2026] [security2:error] [pid 872418:tid 872597] [client 20.52.54.143:10357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/alfa.php"] [unique_id "amuVXFymN6QYcoA7XB4-OQAAADE"]
[Thu Jul 30 13:18:05.858902 2026] [security2:error] [pid 872418:tid 872656] [client 172.202.44.182:14100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/upfile.php"] [unique_id "amuVXVymN6QYcoA7XB4-RQAAAGw"]
[Thu Jul 30 13:18:05.886565 2026] [security2:error] [pid 872418:tid 872608] [client 172.236.9.101:61660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVXVymN6QYcoA7XB4-OwAAADw"]
[Thu Jul 30 13:18:05.990909 2026] [security2:error] [pid 872418:tid 872639] [client 20.52.54.143:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuVXVymN6QYcoA7XB4-RgAAAFs"]
[Thu Jul 30 13:18:06.034102 2026] [security2:error] [pid 872418:tid 872659] [client 191.232.199.39:6176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/bypass.php"] [unique_id "amuVXlymN6QYcoA7XB4-RwAAAG8"]
[Thu Jul 30 13:18:06.748797 2026] [security2:error] [pid 872418:tid 872672] [client 20.52.54.143:10345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuVXlymN6QYcoA7XB4-SwAAAHw"]
[Thu Jul 30 13:18:07.040205 2026] [security2:error] [pid 872418:tid 872634] [client 172.202.44.182:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/bypass.php"] [unique_id "amuVX1ymN6QYcoA7XB4-TQAAAFY"]
[Thu Jul 30 13:18:07.806572 2026] [security2:error] [pid 872418:tid 872589] [client 20.52.54.143:10424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuVX1ymN6QYcoA7XB4-UAAAACk"]
[Thu Jul 30 13:18:08.029054 2026] [security2:error] [pid 872418:tid 872586] [client 20.52.54.143:10386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuVYFymN6QYcoA7XB4-UQAAACY"]
[Thu Jul 30 13:18:08.203000 2026] [security2:error] [pid 872418:tid 872426] [remote 216.73.217.142:52571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVYFymN6QYcoA7XB4-UgAAewc"]
[Thu Jul 30 13:18:08.339067 2026] [security2:error] [pid 872418:tid 872593] [client 172.202.44.182:14080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/updates.php"] [unique_id "amuVYFymN6QYcoA7XB4-VQAAAC0"]
[Thu Jul 30 13:18:08.472807 2026] [security2:error] [pid 872418:tid 872565] [client 82.102.27.195:33990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuVYFymN6QYcoA7XB4-VwAAABE"]
[Thu Jul 30 13:18:08.472916 2026] [security2:error] [pid 872418:tid 872565] [client 82.102.27.195:33990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuVYFymN6QYcoA7XB4-VwAAABE"]
[Thu Jul 30 13:18:08.483777 2026] [security2:error] [pid 872418:tid 872596] [client 191.232.199.39:6182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/updates.php"] [unique_id "amuVYFymN6QYcoA7XB4-WAAAADA"]
[Thu Jul 30 13:18:08.598915 2026] [security2:error] [pid 872418:tid 872662] [client 20.52.54.143:11167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/edit.php"] [unique_id "amuVYFymN6QYcoA7XB4-WQAAAHI"]
[Thu Jul 30 13:18:08.664185 2026] [security2:error] [pid 872418:tid 872613] [client 20.52.54.143:10419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuVYFymN6QYcoA7XB4-WgAAAEE"]
[Thu Jul 30 13:18:08.758379 2026] [proxy:error] [pid 872418:tid 872636] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:18:08.758476 2026] [proxy_http:error] [pid 872418:tid 872636] [client 193.47.62.167:53158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:18:08.759207 2026] [proxy:error] [pid 872418:tid 872636] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:18:08.759258 2026] [proxy_http:error] [pid 872418:tid 872636] [client 193.47.62.167:53158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:18:09.168528 2026] [security2:error] [pid 872418:tid 872558] [client 172.202.44.182:21207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/xmrlpc.php"] [unique_id "amuVYVymN6QYcoA7XB4-XQAAAAo"]
[Thu Jul 30 13:18:09.335276 2026] [security2:error] [pid 872418:tid 872638] [client 20.52.54.143:10312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/plugins.php"] [unique_id "amuVYVymN6QYcoA7XB4-XgAAAFo"]
[Thu Jul 30 13:18:09.705687 2026] [security2:error] [pid 872418:tid 872577] [client 191.232.199.39:41117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/xmrlpc.php"] [unique_id "amuVYVymN6QYcoA7XB4-ZAAAAB0"]
[Thu Jul 30 13:18:09.851069 2026] [security2:error] [pid 872418:tid 872620] [client 172.236.9.101:6384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVYVymN6QYcoA7XB4-XwAAAEg"]
[Thu Jul 30 13:18:10.019869 2026] [security2:error] [pid 872418:tid 872594] [client 20.52.54.143:11137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/sf.php"] [unique_id "amuVYlymN6QYcoA7XB4-aQAAAC4"]
[Thu Jul 30 13:18:10.117140 2026] [security2:error] [pid 872418:tid 872582] [client 20.52.54.143:10314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuVYlymN6QYcoA7XB4-agAAACI"]
[Thu Jul 30 13:18:10.122329 2026] [security2:error] [pid 872418:tid 872557] [client 172.202.44.182:51176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/ae.php"] [unique_id "amuVYlymN6QYcoA7XB4-awAAAAk"]
[Thu Jul 30 13:18:10.197279 2026] [core:notice] [pid 872418:tid 872578] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:10.710389 2026] [security2:error] [pid 872418:tid 872641] [client 20.52.54.143:10420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/go.php"] [unique_id "amuVYlymN6QYcoA7XB4-cAAAAF0"]
[Thu Jul 30 13:18:10.771624 2026] [security2:error] [pid 872418:tid 872554] [client 20.52.54.143:10371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wso.php"] [unique_id "amuVYlymN6QYcoA7XB4-cQAAAAY"]
[Thu Jul 30 13:18:10.825481 2026] [security2:error] [pid 872418:tid 872597] [client 172.236.9.101:18978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVYlymN6QYcoA7XB4-bQAAADE"]
[Thu Jul 30 13:18:11.167919 2026] [security2:error] [pid 872418:tid 872576] [client 191.232.199.39:41102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/ae.php"] [unique_id "amuVY1ymN6QYcoA7XB4-dAAAABw"]
[Thu Jul 30 13:18:11.348170 2026] [security2:error] [pid 872418:tid 872571] [client 20.52.54.143:10391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/ioxi-o.php"] [unique_id "amuVY1ymN6QYcoA7XB4-dgAAABc"]
[Thu Jul 30 13:18:11.603320 2026] [security2:error] [pid 872418:tid 872622] [client 172.202.44.182:51147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/moon.php"] [unique_id "amuVY1ymN6QYcoA7XB4-eAAAAEo"]
[Thu Jul 30 13:18:11.929307 2026] [security2:error] [pid 872418:tid 872664] [client 20.52.54.143:10350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/test1.php"] [unique_id "amuVY1ymN6QYcoA7XB4-egAAAHQ"]
[Thu Jul 30 13:18:12.254826 2026] [security2:error] [pid 872418:tid 872626] [client 20.52.54.143:11149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/file56.php"] [unique_id "amuVZFymN6QYcoA7XB4-fAAAAE4"]
[Thu Jul 30 13:18:12.354510 2026] [security2:error] [pid 872418:tid 872587] [client 191.232.199.39:6930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/moon.php"] [unique_id "amuVZFymN6QYcoA7XB4-fQAAACc"]
[Thu Jul 30 13:18:12.676951 2026] [security2:error] [pid 872418:tid 872661] [client 172.202.44.182:21341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/blog.php"] [unique_id "amuVZFymN6QYcoA7XB4-fwAAAHE"]
[Thu Jul 30 13:18:12.948429 2026] [core:error] [pid 872418:tid 872588] [client 20.52.54.143:10316] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:12.948453 2026] [core:error] [pid 872418:tid 872588] [client 20.52.54.143:10316] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:13.063844 2026] [security2:error] [pid 872418:tid 872556] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/api/.env"] [unique_id "amuVZVymN6QYcoA7XB4-ggAAAAg"]
[Thu Jul 30 13:18:13.190360 2026] [security2:error] [pid 872418:tid 872589] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/backend/.env"] [unique_id "amuVZVymN6QYcoA7XB4-gwAAACk"]
[Thu Jul 30 13:18:13.204452 2026] [security2:error] [pid 872418:tid 872437] [remote 216.73.217.142:52571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVZVymN6QYcoA7XB4-hAAAaBI"]
[Thu Jul 30 13:18:13.634555 2026] [security2:error] [pid 872418:tid 872665] [client 20.52.54.143:10311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/images/index.php"] [unique_id "amuVZVymN6QYcoA7XB4-hwAAAHU"]
[Thu Jul 30 13:18:13.639593 2026] [security2:error] [pid 872418:tid 872567] [client 191.232.199.39:41139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/blog.php"] [unique_id "amuVZVymN6QYcoA7XB4-iAAAABM"]
[Thu Jul 30 13:18:13.645798 2026] [security2:error] [pid 872418:tid 872599] [client 179.64.21.229:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVZVymN6QYcoA7XB4-iQAAADM"]
[Thu Jul 30 13:18:13.645908 2026] [security2:error] [pid 872418:tid 872599] [client 179.64.21.229:49130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVZVymN6QYcoA7XB4-iQAAADM"]
[Thu Jul 30 13:18:14.214964 2026] [core:error] [pid 872418:tid 872565] [client 20.52.54.143:10393] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:14.215006 2026] [core:error] [pid 872418:tid 872565] [client 20.52.54.143:10393] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:14.420134 2026] [security2:error] [pid 872418:tid 872586] [client 172.202.44.182:14102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/ini.php"] [unique_id "amuVZlymN6QYcoA7XB4-jAAAACY"]
[Thu Jul 30 13:18:14.827581 2026] [core:notice] [pid 872418:tid 872669] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:14.871422 2026] [security2:error] [pid 872418:tid 872634] [client 20.52.54.143:10374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuVZlymN6QYcoA7XB4-kAAAAFY"]
[Thu Jul 30 13:18:15.035930 2026] [security2:error] [pid 872418:tid 872551] [client 191.232.199.39:31042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/ini.php"] [unique_id "amuVZ1ymN6QYcoA7XB4-kQAAAAM"]
[Thu Jul 30 13:18:15.184205 2026] [security2:error] [pid 872418:tid 872662] [client 20.52.54.143:10325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/asd.php"] [unique_id "amuVZ1ymN6QYcoA7XB4-lAAAAHI"]
[Thu Jul 30 13:18:15.253169 2026] [security2:error] [pid 872418:tid 872572] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/frontend/.env"] [unique_id "amuVZ1ymN6QYcoA7XB4-lQAAABg"]
[Thu Jul 30 13:18:15.257586 2026] [core:notice] [pid 872418:tid 872638] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:15.474081 2026] [core:notice] [pid 872418:tid 872609] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:15.665931 2026] [core:notice] [pid 872418:tid 872592] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:15.852375 2026] [security2:error] [pid 872418:tid 872558] [client 172.236.9.101:49612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVZ1ymN6QYcoA7XB4-mAAAAAo"]
[Thu Jul 30 13:18:15.861134 2026] [core:notice] [pid 872418:tid 872612] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:16.018328 2026] [security2:error] [pid 872418:tid 872600] [client 20.52.54.143:10319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuVaFymN6QYcoA7XB4-nQAAADQ"]
[Thu Jul 30 13:18:16.052177 2026] [core:notice] [pid 872418:tid 872606] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:16.105313 2026] [security2:error] [pid 872418:tid 872566] [client 172.202.44.182:57742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/admin-ajax.php"] [unique_id "amuVaFymN6QYcoA7XB4-nwAAABI"]
[Thu Jul 30 13:18:16.245728 2026] [core:notice] [pid 872418:tid 872621] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:16.278556 2026] [security2:error] [pid 872418:tid 872564] [client 191.232.199.39:41129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/admin-ajax.php"] [unique_id "amuVaFymN6QYcoA7XB4-owAAABA"]
[Thu Jul 30 13:18:16.436919 2026] [core:notice] [pid 872418:tid 872563] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:16.631549 2026] [core:notice] [pid 872418:tid 872594] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:16.819696 2026] [security2:error] [pid 872418:tid 872658] [client 172.236.9.101:29812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVaFymN6QYcoA7XB4-pwAAAG4"]
[Thu Jul 30 13:18:16.822889 2026] [core:notice] [pid 872418:tid 872559] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:16.944335 2026] [security2:error] [pid 872418:tid 872568] [client 20.52.54.143:10402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuVaFymN6QYcoA7XB4-rgAAABQ"]
[Thu Jul 30 13:18:17.016411 2026] [core:notice] [pid 872418:tid 872647] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:17.207115 2026] [core:notice] [pid 872418:tid 872595] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:17.212107 2026] [security2:error] [pid 872418:tid 872585] [client 172.202.44.182:58612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/akc.php"] [unique_id "amuVaVymN6QYcoA7XB4-sgAAACU"]
[Thu Jul 30 13:18:17.401930 2026] [core:notice] [pid 872418:tid 872641] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:17.593022 2026] [core:notice] [pid 872418:tid 872651] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:17.691540 2026] [security2:error] [pid 872418:tid 872554] [client 20.52.54.143:10413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/atomlib.php"] [unique_id "amuVaVymN6QYcoA7XB4-twAAAAY"]
[Thu Jul 30 13:18:17.714503 2026] [security2:error] [pid 872418:tid 872574] [client 191.232.199.39:6188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/akc.php"] [unique_id "amuVaVymN6QYcoA7XB4-uAAAABo"]
[Thu Jul 30 13:18:18.268317 2026] [security2:error] [pid 872418:tid 872608] [client 172.202.44.182:21322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/akcc.php"] [unique_id "amuValymN6QYcoA7XB4-vQAAADw"]
[Thu Jul 30 13:18:18.286931 2026] [security2:error] [pid 872418:tid 872579] [client 20.52.54.143:10397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuValymN6QYcoA7XB4-vgAAAB8"]
[Thu Jul 30 13:18:18.347842 2026] [security2:error] [pid 872418:tid 872632] [client 20.63.98.115:25664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/gmo.php"] [unique_id "amuValymN6QYcoA7XB4-vwAAAFQ"]
[Thu Jul 30 13:18:19.076504 2026] [security2:error] [pid 872418:tid 872587] [client 191.232.199.39:6154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/akcc.php"] [unique_id "amuVa1ymN6QYcoA7XB4-xgAAACc"]
[Thu Jul 30 13:18:19.142547 2026] [security2:error] [pid 872418:tid 872561] [client 20.63.98.115:42369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/nakrip.php"] [unique_id "amuVa1ymN6QYcoA7XB4-xwAAAA0"]
[Thu Jul 30 13:18:19.229692 2026] [security2:error] [pid 872418:tid 872623] [client 172.202.44.182:51140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/asasx.php"] [unique_id "amuVa1ymN6QYcoA7XB4-yAAAAEs"]
[Thu Jul 30 13:18:19.233023 2026] [security2:error] [pid 872418:tid 872630] [client 20.52.54.143:10386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/edit.php"] [unique_id "amuVa1ymN6QYcoA7XB4-yQAAAFI"]
[Thu Jul 30 13:18:19.342816 2026] [core:error] [pid 872418:tid 872622] [client 20.52.54.143:10429] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:19.342855 2026] [core:error] [pid 872418:tid 872622] [client 20.52.54.143:10429] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:19.996797 2026] [security2:error] [pid 872418:tid 872648] [client 20.52.54.143:10409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/2.php"] [unique_id "amuVa1ymN6QYcoA7XB4-4QAAAGQ"]
[Thu Jul 30 13:18:20.226132 2026] [core:error] [pid 872418:tid 872562] [client 20.52.54.143:10417] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:20.226155 2026] [core:error] [pid 872418:tid 872562] [client 20.52.54.143:10417] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:20.405368 2026] [security2:error] [pid 872418:tid 872638] [client 191.232.199.39:41220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/asasx.php"] [unique_id "amuVbFymN6QYcoA7XB4-6AAAAFo"]
[Thu Jul 30 13:18:20.475861 2026] [security2:error] [pid 872418:tid 872570] [client 172.202.44.182:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/axx.php"] [unique_id "amuVbFymN6QYcoA7XB4-6QAAABY"]
[Thu Jul 30 13:18:20.882194 2026] [security2:error] [pid 872418:tid 872566] [client 172.236.9.101:4898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVbFymN6QYcoA7XB4-5wAAABI"]
[Thu Jul 30 13:18:20.895186 2026] [security2:error] [pid 872418:tid 872650] [client 20.52.54.143:11144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuVbFymN6QYcoA7XB4-8AAAAGY"]
[Thu Jul 30 13:18:21.666761 2026] [security2:error] [pid 872418:tid 872674] [client 191.232.199.39:41090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/axx.php"] [unique_id "amuVbVymN6QYcoA7XB4--AAAAH4"]
[Thu Jul 30 13:18:21.819097 2026] [security2:error] [pid 872418:tid 872557] [client 172.236.9.101:55322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVbVymN6QYcoA7XB4-9AAAAAk"]
[Thu Jul 30 13:18:21.842458 2026] [security2:error] [pid 872418:tid 872658] [client 20.52.54.143:11139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/mah.php"] [unique_id "amuVbVymN6QYcoA7XB4--QAAAG4"]
[Thu Jul 30 13:18:22.160936 2026] [security2:error] [pid 872418:tid 872575] [client 20.63.98.115:25691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/radio.php"] [unique_id "amuVblymN6QYcoA7XB4-_AAAABs"]
[Thu Jul 30 13:18:22.326055 2026] [security2:error] [pid 872418:tid 872651] [client 20.52.54.143:10307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuVblymN6QYcoA7XB4-_wAAAGc"]
[Thu Jul 30 13:18:22.771418 2026] [security2:error] [pid 872418:tid 872656] [client 20.52.54.143:10406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/send.php"] [unique_id "amuVblymN6QYcoA7XB4_BAAAAGw"]
[Thu Jul 30 13:18:22.981418 2026] [security2:error] [pid 872418:tid 872576] [client 66.249.65.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVblymN6QYcoA7XB4_AgAAABw"]
[Thu Jul 30 13:18:23.212499 2026] [security2:error] [pid 872418:tid 872644] [client 20.63.98.115:42386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-singin.php"] [unique_id "amuVb1ymN6QYcoA7XB4_BgAAAGA"]
[Thu Jul 30 13:18:23.212550 2026] [security2:error] [pid 872418:tid 872550] [client 191.232.199.39:6336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/berax.php"] [unique_id "amuVb1ymN6QYcoA7XB4_BwAAAAI"]
[Thu Jul 30 13:18:23.362688 2026] [core:error] [pid 872418:tid 872605] [client 20.52.54.143:11142] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:23.362709 2026] [core:error] [pid 872418:tid 872605] [client 20.52.54.143:11142] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:23.554800 2026] [security2:error] [pid 872418:tid 872598] [client 20.52.54.143:10354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuVb1ymN6QYcoA7XB4_CgAAADI"]
[Thu Jul 30 13:18:24.000710 2026] [security2:error] [pid 872418:tid 872654] [client 179.64.21.229:20342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVb1ymN6QYcoA7XB4_DQAAAGo"]
[Thu Jul 30 13:18:24.000903 2026] [security2:error] [pid 872418:tid 872654] [client 179.64.21.229:20342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVb1ymN6QYcoA7XB4_DQAAAGo"]
[Thu Jul 30 13:18:24.377634 2026] [core:error] [pid 872418:tid 872659] [client 20.52.54.143:11136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:24.377658 2026] [core:error] [pid 872418:tid 872659] [client 20.52.54.143:11136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:24.575710 2026] [security2:error] [pid 872418:tid 872661] [client 20.52.54.143:10342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/about.php"] [unique_id "amuVcFymN6QYcoA7XB4_FgAAAHE"]
[Thu Jul 30 13:18:24.800713 2026] [security2:error] [pid 872418:tid 872587] [client 191.232.199.39:6660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/build.php"] [unique_id "amuVcFymN6QYcoA7XB4_FwAAACc"]
[Thu Jul 30 13:18:25.176697 2026] [security2:error] [pid 872418:tid 872565] [client 20.52.54.143:10313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/options.php"] [unique_id "amuVcVymN6QYcoA7XB4_GAAAABE"]
[Thu Jul 30 13:18:25.189026 2026] [core:error] [pid 872418:tid 872596] [client 20.52.54.143:10389] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:25.189044 2026] [core:error] [pid 872418:tid 872596] [client 20.52.54.143:10389] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:25.195380 2026] [security2:error] [pid 872418:tid 872470] [remote 72.167.132.114:36558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-fdb1204b.med.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuVcVymN6QYcoA7XB4_GgAASjM"]
[Thu Jul 30 13:18:25.261358 2026] [core:error] [pid 872418:tid 872469] [remote 216.73.217.126:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:25.261383 2026] [core:error] [pid 872418:tid 872469] [remote 216.73.217.126:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:25.795456 2026] [security2:error] [pid 872418:tid 872567] [client 172.202.44.182:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/berax.php"] [unique_id "amuVcVymN6QYcoA7XB4_HgAAABM"]
[Thu Jul 30 13:18:26.069553 2026] [security2:error] [pid 872418:tid 872606] [client 20.52.54.143:11189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuVclymN6QYcoA7XB4_IQAAADo"]
[Thu Jul 30 13:18:26.165757 2026] [security2:error] [pid 872418:tid 872600] [client 20.52.54.143:10320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/inputs.php"] [unique_id "amuVclymN6QYcoA7XB4_IwAAADQ"]
[Thu Jul 30 13:18:26.471927 2026] [security2:error] [pid 872418:tid 872616] [client 191.232.199.39:32670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/buy.php"] [unique_id "amuVclymN6QYcoA7XB4_JQAAAEQ"]
[Thu Jul 30 13:18:26.764411 2026] [security2:error] [pid 872418:tid 872580] [client 172.202.44.182:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/build.php"] [unique_id "amuVclymN6QYcoA7XB4_JwAAACA"]
[Thu Jul 30 13:18:26.864069 2026] [security2:error] [pid 872418:tid 872657] [client 172.236.9.101:21820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVclymN6QYcoA7XB4_JAAAAG0"]
[Thu Jul 30 13:18:27.059312 2026] [core:notice] [pid 872418:tid 872548] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:27.703679 2026] [security2:error] [pid 872418:tid 872614] [client 191.232.199.39:32657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/checkbox.php"] [unique_id "amuVc1ymN6QYcoA7XB4_LQAAAEI"]
[Thu Jul 30 13:18:27.754539 2026] [security2:error] [pid 872418:tid 872563] [client 172.202.44.182:32674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/buy.php"] [unique_id "amuVc1ymN6QYcoA7XB4_LgAAAA8"]
[Thu Jul 30 13:18:28.207729 2026] [security2:error] [pid 872418:tid 872473] [remote 216.73.217.142:21259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVdFymN6QYcoA7XB4_NgAAYTY"]
[Thu Jul 30 13:18:28.484848 2026] [security2:error] [pid 872418:tid 872607] [client 20.52.54.143:11190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/wp-file.php"] [unique_id "amuVdFymN6QYcoA7XB4_OgAAADs"]
[Thu Jul 30 13:18:28.862831 2026] [proxy:error] [pid 872418:tid 872569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:18:28.862909 2026] [proxy_http:error] [pid 872418:tid 872569] [client 54.87.222.253:17422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:18:28.863490 2026] [proxy:error] [pid 872418:tid 872569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:18:28.863534 2026] [proxy_http:error] [pid 872418:tid 872569] [client 54.87.222.253:17422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:18:29.126101 2026] [security2:error] [pid 872418:tid 872574] [client 20.63.98.115:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/as.php"] [unique_id "amuVdVymN6QYcoA7XB4_PgAAABo"]
[Thu Jul 30 13:18:29.215378 2026] [security2:error] [pid 872418:tid 872579] [client 191.232.199.39:41230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/cong.php"] [unique_id "amuVdVymN6QYcoA7XB4_PwAAAB8"]
[Thu Jul 30 13:18:29.319356 2026] [security2:error] [pid 872418:tid 872628] [client 20.52.54.143:10327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/index.php"] [unique_id "amuVdVymN6QYcoA7XB4_QQAAAFA"]
[Thu Jul 30 13:18:29.362698 2026] [security2:error] [pid 872418:tid 872552] [client 172.202.44.182:53480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/checkbox.php"] [unique_id "amuVdVymN6QYcoA7XB4_QgAAAAQ"]
[Thu Jul 30 13:18:29.407568 2026] [security2:error] [pid 872418:tid 872644] [client 20.52.54.143:10347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.asian-connect.com"] [uri "/sid3.php"] [unique_id "amuVdVymN6QYcoA7XB4_QwAAAGA"]
[Thu Jul 30 13:18:29.805812 2026] [security2:error] [pid 872418:tid 872630] [client 20.52.54.143:11140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuVdVymN6QYcoA7XB4_SAAAAFI"]
[Thu Jul 30 13:18:29.988008 2026] [security2:error] [pid 872418:tid 872627] [client 20.63.98.115:42390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/x.php"] [unique_id "amuVdVymN6QYcoA7XB4_SQAAAE8"]
[Thu Jul 30 13:18:30.797113 2026] [security2:error] [pid 872418:tid 872653] [client 191.232.199.39:6484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/file4.php"] [unique_id "amuVdlymN6QYcoA7XB4_TwAAAGk"]
[Thu Jul 30 13:18:30.936077 2026] [security2:error] [pid 872418:tid 872675] [client 68.67.112.200:1599] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuVdlymN6QYcoA7XB4_UAAAAH8"]
[Thu Jul 30 13:18:30.948831 2026] [security2:error] [pid 872418:tid 872587] [client 172.202.44.182:53501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/cong.php"] [unique_id "amuVdlymN6QYcoA7XB4_UQAAACc"]
[Thu Jul 30 13:18:31.137457 2026] [security2:error] [pid 872418:tid 872668] [client 20.52.54.143:10308] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/1.php"] [unique_id "amuVd1ymN6QYcoA7XB4_UgAAAHg"]
[Thu Jul 30 13:18:31.137584 2026] [security2:error] [pid 872418:tid 872668] [client 20.52.54.143:10308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/1.php"] [unique_id "amuVd1ymN6QYcoA7XB4_UgAAAHg"]
[Thu Jul 30 13:18:31.199476 2026] [core:error] [pid 872418:tid 872635] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:31.199496 2026] [core:error] [pid 872418:tid 872635] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:31.322680 2026] [security2:error] [pid 872418:tid 872596] [client 20.63.98.115:46668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/item.php"] [unique_id "amuVd1ymN6QYcoA7XB4_VAAAADA"]
[Thu Jul 30 13:18:31.703856 2026] [security2:error] [pid 872418:tid 872648] [client 20.52.54.143:10423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/plugin.php"] [unique_id "amuVd1ymN6QYcoA7XB4_WAAAAGQ"]
[Thu Jul 30 13:18:31.871120 2026] [security2:error] [pid 872418:tid 872567] [client 23.94.216.234:59208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.kev.udi.temporary.site"] [uri "/"] [unique_id "amuVd1ymN6QYcoA7XB4_WgAAABM"]
[Thu Jul 30 13:18:31.882801 2026] [security2:error] [pid 872418:tid 872613] [client 172.236.9.101:61365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVd1ymN6QYcoA7XB4_VgAAAEE"]
[Thu Jul 30 13:18:31.892066 2026] [core:notice] [pid 872418:tid 872562] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:32.213569 2026] [security2:error] [pid 872418:tid 872619] [client 191.232.199.39:6798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/flower.php"] [unique_id "amuVeFymN6QYcoA7XB4_XwAAAEc"]
[Thu Jul 30 13:18:32.375655 2026] [security2:error] [pid 872418:tid 872620] [client 172.202.44.182:20722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/file4.php"] [unique_id "amuVeFymN6QYcoA7XB4_YQAAAEg"]
[Thu Jul 30 13:18:32.450008 2026] [security2:error] [pid 872418:tid 872650] [client 23.94.216.234:35386] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "mail.kevinderarslanian.com"] [uri "/"] [unique_id "amuVeFymN6QYcoA7XB4_YgAAAGY"]
[Thu Jul 30 13:18:32.493678 2026] [security2:error] [pid 872418:tid 872553] [client 20.52.54.143:10395] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.bisbeewalk.com"] [uri "/1.php"] [unique_id "amuVeFymN6QYcoA7XB4_YwAAAAU"]
[Thu Jul 30 13:18:32.493811 2026] [security2:error] [pid 872418:tid 872553] [client 20.52.54.143:10395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/1.php"] [unique_id "amuVeFymN6QYcoA7XB4_YwAAAAU"]
[Thu Jul 30 13:18:32.513730 2026] [security2:error] [pid 872418:tid 872580] [client 57.141.0.18:53144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuVeFymN6QYcoA7XB4_XgAAIEo"], referer: https://igetvape-australia.com/product-category/iget-bar-pro/
[Thu Jul 30 13:18:32.625545 2026] [core:notice] [pid 872418:tid 872558] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:32.817108 2026] [security2:error] [pid 872418:tid 872570] [client 20.63.98.115:26623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/app.php"] [unique_id "amuVeFymN6QYcoA7XB4_ZwAAABY"]
[Thu Jul 30 13:18:32.823586 2026] [security2:error] [pid 872418:tid 872566] [client 172.236.9.101:16949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVeFymN6QYcoA7XB4_YAAAABI"]
[Thu Jul 30 13:18:33.142624 2026] [security2:error] [pid 872418:tid 872592] [client 178.156.189.249:1990] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuVd1ymN6QYcoA7XB4_WQAAACw"], referer: https://globalmarks.pk/
[Thu Jul 30 13:18:33.781526 2026] [security2:error] [pid 872418:tid 872614] [client 20.52.54.143:10318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/gg.php"] [unique_id "amuVeVymN6QYcoA7XB4_bgAAAEI"]
[Thu Jul 30 13:18:33.813914 2026] [security2:error] [pid 872418:tid 872478] [remote 216.73.217.142:5024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVeVymN6QYcoA7XB4_bwAAOzs"]
[Thu Jul 30 13:18:33.911301 2026] [security2:error] [pid 872418:tid 872640] [client 191.232.199.39:6493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/form.php"] [unique_id "amuVeVymN6QYcoA7XB4_cQAAAFw"]
[Thu Jul 30 13:18:34.675207 2026] [security2:error] [pid 872418:tid 872628] [client 20.63.98.115:26607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/k.php"] [unique_id "amuVelymN6QYcoA7XB4_dAAAAFA"]
[Thu Jul 30 13:18:35.058670 2026] [security2:error] [pid 872418:tid 872637] [client 172.202.44.182:33227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/flower.php"] [unique_id "amuVe1ymN6QYcoA7XB4_eAAAAFk"]
[Thu Jul 30 13:18:35.143457 2026] [security2:error] [pid 872418:tid 872644] [client 191.232.199.39:6802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/gecko.php"] [unique_id "amuVe1ymN6QYcoA7XB4_eQAAAGA"]
[Thu Jul 30 13:18:35.479350 2026] [security2:error] [pid 872418:tid 872598] [client 104.248.49.36:51860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuVelymN6QYcoA7XB4_dQAAADI"]
[Thu Jul 30 13:18:35.752559 2026] [core:error] [pid 872418:tid 872623] [client 20.52.54.143:10306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:35.752589 2026] [core:error] [pid 872418:tid 872623] [client 20.52.54.143:10306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:35.804599 2026] [security2:error] [pid 872418:tid 872639] [client 20.63.98.115:26570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-fmfile.php"] [unique_id "amuVe1ymN6QYcoA7XB4_fwAAAFs"]
[Thu Jul 30 13:18:36.091566 2026] [security2:error] [pid 872418:tid 872660] [client 104.248.49.36:51860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuVe1ymN6QYcoA7XB4_fAAAAHA"]
[Thu Jul 30 13:18:36.300703 2026] [security2:error] [pid 872418:tid 872671] [client 172.202.44.182:33273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/form.php"] [unique_id "amuVfFymN6QYcoA7XB4_ggAAAHs"]
[Thu Jul 30 13:18:36.570506 2026] [security2:error] [pid 872418:tid 872675] [client 20.52.54.143:10329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp.php"] [unique_id "amuVfFymN6QYcoA7XB4_hQAAAH8"]
[Thu Jul 30 13:18:36.871578 2026] [security2:error] [pid 872418:tid 872653] [client 191.232.199.39:36877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/kyami.php"] [unique_id "amuVfFymN6QYcoA7XB4_hwAAAGk"]
[Thu Jul 30 13:18:37.954472 2026] [security2:error] [pid 872418:tid 872665] [client 20.63.98.115:46674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wi.php"] [unique_id "amuVfVymN6QYcoA7XB4_kQAAAHU"]
[Thu Jul 30 13:18:38.170466 2026] [security2:error] [pid 872418:tid 872661] [client 191.232.199.39:6813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/manager.php"] [unique_id "amuVflymN6QYcoA7XB4_kgAAAHE"]
[Thu Jul 30 13:18:38.379055 2026] [security2:error] [pid 872418:tid 872567] [client 20.52.54.143:10380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuVflymN6QYcoA7XB4_lAAAABM"]
[Thu Jul 30 13:18:38.684706 2026] [security2:error] [pid 872418:tid 872638] [client 179.64.21.229:61710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVflymN6QYcoA7XB4_lwAAAFo"]
[Thu Jul 30 13:18:38.684833 2026] [security2:error] [pid 872418:tid 872638] [client 179.64.21.229:61710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVflymN6QYcoA7XB4_lwAAAFo"]
[Thu Jul 30 13:18:38.937817 2026] [security2:error] [pid 872418:tid 872577] [client 104.248.49.36:51860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuVflymN6QYcoA7XB4_lgAAAB0"]
[Thu Jul 30 13:18:39.380526 2026] [security2:error] [pid 872418:tid 872588] [client 191.232.199.39:6497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/mari.php"] [unique_id "amuVf1ymN6QYcoA7XB4_nQAAACg"]
[Thu Jul 30 13:18:39.542248 2026] [security2:error] [pid 872418:tid 872591] [client 104.248.49.36:51860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuVf1ymN6QYcoA7XB4_mQAAACs"]
[Thu Jul 30 13:18:39.722310 2026] [security2:error] [pid 872418:tid 872553] [client 20.63.98.115:26065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/php8.php"] [unique_id "amuVf1ymN6QYcoA7XB4_nwAAAAU"]
[Thu Jul 30 13:18:39.967958 2026] [security2:error] [pid 872418:tid 872590] [client 138.199.60.23:44750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "deltaedu.net"] [uri "/wp-json/batch/v1"] [unique_id "amuVf1ymN6QYcoA7XB4_ogAAACo"]
[Thu Jul 30 13:18:40.123008 2026] [security2:error] [pid 872418:tid 872558] [client 20.52.54.143:10384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/file.php"] [unique_id "amuVgFymN6QYcoA7XB4_owAAAAo"]
[Thu Jul 30 13:18:40.146507 2026] [security2:error] [pid 872418:tid 872564] [client 104.248.49.36:51860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuVf1ymN6QYcoA7XB4_oAAAABA"]
[Thu Jul 30 13:18:40.171272 2026] [security2:error] [pid 872418:tid 872636] [client 198.44.134.4:51958] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuVf1ymN6QYcoA7XB4_oQAAAFg"]
[Thu Jul 30 13:18:40.171425 2026] [security2:error] [pid 872418:tid 872636] [client 198.44.134.4:51958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuVf1ymN6QYcoA7XB4_oQAAAFg"]
[Thu Jul 30 13:18:40.669752 2026] [security2:error] [pid 872418:tid 872649] [client 191.232.199.39:6843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/nc4.php"] [unique_id "amuVgFymN6QYcoA7XB4_pQAAAGU"]
[Thu Jul 30 13:18:40.843781 2026] [core:error] [pid 872418:tid 872667] [client 66.249.73.132:49497] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:40.843809 2026] [core:error] [pid 872418:tid 872667] [client 66.249.73.132:49497] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:40.982764 2026] [security2:error] [pid 872418:tid 872480] [remote 57.141.0.29:36186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuVgFymN6QYcoA7XB4_pwAART0"]
[Thu Jul 30 13:18:41.204325 2026] [security2:error] [pid 872418:tid 872548] [client 172.202.44.182:42412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/gecko.php"] [unique_id "amuVgVymN6QYcoA7XB4_qgAAAAA"]
[Thu Jul 30 13:18:41.899598 2026] [security2:error] [pid 872418:tid 872656] [client 138.199.60.23:44756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "deltaedu.net"] [uri "/"] [unique_id "amuVgVymN6QYcoA7XB4_rQAAAGw"]
[Thu Jul 30 13:18:42.061866 2026] [cgid:error] [pid 872418:tid 872663] [client 191.232.199.39:6840] AH01265: stderr from /home1/khwnyxte/mydubaidesertsafari.com/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 13:18:42.325047 2026] [security2:error] [pid 872418:tid 872595] [client 20.63.98.115:26609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/tes.php"] [unique_id "amuVglymN6QYcoA7XB4_sAAAAC8"]
[Thu Jul 30 13:18:42.419206 2026] [security2:error] [pid 872418:tid 872594] [client 20.52.54.143:10332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuVglymN6QYcoA7XB4_sQAAAC4"]
[Thu Jul 30 13:18:42.947582 2026] [core:error] [pid 872418:tid 872673] [client 20.52.54.143:10397] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:42.947605 2026] [core:error] [pid 872418:tid 872673] [client 20.52.54.143:10397] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:42.997127 2026] [security2:error] [pid 872418:tid 872602] [client 172.202.44.182:42088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/kyami.php"] [unique_id "amuVglymN6QYcoA7XB4_twAAADY"]
[Thu Jul 30 13:18:43.214470 2026] [security2:error] [pid 872418:tid 872492] [remote 216.73.217.142:5024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuVg1ymN6QYcoA7XB4_uAAATkk"]
[Thu Jul 30 13:18:43.363758 2026] [proxy:error] [pid 872418:tid 872598] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:18:43.363837 2026] [proxy_http:error] [pid 872418:tid 872598] [client 54.87.222.253:42760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:18:43.364437 2026] [proxy:error] [pid 872418:tid 872598] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:18:43.364484 2026] [proxy_http:error] [pid 872418:tid 872598] [client 54.87.222.253:42760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:18:43.406780 2026] [proxy:error] [pid 872418:tid 872639] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:18:43.406865 2026] [proxy_http:error] [pid 872418:tid 872639] [client 3.228.112.215:17356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:18:43.407613 2026] [proxy:error] [pid 872418:tid 872639] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:18:43.407674 2026] [proxy_http:error] [pid 872418:tid 872639] [client 3.228.112.215:17356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:18:43.566018 2026] [security2:error] [pid 872418:tid 872581] [client 20.52.54.143:11148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuVg1ymN6QYcoA7XB4_xAAAACE"]
[Thu Jul 30 13:18:43.860215 2026] [security2:error] [pid 872418:tid 872671] [client 172.202.44.182:20739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/manager.php"] [unique_id "amuVg1ymN6QYcoA7XB4_xgAAAHs"]
[Thu Jul 30 13:18:44.058401 2026] [security2:error] [pid 872418:tid 872557] [client 20.52.54.143:10405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/index/function.php"] [unique_id "amuVhFymN6QYcoA7XB4_yQAAAAk"]
[Thu Jul 30 13:18:44.118803 2026] [security2:error] [pid 872418:tid 872601] [client 20.63.98.115:26587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/about.php"] [unique_id "amuVhFymN6QYcoA7XB4_ygAAADU"]
[Thu Jul 30 13:18:44.755214 2026] [security2:error] [pid 872418:tid 872611] [client 172.202.44.182:42370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/mari.php"] [unique_id "amuVhFymN6QYcoA7XB4_0gAAAD8"]
[Thu Jul 30 13:18:45.089010 2026] [core:error] [pid 872418:tid 872634] [client 20.52.54.143:11139] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:45.089037 2026] [core:error] [pid 872418:tid 872634] [client 20.52.54.143:11139] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:45.125044 2026] [security2:error] [pid 872418:tid 872552] [client 193.47.62.167:57196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "myintentionalreset.com"] [uri "/index.php"] [unique_id "amuVglymN6QYcoA7XB4_swAAAAQ"]
[Thu Jul 30 13:18:45.207022 2026] [core:notice] [pid 872418:tid 872616] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:45.576580 2026] [security2:error] [pid 872418:tid 872672] [client 57.141.0.20:24524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koriusa.info"] [uri "/index.php"] [unique_id "amuVg1ymN6QYcoA7XB4_wgAAfDg"]
[Thu Jul 30 13:18:45.671810 2026] [core:notice] [pid 872418:tid 872606] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:45.750769 2026] [core:error] [pid 872418:tid 872603] [client 20.52.54.143:10310] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:45.750791 2026] [core:error] [pid 872418:tid 872603] [client 20.52.54.143:10310] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:45.856081 2026] [security2:error] [pid 872418:tid 872553] [client 172.202.44.182:33239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/nc4.php"] [unique_id "amuVhVymN6QYcoA7XB4_3QAAAAU"]
[Thu Jul 30 13:18:46.249824 2026] [security2:error] [pid 872418:tid 872592] [client 148.153.159.15:42570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.serverkr.com"] [uri "/index.php"] [unique_id "amuVhlymN6QYcoA7XB4_3wAAACw"]
[Thu Jul 30 13:18:46.275241 2026] [security2:error] [pid 872418:tid 872636] [client 179.64.21.229:40314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVhlymN6QYcoA7XB4_4AAAAFg"]
[Thu Jul 30 13:18:46.282971 2026] [security2:error] [pid 872418:tid 872636] [client 179.64.21.229:40314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVhlymN6QYcoA7XB4_4AAAAFg"]
[Thu Jul 30 13:18:46.307487 2026] [security2:error] [pid 872418:tid 872564] [client 20.63.98.115:46680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/headers.php"] [unique_id "amuVhlymN6QYcoA7XB4_4QAAABA"]
[Thu Jul 30 13:18:46.371347 2026] [security2:error] [pid 872418:tid 872650] [client 20.52.54.143:10348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/aaa.php"] [unique_id "amuVhlymN6QYcoA7XB4_4gAAAGY"]
[Thu Jul 30 13:18:47.408143 2026] [security2:error] [pid 872418:tid 872624] [client 172.237.109.114:48795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVhlymN6QYcoA7XB4_5wAAAEw"]
[Thu Jul 30 13:18:47.626327 2026] [security2:error] [pid 872418:tid 872632] [client 20.52.54.143:10351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/getid3-core.php"] [unique_id "amuVh1ymN6QYcoA7XB4_6gAAAFQ"]
[Thu Jul 30 13:18:47.825120 2026] [security2:error] [pid 872418:tid 872663] [client 148.153.159.15:42570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.serverkr.com"] [uri "/index.php"] [unique_id "amuVh1ymN6QYcoA7XB4_7gAAAHM"]
[Thu Jul 30 13:18:48.031440 2026] [core:notice] [pid 872418:tid 872500] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:48.215798 2026] [security2:error] [pid 872418:tid 872501] [remote 216.73.217.142:5024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuViFymN6QYcoA7XB4_8wAALlI"]
[Thu Jul 30 13:18:48.576289 2026] [security2:error] [pid 872418:tid 872574] [client 20.52.54.143:10360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/adminer.php"] [unique_id "amuViFymN6QYcoA7XB4_9QAAABo"]
[Thu Jul 30 13:18:48.630379 2026] [cgid:error] [pid 872418:tid 872563] [client 172.202.44.182:20759] AH01265: stderr from /home2/evkgplte/public_html/website_178d2f94/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 13:18:49.203846 2026] [security2:error] [pid 872418:tid 872597] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuViFymN6QYcoA7XB4_-AAAMVQ"]
[Thu Jul 30 13:18:49.350020 2026] [core:error] [pid 872418:tid 872630] [client 20.52.54.143:10399] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:49.350041 2026] [core:error] [pid 872418:tid 872630] [client 20.52.54.143:10399] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:50.294513 2026] [core:notice] [pid 872418:tid 872622] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:50.779022 2026] [security2:error] [pid 872418:tid 872633] [client 20.63.98.115:26073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/admin.php"] [unique_id "amuVilymN6QYcoA7XB5ADgAAAFU"]
[Thu Jul 30 13:18:52.136546 2026] [security2:error] [pid 872418:tid 872625] [client 20.63.98.115:25664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/flower.php"] [unique_id "amuVjFymN6QYcoA7XB5AFQAAAE0"]
[Thu Jul 30 13:18:53.389538 2026] [security2:error] [pid 872418:tid 872642] [client 20.52.54.143:10342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/alfa.php"] [unique_id "amuVjVymN6QYcoA7XB5AGgAAAF4"]
[Thu Jul 30 13:18:53.812187 2026] [security2:error] [pid 872418:tid 872564] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/laravel/.env"] [unique_id "amuVjVymN6QYcoA7XB5AGwAAABA"]
[Thu Jul 30 13:18:53.863476 2026] [security2:error] [pid 872418:tid 872514] [remote 216.73.217.142:56541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVjVymN6QYcoA7XB5AHAAALF8"]
[Thu Jul 30 13:18:54.202085 2026] [core:notice] [pid 872418:tid 872499] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:54.806555 2026] [security2:error] [pid 872418:tid 872595] [client 82.102.27.195:48852] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuVjlymN6QYcoA7XB5AJgAAAC8"]
[Thu Jul 30 13:18:54.806671 2026] [security2:error] [pid 872418:tid 872595] [client 82.102.27.195:48852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuVjlymN6QYcoA7XB5AJgAAAC8"]
[Thu Jul 30 13:18:54.902572 2026] [security2:error] [pid 872418:tid 872571] [client 172.236.9.101:32980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVjlymN6QYcoA7XB5AIAAAABc"]
[Thu Jul 30 13:18:55.083288 2026] [core:notice] [pid 872418:tid 872579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:55.221652 2026] [security2:error] [pid 872418:tid 872588] [client 20.63.98.115:16133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuVj1ymN6QYcoA7XB5AKwAAACg"]
[Thu Jul 30 13:18:55.251688 2026] [security2:error] [pid 872418:tid 872550] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/symfony/.env"] [unique_id "amuVj1ymN6QYcoA7XB5ALAAAAAI"]
[Thu Jul 30 13:18:55.346800 2026] [security2:error] [pid 872418:tid 872563] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVj1ymN6QYcoA7XB5AKQAAAA8"]
[Thu Jul 30 13:18:55.623018 2026] [core:error] [pid 872418:tid 872630] [client 20.52.54.143:10330] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:55.623041 2026] [core:error] [pid 872418:tid 872630] [client 20.52.54.143:10330] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:18:55.884519 2026] [core:notice] [pid 872418:tid 872653] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:56.454771 2026] [security2:error] [pid 872418:tid 872565] [client 172.237.109.114:9341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVj1ymN6QYcoA7XB5AMwAAABE"]
[Thu Jul 30 13:18:56.562007 2026] [security2:error] [pid 872418:tid 872636] [client 20.63.98.115:16209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-content.php"] [unique_id "amuVkFymN6QYcoA7XB5AXQAAAFg"]
[Thu Jul 30 13:18:56.972333 2026] [security2:error] [pid 872418:tid 872592] [client 179.64.21.229:8368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVkFymN6QYcoA7XB5AYAAAACw"]
[Thu Jul 30 13:18:56.972472 2026] [security2:error] [pid 872418:tid 872592] [client 179.64.21.229:8368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVkFymN6QYcoA7XB5AYAAAACw"]
[Thu Jul 30 13:18:57.659461 2026] [security2:error] [pid 872418:tid 872673] [client 94.154.43.183:27794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "deltaedu.net"] [uri "/.env"] [unique_id "amuVkVymN6QYcoA7XB5AagAAAH0"]
[Thu Jul 30 13:18:57.935766 2026] [security2:error] [pid 872418:tid 872531] [remote 57.141.0.6:35174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amuVkVymN6QYcoA7XB5AbAAAGnA"]
[Thu Jul 30 13:18:58.250917 2026] [security2:error] [pid 872418:tid 872597] [client 78.40.199.55:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "78.40.199.55" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "lucky-strike-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuVklymN6QYcoA7XB5AcgAAADE"], referer: http://lucky-strike-shop.com/hello-world/
[Thu Jul 30 13:18:58.251062 2026] [security2:error] [pid 872418:tid 872597] [client 78.40.199.55:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "lucky-strike-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amuVklymN6QYcoA7XB5AcgAAADE"], referer: http://lucky-strike-shop.com/hello-world/
[Thu Jul 30 13:18:58.432279 2026] [core:notice] [pid 872418:tid 872537] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:58.801772 2026] [security2:error] [pid 872418:tid 872639] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVklymN6QYcoA7XB5AegAAAFs"]
[Thu Jul 30 13:18:59.248431 2026] [core:notice] [pid 872418:tid 872646] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:59.328526 2026] [security2:error] [pid 872418:tid 872588] [client 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVklymN6QYcoA7XB5AfQAAKHo"]
[Thu Jul 30 13:18:59.419928 2026] [core:notice] [pid 872418:tid 872573] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:18:59.853918 2026] [security2:error] [pid 872418:tid 872583] [client 20.52.54.143:11155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuVk1ymN6QYcoA7XB5AggAAACM"]
[Thu Jul 30 13:19:00.163626 2026] [proxy:error] [pid 872418:tid 872621] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:00.163704 2026] [proxy_http:error] [pid 872418:tid 872621] [client 3.228.112.215:3634] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:00.164386 2026] [proxy:error] [pid 872418:tid 872621] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:00.164449 2026] [proxy_http:error] [pid 872418:tid 872621] [client 3.228.112.215:3634] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:00.175025 2026] [proxy:error] [pid 872418:tid 872558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:00.175084 2026] [proxy_http:error] [pid 872418:tid 872558] [client 54.87.222.253:28845] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:00.175650 2026] [proxy:error] [pid 872418:tid 872558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:00.175697 2026] [proxy_http:error] [pid 872418:tid 872558] [client 54.87.222.253:28845] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:00.260702 2026] [security2:error] [pid 872418:tid 872595] [client 20.63.98.115:16179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/function.php"] [unique_id "amuVlFymN6QYcoA7XB5AjgAAAC8"]
[Thu Jul 30 13:19:00.316305 2026] [security2:error] [pid 872418:tid 872648] [client 185.191.171.11:38088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/03/08/humorista-kleber-lopes-morre-aos-39-anos-apos-piora-da-covid/"] [unique_id "amuVlFymN6QYcoA7XB5AjwAAAGQ"]
[Thu Jul 30 13:19:00.316483 2026] [security2:error] [pid 872418:tid 872648] [client 185.191.171.11:38088] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/03/08/humorista-kleber-lopes-morre-aos-39-anos-apos-piora-da-covid/"] [unique_id "amuVlFymN6QYcoA7XB5AjwAAAGQ"]
[Thu Jul 30 13:19:00.567187 2026] [security2:error] [pid 872418:tid 872604] [client 20.52.54.143:11158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuVlFymN6QYcoA7XB5AkgAAADg"]
[Thu Jul 30 13:19:01.255417 2026] [core:notice] [pid 872418:tid 872419] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:01.298448 2026] [security2:error] [pid 872418:tid 872610] [client 20.52.54.143:11161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuVlVymN6QYcoA7XB5AmQAAAD4"]
[Thu Jul 30 13:19:01.819731 2026] [security2:error] [pid 872418:tid 872619] [client 34.74.242.206:1591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/"] [unique_id "amuVlVymN6QYcoA7XB5AngAAAEc"]
[Thu Jul 30 13:19:01.819914 2026] [security2:error] [pid 872418:tid 872619] [client 34.74.242.206:1591] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/"] [unique_id "amuVlVymN6QYcoA7XB5AngAAAEc"]
[Thu Jul 30 13:19:01.829295 2026] [security2:error] [pid 872418:tid 872633] [client 20.52.54.143:10422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/edit.php"] [unique_id "amuVlVymN6QYcoA7XB5AnwAAAFU"]
[Thu Jul 30 13:19:01.951000 2026] [security2:error] [pid 872418:tid 872594] [client 20.9.63.139:30242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVlVymN6QYcoA7XB5ApQAAAC4"]
[Thu Jul 30 13:19:01.951093 2026] [security2:error] [pid 872418:tid 872594] [client 20.9.63.139:30242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVlVymN6QYcoA7XB5ApQAAAC4"]
[Thu Jul 30 13:19:02.071182 2026] [security2:error] [pid 872418:tid 872568] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVlVymN6QYcoA7XB5AnAAAABQ"]
[Thu Jul 30 13:19:02.601874 2026] [core:error] [pid 872418:tid 872589] [client 20.52.54.143:10364] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:02.601901 2026] [core:error] [pid 872418:tid 872589] [client 20.52.54.143:10364] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:03.032810 2026] [security2:error] [pid 872418:tid 872672] [client 20.63.98.115:26456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/chosen.php"] [unique_id "amuVl1ymN6QYcoA7XB5AqQAAAHw"]
[Thu Jul 30 13:19:03.222361 2026] [security2:error] [pid 872418:tid 872422] [remote 216.73.217.142:56541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVl1ymN6QYcoA7XB5AqwAAVwM"]
[Thu Jul 30 13:19:03.341892 2026] [security2:error] [pid 872418:tid 872655] [client 20.9.63.139:4914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVl1ymN6QYcoA7XB5ArAAAAGs"]
[Thu Jul 30 13:19:03.342030 2026] [security2:error] [pid 872418:tid 872655] [client 20.9.63.139:4914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVl1ymN6QYcoA7XB5ArAAAAGs"]
[Thu Jul 30 13:19:04.257810 2026] [core:error] [pid 872418:tid 872675] [client 20.52.54.143:10359] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:04.257841 2026] [core:error] [pid 872418:tid 872675] [client 20.52.54.143:10359] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:04.469814 2026] [security2:error] [pid 872418:tid 872652] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/backup/.env"] [unique_id "amuVmFymN6QYcoA7XB5AsAAAAGg"]
[Thu Jul 30 13:19:04.900448 2026] [security2:error] [pid 872418:tid 872660] [client 172.236.9.101:44946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVmFymN6QYcoA7XB5ArwAAAHA"]
[Thu Jul 30 13:19:05.046329 2026] [security2:error] [pid 872418:tid 872656] [client 20.52.54.143:10397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/sf.php"] [unique_id "amuVmVymN6QYcoA7XB5AsgAAAGw"]
[Thu Jul 30 13:19:05.461698 2026] [security2:error] [pid 872418:tid 872627] [client 20.63.98.115:16174] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "essenceeast.com"] [uri "/1.php"] [unique_id "amuVmVymN6QYcoA7XB5AuwAAAE8"]
[Thu Jul 30 13:19:05.461837 2026] [security2:error] [pid 872418:tid 872627] [client 20.63.98.115:16174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/1.php"] [unique_id "amuVmVymN6QYcoA7XB5AuwAAAE8"]
[Thu Jul 30 13:19:05.654778 2026] [proxy:error] [pid 872418:tid 872638] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:05.655075 2026] [proxy_http:error] [pid 872418:tid 872638] [client 54.87.222.253:3896] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:05.655941 2026] [proxy:error] [pid 872418:tid 872638] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:05.656027 2026] [proxy_http:error] [pid 872418:tid 872638] [client 54.87.222.253:3896] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:05.667896 2026] [autoindex:error] [pid 872418:tid 872601] [client 52.202.41.153:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:19:05.684734 2026] [proxy:error] [pid 872418:tid 872590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:05.684813 2026] [proxy_http:error] [pid 872418:tid 872590] [client 54.87.222.253:5292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:05.685460 2026] [proxy:error] [pid 872418:tid 872590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:05.685507 2026] [proxy_http:error] [pid 872418:tid 872590] [client 54.87.222.253:5292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:05.761988 2026] [autoindex:error] [pid 872418:tid 872555] [client 52.202.41.153:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:19:07.450083 2026] [security2:error] [pid 872418:tid 872620] [client 179.64.21.229:23372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVm1ymN6QYcoA7XB5A0QAAAEg"]
[Thu Jul 30 13:19:07.450263 2026] [security2:error] [pid 872418:tid 872620] [client 179.64.21.229:23372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVm1ymN6QYcoA7XB5A0QAAAEg"]
[Thu Jul 30 13:19:07.842382 2026] [security2:error] [pid 872418:tid 872562] [client 20.63.98.115:50299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/lv.php"] [unique_id "amuVm1ymN6QYcoA7XB5A0wAAAA4"]
[Thu Jul 30 13:19:07.865399 2026] [core:notice] [pid 872418:tid 872421] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:08.191910 2026] [core:error] [pid 872418:tid 872610] [client 20.52.54.143:10326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:08.191932 2026] [core:error] [pid 872418:tid 872610] [client 20.52.54.143:10326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:08.596838 2026] [core:notice] [pid 872418:tid 872654] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:08.750246 2026] [security2:error] [pid 872418:tid 872673] [client 20.9.63.139:27294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/inputs.php"] [unique_id "amuVnFymN6QYcoA7XB5A2QAAAH0"]
[Thu Jul 30 13:19:08.750363 2026] [security2:error] [pid 872418:tid 872673] [client 20.9.63.139:27294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/inputs.php"] [unique_id "amuVnFymN6QYcoA7XB5A2QAAAH0"]
[Thu Jul 30 13:19:08.832590 2026] [security2:error] [pid 872418:tid 872424] [remote 216.73.217.142:12519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVnFymN6QYcoA7XB5A3QAAFAU"]
[Thu Jul 30 13:19:08.906194 2026] [proxy:error] [pid 872418:tid 872581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:08.906265 2026] [proxy_http:error] [pid 872418:tid 872581] [client 32.194.121.99:19635] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:08.906871 2026] [proxy:error] [pid 872418:tid 872581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:08.906916 2026] [proxy_http:error] [pid 872418:tid 872581] [client 32.194.121.99:19635] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:08.924577 2026] [proxy:error] [pid 872418:tid 872666] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:08.924644 2026] [proxy_http:error] [pid 872418:tid 872666] [client 34.224.175.62:31644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:08.925216 2026] [proxy:error] [pid 872418:tid 872666] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:08.925262 2026] [proxy_http:error] [pid 872418:tid 872666] [client 34.224.175.62:31644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:09.310414 2026] [security2:error] [pid 872418:tid 872584] [client 20.52.54.143:10414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wso.php"] [unique_id "amuVnVymN6QYcoA7XB5A7gAAACQ"]
[Thu Jul 30 13:19:09.921091 2026] [security2:error] [pid 872418:tid 872607] [client 20.63.98.115:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/css.php"] [unique_id "amuVnVymN6QYcoA7XB5A9QAAADs"]
[Thu Jul 30 13:19:10.264021 2026] [security2:error] [pid 872418:tid 872567] [client 17.241.219.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuVnlymN6QYcoA7XB5A-QAAABM"]
[Thu Jul 30 13:19:10.458022 2026] [core:notice] [pid 872418:tid 872551] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:11.964374 2026] [core:notice] [pid 872418:tid 872430] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:12.524878 2026] [core:notice] [pid 872418:tid 872431] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:12.915759 2026] [security2:error] [pid 872418:tid 872553] [client 20.63.98.115:42622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/gecko.php"] [unique_id "amuVoFymN6QYcoA7XB5BCQAAAAU"]
[Thu Jul 30 13:19:13.228270 2026] [security2:error] [pid 872418:tid 872427] [remote 216.73.217.142:12519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVoVymN6QYcoA7XB5BCgAAWAg"]
[Thu Jul 30 13:19:13.414898 2026] [security2:error] [pid 872418:tid 872622] [client 20.52.54.143:10340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/ioxi-o.php"] [unique_id "amuVoVymN6QYcoA7XB5BCwAAAEo"]
[Thu Jul 30 13:19:14.449449 2026] [proxy:error] [pid 872418:tid 872572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:14.449528 2026] [proxy_http:error] [pid 872418:tid 872572] [client 44.213.206.96:4122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:14.450113 2026] [proxy:error] [pid 872418:tid 872572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:14.450163 2026] [proxy_http:error] [pid 872418:tid 872572] [client 44.213.206.96:4122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:14.468667 2026] [proxy:error] [pid 872418:tid 872640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:14.468736 2026] [proxy_http:error] [pid 872418:tid 872640] [client 52.4.19.39:15862] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:14.469569 2026] [proxy:error] [pid 872418:tid 872640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:14.469626 2026] [proxy_http:error] [pid 872418:tid 872640] [client 52.4.19.39:15862] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:14.566812 2026] [security2:error] [pid 872418:tid 872610] [client 20.52.54.143:10371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/file56.php"] [unique_id "amuVolymN6QYcoA7XB5BIgAAAD4"]
[Thu Jul 30 13:19:14.813202 2026] [security2:error] [pid 872418:tid 872575] [client 20.63.98.115:61533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/xmlrpc.php"] [unique_id "amuVolymN6QYcoA7XB5BJAAAABs"]
[Thu Jul 30 13:19:14.932117 2026] [security2:error] [pid 872418:tid 872649] [client 172.236.9.101:44618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVolymN6QYcoA7XB5BEwAAAGU"]
[Thu Jul 30 13:19:15.296004 2026] [security2:error] [pid 872418:tid 872587] [client 20.52.54.143:11138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuVo1ymN6QYcoA7XB5BKwAAACc"]
[Thu Jul 30 13:19:16.115196 2026] [security2:error] [pid 872418:tid 872627] [client 20.52.54.143:10328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuVpFymN6QYcoA7XB5BMQAAAE8"]
[Thu Jul 30 13:19:18.039744 2026] [security2:error] [pid 872418:tid 872551] [client 20.52.54.143:10379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/edit.php"] [unique_id "amuVplymN6QYcoA7XB5BPAAAAAM"]
[Thu Jul 30 13:19:18.154898 2026] [security2:error] [pid 872418:tid 872625] [client 179.64.21.229:46605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVplymN6QYcoA7XB5BQgAAAE0"]
[Thu Jul 30 13:19:18.155054 2026] [security2:error] [pid 872418:tid 872625] [client 179.64.21.229:46605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVplymN6QYcoA7XB5BQgAAAE0"]
[Thu Jul 30 13:19:18.837275 2026] [security2:error] [pid 872418:tid 872454] [remote 216.73.217.142:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuVplymN6QYcoA7XB5BSQAAViM"]
[Thu Jul 30 13:19:18.922349 2026] [security2:error] [pid 872418:tid 872449] [remote 66.249.93.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuVplymN6QYcoA7XB5BQQAACx4"]
[Thu Jul 30 13:19:18.976468 2026] [security2:error] [pid 872418:tid 872604] [client 20.52.54.143:10339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/2.php"] [unique_id "amuVplymN6QYcoA7XB5BSgAAADg"]
[Thu Jul 30 13:19:19.447991 2026] [security2:error] [pid 872418:tid 872465] [remote 47.128.28.119:13774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-11-retro-jubilee-25th-anniversary-2/"] [unique_id "amuVp1ymN6QYcoA7XB5BVQAAFC4"]
[Thu Jul 30 13:19:19.696044 2026] [security2:error] [pid 872418:tid 872650] [client 20.52.54.143:10581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuVp1ymN6QYcoA7XB5BVgAAAGY"]
[Thu Jul 30 13:19:20.297926 2026] [security2:error] [pid 872418:tid 872563] [client 20.52.54.143:10356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/mah.php"] [unique_id "amuVqFymN6QYcoA7XB5BWgAAAA8"]
[Thu Jul 30 13:19:21.277221 2026] [security2:error] [pid 872418:tid 872668] [client 20.52.54.143:10315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/send.php"] [unique_id "amuVqVymN6QYcoA7XB5BXgAAAHg"]
[Thu Jul 30 13:19:22.016390 2026] [security2:error] [pid 872418:tid 872611] [client 20.63.98.115:33577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/f35.php"] [unique_id "amuVqlymN6QYcoA7XB5BZQAAAD8"]
[Thu Jul 30 13:19:22.434624 2026] [core:notice] [pid 872418:tid 872645] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:22.472397 2026] [proxy:error] [pid 872418:tid 872656] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:22.472507 2026] [proxy_http:error] [pid 872418:tid 872656] [client 34.233.129.35:24998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:22.472936 2026] [proxy:error] [pid 872418:tid 872652] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:22.473028 2026] [proxy_http:error] [pid 872418:tid 872652] [client 34.224.175.62:51886] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:22.473312 2026] [proxy:error] [pid 872418:tid 872656] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:22.473372 2026] [proxy_http:error] [pid 872418:tid 872656] [client 34.233.129.35:24998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:22.473813 2026] [proxy:error] [pid 872418:tid 872652] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:22.473880 2026] [proxy_http:error] [pid 872418:tid 872652] [client 34.224.175.62:51886] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:22.957962 2026] [security2:error] [pid 872418:tid 872594] [client 172.236.9.101:9559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVqlymN6QYcoA7XB5BZgAAAC4"]
[Thu Jul 30 13:19:23.430948 2026] [core:notice] [pid 872418:tid 872558] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:23.501965 2026] [security2:error] [pid 872418:tid 872625] [client 20.9.63.139:29827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/admin.php"] [unique_id "amuVq1ymN6QYcoA7XB5BeQAAAE0"]
[Thu Jul 30 13:19:23.502125 2026] [security2:error] [pid 872418:tid 872625] [client 20.9.63.139:29827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/admin.php"] [unique_id "amuVq1ymN6QYcoA7XB5BeQAAAE0"]
[Thu Jul 30 13:19:24.552670 2026] [security2:error] [pid 872418:tid 872565] [client 20.9.63.139:20994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/goods.php"] [unique_id "amuVrFymN6QYcoA7XB5BfgAAABE"]
[Thu Jul 30 13:19:24.552771 2026] [security2:error] [pid 872418:tid 872565] [client 20.9.63.139:20994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/goods.php"] [unique_id "amuVrFymN6QYcoA7XB5BfgAAABE"]
[Thu Jul 30 13:19:24.660007 2026] [security2:error] [pid 872418:tid 872642] [client 20.63.98.115:33572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/autoload_classmap.php"] [unique_id "amuVrFymN6QYcoA7XB5BfwAAAF4"]
[Thu Jul 30 13:19:25.478322 2026] [security2:error] [pid 872418:tid 872591] [client 20.9.63.139:1212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/file.php"] [unique_id "amuVrVymN6QYcoA7XB5BhQAAACs"]
[Thu Jul 30 13:19:25.478438 2026] [security2:error] [pid 872418:tid 872591] [client 20.9.63.139:1212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/file.php"] [unique_id "amuVrVymN6QYcoA7XB5BhQAAACs"]
[Thu Jul 30 13:19:25.704372 2026] [security2:error] [pid 872418:tid 872587] [client 20.52.54.143:10331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuVrVymN6QYcoA7XB5BhwAAACc"]
[Thu Jul 30 13:19:26.157566 2026] [security2:error] [pid 872418:tid 872651] [client 20.9.63.139:10564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/adminfuns.php"] [unique_id "amuVrlymN6QYcoA7XB5BiQAAAGc"]
[Thu Jul 30 13:19:26.157725 2026] [security2:error] [pid 872418:tid 872651] [client 20.9.63.139:10564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/adminfuns.php"] [unique_id "amuVrlymN6QYcoA7XB5BiQAAAGc"]
[Thu Jul 30 13:19:26.597681 2026] [security2:error] [pid 872418:tid 872568] [client 20.63.98.115:33587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/NewFile.php"] [unique_id "amuVrlymN6QYcoA7XB5BiwAAABQ"]
[Thu Jul 30 13:19:26.870766 2026] [proxy:error] [pid 872418:tid 872589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:26.870849 2026] [proxy_http:error] [pid 872418:tid 872589] [client 34.233.129.35:18352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:26.871418 2026] [proxy:error] [pid 872418:tid 872589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:26.871463 2026] [proxy_http:error] [pid 872418:tid 872589] [client 34.233.129.35:18352] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:26.881534 2026] [proxy:error] [pid 872418:tid 872581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:26.881593 2026] [proxy_http:error] [pid 872418:tid 872581] [client 34.233.129.35:42559] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:26.882159 2026] [proxy:error] [pid 872418:tid 872581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:26.882204 2026] [proxy_http:error] [pid 872418:tid 872581] [client 34.233.129.35:42559] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:26.887077 2026] [proxy:error] [pid 872418:tid 872563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:26.887154 2026] [proxy_http:error] [pid 872418:tid 872563] [client 98.87.102.177:50767] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:26.887988 2026] [proxy:error] [pid 872418:tid 872563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:26.888047 2026] [proxy_http:error] [pid 872418:tid 872563] [client 98.87.102.177:50767] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:27.117108 2026] [security2:error] [pid 872418:tid 872662] [client 20.9.63.139:21054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/404.php"] [unique_id "amuVr1ymN6QYcoA7XB5BngAAAHI"]
[Thu Jul 30 13:19:27.117221 2026] [security2:error] [pid 872418:tid 872662] [client 20.9.63.139:21054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/404.php"] [unique_id "amuVr1ymN6QYcoA7XB5BngAAAHI"]
[Thu Jul 30 13:19:27.506541 2026] [security2:error] [pid 872418:tid 872645] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVr1ymN6QYcoA7XB5BnwAAAGE"]
[Thu Jul 30 13:19:27.506656 2026] [security2:error] [pid 872418:tid 872645] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVr1ymN6QYcoA7XB5BnwAAAGE"]
[Thu Jul 30 13:19:27.642644 2026] [security2:error] [pid 872418:tid 872656] [client 194.187.251.163:36056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuVr1ymN6QYcoA7XB5BoQAAAGw"]
[Thu Jul 30 13:19:27.642767 2026] [security2:error] [pid 872418:tid 872656] [client 194.187.251.163:36056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuVr1ymN6QYcoA7XB5BoQAAAGw"]
[Thu Jul 30 13:19:27.730130 2026] [security2:error] [pid 872418:tid 872588] [client 20.63.98.115:61564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/xx.php"] [unique_id "amuVr1ymN6QYcoA7XB5BogAAACg"]
[Thu Jul 30 13:19:27.756879 2026] [security2:error] [pid 872418:tid 872652] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVr1ymN6QYcoA7XB5BowAAAGg"]
[Thu Jul 30 13:19:27.756988 2026] [security2:error] [pid 872418:tid 872652] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVr1ymN6QYcoA7XB5BowAAAGg"]
[Thu Jul 30 13:19:27.788354 2026] [proxy:error] [pid 872418:tid 872607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:27.788423 2026] [proxy_http:error] [pid 872418:tid 872607] [client 18.211.55.47:20607] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:27.788992 2026] [proxy:error] [pid 872418:tid 872607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:27.789037 2026] [proxy_http:error] [pid 872418:tid 872607] [client 18.211.55.47:20607] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:27.838901 2026] [proxy:error] [pid 872418:tid 872646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:27.838988 2026] [proxy_http:error] [pid 872418:tid 872646] [client 18.211.55.47:3630] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:27.839567 2026] [proxy:error] [pid 872418:tid 872646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:27.839609 2026] [proxy_http:error] [pid 872418:tid 872646] [client 18.211.55.47:3630] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:27.995285 2026] [security2:error] [pid 872418:tid 872615] [client 20.9.63.139:20448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/wk/index.php"] [unique_id "amuVr1ymN6QYcoA7XB5BrgAAAEM"]
[Thu Jul 30 13:19:27.995403 2026] [security2:error] [pid 872418:tid 872615] [client 20.9.63.139:20448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/wk/index.php"] [unique_id "amuVr1ymN6QYcoA7XB5BrgAAAEM"]
[Thu Jul 30 13:19:28.015082 2026] [security2:error] [pid 872418:tid 872669] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuVsFymN6QYcoA7XB5BrwAAAHk"]
[Thu Jul 30 13:19:28.015169 2026] [security2:error] [pid 872418:tid 872669] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuVsFymN6QYcoA7XB5BrwAAAHk"]
[Thu Jul 30 13:19:28.259957 2026] [security2:error] [pid 872418:tid 872621] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/err.php"] [unique_id "amuVsFymN6QYcoA7XB5BugAAAEk"]
[Thu Jul 30 13:19:28.260084 2026] [security2:error] [pid 872418:tid 872621] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/err.php"] [unique_id "amuVsFymN6QYcoA7XB5BugAAAEk"]
[Thu Jul 30 13:19:28.495274 2026] [security2:error] [pid 872418:tid 872671] [client 23.94.216.234:47890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "mail.kii.nyx.temporary.site"] [uri "/"] [unique_id "amuVsFymN6QYcoA7XB5BuwAAAHs"]
[Thu Jul 30 13:19:28.509920 2026] [core:error] [pid 872418:tid 872561] [client 20.52.54.143:10362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:28.509946 2026] [core:error] [pid 872418:tid 872561] [client 20.52.54.143:10362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:28.513226 2026] [security2:error] [pid 872418:tid 872620] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/img.php"] [unique_id "amuVsFymN6QYcoA7XB5BvQAAAEg"]
[Thu Jul 30 13:19:28.513308 2026] [security2:error] [pid 872418:tid 872620] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/img.php"] [unique_id "amuVsFymN6QYcoA7XB5BvQAAAEg"]
[Thu Jul 30 13:19:28.766820 2026] [security2:error] [pid 872418:tid 872667] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/aa.php"] [unique_id "amuVsFymN6QYcoA7XB5BvwAAAHc"]
[Thu Jul 30 13:19:28.766939 2026] [security2:error] [pid 872418:tid 872667] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/aa.php"] [unique_id "amuVsFymN6QYcoA7XB5BvwAAAHc"]
[Thu Jul 30 13:19:28.907435 2026] [security2:error] [pid 872418:tid 872554] [client 20.9.63.139:23195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/about.php"] [unique_id "amuVsFymN6QYcoA7XB5BwAAAAAY"]
[Thu Jul 30 13:19:28.907559 2026] [security2:error] [pid 872418:tid 872554] [client 20.9.63.139:23195] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/about.php"] [unique_id "amuVsFymN6QYcoA7XB5BwAAAAAY"]
[Thu Jul 30 13:19:28.917089 2026] [security2:error] [pid 872418:tid 872565] [client 179.64.21.229:19203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVsFymN6QYcoA7XB5BwQAAABE"]
[Thu Jul 30 13:19:28.918536 2026] [security2:error] [pid 872418:tid 872565] [client 179.64.21.229:19203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVsFymN6QYcoA7XB5BwQAAABE"]
[Thu Jul 30 13:19:28.969883 2026] [core:notice] [pid 872418:tid 872612] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:29.023343 2026] [security2:error] [pid 872418:tid 872572] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/av.php"] [unique_id "amuVsVymN6QYcoA7XB5ByQAAABg"]
[Thu Jul 30 13:19:29.023495 2026] [security2:error] [pid 872418:tid 872572] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/av.php"] [unique_id "amuVsVymN6QYcoA7XB5ByQAAABg"]
[Thu Jul 30 13:19:29.098018 2026] [security2:error] [pid 872418:tid 872634] [client 20.63.98.115:61519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/plugins.php"] [unique_id "amuVsVymN6QYcoA7XB5BygAAAFY"]
[Thu Jul 30 13:19:29.256743 2026] [security2:error] [pid 872418:tid 872596] [client 20.52.54.143:10570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/about.php"] [unique_id "amuVsVymN6QYcoA7XB5BzAAAADA"]
[Thu Jul 30 13:19:29.281444 2026] [security2:error] [pid 872418:tid 872665] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/xa.php"] [unique_id "amuVsVymN6QYcoA7XB5BzQAAAHU"]
[Thu Jul 30 13:19:29.281586 2026] [security2:error] [pid 872418:tid 872665] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/xa.php"] [unique_id "amuVsVymN6QYcoA7XB5BzQAAAHU"]
[Thu Jul 30 13:19:29.535506 2026] [security2:error] [pid 872418:tid 872589] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/media.php"] [unique_id "amuVsVymN6QYcoA7XB5BzwAAACk"]
[Thu Jul 30 13:19:29.535649 2026] [security2:error] [pid 872418:tid 872589] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/media.php"] [unique_id "amuVsVymN6QYcoA7XB5BzwAAACk"]
[Thu Jul 30 13:19:29.633062 2026] [security2:error] [pid 872418:tid 872591] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVsFymN6QYcoA7XB5ByAAAACs"]
[Thu Jul 30 13:19:29.779575 2026] [security2:error] [pid 872418:tid 872630] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/images.php"] [unique_id "amuVsVymN6QYcoA7XB5B1AAAAFI"]
[Thu Jul 30 13:19:29.779696 2026] [security2:error] [pid 872418:tid 872630] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/images.php"] [unique_id "amuVsVymN6QYcoA7XB5B1AAAAFI"]
[Thu Jul 30 13:19:29.881811 2026] [security2:error] [pid 872418:tid 872598] [client 172.236.9.101:43425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVsVymN6QYcoA7XB5BzgAAADI"]
[Thu Jul 30 13:19:29.945818 2026] [security2:error] [pid 872418:tid 872603] [client 20.52.54.143:10349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/options.php"] [unique_id "amuVsVymN6QYcoA7XB5B1gAAADc"]
[Thu Jul 30 13:19:30.020571 2026] [security2:error] [pid 872418:tid 872662] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/gecko.php"] [unique_id "amuVslymN6QYcoA7XB5B1wAAAHI"]
[Thu Jul 30 13:19:30.020683 2026] [security2:error] [pid 872418:tid 872662] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/gecko.php"] [unique_id "amuVslymN6QYcoA7XB5B1wAAAHI"]
[Thu Jul 30 13:19:30.105080 2026] [core:notice] [pid 872418:tid 872563] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:30.109527 2026] [security2:error] [pid 872418:tid 872563] [client 66.249.79.8:46144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/citationstylelanguage/get/acs-nano"] [unique_id "amuVsVymN6QYcoA7XB5B1QAAAA8"]
[Thu Jul 30 13:19:30.268424 2026] [security2:error] [pid 872418:tid 872609] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/82.php"] [unique_id "amuVslymN6QYcoA7XB5B2AAAAD0"]
[Thu Jul 30 13:19:30.268534 2026] [security2:error] [pid 872418:tid 872609] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/82.php"] [unique_id "amuVslymN6QYcoA7XB5B2AAAAD0"]
[Thu Jul 30 13:19:30.495826 2026] [security2:error] [pid 872418:tid 872550] [client 20.52.54.143:10358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuVslymN6QYcoA7XB5B2wAAAAI"]
[Thu Jul 30 13:19:30.518005 2026] [security2:error] [pid 872418:tid 872557] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/xstelth.php"] [unique_id "amuVslymN6QYcoA7XB5B3AAAAAk"]
[Thu Jul 30 13:19:30.518160 2026] [security2:error] [pid 872418:tid 872557] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/xstelth.php"] [unique_id "amuVslymN6QYcoA7XB5B3AAAAAk"]
[Thu Jul 30 13:19:30.589942 2026] [proxy:error] [pid 872418:tid 872672] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:30.590047 2026] [proxy_http:error] [pid 872418:tid 872672] [client 44.216.125.112:49827] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:30.590777 2026] [proxy:error] [pid 872418:tid 872672] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:30.590832 2026] [proxy_http:error] [pid 872418:tid 872672] [client 44.216.125.112:49827] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:30.614806 2026] [proxy:error] [pid 872418:tid 872635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:30.614897 2026] [proxy_http:error] [pid 872418:tid 872635] [client 18.211.55.47:47158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:30.615509 2026] [proxy:error] [pid 872418:tid 872635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:30.615558 2026] [proxy_http:error] [pid 872418:tid 872635] [client 18.211.55.47:47158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:30.725238 2026] [security2:error] [pid 872418:tid 872638] [client 20.9.63.139:36296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/term.php"] [unique_id "amuVslymN6QYcoA7XB5B5wAAAFo"]
[Thu Jul 30 13:19:30.725360 2026] [security2:error] [pid 872418:tid 872638] [client 20.9.63.139:36296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/term.php"] [unique_id "amuVslymN6QYcoA7XB5B5wAAAFo"]
[Thu Jul 30 13:19:30.780962 2026] [security2:error] [pid 872418:tid 872641] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/xp.php"] [unique_id "amuVslymN6QYcoA7XB5B6AAAAF0"]
[Thu Jul 30 13:19:30.781149 2026] [security2:error] [pid 872418:tid 872641] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/xp.php"] [unique_id "amuVslymN6QYcoA7XB5B6AAAAF0"]
[Thu Jul 30 13:19:30.857832 2026] [security2:error] [pid 872418:tid 872605] [client 172.236.9.101:49298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVslymN6QYcoA7XB5B2QAAADk"]
[Thu Jul 30 13:19:30.878701 2026] [security2:error] [pid 872418:tid 872560] [client 20.63.98.115:42588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/xxx.php"] [unique_id "amuVslymN6QYcoA7XB5B6QAAAAw"]
[Thu Jul 30 13:19:31.067920 2026] [security2:error] [pid 872418:tid 872627] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/admin.php"] [unique_id "amuVs1ymN6QYcoA7XB5B6wAAAE8"]
[Thu Jul 30 13:19:31.068089 2026] [security2:error] [pid 872418:tid 872627] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/admin.php"] [unique_id "amuVs1ymN6QYcoA7XB5B6wAAAE8"]
[Thu Jul 30 13:19:31.316860 2026] [security2:error] [pid 872418:tid 872648] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/adminner.php"] [unique_id "amuVs1ymN6QYcoA7XB5B7QAAAGQ"]
[Thu Jul 30 13:19:31.317015 2026] [security2:error] [pid 872418:tid 872648] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/adminner.php"] [unique_id "amuVs1ymN6QYcoA7XB5B7QAAAGQ"]
[Thu Jul 30 13:19:31.410461 2026] [core:notice] [pid 872418:tid 872583] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:31.812714 2026] [security2:error] [pid 872418:tid 872570] [client 20.52.54.143:10336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/wp-file.php"] [unique_id "amuVs1ymN6QYcoA7XB5B8AAAABY"]
[Thu Jul 30 13:19:32.661799 2026] [security2:error] [pid 872418:tid 872671] [client 20.63.98.115:61668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/css.php"] [unique_id "amuVtFymN6QYcoA7XB5B9AAAAHs"]
[Thu Jul 30 13:19:32.723299 2026] [security2:error] [pid 872418:tid 872661] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVtFymN6QYcoA7XB5B8QAAcUQ"]
[Thu Jul 30 13:19:32.987947 2026] [security2:error] [pid 872418:tid 872559] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/a.php"] [unique_id "amuVtFymN6QYcoA7XB5B9QAAAAs"]
[Thu Jul 30 13:19:32.988083 2026] [security2:error] [pid 872418:tid 872559] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/a.php"] [unique_id "amuVtFymN6QYcoA7XB5B9QAAAAs"]
[Thu Jul 30 13:19:33.100770 2026] [security2:error] [pid 872418:tid 872562] [client 20.52.54.143:10367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeewalk.com"] [uri "/sid3.php"] [unique_id "amuVtVymN6QYcoA7XB5B9gAAAA4"]
[Thu Jul 30 13:19:33.235194 2026] [security2:error] [pid 872418:tid 872486] [remote 216.73.217.142:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVtVymN6QYcoA7XB5B9wAARUM"]
[Thu Jul 30 13:19:33.245722 2026] [security2:error] [pid 872418:tid 872554] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/k.php"] [unique_id "amuVtVymN6QYcoA7XB5B-AAAAAY"]
[Thu Jul 30 13:19:33.245798 2026] [security2:error] [pid 872418:tid 872554] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/k.php"] [unique_id "amuVtVymN6QYcoA7XB5B-AAAAAY"]
[Thu Jul 30 13:19:33.491312 2026] [security2:error] [pid 872418:tid 872622] [client 20.63.98.115:33564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuVtVymN6QYcoA7XB5B-wAAAEo"]
[Thu Jul 30 13:19:34.379539 2026] [security2:error] [pid 872418:tid 872654] [client 20.9.63.139:23223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/ioxi-o.php"] [unique_id "amuVtlymN6QYcoA7XB5B_AAAAGo"]
[Thu Jul 30 13:19:34.379686 2026] [security2:error] [pid 872418:tid 872654] [client 20.9.63.139:23223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/ioxi-o.php"] [unique_id "amuVtlymN6QYcoA7XB5B_AAAAGo"]
[Thu Jul 30 13:19:34.765532 2026] [security2:error] [pid 872418:tid 872634] [client 185.191.171.7:34438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/product-page/beginner-workout-plan"] [unique_id "amuVtlymN6QYcoA7XB5CAAAAAFY"]
[Thu Jul 30 13:19:34.765683 2026] [security2:error] [pid 872418:tid 872634] [client 185.191.171.7:34438] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/product-page/beginner-workout-plan"] [unique_id "amuVtlymN6QYcoA7XB5CAAAAAFY"]
[Thu Jul 30 13:19:35.007049 2026] [security2:error] [pid 872418:tid 872640] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuVtlymN6QYcoA7XB5B_wAAAFw"]
[Thu Jul 30 13:19:35.025528 2026] [security2:error] [pid 872418:tid 872614] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/222.php"] [unique_id "amuVt1ymN6QYcoA7XB5CBgAAAEI"]
[Thu Jul 30 13:19:35.025610 2026] [security2:error] [pid 872418:tid 872614] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/222.php"] [unique_id "amuVt1ymN6QYcoA7XB5CBgAAAEI"]
[Thu Jul 30 13:19:35.272884 2026] [security2:error] [pid 872418:tid 872630] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/mac.php"] [unique_id "amuVt1ymN6QYcoA7XB5CDwAAAFI"]
[Thu Jul 30 13:19:35.273010 2026] [security2:error] [pid 872418:tid 872630] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/mac.php"] [unique_id "amuVt1ymN6QYcoA7XB5CDwAAAFI"]
[Thu Jul 30 13:19:35.533750 2026] [autoindex:error] [pid 872418:tid 872662] [client 4.185.41.66:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_26e591d8/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:19:35.534518 2026] [security2:error] [pid 872418:tid 872662] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.chimnify.services"] [uri "/cgi-sys/403.html"] [unique_id "amuVt1ymN6QYcoA7XB5CFAAAAHI"]
[Thu Jul 30 13:19:35.793535 2026] [autoindex:error] [pid 872418:tid 872666] [client 4.185.41.66:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_26e591d8/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:19:35.794281 2026] [security2:error] [pid 872418:tid 872666] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.chimnify.services"] [uri "/cgi-sys/403.html"] [unique_id "amuVt1ymN6QYcoA7XB5CFQAAAHY"]
[Thu Jul 30 13:19:35.934498 2026] [security2:error] [pid 872418:tid 872598] [client 172.236.9.101:21359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVt1ymN6QYcoA7XB5CEwAAADI"]
[Thu Jul 30 13:19:35.943671 2026] [security2:error] [pid 872418:tid 872550] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/ops.php"] [unique_id "amuVt1ymN6QYcoA7XB5CGQAAAAI"]
[Thu Jul 30 13:19:35.943818 2026] [security2:error] [pid 872418:tid 872550] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/ops.php"] [unique_id "amuVt1ymN6QYcoA7XB5CGQAAAAI"]
[Thu Jul 30 13:19:36.208105 2026] [security2:error] [pid 872418:tid 872656] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/8.php"] [unique_id "amuVuFymN6QYcoA7XB5CGgAAAGw"]
[Thu Jul 30 13:19:36.208210 2026] [security2:error] [pid 872418:tid 872656] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/8.php"] [unique_id "amuVuFymN6QYcoA7XB5CGgAAAGw"]
[Thu Jul 30 13:19:36.369847 2026] [security2:error] [pid 872418:tid 872566] [client 20.63.98.115:61559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuVuFymN6QYcoA7XB5CGwAAABI"]
[Thu Jul 30 13:19:36.458265 2026] [security2:error] [pid 872418:tid 872669] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/FWAZ.php"] [unique_id "amuVuFymN6QYcoA7XB5CHQAAAHk"]
[Thu Jul 30 13:19:36.458374 2026] [security2:error] [pid 872418:tid 872669] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/FWAZ.php"] [unique_id "amuVuFymN6QYcoA7XB5CHQAAAHk"]
[Thu Jul 30 13:19:36.571933 2026] [core:notice] [pid 872418:tid 872609] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:36.701847 2026] [security2:error] [pid 872418:tid 872627] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/biufile.php"] [unique_id "amuVuFymN6QYcoA7XB5CHwAAAE8"]
[Thu Jul 30 13:19:36.702001 2026] [security2:error] [pid 872418:tid 872627] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/biufile.php"] [unique_id "amuVuFymN6QYcoA7XB5CHwAAAE8"]
[Thu Jul 30 13:19:36.957084 2026] [security2:error] [pid 872418:tid 872616] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/coffexium.php"] [unique_id "amuVuFymN6QYcoA7XB5CIAAAAEQ"]
[Thu Jul 30 13:19:36.957207 2026] [security2:error] [pid 872418:tid 872616] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/coffexium.php"] [unique_id "amuVuFymN6QYcoA7XB5CIAAAAEQ"]
[Thu Jul 30 13:19:37.219262 2026] [security2:error] [pid 872418:tid 872652] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/simple.php"] [unique_id "amuVuVymN6QYcoA7XB5CJgAAAGg"]
[Thu Jul 30 13:19:37.219361 2026] [security2:error] [pid 872418:tid 872652] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/simple.php"] [unique_id "amuVuVymN6QYcoA7XB5CJgAAAGg"]
[Thu Jul 30 13:19:37.366831 2026] [security2:error] [pid 872418:tid 872552] [client 20.63.98.115:42573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuVuVymN6QYcoA7XB5CKAAAAAQ"]
[Thu Jul 30 13:19:37.473248 2026] [security2:error] [pid 872418:tid 872621] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/fpwch.php"] [unique_id "amuVuVymN6QYcoA7XB5CKQAAAEk"]
[Thu Jul 30 13:19:37.473352 2026] [security2:error] [pid 872418:tid 872621] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/fpwch.php"] [unique_id "amuVuVymN6QYcoA7XB5CKQAAAEk"]
[Thu Jul 30 13:19:37.713237 2026] [security2:error] [pid 872418:tid 872582] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/dex.php"] [unique_id "amuVuVymN6QYcoA7XB5CKgAAACI"]
[Thu Jul 30 13:19:37.713361 2026] [security2:error] [pid 872418:tid 872582] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/dex.php"] [unique_id "amuVuVymN6QYcoA7XB5CKgAAACI"]
[Thu Jul 30 13:19:37.960702 2026] [security2:error] [pid 872418:tid 872549] [client 4.185.41.66:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.chimnify.services"] [uri "/1.php"] [unique_id "amuVuVymN6QYcoA7XB5CKwAAAAE"]
[Thu Jul 30 13:19:37.960826 2026] [security2:error] [pid 872418:tid 872549] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/1.php"] [unique_id "amuVuVymN6QYcoA7XB5CKwAAAAE"]
[Thu Jul 30 13:19:37.960959 2026] [security2:error] [pid 872418:tid 872549] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/1.php"] [unique_id "amuVuVymN6QYcoA7XB5CKwAAAAE"]
[Thu Jul 30 13:19:38.284636 2026] [autoindex:error] [pid 872418:tid 872636] [client 4.185.41.66:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_26e591d8/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:19:38.285386 2026] [security2:error] [pid 872418:tid 872636] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.chimnify.services"] [uri "/cgi-sys/403.html"] [unique_id "amuVulymN6QYcoA7XB5CLwAAAFg"]
[Thu Jul 30 13:19:38.365097 2026] [security2:error] [pid 872418:tid 872561] [client 20.63.98.115:33595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-admin/network/about.php"] [unique_id "amuVulymN6QYcoA7XB5CMAAAAA0"]
[Thu Jul 30 13:19:38.413607 2026] [security2:error] [pid 872418:tid 872564] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/config.json.php"] [unique_id "amuVulymN6QYcoA7XB5CMQAAABA"]
[Thu Jul 30 13:19:38.413803 2026] [security2:error] [pid 872418:tid 872564] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/config.json.php"] [unique_id "amuVulymN6QYcoA7XB5CMQAAABA"]
[Thu Jul 30 13:19:38.655379 2026] [security2:error] [pid 872418:tid 872554] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/k2.php"] [unique_id "amuVulymN6QYcoA7XB5CMgAAAAY"]
[Thu Jul 30 13:19:38.655507 2026] [security2:error] [pid 872418:tid 872554] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/k2.php"] [unique_id "amuVulymN6QYcoA7XB5CMgAAAAY"]
[Thu Jul 30 13:19:38.904364 2026] [security2:error] [pid 872418:tid 872491] [remote 216.73.217.142:27463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuVulymN6QYcoA7XB5CMwAAEUg"]
[Thu Jul 30 13:19:38.905654 2026] [security2:error] [pid 872418:tid 872585] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/raw.php"] [unique_id "amuVulymN6QYcoA7XB5CNAAAACU"]
[Thu Jul 30 13:19:38.905731 2026] [security2:error] [pid 872418:tid 872585] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/raw.php"] [unique_id "amuVulymN6QYcoA7XB5CNAAAACU"]
[Thu Jul 30 13:19:39.165033 2026] [security2:error] [pid 872418:tid 872587] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/wp.php"] [unique_id "amuVu1ymN6QYcoA7XB5CNwAAACc"]
[Thu Jul 30 13:19:39.165131 2026] [security2:error] [pid 872418:tid 872587] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/wp.php"] [unique_id "amuVu1ymN6QYcoA7XB5CNwAAACc"]
[Thu Jul 30 13:19:39.345881 2026] [security2:error] [pid 872418:tid 872658] [client 179.64.21.229:43990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVu1ymN6QYcoA7XB5COQAAAG4"]
[Thu Jul 30 13:19:39.357211 2026] [security2:error] [pid 872418:tid 872658] [client 179.64.21.229:43990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVu1ymN6QYcoA7XB5COQAAAG4"]
[Thu Jul 30 13:19:39.426726 2026] [security2:error] [pid 872418:tid 872612] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/fffm.php"] [unique_id "amuVu1ymN6QYcoA7XB5COgAAAEA"]
[Thu Jul 30 13:19:39.426834 2026] [security2:error] [pid 872418:tid 872612] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/fffm.php"] [unique_id "amuVu1ymN6QYcoA7XB5COgAAAEA"]
[Thu Jul 30 13:19:39.679003 2026] [security2:error] [pid 872418:tid 872592] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/111.php"] [unique_id "amuVu1ymN6QYcoA7XB5CPAAAACw"]
[Thu Jul 30 13:19:39.679125 2026] [security2:error] [pid 872418:tid 872592] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/111.php"] [unique_id "amuVu1ymN6QYcoA7XB5CPAAAACw"]
[Thu Jul 30 13:19:39.717361 2026] [security2:error] [pid 872418:tid 872634] [client 172.236.9.101:35634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVu1ymN6QYcoA7XB5COAAAAFY"]
[Thu Jul 30 13:19:39.931550 2026] [autoindex:error] [pid 872418:tid 872603] [client 4.185.41.66:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_26e591d8/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:19:39.932633 2026] [security2:error] [pid 872418:tid 872603] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.chimnify.services"] [uri "/cgi-sys/403.html"] [unique_id "amuVu1ymN6QYcoA7XB5CQQAAADc"]
[Thu Jul 30 13:19:40.092032 2026] [security2:error] [pid 872418:tid 872626] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/ws.php"] [unique_id "amuVvFymN6QYcoA7XB5CQgAAAE4"]
[Thu Jul 30 13:19:40.092153 2026] [security2:error] [pid 872418:tid 872626] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/ws.php"] [unique_id "amuVvFymN6QYcoA7XB5CQgAAAE4"]
[Thu Jul 30 13:19:40.342230 2026] [security2:error] [pid 872418:tid 872623] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/coffee.php"] [unique_id "amuVvFymN6QYcoA7XB5CRgAAAEs"]
[Thu Jul 30 13:19:40.342338 2026] [security2:error] [pid 872418:tid 872623] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/coffee.php"] [unique_id "amuVvFymN6QYcoA7XB5CRgAAAEs"]
[Thu Jul 30 13:19:40.360907 2026] [security2:error] [pid 872418:tid 872553] [client 20.52.125.110:7361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.tmb/LA.php"] [unique_id "amuVvFymN6QYcoA7XB5CRwAAAAU"]
[Thu Jul 30 13:19:40.585624 2026] [core:notice] [pid 872418:tid 872563] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:40.606230 2026] [security2:error] [pid 872418:tid 872666] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/goods.php"] [unique_id "amuVvFymN6QYcoA7XB5CSQAAAHY"]
[Thu Jul 30 13:19:40.606320 2026] [security2:error] [pid 872418:tid 872666] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/goods.php"] [unique_id "amuVvFymN6QYcoA7XB5CSQAAAHY"]
[Thu Jul 30 13:19:40.860301 2026] [security2:error] [pid 872418:tid 872550] [client 20.52.125.110:7409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.tmb/admin.php"] [unique_id "amuVvFymN6QYcoA7XB5CSgAAAAI"]
[Thu Jul 30 13:19:40.874090 2026] [security2:error] [pid 872418:tid 872653] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/about.php"] [unique_id "amuVvFymN6QYcoA7XB5CSwAAAGk"]
[Thu Jul 30 13:19:40.874180 2026] [security2:error] [pid 872418:tid 872653] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/about.php"] [unique_id "amuVvFymN6QYcoA7XB5CSwAAAGk"]
[Thu Jul 30 13:19:40.953838 2026] [security2:error] [pid 872418:tid 872598] [client 20.63.98.115:25945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/xpw.php"] [unique_id "amuVvFymN6QYcoA7XB5CTAAAADI"]
[Thu Jul 30 13:19:41.138896 2026] [security2:error] [pid 872418:tid 872656] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/about.php"] [unique_id "amuVvVymN6QYcoA7XB5CTgAAAGw"]
[Thu Jul 30 13:19:41.139020 2026] [security2:error] [pid 872418:tid 872656] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/about.php"] [unique_id "amuVvVymN6QYcoA7XB5CTgAAAGw"]
[Thu Jul 30 13:19:41.385190 2026] [security2:error] [pid 872418:tid 872601] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/admin.php"] [unique_id "amuVvVymN6QYcoA7XB5CUgAAADU"]
[Thu Jul 30 13:19:41.385331 2026] [security2:error] [pid 872418:tid 872601] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/admin.php"] [unique_id "amuVvVymN6QYcoA7XB5CUgAAADU"]
[Thu Jul 30 13:19:41.496301 2026] [security2:error] [pid 872418:tid 872566] [client 20.52.125.110:7384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.tmb/class_api.php"] [unique_id "amuVvVymN6QYcoA7XB5CVAAAABI"]
[Thu Jul 30 13:19:41.628690 2026] [security2:error] [pid 872418:tid 872674] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/inputs.php"] [unique_id "amuVvVymN6QYcoA7XB5CVQAAAH4"]
[Thu Jul 30 13:19:41.628808 2026] [security2:error] [pid 872418:tid 872674] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/inputs.php"] [unique_id "amuVvVymN6QYcoA7XB5CVQAAAH4"]
[Thu Jul 30 13:19:41.881507 2026] [security2:error] [pid 872418:tid 872567] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/inputs.php"] [unique_id "amuVvVymN6QYcoA7XB5CVgAAABM"]
[Thu Jul 30 13:19:41.881670 2026] [security2:error] [pid 872418:tid 872567] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/inputs.php"] [unique_id "amuVvVymN6QYcoA7XB5CVgAAABM"]
[Thu Jul 30 13:19:42.000152 2026] [security2:error] [pid 872418:tid 872643] [client 20.52.125.110:7418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuVvVymN6QYcoA7XB5CWgAAAF8"]
[Thu Jul 30 13:19:42.188515 2026] [security2:error] [pid 872418:tid 872648] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/adminfuns.php"] [unique_id "amuVvlymN6QYcoA7XB5CWwAAAGQ"]
[Thu Jul 30 13:19:42.188663 2026] [security2:error] [pid 872418:tid 872648] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/adminfuns.php"] [unique_id "amuVvlymN6QYcoA7XB5CWwAAAGQ"]
[Thu Jul 30 13:19:42.446158 2026] [security2:error] [pid 872418:tid 872579] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/404.php"] [unique_id "amuVvlymN6QYcoA7XB5CXAAAAB8"]
[Thu Jul 30 13:19:42.446298 2026] [security2:error] [pid 872418:tid 872579] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/404.php"] [unique_id "amuVvlymN6QYcoA7XB5CXAAAAB8"]
[Thu Jul 30 13:19:42.687011 2026] [security2:error] [pid 872418:tid 872637] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/xxx.php"] [unique_id "amuVvlymN6QYcoA7XB5CXgAAAFk"]
[Thu Jul 30 13:19:42.687124 2026] [security2:error] [pid 872418:tid 872637] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/xxx.php"] [unique_id "amuVvlymN6QYcoA7XB5CXgAAAFk"]
[Thu Jul 30 13:19:42.800499 2026] [security2:error] [pid 872418:tid 872611] [client 20.52.125.110:6658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuVvlymN6QYcoA7XB5CXQAAAD8"]
[Thu Jul 30 13:19:42.927924 2026] [security2:error] [pid 872418:tid 872573] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/classwithtostring.php"] [unique_id "amuVvlymN6QYcoA7XB5CYgAAABk"]
[Thu Jul 30 13:19:42.928071 2026] [security2:error] [pid 872418:tid 872573] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/classwithtostring.php"] [unique_id "amuVvlymN6QYcoA7XB5CYgAAABk"]
[Thu Jul 30 13:19:43.204205 2026] [security2:error] [pid 872418:tid 872552] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/234ff.php"] [unique_id "amuVv1ymN6QYcoA7XB5CYwAAAAQ"]
[Thu Jul 30 13:19:43.204324 2026] [security2:error] [pid 872418:tid 872552] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/234ff.php"] [unique_id "amuVv1ymN6QYcoA7XB5CYwAAAAQ"]
[Thu Jul 30 13:19:43.288540 2026] [security2:error] [pid 872418:tid 872657] [client 20.52.125.110:7399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuVv1ymN6QYcoA7XB5CZQAAAG0"]
[Thu Jul 30 13:19:43.448907 2026] [security2:error] [pid 872418:tid 872590] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/133.php"] [unique_id "amuVv1ymN6QYcoA7XB5CZgAAACo"]
[Thu Jul 30 13:19:43.449089 2026] [security2:error] [pid 872418:tid 872590] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/133.php"] [unique_id "amuVv1ymN6QYcoA7XB5CZgAAACo"]
[Thu Jul 30 13:19:43.557029 2026] [security2:error] [pid 872418:tid 872558] [client 20.9.63.139:1187] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.kool-shop.com"] [uri "/1.php"] [unique_id "amuVv1ymN6QYcoA7XB5CZwAAAAo"]
[Thu Jul 30 13:19:43.557154 2026] [security2:error] [pid 872418:tid 872558] [client 20.9.63.139:1187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/1.php"] [unique_id "amuVv1ymN6QYcoA7XB5CZwAAAAo"]
[Thu Jul 30 13:19:43.557256 2026] [security2:error] [pid 872418:tid 872558] [client 20.9.63.139:1187] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/1.php"] [unique_id "amuVv1ymN6QYcoA7XB5CZwAAAAo"]
[Thu Jul 30 13:19:43.699198 2026] [security2:error] [pid 872418:tid 872595] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/wp-ws68.php"] [unique_id "amuVv1ymN6QYcoA7XB5CaAAAAC8"]
[Thu Jul 30 13:19:43.699311 2026] [security2:error] [pid 872418:tid 872595] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/wp-ws68.php"] [unique_id "amuVv1ymN6QYcoA7XB5CaAAAAC8"]
[Thu Jul 30 13:19:43.831475 2026] [security2:error] [pid 872418:tid 872580] [client 20.52.125.110:7408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/991176.php"] [unique_id "amuVv1ymN6QYcoA7XB5CbAAAACA"]
[Thu Jul 30 13:19:43.950924 2026] [security2:error] [pid 872418:tid 872561] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/mgrr.php"] [unique_id "amuVv1ymN6QYcoA7XB5CbQAAAA0"]
[Thu Jul 30 13:19:43.951092 2026] [security2:error] [pid 872418:tid 872561] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/mgrr.php"] [unique_id "amuVv1ymN6QYcoA7XB5CbQAAAA0"]
[Thu Jul 30 13:19:44.196843 2026] [security2:error] [pid 872418:tid 872667] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chimnify.services"] [uri "/55.php"] [unique_id "amuVwFymN6QYcoA7XB5CbgAAAHc"]
[Thu Jul 30 13:19:44.197001 2026] [security2:error] [pid 872418:tid 872667] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.chimnify.services"] [uri "/55.php"] [unique_id "amuVwFymN6QYcoA7XB5CbgAAAHc"]
[Thu Jul 30 13:19:44.460628 2026] [security2:error] [pid 872418:tid 872617] [client 20.52.125.110:7366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuVwFymN6QYcoA7XB5CcgAAAEU"]
[Thu Jul 30 13:19:44.590523 2026] [security2:error] [pid 872418:tid 872587] [client 20.63.98.115:48830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/wp-cron.php"] [unique_id "amuVwFymN6QYcoA7XB5CcwAAACc"]
[Thu Jul 30 13:19:44.961384 2026] [security2:error] [pid 872418:tid 872620] [client 20.52.125.110:7397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuVwFymN6QYcoA7XB5CdAAAAEg"]
[Thu Jul 30 13:19:45.079810 2026] [security2:error] [pid 872418:tid 872569] [client 20.9.63.139:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/alfa.php"] [unique_id "amuVwVymN6QYcoA7XB5CdQAAABU"]
[Thu Jul 30 13:19:45.079920 2026] [security2:error] [pid 872418:tid 872569] [client 20.9.63.139:20476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/alfa.php"] [unique_id "amuVwVymN6QYcoA7XB5CdQAAABU"]
[Thu Jul 30 13:19:45.542065 2026] [security2:error] [pid 872418:tid 872576] [client 20.52.125.110:6715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuVwVymN6QYcoA7XB5CeAAAABw"]
[Thu Jul 30 13:19:45.625835 2026] [security2:error] [pid 872418:tid 872651] [client 172.237.109.114:35453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVwVymN6QYcoA7XB5CdgAAAGc"]
[Thu Jul 30 13:19:45.805321 2026] [core:notice] [pid 872418:tid 872661] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:19:46.029216 2026] [security2:error] [pid 872418:tid 872614] [client 20.63.98.115:32361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/cah.php"] [unique_id "amuVwlymN6QYcoA7XB5CfgAAAEI"]
[Thu Jul 30 13:19:46.177641 2026] [security2:error] [pid 872418:tid 872623] [client 20.52.125.110:7375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuVwlymN6QYcoA7XB5CgQAAAEs"]
[Thu Jul 30 13:19:46.425454 2026] [security2:error] [pid 872418:tid 872563] [client 20.9.63.139:22626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/edit.php"] [unique_id "amuVwlymN6QYcoA7XB5CggAAAA8"]
[Thu Jul 30 13:19:46.425574 2026] [security2:error] [pid 872418:tid 872563] [client 20.9.63.139:22626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/edit.php"] [unique_id "amuVwlymN6QYcoA7XB5CggAAAA8"]
[Thu Jul 30 13:19:46.684225 2026] [security2:error] [pid 872418:tid 872649] [client 20.52.125.110:7403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuVwlymN6QYcoA7XB5ChAAAAGU"]
[Thu Jul 30 13:19:46.853521 2026] [security2:error] [pid 872418:tid 872665] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVwlymN6QYcoA7XB5ChgAAAHU"]
[Thu Jul 30 13:19:46.853642 2026] [security2:error] [pid 872418:tid 872665] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVwlymN6QYcoA7XB5ChgAAAHU"]
[Thu Jul 30 13:19:47.385629 2026] [security2:error] [pid 872418:tid 872644] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVw1ymN6QYcoA7XB5CjgAAAGA"]
[Thu Jul 30 13:19:47.385763 2026] [security2:error] [pid 872418:tid 872644] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVw1ymN6QYcoA7XB5CjgAAAGA"]
[Thu Jul 30 13:19:47.940357 2026] [security2:error] [pid 872418:tid 872616] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/bootstrap.php"] [unique_id "amuVw1ymN6QYcoA7XB5ClQAAAEQ"]
[Thu Jul 30 13:19:47.940527 2026] [security2:error] [pid 872418:tid 872616] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/bootstrap.php"] [unique_id "amuVw1ymN6QYcoA7XB5ClQAAAEQ"]
[Thu Jul 30 13:19:48.077846 2026] [security2:error] [pid 872418:tid 872646] [client 20.52.125.110:6674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuVxFymN6QYcoA7XB5CsAAAAGI"]
[Thu Jul 30 13:19:48.233128 2026] [security2:error] [pid 872418:tid 872583] [client 20.9.63.139:29843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/elp.php"] [unique_id "amuVxFymN6QYcoA7XB5CsgAAACM"]
[Thu Jul 30 13:19:48.233219 2026] [security2:error] [pid 872418:tid 872583] [client 20.9.63.139:29843] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/elp.php"] [unique_id "amuVxFymN6QYcoA7XB5CsgAAACM"]
[Thu Jul 30 13:19:48.444160 2026] [security2:error] [pid 872418:tid 872556] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-blog-header.php"] [unique_id "amuVxFymN6QYcoA7XB5CxAAAAAg"]
[Thu Jul 30 13:19:48.444297 2026] [security2:error] [pid 872418:tid 872556] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-blog-header.php"] [unique_id "amuVxFymN6QYcoA7XB5CxAAAAAg"]
[Thu Jul 30 13:19:48.561932 2026] [security2:error] [pid 872418:tid 872615] [client 20.52.125.110:7411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuVxFymN6QYcoA7XB5CywAAAEM"]
[Thu Jul 30 13:19:48.807714 2026] [security2:error] [pid 872418:tid 872577] [client 172.236.9.101:6051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVxFymN6QYcoA7XB5CswAAAB0"]
[Thu Jul 30 13:19:48.938676 2026] [security2:error] [pid 872418:tid 872582] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-load.php"] [unique_id "amuVxFymN6QYcoA7XB5C0QAAACI"]
[Thu Jul 30 13:19:48.938832 2026] [security2:error] [pid 872418:tid 872582] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-load.php"] [unique_id "amuVxFymN6QYcoA7XB5C0QAAACI"]
[Thu Jul 30 13:19:48.993939 2026] [security2:error] [pid 872418:tid 872573] [client 20.63.98.115:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceeast.com"] [uri "/cong.php"] [unique_id "amuVxFymN6QYcoA7XB5C0wAAABk"]
[Thu Jul 30 13:19:49.035588 2026] [security2:error] [pid 872418:tid 872427] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/classwithtostring.php"] [unique_id "amuVxVymN6QYcoA7XB5C1AAAIAg"]
[Thu Jul 30 13:19:49.096795 2026] [security2:error] [pid 872418:tid 872647] [client 20.52.125.110:7371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuVxVymN6QYcoA7XB5C1gAAAGM"]
[Thu Jul 30 13:19:49.472056 2026] [security2:error] [pid 872418:tid 872622] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/edit.php"] [unique_id "amuVxVymN6QYcoA7XB5C2QAAAEo"]
[Thu Jul 30 13:19:49.472246 2026] [security2:error] [pid 872418:tid 872622] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/edit.php"] [unique_id "amuVxVymN6QYcoA7XB5C2QAAAEo"]
[Thu Jul 30 13:19:49.610431 2026] [security2:error] [pid 872418:tid 872633] [client 154.159.252.63:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuVxVymN6QYcoA7XB5C2wAAVRI"], referer: https://rocket-bookkeepers.com/
[Thu Jul 30 13:19:49.614110 2026] [security2:error] [pid 872418:tid 872565] [client 20.52.125.110:6659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuVxVymN6QYcoA7XB5C4gAAABE"]
[Thu Jul 30 13:19:49.630048 2026] [security2:error] [pid 872418:tid 872633] [client 154.159.252.63:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuVxVymN6QYcoA7XB5C2gAAVRA"], referer: https://rocket-bookkeepers.com/
[Thu Jul 30 13:19:49.649061 2026] [security2:error] [pid 872418:tid 872633] [client 154.159.252.63:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuVxVymN6QYcoA7XB5C3AAAVQ0"], referer: https://rocket-bookkeepers.com/
[Thu Jul 30 13:19:49.649151 2026] [security2:error] [pid 872418:tid 872633] [client 154.159.252.63:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuVxVymN6QYcoA7XB5C4QAAVRY"], referer: https://rocket-bookkeepers.com/
[Thu Jul 30 13:19:49.652098 2026] [security2:error] [pid 872418:tid 872633] [client 154.159.252.63:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuVxVymN6QYcoA7XB5C4AAAVRQ"], referer: https://rocket-bookkeepers.com/
[Thu Jul 30 13:19:49.653211 2026] [security2:error] [pid 872418:tid 872633] [client 154.159.252.63:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuVxVymN6QYcoA7XB5C3wAAVRU"], referer: https://rocket-bookkeepers.com/
[Thu Jul 30 13:19:49.653307 2026] [security2:error] [pid 872418:tid 872633] [client 154.159.252.63:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuVxVymN6QYcoA7XB5C3gAAVQc"], referer: https://rocket-bookkeepers.com/
[Thu Jul 30 13:19:49.654349 2026] [security2:error] [pid 872418:tid 872633] [client 154.159.252.63:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rocket-bookkeepers.com"] [uri "/index.php"] [unique_id "amuVxVymN6QYcoA7XB5C3QAAVRM"], referer: https://rocket-bookkeepers.com/
[Thu Jul 30 13:19:49.981502 2026] [proxy:error] [pid 872418:tid 872671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:49.981580 2026] [proxy_http:error] [pid 872418:tid 872671] [client 52.4.19.39:46860] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:49.982147 2026] [proxy:error] [pid 872418:tid 872671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:49.982191 2026] [proxy_http:error] [pid 872418:tid 872671] [client 52.4.19.39:46860] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:49.997913 2026] [security2:error] [pid 872418:tid 872640] [client 20.9.63.139:5192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/classwithtostring.php"] [unique_id "amuVxVymN6QYcoA7XB5C5AAAAFw"]
[Thu Jul 30 13:19:49.998023 2026] [security2:error] [pid 872418:tid 872640] [client 20.9.63.139:5192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/classwithtostring.php"] [unique_id "amuVxVymN6QYcoA7XB5C5AAAAFw"]
[Thu Jul 30 13:19:50.006907 2026] [security2:error] [pid 872418:tid 872620] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/cgi-bin"] [unique_id "amuVxlymN6QYcoA7XB5C5QAAAEg"]
[Thu Jul 30 13:19:50.032948 2026] [security2:error] [pid 872418:tid 872617] [client 179.64.21.229:6312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVxlymN6QYcoA7XB5C5wAAAEU"]
[Thu Jul 30 13:19:50.038277 2026] [security2:error] [pid 872418:tid 872617] [client 179.64.21.229:6312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuVxlymN6QYcoA7XB5C5wAAAEU"]
[Thu Jul 30 13:19:50.140937 2026] [security2:error] [pid 872418:tid 872587] [client 20.52.125.110:7417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuVxlymN6QYcoA7XB5C6AAAACc"]
[Thu Jul 30 13:19:50.649438 2026] [security2:error] [pid 872418:tid 872673] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/etc/config.php"] [unique_id "amuVxlymN6QYcoA7XB5C7wAAAH0"]
[Thu Jul 30 13:19:50.767210 2026] [security2:error] [pid 872418:tid 872651] [client 20.52.125.110:7394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuVxlymN6QYcoA7XB5C8wAAAGc"]
[Thu Jul 30 13:19:50.772510 2026] [security2:error] [pid 872418:tid 872614] [client 185.177.72.56:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "okcasino-1.com"] [uri "/etc/settings.php"] [unique_id "amuVxlymN6QYcoA7XB5C9AAAAEI"]
[Thu Jul 30 13:19:50.838142 2026] [security2:error] [pid 872418:tid 872658] [client 172.236.9.101:26603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuVxlymN6QYcoA7XB5C6wAAAG4"]
[Thu Jul 30 13:19:50.954993 2026] [security2:error] [pid 872418:tid 872623] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuVxlymN6QYcoA7XB5C9gAAAEs"]
[Thu Jul 30 13:19:51.023102 2026] [security2:error] [pid 872418:tid 872586] [client 20.9.63.139:22173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.itrnetwork.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVx1ymN6QYcoA7XB5C9wAAACY"]
[Thu Jul 30 13:19:51.023213 2026] [security2:error] [pid 872418:tid 872586] [client 20.9.63.139:22173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.itrnetwork.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuVx1ymN6QYcoA7XB5C9wAAACY"]
[Thu Jul 30 13:19:51.182385 2026] [security2:error] [pid 872418:tid 872666] [client 20.9.63.139:25355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/666.php"] [unique_id "amuVx1ymN6QYcoA7XB5C-AAAAHY"]
[Thu Jul 30 13:19:51.182508 2026] [security2:error] [pid 872418:tid 872666] [client 20.9.63.139:25355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/666.php"] [unique_id "amuVx1ymN6QYcoA7XB5C-AAAAHY"]
[Thu Jul 30 13:19:51.221815 2026] [security2:error] [pid 872418:tid 872645] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/mah.php"] [unique_id "amuVx1ymN6QYcoA7XB5C_AAAAGE"]
[Thu Jul 30 13:19:51.221957 2026] [security2:error] [pid 872418:tid 872645] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/mah.php"] [unique_id "amuVx1ymN6QYcoA7XB5C_AAAAGE"]
[Thu Jul 30 13:19:51.313525 2026] [security2:error] [pid 872418:tid 872563] [client 20.52.125.110:6667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuVx1ymN6QYcoA7XB5C_QAAAA8"]
[Thu Jul 30 13:19:51.582322 2026] [core:error] [pid 872418:tid 872603] [client 193.47.62.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:51.582345 2026] [core:error] [pid 872418:tid 872603] [client 193.47.62.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:19:51.707462 2026] [security2:error] [pid 872418:tid 872669] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/archive.php"] [unique_id "amuVx1ymN6QYcoA7XB5DAAAAAHk"]
[Thu Jul 30 13:19:51.707573 2026] [security2:error] [pid 872418:tid 872669] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/archive.php"] [unique_id "amuVx1ymN6QYcoA7XB5DAAAAAHk"]
[Thu Jul 30 13:19:51.829317 2026] [security2:error] [pid 872418:tid 872629] [client 20.52.125.110:6669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuVx1ymN6QYcoA7XB5DAQAAAFE"]
[Thu Jul 30 13:19:51.897074 2026] [security2:error] [pid 872418:tid 872654] [client 43.134.3.111:41036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.3.134.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/camic"] [unique_id "amuVx1ymN6QYcoA7XB5DBgAAAGo"], referer: https://ejournalugj.com/index_php/camic
[Thu Jul 30 13:19:52.231071 2026] [security2:error] [pid 872418:tid 872601] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/hosty.php"] [unique_id "amuVyFymN6QYcoA7XB5DCwAAADU"]
[Thu Jul 30 13:19:52.231205 2026] [security2:error] [pid 872418:tid 872601] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/hosty.php"] [unique_id "amuVyFymN6QYcoA7XB5DCwAAADU"]
[Thu Jul 30 13:19:52.282388 2026] [security2:error] [pid 872418:tid 872578] [client 20.52.125.110:7383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuVyFymN6QYcoA7XB5DDAAAAB4"]
[Thu Jul 30 13:19:52.727952 2026] [security2:error] [pid 872418:tid 872607] [client 82.102.27.195:43956] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuVyFymN6QYcoA7XB5DDQAAADs"]
[Thu Jul 30 13:19:52.728104 2026] [security2:error] [pid 872418:tid 872607] [client 82.102.27.195:43956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuVyFymN6QYcoA7XB5DDQAAADs"]
[Thu Jul 30 13:19:52.756050 2026] [security2:error] [pid 872418:tid 872594] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "amuVyFymN6QYcoA7XB5DEAAAAC4"]
[Thu Jul 30 13:19:52.788442 2026] [security2:error] [pid 872418:tid 872579] [client 20.52.125.110:6656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/bek.php"] [unique_id "amuVyFymN6QYcoA7XB5DEQAAAB8"]
[Thu Jul 30 13:19:53.033826 2026] [security2:error] [pid 872418:tid 872675] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuVyVymN6QYcoA7XB5DFAAAAH8"]
[Thu Jul 30 13:19:53.257046 2026] [security2:error] [pid 872418:tid 872573] [client 20.52.125.110:7390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuVyVymN6QYcoA7XB5DFQAAABk"]
[Thu Jul 30 13:19:53.286600 2026] [security2:error] [pid 872418:tid 872621] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/admin.php"] [unique_id "amuVyVymN6QYcoA7XB5DFgAAAEk"]
[Thu Jul 30 13:19:53.286716 2026] [security2:error] [pid 872418:tid 872621] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/admin.php"] [unique_id "amuVyVymN6QYcoA7XB5DFgAAAEk"]
[Thu Jul 30 13:19:53.333763 2026] [security2:error] [pid 872418:tid 872571] [client 77.75.77.95:29327] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.milfordauto.com"] [uri "/robots.txt"] [unique_id "amuVyVymN6QYcoA7XB5DHQAAABc"]
[Thu Jul 30 13:19:53.333843 2026] [security2:error] [pid 872418:tid 872571] [client 77.75.77.95:29327] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.milfordauto.com"] [uri "/robots.txt"] [unique_id "amuVyVymN6QYcoA7XB5DHQAAABc"]
[Thu Jul 30 13:19:53.351814 2026] [security2:error] [pid 872418:tid 872659] [client 77.75.77.95:18744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.milfordauto.com"] [uri "/"] [unique_id "amuVyVymN6QYcoA7XB5DIQAAAG8"]
[Thu Jul 30 13:19:53.351915 2026] [security2:error] [pid 872418:tid 872659] [client 77.75.77.95:18744] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.milfordauto.com"] [uri "/"] [unique_id "amuVyVymN6QYcoA7XB5DIQAAAG8"]
[Thu Jul 30 13:19:53.712180 2026] [security2:error] [pid 872418:tid 872598] [client 20.52.125.110:6670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/class.api.php"] [unique_id "amuVyVymN6QYcoA7XB5DSAAAADI"]
[Thu Jul 30 13:19:53.774246 2026] [security2:error] [pid 872418:tid 872632] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/av.php"] [unique_id "amuVyVymN6QYcoA7XB5DSQAAAFQ"]
[Thu Jul 30 13:19:53.774402 2026] [security2:error] [pid 872418:tid 872632] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/av.php"] [unique_id "amuVyVymN6QYcoA7XB5DSQAAAFQ"]
[Thu Jul 30 13:19:53.918600 2026] [security2:error] [pid 872418:tid 872457] [remote 57.141.0.16:39854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuVyVymN6QYcoA7XB5DTQAAdSY"]
[Thu Jul 30 13:19:54.152967 2026] [proxy:error] [pid 872418:tid 872627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:54.153074 2026] [proxy_http:error] [pid 872418:tid 872627] [client 20.9.63.139:29841] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:54.153748 2026] [proxy:error] [pid 872418:tid 872627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:19:54.153792 2026] [proxy_http:error] [pid 872418:tid 872627] [client 20.9.63.139:29841] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:19:54.153906 2026] [security2:error] [pid 872418:tid 872627] [client 20.9.63.139:29841] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.kool-shop.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuVylymN6QYcoA7XB5DUgAAAE8"]
[Thu Jul 30 13:19:54.253587 2026] [security2:error] [pid 872418:tid 872629] [client 20.52.125.110:7405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/cong.php"] [unique_id "amuVylymN6QYcoA7XB5DVQAAAFE"]
[Thu Jul 30 13:19:54.319502 2026] [security2:error] [pid 872418:tid 872611] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/shell.php"] [unique_id "amuVylymN6QYcoA7XB5DVwAAAD8"]
[Thu Jul 30 13:19:54.319626 2026] [security2:error] [pid 872418:tid 872611] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/shell.php"] [unique_id "amuVylymN6QYcoA7XB5DVwAAAD8"]
[Thu Jul 30 13:19:54.736154 2026] [security2:error] [pid 872418:tid 872652] [client 20.52.125.110:6706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/content.php"] [unique_id "amuVylymN6QYcoA7XB5DWQAAAGg"]
[Thu Jul 30 13:19:54.895017 2026] [security2:error] [pid 872418:tid 872674] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/storage/index.php"] [unique_id "amuVylymN6QYcoA7XB5DXQAAAH4"]
[Thu Jul 30 13:19:54.895168 2026] [security2:error] [pid 872418:tid 872674] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/storage/index.php"] [unique_id "amuVylymN6QYcoA7XB5DXQAAAH4"]
[Thu Jul 30 13:19:55.031508 2026] [security2:error] [pid 872418:tid 872592] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuVylymN6QYcoA7XB5DWAAALDI"]
[Thu Jul 30 13:19:55.218544 2026] [security2:error] [pid 872418:tid 872573] [client 20.52.125.110:7365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuVy1ymN6QYcoA7XB5DYwAAABk"]
[Thu Jul 30 13:19:55.448259 2026] [security2:error] [pid 872418:tid 872571] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/w.php"] [unique_id "amuVy1ymN6QYcoA7XB5DaQAAABc"]
[Thu Jul 30 13:19:55.448387 2026] [security2:error] [pid 872418:tid 872571] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/w.php"] [unique_id "amuVy1ymN6QYcoA7XB5DaQAAABc"]
[Thu Jul 30 13:19:55.620760 2026] [security2:error] [pid 872418:tid 872562] [client 80.200.140.145:40630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVy1ymN6QYcoA7XB5DZAAAAA4"], referer: http://pkf.jo
[Thu Jul 30 13:19:55.735506 2026] [security2:error] [pid 872418:tid 872663] [client 20.52.125.110:7388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/elp.php"] [unique_id "amuVy1ymN6QYcoA7XB5DbAAAAHM"]
[Thu Jul 30 13:19:55.943208 2026] [security2:error] [pid 872418:tid 872662] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/jp.php"] [unique_id "amuVy1ymN6QYcoA7XB5DdAAAAHI"]
[Thu Jul 30 13:19:55.943360 2026] [security2:error] [pid 872418:tid 872662] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/jp.php"] [unique_id "amuVy1ymN6QYcoA7XB5DdAAAAHI"]
[Thu Jul 30 13:19:56.007013 2026] [security2:error] [pid 872418:tid 872588] [client 41.90.180.9:3463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVy1ymN6QYcoA7XB5DawAAACg"], referer: http://pkf.jo
[Thu Jul 30 13:19:56.179721 2026] [security2:error] [pid 872418:tid 872576] [client 20.52.125.110:6664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuVzFymN6QYcoA7XB5DdQAAABw"]
[Thu Jul 30 13:19:56.414235 2026] [security2:error] [pid 872418:tid 872586] [client 176.64.20.107:17313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVy1ymN6QYcoA7XB5DcwAAACY"], referer: http://pkf.jo
[Thu Jul 30 13:19:56.451216 2026] [authz_core:error] [pid 872418:tid 872587] [client 20.9.4.9:0] AH01630: client denied by server configuration: /home1/vwhhflte/public_html/website_ffa422ec/php.ini
[Thu Jul 30 13:19:56.452817 2026] [security2:error] [pid 872418:tid 872587] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "propertyspro.com"] [uri "/cgi-sys/403.html"] [unique_id "amuVzFymN6QYcoA7XB5DewAAACc"]
[Thu Jul 30 13:19:56.562334 2026] [security2:error] [pid 872418:tid 872626] [client 20.9.63.139:26509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.itrnetwork.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVzFymN6QYcoA7XB5DfgAAAE4"]
[Thu Jul 30 13:19:56.562447 2026] [security2:error] [pid 872418:tid 872626] [client 20.9.63.139:26509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.itrnetwork.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuVzFymN6QYcoA7XB5DfgAAAE4"]
[Thu Jul 30 13:19:56.673576 2026] [security2:error] [pid 872418:tid 872558] [client 20.52.125.110:7402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuVzFymN6QYcoA7XB5DfwAAAAo"]
[Thu Jul 30 13:19:56.729588 2026] [security2:error] [pid 872418:tid 872635] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/ws77.php"] [unique_id "amuVzFymN6QYcoA7XB5DgQAAAFc"]
[Thu Jul 30 13:19:56.729681 2026] [security2:error] [pid 872418:tid 872635] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/ws77.php"] [unique_id "amuVzFymN6QYcoA7XB5DgQAAAFc"]
[Thu Jul 30 13:19:57.098053 2026] [security2:error] [pid 872418:tid 872627] [client 105.72.214.93:50210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuVzFymN6QYcoA7XB5DggAAAE8"], referer: http://pkf.jo
[Thu Jul 30 13:19:57.126808 2026] [security2:error] [pid 872418:tid 872597] [client 20.52.125.110:7363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuVzVymN6QYcoA7XB5DgwAAADE"]
[Thu Jul 30 13:19:57.241042 2026] [security2:error] [pid 872418:tid 872616] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/blass.php"] [unique_id "amuVzVymN6QYcoA7XB5DhAAAAEQ"]
[Thu Jul 30 13:19:57.241206 2026] [security2:error] [pid 872418:tid 872616] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/blass.php"] [unique_id "amuVzVymN6QYcoA7XB5DhAAAAEQ"]
[Thu Jul 30 13:19:57.615160 2026] [security2:error] [pid 872418:tid 872608] [client 20.52.125.110:7400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuVzVymN6QYcoA7XB5DhgAAADw"]
[Thu Jul 30 13:19:58.069786 2026] [security2:error] [pid 872418:tid 872556] [client 20.52.125.110:7367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuVzlymN6QYcoA7XB5DkAAAAAg"]
[Thu Jul 30 13:19:58.160283 2026] [security2:error] [pid 872418:tid 872615] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-info.php"] [unique_id "amuVzlymN6QYcoA7XB5DkQAAAEM"]
[Thu Jul 30 13:19:58.160446 2026] [security2:error] [pid 872418:tid 872615] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-info.php"] [unique_id "amuVzlymN6QYcoA7XB5DkQAAAEM"]
[Thu Jul 30 13:19:58.473754 2026] [security2:error] [pid 872418:tid 872566] [client 20.52.125.110:7374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuVzlymN6QYcoA7XB5DmAAAABI"]
[Thu Jul 30 13:19:58.673538 2026] [security2:error] [pid 872418:tid 872582] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/CDX1.php"] [unique_id "amuVzlymN6QYcoA7XB5DmQAAACI"]
[Thu Jul 30 13:19:58.673686 2026] [security2:error] [pid 872418:tid 872582] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/CDX1.php"] [unique_id "amuVzlymN6QYcoA7XB5DmQAAACI"]
[Thu Jul 30 13:19:58.959503 2026] [security2:error] [pid 872418:tid 872674] [client 20.52.125.110:7381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuVzlymN6QYcoA7XB5DmgAAAH4"]
[Thu Jul 30 13:19:59.159027 2026] [security2:error] [pid 872418:tid 872564] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wpc.php"] [unique_id "amuVz1ymN6QYcoA7XB5DoQAAABA"]
[Thu Jul 30 13:19:59.159163 2026] [security2:error] [pid 872418:tid 872564] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wpc.php"] [unique_id "amuVz1ymN6QYcoA7XB5DoQAAABA"]
[Thu Jul 30 13:19:59.422004 2026] [security2:error] [pid 872418:tid 872580] [client 20.52.125.110:7377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuVz1ymN6QYcoA7XB5DowAAACA"]
[Thu Jul 30 13:19:59.729809 2026] [security2:error] [pid 872418:tid 872623] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/jga.php"] [unique_id "amuVz1ymN6QYcoA7XB5DpQAAAEs"]
[Thu Jul 30 13:19:59.729925 2026] [security2:error] [pid 872418:tid 872623] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/jga.php"] [unique_id "amuVz1ymN6QYcoA7XB5DpQAAAEs"]
[Thu Jul 30 13:19:59.755675 2026] [security2:error] [pid 872418:tid 872671] [client 134.19.179.147:42150] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuVz1ymN6QYcoA7XB5DpAAAAHs"]
[Thu Jul 30 13:19:59.755791 2026] [security2:error] [pid 872418:tid 872671] [client 134.19.179.147:42150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuVz1ymN6QYcoA7XB5DpAAAAHs"]
[Thu Jul 30 13:19:59.870600 2026] [security2:error] [pid 872418:tid 872568] [client 20.52.125.110:6660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuVz1ymN6QYcoA7XB5DpgAAABQ"]
[Thu Jul 30 13:20:00.286420 2026] [security2:error] [pid 872418:tid 872584] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/666.php"] [unique_id "amuV0FymN6QYcoA7XB5DqgAAACQ"]
[Thu Jul 30 13:20:00.286519 2026] [security2:error] [pid 872418:tid 872584] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/666.php"] [unique_id "amuV0FymN6QYcoA7XB5DqgAAACQ"]
[Thu Jul 30 13:20:00.421291 2026] [security2:error] [pid 872418:tid 872638] [client 20.52.125.110:7420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuV0FymN6QYcoA7XB5DrAAAAFo"]
[Thu Jul 30 13:20:00.588654 2026] [security2:error] [pid 872418:tid 872612] [client 179.64.21.229:35760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuV0FymN6QYcoA7XB5DsAAAAEA"]
[Thu Jul 30 13:20:00.592585 2026] [security2:error] [pid 872418:tid 872612] [client 179.64.21.229:35760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuV0FymN6QYcoA7XB5DsAAAAEA"]
[Thu Jul 30 13:20:00.780884 2026] [security2:error] [pid 872418:tid 872581] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/htaccess.php"] [unique_id "amuV0FymN6QYcoA7XB5DsQAAACE"]
[Thu Jul 30 13:20:00.781050 2026] [security2:error] [pid 872418:tid 872581] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/htaccess.php"] [unique_id "amuV0FymN6QYcoA7XB5DsQAAACE"]
[Thu Jul 30 13:20:00.859363 2026] [security2:error] [pid 872418:tid 872660] [client 20.52.125.110:7410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuV0FymN6QYcoA7XB5DsgAAAHA"]
[Thu Jul 30 13:20:01.164677 2026] [security2:error] [pid 872418:tid 872626] [client 20.9.63.139:5124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.itrnetwork.org"] [uri "/bootstrap.php"] [unique_id "amuV0VymN6QYcoA7XB5DswAAAE4"]
[Thu Jul 30 13:20:01.164802 2026] [security2:error] [pid 872418:tid 872626] [client 20.9.63.139:5124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.itrnetwork.org"] [uri "/bootstrap.php"] [unique_id "amuV0VymN6QYcoA7XB5DswAAAE4"]
[Thu Jul 30 13:20:01.170816 2026] [proxy:error] [pid 872418:tid 872613] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:01.170876 2026] [proxy_http:error] [pid 872418:tid 872613] [client 3.228.112.215:64939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:01.171442 2026] [proxy:error] [pid 872418:tid 872613] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:01.171485 2026] [proxy_http:error] [pid 872418:tid 872613] [client 3.228.112.215:64939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:01.183911 2026] [proxy:error] [pid 872418:tid 872632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:01.184038 2026] [proxy_http:error] [pid 872418:tid 872632] [client 52.202.41.153:23018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:01.184779 2026] [proxy:error] [pid 872418:tid 872632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:01.184829 2026] [proxy_http:error] [pid 872418:tid 872632] [client 52.202.41.153:23018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:01.303528 2026] [security2:error] [pid 872418:tid 872627] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/m.php"] [unique_id "amuV0VymN6QYcoA7XB5DwAAAAE8"]
[Thu Jul 30 13:20:01.303637 2026] [security2:error] [pid 872418:tid 872627] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/m.php"] [unique_id "amuV0VymN6QYcoA7XB5DwAAAAE8"]
[Thu Jul 30 13:20:01.393306 2026] [security2:error] [pid 872418:tid 872668] [client 20.52.125.110:7401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuV0VymN6QYcoA7XB5DwQAAAHg"]
[Thu Jul 30 13:20:01.840266 2026] [security2:error] [pid 872418:tid 872625] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/file.php"] [unique_id "amuV0VymN6QYcoA7XB5DxgAAAE0"]
[Thu Jul 30 13:20:01.840388 2026] [security2:error] [pid 872418:tid 872625] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/file.php"] [unique_id "amuV0VymN6QYcoA7XB5DxgAAAE0"]
[Thu Jul 30 13:20:01.853853 2026] [security2:error] [pid 872418:tid 872604] [client 20.52.125.110:7423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuV0VymN6QYcoA7XB5DxwAAADg"]
[Thu Jul 30 13:20:02.327022 2026] [security2:error] [pid 872418:tid 872595] [client 20.52.125.110:7376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuV0lymN6QYcoA7XB5DyQAAAC8"]
[Thu Jul 30 13:20:02.413611 2026] [security2:error] [pid 872418:tid 872570] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/.dj/index.php"] [unique_id "amuV0lymN6QYcoA7XB5DygAAABY"]
[Thu Jul 30 13:20:02.413758 2026] [security2:error] [pid 872418:tid 872570] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/.dj/index.php"] [unique_id "amuV0lymN6QYcoA7XB5DygAAABY"]
[Thu Jul 30 13:20:02.924273 2026] [security2:error] [pid 872418:tid 872628] [client 20.52.125.110:6672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuV0lymN6QYcoA7XB5DzAAAAFA"]
[Thu Jul 30 13:20:02.978443 2026] [security2:error] [pid 872418:tid 872647] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuV0lymN6QYcoA7XB5DzgAAAGM"]
[Thu Jul 30 13:20:02.978564 2026] [security2:error] [pid 872418:tid 872647] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuV0lymN6QYcoA7XB5DzgAAAGM"]
[Thu Jul 30 13:20:03.200965 2026] [proxy:error] [pid 872418:tid 872564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:03.201069 2026] [proxy_http:error] [pid 872418:tid 872564] [client 34.224.175.62:62697] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:03.201945 2026] [proxy:error] [pid 872418:tid 872564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:03.202020 2026] [proxy_http:error] [pid 872418:tid 872564] [client 34.224.175.62:62697] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:03.220476 2026] [proxy:error] [pid 872418:tid 872622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:03.220571 2026] [proxy_http:error] [pid 872418:tid 872622] [client 32.194.121.99:65067] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:03.221612 2026] [proxy:error] [pid 872418:tid 872622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:03.221687 2026] [proxy_http:error] [pid 872418:tid 872622] [client 32.194.121.99:65067] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:03.389106 2026] [security2:error] [pid 872418:tid 872562] [client 20.52.125.110:6685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuV01ymN6QYcoA7XB5D3AAAAA4"]
[Thu Jul 30 13:20:03.506251 2026] [security2:error] [pid 872418:tid 872617] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/pages.php"] [unique_id "amuV01ymN6QYcoA7XB5D3QAAAEU"]
[Thu Jul 30 13:20:03.506359 2026] [security2:error] [pid 872418:tid 872617] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/pages.php"] [unique_id "amuV01ymN6QYcoA7XB5D3QAAAEU"]
[Thu Jul 30 13:20:03.860269 2026] [core:error] [pid 872418:tid 872605] [client 66.249.79.193:38503] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:20:03.860293 2026] [core:error] [pid 872418:tid 872605] [client 66.249.79.193:38503] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:20:03.890728 2026] [security2:error] [pid 872418:tid 872553] [client 20.52.125.110:7364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuV01ymN6QYcoA7XB5D4AAAAAU"]
[Thu Jul 30 13:20:04.139908 2026] [security2:error] [pid 872418:tid 872659] [client 20.9.63.139:29851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.63.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.kool-shop.com"] [uri "/ws54.php"] [unique_id "amuV1FymN6QYcoA7XB5D4QAAAG8"]
[Thu Jul 30 13:20:04.140025 2026] [security2:error] [pid 872418:tid 872659] [client 20.9.63.139:29851] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.kool-shop.com"] [uri "/ws54.php"] [unique_id "amuV1FymN6QYcoA7XB5D4QAAAG8"]
[Thu Jul 30 13:20:04.191033 2026] [security2:error] [pid 872418:tid 872588] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/adminfuns.php"] [unique_id "amuV1FymN6QYcoA7XB5D4gAAACg"]
[Thu Jul 30 13:20:04.191138 2026] [security2:error] [pid 872418:tid 872588] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/adminfuns.php"] [unique_id "amuV1FymN6QYcoA7XB5D4gAAACg"]
[Thu Jul 30 13:20:04.363013 2026] [security2:error] [pid 872418:tid 872610] [client 20.52.125.110:6665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuV1FymN6QYcoA7XB5D5gAAAD4"]
[Thu Jul 30 13:20:04.687218 2026] [security2:error] [pid 872418:tid 872563] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/aa.php"] [unique_id "amuV1FymN6QYcoA7XB5D7QAAAA8"]
[Thu Jul 30 13:20:04.687354 2026] [security2:error] [pid 872418:tid 872563] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/aa.php"] [unique_id "amuV1FymN6QYcoA7XB5D7QAAAA8"]
[Thu Jul 30 13:20:04.814175 2026] [security2:error] [pid 872418:tid 872591] [client 20.52.125.110:7389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuV1FymN6QYcoA7XB5D7gAAACs"]
[Thu Jul 30 13:20:05.227841 2026] [security2:error] [pid 872418:tid 872632] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "amuV1VymN6QYcoA7XB5D9gAAAFQ"]
[Thu Jul 30 13:20:05.262165 2026] [security2:error] [pid 872418:tid 872585] [client 20.52.125.110:7406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuV1VymN6QYcoA7XB5D9wAAACU"]
[Thu Jul 30 13:20:05.560877 2026] [security2:error] [pid 872418:tid 872654] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuV1VymN6QYcoA7XB5D-AAAAGo"]
[Thu Jul 30 13:20:05.694096 2026] [security2:error] [pid 872418:tid 872627] [client 20.52.125.110:7368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuV1VymN6QYcoA7XB5D-QAAAE8"]
[Thu Jul 30 13:20:05.861402 2026] [security2:error] [pid 872418:tid 872619] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/classwithtostring.php"] [unique_id "amuV1VymN6QYcoA7XB5D-wAAAEc"]
[Thu Jul 30 13:20:05.861491 2026] [security2:error] [pid 872418:tid 872619] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/classwithtostring.php"] [unique_id "amuV1VymN6QYcoA7XB5D-wAAAEc"]
[Thu Jul 30 13:20:06.200490 2026] [security2:error] [pid 872418:tid 872615] [client 20.52.125.110:6704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuV1lymN6QYcoA7XB5D_gAAAEM"]
[Thu Jul 30 13:20:06.390702 2026] [security2:error] [pid 872418:tid 872648] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/about.php"] [unique_id "amuV1lymN6QYcoA7XB5EAAAAAGQ"]
[Thu Jul 30 13:20:06.390834 2026] [security2:error] [pid 872418:tid 872648] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/about.php"] [unique_id "amuV1lymN6QYcoA7XB5EAAAAAGQ"]
[Thu Jul 30 13:20:06.751740 2026] [security2:error] [pid 872418:tid 872596] [client 20.52.125.110:7407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuV1lymN6QYcoA7XB5EAwAAADA"]
[Thu Jul 30 13:20:06.774234 2026] [proxy:error] [pid 872418:tid 872590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:06.774312 2026] [proxy_http:error] [pid 872418:tid 872590] [client 44.213.206.96:2929] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:06.774884 2026] [proxy:error] [pid 872418:tid 872590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:06.774929 2026] [proxy_http:error] [pid 872418:tid 872590] [client 44.213.206.96:2929] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:06.805242 2026] [proxy:error] [pid 872418:tid 872577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:06.805331 2026] [proxy_http:error] [pid 872418:tid 872577] [client 3.225.222.228:20102] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:06.806162 2026] [proxy:error] [pid 872418:tid 872577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:06.806218 2026] [proxy_http:error] [pid 872418:tid 872577] [client 3.225.222.228:20102] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:06.881538 2026] [security2:error] [pid 872418:tid 872595] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/goods.php"] [unique_id "amuV1lymN6QYcoA7XB5EDwAAAC8"]
[Thu Jul 30 13:20:06.881664 2026] [security2:error] [pid 872418:tid 872595] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/goods.php"] [unique_id "amuV1lymN6QYcoA7XB5EDwAAAC8"]
[Thu Jul 30 13:20:07.114051 2026] [core:error] [pid 872418:tid 872641] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:20:07.114083 2026] [core:error] [pid 872418:tid 872641] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:20:07.230582 2026] [security2:error] [pid 872418:tid 872628] [client 20.52.125.110:7360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuV11ymN6QYcoA7XB5EEQAAAFA"]
[Thu Jul 30 13:20:07.335743 2026] [proxy:error] [pid 872418:tid 872624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:07.335823 2026] [proxy_http:error] [pid 872418:tid 872624] [client 52.4.19.39:15652] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:07.336732 2026] [proxy:error] [pid 872418:tid 872624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:07.336781 2026] [proxy_http:error] [pid 872418:tid 872624] [client 52.4.19.39:15652] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:07.340370 2026] [proxy:error] [pid 872418:tid 872633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:07.340438 2026] [proxy_http:error] [pid 872418:tid 872633] [client 44.213.206.96:41248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:07.341044 2026] [proxy:error] [pid 872418:tid 872633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:07.341093 2026] [proxy_http:error] [pid 872418:tid 872633] [client 44.213.206.96:41248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:07.402390 2026] [security2:error] [pid 872418:tid 872600] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/php8.php"] [unique_id "amuV11ymN6QYcoA7XB5EGwAAADQ"]
[Thu Jul 30 13:20:07.402525 2026] [security2:error] [pid 872418:tid 872600] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/php8.php"] [unique_id "amuV11ymN6QYcoA7XB5EGwAAADQ"]
[Thu Jul 30 13:20:07.694017 2026] [security2:error] [pid 872418:tid 872620] [client 20.52.125.110:7393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuV11ymN6QYcoA7XB5EHAAAAEg"]
[Thu Jul 30 13:20:07.764512 2026] [security2:error] [pid 872418:tid 872494] [remote 20.63.98.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuV11ymN6QYcoA7XB5EHQAAXEs"]
[Thu Jul 30 13:20:07.902588 2026] [security2:error] [pid 872418:tid 872559] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/info.php"] [unique_id "amuV11ymN6QYcoA7XB5EHwAAAAs"]
[Thu Jul 30 13:20:07.902699 2026] [security2:error] [pid 872418:tid 872559] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/info.php"] [unique_id "amuV11ymN6QYcoA7XB5EHwAAAAs"]
[Thu Jul 30 13:20:08.119344 2026] [security2:error] [pid 872418:tid 872571] [client 20.52.125.110:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuV2FymN6QYcoA7XB5EIwAAABc"]
[Thu Jul 30 13:20:08.395401 2026] [security2:error] [pid 872418:tid 872659] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/class-t.api.php"] [unique_id "amuV2FymN6QYcoA7XB5EJAAAAG8"]
[Thu Jul 30 13:20:08.395528 2026] [security2:error] [pid 872418:tid 872659] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/class-t.api.php"] [unique_id "amuV2FymN6QYcoA7XB5EJAAAAG8"]
[Thu Jul 30 13:20:08.716810 2026] [security2:error] [pid 872418:tid 872664] [client 20.52.125.110:7489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuV2FymN6QYcoA7XB5ELwAAAHQ"]
[Thu Jul 30 13:20:08.910180 2026] [security2:error] [pid 872418:tid 872586] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/simple.php"] [unique_id "amuV2FymN6QYcoA7XB5EOAAAACY"]
[Thu Jul 30 13:20:08.910292 2026] [security2:error] [pid 872418:tid 872586] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/simple.php"] [unique_id "amuV2FymN6QYcoA7XB5EOAAAACY"]
[Thu Jul 30 13:20:09.074548 2026] [security2:error] [pid 872418:tid 872563] [client 79.116.147.189:58176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuV2FymN6QYcoA7XB5EMAAAAA8"], referer: http://pkf.jo
[Thu Jul 30 13:20:09.168205 2026] [security2:error] [pid 872418:tid 872602] [client 194.187.251.163:48690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuV2VymN6QYcoA7XB5ESwAAADY"]
[Thu Jul 30 13:20:09.168298 2026] [security2:error] [pid 872418:tid 872602] [client 194.187.251.163:48690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuV2VymN6QYcoA7XB5ESwAAADY"]
[Thu Jul 30 13:20:09.198592 2026] [security2:error] [pid 872418:tid 872661] [client 20.52.125.110:7491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuV2VymN6QYcoA7XB5ETQAAAHE"]
[Thu Jul 30 13:20:09.469207 2026] [security2:error] [pid 872418:tid 872648] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/ioxi-o.php"] [unique_id "amuV2VymN6QYcoA7XB5EVgAAAGQ"]
[Thu Jul 30 13:20:09.469302 2026] [security2:error] [pid 872418:tid 872648] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/ioxi-o.php"] [unique_id "amuV2VymN6QYcoA7XB5EVgAAAGQ"]
[Thu Jul 30 13:20:09.612882 2026] [security2:error] [pid 872418:tid 872665] [client 20.52.125.110:7372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuV2VymN6QYcoA7XB5EWAAAAHU"]
[Thu Jul 30 13:20:10.023717 2026] [security2:error] [pid 872418:tid 872551] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/wp-admin"] [unique_id "amuV2lymN6QYcoA7XB5EXAAAAAM"]
[Thu Jul 30 13:20:10.057516 2026] [security2:error] [pid 872418:tid 872577] [client 20.52.125.110:6690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuV2lymN6QYcoA7XB5EXQAAAB0"]
[Thu Jul 30 13:20:10.302354 2026] [security2:error] [pid 872418:tid 872582] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuV2lymN6QYcoA7XB5EXgAAACI"]
[Thu Jul 30 13:20:10.708948 2026] [security2:error] [pid 872418:tid 872567] [client 20.52.125.110:7382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuV2lymN6QYcoA7XB5EXwAAABM"]
[Thu Jul 30 13:20:10.868463 2026] [security2:error] [pid 872418:tid 872674] [client 179.64.21.229:4058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuV2lymN6QYcoA7XB5EYQAAAH4"]
[Thu Jul 30 13:20:10.868625 2026] [security2:error] [pid 872418:tid 872674] [client 179.64.21.229:4058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuV2lymN6QYcoA7XB5EYQAAAH4"]
[Thu Jul 30 13:20:11.192901 2026] [security2:error] [pid 872418:tid 872636] [client 20.52.125.110:6693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuV21ymN6QYcoA7XB5EYwAAAFg"]
[Thu Jul 30 13:20:11.440836 2026] [security2:error] [pid 872418:tid 872548] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp.php"] [unique_id "amuV21ymN6QYcoA7XB5EZAAAAAA"]
[Thu Jul 30 13:20:11.440962 2026] [security2:error] [pid 872418:tid 872548] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp.php"] [unique_id "amuV21ymN6QYcoA7XB5EZAAAAAA"]
[Thu Jul 30 13:20:11.706186 2026] [security2:error] [pid 872418:tid 872652] [client 20.52.125.110:6676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.mediaspawn.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuV21ymN6QYcoA7XB5EZwAAAGg"]
[Thu Jul 30 13:20:11.931638 2026] [security2:error] [pid 872418:tid 872640] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/file2.php"] [unique_id "amuV21ymN6QYcoA7XB5EaQAAAFw"]
[Thu Jul 30 13:20:11.931758 2026] [security2:error] [pid 872418:tid 872640] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/file2.php"] [unique_id "amuV21ymN6QYcoA7XB5EaQAAAFw"]
[Thu Jul 30 13:20:12.421453 2026] [security2:error] [pid 872418:tid 872562] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/images/class-config.php"] [unique_id "amuV3FymN6QYcoA7XB5EagAAAA4"]
[Thu Jul 30 13:20:12.421569 2026] [security2:error] [pid 872418:tid 872562] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/images/class-config.php"] [unique_id "amuV3FymN6QYcoA7XB5EagAAAA4"]
[Thu Jul 30 13:20:12.923470 2026] [security2:error] [pid 872418:tid 872670] [client 20.9.4.9:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "propertyspro.com"] [uri "/1.php"] [unique_id "amuV3FymN6QYcoA7XB5EbQAAAHo"]
[Thu Jul 30 13:20:12.923589 2026] [security2:error] [pid 872418:tid 872670] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/1.php"] [unique_id "amuV3FymN6QYcoA7XB5EbQAAAHo"]
[Thu Jul 30 13:20:12.923722 2026] [security2:error] [pid 872418:tid 872670] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/1.php"] [unique_id "amuV3FymN6QYcoA7XB5EbQAAAHo"]
[Thu Jul 30 13:20:13.422942 2026] [security2:error] [pid 872418:tid 872534] [remote 216.73.217.142:25150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuV3VymN6QYcoA7XB5EbwAASXM"]
[Thu Jul 30 13:20:13.444276 2026] [security2:error] [pid 872418:tid 872605] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/222.php"] [unique_id "amuV3VymN6QYcoA7XB5EcAAAADk"]
[Thu Jul 30 13:20:13.444389 2026] [security2:error] [pid 872418:tid 872605] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/222.php"] [unique_id "amuV3VymN6QYcoA7XB5EcAAAADk"]
[Thu Jul 30 13:20:13.498614 2026] [security2:error] [pid 872418:tid 872644] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuV3FymN6QYcoA7XB5EbAAAYG8"]
[Thu Jul 30 13:20:13.947331 2026] [security2:error] [pid 872418:tid 872568] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/themes.php"] [unique_id "amuV3VymN6QYcoA7XB5EcQAAABQ"]
[Thu Jul 30 13:20:13.947454 2026] [security2:error] [pid 872418:tid 872568] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/themes.php"] [unique_id "amuV3VymN6QYcoA7XB5EcQAAABQ"]
[Thu Jul 30 13:20:14.099948 2026] [proxy:error] [pid 872418:tid 872569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:14.100035 2026] [proxy_http:error] [pid 872418:tid 872569] [client 3.228.112.215:4807] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:14.100591 2026] [proxy:error] [pid 872418:tid 872569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:14.100633 2026] [proxy_http:error] [pid 872418:tid 872569] [client 3.228.112.215:4807] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:14.125255 2026] [proxy:error] [pid 872418:tid 872673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:14.125350 2026] [proxy_http:error] [pid 872418:tid 872673] [client 54.87.222.253:8306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:14.126201 2026] [proxy:error] [pid 872418:tid 872673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:14.126271 2026] [proxy_http:error] [pid 872418:tid 872673] [client 54.87.222.253:8306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:14.429619 2026] [security2:error] [pid 872418:tid 872587] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/admin.php"] [unique_id "amuV3lymN6QYcoA7XB5EfAAAACc"]
[Thu Jul 30 13:20:14.429757 2026] [security2:error] [pid 872418:tid 872587] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/admin.php"] [unique_id "amuV3lymN6QYcoA7XB5EfAAAACc"]
[Thu Jul 30 13:20:14.941214 2026] [security2:error] [pid 872418:tid 872557] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/dropdown.php"] [unique_id "amuV3lymN6QYcoA7XB5EfgAAAAk"]
[Thu Jul 30 13:20:14.941329 2026] [security2:error] [pid 872418:tid 872557] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/dropdown.php"] [unique_id "amuV3lymN6QYcoA7XB5EfgAAAAk"]
[Thu Jul 30 13:20:15.110454 2026] [core:notice] [pid 872418:tid 872566] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:20:15.439313 2026] [security2:error] [pid 872418:tid 872658] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/inputs.php"] [unique_id "amuV31ymN6QYcoA7XB5EgwAAAG4"]
[Thu Jul 30 13:20:15.439435 2026] [security2:error] [pid 872418:tid 872658] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/inputs.php"] [unique_id "amuV31ymN6QYcoA7XB5EgwAAAG4"]
[Thu Jul 30 13:20:15.807898 2026] [security2:error] [pid 872418:tid 872614] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuV31ymN6QYcoA7XB5EgAAAQnI"]
[Thu Jul 30 13:20:15.949338 2026] [security2:error] [pid 872418:tid 872597] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/100.php"] [unique_id "amuV31ymN6QYcoA7XB5EiAAAADE"]
[Thu Jul 30 13:20:15.949509 2026] [security2:error] [pid 872418:tid 872597] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/100.php"] [unique_id "amuV31ymN6QYcoA7XB5EiAAAADE"]
[Thu Jul 30 13:20:16.025795 2026] [core:notice] [pid 872418:tid 872558] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:20:16.452060 2026] [security2:error] [pid 872418:tid 872572] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/autoload_classmap/function.php"] [unique_id "amuV4FymN6QYcoA7XB5EkAAAABg"]
[Thu Jul 30 13:20:16.452164 2026] [security2:error] [pid 872418:tid 872572] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/autoload_classmap/function.php"] [unique_id "amuV4FymN6QYcoA7XB5EkAAAABg"]
[Thu Jul 30 13:20:17.004228 2026] [security2:error] [pid 872418:tid 872650] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/php.php"] [unique_id "amuV4VymN6QYcoA7XB5E3gAAAGY"]
[Thu Jul 30 13:20:17.004389 2026] [security2:error] [pid 872418:tid 872650] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/php.php"] [unique_id "amuV4VymN6QYcoA7XB5E3gAAAGY"]
[Thu Jul 30 13:20:17.210457 2026] [security2:error] [pid 872418:tid 872622] [client 119.73.97.132:30847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuV4FymN6QYcoA7XB5EvwAASg0"], referer: https://www.urwru.club/wp-admin/post.php?post=1023&action=elementor
[Thu Jul 30 13:20:17.553332 2026] [security2:error] [pid 872418:tid 872590] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/t.php"] [unique_id "amuV4VymN6QYcoA7XB5E4AAAACo"]
[Thu Jul 30 13:20:17.553493 2026] [security2:error] [pid 872418:tid 872590] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/t.php"] [unique_id "amuV4VymN6QYcoA7XB5E4AAAACo"]
[Thu Jul 30 13:20:17.925106 2026] [security2:error] [pid 872418:tid 872596] [client 172.236.9.101:65143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuV4VymN6QYcoA7XB5E3wAAADA"]
[Thu Jul 30 13:20:18.087952 2026] [security2:error] [pid 872418:tid 872570] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-blink.php"] [unique_id "amuV4lymN6QYcoA7XB5E4wAAABY"]
[Thu Jul 30 13:20:18.088094 2026] [security2:error] [pid 872418:tid 872570] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-blink.php"] [unique_id "amuV4lymN6QYcoA7XB5E4wAAABY"]
[Thu Jul 30 13:20:18.665515 2026] [security2:error] [pid 872418:tid 872549] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/xfun.php"] [unique_id "amuV4lymN6QYcoA7XB5E5wAAAAE"]
[Thu Jul 30 13:20:18.665663 2026] [security2:error] [pid 872418:tid 872549] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/xfun.php"] [unique_id "amuV4lymN6QYcoA7XB5E5wAAAAE"]
[Thu Jul 30 13:20:18.934430 2026] [core:notice] [pid 872418:tid 872503] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:20:19.181754 2026] [core:notice] [pid 872418:tid 872501] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:20:19.197888 2026] [security2:error] [pid 872418:tid 872634] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/p.php"] [unique_id "amuV41ymN6QYcoA7XB5E7QAAAFY"]
[Thu Jul 30 13:20:19.198050 2026] [security2:error] [pid 872418:tid 872634] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/p.php"] [unique_id "amuV41ymN6QYcoA7XB5E7QAAAFY"]
[Thu Jul 30 13:20:19.422527 2026] [core:notice] [pid 872418:tid 872505] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:20:19.466661 2026] [security2:error] [pid 872418:tid 872671] [client 82.102.27.195:51014] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuV41ymN6QYcoA7XB5E8AAAAHs"]
[Thu Jul 30 13:20:19.466761 2026] [security2:error] [pid 872418:tid 872671] [client 82.102.27.195:51014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuV41ymN6QYcoA7XB5E8AAAAHs"]
[Thu Jul 30 13:20:19.709402 2026] [security2:error] [pid 872418:tid 872644] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuV41ymN6QYcoA7XB5E8QAAAGA"]
[Thu Jul 30 13:20:19.709521 2026] [security2:error] [pid 872418:tid 872644] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuV41ymN6QYcoA7XB5E8QAAAGA"]
[Thu Jul 30 13:20:20.210242 2026] [security2:error] [pid 872418:tid 872662] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/aaa.php"] [unique_id "amuV5FymN6QYcoA7XB5E8wAAAHI"]
[Thu Jul 30 13:20:20.210359 2026] [security2:error] [pid 872418:tid 872662] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/aaa.php"] [unique_id "amuV5FymN6QYcoA7XB5E8wAAAHI"]
[Thu Jul 30 13:20:20.723194 2026] [security2:error] [pid 872418:tid 872591] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/7.php"] [unique_id "amuV5FymN6QYcoA7XB5E9AAAACs"]
[Thu Jul 30 13:20:20.723302 2026] [security2:error] [pid 872418:tid 872591] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/7.php"] [unique_id "amuV5FymN6QYcoA7XB5E9AAAACs"]
[Thu Jul 30 13:20:21.078905 2026] [security2:error] [pid 872418:tid 872642] [client 43.173.167.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuV5FymN6QYcoA7XB5E-AAAAF4"]
[Thu Jul 30 13:20:21.274195 2026] [security2:error] [pid 872418:tid 872574] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/file5.php"] [unique_id "amuV5VymN6QYcoA7XB5E-gAAABo"]
[Thu Jul 30 13:20:21.274346 2026] [security2:error] [pid 872418:tid 872574] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/file5.php"] [unique_id "amuV5VymN6QYcoA7XB5E-gAAABo"]
[Thu Jul 30 13:20:21.379516 2026] [security2:error] [pid 872418:tid 872555] [client 179.64.21.229:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuV5VymN6QYcoA7XB5E-wAAAAc"]
[Thu Jul 30 13:20:21.386918 2026] [security2:error] [pid 872418:tid 872555] [client 179.64.21.229:63046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuV5VymN6QYcoA7XB5E-wAAAAc"]
[Thu Jul 30 13:20:21.864340 2026] [security2:error] [pid 872418:tid 872608] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/makeasmtp.php"] [unique_id "amuV5VymN6QYcoA7XB5FFwAAADw"]
[Thu Jul 30 13:20:21.864467 2026] [security2:error] [pid 872418:tid 872608] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/makeasmtp.php"] [unique_id "amuV5VymN6QYcoA7XB5FFwAAADw"]
[Thu Jul 30 13:20:22.437690 2026] [security2:error] [pid 872418:tid 872643] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/index.php"] [unique_id "amuV5lymN6QYcoA7XB5FHwAAAF8"]
[Thu Jul 30 13:20:22.437836 2026] [security2:error] [pid 872418:tid 872643] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/index.php"] [unique_id "amuV5lymN6QYcoA7XB5FHwAAAF8"]
[Thu Jul 30 13:20:22.750536 2026] [security2:error] [pid 872418:tid 872579] [client 119.73.97.132:30847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuV5lymN6QYcoA7XB5FIAAAH3w"], referer: https://www.urwru.club/wp-admin/post.php?post=1023&action=elementor
[Thu Jul 30 13:20:22.908633 2026] [security2:error] [pid 872418:tid 872563] [client 172.236.9.101:63653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuV5lymN6QYcoA7XB5FHQAAAA8"]
[Thu Jul 30 13:20:23.023462 2026] [security2:error] [pid 872418:tid 872655] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/atomlib.php"] [unique_id "amuV51ymN6QYcoA7XB5FJAAAAGs"]
[Thu Jul 30 13:20:23.023586 2026] [security2:error] [pid 872418:tid 872655] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/atomlib.php"] [unique_id "amuV51ymN6QYcoA7XB5FJAAAAGs"]
[Thu Jul 30 13:20:23.428774 2026] [security2:error] [pid 872418:tid 872536] [remote 216.73.217.142:35750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuV51ymN6QYcoA7XB5FKAAAE3U"]
[Thu Jul 30 13:20:23.442161 2026] [security2:error] [pid 872418:tid 872641] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuV51ymN6QYcoA7XB5FJwAAAF0"]
[Thu Jul 30 13:20:23.605853 2026] [security2:error] [pid 872418:tid 872667] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/min.php"] [unique_id "amuV51ymN6QYcoA7XB5FKQAAAHc"]
[Thu Jul 30 13:20:23.605962 2026] [security2:error] [pid 872418:tid 872667] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/min.php"] [unique_id "amuV51ymN6QYcoA7XB5FKQAAAHc"]
[Thu Jul 30 13:20:24.144937 2026] [security2:error] [pid 872418:tid 872652] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/moon.php"] [unique_id "amuV6FymN6QYcoA7XB5FKwAAAGg"]
[Thu Jul 30 13:20:24.145064 2026] [security2:error] [pid 872418:tid 872652] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/moon.php"] [unique_id "amuV6FymN6QYcoA7XB5FKwAAAGg"]
[Thu Jul 30 13:20:24.665960 2026] [proxy:error] [pid 872418:tid 872618] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:24.666064 2026] [proxy_http:error] [pid 872418:tid 872618] [client 18.211.55.47:62047] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:24.666969 2026] [proxy:error] [pid 872418:tid 872618] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:24.667040 2026] [proxy_http:error] [pid 872418:tid 872618] [client 18.211.55.47:62047] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:24.669068 2026] [security2:error] [pid 872418:tid 872671] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/ws83.php"] [unique_id "amuV6FymN6QYcoA7XB5FNwAAAHs"]
[Thu Jul 30 13:20:24.669194 2026] [security2:error] [pid 872418:tid 872671] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/ws83.php"] [unique_id "amuV6FymN6QYcoA7XB5FNwAAAHs"]
[Thu Jul 30 13:20:25.196573 2026] [security2:error] [pid 872418:tid 872662] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/403.php"] [unique_id "amuV6VymN6QYcoA7XB5FOAAAAHI"]
[Thu Jul 30 13:20:25.196673 2026] [security2:error] [pid 872418:tid 872662] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/403.php"] [unique_id "amuV6VymN6QYcoA7XB5FOAAAAHI"]
[Thu Jul 30 13:20:25.728356 2026] [security2:error] [pid 872418:tid 872649] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/api.php"] [unique_id "amuV6VymN6QYcoA7XB5FPwAAAGU"]
[Thu Jul 30 13:20:25.728467 2026] [security2:error] [pid 872418:tid 872649] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/api.php"] [unique_id "amuV6VymN6QYcoA7XB5FPwAAAGU"]
[Thu Jul 30 13:20:26.328609 2026] [security2:error] [pid 872418:tid 872566] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/3.php"] [unique_id "amuV6lymN6QYcoA7XB5FQwAAABI"]
[Thu Jul 30 13:20:26.328720 2026] [security2:error] [pid 872418:tid 872566] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/3.php"] [unique_id "amuV6lymN6QYcoA7XB5FQwAAABI"]
[Thu Jul 30 13:20:26.771466 2026] [security2:error] [pid 872418:tid 872638] [client 119.73.97.132:30847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuV6lymN6QYcoA7XB5FRgAAWgo"], referer: https://www.urwru.club/wp-admin/post.php?post=1023&action=elementor
[Thu Jul 30 13:20:27.888641 2026] [security2:error] [pid 872418:tid 872616] [client 154.100.20.58:37290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuV61ymN6QYcoA7XB5FUwAAAEQ"], referer: http://pkf.jo
[Thu Jul 30 13:20:27.937134 2026] [security2:error] [pid 872418:tid 872597] [client 172.236.9.101:43748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuV61ymN6QYcoA7XB5FUQAAADE"]
[Thu Jul 30 13:20:28.319834 2026] [security2:error] [pid 872418:tid 872629] [client 154.160.16.29:14156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuV7FymN6QYcoA7XB5FVQAAAFE"], referer: http://pkf.jo
[Thu Jul 30 13:20:29.063875 2026] [security2:error] [pid 872418:tid 872426] [remote 216.73.217.142:24980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuV7VymN6QYcoA7XB5FXQAAZAc"]
[Thu Jul 30 13:20:29.239911 2026] [core:notice] [pid 872418:tid 872563] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:20:29.539386 2026] [security2:error] [pid 872418:tid 872596] [client 79.47.250.33:37124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuV7VymN6QYcoA7XB5FXwAAADA"], referer: http://pkf.jo
[Thu Jul 30 13:20:30.311311 2026] [core:notice] [pid 872418:tid 872441] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:20:30.465584 2026] [security2:error] [pid 872418:tid 872551] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuV7VymN6QYcoA7XB5FYAAAAxU"]
[Thu Jul 30 13:20:32.225567 2026] [security2:error] [pid 872418:tid 872639] [client 179.64.21.229:42445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuV8FymN6QYcoA7XB5FZQAAAFs"]
[Thu Jul 30 13:20:32.229290 2026] [security2:error] [pid 872418:tid 872639] [client 179.64.21.229:42445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuV8FymN6QYcoA7XB5FZQAAAFs"]
[Thu Jul 30 13:20:32.981910 2026] [security2:error] [pid 872418:tid 872600] [client 172.236.9.101:60639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuV8FymN6QYcoA7XB5FZgAAADQ"]
[Thu Jul 30 13:20:33.437106 2026] [security2:error] [pid 872418:tid 872439] [remote 216.73.217.142:24980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuV8VymN6QYcoA7XB5FcQAAIRQ"]
[Thu Jul 30 13:20:33.519955 2026] [security2:error] [pid 872418:tid 872586] [client 82.102.27.195:42900] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuV8VymN6QYcoA7XB5FcgAAACY"]
[Thu Jul 30 13:20:33.520070 2026] [security2:error] [pid 872418:tid 872586] [client 82.102.27.195:42900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuV8VymN6QYcoA7XB5FcgAAACY"]
[Thu Jul 30 13:20:34.520778 2026] [core:error] [pid 872418:tid 872469] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:20:34.520806 2026] [core:error] [pid 872418:tid 872469] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:20:35.134433 2026] [core:error] [pid 872418:tid 872431] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:20:35.134467 2026] [core:error] [pid 872418:tid 872431] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:20:35.288774 2026] [security2:error] [pid 872418:tid 872563] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "amuV81ymN6QYcoA7XB5FfwAAAA8"]
[Thu Jul 30 13:20:35.461863 2026] [security2:error] [pid 872418:tid 872613] [client 119.28.140.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuV81ymN6QYcoA7XB5FegAAQTA"]
[Thu Jul 30 13:20:35.601115 2026] [security2:error] [pid 872418:tid 872641] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuV81ymN6QYcoA7XB5FgAAAAF0"]
[Thu Jul 30 13:20:37.113270 2026] [core:notice] [pid 872418:tid 872457] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:20:38.272498 2026] [security2:error] [pid 872418:tid 872578] [client 185.191.171.11:13778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/05/lula-e-presenca-no-jornal-nacional-confira-datas/"] [unique_id "amuV9lymN6QYcoA7XB5FqwAAAB4"]
[Thu Jul 30 13:20:38.272624 2026] [security2:error] [pid 872418:tid 872578] [client 185.191.171.11:13778] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/05/lula-e-presenca-no-jornal-nacional-confira-datas/"] [unique_id "amuV9lymN6QYcoA7XB5FqwAAAB4"]
[Thu Jul 30 13:20:38.365097 2026] [proxy:error] [pid 872418:tid 872633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:38.365181 2026] [proxy_http:error] [pid 872418:tid 872633] [client 34.233.129.35:59418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:38.365915 2026] [proxy:error] [pid 872418:tid 872633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:38.365963 2026] [proxy_http:error] [pid 872418:tid 872633] [client 34.233.129.35:59418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:38.501421 2026] [security2:error] [pid 872418:tid 872460] [remote 57.141.0.56:36164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuV9lymN6QYcoA7XB5FrQAAAyk"]
[Thu Jul 30 13:20:38.600815 2026] [security2:error] [pid 872418:tid 872599] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuV9VymN6QYcoA7XB5FqgAAMyE"]
[Thu Jul 30 13:20:39.087202 2026] [security2:error] [pid 872418:tid 872493] [remote 216.73.217.142:4629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuV91ymN6QYcoA7XB5FrwAAOUo"]
[Thu Jul 30 13:20:39.971362 2026] [security2:error] [pid 872418:tid 872638] [client 82.102.27.195:38566] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuV91ymN6QYcoA7XB5FtAAAAFo"]
[Thu Jul 30 13:20:39.971459 2026] [security2:error] [pid 872418:tid 872638] [client 82.102.27.195:38566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuV91ymN6QYcoA7XB5FtAAAAFo"]
[Thu Jul 30 13:20:40.191781 2026] [security2:error] [pid 872418:tid 872589] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/ws77.php"] [unique_id "amuV-FymN6QYcoA7XB5FtQAAACk"]
[Thu Jul 30 13:20:40.191928 2026] [security2:error] [pid 872418:tid 872589] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/ws77.php"] [unique_id "amuV-FymN6QYcoA7XB5FtQAAACk"]
[Thu Jul 30 13:20:40.765390 2026] [security2:error] [pid 872418:tid 872629] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/nc4.php"] [unique_id "amuV-FymN6QYcoA7XB5FvAAAAFE"]
[Thu Jul 30 13:20:40.765508 2026] [security2:error] [pid 872418:tid 872629] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/nc4.php"] [unique_id "amuV-FymN6QYcoA7XB5FvAAAAFE"]
[Thu Jul 30 13:20:40.842395 2026] [security2:error] [pid 872418:tid 872586] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuV-FymN6QYcoA7XB5FuAAAACY"]
[Thu Jul 30 13:20:40.877960 2026] [security2:error] [pid 872418:tid 872575] [client 172.236.9.101:49873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuV-FymN6QYcoA7XB5FuQAAABs"]
[Thu Jul 30 13:20:41.150644 2026] [security2:error] [pid 872418:tid 872668] [client 176.92.209.234:34508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuV-FymN6QYcoA7XB5FvQAAAHg"], referer: http://pkf.jo
[Thu Jul 30 13:20:41.319659 2026] [security2:error] [pid 872418:tid 872590] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/as.php"] [unique_id "amuV-VymN6QYcoA7XB5FwAAAACo"]
[Thu Jul 30 13:20:41.319768 2026] [security2:error] [pid 872418:tid 872590] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/as.php"] [unique_id "amuV-VymN6QYcoA7XB5FwAAAACo"]
[Thu Jul 30 13:20:41.892105 2026] [security2:error] [pid 872418:tid 872599] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/k.php"] [unique_id "amuV-VymN6QYcoA7XB5FwgAAADM"]
[Thu Jul 30 13:20:41.892208 2026] [security2:error] [pid 872418:tid 872599] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/k.php"] [unique_id "amuV-VymN6QYcoA7XB5FwgAAADM"]
[Thu Jul 30 13:20:42.332884 2026] [security2:error] [pid 872418:tid 872670] [client 194.187.251.163:52700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuV-lymN6QYcoA7XB5FxAAAAHo"]
[Thu Jul 30 13:20:42.333038 2026] [security2:error] [pid 872418:tid 872670] [client 194.187.251.163:52700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuV-lymN6QYcoA7XB5FxAAAAHo"]
[Thu Jul 30 13:20:42.447029 2026] [security2:error] [pid 872418:tid 872659] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/system_log.php"] [unique_id "amuV-lymN6QYcoA7XB5FxQAAAG8"]
[Thu Jul 30 13:20:42.447147 2026] [security2:error] [pid 872418:tid 872659] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/system_log.php"] [unique_id "amuV-lymN6QYcoA7XB5FxQAAAG8"]
[Thu Jul 30 13:20:42.955345 2026] [security2:error] [pid 872418:tid 872660] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/x.php"] [unique_id "amuV-lymN6QYcoA7XB5FzAAAAHA"]
[Thu Jul 30 13:20:42.955504 2026] [security2:error] [pid 872418:tid 872660] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/x.php"] [unique_id "amuV-lymN6QYcoA7XB5FzAAAAHA"]
[Thu Jul 30 13:20:42.993331 2026] [proxy:error] [pid 872418:tid 872588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:42.993397 2026] [proxy_http:error] [pid 872418:tid 872588] [client 18.211.55.47:49776] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:42.994001 2026] [proxy:error] [pid 872418:tid 872588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:42.994052 2026] [proxy_http:error] [pid 872418:tid 872588] [client 18.211.55.47:49776] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:43.051991 2026] [proxy:error] [pid 872418:tid 872614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:43.052069 2026] [proxy_http:error] [pid 872418:tid 872614] [client 98.87.102.177:39071] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:20:43.052641 2026] [proxy:error] [pid 872418:tid 872614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:20:43.052684 2026] [proxy_http:error] [pid 872418:tid 872614] [client 98.87.102.177:39071] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 13:20:43.443034 2026] [security2:error] [pid 872418:tid 872628] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/autoload_classmap.php"] [unique_id "amuV-1ymN6QYcoA7XB5F5QAAAFA"]
[Thu Jul 30 13:20:43.443151 2026] [security2:error] [pid 872418:tid 872628] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/autoload_classmap.php"] [unique_id "amuV-1ymN6QYcoA7XB5F5QAAAFA"]
[Thu Jul 30 13:20:43.444646 2026] [security2:error] [pid 872418:tid 872482] [remote 216.73.217.142:4629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuV-1ymN6QYcoA7XB5F5gAAKj8"]
[Thu Jul 30 13:20:43.971139 2026] [security2:error] [pid 872418:tid 872573] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/test1.php"] [unique_id "amuV-1ymN6QYcoA7XB5F6AAAABk"]
[Thu Jul 30 13:20:43.971255 2026] [security2:error] [pid 872418:tid 872573] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/test1.php"] [unique_id "amuV-1ymN6QYcoA7XB5F6AAAABk"]
[Thu Jul 30 13:20:44.111678 2026] [security2:error] [pid 872418:tid 872583] [client 194.187.251.163:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuV_FymN6QYcoA7XB5F6wAAACM"]
[Thu Jul 30 13:20:44.111998 2026] [security2:error] [pid 872418:tid 872583] [client 194.187.251.163:52704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuV_FymN6QYcoA7XB5F6wAAACM"]
[Thu Jul 30 13:20:44.515376 2026] [security2:error] [pid 872418:tid 872562] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/mini"] [unique_id "amuV_FymN6QYcoA7XB5F8QAAAA4"]
[Thu Jul 30 13:20:44.706294 2026] [security2:error] [pid 872418:tid 872600] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuV_FymN6QYcoA7XB5F7AAAADQ"]
[Thu Jul 30 13:20:44.806218 2026] [security2:error] [pid 872418:tid 872591] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuV_FymN6QYcoA7XB5F8gAAACs"]
[Thu Jul 30 13:20:44.849742 2026] [security2:error] [pid 872418:tid 872623] [client 172.236.9.101:54600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuV_FymN6QYcoA7XB5F7wAAAEs"]
[Thu Jul 30 13:20:45.107458 2026] [security2:error] [pid 872418:tid 872603] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-signin.php"] [unique_id "amuV_VymN6QYcoA7XB5F8wAAADc"]
[Thu Jul 30 13:20:45.107604 2026] [security2:error] [pid 872418:tid 872603] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-signin.php"] [unique_id "amuV_VymN6QYcoA7XB5F8wAAADc"]
[Thu Jul 30 13:20:45.249480 2026] [security2:error] [pid 872418:tid 872588] [client 82.102.27.195:38572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuV_VymN6QYcoA7XB5F9AAAACg"]
[Thu Jul 30 13:20:45.249585 2026] [security2:error] [pid 872418:tid 872588] [client 82.102.27.195:38572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuV_VymN6QYcoA7XB5F9AAAACg"]
[Thu Jul 30 13:20:45.298476 2026] [security2:error] [pid 872418:tid 872653] [client 43.167.239.66:57902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.239.167.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/mediaf.php"] [unique_id "amuV_VymN6QYcoA7XB5F9QAAAGk"]
[Thu Jul 30 13:20:45.643948 2026] [security2:error] [pid 872418:tid 872619] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/gg.php"] [unique_id "amuV_VymN6QYcoA7XB5F9gAAAEc"]
[Thu Jul 30 13:20:45.644081 2026] [security2:error] [pid 872418:tid 872619] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/gg.php"] [unique_id "amuV_VymN6QYcoA7XB5F9gAAAEc"]
[Thu Jul 30 13:20:47.287354 2026] [security2:error] [pid 872418:tid 872657] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuV_lymN6QYcoA7XB5F_QAAbUw"]
[Thu Jul 30 13:20:47.917887 2026] [security2:error] [pid 872418:tid 872625] [client 66.249.73.96:48930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuV_1ymN6QYcoA7XB5GAwAAAE0"]
[Thu Jul 30 13:20:48.571029 2026] [security2:error] [pid 872418:tid 872566] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/class.php"] [unique_id "amuWAFymN6QYcoA7XB5GCgAAABI"]
[Thu Jul 30 13:20:48.571151 2026] [security2:error] [pid 872418:tid 872566] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/class.php"] [unique_id "amuWAFymN6QYcoA7XB5GCgAAABI"]
[Thu Jul 30 13:20:48.905659 2026] [security2:error] [pid 872418:tid 872674] [client 172.236.9.101:6168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWAFymN6QYcoA7XB5GCQAAAH4"]
[Thu Jul 30 13:20:49.091749 2026] [security2:error] [pid 872418:tid 872667] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/404.php"] [unique_id "amuWAVymN6QYcoA7XB5GCwAAAHc"]
[Thu Jul 30 13:20:49.091910 2026] [security2:error] [pid 872418:tid 872667] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/404.php"] [unique_id "amuWAVymN6QYcoA7XB5GCwAAAHc"]
[Thu Jul 30 13:20:49.114612 2026] [security2:error] [pid 872418:tid 872505] [remote 216.73.217.142:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuWAVymN6QYcoA7XB5GDAAAHlY"]
[Thu Jul 30 13:20:49.639583 2026] [security2:error] [pid 872418:tid 872634] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/lite.php"] [unique_id "amuWAVymN6QYcoA7XB5GFgAAAFY"]
[Thu Jul 30 13:20:49.639697 2026] [security2:error] [pid 872418:tid 872634] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/lite.php"] [unique_id "amuWAVymN6QYcoA7XB5GFgAAAFY"]
[Thu Jul 30 13:20:51.089218 2026] [security2:error] [pid 872418:tid 872516] [remote 103.75.185.95:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuWA1ymN6QYcoA7XB5GJgAADmE"]
[Thu Jul 30 13:20:51.482706 2026] [security2:error] [pid 872418:tid 872530] [remote 57.141.0.67:29222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuWA1ymN6QYcoA7XB5GKgAATm8"]
[Thu Jul 30 13:20:51.535668 2026] [core:notice] [pid 872418:tid 872645] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:20:51.695719 2026] [security2:error] [pid 872418:tid 872579] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/lock360.php"] [unique_id "amuWA1ymN6QYcoA7XB5GLwAAAB8"]
[Thu Jul 30 13:20:51.695836 2026] [security2:error] [pid 872418:tid 872579] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/lock360.php"] [unique_id "amuWA1ymN6QYcoA7XB5GLwAAAB8"]
[Thu Jul 30 13:20:51.843728 2026] [security2:error] [pid 872418:tid 872581] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWA1ymN6QYcoA7XB5GLgAAACE"]
[Thu Jul 30 13:20:52.215112 2026] [security2:error] [pid 872418:tid 872616] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuWBFymN6QYcoA7XB5GMwAAAEQ"]
[Thu Jul 30 13:20:52.215280 2026] [security2:error] [pid 872418:tid 872616] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuWBFymN6QYcoA7XB5GMwAAAEQ"]
[Thu Jul 30 13:20:52.460049 2026] [security2:error] [pid 872418:tid 872523] [remote 184.168.126.180:51454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amuWBFymN6QYcoA7XB5GNQAAKGg"]
[Thu Jul 30 13:20:52.873112 2026] [security2:error] [pid 872418:tid 872584] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-links-opml.php"] [unique_id "amuWBFymN6QYcoA7XB5GRgAAACQ"]
[Thu Jul 30 13:20:52.873255 2026] [security2:error] [pid 872418:tid 872584] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-links-opml.php"] [unique_id "amuWBFymN6QYcoA7XB5GRgAAACQ"]
[Thu Jul 30 13:20:52.997547 2026] [security2:error] [pid 872418:tid 872577] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWBFymN6QYcoA7XB5GNAAAHXc"]
[Thu Jul 30 13:20:53.094851 2026] [security2:error] [pid 872418:tid 872657] [client 179.64.21.229:60260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWBVymN6QYcoA7XB5GSAAAAG0"]
[Thu Jul 30 13:20:53.094959 2026] [security2:error] [pid 872418:tid 872657] [client 179.64.21.229:60260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWBVymN6QYcoA7XB5GSAAAAG0"]
[Thu Jul 30 13:20:53.422178 2026] [security2:error] [pid 872418:tid 872587] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/uploads/min.php"] [unique_id "amuWBVymN6QYcoA7XB5GSwAAACc"]
[Thu Jul 30 13:20:53.422282 2026] [security2:error] [pid 872418:tid 872587] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/uploads/min.php"] [unique_id "amuWBVymN6QYcoA7XB5GSwAAACc"]
[Thu Jul 30 13:20:53.450853 2026] [security2:error] [pid 872418:tid 872540] [remote 216.73.217.142:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuWBVymN6QYcoA7XB5GTQAAUnk"]
[Thu Jul 30 13:20:55.383578 2026] [security2:error] [pid 872418:tid 872571] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWBlymN6QYcoA7XB5GVAAAABc"]
[Thu Jul 30 13:20:58.634015 2026] [security2:error] [pid 872418:tid 872424] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.allmontecristi.com"] [uri "/"] [unique_id "amuWClymN6QYcoA7XB5GZQAATwU"]
[Thu Jul 30 13:20:59.081323 2026] [security2:error] [pid 872418:tid 872527] [remote 216.73.217.142:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuWC1ymN6QYcoA7XB5GZwAAO2w"]
[Thu Jul 30 13:20:59.108305 2026] [security2:error] [pid 872418:tid 872433] [remote 62.60.130.227:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.allmontecristi.com"] [uri "/"] [unique_id "amuWC1ymN6QYcoA7XB5GaAAAPg4"]
[Thu Jul 30 13:21:01.479091 2026] [security2:error] [pid 872418:tid 872662] [client 78.174.214.216:8206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuWDVymN6QYcoA7XB5GcQAAAHI"], referer: http://pkf.jo
[Thu Jul 30 13:21:02.161060 2026] [security2:error] [pid 872418:tid 872567] [client 45.191.81.146:58243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuWDVymN6QYcoA7XB5GcwAAABM"], referer: http://pkf.jo
[Thu Jul 30 13:21:03.649180 2026] [security2:error] [pid 872418:tid 872566] [client 179.64.21.229:15848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWD1ymN6QYcoA7XB5GewAAABI"]
[Thu Jul 30 13:21:03.649304 2026] [security2:error] [pid 872418:tid 872566] [client 179.64.21.229:15848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWD1ymN6QYcoA7XB5GewAAABI"]
[Thu Jul 30 13:21:04.077432 2026] [security2:error] [pid 872418:tid 872611] [client 20.104.18.253:6681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/astra/inc/fm.php"] [unique_id "amuWEFymN6QYcoA7XB5GfwAAAD8"]
[Thu Jul 30 13:21:04.538016 2026] [security2:error] [pid 872418:tid 872573] [client 18.193.252.127:19036] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuWEFymN6QYcoA7XB5GhgAAABk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:21:04.682388 2026] [security2:error] [pid 872418:tid 872633] [client 20.104.18.253:7034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/astra/inc/ki1k.php"] [unique_id "amuWEFymN6QYcoA7XB5GiwAAAFU"]
[Thu Jul 30 13:21:04.907719 2026] [core:notice] [pid 872418:tid 872555] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:04.912357 2026] [security2:error] [pid 872418:tid 872555] [client 18.193.252.127:19038] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuWEFymN6QYcoA7XB5GjgAAAAc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:21:04.923254 2026] [security2:error] [pid 872418:tid 872641] [client 47.254.47.156:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.47.254.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "womenclothingbox.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuWEFymN6QYcoA7XB5GjwAAAF0"]
[Thu Jul 30 13:21:05.278285 2026] [security2:error] [pid 872418:tid 872606] [client 20.104.18.253:7037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/atombil.php"] [unique_id "amuWEVymN6QYcoA7XB5GlAAAADo"]
[Thu Jul 30 13:21:05.327514 2026] [security2:error] [pid 872418:tid 872614] [client 18.193.252.127:19052] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuWEVymN6QYcoA7XB5GmAAAAEI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:21:05.875605 2026] [security2:error] [pid 872418:tid 872602] [client 20.104.18.253:6659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/atomlib.php"] [unique_id "amuWEVymN6QYcoA7XB5GnQAAADY"]
[Thu Jul 30 13:21:05.960378 2026] [security2:error] [pid 872418:tid 872556] [client 57.141.0.13:33928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuWEVymN6QYcoA7XB5GmwAACBc"], referer: https://igetvape-australia.com/product/iget-bar-pro-raspberry-grape/?add-to-cart=83
[Thu Jul 30 13:21:06.473085 2026] [proxy:error] [pid 872418:tid 872613] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:06.473172 2026] [proxy_http:error] [pid 872418:tid 872613] [client 98.87.102.177:11384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:06.473968 2026] [proxy:error] [pid 872418:tid 872613] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:06.474036 2026] [proxy_http:error] [pid 872418:tid 872613] [client 98.87.102.177:11384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:06.478533 2026] [proxy:error] [pid 872418:tid 872670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:06.478595 2026] [proxy_http:error] [pid 872418:tid 872670] [client 98.87.102.177:21645] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:06.478799 2026] [security2:error] [pid 872418:tid 872601] [client 20.104.18.253:7015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aua.php"] [unique_id "amuWElymN6QYcoA7XB5GpgAAADU"]
[Thu Jul 30 13:21:06.479162 2026] [proxy:error] [pid 872418:tid 872670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:06.479209 2026] [proxy_http:error] [pid 872418:tid 872670] [client 98.87.102.177:21645] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:06.559206 2026] [security2:error] [pid 872418:tid 872584] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWEVymN6QYcoA7XB5GoAAAACQ"]
[Thu Jul 30 13:21:06.565583 2026] [security2:error] [pid 872418:tid 872464] [remote 192.250.227.227:36644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.227.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-login.php"] [unique_id "amuWElymN6QYcoA7XB5GqgAAEC0"]
[Thu Jul 30 13:21:07.079427 2026] [security2:error] [pid 872418:tid 872561] [client 20.104.18.253:7000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aucxzso.php"] [unique_id "amuWE1ymN6QYcoA7XB5GuwAAAA0"]
[Thu Jul 30 13:21:07.679597 2026] [security2:error] [pid 872418:tid 872583] [client 20.104.18.253:6679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/audio.php"] [unique_id "amuWE1ymN6QYcoA7XB5GwQAAACM"]
[Thu Jul 30 13:21:07.773309 2026] [proxy:error] [pid 872418:tid 872669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:07.773402 2026] [proxy_http:error] [pid 872418:tid 872669] [client 18.211.55.47:48323] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:07.774003 2026] [proxy:error] [pid 872418:tid 872669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:07.774050 2026] [proxy_http:error] [pid 872418:tid 872669] [client 18.211.55.47:48323] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:07.776373 2026] [proxy:error] [pid 872418:tid 872565] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:07.776451 2026] [proxy_http:error] [pid 872418:tid 872565] [client 44.216.125.112:12510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:07.777200 2026] [proxy:error] [pid 872418:tid 872565] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:07.777250 2026] [proxy_http:error] [pid 872418:tid 872565] [client 44.216.125.112:12510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:07.814493 2026] [security2:error] [pid 872418:tid 872611] [client 172.236.9.101:21961] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWE1ymN6QYcoA7XB5GvgAAAD8"]
[Thu Jul 30 13:21:08.277354 2026] [security2:error] [pid 872418:tid 872612] [client 20.104.18.253:7030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/audit.php"] [unique_id "amuWFFymN6QYcoA7XB5GzAAAAEA"]
[Thu Jul 30 13:21:08.458809 2026] [security2:error] [pid 872418:tid 872485] [remote 216.73.217.142:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuWFFymN6QYcoA7XB5GzwAAaUI"]
[Thu Jul 30 13:21:08.877052 2026] [security2:error] [pid 872418:tid 872641] [client 20.104.18.253:6144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/auth.php"] [unique_id "amuWFFymN6QYcoA7XB5G0wAAAF0"]
[Thu Jul 30 13:21:09.330672 2026] [core:notice] [pid 872418:tid 872636] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:09.473747 2026] [security2:error] [pid 872418:tid 872651] [client 20.104.18.253:6978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/authorize.php"] [unique_id "amuWFVymN6QYcoA7XB5G2AAAAGc"]
[Thu Jul 30 13:21:10.075490 2026] [security2:error] [pid 872418:tid 872607] [client 20.104.18.253:7019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/autoload_classmap.php"] [unique_id "amuWFlymN6QYcoA7XB5G3QAAADs"]
[Thu Jul 30 13:21:10.673188 2026] [security2:error] [pid 872418:tid 872567] [client 20.104.18.253:7025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/autoloadclassmap.php"] [unique_id "amuWFlymN6QYcoA7XB5G3gAAABM"]
[Thu Jul 30 13:21:11.269673 2026] [security2:error] [pid 872418:tid 872622] [client 20.104.18.253:6988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/automanipulative.php"] [unique_id "amuWF1ymN6QYcoA7XB5G4QAAAEo"]
[Thu Jul 30 13:21:11.719723 2026] [security2:error] [pid 872418:tid 872637] [client 172.236.9.101:64653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWF1ymN6QYcoA7XB5G4AAAAFk"]
[Thu Jul 30 13:21:11.811188 2026] [proxy:error] [pid 872418:tid 872624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:11.811277 2026] [proxy_http:error] [pid 872418:tid 872624] [client 44.213.206.96:49551] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:11.811855 2026] [proxy:error] [pid 872418:tid 872624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:11.811899 2026] [proxy_http:error] [pid 872418:tid 872624] [client 44.213.206.96:49551] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:11.814492 2026] [proxy:error] [pid 872418:tid 872671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:11.814572 2026] [proxy_http:error] [pid 872418:tid 872671] [client 3.225.222.228:35381] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:11.815151 2026] [proxy:error] [pid 872418:tid 872671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:11.815200 2026] [proxy_http:error] [pid 872418:tid 872671] [client 3.225.222.228:35381] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:11.870872 2026] [security2:error] [pid 872418:tid 872552] [client 20.104.18.253:7001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/av.php"] [unique_id "amuWF1ymN6QYcoA7XB5G7wAAAAQ"]
[Thu Jul 30 13:21:12.474066 2026] [security2:error] [pid 872418:tid 872574] [client 20.104.18.253:6663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ava.php"] [unique_id "amuWGFymN6QYcoA7XB5G8gAAABo"]
[Thu Jul 30 13:21:13.075761 2026] [security2:error] [pid 872418:tid 872612] [client 20.104.18.253:6999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/avaa.php"] [unique_id "amuWGVymN6QYcoA7XB5G-AAAAEA"]
[Thu Jul 30 13:21:13.632637 2026] [security2:error] [pid 872418:tid 872589] [client 189.161.146.242:55046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuWGVymN6QYcoA7XB5G-QAAACk"], referer: http://pkf.jo
[Thu Jul 30 13:21:13.673697 2026] [security2:error] [pid 872418:tid 872557] [client 20.104.18.253:6665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ave.php"] [unique_id "amuWGVymN6QYcoA7XB5G-wAAAAk"]
[Thu Jul 30 13:21:13.748535 2026] [proxy:error] [pid 872418:tid 872632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:13.748618 2026] [proxy_http:error] [pid 872418:tid 872632] [client 98.87.102.177:47241] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:13.749196 2026] [proxy:error] [pid 872418:tid 872632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:13.749241 2026] [proxy_http:error] [pid 872418:tid 872632] [client 98.87.102.177:47241] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:13.769490 2026] [proxy:error] [pid 872418:tid 872614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:13.769577 2026] [proxy_http:error] [pid 872418:tid 872614] [client 98.87.102.177:7695] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:13.770170 2026] [proxy:error] [pid 872418:tid 872614] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:13.770222 2026] [proxy_http:error] [pid 872418:tid 872614] [client 98.87.102.177:7695] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:14.441372 2026] [security2:error] [pid 872418:tid 872569] [client 179.64.21.229:49944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWGlymN6QYcoA7XB5HDQAAABU"]
[Thu Jul 30 13:21:14.449129 2026] [security2:error] [pid 872418:tid 872569] [client 179.64.21.229:49944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWGlymN6QYcoA7XB5HDQAAABU"]
[Thu Jul 30 13:21:14.634633 2026] [security2:error] [pid 872418:tid 872661] [client 194.187.251.163:54692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.251.187.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuWGlymN6QYcoA7XB5HEQAAAHE"]
[Thu Jul 30 13:21:14.634796 2026] [security2:error] [pid 872418:tid 872661] [client 194.187.251.163:54692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuWGlymN6QYcoA7XB5HEQAAAHE"]
[Thu Jul 30 13:21:14.758908 2026] [security2:error] [pid 872418:tid 872662] [client 172.236.9.101:25308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWGlymN6QYcoA7XB5HDAAAAHI"]
[Thu Jul 30 13:21:15.681473 2026] [proxy:error] [pid 872418:tid 872637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:15.681561 2026] [proxy_http:error] [pid 872418:tid 872637] [client 52.202.41.153:40470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:15.682159 2026] [proxy:error] [pid 872418:tid 872637] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:15.682207 2026] [proxy_http:error] [pid 872418:tid 872637] [client 52.202.41.153:40470] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:15.711509 2026] [proxy:error] [pid 872418:tid 872663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:15.711587 2026] [proxy_http:error] [pid 872418:tid 872663] [client 54.87.222.253:39427] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:15.712156 2026] [proxy:error] [pid 872418:tid 872663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:15.712200 2026] [proxy_http:error] [pid 872418:tid 872663] [client 54.87.222.253:39427] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:16.028028 2026] [security2:error] [pid 872418:tid 872548] [client 20.104.18.253:6203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aves.php"] [unique_id "amuWHFymN6QYcoA7XB5HJAAAAAA"]
[Thu Jul 30 13:21:16.152898 2026] [security2:error] [pid 872418:tid 872471] [remote 57.141.0.39:65084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6113126855/feed/rss2/"] [unique_id "amuWHFymN6QYcoA7XB5HJQAALTQ"]
[Thu Jul 30 13:21:16.538098 2026] [proxy:error] [pid 872418:tid 872673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:16.538179 2026] [proxy_http:error] [pid 872418:tid 872673] [client 18.211.55.47:1031] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:16.538786 2026] [proxy:error] [pid 872418:tid 872673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:16.538831 2026] [proxy_http:error] [pid 872418:tid 872673] [client 18.211.55.47:1031] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:16.540269 2026] [security2:error] [pid 872418:tid 872432] [remote 57.141.0.13:22770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6113126855/feed/rss2/"] [unique_id "amuWHFymN6QYcoA7XB5HKwAAFA0"]
[Thu Jul 30 13:21:16.543071 2026] [proxy:error] [pid 872418:tid 872550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:16.543124 2026] [proxy_http:error] [pid 872418:tid 872550] [client 44.216.125.112:53703] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:16.543672 2026] [proxy:error] [pid 872418:tid 872550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:16.543714 2026] [proxy_http:error] [pid 872418:tid 872550] [client 44.216.125.112:53703] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:16.633758 2026] [security2:error] [pid 872418:tid 872559] [client 20.104.18.253:6431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/awesome-coming-soon/come.php"] [unique_id "amuWHFymN6QYcoA7XB5HOAAAAAs"]
[Thu Jul 30 13:21:17.020360 2026] [core:notice] [pid 872418:tid 872498] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:17.040839 2026] [security2:error] [pid 872418:tid 872496] [remote 57.141.0.50:62202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6113126855/feed/rss2/"] [unique_id "amuWHVymN6QYcoA7XB5HPgAAKU0"]
[Thu Jul 30 13:21:17.253257 2026] [security2:error] [pid 872418:tid 872616] [client 20.104.18.253:6452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/awesome-coming-soon/flower.php"] [unique_id "amuWHVymN6QYcoA7XB5HQQAAAEQ"]
[Thu Jul 30 13:21:17.851912 2026] [security2:error] [pid 872418:tid 872657] [client 20.104.18.253:6435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aws.php"] [unique_id "amuWHVymN6QYcoA7XB5HRgAAAG0"]
[Thu Jul 30 13:21:18.095214 2026] [proxy:error] [pid 872418:tid 872648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:18.095289 2026] [proxy_http:error] [pid 872418:tid 872648] [client 44.216.125.112:10920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:18.095858 2026] [proxy:error] [pid 872418:tid 872648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:18.095899 2026] [proxy_http:error] [pid 872418:tid 872648] [client 44.216.125.112:10920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:18.467193 2026] [security2:error] [pid 872418:tid 872661] [client 20.104.18.253:6406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ax.php"] [unique_id "amuWHlymN6QYcoA7XB5HUAAAAHE"]
[Thu Jul 30 13:21:18.762878 2026] [core:notice] [pid 872418:tid 872584] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:19.066452 2026] [security2:error] [pid 872418:tid 872620] [client 20.104.18.253:6664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/axx.php"] [unique_id "amuWH1ymN6QYcoA7XB5HWwAAAEg"]
[Thu Jul 30 13:21:19.200133 2026] [security2:error] [pid 872418:tid 872671] [client 20.215.218.234:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/kontol.php"] [unique_id "amuWH1ymN6QYcoA7XB5HXAAAAHs"]
[Thu Jul 30 13:21:19.200258 2026] [security2:error] [pid 872418:tid 872671] [client 20.215.218.234:63526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/kontol.php"] [unique_id "amuWH1ymN6QYcoA7XB5HXAAAAHs"]
[Thu Jul 30 13:21:19.552893 2026] [security2:error] [pid 872418:tid 872573] [client 20.215.218.234:64082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp.php"] [unique_id "amuWH1ymN6QYcoA7XB5HZAAAABk"]
[Thu Jul 30 13:21:19.553015 2026] [security2:error] [pid 872418:tid 872573] [client 20.215.218.234:64082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp.php"] [unique_id "amuWH1ymN6QYcoA7XB5HZAAAABk"]
[Thu Jul 30 13:21:19.687292 2026] [security2:error] [pid 872418:tid 872552] [client 20.104.18.253:6427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ay.php"] [unique_id "amuWH1ymN6QYcoA7XB5HZQAAAAQ"]
[Thu Jul 30 13:21:19.936846 2026] [security2:error] [pid 872418:tid 872634] [client 20.215.218.234:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/readme.php"] [unique_id "amuWH1ymN6QYcoA7XB5HZwAAAFY"]
[Thu Jul 30 13:21:19.937006 2026] [security2:error] [pid 872418:tid 872634] [client 20.215.218.234:63491] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/readme.php"] [unique_id "amuWH1ymN6QYcoA7XB5HZwAAAFY"]
[Thu Jul 30 13:21:20.350554 2026] [security2:error] [pid 872418:tid 872568] [client 20.215.218.234:9937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/error_log.php"] [unique_id "amuWIFymN6QYcoA7XB5HaQAAABQ"]
[Thu Jul 30 13:21:20.350678 2026] [security2:error] [pid 872418:tid 872568] [client 20.215.218.234:9937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/error_log.php"] [unique_id "amuWIFymN6QYcoA7XB5HaQAAABQ"]
[Thu Jul 30 13:21:20.352226 2026] [security2:error] [pid 872418:tid 872579] [client 20.104.18.253:6674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ayk.php"] [unique_id "amuWIFymN6QYcoA7XB5HagAAAB8"]
[Thu Jul 30 13:21:20.679164 2026] [security2:error] [pid 872418:tid 872612] [client 20.215.218.234:21753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin.php"] [unique_id "amuWIFymN6QYcoA7XB5HawAAAEA"]
[Thu Jul 30 13:21:20.679268 2026] [security2:error] [pid 872418:tid 872612] [client 20.215.218.234:21753] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin.php"] [unique_id "amuWIFymN6QYcoA7XB5HawAAAEA"]
[Thu Jul 30 13:21:20.719565 2026] [security2:error] [pid 872418:tid 872673] [client 172.236.9.101:26675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWIFymN6QYcoA7XB5HaAAAAH0"]
[Thu Jul 30 13:21:20.968025 2026] [security2:error] [pid 872418:tid 872639] [client 20.104.18.253:6460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/az.php"] [unique_id "amuWIFymN6QYcoA7XB5HbgAAAFs"]
[Thu Jul 30 13:21:21.100347 2026] [security2:error] [pid 872418:tid 872499] [remote 57.141.0.47:34862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amuWIVymN6QYcoA7XB5HcAAAOlA"]
[Thu Jul 30 13:21:21.253070 2026] [security2:error] [pid 872418:tid 872666] [client 20.215.218.234:20751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-login.php"] [unique_id "amuWIVymN6QYcoA7XB5HbwAAAHY"]
[Thu Jul 30 13:21:21.253212 2026] [security2:error] [pid 872418:tid 872666] [client 20.215.218.234:20751] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-login.php"] [unique_id "amuWIVymN6QYcoA7XB5HbwAAAHY"]
[Thu Jul 30 13:21:21.569944 2026] [security2:error] [pid 872418:tid 872586] [client 20.215.218.234:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/administrator.php"] [unique_id "amuWIVymN6QYcoA7XB5HdgAAACY"]
[Thu Jul 30 13:21:21.570049 2026] [security2:error] [pid 872418:tid 872586] [client 20.215.218.234:63493] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/administrator.php"] [unique_id "amuWIVymN6QYcoA7XB5HdgAAACY"]
[Thu Jul 30 13:21:21.582073 2026] [security2:error] [pid 872418:tid 872672] [client 20.104.18.253:6703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/azdare.php"] [unique_id "amuWIVymN6QYcoA7XB5HdwAAAHw"]
[Thu Jul 30 13:21:21.798455 2026] [proxy:error] [pid 872418:tid 872598] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:21.798527 2026] [proxy_http:error] [pid 872418:tid 872598] [client 34.224.175.62:49081] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:21.799354 2026] [proxy:error] [pid 872418:tid 872598] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:21.799434 2026] [proxy_http:error] [pid 872418:tid 872598] [client 34.224.175.62:49081] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:21.815212 2026] [proxy:error] [pid 872418:tid 872604] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:21.815275 2026] [proxy_http:error] [pid 872418:tid 872604] [client 34.233.129.35:62816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:21.815906 2026] [proxy:error] [pid 872418:tid 872604] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:21.815954 2026] [proxy_http:error] [pid 872418:tid 872604] [client 34.233.129.35:62816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:21.828289 2026] [core:notice] [pid 872418:tid 872657] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:21.875790 2026] [security2:error] [pid 872418:tid 872670] [client 20.215.218.234:63523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-load.php"] [unique_id "amuWIVymN6QYcoA7XB5HhQAAAHo"]
[Thu Jul 30 13:21:21.875883 2026] [security2:error] [pid 872418:tid 872670] [client 20.215.218.234:63523] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-load.php"] [unique_id "amuWIVymN6QYcoA7XB5HhQAAAHo"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 13:21:22.185492 2026] [security2:error] [pid 872418:tid 872570] [client 20.104.18.253:6979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/azra-tn/wso.php"] [unique_id "amuWIlymN6QYcoA7XB5HjAAAABY"]
[Thu Jul 30 13:21:22.328608 2026] [core:notice] [pid 872418:tid 872667] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:22.437964 2026] [security2:error] [pid 872418:tid 872620] [client 20.215.218.234:63518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-includes.php"] [unique_id "amuWIlymN6QYcoA7XB5HlAAAAEg"]
[Thu Jul 30 13:21:22.438091 2026] [security2:error] [pid 872418:tid 872620] [client 20.215.218.234:63518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-includes.php"] [unique_id "amuWIlymN6QYcoA7XB5HlAAAAEg"]
[Thu Jul 30 13:21:22.775086 2026] [security2:error] [pid 872418:tid 872631] [client 20.215.218.234:9970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content.php"] [unique_id "amuWIlymN6QYcoA7XB5HlwAAAFM"]
[Thu Jul 30 13:21:22.775199 2026] [security2:error] [pid 872418:tid 872631] [client 20.215.218.234:9970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content.php"] [unique_id "amuWIlymN6QYcoA7XB5HlwAAAFM"]
[Thu Jul 30 13:21:22.783206 2026] [security2:error] [pid 872418:tid 872562] [client 20.104.18.253:6405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/b.php"] [unique_id "amuWIlymN6QYcoA7XB5HmAAAAA4"]
[Thu Jul 30 13:21:23.076952 2026] [security2:error] [pid 872418:tid 872565] [client 20.215.218.234:20784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index.php"] [unique_id "amuWI1ymN6QYcoA7XB5HmgAAABE"]
[Thu Jul 30 13:21:23.077074 2026] [security2:error] [pid 872418:tid 872565] [client 20.215.218.234:20784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index.php"] [unique_id "amuWI1ymN6QYcoA7XB5HmgAAABE"]
[Thu Jul 30 13:21:23.379120 2026] [security2:error] [pid 872418:tid 872573] [client 20.104.18.253:7023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/b374k.php"] [unique_id "amuWI1ymN6QYcoA7XB5HngAAABk"]
[Thu Jul 30 13:21:23.383287 2026] [security2:error] [pid 872418:tid 872548] [client 20.215.218.234:20775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/bypp.php"] [unique_id "amuWI1ymN6QYcoA7XB5HnwAAAAA"]
[Thu Jul 30 13:21:23.383383 2026] [security2:error] [pid 872418:tid 872548] [client 20.215.218.234:20775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/bypp.php"] [unique_id "amuWI1ymN6QYcoA7XB5HnwAAAAA"]
[Thu Jul 30 13:21:23.702762 2026] [security2:error] [pid 872418:tid 872664] [client 20.215.218.234:21705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/byp7.php"] [unique_id "amuWI1ymN6QYcoA7XB5HsgAAAHQ"]
[Thu Jul 30 13:21:23.702859 2026] [security2:error] [pid 872418:tid 872664] [client 20.215.218.234:21705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/byp7.php"] [unique_id "amuWI1ymN6QYcoA7XB5HsgAAAHQ"]
[Thu Jul 30 13:21:23.733383 2026] [proxy:error] [pid 872418:tid 872589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:23.733459 2026] [proxy_http:error] [pid 872418:tid 872589] [client 44.213.206.96:52674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:23.733883 2026] [proxy:error] [pid 872418:tid 872586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:23.733942 2026] [proxy_http:error] [pid 872418:tid 872586] [client 3.225.222.228:2999] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:23.734082 2026] [proxy:error] [pid 872418:tid 872589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:23.734130 2026] [proxy_http:error] [pid 872418:tid 872589] [client 44.213.206.96:52674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:23.734547 2026] [proxy:error] [pid 872418:tid 872586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:23.734591 2026] [proxy_http:error] [pid 872418:tid 872586] [client 3.225.222.228:2999] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:23.735647 2026] [security2:error] [pid 872418:tid 872554] [client 172.236.9.101:33871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWI1ymN6QYcoA7XB5HnQAAAAY"]
[Thu Jul 30 13:21:23.986099 2026] [security2:error] [pid 872418:tid 872651] [client 20.104.18.253:6451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/b8b.php"] [unique_id "amuWI1ymN6QYcoA7XB5HzwAAAGc"]
[Thu Jul 30 13:21:24.019729 2026] [security2:error] [pid 872418:tid 872665] [client 20.215.218.234:60284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/anonsec.php"] [unique_id "amuWJFymN6QYcoA7XB5H0AAAAHU"]
[Thu Jul 30 13:21:24.019857 2026] [security2:error] [pid 872418:tid 872665] [client 20.215.218.234:60284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/anonsec.php"] [unique_id "amuWJFymN6QYcoA7XB5H0AAAAHU"]
[Thu Jul 30 13:21:24.358230 2026] [security2:error] [pid 872418:tid 872595] [client 20.215.218.234:21196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/anon.php"] [unique_id "amuWJFymN6QYcoA7XB5H2wAAAC8"]
[Thu Jul 30 13:21:24.358409 2026] [security2:error] [pid 872418:tid 872595] [client 20.215.218.234:21196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/anon.php"] [unique_id "amuWJFymN6QYcoA7XB5H2wAAAC8"]
[Thu Jul 30 13:21:24.601254 2026] [security2:error] [pid 872418:tid 872620] [client 20.104.18.253:6998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/babu.php"] [unique_id "amuWJFymN6QYcoA7XB5H4gAAAEg"]
[Thu Jul 30 13:21:24.686375 2026] [security2:error] [pid 872418:tid 872624] [client 20.215.218.234:60233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/bypas.php"] [unique_id "amuWJFymN6QYcoA7XB5H4wAAAEw"]
[Thu Jul 30 13:21:24.686542 2026] [security2:error] [pid 872418:tid 872624] [client 20.215.218.234:60233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/bypas.php"] [unique_id "amuWJFymN6QYcoA7XB5H4wAAAEw"]
[Thu Jul 30 13:21:25.037798 2026] [security2:error] [pid 872418:tid 872580] [client 20.215.218.234:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ucen.php"] [unique_id "amuWJVymN6QYcoA7XB5H7AAAACA"]
[Thu Jul 30 13:21:25.037895 2026] [security2:error] [pid 872418:tid 872580] [client 20.215.218.234:60267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ucen.php"] [unique_id "amuWJVymN6QYcoA7XB5H7AAAACA"]
[Thu Jul 30 13:21:25.270202 2026] [security2:error] [pid 872418:tid 872583] [client 179.64.21.229:64847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWJVymN6QYcoA7XB5H8gAAACM"]
[Thu Jul 30 13:21:25.277445 2026] [security2:error] [pid 872418:tid 872583] [client 179.64.21.229:64847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWJVymN6QYcoA7XB5H8gAAACM"]
[Thu Jul 30 13:21:25.447745 2026] [security2:error] [pid 872418:tid 872669] [client 20.215.218.234:20780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/miya.php"] [unique_id "amuWJVymN6QYcoA7XB5H9gAAAHk"]
[Thu Jul 30 13:21:25.447850 2026] [security2:error] [pid 872418:tid 872669] [client 20.215.218.234:20780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/miya.php"] [unique_id "amuWJVymN6QYcoA7XB5H9gAAAHk"]
[Thu Jul 30 13:21:25.755316 2026] [security2:error] [pid 872418:tid 872639] [client 20.215.218.234:21237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/error.php"] [unique_id "amuWJVymN6QYcoA7XB5H-wAAAFs"]
[Thu Jul 30 13:21:25.755479 2026] [security2:error] [pid 872418:tid 872639] [client 20.215.218.234:21237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/error.php"] [unique_id "amuWJVymN6QYcoA7XB5H-wAAAFs"]
[Thu Jul 30 13:21:26.040618 2026] [proxy:error] [pid 872418:tid 872611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:26.040730 2026] [proxy_http:error] [pid 872418:tid 872611] [client 3.228.112.215:35362] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:26.042039 2026] [proxy:error] [pid 872418:tid 872611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:26.042108 2026] [proxy_http:error] [pid 872418:tid 872611] [client 3.228.112.215:35362] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:26.103219 2026] [security2:error] [pid 872418:tid 872656] [client 20.215.218.234:20770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfav.php"] [unique_id "amuWJlymN6QYcoA7XB5IBQAAAGw"]
[Thu Jul 30 13:21:26.103310 2026] [security2:error] [pid 872418:tid 872656] [client 20.215.218.234:20770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfav.php"] [unique_id "amuWJlymN6QYcoA7XB5IBQAAAGw"]
[Thu Jul 30 13:21:26.235108 2026] [security2:error] [pid 872418:tid 872638] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWJVymN6QYcoA7XB5H9wAAWn4"]
[Thu Jul 30 13:21:26.434635 2026] [security2:error] [pid 872418:tid 872630] [client 20.215.218.234:20794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alpas.php"] [unique_id "amuWJlymN6QYcoA7XB5IEQAAAFI"]
[Thu Jul 30 13:21:26.434757 2026] [security2:error] [pid 872418:tid 872630] [client 20.215.218.234:20794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alpas.php"] [unique_id "amuWJlymN6QYcoA7XB5IEQAAAFI"]
[Thu Jul 30 13:21:26.722615 2026] [core:notice] [pid 872418:tid 872445] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:26.771721 2026] [security2:error] [pid 872418:tid 872648] [client 172.236.9.101:8107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWJlymN6QYcoA7XB5ICgAAAGQ"]
[Thu Jul 30 13:21:26.829530 2026] [security2:error] [pid 872418:tid 872596] [client 20.215.218.234:9972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfa.php"] [unique_id "amuWJlymN6QYcoA7XB5IFgAAADA"]
[Thu Jul 30 13:21:26.829648 2026] [security2:error] [pid 872418:tid 872596] [client 20.215.218.234:9972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfa.php"] [unique_id "amuWJlymN6QYcoA7XB5IFgAAADA"]
[Thu Jul 30 13:21:26.977471 2026] [security2:error] [pid 872418:tid 872613] [client 47.85.195.135:42476] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWJlymN6QYcoA7XB5IBwAAAEE"]
[Thu Jul 30 13:21:27.173474 2026] [core:notice] [pid 872418:tid 872446] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:27.175245 2026] [security2:error] [pid 872418:tid 872637] [client 74.7.230.2:49562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amuWJ1ymN6QYcoA7XB5IFwAAWRs"]
[Thu Jul 30 13:21:27.206618 2026] [security2:error] [pid 872418:tid 872631] [client 127.0.0.1:10186] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuWJ1ymN6QYcoA7XB5IGgAAAFM"]
[Thu Jul 30 13:21:27.206623 2026] [security2:error] [pid 872418:tid 872668] [client 127.0.0.1:10176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.nfi.nyx.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuWJ1ymN6QYcoA7XB5IGQAAAHg"]
[Thu Jul 30 13:21:27.206781 2026] [security2:error] [pid 872418:tid 872620] [client 74.7.230.51:53008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.nfi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuWJ1ymN6QYcoA7XB5IGAAASBQ"]
[Thu Jul 30 13:21:27.241881 2026] [security2:error] [pid 872418:tid 872591] [client 20.215.218.234:20782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/0byte.php"] [unique_id "amuWJ1ymN6QYcoA7XB5IGwAAACs"]
[Thu Jul 30 13:21:27.241995 2026] [security2:error] [pid 872418:tid 872591] [client 20.215.218.234:20782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/0byte.php"] [unique_id "amuWJ1ymN6QYcoA7XB5IGwAAACs"]
[Thu Jul 30 13:21:27.251998 2026] [security2:error] [pid 872418:tid 872613] [client 47.85.195.135:42476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWJlymN6QYcoA7XB5IBwAAAEE"]
[Thu Jul 30 13:21:27.252428 2026] [security2:error] [pid 872418:tid 872613] [client 47.85.195.135:42476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWJlymN6QYcoA7XB5IBwAAAEE"]
[Thu Jul 30 13:21:27.562298 2026] [security2:error] [pid 872418:tid 872583] [client 20.215.218.234:21757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index3.php"] [unique_id "amuWJ1ymN6QYcoA7XB5IHAAAACM"]
[Thu Jul 30 13:21:27.562396 2026] [security2:error] [pid 872418:tid 872583] [client 20.215.218.234:21757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index3.php"] [unique_id "amuWJ1ymN6QYcoA7XB5IHAAAACM"]
[Thu Jul 30 13:21:27.641502 2026] [autoindex:error] [pid 872418:tid 872576] [client 74.7.227.39:0] AH01276: Cannot serve directory /home2/kaxudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:21:27.874191 2026] [security2:error] [pid 872418:tid 872672] [client 20.215.218.234:63529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index2.php"] [unique_id "amuWJ1ymN6QYcoA7XB5IJAAAAHw"]
[Thu Jul 30 13:21:27.874325 2026] [security2:error] [pid 872418:tid 872672] [client 20.215.218.234:63529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index2.php"] [unique_id "amuWJ1ymN6QYcoA7XB5IJAAAAHw"]
[Thu Jul 30 13:21:28.126602 2026] [security2:error] [pid 872418:tid 872652] [client 47.85.195.135:42484] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWKFymN6QYcoA7XB5IJQAAAGg"]
[Thu Jul 30 13:21:28.184690 2026] [security2:error] [pid 872418:tid 872431] [remote 40.77.167.43:27386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/zh-tw/aboutf.php"] [unique_id "amuWKFymN6QYcoA7XB5IJgAAHQw"]
[Thu Jul 30 13:21:28.224961 2026] [security2:error] [pid 872418:tid 872627] [client 20.215.218.234:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index1.php"] [unique_id "amuWKFymN6QYcoA7XB5IKwAAAE8"]
[Thu Jul 30 13:21:28.225081 2026] [security2:error] [pid 872418:tid 872627] [client 20.215.218.234:64087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index1.php"] [unique_id "amuWKFymN6QYcoA7XB5IKwAAAE8"]
[Thu Jul 30 13:21:28.274820 2026] [security2:error] [pid 872418:tid 872652] [client 47.85.195.135:42484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWKFymN6QYcoA7XB5IJQAAAGg"]
[Thu Jul 30 13:21:28.414869 2026] [security2:error] [pid 872418:tid 872655] [client 64.31.3.126:10156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuWJFymN6QYcoA7XB5H4QAAAEM"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2271
[Thu Jul 30 13:21:28.562372 2026] [security2:error] [pid 872418:tid 872616] [client 20.215.218.234:60238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/303.php"] [unique_id "amuWKFymN6QYcoA7XB5IMAAAAEQ"]
[Thu Jul 30 13:21:28.562499 2026] [security2:error] [pid 872418:tid 872616] [client 20.215.218.234:60238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/303.php"] [unique_id "amuWKFymN6QYcoA7XB5IMAAAAEQ"]
[Thu Jul 30 13:21:29.028042 2026] [security2:error] [pid 872418:tid 872664] [client 74.7.241.192:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.safaratraveltours.com"] [uri "/index.php"] [unique_id "amuWJ1ymN6QYcoA7XB5IIwAAAHQ"]
[Thu Jul 30 13:21:29.028075 2026] [security2:error] [pid 872418:tid 872664] [client 74.7.241.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.safaratraveltours.com"] [uri "/index.php"] [unique_id "amuWJ1ymN6QYcoA7XB5IIwAAAHQ"]
[Thu Jul 30 13:21:29.028803 2026] [security2:error] [pid 872418:tid 872646] [client 74.7.241.192:35386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.safaratraveltours.com"] [uri "/robots.txt"] [unique_id "amuWJ1ymN6QYcoA7XB5IIQAAYjE"]
[Thu Jul 30 13:21:29.058161 2026] [security2:error] [pid 872418:tid 872618] [client 20.215.218.234:60285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/505.php"] [unique_id "amuWKVymN6QYcoA7XB5INgAAAEY"]
[Thu Jul 30 13:21:29.058263 2026] [security2:error] [pid 872418:tid 872618] [client 20.215.218.234:60285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/505.php"] [unique_id "amuWKVymN6QYcoA7XB5INgAAAEY"]
[Thu Jul 30 13:21:29.128173 2026] [security2:error] [pid 872418:tid 872630] [client 47.85.195.135:42490] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWKVymN6QYcoA7XB5INwAAAFI"]
[Thu Jul 30 13:21:29.162261 2026] [core:notice] [pid 872418:tid 872628] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:29.290966 2026] [security2:error] [pid 872418:tid 872630] [client 47.85.195.135:42490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWKVymN6QYcoA7XB5INwAAAFI"]
[Thu Jul 30 13:21:29.392082 2026] [security2:error] [pid 872418:tid 872562] [client 20.215.218.234:21748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/500.php"] [unique_id "amuWKVymN6QYcoA7XB5IOwAAAA4"]
[Thu Jul 30 13:21:29.392202 2026] [security2:error] [pid 872418:tid 872562] [client 20.215.218.234:21748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/500.php"] [unique_id "amuWKVymN6QYcoA7XB5IOwAAAA4"]
[Thu Jul 30 13:21:29.758596 2026] [security2:error] [pid 872418:tid 872576] [client 74.7.241.192:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuWKVymN6QYcoA7XB5IQAAAABw"], referer: https://www.safaratraveltours.com/robots.txt
[Thu Jul 30 13:21:29.759429 2026] [security2:error] [pid 872418:tid 872667] [client 74.7.241.192:35400] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/robots.txt"] [unique_id "amuWKVymN6QYcoA7XB5IPgAAdyI"], referer: https://www.safaratraveltours.com/robots.txt
[Thu Jul 30 13:21:29.807053 2026] [security2:error] [pid 872418:tid 872672] [client 20.215.218.234:60599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/77.php"] [unique_id "amuWKVymN6QYcoA7XB5IQgAAAHw"]
[Thu Jul 30 13:21:29.807156 2026] [security2:error] [pid 872418:tid 872672] [client 20.215.218.234:60599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/77.php"] [unique_id "amuWKVymN6QYcoA7XB5IQgAAAHw"]
[Thu Jul 30 13:21:30.129474 2026] [security2:error] [pid 872418:tid 872606] [client 47.85.195.135:42504] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWKlymN6QYcoA7XB5IRAAAADo"]
[Thu Jul 30 13:21:30.196998 2026] [security2:error] [pid 872418:tid 872626] [client 20.215.218.234:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/76.php"] [unique_id "amuWKlymN6QYcoA7XB5IRQAAAE4"]
[Thu Jul 30 13:21:30.197155 2026] [security2:error] [pid 872418:tid 872626] [client 20.215.218.234:63524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/76.php"] [unique_id "amuWKlymN6QYcoA7XB5IRQAAAE4"]
[Thu Jul 30 13:21:30.279643 2026] [security2:error] [pid 872418:tid 872606] [client 47.85.195.135:42504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWKlymN6QYcoA7XB5IRAAAADo"]
[Thu Jul 30 13:21:30.536096 2026] [security2:error] [pid 872418:tid 872655] [client 20.215.218.234:21726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/74.php"] [unique_id "amuWKlymN6QYcoA7XB5ISQAAAGs"]
[Thu Jul 30 13:21:30.536209 2026] [security2:error] [pid 872418:tid 872655] [client 20.215.218.234:21726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/74.php"] [unique_id "amuWKlymN6QYcoA7XB5ISQAAAGs"]
[Thu Jul 30 13:21:30.856654 2026] [security2:error] [pid 872418:tid 872554] [client 20.215.218.234:21721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-config.php"] [unique_id "amuWKlymN6QYcoA7XB5ISwAAAAY"]
[Thu Jul 30 13:21:30.856775 2026] [security2:error] [pid 872418:tid 872554] [client 20.215.218.234:21721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-config.php"] [unique_id "amuWKlymN6QYcoA7XB5ISwAAAAY"]
[Thu Jul 30 13:21:31.172061 2026] [security2:error] [pid 872418:tid 872550] [client 20.215.218.234:21229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/75.php"] [unique_id "amuWK1ymN6QYcoA7XB5ITAAAAAI"]
[Thu Jul 30 13:21:31.172185 2026] [security2:error] [pid 872418:tid 872550] [client 20.215.218.234:21229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/75.php"] [unique_id "amuWK1ymN6QYcoA7XB5ITAAAAAI"]
[Thu Jul 30 13:21:31.176931 2026] [security2:error] [pid 872418:tid 872601] [client 47.85.195.135:42512] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWK1ymN6QYcoA7XB5ITQAAADU"]
[Thu Jul 30 13:21:31.327476 2026] [security2:error] [pid 872418:tid 872601] [client 47.85.195.135:42512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "daralnaseemdxb.com"] [uri "/wp-comments-post.php"] [unique_id "amuWK1ymN6QYcoA7XB5ITQAAADU"]
[Thu Jul 30 13:21:31.533255 2026] [security2:error] [pid 872418:tid 872563] [client 20.215.218.234:60268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/71.php"] [unique_id "amuWK1ymN6QYcoA7XB5ITwAAAA8"]
[Thu Jul 30 13:21:31.533377 2026] [security2:error] [pid 872418:tid 872563] [client 20.215.218.234:60268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/71.php"] [unique_id "amuWK1ymN6QYcoA7XB5ITwAAAA8"]
[Thu Jul 30 13:21:31.931940 2026] [security2:error] [pid 872418:tid 872665] [client 20.215.218.234:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/72.php"] [unique_id "amuWK1ymN6QYcoA7XB5IUgAAAHU"]
[Thu Jul 30 13:21:31.932130 2026] [security2:error] [pid 872418:tid 872665] [client 20.215.218.234:64075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/72.php"] [unique_id "amuWK1ymN6QYcoA7XB5IUgAAAHU"]
[Thu Jul 30 13:21:32.298238 2026] [security2:error] [pid 872418:tid 872575] [client 20.215.218.234:9979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/70.php"] [unique_id "amuWLFymN6QYcoA7XB5IUwAAABs"]
[Thu Jul 30 13:21:32.298380 2026] [security2:error] [pid 872418:tid 872575] [client 20.215.218.234:9979] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/70.php"] [unique_id "amuWLFymN6QYcoA7XB5IUwAAABs"]
[Thu Jul 30 13:21:32.434170 2026] [security2:error] [pid 872418:tid 872427] [remote 72.167.132.114:55300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amuWLFymN6QYcoA7XB5IVQAAWgg"]
[Thu Jul 30 13:21:32.648297 2026] [security2:error] [pid 872418:tid 872647] [client 20.215.218.234:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/69.php"] [unique_id "amuWLFymN6QYcoA7XB5IVgAAAGM"]
[Thu Jul 30 13:21:32.648436 2026] [security2:error] [pid 872418:tid 872647] [client 20.215.218.234:63541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/69.php"] [unique_id "amuWLFymN6QYcoA7XB5IVgAAAGM"]
[Thu Jul 30 13:21:32.793160 2026] [security2:error] [pid 872418:tid 872653] [client 68.221.186.136:16948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/geju.php"] [unique_id "amuWLFymN6QYcoA7XB5IWwAAAGk"]
[Thu Jul 30 13:21:33.099585 2026] [security2:error] [pid 872418:tid 872666] [client 20.215.218.234:21209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/68.php"] [unique_id "amuWLVymN6QYcoA7XB5IXAAAAHY"]
[Thu Jul 30 13:21:33.099690 2026] [security2:error] [pid 872418:tid 872666] [client 20.215.218.234:21209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/68.php"] [unique_id "amuWLVymN6QYcoA7XB5IXAAAAHY"]
[Thu Jul 30 13:21:33.514877 2026] [security2:error] [pid 872418:tid 872628] [client 20.215.218.234:60243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/66.php"] [unique_id "amuWLVymN6QYcoA7XB5IXgAAAFA"]
[Thu Jul 30 13:21:33.515012 2026] [security2:error] [pid 872418:tid 872628] [client 20.215.218.234:60243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/66.php"] [unique_id "amuWLVymN6QYcoA7XB5IXgAAAFA"]
[Thu Jul 30 13:21:33.646713 2026] [security2:error] [pid 872418:tid 872624] [client 68.221.186.136:1764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuWLVymN6QYcoA7XB5IYAAAAEw"]
[Thu Jul 30 13:21:33.968727 2026] [security2:error] [pid 872418:tid 872552] [client 20.215.218.234:60261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/67.php"] [unique_id "amuWLVymN6QYcoA7XB5IZQAAAAQ"]
[Thu Jul 30 13:21:33.968855 2026] [security2:error] [pid 872418:tid 872552] [client 20.215.218.234:60261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/67.php"] [unique_id "amuWLVymN6QYcoA7XB5IZQAAAAQ"]
[Thu Jul 30 13:21:34.303347 2026] [security2:error] [pid 872418:tid 872623] [client 20.215.218.234:21214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/65.php"] [unique_id "amuWLlymN6QYcoA7XB5IaAAAAEs"]
[Thu Jul 30 13:21:34.303483 2026] [security2:error] [pid 872418:tid 872623] [client 20.215.218.234:21214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/65.php"] [unique_id "amuWLlymN6QYcoA7XB5IaAAAAEs"]
[Thu Jul 30 13:21:34.656213 2026] [security2:error] [pid 872418:tid 872579] [client 20.215.218.234:63533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/64.php"] [unique_id "amuWLlymN6QYcoA7XB5IagAAAB8"]
[Thu Jul 30 13:21:34.656347 2026] [security2:error] [pid 872418:tid 872579] [client 20.215.218.234:63533] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/64.php"] [unique_id "amuWLlymN6QYcoA7XB5IagAAAB8"]
[Thu Jul 30 13:21:35.052960 2026] [security2:error] [pid 872418:tid 872642] [client 20.215.218.234:20754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/63.php"] [unique_id "amuWL1ymN6QYcoA7XB5IbwAAAF4"]
[Thu Jul 30 13:21:35.053098 2026] [security2:error] [pid 872418:tid 872642] [client 20.215.218.234:20754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/63.php"] [unique_id "amuWL1ymN6QYcoA7XB5IbwAAAF4"]
[Thu Jul 30 13:21:35.179529 2026] [security2:error] [pid 872418:tid 872600] [client 68.221.186.136:1283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp.php"] [unique_id "amuWL1ymN6QYcoA7XB5IcwAAADQ"]
[Thu Jul 30 13:21:35.390754 2026] [security2:error] [pid 872418:tid 872617] [client 20.215.218.234:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/62.php"] [unique_id "amuWL1ymN6QYcoA7XB5IdQAAAEU"]
[Thu Jul 30 13:21:35.390857 2026] [security2:error] [pid 872418:tid 872617] [client 20.215.218.234:60275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/62.php"] [unique_id "amuWL1ymN6QYcoA7XB5IdQAAAEU"]
[Thu Jul 30 13:21:35.722588 2026] [security2:error] [pid 872418:tid 872550] [client 20.215.218.234:21720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/61.php"] [unique_id "amuWL1ymN6QYcoA7XB5IrQAAAAI"]
[Thu Jul 30 13:21:35.722709 2026] [security2:error] [pid 872418:tid 872550] [client 20.215.218.234:21720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/61.php"] [unique_id "amuWL1ymN6QYcoA7XB5IrQAAAAI"]
[Thu Jul 30 13:21:36.063827 2026] [security2:error] [pid 872418:tid 872649] [client 20.215.218.234:54764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/60.php"] [unique_id "amuWMFymN6QYcoA7XB5IzAAAAGU"]
[Thu Jul 30 13:21:36.063937 2026] [security2:error] [pid 872418:tid 872649] [client 20.215.218.234:54764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/60.php"] [unique_id "amuWMFymN6QYcoA7XB5IzAAAAGU"]
[Thu Jul 30 13:21:36.345953 2026] [security2:error] [pid 872418:tid 872673] [client 113.44.97.54:55964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuWLlymN6QYcoA7XB5IZwAAfUo"]
[Thu Jul 30 13:21:36.462555 2026] [security2:error] [pid 872418:tid 872595] [client 20.215.218.234:20787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/58.php"] [unique_id "amuWMFymN6QYcoA7XB5I7gAAAC8"]
[Thu Jul 30 13:21:36.462669 2026] [security2:error] [pid 872418:tid 872595] [client 20.215.218.234:20787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/58.php"] [unique_id "amuWMFymN6QYcoA7XB5I7gAAAC8"]
[Thu Jul 30 13:21:36.830890 2026] [core:notice] [pid 872418:tid 872431] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:21:36.854324 2026] [security2:error] [pid 872418:tid 872578] [client 20.215.218.234:21749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/59.php"] [unique_id "amuWMFymN6QYcoA7XB5I8QAAAB4"]
[Thu Jul 30 13:21:36.854421 2026] [security2:error] [pid 872418:tid 872578] [client 20.215.218.234:21749] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/59.php"] [unique_id "amuWMFymN6QYcoA7XB5I8QAAAB4"]
[Thu Jul 30 13:21:36.957783 2026] [security2:error] [pid 872418:tid 872596] [client 179.64.21.229:57554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWMFymN6QYcoA7XB5I9AAAADA"]
[Thu Jul 30 13:21:36.967953 2026] [security2:error] [pid 872418:tid 872596] [client 179.64.21.229:57554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWMFymN6QYcoA7XB5I9AAAADA"]
[Thu Jul 30 13:21:36.968532 2026] [security2:error] [pid 872418:tid 872448] [remote 74.7.243.224:36568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/mission/js/uploads/content/uploads/partners/uploads/content/js/img/fonts/css/img/aprochef.php"] [unique_id "amuWMFymN6QYcoA7XB5I7wAARh0"], referer: https://aded-rdc.org/mission/js/uploads/content/uploads/partners/uploads/content/js/img/fonts/css/img/humanitariaf.html
[Thu Jul 30 13:21:37.202367 2026] [security2:error] [pid 872418:tid 872631] [client 20.215.218.234:20788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/57.php/56.php"] [unique_id "amuWMVymN6QYcoA7XB5I-AAAAFM"]
[Thu Jul 30 13:21:37.202529 2026] [security2:error] [pid 872418:tid 872631] [client 20.215.218.234:20788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/57.php/56.php"] [unique_id "amuWMVymN6QYcoA7XB5I-AAAAFM"]
[Thu Jul 30 13:21:37.544938 2026] [security2:error] [pid 872418:tid 872623] [client 20.215.218.234:63517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/55.php"] [unique_id "amuWMVymN6QYcoA7XB5I-gAAAEs"]
[Thu Jul 30 13:21:37.545066 2026] [security2:error] [pid 872418:tid 872623] [client 20.215.218.234:63517] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/55.php"] [unique_id "amuWMVymN6QYcoA7XB5I-gAAAEs"]
[Thu Jul 30 13:21:37.666663 2026] [security2:error] [pid 872418:tid 872559] [client 68.221.186.136:15270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/aaa.php"] [unique_id "amuWMVymN6QYcoA7XB5I_AAAAAs"]
[Thu Jul 30 13:21:37.872795 2026] [security2:error] [pid 872418:tid 872640] [client 5.30.96.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuWMVymN6QYcoA7XB5I-QAAXDU"], referer: https://flixon.net/?post_type=any&s=Desire&search=&search_filter=post_types&_wpnonce=ab8659ecbd
[Thu Jul 30 13:21:37.923007 2026] [security2:error] [pid 872418:tid 872562] [client 20.215.218.234:21728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/54.php"] [unique_id "amuWMVymN6QYcoA7XB5I_gAAAA4"]
[Thu Jul 30 13:21:37.923111 2026] [security2:error] [pid 872418:tid 872562] [client 20.215.218.234:21728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/54.php"] [unique_id "amuWMVymN6QYcoA7XB5I_gAAAA4"]
[Thu Jul 30 13:21:38.325559 2026] [security2:error] [pid 872418:tid 872589] [client 20.215.218.234:9926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/53.php"] [unique_id "amuWMlymN6QYcoA7XB5JBQAAACk"]
[Thu Jul 30 13:21:38.325693 2026] [security2:error] [pid 872418:tid 872589] [client 20.215.218.234:9926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/53.php"] [unique_id "amuWMlymN6QYcoA7XB5JBQAAACk"]
[Thu Jul 30 13:21:38.666520 2026] [security2:error] [pid 872418:tid 872598] [client 20.215.218.234:62987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/52.php"] [unique_id "amuWMlymN6QYcoA7XB5JFwAAADI"]
[Thu Jul 30 13:21:38.666624 2026] [security2:error] [pid 872418:tid 872598] [client 20.215.218.234:62987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/52.php"] [unique_id "amuWMlymN6QYcoA7XB5JFwAAADI"]
[Thu Jul 30 13:21:39.024870 2026] [security2:error] [pid 872418:tid 872617] [client 20.215.218.234:62983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/51.php"] [unique_id "amuWM1ymN6QYcoA7XB5JGAAAAEU"]
[Thu Jul 30 13:21:39.025006 2026] [security2:error] [pid 872418:tid 872617] [client 20.215.218.234:62983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/51.php"] [unique_id "amuWM1ymN6QYcoA7XB5JGAAAAEU"]
[Thu Jul 30 13:21:39.034963 2026] [security2:error] [pid 872418:tid 872669] [client 68.221.186.136:17072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/hoot.php"] [unique_id "amuWM1ymN6QYcoA7XB5JGQAAAHk"]
[Thu Jul 30 13:21:39.403434 2026] [security2:error] [pid 872418:tid 872609] [client 20.215.218.234:21732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/50.php"] [unique_id "amuWM1ymN6QYcoA7XB5JIgAAAD0"]
[Thu Jul 30 13:21:39.403569 2026] [security2:error] [pid 872418:tid 872609] [client 20.215.218.234:21732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/50.php"] [unique_id "amuWM1ymN6QYcoA7XB5JIgAAAD0"]
[Thu Jul 30 13:21:39.788007 2026] [security2:error] [pid 872418:tid 872551] [client 20.215.218.234:21210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/49.php"] [unique_id "amuWM1ymN6QYcoA7XB5JJAAAAAM"]
[Thu Jul 30 13:21:39.788137 2026] [security2:error] [pid 872418:tid 872551] [client 20.215.218.234:21210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/49.php"] [unique_id "amuWM1ymN6QYcoA7XB5JJAAAAAM"]
[Thu Jul 30 13:21:40.133854 2026] [security2:error] [pid 872418:tid 872619] [client 20.215.218.234:9944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/48.php"] [unique_id "amuWNFymN6QYcoA7XB5JMwAAAEc"]
[Thu Jul 30 13:21:40.133971 2026] [security2:error] [pid 872418:tid 872619] [client 20.215.218.234:9944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/48.php"] [unique_id "amuWNFymN6QYcoA7XB5JMwAAAEc"]
[Thu Jul 30 13:21:40.638547 2026] [security2:error] [pid 872418:tid 872569] [client 20.215.218.234:64084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/47.php"] [unique_id "amuWNFymN6QYcoA7XB5JNAAAABU"]
[Thu Jul 30 13:21:40.638717 2026] [security2:error] [pid 872418:tid 872569] [client 20.215.218.234:64084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/47.php"] [unique_id "amuWNFymN6QYcoA7XB5JNAAAABU"]
[Thu Jul 30 13:21:40.913444 2026] [security2:error] [pid 872418:tid 872661] [client 68.221.186.136:1790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/about.php"] [unique_id "amuWNFymN6QYcoA7XB5JOAAAAHE"]
[Thu Jul 30 13:21:41.048758 2026] [security2:error] [pid 872418:tid 872622] [client 20.215.218.234:20737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/46.php"] [unique_id "amuWNVymN6QYcoA7XB5JOQAAAEo"]
[Thu Jul 30 13:21:41.048863 2026] [security2:error] [pid 872418:tid 872622] [client 20.215.218.234:20737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/46.php"] [unique_id "amuWNVymN6QYcoA7XB5JOQAAAEo"]
[Thu Jul 30 13:21:41.365034 2026] [security2:error] [pid 872418:tid 872594] [client 20.215.218.234:21742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/44.php"] [unique_id "amuWNVymN6QYcoA7XB5JOwAAAC4"]
[Thu Jul 30 13:21:41.365178 2026] [security2:error] [pid 872418:tid 872594] [client 20.215.218.234:21742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/44.php"] [unique_id "amuWNVymN6QYcoA7XB5JOwAAAC4"]
[Thu Jul 30 13:21:41.443613 2026] [security2:error] [pid 872418:tid 872498] [remote 74.7.227.39:41988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuWNVymN6QYcoA7XB5JOgAAN08"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/
[Thu Jul 30 13:21:41.457036 2026] [security2:error] [pid 872418:tid 872557] [client 68.221.186.136:1314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/admin.php"] [unique_id "amuWNVymN6QYcoA7XB5JPAAAAAk"]
[Thu Jul 30 13:21:41.694648 2026] [security2:error] [pid 872418:tid 872574] [client 20.215.218.234:21719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/43.php"] [unique_id "amuWNVymN6QYcoA7XB5JPQAAABo"]
[Thu Jul 30 13:21:41.694791 2026] [security2:error] [pid 872418:tid 872574] [client 20.215.218.234:21719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/43.php"] [unique_id "amuWNVymN6QYcoA7XB5JPQAAABo"]
[Thu Jul 30 13:21:42.072513 2026] [security2:error] [pid 872418:tid 872556] [client 20.215.218.234:9921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/42.php"] [unique_id "amuWNlymN6QYcoA7XB5JPwAAAAg"]
[Thu Jul 30 13:21:42.072628 2026] [security2:error] [pid 872418:tid 872556] [client 20.215.218.234:9921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/42.php"] [unique_id "amuWNlymN6QYcoA7XB5JPwAAAAg"]
[Thu Jul 30 13:21:42.247308 2026] [security2:error] [pid 872418:tid 872607] [client 68.221.186.136:9447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuWNlymN6QYcoA7XB5JQAAAADs"]
[Thu Jul 30 13:21:42.412738 2026] [security2:error] [pid 872418:tid 872599] [client 20.215.218.234:9978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/41.php"] [unique_id "amuWNlymN6QYcoA7XB5JRgAAADM"]
[Thu Jul 30 13:21:42.412859 2026] [security2:error] [pid 872418:tid 872599] [client 20.215.218.234:9978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/41.php"] [unique_id "amuWNlymN6QYcoA7XB5JRgAAADM"]
[Thu Jul 30 13:21:42.560258 2026] [core:error] [pid 872418:tid 872578] [client 74.7.175.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:21:42.560282 2026] [core:error] [pid 872418:tid 872578] [client 74.7.175.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:21:42.560439 2026] [security2:error] [pid 872418:tid 872578] [client 74.7.175.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.agr8story.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuWNlymN6QYcoA7XB5JSQAAAB4"]
[Thu Jul 30 13:21:42.561047 2026] [security2:error] [pid 872418:tid 872572] [client 74.7.175.184:39398] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.agr8story.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuWNlymN6QYcoA7XB5JRwAAGD8"]
[Thu Jul 30 13:21:42.860973 2026] [security2:error] [pid 872418:tid 872624] [client 20.215.218.234:21240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/40.php"] [unique_id "amuWNlymN6QYcoA7XB5JSwAAAEw"]
[Thu Jul 30 13:21:42.861106 2026] [security2:error] [pid 872418:tid 872624] [client 20.215.218.234:21240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/40.php"] [unique_id "amuWNlymN6QYcoA7XB5JSwAAAEw"]
[Thu Jul 30 13:21:43.134965 2026] [security2:error] [pid 872418:tid 872637] [client 68.221.186.136:8693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuWN1ymN6QYcoA7XB5JTAAAAFk"]
[Thu Jul 30 13:21:43.192859 2026] [security2:error] [pid 872418:tid 872621] [client 20.215.218.234:21716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/39.php"] [unique_id "amuWN1ymN6QYcoA7XB5JTQAAAEk"]
[Thu Jul 30 13:21:43.192990 2026] [security2:error] [pid 872418:tid 872621] [client 20.215.218.234:21716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/39.php"] [unique_id "amuWN1ymN6QYcoA7XB5JTQAAAEk"]
[Thu Jul 30 13:21:43.488622 2026] [security2:error] [pid 872418:tid 872458] [remote 74.7.243.224:53270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/nos-rapports/uploads/partners/img/uploads/content/js/img/css/uploads/content/misionf.php"] [unique_id "amuWN1ymN6QYcoA7XB5JTwAASyc"], referer: https://aded-rdc.org/nos-rapports/uploads/partners/img/uploads/content/js/img/css/uploads/content/vloloteerf.html
[Thu Jul 30 13:21:43.578695 2026] [security2:error] [pid 872418:tid 872568] [client 20.215.218.234:63507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/38.php"] [unique_id "amuWN1ymN6QYcoA7XB5JUAAAABQ"]
[Thu Jul 30 13:21:43.578805 2026] [security2:error] [pid 872418:tid 872568] [client 20.215.218.234:63507] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/38.php"] [unique_id "amuWN1ymN6QYcoA7XB5JUAAAABQ"]
[Thu Jul 30 13:21:43.820470 2026] [security2:error] [pid 872418:tid 872571] [client 68.221.186.136:8646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuWN1ymN6QYcoA7XB5JUQAAABc"]
[Thu Jul 30 13:21:43.893000 2026] [security2:error] [pid 872418:tid 872590] [client 20.215.218.234:21712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/37.php"] [unique_id "amuWN1ymN6QYcoA7XB5JUwAAACo"]
[Thu Jul 30 13:21:43.893114 2026] [security2:error] [pid 872418:tid 872590] [client 20.215.218.234:21712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/37.php"] [unique_id "amuWN1ymN6QYcoA7XB5JUwAAACo"]
[Thu Jul 30 13:21:44.324695 2026] [security2:error] [pid 872418:tid 872672] [client 20.215.218.234:20790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/36.php"] [unique_id "amuWOFymN6QYcoA7XB5JVwAAAHw"]
[Thu Jul 30 13:21:44.324814 2026] [security2:error] [pid 872418:tid 872672] [client 20.215.218.234:20790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/36.php"] [unique_id "amuWOFymN6QYcoA7XB5JVwAAAHw"]
[Thu Jul 30 13:21:44.629173 2026] [security2:error] [pid 872418:tid 872655] [client 20.215.218.234:9946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/35.php"] [unique_id "amuWOFymN6QYcoA7XB5JXgAAAGs"]
[Thu Jul 30 13:21:44.629280 2026] [security2:error] [pid 872418:tid 872655] [client 20.215.218.234:9946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/35.php"] [unique_id "amuWOFymN6QYcoA7XB5JXgAAAGs"]
[Thu Jul 30 13:21:44.840813 2026] [security2:error] [pid 872418:tid 872604] [client 68.221.186.136:41829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuWOFymN6QYcoA7XB5JXwAAADg"]
[Thu Jul 30 13:21:44.943481 2026] [security2:error] [pid 872418:tid 872657] [client 20.215.218.234:21703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/34.php"] [unique_id "amuWOFymN6QYcoA7XB5JYwAAAG0"]
[Thu Jul 30 13:21:44.943618 2026] [security2:error] [pid 872418:tid 872657] [client 20.215.218.234:21703] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/34.php"] [unique_id "amuWOFymN6QYcoA7XB5JYwAAAG0"]
[Thu Jul 30 13:21:45.277639 2026] [security2:error] [pid 872418:tid 872635] [client 20.215.218.234:20791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/33.php"] [unique_id "amuWOVymN6QYcoA7XB5JZQAAAFc"]
[Thu Jul 30 13:21:45.277758 2026] [security2:error] [pid 872418:tid 872635] [client 20.215.218.234:20791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/33.php"] [unique_id "amuWOVymN6QYcoA7XB5JZQAAAFc"]
[Thu Jul 30 13:21:45.612516 2026] [security2:error] [pid 872418:tid 872661] [client 82.102.27.195:46928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuWOVymN6QYcoA7XB5JaAAAAHE"]
[Thu Jul 30 13:21:45.612636 2026] [security2:error] [pid 872418:tid 872661] [client 82.102.27.195:46928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuWOVymN6QYcoA7XB5JaAAAAHE"]
[Thu Jul 30 13:21:45.718443 2026] [security2:error] [pid 872418:tid 872651] [client 20.215.218.234:21232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/25.php"] [unique_id "amuWOVymN6QYcoA7XB5JaQAAAGc"]
[Thu Jul 30 13:21:45.718572 2026] [security2:error] [pid 872418:tid 872651] [client 20.215.218.234:21232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/25.php"] [unique_id "amuWOVymN6QYcoA7XB5JaQAAAGc"]
[Thu Jul 30 13:21:46.166074 2026] [security2:error] [pid 872418:tid 872647] [client 20.215.218.234:21709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/24.php"] [unique_id "amuWOlymN6QYcoA7XB5JbQAAAGM"]
[Thu Jul 30 13:21:46.166192 2026] [security2:error] [pid 872418:tid 872647] [client 20.215.218.234:21709] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/24.php"] [unique_id "amuWOlymN6QYcoA7XB5JbQAAAGM"]
[Thu Jul 30 13:21:46.477197 2026] [security2:error] [pid 872418:tid 872619] [client 68.221.186.136:15288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuWOlymN6QYcoA7XB5JdQAAAEc"]
[Thu Jul 30 13:21:46.749079 2026] [security2:error] [pid 872418:tid 872607] [client 20.215.218.234:63535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/15.php"] [unique_id "amuWOlymN6QYcoA7XB5JdgAAADs"]
[Thu Jul 30 13:21:46.749170 2026] [security2:error] [pid 872418:tid 872607] [client 20.215.218.234:63535] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/15.php"] [unique_id "amuWOlymN6QYcoA7XB5JdgAAADs"]
[Thu Jul 30 13:21:47.243264 2026] [security2:error] [pid 872418:tid 872591] [client 20.215.218.234:63500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/123456.php"] [unique_id "amuWO1ymN6QYcoA7XB5JfAAAACs"]
[Thu Jul 30 13:21:47.243383 2026] [security2:error] [pid 872418:tid 872591] [client 20.215.218.234:63500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/123456.php"] [unique_id "amuWO1ymN6QYcoA7XB5JfAAAACs"]
[Thu Jul 30 13:21:47.306114 2026] [security2:error] [pid 872418:tid 872602] [client 179.64.21.229:42417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWO1ymN6QYcoA7XB5JfQAAADY"]
[Thu Jul 30 13:21:47.306276 2026] [security2:error] [pid 872418:tid 872602] [client 179.64.21.229:42417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWO1ymN6QYcoA7XB5JfQAAADY"]
[Thu Jul 30 13:21:47.566431 2026] [security2:error] [pid 872418:tid 872561] [client 20.215.218.234:63544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/12345.php"] [unique_id "amuWO1ymN6QYcoA7XB5JfgAAAA0"]
[Thu Jul 30 13:21:47.566547 2026] [security2:error] [pid 872418:tid 872561] [client 20.215.218.234:63544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/12345.php"] [unique_id "amuWO1ymN6QYcoA7XB5JfgAAAA0"]
[Thu Jul 30 13:21:47.876727 2026] [security2:error] [pid 872418:tid 872580] [client 20.215.218.234:64081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/1234.php"] [unique_id "amuWO1ymN6QYcoA7XB5JggAAACA"]
[Thu Jul 30 13:21:47.876871 2026] [security2:error] [pid 872418:tid 872580] [client 20.215.218.234:64081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/1234.php"] [unique_id "amuWO1ymN6QYcoA7XB5JggAAACA"]
[Thu Jul 30 13:21:48.225258 2026] [security2:error] [pid 872418:tid 872560] [client 20.215.218.234:63525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/10.php"] [unique_id "amuWPFymN6QYcoA7XB5JhAAAAAw"]
[Thu Jul 30 13:21:48.225371 2026] [security2:error] [pid 872418:tid 872560] [client 20.215.218.234:63525] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/10.php"] [unique_id "amuWPFymN6QYcoA7XB5JhAAAAAw"]
[Thu Jul 30 13:21:48.571585 2026] [security2:error] [pid 872418:tid 872590] [client 20.215.218.234:9935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/9.php"] [unique_id "amuWPFymN6QYcoA7XB5JhgAAACo"]
[Thu Jul 30 13:21:48.571705 2026] [security2:error] [pid 872418:tid 872590] [client 20.215.218.234:9935] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/9.php"] [unique_id "amuWPFymN6QYcoA7XB5JhgAAACo"]
[Thu Jul 30 13:21:48.957372 2026] [security2:error] [pid 872418:tid 872672] [client 20.215.218.234:9981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/8.php"] [unique_id "amuWPFymN6QYcoA7XB5JjAAAAHw"]
[Thu Jul 30 13:21:48.957504 2026] [security2:error] [pid 872418:tid 872672] [client 20.215.218.234:9981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/8.php"] [unique_id "amuWPFymN6QYcoA7XB5JjAAAAHw"]
[Thu Jul 30 13:21:49.260589 2026] [security2:error] [pid 872418:tid 872658] [client 20.215.218.234:21053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/7.php"] [unique_id "amuWPVymN6QYcoA7XB5JkAAAAG4"]
[Thu Jul 30 13:21:49.260695 2026] [security2:error] [pid 872418:tid 872658] [client 20.215.218.234:21053] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/7.php"] [unique_id "amuWPVymN6QYcoA7XB5JkAAAAG4"]
[Thu Jul 30 13:21:49.601506 2026] [security2:error] [pid 872418:tid 872654] [client 20.215.218.234:9951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/6.php"] [unique_id "amuWPVymN6QYcoA7XB5JmAAAAGo"]
[Thu Jul 30 13:21:49.601602 2026] [security2:error] [pid 872418:tid 872654] [client 20.215.218.234:9951] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/6.php"] [unique_id "amuWPVymN6QYcoA7XB5JmAAAAGo"]
[Thu Jul 30 13:21:50.136052 2026] [security2:error] [pid 872418:tid 872548] [client 20.215.218.234:20797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/5.php"] [unique_id "amuWPlymN6QYcoA7XB5JoAAAAAA"]
[Thu Jul 30 13:21:50.136159 2026] [security2:error] [pid 872418:tid 872548] [client 20.215.218.234:20797] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/5.php"] [unique_id "amuWPlymN6QYcoA7XB5JoAAAAAA"]
[Thu Jul 30 13:21:50.489091 2026] [security2:error] [pid 872418:tid 872569] [client 20.215.218.234:60258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/4.php"] [unique_id "amuWPlymN6QYcoA7XB5JpwAAABU"]
[Thu Jul 30 13:21:50.489234 2026] [security2:error] [pid 872418:tid 872569] [client 20.215.218.234:60258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/4.php"] [unique_id "amuWPlymN6QYcoA7XB5JpwAAABU"]
[Thu Jul 30 13:21:50.743721 2026] [security2:error] [pid 872418:tid 872515] [remote 74.7.227.39:41988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuWPlymN6QYcoA7XB5JrQAAPmA"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/wpforms-lite/includes/fields
[Thu Jul 30 13:21:50.811168 2026] [security2:error] [pid 872418:tid 872619] [client 20.215.218.234:9968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/3.php"] [unique_id "amuWPlymN6QYcoA7XB5JrgAAAEc"]
[Thu Jul 30 13:21:50.811280 2026] [security2:error] [pid 872418:tid 872619] [client 20.215.218.234:9968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/3.php"] [unique_id "amuWPlymN6QYcoA7XB5JrgAAAEc"]
[Thu Jul 30 13:21:51.140806 2026] [security2:error] [pid 872418:tid 872595] [client 20.215.218.234:21190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/2.php"] [unique_id "amuWP1ymN6QYcoA7XB5JtAAAAC8"]
[Thu Jul 30 13:21:51.140920 2026] [security2:error] [pid 872418:tid 872595] [client 20.215.218.234:21190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/2.php"] [unique_id "amuWP1ymN6QYcoA7XB5JtAAAAC8"]
[Thu Jul 30 13:21:51.460913 2026] [security2:error] [pid 872418:tid 872628] [client 20.215.218.234:63512] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/1.php"] [unique_id "amuWP1ymN6QYcoA7XB5JvgAAAFA"]
[Thu Jul 30 13:21:51.461022 2026] [security2:error] [pid 872418:tid 872628] [client 20.215.218.234:63512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/1.php"] [unique_id "amuWP1ymN6QYcoA7XB5JvgAAAFA"]
[Thu Jul 30 13:21:51.461111 2026] [security2:error] [pid 872418:tid 872628] [client 20.215.218.234:63512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/1.php"] [unique_id "amuWP1ymN6QYcoA7XB5JvgAAAFA"]
[Thu Jul 30 13:21:51.872803 2026] [security2:error] [pid 872418:tid 872573] [client 20.215.218.234:9958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/0.php"] [unique_id "amuWP1ymN6QYcoA7XB5JxgAAABk"]
[Thu Jul 30 13:21:51.872922 2026] [security2:error] [pid 872418:tid 872573] [client 20.215.218.234:9958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/0.php"] [unique_id "amuWP1ymN6QYcoA7XB5JxgAAABk"]
[Thu Jul 30 13:21:52.238680 2026] [security2:error] [pid 872418:tid 872571] [client 20.215.218.234:21725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/z.php"] [unique_id "amuWQFymN6QYcoA7XB5JzAAAABc"]
[Thu Jul 30 13:21:52.238786 2026] [security2:error] [pid 872418:tid 872571] [client 20.215.218.234:21725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/z.php"] [unique_id "amuWQFymN6QYcoA7XB5JzAAAABc"]
[Thu Jul 30 13:21:52.534223 2026] [security2:error] [pid 872418:tid 872645] [client 20.215.218.234:21745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/y.php"] [unique_id "amuWQFymN6QYcoA7XB5J0AAAAGE"]
[Thu Jul 30 13:21:52.534345 2026] [security2:error] [pid 872418:tid 872645] [client 20.215.218.234:21745] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/y.php"] [unique_id "amuWQFymN6QYcoA7XB5J0AAAAGE"]
[Thu Jul 30 13:21:52.837023 2026] [security2:error] [pid 872418:tid 872616] [client 20.215.218.234:9925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/x.php"] [unique_id "amuWQFymN6QYcoA7XB5J3QAAAEQ"]
[Thu Jul 30 13:21:52.837170 2026] [security2:error] [pid 872418:tid 872616] [client 20.215.218.234:9925] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/x.php"] [unique_id "amuWQFymN6QYcoA7XB5J3QAAAEQ"]
[Thu Jul 30 13:21:53.173381 2026] [security2:error] [pid 872418:tid 872654] [client 20.215.218.234:21022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/w.php"] [unique_id "amuWQVymN6QYcoA7XB5J5AAAAGo"]
[Thu Jul 30 13:21:53.173493 2026] [security2:error] [pid 872418:tid 872654] [client 20.215.218.234:21022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/w.php"] [unique_id "amuWQVymN6QYcoA7XB5J5AAAAGo"]
[Thu Jul 30 13:21:53.479646 2026] [security2:error] [pid 872418:tid 872567] [client 134.19.179.147:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuWQVymN6QYcoA7XB5J7wAAABM"]
[Thu Jul 30 13:21:53.479793 2026] [security2:error] [pid 872418:tid 872567] [client 134.19.179.147:52156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuWQVymN6QYcoA7XB5J7wAAABM"]
[Thu Jul 30 13:21:53.582598 2026] [security2:error] [pid 872418:tid 872575] [client 20.215.218.234:64088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/v.php"] [unique_id "amuWQVymN6QYcoA7XB5J8gAAABs"]
[Thu Jul 30 13:21:53.582707 2026] [security2:error] [pid 872418:tid 872575] [client 20.215.218.234:64088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/v.php"] [unique_id "amuWQVymN6QYcoA7XB5J8gAAABs"]
[Thu Jul 30 13:21:53.583301 2026] [security2:error] [pid 872418:tid 872589] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWQFymN6QYcoA7XB5J2wAAKX0"]
[Thu Jul 30 13:21:53.790522 2026] [proxy:error] [pid 872418:tid 872659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:53.790613 2026] [proxy_http:error] [pid 872418:tid 872659] [client 52.202.41.153:50495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:53.791099 2026] [proxy:error] [pid 872418:tid 872572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:53.791165 2026] [proxy_http:error] [pid 872418:tid 872572] [client 54.87.222.253:25243] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:53.791465 2026] [proxy:error] [pid 872418:tid 872659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:53.791523 2026] [proxy_http:error] [pid 872418:tid 872659] [client 52.202.41.153:50495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:53.791995 2026] [proxy:error] [pid 872418:tid 872572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:53.792056 2026] [proxy_http:error] [pid 872418:tid 872572] [client 54.87.222.253:25243] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:54.038039 2026] [security2:error] [pid 872418:tid 872669] [client 20.215.218.234:21188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/u.php"] [unique_id "amuWQlymN6QYcoA7XB5KJwAAAHk"]
[Thu Jul 30 13:21:54.038169 2026] [security2:error] [pid 872418:tid 872669] [client 20.215.218.234:21188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/u.php"] [unique_id "amuWQlymN6QYcoA7XB5KJwAAAHk"]
[Thu Jul 30 13:21:54.365681 2026] [security2:error] [pid 872418:tid 872657] [client 20.215.218.234:60271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/s.php"] [unique_id "amuWQlymN6QYcoA7XB5KKQAAAG0"]
[Thu Jul 30 13:21:54.365806 2026] [security2:error] [pid 872418:tid 872657] [client 20.215.218.234:60271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/s.php"] [unique_id "amuWQlymN6QYcoA7XB5KKQAAAG0"]
[Thu Jul 30 13:21:54.719404 2026] [security2:error] [pid 872418:tid 872569] [client 20.215.218.234:21245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/t.php"] [unique_id "amuWQlymN6QYcoA7XB5KPQAAABU"]
[Thu Jul 30 13:21:54.719504 2026] [security2:error] [pid 872418:tid 872569] [client 20.215.218.234:21245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/t.php"] [unique_id "amuWQlymN6QYcoA7XB5KPQAAABU"]
[Thu Jul 30 13:21:54.900893 2026] [security2:error] [pid 872418:tid 872606] [client 68.221.186.136:8664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuWQlymN6QYcoA7XB5KSQAAADo"]
[Thu Jul 30 13:21:55.198066 2026] [security2:error] [pid 872418:tid 872646] [client 20.215.218.234:60240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/r.php"] [unique_id "amuWQ1ymN6QYcoA7XB5KSwAAAGI"]
[Thu Jul 30 13:21:55.198186 2026] [security2:error] [pid 872418:tid 872646] [client 20.215.218.234:60240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/r.php"] [unique_id "amuWQ1ymN6QYcoA7XB5KSwAAAGI"]
[Thu Jul 30 13:21:55.500899 2026] [security2:error] [pid 872418:tid 872630] [client 20.215.218.234:21758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/q.php"] [unique_id "amuWQ1ymN6QYcoA7XB5KTgAAAFI"]
[Thu Jul 30 13:21:55.501020 2026] [security2:error] [pid 872418:tid 872630] [client 20.215.218.234:21758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/q.php"] [unique_id "amuWQ1ymN6QYcoA7XB5KTgAAAFI"]
[Thu Jul 30 13:21:55.902733 2026] [security2:error] [pid 872418:tid 872591] [client 20.215.218.234:9965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/p.php"] [unique_id "amuWQ1ymN6QYcoA7XB5KUgAAACs"]
[Thu Jul 30 13:21:55.902852 2026] [security2:error] [pid 872418:tid 872591] [client 20.215.218.234:9965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/p.php"] [unique_id "amuWQ1ymN6QYcoA7XB5KUgAAACs"]
[Thu Jul 30 13:21:56.088849 2026] [security2:error] [pid 872418:tid 872668] [client 68.221.186.136:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuWRFymN6QYcoA7XB5KWQAAAHg"]
[Thu Jul 30 13:21:56.278028 2026] [security2:error] [pid 872418:tid 872643] [client 20.215.218.234:63513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/n.php"] [unique_id "amuWRFymN6QYcoA7XB5KWgAAAF8"]
[Thu Jul 30 13:21:56.278137 2026] [security2:error] [pid 872418:tid 872643] [client 20.215.218.234:63513] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/n.php"] [unique_id "amuWRFymN6QYcoA7XB5KWgAAAF8"]
[Thu Jul 30 13:21:56.349711 2026] [autoindex:error] [pid 872418:tid 872672] [client 85.204.70.94:0] AH01276: Cannot serve directory /home2/mbmudite/ok.otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:21:56.601257 2026] [security2:error] [pid 872418:tid 872655] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuWRFymN6QYcoA7XB5KYAAAAGs"]
[Thu Jul 30 13:21:56.630510 2026] [security2:error] [pid 872418:tid 872634] [client 20.215.218.234:54761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/o.php"] [unique_id "amuWRFymN6QYcoA7XB5KYQAAAFY"]
[Thu Jul 30 13:21:56.630609 2026] [security2:error] [pid 872418:tid 872634] [client 20.215.218.234:54761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/o.php"] [unique_id "amuWRFymN6QYcoA7XB5KYQAAAFY"]
[Thu Jul 30 13:21:56.733783 2026] [security2:error] [pid 872418:tid 872559] [client 85.204.70.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ok.otbola.click"] [uri "/xmlrpc.php"] [unique_id "amuWRFymN6QYcoA7XB5KYgAAAAs"]
[Thu Jul 30 13:21:56.948466 2026] [security2:error] [pid 872418:tid 872611] [client 20.215.218.234:21203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/m.php"] [unique_id "amuWRFymN6QYcoA7XB5KZgAAAD8"]
[Thu Jul 30 13:21:56.948585 2026] [security2:error] [pid 872418:tid 872611] [client 20.215.218.234:21203] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/m.php"] [unique_id "amuWRFymN6QYcoA7XB5KZgAAAD8"]
[Thu Jul 30 13:21:56.990508 2026] [autoindex:error] [pid 872418:tid 872652] [client 85.204.70.94:0] AH01276: Cannot serve directory /home2/mbmudite/ok.otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:21:57.118161 2026] [security2:error] [pid 872418:tid 872671] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuWRVymN6QYcoA7XB5KaQAAAHs"]
[Thu Jul 30 13:21:57.330185 2026] [security2:error] [pid 872418:tid 872621] [client 20.215.218.234:20762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/l.php"] [unique_id "amuWRVymN6QYcoA7XB5KcQAAAEk"]
[Thu Jul 30 13:21:57.330316 2026] [security2:error] [pid 872418:tid 872621] [client 20.215.218.234:20762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/l.php"] [unique_id "amuWRVymN6QYcoA7XB5KcQAAAEk"]
[Thu Jul 30 13:21:57.362669 2026] [security2:error] [pid 872418:tid 872610] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuWRVymN6QYcoA7XB5KegAAAD4"]
[Thu Jul 30 13:21:57.511030 2026] [security2:error] [pid 872418:tid 872615] [client 144.76.19.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuWRVymN6QYcoA7XB5KcAAAAEM"]
[Thu Jul 30 13:21:57.605504 2026] [security2:error] [pid 872418:tid 872659] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuWRVymN6QYcoA7XB5KgwAAAG8"]
[Thu Jul 30 13:21:57.713459 2026] [security2:error] [pid 872418:tid 872630] [client 20.215.218.234:20767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/k.php"] [unique_id "amuWRVymN6QYcoA7XB5KhAAAAFI"]
[Thu Jul 30 13:21:57.713705 2026] [security2:error] [pid 872418:tid 872630] [client 20.215.218.234:20767] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/k.php"] [unique_id "amuWRVymN6QYcoA7XB5KhAAAAFI"]
[Thu Jul 30 13:21:57.848310 2026] [security2:error] [pid 872418:tid 872560] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuWRVymN6QYcoA7XB5KiQAAAAw"]
[Thu Jul 30 13:21:58.093434 2026] [security2:error] [pid 872418:tid 872578] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuWRlymN6QYcoA7XB5KiwAAAB4"]
[Thu Jul 30 13:21:58.179876 2026] [security2:error] [pid 872418:tid 872588] [client 20.215.218.234:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/j.php"] [unique_id "amuWRlymN6QYcoA7XB5KjwAAACg"]
[Thu Jul 30 13:21:58.179994 2026] [security2:error] [pid 872418:tid 872588] [client 20.215.218.234:60265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/j.php"] [unique_id "amuWRlymN6QYcoA7XB5KjwAAACg"]
[Thu Jul 30 13:21:58.183933 2026] [proxy:error] [pid 872418:tid 872568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:58.184021 2026] [proxy_http:error] [pid 872418:tid 872568] [client 34.224.175.62:62549] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:58.184675 2026] [proxy:error] [pid 872418:tid 872568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:58.184720 2026] [proxy_http:error] [pid 872418:tid 872568] [client 34.224.175.62:62549] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:58.199736 2026] [proxy:error] [pid 872418:tid 872644] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:58.199814 2026] [proxy_http:error] [pid 872418:tid 872644] [client 34.233.129.35:39516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:58.200673 2026] [proxy:error] [pid 872418:tid 872644] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:58.200733 2026] [proxy_http:error] [pid 872418:tid 872644] [client 34.233.129.35:39516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:58.336638 2026] [security2:error] [pid 872418:tid 872643] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuWRlymN6QYcoA7XB5KlwAAAF8"]
[Thu Jul 30 13:21:58.355312 2026] [security2:error] [pid 872418:tid 872591] [client 179.64.21.229:63118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWRlymN6QYcoA7XB5KmgAAACs"]
[Thu Jul 30 13:21:58.359162 2026] [security2:error] [pid 872418:tid 872591] [client 179.64.21.229:63118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWRlymN6QYcoA7XB5KmgAAACs"]
[Thu Jul 30 13:21:58.578782 2026] [security2:error] [pid 872418:tid 872619] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuWRlymN6QYcoA7XB5KnQAAAEc"]
[Thu Jul 30 13:21:58.582246 2026] [security2:error] [pid 872418:tid 872641] [client 20.215.218.234:64067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/i.php"] [unique_id "amuWRlymN6QYcoA7XB5KngAAAF0"]
[Thu Jul 30 13:21:58.582321 2026] [security2:error] [pid 872418:tid 872641] [client 20.215.218.234:64067] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/i.php"] [unique_id "amuWRlymN6QYcoA7XB5KngAAAF0"]
[Thu Jul 30 13:21:58.789092 2026] [security2:error] [pid 872418:tid 872673] [client 68.221.186.136:7611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/content.php"] [unique_id "amuWRlymN6QYcoA7XB5KoQAAAH0"]
[Thu Jul 30 13:21:58.820410 2026] [security2:error] [pid 872418:tid 872671] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuWRlymN6QYcoA7XB5KogAAAHs"]
[Thu Jul 30 13:21:58.837481 2026] [security2:error] [pid 872418:tid 872496] [remote 74.7.227.39:41468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuWRlymN6QYcoA7XB5KowAAPU0"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/better-search-replace
[Thu Jul 30 13:21:58.962797 2026] [security2:error] [pid 872418:tid 872548] [client 20.215.218.234:21730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/h.php"] [unique_id "amuWRlymN6QYcoA7XB5KqgAAAAA"]
[Thu Jul 30 13:21:58.962910 2026] [security2:error] [pid 872418:tid 872548] [client 20.215.218.234:21730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/h.php"] [unique_id "amuWRlymN6QYcoA7XB5KqgAAAAA"]
[Thu Jul 30 13:21:59.060696 2026] [security2:error] [pid 872418:tid 872661] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuWR1ymN6QYcoA7XB5KrgAAAHE"]
[Thu Jul 30 13:21:59.305088 2026] [security2:error] [pid 872418:tid 872563] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuWR1ymN6QYcoA7XB5KsQAAAA8"]
[Thu Jul 30 13:21:59.356312 2026] [security2:error] [pid 872418:tid 872653] [client 20.215.218.234:9967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/g.php"] [unique_id "amuWR1ymN6QYcoA7XB5KtAAAAGk"]
[Thu Jul 30 13:21:59.356423 2026] [security2:error] [pid 872418:tid 872653] [client 20.215.218.234:9967] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/g.php"] [unique_id "amuWR1ymN6QYcoA7XB5KtAAAAGk"]
[Thu Jul 30 13:21:59.547755 2026] [security2:error] [pid 872418:tid 872575] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuWR1ymN6QYcoA7XB5KtwAAABs"]
[Thu Jul 30 13:21:59.568816 2026] [proxy:error] [pid 872418:tid 872601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:59.568908 2026] [proxy_http:error] [pid 872418:tid 872601] [client 34.233.129.35:11079] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:59.569528 2026] [proxy:error] [pid 872418:tid 872601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:21:59.569581 2026] [proxy_http:error] [pid 872418:tid 872601] [client 34.233.129.35:11079] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:21:59.634794 2026] [security2:error] [pid 872418:tid 872625] [client 68.221.186.136:7585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuWR1ymN6QYcoA7XB5KwQAAAE0"]
[Thu Jul 30 13:21:59.661872 2026] [security2:error] [pid 872418:tid 872607] [client 20.215.218.234:54744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/f.php"] [unique_id "amuWR1ymN6QYcoA7XB5KwgAAADs"]
[Thu Jul 30 13:21:59.662004 2026] [security2:error] [pid 872418:tid 872607] [client 20.215.218.234:54744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/f.php"] [unique_id "amuWR1ymN6QYcoA7XB5KwgAAADs"]
[Thu Jul 30 13:21:59.788855 2026] [security2:error] [pid 872418:tid 872599] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuWR1ymN6QYcoA7XB5KwwAAADM"]
[Thu Jul 30 13:22:00.016528 2026] [security2:error] [pid 872418:tid 872618] [client 20.215.218.234:9973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/e.php"] [unique_id "amuWSFymN6QYcoA7XB5KxAAAAEY"]
[Thu Jul 30 13:22:00.016664 2026] [security2:error] [pid 872418:tid 872618] [client 20.215.218.234:9973] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/e.php"] [unique_id "amuWSFymN6QYcoA7XB5KxAAAAEY"]
[Thu Jul 30 13:22:00.032483 2026] [security2:error] [pid 872418:tid 872640] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuWSFymN6QYcoA7XB5KxgAAAFw"]
[Thu Jul 30 13:22:00.037009 2026] [security2:error] [pid 872418:tid 872647] [client 172.236.9.101:63462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWR1ymN6QYcoA7XB5KtgAAAGM"]
[Thu Jul 30 13:22:00.274592 2026] [security2:error] [pid 872418:tid 872592] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuWSFymN6QYcoA7XB5K0QAAACw"]
[Thu Jul 30 13:22:00.429348 2026] [security2:error] [pid 872418:tid 872612] [client 20.215.218.234:20779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/d.php"] [unique_id "amuWSFymN6QYcoA7XB5K1AAAAEA"]
[Thu Jul 30 13:22:00.429464 2026] [security2:error] [pid 872418:tid 872612] [client 20.215.218.234:20779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/d.php"] [unique_id "amuWSFymN6QYcoA7XB5K1AAAAEA"]
[Thu Jul 30 13:22:00.516835 2026] [security2:error] [pid 872418:tid 872554] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuWSFymN6QYcoA7XB5K1QAAAAY"]
[Thu Jul 30 13:22:00.744428 2026] [security2:error] [pid 872418:tid 872652] [client 20.215.218.234:21222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/c.php"] [unique_id "amuWSFymN6QYcoA7XB5K1gAAAGg"]
[Thu Jul 30 13:22:00.744541 2026] [security2:error] [pid 872418:tid 872652] [client 20.215.218.234:21222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/c.php"] [unique_id "amuWSFymN6QYcoA7XB5K1gAAAGg"]
[Thu Jul 30 13:22:00.761008 2026] [security2:error] [pid 872418:tid 872637] [client 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ok.otbola.click"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuWSFymN6QYcoA7XB5K1wAAAFk"]
[Thu Jul 30 13:22:01.042858 2026] [core:notice] [pid 872418:tid 872550] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:01.110901 2026] [security2:error] [pid 872418:tid 872565] [client 20.215.218.234:60277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/b.php"] [unique_id "amuWSVymN6QYcoA7XB5K3QAAABE"]
[Thu Jul 30 13:22:01.111024 2026] [security2:error] [pid 872418:tid 872565] [client 20.215.218.234:60277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/b.php"] [unique_id "amuWSVymN6QYcoA7XB5K3QAAABE"]
[Thu Jul 30 13:22:01.473340 2026] [security2:error] [pid 872418:tid 872675] [client 20.215.218.234:21006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/indexc.php"] [unique_id "amuWSVymN6QYcoA7XB5K5wAAAH8"]
[Thu Jul 30 13:22:01.473459 2026] [security2:error] [pid 872418:tid 872675] [client 20.215.218.234:21006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/indexc.php"] [unique_id "amuWSVymN6QYcoA7XB5K5wAAAH8"]
[Thu Jul 30 13:22:01.489835 2026] [security2:error] [pid 872418:tid 872619] [client 68.221.186.136:12653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuWSVymN6QYcoA7XB5K6AAAAEc"]
[Thu Jul 30 13:22:01.601286 2026] [security2:error] [pid 872418:tid 872670] [client 43.172.195.27:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/05/28/miami-lorganisation-de-mon-sejour/"] [unique_id "amuWSVymN6QYcoA7XB5K5QAAAHo"]
[Thu Jul 30 13:22:01.843564 2026] [security2:error] [pid 872418:tid 872567] [client 20.215.218.234:21750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuWSVymN6QYcoA7XB5K7QAAABM"]
[Thu Jul 30 13:22:01.843677 2026] [security2:error] [pid 872418:tid 872567] [client 20.215.218.234:21750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuWSVymN6QYcoA7XB5K7QAAABM"]
[Thu Jul 30 13:22:02.008552 2026] [security2:error] [pid 872418:tid 872641] [client 20.215.191.139:65124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/json.php"] [unique_id "amuWSlymN6QYcoA7XB5K8gAAAF0"]
[Thu Jul 30 13:22:02.372752 2026] [core:notice] [pid 872418:tid 872511] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:02.377332 2026] [security2:error] [pid 872418:tid 872574] [client 20.215.218.234:54753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuWSlymN6QYcoA7XB5K9wAAABo"]
[Thu Jul 30 13:22:02.377483 2026] [security2:error] [pid 872418:tid 872574] [client 20.215.218.234:54753] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuWSlymN6QYcoA7XB5K9wAAABo"]
[Thu Jul 30 13:22:02.383921 2026] [core:notice] [pid 872418:tid 872659] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:02.389346 2026] [security2:error] [pid 872418:tid 872659] [client 43.173.181.207:38736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/05/28/miami-lorganisation-de-mon-sejour/"] [unique_id "amuWSlymN6QYcoA7XB5K-AAAAG8"], referer: https://carnetdeshopping.com/index.php/2012/05/28/miami-lorganisation-de-mon-sejour/?replytocom=550
[Thu Jul 30 13:22:02.684339 2026] [security2:error] [pid 872418:tid 872618] [client 20.215.218.234:63503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuWSlymN6QYcoA7XB5K_QAAAEY"]
[Thu Jul 30 13:22:02.684475 2026] [security2:error] [pid 872418:tid 872618] [client 20.215.218.234:63503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuWSlymN6QYcoA7XB5K_QAAAEY"]
[Thu Jul 30 13:22:02.898225 2026] [security2:error] [pid 872418:tid 872564] [client 172.236.9.101:49734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWSlymN6QYcoA7XB5K-QAAABA"]
[Thu Jul 30 13:22:03.343769 2026] [security2:error] [pid 872418:tid 872655] [client 20.215.218.234:21747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/.561988674612251.php"] [unique_id "amuWS1ymN6QYcoA7XB5LDQAAAGs"]
[Thu Jul 30 13:22:03.343858 2026] [security2:error] [pid 872418:tid 872655] [client 20.215.218.234:21747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/.561988674612251.php"] [unique_id "amuWS1ymN6QYcoA7XB5LDQAAAGs"]
[Thu Jul 30 13:22:03.351786 2026] [core:notice] [pid 872418:tid 872589] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:03.375637 2026] [security2:error] [pid 872418:tid 872631] [client 20.215.191.139:51135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/mini.php"] [unique_id "amuWS1ymN6QYcoA7XB5LDwAAAFM"]
[Thu Jul 30 13:22:03.445781 2026] [security2:error] [pid 872418:tid 872666] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWSlymN6QYcoA7XB5LAAAAdms"]
[Thu Jul 30 13:22:03.765496 2026] [security2:error] [pid 872418:tid 872552] [client 20.215.218.234:63494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/indexw.php"] [unique_id "amuWS1ymN6QYcoA7XB5LIAAAAAQ"]
[Thu Jul 30 13:22:03.765583 2026] [security2:error] [pid 872418:tid 872552] [client 20.215.218.234:63494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/indexw.php"] [unique_id "amuWS1ymN6QYcoA7XB5LIAAAAAQ"]
[Thu Jul 30 13:22:04.272551 2026] [security2:error] [pid 872418:tid 872567] [client 20.215.218.234:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/.284214373991941.php"] [unique_id "amuWTFymN6QYcoA7XB5LKAAAABM"]
[Thu Jul 30 13:22:04.272659 2026] [security2:error] [pid 872418:tid 872567] [client 20.215.218.234:60228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/.284214373991941.php"] [unique_id "amuWTFymN6QYcoA7XB5LKAAAABM"]
[Thu Jul 30 13:22:04.620540 2026] [security2:error] [pid 872418:tid 872599] [client 68.221.186.136:41830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuWTFymN6QYcoA7XB5LMAAAADM"]
[Thu Jul 30 13:22:05.293354 2026] [security2:error] [pid 872418:tid 872602] [client 20.215.191.139:46425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/chosen.php"] [unique_id "amuWTVymN6QYcoA7XB5LPwAAADY"]
[Thu Jul 30 13:22:05.848798 2026] [security2:error] [pid 872418:tid 872593] [client 172.236.9.101:34170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWTVymN6QYcoA7XB5LQAAAAC0"]
[Thu Jul 30 13:22:05.887353 2026] [proxy:error] [pid 872418:tid 872613] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:05.887439 2026] [proxy_http:error] [pid 872418:tid 872613] [client 3.228.112.215:22168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:05.888033 2026] [proxy:error] [pid 872418:tid 872613] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:05.888085 2026] [proxy_http:error] [pid 872418:tid 872613] [client 3.228.112.215:22168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:05.948240 2026] [security2:error] [pid 872418:tid 872522] [remote 57.141.0.3:27858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/44562851719/feed/rss2/"] [unique_id "amuWTVymN6QYcoA7XB5LRAAAXmc"]
[Thu Jul 30 13:22:06.355770 2026] [security2:error] [pid 872418:tid 872616] [client 20.215.191.139:20595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/kj.php"] [unique_id "amuWTlymN6QYcoA7XB5LXgAAAEQ"]
[Thu Jul 30 13:22:06.358841 2026] [security2:error] [pid 872418:tid 872674] [client 172.236.9.101:18525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/kcfinder/browse.php"] [unique_id "amuWTlymN6QYcoA7XB5LYAAAAH4"]
[Thu Jul 30 13:22:07.141065 2026] [security2:error] [pid 872418:tid 872596] [client 68.221.186.136:5565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuWT1ymN6QYcoA7XB5LbQAAADA"]
[Thu Jul 30 13:22:07.426643 2026] [proxy:error] [pid 872418:tid 872592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:07.426711 2026] [proxy_http:error] [pid 872418:tid 872592] [client 167.71.179.1:47188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:07.427287 2026] [proxy:error] [pid 872418:tid 872592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:07.428407 2026] [proxy_http:error] [pid 872418:tid 872592] [client 167.71.179.1:47188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:07.833932 2026] [proxy:error] [pid 872418:tid 872631] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:07.834036 2026] [proxy_http:error] [pid 872418:tid 872631] [client 167.71.179.1:47200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.sua.nyx.temporary.site/
[Thu Jul 30 13:22:07.835011 2026] [proxy:error] [pid 872418:tid 872631] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:07.835069 2026] [proxy_http:error] [pid 872418:tid 872631] [client 167.71.179.1:47200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.sua.nyx.temporary.site/
[Thu Jul 30 13:22:07.849649 2026] [security2:error] [pid 872418:tid 872672] [client 68.221.186.136:29533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuWT1ymN6QYcoA7XB5LgwAAAHw"]
[Thu Jul 30 13:22:08.082991 2026] [security2:error] [pid 872418:tid 872671] [client 20.215.191.139:20554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-files.php"] [unique_id "amuWUFymN6QYcoA7XB5LiQAAAHs"]
[Thu Jul 30 13:22:08.567931 2026] [security2:error] [pid 872418:tid 872563] [client 68.221.186.136:15263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuWUFymN6QYcoA7XB5LmgAAAA8"]
[Thu Jul 30 13:22:08.611847 2026] [core:error] [pid 872418:tid 872614] [client 167.71.179.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:22:08.611870 2026] [core:error] [pid 872418:tid 872614] [client 167.71.179.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:22:08.704851 2026] [security2:error] [pid 872418:tid 872493] [remote 216.73.217.142:54354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuWUFymN6QYcoA7XB5LngAAE0o"]
[Thu Jul 30 13:22:08.724337 2026] [core:notice] [pid 872418:tid 872616] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:08.745100 2026] [security2:error] [pid 872418:tid 872674] [client 20.215.191.139:52616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-setup.php"] [unique_id "amuWUFymN6QYcoA7XB5LoAAAAH4"]
[Thu Jul 30 13:22:08.766314 2026] [security2:error] [pid 872418:tid 872549] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWUFymN6QYcoA7XB5LjAAAAAE"]
[Thu Jul 30 13:22:09.024032 2026] [security2:error] [pid 872418:tid 872670] [client 74.7.175.170:51600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.globalmarks.pk"] [uri "/index.php"] [unique_id "amuWUFymN6QYcoA7XB5LpwAAeho"]
[Thu Jul 30 13:22:09.101495 2026] [security2:error] [pid 872418:tid 872608] [client 179.64.21.229:45252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWUVymN6QYcoA7XB5LrgAAADw"]
[Thu Jul 30 13:22:09.101616 2026] [security2:error] [pid 872418:tid 872608] [client 179.64.21.229:45252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWUVymN6QYcoA7XB5LrgAAADw"]
[Thu Jul 30 13:22:09.401067 2026] [security2:error] [pid 872418:tid 872581] [client 20.215.191.139:20590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/defaults.php"] [unique_id "amuWUVymN6QYcoA7XB5LtwAAACE"]
[Thu Jul 30 13:22:09.430644 2026] [security2:error] [pid 872418:tid 872659] [client 172.236.9.101:59545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/assets/kcfinder/browse.php"] [unique_id "amuWUVymN6QYcoA7XB5LvQAAAG8"]
[Thu Jul 30 13:22:09.723915 2026] [security2:error] [pid 872418:tid 872596] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWUVymN6QYcoA7XB5LsAAAADA"]
[Thu Jul 30 13:22:10.741077 2026] [security2:error] [pid 872418:tid 872620] [client 68.221.186.136:17046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuWUlymN6QYcoA7XB5L3gAAAEg"]
[Thu Jul 30 13:22:10.799514 2026] [security2:error] [pid 872418:tid 872621] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWUlymN6QYcoA7XB5L0gAAAEk"]
[Thu Jul 30 13:22:10.809615 2026] [security2:error] [pid 872418:tid 872664] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWUlymN6QYcoA7XB5L1AAAAHQ"]
[Thu Jul 30 13:22:11.214411 2026] [security2:error] [pid 872418:tid 872430] [remote 57.141.0.71:43422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amuWU1ymN6QYcoA7XB5L6wAAOgs"]
[Thu Jul 30 13:22:11.400238 2026] [security2:error] [pid 872418:tid 872572] [client 20.215.191.139:65093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/gtc.php"] [unique_id "amuWU1ymN6QYcoA7XB5L7wAAABg"]
[Thu Jul 30 13:22:12.358913 2026] [security2:error] [pid 872418:tid 872554] [client 172.236.9.101:33895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/lib/kcfinder/browse.php"] [unique_id "amuWVFymN6QYcoA7XB5MBwAAAAY"]
[Thu Jul 30 13:22:13.036918 2026] [security2:error] [pid 872418:tid 872675] [client 20.215.191.139:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/import.php"] [unique_id "amuWVVymN6QYcoA7XB5MGQAAAH8"]
[Thu Jul 30 13:22:13.118034 2026] [security2:error] [pid 872418:tid 872619] [client 68.221.186.136:17049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuWVVymN6QYcoA7XB5MHQAAAEc"]
[Thu Jul 30 13:22:13.252239 2026] [core:error] [pid 872418:tid 872632] [client 167.71.179.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.sua.nyx.temporary.site/
[Thu Jul 30 13:22:13.252265 2026] [core:error] [pid 872418:tid 872632] [client 167.71.179.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.sua.nyx.temporary.site/
[Thu Jul 30 13:22:13.797084 2026] [security2:error] [pid 872418:tid 872601] [client 68.221.186.136:1500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuWVVymN6QYcoA7XB5MKgAAADU"]
[Thu Jul 30 13:22:14.491374 2026] [security2:error] [pid 872418:tid 872495] [remote 57.141.0.63:26888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6113126855/feed/rss2/"] [unique_id "amuWVlymN6QYcoA7XB5MPAAAeEw"]
[Thu Jul 30 13:22:15.355917 2026] [security2:error] [pid 872418:tid 872563] [client 172.236.9.101:41653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/admin/kcfinder/browse.php"] [unique_id "amuWV1ymN6QYcoA7XB5MVQAAAA8"]
[Thu Jul 30 13:22:15.590637 2026] [security2:error] [pid 872418:tid 872620] [client 43.166.134.114:49790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuWV1ymN6QYcoA7XB5MVAAAAEg"]
[Thu Jul 30 13:22:15.867352 2026] [security2:error] [pid 872418:tid 872512] [remote 74.7.243.224:41848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/mission/js/uploads/content/uploads/partners/uploads/content/js/img/fonts/css/img/reportf.php"] [unique_id "amuWV1ymN6QYcoA7XB5MXwAAR10"], referer: https://aded-rdc.org/mission/js/uploads/content/uploads/partners/uploads/content/js/img/fonts/css/img/humanitariaf.html
[Thu Jul 30 13:22:16.155228 2026] [security2:error] [pid 872418:tid 872570] [client 74.7.175.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-dd429813.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuWV1ymN6QYcoA7XB5MUwAAABY"]
[Thu Jul 30 13:22:16.156082 2026] [security2:error] [pid 872418:tid 872636] [client 74.7.175.151:54468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-dd429813.dlr.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuWV1ymN6QYcoA7XB5MUQAAWF8"]
[Thu Jul 30 13:22:16.272013 2026] [core:error] [pid 872418:tid 872630] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:22:16.272038 2026] [core:error] [pid 872418:tid 872630] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:22:16.429087 2026] [security2:error] [pid 872418:tid 872550] [client 68.221.186.136:13631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuWWFymN6QYcoA7XB5McAAAAAI"]
[Thu Jul 30 13:22:16.614498 2026] [security2:error] [pid 872418:tid 872635] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWWFymN6QYcoA7XB5MYgAAAFc"]
[Thu Jul 30 13:22:16.696270 2026] [core:notice] [pid 872418:tid 872667] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:18.404748 2026] [security2:error] [pid 872418:tid 872565] [client 172.236.9.101:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/includes/kcfinder/browse.php"] [unique_id "amuWWlymN6QYcoA7XB5MnwAAABE"]
[Thu Jul 30 13:22:19.738829 2026] [security2:error] [pid 872418:tid 872560] [client 179.64.21.229:62348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWW1ymN6QYcoA7XB5M2AAAAAw"]
[Thu Jul 30 13:22:19.738928 2026] [security2:error] [pid 872418:tid 872560] [client 179.64.21.229:62348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWW1ymN6QYcoA7XB5M2AAAAAw"]
[Thu Jul 30 13:22:20.177610 2026] [autoindex:error] [pid 872418:tid 872582] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:20.178252 2026] [security2:error] [pid 872418:tid 872582] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWXFymN6QYcoA7XB5M3wAAACI"]
[Thu Jul 30 13:22:20.317642 2026] [autoindex:error] [pid 872418:tid 872580] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:20.318244 2026] [security2:error] [pid 872418:tid 872580] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWXFymN6QYcoA7XB5M5QAAACA"]
[Thu Jul 30 13:22:20.459488 2026] [autoindex:error] [pid 872418:tid 872659] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:20.460138 2026] [security2:error] [pid 872418:tid 872659] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWXFymN6QYcoA7XB5M6gAAAG8"]
[Thu Jul 30 13:22:20.600760 2026] [autoindex:error] [pid 872418:tid 872627] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:20.601377 2026] [security2:error] [pid 872418:tid 872627] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWXFymN6QYcoA7XB5M7wAAAE8"]
[Thu Jul 30 13:22:20.743549 2026] [autoindex:error] [pid 872418:tid 872577] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:20.744187 2026] [security2:error] [pid 872418:tid 872577] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWXFymN6QYcoA7XB5M8AAAAB0"]
[Thu Jul 30 13:22:20.877306 2026] [core:notice] [pid 872418:tid 872603] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:20.882415 2026] [security2:error] [pid 872418:tid 872593] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWXFymN6QYcoA7XB5M5gAAAC0"]
[Thu Jul 30 13:22:20.899867 2026] [autoindex:error] [pid 872418:tid 872569] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:20.900504 2026] [security2:error] [pid 872418:tid 872569] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWXFymN6QYcoA7XB5M-QAAABU"]
[Thu Jul 30 13:22:21.044395 2026] [autoindex:error] [pid 872418:tid 872614] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:21.045069 2026] [security2:error] [pid 872418:tid 872614] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWXVymN6QYcoA7XB5M_gAAAEI"]
[Thu Jul 30 13:22:21.186132 2026] [autoindex:error] [pid 872418:tid 872656] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:21.186751 2026] [security2:error] [pid 872418:tid 872656] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWXVymN6QYcoA7XB5M_wAAAGw"]
[Thu Jul 30 13:22:21.293167 2026] [security2:error] [pid 872418:tid 872557] [client 20.215.191.139:46450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/lufix.php"] [unique_id "amuWXVymN6QYcoA7XB5NAwAAAAk"]
[Thu Jul 30 13:22:21.483715 2026] [core:notice] [pid 872418:tid 872550] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:21.576926 2026] [security2:error] [pid 872418:tid 872629] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWXVymN6QYcoA7XB5NBAAAAFE"]
[Thu Jul 30 13:22:21.576953 2026] [security2:error] [pid 872418:tid 872629] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWXVymN6QYcoA7XB5NBAAAAFE"]
[Thu Jul 30 13:22:21.790547 2026] [core:notice] [pid 872418:tid 872617] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:21.961121 2026] [security2:error] [pid 872418:tid 872604] [client 20.215.191.139:51190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/Geforce.php"] [unique_id "amuWXVymN6QYcoA7XB5NFAAAADg"]
[Thu Jul 30 13:22:21.994852 2026] [security2:error] [pid 872418:tid 872606] [client 68.221.186.136:4461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuWXVymN6QYcoA7XB5NFQAAADo"]
[Thu Jul 30 13:22:22.215353 2026] [core:notice] [pid 872418:tid 872591] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:22.248457 2026] [security2:error] [pid 872418:tid 872660] [client 51.68.236.92:33253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "siatfc.com"] [uri "/robots.txt"] [unique_id "amuWXlymN6QYcoA7XB5NGgAAAHA"]
[Thu Jul 30 13:22:22.248547 2026] [security2:error] [pid 872418:tid 872660] [client 51.68.236.92:33253] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "siatfc.com"] [uri "/robots.txt"] [unique_id "amuWXlymN6QYcoA7XB5NGgAAAHA"]
[Thu Jul 30 13:22:22.582578 2026] [core:notice] [pid 872418:tid 872590] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:22.586749 2026] [core:notice] [pid 872418:tid 872638] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:22.590589 2026] [core:notice] [pid 872418:tid 872642] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:22.593634 2026] [core:notice] [pid 872418:tid 872553] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:22.595068 2026] [core:notice] [pid 872418:tid 872652] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:22.599886 2026] [core:notice] [pid 872418:tid 872568] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:22.665831 2026] [security2:error] [pid 872418:tid 872615] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWXlymN6QYcoA7XB5NIQAAAEM"]
[Thu Jul 30 13:22:22.665856 2026] [security2:error] [pid 872418:tid 872615] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWXlymN6QYcoA7XB5NIQAAAEM"]
[Thu Jul 30 13:22:22.772439 2026] [security2:error] [pid 872418:tid 872624] [client 68.221.186.136:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/about.php"] [unique_id "amuWXlymN6QYcoA7XB5NLAAAAEw"]
[Thu Jul 30 13:22:23.009709 2026] [security2:error] [pid 872418:tid 872582] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWXlymN6QYcoA7XB5NLQAAACI"]
[Thu Jul 30 13:22:23.009755 2026] [security2:error] [pid 872418:tid 872582] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWXlymN6QYcoA7XB5NLQAAACI"]
[Thu Jul 30 13:22:23.152948 2026] [autoindex:error] [pid 872418:tid 872659] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:23.153612 2026] [security2:error] [pid 872418:tid 872659] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWX1ymN6QYcoA7XB5NNAAAAG8"]
[Thu Jul 30 13:22:23.286300 2026] [security2:error] [pid 872418:tid 872637] [client 20.215.191.139:52700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/a4.php"] [unique_id "amuWX1ymN6QYcoA7XB5NOQAAAFk"]
[Thu Jul 30 13:22:23.304957 2026] [autoindex:error] [pid 872418:tid 872577] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:23.305863 2026] [security2:error] [pid 872418:tid 872577] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWX1ymN6QYcoA7XB5NOAAAAB0"]
[Thu Jul 30 13:22:23.311044 2026] [core:notice] [pid 872418:tid 872661] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:23.366044 2026] [security2:error] [pid 872418:tid 872645] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWXlymN6QYcoA7XB5NKwAAYSs"]
[Thu Jul 30 13:22:23.448117 2026] [security2:error] [pid 872418:tid 872567] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "siatfc.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "amuWX1ymN6QYcoA7XB5NPwAAABM"]
[Thu Jul 30 13:22:23.589833 2026] [autoindex:error] [pid 872418:tid 872649] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:23.590484 2026] [security2:error] [pid 872418:tid 872649] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWX1ymN6QYcoA7XB5NQgAAAGU"]
[Thu Jul 30 13:22:23.591803 2026] [security2:error] [pid 872418:tid 872675] [client 134.19.179.147:51974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuWX1ymN6QYcoA7XB5NQwAAAH8"]
[Thu Jul 30 13:22:23.591881 2026] [security2:error] [pid 872418:tid 872675] [client 134.19.179.147:51974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuWX1ymN6QYcoA7XB5NQwAAAH8"]
[Thu Jul 30 13:22:23.707820 2026] [core:notice] [pid 872418:tid 872549] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:23.718846 2026] [core:notice] [pid 872418:tid 872575] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:23.732840 2026] [core:notice] [pid 872418:tid 872656] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:23.739874 2026] [autoindex:error] [pid 872418:tid 872614] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:23.740774 2026] [security2:error] [pid 872418:tid 872614] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWX1ymN6QYcoA7XB5NTQAAAEI"]
[Thu Jul 30 13:22:23.882579 2026] [autoindex:error] [pid 872418:tid 872646] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:23.883191 2026] [security2:error] [pid 872418:tid 872646] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWX1ymN6QYcoA7XB5NUQAAAGI"]
[Thu Jul 30 13:22:24.025812 2026] [autoindex:error] [pid 872418:tid 872658] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:24.026437 2026] [security2:error] [pid 872418:tid 872658] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWYFymN6QYcoA7XB5NWAAAAG4"]
[Thu Jul 30 13:22:24.142673 2026] [core:notice] [pid 872418:tid 872628] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:24.147610 2026] [core:notice] [pid 872418:tid 872574] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:24.164666 2026] [autoindex:error] [pid 872418:tid 872667] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:24.165259 2026] [security2:error] [pid 872418:tid 872667] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWYFymN6QYcoA7XB5NWwAAAHc"]
[Thu Jul 30 13:22:24.500762 2026] [security2:error] [pid 872418:tid 872555] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYFymN6QYcoA7XB5NXwAAAAc"]
[Thu Jul 30 13:22:24.500788 2026] [security2:error] [pid 872418:tid 872555] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYFymN6QYcoA7XB5NXwAAAAc"]
[Thu Jul 30 13:22:24.526539 2026] [core:notice] [pid 872418:tid 872583] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:24.544485 2026] [core:notice] [pid 872418:tid 872655] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:24.547683 2026] [core:notice] [pid 872418:tid 872576] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:24.555606 2026] [core:notice] [pid 872418:tid 872626] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:24.793064 2026] [proxy:error] [pid 872418:tid 872615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:24.793124 2026] [proxy_http:error] [pid 872418:tid 872615] [client 34.233.129.35:3962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:24.793681 2026] [proxy:error] [pid 872418:tid 872615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:24.793725 2026] [proxy_http:error] [pid 872418:tid 872615] [client 34.233.129.35:3962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:24.801137 2026] [proxy:error] [pid 872418:tid 872622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:24.801200 2026] [proxy_http:error] [pid 872418:tid 872622] [client 34.233.129.35:46285] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:24.802018 2026] [proxy:error] [pid 872418:tid 872622] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:24.802075 2026] [proxy_http:error] [pid 872418:tid 872622] [client 34.233.129.35:46285] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:24.898107 2026] [security2:error] [pid 872418:tid 872666] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYFymN6QYcoA7XB5NbgAAAHY"]
[Thu Jul 30 13:22:24.898135 2026] [security2:error] [pid 872418:tid 872666] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYFymN6QYcoA7XB5NbgAAAHY"]
[Thu Jul 30 13:22:24.949133 2026] [core:notice] [pid 872418:tid 872559] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:24.959680 2026] [core:notice] [pid 872418:tid 872665] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:24.961724 2026] [core:notice] [pid 872418:tid 872580] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:24.965157 2026] [core:notice] [pid 872418:tid 872611] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:25.062188 2026] [autoindex:error] [pid 872418:tid 872645] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:25.062791 2026] [security2:error] [pid 872418:tid 872645] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWYVymN6QYcoA7XB5NiAAAAGE"]
[Thu Jul 30 13:22:25.150279 2026] [security2:error] [pid 872418:tid 872589] [client 20.215.191.139:51029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/accueil.php"] [unique_id "amuWYVymN6QYcoA7XB5NigAAACk"]
[Thu Jul 30 13:22:25.205705 2026] [cgid:error] [pid 872418:tid 872674] [client 85.204.70.102:56244] AH01265: stderr from /home1/jvcnyxte/public_html/website_c7e2d6e8/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 13:22:25.206479 2026] [security2:error] [pid 872418:tid 872674] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWYVymN6QYcoA7XB5NiwAAAH4"]
[Thu Jul 30 13:22:25.243163 2026] [core:notice] [pid 872418:tid 872567] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:25.370857 2026] [proxy:error] [pid 872418:tid 872649] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:25.370942 2026] [proxy_http:error] [pid 872418:tid 872649] [client 34.233.129.35:36887] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:25.371671 2026] [proxy:error] [pid 872418:tid 872649] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:25.371721 2026] [proxy_http:error] [pid 872418:tid 872649] [client 34.233.129.35:36887] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:25.379035 2026] [proxy:error] [pid 872418:tid 872675] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:25.379094 2026] [proxy_http:error] [pid 872418:tid 872675] [client 32.194.121.99:36995] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:25.379679 2026] [proxy:error] [pid 872418:tid 872675] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:25.379722 2026] [proxy_http:error] [pid 872418:tid 872675] [client 32.194.121.99:36995] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:25.545340 2026] [security2:error] [pid 872418:tid 872619] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYVymN6QYcoA7XB5NkAAAAEc"]
[Thu Jul 30 13:22:25.545366 2026] [security2:error] [pid 872418:tid 872619] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYVymN6QYcoA7XB5NkAAAAEc"]
[Thu Jul 30 13:22:25.657088 2026] [core:notice] [pid 872418:tid 872558] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:25.661136 2026] [core:notice] [pid 872418:tid 872639] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:25.664009 2026] [core:notice] [pid 872418:tid 872663] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:25.815269 2026] [proxy:error] [pid 872418:tid 872644] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:25.815368 2026] [proxy_http:error] [pid 872418:tid 872644] [client 54.87.222.253:20649] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:25.816205 2026] [proxy:error] [pid 872418:tid 872644] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:25.816263 2026] [proxy_http:error] [pid 872418:tid 872644] [client 54.87.222.253:20649] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:25.828155 2026] [proxy:error] [pid 872418:tid 872581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:25.828246 2026] [proxy_http:error] [pid 872418:tid 872581] [client 3.228.112.215:46854] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:25.828861 2026] [proxy:error] [pid 872418:tid 872581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:25.828904 2026] [proxy_http:error] [pid 872418:tid 872581] [client 3.228.112.215:46854] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:25.891339 2026] [security2:error] [pid 872418:tid 872658] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYVymN6QYcoA7XB5NqgAAAG4"]
[Thu Jul 30 13:22:25.891368 2026] [security2:error] [pid 872418:tid 872658] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYVymN6QYcoA7XB5NqgAAAG4"]
[Thu Jul 30 13:22:25.933622 2026] [security2:error] [pid 872418:tid 872585] [client 20.215.191.139:51961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/dashboard.php"] [unique_id "amuWYVymN6QYcoA7XB5NtAAAACU"]
[Thu Jul 30 13:22:26.002382 2026] [security2:error] [pid 872418:tid 872569] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWYVymN6QYcoA7XB5NnAAAABU"]
[Thu Jul 30 13:22:26.232059 2026] [security2:error] [pid 872418:tid 872660] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYlymN6QYcoA7XB5NtgAAAHA"]
[Thu Jul 30 13:22:26.232088 2026] [security2:error] [pid 872418:tid 872660] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYlymN6QYcoA7XB5NtgAAAHA"]
[Thu Jul 30 13:22:26.421342 2026] [security2:error] [pid 872418:tid 872556] [client 68.221.186.136:29546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/about.php"] [unique_id "amuWYlymN6QYcoA7XB5NxAAAAAg"]
[Thu Jul 30 13:22:26.489060 2026] [security2:error] [pid 872418:tid 872633] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYlymN6QYcoA7XB5NwwAAAFU"]
[Thu Jul 30 13:22:26.489090 2026] [security2:error] [pid 872418:tid 872633] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWYlymN6QYcoA7XB5NwwAAAFU"]
[Thu Jul 30 13:22:26.704937 2026] [security2:error] [pid 872418:tid 872563] [client 20.215.191.139:51039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/radio.php"] [unique_id "amuWYlymN6QYcoA7XB5NywAAAA8"]
[Thu Jul 30 13:22:26.961402 2026] [proxy:error] [pid 872418:tid 872621] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:26.961498 2026] [proxy_http:error] [pid 872418:tid 872621] [client 52.202.41.153:50467] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:26.962200 2026] [proxy:error] [pid 872418:tid 872621] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:26.962250 2026] [proxy_http:error] [pid 872418:tid 872621] [client 52.202.41.153:50467] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:26.978033 2026] [proxy:error] [pid 872418:tid 872609] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:26.978094 2026] [proxy_http:error] [pid 872418:tid 872609] [client 54.87.222.253:35409] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:26.978670 2026] [proxy:error] [pid 872418:tid 872609] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:26.978714 2026] [proxy_http:error] [pid 872418:tid 872609] [client 54.87.222.253:35409] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:27.018655 2026] [core:notice] [pid 872418:tid 872666] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:27.319847 2026] [security2:error] [pid 872418:tid 872572] [client 85.204.70.102:35554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWY1ymN6QYcoA7XB5N1gAAAHk"]
[Thu Jul 30 13:22:27.442734 2026] [security2:error] [pid 872418:tid 872632] [client 68.221.186.136:1551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuWY1ymN6QYcoA7XB5N5gAAAFQ"]
[Thu Jul 30 13:22:27.783080 2026] [security2:error] [pid 872418:tid 872586] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWY1ymN6QYcoA7XB5N5wAAACY"]
[Thu Jul 30 13:22:27.783108 2026] [security2:error] [pid 872418:tid 872586] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWY1ymN6QYcoA7XB5N5wAAACY"]
[Thu Jul 30 13:22:28.114881 2026] [security2:error] [pid 872418:tid 872635] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWY1ymN6QYcoA7XB5N8QAAAFc"]
[Thu Jul 30 13:22:28.114912 2026] [security2:error] [pid 872418:tid 872635] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWY1ymN6QYcoA7XB5N8QAAAFc"]
[Thu Jul 30 13:22:28.156813 2026] [security2:error] [pid 872418:tid 872579] [client 68.221.186.136:11170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuWZFymN6QYcoA7XB5N-AAAAB8"]
[Thu Jul 30 13:22:28.165415 2026] [security2:error] [pid 872418:tid 872573] [client 20.215.191.139:46417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wpsml-sys.php"] [unique_id "amuWZFymN6QYcoA7XB5N-gAAABk"]
[Thu Jul 30 13:22:28.241937 2026] [core:notice] [pid 872418:tid 872477] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:28.464746 2026] [security2:error] [pid 872418:tid 872672] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZFymN6QYcoA7XB5OAgAAAHw"]
[Thu Jul 30 13:22:28.464774 2026] [security2:error] [pid 872418:tid 872672] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZFymN6QYcoA7XB5OAgAAAHw"]
[Thu Jul 30 13:22:28.556371 2026] [proxy:error] [pid 872418:tid 872657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:28.556480 2026] [proxy_http:error] [pid 872418:tid 872657] [client 32.194.121.99:47545] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:28.558056 2026] [proxy:error] [pid 872418:tid 872657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:28.558130 2026] [proxy_http:error] [pid 872418:tid 872657] [client 32.194.121.99:47545] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:28.562786 2026] [proxy:error] [pid 872418:tid 872611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:28.562861 2026] [proxy_http:error] [pid 872418:tid 872611] [client 34.233.129.35:61995] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:28.563948 2026] [proxy:error] [pid 872418:tid 872611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:28.564041 2026] [proxy_http:error] [pid 872418:tid 872611] [client 34.233.129.35:61995] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:28.708843 2026] [security2:error] [pid 872418:tid 872499] [remote 216.73.217.142:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuWZFymN6QYcoA7XB5OGgAAD1A"]
[Thu Jul 30 13:22:28.809755 2026] [security2:error] [pid 872418:tid 872633] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZFymN6QYcoA7XB5OEgAAAFU"]
[Thu Jul 30 13:22:28.809784 2026] [security2:error] [pid 872418:tid 872633] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZFymN6QYcoA7XB5OEgAAAFU"]
[Thu Jul 30 13:22:29.142118 2026] [security2:error] [pid 872418:tid 872656] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZFymN6QYcoA7XB5OIAAAAGw"]
[Thu Jul 30 13:22:29.142158 2026] [security2:error] [pid 872418:tid 872656] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZFymN6QYcoA7XB5OIAAAAGw"]
[Thu Jul 30 13:22:29.515734 2026] [security2:error] [pid 872418:tid 872630] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZVymN6QYcoA7XB5OLAAAAFI"]
[Thu Jul 30 13:22:29.515763 2026] [security2:error] [pid 872418:tid 872630] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZVymN6QYcoA7XB5OLAAAAFI"]
[Thu Jul 30 13:22:29.784334 2026] [security2:error] [pid 872418:tid 872562] [client 68.221.186.136:8414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/img/about.php"] [unique_id "amuWZVymN6QYcoA7XB5OOQAAAA4"]
[Thu Jul 30 13:22:29.865407 2026] [security2:error] [pid 872418:tid 872571] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZVymN6QYcoA7XB5ONAAAABc"]
[Thu Jul 30 13:22:29.865450 2026] [security2:error] [pid 872418:tid 872571] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZVymN6QYcoA7XB5ONAAAABc"]
[Thu Jul 30 13:22:29.937963 2026] [security2:error] [pid 872418:tid 872588] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWZVymN6QYcoA7XB5OLwAAACg"]
[Thu Jul 30 13:22:30.172883 2026] [security2:error] [pid 872418:tid 872531] [remote 57.141.0.11:63400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuWZlymN6QYcoA7XB5OQAAAB3A"]
[Thu Jul 30 13:22:30.204804 2026] [security2:error] [pid 872418:tid 872585] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZVymN6QYcoA7XB5OPAAAACU"]
[Thu Jul 30 13:22:30.204828 2026] [security2:error] [pid 872418:tid 872585] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZVymN6QYcoA7XB5OPAAAACU"]
[Thu Jul 30 13:22:30.265393 2026] [security2:error] [pid 872418:tid 872591] [client 74.7.244.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.buyfluoxetine.store"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuWZlymN6QYcoA7XB5ORAAAACs"]
[Thu Jul 30 13:22:30.377077 2026] [proxy:error] [pid 872418:tid 872634] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:30.377183 2026] [proxy_http:error] [pid 872418:tid 872634] [client 54.87.222.253:22528] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:30.378069 2026] [proxy:error] [pid 872418:tid 872634] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:30.378130 2026] [proxy_http:error] [pid 872418:tid 872634] [client 54.87.222.253:22528] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:30.411590 2026] [proxy:error] [pid 872418:tid 872559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:30.411677 2026] [proxy_http:error] [pid 872418:tid 872559] [client 52.202.41.153:25653] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:30.412488 2026] [proxy:error] [pid 872418:tid 872559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:30.412537 2026] [proxy_http:error] [pid 872418:tid 872559] [client 52.202.41.153:25653] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:30.427159 2026] [security2:error] [pid 872418:tid 872674] [client 20.215.191.139:52640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/02.php"] [unique_id "amuWZlymN6QYcoA7XB5OVQAAAH4"]
[Thu Jul 30 13:22:30.555109 2026] [security2:error] [pid 872418:tid 872622] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZlymN6QYcoA7XB5OTAAAAEo"]
[Thu Jul 30 13:22:30.555144 2026] [security2:error] [pid 872418:tid 872622] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZlymN6QYcoA7XB5OTAAAAEo"]
[Thu Jul 30 13:22:30.580192 2026] [security2:error] [pid 872418:tid 872573] [client 179.64.21.229:53766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWZlymN6QYcoA7XB5OXQAAABk"]
[Thu Jul 30 13:22:30.583568 2026] [security2:error] [pid 872418:tid 872573] [client 179.64.21.229:53766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWZlymN6QYcoA7XB5OXQAAABk"]
[Thu Jul 30 13:22:30.597508 2026] [autoindex:error] [pid 872418:tid 872587] [client 170.106.180.153:44758] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_da8a69f1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:30.903950 2026] [security2:error] [pid 872418:tid 872609] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZlymN6QYcoA7XB5OYAAAAD0"]
[Thu Jul 30 13:22:30.904004 2026] [security2:error] [pid 872418:tid 872609] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZlymN6QYcoA7XB5OYAAAAD0"]
[Thu Jul 30 13:22:31.242445 2026] [security2:error] [pid 872418:tid 872661] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZ1ymN6QYcoA7XB5OdAAAAHE"]
[Thu Jul 30 13:22:31.242473 2026] [security2:error] [pid 872418:tid 872661] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZ1ymN6QYcoA7XB5OdAAAAHE"]
[Thu Jul 30 13:22:31.575908 2026] [security2:error] [pid 872418:tid 872617] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZ1ymN6QYcoA7XB5OgQAAAEU"]
[Thu Jul 30 13:22:31.575939 2026] [security2:error] [pid 872418:tid 872617] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZ1ymN6QYcoA7XB5OgQAAAEU"]
[Thu Jul 30 13:22:31.704371 2026] [security2:error] [pid 872418:tid 872424] [remote 103.75.185.95:52104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuWZ1ymN6QYcoA7XB5OhQAALQU"]
[Thu Jul 30 13:22:31.910476 2026] [security2:error] [pid 872418:tid 872575] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZ1ymN6QYcoA7XB5OhgAAABs"]
[Thu Jul 30 13:22:31.910505 2026] [security2:error] [pid 872418:tid 872575] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWZ1ymN6QYcoA7XB5OhgAAABs"]
[Thu Jul 30 13:22:32.242556 2026] [security2:error] [pid 872418:tid 872554] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaFymN6QYcoA7XB5OjQAAAAY"]
[Thu Jul 30 13:22:32.242581 2026] [security2:error] [pid 872418:tid 872554] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaFymN6QYcoA7XB5OjQAAAAY"]
[Thu Jul 30 13:22:32.577462 2026] [security2:error] [pid 872418:tid 872606] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaFymN6QYcoA7XB5OlAAAADo"]
[Thu Jul 30 13:22:32.577489 2026] [security2:error] [pid 872418:tid 872606] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaFymN6QYcoA7XB5OlAAAADo"]
[Thu Jul 30 13:22:32.914966 2026] [security2:error] [pid 872418:tid 872582] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaFymN6QYcoA7XB5OngAAACI"]
[Thu Jul 30 13:22:32.915006 2026] [security2:error] [pid 872418:tid 872582] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaFymN6QYcoA7XB5OngAAACI"]
[Thu Jul 30 13:22:32.976563 2026] [security2:error] [pid 872418:tid 872659] [client 68.221.186.136:8424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuWaFymN6QYcoA7XB5OpQAAAG8"]
[Thu Jul 30 13:22:33.280337 2026] [security2:error] [pid 872418:tid 872598] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaVymN6QYcoA7XB5OpgAAADI"]
[Thu Jul 30 13:22:33.280373 2026] [security2:error] [pid 872418:tid 872598] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaVymN6QYcoA7XB5OpgAAADI"]
[Thu Jul 30 13:22:33.620016 2026] [security2:error] [pid 872418:tid 872664] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaVymN6QYcoA7XB5OrgAAAHQ"]
[Thu Jul 30 13:22:33.620044 2026] [security2:error] [pid 872418:tid 872664] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaVymN6QYcoA7XB5OrgAAAHQ"]
[Thu Jul 30 13:22:33.959430 2026] [security2:error] [pid 872418:tid 872561] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaVymN6QYcoA7XB5OtQAAAA0"]
[Thu Jul 30 13:22:33.959459 2026] [security2:error] [pid 872418:tid 872561] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWaVymN6QYcoA7XB5OtQAAAA0"]
[Thu Jul 30 13:22:34.101122 2026] [security2:error] [pid 872418:tid 872441] [remote 57.141.0.61:50540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuWalymN6QYcoA7XB5OwAAAChY"]
[Thu Jul 30 13:22:34.282269 2026] [security2:error] [pid 872418:tid 872648] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWaVymN6QYcoA7XB5OtAAAZH4"]
[Thu Jul 30 13:22:34.300862 2026] [security2:error] [pid 872418:tid 872635] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWalymN6QYcoA7XB5OvwAAAFc"]
[Thu Jul 30 13:22:34.300888 2026] [security2:error] [pid 872418:tid 872635] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWalymN6QYcoA7XB5OvwAAAFc"]
[Thu Jul 30 13:22:34.626757 2026] [security2:error] [pid 872418:tid 872555] [client 68.221.186.136:4442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuWalymN6QYcoA7XB5O0AAAAAc"]
[Thu Jul 30 13:22:34.629317 2026] [security2:error] [pid 872418:tid 872584] [client 20.215.191.139:52681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/infos.php"] [unique_id "amuWalymN6QYcoA7XB5O0QAAACQ"]
[Thu Jul 30 13:22:34.636952 2026] [security2:error] [pid 872418:tid 872574] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWalymN6QYcoA7XB5OywAAABo"]
[Thu Jul 30 13:22:34.637004 2026] [security2:error] [pid 872418:tid 872574] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWalymN6QYcoA7XB5OywAAABo"]
[Thu Jul 30 13:22:34.987366 2026] [security2:error] [pid 872418:tid 872612] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWalymN6QYcoA7XB5O0gAAAEA"]
[Thu Jul 30 13:22:34.987396 2026] [security2:error] [pid 872418:tid 872612] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWalymN6QYcoA7XB5O0gAAAEA"]
[Thu Jul 30 13:22:35.321475 2026] [security2:error] [pid 872418:tid 872620] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWa1ymN6QYcoA7XB5O3QAAAEg"]
[Thu Jul 30 13:22:35.321505 2026] [security2:error] [pid 872418:tid 872620] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWa1ymN6QYcoA7XB5O3QAAAEg"]
[Thu Jul 30 13:22:35.416605 2026] [proxy:error] [pid 872418:tid 872563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:35.416688 2026] [proxy_http:error] [pid 872418:tid 872563] [client 34.233.129.35:1101] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:35.417445 2026] [proxy:error] [pid 872418:tid 872563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:35.417501 2026] [proxy_http:error] [pid 872418:tid 872563] [client 34.233.129.35:1101] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:35.663479 2026] [security2:error] [pid 872418:tid 872659] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWa1ymN6QYcoA7XB5O5wAAAG8"]
[Thu Jul 30 13:22:35.663506 2026] [security2:error] [pid 872418:tid 872659] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWa1ymN6QYcoA7XB5O5wAAAG8"]
[Thu Jul 30 13:22:36.008032 2026] [security2:error] [pid 872418:tid 872598] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWa1ymN6QYcoA7XB5O7AAAADI"]
[Thu Jul 30 13:22:36.008093 2026] [security2:error] [pid 872418:tid 872598] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWa1ymN6QYcoA7XB5O7AAAADI"]
[Thu Jul 30 13:22:36.201140 2026] [autoindex:error] [pid 872418:tid 872557] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:36.201835 2026] [security2:error] [pid 872418:tid 872557] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWbFymN6QYcoA7XB5O9gAAAAk"]
[Thu Jul 30 13:22:36.516544 2026] [security2:error] [pid 872418:tid 872654] [client 74.7.241.181:60082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.frg.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuWbFymN6QYcoA7XB5O_gAAAGo"]
[Thu Jul 30 13:22:36.543459 2026] [security2:error] [pid 872418:tid 872566] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWbFymN6QYcoA7XB5O9wAAABI"]
[Thu Jul 30 13:22:36.543487 2026] [security2:error] [pid 872418:tid 872566] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWbFymN6QYcoA7XB5O9wAAABI"]
[Thu Jul 30 13:22:36.876357 2026] [security2:error] [pid 872418:tid 872632] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWbFymN6QYcoA7XB5O_wAAAFQ"]
[Thu Jul 30 13:22:36.876386 2026] [security2:error] [pid 872418:tid 872632] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWbFymN6QYcoA7XB5O_wAAAFQ"]
[Thu Jul 30 13:22:36.931698 2026] [security2:error] [pid 872418:tid 872550] [client 68.221.186.136:5541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuWbFymN6QYcoA7XB5PBgAAAAI"]
[Thu Jul 30 13:22:37.663823 2026] [security2:error] [pid 872418:tid 872616] [client 68.221.186.136:17115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuWbVymN6QYcoA7XB5PIgAAAEQ"]
[Thu Jul 30 13:22:37.718105 2026] [autoindex:error] [pid 872418:tid 872613] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:37.718784 2026] [security2:error] [pid 872418:tid 872613] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWbVymN6QYcoA7XB5PIQAAAEE"]
[Thu Jul 30 13:22:37.949778 2026] [security2:error] [pid 872418:tid 872576] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWbVymN6QYcoA7XB5PEAAAABw"]
[Thu Jul 30 13:22:38.063428 2026] [security2:error] [pid 872418:tid 872668] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWbVymN6QYcoA7XB5PJgAAAHg"]
[Thu Jul 30 13:22:38.063465 2026] [security2:error] [pid 872418:tid 872668] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWbVymN6QYcoA7XB5PJgAAAHg"]
[Thu Jul 30 13:22:38.207191 2026] [autoindex:error] [pid 872418:tid 872589] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:38.207860 2026] [security2:error] [pid 872418:tid 872589] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWblymN6QYcoA7XB5PMQAAACk"]
[Thu Jul 30 13:22:38.292562 2026] [security2:error] [pid 872418:tid 872577] [client 68.221.186.136:29551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuWblymN6QYcoA7XB5PNAAAAB0"]
[Thu Jul 30 13:22:38.362512 2026] [autoindex:error] [pid 872418:tid 872665] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:38.363503 2026] [security2:error] [pid 872418:tid 872665] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWblymN6QYcoA7XB5PNgAAAHU"]
[Thu Jul 30 13:22:38.498652 2026] [security2:error] [pid 872418:tid 872432] [remote 57.141.0.4:33018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/361873924/feed/rss2/"] [unique_id "amuWblymN6QYcoA7XB5POwAAWQ0"]
[Thu Jul 30 13:22:38.513004 2026] [autoindex:error] [pid 872418:tid 872607] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:38.513805 2026] [security2:error] [pid 872418:tid 872607] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWblymN6QYcoA7XB5POQAAADs"]
[Thu Jul 30 13:22:38.671111 2026] [autoindex:error] [pid 872418:tid 872581] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:38.672150 2026] [security2:error] [pid 872418:tid 872581] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWblymN6QYcoA7XB5PQgAAACE"]
[Thu Jul 30 13:22:38.696458 2026] [security2:error] [pid 872418:tid 872483] [remote 47.86.33.52:5750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/wp-login.php"] [unique_id "amuWblymN6QYcoA7XB5PQwAAT0A"]
[Thu Jul 30 13:22:38.750270 2026] [security2:error] [pid 872418:tid 872655] [client 66.249.73.97:55707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuWbVymN6QYcoA7XB5PKQAAAGs"]
[Thu Jul 30 13:22:38.816167 2026] [autoindex:error] [pid 872418:tid 872549] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:38.816920 2026] [security2:error] [pid 872418:tid 872549] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWblymN6QYcoA7XB5PSwAAAAE"]
[Thu Jul 30 13:22:38.961122 2026] [autoindex:error] [pid 872418:tid 872560] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:38.961743 2026] [security2:error] [pid 872418:tid 872560] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWblymN6QYcoA7XB5PVQAAAAw"]
[Thu Jul 30 13:22:39.102963 2026] [autoindex:error] [pid 872418:tid 872606] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:39.103660 2026] [security2:error] [pid 872418:tid 872606] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWb1ymN6QYcoA7XB5PawAAADo"]
[Thu Jul 30 13:22:39.248095 2026] [autoindex:error] [pid 872418:tid 872590] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:39.248775 2026] [security2:error] [pid 872418:tid 872590] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWb1ymN6QYcoA7XB5PcAAAACo"]
[Thu Jul 30 13:22:39.353748 2026] [security2:error] [pid 872418:tid 872562] [client 68.221.186.136:11147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuWb1ymN6QYcoA7XB5PcwAAAA4"]
[Thu Jul 30 13:22:39.600730 2026] [security2:error] [pid 872418:tid 872548] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWb1ymN6QYcoA7XB5PdQAAAAA"]
[Thu Jul 30 13:22:39.600765 2026] [security2:error] [pid 872418:tid 872548] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWb1ymN6QYcoA7XB5PdQAAAAA"]
[Thu Jul 30 13:22:39.746522 2026] [autoindex:error] [pid 872418:tid 872598] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:39.747191 2026] [security2:error] [pid 872418:tid 872598] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWb1ymN6QYcoA7XB5PggAAADI"]
[Thu Jul 30 13:22:39.862156 2026] [security2:error] [pid 872418:tid 872594] [client 20.215.191.139:51939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/updates.php"] [unique_id "amuWb1ymN6QYcoA7XB5PiQAAAC4"]
[Thu Jul 30 13:22:39.867554 2026] [security2:error] [pid 872418:tid 872636] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWb1ymN6QYcoA7XB5PbwAAWDQ"]
[Thu Jul 30 13:22:39.890438 2026] [autoindex:error] [pid 872418:tid 872641] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:39.891103 2026] [security2:error] [pid 872418:tid 872641] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWb1ymN6QYcoA7XB5PigAAAF0"]
[Thu Jul 30 13:22:40.042373 2026] [autoindex:error] [pid 872418:tid 872566] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:40.043078 2026] [security2:error] [pid 872418:tid 872566] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWcFymN6QYcoA7XB5PjwAAABI"]
[Thu Jul 30 13:22:40.172571 2026] [security2:error] [pid 872418:tid 872568] [client 68.221.186.136:1548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuWcFymN6QYcoA7XB5PmAAAABQ"]
[Thu Jul 30 13:22:40.186709 2026] [autoindex:error] [pid 872418:tid 872561] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:40.187383 2026] [security2:error] [pid 872418:tid 872561] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWcFymN6QYcoA7XB5PlwAAAA0"]
[Thu Jul 30 13:22:40.337891 2026] [autoindex:error] [pid 872418:tid 872629] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:40.338491 2026] [security2:error] [pid 872418:tid 872629] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWcFymN6QYcoA7XB5PmQAAAFE"]
[Thu Jul 30 13:22:40.492604 2026] [autoindex:error] [pid 872418:tid 872619] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:40.493579 2026] [security2:error] [pid 872418:tid 872619] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWcFymN6QYcoA7XB5PnwAAAEc"]
[Thu Jul 30 13:22:40.575103 2026] [core:notice] [pid 872418:tid 872615] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:40.691444 2026] [autoindex:error] [pid 872418:tid 872672] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:40.692177 2026] [security2:error] [pid 872418:tid 872672] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWcFymN6QYcoA7XB5PpAAAAHw"]
[Thu Jul 30 13:22:41.080555 2026] [security2:error] [pid 872418:tid 872600] [client 179.64.21.229:44820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWcVymN6QYcoA7XB5PqwAAADQ"]
[Thu Jul 30 13:22:41.087846 2026] [security2:error] [pid 872418:tid 872600] [client 179.64.21.229:44820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWcVymN6QYcoA7XB5PqwAAADQ"]
[Thu Jul 30 13:22:41.267596 2026] [autoindex:error] [pid 872418:tid 872631] [client 85.204.70.102:56244] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:41.268254 2026] [security2:error] [pid 872418:tid 872631] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWcVymN6QYcoA7XB5PrwAAAFM"]
[Thu Jul 30 13:22:41.605481 2026] [security2:error] [pid 872418:tid 872562] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWcVymN6QYcoA7XB5PswAAAA4"]
[Thu Jul 30 13:22:41.605508 2026] [security2:error] [pid 872418:tid 872562] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWcVymN6QYcoA7XB5PswAAAA4"]
[Thu Jul 30 13:22:41.942747 2026] [security2:error] [pid 872418:tid 872603] [client 85.204.70.102:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWcVymN6QYcoA7XB5PuwAAADc"]
[Thu Jul 30 13:22:41.942777 2026] [security2:error] [pid 872418:tid 872603] [client 85.204.70.102:56244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWcVymN6QYcoA7XB5PuwAAADc"]
[Thu Jul 30 13:22:41.947340 2026] [core:notice] [pid 872418:tid 872539] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:42.039149 2026] [security2:error] [pid 872418:tid 872610] [client 20.215.191.139:40466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/user.php"] [unique_id "amuWclymN6QYcoA7XB5PwgAAAD4"]
[Thu Jul 30 13:22:42.370711 2026] [security2:error] [pid 872418:tid 872537] [remote 74.7.243.224:48930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/formation-sur-les-techniques-agricoles-en-faveur-des-jeunes-de-16-a-25-ans-a-kahororo-kawizi-et-rutemba/feed/js/img/js/fonts/css/uploads/partners/indexf.php"] [unique_id "amuWclymN6QYcoA7XB5PzgAAT3Y"], referer: https://aded-rdc.org/formation-sur-les-techniques-agricoles-en-faveur-des-jeunes-de-16-a-25-ans-a-kahororo-kawizi-et-rutemba/feed/js/img/js/fonts/css/uploads/partners/partner.html
[Thu Jul 30 13:22:42.432919 2026] [security2:error] [pid 872418:tid 872661] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWclymN6QYcoA7XB5PzAAAAHE"]
[Thu Jul 30 13:22:42.432945 2026] [security2:error] [pid 872418:tid 872661] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWclymN6QYcoA7XB5PzAAAAHE"]
[Thu Jul 30 13:22:42.829905 2026] [security2:error] [pid 872418:tid 872532] [remote 80.150.6.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.6.150.80.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/wp-includes/wp-login.php"] [unique_id "amuWclymN6QYcoA7XB5P0gAAYHE"]
[Thu Jul 30 13:22:43.054578 2026] [security2:error] [pid 872418:tid 872560] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWclymN6QYcoA7XB5P3AAAAAw"]
[Thu Jul 30 13:22:43.054605 2026] [security2:error] [pid 872418:tid 872560] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWclymN6QYcoA7XB5P3AAAAAw"]
[Thu Jul 30 13:22:43.403450 2026] [security2:error] [pid 872418:tid 872591] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWc1ymN6QYcoA7XB5P4QAAACs"]
[Thu Jul 30 13:22:43.403478 2026] [security2:error] [pid 872418:tid 872591] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWc1ymN6QYcoA7XB5P4QAAACs"]
[Thu Jul 30 13:22:43.755453 2026] [security2:error] [pid 872418:tid 872578] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWc1ymN6QYcoA7XB5P7AAAAB4"]
[Thu Jul 30 13:22:43.755481 2026] [security2:error] [pid 872418:tid 872578] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWc1ymN6QYcoA7XB5P7AAAAB4"]
[Thu Jul 30 13:22:43.784845 2026] [security2:error] [pid 872418:tid 872655] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWc1ymN6QYcoA7XB5P4AAAa20"]
[Thu Jul 30 13:22:43.956141 2026] [security2:error] [pid 872418:tid 872581] [client 68.221.186.136:29512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuWc1ymN6QYcoA7XB5P-QAAACE"]
[Thu Jul 30 13:22:43.984535 2026] [core:notice] [pid 872418:tid 872542] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:44.103743 2026] [security2:error] [pid 872418:tid 872589] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWc1ymN6QYcoA7XB5P-AAAACk"]
[Thu Jul 30 13:22:44.103771 2026] [security2:error] [pid 872418:tid 872589] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWc1ymN6QYcoA7XB5P-AAAACk"]
[Thu Jul 30 13:22:44.261247 2026] [autoindex:error] [pid 872418:tid 872656] [client 85.204.70.102:40618] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-content/plugins/classic-editor/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:44.261860 2026] [security2:error] [pid 872418:tid 872656] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWdFymN6QYcoA7XB5P_wAAAGw"]
[Thu Jul 30 13:22:44.381694 2026] [security2:error] [pid 872418:tid 872421] [remote 5.161.62.209:57078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.alshateeintl.com"] [uri "/.env"] [unique_id "amuWdFymN6QYcoA7XB5QBQAANwI"]
[Thu Jul 30 13:22:44.609919 2026] [security2:error] [pid 872418:tid 872594] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdFymN6QYcoA7XB5QBgAAAC4"]
[Thu Jul 30 13:22:44.609948 2026] [security2:error] [pid 872418:tid 872594] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdFymN6QYcoA7XB5QBgAAAC4"]
[Thu Jul 30 13:22:44.826841 2026] [core:notice] [pid 872418:tid 872636] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:44.961083 2026] [security2:error] [pid 872418:tid 872661] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdFymN6QYcoA7XB5QEAAAAHE"]
[Thu Jul 30 13:22:44.961121 2026] [security2:error] [pid 872418:tid 872661] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdFymN6QYcoA7XB5QEAAAAHE"]
[Thu Jul 30 13:22:45.364872 2026] [autoindex:error] [pid 872418:tid 872574] [client 85.204.70.102:40618] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-content/plugins/contact-form-7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:45.365527 2026] [security2:error] [pid 872418:tid 872574] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWdVymN6QYcoA7XB5QGwAAABo"]
[Thu Jul 30 13:22:45.455957 2026] [core:notice] [pid 872418:tid 872567] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:45.719538 2026] [security2:error] [pid 872418:tid 872672] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdVymN6QYcoA7XB5QIAAAAHw"]
[Thu Jul 30 13:22:45.719566 2026] [security2:error] [pid 872418:tid 872672] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdVymN6QYcoA7XB5QIAAAAHw"]
[Thu Jul 30 13:22:45.753414 2026] [security2:error] [pid 872418:tid 872571] [client 68.221.186.136:17142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuWdVymN6QYcoA7XB5QJAAAABc"]
[Thu Jul 30 13:22:45.921043 2026] [autoindex:error] [pid 872418:tid 872671] [client 85.204.70.102:40618] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:45.921721 2026] [security2:error] [pid 872418:tid 872671] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWdVymN6QYcoA7XB5QKAAAAHs"]
[Thu Jul 30 13:22:45.975941 2026] [security2:error] [pid 872418:tid 872426] [remote 213.180.203.82:52056] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/tag/logistics/"] [unique_id "amuWdVymN6QYcoA7XB5QLAAAcgc"]
[Thu Jul 30 13:22:46.080351 2026] [autoindex:error] [pid 872418:tid 872623] [client 85.204.70.102:40618] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:46.081110 2026] [security2:error] [pid 872418:tid 872623] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWdlymN6QYcoA7XB5QLQAAAEs"]
[Thu Jul 30 13:22:46.237192 2026] [security2:error] [pid 872418:tid 872645] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "siatfc.com"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "amuWdlymN6QYcoA7XB5QMgAAAGE"]
[Thu Jul 30 13:22:46.582631 2026] [security2:error] [pid 872418:tid 872666] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdlymN6QYcoA7XB5QNQAAAHY"]
[Thu Jul 30 13:22:46.582658 2026] [security2:error] [pid 872418:tid 872666] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdlymN6QYcoA7XB5QNQAAAHY"]
[Thu Jul 30 13:22:46.926164 2026] [security2:error] [pid 872418:tid 872614] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdlymN6QYcoA7XB5QOgAAAEI"]
[Thu Jul 30 13:22:46.926201 2026] [security2:error] [pid 872418:tid 872614] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWdlymN6QYcoA7XB5QOgAAAEI"]
[Thu Jul 30 13:22:47.029221 2026] [security2:error] [pid 872418:tid 872563] [client 68.221.186.136:8166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuWd1ymN6QYcoA7XB5QRAAAAA8"]
[Thu Jul 30 13:22:47.106923 2026] [core:notice] [pid 872418:tid 872642] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:47.281757 2026] [security2:error] [pid 872418:tid 872638] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWd1ymN6QYcoA7XB5QRQAAAFo"]
[Thu Jul 30 13:22:47.281792 2026] [security2:error] [pid 872418:tid 872638] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWd1ymN6QYcoA7XB5QRQAAAFo"]
[Thu Jul 30 13:22:47.641635 2026] [security2:error] [pid 872418:tid 872670] [client 85.204.70.102:40618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWd1ymN6QYcoA7XB5QSgAAAHo"]
[Thu Jul 30 13:22:47.641672 2026] [security2:error] [pid 872418:tid 872670] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuWd1ymN6QYcoA7XB5QSgAAAHo"]
[Thu Jul 30 13:22:47.973056 2026] [core:notice] [pid 872418:tid 872472] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:48.100596 2026] [security2:error] [pid 872418:tid 872660] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuWd1ymN6QYcoA7XB5QVgAAAHA"]
[Thu Jul 30 13:22:48.398245 2026] [core:notice] [pid 872418:tid 872617] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:48.470781 2026] [security2:error] [pid 872418:tid 872657] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuWeFymN6QYcoA7XB5QXwAAAG0"]
[Thu Jul 30 13:22:48.625091 2026] [security2:error] [pid 872418:tid 872585] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "siatfc.com"] [uri "/wp-content/index.php"] [unique_id "amuWeFymN6QYcoA7XB5QawAAACU"]
[Thu Jul 30 13:22:48.780519 2026] [security2:error] [pid 872418:tid 872662] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "siatfc.com"] [uri "/wp-content/plugins/index.php"] [unique_id "amuWeFymN6QYcoA7XB5QbQAAAHI"]
[Thu Jul 30 13:22:48.939698 2026] [security2:error] [pid 872418:tid 872548] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "siatfc.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuWeFymN6QYcoA7XB5QcQAAAAA"]
[Thu Jul 30 13:22:49.144191 2026] [autoindex:error] [pid 872418:tid 872582] [client 85.204.70.102:40618] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:49.144852 2026] [security2:error] [pid 872418:tid 872582] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWeVymN6QYcoA7XB5QegAAACI"]
[Thu Jul 30 13:22:49.210966 2026] [security2:error] [pid 872418:tid 872551] [client 185.191.171.16:24734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/26/liga-dos-campeoes-inter-de-milao-vence-e-avanca-barca-esta-eliminado/"] [unique_id "amuWeVymN6QYcoA7XB5QfwAAAAM"]
[Thu Jul 30 13:22:49.211089 2026] [security2:error] [pid 872418:tid 872551] [client 185.191.171.16:24734] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/26/liga-dos-campeoes-inter-de-milao-vence-e-avanca-barca-esta-eliminado/"] [unique_id "amuWeVymN6QYcoA7XB5QfwAAAAM"]
[Thu Jul 30 13:22:49.429440 2026] [core:notice] [pid 872418:tid 872556] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:49.501395 2026] [security2:error] [pid 872418:tid 872599] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/wp-admin/index.php"] [unique_id "amuWeVymN6QYcoA7XB5QhAAAADM"]
[Thu Jul 30 13:22:49.892013 2026] [autoindex:error] [pid 872418:tid 872628] [client 85.204.70.102:40618] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_c7e2d6e8/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:22:49.892711 2026] [security2:error] [pid 872418:tid 872628] [client 85.204.70.102:40618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "siatfc.com"] [uri "/cgi-sys/403.html"] [unique_id "amuWeVymN6QYcoA7XB5QkgAAAFA"]
[Thu Jul 30 13:22:50.352886 2026] [core:notice] [pid 872418:tid 872567] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:22:50.856079 2026] [security2:error] [pid 872418:tid 872605] [client 20.215.191.139:51923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/admin-ajax.php"] [unique_id "amuWelymN6QYcoA7XB5QpwAAADk"]
[Thu Jul 30 13:22:51.554732 2026] [security2:error] [pid 872418:tid 872548] [client 179.64.21.229:45813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWe1ymN6QYcoA7XB5QtwAAAAA"]
[Thu Jul 30 13:22:51.558316 2026] [security2:error] [pid 872418:tid 872548] [client 179.64.21.229:45813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWe1ymN6QYcoA7XB5QtwAAAAA"]
[Thu Jul 30 13:22:52.285317 2026] [security2:error] [pid 872418:tid 872664] [client 20.215.191.139:50841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/alfa.php"] [unique_id "amuWfFymN6QYcoA7XB5QyAAAAHQ"]
[Thu Jul 30 13:22:52.287242 2026] [security2:error] [pid 872418:tid 872566] [client 20.52.125.110:9573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.tmb/LA.php"] [unique_id "amuWfFymN6QYcoA7XB5QyQAAABI"]
[Thu Jul 30 13:22:52.401682 2026] [security2:error] [pid 872418:tid 872663] [client 68.221.186.136:6435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuWfFymN6QYcoA7XB5QygAAAHM"]
[Thu Jul 30 13:22:52.975541 2026] [security2:error] [pid 872418:tid 872604] [client 20.52.125.110:9586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.tmb/admin.php"] [unique_id "amuWfFymN6QYcoA7XB5Q1QAAADg"]
[Thu Jul 30 13:22:53.241123 2026] [proxy:error] [pid 872418:tid 872670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:53.241186 2026] [proxy_http:error] [pid 872418:tid 872670] [client 20.215.191.139:50842] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:53.241762 2026] [proxy:error] [pid 872418:tid 872670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:22:53.241804 2026] [proxy_http:error] [pid 872418:tid 872670] [client 20.215.191.139:50842] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:22:53.501704 2026] [security2:error] [pid 872418:tid 872588] [client 20.52.125.110:9561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.tmb/class_api.php"] [unique_id "amuWfVymN6QYcoA7XB5Q4AAAACg"]
[Thu Jul 30 13:22:53.717513 2026] [security2:error] [pid 872418:tid 872481] [remote 216.73.217.142:54195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuWfVymN6QYcoA7XB5Q5gAAHD4"]
[Thu Jul 30 13:22:54.031306 2026] [security2:error] [pid 872418:tid 872571] [client 20.52.125.110:9103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuWflymN6QYcoA7XB5Q7wAAABc"]
[Thu Jul 30 13:22:54.073819 2026] [security2:error] [pid 872418:tid 872645] [client 20.215.191.139:52037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/hehe.php"] [unique_id "amuWflymN6QYcoA7XB5Q8wAAAGE"]
[Thu Jul 30 13:22:54.416190 2026] [security2:error] [pid 872418:tid 872643] [client 68.221.186.136:6407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuWflymN6QYcoA7XB5Q-gAAAF8"]
[Thu Jul 30 13:22:54.479643 2026] [security2:error] [pid 872418:tid 872554] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWfVymN6QYcoA7XB5Q7gAABhA"]
[Thu Jul 30 13:22:54.778073 2026] [security2:error] [pid 872418:tid 872603] [client 20.215.191.139:20551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/rk2.php"] [unique_id "amuWflymN6QYcoA7XB5Q_wAAADc"]
[Thu Jul 30 13:22:54.821791 2026] [security2:error] [pid 872418:tid 872557] [client 20.52.125.110:9594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuWflymN6QYcoA7XB5Q-wAAAAk"]
[Thu Jul 30 13:22:55.367164 2026] [security2:error] [pid 872418:tid 872556] [client 68.221.186.136:6402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuWf1ymN6QYcoA7XB5RDgAAAAg"]
[Thu Jul 30 13:22:55.368251 2026] [security2:error] [pid 872418:tid 872635] [client 20.52.125.110:9548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuWf1ymN6QYcoA7XB5RDwAAAFc"]
[Thu Jul 30 13:22:55.479240 2026] [security2:error] [pid 872418:tid 872565] [client 2a03:2880:f800:46:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWflymN6QYcoA7XB5RBgAAETo"]
[Thu Jul 30 13:22:55.568596 2026] [security2:error] [pid 872418:tid 872648] [client 20.215.191.139:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/setup-config.php"] [unique_id "amuWf1ymN6QYcoA7XB5RFAAAAGQ"]
[Thu Jul 30 13:22:55.889393 2026] [security2:error] [pid 872418:tid 872660] [client 20.52.125.110:9578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/991176.php"] [unique_id "amuWf1ymN6QYcoA7XB5RGwAAAHA"]
[Thu Jul 30 13:22:56.225828 2026] [security2:error] [pid 872418:tid 872631] [client 20.215.191.139:52041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/a7.php"] [unique_id "amuWgFymN6QYcoA7XB5RHwAAAFM"]
[Thu Jul 30 13:22:56.316507 2026] [security2:error] [pid 872418:tid 872591] [client 20.52.125.110:9092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuWgFymN6QYcoA7XB5RJAAAACs"]
[Thu Jul 30 13:22:56.901210 2026] [security2:error] [pid 872418:tid 872573] [client 20.52.125.110:9094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuWgFymN6QYcoA7XB5RMgAAABk"]
[Thu Jul 30 13:22:56.985646 2026] [security2:error] [pid 872418:tid 872666] [client 20.215.191.139:50860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/f7.php"] [unique_id "amuWgFymN6QYcoA7XB5ROAAAAHY"]
[Thu Jul 30 13:22:57.359855 2026] [security2:error] [pid 872418:tid 872552] [client 47.141.206.134:32833] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "qhp.nyx.temporary.site"] [uri "/wp-comments-post.php"] [unique_id "amuWgFymN6QYcoA7XB5RKwAAAAQ"]
[Thu Jul 30 13:22:57.385326 2026] [security2:error] [pid 872418:tid 872603] [client 20.52.125.110:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuWgVymN6QYcoA7XB5RPgAAADc"]
[Thu Jul 30 13:22:57.452108 2026] [security2:error] [pid 872418:tid 872625] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWgFymN6QYcoA7XB5RMQAAAE0"]
[Thu Jul 30 13:22:57.906680 2026] [security2:error] [pid 872418:tid 872647] [client 20.52.125.110:9540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuWgVymN6QYcoA7XB5RSAAAAGM"]
[Thu Jul 30 13:22:57.937611 2026] [security2:error] [pid 872418:tid 872552] [client 47.141.206.134:32833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "qhp.nyx.temporary.site"] [uri "/wp-comments-post.php"] [unique_id "amuWgFymN6QYcoA7XB5RKwAAAAQ"]
[Thu Jul 30 13:22:57.937659 2026] [security2:error] [pid 872418:tid 872552] [client 47.141.206.134:32833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "qhp.nyx.temporary.site"] [uri "/wp-comments-post.php"] [unique_id "amuWgFymN6QYcoA7XB5RKwAAAAQ"]
[Thu Jul 30 13:22:58.395553 2026] [security2:error] [pid 872418:tid 872619] [client 20.52.125.110:9550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuWglymN6QYcoA7XB5RUgAAAEc"]
[Thu Jul 30 13:22:59.050572 2026] [security2:error] [pid 872418:tid 872559] [client 20.52.125.110:9572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuWg1ymN6QYcoA7XB5RYgAAAAs"]
[Thu Jul 30 13:22:59.493022 2026] [security2:error] [pid 872418:tid 872577] [client 20.52.125.110:9562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuWg1ymN6QYcoA7XB5RbgAAAB0"]
[Thu Jul 30 13:22:59.883145 2026] [security2:error] [pid 872418:tid 872570] [client 20.215.191.139:40478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/nw.php"] [unique_id "amuWg1ymN6QYcoA7XB5RewAAABY"]
[Thu Jul 30 13:22:59.960782 2026] [security2:error] [pid 872418:tid 872609] [client 20.52.125.110:9581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuWg1ymN6QYcoA7XB5RfwAAAD0"]
[Thu Jul 30 13:23:00.207523 2026] [core:notice] [pid 872418:tid 872542] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:00.461440 2026] [core:notice] [pid 872418:tid 872535] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:00.559145 2026] [security2:error] [pid 872418:tid 872574] [client 20.52.125.110:9556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuWhFymN6QYcoA7XB5RjwAAABo"]
[Thu Jul 30 13:23:00.645677 2026] [security2:error] [pid 872418:tid 872558] [client 20.215.191.139:41949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/ova.php"] [unique_id "amuWhFymN6QYcoA7XB5RkwAAAAo"]
[Thu Jul 30 13:23:01.027627 2026] [security2:error] [pid 872418:tid 872672] [client 20.52.125.110:9590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuWhVymN6QYcoA7XB5RmwAAAHw"]
[Thu Jul 30 13:23:01.342927 2026] [security2:error] [pid 872418:tid 872671] [client 20.215.191.139:52719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/robots.php"] [unique_id "amuWhVymN6QYcoA7XB5RpQAAAHs"]
[Thu Jul 30 13:23:01.589251 2026] [security2:error] [pid 872418:tid 872597] [client 20.52.125.110:9564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuWhVymN6QYcoA7XB5RqwAAADE"]
[Thu Jul 30 13:23:02.140069 2026] [security2:error] [pid 872418:tid 872601] [client 179.64.21.229:23645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWhlymN6QYcoA7XB5RtQAAADU"]
[Thu Jul 30 13:23:02.143963 2026] [security2:error] [pid 872418:tid 872601] [client 179.64.21.229:23645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWhlymN6QYcoA7XB5RtQAAADU"]
[Thu Jul 30 13:23:02.306091 2026] [security2:error] [pid 872418:tid 872642] [client 20.215.191.139:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/alf.php"] [unique_id "amuWhlymN6QYcoA7XB5RvAAAAF4"]
[Thu Jul 30 13:23:02.339562 2026] [security2:error] [pid 872418:tid 872661] [client 20.52.125.110:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuWhlymN6QYcoA7XB5RvQAAAHE"]
[Thu Jul 30 13:23:02.812916 2026] [security2:error] [pid 872418:tid 872550] [client 20.52.125.110:9561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuWhlymN6QYcoA7XB5RxwAAAAI"]
[Thu Jul 30 13:23:03.265374 2026] [security2:error] [pid 872418:tid 872612] [client 20.52.125.110:9567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuWh1ymN6QYcoA7XB5R1AAAAEA"]
[Thu Jul 30 13:23:03.295524 2026] [core:notice] [pid 872418:tid 872634] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:03.433144 2026] [security2:error] [pid 872418:tid 872567] [client 20.215.191.139:53248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/feedback.php"] [unique_id "amuWh1ymN6QYcoA7XB5R1gAAABM"]
[Thu Jul 30 13:23:03.819948 2026] [security2:error] [pid 872418:tid 872656] [client 20.52.125.110:9574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/bek.php"] [unique_id "amuWh1ymN6QYcoA7XB5R5AAAAGw"]
[Thu Jul 30 13:23:04.171698 2026] [security2:error] [pid 872418:tid 872599] [client 20.215.191.139:52032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/gettest.php"] [unique_id "amuWiFymN6QYcoA7XB5R6wAAADM"]
[Thu Jul 30 13:23:04.313046 2026] [security2:error] [pid 872418:tid 872654] [client 20.52.125.110:9588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuWiFymN6QYcoA7XB5R7wAAAGo"]
[Thu Jul 30 13:23:04.782375 2026] [security2:error] [pid 872418:tid 872642] [client 20.52.125.110:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/class.api.php"] [unique_id "amuWiFymN6QYcoA7XB5R-QAAAF4"]
[Thu Jul 30 13:23:04.872554 2026] [security2:error] [pid 872418:tid 872661] [client 20.215.191.139:40485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/maint.php"] [unique_id "amuWiFymN6QYcoA7XB5R_QAAAHE"]
[Thu Jul 30 13:23:04.998284 2026] [core:notice] [pid 872418:tid 872669] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:05.304064 2026] [security2:error] [pid 872418:tid 872616] [client 20.52.125.110:9536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/cong.php"] [unique_id "amuWiVymN6QYcoA7XB5SBQAAAEQ"]
[Thu Jul 30 13:23:05.495537 2026] [security2:error] [pid 872418:tid 872613] [client 68.221.186.136:29412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/images/about.php"] [unique_id "amuWiVymN6QYcoA7XB5SDQAAAEE"]
[Thu Jul 30 13:23:05.655843 2026] [security2:error] [pid 872418:tid 872580] [client 20.215.191.139:51929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/files.php"] [unique_id "amuWiVymN6QYcoA7XB5SEQAAACA"]
[Thu Jul 30 13:23:05.865860 2026] [security2:error] [pid 872418:tid 872556] [client 20.52.125.110:9595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/content.php"] [unique_id "amuWiVymN6QYcoA7XB5SFAAAAAg"]
[Thu Jul 30 13:23:06.325664 2026] [security2:error] [pid 872418:tid 872651] [client 20.52.125.110:10955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuWilymN6QYcoA7XB5SHQAAAGc"]
[Thu Jul 30 13:23:06.856868 2026] [security2:error] [pid 872418:tid 872647] [client 20.52.125.110:9113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/elp.php"] [unique_id "amuWilymN6QYcoA7XB5SKwAAAGM"]
[Thu Jul 30 13:23:07.367973 2026] [security2:error] [pid 872418:tid 872558] [client 20.52.125.110:9589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuWi1ymN6QYcoA7XB5SNQAAAAo"]
[Thu Jul 30 13:23:07.410158 2026] [security2:error] [pid 872418:tid 872594] [client 20.215.191.139:51829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/gecko.php"] [unique_id "amuWi1ymN6QYcoA7XB5SNwAAAC4"]
[Thu Jul 30 13:23:07.866527 2026] [security2:error] [pid 872418:tid 872579] [client 20.52.125.110:9551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuWi1ymN6QYcoA7XB5SQQAAAB8"]
[Thu Jul 30 13:23:08.100910 2026] [security2:error] [pid 872418:tid 872612] [client 20.215.191.139:50839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/zwso.php"] [unique_id "amuWjFymN6QYcoA7XB5SSwAAAEA"]
[Thu Jul 30 13:23:08.428449 2026] [security2:error] [pid 872418:tid 872614] [client 20.52.125.110:9119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuWjFymN6QYcoA7XB5STwAAAEI"]
[Thu Jul 30 13:23:08.867149 2026] [security2:error] [pid 872418:tid 872640] [client 20.215.191.139:21592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/13.php"] [unique_id "amuWjFymN6QYcoA7XB5SXAAAAFw"]
[Thu Jul 30 13:23:08.955955 2026] [security2:error] [pid 872418:tid 872603] [client 20.52.125.110:9545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuWjFymN6QYcoA7XB5SXQAAADc"]
[Thu Jul 30 13:23:09.503452 2026] [security2:error] [pid 872418:tid 872553] [client 20.52.125.110:9560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuWjVymN6QYcoA7XB5SagAAAAU"]
[Thu Jul 30 13:23:09.656802 2026] [security2:error] [pid 872418:tid 872566] [client 172.236.9.101:11948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWjVymN6QYcoA7XB5SaAAAABI"]
[Thu Jul 30 13:23:09.936080 2026] [security2:error] [pid 872418:tid 872618] [client 20.52.125.110:9104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuWjVymN6QYcoA7XB5SfAAAAEY"]
[Thu Jul 30 13:23:10.006082 2026] [security2:error] [pid 872418:tid 872642] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWjVymN6QYcoA7XB5ScwAAAF4"]
[Thu Jul 30 13:23:10.311317 2026] [security2:error] [pid 872418:tid 872593] [client 20.215.191.139:51824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/ava.php"] [unique_id "amuWjlymN6QYcoA7XB5SiQAAAC0"]
[Thu Jul 30 13:23:10.524083 2026] [security2:error] [pid 872418:tid 872629] [client 20.52.125.110:9098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuWjlymN6QYcoA7XB5SjAAAAFE"]
[Thu Jul 30 13:23:10.846876 2026] [security2:error] [pid 872418:tid 872560] [client 68.221.186.136:7926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuWjlymN6QYcoA7XB5SlwAAAAw"]
[Thu Jul 30 13:23:11.019033 2026] [security2:error] [pid 872418:tid 872597] [client 20.52.125.110:9555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuWj1ymN6QYcoA7XB5SmQAAADE"]
[Thu Jul 30 13:23:11.290724 2026] [security2:error] [pid 872418:tid 872601] [client 172.236.9.101:25803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/app_dev.php/_profiler/empty/search/results"] [unique_id "amuWj1ymN6QYcoA7XB5SowAAADU"]
[Thu Jul 30 13:23:11.477658 2026] [security2:error] [pid 872418:tid 872609] [client 172.237.109.114:19628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWjlymN6QYcoA7XB5SmAAAAD0"]
[Thu Jul 30 13:23:11.633022 2026] [security2:error] [pid 872418:tid 872661] [client 20.52.125.110:9591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuWj1ymN6QYcoA7XB5SrQAAAHE"]
[Thu Jul 30 13:23:11.992813 2026] [security2:error] [pid 872418:tid 872600] [client 20.215.191.139:21576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/main.php"] [unique_id "amuWj1ymN6QYcoA7XB5SugAAADQ"]
[Thu Jul 30 13:23:12.157964 2026] [security2:error] [pid 872418:tid 872566] [client 68.221.186.136:9902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuWkFymN6QYcoA7XB5SwQAAABI"]
[Thu Jul 30 13:23:12.178804 2026] [security2:error] [pid 872418:tid 872627] [client 20.52.125.110:9577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuWkFymN6QYcoA7XB5SwwAAAE8"]
[Thu Jul 30 13:23:12.383322 2026] [security2:error] [pid 872418:tid 872620] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWj1ymN6QYcoA7XB5StgAAAEg"]
[Thu Jul 30 13:23:12.517957 2026] [security2:error] [pid 872418:tid 872662] [client 179.64.21.229:60751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWkFymN6QYcoA7XB5S0wAAAHI"]
[Thu Jul 30 13:23:12.518123 2026] [security2:error] [pid 872418:tid 872662] [client 179.64.21.229:60751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWkFymN6QYcoA7XB5S0wAAAHI"]
[Thu Jul 30 13:23:12.594883 2026] [security2:error] [pid 872418:tid 872629] [client 20.215.191.139:40471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-file.php"] [unique_id "amuWkFymN6QYcoA7XB5S1gAAAFE"]
[Thu Jul 30 13:23:12.793210 2026] [security2:error] [pid 872418:tid 872655] [client 5.133.9.204:39604] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.remoteworksit.com"] [uri "/wp-comments-post.php"] [unique_id "amuWkFymN6QYcoA7XB5SyQAAAGs"]
[Thu Jul 30 13:23:12.831223 2026] [security2:error] [pid 872418:tid 872656] [client 20.52.125.110:9578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuWkFymN6QYcoA7XB5S4AAAAGw"]
[Thu Jul 30 13:23:12.944150 2026] [security2:error] [pid 872418:tid 872655] [client 5.133.9.204:39604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "www.remoteworksit.com"] [uri "/wp-comments-post.php"] [unique_id "amuWkFymN6QYcoA7XB5SyQAAAGs"]
[Thu Jul 30 13:23:13.248392 2026] [security2:error] [pid 872418:tid 872568] [client 172.236.9.101:40310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/index.php/_profiler/empty/search/results"] [unique_id "amuWkVymN6QYcoA7XB5S7QAAABQ"]
[Thu Jul 30 13:23:13.351219 2026] [security2:error] [pid 872418:tid 872635] [client 20.52.125.110:9109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuWkVymN6QYcoA7XB5S8gAAAFc"]
[Thu Jul 30 13:23:13.449202 2026] [security2:error] [pid 872418:tid 872575] [client 68.221.186.136:8883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/about.php"] [unique_id "amuWkVymN6QYcoA7XB5S8wAAABs"]
[Thu Jul 30 13:23:13.728528 2026] [security2:error] [pid 872418:tid 872533] [remote 216.73.217.142:38354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuWkVymN6QYcoA7XB5S-gAATnI"]
[Thu Jul 30 13:23:13.833070 2026] [security2:error] [pid 872418:tid 872569] [client 20.52.125.110:9570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuWkVymN6QYcoA7XB5S_AAAABU"]
[Thu Jul 30 13:23:14.225477 2026] [security2:error] [pid 872418:tid 872672] [client 209.141.35.192:59468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuWkFymN6QYcoA7XB5SwAAAAHw"], referer: https://pkf.jo/
[Thu Jul 30 13:23:14.274230 2026] [security2:error] [pid 872418:tid 872651] [client 172.236.9.101:50281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/index_dev.php/_profiler/empty/search/results"] [unique_id "amuWklymN6QYcoA7XB5TBAAAAGc"]
[Thu Jul 30 13:23:14.383242 2026] [security2:error] [pid 872418:tid 872611] [client 68.221.186.136:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/cgi-bin/about.php"] [unique_id "amuWklymN6QYcoA7XB5TCQAAAD8"]
[Thu Jul 30 13:23:14.417031 2026] [security2:error] [pid 872418:tid 872607] [client 20.52.125.110:10946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuWklymN6QYcoA7XB5TCwAAADs"]
[Thu Jul 30 13:23:14.895946 2026] [security2:error] [pid 872418:tid 872622] [client 20.52.125.110:10950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuWklymN6QYcoA7XB5TFwAAAEo"]
[Thu Jul 30 13:23:15.287829 2026] [security2:error] [pid 872418:tid 872675] [client 68.221.186.136:1706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuWk1ymN6QYcoA7XB5TIwAAAH8"]
[Thu Jul 30 13:23:15.378347 2026] [security2:error] [pid 872418:tid 872549] [client 20.52.125.110:9137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuWk1ymN6QYcoA7XB5TJAAAAAE"]
[Thu Jul 30 13:23:15.431025 2026] [proxy:error] [pid 872418:tid 872592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:15.431127 2026] [proxy_http:error] [pid 872418:tid 872592] [client 34.233.129.35:52618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:15.431775 2026] [proxy:error] [pid 872418:tid 872592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:15.431822 2026] [proxy_http:error] [pid 872418:tid 872592] [client 34.233.129.35:52618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:15.468841 2026] [proxy:error] [pid 872418:tid 872565] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:15.468925 2026] [proxy_http:error] [pid 872418:tid 872565] [client 34.233.129.35:65012] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:15.469803 2026] [proxy:error] [pid 872418:tid 872565] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:15.469851 2026] [proxy_http:error] [pid 872418:tid 872565] [client 34.233.129.35:65012] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:15.837125 2026] [security2:error] [pid 872418:tid 872595] [client 20.52.125.110:9118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuWk1ymN6QYcoA7XB5TRQAAAC8"]
[Thu Jul 30 13:23:16.231658 2026] [security2:error] [pid 872418:tid 872576] [client 209.141.35.192:59471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuWkFymN6QYcoA7XB5SxQAAABw"], referer: https://pkf.jo/
[Thu Jul 30 13:23:16.271637 2026] [security2:error] [pid 872418:tid 872663] [client 172.236.9.101:61562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/dev.php/_profiler/empty/search/results"] [unique_id "amuWlFymN6QYcoA7XB5TYAAAAHM"]
[Thu Jul 30 13:23:16.384990 2026] [security2:error] [pid 872418:tid 872605] [client 68.221.186.136:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuWlFymN6QYcoA7XB5TbAAAADk"]
[Thu Jul 30 13:23:16.393251 2026] [security2:error] [pid 872418:tid 872572] [client 20.52.125.110:9149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuWlFymN6QYcoA7XB5TbQAAABg"]
[Thu Jul 30 13:23:16.452504 2026] [security2:error] [pid 872418:tid 872563] [client 20.215.191.139:51838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-signin.php"] [unique_id "amuWlFymN6QYcoA7XB5TdAAAAA8"]
[Thu Jul 30 13:23:16.698809 2026] [security2:error] [pid 872418:tid 872648] [client 74.7.230.26:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jacislamabad.com"] [uri "/index.php"] [unique_id "amuWk1ymN6QYcoA7XB5TMwAAZHM"]
[Thu Jul 30 13:23:16.878989 2026] [security2:error] [pid 872418:tid 872624] [client 20.52.125.110:9107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuWlFymN6QYcoA7XB5TfgAAAEw"]
[Thu Jul 30 13:23:17.119651 2026] [security2:error] [pid 872418:tid 872667] [client 68.221.186.136:9912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuWlVymN6QYcoA7XB5TggAAAHc"]
[Thu Jul 30 13:23:17.480352 2026] [security2:error] [pid 872418:tid 872640] [client 20.52.125.110:9584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuWlVymN6QYcoA7XB5TjgAAAFw"]
[Thu Jul 30 13:23:17.832553 2026] [security2:error] [pid 872418:tid 872669] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWlVymN6QYcoA7XB5ThwAAeQo"]
[Thu Jul 30 13:23:17.864499 2026] [security2:error] [pid 872418:tid 872655] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWlFymN6QYcoA7XB5TXgAAAGs"]
[Thu Jul 30 13:23:17.964770 2026] [security2:error] [pid 872418:tid 872605] [client 20.52.125.110:9117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuWlVymN6QYcoA7XB5TmgAAADk"]
[Thu Jul 30 13:23:18.212641 2026] [security2:error] [pid 872418:tid 872566] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWk1ymN6QYcoA7XB5TPAAAABI"]
[Thu Jul 30 13:23:18.256471 2026] [security2:error] [pid 872418:tid 872653] [client 172.236.9.101:43402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/debug.php/_profiler/empty/search/results"] [unique_id "amuWllymN6QYcoA7XB5TpAAAAGk"]
[Thu Jul 30 13:23:18.466450 2026] [security2:error] [pid 872418:tid 872648] [client 20.52.125.110:9597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuWllymN6QYcoA7XB5TqAAAAGQ"]
[Thu Jul 30 13:23:18.797318 2026] [core:notice] [pid 872418:tid 872419] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:18.952409 2026] [security2:error] [pid 872418:tid 872557] [client 68.221.186.136:8847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuWllymN6QYcoA7XB5TtgAAAAk"]
[Thu Jul 30 13:23:18.988987 2026] [core:notice] [pid 872418:tid 872467] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:19.000761 2026] [security2:error] [pid 872418:tid 872659] [client 20.52.125.110:9095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuWl1ymN6QYcoA7XB5TuAAAAG8"]
[Thu Jul 30 13:23:19.256193 2026] [security2:error] [pid 872418:tid 872448] [remote 216.73.217.142:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuWl1ymN6QYcoA7XB5TwgAAQx0"]
[Thu Jul 30 13:23:19.365749 2026] [security2:error] [pid 872418:tid 872513] [remote 57.141.0.55:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuWl1ymN6QYcoA7XB5TyAAAUV4"]
[Thu Jul 30 13:23:19.537836 2026] [security2:error] [pid 872418:tid 872601] [client 20.52.125.110:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuWl1ymN6QYcoA7XB5TygAAADU"]
[Thu Jul 30 13:23:19.577957 2026] [security2:error] [pid 872418:tid 872597] [client 172.236.9.101:57769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWl1ymN6QYcoA7XB5TwwAAADE"]
[Thu Jul 30 13:23:19.726641 2026] [security2:error] [pid 872418:tid 872669] [client 68.221.186.136:12387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuWl1ymN6QYcoA7XB5TzwAAAHk"]
[Thu Jul 30 13:23:19.828923 2026] [security2:error] [pid 872418:tid 872559] [client 20.215.191.139:16275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/simi.php"] [unique_id "amuWl1ymN6QYcoA7XB5T1AAAAAs"]
[Thu Jul 30 13:23:19.876411 2026] [security2:error] [pid 872418:tid 872563] [client 65.109.165.110:24884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuWl1ymN6QYcoA7XB5TywAAAA8"]
[Thu Jul 30 13:23:20.083042 2026] [security2:error] [pid 872418:tid 872455] [remote 47.128.27.98:61904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-wmns-air-jordan-1-low-barb-white-black-green/"] [unique_id "amuWmFymN6QYcoA7XB5T2wAAXiQ"]
[Thu Jul 30 13:23:20.106641 2026] [security2:error] [pid 872418:tid 872616] [client 20.52.125.110:9582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuWmFymN6QYcoA7XB5T3AAAAEQ"]
[Thu Jul 30 13:23:20.526783 2026] [security2:error] [pid 872418:tid 872452] [remote 97.74.87.194:42534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuWmFymN6QYcoA7XB5T5wAAfCE"]
[Thu Jul 30 13:23:20.648398 2026] [security2:error] [pid 872418:tid 872551] [client 20.52.125.110:9126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuWmFymN6QYcoA7XB5T6QAAAAM"]
[Thu Jul 30 13:23:21.136962 2026] [security2:error] [pid 872418:tid 872549] [client 20.52.125.110:9097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuWmVymN6QYcoA7XB5T-wAAAAE"]
[Thu Jul 30 13:23:21.365028 2026] [security2:error] [pid 872418:tid 872463] [remote 57.141.0.37:57956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/issue/view/599"] [unique_id "amuWmVymN6QYcoA7XB5UBwAACCw"]
[Thu Jul 30 13:23:21.387104 2026] [core:notice] [pid 872418:tid 872592] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:21.488689 2026] [security2:error] [pid 872418:tid 872621] [client 20.215.191.139:51807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/wp-conf.php"] [unique_id "amuWmVymN6QYcoA7XB5UDwAAAEk"]
[Thu Jul 30 13:23:21.517131 2026] [core:notice] [pid 872418:tid 872657] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:21.591860 2026] [security2:error] [pid 872418:tid 872568] [client 172.236.9.101:57797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWmVymN6QYcoA7XB5UAgAAABQ"]
[Thu Jul 30 13:23:21.598317 2026] [security2:error] [pid 872418:tid 872624] [client 20.52.125.110:9593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuWmVymN6QYcoA7XB5UEwAAAEw"]
[Thu Jul 30 13:23:21.759809 2026] [core:notice] [pid 872418:tid 872562] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:22.053569 2026] [security2:error] [pid 872418:tid 872666] [client 20.215.191.139:21627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuWmlymN6QYcoA7XB5UJwAAAHY"]
[Thu Jul 30 13:23:22.097309 2026] [security2:error] [pid 872418:tid 872574] [client 20.52.125.110:9091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuWmlymN6QYcoA7XB5UKAAAABo"]
[Thu Jul 30 13:23:22.128961 2026] [core:notice] [pid 872418:tid 872582] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:22.516705 2026] [core:notice] [pid 872418:tid 872597] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:22.555739 2026] [security2:error] [pid 872418:tid 872488] [remote 103.133.214.160:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.214.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuWmlymN6QYcoA7XB5UPAAAKEU"]
[Thu Jul 30 13:23:22.596744 2026] [security2:error] [pid 872418:tid 872600] [client 20.52.125.110:9552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuWmlymN6QYcoA7XB5UPQAAADQ"]
[Thu Jul 30 13:23:22.919874 2026] [security2:error] [pid 872418:tid 872652] [client 20.215.191.139:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/bala.php"] [unique_id "amuWmlymN6QYcoA7XB5URwAAAGg"]
[Thu Jul 30 13:23:22.961021 2026] [core:notice] [pid 872418:tid 872675] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:23.035360 2026] [security2:error] [pid 872418:tid 872669] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWmlymN6QYcoA7XB5UNwAAAHk"]
[Thu Jul 30 13:23:23.116404 2026] [security2:error] [pid 872418:tid 872626] [client 20.52.125.110:9111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuWm1ymN6QYcoA7XB5UTgAAAE4"]
[Thu Jul 30 13:23:23.227233 2026] [security2:error] [pid 872418:tid 872591] [client 179.64.21.229:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWm1ymN6QYcoA7XB5UUQAAACs"]
[Thu Jul 30 13:23:23.228443 2026] [security2:error] [pid 872418:tid 872591] [client 179.64.21.229:65464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWm1ymN6QYcoA7XB5UUQAAACs"]
[Thu Jul 30 13:23:23.328769 2026] [core:notice] [pid 872418:tid 872659] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:23.563283 2026] [security2:error] [pid 872418:tid 872618] [client 172.236.9.101:25572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWm1ymN6QYcoA7XB5UUgAAAEY"]
[Thu Jul 30 13:23:23.640269 2026] [security2:error] [pid 872418:tid 872601] [client 82.102.27.195:41456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuWm1ymN6QYcoA7XB5UZQAAADU"]
[Thu Jul 30 13:23:23.640385 2026] [security2:error] [pid 872418:tid 872601] [client 82.102.27.195:41456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuWm1ymN6QYcoA7XB5UZQAAADU"]
[Thu Jul 30 13:23:23.644004 2026] [security2:error] [pid 872418:tid 872595] [client 20.52.125.110:9538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuWm1ymN6QYcoA7XB5UZgAAAC8"]
[Thu Jul 30 13:23:23.727760 2026] [core:notice] [pid 872418:tid 872583] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:23.829238 2026] [security2:error] [pid 872418:tid 872625] [client 68.221.186.136:1722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuWm1ymN6QYcoA7XB5UggAAAE0"]
[Thu Jul 30 13:23:23.952119 2026] [core:notice] [pid 872418:tid 872471] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:24.109281 2026] [core:notice] [pid 872418:tid 872613] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:24.157087 2026] [security2:error] [pid 872418:tid 872643] [client 20.52.125.110:9108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuWnFymN6QYcoA7XB5UkAAAAF8"]
[Thu Jul 30 13:23:24.619541 2026] [core:notice] [pid 872418:tid 872594] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:24.670022 2026] [core:notice] [pid 872418:tid 872667] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:24.966598 2026] [autoindex:error] [pid 872418:tid 872555] [client 119.28.89.249:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://melatipkr.xyz
[Thu Jul 30 13:23:25.290720 2026] [security2:error] [pid 872418:tid 872606] [client 172.236.9.101:1070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/frontend_dev.php/_profiler/empty/search/results"] [unique_id "amuWnVymN6QYcoA7XB5UtgAAADo"]
[Thu Jul 30 13:23:25.475219 2026] [security2:error] [pid 872418:tid 872664] [client 216.244.66.233:55028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuWnVymN6QYcoA7XB5UugAAAHQ"]
[Thu Jul 30 13:23:25.475413 2026] [security2:error] [pid 872418:tid 872664] [client 216.244.66.233:55028] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuWnVymN6QYcoA7XB5UugAAAHQ"]
[Thu Jul 30 13:23:26.278725 2026] [security2:error] [pid 872418:tid 872643] [client 82.102.27.195:33872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuWnlymN6QYcoA7XB5U0gAAAF8"]
[Thu Jul 30 13:23:26.278860 2026] [security2:error] [pid 872418:tid 872643] [client 82.102.27.195:33872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuWnlymN6QYcoA7XB5U0gAAAF8"]
[Thu Jul 30 13:23:26.329842 2026] [security2:error] [pid 872418:tid 872647] [client 20.215.191.139:22949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/bk.php"] [unique_id "amuWnlymN6QYcoA7XB5U1AAAAGM"]
[Thu Jul 30 13:23:27.095318 2026] [security2:error] [pid 872418:tid 872629] [client 20.215.191.139:53359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nordeste1.com"] [uri "/ahax.php"] [unique_id "amuWn1ymN6QYcoA7XB5U9wAAAFE"]
[Thu Jul 30 13:23:27.197558 2026] [core:notice] [pid 872418:tid 872671] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:27.251266 2026] [security2:error] [pid 872418:tid 872675] [client 172.236.9.101:19490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/backend_dev.php/_profiler/empty/search/results"] [unique_id "amuWn1ymN6QYcoA7XB5VBAAAAH8"]
[Thu Jul 30 13:23:27.511742 2026] [proxy:error] [pid 872418:tid 872587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:27.511834 2026] [proxy_http:error] [pid 872418:tid 872587] [client 3.225.222.228:27901] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:27.513093 2026] [proxy:error] [pid 872418:tid 872587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:27.513160 2026] [proxy_http:error] [pid 872418:tid 872587] [client 3.225.222.228:27901] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:27.522605 2026] [proxy:error] [pid 872418:tid 872636] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:27.522676 2026] [proxy_http:error] [pid 872418:tid 872636] [client 44.213.206.96:43397] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:27.523360 2026] [proxy:error] [pid 872418:tid 872636] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:27.523416 2026] [proxy_http:error] [pid 872418:tid 872636] [client 44.213.206.96:43397] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:27.915685 2026] [security2:error] [pid 872418:tid 872576] [client 68.221.186.136:12339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuWn1ymN6QYcoA7XB5VIwAAABw"]
[Thu Jul 30 13:23:28.147903 2026] [security2:error] [pid 872418:tid 872633] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amuWoFymN6QYcoA7XB5VKQAAAFU"]
[Thu Jul 30 13:23:28.253090 2026] [security2:error] [pid 872418:tid 872646] [client 172.236.9.101:42582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/api_dev.php/_profiler/empty/search/results"] [unique_id "amuWoFymN6QYcoA7XB5VNgAAAGI"]
[Thu Jul 30 13:23:28.393749 2026] [security2:error] [pid 872418:tid 872628] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amuWoFymN6QYcoA7XB5VOAAAAFA"]
[Thu Jul 30 13:23:28.639306 2026] [security2:error] [pid 872418:tid 872606] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "amuWoFymN6QYcoA7XB5VQAAAADo"]
[Thu Jul 30 13:23:28.886313 2026] [security2:error] [pid 872418:tid 872653] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/.env"] [unique_id "amuWoFymN6QYcoA7XB5VTAAAAGk"]
[Thu Jul 30 13:23:29.273991 2026] [security2:error] [pid 872418:tid 872579] [client 172.236.9.101:54873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/app.php/_profiler/empty/search/results"] [unique_id "amuWoVymN6QYcoA7XB5VWgAAAB8"]
[Thu Jul 30 13:23:29.663654 2026] [security2:error] [pid 872418:tid 872548] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/app/.env"] [unique_id "amuWoVymN6QYcoA7XB5VZQAAAAA"]
[Thu Jul 30 13:23:29.733181 2026] [core:notice] [pid 872418:tid 872659] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:30.059084 2026] [security2:error] [pid 872418:tid 872600] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/opt/.env"] [unique_id "amuWolymN6QYcoA7XB5VcAAAADQ"]
[Thu Jul 30 13:23:30.190075 2026] [security2:error] [pid 872418:tid 872555] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/.git/config.bak"] [unique_id "amuWolymN6QYcoA7XB5VdQAAAAc"]
[Thu Jul 30 13:23:30.320363 2026] [security2:error] [pid 872418:tid 872577] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/.git/config.old"] [unique_id "amuWolymN6QYcoA7XB5VegAAAB0"]
[Thu Jul 30 13:23:30.578917 2026] [security2:error] [pid 872418:tid 872662] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/.env"] [unique_id "amuWolymN6QYcoA7XB5VfwAAAHI"]
[Thu Jul 30 13:23:30.875913 2026] [core:notice] [pid 872418:tid 872581] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:30.971083 2026] [security2:error] [pid 872418:tid 872652] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/backend/.env"] [unique_id "amuWolymN6QYcoA7XB5VkAAAAGg"]
[Thu Jul 30 13:23:31.240069 2026] [security2:error] [pid 872418:tid 872594] [client 190.2.96.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWolymN6QYcoA7XB5VdgAALgA"], referer: https://allmontecristi.com
[Thu Jul 30 13:23:31.270867 2026] [security2:error] [pid 872418:tid 872644] [client 172.236.9.101:21809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/app_test.php/_profiler/empty/search/results"] [unique_id "amuWo1ymN6QYcoA7XB5VmgAAAGA"]
[Thu Jul 30 13:23:31.282061 2026] [security2:error] [pid 872418:tid 872675] [client 68.221.186.136:41901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/cloud.php"] [unique_id "amuWo1ymN6QYcoA7XB5VmwAAAH8"]
[Thu Jul 30 13:23:31.484420 2026] [security2:error] [pid 872418:tid 872548] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "httpd.conf"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/httpd.conf"] [unique_id "amuWo1ymN6QYcoA7XB5VowAAAAA"]
[Thu Jul 30 13:23:31.695178 2026] [security2:error] [pid 872418:tid 872551] [client 74.248.20.32:56559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuWo1ymN6QYcoA7XB5VpgAAAAM"]
[Thu Jul 30 13:23:31.695290 2026] [security2:error] [pid 872418:tid 872551] [client 74.248.20.32:56559] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuWo1ymN6QYcoA7XB5VpgAAAAM"]
[Thu Jul 30 13:23:33.288236 2026] [security2:error] [pid 872418:tid 872558] [client 172.236.9.101:10857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/test.php/_profiler/empty/search/results"] [unique_id "amuWpVymN6QYcoA7XB5V3gAAAAo"]
[Thu Jul 30 13:23:33.649105 2026] [security2:error] [pid 872418:tid 872613] [client 179.64.21.229:39406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWpVymN6QYcoA7XB5V6QAAAEE"]
[Thu Jul 30 13:23:33.650805 2026] [security2:error] [pid 872418:tid 872613] [client 179.64.21.229:39406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWpVymN6QYcoA7XB5V6QAAAEE"]
[Thu Jul 30 13:23:34.501536 2026] [core:notice] [pid 872418:tid 872498] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:34.659785 2026] [security2:error] [pid 872418:tid 872588] [client 68.221.186.136:4381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuWplymN6QYcoA7XB5WBwAAACg"]
[Thu Jul 30 13:23:35.087711 2026] [core:error] [pid 872418:tid 872653] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:23:35.087738 2026] [core:error] [pid 872418:tid 872653] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:23:35.322905 2026] [security2:error] [pid 872418:tid 872669] [client 68.221.186.136:4363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/updates.php"] [unique_id "amuWp1ymN6QYcoA7XB5WGgAAAHk"]
[Thu Jul 30 13:23:35.485026 2026] [security2:error] [pid 872418:tid 872675] [client 74.248.20.32:51780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuWp1ymN6QYcoA7XB5WIAAAAH8"]
[Thu Jul 30 13:23:35.485170 2026] [security2:error] [pid 872418:tid 872675] [client 74.248.20.32:51780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuWp1ymN6QYcoA7XB5WIAAAAH8"]
[Thu Jul 30 13:23:35.621250 2026] [security2:error] [pid 872418:tid 872636] [client 172.236.9.101:34719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWp1ymN6QYcoA7XB5WFgAAAFg"]
[Thu Jul 30 13:23:36.114743 2026] [security2:error] [pid 872418:tid 872589] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/wp-content/uploads/2024/.env"] [unique_id "amuWqFymN6QYcoA7XB5WMQAAACk"]
[Thu Jul 30 13:23:36.251316 2026] [security2:error] [pid 872418:tid 872670] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/wp-content/uploads/2025/.env"] [unique_id "amuWqFymN6QYcoA7XB5WNQAAAHo"]
[Thu Jul 30 13:23:37.531550 2026] [security2:error] [pid 872418:tid 872559] [client 172.236.9.101:57648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWqVymN6QYcoA7XB5WUAAAAAs"]
[Thu Jul 30 13:23:37.583141 2026] [security2:error] [pid 872418:tid 872620] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/web.config"] [unique_id "amuWqVymN6QYcoA7XB5WVwAAAEg"]
[Thu Jul 30 13:23:37.923801 2026] [security2:error] [pid 872418:tid 872629] [client 178.156.181.172:52158] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuWqVymN6QYcoA7XB5WXwAAAFE"], referer: https://globalmarks.pk/
[Thu Jul 30 13:23:38.817195 2026] [security2:error] [pid 872418:tid 872539] [remote 216.73.217.142:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuWqlymN6QYcoA7XB5WfgAAKXg"]
[Thu Jul 30 13:23:38.915362 2026] [security2:error] [pid 872418:tid 872640] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWqlymN6QYcoA7XB5WbwAAAFw"]
[Thu Jul 30 13:23:39.238483 2026] [security2:error] [pid 872418:tid 872667] [client 74.248.20.32:61354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/ioxi-o.php"] [unique_id "amuWq1ymN6QYcoA7XB5WiAAAAHc"]
[Thu Jul 30 13:23:39.238637 2026] [security2:error] [pid 872418:tid 872667] [client 74.248.20.32:61354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/ioxi-o.php"] [unique_id "amuWq1ymN6QYcoA7XB5WiAAAAHc"]
[Thu Jul 30 13:23:39.574130 2026] [security2:error] [pid 872418:tid 872637] [client 172.236.9.101:49634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWq1ymN6QYcoA7XB5WiQAAAFk"]
[Thu Jul 30 13:23:40.055661 2026] [core:notice] [pid 872418:tid 872563] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:40.124240 2026] [cgid:error] [pid 872418:tid 872649] [client 185.177.72.54:0] AH01264: stderr from /home1/apwudite/public_html/sysinfo.cgi: script not found or unable to stat
[Thu Jul 30 13:23:40.252321 2026] [security2:error] [pid 872418:tid 872587] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/sites/default/.env"] [unique_id "amuWrFymN6QYcoA7XB5WsAAAACc"]
[Thu Jul 30 13:23:40.377480 2026] [security2:error] [pid 872418:tid 872606] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWq1ymN6QYcoA7XB5WnQAAADo"]
[Thu Jul 30 13:23:40.586406 2026] [security2:error] [pid 872418:tid 872583] [client 68.221.186.136:1908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/css/cloud.php"] [unique_id "amuWrFymN6QYcoA7XB5WtgAAACM"]
[Thu Jul 30 13:23:41.494126 2026] [security2:error] [pid 872418:tid 872613] [client 68.221.186.136:5108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuWrVymN6QYcoA7XB5W0wAAAEE"]
[Thu Jul 30 13:23:41.578388 2026] [security2:error] [pid 872418:tid 872626] [client 172.236.9.101:58032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWrVymN6QYcoA7XB5WyAAAAE4"]
[Thu Jul 30 13:23:41.589688 2026] [security2:error] [pid 872418:tid 872647] [client 137.184.79.59:36934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuWrVymN6QYcoA7XB5WygAAAGM"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 13:23:41.841690 2026] [security2:error] [pid 872418:tid 872628] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuWrVymN6QYcoA7XB5W2wAAAFA"]
[Thu Jul 30 13:23:42.149995 2026] [security2:error] [pid 872418:tid 872588] [client 68.221.186.136:1871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/img/cloud.php"] [unique_id "amuWrlymN6QYcoA7XB5W6QAAACg"]
[Thu Jul 30 13:23:43.869516 2026] [autoindex:error] [pid 872418:tid 872553] [client 185.177.72.54:0] AH01276: Cannot serve directory /home1/apwudite/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:23:44.009534 2026] [cgid:error] [pid 872418:tid 872600] [client 185.177.72.54:0] AH01264: stderr from /home1/apwudite/public_html/dnscfg.cgi: script not found or unable to stat
[Thu Jul 30 13:23:44.399393 2026] [security2:error] [pid 872418:tid 872555] [client 179.64.21.229:6386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWsFymN6QYcoA7XB5XMAAAAAc"]
[Thu Jul 30 13:23:44.399523 2026] [security2:error] [pid 872418:tid 872555] [client 179.64.21.229:6386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWsFymN6QYcoA7XB5XMAAAAAc"]
[Thu Jul 30 13:23:44.605221 2026] [security2:error] [pid 872418:tid 872667] [client 137.184.79.59:36950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuWsFymN6QYcoA7XB5XKwAAAHc"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 13:23:45.099619 2026] [security2:error] [pid 872418:tid 872614] [client 74.248.20.32:38341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/66.php"] [unique_id "amuWsVymN6QYcoA7XB5XTAAAAEI"]
[Thu Jul 30 13:23:45.099722 2026] [security2:error] [pid 872418:tid 872614] [client 74.248.20.32:38341] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/66.php"] [unique_id "amuWsVymN6QYcoA7XB5XTAAAAEI"]
[Thu Jul 30 13:23:45.268619 2026] [security2:error] [pid 872418:tid 872436] [remote 74.7.243.224:48062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/vision/img/js/uploads/partners/js/js/fonts/css/uploads/content/uploads/partners/aprochef.php"] [unique_id "amuWsVymN6QYcoA7XB5XUQAAOhE"], referer: https://aded-rdc.org/vision/img/js/uploads/partners/js/js/fonts/css/uploads/content/uploads/partners/humanitariaf.html
[Thu Jul 30 13:23:45.317666 2026] [core:notice] [pid 872418:tid 872611] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:46.276170 2026] [security2:error] [pid 872418:tid 872646] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWsVymN6QYcoA7XB5XcwAAAGI"]
[Thu Jul 30 13:23:46.373072 2026] [security2:error] [pid 872418:tid 872619] [client 68.221.186.136:43752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuWslymN6QYcoA7XB5XoQAAAEc"]
[Thu Jul 30 13:23:46.484605 2026] [security2:error] [pid 872418:tid 872642] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWsVymN6QYcoA7XB5XkAAAAF4"]
[Thu Jul 30 13:23:46.608691 2026] [security2:error] [pid 872418:tid 872586] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWsVymN6QYcoA7XB5XmAAAJic"]
[Thu Jul 30 13:23:47.077490 2026] [security2:error] [pid 872418:tid 872664] [client 68.221.186.136:2029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuWs1ymN6QYcoA7XB5X-gAAAHQ"]
[Thu Jul 30 13:23:47.624236 2026] [security2:error] [pid 872418:tid 872660] [client 68.221.186.136:12374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/avaa.php"] [unique_id "amuWs1ymN6QYcoA7XB5YDQAAAHA"]
[Thu Jul 30 13:23:48.601135 2026] [security2:error] [pid 872418:tid 872455] [remote 57.141.0.14:64986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuWtFymN6QYcoA7XB5YKgAAEiQ"]
[Thu Jul 30 13:23:48.673268 2026] [security2:error] [pid 872418:tid 872609] [client 181.66.139.177:12862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuWtFymN6QYcoA7XB5YJwAAAD0"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 13:23:49.233197 2026] [security2:error] [pid 872418:tid 872619] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/app/Services/SparkPostService.php"] [unique_id "amuWtVymN6QYcoA7XB5YTQAAAEc"]
[Thu Jul 30 13:23:49.275501 2026] [security2:error] [pid 872418:tid 872600] [client 68.221.186.136:8834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/images/cloud.php"] [unique_id "amuWtVymN6QYcoA7XB5YWgAAADQ"]
[Thu Jul 30 13:23:49.487900 2026] [core:error] [pid 872418:tid 872550] [client 184.154.139.46:54664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=carrecoveryserviceabudhabillc.site&yahoo.com
[Thu Jul 30 13:23:49.487921 2026] [core:error] [pid 872418:tid 872550] [client 184.154.139.46:54664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=carrecoveryserviceabudhabillc.site&yahoo.com
[Thu Jul 30 13:23:49.779474 2026] [core:notice] [pid 872418:tid 872565] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:50.123536 2026] [security2:error] [pid 872418:tid 872628] [client 184.154.139.46:55032] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "carrecoveryserviceabudhabillc.site"] [uri "/style.css"] [unique_id "amuWtlymN6QYcoA7XB5YmwAAAFA"]
[Thu Jul 30 13:23:50.677388 2026] [security2:error] [pid 872418:tid 872524] [remote 40.77.167.149:10920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/nanatsu-no-taizai.fandom.com/wiki/misionf.php"] [unique_id "amuWtlymN6QYcoA7XB5YtAAAUWk"]
[Thu Jul 30 13:23:50.977810 2026] [security2:error] [pid 872418:tid 872563] [client 68.221.186.136:11412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuWtlymN6QYcoA7XB5YwAAAAA8"]
[Thu Jul 30 13:23:51.063392 2026] [proxy:error] [pid 872418:tid 872550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:51.063497 2026] [proxy_http:error] [pid 872418:tid 872550] [client 18.211.55.47:3137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:51.064318 2026] [proxy:error] [pid 872418:tid 872550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:51.064378 2026] [proxy_http:error] [pid 872418:tid 872550] [client 18.211.55.47:3137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:51.068970 2026] [proxy:error] [pid 872418:tid 872586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:51.069048 2026] [proxy_http:error] [pid 872418:tid 872586] [client 98.87.102.177:15088] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:51.069888 2026] [proxy:error] [pid 872418:tid 872586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:51.069946 2026] [proxy_http:error] [pid 872418:tid 872586] [client 98.87.102.177:15088] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:52.279934 2026] [security2:error] [pid 872418:tid 872620] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/terraform.tfstate.backup"] [unique_id "amuWuFymN6QYcoA7XB5Y6QAAAEg"]
[Thu Jul 30 13:23:52.549883 2026] [security2:error] [pid 872418:tid 872617] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/sendgrid.env"] [unique_id "amuWuFymN6QYcoA7XB5Y9gAAAEU"]
[Thu Jul 30 13:23:52.815645 2026] [security2:error] [pid 872418:tid 872667] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/env.php"] [unique_id "amuWuFymN6QYcoA7XB5Y-wAAAHc"]
[Thu Jul 30 13:23:53.683250 2026] [security2:error] [pid 872418:tid 872534] [remote 57.141.0.17:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6151894337/feed/rss2/"] [unique_id "amuWuVymN6QYcoA7XB5ZGwAABnM"]
[Thu Jul 30 13:23:54.077998 2026] [security2:error] [pid 872418:tid 872656] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuWuVymN6QYcoA7XB5ZEgAAAGw"]
[Thu Jul 30 13:23:54.645598 2026] [proxy:error] [pid 872418:tid 872659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:54.645706 2026] [proxy_http:error] [pid 872418:tid 872659] [client 18.211.55.47:41268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:54.646339 2026] [proxy:error] [pid 872418:tid 872632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:54.646436 2026] [proxy_http:error] [pid 872418:tid 872632] [client 44.216.125.112:3049] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:54.646881 2026] [proxy:error] [pid 872418:tid 872659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:54.646934 2026] [proxy_http:error] [pid 872418:tid 872659] [client 18.211.55.47:41268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:54.647345 2026] [proxy:error] [pid 872418:tid 872632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:54.647409 2026] [proxy_http:error] [pid 872418:tid 872632] [client 44.216.125.112:3049] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:54.721251 2026] [security2:error] [pid 872418:tid 872609] [client 172.237.109.114:30219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWulymN6QYcoA7XB5ZLQAAAD0"]
[Thu Jul 30 13:23:54.722157 2026] [security2:error] [pid 872418:tid 872648] [client 172.237.109.114:34885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWulymN6QYcoA7XB5ZKwAAAGQ"]
[Thu Jul 30 13:23:54.733728 2026] [security2:error] [pid 872418:tid 872592] [client 172.237.109.114:35799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWulymN6QYcoA7XB5ZLAAAACw"]
[Thu Jul 30 13:23:54.753352 2026] [security2:error] [pid 872418:tid 872644] [client 172.237.109.114:29152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWulymN6QYcoA7XB5ZLgAAAGA"]
[Thu Jul 30 13:23:54.767218 2026] [security2:error] [pid 872418:tid 872581] [client 172.237.109.114:24082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWulymN6QYcoA7XB5ZMgAAACE"]
[Thu Jul 30 13:23:54.768703 2026] [security2:error] [pid 872418:tid 872605] [client 172.237.109.114:54414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWulymN6QYcoA7XB5ZMQAAADk"]
[Thu Jul 30 13:23:54.777225 2026] [security2:error] [pid 872418:tid 872559] [client 172.237.109.114:48931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWulymN6QYcoA7XB5ZMAAAAAs"]
[Thu Jul 30 13:23:54.784867 2026] [security2:error] [pid 872418:tid 872626] [client 179.64.21.229:20081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWulymN6QYcoA7XB5ZTAAAAE4"]
[Thu Jul 30 13:23:54.788578 2026] [security2:error] [pid 872418:tid 872626] [client 179.64.21.229:20081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWulymN6QYcoA7XB5ZTAAAAE4"]
[Thu Jul 30 13:23:54.798826 2026] [security2:error] [pid 872418:tid 872564] [client 172.237.109.114:17670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWulymN6QYcoA7XB5ZNAAAABA"]
[Thu Jul 30 13:23:54.804829 2026] [security2:error] [pid 872418:tid 872675] [client 172.237.109.114:33808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuWulymN6QYcoA7XB5ZMwAAAH8"]
[Thu Jul 30 13:23:54.893909 2026] [security2:error] [pid 872418:tid 872584] [client 68.221.186.136:12403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuWulymN6QYcoA7XB5ZTwAAACQ"]
[Thu Jul 30 13:23:55.191199 2026] [security2:error] [pid 872418:tid 872628] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/backend/.env"] [unique_id "amuWu1ymN6QYcoA7XB5ZXQAAAFA"]
[Thu Jul 30 13:23:56.397560 2026] [security2:error] [pid 872418:tid 872662] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/s3/.env.bak"] [unique_id "amuWvFymN6QYcoA7XB5ZegAAAHI"]
[Thu Jul 30 13:23:56.527143 2026] [security2:error] [pid 872418:tid 872619] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/srv/.env"] [unique_id "amuWvFymN6QYcoA7XB5ZewAAAEc"]
[Thu Jul 30 13:23:56.795371 2026] [security2:error] [pid 872418:tid 872581] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/laravel/.env"] [unique_id "amuWvFymN6QYcoA7XB5ZhwAAACE"]
[Thu Jul 30 13:23:56.924115 2026] [security2:error] [pid 872418:tid 872605] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/app/etc/env.php"] [unique_id "amuWvFymN6QYcoA7XB5ZiAAAADk"]
[Thu Jul 30 13:23:57.620576 2026] [proxy:error] [pid 872418:tid 872611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:57.620655 2026] [proxy_http:error] [pid 872418:tid 872611] [client 44.216.125.112:10763] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:57.621530 2026] [proxy:error] [pid 872418:tid 872611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:57.621588 2026] [proxy_http:error] [pid 872418:tid 872611] [client 44.216.125.112:10763] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:57.642205 2026] [proxy:error] [pid 872418:tid 872670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:57.642299 2026] [proxy_http:error] [pid 872418:tid 872670] [client 98.87.102.177:21894] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:57.644051 2026] [proxy:error] [pid 872418:tid 872670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:57.644120 2026] [proxy_http:error] [pid 872418:tid 872670] [client 98.87.102.177:21894] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:57.690945 2026] [security2:error] [pid 872418:tid 872549] [client 197.185.157.187:12810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuWvVymN6QYcoA7XB5ZkwAAAAE"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 13:23:57.836879 2026] [security2:error] [pid 872418:tid 872672] [client 68.221.186.136:6776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuWvVymN6QYcoA7XB5ZrgAAAHw"]
[Thu Jul 30 13:23:58.460297 2026] [core:notice] [pid 872418:tid 872664] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:23:58.491525 2026] [proxy:error] [pid 872418:tid 872660] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:58.491605 2026] [proxy_http:error] [pid 872418:tid 872660] [client 44.216.125.112:47679] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:58.492484 2026] [proxy:error] [pid 872418:tid 872660] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:58.492544 2026] [proxy_http:error] [pid 872418:tid 872660] [client 44.216.125.112:47679] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:58.493700 2026] [proxy:error] [pid 872418:tid 872646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:58.493775 2026] [proxy_http:error] [pid 872418:tid 872646] [client 44.216.125.112:61359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:58.494631 2026] [proxy:error] [pid 872418:tid 872646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:23:58.494691 2026] [proxy_http:error] [pid 872418:tid 872646] [client 44.216.125.112:61359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:23:58.798160 2026] [security2:error] [pid 872418:tid 872657] [client 68.221.186.136:13837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuWvlymN6QYcoA7XB5Z0QAAAG0"]
[Thu Jul 30 13:23:59.463707 2026] [security2:error] [pid 872418:tid 872476] [remote 57.141.0.20:52520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuWv1ymN6QYcoA7XB5Z6gAAADk"]
[Thu Jul 30 13:24:00.643380 2026] [core:notice] [pid 872418:tid 872635] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:00.689114 2026] [security2:error] [pid 872418:tid 872574] [client 127.0.0.1:51900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuWwFymN6QYcoA7XB5aCQAAABo"]
[Thu Jul 30 13:24:00.689184 2026] [security2:error] [pid 872418:tid 872658] [client 74.7.230.25:53488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tvs.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuWwFymN6QYcoA7XB5aBwAAbkE"]
[Thu Jul 30 13:24:00.883890 2026] [security2:error] [pid 872418:tid 872632] [client 43.173.175.235:35058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.175.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/06/23/ete-2013-15-accessoires-et-produits-de-beaute-a-mettre-dans-votre-valise/"] [unique_id "amuWwFymN6QYcoA7XB5aFQAAAFQ"]
[Thu Jul 30 13:24:01.322716 2026] [security2:error] [pid 872418:tid 872557] [client 68.221.186.136:13881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuWwVymN6QYcoA7XB5aJgAAAAk"]
[Thu Jul 30 13:24:01.548734 2026] [security2:error] [pid 872418:tid 872588] [client 111.119.39.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWwFymN6QYcoA7XB5aFAAAKDc"], referer: https://allmontecristi.com
[Thu Jul 30 13:24:01.550578 2026] [core:notice] [pid 872418:tid 872611] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:01.555448 2026] [security2:error] [pid 872418:tid 872611] [client 43.173.180.183:48418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/06/23/ete-2013-15-accessoires-et-produits-de-beaute-a-mettre-dans-votre-valise/"] [unique_id "amuWwVymN6QYcoA7XB5aLgAAAD8"], referer: https://carnetdeshopping.com/index.php/2013/06/23/ete-2013-15-accessoires-et-produits-de-beaute-a-mettre-dans-votre-valise/
[Thu Jul 30 13:24:02.299450 2026] [security2:error] [pid 872418:tid 872612] [client 68.221.186.136:2041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuWwlymN6QYcoA7XB5aRQAAAEA"]
[Thu Jul 30 13:24:02.938784 2026] [security2:error] [pid 872418:tid 872594] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/.git/config~"] [unique_id "amuWwlymN6QYcoA7XB5aXgAAAC4"]
[Thu Jul 30 13:24:03.196532 2026] [security2:error] [pid 872418:tid 872616] [client 68.221.186.136:1864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/updates.php"] [unique_id "amuWw1ymN6QYcoA7XB5aYQAAAEQ"]
[Thu Jul 30 13:24:03.386208 2026] [security2:error] [pid 872418:tid 872615] [client 40.77.167.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuWwVymN6QYcoA7XB5aIgAAAEM"]
[Thu Jul 30 13:24:03.452451 2026] [security2:error] [pid 872418:tid 872664] [client 20.91.199.21:36010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/011i.php"] [unique_id "amuWw1ymN6QYcoA7XB5abwAAAHQ"]
[Thu Jul 30 13:24:03.473851 2026] [security2:error] [pid 872418:tid 872557] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/sendgrid/.env"] [unique_id "amuWw1ymN6QYcoA7XB5acAAAAAk"]
[Thu Jul 30 13:24:04.139665 2026] [security2:error] [pid 872418:tid 872665] [client 68.221.186.136:1899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuWxFymN6QYcoA7XB5agQAAAHU"]
[Thu Jul 30 13:24:04.544230 2026] [core:notice] [pid 872418:tid 872606] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:04.673454 2026] [security2:error] [pid 872418:tid 872656] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/stripe/.env"] [unique_id "amuWxFymN6QYcoA7XB5akwAAAGw"]
[Thu Jul 30 13:24:05.010813 2026] [security2:error] [pid 872418:tid 872558] [client 20.91.199.21:49564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/03a005685d.php"] [unique_id "amuWxVymN6QYcoA7XB5anAAAAAo"]
[Thu Jul 30 13:24:05.013858 2026] [security2:error] [pid 872418:tid 872651] [client 68.221.186.136:12394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuWxVymN6QYcoA7XB5anQAAAGc"]
[Thu Jul 30 13:24:05.415265 2026] [core:notice] [pid 872418:tid 872600] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:05.746077 2026] [security2:error] [pid 872418:tid 872616] [client 68.221.186.136:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuWxVymN6QYcoA7XB5asQAAAEQ"]
[Thu Jul 30 13:24:05.871059 2026] [security2:error] [pid 872418:tid 872664] [client 20.91.199.21:36007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/403.php"] [unique_id "amuWxVymN6QYcoA7XB5aswAAAHQ"]
[Thu Jul 30 13:24:06.015734 2026] [security2:error] [pid 872418:tid 872556] [client 179.64.21.229:16787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWxlymN6QYcoA7XB5auAAAAAg"]
[Thu Jul 30 13:24:06.019528 2026] [security2:error] [pid 872418:tid 872556] [client 179.64.21.229:16787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuWxlymN6QYcoA7XB5auAAAAAg"]
[Thu Jul 30 13:24:06.558002 2026] [security2:error] [pid 872418:tid 872567] [client 20.91.199.21:52394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/404.php"] [unique_id "amuWxlymN6QYcoA7XB5ayAAAABM"]
[Thu Jul 30 13:24:06.793110 2026] [security2:error] [pid 872418:tid 872554] [client 68.221.186.136:11452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/alfa-rex.php7"] [unique_id "amuWxlymN6QYcoA7XB5a0QAAAAY"]
[Thu Jul 30 13:24:06.842096 2026] [security2:error] [pid 872418:tid 872633] [client 134.19.179.147:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuWxlymN6QYcoA7XB5a0wAAAFU"]
[Thu Jul 30 13:24:06.842180 2026] [security2:error] [pid 872418:tid 872633] [client 134.19.179.147:50022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuWxlymN6QYcoA7XB5a0wAAAFU"]
[Thu Jul 30 13:24:06.983115 2026] [core:notice] [pid 872418:tid 872649] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:07.017970 2026] [security2:error] [pid 872418:tid 872655] [client 57.141.0.7:56992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuWxlymN6QYcoA7XB5a0AAAa2Y"], referer: https://igetvape-australia.com/product/alibarbar-ingot-blueberry-mint-9000-puffs/?add-to-cart=933
[Thu Jul 30 13:24:07.097149 2026] [authz_core:error] [pid 872418:tid 872558] [client 185.177.72.54:0] AH01630: client denied by server configuration: /home1/apwudite/public_html/error_log
[Thu Jul 30 13:24:07.275205 2026] [security2:error] [pid 872418:tid 872646] [client 20.91.199.21:45696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/aa.php"] [unique_id "amuWx1ymN6QYcoA7XB5a5QAAAGI"]
[Thu Jul 30 13:24:07.838314 2026] [security2:error] [pid 872418:tid 872648] [client 20.91.199.21:36191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/aafewc0k.php"] [unique_id "amuWx1ymN6QYcoA7XB5a8gAAAGQ"]
[Thu Jul 30 13:24:08.493405 2026] [security2:error] [pid 872418:tid 872583] [client 20.91.199.21:35768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/abcd.php"] [unique_id "amuWyFymN6QYcoA7XB5bAwAAACM"]
[Thu Jul 30 13:24:09.375893 2026] [security2:error] [pid 872418:tid 872659] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/var/www/html/.env"] [unique_id "amuWyVymN6QYcoA7XB5bIgAAAG8"]
[Thu Jul 30 13:24:09.507584 2026] [security2:error] [pid 872418:tid 872594] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/index.php/ci_environment"] [unique_id "amuWyVymN6QYcoA7XB5bJAAAAC4"]
[Thu Jul 30 13:24:09.695085 2026] [core:notice] [pid 872418:tid 872552] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:10.146086 2026] [security2:error] [pid 872418:tid 872551] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileName. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "amuWylymN6QYcoA7XB5bMgAAAAM"]
[Thu Jul 30 13:24:10.179808 2026] [security2:error] [pid 872418:tid 872602] [client 20.91.199.21:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/about.php"] [unique_id "amuWylymN6QYcoA7XB5bNAAAADY"]
[Thu Jul 30 13:24:10.275867 2026] [security2:error] [pid 872418:tid 872559] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileName. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "amuWylymN6QYcoA7XB5bOwAAAAs"]
[Thu Jul 30 13:24:10.413146 2026] [security2:error] [pid 872418:tid 872588] [client 68.221.186.136:12398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/alfanew.php"] [unique_id "amuWylymN6QYcoA7XB5bPQAAACg"]
[Thu Jul 30 13:24:10.413772 2026] [security2:error] [pid 872418:tid 872595] [client 66.249.71.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.palmtreepools.ca"] [uri "/index.php"] [unique_id "amuWyFymN6QYcoA7XB5bDgAAL3Q"]
[Thu Jul 30 13:24:10.677436 2026] [cgid:error] [pid 872418:tid 872663] [client 185.177.72.54:0] AH01264: stderr from /home1/apwudite/public_html/cgi-bin/config.exp: script not found or unable to stat
[Thu Jul 30 13:24:11.142999 2026] [core:notice] [pid 872418:tid 872650] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:11.229941 2026] [security2:error] [pid 872418:tid 872634] [client 20.91.199.21:50841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/admin.php"] [unique_id "amuWy1ymN6QYcoA7XB5bVwAAAFY"]
[Thu Jul 30 13:24:11.630634 2026] [security2:error] [pid 872418:tid 872633] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/var/www/.env"] [unique_id "amuWy1ymN6QYcoA7XB5bYAAAAFU"]
[Thu Jul 30 13:24:11.734566 2026] [security2:error] [pid 872418:tid 872548] [client 74.7.241.172:51330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "ecvh.ae.muu.udi.temporary.site"] [uri "/index.php"] [unique_id "amuWy1ymN6QYcoA7XB5bUQAAADM"]
[Thu Jul 30 13:24:11.734596 2026] [security2:error] [pid 872418:tid 872548] [client 74.7.241.172:51330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ecvh.ae.muu.udi.temporary.site"] [uri "/index.php"] [unique_id "amuWy1ymN6QYcoA7XB5bUQAAADM"]
[Thu Jul 30 13:24:11.761526 2026] [security2:error] [pid 872418:tid 872603] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/var/www/html/.env"] [unique_id "amuWy1ymN6QYcoA7XB5bZAAAADc"]
[Thu Jul 30 13:24:11.944104 2026] [core:notice] [pid 872418:tid 872438] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:12.731974 2026] [security2:error] [pid 872418:tid 872551] [client 74.7.241.172:50602] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ecvh.ae"] [uri "/index.php"] [unique_id "amuWzFymN6QYcoA7XB5bfQAAAAM"]
[Thu Jul 30 13:24:12.804099 2026] [security2:error] [pid 872418:tid 872607] [client 20.91.199.21:52396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/adminfuns.php"] [unique_id "amuWzFymN6QYcoA7XB5bgQAAADs"]
[Thu Jul 30 13:24:12.913568 2026] [core:notice] [pid 872418:tid 872587] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:12.972950 2026] [security2:error] [pid 872418:tid 872588] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/mail/sendmail.cf"] [unique_id "amuWzFymN6QYcoA7XB5bigAAACg"]
[Thu Jul 30 13:24:13.073450 2026] [security2:error] [pid 872418:tid 872469] [remote 57.141.0.20:43480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuWzVymN6QYcoA7XB5bjwAATjI"]
[Thu Jul 30 13:24:13.101242 2026] [security2:error] [pid 872418:tid 872556] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/ssmtp/ssmtp.conf"] [unique_id "amuWzVymN6QYcoA7XB5bkAAAAAg"]
[Thu Jul 30 13:24:13.238325 2026] [security2:error] [pid 872418:tid 872615] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/exim4/exim4.conf"] [unique_id "amuWzVymN6QYcoA7XB5bkQAAAEM"]
[Thu Jul 30 13:24:13.371185 2026] [security2:error] [pid 872418:tid 872584] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/exim4/update-exim4.conf.conf"] [unique_id "amuWzVymN6QYcoA7XB5bmgAAACQ"]
[Thu Jul 30 13:24:13.416476 2026] [security2:error] [pid 872418:tid 872576] [client 74.7.241.172:55370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "ecvh.ae"] [uri "/index.php"] [unique_id "amuWzVymN6QYcoA7XB5bmQAAHBo"], referer: http://ecvh.ae/
[Thu Jul 30 13:24:13.505141 2026] [security2:error] [pid 872418:tid 872637] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/postfix/main.cf"] [unique_id "amuWzVymN6QYcoA7XB5bngAAAFk"]
[Thu Jul 30 13:24:13.649405 2026] [security2:error] [pid 872418:tid 872578] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuWzFymN6QYcoA7XB5biwAAHhE"]
[Thu Jul 30 13:24:13.969876 2026] [core:notice] [pid 872418:tid 872580] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:14.037054 2026] [access_compat:error] [pid 872418:tid 872548] [client 185.177.72.54:0] AH01797: client denied by server configuration: /home1/apwudite/public_html/server-status
[Thu Jul 30 13:24:14.173307 2026] [security2:error] [pid 872418:tid 872627] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/server-info"] [unique_id "amuWzlymN6QYcoA7XB5bswAAAE8"]
[Thu Jul 30 13:24:14.201583 2026] [security2:error] [pid 872418:tid 872604] [client 50.6.43.217:10314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuWzlymN6QYcoA7XB5btAAAADg"]
[Thu Jul 30 13:24:14.210699 2026] [security2:error] [pid 872418:tid 872658] [client 50.6.43.217:10326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuWzlymN6QYcoA7XB5btQAAAG4"]
[Thu Jul 30 13:24:14.221343 2026] [security2:error] [pid 872418:tid 872651] [client 50.6.43.217:10340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuWzlymN6QYcoA7XB5btgAAAGc"]
[Thu Jul 30 13:24:14.247881 2026] [security2:error] [pid 872418:tid 872590] [client 74.7.241.172:55370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/index.php"] [unique_id "amuWzVymN6QYcoA7XB5bowAAKh0"], referer: https://ecvh.ae/
[Thu Jul 30 13:24:14.342249 2026] [security2:error] [pid 872418:tid 872674] [client 20.91.199.21:56822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/albin.php"] [unique_id "amuWzlymN6QYcoA7XB5buAAAAH4"]
[Thu Jul 30 13:24:14.701525 2026] [security2:error] [pid 872418:tid 872550] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "amuWzlymN6QYcoA7XB5bxgAAAAI"]
[Thu Jul 30 13:24:14.898455 2026] [security2:error] [pid 872418:tid 872605] [client 20.91.199.21:49822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/amfsqvgv.php"] [unique_id "amuWzlymN6QYcoA7XB5bzAAAADk"]
[Thu Jul 30 13:24:15.338996 2026] [security2:error] [pid 872418:tid 872549] [client 68.221.186.136:9896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuWz1ymN6QYcoA7XB5b2wAAAAE"]
[Thu Jul 30 13:24:15.579510 2026] [security2:error] [pid 872418:tid 872634] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/static../var/www/html/.env"] [unique_id "amuWz1ymN6QYcoA7XB5b5AAAAFY"]
[Thu Jul 30 13:24:15.621475 2026] [security2:error] [pid 872418:tid 872570] [client 20.91.199.21:51542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/ant.php"] [unique_id "amuWz1ymN6QYcoA7XB5b5QAAABY"]
[Thu Jul 30 13:24:15.846571 2026] [security2:error] [pid 872418:tid 872612] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/boto.cfg"] [unique_id "amuWz1ymN6QYcoA7XB5b6wAAAEA"]
[Thu Jul 30 13:24:16.194155 2026] [security2:error] [pid 872418:tid 872573] [client 20.91.199.21:35755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/appreciators.php"] [unique_id "amuW0FymN6QYcoA7XB5b-AAAABk"]
[Thu Jul 30 13:24:16.278021 2026] [security2:error] [pid 872418:tid 872483] [remote 5.161.62.209:11754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.arabiantourz.com"] [uri "/.env"] [unique_id "amuW0FymN6QYcoA7XB5b_AAAeEA"]
[Thu Jul 30 13:24:16.382196 2026] [security2:error] [pid 872418:tid 872673] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/index_dev.php/_profiler/open"] [unique_id "amuW0FymN6QYcoA7XB5b_QAAAH0"]
[Thu Jul 30 13:24:16.489732 2026] [security2:error] [pid 872418:tid 872633] [client 179.64.21.229:43949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuW0FymN6QYcoA7XB5cBAAAAFU"]
[Thu Jul 30 13:24:16.489829 2026] [security2:error] [pid 872418:tid 872633] [client 179.64.21.229:43949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuW0FymN6QYcoA7XB5cBAAAAFU"]
[Thu Jul 30 13:24:16.634116 2026] [security2:error] [pid 872418:tid 872667] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/index_dev.php/_profiler/open"] [unique_id "amuW0FymN6QYcoA7XB5cCgAAAHc"]
[Thu Jul 30 13:24:16.882381 2026] [security2:error] [pid 872418:tid 872621] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/"] [unique_id "amuW0FymN6QYcoA7XB5cEgAAAEk"]
[Thu Jul 30 13:24:17.014011 2026] [security2:error] [pid 872418:tid 872615] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/gitlab/gitlab.rb"] [unique_id "amuW0VymN6QYcoA7XB5cGAAAAEM"]
[Thu Jul 30 13:24:17.589748 2026] [security2:error] [pid 872418:tid 872581] [client 20.91.199.21:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/archive.php"] [unique_id "amuW0VymN6QYcoA7XB5cLAAAACE"]
[Thu Jul 30 13:24:17.628512 2026] [security2:error] [pid 872418:tid 872585] [client 68.221.186.136:12348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuW0VymN6QYcoA7XB5cMwAAACU"]
[Thu Jul 30 13:24:18.025573 2026] [security2:error] [pid 872418:tid 872610] [client 74.7.175.154:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mgstudiostore.com"] [uri "/cgi-sys/404.html"] [unique_id "amuW0lymN6QYcoA7XB5cQAAAAD4"]
[Thu Jul 30 13:24:18.026373 2026] [security2:error] [pid 872418:tid 872603] [client 74.7.175.154:40282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mgstudiostore.com"] [uri "/robots.txt"] [unique_id "amuW0lymN6QYcoA7XB5cPgAAN0Q"]
[Thu Jul 30 13:24:18.312818 2026] [security2:error] [pid 872418:tid 872646] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:helpFilePath. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:helpFilePath"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/jsp/help-hierarchyTree.jsp"] [unique_id "amuW0lymN6QYcoA7XB5cUAAAAGI"]
[Thu Jul 30 13:24:18.452749 2026] [security2:error] [pid 872418:tid 872602] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:helpFilePath. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:helpFilePath"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/jsp/help-hierarchyTree.jsp"] [unique_id "amuW0lymN6QYcoA7XB5cUgAAADY"]
[Thu Jul 30 13:24:18.466420 2026] [security2:error] [pid 872418:tid 872630] [client 20.91.199.21:36008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/as.php"] [unique_id "amuW0lymN6QYcoA7XB5cUwAAAFI"]
[Thu Jul 30 13:24:18.595131 2026] [cgid:error] [pid 872418:tid 872641] [client 185.177.72.54:0] AH01264: stderr from /home1/apwudite/public_html/cgi-bin/php: script not found or unable to stat
[Thu Jul 30 13:24:18.725553 2026] [cgid:error] [pid 872418:tid 872616] [client 185.177.72.54:0] AH01264: stderr from /home1/apwudite/public_html/cgi-bin/php5: script not found or unable to stat
[Thu Jul 30 13:24:18.854121 2026] [security2:error] [pid 872418:tid 872549] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/var/www/.env"] [unique_id "amuW0lymN6QYcoA7XB5cZgAAAAE"]
[Thu Jul 30 13:24:18.887660 2026] [security2:error] [pid 872418:tid 872568] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW0lymN6QYcoA7XB5cTAAAABQ"]
[Thu Jul 30 13:24:18.932116 2026] [core:error] [pid 872418:tid 872539] [remote 74.7.230.33:53724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:24:18.932143 2026] [core:error] [pid 872418:tid 872539] [remote 74.7.230.33:53724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:24:18.932313 2026] [security2:error] [pid 872418:tid 872631] [client 74.7.230.33:53724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "offthewallinbisbee.com.dov.dtn.temporary.site"] [uri "/index.php"] [unique_id "amuW0lymN6QYcoA7XB5cawAAU3g"]
[Thu Jul 30 13:24:18.940746 2026] [security2:error] [pid 872418:tid 872573] [client 103.189.161.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuW0VymN6QYcoA7XB5cPQAAABk"], referer: https://tereashops.com/product/iqos-terea-black-fuchsia-menthol/
[Thu Jul 30 13:24:19.099598 2026] [security2:error] [pid 872418:tid 872674] [client 68.221.186.136:41902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-p.php7"] [unique_id "amuW01ymN6QYcoA7XB5cbQAAAH4"]
[Thu Jul 30 13:24:19.112367 2026] [security2:error] [pid 872418:tid 872672] [client 185.177.72.54:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "markmocek.com"] [uri "/proc/self/environ"] [unique_id "amuW01ymN6QYcoA7XB5cbgAAAHw"]
[Thu Jul 30 13:24:19.350435 2026] [security2:error] [pid 872418:tid 872665] [client 185.177.72.54:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "markmocek.com"] [uri "/proc/self/environ"] [unique_id "amuW01ymN6QYcoA7XB5cdQAAAHU"]
[Thu Jul 30 13:24:19.640600 2026] [security2:error] [pid 872418:tid 872651] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/etc/shadow"] [unique_id "amuW01ymN6QYcoA7XB5ceQAAAGc"]
[Thu Jul 30 13:24:19.671103 2026] [security2:error] [pid 872418:tid 872521] [remote 57.141.0.7:24028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/4208817797/feed/rss2/"] [unique_id "amuW01ymN6QYcoA7XB5cewAAMGY"]
[Thu Jul 30 13:24:20.014386 2026] [security2:error] [pid 872418:tid 872601] [client 185.177.72.54:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "markmocek.com"] [uri "/proc/self/environ"] [unique_id "amuW1FymN6QYcoA7XB5cjQAAADU"]
[Thu Jul 30 13:24:20.304901 2026] [security2:error] [pid 872418:tid 872629] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW01ymN6QYcoA7XB5cgQAAAFE"]
[Thu Jul 30 13:24:20.688728 2026] [security2:error] [pid 872418:tid 872663] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/magento/app/etc/env.php"] [unique_id "amuW1FymN6QYcoA7XB5cngAAAHM"]
[Thu Jul 30 13:24:21.062973 2026] [security2:error] [pid 872418:tid 872670] [client 20.91.199.21:49283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/atomlib.php"] [unique_id "amuW1VymN6QYcoA7XB5cqgAAAHo"]
[Thu Jul 30 13:24:21.752206 2026] [security2:error] [pid 872418:tid 872604] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/supabase/.env"] [unique_id "amuW1VymN6QYcoA7XB5cwgAAADg"]
[Thu Jul 30 13:24:21.886755 2026] [security2:error] [pid 872418:tid 872633] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/.env"] [unique_id "amuW1VymN6QYcoA7XB5cyQAAAFU"]
[Thu Jul 30 13:24:22.028041 2026] [security2:error] [pid 872418:tid 872582] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/.env"] [unique_id "amuW1lymN6QYcoA7XB5czAAAACI"]
[Thu Jul 30 13:24:22.029227 2026] [core:notice] [pid 872418:tid 872560] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:22.160803 2026] [security2:error] [pid 872418:tid 872646] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/app/.env"] [unique_id "amuW1lymN6QYcoA7XB5c1wAAAGI"]
[Thu Jul 30 13:24:22.301578 2026] [security2:error] [pid 872418:tid 872641] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/system/.env"] [unique_id "amuW1lymN6QYcoA7XB5c2wAAAF0"]
[Thu Jul 30 13:24:22.307577 2026] [security2:error] [pid 872418:tid 872558] [client 68.221.186.136:13509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuW1lymN6QYcoA7XB5c3AAAAAo"]
[Thu Jul 30 13:24:22.430577 2026] [security2:error] [pid 872418:tid 872588] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/laravel/.env"] [unique_id "amuW1lymN6QYcoA7XB5c4QAAACg"]
[Thu Jul 30 13:24:22.561855 2026] [security2:error] [pid 872418:tid 872564] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/core/.env"] [unique_id "amuW1lymN6QYcoA7XB5c5AAAABA"]
[Thu Jul 30 13:24:22.696193 2026] [security2:error] [pid 872418:tid 872568] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/vendor/.env"] [unique_id "amuW1lymN6QYcoA7XB5c6AAAABQ"]
[Thu Jul 30 13:24:22.728328 2026] [security2:error] [pid 872418:tid 872621] [client 20.91.199.21:36450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/autoload_classmap.php"] [unique_id "amuW1lymN6QYcoA7XB5c6wAAAEk"]
[Thu Jul 30 13:24:22.774715 2026] [security2:error] [pid 872418:tid 872420] [remote 57.141.0.49:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/94764231632/feed/rss2/"] [unique_id "amuW1lymN6QYcoA7XB5c4wAAdwE"]
[Thu Jul 30 13:24:22.827102 2026] [security2:error] [pid 872418:tid 872577] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/storage/.env"] [unique_id "amuW1lymN6QYcoA7XB5c7AAAAB0"]
[Thu Jul 30 13:24:22.975500 2026] [security2:error] [pid 872418:tid 872573] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/public/.env"] [unique_id "amuW1lymN6QYcoA7XB5c9AAAABk"]
[Thu Jul 30 13:24:23.111453 2026] [security2:error] [pid 872418:tid 872566] [client 68.221.186.136:41895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuW11ymN6QYcoA7XB5c9gAAABI"]
[Thu Jul 30 13:24:23.112508 2026] [security2:error] [pid 872418:tid 872632] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/dev/.env"] [unique_id "amuW11ymN6QYcoA7XB5c9QAAAFQ"]
[Thu Jul 30 13:24:23.245773 2026] [security2:error] [pid 872418:tid 872654] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/v1/.env"] [unique_id "amuW11ymN6QYcoA7XB5c-gAAAGo"]
[Thu Jul 30 13:24:23.332947 2026] [security2:error] [pid 872418:tid 872661] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuW1lymN6QYcoA7XB5c6gAAcXM"]
[Thu Jul 30 13:24:23.396077 2026] [security2:error] [pid 872418:tid 872598] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/v2/.env"] [unique_id "amuW11ymN6QYcoA7XB5c_gAAADI"]
[Thu Jul 30 13:24:23.553579 2026] [core:notice] [pid 872418:tid 872424] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:23.805497 2026] [core:notice] [pid 872418:tid 872544] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:23.824775 2026] [security2:error] [pid 872418:tid 872652] [client 20.91.199.21:51812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/bb.php"] [unique_id "amuW11ymN6QYcoA7XB5dEAAAAGg"]
[Thu Jul 30 13:24:24.202389 2026] [security2:error] [pid 872418:tid 872668] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.env.local.php"] [unique_id "amuW2FymN6QYcoA7XB5dHwAAAHg"]
[Thu Jul 30 13:24:24.245289 2026] [security2:error] [pid 872418:tid 872633] [client 68.221.186.136:6515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-content/repeater.php"] [unique_id "amuW2FymN6QYcoA7XB5dIQAAAFU"]
[Thu Jul 30 13:24:24.296001 2026] [security2:error] [pid 872418:tid 872582] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW11ymN6QYcoA7XB5dCgAAACI"]
[Thu Jul 30 13:24:24.450504 2026] [security2:error] [pid 872418:tid 872621] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/config/.env"] [unique_id "amuW2FymN6QYcoA7XB5dKAAAAEk"]
[Thu Jul 30 13:24:24.839315 2026] [security2:error] [pid 872418:tid 872561] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/app/config/.env"] [unique_id "amuW2FymN6QYcoA7XB5dNAAAAA0"]
[Thu Jul 30 13:24:24.959678 2026] [security2:error] [pid 872418:tid 872656] [client 20.91.199.21:51822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/bnm.php"] [unique_id "amuW2FymN6QYcoA7XB5dOQAAAGw"]
[Thu Jul 30 13:24:24.970910 2026] [security2:error] [pid 872418:tid 872650] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/apps/.env"] [unique_id "amuW2FymN6QYcoA7XB5dPAAAAGY"]
[Thu Jul 30 13:24:25.040651 2026] [core:notice] [pid 872418:tid 872439] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:25.102177 2026] [security2:error] [pid 872418:tid 872627] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/apps/config/.env"] [unique_id "amuW2VymN6QYcoA7XB5dPwAAAE8"]
[Thu Jul 30 13:24:25.219130 2026] [core:notice] [pid 872418:tid 872453] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:25.238332 2026] [core:notice] [pid 872418:tid 872419] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:25.243480 2026] [security2:error] [pid 872418:tid 872604] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/backend/.env"] [unique_id "amuW2VymN6QYcoA7XB5dQwAAADg"]
[Thu Jul 30 13:24:25.263275 2026] [core:notice] [pid 872418:tid 872466] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:25.373841 2026] [security2:error] [pid 872418:tid 872554] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/client/.env"] [unique_id "amuW2VymN6QYcoA7XB5dSAAAAAY"]
[Thu Jul 30 13:24:25.500854 2026] [security2:error] [pid 872418:tid 872590] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/clients/.env"] [unique_id "amuW2VymN6QYcoA7XB5dTgAAACo"]
[Thu Jul 30 13:24:25.635704 2026] [security2:error] [pid 872418:tid 872572] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/customer/.env"] [unique_id "amuW2VymN6QYcoA7XB5dUAAAABg"]
[Thu Jul 30 13:24:25.762680 2026] [security2:error] [pid 872418:tid 872579] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/customers/.env"] [unique_id "amuW2VymN6QYcoA7XB5dUwAAAB8"]
[Thu Jul 30 13:24:26.019073 2026] [security2:error] [pid 872418:tid 872622] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/administrator/.env"] [unique_id "amuW2lymN6QYcoA7XB5dYAAAAEo"]
[Thu Jul 30 13:24:26.145763 2026] [security2:error] [pid 872418:tid 872629] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/wp/.env"] [unique_id "amuW2lymN6QYcoA7XB5dYQAAAFE"]
[Thu Jul 30 13:24:26.274810 2026] [security2:error] [pid 872418:tid 872607] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/wordpress/.env"] [unique_id "amuW2lymN6QYcoA7XB5dYgAAADs"]
[Thu Jul 30 13:24:26.404244 2026] [security2:error] [pid 872418:tid 872666] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/cms/.env"] [unique_id "amuW2lymN6QYcoA7XB5dZgAAAHY"]
[Thu Jul 30 13:24:26.532109 2026] [security2:error] [pid 872418:tid 872589] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/database/.env"] [unique_id "amuW2lymN6QYcoA7XB5dbAAAACk"]
[Thu Jul 30 13:24:26.597057 2026] [security2:error] [pid 872418:tid 872620] [client 127.0.0.1:13082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuW2lymN6QYcoA7XB5dcgAAAEg"]
[Thu Jul 30 13:24:26.597132 2026] [security2:error] [pid 872418:tid 872564] [client 74.7.244.35:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.abudhabifurnituremoversandpackers.site"] [uri "/robots.txt"] [unique_id "amuW2lymN6QYcoA7XB5dcQAAEDE"]
[Thu Jul 30 13:24:26.616696 2026] [core:notice] [pid 872418:tid 872485] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:26.661363 2026] [security2:error] [pid 872418:tid 872609] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/db/.env"] [unique_id "amuW2lymN6QYcoA7XB5ddAAAAD0"]
[Thu Jul 30 13:24:26.738217 2026] [security2:error] [pid 872418:tid 872563] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuW2lymN6QYcoA7XB5dcAAAAA8"]
[Thu Jul 30 13:24:26.787686 2026] [security2:error] [pid 872418:tid 872613] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/upload/.env"] [unique_id "amuW2lymN6QYcoA7XB5ddgAAAEE"]
[Thu Jul 30 13:24:26.827494 2026] [security2:error] [pid 872418:tid 872663] [client 179.64.21.229:48857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuW2lymN6QYcoA7XB5ddwAAAHM"]
[Thu Jul 30 13:24:26.827622 2026] [security2:error] [pid 872418:tid 872663] [client 179.64.21.229:48857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuW2lymN6QYcoA7XB5ddwAAAHM"]
[Thu Jul 30 13:24:26.882608 2026] [core:notice] [pid 872418:tid 872476] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:26.886760 2026] [core:notice] [pid 872418:tid 872491] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:26.920353 2026] [security2:error] [pid 872418:tid 872631] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/uploads/.env"] [unique_id "amuW2lymN6QYcoA7XB5dfQAAAFM"]
[Thu Jul 30 13:24:27.068111 2026] [security2:error] [pid 872418:tid 872671] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/backup/.env"] [unique_id "amuW21ymN6QYcoA7XB5dgwAAAHs"]
[Thu Jul 30 13:24:27.195444 2026] [security2:error] [pid 872418:tid 872548] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/backups/.env"] [unique_id "amuW21ymN6QYcoA7XB5dhgAAAAA"]
[Thu Jul 30 13:24:27.321743 2026] [security2:error] [pid 872418:tid 872658] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/.backup/.env"] [unique_id "amuW21ymN6QYcoA7XB5dhwAAAG4"]
[Thu Jul 30 13:24:27.339712 2026] [security2:error] [pid 872418:tid 872657] [client 20.91.199.21:49803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/bootstrap.php"] [unique_id "amuW21ymN6QYcoA7XB5diAAAAG0"]
[Thu Jul 30 13:24:27.421608 2026] [core:notice] [pid 872418:tid 872484] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:27.575355 2026] [security2:error] [pid 872418:tid 872652] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/old/.env"] [unique_id "amuW21ymN6QYcoA7XB5dkQAAAGg"]
[Thu Jul 30 13:24:27.706747 2026] [security2:error] [pid 872418:tid 872646] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/new/.env"] [unique_id "amuW21ymN6QYcoA7XB5dlQAAAGI"]
[Thu Jul 30 13:24:27.832532 2026] [security2:error] [pid 872418:tid 872559] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/2020/.env"] [unique_id "amuW21ymN6QYcoA7XB5dlgAAAAs"]
[Thu Jul 30 13:24:27.958970 2026] [security2:error] [pid 872418:tid 872623] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/2021/.env"] [unique_id "amuW21ymN6QYcoA7XB5dmgAAAEs"]
[Thu Jul 30 13:24:27.973587 2026] [security2:error] [pid 872418:tid 872674] [client 172.237.109.114:55986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/ui/login"] [unique_id "amuW21ymN6QYcoA7XB5dmwAAAH4"]
[Thu Jul 30 13:24:28.092695 2026] [security2:error] [pid 872418:tid 872585] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/2022/.env"] [unique_id "amuW3FymN6QYcoA7XB5dogAAACU"]
[Thu Jul 30 13:24:28.219349 2026] [security2:error] [pid 872418:tid 872666] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/2023/.env"] [unique_id "amuW3FymN6QYcoA7XB5dqgAAAHY"]
[Thu Jul 30 13:24:28.353315 2026] [security2:error] [pid 872418:tid 872615] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/2024/.env"] [unique_id "amuW3FymN6QYcoA7XB5dqwAAAEM"]
[Thu Jul 30 13:24:28.482269 2026] [security2:error] [pid 872418:tid 872670] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/v1/.env"] [unique_id "amuW3FymN6QYcoA7XB5drwAAAHo"]
[Thu Jul 30 13:24:28.616396 2026] [security2:error] [pid 872418:tid 872568] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/v2/.env"] [unique_id "amuW3FymN6QYcoA7XB5dtAAAABQ"]
[Thu Jul 30 13:24:28.742358 2026] [security2:error] [pid 872418:tid 872672] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/v3/.env"] [unique_id "amuW3FymN6QYcoA7XB5dugAAAHw"]
[Thu Jul 30 13:24:28.764596 2026] [security2:error] [pid 872418:tid 872647] [client 20.91.199.21:49536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/buy.php"] [unique_id "amuW3FymN6QYcoA7XB5duwAAAGM"]
[Thu Jul 30 13:24:28.871634 2026] [security2:error] [pid 872418:tid 872575] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/config/.env"] [unique_id "amuW3FymN6QYcoA7XB5dvQAAABs"]
[Thu Jul 30 13:24:28.988567 2026] [security2:error] [pid 872418:tid 872614] [client 68.67.112.242:18521] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuW3FymN6QYcoA7XB5dxAAAAEI"]
[Thu Jul 30 13:24:29.002336 2026] [security2:error] [pid 872418:tid 872628] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/core/.env"] [unique_id "amuW3FymN6QYcoA7XB5dxQAAAFA"]
[Thu Jul 30 13:24:29.133876 2026] [security2:error] [pid 872418:tid 872584] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/app/.env"] [unique_id "amuW3VymN6QYcoA7XB5dygAAACQ"]
[Thu Jul 30 13:24:29.263232 2026] [security2:error] [pid 872418:tid 872657] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/test/.env"] [unique_id "amuW3VymN6QYcoA7XB5dzgAAAG0"]
[Thu Jul 30 13:24:29.401854 2026] [security2:error] [pid 872418:tid 872659] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/dev/.env"] [unique_id "amuW3VymN6QYcoA7XB5d0gAAAG8"]
[Thu Jul 30 13:24:29.529465 2026] [security2:error] [pid 872418:tid 872562] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/api/beta/.env"] [unique_id "amuW3VymN6QYcoA7XB5d1gAAAA4"]
[Thu Jul 30 13:24:29.664493 2026] [security2:error] [pid 872418:tid 872653] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/beta/.env"] [unique_id "amuW3VymN6QYcoA7XB5d3QAAAGk"]
[Thu Jul 30 13:24:29.796375 2026] [security2:error] [pid 872418:tid 872644] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/prod/.env"] [unique_id "amuW3VymN6QYcoA7XB5d3gAAAGA"]
[Thu Jul 30 13:24:29.929043 2026] [security2:error] [pid 872418:tid 872558] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/production/.env"] [unique_id "amuW3VymN6QYcoA7XB5d3wAAAAo"]
[Thu Jul 30 13:24:30.057267 2026] [security2:error] [pid 872418:tid 872550] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/stage/.env"] [unique_id "amuW3lymN6QYcoA7XB5d4wAAAAI"]
[Thu Jul 30 13:24:30.188534 2026] [security2:error] [pid 872418:tid 872622] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/staging/.env"] [unique_id "amuW3lymN6QYcoA7XB5d6wAAAEo"]
[Thu Jul 30 13:24:30.314676 2026] [security2:error] [pid 872418:tid 872549] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/test/.env"] [unique_id "amuW3lymN6QYcoA7XB5d7AAAAAE"]
[Thu Jul 30 13:24:30.352540 2026] [core:notice] [pid 872418:tid 872487] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:30.447421 2026] [security2:error] [pid 872418:tid 872606] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/testing/.env"] [unique_id "amuW3lymN6QYcoA7XB5d8AAAADo"]
[Thu Jul 30 13:24:30.577585 2026] [security2:error] [pid 872418:tid 872621] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/development/.env"] [unique_id "amuW3lymN6QYcoA7XB5d9AAAAEk"]
[Thu Jul 30 13:24:30.606864 2026] [core:notice] [pid 872418:tid 872630] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:30.612164 2026] [security2:error] [pid 872418:tid 872630] [client 52.53.223.6:2722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2010/05/03/40-paires-de-chaussures-pour-le-printemps-2010/"] [unique_id "amuW3lymN6QYcoA7XB5d7QAAAFI"]
[Thu Jul 30 13:24:30.703612 2026] [security2:error] [pid 872418:tid 872577] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/develop/.env"] [unique_id "amuW3lymN6QYcoA7XB5d-AAAAB0"]
[Thu Jul 30 13:24:30.838565 2026] [security2:error] [pid 872418:tid 872640] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/docker/.env"] [unique_id "amuW3lymN6QYcoA7XB5eAAAAAFw"]
[Thu Jul 30 13:24:30.966898 2026] [security2:error] [pid 872418:tid 872647] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/docker-compose/.env"] [unique_id "amuW3lymN6QYcoA7XB5eAQAAAGM"]
[Thu Jul 30 13:24:31.064283 2026] [core:notice] [pid 872418:tid 872671] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:31.097321 2026] [security2:error] [pid 872418:tid 872628] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/.docker/.env"] [unique_id "amuW31ymN6QYcoA7XB5eCQAAAFA"]
[Thu Jul 30 13:24:31.225209 2026] [security2:error] [pid 872418:tid 872565] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/src/.env"] [unique_id "amuW31ymN6QYcoA7XB5eEQAAABE"]
[Thu Jul 30 13:24:31.350016 2026] [security2:error] [pid 872418:tid 872625] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/source/.env"] [unique_id "amuW31ymN6QYcoA7XB5eGAAAAE0"]
[Thu Jul 30 13:24:31.490155 2026] [security2:error] [pid 872418:tid 872608] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/sources/.env"] [unique_id "amuW31ymN6QYcoA7XB5eGgAAADw"]
[Thu Jul 30 13:24:31.969020 2026] [security2:error] [pid 872418:tid 872473] [remote 165.22.214.22:50532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.214.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuW31ymN6QYcoA7XB5eJgAABDY"]
[Thu Jul 30 13:24:31.982672 2026] [security2:error] [pid 872418:tid 872614] [client 49.36.219.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuW31ymN6QYcoA7XB5eCAAAAEI"], referer: https://tereashops.com/product/iqos-terea-black-fuchsia-menthol/
[Thu Jul 30 13:24:34.478342 2026] [core:notice] [pid 872418:tid 872668] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:34.516429 2026] [security2:error] [pid 872418:tid 872554] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW4VymN6QYcoA7XB5eTQAAAAY"]
[Thu Jul 30 13:24:34.586106 2026] [security2:error] [pid 872418:tid 872662] [client 20.91.199.21:36445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/chosen.php"] [unique_id "amuW4lymN6QYcoA7XB5ecAAAAHI"]
[Thu Jul 30 13:24:34.979513 2026] [security2:error] [pid 872418:tid 872650] [client 172.236.9.101:30811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuW4lymN6QYcoA7XB5eYwAAAGY"]
[Thu Jul 30 13:24:35.138121 2026] [security2:error] [pid 872418:tid 872611] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW4lymN6QYcoA7XB5ebwAAAD8"]
[Thu Jul 30 13:24:35.249244 2026] [core:notice] [pid 872418:tid 872553] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:35.257203 2026] [core:error] [pid 872418:tid 872620] [client 74.7.244.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:24:35.257227 2026] [core:error] [pid 872418:tid 872620] [client 74.7.244.39:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:24:35.257352 2026] [security2:error] [pid 872418:tid 872620] [client 74.7.244.39:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.guardian-heir.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuW41ymN6QYcoA7XB5efwAAAEg"]
[Thu Jul 30 13:24:35.258844 2026] [security2:error] [pid 872418:tid 872626] [client 74.7.244.39:45670] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.guardian-heir.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuW41ymN6QYcoA7XB5efAAATg8"]
[Thu Jul 30 13:24:35.777549 2026] [security2:error] [pid 872418:tid 872548] [client 20.215.191.139:39714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/LA.php"] [unique_id "amuW41ymN6QYcoA7XB5ejQAAAAA"]
[Thu Jul 30 13:24:35.795583 2026] [security2:error] [pid 872418:tid 872561] [client 20.91.199.21:36449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/class-wp-image.php"] [unique_id "amuW41ymN6QYcoA7XB5ejgAAAA0"]
[Thu Jul 30 13:24:36.639116 2026] [security2:error] [pid 872418:tid 872656] [client 20.91.199.21:50817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/classsmtps.php"] [unique_id "amuW5FymN6QYcoA7XB5epQAAAGw"]
[Thu Jul 30 13:24:36.832913 2026] [security2:error] [pid 872418:tid 872614] [client 172.236.9.101:29813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuW5FymN6QYcoA7XB5enQAAAEI"]
[Thu Jul 30 13:24:36.844817 2026] [security2:error] [pid 872418:tid 872587] [client 20.215.191.139:39055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/admin.php"] [unique_id "amuW5FymN6QYcoA7XB5eqQAAACc"]
[Thu Jul 30 13:24:37.372565 2026] [core:notice] [pid 872418:tid 872599] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:37.867851 2026] [security2:error] [pid 872418:tid 872640] [client 179.64.21.229:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuW5VymN6QYcoA7XB5ewAAAAFw"]
[Thu Jul 30 13:24:37.868010 2026] [security2:error] [pid 872418:tid 872640] [client 179.64.21.229:47608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuW5VymN6QYcoA7XB5ewAAAAFw"]
[Thu Jul 30 13:24:37.947740 2026] [security2:error] [pid 872418:tid 872675] [client 20.215.191.139:39042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/class_api.php"] [unique_id "amuW5VymN6QYcoA7XB5exwAAAH8"]
[Thu Jul 30 13:24:38.075739 2026] [security2:error] [pid 872418:tid 872663] [client 20.91.199.21:56811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/classwithtostring.php"] [unique_id "amuW5lymN6QYcoA7XB5eywAAAHM"]
[Thu Jul 30 13:24:38.470080 2026] [security2:error] [pid 872418:tid 872610] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW5VymN6QYcoA7XB5ewwAAAD4"]
[Thu Jul 30 13:24:38.624654 2026] [security2:error] [pid 872418:tid 872608] [client 20.215.191.139:43368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuW5lymN6QYcoA7XB5e3AAAADw"]
[Thu Jul 30 13:24:38.744922 2026] [security2:error] [pid 872418:tid 872619] [client 20.91.199.21:36419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/config.php"] [unique_id "amuW5lymN6QYcoA7XB5e3QAAAEc"]
[Thu Jul 30 13:24:38.885264 2026] [security2:error] [pid 872418:tid 872642] [client 172.236.9.101:28715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuW5lymN6QYcoA7XB5e0gAAAF4"]
[Thu Jul 30 13:24:38.970888 2026] [security2:error] [pid 872418:tid 872652] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW5lymN6QYcoA7XB5e0QAAAGg"]
[Thu Jul 30 13:24:39.439591 2026] [security2:error] [pid 872418:tid 872622] [client 20.91.199.21:49543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/core.php"] [unique_id "amuW51ymN6QYcoA7XB5e8gAAAEo"]
[Thu Jul 30 13:24:39.715067 2026] [security2:error] [pid 872418:tid 872667] [client 20.215.191.139:38100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuW51ymN6QYcoA7XB5e9AAAAHc"]
[Thu Jul 30 13:24:40.132036 2026] [security2:error] [pid 872418:tid 872668] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuW51ymN6QYcoA7XB5e8wAAeCE"]
[Thu Jul 30 13:24:40.482743 2026] [security2:error] [pid 872418:tid 872582] [client 20.91.199.21:49583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/css.php"] [unique_id "amuW6FymN6QYcoA7XB5fDwAAACI"]
[Thu Jul 30 13:24:40.624619 2026] [security2:error] [pid 872418:tid 872588] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amuW5lymN6QYcoA7XB5e4wAAACg"]
[Thu Jul 30 13:24:41.010677 2026] [security2:error] [pid 872418:tid 872591] [client 20.215.191.139:38141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuW6VymN6QYcoA7XB5fIgAAACs"]
[Thu Jul 30 13:24:42.165169 2026] [security2:error] [pid 872418:tid 872611] [client 20.215.191.139:36194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/991176.php"] [unique_id "amuW6lymN6QYcoA7XB5fPwAAAD8"]
[Thu Jul 30 13:24:42.841106 2026] [security2:error] [pid 872418:tid 872581] [client 20.215.191.139:36217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuW6lymN6QYcoA7XB5fVAAAACE"]
[Thu Jul 30 13:24:42.891482 2026] [security2:error] [pid 872418:tid 872631] [client 172.236.9.101:60599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuW6lymN6QYcoA7XB5fRwAAAFM"]
[Thu Jul 30 13:24:43.351267 2026] [security2:error] [pid 872418:tid 872675] [client 20.91.199.21:50840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/database.php"] [unique_id "amuW61ymN6QYcoA7XB5fXQAAAH8"]
[Thu Jul 30 13:24:43.481149 2026] [security2:error] [pid 872418:tid 872554] [client 20.215.191.139:38132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuW61ymN6QYcoA7XB5fYQAAAAY"]
[Thu Jul 30 13:24:44.072240 2026] [core:notice] [pid 872418:tid 872556] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:44.402398 2026] [security2:error] [pid 872418:tid 872648] [client 176.36.146.80:61071] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "176.36.146.80" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuW7FymN6QYcoA7XB5ffQAAAGQ"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 13:24:44.587211 2026] [security2:error] [pid 872418:tid 872668] [client 20.215.191.139:36172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuW7FymN6QYcoA7XB5fggAAAHg"]
[Thu Jul 30 13:24:44.924708 2026] [security2:error] [pid 872418:tid 872653] [client 172.236.9.101:19242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuW7FymN6QYcoA7XB5ffAAAAGk"]
[Thu Jul 30 13:24:44.985326 2026] [core:notice] [pid 872418:tid 872514] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:45.054494 2026] [security2:error] [pid 872418:tid 872635] [client 20.91.199.21:54654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/db.php"] [unique_id "amuW7VymN6QYcoA7XB5flQAAAFc"]
[Thu Jul 30 13:24:45.231743 2026] [core:notice] [pid 872418:tid 872539] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:45.465206 2026] [security2:error] [pid 872418:tid 872521] [remote 74.7.243.224:53944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/nos-rapports/js/img/uploads/partners/js/fonts/css/js/contactff.php"] [unique_id "amuW7VymN6QYcoA7XB5fnwAALGY"], referer: https://aded-rdc.org/nos-rapports/js/img/uploads/partners/js/fonts/css/js/bootstrap.bundle.min.js
[Thu Jul 30 13:24:45.806685 2026] [security2:error] [pid 872418:tid 872574] [client 20.91.199.21:50052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/default.php"] [unique_id "amuW7VymN6QYcoA7XB5fowAAABo"]
[Thu Jul 30 13:24:46.235398 2026] [security2:error] [pid 872418:tid 872563] [client 20.215.191.139:43282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuW7lymN6QYcoA7XB5frwAAAA8"]
[Thu Jul 30 13:24:46.419484 2026] [security2:error] [pid 872418:tid 872593] [client 20.91.199.21:51995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/dropdown.php"] [unique_id "amuW7lymN6QYcoA7XB5fsgAAAC0"]
[Thu Jul 30 13:24:46.731756 2026] [core:notice] [pid 872418:tid 872543] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:46.919215 2026] [security2:error] [pid 872418:tid 872661] [client 172.236.9.101:62082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuW7lymN6QYcoA7XB5ftQAAAHE"]
[Thu Jul 30 13:24:47.075379 2026] [security2:error] [pid 872418:tid 872658] [client 20.215.191.139:38126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuW71ymN6QYcoA7XB5fxwAAAG4"]
[Thu Jul 30 13:24:47.406218 2026] [security2:error] [pid 872418:tid 872627] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW7lymN6QYcoA7XB5fwAAAAE8"]
[Thu Jul 30 13:24:48.121897 2026] [security2:error] [pid 872418:tid 872664] [client 20.91.199.21:49833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/edit.php"] [unique_id "amuW8FymN6QYcoA7XB5f2wAAAHQ"]
[Thu Jul 30 13:24:48.566375 2026] [security2:error] [pid 872418:tid 872662] [client 179.64.21.229:19336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuW8FymN6QYcoA7XB5f4wAAAHI"]
[Thu Jul 30 13:24:48.566490 2026] [security2:error] [pid 872418:tid 872662] [client 179.64.21.229:19336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuW8FymN6QYcoA7XB5f4wAAAHI"]
[Thu Jul 30 13:24:49.503057 2026] [security2:error] [pid 872418:tid 872568] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW8VymN6QYcoA7XB5f9wAAABQ"]
[Thu Jul 30 13:24:49.528710 2026] [security2:error] [pid 872418:tid 872621] [client 20.91.199.21:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/f35.php"] [unique_id "amuW8VymN6QYcoA7XB5f_wAAAEk"]
[Thu Jul 30 13:24:49.650863 2026] [security2:error] [pid 872418:tid 872661] [client 20.215.191.139:17493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuW8VymN6QYcoA7XB5gBAAAAHE"]
[Thu Jul 30 13:24:50.181481 2026] [security2:error] [pid 872418:tid 872642] [client 20.91.199.21:54593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.happyspree.app"] [uri "/f7.php"] [unique_id "amuW8lymN6QYcoA7XB5gEgAAAF4"]
[Thu Jul 30 13:24:50.276688 2026] [security2:error] [pid 872418:tid 872588] [client 20.215.191.139:17857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuW8lymN6QYcoA7XB5gFgAAACg"]
[Thu Jul 30 13:24:51.609246 2026] [security2:error] [pid 872418:tid 872672] [client 20.215.191.139:17484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuW81ymN6QYcoA7XB5gNQAAAHw"]
[Thu Jul 30 13:24:51.975721 2026] [core:notice] [pid 872418:tid 872568] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:52.260047 2026] [core:notice] [pid 872418:tid 872439] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:52.419925 2026] [security2:error] [pid 872418:tid 872653] [client 20.215.191.139:37424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuW9FymN6QYcoA7XB5gUwAAAGk"]
[Thu Jul 30 13:24:52.433384 2026] [security2:error] [pid 872418:tid 872608] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW81ymN6QYcoA7XB5gRAAAADw"]
[Thu Jul 30 13:24:52.511613 2026] [core:notice] [pid 872418:tid 872447] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:24:53.294399 2026] [proxy:error] [pid 872418:tid 872566] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:24:53.294489 2026] [proxy_http:error] [pid 872418:tid 872566] [client 52.4.19.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:24:53.295094 2026] [proxy:error] [pid 872418:tid 872566] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:24:53.295141 2026] [proxy_http:error] [pid 872418:tid 872566] [client 52.4.19.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:24:53.325220 2026] [proxy:error] [pid 872418:tid 872606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:24:53.325304 2026] [proxy_http:error] [pid 872418:tid 872606] [client 3.225.222.228:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:24:53.325895 2026] [proxy:error] [pid 872418:tid 872606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:24:53.325938 2026] [proxy_http:error] [pid 872418:tid 872606] [client 3.225.222.228:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:24:53.346897 2026] [security2:error] [pid 872418:tid 872645] [client 20.215.191.139:38731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuW9VymN6QYcoA7XB5gagAAAGE"]
[Thu Jul 30 13:24:54.610620 2026] [security2:error] [pid 872418:tid 872609] [client 20.215.191.139:36835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuW9lymN6QYcoA7XB5gjAAAAD0"]
[Thu Jul 30 13:24:54.923407 2026] [security2:error] [pid 872418:tid 872623] [client 74.248.20.32:30539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/bgymj.php"] [unique_id "amuW9lymN6QYcoA7XB5gmQAAAEs"]
[Thu Jul 30 13:24:54.923527 2026] [security2:error] [pid 872418:tid 872623] [client 74.248.20.32:30539] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/bgymj.php"] [unique_id "amuW9lymN6QYcoA7XB5gmQAAAEs"]
[Thu Jul 30 13:24:55.821229 2026] [security2:error] [pid 872418:tid 872566] [client 20.215.191.139:38771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuW91ymN6QYcoA7XB5gtAAAABI"]
[Thu Jul 30 13:24:56.876092 2026] [security2:error] [pid 872418:tid 872563] [client 20.215.191.139:40916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuW-FymN6QYcoA7XB5g2gAAAA8"]
[Thu Jul 30 13:24:57.767848 2026] [security2:error] [pid 872418:tid 872664] [client 20.215.191.139:40920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuW-VymN6QYcoA7XB5g9QAAAHQ"]
[Thu Jul 30 13:24:57.877843 2026] [security2:error] [pid 872418:tid 872645] [client 74.248.20.32:5827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/ah25.php"] [unique_id "amuW-VymN6QYcoA7XB5g-QAAAGE"]
[Thu Jul 30 13:24:57.878045 2026] [security2:error] [pid 872418:tid 872645] [client 74.248.20.32:5827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/ah25.php"] [unique_id "amuW-VymN6QYcoA7XB5g-QAAAGE"]
[Thu Jul 30 13:24:57.952085 2026] [security2:error] [pid 872418:tid 872458] [remote 207.46.13.87:32832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/mitsukoshi_nihombashi/login.php"] [unique_id "amuW-VymN6QYcoA7XB5g6wAALic"]
[Thu Jul 30 13:24:58.318096 2026] [security2:error] [pid 872418:tid 872550] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuW-VymN6QYcoA7XB5g9AAAAAI"]
[Thu Jul 30 13:24:58.471234 2026] [security2:error] [pid 872418:tid 872548] [client 20.215.191.139:37392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/bek.php"] [unique_id "amuW-lymN6QYcoA7XB5hBwAAAAA"]
[Thu Jul 30 13:24:58.812210 2026] [security2:error] [pid 872418:tid 872601] [client 74.248.20.32:30554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/main.php"] [unique_id "amuW-lymN6QYcoA7XB5hEAAAADU"]
[Thu Jul 30 13:24:58.812326 2026] [security2:error] [pid 872418:tid 872601] [client 74.248.20.32:30554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/main.php"] [unique_id "amuW-lymN6QYcoA7XB5hEAAAADU"]
[Thu Jul 30 13:24:59.692931 2026] [core:notice] [pid 872418:tid 872508] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:25:00.003696 2026] [security2:error] [pid 872418:tid 872629] [client 20.215.191.139:37387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuW_FymN6QYcoA7XB5hKwAAAFE"]
[Thu Jul 30 13:25:00.172744 2026] [core:error] [pid 872418:tid 872665] [client 54.147.150.116:54546] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:25:00.172774 2026] [core:error] [pid 872418:tid 872665] [client 54.147.150.116:54546] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:25:00.474282 2026] [security2:error] [pid 872418:tid 872651] [client 172.237.109.114:1136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuW_FymN6QYcoA7XB5hMAAAAGc"]
[Thu Jul 30 13:25:00.718683 2026] [security2:error] [pid 872418:tid 872611] [client 20.215.191.139:38757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/class.api.php"] [unique_id "amuW_FymN6QYcoA7XB5hPQAAAD8"]
[Thu Jul 30 13:25:01.374757 2026] [security2:error] [pid 872418:tid 872641] [client 20.215.191.139:40739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/cong.php"] [unique_id "amuW_VymN6QYcoA7XB5hXAAAAF0"]
[Thu Jul 30 13:25:01.649520 2026] [security2:error] [pid 872418:tid 872652] [client 172.237.109.114:34243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuW_VymN6QYcoA7XB5hUgAAAGg"]
[Thu Jul 30 13:25:02.066319 2026] [security2:error] [pid 872418:tid 872610] [client 20.215.191.139:38754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/content.php"] [unique_id "amuW_lymN6QYcoA7XB5hewAAAD4"]
[Thu Jul 30 13:25:02.950040 2026] [security2:error] [pid 872418:tid 872601] [client 20.215.191.139:40911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuW_lymN6QYcoA7XB5h6gAAADU"]
[Thu Jul 30 13:25:03.029780 2026] [security2:error] [pid 872418:tid 872554] [client 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuW_lymN6QYcoA7XB5hngAABiA"]
[Thu Jul 30 13:25:03.799835 2026] [security2:error] [pid 872418:tid 872640] [client 95.108.213.159:48652] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/robots.txt"] [unique_id "amuW_1ymN6QYcoA7XB5iOAAAAFw"]
[Thu Jul 30 13:25:04.034701 2026] [core:notice] [pid 872418:tid 872557] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:25:04.061133 2026] [security2:error] [pid 872418:tid 872641] [client 74.248.20.32:56541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/new4.php"] [unique_id "amuXAFymN6QYcoA7XB5iRgAAAF0"]
[Thu Jul 30 13:25:04.061281 2026] [security2:error] [pid 872418:tid 872641] [client 74.248.20.32:56541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/new4.php"] [unique_id "amuXAFymN6QYcoA7XB5iRgAAAF0"]
[Thu Jul 30 13:25:04.786013 2026] [security2:error] [pid 872418:tid 872605] [client 20.215.191.139:36843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/elp.php"] [unique_id "amuXAFymN6QYcoA7XB5iXgAAADk"]
[Thu Jul 30 13:25:04.836182 2026] [security2:error] [pid 872418:tid 872657] [client 74.248.20.32:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/inputs.php"] [unique_id "amuXAFymN6QYcoA7XB5iYAAAAG0"]
[Thu Jul 30 13:25:04.836268 2026] [security2:error] [pid 872418:tid 872657] [client 74.248.20.32:14324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/inputs.php"] [unique_id "amuXAFymN6QYcoA7XB5iYAAAAG0"]
[Thu Jul 30 13:25:05.692639 2026] [security2:error] [pid 872418:tid 872562] [client 20.215.191.139:37439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuXAVymN6QYcoA7XB5iggAAAA4"]
[Thu Jul 30 13:25:05.695578 2026] [security2:error] [pid 872418:tid 872662] [client 202.29.232.244:54444] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuXAVymN6QYcoA7XB5ihAAAAHI"]
[Thu Jul 30 13:25:06.090552 2026] [security2:error] [pid 872418:tid 872587] [client 202.29.232.244:54584] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuXAlymN6QYcoA7XB5imQAAACc"]
[Thu Jul 30 13:25:06.134645 2026] [core:notice] [pid 872418:tid 872450] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:25:06.301307 2026] [security2:error] [pid 872418:tid 872633] [client 20.215.191.139:36806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuXAlymN6QYcoA7XB5ipQAAAFU"]
[Thu Jul 30 13:25:06.905163 2026] [security2:error] [pid 872418:tid 872630] [client 20.215.191.139:40946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuXAlymN6QYcoA7XB5ivAAAAFI"]
[Thu Jul 30 13:25:07.529688 2026] [security2:error] [pid 872418:tid 872559] [client 20.215.191.139:40745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuXA1ymN6QYcoA7XB5i4gAAAAs"]
[Thu Jul 30 13:25:08.198882 2026] [security2:error] [pid 872418:tid 872644] [client 20.215.191.139:18216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuXBFymN6QYcoA7XB5i9wAAAGA"]
[Thu Jul 30 13:25:09.089106 2026] [security2:error] [pid 872418:tid 872653] [client 20.215.191.139:40896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuXBVymN6QYcoA7XB5jFwAAAGk"]
[Thu Jul 30 13:25:09.655367 2026] [core:error] [pid 872418:tid 872474] [remote 216.73.217.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:25:09.655394 2026] [core:error] [pid 872418:tid 872474] [remote 216.73.217.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:25:10.221799 2026] [security2:error] [pid 872418:tid 872504] [remote 74.7.227.39:56484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuXBlymN6QYcoA7XB5jOAAAAlU"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/theme-builder/documents
[Thu Jul 30 13:25:10.609866 2026] [security2:error] [pid 872418:tid 872588] [client 179.64.21.229:40035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXBlymN6QYcoA7XB5jQQAAACg"]
[Thu Jul 30 13:25:10.613488 2026] [security2:error] [pid 872418:tid 872588] [client 179.64.21.229:40035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXBlymN6QYcoA7XB5jQQAAACg"]
[Thu Jul 30 13:25:11.498921 2026] [security2:error] [pid 872418:tid 872614] [client 20.215.191.139:18223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuXB1ymN6QYcoA7XB5jVgAAAEI"]
[Thu Jul 30 13:25:12.290887 2026] [security2:error] [pid 872418:tid 872523] [remote 207.46.13.31:26245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/tongs/"] [unique_id "amuXCFymN6QYcoA7XB5jcAAABmg"]
[Thu Jul 30 13:25:12.478789 2026] [security2:error] [pid 872418:tid 872572] [client 20.215.191.139:37429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuXCFymN6QYcoA7XB5jdQAAABg"]
[Thu Jul 30 13:25:13.408351 2026] [security2:error] [pid 872418:tid 872567] [client 20.215.191.139:40991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuXCVymN6QYcoA7XB5jlwAAABM"]
[Thu Jul 30 13:25:13.725141 2026] [security2:error] [pid 872418:tid 872556] [client 50.6.43.217:60798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuXCVymN6QYcoA7XB5jnQAAAAg"]
[Thu Jul 30 13:25:13.852146 2026] [security2:error] [pid 872418:tid 872575] [client 50.6.43.217:60808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuXCVymN6QYcoA7XB5jogAAABs"]
[Thu Jul 30 13:25:14.394498 2026] [security2:error] [pid 872418:tid 872434] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fantasynamelist.com"] [uri "/wp-login.php"] [unique_id "amuXClymN6QYcoA7XB5jvwAAVw8"]
[Thu Jul 30 13:25:14.631265 2026] [security2:error] [pid 872418:tid 872554] [client 20.215.191.139:17840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuXClymN6QYcoA7XB5jxQAAAAY"]
[Thu Jul 30 13:25:14.746774 2026] [security2:error] [pid 872418:tid 872552] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXClymN6QYcoA7XB5jsQAAAAQ"]
[Thu Jul 30 13:25:14.844873 2026] [core:notice] [pid 872418:tid 872652] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:25:15.027074 2026] [core:notice] [pid 872418:tid 872570] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:25:15.187851 2026] [security2:error] [pid 872418:tid 872594] [client 57.141.0.16:53370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuXCVymN6QYcoA7XB5jjQAALnE"]
[Thu Jul 30 13:25:15.395074 2026] [security2:error] [pid 872418:tid 872605] [client 20.215.191.139:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuXC1ymN6QYcoA7XB5j5QAAADk"]
[Thu Jul 30 13:25:16.220680 2026] [security2:error] [pid 872418:tid 872549] [client 20.215.191.139:42727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuXDFymN6QYcoA7XB5kAQAAAAE"]
[Thu Jul 30 13:25:16.433415 2026] [security2:error] [pid 872418:tid 872666] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXC1ymN6QYcoA7XB5j8gAAdn4"]
[Thu Jul 30 13:25:16.937615 2026] [security2:error] [pid 872418:tid 872595] [client 20.215.191.139:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuXDFymN6QYcoA7XB5kFQAAAC8"]
[Thu Jul 30 13:25:17.223805 2026] [security2:error] [pid 872418:tid 872604] [client 74.7.175.147:47500] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ses.hfl.temporary.site"] [uri "/index.php"] [unique_id "amuXCVymN6QYcoA7XB5jqgAAOHs"]
[Thu Jul 30 13:25:17.566683 2026] [security2:error] [pid 872418:tid 872572] [client 20.215.191.139:41012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuXDVymN6QYcoA7XB5kJgAAABg"]
[Thu Jul 30 13:25:18.336220 2026] [security2:error] [pid 872418:tid 872569] [client 20.215.191.139:18013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuXDlymN6QYcoA7XB5kOgAAABU"]
[Thu Jul 30 13:25:20.607775 2026] [core:notice] [pid 872418:tid 872567] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:25:21.022855 2026] [security2:error] [pid 872418:tid 872571] [client 20.215.191.139:17848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuXEVymN6QYcoA7XB5kiwAAABc"]
[Thu Jul 30 13:25:21.497227 2026] [security2:error] [pid 872418:tid 872604] [client 179.64.21.229:24301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXEVymN6QYcoA7XB5klgAAADg"]
[Thu Jul 30 13:25:21.508463 2026] [security2:error] [pid 872418:tid 872604] [client 179.64.21.229:24301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXEVymN6QYcoA7XB5klgAAADg"]
[Thu Jul 30 13:25:22.583335 2026] [security2:error] [pid 872418:tid 872649] [client 20.215.191.139:41344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuXElymN6QYcoA7XB5kswAAAGU"]
[Thu Jul 30 13:25:23.287629 2026] [security2:error] [pid 872418:tid 872634] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXElymN6QYcoA7XB5kuQAAAFY"]
[Thu Jul 30 13:25:23.393616 2026] [security2:error] [pid 872418:tid 872621] [client 20.215.191.139:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuXE1ymN6QYcoA7XB5kxwAAAEk"]
[Thu Jul 30 13:25:24.364677 2026] [security2:error] [pid 872418:tid 872620] [client 20.215.191.139:17836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuXFFymN6QYcoA7XB5k3gAAAEg"]
[Thu Jul 30 13:25:24.652837 2026] [autoindex:error] [pid 872418:tid 872558] [client 44.216.125.112:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:25:24.854971 2026] [security2:error] [pid 872418:tid 872608] [client 20.91.199.21:1276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/geju.php"] [unique_id "amuXFFymN6QYcoA7XB5k9AAAADw"]
[Thu Jul 30 13:25:24.855973 2026] [security2:error] [pid 872418:tid 872672] [client 50.6.43.217:25924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuXFFymN6QYcoA7XB5k8wAAAHw"]
[Thu Jul 30 13:25:24.870397 2026] [security2:error] [pid 872418:tid 872631] [client 50.6.43.217:25928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuXFFymN6QYcoA7XB5k9QAAAFM"]
[Thu Jul 30 13:25:24.880963 2026] [security2:error] [pid 872418:tid 872594] [client 50.6.43.217:25944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuXFFymN6QYcoA7XB5k9gAAAC4"]
[Thu Jul 30 13:25:25.104655 2026] [security2:error] [pid 872418:tid 872617] [client 20.215.191.139:40941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuXFVymN6QYcoA7XB5lAQAAAEU"]
[Thu Jul 30 13:25:25.193856 2026] [security2:error] [pid 872418:tid 872668] [client 50.6.43.217:24848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuXFFymN6QYcoA7XB5k3QAAAHg"]
[Thu Jul 30 13:25:25.626267 2026] [security2:error] [pid 872418:tid 872557] [client 20.91.199.21:5807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuXFVymN6QYcoA7XB5lDQAAAAk"]
[Thu Jul 30 13:25:25.768653 2026] [security2:error] [pid 872418:tid 872610] [client 20.215.191.139:17834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuXFVymN6QYcoA7XB5lDwAAAD4"]
[Thu Jul 30 13:25:26.067456 2026] [security2:error] [pid 872418:tid 872634] [client 50.6.43.217:24856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuXFVymN6QYcoA7XB5lAgAAAFY"]
[Thu Jul 30 13:25:26.569877 2026] [security2:error] [pid 872418:tid 872658] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXFVymN6QYcoA7XB5lGAAAblY"]
[Thu Jul 30 13:25:26.764202 2026] [security2:error] [pid 872418:tid 872581] [client 20.91.199.21:5812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp.php"] [unique_id "amuXFlymN6QYcoA7XB5lKgAAACE"]
[Thu Jul 30 13:25:27.073784 2026] [security2:error] [pid 872418:tid 872608] [client 20.215.191.139:17542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuXF1ymN6QYcoA7XB5lOQAAADw"]
[Thu Jul 30 13:25:27.348277 2026] [security2:error] [pid 872418:tid 872589] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXFlymN6QYcoA7XB5lKQAAACk"]
[Thu Jul 30 13:25:27.442032 2026] [security2:error] [pid 872418:tid 872663] [client 20.91.199.21:1734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/aaa.php"] [unique_id "amuXF1ymN6QYcoA7XB5lQAAAAHM"]
[Thu Jul 30 13:25:28.169549 2026] [security2:error] [pid 872418:tid 872645] [client 74.248.20.32:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/a2.php"] [unique_id "amuXGFymN6QYcoA7XB5lVwAAAGE"]
[Thu Jul 30 13:25:28.169697 2026] [security2:error] [pid 872418:tid 872645] [client 74.248.20.32:61087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/a2.php"] [unique_id "amuXGFymN6QYcoA7XB5lVwAAAGE"]
[Thu Jul 30 13:25:28.213616 2026] [security2:error] [pid 872418:tid 872615] [client 82.102.27.195:35658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuXGFymN6QYcoA7XB5lXAAAAEM"]
[Thu Jul 30 13:25:28.213715 2026] [security2:error] [pid 872418:tid 872615] [client 82.102.27.195:35658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuXGFymN6QYcoA7XB5lXAAAAEM"]
[Thu Jul 30 13:25:28.363619 2026] [security2:error] [pid 872418:tid 872609] [client 20.215.191.139:40955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuXGFymN6QYcoA7XB5lXQAAAD0"]
[Thu Jul 30 13:25:28.617876 2026] [core:notice] [pid 872418:tid 872573] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:25:29.138331 2026] [security2:error] [pid 872418:tid 872606] [client 20.91.199.21:15804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/hoot.php"] [unique_id "amuXGVymN6QYcoA7XB5lcAAAADo"]
[Thu Jul 30 13:25:29.221478 2026] [security2:error] [pid 872418:tid 872556] [client 20.215.191.139:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuXGVymN6QYcoA7XB5ldAAAAAg"]
[Thu Jul 30 13:25:29.279577 2026] [autoindex:error] [pid 872418:tid 872522] [remote 74.207.245.209:55112] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:25:29.735332 2026] [security2:error] [pid 872418:tid 872652] [client 85.208.96.208:33090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/08/brasil-doa-21-blindados-de-combate-usados-para-o-exercito-do-uruguai/"] [unique_id "amuXGVymN6QYcoA7XB5lhQAAAGg"]
[Thu Jul 30 13:25:29.735464 2026] [security2:error] [pid 872418:tid 872652] [client 85.208.96.208:33090] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/08/brasil-doa-21-blindados-de-combate-usados-para-o-exercito-do-uruguai/"] [unique_id "amuXGVymN6QYcoA7XB5lhQAAAGg"]
[Thu Jul 30 13:25:29.828466 2026] [security2:error] [pid 872418:tid 872651] [client 20.91.199.21:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/about.php"] [unique_id "amuXGVymN6QYcoA7XB5lhwAAAGc"]
[Thu Jul 30 13:25:30.346231 2026] [security2:error] [pid 872418:tid 872561] [client 20.215.191.139:40974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuXGlymN6QYcoA7XB5lkwAAAA0"]
[Thu Jul 30 13:25:30.364248 2026] [autoindex:error] [pid 872418:tid 872647] [client 195.96.139.34:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.otbola.click:2095
[Thu Jul 30 13:25:30.962270 2026] [security2:error] [pid 872418:tid 872612] [client 20.91.199.21:5593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/admin.php"] [unique_id "amuXGlymN6QYcoA7XB5lowAAAEA"]
[Thu Jul 30 13:25:31.574758 2026] [security2:error] [pid 872418:tid 872558] [client 20.215.191.139:17852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuXG1ymN6QYcoA7XB5lsQAAAAo"]
[Thu Jul 30 13:25:31.732126 2026] [security2:error] [pid 872418:tid 872606] [client 20.91.199.21:17401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuXG1ymN6QYcoA7XB5luwAAADo"]
[Thu Jul 30 13:25:32.178254 2026] [security2:error] [pid 872418:tid 872602] [client 179.64.21.229:10862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXHFymN6QYcoA7XB5lwgAAADY"]
[Thu Jul 30 13:25:32.178411 2026] [security2:error] [pid 872418:tid 872602] [client 179.64.21.229:10862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXHFymN6QYcoA7XB5lwgAAADY"]
[Thu Jul 30 13:25:32.518824 2026] [security2:error] [pid 872418:tid 872654] [client 20.215.191.139:17833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuXHFymN6QYcoA7XB5lzAAAAGo"]
[Thu Jul 30 13:25:32.533409 2026] [security2:error] [pid 872418:tid 872579] [client 20.91.199.21:1896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuXHFymN6QYcoA7XB5lzQAAAB8"]
[Thu Jul 30 13:25:33.302967 2026] [security2:error] [pid 872418:tid 872586] [client 20.215.191.139:36790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuXHVymN6QYcoA7XB5l4QAAACY"]
[Thu Jul 30 13:25:34.252634 2026] [security2:error] [pid 872418:tid 872648] [client 49.51.38.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "magicmooncorp.com"] [uri "/index.php"] [unique_id "amuXG1ymN6QYcoA7XB5ltAAAAGQ"]
[Thu Jul 30 13:25:34.628613 2026] [security2:error] [pid 872418:tid 872572] [client 134.19.179.147:46590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXHlymN6QYcoA7XB5mBAAAABg"]
[Thu Jul 30 13:25:34.628727 2026] [security2:error] [pid 872418:tid 872572] [client 134.19.179.147:46590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXHlymN6QYcoA7XB5mBAAAABg"]
[Thu Jul 30 13:25:34.727678 2026] [security2:error] [pid 872418:tid 872605] [client 20.91.199.21:1757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuXHlymN6QYcoA7XB5mBQAAADk"]
[Thu Jul 30 13:25:35.129595 2026] [security2:error] [pid 872418:tid 872566] [client 20.215.191.139:41010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuXH1ymN6QYcoA7XB5mFAAAABI"]
[Thu Jul 30 13:25:36.278679 2026] [security2:error] [pid 872418:tid 872591] [client 20.215.191.139:17663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuXIFymN6QYcoA7XB5mOQAAACs"]
[Thu Jul 30 13:25:36.644341 2026] [security2:error] [pid 872418:tid 872562] [client 134.19.179.147:46604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuXIFymN6QYcoA7XB5mSAAAAA4"]
[Thu Jul 30 13:25:36.644475 2026] [security2:error] [pid 872418:tid 872562] [client 134.19.179.147:46604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuXIFymN6QYcoA7XB5mSAAAAA4"]
[Thu Jul 30 13:25:37.026070 2026] [security2:error] [pid 872418:tid 872610] [client 20.215.191.139:18200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuXIVymN6QYcoA7XB5mTwAAAD4"]
[Thu Jul 30 13:25:37.676118 2026] [security2:error] [pid 872418:tid 872627] [client 20.215.191.139:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuXIVymN6QYcoA7XB5mZQAAAE8"]
[Thu Jul 30 13:25:38.458521 2026] [security2:error] [pid 872418:tid 872589] [client 20.215.191.139:17821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuXIlymN6QYcoA7XB5mdwAAACk"]
[Thu Jul 30 13:25:41.612962 2026] [fcgid:warn] [pid 872418:tid 872617] (70014)End of file found: [client 66.132.172.180:46830] mod_fcgid: can't get data from http client
[Thu Jul 30 13:25:42.540041 2026] [security2:error] [pid 872418:tid 872631] [client 179.64.21.229:21548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXJlymN6QYcoA7XB5m3QAAAFM"]
[Thu Jul 30 13:25:42.551968 2026] [security2:error] [pid 872418:tid 872631] [client 179.64.21.229:21548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXJlymN6QYcoA7XB5m3QAAAFM"]
[Thu Jul 30 13:25:43.108405 2026] [security2:error] [pid 872418:tid 872600] [client 74.7.241.143:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.jookreview.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuXJ1ymN6QYcoA7XB5m6AAANAI"]
[Thu Jul 30 13:25:43.475349 2026] [core:notice] [pid 872418:tid 872536] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:25:43.818507 2026] [security2:error] [pid 872418:tid 872556] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXJ1ymN6QYcoA7XB5m6wAAAAg"]
[Thu Jul 30 13:25:44.049227 2026] [core:notice] [pid 872418:tid 872433] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:25:44.902618 2026] [security2:error] [pid 872418:tid 872590] [client 20.91.199.21:1863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuXKFymN6QYcoA7XB5nEwAAACo"]
[Thu Jul 30 13:25:45.841565 2026] [security2:error] [pid 872418:tid 872626] [client 20.91.199.21:1422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuXKVymN6QYcoA7XB5nLQAAAE4"]
[Thu Jul 30 13:25:46.059571 2026] [security2:error] [pid 872418:tid 872568] [client 172.236.9.101:54785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXKVymN6QYcoA7XB5nIAAAABQ"]
[Thu Jul 30 13:25:46.384023 2026] [security2:error] [pid 872418:tid 872587] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXKVymN6QYcoA7XB5nJgAAACc"]
[Thu Jul 30 13:25:47.549220 2026] [security2:error] [pid 872418:tid 872663] [client 20.91.199.21:1454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuXK1ymN6QYcoA7XB5nWQAAAHM"]
[Thu Jul 30 13:25:47.921250 2026] [security2:error] [pid 872418:tid 872602] [client 172.236.9.101:22821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXK1ymN6QYcoA7XB5nVQAAADY"]
[Thu Jul 30 13:25:48.020175 2026] [security2:error] [pid 872418:tid 872672] [client 144.79.241.10:42734] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuXLFymN6QYcoA7XB5nZgAAAHw"]
[Thu Jul 30 13:25:48.153224 2026] [security2:error] [pid 872418:tid 872623] [client 144.79.241.10:36244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuXLFymN6QYcoA7XB5nagAAAEs"]
[Thu Jul 30 13:25:48.358363 2026] [security2:error] [pid 872418:tid 872588] [client 20.91.199.21:17382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuXLFymN6QYcoA7XB5nbAAAACg"]
[Thu Jul 30 13:25:48.975393 2026] [security2:error] [pid 872418:tid 872464] [remote 74.7.243.224:36578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/nos-brochures/img/img/uploads/content/js/uploads/partners/uploads/content/css/js/aprochef.php"] [unique_id "amuXLFymN6QYcoA7XB5ngAAALS0"], referer: https://aded-rdc.org/nos-brochures/img/img/uploads/content/js/uploads/partners/uploads/content/css/js/humanitariaf.html
[Thu Jul 30 13:25:49.759511 2026] [security2:error] [pid 872418:tid 872631] [client 74.7.241.139:37404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-d5aea03f.evk.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuXLVymN6QYcoA7XB5nlQAAUzU"]
[Thu Jul 30 13:25:49.834509 2026] [security2:error] [pid 872418:tid 872595] [client 172.236.9.101:52814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXLVymN6QYcoA7XB5nhwAAAC8"]
[Thu Jul 30 13:25:51.884865 2026] [security2:error] [pid 872418:tid 872657] [client 172.236.9.101:14623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXL1ymN6QYcoA7XB5nuQAAAG0"]
[Thu Jul 30 13:25:52.013655 2026] [security2:error] [pid 872418:tid 872604] [client 20.91.199.21:1257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/content.php"] [unique_id "amuXMFymN6QYcoA7XB5nxAAAADg"]
[Thu Jul 30 13:25:52.876538 2026] [security2:error] [pid 872418:tid 872578] [client 179.64.21.229:2562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXMFymN6QYcoA7XB5n2QAAAB4"]
[Thu Jul 30 13:25:52.876657 2026] [security2:error] [pid 872418:tid 872578] [client 179.64.21.229:2562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXMFymN6QYcoA7XB5n2QAAAB4"]
[Thu Jul 30 13:25:53.343596 2026] [security2:error] [pid 872418:tid 872457] [remote 103.255.134.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "widedaddy.com"] [uri "/wp-login.php"] [unique_id "amuXMVymN6QYcoA7XB5n5AAAQyY"]
[Thu Jul 30 13:25:53.513354 2026] [security2:error] [pid 872418:tid 872494] [remote 195.26.253.119:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daralnaseemdxb.com"] [uri "/wp-login.php"] [unique_id "amuXMVymN6QYcoA7XB5n6AAAVEs"]
[Thu Jul 30 13:25:53.900039 2026] [security2:error] [pid 872418:tid 872548] [client 172.236.9.101:58696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXMVymN6QYcoA7XB5n5wAAAAA"]
[Thu Jul 30 13:25:54.161954 2026] [security2:error] [pid 872418:tid 872568] [client 57.141.0.60:60636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuXMVymN6QYcoA7XB5n8gAAFDw"], referer: https://igetvape-australia.com/store/?product-page=8&add-to-cart=169
[Thu Jul 30 13:25:55.322726 2026] [security2:error] [pid 872418:tid 872611] [client 66.132.172.180:31204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.172.132.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lms.aetiiph.net"] [uri "/login/index.php"] [unique_id "amuXM1ymN6QYcoA7XB5oEAAAAD8"]
[Thu Jul 30 13:25:55.521316 2026] [security2:error] [pid 872418:tid 872558] [client 74.248.20.32:56517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/0.php"] [unique_id "amuXM1ymN6QYcoA7XB5oHwAAAAo"]
[Thu Jul 30 13:25:55.521413 2026] [security2:error] [pid 872418:tid 872558] [client 74.248.20.32:56517] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/0.php"] [unique_id "amuXM1ymN6QYcoA7XB5oHwAAAAo"]
[Thu Jul 30 13:25:55.838029 2026] [security2:error] [pid 872418:tid 872652] [client 172.236.9.101:39497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXM1ymN6QYcoA7XB5oGAAAAGg"]
[Thu Jul 30 13:25:56.086451 2026] [security2:error] [pid 872418:tid 872574] [client 20.91.199.21:1765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuXNFymN6QYcoA7XB5oKwAAABo"]
[Thu Jul 30 13:25:56.561889 2026] [security2:error] [pid 872418:tid 872631] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXM1ymN6QYcoA7XB5oKgAAU2Y"]
[Thu Jul 30 13:25:56.638262 2026] [security2:error] [pid 872418:tid 872612] [client 74.248.20.32:5428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/lock360.php"] [unique_id "amuXNFymN6QYcoA7XB5oNwAAAEA"]
[Thu Jul 30 13:25:56.638372 2026] [security2:error] [pid 872418:tid 872612] [client 74.248.20.32:5428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/lock360.php"] [unique_id "amuXNFymN6QYcoA7XB5oNwAAAEA"]
[Thu Jul 30 13:25:57.175549 2026] [security2:error] [pid 872418:tid 872656] [client 20.91.199.21:1465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuXNVymN6QYcoA7XB5oRwAAAGw"]
[Thu Jul 30 13:25:57.402869 2026] [security2:error] [pid 872418:tid 872667] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXNFymN6QYcoA7XB5oOwAAdyc"]
[Thu Jul 30 13:25:57.777267 2026] [security2:error] [pid 872418:tid 872667] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXNVymN6QYcoA7XB5oRgAAd1s"]
[Thu Jul 30 13:25:57.857041 2026] [security2:error] [pid 872418:tid 872590] [client 172.236.9.101:54331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXNVymN6QYcoA7XB5oSgAAACo"]
[Thu Jul 30 13:25:58.237999 2026] [security2:error] [pid 872418:tid 872671] [client 20.91.199.21:1445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuXNlymN6QYcoA7XB5oYgAAAHs"]
[Thu Jul 30 13:25:58.536568 2026] [security2:error] [pid 872418:tid 872638] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXNVymN6QYcoA7XB5oWQAAWlk"]
[Thu Jul 30 13:25:59.558697 2026] [security2:error] [pid 872418:tid 872593] [client 20.91.199.21:1421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuXN1ymN6QYcoA7XB5oiQAAAC0"]
[Thu Jul 30 13:25:59.900872 2026] [security2:error] [pid 872418:tid 872661] [client 172.236.9.101:12360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXN1ymN6QYcoA7XB5oggAAAHE"]
[Thu Jul 30 13:26:00.427866 2026] [security2:error] [pid 872418:tid 872641] [client 82.102.27.195:41602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuXOFymN6QYcoA7XB5omAAAAF0"]
[Thu Jul 30 13:26:00.427999 2026] [security2:error] [pid 872418:tid 872641] [client 82.102.27.195:41602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuXOFymN6QYcoA7XB5omAAAAF0"]
[Thu Jul 30 13:26:00.767878 2026] [security2:error] [pid 872418:tid 872581] [client 20.171.55.167:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuXOFymN6QYcoA7XB5oogAAACE"]
[Thu Jul 30 13:26:01.084293 2026] [security2:error] [pid 872418:tid 872563] [client 43.172.194.51:52614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/06/22/nu-pieds-printemps-ete-2015/"] [unique_id "amuXOFymN6QYcoA7XB5oowAAAA8"]
[Thu Jul 30 13:26:01.474457 2026] [core:notice] [pid 872418:tid 872609] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:01.480442 2026] [security2:error] [pid 872418:tid 872609] [client 43.173.182.189:46810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/06/22/nu-pieds-printemps-ete-2015/"] [unique_id "amuXOVymN6QYcoA7XB5orgAAAD0"], referer: https://carnetdeshopping.com/index.php/2015/06/22/nu-pieds-printemps-ete-2015/?replytocom=1500
[Thu Jul 30 13:26:01.492108 2026] [security2:error] [pid 872418:tid 872587] [client 20.171.55.167:4232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/404.php"] [unique_id "amuXOVymN6QYcoA7XB5orwAAACc"]
[Thu Jul 30 13:26:01.915153 2026] [security2:error] [pid 872418:tid 872586] [client 172.236.9.101:7488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXOVymN6QYcoA7XB5orQAAACY"]
[Thu Jul 30 13:26:02.231815 2026] [security2:error] [pid 872418:tid 872631] [client 20.171.55.167:4242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-configs.php"] [unique_id "amuXOlymN6QYcoA7XB5owgAAAFM"]
[Thu Jul 30 13:26:02.565280 2026] [security2:error] [pid 872418:tid 872668] [client 194.32.107.14:58780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.107.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happyspree.app"] [uri "/xmlrpc.php"] [unique_id "amuXOlymN6QYcoA7XB5oxwAAAHg"]
[Thu Jul 30 13:26:02.565426 2026] [security2:error] [pid 872418:tid 872668] [client 194.32.107.14:58780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happyspree.app"] [uri "/xmlrpc.php"] [unique_id "amuXOlymN6QYcoA7XB5oxwAAAHg"]
[Thu Jul 30 13:26:02.573118 2026] [core:notice] [pid 872418:tid 872569] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:02.697308 2026] [security2:error] [pid 872418:tid 872622] [client 20.91.199.21:1697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuXOlymN6QYcoA7XB5ozwAAAEo"]
[Thu Jul 30 13:26:02.948805 2026] [security2:error] [pid 872418:tid 872633] [client 20.171.55.167:4249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/simple.php"] [unique_id "amuXOlymN6QYcoA7XB5o1QAAAFU"]
[Thu Jul 30 13:26:03.470722 2026] [security2:error] [pid 872418:tid 872589] [client 179.64.21.229:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXO1ymN6QYcoA7XB5o4QAAACk"]
[Thu Jul 30 13:26:03.470847 2026] [security2:error] [pid 872418:tid 872589] [client 179.64.21.229:12261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXO1ymN6QYcoA7XB5o4QAAACk"]
[Thu Jul 30 13:26:03.687656 2026] [security2:error] [pid 872418:tid 872551] [client 20.171.55.167:4684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/themes.php"] [unique_id "amuXO1ymN6QYcoA7XB5o5wAAAAM"]
[Thu Jul 30 13:26:03.893879 2026] [security2:error] [pid 872418:tid 872615] [client 172.236.9.101:63675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXO1ymN6QYcoA7XB5o3gAAAEM"]
[Thu Jul 30 13:26:04.286451 2026] [security2:error] [pid 872418:tid 872634] [client 194.32.107.14:60994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.107.32.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happyspree.app"] [uri "/xmlrpc.php"] [unique_id "amuXPFymN6QYcoA7XB5o8wAAAFY"]
[Thu Jul 30 13:26:04.286642 2026] [security2:error] [pid 872418:tid 872634] [client 194.32.107.14:60994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happyspree.app"] [uri "/xmlrpc.php"] [unique_id "amuXPFymN6QYcoA7XB5o8wAAAFY"]
[Thu Jul 30 13:26:04.397165 2026] [security2:error] [pid 872418:tid 872669] [client 20.171.55.167:4733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/ini.php"] [unique_id "amuXPFymN6QYcoA7XB5o-wAAAHk"]
[Thu Jul 30 13:26:04.812447 2026] [core:notice] [pid 872418:tid 872427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:05.103582 2026] [security2:error] [pid 872418:tid 872569] [client 20.171.55.167:4888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/autoload_classmap.php"] [unique_id "amuXPVymN6QYcoA7XB5pCgAAABU"]
[Thu Jul 30 13:26:05.282117 2026] [security2:error] [pid 872418:tid 872570] [client 20.91.199.21:15749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuXPVymN6QYcoA7XB5pDgAAABY"]
[Thu Jul 30 13:26:05.618842 2026] [core:notice] [pid 872418:tid 872566] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:05.807749 2026] [security2:error] [pid 872418:tid 872663] [client 20.171.55.167:4694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/as.php"] [unique_id "amuXPVymN6QYcoA7XB5pGwAAAHM"]
[Thu Jul 30 13:26:05.905537 2026] [security2:error] [pid 872418:tid 872624] [client 172.236.9.101:9583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXPVymN6QYcoA7XB5pEgAAAEw"]
[Thu Jul 30 13:26:06.520838 2026] [security2:error] [pid 872418:tid 872670] [client 20.171.55.167:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/admin/upload/css.php"] [unique_id "amuXPlymN6QYcoA7XB5pKgAAAHo"]
[Thu Jul 30 13:26:06.852045 2026] [security2:error] [pid 872418:tid 872621] [client 20.91.199.21:14785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuXPlymN6QYcoA7XB5pMQAAAEk"]
[Thu Jul 30 13:26:07.249704 2026] [security2:error] [pid 872418:tid 872617] [client 20.171.55.167:4582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/pki-validation/afnew.php"] [unique_id "amuXP1ymN6QYcoA7XB5pOQAAAEU"]
[Thu Jul 30 13:26:07.826257 2026] [security2:error] [pid 872418:tid 872584] [client 172.236.9.101:30180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXP1ymN6QYcoA7XB5pOgAAACQ"]
[Thu Jul 30 13:26:07.981752 2026] [security2:error] [pid 872418:tid 872665] [client 20.171.55.167:4573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/lufix.php"] [unique_id "amuXP1ymN6QYcoA7XB5pSwAAAHU"]
[Thu Jul 30 13:26:08.359248 2026] [security2:error] [pid 872418:tid 872633] [client 74.248.20.32:5411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/plss3.php"] [unique_id "amuXQFymN6QYcoA7XB5pUQAAAFU"]
[Thu Jul 30 13:26:08.359353 2026] [security2:error] [pid 872418:tid 872633] [client 74.248.20.32:5411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/plss3.php"] [unique_id "amuXQFymN6QYcoA7XB5pUQAAAFU"]
[Thu Jul 30 13:26:08.701784 2026] [security2:error] [pid 872418:tid 872654] [client 20.171.55.167:4607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/media.php"] [unique_id "amuXQFymN6QYcoA7XB5pXQAAAGo"]
[Thu Jul 30 13:26:09.429880 2026] [security2:error] [pid 872418:tid 872580] [client 20.171.55.167:4566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/simple.php"] [unique_id "amuXQVymN6QYcoA7XB5pbwAAACA"]
[Thu Jul 30 13:26:09.916614 2026] [security2:error] [pid 872418:tid 872583] [client 172.236.9.101:18969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXQVymN6QYcoA7XB5pcAAAACM"]
[Thu Jul 30 13:26:09.929132 2026] [core:notice] [pid 872418:tid 872554] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:09.934091 2026] [security2:error] [pid 872418:tid 872554] [client 66.249.79.1:61878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JPA/$$$call$$$/page/page/css"] [unique_id "amuXQVymN6QYcoA7XB5pewAAAAY"], referer: https://ejournalugj.com/index.php/JPA
[Thu Jul 30 13:26:10.171770 2026] [security2:error] [pid 872418:tid 872552] [client 20.171.55.167:4550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/contact.php"] [unique_id "amuXQlymN6QYcoA7XB5phQAAAAQ"]
[Thu Jul 30 13:26:10.203654 2026] [security2:error] [pid 872418:tid 872555] [client 3.79.134.69:53244] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuXQlymN6QYcoA7XB5phgAAAAc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:26:10.353469 2026] [security2:error] [pid 872418:tid 872463] [remote 156.59.198.135:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nafmedical.com"] [uri "/wp-content/uploads/2025/11/7-1-uai-180x90.png"] [unique_id "amuXQlymN6QYcoA7XB5pigAAdiw"], referer: https://www.alfarwaniya.com
[Thu Jul 30 13:26:10.546771 2026] [security2:error] [pid 872418:tid 872487] [remote 17.246.23.118:54466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.23.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuXQlymN6QYcoA7XB5piQAAC0Q"], referer: https://lark-shop.com/product/pianissimo-8/
[Thu Jul 30 13:26:10.610765 2026] [core:notice] [pid 872418:tid 872622] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:10.636840 2026] [security2:error] [pid 872418:tid 872631] [client 20.91.199.21:1332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuXQlymN6QYcoA7XB5plAAAAFM"]
[Thu Jul 30 13:26:10.791383 2026] [core:notice] [pid 872418:tid 872575] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:10.795319 2026] [security2:error] [pid 872418:tid 872575] [client 3.79.134.69:53246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuXQlymN6QYcoA7XB5pmQAAABs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:26:10.857402 2026] [core:notice] [pid 872418:tid 872671] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:10.906090 2026] [security2:error] [pid 872418:tid 872595] [client 20.171.55.167:4568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/byp.php"] [unique_id "amuXQlymN6QYcoA7XB5pmwAAAC8"]
[Thu Jul 30 13:26:11.220340 2026] [security2:error] [pid 872418:tid 872654] [client 20.91.199.21:1326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuXQ1ymN6QYcoA7XB5ppgAAAGo"]
[Thu Jul 30 13:26:11.512161 2026] [security2:error] [pid 872418:tid 872560] [client 3.79.134.69:53258] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuXQ1ymN6QYcoA7XB5pqAAAAAw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:26:11.532268 2026] [core:notice] [pid 872418:tid 872582] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:11.653851 2026] [security2:error] [pid 872418:tid 872609] [client 20.171.55.167:4268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/upload.php"] [unique_id "amuXQ1ymN6QYcoA7XB5prQAAAD0"]
[Thu Jul 30 13:26:11.896018 2026] [security2:error] [pid 872418:tid 872614] [client 172.236.9.101:36379] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXQ1ymN6QYcoA7XB5ppwAAAEI"]
[Thu Jul 30 13:26:12.142043 2026] [core:notice] [pid 872418:tid 872643] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:12.734144 2026] [core:notice] [pid 872418:tid 872630] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:12.860262 2026] [security2:error] [pid 872418:tid 872557] [client 20.171.55.167:4698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "amuXRFymN6QYcoA7XB5p8wAAAAk"]
[Thu Jul 30 13:26:13.273493 2026] [core:notice] [pid 872418:tid 872669] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:13.367049 2026] [security2:error] [pid 872418:tid 872548] [client 20.91.199.21:1449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuXRVymN6QYcoA7XB5p_wAAAAA"]
[Thu Jul 30 13:26:13.475490 2026] [core:error] [pid 872418:tid 872585] [client 184.154.139.52:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=prolineroofingservices.homes&yahoo.com
[Thu Jul 30 13:26:13.475539 2026] [core:error] [pid 872418:tid 872585] [client 184.154.139.52:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=prolineroofingservices.homes&yahoo.com
[Thu Jul 30 13:26:13.574643 2026] [security2:error] [pid 872418:tid 872663] [client 20.171.55.167:4716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cong.php"] [unique_id "amuXRVymN6QYcoA7XB5qBgAAAHM"]
[Thu Jul 30 13:26:13.770673 2026] [core:notice] [pid 872418:tid 872642] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:13.862296 2026] [security2:error] [pid 872418:tid 872558] [client 172.236.9.101:33692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXRVymN6QYcoA7XB5qAQAAAAo"]
[Thu Jul 30 13:26:14.058480 2026] [security2:error] [pid 872418:tid 872611] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXRVymN6QYcoA7XB5qBAAAAD8"]
[Thu Jul 30 13:26:14.067017 2026] [security2:error] [pid 872418:tid 872620] [client 179.64.21.229:54454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXRlymN6QYcoA7XB5qGgAAAEg"]
[Thu Jul 30 13:26:14.074540 2026] [security2:error] [pid 872418:tid 872620] [client 179.64.21.229:54454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXRlymN6QYcoA7XB5qGgAAAEg"]
[Thu Jul 30 13:26:14.289776 2026] [security2:error] [pid 872418:tid 872565] [client 20.91.199.21:1330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuXRlymN6QYcoA7XB5qHgAAABE"]
[Thu Jul 30 13:26:14.340254 2026] [security2:error] [pid 872418:tid 872592] [client 20.171.55.167:4574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/about/function.php"] [unique_id "amuXRlymN6QYcoA7XB5qIgAAACw"]
[Thu Jul 30 13:26:14.579119 2026] [security2:error] [pid 872418:tid 872605] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXRVymN6QYcoA7XB5qGAAAADk"]
[Thu Jul 30 13:26:15.067312 2026] [security2:error] [pid 872418:tid 872550] [client 20.171.55.167:4578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/filemanager/dialog.php"] [unique_id "amuXR1ymN6QYcoA7XB5qNAAAAAI"]
[Thu Jul 30 13:26:15.683287 2026] [security2:error] [pid 872418:tid 872635] [client 20.91.199.21:11947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/about.php"] [unique_id "amuXR1ymN6QYcoA7XB5qQgAAAFc"]
[Thu Jul 30 13:26:15.714421 2026] [security2:error] [pid 872418:tid 872460] [remote 40.77.167.123:50732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/page/index.php"] [unique_id "amuXR1ymN6QYcoA7XB5qRgAAWCk"]
[Thu Jul 30 13:26:15.765515 2026] [security2:error] [pid 872418:tid 872609] [client 160.176.144.54:61868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/info.php"] [unique_id "amuXR1ymN6QYcoA7XB5qRwAAAD0"]
[Thu Jul 30 13:26:15.772139 2026] [security2:error] [pid 872418:tid 872660] [client 20.171.55.167:4572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/bak.php"] [unique_id "amuXR1ymN6QYcoA7XB5qSAAAAHA"]
[Thu Jul 30 13:26:15.795518 2026] [security2:error] [pid 872418:tid 872615] [client 160.176.144.54:61863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/phpinfo.php"] [unique_id "amuXR1ymN6QYcoA7XB5qSQAAAEM"]
[Thu Jul 30 13:26:15.806761 2026] [security2:error] [pid 872418:tid 872576] [client 160.176.144.54:61862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/test.php"] [unique_id "amuXR1ymN6QYcoA7XB5qSgAAABw"]
[Thu Jul 30 13:26:15.837256 2026] [security2:error] [pid 872418:tid 872651] [client 160.176.144.54:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.siatfc.com"] [uri "/info.php"] [unique_id "amuXR1ymN6QYcoA7XB5qTAAAAGc"]
[Thu Jul 30 13:26:15.837370 2026] [security2:error] [pid 872418:tid 872588] [client 160.176.144.54:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.siatfc.com"] [uri "/phpinfo.php"] [unique_id "amuXR1ymN6QYcoA7XB5qSwAAACg"]
[Thu Jul 30 13:26:15.872657 2026] [security2:error] [pid 872418:tid 872602] [client 172.236.9.101:20288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXR1ymN6QYcoA7XB5qOwAAADY"]
[Thu Jul 30 13:26:15.894729 2026] [security2:error] [pid 872418:tid 872658] [client 160.176.144.54:54237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.siatfc.com"] [uri "/test.php"] [unique_id "amuXR1ymN6QYcoA7XB5qUAAAAG4"]
[Thu Jul 30 13:26:15.966475 2026] [security2:error] [pid 872418:tid 872465] [remote 160.176.144.54:61867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/test.php"] [unique_id "amuXR1ymN6QYcoA7XB5qVwAADC4"]
[Thu Jul 30 13:26:15.966532 2026] [security2:error] [pid 872418:tid 872444] [remote 160.176.144.54:61867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/info.php"] [unique_id "amuXR1ymN6QYcoA7XB5qVQAADBk"]
[Thu Jul 30 13:26:15.966555 2026] [security2:error] [pid 872418:tid 872472] [remote 160.176.144.54:61867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/phpinfo.php"] [unique_id "amuXR1ymN6QYcoA7XB5qVgAADDU"]
[Thu Jul 30 13:26:16.067183 2026] [security2:error] [pid 872418:tid 872468] [remote 160.176.144.54:54242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.siatfc.com"] [uri "/phpinfo.php"] [unique_id "amuXSFymN6QYcoA7XB5qWgAARzE"]
[Thu Jul 30 13:26:16.067241 2026] [security2:error] [pid 872418:tid 872450] [remote 160.176.144.54:54242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.siatfc.com"] [uri "/test.php"] [unique_id "amuXSFymN6QYcoA7XB5qWQAARx8"]
[Thu Jul 30 13:26:16.067269 2026] [security2:error] [pid 872418:tid 872431] [remote 160.176.144.54:54242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.144.176.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.siatfc.com"] [uri "/info.php"] [unique_id "amuXSFymN6QYcoA7XB5qWAAARww"]
[Thu Jul 30 13:26:16.149081 2026] [security2:error] [pid 872418:tid 872476] [remote 160.176.144.54:61867] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "siatfc.com"] [uri "/.env"] [unique_id "amuXSFymN6QYcoA7XB5qWwAAbDk"]
[Thu Jul 30 13:26:16.381541 2026] [security2:error] [pid 872418:tid 872486] [remote 160.176.144.54:54242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.siatfc.com"] [uri "/.env"] [unique_id "amuXSFymN6QYcoA7XB5qYAAAHkM"]
[Thu Jul 30 13:26:16.408877 2026] [security2:error] [pid 872418:tid 872634] [client 160.176.144.54:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "siatfc.com"] [uri "/.env"] [unique_id "amuXSFymN6QYcoA7XB5qYQAAAFY"]
[Thu Jul 30 13:26:16.487681 2026] [security2:error] [pid 872418:tid 872571] [client 20.171.55.167:4601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-info.php"] [unique_id "amuXSFymN6QYcoA7XB5qaAAAABc"]
[Thu Jul 30 13:26:16.634631 2026] [security2:error] [pid 872418:tid 872661] [client 160.176.144.54:53161] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.siatfc.com"] [uri "/.env"] [unique_id "amuXSFymN6QYcoA7XB5qbAAAAHE"]
[Thu Jul 30 13:26:17.198076 2026] [security2:error] [pid 872418:tid 872649] [client 20.171.55.167:4607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/files/index.php"] [unique_id "amuXSVymN6QYcoA7XB5qdgAAAGU"]
[Thu Jul 30 13:26:17.239539 2026] [proxy:error] [pid 872418:tid 872556] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:17.239631 2026] [proxy_http:error] [pid 872418:tid 872556] [client 17.246.19.248:60504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:17.240246 2026] [proxy:error] [pid 872418:tid 872556] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:17.240293 2026] [proxy_http:error] [pid 872418:tid 872556] [client 17.246.19.248:60504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:17.800038 2026] [security2:error] [pid 872418:tid 872609] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuXSVymN6QYcoA7XB5qgwAAAD0"]
[Thu Jul 30 13:26:17.905362 2026] [security2:error] [pid 872418:tid 872660] [client 20.171.55.167:4692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/css.php"] [unique_id "amuXSVymN6QYcoA7XB5qiAAAAHA"]
[Thu Jul 30 13:26:18.279473 2026] [security2:error] [pid 872418:tid 872562] [client 20.91.199.21:14832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/about.php"] [unique_id "amuXSlymN6QYcoA7XB5qkQAAAA4"]
[Thu Jul 30 13:26:18.569275 2026] [security2:error] [pid 872418:tid 872579] [client 74.248.20.32:30577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/wp.php"] [unique_id "amuXSlymN6QYcoA7XB5qmwAAAB8"]
[Thu Jul 30 13:26:18.569372 2026] [security2:error] [pid 872418:tid 872579] [client 74.248.20.32:30577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/wp.php"] [unique_id "amuXSlymN6QYcoA7XB5qmwAAAB8"]
[Thu Jul 30 13:26:18.619242 2026] [security2:error] [pid 872418:tid 872606] [client 20.171.55.167:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/css/index.php"] [unique_id "amuXSlymN6QYcoA7XB5qnwAAADo"]
[Thu Jul 30 13:26:19.340258 2026] [security2:error] [pid 872418:tid 872675] [client 20.171.55.167:4554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/bak.php"] [unique_id "amuXS1ymN6QYcoA7XB5qsAAAAH8"]
[Thu Jul 30 13:26:19.598515 2026] [security2:error] [pid 872418:tid 872666] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXS1ymN6QYcoA7XB5qpgAAAHY"]
[Thu Jul 30 13:26:19.776024 2026] [security2:error] [pid 872418:tid 872613] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/root/.env"] [unique_id "amuXS1ymN6QYcoA7XB5qugAAAEE"]
[Thu Jul 30 13:26:19.786682 2026] [security2:error] [pid 872418:tid 872669] [client 20.91.199.21:1252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuXS1ymN6QYcoA7XB5quwAAAHk"]
[Thu Jul 30 13:26:19.902353 2026] [security2:error] [pid 872418:tid 872614] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/home/.env"] [unique_id "amuXS1ymN6QYcoA7XB5qvwAAAEI"]
[Thu Jul 30 13:26:20.038262 2026] [security2:error] [pid 872418:tid 872673] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/site/.env"] [unique_id "amuXTFymN6QYcoA7XB5qwgAAAH0"]
[Thu Jul 30 13:26:20.044562 2026] [security2:error] [pid 872418:tid 872609] [client 20.171.55.167:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/alfa-rex.php7"] [unique_id "amuXTFymN6QYcoA7XB5qxAAAAD0"]
[Thu Jul 30 13:26:20.171350 2026] [security2:error] [pid 872418:tid 872586] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/panel/.env"] [unique_id "amuXTFymN6QYcoA7XB5qygAAACY"]
[Thu Jul 30 13:26:20.297590 2026] [security2:error] [pid 872418:tid 872573] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/control/.env"] [unique_id "amuXTFymN6QYcoA7XB5qzgAAABk"]
[Thu Jul 30 13:26:20.427537 2026] [security2:error] [pid 872418:tid 872672] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/console/.env"] [unique_id "amuXTFymN6QYcoA7XB5q0AAAAHw"]
[Thu Jul 30 13:26:20.787255 2026] [security2:error] [pid 872418:tid 872648] [client 20.171.55.167:4686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/wp-login.php"] [unique_id "amuXTFymN6QYcoA7XB5q4wAAAGQ"]
[Thu Jul 30 13:26:20.982300 2026] [security2:error] [pid 872418:tid 872667] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/administrator/config/.env"] [unique_id "amuXTFymN6QYcoA7XB5q3wAAAHc"]
[Thu Jul 30 13:26:21.054898 2026] [security2:error] [pid 872418:tid 872606] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXTFymN6QYcoA7XB5q1gAAADo"]
[Thu Jul 30 13:26:21.119053 2026] [security2:error] [pid 872418:tid 872593] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/webadmin/.env"] [unique_id "amuXTVymN6QYcoA7XB5q6gAAAC0"]
[Thu Jul 30 13:26:21.250938 2026] [security2:error] [pid 872418:tid 872581] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/sysadmin/.env"] [unique_id "amuXTVymN6QYcoA7XB5q7gAAACE"]
[Thu Jul 30 13:26:21.340186 2026] [security2:error] [pid 872418:tid 872549] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXTFymN6QYcoA7XB5q4gAAAAE"]
[Thu Jul 30 13:26:21.379409 2026] [security2:error] [pid 872418:tid 872607] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/mysql/.env"] [unique_id "amuXTVymN6QYcoA7XB5q8AAAADs"]
[Thu Jul 30 13:26:21.385330 2026] [security2:error] [pid 872418:tid 872604] [client 20.91.199.21:14819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuXTVymN6QYcoA7XB5q8QAAADg"]
[Thu Jul 30 13:26:21.508101 2026] [security2:error] [pid 872418:tid 872595] [client 20.171.55.167:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/cloud.php"] [unique_id "amuXTVymN6QYcoA7XB5q9QAAAC8"]
[Thu Jul 30 13:26:21.516315 2026] [security2:error] [pid 872418:tid 872635] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/dbadmin/.env"] [unique_id "amuXTVymN6QYcoA7XB5q9gAAAFc"]
[Thu Jul 30 13:26:21.646136 2026] [security2:error] [pid 872418:tid 872555] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/sql/.env"] [unique_id "amuXTVymN6QYcoA7XB5q-gAAAAc"]
[Thu Jul 30 13:26:21.774610 2026] [security2:error] [pid 872418:tid 872613] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/master/.env"] [unique_id "amuXTVymN6QYcoA7XB5q_gAAAEE"]
[Thu Jul 30 13:26:21.900874 2026] [security2:error] [pid 872418:tid 872610] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/temp/.env"] [unique_id "amuXTVymN6QYcoA7XB5q_wAAAD4"]
[Thu Jul 30 13:26:22.028924 2026] [security2:error] [pid 872418:tid 872553] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/tmp/.env"] [unique_id "amuXTlymN6QYcoA7XB5rAwAAAAU"]
[Thu Jul 30 13:26:22.053568 2026] [security2:error] [pid 872418:tid 872643] [client 74.248.20.32:61368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/x.php"] [unique_id "amuXTlymN6QYcoA7XB5rBAAAAF8"]
[Thu Jul 30 13:26:22.053683 2026] [security2:error] [pid 872418:tid 872643] [client 74.248.20.32:61368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/x.php"] [unique_id "amuXTlymN6QYcoA7XB5rBAAAAF8"]
[Thu Jul 30 13:26:22.155991 2026] [security2:error] [pid 872418:tid 872673] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/cloud/.env"] [unique_id "amuXTlymN6QYcoA7XB5rBwAAAH0"]
[Thu Jul 30 13:26:22.237201 2026] [security2:error] [pid 872418:tid 872621] [client 20.171.55.167:4680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/index.php"] [unique_id "amuXTlymN6QYcoA7XB5rDgAAAEk"]
[Thu Jul 30 13:26:22.284407 2026] [security2:error] [pid 872418:tid 872583] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/cgi-bin/.env"] [unique_id "amuXTlymN6QYcoA7XB5rEQAAACM"]
[Thu Jul 30 13:26:22.353637 2026] [core:notice] [pid 872418:tid 872565] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:22.415046 2026] [security2:error] [pid 872418:tid 872608] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/blog/.env"] [unique_id "amuXTlymN6QYcoA7XB5rEwAAADw"]
[Thu Jul 30 13:26:22.437856 2026] [security2:error] [pid 872418:tid 872592] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rocket-bookkeepers.com"] [uri "/wp-admin/install.php"] [unique_id "amuXTlymN6QYcoA7XB5rFAAAACw"]
[Thu Jul 30 13:26:22.542314 2026] [security2:error] [pid 872418:tid 872598] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/blogs/.env"] [unique_id "amuXTlymN6QYcoA7XB5rGAAAADI"]
[Thu Jul 30 13:26:22.568919 2026] [security2:error] [pid 872418:tid 872645] [client 20.91.199.21:1671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/img/about.php"] [unique_id "amuXTlymN6QYcoA7XB5rGQAAAGE"]
[Thu Jul 30 13:26:22.669856 2026] [security2:error] [pid 872418:tid 872572] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/engine/.env"] [unique_id "amuXTlymN6QYcoA7XB5rGwAAABg"]
[Thu Jul 30 13:26:22.797238 2026] [security2:error] [pid 872418:tid 872554] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/forum/.env"] [unique_id "amuXTlymN6QYcoA7XB5rJwAAAAY"]
[Thu Jul 30 13:26:22.926419 2026] [security2:error] [pid 872418:tid 872648] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/forums/.env"] [unique_id "amuXTlymN6QYcoA7XB5rKAAAAGQ"]
[Thu Jul 30 13:26:22.971548 2026] [security2:error] [pid 872418:tid 872615] [client 20.171.55.167:4597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/readme.php"] [unique_id "amuXTlymN6QYcoA7XB5rKQAAAEM"]
[Thu Jul 30 13:26:23.052751 2026] [security2:error] [pid 872418:tid 872631] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/store/.env"] [unique_id "amuXT1ymN6QYcoA7XB5rLQAAAFM"]
[Thu Jul 30 13:26:23.105252 2026] [proxy:error] [pid 872418:tid 872606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:23.105338 2026] [proxy_http:error] [pid 872418:tid 872606] [client 3.228.112.215:15112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:23.106085 2026] [proxy:error] [pid 872418:tid 872606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:23.106136 2026] [proxy_http:error] [pid 872418:tid 872606] [client 3.228.112.215:15112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:23.144425 2026] [proxy:error] [pid 872418:tid 872593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:23.144538 2026] [proxy_http:error] [pid 872418:tid 872593] [client 54.87.222.253:16897] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:23.145641 2026] [proxy:error] [pid 872418:tid 872593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:23.145710 2026] [proxy_http:error] [pid 872418:tid 872593] [client 54.87.222.253:16897] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:23.184601 2026] [security2:error] [pid 872418:tid 872603] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/shop/.env"] [unique_id "amuXT1ymN6QYcoA7XB5rOwAAADc"]
[Thu Jul 30 13:26:23.314082 2026] [security2:error] [pid 872418:tid 872661] [client 185.177.72.54:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "markmocek.com"] [uri "/cart/.env"] [unique_id "amuXT1ymN6QYcoA7XB5rQgAAAHE"]
[Thu Jul 30 13:26:23.692332 2026] [security2:error] [pid 872418:tid 872635] [client 20.171.55.167:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/about.php"] [unique_id "amuXT1ymN6QYcoA7XB5rSgAAAFc"]
[Thu Jul 30 13:26:23.697310 2026] [security2:error] [pid 872418:tid 872587] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/phpinfo.php"] [unique_id "amuXT1ymN6QYcoA7XB5rSwAAACc"]
[Thu Jul 30 13:26:23.941683 2026] [security2:error] [pid 872418:tid 872643] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/info.php"] [unique_id "amuXT1ymN6QYcoA7XB5rVQAAAF8"]
[Thu Jul 30 13:26:24.187053 2026] [security2:error] [pid 872418:tid 872628] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/php.php"] [unique_id "amuXUFymN6QYcoA7XB5rWQAAAFA"]
[Thu Jul 30 13:26:24.209493 2026] [security2:error] [pid 872418:tid 872673] [client 20.91.199.21:1751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuXUFymN6QYcoA7XB5rWgAAAH0"]
[Thu Jul 30 13:26:24.398612 2026] [security2:error] [pid 872418:tid 872621] [client 20.171.55.167:4552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/themes/404.php"] [unique_id "amuXUFymN6QYcoA7XB5rYwAAAEk"]
[Thu Jul 30 13:26:24.432815 2026] [security2:error] [pid 872418:tid 872602] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/test.php"] [unique_id "amuXUFymN6QYcoA7XB5rZAAAADY"]
[Thu Jul 30 13:26:24.484272 2026] [security2:error] [pid 872418:tid 872553] [client 119.73.97.132:30895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuXUFymN6QYcoA7XB5rXAAABWY"], referer: https://www.urwru.club/about/?preview_id=1023&preview_nonce=819b5eaec1&preview=true&aaeid=1
[Thu Jul 30 13:26:24.675856 2026] [security2:error] [pid 872418:tid 872644] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/i.php"] [unique_id "amuXUFymN6QYcoA7XB5raAAAAGA"]
[Thu Jul 30 13:26:24.805471 2026] [security2:error] [pid 872418:tid 872608] [client 179.64.21.229:6649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXUFymN6QYcoA7XB5rcAAAADw"]
[Thu Jul 30 13:26:24.812547 2026] [security2:error] [pid 872418:tid 872608] [client 179.64.21.229:6649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXUFymN6QYcoA7XB5rcAAAADw"]
[Thu Jul 30 13:26:24.918300 2026] [security2:error] [pid 872418:tid 872603] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/asdf.php"] [unique_id "amuXUFymN6QYcoA7XB5rdAAAADc"]
[Thu Jul 30 13:26:25.111823 2026] [security2:error] [pid 872418:tid 872574] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuXUFymN6QYcoA7XB5rdwAAABo"]
[Thu Jul 30 13:26:25.138699 2026] [security2:error] [pid 872418:tid 872575] [client 20.171.55.167:4454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/index.php"] [unique_id "amuXUVymN6QYcoA7XB5rewAAABs"]
[Thu Jul 30 13:26:25.159280 2026] [security2:error] [pid 872418:tid 872655] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/phpversion.php"] [unique_id "amuXUVymN6QYcoA7XB5rfQAAAGs"]
[Thu Jul 30 13:26:25.401995 2026] [security2:error] [pid 872418:tid 872647] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/temp.php"] [unique_id "amuXUVymN6QYcoA7XB5rhAAAAGM"]
[Thu Jul 30 13:26:25.525307 2026] [core:notice] [pid 872418:tid 872638] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:25.643878 2026] [security2:error] [pid 872418:tid 872636] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/old/phpinfo.php"] [unique_id "amuXUVymN6QYcoA7XB5riAAAAFg"]
[Thu Jul 30 13:26:25.851803 2026] [security2:error] [pid 872418:tid 872551] [client 20.171.55.167:4567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/themes.php"] [unique_id "amuXUVymN6QYcoA7XB5rjQAAAAM"]
[Thu Jul 30 13:26:25.885283 2026] [security2:error] [pid 872418:tid 872651] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/infophp.php"] [unique_id "amuXUVymN6QYcoA7XB5rjgAAAGc"]
[Thu Jul 30 13:26:26.256306 2026] [security2:error] [pid 872418:tid 872609] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/php/info.php"] [unique_id "amuXUlymN6QYcoA7XB5rlgAAAD0"]
[Thu Jul 30 13:26:26.501247 2026] [security2:error] [pid 872418:tid 872619] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/php/phpinfo.php"] [unique_id "amuXUlymN6QYcoA7XB5rnQAAAEc"]
[Thu Jul 30 13:26:26.742858 2026] [security2:error] [pid 872418:tid 872629] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/test/phpinfo.php"] [unique_id "amuXUlymN6QYcoA7XB5rpQAAAFE"]
[Thu Jul 30 13:26:26.851670 2026] [security2:error] [pid 872418:tid 872657] [client 20.171.55.167:4474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/dropdown.php"] [unique_id "amuXUlymN6QYcoA7XB5rpgAAAG0"]
[Thu Jul 30 13:26:26.983740 2026] [security2:error] [pid 872418:tid 872622] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/demo/phpinfo.php"] [unique_id "amuXUlymN6QYcoA7XB5rrQAAAEo"]
[Thu Jul 30 13:26:27.225299 2026] [security2:error] [pid 872418:tid 872665] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/site/phpinfo.php"] [unique_id "amuXU1ymN6QYcoA7XB5rrwAAAHU"]
[Thu Jul 30 13:26:27.470298 2026] [security2:error] [pid 872418:tid 872566] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/tmp/phpinfo.php"] [unique_id "amuXU1ymN6QYcoA7XB5ruwAAABI"]
[Thu Jul 30 13:26:27.636483 2026] [security2:error] [pid 872418:tid 872574] [client 20.171.55.167:4427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/404.php"] [unique_id "amuXU1ymN6QYcoA7XB5rvwAAABo"]
[Thu Jul 30 13:26:27.714998 2026] [security2:error] [pid 872418:tid 872647] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/dev/phpinfo.php"] [unique_id "amuXU1ymN6QYcoA7XB5rwwAAAGM"]
[Thu Jul 30 13:26:27.956249 2026] [security2:error] [pid 872418:tid 872653] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/local/phpinfo.php"] [unique_id "amuXU1ymN6QYcoA7XB5rxwAAAGk"]
[Thu Jul 30 13:26:28.123343 2026] [security2:error] [pid 872418:tid 872639] [client 20.91.199.21:14847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuXVFymN6QYcoA7XB5rzAAAAFs"]
[Thu Jul 30 13:26:28.196595 2026] [security2:error] [pid 872418:tid 872551] [client 185.177.72.54:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/backend/phpinfo.php"] [unique_id "amuXVFymN6QYcoA7XB5rzQAAAAM"]
[Thu Jul 30 13:26:28.347015 2026] [security2:error] [pid 872418:tid 872670] [client 20.171.55.167:4584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuXVFymN6QYcoA7XB5r1QAAAHo"]
[Thu Jul 30 13:26:28.828635 2026] [autoindex:error] [pid 872418:tid 872599] [client 146.190.102.139:50919] AH01276: Cannot serve directory /home1/wdrgplte/public_html/jesus.claims/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 13:26:29.059571 2026] [security2:error] [pid 872418:tid 872565] [client 20.171.55.167:4443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/file.php"] [unique_id "amuXVVymN6QYcoA7XB5r5wAAABE"]
[Thu Jul 30 13:26:29.350388 2026] [security2:error] [pid 872418:tid 872602] [client 20.91.199.21:15751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuXVVymN6QYcoA7XB5r7gAAADY"]
[Thu Jul 30 13:26:29.776174 2026] [security2:error] [pid 872418:tid 872615] [client 20.171.55.167:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/index.php"] [unique_id "amuXVVymN6QYcoA7XB5r-gAAAEM"]
[Thu Jul 30 13:26:30.180739 2026] [security2:error] [pid 872418:tid 872671] [client 20.91.199.21:9526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuXVlymN6QYcoA7XB5sCAAAAHs"]
[Thu Jul 30 13:26:30.544355 2026] [security2:error] [pid 872418:tid 872653] [client 20.171.55.167:4560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/cloud.php"] [unique_id "amuXVlymN6QYcoA7XB5sDAAAAGk"]
[Thu Jul 30 13:26:31.178020 2026] [security2:error] [pid 872418:tid 872558] [client 20.91.199.21:15803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuXV1ymN6QYcoA7XB5sHQAAAAo"]
[Thu Jul 30 13:26:31.254896 2026] [security2:error] [pid 872418:tid 872591] [client 20.171.55.167:4467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amuXV1ymN6QYcoA7XB5sHgAAACs"]
[Thu Jul 30 13:26:31.960915 2026] [security2:error] [pid 872418:tid 872553] [client 20.171.55.167:4476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/404.php"] [unique_id "amuXV1ymN6QYcoA7XB5sKgAAAAU"]
[Thu Jul 30 13:26:32.671583 2026] [security2:error] [pid 872418:tid 872548] [client 20.171.55.167:4253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/function.php"] [unique_id "amuXWFymN6QYcoA7XB5sPAAAAAA"]
[Thu Jul 30 13:26:33.091110 2026] [security2:error] [pid 872418:tid 872574] [client 20.91.199.21:1861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuXWVymN6QYcoA7XB5sSAAAABo"]
[Thu Jul 30 13:26:33.218847 2026] [security2:error] [pid 872418:tid 872484] [remote 57.141.0.40:46266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuXWVymN6QYcoA7XB5sSwAAS0E"]
[Thu Jul 30 13:26:33.426750 2026] [security2:error] [pid 872418:tid 872595] [client 20.171.55.167:4446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/file.php"] [unique_id "amuXWVymN6QYcoA7XB5sUAAAAC8"]
[Thu Jul 30 13:26:34.144846 2026] [security2:error] [pid 872418:tid 872599] [client 20.171.55.167:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/acme-challenge/autoload_classmap.php"] [unique_id "amuXWlymN6QYcoA7XB5sagAAADM"]
[Thu Jul 30 13:26:34.271503 2026] [security2:error] [pid 872418:tid 872573] [client 185.156.175.51:34282] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuXWlymN6QYcoA7XB5sZgAAABk"]
[Thu Jul 30 13:26:34.271650 2026] [security2:error] [pid 872418:tid 872573] [client 185.156.175.51:34282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuXWlymN6QYcoA7XB5sZgAAABk"]
[Thu Jul 30 13:26:34.314699 2026] [security2:error] [pid 872418:tid 872618] [client 20.91.199.21:14800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuXWlymN6QYcoA7XB5sbgAAAEY"]
[Thu Jul 30 13:26:34.492958 2026] [security2:error] [pid 872418:tid 872638] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXWVymN6QYcoA7XB5sYgAAWlA"]
[Thu Jul 30 13:26:34.851790 2026] [security2:error] [pid 872418:tid 872615] [client 20.171.55.167:4469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/themes.php"] [unique_id "amuXWlymN6QYcoA7XB5sfAAAAEM"]
[Thu Jul 30 13:26:35.363460 2026] [security2:error] [pid 872418:tid 872564] [client 179.64.21.229:14364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXW1ymN6QYcoA7XB5shgAAABA"]
[Thu Jul 30 13:26:35.363652 2026] [security2:error] [pid 872418:tid 872564] [client 179.64.21.229:14364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXW1ymN6QYcoA7XB5shgAAABA"]
[Thu Jul 30 13:26:35.515899 2026] [security2:error] [pid 872418:tid 872623] [client 74.248.20.32:61065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/aq.php"] [unique_id "amuXW1ymN6QYcoA7XB5siwAAAEs"]
[Thu Jul 30 13:26:35.516040 2026] [security2:error] [pid 872418:tid 872623] [client 74.248.20.32:61065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/aq.php"] [unique_id "amuXW1ymN6QYcoA7XB5siwAAAEs"]
[Thu Jul 30 13:26:35.558649 2026] [security2:error] [pid 872418:tid 872668] [client 20.171.55.167:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/wp-login.php"] [unique_id "amuXW1ymN6QYcoA7XB5sjAAAAHg"]
[Thu Jul 30 13:26:35.829309 2026] [proxy:error] [pid 872418:tid 872642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:35.829391 2026] [proxy_http:error] [pid 872418:tid 872642] [client 52.202.41.153:55507] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:35.830083 2026] [proxy:error] [pid 872418:tid 872642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:35.830134 2026] [proxy_http:error] [pid 872418:tid 872642] [client 52.202.41.153:55507] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:35.934710 2026] [security2:error] [pid 872418:tid 872633] [client 20.91.199.21:4194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuXW1ymN6QYcoA7XB5snAAAAFU"]
[Thu Jul 30 13:26:36.040055 2026] [proxy:error] [pid 872418:tid 872619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:36.040135 2026] [proxy_http:error] [pid 872418:tid 872619] [client 3.228.112.215:42425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:36.040741 2026] [proxy:error] [pid 872418:tid 872619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:26:36.040788 2026] [proxy_http:error] [pid 872418:tid 872619] [client 3.228.112.215:42425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:26:36.163347 2026] [security2:error] [pid 872418:tid 872558] [client 116.179.32.77:48643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/PBB/article/view/7399"] [unique_id "amuXW1ymN6QYcoA7XB5smgAAAAo"]
[Thu Jul 30 13:26:36.339564 2026] [security2:error] [pid 872418:tid 872611] [client 20.171.55.167:4452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/file.php"] [unique_id "amuXXFymN6QYcoA7XB5spgAAAD8"]
[Thu Jul 30 13:26:37.045754 2026] [security2:error] [pid 872418:tid 872589] [client 20.171.55.167:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-trackback.php"] [unique_id "amuXXVymN6QYcoA7XB5sygAAACk"]
[Thu Jul 30 13:26:37.064966 2026] [core:notice] [pid 872418:tid 872550] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:37.727080 2026] [security2:error] [pid 872418:tid 872570] [client 20.91.199.21:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuXXVymN6QYcoA7XB5s2AAAABY"]
[Thu Jul 30 13:26:37.778547 2026] [security2:error] [pid 872418:tid 872633] [client 20.171.55.167:4545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "amuXXVymN6QYcoA7XB5s3AAAAFU"]
[Thu Jul 30 13:26:37.920870 2026] [security2:error] [pid 872418:tid 872510] [remote 57.141.0.52:27150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5351135361/feed/rss2/"] [unique_id "amuXXVymN6QYcoA7XB5s3QAACFs"]
[Thu Jul 30 13:26:38.539805 2026] [security2:error] [pid 872418:tid 872657] [client 20.171.55.167:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/index.php"] [unique_id "amuXXlymN6QYcoA7XB5s7QAAAG0"]
[Thu Jul 30 13:26:39.246955 2026] [security2:error] [pid 872418:tid 872568] [client 20.171.55.167:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/themes.php"] [unique_id "amuXX1ymN6QYcoA7XB5s_QAAABQ"]
[Thu Jul 30 13:26:39.971805 2026] [security2:error] [pid 872418:tid 872669] [client 20.171.55.167:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/cloud.php"] [unique_id "amuXX1ymN6QYcoA7XB5tEAAAAHk"]
[Thu Jul 30 13:26:40.122318 2026] [security2:error] [pid 872418:tid 872651] [client 20.91.199.21:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuXYFymN6QYcoA7XB5tFQAAAGc"]
[Thu Jul 30 13:26:40.187046 2026] [core:notice] [pid 872418:tid 872628] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:40.206286 2026] [core:notice] [pid 872418:tid 872673] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:40.729748 2026] [security2:error] [pid 872418:tid 872599] [client 20.171.55.167:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/wp-load.php"] [unique_id "amuXYFymN6QYcoA7XB5tKgAAADM"]
[Thu Jul 30 13:26:40.929777 2026] [core:notice] [pid 872418:tid 872420] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:41.434092 2026] [core:notice] [pid 872418:tid 872426] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:41.442825 2026] [security2:error] [pid 872418:tid 872634] [client 20.171.55.167:4564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/file.php"] [unique_id "amuXYVymN6QYcoA7XB5tOwAAAFY"]
[Thu Jul 30 13:26:41.469540 2026] [security2:error] [pid 872418:tid 872629] [client 20.91.199.21:9477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuXYVymN6QYcoA7XB5tPAAAAFE"]
[Thu Jul 30 13:26:42.121763 2026] [core:notice] [pid 872418:tid 872534] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:42.149743 2026] [security2:error] [pid 872418:tid 872626] [client 20.171.55.167:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuXYlymN6QYcoA7XB5tSQAAAE4"]
[Thu Jul 30 13:26:42.794388 2026] [security2:error] [pid 872418:tid 872617] [client 20.91.199.21:4219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuXYlymN6QYcoA7XB5tWAAAAEU"]
[Thu Jul 30 13:26:42.856186 2026] [security2:error] [pid 872418:tid 872644] [client 20.171.55.167:4577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/index.php"] [unique_id "amuXYlymN6QYcoA7XB5tXAAAAGA"]
[Thu Jul 30 13:26:43.561063 2026] [security2:error] [pid 872418:tid 872572] [client 20.171.55.167:4456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuXY1ymN6QYcoA7XB5tawAAABg"]
[Thu Jul 30 13:26:44.047694 2026] [security2:error] [pid 872418:tid 872604] [client 20.91.199.21:1783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuXZFymN6QYcoA7XB5tdAAAADg"]
[Thu Jul 30 13:26:44.177662 2026] [core:error] [pid 872418:tid 872582] [client 193.47.62.167:48766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:26:44.177684 2026] [core:error] [pid 872418:tid 872582] [client 193.47.62.167:48766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:26:44.181942 2026] [security2:error] [pid 872418:tid 872578] [client 121.229.156.78:38972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hoki188win.com"] [uri "/"] [unique_id "amuXZFymN6QYcoA7XB5teQAAAB4"]
[Thu Jul 30 13:26:44.182076 2026] [security2:error] [pid 872418:tid 872578] [client 121.229.156.78:38972] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hoki188win.com"] [uri "/"] [unique_id "amuXZFymN6QYcoA7XB5teQAAAB4"]
[Thu Jul 30 13:26:44.210197 2026] [core:notice] [pid 872418:tid 872576] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:44.281448 2026] [security2:error] [pid 872418:tid 872641] [client 20.171.55.167:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/404.php"] [unique_id "amuXZFymN6QYcoA7XB5tfwAAAF0"]
[Thu Jul 30 13:26:44.740367 2026] [security2:error] [pid 872418:tid 872584] [client 43.166.130.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuXZFymN6QYcoA7XB5tiwAAACQ"]
[Thu Jul 30 13:26:44.761381 2026] [security2:error] [pid 872418:tid 872593] [client 20.91.199.21:1762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/images/about.php"] [unique_id "amuXZFymN6QYcoA7XB5tjAAAAC0"]
[Thu Jul 30 13:26:45.407837 2026] [security2:error] [pid 872418:tid 872619] [client 20.171.55.167:4463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "amuXZVymN6QYcoA7XB5tngAAAEc"]
[Thu Jul 30 13:26:45.824735 2026] [security2:error] [pid 872418:tid 872599] [client 179.64.21.229:57157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXZVymN6QYcoA7XB5tpQAAADM"]
[Thu Jul 30 13:26:45.824868 2026] [security2:error] [pid 872418:tid 872599] [client 179.64.21.229:57157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXZVymN6QYcoA7XB5tpQAAADM"]
[Thu Jul 30 13:26:45.927157 2026] [security2:error] [pid 872418:tid 872648] [client 20.91.199.21:9489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuXZVymN6QYcoA7XB5tqQAAAGQ"]
[Thu Jul 30 13:26:46.223688 2026] [security2:error] [pid 872418:tid 872554] [client 20.171.55.167:4674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/radio.php"] [unique_id "amuXZlymN6QYcoA7XB5tsgAAAAY"]
[Thu Jul 30 13:26:46.423246 2026] [security2:error] [pid 872418:tid 872675] [client 74.248.20.32:30538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/wp-admin/about.php"] [unique_id "amuXZlymN6QYcoA7XB5tuQAAAH8"]
[Thu Jul 30 13:26:46.423355 2026] [security2:error] [pid 872418:tid 872675] [client 74.248.20.32:30538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/wp-admin/about.php"] [unique_id "amuXZlymN6QYcoA7XB5tuQAAAH8"]
[Thu Jul 30 13:26:46.691733 2026] [core:error] [pid 872418:tid 872653] [client 74.7.241.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:26:46.691755 2026] [core:error] [pid 872418:tid 872653] [client 74.7.241.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:26:46.691878 2026] [security2:error] [pid 872418:tid 872653] [client 74.7.241.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.sua.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuXZlymN6QYcoA7XB5twgAAAGk"]
[Thu Jul 30 13:26:46.692558 2026] [security2:error] [pid 872418:tid 872578] [client 74.7.241.172:49652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.sua.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuXZlymN6QYcoA7XB5tvQAAHkI"]
[Thu Jul 30 13:26:46.935633 2026] [security2:error] [pid 872418:tid 872635] [client 20.171.55.167:4602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/themes/index.php"] [unique_id "amuXZlymN6QYcoA7XB5txgAAAFc"]
[Thu Jul 30 13:26:47.640993 2026] [security2:error] [pid 872418:tid 872662] [client 172.216.169.248:36042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.169.216.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-login.php/wp-login.php"] [unique_id "amuXZ1ymN6QYcoA7XB5t1wAAAHI"]
[Thu Jul 30 13:26:47.668698 2026] [security2:error] [pid 872418:tid 872659] [client 20.171.55.167:4687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/admin.php"] [unique_id "amuXZ1ymN6QYcoA7XB5t2QAAAG8"]
[Thu Jul 30 13:26:47.869797 2026] [security2:error] [pid 872418:tid 872673] [client 172.236.9.101:28206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXZ1ymN6QYcoA7XB5tzwAAAH0"]
[Thu Jul 30 13:26:48.289949 2026] [security2:error] [pid 872418:tid 872572] [client 185.156.175.51:47058] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXaFymN6QYcoA7XB5t6QAAABg"]
[Thu Jul 30 13:26:48.290120 2026] [security2:error] [pid 872418:tid 872572] [client 185.156.175.51:47058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXaFymN6QYcoA7XB5t6QAAABg"]
[Thu Jul 30 13:26:48.390501 2026] [security2:error] [pid 872418:tid 872649] [client 20.171.55.167:4549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/system_log.php"] [unique_id "amuXaFymN6QYcoA7XB5t6gAAAGU"]
[Thu Jul 30 13:26:49.102194 2026] [security2:error] [pid 872418:tid 872589] [client 20.171.55.167:4431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/wp-activate.php"] [unique_id "amuXaVymN6QYcoA7XB5t_wAAACk"]
[Thu Jul 30 13:26:49.770343 2026] [security2:error] [pid 872418:tid 872610] [client 172.236.9.101:1250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXaVymN6QYcoA7XB5uBAAAAD4"]
[Thu Jul 30 13:26:49.810697 2026] [security2:error] [pid 872418:tid 872600] [client 20.171.55.167:4585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/makeasmtp.php"] [unique_id "amuXaVymN6QYcoA7XB5uEAAAADQ"]
[Thu Jul 30 13:26:50.524536 2026] [security2:error] [pid 872418:tid 872623] [client 20.171.55.167:4459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/user/index.php"] [unique_id "amuXalymN6QYcoA7XB5uHQAAAEs"]
[Thu Jul 30 13:26:50.746563 2026] [security2:error] [pid 872418:tid 872606] [client 5.25.139.135:41380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXalymN6QYcoA7XB5uHAAAADo"], referer: http://pkf.jo
[Thu Jul 30 13:26:51.235169 2026] [security2:error] [pid 872418:tid 872607] [client 20.171.55.167:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/link.php"] [unique_id "amuXa1ymN6QYcoA7XB5uTwAAADs"]
[Thu Jul 30 13:26:51.787088 2026] [security2:error] [pid 872418:tid 872574] [client 172.236.9.101:3141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXa1ymN6QYcoA7XB5uUAAAABo"]
[Thu Jul 30 13:26:51.965720 2026] [security2:error] [pid 872418:tid 872582] [client 20.171.55.167:4451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuXa1ymN6QYcoA7XB5uXwAAACI"]
[Thu Jul 30 13:26:52.082511 2026] [security2:error] [pid 872418:tid 872642] [client 45.175.162.13:52902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXa1ymN6QYcoA7XB5uWgAAAF4"], referer: http://pkf.jo
[Thu Jul 30 13:26:52.698177 2026] [security2:error] [pid 872418:tid 872583] [client 20.171.55.167:4423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/themes.php"] [unique_id "amuXbFymN6QYcoA7XB5ubQAAACM"]
[Thu Jul 30 13:26:53.317211 2026] [security2:error] [pid 872418:tid 872610] [client 20.91.199.21:4165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuXbVymN6QYcoA7XB5uewAAAD4"]
[Thu Jul 30 13:26:53.423157 2026] [security2:error] [pid 872418:tid 872670] [client 20.171.55.167:4723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/themes/admin.php"] [unique_id "amuXbVymN6QYcoA7XB5ufAAAAHo"]
[Thu Jul 30 13:26:53.775115 2026] [security2:error] [pid 872418:tid 872650] [client 172.236.9.101:26107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXbVymN6QYcoA7XB5uegAAAGY"]
[Thu Jul 30 13:26:53.867773 2026] [security2:error] [pid 872418:tid 872624] [client 163.47.98.22:43026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXbVymN6QYcoA7XB5ugwAAAEw"], referer: http://pkf.jo
[Thu Jul 30 13:26:54.074046 2026] [security2:error] [pid 872418:tid 872648] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXbVymN6QYcoA7XB5ufwAAAGQ"]
[Thu Jul 30 13:26:54.172319 2026] [security2:error] [pid 872418:tid 872549] [client 20.171.55.167:4595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuXblymN6QYcoA7XB5ulQAAAAE"]
[Thu Jul 30 13:26:54.876959 2026] [security2:error] [pid 872418:tid 872635] [client 20.171.55.167:4559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/function.php"] [unique_id "amuXblymN6QYcoA7XB5upgAAAFc"]
[Thu Jul 30 13:26:54.974782 2026] [security2:error] [pid 872418:tid 872615] [client 20.91.199.21:4191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/about.php"] [unique_id "amuXblymN6QYcoA7XB5uqAAAAEM"]
[Thu Jul 30 13:26:55.366091 2026] [core:notice] [pid 872418:tid 872544] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:55.597365 2026] [security2:error] [pid 872418:tid 872598] [client 20.171.55.167:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/images/wp-login.php"] [unique_id "amuXb1ymN6QYcoA7XB5utAAAADI"]
[Thu Jul 30 13:26:55.754933 2026] [security2:error] [pid 872418:tid 872662] [client 172.236.9.101:61771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXb1ymN6QYcoA7XB5usgAAAHI"]
[Thu Jul 30 13:26:55.818208 2026] [security2:error] [pid 872418:tid 872612] [client 20.91.199.21:9480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/cgi-bin/about.php"] [unique_id "amuXb1ymN6QYcoA7XB5uvQAAAEA"]
[Thu Jul 30 13:26:56.017847 2026] [core:notice] [pid 872418:tid 872439] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:56.243296 2026] [security2:error] [pid 872418:tid 872633] [client 179.64.21.229:25378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXcFymN6QYcoA7XB5uyQAAAFU"]
[Thu Jul 30 13:26:56.243406 2026] [security2:error] [pid 872418:tid 872633] [client 179.64.21.229:25378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXcFymN6QYcoA7XB5uyQAAAFU"]
[Thu Jul 30 13:26:56.301291 2026] [security2:error] [pid 872418:tid 872625] [client 20.171.55.167:4563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/log.php"] [unique_id "amuXcFymN6QYcoA7XB5uzQAAAE0"]
[Thu Jul 30 13:26:56.570686 2026] [security2:error] [pid 872418:tid 872453] [remote 57.141.0.9:48222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amuXcFymN6QYcoA7XB5u1wAAEiI"]
[Thu Jul 30 13:26:56.604820 2026] [core:notice] [pid 872418:tid 872554] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:26:56.609047 2026] [security2:error] [pid 872418:tid 872554] [client 66.249.79.8:37446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/citationstylelanguage/get/modern-language-association"] [unique_id "amuXcFymN6QYcoA7XB5u2AAAAAY"]
[Thu Jul 30 13:26:56.734696 2026] [security2:error] [pid 872418:tid 872581] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXcFymN6QYcoA7XB5uwwAAACE"]
[Thu Jul 30 13:26:56.900310 2026] [security2:error] [pid 872418:tid 872656] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXcFymN6QYcoA7XB5uzAAAAGw"]
[Thu Jul 30 13:26:57.001951 2026] [http2:info] [pid 890219:tid 890219] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 13:26:57.058524 2026] [security2:error] [pid 872418:tid 872568] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXcFymN6QYcoA7XB5u1gAAABQ"]
[Thu Jul 30 13:26:57.252318 2026] [security2:error] [pid 890219:tid 890350] [client 20.171.55.167:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/wp-signup.php"] [unique_id "amuXcYJkCYmL5o6vh9JmbAAAAIU"]
[Thu Jul 30 13:26:57.761760 2026] [security2:error] [pid 890219:tid 890355] [client 172.236.9.101:8241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXcYJkCYmL5o6vh9JmbQAAAIo"]
[Thu Jul 30 13:26:57.954808 2026] [security2:error] [pid 890219:tid 890392] [client 20.171.55.167:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/themes/themes.php"] [unique_id "amuXcYJkCYmL5o6vh9JmhQAAAK8"]
[Thu Jul 30 13:26:58.674010 2026] [security2:error] [pid 890219:tid 890418] [client 20.171.55.167:4604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/radio.php"] [unique_id "amuXcoJkCYmL5o6vh9JmkwAAAMk"]
[Thu Jul 30 13:26:59.015385 2026] [security2:error] [pid 890219:tid 890424] [client 41.90.172.86:2479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXcoJkCYmL5o6vh9JmlAAAAM8"], referer: http://pkf.jo
[Thu Jul 30 13:26:59.381249 2026] [security2:error] [pid 890219:tid 890441] [client 20.171.55.167:4600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-mail.php"] [unique_id "amuXc4JkCYmL5o6vh9JmpAAAAOA"]
[Thu Jul 30 13:26:59.747990 2026] [security2:error] [pid 890219:tid 890447] [client 172.236.9.101:33155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXc4JkCYmL5o6vh9JmogAAAOY"]
[Thu Jul 30 13:26:59.860340 2026] [core:notice] [pid 890219:tid 890455] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:00.098234 2026] [security2:error] [pid 890219:tid 890462] [client 20.171.55.167:4677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuXdIJkCYmL5o6vh9JmsAAAAPU"]
[Thu Jul 30 13:27:00.775018 2026] [security2:error] [pid 890219:tid 890477] [client 220.181.108.169:50987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.pkf.jo"] [uri "/index.php"] [unique_id "amuXdIJkCYmL5o6vh9JmtwABBBg"]
[Thu Jul 30 13:27:00.775238 2026] [security2:error] [pid 890219:tid 890249] [remote 217.182.128.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plumbingplumb.com"] [uri "/wp/wp-login.php"] [unique_id "amuXdIJkCYmL5o6vh9JmvgAAlBw"]
[Thu Jul 30 13:27:01.180167 2026] [security2:error] [pid 890219:tid 890372] [client 20.171.55.167:4579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/admin.php"] [unique_id "amuXdYJkCYmL5o6vh9JmyAAAAJs"]
[Thu Jul 30 13:27:01.323761 2026] [security2:error] [pid 890219:tid 890408] [client 74.248.20.32:61323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.progroupdoha.com"] [uri "/css.php"] [unique_id "amuXdYJkCYmL5o6vh9JmzwAAAL8"]
[Thu Jul 30 13:27:01.323928 2026] [security2:error] [pid 890219:tid 890408] [client 74.248.20.32:61323] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.progroupdoha.com"] [uri "/css.php"] [unique_id "amuXdYJkCYmL5o6vh9JmzwAAAL8"]
[Thu Jul 30 13:27:01.591752 2026] [security2:error] [pid 890219:tid 890396] [client 102.208.164.205:3966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXdYJkCYmL5o6vh9JmyQAAALM"], referer: http://pkf.jo
[Thu Jul 30 13:27:01.650853 2026] [security2:error] [pid 872418:tid 872647] [client 20.91.199.21:15771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuXdVymN6QYcoA7XB5u3QAAAGM"]
[Thu Jul 30 13:27:01.799570 2026] [security2:error] [pid 890219:tid 890400] [client 172.236.9.101:32686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXdYJkCYmL5o6vh9JmywAAALc"]
[Thu Jul 30 13:27:01.898863 2026] [security2:error] [pid 890219:tid 890448] [client 20.40.58.237:62567] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuXdYJkCYmL5o6vh9Jm3wAAAOc"]
[Thu Jul 30 13:27:01.968478 2026] [security2:error] [pid 890219:tid 890437] [client 20.171.55.167:4453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuXdYJkCYmL5o6vh9Jm4gAAANw"]
[Thu Jul 30 13:27:02.482590 2026] [security2:error] [pid 890219:tid 890456] [client 20.91.199.21:1279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuXdoJkCYmL5o6vh9Jm7gAAAO8"]
[Thu Jul 30 13:27:02.697067 2026] [security2:error] [pid 890219:tid 890465] [client 20.171.55.167:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-links-opml.php"] [unique_id "amuXdoJkCYmL5o6vh9Jm9gAAAPg"]
[Thu Jul 30 13:27:02.704382 2026] [security2:error] [pid 890219:tid 890442] [client 3.224.12.127:60963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuXdoJkCYmL5o6vh9Jm8gAA4S4"]
[Thu Jul 30 13:27:03.437274 2026] [security2:error] [pid 890219:tid 890364] [client 20.171.55.167:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/acme-challenge/radio.php"] [unique_id "amuXd4JkCYmL5o6vh9JnCAAAAJM"]
[Thu Jul 30 13:27:03.750387 2026] [security2:error] [pid 890219:tid 890382] [client 143.208.239.96:26476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXd4JkCYmL5o6vh9JnBwAAAKU"], referer: http://pkf.jo
[Thu Jul 30 13:27:03.786964 2026] [security2:error] [pid 890219:tid 890383] [client 172.236.9.101:6591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXd4JkCYmL5o6vh9JnBQAAAKY"]
[Thu Jul 30 13:27:03.933678 2026] [security2:error] [pid 890219:tid 890406] [client 119.73.97.132:29263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuXd4JkCYmL5o6vh9JnEgAAvTo"], referer: https://trello.com/
[Thu Jul 30 13:27:04.012261 2026] [security2:error] [pid 890219:tid 890422] [client 185.156.175.51:45750] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuXeIJkCYmL5o6vh9JnFAAAAM0"]
[Thu Jul 30 13:27:04.012387 2026] [security2:error] [pid 890219:tid 890422] [client 185.156.175.51:45750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuXeIJkCYmL5o6vh9JnFAAAAM0"]
[Thu Jul 30 13:27:04.147243 2026] [security2:error] [pid 890219:tid 890407] [client 20.171.55.167:4583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/images/file.php"] [unique_id "amuXeIJkCYmL5o6vh9JnHgAAAL4"]
[Thu Jul 30 13:27:04.864423 2026] [security2:error] [pid 890219:tid 890450] [client 20.171.55.167:4433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/upgrade/function.php"] [unique_id "amuXeIJkCYmL5o6vh9JnLQAAAOk"]
[Thu Jul 30 13:27:05.172016 2026] [security2:error] [pid 890219:tid 890462] [client 127.0.0.1:11326] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuXeYJkCYmL5o6vh9JnNgAAAPU"]
[Thu Jul 30 13:27:05.172072 2026] [security2:error] [pid 890219:tid 890459] [client 74.7.230.38:53538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.jjp.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuXeYJkCYmL5o6vh9JnNQAA8kQ"]
[Thu Jul 30 13:27:05.233865 2026] [security2:error] [pid 890219:tid 890359] [client 185.189.112.19:50462] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuXeYJkCYmL5o6vh9JnNwAAAI4"]
[Thu Jul 30 13:27:05.233989 2026] [security2:error] [pid 890219:tid 890359] [client 185.189.112.19:50462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuXeYJkCYmL5o6vh9JnNwAAAI4"]
[Thu Jul 30 13:27:05.591567 2026] [security2:error] [pid 890219:tid 890357] [client 20.171.55.167:4710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/user/themes.php"] [unique_id "amuXeYJkCYmL5o6vh9JnQgAAAIw"]
[Thu Jul 30 13:27:05.764827 2026] [security2:error] [pid 890219:tid 890361] [client 172.236.9.101:55256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXeYJkCYmL5o6vh9JnOwAAAJA"]
[Thu Jul 30 13:27:06.016798 2026] [security2:error] [pid 890219:tid 890378] [client 42.104.222.23:34765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXeYJkCYmL5o6vh9JnRgAAAKE"], referer: http://pkf.jo
[Thu Jul 30 13:27:06.333522 2026] [security2:error] [pid 890219:tid 890399] [client 20.171.55.167:4672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/radio.php"] [unique_id "amuXeoJkCYmL5o6vh9JnVgAAALY"]
[Thu Jul 30 13:27:06.618314 2026] [security2:error] [pid 890219:tid 890428] [client 51.39.232.11:24350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXeoJkCYmL5o6vh9JnVQAAANM"], referer: http://pkf.jo
[Thu Jul 30 13:27:06.753352 2026] [security2:error] [pid 890219:tid 890429] [client 172.236.9.101:60205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXeoJkCYmL5o6vh9JnVAAAANQ"]
[Thu Jul 30 13:27:07.043265 2026] [security2:error] [pid 890219:tid 890448] [client 20.171.55.167:4478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/license.php"] [unique_id "amuXe4JkCYmL5o6vh9JnYwAAAOc"]
[Thu Jul 30 13:27:07.080687 2026] [security2:error] [pid 890219:tid 890419] [client 179.64.21.229:20826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXe4JkCYmL5o6vh9JnZAAAAMo"]
[Thu Jul 30 13:27:07.081195 2026] [security2:error] [pid 890219:tid 890419] [client 179.64.21.229:20826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXe4JkCYmL5o6vh9JnZAAAAMo"]
[Thu Jul 30 13:27:07.107036 2026] [security2:error] [pid 890219:tid 890391] [client 20.91.199.21:1875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuXe4JkCYmL5o6vh9JnZQAAAK4"]
[Thu Jul 30 13:27:07.758715 2026] [security2:error] [pid 890219:tid 890469] [client 20.171.55.167:4430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/pki-validation/wp-config.php"] [unique_id "amuXe4JkCYmL5o6vh9JndgAAAPw"]
[Thu Jul 30 13:27:07.761799 2026] [security2:error] [pid 890219:tid 890458] [client 172.236.9.101:12723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXe4JkCYmL5o6vh9JnbAAAAPE"]
[Thu Jul 30 13:27:08.080189 2026] [security2:error] [pid 890219:tid 890477] [client 20.91.199.21:15801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuXfIJkCYmL5o6vh9JnewAAAQQ"]
[Thu Jul 30 13:27:08.450499 2026] [security2:error] [pid 890219:tid 890397] [client 185.156.175.51:48312] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXfIJkCYmL5o6vh9JniQAAALQ"]
[Thu Jul 30 13:27:08.450607 2026] [security2:error] [pid 890219:tid 890397] [client 185.156.175.51:48312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXfIJkCYmL5o6vh9JniQAAALQ"]
[Thu Jul 30 13:27:08.483719 2026] [security2:error] [pid 890219:tid 890350] [client 20.171.55.167:4696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/radio.php"] [unique_id "amuXfIJkCYmL5o6vh9JnigAAAIU"]
[Thu Jul 30 13:27:08.657911 2026] [core:notice] [pid 890219:tid 890359] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:08.706443 2026] [security2:error] [pid 890219:tid 890387] [client 172.236.9.101:34291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXfIJkCYmL5o6vh9JngwAAAKo"]
[Thu Jul 30 13:27:08.727971 2026] [security2:error] [pid 890219:tid 890355] [client 20.91.199.21:1688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuXfIJkCYmL5o6vh9JnjwAAAIo"]
[Thu Jul 30 13:27:08.788118 2026] [security2:error] [pid 890219:tid 890422] [client 74.7.230.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "odk.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuXfIJkCYmL5o6vh9JnlQAAAM0"]
[Thu Jul 30 13:27:08.788669 2026] [security2:error] [pid 890219:tid 890404] [client 74.7.230.3:41560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "odk.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuXfIJkCYmL5o6vh9JnkAAAALs"]
[Thu Jul 30 13:27:09.037484 2026] [security2:error] [pid 890219:tid 890429] [client 74.7.230.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "odk.udi.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuXfYJkCYmL5o6vh9JnnAAAANQ"], referer: https://odk.udi.temporary.site/robots.txt
[Thu Jul 30 13:27:09.038035 2026] [security2:error] [pid 890219:tid 890390] [client 74.7.230.3:41560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "odk.udi.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuXfIJkCYmL5o6vh9JnmgAAAK0"], referer: https://odk.udi.temporary.site/robots.txt
[Thu Jul 30 13:27:09.189511 2026] [security2:error] [pid 890219:tid 890401] [client 20.171.55.167:4570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/plugins/about.php"] [unique_id "amuXfYJkCYmL5o6vh9JnoAAAALg"]
[Thu Jul 30 13:27:09.713091 2026] [security2:error] [pid 890219:tid 890441] [client 172.236.9.101:49417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXfYJkCYmL5o6vh9JnoQAAAOA"]
[Thu Jul 30 13:27:09.903725 2026] [security2:error] [pid 890219:tid 890468] [client 20.171.55.167:4676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuXfYJkCYmL5o6vh9JntQAAAPs"]
[Thu Jul 30 13:27:10.030854 2026] [security2:error] [pid 890219:tid 890474] [client 20.91.199.21:1865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuXfoJkCYmL5o6vh9JnuQAAAQE"]
[Thu Jul 30 13:27:10.641634 2026] [security2:error] [pid 890219:tid 890385] [client 20.171.55.167:4700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/wp-login.php"] [unique_id "amuXfoJkCYmL5o6vh9JnyQAAAKg"]
[Thu Jul 30 13:27:10.674316 2026] [security2:error] [pid 890219:tid 890368] [client 47.128.122.81:27702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ejournalugj.com"] [uri "/robots.txt"] [unique_id "amuXfoJkCYmL5o6vh9JnygAAAJc"]
[Thu Jul 30 13:27:10.731666 2026] [security2:error] [pid 890219:tid 890365] [client 172.236.9.101:40990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXfoJkCYmL5o6vh9JnvQAAAJQ"]
[Thu Jul 30 13:27:10.770763 2026] [security2:error] [pid 890219:tid 890395] [client 20.91.199.21:1464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuXfoJkCYmL5o6vh9JnywAAALI"]
[Thu Jul 30 13:27:11.362701 2026] [security2:error] [pid 890219:tid 890436] [client 20.171.55.167:4726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/wp-load.php"] [unique_id "amuXf4JkCYmL5o6vh9Jn2AAAANs"]
[Thu Jul 30 13:27:11.518347 2026] [security2:error] [pid 890219:tid 890418] [client 20.91.199.21:1887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/cloud.php"] [unique_id "amuXf4JkCYmL5o6vh9Jn4QAAAMk"]
[Thu Jul 30 13:27:11.618620 2026] [security2:error] [pid 890219:tid 890473] [client 74.7.244.18:54264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoki188win.com"] [uri "/robots.txt"] [unique_id "amuXf4JkCYmL5o6vh9Jn5gABAHA"]
[Thu Jul 30 13:27:11.722910 2026] [security2:error] [pid 890219:tid 890430] [client 172.236.9.101:64738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXf4JkCYmL5o6vh9Jn1gAAANU"]
[Thu Jul 30 13:27:12.074313 2026] [security2:error] [pid 890219:tid 890438] [client 20.171.55.167:4695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/file.php"] [unique_id "amuXgIJkCYmL5o6vh9Jn8QAAAN0"]
[Thu Jul 30 13:27:12.160732 2026] [security2:error] [pid 890219:tid 890464] [client 116.179.37.103:15321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuXgIJkCYmL5o6vh9Jn9QAAAPc"], referer: https://pkf.jo/
[Thu Jul 30 13:27:12.289774 2026] [security2:error] [pid 890219:tid 890465] [client 20.52.125.110:8700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.tmb/LA.php"] [unique_id "amuXgIJkCYmL5o6vh9Jn9wAAAPg"]
[Thu Jul 30 13:27:12.724440 2026] [security2:error] [pid 890219:tid 890362] [client 172.236.9.101:16623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXgIJkCYmL5o6vh9Jn9gAAAJE"]
[Thu Jul 30 13:27:12.784008 2026] [security2:error] [pid 890219:tid 890377] [client 20.52.125.110:8650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.tmb/admin.php"] [unique_id "amuXgIJkCYmL5o6vh9JoAQAAAKA"]
[Thu Jul 30 13:27:12.800290 2026] [security2:error] [pid 890219:tid 890354] [client 20.171.55.167:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/dropdown.php"] [unique_id "amuXgIJkCYmL5o6vh9JoAgAAAIk"]
[Thu Jul 30 13:27:13.350590 2026] [security2:error] [pid 890219:tid 890395] [client 20.52.125.110:8691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.tmb/class_api.php"] [unique_id "amuXgYJkCYmL5o6vh9JoDQAAALI"]
[Thu Jul 30 13:27:13.511297 2026] [security2:error] [pid 890219:tid 890414] [client 20.171.55.167:4465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/plugins/dropdown.php"] [unique_id "amuXgYJkCYmL5o6vh9JoFAAAAMU"]
[Thu Jul 30 13:27:13.633732 2026] [security2:error] [pid 890219:tid 890466] [client 20.91.199.21:1227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuXgYJkCYmL5o6vh9JoGQAAAPk"]
[Thu Jul 30 13:27:13.716332 2026] [security2:error] [pid 890219:tid 890398] [client 185.24.60.222:36860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXgYJkCYmL5o6vh9JoDgAAALU"], referer: http://pkf.jo
[Thu Jul 30 13:27:13.753040 2026] [security2:error] [pid 890219:tid 890382] [client 172.236.9.101:44230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXgYJkCYmL5o6vh9JoDAAAAKU"]
[Thu Jul 30 13:27:13.847132 2026] [security2:error] [pid 890219:tid 890425] [client 20.52.125.110:9546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuXgYJkCYmL5o6vh9JoIQAAANA"]
[Thu Jul 30 13:27:14.262051 2026] [security2:error] [pid 890219:tid 890419] [client 20.91.199.21:14738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/updates.php"] [unique_id "amuXgoJkCYmL5o6vh9JoKgAAAMo"]
[Thu Jul 30 13:27:14.588448 2026] [security2:error] [pid 890219:tid 890428] [client 20.52.125.110:9550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuXgoJkCYmL5o6vh9JoLwAAANM"]
[Thu Jul 30 13:27:14.613778 2026] [security2:error] [pid 890219:tid 890396] [client 20.171.55.167:4557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/includes/index.php"] [unique_id "amuXgoJkCYmL5o6vh9JoNQAAALM"]
[Thu Jul 30 13:27:14.765259 2026] [security2:error] [pid 890219:tid 890447] [client 172.236.9.101:11475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXgoJkCYmL5o6vh9JoLAAAAOY"]
[Thu Jul 30 13:27:15.144239 2026] [security2:error] [pid 890219:tid 890373] [client 20.52.125.110:8666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuXg4JkCYmL5o6vh9JoPwAAAJw"]
[Thu Jul 30 13:27:15.403828 2026] [security2:error] [pid 890219:tid 890389] [client 20.171.55.167:4445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-signup.php"] [unique_id "amuXg4JkCYmL5o6vh9JoRwAAAKw"]
[Thu Jul 30 13:27:15.718596 2026] [security2:error] [pid 890219:tid 890387] [client 20.52.125.110:8671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/991176.php"] [unique_id "amuXg4JkCYmL5o6vh9JoUAAAAKo"]
[Thu Jul 30 13:27:15.766356 2026] [security2:error] [pid 890219:tid 890375] [client 172.236.9.101:16740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXg4JkCYmL5o6vh9JoQwAAAJ4"]
[Thu Jul 30 13:27:15.837724 2026] [security2:error] [pid 890219:tid 890405] [client 20.91.199.21:14766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/css/cloud.php"] [unique_id "amuXg4JkCYmL5o6vh9JoUwAAALw"]
[Thu Jul 30 13:27:16.110786 2026] [security2:error] [pid 890219:tid 890397] [client 20.171.55.167:4565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/images/css.php"] [unique_id "amuXhIJkCYmL5o6vh9JoVwAAALQ"]
[Thu Jul 30 13:27:16.354777 2026] [security2:error] [pid 890219:tid 890466] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXg4JkCYmL5o6vh9JoTwAA-Qs"]
[Thu Jul 30 13:27:16.362635 2026] [security2:error] [pid 890219:tid 890415] [client 20.52.125.110:8692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuXhIJkCYmL5o6vh9JoYAAAAMY"]
[Thu Jul 30 13:27:16.756738 2026] [http2:info] [pid 890219:tid 890461] [client 84.90.204.109:51300] AH10178: h2_stream(890219-32-3,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:27:16.781648 2026] [security2:error] [pid 890219:tid 890241] [remote 57.141.0.32:63878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuXhIJkCYmL5o6vh9JoagAA8xQ"]
[Thu Jul 30 13:27:16.820132 2026] [security2:error] [pid 890219:tid 890453] [client 20.171.55.167:4721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/chosen.php"] [unique_id "amuXhIJkCYmL5o6vh9JoawAAAOw"]
[Thu Jul 30 13:27:16.926142 2026] [security2:error] [pid 890219:tid 890432] [client 20.52.125.110:8695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuXhIJkCYmL5o6vh9JobwAAANc"]
[Thu Jul 30 13:27:17.013864 2026] [security2:error] [pid 890219:tid 890425] [client 172.236.9.101:47903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXhIJkCYmL5o6vh9JoXgAAANA"]
[Thu Jul 30 13:27:17.159898 2026] [security2:error] [pid 890219:tid 890449] [client 20.91.199.21:1224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuXhYJkCYmL5o6vh9JocQAAAOg"]
[Thu Jul 30 13:27:17.368681 2026] [security2:error] [pid 890219:tid 890468] [client 131.222.247.138:35992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXhYJkCYmL5o6vh9JocAAAAPs"], referer: http://pkf.jo
[Thu Jul 30 13:27:17.392571 2026] [security2:error] [pid 890219:tid 890472] [client 179.64.21.229:15600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXhYJkCYmL5o6vh9JoeQAAAP8"]
[Thu Jul 30 13:27:17.396251 2026] [security2:error] [pid 890219:tid 890472] [client 179.64.21.229:15600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXhYJkCYmL5o6vh9JoeQAAAP8"]
[Thu Jul 30 13:27:17.468211 2026] [security2:error] [pid 890219:tid 890376] [client 20.52.125.110:9567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuXhYJkCYmL5o6vh9JofQAAAJ8"]
[Thu Jul 30 13:27:17.529122 2026] [security2:error] [pid 890219:tid 890362] [client 20.171.55.167:4455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/cong.php"] [unique_id "amuXhYJkCYmL5o6vh9JofwAAAJE"]
[Thu Jul 30 13:27:17.825917 2026] [http2:info] [pid 890219:tid 890399] [client 84.90.204.109:51300] AH10178: h2_stream(890219-32-5,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:27:17.964780 2026] [security2:error] [pid 890219:tid 890422] [client 20.52.125.110:8684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuXhYJkCYmL5o6vh9JohgAAAM0"]
[Thu Jul 30 13:27:18.171521 2026] [security2:error] [pid 890219:tid 890410] [client 20.91.199.21:15794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/img/cloud.php"] [unique_id "amuXhoJkCYmL5o6vh9JoiwAAAME"]
[Thu Jul 30 13:27:18.290283 2026] [security2:error] [pid 890219:tid 890350] [client 20.171.55.167:4722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/mah.php"] [unique_id "amuXhoJkCYmL5o6vh9JokAAAAIU"]
[Thu Jul 30 13:27:18.598929 2026] [security2:error] [pid 890219:tid 890440] [client 20.52.125.110:8648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuXhoJkCYmL5o6vh9JolwAAAN8"]
[Thu Jul 30 13:27:18.756168 2026] [security2:error] [pid 890219:tid 890435] [client 172.236.9.101:64141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXhoJkCYmL5o6vh9JojAAAANo"]
[Thu Jul 30 13:27:18.869741 2026] [security2:error] [pid 890219:tid 890441] [client 82.102.18.182:57914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvape-australia.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuXhoJkCYmL5o6vh9JonwAAAOA"]
[Thu Jul 30 13:27:18.935191 2026] [security2:error] [pid 890219:tid 890444] [client 94.154.43.178:23750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alseermarine.com"] [uri "/.env"] [unique_id "amuXhoJkCYmL5o6vh9JoogAAAOM"]
[Thu Jul 30 13:27:18.996716 2026] [autoindex:error] [pid 890219:tid 890260] [remote 20.116.106.6:52813] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:27:19.017647 2026] [security2:error] [pid 890219:tid 890448] [client 20.171.55.167:4246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuXh4JkCYmL5o6vh9JopAAAAOc"]
[Thu Jul 30 13:27:19.208567 2026] [security2:error] [pid 890219:tid 890424] [client 20.91.199.21:5622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuXh4JkCYmL5o6vh9JoqQAAAM8"]
[Thu Jul 30 13:27:19.438760 2026] [security2:error] [pid 890219:tid 890458] [client 82.102.18.182:57924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amuXh4JkCYmL5o6vh9JosQAAAPE"]
[Thu Jul 30 13:27:19.711302 2026] [autoindex:error] [pid 890219:tid 890264] [remote 20.104.228.251:31709] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:27:19.778696 2026] [security2:error] [pid 890219:tid 890432] [client 172.236.9.101:42334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXh4JkCYmL5o6vh9JoqgAAANc"]
[Thu Jul 30 13:27:19.779689 2026] [security2:error] [pid 890219:tid 890477] [client 20.171.55.167:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/ova-tools.php"] [unique_id "amuXh4JkCYmL5o6vh9JougAAAQQ"]
[Thu Jul 30 13:27:20.114538 2026] [security2:error] [pid 890219:tid 890381] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXh4JkCYmL5o6vh9JotAAAAKQ"]
[Thu Jul 30 13:27:20.195238 2026] [security2:error] [pid 890219:tid 890271] [remote 47.128.28.115:19526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/search/Nike/page/107/"] [unique_id "amuXiIJkCYmL5o6vh9JoygAAuzI"]
[Thu Jul 30 13:27:20.359157 2026] [security2:error] [pid 890219:tid 890426] [client 20.91.199.21:18303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuXiIJkCYmL5o6vh9Jo0QAAANE"]
[Thu Jul 30 13:27:20.485299 2026] [security2:error] [pid 890219:tid 890431] [client 20.171.55.167:4703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuXiIJkCYmL5o6vh9Jo1QAAANY"]
[Thu Jul 30 13:27:20.735864 2026] [security2:error] [pid 890219:tid 890422] [client 172.236.9.101:46235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXiIJkCYmL5o6vh9JoywAAAM0"]
[Thu Jul 30 13:27:20.894063 2026] [security2:error] [pid 890219:tid 890450] [client 20.52.125.110:8670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "clubnails.bonafideadvisors.com"] [uri "/index.php"] [unique_id "amuXh4JkCYmL5o6vh9JoqAAAAOk"]
[Thu Jul 30 13:27:21.024729 2026] [security2:error] [pid 890219:tid 890444] [client 20.52.125.110:8670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuXiYJkCYmL5o6vh9Jo4wAAAOM"]
[Thu Jul 30 13:27:21.158989 2026] [autoindex:error] [pid 890219:tid 890281] [remote 4.210.65.194:20487] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:27:21.202463 2026] [security2:error] [pid 890219:tid 890430] [client 20.91.199.21:5592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/avaa.php"] [unique_id "amuXiYJkCYmL5o6vh9Jo6AAAANU"]
[Thu Jul 30 13:27:21.232874 2026] [security2:error] [pid 890219:tid 890441] [client 20.171.55.167:4606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuXiYJkCYmL5o6vh9Jo6gAAAOA"]
[Thu Jul 30 13:27:21.337634 2026] [security2:error] [pid 890219:tid 890282] [remote 57.141.0.47:47412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuXiYJkCYmL5o6vh9Jo7AAAzj0"]
[Thu Jul 30 13:27:21.592345 2026] [security2:error] [pid 890219:tid 890390] [client 20.52.125.110:8640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuXiYJkCYmL5o6vh9Jo-gAAAK0"]
[Thu Jul 30 13:27:21.778378 2026] [security2:error] [pid 890219:tid 890396] [client 172.236.9.101:33325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXiYJkCYmL5o6vh9Jo6wAAALM"]
[Thu Jul 30 13:27:21.867567 2026] [security2:error] [pid 890219:tid 890463] [client 20.91.199.21:1611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/images/cloud.php"] [unique_id "amuXiYJkCYmL5o6vh9Jo_AAAAPY"]
[Thu Jul 30 13:27:21.950087 2026] [security2:error] [pid 890219:tid 890389] [client 20.171.55.167:4605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuXiYJkCYmL5o6vh9JpAQAAAKw"]
[Thu Jul 30 13:27:22.202793 2026] [security2:error] [pid 890219:tid 890470] [client 20.52.125.110:8678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuXioJkCYmL5o6vh9JpCQAAAP0"]
[Thu Jul 30 13:27:22.414011 2026] [security2:error] [pid 890219:tid 890352] [client 20.91.199.21:33864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/json.php"] [unique_id "amuXioJkCYmL5o6vh9JpDwAAAIc"]
[Thu Jul 30 13:27:22.657430 2026] [security2:error] [pid 890219:tid 890443] [client 20.171.55.167:4714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuXioJkCYmL5o6vh9JpGwAAAOI"]
[Thu Jul 30 13:27:22.692222 2026] [autoindex:error] [pid 890219:tid 890295] [remote 20.48.109.27:21795] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:27:22.764155 2026] [security2:error] [pid 890219:tid 890409] [client 172.236.9.101:38407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXioJkCYmL5o6vh9JpDQAAAMA"]
[Thu Jul 30 13:27:22.960474 2026] [security2:error] [pid 890219:tid 890476] [client 82.102.18.182:5168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amuXioJkCYmL5o6vh9JpIwAAAQM"]
[Thu Jul 30 13:27:22.960575 2026] [security2:error] [pid 890219:tid 890476] [client 82.102.18.182:5168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amuXioJkCYmL5o6vh9JpIwAAAQM"]
[Thu Jul 30 13:27:23.182701 2026] [security2:error] [pid 890219:tid 890437] [client 20.91.199.21:4824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuXi4JkCYmL5o6vh9JpKwAAANw"]
[Thu Jul 30 13:27:23.289307 2026] [security2:error] [pid 890219:tid 890424] [client 20.91.199.21:33900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/mini.php"] [unique_id "amuXi4JkCYmL5o6vh9JpMAAAAM8"]
[Thu Jul 30 13:27:23.372836 2026] [security2:error] [pid 890219:tid 890367] [client 20.171.55.167:4586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/banners/about.php"] [unique_id "amuXi4JkCYmL5o6vh9JpMgAAAJY"]
[Thu Jul 30 13:27:23.421214 2026] [core:notice] [pid 890219:tid 890394] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:23.522314 2026] [security2:error] [pid 890219:tid 890363] [client 216.73.216.33:25339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jdasecurity.ph"] [uri "/index.php"] [unique_id "amuXi4JkCYmL5o6vh9JpMQAAklE"]
[Thu Jul 30 13:27:23.722158 2026] [security2:error] [pid 890219:tid 890354] [client 172.236.9.101:44467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXi4JkCYmL5o6vh9JpLwAAAIk"]
[Thu Jul 30 13:27:23.872810 2026] [core:notice] [pid 890219:tid 890442] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:23.889561 2026] [security2:error] [pid 890219:tid 890446] [client 20.52.125.110:9539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuXi4JkCYmL5o6vh9JpRAAAAOU"]
[Thu Jul 30 13:27:24.079327 2026] [security2:error] [pid 890219:tid 890462] [client 20.171.55.167:4457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/license.php"] [unique_id "amuXjIJkCYmL5o6vh9JpSAAAAPU"]
[Thu Jul 30 13:27:24.415141 2026] [security2:error] [pid 890219:tid 890431] [client 20.52.125.110:8698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuXjIJkCYmL5o6vh9JpUgAAANY"]
[Thu Jul 30 13:27:24.685566 2026] [security2:error] [pid 890219:tid 890402] [client 20.91.199.21:1782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuXjIJkCYmL5o6vh9JpWQAAALk"]
[Thu Jul 30 13:27:24.712224 2026] [security2:error] [pid 890219:tid 890407] [client 172.236.9.101:33272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXjIJkCYmL5o6vh9JpTgAAAL4"]
[Thu Jul 30 13:27:24.750473 2026] [security2:error] [pid 890219:tid 890401] [client 20.91.199.21:47173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/chosen.php"] [unique_id "amuXjIJkCYmL5o6vh9JpXQAAALg"]
[Thu Jul 30 13:27:24.826033 2026] [security2:error] [pid 890219:tid 890422] [client 20.171.55.167:4673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/about.php"] [unique_id "amuXjIJkCYmL5o6vh9JpYwAAAM0"]
[Thu Jul 30 13:27:24.904940 2026] [security2:error] [pid 890219:tid 890452] [client 20.52.125.110:8680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuXjIJkCYmL5o6vh9JpZAAAAOs"]
[Thu Jul 30 13:27:25.399297 2026] [security2:error] [pid 890219:tid 890430] [client 20.52.125.110:9552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuXjYJkCYmL5o6vh9JpcQAAANU"]
[Thu Jul 30 13:27:25.532907 2026] [security2:error] [pid 890219:tid 890369] [client 20.171.55.167:11485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/about.php"] [unique_id "amuXjYJkCYmL5o6vh9JpcgAAAJg"]
[Thu Jul 30 13:27:25.729349 2026] [security2:error] [pid 890219:tid 890423] [client 172.236.9.101:18875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXjYJkCYmL5o6vh9JpbAAAAM4"]
[Thu Jul 30 13:27:25.833905 2026] [security2:error] [pid 890219:tid 890474] [client 20.52.125.110:8684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuXjYJkCYmL5o6vh9JpfQAAAQE"]
[Thu Jul 30 13:27:25.868789 2026] [security2:error] [pid 890219:tid 890353] [client 20.91.199.21:8373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuXjYJkCYmL5o6vh9JpfgAAAIg"]
[Thu Jul 30 13:27:26.270109 2026] [security2:error] [pid 890219:tid 890385] [client 20.91.199.21:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/kj.php"] [unique_id "amuXjoJkCYmL5o6vh9JphwAAAKg"]
[Thu Jul 30 13:27:26.398716 2026] [security2:error] [pid 890219:tid 890387] [client 20.52.125.110:9563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuXjoJkCYmL5o6vh9JpjgAAAKo"]
[Thu Jul 30 13:27:26.583106 2026] [security2:error] [pid 890219:tid 890368] [client 20.91.199.21:4846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuXjoJkCYmL5o6vh9JpjwAAAJc"]
[Thu Jul 30 13:27:26.741575 2026] [security2:error] [pid 890219:tid 890442] [client 172.236.9.101:59725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXjoJkCYmL5o6vh9JpiAAAAOE"]
[Thu Jul 30 13:27:26.744276 2026] [security2:error] [pid 890219:tid 890374] [client 20.171.55.167:11497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/Text/about.php"] [unique_id "amuXjoJkCYmL5o6vh9JplQAAAJ0"]
[Thu Jul 30 13:27:26.907314 2026] [security2:error] [pid 890219:tid 890395] [client 20.52.125.110:8663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/bek.php"] [unique_id "amuXjoJkCYmL5o6vh9JpmwAAALI"]
[Thu Jul 30 13:27:27.238334 2026] [security2:error] [pid 890219:tid 890377] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXjoJkCYmL5o6vh9JpiQAAoHM"]
[Thu Jul 30 13:27:27.380929 2026] [security2:error] [pid 890219:tid 890445] [client 20.52.125.110:8681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuXj4JkCYmL5o6vh9JppwAAAOQ"]
[Thu Jul 30 13:27:27.381015 2026] [security2:error] [pid 890219:tid 890377] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXjoJkCYmL5o6vh9JpjQAAoHI"]
[Thu Jul 30 13:27:27.388674 2026] [core:notice] [pid 890219:tid 890360] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:27.513486 2026] [security2:error] [pid 890219:tid 890418] [client 20.171.55.167:11503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuXj4JkCYmL5o6vh9JpqgAAAMk"]
[Thu Jul 30 13:27:27.553337 2026] [security2:error] [pid 890219:tid 890421] [client 20.91.199.21:15526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuXj4JkCYmL5o6vh9JpqwAAAMw"]
[Thu Jul 30 13:27:27.729176 2026] [security2:error] [pid 890219:tid 890422] [client 172.236.9.101:49991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXj4JkCYmL5o6vh9JpoAAAAM0"]
[Thu Jul 30 13:27:27.804919 2026] [security2:error] [pid 890219:tid 890467] [client 20.91.199.21:10349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/wp-files.php"] [unique_id "amuXj4JkCYmL5o6vh9JpsgAAAPo"]
[Thu Jul 30 13:27:27.885664 2026] [core:notice] [pid 890219:tid 890476] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:27.955926 2026] [security2:error] [pid 890219:tid 890441] [client 20.52.125.110:8660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/class.api.php"] [unique_id "amuXj4JkCYmL5o6vh9JpuAAAAOA"]
[Thu Jul 30 13:27:28.237452 2026] [security2:error] [pid 890219:tid 890369] [client 20.171.55.167:4589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/img/about.php"] [unique_id "amuXkIJkCYmL5o6vh9JpvwAAAJg"]
[Thu Jul 30 13:27:28.407758 2026] [security2:error] [pid 890219:tid 890229] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greecevisaassistanceislamabad.online"] [uri "/app/config/local.php"] [unique_id "amuXkIJkCYmL5o6vh9JpygAAxwg"]
[Thu Jul 30 13:27:28.437380 2026] [security2:error] [pid 890219:tid 890373] [client 20.52.125.110:8645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/cong.php"] [unique_id "amuXkIJkCYmL5o6vh9Jp6wAAAJw"]
[Thu Jul 30 13:27:28.517224 2026] [security2:error] [pid 890219:tid 890379] [client 20.91.199.21:8831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuXkIJkCYmL5o6vh9Jp9QAAAKI"]
[Thu Jul 30 13:27:28.590234 2026] [security2:error] [pid 890219:tid 890378] [client 20.91.199.21:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/wp-setup.php"] [unique_id "amuXkIJkCYmL5o6vh9Jp9wAAAKE"]
[Thu Jul 30 13:27:28.612068 2026] [security2:error] [pid 890219:tid 890388] [client 179.64.21.229:57018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXkIJkCYmL5o6vh9Jp-QAAAKs"]
[Thu Jul 30 13:27:28.619693 2026] [security2:error] [pid 890219:tid 890388] [client 179.64.21.229:57018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXkIJkCYmL5o6vh9Jp-QAAAKs"]
[Thu Jul 30 13:27:28.734693 2026] [security2:error] [pid 890219:tid 890364] [client 172.236.9.101:44108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXkIJkCYmL5o6vh9JpwAAAAJM"]
[Thu Jul 30 13:27:28.816090 2026] [security2:error] [pid 890219:tid 890424] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXkIJkCYmL5o6vh9JpugAAzwE"]
[Thu Jul 30 13:27:28.874343 2026] [security2:error] [pid 890219:tid 890270] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greecevisaassistanceislamabad.online"] [uri "/app/config/local.php.bak"] [unique_id "amuXkIJkCYmL5o6vh9JqAgAArjE"]
[Thu Jul 30 13:27:28.942820 2026] [security2:error] [pid 890219:tid 890439] [client 20.171.55.167:11479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/languages/about.php"] [unique_id "amuXkIJkCYmL5o6vh9JqCQAAAN4"]
[Thu Jul 30 13:27:28.948657 2026] [security2:error] [pid 890219:tid 890401] [client 20.52.125.110:8701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/content.php"] [unique_id "amuXkIJkCYmL5o6vh9JqCgAAALg"]
[Thu Jul 30 13:27:29.071428 2026] [security2:error] [pid 890219:tid 890278] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greecevisaassistanceislamabad.online"] [uri "/mautic/app/config/local.php"] [unique_id "amuXkYJkCYmL5o6vh9JqCwAA5zk"]
[Thu Jul 30 13:27:29.147819 2026] [security2:error] [pid 890219:tid 890461] [client 188.120.106.251:12029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuXkIJkCYmL5o6vh9JqAAAAAPQ"], referer: http://pkf.jo
[Thu Jul 30 13:27:29.464177 2026] [security2:error] [pid 890219:tid 890282] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greecevisaassistanceislamabad.online"] [uri "/config/mail.php"] [unique_id "amuXkYJkCYmL5o6vh9JqFQAA6D0"]
[Thu Jul 30 13:27:29.548379 2026] [security2:error] [pid 890219:tid 890475] [client 20.52.125.110:8693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuXkYJkCYmL5o6vh9JqGAAAAQI"]
[Thu Jul 30 13:27:29.651998 2026] [security2:error] [pid 890219:tid 890465] [client 20.171.55.167:11498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/customize/about.php"] [unique_id "amuXkYJkCYmL5o6vh9JqGQAAAPg"]
[Thu Jul 30 13:27:29.678010 2026] [security2:error] [pid 890219:tid 890283] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greecevisaassistanceislamabad.online"] [uri "/config/services.php"] [unique_id "amuXkYJkCYmL5o6vh9JqGgAAzj4"]
[Thu Jul 30 13:27:29.737852 2026] [security2:error] [pid 890219:tid 890358] [client 172.236.9.101:60577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXkYJkCYmL5o6vh9JqDQAAAI0"]
[Thu Jul 30 13:27:30.178701 2026] [security2:error] [pid 890219:tid 890390] [client 20.52.125.110:9560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/elp.php"] [unique_id "amuXkoJkCYmL5o6vh9JqJAAAAK0"]
[Thu Jul 30 13:27:30.383728 2026] [security2:error] [pid 890219:tid 890446] [client 20.171.55.167:11488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuXkoJkCYmL5o6vh9JqJwAAAOU"]
[Thu Jul 30 13:27:30.545388 2026] [security2:error] [pid 890219:tid 890373] [client 20.91.199.21:40445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/defaults.php"] [unique_id "amuXkoJkCYmL5o6vh9JqMQAAAJw"]
[Thu Jul 30 13:27:30.706266 2026] [security2:error] [pid 890219:tid 890383] [client 172.236.9.101:12582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXkoJkCYmL5o6vh9JqJgAAAKY"]
[Thu Jul 30 13:27:30.804507 2026] [security2:error] [pid 890219:tid 890400] [client 20.52.125.110:9537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuXkoJkCYmL5o6vh9JqMgAAALc"]
[Thu Jul 30 13:27:31.089174 2026] [security2:error] [pid 890219:tid 890431] [client 20.171.55.167:11470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuXk4JkCYmL5o6vh9JqOwAAANY"]
[Thu Jul 30 13:27:31.130060 2026] [security2:error] [pid 890219:tid 890379] [client 20.91.199.21:5582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/updates.php"] [unique_id "amuXk4JkCYmL5o6vh9JqPQAAAKI"]
[Thu Jul 30 13:27:31.297054 2026] [security2:error] [pid 890219:tid 890436] [client 20.52.125.110:8658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuXk4JkCYmL5o6vh9JqPwAAANs"]
[Thu Jul 30 13:27:31.759576 2026] [security2:error] [pid 890219:tid 890450] [client 172.236.9.101:29376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXk4JkCYmL5o6vh9JqPgAAAOk"]
[Thu Jul 30 13:27:31.777899 2026] [core:notice] [pid 890219:tid 890409] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:31.797067 2026] [security2:error] [pid 890219:tid 890454] [client 20.171.55.167:11490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuXk4JkCYmL5o6vh9JqSgAAAO0"]
[Thu Jul 30 13:27:31.876160 2026] [security2:error] [pid 890219:tid 890422] [client 20.52.125.110:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuXk4JkCYmL5o6vh9JqSwAAAM0"]
[Thu Jul 30 13:27:32.210952 2026] [security2:error] [pid 890219:tid 890453] [client 20.91.199.21:10623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/gtc.php"] [unique_id "amuXlIJkCYmL5o6vh9JqWAAAAOw"]
[Thu Jul 30 13:27:32.454168 2026] [security2:error] [pid 890219:tid 890475] [client 20.52.125.110:9243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuXlIJkCYmL5o6vh9JqWgAAAQI"]
[Thu Jul 30 13:27:32.502901 2026] [security2:error] [pid 890219:tid 890465] [client 20.171.55.167:4230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/js/about.php"] [unique_id "amuXlIJkCYmL5o6vh9JqXgAAAPg"]
[Thu Jul 30 13:27:32.705157 2026] [security2:error] [pid 890219:tid 890425] [client 172.236.9.101:49865] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXlIJkCYmL5o6vh9JqWQAAANA"]
[Thu Jul 30 13:27:33.132949 2026] [security2:error] [pid 890219:tid 890414] [client 20.52.125.110:9252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuXlYJkCYmL5o6vh9JqdQAAAMU"]
[Thu Jul 30 13:27:33.204499 2026] [security2:error] [pid 890219:tid 890442] [client 20.91.199.21:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/import.php"] [unique_id "amuXlYJkCYmL5o6vh9JqeAAAAOE"]
[Thu Jul 30 13:27:33.245750 2026] [security2:error] [pid 890219:tid 890410] [client 20.171.55.167:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuXlYJkCYmL5o6vh9JqegAAAME"]
[Thu Jul 30 13:27:33.334467 2026] [security2:error] [pid 890219:tid 890389] [client 20.91.199.21:1690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuXlYJkCYmL5o6vh9JqfQAAAKw"]
[Thu Jul 30 13:27:33.492889 2026] [security2:error] [pid 890219:tid 890392] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXlIJkCYmL5o6vh9JqbQAAAK8"]
[Thu Jul 30 13:27:33.684293 2026] [security2:error] [pid 890219:tid 890443] [client 20.52.125.110:9217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuXlYJkCYmL5o6vh9JqhQAAAOI"]
[Thu Jul 30 13:27:33.724824 2026] [security2:error] [pid 890219:tid 890366] [client 172.236.9.101:56147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXlYJkCYmL5o6vh9JqewAAAJU"]
[Thu Jul 30 13:27:33.974734 2026] [security2:error] [pid 890219:tid 890438] [client 20.171.55.167:4571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuXlYJkCYmL5o6vh9JqjAAAAN0"]
[Thu Jul 30 13:27:34.103570 2026] [security2:error] [pid 890219:tid 890317] [remote 57.141.0.7:57328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83688077468/feed/rss2/"] [unique_id "amuXloJkCYmL5o6vh9JqkQAA2GA"]
[Thu Jul 30 13:27:34.115670 2026] [security2:error] [pid 890219:tid 890454] [client 20.91.199.21:43916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/lufix.php"] [unique_id "amuXloJkCYmL5o6vh9JqkgAAAO0"]
[Thu Jul 30 13:27:34.186893 2026] [security2:error] [pid 890219:tid 890445] [client 20.91.199.21:12810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuXloJkCYmL5o6vh9JqlgAAAOQ"]
[Thu Jul 30 13:27:34.262082 2026] [security2:error] [pid 890219:tid 890411] [client 20.52.125.110:8643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuXloJkCYmL5o6vh9JqmgAAAMI"]
[Thu Jul 30 13:27:34.691319 2026] [security2:error] [pid 890219:tid 890367] [client 20.171.55.167:11465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuXloJkCYmL5o6vh9JqowAAAJY"]
[Thu Jul 30 13:27:34.740241 2026] [security2:error] [pid 890219:tid 890358] [client 172.236.9.101:17842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXloJkCYmL5o6vh9JqmwAAAI0"]
[Thu Jul 30 13:27:34.761055 2026] [security2:error] [pid 890219:tid 890353] [client 20.52.125.110:9218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuXloJkCYmL5o6vh9JqpwAAAIg"]
[Thu Jul 30 13:27:35.049007 2026] [security2:error] [pid 890219:tid 890405] [client 20.91.199.21:4803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuXl4JkCYmL5o6vh9JqqAAAALw"]
[Thu Jul 30 13:27:35.151670 2026] [security2:error] [pid 890219:tid 890355] [client 20.91.199.21:10306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/Geforce.php"] [unique_id "amuXl4JkCYmL5o6vh9JqrQAAAIo"]
[Thu Jul 30 13:27:35.375695 2026] [security2:error] [pid 890219:tid 890400] [client 20.52.125.110:9273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuXl4JkCYmL5o6vh9JqtgAAALc"]
[Thu Jul 30 13:27:35.453317 2026] [security2:error] [pid 890219:tid 890383] [client 20.171.55.167:4464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/updraft/about.php"] [unique_id "amuXl4JkCYmL5o6vh9JquQAAAKY"]
[Thu Jul 30 13:27:35.721839 2026] [security2:error] [pid 890219:tid 890380] [client 172.236.9.101:44178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXl4JkCYmL5o6vh9JqsAAAAKM"]
[Thu Jul 30 13:27:35.943845 2026] [security2:error] [pid 890219:tid 890424] [client 20.52.125.110:9268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuXl4JkCYmL5o6vh9JqwwAAAM8"]
[Thu Jul 30 13:27:35.966819 2026] [security2:error] [pid 890219:tid 890415] [client 20.91.199.21:8812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/alfa-rex.php7"] [unique_id "amuXl4JkCYmL5o6vh9JqxAAAAMY"]
[Thu Jul 30 13:27:36.184911 2026] [security2:error] [pid 890219:tid 890450] [client 20.171.55.167:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuXmIJkCYmL5o6vh9JqzgAAAOk"]
[Thu Jul 30 13:27:36.643507 2026] [security2:error] [pid 890219:tid 890476] [client 20.52.125.110:9253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuXmIJkCYmL5o6vh9Jq1gAAAQM"]
[Thu Jul 30 13:27:36.725608 2026] [security2:error] [pid 890219:tid 890351] [client 172.236.9.101:4687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXmIJkCYmL5o6vh9JqzwAAAIY"]
[Thu Jul 30 13:27:36.841905 2026] [security2:error] [pid 890219:tid 890411] [client 20.91.199.21:12831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/alfanew.php"] [unique_id "amuXmIJkCYmL5o6vh9Jq3QAAAMI"]
[Thu Jul 30 13:27:36.894122 2026] [security2:error] [pid 890219:tid 890363] [client 20.171.55.167:11475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/themes/about.php"] [unique_id "amuXmIJkCYmL5o6vh9Jq4QAAAJI"]
[Thu Jul 30 13:27:37.247343 2026] [security2:error] [pid 890219:tid 890365] [client 20.91.199.21:44015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/a4.php"] [unique_id "amuXmYJkCYmL5o6vh9Jq5gAAAJQ"]
[Thu Jul 30 13:27:37.268031 2026] [security2:error] [pid 890219:tid 890425] [client 20.52.125.110:9263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuXmYJkCYmL5o6vh9Jq6gAAANA"]
[Thu Jul 30 13:27:37.630200 2026] [security2:error] [pid 890219:tid 890350] [client 20.171.55.167:11518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/includes/about.php"] [unique_id "amuXmYJkCYmL5o6vh9Jq9AAAAIU"]
[Thu Jul 30 13:27:37.775944 2026] [security2:error] [pid 890219:tid 890405] [client 172.236.9.101:30427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXmYJkCYmL5o6vh9Jq6wAAALw"]
[Thu Jul 30 13:27:37.816545 2026] [security2:error] [pid 890219:tid 890434] [client 20.52.125.110:9246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuXmYJkCYmL5o6vh9Jq_AAAANk"]
[Thu Jul 30 13:27:38.072148 2026] [core:notice] [pid 890219:tid 890380] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:38.251569 2026] [security2:error] [pid 890219:tid 890226] [remote 57.141.0.38:33392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/613058497/feed/rss2/"] [unique_id "amuXmoJkCYmL5o6vh9JrBQAA2wU"]
[Thu Jul 30 13:27:38.343295 2026] [security2:error] [pid 890219:tid 890460] [client 20.171.55.167:11502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/images/about.php"] [unique_id "amuXmoJkCYmL5o6vh9JrCAAAAPM"]
[Thu Jul 30 13:27:38.487310 2026] [security2:error] [pid 890219:tid 890409] [client 20.52.125.110:9270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuXmoJkCYmL5o6vh9JrDgAAAMA"]
[Thu Jul 30 13:27:38.754266 2026] [security2:error] [pid 890219:tid 890422] [client 172.236.9.101:62561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXmoJkCYmL5o6vh9JrBgAAAM0"]
[Thu Jul 30 13:27:38.768865 2026] [security2:error] [pid 890219:tid 890441] [client 185.156.175.51:60850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuXmoJkCYmL5o6vh9JrEAAAAOA"]
[Thu Jul 30 13:27:38.768967 2026] [security2:error] [pid 890219:tid 890441] [client 185.156.175.51:60850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuXmoJkCYmL5o6vh9JrEAAAAOA"]
[Thu Jul 30 13:27:38.865300 2026] [security2:error] [pid 890219:tid 890427] [client 20.91.199.21:43911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/accueil.php"] [unique_id "amuXmoJkCYmL5o6vh9JrFAAAANI"]
[Thu Jul 30 13:27:39.057871 2026] [security2:error] [pid 890219:tid 890453] [client 20.171.55.167:4473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuXm4JkCYmL5o6vh9JrGwAAAOw"]
[Thu Jul 30 13:27:39.098592 2026] [security2:error] [pid 890219:tid 890359] [client 20.52.125.110:9239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuXm4JkCYmL5o6vh9JrHAAAAI4"]
[Thu Jul 30 13:27:39.203100 2026] [security2:error] [pid 890219:tid 890375] [client 179.64.21.229:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXm4JkCYmL5o6vh9JrHQAAAJ4"]
[Thu Jul 30 13:27:39.210927 2026] [security2:error] [pid 890219:tid 890375] [client 179.64.21.229:58929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXm4JkCYmL5o6vh9JrHQAAAJ4"]
[Thu Jul 30 13:27:39.645418 2026] [security2:error] [pid 890219:tid 890374] [client 20.52.125.110:8814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuXm4JkCYmL5o6vh9JrKwAAAJ0"]
[Thu Jul 30 13:27:39.748400 2026] [security2:error] [pid 890219:tid 890386] [client 172.236.9.101:43458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXm4JkCYmL5o6vh9JrHgAAAKk"]
[Thu Jul 30 13:27:39.764865 2026] [security2:error] [pid 890219:tid 890462] [client 20.171.55.167:4591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/images/about.php"] [unique_id "amuXm4JkCYmL5o6vh9JrLAAAAPU"]
[Thu Jul 30 13:27:39.906237 2026] [proxy:error] [pid 890219:tid 890402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:27:39.906287 2026] [proxy_http:error] [pid 890219:tid 890402] [client 44.216.125.112:56086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:27:39.906934 2026] [proxy:error] [pid 890219:tid 890402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:27:39.907004 2026] [proxy_http:error] [pid 890219:tid 890402] [client 44.216.125.112:56086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:27:39.922044 2026] [proxy:error] [pid 890219:tid 890447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:27:39.922111 2026] [proxy_http:error] [pid 890219:tid 890447] [client 18.211.55.47:44793] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:27:39.922705 2026] [proxy:error] [pid 890219:tid 890447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:27:39.922753 2026] [proxy_http:error] [pid 890219:tid 890447] [client 18.211.55.47:44793] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:27:40.189375 2026] [security2:error] [pid 890219:tid 890436] [client 20.52.125.110:8796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuXnIJkCYmL5o6vh9JrRwAAANs"]
[Thu Jul 30 13:27:40.473423 2026] [security2:error] [pid 890219:tid 890393] [client 20.171.55.167:11494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/about.php"] [unique_id "amuXnIJkCYmL5o6vh9JrUAAAALA"]
[Thu Jul 30 13:27:40.704552 2026] [security2:error] [pid 890219:tid 890464] [client 20.52.125.110:9234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuXnIJkCYmL5o6vh9JrVAAAAPc"]
[Thu Jul 30 13:27:40.727696 2026] [security2:error] [pid 890219:tid 890366] [client 172.236.9.101:61424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXnIJkCYmL5o6vh9JrSAAAAJU"]
[Thu Jul 30 13:27:41.196430 2026] [security2:error] [pid 890219:tid 890394] [client 20.171.55.167:11509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/about.php"] [unique_id "amuXnYJkCYmL5o6vh9JrYwAAALE"]
[Thu Jul 30 13:27:41.227434 2026] [security2:error] [pid 890219:tid 890422] [client 20.91.199.21:43935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/dashboard.php"] [unique_id "amuXnYJkCYmL5o6vh9JrZAAAAM0"]
[Thu Jul 30 13:27:41.286471 2026] [security2:error] [pid 890219:tid 890444] [client 20.52.125.110:9256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuXnYJkCYmL5o6vh9JrZQAAAOM"]
[Thu Jul 30 13:27:41.439573 2026] [security2:error] [pid 890219:tid 890378] [client 20.91.199.21:21020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuXnYJkCYmL5o6vh9JrbAAAAKE"]
[Thu Jul 30 13:27:41.549045 2026] [security2:error] [pid 890219:tid 890242] [remote 5.161.62.209:56770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.arabiandubaisafari.com"] [uri "/.env"] [unique_id "amuXnYJkCYmL5o6vh9JrcAAAuxU"]
[Thu Jul 30 13:27:41.566642 2026] [security2:error] [pid 890219:tid 890235] [remote 5.161.62.209:56786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.arabiandubaisafari.com.khw.nyx.temporary.site"] [uri "/.env"] [unique_id "amuXnYJkCYmL5o6vh9JrcQAA5g4"]
[Thu Jul 30 13:27:41.772096 2026] [security2:error] [pid 890219:tid 890367] [client 172.236.9.101:3173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXnYJkCYmL5o6vh9JrZgAAAJY"]
[Thu Jul 30 13:27:41.854329 2026] [security2:error] [pid 890219:tid 890452] [client 20.52.125.110:8797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuXnYJkCYmL5o6vh9JrdgAAAOs"]
[Thu Jul 30 13:27:41.984258 2026] [core:notice] [pid 890219:tid 890448] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:42.229919 2026] [security2:error] [pid 890219:tid 890449] [client 216.73.216.131:45901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mgr3.com"] [uri "/index.php"] [unique_id "amuXnoJkCYmL5o6vh9JrggAA6Co"]
[Thu Jul 30 13:27:42.270725 2026] [security2:error] [pid 890219:tid 890266] [remote 5.161.62.209:56812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.arabiantourz.com.khw.nyx.temporary.site"] [uri "/.env"] [unique_id "amuXnoJkCYmL5o6vh9JrhAAAoC0"]
[Thu Jul 30 13:27:42.277776 2026] [security2:error] [pid 890219:tid 890268] [remote 5.161.62.209:56800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.arabiantourz.com"] [uri "/.env"] [unique_id "amuXnoJkCYmL5o6vh9JrhgAAsC8"]
[Thu Jul 30 13:27:42.324057 2026] [security2:error] [pid 890219:tid 890429] [client 20.171.55.167:11507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/gallery/about.php"] [unique_id "amuXnoJkCYmL5o6vh9JrhwAAANQ"]
[Thu Jul 30 13:27:42.529672 2026] [security2:error] [pid 890219:tid 890445] [client 20.52.125.110:8769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuXnoJkCYmL5o6vh9JriwAAAOQ"]
[Thu Jul 30 13:27:42.637419 2026] [security2:error] [pid 890219:tid 890264] [remote 162.62.213.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuXnoJkCYmL5o6vh9JrgwAA-is"]
[Thu Jul 30 13:27:42.728301 2026] [security2:error] [pid 890219:tid 890357] [client 20.91.199.21:12818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuXnoJkCYmL5o6vh9JrkwAAAIw"]
[Thu Jul 30 13:27:42.756305 2026] [security2:error] [pid 890219:tid 890370] [client 172.236.9.101:44071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXnoJkCYmL5o6vh9JrhQAAAJk"]
[Thu Jul 30 13:27:43.101311 2026] [security2:error] [pid 890219:tid 890473] [client 20.171.55.167:11457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuXn4JkCYmL5o6vh9JrngAAAQA"]
[Thu Jul 30 13:27:43.232564 2026] [security2:error] [pid 890219:tid 890408] [client 20.52.125.110:9216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuXn4JkCYmL5o6vh9JrogAAAL8"]
[Thu Jul 30 13:27:43.597962 2026] [security2:error] [pid 890219:tid 890353] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXnoJkCYmL5o6vh9JrlAAAiAY"]
[Thu Jul 30 13:27:43.741005 2026] [security2:error] [pid 890219:tid 890420] [client 172.236.9.101:2462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXn4JkCYmL5o6vh9JrpgAAAMs"]
[Thu Jul 30 13:27:43.795021 2026] [security2:error] [pid 890219:tid 890379] [client 20.52.125.110:9259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuXn4JkCYmL5o6vh9JrsQAAAKI"]
[Thu Jul 30 13:27:43.812483 2026] [security2:error] [pid 890219:tid 890426] [client 20.171.55.167:11514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/about.php"] [unique_id "amuXn4JkCYmL5o6vh9JrsgAAANE"]
[Thu Jul 30 13:27:44.385884 2026] [security2:error] [pid 890219:tid 890435] [client 20.52.125.110:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuXoIJkCYmL5o6vh9JrwwAAANo"]
[Thu Jul 30 13:27:44.414135 2026] [core:notice] [pid 890219:tid 890284] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:44.529794 2026] [proxy:error] [pid 890219:tid 890366] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:27:44.529854 2026] [proxy_http:error] [pid 890219:tid 890366] [client 34.224.175.62:62019] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:27:44.530423 2026] [proxy:error] [pid 890219:tid 890366] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:27:44.530475 2026] [proxy_http:error] [pid 890219:tid 890366] [client 34.224.175.62:62019] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:27:44.535939 2026] [proxy:error] [pid 890219:tid 890465] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:27:44.536019 2026] [proxy_http:error] [pid 890219:tid 890465] [client 32.194.121.99:63822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:27:44.536589 2026] [proxy:error] [pid 890219:tid 890465] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:27:44.536632 2026] [proxy_http:error] [pid 890219:tid 890465] [client 32.194.121.99:63822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:27:44.554189 2026] [security2:error] [pid 890219:tid 890451] [client 20.171.55.167:11495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/images/about.php"] [unique_id "amuXoIJkCYmL5o6vh9Jr1AAAAOo"]
[Thu Jul 30 13:27:44.696077 2026] [security2:error] [pid 890219:tid 890471] [client 20.91.199.21:40394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/radio.php"] [unique_id "amuXoIJkCYmL5o6vh9Jr3QAAAP4"]
[Thu Jul 30 13:27:44.755031 2026] [security2:error] [pid 890219:tid 890417] [client 172.236.9.101:35938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXoIJkCYmL5o6vh9JrvgAAAMg"]
[Thu Jul 30 13:27:45.039712 2026] [security2:error] [pid 890219:tid 890432] [client 20.52.125.110:9245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuXoYJkCYmL5o6vh9Jr4gAAANc"]
[Thu Jul 30 13:27:45.263099 2026] [security2:error] [pid 890219:tid 890474] [client 20.171.55.167:11466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuXoYJkCYmL5o6vh9Jr7QAAAQE"]
[Thu Jul 30 13:27:45.639966 2026] [security2:error] [pid 890219:tid 890383] [client 20.52.125.110:9258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuXoYJkCYmL5o6vh9Jr8wAAAKY"]
[Thu Jul 30 13:27:45.641305 2026] [security2:error] [pid 890219:tid 890438] [client 74.7.228.51:40700] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ull.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuXoIJkCYmL5o6vh9JrwgAA3TA"]
[Thu Jul 30 13:27:45.812634 2026] [security2:error] [pid 890219:tid 890447] [client 172.236.9.101:55593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXoYJkCYmL5o6vh9Jr7gAAAOY"]
[Thu Jul 30 13:27:46.006540 2026] [security2:error] [pid 890219:tid 890439] [client 20.171.55.167:11493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuXooJkCYmL5o6vh9JsAQAAAN4"]
[Thu Jul 30 13:27:46.209961 2026] [security2:error] [pid 890219:tid 890429] [client 20.52.125.110:9224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuXooJkCYmL5o6vh9JsBQAAANQ"]
[Thu Jul 30 13:27:46.708802 2026] [security2:error] [pid 890219:tid 890465] [client 172.236.9.101:33685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXooJkCYmL5o6vh9JsBwAAAPg"]
[Thu Jul 30 13:27:46.717280 2026] [security2:error] [pid 890219:tid 890444] [client 20.171.55.167:11458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuXooJkCYmL5o6vh9JsGgAAAOM"]
[Thu Jul 30 13:27:46.747784 2026] [security2:error] [pid 890219:tid 890394] [client 20.52.125.110:8810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuXooJkCYmL5o6vh9JsGwAAALE"]
[Thu Jul 30 13:27:46.852229 2026] [security2:error] [pid 890219:tid 890403] [client 20.91.199.21:33875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/wpsml-sys.php"] [unique_id "amuXooJkCYmL5o6vh9JsIwAAALo"]
[Thu Jul 30 13:27:47.319291 2026] [security2:error] [pid 890219:tid 890353] [client 20.52.125.110:8790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuXo4JkCYmL5o6vh9JsOQAAAIg"]
[Thu Jul 30 13:27:47.458788 2026] [security2:error] [pid 890219:tid 890419] [client 20.171.55.167:11477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cloud.php"] [unique_id "amuXo4JkCYmL5o6vh9JsPQAAAMo"]
[Thu Jul 30 13:27:47.774314 2026] [security2:error] [pid 890219:tid 890445] [client 172.236.9.101:12574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXo4JkCYmL5o6vh9JsOAAAAOQ"]
[Thu Jul 30 13:27:47.963087 2026] [security2:error] [pid 890219:tid 890360] [client 20.52.125.110:8789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuXo4JkCYmL5o6vh9JsSQAAAI8"]
[Thu Jul 30 13:27:48.172723 2026] [security2:error] [pid 890219:tid 890375] [client 20.171.55.167:11487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/cloud.php"] [unique_id "amuXpIJkCYmL5o6vh9JsSwAAAJ4"]
[Thu Jul 30 13:27:48.244692 2026] [security2:error] [pid 890219:tid 890475] [client 134.19.179.131:35162] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuXo4JkCYmL5o6vh9JsSgAAAQI"]
[Thu Jul 30 13:27:48.244815 2026] [security2:error] [pid 890219:tid 890475] [client 134.19.179.131:35162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuXo4JkCYmL5o6vh9JsSgAAAQI"]
[Thu Jul 30 13:27:48.380157 2026] [security2:error] [pid 890219:tid 890314] [remote 57.141.0.19:31572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuXpIJkCYmL5o6vh9JsVQAA110"]
[Thu Jul 30 13:27:48.463794 2026] [security2:error] [pid 890219:tid 890465] [client 20.52.125.110:9274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuXpIJkCYmL5o6vh9JsWAAAAPg"]
[Thu Jul 30 13:27:48.541730 2026] [core:notice] [pid 890219:tid 890377] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:48.700781 2026] [security2:error] [pid 890219:tid 890356] [client 20.91.199.21:38480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/02.php"] [unique_id "amuXpIJkCYmL5o6vh9JsWwAAAIs"]
[Thu Jul 30 13:27:48.731271 2026] [security2:error] [pid 890219:tid 890417] [client 172.236.9.101:60435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXpIJkCYmL5o6vh9JsTAAAAMg"]
[Thu Jul 30 13:27:48.857646 2026] [security2:error] [pid 890219:tid 890436] [client 20.91.199.21:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-p.php7"] [unique_id "amuXpIJkCYmL5o6vh9JsagAAANs"]
[Thu Jul 30 13:27:48.903350 2026] [security2:error] [pid 890219:tid 890457] [client 20.171.55.167:4590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/updates.php"] [unique_id "amuXpIJkCYmL5o6vh9JsbAAAAPA"]
[Thu Jul 30 13:27:48.991044 2026] [security2:error] [pid 890219:tid 890361] [client 20.52.125.110:9266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuXpIJkCYmL5o6vh9JsbwAAAJA"]
[Thu Jul 30 13:27:49.189779 2026] [security2:error] [pid 890219:tid 890320] [remote 57.141.0.63:36444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amuXpYJkCYmL5o6vh9JscQAAxmM"]
[Thu Jul 30 13:27:49.625074 2026] [security2:error] [pid 890219:tid 890467] [client 20.52.125.110:8818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuXpYJkCYmL5o6vh9JsgwAAAPo"]
[Thu Jul 30 13:27:49.638635 2026] [security2:error] [pid 890219:tid 890393] [client 20.171.55.167:4472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/css/cloud.php"] [unique_id "amuXpYJkCYmL5o6vh9JshgAAALA"]
[Thu Jul 30 13:27:49.693915 2026] [core:notice] [pid 890219:tid 890325] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:27:49.725919 2026] [security2:error] [pid 890219:tid 890449] [client 172.236.9.101:44898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXpYJkCYmL5o6vh9JscgAAAOg"]
[Thu Jul 30 13:27:49.762662 2026] [security2:error] [pid 890219:tid 890462] [client 179.64.21.229:30868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXpYJkCYmL5o6vh9JsiQAAAPU"]
[Thu Jul 30 13:27:49.766109 2026] [security2:error] [pid 890219:tid 890462] [client 179.64.21.229:30868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXpYJkCYmL5o6vh9JsiQAAAPU"]
[Thu Jul 30 13:27:50.091798 2026] [security2:error] [pid 890219:tid 890363] [client 20.91.199.21:9921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuXpoJkCYmL5o6vh9JsmgAAAJI"]
[Thu Jul 30 13:27:50.395758 2026] [security2:error] [pid 890219:tid 890377] [client 20.171.55.167:11512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuXpoJkCYmL5o6vh9JsowAAAKA"]
[Thu Jul 30 13:27:50.744042 2026] [security2:error] [pid 890219:tid 890383] [client 172.236.9.101:23280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXpoJkCYmL5o6vh9JsngAAAKY"]
[Thu Jul 30 13:27:51.101249 2026] [security2:error] [pid 890219:tid 890392] [client 20.171.55.167:4228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/img/cloud.php"] [unique_id "amuXp4JkCYmL5o6vh9JsxQAAAK8"]
[Thu Jul 30 13:27:51.768229 2026] [security2:error] [pid 890219:tid 890470] [client 172.236.9.101:36492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXp4JkCYmL5o6vh9JsyAAAAP0"]
[Thu Jul 30 13:27:51.807185 2026] [security2:error] [pid 890219:tid 890370] [client 20.171.55.167:11467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuXp4JkCYmL5o6vh9Js3QAAAJk"]
[Thu Jul 30 13:27:52.071248 2026] [security2:error] [pid 890219:tid 890418] [client 20.91.199.21:38512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/infos.php"] [unique_id "amuXqIJkCYmL5o6vh9Js7AAAAMk"]
[Thu Jul 30 13:27:52.096176 2026] [security2:error] [pid 890219:tid 890346] [remote 217.182.128.41:50294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ldk.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuXqIJkCYmL5o6vh9Js8QAA-30"]
[Thu Jul 30 13:27:52.234414 2026] [security2:error] [pid 890219:tid 890348] [remote 57.141.0.62:54414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55997217192/feed/rss2/"] [unique_id "amuXqIJkCYmL5o6vh9Js9QAA1X8"]
[Thu Jul 30 13:27:52.515397 2026] [security2:error] [pid 890219:tid 890464] [client 20.171.55.167:4732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuXqIJkCYmL5o6vh9JtAAAAAPc"]
[Thu Jul 30 13:27:52.720882 2026] [security2:error] [pid 890219:tid 890389] [client 172.236.9.101:10531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXqIJkCYmL5o6vh9Js9gAAAKw"]
[Thu Jul 30 13:27:52.942729 2026] [security2:error] [pid 890219:tid 890438] [client 68.235.48.108:44902] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuXqIJkCYmL5o6vh9JtCgAAAN0"]
[Thu Jul 30 13:27:52.942859 2026] [security2:error] [pid 890219:tid 890438] [client 68.235.48.108:44902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuXqIJkCYmL5o6vh9JtCgAAAN0"]
[Thu Jul 30 13:27:53.670397 2026] [security2:error] [pid 890219:tid 890360] [client 20.171.55.167:11459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/avaa.php"] [unique_id "amuXqYJkCYmL5o6vh9JtJwAAAI8"]
[Thu Jul 30 13:27:53.792187 2026] [security2:error] [pid 890219:tid 890352] [client 20.91.199.21:7239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuXqYJkCYmL5o6vh9JtKAAAAIc"]
[Thu Jul 30 13:27:53.795720 2026] [security2:error] [pid 890219:tid 890376] [client 172.236.9.101:39335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXqYJkCYmL5o6vh9JtGwAAAJ8"]
[Thu Jul 30 13:27:54.003897 2026] [security2:error] [pid 890219:tid 890441] [client 20.91.199.21:46852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/updates.php"] [unique_id "amuXqoJkCYmL5o6vh9JtLgAAAOA"]
[Thu Jul 30 13:27:54.375377 2026] [security2:error] [pid 890219:tid 890378] [client 20.171.55.167:11491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/images/cloud.php"] [unique_id "amuXqoJkCYmL5o6vh9JtNgAAAKE"]
[Thu Jul 30 13:27:54.762470 2026] [security2:error] [pid 890219:tid 890377] [client 20.91.199.21:41156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-content/repeater.php"] [unique_id "amuXqoJkCYmL5o6vh9JtQwAAAKA"]
[Thu Jul 30 13:27:55.082365 2026] [security2:error] [pid 890219:tid 890419] [client 20.171.55.167:11482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuXq4JkCYmL5o6vh9JtSQAAAMo"]
[Thu Jul 30 13:27:55.156413 2026] [security2:error] [pid 890219:tid 890408] [client 57.141.0.5:23036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuXqoJkCYmL5o6vh9JtRAAAvyM"], referer: https://igetvape-australia.com/product/iget-moon-orange-peel-apple-ice/
[Thu Jul 30 13:27:55.789847 2026] [security2:error] [pid 890219:tid 890447] [client 20.171.55.167:11462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuXq4JkCYmL5o6vh9JtWwAAAOY"]
[Thu Jul 30 13:27:56.297911 2026] [security2:error] [pid 890219:tid 890450] [client 20.91.199.21:38456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/user.php"] [unique_id "amuXrIJkCYmL5o6vh9JtZgAAAOk"]
[Thu Jul 30 13:27:56.497179 2026] [security2:error] [pid 890219:tid 890370] [client 20.171.55.167:4679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuXrIJkCYmL5o6vh9JtZwAAAJk"]
[Thu Jul 30 13:27:57.205354 2026] [security2:error] [pid 890219:tid 890468] [client 20.171.55.167:4432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuXrYJkCYmL5o6vh9JtfgAAAPs"]
[Thu Jul 30 13:27:57.246897 2026] [security2:error] [pid 890219:tid 890412] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXrIJkCYmL5o6vh9JtbwAAAMM"]
[Thu Jul 30 13:27:57.486657 2026] [security2:error] [pid 890219:tid 890456] [client 172.237.109.114:3113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuXrYJkCYmL5o6vh9JtdwAAAO8"]
[Thu Jul 30 13:27:57.943471 2026] [security2:error] [pid 890219:tid 890446] [client 20.171.55.167:4460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuXrYJkCYmL5o6vh9JtjAAAAOU"]
[Thu Jul 30 13:27:58.678430 2026] [security2:error] [pid 890219:tid 890476] [client 20.171.55.167:4580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/cloud.php"] [unique_id "amuXroJkCYmL5o6vh9JtmQAAAQM"]
[Thu Jul 30 13:27:58.868487 2026] [security2:error] [pid 890219:tid 890384] [client 74.7.241.130:50040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "k2k.tech"] [uri "/robots.txt"] [unique_id "amuXroJkCYmL5o6vh9JtowAAAKc"]
[Thu Jul 30 13:27:59.016342 2026] [security2:error] [pid 890219:tid 890222] [remote 74.7.243.224:40802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/no-sidebar-full-width/js/css/img/js/uploads/content/uploads/content/uploads/content/article.php"] [unique_id "amuXr4JkCYmL5o6vh9JtpgAA9QE"], referer: https://aded-rdc.org/no-sidebar-full-width/js/css/img/js/uploads/content/uploads/content/uploads/content/1784122425_Physioth%C3%A9rapie%20%C3%A0%20Domicile.jpg
[Thu Jul 30 13:27:59.030643 2026] [security2:error] [pid 890219:tid 890429] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXroJkCYmL5o6vh9JtmAAAANQ"]
[Thu Jul 30 13:27:59.381926 2026] [security2:error] [pid 890219:tid 890470] [client 20.171.55.167:4693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/updates.php"] [unique_id "amuXr4JkCYmL5o6vh9JtsQAAAP0"]
[Thu Jul 30 13:27:59.729319 2026] [security2:error] [pid 890219:tid 890394] [client 20.91.199.21:33713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/admin-ajax.php"] [unique_id "amuXr4JkCYmL5o6vh9JttgAAALE"]
[Thu Jul 30 13:28:00.118072 2026] [security2:error] [pid 890219:tid 890391] [client 20.171.55.167:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/libraries/legacy/updates.php"] [unique_id "amuXsIJkCYmL5o6vh9JtvQAAAK4"]
[Thu Jul 30 13:28:00.454817 2026] [security2:error] [pid 890219:tid 890412] [client 179.64.21.229:41515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXsIJkCYmL5o6vh9JtxwAAAMM"]
[Thu Jul 30 13:28:00.466473 2026] [security2:error] [pid 890219:tid 890412] [client 179.64.21.229:41515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXsIJkCYmL5o6vh9JtxwAAAMM"]
[Thu Jul 30 13:28:00.826041 2026] [security2:error] [pid 890219:tid 890431] [client 20.171.55.167:11484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuXsIJkCYmL5o6vh9Jt0QAAANY"]
[Thu Jul 30 13:28:00.963826 2026] [security2:error] [pid 890219:tid 890419] [client 20.91.199.21:36747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/alfa.php"] [unique_id "amuXsIJkCYmL5o6vh9Jt1gAAAMo"]
[Thu Jul 30 13:28:01.557806 2026] [security2:error] [pid 890219:tid 890380] [client 20.171.55.167:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/libraries/vendor/updates.php"] [unique_id "amuXsYJkCYmL5o6vh9Jt4gAAAKM"]
[Thu Jul 30 13:28:02.267099 2026] [security2:error] [pid 890219:tid 890416] [client 20.171.55.167:4448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/alfa-rex.php7"] [unique_id "amuXsoJkCYmL5o6vh9Jt9QAAAMc"]
[Thu Jul 30 13:28:02.288706 2026] [security2:error] [pid 890219:tid 890414] [client 127.0.0.1:49718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuXsoJkCYmL5o6vh9Jt9AAAAMU"]
[Thu Jul 30 13:28:02.288752 2026] [security2:error] [pid 890219:tid 890395] [client 127.0.0.1:49702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.pna.djb.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuXsoJkCYmL5o6vh9Jt8wAAALI"]
[Thu Jul 30 13:28:02.288884 2026] [security2:error] [pid 890219:tid 890421] [client 74.7.241.185:43000] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.pna.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuXsoJkCYmL5o6vh9Jt8gAAzEw"]
[Thu Jul 30 13:28:02.325720 2026] [core:notice] [pid 890219:tid 890288] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:02.415624 2026] [security2:error] [pid 890219:tid 890244] [remote 198.244.240.79:16960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fiyan.co"] [uri "/robots.txt"] [unique_id "amuXsoJkCYmL5o6vh9Jt-gAAlxc"]
[Thu Jul 30 13:28:02.415787 2026] [security2:error] [pid 890219:tid 890368] [client 198.244.240.79:16960] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fiyan.co"] [uri "/robots.txt"] [unique_id "amuXsoJkCYmL5o6vh9Jt-gAAlxc"]
[Thu Jul 30 13:28:02.971879 2026] [security2:error] [pid 890219:tid 890430] [client 20.171.55.167:4701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/alfanew.php"] [unique_id "amuXsoJkCYmL5o6vh9JuBwAAANU"]
[Thu Jul 30 13:28:03.135636 2026] [core:notice] [pid 890219:tid 890304] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:03.281277 2026] [security2:error] [pid 890219:tid 890455] [client 43.130.139.136:39610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.139.130.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/wp-comments-post.php"] [unique_id "amuXs4JkCYmL5o6vh9JuDwAAAO4"]
[Thu Jul 30 13:28:03.353705 2026] [core:notice] [pid 890219:tid 890415] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:03.689894 2026] [security2:error] [pid 890219:tid 890413] [client 20.171.55.167:11456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuXs4JkCYmL5o6vh9JuHAAAAMQ"]
[Thu Jul 30 13:28:04.398089 2026] [security2:error] [pid 890219:tid 890401] [client 20.171.55.167:4702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuXtIJkCYmL5o6vh9JuKgAAALg"]
[Thu Jul 30 13:28:04.980292 2026] [security2:error] [pid 890219:tid 890309] [remote 198.244.183.225:57724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fiyan.co"] [uri "/"] [unique_id "amuXtIJkCYmL5o6vh9JuNQAAk1g"]
[Thu Jul 30 13:28:04.980462 2026] [security2:error] [pid 890219:tid 890364] [client 198.244.183.225:57724] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fiyan.co"] [uri "/"] [unique_id "amuXtIJkCYmL5o6vh9JuNQAAk1g"]
[Thu Jul 30 13:28:05.139860 2026] [security2:error] [pid 890219:tid 890434] [client 20.171.55.167:11510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-p.php7"] [unique_id "amuXtYJkCYmL5o6vh9JuPgAAANk"]
[Thu Jul 30 13:28:05.295946 2026] [security2:error] [pid 890219:tid 890468] [client 20.52.125.110:11988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/011i.php"] [unique_id "amuXtYJkCYmL5o6vh9JuRQAAAPs"]
[Thu Jul 30 13:28:05.689231 2026] [security2:error] [pid 890219:tid 890412] [client 20.52.125.110:11983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/03a005685d.php"] [unique_id "amuXtYJkCYmL5o6vh9JuUQAAAMM"]
[Thu Jul 30 13:28:05.865780 2026] [security2:error] [pid 890219:tid 890402] [client 20.171.55.167:4561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/repeater.php"] [unique_id "amuXtYJkCYmL5o6vh9JuVQAAALk"]
[Thu Jul 30 13:28:06.080524 2026] [security2:error] [pid 890219:tid 890399] [client 20.52.125.110:11997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/403.php"] [unique_id "amuXtoJkCYmL5o6vh9JuXQAAALY"]
[Thu Jul 30 13:28:06.474318 2026] [security2:error] [pid 890219:tid 890409] [client 20.52.125.110:11992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/404.php"] [unique_id "amuXtoJkCYmL5o6vh9JubwAAAMA"]
[Thu Jul 30 13:28:06.569459 2026] [security2:error] [pid 890219:tid 890382] [client 20.171.55.167:11481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-includes/repeater.php"] [unique_id "amuXtoJkCYmL5o6vh9JucwAAAKU"]
[Thu Jul 30 13:28:06.868400 2026] [security2:error] [pid 890219:tid 890403] [client 20.52.125.110:11974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/aa.php"] [unique_id "amuXtoJkCYmL5o6vh9JuiwAAALo"]
[Thu Jul 30 13:28:07.271850 2026] [security2:error] [pid 890219:tid 890433] [client 20.52.125.110:11266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/aafewc0k.php"] [unique_id "amuXt4JkCYmL5o6vh9JungAAANg"]
[Thu Jul 30 13:28:07.275025 2026] [security2:error] [pid 890219:tid 890399] [client 20.171.55.167:4282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/repeater.php"] [unique_id "amuXt4JkCYmL5o6vh9JunwAAALY"]
[Thu Jul 30 13:28:07.665918 2026] [security2:error] [pid 890219:tid 890450] [client 20.52.125.110:12002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/abcd.php"] [unique_id "amuXt4JkCYmL5o6vh9JupQAAAOk"]
[Thu Jul 30 13:28:07.984455 2026] [security2:error] [pid 890219:tid 890449] [client 20.171.55.167:4435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wsoyanz.php"] [unique_id "amuXt4JkCYmL5o6vh9JutAAAAOg"]
[Thu Jul 30 13:28:08.061509 2026] [security2:error] [pid 890219:tid 890466] [client 20.52.125.110:12024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/about.php"] [unique_id "amuXuIJkCYmL5o6vh9JuuwAAAPk"]
[Thu Jul 30 13:28:08.469107 2026] [security2:error] [pid 890219:tid 890405] [client 20.52.125.110:12007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/admin.php"] [unique_id "amuXuIJkCYmL5o6vh9JuygAAALw"]
[Thu Jul 30 13:28:08.689388 2026] [security2:error] [pid 890219:tid 890357] [client 20.171.55.167:4735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/yanz.php"] [unique_id "amuXuIJkCYmL5o6vh9Ju1AAAAIw"]
[Thu Jul 30 13:28:08.891148 2026] [security2:error] [pid 890219:tid 890384] [client 20.52.125.110:11279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/adminfuns.php"] [unique_id "amuXuIJkCYmL5o6vh9Ju4gAAAKc"]
[Thu Jul 30 13:28:09.293321 2026] [security2:error] [pid 890219:tid 890397] [client 20.52.125.110:12022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/albin.php"] [unique_id "amuXuYJkCYmL5o6vh9Ju7gAAALQ"]
[Thu Jul 30 13:28:09.404645 2026] [security2:error] [pid 890219:tid 890410] [client 20.91.199.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cnpinyin.com"] [uri "/index.php"] [unique_id "amuXuYJkCYmL5o6vh9Ju7QAAAME"]
[Thu Jul 30 13:28:09.556392 2026] [security2:error] [pid 890219:tid 890383] [client 20.91.199.21:38414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/hehe.php"] [unique_id "amuXuYJkCYmL5o6vh9Ju-gAAAKY"]
[Thu Jul 30 13:28:09.685297 2026] [security2:error] [pid 890219:tid 890415] [client 20.52.125.110:11982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/amfsqvgv.php"] [unique_id "amuXuYJkCYmL5o6vh9Ju-wAAAMY"]
[Thu Jul 30 13:28:09.779952 2026] [security2:error] [pid 890219:tid 890359] [client 20.171.55.167:4720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "amuXuYJkCYmL5o6vh9Ju_wAAAI4"]
[Thu Jul 30 13:28:10.083265 2026] [security2:error] [pid 890219:tid 890451] [client 20.52.125.110:11998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/ant.php"] [unique_id "amuXuoJkCYmL5o6vh9JvCgAAAOo"]
[Thu Jul 30 13:28:10.478842 2026] [security2:error] [pid 890219:tid 890444] [client 20.52.125.110:12014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/appreciators.php"] [unique_id "amuXuoJkCYmL5o6vh9JvFAAAAOM"]
[Thu Jul 30 13:28:10.503061 2026] [security2:error] [pid 890219:tid 890461] [client 20.171.55.167:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "amuXuoJkCYmL5o6vh9JvFQAAAPQ"]
[Thu Jul 30 13:28:10.878879 2026] [security2:error] [pid 890219:tid 890355] [client 20.52.125.110:12028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/archive.php"] [unique_id "amuXuoJkCYmL5o6vh9JvHAAAAIo"]
[Thu Jul 30 13:28:11.004383 2026] [security2:error] [pid 890219:tid 890378] [client 179.64.21.229:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXu4JkCYmL5o6vh9JvIwAAAKE"]
[Thu Jul 30 13:28:11.008627 2026] [security2:error] [pid 890219:tid 890378] [client 179.64.21.229:50620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXu4JkCYmL5o6vh9JvIwAAAKE"]
[Thu Jul 30 13:28:11.133894 2026] [proxy:error] [pid 890219:tid 890372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:11.133991 2026] [proxy_http:error] [pid 890219:tid 890372] [client 143.244.57.82:44212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:11.134643 2026] [proxy:error] [pid 890219:tid 890372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:11.134689 2026] [proxy_http:error] [pid 890219:tid 890372] [client 143.244.57.82:44212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:11.250534 2026] [security2:error] [pid 890219:tid 890396] [client 20.171.55.167:11476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cache-compat.php"] [unique_id "amuXu4JkCYmL5o6vh9JvKAAAALM"]
[Thu Jul 30 13:28:11.273556 2026] [security2:error] [pid 890219:tid 890426] [client 20.52.125.110:11969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/as.php"] [unique_id "amuXu4JkCYmL5o6vh9JvKQAAANE"]
[Thu Jul 30 13:28:11.369369 2026] [security2:error] [pid 890219:tid 890416] [client 20.91.199.21:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/rk2.php"] [unique_id "amuXu4JkCYmL5o6vh9JvKgAAAMc"]
[Thu Jul 30 13:28:11.422039 2026] [proxy:error] [pid 890219:tid 890457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:11.422107 2026] [proxy_http:error] [pid 890219:tid 890457] [client 143.244.57.82:44222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:11.422702 2026] [proxy:error] [pid 890219:tid 890457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:11.422745 2026] [proxy_http:error] [pid 890219:tid 890457] [client 143.244.57.82:44222] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:11.675719 2026] [security2:error] [pid 890219:tid 890445] [client 20.52.125.110:11272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/atomlib.php"] [unique_id "amuXu4JkCYmL5o6vh9JvQgAAAOQ"]
[Thu Jul 30 13:28:11.718646 2026] [security2:error] [pid 890219:tid 890393] [client 143.244.57.82:44228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuXu4JkCYmL5o6vh9JvQwAAALA"]
[Thu Jul 30 13:28:11.728932 2026] [security2:error] [pid 890219:tid 890418] [client 4.232.188.49:59456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuXu4JkCYmL5o6vh9JvRAAAAMk"]
[Thu Jul 30 13:28:11.729050 2026] [security2:error] [pid 890219:tid 890418] [client 4.232.188.49:59456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuXu4JkCYmL5o6vh9JvRAAAAMk"]
[Thu Jul 30 13:28:11.977804 2026] [security2:error] [pid 890219:tid 890375] [client 20.171.55.167:11508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/ajax-actions.php"] [unique_id "amuXu4JkCYmL5o6vh9JvSQAAAJ4"]
[Thu Jul 30 13:28:12.005545 2026] [security2:error] [pid 890219:tid 890429] [client 143.244.57.82:44242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuXu4JkCYmL5o6vh9JvTQAAANQ"]
[Thu Jul 30 13:28:12.010592 2026] [security2:error] [pid 890219:tid 890395] [client 4.232.188.49:38819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuXvIJkCYmL5o6vh9JvTgAAALI"]
[Thu Jul 30 13:28:12.010680 2026] [security2:error] [pid 890219:tid 890395] [client 4.232.188.49:38819] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuXvIJkCYmL5o6vh9JvTgAAALI"]
[Thu Jul 30 13:28:12.072173 2026] [security2:error] [pid 890219:tid 890462] [client 20.52.125.110:11999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/autoload_classmap.php"] [unique_id "amuXvIJkCYmL5o6vh9JvUgAAAPU"]
[Thu Jul 30 13:28:12.289929 2026] [security2:error] [pid 890219:tid 890432] [client 4.232.188.49:38797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/x.php"] [unique_id "amuXvIJkCYmL5o6vh9JvVgAAANc"]
[Thu Jul 30 13:28:12.290104 2026] [security2:error] [pid 890219:tid 890432] [client 4.232.188.49:38797] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/x.php"] [unique_id "amuXvIJkCYmL5o6vh9JvVgAAANc"]
[Thu Jul 30 13:28:12.300711 2026] [proxy:error] [pid 890219:tid 890448] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:12.300794 2026] [proxy_http:error] [pid 890219:tid 890448] [client 143.244.57.82:44246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:12.301367 2026] [proxy:error] [pid 890219:tid 890448] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:12.301412 2026] [proxy_http:error] [pid 890219:tid 890448] [client 143.244.57.82:44246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:12.433384 2026] [security2:error] [pid 890219:tid 890443] [client 20.91.199.21:10878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/setup-config.php"] [unique_id "amuXvIJkCYmL5o6vh9JvWwAAAOI"]
[Thu Jul 30 13:28:12.471502 2026] [security2:error] [pid 890219:tid 890358] [client 20.52.125.110:12030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/bb.php"] [unique_id "amuXvIJkCYmL5o6vh9JvXQAAAI0"]
[Thu Jul 30 13:28:12.578516 2026] [security2:error] [pid 890219:tid 890396] [client 143.244.57.82:44252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuXvIJkCYmL5o6vh9JvZQAAALM"]
[Thu Jul 30 13:28:12.603999 2026] [security2:error] [pid 890219:tid 890426] [client 4.232.188.49:59466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/mgrr.php"] [unique_id "amuXvIJkCYmL5o6vh9JvZgAAANE"]
[Thu Jul 30 13:28:12.604084 2026] [security2:error] [pid 890219:tid 890426] [client 4.232.188.49:59466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/mgrr.php"] [unique_id "amuXvIJkCYmL5o6vh9JvZgAAANE"]
[Thu Jul 30 13:28:12.711195 2026] [security2:error] [pid 890219:tid 890397] [client 20.171.55.167:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/ajax-actions.php"] [unique_id "amuXvIJkCYmL5o6vh9JvZwAAALQ"]
[Thu Jul 30 13:28:12.722360 2026] [security2:error] [pid 890219:tid 890361] [client 185.189.112.19:37024] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuXvIJkCYmL5o6vh9JvaAAAAJA"]
[Thu Jul 30 13:28:12.722474 2026] [security2:error] [pid 890219:tid 890361] [client 185.189.112.19:37024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuXvIJkCYmL5o6vh9JvaAAAAJA"]
[Thu Jul 30 13:28:12.862751 2026] [security2:error] [pid 890219:tid 890464] [client 143.244.57.82:44260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuXvIJkCYmL5o6vh9JvaQAAAPc"]
[Thu Jul 30 13:28:12.888301 2026] [security2:error] [pid 890219:tid 890412] [client 4.232.188.49:60254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/domvf.php"] [unique_id "amuXvIJkCYmL5o6vh9JvagAAAMM"]
[Thu Jul 30 13:28:12.888386 2026] [security2:error] [pid 890219:tid 890412] [client 4.232.188.49:60254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/domvf.php"] [unique_id "amuXvIJkCYmL5o6vh9JvagAAAMM"]
[Thu Jul 30 13:28:12.900368 2026] [security2:error] [pid 890219:tid 890353] [client 20.52.125.110:11986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/bnm.php"] [unique_id "amuXvIJkCYmL5o6vh9JvawAAAIg"]
[Thu Jul 30 13:28:13.141887 2026] [security2:error] [pid 890219:tid 890391] [client 143.244.57.82:44270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuXvYJkCYmL5o6vh9JvdQAAAK4"]
[Thu Jul 30 13:28:13.149814 2026] [security2:error] [pid 890219:tid 890368] [client 4.232.188.49:38815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/yup.php"] [unique_id "amuXvYJkCYmL5o6vh9JvdwAAAJc"]
[Thu Jul 30 13:28:13.149910 2026] [security2:error] [pid 890219:tid 890368] [client 4.232.188.49:38815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/yup.php"] [unique_id "amuXvYJkCYmL5o6vh9JvdwAAAJc"]
[Thu Jul 30 13:28:13.307403 2026] [security2:error] [pid 890219:tid 890447] [client 20.52.125.110:11970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/bootstrap.php"] [unique_id "amuXvYJkCYmL5o6vh9JveAAAAOY"]
[Thu Jul 30 13:28:13.415545 2026] [security2:error] [pid 890219:tid 890463] [client 4.232.188.49:59467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/X.php"] [unique_id "amuXvYJkCYmL5o6vh9JvegAAAPY"]
[Thu Jul 30 13:28:13.415626 2026] [security2:error] [pid 890219:tid 890463] [client 4.232.188.49:59467] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/X.php"] [unique_id "amuXvYJkCYmL5o6vh9JvegAAAPY"]
[Thu Jul 30 13:28:13.425853 2026] [security2:error] [pid 890219:tid 890476] [client 143.244.57.82:44282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuXvYJkCYmL5o6vh9JvewAAAQM"]
[Thu Jul 30 13:28:13.430773 2026] [security2:error] [pid 890219:tid 890380] [client 20.171.55.167:4551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-consar.php"] [unique_id "amuXvYJkCYmL5o6vh9JvfAAAAKM"]
[Thu Jul 30 13:28:13.436278 2026] [security2:error] [pid 890219:tid 890419] [client 20.91.199.21:10872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/a7.php"] [unique_id "amuXvYJkCYmL5o6vh9JvfQAAAMo"]
[Thu Jul 30 13:28:13.694292 2026] [security2:error] [pid 890219:tid 890350] [client 4.232.188.49:59479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuXvYJkCYmL5o6vh9JvhwAAAIU"]
[Thu Jul 30 13:28:13.694399 2026] [security2:error] [pid 890219:tid 890350] [client 4.232.188.49:59479] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuXvYJkCYmL5o6vh9JvhwAAAIU"]
[Thu Jul 30 13:28:13.707129 2026] [security2:error] [pid 890219:tid 890360] [client 143.244.57.82:13054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuXvYJkCYmL5o6vh9JviAAAAI8"]
[Thu Jul 30 13:28:13.713526 2026] [security2:error] [pid 890219:tid 890422] [client 20.52.125.110:12003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/buy.php"] [unique_id "amuXvYJkCYmL5o6vh9JviQAAAM0"]
[Thu Jul 30 13:28:13.975253 2026] [security2:error] [pid 890219:tid 890473] [client 4.232.188.49:38810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/gec.php"] [unique_id "amuXvYJkCYmL5o6vh9JvigAAAQA"]
[Thu Jul 30 13:28:13.975364 2026] [security2:error] [pid 890219:tid 890473] [client 4.232.188.49:38810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carrecoveryabuduabi.store"] [uri "/gec.php"] [unique_id "amuXvYJkCYmL5o6vh9JvigAAAQA"]
[Thu Jul 30 13:28:13.993954 2026] [security2:error] [pid 890219:tid 890417] [client 143.244.57.82:44298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuXvYJkCYmL5o6vh9JviwAAAMg"]
[Thu Jul 30 13:28:14.105855 2026] [security2:error] [pid 890219:tid 890394] [client 20.52.125.110:11281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/chosen.php"] [unique_id "amuXvoJkCYmL5o6vh9JvkgAAALE"]
[Thu Jul 30 13:28:14.139467 2026] [security2:error] [pid 890219:tid 890458] [client 20.171.55.167:11468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/repeater.php"] [unique_id "amuXvoJkCYmL5o6vh9JvlAAAAPE"]
[Thu Jul 30 13:28:14.306868 2026] [security2:error] [pid 890219:tid 890456] [client 143.244.57.82:44306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuXvoJkCYmL5o6vh9JvmgAAAO8"]
[Thu Jul 30 13:28:14.514049 2026] [security2:error] [pid 890219:tid 890374] [client 20.52.125.110:11274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/class-wp-image.php"] [unique_id "amuXvoJkCYmL5o6vh9JvnAAAAJ0"]
[Thu Jul 30 13:28:14.621393 2026] [security2:error] [pid 890219:tid 890365] [client 143.244.57.82:50553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuXvoJkCYmL5o6vh9JvnQAAAJQ"]
[Thu Jul 30 13:28:14.870580 2026] [security2:error] [pid 890219:tid 890410] [client 20.171.55.167:4717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/admin-post.php"] [unique_id "amuXvoJkCYmL5o6vh9JvogAAAME"]
[Thu Jul 30 13:28:14.900718 2026] [security2:error] [pid 890219:tid 890415] [client 143.244.57.82:44316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuXvoJkCYmL5o6vh9JvowAAAMY"]
[Thu Jul 30 13:28:14.919082 2026] [security2:error] [pid 890219:tid 890388] [client 20.52.125.110:11984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/classsmtps.php"] [unique_id "amuXvoJkCYmL5o6vh9JvpAAAAKs"]
[Thu Jul 30 13:28:15.215994 2026] [security2:error] [pid 890219:tid 890431] [client 143.244.57.82:23556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuXv4JkCYmL5o6vh9JvrgAAANY"]
[Thu Jul 30 13:28:15.317947 2026] [security2:error] [pid 890219:tid 890391] [client 20.52.125.110:11980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/classwithtostring.php"] [unique_id "amuXv4JkCYmL5o6vh9JvrwAAAK4"]
[Thu Jul 30 13:28:15.422572 2026] [security2:error] [pid 890219:tid 890390] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuXvoJkCYmL5o6vh9JvngAArQE"]
[Thu Jul 30 13:28:15.497517 2026] [security2:error] [pid 890219:tid 890364] [client 143.244.57.82:44342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuXv4JkCYmL5o6vh9JvtAAAAJM"]
[Thu Jul 30 13:28:15.573142 2026] [security2:error] [pid 890219:tid 890423] [client 20.171.55.167:4588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "amuXv4JkCYmL5o6vh9JvuQAAAM4"]
[Thu Jul 30 13:28:15.711396 2026] [security2:error] [pid 890219:tid 890427] [client 20.52.125.110:11991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/config.php"] [unique_id "amuXv4JkCYmL5o6vh9JvvwAAANI"]
[Thu Jul 30 13:28:15.778883 2026] [security2:error] [pid 890219:tid 890409] [client 143.244.57.82:44352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuXv4JkCYmL5o6vh9JvwAAAAMA"]
[Thu Jul 30 13:28:15.786750 2026] [security2:error] [pid 890219:tid 890280] [remote 57.141.0.37:63256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuXv4JkCYmL5o6vh9JvwQAAjDs"]
[Thu Jul 30 13:28:16.066862 2026] [security2:error] [pid 890219:tid 890461] [client 143.244.57.82:44368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuXwIJkCYmL5o6vh9JvxQAAAPQ"]
[Thu Jul 30 13:28:16.111421 2026] [security2:error] [pid 890219:tid 890350] [client 20.52.125.110:12026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/core.php"] [unique_id "amuXwIJkCYmL5o6vh9JvxgAAAIU"]
[Thu Jul 30 13:28:16.277783 2026] [security2:error] [pid 890219:tid 890429] [client 20.171.55.167:11519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/dropdown.php"] [unique_id "amuXwIJkCYmL5o6vh9JvzQAAANQ"]
[Thu Jul 30 13:28:16.381496 2026] [security2:error] [pid 890219:tid 890358] [client 143.244.57.82:44374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuXwIJkCYmL5o6vh9JvzwAAAI0"]
[Thu Jul 30 13:28:16.512836 2026] [security2:error] [pid 890219:tid 890430] [client 20.52.125.110:11278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/css.php"] [unique_id "amuXwIJkCYmL5o6vh9Jv0AAAANU"]
[Thu Jul 30 13:28:16.653847 2026] [security2:error] [pid 890219:tid 890378] [client 143.244.57.82:44390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tlt.zzt.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuXwIJkCYmL5o6vh9Jv1AAAAKE"]
[Thu Jul 30 13:28:16.852668 2026] [security2:error] [pid 890219:tid 890363] [client 185.191.171.14:60802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/07/operacao-da-pf-contra-esquema-de-compra-de-votos-na-paraiba/"] [unique_id "amuXwIJkCYmL5o6vh9Jv2wAAAJI"]
[Thu Jul 30 13:28:16.852850 2026] [security2:error] [pid 890219:tid 890363] [client 185.191.171.14:60802] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/07/operacao-da-pf-contra-esquema-de-compra-de-votos-na-paraiba/"] [unique_id "amuXwIJkCYmL5o6vh9Jv2wAAAJI"]
[Thu Jul 30 13:28:16.910740 2026] [security2:error] [pid 890219:tid 890403] [client 20.52.125.110:12025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/database.php"] [unique_id "amuXwIJkCYmL5o6vh9Jv3AAAALo"]
[Thu Jul 30 13:28:16.981995 2026] [security2:error] [pid 890219:tid 890420] [client 20.171.55.167:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/index.php"] [unique_id "amuXwIJkCYmL5o6vh9Jv3gAAAMs"]
[Thu Jul 30 13:28:17.001881 2026] [security2:error] [pid 890219:tid 890354] [client 74.7.228.26:36820] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-d5b66369.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuXwIJkCYmL5o6vh9Jv3wAAiUE"]
[Thu Jul 30 13:28:17.307423 2026] [security2:error] [pid 890219:tid 890362] [client 20.52.125.110:11271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/db.php"] [unique_id "amuXwYJkCYmL5o6vh9Jv7wAAAJE"]
[Thu Jul 30 13:28:17.520019 2026] [security2:error] [pid 890219:tid 890390] [client 20.91.199.21:46891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/f7.php"] [unique_id "amuXwYJkCYmL5o6vh9Jv8AAAAK0"]
[Thu Jul 30 13:28:17.699940 2026] [security2:error] [pid 890219:tid 890364] [client 20.171.55.167:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/dropdown.php"] [unique_id "amuXwYJkCYmL5o6vh9Jv9QAAAJM"]
[Thu Jul 30 13:28:17.705780 2026] [security2:error] [pid 890219:tid 890453] [client 20.52.125.110:11322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/default.php"] [unique_id "amuXwYJkCYmL5o6vh9Jv9gAAAOw"]
[Thu Jul 30 13:28:18.098869 2026] [security2:error] [pid 890219:tid 890376] [client 20.52.125.110:12012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/dropdown.php"] [unique_id "amuXwoJkCYmL5o6vh9Jv_QAAAJ8"]
[Thu Jul 30 13:28:18.431330 2026] [security2:error] [pid 890219:tid 890427] [client 20.171.55.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/about.php"] [unique_id "amuXwoJkCYmL5o6vh9JwBwAAANI"]
[Thu Jul 30 13:28:18.491916 2026] [core:error] [pid 890219:tid 890296] [remote 74.7.244.54:57778] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:28:18.491935 2026] [core:error] [pid 890219:tid 890296] [remote 74.7.244.54:57778] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:28:18.492103 2026] [security2:error] [pid 890219:tid 890452] [client 74.7.244.54:57778] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-d0fe016a.wvq.nyx.temporary.site"] [uri "/website_d0fe016a/index.php"] [unique_id "amuXwoJkCYmL5o6vh9JwCQAA60s"]
[Thu Jul 30 13:28:18.531630 2026] [security2:error] [pid 890219:tid 890350] [client 20.52.125.110:11977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/edit.php"] [unique_id "amuXwoJkCYmL5o6vh9JwCgAAAIU"]
[Thu Jul 30 13:28:18.939280 2026] [security2:error] [pid 890219:tid 890411] [client 20.52.125.110:11979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/f35.php"] [unique_id "amuXwoJkCYmL5o6vh9JwFwAAAMI"]
[Thu Jul 30 13:28:19.134564 2026] [security2:error] [pid 890219:tid 890365] [client 20.171.55.167:4603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/about.php7"] [unique_id "amuXw4JkCYmL5o6vh9JwGwAAAJQ"]
[Thu Jul 30 13:28:19.331174 2026] [security2:error] [pid 890219:tid 890370] [client 20.52.125.110:11270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/f7.php"] [unique_id "amuXw4JkCYmL5o6vh9JwIgAAAJk"]
[Thu Jul 30 13:28:19.838968 2026] [security2:error] [pid 890219:tid 890457] [client 20.171.55.167:11464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/alfanew.php7"] [unique_id "amuXw4JkCYmL5o6vh9JwKQAAAPA"]
[Thu Jul 30 13:28:20.338192 2026] [core:notice] [pid 890219:tid 890391] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:20.419566 2026] [security2:error] [pid 890219:tid 890428] [client 20.91.199.21:33709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/nw.php"] [unique_id "amuXxIJkCYmL5o6vh9JwPAAAANM"]
[Thu Jul 30 13:28:20.554470 2026] [security2:error] [pid 890219:tid 890380] [client 20.171.55.167:11516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/adminfuns.php7"] [unique_id "amuXxIJkCYmL5o6vh9JwQwAAAKM"]
[Thu Jul 30 13:28:21.177629 2026] [security2:error] [pid 890219:tid 890357] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuXxIJkCYmL5o6vh9JwQgAAAIw"]
[Thu Jul 30 13:28:21.259567 2026] [security2:error] [pid 890219:tid 890367] [client 20.171.55.167:4426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/ebs.php7"] [unique_id "amuXxYJkCYmL5o6vh9JwWQAAAJY"]
[Thu Jul 30 13:28:21.515207 2026] [security2:error] [pid 890219:tid 890379] [client 20.91.199.21:38549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/ova.php"] [unique_id "amuXxYJkCYmL5o6vh9JwZQAAAKI"]
[Thu Jul 30 13:28:21.717799 2026] [security2:error] [pid 890219:tid 890386] [client 179.64.21.229:10079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXxYJkCYmL5o6vh9JwZwAAAKk"]
[Thu Jul 30 13:28:21.718185 2026] [security2:error] [pid 890219:tid 890386] [client 179.64.21.229:10079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuXxYJkCYmL5o6vh9JwZwAAAKk"]
[Thu Jul 30 13:28:21.963670 2026] [security2:error] [pid 890219:tid 890424] [client 20.171.55.167:4715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/ws.php7"] [unique_id "amuXxYJkCYmL5o6vh9JwbgAAAM8"]
[Thu Jul 30 13:28:22.283501 2026] [security2:error] [pid 890219:tid 890474] [client 20.91.199.21:46904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/robots.php"] [unique_id "amuXxoJkCYmL5o6vh9JwdQAAAQE"]
[Thu Jul 30 13:28:22.673015 2026] [security2:error] [pid 890219:tid 890373] [client 20.171.55.167:4277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/alfanew2.php7"] [unique_id "amuXxoJkCYmL5o6vh9JwfwAAAJw"]
[Thu Jul 30 13:28:22.873874 2026] [autoindex:error] [pid 890219:tid 890401] [client 54.87.222.253:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:28:23.549305 2026] [security2:error] [pid 890219:tid 890436] [client 20.171.55.167:11489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/alfa-rex2.php7"] [unique_id "amuXx4JkCYmL5o6vh9JwlgAAANs"]
[Thu Jul 30 13:28:24.649158 2026] [security2:error] [pid 890219:tid 890370] [client 20.171.55.167:4682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/images/index.php"] [unique_id "amuXyIJkCYmL5o6vh9JwsAAAAJk"]
[Thu Jul 30 13:28:25.469520 2026] [security2:error] [pid 890219:tid 890393] [client 20.171.55.167:11460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/colors/index.php"] [unique_id "amuXyYJkCYmL5o6vh9JwvgAAALA"]
[Thu Jul 30 13:28:25.639780 2026] [proxy:error] [pid 890219:tid 890444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:25.639855 2026] [proxy_http:error] [pid 890219:tid 890444] [client 44.213.206.96:22497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:25.640687 2026] [proxy:error] [pid 890219:tid 890444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:25.640751 2026] [proxy_http:error] [pid 890219:tid 890444] [client 44.213.206.96:22497] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:25.651292 2026] [proxy:error] [pid 890219:tid 890387] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:25.651375 2026] [proxy_http:error] [pid 890219:tid 890387] [client 52.4.19.39:63903] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:25.652344 2026] [proxy:error] [pid 890219:tid 890387] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:25.652400 2026] [proxy_http:error] [pid 890219:tid 890387] [client 52.4.19.39:63903] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:26.228909 2026] [security2:error] [pid 890219:tid 890374] [client 20.171.55.167:4256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuXyoJkCYmL5o6vh9Jw4QAAAJ0"]
[Thu Jul 30 13:28:26.884201 2026] [security2:error] [pid 890219:tid 890422] [client 20.91.199.21:33698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/alf.php"] [unique_id "amuXyoJkCYmL5o6vh9Jw7AAAAM0"]
[Thu Jul 30 13:28:26.933655 2026] [security2:error] [pid 890219:tid 890415] [client 20.171.55.167:4271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "amuXyoJkCYmL5o6vh9Jw7QAAAMY"]
[Thu Jul 30 13:28:27.150056 2026] [security2:error] [pid 890219:tid 890464] [client 74.7.241.165:55080] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.fintn.com"] [uri "/cgi-sys/404.html"] [unique_id "amuXy4JkCYmL5o6vh9Jw9QAA9w0"]
[Thu Jul 30 13:28:27.640658 2026] [security2:error] [pid 890219:tid 890402] [client 20.171.55.167:4553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuXy4JkCYmL5o6vh9JxAAAAALk"]
[Thu Jul 30 13:28:27.966427 2026] [autoindex:error] [pid 890219:tid 890230] [remote 74.7.227.176:48106] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:28:28.415433 2026] [security2:error] [pid 890219:tid 890352] [client 20.171.55.167:11474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "amuXzIJkCYmL5o6vh9JxFgAAAIc"]
[Thu Jul 30 13:28:28.546034 2026] [core:notice] [pid 890219:tid 890428] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:28.550913 2026] [security2:error] [pid 890219:tid 890428] [client 170.83.176.22:53897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/download/933/587"] [unique_id "amuXzIJkCYmL5o6vh9JxEwAAANM"]
[Thu Jul 30 13:28:28.914774 2026] [security2:error] [pid 890219:tid 890440] [client 114.119.136.15:36783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/robots.txt"] [unique_id "amuXzIJkCYmL5o6vh9JxIwAAAN8"], referer: https://www.shorewooddaycare.com/robots.txt
[Thu Jul 30 13:28:29.087066 2026] [security2:error] [pid 890219:tid 890441] [client 68.235.48.108:60944] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuXzYJkCYmL5o6vh9JxJAAAAOA"]
[Thu Jul 30 13:28:29.087165 2026] [security2:error] [pid 890219:tid 890441] [client 68.235.48.108:60944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuXzYJkCYmL5o6vh9JxJAAAAOA"]
[Thu Jul 30 13:28:29.121887 2026] [security2:error] [pid 890219:tid 890376] [client 20.171.55.167:4704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "amuXzYJkCYmL5o6vh9JxJQAAAJ8"]
[Thu Jul 30 13:28:29.131263 2026] [security2:error] [pid 890219:tid 890476] [client 20.91.199.21:10286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/feedback.php"] [unique_id "amuXzYJkCYmL5o6vh9JxJgAAAQM"]
[Thu Jul 30 13:28:29.291637 2026] [core:notice] [pid 890219:tid 890365] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:29.360764 2026] [security2:error] [pid 890219:tid 890403] [client 20.79.250.162:9592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuXzYJkCYmL5o6vh9JxLgAAALo"]
[Thu Jul 30 13:28:29.360905 2026] [security2:error] [pid 890219:tid 890403] [client 20.79.250.162:9592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuXzYJkCYmL5o6vh9JxLgAAALo"]
[Thu Jul 30 13:28:29.730705 2026] [security2:error] [pid 890219:tid 890442] [client 20.79.250.162:9597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuXzYJkCYmL5o6vh9JxOQAAAOE"]
[Thu Jul 30 13:28:29.730794 2026] [security2:error] [pid 890219:tid 890442] [client 20.79.250.162:9597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuXzYJkCYmL5o6vh9JxOQAAAOE"]
[Thu Jul 30 13:28:29.836905 2026] [security2:error] [pid 890219:tid 890405] [client 20.171.55.167:4886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/xmrlpc.php"] [unique_id "amuXzYJkCYmL5o6vh9JxPQAAALw"]
[Thu Jul 30 13:28:30.022318 2026] [security2:error] [pid 890219:tid 890400] [client 20.79.250.162:9584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/xstelth.php"] [unique_id "amuXzoJkCYmL5o6vh9JxQQAAALc"]
[Thu Jul 30 13:28:30.022415 2026] [security2:error] [pid 890219:tid 890400] [client 20.79.250.162:9584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/xstelth.php"] [unique_id "amuXzoJkCYmL5o6vh9JxQQAAALc"]
[Thu Jul 30 13:28:30.143063 2026] [security2:error] [pid 890219:tid 890424] [client 20.91.199.21:46907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/gettest.php"] [unique_id "amuXzoJkCYmL5o6vh9JxQwAAAM8"]
[Thu Jul 30 13:28:30.291712 2026] [security2:error] [pid 890219:tid 890453] [client 20.79.250.162:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/584062352875874akp.php"] [unique_id "amuXzoJkCYmL5o6vh9JxSQAAAOw"]
[Thu Jul 30 13:28:30.291810 2026] [security2:error] [pid 890219:tid 890453] [client 20.79.250.162:9557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/584062352875874akp.php"] [unique_id "amuXzoJkCYmL5o6vh9JxSQAAAOw"]
[Thu Jul 30 13:28:30.340347 2026] [autoindex:error] [pid 890219:tid 890364] [client 3.225.222.228:13944] AH01276: Cannot serve directory /home2/qnjgzjte/hris.rgserve.ph/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:28:30.561283 2026] [security2:error] [pid 890219:tid 890447] [client 20.171.55.167:4593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuXzoJkCYmL5o6vh9JxVAAAAOY"]
[Thu Jul 30 13:28:30.637649 2026] [security2:error] [pid 890219:tid 890355] [client 20.79.250.162:9477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/newfile.php"] [unique_id "amuXzoJkCYmL5o6vh9JxVQAAAIo"]
[Thu Jul 30 13:28:30.637763 2026] [security2:error] [pid 890219:tid 890355] [client 20.79.250.162:9477] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/newfile.php"] [unique_id "amuXzoJkCYmL5o6vh9JxVQAAAIo"]
[Thu Jul 30 13:28:31.055511 2026] [security2:error] [pid 890219:tid 890377] [client 20.79.250.162:9539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/tBEZGQz.php"] [unique_id "amuXz4JkCYmL5o6vh9JxXwAAAKA"]
[Thu Jul 30 13:28:31.055622 2026] [security2:error] [pid 890219:tid 890377] [client 20.79.250.162:9539] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/tBEZGQz.php"] [unique_id "amuXz4JkCYmL5o6vh9JxXwAAAKA"]
[Thu Jul 30 13:28:31.126578 2026] [security2:error] [pid 890219:tid 890375] [client 20.91.199.21:33721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/maint.php"] [unique_id "amuXz4JkCYmL5o6vh9JxYAAAAJ4"]
[Thu Jul 30 13:28:31.173037 2026] [core:notice] [pid 890219:tid 890394] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:31.272167 2026] [security2:error] [pid 890219:tid 890382] [client 20.171.55.167:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/css/xmrlpc.php"] [unique_id "amuXz4JkCYmL5o6vh9JxZQAAAKU"]
[Thu Jul 30 13:28:31.369078 2026] [security2:error] [pid 890219:tid 890399] [client 20.79.250.162:9577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.nimna.lk"] [uri "/___proxy_subdomain_webdisk/phpinfo"] [unique_id "amuXz4JkCYmL5o6vh9JxZgAAALY"]
[Thu Jul 30 13:28:31.499047 2026] [security2:error] [pid 890219:tid 890354] [client 20.79.250.162:9577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/drykl.php"] [unique_id "amuXz4JkCYmL5o6vh9JxawAAAIk"]
[Thu Jul 30 13:28:31.499173 2026] [security2:error] [pid 890219:tid 890354] [client 20.79.250.162:9577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/drykl.php"] [unique_id "amuXz4JkCYmL5o6vh9JxawAAAIk"]
[Thu Jul 30 13:28:31.791249 2026] [security2:error] [pid 890219:tid 890415] [client 20.79.250.162:9563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.nimna.lk"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuXz4JkCYmL5o6vh9JxdAAAAMY"]
[Thu Jul 30 13:28:31.920943 2026] [security2:error] [pid 890219:tid 890434] [client 20.79.250.162:9563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/ls.php"] [unique_id "amuXz4JkCYmL5o6vh9JxdgAAANk"]
[Thu Jul 30 13:28:31.921095 2026] [security2:error] [pid 890219:tid 890434] [client 20.79.250.162:9563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/ls.php"] [unique_id "amuXz4JkCYmL5o6vh9JxdgAAANk"]
[Thu Jul 30 13:28:31.983637 2026] [security2:error] [pid 890219:tid 890416] [client 20.171.55.167:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuXz4JkCYmL5o6vh9JxegAAAMc"]
[Thu Jul 30 13:28:32.215662 2026] [security2:error] [pid 890219:tid 890406] [client 20.79.250.162:9560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/dx.php"] [unique_id "amuX0IJkCYmL5o6vh9JxgQAAAL0"]
[Thu Jul 30 13:28:32.215753 2026] [security2:error] [pid 890219:tid 890406] [client 20.79.250.162:9560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/dx.php"] [unique_id "amuX0IJkCYmL5o6vh9JxgQAAAL0"]
[Thu Jul 30 13:28:32.309340 2026] [security2:error] [pid 890219:tid 890386] [client 179.64.21.229:25183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuX0IJkCYmL5o6vh9JxhQAAAKk"]
[Thu Jul 30 13:28:32.309437 2026] [security2:error] [pid 890219:tid 890386] [client 179.64.21.229:25183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuX0IJkCYmL5o6vh9JxhQAAAKk"]
[Thu Jul 30 13:28:32.438719 2026] [security2:error] [pid 890219:tid 890408] [client 20.91.199.21:11040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/files.php"] [unique_id "amuX0IJkCYmL5o6vh9JxigAAAL8"]
[Thu Jul 30 13:28:32.498829 2026] [security2:error] [pid 890219:tid 890366] [client 20.79.250.162:9487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/mac.php"] [unique_id "amuX0IJkCYmL5o6vh9JxjgAAAJU"]
[Thu Jul 30 13:28:32.498935 2026] [security2:error] [pid 890219:tid 890366] [client 20.79.250.162:9487] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/mac.php"] [unique_id "amuX0IJkCYmL5o6vh9JxjgAAAJU"]
[Thu Jul 30 13:28:32.692193 2026] [security2:error] [pid 890219:tid 890454] [client 20.171.55.167:11490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/img/xmrlpc.php"] [unique_id "amuX0IJkCYmL5o6vh9JxkwAAAO0"]
[Thu Jul 30 13:28:32.773606 2026] [security2:error] [pid 890219:tid 890438] [client 20.79.250.162:9596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/485.php"] [unique_id "amuX0IJkCYmL5o6vh9JxlAAAAN0"]
[Thu Jul 30 13:28:32.773709 2026] [security2:error] [pid 890219:tid 890438] [client 20.79.250.162:9596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/485.php"] [unique_id "amuX0IJkCYmL5o6vh9JxlAAAAN0"]
[Thu Jul 30 13:28:33.102997 2026] [security2:error] [pid 890219:tid 890436] [client 20.79.250.162:9564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/gelio1.php"] [unique_id "amuX0YJkCYmL5o6vh9JxpAAAANs"]
[Thu Jul 30 13:28:33.103110 2026] [security2:error] [pid 890219:tid 890436] [client 20.79.250.162:9564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/gelio1.php"] [unique_id "amuX0YJkCYmL5o6vh9JxpAAAANs"]
[Thu Jul 30 13:28:33.157613 2026] [security2:error] [pid 890219:tid 890456] [client 20.91.199.21:10269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/gecko.php"] [unique_id "amuX0YJkCYmL5o6vh9JxpQAAAO8"]
[Thu Jul 30 13:28:33.372961 2026] [security2:error] [pid 890219:tid 890385] [client 20.79.250.162:9500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/lp6.php"] [unique_id "amuX0YJkCYmL5o6vh9JxrAAAAKg"]
[Thu Jul 30 13:28:33.373083 2026] [security2:error] [pid 890219:tid 890385] [client 20.79.250.162:9500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/lp6.php"] [unique_id "amuX0YJkCYmL5o6vh9JxrAAAAKg"]
[Thu Jul 30 13:28:33.397649 2026] [security2:error] [pid 890219:tid 890367] [client 20.171.55.167:4575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "amuX0YJkCYmL5o6vh9JxrQAAAJY"]
[Thu Jul 30 13:28:33.655069 2026] [security2:error] [pid 890219:tid 890410] [client 20.79.250.162:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuX0YJkCYmL5o6vh9JxtgAAAME"]
[Thu Jul 30 13:28:33.655218 2026] [security2:error] [pid 890219:tid 890410] [client 20.79.250.162:9542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuX0YJkCYmL5o6vh9JxtgAAAME"]
[Thu Jul 30 13:28:33.955033 2026] [security2:error] [pid 890219:tid 890460] [client 20.79.250.162:9480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.nimna.lk"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuX0YJkCYmL5o6vh9JxugAAAPM"]
[Thu Jul 30 13:28:34.084194 2026] [security2:error] [pid 890219:tid 890421] [client 20.79.250.162:9480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/w3llscc.php"] [unique_id "amuX0oJkCYmL5o6vh9JxvgAAAMw"]
[Thu Jul 30 13:28:34.084291 2026] [security2:error] [pid 890219:tid 890421] [client 20.79.250.162:9480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/w3llscc.php"] [unique_id "amuX0oJkCYmL5o6vh9JxvgAAAMw"]
[Thu Jul 30 13:28:34.139937 2026] [security2:error] [pid 890219:tid 890464] [client 20.171.55.167:4477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "amuX0oJkCYmL5o6vh9JxwQAAAPc"]
[Thu Jul 30 13:28:34.366926 2026] [security2:error] [pid 890219:tid 890468] [client 20.79.250.162:9481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/miru3.php"] [unique_id "amuX0oJkCYmL5o6vh9JxxgAAAPs"]
[Thu Jul 30 13:28:34.367037 2026] [security2:error] [pid 890219:tid 890468] [client 20.79.250.162:9481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/miru3.php"] [unique_id "amuX0oJkCYmL5o6vh9JxxgAAAPs"]
[Thu Jul 30 13:28:34.416265 2026] [security2:error] [pid 890219:tid 890391] [client 188.119.13.37:10077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX0oJkCYmL5o6vh9JxxwAAAK4"]
[Thu Jul 30 13:28:34.664859 2026] [security2:error] [pid 890219:tid 890461] [client 20.79.250.162:9553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/autoload_classmap.php"] [unique_id "amuX0oJkCYmL5o6vh9JxzwAAAPQ"]
[Thu Jul 30 13:28:34.664950 2026] [security2:error] [pid 890219:tid 890461] [client 20.79.250.162:9553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/autoload_classmap.php"] [unique_id "amuX0oJkCYmL5o6vh9JxzwAAAPQ"]
[Thu Jul 30 13:28:34.796575 2026] [security2:error] [pid 890219:tid 890401] [client 188.119.13.37:10697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX0oJkCYmL5o6vh9Jx0AAAALg"]
[Thu Jul 30 13:28:34.852341 2026] [security2:error] [pid 890219:tid 890418] [client 20.171.55.167:4876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/images/xmrlpc.php"] [unique_id "amuX0oJkCYmL5o6vh9Jx1AAAAMk"]
[Thu Jul 30 13:28:34.950505 2026] [security2:error] [pid 890219:tid 890454] [client 20.79.250.162:9556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.nimna.lk"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuX0oJkCYmL5o6vh9Jx1QAAAO0"]
[Thu Jul 30 13:28:35.080665 2026] [security2:error] [pid 890219:tid 890439] [client 20.79.250.162:9556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-content/themes/index.php"] [unique_id "amuX04JkCYmL5o6vh9Jx2QAAAN4"]
[Thu Jul 30 13:28:35.080795 2026] [security2:error] [pid 890219:tid 890439] [client 20.79.250.162:9556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-content/themes/index.php"] [unique_id "amuX04JkCYmL5o6vh9Jx2QAAAN4"]
[Thu Jul 30 13:28:35.193551 2026] [security2:error] [pid 890219:tid 890357] [client 188.119.13.37:11178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX04JkCYmL5o6vh9Jx3wAAAIw"]
[Thu Jul 30 13:28:35.367356 2026] [core:notice] [pid 890219:tid 890470] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:35.459218 2026] [security2:error] [pid 890219:tid 890462] [client 20.79.250.162:9565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/av.php"] [unique_id "amuX04JkCYmL5o6vh9Jx5wAAAPU"]
[Thu Jul 30 13:28:35.459322 2026] [security2:error] [pid 890219:tid 890462] [client 20.79.250.162:9565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/av.php"] [unique_id "amuX04JkCYmL5o6vh9Jx5wAAAPU"]
[Thu Jul 30 13:28:35.573577 2026] [security2:error] [pid 890219:tid 890377] [client 20.171.55.167:4899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "amuX04JkCYmL5o6vh9Jx6wAAAKA"]
[Thu Jul 30 13:28:35.583166 2026] [security2:error] [pid 890219:tid 890472] [client 188.119.13.37:10241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX04JkCYmL5o6vh9Jx7QAAAP8"]
[Thu Jul 30 13:28:35.747491 2026] [security2:error] [pid 890219:tid 890365] [client 20.79.250.162:9541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.nimna.lk"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuX04JkCYmL5o6vh9Jx9AAAAJQ"]
[Thu Jul 30 13:28:35.808963 2026] [security2:error] [pid 890219:tid 890409] [client 144.76.32.237:54134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koriusa.info"] [uri "/index.php"] [unique_id "amuX04JkCYmL5o6vh9Jx7wAAAMA"]
[Thu Jul 30 13:28:35.892115 2026] [security2:error] [pid 890219:tid 890459] [client 20.79.250.162:9541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.nimna.lk"] [uri "/___proxy_subdomain_webdisk/wordpress/wp-admin/maint/"] [unique_id "amuX04JkCYmL5o6vh9Jx_AAAAPI"]
[Thu Jul 30 13:28:35.959410 2026] [security2:error] [pid 890219:tid 890434] [client 188.119.13.37:10763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX04JkCYmL5o6vh9Jx_wAAANk"]
[Thu Jul 30 13:28:36.022175 2026] [security2:error] [pid 890219:tid 890446] [client 20.79.250.162:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/tiny.php"] [unique_id "amuX1IJkCYmL5o6vh9JyAQAAAOU"]
[Thu Jul 30 13:28:36.022309 2026] [security2:error] [pid 890219:tid 890446] [client 20.79.250.162:9541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/tiny.php"] [unique_id "amuX1IJkCYmL5o6vh9JyAQAAAOU"]
[Thu Jul 30 13:28:36.116010 2026] [core:notice] [pid 890219:tid 890389] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:36.254894 2026] [security2:error] [pid 890219:tid 890405] [client 20.91.199.21:11062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/zwso.php"] [unique_id "amuX1IJkCYmL5o6vh9JyCgAAALw"]
[Thu Jul 30 13:28:36.302261 2026] [security2:error] [pid 890219:tid 890424] [client 20.79.250.162:9479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuX1IJkCYmL5o6vh9JyDAAAAM8"]
[Thu Jul 30 13:28:36.302407 2026] [security2:error] [pid 890219:tid 890424] [client 20.79.250.162:9479] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuX1IJkCYmL5o6vh9JyDAAAAM8"]
[Thu Jul 30 13:28:36.320605 2026] [security2:error] [pid 890219:tid 890455] [client 20.171.55.167:11501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "amuX1IJkCYmL5o6vh9JyDQAAAO4"]
[Thu Jul 30 13:28:36.332544 2026] [security2:error] [pid 890219:tid 890370] [client 188.119.13.37:10558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX1IJkCYmL5o6vh9JyDgAAAJk"]
[Thu Jul 30 13:28:36.430227 2026] [core:notice] [pid 890219:tid 890426] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:36.588186 2026] [security2:error] [pid 890219:tid 890445] [client 20.79.250.162:9569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/zrrhj.php"] [unique_id "amuX1IJkCYmL5o6vh9JyFgAAAOQ"]
[Thu Jul 30 13:28:36.588312 2026] [security2:error] [pid 890219:tid 890445] [client 20.79.250.162:9569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/zrrhj.php"] [unique_id "amuX1IJkCYmL5o6vh9JyFgAAAOQ"]
[Thu Jul 30 13:28:36.720103 2026] [security2:error] [pid 890219:tid 890458] [client 188.119.13.37:10933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX1IJkCYmL5o6vh9JyGwAAAPE"]
[Thu Jul 30 13:28:36.856586 2026] [security2:error] [pid 890219:tid 890355] [client 20.79.250.162:9490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuX1IJkCYmL5o6vh9JyIAAAAIo"]
[Thu Jul 30 13:28:36.856740 2026] [security2:error] [pid 890219:tid 890355] [client 20.79.250.162:9490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuX1IJkCYmL5o6vh9JyIAAAAIo"]
[Thu Jul 30 13:28:37.037000 2026] [security2:error] [pid 890219:tid 890454] [client 20.171.55.167:4647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "amuX1YJkCYmL5o6vh9JyJQAAAO0"]
[Thu Jul 30 13:28:37.089542 2026] [proxy:error] [pid 890219:tid 890430] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:37.089645 2026] [proxy_http:error] [pid 890219:tid 890430] [client 54.87.222.253:43977] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:37.089805 2026] [proxy:error] [pid 890219:tid 890437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:37.089868 2026] [proxy_http:error] [pid 890219:tid 890437] [client 52.202.41.153:18070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:37.090254 2026] [proxy:error] [pid 890219:tid 890430] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:37.090303 2026] [proxy_http:error] [pid 890219:tid 890430] [client 54.87.222.253:43977] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:37.090492 2026] [proxy:error] [pid 890219:tid 890437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:37.090540 2026] [proxy_http:error] [pid 890219:tid 890437] [client 52.202.41.153:18070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:37.112061 2026] [security2:error] [pid 890219:tid 890456] [client 188.119.13.37:10335] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX1YJkCYmL5o6vh9JyMwAAAO8"]
[Thu Jul 30 13:28:37.129056 2026] [security2:error] [pid 890219:tid 890473] [client 20.79.250.162:9494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wpgum.php"] [unique_id "amuX1YJkCYmL5o6vh9JyOQAAAQA"]
[Thu Jul 30 13:28:37.129153 2026] [security2:error] [pid 890219:tid 890473] [client 20.79.250.162:9494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wpgum.php"] [unique_id "amuX1YJkCYmL5o6vh9JyOQAAAQA"]
[Thu Jul 30 13:28:37.400637 2026] [security2:error] [pid 890219:tid 890354] [client 20.79.250.162:9506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/ywwbf.php"] [unique_id "amuX1YJkCYmL5o6vh9JySAAAAIk"]
[Thu Jul 30 13:28:37.400758 2026] [security2:error] [pid 890219:tid 890354] [client 20.79.250.162:9506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/ywwbf.php"] [unique_id "amuX1YJkCYmL5o6vh9JySAAAAIk"]
[Thu Jul 30 13:28:37.487791 2026] [security2:error] [pid 890219:tid 890397] [client 188.119.13.37:11030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX1YJkCYmL5o6vh9JyTAAAALQ"]
[Thu Jul 30 13:28:37.623911 2026] [security2:error] [pid 890219:tid 890381] [client 172.237.109.114:25525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX1YJkCYmL5o6vh9JyNAAAAKQ"]
[Thu Jul 30 13:28:37.683424 2026] [security2:error] [pid 890219:tid 890406] [client 20.79.250.162:9562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/xoldj.php"] [unique_id "amuX1YJkCYmL5o6vh9JyTgAAAL0"]
[Thu Jul 30 13:28:37.683551 2026] [security2:error] [pid 890219:tid 890406] [client 20.79.250.162:9562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/xoldj.php"] [unique_id "amuX1YJkCYmL5o6vh9JyTgAAAL0"]
[Thu Jul 30 13:28:37.742515 2026] [security2:error] [pid 890219:tid 890469] [client 20.171.55.167:11469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "amuX1YJkCYmL5o6vh9JyUgAAAPw"]
[Thu Jul 30 13:28:37.862658 2026] [security2:error] [pid 890219:tid 890445] [client 188.119.13.37:10220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX1YJkCYmL5o6vh9JyWgAAAOQ"]
[Thu Jul 30 13:28:37.959198 2026] [security2:error] [pid 890219:tid 890413] [client 20.79.250.162:9550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/f35.php"] [unique_id "amuX1YJkCYmL5o6vh9JyWwAAAMQ"]
[Thu Jul 30 13:28:37.959305 2026] [security2:error] [pid 890219:tid 890413] [client 20.79.250.162:9550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/f35.php"] [unique_id "amuX1YJkCYmL5o6vh9JyWwAAAMQ"]
[Thu Jul 30 13:28:38.166592 2026] [security2:error] [pid 890219:tid 890454] [client 43.156.36.169:57794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.36.156.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/misionf.php"] [unique_id "amuX1oJkCYmL5o6vh9JyYQAAAO0"]
[Thu Jul 30 13:28:38.250055 2026] [security2:error] [pid 890219:tid 890456] [client 188.119.13.37:10264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX1oJkCYmL5o6vh9JyYwAAAO8"]
[Thu Jul 30 13:28:38.258350 2026] [security2:error] [pid 890219:tid 890465] [client 20.79.250.162:9591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/gk.php"] [unique_id "amuX1oJkCYmL5o6vh9JyZAAAAPg"]
[Thu Jul 30 13:28:38.258426 2026] [security2:error] [pid 890219:tid 890465] [client 20.79.250.162:9591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/gk.php"] [unique_id "amuX1oJkCYmL5o6vh9JyZAAAAPg"]
[Thu Jul 30 13:28:38.453006 2026] [security2:error] [pid 890219:tid 890437] [client 20.171.55.167:4608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/xmrlpc.php"] [unique_id "amuX1oJkCYmL5o6vh9JybgAAANw"]
[Thu Jul 30 13:28:38.465608 2026] [security2:error] [pid 890219:tid 890430] [client 185.189.112.19:35834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuX1oJkCYmL5o6vh9JyYgAAANU"]
[Thu Jul 30 13:28:38.465731 2026] [security2:error] [pid 890219:tid 890430] [client 185.189.112.19:35834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuX1oJkCYmL5o6vh9JyYgAAANU"]
[Thu Jul 30 13:28:38.585481 2026] [security2:error] [pid 890219:tid 890443] [client 20.79.250.162:9579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/584062352875874akp.php"] [unique_id "amuX1oJkCYmL5o6vh9JybwAAAOI"]
[Thu Jul 30 13:28:38.585588 2026] [security2:error] [pid 890219:tid 890443] [client 20.79.250.162:9579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/584062352875874akp.php"] [unique_id "amuX1oJkCYmL5o6vh9JybwAAAOI"]
[Thu Jul 30 13:28:38.643487 2026] [security2:error] [pid 890219:tid 890409] [client 188.119.13.37:11274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX1oJkCYmL5o6vh9JycAAAAMA"]
[Thu Jul 30 13:28:38.878950 2026] [security2:error] [pid 890219:tid 890410] [client 20.79.250.162:9552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wper3.php"] [unique_id "amuX1oJkCYmL5o6vh9JydwAAAME"]
[Thu Jul 30 13:28:38.879103 2026] [security2:error] [pid 890219:tid 890410] [client 20.79.250.162:9552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wper3.php"] [unique_id "amuX1oJkCYmL5o6vh9JydwAAAME"]
[Thu Jul 30 13:28:39.190353 2026] [security2:error] [pid 890219:tid 890449] [client 20.171.55.167:4641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/text.php"] [unique_id "amuX14JkCYmL5o6vh9JyewAAAOg"]
[Thu Jul 30 13:28:39.225740 2026] [security2:error] [pid 890219:tid 890446] [client 20.79.250.162:9503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/bthil.php"] [unique_id "amuX14JkCYmL5o6vh9JyfAAAAOU"]
[Thu Jul 30 13:28:39.225842 2026] [security2:error] [pid 890219:tid 890446] [client 20.79.250.162:9503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/bthil.php"] [unique_id "amuX14JkCYmL5o6vh9JyfAAAAOU"]
[Thu Jul 30 13:28:39.522010 2026] [security2:error] [pid 890219:tid 890469] [client 20.79.250.162:9496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wyzer1.php"] [unique_id "amuX14JkCYmL5o6vh9JyiQAAAPw"]
[Thu Jul 30 13:28:39.522101 2026] [security2:error] [pid 890219:tid 890469] [client 20.79.250.162:9496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wyzer1.php"] [unique_id "amuX14JkCYmL5o6vh9JyiQAAAPw"]
[Thu Jul 30 13:28:39.793558 2026] [security2:error] [pid 890219:tid 890455] [client 20.79.250.162:9508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/mh.php"] [unique_id "amuX14JkCYmL5o6vh9JyigAAAO4"]
[Thu Jul 30 13:28:39.793669 2026] [security2:error] [pid 890219:tid 890455] [client 20.79.250.162:9508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/mh.php"] [unique_id "amuX14JkCYmL5o6vh9JyigAAAO4"]
[Thu Jul 30 13:28:39.894755 2026] [security2:error] [pid 890219:tid 890419] [client 20.171.55.167:4630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/wp-admin/network/index.php"] [unique_id "amuX14JkCYmL5o6vh9JyjgAAAMo"]
[Thu Jul 30 13:28:40.084951 2026] [security2:error] [pid 890219:tid 890392] [client 20.79.250.162:9586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuX2IJkCYmL5o6vh9JymQAAAK8"]
[Thu Jul 30 13:28:40.085114 2026] [security2:error] [pid 890219:tid 890392] [client 20.79.250.162:9586] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuX2IJkCYmL5o6vh9JymQAAAK8"]
[Thu Jul 30 13:28:40.220541 2026] [core:error] [pid 890219:tid 890387] [client 74.7.228.57:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:28:40.220570 2026] [core:error] [pid 890219:tid 890387] [client 74.7.228.57:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:28:40.220715 2026] [security2:error] [pid 890219:tid 890387] [client 74.7.228.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuX2IJkCYmL5o6vh9JynAAAAKo"]
[Thu Jul 30 13:28:40.221340 2026] [security2:error] [pid 890219:tid 890418] [client 74.7.228.57:43236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.caflchimneysweeper.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuX2IJkCYmL5o6vh9JymgAAyRk"]
[Thu Jul 30 13:28:40.350829 2026] [security2:error] [pid 890219:tid 890356] [client 20.79.250.162:9578] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.nimna.lk"] [uri "/1.php"] [unique_id "amuX2IJkCYmL5o6vh9JyngAAAIs"]
[Thu Jul 30 13:28:40.350955 2026] [security2:error] [pid 890219:tid 890356] [client 20.79.250.162:9578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/1.php"] [unique_id "amuX2IJkCYmL5o6vh9JyngAAAIs"]
[Thu Jul 30 13:28:40.351070 2026] [security2:error] [pid 890219:tid 890356] [client 20.79.250.162:9578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/1.php"] [unique_id "amuX2IJkCYmL5o6vh9JyngAAAIs"]
[Thu Jul 30 13:28:40.642663 2026] [security2:error] [pid 890219:tid 890365] [client 20.79.250.162:9587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/chosen.php"] [unique_id "amuX2IJkCYmL5o6vh9JypwAAAJQ"]
[Thu Jul 30 13:28:40.642775 2026] [security2:error] [pid 890219:tid 890365] [client 20.79.250.162:9587] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/chosen.php"] [unique_id "amuX2IJkCYmL5o6vh9JypwAAAJQ"]
[Thu Jul 30 13:28:40.917152 2026] [security2:error] [pid 890219:tid 890369] [client 20.79.250.162:6339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/sd.php"] [unique_id "amuX2IJkCYmL5o6vh9JyqwAAAJg"]
[Thu Jul 30 13:28:40.917235 2026] [security2:error] [pid 890219:tid 890369] [client 20.79.250.162:6339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/sd.php"] [unique_id "amuX2IJkCYmL5o6vh9JyqwAAAJg"]
[Thu Jul 30 13:28:40.952286 2026] [security2:error] [pid 890219:tid 890235] [remote 103.253.21.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.21.253.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aakmiddleast.com"] [uri "/wp-login.php"] [unique_id "amuX2IJkCYmL5o6vh9JyrAAA4A4"]
[Thu Jul 30 13:28:41.118642 2026] [security2:error] [pid 890219:tid 890384] [client 20.171.55.167:4651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.aded-rdc.org"] [uri "/makeasmtp.php"] [unique_id "amuX2YJkCYmL5o6vh9JyswAAAKc"]
[Thu Jul 30 13:28:41.216307 2026] [security2:error] [pid 890219:tid 890453] [client 20.91.199.21:33693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/13.php"] [unique_id "amuX2YJkCYmL5o6vh9JytAAAAOw"]
[Thu Jul 30 13:28:41.223335 2026] [security2:error] [pid 890219:tid 890371] [client 20.79.250.162:9473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/z60.php"] [unique_id "amuX2YJkCYmL5o6vh9JytQAAAJo"]
[Thu Jul 30 13:28:41.223414 2026] [security2:error] [pid 890219:tid 890371] [client 20.79.250.162:9473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/z60.php"] [unique_id "amuX2YJkCYmL5o6vh9JytQAAAJo"]
[Thu Jul 30 13:28:41.534091 2026] [security2:error] [pid 890219:tid 890477] [client 20.79.250.162:9593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/home.php"] [unique_id "amuX2YJkCYmL5o6vh9JyvQAAAQQ"]
[Thu Jul 30 13:28:41.534193 2026] [security2:error] [pid 890219:tid 890477] [client 20.79.250.162:9593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/home.php"] [unique_id "amuX2YJkCYmL5o6vh9JyvQAAAQQ"]
[Thu Jul 30 13:28:41.600626 2026] [security2:error] [pid 890219:tid 890425] [client 188.119.13.37:11123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX2YJkCYmL5o6vh9JywAAAANA"]
[Thu Jul 30 13:28:41.834333 2026] [security2:error] [pid 890219:tid 890424] [client 20.79.250.162:9478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/ws58.php"] [unique_id "amuX2YJkCYmL5o6vh9JywwAAAM8"]
[Thu Jul 30 13:28:41.834457 2026] [security2:error] [pid 890219:tid 890424] [client 20.79.250.162:9478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/ws58.php"] [unique_id "amuX2YJkCYmL5o6vh9JywwAAAM8"]
[Thu Jul 30 13:28:41.976062 2026] [security2:error] [pid 890219:tid 890364] [client 188.119.13.37:10088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX2YJkCYmL5o6vh9JyygAAAJM"]
[Thu Jul 30 13:28:42.113707 2026] [security2:error] [pid 890219:tid 890474] [client 20.79.250.162:6364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/gulu.php"] [unique_id "amuX2oJkCYmL5o6vh9JyzgAAAQE"]
[Thu Jul 30 13:28:42.113822 2026] [security2:error] [pid 890219:tid 890474] [client 20.79.250.162:6364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/gulu.php"] [unique_id "amuX2oJkCYmL5o6vh9JyzgAAAQE"]
[Thu Jul 30 13:28:42.354904 2026] [security2:error] [pid 890219:tid 890450] [client 188.119.13.37:10759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX2oJkCYmL5o6vh9Jy1gAAAOk"]
[Thu Jul 30 13:28:42.380212 2026] [security2:error] [pid 890219:tid 890439] [client 20.79.250.162:9549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuX2oJkCYmL5o6vh9Jy1wAAAN4"]
[Thu Jul 30 13:28:42.380301 2026] [security2:error] [pid 890219:tid 890439] [client 20.79.250.162:9549] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuX2oJkCYmL5o6vh9Jy1wAAAN4"]
[Thu Jul 30 13:28:42.646467 2026] [security2:error] [pid 890219:tid 890465] [client 20.79.250.162:9522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wpls.php"] [unique_id "amuX2oJkCYmL5o6vh9Jy4QAAAPg"]
[Thu Jul 30 13:28:42.646601 2026] [security2:error] [pid 890219:tid 890465] [client 20.79.250.162:9522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wpls.php"] [unique_id "amuX2oJkCYmL5o6vh9Jy4QAAAPg"]
[Thu Jul 30 13:28:42.767848 2026] [security2:error] [pid 890219:tid 890466] [client 188.119.13.37:10146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "shorewooddaycare.com"] [uri "/index.php"] [unique_id "amuX2oJkCYmL5o6vh9Jy4gAAAPk"]
[Thu Jul 30 13:28:42.938371 2026] [security2:error] [pid 890219:tid 890372] [client 20.79.250.162:6383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/php.php"] [unique_id "amuX2oJkCYmL5o6vh9Jy5gAAAJs"]
[Thu Jul 30 13:28:42.938476 2026] [security2:error] [pid 890219:tid 890372] [client 20.79.250.162:6383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/php.php"] [unique_id "amuX2oJkCYmL5o6vh9Jy5gAAAJs"]
[Thu Jul 30 13:28:43.193206 2026] [security2:error] [pid 890219:tid 890452] [client 20.91.199.21:19674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/ava.php"] [unique_id "amuX24JkCYmL5o6vh9Jy7QAAAOs"]
[Thu Jul 30 13:28:43.220416 2026] [security2:error] [pid 890219:tid 890385] [client 20.79.250.162:9538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/100.php"] [unique_id "amuX24JkCYmL5o6vh9Jy7gAAAKg"]
[Thu Jul 30 13:28:43.220542 2026] [security2:error] [pid 890219:tid 890385] [client 20.79.250.162:9538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/100.php"] [unique_id "amuX24JkCYmL5o6vh9Jy7gAAAKg"]
[Thu Jul 30 13:28:43.447419 2026] [security2:error] [pid 890219:tid 890390] [client 179.64.21.229:3949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuX24JkCYmL5o6vh9Jy7wAAAK0"]
[Thu Jul 30 13:28:43.447568 2026] [security2:error] [pid 890219:tid 890390] [client 179.64.21.229:3949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuX24JkCYmL5o6vh9Jy7wAAAK0"]
[Thu Jul 30 13:28:43.500018 2026] [security2:error] [pid 890219:tid 890358] [client 20.79.250.162:9548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/BDKR28WP.php"] [unique_id "amuX24JkCYmL5o6vh9Jy9AAAAI0"]
[Thu Jul 30 13:28:43.500122 2026] [security2:error] [pid 890219:tid 890358] [client 20.79.250.162:9548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/BDKR28WP.php"] [unique_id "amuX24JkCYmL5o6vh9Jy9AAAAI0"]
[Thu Jul 30 13:28:43.776783 2026] [security2:error] [pid 890219:tid 890460] [client 20.79.250.162:9567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/browse.php"] [unique_id "amuX24JkCYmL5o6vh9Jy-wAAAPM"]
[Thu Jul 30 13:28:43.776869 2026] [security2:error] [pid 890219:tid 890460] [client 20.79.250.162:9567] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/browse.php"] [unique_id "amuX24JkCYmL5o6vh9Jy-wAAAPM"]
[Thu Jul 30 13:28:44.046013 2026] [security2:error] [pid 890219:tid 890477] [client 20.79.250.162:9492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-good.php"] [unique_id "amuX3IJkCYmL5o6vh9Jy_wAAAQQ"]
[Thu Jul 30 13:28:44.046116 2026] [security2:error] [pid 890219:tid 890477] [client 20.79.250.162:9492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-good.php"] [unique_id "amuX3IJkCYmL5o6vh9Jy_wAAAQQ"]
[Thu Jul 30 13:28:44.277972 2026] [security2:error] [pid 890219:tid 890359] [client 20.91.199.21:10281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/main.php"] [unique_id "amuX3IJkCYmL5o6vh9JzBwAAAI4"]
[Thu Jul 30 13:28:44.329401 2026] [security2:error] [pid 890219:tid 890412] [client 20.79.250.162:6275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/8573.php"] [unique_id "amuX3IJkCYmL5o6vh9JzCAAAAMM"]
[Thu Jul 30 13:28:44.329518 2026] [security2:error] [pid 890219:tid 890412] [client 20.79.250.162:6275] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/8573.php"] [unique_id "amuX3IJkCYmL5o6vh9JzCAAAAMM"]
[Thu Jul 30 13:28:44.599864 2026] [security2:error] [pid 890219:tid 890413] [client 20.79.250.162:6336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-admin/install.php"] [unique_id "amuX3IJkCYmL5o6vh9JzEAAAAMQ"]
[Thu Jul 30 13:28:44.599952 2026] [security2:error] [pid 890219:tid 890413] [client 20.79.250.162:6336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-admin/install.php"] [unique_id "amuX3IJkCYmL5o6vh9JzEAAAAMQ"]
[Thu Jul 30 13:28:44.865646 2026] [security2:error] [pid 890219:tid 890450] [client 20.79.250.162:9571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/classwithtostring.php"] [unique_id "amuX3IJkCYmL5o6vh9JzFgAAAOk"]
[Thu Jul 30 13:28:44.865766 2026] [security2:error] [pid 890219:tid 890450] [client 20.79.250.162:9571] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/classwithtostring.php"] [unique_id "amuX3IJkCYmL5o6vh9JzFgAAAOk"]
[Thu Jul 30 13:28:45.138965 2026] [security2:error] [pid 890219:tid 890423] [client 20.79.250.162:9573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/ohct.php"] [unique_id "amuX3YJkCYmL5o6vh9JzHQAAAM4"]
[Thu Jul 30 13:28:45.139125 2026] [security2:error] [pid 890219:tid 890423] [client 20.79.250.162:9573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/ohct.php"] [unique_id "amuX3YJkCYmL5o6vh9JzHQAAAM4"]
[Thu Jul 30 13:28:45.139827 2026] [security2:error] [pid 890219:tid 890373] [client 20.91.199.21:33695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/wp-file.php"] [unique_id "amuX3YJkCYmL5o6vh9JzHgAAAJw"]
[Thu Jul 30 13:28:45.422540 2026] [security2:error] [pid 890219:tid 890472] [client 20.79.250.162:9574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/bless.php"] [unique_id "amuX3YJkCYmL5o6vh9JzIgAAAP8"]
[Thu Jul 30 13:28:45.422633 2026] [security2:error] [pid 890219:tid 890472] [client 20.79.250.162:9574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/bless.php"] [unique_id "amuX3YJkCYmL5o6vh9JzIgAAAP8"]
[Thu Jul 30 13:28:45.438567 2026] [security2:error] [pid 890219:tid 890397] [client 52.15.147.27:51754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuX3IJkCYmL5o6vh9JzAwAAALQ"], referer: https://globalmarks.pk/
[Thu Jul 30 13:28:45.738878 2026] [security2:error] [pid 890219:tid 890376] [client 20.79.250.162:9507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/about.php"] [unique_id "amuX3YJkCYmL5o6vh9JzKQAAAJ8"]
[Thu Jul 30 13:28:45.739042 2026] [security2:error] [pid 890219:tid 890376] [client 20.79.250.162:9507] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/about.php"] [unique_id "amuX3YJkCYmL5o6vh9JzKQAAAJ8"]
[Thu Jul 30 13:28:46.058663 2026] [security2:error] [pid 890219:tid 890441] [client 20.79.250.162:6343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuX3oJkCYmL5o6vh9JzLgAAAOA"]
[Thu Jul 30 13:28:46.058786 2026] [security2:error] [pid 890219:tid 890441] [client 20.79.250.162:6343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuX3oJkCYmL5o6vh9JzLgAAAOA"]
[Thu Jul 30 13:28:46.335109 2026] [security2:error] [pid 890219:tid 890358] [client 20.79.250.162:9582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/ta0ol.php"] [unique_id "amuX3oJkCYmL5o6vh9JzNQAAAI0"]
[Thu Jul 30 13:28:46.335230 2026] [security2:error] [pid 890219:tid 890358] [client 20.79.250.162:9582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/ta0ol.php"] [unique_id "amuX3oJkCYmL5o6vh9JzNQAAAI0"]
[Thu Jul 30 13:28:46.606971 2026] [security2:error] [pid 890219:tid 890434] [client 20.79.250.162:9594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/sa.php7"] [unique_id "amuX3oJkCYmL5o6vh9JzPAAAANk"]
[Thu Jul 30 13:28:46.607093 2026] [security2:error] [pid 890219:tid 890434] [client 20.79.250.162:9594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/sa.php7"] [unique_id "amuX3oJkCYmL5o6vh9JzPAAAANk"]
[Thu Jul 30 13:28:46.885768 2026] [proxy:error] [pid 890219:tid 890457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:46.885845 2026] [proxy_http:error] [pid 890219:tid 890457] [client 17.241.75.237:44614] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:46.886416 2026] [proxy:error] [pid 890219:tid 890457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:46.886471 2026] [proxy_http:error] [pid 890219:tid 890457] [client 17.241.75.237:44614] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:46.892398 2026] [security2:error] [pid 890219:tid 890421] [client 20.79.250.162:6369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-class.php"] [unique_id "amuX3oJkCYmL5o6vh9JzRgAAAMw"]
[Thu Jul 30 13:28:46.892477 2026] [security2:error] [pid 890219:tid 890421] [client 20.79.250.162:6369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-class.php"] [unique_id "amuX3oJkCYmL5o6vh9JzRgAAAMw"]
[Thu Jul 30 13:28:47.166041 2026] [security2:error] [pid 890219:tid 890469] [client 20.79.250.162:9495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/8.php"] [unique_id "amuX34JkCYmL5o6vh9JzUQAAAPw"]
[Thu Jul 30 13:28:47.166134 2026] [security2:error] [pid 890219:tid 890469] [client 20.79.250.162:9495] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/8.php"] [unique_id "amuX34JkCYmL5o6vh9JzUQAAAPw"]
[Thu Jul 30 13:28:47.428091 2026] [security2:error] [pid 890219:tid 890401] [client 20.79.250.162:9524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/bootstrap.php"] [unique_id "amuX34JkCYmL5o6vh9JzWAAAALg"]
[Thu Jul 30 13:28:47.428215 2026] [security2:error] [pid 890219:tid 890401] [client 20.79.250.162:9524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/bootstrap.php"] [unique_id "amuX34JkCYmL5o6vh9JzWAAAALg"]
[Thu Jul 30 13:28:47.472877 2026] [core:notice] [pid 890219:tid 890458] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:28:47.675456 2026] [security2:error] [pid 890219:tid 890404] [client 185.191.171.12:51798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/02/23/em-araruna-bandidos-assaltam-posto-de-combustiveis/"] [unique_id "amuX34JkCYmL5o6vh9JzWwAAALs"]
[Thu Jul 30 13:28:47.675593 2026] [security2:error] [pid 890219:tid 890404] [client 185.191.171.12:51798] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/02/23/em-araruna-bandidos-assaltam-posto-de-combustiveis/"] [unique_id "amuX34JkCYmL5o6vh9JzWwAAALs"]
[Thu Jul 30 13:28:47.702988 2026] [security2:error] [pid 890219:tid 890439] [client 20.79.250.162:9590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-blog-header.php"] [unique_id "amuX34JkCYmL5o6vh9JzXgAAAN4"]
[Thu Jul 30 13:28:47.703085 2026] [security2:error] [pid 890219:tid 890439] [client 20.79.250.162:9590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-blog-header.php"] [unique_id "amuX34JkCYmL5o6vh9JzXgAAAN4"]
[Thu Jul 30 13:28:47.814143 2026] [security2:error] [pid 890219:tid 890402] [client 20.91.199.21:11020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/wp-signin.php"] [unique_id "amuX34JkCYmL5o6vh9JzYgAAALk"]
[Thu Jul 30 13:28:47.968814 2026] [security2:error] [pid 890219:tid 890465] [client 20.79.250.162:9554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/aa.php"] [unique_id "amuX34JkCYmL5o6vh9JzaAAAAPg"]
[Thu Jul 30 13:28:47.968927 2026] [security2:error] [pid 890219:tid 890465] [client 20.79.250.162:9554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/aa.php"] [unique_id "amuX34JkCYmL5o6vh9JzaAAAAPg"]
[Thu Jul 30 13:28:48.042055 2026] [proxy:error] [pid 890219:tid 890317] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:48.042113 2026] [proxy_http:error] [pid 890219:tid 890317] [remote 74.7.228.59:57430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:48.042928 2026] [proxy:error] [pid 890219:tid 890317] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:28:48.043022 2026] [proxy_http:error] [pid 890219:tid 890317] [remote 74.7.228.59:57430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:28:48.250207 2026] [security2:error] [pid 890219:tid 890372] [client 20.79.250.162:9527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/tx79.php"] [unique_id "amuX4IJkCYmL5o6vh9JzcAAAAJs"]
[Thu Jul 30 13:28:48.250290 2026] [security2:error] [pid 890219:tid 890372] [client 20.79.250.162:9527] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/tx79.php"] [unique_id "amuX4IJkCYmL5o6vh9JzcAAAAJs"]
[Thu Jul 30 13:28:48.513287 2026] [security2:error] [pid 890219:tid 890452] [client 20.79.250.162:9523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/motu.php"] [unique_id "amuX4IJkCYmL5o6vh9JzdAAAAOs"]
[Thu Jul 30 13:28:48.513420 2026] [security2:error] [pid 890219:tid 890452] [client 20.79.250.162:9523] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/motu.php"] [unique_id "amuX4IJkCYmL5o6vh9JzdAAAAOs"]
[Thu Jul 30 13:28:48.550662 2026] [security2:error] [pid 890219:tid 890396] [client 74.7.241.131:39832] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "xjj.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuX4IJkCYmL5o6vh9JzdQAAs1Q"]
[Thu Jul 30 13:28:48.552271 2026] [security2:error] [pid 890219:tid 890403] [client 20.91.199.21:39064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/simi.php"] [unique_id "amuX4IJkCYmL5o6vh9JzdwAAALo"]
[Thu Jul 30 13:28:48.823956 2026] [security2:error] [pid 890219:tid 890436] [client 20.79.250.162:9536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-head.php"] [unique_id "amuX4IJkCYmL5o6vh9JzhAAAANs"]
[Thu Jul 30 13:28:48.824069 2026] [security2:error] [pid 890219:tid 890436] [client 20.79.250.162:9536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-head.php"] [unique_id "amuX4IJkCYmL5o6vh9JzhAAAANs"]
[Thu Jul 30 13:28:49.148541 2026] [security2:error] [pid 890219:tid 890477] [client 20.79.250.162:9544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuX4YJkCYmL5o6vh9JziAAAAQQ"]
[Thu Jul 30 13:28:49.148702 2026] [security2:error] [pid 890219:tid 890477] [client 20.79.250.162:9544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuX4YJkCYmL5o6vh9JziAAAAQQ"]
[Thu Jul 30 13:28:49.419614 2026] [security2:error] [pid 890219:tid 890424] [client 20.79.250.162:9518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/60856e3a4findex.php"] [unique_id "amuX4YJkCYmL5o6vh9JzjwAAAM8"]
[Thu Jul 30 13:28:49.419727 2026] [security2:error] [pid 890219:tid 890424] [client 20.79.250.162:9518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/60856e3a4findex.php"] [unique_id "amuX4YJkCYmL5o6vh9JzjwAAAM8"]
[Thu Jul 30 13:28:49.698260 2026] [security2:error] [pid 890219:tid 890463] [client 20.79.250.162:9589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp-the.php"] [unique_id "amuX4YJkCYmL5o6vh9JzlgAAAPY"]
[Thu Jul 30 13:28:49.698382 2026] [security2:error] [pid 890219:tid 890463] [client 20.79.250.162:9589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp-the.php"] [unique_id "amuX4YJkCYmL5o6vh9JzlgAAAPY"]
[Thu Jul 30 13:28:49.965384 2026] [security2:error] [pid 890219:tid 890401] [client 20.79.250.162:9474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wp.php"] [unique_id "amuX4YJkCYmL5o6vh9JznQAAALg"]
[Thu Jul 30 13:28:49.965506 2026] [security2:error] [pid 890219:tid 890401] [client 20.79.250.162:9474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wp.php"] [unique_id "amuX4YJkCYmL5o6vh9JznQAAALg"]
[Thu Jul 30 13:28:50.141372 2026] [security2:error] [pid 890219:tid 890427] [client 20.91.199.21:19651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/wp-conf.php"] [unique_id "amuX4oJkCYmL5o6vh9Jz6gAAANI"]
[Thu Jul 30 13:28:50.311865 2026] [security2:error] [pid 890219:tid 890380] [client 119.73.97.132:29613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuX4oJkCYmL5o6vh9Jz0QAAoxk"], referer: https://www.urwru.club/wp-admin/upload.php
[Thu Jul 30 13:28:50.339787 2026] [security2:error] [pid 890219:tid 890375] [client 20.79.250.162:9472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/users.php"] [unique_id "amuX4oJkCYmL5o6vh9Jz7gAAAJ4"]
[Thu Jul 30 13:28:50.339867 2026] [security2:error] [pid 890219:tid 890375] [client 20.79.250.162:9472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/users.php"] [unique_id "amuX4oJkCYmL5o6vh9Jz7gAAAJ4"]
[Thu Jul 30 13:28:50.601507 2026] [security2:error] [pid 890219:tid 890466] [client 20.79.250.162:9531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/tinysd.php"] [unique_id "amuX4oJkCYmL5o6vh9Jz9gAAAPk"]
[Thu Jul 30 13:28:50.601610 2026] [security2:error] [pid 890219:tid 890466] [client 20.79.250.162:9531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/tinysd.php"] [unique_id "amuX4oJkCYmL5o6vh9Jz9gAAAPk"]
[Thu Jul 30 13:28:50.869400 2026] [security2:error] [pid 890219:tid 890471] [client 20.79.250.162:6352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/ws78.php"] [unique_id "amuX4oJkCYmL5o6vh9Jz-gAAAP4"]
[Thu Jul 30 13:28:50.869517 2026] [security2:error] [pid 890219:tid 890471] [client 20.79.250.162:6352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/ws78.php"] [unique_id "amuX4oJkCYmL5o6vh9Jz-gAAAP4"]
[Thu Jul 30 13:28:51.136048 2026] [security2:error] [pid 890219:tid 890388] [client 20.79.250.162:9588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/elp.php"] [unique_id "amuX44JkCYmL5o6vh9J0CAAAAKs"]
[Thu Jul 30 13:28:51.136153 2026] [security2:error] [pid 890219:tid 890388] [client 20.79.250.162:9588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/elp.php"] [unique_id "amuX44JkCYmL5o6vh9J0CAAAAKs"]
[Thu Jul 30 13:28:51.440486 2026] [security2:error] [pid 890219:tid 890382] [client 20.79.250.162:9530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/atomlib.php"] [unique_id "amuX44JkCYmL5o6vh9J0EgAAAKU"]
[Thu Jul 30 13:28:51.440581 2026] [security2:error] [pid 890219:tid 890382] [client 20.79.250.162:9530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/atomlib.php"] [unique_id "amuX44JkCYmL5o6vh9J0EgAAAKU"]
[Thu Jul 30 13:28:51.465613 2026] [security2:error] [pid 890219:tid 890431] [client 20.91.199.21:34933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuX44JkCYmL5o6vh9J0EwAAANY"]
[Thu Jul 30 13:28:51.708520 2026] [security2:error] [pid 890219:tid 890442] [client 20.79.250.162:9513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/wyzer3.php"] [unique_id "amuX44JkCYmL5o6vh9J0FwAAAOE"]
[Thu Jul 30 13:28:51.708627 2026] [security2:error] [pid 890219:tid 890442] [client 20.79.250.162:9513] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/wyzer3.php"] [unique_id "amuX44JkCYmL5o6vh9J0FwAAAOE"]
[Thu Jul 30 13:28:51.978557 2026] [security2:error] [pid 890219:tid 890424] [client 20.79.250.162:9511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/max.php"] [unique_id "amuX44JkCYmL5o6vh9J0HgAAAM8"]
[Thu Jul 30 13:28:51.978659 2026] [security2:error] [pid 890219:tid 890424] [client 20.79.250.162:9511] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/max.php"] [unique_id "amuX44JkCYmL5o6vh9J0HgAAAM8"]
[Thu Jul 30 13:28:52.241893 2026] [security2:error] [pid 890219:tid 890412] [client 20.79.250.162:9599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.250.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nimna.lk"] [uri "/ftde.php"] [unique_id "amuX5IJkCYmL5o6vh9J0JQAAAMM"]
[Thu Jul 30 13:28:52.242015 2026] [security2:error] [pid 890219:tid 890412] [client 20.79.250.162:9599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.nimna.lk"] [uri "/ftde.php"] [unique_id "amuX5IJkCYmL5o6vh9J0JQAAAMM"]
[Thu Jul 30 13:28:52.841544 2026] [security2:error] [pid 890219:tid 890366] [client 20.91.199.21:35247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/bala.php"] [unique_id "amuX5IJkCYmL5o6vh9J0MgAAAJU"]
[Thu Jul 30 13:28:53.207384 2026] [security2:error] [pid 890219:tid 890373] [client 179.64.21.229:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuX5YJkCYmL5o6vh9J0PAAAAJw"]
[Thu Jul 30 13:28:53.207543 2026] [security2:error] [pid 890219:tid 890373] [client 179.64.21.229:43104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuX5YJkCYmL5o6vh9J0PAAAAJw"]
[Thu Jul 30 13:28:55.613677 2026] [security2:error] [pid 890219:tid 890381] [client 20.91.199.21:10285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/bk.php"] [unique_id "amuX54JkCYmL5o6vh9J0aQAAAKQ"]
[Thu Jul 30 13:28:56.442898 2026] [security2:error] [pid 890219:tid 890472] [client 127.0.0.1:18526] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuX6IJkCYmL5o6vh9J0fQAAAP8"]
[Thu Jul 30 13:28:56.443043 2026] [security2:error] [pid 890219:tid 890373] [client 127.0.0.1:18510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ahm.djb.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuX6IJkCYmL5o6vh9J0fAAAAJw"]
[Thu Jul 30 13:28:56.443095 2026] [security2:error] [pid 890219:tid 890356] [client 74.7.244.18:33698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ahm.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuX6IJkCYmL5o6vh9J0ewAAi2k"]
[Thu Jul 30 13:28:56.977330 2026] [core:error] [pid 890219:tid 890394] [client 2a03:2880:16ff:44:::0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:28:56.977356 2026] [core:error] [pid 890219:tid 890394] [client 2a03:2880:16ff:44:::0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:28:57.062225 2026] [security2:error] [pid 890219:tid 890458] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuX6IJkCYmL5o6vh9J0fgAA8V4"]
[Thu Jul 30 13:28:57.644313 2026] [security2:error] [pid 890219:tid 890431] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuX6IJkCYmL5o6vh9J0lwAAANY"]
[Thu Jul 30 13:28:58.923018 2026] [security2:error] [pid 890219:tid 890476] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuX6oJkCYmL5o6vh9J0xQAAAQM"]
[Thu Jul 30 13:29:01.714139 2026] [security2:error] [pid 890219:tid 890471] [client 172.236.9.101:3246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX7YJkCYmL5o6vh9J1BAAAAP4"]
[Thu Jul 30 13:29:02.213216 2026] [core:notice] [pid 890219:tid 890258] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:02.374005 2026] [security2:error] [pid 890219:tid 890415] [client 172.236.9.101:18111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/app_dev.php/_profiler/empty/search/results"] [unique_id "amuX7oJkCYmL5o6vh9J1IwAAAMY"]
[Thu Jul 30 13:29:02.419517 2026] [security2:error] [pid 890219:tid 890398] [client 20.91.199.21:19658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cnpinyin.com"] [uri "/ahax.php"] [unique_id "amuX7oJkCYmL5o6vh9J1HgAAALU"]
[Thu Jul 30 13:29:03.428700 2026] [security2:error] [pid 890219:tid 890430] [client 172.236.9.101:3955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/index.php/_profiler/empty/search/results"] [unique_id "amuX74JkCYmL5o6vh9J1PwAAANU"]
[Thu Jul 30 13:29:03.909201 2026] [security2:error] [pid 890219:tid 890399] [client 179.64.21.229:27345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuX74JkCYmL5o6vh9J1SAAAALY"]
[Thu Jul 30 13:29:03.909352 2026] [security2:error] [pid 890219:tid 890399] [client 179.64.21.229:27345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuX74JkCYmL5o6vh9J1SAAAALY"]
[Thu Jul 30 13:29:04.366735 2026] [security2:error] [pid 890219:tid 890467] [client 172.236.9.101:52273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/index_dev.php/_profiler/empty/search/results"] [unique_id "amuX8IJkCYmL5o6vh9J1XQAAAPo"]
[Thu Jul 30 13:29:04.473086 2026] [security2:error] [pid 890219:tid 890416] [client 172.237.109.114:10739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX74JkCYmL5o6vh9J1TAAAAMc"]
[Thu Jul 30 13:29:05.357855 2026] [security2:error] [pid 890219:tid 890397] [client 172.236.9.101:23324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/dev.php/_profiler/empty/search/results"] [unique_id "amuX8YJkCYmL5o6vh9J1dAAAALQ"]
[Thu Jul 30 13:29:05.832917 2026] [core:notice] [pid 890219:tid 890363] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:05.999824 2026] [core:notice] [pid 890219:tid 890269] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:06.042585 2026] [core:notice] [pid 890219:tid 890292] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:06.434008 2026] [security2:error] [pid 890219:tid 890354] [client 172.236.9.101:40378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/debug.php/_profiler/empty/search/results"] [unique_id "amuX8oJkCYmL5o6vh9J1iwAAAIk"]
[Thu Jul 30 13:29:07.413531 2026] [security2:error] [pid 890219:tid 890370] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuX8oJkCYmL5o6vh9J1lAAAmRc"]
[Thu Jul 30 13:29:07.691565 2026] [security2:error] [pid 890219:tid 890433] [client 172.236.9.101:59169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX84JkCYmL5o6vh9J1qgAAANg"]
[Thu Jul 30 13:29:08.651501 2026] [security2:error] [pid 890219:tid 890400] [client 185.12.149.40:48139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "azureskyfilms.com"] [uri "/wp-login.php"] [unique_id "amuX8oJkCYmL5o6vh9J1jwAAALc"]
[Thu Jul 30 13:29:08.659075 2026] [security2:error] [pid 890219:tid 890378] [client 172.236.9.101:14331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX9IJkCYmL5o6vh9J1vwAAAKE"]
[Thu Jul 30 13:29:09.658618 2026] [proxy:error] [pid 890219:tid 890450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:09.658686 2026] [proxy_http:error] [pid 890219:tid 890450] [client 44.216.125.112:55173] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:09.659339 2026] [proxy:error] [pid 890219:tid 890450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:09.659389 2026] [proxy_http:error] [pid 890219:tid 890450] [client 44.216.125.112:55173] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:09.663299 2026] [proxy:error] [pid 890219:tid 890380] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:09.663369 2026] [proxy_http:error] [pid 890219:tid 890380] [client 18.211.55.47:45725] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:09.664211 2026] [proxy:error] [pid 890219:tid 890380] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:09.664272 2026] [proxy_http:error] [pid 890219:tid 890380] [client 18.211.55.47:45725] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:09.733655 2026] [security2:error] [pid 890219:tid 890355] [client 172.236.9.101:44445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX9YJkCYmL5o6vh9J11wAAAIo"]
[Thu Jul 30 13:29:10.403400 2026] [security2:error] [pid 890219:tid 890452] [client 172.236.9.101:63894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/frontend_dev.php/_profiler/empty/search/results"] [unique_id "amuX9oJkCYmL5o6vh9J2BAAAAOs"]
[Thu Jul 30 13:29:11.372113 2026] [security2:error] [pid 890219:tid 890416] [client 172.236.9.101:38996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/backend_dev.php/_profiler/empty/search/results"] [unique_id "amuX94JkCYmL5o6vh9J2HQAAAMc"]
[Thu Jul 30 13:29:11.578942 2026] [core:notice] [pid 890219:tid 890346] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:11.603417 2026] [core:notice] [pid 890219:tid 890337] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:12.381997 2026] [security2:error] [pid 890219:tid 890388] [client 172.236.9.101:1664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/api_dev.php/_profiler/empty/search/results"] [unique_id "amuX-IJkCYmL5o6vh9J2NgAAAKs"]
[Thu Jul 30 13:29:13.372190 2026] [security2:error] [pid 890219:tid 890383] [client 172.236.9.101:30187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/app.php/_profiler/empty/search/results"] [unique_id "amuX-YJkCYmL5o6vh9J2SwAAAKY"]
[Thu Jul 30 13:29:14.357345 2026] [security2:error] [pid 890219:tid 890400] [client 172.236.9.101:38695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/app_test.php/_profiler/empty/search/results"] [unique_id "amuX-oJkCYmL5o6vh9J2XwAAALc"]
[Thu Jul 30 13:29:15.124799 2026] [proxy:error] [pid 890219:tid 890476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:15.124877 2026] [proxy_http:error] [pid 890219:tid 890476] [client 34.224.175.62:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:15.125598 2026] [proxy:error] [pid 890219:tid 890476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:15.125650 2026] [proxy_http:error] [pid 890219:tid 890476] [client 34.224.175.62:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:15.401747 2026] [security2:error] [pid 890219:tid 890426] [client 172.236.9.101:29578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.9.236.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/test.php/_profiler/empty/search/results"] [unique_id "amuX-4JkCYmL5o6vh9J2fQAAANE"]
[Thu Jul 30 13:29:15.990573 2026] [security2:error] [pid 890219:tid 890423] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuX-4JkCYmL5o6vh9J2fAAAAM4"]
[Thu Jul 30 13:29:16.164611 2026] [proxy:error] [pid 890219:tid 890411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:16.164706 2026] [proxy_http:error] [pid 890219:tid 890411] [client 32.194.121.99:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:16.166125 2026] [proxy:error] [pid 890219:tid 890411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:16.166189 2026] [proxy_http:error] [pid 890219:tid 890411] [client 32.194.121.99:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:16.376853 2026] [security2:error] [pid 890219:tid 890472] [client 185.191.171.2:53606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/22/colombiano-e-assassinado-a-tiros-no-bairro-colinas-do-sul-em-jp-um-dia-antes-de-voltar-para-o-seu-pais/"] [unique_id "amuX_IJkCYmL5o6vh9J2lgAAAP8"]
[Thu Jul 30 13:29:16.376994 2026] [security2:error] [pid 890219:tid 890472] [client 185.191.171.2:53606] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/22/colombiano-e-assassinado-a-tiros-no-bairro-colinas-do-sul-em-jp-um-dia-antes-de-voltar-para-o-seu-pais/"] [unique_id "amuX_IJkCYmL5o6vh9J2lgAAAP8"]
[Thu Jul 30 13:29:16.806820 2026] [security2:error] [pid 890219:tid 890417] [client 172.236.9.101:33463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX_IJkCYmL5o6vh9J2lwAAAMg"]
[Thu Jul 30 13:29:17.108867 2026] [core:notice] [pid 890219:tid 890467] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:17.219692 2026] [security2:error] [pid 890219:tid 890267] [remote 57.141.0.23:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuX_YJkCYmL5o6vh9J2sAAAjC4"]
[Thu Jul 30 13:29:17.569341 2026] [security2:error] [pid 890219:tid 890381] [client 74.7.175.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcalendars.mza.djb.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/404.html"] [unique_id "amuX_YJkCYmL5o6vh9J2ugAAAKQ"]
[Thu Jul 30 13:29:17.569932 2026] [security2:error] [pid 890219:tid 890392] [client 74.7.175.172:39764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcalendars.mza.djb.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuX_YJkCYmL5o6vh9J2uAAAry0"]
[Thu Jul 30 13:29:17.650212 2026] [security2:error] [pid 890219:tid 890421] [client 172.236.9.101:15079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX_YJkCYmL5o6vh9J2twAAAMw"]
[Thu Jul 30 13:29:18.040485 2026] [security2:error] [pid 890219:tid 890270] [remote 57.141.0.40:37348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amuX_oJkCYmL5o6vh9J2yQAAlTE"]
[Thu Jul 30 13:29:18.650512 2026] [security2:error] [pid 890219:tid 890432] [client 172.236.9.101:23803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX_oJkCYmL5o6vh9J21gAAANc"]
[Thu Jul 30 13:29:19.306402 2026] [core:notice] [pid 890219:tid 890444] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:19.666949 2026] [security2:error] [pid 890219:tid 890462] [client 172.236.9.101:41764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuX_4JkCYmL5o6vh9J26wAAAPU"]
[Thu Jul 30 13:29:21.789700 2026] [core:notice] [pid 890219:tid 890297] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:24.251923 2026] [security2:error] [pid 890219:tid 890467] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYA4JkCYmL5o6vh9J3RQAA-lM"]
[Thu Jul 30 13:29:25.092953 2026] [security2:error] [pid 890219:tid 890400] [client 179.64.21.229:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYBYJkCYmL5o6vh9J3XgAAALc"]
[Thu Jul 30 13:29:25.093075 2026] [security2:error] [pid 890219:tid 890400] [client 179.64.21.229:4436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYBYJkCYmL5o6vh9J3XgAAALc"]
[Thu Jul 30 13:29:27.135060 2026] [security2:error] [pid 890219:tid 890397] [client 159.65.142.59:60691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.142.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-login.php"] [unique_id "amuYB4JkCYmL5o6vh9J3gwAAALQ"]
[Thu Jul 30 13:29:27.419876 2026] [core:notice] [pid 890219:tid 890376] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:27.454087 2026] [security2:error] [pid 890219:tid 890338] [remote 198.244.226.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "propertyspro.com"] [uri "/contact-us/"] [unique_id "amuYB4JkCYmL5o6vh9J3lwAA33U"]
[Thu Jul 30 13:29:27.454303 2026] [security2:error] [pid 890219:tid 890440] [client 198.244.226.250:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "propertyspro.com"] [uri "/contact-us/"] [unique_id "amuYB4JkCYmL5o6vh9J3lwAA33U"]
[Thu Jul 30 13:29:28.033153 2026] [security2:error] [pid 890219:tid 890459] [client 74.7.175.166:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bio.djb.temporary.site"] [uri "/index.php"] [unique_id "amuYB4JkCYmL5o6vh9J3owAAAPI"]
[Thu Jul 30 13:29:28.033891 2026] [security2:error] [pid 890219:tid 890388] [client 74.7.175.166:59434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bio.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuYB4JkCYmL5o6vh9J3oQAAq3w"]
[Thu Jul 30 13:29:28.136306 2026] [security2:error] [pid 890219:tid 890449] [client 68.235.48.108:56836] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuYCIJkCYmL5o6vh9J3sgAAAOg"]
[Thu Jul 30 13:29:28.136426 2026] [security2:error] [pid 890219:tid 890449] [client 68.235.48.108:56836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuYCIJkCYmL5o6vh9J3sgAAAOg"]
[Thu Jul 30 13:29:29.390320 2026] [core:notice] [pid 890219:tid 890223] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:29.508638 2026] [security2:error] [pid 890219:tid 890396] [client 74.7.230.26:43750] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-eab6feff.his.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuYCYJkCYmL5o6vh9J38AAAALM"]
[Thu Jul 30 13:29:30.074597 2026] [security2:error] [pid 890219:tid 890437] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYCYJkCYmL5o6vh9J37wAAANw"]
[Thu Jul 30 13:29:31.104622 2026] [security2:error] [pid 890219:tid 890407] [client 159.65.142.59:62025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.142.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-login.php"] [unique_id "amuYC4JkCYmL5o6vh9J4EwAAAL4"]
[Thu Jul 30 13:29:31.603383 2026] [security2:error] [pid 890219:tid 890467] [client 172.237.109.114:23815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuYC4JkCYmL5o6vh9J4DgAAAPo"]
[Thu Jul 30 13:29:31.776882 2026] [core:notice] [pid 890219:tid 890257] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:31.825286 2026] [core:notice] [pid 890219:tid 890255] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:32.684346 2026] [security2:error] [pid 890219:tid 890390] [client 127.0.0.1:14730] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuYDIJkCYmL5o6vh9J4OQAAAK0"]
[Thu Jul 30 13:29:32.684353 2026] [security2:error] [pid 890219:tid 890434] [client 74.7.241.143:55800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.frg.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuYDIJkCYmL5o6vh9J4OAAAANk"]
[Thu Jul 30 13:29:35.304728 2026] [security2:error] [pid 890219:tid 890474] [client 74.7.228.46:50960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "zbj.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuYD4JkCYmL5o6vh9J4bwAAAQE"]
[Thu Jul 30 13:29:35.405851 2026] [security2:error] [pid 890219:tid 890352] [client 179.64.21.229:56930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYD4JkCYmL5o6vh9J4dAAAAIc"]
[Thu Jul 30 13:29:35.405996 2026] [security2:error] [pid 890219:tid 890352] [client 179.64.21.229:56930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYD4JkCYmL5o6vh9J4dAAAAIc"]
[Thu Jul 30 13:29:35.905417 2026] [security2:error] [pid 890219:tid 890435] [client 68.235.48.108:53980] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuYD4JkCYmL5o6vh9J4gAAAANo"]
[Thu Jul 30 13:29:35.905522 2026] [security2:error] [pid 890219:tid 890435] [client 68.235.48.108:53980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuYD4JkCYmL5o6vh9J4gAAAANo"]
[Thu Jul 30 13:29:36.135583 2026] [core:notice] [pid 890219:tid 890234] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:38.347297 2026] [core:notice] [pid 890219:tid 890269] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:38.568262 2026] [security2:error] [pid 890219:tid 890393] [client 185.189.112.19:59252] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuYEoJkCYmL5o6vh9J4vAAAALA"]
[Thu Jul 30 13:29:38.568426 2026] [security2:error] [pid 890219:tid 890393] [client 185.189.112.19:59252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuYEoJkCYmL5o6vh9J4vAAAALA"]
[Thu Jul 30 13:29:40.274740 2026] [security2:error] [pid 890219:tid 890428] [client 54.37.118.86:51300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "globalmarks.pk"] [uri "/robots.txt"] [unique_id "amuYFIJkCYmL5o6vh9J44AAAANM"]
[Thu Jul 30 13:29:40.274866 2026] [security2:error] [pid 890219:tid 890428] [client 54.37.118.86:51300] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "globalmarks.pk"] [uri "/robots.txt"] [unique_id "amuYFIJkCYmL5o6vh9J44AAAANM"]
[Thu Jul 30 13:29:41.641567 2026] [security2:error] [pid 890219:tid 890432] [client 54.37.118.83:38672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "globalmarks.pk"] [uri "/"] [unique_id "amuYFYJkCYmL5o6vh9J5DAAAANc"]
[Thu Jul 30 13:29:41.641653 2026] [security2:error] [pid 890219:tid 890432] [client 54.37.118.83:38672] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "globalmarks.pk"] [uri "/"] [unique_id "amuYFYJkCYmL5o6vh9J5DAAAANc"]
[Thu Jul 30 13:29:42.817816 2026] [security2:error] [pid 890219:tid 890403] [client 134.19.179.131:38706] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYFoJkCYmL5o6vh9J5IwAAALo"]
[Thu Jul 30 13:29:42.817958 2026] [security2:error] [pid 890219:tid 890403] [client 134.19.179.131:38706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYFoJkCYmL5o6vh9J5IwAAALo"]
[Thu Jul 30 13:29:43.146686 2026] [core:notice] [pid 890219:tid 890345] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:44.421349 2026] [security2:error] [pid 890219:tid 890379] [client 52.167.144.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYFoJkCYmL5o6vh9J5HwAAAKI"]
[Thu Jul 30 13:29:45.994668 2026] [security2:error] [pid 890219:tid 890420] [client 179.64.21.229:18984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYGYJkCYmL5o6vh9J5ewAAAMs"]
[Thu Jul 30 13:29:45.994824 2026] [security2:error] [pid 890219:tid 890420] [client 179.64.21.229:18984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYGYJkCYmL5o6vh9J5ewAAAMs"]
[Thu Jul 30 13:29:46.152580 2026] [core:notice] [pid 890219:tid 890262] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:46.438839 2026] [security2:error] [pid 890219:tid 890447] [client 52.167.144.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYGoJkCYmL5o6vh9J5fwAAAOY"]
[Thu Jul 30 13:29:47.954340 2026] [security2:error] [pid 890219:tid 890477] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYG4JkCYmL5o6vh9J5oQAAAQQ"]
[Thu Jul 30 13:29:48.067820 2026] [security2:error] [pid 890219:tid 890368] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYG4JkCYmL5o6vh9J5pwAAAJc"]
[Thu Jul 30 13:29:48.437781 2026] [core:notice] [pid 890219:tid 890277] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:48.746123 2026] [security2:error] [pid 890219:tid 890355] [client 74.7.244.59:33848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.rqc.hfl.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuYHIJkCYmL5o6vh9J5vgAAAIo"]
[Thu Jul 30 13:29:49.917398 2026] [proxy:error] [pid 890219:tid 890377] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:49.917479 2026] [proxy_http:error] [pid 890219:tid 890377] [client 32.194.121.99:12244] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:49.918048 2026] [proxy:error] [pid 890219:tid 890377] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:49.918094 2026] [proxy_http:error] [pid 890219:tid 890377] [client 32.194.121.99:12244] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:49.924869 2026] [proxy:error] [pid 890219:tid 890368] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:49.924928 2026] [proxy_http:error] [pid 890219:tid 890368] [client 32.194.121.99:37622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:49.925491 2026] [proxy:error] [pid 890219:tid 890368] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:29:49.925536 2026] [proxy_http:error] [pid 890219:tid 890368] [client 32.194.121.99:37622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:29:52.816233 2026] [core:notice] [pid 890219:tid 890318] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:53.140097 2026] [security2:error] [pid 890219:tid 890435] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYIIJkCYmL5o6vh9J6NwAAANo"]
[Thu Jul 30 13:29:53.851744 2026] [core:notice] [pid 890219:tid 890321] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:54.026296 2026] [security2:error] [pid 890219:tid 890470] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYIYJkCYmL5o6vh9J6SAAAAP0"]
[Thu Jul 30 13:29:54.487769 2026] [core:notice] [pid 890219:tid 890326] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:54.671853 2026] [security2:error] [pid 890219:tid 890459] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYIoJkCYmL5o6vh9J6ZAAAAPI"]
[Thu Jul 30 13:29:56.729759 2026] [security2:error] [pid 890219:tid 890412] [client 179.64.21.229:22166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYJIJkCYmL5o6vh9J6lQAAAMM"]
[Thu Jul 30 13:29:56.737786 2026] [security2:error] [pid 890219:tid 890412] [client 179.64.21.229:22166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYJIJkCYmL5o6vh9J6lQAAAMM"]
[Thu Jul 30 13:29:57.215398 2026] [security2:error] [pid 890219:tid 890380] [client 40.77.167.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYJIJkCYmL5o6vh9J6nAAAAKM"]
[Thu Jul 30 13:29:58.093485 2026] [core:notice] [pid 890219:tid 890373] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:29:58.716953 2026] [security2:error] [pid 890219:tid 890472] [client 172.237.109.114:11961] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuYJoJkCYmL5o6vh9J6uQAAAP8"]
[Thu Jul 30 13:30:00.491391 2026] [security2:error] [pid 890219:tid 890262] [remote 40.77.167.149:10914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/blog/post/job.php"] [unique_id "amuYKIJkCYmL5o6vh9J68gAA8Sk"]
[Thu Jul 30 13:30:01.397427 2026] [autoindex:error] [pid 890219:tid 890367] [client 32.194.121.99:4938] AH01276: Cannot serve directory /home2/qnjgzjte/hris.rgserve.ph/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:30:01.535539 2026] [core:notice] [pid 890219:tid 890418] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:03.893051 2026] [security2:error] [pid 890219:tid 890452] [client 185.156.175.51:55292] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuYK4JkCYmL5o6vh9J7NQAAAOs"]
[Thu Jul 30 13:30:03.893175 2026] [security2:error] [pid 890219:tid 890452] [client 185.156.175.51:55292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuYK4JkCYmL5o6vh9J7NQAAAOs"]
[Thu Jul 30 13:30:04.597110 2026] [core:error] [pid 890219:tid 890222] [remote 216.73.217.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:30:04.597136 2026] [core:error] [pid 890219:tid 890222] [remote 216.73.217.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:30:05.692606 2026] [security2:error] [pid 890219:tid 890288] [remote 192.250.239.84:48548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.239.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYLYJkCYmL5o6vh9J7aAAAi0M"]
[Thu Jul 30 13:30:05.692765 2026] [security2:error] [pid 890219:tid 890356] [client 192.250.239.84:48548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYLYJkCYmL5o6vh9J7aAAAi0M"]
[Thu Jul 30 13:30:05.703154 2026] [core:error] [pid 890219:tid 890299] [remote 216.73.217.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:30:05.703174 2026] [core:error] [pid 890219:tid 890299] [remote 216.73.217.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:30:07.078794 2026] [security2:error] [pid 890219:tid 890423] [client 179.64.21.229:10671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYL4JkCYmL5o6vh9J7hgAAAM4"]
[Thu Jul 30 13:30:07.090940 2026] [security2:error] [pid 890219:tid 890423] [client 179.64.21.229:10671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYL4JkCYmL5o6vh9J7hgAAAM4"]
[Thu Jul 30 13:30:07.363422 2026] [security2:error] [pid 890219:tid 890453] [client 20.203.200.218:51737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/65.php"] [unique_id "amuYL4JkCYmL5o6vh9J7swAAAOw"]
[Thu Jul 30 13:30:07.363534 2026] [security2:error] [pid 890219:tid 890453] [client 20.203.200.218:51737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/65.php"] [unique_id "amuYL4JkCYmL5o6vh9J7swAAAOw"]
[Thu Jul 30 13:30:07.629701 2026] [security2:error] [pid 890219:tid 890417] [client 20.203.200.218:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/64.php"] [unique_id "amuYL4JkCYmL5o6vh9J71QAAAMg"]
[Thu Jul 30 13:30:07.629807 2026] [security2:error] [pid 890219:tid 890417] [client 20.203.200.218:62433] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/64.php"] [unique_id "amuYL4JkCYmL5o6vh9J71QAAAMg"]
[Thu Jul 30 13:30:07.887761 2026] [security2:error] [pid 890219:tid 890356] [client 20.203.200.218:51716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/63.php"] [unique_id "amuYL4JkCYmL5o6vh9J72gAAAIs"]
[Thu Jul 30 13:30:07.887865 2026] [security2:error] [pid 890219:tid 890356] [client 20.203.200.218:51716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/63.php"] [unique_id "amuYL4JkCYmL5o6vh9J72gAAAIs"]
[Thu Jul 30 13:30:08.141238 2026] [security2:error] [pid 890219:tid 890443] [client 20.203.200.218:62418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/62.php"] [unique_id "amuYMIJkCYmL5o6vh9J74QAAAOI"]
[Thu Jul 30 13:30:08.141340 2026] [security2:error] [pid 890219:tid 890443] [client 20.203.200.218:62418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/62.php"] [unique_id "amuYMIJkCYmL5o6vh9J74QAAAOI"]
[Thu Jul 30 13:30:08.398002 2026] [security2:error] [pid 890219:tid 890451] [client 20.203.200.218:52221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/61.php"] [unique_id "amuYMIJkCYmL5o6vh9J75wAAAOo"]
[Thu Jul 30 13:30:08.398141 2026] [security2:error] [pid 890219:tid 890451] [client 20.203.200.218:52221] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/61.php"] [unique_id "amuYMIJkCYmL5o6vh9J75wAAAOo"]
[Thu Jul 30 13:30:08.439198 2026] [core:notice] [pid 890219:tid 890364] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:08.665796 2026] [security2:error] [pid 890219:tid 890375] [client 20.203.200.218:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/60.php"] [unique_id "amuYMIJkCYmL5o6vh9J77wAAAJ4"]
[Thu Jul 30 13:30:08.665900 2026] [security2:error] [pid 890219:tid 890375] [client 20.203.200.218:52162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/60.php"] [unique_id "amuYMIJkCYmL5o6vh9J77wAAAJ4"]
[Thu Jul 30 13:30:08.919993 2026] [security2:error] [pid 890219:tid 890433] [client 20.203.200.218:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/58.php"] [unique_id "amuYMIJkCYmL5o6vh9J78wAAANg"]
[Thu Jul 30 13:30:08.920148 2026] [security2:error] [pid 890219:tid 890433] [client 20.203.200.218:62419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/58.php"] [unique_id "amuYMIJkCYmL5o6vh9J78wAAANg"]
[Thu Jul 30 13:30:09.184171 2026] [security2:error] [pid 890219:tid 890351] [client 20.203.200.218:52182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/59.php"] [unique_id "amuYMYJkCYmL5o6vh9J7_QAAAIY"]
[Thu Jul 30 13:30:09.184306 2026] [security2:error] [pid 890219:tid 890351] [client 20.203.200.218:52182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/59.php"] [unique_id "amuYMYJkCYmL5o6vh9J7_QAAAIY"]
[Thu Jul 30 13:30:09.373417 2026] [security2:error] [pid 890219:tid 890368] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYMIJkCYmL5o6vh9J75gAAlzU"]
[Thu Jul 30 13:30:09.440294 2026] [security2:error] [pid 890219:tid 890406] [client 20.203.200.218:51741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/57.php/56.php"] [unique_id "amuYMYJkCYmL5o6vh9J8AwAAAL0"]
[Thu Jul 30 13:30:09.440397 2026] [security2:error] [pid 890219:tid 890406] [client 20.203.200.218:51741] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/57.php/56.php"] [unique_id "amuYMYJkCYmL5o6vh9J8AwAAAL0"]
[Thu Jul 30 13:30:09.714278 2026] [security2:error] [pid 890219:tid 890446] [client 20.203.200.218:52222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/55.php"] [unique_id "amuYMYJkCYmL5o6vh9J8DgAAAOU"]
[Thu Jul 30 13:30:09.714367 2026] [security2:error] [pid 890219:tid 890446] [client 20.203.200.218:52222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/55.php"] [unique_id "amuYMYJkCYmL5o6vh9J8DgAAAOU"]
[Thu Jul 30 13:30:09.838414 2026] [security2:error] [pid 890219:tid 890394] [client 43.172.195.69:55930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amuYMYJkCYmL5o6vh9J8BwAAALE"]
[Thu Jul 30 13:30:09.969158 2026] [security2:error] [pid 890219:tid 890367] [client 20.203.200.218:61155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/54.php"] [unique_id "amuYMYJkCYmL5o6vh9J8DwAAAJY"]
[Thu Jul 30 13:30:09.969267 2026] [security2:error] [pid 890219:tid 890367] [client 20.203.200.218:61155] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/54.php"] [unique_id "amuYMYJkCYmL5o6vh9J8DwAAAJY"]
[Thu Jul 30 13:30:10.263660 2026] [security2:error] [pid 890219:tid 890450] [client 20.203.200.218:52186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/53.php"] [unique_id "amuYMoJkCYmL5o6vh9J8FgAAAOk"]
[Thu Jul 30 13:30:10.263752 2026] [security2:error] [pid 890219:tid 890450] [client 20.203.200.218:52186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/53.php"] [unique_id "amuYMoJkCYmL5o6vh9J8FgAAAOk"]
[Thu Jul 30 13:30:10.458999 2026] [core:notice] [pid 890219:tid 890462] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:10.464507 2026] [security2:error] [pid 890219:tid 890462] [client 43.172.194.193:39318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amuYMoJkCYmL5o6vh9J8HgAAAPU"], referer: https://carnetdeshopping.com/index.php/typography/
[Thu Jul 30 13:30:10.515020 2026] [security2:error] [pid 890219:tid 890375] [client 20.203.200.218:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/52.php"] [unique_id "amuYMoJkCYmL5o6vh9J8IAAAAJ4"]
[Thu Jul 30 13:30:10.515135 2026] [security2:error] [pid 890219:tid 890375] [client 20.203.200.218:61175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/52.php"] [unique_id "amuYMoJkCYmL5o6vh9J8IAAAAJ4"]
[Thu Jul 30 13:30:10.768244 2026] [security2:error] [pid 890219:tid 890403] [client 20.203.200.218:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/51.php"] [unique_id "amuYMoJkCYmL5o6vh9J8KgAAALo"]
[Thu Jul 30 13:30:10.768358 2026] [security2:error] [pid 890219:tid 890403] [client 20.203.200.218:62438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/51.php"] [unique_id "amuYMoJkCYmL5o6vh9J8KgAAALo"]
[Thu Jul 30 13:30:10.898364 2026] [security2:error] [pid 890219:tid 890373] [client 216.73.216.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.guardian-heir.com"] [uri "/index.php"] [unique_id "amuYMYJkCYmL5o6vh9J8AgAAnAM"]
[Thu Jul 30 13:30:11.026770 2026] [security2:error] [pid 890219:tid 890425] [client 20.203.200.218:52183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/50.php"] [unique_id "amuYM4JkCYmL5o6vh9J8MgAAANA"]
[Thu Jul 30 13:30:11.026877 2026] [security2:error] [pid 890219:tid 890425] [client 20.203.200.218:52183] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/50.php"] [unique_id "amuYM4JkCYmL5o6vh9J8MgAAANA"]
[Thu Jul 30 13:30:11.315414 2026] [security2:error] [pid 890219:tid 890411] [client 20.203.200.218:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/49.php"] [unique_id "amuYM4JkCYmL5o6vh9J8RQAAAMI"]
[Thu Jul 30 13:30:11.315528 2026] [security2:error] [pid 890219:tid 890411] [client 20.203.200.218:61125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/49.php"] [unique_id "amuYM4JkCYmL5o6vh9J8RQAAAMI"]
[Thu Jul 30 13:30:11.570750 2026] [security2:error] [pid 890219:tid 890455] [client 20.203.200.218:61135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/48.php"] [unique_id "amuYM4JkCYmL5o6vh9J8RwAAAO4"]
[Thu Jul 30 13:30:11.570854 2026] [security2:error] [pid 890219:tid 890455] [client 20.203.200.218:61135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/48.php"] [unique_id "amuYM4JkCYmL5o6vh9J8RwAAAO4"]
[Thu Jul 30 13:30:11.822752 2026] [security2:error] [pid 890219:tid 890462] [client 20.203.200.218:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/47.php"] [unique_id "amuYM4JkCYmL5o6vh9J8TwAAAPU"]
[Thu Jul 30 13:30:11.822914 2026] [security2:error] [pid 890219:tid 890462] [client 20.203.200.218:62462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/47.php"] [unique_id "amuYM4JkCYmL5o6vh9J8TwAAAPU"]
[Thu Jul 30 13:30:12.074059 2026] [security2:error] [pid 890219:tid 890466] [client 20.203.200.218:52214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/46.php"] [unique_id "amuYNIJkCYmL5o6vh9J8UwAAAPk"]
[Thu Jul 30 13:30:12.074180 2026] [security2:error] [pid 890219:tid 890466] [client 20.203.200.218:52214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/46.php"] [unique_id "amuYNIJkCYmL5o6vh9J8UwAAAPk"]
[Thu Jul 30 13:30:12.323217 2026] [security2:error] [pid 890219:tid 890458] [client 20.203.200.218:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/44.php"] [unique_id "amuYNIJkCYmL5o6vh9J8XwAAAPE"]
[Thu Jul 30 13:30:12.323311 2026] [security2:error] [pid 890219:tid 890458] [client 20.203.200.218:51726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/44.php"] [unique_id "amuYNIJkCYmL5o6vh9J8XwAAAPE"]
[Thu Jul 30 13:30:12.616553 2026] [security2:error] [pid 890219:tid 890369] [client 20.203.200.218:61122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/43.php"] [unique_id "amuYNIJkCYmL5o6vh9J8ZAAAAJg"]
[Thu Jul 30 13:30:12.616666 2026] [security2:error] [pid 890219:tid 890369] [client 20.203.200.218:61122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/43.php"] [unique_id "amuYNIJkCYmL5o6vh9J8ZAAAAJg"]
[Thu Jul 30 13:30:12.882716 2026] [security2:error] [pid 890219:tid 890379] [client 20.203.200.218:61137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/42.php"] [unique_id "amuYNIJkCYmL5o6vh9J8bgAAAKI"]
[Thu Jul 30 13:30:12.882826 2026] [security2:error] [pid 890219:tid 890379] [client 20.203.200.218:61137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/42.php"] [unique_id "amuYNIJkCYmL5o6vh9J8bgAAAKI"]
[Thu Jul 30 13:30:12.982921 2026] [security2:error] [pid 890219:tid 890434] [client 51.38.177.7:49570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "milfordauto.com"] [uri "/"] [unique_id "amuYNIJkCYmL5o6vh9J8cgAAANk"]
[Thu Jul 30 13:30:13.139414 2026] [security2:error] [pid 890219:tid 890469] [client 20.203.200.218:62423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/41.php"] [unique_id "amuYNYJkCYmL5o6vh9J8dAAAAPw"]
[Thu Jul 30 13:30:13.139539 2026] [security2:error] [pid 890219:tid 890469] [client 20.203.200.218:62423] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/41.php"] [unique_id "amuYNYJkCYmL5o6vh9J8dAAAAPw"]
[Thu Jul 30 13:30:13.277176 2026] [core:notice] [pid 890219:tid 890302] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:13.389595 2026] [security2:error] [pid 890219:tid 890392] [client 20.203.200.218:52210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/40.php"] [unique_id "amuYNYJkCYmL5o6vh9J8fQAAAK8"]
[Thu Jul 30 13:30:13.389703 2026] [security2:error] [pid 890219:tid 890392] [client 20.203.200.218:52210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/40.php"] [unique_id "amuYNYJkCYmL5o6vh9J8fQAAAK8"]
[Thu Jul 30 13:30:13.692318 2026] [security2:error] [pid 890219:tid 890418] [client 20.203.200.218:52169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/39.php"] [unique_id "amuYNYJkCYmL5o6vh9J8hgAAAMk"]
[Thu Jul 30 13:30:13.692419 2026] [security2:error] [pid 890219:tid 890418] [client 20.203.200.218:52169] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/39.php"] [unique_id "amuYNYJkCYmL5o6vh9J8hgAAAMk"]
[Thu Jul 30 13:30:13.738059 2026] [security2:error] [pid 890219:tid 890423] [client 94.154.43.188:63636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "arabiandubaisafari.com"] [uri "/.env"] [unique_id "amuYNYJkCYmL5o6vh9J8iAAAAM4"]
[Thu Jul 30 13:30:13.945730 2026] [security2:error] [pid 890219:tid 890465] [client 20.203.200.218:61150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/38.php"] [unique_id "amuYNYJkCYmL5o6vh9J8jAAAAPg"]
[Thu Jul 30 13:30:13.945851 2026] [security2:error] [pid 890219:tid 890465] [client 20.203.200.218:61150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/38.php"] [unique_id "amuYNYJkCYmL5o6vh9J8jAAAAPg"]
[Thu Jul 30 13:30:14.220479 2026] [security2:error] [pid 890219:tid 890374] [client 20.203.200.218:52196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/37.php"] [unique_id "amuYNoJkCYmL5o6vh9J8kAAAAJ0"]
[Thu Jul 30 13:30:14.220621 2026] [security2:error] [pid 890219:tid 890374] [client 20.203.200.218:52196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/37.php"] [unique_id "amuYNoJkCYmL5o6vh9J8kAAAAJ0"]
[Thu Jul 30 13:30:14.266236 2026] [security2:error] [pid 890219:tid 890476] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYNYJkCYmL5o6vh9J8dQABA10"]
[Thu Jul 30 13:30:14.305185 2026] [security2:error] [pid 890219:tid 890366] [client 94.154.43.179:42098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dhowcruisedinner.com"] [uri "/.env"] [unique_id "amuYNoJkCYmL5o6vh9J8lAAAAJU"]
[Thu Jul 30 13:30:14.445354 2026] [security2:error] [pid 890219:tid 890422] [client 94.154.43.179:42112] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "arabiantourz.com"] [uri "/.env"] [unique_id "amuYNoJkCYmL5o6vh9J8mAAAAM0"]
[Thu Jul 30 13:30:14.488163 2026] [security2:error] [pid 890219:tid 890446] [client 20.203.200.218:52219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/36.php"] [unique_id "amuYNoJkCYmL5o6vh9J8nAAAAOU"]
[Thu Jul 30 13:30:14.488270 2026] [security2:error] [pid 890219:tid 890446] [client 20.203.200.218:52219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/36.php"] [unique_id "amuYNoJkCYmL5o6vh9J8nAAAAOU"]
[Thu Jul 30 13:30:14.796421 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:61179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/35.php"] [unique_id "amuYNoJkCYmL5o6vh9J8owAAALU"]
[Thu Jul 30 13:30:14.796520 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:61179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/35.php"] [unique_id "amuYNoJkCYmL5o6vh9J8owAAALU"]
[Thu Jul 30 13:30:15.071250 2026] [security2:error] [pid 890219:tid 890449] [client 20.203.200.218:61145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/34.php"] [unique_id "amuYN4JkCYmL5o6vh9J8qgAAAOg"]
[Thu Jul 30 13:30:15.071404 2026] [security2:error] [pid 890219:tid 890449] [client 20.203.200.218:61145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/34.php"] [unique_id "amuYN4JkCYmL5o6vh9J8qgAAAOg"]
[Thu Jul 30 13:30:15.343414 2026] [security2:error] [pid 890219:tid 890462] [client 20.203.200.218:61173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/33.php"] [unique_id "amuYN4JkCYmL5o6vh9J8sAAAAPU"]
[Thu Jul 30 13:30:15.343545 2026] [security2:error] [pid 890219:tid 890462] [client 20.203.200.218:61173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/33.php"] [unique_id "amuYN4JkCYmL5o6vh9J8sAAAAPU"]
[Thu Jul 30 13:30:15.598676 2026] [security2:error] [pid 890219:tid 890423] [client 20.203.200.218:51722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/25.php"] [unique_id "amuYN4JkCYmL5o6vh9J8uAAAAM4"]
[Thu Jul 30 13:30:15.598804 2026] [security2:error] [pid 890219:tid 890423] [client 20.203.200.218:51722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/25.php"] [unique_id "amuYN4JkCYmL5o6vh9J8uAAAAM4"]
[Thu Jul 30 13:30:15.858594 2026] [security2:error] [pid 890219:tid 890424] [client 20.203.200.218:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/24.php"] [unique_id "amuYN4JkCYmL5o6vh9J8wAAAAM8"]
[Thu Jul 30 13:30:15.858723 2026] [security2:error] [pid 890219:tid 890424] [client 20.203.200.218:52218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/24.php"] [unique_id "amuYN4JkCYmL5o6vh9J8wAAAAM8"]
[Thu Jul 30 13:30:16.124411 2026] [security2:error] [pid 890219:tid 890377] [client 20.203.200.218:61153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/15.php"] [unique_id "amuYOIJkCYmL5o6vh9J8xwAAAKA"]
[Thu Jul 30 13:30:16.124520 2026] [security2:error] [pid 890219:tid 890377] [client 20.203.200.218:61153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/15.php"] [unique_id "amuYOIJkCYmL5o6vh9J8xwAAAKA"]
[Thu Jul 30 13:30:16.177295 2026] [proxy:error] [pid 890219:tid 890472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:16.177372 2026] [proxy_http:error] [pid 890219:tid 890472] [client 193.47.62.167:38982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:16.178204 2026] [proxy:error] [pid 890219:tid 890472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:16.178258 2026] [proxy_http:error] [pid 890219:tid 890472] [client 193.47.62.167:38982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:16.264300 2026] [security2:error] [pid 890219:tid 890456] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYN4JkCYmL5o6vh9J8vAAAAO8"]
[Thu Jul 30 13:30:16.396275 2026] [security2:error] [pid 890219:tid 890459] [client 20.203.200.218:51743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/123456.php"] [unique_id "amuYOIJkCYmL5o6vh9J8zgAAAPI"]
[Thu Jul 30 13:30:16.396398 2026] [security2:error] [pid 890219:tid 890459] [client 20.203.200.218:51743] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/123456.php"] [unique_id "amuYOIJkCYmL5o6vh9J8zgAAAPI"]
[Thu Jul 30 13:30:16.554395 2026] [security2:error] [pid 890219:tid 890369] [client 216.73.216.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guardian-heir.com"] [uri "/index.php"] [unique_id "amuYOIJkCYmL5o6vh9J8zQAAmHU"]
[Thu Jul 30 13:30:16.649850 2026] [security2:error] [pid 890219:tid 890378] [client 20.203.200.218:61142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/12345.php"] [unique_id "amuYOIJkCYmL5o6vh9J82QAAAKE"]
[Thu Jul 30 13:30:16.649959 2026] [security2:error] [pid 890219:tid 890378] [client 20.203.200.218:61142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/12345.php"] [unique_id "amuYOIJkCYmL5o6vh9J82QAAAKE"]
[Thu Jul 30 13:30:16.702950 2026] [security2:error] [pid 890219:tid 890315] [remote 116.179.37.3:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuYOIJkCYmL5o6vh9J8zwAAxV4"], referer: https://nafmedical.com/blog/blog-lateral/
[Thu Jul 30 13:30:16.908525 2026] [security2:error] [pid 890219:tid 890435] [client 20.203.200.218:52185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/1234.php"] [unique_id "amuYOIJkCYmL5o6vh9J83gAAANo"]
[Thu Jul 30 13:30:16.908620 2026] [security2:error] [pid 890219:tid 890435] [client 20.203.200.218:52185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/1234.php"] [unique_id "amuYOIJkCYmL5o6vh9J83gAAANo"]
[Thu Jul 30 13:30:16.948493 2026] [security2:error] [pid 890219:tid 890465] [client 68.235.48.108:47536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuYOIJkCYmL5o6vh9J84AAAAPg"]
[Thu Jul 30 13:30:16.948578 2026] [security2:error] [pid 890219:tid 890465] [client 68.235.48.108:47536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuYOIJkCYmL5o6vh9J84AAAAPg"]
[Thu Jul 30 13:30:17.071483 2026] [security2:error] [pid 890219:tid 890361] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYOIJkCYmL5o6vh9J80gAAAJA"]
[Thu Jul 30 13:30:17.172119 2026] [security2:error] [pid 890219:tid 890341] [remote 116.179.37.154:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuYOIJkCYmL5o6vh9J83wAAqHg"], referer: https://nafmedical.com/blog/blog-lateral/
[Thu Jul 30 13:30:17.173875 2026] [security2:error] [pid 890219:tid 890476] [client 20.203.200.218:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/10.php"] [unique_id "amuYOYJkCYmL5o6vh9J86AAAAQM"]
[Thu Jul 30 13:30:17.173955 2026] [security2:error] [pid 890219:tid 890476] [client 20.203.200.218:62406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/10.php"] [unique_id "amuYOYJkCYmL5o6vh9J86AAAAQM"]
[Thu Jul 30 13:30:17.247166 2026] [security2:error] [pid 890219:tid 890346] [remote 57.141.0.20:43194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuYOYJkCYmL5o6vh9J86wAAq30"]
[Thu Jul 30 13:30:17.251230 2026] [core:notice] [pid 890219:tid 890223] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:17.436590 2026] [security2:error] [pid 890219:tid 890422] [client 20.203.200.218:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/9.php"] [unique_id "amuYOYJkCYmL5o6vh9J88AAAAM0"]
[Thu Jul 30 13:30:17.436677 2026] [security2:error] [pid 890219:tid 890422] [client 20.203.200.218:62463] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/9.php"] [unique_id "amuYOYJkCYmL5o6vh9J88AAAAM0"]
[Thu Jul 30 13:30:17.537580 2026] [security2:error] [pid 890219:tid 890419] [client 50.6.43.217:35176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amuYKoJkCYmL5o6vh9J7EAAAAMo"]
[Thu Jul 30 13:30:17.618820 2026] [security2:error] [pid 890219:tid 890366] [client 179.64.21.229:59159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYOYJkCYmL5o6vh9J88QAAAJU"]
[Thu Jul 30 13:30:17.630507 2026] [security2:error] [pid 890219:tid 890366] [client 179.64.21.229:59159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYOYJkCYmL5o6vh9J88QAAAJU"]
[Thu Jul 30 13:30:17.687052 2026] [security2:error] [pid 890219:tid 890438] [client 20.203.200.218:61147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/8.php"] [unique_id "amuYOYJkCYmL5o6vh9J89QAAAN0"]
[Thu Jul 30 13:30:17.687164 2026] [security2:error] [pid 890219:tid 890438] [client 20.203.200.218:61147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/8.php"] [unique_id "amuYOYJkCYmL5o6vh9J89QAAAN0"]
[Thu Jul 30 13:30:17.989489 2026] [security2:error] [pid 890219:tid 890355] [client 20.203.200.218:51735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/7.php"] [unique_id "amuYOYJkCYmL5o6vh9J8_AAAAIo"]
[Thu Jul 30 13:30:17.989601 2026] [security2:error] [pid 890219:tid 890355] [client 20.203.200.218:51735] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/7.php"] [unique_id "amuYOYJkCYmL5o6vh9J8_AAAAIo"]
[Thu Jul 30 13:30:18.265699 2026] [security2:error] [pid 890219:tid 890371] [client 20.203.200.218:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/6.php"] [unique_id "amuYOoJkCYmL5o6vh9J9AAAAAJo"]
[Thu Jul 30 13:30:18.265797 2026] [security2:error] [pid 890219:tid 890371] [client 20.203.200.218:61120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/6.php"] [unique_id "amuYOoJkCYmL5o6vh9J9AAAAAJo"]
[Thu Jul 30 13:30:18.446492 2026] [proxy:error] [pid 890219:tid 890466] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:18.446582 2026] [proxy_http:error] [pid 890219:tid 890466] [client 32.194.121.99:38701] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:18.447375 2026] [proxy:error] [pid 890219:tid 890466] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:18.447431 2026] [proxy_http:error] [pid 890219:tid 890466] [client 32.194.121.99:38701] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:18.453872 2026] [proxy:error] [pid 890219:tid 890461] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:18.453935 2026] [proxy_http:error] [pid 890219:tid 890461] [client 34.224.175.62:60548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:18.454544 2026] [proxy:error] [pid 890219:tid 890461] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:18.454594 2026] [proxy_http:error] [pid 890219:tid 890461] [client 34.224.175.62:60548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:18.515592 2026] [security2:error] [pid 890219:tid 890440] [client 20.203.200.218:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/5.php"] [unique_id "amuYOoJkCYmL5o6vh9J9EAAAAN8"]
[Thu Jul 30 13:30:18.515714 2026] [security2:error] [pid 890219:tid 890440] [client 20.203.200.218:52216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/5.php"] [unique_id "amuYOoJkCYmL5o6vh9J9EAAAAN8"]
[Thu Jul 30 13:30:18.766717 2026] [security2:error] [pid 890219:tid 890397] [client 20.203.200.218:52190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/4.php"] [unique_id "amuYOoJkCYmL5o6vh9J9FAAAALQ"]
[Thu Jul 30 13:30:18.766815 2026] [security2:error] [pid 890219:tid 890397] [client 20.203.200.218:52190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/4.php"] [unique_id "amuYOoJkCYmL5o6vh9J9FAAAALQ"]
[Thu Jul 30 13:30:19.038059 2026] [security2:error] [pid 890219:tid 890374] [client 20.203.200.218:52189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/3.php"] [unique_id "amuYO4JkCYmL5o6vh9J9GwAAAJ0"]
[Thu Jul 30 13:30:19.038200 2026] [security2:error] [pid 890219:tid 890374] [client 20.203.200.218:52189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/3.php"] [unique_id "amuYO4JkCYmL5o6vh9J9GwAAAJ0"]
[Thu Jul 30 13:30:19.302952 2026] [security2:error] [pid 890219:tid 890432] [client 20.203.200.218:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/2.php"] [unique_id "amuYO4JkCYmL5o6vh9J9IgAAANc"]
[Thu Jul 30 13:30:19.303062 2026] [security2:error] [pid 890219:tid 890432] [client 20.203.200.218:62412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/2.php"] [unique_id "amuYO4JkCYmL5o6vh9J9IgAAANc"]
[Thu Jul 30 13:30:19.563802 2026] [security2:error] [pid 890219:tid 890477] [client 20.203.200.218:52165] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/1.php"] [unique_id "amuYO4JkCYmL5o6vh9J9JgAAAQQ"]
[Thu Jul 30 13:30:19.563916 2026] [security2:error] [pid 890219:tid 890477] [client 20.203.200.218:52165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/1.php"] [unique_id "amuYO4JkCYmL5o6vh9J9JgAAAQQ"]
[Thu Jul 30 13:30:19.564019 2026] [security2:error] [pid 890219:tid 890477] [client 20.203.200.218:52165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/1.php"] [unique_id "amuYO4JkCYmL5o6vh9J9JgAAAQQ"]
[Thu Jul 30 13:30:19.817235 2026] [security2:error] [pid 890219:tid 890364] [client 20.203.200.218:51717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/0.php"] [unique_id "amuYO4JkCYmL5o6vh9J9LwAAAJM"]
[Thu Jul 30 13:30:19.817318 2026] [security2:error] [pid 890219:tid 890364] [client 20.203.200.218:51717] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/0.php"] [unique_id "amuYO4JkCYmL5o6vh9J9LwAAAJM"]
[Thu Jul 30 13:30:20.107830 2026] [security2:error] [pid 890219:tid 890462] [client 20.203.200.218:62402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/z.php"] [unique_id "amuYPIJkCYmL5o6vh9J9NAAAAPU"]
[Thu Jul 30 13:30:20.107948 2026] [security2:error] [pid 890219:tid 890462] [client 20.203.200.218:62402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/z.php"] [unique_id "amuYPIJkCYmL5o6vh9J9NAAAAPU"]
[Thu Jul 30 13:30:20.365057 2026] [security2:error] [pid 890219:tid 890375] [client 20.203.200.218:62427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/y.php"] [unique_id "amuYPIJkCYmL5o6vh9J9OwAAAJ4"]
[Thu Jul 30 13:30:20.365184 2026] [security2:error] [pid 890219:tid 890375] [client 20.203.200.218:62427] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/y.php"] [unique_id "amuYPIJkCYmL5o6vh9J9OwAAAJ4"]
[Thu Jul 30 13:30:20.617309 2026] [security2:error] [pid 890219:tid 890410] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYO4JkCYmL5o6vh9J9MAAAwRg"]
[Thu Jul 30 13:30:20.628325 2026] [security2:error] [pid 890219:tid 890441] [client 20.203.200.218:61180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/x.php"] [unique_id "amuYPIJkCYmL5o6vh9J9PwAAAOA"]
[Thu Jul 30 13:30:20.628405 2026] [security2:error] [pid 890219:tid 890441] [client 20.203.200.218:61180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/x.php"] [unique_id "amuYPIJkCYmL5o6vh9J9PwAAAOA"]
[Thu Jul 30 13:30:20.885470 2026] [security2:error] [pid 890219:tid 890388] [client 20.203.200.218:52200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/w.php"] [unique_id "amuYPIJkCYmL5o6vh9J9SwAAAKs"]
[Thu Jul 30 13:30:20.885555 2026] [security2:error] [pid 890219:tid 890388] [client 20.203.200.218:52200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/w.php"] [unique_id "amuYPIJkCYmL5o6vh9J9SwAAAKs"]
[Thu Jul 30 13:30:21.135651 2026] [security2:error] [pid 890219:tid 890422] [client 20.203.200.218:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/v.php"] [unique_id "amuYPYJkCYmL5o6vh9J9TgAAAM0"]
[Thu Jul 30 13:30:21.135751 2026] [security2:error] [pid 890219:tid 890422] [client 20.203.200.218:62458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/v.php"] [unique_id "amuYPYJkCYmL5o6vh9J9TgAAAM0"]
[Thu Jul 30 13:30:21.409501 2026] [security2:error] [pid 890219:tid 890477] [client 20.203.200.218:45547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/u.php"] [unique_id "amuYPYJkCYmL5o6vh9J9WAAAAQQ"]
[Thu Jul 30 13:30:21.409604 2026] [security2:error] [pid 890219:tid 890477] [client 20.203.200.218:45547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/u.php"] [unique_id "amuYPYJkCYmL5o6vh9J9WAAAAQQ"]
[Thu Jul 30 13:30:21.581120 2026] [security2:error] [pid 890219:tid 890456] [client 74.7.244.59:50456] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-ae2db365.ais.njr.temporary.site"] [uri "/robots.txt"] [unique_id "amuYPYJkCYmL5o6vh9J9WgAAAO8"]
[Thu Jul 30 13:30:21.717703 2026] [security2:error] [pid 890219:tid 890383] [client 20.203.200.218:61180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/s.php"] [unique_id "amuYPYJkCYmL5o6vh9J9XgAAAKY"]
[Thu Jul 30 13:30:21.717805 2026] [security2:error] [pid 890219:tid 890383] [client 20.203.200.218:61180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/s.php"] [unique_id "amuYPYJkCYmL5o6vh9J9XgAAAKY"]
[Thu Jul 30 13:30:21.966846 2026] [security2:error] [pid 890219:tid 890380] [client 20.203.200.218:51714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/t.php"] [unique_id "amuYPYJkCYmL5o6vh9J9ZQAAAKM"]
[Thu Jul 30 13:30:21.966934 2026] [security2:error] [pid 890219:tid 890380] [client 20.203.200.218:51714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/t.php"] [unique_id "amuYPYJkCYmL5o6vh9J9ZQAAAKM"]
[Thu Jul 30 13:30:22.199688 2026] [security2:error] [pid 890219:tid 890373] [client 74.7.241.150:41242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vdb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuYPIJkCYmL5o6vh9J9SgAAnF8"]
[Thu Jul 30 13:30:22.224039 2026] [security2:error] [pid 890219:tid 890461] [client 20.203.200.218:52171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/r.php"] [unique_id "amuYPoJkCYmL5o6vh9J9bwAAAPQ"]
[Thu Jul 30 13:30:22.224358 2026] [security2:error] [pid 890219:tid 890461] [client 20.203.200.218:52171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/r.php"] [unique_id "amuYPoJkCYmL5o6vh9J9bwAAAPQ"]
[Thu Jul 30 13:30:22.495503 2026] [security2:error] [pid 890219:tid 890421] [client 20.203.200.218:61141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/q.php"] [unique_id "amuYPoJkCYmL5o6vh9J9fgAAAMw"]
[Thu Jul 30 13:30:22.495598 2026] [security2:error] [pid 890219:tid 890421] [client 20.203.200.218:61141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/q.php"] [unique_id "amuYPoJkCYmL5o6vh9J9fgAAAMw"]
[Thu Jul 30 13:30:22.745190 2026] [security2:error] [pid 890219:tid 890439] [client 20.203.200.218:52177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/p.php"] [unique_id "amuYPoJkCYmL5o6vh9J9ggAAAN4"]
[Thu Jul 30 13:30:22.745283 2026] [security2:error] [pid 890219:tid 890439] [client 20.203.200.218:52177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/p.php"] [unique_id "amuYPoJkCYmL5o6vh9J9ggAAAN4"]
[Thu Jul 30 13:30:22.952756 2026] [security2:error] [pid 890219:tid 890353] [client 127.0.0.1:11712] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuYPoJkCYmL5o6vh9J9iQAAAIg"]
[Thu Jul 30 13:30:22.952798 2026] [security2:error] [pid 890219:tid 890394] [client 127.0.0.1:11700] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.vvr.hfl.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuYPoJkCYmL5o6vh9J9iAAAALE"]
[Thu Jul 30 13:30:22.952926 2026] [security2:error] [pid 890219:tid 890363] [client 74.7.175.140:32930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.vvr.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuYPoJkCYmL5o6vh9J9hwAAkhA"]
[Thu Jul 30 13:30:22.997650 2026] [security2:error] [pid 890219:tid 890446] [client 20.203.200.218:52178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/n.php"] [unique_id "amuYPoJkCYmL5o6vh9J9kAAAAOU"]
[Thu Jul 30 13:30:22.997750 2026] [security2:error] [pid 890219:tid 890446] [client 20.203.200.218:52178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/n.php"] [unique_id "amuYPoJkCYmL5o6vh9J9kAAAAOU"]
[Thu Jul 30 13:30:23.104239 2026] [security2:error] [pid 890219:tid 890457] [client 82.102.18.188:44972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuYP4JkCYmL5o6vh9J9kQAAAPA"]
[Thu Jul 30 13:30:23.280838 2026] [security2:error] [pid 890219:tid 890420] [client 20.203.200.218:61129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/o.php"] [unique_id "amuYP4JkCYmL5o6vh9J9lQAAAMs"]
[Thu Jul 30 13:30:23.280946 2026] [security2:error] [pid 890219:tid 890420] [client 20.203.200.218:61129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/o.php"] [unique_id "amuYP4JkCYmL5o6vh9J9lQAAAMs"]
[Thu Jul 30 13:30:23.387894 2026] [security2:error] [pid 890219:tid 890431] [client 82.102.18.188:44986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.psz.dtn.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuYP4JkCYmL5o6vh9J9lgAAANY"]
[Thu Jul 30 13:30:23.497182 2026] [security2:error] [pid 890219:tid 890246] [remote 57.141.0.49:21718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuYP4JkCYmL5o6vh9J9ngABABk"]
[Thu Jul 30 13:30:23.529788 2026] [security2:error] [pid 890219:tid 890447] [client 20.203.200.218:52193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/m.php"] [unique_id "amuYP4JkCYmL5o6vh9J9nwAAAOY"]
[Thu Jul 30 13:30:23.529884 2026] [security2:error] [pid 890219:tid 890447] [client 20.203.200.218:52193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/m.php"] [unique_id "amuYP4JkCYmL5o6vh9J9nwAAAOY"]
[Thu Jul 30 13:30:23.691912 2026] [security2:error] [pid 890219:tid 890405] [client 82.102.18.188:44990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuYP4JkCYmL5o6vh9J9owAAALw"]
[Thu Jul 30 13:30:23.796373 2026] [security2:error] [pid 890219:tid 890401] [client 20.203.200.218:51712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/l.php"] [unique_id "amuYP4JkCYmL5o6vh9J9qgAAALg"]
[Thu Jul 30 13:30:23.796468 2026] [security2:error] [pid 890219:tid 890401] [client 20.203.200.218:51712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/l.php"] [unique_id "amuYP4JkCYmL5o6vh9J9qgAAALg"]
[Thu Jul 30 13:30:23.995003 2026] [security2:error] [pid 890219:tid 890409] [client 82.102.18.188:49344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuYP4JkCYmL5o6vh9J9rgAAAMA"]
[Thu Jul 30 13:30:24.062423 2026] [core:notice] [pid 890219:tid 890224] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:24.064150 2026] [security2:error] [pid 890219:tid 890410] [client 20.203.200.218:45172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/k.php"] [unique_id "amuYQIJkCYmL5o6vh9J9sgAAAME"]
[Thu Jul 30 13:30:24.064223 2026] [security2:error] [pid 890219:tid 890410] [client 20.203.200.218:45172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/k.php"] [unique_id "amuYQIJkCYmL5o6vh9J9sgAAAME"]
[Thu Jul 30 13:30:24.272071 2026] [security2:error] [pid 890219:tid 890407] [client 82.102.18.188:49352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuYQIJkCYmL5o6vh9J9twAAAL4"]
[Thu Jul 30 13:30:24.331520 2026] [security2:error] [pid 890219:tid 890369] [client 20.203.200.218:51720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/j.php"] [unique_id "amuYQIJkCYmL5o6vh9J9uAAAAJg"]
[Thu Jul 30 13:30:24.331620 2026] [security2:error] [pid 890219:tid 890369] [client 20.203.200.218:51720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/j.php"] [unique_id "amuYQIJkCYmL5o6vh9J9uAAAAJg"]
[Thu Jul 30 13:30:24.531379 2026] [security2:error] [pid 890219:tid 890468] [client 82.102.18.188:49360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuYQIJkCYmL5o6vh9J9ugAAAPs"]
[Thu Jul 30 13:30:24.587231 2026] [security2:error] [pid 890219:tid 890363] [client 20.203.200.218:52217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/i.php"] [unique_id "amuYQIJkCYmL5o6vh9J9wAAAAJI"]
[Thu Jul 30 13:30:24.587341 2026] [security2:error] [pid 890219:tid 890363] [client 20.203.200.218:52217] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/i.php"] [unique_id "amuYQIJkCYmL5o6vh9J9wAAAAJI"]
[Thu Jul 30 13:30:24.733807 2026] [core:notice] [pid 890219:tid 890287] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:24.788570 2026] [security2:error] [pid 890219:tid 890386] [client 82.102.18.188:49370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuYQIJkCYmL5o6vh9J9yAAAAKk"]
[Thu Jul 30 13:30:24.840494 2026] [security2:error] [pid 890219:tid 890411] [client 20.203.200.218:52211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/h.php"] [unique_id "amuYQIJkCYmL5o6vh9J9yQAAAMI"]
[Thu Jul 30 13:30:24.840585 2026] [security2:error] [pid 890219:tid 890411] [client 20.203.200.218:52211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/h.php"] [unique_id "amuYQIJkCYmL5o6vh9J9yQAAAMI"]
[Thu Jul 30 13:30:25.049720 2026] [security2:error] [pid 890219:tid 890444] [client 82.102.18.188:49372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuYQYJkCYmL5o6vh9J9zQAAAOM"]
[Thu Jul 30 13:30:25.099510 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:61133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/g.php"] [unique_id "amuYQYJkCYmL5o6vh9J90QAAALU"]
[Thu Jul 30 13:30:25.099625 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:61133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/g.php"] [unique_id "amuYQYJkCYmL5o6vh9J90QAAALU"]
[Thu Jul 30 13:30:25.357505 2026] [security2:error] [pid 890219:tid 890391] [client 20.203.200.218:61183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/f.php"] [unique_id "amuYQYJkCYmL5o6vh9J91gAAAK4"]
[Thu Jul 30 13:30:25.357632 2026] [security2:error] [pid 890219:tid 890391] [client 20.203.200.218:61183] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/f.php"] [unique_id "amuYQYJkCYmL5o6vh9J91gAAAK4"]
[Thu Jul 30 13:30:25.381292 2026] [security2:error] [pid 890219:tid 890473] [client 82.102.18.188:49388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuYQYJkCYmL5o6vh9J91wAAAQA"]
[Thu Jul 30 13:30:25.419206 2026] [core:notice] [pid 890219:tid 890356] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:25.615720 2026] [security2:error] [pid 890219:tid 890429] [client 20.203.200.218:51719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/e.php"] [unique_id "amuYQYJkCYmL5o6vh9J93AAAANQ"]
[Thu Jul 30 13:30:25.615838 2026] [security2:error] [pid 890219:tid 890429] [client 20.203.200.218:51719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/e.php"] [unique_id "amuYQYJkCYmL5o6vh9J93AAAANQ"]
[Thu Jul 30 13:30:25.649180 2026] [security2:error] [pid 890219:tid 890360] [client 82.102.18.188:49402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuYQYJkCYmL5o6vh9J94AAAAI8"]
[Thu Jul 30 13:30:25.887502 2026] [security2:error] [pid 890219:tid 890357] [client 20.203.200.218:61161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/d.php"] [unique_id "amuYQYJkCYmL5o6vh9J95wAAAIw"]
[Thu Jul 30 13:30:25.887609 2026] [security2:error] [pid 890219:tid 890357] [client 20.203.200.218:61161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/d.php"] [unique_id "amuYQYJkCYmL5o6vh9J95wAAAIw"]
[Thu Jul 30 13:30:25.999215 2026] [security2:error] [pid 890219:tid 890465] [client 82.102.18.188:49408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuYQYJkCYmL5o6vh9J96AAAAPg"]
[Thu Jul 30 13:30:26.171409 2026] [security2:error] [pid 890219:tid 890406] [client 20.203.200.218:52193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/c.php"] [unique_id "amuYQoJkCYmL5o6vh9J97wAAAL0"]
[Thu Jul 30 13:30:26.171514 2026] [security2:error] [pid 890219:tid 890406] [client 20.203.200.218:52193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/c.php"] [unique_id "amuYQoJkCYmL5o6vh9J97wAAAL0"]
[Thu Jul 30 13:30:26.272568 2026] [security2:error] [pid 890219:tid 890425] [client 82.102.18.188:49418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuYQoJkCYmL5o6vh9J98AAAANA"]
[Thu Jul 30 13:30:26.428420 2026] [security2:error] [pid 890219:tid 890353] [client 20.203.200.218:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/b.php"] [unique_id "amuYQoJkCYmL5o6vh9J99AAAAIg"]
[Thu Jul 30 13:30:26.428557 2026] [security2:error] [pid 890219:tid 890353] [client 20.203.200.218:62440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/b.php"] [unique_id "amuYQoJkCYmL5o6vh9J99AAAAIg"]
[Thu Jul 30 13:30:26.709246 2026] [security2:error] [pid 890219:tid 890464] [client 20.203.200.218:52209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indexc.php"] [unique_id "amuYQoJkCYmL5o6vh9J9-wAAAPc"]
[Thu Jul 30 13:30:26.709344 2026] [security2:error] [pid 890219:tid 890464] [client 20.203.200.218:52209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indexc.php"] [unique_id "amuYQoJkCYmL5o6vh9J9-wAAAPc"]
[Thu Jul 30 13:30:26.785963 2026] [security2:error] [pid 890219:tid 890376] [client 82.102.18.188:49430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuYQoJkCYmL5o6vh9J9_AAAAJ8"]
[Thu Jul 30 13:30:26.970564 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:51729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuYQoJkCYmL5o6vh9J-AAAAALU"]
[Thu Jul 30 13:30:26.970671 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:51729] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuYQoJkCYmL5o6vh9J-AAAAALU"]
[Thu Jul 30 13:30:27.058722 2026] [security2:error] [pid 890219:tid 890475] [client 82.102.18.188:49438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuYQ4JkCYmL5o6vh9J-AQAAAQI"]
[Thu Jul 30 13:30:27.239412 2026] [security2:error] [pid 890219:tid 890428] [client 20.203.200.218:52170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuYQ4JkCYmL5o6vh9J-CwAAANM"]
[Thu Jul 30 13:30:27.239521 2026] [security2:error] [pid 890219:tid 890428] [client 20.203.200.218:52170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuYQ4JkCYmL5o6vh9J-CwAAANM"]
[Thu Jul 30 13:30:27.341767 2026] [security2:error] [pid 890219:tid 890395] [client 82.102.18.188:49450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuYQ4JkCYmL5o6vh9J-DwAAALI"]
[Thu Jul 30 13:30:27.533114 2026] [security2:error] [pid 890219:tid 890426] [client 20.203.200.218:51723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuYQ4JkCYmL5o6vh9J-EwAAANE"]
[Thu Jul 30 13:30:27.533210 2026] [security2:error] [pid 890219:tid 890426] [client 20.203.200.218:51723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuYQ4JkCYmL5o6vh9J-EwAAANE"]
[Thu Jul 30 13:30:27.786299 2026] [security2:error] [pid 890219:tid 890436] [client 20.203.200.218:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/.561988674612251.php"] [unique_id "amuYQ4JkCYmL5o6vh9J-GgAAANs"]
[Thu Jul 30 13:30:27.786404 2026] [security2:error] [pid 890219:tid 890436] [client 20.203.200.218:61127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/.561988674612251.php"] [unique_id "amuYQ4JkCYmL5o6vh9J-GgAAANs"]
[Thu Jul 30 13:30:28.075964 2026] [security2:error] [pid 890219:tid 890417] [client 20.203.200.218:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indexw.php"] [unique_id "amuYRIJkCYmL5o6vh9J-HwAAAMg"]
[Thu Jul 30 13:30:28.076089 2026] [security2:error] [pid 890219:tid 890417] [client 20.203.200.218:61157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indexw.php"] [unique_id "amuYRIJkCYmL5o6vh9J-HwAAAMg"]
[Thu Jul 30 13:30:28.356120 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:45566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/.284214373991941.php"] [unique_id "amuYRIJkCYmL5o6vh9J-KwAAALU"]
[Thu Jul 30 13:30:28.356218 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:45566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/.284214373991941.php"] [unique_id "amuYRIJkCYmL5o6vh9J-KwAAALU"]
[Thu Jul 30 13:30:28.366666 2026] [core:notice] [pid 890219:tid 890420] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:28.603098 2026] [security2:error] [pid 890219:tid 890359] [client 179.64.21.229:42893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYRIJkCYmL5o6vh9J-NAAAAI4"]
[Thu Jul 30 13:30:28.603219 2026] [security2:error] [pid 890219:tid 890359] [client 179.64.21.229:42893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYRIJkCYmL5o6vh9J-NAAAAI4"]
[Thu Jul 30 13:30:28.616596 2026] [security2:error] [pid 890219:tid 890381] [client 20.203.200.218:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/.109753674214724.php"] [unique_id "amuYRIJkCYmL5o6vh9J-NQAAAKQ"]
[Thu Jul 30 13:30:28.616696 2026] [security2:error] [pid 890219:tid 890381] [client 20.203.200.218:61127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/.109753674214724.php"] [unique_id "amuYRIJkCYmL5o6vh9J-NQAAAKQ"]
[Thu Jul 30 13:30:28.708957 2026] [security2:error] [pid 890219:tid 890429] [client 82.102.18.188:49466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.psz.dtn.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuYRIJkCYmL5o6vh9J-NwAAANQ"]
[Thu Jul 30 13:30:28.895211 2026] [security2:error] [pid 890219:tid 890392] [client 20.203.200.218:52173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/kjihe.php"] [unique_id "amuYRIJkCYmL5o6vh9J-PgAAAK8"]
[Thu Jul 30 13:30:28.895325 2026] [security2:error] [pid 890219:tid 890392] [client 20.203.200.218:52173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/kjihe.php"] [unique_id "amuYRIJkCYmL5o6vh9J-PgAAAK8"]
[Thu Jul 30 13:30:29.146476 2026] [security2:error] [pid 890219:tid 890442] [client 20.203.200.218:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/Uploading.php"] [unique_id "amuYRYJkCYmL5o6vh9J-QwAAAOE"]
[Thu Jul 30 13:30:29.146591 2026] [security2:error] [pid 890219:tid 890442] [client 20.203.200.218:51718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/Uploading.php"] [unique_id "amuYRYJkCYmL5o6vh9J-QwAAAOE"]
[Thu Jul 30 13:30:29.369196 2026] [security2:error] [pid 890219:tid 890391] [client 43.155.188.157:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.188.155.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JPAS/issue/current"] [unique_id "amuYRYJkCYmL5o6vh9J-TAAAAK4"], referer: https://ejournalugj.com/index_php/JPAS/issue/current
[Thu Jul 30 13:30:29.398525 2026] [security2:error] [pid 890219:tid 890436] [client 20.203.200.218:51760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ip.php"] [unique_id "amuYRYJkCYmL5o6vh9J-TwAAANs"]
[Thu Jul 30 13:30:29.398701 2026] [security2:error] [pid 890219:tid 890436] [client 20.203.200.218:51760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ip.php"] [unique_id "amuYRYJkCYmL5o6vh9J-TwAAANs"]
[Thu Jul 30 13:30:29.680049 2026] [security2:error] [pid 890219:tid 890370] [client 20.203.200.218:61152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/__1975.php"] [unique_id "amuYRYJkCYmL5o6vh9J-UgAAAJk"]
[Thu Jul 30 13:30:29.680203 2026] [security2:error] [pid 890219:tid 890370] [client 20.203.200.218:61152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/__1975.php"] [unique_id "amuYRYJkCYmL5o6vh9J-UgAAAJk"]
[Thu Jul 30 13:30:29.685671 2026] [security2:error] [pid 890219:tid 890248] [remote 40.77.167.123:44911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/1850467124/indexf.php"] [unique_id "amuYRYJkCYmL5o6vh9J-UwAAtxs"]
[Thu Jul 30 13:30:29.764105 2026] [core:notice] [pid 890219:tid 890326] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:30.001843 2026] [security2:error] [pid 890219:tid 890327] [remote 91.86.16.6:14042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.16.86.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/wp-login.php"] [unique_id "amuYRYJkCYmL5o6vh9J-XAAAz2o"]
[Thu Jul 30 13:30:30.002921 2026] [security2:error] [pid 890219:tid 890362] [client 20.203.200.218:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/gaya.php"] [unique_id "amuYRoJkCYmL5o6vh9J-XgAAAJE"]
[Thu Jul 30 13:30:30.003024 2026] [security2:error] [pid 890219:tid 890362] [client 20.203.200.218:62451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/gaya.php"] [unique_id "amuYRoJkCYmL5o6vh9J-XgAAAJE"]
[Thu Jul 30 13:30:30.310616 2026] [security2:error] [pid 890219:tid 890381] [client 20.203.200.218:42083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/jal.php"] [unique_id "amuYRoJkCYmL5o6vh9J-ZAAAAKQ"]
[Thu Jul 30 13:30:30.310718 2026] [security2:error] [pid 890219:tid 890381] [client 20.203.200.218:42083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/jal.php"] [unique_id "amuYRoJkCYmL5o6vh9J-ZAAAAKQ"]
[Thu Jul 30 13:30:30.585249 2026] [security2:error] [pid 890219:tid 890384] [client 20.203.200.218:51772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/pfa.php"] [unique_id "amuYRoJkCYmL5o6vh9J-awAAAKc"]
[Thu Jul 30 13:30:30.585349 2026] [security2:error] [pid 890219:tid 890384] [client 20.203.200.218:51772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/pfa.php"] [unique_id "amuYRoJkCYmL5o6vh9J-awAAAKc"]
[Thu Jul 30 13:30:30.839141 2026] [security2:error] [pid 890219:tid 890393] [client 20.203.200.218:51775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/advanced-cf7-db.php"] [unique_id "amuYRoJkCYmL5o6vh9J-bwAAALA"]
[Thu Jul 30 13:30:30.839304 2026] [security2:error] [pid 890219:tid 890393] [client 20.203.200.218:51775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/advanced-cf7-db.php"] [unique_id "amuYRoJkCYmL5o6vh9J-bwAAALA"]
[Thu Jul 30 13:30:31.099457 2026] [security2:error] [pid 890219:tid 890367] [client 20.203.200.218:61160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/Astagaaaaa.php"] [unique_id "amuYR4JkCYmL5o6vh9J-dgAAAJY"]
[Thu Jul 30 13:30:31.099554 2026] [security2:error] [pid 890219:tid 890367] [client 20.203.200.218:61160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/Astagaaaaa.php"] [unique_id "amuYR4JkCYmL5o6vh9J-dgAAAJY"]
[Thu Jul 30 13:30:31.348942 2026] [security2:error] [pid 890219:tid 890422] [client 20.203.200.218:52220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-user.php"] [unique_id "amuYR4JkCYmL5o6vh9J-fgAAAM0"]
[Thu Jul 30 13:30:31.349051 2026] [security2:error] [pid 890219:tid 890422] [client 20.203.200.218:52220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-user.php"] [unique_id "amuYR4JkCYmL5o6vh9J-fgAAAM0"]
[Thu Jul 30 13:30:31.523551 2026] [proxy:error] [pid 890219:tid 890463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:31.523637 2026] [proxy_http:error] [pid 890219:tid 890463] [client 3.225.222.228:48150] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:31.524302 2026] [proxy:error] [pid 890219:tid 890463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:31.524353 2026] [proxy_http:error] [pid 890219:tid 890463] [client 3.225.222.228:48150] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:31.534141 2026] [proxy:error] [pid 890219:tid 890376] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:31.534206 2026] [proxy_http:error] [pid 890219:tid 890376] [client 52.4.19.39:10881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:31.534780 2026] [proxy:error] [pid 890219:tid 890376] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:31.534824 2026] [proxy_http:error] [pid 890219:tid 890376] [client 52.4.19.39:10881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:31.604252 2026] [security2:error] [pid 890219:tid 890386] [client 20.203.200.218:61143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/theme-insnhpf.php"] [unique_id "amuYR4JkCYmL5o6vh9J-kAAAAKk"]
[Thu Jul 30 13:30:31.604444 2026] [security2:error] [pid 890219:tid 890386] [client 20.203.200.218:61143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/theme-insnhpf.php"] [unique_id "amuYR4JkCYmL5o6vh9J-kAAAAKk"]
[Thu Jul 30 13:30:31.918825 2026] [security2:error] [pid 890219:tid 890445] [client 20.203.200.218:45522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/process_login.php"] [unique_id "amuYR4JkCYmL5o6vh9J-lAAAAOQ"]
[Thu Jul 30 13:30:31.918907 2026] [security2:error] [pid 890219:tid 890445] [client 20.203.200.218:45522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/process_login.php"] [unique_id "amuYR4JkCYmL5o6vh9J-lAAAAOQ"]
[Thu Jul 30 13:30:32.084138 2026] [security2:error] [pid 890219:tid 890400] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYR4JkCYmL5o6vh9J-hAAAALc"]
[Thu Jul 30 13:30:32.215123 2026] [security2:error] [pid 890219:tid 890360] [client 20.203.200.218:45132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/liverpool-health.php"] [unique_id "amuYSIJkCYmL5o6vh9J-ngAAAI8"]
[Thu Jul 30 13:30:32.215263 2026] [security2:error] [pid 890219:tid 890360] [client 20.203.200.218:45132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/liverpool-health.php"] [unique_id "amuYSIJkCYmL5o6vh9J-ngAAAI8"]
[Thu Jul 30 13:30:32.473732 2026] [security2:error] [pid 890219:tid 890458] [client 20.203.200.218:52174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/.012263646060568.php"] [unique_id "amuYSIJkCYmL5o6vh9J-pAAAAPE"]
[Thu Jul 30 13:30:32.473834 2026] [security2:error] [pid 890219:tid 890458] [client 20.203.200.218:52174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/.012263646060568.php"] [unique_id "amuYSIJkCYmL5o6vh9J-pAAAAPE"]
[Thu Jul 30 13:30:32.598945 2026] [core:notice] [pid 890219:tid 890401] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:32.789513 2026] [security2:error] [pid 890219:tid 890439] [client 20.203.200.218:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/jmbt.php"] [unique_id "amuYSIJkCYmL5o6vh9J-rQAAAN4"]
[Thu Jul 30 13:30:32.789657 2026] [security2:error] [pid 890219:tid 890439] [client 20.203.200.218:61158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/jmbt.php"] [unique_id "amuYSIJkCYmL5o6vh9J-rQAAAN4"]
[Thu Jul 30 13:30:32.871806 2026] [security2:error] [pid 890219:tid 890225] [remote 57.141.0.26:31586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amuYSIJkCYmL5o6vh9J-rgAAtgQ"]
[Thu Jul 30 13:30:33.055943 2026] [security2:error] [pid 890219:tid 890394] [client 20.203.200.218:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/maho.php"] [unique_id "amuYSYJkCYmL5o6vh9J-tgAAALE"]
[Thu Jul 30 13:30:33.056057 2026] [security2:error] [pid 890219:tid 890394] [client 20.203.200.218:62457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/maho.php"] [unique_id "amuYSYJkCYmL5o6vh9J-tgAAALE"]
[Thu Jul 30 13:30:33.077337 2026] [security2:error] [pid 890219:tid 890240] [remote 57.141.0.56:25864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4208817797/feed/rss2/"] [unique_id "amuYSYJkCYmL5o6vh9J-uAAAxxM"]
[Thu Jul 30 13:30:33.199621 2026] [core:notice] [pid 890219:tid 890425] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:33.308096 2026] [security2:error] [pid 890219:tid 890419] [client 20.203.200.218:61139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/mia.php"] [unique_id "amuYSYJkCYmL5o6vh9J-vgAAAMo"]
[Thu Jul 30 13:30:33.308205 2026] [security2:error] [pid 890219:tid 890419] [client 20.203.200.218:61139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/mia.php"] [unique_id "amuYSYJkCYmL5o6vh9J-vgAAAMo"]
[Thu Jul 30 13:30:33.502114 2026] [core:notice] [pid 890219:tid 890347] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:33.560420 2026] [security2:error] [pid 890219:tid 890452] [client 20.203.200.218:45557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/qwe.php"] [unique_id "amuYSYJkCYmL5o6vh9J-xQAAAOs"]
[Thu Jul 30 13:30:33.560526 2026] [security2:error] [pid 890219:tid 890452] [client 20.203.200.218:45557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/qwe.php"] [unique_id "amuYSYJkCYmL5o6vh9J-xQAAAOs"]
[Thu Jul 30 13:30:33.834097 2026] [security2:error] [pid 890219:tid 890428] [client 20.203.200.218:52219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/shell_finder.php"] [unique_id "amuYSYJkCYmL5o6vh9J-ygAAANM"]
[Thu Jul 30 13:30:33.834251 2026] [security2:error] [pid 890219:tid 890428] [client 20.203.200.218:52219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/shell_finder.php"] [unique_id "amuYSYJkCYmL5o6vh9J-ygAAANM"]
[Thu Jul 30 13:30:34.121306 2026] [security2:error] [pid 890219:tid 890360] [client 20.203.200.218:52172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/cfinder.php"] [unique_id "amuYSoJkCYmL5o6vh9J-0QAAAI8"]
[Thu Jul 30 13:30:34.121401 2026] [security2:error] [pid 890219:tid 890360] [client 20.203.200.218:52172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/cfinder.php"] [unique_id "amuYSoJkCYmL5o6vh9J-0QAAAI8"]
[Thu Jul 30 13:30:34.385596 2026] [security2:error] [pid 890219:tid 890430] [client 20.203.200.218:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/pasired.php"] [unique_id "amuYSoJkCYmL5o6vh9J-1gAAANU"]
[Thu Jul 30 13:30:34.385708 2026] [security2:error] [pid 890219:tid 890430] [client 20.203.200.218:62417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/pasired.php"] [unique_id "amuYSoJkCYmL5o6vh9J-1gAAANU"]
[Thu Jul 30 13:30:34.676466 2026] [security2:error] [pid 890219:tid 890435] [client 20.203.200.218:61144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/adm.php"] [unique_id "amuYSoJkCYmL5o6vh9J-3QAAANo"]
[Thu Jul 30 13:30:34.676583 2026] [security2:error] [pid 890219:tid 890435] [client 20.203.200.218:61144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/adm.php"] [unique_id "amuYSoJkCYmL5o6vh9J-3QAAANo"]
[Thu Jul 30 13:30:34.955692 2026] [security2:error] [pid 890219:tid 890399] [client 20.203.200.218:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/noob.php"] [unique_id "amuYSoJkCYmL5o6vh9J-4QAAALY"]
[Thu Jul 30 13:30:34.955798 2026] [security2:error] [pid 890219:tid 890399] [client 20.203.200.218:62430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/noob.php"] [unique_id "amuYSoJkCYmL5o6vh9J-4QAAALY"]
[Thu Jul 30 13:30:35.224726 2026] [security2:error] [pid 890219:tid 890477] [client 20.203.200.218:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/..php"] [unique_id "amuYS4JkCYmL5o6vh9J-7QAAAQQ"]
[Thu Jul 30 13:30:35.224827 2026] [security2:error] [pid 890219:tid 890477] [client 20.203.200.218:62403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/..php"] [unique_id "amuYS4JkCYmL5o6vh9J-7QAAAQQ"]
[Thu Jul 30 13:30:35.344122 2026] [autoindex:error] [pid 890219:tid 890461] [client 209.97.166.251:52677] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 13:30:35.438854 2026] [security2:error] [pid 890219:tid 890255] [remote 57.141.0.31:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuYS4JkCYmL5o6vh9J-8gAA-CI"]
[Thu Jul 30 13:30:35.481401 2026] [security2:error] [pid 890219:tid 890379] [client 20.203.200.218:45533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/Lol.php"] [unique_id "amuYS4JkCYmL5o6vh9J-8wAAAKI"]
[Thu Jul 30 13:30:35.481508 2026] [security2:error] [pid 890219:tid 890379] [client 20.203.200.218:45533] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/Lol.php"] [unique_id "amuYS4JkCYmL5o6vh9J-8wAAAKI"]
[Thu Jul 30 13:30:35.765471 2026] [security2:error] [pid 890219:tid 890352] [client 20.203.200.218:62461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/b2.php"] [unique_id "amuYS4JkCYmL5o6vh9J-_QAAAIc"]
[Thu Jul 30 13:30:35.765585 2026] [security2:error] [pid 890219:tid 890352] [client 20.203.200.218:62461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/b2.php"] [unique_id "amuYS4JkCYmL5o6vh9J-_QAAAIc"]
[Thu Jul 30 13:30:36.021430 2026] [security2:error] [pid 890219:tid 890408] [client 20.203.200.218:45551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ex.php"] [unique_id "amuYTIJkCYmL5o6vh9J_CQAAAL8"]
[Thu Jul 30 13:30:36.021548 2026] [security2:error] [pid 890219:tid 890408] [client 20.203.200.218:45551] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ex.php"] [unique_id "amuYTIJkCYmL5o6vh9J_CQAAAL8"]
[Thu Jul 30 13:30:36.271572 2026] [security2:error] [pid 890219:tid 890380] [client 20.203.200.218:51767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/dhanush.php"] [unique_id "amuYTIJkCYmL5o6vh9J_DQAAAKM"]
[Thu Jul 30 13:30:36.271693 2026] [security2:error] [pid 890219:tid 890380] [client 20.203.200.218:51767] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/dhanush.php"] [unique_id "amuYTIJkCYmL5o6vh9J_DQAAAKM"]
[Thu Jul 30 13:30:36.543716 2026] [security2:error] [pid 890219:tid 890442] [client 20.203.200.218:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/asw.php"] [unique_id "amuYTIJkCYmL5o6vh9J_EQAAAOE"]
[Thu Jul 30 13:30:36.543820 2026] [security2:error] [pid 890219:tid 890442] [client 20.203.200.218:61123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/asw.php"] [unique_id "amuYTIJkCYmL5o6vh9J_EQAAAOE"]
[Thu Jul 30 13:30:36.656809 2026] [core:notice] [pid 890219:tid 890258] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:36.828136 2026] [security2:error] [pid 890219:tid 890440] [client 20.203.200.218:52197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/mini.php5"] [unique_id "amuYTIJkCYmL5o6vh9J_GQAAAN8"]
[Thu Jul 30 13:30:36.828296 2026] [security2:error] [pid 890219:tid 890440] [client 20.203.200.218:52197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/mini.php5"] [unique_id "amuYTIJkCYmL5o6vh9J_GQAAAN8"]
[Thu Jul 30 13:30:37.080628 2026] [security2:error] [pid 890219:tid 890396] [client 20.203.200.218:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ler.php"] [unique_id "amuYTYJkCYmL5o6vh9J_IAAAALM"]
[Thu Jul 30 13:30:37.080747 2026] [security2:error] [pid 890219:tid 890396] [client 20.203.200.218:62411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ler.php"] [unique_id "amuYTYJkCYmL5o6vh9J_IAAAALM"]
[Thu Jul 30 13:30:37.154501 2026] [core:notice] [pid 890219:tid 890235] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:37.338430 2026] [security2:error] [pid 890219:tid 890363] [client 20.203.200.218:45528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/def.php"] [unique_id "amuYTYJkCYmL5o6vh9J_KQAAAJI"]
[Thu Jul 30 13:30:37.338551 2026] [security2:error] [pid 890219:tid 890363] [client 20.203.200.218:45528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/def.php"] [unique_id "amuYTYJkCYmL5o6vh9J_KQAAAJI"]
[Thu Jul 30 13:30:37.587813 2026] [security2:error] [pid 890219:tid 890394] [client 20.203.200.218:62448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/extremecrw.php"] [unique_id "amuYTYJkCYmL5o6vh9J_LQAAALE"]
[Thu Jul 30 13:30:37.587924 2026] [security2:error] [pid 890219:tid 890394] [client 20.203.200.218:62448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/extremecrw.php"] [unique_id "amuYTYJkCYmL5o6vh9J_LQAAALE"]
[Thu Jul 30 13:30:37.682379 2026] [core:notice] [pid 890219:tid 890271] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:37.855374 2026] [security2:error] [pid 890219:tid 890475] [client 20.203.200.218:52201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indx.php"] [unique_id "amuYTYJkCYmL5o6vh9J_NgAAAQI"]
[Thu Jul 30 13:30:37.855508 2026] [security2:error] [pid 890219:tid 890475] [client 20.203.200.218:52201] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indx.php"] [unique_id "amuYTYJkCYmL5o6vh9J_NgAAAQI"]
[Thu Jul 30 13:30:38.130238 2026] [security2:error] [pid 890219:tid 890473] [client 20.203.200.218:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/bv7binary.php"] [unique_id "amuYToJkCYmL5o6vh9J_PwAAAQA"]
[Thu Jul 30 13:30:38.130340 2026] [security2:error] [pid 890219:tid 890473] [client 20.203.200.218:62426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/bv7binary.php"] [unique_id "amuYToJkCYmL5o6vh9J_PwAAAQA"]
[Thu Jul 30 13:30:38.390688 2026] [security2:error] [pid 890219:tid 890415] [client 20.203.200.218:61159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/webroot.php"] [unique_id "amuYToJkCYmL5o6vh9J_RwAAAMY"]
[Thu Jul 30 13:30:38.390803 2026] [security2:error] [pid 890219:tid 890415] [client 20.203.200.218:61159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/webroot.php"] [unique_id "amuYToJkCYmL5o6vh9J_RwAAAMY"]
[Thu Jul 30 13:30:38.451939 2026] [security2:error] [pid 890219:tid 890432] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYTYJkCYmL5o6vh9J_OAAAANc"]
[Thu Jul 30 13:30:38.656125 2026] [security2:error] [pid 890219:tid 890404] [client 20.203.200.218:51759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/h4cker.php"] [unique_id "amuYToJkCYmL5o6vh9J_TgAAALs"]
[Thu Jul 30 13:30:38.656232 2026] [security2:error] [pid 890219:tid 890404] [client 20.203.200.218:51759] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/h4cker.php"] [unique_id "amuYToJkCYmL5o6vh9J_TgAAALs"]
[Thu Jul 30 13:30:38.909921 2026] [security2:error] [pid 890219:tid 890466] [client 20.203.200.218:61171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/gazashell.php"] [unique_id "amuYToJkCYmL5o6vh9J_UgAAAPk"]
[Thu Jul 30 13:30:38.910052 2026] [security2:error] [pid 890219:tid 890466] [client 20.203.200.218:61171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/gazashell.php"] [unique_id "amuYToJkCYmL5o6vh9J_UgAAAPk"]
[Thu Jul 30 13:30:39.089636 2026] [security2:error] [pid 890219:tid 890227] [remote 57.141.0.24:24032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5033157679/feed/rss2/"] [unique_id "amuYT4JkCYmL5o6vh9J_VgAA3wY"]
[Thu Jul 30 13:30:39.227803 2026] [security2:error] [pid 890219:tid 890363] [client 20.203.200.218:61170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/syrianshell.php"] [unique_id "amuYT4JkCYmL5o6vh9J_XAAAAJI"]
[Thu Jul 30 13:30:39.227914 2026] [security2:error] [pid 890219:tid 890363] [client 20.203.200.218:61170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/syrianshell.php"] [unique_id "amuYT4JkCYmL5o6vh9J_XAAAAJI"]
[Thu Jul 30 13:30:39.481569 2026] [security2:error] [pid 890219:tid 890477] [client 20.203.200.218:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/locus7shell.php"] [unique_id "amuYT4JkCYmL5o6vh9J_YAAAAQQ"]
[Thu Jul 30 13:30:39.481663 2026] [security2:error] [pid 890219:tid 890477] [client 20.203.200.218:62444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/locus7shell.php"] [unique_id "amuYT4JkCYmL5o6vh9J_YAAAAQQ"]
[Thu Jul 30 13:30:39.621519 2026] [security2:error] [pid 890219:tid 890378] [client 179.64.21.229:27010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYT4JkCYmL5o6vh9J_YgAAAKE"]
[Thu Jul 30 13:30:39.624805 2026] [security2:error] [pid 890219:tid 890378] [client 179.64.21.229:27010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYT4JkCYmL5o6vh9J_YgAAAKE"]
[Thu Jul 30 13:30:39.646425 2026] [security2:error] [pid 890219:tid 890280] [remote 57.141.0.4:45112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amuYT4JkCYmL5o6vh9J_YwAAuTs"]
[Thu Jul 30 13:30:39.736494 2026] [security2:error] [pid 890219:tid 890425] [client 20.203.200.218:51756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/cyberwarrior.php"] [unique_id "amuYT4JkCYmL5o6vh9J_ZwAAANA"]
[Thu Jul 30 13:30:39.736602 2026] [security2:error] [pid 890219:tid 890425] [client 20.203.200.218:51756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/cyberwarrior.php"] [unique_id "amuYT4JkCYmL5o6vh9J_ZwAAANA"]
[Thu Jul 30 13:30:39.987933 2026] [security2:error] [pid 890219:tid 890431] [client 20.203.200.218:61169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ernebypass.php"] [unique_id "amuYT4JkCYmL5o6vh9J_awAAANY"]
[Thu Jul 30 13:30:39.988061 2026] [security2:error] [pid 890219:tid 890431] [client 20.203.200.218:61169] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ernebypass.php"] [unique_id "amuYT4JkCYmL5o6vh9J_awAAANY"]
[Thu Jul 30 13:30:40.074128 2026] [core:notice] [pid 890219:tid 890272] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:40.244234 2026] [security2:error] [pid 890219:tid 890415] [client 20.203.200.218:45545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/g6shell.php"] [unique_id "amuYUIJkCYmL5o6vh9J_cQAAAMY"]
[Thu Jul 30 13:30:40.244336 2026] [security2:error] [pid 890219:tid 890415] [client 20.203.200.218:45545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/g6shell.php"] [unique_id "amuYUIJkCYmL5o6vh9J_cQAAAMY"]
[Thu Jul 30 13:30:40.501769 2026] [security2:error] [pid 890219:tid 890404] [client 20.203.200.218:51733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/pouyaserver.php"] [unique_id "amuYUIJkCYmL5o6vh9J_egAAALs"]
[Thu Jul 30 13:30:40.501876 2026] [security2:error] [pid 890219:tid 890404] [client 20.203.200.218:51733] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/pouyaserver.php"] [unique_id "amuYUIJkCYmL5o6vh9J_egAAALs"]
[Thu Jul 30 13:30:40.617809 2026] [security2:error] [pid 890219:tid 890418] [client 52.167.144.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYUIJkCYmL5o6vh9J_eAAAAMk"]
[Thu Jul 30 13:30:40.805245 2026] [security2:error] [pid 890219:tid 890436] [client 20.203.200.218:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/saudishell.php"] [unique_id "amuYUIJkCYmL5o6vh9J_ggAAANs"]
[Thu Jul 30 13:30:40.805364 2026] [security2:error] [pid 890219:tid 890436] [client 20.203.200.218:51748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/saudishell.php"] [unique_id "amuYUIJkCYmL5o6vh9J_ggAAANs"]
[Thu Jul 30 13:30:40.816387 2026] [core:notice] [pid 890219:tid 890281] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:40.821644 2026] [security2:error] [pid 890219:tid 890397] [client 74.7.244.35:57152] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-7c59acf7.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuYUIJkCYmL5o6vh9J_gwAAtDw"]
[Thu Jul 30 13:30:41.076124 2026] [security2:error] [pid 890219:tid 890417] [client 20.203.200.218:51721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/sosyeteshell.php"] [unique_id "amuYUYJkCYmL5o6vh9J_igAAAMg"]
[Thu Jul 30 13:30:41.076222 2026] [security2:error] [pid 890219:tid 890417] [client 20.203.200.218:51721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/sosyeteshell.php"] [unique_id "amuYUYJkCYmL5o6vh9J_igAAAMg"]
[Thu Jul 30 13:30:41.335079 2026] [security2:error] [pid 890219:tid 890365] [client 20.203.200.218:52202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/tryagshell.php"] [unique_id "amuYUYJkCYmL5o6vh9J_kgAAAJQ"]
[Thu Jul 30 13:30:41.335236 2026] [security2:error] [pid 890219:tid 890365] [client 20.203.200.218:52202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/tryagshell.php"] [unique_id "amuYUYJkCYmL5o6vh9J_kgAAAJQ"]
[Thu Jul 30 13:30:41.606175 2026] [security2:error] [pid 890219:tid 890424] [client 20.203.200.218:45123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/uploadshell.php"] [unique_id "amuYUYJkCYmL5o6vh9J_mwAAAM8"]
[Thu Jul 30 13:30:41.606262 2026] [security2:error] [pid 890219:tid 890424] [client 20.203.200.218:45123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/uploadshell.php"] [unique_id "amuYUYJkCYmL5o6vh9J_mwAAAM8"]
[Thu Jul 30 13:30:41.710814 2026] [core:notice] [pid 890219:tid 890222] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:41.879604 2026] [security2:error] [pid 890219:tid 890450] [client 20.203.200.218:62454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/zehir4shell.php"] [unique_id "amuYUYJkCYmL5o6vh9J_pQAAAOk"]
[Thu Jul 30 13:30:41.879712 2026] [security2:error] [pid 890219:tid 890450] [client 20.203.200.218:62454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/zehir4shell.php"] [unique_id "amuYUYJkCYmL5o6vh9J_pQAAAOk"]
[Thu Jul 30 13:30:42.142939 2026] [security2:error] [pid 890219:tid 890380] [client 20.203.200.218:41993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/lostdcshell.php"] [unique_id "amuYUoJkCYmL5o6vh9J_qwAAAKM"]
[Thu Jul 30 13:30:42.143044 2026] [security2:error] [pid 890219:tid 890380] [client 20.203.200.218:41993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/lostdcshell.php"] [unique_id "amuYUoJkCYmL5o6vh9J_qwAAAKM"]
[Thu Jul 30 13:30:42.422972 2026] [security2:error] [pid 890219:tid 890462] [client 20.203.200.218:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/commandshell.php"] [unique_id "amuYUoJkCYmL5o6vh9J_tAAAAPU"]
[Thu Jul 30 13:30:42.423079 2026] [security2:error] [pid 890219:tid 890462] [client 20.203.200.218:62441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/commandshell.php"] [unique_id "amuYUoJkCYmL5o6vh9J_tAAAAPU"]
[Thu Jul 30 13:30:42.702365 2026] [security2:error] [pid 890219:tid 890441] [client 20.203.200.218:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/mailershell.php"] [unique_id "amuYUoJkCYmL5o6vh9J_vQAAAOA"]
[Thu Jul 30 13:30:42.702490 2026] [security2:error] [pid 890219:tid 890441] [client 20.203.200.218:52198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/mailershell.php"] [unique_id "amuYUoJkCYmL5o6vh9J_vQAAAOA"]
[Thu Jul 30 13:30:42.930620 2026] [security2:error] [pid 890219:tid 890436] [client 52.167.144.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYUoJkCYmL5o6vh9J_vAAAANs"]
[Thu Jul 30 13:30:42.977040 2026] [security2:error] [pid 890219:tid 890368] [client 20.203.200.218:52207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/cwshell.php"] [unique_id "amuYUoJkCYmL5o6vh9J_wwAAAJc"]
[Thu Jul 30 13:30:42.977149 2026] [security2:error] [pid 890219:tid 890368] [client 20.203.200.218:52207] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/cwshell.php"] [unique_id "amuYUoJkCYmL5o6vh9J_wwAAAJc"]
[Thu Jul 30 13:30:43.256406 2026] [security2:error] [pid 890219:tid 890420] [client 20.203.200.218:51732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/iranshell.php"] [unique_id "amuYU4JkCYmL5o6vh9J_zwAAAMs"]
[Thu Jul 30 13:30:43.256505 2026] [security2:error] [pid 890219:tid 890420] [client 20.203.200.218:51732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/iranshell.php"] [unique_id "amuYU4JkCYmL5o6vh9J_zwAAAMs"]
[Thu Jul 30 13:30:43.510389 2026] [security2:error] [pid 890219:tid 890362] [client 20.203.200.218:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indishell.php"] [unique_id "amuYU4JkCYmL5o6vh9J_2QAAAJE"]
[Thu Jul 30 13:30:43.510473 2026] [security2:error] [pid 890219:tid 890362] [client 20.203.200.218:62421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indishell.php"] [unique_id "amuYU4JkCYmL5o6vh9J_2QAAAJE"]
[Thu Jul 30 13:30:43.771033 2026] [security2:error] [pid 890219:tid 890392] [client 20.203.200.218:42057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/zehirshell.php"] [unique_id "amuYU4JkCYmL5o6vh9J_5wAAAK8"]
[Thu Jul 30 13:30:43.771149 2026] [security2:error] [pid 890219:tid 890392] [client 20.203.200.218:42057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/zehirshell.php"] [unique_id "amuYU4JkCYmL5o6vh9J_5wAAAK8"]
[Thu Jul 30 13:30:44.056327 2026] [security2:error] [pid 890219:tid 890467] [client 20.203.200.218:51739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/g6sshell.php"] [unique_id "amuYVIJkCYmL5o6vh9J_8AAAAPo"]
[Thu Jul 30 13:30:44.056438 2026] [security2:error] [pid 890219:tid 890467] [client 20.203.200.218:51739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/g6sshell.php"] [unique_id "amuYVIJkCYmL5o6vh9J_8AAAAPo"]
[Thu Jul 30 13:30:44.305606 2026] [security2:error] [pid 890219:tid 890466] [client 20.203.200.218:62407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/sqlshell.php"] [unique_id "amuYVIJkCYmL5o6vh9J_9QAAAPk"]
[Thu Jul 30 13:30:44.305721 2026] [security2:error] [pid 890219:tid 890466] [client 20.203.200.218:62407] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/sqlshell.php"] [unique_id "amuYVIJkCYmL5o6vh9J_9QAAAPk"]
[Thu Jul 30 13:30:44.585918 2026] [security2:error] [pid 890219:tid 890455] [client 20.203.200.218:51755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/simshell.php"] [unique_id "amuYVIJkCYmL5o6vh9KAAgAAAO4"]
[Thu Jul 30 13:30:44.586071 2026] [security2:error] [pid 890219:tid 890455] [client 20.203.200.218:51755] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/simshell.php"] [unique_id "amuYVIJkCYmL5o6vh9KAAgAAAO4"]
[Thu Jul 30 13:30:44.841467 2026] [security2:error] [pid 890219:tid 890411] [client 20.203.200.218:52195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/k2ll33d.php"] [unique_id "amuYVIJkCYmL5o6vh9KACQAAAMI"]
[Thu Jul 30 13:30:44.841580 2026] [security2:error] [pid 890219:tid 890411] [client 20.203.200.218:52195] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/k2ll33d.php"] [unique_id "amuYVIJkCYmL5o6vh9KACQAAAMI"]
[Thu Jul 30 13:30:44.980049 2026] [security2:error] [pid 890219:tid 890387] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYVIJkCYmL5o6vh9J_9gAAqmg"]
[Thu Jul 30 13:30:45.090875 2026] [security2:error] [pid 890219:tid 890420] [client 20.203.200.218:45526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/b1n4ry.php"] [unique_id "amuYVYJkCYmL5o6vh9KADQAAAMs"]
[Thu Jul 30 13:30:45.090997 2026] [security2:error] [pid 890219:tid 890420] [client 20.203.200.218:45526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/b1n4ry.php"] [unique_id "amuYVYJkCYmL5o6vh9KADQAAAMs"]
[Thu Jul 30 13:30:45.354526 2026] [security2:error] [pid 890219:tid 890468] [client 20.203.200.218:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/default.php"] [unique_id "amuYVYJkCYmL5o6vh9KAFAAAAPs"]
[Thu Jul 30 13:30:45.354612 2026] [security2:error] [pid 890219:tid 890468] [client 20.203.200.218:51771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/default.php"] [unique_id "amuYVYJkCYmL5o6vh9KAFAAAAPs"]
[Thu Jul 30 13:30:45.621280 2026] [security2:error] [pid 890219:tid 890446] [client 20.203.200.218:45162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/blank.php"] [unique_id "amuYVYJkCYmL5o6vh9KAHAAAAOU"]
[Thu Jul 30 13:30:45.621438 2026] [security2:error] [pid 890219:tid 890446] [client 20.203.200.218:45162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/blank.php"] [unique_id "amuYVYJkCYmL5o6vh9KAHAAAAOU"]
[Thu Jul 30 13:30:45.845072 2026] [security2:error] [pid 890219:tid 890471] [client 52.167.144.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYVYJkCYmL5o6vh9KAGwAAAP4"]
[Thu Jul 30 13:30:45.893637 2026] [security2:error] [pid 890219:tid 890366] [client 20.203.200.218:62453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/admin-demo/index.php"] [unique_id "amuYVYJkCYmL5o6vh9KAIwAAAJU"]
[Thu Jul 30 13:30:45.893732 2026] [security2:error] [pid 890219:tid 890366] [client 20.203.200.218:62453] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/admin-demo/index.php"] [unique_id "amuYVYJkCYmL5o6vh9KAIwAAAJU"]
[Thu Jul 30 13:30:46.178288 2026] [proxy:error] [pid 890219:tid 890418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:46.178375 2026] [proxy_http:error] [pid 890219:tid 890418] [client 20.203.200.218:52223] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:46.178941 2026] [proxy:error] [pid 890219:tid 890418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:46.178999 2026] [proxy_http:error] [pid 890219:tid 890418] [client 20.203.200.218:52223] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:46.179109 2026] [security2:error] [pid 890219:tid 890418] [client 20.203.200.218:52223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuYVoJkCYmL5o6vh9KAJwAAAMk"]
[Thu Jul 30 13:30:46.700761 2026] [security2:error] [pid 890219:tid 890466] [client 20.203.200.218:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amuYVoJkCYmL5o6vh9KAMAAAAPk"]
[Thu Jul 30 13:30:46.700888 2026] [security2:error] [pid 890219:tid 890466] [client 20.203.200.218:61151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amuYVoJkCYmL5o6vh9KAMAAAAPk"]
[Thu Jul 30 13:30:46.964227 2026] [security2:error] [pid 890219:tid 890411] [client 20.203.200.218:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/01.php"] [unique_id "amuYVoJkCYmL5o6vh9KAOwAAAMI"]
[Thu Jul 30 13:30:46.964341 2026] [security2:error] [pid 890219:tid 890411] [client 20.203.200.218:51770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/01.php"] [unique_id "amuYVoJkCYmL5o6vh9KAOwAAAMI"]
[Thu Jul 30 13:30:47.214640 2026] [security2:error] [pid 890219:tid 890387] [client 20.203.200.218:45553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/xs.php"] [unique_id "amuYV4JkCYmL5o6vh9KAQQAAAKo"]
[Thu Jul 30 13:30:47.214749 2026] [security2:error] [pid 890219:tid 890387] [client 20.203.200.218:45553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/xs.php"] [unique_id "amuYV4JkCYmL5o6vh9KAQQAAAKo"]
[Thu Jul 30 13:30:47.469189 2026] [security2:error] [pid 890219:tid 890362] [client 20.203.200.218:61140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/data.php"] [unique_id "amuYV4JkCYmL5o6vh9KATAAAAJE"]
[Thu Jul 30 13:30:47.469302 2026] [security2:error] [pid 890219:tid 890362] [client 20.203.200.218:61140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/data.php"] [unique_id "amuYV4JkCYmL5o6vh9KATAAAAJE"]
[Thu Jul 30 13:30:47.690842 2026] [security2:error] [pid 890219:tid 890429] [client 40.77.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYV4JkCYmL5o6vh9KASwAAANQ"]
[Thu Jul 30 13:30:47.720137 2026] [security2:error] [pid 890219:tid 890384] [client 20.203.200.218:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/dph.php"] [unique_id "amuYV4JkCYmL5o6vh9KAUAAAAKc"]
[Thu Jul 30 13:30:47.720250 2026] [security2:error] [pid 890219:tid 890384] [client 20.203.200.218:52191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/dph.php"] [unique_id "amuYV4JkCYmL5o6vh9KAUAAAAKc"]
[Thu Jul 30 13:30:48.021566 2026] [security2:error] [pid 890219:tid 890469] [client 20.203.200.218:42058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/todo.php"] [unique_id "amuYWIJkCYmL5o6vh9KAXQAAAPw"]
[Thu Jul 30 13:30:48.021701 2026] [security2:error] [pid 890219:tid 890469] [client 20.203.200.218:42058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/todo.php"] [unique_id "amuYWIJkCYmL5o6vh9KAXQAAAPw"]
[Thu Jul 30 13:30:48.188482 2026] [security2:error] [pid 890219:tid 890403] [client 40.77.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYV4JkCYmL5o6vh9KAWQAAALo"]
[Thu Jul 30 13:30:48.279226 2026] [security2:error] [pid 890219:tid 890358] [client 20.203.200.218:52205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/shoop.php"] [unique_id "amuYWIJkCYmL5o6vh9KAXgAAAI0"]
[Thu Jul 30 13:30:48.279364 2026] [security2:error] [pid 890219:tid 890358] [client 20.203.200.218:52205] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/shoop.php"] [unique_id "amuYWIJkCYmL5o6vh9KAXgAAAI0"]
[Thu Jul 30 13:30:48.531474 2026] [security2:error] [pid 890219:tid 890397] [client 20.203.200.218:52203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wsa.php"] [unique_id "amuYWIJkCYmL5o6vh9KAZQAAALQ"]
[Thu Jul 30 13:30:48.531570 2026] [security2:error] [pid 890219:tid 890397] [client 20.203.200.218:52203] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wsa.php"] [unique_id "amuYWIJkCYmL5o6vh9KAZQAAALQ"]
[Thu Jul 30 13:30:48.785595 2026] [security2:error] [pid 890219:tid 890394] [client 20.203.200.218:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/22625814acb09634e45d67c98c55a6a2f6e2532c_0.file.painel.html.php"] [unique_id "amuYWIJkCYmL5o6vh9KAaQAAALE"]
[Thu Jul 30 13:30:48.785716 2026] [security2:error] [pid 890219:tid 890394] [client 20.203.200.218:45510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/22625814acb09634e45d67c98c55a6a2f6e2532c_0.file.painel.html.php"] [unique_id "amuYWIJkCYmL5o6vh9KAaQAAALE"]
[Thu Jul 30 13:30:49.069234 2026] [security2:error] [pid 890219:tid 890415] [client 20.203.200.218:62449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/m4m4nkmud4.php"] [unique_id "amuYWYJkCYmL5o6vh9KAdwAAAMY"]
[Thu Jul 30 13:30:49.069335 2026] [security2:error] [pid 890219:tid 890415] [client 20.203.200.218:62449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/m4m4nkmud4.php"] [unique_id "amuYWYJkCYmL5o6vh9KAdwAAAMY"]
[Thu Jul 30 13:30:49.176487 2026] [security2:error] [pid 890219:tid 890453] [client 40.77.167.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuYWIJkCYmL5o6vh9KAbwAAAOw"]
[Thu Jul 30 13:30:49.333268 2026] [security2:error] [pid 890219:tid 890393] [client 20.203.200.218:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-go.php"] [unique_id "amuYWYJkCYmL5o6vh9KAewAAALA"]
[Thu Jul 30 13:30:49.333414 2026] [security2:error] [pid 890219:tid 890393] [client 20.203.200.218:45142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-go.php"] [unique_id "amuYWYJkCYmL5o6vh9KAewAAALA"]
[Thu Jul 30 13:30:49.600172 2026] [security2:error] [pid 890219:tid 890458] [client 20.203.200.218:45538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/red404.php"] [unique_id "amuYWYJkCYmL5o6vh9KAhgAAAPE"]
[Thu Jul 30 13:30:49.600328 2026] [security2:error] [pid 890219:tid 890458] [client 20.203.200.218:45538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/red404.php"] [unique_id "amuYWYJkCYmL5o6vh9KAhgAAAPE"]
[Thu Jul 30 13:30:49.886906 2026] [security2:error] [pid 890219:tid 890442] [client 20.203.200.218:61128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/kdoor.php"] [unique_id "amuYWYJkCYmL5o6vh9KAhwAAAOE"]
[Thu Jul 30 13:30:49.887039 2026] [security2:error] [pid 890219:tid 890442] [client 20.203.200.218:61128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/kdoor.php"] [unique_id "amuYWYJkCYmL5o6vh9KAhwAAAOE"]
[Thu Jul 30 13:30:50.148735 2026] [security2:error] [pid 890219:tid 890402] [client 20.203.200.218:62429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/years.php"] [unique_id "amuYWoJkCYmL5o6vh9KAkQAAALk"]
[Thu Jul 30 13:30:50.148877 2026] [security2:error] [pid 890219:tid 890402] [client 20.203.200.218:62429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/years.php"] [unique_id "amuYWoJkCYmL5o6vh9KAkQAAALk"]
[Thu Jul 30 13:30:50.417048 2026] [security2:error] [pid 890219:tid 890389] [client 20.203.200.218:45537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/galekjaya.php"] [unique_id "amuYWoJkCYmL5o6vh9KAkwAAAKw"]
[Thu Jul 30 13:30:50.417152 2026] [security2:error] [pid 890219:tid 890389] [client 20.203.200.218:45537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/galekjaya.php"] [unique_id "amuYWoJkCYmL5o6vh9KAkwAAAKw"]
[Thu Jul 30 13:30:50.599773 2026] [security2:error] [pid 890219:tid 890356] [client 179.64.21.229:36572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYWoJkCYmL5o6vh9KAnAAAAIs"]
[Thu Jul 30 13:30:50.600349 2026] [security2:error] [pid 890219:tid 890356] [client 179.64.21.229:36572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYWoJkCYmL5o6vh9KAnAAAAIs"]
[Thu Jul 30 13:30:50.678290 2026] [security2:error] [pid 890219:tid 890391] [client 20.203.200.218:61126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-admin/evil.php"] [unique_id "amuYWoJkCYmL5o6vh9KAnwAAAK4"]
[Thu Jul 30 13:30:50.678480 2026] [security2:error] [pid 890219:tid 890391] [client 20.203.200.218:61126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-admin/evil.php"] [unique_id "amuYWoJkCYmL5o6vh9KAnwAAAK4"]
[Thu Jul 30 13:30:50.942728 2026] [security2:error] [pid 890219:tid 890444] [client 20.203.200.218:62424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-admin/ichi.php"] [unique_id "amuYWoJkCYmL5o6vh9KAoQAAAOM"]
[Thu Jul 30 13:30:50.942852 2026] [security2:error] [pid 890219:tid 890444] [client 20.203.200.218:62424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/wp-admin/ichi.php"] [unique_id "amuYWoJkCYmL5o6vh9KAoQAAAOM"]
[Thu Jul 30 13:30:51.227906 2026] [security2:error] [pid 890219:tid 890474] [client 78.167.1.90:54909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYWoJkCYmL5o6vh9KAowAAAQE"]
[Thu Jul 30 13:30:51.228143 2026] [security2:error] [pid 890219:tid 890474] [client 78.167.1.90:54909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYWoJkCYmL5o6vh9KAowAAAQE"]
[Thu Jul 30 13:30:51.230256 2026] [security2:error] [pid 890219:tid 890377] [client 20.203.200.218:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/turkiye.php"] [unique_id "amuYW4JkCYmL5o6vh9KArQAAAKA"]
[Thu Jul 30 13:30:51.230332 2026] [security2:error] [pid 890219:tid 890377] [client 20.203.200.218:52166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/turkiye.php"] [unique_id "amuYW4JkCYmL5o6vh9KArQAAAKA"]
[Thu Jul 30 13:30:51.495926 2026] [security2:error] [pid 890219:tid 890366] [client 20.203.200.218:42096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/max.php"] [unique_id "amuYW4JkCYmL5o6vh9KAsQAAAJU"]
[Thu Jul 30 13:30:51.496040 2026] [security2:error] [pid 890219:tid 890366] [client 20.203.200.218:42096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/max.php"] [unique_id "amuYW4JkCYmL5o6vh9KAsQAAAJU"]
[Thu Jul 30 13:30:51.776618 2026] [security2:error] [pid 890219:tid 890435] [client 20.203.200.218:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/you.php"] [unique_id "amuYW4JkCYmL5o6vh9KAuAAAANo"]
[Thu Jul 30 13:30:51.776725 2026] [security2:error] [pid 890219:tid 890435] [client 20.203.200.218:61154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/you.php"] [unique_id "amuYW4JkCYmL5o6vh9KAuAAAANo"]
[Thu Jul 30 13:30:51.813000 2026] [core:notice] [pid 890219:tid 890467] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:52.025706 2026] [security2:error] [pid 890219:tid 890417] [client 20.203.200.218:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/a.php"] [unique_id "amuYXIJkCYmL5o6vh9KAuwAAAMg"]
[Thu Jul 30 13:30:52.025803 2026] [security2:error] [pid 890219:tid 890417] [client 20.203.200.218:62416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/a.php"] [unique_id "amuYXIJkCYmL5o6vh9KAuwAAAMg"]
[Thu Jul 30 13:30:52.277268 2026] [security2:error] [pid 890219:tid 890470] [client 20.203.200.218:45134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ap.php"] [unique_id "amuYXIJkCYmL5o6vh9KAxwAAAP0"]
[Thu Jul 30 13:30:52.277416 2026] [security2:error] [pid 890219:tid 890470] [client 20.203.200.218:45134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ap.php"] [unique_id "amuYXIJkCYmL5o6vh9KAxwAAAP0"]
[Thu Jul 30 13:30:52.316482 2026] [security2:error] [pid 890219:tid 890372] [client 85.208.96.207:47896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/16/semana-do-pcd-inicia-com-140-oportunidades-novas-e-remanescentes-em-campina-grande/"] [unique_id "amuYXIJkCYmL5o6vh9KAywAAAJs"]
[Thu Jul 30 13:30:52.316573 2026] [security2:error] [pid 890219:tid 890372] [client 85.208.96.207:47896] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/16/semana-do-pcd-inicia-com-140-oportunidades-novas-e-remanescentes-em-campina-grande/"] [unique_id "amuYXIJkCYmL5o6vh9KAywAAAJs"]
[Thu Jul 30 13:30:52.570968 2026] [security2:error] [pid 890219:tid 890448] [client 20.203.200.218:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/000000.php"] [unique_id "amuYXIJkCYmL5o6vh9KA0QAAAOc"]
[Thu Jul 30 13:30:52.571100 2026] [security2:error] [pid 890219:tid 890448] [client 20.203.200.218:45120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/000000.php"] [unique_id "amuYXIJkCYmL5o6vh9KA0QAAAOc"]
[Thu Jul 30 13:30:52.856963 2026] [security2:error] [pid 890219:tid 890380] [client 20.203.200.218:45505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/mosok.php"] [unique_id "amuYXIJkCYmL5o6vh9KA2AAAAKM"]
[Thu Jul 30 13:30:52.857081 2026] [security2:error] [pid 890219:tid 890380] [client 20.203.200.218:45505] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/mosok.php"] [unique_id "amuYXIJkCYmL5o6vh9KA2AAAAKM"]
[Thu Jul 30 13:30:53.150807 2026] [security2:error] [pid 890219:tid 890461] [client 20.203.200.218:62405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/kamu.php"] [unique_id "amuYXYJkCYmL5o6vh9KA3wAAAPQ"]
[Thu Jul 30 13:30:53.150903 2026] [security2:error] [pid 890219:tid 890461] [client 20.203.200.218:62405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/kamu.php"] [unique_id "amuYXYJkCYmL5o6vh9KA3wAAAPQ"]
[Thu Jul 30 13:30:53.392501 2026] [security2:error] [pid 890219:tid 890404] [client 74.7.228.23:42612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuYXYJkCYmL5o6vh9KA5gAAALs"]
[Thu Jul 30 13:30:53.429311 2026] [security2:error] [pid 890219:tid 890366] [client 20.203.200.218:45137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/inject.php"] [unique_id "amuYXYJkCYmL5o6vh9KA5wAAAJU"]
[Thu Jul 30 13:30:53.429407 2026] [security2:error] [pid 890219:tid 890366] [client 20.203.200.218:45137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/inject.php"] [unique_id "amuYXYJkCYmL5o6vh9KA5wAAAJU"]
[Thu Jul 30 13:30:53.684351 2026] [proxy:error] [pid 890219:tid 890357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:53.684420 2026] [proxy_http:error] [pid 890219:tid 890357] [client 20.203.200.218:51757] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:53.685162 2026] [proxy:error] [pid 890219:tid 890357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:53.685213 2026] [proxy_http:error] [pid 890219:tid 890357] [client 20.203.200.218:51757] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:53.685311 2026] [security2:error] [pid 890219:tid 890357] [client 20.203.200.218:51757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuYXYJkCYmL5o6vh9KA6wAAAIw"]
[Thu Jul 30 13:30:53.913749 2026] [security2:error] [pid 890219:tid 890403] [client 74.7.241.144:32816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.myabudhabidesertsafari.com"] [uri "/robots.txt"] [unique_id "amuYXYJkCYmL5o6vh9KA9AAAukk"]
[Thu Jul 30 13:30:53.948918 2026] [security2:error] [pid 890219:tid 890397] [client 20.203.200.218:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/iya.php"] [unique_id "amuYXYJkCYmL5o6vh9KA9QAAALQ"]
[Thu Jul 30 13:30:53.949034 2026] [security2:error] [pid 890219:tid 890397] [client 20.203.200.218:45558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/iya.php"] [unique_id "amuYXYJkCYmL5o6vh9KA9QAAALQ"]
[Thu Jul 30 13:30:54.087458 2026] [security2:error] [pid 890219:tid 890352] [client 119.73.97.132:29980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuYXYJkCYmL5o6vh9KA8wAAh0c"], referer: https://www.urwru.club/wp-admin/upload.php
[Thu Jul 30 13:30:54.202318 2026] [security2:error] [pid 890219:tid 890382] [client 20.203.200.218:45514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/sj.php"] [unique_id "amuYXoJkCYmL5o6vh9KA_wAAAKU"]
[Thu Jul 30 13:30:54.202428 2026] [security2:error] [pid 890219:tid 890382] [client 20.203.200.218:45514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/sj.php"] [unique_id "amuYXoJkCYmL5o6vh9KA_wAAAKU"]
[Thu Jul 30 13:30:54.306400 2026] [security2:error] [pid 890219:tid 890439] [client 185.189.112.19:55458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuYXoJkCYmL5o6vh9KA9wAAAN4"]
[Thu Jul 30 13:30:54.306543 2026] [security2:error] [pid 890219:tid 890439] [client 185.189.112.19:55458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuYXoJkCYmL5o6vh9KA9wAAAN4"]
[Thu Jul 30 13:30:54.498169 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/gca.php"] [unique_id "amuYXoJkCYmL5o6vh9KBAwAAALU"]
[Thu Jul 30 13:30:54.498282 2026] [security2:error] [pid 890219:tid 890398] [client 20.203.200.218:52206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/gca.php"] [unique_id "amuYXoJkCYmL5o6vh9KBAwAAALU"]
[Thu Jul 30 13:30:54.750379 2026] [security2:error] [pid 890219:tid 890353] [client 20.203.200.218:45534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/koe.php"] [unique_id "amuYXoJkCYmL5o6vh9KBCgAAAIg"]
[Thu Jul 30 13:30:54.750473 2026] [security2:error] [pid 890219:tid 890353] [client 20.203.200.218:45534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/koe.php"] [unique_id "amuYXoJkCYmL5o6vh9KBCgAAAIg"]
[Thu Jul 30 13:30:55.006661 2026] [security2:error] [pid 890219:tid 890384] [client 20.203.200.218:42054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/konten.php"] [unique_id "amuYX4JkCYmL5o6vh9KBEAAAAKc"]
[Thu Jul 30 13:30:55.006774 2026] [security2:error] [pid 890219:tid 890384] [client 20.203.200.218:42054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/konten.php"] [unique_id "amuYX4JkCYmL5o6vh9KBEAAAAKc"]
[Thu Jul 30 13:30:55.240024 2026] [security2:error] [pid 890219:tid 890324] [remote 57.141.0.41:31994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/591457414/feed/rss2/"] [unique_id "amuYX4JkCYmL5o6vh9KBIAAAw2c"]
[Thu Jul 30 13:30:55.259673 2026] [security2:error] [pid 890219:tid 890366] [client 20.203.200.218:61178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/bekdur.php"] [unique_id "amuYX4JkCYmL5o6vh9KBIwAAAJU"]
[Thu Jul 30 13:30:55.259763 2026] [security2:error] [pid 890219:tid 890366] [client 20.203.200.218:61178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/bekdur.php"] [unique_id "amuYX4JkCYmL5o6vh9KBIwAAAJU"]
[Thu Jul 30 13:30:55.537151 2026] [security2:error] [pid 890219:tid 890419] [client 20.203.200.218:51724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/webadmin.php"] [unique_id "amuYX4JkCYmL5o6vh9KBKwAAAMo"]
[Thu Jul 30 13:30:55.537291 2026] [security2:error] [pid 890219:tid 890419] [client 20.203.200.218:51724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/webadmin.php"] [unique_id "amuYX4JkCYmL5o6vh9KBKwAAAMo"]
[Thu Jul 30 13:30:55.795787 2026] [security2:error] [pid 890219:tid 890403] [client 20.203.200.218:62436] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/r57.php"] [unique_id "amuYX4JkCYmL5o6vh9KBNAAAALo"]
[Thu Jul 30 13:30:55.796531 2026] [proxy:error] [pid 890219:tid 890403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:55.796600 2026] [proxy_http:error] [pid 890219:tid 890403] [client 20.203.200.218:62436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:55.796676 2026] [security2:error] [pid 890219:tid 890403] [client 20.203.200.218:62436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/403.html"] [unique_id "amuYX4JkCYmL5o6vh9KBNAAAALo"]
[Thu Jul 30 13:30:56.081756 2026] [security2:error] [pid 890219:tid 890406] [client 20.203.200.218:45145] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/r57.php"] [unique_id "amuYYIJkCYmL5o6vh9KBOAAAAL0"]
[Thu Jul 30 13:30:56.082911 2026] [proxy:error] [pid 890219:tid 890406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:56.083001 2026] [proxy_http:error] [pid 890219:tid 890406] [client 20.203.200.218:45145] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:56.083079 2026] [security2:error] [pid 890219:tid 890406] [client 20.203.200.218:45145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/403.html"] [unique_id "amuYYIJkCYmL5o6vh9KBOAAAAL0"]
[Thu Jul 30 13:30:56.403786 2026] [security2:error] [pid 890219:tid 890451] [client 20.203.200.218:52204] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/r57.php"] [unique_id "amuYYIJkCYmL5o6vh9KBTgAAAOo"]
[Thu Jul 30 13:30:56.404286 2026] [proxy:error] [pid 890219:tid 890451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:56.404340 2026] [proxy_http:error] [pid 890219:tid 890451] [client 20.203.200.218:52204] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:56.404397 2026] [security2:error] [pid 890219:tid 890451] [client 20.203.200.218:52204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/403.html"] [unique_id "amuYYIJkCYmL5o6vh9KBTgAAAOo"]
[Thu Jul 30 13:30:56.658537 2026] [security2:error] [pid 890219:tid 890456] [client 20.203.200.218:51728] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/c99.php"] [unique_id "amuYYIJkCYmL5o6vh9KBTwAAAO8"]
[Thu Jul 30 13:30:56.659575 2026] [proxy:error] [pid 890219:tid 890456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:56.659668 2026] [proxy_http:error] [pid 890219:tid 890456] [client 20.203.200.218:51728] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:56.659736 2026] [security2:error] [pid 890219:tid 890456] [client 20.203.200.218:51728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/403.html"] [unique_id "amuYYIJkCYmL5o6vh9KBTwAAAO8"]
[Thu Jul 30 13:30:56.965944 2026] [security2:error] [pid 890219:tid 890379] [client 20.203.200.218:45180] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/c99.php"] [unique_id "amuYYIJkCYmL5o6vh9KBXQAAAKI"]
[Thu Jul 30 13:30:56.966943 2026] [proxy:error] [pid 890219:tid 890379] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:56.967022 2026] [proxy_http:error] [pid 890219:tid 890379] [client 20.203.200.218:45180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:56.967085 2026] [security2:error] [pid 890219:tid 890379] [client 20.203.200.218:45180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/403.html"] [unique_id "amuYYIJkCYmL5o6vh9KBXQAAAKI"]
[Thu Jul 30 13:30:56.994763 2026] [security2:error] [pid 890219:tid 890459] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuYYIJkCYmL5o6vh9KBVgAAAPI"]
[Thu Jul 30 13:30:57.226710 2026] [security2:error] [pid 890219:tid 890437] [client 20.203.200.218:52199] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/c99.php"] [unique_id "amuYYYJkCYmL5o6vh9KBZAAAANw"]
[Thu Jul 30 13:30:57.227461 2026] [proxy:error] [pid 890219:tid 890437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:57.227531 2026] [proxy_http:error] [pid 890219:tid 890437] [client 20.203.200.218:52199] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:57.227600 2026] [security2:error] [pid 890219:tid 890437] [client 20.203.200.218:52199] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/403.html"] [unique_id "amuYYYJkCYmL5o6vh9KBZAAAANw"]
[Thu Jul 30 13:30:57.499495 2026] [security2:error] [pid 890219:tid 890427] [client 20.203.200.218:52181] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/c99.php"] [unique_id "amuYYYJkCYmL5o6vh9KBbwAAANI"]
[Thu Jul 30 13:30:57.500496 2026] [proxy:error] [pid 890219:tid 890427] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:30:57.500567 2026] [proxy_http:error] [pid 890219:tid 890427] [client 20.203.200.218:52181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:30:57.500624 2026] [security2:error] [pid 890219:tid 890427] [client 20.203.200.218:52181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/403.html"] [unique_id "amuYYYJkCYmL5o6vh9KBbwAAANI"]
[Thu Jul 30 13:30:57.663104 2026] [security2:error] [pid 890219:tid 890347] [remote 57.141.0.17:65182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4627290655/feed/rss2/"] [unique_id "amuYYYJkCYmL5o6vh9KBcAAA9X4"]
[Thu Jul 30 13:30:57.792805 2026] [security2:error] [pid 890219:tid 890440] [client 20.203.200.218:61138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/xxx.php"] [unique_id "amuYYYJkCYmL5o6vh9KBcQAAAN8"]
[Thu Jul 30 13:30:57.792959 2026] [security2:error] [pid 890219:tid 890440] [client 20.203.200.218:61138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/xxx.php"] [unique_id "amuYYYJkCYmL5o6vh9KBcQAAAN8"]
[Thu Jul 30 13:30:57.942639 2026] [autoindex:error] [pid 890219:tid 890348] [remote 139.144.212.130:35260] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:30:58.064893 2026] [security2:error] [pid 890219:tid 890431] [client 20.203.200.218:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/arab.php"] [unique_id "amuYYoJkCYmL5o6vh9KBfgAAANY"]
[Thu Jul 30 13:30:58.065000 2026] [security2:error] [pid 890219:tid 890431] [client 20.203.200.218:61130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/arab.php"] [unique_id "amuYYoJkCYmL5o6vh9KBfgAAANY"]
[Thu Jul 30 13:30:58.150578 2026] [core:notice] [pid 890219:tid 890382] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:58.325088 2026] [security2:error] [pid 890219:tid 890372] [client 20.203.200.218:51725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/bd.php"] [unique_id "amuYYoJkCYmL5o6vh9KBgAAAAJs"]
[Thu Jul 30 13:30:58.325208 2026] [security2:error] [pid 890219:tid 890372] [client 20.203.200.218:51725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/bd.php"] [unique_id "amuYYoJkCYmL5o6vh9KBgAAAAJs"]
[Thu Jul 30 13:30:58.594060 2026] [security2:error] [pid 890219:tid 890420] [client 20.203.200.218:45165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/komet.php"] [unique_id "amuYYoJkCYmL5o6vh9KBigAAAMs"]
[Thu Jul 30 13:30:58.594187 2026] [security2:error] [pid 890219:tid 890420] [client 20.203.200.218:45165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/komet.php"] [unique_id "amuYYoJkCYmL5o6vh9KBigAAAMs"]
[Thu Jul 30 13:30:58.643268 2026] [core:notice] [pid 890219:tid 890475] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:58.884106 2026] [security2:error] [pid 890219:tid 890410] [client 20.203.200.218:42051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/1337.php"] [unique_id "amuYYoJkCYmL5o6vh9KBjQAAAME"]
[Thu Jul 30 13:30:58.884211 2026] [security2:error] [pid 890219:tid 890410] [client 20.203.200.218:42051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/1337.php"] [unique_id "amuYYoJkCYmL5o6vh9KBjQAAAME"]
[Thu Jul 30 13:30:59.146914 2026] [security2:error] [pid 890219:tid 890430] [client 20.203.200.218:45157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/backd00r.php"] [unique_id "amuYY4JkCYmL5o6vh9KBmAAAANU"]
[Thu Jul 30 13:30:59.147039 2026] [security2:error] [pid 890219:tid 890430] [client 20.203.200.218:45157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/backd00r.php"] [unique_id "amuYY4JkCYmL5o6vh9KBmAAAANU"]
[Thu Jul 30 13:30:59.398868 2026] [core:notice] [pid 890219:tid 890230] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:30:59.427813 2026] [security2:error] [pid 890219:tid 890450] [client 20.203.200.218:45525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/backdoor.php"] [unique_id "amuYY4JkCYmL5o6vh9KBngAAAOk"]
[Thu Jul 30 13:30:59.427911 2026] [security2:error] [pid 890219:tid 890450] [client 20.203.200.218:45525] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/backdoor.php"] [unique_id "amuYY4JkCYmL5o6vh9KBngAAAOk"]
[Thu Jul 30 13:30:59.448268 2026] [security2:error] [pid 890219:tid 890386] [client 85.208.96.198:36214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2013/11/cara-mengganti-layar-lcd-netbook-acer"] [unique_id "amuYY4JkCYmL5o6vh9KBoAAAAKk"]
[Thu Jul 30 13:30:59.448356 2026] [security2:error] [pid 890219:tid 890386] [client 85.208.96.198:36214] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2013/11/cara-mengganti-layar-lcd-netbook-acer"] [unique_id "amuYY4JkCYmL5o6vh9KBoAAAAKk"]
[Thu Jul 30 13:30:59.526029 2026] [security2:error] [pid 890219:tid 890474] [client 74.7.244.52:33348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pwy.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuYY4JkCYmL5o6vh9KBpQAAAQE"]
[Thu Jul 30 13:30:59.709616 2026] [security2:error] [pid 890219:tid 890401] [client 20.203.200.218:45550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/andela.php"] [unique_id "amuYY4JkCYmL5o6vh9KBqgAAALg"]
[Thu Jul 30 13:30:59.709723 2026] [security2:error] [pid 890219:tid 890401] [client 20.203.200.218:45550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/andela.php"] [unique_id "amuYY4JkCYmL5o6vh9KBqgAAALg"]
[Thu Jul 30 13:31:00.020228 2026] [security2:error] [pid 890219:tid 890470] [client 20.203.200.218:51751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/jkt48.php"] [unique_id "amuYZIJkCYmL5o6vh9KBsQAAAP0"]
[Thu Jul 30 13:31:00.020313 2026] [security2:error] [pid 890219:tid 890470] [client 20.203.200.218:51751] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/jkt48.php"] [unique_id "amuYZIJkCYmL5o6vh9KBsQAAAP0"]
[Thu Jul 30 13:31:00.341189 2026] [security2:error] [pid 890219:tid 890408] [client 20.203.200.218:45178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/gaza.php"] [unique_id "amuYZIJkCYmL5o6vh9KBwQAAAL8"]
[Thu Jul 30 13:31:00.341316 2026] [security2:error] [pid 890219:tid 890408] [client 20.203.200.218:45178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/gaza.php"] [unique_id "amuYZIJkCYmL5o6vh9KBwQAAAL8"]
[Thu Jul 30 13:31:00.605928 2026] [security2:error] [pid 890219:tid 890443] [client 20.203.200.218:61156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/injection.php"] [unique_id "amuYZIJkCYmL5o6vh9KByAAAAOI"]
[Thu Jul 30 13:31:00.606046 2026] [security2:error] [pid 890219:tid 890443] [client 20.203.200.218:61156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/injection.php"] [unique_id "amuYZIJkCYmL5o6vh9KByAAAAOI"]
[Thu Jul 30 13:31:00.866390 2026] [security2:error] [pid 890219:tid 890412] [client 20.203.200.218:61181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/bejak.php"] [unique_id "amuYZIJkCYmL5o6vh9KBzAAAAMM"]
[Thu Jul 30 13:31:00.866509 2026] [security2:error] [pid 890219:tid 890412] [client 20.203.200.218:61181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/bejak.php"] [unique_id "amuYZIJkCYmL5o6vh9KBzAAAAMM"]
[Thu Jul 30 13:31:01.167019 2026] [security2:error] [pid 890219:tid 890461] [client 20.203.200.218:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/idca_shell.php"] [unique_id "amuYZYJkCYmL5o6vh9KB2QAAAPQ"]
[Thu Jul 30 13:31:01.167109 2026] [security2:error] [pid 890219:tid 890461] [client 20.203.200.218:51762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/idca_shell.php"] [unique_id "amuYZYJkCYmL5o6vh9KB2QAAAPQ"]
[Thu Jul 30 13:31:01.445221 2026] [security2:error] [pid 890219:tid 890438] [client 20.203.200.218:61138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/idca.php"] [unique_id "amuYZYJkCYmL5o6vh9KB2wAAAN0"]
[Thu Jul 30 13:31:01.445323 2026] [security2:error] [pid 890219:tid 890438] [client 20.203.200.218:61138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/idca.php"] [unique_id "amuYZYJkCYmL5o6vh9KB2wAAAN0"]
[Thu Jul 30 13:31:01.526255 2026] [security2:error] [pid 890219:tid 890388] [client 78.167.1.90:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYZYJkCYmL5o6vh9KB3wAAAKs"]
[Thu Jul 30 13:31:01.526854 2026] [security2:error] [pid 890219:tid 890388] [client 78.167.1.90:54090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYZYJkCYmL5o6vh9KB3wAAAKs"]
[Thu Jul 30 13:31:01.558044 2026] [security2:error] [pid 890219:tid 890385] [client 179.64.21.229:10087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYZYJkCYmL5o6vh9KB4AAAAKg"]
[Thu Jul 30 13:31:01.558174 2026] [security2:error] [pid 890219:tid 890385] [client 179.64.21.229:10087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuYZYJkCYmL5o6vh9KB4AAAAKg"]
[Thu Jul 30 13:31:01.698656 2026] [security2:error] [pid 890219:tid 890352] [client 20.203.200.218:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indoxploit_shell.php"] [unique_id "amuYZYJkCYmL5o6vh9KB6wAAAIc"]
[Thu Jul 30 13:31:01.698828 2026] [security2:error] [pid 890219:tid 890352] [client 20.203.200.218:52194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/indoxploit_shell.php"] [unique_id "amuYZYJkCYmL5o6vh9KB6wAAAIc"]
[Thu Jul 30 13:31:01.829254 2026] [core:error] [pid 890219:tid 890282] [remote 74.7.230.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:01.829276 2026] [core:error] [pid 890219:tid 890282] [remote 74.7.230.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:01.829472 2026] [security2:error] [pid 890219:tid 890420] [client 74.7.230.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.appliancerepairservice.one"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuYZYJkCYmL5o6vh9KB7AAAyz0"]
[Thu Jul 30 13:31:03.705047 2026] [core:notice] [pid 890219:tid 890380] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:04.994398 2026] [core:error] [pid 890219:tid 890379] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:04.994428 2026] [core:error] [pid 890219:tid 890379] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:06.207509 2026] [security2:error] [pid 890219:tid 890346] [remote 57.141.0.15:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/63798190810/feed/rss2/"] [unique_id "amuYaoJkCYmL5o6vh9KCbAAA4X0"]
[Thu Jul 30 13:31:08.416597 2026] [security2:error] [pid 890219:tid 890438] [client 57.141.0.34:39934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuYbIJkCYmL5o6vh9KClwAA3RM"], referer: https://igetvape-australia.com/product/iget-moon-blueberry-raspberry-ice/?add-to-cart=175
[Thu Jul 30 13:31:09.982740 2026] [security2:error] [pid 890219:tid 890230] [remote 47.128.27.39:50882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-13-retro-white-lucky-orange/"] [unique_id "amuYbYJkCYmL5o6vh9KCvgAAvAk"]
[Thu Jul 30 13:31:10.093167 2026] [security2:error] [pid 890219:tid 890424] [client 68.235.48.108:54402] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuYbYJkCYmL5o6vh9KCtwAAAM8"]
[Thu Jul 30 13:31:10.093278 2026] [security2:error] [pid 890219:tid 890424] [client 68.235.48.108:54402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuYbYJkCYmL5o6vh9KCtwAAAM8"]
[Thu Jul 30 13:31:10.607331 2026] [core:error] [pid 890219:tid 890429] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.607359 2026] [core:error] [pid 890219:tid 890429] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.610018 2026] [security2:error] [pid 890219:tid 890367] [client 34.24.215.179:2894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/.env"] [unique_id "amuYboJkCYmL5o6vh9KC1wAAAJY"]
[Thu Jul 30 13:31:10.610109 2026] [security2:error] [pid 890219:tid 890352] [client 34.24.215.179:2938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "amuYboJkCYmL5o6vh9KC1gAAAIc"]
[Thu Jul 30 13:31:10.610121 2026] [security2:error] [pid 890219:tid 890367] [client 34.24.215.179:2894] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/.env"] [unique_id "amuYboJkCYmL5o6vh9KC1wAAAJY"]
[Thu Jul 30 13:31:10.612551 2026] [security2:error] [pid 890219:tid 890356] [client 34.24.215.179:2932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/.env.bak"] [unique_id "amuYboJkCYmL5o6vh9KC3AAAAIs"]
[Thu Jul 30 13:31:10.614923 2026] [core:error] [pid 890219:tid 890400] [client 34.24.215.179:2954] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.614938 2026] [core:error] [pid 890219:tid 890400] [client 34.24.215.179:2954] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.616636 2026] [core:error] [pid 890219:tid 890358] [client 34.24.215.179:2940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.616662 2026] [core:error] [pid 890219:tid 890358] [client 34.24.215.179:2940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.617596 2026] [security2:error] [pid 890219:tid 890359] [client 34.24.215.179:2956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "amuYboJkCYmL5o6vh9KC3gAAAI4"]
[Thu Jul 30 13:31:10.619175 2026] [security2:error] [pid 890219:tid 890454] [client 34.24.215.179:2966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "amuYboJkCYmL5o6vh9KC4AAAAO0"]
[Thu Jul 30 13:31:10.621141 2026] [core:error] [pid 890219:tid 890416] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.621156 2026] [core:error] [pid 890219:tid 890416] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.622809 2026] [security2:error] [pid 890219:tid 890350] [client 34.24.215.179:2974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "amuYboJkCYmL5o6vh9KC4wAAAIU"]
[Thu Jul 30 13:31:10.623108 2026] [core:error] [pid 890219:tid 890370] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.623125 2026] [core:error] [pid 890219:tid 890370] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.624865 2026] [security2:error] [pid 890219:tid 890408] [client 34.24.215.179:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "amuYboJkCYmL5o6vh9KC5AAAAL8"]
[Thu Jul 30 13:31:10.625549 2026] [security2:error] [pid 890219:tid 890470] [client 34.24.215.179:3018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "amuYboJkCYmL5o6vh9KC5QAAAP0"]
[Thu Jul 30 13:31:10.626947 2026] [security2:error] [pid 890219:tid 890453] [client 34.24.215.179:3014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "amuYboJkCYmL5o6vh9KC6AAAAOw"]
[Thu Jul 30 13:31:10.635025 2026] [security2:error] [pid 890219:tid 890444] [client 34.24.215.179:2950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "amuYboJkCYmL5o6vh9KC8wAAAOM"]
[Thu Jul 30 13:31:10.635776 2026] [core:error] [pid 890219:tid 890473] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.635788 2026] [core:error] [pid 890219:tid 890473] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.636726 2026] [core:error] [pid 890219:tid 890379] [client 34.24.215.179:3102] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.636740 2026] [core:error] [pid 890219:tid 890379] [client 34.24.215.179:3102] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.639005 2026] [security2:error] [pid 890219:tid 890382] [client 34.24.215.179:3088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/.gcloud/credentials"] [unique_id "amuYboJkCYmL5o6vh9KC_QAAAKU"]
[Thu Jul 30 13:31:10.639089 2026] [security2:error] [pid 890219:tid 890382] [client 34.24.215.179:3088] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/.gcloud/credentials"] [unique_id "amuYboJkCYmL5o6vh9KC_QAAAKU"]
[Thu Jul 30 13:31:10.640669 2026] [core:error] [pid 890219:tid 890465] [client 34.24.215.179:3112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.640686 2026] [core:error] [pid 890219:tid 890465] [client 34.24.215.179:3112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.642766 2026] [core:error] [pid 890219:tid 890460] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.642781 2026] [core:error] [pid 890219:tid 890460] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.642944 2026] [core:error] [pid 890219:tid 890434] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.642959 2026] [core:error] [pid 890219:tid 890434] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.643064 2026] [core:error] [pid 890219:tid 890389] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.643081 2026] [core:error] [pid 890219:tid 890389] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.645520 2026] [core:error] [pid 890219:tid 890474] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.645539 2026] [core:error] [pid 890219:tid 890474] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.647056 2026] [core:error] [pid 890219:tid 890442] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.647069 2026] [core:error] [pid 890219:tid 890442] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.648249 2026] [core:error] [pid 890219:tid 890476] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.648264 2026] [core:error] [pid 890219:tid 890476] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.648438 2026] [core:error] [pid 890219:tid 890423] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.648457 2026] [core:error] [pid 890219:tid 890423] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.651741 2026] [core:error] [pid 890219:tid 890363] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.651768 2026] [core:error] [pid 890219:tid 890363] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.651949 2026] [core:error] [pid 890219:tid 890374] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.651961 2026] [core:error] [pid 890219:tid 890374] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.654275 2026] [core:error] [pid 890219:tid 890385] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.654292 2026] [core:error] [pid 890219:tid 890385] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.654490 2026] [security2:error] [pid 890219:tid 890407] [client 34.24.215.179:3124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.ssh/id_rsa"] [unique_id "amuYboJkCYmL5o6vh9KDDgAAAL4"]
[Thu Jul 30 13:31:10.656342 2026] [security2:error] [pid 890219:tid 890433] [client 34.24.215.179:3140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/.ssh/id_ed25519"] [unique_id "amuYboJkCYmL5o6vh9KDEQAAANg"]
[Thu Jul 30 13:31:10.664665 2026] [core:error] [pid 890219:tid 890422] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.664683 2026] [core:error] [pid 890219:tid 890422] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.665817 2026] [core:error] [pid 890219:tid 890395] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.665835 2026] [core:error] [pid 890219:tid 890395] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:10.666002 2026] [security2:error] [pid 890219:tid 890395] [client 34.24.215.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuYboJkCYmL5o6vh9KDEgAAALI"]
[Thu Jul 30 13:31:10.666607 2026] [security2:error] [pid 890219:tid 890425] [client 34.24.215.179:3060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.aws/credentials"] [unique_id "amuYboJkCYmL5o6vh9KDDAAAANA"]
[Thu Jul 30 13:31:11.089299 2026] [security2:error] [pid 890219:tid 890465] [client 23.94.216.234:50534] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "mail.lalibanista.com"] [uri "/"] [unique_id "amuYb4JkCYmL5o6vh9KDGgAAAPg"]
[Thu Jul 30 13:31:11.132183 2026] [security2:error] [pid 890219:tid 890418] [client 78.167.1.90:55565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYb4JkCYmL5o6vh9KDHgAAAMk"]
[Thu Jul 30 13:31:11.133020 2026] [security2:error] [pid 890219:tid 890418] [client 78.167.1.90:55565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYb4JkCYmL5o6vh9KDHgAAAMk"]
[Thu Jul 30 13:31:11.997734 2026] [security2:error] [pid 890219:tid 890354] [client 20.104.18.253:32768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/011i.php"] [unique_id "amuYb4JkCYmL5o6vh9KDKwAAAIk"]
[Thu Jul 30 13:31:12.842785 2026] [core:notice] [pid 890219:tid 890359] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:12.854780 2026] [security2:error] [pid 890219:tid 890416] [client 20.104.18.253:29334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/03a005685d.php"] [unique_id "amuYcIJkCYmL5o6vh9KDSgAAAMc"]
[Thu Jul 30 13:31:13.035581 2026] [security2:error] [pid 890219:tid 890282] [remote 57.141.0.39:35200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amuYcYJkCYmL5o6vh9KDTgAA8z0"]
[Thu Jul 30 13:31:13.177663 2026] [core:notice] [pid 890219:tid 890224] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:13.644311 2026] [core:notice] [pid 890219:tid 890269] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:13.906501 2026] [security2:error] [pid 890219:tid 890455] [client 20.104.18.253:61833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/403.php"] [unique_id "amuYcYJkCYmL5o6vh9KDaQAAAO4"]
[Thu Jul 30 13:31:14.124857 2026] [security2:error] [pid 890219:tid 890290] [remote 57.141.0.11:50144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuYcoJkCYmL5o6vh9KDbQAAmkU"]
[Thu Jul 30 13:31:14.610207 2026] [security2:error] [pid 890219:tid 890372] [client 20.104.18.253:37794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/404.php"] [unique_id "amuYcoJkCYmL5o6vh9KDdgAAAJs"]
[Thu Jul 30 13:31:15.437838 2026] [security2:error] [pid 890219:tid 890438] [client 20.104.18.253:37798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/aa.php"] [unique_id "amuYc4JkCYmL5o6vh9KDjwAAAN0"]
[Thu Jul 30 13:31:15.965666 2026] [security2:error] [pid 890219:tid 890307] [remote 116.179.37.252:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flixon.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuYc4JkCYmL5o6vh9KDlgAAklY"], referer: https://flixon.net/video/dances-with-wolves-vj-mark/
[Thu Jul 30 13:31:16.600857 2026] [security2:error] [pid 890219:tid 890380] [client 20.104.18.253:34531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/aafewc0k.php"] [unique_id "amuYdIJkCYmL5o6vh9KDsQAAAKM"]
[Thu Jul 30 13:31:17.973179 2026] [security2:error] [pid 890219:tid 890365] [client 128.140.41.193:6464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuYdYJkCYmL5o6vh9KD2AAAAJQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:31:18.054968 2026] [security2:error] [pid 890219:tid 890354] [client 20.104.18.253:27847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/abcd.php"] [unique_id "amuYdoJkCYmL5o6vh9KD3AAAAIk"]
[Thu Jul 30 13:31:18.407618 2026] [core:notice] [pid 890219:tid 890357] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:18.415958 2026] [security2:error] [pid 890219:tid 890357] [client 128.140.41.193:6472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuYdoJkCYmL5o6vh9KD5gAAAIw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:31:19.038922 2026] [security2:error] [pid 890219:tid 890422] [client 128.140.41.193:6478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuYd4JkCYmL5o6vh9KD-AAAAM0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:31:19.248261 2026] [core:error] [pid 890219:tid 890445] [client 34.24.215.179:26470] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.248284 2026] [core:error] [pid 890219:tid 890445] [client 34.24.215.179:26470] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.248296 2026] [core:error] [pid 890219:tid 890376] [client 34.24.215.179:26458] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.248307 2026] [core:error] [pid 890219:tid 890376] [client 34.24.215.179:26458] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.249875 2026] [security2:error] [pid 890219:tid 890362] [client 34.24.215.179:26572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/config/database.yml"] [unique_id "amuYd4JkCYmL5o6vh9KEAQAAAJE"]
[Thu Jul 30 13:31:19.249954 2026] [security2:error] [pid 890219:tid 890362] [client 34.24.215.179:26572] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/config/database.yml"] [unique_id "amuYd4JkCYmL5o6vh9KEAQAAAJE"]
[Thu Jul 30 13:31:19.250030 2026] [security2:error] [pid 890219:tid 890467] [client 34.24.215.179:26652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/actuator/env"] [unique_id "amuYd4JkCYmL5o6vh9KEBAAAAPo"]
[Thu Jul 30 13:31:19.251037 2026] [core:error] [pid 890219:tid 890472] [client 34.24.215.179:26484] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.251054 2026] [core:error] [pid 890219:tid 890472] [client 34.24.215.179:26484] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.251356 2026] [core:error] [pid 890219:tid 890415] [client 34.24.215.179:26476] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.251377 2026] [core:error] [pid 890219:tid 890415] [client 34.24.215.179:26476] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.252027 2026] [core:error] [pid 890219:tid 890355] [client 34.24.215.179:26508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.252044 2026] [core:error] [pid 890219:tid 890355] [client 34.24.215.179:26508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.253688 2026] [core:error] [pid 890219:tid 890387] [client 34.24.215.179:26486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.253703 2026] [core:error] [pid 890219:tid 890387] [client 34.24.215.179:26486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.254244 2026] [core:error] [pid 890219:tid 890430] [client 34.24.215.179:26524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.254259 2026] [core:error] [pid 890219:tid 890430] [client 34.24.215.179:26524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.254506 2026] [core:error] [pid 890219:tid 890475] [client 34.24.215.179:26684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.254517 2026] [core:error] [pid 890219:tid 890475] [client 34.24.215.179:26684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.263350 2026] [core:error] [pid 890219:tid 890417] [client 34.24.215.179:26666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.263370 2026] [core:error] [pid 890219:tid 890417] [client 34.24.215.179:26666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.265477 2026] [core:error] [pid 890219:tid 890408] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.265500 2026] [core:error] [pid 890219:tid 890408] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.265834 2026] [core:error] [pid 890219:tid 890434] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.265845 2026] [core:error] [pid 890219:tid 890434] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.266498 2026] [core:error] [pid 890219:tid 890359] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.266515 2026] [core:error] [pid 890219:tid 890359] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.266724 2026] [security2:error] [pid 890219:tid 890463] [client 34.24.215.179:26528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.kbaagency.com"] [uri "/wp-config.php.bak"] [unique_id "amuYd4JkCYmL5o6vh9KEKQAAAPY"]
[Thu Jul 30 13:31:19.266762 2026] [core:error] [pid 890219:tid 890351] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.266782 2026] [core:error] [pid 890219:tid 890351] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.266861 2026] [core:error] [pid 890219:tid 890371] [client 34.24.215.179:26468] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.266871 2026] [core:error] [pid 890219:tid 890371] [client 34.24.215.179:26468] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.267183 2026] [core:error] [pid 890219:tid 890369] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.267201 2026] [core:error] [pid 890219:tid 890369] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.269376 2026] [core:error] [pid 890219:tid 890377] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.269398 2026] [core:error] [pid 890219:tid 890377] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.269514 2026] [core:error] [pid 890219:tid 890414] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.269524 2026] [core:error] [pid 890219:tid 890414] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.270169 2026] [core:error] [pid 890219:tid 890419] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.270185 2026] [core:error] [pid 890219:tid 890419] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.270736 2026] [core:error] [pid 890219:tid 890477] [client 34.24.215.179:26494] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.270752 2026] [core:error] [pid 890219:tid 890477] [client 34.24.215.179:26494] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.270833 2026] [core:error] [pid 890219:tid 890413] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.270846 2026] [core:error] [pid 890219:tid 890413] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.272699 2026] [core:error] [pid 890219:tid 890380] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.272713 2026] [core:error] [pid 890219:tid 890380] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.274241 2026] [core:error] [pid 890219:tid 890418] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.274257 2026] [core:error] [pid 890219:tid 890418] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.274490 2026] [core:error] [pid 890219:tid 890396] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.274506 2026] [core:error] [pid 890219:tid 890396] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.281869 2026] [core:error] [pid 890219:tid 890428] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.281884 2026] [core:error] [pid 890219:tid 890428] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.282405 2026] [core:error] [pid 890219:tid 890474] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.282418 2026] [core:error] [pid 890219:tid 890474] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.287328 2026] [core:error] [pid 890219:tid 890378] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.287342 2026] [core:error] [pid 890219:tid 890378] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.374852 2026] [security2:error] [pid 890219:tid 890458] [client 20.104.18.253:26510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/about.php"] [unique_id "amuYd4JkCYmL5o6vh9KEOQAAAPE"]
[Thu Jul 30 13:31:19.419007 2026] [core:notice] [pid 890219:tid 890379] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:19.518998 2026] [core:error] [pid 890219:tid 890381] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.519018 2026] [core:error] [pid 890219:tid 890381] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.519120 2026] [security2:error] [pid 890219:tid 890381] [client 34.24.215.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuYd4JkCYmL5o6vh9KERAAAAKQ"]
[Thu Jul 30 13:31:19.519305 2026] [core:error] [pid 890219:tid 890414] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.519630 2026] [core:error] [pid 890219:tid 890414] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.519712 2026] [security2:error] [pid 890219:tid 890410] [client 34.24.215.179:26556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/config.php"] [unique_id "amuYd4JkCYmL5o6vh9KEAgAAAME"]
[Thu Jul 30 13:31:19.520946 2026] [core:error] [pid 890219:tid 890432] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:19.520967 2026] [core:error] [pid 890219:tid 890432] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:20.119740 2026] [security2:error] [pid 890219:tid 890254] [remote 43.156.51.18:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lucky-strike-shop.com"] [uri "/product/kent-5/"] [unique_id "amuYeIJkCYmL5o6vh9KEVgAA7yE"]
[Thu Jul 30 13:31:20.119945 2026] [security2:error] [pid 890219:tid 890456] [client 43.156.51.18:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lucky-strike-shop.com"] [uri "/product/kent-5/"] [unique_id "amuYeIJkCYmL5o6vh9KEVgAA7yE"]
[Thu Jul 30 13:31:20.181243 2026] [core:notice] [pid 890219:tid 890256] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:20.277823 2026] [core:notice] [pid 890219:tid 890228] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:20.437359 2026] [core:notice] [pid 890219:tid 890230] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:20.507796 2026] [security2:error] [pid 890219:tid 890233] [remote 47.128.28.1:38128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/search/Nike/page/50/"] [unique_id "amuYeIJkCYmL5o6vh9KEYgAA2gw"]
[Thu Jul 30 13:31:20.704523 2026] [security2:error] [pid 890219:tid 890365] [client 20.104.18.253:40322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/admin.php"] [unique_id "amuYeIJkCYmL5o6vh9KEaAAAAJQ"]
[Thu Jul 30 13:31:21.522143 2026] [security2:error] [pid 890219:tid 890393] [client 185.189.112.19:39322] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuYeYJkCYmL5o6vh9KEeQAAALA"]
[Thu Jul 30 13:31:21.522238 2026] [security2:error] [pid 890219:tid 890393] [client 185.189.112.19:39322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuYeYJkCYmL5o6vh9KEeQAAALA"]
[Thu Jul 30 13:31:21.542084 2026] [security2:error] [pid 890219:tid 890380] [client 20.104.18.253:39807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/adminfuns.php"] [unique_id "amuYeYJkCYmL5o6vh9KEegAAAKM"]
[Thu Jul 30 13:31:22.279938 2026] [security2:error] [pid 890219:tid 890362] [client 20.104.18.253:40358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/albin.php"] [unique_id "amuYeoJkCYmL5o6vh9KEkgAAAJE"]
[Thu Jul 30 13:31:22.577035 2026] [security2:error] [pid 890219:tid 890465] [client 78.167.1.90:57339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYeoJkCYmL5o6vh9KEmAAAAPg"]
[Thu Jul 30 13:31:22.577524 2026] [security2:error] [pid 890219:tid 890465] [client 78.167.1.90:57339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYeoJkCYmL5o6vh9KEmAAAAPg"]
[Thu Jul 30 13:31:23.105365 2026] [security2:error] [pid 890219:tid 890447] [client 20.104.18.253:29372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/amfsqvgv.php"] [unique_id "amuYe4JkCYmL5o6vh9KEqQAAAOY"]
[Thu Jul 30 13:31:23.670551 2026] [security2:error] [pid 890219:tid 890411] [client 47.128.122.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuYe4JkCYmL5o6vh9KEtgAAAMI"]
[Thu Jul 30 13:31:24.638272 2026] [core:notice] [pid 890219:tid 890391] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:24.706176 2026] [security2:error] [pid 890219:tid 890449] [client 20.104.18.253:55619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/ant.php"] [unique_id "amuYfIJkCYmL5o6vh9KE1wAAAOg"]
[Thu Jul 30 13:31:26.173150 2026] [security2:error] [pid 890219:tid 890392] [client 119.157.140.230:49877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuYfoJkCYmL5o6vh9KE-AAAr1U"]
[Thu Jul 30 13:31:26.247369 2026] [security2:error] [pid 890219:tid 890392] [client 119.157.140.230:49877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuYfoJkCYmL5o6vh9KE9wAAr1c"]
[Thu Jul 30 13:31:26.253367 2026] [security2:error] [pid 890219:tid 890392] [client 119.157.140.230:49877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuYfoJkCYmL5o6vh9KE9gAAr00"]
[Thu Jul 30 13:31:26.384647 2026] [security2:error] [pid 890219:tid 890412] [client 20.104.18.253:36992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/appreciators.php"] [unique_id "amuYfoJkCYmL5o6vh9KFBAAAAMM"]
[Thu Jul 30 13:31:27.200066 2026] [security2:error] [pid 890219:tid 890426] [client 20.104.18.253:36998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/archive.php"] [unique_id "amuYf4JkCYmL5o6vh9KFHAAAANE"]
[Thu Jul 30 13:31:27.513879 2026] [core:notice] [pid 890219:tid 890407] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:27.908524 2026] [security2:error] [pid 890219:tid 890473] [client 20.104.18.253:34506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/as.php"] [unique_id "amuYf4JkCYmL5o6vh9KFNQAAAQA"]
[Thu Jul 30 13:31:28.780359 2026] [core:notice] [pid 890219:tid 890459] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:28.962753 2026] [security2:error] [pid 890219:tid 890431] [client 20.104.18.253:35917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/atomlib.php"] [unique_id "amuYgIJkCYmL5o6vh9KFVAAAANY"]
[Thu Jul 30 13:31:29.131999 2026] [security2:error] [pid 890219:tid 890328] [remote 57.141.0.22:31484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/591457414/feed/rss2/"] [unique_id "amuYgYJkCYmL5o6vh9KFWQAA02s"]
[Thu Jul 30 13:31:30.108400 2026] [security2:error] [pid 890219:tid 890472] [client 20.104.18.253:26505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/autoload_classmap.php"] [unique_id "amuYgoJkCYmL5o6vh9KFcQAAAP8"]
[Thu Jul 30 13:31:31.192655 2026] [security2:error] [pid 890219:tid 890416] [client 20.104.18.253:22264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/bb.php"] [unique_id "amuYg4JkCYmL5o6vh9KFjQAAAMc"]
[Thu Jul 30 13:31:32.328287 2026] [security2:error] [pid 890219:tid 890460] [client 78.167.1.90:53671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYhIJkCYmL5o6vh9KFrAAAAPM"]
[Thu Jul 30 13:31:32.328799 2026] [security2:error] [pid 890219:tid 890460] [client 78.167.1.90:53671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYhIJkCYmL5o6vh9KFrAAAAPM"]
[Thu Jul 30 13:31:32.502119 2026] [security2:error] [pid 890219:tid 890242] [remote 207.46.13.154:28176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/03/21/bijoux-en-perles-de-culture-histoire-d-or/"] [unique_id "amuYhIJkCYmL5o6vh9KFrgAA5hU"]
[Thu Jul 30 13:31:32.620789 2026] [security2:error] [pid 890219:tid 890363] [client 20.104.18.253:27843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/bnm.php"] [unique_id "amuYhIJkCYmL5o6vh9KFtQAAAJI"]
[Thu Jul 30 13:31:33.204771 2026] [security2:error] [pid 890219:tid 890373] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYhIJkCYmL5o6vh9KFtAAAAJw"]
[Thu Jul 30 13:31:33.742597 2026] [security2:error] [pid 890219:tid 890376] [client 20.104.18.253:42821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/bootstrap.php"] [unique_id "amuYhYJkCYmL5o6vh9KF0AAAAJ8"]
[Thu Jul 30 13:31:34.220275 2026] [security2:error] [pid 890219:tid 890465] [client 34.24.215.179:36272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/.env.save"] [unique_id "amuYhoJkCYmL5o6vh9KF4AAAAPg"]
[Thu Jul 30 13:31:34.222432 2026] [security2:error] [pid 890219:tid 890458] [client 34.24.215.179:36278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "amuYhoJkCYmL5o6vh9KF4QAAAPE"]
[Thu Jul 30 13:31:34.224797 2026] [security2:error] [pid 890219:tid 890392] [client 34.24.215.179:36294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "amuYhoJkCYmL5o6vh9KF5AAAAK8"]
[Thu Jul 30 13:31:34.226939 2026] [security2:error] [pid 890219:tid 890403] [client 34.24.215.179:36354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.env.php.backup"] [unique_id "amuYhoJkCYmL5o6vh9KF5gAAALo"]
[Thu Jul 30 13:31:34.227587 2026] [security2:error] [pid 890219:tid 890432] [client 34.24.215.179:36420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/.env.sample.php"] [unique_id "amuYhoJkCYmL5o6vh9KF6gAAANc"]
[Thu Jul 30 13:31:34.227662 2026] [security2:error] [pid 890219:tid 890432] [client 34.24.215.179:36420] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/.env.sample.php"] [unique_id "amuYhoJkCYmL5o6vh9KF6gAAANc"]
[Thu Jul 30 13:31:34.229758 2026] [core:error] [pid 890219:tid 890414] [client 34.24.215.179:36296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.229775 2026] [core:error] [pid 890219:tid 890414] [client 34.24.215.179:36296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.233393 2026] [core:error] [pid 890219:tid 890413] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.233408 2026] [core:error] [pid 890219:tid 890413] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.233617 2026] [core:error] [pid 890219:tid 890450] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.233628 2026] [core:error] [pid 890219:tid 890450] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.236899 2026] [core:error] [pid 890219:tid 890360] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.236915 2026] [core:error] [pid 890219:tid 890360] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.242158 2026] [core:error] [pid 890219:tid 890448] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.242173 2026] [core:error] [pid 890219:tid 890448] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.243324 2026] [core:error] [pid 890219:tid 890426] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.243339 2026] [core:error] [pid 890219:tid 890426] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.244152 2026] [core:error] [pid 890219:tid 890398] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.244170 2026] [core:error] [pid 890219:tid 890398] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.244276 2026] [security2:error] [pid 890219:tid 890398] [client 34.24.215.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuYhoJkCYmL5o6vh9KF-gAAALU"]
[Thu Jul 30 13:31:34.244535 2026] [security2:error] [pid 890219:tid 890386] [client 34.24.215.179:36358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.env.php.bak"] [unique_id "amuYhoJkCYmL5o6vh9KF_wAAAKk"]
[Thu Jul 30 13:31:34.244770 2026] [security2:error] [pid 890219:tid 890400] [client 34.24.215.179:36410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.env.production.php"] [unique_id "amuYhoJkCYmL5o6vh9KF7AAAALc"]
[Thu Jul 30 13:31:34.246423 2026] [core:error] [pid 890219:tid 890455] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.246441 2026] [core:error] [pid 890219:tid 890455] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.250016 2026] [core:error] [pid 890219:tid 890379] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.250034 2026] [core:error] [pid 890219:tid 890379] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.250132 2026] [security2:error] [pid 890219:tid 890421] [client 34.24.215.179:36282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "amuYhoJkCYmL5o6vh9KGDAAAAMw"]
[Thu Jul 30 13:31:34.250800 2026] [core:error] [pid 890219:tid 890354] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.250811 2026] [core:error] [pid 890219:tid 890354] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.251680 2026] [security2:error] [pid 890219:tid 890372] [client 34.24.215.179:36554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "amuYhoJkCYmL5o6vh9KGDgAAAJs"]
[Thu Jul 30 13:31:34.252320 2026] [security2:error] [pid 890219:tid 890361] [client 34.24.215.179:36540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "amuYhoJkCYmL5o6vh9KGEAAAAJA"]
[Thu Jul 30 13:31:34.257382 2026] [core:notice] [pid 890219:tid 890231] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:34.257499 2026] [core:error] [pid 890219:tid 890435] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.257510 2026] [core:error] [pid 890219:tid 890435] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.259350 2026] [core:error] [pid 890219:tid 890366] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.259367 2026] [core:error] [pid 890219:tid 890366] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.259426 2026] [core:error] [pid 890219:tid 890463] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.259433 2026] [core:error] [pid 890219:tid 890389] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.259436 2026] [core:error] [pid 890219:tid 890463] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.259448 2026] [core:error] [pid 890219:tid 890389] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.260318 2026] [core:error] [pid 890219:tid 890406] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.260332 2026] [core:error] [pid 890219:tid 890406] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.261297 2026] [core:error] [pid 890219:tid 890452] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.261312 2026] [core:error] [pid 890219:tid 890452] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.261514 2026] [security2:error] [pid 890219:tid 890370] [client 34.24.215.179:36486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/sendgrid.env"] [unique_id "amuYhoJkCYmL5o6vh9KGHAAAAJk"]
[Thu Jul 30 13:31:34.261863 2026] [core:error] [pid 890219:tid 890365] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.261874 2026] [core:error] [pid 890219:tid 890365] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.262714 2026] [security2:error] [pid 890219:tid 890461] [client 34.24.215.179:36526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "amuYhoJkCYmL5o6vh9KGHQAAAPQ"]
[Thu Jul 30 13:31:34.263197 2026] [security2:error] [pid 890219:tid 890350] [client 34.24.215.179:36502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/frontend/.env"] [unique_id "amuYhoJkCYmL5o6vh9KGHwAAAIU"]
[Thu Jul 30 13:31:34.263338 2026] [security2:error] [pid 890219:tid 890437] [client 34.24.215.179:36514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/API/.env"] [unique_id "amuYhoJkCYmL5o6vh9KGIAAAANw"]
[Thu Jul 30 13:31:34.266017 2026] [core:error] [pid 890219:tid 890377] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.266031 2026] [core:error] [pid 890219:tid 890377] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.271266 2026] [core:error] [pid 890219:tid 890364] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.271280 2026] [core:error] [pid 890219:tid 890364] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:34.710034 2026] [security2:error] [pid 890219:tid 890433] [client 20.104.18.253:22247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/buy.php"] [unique_id "amuYhoJkCYmL5o6vh9KGLgAAANg"]
[Thu Jul 30 13:31:34.893139 2026] [core:notice] [pid 890219:tid 890270] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:35.979170 2026] [security2:error] [pid 890219:tid 890460] [client 20.104.18.253:42869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/chosen.php"] [unique_id "amuYh4JkCYmL5o6vh9KGSwAAAPM"]
[Thu Jul 30 13:31:38.206570 2026] [security2:error] [pid 890219:tid 890400] [client 20.104.18.253:37027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/class-wp-image.php"] [unique_id "amuYioJkCYmL5o6vh9KGdwAAALc"]
[Thu Jul 30 13:31:38.792820 2026] [core:notice] [pid 890219:tid 890449] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:38.798547 2026] [security2:error] [pid 890219:tid 890449] [client 48.192.92.20:30912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/03/21/bijoux-en-perles-de-culture-histoire-d-or/"] [unique_id "amuYioJkCYmL5o6vh9KGggAAAOg"]
[Thu Jul 30 13:31:38.998367 2026] [security2:error] [pid 890219:tid 890459] [client 20.104.18.253:28345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/classsmtps.php"] [unique_id "amuYioJkCYmL5o6vh9KGiwAAAPI"]
[Thu Jul 30 13:31:40.388183 2026] [security2:error] [pid 890219:tid 890418] [client 20.104.18.253:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/classwithtostring.php"] [unique_id "amuYjIJkCYmL5o6vh9KGqgAAAMk"]
[Thu Jul 30 13:31:41.732134 2026] [security2:error] [pid 890219:tid 890477] [client 20.104.18.253:42828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/config.php"] [unique_id "amuYjYJkCYmL5o6vh9KGygAAAQQ"]
[Thu Jul 30 13:31:41.796216 2026] [security2:error] [pid 890219:tid 890351] [client 74.7.228.4:43482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.rdy.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuYjYJkCYmL5o6vh9KGywAAAIY"]
[Thu Jul 30 13:31:42.249657 2026] [security2:error] [pid 890219:tid 890425] [client 154.227.129.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/wp-login.php"] [unique_id "amuYjYJkCYmL5o6vh9KGyQAA0GQ"], referer: https://flixon.net/
[Thu Jul 30 13:31:42.527889 2026] [security2:error] [pid 890219:tid 890460] [client 20.104.18.253:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/core.php"] [unique_id "amuYjoJkCYmL5o6vh9KG3wAAAPM"]
[Thu Jul 30 13:31:42.766347 2026] [security2:error] [pid 890219:tid 890404] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYjoJkCYmL5o6vh9KG1QAAu2Y"]
[Thu Jul 30 13:31:42.919833 2026] [security2:error] [pid 890219:tid 890378] [client 78.167.1.90:53482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYjoJkCYmL5o6vh9KG6AAAAKE"]
[Thu Jul 30 13:31:42.920390 2026] [security2:error] [pid 890219:tid 890378] [client 78.167.1.90:53482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYjoJkCYmL5o6vh9KG6AAAAKE"]
[Thu Jul 30 13:31:44.381264 2026] [security2:error] [pid 890219:tid 890385] [client 20.104.18.253:28312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/css.php"] [unique_id "amuYkIJkCYmL5o6vh9KHCgAAAKg"]
[Thu Jul 30 13:31:45.206542 2026] [security2:error] [pid 890219:tid 890430] [client 20.104.18.253:27015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/database.php"] [unique_id "amuYkYJkCYmL5o6vh9KHHwAAANU"]
[Thu Jul 30 13:31:46.184497 2026] [security2:error] [pid 890219:tid 890464] [client 20.104.18.253:41882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/db.php"] [unique_id "amuYkoJkCYmL5o6vh9KHOAAAAPc"]
[Thu Jul 30 13:31:46.349848 2026] [security2:error] [pid 890219:tid 890400] [client 82.102.18.188:33574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "magicmooncorp.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuYkoJkCYmL5o6vh9KHQgAAALc"]
[Thu Jul 30 13:31:47.014195 2026] [security2:error] [pid 890219:tid 890474] [client 20.104.18.253:39130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/default.php"] [unique_id "amuYk4JkCYmL5o6vh9KHTwAAAQE"]
[Thu Jul 30 13:31:47.056758 2026] [security2:error] [pid 890219:tid 890373] [client 82.102.18.188:42970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuYk4JkCYmL5o6vh9KHUAAAAJw"]
[Thu Jul 30 13:31:47.265235 2026] [security2:error] [pid 890219:tid 890417] [client 34.24.215.179:36472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/html/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHUQAAAMg"]
[Thu Jul 30 13:31:47.266436 2026] [security2:error] [pid 890219:tid 890387] [client 34.24.215.179:36474] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHUgAAAKo"]
[Thu Jul 30 13:31:47.266582 2026] [security2:error] [pid 890219:tid 890387] [client 34.24.215.179:36474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHUgAAAKo"]
[Thu Jul 30 13:31:47.274123 2026] [security2:error] [pid 890219:tid 890254] [remote 216.73.217.142:19872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuYk4JkCYmL5o6vh9KHVQAAoCE"]
[Thu Jul 30 13:31:47.274249 2026] [security2:error] [pid 890219:tid 890463] [client 34.24.215.179:36478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHVAAAAPY"]
[Thu Jul 30 13:31:47.285280 2026] [security2:error] [pid 890219:tid 890361] [client 34.24.215.179:36482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/client/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHWAAAAJA"]
[Thu Jul 30 13:31:47.285374 2026] [security2:error] [pid 890219:tid 890361] [client 34.24.215.179:36482] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/client/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHWAAAAJA"]
[Thu Jul 30 13:31:47.287208 2026] [security2:error] [pid 890219:tid 890367] [client 34.24.215.179:36484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHWQAAAJY"]
[Thu Jul 30 13:31:47.300523 2026] [security2:error] [pid 890219:tid 890402] [client 34.24.215.179:36490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/.docker/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHWgAAALk"]
[Thu Jul 30 13:31:47.314100 2026] [security2:error] [pid 890219:tid 890435] [client 34.24.215.179:36510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHWwAAANo"]
[Thu Jul 30 13:31:47.317240 2026] [security2:error] [pid 890219:tid 890389] [client 34.24.215.179:36486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHXAAAAKw"]
[Thu Jul 30 13:31:47.318111 2026] [security2:error] [pid 890219:tid 890407] [client 34.24.215.179:36538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/production/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHXQAAAL4"]
[Thu Jul 30 13:31:47.323538 2026] [security2:error] [pid 890219:tid 890380] [client 34.24.215.179:36518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/development/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHXgAAAKM"]
[Thu Jul 30 13:31:47.324769 2026] [security2:error] [pid 890219:tid 890370] [client 34.24.215.179:36502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/conf/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHXwAAAJk"]
[Thu Jul 30 13:31:47.325630 2026] [security2:error] [pid 890219:tid 890365] [client 34.24.215.179:36554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHYAAAAJQ"]
[Thu Jul 30 13:31:47.329119 2026] [security2:error] [pid 890219:tid 890419] [client 34.24.215.179:36566] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/test/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHYQAAAMo"]
[Thu Jul 30 13:31:47.332950 2026] [security2:error] [pid 890219:tid 890356] [client 34.24.215.179:36584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/backup/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHYgAAAIs"]
[Thu Jul 30 13:31:47.336399 2026] [security2:error] [pid 890219:tid 890428] [client 34.24.215.179:36526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHYwAAANM"]
[Thu Jul 30 13:31:47.339428 2026] [security2:error] [pid 890219:tid 890462] [client 34.24.215.179:36596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHZAAAAPU"]
[Thu Jul 30 13:31:47.351429 2026] [security2:error] [pid 890219:tid 890415] [client 34.24.215.179:36578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHZQAAAMY"]
[Thu Jul 30 13:31:47.363169 2026] [security2:error] [pid 890219:tid 890459] [client 34.24.215.179:36624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/site/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHZgAAAPI"]
[Thu Jul 30 13:31:47.365368 2026] [security2:error] [pid 890219:tid 890350] [client 34.24.215.179:36640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHZwAAAIU"]
[Thu Jul 30 13:31:47.367989 2026] [security2:error] [pid 890219:tid 890477] [client 34.24.215.179:36644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/application/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHaAAAAQQ"]
[Thu Jul 30 13:31:47.368841 2026] [security2:error] [pid 890219:tid 890362] [client 34.24.215.179:36662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/v1/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHaQAAAJE"]
[Thu Jul 30 13:31:47.371901 2026] [security2:error] [pid 890219:tid 890408] [client 34.24.215.179:36606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHagAAAL8"]
[Thu Jul 30 13:31:47.372147 2026] [security2:error] [pid 890219:tid 890382] [client 34.24.215.179:36678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/v2/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHawAAAKU"]
[Thu Jul 30 13:31:47.376228 2026] [security2:error] [pid 890219:tid 890409] [client 34.24.215.179:36706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/twilio/.env.php"] [unique_id "amuYk4JkCYmL5o6vh9KHbwAAAMA"]
[Thu Jul 30 13:31:47.376304 2026] [security2:error] [pid 890219:tid 890409] [client 34.24.215.179:36706] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/twilio/.env.php"] [unique_id "amuYk4JkCYmL5o6vh9KHbwAAAMA"]
[Thu Jul 30 13:31:47.379676 2026] [security2:error] [pid 890219:tid 890412] [client 34.24.215.179:36614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/portal/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHcgAAAMM"]
[Thu Jul 30 13:31:47.385355 2026] [security2:error] [pid 890219:tid 890424] [client 34.24.215.179:36656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/project/.env"] [unique_id "amuYk4JkCYmL5o6vh9KHdgAAAM8"]
[Thu Jul 30 13:31:47.385867 2026] [core:error] [pid 890219:tid 890403] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.385878 2026] [core:error] [pid 890219:tid 890403] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.385992 2026] [security2:error] [pid 890219:tid 890403] [client 34.24.215.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuYk4JkCYmL5o6vh9KHdQAAALo"]
[Thu Jul 30 13:31:47.386559 2026] [security2:error] [pid 890219:tid 890406] [client 34.24.215.179:36684] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/config/.env.php"] [unique_id "amuYk4JkCYmL5o6vh9KHbAAAAL0"]
[Thu Jul 30 13:31:47.389266 2026] [core:error] [pid 890219:tid 890424] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.389281 2026] [core:error] [pid 890219:tid 890424] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.389360 2026] [core:error] [pid 890219:tid 890388] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.389371 2026] [core:error] [pid 890219:tid 890388] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.408695 2026] [core:error] [pid 890219:tid 890431] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.408713 2026] [core:error] [pid 890219:tid 890431] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.411504 2026] [core:error] [pid 890219:tid 890405] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.411521 2026] [core:error] [pid 890219:tid 890405] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.413293 2026] [core:error] [pid 890219:tid 890467] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:47.413309 2026] [core:error] [pid 890219:tid 890467] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:48.292850 2026] [security2:error] [pid 890219:tid 890372] [client 20.104.18.253:37022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/dropdown.php"] [unique_id "amuYlIJkCYmL5o6vh9KHlQAAAJs"]
[Thu Jul 30 13:31:48.508599 2026] [core:notice] [pid 890219:tid 890352] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:48.892118 2026] [core:notice] [pid 890219:tid 890427] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:49.041009 2026] [security2:error] [pid 890219:tid 890465] [client 82.102.18.188:60204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuYlYJkCYmL5o6vh9KHrwAAAPg"]
[Thu Jul 30 13:31:49.239375 2026] [security2:error] [pid 890219:tid 890467] [client 20.104.18.253:28306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/edit.php"] [unique_id "amuYlYJkCYmL5o6vh9KHugAAAPo"]
[Thu Jul 30 13:31:49.307571 2026] [security2:error] [pid 890219:tid 890396] [client 82.102.18.188:60218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ejournalugj.com"] [uri "/xmlrpc.php"] [unique_id "amuYlYJkCYmL5o6vh9KHuwAAALM"]
[Thu Jul 30 13:31:49.584927 2026] [core:notice] [pid 890219:tid 890438] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:49.969401 2026] [security2:error] [pid 890219:tid 890434] [client 82.102.18.188:60220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuYlYJkCYmL5o6vh9KH0QAAANk"]
[Thu Jul 30 13:31:49.982084 2026] [security2:error] [pid 890219:tid 890400] [client 20.104.18.253:40503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/f35.php"] [unique_id "amuYlYJkCYmL5o6vh9KH0wAAALc"]
[Thu Jul 30 13:31:50.244013 2026] [security2:error] [pid 890219:tid 890465] [client 82.102.18.188:60234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuYloJkCYmL5o6vh9KH2wAAAPg"]
[Thu Jul 30 13:31:50.518393 2026] [security2:error] [pid 890219:tid 890376] [client 82.102.18.188:60236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuYloJkCYmL5o6vh9KH5QAAAJ8"]
[Thu Jul 30 13:31:50.576968 2026] [security2:error] [pid 890219:tid 890358] [client 172.237.109.114:26735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuYlYJkCYmL5o6vh9KH0gAAAI0"]
[Thu Jul 30 13:31:50.664416 2026] [security2:error] [pid 890219:tid 890366] [client 20.104.18.253:40502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/f7.php"] [unique_id "amuYloJkCYmL5o6vh9KH6gAAAJU"]
[Thu Jul 30 13:31:50.804377 2026] [security2:error] [pid 890219:tid 890407] [client 82.102.18.188:60250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuYloJkCYmL5o6vh9KH6wAAAL4"]
[Thu Jul 30 13:31:51.175196 2026] [security2:error] [pid 890219:tid 890442] [client 51.68.236.94:17287] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amuYl4JkCYmL5o6vh9KH-AAAAOE"]
[Thu Jul 30 13:31:51.175308 2026] [security2:error] [pid 890219:tid 890442] [client 51.68.236.94:17287] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amuYl4JkCYmL5o6vh9KH-AAAAOE"]
[Thu Jul 30 13:31:51.575335 2026] [security2:error] [pid 890219:tid 890448] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuYl4JkCYmL5o6vh9KH_wAAAOc"]
[Thu Jul 30 13:31:51.575449 2026] [security2:error] [pid 890219:tid 890448] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuYl4JkCYmL5o6vh9KH_wAAAOc"]
[Thu Jul 30 13:31:51.590201 2026] [security2:error] [pid 890219:tid 890427] [client 82.102.18.188:42984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuYl4JkCYmL5o6vh9KIAAAAANI"]
[Thu Jul 30 13:31:51.590326 2026] [security2:error] [pid 890219:tid 890427] [client 82.102.18.188:42984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuYl4JkCYmL5o6vh9KIAAAAANI"]
[Thu Jul 30 13:31:51.823402 2026] [security2:error] [pid 890219:tid 890379] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuYl4JkCYmL5o6vh9KIBAAAAKI"]
[Thu Jul 30 13:31:51.823528 2026] [security2:error] [pid 890219:tid 890379] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuYl4JkCYmL5o6vh9KIBAAAAKI"]
[Thu Jul 30 13:31:52.069163 2026] [security2:error] [pid 890219:tid 890289] [remote 198.38.94.87:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amuYmIJkCYmL5o6vh9KIDgAA3kQ"]
[Thu Jul 30 13:31:52.082860 2026] [security2:error] [pid 890219:tid 890469] [client 82.102.18.188:60258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuYmIJkCYmL5o6vh9KIDwAAAPw"]
[Thu Jul 30 13:31:52.093301 2026] [security2:error] [pid 890219:tid 890471] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuYmIJkCYmL5o6vh9KIEAAAAP4"]
[Thu Jul 30 13:31:52.093384 2026] [security2:error] [pid 890219:tid 890471] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuYmIJkCYmL5o6vh9KIEAAAAP4"]
[Thu Jul 30 13:31:52.330415 2026] [security2:error] [pid 890219:tid 890367] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/media.php"] [unique_id "amuYmIJkCYmL5o6vh9KIGAAAAJY"]
[Thu Jul 30 13:31:52.330515 2026] [security2:error] [pid 890219:tid 890367] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/media.php"] [unique_id "amuYmIJkCYmL5o6vh9KIGAAAAJY"]
[Thu Jul 30 13:31:52.356902 2026] [security2:error] [pid 890219:tid 890411] [client 82.102.18.188:60260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuYmIJkCYmL5o6vh9KIGQAAAMI"]
[Thu Jul 30 13:31:52.597950 2026] [security2:error] [pid 890219:tid 890415] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/images.php"] [unique_id "amuYmIJkCYmL5o6vh9KIJAAAAMY"]
[Thu Jul 30 13:31:52.598109 2026] [security2:error] [pid 890219:tid 890415] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/images.php"] [unique_id "amuYmIJkCYmL5o6vh9KIJAAAAMY"]
[Thu Jul 30 13:31:52.626201 2026] [security2:error] [pid 890219:tid 890371] [client 68.221.186.136:2671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/geju.php"] [unique_id "amuYmIJkCYmL5o6vh9KIJwAAAJo"]
[Thu Jul 30 13:31:52.626443 2026] [security2:error] [pid 890219:tid 890477] [client 82.102.18.188:60264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuYmIJkCYmL5o6vh9KIKAAAAQQ"]
[Thu Jul 30 13:31:52.845552 2026] [security2:error] [pid 890219:tid 890362] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/adminner.php"] [unique_id "amuYmIJkCYmL5o6vh9KILQAAAJE"]
[Thu Jul 30 13:31:52.845662 2026] [security2:error] [pid 890219:tid 890362] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/adminner.php"] [unique_id "amuYmIJkCYmL5o6vh9KILQAAAJE"]
[Thu Jul 30 13:31:52.908169 2026] [security2:error] [pid 890219:tid 890436] [client 82.102.18.188:1167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuYmIJkCYmL5o6vh9KIMQAAANs"]
[Thu Jul 30 13:31:53.132323 2026] [security2:error] [pid 890219:tid 890444] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/admin.php"] [unique_id "amuYmYJkCYmL5o6vh9KIOgAAAOM"]
[Thu Jul 30 13:31:53.132436 2026] [security2:error] [pid 890219:tid 890444] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/admin.php"] [unique_id "amuYmYJkCYmL5o6vh9KIOgAAAOM"]
[Thu Jul 30 13:31:53.177520 2026] [security2:error] [pid 890219:tid 890353] [client 82.102.18.188:60274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuYmYJkCYmL5o6vh9KIPgAAAIg"]
[Thu Jul 30 13:31:53.392801 2026] [security2:error] [pid 890219:tid 890474] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/ops.php"] [unique_id "amuYmYJkCYmL5o6vh9KIQgAAAQE"]
[Thu Jul 30 13:31:53.392909 2026] [security2:error] [pid 890219:tid 890474] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/ops.php"] [unique_id "amuYmYJkCYmL5o6vh9KIQgAAAQE"]
[Thu Jul 30 13:31:53.448758 2026] [security2:error] [pid 890219:tid 890355] [client 82.102.18.188:60282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuYmYJkCYmL5o6vh9KIRQAAAIo"]
[Thu Jul 30 13:31:53.537845 2026] [security2:error] [pid 890219:tid 890454] [client 78.167.1.90:54785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYmYJkCYmL5o6vh9KISAAAAO0"]
[Thu Jul 30 13:31:53.538302 2026] [security2:error] [pid 890219:tid 890454] [client 78.167.1.90:54785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYmYJkCYmL5o6vh9KISAAAAO0"]
[Thu Jul 30 13:31:53.633338 2026] [security2:error] [pid 890219:tid 890414] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/mac.php"] [unique_id "amuYmYJkCYmL5o6vh9KITwAAAMU"]
[Thu Jul 30 13:31:53.633447 2026] [security2:error] [pid 890219:tid 890414] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/mac.php"] [unique_id "amuYmYJkCYmL5o6vh9KITwAAAMU"]
[Thu Jul 30 13:31:53.770871 2026] [security2:error] [pid 890219:tid 890453] [client 82.102.18.188:60294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuYmYJkCYmL5o6vh9KIVAAAAOw"]
[Thu Jul 30 13:31:53.877713 2026] [security2:error] [pid 890219:tid 890352] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "n1rmalabet88.com"] [uri "/cgi-sys/404.html"] [unique_id "amuYmYJkCYmL5o6vh9KIWAAAAIc"]
[Thu Jul 30 13:31:53.994702 2026] [security2:error] [pid 890219:tid 890393] [client 68.221.186.136:13363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuYmYJkCYmL5o6vh9KIWQAAALA"]
[Thu Jul 30 13:31:54.040268 2026] [security2:error] [pid 890219:tid 890356] [client 82.102.18.188:36956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuYmoJkCYmL5o6vh9KIXQAAAIs"]
[Thu Jul 30 13:31:54.242885 2026] [security2:error] [pid 890219:tid 890317] [remote 74.7.243.224:59630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/appel-doffres/uploads/partners/img/uploads/content/js/css/img/uploads/content/js/partners/js/login.php"] [unique_id "amuYmoJkCYmL5o6vh9KIYgAA82A"], referer: https://aded-rdc.org/appel-doffres/uploads/partners/img/uploads/content/js/css/img/uploads/content/js/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 13:31:54.269668 2026] [security2:error] [pid 890219:tid 890307] [remote 57.141.0.43:24148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuYmoJkCYmL5o6vh9KIWgAAk1Y"]
[Thu Jul 30 13:31:54.296714 2026] [security2:error] [pid 890219:tid 890401] [client 82.102.18.188:36968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuYmoJkCYmL5o6vh9KIZgAAALg"]
[Thu Jul 30 13:31:54.574630 2026] [security2:error] [pid 890219:tid 890431] [client 82.102.18.188:36976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuYmoJkCYmL5o6vh9KIagAAANY"]
[Thu Jul 30 13:31:54.710129 2026] [security2:error] [pid 890219:tid 890404] [client 68.221.186.136:9588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp.php"] [unique_id "amuYmoJkCYmL5o6vh9KIdAAAALs"]
[Thu Jul 30 13:31:54.844123 2026] [security2:error] [pid 890219:tid 890468] [client 82.102.18.188:36978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuYmoJkCYmL5o6vh9KIegAAAPs"]
[Thu Jul 30 13:31:54.925205 2026] [security2:error] [pid 890219:tid 890425] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/pucci.php"] [unique_id "amuYmoJkCYmL5o6vh9KIewAAANA"]
[Thu Jul 30 13:31:54.925323 2026] [security2:error] [pid 890219:tid 890425] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/pucci.php"] [unique_id "amuYmoJkCYmL5o6vh9KIewAAANA"]
[Thu Jul 30 13:31:55.069846 2026] [security2:error] [pid 890219:tid 890384] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuYm4JkCYmL5o6vh9KIfgAAAKc"]
[Thu Jul 30 13:31:55.070018 2026] [security2:error] [pid 890219:tid 890384] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuYm4JkCYmL5o6vh9KIfgAAAKc"]
[Thu Jul 30 13:31:55.079764 2026] [core:notice] [pid 890219:tid 890244] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:55.125474 2026] [security2:error] [pid 890219:tid 890461] [client 82.102.18.188:36994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ejournalugj.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuYm4JkCYmL5o6vh9KIgwAAAPQ"]
[Thu Jul 30 13:31:55.187855 2026] [security2:error] [pid 890219:tid 890466] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYmoJkCYmL5o6vh9KIbgAAAPk"]
[Thu Jul 30 13:31:55.307086 2026] [security2:error] [pid 890219:tid 890428] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/8.php"] [unique_id "amuYm4JkCYmL5o6vh9KIiwAAANM"]
[Thu Jul 30 13:31:55.307182 2026] [security2:error] [pid 890219:tid 890428] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/8.php"] [unique_id "amuYm4JkCYmL5o6vh9KIiwAAANM"]
[Thu Jul 30 13:31:55.324589 2026] [security2:error] [pid 890219:tid 890388] [client 185.156.175.51:33276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuYm4JkCYmL5o6vh9KIjgAAAKs"]
[Thu Jul 30 13:31:55.324692 2026] [security2:error] [pid 890219:tid 890388] [client 185.156.175.51:33276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuYm4JkCYmL5o6vh9KIjgAAAKs"]
[Thu Jul 30 13:31:55.561576 2026] [security2:error] [pid 890219:tid 890458] [client 158.158.32.229:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "n1rmalabet88.com"] [uri "/1.php"] [unique_id "amuYm4JkCYmL5o6vh9KIkAAAAPE"]
[Thu Jul 30 13:31:55.561683 2026] [security2:error] [pid 890219:tid 890458] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/1.php"] [unique_id "amuYm4JkCYmL5o6vh9KIkAAAAPE"]
[Thu Jul 30 13:31:55.561784 2026] [security2:error] [pid 890219:tid 890458] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/1.php"] [unique_id "amuYm4JkCYmL5o6vh9KIkAAAAPE"]
[Thu Jul 30 13:31:55.798636 2026] [security2:error] [pid 890219:tid 890394] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp-content/admin.php"] [unique_id "amuYm4JkCYmL5o6vh9KImgAAALE"]
[Thu Jul 30 13:31:55.798743 2026] [security2:error] [pid 890219:tid 890394] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/wp-content/admin.php"] [unique_id "amuYm4JkCYmL5o6vh9KImgAAALE"]
[Thu Jul 30 13:31:55.813879 2026] [core:notice] [pid 890219:tid 890339] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:55.948936 2026] [security2:error] [pid 890219:tid 890370] [client 68.221.186.136:2735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/aaa.php"] [unique_id "amuYm4JkCYmL5o6vh9KIngAAAJk"]
[Thu Jul 30 13:31:56.064428 2026] [security2:error] [pid 890219:tid 890476] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuYnIJkCYmL5o6vh9KInwAAAQM"]
[Thu Jul 30 13:31:56.064587 2026] [security2:error] [pid 890219:tid 890476] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuYnIJkCYmL5o6vh9KInwAAAQM"]
[Thu Jul 30 13:31:56.120859 2026] [core:notice] [pid 890219:tid 890366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:31:56.305693 2026] [security2:error] [pid 890219:tid 890416] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/222.php"] [unique_id "amuYnIJkCYmL5o6vh9KIpgAAAMc"]
[Thu Jul 30 13:31:56.305794 2026] [security2:error] [pid 890219:tid 890416] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/222.php"] [unique_id "amuYnIJkCYmL5o6vh9KIpgAAAMc"]
[Thu Jul 30 13:31:56.543361 2026] [security2:error] [pid 890219:tid 890455] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/cgi-bin/index.php"] [unique_id "amuYnIJkCYmL5o6vh9KIqwAAAO4"]
[Thu Jul 30 13:31:56.543438 2026] [security2:error] [pid 890219:tid 890455] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/cgi-bin/index.php"] [unique_id "amuYnIJkCYmL5o6vh9KIqwAAAO4"]
[Thu Jul 30 13:31:56.894134 2026] [core:error] [pid 890219:tid 890384] [client 46.202.59.121:36961] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:56.894164 2026] [core:error] [pid 890219:tid 890384] [client 46.202.59.121:36961] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:56.951535 2026] [core:error] [pid 890219:tid 890380] [client 216.173.76.135:58879] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:56.951555 2026] [core:error] [pid 890219:tid 890380] [client 216.173.76.135:58879] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:31:59.009090 2026] [security2:error] [pid 890219:tid 890408] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "n1rmalabet88.com"] [uri "/cgi-sys/404.html"] [unique_id "amuYn4JkCYmL5o6vh9KI3wAAAL8"]
[Thu Jul 30 13:31:59.203173 2026] [security2:error] [pid 890219:tid 890429] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "n1rmalabet88.com"] [uri "/cgi-sys/404.html"] [unique_id "amuYn4JkCYmL5o6vh9KI4wAAANQ"]
[Thu Jul 30 13:31:59.368020 2026] [security2:error] [pid 890219:tid 890434] [client 68.235.48.108:57416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuYn4JkCYmL5o6vh9KI6AAAANk"]
[Thu Jul 30 13:31:59.368142 2026] [security2:error] [pid 890219:tid 890434] [client 68.235.48.108:57416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuYn4JkCYmL5o6vh9KI6AAAANk"]
[Thu Jul 30 13:31:59.378795 2026] [security2:error] [pid 890219:tid 890458] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "n1rmalabet88.com"] [uri "/cgi-sys/404.html"] [unique_id "amuYn4JkCYmL5o6vh9KI6QAAAPE"]
[Thu Jul 30 13:31:59.529306 2026] [security2:error] [pid 890219:tid 890401] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/raw.php"] [unique_id "amuYn4JkCYmL5o6vh9KI8AAAALg"]
[Thu Jul 30 13:31:59.529477 2026] [security2:error] [pid 890219:tid 890401] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/raw.php"] [unique_id "amuYn4JkCYmL5o6vh9KI8AAAALg"]
[Thu Jul 30 13:31:59.636990 2026] [security2:error] [pid 890219:tid 890438] [client 68.221.186.136:8763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/hoot.php"] [unique_id "amuYn4JkCYmL5o6vh9KI9AAAAN0"]
[Thu Jul 30 13:31:59.864228 2026] [security2:error] [pid 890219:tid 890464] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "n1rmalabet88.com"] [uri "/cgi-sys/404.html"] [unique_id "amuYn4JkCYmL5o6vh9KI-AAAAPc"]
[Thu Jul 30 13:32:00.010357 2026] [security2:error] [pid 890219:tid 890376] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/simple.php"] [unique_id "amuYoIJkCYmL5o6vh9KI-QAAAJ8"]
[Thu Jul 30 13:32:00.010506 2026] [security2:error] [pid 890219:tid 890376] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/simple.php"] [unique_id "amuYoIJkCYmL5o6vh9KI-QAAAJ8"]
[Thu Jul 30 13:32:00.248114 2026] [security2:error] [pid 890219:tid 890463] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/xxx.php"] [unique_id "amuYoIJkCYmL5o6vh9KJAwAAAPY"]
[Thu Jul 30 13:32:00.248227 2026] [security2:error] [pid 890219:tid 890463] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/xxx.php"] [unique_id "amuYoIJkCYmL5o6vh9KJAwAAAPY"]
[Thu Jul 30 13:32:00.429400 2026] [core:error] [pid 890219:tid 890392] [client 34.24.215.179:21384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.429423 2026] [core:error] [pid 890219:tid 890392] [client 34.24.215.179:21384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.438793 2026] [security2:error] [pid 890219:tid 890427] [client 34.24.215.179:21352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/.travis.yml"] [unique_id "amuYoIJkCYmL5o6vh9KJDwAAANI"]
[Thu Jul 30 13:32:00.439543 2026] [core:error] [pid 890219:tid 890459] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.439572 2026] [core:error] [pid 890219:tid 890459] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.440028 2026] [core:error] [pid 890219:tid 890352] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.440048 2026] [core:error] [pid 890219:tid 890352] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.440992 2026] [core:error] [pid 890219:tid 890407] [client 34.24.215.179:21466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.441008 2026] [core:error] [pid 890219:tid 890407] [client 34.24.215.179:21466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.442329 2026] [core:error] [pid 890219:tid 890474] [client 34.24.215.179:21482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.442344 2026] [core:error] [pid 890219:tid 890474] [client 34.24.215.179:21482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.445659 2026] [security2:error] [pid 890219:tid 890373] [client 34.24.215.179:21524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/appsettings.json"] [unique_id "amuYoIJkCYmL5o6vh9KJHAAAAJw"]
[Thu Jul 30 13:32:00.445765 2026] [security2:error] [pid 890219:tid 890373] [client 34.24.215.179:21524] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/appsettings.json"] [unique_id "amuYoIJkCYmL5o6vh9KJHAAAAJw"]
[Thu Jul 30 13:32:00.445822 2026] [core:error] [pid 890219:tid 890350] [client 34.24.215.179:21518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.445833 2026] [core:error] [pid 890219:tid 890350] [client 34.24.215.179:21518] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.446571 2026] [core:error] [pid 890219:tid 890386] [client 34.24.215.179:21502] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.446587 2026] [core:error] [pid 890219:tid 890386] [client 34.24.215.179:21502] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.446728 2026] [security2:error] [pid 890219:tid 890386] [client 34.24.215.179:21502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuYoIJkCYmL5o6vh9KJFgAAAKk"]
[Thu Jul 30 13:32:00.447168 2026] [core:error] [pid 890219:tid 890415] [client 34.24.215.179:21560] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.447182 2026] [core:error] [pid 890219:tid 890415] [client 34.24.215.179:21560] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.447520 2026] [core:error] [pid 890219:tid 890354] [client 34.24.215.179:21532] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.447535 2026] [core:error] [pid 890219:tid 890354] [client 34.24.215.179:21532] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.447994 2026] [core:error] [pid 890219:tid 890466] [client 34.24.215.179:21572] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.448011 2026] [core:error] [pid 890219:tid 890466] [client 34.24.215.179:21572] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.449450 2026] [security2:error] [pid 890219:tid 890408] [client 68.221.186.136:8748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/about.php"] [unique_id "amuYoIJkCYmL5o6vh9KJIQAAAL8"]
[Thu Jul 30 13:32:00.449944 2026] [core:error] [pid 890219:tid 890367] [client 34.24.215.179:21392] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.449958 2026] [core:error] [pid 890219:tid 890367] [client 34.24.215.179:21392] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.450777 2026] [core:error] [pid 890219:tid 890406] [client 34.24.215.179:21584] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.450794 2026] [core:error] [pid 890219:tid 890406] [client 34.24.215.179:21584] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.450987 2026] [core:error] [pid 890219:tid 890461] [client 34.24.215.179:21406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.451003 2026] [core:error] [pid 890219:tid 890461] [client 34.24.215.179:21406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.452300 2026] [security2:error] [pid 890219:tid 890371] [client 34.24.215.179:21586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/client_secret.json"] [unique_id "amuYoIJkCYmL5o6vh9KJKQAAAJo"]
[Thu Jul 30 13:32:00.453077 2026] [core:error] [pid 890219:tid 890417] [client 34.24.215.179:21604] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.453094 2026] [core:error] [pid 890219:tid 890417] [client 34.24.215.179:21604] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.453207 2026] [core:error] [pid 890219:tid 890387] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.453220 2026] [core:error] [pid 890219:tid 890387] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.453225 2026] [core:error] [pid 890219:tid 890434] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.453241 2026] [core:error] [pid 890219:tid 890434] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.453634 2026] [core:error] [pid 890219:tid 890466] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.453650 2026] [core:error] [pid 890219:tid 890466] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.454144 2026] [core:error] [pid 890219:tid 890364] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.454160 2026] [core:error] [pid 890219:tid 890364] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.454793 2026] [core:error] [pid 890219:tid 890473] [client 34.24.215.179:21432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.454804 2026] [core:error] [pid 890219:tid 890473] [client 34.24.215.179:21432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.455951 2026] [core:error] [pid 890219:tid 890360] [client 34.24.215.179:21662] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.455967 2026] [core:error] [pid 890219:tid 890360] [client 34.24.215.179:21662] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.458140 2026] [core:error] [pid 890219:tid 890363] [client 34.24.215.179:21620] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.458157 2026] [core:error] [pid 890219:tid 890363] [client 34.24.215.179:21620] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.460612 2026] [core:error] [pid 890219:tid 890409] [client 34.24.215.179:21496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.460636 2026] [core:error] [pid 890219:tid 890409] [client 34.24.215.179:21496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.460692 2026] [core:error] [pid 890219:tid 890477] [client 34.24.215.179:21646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.460703 2026] [core:error] [pid 890219:tid 890477] [client 34.24.215.179:21646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.465695 2026] [core:error] [pid 890219:tid 890400] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.465714 2026] [core:error] [pid 890219:tid 890400] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.465970 2026] [core:error] [pid 890219:tid 890465] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.466003 2026] [core:error] [pid 890219:tid 890465] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.466536 2026] [core:error] [pid 890219:tid 890424] [client 34.24.215.179:21544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.466547 2026] [core:error] [pid 890219:tid 890424] [client 34.24.215.179:21544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.471137 2026] [core:error] [pid 890219:tid 890403] [client 34.24.215.179:21594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.471154 2026] [core:error] [pid 890219:tid 890403] [client 34.24.215.179:21594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.473677 2026] [core:error] [pid 890219:tid 890369] [client 34.24.215.179:21636] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.473690 2026] [core:error] [pid 890219:tid 890369] [client 34.24.215.179:21636] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.478416 2026] [core:error] [pid 890219:tid 890380] [client 34.24.215.179:21624] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.478449 2026] [core:error] [pid 890219:tid 890380] [client 34.24.215.179:21624] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:00.487076 2026] [security2:error] [pid 890219:tid 890375] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/file.php"] [unique_id "amuYoIJkCYmL5o6vh9KJNgAAAJ4"]
[Thu Jul 30 13:32:00.487164 2026] [security2:error] [pid 890219:tid 890375] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/file.php"] [unique_id "amuYoIJkCYmL5o6vh9KJNgAAAJ4"]
[Thu Jul 30 13:32:00.774073 2026] [security2:error] [pid 890219:tid 890387] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp-load.php"] [unique_id "amuYoIJkCYmL5o6vh9KJQQAAAKo"]
[Thu Jul 30 13:32:00.774172 2026] [security2:error] [pid 890219:tid 890387] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/wp-load.php"] [unique_id "amuYoIJkCYmL5o6vh9KJQQAAAKo"]
[Thu Jul 30 13:32:01.029835 2026] [security2:error] [pid 890219:tid 890440] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "n1rmalabet88.com"] [uri "/cgi-sys/404.html"] [unique_id "amuYoYJkCYmL5o6vh9KJQwAAAN8"]
[Thu Jul 30 13:32:01.055638 2026] [security2:error] [pid 890219:tid 890390] [client 74.7.175.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-a3b4bcfc.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuYn4JkCYmL5o6vh9KI5wAAAK0"]
[Thu Jul 30 13:32:01.056381 2026] [security2:error] [pid 890219:tid 890362] [client 74.7.175.148:49316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-a3b4bcfc.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuYn4JkCYmL5o6vh9KI5QAAkQs"]
[Thu Jul 30 13:32:01.168900 2026] [security2:error] [pid 890219:tid 890441] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "n1rmalabet88.com"] [uri "/cgi-sys/404.html"] [unique_id "amuYoYJkCYmL5o6vh9KJRwAAAOA"]
[Thu Jul 30 13:32:01.314321 2026] [security2:error] [pid 890219:tid 890382] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuYoYJkCYmL5o6vh9KJTwAAAKU"]
[Thu Jul 30 13:32:01.314919 2026] [security2:error] [pid 890219:tid 890382] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "amuYoYJkCYmL5o6vh9KJTwAAAKU"]
[Thu Jul 30 13:32:02.371664 2026] [security2:error] [pid 890219:tid 890350] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/a.php"] [unique_id "amuYooJkCYmL5o6vh9KJZgAAAIU"]
[Thu Jul 30 13:32:02.371762 2026] [security2:error] [pid 890219:tid 890350] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/a.php"] [unique_id "amuYooJkCYmL5o6vh9KJZgAAAIU"]
[Thu Jul 30 13:32:02.522030 2026] [security2:error] [pid 890219:tid 890427] [client 34.147.16.58:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.chicago-mfg.com"] [uri "/"] [unique_id "amuYooJkCYmL5o6vh9KJZwAAANI"]
[Thu Jul 30 13:32:02.522132 2026] [security2:error] [pid 890219:tid 890427] [client 34.147.16.58:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.chicago-mfg.com"] [uri "/"] [unique_id "amuYooJkCYmL5o6vh9KJZwAAANI"]
[Thu Jul 30 13:32:02.662197 2026] [security2:error] [pid 890219:tid 890460] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuYooJkCYmL5o6vh9KJaAAAAPM"]
[Thu Jul 30 13:32:02.662305 2026] [security2:error] [pid 890219:tid 890460] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuYooJkCYmL5o6vh9KJaAAAAPM"]
[Thu Jul 30 13:32:02.901217 2026] [security2:error] [pid 890219:tid 890390] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/aa.php"] [unique_id "amuYooJkCYmL5o6vh9KJcgAAAK0"]
[Thu Jul 30 13:32:02.901329 2026] [security2:error] [pid 890219:tid 890390] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/aa.php"] [unique_id "amuYooJkCYmL5o6vh9KJcgAAAK0"]
[Thu Jul 30 13:32:03.152523 2026] [security2:error] [pid 890219:tid 890441] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/177.php"] [unique_id "amuYo4JkCYmL5o6vh9KJcwAAAOA"]
[Thu Jul 30 13:32:03.152653 2026] [security2:error] [pid 890219:tid 890441] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/177.php"] [unique_id "amuYo4JkCYmL5o6vh9KJcwAAAOA"]
[Thu Jul 30 13:32:03.390198 2026] [security2:error] [pid 890219:tid 890398] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/coffexium.php"] [unique_id "amuYo4JkCYmL5o6vh9KJfQAAALU"]
[Thu Jul 30 13:32:03.390322 2026] [security2:error] [pid 890219:tid 890398] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/coffexium.php"] [unique_id "amuYo4JkCYmL5o6vh9KJfQAAALU"]
[Thu Jul 30 13:32:03.637076 2026] [security2:error] [pid 890219:tid 890369] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/fffm.php"] [unique_id "amuYo4JkCYmL5o6vh9KJfgAAAJg"]
[Thu Jul 30 13:32:03.637188 2026] [security2:error] [pid 890219:tid 890369] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/fffm.php"] [unique_id "amuYo4JkCYmL5o6vh9KJfgAAAJg"]
[Thu Jul 30 13:32:03.875325 2026] [security2:error] [pid 890219:tid 890467] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/82.php"] [unique_id "amuYo4JkCYmL5o6vh9KJiAAAAPo"]
[Thu Jul 30 13:32:03.875430 2026] [security2:error] [pid 890219:tid 890467] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/82.php"] [unique_id "amuYo4JkCYmL5o6vh9KJiAAAAPo"]
[Thu Jul 30 13:32:04.160158 2026] [security2:error] [pid 890219:tid 890449] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/config.json.php"] [unique_id "amuYpIJkCYmL5o6vh9KJjwAAAOg"]
[Thu Jul 30 13:32:04.160281 2026] [security2:error] [pid 890219:tid 890449] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/config.json.php"] [unique_id "amuYpIJkCYmL5o6vh9KJjwAAAOg"]
[Thu Jul 30 13:32:04.399354 2026] [security2:error] [pid 890219:tid 890413] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/fpwch.php"] [unique_id "amuYpIJkCYmL5o6vh9KJmQAAAMQ"]
[Thu Jul 30 13:32:04.399505 2026] [security2:error] [pid 890219:tid 890413] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/fpwch.php"] [unique_id "amuYpIJkCYmL5o6vh9KJmQAAAMQ"]
[Thu Jul 30 13:32:04.664738 2026] [security2:error] [pid 890219:tid 890373] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/xp.php"] [unique_id "amuYpIJkCYmL5o6vh9KJmgAAAJw"]
[Thu Jul 30 13:32:04.664865 2026] [security2:error] [pid 890219:tid 890373] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/xp.php"] [unique_id "amuYpIJkCYmL5o6vh9KJmgAAAJw"]
[Thu Jul 30 13:32:04.909157 2026] [security2:error] [pid 890219:tid 890461] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/reop3.php"] [unique_id "amuYpIJkCYmL5o6vh9KJpQAAAPQ"]
[Thu Jul 30 13:32:04.909281 2026] [security2:error] [pid 890219:tid 890461] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/reop3.php"] [unique_id "amuYpIJkCYmL5o6vh9KJpQAAAPQ"]
[Thu Jul 30 13:32:05.055493 2026] [security2:error] [pid 890219:tid 890458] [client 68.221.186.136:4980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/admin.php"] [unique_id "amuYpYJkCYmL5o6vh9KJpgAAAPE"]
[Thu Jul 30 13:32:05.172118 2026] [security2:error] [pid 890219:tid 890390] [client 78.167.1.90:55297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYpYJkCYmL5o6vh9KJqAAAAK0"]
[Thu Jul 30 13:32:05.172260 2026] [security2:error] [pid 890219:tid 890390] [client 78.167.1.90:55297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYpYJkCYmL5o6vh9KJqAAAAK0"]
[Thu Jul 30 13:32:05.178399 2026] [security2:error] [pid 890219:tid 890466] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "n1rmalabet88.com"] [uri "/cgi-sys/404.html"] [unique_id "amuYpYJkCYmL5o6vh9KJqQAAAPk"]
[Thu Jul 30 13:32:05.320657 2026] [security2:error] [pid 890219:tid 890391] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp.php"] [unique_id "amuYpYJkCYmL5o6vh9KJrgAAAK4"]
[Thu Jul 30 13:32:05.320773 2026] [security2:error] [pid 890219:tid 890391] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/wp.php"] [unique_id "amuYpYJkCYmL5o6vh9KJrgAAAK4"]
[Thu Jul 30 13:32:05.729403 2026] [security2:error] [pid 890219:tid 890442] [client 68.221.186.136:40801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuYpYJkCYmL5o6vh9KJtgAAAOE"]
[Thu Jul 30 13:32:06.662595 2026] [security2:error] [pid 890219:tid 890460] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/dex.php"] [unique_id "amuYpoJkCYmL5o6vh9KJzQAAAPM"]
[Thu Jul 30 13:32:06.662706 2026] [security2:error] [pid 890219:tid 890460] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/dex.php"] [unique_id "amuYpoJkCYmL5o6vh9KJzQAAAPM"]
[Thu Jul 30 13:32:06.931241 2026] [security2:error] [pid 890219:tid 890419] [client 68.221.186.136:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuYpoJkCYmL5o6vh9KJ1AAAAMo"]
[Thu Jul 30 13:32:06.948661 2026] [security2:error] [pid 890219:tid 890362] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/biufile.php"] [unique_id "amuYpoJkCYmL5o6vh9KJ1QAAAJE"]
[Thu Jul 30 13:32:06.948780 2026] [security2:error] [pid 890219:tid 890362] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/biufile.php"] [unique_id "amuYpoJkCYmL5o6vh9KJ1QAAAJE"]
[Thu Jul 30 13:32:07.215010 2026] [security2:error] [pid 890219:tid 890414] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/inputs.php"] [unique_id "amuYp4JkCYmL5o6vh9KJ3AAAAMU"]
[Thu Jul 30 13:32:07.215126 2026] [security2:error] [pid 890219:tid 890414] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/inputs.php"] [unique_id "amuYp4JkCYmL5o6vh9KJ3AAAAMU"]
[Thu Jul 30 13:32:07.454843 2026] [security2:error] [pid 890219:tid 890397] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/inputs.php"] [unique_id "amuYp4JkCYmL5o6vh9KJ5gAAALQ"]
[Thu Jul 30 13:32:07.454965 2026] [security2:error] [pid 890219:tid 890397] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/inputs.php"] [unique_id "amuYp4JkCYmL5o6vh9KJ5gAAALQ"]
[Thu Jul 30 13:32:07.986765 2026] [security2:error] [pid 890219:tid 890403] [client 68.221.186.136:9784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuYp4JkCYmL5o6vh9KJ9AAAALo"]
[Thu Jul 30 13:32:08.425898 2026] [security2:error] [pid 890219:tid 890406] [client 74.7.230.26:36908] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuYp4JkCYmL5o6vh9KJ2gAAvUQ"]
[Thu Jul 30 13:32:08.497154 2026] [security2:error] [pid 890219:tid 890388] [client 74.7.230.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "professionalfurnituremovingcompanyllc.store"] [uri "/index.php"] [unique_id "amuYp4JkCYmL5o6vh9KJ2wAAqzY"]
[Thu Jul 30 13:32:08.710624 2026] [security2:error] [pid 890219:tid 890474] [client 68.221.186.136:41507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuYqIJkCYmL5o6vh9KKBAAAAQE"]
[Thu Jul 30 13:32:09.180769 2026] [core:notice] [pid 890219:tid 890271] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:09.262597 2026] [security2:error] [pid 890219:tid 890360] [client 13.215.155.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuYqYJkCYmL5o6vh9KKDwAAAI8"], referer: http://cnpinyin.com/miv-play?miv-id=258
[Thu Jul 30 13:32:09.718682 2026] [security2:error] [pid 890219:tid 890382] [client 68.221.186.136:2411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuYqYJkCYmL5o6vh9KKIgAAAKU"]
[Thu Jul 30 13:32:09.810382 2026] [core:notice] [pid 890219:tid 890288] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:09.940289 2026] [security2:error] [pid 890219:tid 890361] [client 193.47.62.167:56186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-b4577515.jvc.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuYp4JkCYmL5o6vh9KJ8AAAAJA"]
[Thu Jul 30 13:32:11.012526 2026] [security2:error] [pid 890219:tid 890428] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/adminfuns.php"] [unique_id "amuYq4JkCYmL5o6vh9KKPwAAANM"]
[Thu Jul 30 13:32:11.012639 2026] [security2:error] [pid 890219:tid 890428] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/adminfuns.php"] [unique_id "amuYq4JkCYmL5o6vh9KKPwAAANM"]
[Thu Jul 30 13:32:11.291795 2026] [security2:error] [pid 890219:tid 890359] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/goods.php"] [unique_id "amuYq4JkCYmL5o6vh9KKTAAAAI4"]
[Thu Jul 30 13:32:11.291896 2026] [security2:error] [pid 890219:tid 890359] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/goods.php"] [unique_id "amuYq4JkCYmL5o6vh9KKTAAAAI4"]
[Thu Jul 30 13:32:11.561569 2026] [security2:error] [pid 890219:tid 890375] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/about.php"] [unique_id "amuYq4JkCYmL5o6vh9KKUwAAAJ4"]
[Thu Jul 30 13:32:11.561671 2026] [security2:error] [pid 890219:tid 890375] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/about.php"] [unique_id "amuYq4JkCYmL5o6vh9KKUwAAAJ4"]
[Thu Jul 30 13:32:11.800794 2026] [security2:error] [pid 890219:tid 890393] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/about.php"] [unique_id "amuYq4JkCYmL5o6vh9KKWgAAALA"]
[Thu Jul 30 13:32:11.800913 2026] [security2:error] [pid 890219:tid 890393] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/about.php"] [unique_id "amuYq4JkCYmL5o6vh9KKWgAAALA"]
[Thu Jul 30 13:32:11.946578 2026] [security2:error] [pid 890219:tid 890436] [client 68.221.186.136:41502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuYq4JkCYmL5o6vh9KKWwAAANs"]
[Thu Jul 30 13:32:12.062998 2026] [security2:error] [pid 890219:tid 890404] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/admin.php"] [unique_id "amuYrIJkCYmL5o6vh9KKXwAAALs"]
[Thu Jul 30 13:32:12.063106 2026] [security2:error] [pid 890219:tid 890404] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/admin.php"] [unique_id "amuYrIJkCYmL5o6vh9KKXwAAALs"]
[Thu Jul 30 13:32:12.305415 2026] [security2:error] [pid 890219:tid 890417] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/admin.php"] [unique_id "amuYrIJkCYmL5o6vh9KKZwAAAMg"]
[Thu Jul 30 13:32:12.305540 2026] [security2:error] [pid 890219:tid 890417] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/admin.php"] [unique_id "amuYrIJkCYmL5o6vh9KKZwAAAMg"]
[Thu Jul 30 13:32:12.546778 2026] [security2:error] [pid 890219:tid 890476] [client 158.158.32.229:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.32.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/chosen.php"] [unique_id "amuYrIJkCYmL5o6vh9KKaAAAAQM"]
[Thu Jul 30 13:32:12.546889 2026] [security2:error] [pid 890219:tid 890476] [client 158.158.32.229:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "n1rmalabet88.com"] [uri "/chosen.php"] [unique_id "amuYrIJkCYmL5o6vh9KKaAAAAQM"]
[Thu Jul 30 13:32:12.640738 2026] [core:notice] [pid 890219:tid 890339] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:12.823828 2026] [security2:error] [pid 890219:tid 890357] [client 68.221.186.136:9776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuYrIJkCYmL5o6vh9KKdwAAAIw"]
[Thu Jul 30 13:32:12.826263 2026] [core:notice] [pid 890219:tid 890322] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:12.829694 2026] [core:error] [pid 890219:tid 890437] [client 74.7.241.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:12.829719 2026] [core:error] [pid 890219:tid 890437] [client 74.7.241.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:12.829862 2026] [security2:error] [pid 890219:tid 890437] [client 74.7.241.166:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuYrIJkCYmL5o6vh9KKeQAAANw"]
[Thu Jul 30 13:32:12.830598 2026] [security2:error] [pid 890219:tid 890446] [client 74.7.241.166:35674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuYrIJkCYmL5o6vh9KKdQAA5Xg"]
[Thu Jul 30 13:32:13.652068 2026] [core:notice] [pid 890219:tid 890393] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:13.822963 2026] [security2:error] [pid 890219:tid 890380] [client 68.221.186.136:12965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/content.php"] [unique_id "amuYrYJkCYmL5o6vh9KKkQAAAKM"]
[Thu Jul 30 13:32:14.200324 2026] [security2:error] [pid 890219:tid 890331] [remote 52.167.144.169:2795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/publika/article/view/8892/3549"] [unique_id "amuYrYJkCYmL5o6vh9KKkgAAoW4"]
[Thu Jul 30 13:32:14.698948 2026] [security2:error] [pid 890219:tid 890412] [client 78.167.1.90:55754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYroJkCYmL5o6vh9KKnwAAAMM"]
[Thu Jul 30 13:32:14.699754 2026] [security2:error] [pid 890219:tid 890412] [client 78.167.1.90:55754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYroJkCYmL5o6vh9KKnwAAAMM"]
[Thu Jul 30 13:32:14.910846 2026] [core:notice] [pid 890219:tid 890433] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:15.067221 2026] [core:error] [pid 890219:tid 890420] [client 34.24.215.179:46848] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.067230 2026] [core:error] [pid 890219:tid 890468] [client 34.24.215.179:46858] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.067245 2026] [core:error] [pid 890219:tid 890420] [client 34.24.215.179:46848] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.067254 2026] [core:error] [pid 890219:tid 890468] [client 34.24.215.179:46858] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.070065 2026] [core:error] [pid 890219:tid 890470] [client 34.24.215.179:46870] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.070080 2026] [core:error] [pid 890219:tid 890470] [client 34.24.215.179:46870] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.070413 2026] [core:error] [pid 890219:tid 890398] [client 34.24.215.179:46918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.070423 2026] [core:error] [pid 890219:tid 890398] [client 34.24.215.179:46918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.072119 2026] [core:error] [pid 890219:tid 890396] [client 34.24.215.179:46892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.072146 2026] [core:error] [pid 890219:tid 890396] [client 34.24.215.179:46892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.073582 2026] [core:error] [pid 890219:tid 890443] [client 34.24.215.179:46880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.073596 2026] [core:error] [pid 890219:tid 890443] [client 34.24.215.179:46880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.080093 2026] [core:error] [pid 890219:tid 890424] [client 34.24.215.179:46924] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.080107 2026] [core:error] [pid 890219:tid 890424] [client 34.24.215.179:46924] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.082218 2026] [core:error] [pid 890219:tid 890375] [client 34.24.215.179:46930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.082233 2026] [core:error] [pid 890219:tid 890375] [client 34.24.215.179:46930] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.082677 2026] [core:error] [pid 890219:tid 890438] [client 34.24.215.179:46946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.082687 2026] [core:error] [pid 890219:tid 890438] [client 34.24.215.179:46946] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.084112 2026] [security2:error] [pid 890219:tid 890359] [client 34.24.215.179:46874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/api/keys.json"] [unique_id "amuYr4JkCYmL5o6vh9KKsAAAAI4"]
[Thu Jul 30 13:32:15.090232 2026] [core:error] [pid 890219:tid 890385] [client 34.24.215.179:46968] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.090247 2026] [core:error] [pid 890219:tid 890385] [client 34.24.215.179:46968] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.090278 2026] [core:error] [pid 890219:tid 890358] [client 34.24.215.179:46958] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.090289 2026] [core:error] [pid 890219:tid 890358] [client 34.24.215.179:46958] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.090335 2026] [core:error] [pid 890219:tid 890365] [client 34.24.215.179:46982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.090346 2026] [core:error] [pid 890219:tid 890365] [client 34.24.215.179:46982] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.090768 2026] [security2:error] [pid 890219:tid 890439] [client 34.24.215.179:47040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.kbaagency.com"] [uri "/wp-config.php~"] [unique_id "amuYr4JkCYmL5o6vh9KKtQAAAN4"]
[Thu Jul 30 13:32:15.091362 2026] [core:error] [pid 890219:tid 890369] [client 34.24.215.179:46908] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.091380 2026] [core:error] [pid 890219:tid 890369] [client 34.24.215.179:46908] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.092910 2026] [security2:error] [pid 890219:tid 890475] [client 34.24.215.179:47060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.kbaagency.com"] [uri "/wp-config.php.save"] [unique_id "amuYr4JkCYmL5o6vh9KKuQAAAQI"]
[Thu Jul 30 13:32:15.093027 2026] [security2:error] [pid 890219:tid 890475] [client 34.24.215.179:47060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/wp-config.php.save"] [unique_id "amuYr4JkCYmL5o6vh9KKuQAAAQI"]
[Thu Jul 30 13:32:15.093469 2026] [core:error] [pid 890219:tid 890351] [client 34.24.215.179:47012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.093480 2026] [core:error] [pid 890219:tid 890351] [client 34.24.215.179:47012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.094008 2026] [core:error] [pid 890219:tid 890421] [client 34.24.215.179:46996] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.094023 2026] [core:error] [pid 890219:tid 890421] [client 34.24.215.179:46996] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.094533 2026] [core:error] [pid 890219:tid 890430] [client 34.24.215.179:46986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.094544 2026] [core:error] [pid 890219:tid 890430] [client 34.24.215.179:46986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.094969 2026] [security2:error] [pid 890219:tid 890449] [client 34.24.215.179:47068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/config.php.bak"] [unique_id "amuYr4JkCYmL5o6vh9KKuwAAAOg"]
[Thu Jul 30 13:32:15.095049 2026] [security2:error] [pid 890219:tid 890451] [client 34.24.215.179:47056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.kbaagency.com"] [uri "/wp-config.php.orig"] [unique_id "amuYr4JkCYmL5o6vh9KKvAAAAOo"]
[Thu Jul 30 13:32:15.095079 2026] [security2:error] [pid 890219:tid 890449] [client 34.24.215.179:47068] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/config.php.bak"] [unique_id "amuYr4JkCYmL5o6vh9KKuwAAAOg"]
[Thu Jul 30 13:32:15.108553 2026] [core:error] [pid 890219:tid 890404] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.108575 2026] [core:error] [pid 890219:tid 890404] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.108967 2026] [security2:error] [pid 890219:tid 890455] [client 34.24.215.179:47028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.kbaagency.com"] [uri "/wp-config.php.old"] [unique_id "amuYr4JkCYmL5o6vh9KKyQAAAO4"]
[Thu Jul 30 13:32:15.109101 2026] [core:error] [pid 890219:tid 890407] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.109113 2026] [core:error] [pid 890219:tid 890407] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.110208 2026] [core:error] [pid 890219:tid 890422] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.110222 2026] [core:error] [pid 890219:tid 890422] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.112513 2026] [core:error] [pid 890219:tid 890379] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.112528 2026] [core:error] [pid 890219:tid 890379] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.114359 2026] [core:error] [pid 890219:tid 890386] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.114375 2026] [core:error] [pid 890219:tid 890386] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.114476 2026] [security2:error] [pid 890219:tid 890399] [client 34.24.215.179:47140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/db.php"] [unique_id "amuYr4JkCYmL5o6vh9KKzQAAALY"]
[Thu Jul 30 13:32:15.128034 2026] [core:error] [pid 890219:tid 890461] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.128057 2026] [core:error] [pid 890219:tid 890461] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.128135 2026] [core:error] [pid 890219:tid 890474] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.128146 2026] [core:error] [pid 890219:tid 890474] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.128600 2026] [core:error] [pid 890219:tid 890354] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.128616 2026] [core:error] [pid 890219:tid 890354] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.131919 2026] [core:error] [pid 890219:tid 890378] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.131936 2026] [core:error] [pid 890219:tid 890378] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:15.465196 2026] [security2:error] [pid 890219:tid 890347] [remote 20.54.134.42:2524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-eea484b2.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuYr4JkCYmL5o6vh9KK4gAA-n4"]
[Thu Jul 30 13:32:16.960690 2026] [security2:error] [pid 890219:tid 890400] [client 68.221.186.136:12988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuYsIJkCYmL5o6vh9KLAQAAALc"]
[Thu Jul 30 13:32:17.605579 2026] [security2:error] [pid 890219:tid 890350] [client 85.208.96.211:44038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/09/23/estado-de-calamidade-publica-e-decretado-em-bananeiras-na-pb-por-causa-da-crise-hidrica/"] [unique_id "amuYsYJkCYmL5o6vh9KLEAAAAIU"]
[Thu Jul 30 13:32:17.605734 2026] [security2:error] [pid 890219:tid 890350] [client 85.208.96.211:44038] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/09/23/estado-de-calamidade-publica-e-decretado-em-bananeiras-na-pb-por-causa-da-crise-hidrica/"] [unique_id "amuYsYJkCYmL5o6vh9KLEAAAAIU"]
[Thu Jul 30 13:32:17.653942 2026] [security2:error] [pid 890219:tid 890444] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYsYJkCYmL5o6vh9KLAgAA4xg"]
[Thu Jul 30 13:32:17.665476 2026] [security2:error] [pid 890219:tid 890474] [client 129.226.174.80:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.174.226.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuYsYJkCYmL5o6vh9KLEQAAAQE"]
[Thu Jul 30 13:32:18.264666 2026] [security2:error] [pid 890219:tid 890412] [client 68.221.186.136:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuYsoJkCYmL5o6vh9KLGwAAAMM"]
[Thu Jul 30 13:32:19.124385 2026] [security2:error] [pid 890219:tid 890365] [client 68.221.186.136:22696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuYs4JkCYmL5o6vh9KLLwAAAJQ"]
[Thu Jul 30 13:32:19.190841 2026] [core:notice] [pid 890219:tid 890373] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:20.044861 2026] [security2:error] [pid 890219:tid 890356] [client 68.221.186.136:12754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuYtIJkCYmL5o6vh9KLSwAAAIs"]
[Thu Jul 30 13:32:21.329901 2026] [security2:error] [pid 890219:tid 890375] [client 68.221.186.136:22052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuYtYJkCYmL5o6vh9KLXwAAAJ4"]
[Thu Jul 30 13:32:21.903445 2026] [security2:error] [pid 890219:tid 890412] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYtYJkCYmL5o6vh9KLXgAAwy8"]
[Thu Jul 30 13:32:22.389825 2026] [security2:error] [pid 890219:tid 890452] [client 68.221.186.136:22698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuYtoJkCYmL5o6vh9KLdQAAAOs"]
[Thu Jul 30 13:32:22.574486 2026] [security2:error] [pid 890219:tid 890417] [client 74.7.241.170:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yne.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuYs4JkCYmL5o6vh9KLQQAAAMg"]
[Thu Jul 30 13:32:22.575238 2026] [security2:error] [pid 890219:tid 890350] [client 74.7.241.170:41822] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.yne.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuYs4JkCYmL5o6vh9KLPgAAhSs"]
[Thu Jul 30 13:32:22.961498 2026] [security2:error] [pid 890219:tid 890409] [client 68.221.186.136:4586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuYtoJkCYmL5o6vh9KLkgAAAMA"]
[Thu Jul 30 13:32:23.702036 2026] [security2:error] [pid 890219:tid 890351] [client 74.7.230.38:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kamiliacademy.com"] [uri "/index.php"] [unique_id "amuYt4JkCYmL5o6vh9KLngAAAIY"]
[Thu Jul 30 13:32:23.702784 2026] [security2:error] [pid 890219:tid 890446] [client 74.7.230.38:40940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kamiliacademy.com"] [uri "/robots.txt"] [unique_id "amuYt4JkCYmL5o6vh9KLnAAA5TA"]
[Thu Jul 30 13:32:23.765711 2026] [security2:error] [pid 890219:tid 890455] [client 74.248.33.8:42395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/themes/admin.php"] [unique_id "amuYt4JkCYmL5o6vh9KLqwAAAO4"]
[Thu Jul 30 13:32:24.153125 2026] [security2:error] [pid 890219:tid 890451] [client 68.221.186.136:22040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuYuIJkCYmL5o6vh9KLrgAAAOo"]
[Thu Jul 30 13:32:24.526850 2026] [core:notice] [pid 890219:tid 890401] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:24.988086 2026] [security2:error] [pid 890219:tid 890439] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuYuIJkCYmL5o6vh9KLwAAAAN4"]
[Thu Jul 30 13:32:24.988203 2026] [security2:error] [pid 890219:tid 890439] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuYuIJkCYmL5o6vh9KLwAAAAN4"]
[Thu Jul 30 13:32:25.248525 2026] [core:notice] [pid 890219:tid 890385] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:25.266714 2026] [security2:error] [pid 890219:tid 890351] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuYuYJkCYmL5o6vh9KLzAAAAIY"]
[Thu Jul 30 13:32:25.266794 2026] [security2:error] [pid 890219:tid 890351] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuYuYJkCYmL5o6vh9KLzAAAAIY"]
[Thu Jul 30 13:32:25.270673 2026] [security2:error] [pid 890219:tid 890468] [client 78.167.1.90:54760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYuYJkCYmL5o6vh9KLzgAAAPs"]
[Thu Jul 30 13:32:25.271461 2026] [security2:error] [pid 890219:tid 890468] [client 78.167.1.90:54760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYuYJkCYmL5o6vh9KLzgAAAPs"]
[Thu Jul 30 13:32:25.557757 2026] [security2:error] [pid 890219:tid 890364] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuYuYJkCYmL5o6vh9KL1gAAAJM"]
[Thu Jul 30 13:32:25.557874 2026] [security2:error] [pid 890219:tid 890364] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuYuYJkCYmL5o6vh9KL1gAAAJM"]
[Thu Jul 30 13:32:25.718862 2026] [security2:error] [pid 890219:tid 890433] [client 74.248.33.8:63757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/m.php"] [unique_id "amuYuYJkCYmL5o6vh9KL3wAAANg"]
[Thu Jul 30 13:32:25.774665 2026] [security2:error] [pid 890219:tid 890391] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYuYJkCYmL5o6vh9KLwwAArjI"]
[Thu Jul 30 13:32:25.816347 2026] [security2:error] [pid 890219:tid 890393] [client 136.116.113.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.113.116.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/reviewer"] [unique_id "amuYuYJkCYmL5o6vh9KL1QAAALA"]
[Thu Jul 30 13:32:25.845434 2026] [security2:error] [pid 890219:tid 890447] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/err.php"] [unique_id "amuYuYJkCYmL5o6vh9KL6gAAAOY"]
[Thu Jul 30 13:32:25.845534 2026] [security2:error] [pid 890219:tid 890447] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/err.php"] [unique_id "amuYuYJkCYmL5o6vh9KL6gAAAOY"]
[Thu Jul 30 13:32:26.144386 2026] [security2:error] [pid 890219:tid 890382] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/img.php"] [unique_id "amuYuoJkCYmL5o6vh9KL-wAAAKU"]
[Thu Jul 30 13:32:26.144547 2026] [security2:error] [pid 890219:tid 890382] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/img.php"] [unique_id "amuYuoJkCYmL5o6vh9KL-wAAAKU"]
[Thu Jul 30 13:32:26.439159 2026] [security2:error] [pid 890219:tid 890429] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/aa.php"] [unique_id "amuYuoJkCYmL5o6vh9KMBwAAANQ"]
[Thu Jul 30 13:32:26.439254 2026] [security2:error] [pid 890219:tid 890429] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/aa.php"] [unique_id "amuYuoJkCYmL5o6vh9KMBwAAANQ"]
[Thu Jul 30 13:32:26.724053 2026] [security2:error] [pid 890219:tid 890422] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/av.php"] [unique_id "amuYuoJkCYmL5o6vh9KMHQAAAM0"]
[Thu Jul 30 13:32:26.724151 2026] [security2:error] [pid 890219:tid 890422] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/av.php"] [unique_id "amuYuoJkCYmL5o6vh9KMHQAAAM0"]
[Thu Jul 30 13:32:26.996148 2026] [security2:error] [pid 890219:tid 890452] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/xa.php"] [unique_id "amuYuoJkCYmL5o6vh9KMNgAAAOs"]
[Thu Jul 30 13:32:26.996285 2026] [security2:error] [pid 890219:tid 890452] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/xa.php"] [unique_id "amuYuoJkCYmL5o6vh9KMNgAAAOs"]
[Thu Jul 30 13:32:27.297785 2026] [security2:error] [pid 890219:tid 890448] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/media.php"] [unique_id "amuYu4JkCYmL5o6vh9KMPgAAAOc"]
[Thu Jul 30 13:32:27.297904 2026] [security2:error] [pid 890219:tid 890448] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/media.php"] [unique_id "amuYu4JkCYmL5o6vh9KMPgAAAOc"]
[Thu Jul 30 13:32:27.571741 2026] [security2:error] [pid 890219:tid 890357] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/images.php"] [unique_id "amuYu4JkCYmL5o6vh9KMRQAAAIw"]
[Thu Jul 30 13:32:27.571862 2026] [security2:error] [pid 890219:tid 890357] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/images.php"] [unique_id "amuYu4JkCYmL5o6vh9KMRQAAAIw"]
[Thu Jul 30 13:32:27.744417 2026] [security2:error] [pid 890219:tid 890385] [client 74.248.33.8:43383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuYu4JkCYmL5o6vh9KMRAAAAKg"]
[Thu Jul 30 13:32:27.841488 2026] [security2:error] [pid 890219:tid 890359] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/gecko.php"] [unique_id "amuYu4JkCYmL5o6vh9KMTAAAAI4"]
[Thu Jul 30 13:32:27.841579 2026] [security2:error] [pid 890219:tid 890359] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/gecko.php"] [unique_id "amuYu4JkCYmL5o6vh9KMTAAAAI4"]
[Thu Jul 30 13:32:27.996591 2026] [core:error] [pid 890219:tid 890458] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:27.996611 2026] [core:error] [pid 890219:tid 890458] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.008803 2026] [security2:error] [pid 890219:tid 890405] [client 34.24.215.179:42936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/web.config"] [unique_id "amuYvIJkCYmL5o6vh9KMWQAAALw"]
[Thu Jul 30 13:32:28.010567 2026] [core:error] [pid 890219:tid 890395] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.010583 2026] [core:error] [pid 890219:tid 890395] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.028339 2026] [core:error] [pid 890219:tid 890449] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.028358 2026] [core:error] [pid 890219:tid 890449] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.036842 2026] [core:error] [pid 890219:tid 890415] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.036871 2026] [core:error] [pid 890219:tid 890415] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.041280 2026] [core:error] [pid 890219:tid 890446] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.041300 2026] [core:error] [pid 890219:tid 890446] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.042785 2026] [core:error] [pid 890219:tid 890370] [client 34.24.215.179:43028] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.042803 2026] [core:error] [pid 890219:tid 890370] [client 34.24.215.179:43028] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.043439 2026] [security2:error] [pid 890219:tid 890409] [client 34.24.215.179:43066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/database.sql"] [unique_id "amuYvIJkCYmL5o6vh9KMaAAAAMA"]
[Thu Jul 30 13:32:28.043963 2026] [security2:error] [pid 890219:tid 890389] [client 34.24.215.179:43050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/dump.sql"] [unique_id "amuYvIJkCYmL5o6vh9KMagAAAKw"]
[Thu Jul 30 13:32:28.045022 2026] [core:error] [pid 890219:tid 890460] [client 34.24.215.179:43018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.045037 2026] [core:error] [pid 890219:tid 890460] [client 34.24.215.179:43018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.047014 2026] [core:error] [pid 890219:tid 890453] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.047030 2026] [core:error] [pid 890219:tid 890453] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.047083 2026] [security2:error] [pid 890219:tid 890353] [client 34.24.215.179:43036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/backup.sql"] [unique_id "amuYvIJkCYmL5o6vh9KMbQAAAIg"]
[Thu Jul 30 13:32:28.047615 2026] [core:error] [pid 890219:tid 890450] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.047628 2026] [core:error] [pid 890219:tid 890450] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.059230 2026] [core:error] [pid 890219:tid 890438] [client 34.24.215.179:43006] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.059246 2026] [core:error] [pid 890219:tid 890438] [client 34.24.215.179:43006] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.062527 2026] [core:error] [pid 890219:tid 890382] [client 34.24.215.179:43014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.062546 2026] [core:error] [pid 890219:tid 890382] [client 34.24.215.179:43014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.062716 2026] [security2:error] [pid 890219:tid 890456] [client 34.24.215.179:43058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/db.sql"] [unique_id "amuYvIJkCYmL5o6vh9KMcgAAAO8"]
[Thu Jul 30 13:32:28.062845 2026] [security2:error] [pid 890219:tid 890456] [client 34.24.215.179:43058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/db.sql"] [unique_id "amuYvIJkCYmL5o6vh9KMcgAAAO8"]
[Thu Jul 30 13:32:28.069050 2026] [core:error] [pid 890219:tid 890372] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.069066 2026] [core:error] [pid 890219:tid 890372] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:28.130298 2026] [security2:error] [pid 890219:tid 890406] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/82.php"] [unique_id "amuYvIJkCYmL5o6vh9KMdAAAAL0"]
[Thu Jul 30 13:32:28.130404 2026] [security2:error] [pid 890219:tid 890406] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/82.php"] [unique_id "amuYvIJkCYmL5o6vh9KMdAAAAL0"]
[Thu Jul 30 13:32:28.494168 2026] [security2:error] [pid 890219:tid 890391] [client 74.248.33.8:63852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wk/index.php"] [unique_id "amuYvIJkCYmL5o6vh9KMgwAAAK4"]
[Thu Jul 30 13:32:28.602330 2026] [security2:error] [pid 890219:tid 890411] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/xstelth.php"] [unique_id "amuYvIJkCYmL5o6vh9KMhQAAAMI"]
[Thu Jul 30 13:32:28.602432 2026] [security2:error] [pid 890219:tid 890411] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/xstelth.php"] [unique_id "amuYvIJkCYmL5o6vh9KMhQAAAMI"]
[Thu Jul 30 13:32:28.893802 2026] [security2:error] [pid 890219:tid 890421] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/xp.php"] [unique_id "amuYvIJkCYmL5o6vh9KMiQAAAMw"]
[Thu Jul 30 13:32:28.893922 2026] [security2:error] [pid 890219:tid 890421] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/xp.php"] [unique_id "amuYvIJkCYmL5o6vh9KMiQAAAMw"]
[Thu Jul 30 13:32:29.107394 2026] [security2:error] [pid 890219:tid 890429] [client 74.248.33.8:43333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/mini.php"] [unique_id "amuYvYJkCYmL5o6vh9KMlwAAANQ"]
[Thu Jul 30 13:32:29.175795 2026] [security2:error] [pid 890219:tid 890401] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/admin.php"] [unique_id "amuYvYJkCYmL5o6vh9KMmAAAALg"]
[Thu Jul 30 13:32:29.175919 2026] [security2:error] [pid 890219:tid 890401] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/admin.php"] [unique_id "amuYvYJkCYmL5o6vh9KMmAAAALg"]
[Thu Jul 30 13:32:29.457320 2026] [security2:error] [pid 890219:tid 890450] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/adminner.php"] [unique_id "amuYvYJkCYmL5o6vh9KMngAAAOk"]
[Thu Jul 30 13:32:29.457408 2026] [security2:error] [pid 890219:tid 890450] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/adminner.php"] [unique_id "amuYvYJkCYmL5o6vh9KMngAAAOk"]
[Thu Jul 30 13:32:29.626123 2026] [proxy:error] [pid 890219:tid 890273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:32:29.626175 2026] [proxy_http:error] [pid 890219:tid 890273] [remote 74.7.241.177:49564] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:32:29.626994 2026] [proxy:error] [pid 890219:tid 890273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:32:29.627054 2026] [proxy_http:error] [pid 890219:tid 890273] [remote 74.7.241.177:49564] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:32:29.724692 2026] [security2:error] [pid 890219:tid 890425] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/a.php"] [unique_id "amuYvYJkCYmL5o6vh9KMpwAAANA"]
[Thu Jul 30 13:32:29.724827 2026] [security2:error] [pid 890219:tid 890425] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/a.php"] [unique_id "amuYvYJkCYmL5o6vh9KMpwAAANA"]
[Thu Jul 30 13:32:30.034772 2026] [security2:error] [pid 890219:tid 890440] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/k.php"] [unique_id "amuYvoJkCYmL5o6vh9KMrgAAAN8"]
[Thu Jul 30 13:32:30.034883 2026] [security2:error] [pid 890219:tid 890440] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/k.php"] [unique_id "amuYvoJkCYmL5o6vh9KMrgAAAN8"]
[Thu Jul 30 13:32:30.262781 2026] [security2:error] [pid 890219:tid 890476] [client 74.248.33.8:32706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/aa.php"] [unique_id "amuYvoJkCYmL5o6vh9KMsgAAAQM"]
[Thu Jul 30 13:32:30.325875 2026] [security2:error] [pid 890219:tid 890383] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/222.php"] [unique_id "amuYvoJkCYmL5o6vh9KMswAAAKY"]
[Thu Jul 30 13:32:30.326047 2026] [security2:error] [pid 890219:tid 890383] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/222.php"] [unique_id "amuYvoJkCYmL5o6vh9KMswAAAKY"]
[Thu Jul 30 13:32:30.355969 2026] [security2:error] [pid 890219:tid 890459] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuYvYJkCYmL5o6vh9KMpgAAAPI"]
[Thu Jul 30 13:32:30.599206 2026] [security2:error] [pid 890219:tid 890475] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/mac.php"] [unique_id "amuYvoJkCYmL5o6vh9KMvgAAAQI"]
[Thu Jul 30 13:32:30.599345 2026] [security2:error] [pid 890219:tid 890475] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/mac.php"] [unique_id "amuYvoJkCYmL5o6vh9KMvgAAAQI"]
[Thu Jul 30 13:32:30.916508 2026] [security2:error] [pid 890219:tid 890414] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.jookreview.com"] [uri "/___proxy_subdomain_webmail/wp-content/uploads/"] [unique_id "amuYvoJkCYmL5o6vh9KMwAAAAMU"]
[Thu Jul 30 13:32:31.096721 2026] [security2:error] [pid 890219:tid 890435] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.jookreview.com"] [uri "/___proxy_subdomain_webmail/wp-includes/Text/"] [unique_id "amuYv4JkCYmL5o6vh9KMxwAAANo"]
[Thu Jul 30 13:32:31.160973 2026] [security2:error] [pid 890219:tid 890395] [client 74.248.33.8:46560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/w.php"] [unique_id "amuYv4JkCYmL5o6vh9KMywAAALI"]
[Thu Jul 30 13:32:31.241303 2026] [security2:error] [pid 890219:tid 890460] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/ops.php"] [unique_id "amuYv4JkCYmL5o6vh9KMzAAAAPM"]
[Thu Jul 30 13:32:31.241549 2026] [security2:error] [pid 890219:tid 890460] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/ops.php"] [unique_id "amuYv4JkCYmL5o6vh9KMzAAAAPM"]
[Thu Jul 30 13:32:31.531663 2026] [security2:error] [pid 890219:tid 890426] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/8.php"] [unique_id "amuYv4JkCYmL5o6vh9KM0AAAANE"]
[Thu Jul 30 13:32:31.531766 2026] [security2:error] [pid 890219:tid 890426] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/8.php"] [unique_id "amuYv4JkCYmL5o6vh9KM0AAAANE"]
[Thu Jul 30 13:32:32.197353 2026] [security2:error] [pid 890219:tid 890440] [client 74.248.33.8:63868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/admin.php"] [unique_id "amuYwIJkCYmL5o6vh9KM5AAAAN8"]
[Thu Jul 30 13:32:32.999089 2026] [security2:error] [pid 890219:tid 890297] [remote 97.74.93.24:58002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahk.tqa.temporary.site"] [uri "/wp-login.php"] [unique_id "amuYwIJkCYmL5o6vh9KM-QAA4kw"]
[Thu Jul 30 13:32:33.237079 2026] [security2:error] [pid 890219:tid 890431] [client 103.112.69.58:36282] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 58.69.112.103.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/wp-comments-post.php"] [unique_id "amuYwIJkCYmL5o6vh9KM-AAAANY"]
[Thu Jul 30 13:32:33.237246 2026] [security2:error] [pid 890219:tid 890431] [client 103.112.69.58:36282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/wp-comments-post.php"] [unique_id "amuYwIJkCYmL5o6vh9KM-AAAANY"]
[Thu Jul 30 13:32:33.301153 2026] [security2:error] [pid 890219:tid 890364] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYwIJkCYmL5o6vh9KM7wAAkzo"]
[Thu Jul 30 13:32:33.592167 2026] [security2:error] [pid 890219:tid 890427] [client 74.248.33.8:25756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/404.php"] [unique_id "amuYwYJkCYmL5o6vh9KNBAAAANI"]
[Thu Jul 30 13:32:33.907167 2026] [security2:error] [pid 890219:tid 890271] [remote 122.154.0.170:49266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.0.154.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-login.php"] [unique_id "amuYwYJkCYmL5o6vh9KNDgAA_zI"]
[Thu Jul 30 13:32:33.992837 2026] [security2:error] [pid 890219:tid 890393] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/FWAZ.php"] [unique_id "amuYwYJkCYmL5o6vh9KNEAAAALA"]
[Thu Jul 30 13:32:33.992937 2026] [security2:error] [pid 890219:tid 890393] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/FWAZ.php"] [unique_id "amuYwYJkCYmL5o6vh9KNEAAAALA"]
[Thu Jul 30 13:32:34.286063 2026] [security2:error] [pid 890219:tid 890461] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/biufile.php"] [unique_id "amuYwoJkCYmL5o6vh9KNGAAAAPQ"]
[Thu Jul 30 13:32:34.286158 2026] [security2:error] [pid 890219:tid 890461] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/biufile.php"] [unique_id "amuYwoJkCYmL5o6vh9KNGAAAAPQ"]
[Thu Jul 30 13:32:34.554833 2026] [security2:error] [pid 890219:tid 890447] [client 74.248.33.8:46573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/init.php"] [unique_id "amuYwoJkCYmL5o6vh9KNHQAAAOY"]
[Thu Jul 30 13:32:34.554957 2026] [security2:error] [pid 890219:tid 890396] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/coffexium.php"] [unique_id "amuYwoJkCYmL5o6vh9KNHgAAALM"]
[Thu Jul 30 13:32:34.555044 2026] [security2:error] [pid 890219:tid 890396] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/coffexium.php"] [unique_id "amuYwoJkCYmL5o6vh9KNHgAAALM"]
[Thu Jul 30 13:32:34.834120 2026] [security2:error] [pid 890219:tid 890443] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/simple.php"] [unique_id "amuYwoJkCYmL5o6vh9KNKAAAAOI"]
[Thu Jul 30 13:32:34.834242 2026] [security2:error] [pid 890219:tid 890443] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/simple.php"] [unique_id "amuYwoJkCYmL5o6vh9KNKAAAAOI"]
[Thu Jul 30 13:32:34.983074 2026] [security2:error] [pid 890219:tid 890385] [client 68.221.186.136:12887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuYwoJkCYmL5o6vh9KNLAAAAKg"]
[Thu Jul 30 13:32:35.143586 2026] [security2:error] [pid 890219:tid 890455] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/fpwch.php"] [unique_id "amuYw4JkCYmL5o6vh9KNLgAAAO4"]
[Thu Jul 30 13:32:35.143734 2026] [security2:error] [pid 890219:tid 890455] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/fpwch.php"] [unique_id "amuYw4JkCYmL5o6vh9KNLgAAAO4"]
[Thu Jul 30 13:32:35.420201 2026] [security2:error] [pid 890219:tid 890382] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/dex.php"] [unique_id "amuYw4JkCYmL5o6vh9KNOwAAAKU"]
[Thu Jul 30 13:32:35.420351 2026] [security2:error] [pid 890219:tid 890382] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/dex.php"] [unique_id "amuYw4JkCYmL5o6vh9KNOwAAAKU"]
[Thu Jul 30 13:32:35.704676 2026] [security2:error] [pid 890219:tid 890451] [client 20.215.216.94:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.jookreview.com"] [uri "/1.php"] [unique_id "amuYw4JkCYmL5o6vh9KNQQAAAOo"]
[Thu Jul 30 13:32:35.704806 2026] [security2:error] [pid 890219:tid 890451] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/1.php"] [unique_id "amuYw4JkCYmL5o6vh9KNQQAAAOo"]
[Thu Jul 30 13:32:35.704927 2026] [security2:error] [pid 890219:tid 890451] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/1.php"] [unique_id "amuYw4JkCYmL5o6vh9KNQQAAAOo"]
[Thu Jul 30 13:32:35.933789 2026] [security2:error] [pid 890219:tid 890309] [remote 57.141.0.15:65162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuYw4JkCYmL5o6vh9KNSwAA9Vg"]
[Thu Jul 30 13:32:36.065031 2026] [security2:error] [pid 890219:tid 890396] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.jookreview.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/modern/"] [unique_id "amuYxIJkCYmL5o6vh9KNTAAAALM"]
[Thu Jul 30 13:32:36.074382 2026] [security2:error] [pid 890219:tid 890448] [client 74.248.33.8:43328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/adminfuns.php"] [unique_id "amuYxIJkCYmL5o6vh9KNTQAAAOc"]
[Thu Jul 30 13:32:36.237128 2026] [security2:error] [pid 890219:tid 890421] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/config.json.php"] [unique_id "amuYxIJkCYmL5o6vh9KNUgAAAMw"]
[Thu Jul 30 13:32:36.237248 2026] [security2:error] [pid 890219:tid 890421] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/config.json.php"] [unique_id "amuYxIJkCYmL5o6vh9KNUgAAAMw"]
[Thu Jul 30 13:32:36.281845 2026] [security2:error] [pid 890219:tid 890472] [client 68.221.186.136:3037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuYxIJkCYmL5o6vh9KNUwAAAP8"]
[Thu Jul 30 13:32:36.556016 2026] [security2:error] [pid 890219:tid 890443] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/k2.php"] [unique_id "amuYxIJkCYmL5o6vh9KNWgAAAOI"]
[Thu Jul 30 13:32:36.556126 2026] [security2:error] [pid 890219:tid 890443] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/k2.php"] [unique_id "amuYxIJkCYmL5o6vh9KNWgAAAOI"]
[Thu Jul 30 13:32:36.828188 2026] [security2:error] [pid 890219:tid 890409] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/raw.php"] [unique_id "amuYxIJkCYmL5o6vh9KNXgAAAMA"]
[Thu Jul 30 13:32:36.828294 2026] [security2:error] [pid 890219:tid 890409] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/raw.php"] [unique_id "amuYxIJkCYmL5o6vh9KNXgAAAMA"]
[Thu Jul 30 13:32:36.881448 2026] [security2:error] [pid 890219:tid 890435] [client 78.167.1.90:53919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYxIJkCYmL5o6vh9KNYgAAANo"]
[Thu Jul 30 13:32:36.882251 2026] [security2:error] [pid 890219:tid 890435] [client 78.167.1.90:53919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYxIJkCYmL5o6vh9KNYgAAANo"]
[Thu Jul 30 13:32:37.008204 2026] [security2:error] [pid 890219:tid 890408] [client 74.248.33.8:32138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/file.php"] [unique_id "amuYxYJkCYmL5o6vh9KNZgAAAL8"]
[Thu Jul 30 13:32:37.135441 2026] [security2:error] [pid 890219:tid 890456] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/wp.php"] [unique_id "amuYxYJkCYmL5o6vh9KNZwAAAO8"]
[Thu Jul 30 13:32:37.135569 2026] [security2:error] [pid 890219:tid 890456] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/wp.php"] [unique_id "amuYxYJkCYmL5o6vh9KNZwAAAO8"]
[Thu Jul 30 13:32:37.409513 2026] [security2:error] [pid 890219:tid 890370] [client 68.221.186.136:22548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuYxYJkCYmL5o6vh9KNeQAAAJk"]
[Thu Jul 30 13:32:37.440298 2026] [security2:error] [pid 890219:tid 890444] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/fffm.php"] [unique_id "amuYxYJkCYmL5o6vh9KNegAAAOM"]
[Thu Jul 30 13:32:37.440390 2026] [security2:error] [pid 890219:tid 890444] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/fffm.php"] [unique_id "amuYxYJkCYmL5o6vh9KNegAAAOM"]
[Thu Jul 30 13:32:37.755720 2026] [security2:error] [pid 890219:tid 890368] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/111.php"] [unique_id "amuYxYJkCYmL5o6vh9KNewAAAJc"]
[Thu Jul 30 13:32:37.755846 2026] [security2:error] [pid 890219:tid 890368] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/111.php"] [unique_id "amuYxYJkCYmL5o6vh9KNewAAAJc"]
[Thu Jul 30 13:32:38.106082 2026] [security2:error] [pid 890219:tid 890430] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.jookreview.com"] [uri "/___proxy_subdomain_webmail/wp-includes/Requests/"] [unique_id "amuYxoJkCYmL5o6vh9KNhQAAANU"]
[Thu Jul 30 13:32:38.205845 2026] [security2:error] [pid 890219:tid 890445] [client 68.221.186.136:22588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/about.php"] [unique_id "amuYxoJkCYmL5o6vh9KNhgAAAOQ"]
[Thu Jul 30 13:32:38.251860 2026] [security2:error] [pid 890219:tid 890470] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/ws.php"] [unique_id "amuYxoJkCYmL5o6vh9KNhwAAAP0"]
[Thu Jul 30 13:32:38.252000 2026] [security2:error] [pid 890219:tid 890470] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/ws.php"] [unique_id "amuYxoJkCYmL5o6vh9KNhwAAAP0"]
[Thu Jul 30 13:32:38.529732 2026] [security2:error] [pid 890219:tid 890429] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/coffee.php"] [unique_id "amuYxoJkCYmL5o6vh9KNkQAAANQ"]
[Thu Jul 30 13:32:38.529811 2026] [security2:error] [pid 890219:tid 890429] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/coffee.php"] [unique_id "amuYxoJkCYmL5o6vh9KNkQAAANQ"]
[Thu Jul 30 13:32:38.707062 2026] [security2:error] [pid 890219:tid 890334] [remote 74.7.243.224:42616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/article.php"] [unique_id "amuYxoJkCYmL5o6vh9KNkwAAknE"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:32:38.815157 2026] [security2:error] [pid 890219:tid 890431] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/goods.php"] [unique_id "amuYxoJkCYmL5o6vh9KNlwAAANY"]
[Thu Jul 30 13:32:38.815276 2026] [security2:error] [pid 890219:tid 890431] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/goods.php"] [unique_id "amuYxoJkCYmL5o6vh9KNlwAAANY"]
[Thu Jul 30 13:32:38.996504 2026] [security2:error] [pid 890219:tid 890389] [client 68.221.186.136:22553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/about.php"] [unique_id "amuYxoJkCYmL5o6vh9KNngAAAKw"]
[Thu Jul 30 13:32:39.086128 2026] [security2:error] [pid 890219:tid 890372] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/about.php"] [unique_id "amuYx4JkCYmL5o6vh9KNnwAAAJs"]
[Thu Jul 30 13:32:39.086231 2026] [security2:error] [pid 890219:tid 890372] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/about.php"] [unique_id "amuYx4JkCYmL5o6vh9KNnwAAAJs"]
[Thu Jul 30 13:32:39.372344 2026] [security2:error] [pid 890219:tid 890452] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/about.php"] [unique_id "amuYx4JkCYmL5o6vh9KNpQAAAOs"]
[Thu Jul 30 13:32:39.372502 2026] [security2:error] [pid 890219:tid 890452] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/about.php"] [unique_id "amuYx4JkCYmL5o6vh9KNpQAAAOs"]
[Thu Jul 30 13:32:39.562139 2026] [security2:error] [pid 890219:tid 890366] [client 74.248.33.8:48386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/222.php"] [unique_id "amuYx4JkCYmL5o6vh9KNrAAAAJU"]
[Thu Jul 30 13:32:40.277418 2026] [security2:error] [pid 890219:tid 890373] [client 74.248.33.8:46565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuYyIJkCYmL5o6vh9KNtwAAAJw"]
[Thu Jul 30 13:32:40.578179 2026] [security2:error] [pid 890219:tid 890412] [client 68.221.186.136:6349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuYyIJkCYmL5o6vh9KNwwAAAMM"]
[Thu Jul 30 13:32:40.954213 2026] [security2:error] [pid 890219:tid 890468] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/admin.php"] [unique_id "amuYyIJkCYmL5o6vh9KNywAAAPs"]
[Thu Jul 30 13:32:40.954318 2026] [security2:error] [pid 890219:tid 890468] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/admin.php"] [unique_id "amuYyIJkCYmL5o6vh9KNywAAAPs"]
[Thu Jul 30 13:32:41.245868 2026] [security2:error] [pid 890219:tid 890477] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/inputs.php"] [unique_id "amuYyYJkCYmL5o6vh9KN1gAAAQQ"]
[Thu Jul 30 13:32:41.246025 2026] [security2:error] [pid 890219:tid 890477] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/inputs.php"] [unique_id "amuYyYJkCYmL5o6vh9KN1gAAAQQ"]
[Thu Jul 30 13:32:41.342430 2026] [core:error] [pid 890219:tid 890369] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:41.342461 2026] [core:error] [pid 890219:tid 890369] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:41.349399 2026] [fcgid:warn] [pid 890219:tid 890372] (70014)End of file found: [client 34.24.215.179:28922] mod_fcgid: can't get data from http client
[Thu Jul 30 13:32:41.513872 2026] [security2:error] [pid 890219:tid 890360] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/inputs.php"] [unique_id "amuYyYJkCYmL5o6vh9KN4QAAAI8"]
[Thu Jul 30 13:32:41.513985 2026] [security2:error] [pid 890219:tid 890360] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/inputs.php"] [unique_id "amuYyYJkCYmL5o6vh9KN4QAAAI8"]
[Thu Jul 30 13:32:41.543894 2026] [security2:error] [pid 890219:tid 890267] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admadmin.php"] [unique_id "amuYyYJkCYmL5o6vh9KN4gAAxC4"]
[Thu Jul 30 13:32:41.798770 2026] [security2:error] [pid 890219:tid 890416] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/adminfuns.php"] [unique_id "amuYyYJkCYmL5o6vh9KN7gAAAMc"]
[Thu Jul 30 13:32:41.798861 2026] [security2:error] [pid 890219:tid 890416] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/adminfuns.php"] [unique_id "amuYyYJkCYmL5o6vh9KN7gAAAMc"]
[Thu Jul 30 13:32:42.086840 2026] [security2:error] [pid 890219:tid 890359] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/404.php"] [unique_id "amuYyoJkCYmL5o6vh9KN9QAAAI4"]
[Thu Jul 30 13:32:42.086946 2026] [security2:error] [pid 890219:tid 890359] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/404.php"] [unique_id "amuYyoJkCYmL5o6vh9KN9QAAAI4"]
[Thu Jul 30 13:32:42.358335 2026] [security2:error] [pid 890219:tid 890405] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/xxx.php"] [unique_id "amuYyoJkCYmL5o6vh9KN_gAAALw"]
[Thu Jul 30 13:32:42.358435 2026] [security2:error] [pid 890219:tid 890405] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/xxx.php"] [unique_id "amuYyoJkCYmL5o6vh9KN_gAAALw"]
[Thu Jul 30 13:32:42.480890 2026] [security2:error] [pid 890219:tid 890270] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admalfa.php"] [unique_id "amuYyoJkCYmL5o6vh9KN_wAA8DE"]
[Thu Jul 30 13:32:42.641594 2026] [security2:error] [pid 890219:tid 890465] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/classwithtostring.php"] [unique_id "amuYyoJkCYmL5o6vh9KOBgAAAPg"]
[Thu Jul 30 13:32:42.641675 2026] [security2:error] [pid 890219:tid 890465] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/classwithtostring.php"] [unique_id "amuYyoJkCYmL5o6vh9KOBgAAAPg"]
[Thu Jul 30 13:32:42.806124 2026] [security2:error] [pid 890219:tid 890227] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admbypass.php"] [unique_id "amuYyoJkCYmL5o6vh9KODAAAtAY"]
[Thu Jul 30 13:32:42.932742 2026] [security2:error] [pid 890219:tid 890471] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/234ff.php"] [unique_id "amuYyoJkCYmL5o6vh9KODQAAAP4"]
[Thu Jul 30 13:32:42.932896 2026] [security2:error] [pid 890219:tid 890471] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/234ff.php"] [unique_id "amuYyoJkCYmL5o6vh9KODQAAAP4"]
[Thu Jul 30 13:32:43.072837 2026] [security2:error] [pid 890219:tid 890365] [client 74.7.241.185:57954] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.wce.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuYyYJkCYmL5o6vh9KN6QAAlBY"]
[Thu Jul 30 13:32:43.102176 2026] [security2:error] [pid 890219:tid 890263] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admiin.php"] [unique_id "amuYy4JkCYmL5o6vh9KOFAAAkio"]
[Thu Jul 30 13:32:43.220927 2026] [security2:error] [pid 890219:tid 890398] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/133.php"] [unique_id "amuYy4JkCYmL5o6vh9KOHwAAALU"]
[Thu Jul 30 13:32:43.221073 2026] [security2:error] [pid 890219:tid 890398] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/133.php"] [unique_id "amuYy4JkCYmL5o6vh9KOHwAAALU"]
[Thu Jul 30 13:32:43.246876 2026] [security2:error] [pid 890219:tid 890356] [client 74.248.33.8:46584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/admin.php"] [unique_id "amuYy4JkCYmL5o6vh9KOIAAAAIs"]
[Thu Jul 30 13:32:43.378965 2026] [security2:error] [pid 890219:tid 890285] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin%201.php"] [unique_id "amuYy4JkCYmL5o6vh9KOIQAAqUA"]
[Thu Jul 30 13:32:43.504296 2026] [security2:error] [pid 890219:tid 890463] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/wp-ws68.php"] [unique_id "amuYy4JkCYmL5o6vh9KOIwAAAPY"]
[Thu Jul 30 13:32:43.504405 2026] [security2:error] [pid 890219:tid 890463] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/wp-ws68.php"] [unique_id "amuYy4JkCYmL5o6vh9KOIwAAAPY"]
[Thu Jul 30 13:32:43.582286 2026] [security2:error] [pid 890219:tid 890426] [client 68.221.186.136:11968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuYy4JkCYmL5o6vh9KOJAAAANE"]
[Thu Jul 30 13:32:43.683055 2026] [security2:error] [pid 890219:tid 890265] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin-ajax.php"] [unique_id "amuYy4JkCYmL5o6vh9KOKwAAqiw"]
[Thu Jul 30 13:32:43.794989 2026] [security2:error] [pid 890219:tid 890459] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/mgrr.php"] [unique_id "amuYy4JkCYmL5o6vh9KONAAAAPI"]
[Thu Jul 30 13:32:43.795107 2026] [security2:error] [pid 890219:tid 890459] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/mgrr.php"] [unique_id "amuYy4JkCYmL5o6vh9KONAAAAPI"]
[Thu Jul 30 13:32:43.951362 2026] [security2:error] [pid 890219:tid 890289] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin-footer.php"] [unique_id "amuYy4JkCYmL5o6vh9KONgAA30Q"]
[Thu Jul 30 13:32:44.078230 2026] [security2:error] [pid 890219:tid 890404] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/55.php"] [unique_id "amuYzIJkCYmL5o6vh9KONwAAALs"]
[Thu Jul 30 13:32:44.078348 2026] [security2:error] [pid 890219:tid 890404] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/55.php"] [unique_id "amuYzIJkCYmL5o6vh9KONwAAALs"]
[Thu Jul 30 13:32:44.269529 2026] [security2:error] [pid 890219:tid 890290] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin-functions.php"] [unique_id "amuYzIJkCYmL5o6vh9KOQQAA5kU"]
[Thu Jul 30 13:32:44.327266 2026] [security2:error] [pid 890219:tid 890416] [client 74.248.33.8:32720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-configs.php"] [unique_id "amuYzIJkCYmL5o6vh9KORwAAAMc"]
[Thu Jul 30 13:32:44.603914 2026] [security2:error] [pid 890219:tid 890351] [client 68.221.186.136:6551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/img/about.php"] [unique_id "amuYzIJkCYmL5o6vh9KOSwAAAIY"]
[Thu Jul 30 13:32:44.606010 2026] [security2:error] [pid 890219:tid 890282] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin-heade.php"] [unique_id "amuYzIJkCYmL5o6vh9KOTAAAzT0"]
[Thu Jul 30 13:32:44.923442 2026] [security2:error] [pid 890219:tid 890298] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin-header.php"] [unique_id "amuYzIJkCYmL5o6vh9KOVwAAqE0"]
[Thu Jul 30 13:32:45.112156 2026] [core:notice] [pid 890219:tid 890364] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:45.183840 2026] [security2:error] [pid 890219:tid 890288] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin-post.php"] [unique_id "amuYzYJkCYmL5o6vh9KOWQAA-0M"]
[Thu Jul 30 13:32:45.447314 2026] [security2:error] [pid 890219:tid 890307] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin-wolf.php"] [unique_id "amuYzYJkCYmL5o6vh9KOYwAAoFY"]
[Thu Jul 30 13:32:45.722462 2026] [security2:error] [pid 890219:tid 890321] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin.php"] [unique_id "amuYzYJkCYmL5o6vh9KOZgAArGQ"]
[Thu Jul 30 13:32:45.787923 2026] [security2:error] [pid 890219:tid 890438] [client 74.248.33.8:43993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/php.php"] [unique_id "amuYzYJkCYmL5o6vh9KObAAAAN0"]
[Thu Jul 30 13:32:45.996029 2026] [security2:error] [pid 890219:tid 890302] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin1.php"] [unique_id "amuYzYJkCYmL5o6vh9KOdAAAj1E"]
[Thu Jul 30 13:32:46.085424 2026] [security2:error] [pid 890219:tid 890429] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuYzYJkCYmL5o6vh9KOZAAA1Bc"]
[Thu Jul 30 13:32:46.293887 2026] [security2:error] [pid 890219:tid 890311] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin403.php"] [unique_id "amuYzoJkCYmL5o6vh9KOegAA8lo"]
[Thu Jul 30 13:32:46.454779 2026] [security2:error] [pid 890219:tid 890394] [client 78.167.1.90:55691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYzoJkCYmL5o6vh9KOgQAAALE"]
[Thu Jul 30 13:32:46.455300 2026] [security2:error] [pid 890219:tid 890394] [client 78.167.1.90:55691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuYzoJkCYmL5o6vh9KOgQAAALE"]
[Thu Jul 30 13:32:46.478961 2026] [core:notice] [pid 890219:tid 890370] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:46.524309 2026] [security2:error] [pid 890219:tid 890425] [client 74.248.33.8:30390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/index.php"] [unique_id "amuYzoJkCYmL5o6vh9KOgwAAANA"]
[Thu Jul 30 13:32:46.564935 2026] [security2:error] [pid 890219:tid 890319] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin404.php"] [unique_id "amuYzoJkCYmL5o6vh9KOhAAAmmI"]
[Thu Jul 30 13:32:46.873782 2026] [security2:error] [pid 890219:tid 890248] [remote 47.128.34.241:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.onlinkfintech.com"] [uri "/robots.txt"] [unique_id "amuYzoJkCYmL5o6vh9KOiwAA3Bs"]
[Thu Jul 30 13:32:46.904757 2026] [security2:error] [pid 890219:tid 890305] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admin836.php"] [unique_id "amuYzoJkCYmL5o6vh9KOjAAAwlQ"]
[Thu Jul 30 13:32:47.212137 2026] [security2:error] [pid 890219:tid 890322] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminadmin.php"] [unique_id "amuYz4JkCYmL5o6vh9KOkgAA5mU"]
[Thu Jul 30 13:32:47.215816 2026] [security2:error] [pid 890219:tid 890309] [remote 152.53.111.131:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/wp-login.php"] [unique_id "amuYz4JkCYmL5o6vh9KOkQAA31g"]
[Thu Jul 30 13:32:47.250547 2026] [security2:error] [pid 890219:tid 890426] [client 68.221.186.136:8542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuYz4JkCYmL5o6vh9KOkwAAANE"]
[Thu Jul 30 13:32:47.554882 2026] [security2:error] [pid 890219:tid 890346] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminalfa.php"] [unique_id "amuYz4JkCYmL5o6vh9KOoQAA8X0"]
[Thu Jul 30 13:32:47.814041 2026] [core:notice] [pid 890219:tid 890315] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:47.858542 2026] [security2:error] [pid 890219:tid 890328] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminbypass.php"] [unique_id "amuYz4JkCYmL5o6vh9KOqwAA-2s"]
[Thu Jul 30 13:32:47.894225 2026] [security2:error] [pid 890219:tid 890401] [client 119.73.97.132:30298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuYzoJkCYmL5o6vh9KOkAAAuHk"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 13:32:48.140911 2026] [security2:error] [pid 890219:tid 890325] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminer.php"] [unique_id "amuY0IJkCYmL5o6vh9KOswAAvmg"]
[Thu Jul 30 13:32:48.181376 2026] [security2:error] [pid 890219:tid 890460] [client 74.248.33.8:18447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/a.php"] [unique_id "amuY0IJkCYmL5o6vh9KOtAAAAPM"]
[Thu Jul 30 13:32:48.399831 2026] [security2:error] [pid 890219:tid 890254] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminer/adminer.php"] [unique_id "amuY0IJkCYmL5o6vh9KOuAAAqSE"]
[Thu Jul 30 13:32:48.407088 2026] [core:notice] [pid 890219:tid 890332] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:48.612655 2026] [security2:error] [pid 890219:tid 890467] [client 68.221.186.136:8483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuY0IJkCYmL5o6vh9KOwQAAAPo"]
[Thu Jul 30 13:32:48.665853 2026] [security2:error] [pid 890219:tid 890340] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuY0IJkCYmL5o6vh9KOwgAAuXc"]
[Thu Jul 30 13:32:49.201375 2026] [security2:error] [pid 890219:tid 890335] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/administratoradmin.php"] [unique_id "amuY0IJkCYmL5o6vh9KOxgAA4HI"]
[Thu Jul 30 13:32:49.466658 2026] [security2:error] [pid 890219:tid 890347] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/administratoralfa.php"] [unique_id "amuY0YJkCYmL5o6vh9KO1AAA9X4"]
[Thu Jul 30 13:32:49.775868 2026] [security2:error] [pid 890219:tid 890344] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/administratorbypass.php"] [unique_id "amuY0YJkCYmL5o6vh9KO3QAAzXs"]
[Thu Jul 30 13:32:50.009917 2026] [security2:error] [pid 890219:tid 890374] [client 74.248.33.8:30395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/Text/about.php"] [unique_id "amuY0oJkCYmL5o6vh9KO6QAAAJ0"]
[Thu Jul 30 13:32:50.037291 2026] [security2:error] [pid 890219:tid 890260] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/administratork.php"] [unique_id "amuY0oJkCYmL5o6vh9KO6gAA_ic"]
[Thu Jul 30 13:32:50.299340 2026] [security2:error] [pid 890219:tid 890230] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/administratorwp.php"] [unique_id "amuY0oJkCYmL5o6vh9KO7wAAkQk"]
[Thu Jul 30 13:32:50.597189 2026] [security2:error] [pid 890219:tid 890241] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/admink.php"] [unique_id "amuY0oJkCYmL5o6vh9KO-QAA3RQ"]
[Thu Jul 30 13:32:50.857346 2026] [security2:error] [pid 890219:tid 890258] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminwebadmin.php"] [unique_id "amuY0oJkCYmL5o6vh9KPAwAA-SU"]
[Thu Jul 30 13:32:50.959537 2026] [security2:error] [pid 890219:tid 890427] [client 74.248.33.8:48430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin.php"] [unique_id "amuY0oJkCYmL5o6vh9KPBgAAANI"]
[Thu Jul 30 13:32:51.117675 2026] [security2:error] [pid 890219:tid 890316] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminwebalfa.php"] [unique_id "amuY04JkCYmL5o6vh9KPDgAA4F8"]
[Thu Jul 30 13:32:51.254411 2026] [fcgid:warn] [pid 890219:tid 890428] (70014)End of file found: [client 34.24.215.179:13096] mod_fcgid: can't get data from http client
[Thu Jul 30 13:32:51.391302 2026] [security2:error] [pid 890219:tid 890270] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/adminwebbypass.php"] [unique_id "amuY04JkCYmL5o6vh9KPFQAA5zE"]
[Thu Jul 30 13:32:51.540717 2026] [core:error] [pid 890219:tid 890462] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:51.540739 2026] [core:error] [pid 890219:tid 890462] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:51.687990 2026] [security2:error] [pid 890219:tid 890273] [remote 57.141.0.27:46184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuY04JkCYmL5o6vh9KPIQAArjQ"]
[Thu Jul 30 13:32:51.919275 2026] [core:notice] [pid 890219:tid 890234] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:51.921501 2026] [security2:error] [pid 890219:tid 890465] [client 74.7.244.20:59782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuY04JkCYmL5o6vh9KPIwAA-A0"], referer: https://insurancecouncilinc.com/
[Thu Jul 30 13:32:52.130196 2026] [core:notice] [pid 890219:tid 890237] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:52.132331 2026] [security2:error] [pid 890219:tid 890468] [client 74.7.244.20:59782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/category/politica/"] [unique_id "amuY1IJkCYmL5o6vh9KPKgAA-xA"], referer: https://www.nordeste1.com/category/policiais/
[Thu Jul 30 13:32:53.515861 2026] [core:error] [pid 890219:tid 890252] [remote 74.7.175.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:53.515889 2026] [core:error] [pid 890219:tid 890252] [remote 74.7.175.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:53.516119 2026] [security2:error] [pid 890219:tid 890394] [client 74.7.175.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.chimnify.services"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuY1YJkCYmL5o6vh9KPRwAAsR8"]
[Thu Jul 30 13:32:53.718302 2026] [security2:error] [pid 890219:tid 890444] [client 74.248.33.8:23487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/size.php"] [unique_id "amuY1YJkCYmL5o6vh9KPUQAAAOM"]
[Thu Jul 30 13:32:54.780323 2026] [security2:error] [pid 890219:tid 890375] [client 74.248.33.8:18721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/wp-class.php"] [unique_id "amuY1oJkCYmL5o6vh9KPZgAAAJ4"]
[Thu Jul 30 13:32:55.599568 2026] [core:notice] [pid 890219:tid 890434] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:55.749437 2026] [core:notice] [pid 890219:tid 890467] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:56.083655 2026] [security2:error] [pid 890219:tid 890464] [client 74.248.33.8:23436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/403.php"] [unique_id "amuY2IJkCYmL5o6vh9KPfwAAAPc"]
[Thu Jul 30 13:32:56.472763 2026] [security2:error] [pid 890219:tid 890353] [client 74.7.241.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amuY2IJkCYmL5o6vh9KPhQAAAIg"]
[Thu Jul 30 13:32:56.473713 2026] [security2:error] [pid 890219:tid 890392] [client 74.7.241.130:48896] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "skcarrental.ae"] [uri "/robots.txt"] [unique_id "amuY2IJkCYmL5o6vh9KPggAAr1A"]
[Thu Jul 30 13:32:57.051794 2026] [security2:error] [pid 890219:tid 890458] [client 78.167.1.90:54930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuY2YJkCYmL5o6vh9KPngAAAPE"]
[Thu Jul 30 13:32:57.052269 2026] [security2:error] [pid 890219:tid 890458] [client 78.167.1.90:54930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuY2YJkCYmL5o6vh9KPngAAAPE"]
[Thu Jul 30 13:32:57.768936 2026] [security2:error] [pid 890219:tid 890435] [client 68.221.186.136:6577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuY2YJkCYmL5o6vh9KPsQAAANo"]
[Thu Jul 30 13:32:58.728633 2026] [security2:error] [pid 890219:tid 890366] [client 74.248.33.8:30754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuY2oJkCYmL5o6vh9KPzAAAAJU"]
[Thu Jul 30 13:32:58.819373 2026] [fcgid:warn] [pid 890219:tid 890419] (70014)End of file found: [client 34.24.215.179:18024] mod_fcgid: can't get data from http client
[Thu Jul 30 13:32:59.003818 2026] [core:error] [pid 890219:tid 890364] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:59.003841 2026] [core:error] [pid 890219:tid 890364] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:32:59.028058 2026] [core:notice] [pid 890219:tid 890420] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:59.237690 2026] [core:notice] [pid 890219:tid 890416] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:32:59.425040 2026] [security2:error] [pid 890219:tid 890356] [client 74.248.33.8:43298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/as.php"] [unique_id "amuY24JkCYmL5o6vh9KP3wAAAIs"]
[Thu Jul 30 13:32:59.433871 2026] [security2:error] [pid 890219:tid 890373] [client 68.221.186.136:15183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuY24JkCYmL5o6vh9KP4QAAAJw"]
[Thu Jul 30 13:32:59.949847 2026] [security2:error] [pid 890219:tid 890395] [client 20.65.195.63:60720] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.6.43.58"] [uri "/index.cgi"] [unique_id "amuY24JkCYmL5o6vh9KP6wAAALI"]
[Thu Jul 30 13:32:59.955165 2026] [security2:error] [pid 890219:tid 890451] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuY24JkCYmL5o6vh9KP9QAAAOo"]
[Thu Jul 30 13:32:59.955285 2026] [security2:error] [pid 890219:tid 890451] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuY24JkCYmL5o6vh9KP9QAAAOo"]
[Thu Jul 30 13:33:00.430532 2026] [security2:error] [pid 890219:tid 890433] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuY24JkCYmL5o6vh9KP6gAAANg"]
[Thu Jul 30 13:33:00.569524 2026] [security2:error] [pid 890219:tid 890412] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuY3IJkCYmL5o6vh9KQCQAAAMM"]
[Thu Jul 30 13:33:00.569652 2026] [security2:error] [pid 890219:tid 890412] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuY3IJkCYmL5o6vh9KQCQAAAMM"]
[Thu Jul 30 13:33:00.646832 2026] [core:error] [pid 890219:tid 890437] [client 138.246.253.24:42266] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:00.646856 2026] [core:error] [pid 890219:tid 890437] [client 138.246.253.24:42266] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:01.143684 2026] [security2:error] [pid 890219:tid 890420] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wicked.php"] [unique_id "amuY3YJkCYmL5o6vh9KQGgAAAMs"]
[Thu Jul 30 13:33:01.143794 2026] [security2:error] [pid 890219:tid 890420] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wicked.php"] [unique_id "amuY3YJkCYmL5o6vh9KQGgAAAMs"]
[Thu Jul 30 13:33:01.193734 2026] [core:notice] [pid 890219:tid 890345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:01.468509 2026] [security2:error] [pid 890219:tid 890351] [client 68.221.186.136:21975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuY3YJkCYmL5o6vh9KQIgAAAIY"]
[Thu Jul 30 13:33:01.768191 2026] [security2:error] [pid 890219:tid 890463] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wpx.php"] [unique_id "amuY3YJkCYmL5o6vh9KQKwAAAPY"]
[Thu Jul 30 13:33:01.768305 2026] [security2:error] [pid 890219:tid 890463] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wpx.php"] [unique_id "amuY3YJkCYmL5o6vh9KQKwAAAPY"]
[Thu Jul 30 13:33:01.955688 2026] [core:error] [pid 890219:tid 890251] [remote 74.7.175.149:43348] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:01.955717 2026] [core:error] [pid 890219:tid 890251] [remote 74.7.175.149:43348] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:01.955956 2026] [security2:error] [pid 890219:tid 890362] [client 74.7.175.149:43348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-9bd961c9.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuY3YJkCYmL5o6vh9KQLAAAkR4"]
[Thu Jul 30 13:33:02.307514 2026] [security2:error] [pid 890219:tid 890448] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/images.php"] [unique_id "amuY3oJkCYmL5o6vh9KQOgAAAOc"]
[Thu Jul 30 13:33:02.307613 2026] [security2:error] [pid 890219:tid 890448] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/images.php"] [unique_id "amuY3oJkCYmL5o6vh9KQOgAAAOc"]
[Thu Jul 30 13:33:02.789330 2026] [security2:error] [pid 890219:tid 890424] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1xmomo.php"] [unique_id "amuY3oJkCYmL5o6vh9KQRQAAAM8"]
[Thu Jul 30 13:33:02.789493 2026] [security2:error] [pid 890219:tid 890424] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1xmomo.php"] [unique_id "amuY3oJkCYmL5o6vh9KQRQAAAM8"]
[Thu Jul 30 13:33:03.181553 2026] [authz_core:error] [pid 890219:tid 890458] [client 87.99.136.107:4762] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 13:33:03.327797 2026] [security2:error] [pid 890219:tid 890365] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1revo.php"] [unique_id "amuY34JkCYmL5o6vh9KQVAAAAJQ"]
[Thu Jul 30 13:33:03.327913 2026] [security2:error] [pid 890219:tid 890365] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1revo.php"] [unique_id "amuY34JkCYmL5o6vh9KQVAAAAJQ"]
[Thu Jul 30 13:33:03.364822 2026] [authz_core:error] [pid 890219:tid 890468] [client 87.99.136.107:44562] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 13:33:03.866727 2026] [security2:error] [pid 890219:tid 890429] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/cong.php"] [unique_id "amuY34JkCYmL5o6vh9KQaQAAANQ"]
[Thu Jul 30 13:33:03.866840 2026] [security2:error] [pid 890219:tid 890429] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/cong.php"] [unique_id "amuY34JkCYmL5o6vh9KQaQAAANQ"]
[Thu Jul 30 13:33:04.206352 2026] [authz_core:error] [pid 890219:tid 890436] [client 87.99.136.107:4812] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 13:33:04.238845 2026] [authz_core:error] [pid 890219:tid 890461] [client 87.99.136.107:4832] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 13:33:04.406193 2026] [authz_core:error] [pid 890219:tid 890411] [client 87.99.136.107:44604] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 13:33:04.431703 2026] [authz_core:error] [pid 890219:tid 890390] [client 87.99.136.107:44626] AH01630: client denied by server configuration: /home1/lomgzjte/public_html/web/.git
[Thu Jul 30 13:33:04.499023 2026] [security2:error] [pid 890219:tid 890428] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/a.php"] [unique_id "amuY4IJkCYmL5o6vh9KQewAAANM"]
[Thu Jul 30 13:33:04.499135 2026] [security2:error] [pid 890219:tid 890428] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/a.php"] [unique_id "amuY4IJkCYmL5o6vh9KQewAAANM"]
[Thu Jul 30 13:33:04.733801 2026] [security2:error] [pid 890219:tid 890452] [client 68.221.186.136:15228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuY4IJkCYmL5o6vh9KQggAAAOs"]
[Thu Jul 30 13:33:05.107832 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/srontol.php"] [unique_id "amuY4YJkCYmL5o6vh9KQhwAAAMk"]
[Thu Jul 30 13:33:05.107948 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/srontol.php"] [unique_id "amuY4YJkCYmL5o6vh9KQhwAAAMk"]
[Thu Jul 30 13:33:05.132673 2026] [security2:error] [pid 890219:tid 890447] [client 147.90.227.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/web/xmlrpc.php"] [unique_id "amuY4YJkCYmL5o6vh9KQiAAAAOY"]
[Thu Jul 30 13:33:05.644274 2026] [security2:error] [pid 890219:tid 890365] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/reop3.php"] [unique_id "amuY4YJkCYmL5o6vh9KQlAAAAJQ"]
[Thu Jul 30 13:33:05.644379 2026] [security2:error] [pid 890219:tid 890365] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/reop3.php"] [unique_id "amuY4YJkCYmL5o6vh9KQlAAAAJQ"]
[Thu Jul 30 13:33:05.657615 2026] [security2:error] [pid 890219:tid 890471] [client 68.221.186.136:4521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuY4YJkCYmL5o6vh9KQlgAAAP4"]
[Thu Jul 30 13:33:05.751553 2026] [security2:error] [pid 890219:tid 890252] [remote 147.90.227.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/old/xmlrpc.php"] [unique_id "amuY4YJkCYmL5o6vh9KQnAAAsx8"]
[Thu Jul 30 13:33:05.944949 2026] [security2:error] [pid 890219:tid 890416] [client 147.90.227.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/OLD//xmlrpc.php"] [unique_id "amuY4YJkCYmL5o6vh9KQnwAAAMc"]
[Thu Jul 30 13:33:05.959571 2026] [security2:error] [pid 890219:tid 890477] [client 147.90.227.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/backup/xmlrpc.php"] [unique_id "amuY4YJkCYmL5o6vh9KQoAAAAQQ"]
[Thu Jul 30 13:33:05.961079 2026] [security2:error] [pid 890219:tid 890450] [client 147.90.227.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/core/xmlrpc.php"] [unique_id "amuY4YJkCYmL5o6vh9KQoQAAAOk"]
[Thu Jul 30 13:33:05.970755 2026] [security2:error] [pid 890219:tid 890354] [client 147.90.227.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/dev/xmlrpc.php"] [unique_id "amuY4YJkCYmL5o6vh9KQogAAAIk"]
[Thu Jul 30 13:33:05.974576 2026] [security2:error] [pid 890219:tid 890443] [client 147.90.227.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "amuY4YJkCYmL5o6vh9KQowAAAOI"]
[Thu Jul 30 13:33:05.994364 2026] [security2:error] [pid 890219:tid 890434] [client 147.90.227.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/cms/xmlrpc.php"] [unique_id "amuY4YJkCYmL5o6vh9KQpAAAANk"]
[Thu Jul 30 13:33:06.006566 2026] [security2:error] [pid 890219:tid 890463] [client 147.90.227.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/prod/xmlrpc.php"] [unique_id "amuY4oJkCYmL5o6vh9KQpgAAAPY"]
[Thu Jul 30 13:33:06.147535 2026] [security2:error] [pid 890219:tid 890372] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file5.php"] [unique_id "amuY4oJkCYmL5o6vh9KQpwAAAJs"]
[Thu Jul 30 13:33:06.147646 2026] [security2:error] [pid 890219:tid 890372] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file5.php"] [unique_id "amuY4oJkCYmL5o6vh9KQpwAAAJs"]
[Thu Jul 30 13:33:06.402910 2026] [security2:error] [pid 890219:tid 890472] [client 185.191.171.5:22268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/07/guilherme-boulos-e-presidente-do-psol-vao-integrar-equipe-de-transicao-de-lula/"] [unique_id "amuY4oJkCYmL5o6vh9KQsgAAAP8"]
[Thu Jul 30 13:33:06.403093 2026] [security2:error] [pid 890219:tid 890472] [client 185.191.171.5:22268] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/07/guilherme-boulos-e-presidente-do-psol-vao-integrar-equipe-de-transicao-de-lula/"] [unique_id "amuY4oJkCYmL5o6vh9KQsgAAAP8"]
[Thu Jul 30 13:33:06.666900 2026] [security2:error] [pid 890219:tid 890469] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/domvf.php"] [unique_id "amuY4oJkCYmL5o6vh9KQswAAAPw"]
[Thu Jul 30 13:33:06.667033 2026] [security2:error] [pid 890219:tid 890469] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/domvf.php"] [unique_id "amuY4oJkCYmL5o6vh9KQswAAAPw"]
[Thu Jul 30 13:33:06.689556 2026] [core:notice] [pid 890219:tid 890371] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:06.816801 2026] [core:error] [pid 890219:tid 890387] [client 34.24.215.179:46296] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Jul 30 13:33:06.829700 2026] [core:error] [pid 890219:tid 890425] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:06.829721 2026] [core:error] [pid 890219:tid 890425] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:06.842048 2026] [security2:error] [pid 890219:tid 890444] [client 34.24.215.179:46302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/?\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuY4oJkCYmL5o6vh9KQwAAAAOM"]
[Thu Jul 30 13:33:06.842154 2026] [security2:error] [pid 890219:tid 890444] [client 34.24.215.179:46302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuY4oJkCYmL5o6vh9KQwAAAAOM"]
[Thu Jul 30 13:33:06.977884 2026] [security2:error] [pid 890219:tid 890438] [client 66.249.73.65:42038] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/robots.txt"] [unique_id "amuY4oJkCYmL5o6vh9KQwgAAAN0"]
[Thu Jul 30 13:33:06.989741 2026] [security2:error] [pid 890219:tid 890358] [client 68.221.186.136:21957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuY4oJkCYmL5o6vh9KQwwAAAI0"]
[Thu Jul 30 13:33:07.220680 2026] [security2:error] [pid 890219:tid 890374] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zero.php"] [unique_id "amuY44JkCYmL5o6vh9KQxQAAAJ0"]
[Thu Jul 30 13:33:07.220821 2026] [security2:error] [pid 890219:tid 890374] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zero.php"] [unique_id "amuY44JkCYmL5o6vh9KQxQAAAJ0"]
[Thu Jul 30 13:33:07.426427 2026] [security2:error] [pid 890219:tid 890454] [client 134.19.179.131:36116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuY44JkCYmL5o6vh9KQ1AAAAO0"]
[Thu Jul 30 13:33:07.426526 2026] [security2:error] [pid 890219:tid 890454] [client 134.19.179.131:36116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuY44JkCYmL5o6vh9KQ1AAAAO0"]
[Thu Jul 30 13:33:07.679243 2026] [security2:error] [pid 890219:tid 890474] [client 78.167.1.90:55838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuY44JkCYmL5o6vh9KQ1gAAAQE"]
[Thu Jul 30 13:33:07.679821 2026] [security2:error] [pid 890219:tid 890474] [client 78.167.1.90:55838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuY44JkCYmL5o6vh9KQ1gAAAQE"]
[Thu Jul 30 13:33:07.795609 2026] [security2:error] [pid 890219:tid 890439] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/002.php"] [unique_id "amuY44JkCYmL5o6vh9KQ3QAAAN4"]
[Thu Jul 30 13:33:07.795753 2026] [security2:error] [pid 890219:tid 890439] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/002.php"] [unique_id "amuY44JkCYmL5o6vh9KQ3QAAAN4"]
[Thu Jul 30 13:33:07.922149 2026] [security2:error] [pid 890219:tid 890383] [client 74.248.33.8:32828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/includes/index.php"] [unique_id "amuY44JkCYmL5o6vh9KQ5gAAAKY"]
[Thu Jul 30 13:33:08.222922 2026] [core:notice] [pid 890219:tid 890307] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:08.238165 2026] [security2:error] [pid 890219:tid 890376] [client 66.249.73.64:41694] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/product-tag/mevius\\xe4\\xb8\\x83\\xe6\\x98\\x9f\\xe9\\xa6\\x99\\xe7\\x85\\x993mg\\xe6\\x97\\xa5\\xe6\\x9c\\xac\\xe6\\x9c\\xac\\xe5\\x9c\\x9f\\xe5\\x85\\x8d\\xe7\\xa8\\x85\\xe9\\xa6\\x99\\xe6\\xb8\\xaf\\xe7\\x8f\\xbe\\xe8\\xb2\\xa8/feed/"] [unique_id "amuY5IJkCYmL5o6vh9KQ6QAAAJ8"]
[Thu Jul 30 13:33:08.444734 2026] [security2:error] [pid 890219:tid 890356] [client 68.221.186.136:12530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuY5IJkCYmL5o6vh9KQ8wAAAIs"]
[Thu Jul 30 13:33:08.529603 2026] [security2:error] [pid 890219:tid 890350] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/thoms.php"] [unique_id "amuY5IJkCYmL5o6vh9KQ9AAAAIU"]
[Thu Jul 30 13:33:08.529706 2026] [security2:error] [pid 890219:tid 890350] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/thoms.php"] [unique_id "amuY5IJkCYmL5o6vh9KQ9AAAAIU"]
[Thu Jul 30 13:33:08.708114 2026] [core:notice] [pid 890219:tid 890433] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:09.070817 2026] [security2:error] [pid 890219:tid 890400] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fi22.php"] [unique_id "amuY5YJkCYmL5o6vh9KRBAAAALc"]
[Thu Jul 30 13:33:09.070936 2026] [security2:error] [pid 890219:tid 890400] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fi22.php"] [unique_id "amuY5YJkCYmL5o6vh9KRBAAAALc"]
[Thu Jul 30 13:33:09.169796 2026] [security2:error] [pid 890219:tid 890461] [client 74.248.33.8:33367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuY5YJkCYmL5o6vh9KRBQAAAPQ"]
[Thu Jul 30 13:33:09.303489 2026] [security2:error] [pid 890219:tid 890359] [client 68.221.186.136:21955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuY5YJkCYmL5o6vh9KRBgAAAI4"]
[Thu Jul 30 13:33:09.588598 2026] [security2:error] [pid 890219:tid 890365] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuY5YJkCYmL5o6vh9KREgAAAJQ"]
[Thu Jul 30 13:33:09.740904 2026] [security2:error] [pid 890219:tid 890421] [client 20.104.18.253:39434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/011i.php"] [unique_id "amuY5YJkCYmL5o6vh9KREwAAAMw"]
[Thu Jul 30 13:33:09.866176 2026] [security2:error] [pid 890219:tid 890406] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuY5YJkCYmL5o6vh9KRFwAAAL0"]
[Thu Jul 30 13:33:10.130872 2026] [security2:error] [pid 890219:tid 890439] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/82.php"] [unique_id "amuY5oJkCYmL5o6vh9KRHgAAAN4"]
[Thu Jul 30 13:33:10.131045 2026] [security2:error] [pid 890219:tid 890439] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/82.php"] [unique_id "amuY5oJkCYmL5o6vh9KRHgAAAN4"]
[Thu Jul 30 13:33:10.626708 2026] [security2:error] [pid 890219:tid 890451] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sx.php"] [unique_id "amuY5oJkCYmL5o6vh9KRKQAAAOo"]
[Thu Jul 30 13:33:10.626832 2026] [security2:error] [pid 890219:tid 890451] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sx.php"] [unique_id "amuY5oJkCYmL5o6vh9KRKQAAAOo"]
[Thu Jul 30 13:33:10.634804 2026] [security2:error] [pid 890219:tid 890471] [client 74.248.33.8:64384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/plugins.php"] [unique_id "amuY5oJkCYmL5o6vh9KRKgAAAP4"]
[Thu Jul 30 13:33:10.774702 2026] [core:notice] [pid 890219:tid 890392] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:11.062683 2026] [security2:error] [pid 890219:tid 890409] [client 68.221.186.136:9986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuY54JkCYmL5o6vh9KROQAAAMA"]
[Thu Jul 30 13:33:11.123712 2026] [security2:error] [pid 890219:tid 890375] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/dex.php"] [unique_id "amuY54JkCYmL5o6vh9KROwAAAJ4"]
[Thu Jul 30 13:33:11.123818 2026] [security2:error] [pid 890219:tid 890375] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/dex.php"] [unique_id "amuY54JkCYmL5o6vh9KROwAAAJ4"]
[Thu Jul 30 13:33:11.253746 2026] [security2:error] [pid 890219:tid 890356] [client 34.24.215.179:46318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "/Util/PHP/eval-stdin\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1510"] [id "900414"] [msg "block PHPUnit eval-stdin.php"] [hostname "cpanel.kbaagency.com"] [uri "/___proxy_subdomain_cpanel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuY54JkCYmL5o6vh9KRPAAAAIs"]
[Thu Jul 30 13:33:11.272887 2026] [security2:error] [pid 890219:tid 890378] [client 20.104.18.253:39433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/03a005685d.php"] [unique_id "amuY54JkCYmL5o6vh9KRPQAAAKE"]
[Thu Jul 30 13:33:11.455831 2026] [proxy:error] [pid 890219:tid 890353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:11.455915 2026] [proxy_http:error] [pid 890219:tid 890353] [client 44.213.206.96:14783] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:11.456758 2026] [proxy:error] [pid 890219:tid 890353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:11.456817 2026] [proxy_http:error] [pid 890219:tid 890353] [client 44.213.206.96:14783] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:11.456895 2026] [proxy:error] [pid 890219:tid 890457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:11.456949 2026] [proxy_http:error] [pid 890219:tid 890457] [client 44.213.206.96:6454] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:11.457513 2026] [proxy:error] [pid 890219:tid 890457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:11.457559 2026] [proxy_http:error] [pid 890219:tid 890457] [client 44.213.206.96:6454] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:11.493634 2026] [core:error] [pid 890219:tid 890389] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:11.493668 2026] [core:error] [pid 890219:tid 890389] [client 34.24.215.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:11.555773 2026] [security2:error] [pid 890219:tid 890404] [client 34.24.215.179:46326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.kbaagency.com"] [uri "/%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22id%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Gscan%22%2C%23a%29%29%7D/"] [unique_id "amuY54JkCYmL5o6vh9KRUQAAALs"]
[Thu Jul 30 13:33:11.555874 2026] [security2:error] [pid 890219:tid 890404] [client 34.24.215.179:46326] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.kbaagency.com"] [uri "/%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22id%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Gscan%22%2C%23a%29%29%7D/"] [unique_id "amuY54JkCYmL5o6vh9KRUQAAALs"]
[Thu Jul 30 13:33:11.632152 2026] [security2:error] [pid 890219:tid 890393] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fpwch.php"] [unique_id "amuY54JkCYmL5o6vh9KRVwAAALA"]
[Thu Jul 30 13:33:11.632248 2026] [security2:error] [pid 890219:tid 890393] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fpwch.php"] [unique_id "amuY54JkCYmL5o6vh9KRVwAAALA"]
[Thu Jul 30 13:33:12.115044 2026] [security2:error] [pid 890219:tid 890421] [client 68.221.186.136:13183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuY6IJkCYmL5o6vh9KRXgAAAMw"]
[Thu Jul 30 13:33:12.172335 2026] [security2:error] [pid 890219:tid 890444] [client 74.248.33.8:35747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/js/index.php"] [unique_id "amuY6IJkCYmL5o6vh9KRYgAAAOM"]
[Thu Jul 30 13:33:12.230333 2026] [security2:error] [pid 890219:tid 890431] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/black.php"] [unique_id "amuY6IJkCYmL5o6vh9KRYwAAANY"]
[Thu Jul 30 13:33:12.230450 2026] [security2:error] [pid 890219:tid 890431] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/black.php"] [unique_id "amuY6IJkCYmL5o6vh9KRYwAAANY"]
[Thu Jul 30 13:33:12.244520 2026] [security2:error] [pid 890219:tid 890423] [client 20.104.18.253:29115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/403.php"] [unique_id "amuY6IJkCYmL5o6vh9KRZAAAAM4"]
[Thu Jul 30 13:33:12.707638 2026] [security2:error] [pid 890219:tid 890432] [client 68.221.186.136:13144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuY6IJkCYmL5o6vh9KRfgAAANc"]
[Thu Jul 30 13:33:12.756808 2026] [security2:error] [pid 890219:tid 890356] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/loader.php"] [unique_id "amuY6IJkCYmL5o6vh9KRfwAAAIs"]
[Thu Jul 30 13:33:12.756906 2026] [security2:error] [pid 890219:tid 890356] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/loader.php"] [unique_id "amuY6IJkCYmL5o6vh9KRfwAAAIs"]
[Thu Jul 30 13:33:12.795379 2026] [security2:error] [pid 890219:tid 890442] [client 74.7.230.27:33318] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoverspackers.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuY6IJkCYmL5o6vh9KRgAAAAOE"]
[Thu Jul 30 13:33:13.006114 2026] [security2:error] [pid 890219:tid 890427] [client 74.248.33.8:31904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/go.php"] [unique_id "amuY6YJkCYmL5o6vh9KRggAAANI"]
[Thu Jul 30 13:33:13.231821 2026] [security2:error] [pid 890219:tid 890387] [client 74.7.175.157:55426] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.hhmoaf.org"] [uri "/cgi-sys/404.html"] [unique_id "amuY6YJkCYmL5o6vh9KRjAAAqn8"]
[Thu Jul 30 13:33:13.297698 2026] [security2:error] [pid 890219:tid 890426] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file61.php"] [unique_id "amuY6YJkCYmL5o6vh9KRjQAAANE"]
[Thu Jul 30 13:33:13.298058 2026] [security2:error] [pid 890219:tid 890426] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file61.php"] [unique_id "amuY6YJkCYmL5o6vh9KRjQAAANE"]
[Thu Jul 30 13:33:13.666604 2026] [security2:error] [pid 890219:tid 890400] [client 68.221.186.136:4500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/images/about.php"] [unique_id "amuY6YJkCYmL5o6vh9KRmQAAALc"]
[Thu Jul 30 13:33:13.706469 2026] [security2:error] [pid 890219:tid 890401] [client 185.189.112.19:37708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuY6YJkCYmL5o6vh9KRmgAAALg"]
[Thu Jul 30 13:33:13.706574 2026] [security2:error] [pid 890219:tid 890401] [client 185.189.112.19:37708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuY6YJkCYmL5o6vh9KRmgAAALg"]
[Thu Jul 30 13:33:13.805083 2026] [security2:error] [pid 890219:tid 890402] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-css.php"] [unique_id "amuY6YJkCYmL5o6vh9KRmwAAALk"]
[Thu Jul 30 13:33:13.805235 2026] [security2:error] [pid 890219:tid 890402] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-css.php"] [unique_id "amuY6YJkCYmL5o6vh9KRmwAAALk"]
[Thu Jul 30 13:33:14.093838 2026] [autoindex:error] [pid 890219:tid 890232] [remote 74.7.241.36:55926] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:33:14.152789 2026] [security2:error] [pid 890219:tid 890439] [client 74.248.33.8:64410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/aaa.php"] [unique_id "amuY6oJkCYmL5o6vh9KRowAAAN4"]
[Thu Jul 30 13:33:14.326042 2026] [security2:error] [pid 890219:tid 890434] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-blink.php"] [unique_id "amuY6oJkCYmL5o6vh9KRpwAAANk"]
[Thu Jul 30 13:33:14.326163 2026] [security2:error] [pid 890219:tid 890434] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-blink.php"] [unique_id "amuY6oJkCYmL5o6vh9KRpwAAANk"]
[Thu Jul 30 13:33:14.841717 2026] [security2:error] [pid 890219:tid 890372] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/txets.php"] [unique_id "amuY6oJkCYmL5o6vh9KRrQAAAJs"]
[Thu Jul 30 13:33:14.841829 2026] [security2:error] [pid 890219:tid 890372] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/txets.php"] [unique_id "amuY6oJkCYmL5o6vh9KRrQAAAJs"]
[Thu Jul 30 13:33:15.399561 2026] [security2:error] [pid 890219:tid 890432] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/pucci.php"] [unique_id "amuY64JkCYmL5o6vh9KRvAAAANc"]
[Thu Jul 30 13:33:15.399687 2026] [security2:error] [pid 890219:tid 890432] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/pucci.php"] [unique_id "amuY64JkCYmL5o6vh9KRvAAAANc"]
[Thu Jul 30 13:33:15.485442 2026] [security2:error] [pid 890219:tid 890469] [client 74.248.33.8:31517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/getid3-core.php"] [unique_id "amuY64JkCYmL5o6vh9KRwAAAAPw"]
[Thu Jul 30 13:33:15.930401 2026] [security2:error] [pid 890219:tid 890379] [client 20.104.18.253:36233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/404.php"] [unique_id "amuY64JkCYmL5o6vh9KRxwAAAKI"]
[Thu Jul 30 13:33:15.982640 2026] [security2:error] [pid 890219:tid 890355] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xwpg.php"] [unique_id "amuY64JkCYmL5o6vh9KRygAAAIo"]
[Thu Jul 30 13:33:15.982727 2026] [security2:error] [pid 890219:tid 890355] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xwpg.php"] [unique_id "amuY64JkCYmL5o6vh9KRygAAAIo"]
[Thu Jul 30 13:33:16.200230 2026] [core:error] [pid 890219:tid 890452] [client 34.24.215.179:43038] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:16.200263 2026] [core:error] [pid 890219:tid 890452] [client 34.24.215.179:43038] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:16.250577 2026] [security2:error] [pid 890219:tid 890445] [client 74.248.33.8:13634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/adminer.php"] [unique_id "amuY7IJkCYmL5o6vh9KR0QAAAOQ"]
[Thu Jul 30 13:33:16.536469 2026] [security2:error] [pid 890219:tid 890366] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ops.php"] [unique_id "amuY7IJkCYmL5o6vh9KR3gAAAJU"]
[Thu Jul 30 13:33:16.536575 2026] [security2:error] [pid 890219:tid 890366] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ops.php"] [unique_id "amuY7IJkCYmL5o6vh9KR3gAAAJU"]
[Thu Jul 30 13:33:17.024704 2026] [security2:error] [pid 890219:tid 890474] [client 52.165.196.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuY7YJkCYmL5o6vh9KR7AAAAQE"]
[Thu Jul 30 13:33:17.024810 2026] [security2:error] [pid 890219:tid 890474] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuY7YJkCYmL5o6vh9KR7AAAAQE"]
[Thu Jul 30 13:33:17.024892 2026] [security2:error] [pid 890219:tid 890474] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuY7YJkCYmL5o6vh9KR7AAAAQE"]
[Thu Jul 30 13:33:17.436656 2026] [security2:error] [pid 890219:tid 890376] [client 74.248.33.8:64388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/maint/index.php"] [unique_id "amuY7YJkCYmL5o6vh9KR9gAAAJ8"]
[Thu Jul 30 13:33:17.535032 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuY7YJkCYmL5o6vh9KR-AAAAKs"]
[Thu Jul 30 13:33:17.535129 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuY7YJkCYmL5o6vh9KR-AAAAKs"]
[Thu Jul 30 13:33:18.035049 2026] [security2:error] [pid 890219:tid 890473] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuY7oJkCYmL5o6vh9KSCQAAAQA"]
[Thu Jul 30 13:33:18.035153 2026] [security2:error] [pid 890219:tid 890473] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuY7oJkCYmL5o6vh9KSCQAAAQA"]
[Thu Jul 30 13:33:18.172954 2026] [security2:error] [pid 890219:tid 890443] [client 43.157.158.178:52044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.158.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/xmlrpc.php"] [unique_id "amuY7YJkCYmL5o6vh9KR_wAAAOI"]
[Thu Jul 30 13:33:18.234491 2026] [security2:error] [pid 890219:tid 890457] [client 78.167.1.90:57007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuY7oJkCYmL5o6vh9KSEwAAAPA"]
[Thu Jul 30 13:33:18.234607 2026] [security2:error] [pid 890219:tid 890457] [client 78.167.1.90:57007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuY7oJkCYmL5o6vh9KSEwAAAPA"]
[Thu Jul 30 13:33:18.482595 2026] [security2:error] [pid 890219:tid 890425] [client 20.104.18.253:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/aa.php"] [unique_id "amuY7oJkCYmL5o6vh9KSFwAAANA"]
[Thu Jul 30 13:33:18.661638 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuY7oJkCYmL5o6vh9KSHwAAAMk"]
[Thu Jul 30 13:33:18.661744 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuY7oJkCYmL5o6vh9KSHwAAAMk"]
[Thu Jul 30 13:33:18.668135 2026] [security2:error] [pid 890219:tid 890385] [client 74.248.33.8:64362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/alfa.php"] [unique_id "amuY7oJkCYmL5o6vh9KSIAAAAKg"]
[Thu Jul 30 13:33:19.225659 2026] [security2:error] [pid 890219:tid 890420] [client 20.104.18.253:38451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/aafewc0k.php"] [unique_id "amuY74JkCYmL5o6vh9KSNQAAAMs"]
[Thu Jul 30 13:33:19.248056 2026] [core:notice] [pid 890219:tid 890289] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:19.275868 2026] [security2:error] [pid 890219:tid 890376] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xyn.php"] [unique_id "amuY74JkCYmL5o6vh9KSOAAAAJ8"]
[Thu Jul 30 13:33:19.275960 2026] [security2:error] [pid 890219:tid 890376] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xyn.php"] [unique_id "amuY74JkCYmL5o6vh9KSOAAAAJ8"]
[Thu Jul 30 13:33:19.387886 2026] [security2:error] [pid 890219:tid 890416] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuY74JkCYmL5o6vh9KSKgAAAMc"]
[Thu Jul 30 13:33:19.859750 2026] [security2:error] [pid 890219:tid 890404] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-wp.php"] [unique_id "amuY74JkCYmL5o6vh9KSSAAAALs"]
[Thu Jul 30 13:33:19.859865 2026] [security2:error] [pid 890219:tid 890404] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-wp.php"] [unique_id "amuY74JkCYmL5o6vh9KSSAAAALs"]
[Thu Jul 30 13:33:20.331189 2026] [security2:error] [pid 890219:tid 890368] [client 68.221.186.136:12500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuY8IJkCYmL5o6vh9KSUQAAAJc"]
[Thu Jul 30 13:33:20.586194 2026] [security2:error] [pid 890219:tid 890393] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/aw.php"] [unique_id "amuY8IJkCYmL5o6vh9KSVAAAALA"]
[Thu Jul 30 13:33:20.586311 2026] [security2:error] [pid 890219:tid 890393] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/aw.php"] [unique_id "amuY8IJkCYmL5o6vh9KSVAAAALA"]
[Thu Jul 30 13:33:20.812968 2026] [security2:error] [pid 890219:tid 890363] [client 57.141.0.67:35200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuY7oJkCYmL5o6vh9KSJQAAkkY"]
[Thu Jul 30 13:33:20.814373 2026] [security2:error] [pid 890219:tid 890402] [client 74.248.33.8:13805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuY8IJkCYmL5o6vh9KSYQAAALk"]
[Thu Jul 30 13:33:20.971377 2026] [security2:error] [pid 890219:tid 890454] [client 68.221.186.136:8475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuY8IJkCYmL5o6vh9KSZgAAAO0"]
[Thu Jul 30 13:33:21.210047 2026] [security2:error] [pid 890219:tid 890423] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuY8YJkCYmL5o6vh9KSawAAAM4"]
[Thu Jul 30 13:33:21.210188 2026] [security2:error] [pid 890219:tid 890423] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuY8YJkCYmL5o6vh9KSawAAAM4"]
[Thu Jul 30 13:33:21.557887 2026] [core:notice] [pid 890219:tid 890323] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:21.801550 2026] [security2:error] [pid 890219:tid 890468] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yawa.php"] [unique_id "amuY8YJkCYmL5o6vh9KSegAAAPs"]
[Thu Jul 30 13:33:21.801667 2026] [security2:error] [pid 890219:tid 890468] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yawa.php"] [unique_id "amuY8YJkCYmL5o6vh9KSegAAAPs"]
[Thu Jul 30 13:33:22.177097 2026] [security2:error] [pid 890219:tid 890449] [client 20.104.18.253:53857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/abcd.php"] [unique_id "amuY8oJkCYmL5o6vh9KShQAAAOg"]
[Thu Jul 30 13:33:22.346282 2026] [security2:error] [pid 890219:tid 890404] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sym403.php"] [unique_id "amuY8oJkCYmL5o6vh9KSiQAAALs"]
[Thu Jul 30 13:33:22.346393 2026] [security2:error] [pid 890219:tid 890404] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sym403.php"] [unique_id "amuY8oJkCYmL5o6vh9KSiQAAALs"]
[Thu Jul 30 13:33:22.859781 2026] [security2:error] [pid 890219:tid 890393] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuY8oJkCYmL5o6vh9KSkwAAALA"]
[Thu Jul 30 13:33:23.114189 2026] [security2:error] [pid 890219:tid 890366] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuY84JkCYmL5o6vh9KSngAAAJU"]
[Thu Jul 30 13:33:23.204994 2026] [security2:error] [pid 890219:tid 890356] [client 74.248.33.8:64711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuY84JkCYmL5o6vh9KSogAAAIs"]
[Thu Jul 30 13:33:23.429053 2026] [security2:error] [pid 890219:tid 890373] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/adminner.php"] [unique_id "amuY84JkCYmL5o6vh9KSowAAAJw"]
[Thu Jul 30 13:33:23.429213 2026] [security2:error] [pid 890219:tid 890373] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/adminner.php"] [unique_id "amuY84JkCYmL5o6vh9KSowAAAJw"]
[Thu Jul 30 13:33:23.595895 2026] [security2:error] [pid 890219:tid 890427] [client 172.237.109.114:45388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuY8oJkCYmL5o6vh9KSlQAAANI"]
[Thu Jul 30 13:33:23.675085 2026] [proxy:error] [pid 890219:tid 890474] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:23.675165 2026] [proxy_http:error] [pid 890219:tid 890474] [client 143.244.57.82:37218] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:23.675757 2026] [proxy:error] [pid 890219:tid 890474] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:23.675800 2026] [proxy_http:error] [pid 890219:tid 890474] [client 143.244.57.82:37218] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:23.755926 2026] [security2:error] [pid 890219:tid 890452] [client 20.104.18.253:46278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/about.php"] [unique_id "amuY84JkCYmL5o6vh9KSrgAAAOs"]
[Thu Jul 30 13:33:23.961132 2026] [security2:error] [pid 890219:tid 890376] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yup.php"] [unique_id "amuY84JkCYmL5o6vh9KSsQAAAJ8"]
[Thu Jul 30 13:33:23.961284 2026] [security2:error] [pid 890219:tid 890376] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yup.php"] [unique_id "amuY84JkCYmL5o6vh9KSsQAAAJ8"]
[Thu Jul 30 13:33:23.975685 2026] [proxy:error] [pid 890219:tid 890397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:23.975760 2026] [proxy_http:error] [pid 890219:tid 890397] [client 143.244.57.82:37224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:23.976584 2026] [proxy:error] [pid 890219:tid 890397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:23.976636 2026] [proxy_http:error] [pid 890219:tid 890397] [client 143.244.57.82:37224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:24.199927 2026] [autoindex:error] [pid 890219:tid 890472] [client 18.211.55.47:29320] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_9bd961c9/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:33:24.271996 2026] [security2:error] [pid 890219:tid 890464] [client 143.244.57.82:37238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuY9IJkCYmL5o6vh9KSwAAAAPc"]
[Thu Jul 30 13:33:24.500774 2026] [security2:error] [pid 890219:tid 890389] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/config.json.php"] [unique_id "amuY9IJkCYmL5o6vh9KSywAAAKw"]
[Thu Jul 30 13:33:24.500882 2026] [security2:error] [pid 890219:tid 890389] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/config.json.php"] [unique_id "amuY9IJkCYmL5o6vh9KSywAAAKw"]
[Thu Jul 30 13:33:24.549682 2026] [proxy:error] [pid 890219:tid 890404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:24.549745 2026] [proxy_http:error] [pid 890219:tid 890404] [client 143.244.57.82:37242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:24.550330 2026] [proxy:error] [pid 890219:tid 890404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:24.550375 2026] [proxy_http:error] [pid 890219:tid 890404] [client 143.244.57.82:37242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:24.830954 2026] [security2:error] [pid 890219:tid 890419] [client 143.244.57.82:37248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuY9IJkCYmL5o6vh9KS1wAAAMo"]
[Thu Jul 30 13:33:24.971384 2026] [security2:error] [pid 890219:tid 890455] [client 68.221.186.136:8498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/about.php"] [unique_id "amuY9IJkCYmL5o6vh9KS2QAAAO4"]
[Thu Jul 30 13:33:25.032067 2026] [security2:error] [pid 890219:tid 890393] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuY9YJkCYmL5o6vh9KS2gAAALA"]
[Thu Jul 30 13:33:25.110726 2026] [security2:error] [pid 890219:tid 890418] [client 143.244.57.82:37258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuY9YJkCYmL5o6vh9KS3gAAAMk"]
[Thu Jul 30 13:33:25.120506 2026] [proxy:error] [pid 890219:tid 890395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:25.120577 2026] [proxy_http:error] [pid 890219:tid 890395] [client 18.211.55.47:55537] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:25.121199 2026] [proxy:error] [pid 890219:tid 890395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:25.121255 2026] [proxy_http:error] [pid 890219:tid 890395] [client 18.211.55.47:55537] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:25.127078 2026] [proxy:error] [pid 890219:tid 890400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:25.127145 2026] [proxy_http:error] [pid 890219:tid 890400] [client 44.216.125.112:5911] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:25.127769 2026] [proxy:error] [pid 890219:tid 890400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:25.127819 2026] [proxy_http:error] [pid 890219:tid 890400] [client 44.216.125.112:5911] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:25.339392 2026] [security2:error] [pid 890219:tid 890441] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuY9YJkCYmL5o6vh9KTAwAAAOA"]
[Thu Jul 30 13:33:25.396513 2026] [security2:error] [pid 890219:tid 890382] [client 143.244.57.82:37262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuY9YJkCYmL5o6vh9KTBAAAAKU"]
[Thu Jul 30 13:33:25.607931 2026] [security2:error] [pid 890219:tid 890390] [client 68.221.186.136:21989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/cgi-bin/about.php"] [unique_id "amuY9YJkCYmL5o6vh9KTCwAAAK0"]
[Thu Jul 30 13:33:25.621931 2026] [security2:error] [pid 890219:tid 890370] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2.php"] [unique_id "amuY9YJkCYmL5o6vh9KTDAAAAJk"]
[Thu Jul 30 13:33:25.622055 2026] [security2:error] [pid 890219:tid 890370] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2.php"] [unique_id "amuY9YJkCYmL5o6vh9KTDAAAAJk"]
[Thu Jul 30 13:33:25.709647 2026] [security2:error] [pid 890219:tid 890456] [client 143.244.57.82:37268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuY9YJkCYmL5o6vh9KTFAAAAO8"]
[Thu Jul 30 13:33:25.999314 2026] [security2:error] [pid 890219:tid 890468] [client 143.244.57.82:37278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuY9YJkCYmL5o6vh9KTGQAAAPs"]
[Thu Jul 30 13:33:26.146380 2026] [security2:error] [pid 890219:tid 890423] [client 20.104.18.253:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/admin.php"] [unique_id "amuY9oJkCYmL5o6vh9KTHwAAAM4"]
[Thu Jul 30 13:33:26.161723 2026] [security2:error] [pid 890219:tid 890459] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/f35.update.php"] [unique_id "amuY9oJkCYmL5o6vh9KTIAAAAPI"]
[Thu Jul 30 13:33:26.161809 2026] [security2:error] [pid 890219:tid 890459] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/f35.update.php"] [unique_id "amuY9oJkCYmL5o6vh9KTIAAAAPI"]
[Thu Jul 30 13:33:26.302509 2026] [security2:error] [pid 890219:tid 890393] [client 143.244.57.82:37282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuY9oJkCYmL5o6vh9KTJQAAALA"]
[Thu Jul 30 13:33:26.579294 2026] [security2:error] [pid 890219:tid 890396] [client 143.244.57.82:37298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuY9oJkCYmL5o6vh9KTKgAAALM"]
[Thu Jul 30 13:33:26.690330 2026] [security2:error] [pid 890219:tid 890454] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/k.php"] [unique_id "amuY9oJkCYmL5o6vh9KTMgAAAO0"]
[Thu Jul 30 13:33:26.690448 2026] [security2:error] [pid 890219:tid 890454] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/k.php"] [unique_id "amuY9oJkCYmL5o6vh9KTMgAAAO0"]
[Thu Jul 30 13:33:26.841716 2026] [security2:error] [pid 890219:tid 890417] [client 154.227.129.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuY9IJkCYmL5o6vh9KS0AAAyG0"], referer: https://flixon.net/create-account/
[Thu Jul 30 13:33:26.874154 2026] [security2:error] [pid 890219:tid 890441] [client 143.244.57.82:40760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuY9oJkCYmL5o6vh9KTOQAAAOA"]
[Thu Jul 30 13:33:26.925568 2026] [security2:error] [pid 890219:tid 890434] [client 68.221.186.136:7948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuY9oJkCYmL5o6vh9KTPQAAANk"]
[Thu Jul 30 13:33:27.155371 2026] [security2:error] [pid 890219:tid 890383] [client 143.244.57.82:40762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuY94JkCYmL5o6vh9KTPgAAAKY"]
[Thu Jul 30 13:33:27.177945 2026] [security2:error] [pid 890219:tid 890413] [client 74.248.33.8:31488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuY94JkCYmL5o6vh9KTQgAAAMQ"]
[Thu Jul 30 13:33:27.217084 2026] [security2:error] [pid 890219:tid 890356] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuY94JkCYmL5o6vh9KTQwAAAIs"]
[Thu Jul 30 13:33:27.432613 2026] [security2:error] [pid 890219:tid 890371] [client 143.244.57.82:40778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuY94JkCYmL5o6vh9KTSgAAAJo"]
[Thu Jul 30 13:33:27.475820 2026] [security2:error] [pid 890219:tid 890421] [client 68.221.186.136:6552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuY94JkCYmL5o6vh9KTTQAAAMw"]
[Thu Jul 30 13:33:27.505846 2026] [security2:error] [pid 890219:tid 890410] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuY94JkCYmL5o6vh9KTTgAAAME"]
[Thu Jul 30 13:33:27.737803 2026] [security2:error] [pid 890219:tid 890470] [client 143.244.57.82:40792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuY94JkCYmL5o6vh9KTZQAAAP0"]
[Thu Jul 30 13:33:27.811017 2026] [security2:error] [pid 890219:tid 890457] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/spadex.php"] [unique_id "amuY94JkCYmL5o6vh9KTZwAAAPA"]
[Thu Jul 30 13:33:27.811162 2026] [security2:error] [pid 890219:tid 890457] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/spadex.php"] [unique_id "amuY94JkCYmL5o6vh9KTZwAAAPA"]
[Thu Jul 30 13:33:27.857293 2026] [security2:error] [pid 890219:tid 890280] [remote 62.210.185.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sama-architect.com"] [uri "/wp-login.php"] [unique_id "amuY94JkCYmL5o6vh9KTaAAAqDs"]
[Thu Jul 30 13:33:27.896497 2026] [security2:error] [pid 890219:tid 890366] [client 180.102.110.140:57376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mediaspawn.com"] [uri "/"] [unique_id "amuY94JkCYmL5o6vh9KTaQAAAJU"]
[Thu Jul 30 13:33:27.896633 2026] [security2:error] [pid 890219:tid 890366] [client 180.102.110.140:57376] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.mediaspawn.com"] [uri "/"] [unique_id "amuY94JkCYmL5o6vh9KTaQAAAJU"]
[Thu Jul 30 13:33:28.024499 2026] [security2:error] [pid 890219:tid 890453] [client 143.244.57.82:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuY-IJkCYmL5o6vh9KTbgAAAOw"]
[Thu Jul 30 13:33:28.075447 2026] [security2:error] [pid 890219:tid 890477] [client 20.104.18.253:36285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/adminfuns.php"] [unique_id "amuY-IJkCYmL5o6vh9KTbwAAAQQ"]
[Thu Jul 30 13:33:28.260948 2026] [security2:error] [pid 890219:tid 890398] [client 185.191.171.4:65266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/04/janones-desiste-de-candidatura-e-apoiara-lula-para-presidente-da-republica/"] [unique_id "amuY-IJkCYmL5o6vh9KTeQAAALU"]
[Thu Jul 30 13:33:28.261089 2026] [security2:error] [pid 890219:tid 890398] [client 185.191.171.4:65266] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/04/janones-desiste-de-candidatura-e-apoiara-lula-para-presidente-da-republica/"] [unique_id "amuY-IJkCYmL5o6vh9KTeQAAALU"]
[Thu Jul 30 13:33:28.313652 2026] [security2:error] [pid 890219:tid 890465] [client 143.244.57.82:40814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuY-IJkCYmL5o6vh9KTfQAAAPg"]
[Thu Jul 30 13:33:28.339777 2026] [security2:error] [pid 890219:tid 890360] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mg.php"] [unique_id "amuY-IJkCYmL5o6vh9KTfgAAAI8"]
[Thu Jul 30 13:33:28.339930 2026] [security2:error] [pid 890219:tid 890360] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mg.php"] [unique_id "amuY-IJkCYmL5o6vh9KTfgAAAI8"]
[Thu Jul 30 13:33:28.406379 2026] [security2:error] [pid 890219:tid 890463] [client 74.7.228.37:37150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.eaw.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuY-IJkCYmL5o6vh9KTfwAAAPY"]
[Thu Jul 30 13:33:28.590154 2026] [security2:error] [pid 890219:tid 890458] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuY94JkCYmL5o6vh9KTagAA8T8"]
[Thu Jul 30 13:33:28.594144 2026] [security2:error] [pid 890219:tid 890376] [client 143.244.57.82:40830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ahe.udi.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuY-IJkCYmL5o6vh9KThwAAAJ8"]
[Thu Jul 30 13:33:28.666927 2026] [autoindex:error] [pid 890219:tid 890431] [client 34.233.129.35:56419] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_9bd961c9/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:33:28.887144 2026] [security2:error] [pid 890219:tid 890392] [client 78.167.1.90:54105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuY-IJkCYmL5o6vh9KTjwAAAK8"]
[Thu Jul 30 13:33:28.887911 2026] [security2:error] [pid 890219:tid 890392] [client 78.167.1.90:54105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuY-IJkCYmL5o6vh9KTjwAAAK8"]
[Thu Jul 30 13:33:28.910593 2026] [security2:error] [pid 890219:tid 890378] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fnstall.php"] [unique_id "amuY-IJkCYmL5o6vh9KTkAAAAKE"]
[Thu Jul 30 13:33:28.910689 2026] [security2:error] [pid 890219:tid 890378] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fnstall.php"] [unique_id "amuY-IJkCYmL5o6vh9KTkAAAAKE"]
[Thu Jul 30 13:33:28.973387 2026] [security2:error] [pid 890219:tid 890382] [client 20.104.18.253:48343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/albin.php"] [unique_id "amuY-IJkCYmL5o6vh9KTkQAAAKU"]
[Thu Jul 30 13:33:29.108132 2026] [core:error] [pid 890219:tid 890464] [client 138.246.253.24:56242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:29.108155 2026] [core:error] [pid 890219:tid 890464] [client 138.246.253.24:56242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:33:29.267244 2026] [security2:error] [pid 890219:tid 890367] [client 74.248.33.8:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/edit.php"] [unique_id "amuY-YJkCYmL5o6vh9KTmQAAAJY"]
[Thu Jul 30 13:33:29.448097 2026] [security2:error] [pid 890219:tid 890460] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ortasekerli1.php"] [unique_id "amuY-YJkCYmL5o6vh9KTngAAAPM"]
[Thu Jul 30 13:33:29.448221 2026] [security2:error] [pid 890219:tid 890460] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ortasekerli1.php"] [unique_id "amuY-YJkCYmL5o6vh9KTngAAAPM"]
[Thu Jul 30 13:33:29.464843 2026] [security2:error] [pid 890219:tid 890417] [client 68.221.186.136:8450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuY-YJkCYmL5o6vh9KToAAAAMg"]
[Thu Jul 30 13:33:29.564323 2026] [proxy:error] [pid 890219:tid 890366] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:29.564404 2026] [proxy_http:error] [pid 890219:tid 890366] [client 34.224.175.62:1320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:29.565196 2026] [proxy:error] [pid 890219:tid 890366] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:29.565258 2026] [proxy_http:error] [pid 890219:tid 890366] [client 34.224.175.62:1320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:29.583172 2026] [proxy:error] [pid 890219:tid 890423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:29.583257 2026] [proxy_http:error] [pid 890219:tid 890423] [client 34.233.129.35:29999] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:29.583890 2026] [proxy:error] [pid 890219:tid 890423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:29.583937 2026] [proxy_http:error] [pid 890219:tid 890423] [client 34.233.129.35:29999] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:29.963615 2026] [security2:error] [pid 890219:tid 890436] [client 20.104.18.253:36242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/amfsqvgv.php"] [unique_id "amuY-YJkCYmL5o6vh9KTvQAAANs"]
[Thu Jul 30 13:33:29.983615 2026] [security2:error] [pid 890219:tid 890399] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sump1.php"] [unique_id "amuY-YJkCYmL5o6vh9KTwQAAALY"]
[Thu Jul 30 13:33:29.983719 2026] [security2:error] [pid 890219:tid 890399] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sump1.php"] [unique_id "amuY-YJkCYmL5o6vh9KTwQAAALY"]
[Thu Jul 30 13:33:30.240540 2026] [security2:error] [pid 890219:tid 890381] [client 100.27.153.9:14007] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/jkhgsdf.jpg"] [unique_id "amuY-oJkCYmL5o6vh9KTyQAAAKQ"]
[Thu Jul 30 13:33:30.289787 2026] [security2:error] [pid 890219:tid 890401] [client 68.221.186.136:6554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuY-oJkCYmL5o6vh9KT0AAAALg"]
[Thu Jul 30 13:33:30.515352 2026] [security2:error] [pid 890219:tid 890351] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ops.php"] [unique_id "amuY-oJkCYmL5o6vh9KT1AAAAIY"]
[Thu Jul 30 13:33:30.515484 2026] [security2:error] [pid 890219:tid 890351] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ops.php"] [unique_id "amuY-oJkCYmL5o6vh9KT1AAAAIY"]
[Thu Jul 30 13:33:30.945854 2026] [security2:error] [pid 890219:tid 890470] [client 74.248.33.8:29513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/file5.php"] [unique_id "amuY-oJkCYmL5o6vh9KT5AAAAP0"]
[Thu Jul 30 13:33:31.030772 2026] [security2:error] [pid 890219:tid 890366] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-post-data.php"] [unique_id "amuY-4JkCYmL5o6vh9KT5QAAAJU"]
[Thu Jul 30 13:33:31.030878 2026] [security2:error] [pid 890219:tid 890366] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-post-data.php"] [unique_id "amuY-4JkCYmL5o6vh9KT5QAAAJU"]
[Thu Jul 30 13:33:31.576411 2026] [security2:error] [pid 890219:tid 890354] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/root.php"] [unique_id "amuY-4JkCYmL5o6vh9KT_QAAAIk"]
[Thu Jul 30 13:33:31.576546 2026] [security2:error] [pid 890219:tid 890354] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/root.php"] [unique_id "amuY-4JkCYmL5o6vh9KT_QAAAIk"]
[Thu Jul 30 13:33:32.014901 2026] [security2:error] [pid 890219:tid 890436] [client 68.221.186.136:10006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuY_IJkCYmL5o6vh9KULgAAANs"]
[Thu Jul 30 13:33:32.093732 2026] [security2:error] [pid 890219:tid 890395] [client 74.248.33.8:64382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/sf.php"] [unique_id "amuY_IJkCYmL5o6vh9KUOQAAALI"]
[Thu Jul 30 13:33:32.095196 2026] [core:notice] [pid 890219:tid 890448] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:32.130408 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/v543.php"] [unique_id "amuY_IJkCYmL5o6vh9KUPQAAAMk"]
[Thu Jul 30 13:33:32.130526 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/v543.php"] [unique_id "amuY_IJkCYmL5o6vh9KUPQAAAMk"]
[Thu Jul 30 13:33:32.194592 2026] [security2:error] [pid 890219:tid 890473] [client 20.104.18.253:29536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/ant.php"] [unique_id "amuY_IJkCYmL5o6vh9KUPwAAAQA"]
[Thu Jul 30 13:33:32.281780 2026] [security2:error] [pid 890219:tid 890471] [client 68.235.48.108:48022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.48.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuY_IJkCYmL5o6vh9KUQAAAAP4"]
[Thu Jul 30 13:33:32.281892 2026] [security2:error] [pid 890219:tid 890471] [client 68.235.48.108:48022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuY_IJkCYmL5o6vh9KUQAAAAP4"]
[Thu Jul 30 13:33:32.621994 2026] [security2:error] [pid 890219:tid 890365] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sixxis.php"] [unique_id "amuY_IJkCYmL5o6vh9KUTAAAAJQ"]
[Thu Jul 30 13:33:32.622156 2026] [security2:error] [pid 890219:tid 890365] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sixxis.php"] [unique_id "amuY_IJkCYmL5o6vh9KUTAAAAJQ"]
[Thu Jul 30 13:33:32.626586 2026] [core:notice] [pid 890219:tid 890466] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:32.925367 2026] [security2:error] [pid 890219:tid 890396] [client 68.221.186.136:4493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuY_IJkCYmL5o6vh9KUWgAAALM"]
[Thu Jul 30 13:33:32.975489 2026] [security2:error] [pid 890219:tid 890474] [client 20.104.18.253:36232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/appreciators.php"] [unique_id "amuY_IJkCYmL5o6vh9KUWwAAAQE"]
[Thu Jul 30 13:33:33.162436 2026] [security2:error] [pid 890219:tid 890363] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ip.php"] [unique_id "amuY_YJkCYmL5o6vh9KUXQAAAJI"]
[Thu Jul 30 13:33:33.162584 2026] [security2:error] [pid 890219:tid 890363] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ip.php"] [unique_id "amuY_YJkCYmL5o6vh9KUXQAAAJI"]
[Thu Jul 30 13:33:33.188515 2026] [core:notice] [pid 890219:tid 890443] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:33.687940 2026] [security2:error] [pid 890219:tid 890435] [client 74.248.33.8:64342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wso.php"] [unique_id "amuY_YJkCYmL5o6vh9KUbwAAANo"]
[Thu Jul 30 13:33:33.707464 2026] [core:notice] [pid 890219:tid 890352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:33.717584 2026] [security2:error] [pid 890219:tid 890419] [client 20.104.18.253:46359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/archive.php"] [unique_id "amuY_YJkCYmL5o6vh9KUcQAAAMo"]
[Thu Jul 30 13:33:33.765585 2026] [security2:error] [pid 890219:tid 890395] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/kq1.php"] [unique_id "amuY_YJkCYmL5o6vh9KUdgAAALI"]
[Thu Jul 30 13:33:33.765708 2026] [security2:error] [pid 890219:tid 890395] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/kq1.php"] [unique_id "amuY_YJkCYmL5o6vh9KUdgAAALI"]
[Thu Jul 30 13:33:34.298077 2026] [security2:error] [pid 890219:tid 890408] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fw/faiyy.php"] [unique_id "amuY_oJkCYmL5o6vh9KUgQAAAL8"]
[Thu Jul 30 13:33:34.298180 2026] [security2:error] [pid 890219:tid 890408] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fw/faiyy.php"] [unique_id "amuY_oJkCYmL5o6vh9KUgQAAAL8"]
[Thu Jul 30 13:33:34.372831 2026] [security2:error] [pid 890219:tid 890398] [client 52.54.95.127:64297] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/prefeituras-paraibanas-receberao-r-1218-mi-de-parcela-extra-do-fpm-em-dezembro/"] [unique_id "amuY_oJkCYmL5o6vh9KUhgAAALU"]
[Thu Jul 30 13:33:34.699403 2026] [security2:error] [pid 890219:tid 890439] [client 68.221.186.136:41599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuY_oJkCYmL5o6vh9KUjgAAAN4"]
[Thu Jul 30 13:33:34.787773 2026] [security2:error] [pid 890219:tid 890416] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/h02ugyh.php"] [unique_id "amuY_oJkCYmL5o6vh9KUkgAAAMc"]
[Thu Jul 30 13:33:34.787881 2026] [security2:error] [pid 890219:tid 890416] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/h02ugyh.php"] [unique_id "amuY_oJkCYmL5o6vh9KUkgAAAMc"]
[Thu Jul 30 13:33:34.921915 2026] [security2:error] [pid 890219:tid 890361] [client 74.248.33.8:16018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/ioxi-o.php"] [unique_id "amuY_oJkCYmL5o6vh9KUlgAAAJA"]
[Thu Jul 30 13:33:35.131909 2026] [security2:error] [pid 890219:tid 890458] [client 20.104.18.253:53859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/as.php"] [unique_id "amuY_4JkCYmL5o6vh9KUmwAAAPE"]
[Thu Jul 30 13:33:35.346140 2026] [security2:error] [pid 890219:tid 890390] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-temp.php"] [unique_id "amuY_4JkCYmL5o6vh9KUnwAAAK0"]
[Thu Jul 30 13:33:35.346270 2026] [security2:error] [pid 890219:tid 890390] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-temp.php"] [unique_id "amuY_4JkCYmL5o6vh9KUnwAAAK0"]
[Thu Jul 30 13:33:35.658023 2026] [security2:error] [pid 890219:tid 890375] [client 68.221.186.136:6529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/cloud.php"] [unique_id "amuY_4JkCYmL5o6vh9KUqAAAAJ4"]
[Thu Jul 30 13:33:36.082142 2026] [security2:error] [pid 890219:tid 890378] [client 20.104.18.253:53878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/atomlib.php"] [unique_id "amuZAIJkCYmL5o6vh9KUtQAAAKE"]
[Thu Jul 30 13:33:36.119878 2026] [security2:error] [pid 890219:tid 890370] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/cong.php"] [unique_id "amuZAIJkCYmL5o6vh9KUtgAAAJk"]
[Thu Jul 30 13:33:36.119995 2026] [security2:error] [pid 890219:tid 890370] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/cong.php"] [unique_id "amuZAIJkCYmL5o6vh9KUtgAAAJk"]
[Thu Jul 30 13:33:36.563157 2026] [security2:error] [pid 890219:tid 890451] [client 68.221.186.136:6542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuZAIJkCYmL5o6vh9KUwQAAAOo"]
[Thu Jul 30 13:33:36.716360 2026] [security2:error] [pid 890219:tid 890369] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZAIJkCYmL5o6vh9KUxQAAAJg"]
[Thu Jul 30 13:33:36.718041 2026] [security2:error] [pid 890219:tid 890468] [client 74.248.33.8:32056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/file56.php"] [unique_id "amuZAIJkCYmL5o6vh9KUxgAAAPs"]
[Thu Jul 30 13:33:37.023719 2026] [security2:error] [pid 890219:tid 890382] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZAYJkCYmL5o6vh9KU0QAAAKU"]
[Thu Jul 30 13:33:37.102604 2026] [security2:error] [pid 890219:tid 890445] [client 20.104.18.253:28612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/autoload_classmap.php"] [unique_id "amuZAYJkCYmL5o6vh9KU0gAAAOQ"]
[Thu Jul 30 13:33:37.326620 2026] [security2:error] [pid 890219:tid 890455] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/css/index.php"] [unique_id "amuZAYJkCYmL5o6vh9KU1gAAAO4"]
[Thu Jul 30 13:33:37.326742 2026] [security2:error] [pid 890219:tid 890455] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/css/index.php"] [unique_id "amuZAYJkCYmL5o6vh9KU1gAAAO4"]
[Thu Jul 30 13:33:37.818137 2026] [security2:error] [pid 890219:tid 890384] [client 20.104.18.253:25688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/bb.php"] [unique_id "amuZAYJkCYmL5o6vh9KU5QAAAKc"]
[Thu Jul 30 13:33:37.878145 2026] [security2:error] [pid 890219:tid 890452] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/jj.php"] [unique_id "amuZAYJkCYmL5o6vh9KU5gAAAOs"]
[Thu Jul 30 13:33:37.878258 2026] [security2:error] [pid 890219:tid 890452] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/jj.php"] [unique_id "amuZAYJkCYmL5o6vh9KU5gAAAOs"]
[Thu Jul 30 13:33:38.286367 2026] [security2:error] [pid 890219:tid 890449] [client 23.21.225.190:30744] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/08/mae-bebe-armario-400x300@2x.jpg"] [unique_id "amuZAoJkCYmL5o6vh9KU8QAAAOg"]
[Thu Jul 30 13:33:38.349281 2026] [security2:error] [pid 890219:tid 890438] [client 68.221.186.136:2259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/updates.php"] [unique_id "amuZAoJkCYmL5o6vh9KU8gAAAN0"]
[Thu Jul 30 13:33:38.396012 2026] [security2:error] [pid 890219:tid 890386] [client 74.248.33.8:16459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuZAoJkCYmL5o6vh9KU9AAAAKk"]
[Thu Jul 30 13:33:38.417231 2026] [security2:error] [pid 890219:tid 890367] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/class-walker-footer-dev.php"] [unique_id "amuZAoJkCYmL5o6vh9KU9wAAAJY"]
[Thu Jul 30 13:33:38.417318 2026] [security2:error] [pid 890219:tid 890367] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/class-walker-footer-dev.php"] [unique_id "amuZAoJkCYmL5o6vh9KU9wAAAJY"]
[Thu Jul 30 13:33:39.013995 2026] [security2:error] [pid 890219:tid 890460] [client 20.104.18.253:44671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/bnm.php"] [unique_id "amuZA4JkCYmL5o6vh9KVBAAAAPM"]
[Thu Jul 30 13:33:39.014387 2026] [security2:error] [pid 890219:tid 890461] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xpwer1.php"] [unique_id "amuZA4JkCYmL5o6vh9KVBgAAAPQ"]
[Thu Jul 30 13:33:39.014477 2026] [security2:error] [pid 890219:tid 890461] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xpwer1.php"] [unique_id "amuZA4JkCYmL5o6vh9KVBgAAAPQ"]
[Thu Jul 30 13:33:39.033834 2026] [security2:error] [pid 890219:tid 890355] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZAoJkCYmL5o6vh9KU-AAAAIo"]
[Thu Jul 30 13:33:39.566467 2026] [security2:error] [pid 890219:tid 890463] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/flox.php"] [unique_id "amuZA4JkCYmL5o6vh9KVFgAAAPY"]
[Thu Jul 30 13:33:39.566594 2026] [security2:error] [pid 890219:tid 890463] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/flox.php"] [unique_id "amuZA4JkCYmL5o6vh9KVFgAAAPY"]
[Thu Jul 30 13:33:39.698019 2026] [security2:error] [pid 890219:tid 890387] [client 68.221.186.136:2294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/css/cloud.php"] [unique_id "amuZA4JkCYmL5o6vh9KVHAAAAKo"]
[Thu Jul 30 13:33:39.813209 2026] [security2:error] [pid 890219:tid 890351] [client 78.167.1.90:56573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZA4JkCYmL5o6vh9KVIgAAAIY"]
[Thu Jul 30 13:33:39.814039 2026] [security2:error] [pid 890219:tid 890351] [client 78.167.1.90:56573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZA4JkCYmL5o6vh9KVIgAAAIY"]
[Thu Jul 30 13:33:40.110375 2026] [security2:error] [pid 890219:tid 890415] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/popo.php"] [unique_id "amuZBIJkCYmL5o6vh9KVKAAAAMY"]
[Thu Jul 30 13:33:40.110476 2026] [security2:error] [pid 890219:tid 890415] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/popo.php"] [unique_id "amuZBIJkCYmL5o6vh9KVKAAAAMY"]
[Thu Jul 30 13:33:40.484858 2026] [security2:error] [pid 890219:tid 890467] [client 20.104.18.253:25955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/bootstrap.php"] [unique_id "amuZBIJkCYmL5o6vh9KVNAAAAPo"]
[Thu Jul 30 13:33:40.528469 2026] [security2:error] [pid 890219:tid 890277] [remote 156.59.198.135:38636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aded-rdc.org"] [uri "/wp-content/uploads/2022/08/ADED_2020_Annual_Report.pdf"] [unique_id "amuZBIJkCYmL5o6vh9KVNQAAyTg"]
[Thu Jul 30 13:33:40.601843 2026] [security2:error] [pid 890219:tid 890436] [client 185.156.175.51:36178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuZBIJkCYmL5o6vh9KVOAAAANs"]
[Thu Jul 30 13:33:40.602007 2026] [security2:error] [pid 890219:tid 890436] [client 185.156.175.51:36178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuZBIJkCYmL5o6vh9KVOAAAANs"]
[Thu Jul 30 13:33:40.603819 2026] [security2:error] [pid 890219:tid 890430] [client 60.26.9.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuZA4JkCYmL5o6vh9KVHwAAANU"]
[Thu Jul 30 13:33:40.917429 2026] [security2:error] [pid 890219:tid 890410] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yas.php"] [unique_id "amuZBIJkCYmL5o6vh9KVSAAAAME"]
[Thu Jul 30 13:33:40.917531 2026] [security2:error] [pid 890219:tid 890410] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yas.php"] [unique_id "amuZBIJkCYmL5o6vh9KVSAAAAME"]
[Thu Jul 30 13:33:40.995655 2026] [security2:error] [pid 890219:tid 890392] [client 74.248.33.8:13692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/css/index.php"] [unique_id "amuZBIJkCYmL5o6vh9KVSQAAAK8"]
[Thu Jul 30 13:33:41.470925 2026] [security2:error] [pid 890219:tid 890412] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/water.php"] [unique_id "amuZBYJkCYmL5o6vh9KVVAAAAMM"]
[Thu Jul 30 13:33:41.471084 2026] [security2:error] [pid 890219:tid 890412] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/water.php"] [unique_id "amuZBYJkCYmL5o6vh9KVVAAAAMM"]
[Thu Jul 30 13:33:41.538572 2026] [security2:error] [pid 890219:tid 890380] [client 20.104.18.253:25719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/buy.php"] [unique_id "amuZBYJkCYmL5o6vh9KVVQAAAKM"]
[Thu Jul 30 13:33:41.958164 2026] [security2:error] [pid 890219:tid 890377] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/nano.php"] [unique_id "amuZBYJkCYmL5o6vh9KVaQAAAKA"]
[Thu Jul 30 13:33:41.958282 2026] [security2:error] [pid 890219:tid 890377] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/nano.php"] [unique_id "amuZBYJkCYmL5o6vh9KVaQAAAKA"]
[Thu Jul 30 13:33:42.050939 2026] [core:notice] [pid 890219:tid 890286] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:42.369211 2026] [core:notice] [pid 890219:tid 890324] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:33:42.462941 2026] [security2:error] [pid 890219:tid 890396] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/moon.php"] [unique_id "amuZBoJkCYmL5o6vh9KViwAAALM"]
[Thu Jul 30 13:33:42.463103 2026] [security2:error] [pid 890219:tid 890396] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/moon.php"] [unique_id "amuZBoJkCYmL5o6vh9KViwAAALM"]
[Thu Jul 30 13:33:42.615710 2026] [security2:error] [pid 890219:tid 890432] [client 20.104.18.253:25964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/chosen.php"] [unique_id "amuZBoJkCYmL5o6vh9KVkQAAANc"]
[Thu Jul 30 13:33:42.694958 2026] [security2:error] [pid 890219:tid 890370] [client 34.230.124.21:45241] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2018/06/WhatsApp-Image-2018-06-30-at-21.41.52-576x1024.jpeg"] [unique_id "amuZBoJkCYmL5o6vh9KVlQAAAJk"]
[Thu Jul 30 13:33:42.812182 2026] [proxy:error] [pid 890219:tid 890393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:42.812269 2026] [proxy_http:error] [pid 890219:tid 890393] [client 52.4.19.39:29643] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:42.812875 2026] [proxy:error] [pid 890219:tid 890393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:42.812918 2026] [proxy_http:error] [pid 890219:tid 890393] [client 52.4.19.39:29643] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:42.866061 2026] [proxy:error] [pid 890219:tid 890477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:42.866143 2026] [proxy_http:error] [pid 890219:tid 890477] [client 52.4.19.39:55831] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:42.866719 2026] [proxy:error] [pid 890219:tid 890477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:33:42.866761 2026] [proxy_http:error] [pid 890219:tid 890477] [client 52.4.19.39:55831] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:33:42.951790 2026] [security2:error] [pid 890219:tid 890463] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-info.php"] [unique_id "amuZBoJkCYmL5o6vh9KVuAAAAPY"]
[Thu Jul 30 13:33:42.951878 2026] [security2:error] [pid 890219:tid 890463] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-info.php"] [unique_id "amuZBoJkCYmL5o6vh9KVuAAAAPY"]
[Thu Jul 30 13:33:43.072708 2026] [security2:error] [pid 890219:tid 890402] [client 74.248.33.8:24264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/edit.php"] [unique_id "amuZB4JkCYmL5o6vh9KVvAAAALk"]
[Thu Jul 30 13:33:43.117388 2026] [security2:error] [pid 890219:tid 890361] [client 139.28.219.70:49888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "daralnaseemdxb.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuZB4JkCYmL5o6vh9KVvgAAAJA"]
[Thu Jul 30 13:33:43.418450 2026] [security2:error] [pid 890219:tid 890382] [client 68.221.186.136:7700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuZB4JkCYmL5o6vh9KVygAAAKU"]
[Thu Jul 30 13:33:43.492670 2026] [security2:error] [pid 890219:tid 890377] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file5.php"] [unique_id "amuZB4JkCYmL5o6vh9KVywAAAKA"]
[Thu Jul 30 13:33:43.492780 2026] [security2:error] [pid 890219:tid 890377] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file5.php"] [unique_id "amuZB4JkCYmL5o6vh9KVywAAAKA"]
[Thu Jul 30 13:33:43.797048 2026] [security2:error] [pid 890219:tid 890332] [remote 110.249.202.46:13814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/product/peace-4/"] [unique_id "amuZB4JkCYmL5o6vh9KV0QAAiW8"]
[Thu Jul 30 13:33:44.053857 2026] [security2:error] [pid 890219:tid 890425] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2000.php"] [unique_id "amuZCIJkCYmL5o6vh9KV2QAAANA"]
[Thu Jul 30 13:33:44.053966 2026] [security2:error] [pid 890219:tid 890425] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2000.php"] [unique_id "amuZCIJkCYmL5o6vh9KV2QAAANA"]
[Thu Jul 30 13:33:44.276281 2026] [security2:error] [pid 890219:tid 890239] [remote 74.7.243.224:52942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/article.php"] [unique_id "amuZCIJkCYmL5o6vh9KV4AAAoRI"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:33:44.577190 2026] [security2:error] [pid 890219:tid 890477] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/122.php"] [unique_id "amuZCIJkCYmL5o6vh9KV6wAAAQQ"]
[Thu Jul 30 13:33:44.577295 2026] [security2:error] [pid 890219:tid 890477] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/122.php"] [unique_id "amuZCIJkCYmL5o6vh9KV6wAAAQQ"]
[Thu Jul 30 13:33:44.656771 2026] [security2:error] [pid 890219:tid 890388] [client 74.248.33.8:21144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/2.php"] [unique_id "amuZCIJkCYmL5o6vh9KV7AAAAKs"]
[Thu Jul 30 13:33:44.741342 2026] [security2:error] [pid 890219:tid 890351] [client 20.104.18.253:48342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/class-wp-image.php"] [unique_id "amuZCIJkCYmL5o6vh9KV7QAAAIY"]
[Thu Jul 30 13:33:44.900911 2026] [security2:error] [pid 890219:tid 890444] [client 74.7.228.55:44752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "xwy.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuZB4JkCYmL5o6vh9KVvQAA42M"]
[Thu Jul 30 13:33:45.079099 2026] [security2:error] [pid 890219:tid 890476] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mds.php"] [unique_id "amuZCYJkCYmL5o6vh9KV-wAAAQM"]
[Thu Jul 30 13:33:45.079242 2026] [security2:error] [pid 890219:tid 890476] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mds.php"] [unique_id "amuZCYJkCYmL5o6vh9KV-wAAAQM"]
[Thu Jul 30 13:33:45.408036 2026] [security2:error] [pid 890219:tid 890384] [client 20.104.18.253:25958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/classsmtps.php"] [unique_id "amuZCYJkCYmL5o6vh9KWBQAAAKc"]
[Thu Jul 30 13:33:45.545705 2026] [security2:error] [pid 890219:tid 890409] [client 139.28.219.70:49900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daralnaseemdxb.com"] [uri "/xmlrpc.php"] [unique_id "amuZCYJkCYmL5o6vh9KWCwAAAMA"]
[Thu Jul 30 13:33:45.545839 2026] [security2:error] [pid 890219:tid 890409] [client 139.28.219.70:49900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daralnaseemdxb.com"] [uri "/xmlrpc.php"] [unique_id "amuZCYJkCYmL5o6vh9KWCwAAAMA"]
[Thu Jul 30 13:33:45.572161 2026] [security2:error] [pid 890219:tid 890350] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zc-208.php"] [unique_id "amuZCYJkCYmL5o6vh9KWDQAAAIU"]
[Thu Jul 30 13:33:45.572281 2026] [security2:error] [pid 890219:tid 890350] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zc-208.php"] [unique_id "amuZCYJkCYmL5o6vh9KWDQAAAIU"]
[Thu Jul 30 13:33:46.122181 2026] [security2:error] [pid 890219:tid 890453] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sid4.php"] [unique_id "amuZCoJkCYmL5o6vh9KWGQAAAOw"]
[Thu Jul 30 13:33:46.122295 2026] [security2:error] [pid 890219:tid 890453] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sid4.php"] [unique_id "amuZCoJkCYmL5o6vh9KWGQAAAOw"]
[Thu Jul 30 13:33:46.479542 2026] [security2:error] [pid 890219:tid 890368] [client 20.104.18.253:25689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/classwithtostring.php"] [unique_id "amuZCoJkCYmL5o6vh9KWKAAAAJc"]
[Thu Jul 30 13:33:46.485451 2026] [security2:error] [pid 890219:tid 890457] [client 68.221.186.136:6562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/img/cloud.php"] [unique_id "amuZCoJkCYmL5o6vh9KWKQAAAPA"]
[Thu Jul 30 13:33:46.694081 2026] [security2:error] [pid 890219:tid 890461] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZCoJkCYmL5o6vh9KWLgAAAPQ"]
[Thu Jul 30 13:33:46.875600 2026] [security2:error] [pid 890219:tid 890440] [client 74.248.33.8:21176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuZCoJkCYmL5o6vh9KWLwAAAN8"]
[Thu Jul 30 13:33:46.981600 2026] [security2:error] [pid 890219:tid 890401] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZCoJkCYmL5o6vh9KWNgAAALg"]
[Thu Jul 30 13:33:47.156056 2026] [security2:error] [pid 890219:tid 890437] [client 20.104.18.253:53870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/config.php"] [unique_id "amuZC4JkCYmL5o6vh9KWPAAAANw"]
[Thu Jul 30 13:33:47.284836 2026] [security2:error] [pid 890219:tid 890446] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wmore1.php"] [unique_id "amuZC4JkCYmL5o6vh9KWPQAAAOU"]
[Thu Jul 30 13:33:47.285074 2026] [security2:error] [pid 890219:tid 890446] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wmore1.php"] [unique_id "amuZC4JkCYmL5o6vh9KWPQAAAOU"]
[Thu Jul 30 13:33:47.441139 2026] [security2:error] [pid 890219:tid 890469] [client 68.221.186.136:7691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuZC4JkCYmL5o6vh9KWQgAAAPw"]
[Thu Jul 30 13:33:47.475811 2026] [security2:error] [pid 890219:tid 890369] [client 66.249.73.97:43739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZC4JkCYmL5o6vh9KWNwAAAJg"]
[Thu Jul 30 13:33:47.696698 2026] [security2:error] [pid 890219:tid 890365] [client 34.203.111.15:29725] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2019/07/1-4-549x420.png"] [unique_id "amuZC4JkCYmL5o6vh9KWTgAAAJQ"]
[Thu Jul 30 13:33:47.866715 2026] [security2:error] [pid 890219:tid 890358] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/solo1.php"] [unique_id "amuZC4JkCYmL5o6vh9KWTwAAAI0"]
[Thu Jul 30 13:33:47.866839 2026] [security2:error] [pid 890219:tid 890358] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/solo1.php"] [unique_id "amuZC4JkCYmL5o6vh9KWTwAAAI0"]
[Thu Jul 30 13:33:48.465447 2026] [security2:error] [pid 890219:tid 890460] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZDIJkCYmL5o6vh9KWXgAAAPM"]
[Thu Jul 30 13:33:48.486310 2026] [security2:error] [pid 890219:tid 890395] [client 20.104.18.253:41569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/core.php"] [unique_id "amuZDIJkCYmL5o6vh9KWYgAAALI"]
[Thu Jul 30 13:33:48.505489 2026] [security2:error] [pid 890219:tid 890458] [client 68.221.186.136:8477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuZDIJkCYmL5o6vh9KWYwAAAPE"]
[Thu Jul 30 13:33:48.719840 2026] [security2:error] [pid 890219:tid 890477] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZDIJkCYmL5o6vh9KWbQAAAQQ"]
[Thu Jul 30 13:33:48.828373 2026] [security2:error] [pid 890219:tid 890370] [client 74.248.33.8:29511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/mah.php"] [unique_id "amuZDIJkCYmL5o6vh9KWbwAAAJk"]
[Thu Jul 30 13:33:48.978545 2026] [security2:error] [pid 890219:tid 890401] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZDIJkCYmL5o6vh9KWcQAAALg"]
[Thu Jul 30 13:33:49.290310 2026] [security2:error] [pid 890219:tid 890369] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZDYJkCYmL5o6vh9KWiAAAAJg"]
[Thu Jul 30 13:33:49.330033 2026] [security2:error] [pid 890219:tid 890383] [client 20.104.18.253:41598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/css.php"] [unique_id "amuZDYJkCYmL5o6vh9KWjQAAAKY"]
[Thu Jul 30 13:33:49.564259 2026] [security2:error] [pid 890219:tid 890466] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/public/css.php"] [unique_id "amuZDYJkCYmL5o6vh9KWnAAAAPk"]
[Thu Jul 30 13:33:49.564424 2026] [security2:error] [pid 890219:tid 890466] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/public/css.php"] [unique_id "amuZDYJkCYmL5o6vh9KWnAAAAPk"]
[Thu Jul 30 13:33:50.040320 2026] [security2:error] [pid 890219:tid 890362] [client 78.167.1.90:54275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZDoJkCYmL5o6vh9KWrAAAAJE"]
[Thu Jul 30 13:33:50.040916 2026] [security2:error] [pid 890219:tid 890362] [client 78.167.1.90:54275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZDoJkCYmL5o6vh9KWrAAAAJE"]
[Thu Jul 30 13:33:50.058080 2026] [security2:error] [pid 890219:tid 890359] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/output.php"] [unique_id "amuZDoJkCYmL5o6vh9KWrQAAAI4"]
[Thu Jul 30 13:33:50.058200 2026] [security2:error] [pid 890219:tid 890359] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/output.php"] [unique_id "amuZDoJkCYmL5o6vh9KWrQAAAI4"]
[Thu Jul 30 13:33:50.256014 2026] [security2:error] [pid 890219:tid 890423] [client 74.248.33.8:24314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/send.php"] [unique_id "amuZDoJkCYmL5o6vh9KWtgAAAM4"]
[Thu Jul 30 13:33:50.386892 2026] [security2:error] [pid 890219:tid 890458] [client 20.104.18.253:46826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/database.php"] [unique_id "amuZDoJkCYmL5o6vh9KWuAAAAPE"]
[Thu Jul 30 13:33:50.593481 2026] [security2:error] [pid 890219:tid 890455] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-file-120.php"] [unique_id "amuZDoJkCYmL5o6vh9KWvwAAAO4"]
[Thu Jul 30 13:33:50.593659 2026] [security2:error] [pid 890219:tid 890455] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-file-120.php"] [unique_id "amuZDoJkCYmL5o6vh9KWvwAAAO4"]
[Thu Jul 30 13:33:51.138290 2026] [security2:error] [pid 890219:tid 890452] [client 74.248.33.8:24284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuZD4JkCYmL5o6vh9KW3gAAAOs"]
[Thu Jul 30 13:33:51.316473 2026] [security2:error] [pid 890219:tid 890358] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/special.php"] [unique_id "amuZD4JkCYmL5o6vh9KW5AAAAI0"]
[Thu Jul 30 13:33:51.316569 2026] [security2:error] [pid 890219:tid 890358] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/special.php"] [unique_id "amuZD4JkCYmL5o6vh9KW5AAAAI0"]
[Thu Jul 30 13:33:51.400695 2026] [security2:error] [pid 890219:tid 890467] [client 82.102.18.118:41290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuZD4JkCYmL5o6vh9KW5QAAAPo"]
[Thu Jul 30 13:33:51.684440 2026] [security2:error] [pid 890219:tid 890400] [client 82.102.18.118:26958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuZD4JkCYmL5o6vh9KW7QAAALc"]
[Thu Jul 30 13:33:51.769638 2026] [security2:error] [pid 890219:tid 890383] [client 20.104.18.253:25950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/db.php"] [unique_id "amuZD4JkCYmL5o6vh9KW7gAAAKY"]
[Thu Jul 30 13:33:51.843641 2026] [security2:error] [pid 890219:tid 890432] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/as.php"] [unique_id "amuZD4JkCYmL5o6vh9KW9wAAANc"]
[Thu Jul 30 13:33:51.843729 2026] [security2:error] [pid 890219:tid 890432] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/as.php"] [unique_id "amuZD4JkCYmL5o6vh9KW9wAAANc"]
[Thu Jul 30 13:33:52.328831 2026] [security2:error] [pid 890219:tid 890422] [client 5.161.177.47:61702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuZD4JkCYmL5o6vh9KW2QAAAM0"], referer: https://globalmarks.pk/
[Thu Jul 30 13:33:52.468889 2026] [security2:error] [pid 890219:tid 890380] [client 82.102.18.118:41314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuZEIJkCYmL5o6vh9KXDgAAAKM"]
[Thu Jul 30 13:33:52.509997 2026] [security2:error] [pid 890219:tid 890428] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/cgi-bin/index.php"] [unique_id "amuZEIJkCYmL5o6vh9KXEAAAANM"]
[Thu Jul 30 13:33:52.510135 2026] [security2:error] [pid 890219:tid 890428] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/cgi-bin/index.php"] [unique_id "amuZEIJkCYmL5o6vh9KXEAAAANM"]
[Thu Jul 30 13:33:52.665953 2026] [security2:error] [pid 890219:tid 890399] [client 74.248.33.8:16499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/about.php"] [unique_id "amuZEIJkCYmL5o6vh9KXGgAAALY"]
[Thu Jul 30 13:33:52.757299 2026] [security2:error] [pid 890219:tid 890443] [client 82.102.18.118:41320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuZEIJkCYmL5o6vh9KXHQAAAOI"]
[Thu Jul 30 13:33:52.987437 2026] [security2:error] [pid 890219:tid 890306] [remote 208.109.9.173:43434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZEIJkCYmL5o6vh9KXIwAAxlU"]
[Thu Jul 30 13:33:52.987606 2026] [security2:error] [pid 890219:tid 890415] [client 208.109.9.173:43434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZEIJkCYmL5o6vh9KXIwAAxlU"]
[Thu Jul 30 13:33:53.034419 2026] [security2:error] [pid 890219:tid 890452] [client 82.102.18.118:33747] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuZEYJkCYmL5o6vh9KXKAAAAOs"]
[Thu Jul 30 13:33:53.123507 2026] [security2:error] [pid 890219:tid 890430] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w1px.php"] [unique_id "amuZEYJkCYmL5o6vh9KXLAAAANU"]
[Thu Jul 30 13:33:53.123657 2026] [security2:error] [pid 890219:tid 890430] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w1px.php"] [unique_id "amuZEYJkCYmL5o6vh9KXLAAAANU"]
[Thu Jul 30 13:33:53.256917 2026] [security2:error] [pid 890219:tid 890442] [client 68.221.186.136:7716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/avaa.php"] [unique_id "amuZEYJkCYmL5o6vh9KXMgAAAOE"]
[Thu Jul 30 13:33:53.313870 2026] [security2:error] [pid 890219:tid 890419] [client 82.102.18.118:33752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuZEYJkCYmL5o6vh9KXMwAAAMo"]
[Thu Jul 30 13:33:53.567231 2026] [security2:error] [pid 890219:tid 890355] [client 20.104.18.253:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/default.php"] [unique_id "amuZEYJkCYmL5o6vh9KXOAAAAIo"]
[Thu Jul 30 13:33:53.592004 2026] [security2:error] [pid 890219:tid 890403] [client 82.102.18.118:37238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuZEYJkCYmL5o6vh9KXOgAAALo"]
[Thu Jul 30 13:33:53.669875 2026] [security2:error] [pid 890219:tid 890417] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/js.php"] [unique_id "amuZEYJkCYmL5o6vh9KXOwAAAMg"]
[Thu Jul 30 13:33:53.670003 2026] [security2:error] [pid 890219:tid 890417] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/js.php"] [unique_id "amuZEYJkCYmL5o6vh9KXOwAAAMg"]
[Thu Jul 30 13:33:53.731663 2026] [security2:error] [pid 890219:tid 890232] [remote 110.249.202.7:38506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/product/peace-4/"] [unique_id "amuZEYJkCYmL5o6vh9KXQgAAsgs"]
[Thu Jul 30 13:33:53.771312 2026] [security2:error] [pid 890219:tid 890420] [client 74.248.33.8:24318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/options.php"] [unique_id "amuZEYJkCYmL5o6vh9KXQwAAAMs"]
[Thu Jul 30 13:33:54.134666 2026] [security2:error] [pid 890219:tid 890361] [client 82.102.18.118:37242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuZEoJkCYmL5o6vh9KXSQAAAJA"]
[Thu Jul 30 13:33:54.233542 2026] [security2:error] [pid 890219:tid 890436] [client 68.221.186.136:11686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/images/cloud.php"] [unique_id "amuZEoJkCYmL5o6vh9KXUAAAANs"]
[Thu Jul 30 13:33:54.256531 2026] [security2:error] [pid 890219:tid 890371] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/core.php"] [unique_id "amuZEoJkCYmL5o6vh9KXUQAAAJo"]
[Thu Jul 30 13:33:54.256627 2026] [security2:error] [pid 890219:tid 890371] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/core.php"] [unique_id "amuZEoJkCYmL5o6vh9KXUQAAAJo"]
[Thu Jul 30 13:33:54.416626 2026] [security2:error] [pid 890219:tid 890399] [client 82.102.18.118:37250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuZEoJkCYmL5o6vh9KXUgAAALY"]
[Thu Jul 30 13:33:54.554805 2026] [security2:error] [pid 890219:tid 890431] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZEYJkCYmL5o6vh9KXSAAA1hg"]
[Thu Jul 30 13:33:54.689289 2026] [security2:error] [pid 890219:tid 890374] [client 82.102.18.118:37264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuZEoJkCYmL5o6vh9KXWwAAAJ0"]
[Thu Jul 30 13:33:54.737060 2026] [security2:error] [pid 890219:tid 890369] [client 20.104.18.253:46328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/dropdown.php"] [unique_id "amuZEoJkCYmL5o6vh9KXXAAAAJg"]
[Thu Jul 30 13:33:54.811325 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fffm.php"] [unique_id "amuZEoJkCYmL5o6vh9KXYAAAAMk"]
[Thu Jul 30 13:33:54.811476 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fffm.php"] [unique_id "amuZEoJkCYmL5o6vh9KXYAAAAMk"]
[Thu Jul 30 13:33:54.815434 2026] [security2:error] [pid 890219:tid 890469] [client 74.248.33.8:21134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/themes/index.php"] [unique_id "amuZEoJkCYmL5o6vh9KXYQAAAPw"]
[Thu Jul 30 13:33:54.893224 2026] [security2:error] [pid 890219:tid 890391] [client 74.7.175.157:42278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.01.adtop.net"] [uri "/robots.txt"] [unique_id "amuZEoJkCYmL5o6vh9KXYgAAri4"]
[Thu Jul 30 13:33:54.972417 2026] [security2:error] [pid 890219:tid 890358] [client 82.102.18.118:12208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuZEoJkCYmL5o6vh9KXZAAAAI0"]
[Thu Jul 30 13:33:54.992936 2026] [security2:error] [pid 890219:tid 890382] [client 68.221.186.136:2256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuZEoJkCYmL5o6vh9KXZgAAAKU"]
[Thu Jul 30 13:33:55.245832 2026] [security2:error] [pid 890219:tid 890383] [client 82.102.18.118:37284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuZE4JkCYmL5o6vh9KXcQAAAKY"]
[Thu Jul 30 13:33:55.432159 2026] [security2:error] [pid 890219:tid 890429] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ww.php"] [unique_id "amuZE4JkCYmL5o6vh9KXdQAAANQ"]
[Thu Jul 30 13:33:55.432312 2026] [security2:error] [pid 890219:tid 890429] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ww.php"] [unique_id "amuZE4JkCYmL5o6vh9KXdQAAANQ"]
[Thu Jul 30 13:33:55.513892 2026] [security2:error] [pid 890219:tid 890356] [client 20.104.18.253:25715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/edit.php"] [unique_id "amuZE4JkCYmL5o6vh9KXeAAAAIs"]
[Thu Jul 30 13:33:55.548320 2026] [security2:error] [pid 890219:tid 890459] [client 82.102.18.118:37298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuZE4JkCYmL5o6vh9KXewAAAPI"]
[Thu Jul 30 13:33:55.836624 2026] [security2:error] [pid 890219:tid 890357] [client 82.102.18.118:26946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuZE4JkCYmL5o6vh9KXggAAAIw"]
[Thu Jul 30 13:33:55.854157 2026] [security2:error] [pid 890219:tid 890362] [client 68.221.186.136:10014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuZE4JkCYmL5o6vh9KXgwAAAJE"]
[Thu Jul 30 13:33:55.950788 2026] [security2:error] [pid 890219:tid 890437] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/domvf.php"] [unique_id "amuZE4JkCYmL5o6vh9KXiQAAANw"]
[Thu Jul 30 13:33:55.950876 2026] [security2:error] [pid 890219:tid 890437] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/domvf.php"] [unique_id "amuZE4JkCYmL5o6vh9KXiQAAANw"]
[Thu Jul 30 13:33:56.118531 2026] [security2:error] [pid 890219:tid 890474] [client 82.102.18.118:37310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuZFIJkCYmL5o6vh9KXjgAAAQE"]
[Thu Jul 30 13:33:56.296597 2026] [security2:error] [pid 890219:tid 890427] [client 20.104.18.253:25930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/f35.php"] [unique_id "amuZFIJkCYmL5o6vh9KXkgAAANI"]
[Thu Jul 30 13:33:56.399351 2026] [security2:error] [pid 890219:tid 890430] [client 82.102.18.118:37316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuZFIJkCYmL5o6vh9KXlgAAANU"]
[Thu Jul 30 13:33:56.468319 2026] [security2:error] [pid 890219:tid 890409] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/echkm.php"] [unique_id "amuZFIJkCYmL5o6vh9KXlwAAAMA"]
[Thu Jul 30 13:33:56.468528 2026] [security2:error] [pid 890219:tid 890409] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/echkm.php"] [unique_id "amuZFIJkCYmL5o6vh9KXlwAAAMA"]
[Thu Jul 30 13:33:56.578276 2026] [security2:error] [pid 890219:tid 890456] [client 68.221.186.136:10011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuZFIJkCYmL5o6vh9KXnAAAAO8"]
[Thu Jul 30 13:33:56.682336 2026] [security2:error] [pid 890219:tid 890390] [client 82.102.18.118:37318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuZFIJkCYmL5o6vh9KXnQAAAK0"]
[Thu Jul 30 13:33:56.721581 2026] [security2:error] [pid 890219:tid 890448] [client 74.248.33.8:16494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-file.php"] [unique_id "amuZFIJkCYmL5o6vh9KXngAAAOc"]
[Thu Jul 30 13:33:56.961648 2026] [security2:error] [pid 890219:tid 890359] [client 82.102.18.118:33557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "happiestours-portfolio.txend.com.yqe.gzj.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuZFIJkCYmL5o6vh9KXqQAAAI4"]
[Thu Jul 30 13:33:56.973599 2026] [security2:error] [pid 890219:tid 890396] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ano.php"] [unique_id "amuZFIJkCYmL5o6vh9KXqgAAALM"]
[Thu Jul 30 13:33:56.973688 2026] [security2:error] [pid 890219:tid 890396] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ano.php"] [unique_id "amuZFIJkCYmL5o6vh9KXqgAAALM"]
[Thu Jul 30 13:33:57.527738 2026] [security2:error] [pid 890219:tid 890364] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ah25.php"] [unique_id "amuZFYJkCYmL5o6vh9KXtgAAAJM"]
[Thu Jul 30 13:33:57.527886 2026] [security2:error] [pid 890219:tid 890364] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ah25.php"] [unique_id "amuZFYJkCYmL5o6vh9KXtgAAAJM"]
[Thu Jul 30 13:33:57.702848 2026] [security2:error] [pid 890219:tid 890441] [client 74.248.33.8:29531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/sid3.php"] [unique_id "amuZFYJkCYmL5o6vh9KXwAAAAOA"]
[Thu Jul 30 13:33:57.916042 2026] [security2:error] [pid 890219:tid 890356] [client 43.159.36.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuZFIJkCYmL5o6vh9KXpwAAAIs"]
[Thu Jul 30 13:33:58.057044 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/term.php"] [unique_id "amuZFoJkCYmL5o6vh9KXzwAAAMk"]
[Thu Jul 30 13:33:58.057210 2026] [security2:error] [pid 890219:tid 890418] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/term.php"] [unique_id "amuZFoJkCYmL5o6vh9KXzwAAAMk"]
[Thu Jul 30 13:33:58.543072 2026] [security2:error] [pid 890219:tid 890383] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/we.php"] [unique_id "amuZFoJkCYmL5o6vh9KX2wAAAKY"]
[Thu Jul 30 13:33:58.543184 2026] [security2:error] [pid 890219:tid 890383] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/we.php"] [unique_id "amuZFoJkCYmL5o6vh9KX2wAAAKY"]
[Thu Jul 30 13:33:59.095203 2026] [security2:error] [pid 890219:tid 890376] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zip-onee.php"] [unique_id "amuZF4JkCYmL5o6vh9KX6gAAAJ8"]
[Thu Jul 30 13:33:59.095308 2026] [security2:error] [pid 890219:tid 890376] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zip-onee.php"] [unique_id "amuZF4JkCYmL5o6vh9KX6gAAAJ8"]
[Thu Jul 30 13:33:59.193439 2026] [security2:error] [pid 890219:tid 890477] [client 20.104.18.253:57276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/f7.php"] [unique_id "amuZF4JkCYmL5o6vh9KX7gAAAQQ"]
[Thu Jul 30 13:33:59.653656 2026] [security2:error] [pid 890219:tid 890433] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/il.php"] [unique_id "amuZF4JkCYmL5o6vh9KX_QAAANg"]
[Thu Jul 30 13:33:59.653810 2026] [security2:error] [pid 890219:tid 890433] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/il.php"] [unique_id "amuZF4JkCYmL5o6vh9KX_QAAANg"]
[Thu Jul 30 13:34:00.136408 2026] [security2:error] [pid 890219:tid 890370] [client 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZF4JkCYmL5o6vh9KX9wAAmRA"]
[Thu Jul 30 13:34:00.174762 2026] [security2:error] [pid 890219:tid 890443] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/one.php"] [unique_id "amuZGIJkCYmL5o6vh9KYDwAAAOI"]
[Thu Jul 30 13:34:00.174868 2026] [security2:error] [pid 890219:tid 890443] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/one.php"] [unique_id "amuZGIJkCYmL5o6vh9KYDwAAAOI"]
[Thu Jul 30 13:34:00.181424 2026] [core:error] [pid 890219:tid 890416] [client 5.255.231.5:55538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:00.181440 2026] [core:error] [pid 890219:tid 890416] [client 5.255.231.5:55538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:00.675008 2026] [security2:error] [pid 890219:tid 890394] [client 78.167.1.90:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZGIJkCYmL5o6vh9KYHQAAALE"]
[Thu Jul 30 13:34:00.675563 2026] [security2:error] [pid 890219:tid 890394] [client 78.167.1.90:53457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZGIJkCYmL5o6vh9KYHQAAALE"]
[Thu Jul 30 13:34:00.687416 2026] [security2:error] [pid 890219:tid 890415] [client 68.221.186.136:41565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuZGIJkCYmL5o6vh9KYHgAAAMY"]
[Thu Jul 30 13:34:00.966957 2026] [security2:error] [pid 890219:tid 890393] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/002.php"] [unique_id "amuZGIJkCYmL5o6vh9KYJgAAALA"]
[Thu Jul 30 13:34:00.967112 2026] [security2:error] [pid 890219:tid 890393] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/002.php"] [unique_id "amuZGIJkCYmL5o6vh9KYJgAAALA"]
[Thu Jul 30 13:34:01.185792 2026] [core:error] [pid 890219:tid 890408] [client 5.255.231.3:64506] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:01.185812 2026] [core:error] [pid 890219:tid 890408] [client 5.255.231.3:64506] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:01.438143 2026] [security2:error] [pid 890219:tid 890422] [client 68.221.186.136:10021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuZGYJkCYmL5o6vh9KYOQAAAM0"]
[Thu Jul 30 13:34:01.529891 2026] [security2:error] [pid 890219:tid 890396] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file1.php"] [unique_id "amuZGYJkCYmL5o6vh9KYOwAAALM"]
[Thu Jul 30 13:34:01.530017 2026] [security2:error] [pid 890219:tid 890396] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file1.php"] [unique_id "amuZGYJkCYmL5o6vh9KYOwAAALM"]
[Thu Jul 30 13:34:02.031366 2026] [security2:error] [pid 890219:tid 890431] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/akimet.php"] [unique_id "amuZGoJkCYmL5o6vh9KYSAAAANY"]
[Thu Jul 30 13:34:02.031530 2026] [security2:error] [pid 890219:tid 890431] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/akimet.php"] [unique_id "amuZGoJkCYmL5o6vh9KYSAAAANY"]
[Thu Jul 30 13:34:02.173417 2026] [core:error] [pid 890219:tid 890443] [client 87.250.224.85:39724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:02.173439 2026] [core:error] [pid 890219:tid 890443] [client 87.250.224.85:39724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:02.201786 2026] [security2:error] [pid 890219:tid 890449] [client 68.221.186.136:10045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuZGoJkCYmL5o6vh9KYTwAAAOg"]
[Thu Jul 30 13:34:02.390752 2026] [security2:error] [pid 890219:tid 890358] [client 85.204.70.94:59468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuZGoJkCYmL5o6vh9KYUwAAAI0"]
[Thu Jul 30 13:34:02.521406 2026] [security2:error] [pid 890219:tid 890467] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/reop3.php"] [unique_id "amuZGoJkCYmL5o6vh9KYWwAAAPo"]
[Thu Jul 30 13:34:02.521527 2026] [security2:error] [pid 890219:tid 890467] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/reop3.php"] [unique_id "amuZGoJkCYmL5o6vh9KYWwAAAPo"]
[Thu Jul 30 13:34:02.659933 2026] [security2:error] [pid 890219:tid 890415] [client 85.204.70.94:59476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuZGoJkCYmL5o6vh9KYXwAAAMY"]
[Thu Jul 30 13:34:02.687327 2026] [security2:error] [pid 890219:tid 890474] [client 172.237.109.114:16504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZGoJkCYmL5o6vh9KYSQAAAQE"]
[Thu Jul 30 13:34:02.980286 2026] [core:notice] [pid 890219:tid 890341] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:03.019103 2026] [security2:error] [pid 890219:tid 890367] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/h.php"] [unique_id "amuZG4JkCYmL5o6vh9KYbQAAAJY"]
[Thu Jul 30 13:34:03.019204 2026] [security2:error] [pid 890219:tid 890367] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/h.php"] [unique_id "amuZG4JkCYmL5o6vh9KYbQAAAJY"]
[Thu Jul 30 13:34:03.182314 2026] [core:error] [pid 890219:tid 890403] [client 95.108.213.213:51606] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:03.182347 2026] [core:error] [pid 890219:tid 890403] [client 95.108.213.213:51606] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:03.256289 2026] [security2:error] [pid 890219:tid 890392] [client 85.204.70.94:59490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuZG4JkCYmL5o6vh9KYeAAAAK8"]
[Thu Jul 30 13:34:03.508042 2026] [security2:error] [pid 890219:tid 890396] [client 85.204.70.94:59494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuZG4JkCYmL5o6vh9KYggAAALM"]
[Thu Jul 30 13:34:03.537277 2026] [core:notice] [pid 890219:tid 890317] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:03.604847 2026] [core:notice] [pid 890219:tid 890256] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:03.691186 2026] [security2:error] [pid 890219:tid 890434] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2x.php"] [unique_id "amuZG4JkCYmL5o6vh9KYhQAAANk"]
[Thu Jul 30 13:34:03.691305 2026] [security2:error] [pid 890219:tid 890434] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2x.php"] [unique_id "amuZG4JkCYmL5o6vh9KYhQAAANk"]
[Thu Jul 30 13:34:03.730124 2026] [security2:error] [pid 890219:tid 890477] [client 74.248.33.8:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/themes.php"] [unique_id "amuZG4JkCYmL5o6vh9KYhgAAAQQ"]
[Thu Jul 30 13:34:03.759247 2026] [security2:error] [pid 890219:tid 890356] [client 85.204.70.94:59510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuZG4JkCYmL5o6vh9KYigAAAIs"]
[Thu Jul 30 13:34:03.853962 2026] [security2:error] [pid 890219:tid 890394] [client 68.221.186.136:9994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/updates.php"] [unique_id "amuZG4JkCYmL5o6vh9KYjAAAALE"]
[Thu Jul 30 13:34:04.058651 2026] [security2:error] [pid 890219:tid 890370] [client 85.204.70.94:59520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuZHIJkCYmL5o6vh9KYkwAAAJk"]
[Thu Jul 30 13:34:04.177751 2026] [core:error] [pid 890219:tid 890369] [client 87.250.224.236:48248] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:04.177781 2026] [core:error] [pid 890219:tid 890369] [client 87.250.224.236:48248] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:04.229377 2026] [core:notice] [pid 890219:tid 890348] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:04.237336 2026] [security2:error] [pid 890219:tid 890419] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/petx.php"] [unique_id "amuZHIJkCYmL5o6vh9KYlgAAAMo"]
[Thu Jul 30 13:34:04.237444 2026] [security2:error] [pid 890219:tid 890419] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/petx.php"] [unique_id "amuZHIJkCYmL5o6vh9KYlgAAAMo"]
[Thu Jul 30 13:34:04.368477 2026] [security2:error] [pid 890219:tid 890382] [client 85.204.70.94:59534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuZHIJkCYmL5o6vh9KYmwAAAKU"]
[Thu Jul 30 13:34:04.618959 2026] [security2:error] [pid 890219:tid 890474] [client 85.204.70.94:59540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuZHIJkCYmL5o6vh9KYpAAAAQE"]
[Thu Jul 30 13:34:04.674403 2026] [security2:error] [pid 890219:tid 890409] [client 68.221.186.136:6547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuZHIJkCYmL5o6vh9KYpQAAAMA"]
[Thu Jul 30 13:34:04.700882 2026] [security2:error] [pid 890219:tid 890358] [client 74.248.33.8:37276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/plugins/index.php"] [unique_id "amuZHIJkCYmL5o6vh9KYpgAAAI0"]
[Thu Jul 30 13:34:04.865304 2026] [security2:error] [pid 890219:tid 890400] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zxz.php"] [unique_id "amuZHIJkCYmL5o6vh9KYqgAAALc"]
[Thu Jul 30 13:34:04.865399 2026] [security2:error] [pid 890219:tid 890400] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zxz.php"] [unique_id "amuZHIJkCYmL5o6vh9KYqgAAALc"]
[Thu Jul 30 13:34:04.894585 2026] [security2:error] [pid 890219:tid 890359] [client 85.204.70.94:59550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuZHIJkCYmL5o6vh9KYrAAAAI4"]
[Thu Jul 30 13:34:05.034733 2026] [security2:error] [pid 890219:tid 890232] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.reviewbyjook.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amuZHYJkCYmL5o6vh9KYrgAAwws"]
[Thu Jul 30 13:34:05.173961 2026] [security2:error] [pid 890219:tid 890362] [client 85.204.70.94:59558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuZHYJkCYmL5o6vh9KYtAAAAJE"]
[Thu Jul 30 13:34:05.182734 2026] [core:error] [pid 890219:tid 890354] [client 95.108.213.192:37512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:05.182750 2026] [core:error] [pid 890219:tid 890354] [client 95.108.213.192:37512] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:05.421643 2026] [security2:error] [pid 890219:tid 890436] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2.php"] [unique_id "amuZHYJkCYmL5o6vh9KYuwAAANs"]
[Thu Jul 30 13:34:05.421740 2026] [security2:error] [pid 890219:tid 890436] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2.php"] [unique_id "amuZHYJkCYmL5o6vh9KYuwAAANs"]
[Thu Jul 30 13:34:05.463401 2026] [security2:error] [pid 890219:tid 890437] [client 85.204.70.94:59568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuZHYJkCYmL5o6vh9KYvQAAANw"]
[Thu Jul 30 13:34:05.479850 2026] [security2:error] [pid 890219:tid 890444] [client 68.221.186.136:10009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuZHYJkCYmL5o6vh9KYvgAAAOM"]
[Thu Jul 30 13:34:05.742417 2026] [security2:error] [pid 890219:tid 890389] [client 85.204.70.94:59582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuZHYJkCYmL5o6vh9KYxgAAAKw"]
[Thu Jul 30 13:34:05.840962 2026] [security2:error] [pid 890219:tid 890464] [client 74.248.33.8:29550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/images/index.php"] [unique_id "amuZHYJkCYmL5o6vh9KYxwAAAPc"]
[Thu Jul 30 13:34:06.028192 2026] [security2:error] [pid 890219:tid 890374] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/op.php"] [unique_id "amuZHoJkCYmL5o6vh9KY0AAAAJ0"]
[Thu Jul 30 13:34:06.028369 2026] [security2:error] [pid 890219:tid 890374] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/op.php"] [unique_id "amuZHoJkCYmL5o6vh9KY0AAAAJ0"]
[Thu Jul 30 13:34:06.033004 2026] [security2:error] [pid 890219:tid 890407] [client 85.204.70.94:59586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuZHoJkCYmL5o6vh9KY0QAAAL4"]
[Thu Jul 30 13:34:06.183487 2026] [core:error] [pid 890219:tid 890377] [client 95.108.213.168:51704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:06.183508 2026] [core:error] [pid 890219:tid 890377] [client 95.108.213.168:51704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:06.319919 2026] [security2:error] [pid 890219:tid 890452] [client 85.204.70.94:59598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuZHoJkCYmL5o6vh9KY1wAAAOs"]
[Thu Jul 30 13:34:06.588225 2026] [security2:error] [pid 890219:tid 890471] [client 85.204.70.94:59610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuZHoJkCYmL5o6vh9KY3wAAAP4"]
[Thu Jul 30 13:34:06.689008 2026] [security2:error] [pid 890219:tid 890415] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/a5.php"] [unique_id "amuZHoJkCYmL5o6vh9KY4wAAAMY"]
[Thu Jul 30 13:34:06.689153 2026] [security2:error] [pid 890219:tid 890415] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/a5.php"] [unique_id "amuZHoJkCYmL5o6vh9KY4wAAAMY"]
[Thu Jul 30 13:34:06.808338 2026] [security2:error] [pid 890219:tid 890454] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZHoJkCYmL5o6vh9KY1QAA7RE"]
[Thu Jul 30 13:34:06.865326 2026] [security2:error] [pid 890219:tid 890358] [client 85.204.70.94:59612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gfy.nyx.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuZHoJkCYmL5o6vh9KY5AAAAI0"]
[Thu Jul 30 13:34:07.181658 2026] [core:error] [pid 890219:tid 890393] [client 213.180.203.246:53240] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:07.181679 2026] [core:error] [pid 890219:tid 890393] [client 213.180.203.246:53240] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:07.212736 2026] [security2:error] [pid 890219:tid 890417] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ws80.php"] [unique_id "amuZH4JkCYmL5o6vh9KY7QAAAMg"]
[Thu Jul 30 13:34:07.212833 2026] [security2:error] [pid 890219:tid 890417] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ws80.php"] [unique_id "amuZH4JkCYmL5o6vh9KY7QAAAMg"]
[Thu Jul 30 13:34:07.516783 2026] [security2:error] [pid 890219:tid 890403] [client 216.73.216.24:3354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lalibanista.com"] [uri "/index.php"] [unique_id "amuZH4JkCYmL5o6vh9KY8wAAuhQ"]
[Thu Jul 30 13:34:07.544757 2026] [security2:error] [pid 890219:tid 890426] [client 68.221.186.136:10034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuZH4JkCYmL5o6vh9KY9wAAANE"]
[Thu Jul 30 13:34:07.546651 2026] [security2:error] [pid 890219:tid 890363] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.reviewbyjook.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amuZH4JkCYmL5o6vh9KY-AAAAJI"]
[Thu Jul 30 13:34:07.549691 2026] [security2:error] [pid 890219:tid 890345] [remote 216.73.217.142:9637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuZH4JkCYmL5o6vh9KY-QAAtXw"]
[Thu Jul 30 13:34:07.870170 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xa.php"] [unique_id "amuZH4JkCYmL5o6vh9KZAAAAAKs"]
[Thu Jul 30 13:34:07.870289 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xa.php"] [unique_id "amuZH4JkCYmL5o6vh9KZAAAAAKs"]
[Thu Jul 30 13:34:08.173863 2026] [core:error] [pid 890219:tid 890356] [client 5.255.231.32:33850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:08.173889 2026] [core:error] [pid 890219:tid 890356] [client 5.255.231.32:33850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:08.468430 2026] [security2:error] [pid 890219:tid 890370] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/asd67.php"] [unique_id "amuZIIJkCYmL5o6vh9KZEAAAAJk"]
[Thu Jul 30 13:34:08.468541 2026] [security2:error] [pid 890219:tid 890370] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/asd67.php"] [unique_id "amuZIIJkCYmL5o6vh9KZEAAAAJk"]
[Thu Jul 30 13:34:08.861588 2026] [security2:error] [pid 890219:tid 890431] [client 74.248.33.8:32043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/num.php"] [unique_id "amuZIIJkCYmL5o6vh9KZHAAAANY"]
[Thu Jul 30 13:34:09.075273 2026] [security2:error] [pid 890219:tid 890460] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/bk.php"] [unique_id "amuZIYJkCYmL5o6vh9KZIQAAAPM"]
[Thu Jul 30 13:34:09.075395 2026] [security2:error] [pid 890219:tid 890460] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/bk.php"] [unique_id "amuZIYJkCYmL5o6vh9KZIQAAAPM"]
[Thu Jul 30 13:34:09.176767 2026] [core:error] [pid 890219:tid 890409] [client 87.250.224.216:65330] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:09.176789 2026] [core:error] [pid 890219:tid 890409] [client 87.250.224.216:65330] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:34:09.301411 2026] [core:notice] [pid 890219:tid 890390] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:09.772317 2026] [core:notice] [pid 890219:tid 890373] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:10.084208 2026] [security2:error] [pid 890219:tid 890371] [client 74.248.33.8:36687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/images/admin.php"] [unique_id "amuZIoJkCYmL5o6vh9KZUAAAAJo"]
[Thu Jul 30 13:34:10.424535 2026] [security2:error] [pid 890219:tid 890433] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-links.php"] [unique_id "amuZIoJkCYmL5o6vh9KZWQAAANg"]
[Thu Jul 30 13:34:10.424668 2026] [security2:error] [pid 890219:tid 890433] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-links.php"] [unique_id "amuZIoJkCYmL5o6vh9KZWQAAANg"]
[Thu Jul 30 13:34:10.973284 2026] [security2:error] [pid 890219:tid 890438] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mosty.php"] [unique_id "amuZIoJkCYmL5o6vh9KZagAAAN0"]
[Thu Jul 30 13:34:10.973396 2026] [security2:error] [pid 890219:tid 890438] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mosty.php"] [unique_id "amuZIoJkCYmL5o6vh9KZagAAAN0"]
[Thu Jul 30 13:34:11.216566 2026] [security2:error] [pid 890219:tid 890427] [client 78.167.1.90:54277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZI4JkCYmL5o6vh9KZbwAAANI"]
[Thu Jul 30 13:34:11.217054 2026] [security2:error] [pid 890219:tid 890427] [client 78.167.1.90:54277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZI4JkCYmL5o6vh9KZbwAAANI"]
[Thu Jul 30 13:34:11.337178 2026] [proxy:error] [pid 890219:tid 890409] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:11.337237 2026] [proxy_http:error] [pid 890219:tid 890409] [client 98.87.102.177:49383] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:11.337795 2026] [proxy:error] [pid 890219:tid 890409] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:11.337838 2026] [proxy_http:error] [pid 890219:tid 890409] [client 98.87.102.177:49383] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:11.370738 2026] [proxy:error] [pid 890219:tid 890379] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:11.370815 2026] [proxy_http:error] [pid 890219:tid 890379] [client 44.216.125.112:62029] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:11.371391 2026] [proxy:error] [pid 890219:tid 890379] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:11.371437 2026] [proxy_http:error] [pid 890219:tid 890379] [client 44.216.125.112:62029] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:11.481625 2026] [security2:error] [pid 890219:tid 890359] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sump3.php"] [unique_id "amuZI4JkCYmL5o6vh9KZgAAAAI4"]
[Thu Jul 30 13:34:11.481774 2026] [security2:error] [pid 890219:tid 890359] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sump3.php"] [unique_id "amuZI4JkCYmL5o6vh9KZgAAAAI4"]
[Thu Jul 30 13:34:12.036455 2026] [security2:error] [pid 890219:tid 890447] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/first.php"] [unique_id "amuZJIJkCYmL5o6vh9KZlwAAAOY"]
[Thu Jul 30 13:34:12.036606 2026] [security2:error] [pid 890219:tid 890447] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/first.php"] [unique_id "amuZJIJkCYmL5o6vh9KZlwAAAOY"]
[Thu Jul 30 13:34:12.706492 2026] [security2:error] [pid 890219:tid 890405] [client 68.221.186.136:41585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/alfa-rex.php7"] [unique_id "amuZJIJkCYmL5o6vh9KZqwAAALw"]
[Thu Jul 30 13:34:12.711300 2026] [security2:error] [pid 890219:tid 890452] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/acp.php"] [unique_id "amuZJIJkCYmL5o6vh9KZrAAAAOs"]
[Thu Jul 30 13:34:12.711380 2026] [security2:error] [pid 890219:tid 890452] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/acp.php"] [unique_id "amuZJIJkCYmL5o6vh9KZrAAAAOs"]
[Thu Jul 30 13:34:12.917820 2026] [security2:error] [pid 890219:tid 890455] [client 74.248.33.8:29545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuZJIJkCYmL5o6vh9KZsAAAAO4"]
[Thu Jul 30 13:34:13.304601 2026] [security2:error] [pid 890219:tid 890448] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuZJYJkCYmL5o6vh9KZuwAAAOc"]
[Thu Jul 30 13:34:13.304722 2026] [security2:error] [pid 890219:tid 890448] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuZJYJkCYmL5o6vh9KZuwAAAOc"]
[Thu Jul 30 13:34:13.563395 2026] [security2:error] [pid 890219:tid 890359] [client 74.248.33.8:39644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "amuZJYJkCYmL5o6vh9KZxAAAAI4"]
[Thu Jul 30 13:34:14.015250 2026] [security2:error] [pid 890219:tid 890371] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuZJoJkCYmL5o6vh9KZ0AAAAJo"]
[Thu Jul 30 13:34:14.015387 2026] [security2:error] [pid 890219:tid 890371] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuZJoJkCYmL5o6vh9KZ0AAAAJo"]
[Thu Jul 30 13:34:14.290142 2026] [security2:error] [pid 890219:tid 890435] [client 68.221.186.136:41556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/alfanew.php"] [unique_id "amuZJoJkCYmL5o6vh9KZ2AAAANo"]
[Thu Jul 30 13:34:14.517958 2026] [security2:error] [pid 890219:tid 890433] [client 74.248.33.8:15967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/gifclass.php"] [unique_id "amuZJoJkCYmL5o6vh9KZ3gAAANg"]
[Thu Jul 30 13:34:14.545936 2026] [security2:error] [pid 890219:tid 890402] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuZJoJkCYmL5o6vh9KZ4wAAALk"]
[Thu Jul 30 13:34:14.546035 2026] [security2:error] [pid 890219:tid 890402] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuZJoJkCYmL5o6vh9KZ4wAAALk"]
[Thu Jul 30 13:34:14.618635 2026] [security2:error] [pid 890219:tid 890407] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/daerl3.php"] [unique_id "amuZJoJkCYmL5o6vh9KZ5gAAAL4"]
[Thu Jul 30 13:34:14.618727 2026] [security2:error] [pid 890219:tid 890407] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/daerl3.php"] [unique_id "amuZJoJkCYmL5o6vh9KZ5gAAAL4"]
[Thu Jul 30 13:34:15.055694 2026] [security2:error] [pid 890219:tid 890427] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wicked.php"] [unique_id "amuZJ4JkCYmL5o6vh9KZ7wAAANI"]
[Thu Jul 30 13:34:15.055799 2026] [security2:error] [pid 890219:tid 890427] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wicked.php"] [unique_id "amuZJ4JkCYmL5o6vh9KZ7wAAANI"]
[Thu Jul 30 13:34:15.249473 2026] [security2:error] [pid 890219:tid 890457] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/php5.php"] [unique_id "amuZJ4JkCYmL5o6vh9KZ9gAAAPA"]
[Thu Jul 30 13:34:15.249563 2026] [security2:error] [pid 890219:tid 890457] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/php5.php"] [unique_id "amuZJ4JkCYmL5o6vh9KZ9gAAAPA"]
[Thu Jul 30 13:34:15.333498 2026] [proxy:error] [pid 890219:tid 890456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:15.333562 2026] [proxy_http:error] [pid 890219:tid 890456] [client 74.7.241.140:44460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:15.334393 2026] [proxy:error] [pid 890219:tid 890456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:15.334449 2026] [proxy_http:error] [pid 890219:tid 890456] [client 74.7.241.140:44460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:15.334575 2026] [security2:error] [pid 890219:tid 890456] [client 74.7.241.140:44460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.ndn.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuZJ4JkCYmL5o6vh9KZ-gAAAO8"]
[Thu Jul 30 13:34:15.558644 2026] [security2:error] [pid 890219:tid 890423] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wpx.php"] [unique_id "amuZJ4JkCYmL5o6vh9KZ_QAAAM4"]
[Thu Jul 30 13:34:15.558750 2026] [security2:error] [pid 890219:tid 890423] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wpx.php"] [unique_id "amuZJ4JkCYmL5o6vh9KZ_QAAAM4"]
[Thu Jul 30 13:34:15.605340 2026] [security2:error] [pid 890219:tid 890386] [client 68.221.186.136:6589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuZJ4JkCYmL5o6vh9KaAAAAAKk"]
[Thu Jul 30 13:34:15.797792 2026] [security2:error] [pid 890219:tid 890398] [client 74.248.33.8:30794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuZJ4JkCYmL5o6vh9KaDAAAALU"]
[Thu Jul 30 13:34:15.892187 2026] [security2:error] [pid 890219:tid 890351] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xoot.php"] [unique_id "amuZJ4JkCYmL5o6vh9KaDQAAAIY"]
[Thu Jul 30 13:34:15.892294 2026] [security2:error] [pid 890219:tid 890351] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xoot.php"] [unique_id "amuZJ4JkCYmL5o6vh9KaDQAAAIY"]
[Thu Jul 30 13:34:16.068402 2026] [security2:error] [pid 890219:tid 890468] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/images.php"] [unique_id "amuZKIJkCYmL5o6vh9KaDgAAAPs"]
[Thu Jul 30 13:34:16.068549 2026] [security2:error] [pid 890219:tid 890468] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/images.php"] [unique_id "amuZKIJkCYmL5o6vh9KaDgAAAPs"]
[Thu Jul 30 13:34:16.363179 2026] [security2:error] [pid 890219:tid 890365] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZJ4JkCYmL5o6vh9KaBQAAlA8"]
[Thu Jul 30 13:34:16.545875 2026] [security2:error] [pid 890219:tid 890366] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/clxcc.php"] [unique_id "amuZKIJkCYmL5o6vh9KaGwAAAJU"]
[Thu Jul 30 13:34:16.546003 2026] [security2:error] [pid 890219:tid 890366] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/clxcc.php"] [unique_id "amuZKIJkCYmL5o6vh9KaGwAAAJU"]
[Thu Jul 30 13:34:16.574597 2026] [security2:error] [pid 890219:tid 890392] [client 74.248.33.8:36557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/css/index.php"] [unique_id "amuZKIJkCYmL5o6vh9KaHAAAAK8"]
[Thu Jul 30 13:34:16.583325 2026] [security2:error] [pid 890219:tid 890354] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1xmomo.php"] [unique_id "amuZKIJkCYmL5o6vh9KaHQAAAIk"]
[Thu Jul 30 13:34:16.583411 2026] [security2:error] [pid 890219:tid 890354] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1xmomo.php"] [unique_id "amuZKIJkCYmL5o6vh9KaHQAAAIk"]
[Thu Jul 30 13:34:17.097073 2026] [security2:error] [pid 890219:tid 890455] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1revo.php"] [unique_id "amuZKYJkCYmL5o6vh9KaKgAAAO4"]
[Thu Jul 30 13:34:17.097181 2026] [security2:error] [pid 890219:tid 890455] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1revo.php"] [unique_id "amuZKYJkCYmL5o6vh9KaKgAAAO4"]
[Thu Jul 30 13:34:17.211338 2026] [security2:error] [pid 890219:tid 890369] [client 68.221.186.136:12485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuZKYJkCYmL5o6vh9KaLwAAAJg"]
[Thu Jul 30 13:34:17.376692 2026] [security2:error] [pid 890219:tid 890456] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ai.php"] [unique_id "amuZKYJkCYmL5o6vh9KaOAAAAO8"]
[Thu Jul 30 13:34:17.376810 2026] [security2:error] [pid 890219:tid 890456] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ai.php"] [unique_id "amuZKYJkCYmL5o6vh9KaOAAAAO8"]
[Thu Jul 30 13:34:17.640683 2026] [security2:error] [pid 890219:tid 890359] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/cong.php"] [unique_id "amuZKYJkCYmL5o6vh9KaPAAAAI4"]
[Thu Jul 30 13:34:17.640851 2026] [security2:error] [pid 890219:tid 890359] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/cong.php"] [unique_id "amuZKYJkCYmL5o6vh9KaPAAAAI4"]
[Thu Jul 30 13:34:17.842404 2026] [security2:error] [pid 890219:tid 890473] [client 74.7.228.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.okcasino-1.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuZKYJkCYmL5o6vh9KaSAABAB0"]
[Thu Jul 30 13:34:17.916259 2026] [security2:error] [pid 890219:tid 890375] [client 74.248.33.8:30815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-cron.php"] [unique_id "amuZKYJkCYmL5o6vh9KaSQAAAJ4"]
[Thu Jul 30 13:34:18.050760 2026] [security2:error] [pid 890219:tid 890380] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/nwflm.php"] [unique_id "amuZKoJkCYmL5o6vh9KaSwAAAKM"]
[Thu Jul 30 13:34:18.050901 2026] [security2:error] [pid 890219:tid 890380] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/nwflm.php"] [unique_id "amuZKoJkCYmL5o6vh9KaSwAAAKM"]
[Thu Jul 30 13:34:18.272666 2026] [security2:error] [pid 890219:tid 890422] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/a.php"] [unique_id "amuZKoJkCYmL5o6vh9KaUwAAAM0"]
[Thu Jul 30 13:34:18.272764 2026] [security2:error] [pid 890219:tid 890422] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/a.php"] [unique_id "amuZKoJkCYmL5o6vh9KaUwAAAM0"]
[Thu Jul 30 13:34:18.470673 2026] [core:notice] [pid 890219:tid 890345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:18.689405 2026] [security2:error] [pid 890219:tid 890419] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/hypo.php"] [unique_id "amuZKoJkCYmL5o6vh9KaWwAAAMo"]
[Thu Jul 30 13:34:18.689524 2026] [security2:error] [pid 890219:tid 890419] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/hypo.php"] [unique_id "amuZKoJkCYmL5o6vh9KaWwAAAMo"]
[Thu Jul 30 13:34:18.707646 2026] [security2:error] [pid 890219:tid 890429] [client 74.248.33.8:16057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-block.php"] [unique_id "amuZKoJkCYmL5o6vh9KaXQAAANQ"]
[Thu Jul 30 13:34:18.758795 2026] [security2:error] [pid 890219:tid 890405] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/srontol.php"] [unique_id "amuZKoJkCYmL5o6vh9KaYQAAALw"]
[Thu Jul 30 13:34:18.758895 2026] [security2:error] [pid 890219:tid 890405] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/srontol.php"] [unique_id "amuZKoJkCYmL5o6vh9KaYQAAALw"]
[Thu Jul 30 13:34:19.291905 2026] [security2:error] [pid 890219:tid 890460] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/reop3.php"] [unique_id "amuZK4JkCYmL5o6vh9KacAAAAPM"]
[Thu Jul 30 13:34:19.292016 2026] [security2:error] [pid 890219:tid 890460] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/reop3.php"] [unique_id "amuZK4JkCYmL5o6vh9KacAAAAPM"]
[Thu Jul 30 13:34:19.384855 2026] [security2:error] [pid 890219:tid 890352] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuZK4JkCYmL5o6vh9KacQAAAIc"]
[Thu Jul 30 13:34:19.384958 2026] [security2:error] [pid 890219:tid 890352] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuZK4JkCYmL5o6vh9KacQAAAIc"]
[Thu Jul 30 13:34:19.480544 2026] [security2:error] [pid 890219:tid 890391] [client 142.93.53.183:56321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/"] [unique_id "amuZK4JkCYmL5o6vh9KadgAAAK4"]
[Thu Jul 30 13:34:19.859156 2026] [security2:error] [pid 890219:tid 890469] [client 74.248.33.8:21334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/fonts/admin.php"] [unique_id "amuZK4JkCYmL5o6vh9KafgAAAPw"]
[Thu Jul 30 13:34:19.878420 2026] [core:notice] [pid 890219:tid 890458] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:19.997120 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file5.php"] [unique_id "amuZK4JkCYmL5o6vh9KahAAAAKs"]
[Thu Jul 30 13:34:19.997213 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file5.php"] [unique_id "amuZK4JkCYmL5o6vh9KahAAAAKs"]
[Thu Jul 30 13:34:20.078887 2026] [core:notice] [pid 890219:tid 890465] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:20.116748 2026] [security2:error] [pid 890219:tid 890351] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuZLIJkCYmL5o6vh9KaiAAAAIY"]
[Thu Jul 30 13:34:20.116836 2026] [security2:error] [pid 890219:tid 890351] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuZLIJkCYmL5o6vh9KaiAAAAIY"]
[Thu Jul 30 13:34:20.278535 2026] [core:notice] [pid 890219:tid 890415] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:20.301229 2026] [security2:error] [pid 890219:tid 890394] [client 68.221.186.136:8544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-p.php7"] [unique_id "amuZLIJkCYmL5o6vh9KajQAAALE"]
[Thu Jul 30 13:34:20.478206 2026] [core:notice] [pid 890219:tid 890356] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:20.598241 2026] [security2:error] [pid 890219:tid 890366] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/domvf.php"] [unique_id "amuZLIJkCYmL5o6vh9KalwAAAJU"]
[Thu Jul 30 13:34:20.598327 2026] [security2:error] [pid 890219:tid 890366] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/domvf.php"] [unique_id "amuZLIJkCYmL5o6vh9KalwAAAJU"]
[Thu Jul 30 13:34:20.678249 2026] [core:notice] [pid 890219:tid 890392] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:20.808944 2026] [security2:error] [pid 890219:tid 890439] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuZLIJkCYmL5o6vh9KamgAAAN4"]
[Thu Jul 30 13:34:20.809067 2026] [security2:error] [pid 890219:tid 890439] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuZLIJkCYmL5o6vh9KamgAAAN4"]
[Thu Jul 30 13:34:21.049120 2026] [core:notice] [pid 890219:tid 890451] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:21.081253 2026] [security2:error] [pid 890219:tid 890416] [client 142.93.53.183:56333] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ERENUSE/Erencgiapi/perl.Eren"] [unique_id "amuZLYJkCYmL5o6vh9KapQAAAMc"]
[Thu Jul 30 13:34:21.200663 2026] [security2:error] [pid 890219:tid 890397] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zero.php"] [unique_id "amuZLYJkCYmL5o6vh9KapgAAALQ"]
[Thu Jul 30 13:34:21.200820 2026] [security2:error] [pid 890219:tid 890397] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zero.php"] [unique_id "amuZLYJkCYmL5o6vh9KapgAAALQ"]
[Thu Jul 30 13:34:21.461540 2026] [security2:error] [pid 890219:tid 890382] [client 142.93.53.183:56340] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/lib/pkp/lib/vendor/voku/portable-ascii/src/voku/helper/data/ERENUSE/Erencgiapi/perl.Eren"] [unique_id "amuZLYJkCYmL5o6vh9KarAAAAKU"]
[Thu Jul 30 13:34:21.555069 2026] [security2:error] [pid 890219:tid 890390] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fnstall.php"] [unique_id "amuZLYJkCYmL5o6vh9KasgAAAK0"]
[Thu Jul 30 13:34:21.555177 2026] [security2:error] [pid 890219:tid 890390] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fnstall.php"] [unique_id "amuZLYJkCYmL5o6vh9KasgAAAK0"]
[Thu Jul 30 13:34:21.731570 2026] [security2:error] [pid 890219:tid 890369] [client 78.167.1.90:55127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZLYJkCYmL5o6vh9KaswAAAJg"]
[Thu Jul 30 13:34:21.732866 2026] [security2:error] [pid 890219:tid 890369] [client 78.167.1.90:55127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZLYJkCYmL5o6vh9KaswAAAJg"]
[Thu Jul 30 13:34:21.780393 2026] [security2:error] [pid 890219:tid 890456] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/002.php"] [unique_id "amuZLYJkCYmL5o6vh9KatwAAAO8"]
[Thu Jul 30 13:34:21.780507 2026] [security2:error] [pid 890219:tid 890456] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/002.php"] [unique_id "amuZLYJkCYmL5o6vh9KatwAAAO8"]
[Thu Jul 30 13:34:21.846600 2026] [security2:error] [pid 890219:tid 890358] [client 142.93.53.183:56346] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZLYJkCYmL5o6vh9KauQAAAI0"]
[Thu Jul 30 13:34:22.217225 2026] [security2:error] [pid 890219:tid 890411] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/edorxrr.php"] [unique_id "amuZLoJkCYmL5o6vh9KaxgAAAMI"]
[Thu Jul 30 13:34:22.217352 2026] [security2:error] [pid 890219:tid 890411] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/edorxrr.php"] [unique_id "amuZLoJkCYmL5o6vh9KaxgAAAMI"]
[Thu Jul 30 13:34:22.222164 2026] [security2:error] [pid 890219:tid 890436] [client 142.93.53.183:56351] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuZLoJkCYmL5o6vh9KaxwAAANs"]
[Thu Jul 30 13:34:22.322114 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/thoms.php"] [unique_id "amuZLoJkCYmL5o6vh9KayQAAAKs"]
[Thu Jul 30 13:34:22.322223 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/thoms.php"] [unique_id "amuZLoJkCYmL5o6vh9KayQAAAKs"]
[Thu Jul 30 13:34:22.612260 2026] [security2:error] [pid 890219:tid 890364] [client 142.93.53.183:56355] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/Admin/warriors/Admin/pages/modules/datagrid/modules/jscalendar/skins/aqua/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuZLoJkCYmL5o6vh9Ka1wAAAJM"]
[Thu Jul 30 13:34:22.758134 2026] [security2:error] [pid 890219:tid 890224] [remote 216.73.217.142:47902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuZLoJkCYmL5o6vh9Ka2QAAlAM"]
[Thu Jul 30 13:34:22.800089 2026] [security2:error] [pid 890219:tid 890376] [client 68.221.186.136:13140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuZLoJkCYmL5o6vh9Ka2gAAAJ8"]
[Thu Jul 30 13:34:22.835158 2026] [security2:error] [pid 890219:tid 890372] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/setup.php"] [unique_id "amuZLoJkCYmL5o6vh9Ka2wAAAJs"]
[Thu Jul 30 13:34:22.835273 2026] [security2:error] [pid 890219:tid 890372] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/setup.php"] [unique_id "amuZLoJkCYmL5o6vh9Ka2wAAAJs"]
[Thu Jul 30 13:34:22.836622 2026] [security2:error] [pid 890219:tid 890435] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fi22.php"] [unique_id "amuZLoJkCYmL5o6vh9Ka3AAAANo"]
[Thu Jul 30 13:34:22.836692 2026] [security2:error] [pid 890219:tid 890435] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fi22.php"] [unique_id "amuZLoJkCYmL5o6vh9Ka3AAAANo"]
[Thu Jul 30 13:34:22.893652 2026] [security2:error] [pid 890219:tid 890392] [client 74.248.33.8:15716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/classwithtostring.php"] [unique_id "amuZLoJkCYmL5o6vh9Ka3gAAAK8"]
[Thu Jul 30 13:34:23.002945 2026] [security2:error] [pid 890219:tid 890453] [client 142.93.53.183:56361] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZL4JkCYmL5o6vh9Ka4wAAAOw"]
[Thu Jul 30 13:34:23.377941 2026] [security2:error] [pid 890219:tid 890418] [client 142.93.53.183:56368] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZL4JkCYmL5o6vh9Ka6QAAAMk"]
[Thu Jul 30 13:34:23.386690 2026] [security2:error] [pid 890219:tid 890269] [remote 57.141.0.43:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuZL4JkCYmL5o6vh9Ka6gAA6jA"]
[Thu Jul 30 13:34:23.476000 2026] [security2:error] [pid 890219:tid 890455] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZL4JkCYmL5o6vh9Ka7AAAAO4"]
[Thu Jul 30 13:34:23.561201 2026] [security2:error] [pid 890219:tid 890355] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/6.php"] [unique_id "amuZL4JkCYmL5o6vh9Ka8QAAAIo"]
[Thu Jul 30 13:34:23.561303 2026] [security2:error] [pid 890219:tid 890355] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/6.php"] [unique_id "amuZL4JkCYmL5o6vh9Ka8QAAAIo"]
[Thu Jul 30 13:34:23.768567 2026] [security2:error] [pid 890219:tid 890440] [client 142.93.53.183:56376] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wp-content/cache/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZL4JkCYmL5o6vh9Ka-AAAAN8"]
[Thu Jul 30 13:34:23.869784 2026] [security2:error] [pid 890219:tid 890391] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZL4JkCYmL5o6vh9Ka_QAAAK4"]
[Thu Jul 30 13:34:24.039758 2026] [security2:error] [pid 890219:tid 890431] [client 74.248.33.8:30845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/test1.php"] [unique_id "amuZMIJkCYmL5o6vh9Ka_wAAANY"]
[Thu Jul 30 13:34:24.143627 2026] [security2:error] [pid 890219:tid 890437] [client 142.93.53.183:56382] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wp-content/wflogs/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZMIJkCYmL5o6vh9KbBgAAANw"]
[Thu Jul 30 13:34:24.165820 2026] [security2:error] [pid 890219:tid 890425] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/82.php"] [unique_id "amuZMIJkCYmL5o6vh9KbBwAAANA"]
[Thu Jul 30 13:34:24.165916 2026] [security2:error] [pid 890219:tid 890425] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/82.php"] [unique_id "amuZMIJkCYmL5o6vh9KbBwAAANA"]
[Thu Jul 30 13:34:24.462860 2026] [security2:error] [pid 890219:tid 890373] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w3lls.php"] [unique_id "amuZMIJkCYmL5o6vh9KbDAAAAJw"]
[Thu Jul 30 13:34:24.462996 2026] [security2:error] [pid 890219:tid 890373] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w3lls.php"] [unique_id "amuZMIJkCYmL5o6vh9KbDAAAAJw"]
[Thu Jul 30 13:34:24.531345 2026] [security2:error] [pid 890219:tid 890379] [client 142.93.53.183:56390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wp-content/wpo-cache/ALFA_DATA/alfacgiapi/perl.alfa/"] [unique_id "amuZMIJkCYmL5o6vh9KbDwAAAKI"]
[Thu Jul 30 13:34:24.816568 2026] [security2:error] [pid 890219:tid 890396] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sx.php"] [unique_id "amuZMIJkCYmL5o6vh9KbGwAAALM"]
[Thu Jul 30 13:34:24.816680 2026] [security2:error] [pid 890219:tid 890396] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sx.php"] [unique_id "amuZMIJkCYmL5o6vh9KbGwAAALM"]
[Thu Jul 30 13:34:24.858919 2026] [security2:error] [pid 890219:tid 890404] [client 74.248.33.8:24194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/images/index.php"] [unique_id "amuZMIJkCYmL5o6vh9KbHAAAALs"]
[Thu Jul 30 13:34:24.924697 2026] [security2:error] [pid 890219:tid 890435] [client 142.93.53.183:56398] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wp-content/wpo-cache/config/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZMIJkCYmL5o6vh9KbHQAAANo"]
[Thu Jul 30 13:34:25.204955 2026] [security2:error] [pid 890219:tid 890464] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/99.php"] [unique_id "amuZMYJkCYmL5o6vh9KbJwAAAPc"]
[Thu Jul 30 13:34:25.205075 2026] [security2:error] [pid 890219:tid 890464] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/99.php"] [unique_id "amuZMYJkCYmL5o6vh9KbJwAAAPc"]
[Thu Jul 30 13:34:25.249527 2026] [security2:error] [pid 890219:tid 890398] [client 68.221.186.136:11982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuZMYJkCYmL5o6vh9KbKQAAALU"]
[Thu Jul 30 13:34:25.303543 2026] [security2:error] [pid 890219:tid 890402] [client 142.93.53.183:56408] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wp-content/updraft/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZMYJkCYmL5o6vh9KbKgAAALk"]
[Thu Jul 30 13:34:25.340024 2026] [security2:error] [pid 890219:tid 890350] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/dex.php"] [unique_id "amuZMYJkCYmL5o6vh9KbKwAAAIU"]
[Thu Jul 30 13:34:25.340168 2026] [security2:error] [pid 890219:tid 890350] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/dex.php"] [unique_id "amuZMYJkCYmL5o6vh9KbKwAAAIU"]
[Thu Jul 30 13:34:25.688086 2026] [security2:error] [pid 890219:tid 890470] [client 142.93.53.183:56414] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wp-content/mu-plugins/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZMYJkCYmL5o6vh9KbNAAAAP0"]
[Thu Jul 30 13:34:25.832657 2026] [security2:error] [pid 890219:tid 890456] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/admin.php"] [unique_id "amuZMYJkCYmL5o6vh9KbOwAAAO8"]
[Thu Jul 30 13:34:25.832772 2026] [security2:error] [pid 890219:tid 890456] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/admin.php"] [unique_id "amuZMYJkCYmL5o6vh9KbOwAAAO8"]
[Thu Jul 30 13:34:25.858849 2026] [security2:error] [pid 890219:tid 890378] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fpwch.php"] [unique_id "amuZMYJkCYmL5o6vh9KbPAAAAKE"]
[Thu Jul 30 13:34:25.858940 2026] [security2:error] [pid 890219:tid 890378] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fpwch.php"] [unique_id "amuZMYJkCYmL5o6vh9KbPAAAAKE"]
[Thu Jul 30 13:34:26.014555 2026] [security2:error] [pid 890219:tid 890460] [client 68.221.186.136:13161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.worldofwhiskers.com"] [uri "/wp-content/repeater.php"] [unique_id "amuZMoJkCYmL5o6vh9KbPQAAAPM"]
[Thu Jul 30 13:34:26.069098 2026] [security2:error] [pid 890219:tid 890448] [client 142.93.53.183:56425] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wp-content/backups-dup-lite/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZMoJkCYmL5o6vh9KbPwAAAOc"]
[Thu Jul 30 13:34:26.457926 2026] [security2:error] [pid 890219:tid 890420] [client 142.93.53.183:56433] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wp-content/backups-dup-lite/tmp/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZMoJkCYmL5o6vh9KbSAAAAMs"]
[Thu Jul 30 13:34:26.505445 2026] [security2:error] [pid 890219:tid 890362] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/media.php"] [unique_id "amuZMoJkCYmL5o6vh9KbSQAAAJE"]
[Thu Jul 30 13:34:26.505567 2026] [security2:error] [pid 890219:tid 890362] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/media.php"] [unique_id "amuZMoJkCYmL5o6vh9KbSQAAAJE"]
[Thu Jul 30 13:34:26.577194 2026] [security2:error] [pid 890219:tid 890339] [remote 18.206.47.187:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "fantasynamelist.com"] [uri "/"] [unique_id "amuZMoJkCYmL5o6vh9KbSgAAsHY"]
[Thu Jul 30 13:34:26.699925 2026] [core:notice] [pid 890219:tid 890313] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:26.844724 2026] [security2:error] [pid 890219:tid 890351] [client 142.93.53.183:56441] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/alfacgiapi/perl.alfa"] [unique_id "amuZMoJkCYmL5o6vh9KbVAAAAIY"]
[Thu Jul 30 13:34:26.866269 2026] [security2:error] [pid 890219:tid 890468] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/black.php"] [unique_id "amuZMoJkCYmL5o6vh9KbVgAAAPs"]
[Thu Jul 30 13:34:26.866379 2026] [security2:error] [pid 890219:tid 890468] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/black.php"] [unique_id "amuZMoJkCYmL5o6vh9KbVgAAAPs"]
[Thu Jul 30 13:34:27.219862 2026] [security2:error] [pid 890219:tid 890356] [client 142.93.53.183:56449] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/libraries/smartslider3/GODEST/zestcgiapi/py.zest"] [unique_id "amuZM4JkCYmL5o6vh9KbWwAAAIs"]
[Thu Jul 30 13:34:27.331324 2026] [core:notice] [pid 890219:tid 890328] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:27.415881 2026] [security2:error] [pid 890219:tid 890413] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/loader.php"] [unique_id "amuZM4JkCYmL5o6vh9KbZAAAAMQ"]
[Thu Jul 30 13:34:27.415998 2026] [security2:error] [pid 890219:tid 890413] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/loader.php"] [unique_id "amuZM4JkCYmL5o6vh9KbZAAAAMQ"]
[Thu Jul 30 13:34:27.437887 2026] [security2:error] [pid 890219:tid 890453] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuZM4JkCYmL5o6vh9KbZQAAAOw"]
[Thu Jul 30 13:34:27.437996 2026] [security2:error] [pid 890219:tid 890453] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuZM4JkCYmL5o6vh9KbZQAAAOw"]
[Thu Jul 30 13:34:27.526234 2026] [security2:error] [pid 890219:tid 890406] [client 74.248.33.8:36572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/asd.php"] [unique_id "amuZM4JkCYmL5o6vh9KbZwAAAL0"]
[Thu Jul 30 13:34:27.612201 2026] [security2:error] [pid 890219:tid 890461] [client 142.93.53.183:56456] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/libraries/smartslider3/GODEST/zestcgiapi/perl.zest"] [unique_id "amuZM4JkCYmL5o6vh9KbaAAAAPQ"]
[Thu Jul 30 13:34:27.759256 2026] [security2:error] [pid 890219:tid 890305] [remote 216.73.217.142:47902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuZM4JkCYmL5o6vh9KbbwAA2VQ"]
[Thu Jul 30 13:34:27.930220 2026] [security2:error] [pid 890219:tid 890397] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file61.php"] [unique_id "amuZM4JkCYmL5o6vh9KbdAAAALQ"]
[Thu Jul 30 13:34:27.930346 2026] [security2:error] [pid 890219:tid 890397] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file61.php"] [unique_id "amuZM4JkCYmL5o6vh9KbdAAAALQ"]
[Thu Jul 30 13:34:28.002700 2026] [security2:error] [pid 890219:tid 890447] [client 142.93.53.183:56467] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/libraries/smartslider3/GODEST/zestcgiapi/bash.zest"] [unique_id "amuZNIJkCYmL5o6vh9KbdQAAAOY"]
[Thu Jul 30 13:34:28.106172 2026] [security2:error] [pid 890219:tid 890361] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/222.php"] [unique_id "amuZNIJkCYmL5o6vh9KbdgAAAJA"]
[Thu Jul 30 13:34:28.106292 2026] [security2:error] [pid 890219:tid 890361] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/222.php"] [unique_id "amuZNIJkCYmL5o6vh9KbdgAAAJA"]
[Thu Jul 30 13:34:28.176302 2026] [security2:error] [pid 890219:tid 890452] [client 74.248.33.8:37300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/customize/index.php"] [unique_id "amuZNIJkCYmL5o6vh9KbdwAAAOs"]
[Thu Jul 30 13:34:28.383354 2026] [security2:error] [pid 890219:tid 890474] [client 142.93.53.183:56475] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/.tmb/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZNIJkCYmL5o6vh9KbhQAAAQE"]
[Thu Jul 30 13:34:28.593638 2026] [security2:error] [pid 890219:tid 890391] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-css.php"] [unique_id "amuZNIJkCYmL5o6vh9KbhwAAAK4"]
[Thu Jul 30 13:34:28.593731 2026] [security2:error] [pid 890219:tid 890391] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-css.php"] [unique_id "amuZNIJkCYmL5o6vh9KbhwAAAK4"]
[Thu Jul 30 13:34:28.767021 2026] [security2:error] [pid 890219:tid 890386] [client 142.93.53.183:56484] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/.well-known/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZNIJkCYmL5o6vh9KbiwAAAKk"]
[Thu Jul 30 13:34:28.782496 2026] [security2:error] [pid 890219:tid 890431] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-load.php"] [unique_id "amuZNIJkCYmL5o6vh9KbjAAAANY"]
[Thu Jul 30 13:34:28.782610 2026] [security2:error] [pid 890219:tid 890431] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-load.php"] [unique_id "amuZNIJkCYmL5o6vh9KbjAAAANY"]
[Thu Jul 30 13:34:28.793889 2026] [security2:error] [pid 890219:tid 890430] [client 74.248.33.8:36678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuZNIJkCYmL5o6vh9KbjQAAANU"]
[Thu Jul 30 13:34:29.159178 2026] [security2:error] [pid 890219:tid 890403] [client 142.93.53.183:56490] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZNYJkCYmL5o6vh9KblQAAALo"]
[Thu Jul 30 13:34:29.421204 2026] [security2:error] [pid 890219:tid 890411] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuZNYJkCYmL5o6vh9KbmQAAAMI"]
[Thu Jul 30 13:34:29.421324 2026] [security2:error] [pid 890219:tid 890411] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuZNYJkCYmL5o6vh9KbmQAAAMI"]
[Thu Jul 30 13:34:29.549620 2026] [security2:error] [pid 890219:tid 890415] [client 142.93.53.183:56498] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZNYJkCYmL5o6vh9KbmwAAAMY"]
[Thu Jul 30 13:34:29.601029 2026] [security2:error] [pid 890219:tid 890394] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-blink.php"] [unique_id "amuZNYJkCYmL5o6vh9KbnAAAALE"]
[Thu Jul 30 13:34:29.601164 2026] [security2:error] [pid 890219:tid 890394] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-blink.php"] [unique_id "amuZNYJkCYmL5o6vh9KbnAAAALE"]
[Thu Jul 30 13:34:29.941860 2026] [security2:error] [pid 890219:tid 890476] [client 142.93.53.183:56505] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/word/alfacgiapi/perl.alfa"] [unique_id "amuZNYJkCYmL5o6vh9KbpwAAAQM"]
[Thu Jul 30 13:34:30.072425 2026] [security2:error] [pid 890219:tid 890439] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZNoJkCYmL5o6vh9KbqgAAAN4"]
[Thu Jul 30 13:34:30.072564 2026] [security2:error] [pid 890219:tid 890439] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZNoJkCYmL5o6vh9KbqgAAAN4"]
[Thu Jul 30 13:34:30.143574 2026] [security2:error] [pid 890219:tid 890371] [client 74.248.33.8:36728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/atomlib.php"] [unique_id "amuZNoJkCYmL5o6vh9KbqwAAAJo"]
[Thu Jul 30 13:34:30.170871 2026] [security2:error] [pid 890219:tid 890472] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/txets.php"] [unique_id "amuZNoJkCYmL5o6vh9KbrAAAAP8"]
[Thu Jul 30 13:34:30.170973 2026] [security2:error] [pid 890219:tid 890472] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/txets.php"] [unique_id "amuZNoJkCYmL5o6vh9KbrAAAAP8"]
[Thu Jul 30 13:34:30.218660 2026] [core:notice] [pid 890219:tid 890380] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:30.223881 2026] [security2:error] [pid 890219:tid 890380] [client 66.249.79.2:48016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/481"] [unique_id "amuZNYJkCYmL5o6vh9KbqAAAAKM"]
[Thu Jul 30 13:34:30.268377 2026] [core:notice] [pid 890219:tid 890446] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:30.332732 2026] [security2:error] [pid 890219:tid 890450] [client 142.93.53.183:56515] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/word/alfacgiapi/py.alfa"] [unique_id "amuZNoJkCYmL5o6vh9KbsQAAAOk"]
[Thu Jul 30 13:34:30.666050 2026] [security2:error] [pid 890219:tid 890398] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/pucci.php"] [unique_id "amuZNoJkCYmL5o6vh9KbuQAAALU"]
[Thu Jul 30 13:34:30.666179 2026] [security2:error] [pid 890219:tid 890398] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/pucci.php"] [unique_id "amuZNoJkCYmL5o6vh9KbuQAAALU"]
[Thu Jul 30 13:34:30.720400 2026] [security2:error] [pid 890219:tid 890397] [client 142.93.53.183:56522] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/word/alfacgiapi/bash.alfa"] [unique_id "amuZNoJkCYmL5o6vh9KbugAAALQ"]
[Thu Jul 30 13:34:30.728697 2026] [security2:error] [pid 890219:tid 890447] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/memberfuns.php"] [unique_id "amuZNoJkCYmL5o6vh9KbuwAAAOY"]
[Thu Jul 30 13:34:30.728885 2026] [security2:error] [pid 890219:tid 890447] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/memberfuns.php"] [unique_id "amuZNoJkCYmL5o6vh9KbuwAAAOY"]
[Thu Jul 30 13:34:31.109646 2026] [security2:error] [pid 890219:tid 890460] [client 142.93.53.183:56533] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/dist/editor/ckfinder/core/connector/RIMURU/rimurucgiapi/perl.rimuru"] [unique_id "amuZN4JkCYmL5o6vh9KbxQAAAPM"]
[Thu Jul 30 13:34:31.193910 2026] [security2:error] [pid 890219:tid 890432] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xwpg.php"] [unique_id "amuZN4JkCYmL5o6vh9KbxgAAANc"]
[Thu Jul 30 13:34:31.194046 2026] [security2:error] [pid 890219:tid 890432] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xwpg.php"] [unique_id "amuZN4JkCYmL5o6vh9KbxgAAANc"]
[Thu Jul 30 13:34:31.363110 2026] [security2:error] [pid 890219:tid 890359] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/orange3.php"] [unique_id "amuZN4JkCYmL5o6vh9KbzQAAAI4"]
[Thu Jul 30 13:34:31.363238 2026] [security2:error] [pid 890219:tid 890359] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/orange3.php"] [unique_id "amuZN4JkCYmL5o6vh9KbzQAAAI4"]
[Thu Jul 30 13:34:31.500441 2026] [security2:error] [pid 890219:tid 890403] [client 142.93.53.183:56542] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/dist/editor/ckfinder/core/connector/RIMURU/rimurucgiapi/py.rimuru"] [unique_id "amuZN4JkCYmL5o6vh9Kb1AAAALo"]
[Thu Jul 30 13:34:31.729928 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ops.php"] [unique_id "amuZN4JkCYmL5o6vh9Kb1QAAAKs"]
[Thu Jul 30 13:34:31.730053 2026] [security2:error] [pid 890219:tid 890388] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ops.php"] [unique_id "amuZN4JkCYmL5o6vh9Kb1QAAAKs"]
[Thu Jul 30 13:34:31.875248 2026] [security2:error] [pid 890219:tid 890420] [client 142.93.53.183:56547] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/dist/editor/ckfinder/core/connector/RIMURU/rimurucgiapi/bash.rimuru"] [unique_id "amuZN4JkCYmL5o6vh9Kb2QAAAMs"]
[Thu Jul 30 13:34:32.127662 2026] [security2:error] [pid 890219:tid 890357] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb4QAAAIw"]
[Thu Jul 30 13:34:32.127777 2026] [security2:error] [pid 890219:tid 890357] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb4QAAAIw"]
[Thu Jul 30 13:34:32.236303 2026] [security2:error] [pid 890219:tid 890404] [client 52.165.196.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb4wAAALs"]
[Thu Jul 30 13:34:32.236432 2026] [security2:error] [pid 890219:tid 890404] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb4wAAALs"]
[Thu Jul 30 13:34:32.236569 2026] [security2:error] [pid 890219:tid 890404] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/1.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb4wAAALs"]
[Thu Jul 30 13:34:32.269945 2026] [security2:error] [pid 890219:tid 890353] [client 142.93.53.183:56549] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuZOIJkCYmL5o6vh9Kb5AAAAIg"]
[Thu Jul 30 13:34:32.319755 2026] [security2:error] [pid 890219:tid 890422] [client 78.167.1.90:53473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb5QAAAM0"]
[Thu Jul 30 13:34:32.319894 2026] [security2:error] [pid 890219:tid 890422] [client 78.167.1.90:53473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb5QAAAM0"]
[Thu Jul 30 13:34:32.659349 2026] [security2:error] [pid 890219:tid 890407] [client 142.93.53.183:56558] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/public/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/perl.alfa"] [unique_id "amuZOIJkCYmL5o6vh9Kb8AAAAL4"]
[Thu Jul 30 13:34:32.744556 2026] [security2:error] [pid 890219:tid 890402] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb9AAAALk"]
[Thu Jul 30 13:34:32.744696 2026] [security2:error] [pid 890219:tid 890402] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mac.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb9AAAALk"]
[Thu Jul 30 13:34:32.769401 2026] [security2:error] [pid 890219:tid 890368] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb9QAAAJc"]
[Thu Jul 30 13:34:32.769507 2026] [security2:error] [pid 890219:tid 890368] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuZOIJkCYmL5o6vh9Kb9QAAAJc"]
[Thu Jul 30 13:34:32.784820 2026] [core:notice] [pid 890219:tid 890427] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:33.049797 2026] [security2:error] [pid 890219:tid 890387] [client 142.93.53.183:56569] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuZOYJkCYmL5o6vh9KcAgAAAKo"]
[Thu Jul 30 13:34:33.311114 2026] [security2:error] [pid 890219:tid 890381] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZOYJkCYmL5o6vh9KcBQAAAKQ"]
[Thu Jul 30 13:34:33.311228 2026] [security2:error] [pid 890219:tid 890381] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZOYJkCYmL5o6vh9KcBQAAAKQ"]
[Thu Jul 30 13:34:33.390653 2026] [security2:error] [pid 890219:tid 890448] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/crgio.php"] [unique_id "amuZOYJkCYmL5o6vh9KcCQAAAOc"]
[Thu Jul 30 13:34:33.390776 2026] [security2:error] [pid 890219:tid 890448] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/crgio.php"] [unique_id "amuZOYJkCYmL5o6vh9KcCQAAAOc"]
[Thu Jul 30 13:34:33.422081 2026] [security2:error] [pid 890219:tid 890431] [client 142.93.53.183:56580] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/public/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/py.alfa"] [unique_id "amuZOYJkCYmL5o6vh9KcCwAAANY"]
[Thu Jul 30 13:34:33.799997 2026] [security2:error] [pid 890219:tid 890467] [client 142.93.53.183:56593] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuZOYJkCYmL5o6vh9KcGQAAAPo"]
[Thu Jul 30 13:34:34.022022 2026] [security2:error] [pid 890219:tid 890404] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ws13.php"] [unique_id "amuZOoJkCYmL5o6vh9KcJAAAALs"]
[Thu Jul 30 13:34:34.022141 2026] [security2:error] [pid 890219:tid 890404] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ws13.php"] [unique_id "amuZOoJkCYmL5o6vh9KcJAAAALs"]
[Thu Jul 30 13:34:34.039851 2026] [security2:error] [pid 890219:tid 890422] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuZOoJkCYmL5o6vh9KcJQAAAM0"]
[Thu Jul 30 13:34:34.039937 2026] [security2:error] [pid 890219:tid 890422] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/aa.php"] [unique_id "amuZOoJkCYmL5o6vh9KcJQAAAM0"]
[Thu Jul 30 13:34:34.190942 2026] [security2:error] [pid 890219:tid 890476] [client 142.93.53.183:56603] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/public/assets/admin/fonts/vazir/Without-Latin/HYBRID_THEORY/hybridcgiapi/bash.alfa"] [unique_id "amuZOoJkCYmL5o6vh9KcJgAAAQM"]
[Thu Jul 30 13:34:34.578500 2026] [security2:error] [pid 890219:tid 890408] [client 142.93.53.183:56629] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/public/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZOoJkCYmL5o6vh9KcMgAAAL8"]
[Thu Jul 30 13:34:34.622308 2026] [security2:error] [pid 890219:tid 890407] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xyn.php"] [unique_id "amuZOoJkCYmL5o6vh9KcMwAAAL4"]
[Thu Jul 30 13:34:34.622408 2026] [security2:error] [pid 890219:tid 890407] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xyn.php"] [unique_id "amuZOoJkCYmL5o6vh9KcMwAAAL4"]
[Thu Jul 30 13:34:34.684424 2026] [security2:error] [pid 890219:tid 890434] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/srontol.php"] [unique_id "amuZOoJkCYmL5o6vh9KcNAAAANk"]
[Thu Jul 30 13:34:34.684578 2026] [security2:error] [pid 890219:tid 890434] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/srontol.php"] [unique_id "amuZOoJkCYmL5o6vh9KcNAAAANk"]
[Thu Jul 30 13:34:34.921966 2026] [security2:error] [pid 890219:tid 890427] [client 74.248.33.8:16031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuZOoJkCYmL5o6vh9KcOwAAANI"]
[Thu Jul 30 13:34:34.971925 2026] [security2:error] [pid 890219:tid 890361] [client 142.93.53.183:56646] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZOoJkCYmL5o6vh9KcPAAAAJA"]
[Thu Jul 30 13:34:35.140779 2026] [security2:error] [pid 890219:tid 890355] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-wp.php"] [unique_id "amuZO4JkCYmL5o6vh9KcQgAAAIo"]
[Thu Jul 30 13:34:35.140878 2026] [security2:error] [pid 890219:tid 890355] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-wp.php"] [unique_id "amuZO4JkCYmL5o6vh9KcQgAAAIo"]
[Thu Jul 30 13:34:35.329538 2026] [security2:error] [pid 890219:tid 890263] [remote 216.38.28.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skilledfurnituremoversuae.com"] [uri "/xmlrpc.php"] [unique_id "amuZO4JkCYmL5o6vh9KcRAAAtSo"]
[Thu Jul 30 13:34:35.329696 2026] [security2:error] [pid 890219:tid 890398] [client 216.38.28.47:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skilledfurnituremoversuae.com"] [uri "/xmlrpc.php"] [unique_id "amuZO4JkCYmL5o6vh9KcRAAAtSo"]
[Thu Jul 30 13:34:35.343970 2026] [security2:error] [pid 890219:tid 890410] [client 142.93.53.183:56661] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/public/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuZO4JkCYmL5o6vh9KcRQAAAME"]
[Thu Jul 30 13:34:35.371778 2026] [security2:error] [pid 890219:tid 890369] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuZO4JkCYmL5o6vh9KcRgAAAJg"]
[Thu Jul 30 13:34:35.371876 2026] [security2:error] [pid 890219:tid 890369] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuZO4JkCYmL5o6vh9KcRgAAAJg"]
[Thu Jul 30 13:34:35.658601 2026] [security2:error] [pid 890219:tid 890403] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/aw.php"] [unique_id "amuZO4JkCYmL5o6vh9KcTgAAALo"]
[Thu Jul 30 13:34:35.658678 2026] [security2:error] [pid 890219:tid 890403] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/aw.php"] [unique_id "amuZO4JkCYmL5o6vh9KcTgAAALo"]
[Thu Jul 30 13:34:35.738926 2026] [security2:error] [pid 890219:tid 890360] [client 142.93.53.183:56672] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuZO4JkCYmL5o6vh9KcUgAAAI8"]
[Thu Jul 30 13:34:36.010409 2026] [security2:error] [pid 890219:tid 890375] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ingfo.php"] [unique_id "amuZPIJkCYmL5o6vh9KcVwAAAJ4"]
[Thu Jul 30 13:34:36.010517 2026] [security2:error] [pid 890219:tid 890375] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ingfo.php"] [unique_id "amuZPIJkCYmL5o6vh9KcVwAAAJ4"]
[Thu Jul 30 13:34:36.127639 2026] [security2:error] [pid 890219:tid 890415] [client 142.93.53.183:56687] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/dist/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZPIJkCYmL5o6vh9KcWgAAAMY"]
[Thu Jul 30 13:34:36.191130 2026] [security2:error] [pid 890219:tid 890394] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuZPIJkCYmL5o6vh9KcXQAAALE"]
[Thu Jul 30 13:34:36.191287 2026] [security2:error] [pid 890219:tid 890394] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/classwithtostring.php"] [unique_id "amuZPIJkCYmL5o6vh9KcXQAAALE"]
[Thu Jul 30 13:34:36.509188 2026] [security2:error] [pid 890219:tid 890379] [client 142.93.53.183:56701] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/dist/css/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuZPIJkCYmL5o6vh9KcZQAAAKI"]
[Thu Jul 30 13:34:36.682329 2026] [security2:error] [pid 890219:tid 890413] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ey5.php"] [unique_id "amuZPIJkCYmL5o6vh9KcagAAAMQ"]
[Thu Jul 30 13:34:36.682447 2026] [security2:error] [pid 890219:tid 890413] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ey5.php"] [unique_id "amuZPIJkCYmL5o6vh9KcagAAAMQ"]
[Thu Jul 30 13:34:36.777118 2026] [security2:error] [pid 890219:tid 890399] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yawa.php"] [unique_id "amuZPIJkCYmL5o6vh9KccQAAALY"]
[Thu Jul 30 13:34:36.777205 2026] [security2:error] [pid 890219:tid 890399] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yawa.php"] [unique_id "amuZPIJkCYmL5o6vh9KccQAAALY"]
[Thu Jul 30 13:34:36.893521 2026] [security2:error] [pid 890219:tid 890438] [client 142.93.53.183:56718] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/dist/css/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuZPIJkCYmL5o6vh9KccgAAAN0"]
[Thu Jul 30 13:34:36.906094 2026] [security2:error] [pid 890219:tid 890368] [client 74.248.33.8:24198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/inputs.php"] [unique_id "amuZPIJkCYmL5o6vh9KccwAAAJc"]
[Thu Jul 30 13:34:37.270503 2026] [security2:error] [pid 890219:tid 890470] [client 142.93.53.183:56732] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/public/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuZPYJkCYmL5o6vh9KcegAAAP0"]
[Thu Jul 30 13:34:37.308495 2026] [security2:error] [pid 890219:tid 890355] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fine.php"] [unique_id "amuZPYJkCYmL5o6vh9KcfgAAAIo"]
[Thu Jul 30 13:34:37.308604 2026] [security2:error] [pid 890219:tid 890355] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fine.php"] [unique_id "amuZPYJkCYmL5o6vh9KcfgAAAIo"]
[Thu Jul 30 13:34:37.632754 2026] [security2:error] [pid 890219:tid 890466] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sym403.php"] [unique_id "amuZPYJkCYmL5o6vh9KcggAAAPk"]
[Thu Jul 30 13:34:37.632846 2026] [security2:error] [pid 890219:tid 890466] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sym403.php"] [unique_id "amuZPYJkCYmL5o6vh9KcggAAAPk"]
[Thu Jul 30 13:34:37.658927 2026] [security2:error] [pid 890219:tid 890369] [client 142.93.53.183:56745] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/vendors/summernote/font/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuZPYJkCYmL5o6vh9KcgwAAAJg"]
[Thu Jul 30 13:34:38.450594 2026] [http2:info] [pid 914912:tid 914912] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 13:34:38.465183 2026] [security2:error] [pid 914912:tid 915042] [client 142.93.53.183:56759] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/help/en_US/bibliography/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZPq469-jfU7M1CLhEcwAAAAA"]
[Thu Jul 30 13:34:38.475370 2026] [security2:error] [pid 914912:tid 915043] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZPq469-jfU7M1CLhEdAAAAAE"]
[Thu Jul 30 13:34:38.848479 2026] [security2:error] [pid 914912:tid 915070] [client 142.93.53.183:56794] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/admin/default/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZPq469-jfU7M1CLhEgwAAABw"]
[Thu Jul 30 13:34:39.001905 2026] [security2:error] [pid 914912:tid 915059] [client 74.248.33.8:15946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/index.php"] [unique_id "amuZP6469-jfU7M1CLhEhAAAABE"]
[Thu Jul 30 13:34:39.237135 2026] [security2:error] [pid 914912:tid 915091] [client 142.93.53.183:56808] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/images/.../LEVIATHAN/haxorcgiapi/perl.haxor"] [unique_id "amuZP6469-jfU7M1CLhEjgAAADE"]
[Thu Jul 30 13:34:39.246813 2026] [security2:error] [pid 914912:tid 915092] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZP6469-jfU7M1CLhEjwAAADI"]
[Thu Jul 30 13:34:39.509186 2026] [security2:error] [pid 914912:tid 915108] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/adminner.php"] [unique_id "amuZP6469-jfU7M1CLhEmgAAAEI"]
[Thu Jul 30 13:34:39.509337 2026] [security2:error] [pid 914912:tid 915108] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/adminner.php"] [unique_id "amuZP6469-jfU7M1CLhEmgAAAEI"]
[Thu Jul 30 13:34:39.516807 2026] [proxy:error] [pid 914912:tid 915110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:39.516935 2026] [proxy_http:error] [pid 914912:tid 915110] [client 34.233.129.35:27066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:39.517585 2026] [proxy:error] [pid 914912:tid 915110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:39.517631 2026] [proxy_http:error] [pid 914912:tid 915110] [client 34.233.129.35:27066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:39.529647 2026] [proxy:error] [pid 914912:tid 915112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:39.529729 2026] [proxy_http:error] [pid 914912:tid 915112] [client 34.233.129.35:14563] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:39.530854 2026] [proxy:error] [pid 914912:tid 915112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:39.530921 2026] [proxy_http:error] [pid 914912:tid 915112] [client 34.233.129.35:14563] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:39.625665 2026] [security2:error] [pid 914912:tid 915121] [client 142.93.53.183:56821] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/help/en_US/bibliography/SEOBARBAR_DATA/alfacgiapi/bash.alfa"] [unique_id "amuZP6469-jfU7M1CLhEogAAAE8"]
[Thu Jul 30 13:34:39.660761 2026] [security2:error] [pid 914912:tid 915099] [client 74.248.33.8:36697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/network/index.php"] [unique_id "amuZP6469-jfU7M1CLhEpgAAADk"]
[Thu Jul 30 13:34:40.002719 2026] [security2:error] [pid 914912:tid 915143] [client 142.93.53.183:56836] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/admin/default/ALFA_DATA/alfacgiapi/bash.alfa"] [unique_id "amuZQK469-jfU7M1CLhEqgAAAGU"]
[Thu Jul 30 13:34:40.008388 2026] [security2:error] [pid 914912:tid 915144] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yup.php"] [unique_id "amuZQK469-jfU7M1CLhEqwAAAGY"]
[Thu Jul 30 13:34:40.008490 2026] [security2:error] [pid 914912:tid 915144] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yup.php"] [unique_id "amuZQK469-jfU7M1CLhEqwAAAGY"]
[Thu Jul 30 13:34:40.026713 2026] [security2:error] [pid 914912:tid 914925] [remote 194.116.184.179:56820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.zjp.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuZQK469-jfU7M1CLhErAAAXww"]
[Thu Jul 30 13:34:40.277022 2026] [core:notice] [pid 914912:tid 915158] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:40.384961 2026] [security2:error] [pid 914912:tid 915167] [client 68.235.48.108:41756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.48.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuZQK469-jfU7M1CLhEuAAAAH0"]
[Thu Jul 30 13:34:40.385090 2026] [security2:error] [pid 914912:tid 915167] [client 68.235.48.108:41756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuZQK469-jfU7M1CLhEuAAAAH0"]
[Thu Jul 30 13:34:40.393402 2026] [security2:error] [pid 914912:tid 915169] [client 142.93.53.183:56852] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/images/.../LEVIATHAN/haxorcgiapi/bash.haxor"] [unique_id "amuZQK469-jfU7M1CLhEuQAAAH8"]
[Thu Jul 30 13:34:40.539526 2026] [security2:error] [pid 914912:tid 915042] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/config.json.php"] [unique_id "amuZQK469-jfU7M1CLhEugAAAAA"]
[Thu Jul 30 13:34:40.539636 2026] [security2:error] [pid 914912:tid 915042] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/config.json.php"] [unique_id "amuZQK469-jfU7M1CLhEugAAAAA"]
[Thu Jul 30 13:34:40.781609 2026] [security2:error] [pid 914912:tid 915066] [client 142.93.53.183:56865] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/help/en_US/bibliography/SEOBARBAR_DATA/alfacgiapi/py.alfa"] [unique_id "amuZQK469-jfU7M1CLhEwwAAABg"]
[Thu Jul 30 13:34:41.084542 2026] [security2:error] [pid 914912:tid 915072] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZQa469-jfU7M1CLhEygAAAB4"]
[Thu Jul 30 13:34:41.160115 2026] [security2:error] [pid 914912:tid 915079] [client 142.93.53.183:56876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/admin/default/ALFA_DATA/alfacgiapi/py.alfa"] [unique_id "amuZQa469-jfU7M1CLhEzgAAACU"]
[Thu Jul 30 13:34:41.343716 2026] [security2:error] [pid 914912:tid 915086] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZQa469-jfU7M1CLhE0gAAACw"]
[Thu Jul 30 13:34:41.547099 2026] [security2:error] [pid 914912:tid 915098] [client 142.93.53.183:56887] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/images/.../LEVIATHAN/haxorcgiapi/py.haxor"] [unique_id "amuZQa469-jfU7M1CLhE1wAAADg"]
[Thu Jul 30 13:34:41.548313 2026] [security2:error] [pid 914912:tid 915069] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZQK469-jfU7M1CLhEyQAAABs"]
[Thu Jul 30 13:34:41.604036 2026] [security2:error] [pid 914912:tid 915100] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2.php"] [unique_id "amuZQa469-jfU7M1CLhE2AAAADo"]
[Thu Jul 30 13:34:41.604167 2026] [security2:error] [pid 914912:tid 915100] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2.php"] [unique_id "amuZQa469-jfU7M1CLhE2AAAADo"]
[Thu Jul 30 13:34:41.940889 2026] [security2:error] [pid 914912:tid 915099] [client 142.93.53.183:56900] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/cgi-bin/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZQa469-jfU7M1CLhE4wAAADk"]
[Thu Jul 30 13:34:41.995076 2026] [security2:error] [pid 914912:tid 915115] [client 74.248.33.8:15952] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hhmoaf.org"] [uri "/wp-content/1.php"] [unique_id "amuZQa469-jfU7M1CLhE5AAAAEk"]
[Thu Jul 30 13:34:41.995207 2026] [security2:error] [pid 914912:tid 915115] [client 74.248.33.8:15952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/1.php"] [unique_id "amuZQa469-jfU7M1CLhE5AAAAEk"]
[Thu Jul 30 13:34:42.131207 2026] [security2:error] [pid 914912:tid 915123] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/f35.update.php"] [unique_id "amuZQq469-jfU7M1CLhE5QAAAFE"]
[Thu Jul 30 13:34:42.131377 2026] [security2:error] [pid 914912:tid 915123] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/f35.update.php"] [unique_id "amuZQq469-jfU7M1CLhE5QAAAFE"]
[Thu Jul 30 13:34:42.331323 2026] [security2:error] [pid 914912:tid 915141] [client 142.93.53.183:56909] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/image/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZQq469-jfU7M1CLhE7AAAAGM"]
[Thu Jul 30 13:34:42.676123 2026] [security2:error] [pid 914912:tid 915145] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/k.php"] [unique_id "amuZQq469-jfU7M1CLhE8gAAAGc"]
[Thu Jul 30 13:34:42.676263 2026] [security2:error] [pid 914912:tid 915145] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/k.php"] [unique_id "amuZQq469-jfU7M1CLhE8gAAAGc"]
[Thu Jul 30 13:34:42.721526 2026] [security2:error] [pid 914912:tid 915156] [client 142.93.53.183:56926] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/images/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZQq469-jfU7M1CLhE9gAAAHI"]
[Thu Jul 30 13:34:42.824447 2026] [security2:error] [pid 914912:tid 915147] [client 74.248.33.8:16000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/plugin.php"] [unique_id "amuZQq469-jfU7M1CLhE-gAAAGk"]
[Thu Jul 30 13:34:42.896183 2026] [security2:error] [pid 914912:tid 915151] [client 78.167.1.90:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZQq469-jfU7M1CLhE-wAAAG0"]
[Thu Jul 30 13:34:42.896667 2026] [security2:error] [pid 914912:tid 915151] [client 78.167.1.90:56950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZQq469-jfU7M1CLhE-wAAAG0"]
[Thu Jul 30 13:34:43.075669 2026] [security2:error] [pid 914912:tid 915051] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuZQ6469-jfU7M1CLhE_wAAAAk"]
[Thu Jul 30 13:34:43.101606 2026] [security2:error] [pid 914912:tid 915054] [client 142.93.53.183:56936] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/assets/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZQ6469-jfU7M1CLhFAAAAAAw"]
[Thu Jul 30 13:34:43.197143 2026] [security2:error] [pid 914912:tid 915057] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZQ6469-jfU7M1CLhFBwAAAA8"]
[Thu Jul 30 13:34:43.473625 2026] [security2:error] [pid 914912:tid 915082] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZQ6469-jfU7M1CLhFDgAAACg"]
[Thu Jul 30 13:34:43.487143 2026] [security2:error] [pid 914912:tid 915073] [client 142.93.53.183:56954] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/asset/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZQ6469-jfU7M1CLhFEAAAAB8"]
[Thu Jul 30 13:34:43.735118 2026] [security2:error] [pid 914912:tid 915094] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/spadex.php"] [unique_id "amuZQ6469-jfU7M1CLhFGAAAADQ"]
[Thu Jul 30 13:34:43.735283 2026] [security2:error] [pid 914912:tid 915094] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/spadex.php"] [unique_id "amuZQ6469-jfU7M1CLhFGAAAADQ"]
[Thu Jul 30 13:34:43.878158 2026] [security2:error] [pid 914912:tid 915117] [client 142.93.53.183:56969] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/pub/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZQ6469-jfU7M1CLhFIQAAAEs"]
[Thu Jul 30 13:34:44.249145 2026] [security2:error] [pid 914912:tid 915099] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mg.php"] [unique_id "amuZRK469-jfU7M1CLhFJwAAADk"]
[Thu Jul 30 13:34:44.249267 2026] [security2:error] [pid 914912:tid 915099] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mg.php"] [unique_id "amuZRK469-jfU7M1CLhFJwAAADk"]
[Thu Jul 30 13:34:44.268362 2026] [security2:error] [pid 914912:tid 915126] [client 142.93.53.183:56982] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/public/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZRK469-jfU7M1CLhFKgAAAFQ"]
[Thu Jul 30 13:34:44.659351 2026] [security2:error] [pid 914912:tid 915146] [client 142.93.53.183:57001] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/js/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZRK469-jfU7M1CLhFNQAAAGg"]
[Thu Jul 30 13:34:44.785852 2026] [security2:error] [pid 914912:tid 915152] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fnstall.php"] [unique_id "amuZRK469-jfU7M1CLhFNwAAAG4"]
[Thu Jul 30 13:34:44.785952 2026] [security2:error] [pid 914912:tid 915152] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fnstall.php"] [unique_id "amuZRK469-jfU7M1CLhFNwAAAG4"]
[Thu Jul 30 13:34:45.050188 2026] [security2:error] [pid 914912:tid 915043] [client 142.93.53.183:57015] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/css/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZRa469-jfU7M1CLhFQgAAAAE"]
[Thu Jul 30 13:34:45.305995 2026] [security2:error] [pid 914912:tid 915058] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ortasekerli1.php"] [unique_id "amuZRa469-jfU7M1CLhFRQAAABA"]
[Thu Jul 30 13:34:45.306135 2026] [security2:error] [pid 914912:tid 915058] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ortasekerli1.php"] [unique_id "amuZRa469-jfU7M1CLhFRQAAABA"]
[Thu Jul 30 13:34:45.347779 2026] [security2:error] [pid 914912:tid 915122] [client 121.237.36.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuZRK469-jfU7M1CLhFMAAAAFA"]
[Thu Jul 30 13:34:45.440452 2026] [security2:error] [pid 914912:tid 915059] [client 142.93.53.183:57028] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wp/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZRa469-jfU7M1CLhFTgAAABE"]
[Thu Jul 30 13:34:45.770575 2026] [security2:error] [pid 914912:tid 915091] [client 185.189.112.19:56948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuZRa469-jfU7M1CLhFUwAAADE"]
[Thu Jul 30 13:34:45.770687 2026] [security2:error] [pid 914912:tid 915091] [client 185.189.112.19:56948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuZRa469-jfU7M1CLhFUwAAADE"]
[Thu Jul 30 13:34:45.817595 2026] [security2:error] [pid 914912:tid 915089] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sump1.php"] [unique_id "amuZRa469-jfU7M1CLhFVAAAAC8"]
[Thu Jul 30 13:34:45.817734 2026] [security2:error] [pid 914912:tid 915089] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sump1.php"] [unique_id "amuZRa469-jfU7M1CLhFVAAAAC8"]
[Thu Jul 30 13:34:45.828240 2026] [security2:error] [pid 914912:tid 915088] [client 142.93.53.183:57039] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/wordpress/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZRa469-jfU7M1CLhFVQAAAC4"]
[Thu Jul 30 13:34:46.117304 2026] [core:notice] [pid 914912:tid 914974] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:46.221515 2026] [security2:error] [pid 914912:tid 915126] [client 142.93.53.183:57049] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/blog/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZRq469-jfU7M1CLhFZQAAAFQ"]
[Thu Jul 30 13:34:46.354732 2026] [security2:error] [pid 914912:tid 915123] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ops.php"] [unique_id "amuZRq469-jfU7M1CLhFZgAAAFE"]
[Thu Jul 30 13:34:46.354867 2026] [security2:error] [pid 914912:tid 915123] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ops.php"] [unique_id "amuZRq469-jfU7M1CLhFZgAAAFE"]
[Thu Jul 30 13:34:46.462506 2026] [security2:error] [pid 890219:tid 890373] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZRYJkCYmL5o6vh9KchQAAnAM"]
[Thu Jul 30 13:34:46.601070 2026] [security2:error] [pid 914912:tid 915141] [client 142.93.53.183:57064] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/admin/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZRq469-jfU7M1CLhFbQAAAGM"]
[Thu Jul 30 13:34:46.615753 2026] [security2:error] [pid 914912:tid 914977] [remote 74.7.243.224:34602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/article.php"] [unique_id "amuZRq469-jfU7M1CLhFbgAAWkA"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:34:46.684902 2026] [core:notice] [pid 914912:tid 915137] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:46.839148 2026] [security2:error] [pid 914912:tid 915046] [client 181.105.23.132:33224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amuZRa469-jfU7M1CLhFSgAAAAQ"]
[Thu Jul 30 13:34:46.868130 2026] [security2:error] [pid 914912:tid 915147] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-post-data.php"] [unique_id "amuZRq469-jfU7M1CLhFdwAAAGk"]
[Thu Jul 30 13:34:46.868235 2026] [security2:error] [pid 914912:tid 915147] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-post-data.php"] [unique_id "amuZRq469-jfU7M1CLhFdwAAAGk"]
[Thu Jul 30 13:34:46.987452 2026] [security2:error] [pid 914912:tid 915042] [client 142.93.53.183:57078] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/template/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZRq469-jfU7M1CLhFfwAAAAA"]
[Thu Jul 30 13:34:47.290007 2026] [security2:error] [pid 914912:tid 915153] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZRq469-jfU7M1CLhFdQAAAG8"]
[Thu Jul 30 13:34:47.363234 2026] [security2:error] [pid 914912:tid 915061] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/root.php"] [unique_id "amuZR6469-jfU7M1CLhFhQAAABM"]
[Thu Jul 30 13:34:47.363404 2026] [security2:error] [pid 914912:tid 915061] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/root.php"] [unique_id "amuZR6469-jfU7M1CLhFhQAAABM"]
[Thu Jul 30 13:34:47.366570 2026] [security2:error] [pid 914912:tid 915045] [client 142.93.53.183:57089] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/template/beez3/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZR6469-jfU7M1CLhFhgAAAAM"]
[Thu Jul 30 13:34:47.669698 2026] [security2:error] [pid 914912:tid 915068] [client 134.19.179.131:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuZR6469-jfU7M1CLhFkAAAABo"]
[Thu Jul 30 13:34:47.669811 2026] [security2:error] [pid 914912:tid 915068] [client 134.19.179.131:60590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuZR6469-jfU7M1CLhFkAAAABo"]
[Thu Jul 30 13:34:47.745405 2026] [security2:error] [pid 914912:tid 915089] [client 142.93.53.183:57099] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/administrator/ALFA_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZR6469-jfU7M1CLhFkQAAAC8"]
[Thu Jul 30 13:34:47.785429 2026] [security2:error] [pid 914912:tid 915108] [client 74.248.33.8:15991] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hhmoaf.org"] [uri "/1.php"] [unique_id "amuZR6469-jfU7M1CLhFkgAAAEI"]
[Thu Jul 30 13:34:47.785565 2026] [security2:error] [pid 914912:tid 915108] [client 74.248.33.8:15991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/1.php"] [unique_id "amuZR6469-jfU7M1CLhFkgAAAEI"]
[Thu Jul 30 13:34:47.851883 2026] [security2:error] [pid 914912:tid 915097] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/v543.php"] [unique_id "amuZR6469-jfU7M1CLhFlAAAADc"]
[Thu Jul 30 13:34:47.852000 2026] [security2:error] [pid 914912:tid 915097] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/v543.php"] [unique_id "amuZR6469-jfU7M1CLhFlAAAADc"]
[Thu Jul 30 13:34:48.127969 2026] [security2:error] [pid 914912:tid 915077] [client 142.93.53.183:57110] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/.tmb/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZSK469-jfU7M1CLhFnQAAACM"]
[Thu Jul 30 13:34:48.391805 2026] [security2:error] [pid 914912:tid 915140] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sixxis.php"] [unique_id "amuZSK469-jfU7M1CLhFpAAAAGI"]
[Thu Jul 30 13:34:48.391926 2026] [security2:error] [pid 914912:tid 915140] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sixxis.php"] [unique_id "amuZSK469-jfU7M1CLhFpAAAAGI"]
[Thu Jul 30 13:34:48.518571 2026] [security2:error] [pid 914912:tid 915143] [client 142.93.53.183:57126] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "nordeste1.com"] [uri "/.well-known/SEOBARBAR_DATA/alfacgiapi/perl.alfa"] [unique_id "amuZSK469-jfU7M1CLhFqAAAAGU"]
[Thu Jul 30 13:34:49.040521 2026] [security2:error] [pid 914912:tid 915064] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ip.php"] [unique_id "amuZSa469-jfU7M1CLhFvwAAABY"]
[Thu Jul 30 13:34:49.040666 2026] [security2:error] [pid 914912:tid 915064] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ip.php"] [unique_id "amuZSa469-jfU7M1CLhFvwAAABY"]
[Thu Jul 30 13:34:49.224818 2026] [security2:error] [pid 914912:tid 915148] [client 57.141.0.43:39740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuZSK469-jfU7M1CLhFtAAAalY"], referer: https://igetvape-australia.com/product/alibarbar-ingot-kiwi-pineapple-9000-puffs/?add-to-cart=935
[Thu Jul 30 13:34:49.486612 2026] [security2:error] [pid 914912:tid 915054] [client 172.237.109.114:5304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZSK469-jfU7M1CLhFuQAAAAw"]
[Thu Jul 30 13:34:49.558315 2026] [security2:error] [pid 914912:tid 915144] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/kq1.php"] [unique_id "amuZSa469-jfU7M1CLhF5AAAAGY"]
[Thu Jul 30 13:34:49.558434 2026] [security2:error] [pid 914912:tid 915144] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/kq1.php"] [unique_id "amuZSa469-jfU7M1CLhF5AAAAGY"]
[Thu Jul 30 13:34:50.412302 2026] [security2:error] [pid 914912:tid 915047] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fw/faiyy.php"] [unique_id "amuZSq469-jfU7M1CLhGBQAAAAU"]
[Thu Jul 30 13:34:50.412391 2026] [security2:error] [pid 914912:tid 915047] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fw/faiyy.php"] [unique_id "amuZSq469-jfU7M1CLhGBQAAAAU"]
[Thu Jul 30 13:34:50.947870 2026] [security2:error] [pid 914912:tid 915117] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/h02ugyh.php"] [unique_id "amuZSq469-jfU7M1CLhGEQAAAEs"]
[Thu Jul 30 13:34:50.948034 2026] [security2:error] [pid 914912:tid 915117] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/h02ugyh.php"] [unique_id "amuZSq469-jfU7M1CLhGEQAAAEs"]
[Thu Jul 30 13:34:51.075769 2026] [security2:error] [pid 914912:tid 915111] [client 181.45.46.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZSa469-jfU7M1CLhF8AAAAEU"], referer: https://cnpinyin.com
[Thu Jul 30 13:34:51.266996 2026] [security2:error] [pid 914912:tid 915164] [client 74.248.33.8:30037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/gg.php"] [unique_id "amuZS6469-jfU7M1CLhGGgAAAHo"]
[Thu Jul 30 13:34:51.624813 2026] [security2:error] [pid 914912:tid 915128] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-temp.php"] [unique_id "amuZS6469-jfU7M1CLhGIgAAAFY"]
[Thu Jul 30 13:34:51.624997 2026] [security2:error] [pid 914912:tid 915128] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-temp.php"] [unique_id "amuZS6469-jfU7M1CLhGIgAAAFY"]
[Thu Jul 30 13:34:52.551807 2026] [security2:error] [pid 914912:tid 915068] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/cong.php"] [unique_id "amuZTK469-jfU7M1CLhGOAAAABo"]
[Thu Jul 30 13:34:52.551916 2026] [security2:error] [pid 914912:tid 915068] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/cong.php"] [unique_id "amuZTK469-jfU7M1CLhGOAAAABo"]
[Thu Jul 30 13:34:53.142128 2026] [security2:error] [pid 914912:tid 915052] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZTa469-jfU7M1CLhGRQAAAAo"]
[Thu Jul 30 13:34:53.293914 2026] [security2:error] [pid 914912:tid 915077] [client 74.248.33.8:24199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-content/languages/index.php"] [unique_id "amuZTa469-jfU7M1CLhGSgAAACM"]
[Thu Jul 30 13:34:53.462401 2026] [security2:error] [pid 914912:tid 915151] [client 78.167.1.90:53790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZTa469-jfU7M1CLhGTgAAAG0"]
[Thu Jul 30 13:34:53.462905 2026] [security2:error] [pid 914912:tid 915151] [client 78.167.1.90:53790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZTa469-jfU7M1CLhGTgAAAG0"]
[Thu Jul 30 13:34:53.526278 2026] [core:notice] [pid 914912:tid 915117] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:53.530580 2026] [security2:error] [pid 914912:tid 915116] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZTa469-jfU7M1CLhGUwAAAEo"]
[Thu Jul 30 13:34:53.806826 2026] [security2:error] [pid 914912:tid 915128] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/css/index.php"] [unique_id "amuZTa469-jfU7M1CLhGWwAAAFY"]
[Thu Jul 30 13:34:53.807021 2026] [security2:error] [pid 914912:tid 915128] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/css/index.php"] [unique_id "amuZTa469-jfU7M1CLhGWwAAAFY"]
[Thu Jul 30 13:34:53.833335 2026] [proxy:error] [pid 914912:tid 915127] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:53.833407 2026] [proxy_http:error] [pid 914912:tid 915127] [client 52.202.41.153:57038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:53.833991 2026] [proxy:error] [pid 914912:tid 915127] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:53.834037 2026] [proxy_http:error] [pid 914912:tid 915127] [client 52.202.41.153:57038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:53.854767 2026] [proxy:error] [pid 914912:tid 915162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:53.854835 2026] [proxy_http:error] [pid 914912:tid 915162] [client 54.87.222.253:56791] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:53.855561 2026] [proxy:error] [pid 914912:tid 915162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:53.855616 2026] [proxy_http:error] [pid 914912:tid 915162] [client 54.87.222.253:56791] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:54.118795 2026] [core:notice] [pid 914912:tid 915135] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:34:54.405366 2026] [security2:error] [pid 914912:tid 915076] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/jj.php"] [unique_id "amuZTq469-jfU7M1CLhGdgAAACI"]
[Thu Jul 30 13:34:54.405489 2026] [security2:error] [pid 914912:tid 915076] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/jj.php"] [unique_id "amuZTq469-jfU7M1CLhGdgAAACI"]
[Thu Jul 30 13:34:54.555129 2026] [security2:error] [pid 914912:tid 915126] [client 74.248.33.8:15950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp.php"] [unique_id "amuZTq469-jfU7M1CLhGegAAAFQ"]
[Thu Jul 30 13:34:54.574488 2026] [security2:error] [pid 914912:tid 915149] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZTa469-jfU7M1CLhGagAAAGs"]
[Thu Jul 30 13:34:54.918908 2026] [proxy:error] [pid 914912:tid 915148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:54.919003 2026] [proxy_http:error] [pid 914912:tid 915148] [client 32.194.121.99:45278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:54.919785 2026] [proxy:error] [pid 914912:tid 915148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:34:54.919833 2026] [proxy_http:error] [pid 914912:tid 915148] [client 32.194.121.99:45278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:34:54.979078 2026] [security2:error] [pid 914912:tid 915118] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/class-walker-footer-dev.php"] [unique_id "amuZTq469-jfU7M1CLhGhgAAAEw"]
[Thu Jul 30 13:34:54.979185 2026] [security2:error] [pid 914912:tid 915118] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/class-walker-footer-dev.php"] [unique_id "amuZTq469-jfU7M1CLhGhgAAAEw"]
[Thu Jul 30 13:34:55.479731 2026] [security2:error] [pid 914912:tid 915133] [client 172.237.109.114:2185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZTq469-jfU7M1CLhGhQAAAFs"]
[Thu Jul 30 13:34:55.519487 2026] [security2:error] [pid 914912:tid 915147] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xpwer1.php"] [unique_id "amuZT6469-jfU7M1CLhGkgAAAGk"]
[Thu Jul 30 13:34:55.519577 2026] [security2:error] [pid 914912:tid 915147] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xpwer1.php"] [unique_id "amuZT6469-jfU7M1CLhGkgAAAGk"]
[Thu Jul 30 13:34:55.871154 2026] [security2:error] [pid 914912:tid 915053] [client 52.167.144.170:26303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amuZT6469-jfU7M1CLhGmQAACy8"]
[Thu Jul 30 13:34:56.062165 2026] [security2:error] [pid 914912:tid 915080] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/flox.php"] [unique_id "amuZUK469-jfU7M1CLhGnQAAACY"]
[Thu Jul 30 13:34:56.062558 2026] [security2:error] [pid 914912:tid 915080] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/flox.php"] [unique_id "amuZUK469-jfU7M1CLhGnQAAACY"]
[Thu Jul 30 13:34:56.208046 2026] [security2:error] [pid 914912:tid 915119] [client 74.248.33.8:15988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuZUK469-jfU7M1CLhGpQAAAE0"]
[Thu Jul 30 13:34:56.669286 2026] [security2:error] [pid 914912:tid 915152] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/popo.php"] [unique_id "amuZUK469-jfU7M1CLhGrgAAAG4"]
[Thu Jul 30 13:34:56.669402 2026] [security2:error] [pid 914912:tid 915152] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/popo.php"] [unique_id "amuZUK469-jfU7M1CLhGrgAAAG4"]
[Thu Jul 30 13:34:57.157505 2026] [security2:error] [pid 914912:tid 915112] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yas.php"] [unique_id "amuZUa469-jfU7M1CLhGuAAAAEY"]
[Thu Jul 30 13:34:57.157606 2026] [security2:error] [pid 914912:tid 915112] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yas.php"] [unique_id "amuZUa469-jfU7M1CLhGuAAAAEY"]
[Thu Jul 30 13:34:57.733206 2026] [security2:error] [pid 914912:tid 915144] [client 74.248.33.8:24252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/file.php"] [unique_id "amuZUa469-jfU7M1CLhGwwAAAGY"]
[Thu Jul 30 13:34:57.744038 2026] [security2:error] [pid 914912:tid 915054] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/water.php"] [unique_id "amuZUa469-jfU7M1CLhGxQAAAAw"]
[Thu Jul 30 13:34:57.744122 2026] [security2:error] [pid 914912:tid 915054] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/water.php"] [unique_id "amuZUa469-jfU7M1CLhGxQAAAAw"]
[Thu Jul 30 13:34:58.519350 2026] [security2:error] [pid 914912:tid 915061] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/nano.php"] [unique_id "amuZUq469-jfU7M1CLhG2AAAABM"]
[Thu Jul 30 13:34:58.519534 2026] [security2:error] [pid 914912:tid 915061] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/nano.php"] [unique_id "amuZUq469-jfU7M1CLhG2AAAABM"]
[Thu Jul 30 13:34:59.149190 2026] [security2:error] [pid 914912:tid 915131] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/moon.php"] [unique_id "amuZU6469-jfU7M1CLhG6QAAAFk"]
[Thu Jul 30 13:34:59.149344 2026] [security2:error] [pid 914912:tid 915131] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/moon.php"] [unique_id "amuZU6469-jfU7M1CLhG6QAAAFk"]
[Thu Jul 30 13:34:59.412300 2026] [security2:error] [pid 914912:tid 915108] [client 74.248.33.8:36715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/user/index.php"] [unique_id "amuZU6469-jfU7M1CLhG8QAAAEI"]
[Thu Jul 30 13:34:59.651923 2026] [security2:error] [pid 914912:tid 915096] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-info.php"] [unique_id "amuZU6469-jfU7M1CLhG9QAAADY"]
[Thu Jul 30 13:34:59.652040 2026] [security2:error] [pid 914912:tid 915096] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-info.php"] [unique_id "amuZU6469-jfU7M1CLhG9QAAADY"]
[Thu Jul 30 13:35:00.016605 2026] [core:notice] [pid 914912:tid 914992] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:00.186848 2026] [core:notice] [pid 914912:tid 914995] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:00.287821 2026] [security2:error] [pid 914912:tid 915054] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file5.php"] [unique_id "amuZVK469-jfU7M1CLhHAwAAAAw"]
[Thu Jul 30 13:35:00.287963 2026] [security2:error] [pid 914912:tid 915054] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file5.php"] [unique_id "amuZVK469-jfU7M1CLhHAwAAAAw"]
[Thu Jul 30 13:35:00.364163 2026] [core:notice] [pid 914912:tid 914997] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:00.803206 2026] [security2:error] [pid 914912:tid 915082] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2000.php"] [unique_id "amuZVK469-jfU7M1CLhHEgAAACg"]
[Thu Jul 30 13:35:00.803378 2026] [security2:error] [pid 914912:tid 915082] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2000.php"] [unique_id "amuZVK469-jfU7M1CLhHEgAAACg"]
[Thu Jul 30 13:35:01.162656 2026] [security2:error] [pid 914912:tid 915101] [client 46.8.213.112:50205] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "saifalkhaleejest.com"] [uri "/wp-comments-post.php"] [unique_id "amuZVK469-jfU7M1CLhHEQAAADs"], referer: https://saifalkhaleejest.com/bet-hall-casino-ganancias-rapidas-y-accion-de-slots-de-alta-intensidad/
[Thu Jul 30 13:35:01.345910 2026] [security2:error] [pid 914912:tid 915044] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/122.php"] [unique_id "amuZVa469-jfU7M1CLhHHAAAAAI"]
[Thu Jul 30 13:35:01.346031 2026] [security2:error] [pid 914912:tid 915044] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/122.php"] [unique_id "amuZVa469-jfU7M1CLhHHAAAAAI"]
[Thu Jul 30 13:35:01.805662 2026] [security2:error] [pid 914912:tid 915101] [client 46.8.213.112:50205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "saifalkhaleejest.com"] [uri "/wp-comments-post.php"] [unique_id "amuZVK469-jfU7M1CLhHEQAAADs"], referer: https://saifalkhaleejest.com/bet-hall-casino-ganancias-rapidas-y-accion-de-slots-de-alta-intensidad/
[Thu Jul 30 13:35:01.805722 2026] [security2:error] [pid 914912:tid 915101] [client 46.8.213.112:50205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "saifalkhaleejest.com"] [uri "/wp-comments-post.php"] [unique_id "amuZVK469-jfU7M1CLhHEQAAADs"], referer: https://saifalkhaleejest.com/bet-hall-casino-ganancias-rapidas-y-accion-de-slots-de-alta-intensidad/
[Thu Jul 30 13:35:01.906149 2026] [security2:error] [pid 914912:tid 915134] [client 74.248.33.8:39659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuZVa469-jfU7M1CLhHLAAAAFw"]
[Thu Jul 30 13:35:01.907142 2026] [security2:error] [pid 914912:tid 915057] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mds.php"] [unique_id "amuZVa469-jfU7M1CLhHLQAAAA8"]
[Thu Jul 30 13:35:01.907225 2026] [security2:error] [pid 914912:tid 915057] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mds.php"] [unique_id "amuZVa469-jfU7M1CLhHLQAAAA8"]
[Thu Jul 30 13:35:02.429083 2026] [security2:error] [pid 914912:tid 915102] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zc-208.php"] [unique_id "amuZVq469-jfU7M1CLhHOAAAADw"]
[Thu Jul 30 13:35:02.429198 2026] [security2:error] [pid 914912:tid 915102] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zc-208.php"] [unique_id "amuZVq469-jfU7M1CLhHOAAAADw"]
[Thu Jul 30 13:35:02.970315 2026] [security2:error] [pid 914912:tid 915128] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sid4.php"] [unique_id "amuZVq469-jfU7M1CLhHSQAAAFY"]
[Thu Jul 30 13:35:02.970479 2026] [security2:error] [pid 914912:tid 915128] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sid4.php"] [unique_id "amuZVq469-jfU7M1CLhHSQAAAFY"]
[Thu Jul 30 13:35:02.986888 2026] [security2:error] [pid 914912:tid 915133] [client 185.189.112.19:58132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.112.189.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuZVq469-jfU7M1CLhHSgAAAFs"]
[Thu Jul 30 13:35:02.987005 2026] [security2:error] [pid 914912:tid 915133] [client 185.189.112.19:58132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuZVq469-jfU7M1CLhHSgAAAFs"]
[Thu Jul 30 13:35:03.568179 2026] [security2:error] [pid 914912:tid 915159] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZV6469-jfU7M1CLhHXwAAAHU"]
[Thu Jul 30 13:35:03.889998 2026] [security2:error] [pid 914912:tid 915152] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZV6469-jfU7M1CLhHZwAAAG4"]
[Thu Jul 30 13:35:03.966137 2026] [core:notice] [pid 914912:tid 915131] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:04.025568 2026] [security2:error] [pid 914912:tid 915073] [client 78.167.1.90:56449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZWK469-jfU7M1CLhHaQAAAB8"]
[Thu Jul 30 13:35:04.026082 2026] [security2:error] [pid 914912:tid 915073] [client 78.167.1.90:56449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZWK469-jfU7M1CLhHaQAAAB8"]
[Thu Jul 30 13:35:04.168162 2026] [security2:error] [pid 914912:tid 915111] [client 74.248.33.8:35037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/index/function.php"] [unique_id "amuZWK469-jfU7M1CLhHcwAAAEU"]
[Thu Jul 30 13:35:04.206476 2026] [security2:error] [pid 914912:tid 915118] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wmore1.php"] [unique_id "amuZWK469-jfU7M1CLhHdwAAAEw"]
[Thu Jul 30 13:35:04.206575 2026] [security2:error] [pid 914912:tid 915118] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wmore1.php"] [unique_id "amuZWK469-jfU7M1CLhHdwAAAEw"]
[Thu Jul 30 13:35:04.641688 2026] [security2:error] [pid 914912:tid 915141] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZWK469-jfU7M1CLhHbAAAAGM"]
[Thu Jul 30 13:35:04.749864 2026] [security2:error] [pid 914912:tid 915094] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/solo1.php"] [unique_id "amuZWK469-jfU7M1CLhHggAAADQ"]
[Thu Jul 30 13:35:04.749998 2026] [security2:error] [pid 914912:tid 915094] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/solo1.php"] [unique_id "amuZWK469-jfU7M1CLhHggAAADQ"]
[Thu Jul 30 13:35:04.781765 2026] [security2:error] [pid 914912:tid 915087] [client 74.7.175.163:43092] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.globalmarks.pk.pls.udi.temporary.site"] [uri "/index.php"] [unique_id "amuZWK469-jfU7M1CLhHfgAALVk"]
[Thu Jul 30 13:35:04.806098 2026] [core:error] [pid 914912:tid 915116] [client 74.7.230.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:35:04.806131 2026] [core:error] [pid 914912:tid 915116] [client 74.7.230.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:35:04.806294 2026] [security2:error] [pid 914912:tid 915116] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ooj.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuZWK469-jfU7M1CLhHhgAAAEo"]
[Thu Jul 30 13:35:04.807026 2026] [security2:error] [pid 914912:tid 915077] [client 74.7.230.1:36134] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.ooj.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuZWK469-jfU7M1CLhHhAAAI30"]
[Thu Jul 30 13:35:05.278888 2026] [proxy:error] [pid 914912:tid 915124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:05.278973 2026] [proxy_http:error] [pid 914912:tid 915124] [client 32.194.121.99:49556] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:05.279709 2026] [proxy:error] [pid 914912:tid 915124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:05.279755 2026] [proxy_http:error] [pid 914912:tid 915124] [client 32.194.121.99:49556] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:05.293338 2026] [security2:error] [pid 914912:tid 915138] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZWa469-jfU7M1CLhHlwAAAGA"]
[Thu Jul 30 13:35:05.309034 2026] [proxy:error] [pid 914912:tid 915107] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:05.309118 2026] [proxy_http:error] [pid 914912:tid 915107] [client 32.194.121.99:8300] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:05.309933 2026] [proxy:error] [pid 914912:tid 915107] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:05.309998 2026] [proxy_http:error] [pid 914912:tid 915107] [client 32.194.121.99:8300] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:05.609339 2026] [security2:error] [pid 914912:tid 915044] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZWa469-jfU7M1CLhHoAAAAAI"]
[Thu Jul 30 13:35:05.979255 2026] [security2:error] [pid 914912:tid 915073] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.cgi"] [unique_id "amuZWa469-jfU7M1CLhHrAAAAB8"]
[Thu Jul 30 13:35:06.273249 2026] [security2:error] [pid 914912:tid 915153] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/404.html"] [unique_id "amuZWq469-jfU7M1CLhHswAAAG8"]
[Thu Jul 30 13:35:06.618166 2026] [security2:error] [pid 914912:tid 915096] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/public/css.php"] [unique_id "amuZWq469-jfU7M1CLhHtwAAADY"]
[Thu Jul 30 13:35:06.618298 2026] [security2:error] [pid 914912:tid 915096] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/public/css.php"] [unique_id "amuZWq469-jfU7M1CLhHtwAAADY"]
[Thu Jul 30 13:35:07.189301 2026] [security2:error] [pid 914912:tid 915087] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/output.php"] [unique_id "amuZW6469-jfU7M1CLhHxAAAAC0"]
[Thu Jul 30 13:35:07.189416 2026] [security2:error] [pid 914912:tid 915087] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/output.php"] [unique_id "amuZW6469-jfU7M1CLhHxAAAAC0"]
[Thu Jul 30 13:35:07.778074 2026] [security2:error] [pid 914912:tid 915145] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-file-120.php"] [unique_id "amuZW6469-jfU7M1CLhH1QAAAGc"]
[Thu Jul 30 13:35:07.778191 2026] [security2:error] [pid 914912:tid 915145] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-file-120.php"] [unique_id "amuZW6469-jfU7M1CLhH1QAAAGc"]
[Thu Jul 30 13:35:08.113284 2026] [security2:error] [pid 914912:tid 915148] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZW6469-jfU7M1CLhHzgAAahA"]
[Thu Jul 30 13:35:08.353482 2026] [security2:error] [pid 914912:tid 915071] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/special.php"] [unique_id "amuZXK469-jfU7M1CLhH6gAAAB0"]
[Thu Jul 30 13:35:08.353600 2026] [security2:error] [pid 914912:tid 915071] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/special.php"] [unique_id "amuZXK469-jfU7M1CLhH6gAAAB0"]
[Thu Jul 30 13:35:08.494019 2026] [core:notice] [pid 914912:tid 914954] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:08.780243 2026] [security2:error] [pid 914912:tid 915080] [client 134.19.179.131:50218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuZXK469-jfU7M1CLhH9QAAACY"]
[Thu Jul 30 13:35:08.780357 2026] [security2:error] [pid 914912:tid 915080] [client 134.19.179.131:50218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuZXK469-jfU7M1CLhH9QAAACY"]
[Thu Jul 30 13:35:08.845088 2026] [security2:error] [pid 914912:tid 915146] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/as.php"] [unique_id "amuZXK469-jfU7M1CLhH-AAAAGg"]
[Thu Jul 30 13:35:08.845181 2026] [security2:error] [pid 914912:tid 915146] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/as.php"] [unique_id "amuZXK469-jfU7M1CLhH-AAAAGg"]
[Thu Jul 30 13:35:09.386692 2026] [security2:error] [pid 914912:tid 915157] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/cgi-bin/index.php"] [unique_id "amuZXa469-jfU7M1CLhIAQAAAHM"]
[Thu Jul 30 13:35:09.386837 2026] [security2:error] [pid 914912:tid 915157] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/cgi-bin/index.php"] [unique_id "amuZXa469-jfU7M1CLhIAQAAAHM"]
[Thu Jul 30 13:35:10.272325 2026] [security2:error] [pid 914912:tid 915114] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w1px.php"] [unique_id "amuZXq469-jfU7M1CLhIFgAAAEg"]
[Thu Jul 30 13:35:10.272443 2026] [security2:error] [pid 914912:tid 915114] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w1px.php"] [unique_id "amuZXq469-jfU7M1CLhIFgAAAEg"]
[Thu Jul 30 13:35:10.535085 2026] [security2:error] [pid 914912:tid 914969] [remote 47.128.27.88:18920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-se-craft-white-and-phantom/"] [unique_id "amuZXq469-jfU7M1CLhIHQAAdDg"]
[Thu Jul 30 13:35:10.836648 2026] [security2:error] [pid 914912:tid 915050] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/js.php"] [unique_id "amuZXq469-jfU7M1CLhIIwAAAAg"]
[Thu Jul 30 13:35:10.836768 2026] [security2:error] [pid 914912:tid 915050] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/js.php"] [unique_id "amuZXq469-jfU7M1CLhIIwAAAAg"]
[Thu Jul 30 13:35:11.026923 2026] [security2:error] [pid 914912:tid 915051] [client 43.172.197.227:56820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/04/11/hm-premium-printemps-2016/"] [unique_id "amuZXq469-jfU7M1CLhIIgAAAAk"]
[Thu Jul 30 13:35:11.446700 2026] [security2:error] [pid 914912:tid 915065] [client 119.73.97.132:30659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuZX6469-jfU7M1CLhILwAAFz4"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 13:35:11.533390 2026] [security2:error] [pid 914912:tid 915146] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/core.php"] [unique_id "amuZX6469-jfU7M1CLhINgAAAGg"]
[Thu Jul 30 13:35:11.533532 2026] [security2:error] [pid 914912:tid 915146] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/core.php"] [unique_id "amuZX6469-jfU7M1CLhINgAAAGg"]
[Thu Jul 30 13:35:11.775863 2026] [core:notice] [pid 914912:tid 915118] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:11.781545 2026] [security2:error] [pid 914912:tid 915118] [client 43.173.173.160:47278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/04/11/hm-premium-printemps-2016/"] [unique_id "amuZX6469-jfU7M1CLhIOwAAAEw"], referer: https://carnetdeshopping.com/index.php/2016/04/11/hm-premium-printemps-2016/
[Thu Jul 30 13:35:12.247128 2026] [security2:error] [pid 914912:tid 915104] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fffm.php"] [unique_id "amuZYK469-jfU7M1CLhIRQAAAD4"]
[Thu Jul 30 13:35:12.247234 2026] [security2:error] [pid 914912:tid 915104] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fffm.php"] [unique_id "amuZYK469-jfU7M1CLhIRQAAAD4"]
[Thu Jul 30 13:35:12.780101 2026] [security2:error] [pid 914912:tid 915130] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ww.php"] [unique_id "amuZYK469-jfU7M1CLhIUQAAAFg"]
[Thu Jul 30 13:35:12.780197 2026] [security2:error] [pid 914912:tid 915130] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ww.php"] [unique_id "amuZYK469-jfU7M1CLhIUQAAAFg"]
[Thu Jul 30 13:35:13.277650 2026] [security2:error] [pid 914912:tid 915045] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/domvf.php"] [unique_id "amuZYa469-jfU7M1CLhIXwAAAAM"]
[Thu Jul 30 13:35:13.277808 2026] [security2:error] [pid 914912:tid 915045] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/domvf.php"] [unique_id "amuZYa469-jfU7M1CLhIXwAAAAM"]
[Thu Jul 30 13:35:13.558688 2026] [security2:error] [pid 914912:tid 915166] [client 185.191.171.7:27494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/robots.txt"] [unique_id "amuZYa469-jfU7M1CLhIYQAAAHw"]
[Thu Jul 30 13:35:13.558836 2026] [security2:error] [pid 914912:tid 915166] [client 185.191.171.7:27494] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fireworkskenya.co.ke"] [uri "/robots.txt"] [unique_id "amuZYa469-jfU7M1CLhIYQAAAHw"]
[Thu Jul 30 13:35:13.798915 2026] [security2:error] [pid 914912:tid 915071] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/echkm.php"] [unique_id "amuZYa469-jfU7M1CLhIawAAAB0"]
[Thu Jul 30 13:35:13.799054 2026] [security2:error] [pid 914912:tid 915071] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/echkm.php"] [unique_id "amuZYa469-jfU7M1CLhIawAAAB0"]
[Thu Jul 30 13:35:14.300420 2026] [security2:error] [pid 914912:tid 915101] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ano.php"] [unique_id "amuZYq469-jfU7M1CLhIdgAAADs"]
[Thu Jul 30 13:35:14.300533 2026] [security2:error] [pid 914912:tid 915101] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ano.php"] [unique_id "amuZYq469-jfU7M1CLhIdgAAADs"]
[Thu Jul 30 13:35:14.672666 2026] [security2:error] [pid 914912:tid 915139] [client 85.208.96.202:62888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/big-display-cake/"] [unique_id "amuZYq469-jfU7M1CLhIfgAAAGE"]
[Thu Jul 30 13:35:14.672789 2026] [security2:error] [pid 914912:tid 915139] [client 85.208.96.202:62888] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/big-display-cake/"] [unique_id "amuZYq469-jfU7M1CLhIfgAAAGE"]
[Thu Jul 30 13:35:14.722896 2026] [security2:error] [pid 914912:tid 915068] [client 78.167.1.90:54745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZYq469-jfU7M1CLhIhQAAABo"]
[Thu Jul 30 13:35:14.723717 2026] [security2:error] [pid 914912:tid 915068] [client 78.167.1.90:54745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZYq469-jfU7M1CLhIhQAAABo"]
[Thu Jul 30 13:35:14.928019 2026] [security2:error] [pid 914912:tid 915123] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ah25.php"] [unique_id "amuZYq469-jfU7M1CLhIjAAAAFE"]
[Thu Jul 30 13:35:14.928155 2026] [security2:error] [pid 914912:tid 915123] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ah25.php"] [unique_id "amuZYq469-jfU7M1CLhIjAAAAFE"]
[Thu Jul 30 13:35:15.136233 2026] [security2:error] [pid 914912:tid 915150] [client 34.124.248.160:47580] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "kendarikomputer.com"] [uri "/"] [unique_id "amuZY6469-jfU7M1CLhIjQAAAGw"]
[Thu Jul 30 13:35:15.598667 2026] [security2:error] [pid 914912:tid 915163] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/term.php"] [unique_id "amuZY6469-jfU7M1CLhImQAAAHk"]
[Thu Jul 30 13:35:15.598798 2026] [security2:error] [pid 914912:tid 915163] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/term.php"] [unique_id "amuZY6469-jfU7M1CLhImQAAAHk"]
[Thu Jul 30 13:35:16.191241 2026] [security2:error] [pid 914912:tid 915051] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/we.php"] [unique_id "amuZZK469-jfU7M1CLhIqgAAAAk"]
[Thu Jul 30 13:35:16.191338 2026] [security2:error] [pid 914912:tid 915051] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/we.php"] [unique_id "amuZZK469-jfU7M1CLhIqgAAAAk"]
[Thu Jul 30 13:35:16.729272 2026] [security2:error] [pid 914912:tid 915101] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zip-onee.php"] [unique_id "amuZZK469-jfU7M1CLhIvAAAADs"]
[Thu Jul 30 13:35:16.729366 2026] [security2:error] [pid 914912:tid 915101] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zip-onee.php"] [unique_id "amuZZK469-jfU7M1CLhIvAAAADs"]
[Thu Jul 30 13:35:17.244027 2026] [security2:error] [pid 914912:tid 915054] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/il.php"] [unique_id "amuZZa469-jfU7M1CLhI0AAAAAw"]
[Thu Jul 30 13:35:17.244134 2026] [security2:error] [pid 914912:tid 915054] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/il.php"] [unique_id "amuZZa469-jfU7M1CLhI0AAAAAw"]
[Thu Jul 30 13:35:17.780420 2026] [security2:error] [pid 914912:tid 915107] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/one.php"] [unique_id "amuZZa469-jfU7M1CLhI3wAAAEE"]
[Thu Jul 30 13:35:17.780552 2026] [security2:error] [pid 914912:tid 915107] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/one.php"] [unique_id "amuZZa469-jfU7M1CLhI3wAAAEE"]
[Thu Jul 30 13:35:18.272433 2026] [security2:error] [pid 914912:tid 915072] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/002.php"] [unique_id "amuZZq469-jfU7M1CLhI-gAAAB4"]
[Thu Jul 30 13:35:18.272542 2026] [security2:error] [pid 914912:tid 915072] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/002.php"] [unique_id "amuZZq469-jfU7M1CLhI-gAAAB4"]
[Thu Jul 30 13:35:18.533025 2026] [security2:error] [pid 914912:tid 914919] [remote 40.77.167.1:11357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/1936471897/article.php"] [unique_id "amuZZq469-jfU7M1CLhJBAAANwY"]
[Thu Jul 30 13:35:18.606603 2026] [security2:error] [pid 914912:tid 915088] [client 81.220.211.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZZq469-jfU7M1CLhJAAAAAC4"], referer: https://cnpinyin.com
[Thu Jul 30 13:35:18.633487 2026] [security2:error] [pid 914912:tid 915114] [client 74.7.230.38:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.mjsnailspa.com"] [uri "/index.php"] [unique_id "amuZZa469-jfU7M1CLhI2gAAAEg"]
[Thu Jul 30 13:35:18.634379 2026] [security2:error] [pid 914912:tid 915077] [client 74.7.230.38:32974] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.mjsnailspa.com"] [uri "/robots.txt"] [unique_id "amuZZa469-jfU7M1CLhI2AAAIwI"]
[Thu Jul 30 13:35:18.766237 2026] [security2:error] [pid 914912:tid 915099] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file1.php"] [unique_id "amuZZq469-jfU7M1CLhJCAAAADk"]
[Thu Jul 30 13:35:18.766384 2026] [security2:error] [pid 914912:tid 915099] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/file1.php"] [unique_id "amuZZq469-jfU7M1CLhJCAAAADk"]
[Thu Jul 30 13:35:19.337018 2026] [security2:error] [pid 914912:tid 915063] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/akimet.php"] [unique_id "amuZZ6469-jfU7M1CLhJGQAAABU"]
[Thu Jul 30 13:35:19.337148 2026] [security2:error] [pid 914912:tid 915063] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/akimet.php"] [unique_id "amuZZ6469-jfU7M1CLhJGQAAABU"]
[Thu Jul 30 13:35:19.422326 2026] [security2:error] [pid 914912:tid 915094] [client 74.7.228.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mjsnailspa.com"] [uri "/index.php"] [unique_id "amuZZ6469-jfU7M1CLhJHwAAADQ"]
[Thu Jul 30 13:35:19.423284 2026] [security2:error] [pid 914912:tid 915141] [client 74.7.228.1:48782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mjsnailspa.com"] [uri "/robots.txt"] [unique_id "amuZZ6469-jfU7M1CLhJHAAAYxc"]
[Thu Jul 30 13:35:20.233960 2026] [security2:error] [pid 914912:tid 915128] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/reop3.php"] [unique_id "amuZaK469-jfU7M1CLhJLwAAAFY"]
[Thu Jul 30 13:35:20.234122 2026] [security2:error] [pid 914912:tid 915128] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/reop3.php"] [unique_id "amuZaK469-jfU7M1CLhJLwAAAFY"]
[Thu Jul 30 13:35:20.747965 2026] [security2:error] [pid 914912:tid 915081] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/h.php"] [unique_id "amuZaK469-jfU7M1CLhJPAAAACc"]
[Thu Jul 30 13:35:20.748093 2026] [security2:error] [pid 914912:tid 915081] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/h.php"] [unique_id "amuZaK469-jfU7M1CLhJPAAAACc"]
[Thu Jul 30 13:35:21.283911 2026] [security2:error] [pid 914912:tid 915075] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2x.php"] [unique_id "amuZaa469-jfU7M1CLhJRgAAACE"]
[Thu Jul 30 13:35:21.284033 2026] [security2:error] [pid 914912:tid 915075] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2x.php"] [unique_id "amuZaa469-jfU7M1CLhJRgAAACE"]
[Thu Jul 30 13:35:21.462621 2026] [proxy:error] [pid 914912:tid 915084] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:21.462694 2026] [proxy_http:error] [pid 914912:tid 915084] [client 18.211.55.47:17659] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:21.463481 2026] [proxy:error] [pid 914912:tid 915084] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:21.463536 2026] [proxy_http:error] [pid 914912:tid 915084] [client 18.211.55.47:17659] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:21.489951 2026] [proxy:error] [pid 914912:tid 915136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:21.490037 2026] [proxy_http:error] [pid 914912:tid 915136] [client 18.211.55.47:18065] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:21.490809 2026] [proxy:error] [pid 914912:tid 915136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:21.490865 2026] [proxy_http:error] [pid 914912:tid 915136] [client 18.211.55.47:18065] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:21.507811 2026] [security2:error] [pid 914912:tid 914938] [remote 47.128.27.91:57904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/adidas-samba-xlg-31/"] [unique_id "amuZaa469-jfU7M1CLhJVQAAKxk"]
[Thu Jul 30 13:35:21.846888 2026] [security2:error] [pid 914912:tid 915053] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/petx.php"] [unique_id "amuZaa469-jfU7M1CLhJWwAAAAs"]
[Thu Jul 30 13:35:21.847011 2026] [security2:error] [pid 914912:tid 915053] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/petx.php"] [unique_id "amuZaa469-jfU7M1CLhJWwAAAAs"]
[Thu Jul 30 13:35:22.377915 2026] [security2:error] [pid 914912:tid 915129] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zxz.php"] [unique_id "amuZaq469-jfU7M1CLhJcwAAAFc"]
[Thu Jul 30 13:35:22.378038 2026] [security2:error] [pid 914912:tid 915129] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zxz.php"] [unique_id "amuZaq469-jfU7M1CLhJcwAAAFc"]
[Thu Jul 30 13:35:22.912258 2026] [security2:error] [pid 914912:tid 915075] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2.php"] [unique_id "amuZaq469-jfU7M1CLhJgAAAACE"]
[Thu Jul 30 13:35:22.912368 2026] [security2:error] [pid 914912:tid 915075] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/2.php"] [unique_id "amuZaq469-jfU7M1CLhJgAAAACE"]
[Thu Jul 30 13:35:23.059107 2026] [core:notice] [pid 914912:tid 915105] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:23.393129 2026] [proxy:error] [pid 914912:tid 915082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:23.393234 2026] [proxy_http:error] [pid 914912:tid 915082] [client 3.225.222.228:22079] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:23.394113 2026] [proxy:error] [pid 914912:tid 915082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:23.394175 2026] [proxy_http:error] [pid 914912:tid 915082] [client 3.225.222.228:22079] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:23.425489 2026] [proxy:error] [pid 914912:tid 915045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:23.425580 2026] [proxy_http:error] [pid 914912:tid 915045] [client 3.225.222.228:65030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:23.426215 2026] [proxy:error] [pid 914912:tid 915045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:23.426264 2026] [proxy_http:error] [pid 914912:tid 915045] [client 3.225.222.228:65030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:23.612125 2026] [security2:error] [pid 914912:tid 915126] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/op.php"] [unique_id "amuZa6469-jfU7M1CLhJqgAAAFQ"]
[Thu Jul 30 13:35:23.612255 2026] [security2:error] [pid 914912:tid 915126] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/op.php"] [unique_id "amuZa6469-jfU7M1CLhJqgAAAFQ"]
[Thu Jul 30 13:35:23.630813 2026] [security2:error] [pid 914912:tid 915053] [client 47.128.121.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZa6469-jfU7M1CLhJngAAAAs"]
[Thu Jul 30 13:35:23.682326 2026] [security2:error] [pid 914912:tid 915123] [client 172.237.109.114:57275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZa6469-jfU7M1CLhJigAAAFE"]
[Thu Jul 30 13:35:23.702104 2026] [security2:error] [pid 914912:tid 915092] [client 119.73.97.132:30659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuZa6469-jfU7M1CLhJnwAAMkU"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 13:35:24.122306 2026] [security2:error] [pid 914912:tid 915088] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/a5.php"] [unique_id "amuZbK469-jfU7M1CLhJugAAAC4"]
[Thu Jul 30 13:35:24.122461 2026] [security2:error] [pid 914912:tid 915088] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/a5.php"] [unique_id "amuZbK469-jfU7M1CLhJugAAAC4"]
[Thu Jul 30 13:35:24.434001 2026] [security2:error] [pid 914912:tid 915148] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZa6469-jfU7M1CLhJsAAAAGo"]
[Thu Jul 30 13:35:24.678600 2026] [security2:error] [pid 914912:tid 915144] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ws80.php"] [unique_id "amuZbK469-jfU7M1CLhJyAAAAGY"]
[Thu Jul 30 13:35:24.678725 2026] [security2:error] [pid 914912:tid 915144] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ws80.php"] [unique_id "amuZbK469-jfU7M1CLhJyAAAAGY"]
[Thu Jul 30 13:35:25.186176 2026] [security2:error] [pid 914912:tid 915159] [client 78.167.1.90:53631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZba469-jfU7M1CLhJ4wAAAHU"]
[Thu Jul 30 13:35:25.186521 2026] [security2:error] [pid 914912:tid 915159] [client 78.167.1.90:53631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZba469-jfU7M1CLhJ4wAAAHU"]
[Thu Jul 30 13:35:25.209476 2026] [security2:error] [pid 914912:tid 915069] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xa.php"] [unique_id "amuZba469-jfU7M1CLhJ5AAAABs"]
[Thu Jul 30 13:35:25.209600 2026] [security2:error] [pid 914912:tid 915069] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xa.php"] [unique_id "amuZba469-jfU7M1CLhJ5AAAABs"]
[Thu Jul 30 13:35:25.773524 2026] [security2:error] [pid 914912:tid 915080] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/asd67.php"] [unique_id "amuZba469-jfU7M1CLhJ7gAAACY"]
[Thu Jul 30 13:35:25.773642 2026] [security2:error] [pid 914912:tid 915080] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/asd67.php"] [unique_id "amuZba469-jfU7M1CLhJ7gAAACY"]
[Thu Jul 30 13:35:26.252582 2026] [proxy:error] [pid 914912:tid 915064] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:26.252659 2026] [proxy_http:error] [pid 914912:tid 915064] [client 44.213.206.96:41110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:26.253254 2026] [proxy:error] [pid 914912:tid 915064] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:26.253305 2026] [proxy_http:error] [pid 914912:tid 915064] [client 44.213.206.96:41110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:26.272419 2026] [proxy:error] [pid 914912:tid 915161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:26.272503 2026] [proxy_http:error] [pid 914912:tid 915161] [client 52.4.19.39:58471] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:26.273114 2026] [proxy:error] [pid 914912:tid 915161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:26.273160 2026] [proxy_http:error] [pid 914912:tid 915161] [client 52.4.19.39:58471] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:26.314796 2026] [security2:error] [pid 914912:tid 915068] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/bk.php"] [unique_id "amuZbq469-jfU7M1CLhKAQAAABo"]
[Thu Jul 30 13:35:26.314883 2026] [security2:error] [pid 914912:tid 915068] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/bk.php"] [unique_id "amuZbq469-jfU7M1CLhKAQAAABo"]
[Thu Jul 30 13:35:27.068186 2026] [security2:error] [pid 914912:tid 915096] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-links.php"] [unique_id "amuZb6469-jfU7M1CLhKEwAAADY"]
[Thu Jul 30 13:35:27.068290 2026] [security2:error] [pid 914912:tid 915096] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-links.php"] [unique_id "amuZb6469-jfU7M1CLhKEwAAADY"]
[Thu Jul 30 13:35:27.599477 2026] [security2:error] [pid 914912:tid 915023] [remote 195.26.253.119:57784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-468361c2.glb.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuZb6469-jfU7M1CLhKHwAAZW4"]
[Thu Jul 30 13:35:27.653190 2026] [security2:error] [pid 914912:tid 915131] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mosty.php"] [unique_id "amuZb6469-jfU7M1CLhKIwAAAFk"]
[Thu Jul 30 13:35:27.653304 2026] [security2:error] [pid 914912:tid 915131] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/mosty.php"] [unique_id "amuZb6469-jfU7M1CLhKIwAAAFk"]
[Thu Jul 30 13:35:28.168810 2026] [security2:error] [pid 914912:tid 915070] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sump3.php"] [unique_id "amuZcK469-jfU7M1CLhKNQAAABw"]
[Thu Jul 30 13:35:28.168903 2026] [security2:error] [pid 914912:tid 915070] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/sump3.php"] [unique_id "amuZcK469-jfU7M1CLhKNQAAABw"]
[Thu Jul 30 13:35:28.209714 2026] [security2:error] [pid 914912:tid 915033] [remote 216.73.217.142:14067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuZcK469-jfU7M1CLhKOQAABXg"]
[Thu Jul 30 13:35:28.675710 2026] [security2:error] [pid 914912:tid 915162] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/first.php"] [unique_id "amuZcK469-jfU7M1CLhKRQAAAHg"]
[Thu Jul 30 13:35:28.675817 2026] [security2:error] [pid 914912:tid 915162] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/first.php"] [unique_id "amuZcK469-jfU7M1CLhKRQAAAHg"]
[Thu Jul 30 13:35:28.825042 2026] [security2:error] [pid 914912:tid 914913] [remote 57.141.0.65:64432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/64637765089/feed/rss2/"] [unique_id "amuZcK469-jfU7M1CLhKSgAADgA"]
[Thu Jul 30 13:35:29.088027 2026] [proxy:error] [pid 914912:tid 915086] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:29.088102 2026] [proxy_http:error] [pid 914912:tid 915086] [client 3.228.112.215:57017] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:29.088689 2026] [proxy:error] [pid 914912:tid 915086] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:29.088731 2026] [proxy_http:error] [pid 914912:tid 915086] [client 3.228.112.215:57017] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:29.091820 2026] [proxy:error] [pid 914912:tid 915049] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:29.091896 2026] [proxy_http:error] [pid 914912:tid 915049] [client 52.202.41.153:41414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:29.092548 2026] [proxy:error] [pid 914912:tid 915049] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:29.092597 2026] [proxy_http:error] [pid 914912:tid 915049] [client 52.202.41.153:41414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:29.183270 2026] [security2:error] [pid 914912:tid 915155] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/acp.php"] [unique_id "amuZca469-jfU7M1CLhKVwAAAHE"]
[Thu Jul 30 13:35:29.183368 2026] [security2:error] [pid 914912:tid 915155] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/acp.php"] [unique_id "amuZca469-jfU7M1CLhKVwAAAHE"]
[Thu Jul 30 13:35:29.709722 2026] [security2:error] [pid 914912:tid 915101] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuZca469-jfU7M1CLhKbAAAADs"]
[Thu Jul 30 13:35:29.709810 2026] [security2:error] [pid 914912:tid 915101] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-good.php"] [unique_id "amuZca469-jfU7M1CLhKbAAAADs"]
[Thu Jul 30 13:35:30.024990 2026] [security2:error] [pid 914912:tid 915058] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZca469-jfU7M1CLhKYQAAABA"]
[Thu Jul 30 13:35:30.121750 2026] [security2:error] [pid 914912:tid 915147] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZca469-jfU7M1CLhKZAAAAGk"]
[Thu Jul 30 13:35:30.266157 2026] [security2:error] [pid 914912:tid 915050] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/daerl3.php"] [unique_id "amuZcq469-jfU7M1CLhKeQAAAAg"]
[Thu Jul 30 13:35:30.266311 2026] [security2:error] [pid 914912:tid 915050] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/daerl3.php"] [unique_id "amuZcq469-jfU7M1CLhKeQAAAAg"]
[Thu Jul 30 13:35:30.539227 2026] [security2:error] [pid 914912:tid 915090] [client 119.73.97.132:30659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuZcq469-jfU7M1CLhKdwAAMHw"]
[Thu Jul 30 13:35:30.908585 2026] [security2:error] [pid 914912:tid 915085] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/php5.php"] [unique_id "amuZcq469-jfU7M1CLhKiwAAACs"]
[Thu Jul 30 13:35:30.908701 2026] [security2:error] [pid 914912:tid 915085] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/php5.php"] [unique_id "amuZcq469-jfU7M1CLhKiwAAACs"]
[Thu Jul 30 13:35:30.997356 2026] [security2:error] [pid 914912:tid 915068] [client 192.178.15.67:54907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuZcq469-jfU7M1CLhKfgAAABo"]
[Thu Jul 30 13:35:31.068443 2026] [core:notice] [pid 914912:tid 915062] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:31.214829 2026] [proxy:error] [pid 914912:tid 915096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:31.214909 2026] [proxy_http:error] [pid 914912:tid 915096] [client 98.87.102.177:58306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:31.215683 2026] [proxy:error] [pid 914912:tid 915096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:31.215736 2026] [proxy_http:error] [pid 914912:tid 915096] [client 98.87.102.177:58306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:31.239559 2026] [proxy:error] [pid 914912:tid 915067] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:31.239635 2026] [proxy_http:error] [pid 914912:tid 915067] [client 44.216.125.112:55249] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:31.240515 2026] [proxy:error] [pid 914912:tid 915067] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:31.240576 2026] [proxy_http:error] [pid 914912:tid 915067] [client 44.216.125.112:55249] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:31.442718 2026] [security2:error] [pid 914912:tid 915146] [client 216.73.216.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myintentionalreset.com"] [uri "/index.php"] [unique_id "amuZc6469-jfU7M1CLhKkQAAAGg"]
[Thu Jul 30 13:35:31.450192 2026] [security2:error] [pid 914912:tid 915081] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xoot.php"] [unique_id "amuZc6469-jfU7M1CLhKqQAAACc"]
[Thu Jul 30 13:35:31.450334 2026] [security2:error] [pid 914912:tid 915081] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/xoot.php"] [unique_id "amuZc6469-jfU7M1CLhKqQAAACc"]
[Thu Jul 30 13:35:31.868079 2026] [security2:error] [pid 914912:tid 915138] [client 185.191.171.13:49022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ejournalugj.com"] [uri "/index.php/ELPER-Tech/login"] [unique_id "amuZc6469-jfU7M1CLhKtQAAAGA"]
[Thu Jul 30 13:35:31.868229 2026] [security2:error] [pid 914912:tid 915138] [client 185.191.171.13:49022] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejournalugj.com"] [uri "/index.php/ELPER-Tech/login"] [unique_id "amuZc6469-jfU7M1CLhKtQAAAGA"]
[Thu Jul 30 13:35:31.998996 2026] [security2:error] [pid 914912:tid 915140] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZc6469-jfU7M1CLhKqAAAYhg"]
[Thu Jul 30 13:35:32.063397 2026] [security2:error] [pid 914912:tid 915135] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/clxcc.php"] [unique_id "amuZdK469-jfU7M1CLhKuQAAAF0"]
[Thu Jul 30 13:35:32.063516 2026] [security2:error] [pid 914912:tid 915135] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/clxcc.php"] [unique_id "amuZdK469-jfU7M1CLhKuQAAAF0"]
[Thu Jul 30 13:35:32.834493 2026] [security2:error] [pid 914912:tid 915102] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ai.php"] [unique_id "amuZdK469-jfU7M1CLhKzgAAADw"]
[Thu Jul 30 13:35:32.834605 2026] [security2:error] [pid 914912:tid 915102] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ai.php"] [unique_id "amuZdK469-jfU7M1CLhKzgAAADw"]
[Thu Jul 30 13:35:33.382643 2026] [security2:error] [pid 914912:tid 915129] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/nwflm.php"] [unique_id "amuZda469-jfU7M1CLhK2AAAAFc"]
[Thu Jul 30 13:35:33.382754 2026] [security2:error] [pid 914912:tid 915129] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/nwflm.php"] [unique_id "amuZda469-jfU7M1CLhK2AAAAFc"]
[Thu Jul 30 13:35:34.059531 2026] [security2:error] [pid 914912:tid 915167] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/hypo.php"] [unique_id "amuZdq469-jfU7M1CLhK7wAAAH0"]
[Thu Jul 30 13:35:34.059613 2026] [security2:error] [pid 914912:tid 915167] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/hypo.php"] [unique_id "amuZdq469-jfU7M1CLhK7wAAAH0"]
[Thu Jul 30 13:35:34.123662 2026] [security2:error] [pid 914912:tid 915090] [client 119.73.97.132:30659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuZcq469-jfU7M1CLhKeAAAMAI"]
[Thu Jul 30 13:35:34.209244 2026] [security2:error] [pid 914912:tid 915080] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZda469-jfU7M1CLhK3AAAJis"]
[Thu Jul 30 13:35:34.639055 2026] [security2:error] [pid 914912:tid 915148] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuZdq469-jfU7M1CLhK-gAAAGo"]
[Thu Jul 30 13:35:34.639165 2026] [security2:error] [pid 914912:tid 915148] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w3llscc.php"] [unique_id "amuZdq469-jfU7M1CLhK-gAAAGo"]
[Thu Jul 30 13:35:35.231761 2026] [security2:error] [pid 914912:tid 915137] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuZd6469-jfU7M1CLhLBAAAAF8"]
[Thu Jul 30 13:35:35.231870 2026] [security2:error] [pid 914912:tid 915137] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuZd6469-jfU7M1CLhLBAAAAF8"]
[Thu Jul 30 13:35:35.838600 2026] [security2:error] [pid 914912:tid 915103] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuZd6469-jfU7M1CLhLFwAAAD0"]
[Thu Jul 30 13:35:35.838752 2026] [security2:error] [pid 914912:tid 915103] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/8.php"] [unique_id "amuZd6469-jfU7M1CLhLFwAAAD0"]
[Thu Jul 30 13:35:35.900241 2026] [security2:error] [pid 914912:tid 915056] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZd6469-jfU7M1CLhLBwAAAA4"]
[Thu Jul 30 13:35:36.288789 2026] [core:notice] [pid 914912:tid 914984] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:36.360699 2026] [security2:error] [pid 914912:tid 914988] [remote 57.141.0.42:62558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuZeK469-jfU7M1CLhLJwAAD0s"]
[Thu Jul 30 13:35:36.395218 2026] [security2:error] [pid 914912:tid 915069] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fnstall.php"] [unique_id "amuZeK469-jfU7M1CLhLKQAAABs"]
[Thu Jul 30 13:35:36.395358 2026] [security2:error] [pid 914912:tid 915069] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fnstall.php"] [unique_id "amuZeK469-jfU7M1CLhLKQAAABs"]
[Thu Jul 30 13:35:36.842813 2026] [security2:error] [pid 914912:tid 915112] [client 78.167.1.90:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZeK469-jfU7M1CLhLMgAAAEY"]
[Thu Jul 30 13:35:36.843331 2026] [security2:error] [pid 914912:tid 915112] [client 78.167.1.90:54259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZeK469-jfU7M1CLhLMgAAAEY"]
[Thu Jul 30 13:35:36.849111 2026] [core:notice] [pid 914912:tid 914990] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:36.909629 2026] [security2:error] [pid 914912:tid 915100] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/edorxrr.php"] [unique_id "amuZeK469-jfU7M1CLhLNAAAADo"]
[Thu Jul 30 13:35:36.909760 2026] [security2:error] [pid 914912:tid 915100] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/edorxrr.php"] [unique_id "amuZeK469-jfU7M1CLhLNAAAADo"]
[Thu Jul 30 13:35:37.481122 2026] [security2:error] [pid 914912:tid 915092] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/setup.php"] [unique_id "amuZea469-jfU7M1CLhLQgAAADI"]
[Thu Jul 30 13:35:37.481241 2026] [security2:error] [pid 914912:tid 915092] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/setup.php"] [unique_id "amuZea469-jfU7M1CLhLQgAAADI"]
[Thu Jul 30 13:35:37.965652 2026] [security2:error] [pid 914912:tid 915068] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/6.php"] [unique_id "amuZea469-jfU7M1CLhLTAAAABo"]
[Thu Jul 30 13:35:37.965799 2026] [security2:error] [pid 914912:tid 915068] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/6.php"] [unique_id "amuZea469-jfU7M1CLhLTAAAABo"]
[Thu Jul 30 13:35:38.477824 2026] [security2:error] [pid 914912:tid 915097] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w3lls.php"] [unique_id "amuZeq469-jfU7M1CLhLWwAAADc"]
[Thu Jul 30 13:35:38.477925 2026] [security2:error] [pid 914912:tid 915097] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/w3lls.php"] [unique_id "amuZeq469-jfU7M1CLhLWwAAADc"]
[Thu Jul 30 13:35:38.480012 2026] [security2:error] [pid 914912:tid 915013] [remote 57.141.0.52:63816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/ELTERA/about/editorialTeam"] [unique_id "amuZeq469-jfU7M1CLhLXAAAKWQ"]
[Thu Jul 30 13:35:38.755627 2026] [security2:error] [pid 914912:tid 915052] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZeq469-jfU7M1CLhLXwAAAAo"]
[Thu Jul 30 13:35:39.031850 2026] [security2:error] [pid 914912:tid 915154] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/99.php"] [unique_id "amuZe6469-jfU7M1CLhLbwAAAHA"]
[Thu Jul 30 13:35:39.031952 2026] [security2:error] [pid 914912:tid 915154] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/99.php"] [unique_id "amuZe6469-jfU7M1CLhLbwAAAHA"]
[Thu Jul 30 13:35:39.088690 2026] [core:notice] [pid 914912:tid 915011] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:39.566384 2026] [security2:error] [pid 914912:tid 915168] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/admin.php"] [unique_id "amuZe6469-jfU7M1CLhLigAAAH4"]
[Thu Jul 30 13:35:39.566476 2026] [security2:error] [pid 914912:tid 915168] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/admin.php"] [unique_id "amuZe6469-jfU7M1CLhLigAAAH4"]
[Thu Jul 30 13:35:40.098217 2026] [security2:error] [pid 914912:tid 915101] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/media.php"] [unique_id "amuZfK469-jfU7M1CLhLzAAAADs"]
[Thu Jul 30 13:35:40.098348 2026] [security2:error] [pid 914912:tid 915101] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/media.php"] [unique_id "amuZfK469-jfU7M1CLhLzAAAADs"]
[Thu Jul 30 13:35:40.246610 2026] [security2:error] [pid 914912:tid 915115] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZe6469-jfU7M1CLhLpAAAAEk"]
[Thu Jul 30 13:35:40.622274 2026] [security2:error] [pid 914912:tid 915138] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuZfK469-jfU7M1CLhL1wAAAGA"]
[Thu Jul 30 13:35:40.622394 2026] [security2:error] [pid 914912:tid 915138] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuZfK469-jfU7M1CLhL1wAAAGA"]
[Thu Jul 30 13:35:40.795291 2026] [security2:error] [pid 914912:tid 914961] [remote 103.59.160.210:53513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.aetiiph.net"] [uri "/login/index.php"] [unique_id "amuZfK469-jfU7M1CLhL3gAAOjA"]
[Thu Jul 30 13:35:41.122643 2026] [security2:error] [pid 914912:tid 915076] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/222.php"] [unique_id "amuZfa469-jfU7M1CLhL6QAAACI"]
[Thu Jul 30 13:35:41.122768 2026] [security2:error] [pid 914912:tid 915076] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/222.php"] [unique_id "amuZfa469-jfU7M1CLhL6QAAACI"]
[Thu Jul 30 13:35:41.649264 2026] [security2:error] [pid 914912:tid 915163] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-load.php"] [unique_id "amuZfa469-jfU7M1CLhL-gAAAHk"]
[Thu Jul 30 13:35:41.649416 2026] [security2:error] [pid 914912:tid 915163] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-load.php"] [unique_id "amuZfa469-jfU7M1CLhL-gAAAHk"]
[Thu Jul 30 13:35:41.798012 2026] [autoindex:error] [pid 914912:tid 915155] [client 157.143.3.35:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:35:41.955688 2026] [autoindex:error] [pid 914912:tid 914980] [remote 157.143.3.35:44608] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:35:42.067292 2026] [security2:error] [pid 914912:tid 915158] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZfa469-jfU7M1CLhL9QAAAHQ"]
[Thu Jul 30 13:35:42.208588 2026] [security2:error] [pid 914912:tid 915136] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuZfq469-jfU7M1CLhMDAAAAF4"]
[Thu Jul 30 13:35:42.208712 2026] [security2:error] [pid 914912:tid 915136] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuZfq469-jfU7M1CLhMDAAAAF4"]
[Thu Jul 30 13:35:42.276779 2026] [security2:error] [pid 914912:tid 914977] [remote 57.141.0.22:60684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/44562851719/feed/rss2/"] [unique_id "amuZfq469-jfU7M1CLhMEAAAEUA"]
[Thu Jul 30 13:35:42.677663 2026] [security2:error] [pid 914912:tid 915094] [client 185.191.171.19:50232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/03/18/publicada-lei-que-permite-que-governador-da-paraiba-compre-vacinas-contra-a-covid-19/"] [unique_id "amuZfq469-jfU7M1CLhMHAAAADQ"]
[Thu Jul 30 13:35:42.677813 2026] [security2:error] [pid 914912:tid 915094] [client 185.191.171.19:50232] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/03/18/publicada-lei-que-permite-que-governador-da-paraiba-compre-vacinas-contra-a-covid-19/"] [unique_id "amuZfq469-jfU7M1CLhMHAAAADQ"]
[Thu Jul 30 13:35:42.731805 2026] [security2:error] [pid 914912:tid 915075] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZfq469-jfU7M1CLhMHgAAACE"]
[Thu Jul 30 13:35:42.731892 2026] [security2:error] [pid 914912:tid 915075] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZfq469-jfU7M1CLhMHgAAACE"]
[Thu Jul 30 13:35:43.224806 2026] [security2:error] [pid 914912:tid 915055] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/memberfuns.php"] [unique_id "amuZf6469-jfU7M1CLhMMwAAAA0"]
[Thu Jul 30 13:35:43.224921 2026] [security2:error] [pid 914912:tid 915055] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/memberfuns.php"] [unique_id "amuZf6469-jfU7M1CLhMMwAAAA0"]
[Thu Jul 30 13:35:43.743032 2026] [security2:error] [pid 914912:tid 915125] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/orange3.php"] [unique_id "amuZf6469-jfU7M1CLhMRAAAAFM"]
[Thu Jul 30 13:35:43.743146 2026] [security2:error] [pid 914912:tid 915125] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/orange3.php"] [unique_id "amuZf6469-jfU7M1CLhMRAAAAFM"]
[Thu Jul 30 13:35:43.925825 2026] [security2:error] [pid 914912:tid 915010] [remote 57.141.0.63:30382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuZf6469-jfU7M1CLhMSAAAGWE"]
[Thu Jul 30 13:35:44.139257 2026] [security2:error] [pid 914912:tid 915085] [client 40.77.167.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuZf6469-jfU7M1CLhMLQAAACs"]
[Thu Jul 30 13:35:44.325652 2026] [security2:error] [pid 914912:tid 915044] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuZgK469-jfU7M1CLhMUQAAAAI"]
[Thu Jul 30 13:35:44.325759 2026] [security2:error] [pid 914912:tid 915044] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuZgK469-jfU7M1CLhMUQAAAAI"]
[Thu Jul 30 13:35:44.907690 2026] [security2:error] [pid 914912:tid 915080] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuZgK469-jfU7M1CLhMXQAAACY"]
[Thu Jul 30 13:35:44.907810 2026] [security2:error] [pid 914912:tid 915080] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wp-the.php"] [unique_id "amuZgK469-jfU7M1CLhMXQAAACY"]
[Thu Jul 30 13:35:45.496459 2026] [security2:error] [pid 914912:tid 915121] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/crgio.php"] [unique_id "amuZga469-jfU7M1CLhMagAAAE8"]
[Thu Jul 30 13:35:45.496607 2026] [security2:error] [pid 914912:tid 915121] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/crgio.php"] [unique_id "amuZga469-jfU7M1CLhMagAAAE8"]
[Thu Jul 30 13:35:46.348323 2026] [security2:error] [pid 914912:tid 915089] [client 78.167.1.90:55375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZgq469-jfU7M1CLhMiAAAAC8"]
[Thu Jul 30 13:35:46.348456 2026] [security2:error] [pid 914912:tid 915089] [client 78.167.1.90:55375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZgq469-jfU7M1CLhMiAAAAC8"]
[Thu Jul 30 13:35:46.506918 2026] [security2:error] [pid 914912:tid 915150] [client 127.0.0.1:56438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.elitegaragedoorrepairservices.us"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuZgq469-jfU7M1CLhMjgAAAGw"]
[Thu Jul 30 13:35:46.506918 2026] [security2:error] [pid 914912:tid 915136] [client 127.0.0.1:56450] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuZgq469-jfU7M1CLhMjwAAAF4"]
[Thu Jul 30 13:35:46.507005 2026] [security2:error] [pid 914912:tid 915053] [client 74.7.228.29:47052] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.elitegaragedoorrepairservices.us"] [uri "/robots.txt"] [unique_id "amuZgq469-jfU7M1CLhMjQAACwg"]
[Thu Jul 30 13:35:46.675886 2026] [security2:error] [pid 914912:tid 915047] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ws13.php"] [unique_id "amuZgq469-jfU7M1CLhMlgAAAAU"]
[Thu Jul 30 13:35:46.676008 2026] [security2:error] [pid 914912:tid 915047] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ws13.php"] [unique_id "amuZgq469-jfU7M1CLhMlgAAAAU"]
[Thu Jul 30 13:35:46.940834 2026] [security2:error] [pid 914912:tid 914923] [remote 45.14.225.216:53184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.225.14.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dov.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amuZgq469-jfU7M1CLhMlwAAKAo"]
[Thu Jul 30 13:35:47.518731 2026] [security2:error] [pid 914912:tid 915087] [client 74.7.175.135:35064] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "newyorkgiantsfootball.live.qsv.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuZg6469-jfU7M1CLhMqgAAAC0"]
[Thu Jul 30 13:35:47.520391 2026] [security2:error] [pid 914912:tid 915107] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/srontol.php"] [unique_id "amuZg6469-jfU7M1CLhMqwAAAEE"]
[Thu Jul 30 13:35:47.520512 2026] [security2:error] [pid 914912:tid 915107] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/srontol.php"] [unique_id "amuZg6469-jfU7M1CLhMqwAAAEE"]
[Thu Jul 30 13:35:48.098692 2026] [security2:error] [pid 914912:tid 915103] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuZhK469-jfU7M1CLhMuAAAAD0"]
[Thu Jul 30 13:35:48.098839 2026] [security2:error] [pid 914912:tid 915103] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/miru3.php"] [unique_id "amuZhK469-jfU7M1CLhMuAAAAD0"]
[Thu Jul 30 13:35:48.669373 2026] [security2:error] [pid 914912:tid 915141] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ingfo.php"] [unique_id "amuZhK469-jfU7M1CLhMxgAAAGM"]
[Thu Jul 30 13:35:48.669484 2026] [security2:error] [pid 914912:tid 915141] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ingfo.php"] [unique_id "amuZhK469-jfU7M1CLhMxgAAAGM"]
[Thu Jul 30 13:35:48.966436 2026] [security2:error] [pid 914912:tid 914927] [remote 47.128.120.17:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teknomalay.com"] [uri "/robots.txt"] [unique_id "amuZhK469-jfU7M1CLhMywAAAg4"]
[Thu Jul 30 13:35:49.127573 2026] [security2:error] [pid 914912:tid 915164] [client 34.67.106.17:58160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "pnimanpower.net"] [uri "/cgi-sys/404.html"] [unique_id "amuZha469-jfU7M1CLhM0AAAAHo"]
[Thu Jul 30 13:35:49.210205 2026] [security2:error] [pid 914912:tid 915147] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ey5.php"] [unique_id "amuZha469-jfU7M1CLhM1AAAAGk"]
[Thu Jul 30 13:35:49.210321 2026] [security2:error] [pid 914912:tid 915147] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ey5.php"] [unique_id "amuZha469-jfU7M1CLhM1AAAAGk"]
[Thu Jul 30 13:35:49.427554 2026] [security2:error] [pid 914912:tid 915075] [client 74.7.175.144:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buyfluoxetine.store"] [uri "/cgi-sys/404.html"] [unique_id "amuZha469-jfU7M1CLhM3gAAACE"]
[Thu Jul 30 13:35:49.448090 2026] [core:notice] [pid 914912:tid 914940] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:49.506524 2026] [security2:error] [pid 914912:tid 915100] [client 74.7.230.13:53240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.hello-pal.com"] [uri "/cgi-sys/404.html"] [unique_id "amuZha469-jfU7M1CLhM4AAAOic"]
[Thu Jul 30 13:35:49.647890 2026] [autoindex:error] [pid 914912:tid 914946] [remote 74.7.227.191:45254] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:35:49.706005 2026] [security2:error] [pid 914912:tid 915093] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fine.php"] [unique_id "amuZha469-jfU7M1CLhM5gAAADM"]
[Thu Jul 30 13:35:49.706122 2026] [security2:error] [pid 914912:tid 915093] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/fine.php"] [unique_id "amuZha469-jfU7M1CLhM5gAAADM"]
[Thu Jul 30 13:35:49.821503 2026] [security2:error] [pid 914912:tid 915112] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZha469-jfU7M1CLhM1wAAAEY"]
[Thu Jul 30 13:35:50.064932 2026] [core:notice] [pid 914912:tid 914943] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:35:51.752023 2026] [security2:error] [pid 914912:tid 915043] [client 172.236.9.101:40443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZh6469-jfU7M1CLhNCgAAAAE"]
[Thu Jul 30 13:35:52.054926 2026] [security2:error] [pid 914912:tid 914983] [remote 74.7.243.224:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/article.php"] [unique_id "amuZiK469-jfU7M1CLhNHwAAIkY"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:35:52.250109 2026] [security2:error] [pid 914912:tid 915118] [client 57.141.0.31:31260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuZh6469-jfU7M1CLhNHgAATEE"], referer: https://igetvape-australia.com/product-tag/alibarbar-ingot-double-apple-9000-puffs/
[Thu Jul 30 13:35:52.616062 2026] [core:error] [pid 914912:tid 914965] [remote 216.73.216.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:35:52.616088 2026] [core:error] [pid 914912:tid 914965] [remote 216.73.216.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:35:52.696691 2026] [security2:error] [pid 914912:tid 915055] [client 172.236.9.101:64208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZiK469-jfU7M1CLhNIwAAAA0"]
[Thu Jul 30 13:35:53.616549 2026] [proxy:error] [pid 914912:tid 915074] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:53.616627 2026] [proxy_http:error] [pid 914912:tid 915074] [client 23.180.120.146:58742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:53.617354 2026] [proxy:error] [pid 914912:tid 915074] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:35:53.617412 2026] [proxy_http:error] [pid 914912:tid 915074] [client 23.180.120.146:58742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:35:53.666965 2026] [security2:error] [pid 914912:tid 914992] [remote 216.73.217.142:47401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuZia469-jfU7M1CLhNTwAAak8"]
[Thu Jul 30 13:35:53.724930 2026] [security2:error] [pid 914912:tid 915166] [client 172.236.9.101:64863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZia469-jfU7M1CLhNQAAAAHw"]
[Thu Jul 30 13:35:53.993274 2026] [security2:error] [pid 914912:tid 915078] [client 172.237.109.114:64742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/admin/server_import.php"] [unique_id "amuZia469-jfU7M1CLhNWQAAACQ"]
[Thu Jul 30 13:35:53.994635 2026] [security2:error] [pid 914912:tid 915159] [client 172.237.109.114:53810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/phpmyadmin/server_import.php"] [unique_id "amuZia469-jfU7M1CLhNXAAAAHU"]
[Thu Jul 30 13:35:54.008073 2026] [security2:error] [pid 914912:tid 915114] [client 172.237.109.114:22558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/phpMyAdmin/server_import.php"] [unique_id "amuZiq469-jfU7M1CLhNXQAAAEg"]
[Thu Jul 30 13:35:54.009155 2026] [security2:error] [pid 914912:tid 915070] [client 172.237.109.114:17871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/admin/phpMyAdmin/server_import.php"] [unique_id "amuZiq469-jfU7M1CLhNXgAAABw"]
[Thu Jul 30 13:35:54.009313 2026] [security2:error] [pid 914912:tid 915161] [client 172.237.109.114:40241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/db/server_import.php"] [unique_id "amuZiq469-jfU7M1CLhNXwAAAHc"]
[Thu Jul 30 13:35:54.010017 2026] [security2:error] [pid 914912:tid 915137] [client 172.237.109.114:29007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/PMA/server_import.php"] [unique_id "amuZiq469-jfU7M1CLhNYQAAAF8"]
[Thu Jul 30 13:35:54.182252 2026] [security2:error] [pid 914912:tid 915132] [client 185.156.175.51:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.175.156.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuZiq469-jfU7M1CLhNZgAAAFo"]
[Thu Jul 30 13:35:54.182344 2026] [security2:error] [pid 914912:tid 915132] [client 185.156.175.51:55206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuZiq469-jfU7M1CLhNZgAAAFo"]
[Thu Jul 30 13:35:54.219778 2026] [security2:error] [pid 914912:tid 915076] [client 172.237.109.114:11137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/admin/pma/server_import.php"] [unique_id "amuZia469-jfU7M1CLhNVQAAACI"]
[Thu Jul 30 13:35:54.240350 2026] [security2:error] [pid 914912:tid 915160] [client 172.237.109.114:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/server_import.php"] [unique_id "amuZia469-jfU7M1CLhNWgAAAHY"]
[Thu Jul 30 13:35:54.251810 2026] [security2:error] [pid 914912:tid 915123] [client 172.237.109.114:1357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/pma/server_import.php"] [unique_id "amuZia469-jfU7M1CLhNWAAAAFE"]
[Thu Jul 30 13:35:54.257883 2026] [security2:error] [pid 914912:tid 915009] [remote 74.7.227.39:48552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuZiq469-jfU7M1CLhNagAAcWA"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/siteseo/main
[Thu Jul 30 13:35:54.791340 2026] [security2:error] [pid 914912:tid 915062] [client 172.236.9.101:10895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZiq469-jfU7M1CLhNawAAABQ"]
[Thu Jul 30 13:35:55.634088 2026] [security2:error] [pid 914912:tid 915042] [client 74.7.175.143:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "xzd.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuZiq469-jfU7M1CLhNdQAAAAA"]
[Thu Jul 30 13:35:55.635013 2026] [security2:error] [pid 914912:tid 915049] [client 74.7.175.143:35696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "xzd.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuZiq469-jfU7M1CLhNcgAAB14"]
[Thu Jul 30 13:35:55.642498 2026] [security2:error] [pid 914912:tid 915090] [client 172.237.109.114:60384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZi6469-jfU7M1CLhNowAAADA"]
[Thu Jul 30 13:35:55.855327 2026] [security2:error] [pid 914912:tid 915118] [client 172.236.9.101:6457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZi6469-jfU7M1CLhNwAAAAEw"]
[Thu Jul 30 13:35:55.868181 2026] [security2:error] [pid 914912:tid 915046] [client 141.95.54.157:60682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.54.95.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/password_lost.php"] [unique_id "amuZi6469-jfU7M1CLhN2AAAAAQ"]
[Thu Jul 30 13:35:56.234345 2026] [security2:error] [pid 914912:tid 915082] [client 50.6.43.217:22258] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuZjK469-jfU7M1CLhN6gAAACg"]
[Thu Jul 30 13:35:56.258115 2026] [security2:error] [pid 914912:tid 915091] [client 50.6.43.217:22270] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuZjK469-jfU7M1CLhN6wAAADE"]
[Thu Jul 30 13:35:56.432461 2026] [security2:error] [pid 914912:tid 915084] [client 151.80.133.130:60100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.133.80.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/password_lost.php"] [unique_id "amuZjK469-jfU7M1CLhN7gAAACo"]
[Thu Jul 30 13:35:56.547208 2026] [security2:error] [pid 914912:tid 915105] [client 74.7.241.174:55862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.website-2098ead5.qzb.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuZjK469-jfU7M1CLhN9QAAPzc"]
[Thu Jul 30 13:35:56.854141 2026] [security2:error] [pid 914912:tid 915074] [client 172.236.9.101:43775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZjK469-jfU7M1CLhN7QAAACA"]
[Thu Jul 30 13:35:57.136404 2026] [security2:error] [pid 914912:tid 914970] [remote 74.7.227.39:48552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuZja469-jfU7M1CLhOBwAAGDk"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/siteseo/main
[Thu Jul 30 13:35:57.145942 2026] [security2:error] [pid 914912:tid 915158] [client 134.19.179.131:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuZja469-jfU7M1CLhOCAAAAHQ"]
[Thu Jul 30 13:35:57.146065 2026] [security2:error] [pid 914912:tid 915158] [client 134.19.179.131:36358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuZja469-jfU7M1CLhOCAAAAHQ"]
[Thu Jul 30 13:35:57.842690 2026] [security2:error] [pid 914912:tid 915149] [client 172.236.9.101:44548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZja469-jfU7M1CLhODAAAAGs"]
[Thu Jul 30 13:35:58.249845 2026] [security2:error] [pid 914912:tid 915136] [client 57.129.81.155:59764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/new.php"] [unique_id "amuZja469-jfU7M1CLhOHAAAAF4"]
[Thu Jul 30 13:35:58.425512 2026] [security2:error] [pid 914912:tid 915156] [client 217.182.79.131:38962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.79.182.217.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuZjq469-jfU7M1CLhOKQAAAHI"]
[Thu Jul 30 13:35:58.876332 2026] [security2:error] [pid 914912:tid 915130] [client 51.75.21.177:41236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.21.75.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuZjq469-jfU7M1CLhONgAAAFg"]
[Thu Jul 30 13:35:58.893536 2026] [security2:error] [pid 914912:tid 915123] [client 172.236.9.101:33025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZjq469-jfU7M1CLhOKAAAAFE"]
[Thu Jul 30 13:35:59.109168 2026] [security2:error] [pid 914912:tid 915161] [client 51.75.23.120:60176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.23.75.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/new.php"] [unique_id "amuZjq469-jfU7M1CLhONQAAAHc"]
[Thu Jul 30 13:35:59.863729 2026] [security2:error] [pid 914912:tid 915061] [client 172.236.9.101:37007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZj6469-jfU7M1CLhORgAAABM"]
[Thu Jul 30 13:36:00.099203 2026] [security2:error] [pid 914912:tid 915057] [client 50.6.43.217:59044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuZj6469-jfU7M1CLhORQAAAA8"]
[Thu Jul 30 13:36:00.873257 2026] [security2:error] [pid 914912:tid 915095] [client 50.6.43.217:59046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuZkK469-jfU7M1CLhOVQAAADU"]
[Thu Jul 30 13:36:00.894177 2026] [security2:error] [pid 914912:tid 915069] [client 172.236.9.101:37595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZkK469-jfU7M1CLhOYQAAABs"]
[Thu Jul 30 13:36:01.596853 2026] [security2:error] [pid 914912:tid 915119] [client 50.6.43.217:22926] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuZka469-jfU7M1CLhOgAAAAE0"]
[Thu Jul 30 13:36:01.879627 2026] [security2:error] [pid 914912:tid 915125] [client 172.236.9.101:62735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZka469-jfU7M1CLhOegAAAFM"]
[Thu Jul 30 13:36:02.629666 2026] [security2:error] [pid 914912:tid 915096] [client 50.6.43.217:22934] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuZkq469-jfU7M1CLhOmAAAADY"]
[Thu Jul 30 13:36:02.862716 2026] [security2:error] [pid 914912:tid 915145] [client 172.236.9.101:55852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZkq469-jfU7M1CLhOkwAAAGc"]
[Thu Jul 30 13:36:03.467075 2026] [security2:error] [pid 914912:tid 915109] [client 74.7.175.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.online-hope.com"] [uri "/index.php"] [unique_id "amuZk6469-jfU7M1CLhOpgAAAEM"]
[Thu Jul 30 13:36:03.467837 2026] [security2:error] [pid 914912:tid 915052] [client 74.7.175.130:58368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.online-hope.com"] [uri "/robots.txt"] [unique_id "amuZk6469-jfU7M1CLhOpAAACmM"]
[Thu Jul 30 13:36:03.668436 2026] [security2:error] [pid 914912:tid 915033] [remote 216.73.217.142:47412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuZk6469-jfU7M1CLhOuAAAAHg"]
[Thu Jul 30 13:36:03.904962 2026] [security2:error] [pid 914912:tid 915069] [client 172.236.9.101:34060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZk6469-jfU7M1CLhOrAAAABs"]
[Thu Jul 30 13:36:04.241176 2026] [security2:error] [pid 914912:tid 915083] [client 127.0.0.1:23096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuZlK469-jfU7M1CLhOwwAAACk"]
[Thu Jul 30 13:36:04.241338 2026] [security2:error] [pid 914912:tid 915153] [client 74.7.228.5:45800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.qzb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuZlK469-jfU7M1CLhOwgAAb3A"]
[Thu Jul 30 13:36:04.265099 2026] [security2:error] [pid 914912:tid 915103] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZk6469-jfU7M1CLhOtwAAAD0"]
[Thu Jul 30 13:36:04.883043 2026] [security2:error] [pid 914912:tid 915138] [client 172.236.9.101:8353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZlK469-jfU7M1CLhOxwAAAGA"]
[Thu Jul 30 13:36:05.884702 2026] [security2:error] [pid 914912:tid 915121] [client 172.236.9.101:46473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZla469-jfU7M1CLhO4QAAAE8"]
[Thu Jul 30 13:36:06.635456 2026] [security2:error] [pid 914912:tid 914928] [remote 74.7.227.39:54420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuZlq469-jfU7M1CLhPBQAAIA8"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/siteseo/main
[Thu Jul 30 13:36:06.837587 2026] [security2:error] [pid 914912:tid 915073] [client 172.236.9.101:37279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZlq469-jfU7M1CLhO_AAAAB8"]
[Thu Jul 30 13:36:07.836000 2026] [security2:error] [pid 914912:tid 915131] [client 172.236.9.101:30743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZl6469-jfU7M1CLhPFgAAAFk"]
[Thu Jul 30 13:36:07.972694 2026] [security2:error] [pid 914912:tid 915129] [client 78.167.1.90:55061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZl6469-jfU7M1CLhPJQAAAFc"]
[Thu Jul 30 13:36:07.973362 2026] [security2:error] [pid 914912:tid 915129] [client 78.167.1.90:55061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZl6469-jfU7M1CLhPJQAAAFc"]
[Thu Jul 30 13:36:08.780307 2026] [security2:error] [pid 914912:tid 915072] [client 172.236.9.101:45254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZmK469-jfU7M1CLhPMAAAAB4"]
[Thu Jul 30 13:36:08.954608 2026] [security2:error] [pid 914912:tid 914946] [remote 57.141.0.68:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4627290655/feed/rss2/"] [unique_id "amuZmK469-jfU7M1CLhPPQAAPSE"]
[Thu Jul 30 13:36:09.414164 2026] [security2:error] [pid 914912:tid 915085] [client 40.77.179.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuZmK469-jfU7M1CLhPOQAAACs"]
[Thu Jul 30 13:36:09.800645 2026] [security2:error] [pid 914912:tid 915162] [client 172.236.9.101:32422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZma469-jfU7M1CLhPRwAAAHg"]
[Thu Jul 30 13:36:10.798687 2026] [security2:error] [pid 914912:tid 915121] [client 172.236.9.101:23369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZmq469-jfU7M1CLhPZQAAAE8"]
[Thu Jul 30 13:36:10.825269 2026] [core:notice] [pid 914912:tid 915064] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:11.274872 2026] [security2:error] [pid 914912:tid 915101] [client 92.238.183.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZm6469-jfU7M1CLhPcwAAADs"]
[Thu Jul 30 13:36:12.004142 2026] [core:notice] [pid 914912:tid 915145] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:12.177260 2026] [security2:error] [pid 914912:tid 915074] [client 172.236.9.101:20525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZm6469-jfU7M1CLhPfQAAACA"]
[Thu Jul 30 13:36:13.198877 2026] [security2:error] [pid 914912:tid 915115] [client 172.236.9.101:44176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZnK469-jfU7M1CLhPlgAAAEk"]
[Thu Jul 30 13:36:13.814122 2026] [security2:error] [pid 914912:tid 915089] [client 43.172.195.121:45698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/07/26/un-short-en-jean-3-tenues-pour-lete/"] [unique_id "amuZna469-jfU7M1CLhPqgAAAC8"]
[Thu Jul 30 13:36:14.230101 2026] [security2:error] [pid 914912:tid 915132] [client 172.236.9.101:44861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZna469-jfU7M1CLhPrgAAAFo"]
[Thu Jul 30 13:36:14.496556 2026] [core:notice] [pid 914912:tid 915056] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:14.504252 2026] [security2:error] [pid 914912:tid 915056] [client 43.173.175.127:56662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/07/26/un-short-en-jean-3-tenues-pour-lete/"] [unique_id "amuZnq469-jfU7M1CLhPwAAAAA4"], referer: https://carnetdeshopping.com/index.php/2011/07/26/un-short-en-jean-3-tenues-pour-lete/
[Thu Jul 30 13:36:15.119355 2026] [core:notice] [pid 914912:tid 915087] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:15.177725 2026] [security2:error] [pid 914912:tid 915168] [client 172.236.9.101:49152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZnq469-jfU7M1CLhPxAAAAH4"]
[Thu Jul 30 13:36:15.245624 2026] [security2:error] [pid 914912:tid 915167] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZna469-jfU7M1CLhPtQAAAH0"]
[Thu Jul 30 13:36:16.103074 2026] [security2:error] [pid 914912:tid 915066] [client 172.236.9.101:35495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZn6469-jfU7M1CLhP2QAAABg"]
[Thu Jul 30 13:36:17.062099 2026] [security2:error] [pid 914912:tid 915057] [client 172.236.9.101:29752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZoK469-jfU7M1CLhP8gAAAA8"]
[Thu Jul 30 13:36:17.411750 2026] [security2:error] [pid 914912:tid 915156] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuZoa469-jfU7M1CLhQAgAAAHI"]
[Thu Jul 30 13:36:17.411871 2026] [security2:error] [pid 914912:tid 915156] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuZoa469-jfU7M1CLhQAgAAAHI"]
[Thu Jul 30 13:36:17.680723 2026] [security2:error] [pid 914912:tid 915067] [client 20.104.18.253:50448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/011i.php"] [unique_id "amuZoa469-jfU7M1CLhQCwAAABk"]
[Thu Jul 30 13:36:17.924651 2026] [security2:error] [pid 914912:tid 915098] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuZoa469-jfU7M1CLhQEwAAADg"]
[Thu Jul 30 13:36:17.924929 2026] [security2:error] [pid 914912:tid 915098] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuZoa469-jfU7M1CLhQEwAAADg"]
[Thu Jul 30 13:36:18.059142 2026] [security2:error] [pid 914912:tid 915105] [client 172.236.9.101:9045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZoa469-jfU7M1CLhQCgAAAD8"]
[Thu Jul 30 13:36:18.245221 2026] [security2:error] [pid 914912:tid 915063] [client 78.167.1.90:55775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZoq469-jfU7M1CLhQGwAAABU"]
[Thu Jul 30 13:36:18.245836 2026] [security2:error] [pid 914912:tid 915063] [client 78.167.1.90:55775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZoq469-jfU7M1CLhQGwAAABU"]
[Thu Jul 30 13:36:18.457965 2026] [security2:error] [pid 914912:tid 915160] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wicked.php"] [unique_id "amuZoq469-jfU7M1CLhQJQAAAHY"]
[Thu Jul 30 13:36:18.458090 2026] [security2:error] [pid 914912:tid 915160] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wicked.php"] [unique_id "amuZoq469-jfU7M1CLhQJQAAAHY"]
[Thu Jul 30 13:36:18.815092 2026] [core:notice] [pid 914912:tid 915062] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:18.990926 2026] [security2:error] [pid 914912:tid 915136] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wpx.php"] [unique_id "amuZoq469-jfU7M1CLhQNwAAAF4"]
[Thu Jul 30 13:36:18.991098 2026] [security2:error] [pid 914912:tid 915136] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wpx.php"] [unique_id "amuZoq469-jfU7M1CLhQNwAAAF4"]
[Thu Jul 30 13:36:19.013240 2026] [security2:error] [pid 914912:tid 915115] [client 20.104.18.253:57708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/03a005685d.php"] [unique_id "amuZo6469-jfU7M1CLhQOAAAAEk"]
[Thu Jul 30 13:36:19.022433 2026] [security2:error] [pid 914912:tid 915141] [client 172.236.9.101:33232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZoq469-jfU7M1CLhQKQAAAGM"]
[Thu Jul 30 13:36:19.482075 2026] [security2:error] [pid 914912:tid 915067] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/images.php"] [unique_id "amuZo6469-jfU7M1CLhQSAAAABk"]
[Thu Jul 30 13:36:19.482187 2026] [security2:error] [pid 914912:tid 915067] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/images.php"] [unique_id "amuZo6469-jfU7M1CLhQSAAAABk"]
[Thu Jul 30 13:36:19.484495 2026] [security2:error] [pid 914912:tid 915087] [client 5.253.84.92:63792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/wp-login.php"] [unique_id "amuZo6469-jfU7M1CLhQRwAAAC0"]
[Thu Jul 30 13:36:19.986254 2026] [security2:error] [pid 914912:tid 915140] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/1xmomo.php"] [unique_id "amuZo6469-jfU7M1CLhQWgAAAGI"]
[Thu Jul 30 13:36:19.986384 2026] [security2:error] [pid 914912:tid 915140] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/1xmomo.php"] [unique_id "amuZo6469-jfU7M1CLhQWgAAAGI"]
[Thu Jul 30 13:36:19.994553 2026] [security2:error] [pid 914912:tid 915162] [client 172.236.9.101:16414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZo6469-jfU7M1CLhQSQAAAHg"]
[Thu Jul 30 13:36:20.292594 2026] [security2:error] [pid 914912:tid 915127] [client 20.104.18.253:47397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/403.php"] [unique_id "amuZpK469-jfU7M1CLhQYQAAAFU"]
[Thu Jul 30 13:36:20.472485 2026] [security2:error] [pid 914912:tid 915146] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/1revo.php"] [unique_id "amuZpK469-jfU7M1CLhQZwAAAGg"]
[Thu Jul 30 13:36:20.472568 2026] [security2:error] [pid 914912:tid 915146] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/1revo.php"] [unique_id "amuZpK469-jfU7M1CLhQZwAAAGg"]
[Thu Jul 30 13:36:20.480768 2026] [core:error] [pid 914912:tid 915154] [client 74.7.230.16:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:36:20.480792 2026] [core:error] [pid 914912:tid 915154] [client 74.7.230.16:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:36:20.480895 2026] [security2:error] [pid 914912:tid 915154] [client 74.7.230.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.jta.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuZpK469-jfU7M1CLhQaAAAAHA"]
[Thu Jul 30 13:36:20.481559 2026] [security2:error] [pid 914912:tid 915066] [client 74.7.230.16:56898] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.jta.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuZpK469-jfU7M1CLhQZQAAGAY"]
[Thu Jul 30 13:36:20.855123 2026] [security2:error] [pid 914912:tid 915073] [client 93.152.224.221:63312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.224.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amuZpK469-jfU7M1CLhQcwAAAB8"]
[Thu Jul 30 13:36:20.994330 2026] [security2:error] [pid 914912:tid 915082] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/cong.php"] [unique_id "amuZpK469-jfU7M1CLhQdwAAACg"]
[Thu Jul 30 13:36:20.994418 2026] [security2:error] [pid 914912:tid 915082] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/cong.php"] [unique_id "amuZpK469-jfU7M1CLhQdwAAACg"]
[Thu Jul 30 13:36:21.000749 2026] [security2:error] [pid 914912:tid 915088] [client 172.236.9.101:20620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZpK469-jfU7M1CLhQaQAAAC4"]
[Thu Jul 30 13:36:21.506162 2026] [security2:error] [pid 914912:tid 915094] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/a.php"] [unique_id "amuZpa469-jfU7M1CLhQggAAADQ"]
[Thu Jul 30 13:36:21.506294 2026] [security2:error] [pid 914912:tid 915094] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/a.php"] [unique_id "amuZpa469-jfU7M1CLhQggAAADQ"]
[Thu Jul 30 13:36:22.018195 2026] [proxy:error] [pid 914912:tid 915096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:22.018273 2026] [proxy_http:error] [pid 914912:tid 915096] [client 32.194.121.99:6185] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:22.018451 2026] [security2:error] [pid 914912:tid 915152] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/srontol.php"] [unique_id "amuZpq469-jfU7M1CLhQkwAAAG4"]
[Thu Jul 30 13:36:22.018580 2026] [security2:error] [pid 914912:tid 915152] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/srontol.php"] [unique_id "amuZpq469-jfU7M1CLhQkwAAAG4"]
[Thu Jul 30 13:36:22.019029 2026] [proxy:error] [pid 914912:tid 915096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:22.019082 2026] [proxy_http:error] [pid 914912:tid 915096] [client 32.194.121.99:6185] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:22.026087 2026] [proxy:error] [pid 914912:tid 915097] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:22.026152 2026] [proxy_http:error] [pid 914912:tid 915097] [client 34.233.129.35:58435] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:22.026423 2026] [security2:error] [pid 914912:tid 915156] [client 172.236.9.101:62401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZpa469-jfU7M1CLhQgwAAAHI"]
[Thu Jul 30 13:36:22.026798 2026] [proxy:error] [pid 914912:tid 915097] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:22.026850 2026] [proxy_http:error] [pid 914912:tid 915097] [client 34.233.129.35:58435] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:22.147856 2026] [security2:error] [pid 914912:tid 915123] [client 5.253.84.92:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/administrator/"] [unique_id "amuZpq469-jfU7M1CLhQmgAAAFE"]
[Thu Jul 30 13:36:22.396390 2026] [security2:error] [pid 914912:tid 915126] [client 68.67.112.88:31125] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "journeywomenscenter.org"] [uri "/teen-dating-violence/"] [unique_id "amuZpq469-jfU7M1CLhQogAAAFQ"]
[Thu Jul 30 13:36:22.410262 2026] [security2:error] [pid 914912:tid 915052] [client 93.152.224.221:64864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZpq469-jfU7M1CLhQoAAAAAo"]
[Thu Jul 30 13:36:22.548319 2026] [security2:error] [pid 914912:tid 915154] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/reop3.php"] [unique_id "amuZpq469-jfU7M1CLhQpgAAAHA"]
[Thu Jul 30 13:36:22.548434 2026] [security2:error] [pid 914912:tid 915154] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/reop3.php"] [unique_id "amuZpq469-jfU7M1CLhQpgAAAHA"]
[Thu Jul 30 13:36:23.025943 2026] [security2:error] [pid 914912:tid 915082] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/file5.php"] [unique_id "amuZp6469-jfU7M1CLhQtQAAACg"]
[Thu Jul 30 13:36:23.026069 2026] [security2:error] [pid 914912:tid 915082] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/file5.php"] [unique_id "amuZp6469-jfU7M1CLhQtQAAACg"]
[Thu Jul 30 13:36:23.069475 2026] [security2:error] [pid 914912:tid 915149] [client 172.236.9.101:13051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZpq469-jfU7M1CLhQpwAAAGs"]
[Thu Jul 30 13:36:23.553054 2026] [security2:error] [pid 914912:tid 915141] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/domvf.php"] [unique_id "amuZp6469-jfU7M1CLhQvgAAAGM"]
[Thu Jul 30 13:36:23.553171 2026] [security2:error] [pid 914912:tid 915141] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/domvf.php"] [unique_id "amuZp6469-jfU7M1CLhQvgAAAGM"]
[Thu Jul 30 13:36:23.708508 2026] [security2:error] [pid 914912:tid 915166] [client 20.104.18.253:57717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/404.php"] [unique_id "amuZp6469-jfU7M1CLhQxgAAAHw"]
[Thu Jul 30 13:36:24.053402 2026] [security2:error] [pid 914912:tid 915083] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/zero.php"] [unique_id "amuZqK469-jfU7M1CLhQzgAAACk"]
[Thu Jul 30 13:36:24.053557 2026] [security2:error] [pid 914912:tid 915083] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/zero.php"] [unique_id "amuZqK469-jfU7M1CLhQzgAAACk"]
[Thu Jul 30 13:36:24.084267 2026] [security2:error] [pid 914912:tid 915077] [client 172.236.9.101:4814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZp6469-jfU7M1CLhQwgAAACM"]
[Thu Jul 30 13:36:24.280941 2026] [security2:error] [pid 914912:tid 915140] [client 190.181.150.179:27730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZp6469-jfU7M1CLhQzQAAAGI"], referer: http://pkf.jo
[Thu Jul 30 13:36:24.303940 2026] [security2:error] [pid 914912:tid 915142] [client 212.30.202.54:42886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZp6469-jfU7M1CLhQvQAAAGQ"], referer: http://pkf.jo
[Thu Jul 30 13:36:24.517844 2026] [security2:error] [pid 914912:tid 915045] [client 20.104.18.253:45199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/aa.php"] [unique_id "amuZqK469-jfU7M1CLhQ3AAAAAM"]
[Thu Jul 30 13:36:24.526407 2026] [security2:error] [pid 914912:tid 915154] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/002.php"] [unique_id "amuZqK469-jfU7M1CLhQ3QAAAHA"]
[Thu Jul 30 13:36:24.526545 2026] [security2:error] [pid 914912:tid 915154] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/002.php"] [unique_id "amuZqK469-jfU7M1CLhQ3QAAAHA"]
[Thu Jul 30 13:36:24.891243 2026] [security2:error] [pid 914912:tid 915101] [client 185.244.155.92:46186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZqK469-jfU7M1CLhQ3wAAADs"], referer: http://pkf.jo
[Thu Jul 30 13:36:25.021843 2026] [security2:error] [pid 914912:tid 915136] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/thoms.php"] [unique_id "amuZqa469-jfU7M1CLhQ6QAAAF4"]
[Thu Jul 30 13:36:25.022004 2026] [security2:error] [pid 914912:tid 915136] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/thoms.php"] [unique_id "amuZqa469-jfU7M1CLhQ6QAAAF4"]
[Thu Jul 30 13:36:25.053463 2026] [security2:error] [pid 914912:tid 915125] [client 172.236.9.101:48965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZqK469-jfU7M1CLhQ3gAAAFM"]
[Thu Jul 30 13:36:25.289569 2026] [security2:error] [pid 914912:tid 915116] [client 20.104.18.253:57697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/aafewc0k.php"] [unique_id "amuZqa469-jfU7M1CLhQ7gAAAEo"]
[Thu Jul 30 13:36:25.538815 2026] [security2:error] [pid 914912:tid 915141] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fi22.php"] [unique_id "amuZqa469-jfU7M1CLhQ9QAAAGM"]
[Thu Jul 30 13:36:25.538924 2026] [security2:error] [pid 914912:tid 915141] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fi22.php"] [unique_id "amuZqa469-jfU7M1CLhQ9QAAAGM"]
[Thu Jul 30 13:36:25.637741 2026] [proxy:error] [pid 914912:tid 915070] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:25.637826 2026] [proxy_http:error] [pid 914912:tid 915070] [client 44.213.206.96:9768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:25.638405 2026] [proxy:error] [pid 914912:tid 915070] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:25.638460 2026] [proxy_http:error] [pid 914912:tid 915070] [client 44.213.206.96:9768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:25.747132 2026] [security2:error] [pid 914912:tid 915135] [client 74.7.241.136:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thdinfinity.com"] [uri "/robots.txt"] [unique_id "amuZqa469-jfU7M1CLhRAQAAAF0"]
[Thu Jul 30 13:36:25.748059 2026] [security2:error] [pid 914912:tid 915094] [client 74.7.241.136:56364] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thdinfinity.com"] [uri "/robots.txt"] [unique_id "amuZqa469-jfU7M1CLhQ_wAANCw"]
[Thu Jul 30 13:36:25.875718 2026] [security2:error] [pid 914912:tid 915080] [client 51.75.24.242:34268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZqa469-jfU7M1CLhQ9wAAACY"]
[Thu Jul 30 13:36:25.923373 2026] [core:notice] [pid 914912:tid 914963] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:26.048873 2026] [security2:error] [pid 914912:tid 915086] [client 20.48.234.177:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/"] [unique_id "amuZqq469-jfU7M1CLhRDAAAACw"]
[Thu Jul 30 13:36:26.049010 2026] [security2:error] [pid 914912:tid 915086] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/"] [unique_id "amuZqq469-jfU7M1CLhRDAAAACw"]
[Thu Jul 30 13:36:26.051892 2026] [security2:error] [pid 914912:tid 915074] [client 153.117.18.89:57745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZqa469-jfU7M1CLhRAgAAACA"], referer: http://pkf.jo
[Thu Jul 30 13:36:26.059742 2026] [security2:error] [pid 914912:tid 915165] [client 20.104.18.253:43333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/abcd.php"] [unique_id "amuZqq469-jfU7M1CLhRDQAAAHs"]
[Thu Jul 30 13:36:26.087328 2026] [security2:error] [pid 914912:tid 915133] [client 172.236.9.101:44430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZqa469-jfU7M1CLhQ-gAAAFs"]
[Thu Jul 30 13:36:26.307278 2026] [security2:error] [pid 914912:tid 915144] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZqq469-jfU7M1CLhRFAAAAGY"]
[Thu Jul 30 13:36:26.392481 2026] [security2:error] [pid 914912:tid 915054] [client 49.13.164.148:47006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuZqq469-jfU7M1CLhRJwAAAAw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:36:26.552762 2026] [security2:error] [pid 914912:tid 915076] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/82.php"] [unique_id "amuZqq469-jfU7M1CLhRKwAAACI"]
[Thu Jul 30 13:36:26.552862 2026] [security2:error] [pid 914912:tid 915076] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/82.php"] [unique_id "amuZqq469-jfU7M1CLhRKwAAACI"]
[Thu Jul 30 13:36:26.978785 2026] [core:notice] [pid 914912:tid 915073] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:26.986341 2026] [security2:error] [pid 914912:tid 915073] [client 49.13.164.148:47018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuZqq469-jfU7M1CLhROAAAAB8"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:36:27.032047 2026] [security2:error] [pid 914912:tid 915079] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sx.php"] [unique_id "amuZq6469-jfU7M1CLhROgAAACU"]
[Thu Jul 30 13:36:27.032181 2026] [security2:error] [pid 914912:tid 915079] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sx.php"] [unique_id "amuZq6469-jfU7M1CLhROgAAACU"]
[Thu Jul 30 13:36:27.078265 2026] [security2:error] [pid 914912:tid 915119] [client 172.236.9.101:1530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZqq469-jfU7M1CLhRLAAAAE0"]
[Thu Jul 30 13:36:27.507713 2026] [security2:error] [pid 914912:tid 915070] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/dex.php"] [unique_id "amuZq6469-jfU7M1CLhRQgAAABw"]
[Thu Jul 30 13:36:27.507814 2026] [security2:error] [pid 914912:tid 915070] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/dex.php"] [unique_id "amuZq6469-jfU7M1CLhRQgAAABw"]
[Thu Jul 30 13:36:27.516360 2026] [security2:error] [pid 914912:tid 915092] [client 49.13.164.148:47022] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuZq6469-jfU7M1CLhRQQAAADI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:36:27.557548 2026] [security2:error] [pid 914912:tid 915056] [client 20.104.18.253:51549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/about.php"] [unique_id "amuZq6469-jfU7M1CLhRQwAAAA4"]
[Thu Jul 30 13:36:28.027653 2026] [security2:error] [pid 914912:tid 915120] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fpwch.php"] [unique_id "amuZrK469-jfU7M1CLhRUAAAAE4"]
[Thu Jul 30 13:36:28.027766 2026] [security2:error] [pid 914912:tid 915120] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fpwch.php"] [unique_id "amuZrK469-jfU7M1CLhRUAAAAE4"]
[Thu Jul 30 13:36:28.093492 2026] [security2:error] [pid 914912:tid 915065] [client 172.236.9.101:44748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZq6469-jfU7M1CLhRRwAAABc"]
[Thu Jul 30 13:36:28.190934 2026] [security2:error] [pid 914912:tid 915113] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZrK469-jfU7M1CLhRUwAAAEc"]
[Thu Jul 30 13:36:28.535305 2026] [security2:error] [pid 914912:tid 915045] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/black.php"] [unique_id "amuZrK469-jfU7M1CLhRZAAAAAM"]
[Thu Jul 30 13:36:28.535403 2026] [security2:error] [pid 914912:tid 915045] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/black.php"] [unique_id "amuZrK469-jfU7M1CLhRZAAAAAM"]
[Thu Jul 30 13:36:28.697503 2026] [security2:error] [pid 914912:tid 915139] [client 20.104.18.253:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/admin.php"] [unique_id "amuZrK469-jfU7M1CLhRbQAAAGE"]
[Thu Jul 30 13:36:28.805323 2026] [security2:error] [pid 914912:tid 915059] [client 78.167.1.90:55943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZrK469-jfU7M1CLhRbgAAABE"]
[Thu Jul 30 13:36:28.805966 2026] [security2:error] [pid 914912:tid 915059] [client 78.167.1.90:55943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZrK469-jfU7M1CLhRbgAAABE"]
[Thu Jul 30 13:36:29.030596 2026] [security2:error] [pid 914912:tid 915149] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/loader.php"] [unique_id "amuZra469-jfU7M1CLhRdAAAAGs"]
[Thu Jul 30 13:36:29.030705 2026] [security2:error] [pid 914912:tid 915149] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/loader.php"] [unique_id "amuZra469-jfU7M1CLhRdAAAAGs"]
[Thu Jul 30 13:36:29.053093 2026] [security2:error] [pid 914912:tid 915053] [client 172.236.9.101:19748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZrK469-jfU7M1CLhRZQAAAAs"]
[Thu Jul 30 13:36:29.534533 2026] [security2:error] [pid 914912:tid 915110] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/file61.php"] [unique_id "amuZra469-jfU7M1CLhRfQAAAEQ"]
[Thu Jul 30 13:36:29.534644 2026] [security2:error] [pid 914912:tid 915110] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/file61.php"] [unique_id "amuZra469-jfU7M1CLhRfQAAAEQ"]
[Thu Jul 30 13:36:29.698043 2026] [security2:error] [pid 914912:tid 915092] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZra469-jfU7M1CLhRgQAAADI"]
[Thu Jul 30 13:36:29.925184 2026] [security2:error] [pid 914912:tid 915112] [client 20.104.18.253:47310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/adminfuns.php"] [unique_id "amuZra469-jfU7M1CLhRjQAAAEY"]
[Thu Jul 30 13:36:29.992094 2026] [security2:error] [pid 914912:tid 915001] [remote 57.141.0.1:37318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4627290655/feed/rss2/"] [unique_id "amuZra469-jfU7M1CLhRjgAAWVg"]
[Thu Jul 30 13:36:30.005908 2026] [security2:error] [pid 914912:tid 915145] [client 172.236.9.101:8478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZra469-jfU7M1CLhRfwAAAGc"]
[Thu Jul 30 13:36:30.015609 2026] [security2:error] [pid 914912:tid 915065] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-css.php"] [unique_id "amuZrq469-jfU7M1CLhRjwAAABc"]
[Thu Jul 30 13:36:30.015696 2026] [security2:error] [pid 914912:tid 915065] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-css.php"] [unique_id "amuZrq469-jfU7M1CLhRjwAAABc"]
[Thu Jul 30 13:36:30.122882 2026] [security2:error] [pid 914912:tid 915062] [client 91.186.227.137:64404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZra469-jfU7M1CLhRiQAAABQ"], referer: http://pkf.jo
[Thu Jul 30 13:36:30.540338 2026] [security2:error] [pid 914912:tid 915107] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-blink.php"] [unique_id "amuZrq469-jfU7M1CLhRmgAAAEE"]
[Thu Jul 30 13:36:30.540473 2026] [security2:error] [pid 914912:tid 915107] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-blink.php"] [unique_id "amuZrq469-jfU7M1CLhRmgAAAEE"]
[Thu Jul 30 13:36:30.811198 2026] [security2:error] [pid 914912:tid 915108] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZrq469-jfU7M1CLhRlgAAQls"]
[Thu Jul 30 13:36:31.025719 2026] [security2:error] [pid 914912:tid 915064] [client 141.94.79.3:55756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZrq469-jfU7M1CLhRogAAABY"]
[Thu Jul 30 13:36:31.054780 2026] [security2:error] [pid 914912:tid 915140] [client 172.236.9.101:6423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZrq469-jfU7M1CLhRmwAAAGI"]
[Thu Jul 30 13:36:31.095109 2026] [security2:error] [pid 914912:tid 915138] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/txets.php"] [unique_id "amuZr6469-jfU7M1CLhRqQAAAGA"]
[Thu Jul 30 13:36:31.095211 2026] [security2:error] [pid 914912:tid 915138] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/txets.php"] [unique_id "amuZr6469-jfU7M1CLhRqQAAAGA"]
[Thu Jul 30 13:36:31.194679 2026] [security2:error] [pid 914912:tid 915054] [client 121.237.36.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amuZrq469-jfU7M1CLhRpQAAAAw"]
[Thu Jul 30 13:36:31.232932 2026] [security2:error] [pid 914912:tid 915101] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZr6469-jfU7M1CLhRrAAAADs"]
[Thu Jul 30 13:36:31.423926 2026] [security2:error] [pid 914912:tid 915142] [client 20.104.18.253:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/albin.php"] [unique_id "amuZr6469-jfU7M1CLhRuAAAAGQ"]
[Thu Jul 30 13:36:31.461741 2026] [security2:error] [pid 914912:tid 915017] [remote 57.141.0.67:37788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/358522518/feed/rss2/"] [unique_id "amuZr6469-jfU7M1CLhRuQAATGg"]
[Thu Jul 30 13:36:31.632601 2026] [security2:error] [pid 914912:tid 915056] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/pucci.php"] [unique_id "amuZr6469-jfU7M1CLhRvQAAAA4"]
[Thu Jul 30 13:36:31.632714 2026] [security2:error] [pid 914912:tid 915056] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/pucci.php"] [unique_id "amuZr6469-jfU7M1CLhRvQAAAA4"]
[Thu Jul 30 13:36:32.145569 2026] [security2:error] [pid 914912:tid 915063] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xwpg.php"] [unique_id "amuZsK469-jfU7M1CLhRzwAAABU"]
[Thu Jul 30 13:36:32.145701 2026] [security2:error] [pid 914912:tid 915063] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xwpg.php"] [unique_id "amuZsK469-jfU7M1CLhRzwAAABU"]
[Thu Jul 30 13:36:32.158525 2026] [security2:error] [pid 914912:tid 915068] [client 172.236.9.101:40079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZr6469-jfU7M1CLhRwQAAABo"]
[Thu Jul 30 13:36:32.469890 2026] [security2:error] [pid 914912:tid 915062] [client 20.104.18.253:45196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/amfsqvgv.php"] [unique_id "amuZsK469-jfU7M1CLhR1gAAABQ"]
[Thu Jul 30 13:36:32.536729 2026] [security2:error] [pid 914912:tid 915011] [remote 74.7.227.39:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuZsK469-jfU7M1CLhR1wAAJ2I"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/siteseo/main
[Thu Jul 30 13:36:32.646429 2026] [security2:error] [pid 914912:tid 915154] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ops.php"] [unique_id "amuZsK469-jfU7M1CLhR3QAAAHA"]
[Thu Jul 30 13:36:32.646547 2026] [security2:error] [pid 914912:tid 915154] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ops.php"] [unique_id "amuZsK469-jfU7M1CLhR3QAAAHA"]
[Thu Jul 30 13:36:32.850093 2026] [security2:error] [pid 914912:tid 915158] [client 185.187.78.229:46335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZsK469-jfU7M1CLhR2AAAAHQ"], referer: http://pkf.jo
[Thu Jul 30 13:36:33.110189 2026] [security2:error] [pid 914912:tid 915121] [client 172.236.9.101:17836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZsK469-jfU7M1CLhR3AAAAE8"]
[Thu Jul 30 13:36:33.132948 2026] [security2:error] [pid 914912:tid 915051] [client 20.48.234.177:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/1.php"] [unique_id "amuZsa469-jfU7M1CLhR6gAAAAk"]
[Thu Jul 30 13:36:33.133078 2026] [security2:error] [pid 914912:tid 915051] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/1.php"] [unique_id "amuZsa469-jfU7M1CLhR6gAAAAk"]
[Thu Jul 30 13:36:33.133160 2026] [security2:error] [pid 914912:tid 915051] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/1.php"] [unique_id "amuZsa469-jfU7M1CLhR6gAAAAk"]
[Thu Jul 30 13:36:33.495228 2026] [security2:error] [pid 914912:tid 915103] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZsa469-jfU7M1CLhR8wAAAD0"]
[Thu Jul 30 13:36:33.616922 2026] [security2:error] [pid 914912:tid 915114] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/mac.php"] [unique_id "amuZsa469-jfU7M1CLhR9wAAAEg"]
[Thu Jul 30 13:36:33.617039 2026] [security2:error] [pid 914912:tid 915114] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/mac.php"] [unique_id "amuZsa469-jfU7M1CLhR9wAAAEg"]
[Thu Jul 30 13:36:34.002369 2026] [security2:error] [pid 914912:tid 915101] [client 20.104.18.253:25865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/ant.php"] [unique_id "amuZsq469-jfU7M1CLhSBQAAADs"]
[Thu Jul 30 13:36:34.102883 2026] [security2:error] [pid 914912:tid 915115] [client 172.236.9.101:51313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZsa469-jfU7M1CLhR9QAAAEk"]
[Thu Jul 30 13:36:34.106751 2026] [security2:error] [pid 914912:tid 915166] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZsq469-jfU7M1CLhSBgAAAHw"]
[Thu Jul 30 13:36:34.106837 2026] [security2:error] [pid 914912:tid 915166] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZsq469-jfU7M1CLhSBgAAAHw"]
[Thu Jul 30 13:36:34.613249 2026] [security2:error] [pid 914912:tid 915123] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/aa.php"] [unique_id "amuZsq469-jfU7M1CLhSEQAAAFE"]
[Thu Jul 30 13:36:34.613353 2026] [security2:error] [pid 914912:tid 915123] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/aa.php"] [unique_id "amuZsq469-jfU7M1CLhSEQAAAFE"]
[Thu Jul 30 13:36:34.796093 2026] [security2:error] [pid 914912:tid 915104] [client 52.167.144.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuZsK469-jfU7M1CLhR4AAAAD4"]
[Thu Jul 30 13:36:35.027998 2026] [security2:error] [pid 914912:tid 915144] [client 20.104.18.253:38547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/appreciators.php"] [unique_id "amuZs6469-jfU7M1CLhSIQAAAGY"]
[Thu Jul 30 13:36:35.062183 2026] [security2:error] [pid 914912:tid 915060] [client 172.236.9.101:41835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZsq469-jfU7M1CLhSEAAAABI"]
[Thu Jul 30 13:36:35.128811 2026] [security2:error] [pid 914912:tid 915072] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xyn.php"] [unique_id "amuZs6469-jfU7M1CLhSIwAAAB4"]
[Thu Jul 30 13:36:35.128926 2026] [security2:error] [pid 914912:tid 915072] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xyn.php"] [unique_id "amuZs6469-jfU7M1CLhSIwAAAB4"]
[Thu Jul 30 13:36:35.642099 2026] [security2:error] [pid 914912:tid 915103] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-wp.php"] [unique_id "amuZs6469-jfU7M1CLhSMAAAAD0"]
[Thu Jul 30 13:36:35.642214 2026] [security2:error] [pid 914912:tid 915103] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-wp.php"] [unique_id "amuZs6469-jfU7M1CLhSMAAAAD0"]
[Thu Jul 30 13:36:36.070937 2026] [security2:error] [pid 914912:tid 915066] [client 172.236.9.101:32756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZs6469-jfU7M1CLhSLwAAABg"]
[Thu Jul 30 13:36:36.152412 2026] [security2:error] [pid 914912:tid 915101] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/aw.php"] [unique_id "amuZtK469-jfU7M1CLhSPgAAADs"]
[Thu Jul 30 13:36:36.152534 2026] [security2:error] [pid 914912:tid 915101] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/aw.php"] [unique_id "amuZtK469-jfU7M1CLhSPgAAADs"]
[Thu Jul 30 13:36:36.299811 2026] [security2:error] [pid 914912:tid 915084] [client 20.104.18.253:35245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/archive.php"] [unique_id "amuZtK469-jfU7M1CLhSQgAAACo"]
[Thu Jul 30 13:36:36.581683 2026] [security2:error] [pid 914912:tid 914926] [remote 57.141.0.13:23066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/626900273/feed/rss2/"] [unique_id "amuZtK469-jfU7M1CLhSTQAAEA0"]
[Thu Jul 30 13:36:36.663487 2026] [security2:error] [pid 914912:tid 915117] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/classwithtostring.php"] [unique_id "amuZtK469-jfU7M1CLhSTgAAAEs"]
[Thu Jul 30 13:36:36.663623 2026] [security2:error] [pid 914912:tid 915117] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/classwithtostring.php"] [unique_id "amuZtK469-jfU7M1CLhSTgAAAEs"]
[Thu Jul 30 13:36:36.724409 2026] [security2:error] [pid 914912:tid 915095] [client 52.167.144.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuZtK469-jfU7M1CLhSRQAAADU"]
[Thu Jul 30 13:36:37.031212 2026] [security2:error] [pid 914912:tid 915046] [client 172.236.9.101:41348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZtK469-jfU7M1CLhSTAAAAAQ"]
[Thu Jul 30 13:36:37.176465 2026] [security2:error] [pid 914912:tid 915126] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/yawa.php"] [unique_id "amuZta469-jfU7M1CLhSWwAAAFQ"]
[Thu Jul 30 13:36:37.176592 2026] [security2:error] [pid 914912:tid 915126] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/yawa.php"] [unique_id "amuZta469-jfU7M1CLhSWwAAAFQ"]
[Thu Jul 30 13:36:37.267823 2026] [autoindex:error] [pid 914912:tid 915145] [client 20.193.250.173:62575] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_26b933cb/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 13:36:37.694138 2026] [security2:error] [pid 914912:tid 915136] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sym403.php"] [unique_id "amuZta469-jfU7M1CLhSagAAAF4"]
[Thu Jul 30 13:36:37.694296 2026] [security2:error] [pid 914912:tid 915136] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sym403.php"] [unique_id "amuZta469-jfU7M1CLhSagAAAF4"]
[Thu Jul 30 13:36:37.776485 2026] [security2:error] [pid 914912:tid 915088] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZta469-jfU7M1CLhSaQAAAC4"]
[Thu Jul 30 13:36:37.909477 2026] [security2:error] [pid 914912:tid 915125] [client 20.104.18.253:38901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/as.php"] [unique_id "amuZta469-jfU7M1CLhSbgAAAFM"]
[Thu Jul 30 13:36:37.968704 2026] [security2:error] [pid 914912:tid 915158] [client 172.236.9.101:41131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZta469-jfU7M1CLhSYwAAAHQ"]
[Thu Jul 30 13:36:38.212175 2026] [security2:error] [pid 914912:tid 915090] [client 20.48.234.177:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amuZtq469-jfU7M1CLhSdgAAADA"]
[Thu Jul 30 13:36:38.212317 2026] [security2:error] [pid 914912:tid 915090] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amuZtq469-jfU7M1CLhSdgAAADA"]
[Thu Jul 30 13:36:38.669682 2026] [security2:error] [pid 914912:tid 915168] [client 20.104.18.253:35261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/atomlib.php"] [unique_id "amuZtq469-jfU7M1CLhSggAAAH4"]
[Thu Jul 30 13:36:38.737328 2026] [security2:error] [pid 914912:tid 915120] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/adminner.php"] [unique_id "amuZtq469-jfU7M1CLhShAAAAE4"]
[Thu Jul 30 13:36:38.737449 2026] [security2:error] [pid 914912:tid 915120] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/adminner.php"] [unique_id "amuZtq469-jfU7M1CLhShAAAAE4"]
[Thu Jul 30 13:36:38.892862 2026] [core:notice] [pid 914912:tid 915084] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:38.927272 2026] [security2:error] [pid 914912:tid 915056] [client 172.236.9.101:58292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZtq469-jfU7M1CLhSfQAAAA4"]
[Thu Jul 30 13:36:39.089259 2026] [core:error] [pid 914912:tid 914958] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/
[Thu Jul 30 13:36:39.089286 2026] [core:error] [pid 914912:tid 914958] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/
[Thu Jul 30 13:36:39.248192 2026] [security2:error] [pid 914912:tid 915123] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/yup.php"] [unique_id "amuZt6469-jfU7M1CLhSkwAAAFE"]
[Thu Jul 30 13:36:39.248304 2026] [security2:error] [pid 914912:tid 915123] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/yup.php"] [unique_id "amuZt6469-jfU7M1CLhSkwAAAFE"]
[Thu Jul 30 13:36:39.377730 2026] [security2:error] [pid 914912:tid 915162] [client 78.167.1.90:56416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZt6469-jfU7M1CLhSlAAAAHg"]
[Thu Jul 30 13:36:39.377944 2026] [security2:error] [pid 914912:tid 915162] [client 78.167.1.90:56416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZt6469-jfU7M1CLhSlAAAAHg"]
[Thu Jul 30 13:36:39.395588 2026] [security2:error] [pid 914912:tid 915137] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZtq469-jfU7M1CLhSgQAAXx8"]
[Thu Jul 30 13:36:39.552294 2026] [security2:error] [pid 914912:tid 915081] [client 20.104.18.253:39422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/autoload_classmap.php"] [unique_id "amuZt6469-jfU7M1CLhSnQAAACc"]
[Thu Jul 30 13:36:39.583266 2026] [security2:error] [pid 914912:tid 915007] [remote 37.59.204.137:39864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/business-page/"] [unique_id "amuZt6469-jfU7M1CLhSngAAXF4"]
[Thu Jul 30 13:36:39.583464 2026] [security2:error] [pid 914912:tid 915134] [client 37.59.204.137:39864] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/business-page/"] [unique_id "amuZt6469-jfU7M1CLhSngAAXF4"]
[Thu Jul 30 13:36:39.619380 2026] [core:error] [pid 914912:tid 915016] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/
[Thu Jul 30 13:36:39.619405 2026] [core:error] [pid 914912:tid 915016] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/
[Thu Jul 30 13:36:39.737087 2026] [security2:error] [pid 914912:tid 915148] [client 71.232.136.42:46450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZt6469-jfU7M1CLhSmAAAAGo"], referer: http://pkf.jo
[Thu Jul 30 13:36:39.757473 2026] [security2:error] [pid 914912:tid 915121] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/config.json.php"] [unique_id "amuZt6469-jfU7M1CLhSpgAAAE8"]
[Thu Jul 30 13:36:39.757575 2026] [security2:error] [pid 914912:tid 915121] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/config.json.php"] [unique_id "amuZt6469-jfU7M1CLhSpgAAAE8"]
[Thu Jul 30 13:36:39.894233 2026] [security2:error] [pid 914912:tid 915094] [client 172.236.9.101:13943] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZt6469-jfU7M1CLhSlQAAADQ"]
[Thu Jul 30 13:36:40.262534 2026] [security2:error] [pid 914912:tid 915157] [client 20.104.18.253:28504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/bb.php"] [unique_id "amuZuK469-jfU7M1CLhSsAAAAHM"]
[Thu Jul 30 13:36:40.268618 2026] [security2:error] [pid 914912:tid 915153] [client 20.48.234.177:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/block-bindings/"] [unique_id "amuZuK469-jfU7M1CLhSsQAAAG8"]
[Thu Jul 30 13:36:40.268709 2026] [security2:error] [pid 914912:tid 915153] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/block-bindings/"] [unique_id "amuZuK469-jfU7M1CLhSsQAAAG8"]
[Thu Jul 30 13:36:40.764401 2026] [security2:error] [pid 914912:tid 915042] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/2.php"] [unique_id "amuZuK469-jfU7M1CLhSvQAAAAA"]
[Thu Jul 30 13:36:40.764526 2026] [security2:error] [pid 914912:tid 915042] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/2.php"] [unique_id "amuZuK469-jfU7M1CLhSvQAAAAA"]
[Thu Jul 30 13:36:40.849530 2026] [security2:error] [pid 914912:tid 915110] [client 172.236.9.101:39980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZuK469-jfU7M1CLhSsgAAAEQ"]
[Thu Jul 30 13:36:41.259953 2026] [security2:error] [pid 914912:tid 915108] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/f35.update.php"] [unique_id "amuZua469-jfU7M1CLhSyAAAAEI"]
[Thu Jul 30 13:36:41.260075 2026] [security2:error] [pid 914912:tid 915108] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/f35.update.php"] [unique_id "amuZua469-jfU7M1CLhSyAAAAEI"]
[Thu Jul 30 13:36:41.305687 2026] [security2:error] [pid 914912:tid 915085] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZuK469-jfU7M1CLhSvAAAKzg"]
[Thu Jul 30 13:36:41.345673 2026] [security2:error] [pid 914912:tid 915084] [client 20.104.18.253:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/bnm.php"] [unique_id "amuZua469-jfU7M1CLhSygAAACo"]
[Thu Jul 30 13:36:41.744175 2026] [security2:error] [pid 914912:tid 915140] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/k.php"] [unique_id "amuZua469-jfU7M1CLhS1gAAAGI"]
[Thu Jul 30 13:36:41.744293 2026] [security2:error] [pid 914912:tid 915140] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/k.php"] [unique_id "amuZua469-jfU7M1CLhS1gAAAGI"]
[Thu Jul 30 13:36:41.826159 2026] [security2:error] [pid 914912:tid 915162] [client 172.236.9.101:9857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZua469-jfU7M1CLhSyQAAAHg"]
[Thu Jul 30 13:36:41.957728 2026] [security2:error] [pid 914912:tid 915059] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZua469-jfU7M1CLhS2QAAABE"]
[Thu Jul 30 13:36:42.251969 2026] [security2:error] [pid 914912:tid 915158] [client 20.48.234.177:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/css/"] [unique_id "amuZuq469-jfU7M1CLhS5QAAAHQ"]
[Thu Jul 30 13:36:42.252075 2026] [security2:error] [pid 914912:tid 915158] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/css/"] [unique_id "amuZuq469-jfU7M1CLhS5QAAAHQ"]
[Thu Jul 30 13:36:42.332960 2026] [security2:error] [pid 914912:tid 915055] [client 185.24.60.181:54353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZuq469-jfU7M1CLhS2gAAAA0"], referer: http://pkf.jo
[Thu Jul 30 13:36:42.445293 2026] [security2:error] [pid 914912:tid 915053] [client 180.74.66.70:25903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZuq469-jfU7M1CLhS3gAAAAs"], referer: http://pkf.jo
[Thu Jul 30 13:36:42.742575 2026] [security2:error] [pid 914912:tid 915121] [client 20.104.18.253:43267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/bootstrap.php"] [unique_id "amuZuq469-jfU7M1CLhS8gAAAE8"]
[Thu Jul 30 13:36:42.786259 2026] [security2:error] [pid 914912:tid 915074] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/spadex.php"] [unique_id "amuZuq469-jfU7M1CLhS9AAAACA"]
[Thu Jul 30 13:36:42.786360 2026] [security2:error] [pid 914912:tid 915074] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/spadex.php"] [unique_id "amuZuq469-jfU7M1CLhS9AAAACA"]
[Thu Jul 30 13:36:42.816044 2026] [security2:error] [pid 914912:tid 915125] [client 172.236.9.101:45992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZuq469-jfU7M1CLhS5wAAAFM"]
[Thu Jul 30 13:36:43.287740 2026] [security2:error] [pid 914912:tid 915165] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuZuq469-jfU7M1CLhS-QAAAHs"]
[Thu Jul 30 13:36:43.291521 2026] [security2:error] [pid 914912:tid 915045] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/mg.php"] [unique_id "amuZu6469-jfU7M1CLhTAwAAAAM"]
[Thu Jul 30 13:36:43.291595 2026] [security2:error] [pid 914912:tid 915045] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/mg.php"] [unique_id "amuZu6469-jfU7M1CLhTAwAAAAM"]
[Thu Jul 30 13:36:43.679488 2026] [security2:error] [pid 914912:tid 915047] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZu6469-jfU7M1CLhS-gAABUM"]
[Thu Jul 30 13:36:43.681604 2026] [security2:error] [pid 914912:tid 915164] [client 20.104.18.253:38873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/buy.php"] [unique_id "amuZu6469-jfU7M1CLhTCgAAAHo"]
[Thu Jul 30 13:36:43.772297 2026] [security2:error] [pid 914912:tid 915139] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fnstall.php"] [unique_id "amuZu6469-jfU7M1CLhTEAAAAGE"]
[Thu Jul 30 13:36:43.772382 2026] [security2:error] [pid 914912:tid 915139] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fnstall.php"] [unique_id "amuZu6469-jfU7M1CLhTEAAAAGE"]
[Thu Jul 30 13:36:43.840723 2026] [security2:error] [pid 914912:tid 915141] [client 172.236.9.101:3901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZu6469-jfU7M1CLhTBgAAAGM"]
[Thu Jul 30 13:36:44.116554 2026] [security2:error] [pid 914912:tid 915140] [client 156.201.42.226:39396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZu6469-jfU7M1CLhTFgAAAGI"], referer: http://pkf.jo
[Thu Jul 30 13:36:44.299089 2026] [security2:error] [pid 914912:tid 915061] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ortasekerli1.php"] [unique_id "amuZvK469-jfU7M1CLhTHQAAABM"]
[Thu Jul 30 13:36:44.299196 2026] [security2:error] [pid 914912:tid 915061] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ortasekerli1.php"] [unique_id "amuZvK469-jfU7M1CLhTHQAAABM"]
[Thu Jul 30 13:36:44.451363 2026] [security2:error] [pid 914912:tid 915128] [client 20.104.18.253:38532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/chosen.php"] [unique_id "amuZvK469-jfU7M1CLhTIgAAAFY"]
[Thu Jul 30 13:36:44.808560 2026] [security2:error] [pid 914912:tid 915053] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sump1.php"] [unique_id "amuZvK469-jfU7M1CLhTJgAAAAs"]
[Thu Jul 30 13:36:44.808665 2026] [security2:error] [pid 914912:tid 915053] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sump1.php"] [unique_id "amuZvK469-jfU7M1CLhTJgAAAAs"]
[Thu Jul 30 13:36:44.864331 2026] [security2:error] [pid 914912:tid 915089] [client 172.236.9.101:59606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZvK469-jfU7M1CLhTIQAAAC8"]
[Thu Jul 30 13:36:45.288561 2026] [security2:error] [pid 914912:tid 915105] [client 20.104.18.253:48849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/class-wp-image.php"] [unique_id "amuZva469-jfU7M1CLhTNwAAAD8"]
[Thu Jul 30 13:36:45.322700 2026] [security2:error] [pid 914912:tid 915075] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ops.php"] [unique_id "amuZva469-jfU7M1CLhTPAAAACE"]
[Thu Jul 30 13:36:45.322785 2026] [security2:error] [pid 914912:tid 915075] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ops.php"] [unique_id "amuZva469-jfU7M1CLhTPAAAACE"]
[Thu Jul 30 13:36:45.809828 2026] [security2:error] [pid 914912:tid 915086] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-post-data.php"] [unique_id "amuZva469-jfU7M1CLhTRAAAACw"]
[Thu Jul 30 13:36:45.809958 2026] [security2:error] [pid 914912:tid 915086] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-post-data.php"] [unique_id "amuZva469-jfU7M1CLhTRAAAACw"]
[Thu Jul 30 13:36:45.897818 2026] [security2:error] [pid 914912:tid 915110] [client 172.236.9.101:6886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZva469-jfU7M1CLhTPwAAAEQ"]
[Thu Jul 30 13:36:46.280695 2026] [security2:error] [pid 914912:tid 915054] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/root.php"] [unique_id "amuZvq469-jfU7M1CLhTVAAAAAw"]
[Thu Jul 30 13:36:46.280807 2026] [security2:error] [pid 914912:tid 915054] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/root.php"] [unique_id "amuZvq469-jfU7M1CLhTVAAAAAw"]
[Thu Jul 30 13:36:46.706358 2026] [security2:error] [pid 914912:tid 915151] [client 20.104.18.253:46865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/classsmtps.php"] [unique_id "amuZvq469-jfU7M1CLhTYAAAAG0"]
[Thu Jul 30 13:36:46.778730 2026] [security2:error] [pid 914912:tid 915116] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/v543.php"] [unique_id "amuZvq469-jfU7M1CLhTYQAAAEo"]
[Thu Jul 30 13:36:46.778855 2026] [security2:error] [pid 914912:tid 915116] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/v543.php"] [unique_id "amuZvq469-jfU7M1CLhTYQAAAEo"]
[Thu Jul 30 13:36:46.913237 2026] [security2:error] [pid 914912:tid 915106] [client 172.236.9.101:25917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZvq469-jfU7M1CLhTXAAAAEA"]
[Thu Jul 30 13:36:47.277703 2026] [security2:error] [pid 914912:tid 915143] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sixxis.php"] [unique_id "amuZv6469-jfU7M1CLhTawAAAGU"]
[Thu Jul 30 13:36:47.277851 2026] [security2:error] [pid 914912:tid 915143] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sixxis.php"] [unique_id "amuZv6469-jfU7M1CLhTawAAAGU"]
[Thu Jul 30 13:36:47.782930 2026] [security2:error] [pid 914912:tid 915043] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ip.php"] [unique_id "amuZv6469-jfU7M1CLhTeAAAAAE"]
[Thu Jul 30 13:36:47.783046 2026] [security2:error] [pid 914912:tid 915043] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ip.php"] [unique_id "amuZv6469-jfU7M1CLhTeAAAAAE"]
[Thu Jul 30 13:36:47.788033 2026] [security2:error] [pid 914912:tid 915156] [client 93.152.224.221:62095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.224.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/index.php"] [unique_id "amuZv6469-jfU7M1CLhTeQAAAHI"]
[Thu Jul 30 13:36:47.881788 2026] [security2:error] [pid 914912:tid 915160] [client 172.236.9.101:41542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZv6469-jfU7M1CLhTbQAAAHY"]
[Thu Jul 30 13:36:48.266070 2026] [security2:error] [pid 914912:tid 915129] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/kq1.php"] [unique_id "amuZwK469-jfU7M1CLhTiAAAAFc"]
[Thu Jul 30 13:36:48.266179 2026] [security2:error] [pid 914912:tid 915129] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/kq1.php"] [unique_id "amuZwK469-jfU7M1CLhTiAAAAFc"]
[Thu Jul 30 13:36:48.497118 2026] [security2:error] [pid 914912:tid 915117] [client 20.104.18.253:46867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/classwithtostring.php"] [unique_id "amuZwK469-jfU7M1CLhTkgAAAEs"]
[Thu Jul 30 13:36:48.752664 2026] [security2:error] [pid 914912:tid 915151] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fw/faiyy.php"] [unique_id "amuZwK469-jfU7M1CLhTmAAAAG0"]
[Thu Jul 30 13:36:48.752770 2026] [security2:error] [pid 914912:tid 915151] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fw/faiyy.php"] [unique_id "amuZwK469-jfU7M1CLhTmAAAAG0"]
[Thu Jul 30 13:36:49.122926 2026] [security2:error] [pid 914912:tid 915135] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZwK469-jfU7M1CLhToAAAAF0"]
[Thu Jul 30 13:36:49.265969 2026] [security2:error] [pid 914912:tid 915066] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/h02ugyh.php"] [unique_id "amuZwa469-jfU7M1CLhTrQAAABg"]
[Thu Jul 30 13:36:49.266077 2026] [security2:error] [pid 914912:tid 915066] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/h02ugyh.php"] [unique_id "amuZwa469-jfU7M1CLhTrQAAABg"]
[Thu Jul 30 13:36:49.314771 2026] [security2:error] [pid 914912:tid 915082] [client 20.104.18.253:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/config.php"] [unique_id "amuZwa469-jfU7M1CLhTrgAAACg"]
[Thu Jul 30 13:36:49.766793 2026] [security2:error] [pid 914912:tid 915123] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-temp.php"] [unique_id "amuZwa469-jfU7M1CLhTuwAAAFE"]
[Thu Jul 30 13:36:49.766906 2026] [security2:error] [pid 914912:tid 915123] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-temp.php"] [unique_id "amuZwa469-jfU7M1CLhTuwAAAFE"]
[Thu Jul 30 13:36:50.181251 2026] [security2:error] [pid 914912:tid 915160] [client 20.104.18.253:35224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/core.php"] [unique_id "amuZwq469-jfU7M1CLhTyAAAAHY"]
[Thu Jul 30 13:36:50.292921 2026] [security2:error] [pid 914912:tid 915133] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/cong.php"] [unique_id "amuZwq469-jfU7M1CLhTygAAAFs"]
[Thu Jul 30 13:36:50.293046 2026] [security2:error] [pid 914912:tid 915133] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/cong.php"] [unique_id "amuZwq469-jfU7M1CLhTygAAAFs"]
[Thu Jul 30 13:36:50.588847 2026] [security2:error] [pid 914912:tid 915046] [client 176.97.63.65:41040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZwq469-jfU7M1CLhTyQAAAAQ"], referer: http://pkf.jo
[Thu Jul 30 13:36:50.819155 2026] [security2:error] [pid 914912:tid 915148] [client 20.48.234.177:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/js/widget/"] [unique_id "amuZwq469-jfU7M1CLhT2AAAAGo"]
[Thu Jul 30 13:36:50.819309 2026] [security2:error] [pid 914912:tid 915148] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/js/widget/"] [unique_id "amuZwq469-jfU7M1CLhT2AAAAGo"]
[Thu Jul 30 13:36:51.020561 2026] [security2:error] [pid 914912:tid 915071] [client 78.167.1.90:54354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZw6469-jfU7M1CLhT4gAAAB0"]
[Thu Jul 30 13:36:51.020959 2026] [security2:error] [pid 914912:tid 915071] [client 78.167.1.90:54354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZw6469-jfU7M1CLhT4gAAAB0"]
[Thu Jul 30 13:36:51.118654 2026] [security2:error] [pid 914912:tid 915145] [client 74.7.228.35:40944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dl.meshmixers.com.kev.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuZw6469-jfU7M1CLhT6QAAZwo"]
[Thu Jul 30 13:36:51.139594 2026] [security2:error] [pid 914912:tid 915116] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZwq469-jfU7M1CLhT4QAAAEo"]
[Thu Jul 30 13:36:51.329449 2026] [security2:error] [pid 914912:tid 915070] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/css/index.php"] [unique_id "amuZw6469-jfU7M1CLhT7AAAABw"]
[Thu Jul 30 13:36:51.329588 2026] [security2:error] [pid 914912:tid 915070] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/css/index.php"] [unique_id "amuZw6469-jfU7M1CLhT7AAAABw"]
[Thu Jul 30 13:36:51.440423 2026] [security2:error] [pid 914912:tid 915143] [client 20.104.18.253:50975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/css.php"] [unique_id "amuZw6469-jfU7M1CLhT7QAAAGU"]
[Thu Jul 30 13:36:51.624155 2026] [security2:error] [pid 914912:tid 915079] [client 178.251.106.151:49546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZw6469-jfU7M1CLhT6wAAACU"], referer: http://pkf.jo
[Thu Jul 30 13:36:51.886770 2026] [security2:error] [pid 914912:tid 915161] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/jj.php"] [unique_id "amuZw6469-jfU7M1CLhT_QAAAHc"]
[Thu Jul 30 13:36:51.886860 2026] [security2:error] [pid 914912:tid 915161] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/jj.php"] [unique_id "amuZw6469-jfU7M1CLhT_QAAAHc"]
[Thu Jul 30 13:36:51.888918 2026] [security2:error] [pid 914912:tid 914928] [remote 57.141.0.51:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6151894337/feed/rss2/"] [unique_id "amuZw6469-jfU7M1CLhT_AAAPw8"]
[Thu Jul 30 13:36:51.889081 2026] [security2:error] [pid 914912:tid 915073] [client 207.46.13.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuZwq469-jfU7M1CLhT2wAAAB8"]
[Thu Jul 30 13:36:52.396512 2026] [security2:error] [pid 914912:tid 915085] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/class-walker-footer-dev.php"] [unique_id "amuZxK469-jfU7M1CLhUDwAAACs"]
[Thu Jul 30 13:36:52.396656 2026] [security2:error] [pid 914912:tid 915085] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/class-walker-footer-dev.php"] [unique_id "amuZxK469-jfU7M1CLhUDwAAACs"]
[Thu Jul 30 13:36:52.592446 2026] [security2:error] [pid 914912:tid 915126] [client 20.104.18.253:38898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/database.php"] [unique_id "amuZxK469-jfU7M1CLhUGQAAAFQ"]
[Thu Jul 30 13:36:52.651901 2026] [security2:error] [pid 914912:tid 915048] [client 74.7.241.175:53106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.xexrecords.online.kii.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuZxK469-jfU7M1CLhUGwAABhA"]
[Thu Jul 30 13:36:52.907914 2026] [security2:error] [pid 914912:tid 915130] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xpwer1.php"] [unique_id "amuZxK469-jfU7M1CLhUIwAAAFg"]
[Thu Jul 30 13:36:52.908032 2026] [security2:error] [pid 914912:tid 915130] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xpwer1.php"] [unique_id "amuZxK469-jfU7M1CLhUIwAAAFg"]
[Thu Jul 30 13:36:53.014076 2026] [security2:error] [pid 914912:tid 915119] [client 161.10.187.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZxK469-jfU7M1CLhUIgAAAE0"]
[Thu Jul 30 13:36:53.231004 2026] [security2:error] [pid 914912:tid 915099] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZxa469-jfU7M1CLhUKQAAADk"]
[Thu Jul 30 13:36:53.240092 2026] [proxy:error] [pid 914912:tid 915125] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:53.240189 2026] [proxy_http:error] [pid 914912:tid 915125] [client 32.194.121.99:56213] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:53.241079 2026] [proxy:error] [pid 914912:tid 915125] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:53.241144 2026] [proxy_http:error] [pid 914912:tid 915125] [client 32.194.121.99:56213] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:53.273893 2026] [proxy:error] [pid 914912:tid 915167] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:53.274001 2026] [proxy_http:error] [pid 914912:tid 915167] [client 34.224.175.62:14889] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:53.274855 2026] [proxy:error] [pid 914912:tid 915167] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:36:53.274915 2026] [proxy_http:error] [pid 914912:tid 915167] [client 34.224.175.62:14889] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:36:53.359865 2026] [security2:error] [pid 914912:tid 915143] [client 20.104.18.253:38954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/db.php"] [unique_id "amuZxa469-jfU7M1CLhUOAAAAGU"]
[Thu Jul 30 13:36:53.422199 2026] [security2:error] [pid 914912:tid 915095] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/flox.php"] [unique_id "amuZxa469-jfU7M1CLhUOgAAADU"]
[Thu Jul 30 13:36:53.422316 2026] [security2:error] [pid 914912:tid 915095] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/flox.php"] [unique_id "amuZxa469-jfU7M1CLhUOgAAADU"]
[Thu Jul 30 13:36:53.443492 2026] [autoindex:error] [pid 914912:tid 914954] [remote 74.7.241.28:56386] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:36:53.908628 2026] [security2:error] [pid 914912:tid 915133] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/popo.php"] [unique_id "amuZxa469-jfU7M1CLhUTQAAAFs"]
[Thu Jul 30 13:36:53.908749 2026] [security2:error] [pid 914912:tid 915133] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/popo.php"] [unique_id "amuZxa469-jfU7M1CLhUTQAAAFs"]
[Thu Jul 30 13:36:54.050733 2026] [security2:error] [pid 914912:tid 915110] [client 20.104.18.253:38867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/default.php"] [unique_id "amuZxq469-jfU7M1CLhUVQAAAEQ"]
[Thu Jul 30 13:36:54.261779 2026] [security2:error] [pid 914912:tid 915092] [client 181.237.65.245:42160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZxa469-jfU7M1CLhUTgAAADI"], referer: http://pkf.jo
[Thu Jul 30 13:36:54.287764 2026] [security2:error] [pid 914912:tid 915162] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZxa469-jfU7M1CLhUQAAAeB4"]
[Thu Jul 30 13:36:54.410576 2026] [security2:error] [pid 914912:tid 915158] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/yas.php"] [unique_id "amuZxq469-jfU7M1CLhUXwAAAHQ"]
[Thu Jul 30 13:36:54.410690 2026] [security2:error] [pid 914912:tid 915158] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/yas.php"] [unique_id "amuZxq469-jfU7M1CLhUXwAAAHQ"]
[Thu Jul 30 13:36:54.892522 2026] [security2:error] [pid 914912:tid 915151] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZxq469-jfU7M1CLhUaAAAAG0"]
[Thu Jul 30 13:36:54.928463 2026] [security2:error] [pid 914912:tid 915146] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/water.php"] [unique_id "amuZxq469-jfU7M1CLhUcAAAAGg"]
[Thu Jul 30 13:36:54.928615 2026] [security2:error] [pid 914912:tid 915146] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/water.php"] [unique_id "amuZxq469-jfU7M1CLhUcAAAAGg"]
[Thu Jul 30 13:36:55.064079 2026] [security2:error] [pid 914912:tid 915147] [client 78.190.176.250:24430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZxq469-jfU7M1CLhUagAAAGk"], referer: http://pkf.jo
[Thu Jul 30 13:36:55.140033 2026] [security2:error] [pid 914912:tid 915093] [client 20.104.18.253:43309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/dropdown.php"] [unique_id "amuZx6469-jfU7M1CLhUdwAAADM"]
[Thu Jul 30 13:36:55.431619 2026] [security2:error] [pid 914912:tid 915052] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/nano.php"] [unique_id "amuZx6469-jfU7M1CLhUgAAAAAo"]
[Thu Jul 30 13:36:55.431750 2026] [security2:error] [pid 914912:tid 915052] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/nano.php"] [unique_id "amuZx6469-jfU7M1CLhUgAAAAAo"]
[Thu Jul 30 13:36:55.600112 2026] [core:notice] [pid 914912:tid 915142] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:55.947397 2026] [security2:error] [pid 914912:tid 915060] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/moon.php"] [unique_id "amuZx6469-jfU7M1CLhUiwAAABI"]
[Thu Jul 30 13:36:55.947497 2026] [security2:error] [pid 914912:tid 915060] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/moon.php"] [unique_id "amuZx6469-jfU7M1CLhUiwAAABI"]
[Thu Jul 30 13:36:56.326228 2026] [security2:error] [pid 914912:tid 915134] [client 20.104.18.253:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/edit.php"] [unique_id "amuZyK469-jfU7M1CLhUjwAAAFw"]
[Thu Jul 30 13:36:56.362203 2026] [core:notice] [pid 914912:tid 915092] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:36:56.467198 2026] [security2:error] [pid 914912:tid 915114] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-info.php"] [unique_id "amuZyK469-jfU7M1CLhUnQAAAEg"]
[Thu Jul 30 13:36:56.467293 2026] [security2:error] [pid 914912:tid 915114] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-info.php"] [unique_id "amuZyK469-jfU7M1CLhUnQAAAEg"]
[Thu Jul 30 13:36:56.696707 2026] [security2:error] [pid 914912:tid 915058] [client 20.226.90.242:9877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuZyK469-jfU7M1CLhUoQAAABA"]
[Thu Jul 30 13:36:56.696808 2026] [security2:error] [pid 914912:tid 915058] [client 20.226.90.242:9877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuZyK469-jfU7M1CLhUoQAAABA"]
[Thu Jul 30 13:36:56.858797 2026] [security2:error] [pid 914912:tid 914974] [remote 57.141.0.40:36250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/96299823080/feed/rss2/"] [unique_id "amuZyK469-jfU7M1CLhUpQAACT0"]
[Thu Jul 30 13:36:57.004147 2026] [security2:error] [pid 914912:tid 915131] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/file5.php"] [unique_id "amuZya469-jfU7M1CLhUqgAAAFk"]
[Thu Jul 30 13:36:57.004257 2026] [security2:error] [pid 914912:tid 915131] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/file5.php"] [unique_id "amuZya469-jfU7M1CLhUqgAAAFk"]
[Thu Jul 30 13:36:57.118261 2026] [security2:error] [pid 914912:tid 915098] [client 20.104.18.253:40650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/f35.php"] [unique_id "amuZya469-jfU7M1CLhUrwAAADg"]
[Thu Jul 30 13:36:57.270445 2026] [security2:error] [pid 914912:tid 915161] [client 177.74.230.120:32322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuZyK469-jfU7M1CLhUqQAAAHc"], referer: http://pkf.jo
[Thu Jul 30 13:36:57.490854 2026] [security2:error] [pid 914912:tid 914980] [remote 74.7.243.224:38388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/article.php"] [unique_id "amuZya469-jfU7M1CLhUtwAAA0M"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:36:57.503553 2026] [security2:error] [pid 914912:tid 915166] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/2000.php"] [unique_id "amuZya469-jfU7M1CLhUuAAAAHw"]
[Thu Jul 30 13:36:57.503632 2026] [security2:error] [pid 914912:tid 915166] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/2000.php"] [unique_id "amuZya469-jfU7M1CLhUuAAAAHw"]
[Thu Jul 30 13:36:57.866272 2026] [autoindex:error] [pid 914912:tid 915134] [client 217.160.202.182:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:36:58.004611 2026] [security2:error] [pid 914912:tid 915114] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/122.php"] [unique_id "amuZyq469-jfU7M1CLhUyAAAAEg"]
[Thu Jul 30 13:36:58.004710 2026] [security2:error] [pid 914912:tid 915114] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/122.php"] [unique_id "amuZyq469-jfU7M1CLhUyAAAAEg"]
[Thu Jul 30 13:36:58.185917 2026] [security2:error] [pid 914912:tid 915162] [client 119.73.97.132:30213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuZya469-jfU7M1CLhUwAAAeDw"]
[Thu Jul 30 13:36:58.248618 2026] [security2:error] [pid 914912:tid 915162] [client 119.73.97.132:30213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuZya469-jfU7M1CLhUxAAAeEI"]
[Thu Jul 30 13:36:58.314635 2026] [security2:error] [pid 914912:tid 915089] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZyq469-jfU7M1CLhUzwAAAC8"]
[Thu Jul 30 13:36:58.497527 2026] [security2:error] [pid 914912:tid 915151] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/mds.php"] [unique_id "amuZyq469-jfU7M1CLhU1AAAAG0"]
[Thu Jul 30 13:36:58.497643 2026] [security2:error] [pid 914912:tid 915151] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/mds.php"] [unique_id "amuZyq469-jfU7M1CLhU1AAAAG0"]
[Thu Jul 30 13:36:59.001431 2026] [security2:error] [pid 914912:tid 915131] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/zc-208.php"] [unique_id "amuZy6469-jfU7M1CLhU5gAAAFk"]
[Thu Jul 30 13:36:59.001570 2026] [security2:error] [pid 914912:tid 915131] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/zc-208.php"] [unique_id "amuZy6469-jfU7M1CLhU5gAAAFk"]
[Thu Jul 30 13:36:59.236897 2026] [security2:error] [pid 914912:tid 915121] [client 20.226.90.242:9890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuZy6469-jfU7M1CLhU6gAAAE8"]
[Thu Jul 30 13:36:59.237012 2026] [security2:error] [pid 914912:tid 915121] [client 20.226.90.242:9890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuZy6469-jfU7M1CLhU6gAAAE8"]
[Thu Jul 30 13:36:59.494748 2026] [security2:error] [pid 914912:tid 915107] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sid4.php"] [unique_id "amuZy6469-jfU7M1CLhU8QAAAEE"]
[Thu Jul 30 13:36:59.494847 2026] [security2:error] [pid 914912:tid 915107] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sid4.php"] [unique_id "amuZy6469-jfU7M1CLhU8QAAAEE"]
[Thu Jul 30 13:36:59.867823 2026] [security2:error] [pid 914912:tid 915047] [client 20.104.18.253:32400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/f7.php"] [unique_id "amuZy6469-jfU7M1CLhU_QAAAAU"]
[Thu Jul 30 13:37:00.014361 2026] [security2:error] [pid 914912:tid 915122] [client 20.48.234.177:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/l10n/"] [unique_id "amuZzK469-jfU7M1CLhU_gAAAFA"]
[Thu Jul 30 13:37:00.014463 2026] [security2:error] [pid 914912:tid 915122] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/l10n/"] [unique_id "amuZzK469-jfU7M1CLhU_gAAAFA"]
[Thu Jul 30 13:37:00.223730 2026] [security2:error] [pid 914912:tid 915091] [client 93.152.224.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuZzK469-jfU7M1CLhVBwAAADE"]
[Thu Jul 30 13:37:00.429073 2026] [security2:error] [pid 914912:tid 915148] [client 57.141.0.38:50394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuZzK469-jfU7M1CLhVAgAAal8"], referer: https://igetvape-australia.com/product/iget-bar-pro-blackberry-pomegranate-cherry/?add-to-cart=98
[Thu Jul 30 13:37:00.556501 2026] [security2:error] [pid 914912:tid 915152] [client 78.167.1.90:57110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZzK469-jfU7M1CLhVEAAAAG4"]
[Thu Jul 30 13:37:00.556625 2026] [security2:error] [pid 914912:tid 915152] [client 78.167.1.90:57110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZzK469-jfU7M1CLhVEAAAAG4"]
[Thu Jul 30 13:37:00.559908 2026] [security2:error] [pid 914912:tid 915100] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wmore1.php"] [unique_id "amuZzK469-jfU7M1CLhVEQAAADo"]
[Thu Jul 30 13:37:00.560008 2026] [security2:error] [pid 914912:tid 915100] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wmore1.php"] [unique_id "amuZzK469-jfU7M1CLhVEQAAADo"]
[Thu Jul 30 13:37:01.069838 2026] [security2:error] [pid 914912:tid 915083] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/solo1.php"] [unique_id "amuZza469-jfU7M1CLhVIAAAACk"]
[Thu Jul 30 13:37:01.069989 2026] [security2:error] [pid 914912:tid 915083] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/solo1.php"] [unique_id "amuZza469-jfU7M1CLhVIAAAACk"]
[Thu Jul 30 13:37:01.331532 2026] [security2:error] [pid 914912:tid 915156] [client 68.67.112.51:6305] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuZza469-jfU7M1CLhVJQAAAHI"]
[Thu Jul 30 13:37:01.548526 2026] [security2:error] [pid 914912:tid 915042] [client 20.48.234.177:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/assets/"] [unique_id "amuZza469-jfU7M1CLhVKQAAAAA"]
[Thu Jul 30 13:37:01.548634 2026] [security2:error] [pid 914912:tid 915042] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/assets/"] [unique_id "amuZza469-jfU7M1CLhVKQAAAAA"]
[Thu Jul 30 13:37:01.614759 2026] [security2:error] [pid 914912:tid 915143] [client 119.73.97.132:30213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuZza469-jfU7M1CLhVKAAAZW0"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 13:37:02.079831 2026] [security2:error] [pid 914912:tid 915064] [client 20.48.234.177:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/css/"] [unique_id "amuZzq469-jfU7M1CLhVQgAAABY"]
[Thu Jul 30 13:37:02.079968 2026] [security2:error] [pid 914912:tid 915064] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/css/"] [unique_id "amuZzq469-jfU7M1CLhVQgAAABY"]
[Thu Jul 30 13:37:02.136461 2026] [security2:error] [pid 914912:tid 915054] [client 20.226.90.242:40654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/inputs.php"] [unique_id "amuZzq469-jfU7M1CLhVQwAAAAw"]
[Thu Jul 30 13:37:02.136583 2026] [security2:error] [pid 914912:tid 915054] [client 20.226.90.242:40654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/inputs.php"] [unique_id "amuZzq469-jfU7M1CLhVQwAAAAw"]
[Thu Jul 30 13:37:02.607071 2026] [security2:error] [pid 914912:tid 915081] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/public/css.php"] [unique_id "amuZzq469-jfU7M1CLhVUwAAACc"]
[Thu Jul 30 13:37:02.607194 2026] [security2:error] [pid 914912:tid 915081] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/public/css.php"] [unique_id "amuZzq469-jfU7M1CLhVUwAAACc"]
[Thu Jul 30 13:37:03.104766 2026] [security2:error] [pid 914912:tid 915065] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/output.php"] [unique_id "amuZz6469-jfU7M1CLhVXQAAABc"]
[Thu Jul 30 13:37:03.104873 2026] [security2:error] [pid 914912:tid 915065] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/output.php"] [unique_id "amuZz6469-jfU7M1CLhVXQAAABc"]
[Thu Jul 30 13:37:03.615668 2026] [security2:error] [pid 914912:tid 915125] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-file-120.php"] [unique_id "amuZz6469-jfU7M1CLhVZwAAAFM"]
[Thu Jul 30 13:37:03.615783 2026] [security2:error] [pid 914912:tid 915125] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-file-120.php"] [unique_id "amuZz6469-jfU7M1CLhVZwAAAFM"]
[Thu Jul 30 13:37:04.127253 2026] [security2:error] [pid 914912:tid 915168] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/special.php"] [unique_id "amuZ0K469-jfU7M1CLhVeAAAAH4"]
[Thu Jul 30 13:37:04.127354 2026] [security2:error] [pid 914912:tid 915168] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/special.php"] [unique_id "amuZ0K469-jfU7M1CLhVeAAAAH4"]
[Thu Jul 30 13:37:04.616540 2026] [security2:error] [pid 914912:tid 915119] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/as.php"] [unique_id "amuZ0K469-jfU7M1CLhViAAAAE0"]
[Thu Jul 30 13:37:04.616638 2026] [security2:error] [pid 914912:tid 915119] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/as.php"] [unique_id "amuZ0K469-jfU7M1CLhViAAAAE0"]
[Thu Jul 30 13:37:05.104452 2026] [security2:error] [pid 914912:tid 915157] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/cgi-bin/index.php"] [unique_id "amuZ0a469-jfU7M1CLhVlgAAAHM"]
[Thu Jul 30 13:37:05.104569 2026] [security2:error] [pid 914912:tid 915157] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/cgi-bin/index.php"] [unique_id "amuZ0a469-jfU7M1CLhVlgAAAHM"]
[Thu Jul 30 13:37:05.208284 2026] [autoindex:error] [pid 914912:tid 915151] [client 162.141.167.36:52954] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:37:05.569226 2026] [security2:error] [pid 914912:tid 915128] [client 172.237.109.114:15177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0K469-jfU7M1CLhVkQAAAFY"]
[Thu Jul 30 13:37:05.590794 2026] [security2:error] [pid 914912:tid 915106] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/w1px.php"] [unique_id "amuZ0a469-jfU7M1CLhVogAAAEA"]
[Thu Jul 30 13:37:05.590895 2026] [security2:error] [pid 914912:tid 915106] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/w1px.php"] [unique_id "amuZ0a469-jfU7M1CLhVogAAAEA"]
[Thu Jul 30 13:37:05.713177 2026] [security2:error] [pid 914912:tid 915079] [client 20.226.90.242:9885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/admin.php"] [unique_id "amuZ0a469-jfU7M1CLhVpgAAACU"]
[Thu Jul 30 13:37:05.713285 2026] [security2:error] [pid 914912:tid 915079] [client 20.226.90.242:9885] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/admin.php"] [unique_id "amuZ0a469-jfU7M1CLhVpgAAACU"]
[Thu Jul 30 13:37:06.102548 2026] [security2:error] [pid 914912:tid 915110] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/js.php"] [unique_id "amuZ0q469-jfU7M1CLhVtwAAAEQ"]
[Thu Jul 30 13:37:06.102684 2026] [security2:error] [pid 914912:tid 915110] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/js.php"] [unique_id "amuZ0q469-jfU7M1CLhVtwAAAEQ"]
[Thu Jul 30 13:37:06.577205 2026] [security2:error] [pid 914912:tid 915054] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "amuZ0q469-jfU7M1CLhVzQAAAAw"]
[Thu Jul 30 13:37:06.587613 2026] [security2:error] [pid 914912:tid 915122] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/core.php"] [unique_id "amuZ0q469-jfU7M1CLhVzgAAAFA"]
[Thu Jul 30 13:37:06.587691 2026] [security2:error] [pid 914912:tid 915122] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/core.php"] [unique_id "amuZ0q469-jfU7M1CLhVzgAAAFA"]
[Thu Jul 30 13:37:06.830301 2026] [security2:error] [pid 914912:tid 915119] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/.ssh/id_rsa"] [unique_id "amuZ0q469-jfU7M1CLhV1QAAAE0"]
[Thu Jul 30 13:37:06.842154 2026] [security2:error] [pid 914912:tid 915118] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "amuZ0q469-jfU7M1CLhV1wAAAEw"]
[Thu Jul 30 13:37:07.107378 2026] [security2:error] [pid 914912:tid 915094] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fffm.php"] [unique_id "amuZ06469-jfU7M1CLhV4QAAADQ"]
[Thu Jul 30 13:37:07.107534 2026] [security2:error] [pid 914912:tid 915094] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fffm.php"] [unique_id "amuZ06469-jfU7M1CLhV4QAAADQ"]
[Thu Jul 30 13:37:07.136542 2026] [security2:error] [pid 914912:tid 915124] [client 74.7.228.28:60722] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.website-e1173f63.evk.gpl.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuZ06469-jfU7M1CLhV5QAAUmc"]
[Thu Jul 30 13:37:07.563892 2026] [security2:error] [pid 914912:tid 915074] [client 172.237.109.114:27779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVtgAAACA"]
[Thu Jul 30 13:37:07.565624 2026] [security2:error] [pid 914912:tid 915090] [client 172.237.109.114:20214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVswAAADA"]
[Thu Jul 30 13:37:07.622426 2026] [security2:error] [pid 914912:tid 915096] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ww.php"] [unique_id "amuZ06469-jfU7M1CLhV8gAAADY"]
[Thu Jul 30 13:37:07.622552 2026] [security2:error] [pid 914912:tid 915096] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ww.php"] [unique_id "amuZ06469-jfU7M1CLhV8gAAADY"]
[Thu Jul 30 13:37:08.117736 2026] [security2:error] [pid 914912:tid 915168] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/domvf.php"] [unique_id "amuZ1K469-jfU7M1CLhV-gAAAH4"]
[Thu Jul 30 13:37:08.117860 2026] [security2:error] [pid 914912:tid 915168] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/domvf.php"] [unique_id "amuZ1K469-jfU7M1CLhV-gAAAH4"]
[Thu Jul 30 13:37:08.217787 2026] [security2:error] [pid 914912:tid 915045] [client 172.237.109.114:56505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVwAAAAAM"]
[Thu Jul 30 13:37:08.226433 2026] [security2:error] [pid 914912:tid 915104] [client 172.237.109.114:47861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVvAAAAD4"]
[Thu Jul 30 13:37:08.230869 2026] [security2:error] [pid 914912:tid 915142] [client 172.237.109.114:54737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVugAAAGQ"]
[Thu Jul 30 13:37:08.232542 2026] [security2:error] [pid 914912:tid 915165] [client 172.237.109.114:36816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVuAAAAHs"]
[Thu Jul 30 13:37:08.238300 2026] [security2:error] [pid 914912:tid 915088] [client 172.237.109.114:6584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVvQAAAC4"]
[Thu Jul 30 13:37:08.248346 2026] [security2:error] [pid 914912:tid 915050] [client 172.237.109.114:6220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVtAAAAAg"]
[Thu Jul 30 13:37:08.255879 2026] [security2:error] [pid 914912:tid 915156] [client 172.237.109.114:2462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVsgAAAHI"]
[Thu Jul 30 13:37:08.271402 2026] [security2:error] [pid 914912:tid 915042] [client 172.237.109.114:10495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVwwAAAAA"]
[Thu Jul 30 13:37:08.272413 2026] [security2:error] [pid 914912:tid 915138] [client 172.237.109.114:43494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVuQAAAGA"]
[Thu Jul 30 13:37:08.279616 2026] [security2:error] [pid 914912:tid 915133] [client 172.237.109.114:54589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVxQAAAFs"]
[Thu Jul 30 13:37:08.289177 2026] [security2:error] [pid 914912:tid 915063] [client 172.237.109.114:1624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVuwAAABU"]
[Thu Jul 30 13:37:08.295811 2026] [security2:error] [pid 914912:tid 915052] [client 172.237.109.114:42791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVxgAAAAo"]
[Thu Jul 30 13:37:08.308639 2026] [security2:error] [pid 914912:tid 915107] [client 172.237.109.114:35436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVxAAAAEE"]
[Thu Jul 30 13:37:08.310493 2026] [security2:error] [pid 914912:tid 915163] [client 172.237.109.114:12650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVvwAAAHk"]
[Thu Jul 30 13:37:08.326404 2026] [security2:error] [pid 914912:tid 915098] [client 172.237.109.114:27011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVvgAAADg"]
[Thu Jul 30 13:37:08.332033 2026] [security2:error] [pid 914912:tid 915161] [client 172.237.109.114:44727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVtQAAAHc"]
[Thu Jul 30 13:37:08.360724 2026] [security2:error] [pid 914912:tid 915160] [client 172.237.109.114:37813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVwgAAAHY"]
[Thu Jul 30 13:37:08.361797 2026] [security2:error] [pid 914912:tid 915077] [client 172.237.109.114:1818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ0q469-jfU7M1CLhVwQAAACM"]
[Thu Jul 30 13:37:08.512907 2026] [security2:error] [pid 914912:tid 915118] [client 20.226.90.242:40370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/goods.php"] [unique_id "amuZ1K469-jfU7M1CLhWBQAAAEw"]
[Thu Jul 30 13:37:08.513020 2026] [security2:error] [pid 914912:tid 915118] [client 20.226.90.242:40370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/goods.php"] [unique_id "amuZ1K469-jfU7M1CLhWBQAAAEw"]
[Thu Jul 30 13:37:08.652590 2026] [security2:error] [pid 914912:tid 915059] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/echkm.php"] [unique_id "amuZ1K469-jfU7M1CLhWBgAAABE"]
[Thu Jul 30 13:37:08.652711 2026] [security2:error] [pid 914912:tid 915059] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/echkm.php"] [unique_id "amuZ1K469-jfU7M1CLhWBgAAABE"]
[Thu Jul 30 13:37:08.898878 2026] [security2:error] [pid 914912:tid 915082] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "amuZ1K469-jfU7M1CLhWDQAAACg"]
[Thu Jul 30 13:37:09.165175 2026] [security2:error] [pid 914912:tid 915125] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ano.php"] [unique_id "amuZ1a469-jfU7M1CLhWHAAAAFM"]
[Thu Jul 30 13:37:09.165290 2026] [security2:error] [pid 914912:tid 915125] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ano.php"] [unique_id "amuZ1a469-jfU7M1CLhWHAAAAFM"]
[Thu Jul 30 13:37:09.682887 2026] [security2:error] [pid 914912:tid 915160] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ah25.php"] [unique_id "amuZ1a469-jfU7M1CLhWJwAAAHY"]
[Thu Jul 30 13:37:09.683007 2026] [security2:error] [pid 914912:tid 915160] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ah25.php"] [unique_id "amuZ1a469-jfU7M1CLhWJwAAAHY"]
[Thu Jul 30 13:37:10.065899 2026] [security2:error] [pid 914912:tid 915153] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/.env.php.backup"] [unique_id "amuZ1q469-jfU7M1CLhWMgAAAG8"]
[Thu Jul 30 13:37:10.114493 2026] [security2:error] [pid 914912:tid 915114] [client 184.75.214.163:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.214.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuZ1q469-jfU7M1CLhWNQAAAEg"]
[Thu Jul 30 13:37:10.114613 2026] [security2:error] [pid 914912:tid 915114] [client 184.75.214.163:51092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuZ1q469-jfU7M1CLhWNQAAAEg"]
[Thu Jul 30 13:37:10.242592 2026] [security2:error] [pid 914912:tid 915089] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/term.php"] [unique_id "amuZ1q469-jfU7M1CLhWNgAAAC8"]
[Thu Jul 30 13:37:10.242704 2026] [security2:error] [pid 914912:tid 915089] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/term.php"] [unique_id "amuZ1q469-jfU7M1CLhWNgAAAC8"]
[Thu Jul 30 13:37:10.510150 2026] [core:notice] [pid 914912:tid 915077] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:10.745740 2026] [security2:error] [pid 914912:tid 915074] [client 93.152.224.221:56389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.224.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-includes/version.php"] [unique_id "amuZ1q469-jfU7M1CLhWRAAAACA"]
[Thu Jul 30 13:37:10.769401 2026] [security2:error] [pid 914912:tid 915112] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/we.php"] [unique_id "amuZ1q469-jfU7M1CLhWRQAAAEY"]
[Thu Jul 30 13:37:10.769498 2026] [security2:error] [pid 914912:tid 915112] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/we.php"] [unique_id "amuZ1q469-jfU7M1CLhWRQAAAEY"]
[Thu Jul 30 13:37:11.052885 2026] [security2:error] [pid 914912:tid 915075] [client 157.230.223.32:59110] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.6.43.58"] [uri "/index.cgi"] [unique_id "amuZ16469-jfU7M1CLhWTwAAACE"]
[Thu Jul 30 13:37:11.126604 2026] [security2:error] [pid 914912:tid 915102] [client 78.167.1.90:55127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZ16469-jfU7M1CLhWVQAAADw"]
[Thu Jul 30 13:37:11.127176 2026] [security2:error] [pid 914912:tid 915102] [client 78.167.1.90:55127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZ16469-jfU7M1CLhWVQAAADw"]
[Thu Jul 30 13:37:11.144366 2026] [security2:error] [pid 914912:tid 915109] [client 216.73.216.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.emberleafweeddeliverydispensary.delivery"] [uri "/index.php"] [unique_id "amuZ16469-jfU7M1CLhWUQAAAEM"]
[Thu Jul 30 13:37:11.278784 2026] [security2:error] [pid 914912:tid 915139] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/zip-onee.php"] [unique_id "amuZ16469-jfU7M1CLhWVgAAAGE"]
[Thu Jul 30 13:37:11.278895 2026] [security2:error] [pid 914912:tid 915139] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/zip-onee.php"] [unique_id "amuZ16469-jfU7M1CLhWVgAAAGE"]
[Thu Jul 30 13:37:11.690384 2026] [security2:error] [pid 914912:tid 915068] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "amuZ16469-jfU7M1CLhWZQAAABo"]
[Thu Jul 30 13:37:11.709181 2026] [security2:error] [pid 914912:tid 915113] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/backup/.env"] [unique_id "amuZ16469-jfU7M1CLhWZgAAAEc"]
[Thu Jul 30 13:37:11.786647 2026] [autoindex:error] [pid 914912:tid 915129] [client 98.87.102.177:0] AH01276: Cannot serve directory /home1/pnadjbte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:37:11.808489 2026] [security2:error] [pid 914912:tid 915054] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/il.php"] [unique_id "amuZ16469-jfU7M1CLhWagAAAAw"]
[Thu Jul 30 13:37:11.808571 2026] [security2:error] [pid 914912:tid 915054] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/il.php"] [unique_id "amuZ16469-jfU7M1CLhWagAAAAw"]
[Thu Jul 30 13:37:11.913522 2026] [security2:error] [pid 914912:tid 915047] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "amuZ16469-jfU7M1CLhWbgAAAAU"]
[Thu Jul 30 13:37:12.055946 2026] [core:error] [pid 914912:tid 914979] [remote 74.7.241.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:37:12.055972 2026] [core:error] [pid 914912:tid 914979] [remote 74.7.241.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:37:12.056176 2026] [security2:error] [pid 914912:tid 915166] [client 74.7.241.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.choiceroofingservices.click"] [uri "/index.php"] [unique_id "amuZ2K469-jfU7M1CLhWcQAAfEI"]
[Thu Jul 30 13:37:12.060300 2026] [security2:error] [pid 914912:tid 915114] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "amuZ2K469-jfU7M1CLhWcgAAAEg"]
[Thu Jul 30 13:37:12.290042 2026] [core:notice] [pid 914912:tid 914992] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:12.320705 2026] [security2:error] [pid 914912:tid 915134] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/one.php"] [unique_id "amuZ2K469-jfU7M1CLhWegAAAFw"]
[Thu Jul 30 13:37:12.320801 2026] [security2:error] [pid 914912:tid 915134] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/one.php"] [unique_id "amuZ2K469-jfU7M1CLhWegAAAFw"]
[Thu Jul 30 13:37:12.866106 2026] [security2:error] [pid 914912:tid 915095] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/002.php"] [unique_id "amuZ2K469-jfU7M1CLhWhQAAADU"]
[Thu Jul 30 13:37:12.866218 2026] [security2:error] [pid 914912:tid 915095] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/002.php"] [unique_id "amuZ2K469-jfU7M1CLhWhQAAADU"]
[Thu Jul 30 13:37:12.964095 2026] [core:notice] [pid 914912:tid 915001] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:12.967799 2026] [security2:error] [pid 914912:tid 915140] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/project/.env"] [unique_id "amuZ2K469-jfU7M1CLhWigAAAGI"]
[Thu Jul 30 13:37:13.028717 2026] [core:notice] [pid 914912:tid 915015] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:13.374767 2026] [security2:error] [pid 914912:tid 915106] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/file1.php"] [unique_id "amuZ2a469-jfU7M1CLhWkgAAAEA"]
[Thu Jul 30 13:37:13.374880 2026] [security2:error] [pid 914912:tid 915106] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/file1.php"] [unique_id "amuZ2a469-jfU7M1CLhWkgAAAEA"]
[Thu Jul 30 13:37:13.561653 2026] [core:notice] [pid 914912:tid 915013] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:13.910831 2026] [security2:error] [pid 914912:tid 915052] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/akimet.php"] [unique_id "amuZ2a469-jfU7M1CLhWnwAAAAo"]
[Thu Jul 30 13:37:13.910989 2026] [security2:error] [pid 914912:tid 915052] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/akimet.php"] [unique_id "amuZ2a469-jfU7M1CLhWnwAAAAo"]
[Thu Jul 30 13:37:14.468353 2026] [security2:error] [pid 914912:tid 915080] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/reop3.php"] [unique_id "amuZ2q469-jfU7M1CLhWtgAAACY"]
[Thu Jul 30 13:37:14.468486 2026] [security2:error] [pid 914912:tid 915080] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/reop3.php"] [unique_id "amuZ2q469-jfU7M1CLhWtgAAACY"]
[Thu Jul 30 13:37:14.882024 2026] [security2:error] [pid 914912:tid 915127] [client 20.226.90.242:50084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/file.php"] [unique_id "amuZ2q469-jfU7M1CLhWxAAAAFU"]
[Thu Jul 30 13:37:14.882121 2026] [security2:error] [pid 914912:tid 915127] [client 20.226.90.242:50084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/file.php"] [unique_id "amuZ2q469-jfU7M1CLhWxAAAAFU"]
[Thu Jul 30 13:37:14.884207 2026] [security2:error] [pid 914912:tid 915071] [client 66.249.65.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuZ2q469-jfU7M1CLhWsAAAAB0"]
[Thu Jul 30 13:37:14.977199 2026] [security2:error] [pid 914912:tid 915103] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/h.php"] [unique_id "amuZ2q469-jfU7M1CLhWywAAAD0"]
[Thu Jul 30 13:37:14.977311 2026] [security2:error] [pid 914912:tid 915103] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/h.php"] [unique_id "amuZ2q469-jfU7M1CLhWywAAAD0"]
[Thu Jul 30 13:37:15.458623 2026] [security2:error] [pid 914912:tid 915056] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/2x.php"] [unique_id "amuZ26469-jfU7M1CLhW1wAAAA4"]
[Thu Jul 30 13:37:15.458728 2026] [security2:error] [pid 914912:tid 915056] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/2x.php"] [unique_id "amuZ26469-jfU7M1CLhW1wAAAA4"]
[Thu Jul 30 13:37:15.944160 2026] [security2:error] [pid 914912:tid 915156] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/petx.php"] [unique_id "amuZ26469-jfU7M1CLhW4QAAAHI"]
[Thu Jul 30 13:37:15.944268 2026] [security2:error] [pid 914912:tid 915156] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/petx.php"] [unique_id "amuZ26469-jfU7M1CLhW4QAAAHI"]
[Thu Jul 30 13:37:16.431441 2026] [security2:error] [pid 914912:tid 915159] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/zxz.php"] [unique_id "amuZ3K469-jfU7M1CLhW7AAAAHU"]
[Thu Jul 30 13:37:16.431544 2026] [security2:error] [pid 914912:tid 915159] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/zxz.php"] [unique_id "amuZ3K469-jfU7M1CLhW7AAAAHU"]
[Thu Jul 30 13:37:16.924083 2026] [security2:error] [pid 914912:tid 915094] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/2.php"] [unique_id "amuZ3K469-jfU7M1CLhW-QAAADQ"]
[Thu Jul 30 13:37:16.924184 2026] [security2:error] [pid 914912:tid 915094] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/2.php"] [unique_id "amuZ3K469-jfU7M1CLhW-QAAADQ"]
[Thu Jul 30 13:37:17.287546 2026] [core:notice] [pid 914912:tid 915020] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:17.416620 2026] [security2:error] [pid 914912:tid 915051] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/op.php"] [unique_id "amuZ3a469-jfU7M1CLhXCgAAAAk"]
[Thu Jul 30 13:37:17.416740 2026] [security2:error] [pid 914912:tid 915051] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/op.php"] [unique_id "amuZ3a469-jfU7M1CLhXCgAAAAk"]
[Thu Jul 30 13:37:17.700818 2026] [security2:error] [pid 914912:tid 915125] [client 94.154.43.179:42588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nimna.lk"] [uri "/.env"] [unique_id "amuZ3a469-jfU7M1CLhXDwAAAFM"]
[Thu Jul 30 13:37:17.949434 2026] [security2:error] [pid 914912:tid 915111] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/a5.php"] [unique_id "amuZ3a469-jfU7M1CLhXFwAAAEU"]
[Thu Jul 30 13:37:17.949538 2026] [security2:error] [pid 914912:tid 915111] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/a5.php"] [unique_id "amuZ3a469-jfU7M1CLhXFwAAAEU"]
[Thu Jul 30 13:37:17.967865 2026] [core:notice] [pid 914912:tid 914920] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:18.484837 2026] [security2:error] [pid 914912:tid 915169] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ws80.php"] [unique_id "amuZ3q469-jfU7M1CLhXJQAAAH8"]
[Thu Jul 30 13:37:18.484932 2026] [security2:error] [pid 914912:tid 915169] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ws80.php"] [unique_id "amuZ3q469-jfU7M1CLhXJQAAAH8"]
[Thu Jul 30 13:37:18.731525 2026] [security2:error] [pid 914912:tid 915116] [client 37.46.199.86:45054] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuZ3q469-jfU7M1CLhXIwAAAEo"]
[Thu Jul 30 13:37:18.731659 2026] [security2:error] [pid 914912:tid 915116] [client 37.46.199.86:45054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuZ3q469-jfU7M1CLhXIwAAAEo"]
[Thu Jul 30 13:37:19.017939 2026] [security2:error] [pid 914912:tid 915077] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xa.php"] [unique_id "amuZ36469-jfU7M1CLhXNAAAACM"]
[Thu Jul 30 13:37:19.018047 2026] [security2:error] [pid 914912:tid 915077] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xa.php"] [unique_id "amuZ36469-jfU7M1CLhXNAAAACM"]
[Thu Jul 30 13:37:19.507005 2026] [security2:error] [pid 914912:tid 915079] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/asd67.php"] [unique_id "amuZ36469-jfU7M1CLhXQQAAACU"]
[Thu Jul 30 13:37:19.507095 2026] [security2:error] [pid 914912:tid 915079] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/asd67.php"] [unique_id "amuZ36469-jfU7M1CLhXQQAAACU"]
[Thu Jul 30 13:37:19.619940 2026] [autoindex:error] [pid 914912:tid 915133] [client 162.141.167.36:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:37:19.904311 2026] [core:notice] [pid 914912:tid 914929] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:19.998288 2026] [security2:error] [pid 914912:tid 915111] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/bk.php"] [unique_id "amuZ36469-jfU7M1CLhXUQAAAEU"]
[Thu Jul 30 13:37:19.998413 2026] [security2:error] [pid 914912:tid 915111] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/bk.php"] [unique_id "amuZ36469-jfU7M1CLhXUQAAAEU"]
[Thu Jul 30 13:37:20.490699 2026] [security2:error] [pid 914912:tid 915073] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-links.php"] [unique_id "amuZ4K469-jfU7M1CLhXXgAAAB8"]
[Thu Jul 30 13:37:20.490825 2026] [security2:error] [pid 914912:tid 915073] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-links.php"] [unique_id "amuZ4K469-jfU7M1CLhXXgAAAB8"]
[Thu Jul 30 13:37:20.526234 2026] [core:notice] [pid 914912:tid 914939] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:20.817259 2026] [core:notice] [pid 914912:tid 915123] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:21.033236 2026] [security2:error] [pid 914912:tid 915161] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/mosty.php"] [unique_id "amuZ4a469-jfU7M1CLhXcwAAAHc"]
[Thu Jul 30 13:37:21.033378 2026] [security2:error] [pid 914912:tid 915161] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/mosty.php"] [unique_id "amuZ4a469-jfU7M1CLhXcwAAAHc"]
[Thu Jul 30 13:37:21.200361 2026] [core:notice] [pid 914912:tid 914954] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:21.563322 2026] [security2:error] [pid 914912:tid 915079] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sump3.php"] [unique_id "amuZ4a469-jfU7M1CLhXgwAAACU"]
[Thu Jul 30 13:37:21.563438 2026] [security2:error] [pid 914912:tid 915079] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/sump3.php"] [unique_id "amuZ4a469-jfU7M1CLhXgwAAACU"]
[Thu Jul 30 13:37:21.627898 2026] [security2:error] [pid 914912:tid 915081] [client 78.167.1.90:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZ4a469-jfU7M1CLhXhgAAACc"]
[Thu Jul 30 13:37:21.628492 2026] [security2:error] [pid 914912:tid 915081] [client 78.167.1.90:54312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZ4a469-jfU7M1CLhXhgAAACc"]
[Thu Jul 30 13:37:22.051777 2026] [security2:error] [pid 914912:tid 915062] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/first.php"] [unique_id "amuZ4q469-jfU7M1CLhXiwAAABQ"]
[Thu Jul 30 13:37:22.051903 2026] [security2:error] [pid 914912:tid 915062] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/first.php"] [unique_id "amuZ4q469-jfU7M1CLhXiwAAABQ"]
[Thu Jul 30 13:37:22.550058 2026] [security2:error] [pid 914912:tid 915068] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/acp.php"] [unique_id "amuZ4q469-jfU7M1CLhXlQAAABo"]
[Thu Jul 30 13:37:22.550172 2026] [security2:error] [pid 914912:tid 915068] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/acp.php"] [unique_id "amuZ4q469-jfU7M1CLhXlQAAABo"]
[Thu Jul 30 13:37:23.069528 2026] [security2:error] [pid 914912:tid 915047] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-good.php"] [unique_id "amuZ46469-jfU7M1CLhXpQAAAAU"]
[Thu Jul 30 13:37:23.069626 2026] [security2:error] [pid 914912:tid 915047] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-good.php"] [unique_id "amuZ46469-jfU7M1CLhXpQAAAAU"]
[Thu Jul 30 13:37:23.532186 2026] [security2:error] [pid 914912:tid 915142] [client 20.226.90.242:34483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/adminfuns.php"] [unique_id "amuZ46469-jfU7M1CLhXtQAAAGQ"]
[Thu Jul 30 13:37:23.532308 2026] [security2:error] [pid 914912:tid 915142] [client 20.226.90.242:34483] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/adminfuns.php"] [unique_id "amuZ46469-jfU7M1CLhXtQAAAGQ"]
[Thu Jul 30 13:37:23.551295 2026] [security2:error] [pid 914912:tid 915155] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/database.sql"] [unique_id "amuZ46469-jfU7M1CLhXtgAAAHE"]
[Thu Jul 30 13:37:23.577234 2026] [security2:error] [pid 914912:tid 915152] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/daerl3.php"] [unique_id "amuZ46469-jfU7M1CLhXtwAAAG4"]
[Thu Jul 30 13:37:23.577395 2026] [security2:error] [pid 914912:tid 915152] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/daerl3.php"] [unique_id "amuZ46469-jfU7M1CLhXtwAAAG4"]
[Thu Jul 30 13:37:24.001836 2026] [security2:error] [pid 914912:tid 915153] [client 50.6.43.217:24036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuZ46469-jfU7M1CLhXrwAAAG8"]
[Thu Jul 30 13:37:24.061671 2026] [security2:error] [pid 914912:tid 915095] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/php5.php"] [unique_id "amuZ5K469-jfU7M1CLhX0gAAADU"]
[Thu Jul 30 13:37:24.061797 2026] [security2:error] [pid 914912:tid 915095] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/php5.php"] [unique_id "amuZ5K469-jfU7M1CLhX0gAAADU"]
[Thu Jul 30 13:37:24.352023 2026] [security2:error] [pid 914912:tid 915059] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZ46469-jfU7M1CLhXsQAAETU"]
[Thu Jul 30 13:37:24.415395 2026] [security2:error] [pid 914912:tid 915067] [client 74.7.228.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-293b210e.owz.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuZ4q469-jfU7M1CLhXngAAABk"]
[Thu Jul 30 13:37:24.416224 2026] [security2:error] [pid 914912:tid 915076] [client 74.7.228.29:59356] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-293b210e.owz.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuZ4q469-jfU7M1CLhXnAAAIl4"]
[Thu Jul 30 13:37:24.568540 2026] [security2:error] [pid 914912:tid 915111] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xoot.php"] [unique_id "amuZ5K469-jfU7M1CLhX-wAAAEU"]
[Thu Jul 30 13:37:24.568681 2026] [security2:error] [pid 914912:tid 915111] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/xoot.php"] [unique_id "amuZ5K469-jfU7M1CLhX-wAAAEU"]
[Thu Jul 30 13:37:24.730385 2026] [security2:error] [pid 914912:tid 915051] [client 50.6.43.217:24048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuZ5K469-jfU7M1CLhX0QAAAAk"]
[Thu Jul 30 13:37:25.089074 2026] [security2:error] [pid 914912:tid 915047] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/clxcc.php"] [unique_id "amuZ5a469-jfU7M1CLhYBQAAAAU"]
[Thu Jul 30 13:37:25.089169 2026] [security2:error] [pid 914912:tid 915047] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/clxcc.php"] [unique_id "amuZ5a469-jfU7M1CLhYBQAAAAU"]
[Thu Jul 30 13:37:25.630994 2026] [security2:error] [pid 914912:tid 915055] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ai.php"] [unique_id "amuZ5a469-jfU7M1CLhYDwAAAA0"]
[Thu Jul 30 13:37:25.631140 2026] [security2:error] [pid 914912:tid 915055] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ai.php"] [unique_id "amuZ5a469-jfU7M1CLhYDwAAAA0"]
[Thu Jul 30 13:37:26.140189 2026] [security2:error] [pid 914912:tid 915151] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/nwflm.php"] [unique_id "amuZ5q469-jfU7M1CLhYHwAAAG0"]
[Thu Jul 30 13:37:26.140277 2026] [security2:error] [pid 914912:tid 915151] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/nwflm.php"] [unique_id "amuZ5q469-jfU7M1CLhYHwAAAG0"]
[Thu Jul 30 13:37:26.364656 2026] [core:notice] [pid 914912:tid 915120] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:26.626783 2026] [security2:error] [pid 914912:tid 915078] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/hypo.php"] [unique_id "amuZ5q469-jfU7M1CLhYKgAAACQ"]
[Thu Jul 30 13:37:26.626906 2026] [security2:error] [pid 914912:tid 915078] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/hypo.php"] [unique_id "amuZ5q469-jfU7M1CLhYKgAAACQ"]
[Thu Jul 30 13:37:27.137226 2026] [security2:error] [pid 914912:tid 915163] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/w3llscc.php"] [unique_id "amuZ56469-jfU7M1CLhYNgAAAHk"]
[Thu Jul 30 13:37:27.137351 2026] [security2:error] [pid 914912:tid 915163] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/w3llscc.php"] [unique_id "amuZ56469-jfU7M1CLhYNgAAAHk"]
[Thu Jul 30 13:37:27.571133 2026] [security2:error] [pid 914912:tid 915093] [client 20.226.90.242:7504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/404.php"] [unique_id "amuZ56469-jfU7M1CLhYPQAAADM"]
[Thu Jul 30 13:37:27.571244 2026] [security2:error] [pid 914912:tid 915093] [client 20.226.90.242:7504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/404.php"] [unique_id "amuZ56469-jfU7M1CLhYPQAAADM"]
[Thu Jul 30 13:37:27.645867 2026] [security2:error] [pid 914912:tid 915159] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuZ56469-jfU7M1CLhYPgAAAHU"]
[Thu Jul 30 13:37:27.645994 2026] [security2:error] [pid 914912:tid 915159] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuZ56469-jfU7M1CLhYPgAAAHU"]
[Thu Jul 30 13:37:27.828481 2026] [security2:error] [pid 914912:tid 915064] [client 135.119.63.61:20038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/011i.php"] [unique_id "amuZ56469-jfU7M1CLhYRQAAABY"]
[Thu Jul 30 13:37:28.172678 2026] [security2:error] [pid 914912:tid 915094] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/8.php"] [unique_id "amuZ6K469-jfU7M1CLhYSgAAADQ"]
[Thu Jul 30 13:37:28.172822 2026] [security2:error] [pid 914912:tid 915094] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/8.php"] [unique_id "amuZ6K469-jfU7M1CLhYSgAAADQ"]
[Thu Jul 30 13:37:28.584880 2026] [security2:error] [pid 914912:tid 915054] [client 204.8.98.105:34390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuZ6K469-jfU7M1CLhYWQAAAAw"]
[Thu Jul 30 13:37:28.584993 2026] [security2:error] [pid 914912:tid 915054] [client 204.8.98.105:34390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuZ6K469-jfU7M1CLhYWQAAAAw"]
[Thu Jul 30 13:37:28.595713 2026] [core:error] [pid 914912:tid 914920] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/wp/
[Thu Jul 30 13:37:28.595738 2026] [core:error] [pid 914912:tid 914920] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/wp/
[Thu Jul 30 13:37:28.693913 2026] [security2:error] [pid 914912:tid 915122] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fnstall.php"] [unique_id "amuZ6K469-jfU7M1CLhYWwAAAFA"]
[Thu Jul 30 13:37:28.694041 2026] [security2:error] [pid 914912:tid 915122] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fnstall.php"] [unique_id "amuZ6K469-jfU7M1CLhYWwAAAFA"]
[Thu Jul 30 13:37:29.132382 2026] [core:error] [pid 914912:tid 914913] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/wp/
[Thu Jul 30 13:37:29.132413 2026] [core:error] [pid 914912:tid 914913] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/wp/
[Thu Jul 30 13:37:29.204920 2026] [security2:error] [pid 914912:tid 915160] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/edorxrr.php"] [unique_id "amuZ6a469-jfU7M1CLhYaQAAAHY"]
[Thu Jul 30 13:37:29.205047 2026] [security2:error] [pid 914912:tid 915160] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/edorxrr.php"] [unique_id "amuZ6a469-jfU7M1CLhYaQAAAHY"]
[Thu Jul 30 13:37:29.329587 2026] [core:error] [pid 914912:tid 914932] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/wordpress/
[Thu Jul 30 13:37:29.329629 2026] [core:error] [pid 914912:tid 914932] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/wordpress/
[Thu Jul 30 13:37:29.636904 2026] [security2:error] [pid 914912:tid 915091] [client 135.119.63.61:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/03a005685d.php"] [unique_id "amuZ6a469-jfU7M1CLhYdAAAADE"]
[Thu Jul 30 13:37:29.753934 2026] [security2:error] [pid 914912:tid 915123] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/setup.php"] [unique_id "amuZ6a469-jfU7M1CLhYdQAAAFE"]
[Thu Jul 30 13:37:29.754085 2026] [security2:error] [pid 914912:tid 915123] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/setup.php"] [unique_id "amuZ6a469-jfU7M1CLhYdQAAAFE"]
[Thu Jul 30 13:37:29.873645 2026] [core:error] [pid 914912:tid 914914] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/wordpress/
[Thu Jul 30 13:37:29.873672 2026] [core:error] [pid 914912:tid 914914] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/wordpress/
[Thu Jul 30 13:37:30.056823 2026] [security2:error] [pid 914912:tid 914999] [remote 57.141.0.66:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuZ6q469-jfU7M1CLhYgwAAe1Y"]
[Thu Jul 30 13:37:30.276879 2026] [security2:error] [pid 914912:tid 915086] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/6.php"] [unique_id "amuZ6q469-jfU7M1CLhYhAAAACw"]
[Thu Jul 30 13:37:30.277006 2026] [security2:error] [pid 914912:tid 915086] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/6.php"] [unique_id "amuZ6q469-jfU7M1CLhYhAAAACw"]
[Thu Jul 30 13:37:30.414032 2026] [core:error] [pid 914912:tid 914915] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/blog/
[Thu Jul 30 13:37:30.414065 2026] [core:error] [pid 914912:tid 914915] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/blog/
[Thu Jul 30 13:37:30.754778 2026] [security2:error] [pid 914912:tid 915148] [client 135.119.63.61:20078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/403.php"] [unique_id "amuZ6q469-jfU7M1CLhYkgAAAGo"]
[Thu Jul 30 13:37:30.781235 2026] [security2:error] [pid 914912:tid 915049] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/w3lls.php"] [unique_id "amuZ6q469-jfU7M1CLhYlAAAAAc"]
[Thu Jul 30 13:37:30.781332 2026] [security2:error] [pid 914912:tid 915049] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/w3lls.php"] [unique_id "amuZ6q469-jfU7M1CLhYlAAAAAc"]
[Thu Jul 30 13:37:30.997517 2026] [core:error] [pid 914912:tid 914939] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/blog/
[Thu Jul 30 13:37:30.997540 2026] [core:error] [pid 914912:tid 914939] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/blog/
[Thu Jul 30 13:37:31.191200 2026] [core:error] [pid 914912:tid 914937] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/old/
[Thu Jul 30 13:37:31.191224 2026] [core:error] [pid 914912:tid 914937] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/old/
[Thu Jul 30 13:37:31.300853 2026] [security2:error] [pid 914912:tid 915158] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/99.php"] [unique_id "amuZ66469-jfU7M1CLhYoAAAAHQ"]
[Thu Jul 30 13:37:31.300989 2026] [security2:error] [pid 914912:tid 915158] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/99.php"] [unique_id "amuZ66469-jfU7M1CLhYoAAAAHQ"]
[Thu Jul 30 13:37:31.573725 2026] [core:notice] [pid 914912:tid 914954] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:31.727073 2026] [core:error] [pid 914912:tid 914938] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/old/
[Thu Jul 30 13:37:31.727094 2026] [core:error] [pid 914912:tid 914938] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/old/
[Thu Jul 30 13:37:31.731832 2026] [security2:error] [pid 914912:tid 915167] [client 135.119.63.61:37413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/404.php"] [unique_id "amuZ66469-jfU7M1CLhYrwAAAH0"]
[Thu Jul 30 13:37:31.832659 2026] [security2:error] [pid 914912:tid 915056] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/admin.php"] [unique_id "amuZ66469-jfU7M1CLhYsAAAAA4"]
[Thu Jul 30 13:37:31.832777 2026] [security2:error] [pid 914912:tid 915056] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/admin.php"] [unique_id "amuZ66469-jfU7M1CLhYsAAAAA4"]
[Thu Jul 30 13:37:32.261945 2026] [core:error] [pid 914912:tid 914957] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/test/
[Thu Jul 30 13:37:32.261966 2026] [core:error] [pid 914912:tid 914957] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/test/
[Thu Jul 30 13:37:32.315402 2026] [security2:error] [pid 914912:tid 915105] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/media.php"] [unique_id "amuZ7K469-jfU7M1CLhYvgAAAD8"]
[Thu Jul 30 13:37:32.315503 2026] [security2:error] [pid 914912:tid 915105] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/media.php"] [unique_id "amuZ7K469-jfU7M1CLhYvgAAAD8"]
[Thu Jul 30 13:37:32.321252 2026] [security2:error] [pid 914912:tid 915150] [client 78.167.1.90:55735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZ7K469-jfU7M1CLhYvwAAAGw"]
[Thu Jul 30 13:37:32.321894 2026] [security2:error] [pid 914912:tid 915150] [client 78.167.1.90:55735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZ7K469-jfU7M1CLhYvwAAAGw"]
[Thu Jul 30 13:37:32.330568 2026] [autoindex:error] [pid 914912:tid 914958] [remote 172.235.137.214:56790] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:37:32.556875 2026] [security2:error] [pid 914912:tid 914943] [remote 220.181.108.168:49886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/1064"] [unique_id "amuZ7K469-jfU7M1CLhYxgAABR4"]
[Thu Jul 30 13:37:32.801510 2026] [core:error] [pid 914912:tid 914924] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/test/
[Thu Jul 30 13:37:32.801542 2026] [core:error] [pid 914912:tid 914924] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/test/
[Thu Jul 30 13:37:32.812854 2026] [security2:error] [pid 914912:tid 915162] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuZ7K469-jfU7M1CLhYzQAAAHg"]
[Thu Jul 30 13:37:32.812964 2026] [security2:error] [pid 914912:tid 915162] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuZ7K469-jfU7M1CLhYzQAAAHg"]
[Thu Jul 30 13:37:32.867112 2026] [security2:error] [pid 914912:tid 915119] [client 135.119.63.61:37379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/aa.php"] [unique_id "amuZ7K469-jfU7M1CLhYzwAAAE0"]
[Thu Jul 30 13:37:33.120746 2026] [core:notice] [pid 914912:tid 914955] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:33.201560 2026] [security2:error] [pid 914912:tid 915157] [client 57.141.0.22:60596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuZ7K469-jfU7M1CLhYzgAAczc"], referer: https://igetvape-australia.com/product/alibarbar-rich-8000-puffs-2/?add-to-cart=1055
[Thu Jul 30 13:37:33.296887 2026] [security2:error] [pid 914912:tid 915057] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/222.php"] [unique_id "amuZ7a469-jfU7M1CLhY2gAAAA8"]
[Thu Jul 30 13:37:33.297024 2026] [security2:error] [pid 914912:tid 915057] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/222.php"] [unique_id "amuZ7a469-jfU7M1CLhY2gAAAA8"]
[Thu Jul 30 13:37:33.345803 2026] [core:error] [pid 914912:tid 914983] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/dev/
[Thu Jul 30 13:37:33.345824 2026] [core:error] [pid 914912:tid 914983] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/dev/
[Thu Jul 30 13:37:33.537739 2026] [core:error] [pid 914912:tid 914985] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/dev/
[Thu Jul 30 13:37:33.537763 2026] [core:error] [pid 914912:tid 914985] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/dev/
[Thu Jul 30 13:37:33.744967 2026] [core:error] [pid 914912:tid 914976] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/backup/
[Thu Jul 30 13:37:33.745006 2026] [core:error] [pid 914912:tid 914976] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/backup/
[Thu Jul 30 13:37:33.773644 2026] [security2:error] [pid 914912:tid 915121] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-load.php"] [unique_id "amuZ7a469-jfU7M1CLhY6wAAAE8"]
[Thu Jul 30 13:37:33.773748 2026] [security2:error] [pid 914912:tid 915121] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-load.php"] [unique_id "amuZ7a469-jfU7M1CLhY6wAAAE8"]
[Thu Jul 30 13:37:33.777074 2026] [security2:error] [pid 914912:tid 915081] [client 135.119.63.61:20045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/aafewc0k.php"] [unique_id "amuZ7a469-jfU7M1CLhY7AAAACc"]
[Thu Jul 30 13:37:33.891820 2026] [security2:error] [pid 914912:tid 914971] [remote 119.249.100.109:7188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/1064"] [unique_id "amuZ7a469-jfU7M1CLhY5gAATjo"]
[Thu Jul 30 13:37:33.946331 2026] [core:error] [pid 914912:tid 914950] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/backup/
[Thu Jul 30 13:37:33.946350 2026] [core:error] [pid 914912:tid 914950] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/backup/
[Thu Jul 30 13:37:34.149744 2026] [core:error] [pid 914912:tid 914956] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/staging/
[Thu Jul 30 13:37:34.149764 2026] [core:error] [pid 914912:tid 914956] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/staging/
[Thu Jul 30 13:37:34.274616 2026] [security2:error] [pid 914912:tid 915113] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuZ7q469-jfU7M1CLhY-QAAAEc"]
[Thu Jul 30 13:37:34.274730 2026] [security2:error] [pid 914912:tid 915113] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-content/themes/index.php"] [unique_id "amuZ7q469-jfU7M1CLhY-QAAAEc"]
[Thu Jul 30 13:37:34.350599 2026] [core:error] [pid 914912:tid 914991] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/staging/
[Thu Jul 30 13:37:34.350633 2026] [core:error] [pid 914912:tid 914991] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/staging/
[Thu Jul 30 13:37:34.473147 2026] [core:notice] [pid 914912:tid 914982] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:34.546559 2026] [core:error] [pid 914912:tid 914990] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/
[Thu Jul 30 13:37:34.546594 2026] [core:error] [pid 914912:tid 914990] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/
[Thu Jul 30 13:37:34.647101 2026] [security2:error] [pid 914912:tid 914993] [remote 74.7.227.39:40916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuZ7q469-jfU7M1CLhZBAAAbFA"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/insert-headers-and-footers/includes/conditional-logic
[Thu Jul 30 13:37:34.748564 2026] [security2:error] [pid 914912:tid 915099] [client 20.226.90.242:63770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/wk/index.php"] [unique_id "amuZ7q469-jfU7M1CLhZCgAAADk"]
[Thu Jul 30 13:37:34.748692 2026] [security2:error] [pid 914912:tid 915099] [client 20.226.90.242:63770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/wk/index.php"] [unique_id "amuZ7q469-jfU7M1CLhZCgAAADk"]
[Thu Jul 30 13:37:34.762565 2026] [security2:error] [pid 914912:tid 915142] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZ7q469-jfU7M1CLhZCwAAAGQ"]
[Thu Jul 30 13:37:34.762651 2026] [security2:error] [pid 914912:tid 915142] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-admin/js/index.php"] [unique_id "amuZ7q469-jfU7M1CLhZCwAAAGQ"]
[Thu Jul 30 13:37:34.989321 2026] [security2:error] [pid 914912:tid 914944] [remote 119.249.100.108:42560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/1064"] [unique_id "amuZ7q469-jfU7M1CLhZEAAAXB8"]
[Thu Jul 30 13:37:35.000149 2026] [security2:error] [pid 914912:tid 915155] [client 143.244.57.88:55710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuZ7q469-jfU7M1CLhZEQAAAHE"]
[Thu Jul 30 13:37:35.109359 2026] [core:error] [pid 914912:tid 914980] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/
[Thu Jul 30 13:37:35.109381 2026] [core:error] [pid 914912:tid 914980] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.professionalfurnituremovingcompanyllc.store/
[Thu Jul 30 13:37:35.259577 2026] [security2:error] [pid 914912:tid 915151] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/memberfuns.php"] [unique_id "amuZ76469-jfU7M1CLhZGQAAAG0"]
[Thu Jul 30 13:37:35.259687 2026] [security2:error] [pid 914912:tid 915151] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/memberfuns.php"] [unique_id "amuZ76469-jfU7M1CLhZGQAAAG0"]
[Thu Jul 30 13:37:35.569002 2026] [security2:error] [pid 914912:tid 915102] [client 143.244.57.88:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/xmlrpc.php"] [unique_id "amuZ76469-jfU7M1CLhZHgAAADw"]
[Thu Jul 30 13:37:35.578536 2026] [security2:error] [pid 914912:tid 915005] [remote 57.141.0.29:27642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuZ76469-jfU7M1CLhZHwAAXlw"]
[Thu Jul 30 13:37:35.741420 2026] [security2:error] [pid 914912:tid 915106] [client 135.119.63.61:45485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/abcd.php"] [unique_id "amuZ76469-jfU7M1CLhZJQAAAEA"]
[Thu Jul 30 13:37:35.770576 2026] [security2:error] [pid 914912:tid 915133] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/orange3.php"] [unique_id "amuZ76469-jfU7M1CLhZKAAAAFs"]
[Thu Jul 30 13:37:35.770699 2026] [security2:error] [pid 914912:tid 915133] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/orange3.php"] [unique_id "amuZ76469-jfU7M1CLhZKAAAAFs"]
[Thu Jul 30 13:37:36.121135 2026] [core:notice] [pid 914912:tid 915163] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:36.259597 2026] [security2:error] [pid 914912:tid 915093] [client 143.244.57.88:55732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuZ8K469-jfU7M1CLhZMgAAADM"]
[Thu Jul 30 13:37:36.277779 2026] [security2:error] [pid 914912:tid 915159] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuZ8K469-jfU7M1CLhZNQAAAHU"]
[Thu Jul 30 13:37:36.277859 2026] [security2:error] [pid 914912:tid 915159] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuZ8K469-jfU7M1CLhZNQAAAHU"]
[Thu Jul 30 13:37:36.762481 2026] [security2:error] [pid 914912:tid 915088] [client 43.164.0.21:42358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.0.164.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuZ8K469-jfU7M1CLhZOgAAAC4"]
[Thu Jul 30 13:37:36.776154 2026] [security2:error] [pid 914912:tid 915143] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-the.php"] [unique_id "amuZ8K469-jfU7M1CLhZQgAAAGU"]
[Thu Jul 30 13:37:36.776310 2026] [security2:error] [pid 914912:tid 915143] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/wp-the.php"] [unique_id "amuZ8K469-jfU7M1CLhZQgAAAGU"]
[Thu Jul 30 13:37:36.820663 2026] [security2:error] [pid 914912:tid 915064] [client 143.244.57.88:55746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuZ8K469-jfU7M1CLhZRQAAABY"]
[Thu Jul 30 13:37:37.277530 2026] [security2:error] [pid 914912:tid 915134] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/crgio.php"] [unique_id "amuZ8a469-jfU7M1CLhZSwAAAFw"]
[Thu Jul 30 13:37:37.277613 2026] [security2:error] [pid 914912:tid 915134] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/crgio.php"] [unique_id "amuZ8a469-jfU7M1CLhZSwAAAFw"]
[Thu Jul 30 13:37:37.365339 2026] [security2:error] [pid 914912:tid 915119] [client 135.119.63.61:45453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/about.php"] [unique_id "amuZ8a469-jfU7M1CLhZTwAAAE0"]
[Thu Jul 30 13:37:37.386077 2026] [security2:error] [pid 914912:tid 915147] [client 143.244.57.88:43838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuZ8a469-jfU7M1CLhZUAAAAGk"]
[Thu Jul 30 13:37:37.787145 2026] [security2:error] [pid 914912:tid 915058] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ws13.php"] [unique_id "amuZ8a469-jfU7M1CLhZVwAAABA"]
[Thu Jul 30 13:37:37.787255 2026] [security2:error] [pid 914912:tid 915058] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ws13.php"] [unique_id "amuZ8a469-jfU7M1CLhZVwAAABA"]
[Thu Jul 30 13:37:37.934895 2026] [security2:error] [pid 914912:tid 915074] [client 143.244.57.88:43844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuZ8a469-jfU7M1CLhZXgAAACA"]
[Thu Jul 30 13:37:38.305645 2026] [security2:error] [pid 914912:tid 915129] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/srontol.php"] [unique_id "amuZ8q469-jfU7M1CLhZYgAAAFc"]
[Thu Jul 30 13:37:38.305735 2026] [security2:error] [pid 914912:tid 915129] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/srontol.php"] [unique_id "amuZ8q469-jfU7M1CLhZYgAAAFc"]
[Thu Jul 30 13:37:38.493875 2026] [security2:error] [pid 914912:tid 915139] [client 143.244.57.88:43858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuZ8q469-jfU7M1CLhZaQAAAGE"]
[Thu Jul 30 13:37:38.540971 2026] [security2:error] [pid 914912:tid 915062] [client 135.119.63.61:37385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/admin.php"] [unique_id "amuZ8q469-jfU7M1CLhZagAAABQ"]
[Thu Jul 30 13:37:38.553938 2026] [core:notice] [pid 914912:tid 915156] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:38.812511 2026] [security2:error] [pid 914912:tid 915138] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/miru3.php"] [unique_id "amuZ8q469-jfU7M1CLhZbwAAAGA"]
[Thu Jul 30 13:37:38.812600 2026] [security2:error] [pid 914912:tid 915138] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/miru3.php"] [unique_id "amuZ8q469-jfU7M1CLhZbwAAAGA"]
[Thu Jul 30 13:37:39.059184 2026] [security2:error] [pid 914912:tid 915093] [client 143.244.57.88:43870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuZ86469-jfU7M1CLhZeQAAADM"]
[Thu Jul 30 13:37:39.318022 2026] [security2:error] [pid 914912:tid 915132] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ingfo.php"] [unique_id "amuZ86469-jfU7M1CLhZfQAAAFo"]
[Thu Jul 30 13:37:39.318124 2026] [security2:error] [pid 914912:tid 915132] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ingfo.php"] [unique_id "amuZ86469-jfU7M1CLhZfQAAAFo"]
[Thu Jul 30 13:37:39.395718 2026] [core:error] [pid 914912:tid 915004] [remote 74.7.175.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:37:39.395742 2026] [core:error] [pid 914912:tid 915004] [remote 74.7.175.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:37:39.395963 2026] [security2:error] [pid 914912:tid 915162] [client 74.7.175.182:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.tranquilrootsisb.space"] [uri "/index.php"] [unique_id "amuZ86469-jfU7M1CLhZfgAAeFs"]
[Thu Jul 30 13:37:39.633755 2026] [security2:error] [pid 914912:tid 915166] [client 143.244.57.88:43878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuZ86469-jfU7M1CLhZhgAAAHw"]
[Thu Jul 30 13:37:39.654584 2026] [security2:error] [pid 914912:tid 915049] [client 135.119.63.61:45912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/adminfuns.php"] [unique_id "amuZ86469-jfU7M1CLhZhwAAAAc"]
[Thu Jul 30 13:37:39.696929 2026] [security2:error] [pid 914912:tid 915145] [client 34.125.247.125:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "#(submit|validate|pre_render|post_render|element_validate|after_build|value_callback|process|access_callback|lazy_builder|type|markup|value|options)" at ARGS:element_parents. [file "/opt/mod_security/hg_rules.conf"] [line "1455"] [id "9099997"] [msg "Drupalgeddon 2 Block"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/user/register"] [unique_id "amuZ86469-jfU7M1CLhZggAAAGc"]
[Thu Jul 30 13:37:39.697046 2026] [security2:error] [pid 914912:tid 915145] [client 34.125.247.125:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "406"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/user/register"] [unique_id "amuZ86469-jfU7M1CLhZggAAAGc"]
[Thu Jul 30 13:37:39.814863 2026] [security2:error] [pid 914912:tid 915144] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ey5.php"] [unique_id "amuZ86469-jfU7M1CLhZiAAAAGY"]
[Thu Jul 30 13:37:39.814972 2026] [security2:error] [pid 914912:tid 915144] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/ey5.php"] [unique_id "amuZ86469-jfU7M1CLhZiAAAAGY"]
[Thu Jul 30 13:37:39.903121 2026] [core:notice] [pid 914912:tid 915096] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:40.183518 2026] [security2:error] [pid 914912:tid 915066] [client 143.244.57.88:28408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuZ9K469-jfU7M1CLhZkwAAABg"]
[Thu Jul 30 13:37:40.350297 2026] [security2:error] [pid 914912:tid 915154] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fine.php"] [unique_id "amuZ9K469-jfU7M1CLhZlAAAAHA"]
[Thu Jul 30 13:37:40.350416 2026] [security2:error] [pid 914912:tid 915154] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/fine.php"] [unique_id "amuZ9K469-jfU7M1CLhZlAAAAHA"]
[Thu Jul 30 13:37:40.427767 2026] [security2:error] [pid 914912:tid 915152] [client 74.7.175.136:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "inmobiliariadia.com.tfy.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuZ9K469-jfU7M1CLhZnQAAAG4"]
[Thu Jul 30 13:37:40.427886 2026] [security2:error] [pid 914912:tid 915059] [client 116.179.33.82:15330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.33.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/1064"] [unique_id "amuZ9K469-jfU7M1CLhZngAAABE"]
[Thu Jul 30 13:37:40.428434 2026] [security2:error] [pid 914912:tid 915074] [client 74.7.175.136:45754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "inmobiliariadia.com.tfy.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuZ9K469-jfU7M1CLhZmQAAIHY"]
[Thu Jul 30 13:37:40.624462 2026] [security2:error] [pid 914912:tid 915072] [client 104.254.90.251:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuZ9K469-jfU7M1CLhZowAAAB4"]
[Thu Jul 30 13:37:40.624585 2026] [security2:error] [pid 914912:tid 915072] [client 104.254.90.251:51864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuZ9K469-jfU7M1CLhZowAAAB4"]
[Thu Jul 30 13:37:40.743919 2026] [security2:error] [pid 914912:tid 915121] [client 143.244.57.88:43894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuZ9K469-jfU7M1CLhZpAAAAE8"]
[Thu Jul 30 13:37:40.925077 2026] [security2:error] [pid 914912:tid 915063] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuZ9K469-jfU7M1CLhZmAAAFWw"]
[Thu Jul 30 13:37:40.954203 2026] [core:notice] [pid 914912:tid 915163] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:40.990133 2026] [security2:error] [pid 914912:tid 915138] [client 20.226.90.242:10291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/about.php"] [unique_id "amuZ9K469-jfU7M1CLhZqwAAAGA"]
[Thu Jul 30 13:37:40.990349 2026] [security2:error] [pid 914912:tid 915138] [client 20.226.90.242:10291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/about.php"] [unique_id "amuZ9K469-jfU7M1CLhZqwAAAGA"]
[Thu Jul 30 13:37:41.295501 2026] [security2:error] [pid 914912:tid 915060] [client 143.244.57.88:60784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuZ9a469-jfU7M1CLhZtQAAABI"]
[Thu Jul 30 13:37:41.301033 2026] [autoindex:error] [pid 914912:tid 915150] [client 74.7.242.60:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:37:41.361379 2026] [security2:error] [pid 914912:tid 915143] [client 184.75.214.163:37708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.214.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuZ9a469-jfU7M1CLhZtwAAAGU"]
[Thu Jul 30 13:37:41.361512 2026] [security2:error] [pid 914912:tid 915143] [client 184.75.214.163:37708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuZ9a469-jfU7M1CLhZtwAAAGU"]
[Thu Jul 30 13:37:41.464888 2026] [security2:error] [pid 914912:tid 915050] [client 172.237.109.114:62539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ9K469-jfU7M1CLhZqgAAAAg"]
[Thu Jul 30 13:37:41.621340 2026] [core:notice] [pid 914912:tid 915077] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:41.853691 2026] [security2:error] [pid 914912:tid 915065] [client 143.244.57.88:43904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuZ9a469-jfU7M1CLhZxgAAABc"]
[Thu Jul 30 13:37:42.213058 2026] [core:notice] [pid 914912:tid 915141] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:42.242618 2026] [core:notice] [pid 914912:tid 915057] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:42.246311 2026] [security2:error] [pid 914912:tid 915069] [client 114.119.149.65:59617] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/robots.txt"] [unique_id "amuZ9q469-jfU7M1CLhZ1AAAABs"], referer: http://fireworkskenya.co.ke/robots.txt
[Thu Jul 30 13:37:42.407730 2026] [security2:error] [pid 914912:tid 915136] [client 143.244.57.88:43920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuZ9q469-jfU7M1CLhZ1QAAAF4"]
[Thu Jul 30 13:37:42.622064 2026] [security2:error] [pid 914912:tid 915109] [client 172.237.109.114:28887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ9q469-jfU7M1CLhZ0QAAAEM"]
[Thu Jul 30 13:37:42.632258 2026] [security2:error] [pid 914912:tid 915096] [client 172.237.109.114:35072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ9q469-jfU7M1CLhZ0AAAADY"]
[Thu Jul 30 13:37:42.662217 2026] [autoindex:error] [pid 914912:tid 915044] [client 149.50.96.188:34158] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:37:42.808358 2026] [autoindex:error] [pid 914912:tid 915120] [client 149.50.96.188:34174] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:37:42.826364 2026] [security2:error] [pid 914912:tid 915055] [client 135.119.63.61:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/albin.php"] [unique_id "amuZ9q469-jfU7M1CLhZ4gAAAA0"]
[Thu Jul 30 13:37:42.826483 2026] [security2:error] [pid 914912:tid 915129] [client 78.167.1.90:53994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZ9q469-jfU7M1CLhZ4wAAAFc"]
[Thu Jul 30 13:37:42.826959 2026] [security2:error] [pid 914912:tid 915129] [client 78.167.1.90:53994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuZ9q469-jfU7M1CLhZ4wAAAFc"]
[Thu Jul 30 13:37:42.965152 2026] [security2:error] [pid 914912:tid 915091] [client 143.244.57.88:43932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.nordeste1.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuZ9q469-jfU7M1CLhZ5wAAADE"]
[Thu Jul 30 13:37:43.613386 2026] [security2:error] [pid 914912:tid 915060] [client 135.119.63.61:20037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/amfsqvgv.php"] [unique_id "amuZ96469-jfU7M1CLhZ_wAAABI"]
[Thu Jul 30 13:37:43.690141 2026] [security2:error] [pid 914912:tid 915072] [client 172.237.109.114:65188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ96469-jfU7M1CLhZ6AAAAB4"]
[Thu Jul 30 13:37:43.695478 2026] [security2:error] [pid 914912:tid 915121] [client 172.237.109.114:29974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ96469-jfU7M1CLhZ6QAAAE8"]
[Thu Jul 30 13:37:43.752971 2026] [security2:error] [pid 914912:tid 915042] [client 172.237.109.114:42560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ96469-jfU7M1CLhZ6gAAAAA"]
[Thu Jul 30 13:37:43.755902 2026] [security2:error] [pid 914912:tid 915159] [client 172.237.109.114:6802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ96469-jfU7M1CLhZ6wAAAHU"]
[Thu Jul 30 13:37:43.777687 2026] [security2:error] [pid 914912:tid 915163] [client 172.237.109.114:26680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ96469-jfU7M1CLhZ7wAAAHk"]
[Thu Jul 30 13:37:43.780603 2026] [security2:error] [pid 914912:tid 915111] [client 172.237.109.114:43611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ96469-jfU7M1CLhZ8QAAAEU"]
[Thu Jul 30 13:37:43.788067 2026] [security2:error] [pid 914912:tid 915063] [client 172.237.109.114:7515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ96469-jfU7M1CLhZ7AAAABU"]
[Thu Jul 30 13:37:43.798129 2026] [security2:error] [pid 914912:tid 915107] [client 172.237.109.114:7299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ96469-jfU7M1CLhZ8wAAAEE"]
[Thu Jul 30 13:37:43.816359 2026] [security2:error] [pid 914912:tid 915087] [client 172.237.109.114:6580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ96469-jfU7M1CLhZ8gAAAC0"]
[Thu Jul 30 13:37:43.970965 2026] [security2:error] [pid 914912:tid 914931] [remote 216.73.217.142:22896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuZ96469-jfU7M1CLhaAwAAHRI"]
[Thu Jul 30 13:37:44.505908 2026] [security2:error] [pid 914912:tid 915154] [client 135.119.63.61:45924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/ant.php"] [unique_id "amuZ-K469-jfU7M1CLhaFwAAAHA"]
[Thu Jul 30 13:37:44.654653 2026] [security2:error] [pid 914912:tid 915117] [client 172.237.109.114:45428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ-K469-jfU7M1CLhaCgAAAEs"]
[Thu Jul 30 13:37:44.664312 2026] [security2:error] [pid 914912:tid 915161] [client 172.237.109.114:7576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ-K469-jfU7M1CLhaCQAAAHc"]
[Thu Jul 30 13:37:44.666888 2026] [security2:error] [pid 914912:tid 915049] [client 172.237.109.114:29280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ-K469-jfU7M1CLhaCwAAAAc"]
[Thu Jul 30 13:37:44.666899 2026] [security2:error] [pid 914912:tid 915134] [client 172.237.109.114:5048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ-K469-jfU7M1CLhaCAAAAFw"]
[Thu Jul 30 13:37:44.670283 2026] [security2:error] [pid 914912:tid 915166] [client 172.237.109.114:13780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ-K469-jfU7M1CLhaDAAAAHw"]
[Thu Jul 30 13:37:44.681393 2026] [security2:error] [pid 914912:tid 915077] [client 172.237.109.114:2879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ-K469-jfU7M1CLhaBwAAACM"]
[Thu Jul 30 13:37:44.694203 2026] [security2:error] [pid 914912:tid 915147] [client 172.237.109.114:63312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ-K469-jfU7M1CLhaDQAAAGk"]
[Thu Jul 30 13:37:44.703725 2026] [security2:error] [pid 914912:tid 915144] [client 172.237.109.114:35728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ-K469-jfU7M1CLhaEQAAAGY"]
[Thu Jul 30 13:37:44.710423 2026] [security2:error] [pid 914912:tid 915140] [client 172.237.109.114:8341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuZ-K469-jfU7M1CLhaFAAAAGI"]
[Thu Jul 30 13:37:44.962738 2026] [security2:error] [pid 914912:tid 915126] [client 204.8.98.105:55450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuZ-K469-jfU7M1CLhaIwAAAFQ"]
[Thu Jul 30 13:37:44.962867 2026] [security2:error] [pid 914912:tid 915126] [client 204.8.98.105:55450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuZ-K469-jfU7M1CLhaIwAAAFQ"]
[Thu Jul 30 13:37:45.535126 2026] [security2:error] [pid 914912:tid 915047] [client 135.119.63.61:25299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/appreciators.php"] [unique_id "amuZ-a469-jfU7M1CLhaMwAAAAU"]
[Thu Jul 30 13:37:46.634003 2026] [security2:error] [pid 914912:tid 915069] [client 93.152.224.221:50744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuZ-q469-jfU7M1CLhaRgAAABs"]
[Thu Jul 30 13:37:47.214583 2026] [security2:error] [pid 914912:tid 915157] [client 135.119.63.61:37384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/archive.php"] [unique_id "amuZ-6469-jfU7M1CLhaUgAAAHM"]
[Thu Jul 30 13:37:47.961287 2026] [security2:error] [pid 914912:tid 915146] [client 93.152.224.221:52370] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "cnpinyin.com"] [uri "/wp-json/batch/v1"] [unique_id "amuZ-6469-jfU7M1CLhaagAAAGg"]
[Thu Jul 30 13:37:48.184567 2026] [security2:error] [pid 914912:tid 915118] [client 135.119.63.61:46086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/as.php"] [unique_id "amuZ_K469-jfU7M1CLhaawAAAEw"]
[Thu Jul 30 13:37:49.335599 2026] [security2:error] [pid 914912:tid 915061] [client 135.119.63.61:25323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/atomlib.php"] [unique_id "amuZ_a469-jfU7M1CLhaiQAAABM"]
[Thu Jul 30 13:37:49.477001 2026] [security2:error] [pid 914912:tid 915090] [client 93.152.224.221:54130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuZ_a469-jfU7M1CLhakAAAADA"]
[Thu Jul 30 13:37:50.542706 2026] [security2:error] [pid 914912:tid 915073] [client 135.119.63.61:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/autoload_classmap.php"] [unique_id "amuZ_q469-jfU7M1CLhapAAAAB8"]
[Thu Jul 30 13:37:50.869454 2026] [security2:error] [pid 914912:tid 915162] [client 93.152.224.221:56061] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuZ_q469-jfU7M1CLhaqwAAAHg"]
[Thu Jul 30 13:37:52.137496 2026] [core:notice] [pid 914912:tid 915112] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:52.154969 2026] [security2:error] [pid 914912:tid 915044] [client 20.226.90.242:10347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/term.php"] [unique_id "amuaAK469-jfU7M1CLhaxgAAAAI"]
[Thu Jul 30 13:37:52.155130 2026] [security2:error] [pid 914912:tid 915044] [client 20.226.90.242:10347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/term.php"] [unique_id "amuaAK469-jfU7M1CLhaxgAAAAI"]
[Thu Jul 30 13:37:52.336092 2026] [security2:error] [pid 914912:tid 915117] [client 93.152.224.221:57717] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuaAK469-jfU7M1CLhaygAAAEs"]
[Thu Jul 30 13:37:53.017775 2026] [security2:error] [pid 914912:tid 915139] [client 135.119.63.61:37382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/bb.php"] [unique_id "amuaAa469-jfU7M1CLha2AAAAGE"]
[Thu Jul 30 13:37:53.451426 2026] [security2:error] [pid 914912:tid 915114] [client 78.167.1.90:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaAa469-jfU7M1CLha3wAAAEg"]
[Thu Jul 30 13:37:53.452124 2026] [security2:error] [pid 914912:tid 915114] [client 78.167.1.90:55466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaAa469-jfU7M1CLha3wAAAEg"]
[Thu Jul 30 13:37:53.458089 2026] [security2:error] [pid 914912:tid 915093] [client 37.46.199.86:60830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuaAa469-jfU7M1CLha4AAAADM"]
[Thu Jul 30 13:37:53.458182 2026] [security2:error] [pid 914912:tid 915093] [client 37.46.199.86:60830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuaAa469-jfU7M1CLha4AAAADM"]
[Thu Jul 30 13:37:53.579124 2026] [security2:error] [pid 914912:tid 915150] [client 68.67.112.242:27389] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuaAa469-jfU7M1CLha5AAAAGw"]
[Thu Jul 30 13:37:53.730973 2026] [security2:error] [pid 914912:tid 915127] [client 93.152.224.221:59569] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuaAa469-jfU7M1CLha6QAAAFU"]
[Thu Jul 30 13:37:53.855665 2026] [security2:error] [pid 914912:tid 915080] [client 135.119.63.61:37411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/bnm.php"] [unique_id "amuaAa469-jfU7M1CLha7QAAACY"]
[Thu Jul 30 13:37:54.591972 2026] [security2:error] [pid 914912:tid 914973] [remote 57.141.0.49:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuaAq469-jfU7M1CLhbAAAAVjw"]
[Thu Jul 30 13:37:54.796448 2026] [core:notice] [pid 914912:tid 915107] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:55.271101 2026] [security2:error] [pid 914912:tid 915148] [client 135.119.63.61:37376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/bootstrap.php"] [unique_id "amuaA6469-jfU7M1CLhbEgAAAGo"]
[Thu Jul 30 13:37:55.305884 2026] [core:notice] [pid 914912:tid 915083] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:37:55.311280 2026] [security2:error] [pid 914912:tid 915083] [client 54.151.22.44:25019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/12/02/noel-2012-plus-de-100-idees-cadeaux-pour-elle-mode-voyage-techno-beaute-deco-et-gourmande/"] [unique_id "amuaA6469-jfU7M1CLhbCQAAACk"]
[Thu Jul 30 13:37:56.113007 2026] [security2:error] [pid 914912:tid 915116] [client 135.119.63.61:37416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/buy.php"] [unique_id "amuaBK469-jfU7M1CLhbNgAAAEo"]
[Thu Jul 30 13:37:56.589365 2026] [security2:error] [pid 914912:tid 915127] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuaA6469-jfU7M1CLhbMgAAAFU"]
[Thu Jul 30 13:37:57.183021 2026] [security2:error] [pid 914912:tid 915061] [client 135.119.63.61:25296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/chosen.php"] [unique_id "amuaBa469-jfU7M1CLhbTgAAABM"]
[Thu Jul 30 13:37:58.894003 2026] [security2:error] [pid 914912:tid 915091] [client 135.119.63.61:45478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/class-wp-image.php"] [unique_id "amuaBq469-jfU7M1CLhbdAAAADE"]
[Thu Jul 30 13:37:58.953182 2026] [security2:error] [pid 914912:tid 915037] [remote 57.141.0.3:23208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuaBq469-jfU7M1CLhbdgAAbHw"]
[Thu Jul 30 13:37:59.127926 2026] [security2:error] [pid 914912:tid 914925] [remote 74.7.243.224:56112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/article.php"] [unique_id "amuaB6469-jfU7M1CLhbfgAAUAw"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:37:59.906077 2026] [security2:error] [pid 914912:tid 915128] [client 135.119.63.61:46191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/classsmtps.php"] [unique_id "amuaB6469-jfU7M1CLhbjgAAAFY"]
[Thu Jul 30 13:38:00.246179 2026] [security2:error] [pid 914912:tid 915069] [client 93.152.224.221:50916] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/wp-ticket/readme.txt"] [unique_id "amuaCK469-jfU7M1CLhbkgAAABs"]
[Thu Jul 30 13:38:01.559240 2026] [security2:error] [pid 914912:tid 915050] [client 93.152.224.221:52442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/wp-automatic/readme.txt"] [unique_id "amuaCa469-jfU7M1CLhbtQAAAAg"]
[Thu Jul 30 13:38:01.804705 2026] [security2:error] [pid 914912:tid 914952] [remote 40.77.167.43:27331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/$$$call$$$/page/page/css"] [unique_id "amuaCa469-jfU7M1CLhbuAAANyc"], referer: https://ejournalugj.com/index.php/agroswagati/issue/current
[Thu Jul 30 13:38:02.018129 2026] [security2:error] [pid 914912:tid 914938] [remote 40.77.167.43:27331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/$$$call$$$/page/page/css"] [unique_id "amuaCq469-jfU7M1CLhbxQAAIxk"], referer: https://ejournalugj.com/index.php/agroswagati/issue/current
[Thu Jul 30 13:38:02.243561 2026] [security2:error] [pid 914912:tid 915136] [client 20.226.90.242:5639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/ioxi-o.php"] [unique_id "amuaCq469-jfU7M1CLhbyQAAAF4"]
[Thu Jul 30 13:38:02.243669 2026] [security2:error] [pid 914912:tid 915136] [client 20.226.90.242:5639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/ioxi-o.php"] [unique_id "amuaCq469-jfU7M1CLhbyQAAAF4"]
[Thu Jul 30 13:38:02.854771 2026] [security2:error] [pid 914912:tid 915074] [client 93.152.224.221:53826] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "amuaCq469-jfU7M1CLhb2QAAACA"]
[Thu Jul 30 13:38:03.019838 2026] [security2:error] [pid 914912:tid 915156] [client 135.119.63.61:25299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/classwithtostring.php"] [unique_id "amuaC6469-jfU7M1CLhb4AAAAHI"]
[Thu Jul 30 13:38:03.285323 2026] [security2:error] [pid 914912:tid 915144] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuaCq469-jfU7M1CLhb1gAAAGY"]
[Thu Jul 30 13:38:03.977282 2026] [security2:error] [pid 914912:tid 915118] [client 78.167.1.90:57332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaC6469-jfU7M1CLhb9AAAAEw"]
[Thu Jul 30 13:38:03.977749 2026] [security2:error] [pid 914912:tid 915118] [client 78.167.1.90:57332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaC6469-jfU7M1CLhb9AAAAEw"]
[Thu Jul 30 13:38:04.168985 2026] [security2:error] [pid 914912:tid 915149] [client 93.152.224.221:55363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/gamipress/readme.txt"] [unique_id "amuaDK469-jfU7M1CLhb_gAAAGs"]
[Thu Jul 30 13:38:04.223684 2026] [security2:error] [pid 914912:tid 915109] [client 135.119.63.61:37401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/config.php"] [unique_id "amuaDK469-jfU7M1CLhb_wAAAEM"]
[Thu Jul 30 13:38:05.326760 2026] [security2:error] [pid 914912:tid 915153] [client 135.119.63.61:37394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/core.php"] [unique_id "amuaDa469-jfU7M1CLhcGwAAAG8"]
[Thu Jul 30 13:38:05.525450 2026] [security2:error] [pid 914912:tid 915166] [client 93.152.224.221:56809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/userswp/readme.txt"] [unique_id "amuaDa469-jfU7M1CLhcHQAAAHw"]
[Thu Jul 30 13:38:06.055949 2026] [core:notice] [pid 914912:tid 915048] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:06.782209 2026] [security2:error] [pid 914912:tid 915050] [client 93.152.224.221:58369] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/bookingpress-appointment-booking/readme.txt"] [unique_id "amuaDq469-jfU7M1CLhcOgAAAAg"]
[Thu Jul 30 13:38:07.184256 2026] [security2:error] [pid 914912:tid 915043] [client 135.119.63.61:46173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/css.php"] [unique_id "amuaD6469-jfU7M1CLhcRQAAAAE"]
[Thu Jul 30 13:38:08.002095 2026] [core:notice] [pid 914912:tid 915143] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:08.239741 2026] [security2:error] [pid 914912:tid 915069] [client 135.119.63.61:45931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/database.php"] [unique_id "amuaEK469-jfU7M1CLhcWwAAABs"]
[Thu Jul 30 13:38:08.666289 2026] [security2:error] [pid 914912:tid 914994] [remote 77.88.47.27:48360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.47.88.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/10/11/look-jose-les-baskets-compensees/"] [unique_id "amuaEK469-jfU7M1CLhcXwAAV1E"]
[Thu Jul 30 13:38:10.007157 2026] [security2:error] [pid 914912:tid 915098] [client 135.119.63.61:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/db.php"] [unique_id "amuaEq469-jfU7M1CLhcjQAAADg"]
[Thu Jul 30 13:38:10.354468 2026] [security2:error] [pid 914912:tid 915128] [client 20.226.90.242:6176] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.riyadhprinter.com"] [uri "/1.php"] [unique_id "amuaEq469-jfU7M1CLhckwAAAFY"]
[Thu Jul 30 13:38:10.354574 2026] [security2:error] [pid 914912:tid 915128] [client 20.226.90.242:6176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.90.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.riyadhprinter.com"] [uri "/1.php"] [unique_id "amuaEq469-jfU7M1CLhckwAAAFY"]
[Thu Jul 30 13:38:10.354653 2026] [security2:error] [pid 914912:tid 915128] [client 20.226.90.242:6176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.riyadhprinter.com"] [uri "/1.php"] [unique_id "amuaEq469-jfU7M1CLhckwAAAFY"]
[Thu Jul 30 13:38:10.395938 2026] [security2:error] [pid 914912:tid 915079] [client 191.232.199.39:23926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wk/index.php"] [unique_id "amuaEq469-jfU7M1CLhclgAAACU"]
[Thu Jul 30 13:38:11.431596 2026] [autoindex:error] [pid 914912:tid 915114] [client 195.96.139.152:37427] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:38:11.589875 2026] [security2:error] [pid 914912:tid 915070] [client 135.119.63.61:37404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/default.php"] [unique_id "amuaE6469-jfU7M1CLhctwAAABw"]
[Thu Jul 30 13:38:11.745637 2026] [security2:error] [pid 914912:tid 915152] [client 191.232.199.39:23876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/av.php"] [unique_id "amuaE6469-jfU7M1CLhcvAAAAG4"]
[Thu Jul 30 13:38:13.273045 2026] [security2:error] [pid 914912:tid 915054] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuaFK469-jfU7M1CLhc1gAAAAw"]
[Thu Jul 30 13:38:13.517634 2026] [security2:error] [pid 914912:tid 915095] [client 191.232.199.39:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/mini.php"] [unique_id "amuaFa469-jfU7M1CLhc8wAAADU"]
[Thu Jul 30 13:38:13.743933 2026] [security2:error] [pid 914912:tid 915157] [client 135.119.63.61:20113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/dropdown.php"] [unique_id "amuaFa469-jfU7M1CLhc9AAAAHM"]
[Thu Jul 30 13:38:13.835301 2026] [core:notice] [pid 914912:tid 915165] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:14.206273 2026] [security2:error] [pid 914912:tid 915117] [client 20.79.29.209:16239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/alfates.php"] [unique_id "amuaFq469-jfU7M1CLhc_wAAAEs"]
[Thu Jul 30 13:38:14.206395 2026] [security2:error] [pid 914912:tid 915117] [client 20.79.29.209:16239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/alfates.php"] [unique_id "amuaFq469-jfU7M1CLhc_wAAAEs"]
[Thu Jul 30 13:38:14.509343 2026] [security2:error] [pid 914912:tid 915118] [client 20.79.29.209:16146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/themes.php"] [unique_id "amuaFq469-jfU7M1CLhdAwAAAEw"]
[Thu Jul 30 13:38:14.509457 2026] [security2:error] [pid 914912:tid 915118] [client 20.79.29.209:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/themes.php"] [unique_id "amuaFq469-jfU7M1CLhdAwAAAEw"]
[Thu Jul 30 13:38:14.548524 2026] [security2:error] [pid 914912:tid 915063] [client 78.167.1.90:54703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaFq469-jfU7M1CLhdBAAAABU"]
[Thu Jul 30 13:38:14.548672 2026] [security2:error] [pid 914912:tid 915063] [client 78.167.1.90:54703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaFq469-jfU7M1CLhdBAAAABU"]
[Thu Jul 30 13:38:14.585016 2026] [security2:error] [pid 914912:tid 915034] [remote 216.73.217.142:41664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuaFq469-jfU7M1CLhdCAAAFnk"]
[Thu Jul 30 13:38:14.644634 2026] [security2:error] [pid 914912:tid 915164] [client 43.172.197.160:47576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/08/06/shopping-a-miami-mode-chaussures-beaute-mes-bonnes-adresses/"] [unique_id "amuaFq469-jfU7M1CLhdCgAAAHo"]
[Thu Jul 30 13:38:14.809670 2026] [security2:error] [pid 914912:tid 915116] [client 191.232.199.39:32639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aa.php"] [unique_id "amuaFq469-jfU7M1CLhdEQAAAEo"]
[Thu Jul 30 13:38:14.825024 2026] [security2:error] [pid 914912:tid 915125] [client 20.79.29.209:16133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/update.php"] [unique_id "amuaFq469-jfU7M1CLhdEgAAAFM"]
[Thu Jul 30 13:38:14.825102 2026] [security2:error] [pid 914912:tid 915125] [client 20.79.29.209:16133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/update.php"] [unique_id "amuaFq469-jfU7M1CLhdEgAAAFM"]
[Thu Jul 30 13:38:14.871089 2026] [security2:error] [pid 914912:tid 915042] [client 43.172.198.22:54184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/a-propos/"] [unique_id "amuaFq469-jfU7M1CLhdCQAAAAA"]
[Thu Jul 30 13:38:15.091440 2026] [core:notice] [pid 914912:tid 915098] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:15.096370 2026] [security2:error] [pid 914912:tid 915098] [client 43.173.178.44:39686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/a-propos/"] [unique_id "amuaF6469-jfU7M1CLhdFgAAADg"], referer: https://carnetdeshopping.com/index.php/a-propos/
[Thu Jul 30 13:38:15.096574 2026] [security2:error] [pid 914912:tid 915128] [client 20.79.29.209:16142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/upgrade.php"] [unique_id "amuaF6469-jfU7M1CLhdGQAAAFY"]
[Thu Jul 30 13:38:15.096646 2026] [security2:error] [pid 914912:tid 915128] [client 20.79.29.209:16142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/upgrade.php"] [unique_id "amuaF6469-jfU7M1CLhdGQAAAFY"]
[Thu Jul 30 13:38:15.242597 2026] [security2:error] [pid 914912:tid 914931] [remote 57.141.0.67:32364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuaF6469-jfU7M1CLhdHQAAHRI"]
[Thu Jul 30 13:38:15.384161 2026] [core:notice] [pid 914912:tid 915141] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:15.390261 2026] [security2:error] [pid 914912:tid 915141] [client 43.173.175.164:54036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/08/06/shopping-a-miami-mode-chaussures-beaute-mes-bonnes-adresses/"] [unique_id "amuaF6469-jfU7M1CLhdJQAAAGM"], referer: https://carnetdeshopping.com/index.php/2012/08/06/shopping-a-miami-mode-chaussures-beaute-mes-bonnes-adresses/?replytocom=638
[Thu Jul 30 13:38:15.400060 2026] [security2:error] [pid 914912:tid 915147] [client 20.79.29.209:16138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/ajax.php"] [unique_id "amuaF6469-jfU7M1CLhdJgAAAGk"]
[Thu Jul 30 13:38:15.400164 2026] [security2:error] [pid 914912:tid 915147] [client 20.79.29.209:16138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/ajax.php"] [unique_id "amuaF6469-jfU7M1CLhdJgAAAGk"]
[Thu Jul 30 13:38:15.556150 2026] [security2:error] [pid 914912:tid 914935] [remote 57.141.0.9:26406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuaF6469-jfU7M1CLhdJwAAWRY"]
[Thu Jul 30 13:38:15.593599 2026] [security2:error] [pid 914912:tid 915084] [client 172.237.109.114:21666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaF6469-jfU7M1CLhdFwAAACo"]
[Thu Jul 30 13:38:15.593631 2026] [security2:error] [pid 914912:tid 915155] [client 172.237.109.114:49985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaF6469-jfU7M1CLhdGAAAAHE"]
[Thu Jul 30 13:38:15.649824 2026] [security2:error] [pid 914912:tid 915085] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuaF6469-jfU7M1CLhdEwAAK28"]
[Thu Jul 30 13:38:15.699799 2026] [security2:error] [pid 914912:tid 915126] [client 20.79.29.209:16254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-mail.php"] [unique_id "amuaF6469-jfU7M1CLhdLAAAAFQ"]
[Thu Jul 30 13:38:15.699951 2026] [security2:error] [pid 914912:tid 915126] [client 20.79.29.209:16254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-mail.php"] [unique_id "amuaF6469-jfU7M1CLhdLAAAAFQ"]
[Thu Jul 30 13:38:15.851729 2026] [security2:error] [pid 914912:tid 915120] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuaF6469-jfU7M1CLhdHAAAThM"]
[Thu Jul 30 13:38:15.974197 2026] [security2:error] [pid 914912:tid 915163] [client 20.79.29.209:16129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/dashboard.php"] [unique_id "amuaF6469-jfU7M1CLhdNQAAAHk"]
[Thu Jul 30 13:38:15.974327 2026] [security2:error] [pid 914912:tid 915163] [client 20.79.29.209:16129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/dashboard.php"] [unique_id "amuaF6469-jfU7M1CLhdNQAAAHk"]
[Thu Jul 30 13:38:16.318282 2026] [security2:error] [pid 914912:tid 915160] [client 20.79.29.209:16253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/misc.php"] [unique_id "amuaGK469-jfU7M1CLhdSwAAAHY"]
[Thu Jul 30 13:38:16.318425 2026] [security2:error] [pid 914912:tid 915160] [client 20.79.29.209:16253] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/misc.php"] [unique_id "amuaGK469-jfU7M1CLhdSwAAAHY"]
[Thu Jul 30 13:38:16.395019 2026] [security2:error] [pid 914912:tid 915132] [client 191.232.199.39:41361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/w.php"] [unique_id "amuaGK469-jfU7M1CLhdTQAAAFo"]
[Thu Jul 30 13:38:16.457192 2026] [security2:error] [pid 914912:tid 915091] [client 135.119.63.61:37395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/edit.php"] [unique_id "amuaGK469-jfU7M1CLhdVwAAADE"]
[Thu Jul 30 13:38:16.593552 2026] [security2:error] [pid 914912:tid 915158] [client 20.79.29.209:16179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/class-IXR.php"] [unique_id "amuaGK469-jfU7M1CLhdWwAAAHQ"]
[Thu Jul 30 13:38:16.593706 2026] [security2:error] [pid 914912:tid 915158] [client 20.79.29.209:16179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/class-IXR.php"] [unique_id "amuaGK469-jfU7M1CLhdWwAAAHQ"]
[Thu Jul 30 13:38:16.654559 2026] [security2:error] [pid 914912:tid 915152] [client 172.237.109.114:26634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGK469-jfU7M1CLhdOgAAAG4"]
[Thu Jul 30 13:38:16.663285 2026] [security2:error] [pid 914912:tid 915060] [client 172.237.109.114:63468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGK469-jfU7M1CLhdOwAAABI"]
[Thu Jul 30 13:38:16.735418 2026] [security2:error] [pid 914912:tid 915133] [client 172.237.109.114:60017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGK469-jfU7M1CLhdPwAAAFs"]
[Thu Jul 30 13:38:16.746171 2026] [security2:error] [pid 914912:tid 915067] [client 172.237.109.114:7749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGK469-jfU7M1CLhdPQAAABk"]
[Thu Jul 30 13:38:16.759374 2026] [security2:error] [pid 914912:tid 915139] [client 172.237.109.114:45385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGK469-jfU7M1CLhdPgAAAGE"]
[Thu Jul 30 13:38:16.760641 2026] [security2:error] [pid 914912:tid 915093] [client 172.237.109.114:24717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGK469-jfU7M1CLhdPAAAADM"]
[Thu Jul 30 13:38:16.783839 2026] [security2:error] [pid 914912:tid 915063] [client 172.237.109.114:28246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGK469-jfU7M1CLhdQgAAABU"]
[Thu Jul 30 13:38:16.790216 2026] [security2:error] [pid 914912:tid 915146] [client 172.237.109.114:3570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGK469-jfU7M1CLhdQAAAAGg"]
[Thu Jul 30 13:38:16.813915 2026] [security2:error] [pid 914912:tid 915064] [client 172.237.109.114:11446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGK469-jfU7M1CLhdQQAAABY"]
[Thu Jul 30 13:38:16.887402 2026] [security2:error] [pid 914912:tid 915147] [client 20.79.29.209:16241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/plugin.php"] [unique_id "amuaGK469-jfU7M1CLhdZQAAAGk"]
[Thu Jul 30 13:38:16.887513 2026] [security2:error] [pid 914912:tid 915147] [client 20.79.29.209:16241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/plugin.php"] [unique_id "amuaGK469-jfU7M1CLhdZQAAAGk"]
[Thu Jul 30 13:38:17.018582 2026] [core:notice] [pid 914912:tid 915083] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:17.147557 2026] [security2:error] [pid 914912:tid 915068] [client 20.79.29.209:16236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/revision.php"] [unique_id "amuaGa469-jfU7M1CLhdcwAAABo"]
[Thu Jul 30 13:38:17.147693 2026] [security2:error] [pid 914912:tid 915068] [client 20.79.29.209:16236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/revision.php"] [unique_id "amuaGa469-jfU7M1CLhdcwAAABo"]
[Thu Jul 30 13:38:17.416069 2026] [security2:error] [pid 914912:tid 915108] [client 20.79.29.209:16221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/screen.php"] [unique_id "amuaGa469-jfU7M1CLhdfQAAAEI"]
[Thu Jul 30 13:38:17.416212 2026] [security2:error] [pid 914912:tid 915108] [client 20.79.29.209:16221] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/screen.php"] [unique_id "amuaGa469-jfU7M1CLhdfQAAAEI"]
[Thu Jul 30 13:38:17.662707 2026] [security2:error] [pid 914912:tid 915076] [client 172.237.109.114:32351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdawAAACI"]
[Thu Jul 30 13:38:17.664459 2026] [security2:error] [pid 914912:tid 915084] [client 172.237.109.114:24468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdbAAAACo"]
[Thu Jul 30 13:38:17.669379 2026] [security2:error] [pid 914912:tid 915165] [client 172.237.109.114:30957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdcgAAAHs"]
[Thu Jul 30 13:38:17.676093 2026] [security2:error] [pid 914912:tid 915096] [client 172.237.109.114:47629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdagAAADY"]
[Thu Jul 30 13:38:17.677538 2026] [security2:error] [pid 914912:tid 915112] [client 20.79.29.209:16132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/atomlib.php"] [unique_id "amuaGa469-jfU7M1CLhdgAAAAEY"]
[Thu Jul 30 13:38:17.677640 2026] [security2:error] [pid 914912:tid 915112] [client 20.79.29.209:16132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/atomlib.php"] [unique_id "amuaGa469-jfU7M1CLhdgAAAAEY"]
[Thu Jul 30 13:38:17.704415 2026] [security2:error] [pid 914912:tid 915085] [client 172.237.109.114:40910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdbQAAACs"]
[Thu Jul 30 13:38:17.720648 2026] [security2:error] [pid 914912:tid 915121] [client 172.237.109.114:16675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdcQAAAE8"]
[Thu Jul 30 13:38:17.734703 2026] [security2:error] [pid 914912:tid 915157] [client 172.237.109.114:15104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdbgAAAHM"]
[Thu Jul 30 13:38:17.737685 2026] [security2:error] [pid 914912:tid 915110] [client 191.232.199.39:43830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/admin.php"] [unique_id "amuaGa469-jfU7M1CLhdhAAAAEQ"]
[Thu Jul 30 13:38:17.742817 2026] [security2:error] [pid 914912:tid 915095] [client 172.237.109.114:39250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdcAAAADU"]
[Thu Jul 30 13:38:17.743008 2026] [security2:error] [pid 914912:tid 915126] [client 172.237.109.114:42182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdbwAAAFQ"]
[Thu Jul 30 13:38:17.774026 2026] [security2:error] [pid 914912:tid 915105] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuaGa469-jfU7M1CLhdaQAAPyw"]
[Thu Jul 30 13:38:17.949008 2026] [security2:error] [pid 914912:tid 915063] [client 20.79.29.209:16189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/class-wp.php"] [unique_id "amuaGa469-jfU7M1CLhdjQAAABU"]
[Thu Jul 30 13:38:17.949135 2026] [security2:error] [pid 914912:tid 915063] [client 20.79.29.209:16189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/class-wp.php"] [unique_id "amuaGa469-jfU7M1CLhdjQAAABU"]
[Thu Jul 30 13:38:18.241884 2026] [security2:error] [pid 914912:tid 915078] [client 20.79.29.209:16149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/date.php"] [unique_id "amuaGq469-jfU7M1CLhdkgAAACQ"]
[Thu Jul 30 13:38:18.241989 2026] [security2:error] [pid 914912:tid 915078] [client 20.79.29.209:16149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/date.php"] [unique_id "amuaGq469-jfU7M1CLhdkgAAACQ"]
[Thu Jul 30 13:38:18.594125 2026] [security2:error] [pid 914912:tid 915086] [client 119.73.97.132:30849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuaFa469-jfU7M1CLhc7QAALHE"]
[Thu Jul 30 13:38:18.594196 2026] [security2:error] [pid 914912:tid 915086] [client 119.73.97.132:30849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuaFa469-jfU7M1CLhc7gAALHo"]
[Thu Jul 30 13:38:18.597101 2026] [security2:error] [pid 914912:tid 915167] [client 20.79.29.209:16220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/deprecated.php"] [unique_id "amuaGq469-jfU7M1CLhdmwAAAH0"]
[Thu Jul 30 13:38:18.597196 2026] [security2:error] [pid 914912:tid 915167] [client 20.79.29.209:16220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/deprecated.php"] [unique_id "amuaGq469-jfU7M1CLhdmwAAAH0"]
[Thu Jul 30 13:38:18.931607 2026] [security2:error] [pid 914912:tid 915092] [client 20.79.29.209:16240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/feed-atom.php"] [unique_id "amuaGq469-jfU7M1CLhdpQAAADI"]
[Thu Jul 30 13:38:18.931709 2026] [security2:error] [pid 914912:tid 915092] [client 20.79.29.209:16240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/feed-atom.php"] [unique_id "amuaGq469-jfU7M1CLhdpQAAADI"]
[Thu Jul 30 13:38:19.029778 2026] [security2:error] [pid 914912:tid 915117] [client 191.232.199.39:32584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/themes/admin.php"] [unique_id "amuaG6469-jfU7M1CLhdpgAAAEs"]
[Thu Jul 30 13:38:19.086799 2026] [security2:error] [pid 914912:tid 914972] [remote 216.73.217.142:41664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuaG6469-jfU7M1CLhdpwAAejs"]
[Thu Jul 30 13:38:19.114041 2026] [security2:error] [pid 914912:tid 915160] [client 135.119.63.61:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/f35.php"] [unique_id "amuaG6469-jfU7M1CLhdqAAAAHY"]
[Thu Jul 30 13:38:19.288304 2026] [security2:error] [pid 914912:tid 915137] [client 20.79.29.209:16192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/feed.php"] [unique_id "amuaG6469-jfU7M1CLhdrQAAAF8"]
[Thu Jul 30 13:38:19.288400 2026] [security2:error] [pid 914912:tid 915137] [client 20.79.29.209:16192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/feed.php"] [unique_id "amuaG6469-jfU7M1CLhdrQAAAF8"]
[Thu Jul 30 13:38:19.708921 2026] [security2:error] [pid 914912:tid 915126] [client 20.79.29.209:16197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/defense.php"] [unique_id "amuaG6469-jfU7M1CLhdtAAAAFQ"]
[Thu Jul 30 13:38:19.709036 2026] [security2:error] [pid 914912:tid 915126] [client 20.79.29.209:16197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/defense.php"] [unique_id "amuaG6469-jfU7M1CLhdtAAAAFQ"]
[Thu Jul 30 13:38:20.038139 2026] [security2:error] [pid 914912:tid 915133] [client 20.79.29.209:16246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/defend.php"] [unique_id "amuaHK469-jfU7M1CLhdvwAAAFs"]
[Thu Jul 30 13:38:20.038245 2026] [security2:error] [pid 914912:tid 915133] [client 20.79.29.209:16246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/defend.php"] [unique_id "amuaHK469-jfU7M1CLhdvwAAAFs"]
[Thu Jul 30 13:38:20.231773 2026] [security2:error] [pid 914912:tid 915051] [client 85.208.96.204:47672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/20/governador-em-exercicio-e-homenageado-pela-subsecao-da-oab-em-guarabira/"] [unique_id "amuaHK469-jfU7M1CLhdwAAAAAk"]
[Thu Jul 30 13:38:20.231905 2026] [security2:error] [pid 914912:tid 915051] [client 85.208.96.204:47672] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/20/governador-em-exercicio-e-homenageado-pela-subsecao-da-oab-em-guarabira/"] [unique_id "amuaHK469-jfU7M1CLhdwAAAAAk"]
[Thu Jul 30 13:38:20.352216 2026] [security2:error] [pid 914912:tid 915093] [client 20.79.29.209:16135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/load.php"] [unique_id "amuaHK469-jfU7M1CLhdwQAAADM"]
[Thu Jul 30 13:38:20.352360 2026] [security2:error] [pid 914912:tid 915093] [client 20.79.29.209:16135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/load.php"] [unique_id "amuaHK469-jfU7M1CLhdwQAAADM"]
[Thu Jul 30 13:38:20.471900 2026] [security2:error] [pid 914912:tid 915067] [client 135.119.63.61:21064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/f7.php"] [unique_id "amuaHK469-jfU7M1CLhdxwAAABk"]
[Thu Jul 30 13:38:20.612812 2026] [security2:error] [pid 914912:tid 915050] [client 20.79.29.209:16128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/options.php"] [unique_id "amuaHK469-jfU7M1CLhdzQAAAAg"]
[Thu Jul 30 13:38:20.612951 2026] [security2:error] [pid 914912:tid 915050] [client 20.79.29.209:16128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/options.php"] [unique_id "amuaHK469-jfU7M1CLhdzQAAAAg"]
[Thu Jul 30 13:38:20.882144 2026] [security2:error] [pid 914912:tid 915102] [client 20.79.29.209:16202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/option.php"] [unique_id "amuaHK469-jfU7M1CLhdzgAAADw"]
[Thu Jul 30 13:38:20.882255 2026] [security2:error] [pid 914912:tid 915102] [client 20.79.29.209:16202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/option.php"] [unique_id "amuaHK469-jfU7M1CLhdzgAAADw"]
[Thu Jul 30 13:38:21.146336 2026] [security2:error] [pid 914912:tid 915140] [client 20.79.29.209:16200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/query.php"] [unique_id "amuaHa469-jfU7M1CLhd2AAAAGI"]
[Thu Jul 30 13:38:21.146445 2026] [security2:error] [pid 914912:tid 915140] [client 20.79.29.209:16200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/query.php"] [unique_id "amuaHa469-jfU7M1CLhd2AAAAGI"]
[Thu Jul 30 13:38:21.421381 2026] [security2:error] [pid 914912:tid 915072] [client 74.7.241.165:34146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.247telehtechnology.com"] [uri "/index.php"] [unique_id "amuaG6469-jfU7M1CLhdqwAAHkg"]
[Thu Jul 30 13:38:21.433592 2026] [security2:error] [pid 914912:tid 915070] [client 20.79.29.209:16228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/post.php"] [unique_id "amuaHa469-jfU7M1CLhd3AAAABw"]
[Thu Jul 30 13:38:21.433686 2026] [security2:error] [pid 914912:tid 915070] [client 20.79.29.209:16228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/post.php"] [unique_id "amuaHa469-jfU7M1CLhd3AAAABw"]
[Thu Jul 30 13:38:21.656183 2026] [security2:error] [pid 914912:tid 915167] [client 191.232.199.39:32577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/m.php"] [unique_id "amuaHa469-jfU7M1CLhd4wAAAH0"]
[Thu Jul 30 13:38:21.909987 2026] [security2:error] [pid 914912:tid 915046] [client 20.79.29.209:16209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/sessions.php"] [unique_id "amuaHa469-jfU7M1CLhd5QAAAAQ"]
[Thu Jul 30 13:38:21.910101 2026] [security2:error] [pid 914912:tid 915046] [client 20.79.29.209:16209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/sessions.php"] [unique_id "amuaHa469-jfU7M1CLhd5QAAAAQ"]
[Thu Jul 30 13:38:22.232954 2026] [security2:error] [pid 914912:tid 915096] [client 20.79.29.209:16242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/rss.php"] [unique_id "amuaHq469-jfU7M1CLhd8AAAADY"]
[Thu Jul 30 13:38:22.233108 2026] [security2:error] [pid 914912:tid 915096] [client 20.79.29.209:16242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/rss.php"] [unique_id "amuaHq469-jfU7M1CLhd8AAAADY"]
[Thu Jul 30 13:38:22.532541 2026] [security2:error] [pid 914912:tid 915113] [client 20.79.29.209:16211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/sitemaps.php"] [unique_id "amuaHq469-jfU7M1CLhd9gAAAEc"]
[Thu Jul 30 13:38:22.532631 2026] [security2:error] [pid 914912:tid 915113] [client 20.79.29.209:16211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/sitemaps.php"] [unique_id "amuaHq469-jfU7M1CLhd9gAAAEc"]
[Thu Jul 30 13:38:22.989661 2026] [security2:error] [pid 914912:tid 915101] [client 20.79.29.209:16227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/template.php"] [unique_id "amuaHq469-jfU7M1CLhd_gAAADs"]
[Thu Jul 30 13:38:22.989774 2026] [security2:error] [pid 914912:tid 915101] [client 20.79.29.209:16227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/template.php"] [unique_id "amuaHq469-jfU7M1CLhd_gAAADs"]
[Thu Jul 30 13:38:23.278104 2026] [security2:error] [pid 914912:tid 915102] [client 20.79.29.209:16150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/vars.php"] [unique_id "amuaH6469-jfU7M1CLheCAAAADw"]
[Thu Jul 30 13:38:23.278200 2026] [security2:error] [pid 914912:tid 915102] [client 20.79.29.209:16150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/vars.php"] [unique_id "amuaH6469-jfU7M1CLheCAAAADw"]
[Thu Jul 30 13:38:23.540935 2026] [security2:error] [pid 914912:tid 915142] [client 20.79.29.209:16208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/version.php"] [unique_id "amuaH6469-jfU7M1CLheCgAAAGQ"]
[Thu Jul 30 13:38:23.541065 2026] [security2:error] [pid 914912:tid 915142] [client 20.79.29.209:16208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/version.php"] [unique_id "amuaH6469-jfU7M1CLheCgAAAGQ"]
[Thu Jul 30 13:38:23.836250 2026] [security2:error] [pid 914912:tid 915063] [client 191.232.199.39:41391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuaH6469-jfU7M1CLheDQAAABU"]
[Thu Jul 30 13:38:23.893184 2026] [security2:error] [pid 914912:tid 915088] [client 20.79.29.209:16195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/user.php"] [unique_id "amuaH6469-jfU7M1CLheGAAAAC4"]
[Thu Jul 30 13:38:23.893289 2026] [security2:error] [pid 914912:tid 915088] [client 20.79.29.209:16195] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/user.php"] [unique_id "amuaH6469-jfU7M1CLheGAAAAC4"]
[Thu Jul 30 13:38:24.164935 2026] [security2:error] [pid 914912:tid 915160] [client 20.79.29.209:16145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/widgets.php"] [unique_id "amuaIK469-jfU7M1CLheIwAAAHY"]
[Thu Jul 30 13:38:24.165073 2026] [security2:error] [pid 914912:tid 915160] [client 20.79.29.209:16145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/widgets.php"] [unique_id "amuaIK469-jfU7M1CLheIwAAAHY"]
[Thu Jul 30 13:38:24.468844 2026] [security2:error] [pid 914912:tid 915125] [client 20.79.29.209:16232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/theme.php"] [unique_id "amuaIK469-jfU7M1CLheLgAAAFM"]
[Thu Jul 30 13:38:24.468928 2026] [security2:error] [pid 914912:tid 915125] [client 20.79.29.209:16232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/theme.php"] [unique_id "amuaIK469-jfU7M1CLheLgAAAFM"]
[Thu Jul 30 13:38:24.756031 2026] [security2:error] [pid 914912:tid 915113] [client 20.79.29.209:16147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/category.php"] [unique_id "amuaIK469-jfU7M1CLhePAAAAEc"]
[Thu Jul 30 13:38:24.756133 2026] [security2:error] [pid 914912:tid 915113] [client 20.79.29.209:16147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/category.php"] [unique_id "amuaIK469-jfU7M1CLhePAAAAEc"]
[Thu Jul 30 13:38:25.086152 2026] [security2:error] [pid 914912:tid 915151] [client 20.79.29.209:16140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/block.php"] [unique_id "amuaIa469-jfU7M1CLhePwAAAG0"]
[Thu Jul 30 13:38:25.086266 2026] [security2:error] [pid 914912:tid 915151] [client 20.79.29.209:16140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/block.php"] [unique_id "amuaIa469-jfU7M1CLhePwAAAG0"]
[Thu Jul 30 13:38:25.186757 2026] [security2:error] [pid 914912:tid 915056] [client 78.167.1.90:56983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaIa469-jfU7M1CLheQwAAAA4"]
[Thu Jul 30 13:38:25.187416 2026] [security2:error] [pid 914912:tid 915056] [client 78.167.1.90:56983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaIa469-jfU7M1CLheQwAAAA4"]
[Thu Jul 30 13:38:25.398580 2026] [security2:error] [pid 914912:tid 915102] [client 20.79.29.209:16215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/admin-bar.php"] [unique_id "amuaIa469-jfU7M1CLheSgAAADw"]
[Thu Jul 30 13:38:25.398694 2026] [security2:error] [pid 914912:tid 915102] [client 20.79.29.209:16215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/admin-bar.php"] [unique_id "amuaIa469-jfU7M1CLheSgAAADw"]
[Thu Jul 30 13:38:25.719111 2026] [security2:error] [pid 914912:tid 915083] [client 20.79.29.209:16234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/mar.php"] [unique_id "amuaIa469-jfU7M1CLheUgAAACk"]
[Thu Jul 30 13:38:25.719225 2026] [security2:error] [pid 914912:tid 915083] [client 20.79.29.209:16234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/mar.php"] [unique_id "amuaIa469-jfU7M1CLheUgAAACk"]
[Thu Jul 30 13:38:26.118655 2026] [security2:error] [pid 914912:tid 915048] [client 20.79.29.209:16153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/revisi.php"] [unique_id "amuaIq469-jfU7M1CLheWAAAAAY"]
[Thu Jul 30 13:38:26.118772 2026] [security2:error] [pid 914912:tid 915048] [client 20.79.29.209:16153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/revisi.php"] [unique_id "amuaIq469-jfU7M1CLheWAAAAAY"]
[Thu Jul 30 13:38:26.370567 2026] [security2:error] [pid 914912:tid 915082] [client 191.232.199.39:23726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/classwithtostring.php"] [unique_id "amuaIq469-jfU7M1CLheYwAAACg"]
[Thu Jul 30 13:38:26.397646 2026] [security2:error] [pid 914912:tid 915044] [client 20.79.29.209:16249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-activate.php"] [unique_id "amuaIq469-jfU7M1CLheZAAAAAI"]
[Thu Jul 30 13:38:26.397739 2026] [security2:error] [pid 914912:tid 915044] [client 20.79.29.209:16249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-activate.php"] [unique_id "amuaIq469-jfU7M1CLheZAAAAAI"]
[Thu Jul 30 13:38:26.678708 2026] [security2:error] [pid 914912:tid 915163] [client 20.79.29.209:16154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/xmrlpc.php"] [unique_id "amuaIq469-jfU7M1CLheagAAAHk"]
[Thu Jul 30 13:38:26.678805 2026] [security2:error] [pid 914912:tid 915163] [client 20.79.29.209:16154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/xmrlpc.php"] [unique_id "amuaIq469-jfU7M1CLheagAAAHk"]
[Thu Jul 30 13:38:26.798881 2026] [core:notice] [pid 914912:tid 915039] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:26.804092 2026] [security2:error] [pid 914912:tid 915114] [client 47.128.96.152:11526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/1662"] [unique_id "amuaIq469-jfU7M1CLheZgAASH4"]
[Thu Jul 30 13:38:26.914531 2026] [security2:error] [pid 914912:tid 915036] [remote 121.229.156.32:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/"] [unique_id "amuaIq469-jfU7M1CLhecQAARHs"]
[Thu Jul 30 13:38:26.914693 2026] [security2:error] [pid 914912:tid 915110] [client 121.229.156.32:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jipkl.com"] [uri "/"] [unique_id "amuaIq469-jfU7M1CLhecQAARHs"]
[Thu Jul 30 13:38:26.919552 2026] [core:notice] [pid 914912:tid 915038] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:26.981616 2026] [core:error] [pid 914912:tid 915035] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:26.981639 2026] [core:error] [pid 914912:tid 915035] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:27.003372 2026] [core:notice] [pid 914912:tid 915026] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:27.064417 2026] [core:notice] [pid 914912:tid 915027] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:27.067357 2026] [security2:error] [pid 914912:tid 915138] [client 20.79.29.209:16156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-settings.php"] [unique_id "amuaI6469-jfU7M1CLhedwAAAGA"]
[Thu Jul 30 13:38:27.067495 2026] [security2:error] [pid 914912:tid 915138] [client 20.79.29.209:16156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-settings.php"] [unique_id "amuaI6469-jfU7M1CLhedwAAAGA"]
[Thu Jul 30 13:38:27.351221 2026] [security2:error] [pid 914912:tid 915055] [client 20.79.29.209:16182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/kon.php"] [unique_id "amuaI6469-jfU7M1CLhegAAAAA0"]
[Thu Jul 30 13:38:27.351375 2026] [security2:error] [pid 914912:tid 915055] [client 20.79.29.209:16182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/kon.php"] [unique_id "amuaI6469-jfU7M1CLhegAAAAA0"]
[Thu Jul 30 13:38:27.665312 2026] [security2:error] [pid 914912:tid 915139] [client 20.79.29.209:12246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/kontol.php"] [unique_id "amuaI6469-jfU7M1CLhehwAAAGE"]
[Thu Jul 30 13:38:27.665425 2026] [security2:error] [pid 914912:tid 915139] [client 20.79.29.209:12246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/kontol.php"] [unique_id "amuaI6469-jfU7M1CLhehwAAAGE"]
[Thu Jul 30 13:38:27.931037 2026] [security2:error] [pid 914912:tid 915070] [client 20.79.29.209:16230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp.php"] [unique_id "amuaI6469-jfU7M1CLhekwAAABw"]
[Thu Jul 30 13:38:27.931138 2026] [security2:error] [pid 914912:tid 915070] [client 20.79.29.209:16230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp.php"] [unique_id "amuaI6469-jfU7M1CLhekwAAABw"]
[Thu Jul 30 13:38:27.968824 2026] [security2:error] [pid 914912:tid 915067] [client 191.232.199.39:51959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/gmo.php"] [unique_id "amuaI6469-jfU7M1CLhelAAAABk"]
[Thu Jul 30 13:38:28.264884 2026] [security2:error] [pid 914912:tid 915120] [client 20.79.29.209:16219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/readme.php"] [unique_id "amuaJK469-jfU7M1CLheoAAAAE4"]
[Thu Jul 30 13:38:28.265000 2026] [security2:error] [pid 914912:tid 915120] [client 20.79.29.209:16219] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/readme.php"] [unique_id "amuaJK469-jfU7M1CLheoAAAAE4"]
[Thu Jul 30 13:38:28.526535 2026] [security2:error] [pid 914912:tid 915163] [client 20.79.29.209:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/error_log.php"] [unique_id "amuaJK469-jfU7M1CLhepwAAAHk"]
[Thu Jul 30 13:38:28.526646 2026] [security2:error] [pid 914912:tid 915163] [client 20.79.29.209:12238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/error_log.php"] [unique_id "amuaJK469-jfU7M1CLhepwAAAHk"]
[Thu Jul 30 13:38:28.696485 2026] [core:error] [pid 914912:tid 914999] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:28.696505 2026] [core:error] [pid 914912:tid 914999] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:28.819056 2026] [security2:error] [pid 914912:tid 915125] [client 157.245.60.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.60.245.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "embassyofitalyislamabad.vip"] [uri "/wp-login.php"] [unique_id "amuaJK469-jfU7M1CLheqQAAAFM"]
[Thu Jul 30 13:38:28.856554 2026] [security2:error] [pid 914912:tid 915042] [client 20.79.29.209:16166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-admin.php"] [unique_id "amuaJK469-jfU7M1CLherwAAAAA"]
[Thu Jul 30 13:38:28.856655 2026] [security2:error] [pid 914912:tid 915042] [client 20.79.29.209:16166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-admin.php"] [unique_id "amuaJK469-jfU7M1CLherwAAAAA"]
[Thu Jul 30 13:38:29.010659 2026] [security2:error] [pid 914912:tid 915126] [client 35.238.83.104:49517] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.pvl.djb.temporary.site"] [uri "/.env"] [unique_id "amuaJa469-jfU7M1CLhetgAAAFQ"]
[Thu Jul 30 13:38:29.127949 2026] [core:error] [pid 914912:tid 914941] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:29.127971 2026] [core:error] [pid 914912:tid 914941] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:29.493173 2026] [security2:error] [pid 914912:tid 915108] [client 20.79.29.209:16223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-login.php"] [unique_id "amuaJa469-jfU7M1CLheuwAAAEI"]
[Thu Jul 30 13:38:29.493257 2026] [security2:error] [pid 914912:tid 915108] [client 20.79.29.209:16223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-login.php"] [unique_id "amuaJa469-jfU7M1CLheuwAAAEI"]
[Thu Jul 30 13:38:29.611100 2026] [security2:error] [pid 914912:tid 915114] [client 191.232.199.39:23742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/languages/index.php"] [unique_id "amuaJa469-jfU7M1CLheywAAAEg"]
[Thu Jul 30 13:38:29.805968 2026] [security2:error] [pid 914912:tid 915131] [client 20.79.29.209:16243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/administrator.php"] [unique_id "amuaJa469-jfU7M1CLhezAAAAFk"]
[Thu Jul 30 13:38:29.806084 2026] [security2:error] [pid 914912:tid 915131] [client 20.79.29.209:16243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/administrator.php"] [unique_id "amuaJa469-jfU7M1CLhezAAAAFk"]
[Thu Jul 30 13:38:30.092490 2026] [security2:error] [pid 914912:tid 915046] [client 20.79.29.209:16143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-load.php"] [unique_id "amuaJq469-jfU7M1CLhe1gAAAAQ"]
[Thu Jul 30 13:38:30.092581 2026] [security2:error] [pid 914912:tid 915046] [client 20.79.29.209:16143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-load.php"] [unique_id "amuaJq469-jfU7M1CLhe1gAAAAQ"]
[Thu Jul 30 13:38:30.385406 2026] [core:error] [pid 914912:tid 914917] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:30.385426 2026] [core:error] [pid 914912:tid 914917] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:30.447885 2026] [security2:error] [pid 914912:tid 915121] [client 20.79.29.209:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-includes.php"] [unique_id "amuaJq469-jfU7M1CLhe3QAAAE8"]
[Thu Jul 30 13:38:30.448022 2026] [security2:error] [pid 914912:tid 915121] [client 20.79.29.209:12237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-includes.php"] [unique_id "amuaJq469-jfU7M1CLhe3QAAAE8"]
[Thu Jul 30 13:38:30.816217 2026] [security2:error] [pid 914912:tid 915113] [client 20.79.29.209:12269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-content.php"] [unique_id "amuaJq469-jfU7M1CLhe6AAAAEc"]
[Thu Jul 30 13:38:30.816335 2026] [security2:error] [pid 914912:tid 915113] [client 20.79.29.209:12269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-content.php"] [unique_id "amuaJq469-jfU7M1CLhe6AAAAEc"]
[Thu Jul 30 13:38:31.122881 2026] [security2:error] [pid 914912:tid 915110] [client 191.232.199.39:23617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-the.php"] [unique_id "amuaJ6469-jfU7M1CLhe8QAAAEQ"]
[Thu Jul 30 13:38:31.145998 2026] [security2:error] [pid 914912:tid 915051] [client 20.79.29.209:16134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhe9AAAAAk"]
[Thu Jul 30 13:38:31.146114 2026] [security2:error] [pid 914912:tid 915051] [client 20.79.29.209:16134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhe9AAAAAk"]
[Thu Jul 30 13:38:31.207003 2026] [core:error] [pid 914912:tid 914945] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:31.207029 2026] [core:error] [pid 914912:tid 914945] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:31.459859 2026] [security2:error] [pid 914912:tid 915052] [client 193.47.62.167:51062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.embassyinislamabadad.com"] [uri "/index.php"] [unique_id "amuaJq469-jfU7M1CLhe2AAAAAo"]
[Thu Jul 30 13:38:31.498322 2026] [security2:error] [pid 914912:tid 915078] [client 20.79.29.209:16188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/bypp.php"] [unique_id "amuaJ6469-jfU7M1CLhfBQAAACQ"]
[Thu Jul 30 13:38:31.498495 2026] [security2:error] [pid 914912:tid 915078] [client 20.79.29.209:16188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/bypp.php"] [unique_id "amuaJ6469-jfU7M1CLhfBQAAACQ"]
[Thu Jul 30 13:38:31.766119 2026] [security2:error] [pid 914912:tid 915141] [client 20.79.29.209:16204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/byp7.php"] [unique_id "amuaJ6469-jfU7M1CLhfDAAAAGM"]
[Thu Jul 30 13:38:31.766223 2026] [security2:error] [pid 914912:tid 915141] [client 20.79.29.209:16204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/byp7.php"] [unique_id "amuaJ6469-jfU7M1CLhfDAAAAGM"]
[Thu Jul 30 13:38:31.983311 2026] [core:error] [pid 914912:tid 914924] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:31.983337 2026] [core:error] [pid 914912:tid 914924] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:32.029878 2026] [security2:error] [pid 914912:tid 915067] [client 20.79.29.209:12100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/anonsec.php"] [unique_id "amuaKK469-jfU7M1CLhfEQAAABk"]
[Thu Jul 30 13:38:32.029991 2026] [security2:error] [pid 914912:tid 915067] [client 20.79.29.209:12100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/anonsec.php"] [unique_id "amuaKK469-jfU7M1CLhfEQAAABk"]
[Thu Jul 30 13:38:32.315843 2026] [security2:error] [pid 914912:tid 915167] [client 20.79.29.209:16196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/anon.php"] [unique_id "amuaKK469-jfU7M1CLhfFQAAAH0"]
[Thu Jul 30 13:38:32.316009 2026] [security2:error] [pid 914912:tid 915167] [client 20.79.29.209:16196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/anon.php"] [unique_id "amuaKK469-jfU7M1CLhfFQAAAH0"]
[Thu Jul 30 13:38:32.429346 2026] [security2:error] [pid 914912:tid 915062] [client 191.232.199.39:23655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/404.php"] [unique_id "amuaKK469-jfU7M1CLhfGQAAABQ"]
[Thu Jul 30 13:38:32.643690 2026] [security2:error] [pid 914912:tid 915123] [client 20.79.29.209:16231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/bypas.php"] [unique_id "amuaKK469-jfU7M1CLhfIAAAAFE"]
[Thu Jul 30 13:38:32.643883 2026] [security2:error] [pid 914912:tid 915123] [client 20.79.29.209:16231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/bypas.php"] [unique_id "amuaKK469-jfU7M1CLhfIAAAAFE"]
[Thu Jul 30 13:38:32.768491 2026] [core:error] [pid 914912:tid 914968] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:32.768520 2026] [core:error] [pid 914912:tid 914968] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:32.930835 2026] [security2:error] [pid 914912:tid 915113] [client 20.79.29.209:16148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/ucen.php"] [unique_id "amuaKK469-jfU7M1CLhfKwAAAEc"]
[Thu Jul 30 13:38:32.930961 2026] [security2:error] [pid 914912:tid 915113] [client 20.79.29.209:16148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/ucen.php"] [unique_id "amuaKK469-jfU7M1CLhfKwAAAEc"]
[Thu Jul 30 13:38:33.272916 2026] [security2:error] [pid 914912:tid 915133] [client 20.79.29.209:16164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/miya.php"] [unique_id "amuaKa469-jfU7M1CLhfLwAAAFs"]
[Thu Jul 30 13:38:33.273100 2026] [security2:error] [pid 914912:tid 915133] [client 20.79.29.209:16164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/miya.php"] [unique_id "amuaKa469-jfU7M1CLhfLwAAAFs"]
[Thu Jul 30 13:38:33.549649 2026] [core:error] [pid 914912:tid 914951] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:33.549671 2026] [core:error] [pid 914912:tid 914951] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:33.590818 2026] [security2:error] [pid 914912:tid 915103] [client 20.79.29.209:16222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/error.php"] [unique_id "amuaKa469-jfU7M1CLhfOAAAAD0"]
[Thu Jul 30 13:38:33.590931 2026] [security2:error] [pid 914912:tid 915103] [client 20.79.29.209:16222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/error.php"] [unique_id "amuaKa469-jfU7M1CLhfOAAAAD0"]
[Thu Jul 30 13:38:33.633959 2026] [ssl:error] [pid 914912:tid 915055] [client 66.132.195.102:48424] AH02032: Hostname sh00085.hostgator.com (default host as no SNI was provided) and hostname kamiliacademy.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Thu Jul 30 13:38:33.835618 2026] [security2:error] [pid 914912:tid 915049] [client 191.232.199.39:23641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/init.php"] [unique_id "amuaKa469-jfU7M1CLhfQQAAAAc"]
[Thu Jul 30 13:38:33.871796 2026] [security2:error] [pid 914912:tid 915104] [client 20.79.29.209:16170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/alfav.php"] [unique_id "amuaKa469-jfU7M1CLhfQgAAAD4"]
[Thu Jul 30 13:38:33.871887 2026] [security2:error] [pid 914912:tid 915104] [client 20.79.29.209:16170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/alfav.php"] [unique_id "amuaKa469-jfU7M1CLhfQgAAAD4"]
[Thu Jul 30 13:38:34.083628 2026] [security2:error] [pid 914912:tid 915114] [client 18.207.129.220:54189] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mydubaidesertsafari.com"] [uri "/wp-login.php"] [unique_id "amuaKa469-jfU7M1CLhfOQAAAEg"]
[Thu Jul 30 13:38:34.083628 2026] [security2:error] [pid 914912:tid 915129] [client 18.207.129.220:54187] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/wp-login.php"] [unique_id "amuaKa469-jfU7M1CLhfNwAAAFc"]
[Thu Jul 30 13:38:34.152598 2026] [security2:error] [pid 914912:tid 915147] [client 18.207.129.220:54192] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "dhowcruisedinner.com"] [uri "/wp-login.php"] [unique_id "amuaKa469-jfU7M1CLhfOgAAAGk"]
[Thu Jul 30 13:38:34.187496 2026] [security2:error] [pid 914912:tid 915050] [client 18.207.129.220:54198] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.kingstarenterprises.com"] [uri "/wp-login.php"] [unique_id "amuaKa469-jfU7M1CLhfPQAAAAg"]
[Thu Jul 30 13:38:34.195905 2026] [security2:error] [pid 914912:tid 915082] [client 20.79.29.209:16214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/alpas.php"] [unique_id "amuaKq469-jfU7M1CLhfUQAAACg"]
[Thu Jul 30 13:38:34.195999 2026] [security2:error] [pid 914912:tid 915082] [client 20.79.29.209:16214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/alpas.php"] [unique_id "amuaKq469-jfU7M1CLhfUQAAACg"]
[Thu Jul 30 13:38:34.274704 2026] [security2:error] [pid 914912:tid 915093] [client 3.88.130.217:54772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhe9wAAADM"]
[Thu Jul 30 13:38:34.329351 2026] [core:error] [pid 914912:tid 914959] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:34.329374 2026] [core:error] [pid 914912:tid 914959] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:34.414204 2026] [security2:error] [pid 914912:tid 915071] [client 18.207.129.220:54193] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiantourz.com"] [uri "/wp-login.php"] [unique_id "amuaKa469-jfU7M1CLhfPAAAAB0"]
[Thu Jul 30 13:38:34.571319 2026] [security2:error] [pid 914912:tid 915064] [client 20.79.29.209:16217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/alfa.php"] [unique_id "amuaKq469-jfU7M1CLhfZAAAABY"]
[Thu Jul 30 13:38:34.571407 2026] [security2:error] [pid 914912:tid 915064] [client 20.79.29.209:16217] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/alfa.php"] [unique_id "amuaKq469-jfU7M1CLhfZAAAABY"]
[Thu Jul 30 13:38:34.895204 2026] [security2:error] [pid 914912:tid 915103] [client 20.79.29.209:16144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/0byte.php"] [unique_id "amuaKq469-jfU7M1CLhfaAAAAD0"]
[Thu Jul 30 13:38:34.895360 2026] [security2:error] [pid 914912:tid 915103] [client 20.79.29.209:16144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/0byte.php"] [unique_id "amuaKq469-jfU7M1CLhfaAAAAD0"]
[Thu Jul 30 13:38:35.113929 2026] [core:error] [pid 914912:tid 914986] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:35.113950 2026] [core:error] [pid 914912:tid 914986] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:35.174143 2026] [security2:error] [pid 914912:tid 915053] [client 20.79.29.209:16213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/index3.php"] [unique_id "amuaK6469-jfU7M1CLhfdAAAAAs"]
[Thu Jul 30 13:38:35.174245 2026] [security2:error] [pid 914912:tid 915053] [client 20.79.29.209:16213] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/index3.php"] [unique_id "amuaK6469-jfU7M1CLhfdAAAAAs"]
[Thu Jul 30 13:38:35.392227 2026] [security2:error] [pid 914912:tid 915161] [client 185.177.72.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aashlawfirm.com"] [uri "/index.php"] [unique_id "amuaKq469-jfU7M1CLhfSQAAAHc"]
[Thu Jul 30 13:38:35.443150 2026] [security2:error] [pid 914912:tid 915047] [client 20.79.29.209:16247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/index2.php"] [unique_id "amuaK6469-jfU7M1CLhfdQAAAAU"]
[Thu Jul 30 13:38:35.443261 2026] [security2:error] [pid 914912:tid 915047] [client 20.79.29.209:16247] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/index2.php"] [unique_id "amuaK6469-jfU7M1CLhfdQAAAAU"]
[Thu Jul 30 13:38:35.453611 2026] [security2:error] [pid 914912:tid 915014] [remote 212.80.9.235:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amuaK6469-jfU7M1CLhfdgAAE2U"]
[Thu Jul 30 13:38:35.641798 2026] [security2:error] [pid 914912:tid 915089] [client 191.232.199.39:23740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/file5.php"] [unique_id "amuaK6469-jfU7M1CLhffQAAAC8"]
[Thu Jul 30 13:38:35.773743 2026] [security2:error] [pid 914912:tid 915084] [client 20.79.29.209:16198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/index1.php"] [unique_id "amuaK6469-jfU7M1CLhfggAAACo"]
[Thu Jul 30 13:38:35.773884 2026] [security2:error] [pid 914912:tid 915084] [client 20.79.29.209:16198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/index1.php"] [unique_id "amuaK6469-jfU7M1CLhfggAAACo"]
[Thu Jul 30 13:38:35.804400 2026] [security2:error] [pid 914912:tid 915117] [client 78.167.1.90:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaK6469-jfU7M1CLhfgwAAAEs"]
[Thu Jul 30 13:38:35.805298 2026] [security2:error] [pid 914912:tid 915117] [client 78.167.1.90:56594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaK6469-jfU7M1CLhfgwAAAEs"]
[Thu Jul 30 13:38:35.925664 2026] [core:error] [pid 914912:tid 914979] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:35.925685 2026] [core:error] [pid 914912:tid 914979] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:36.066792 2026] [autoindex:error] [pid 914912:tid 915159] [client 185.177.72.9:0] AH01276: Cannot serve directory /home1/xffnyxte/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:38:36.125823 2026] [security2:error] [pid 914912:tid 915087] [client 20.79.29.209:16245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/303.php"] [unique_id "amuaLK469-jfU7M1CLhfiwAAAC0"]
[Thu Jul 30 13:38:36.125918 2026] [security2:error] [pid 914912:tid 915087] [client 20.79.29.209:16245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/303.php"] [unique_id "amuaLK469-jfU7M1CLhfiwAAAC0"]
[Thu Jul 30 13:38:36.309782 2026] [security2:error] [pid 914912:tid 915151] [client 3.88.130.217:54800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhe_QAAAG0"]
[Thu Jul 30 13:38:36.309909 2026] [security2:error] [pid 914912:tid 915107] [client 3.88.130.217:54670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhe_gAAAEE"]
[Thu Jul 30 13:38:36.309909 2026] [security2:error] [pid 914912:tid 915152] [client 3.88.130.217:54738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhe_wAAAG4"]
[Thu Jul 30 13:38:36.310210 2026] [security2:error] [pid 914912:tid 915073] [client 3.88.130.217:54754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaKK469-jfU7M1CLhfGAAAAB8"]
[Thu Jul 30 13:38:36.310318 2026] [security2:error] [pid 914912:tid 915065] [client 3.88.130.217:54768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhe9gAAABc"]
[Thu Jul 30 13:38:36.310365 2026] [security2:error] [pid 914912:tid 915143] [client 3.88.130.217:54798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhfAwAAAGU"]
[Thu Jul 30 13:38:36.310499 2026] [security2:error] [pid 914912:tid 915128] [client 3.88.130.217:54784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhfAgAAAFY"]
[Thu Jul 30 13:38:36.310508 2026] [security2:error] [pid 914912:tid 915057] [client 3.88.130.217:54716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhfAQAAAA8"]
[Thu Jul 30 13:38:36.310528 2026] [security2:error] [pid 914912:tid 915092] [client 3.88.130.217:54682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhfAAAAADI"]
[Thu Jul 30 13:38:36.310549 2026] [security2:error] [pid 914912:tid 915158] [client 3.88.130.217:54724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhe-AAAAHQ"]
[Thu Jul 30 13:38:36.310632 2026] [security2:error] [pid 914912:tid 915085] [client 3.88.130.217:54706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhe_AAAACs"]
[Thu Jul 30 13:38:36.310652 2026] [security2:error] [pid 914912:tid 915074] [client 3.88.130.217:54690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaKK469-jfU7M1CLhfFwAAACA"]
[Thu Jul 30 13:38:36.310698 2026] [security2:error] [pid 914912:tid 915157] [client 3.88.130.217:54668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaJ6469-jfU7M1CLhfBAAAAHM"]
[Thu Jul 30 13:38:36.310773 2026] [security2:error] [pid 914912:tid 915116] [client 3.88.130.217:54692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuaKK469-jfU7M1CLhfFgAAAEo"]
[Thu Jul 30 13:38:36.394621 2026] [security2:error] [pid 914912:tid 915153] [client 20.79.29.209:12274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/505.php"] [unique_id "amuaLK469-jfU7M1CLhfkAAAAG8"]
[Thu Jul 30 13:38:36.394735 2026] [security2:error] [pid 914912:tid 915153] [client 20.79.29.209:12274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/505.php"] [unique_id "amuaLK469-jfU7M1CLhfkAAAAG8"]
[Thu Jul 30 13:38:36.441683 2026] [proxy:error] [pid 914912:tid 915094] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:38:36.441736 2026] [proxy_http:error] [pid 914912:tid 915094] [client 74.7.241.151:40548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:38:36.442306 2026] [proxy:error] [pid 914912:tid 915094] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:38:36.442350 2026] [proxy_http:error] [pid 914912:tid 915094] [client 74.7.241.151:40548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:38:36.551631 2026] [autoindex:error] [pid 914912:tid 914973] [remote 45.56.127.98:51470] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:38:36.604290 2026] [security2:error] [pid 914912:tid 915080] [client 185.177.72.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aashlawfirm.com"] [uri "/index.php"] [unique_id "amuaLK469-jfU7M1CLhfkgAAACY"]
[Thu Jul 30 13:38:36.734396 2026] [security2:error] [pid 914912:tid 915103] [client 20.79.29.209:16226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/500.php"] [unique_id "amuaLK469-jfU7M1CLhfnQAAAD0"]
[Thu Jul 30 13:38:36.734517 2026] [security2:error] [pid 914912:tid 915103] [client 20.79.29.209:16226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/500.php"] [unique_id "amuaLK469-jfU7M1CLhfnQAAAD0"]
[Thu Jul 30 13:38:36.776762 2026] [security2:error] [pid 914912:tid 915099] [client 43.153.119.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuaLK469-jfU7M1CLhfnAAAADk"]
[Thu Jul 30 13:38:36.780908 2026] [core:error] [pid 914912:tid 914988] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:36.780934 2026] [core:error] [pid 914912:tid 914988] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:36.796127 2026] [security2:error] [pid 914912:tid 915013] [remote 74.7.227.39:53360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuaLK469-jfU7M1CLhfowAACWQ"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/woo-title-limit/admin
[Thu Jul 30 13:38:37.085197 2026] [security2:error] [pid 914912:tid 915169] [client 20.79.29.209:16185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/77.php"] [unique_id "amuaLa469-jfU7M1CLhfpQAAAH8"]
[Thu Jul 30 13:38:37.085302 2026] [security2:error] [pid 914912:tid 915169] [client 20.79.29.209:16185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/77.php"] [unique_id "amuaLa469-jfU7M1CLhfpQAAAH8"]
[Thu Jul 30 13:38:37.159795 2026] [security2:error] [pid 914912:tid 915126] [client 191.232.199.39:51966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/maint/index.php"] [unique_id "amuaLa469-jfU7M1CLhfqgAAAFQ"]
[Thu Jul 30 13:38:37.176555 2026] [security2:error] [pid 914912:tid 915069] [client 185.177.72.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aashlawfirm.com"] [uri "/index.php"] [unique_id "amuaLa469-jfU7M1CLhfpAAAABs"]
[Thu Jul 30 13:38:37.357832 2026] [security2:error] [pid 914912:tid 915120] [client 20.79.29.209:16191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/76.php"] [unique_id "amuaLa469-jfU7M1CLhfsQAAAE4"]
[Thu Jul 30 13:38:37.357914 2026] [security2:error] [pid 914912:tid 915120] [client 20.79.29.209:16191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/76.php"] [unique_id "amuaLa469-jfU7M1CLhfsQAAAE4"]
[Thu Jul 30 13:38:37.501261 2026] [security2:error] [pid 914912:tid 915147] [client 18.207.129.220:54365] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.dhowcruisedinner.com"] [uri "/wp-login.php"] [unique_id "amuaLa469-jfU7M1CLhfsgAAAGk"]
[Thu Jul 30 13:38:37.513117 2026] [security2:error] [pid 914912:tid 915001] [remote 116.179.32.179:20923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/fr/e-liquide-paquets/index.php"] [unique_id "amuaLa469-jfU7M1CLhfrQAAfFg"]
[Thu Jul 30 13:38:37.549403 2026] [core:error] [pid 914912:tid 915009] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:37.549424 2026] [core:error] [pid 914912:tid 915009] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:37.616787 2026] [security2:error] [pid 914912:tid 915082] [client 20.79.29.209:16238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/74.php"] [unique_id "amuaLa469-jfU7M1CLhftwAAACg"]
[Thu Jul 30 13:38:37.616899 2026] [security2:error] [pid 914912:tid 915082] [client 20.79.29.209:16238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/74.php"] [unique_id "amuaLa469-jfU7M1CLhftwAAACg"]
[Thu Jul 30 13:38:37.955219 2026] [security2:error] [pid 914912:tid 915091] [client 20.79.29.209:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-config.php"] [unique_id "amuaLa469-jfU7M1CLhfvgAAADE"]
[Thu Jul 30 13:38:37.955325 2026] [security2:error] [pid 914912:tid 915091] [client 20.79.29.209:16136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/wp-config.php"] [unique_id "amuaLa469-jfU7M1CLhfvgAAADE"]
[Thu Jul 30 13:38:38.095509 2026] [security2:error] [pid 914912:tid 914966] [remote 94.154.43.177:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "propertyspro.com"] [uri "/.env"] [unique_id "amuaLq469-jfU7M1CLhfvwAALTU"]
[Thu Jul 30 13:38:38.267954 2026] [security2:error] [pid 914912:tid 915152] [client 20.79.29.209:16194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/75.php"] [unique_id "amuaLq469-jfU7M1CLhfxgAAAG4"]
[Thu Jul 30 13:38:38.268079 2026] [security2:error] [pid 914912:tid 915152] [client 20.79.29.209:16194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/75.php"] [unique_id "amuaLq469-jfU7M1CLhfxgAAAG4"]
[Thu Jul 30 13:38:38.324911 2026] [core:error] [pid 914912:tid 914984] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:38.324933 2026] [core:error] [pid 914912:tid 914984] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:38.527734 2026] [security2:error] [pid 914912:tid 915085] [client 20.79.29.209:12253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/71.php"] [unique_id "amuaLq469-jfU7M1CLhfywAAACs"]
[Thu Jul 30 13:38:38.527883 2026] [security2:error] [pid 914912:tid 915085] [client 20.79.29.209:12253] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/71.php"] [unique_id "amuaLq469-jfU7M1CLhfywAAACs"]
[Thu Jul 30 13:38:38.695708 2026] [security2:error] [pid 914912:tid 915073] [client 191.232.199.39:51963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/shell.php"] [unique_id "amuaLq469-jfU7M1CLhf0gAAAB8"]
[Thu Jul 30 13:38:38.825666 2026] [security2:error] [pid 914912:tid 915080] [client 20.79.29.209:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/72.php"] [unique_id "amuaLq469-jfU7M1CLhf1wAAACY"]
[Thu Jul 30 13:38:38.825792 2026] [security2:error] [pid 914912:tid 915080] [client 20.79.29.209:12228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/72.php"] [unique_id "amuaLq469-jfU7M1CLhf1wAAACY"]
[Thu Jul 30 13:38:39.095832 2026] [core:error] [pid 914912:tid 915018] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:39.095865 2026] [core:error] [pid 914912:tid 915018] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:39.115121 2026] [security2:error] [pid 914912:tid 915083] [client 20.79.29.209:16203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/70.php"] [unique_id "amuaL6469-jfU7M1CLhf3AAAACk"]
[Thu Jul 30 13:38:39.115223 2026] [security2:error] [pid 914912:tid 915083] [client 20.79.29.209:16203] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/70.php"] [unique_id "amuaL6469-jfU7M1CLhf3AAAACk"]
[Thu Jul 30 13:38:39.444801 2026] [security2:error] [pid 914912:tid 915067] [client 20.79.29.209:12262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/69.php"] [unique_id "amuaL6469-jfU7M1CLhf5wAAABk"]
[Thu Jul 30 13:38:39.444960 2026] [security2:error] [pid 914912:tid 915067] [client 20.79.29.209:12262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/69.php"] [unique_id "amuaL6469-jfU7M1CLhf5wAAABk"]
[Thu Jul 30 13:38:39.570271 2026] [security2:error] [pid 914912:tid 915046] [client 46.232.235.3:47104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-8880a99c.lld.nyx.temporary.site"] [uri "/.env"] [unique_id "amuaL6469-jfU7M1CLhf6AAAAAQ"]
[Thu Jul 30 13:38:39.715709 2026] [security2:error] [pid 914912:tid 915062] [client 20.79.29.209:16155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/68.php"] [unique_id "amuaL6469-jfU7M1CLhf7AAAABQ"]
[Thu Jul 30 13:38:39.715814 2026] [security2:error] [pid 914912:tid 915062] [client 20.79.29.209:16155] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/68.php"] [unique_id "amuaL6469-jfU7M1CLhf7AAAABQ"]
[Thu Jul 30 13:38:39.886202 2026] [core:error] [pid 914912:tid 915011] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:39.886227 2026] [core:error] [pid 914912:tid 915011] [remote 123.178.210.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:40.095672 2026] [core:error] [pid 914912:tid 915104] [client 46.232.235.3:47114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:40.095700 2026] [core:error] [pid 914912:tid 915104] [client 46.232.235.3:47114] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:40.183524 2026] [security2:error] [pid 914912:tid 915159] [client 20.79.29.209:16137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/66.php"] [unique_id "amuaMK469-jfU7M1CLhf-gAAAHU"]
[Thu Jul 30 13:38:40.183620 2026] [security2:error] [pid 914912:tid 915159] [client 20.79.29.209:16137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/66.php"] [unique_id "amuaMK469-jfU7M1CLhf-gAAAHU"]
[Thu Jul 30 13:38:40.303781 2026] [proxy:error] [pid 914912:tid 915060] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:38:40.303873 2026] [proxy_http:error] [pid 914912:tid 915060] [client 3.225.222.228:61282] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:38:40.304819 2026] [proxy:error] [pid 914912:tid 915060] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:38:40.304876 2026] [proxy_http:error] [pid 914912:tid 915060] [client 3.225.222.228:61282] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:38:40.320375 2026] [proxy:error] [pid 914912:tid 915128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:38:40.320438 2026] [proxy_http:error] [pid 914912:tid 915128] [client 3.225.222.228:37227] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:38:40.321013 2026] [proxy:error] [pid 914912:tid 915128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:38:40.321059 2026] [proxy_http:error] [pid 914912:tid 915128] [client 3.225.222.228:37227] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:38:40.485133 2026] [security2:error] [pid 914912:tid 915153] [client 20.79.29.209:16130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/67.php"] [unique_id "amuaMK469-jfU7M1CLhgCgAAAG8"]
[Thu Jul 30 13:38:40.485253 2026] [security2:error] [pid 914912:tid 915153] [client 20.79.29.209:16130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/67.php"] [unique_id "amuaMK469-jfU7M1CLhgCgAAAG8"]
[Thu Jul 30 13:38:40.513831 2026] [security2:error] [pid 914912:tid 915072] [client 191.232.199.39:51916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/f35.php"] [unique_id "amuaMK469-jfU7M1CLhgDAAAAB4"]
[Thu Jul 30 13:38:40.709423 2026] [security2:error] [pid 914912:tid 915077] [client 82.102.18.188:60652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.oneuro.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuaMK469-jfU7M1CLhgDQAAACM"]
[Thu Jul 30 13:38:40.782517 2026] [security2:error] [pid 914912:tid 915106] [client 50.6.43.217:22020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuaMK469-jfU7M1CLhf9QAAAEA"]
[Thu Jul 30 13:38:40.813370 2026] [security2:error] [pid 914912:tid 915115] [client 20.79.29.209:12227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/65.php"] [unique_id "amuaMK469-jfU7M1CLhgFQAAAEk"]
[Thu Jul 30 13:38:40.813472 2026] [security2:error] [pid 914912:tid 915115] [client 20.79.29.209:12227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/65.php"] [unique_id "amuaMK469-jfU7M1CLhgFQAAAEk"]
[Thu Jul 30 13:38:41.158675 2026] [security2:error] [pid 914912:tid 915075] [client 20.79.29.209:16162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/64.php"] [unique_id "amuaMa469-jfU7M1CLhgHQAAACE"]
[Thu Jul 30 13:38:41.158784 2026] [security2:error] [pid 914912:tid 915075] [client 20.79.29.209:16162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/64.php"] [unique_id "amuaMa469-jfU7M1CLhgHQAAACE"]
[Thu Jul 30 13:38:41.241691 2026] [security2:error] [pid 914912:tid 915129] [client 82.102.18.188:60664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.oneuro.org"] [uri "/xmlrpc.php"] [unique_id "amuaMa469-jfU7M1CLhgHgAAAFc"]
[Thu Jul 30 13:38:41.429231 2026] [security2:error] [pid 914912:tid 915111] [client 20.79.29.209:16235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/63.php"] [unique_id "amuaMa469-jfU7M1CLhgKgAAAEU"]
[Thu Jul 30 13:38:41.429367 2026] [security2:error] [pid 914912:tid 915111] [client 20.79.29.209:16235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/63.php"] [unique_id "amuaMa469-jfU7M1CLhgKgAAAEU"]
[Thu Jul 30 13:38:41.514647 2026] [security2:error] [pid 914912:tid 915110] [client 50.6.43.217:22030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuaMK469-jfU7M1CLhgEgAAAEQ"]
[Thu Jul 30 13:38:41.646126 2026] [security2:error] [pid 914912:tid 915052] [client 66.249.79.136:48760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuaMa469-jfU7M1CLhgHwAAAAo"]
[Thu Jul 30 13:38:41.737963 2026] [security2:error] [pid 914912:tid 915124] [client 20.79.29.209:16190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/62.php"] [unique_id "amuaMa469-jfU7M1CLhgLQAAAFI"]
[Thu Jul 30 13:38:41.738097 2026] [security2:error] [pid 914912:tid 915124] [client 20.79.29.209:16190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/62.php"] [unique_id "amuaMa469-jfU7M1CLhgLQAAAFI"]
[Thu Jul 30 13:38:41.934458 2026] [core:error] [pid 914912:tid 915113] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:41.934491 2026] [core:error] [pid 914912:tid 915113] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:42.142786 2026] [security2:error] [pid 914912:tid 915065] [client 20.79.29.209:12263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/61.php"] [unique_id "amuaMq469-jfU7M1CLhgOwAAABc"]
[Thu Jul 30 13:38:42.142912 2026] [security2:error] [pid 914912:tid 915065] [client 20.79.29.209:12263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/61.php"] [unique_id "amuaMq469-jfU7M1CLhgOwAAABc"]
[Thu Jul 30 13:38:42.449885 2026] [security2:error] [pid 914912:tid 915138] [client 20.79.29.209:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/60.php"] [unique_id "amuaMq469-jfU7M1CLhgRAAAAGA"]
[Thu Jul 30 13:38:42.450005 2026] [security2:error] [pid 914912:tid 915138] [client 20.79.29.209:12231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/60.php"] [unique_id "amuaMq469-jfU7M1CLhgRAAAAGA"]
[Thu Jul 30 13:38:42.589295 2026] [core:notice] [pid 914912:tid 915030] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:42.718625 2026] [security2:error] [pid 914912:tid 915056] [client 20.79.29.209:12267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/58.php"] [unique_id "amuaMq469-jfU7M1CLhgSgAAAA4"]
[Thu Jul 30 13:38:42.718795 2026] [security2:error] [pid 914912:tid 915056] [client 20.79.29.209:12267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/58.php"] [unique_id "amuaMq469-jfU7M1CLhgSgAAAA4"]
[Thu Jul 30 13:38:42.864828 2026] [security2:error] [pid 914912:tid 915050] [client 191.232.199.39:51921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/new.php"] [unique_id "amuaMq469-jfU7M1CLhgSwAAAAg"]
[Thu Jul 30 13:38:43.055240 2026] [security2:error] [pid 914912:tid 915068] [client 20.79.29.209:16199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/59.php"] [unique_id "amuaM6469-jfU7M1CLhgVQAAABo"]
[Thu Jul 30 13:38:43.055351 2026] [security2:error] [pid 914912:tid 915068] [client 20.79.29.209:16199] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/59.php"] [unique_id "amuaM6469-jfU7M1CLhgVQAAABo"]
[Thu Jul 30 13:38:43.215226 2026] [core:notice] [pid 914912:tid 914914] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:43.431283 2026] [security2:error] [pid 914912:tid 915107] [client 20.79.29.209:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/57.php/56.php"] [unique_id "amuaM6469-jfU7M1CLhgWwAAAEE"]
[Thu Jul 30 13:38:43.431397 2026] [security2:error] [pid 914912:tid 915107] [client 20.79.29.209:12245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/57.php/56.php"] [unique_id "amuaM6469-jfU7M1CLhgWwAAAEE"]
[Thu Jul 30 13:38:43.583660 2026] [core:error] [pid 914912:tid 915110] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:43.583681 2026] [core:error] [pid 914912:tid 915110] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:43.710551 2026] [security2:error] [pid 914912:tid 915062] [client 20.79.29.209:16250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/55.php"] [unique_id "amuaM6469-jfU7M1CLhgZAAAABQ"]
[Thu Jul 30 13:38:43.710669 2026] [security2:error] [pid 914912:tid 915062] [client 20.79.29.209:16250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/55.php"] [unique_id "amuaM6469-jfU7M1CLhgZAAAABQ"]
[Thu Jul 30 13:38:43.991608 2026] [security2:error] [pid 914912:tid 915124] [client 20.79.29.209:12184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/54.php"] [unique_id "amuaM6469-jfU7M1CLhgaQAAAFI"]
[Thu Jul 30 13:38:43.991709 2026] [security2:error] [pid 914912:tid 915124] [client 20.79.29.209:12184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/54.php"] [unique_id "amuaM6469-jfU7M1CLhgaQAAAFI"]
[Thu Jul 30 13:38:44.285045 2026] [core:error] [pid 914912:tid 915164] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:44.285067 2026] [core:error] [pid 914912:tid 915164] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:44.406372 2026] [security2:error] [pid 914912:tid 915154] [client 20.79.29.209:16234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/53.php"] [unique_id "amuaNK469-jfU7M1CLhgdQAAAHA"]
[Thu Jul 30 13:38:44.406487 2026] [security2:error] [pid 914912:tid 915154] [client 20.79.29.209:16234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/53.php"] [unique_id "amuaNK469-jfU7M1CLhgdQAAAHA"]
[Thu Jul 30 13:38:44.713283 2026] [security2:error] [pid 914912:tid 915073] [client 20.79.29.209:16141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/52.php"] [unique_id "amuaNK469-jfU7M1CLhgfwAAAB8"]
[Thu Jul 30 13:38:44.713384 2026] [security2:error] [pid 914912:tid 915073] [client 20.79.29.209:16141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/52.php"] [unique_id "amuaNK469-jfU7M1CLhgfwAAAB8"]
[Thu Jul 30 13:38:44.731700 2026] [security2:error] [pid 914912:tid 915057] [client 20.104.18.253:7605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dirs.php"] [unique_id "amuaNK469-jfU7M1CLhggAAAAA8"]
[Thu Jul 30 13:38:44.911143 2026] [security2:error] [pid 914912:tid 915157] [client 46.232.235.3:47118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-8880a99c.lld.nyx.temporary.site"] [uri "/.env"] [unique_id "amuaNK469-jfU7M1CLhghwAAAHM"]
[Thu Jul 30 13:38:44.956061 2026] [core:error] [pid 914912:tid 915148] [client 46.232.235.3:47132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:44.956082 2026] [core:error] [pid 914912:tid 915148] [client 46.232.235.3:47132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:45.019219 2026] [security2:error] [pid 914912:tid 915125] [client 20.79.29.209:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/51.php"] [unique_id "amuaNa469-jfU7M1CLhgiwAAAFM"]
[Thu Jul 30 13:38:45.019323 2026] [security2:error] [pid 914912:tid 915125] [client 20.79.29.209:12241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/51.php"] [unique_id "amuaNa469-jfU7M1CLhgiwAAAFM"]
[Thu Jul 30 13:38:45.231464 2026] [security2:error] [pid 914912:tid 915160] [client 191.232.199.39:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/adminfuns.php"] [unique_id "amuaNa469-jfU7M1CLhglQAAAHY"]
[Thu Jul 30 13:38:45.328579 2026] [security2:error] [pid 914912:tid 915068] [client 20.104.18.253:65481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/disagimons.php"] [unique_id "amuaNa469-jfU7M1CLhglgAAABo"]
[Thu Jul 30 13:38:45.373428 2026] [security2:error] [pid 914912:tid 915169] [client 20.79.29.209:16165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/50.php"] [unique_id "amuaNa469-jfU7M1CLhglwAAAH8"]
[Thu Jul 30 13:38:45.373535 2026] [security2:error] [pid 914912:tid 915169] [client 20.79.29.209:16165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/50.php"] [unique_id "amuaNa469-jfU7M1CLhglwAAAH8"]
[Thu Jul 30 13:38:45.375357 2026] [core:notice] [pid 914912:tid 914929] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:45.655306 2026] [core:notice] [pid 914912:tid 914945] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:45.662792 2026] [security2:error] [pid 914912:tid 915076] [client 20.79.29.209:16161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/49.php"] [unique_id "amuaNa469-jfU7M1CLhgogAAACI"]
[Thu Jul 30 13:38:45.662920 2026] [security2:error] [pid 914912:tid 915076] [client 20.79.29.209:16161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/49.php"] [unique_id "amuaNa469-jfU7M1CLhgogAAACI"]
[Thu Jul 30 13:38:45.668193 2026] [core:error] [pid 914912:tid 915070] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:45.668223 2026] [core:error] [pid 914912:tid 915070] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:45.924466 2026] [security2:error] [pid 914912:tid 915093] [client 20.104.18.253:7608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/disagraeosc.php"] [unique_id "amuaNa469-jfU7M1CLhgqAAAADM"]
[Thu Jul 30 13:38:45.987144 2026] [security2:error] [pid 914912:tid 915121] [client 20.79.29.209:12249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/48.php"] [unique_id "amuaNa469-jfU7M1CLhgqQAAAE8"]
[Thu Jul 30 13:38:45.987251 2026] [security2:error] [pid 914912:tid 915121] [client 20.79.29.209:12249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/48.php"] [unique_id "amuaNa469-jfU7M1CLhgqQAAAE8"]
[Thu Jul 30 13:38:46.051419 2026] [core:error] [pid 914912:tid 915124] [client 158.69.117.45:45894] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:46.051445 2026] [core:error] [pid 914912:tid 915124] [client 158.69.117.45:45894] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:46.127914 2026] [core:error] [pid 914912:tid 915052] [client 158.69.117.45:24319] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:46.127944 2026] [core:error] [pid 914912:tid 915052] [client 158.69.117.45:24319] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:46.218803 2026] [security2:error] [pid 914912:tid 915122] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuaNa469-jfU7M1CLhgnQAAUAk"]
[Thu Jul 30 13:38:46.300353 2026] [security2:error] [pid 914912:tid 915098] [client 78.167.1.90:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaNq469-jfU7M1CLhgtQAAADg"]
[Thu Jul 30 13:38:46.300868 2026] [security2:error] [pid 914912:tid 915098] [client 78.167.1.90:57074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaNq469-jfU7M1CLhgtQAAADg"]
[Thu Jul 30 13:38:46.352499 2026] [security2:error] [pid 914912:tid 915152] [client 20.79.29.209:12272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/47.php"] [unique_id "amuaNq469-jfU7M1CLhgtgAAAG4"]
[Thu Jul 30 13:38:46.352594 2026] [security2:error] [pid 914912:tid 915152] [client 20.79.29.209:12272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/47.php"] [unique_id "amuaNq469-jfU7M1CLhgtgAAAG4"]
[Thu Jul 30 13:38:46.416599 2026] [core:error] [pid 914912:tid 915092] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:46.416623 2026] [core:error] [pid 914912:tid 915092] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:46.508837 2026] [security2:error] [pid 914912:tid 915094] [client 103.82.26.211:51425] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.guardian-heir.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuaNq469-jfU7M1CLhguQAAADQ"]
[Thu Jul 30 13:38:46.521912 2026] [security2:error] [pid 914912:tid 915085] [client 20.104.18.253:7602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/disagreop.php"] [unique_id "amuaNq469-jfU7M1CLhguwAAACs"]
[Thu Jul 30 13:38:46.785111 2026] [core:error] [pid 914912:tid 915090] [client 158.69.117.45:36535] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:46.785134 2026] [core:error] [pid 914912:tid 915090] [client 158.69.117.45:36535] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:46.791335 2026] [security2:error] [pid 914912:tid 915131] [client 20.79.29.209:12232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/46.php"] [unique_id "amuaNq469-jfU7M1CLhgxgAAAFk"]
[Thu Jul 30 13:38:46.791429 2026] [security2:error] [pid 914912:tid 915131] [client 20.79.29.209:12232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/46.php"] [unique_id "amuaNq469-jfU7M1CLhgxgAAAFk"]
[Thu Jul 30 13:38:46.846680 2026] [security2:error] [pid 914912:tid 915168] [client 103.82.26.211:51473] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.guardian-heir.com"] [uri "/___proxy_subdomain_cpanel/wp-json/batch/v1"] [unique_id "amuaNq469-jfU7M1CLhgxwAAAH4"]
[Thu Jul 30 13:38:46.872075 2026] [core:error] [pid 914912:tid 915101] [client 158.69.117.45:56650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:46.872091 2026] [core:error] [pid 914912:tid 915101] [client 158.69.117.45:56650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:47.061829 2026] [security2:error] [pid 914912:tid 915169] [client 20.79.29.209:16152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/44.php"] [unique_id "amuaN6469-jfU7M1CLhgygAAAH8"]
[Thu Jul 30 13:38:47.061939 2026] [security2:error] [pid 914912:tid 915169] [client 20.79.29.209:16152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/44.php"] [unique_id "amuaN6469-jfU7M1CLhgygAAAH8"]
[Thu Jul 30 13:38:47.136441 2026] [core:error] [pid 914912:tid 915067] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:47.136461 2026] [core:error] [pid 914912:tid 915067] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:47.140121 2026] [security2:error] [pid 914912:tid 915119] [client 20.104.18.253:7577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/about.php"] [unique_id "amuaN6469-jfU7M1CLhgzwAAAE0"]
[Thu Jul 30 13:38:47.365400 2026] [security2:error] [pid 914912:tid 915059] [client 20.79.29.209:16180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/43.php"] [unique_id "amuaN6469-jfU7M1CLhg2AAAABE"]
[Thu Jul 30 13:38:47.365519 2026] [security2:error] [pid 914912:tid 915059] [client 20.79.29.209:16180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/43.php"] [unique_id "amuaN6469-jfU7M1CLhg2AAAABE"]
[Thu Jul 30 13:38:47.600867 2026] [security2:error] [pid 914912:tid 915112] [client 191.232.199.39:51923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/fm.php"] [unique_id "amuaN6469-jfU7M1CLhg2gAAAEY"]
[Thu Jul 30 13:38:47.742854 2026] [security2:error] [pid 914912:tid 915095] [client 20.104.18.253:7584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/alfa-rex.php"] [unique_id "amuaN6469-jfU7M1CLhg4QAAADU"]
[Thu Jul 30 13:38:47.782627 2026] [security2:error] [pid 914912:tid 915158] [client 20.79.29.209:16167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/42.php"] [unique_id "amuaN6469-jfU7M1CLhg5QAAAHQ"]
[Thu Jul 30 13:38:47.782733 2026] [security2:error] [pid 914912:tid 915158] [client 20.79.29.209:16167] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/42.php"] [unique_id "amuaN6469-jfU7M1CLhg5QAAAHQ"]
[Thu Jul 30 13:38:47.888234 2026] [core:error] [pid 914912:tid 915098] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:47.888257 2026] [core:error] [pid 914912:tid 915098] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:47.974250 2026] [fcgid:warn] [pid 914912:tid 915092] (70014)End of file found: [client 172.237.109.114:59495] mod_fcgid: can't get data from http client
[Thu Jul 30 13:38:48.077553 2026] [security2:error] [pid 914912:tid 915057] [client 20.79.29.209:16151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/41.php"] [unique_id "amuaOK469-jfU7M1CLhg6gAAAA8"]
[Thu Jul 30 13:38:48.077663 2026] [security2:error] [pid 914912:tid 915057] [client 20.79.29.209:16151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/41.php"] [unique_id "amuaOK469-jfU7M1CLhg6gAAAA8"]
[Thu Jul 30 13:38:48.268010 2026] [security2:error] [pid 914912:tid 915121] [client 213.180.203.86:38236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuaN6469-jfU7M1CLhg6QAAAE8"]
[Thu Jul 30 13:38:48.337077 2026] [security2:error] [pid 914912:tid 915106] [client 20.104.18.253:7570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/autoload_classmap.php"] [unique_id "amuaOK469-jfU7M1CLhg9AAAAEA"]
[Thu Jul 30 13:38:48.353903 2026] [security2:error] [pid 914912:tid 915049] [client 20.79.29.209:12254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/40.php"] [unique_id "amuaOK469-jfU7M1CLhg9QAAAAc"]
[Thu Jul 30 13:38:48.354007 2026] [security2:error] [pid 914912:tid 915049] [client 20.79.29.209:12254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/40.php"] [unique_id "amuaOK469-jfU7M1CLhg9QAAAAc"]
[Thu Jul 30 13:38:48.580108 2026] [core:error] [pid 914912:tid 915136] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:48.580132 2026] [core:error] [pid 914912:tid 915136] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:48.745356 2026] [security2:error] [pid 914912:tid 915090] [client 20.79.29.209:16176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/39.php"] [unique_id "amuaOK469-jfU7M1CLhg_QAAADA"]
[Thu Jul 30 13:38:48.745492 2026] [security2:error] [pid 914912:tid 915090] [client 20.79.29.209:16176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/39.php"] [unique_id "amuaOK469-jfU7M1CLhg_QAAADA"]
[Thu Jul 30 13:38:48.760609 2026] [security2:error] [pid 914912:tid 915131] [client 139.28.219.70:58772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "pkf.jo"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuaOK469-jfU7M1CLhg_gAAAFk"]
[Thu Jul 30 13:38:48.934953 2026] [security2:error] [pid 914912:tid 915099] [client 20.104.18.253:7563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/block-library/admin.php"] [unique_id "amuaOK469-jfU7M1CLhhAgAAADk"]
[Thu Jul 30 13:38:49.073649 2026] [security2:error] [pid 914912:tid 915061] [client 20.79.29.209:12226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/38.php"] [unique_id "amuaOa469-jfU7M1CLhhAwAAABM"]
[Thu Jul 30 13:38:49.073760 2026] [security2:error] [pid 914912:tid 915061] [client 20.79.29.209:12226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/38.php"] [unique_id "amuaOa469-jfU7M1CLhhAwAAABM"]
[Thu Jul 30 13:38:49.295315 2026] [core:error] [pid 914912:tid 915132] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:49.295336 2026] [core:error] [pid 914912:tid 915132] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:49.372304 2026] [security2:error] [pid 914912:tid 915059] [client 20.79.29.209:12282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/37.php"] [unique_id "amuaOa469-jfU7M1CLhhEgAAABE"]
[Thu Jul 30 13:38:49.372407 2026] [security2:error] [pid 914912:tid 915059] [client 20.79.29.209:12282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/37.php"] [unique_id "amuaOa469-jfU7M1CLhhEgAAABE"]
[Thu Jul 30 13:38:49.533291 2026] [security2:error] [pid 914912:tid 915045] [client 20.104.18.253:7607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/components/about.php"] [unique_id "amuaOa469-jfU7M1CLhhEwAAAAM"]
[Thu Jul 30 13:38:49.697286 2026] [security2:error] [pid 914912:tid 915167] [client 20.79.29.209:16237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/36.php"] [unique_id "amuaOa469-jfU7M1CLhhFAAAAH0"]
[Thu Jul 30 13:38:49.697440 2026] [security2:error] [pid 914912:tid 915167] [client 20.79.29.209:16237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/36.php"] [unique_id "amuaOa469-jfU7M1CLhhFAAAAH0"]
[Thu Jul 30 13:38:50.022204 2026] [security2:error] [pid 914912:tid 915152] [client 20.79.29.209:16248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/35.php"] [unique_id "amuaOq469-jfU7M1CLhhHwAAAG4"]
[Thu Jul 30 13:38:50.022329 2026] [security2:error] [pid 914912:tid 915152] [client 20.79.29.209:16248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/35.php"] [unique_id "amuaOq469-jfU7M1CLhhHwAAAG4"]
[Thu Jul 30 13:38:50.039578 2026] [core:error] [pid 914912:tid 915074] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:50.039598 2026] [core:error] [pid 914912:tid 915074] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:50.129673 2026] [security2:error] [pid 914912:tid 915105] [client 20.104.18.253:7553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/default.php"] [unique_id "amuaOq469-jfU7M1CLhhIwAAAD8"]
[Thu Jul 30 13:38:50.300201 2026] [security2:error] [pid 914912:tid 915115] [client 20.79.29.209:12210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/34.php"] [unique_id "amuaOq469-jfU7M1CLhhKgAAAEk"]
[Thu Jul 30 13:38:50.300345 2026] [security2:error] [pid 914912:tid 915115] [client 20.79.29.209:12210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/34.php"] [unique_id "amuaOq469-jfU7M1CLhhKgAAAEk"]
[Thu Jul 30 13:38:50.582189 2026] [security2:error] [pid 914912:tid 915136] [client 20.79.29.209:12166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/33.php"] [unique_id "amuaOq469-jfU7M1CLhhMwAAAF4"]
[Thu Jul 30 13:38:50.582345 2026] [security2:error] [pid 914912:tid 915136] [client 20.79.29.209:12166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/33.php"] [unique_id "amuaOq469-jfU7M1CLhhMwAAAF4"]
[Thu Jul 30 13:38:50.607445 2026] [security2:error] [pid 914912:tid 915116] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuaOa469-jfU7M1CLhhHgAASi4"]
[Thu Jul 30 13:38:50.617640 2026] [security2:error] [pid 914912:tid 915128] [client 172.237.109.114:3595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaOq469-jfU7M1CLhhIQAAAFY"]
[Thu Jul 30 13:38:50.714992 2026] [security2:error] [pid 914912:tid 915098] [client 172.237.109.114:43290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaOq469-jfU7M1CLhhIgAAADg"]
[Thu Jul 30 13:38:50.728256 2026] [security2:error] [pid 914912:tid 915078] [client 20.104.18.253:65489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/edit-site/about.php"] [unique_id "amuaOq469-jfU7M1CLhhNAAAACQ"]
[Thu Jul 30 13:38:50.779560 2026] [core:error] [pid 914912:tid 915131] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:50.779582 2026] [core:error] [pid 914912:tid 915131] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:50.970190 2026] [security2:error] [pid 914912:tid 915087] [client 20.79.29.209:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/25.php"] [unique_id "amuaOq469-jfU7M1CLhhPwAAAC0"]
[Thu Jul 30 13:38:50.970289 2026] [security2:error] [pid 914912:tid 915087] [client 20.79.29.209:16175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/25.php"] [unique_id "amuaOq469-jfU7M1CLhhPwAAAC0"]
[Thu Jul 30 13:38:51.088152 2026] [security2:error] [pid 914912:tid 915046] [client 191.232.199.39:51907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/file.php"] [unique_id "amuaO6469-jfU7M1CLhhQgAAAAQ"]
[Thu Jul 30 13:38:51.268072 2026] [security2:error] [pid 914912:tid 915081] [client 20.79.29.209:16212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/24.php"] [unique_id "amuaO6469-jfU7M1CLhhTwAAACc"]
[Thu Jul 30 13:38:51.268214 2026] [security2:error] [pid 914912:tid 915081] [client 20.79.29.209:16212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/24.php"] [unique_id "amuaO6469-jfU7M1CLhhTwAAACc"]
[Thu Jul 30 13:38:51.333517 2026] [security2:error] [pid 914912:tid 915123] [client 20.104.18.253:7557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/edit-widgets/about.php"] [unique_id "amuaO6469-jfU7M1CLhhUgAAAFE"]
[Thu Jul 30 13:38:51.491689 2026] [core:error] [pid 914912:tid 915112] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:51.491729 2026] [core:error] [pid 914912:tid 915112] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:51.577396 2026] [security2:error] [pid 914912:tid 915043] [client 20.79.29.209:12225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/15.php"] [unique_id "amuaO6469-jfU7M1CLhhWgAAAAE"]
[Thu Jul 30 13:38:51.577550 2026] [security2:error] [pid 914912:tid 915043] [client 20.79.29.209:12225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/15.php"] [unique_id "amuaO6469-jfU7M1CLhhWgAAAAE"]
[Thu Jul 30 13:38:51.711682 2026] [security2:error] [pid 914912:tid 915099] [client 172.237.109.114:39765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhQQAAADk"]
[Thu Jul 30 13:38:51.712504 2026] [security2:error] [pid 914912:tid 915107] [client 172.237.109.114:46287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhQwAAAEE"]
[Thu Jul 30 13:38:51.821251 2026] [security2:error] [pid 914912:tid 915111] [client 172.237.109.114:4132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhRQAAAEU"]
[Thu Jul 30 13:38:51.821274 2026] [security2:error] [pid 914912:tid 915127] [client 172.237.109.114:11089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhSQAAAFU"]
[Thu Jul 30 13:38:51.824164 2026] [security2:error] [pid 914912:tid 915061] [client 172.237.109.114:7928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhRAAAABM"]
[Thu Jul 30 13:38:51.929177 2026] [security2:error] [pid 914912:tid 915155] [client 20.104.18.253:65487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/edit-widgets/index.php"] [unique_id "amuaO6469-jfU7M1CLhhaAAAAHE"]
[Thu Jul 30 13:38:51.932618 2026] [security2:error] [pid 914912:tid 915080] [client 82.102.18.188:60670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.oneuro.org"] [uri "/xmlrpc.php"] [unique_id "amuaO6469-jfU7M1CLhhaQAAACY"]
[Thu Jul 30 13:38:51.932711 2026] [security2:error] [pid 914912:tid 915080] [client 82.102.18.188:60670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.oneuro.org"] [uri "/xmlrpc.php"] [unique_id "amuaO6469-jfU7M1CLhhaQAAACY"]
[Thu Jul 30 13:38:51.934458 2026] [security2:error] [pid 914912:tid 915085] [client 20.79.29.209:16159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/123456.php"] [unique_id "amuaO6469-jfU7M1CLhhagAAACs"]
[Thu Jul 30 13:38:51.934574 2026] [security2:error] [pid 914912:tid 915085] [client 20.79.29.209:16159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/123456.php"] [unique_id "amuaO6469-jfU7M1CLhhagAAACs"]
[Thu Jul 30 13:38:52.195802 2026] [core:error] [pid 914912:tid 915063] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:52.195829 2026] [core:error] [pid 914912:tid 915063] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:52.216989 2026] [security2:error] [pid 914912:tid 915055] [client 172.237.109.114:12087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhSgAAAA0"]
[Thu Jul 30 13:38:52.226578 2026] [security2:error] [pid 914912:tid 915119] [client 172.237.109.114:57722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhRgAAAE0"]
[Thu Jul 30 13:38:52.247750 2026] [security2:error] [pid 914912:tid 915120] [client 172.237.109.114:27927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhSAAAAE4"]
[Thu Jul 30 13:38:52.248451 2026] [security2:error] [pid 914912:tid 915067] [client 172.237.109.114:44307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhRwAAABk"]
[Thu Jul 30 13:38:52.265770 2026] [security2:error] [pid 914912:tid 915166] [client 172.237.109.114:40708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhTAAAAHw"]
[Thu Jul 30 13:38:52.272954 2026] [security2:error] [pid 914912:tid 915161] [client 172.237.109.114:3874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaO6469-jfU7M1CLhhSwAAAHc"]
[Thu Jul 30 13:38:52.294261 2026] [security2:error] [pid 914912:tid 915168] [client 20.79.29.209:16251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/12345.php"] [unique_id "amuaPK469-jfU7M1CLhhdgAAAH4"]
[Thu Jul 30 13:38:52.294389 2026] [security2:error] [pid 914912:tid 915168] [client 20.79.29.209:16251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/12345.php"] [unique_id "amuaPK469-jfU7M1CLhhdgAAAH4"]
[Thu Jul 30 13:38:52.524915 2026] [security2:error] [pid 914912:tid 915129] [client 20.104.18.253:7559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/list-reusable-blocks/themes.php"] [unique_id "amuaPK469-jfU7M1CLhhgQAAAFc"]
[Thu Jul 30 13:38:52.567506 2026] [security2:error] [pid 914912:tid 915054] [client 20.79.29.209:16218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/1234.php"] [unique_id "amuaPK469-jfU7M1CLhhggAAAAw"]
[Thu Jul 30 13:38:52.567668 2026] [security2:error] [pid 914912:tid 915054] [client 20.79.29.209:16218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/1234.php"] [unique_id "amuaPK469-jfU7M1CLhhggAAAAw"]
[Thu Jul 30 13:38:52.783337 2026] [security2:error] [pid 914912:tid 915148] [client 172.237.109.114:38118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaPK469-jfU7M1CLhhbgAAAGo"]
[Thu Jul 30 13:38:52.787851 2026] [security2:error] [pid 914912:tid 915125] [client 172.237.109.114:48363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaPK469-jfU7M1CLhhcQAAAFM"]
[Thu Jul 30 13:38:52.800373 2026] [security2:error] [pid 914912:tid 915146] [client 172.237.109.114:10857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaPK469-jfU7M1CLhhcAAAAGg"]
[Thu Jul 30 13:38:52.800665 2026] [security2:error] [pid 914912:tid 915052] [client 172.237.109.114:11302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaPK469-jfU7M1CLhhdAAAAAo"]
[Thu Jul 30 13:38:52.808162 2026] [security2:error] [pid 914912:tid 915138] [client 172.237.109.114:57645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaPK469-jfU7M1CLhhcwAAAGA"]
[Thu Jul 30 13:38:52.822622 2026] [security2:error] [pid 914912:tid 915083] [client 172.237.109.114:30217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaPK469-jfU7M1CLhhbwAAACk"]
[Thu Jul 30 13:38:52.886808 2026] [security2:error] [pid 914912:tid 915113] [client 172.237.109.114:52756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaPK469-jfU7M1CLhhcgAAAEc"]
[Thu Jul 30 13:38:52.929067 2026] [security2:error] [pid 914912:tid 915045] [client 20.79.29.209:16184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/10.php"] [unique_id "amuaPK469-jfU7M1CLhhhgAAAAM"]
[Thu Jul 30 13:38:52.929158 2026] [security2:error] [pid 914912:tid 915045] [client 20.79.29.209:16184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/10.php"] [unique_id "amuaPK469-jfU7M1CLhhhgAAAAM"]
[Thu Jul 30 13:38:52.939696 2026] [security2:error] [pid 914912:tid 915112] [client 139.28.219.70:46098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/xmlrpc.php"] [unique_id "amuaPK469-jfU7M1CLhhiAAAAEY"]
[Thu Jul 30 13:38:52.939781 2026] [security2:error] [pid 914912:tid 915112] [client 139.28.219.70:46098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pkf.jo"] [uri "/xmlrpc.php"] [unique_id "amuaPK469-jfU7M1CLhhiAAAAEY"]
[Thu Jul 30 13:38:52.942201 2026] [core:error] [pid 914912:tid 915159] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:52.942218 2026] [core:error] [pid 914912:tid 915159] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:53.127862 2026] [security2:error] [pid 914912:tid 915093] [client 20.104.18.253:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/niil.php"] [unique_id "amuaPa469-jfU7M1CLhhjwAAADM"]
[Thu Jul 30 13:38:53.308953 2026] [security2:error] [pid 914912:tid 915092] [client 20.79.29.209:16216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/9.php"] [unique_id "amuaPa469-jfU7M1CLhhkAAAADI"]
[Thu Jul 30 13:38:53.309073 2026] [security2:error] [pid 914912:tid 915092] [client 20.79.29.209:16216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/9.php"] [unique_id "amuaPa469-jfU7M1CLhhkAAAADI"]
[Thu Jul 30 13:38:53.639850 2026] [core:error] [pid 914912:tid 915145] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:53.639872 2026] [core:error] [pid 914912:tid 915145] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:53.643554 2026] [security2:error] [pid 914912:tid 915102] [client 20.79.29.209:12273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/8.php"] [unique_id "amuaPa469-jfU7M1CLhhmwAAADw"]
[Thu Jul 30 13:38:53.643628 2026] [security2:error] [pid 914912:tid 915102] [client 20.79.29.209:12273] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/8.php"] [unique_id "amuaPa469-jfU7M1CLhhmwAAADw"]
[Thu Jul 30 13:38:53.726758 2026] [security2:error] [pid 914912:tid 915109] [client 20.104.18.253:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/test.php"] [unique_id "amuaPa469-jfU7M1CLhhnAAAAEM"]
[Thu Jul 30 13:38:53.994143 2026] [security2:error] [pid 914912:tid 915078] [client 20.79.29.209:16225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/7.php"] [unique_id "amuaPa469-jfU7M1CLhhoAAAACQ"]
[Thu Jul 30 13:38:53.994240 2026] [security2:error] [pid 914912:tid 915078] [client 20.79.29.209:16225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/7.php"] [unique_id "amuaPa469-jfU7M1CLhhoAAAACQ"]
[Thu Jul 30 13:38:54.282089 2026] [security2:error] [pid 914912:tid 915087] [client 20.79.29.209:12252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/6.php"] [unique_id "amuaPq469-jfU7M1CLhhqwAAAC0"]
[Thu Jul 30 13:38:54.282196 2026] [security2:error] [pid 914912:tid 915087] [client 20.79.29.209:12252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/6.php"] [unique_id "amuaPq469-jfU7M1CLhhqwAAAC0"]
[Thu Jul 30 13:38:54.333056 2026] [security2:error] [pid 914912:tid 915047] [client 20.104.18.253:7552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/vendor/vcard.php"] [unique_id "amuaPq469-jfU7M1CLhhrAAAAAU"]
[Thu Jul 30 13:38:54.344852 2026] [core:error] [pid 914912:tid 915141] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:54.344870 2026] [core:error] [pid 914912:tid 915141] [client 118.212.120.213:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:54.564565 2026] [security2:error] [pid 914912:tid 915089] [client 20.79.29.209:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/5.php"] [unique_id "amuaPq469-jfU7M1CLhhtAAAAC8"]
[Thu Jul 30 13:38:54.564672 2026] [security2:error] [pid 914912:tid 915089] [client 20.79.29.209:12240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/5.php"] [unique_id "amuaPq469-jfU7M1CLhhtAAAAC8"]
[Thu Jul 30 13:38:54.788428 2026] [security2:error] [pid 914912:tid 915138] [client 191.232.199.39:35925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/bolt.php"] [unique_id "amuaPq469-jfU7M1CLhhuAAAAGA"]
[Thu Jul 30 13:38:54.840923 2026] [security2:error] [pid 914912:tid 915083] [client 20.79.29.209:12102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/4.php"] [unique_id "amuaPq469-jfU7M1CLhhuQAAACk"]
[Thu Jul 30 13:38:54.841049 2026] [security2:error] [pid 914912:tid 915083] [client 20.79.29.209:12102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/4.php"] [unique_id "amuaPq469-jfU7M1CLhhuQAAACk"]
[Thu Jul 30 13:38:54.881824 2026] [security2:error] [pid 914912:tid 914977] [remote 72.167.132.114:38758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lld.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuaPq469-jfU7M1CLhhugAAIUA"]
[Thu Jul 30 13:38:54.930962 2026] [security2:error] [pid 914912:tid 915146] [client 74.7.175.169:57180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-e66db2d4.sby.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuaPq469-jfU7M1CLhhuwAAAGg"]
[Thu Jul 30 13:38:54.934206 2026] [security2:error] [pid 914912:tid 915052] [client 20.104.18.253:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/widgets/about.php"] [unique_id "amuaPq469-jfU7M1CLhhvAAAAAo"]
[Thu Jul 30 13:38:55.063314 2026] [security2:error] [pid 914912:tid 914966] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuaP6469-jfU7M1CLhhwQAAUTU"]
[Thu Jul 30 13:38:55.063470 2026] [security2:error] [pid 914912:tid 915123] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuaP6469-jfU7M1CLhhwQAAUTU"]
[Thu Jul 30 13:38:55.199045 2026] [security2:error] [pid 914912:tid 915124] [client 20.79.29.209:12234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/3.php"] [unique_id "amuaP6469-jfU7M1CLhhywAAAFI"]
[Thu Jul 30 13:38:55.199182 2026] [security2:error] [pid 914912:tid 915124] [client 20.79.29.209:12234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/3.php"] [unique_id "amuaP6469-jfU7M1CLhhywAAAFI"]
[Thu Jul 30 13:38:55.483673 2026] [security2:error] [pid 914912:tid 915165] [client 20.79.29.209:12251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/2.php"] [unique_id "amuaP6469-jfU7M1CLhh0AAAAHs"]
[Thu Jul 30 13:38:55.483818 2026] [security2:error] [pid 914912:tid 915165] [client 20.79.29.209:12251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/2.php"] [unique_id "amuaP6469-jfU7M1CLhh0AAAAHs"]
[Thu Jul 30 13:38:55.559275 2026] [security2:error] [pid 914912:tid 914984] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuaP6469-jfU7M1CLhh1wAAH0c"]
[Thu Jul 30 13:38:55.559470 2026] [security2:error] [pid 914912:tid 915073] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuaP6469-jfU7M1CLhh1wAAH0c"]
[Thu Jul 30 13:38:55.746423 2026] [security2:error] [pid 914912:tid 915050] [client 20.79.29.209:12255] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.kevinderarslanian.com"] [uri "/1.php"] [unique_id "amuaP6469-jfU7M1CLhh2wAAAAg"]
[Thu Jul 30 13:38:55.746565 2026] [security2:error] [pid 914912:tid 915050] [client 20.79.29.209:12255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/1.php"] [unique_id "amuaP6469-jfU7M1CLhh2wAAAAg"]
[Thu Jul 30 13:38:55.746674 2026] [security2:error] [pid 914912:tid 915050] [client 20.79.29.209:12255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/1.php"] [unique_id "amuaP6469-jfU7M1CLhh2wAAAAg"]
[Thu Jul 30 13:38:55.801459 2026] [security2:error] [pid 914912:tid 915158] [client 20.104.18.253:7611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dist/wp-login.php"] [unique_id "amuaP6469-jfU7M1CLhh1AAAAHQ"]
[Thu Jul 30 13:38:56.056010 2026] [security2:error] [pid 914912:tid 915058] [client 20.79.29.209:12199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/0.php"] [unique_id "amuaQK469-jfU7M1CLhh3wAAABA"]
[Thu Jul 30 13:38:56.056090 2026] [security2:error] [pid 914912:tid 915058] [client 20.79.29.209:12199] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/0.php"] [unique_id "amuaQK469-jfU7M1CLhh3wAAABA"]
[Thu Jul 30 13:38:56.089388 2026] [core:notice] [pid 914912:tid 915023] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:56.169848 2026] [core:notice] [pid 914912:tid 914953] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:56.293664 2026] [security2:error] [pid 914912:tid 915022] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuaQK469-jfU7M1CLhh6AAAEm0"]
[Thu Jul 30 13:38:56.293926 2026] [security2:error] [pid 914912:tid 915060] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuaQK469-jfU7M1CLhh6AAAEm0"]
[Thu Jul 30 13:38:56.360356 2026] [security2:error] [pid 914912:tid 915090] [client 20.79.29.209:16193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/z.php"] [unique_id "amuaQK469-jfU7M1CLhh6QAAADA"]
[Thu Jul 30 13:38:56.360471 2026] [security2:error] [pid 914912:tid 915090] [client 20.79.29.209:16193] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/z.php"] [unique_id "amuaQK469-jfU7M1CLhh6QAAADA"]
[Thu Jul 30 13:38:56.397525 2026] [security2:error] [pid 914912:tid 915136] [client 20.104.18.253:65473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/distadmin.php"] [unique_id "amuaQK469-jfU7M1CLhh6gAAAF4"]
[Thu Jul 30 13:38:56.470102 2026] [security2:error] [pid 914912:tid 914921] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/err.php"] [unique_id "amuaQK469-jfU7M1CLhh6wAACQg"]
[Thu Jul 30 13:38:56.470388 2026] [security2:error] [pid 914912:tid 915051] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/err.php"] [unique_id "amuaQK469-jfU7M1CLhh6wAACQg"]
[Thu Jul 30 13:38:56.682210 2026] [security2:error] [pid 914912:tid 915029] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/img.php"] [unique_id "amuaQK469-jfU7M1CLhh8gAAeHQ"]
[Thu Jul 30 13:38:56.682467 2026] [security2:error] [pid 914912:tid 915162] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/img.php"] [unique_id "amuaQK469-jfU7M1CLhh8gAAeHQ"]
[Thu Jul 30 13:38:56.730492 2026] [security2:error] [pid 914912:tid 915081] [client 20.79.29.209:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/y.php"] [unique_id "amuaQK469-jfU7M1CLhh9gAAACc"]
[Thu Jul 30 13:38:56.730595 2026] [security2:error] [pid 914912:tid 915081] [client 20.79.29.209:12177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/y.php"] [unique_id "amuaQK469-jfU7M1CLhh9gAAACc"]
[Thu Jul 30 13:38:56.885466 2026] [security2:error] [pid 914912:tid 915011] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/aa.php"] [unique_id "amuaQK469-jfU7M1CLhh9wAAaWI"]
[Thu Jul 30 13:38:56.885661 2026] [security2:error] [pid 914912:tid 915147] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/aa.php"] [unique_id "amuaQK469-jfU7M1CLhh9wAAaWI"]
[Thu Jul 30 13:38:56.994505 2026] [security2:error] [pid 914912:tid 915059] [client 20.79.29.209:12233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/x.php"] [unique_id "amuaQK469-jfU7M1CLhh-AAAABE"]
[Thu Jul 30 13:38:56.994618 2026] [security2:error] [pid 914912:tid 915059] [client 20.79.29.209:12233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/x.php"] [unique_id "amuaQK469-jfU7M1CLhh-AAAABE"]
[Thu Jul 30 13:38:57.000824 2026] [security2:error] [pid 914912:tid 915076] [client 20.104.18.253:7580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/distalfa.php"] [unique_id "amuaQa469-jfU7M1CLhh-QAAACI"]
[Thu Jul 30 13:38:57.066082 2026] [security2:error] [pid 914912:tid 915032] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/av.php"] [unique_id "amuaQa469-jfU7M1CLhh_QAAKXc"]
[Thu Jul 30 13:38:57.066246 2026] [security2:error] [pid 914912:tid 915083] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/av.php"] [unique_id "amuaQa469-jfU7M1CLhh_QAAKXc"]
[Thu Jul 30 13:38:57.239833 2026] [security2:error] [pid 914912:tid 915039] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/xa.php"] [unique_id "amuaQa469-jfU7M1CLhiBAAAS34"]
[Thu Jul 30 13:38:57.240027 2026] [security2:error] [pid 914912:tid 915117] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/xa.php"] [unique_id "amuaQa469-jfU7M1CLhiBAAAS34"]
[Thu Jul 30 13:38:57.259955 2026] [core:error] [pid 914912:tid 915002] [remote 216.73.217.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:57.259985 2026] [core:error] [pid 914912:tid 915002] [remote 216.73.217.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:38:57.336106 2026] [security2:error] [pid 914912:tid 915122] [client 20.79.29.209:12176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/w.php"] [unique_id "amuaQa469-jfU7M1CLhiCQAAAFA"]
[Thu Jul 30 13:38:57.336203 2026] [security2:error] [pid 914912:tid 915122] [client 20.79.29.209:12176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/w.php"] [unique_id "amuaQa469-jfU7M1CLhiCQAAAFA"]
[Thu Jul 30 13:38:57.359381 2026] [security2:error] [pid 914912:tid 915148] [client 137.184.64.22:57180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "kicksity.com"] [uri "/xmlrpc.php"] [unique_id "amuaQa469-jfU7M1CLhiCgAAAGo"]
[Thu Jul 30 13:38:57.359487 2026] [security2:error] [pid 914912:tid 915148] [client 137.184.64.22:57180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kicksity.com"] [uri "/xmlrpc.php"] [unique_id "amuaQa469-jfU7M1CLhiCgAAAGo"]
[Thu Jul 30 13:38:57.437057 2026] [security2:error] [pid 914912:tid 915036] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/media.php"] [unique_id "amuaQa469-jfU7M1CLhiCwAAQXs"]
[Thu Jul 30 13:38:57.437333 2026] [security2:error] [pid 914912:tid 915107] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/media.php"] [unique_id "amuaQa469-jfU7M1CLhiCwAAQXs"]
[Thu Jul 30 13:38:57.599247 2026] [security2:error] [pid 914912:tid 915099] [client 20.104.18.253:7578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/distbypass.php"] [unique_id "amuaQa469-jfU7M1CLhiDgAAADk"]
[Thu Jul 30 13:38:57.619238 2026] [security2:error] [pid 914912:tid 915152] [client 20.79.29.209:12189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/v.php"] [unique_id "amuaQa469-jfU7M1CLhiEAAAAG4"]
[Thu Jul 30 13:38:57.619346 2026] [security2:error] [pid 914912:tid 915152] [client 20.79.29.209:12189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/v.php"] [unique_id "amuaQa469-jfU7M1CLhiEAAAAG4"]
[Thu Jul 30 13:38:57.884881 2026] [security2:error] [pid 914912:tid 915085] [client 20.79.29.209:12256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/u.php"] [unique_id "amuaQa469-jfU7M1CLhiGAAAACs"]
[Thu Jul 30 13:38:57.885008 2026] [security2:error] [pid 914912:tid 915085] [client 20.79.29.209:12256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/u.php"] [unique_id "amuaQa469-jfU7M1CLhiGAAAACs"]
[Thu Jul 30 13:38:57.957507 2026] [security2:error] [pid 914912:tid 915115] [client 78.167.1.90:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaQa469-jfU7M1CLhiGgAAAEk"]
[Thu Jul 30 13:38:57.958084 2026] [security2:error] [pid 914912:tid 915115] [client 78.167.1.90:54714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaQa469-jfU7M1CLhiGgAAAEk"]
[Thu Jul 30 13:38:58.182756 2026] [security2:error] [pid 914912:tid 915078] [client 20.79.29.209:12283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/s.php"] [unique_id "amuaQq469-jfU7M1CLhiIgAAACQ"]
[Thu Jul 30 13:38:58.182861 2026] [security2:error] [pid 914912:tid 915078] [client 20.79.29.209:12283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/s.php"] [unique_id "amuaQq469-jfU7M1CLhiIgAAACQ"]
[Thu Jul 30 13:38:58.224828 2026] [security2:error] [pid 914912:tid 915110] [client 20.104.18.253:65411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/distk.php"] [unique_id "amuaQq469-jfU7M1CLhiIwAAAEQ"]
[Thu Jul 30 13:38:58.502941 2026] [security2:error] [pid 914912:tid 915166] [client 20.79.29.209:12258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/t.php"] [unique_id "amuaQq469-jfU7M1CLhiKAAAAHw"]
[Thu Jul 30 13:38:58.503070 2026] [security2:error] [pid 914912:tid 915166] [client 20.79.29.209:12258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/t.php"] [unique_id "amuaQq469-jfU7M1CLhiKAAAAHw"]
[Thu Jul 30 13:38:58.509270 2026] [core:notice] [pid 914912:tid 914923] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:58.550856 2026] [security2:error] [pid 914912:tid 915157] [client 191.232.199.39:24077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/3.php"] [unique_id "amuaQq469-jfU7M1CLhiKgAAAHM"]
[Thu Jul 30 13:38:58.784273 2026] [security2:error] [pid 914912:tid 915046] [client 20.79.29.209:16158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/r.php"] [unique_id "amuaQq469-jfU7M1CLhiNAAAAAQ"]
[Thu Jul 30 13:38:58.784372 2026] [security2:error] [pid 914912:tid 915046] [client 20.79.29.209:16158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/r.php"] [unique_id "amuaQq469-jfU7M1CLhiNAAAAAQ"]
[Thu Jul 30 13:38:58.822851 2026] [security2:error] [pid 914912:tid 915066] [client 20.104.18.253:7583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/distwp.php"] [unique_id "amuaQq469-jfU7M1CLhiNQAAABg"]
[Thu Jul 30 13:38:59.004621 2026] [security2:error] [pid 914912:tid 915096] [client 178.156.187.238:32106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuaQa469-jfU7M1CLhiFAAAADY"], referer: https://globalmarks.pk/
[Thu Jul 30 13:38:59.179625 2026] [security2:error] [pid 914912:tid 915068] [client 20.79.29.209:12101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/q.php"] [unique_id "amuaQ6469-jfU7M1CLhiPwAAABo"]
[Thu Jul 30 13:38:59.179726 2026] [security2:error] [pid 914912:tid 915068] [client 20.79.29.209:12101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/q.php"] [unique_id "amuaQ6469-jfU7M1CLhiPwAAABo"]
[Thu Jul 30 13:38:59.427161 2026] [security2:error] [pid 914912:tid 915044] [client 20.104.18.253:65521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/doc.php"] [unique_id "amuaQ6469-jfU7M1CLhiRwAAAAI"]
[Thu Jul 30 13:38:59.469171 2026] [security2:error] [pid 914912:tid 915084] [client 74.7.228.6:33048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.essenceeast.com"] [uri "/cgi-sys/404.html"] [unique_id "amuaQ6469-jfU7M1CLhiSgAAKm8"]
[Thu Jul 30 13:38:59.470837 2026] [core:notice] [pid 914912:tid 915124] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:38:59.531513 2026] [security2:error] [pid 914912:tid 915043] [client 20.79.29.209:12211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/p.php"] [unique_id "amuaQ6469-jfU7M1CLhiTAAAAAE"]
[Thu Jul 30 13:38:59.531657 2026] [security2:error] [pid 914912:tid 915043] [client 20.79.29.209:12211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/p.php"] [unique_id "amuaQ6469-jfU7M1CLhiTAAAAAE"]
[Thu Jul 30 13:38:59.627402 2026] [autoindex:error] [pid 914912:tid 915065] [client 34.233.129.35:0] AH01276: Cannot serve directory /home1/pnadjbte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:38:59.831884 2026] [security2:error] [pid 914912:tid 915080] [client 20.79.29.209:12163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/n.php"] [unique_id "amuaQ6469-jfU7M1CLhiVwAAACY"]
[Thu Jul 30 13:38:59.832044 2026] [security2:error] [pid 914912:tid 915080] [client 20.79.29.209:12163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/n.php"] [unique_id "amuaQ6469-jfU7M1CLhiVwAAACY"]
[Thu Jul 30 13:39:00.024589 2026] [security2:error] [pid 914912:tid 915057] [client 20.104.18.253:7604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/docadmin.php"] [unique_id "amuaRK469-jfU7M1CLhiYQAAAA8"]
[Thu Jul 30 13:39:00.163375 2026] [security2:error] [pid 914912:tid 915168] [client 20.79.29.209:12268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/o.php"] [unique_id "amuaRK469-jfU7M1CLhiYwAAAH4"]
[Thu Jul 30 13:39:00.163481 2026] [security2:error] [pid 914912:tid 915168] [client 20.79.29.209:12268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/o.php"] [unique_id "amuaRK469-jfU7M1CLhiYwAAAH4"]
[Thu Jul 30 13:39:00.451187 2026] [security2:error] [pid 914912:tid 915071] [client 20.79.29.209:16244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/m.php"] [unique_id "amuaRK469-jfU7M1CLhibwAAAB0"]
[Thu Jul 30 13:39:00.451303 2026] [security2:error] [pid 914912:tid 915071] [client 20.79.29.209:16244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/m.php"] [unique_id "amuaRK469-jfU7M1CLhibwAAAB0"]
[Thu Jul 30 13:39:00.457136 2026] [security2:error] [pid 914912:tid 914915] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/images.php"] [unique_id "amuaRK469-jfU7M1CLhicAAAOwI"]
[Thu Jul 30 13:39:00.457306 2026] [security2:error] [pid 914912:tid 915101] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/images.php"] [unique_id "amuaRK469-jfU7M1CLhicAAAOwI"]
[Thu Jul 30 13:39:00.636220 2026] [security2:error] [pid 914912:tid 915141] [client 20.104.18.253:7579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/docalfa.php"] [unique_id "amuaRK469-jfU7M1CLhicQAAAGM"]
[Thu Jul 30 13:39:00.644890 2026] [security2:error] [pid 914912:tid 914952] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/gecko.php"] [unique_id "amuaRK469-jfU7M1CLhicgAANic"]
[Thu Jul 30 13:39:00.645056 2026] [security2:error] [pid 914912:tid 915096] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/gecko.php"] [unique_id "amuaRK469-jfU7M1CLhicgAANic"]
[Thu Jul 30 13:39:00.675500 2026] [security2:error] [pid 914912:tid 915144] [client 191.232.199.39:24216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/222.php"] [unique_id "amuaRK469-jfU7M1CLhicwAAAGY"]
[Thu Jul 30 13:39:00.751966 2026] [security2:error] [pid 914912:tid 915126] [client 20.79.29.209:16252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/l.php"] [unique_id "amuaRK469-jfU7M1CLhidAAAAFQ"]
[Thu Jul 30 13:39:00.752072 2026] [security2:error] [pid 914912:tid 915126] [client 20.79.29.209:16252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/l.php"] [unique_id "amuaRK469-jfU7M1CLhidAAAAFQ"]
[Thu Jul 30 13:39:00.801172 2026] [security2:error] [pid 914912:tid 914928] [remote 57.141.0.44:36468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/514832250/feed/rss2/"] [unique_id "amuaRK469-jfU7M1CLhieAAAZw8"]
[Thu Jul 30 13:39:00.858898 2026] [security2:error] [pid 914912:tid 914947] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/82.php"] [unique_id "amuaRK469-jfU7M1CLhifwAAaSI"]
[Thu Jul 30 13:39:00.859060 2026] [security2:error] [pid 914912:tid 915147] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/82.php"] [unique_id "amuaRK469-jfU7M1CLhifwAAaSI"]
[Thu Jul 30 13:39:00.923103 2026] [core:notice] [pid 914912:tid 915100] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:01.065123 2026] [core:notice] [pid 914912:tid 915044] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:01.071369 2026] [security2:error] [pid 914912:tid 914929] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/xstelth.php"] [unique_id "amuaRa469-jfU7M1CLhihQAAKhA"]
[Thu Jul 30 13:39:01.071513 2026] [security2:error] [pid 914912:tid 915084] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/xstelth.php"] [unique_id "amuaRa469-jfU7M1CLhihQAAKhA"]
[Thu Jul 30 13:39:01.089233 2026] [security2:error] [pid 914912:tid 915124] [client 20.79.29.209:12176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/k.php"] [unique_id "amuaRa469-jfU7M1CLhihgAAAFI"]
[Thu Jul 30 13:39:01.089314 2026] [security2:error] [pid 914912:tid 915124] [client 20.79.29.209:12176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/k.php"] [unique_id "amuaRa469-jfU7M1CLhihgAAAFI"]
[Thu Jul 30 13:39:01.153515 2026] [core:error] [pid 914912:tid 914938] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:01.153536 2026] [core:error] [pid 914912:tid 914938] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:01.233222 2026] [security2:error] [pid 914912:tid 915163] [client 20.104.18.253:7564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/docbypass.php"] [unique_id "amuaRa469-jfU7M1CLhiiwAAAHk"]
[Thu Jul 30 13:39:01.381801 2026] [security2:error] [pid 914912:tid 915092] [client 20.79.29.209:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/j.php"] [unique_id "amuaRa469-jfU7M1CLhikgAAADI"]
[Thu Jul 30 13:39:01.381919 2026] [security2:error] [pid 914912:tid 915092] [client 20.79.29.209:12261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/j.php"] [unique_id "amuaRa469-jfU7M1CLhikgAAADI"]
[Thu Jul 30 13:39:01.659554 2026] [security2:error] [pid 914912:tid 915064] [client 20.79.29.209:16229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/i.php"] [unique_id "amuaRa469-jfU7M1CLhimgAAABY"]
[Thu Jul 30 13:39:01.659677 2026] [security2:error] [pid 914912:tid 915064] [client 20.79.29.209:16229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/i.php"] [unique_id "amuaRa469-jfU7M1CLhimgAAABY"]
[Thu Jul 30 13:39:01.837597 2026] [security2:error] [pid 914912:tid 915050] [client 20.104.18.253:7601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/docindex.php"] [unique_id "amuaRa469-jfU7M1CLhingAAAAg"]
[Thu Jul 30 13:39:01.935456 2026] [security2:error] [pid 914912:tid 915157] [client 20.79.29.209:16131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/h.php"] [unique_id "amuaRa469-jfU7M1CLhiowAAAHM"]
[Thu Jul 30 13:39:01.935600 2026] [security2:error] [pid 914912:tid 915157] [client 20.79.29.209:16131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/h.php"] [unique_id "amuaRa469-jfU7M1CLhiowAAAHM"]
[Thu Jul 30 13:39:02.234175 2026] [security2:error] [pid 914912:tid 915053] [client 20.79.29.209:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/g.php"] [unique_id "amuaRq469-jfU7M1CLhiqQAAAAs"]
[Thu Jul 30 13:39:02.234285 2026] [security2:error] [pid 914912:tid 915053] [client 20.79.29.209:12244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/g.php"] [unique_id "amuaRq469-jfU7M1CLhiqQAAAAs"]
[Thu Jul 30 13:39:02.236643 2026] [security2:error] [pid 914912:tid 914924] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/xp.php"] [unique_id "amuaRq469-jfU7M1CLhiqgAAGws"]
[Thu Jul 30 13:39:02.236811 2026] [security2:error] [pid 914912:tid 915069] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/xp.php"] [unique_id "amuaRq469-jfU7M1CLhiqgAAGws"]
[Thu Jul 30 13:39:02.427186 2026] [security2:error] [pid 914912:tid 914970] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/admin.php"] [unique_id "amuaRq469-jfU7M1CLhitAAAWjk"]
[Thu Jul 30 13:39:02.427447 2026] [security2:error] [pid 914912:tid 915132] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/admin.php"] [unique_id "amuaRq469-jfU7M1CLhitAAAWjk"]
[Thu Jul 30 13:39:02.456940 2026] [security2:error] [pid 914912:tid 915070] [client 20.104.18.253:7573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/dock.php"] [unique_id "amuaRq469-jfU7M1CLhitQAAABw"]
[Thu Jul 30 13:39:02.534607 2026] [security2:error] [pid 914912:tid 915052] [client 20.79.29.209:16139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/f.php"] [unique_id "amuaRq469-jfU7M1CLhitwAAAAo"]
[Thu Jul 30 13:39:02.534710 2026] [security2:error] [pid 914912:tid 915052] [client 20.79.29.209:16139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/f.php"] [unique_id "amuaRq469-jfU7M1CLhitwAAAAo"]
[Thu Jul 30 13:39:02.614748 2026] [security2:error] [pid 914912:tid 914932] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/adminner.php"] [unique_id "amuaRq469-jfU7M1CLhiuAAAVxM"]
[Thu Jul 30 13:39:02.614933 2026] [security2:error] [pid 914912:tid 915129] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/adminner.php"] [unique_id "amuaRq469-jfU7M1CLhiuAAAVxM"]
[Thu Jul 30 13:39:02.803778 2026] [security2:error] [pid 914912:tid 915122] [client 20.79.29.209:12186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/e.php"] [unique_id "amuaRq469-jfU7M1CLhiugAAAFA"]
[Thu Jul 30 13:39:02.803899 2026] [security2:error] [pid 914912:tid 915122] [client 20.79.29.209:12186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/e.php"] [unique_id "amuaRq469-jfU7M1CLhiugAAAFA"]
[Thu Jul 30 13:39:02.807527 2026] [security2:error] [pid 914912:tid 914958] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/a.php"] [unique_id "amuaRq469-jfU7M1CLhiuwAAMS0"]
[Thu Jul 30 13:39:02.807678 2026] [security2:error] [pid 914912:tid 915091] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/a.php"] [unique_id "amuaRq469-jfU7M1CLhiuwAAMS0"]
[Thu Jul 30 13:39:02.969911 2026] [core:error] [pid 914912:tid 914978] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:02.969934 2026] [core:error] [pid 914912:tid 914978] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:02.971174 2026] [security2:error] [pid 914912:tid 914972] [remote 74.7.243.224:47618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/article.php"] [unique_id "amuaRq469-jfU7M1CLhiyAAARzs"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:39:02.992181 2026] [security2:error] [pid 914912:tid 914963] [remote 57.141.0.14:20484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuaRq469-jfU7M1CLhiyQAAUzI"]
[Thu Jul 30 13:39:03.001280 2026] [security2:error] [pid 914912:tid 914971] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/k.php"] [unique_id "amuaR6469-jfU7M1CLhiygAAbjo"]
[Thu Jul 30 13:39:03.001422 2026] [security2:error] [pid 914912:tid 915152] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/k.php"] [unique_id "amuaR6469-jfU7M1CLhiygAAbjo"]
[Thu Jul 30 13:39:03.058698 2026] [security2:error] [pid 914912:tid 915167] [client 20.104.18.253:7586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/docsadmin.php"] [unique_id "amuaR6469-jfU7M1CLhiywAAAH0"]
[Thu Jul 30 13:39:03.124508 2026] [security2:error] [pid 914912:tid 915105] [client 20.79.29.209:12279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/d.php"] [unique_id "amuaR6469-jfU7M1CLhizAAAAD8"]
[Thu Jul 30 13:39:03.124618 2026] [security2:error] [pid 914912:tid 915105] [client 20.79.29.209:12279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/d.php"] [unique_id "amuaR6469-jfU7M1CLhizAAAAD8"]
[Thu Jul 30 13:39:03.202520 2026] [security2:error] [pid 914912:tid 914950] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/222.php"] [unique_id "amuaR6469-jfU7M1CLhi0AAAWyU"]
[Thu Jul 30 13:39:03.202709 2026] [security2:error] [pid 914912:tid 915133] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/222.php"] [unique_id "amuaR6469-jfU7M1CLhi0AAAWyU"]
[Thu Jul 30 13:39:03.389239 2026] [security2:error] [pid 914912:tid 915058] [client 20.79.29.209:12239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/c.php"] [unique_id "amuaR6469-jfU7M1CLhi1gAAABA"]
[Thu Jul 30 13:39:03.389322 2026] [security2:error] [pid 914912:tid 915058] [client 20.79.29.209:12239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/c.php"] [unique_id "amuaR6469-jfU7M1CLhi1gAAABA"]
[Thu Jul 30 13:39:03.431052 2026] [core:error] [pid 914912:tid 914965] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:03.431072 2026] [core:error] [pid 914912:tid 914965] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:03.680267 2026] [security2:error] [pid 914912:tid 915055] [client 20.104.18.253:7593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/docsalfa.php"] [unique_id "amuaR6469-jfU7M1CLhi3AAAAA0"]
[Thu Jul 30 13:39:03.701421 2026] [security2:error] [pid 914912:tid 915149] [client 20.79.29.209:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/b.php"] [unique_id "amuaR6469-jfU7M1CLhi3QAAAGs"]
[Thu Jul 30 13:39:03.701519 2026] [security2:error] [pid 914912:tid 915149] [client 20.79.29.209:12242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/b.php"] [unique_id "amuaR6469-jfU7M1CLhi3QAAAGs"]
[Thu Jul 30 13:39:03.974623 2026] [security2:error] [pid 914912:tid 915104] [client 20.79.29.209:16177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/indexc.php"] [unique_id "amuaR6469-jfU7M1CLhi6AAAAD4"]
[Thu Jul 30 13:39:03.974736 2026] [security2:error] [pid 914912:tid 915104] [client 20.79.29.209:16177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/indexc.php"] [unique_id "amuaR6469-jfU7M1CLhi6AAAAD4"]
[Thu Jul 30 13:39:04.295057 2026] [security2:error] [pid 914912:tid 915048] [client 20.79.29.209:16178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuaSK469-jfU7M1CLhi7wAAAAY"]
[Thu Jul 30 13:39:04.295169 2026] [security2:error] [pid 914912:tid 915048] [client 20.79.29.209:16178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/147w3sdtB9D.php"] [unique_id "amuaSK469-jfU7M1CLhi7wAAAAY"]
[Thu Jul 30 13:39:04.386781 2026] [security2:error] [pid 914912:tid 915115] [client 191.232.199.39:35919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/images/admin.php"] [unique_id "amuaSK469-jfU7M1CLhi8AAAAEk"]
[Thu Jul 30 13:39:04.596197 2026] [security2:error] [pid 914912:tid 915123] [client 20.79.29.209:16210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuaSK469-jfU7M1CLhi-wAAAFE"]
[Thu Jul 30 13:39:04.596287 2026] [security2:error] [pid 914912:tid 915123] [client 20.79.29.209:16210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/12htKbyVOUv.php"] [unique_id "amuaSK469-jfU7M1CLhi-wAAAFE"]
[Thu Jul 30 13:39:04.862992 2026] [core:error] [pid 914912:tid 914990] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:04.863016 2026] [core:error] [pid 914912:tid 914990] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:04.917047 2026] [security2:error] [pid 914912:tid 915154] [client 20.79.29.209:12215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuaSK469-jfU7M1CLhi_gAAAHA"]
[Thu Jul 30 13:39:04.917142 2026] [security2:error] [pid 914912:tid 915154] [client 20.79.29.209:12215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "amuaSK469-jfU7M1CLhi_gAAAHA"]
[Thu Jul 30 13:39:05.170180 2026] [security2:error] [pid 914912:tid 915127] [client 139.28.219.70:32986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuaSa469-jfU7M1CLhjCQAAAFU"]
[Thu Jul 30 13:39:05.181648 2026] [security2:error] [pid 914912:tid 914944] [remote 57.141.0.26:54954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuaSa469-jfU7M1CLhjCgAAKh8"]
[Thu Jul 30 13:39:05.238954 2026] [security2:error] [pid 914912:tid 915118] [client 20.79.29.209:16157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/.561988674612251.php"] [unique_id "amuaSa469-jfU7M1CLhjDAAAAEw"]
[Thu Jul 30 13:39:05.239120 2026] [security2:error] [pid 914912:tid 915118] [client 20.79.29.209:16157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/.561988674612251.php"] [unique_id "amuaSa469-jfU7M1CLhjDAAAAEw"]
[Thu Jul 30 13:39:05.512890 2026] [security2:error] [pid 914912:tid 915079] [client 20.79.29.209:12162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/indexw.php"] [unique_id "amuaSa469-jfU7M1CLhjFgAAACU"]
[Thu Jul 30 13:39:05.513002 2026] [security2:error] [pid 914912:tid 915079] [client 20.79.29.209:12162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/indexw.php"] [unique_id "amuaSa469-jfU7M1CLhjFgAAACU"]
[Thu Jul 30 13:39:05.688770 2026] [security2:error] [pid 914912:tid 915166] [client 139.28.219.70:32992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuaSa469-jfU7M1CLhjHgAAAHw"]
[Thu Jul 30 13:39:05.829299 2026] [core:error] [pid 914912:tid 915014] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:05.829320 2026] [core:error] [pid 914912:tid 915014] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:05.862610 2026] [security2:error] [pid 914912:tid 915090] [client 20.79.29.209:12164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/.284214373991941.php"] [unique_id "amuaSa469-jfU7M1CLhjIwAAADA"]
[Thu Jul 30 13:39:05.862707 2026] [security2:error] [pid 914912:tid 915090] [client 20.79.29.209:12164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/.284214373991941.php"] [unique_id "amuaSa469-jfU7M1CLhjIwAAADA"]
[Thu Jul 30 13:39:05.959347 2026] [security2:error] [pid 914912:tid 915051] [client 139.28.219.70:32996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuaSa469-jfU7M1CLhjJwAAAAk"]
[Thu Jul 30 13:39:06.142027 2026] [security2:error] [pid 914912:tid 914992] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/mac.php"] [unique_id "amuaSq469-jfU7M1CLhjLgAASE8"]
[Thu Jul 30 13:39:06.142266 2026] [security2:error] [pid 914912:tid 915114] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/mac.php"] [unique_id "amuaSq469-jfU7M1CLhjLgAASE8"]
[Thu Jul 30 13:39:06.243462 2026] [core:notice] [pid 914912:tid 914988] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:06.270999 2026] [security2:error] [pid 914912:tid 915132] [client 139.28.219.70:33010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuaSq469-jfU7M1CLhjMwAAAFo"]
[Thu Jul 30 13:39:06.375360 2026] [security2:error] [pid 914912:tid 915143] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/index.cgi"] [unique_id "amuaSq469-jfU7M1CLhjNAAAZV0"]
[Thu Jul 30 13:39:06.539055 2026] [security2:error] [pid 914912:tid 915117] [client 139.28.219.70:33020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuaSq469-jfU7M1CLhjOwAAAEs"]
[Thu Jul 30 13:39:06.545427 2026] [security2:error] [pid 914912:tid 915122] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/404.html"] [unique_id "amuaSq469-jfU7M1CLhjPAAAUFw"]
[Thu Jul 30 13:39:06.778925 2026] [security2:error] [pid 914912:tid 915086] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/index.cgi"] [unique_id "amuaSq469-jfU7M1CLhjQAAALFg"]
[Thu Jul 30 13:39:06.809788 2026] [security2:error] [pid 914912:tid 915092] [client 139.28.219.70:33032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuaSq469-jfU7M1CLhjQQAAADI"]
[Thu Jul 30 13:39:06.946642 2026] [security2:error] [pid 914912:tid 915107] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/404.html"] [unique_id "amuaSq469-jfU7M1CLhjQgAAQWA"]
[Thu Jul 30 13:39:07.001773 2026] [core:notice] [pid 914912:tid 915008] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:07.078625 2026] [security2:error] [pid 914912:tid 915073] [client 139.28.219.70:33034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuaS6469-jfU7M1CLhjSwAAAB8"]
[Thu Jul 30 13:39:07.144004 2026] [security2:error] [pid 914912:tid 914975] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/ops.php"] [unique_id "amuaS6469-jfU7M1CLhjTAAAUz4"]
[Thu Jul 30 13:39:07.144233 2026] [security2:error] [pid 914912:tid 915125] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/ops.php"] [unique_id "amuaS6469-jfU7M1CLhjTAAAUz4"]
[Thu Jul 30 13:39:07.330468 2026] [security2:error] [pid 914912:tid 914946] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/8.php"] [unique_id "amuaS6469-jfU7M1CLhjUAAAbSE"]
[Thu Jul 30 13:39:07.330667 2026] [security2:error] [pid 914912:tid 915151] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/8.php"] [unique_id "amuaS6469-jfU7M1CLhjUAAAbSE"]
[Thu Jul 30 13:39:07.349398 2026] [security2:error] [pid 914912:tid 915093] [client 139.28.219.70:33044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuaS6469-jfU7M1CLhjUQAAADM"]
[Thu Jul 30 13:39:07.502229 2026] [security2:error] [pid 914912:tid 915072] [client 78.167.1.90:55421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaS6469-jfU7M1CLhjUgAAAB4"]
[Thu Jul 30 13:39:07.502741 2026] [security2:error] [pid 914912:tid 915072] [client 78.167.1.90:55421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaS6469-jfU7M1CLhjUgAAAB4"]
[Thu Jul 30 13:39:07.533274 2026] [security2:error] [pid 914912:tid 915007] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/FWAZ.php"] [unique_id "amuaS6469-jfU7M1CLhjVQAAJF4"]
[Thu Jul 30 13:39:07.533458 2026] [security2:error] [pid 914912:tid 915078] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/FWAZ.php"] [unique_id "amuaS6469-jfU7M1CLhjVQAAJF4"]
[Thu Jul 30 13:39:07.635677 2026] [security2:error] [pid 914912:tid 915049] [client 139.28.219.70:33058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuaS6469-jfU7M1CLhjWgAAAAc"]
[Thu Jul 30 13:39:07.719077 2026] [core:notice] [pid 914912:tid 915095] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:07.742070 2026] [security2:error] [pid 914912:tid 915023] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/biufile.php"] [unique_id "amuaS6469-jfU7M1CLhjXwAAPW4"]
[Thu Jul 30 13:39:07.742286 2026] [security2:error] [pid 914912:tid 915103] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/biufile.php"] [unique_id "amuaS6469-jfU7M1CLhjXwAAPW4"]
[Thu Jul 30 13:39:07.921506 2026] [security2:error] [pid 914912:tid 915108] [client 139.28.219.70:33064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuaS6469-jfU7M1CLhjYQAAAEI"]
[Thu Jul 30 13:39:07.943937 2026] [security2:error] [pid 914912:tid 914953] [remote 72.167.132.114:55892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-login.php"] [unique_id "amuaS6469-jfU7M1CLhjYgAAISg"]
[Thu Jul 30 13:39:07.960605 2026] [security2:error] [pid 914912:tid 915018] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/coffexium.php"] [unique_id "amuaS6469-jfU7M1CLhjYwAAI2k"]
[Thu Jul 30 13:39:07.960806 2026] [security2:error] [pid 914912:tid 915077] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/coffexium.php"] [unique_id "amuaS6469-jfU7M1CLhjYwAAI2k"]
[Thu Jul 30 13:39:08.062514 2026] [security2:error] [pid 914912:tid 915109] [client 37.140.254.5:46693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.254.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mgstudiostore.com"] [uri "/archivarix.cms.php"] [unique_id "amuaTK469-jfU7M1CLhjZwAAAEM"]
[Thu Jul 30 13:39:08.147089 2026] [security2:error] [pid 914912:tid 915021] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/simple.php"] [unique_id "amuaTK469-jfU7M1CLhjbAAAXGw"]
[Thu Jul 30 13:39:08.147317 2026] [security2:error] [pid 914912:tid 915134] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/simple.php"] [unique_id "amuaTK469-jfU7M1CLhjbAAAXGw"]
[Thu Jul 30 13:39:08.189184 2026] [security2:error] [pid 914912:tid 915101] [client 139.28.219.70:33070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuaTK469-jfU7M1CLhjbQAAADs"]
[Thu Jul 30 13:39:08.359141 2026] [security2:error] [pid 914912:tid 915025] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/fpwch.php"] [unique_id "amuaTK469-jfU7M1CLhjcQAASHA"]
[Thu Jul 30 13:39:08.359353 2026] [security2:error] [pid 914912:tid 915114] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/fpwch.php"] [unique_id "amuaTK469-jfU7M1CLhjcQAASHA"]
[Thu Jul 30 13:39:08.391149 2026] [autoindex:error] [pid 914912:tid 915146] [client 195.96.139.246:47129] AH01276: Cannot serve directory /home2/zorudite/buildmaster.pnimanpower.net/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:39:08.449933 2026] [security2:error] [pid 914912:tid 915145] [client 139.28.219.70:33074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuaTK469-jfU7M1CLhjcwAAAGc"]
[Thu Jul 30 13:39:08.544461 2026] [security2:error] [pid 914912:tid 915011] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/dex.php"] [unique_id "amuaTK469-jfU7M1CLhjdAAAImI"]
[Thu Jul 30 13:39:08.544680 2026] [security2:error] [pid 914912:tid 915076] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/dex.php"] [unique_id "amuaTK469-jfU7M1CLhjdAAAImI"]
[Thu Jul 30 13:39:08.739586 2026] [security2:error] [pid 914912:tid 915122] [client 139.28.219.70:33088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuaTK469-jfU7M1CLhjewAAAFA"]
[Thu Jul 30 13:39:08.766612 2026] [security2:error] [pid 914912:tid 914918] [remote 20.100.203.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/1.php"] [unique_id "amuaTK469-jfU7M1CLhjfAAAOgU"]
[Thu Jul 30 13:39:08.766720 2026] [security2:error] [pid 914912:tid 914918] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/1.php"] [unique_id "amuaTK469-jfU7M1CLhjfAAAOgU"]
[Thu Jul 30 13:39:08.766877 2026] [security2:error] [pid 914912:tid 915100] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/1.php"] [unique_id "amuaTK469-jfU7M1CLhjfAAAOgU"]
[Thu Jul 30 13:39:08.868425 2026] [core:error] [pid 914912:tid 915039] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:08.868447 2026] [core:error] [pid 914912:tid 915039] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:08.971017 2026] [security2:error] [pid 914912:tid 915154] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/index.cgi"] [unique_id "amuaTK469-jfU7M1CLhjgQAAcFk"]
[Thu Jul 30 13:39:09.042776 2026] [security2:error] [pid 914912:tid 915086] [client 139.28.219.70:33100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuaTa469-jfU7M1CLhjggAAACw"]
[Thu Jul 30 13:39:09.100694 2026] [security2:error] [pid 914912:tid 915038] [remote 216.73.217.142:41664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuaTa469-jfU7M1CLhjhgAAen0"]
[Thu Jul 30 13:39:09.137447 2026] [security2:error] [pid 914912:tid 915073] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/404.html"] [unique_id "amuaTa469-jfU7M1CLhjhwAAH3o"]
[Thu Jul 30 13:39:09.325152 2026] [security2:error] [pid 914912:tid 915074] [client 139.28.219.70:33102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "albashayerfurnituremovers.xyz"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuaTa469-jfU7M1CLhjjgAAACA"]
[Thu Jul 30 13:39:09.336679 2026] [security2:error] [pid 914912:tid 915020] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/config.json.php"] [unique_id "amuaTa469-jfU7M1CLhjjwAAb2s"]
[Thu Jul 30 13:39:09.336840 2026] [security2:error] [pid 914912:tid 915153] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/config.json.php"] [unique_id "amuaTa469-jfU7M1CLhjjwAAb2s"]
[Thu Jul 30 13:39:09.536646 2026] [security2:error] [pid 914912:tid 914919] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/k2.php"] [unique_id "amuaTa469-jfU7M1CLhjkQAAMwY"]
[Thu Jul 30 13:39:09.536829 2026] [security2:error] [pid 914912:tid 915093] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/k2.php"] [unique_id "amuaTa469-jfU7M1CLhjkQAAMwY"]
[Thu Jul 30 13:39:09.609822 2026] [security2:error] [pid 914912:tid 915094] [client 191.232.199.39:24071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuaTa469-jfU7M1CLhjkgAAADQ"]
[Thu Jul 30 13:39:09.742350 2026] [security2:error] [pid 914912:tid 914916] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/raw.php"] [unique_id "amuaTa469-jfU7M1CLhjmQAAdAM"]
[Thu Jul 30 13:39:09.742553 2026] [security2:error] [pid 914912:tid 915158] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/raw.php"] [unique_id "amuaTa469-jfU7M1CLhjmQAAdAM"]
[Thu Jul 30 13:39:09.932468 2026] [security2:error] [pid 914912:tid 915028] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/wp.php"] [unique_id "amuaTa469-jfU7M1CLhjnQAADXM"]
[Thu Jul 30 13:39:09.932688 2026] [security2:error] [pid 914912:tid 915055] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/wp.php"] [unique_id "amuaTa469-jfU7M1CLhjnQAADXM"]
[Thu Jul 30 13:39:10.089040 2026] [core:error] [pid 914912:tid 914913] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:10.089073 2026] [core:error] [pid 914912:tid 914913] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:10.156707 2026] [security2:error] [pid 914912:tid 914914] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/fffm.php"] [unique_id "amuaTq469-jfU7M1CLhjoQAARAE"]
[Thu Jul 30 13:39:10.156903 2026] [security2:error] [pid 914912:tid 915110] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/fffm.php"] [unique_id "amuaTq469-jfU7M1CLhjoQAARAE"]
[Thu Jul 30 13:39:10.348023 2026] [security2:error] [pid 914912:tid 915040] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/111.php"] [unique_id "amuaTq469-jfU7M1CLhjpwAAFX8"]
[Thu Jul 30 13:39:10.348209 2026] [security2:error] [pid 914912:tid 915063] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/111.php"] [unique_id "amuaTq469-jfU7M1CLhjpwAAFX8"]
[Thu Jul 30 13:39:11.072656 2026] [core:error] [pid 914912:tid 914935] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:11.072685 2026] [core:error] [pid 914912:tid 914935] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:11.782061 2026] [security2:error] [pid 914912:tid 914952] [remote 47.128.27.94:59816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-13-retro-he-got-game-2018/"] [unique_id "amuaT6469-jfU7M1CLhjxgAAEic"]
[Thu Jul 30 13:39:11.994881 2026] [core:error] [pid 914912:tid 914939] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:11.994902 2026] [core:error] [pid 914912:tid 914939] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:12.014634 2026] [security2:error] [pid 914912:tid 915136] [client 191.232.199.39:24248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/admin.php"] [unique_id "amuaUK469-jfU7M1CLhjzQAAAF4"]
[Thu Jul 30 13:39:12.356216 2026] [fcgid:warn] [pid 914912:tid 915050] (70014)End of file found: [client 199.45.155.98:45450] mod_fcgid: can't get data from http client
[Thu Jul 30 13:39:12.945250 2026] [core:error] [pid 914912:tid 915019] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:12.945277 2026] [core:error] [pid 914912:tid 915019] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:13.084350 2026] [security2:error] [pid 914912:tid 915051] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/index.cgi"] [unique_id "amuaUa469-jfU7M1CLhj4wAACSA"]
[Thu Jul 30 13:39:13.147592 2026] [core:notice] [pid 914912:tid 915067] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:13.252971 2026] [security2:error] [pid 914912:tid 915046] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/404.html"] [unique_id "amuaUa469-jfU7M1CLhj5QAABB4"]
[Thu Jul 30 13:39:13.451379 2026] [security2:error] [pid 914912:tid 914960] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/ws.php"] [unique_id "amuaUa469-jfU7M1CLhj7AAAaC8"]
[Thu Jul 30 13:39:13.451581 2026] [security2:error] [pid 914912:tid 915146] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/ws.php"] [unique_id "amuaUa469-jfU7M1CLhj7AAAaC8"]
[Thu Jul 30 13:39:13.509270 2026] [security2:error] [pid 914912:tid 915077] [client 191.232.199.39:55670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-configs.php"] [unique_id "amuaUa469-jfU7M1CLhj7QAAACM"]
[Thu Jul 30 13:39:13.636151 2026] [security2:error] [pid 914912:tid 914924] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/coffee.php"] [unique_id "amuaUa469-jfU7M1CLhj8QAAfws"]
[Thu Jul 30 13:39:13.636323 2026] [security2:error] [pid 914912:tid 915169] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/coffee.php"] [unique_id "amuaUa469-jfU7M1CLhj8QAAfws"]
[Thu Jul 30 13:39:13.837172 2026] [security2:error] [pid 914912:tid 914964] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/goods.php"] [unique_id "amuaUa469-jfU7M1CLhj9QAAWjM"]
[Thu Jul 30 13:39:13.837413 2026] [security2:error] [pid 914912:tid 915132] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/goods.php"] [unique_id "amuaUa469-jfU7M1CLhj9QAAWjM"]
[Thu Jul 30 13:39:13.933889 2026] [core:error] [pid 914912:tid 914930] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:13.933919 2026] [core:error] [pid 914912:tid 914930] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:14.056864 2026] [security2:error] [pid 914912:tid 914968] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/about.php"] [unique_id "amuaUq469-jfU7M1CLhj-gAASzc"]
[Thu Jul 30 13:39:14.057175 2026] [security2:error] [pid 914912:tid 915117] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/about.php"] [unique_id "amuaUq469-jfU7M1CLhj-gAASzc"]
[Thu Jul 30 13:39:14.244417 2026] [security2:error] [pid 914912:tid 914958] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/about.php"] [unique_id "amuaUq469-jfU7M1CLhkAwAAcC0"]
[Thu Jul 30 13:39:14.244568 2026] [security2:error] [pid 914912:tid 915154] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/about.php"] [unique_id "amuaUq469-jfU7M1CLhkAwAAcC0"]
[Thu Jul 30 13:39:14.426583 2026] [security2:error] [pid 914912:tid 914951] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/admin.php"] [unique_id "amuaUq469-jfU7M1CLhkCwAAHyY"]
[Thu Jul 30 13:39:14.426814 2026] [security2:error] [pid 914912:tid 915073] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/admin.php"] [unique_id "amuaUq469-jfU7M1CLhkCwAAHyY"]
[Thu Jul 30 13:39:14.624800 2026] [security2:error] [pid 914912:tid 914972] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/inputs.php"] [unique_id "amuaUq469-jfU7M1CLhkEQAAIDs"]
[Thu Jul 30 13:39:14.625086 2026] [security2:error] [pid 914912:tid 915074] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/inputs.php"] [unique_id "amuaUq469-jfU7M1CLhkEQAAIDs"]
[Thu Jul 30 13:39:14.821360 2026] [security2:error] [pid 914912:tid 914967] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/inputs.php"] [unique_id "amuaUq469-jfU7M1CLhkEgAAHjY"]
[Thu Jul 30 13:39:14.821548 2026] [security2:error] [pid 914912:tid 915072] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/inputs.php"] [unique_id "amuaUq469-jfU7M1CLhkEgAAHjY"]
[Thu Jul 30 13:39:15.009084 2026] [security2:error] [pid 914912:tid 914976] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/adminfuns.php"] [unique_id "amuaU6469-jfU7M1CLhkGQAADj8"]
[Thu Jul 30 13:39:15.009272 2026] [security2:error] [pid 914912:tid 915056] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/adminfuns.php"] [unique_id "amuaU6469-jfU7M1CLhkGQAADj8"]
[Thu Jul 30 13:39:15.228100 2026] [security2:error] [pid 914912:tid 914969] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/404.php"] [unique_id "amuaU6469-jfU7M1CLhkHQAABzg"]
[Thu Jul 30 13:39:15.228346 2026] [security2:error] [pid 914912:tid 915049] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/404.php"] [unique_id "amuaU6469-jfU7M1CLhkHQAABzg"]
[Thu Jul 30 13:39:15.429201 2026] [security2:error] [pid 914912:tid 914956] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/xxx.php"] [unique_id "amuaU6469-jfU7M1CLhkJgAAZCs"]
[Thu Jul 30 13:39:15.429399 2026] [security2:error] [pid 914912:tid 915142] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/xxx.php"] [unique_id "amuaU6469-jfU7M1CLhkJgAAZCs"]
[Thu Jul 30 13:39:15.547595 2026] [security2:error] [pid 914912:tid 915043] [client 119.73.97.132:30849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuaU6469-jfU7M1CLhkIQAAATQ"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 13:39:16.102037 2026] [core:error] [pid 914912:tid 914981] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:16.102060 2026] [core:error] [pid 914912:tid 914981] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:16.349586 2026] [security2:error] [pid 914912:tid 915046] [client 191.232.199.39:24245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/php.php"] [unique_id "amuaVK469-jfU7M1CLhkRQAAAAQ"]
[Thu Jul 30 13:39:16.451098 2026] [security2:error] [pid 914912:tid 914998] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuaVK469-jfU7M1CLhkSgAAF1U"]
[Thu Jul 30 13:39:17.080003 2026] [core:error] [pid 914912:tid 915015] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:17.080027 2026] [core:error] [pid 914912:tid 915015] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:17.688417 2026] [security2:error] [pid 914912:tid 915131] [client 191.232.199.39:55667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-includes/index.php"] [unique_id "amuaVa469-jfU7M1CLhkZQAAAFk"]
[Thu Jul 30 13:39:17.860851 2026] [security2:error] [pid 914912:tid 915013] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/classwithtostring.php"] [unique_id "amuaVa469-jfU7M1CLhkagAAOGQ"]
[Thu Jul 30 13:39:17.861122 2026] [security2:error] [pid 914912:tid 915098] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/classwithtostring.php"] [unique_id "amuaVa469-jfU7M1CLhkagAAOGQ"]
[Thu Jul 30 13:39:18.044648 2026] [security2:error] [pid 914912:tid 914996] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/234ff.php"] [unique_id "amuaVq469-jfU7M1CLhkbgAAVFM"]
[Thu Jul 30 13:39:18.044911 2026] [security2:error] [pid 914912:tid 915126] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/234ff.php"] [unique_id "amuaVq469-jfU7M1CLhkbgAAVFM"]
[Thu Jul 30 13:39:18.074360 2026] [core:error] [pid 914912:tid 915001] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:18.074386 2026] [core:error] [pid 914912:tid 915001] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:18.110118 2026] [security2:error] [pid 914912:tid 915144] [client 78.167.1.90:56069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaVq469-jfU7M1CLhkcwAAAGY"]
[Thu Jul 30 13:39:18.110900 2026] [security2:error] [pid 914912:tid 915144] [client 78.167.1.90:56069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaVq469-jfU7M1CLhkcwAAAGY"]
[Thu Jul 30 13:39:18.255928 2026] [security2:error] [pid 914912:tid 915009] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/133.php"] [unique_id "amuaVq469-jfU7M1CLhkdAAAY2A"]
[Thu Jul 30 13:39:18.256151 2026] [security2:error] [pid 914912:tid 915141] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/133.php"] [unique_id "amuaVq469-jfU7M1CLhkdAAAY2A"]
[Thu Jul 30 13:39:18.450615 2026] [security2:error] [pid 914912:tid 914966] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/wp-ws68.php"] [unique_id "amuaVq469-jfU7M1CLhkegAAADU"]
[Thu Jul 30 13:39:18.450783 2026] [security2:error] [pid 914912:tid 915042] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/wp-ws68.php"] [unique_id "amuaVq469-jfU7M1CLhkegAAADU"]
[Thu Jul 30 13:39:18.620273 2026] [security2:error] [pid 914912:tid 915129] [client 43.173.174.156:47462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/11/15/soiree-shopping-privilege-mango-forum-des-halles-le-24-nov-2011/"] [unique_id "amuaVq469-jfU7M1CLhkeAAAAFc"]
[Thu Jul 30 13:39:18.655415 2026] [security2:error] [pid 914912:tid 915016] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/mgrr.php"] [unique_id "amuaVq469-jfU7M1CLhkgQAABGc"]
[Thu Jul 30 13:39:18.655608 2026] [security2:error] [pid 914912:tid 915046] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/mgrr.php"] [unique_id "amuaVq469-jfU7M1CLhkgQAABGc"]
[Thu Jul 30 13:39:18.842953 2026] [security2:error] [pid 914912:tid 914946] [remote 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/55.php"] [unique_id "amuaVq469-jfU7M1CLhkggAARyE"]
[Thu Jul 30 13:39:18.843145 2026] [security2:error] [pid 914912:tid 915113] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "d82732dadc7b.teknomalay.com"] [uri "/55.php"] [unique_id "amuaVq469-jfU7M1CLhkggAARyE"]
[Thu Jul 30 13:39:18.951091 2026] [security2:error] [pid 914912:tid 915143] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.vanguardlegalassociates.team"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuaVq469-jfU7M1CLhkhwAAAGU"]
[Thu Jul 30 13:39:19.051730 2026] [core:error] [pid 914912:tid 915004] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:19.051758 2026] [core:error] [pid 914912:tid 915004] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:19.066809 2026] [core:notice] [pid 914912:tid 915065] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:19.093387 2026] [security2:error] [pid 914912:tid 915117] [client 191.232.199.39:52957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/a.php"] [unique_id "amuaV6469-jfU7M1CLhkjQAAAEs"]
[Thu Jul 30 13:39:19.377747 2026] [core:notice] [pid 914912:tid 915094] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:19.383396 2026] [security2:error] [pid 914912:tid 915094] [client 43.172.194.224:47760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/11/15/soiree-shopping-privilege-mango-forum-des-halles-le-24-nov-2011/"] [unique_id "amuaV6469-jfU7M1CLhklQAAADQ"], referer: https://carnetdeshopping.com/index.php/2011/11/15/soiree-shopping-privilege-mango-forum-des-halles-le-24-nov-2011/
[Thu Jul 30 13:39:21.178332 2026] [core:error] [pid 914912:tid 914919] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:21.178353 2026] [core:error] [pid 914912:tid 914919] [remote 1.24.16.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:21.811450 2026] [security2:error] [pid 914912:tid 915162] [client 74.7.228.18:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcontacts.pna.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/404.html"] [unique_id "amuaWa469-jfU7M1CLhk2gAAAHg"]
[Thu Jul 30 13:39:21.812174 2026] [security2:error] [pid 914912:tid 915153] [client 74.7.228.18:42654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcontacts.pna.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuaWa469-jfU7M1CLhk2AAAb3U"]
[Thu Jul 30 13:39:21.813350 2026] [security2:error] [pid 914912:tid 915168] [client 191.232.199.39:55651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-includes/Text/about.php"] [unique_id "amuaWa469-jfU7M1CLhk2wAAAH4"]
[Thu Jul 30 13:39:22.963152 2026] [fcgid:warn] [pid 914912:tid 915096] (70014)End of file found: [client 172.237.109.114:60040] mod_fcgid: can't get data from http client
[Thu Jul 30 13:39:23.257960 2026] [security2:error] [pid 914912:tid 915115] [client 191.232.199.39:24138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin.php"] [unique_id "amuaW6469-jfU7M1CLhlBQAAAEk"]
[Thu Jul 30 13:39:23.626670 2026] [security2:error] [pid 914912:tid 915146] [client 47.128.122.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuaW6469-jfU7M1CLhlCAAAAGg"]
[Thu Jul 30 13:39:23.905189 2026] [autoindex:error] [pid 914912:tid 915093] [client 159.89.32.111:40702] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:39:24.411897 2026] [security2:error] [pid 914912:tid 914999] [remote 57.141.0.36:54032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amuaXK469-jfU7M1CLhlLQAAIVY"]
[Thu Jul 30 13:39:24.706284 2026] [security2:error] [pid 914912:tid 915142] [client 191.232.199.39:55673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/size.php"] [unique_id "amuaXK469-jfU7M1CLhlOQAAAGQ"]
[Thu Jul 30 13:39:25.088408 2026] [autoindex:error] [pid 914912:tid 915123] [client 159.89.32.111:59238] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:39:25.725278 2026] [security2:error] [pid 914912:tid 915045] [client 172.237.109.114:60617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaXa469-jfU7M1CLhlPgAAAAM"]
[Thu Jul 30 13:39:25.802940 2026] [security2:error] [pid 914912:tid 915071] [client 172.237.109.114:37526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaXa469-jfU7M1CLhlQwAAAB0"]
[Thu Jul 30 13:39:26.196997 2026] [security2:error] [pid 914912:tid 915044] [client 191.232.199.39:24196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-includes/wp-class.php"] [unique_id "amuaXq469-jfU7M1CLhlXgAAAAI"]
[Thu Jul 30 13:39:26.649902 2026] [security2:error] [pid 914912:tid 915093] [client 172.237.109.114:19025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaXq469-jfU7M1CLhlWQAAADM"]
[Thu Jul 30 13:39:26.668009 2026] [security2:error] [pid 914912:tid 915094] [client 172.237.109.114:27399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaXq469-jfU7M1CLhlVwAAADQ"]
[Thu Jul 30 13:39:26.743093 2026] [security2:error] [pid 914912:tid 915072] [client 172.237.109.114:32860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaXq469-jfU7M1CLhlWAAAAB4"]
[Thu Jul 30 13:39:26.750525 2026] [security2:error] [pid 914912:tid 915078] [client 172.237.109.114:13802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaXq469-jfU7M1CLhlWgAAACQ"]
[Thu Jul 30 13:39:26.750539 2026] [security2:error] [pid 914912:tid 915056] [client 172.237.109.114:1238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaXq469-jfU7M1CLhlXAAAAA4"]
[Thu Jul 30 13:39:26.781698 2026] [security2:error] [pid 914912:tid 915153] [client 172.237.109.114:51388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaXq469-jfU7M1CLhlWwAAAG8"]
[Thu Jul 30 13:39:26.804501 2026] [security2:error] [pid 914912:tid 915127] [client 172.237.109.114:26268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaXq469-jfU7M1CLhlXQAAAFU"]
[Thu Jul 30 13:39:27.031207 2026] [security2:error] [pid 914912:tid 915147] [client 66.249.79.1:49649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amuaXa469-jfU7M1CLhlTAAAAGk"], referer: https://stunningtouchcleaning.com/
[Thu Jul 30 13:39:27.454511 2026] [security2:error] [pid 914912:tid 915112] [client 104.254.90.251:55366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuaX6469-jfU7M1CLhlgQAAAEY"]
[Thu Jul 30 13:39:27.454644 2026] [security2:error] [pid 914912:tid 915112] [client 104.254.90.251:55366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuaX6469-jfU7M1CLhlgQAAAEY"]
[Thu Jul 30 13:39:27.631884 2026] [security2:error] [pid 914912:tid 915123] [client 191.232.199.39:55657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/403.php"] [unique_id "amuaX6469-jfU7M1CLhlgwAAAFE"]
[Thu Jul 30 13:39:27.769672 2026] [proxy:error] [pid 914912:tid 915150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:27.769744 2026] [proxy_http:error] [pid 914912:tid 915150] [client 98.87.102.177:29817] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:27.770319 2026] [proxy:error] [pid 914912:tid 915150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:27.770365 2026] [proxy_http:error] [pid 914912:tid 915150] [client 98.87.102.177:29817] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:27.797842 2026] [proxy:error] [pid 914912:tid 915168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:27.797921 2026] [proxy_http:error] [pid 914912:tid 915168] [client 98.87.102.177:30028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:27.798507 2026] [proxy:error] [pid 914912:tid 915168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:27.798556 2026] [proxy_http:error] [pid 914912:tid 915168] [client 98.87.102.177:30028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:29.443198 2026] [security2:error] [pid 914912:tid 915163] [client 216.73.216.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.com"] [uri "/index.php"] [unique_id "amuaYa469-jfU7M1CLhlyAAAAHk"]
[Thu Jul 30 13:39:29.735061 2026] [security2:error] [pid 914912:tid 915117] [client 78.167.1.90:54458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaYa469-jfU7M1CLhlygAAAEs"]
[Thu Jul 30 13:39:29.735196 2026] [security2:error] [pid 914912:tid 915117] [client 78.167.1.90:54458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaYa469-jfU7M1CLhlygAAAEs"]
[Thu Jul 30 13:39:29.782998 2026] [security2:error] [pid 914912:tid 915054] [client 191.232.199.39:52947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuaYa469-jfU7M1CLhlyQAAAAw"]
[Thu Jul 30 13:39:31.064026 2026] [security2:error] [pid 914912:tid 915110] [client 191.232.199.39:52931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/as.php"] [unique_id "amuaY6469-jfU7M1CLhl6QAAAEQ"]
[Thu Jul 30 13:39:32.013665 2026] [core:notice] [pid 914912:tid 914975] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:32.450281 2026] [security2:error] [pid 914912:tid 915157] [client 191.232.199.39:24173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/includes/index.php"] [unique_id "amuaZK469-jfU7M1CLhmAgAAAHM"]
[Thu Jul 30 13:39:33.344212 2026] [security2:error] [pid 914912:tid 915060] [client 104.254.90.251:37142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuaZa469-jfU7M1CLhmEgAAABI"]
[Thu Jul 30 13:39:33.344320 2026] [security2:error] [pid 914912:tid 915060] [client 104.254.90.251:37142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuaZa469-jfU7M1CLhmEgAAABI"]
[Thu Jul 30 13:39:33.540865 2026] [core:notice] [pid 914912:tid 914921] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:33.777619 2026] [core:notice] [pid 914912:tid 915022] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:33.843454 2026] [security2:error] [pid 914912:tid 915031] [remote 185.95.156.16:47668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.156.95.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuaZa469-jfU7M1CLhmJgAAGXY"]
[Thu Jul 30 13:39:34.049727 2026] [security2:error] [pid 914912:tid 915125] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuaZa469-jfU7M1CLhmFQAAAFM"]
[Thu Jul 30 13:39:34.117418 2026] [security2:error] [pid 914912:tid 915149] [client 205.164.136.172:60566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuaZa469-jfU7M1CLhmKAAAa3g"], referer: https://trello.com/
[Thu Jul 30 13:39:34.633855 2026] [security2:error] [pid 914912:tid 915047] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuaZq469-jfU7M1CLhmKwAAAAU"]
[Thu Jul 30 13:39:35.548367 2026] [security2:error] [pid 914912:tid 915107] [client 191.232.199.39:55641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuaZ6469-jfU7M1CLhmTQAAAEE"]
[Thu Jul 30 13:39:35.644161 2026] [security2:error] [pid 914912:tid 915126] [client 74.7.228.51:44662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.uqr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuaY6469-jfU7M1CLhl7QAAVFg"]
[Thu Jul 30 13:39:36.157679 2026] [security2:error] [pid 914912:tid 914914] [remote 57.141.0.64:37438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amuaZ6469-jfU7M1CLhmWAAAKgE"]
[Thu Jul 30 13:39:37.269654 2026] [security2:error] [pid 914912:tid 915089] [client 191.232.199.39:52985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/plugins.php"] [unique_id "amuaaa469-jfU7M1CLhmeQAAAC8"]
[Thu Jul 30 13:39:38.546862 2026] [core:error] [pid 914912:tid 915159] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:38.546884 2026] [core:error] [pid 914912:tid 915159] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:39.209579 2026] [security2:error] [pid 914912:tid 915043] [client 191.232.199.39:24184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-includes/js/index.php"] [unique_id "amuaa6469-jfU7M1CLhmrgAAAAE"]
[Thu Jul 30 13:39:39.294830 2026] [security2:error] [pid 914912:tid 915166] [client 78.167.1.90:57187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaa6469-jfU7M1CLhmrwAAAHw"]
[Thu Jul 30 13:39:39.295530 2026] [security2:error] [pid 914912:tid 915166] [client 78.167.1.90:57187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaa6469-jfU7M1CLhmrwAAAHw"]
[Thu Jul 30 13:39:39.707998 2026] [proxy:error] [pid 914912:tid 915107] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:39.708081 2026] [proxy_http:error] [pid 914912:tid 915107] [client 54.87.222.253:26883] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:39.708658 2026] [proxy:error] [pid 914912:tid 915107] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:39.708702 2026] [proxy_http:error] [pid 914912:tid 915107] [client 54.87.222.253:26883] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:39.728794 2026] [proxy:error] [pid 914912:tid 915121] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:39.728860 2026] [proxy_http:error] [pid 914912:tid 915121] [client 54.87.222.253:6424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:39.729436 2026] [proxy:error] [pid 914912:tid 915121] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:39.729490 2026] [proxy_http:error] [pid 914912:tid 915121] [client 54.87.222.253:6424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:40.073947 2026] [core:error] [pid 914912:tid 915106] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:40.073991 2026] [core:error] [pid 914912:tid 915106] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:40.527390 2026] [core:error] [pid 914912:tid 915056] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:40.527412 2026] [core:error] [pid 914912:tid 915056] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:40.697794 2026] [security2:error] [pid 914912:tid 914950] [remote 57.141.0.39:42920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuabK469-jfU7M1CLhm4QAAGiU"]
[Thu Jul 30 13:39:41.108737 2026] [security2:error] [pid 914912:tid 915067] [client 191.232.199.39:52939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/go.php"] [unique_id "amuaba469-jfU7M1CLhm6wAAABk"]
[Thu Jul 30 13:39:41.738894 2026] [core:error] [pid 914912:tid 915053] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:41.738919 2026] [core:error] [pid 914912:tid 915053] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:42.114237 2026] [security2:error] [pid 914912:tid 915047] [client 74.7.230.47:56022] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ad-company.net.meg.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuaba469-jfU7M1CLhm-AAABUU"]
[Thu Jul 30 13:39:42.351547 2026] [core:error] [pid 914912:tid 915079] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:42.351572 2026] [core:error] [pid 914912:tid 915079] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:42.953261 2026] [core:error] [pid 914912:tid 915078] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:42.953283 2026] [core:error] [pid 914912:tid 915078] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:43.560658 2026] [core:error] [pid 914912:tid 915103] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:43.560681 2026] [core:error] [pid 914912:tid 915103] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:43.584405 2026] [security2:error] [pid 914912:tid 915152] [client 191.232.199.39:24131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/test1.php"] [unique_id "amuab6469-jfU7M1CLhnIQAAAG4"]
[Thu Jul 30 13:39:44.170128 2026] [core:error] [pid 914912:tid 915166] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:44.170155 2026] [core:error] [pid 914912:tid 915166] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:44.773553 2026] [core:error] [pid 914912:tid 915074] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:44.773578 2026] [core:error] [pid 914912:tid 915074] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:45.346372 2026] [core:notice] [pid 914912:tid 915060] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:45.377284 2026] [core:error] [pid 914912:tid 915118] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:45.377307 2026] [core:error] [pid 914912:tid 915118] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:45.581867 2026] [security2:error] [pid 914912:tid 915136] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuacK469-jfU7M1CLhnRgAAXl0"]
[Thu Jul 30 13:39:45.862707 2026] [security2:error] [pid 914912:tid 915048] [client 191.232.199.39:55630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/images/index.php"] [unique_id "amuaca469-jfU7M1CLhnYwAAAAY"]
[Thu Jul 30 13:39:45.988230 2026] [core:error] [pid 914912:tid 915080] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:45.988261 2026] [core:error] [pid 914912:tid 915080] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:46.146906 2026] [security2:error] [pid 914912:tid 915104] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuaca469-jfU7M1CLhnWAAAAD4"]
[Thu Jul 30 13:39:46.634842 2026] [core:error] [pid 914912:tid 915163] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:46.634864 2026] [core:error] [pid 914912:tid 915163] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:46.853027 2026] [security2:error] [pid 914912:tid 915090] [client 216.73.216.176:55166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amuaca469-jfU7M1CLhnZAAAMG4"]
[Thu Jul 30 13:39:47.237300 2026] [core:error] [pid 914912:tid 915047] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:47.237323 2026] [core:error] [pid 914912:tid 915047] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:47.839328 2026] [core:error] [pid 914912:tid 915120] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:47.839352 2026] [core:error] [pid 914912:tid 915120] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:48.152559 2026] [security2:error] [pid 914912:tid 915063] [client 191.232.199.39:52982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/asd.php"] [unique_id "amuadK469-jfU7M1CLhnnAAAABU"]
[Thu Jul 30 13:39:48.446295 2026] [core:error] [pid 914912:tid 915114] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:48.446316 2026] [core:error] [pid 914912:tid 915114] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:48.642215 2026] [security2:error] [pid 914912:tid 915039] [remote 57.141.0.61:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amuadK469-jfU7M1CLhnqgAAPn4"]
[Thu Jul 30 13:39:49.377235 2026] [core:error] [pid 914912:tid 915122] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:49.377267 2026] [core:error] [pid 914912:tid 915122] [client 123.178.210.254:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:39:49.829323 2026] [security2:error] [pid 914912:tid 915115] [client 78.167.1.90:54071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuada469-jfU7M1CLhnxwAAAEk"]
[Thu Jul 30 13:39:49.829995 2026] [security2:error] [pid 914912:tid 915115] [client 78.167.1.90:54071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuada469-jfU7M1CLhnxwAAAEk"]
[Thu Jul 30 13:39:50.363027 2026] [security2:error] [pid 914912:tid 915077] [client 191.232.199.39:55624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-includes/customize/index.php"] [unique_id "amuadq469-jfU7M1CLhn1QAAACM"]
[Thu Jul 30 13:39:50.438032 2026] [autoindex:error] [pid 914912:tid 915120] [client 18.211.55.47:62875] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:39:50.456176 2026] [autoindex:error] [pid 914912:tid 915159] [client 98.87.102.177:12358] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:39:52.179153 2026] [security2:error] [pid 914912:tid 915110] [client 191.232.199.39:52942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuaeK469-jfU7M1CLhoBAAAAEQ"]
[Thu Jul 30 13:39:53.273912 2026] [proxy:error] [pid 914912:tid 915070] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:53.274030 2026] [proxy_http:error] [pid 914912:tid 915070] [client 18.211.55.47:18153] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:53.274607 2026] [proxy:error] [pid 914912:tid 915070] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:39:53.274650 2026] [proxy_http:error] [pid 914912:tid 915070] [client 18.211.55.47:18153] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:39:54.523622 2026] [security2:error] [pid 914912:tid 915154] [client 191.232.199.39:52971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/atomlib.php"] [unique_id "amuaeq469-jfU7M1CLhoRgAAAHA"]
[Thu Jul 30 13:39:55.446788 2026] [security2:error] [pid 914912:tid 915142] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuae6469-jfU7M1CLhoYQAAAGQ"]
[Thu Jul 30 13:39:55.446931 2026] [security2:error] [pid 914912:tid 915142] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuae6469-jfU7M1CLhoYQAAAGQ"]
[Thu Jul 30 13:39:55.688901 2026] [security2:error] [pid 914912:tid 915150] [client 172.237.109.114:29486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuae6469-jfU7M1CLhoVwAAAGw"]
[Thu Jul 30 13:39:56.154343 2026] [security2:error] [pid 914912:tid 915053] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuafK469-jfU7M1CLhobwAAAAs"]
[Thu Jul 30 13:39:56.154495 2026] [security2:error] [pid 914912:tid 915053] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuafK469-jfU7M1CLhobwAAAAs"]
[Thu Jul 30 13:39:56.267537 2026] [core:notice] [pid 914912:tid 915138] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:56.426297 2026] [security2:error] [pid 914912:tid 915135] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuafK469-jfU7M1CLhoeAAAAF0"]
[Thu Jul 30 13:39:56.426429 2026] [security2:error] [pid 914912:tid 915135] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuafK469-jfU7M1CLhoeAAAAF0"]
[Thu Jul 30 13:39:56.692793 2026] [security2:error] [pid 914912:tid 915110] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/err.php"] [unique_id "amuafK469-jfU7M1CLhofAAAAEQ"]
[Thu Jul 30 13:39:56.692944 2026] [security2:error] [pid 914912:tid 915110] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/err.php"] [unique_id "amuafK469-jfU7M1CLhofAAAAEQ"]
[Thu Jul 30 13:39:56.743073 2026] [core:notice] [pid 914912:tid 915047] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:56.963966 2026] [security2:error] [pid 914912:tid 915095] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/img.php"] [unique_id "amuafK469-jfU7M1CLhohAAAADU"]
[Thu Jul 30 13:39:56.964079 2026] [security2:error] [pid 914912:tid 915095] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/img.php"] [unique_id "amuafK469-jfU7M1CLhohAAAADU"]
[Thu Jul 30 13:39:57.232815 2026] [security2:error] [pid 914912:tid 915118] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/aa.php"] [unique_id "amuafa469-jfU7M1CLhojAAAAEw"]
[Thu Jul 30 13:39:57.233102 2026] [security2:error] [pid 914912:tid 915118] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/aa.php"] [unique_id "amuafa469-jfU7M1CLhojAAAAEw"]
[Thu Jul 30 13:39:57.256681 2026] [security2:error] [pid 914912:tid 915121] [client 43.157.95.239:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.95.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuafa469-jfU7M1CLhohgAAAE8"]
[Thu Jul 30 13:39:57.390686 2026] [security2:error] [pid 914912:tid 915149] [client 191.232.199.39:55623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuafa469-jfU7M1CLhomAAAAGs"]
[Thu Jul 30 13:39:57.503133 2026] [security2:error] [pid 914912:tid 915102] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/av.php"] [unique_id "amuafa469-jfU7M1CLhongAAADw"]
[Thu Jul 30 13:39:57.503232 2026] [security2:error] [pid 914912:tid 915102] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/av.php"] [unique_id "amuafa469-jfU7M1CLhongAAADw"]
[Thu Jul 30 13:39:57.662256 2026] [core:notice] [pid 914912:tid 914959] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:57.775207 2026] [security2:error] [pid 914912:tid 915064] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/xa.php"] [unique_id "amuafa469-jfU7M1CLhooQAAABY"]
[Thu Jul 30 13:39:57.775342 2026] [security2:error] [pid 914912:tid 915064] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/xa.php"] [unique_id "amuafa469-jfU7M1CLhooQAAABY"]
[Thu Jul 30 13:39:57.863879 2026] [security2:error] [pid 914912:tid 915141] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuafa469-jfU7M1CLhojQAAAGM"]
[Thu Jul 30 13:39:57.943358 2026] [security2:error] [pid 914912:tid 915073] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuafa469-jfU7M1CLhokwAAAB8"]
[Thu Jul 30 13:39:58.045892 2026] [security2:error] [pid 914912:tid 915161] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/media.php"] [unique_id "amuafq469-jfU7M1CLhoqwAAAHc"]
[Thu Jul 30 13:39:58.046014 2026] [security2:error] [pid 914912:tid 915161] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/media.php"] [unique_id "amuafq469-jfU7M1CLhoqwAAAHc"]
[Thu Jul 30 13:39:58.208938 2026] [core:notice] [pid 914912:tid 915000] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.210879 2026] [security2:error] [pid 914912:tid 914981] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/login"] [unique_id "amuafq469-jfU7M1CLhorAAAakQ"]
[Thu Jul 30 13:39:58.320356 2026] [core:notice] [pid 914912:tid 914944] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.343458 2026] [security2:error] [pid 914912:tid 915103] [client 185.191.171.13:53016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/16/luciano-cartaxo-inicia-processo-de-transformacao-digital-da-prefeitura-com-recursos-do-programa-joao-pessoa-sustentavel/"] [unique_id "amuafq469-jfU7M1CLhosgAAAD0"]
[Thu Jul 30 13:39:58.343591 2026] [security2:error] [pid 914912:tid 915103] [client 185.191.171.13:53016] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/16/luciano-cartaxo-inicia-processo-de-transformacao-digital-da-prefeitura-com-recursos-do-programa-joao-pessoa-sustentavel/"] [unique_id "amuafq469-jfU7M1CLhosgAAAD0"]
[Thu Jul 30 13:39:58.384940 2026] [security2:error] [pid 914912:tid 915136] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/images.php"] [unique_id "amuafq469-jfU7M1CLhoswAAAF4"]
[Thu Jul 30 13:39:58.385049 2026] [security2:error] [pid 914912:tid 915136] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/images.php"] [unique_id "amuafq469-jfU7M1CLhoswAAAF4"]
[Thu Jul 30 13:39:58.459879 2026] [security2:error] [pid 914912:tid 914994] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/notice"] [unique_id "amuafq469-jfU7M1CLhotwAARlE"]
[Thu Jul 30 13:39:58.460730 2026] [security2:error] [pid 914912:tid 914980] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/issue/archive"] [unique_id "amuafq469-jfU7M1CLhouAAARkM"]
[Thu Jul 30 13:39:58.462539 2026] [security2:error] [pid 914912:tid 915085] [client 77.75.77.95:25813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "radiojelli.com"] [uri "/psychology/"] [unique_id "amuafq469-jfU7M1CLhouQAAACs"]
[Thu Jul 30 13:39:58.462621 2026] [security2:error] [pid 914912:tid 915085] [client 77.75.77.95:25813] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "radiojelli.com"] [uri "/psychology/"] [unique_id "amuafq469-jfU7M1CLhouQAAACs"]
[Thu Jul 30 13:39:58.465140 2026] [security2:error] [pid 914912:tid 915143] [client 77.75.77.95:15096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amuafq469-jfU7M1CLhougAAAGU"]
[Thu Jul 30 13:39:58.465226 2026] [security2:error] [pid 914912:tid 915143] [client 77.75.77.95:15096] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amuafq469-jfU7M1CLhougAAAGU"]
[Thu Jul 30 13:39:58.549350 2026] [core:notice] [pid 914912:tid 914955] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.670560 2026] [security2:error] [pid 914912:tid 915168] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/gecko.php"] [unique_id "amuafq469-jfU7M1CLhowQAAAH4"]
[Thu Jul 30 13:39:58.670715 2026] [security2:error] [pid 914912:tid 915168] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/gecko.php"] [unique_id "amuafq469-jfU7M1CLhowQAAAH4"]
[Thu Jul 30 13:39:58.689538 2026] [security2:error] [pid 914912:tid 914987] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/about/submissions"] [unique_id "amuafq469-jfU7M1CLhowgAAQEo"]
[Thu Jul 30 13:39:58.695378 2026] [security2:error] [pid 914912:tid 914989] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/about/editorialTeam"] [unique_id "amuafq469-jfU7M1CLhowwAAckw"]
[Thu Jul 30 13:39:58.706083 2026] [security2:error] [pid 914912:tid 914988] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/fee"] [unique_id "amuafq469-jfU7M1CLhoxQAAXUs"]
[Thu Jul 30 13:39:58.706293 2026] [core:notice] [pid 914912:tid 915015] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.731250 2026] [core:notice] [pid 914912:tid 915014] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.733546 2026] [core:notice] [pid 914912:tid 914997] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.775809 2026] [security2:error] [pid 914912:tid 914995] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/about/aboutThisPublishingSystem"] [unique_id "amuafq469-jfU7M1CLhoygAAKFI"]
[Thu Jul 30 13:39:58.782820 2026] [core:notice] [pid 914912:tid 915013] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.784898 2026] [security2:error] [pid 914912:tid 915005] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/about/privacy"] [unique_id "amuafq469-jfU7M1CLhozAAASFw"]
[Thu Jul 30 13:39:58.791050 2026] [security2:error] [pid 914912:tid 914996] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/frekuensi"] [unique_id "amuafq469-jfU7M1CLhozQAARFM"]
[Thu Jul 30 13:39:58.791183 2026] [security2:error] [pid 914912:tid 915003] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/---call---/page/page/css-name-stylesheet.css"] [unique_id "amuafq469-jfU7M1CLhozgAAfVo"]
[Thu Jul 30 13:39:58.808244 2026] [security2:error] [pid 914912:tid 915009] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/pubeth"] [unique_id "amuafq469-jfU7M1CLhozwAAKWA"]
[Thu Jul 30 13:39:58.813546 2026] [security2:error] [pid 914912:tid 914975] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/guide"] [unique_id "amuafq469-jfU7M1CLho0QAAdT4"]
[Thu Jul 30 13:39:58.814337 2026] [core:notice] [pid 914912:tid 914966] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.825148 2026] [core:notice] [pid 914912:tid 915008] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.835684 2026] [core:notice] [pid 914912:tid 915006] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.837415 2026] [core:notice] [pid 914912:tid 914946] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.837865 2026] [security2:error] [pid 914912:tid 915007] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/about/editorialTeam"] [unique_id "amuafq469-jfU7M1CLho1gAAcF4"]
[Thu Jul 30 13:39:58.840172 2026] [security2:error] [pid 914912:tid 914984] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/issue/archive"] [unique_id "amuafq469-jfU7M1CLho1wAAWUc"]
[Thu Jul 30 13:39:58.844499 2026] [security2:error] [pid 914912:tid 915004] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/index"] [unique_id "amuafq469-jfU7M1CLho2AAAIFs"]
[Thu Jul 30 13:39:58.852498 2026] [security2:error] [pid 914912:tid 915012] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/about/submissions"] [unique_id "amuafq469-jfU7M1CLho2QAAAGM"]
[Thu Jul 30 13:39:58.925550 2026] [core:notice] [pid 914912:tid 915016] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.930167 2026] [security2:error] [pid 914912:tid 914921] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/search"] [unique_id "amuafq469-jfU7M1CLho2wAAJQg"]
[Thu Jul 30 13:39:58.934994 2026] [core:notice] [pid 914912:tid 915018] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.940136 2026] [core:notice] [pid 914912:tid 915010] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.944432 2026] [core:notice] [pid 914912:tid 915025] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.947693 2026] [security2:error] [pid 914912:tid 915017] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/about/contact"] [unique_id "amuafq469-jfU7M1CLho3wAAV2g"]
[Thu Jul 30 13:39:58.947715 2026] [security2:error] [pid 914912:tid 915023] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/focus"] [unique_id "amuafq469-jfU7M1CLho4AAATG4"]
[Thu Jul 30 13:39:58.948208 2026] [security2:error] [pid 914912:tid 915021] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/openaccess"] [unique_id "amuafq469-jfU7M1CLho4QAAH2w"]
[Thu Jul 30 13:39:58.951690 2026] [core:notice] [pid 914912:tid 915032] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.953444 2026] [security2:error] [pid 914912:tid 914918] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/about/contact"] [unique_id "amuafq469-jfU7M1CLho5AAAGwU"]
[Thu Jul 30 13:39:58.955332 2026] [security2:error] [pid 914912:tid 915137] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/82.php"] [unique_id "amuafq469-jfU7M1CLho5gAAAF8"]
[Thu Jul 30 13:39:58.955405 2026] [security2:error] [pid 914912:tid 915137] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/82.php"] [unique_id "amuafq469-jfU7M1CLho5gAAAF8"]
[Thu Jul 30 13:39:58.959247 2026] [security2:error] [pid 914912:tid 914992] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/user/register"] [unique_id "amuafq469-jfU7M1CLhoxgAAaE8"]
[Thu Jul 30 13:39:58.960517 2026] [core:notice] [pid 914912:tid 915022] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.972445 2026] [security2:error] [pid 914912:tid 915029] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/scan"] [unique_id "amuafq469-jfU7M1CLho6QAAAnQ"]
[Thu Jul 30 13:39:58.973540 2026] [core:notice] [pid 914912:tid 915002] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.974208 2026] [security2:error] [pid 914912:tid 915033] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/reviewer"] [unique_id "amuafq469-jfU7M1CLho7AAAbXg"]
[Thu Jul 30 13:39:58.974923 2026] [security2:error] [pid 914912:tid 915035] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/withdraw"] [unique_id "amuafq469-jfU7M1CLho7QAAWno"]
[Thu Jul 30 13:39:58.978650 2026] [core:notice] [pid 914912:tid 915031] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.981707 2026] [security2:error] [pid 914912:tid 915026] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/process"] [unique_id "amuafq469-jfU7M1CLho7wAAD3E"]
[Thu Jul 30 13:39:58.983229 2026] [core:notice] [pid 914912:tid 915038] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.984166 2026] [core:notice] [pid 914912:tid 915039] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.984490 2026] [core:notice] [pid 914912:tid 914920] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.991602 2026] [security2:error] [pid 914912:tid 914919] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/---call---/page/page/css-name-font.css"] [unique_id "amuafq469-jfU7M1CLho9AAAJwY"]
[Thu Jul 30 13:39:58.992325 2026] [security2:error] [pid 914912:tid 914923] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/user/register"] [unique_id "amuafq469-jfU7M1CLho9QAABgo"]
[Thu Jul 30 13:39:58.996278 2026] [security2:error] [pid 914912:tid 914916] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/index"] [unique_id "amuafq469-jfU7M1CLho-AAAGAM"]
[Thu Jul 30 13:39:58.997347 2026] [core:notice] [pid 914912:tid 915034] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:58.998466 2026] [core:notice] [pid 914912:tid 915030] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:59.005646 2026] [core:notice] [pid 914912:tid 915001] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:39:59.008754 2026] [security2:error] [pid 914912:tid 915028] [remote 34.168.16.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.16.168.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/login"] [unique_id "amuaf6469-jfU7M1CLho_AAAPXM"]
[Thu Jul 30 13:39:59.226269 2026] [security2:error] [pid 914912:tid 915083] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/xstelth.php"] [unique_id "amuaf6469-jfU7M1CLhpAwAAACk"]
[Thu Jul 30 13:39:59.226396 2026] [security2:error] [pid 914912:tid 915083] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/xstelth.php"] [unique_id "amuaf6469-jfU7M1CLhpAwAAACk"]
[Thu Jul 30 13:39:59.495526 2026] [security2:error] [pid 914912:tid 915079] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/xp.php"] [unique_id "amuaf6469-jfU7M1CLhpBwAAACU"]
[Thu Jul 30 13:39:59.495640 2026] [security2:error] [pid 914912:tid 915079] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/xp.php"] [unique_id "amuaf6469-jfU7M1CLhpBwAAACU"]
[Thu Jul 30 13:39:59.511023 2026] [security2:error] [pid 914912:tid 915127] [client 172.237.109.114:27816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuafq469-jfU7M1CLho6wAAAFU"]
[Thu Jul 30 13:39:59.781055 2026] [security2:error] [pid 914912:tid 915111] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/admin.php"] [unique_id "amuaf6469-jfU7M1CLhpDwAAAEU"]
[Thu Jul 30 13:39:59.781210 2026] [security2:error] [pid 914912:tid 915111] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/admin.php"] [unique_id "amuaf6469-jfU7M1CLhpDwAAAEU"]
[Thu Jul 30 13:40:00.048046 2026] [security2:error] [pid 914912:tid 915125] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/adminner.php"] [unique_id "amuagK469-jfU7M1CLhpFwAAAFM"]
[Thu Jul 30 13:40:00.048133 2026] [security2:error] [pid 914912:tid 915125] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/adminner.php"] [unique_id "amuagK469-jfU7M1CLhpFwAAAFM"]
[Thu Jul 30 13:40:00.320690 2026] [security2:error] [pid 914912:tid 915108] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/a.php"] [unique_id "amuagK469-jfU7M1CLhpHgAAAEI"]
[Thu Jul 30 13:40:00.320835 2026] [security2:error] [pid 914912:tid 915108] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/a.php"] [unique_id "amuagK469-jfU7M1CLhpHgAAAEI"]
[Thu Jul 30 13:40:00.367720 2026] [security2:error] [pid 914912:tid 915157] [client 191.232.199.39:24239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/inputs.php"] [unique_id "amuagK469-jfU7M1CLhpHwAAAHM"]
[Thu Jul 30 13:40:00.591449 2026] [security2:error] [pid 914912:tid 915128] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/k.php"] [unique_id "amuagK469-jfU7M1CLhpJgAAAFY"]
[Thu Jul 30 13:40:00.591560 2026] [security2:error] [pid 914912:tid 915128] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/k.php"] [unique_id "amuagK469-jfU7M1CLhpJgAAAFY"]
[Thu Jul 30 13:40:00.888249 2026] [security2:error] [pid 914912:tid 915112] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/222.php"] [unique_id "amuagK469-jfU7M1CLhpLgAAAEY"]
[Thu Jul 30 13:40:00.888356 2026] [security2:error] [pid 914912:tid 915112] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/222.php"] [unique_id "amuagK469-jfU7M1CLhpLgAAAEY"]
[Thu Jul 30 13:40:01.090677 2026] [security2:error] [pid 914912:tid 914931] [remote 57.141.0.42:58130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuaga469-jfU7M1CLhpNgAAChI"]
[Thu Jul 30 13:40:01.183365 2026] [security2:error] [pid 914912:tid 915158] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/mac.php"] [unique_id "amuaga469-jfU7M1CLhpPQAAAHQ"]
[Thu Jul 30 13:40:01.183456 2026] [security2:error] [pid 914912:tid 915158] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/mac.php"] [unique_id "amuaga469-jfU7M1CLhpPQAAAHQ"]
[Thu Jul 30 13:40:01.518953 2026] [security2:error] [pid 914912:tid 915068] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.jookreview.com"] [uri "/___proxy_subdomain_webmail/wp-content/uploads/"] [unique_id "amuaga469-jfU7M1CLhpQgAAABo"]
[Thu Jul 30 13:40:01.707314 2026] [security2:error] [pid 914912:tid 915134] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.jookreview.com"] [uri "/___proxy_subdomain_webmail/wp-includes/Text/"] [unique_id "amuaga469-jfU7M1CLhpRgAAAFw"]
[Thu Jul 30 13:40:01.823125 2026] [security2:error] [pid 914912:tid 915106] [client 191.232.199.39:24224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/index.php"] [unique_id "amuaga469-jfU7M1CLhpTQAAAEA"]
[Thu Jul 30 13:40:01.861227 2026] [security2:error] [pid 914912:tid 915095] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/ops.php"] [unique_id "amuaga469-jfU7M1CLhpTgAAADU"]
[Thu Jul 30 13:40:01.861390 2026] [security2:error] [pid 914912:tid 915095] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/ops.php"] [unique_id "amuaga469-jfU7M1CLhpTgAAADU"]
[Thu Jul 30 13:40:02.151607 2026] [security2:error] [pid 914912:tid 915153] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/8.php"] [unique_id "amuagq469-jfU7M1CLhpUgAAAG8"]
[Thu Jul 30 13:40:02.151714 2026] [security2:error] [pid 914912:tid 915153] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/8.php"] [unique_id "amuagq469-jfU7M1CLhpUgAAAG8"]
[Thu Jul 30 13:40:02.429493 2026] [security2:error] [pid 914912:tid 915094] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/FWAZ.php"] [unique_id "amuagq469-jfU7M1CLhpWQAAADQ"]
[Thu Jul 30 13:40:02.429613 2026] [security2:error] [pid 914912:tid 915094] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/FWAZ.php"] [unique_id "amuagq469-jfU7M1CLhpWQAAADQ"]
[Thu Jul 30 13:40:02.728597 2026] [security2:error] [pid 914912:tid 915149] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/biufile.php"] [unique_id "amuagq469-jfU7M1CLhpXQAAAGs"]
[Thu Jul 30 13:40:02.728706 2026] [security2:error] [pid 914912:tid 915149] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/biufile.php"] [unique_id "amuagq469-jfU7M1CLhpXQAAAGs"]
[Thu Jul 30 13:40:03.013292 2026] [security2:error] [pid 914912:tid 915048] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/coffexium.php"] [unique_id "amuag6469-jfU7M1CLhpZAAAAAY"]
[Thu Jul 30 13:40:03.013451 2026] [security2:error] [pid 914912:tid 915048] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/coffexium.php"] [unique_id "amuag6469-jfU7M1CLhpZAAAAAY"]
[Thu Jul 30 13:40:03.293331 2026] [security2:error] [pid 914912:tid 915148] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/simple.php"] [unique_id "amuag6469-jfU7M1CLhpbwAAAGo"]
[Thu Jul 30 13:40:03.293436 2026] [security2:error] [pid 914912:tid 915148] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/simple.php"] [unique_id "amuag6469-jfU7M1CLhpbwAAAGo"]
[Thu Jul 30 13:40:03.455566 2026] [security2:error] [pid 914912:tid 915063] [client 185.191.171.14:61078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuag6469-jfU7M1CLhpcgAAABU"]
[Thu Jul 30 13:40:03.455717 2026] [security2:error] [pid 914912:tid 915063] [client 185.191.171.14:61078] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuag6469-jfU7M1CLhpcgAAABU"]
[Thu Jul 30 13:40:03.559506 2026] [security2:error] [pid 914912:tid 915047] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/fpwch.php"] [unique_id "amuag6469-jfU7M1CLhpdgAAAAU"]
[Thu Jul 30 13:40:03.559658 2026] [security2:error] [pid 914912:tid 915047] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/fpwch.php"] [unique_id "amuag6469-jfU7M1CLhpdgAAAAU"]
[Thu Jul 30 13:40:03.691740 2026] [security2:error] [pid 914912:tid 915161] [client 191.232.199.39:55644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/network/index.php"] [unique_id "amuag6469-jfU7M1CLhpewAAAHc"]
[Thu Jul 30 13:40:03.830514 2026] [security2:error] [pid 914912:tid 915167] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/dex.php"] [unique_id "amuag6469-jfU7M1CLhpggAAAH0"]
[Thu Jul 30 13:40:03.830643 2026] [security2:error] [pid 914912:tid 915167] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/dex.php"] [unique_id "amuag6469-jfU7M1CLhpggAAAH0"]
[Thu Jul 30 13:40:04.114845 2026] [security2:error] [pid 914912:tid 915092] [client 20.215.216.94:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.jookreview.com"] [uri "/1.php"] [unique_id "amuahK469-jfU7M1CLhpgwAAADI"]
[Thu Jul 30 13:40:04.114957 2026] [security2:error] [pid 914912:tid 915092] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/1.php"] [unique_id "amuahK469-jfU7M1CLhpgwAAADI"]
[Thu Jul 30 13:40:04.115069 2026] [security2:error] [pid 914912:tid 915092] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/1.php"] [unique_id "amuahK469-jfU7M1CLhpgwAAADI"]
[Thu Jul 30 13:40:04.146208 2026] [security2:error] [pid 914912:tid 915052] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuag6469-jfU7M1CLhpdQAAAAo"]
[Thu Jul 30 13:40:04.426540 2026] [security2:error] [pid 914912:tid 915109] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.jookreview.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/modern/"] [unique_id "amuahK469-jfU7M1CLhpkQAAAEM"]
[Thu Jul 30 13:40:04.565299 2026] [security2:error] [pid 914912:tid 915082] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/config.json.php"] [unique_id "amuahK469-jfU7M1CLhpkwAAACg"]
[Thu Jul 30 13:40:04.565412 2026] [security2:error] [pid 914912:tid 915082] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/config.json.php"] [unique_id "amuahK469-jfU7M1CLhpkwAAACg"]
[Thu Jul 30 13:40:04.842843 2026] [security2:error] [pid 914912:tid 915073] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/k2.php"] [unique_id "amuahK469-jfU7M1CLhpmgAAAB8"]
[Thu Jul 30 13:40:04.842994 2026] [security2:error] [pid 914912:tid 915073] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/k2.php"] [unique_id "amuahK469-jfU7M1CLhpmgAAAB8"]
[Thu Jul 30 13:40:05.069422 2026] [security2:error] [pid 914912:tid 915153] [client 77.83.36.161:60528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuaha469-jfU7M1CLhpngAAAG8"]
[Thu Jul 30 13:40:05.128379 2026] [security2:error] [pid 914912:tid 915083] [client 85.208.96.207:49234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2023/06/harga-komputer-server-perbandingan-dan"] [unique_id "amuaha469-jfU7M1CLhpoAAAACk"]
[Thu Jul 30 13:40:05.128436 2026] [security2:error] [pid 914912:tid 915104] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/raw.php"] [unique_id "amuaha469-jfU7M1CLhpnwAAAD4"]
[Thu Jul 30 13:40:05.128581 2026] [security2:error] [pid 914912:tid 915104] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/raw.php"] [unique_id "amuaha469-jfU7M1CLhpnwAAAD4"]
[Thu Jul 30 13:40:05.128585 2026] [security2:error] [pid 914912:tid 915083] [client 85.208.96.207:49234] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2023/06/harga-komputer-server-perbandingan-dan"] [unique_id "amuaha469-jfU7M1CLhpoAAAACk"]
[Thu Jul 30 13:40:05.435217 2026] [security2:error] [pid 914912:tid 915085] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/wp.php"] [unique_id "amuaha469-jfU7M1CLhpqgAAACs"]
[Thu Jul 30 13:40:05.435333 2026] [security2:error] [pid 914912:tid 915085] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/wp.php"] [unique_id "amuaha469-jfU7M1CLhpqgAAACs"]
[Thu Jul 30 13:40:05.643195 2026] [security2:error] [pid 914912:tid 915044] [client 77.83.36.161:60847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuaha469-jfU7M1CLhpqwAAAAI"]
[Thu Jul 30 13:40:05.719132 2026] [security2:error] [pid 914912:tid 915121] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/fffm.php"] [unique_id "amuaha469-jfU7M1CLhprAAAAE8"]
[Thu Jul 30 13:40:05.719250 2026] [security2:error] [pid 914912:tid 915121] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/fffm.php"] [unique_id "amuaha469-jfU7M1CLhprAAAAE8"]
[Thu Jul 30 13:40:06.005831 2026] [security2:error] [pid 914912:tid 915115] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/111.php"] [unique_id "amuahq469-jfU7M1CLhptwAAAEk"]
[Thu Jul 30 13:40:06.005933 2026] [security2:error] [pid 914912:tid 915115] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/111.php"] [unique_id "amuahq469-jfU7M1CLhptwAAAEk"]
[Thu Jul 30 13:40:06.193296 2026] [security2:error] [pid 914912:tid 915060] [client 77.83.36.161:61136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuahq469-jfU7M1CLhpugAAABI"]
[Thu Jul 30 13:40:06.443178 2026] [security2:error] [pid 914912:tid 915087] [client 204.8.98.105:59868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuahq469-jfU7M1CLhpwQAAAC0"]
[Thu Jul 30 13:40:06.443275 2026] [security2:error] [pid 914912:tid 915087] [client 204.8.98.105:59868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuahq469-jfU7M1CLhpwQAAAC0"]
[Thu Jul 30 13:40:07.290765 2026] [security2:error] [pid 914912:tid 915159] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.jookreview.com"] [uri "/___proxy_subdomain_webmail/wp-includes/Requests/"] [unique_id "amuah6469-jfU7M1CLhp0AAAAHU"]
[Thu Jul 30 13:40:07.440170 2026] [security2:error] [pid 914912:tid 915119] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/ws.php"] [unique_id "amuah6469-jfU7M1CLhp1AAAAE0"]
[Thu Jul 30 13:40:07.440274 2026] [security2:error] [pid 914912:tid 915119] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/ws.php"] [unique_id "amuah6469-jfU7M1CLhp1AAAAE0"]
[Thu Jul 30 13:40:08.037601 2026] [core:notice] [pid 914912:tid 914987] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:08.252404 2026] [proxy:error] [pid 914912:tid 915153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:40:08.252492 2026] [proxy_http:error] [pid 914912:tid 915153] [client 44.213.206.96:59999] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:40:08.253059 2026] [proxy:error] [pid 914912:tid 915153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:40:08.253103 2026] [proxy_http:error] [pid 914912:tid 915153] [client 44.213.206.96:59999] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:40:08.268675 2026] [proxy:error] [pid 914912:tid 915101] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:40:08.268735 2026] [proxy_http:error] [pid 914912:tid 915101] [client 52.4.19.39:21575] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:40:08.269336 2026] [proxy:error] [pid 914912:tid 915101] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:40:08.269385 2026] [proxy_http:error] [pid 914912:tid 915101] [client 52.4.19.39:21575] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:40:08.293817 2026] [security2:error] [pid 914912:tid 915162] [client 20.203.148.31:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.tmb/LA.php"] [unique_id "amuaiK469-jfU7M1CLhp9wAAAHg"]
[Thu Jul 30 13:40:08.466557 2026] [security2:error] [pid 914912:tid 915132] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/coffee.php"] [unique_id "amuaiK469-jfU7M1CLhp_AAAAFo"]
[Thu Jul 30 13:40:08.466691 2026] [security2:error] [pid 914912:tid 915132] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/coffee.php"] [unique_id "amuaiK469-jfU7M1CLhp_AAAAFo"]
[Thu Jul 30 13:40:08.736152 2026] [security2:error] [pid 914912:tid 915048] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/goods.php"] [unique_id "amuaiK469-jfU7M1CLhqBAAAAAY"]
[Thu Jul 30 13:40:08.736290 2026] [security2:error] [pid 914912:tid 915048] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/goods.php"] [unique_id "amuaiK469-jfU7M1CLhqBAAAAAY"]
[Thu Jul 30 13:40:09.008960 2026] [security2:error] [pid 914912:tid 915055] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/about.php"] [unique_id "amuaia469-jfU7M1CLhqCwAAAA0"]
[Thu Jul 30 13:40:09.009075 2026] [security2:error] [pid 914912:tid 915055] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/about.php"] [unique_id "amuaia469-jfU7M1CLhqCwAAAA0"]
[Thu Jul 30 13:40:09.068785 2026] [security2:error] [pid 914912:tid 915013] [remote 74.7.243.224:42212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/login.php"] [unique_id "amuaia469-jfU7M1CLhqDwAAC2Q"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/1784122808_wilde%20gazen.jpg
[Thu Jul 30 13:40:09.231261 2026] [core:notice] [pid 914912:tid 915087] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:09.296917 2026] [security2:error] [pid 914912:tid 915076] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/about.php"] [unique_id "amuaia469-jfU7M1CLhqHAAAACI"]
[Thu Jul 30 13:40:09.297069 2026] [security2:error] [pid 914912:tid 915076] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/about.php"] [unique_id "amuaia469-jfU7M1CLhqHAAAACI"]
[Thu Jul 30 13:40:09.379948 2026] [security2:error] [pid 914912:tid 915047] [client 20.203.148.31:5220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.tmb/admin.php"] [unique_id "amuaia469-jfU7M1CLhqHQAAAAU"]
[Thu Jul 30 13:40:09.585470 2026] [security2:error] [pid 914912:tid 915090] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/admin.php"] [unique_id "amuaia469-jfU7M1CLhqKAAAADA"]
[Thu Jul 30 13:40:09.585561 2026] [security2:error] [pid 914912:tid 915090] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/admin.php"] [unique_id "amuaia469-jfU7M1CLhqKAAAADA"]
[Thu Jul 30 13:40:09.864635 2026] [security2:error] [pid 914912:tid 915106] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/inputs.php"] [unique_id "amuaia469-jfU7M1CLhqLQAAAEA"]
[Thu Jul 30 13:40:09.864734 2026] [security2:error] [pid 914912:tid 915106] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/inputs.php"] [unique_id "amuaia469-jfU7M1CLhqLQAAAEA"]
[Thu Jul 30 13:40:09.981216 2026] [security2:error] [pid 914912:tid 915154] [client 20.203.148.31:5198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.tmb/class_api.php"] [unique_id "amuaia469-jfU7M1CLhqLgAAAHA"]
[Thu Jul 30 13:40:10.158082 2026] [security2:error] [pid 914912:tid 915111] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/inputs.php"] [unique_id "amuaiq469-jfU7M1CLhqOAAAAEU"]
[Thu Jul 30 13:40:10.158223 2026] [security2:error] [pid 914912:tid 915111] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/inputs.php"] [unique_id "amuaiq469-jfU7M1CLhqOAAAAEU"]
[Thu Jul 30 13:40:10.443177 2026] [security2:error] [pid 914912:tid 915062] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/adminfuns.php"] [unique_id "amuaiq469-jfU7M1CLhqOwAAABQ"]
[Thu Jul 30 13:40:10.443284 2026] [security2:error] [pid 914912:tid 915062] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/adminfuns.php"] [unique_id "amuaiq469-jfU7M1CLhqOwAAABQ"]
[Thu Jul 30 13:40:10.675225 2026] [security2:error] [pid 914912:tid 915067] [client 119.73.97.132:29625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuaiq469-jfU7M1CLhqOgAAGW4"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 13:40:10.729652 2026] [security2:error] [pid 914912:tid 915132] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/404.php"] [unique_id "amuaiq469-jfU7M1CLhqRgAAAFo"]
[Thu Jul 30 13:40:10.729757 2026] [security2:error] [pid 914912:tid 915132] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/404.php"] [unique_id "amuaiq469-jfU7M1CLhqRgAAAFo"]
[Thu Jul 30 13:40:10.795522 2026] [security2:error] [pid 914912:tid 915077] [client 20.203.148.31:32938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuaiq469-jfU7M1CLhqSAAAACM"]
[Thu Jul 30 13:40:10.998442 2026] [security2:error] [pid 914912:tid 915072] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/xxx.php"] [unique_id "amuaiq469-jfU7M1CLhqSQAAAB4"]
[Thu Jul 30 13:40:10.998574 2026] [security2:error] [pid 914912:tid 915072] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/xxx.php"] [unique_id "amuaiq469-jfU7M1CLhqSQAAAB4"]
[Thu Jul 30 13:40:11.282211 2026] [security2:error] [pid 914912:tid 915081] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/classwithtostring.php"] [unique_id "amuai6469-jfU7M1CLhqVAAAACc"]
[Thu Jul 30 13:40:11.282343 2026] [security2:error] [pid 914912:tid 915081] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/classwithtostring.php"] [unique_id "amuai6469-jfU7M1CLhqVAAAACc"]
[Thu Jul 30 13:40:11.424489 2026] [security2:error] [pid 914912:tid 915048] [client 78.167.1.90:55768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuai6469-jfU7M1CLhqVQAAAAY"]
[Thu Jul 30 13:40:11.425144 2026] [security2:error] [pid 914912:tid 915048] [client 78.167.1.90:55768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuai6469-jfU7M1CLhqVQAAAAY"]
[Thu Jul 30 13:40:11.432737 2026] [security2:error] [pid 914912:tid 915045] [client 191.232.199.39:55675] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "aded-rdc.org"] [uri "/wp-content/1.php"] [unique_id "amuai6469-jfU7M1CLhqVgAAAAM"]
[Thu Jul 30 13:40:11.432864 2026] [security2:error] [pid 914912:tid 915045] [client 191.232.199.39:55675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/1.php"] [unique_id "amuai6469-jfU7M1CLhqVgAAAAM"]
[Thu Jul 30 13:40:11.560451 2026] [security2:error] [pid 914912:tid 915115] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/234ff.php"] [unique_id "amuai6469-jfU7M1CLhqWAAAAEk"]
[Thu Jul 30 13:40:11.560574 2026] [security2:error] [pid 914912:tid 915115] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/234ff.php"] [unique_id "amuai6469-jfU7M1CLhqWAAAAEk"]
[Thu Jul 30 13:40:11.849691 2026] [security2:error] [pid 914912:tid 915150] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/133.php"] [unique_id "amuai6469-jfU7M1CLhqZAAAAGw"]
[Thu Jul 30 13:40:11.849799 2026] [security2:error] [pid 914912:tid 915150] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/133.php"] [unique_id "amuai6469-jfU7M1CLhqZAAAAGw"]
[Thu Jul 30 13:40:12.039796 2026] [security2:error] [pid 914912:tid 915058] [client 119.73.97.132:29625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuai6469-jfU7M1CLhqXAAAEHY"]
[Thu Jul 30 13:40:12.090498 2026] [security2:error] [pid 914912:tid 914919] [remote 192.250.239.173:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.239.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mshstrategic.com"] [uri "/wp-login.php"] [unique_id "amuai6469-jfU7M1CLhqYwAARgY"]
[Thu Jul 30 13:40:12.136838 2026] [security2:error] [pid 914912:tid 915076] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/wp-ws68.php"] [unique_id "amuajK469-jfU7M1CLhqaAAAACI"]
[Thu Jul 30 13:40:12.136935 2026] [security2:error] [pid 914912:tid 915076] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/wp-ws68.php"] [unique_id "amuajK469-jfU7M1CLhqaAAAACI"]
[Thu Jul 30 13:40:12.416704 2026] [security2:error] [pid 914912:tid 915080] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/mgrr.php"] [unique_id "amuajK469-jfU7M1CLhqcQAAACY"]
[Thu Jul 30 13:40:12.416817 2026] [security2:error] [pid 914912:tid 915080] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/mgrr.php"] [unique_id "amuajK469-jfU7M1CLhqcQAAACY"]
[Thu Jul 30 13:40:12.619906 2026] [security2:error] [pid 914912:tid 915107] [client 20.203.148.31:31041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuajK469-jfU7M1CLhqcAAAAEE"]
[Thu Jul 30 13:40:12.721807 2026] [security2:error] [pid 914912:tid 915114] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jookreview.com"] [uri "/55.php"] [unique_id "amuajK469-jfU7M1CLhqdgAAAEg"]
[Thu Jul 30 13:40:12.721920 2026] [security2:error] [pid 914912:tid 915114] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.jookreview.com"] [uri "/55.php"] [unique_id "amuajK469-jfU7M1CLhqdgAAAEg"]
[Thu Jul 30 13:40:12.752162 2026] [security2:error] [pid 914912:tid 915068] [client 191.232.199.39:24149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/plugin.php"] [unique_id "amuajK469-jfU7M1CLhqeQAAABo"]
[Thu Jul 30 13:40:12.934739 2026] [security2:error] [pid 914912:tid 915049] [client 119.73.97.132:29625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuajK469-jfU7M1CLhqcgAAB3U"]
[Thu Jul 30 13:40:13.615033 2026] [security2:error] [pid 914912:tid 915124] [client 20.203.148.31:5211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuaja469-jfU7M1CLhqmQAAAFI"]
[Thu Jul 30 13:40:13.706156 2026] [security2:error] [pid 914912:tid 915066] [client 114.119.159.236:58937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/investor-contact"] [unique_id "amuaja469-jfU7M1CLhqmgAAABg"], referer: https://alseermarine.com/investor-relations/fact-sheet
[Thu Jul 30 13:40:14.066684 2026] [security2:error] [pid 914912:tid 915121] [client 191.232.199.39:55669] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "aded-rdc.org"] [uri "/1.php"] [unique_id "amuajq469-jfU7M1CLhqpgAAAE8"]
[Thu Jul 30 13:40:14.066829 2026] [security2:error] [pid 914912:tid 915121] [client 191.232.199.39:55669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/1.php"] [unique_id "amuajq469-jfU7M1CLhqpgAAAE8"]
[Thu Jul 30 13:40:14.197509 2026] [autoindex:error] [pid 914912:tid 915089] [client 175.27.171.245:51976] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:40:14.211513 2026] [security2:error] [pid 914912:tid 915160] [client 20.203.148.31:6019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/991176.php"] [unique_id "amuajq469-jfU7M1CLhqqwAAAHY"]
[Thu Jul 30 13:40:14.551016 2026] [security2:error] [pid 914912:tid 915053] [client 172.237.109.114:41822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuaja469-jfU7M1CLhqpQAAAAs"]
[Thu Jul 30 13:40:15.014932 2026] [security2:error] [pid 914912:tid 915080] [client 20.203.148.31:31082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuaj6469-jfU7M1CLhqwAAAACY"]
[Thu Jul 30 13:40:15.446552 2026] [security2:error] [pid 914912:tid 915133] [client 191.232.199.39:55645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/gg.php"] [unique_id "amuaj6469-jfU7M1CLhqxwAAAFs"]
[Thu Jul 30 13:40:15.574606 2026] [security2:error] [pid 914912:tid 915116] [client 114.119.139.167:47217] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2023/01/019-1.jpg"] [unique_id "amuaj6469-jfU7M1CLhqywAAAEo"], referer: https://www.nordeste1.com/2023/01/24/puma-lanca-novo-uniforme-do-palmeiras-e-recebe-criticas-dos-torcedores/
[Thu Jul 30 13:40:15.951155 2026] [security2:error] [pid 914912:tid 915095] [client 20.203.148.31:31071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuaj6469-jfU7M1CLhqzwAAADU"]
[Thu Jul 30 13:40:16.256822 2026] [security2:error] [pid 914912:tid 915094] [client 90.171.239.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuakK469-jfU7M1CLhq2AAAADQ"], referer: https://cnpinyin.com
[Thu Jul 30 13:40:16.605708 2026] [security2:error] [pid 914912:tid 915088] [client 20.203.148.31:32949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuakK469-jfU7M1CLhq4gAAAC4"]
[Thu Jul 30 13:40:16.734332 2026] [core:notice] [pid 914912:tid 914957] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:17.473051 2026] [security2:error] [pid 914912:tid 915121] [client 172.237.109.114:59753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuakK469-jfU7M1CLhq6gAAAE8"]
[Thu Jul 30 13:40:17.668580 2026] [core:notice] [pid 914912:tid 914951] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:18.139776 2026] [security2:error] [pid 914912:tid 915109] [client 20.203.148.31:31047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuakq469-jfU7M1CLhrBgAAAEM"]
[Thu Jul 30 13:40:19.527083 2026] [security2:error] [pid 914912:tid 915042] [client 191.232.199.39:24566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp.php"] [unique_id "amuak6469-jfU7M1CLhrWAAAAAA"]
[Thu Jul 30 13:40:19.604969 2026] [core:notice] [pid 914912:tid 915071] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:19.609142 2026] [core:notice] [pid 914912:tid 915090] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:19.697929 2026] [core:notice] [pid 914912:tid 915086] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:19.735117 2026] [core:notice] [pid 914912:tid 915154] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:20.236839 2026] [core:notice] [pid 914912:tid 915085] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:20.377156 2026] [security2:error] [pid 914912:tid 914916] [remote 192.250.235.18:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.235.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amualK469-jfU7M1CLhrcwAAbQM"]
[Thu Jul 30 13:40:21.701718 2026] [security2:error] [pid 914912:tid 915135] [client 114.119.138.27:61223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/soldes-ete-etsy/soldes-ete-etsy-2019-aranjewels/"] [unique_id "amuala469-jfU7M1CLhrmgAAAF0"], referer: https://www.carnetdeshopping.com/soldes-ete-etsy/soldes-ete-etsy-2019-aranjewels/
[Thu Jul 30 13:40:21.785998 2026] [security2:error] [pid 914912:tid 915094] [client 20.203.148.31:32897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuala469-jfU7M1CLhroAAAADQ"]
[Thu Jul 30 13:40:22.100049 2026] [security2:error] [pid 914912:tid 915156] [client 191.232.199.39:55656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-includes/blocks/about.php"] [unique_id "amualq469-jfU7M1CLhroQAAAHI"]
[Thu Jul 30 13:40:22.480899 2026] [core:notice] [pid 914912:tid 915119] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:22.994504 2026] [core:notice] [pid 914912:tid 915131] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:23.098897 2026] [core:error] [pid 914912:tid 915111] [client 20.203.148.31:5534] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:40:23.098925 2026] [core:error] [pid 914912:tid 915111] [client 20.203.148.31:5534] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:40:23.600051 2026] [security2:error] [pid 914912:tid 915116] [client 185.191.171.3:52892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/fountains/carmel-fountain/"] [unique_id "amual6469-jfU7M1CLhrwQAAAEo"]
[Thu Jul 30 13:40:23.600191 2026] [security2:error] [pid 914912:tid 915116] [client 185.191.171.3:52892] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/fountains/carmel-fountain/"] [unique_id "amual6469-jfU7M1CLhrwQAAAEo"]
[Thu Jul 30 13:40:23.977255 2026] [security2:error] [pid 914912:tid 915146] [client 191.232.199.39:24548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/file.php"] [unique_id "amual6469-jfU7M1CLhrywAAAGg"]
[Thu Jul 30 13:40:25.425503 2026] [security2:error] [pid 914912:tid 915167] [client 191.232.199.39:24156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/user/index.php"] [unique_id "amuama469-jfU7M1CLhr_gAAAH0"]
[Thu Jul 30 13:40:25.750396 2026] [security2:error] [pid 914912:tid 915154] [client 150.241.244.100:46486] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuama469-jfU7M1CLhsSwAAAHA"]
[Thu Jul 30 13:40:26.063676 2026] [security2:error] [pid 914912:tid 915165] [client 150.241.244.100:42614] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuamq469-jfU7M1CLhsWQAAAHs"]
[Thu Jul 30 13:40:26.311113 2026] [security2:error] [pid 914912:tid 914928] [remote 57.141.0.40:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuamq469-jfU7M1CLhsZAAAZg8"]
[Thu Jul 30 13:40:26.480585 2026] [security2:error] [pid 914912:tid 915108] [client 104.254.90.251:48812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuamq469-jfU7M1CLhsawAAAEI"]
[Thu Jul 30 13:40:26.480706 2026] [security2:error] [pid 914912:tid 915108] [client 104.254.90.251:48812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuamq469-jfU7M1CLhsawAAAEI"]
[Thu Jul 30 13:40:27.503163 2026] [security2:error] [pid 914912:tid 915119] [client 45.134.142.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvw.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuama469-jfU7M1CLhsBQAAAE0"]
[Thu Jul 30 13:40:27.513233 2026] [security2:error] [pid 914912:tid 915166] [client 191.232.199.39:24522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuam6469-jfU7M1CLhshgAAAHw"]
[Thu Jul 30 13:40:27.698708 2026] [core:notice] [pid 914912:tid 914915] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:27.783645 2026] [security2:error] [pid 914912:tid 915055] [client 216.73.217.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "santaclaraimports.com"] [uri "/index.php"] [unique_id "amuam6469-jfU7M1CLhsiAAADSI"]
[Thu Jul 30 13:40:28.925314 2026] [core:notice] [pid 914912:tid 915092] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:29.952840 2026] [security2:error] [pid 914912:tid 915160] [client 104.254.90.251:49986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuana469-jfU7M1CLhs_wAAAHY"]
[Thu Jul 30 13:40:29.952949 2026] [security2:error] [pid 914912:tid 915160] [client 104.254.90.251:49986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuana469-jfU7M1CLhs_wAAAHY"]
[Thu Jul 30 13:40:30.143662 2026] [security2:error] [pid 914912:tid 915125] [client 191.232.199.39:24557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/index/function.php"] [unique_id "amuanq469-jfU7M1CLhtBgAAAFM"]
[Thu Jul 30 13:40:31.809658 2026] [security2:error] [pid 914912:tid 915077] [client 74.7.244.42:48344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.knpdongmin2215.com"] [uri "/robots.txt"] [unique_id "amuan6469-jfU7M1CLhtOgAAACM"]
[Thu Jul 30 13:40:32.073814 2026] [security2:error] [pid 914912:tid 915043] [client 78.167.1.90:54771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaoK469-jfU7M1CLhtPwAAAAE"]
[Thu Jul 30 13:40:32.074516 2026] [security2:error] [pid 914912:tid 915043] [client 78.167.1.90:54771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuaoK469-jfU7M1CLhtPwAAAAE"]
[Thu Jul 30 13:40:32.082131 2026] [security2:error] [pid 914912:tid 915074] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuan6469-jfU7M1CLhtLwAAIHI"]
[Thu Jul 30 13:40:32.129063 2026] [security2:error] [pid 914912:tid 914934] [remote 52.167.144.176:27219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/6781"] [unique_id "amuaoK469-jfU7M1CLhtQwAAZRU"]
[Thu Jul 30 13:40:32.568446 2026] [security2:error] [pid 914912:tid 915083] [client 40.77.167.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuaoK469-jfU7M1CLhtTwAAACk"]
[Thu Jul 30 13:40:32.761597 2026] [security2:error] [pid 914912:tid 915105] [client 191.232.199.39:24163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/aaa.php"] [unique_id "amuaoK469-jfU7M1CLhtVgAAAD8"]
[Thu Jul 30 13:40:34.176831 2026] [security2:error] [pid 914912:tid 915093] [client 191.232.199.39:55622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/getid3-core.php"] [unique_id "amuaoq469-jfU7M1CLhtdgAAADM"]
[Thu Jul 30 13:40:34.311477 2026] [security2:error] [pid 914912:tid 915081] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuaoa469-jfU7M1CLhtaQAAACc"]
[Thu Jul 30 13:40:35.323136 2026] [security2:error] [pid 914912:tid 915046] [client 85.208.96.195:46952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/11/29/cicero-lucena-e-eleito-prefeito-de-joao-pessoa-com-53-dos-votos/"] [unique_id "amuao6469-jfU7M1CLhtmQAAAAQ"]
[Thu Jul 30 13:40:35.323271 2026] [security2:error] [pid 914912:tid 915046] [client 85.208.96.195:46952] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/11/29/cicero-lucena-e-eleito-prefeito-de-joao-pessoa-com-53-dos-votos/"] [unique_id "amuao6469-jfU7M1CLhtmQAAAAQ"]
[Thu Jul 30 13:40:35.803425 2026] [security2:error] [pid 914912:tid 914954] [remote 114.119.131.97:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/get/vancouver"] [unique_id "amuao6469-jfU7M1CLhtpwAAVik"], referer: https://www.jipkl.com/index.php/JIPKL/article/view/52
[Thu Jul 30 13:40:36.023711 2026] [core:notice] [pid 914912:tid 915047] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:36.026189 2026] [security2:error] [pid 914912:tid 915101] [client 114.119.152.46:23355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/2026/01/"] [unique_id "amuapK469-jfU7M1CLhtrwAAADs"], referer: https://saifalkhaleejest.com/when-to-use-rotation-chain-hoists-over-standard-chain-hoists/
[Thu Jul 30 13:40:36.322427 2026] [security2:error] [pid 914912:tid 915139] [client 114.119.143.101:55303] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/search"] [unique_id "amuapK469-jfU7M1CLhttAAAAGE"], referer: https://www.kendarikomputer.com/search?updated-max=2023-05-16T08%3A00%3A00%2B08%3A00&max-results=9&m=1
[Thu Jul 30 13:40:38.756546 2026] [security2:error] [pid 914912:tid 914944] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.heiakujawir.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuapq469-jfU7M1CLht4wAAHB8"]
[Thu Jul 30 13:40:38.993508 2026] [security2:error] [pid 914912:tid 915102] [client 114.119.132.248:36167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kingstarenterprises.com"] [uri "/product-category/gym-club-accessories/lifting-straps"] [unique_id "amuapq469-jfU7M1CLht5wAAADw"], referer: https://www.kingstarenterprises.com/product-category/gym-club-accessories/lifting-straps?wc_view_mode=masonry_grid
[Thu Jul 30 13:40:39.148048 2026] [security2:error] [pid 914912:tid 915062] [client 57.129.81.155:48310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/modules/gsnippetsreviews/ws-gsnippetsreviews.php"] [unique_id "amuap6469-jfU7M1CLht7wAAABQ"]
[Thu Jul 30 13:40:39.804553 2026] [security2:error] [pid 914912:tid 915169] [client 141.95.54.59:60926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.54.95.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/modules/gsnippetsreviews/ws-gsnippetsreviews.php"] [unique_id "amuap6469-jfU7M1CLht_QAAAH8"]
[Thu Jul 30 13:40:41.046828 2026] [security2:error] [pid 914912:tid 915046] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuaqK469-jfU7M1CLhuEAAAAAQ"]
[Thu Jul 30 13:40:41.268145 2026] [security2:error] [pid 914912:tid 915047] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.heiakujawir.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuaqa469-jfU7M1CLhuJAAAAAU"]
[Thu Jul 30 13:40:42.977772 2026] [security2:error] [pid 914912:tid 915033] [remote 190.92.174.81:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "urbanshiftmovingcompany.one"] [uri "/wp-login.php"] [unique_id "amuaqq469-jfU7M1CLhuTgAAQHg"]
[Thu Jul 30 13:40:43.098884 2026] [security2:error] [pid 914912:tid 915166] [client 114.119.149.228:37203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiantourz.com"] [uri "/soldes/femme-fantazia-jupe-longue-romantique-psychedelique-heroine-noiretkaki-jupes/"] [unique_id "amuaq6469-jfU7M1CLhuTwAAAHw"], referer: http://www.arabiantourz.com/categorie-produit/femme/jupes/page/3/
[Thu Jul 30 13:40:43.833493 2026] [security2:error] [pid 914912:tid 915082] [client 114.119.150.252:25967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabian-tours.com"] [uri "/site/lisa-kerr-facebook-56216b"] [unique_id "amuaq6469-jfU7M1CLhuZQAAACg"], referer: https://arabian-tours.com/site/lisa-kerr-facebook-56216b
[Thu Jul 30 13:40:44.069938 2026] [security2:error] [pid 914912:tid 915069] [client 204.8.98.105:35028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuarK469-jfU7M1CLhuaQAAABs"]
[Thu Jul 30 13:40:44.070051 2026] [security2:error] [pid 914912:tid 915069] [client 204.8.98.105:35028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuarK469-jfU7M1CLhuaQAAABs"]
[Thu Jul 30 13:40:44.867938 2026] [security2:error] [pid 914912:tid 915085] [client 114.119.156.134:61989] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/docs/5cfb7b-portsmouth-kit-20/5cfb7b-what-do-puffins-eat"] [unique_id "amuarK469-jfU7M1CLhugAAAACs"], referer: https://arabiandubaisafari.com/docs/5cfb7b-portsmouth-kit-20/5cfb7b-marshawn-lynch-2020-stats
[Thu Jul 30 13:40:46.210301 2026] [security2:error] [pid 914912:tid 915146] [client 172.202.44.182:49672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wk/index.php"] [unique_id "amuarq469-jfU7M1CLhuxgAAAGg"]
[Thu Jul 30 13:40:47.134627 2026] [security2:error] [pid 914912:tid 915086] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuarq469-jfU7M1CLhu1gAAACw"]
[Thu Jul 30 13:40:47.413221 2026] [core:notice] [pid 914912:tid 915136] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:48.454820 2026] [security2:error] [pid 914912:tid 915077] [client 37.46.199.86:38544] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuasK469-jfU7M1CLhu-gAAACM"]
[Thu Jul 30 13:40:48.454908 2026] [security2:error] [pid 914912:tid 915077] [client 37.46.199.86:38544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuasK469-jfU7M1CLhu-gAAACM"]
[Thu Jul 30 13:40:48.750749 2026] [security2:error] [pid 914912:tid 915142] [client 172.202.44.182:49669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/av.php"] [unique_id "amuasK469-jfU7M1CLhvCAAAAGQ"]
[Thu Jul 30 13:40:48.787357 2026] [security2:error] [pid 914912:tid 915130] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuasK469-jfU7M1CLhu_QAAAFg"]
[Thu Jul 30 13:40:49.450058 2026] [security2:error] [pid 914912:tid 915105] [client 85.208.96.198:42684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/user/register"] [unique_id "amuasa469-jfU7M1CLhvFgAAAD8"]
[Thu Jul 30 13:40:49.450187 2026] [security2:error] [pid 914912:tid 915105] [client 85.208.96.198:42684] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/user/register"] [unique_id "amuasa469-jfU7M1CLhvFgAAAD8"]
[Thu Jul 30 13:40:49.837950 2026] [core:notice] [pid 914912:tid 915047] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:50.375827 2026] [security2:error] [pid 914912:tid 915098] [client 172.202.44.182:49632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/mini.php"] [unique_id "amuasq469-jfU7M1CLhvKgAAADg"]
[Thu Jul 30 13:40:50.979070 2026] [core:notice] [pid 914912:tid 915012] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:52.207127 2026] [security2:error] [pid 914912:tid 915069] [client 114.119.156.165:41783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/4/"] [unique_id "amuatK469-jfU7M1CLhvXAAAABs"], referer: https://kicksity.com/shop/?filtering=1&filter_product_cat=322%2C180%2C314%2C184
[Thu Jul 30 13:40:52.979996 2026] [core:notice] [pid 914912:tid 915099] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:53.213639 2026] [security2:error] [pid 914912:tid 915116] [client 66.249.73.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuata469-jfU7M1CLhvbAAAAEo"]
[Thu Jul 30 13:40:53.687581 2026] [security2:error] [pid 914912:tid 915098] [client 172.202.44.182:49656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/aa.php"] [unique_id "amuata469-jfU7M1CLhvfAAAADg"]
[Thu Jul 30 13:40:53.706961 2026] [security2:error] [pid 914912:tid 915135] [client 78.167.1.90:55570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuata469-jfU7M1CLhvfgAAAF0"]
[Thu Jul 30 13:40:53.707129 2026] [security2:error] [pid 914912:tid 915135] [client 78.167.1.90:55570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuata469-jfU7M1CLhvfgAAAF0"]
[Thu Jul 30 13:40:54.157557 2026] [security2:error] [pid 914912:tid 915077] [client 4.223.71.149:13528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuatq469-jfU7M1CLhviQAAACM"]
[Thu Jul 30 13:40:54.157650 2026] [security2:error] [pid 914912:tid 915077] [client 4.223.71.149:13528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuatq469-jfU7M1CLhviQAAACM"]
[Thu Jul 30 13:40:55.435782 2026] [security2:error] [pid 914912:tid 915068] [client 4.223.71.149:38371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuat6469-jfU7M1CLhvpgAAABo"]
[Thu Jul 30 13:40:55.435893 2026] [security2:error] [pid 914912:tid 915068] [client 4.223.71.149:38371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuat6469-jfU7M1CLhvpgAAABo"]
[Thu Jul 30 13:40:55.980254 2026] [security2:error] [pid 914912:tid 915149] [client 114.119.162.251:33427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/our-people/mr-mohammed-khaled/"] [unique_id "amuat6469-jfU7M1CLhvsQAAAGs"], referer: https://pkf.jo/our-people/mr-mohammed-khaled/
[Thu Jul 30 13:40:56.296225 2026] [security2:error] [pid 914912:tid 915169] [client 4.223.71.149:51405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuauK469-jfU7M1CLhvtgAAAH8"]
[Thu Jul 30 13:40:56.296320 2026] [security2:error] [pid 914912:tid 915169] [client 4.223.71.149:51405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuauK469-jfU7M1CLhvtgAAAH8"]
[Thu Jul 30 13:40:56.403148 2026] [core:notice] [pid 914912:tid 915089] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:57.091473 2026] [security2:error] [pid 914912:tid 915157] [client 4.223.71.149:59428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/media.php"] [unique_id "amuaua469-jfU7M1CLhvxwAAAHM"]
[Thu Jul 30 13:40:57.091584 2026] [security2:error] [pid 914912:tid 915157] [client 4.223.71.149:59428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/media.php"] [unique_id "amuaua469-jfU7M1CLhvxwAAAHM"]
[Thu Jul 30 13:40:57.267460 2026] [security2:error] [pid 914912:tid 915044] [client 172.202.44.182:49624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/w.php"] [unique_id "amuaua469-jfU7M1CLhvyAAAAAI"]
[Thu Jul 30 13:40:57.674880 2026] [security2:error] [pid 914912:tid 915134] [client 82.102.18.188:41018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lilyinspires.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuaua469-jfU7M1CLhv1AAAAFw"]
[Thu Jul 30 13:40:58.248646 2026] [core:notice] [pid 914912:tid 914952] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:40:58.302101 2026] [security2:error] [pid 914912:tid 915052] [client 82.102.18.188:41030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xmlrpc.php"] [unique_id "amuauq469-jfU7M1CLhv3wAAAAo"]
[Thu Jul 30 13:40:58.897822 2026] [security2:error] [pid 914912:tid 914964] [remote 5.253.84.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/wp-login.php"] [unique_id "amuauq469-jfU7M1CLhv7gAAZjM"]
[Thu Jul 30 13:40:59.428271 2026] [security2:error] [pid 914912:tid 914949] [remote 216.73.217.142:11622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuau6469-jfU7M1CLhv-gAATyQ"]
[Thu Jul 30 13:40:59.497768 2026] [security2:error] [pid 914912:tid 914957] [remote 5.253.84.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/administrator/"] [unique_id "amuau6469-jfU7M1CLhv_QAAFyw"]
[Thu Jul 30 13:40:59.582003 2026] [security2:error] [pid 914912:tid 915151] [client 172.202.44.182:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/admin.php"] [unique_id "amuau6469-jfU7M1CLhwAAAAAG0"]
[Thu Jul 30 13:40:59.711173 2026] [security2:error] [pid 914912:tid 915064] [client 82.102.18.188:41046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xmlrpc.php"] [unique_id "amuau6469-jfU7M1CLhwBAAAABY"]
[Thu Jul 30 13:40:59.711285 2026] [security2:error] [pid 914912:tid 915064] [client 82.102.18.188:41046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lilyinspires.com"] [uri "/xmlrpc.php"] [unique_id "amuau6469-jfU7M1CLhwBAAAABY"]
[Thu Jul 30 13:41:00.519249 2026] [security2:error] [pid 914912:tid 915095] [client 4.223.71.149:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/images.php"] [unique_id "amuavK469-jfU7M1CLhwFQAAADU"]
[Thu Jul 30 13:41:00.519351 2026] [security2:error] [pid 914912:tid 915095] [client 4.223.71.149:47082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/images.php"] [unique_id "amuavK469-jfU7M1CLhwFQAAADU"]
[Thu Jul 30 13:41:00.718539 2026] [security2:error] [pid 914912:tid 915165] [client 172.202.44.182:49667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuavK469-jfU7M1CLhwHQAAAHs"]
[Thu Jul 30 13:41:00.786920 2026] [security2:error] [pid 914912:tid 915108] [client 103.242.199.184:60383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuavK469-jfU7M1CLhwFgAAAEI"]
[Thu Jul 30 13:41:00.787144 2026] [security2:error] [pid 914912:tid 915108] [client 103.242.199.184:60383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuavK469-jfU7M1CLhwFgAAAEI"]
[Thu Jul 30 13:41:01.314782 2026] [autoindex:error] [pid 914912:tid 914968] [remote 172.239.145.199:32888] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:41:01.664379 2026] [security2:error] [pid 914912:tid 915164] [client 114.119.158.113:43359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product/marlboro-5/"] [unique_id "amuava469-jfU7M1CLhwNwAAAHo"], referer: https://online-hope.com/product/marlboro-9/
[Thu Jul 30 13:41:02.317283 2026] [security2:error] [pid 914912:tid 915159] [client 105.165.155.207:42984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuava469-jfU7M1CLhwPwAAAHU"], referer: http://pkf.jo
[Thu Jul 30 13:41:02.531339 2026] [security2:error] [pid 914912:tid 915094] [client 176.65.17.235:43834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuavq469-jfU7M1CLhwQwAAADQ"], referer: http://pkf.jo
[Thu Jul 30 13:41:02.657941 2026] [security2:error] [pid 914912:tid 915130] [client 178.73.69.185:65216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuavq469-jfU7M1CLhwRwAAAFg"], referer: http://pkf.jo
[Thu Jul 30 13:41:02.803845 2026] [security2:error] [pid 914912:tid 915059] [client 114.119.139.183:46559] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuavq469-jfU7M1CLhwUQAAABE"], referer: https://www.toscanamall.com/fr?remove_item=fde238a4fcb7d56461fa0850bd28c86b
[Thu Jul 30 13:41:02.913991 2026] [security2:error] [pid 914912:tid 915146] [client 4.223.71.149:32991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/adminner.php"] [unique_id "amuavq469-jfU7M1CLhwVQAAAGg"]
[Thu Jul 30 13:41:02.914099 2026] [security2:error] [pid 914912:tid 915146] [client 4.223.71.149:32991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/adminner.php"] [unique_id "amuavq469-jfU7M1CLhwVQAAAGg"]
[Thu Jul 30 13:41:03.246545 2026] [security2:error] [pid 914912:tid 915054] [client 78.175.224.198:24570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuavq469-jfU7M1CLhwSAAAAAw"], referer: http://pkf.jo
[Thu Jul 30 13:41:03.454405 2026] [security2:error] [pid 914912:tid 915066] [client 49.228.112.130:58892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuavq469-jfU7M1CLhwTwAAABg"], referer: http://pkf.jo
[Thu Jul 30 13:41:03.499382 2026] [security2:error] [pid 914912:tid 915082] [client 138.94.59.205:22678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuavq469-jfU7M1CLhwUAAAACg"], referer: http://pkf.jo
[Thu Jul 30 13:41:03.968703 2026] [security2:error] [pid 914912:tid 915156] [client 78.167.1.90:55527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuav6469-jfU7M1CLhwagAAAHI"]
[Thu Jul 30 13:41:03.969148 2026] [security2:error] [pid 914912:tid 915156] [client 78.167.1.90:55527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuav6469-jfU7M1CLhwagAAAHI"]
[Thu Jul 30 13:41:04.229064 2026] [proxy:error] [pid 914912:tid 915115] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:04.229153 2026] [proxy_http:error] [pid 914912:tid 915115] [client 32.194.121.99:27760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:04.229258 2026] [proxy:error] [pid 914912:tid 915060] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:04.229319 2026] [proxy_http:error] [pid 914912:tid 915060] [client 32.194.121.99:53103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:04.229743 2026] [proxy:error] [pid 914912:tid 915115] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:04.229788 2026] [proxy_http:error] [pid 914912:tid 915115] [client 32.194.121.99:27760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:04.230164 2026] [proxy:error] [pid 914912:tid 915060] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:04.230236 2026] [proxy_http:error] [pid 914912:tid 915060] [client 32.194.121.99:53103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:04.233934 2026] [security2:error] [pid 914912:tid 915165] [client 109.53.82.84:10112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuav6469-jfU7M1CLhwXwAAAHs"], referer: http://pkf.jo
[Thu Jul 30 13:41:04.323778 2026] [security2:error] [pid 914912:tid 915153] [client 122.170.197.88:23007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuav6469-jfU7M1CLhwYAAAAG8"], referer: http://pkf.jo
[Thu Jul 30 13:41:04.337362 2026] [security2:error] [pid 914912:tid 915042] [client 4.223.71.149:56634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/admin.php"] [unique_id "amuawK469-jfU7M1CLhwfAAAAAA"]
[Thu Jul 30 13:41:04.337505 2026] [security2:error] [pid 914912:tid 915042] [client 4.223.71.149:56634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/admin.php"] [unique_id "amuawK469-jfU7M1CLhwfAAAAAA"]
[Thu Jul 30 13:41:04.607177 2026] [security2:error] [pid 914912:tid 915155] [client 82.139.97.153:64779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuawK469-jfU7M1CLhwewAAAHE"], referer: http://pkf.jo
[Thu Jul 30 13:41:04.885280 2026] [security2:error] [pid 914912:tid 915135] [client 172.202.44.182:49617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/m.php"] [unique_id "amuawK469-jfU7M1CLhwjAAAAF0"]
[Thu Jul 30 13:41:05.002334 2026] [security2:error] [pid 914912:tid 915051] [client 152.59.87.82:18698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuawK469-jfU7M1CLhwiQAAAAk"], referer: http://pkf.jo
[Thu Jul 30 13:41:06.191314 2026] [security2:error] [pid 914912:tid 915045] [client 127.0.0.1:47050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuawq469-jfU7M1CLhwqwAAAAM"]
[Thu Jul 30 13:41:06.191375 2026] [security2:error] [pid 914912:tid 915149] [client 74.7.228.9:59608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.hjq.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuawq469-jfU7M1CLhwqgAAazg"]
[Thu Jul 30 13:41:06.279042 2026] [security2:error] [pid 914912:tid 915005] [remote 216.73.217.142:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuawq469-jfU7M1CLhwrwAAVVw"]
[Thu Jul 30 13:41:06.409705 2026] [security2:error] [pid 914912:tid 915124] [client 4.223.71.149:56639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/ops.php"] [unique_id "amuawq469-jfU7M1CLhwtAAAAFI"]
[Thu Jul 30 13:41:06.409877 2026] [security2:error] [pid 914912:tid 915124] [client 4.223.71.149:56639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/ops.php"] [unique_id "amuawq469-jfU7M1CLhwtAAAAFI"]
[Thu Jul 30 13:41:06.439571 2026] [security2:error] [pid 914912:tid 915093] [client 172.202.44.182:49615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuawq469-jfU7M1CLhwtQAAADM"]
[Thu Jul 30 13:41:06.546349 2026] [security2:error] [pid 914912:tid 915072] [client 216.73.217.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jacislamabad.com"] [uri "/index.php"] [unique_id "amuawK469-jfU7M1CLhwegAAHks"]
[Thu Jul 30 13:41:06.616418 2026] [security2:error] [pid 914912:tid 915132] [client 172.237.109.114:14675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuawa469-jfU7M1CLhwpAAAAFo"]
[Thu Jul 30 13:41:06.927147 2026] [security2:error] [pid 914912:tid 915161] [client 74.7.230.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amuawq469-jfU7M1CLhwyQAAAHc"]
[Thu Jul 30 13:41:06.929878 2026] [security2:error] [pid 914912:tid 915160] [client 74.7.230.3:48752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amuawq469-jfU7M1CLhwxwAAdmE"]
[Thu Jul 30 13:41:06.983060 2026] [security2:error] [pid 914912:tid 915125] [client 82.79.210.79:39798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuawq469-jfU7M1CLhwvwAAAFM"], referer: http://pkf.jo
[Thu Jul 30 13:41:07.457868 2026] [proxy:error] [pid 914912:tid 915135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:07.457925 2026] [proxy_http:error] [pid 914912:tid 915135] [client 172.202.44.182:49638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:07.458772 2026] [proxy:error] [pid 914912:tid 915135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:07.458823 2026] [proxy_http:error] [pid 914912:tid 915135] [client 172.202.44.182:49638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:08.754315 2026] [security2:error] [pid 914912:tid 915057] [client 216.73.217.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jacislamabad.com"] [uri "/index.php"] [unique_id "amuaxK469-jfU7M1CLhw_wAADxU"]
[Thu Jul 30 13:41:09.125882 2026] [security2:error] [pid 914912:tid 915133] [client 4.223.71.149:61889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/mac.php"] [unique_id "amuaxa469-jfU7M1CLhxCQAAAFs"]
[Thu Jul 30 13:41:09.126035 2026] [security2:error] [pid 914912:tid 915133] [client 4.223.71.149:61889] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/mac.php"] [unique_id "amuaxa469-jfU7M1CLhxCQAAAFs"]
[Thu Jul 30 13:41:10.053325 2026] [fcgid:warn] [pid 914912:tid 915052] (70014)End of file found: [client 66.132.195.76:27592] mod_fcgid: can't get data from http client
[Thu Jul 30 13:41:10.473383 2026] [core:notice] [pid 914912:tid 915069] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:10.475686 2026] [security2:error] [pid 914912:tid 915135] [client 103.190.47.88:50690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuaxq469-jfU7M1CLhxJgAAAF0"], referer: http://pkf.jo
[Thu Jul 30 13:41:10.657215 2026] [security2:error] [pid 914912:tid 915152] [client 103.242.199.184:60881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuaxq469-jfU7M1CLhxMwAAAG4"]
[Thu Jul 30 13:41:10.657351 2026] [security2:error] [pid 914912:tid 915152] [client 103.242.199.184:60881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuaxq469-jfU7M1CLhxMwAAAG4"]
[Thu Jul 30 13:41:11.200260 2026] [security2:error] [pid 914912:tid 915121] [client 4.223.71.149:33003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "dhowcruisedinner.com"] [uri "/cgi-sys/404.html"] [unique_id "amuax6469-jfU7M1CLhxPwAAAE8"]
[Thu Jul 30 13:41:11.215193 2026] [core:notice] [pid 914912:tid 915143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:11.257904 2026] [fcgid:warn] [pid 914912:tid 915115] (70014)End of file found: [client 167.94.146.61:23768] mod_fcgid: can't get data from http client
[Thu Jul 30 13:41:11.351347 2026] [security2:error] [pid 914912:tid 915060] [client 4.223.71.149:33003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/pucci.php"] [unique_id "amuax6469-jfU7M1CLhxRQAAABI"]
[Thu Jul 30 13:41:11.351518 2026] [security2:error] [pid 914912:tid 915060] [client 4.223.71.149:33003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/pucci.php"] [unique_id "amuax6469-jfU7M1CLhxRQAAABI"]
[Thu Jul 30 13:41:11.870242 2026] [security2:error] [pid 914912:tid 915042] [client 114.119.161.177:54595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/birthday-sparklers/our-products/fog-machine/"] [unique_id "amuax6469-jfU7M1CLhxVAAAAAA"], referer: https://fireworkskenya.co.ke/our-products/consumer-fireworks/birthday-sparklers/
[Thu Jul 30 13:41:12.745531 2026] [security2:error] [pid 914912:tid 915097] [client 4.223.71.149:38364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuayK469-jfU7M1CLhxZQAAADc"]
[Thu Jul 30 13:41:12.745632 2026] [security2:error] [pid 914912:tid 915097] [client 4.223.71.149:38364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuayK469-jfU7M1CLhxZQAAADc"]
[Thu Jul 30 13:41:12.966216 2026] [security2:error] [pid 914912:tid 914949] [remote 57.141.0.54:65376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/27169508389/feed/rss2/"] [unique_id "amuayK469-jfU7M1CLhxbAAAOSQ"]
[Thu Jul 30 13:41:13.194924 2026] [security2:error] [pid 914912:tid 914999] [remote 74.7.243.224:45814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/js/login.php"] [unique_id "amuaya469-jfU7M1CLhxbgAALFY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 13:41:13.498693 2026] [security2:error] [pid 914912:tid 915066] [client 37.130.110.135:4223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuaya469-jfU7M1CLhxbQAAABg"], referer: http://pkf.jo
[Thu Jul 30 13:41:13.673823 2026] [security2:error] [pid 914912:tid 915064] [client 4.223.71.149:58737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/8.php"] [unique_id "amuaya469-jfU7M1CLhxeQAAABY"]
[Thu Jul 30 13:41:13.673926 2026] [security2:error] [pid 914912:tid 915064] [client 4.223.71.149:58737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/8.php"] [unique_id "amuaya469-jfU7M1CLhxeQAAABY"]
[Thu Jul 30 13:41:14.361075 2026] [security2:error] [pid 914912:tid 915055] [client 78.167.1.90:55303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuayq469-jfU7M1CLhxjAAAAA0"]
[Thu Jul 30 13:41:14.361687 2026] [security2:error] [pid 914912:tid 915055] [client 78.167.1.90:55303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuayq469-jfU7M1CLhxjAAAAA0"]
[Thu Jul 30 13:41:14.831526 2026] [security2:error] [pid 914912:tid 915048] [client 172.202.44.182:49613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/classwithtostring.php"] [unique_id "amuayq469-jfU7M1CLhxnAAAAAY"]
[Thu Jul 30 13:41:15.064939 2026] [security2:error] [pid 914912:tid 915118] [client 4.223.71.149:3291] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "dhowcruisedinner.com"] [uri "/1.php"] [unique_id "amuay6469-jfU7M1CLhxpgAAAEw"]
[Thu Jul 30 13:41:15.065076 2026] [security2:error] [pid 914912:tid 915118] [client 4.223.71.149:3291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.71.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/1.php"] [unique_id "amuay6469-jfU7M1CLhxpgAAAEw"]
[Thu Jul 30 13:41:15.065166 2026] [security2:error] [pid 914912:tid 915118] [client 4.223.71.149:3291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dhowcruisedinner.com"] [uri "/1.php"] [unique_id "amuay6469-jfU7M1CLhxpgAAAEw"]
[Thu Jul 30 13:41:15.269576 2026] [security2:error] [pid 914912:tid 915099] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuayq469-jfU7M1CLhxmAAAADk"]
[Thu Jul 30 13:41:15.525656 2026] [security2:error] [pid 914912:tid 915090] [client 188.160.172.126:45816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuay6469-jfU7M1CLhxqAAAADA"], referer: http://pkf.jo
[Thu Jul 30 13:41:15.688598 2026] [security2:error] [pid 914912:tid 915089] [client 172.237.109.114:45660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuay6469-jfU7M1CLhxpwAAAC8"]
[Thu Jul 30 13:41:16.361853 2026] [core:notice] [pid 914912:tid 914955] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:16.501393 2026] [core:notice] [pid 914912:tid 915100] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:16.540873 2026] [security2:error] [pid 914912:tid 915059] [client 114.119.165.200:57305] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cnpinyin.com"] [uri "/miv-video-play"] [unique_id "amuazK469-jfU7M1CLhxygAAABE"], referer: https://cnpinyin.com/miv/
[Thu Jul 30 13:41:16.621711 2026] [security2:error] [pid 914912:tid 915094] [client 73.251.108.186:35762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuazK469-jfU7M1CLhxwQAAADQ"], referer: http://pkf.jo
[Thu Jul 30 13:41:16.887284 2026] [core:notice] [pid 914912:tid 915097] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:16.974714 2026] [security2:error] [pid 914912:tid 915091] [client 217.199.144.73:58220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuazK469-jfU7M1CLhxzgAAADE"], referer: http://pkf.jo
[Thu Jul 30 13:41:16.995039 2026] [autoindex:error] [pid 914912:tid 915043] [client 52.202.41.153:53458] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:41:17.054909 2026] [security2:error] [pid 914912:tid 915135] [client 60.53.35.235:26985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuazK469-jfU7M1CLhxzwAAAF0"], referer: http://pkf.jo
[Thu Jul 30 13:41:17.413384 2026] [security2:error] [pid 914912:tid 915152] [client 157.119.186.50:37422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuaza469-jfU7M1CLhx2wAAAG4"], referer: http://pkf.jo
[Thu Jul 30 13:41:18.181544 2026] [security2:error] [pid 914912:tid 915099] [client 213.139.63.65:38512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuaza469-jfU7M1CLhx5gAAADk"], referer: http://pkf.jo
[Thu Jul 30 13:41:18.312210 2026] [security2:error] [pid 914912:tid 915092] [client 37.237.130.44:51440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuaza469-jfU7M1CLhx5wAAADI"], referer: http://pkf.jo
[Thu Jul 30 13:41:18.563379 2026] [security2:error] [pid 914912:tid 915140] [client 151.251.168.14:53920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuazq469-jfU7M1CLhx8gAAAGI"], referer: http://pkf.jo
[Thu Jul 30 13:41:18.664644 2026] [security2:error] [pid 914912:tid 915160] [client 213.230.92.81:31679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuazq469-jfU7M1CLhx8wAAAHY"], referer: http://pkf.jo
[Thu Jul 30 13:41:18.689877 2026] [security2:error] [pid 914912:tid 915078] [client 172.237.109.114:1054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuazq469-jfU7M1CLhx7gAAACQ"]
[Thu Jul 30 13:41:18.770833 2026] [fcgid:warn] [pid 914912:tid 915042] (70014)End of file found: [client 167.94.146.61:45438] mod_fcgid: can't get data from http client
[Thu Jul 30 13:41:19.105911 2026] [core:notice] [pid 914912:tid 915129] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:19.729671 2026] [security2:error] [pid 914912:tid 915065] [client 172.202.44.182:49663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/gmo.php"] [unique_id "amuaz6469-jfU7M1CLhyFgAAABc"]
[Thu Jul 30 13:41:19.740696 2026] [security2:error] [pid 914912:tid 915062] [client 114.119.145.102:61193] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/lodgepole/insusceptibility1116490.html"] [unique_id "amuaz6469-jfU7M1CLhyFwAAABQ"], referer: https://www.shorewooddaycare.com/lodgepole/insusceptibility1116490.html
[Thu Jul 30 13:41:19.745809 2026] [security2:error] [pid 914912:tid 915146] [client 181.232.183.40:4623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuaz6469-jfU7M1CLhyDAAAAGg"], referer: http://pkf.jo
[Thu Jul 30 13:41:20.861173 2026] [security2:error] [pid 914912:tid 915120] [client 172.202.44.182:49623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/languages/index.php"] [unique_id "amua0K469-jfU7M1CLhyLAAAAE4"]
[Thu Jul 30 13:41:21.133392 2026] [security2:error] [pid 914912:tid 915088] [client 184.75.214.163:32926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.214.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua0a469-jfU7M1CLhyLgAAAC4"]
[Thu Jul 30 13:41:21.133514 2026] [security2:error] [pid 914912:tid 915088] [client 184.75.214.163:32926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua0a469-jfU7M1CLhyLgAAAC4"]
[Thu Jul 30 13:41:21.349171 2026] [security2:error] [pid 914912:tid 915140] [client 103.242.199.184:61413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua0a469-jfU7M1CLhyOQAAAGI"]
[Thu Jul 30 13:41:21.349296 2026] [security2:error] [pid 914912:tid 915140] [client 103.242.199.184:61413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua0a469-jfU7M1CLhyOQAAAGI"]
[Thu Jul 30 13:41:21.415738 2026] [security2:error] [pid 914912:tid 915057] [client 187.190.140.136:4792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua0a469-jfU7M1CLhyLQAAAA8"], referer: http://pkf.jo
[Thu Jul 30 13:41:21.634797 2026] [security2:error] [pid 914912:tid 915077] [client 103.144.48.133:42300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua0a469-jfU7M1CLhyOgAAACM"], referer: http://pkf.jo
[Thu Jul 30 13:41:21.779128 2026] [security2:error] [pid 914912:tid 915061] [client 114.119.133.34:62687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/store/"] [unique_id "amua0a469-jfU7M1CLhyQwAAABM"], referer: https://lark-shop.com/store?product-page=7
[Thu Jul 30 13:41:21.901063 2026] [security2:error] [pid 914912:tid 915168] [client 172.202.44.182:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-the.php"] [unique_id "amua0a469-jfU7M1CLhyRgAAAH4"]
[Thu Jul 30 13:41:22.335926 2026] [security2:error] [pid 914912:tid 915102] [client 169.224.25.110:31236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua0q469-jfU7M1CLhySQAAADw"], referer: http://pkf.jo
[Thu Jul 30 13:41:22.515233 2026] [core:notice] [pid 914912:tid 915040] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:22.639743 2026] [core:notice] [pid 914912:tid 914986] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:23.004644 2026] [security2:error] [pid 914912:tid 915137] [client 91.21.7.50:50597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amua0a469-jfU7M1CLhySAAAX2g"]
[Thu Jul 30 13:41:23.041476 2026] [security2:error] [pid 914912:tid 915082] [client 172.202.44.182:49676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/404.php"] [unique_id "amua06469-jfU7M1CLhybwAAACg"]
[Thu Jul 30 13:41:25.044227 2026] [security2:error] [pid 914912:tid 915094] [client 78.167.1.90:53717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua1a469-jfU7M1CLhyogAAADQ"]
[Thu Jul 30 13:41:25.044758 2026] [security2:error] [pid 914912:tid 915094] [client 78.167.1.90:53717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua1a469-jfU7M1CLhyogAAADQ"]
[Thu Jul 30 13:41:25.057917 2026] [security2:error] [pid 914912:tid 915024] [remote 103.133.214.160:60736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.214.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amua1a469-jfU7M1CLhyowAAfm8"]
[Thu Jul 30 13:41:25.332015 2026] [security2:error] [pid 914912:tid 915080] [client 82.102.18.182:51208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amua1a469-jfU7M1CLhyqAAAACY"]
[Thu Jul 30 13:41:25.399503 2026] [security2:error] [pid 914912:tid 915072] [client 74.7.228.14:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "waxandgoldbooks.com"] [uri "/index.php"] [unique_id "amua0q469-jfU7M1CLhyagAAHhU"]
[Thu Jul 30 13:41:25.690121 2026] [security2:error] [pid 914912:tid 915108] [client 165.16.185.103:3151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua1a469-jfU7M1CLhyqQAAAEI"], referer: http://pkf.jo
[Thu Jul 30 13:41:25.868651 2026] [security2:error] [pid 914912:tid 915149] [client 82.102.18.182:51216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amua1a469-jfU7M1CLhysgAAAGs"]
[Thu Jul 30 13:41:25.962893 2026] [security2:error] [pid 914912:tid 915107] [client 172.202.44.182:61921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/init.php"] [unique_id "amua1a469-jfU7M1CLhyvQAAAEE"]
[Thu Jul 30 13:41:26.513911 2026] [security2:error] [pid 914912:tid 915042] [client 82.102.18.182:51220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amua1q469-jfU7M1CLhyyAAAAAA"]
[Thu Jul 30 13:41:26.780933 2026] [security2:error] [pid 914912:tid 915160] [client 82.102.18.182:51224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amua1q469-jfU7M1CLhyygAAAHY"]
[Thu Jul 30 13:41:26.992014 2026] [security2:error] [pid 914912:tid 915105] [client 172.237.109.114:15258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amua1q469-jfU7M1CLhy0QAAAD8"]
[Thu Jul 30 13:41:27.015447 2026] [security2:error] [pid 914912:tid 914924] [remote 57.141.0.65:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/74297757886/feed/rss2/"] [unique_id "amua16469-jfU7M1CLhy0gAAags"]
[Thu Jul 30 13:41:27.043301 2026] [security2:error] [pid 914912:tid 915131] [client 191.82.245.128:48426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua1q469-jfU7M1CLhyyQAAAFk"], referer: http://pkf.jo
[Thu Jul 30 13:41:27.050541 2026] [security2:error] [pid 914912:tid 915055] [client 82.102.18.182:51228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amua16469-jfU7M1CLhy1gAAAA0"]
[Thu Jul 30 13:41:27.323133 2026] [security2:error] [pid 914912:tid 915056] [client 82.102.18.182:4211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amua16469-jfU7M1CLhy1wAAAA4"]
[Thu Jul 30 13:41:27.645474 2026] [security2:error] [pid 914912:tid 915111] [client 82.102.18.182:46826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amua16469-jfU7M1CLhy4QAAAEU"]
[Thu Jul 30 13:41:27.936224 2026] [security2:error] [pid 914912:tid 915168] [client 82.102.18.182:46838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amua16469-jfU7M1CLhy4gAAAH4"]
[Thu Jul 30 13:41:28.246833 2026] [security2:error] [pid 914912:tid 915108] [client 82.102.18.182:46848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amua2K469-jfU7M1CLhy8wAAAEI"]
[Thu Jul 30 13:41:28.293854 2026] [security2:error] [pid 914912:tid 915115] [client 114.119.130.60:41553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/events/retreat-dates/eventsbyday/2026/5/12/-"] [unique_id "amua2K469-jfU7M1CLhy9AAAAEk"], referer: https://www.hmhs.ph/events/retreat-dates/monthcalendar/2026/5/-
[Thu Jul 30 13:41:28.521034 2026] [security2:error] [pid 914912:tid 915064] [client 82.102.18.182:46858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amua2K469-jfU7M1CLhzAAAAABY"]
[Thu Jul 30 13:41:28.618189 2026] [security2:error] [pid 914912:tid 914943] [remote 45.93.169.34:50249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amua2K469-jfU7M1CLhy9QAAXx4"]
[Thu Jul 30 13:41:28.618374 2026] [security2:error] [pid 914912:tid 915137] [client 45.93.169.34:50249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/xmlrpc.php"] [unique_id "amua2K469-jfU7M1CLhy9QAAXx4"]
[Thu Jul 30 13:41:28.685162 2026] [security2:error] [pid 914912:tid 915169] [client 116.204.143.104:39122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua2K469-jfU7M1CLhy9gAAAH8"], referer: http://pkf.jo
[Thu Jul 30 13:41:28.741015 2026] [security2:error] [pid 914912:tid 915147] [client 107.170.60.13:37224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.wrf.zzt.temporary.site"] [uri "/.env"] [unique_id "amua2K469-jfU7M1CLhzBgAAAGk"]
[Thu Jul 30 13:41:28.793382 2026] [security2:error] [pid 914912:tid 915134] [client 82.102.18.182:46862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amua2K469-jfU7M1CLhzBwAAAFw"]
[Thu Jul 30 13:41:29.070806 2026] [security2:error] [pid 914912:tid 915121] [client 82.102.18.182:46866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amua2a469-jfU7M1CLhzDQAAAE8"]
[Thu Jul 30 13:41:29.350362 2026] [security2:error] [pid 914912:tid 915100] [client 82.102.18.182:46868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amua2a469-jfU7M1CLhzEgAAADo"]
[Thu Jul 30 13:41:29.616253 2026] [security2:error] [pid 914912:tid 915128] [client 82.102.18.182:46876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amua2a469-jfU7M1CLhzIAAAAFY"]
[Thu Jul 30 13:41:29.930889 2026] [security2:error] [pid 914912:tid 915063] [client 82.102.18.182:46880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amua2a469-jfU7M1CLhzKAAAABU"]
[Thu Jul 30 13:41:30.210963 2026] [security2:error] [pid 914912:tid 915157] [client 82.102.18.182:24120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amua2q469-jfU7M1CLhzOAAAAHM"]
[Thu Jul 30 13:41:30.463771 2026] [security2:error] [pid 914912:tid 915059] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amua2a469-jfU7M1CLhzJwAAABE"]
[Thu Jul 30 13:41:30.531187 2026] [security2:error] [pid 914912:tid 915093] [client 185.206.200.128:43330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua2q469-jfU7M1CLhzOQAAADM"], referer: http://pkf.jo
[Thu Jul 30 13:41:30.706104 2026] [security2:error] [pid 914912:tid 915053] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amua2q469-jfU7M1CLhzMAAAAAs"]
[Thu Jul 30 13:41:30.795104 2026] [security2:error] [pid 914912:tid 915151] [client 103.170.54.197:2370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua2q469-jfU7M1CLhzOgAAAG0"], referer: http://pkf.jo
[Thu Jul 30 13:41:31.241548 2026] [security2:error] [pid 914912:tid 915140] [client 181.174.228.93:39490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua2q469-jfU7M1CLhzRAAAAGI"], referer: http://pkf.jo
[Thu Jul 30 13:41:31.343580 2026] [security2:error] [pid 914912:tid 915119] [client 1.178.242.165:42050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua2q469-jfU7M1CLhzSAAAAE0"], referer: http://pkf.jo
[Thu Jul 30 13:41:31.800907 2026] [security2:error] [pid 914912:tid 915046] [client 114.119.150.210:32037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ejournalugj.com"] [uri "/index_php/index/index"] [unique_id "amua26469-jfU7M1CLhzYwAAAAQ"], referer: https://www.ejournalugj.com/
[Thu Jul 30 13:41:31.845547 2026] [core:notice] [pid 914912:tid 915122] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:31.982668 2026] [security2:error] [pid 914912:tid 915154] [client 103.242.199.184:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua26469-jfU7M1CLhzaQAAAHA"]
[Thu Jul 30 13:41:31.982795 2026] [security2:error] [pid 914912:tid 915154] [client 103.242.199.184:61932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua26469-jfU7M1CLhzaQAAAHA"]
[Thu Jul 30 13:41:32.024809 2026] [security2:error] [pid 914912:tid 915094] [client 103.118.152.119:37264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua26469-jfU7M1CLhzYgAAADQ"], referer: http://pkf.jo
[Thu Jul 30 13:41:32.125206 2026] [core:notice] [pid 914912:tid 915049] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:32.416024 2026] [security2:error] [pid 914912:tid 914944] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.echomemoversalain.casa"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amua3K469-jfU7M1CLhzdQAAch8"]
[Thu Jul 30 13:41:32.536535 2026] [security2:error] [pid 914912:tid 915135] [client 185.19.154.167:16129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua3K469-jfU7M1CLhzdAAAAF0"], referer: http://pkf.jo
[Thu Jul 30 13:41:32.892306 2026] [core:notice] [pid 914912:tid 915157] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:32.896594 2026] [security2:error] [pid 914912:tid 915157] [client 66.249.79.230:41457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/prougj/$$$call$$$/page/page/css"] [unique_id "amua3K469-jfU7M1CLhzeQAAAHM"], referer: http://www.ejournalugj.com/
[Thu Jul 30 13:41:32.999076 2026] [security2:error] [pid 914912:tid 915137] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.echomemoversalain.casa"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amua3K469-jfU7M1CLhzhAAAAF8"]
[Thu Jul 30 13:41:33.455118 2026] [security2:error] [pid 914912:tid 915070] [client 52.28.162.93:51734] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amua3a469-jfU7M1CLhzjwAAABw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:41:33.824987 2026] [core:notice] [pid 914912:tid 915161] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:33.829190 2026] [security2:error] [pid 914912:tid 915161] [client 52.28.162.93:51736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amua3a469-jfU7M1CLhzmgAAAHc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:41:33.854174 2026] [security2:error] [pid 914912:tid 915008] [remote 57.141.0.1:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amua3a469-jfU7M1CLhzmwAAO18"]
[Thu Jul 30 13:41:34.206164 2026] [security2:error] [pid 914912:tid 915140] [client 52.28.162.93:51748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amua3q469-jfU7M1CLhznQAAAGI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:41:34.293192 2026] [security2:error] [pid 914912:tid 915165] [client 172.202.44.182:49322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file5.php"] [unique_id "amua3q469-jfU7M1CLhzpQAAAHs"]
[Thu Jul 30 13:41:34.559768 2026] [security2:error] [pid 914912:tid 915006] [remote 216.73.217.142:16911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amua3q469-jfU7M1CLhzrwAANF0"]
[Thu Jul 30 13:41:35.627692 2026] [security2:error] [pid 914912:tid 915109] [client 78.167.1.90:54529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua36469-jfU7M1CLhz9AAAAEM"]
[Thu Jul 30 13:41:35.628267 2026] [security2:error] [pid 914912:tid 915109] [client 78.167.1.90:54529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua36469-jfU7M1CLhz9AAAAEM"]
[Thu Jul 30 13:41:36.354935 2026] [security2:error] [pid 914912:tid 915139] [client 114.119.140.214:61889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dhowcruisedinner.com"] [uri "/marina-glass-boat.html"] [unique_id "amua4K469-jfU7M1CLh0BAAAAGE"]
[Thu Jul 30 13:41:36.618351 2026] [security2:error] [pid 914912:tid 915162] [client 127.0.0.1:18062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amua4K469-jfU7M1CLh0DAAAAHg"]
[Thu Jul 30 13:41:36.618527 2026] [security2:error] [pid 914912:tid 915052] [client 74.7.230.39:45084] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.vertexfurnituretransport.site"] [uri "/robots.txt"] [unique_id "amua4K469-jfU7M1CLh0CwAACic"]
[Thu Jul 30 13:41:37.076864 2026] [security2:error] [pid 914912:tid 915082] [client 172.202.44.182:49325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amua4a469-jfU7M1CLh0GAAAACg"]
[Thu Jul 30 13:41:38.593331 2026] [security2:error] [pid 914912:tid 915089] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amua4q469-jfU7M1CLh0MwAAAC8"]
[Thu Jul 30 13:41:39.726839 2026] [security2:error] [pid 914912:tid 914971] [remote 198.38.94.87:54110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amua46469-jfU7M1CLh0WAAAGTo"]
[Thu Jul 30 13:41:41.594718 2026] [security2:error] [pid 914912:tid 915138] [client 172.237.109.114:49987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amua5a469-jfU7M1CLh0bwAAAGA"]
[Thu Jul 30 13:41:41.699301 2026] [proxy:error] [pid 914912:tid 915116] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:41.699389 2026] [proxy_http:error] [pid 914912:tid 915116] [client 34.233.129.35:5775] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:41.700219 2026] [proxy:error] [pid 914912:tid 915116] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:41.700273 2026] [proxy_http:error] [pid 914912:tid 915116] [client 34.233.129.35:5775] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:41.747670 2026] [proxy:error] [pid 914912:tid 915122] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:41.747751 2026] [proxy_http:error] [pid 914912:tid 915122] [client 32.194.121.99:42203] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:41.748476 2026] [proxy:error] [pid 914912:tid 915122] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:41.748543 2026] [proxy_http:error] [pid 914912:tid 915122] [client 32.194.121.99:42203] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:41.925570 2026] [core:error] [pid 914912:tid 915056] [client 66.132.172.140:38470] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:41:41.925594 2026] [core:error] [pid 914912:tid 915056] [client 66.132.172.140:38470] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:41:42.644784 2026] [security2:error] [pid 914912:tid 915150] [client 103.242.199.184:62461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua5q469-jfU7M1CLh0nAAAAGw"]
[Thu Jul 30 13:41:42.645195 2026] [security2:error] [pid 914912:tid 915150] [client 103.242.199.184:62461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua5q469-jfU7M1CLh0nAAAAGw"]
[Thu Jul 30 13:41:43.165993 2026] [security2:error] [pid 914912:tid 915129] [client 172.202.44.182:49305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/shell.php"] [unique_id "amua56469-jfU7M1CLh0rAAAAFc"]
[Thu Jul 30 13:41:43.532068 2026] [security2:error] [pid 914912:tid 915096] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amua5q469-jfU7M1CLh0pAAANlc"]
[Thu Jul 30 13:41:44.272245 2026] [security2:error] [pid 914912:tid 915145] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amua5q469-jfU7M1CLh0pwAAZ1Q"]
[Thu Jul 30 13:41:44.503319 2026] [security2:error] [pid 914912:tid 915132] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amua56469-jfU7M1CLh0rQAAWk4"]
[Thu Jul 30 13:41:44.618292 2026] [security2:error] [pid 914912:tid 915072] [client 37.46.199.86:34406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amua6K469-jfU7M1CLh0zwAAAB4"]
[Thu Jul 30 13:41:44.618409 2026] [security2:error] [pid 914912:tid 915072] [client 37.46.199.86:34406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amua6K469-jfU7M1CLh0zwAAAB4"]
[Thu Jul 30 13:41:45.431022 2026] [security2:error] [pid 914912:tid 915059] [client 87.4.136.195:44512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua6K469-jfU7M1CLh01gAAABE"], referer: http://pkf.jo
[Thu Jul 30 13:41:45.667349 2026] [security2:error] [pid 914912:tid 915097] [client 74.7.175.156:37978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.mukasarati.com"] [uri "/index.php"] [unique_id "amua6K469-jfU7M1CLh0ygAAN0s"]
[Thu Jul 30 13:41:46.229854 2026] [security2:error] [pid 914912:tid 915153] [client 78.167.1.90:55640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua6q469-jfU7M1CLh0_AAAAG8"]
[Thu Jul 30 13:41:46.230492 2026] [security2:error] [pid 914912:tid 915153] [client 78.167.1.90:55640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua6q469-jfU7M1CLh0_AAAAG8"]
[Thu Jul 30 13:41:46.336589 2026] [security2:error] [pid 914912:tid 915127] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amua6a469-jfU7M1CLh07wAAAFU"]
[Thu Jul 30 13:41:48.838659 2026] [security2:error] [pid 914912:tid 915109] [client 186.84.90.14:16426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amua7K469-jfU7M1CLh1QAAAAEM"], referer: http://pkf.jo
[Thu Jul 30 13:41:48.845924 2026] [core:notice] [pid 914912:tid 915070] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:49.934046 2026] [security2:error] [pid 914912:tid 915116] [client 172.202.44.182:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/f35.php"] [unique_id "amua7a469-jfU7M1CLh1XgAAAEo"]
[Thu Jul 30 13:41:51.442058 2026] [security2:error] [pid 914912:tid 915064] [client 172.202.44.182:49925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/new.php"] [unique_id "amua76469-jfU7M1CLh1gQAAABY"]
[Thu Jul 30 13:41:51.442360 2026] [proxy:error] [pid 914912:tid 915100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:51.442442 2026] [proxy_http:error] [pid 914912:tid 915100] [client 44.213.206.96:44057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:51.443100 2026] [proxy:error] [pid 914912:tid 915100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:51.443171 2026] [proxy_http:error] [pid 914912:tid 915100] [client 44.213.206.96:44057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:51.457853 2026] [proxy:error] [pid 914912:tid 915153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:51.457921 2026] [proxy_http:error] [pid 914912:tid 915153] [client 3.225.222.228:53104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:51.458521 2026] [proxy:error] [pid 914912:tid 915153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:51.458567 2026] [proxy_http:error] [pid 914912:tid 915153] [client 3.225.222.228:53104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:51.474810 2026] [autoindex:error] [pid 914912:tid 915127] [client 44.213.206.96:0] AH01276: Cannot serve directory /home1/pnadjbte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:41:51.508631 2026] [security2:error] [pid 914912:tid 915034] [remote 57.141.0.27:25762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amua76469-jfU7M1CLh1iQAAXHk"]
[Thu Jul 30 13:41:51.723629 2026] [security2:error] [pid 914912:tid 915119] [client 104.254.90.251:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amua76469-jfU7M1CLh1kgAAAE0"]
[Thu Jul 30 13:41:51.723745 2026] [security2:error] [pid 914912:tid 915119] [client 104.254.90.251:50196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amua76469-jfU7M1CLh1kgAAAE0"]
[Thu Jul 30 13:41:51.910429 2026] [security2:error] [pid 914912:tid 915167] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amua76469-jfU7M1CLh1fQAAAH0"]
[Thu Jul 30 13:41:53.433920 2026] [security2:error] [pid 914912:tid 915130] [client 103.242.199.184:62997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua8a469-jfU7M1CLh1uAAAAFg"]
[Thu Jul 30 13:41:53.434146 2026] [security2:error] [pid 914912:tid 915130] [client 103.242.199.184:62997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua8a469-jfU7M1CLh1uAAAAFg"]
[Thu Jul 30 13:41:53.601445 2026] [security2:error] [pid 914912:tid 915071] [client 172.202.44.182:49928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/adminfuns.php"] [unique_id "amua8a469-jfU7M1CLh1ugAAAB0"]
[Thu Jul 30 13:41:54.599864 2026] [security2:error] [pid 914912:tid 915061] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amua8q469-jfU7M1CLh10wAAABM"]
[Thu Jul 30 13:41:55.562134 2026] [security2:error] [pid 914912:tid 915123] [client 172.237.109.114:50287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amua8q469-jfU7M1CLh14AAAAFE"]
[Thu Jul 30 13:41:55.758657 2026] [core:notice] [pid 914912:tid 914985] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:56.605886 2026] [core:notice] [pid 914912:tid 915007] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:56.790622 2026] [security2:error] [pid 914912:tid 915068] [client 78.167.1.90:54111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua9K469-jfU7M1CLh2EwAAABo"]
[Thu Jul 30 13:41:56.791094 2026] [security2:error] [pid 914912:tid 915068] [client 78.167.1.90:54111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua9K469-jfU7M1CLh2EwAAABo"]
[Thu Jul 30 13:41:56.897801 2026] [core:notice] [pid 914912:tid 915009] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:57.177031 2026] [core:notice] [pid 914912:tid 915013] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:41:59.339585 2026] [security2:error] [pid 914912:tid 915163] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amua9q469-jfU7M1CLh2PwAAeXc"]
[Thu Jul 30 13:41:59.568721 2026] [security2:error] [pid 914912:tid 915029] [remote 216.73.217.142:16600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amua96469-jfU7M1CLh2TQAAAHQ"]
[Thu Jul 30 13:41:59.605157 2026] [core:error] [pid 914912:tid 915002] [remote 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:41:59.605178 2026] [core:error] [pid 914912:tid 915002] [remote 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:41:59.605335 2026] [security2:error] [pid 914912:tid 915080] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "nimna.lk"] [uri "/index.php"] [unique_id "amua96469-jfU7M1CLh2TgAAJlk"]
[Thu Jul 30 13:41:59.674307 2026] [proxy:error] [pid 914912:tid 915110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:59.674524 2026] [proxy_http:error] [pid 914912:tid 915110] [client 172.202.44.182:49751] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:59.675359 2026] [proxy:error] [pid 914912:tid 915110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:41:59.675415 2026] [proxy_http:error] [pid 914912:tid 915110] [client 172.202.44.182:49751] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:41:59.685478 2026] [security2:error] [pid 914912:tid 915043] [client 185.191.171.4:28052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/12/vacina-contra-covid-19-x-vacina-contra-a-gripe-o-que-voce-precisa-saber/"] [unique_id "amua96469-jfU7M1CLh2VAAAAAE"]
[Thu Jul 30 13:41:59.685607 2026] [security2:error] [pid 914912:tid 915043] [client 185.191.171.4:28052] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/12/vacina-contra-covid-19-x-vacina-contra-a-gripe-o-que-voce-precisa-saber/"] [unique_id "amua96469-jfU7M1CLh2VAAAAAE"]
[Thu Jul 30 13:42:01.138096 2026] [security2:error] [pid 914912:tid 914914] [remote 5.161.62.209:32764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.embassyinislamabadad.com"] [uri "/.env"] [unique_id "amua-a469-jfU7M1CLh2cAAAIAE"]
[Thu Jul 30 13:42:01.832334 2026] [security2:error] [pid 914912:tid 915064] [client 85.208.96.206:56852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/robots.txt"] [unique_id "amua-a469-jfU7M1CLh2gAAAABY"]
[Thu Jul 30 13:42:01.832517 2026] [security2:error] [pid 914912:tid 915064] [client 85.208.96.206:56852] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "online-hope.com"] [uri "/robots.txt"] [unique_id "amua-a469-jfU7M1CLh2gAAAABY"]
[Thu Jul 30 13:42:02.708988 2026] [proxy:error] [pid 914912:tid 915156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:02.709072 2026] [proxy_http:error] [pid 914912:tid 915156] [client 172.202.44.182:49729] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:02.709635 2026] [proxy:error] [pid 914912:tid 915156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:02.709677 2026] [proxy_http:error] [pid 914912:tid 915156] [client 172.202.44.182:49729] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:02.778674 2026] [security2:error] [pid 914912:tid 915167] [client 185.191.171.9:13366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product/peace-3/"] [unique_id "amua-q469-jfU7M1CLh2kQAAAH0"]
[Thu Jul 30 13:42:02.778812 2026] [security2:error] [pid 914912:tid 915167] [client 185.191.171.9:13366] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "online-hope.com"] [uri "/product/peace-3/"] [unique_id "amua-q469-jfU7M1CLh2kQAAAH0"]
[Thu Jul 30 13:42:03.050619 2026] [security2:error] [pid 914912:tid 915024] [remote 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baitultateeqmoverscompany.com"] [uri "/wp/wp-login.php"] [unique_id "amua-6469-jfU7M1CLh2mwAACm8"]
[Thu Jul 30 13:42:03.512872 2026] [core:notice] [pid 914912:tid 915092] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:03.516841 2026] [security2:error] [pid 914912:tid 915092] [client 195.23.32.200:38220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/feed/"] [unique_id "amua-6469-jfU7M1CLh2pgAAADI"]
[Thu Jul 30 13:42:04.093996 2026] [security2:error] [pid 914912:tid 915161] [client 103.242.199.184:63535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua_K469-jfU7M1CLh2sAAAAHc"]
[Thu Jul 30 13:42:04.094131 2026] [security2:error] [pid 914912:tid 915161] [client 103.242.199.184:63535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amua_K469-jfU7M1CLh2sAAAAHc"]
[Thu Jul 30 13:42:04.722474 2026] [core:notice] [pid 914912:tid 915065] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:04.727413 2026] [security2:error] [pid 914912:tid 915065] [client 195.23.32.200:38346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/feed/"] [unique_id "amua_K469-jfU7M1CLh2vQAAABc"]
[Thu Jul 30 13:42:04.849558 2026] [security2:error] [pid 914912:tid 915112] [client 104.254.90.251:36022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amua_K469-jfU7M1CLh2vgAAAEY"]
[Thu Jul 30 13:42:04.849657 2026] [security2:error] [pid 914912:tid 915112] [client 104.254.90.251:36022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amua_K469-jfU7M1CLh2vgAAAEY"]
[Thu Jul 30 13:42:05.024141 2026] [core:notice] [pid 914912:tid 914942] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:05.319108 2026] [security2:error] [pid 914912:tid 915110] [client 216.236.36.26:22064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2012/08/shopping-a-miami-bal-harbour-shops.jpg"] [unique_id "amua_a469-jfU7M1CLh2ygAAAEQ"]
[Thu Jul 30 13:42:05.537936 2026] [core:notice] [pid 914912:tid 915049] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:06.322339 2026] [security2:error] [pid 914912:tid 915052] [client 195.23.32.200:38442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amua_a469-jfU7M1CLh22AAAAAo"]
[Thu Jul 30 13:42:06.833002 2026] [core:notice] [pid 914912:tid 915070] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:07.389761 2026] [security2:error] [pid 914912:tid 915079] [client 78.167.1.90:54660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua_6469-jfU7M1CLh2_gAAACU"]
[Thu Jul 30 13:42:07.393970 2026] [security2:error] [pid 914912:tid 915079] [client 78.167.1.90:54660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amua_6469-jfU7M1CLh2_gAAACU"]
[Thu Jul 30 13:42:07.453117 2026] [security2:error] [pid 914912:tid 915127] [client 57.141.0.43:29562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amua_6469-jfU7M1CLh28wAAVSw"], referer: https://igetvape-australia.com/store/?product-page=12&add-to-cart=172
[Thu Jul 30 13:42:07.634330 2026] [core:notice] [pid 914912:tid 915068] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:07.753453 2026] [security2:error] [pid 914912:tid 915020] [remote 216.73.217.142:18376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amua_6469-jfU7M1CLh3EQAAUGs"]
[Thu Jul 30 13:42:09.315122 2026] [core:notice] [pid 914912:tid 914953] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:09.481385 2026] [security2:error] [pid 914912:tid 915169] [client 37.46.199.86:35328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amubAa469-jfU7M1CLh3PQAAAH8"]
[Thu Jul 30 13:42:09.481492 2026] [security2:error] [pid 914912:tid 915169] [client 37.46.199.86:35328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amubAa469-jfU7M1CLh3PQAAAH8"]
[Thu Jul 30 13:42:09.575779 2026] [security2:error] [pid 914912:tid 915014] [remote 216.73.217.142:18376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amubAa469-jfU7M1CLh3QQAAamU"]
[Thu Jul 30 13:42:09.843049 2026] [security2:error] [pid 914912:tid 915126] [client 172.202.44.182:49787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/fm.php"] [unique_id "amubAa469-jfU7M1CLh3SgAAAFQ"]
[Thu Jul 30 13:42:10.042384 2026] [security2:error] [pid 914912:tid 915117] [client 20.104.18.253:5841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/ea3f.php"] [unique_id "amubAq469-jfU7M1CLh3TgAAAEs"]
[Thu Jul 30 13:42:10.171317 2026] [core:notice] [pid 914912:tid 914969] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:10.662419 2026] [security2:error] [pid 914912:tid 915143] [client 20.104.18.253:5870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/eagle.php"] [unique_id "amubAq469-jfU7M1CLh3WgAAAGU"]
[Thu Jul 30 13:42:10.794435 2026] [core:notice] [pid 914912:tid 914974] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:11.145373 2026] [security2:error] [pid 914912:tid 915101] [client 85.208.96.197:47444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/09/ministerio-publico-recomenda-exoneracao-de-contratados-temporarios-em-mamanguape-e-realizacao-de-concurso-publico/"] [unique_id "amubA6469-jfU7M1CLh3ZgAAADs"]
[Thu Jul 30 13:42:11.145508 2026] [security2:error] [pid 914912:tid 915101] [client 85.208.96.197:47444] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/09/ministerio-publico-recomenda-exoneracao-de-contratados-temporarios-em-mamanguape-e-realizacao-de-concurso-publico/"] [unique_id "amubA6469-jfU7M1CLh3ZgAAADs"]
[Thu Jul 30 13:42:11.261926 2026] [security2:error] [pid 914912:tid 915069] [client 20.104.18.253:6022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/ed35f.php"] [unique_id "amubA6469-jfU7M1CLh3bAAAABs"]
[Thu Jul 30 13:42:11.263653 2026] [proxy:error] [pid 914912:tid 915152] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:11.263732 2026] [proxy_http:error] [pid 914912:tid 915152] [client 172.202.44.182:49763] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:11.265140 2026] [proxy:error] [pid 914912:tid 915152] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:11.265193 2026] [proxy_http:error] [pid 914912:tid 915152] [client 172.202.44.182:49763] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:11.608522 2026] [autoindex:error] [pid 914912:tid 915160] [client 108.129.155.37:60302] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:42:11.725151 2026] [autoindex:error] [pid 914912:tid 915114] [client 108.129.155.37:35594] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:42:11.859160 2026] [security2:error] [pid 914912:tid 915169] [client 20.104.18.253:5882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/edit-comments.php"] [unique_id "amubA6469-jfU7M1CLh3fAAAAH8"]
[Thu Jul 30 13:42:12.335377 2026] [security2:error] [pid 914912:tid 914988] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.okcasino-1.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amubBK469-jfU7M1CLh3gwAAEEs"]
[Thu Jul 30 13:42:12.398411 2026] [security2:error] [pid 914912:tid 915012] [remote 57.141.0.21:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/24984966950/feed/rss2/"] [unique_id "amubBK469-jfU7M1CLh3hwAAAGM"]
[Thu Jul 30 13:42:12.462770 2026] [security2:error] [pid 914912:tid 915126] [client 20.104.18.253:6018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/edit-form.php"] [unique_id "amubBK469-jfU7M1CLh3iAAAAFQ"]
[Thu Jul 30 13:42:13.059466 2026] [security2:error] [pid 914912:tid 915141] [client 20.104.18.253:5869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/edit-tags.php"] [unique_id "amubBa469-jfU7M1CLh3lQAAAGM"]
[Thu Jul 30 13:42:13.479317 2026] [security2:error] [pid 914912:tid 915143] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubBK469-jfU7M1CLh3kQAAZW0"]
[Thu Jul 30 13:42:13.490668 2026] [core:notice] [pid 914912:tid 915033] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:13.662693 2026] [security2:error] [pid 914912:tid 915133] [client 20.104.18.253:5848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/edit-wolf.php"] [unique_id "amubBa469-jfU7M1CLh3oAAAAFs"]
[Thu Jul 30 13:42:13.738794 2026] [security2:error] [pid 914912:tid 915110] [client 172.202.44.182:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file.php"] [unique_id "amubBa469-jfU7M1CLh3oQAAAEQ"]
[Thu Jul 30 13:42:14.265844 2026] [security2:error] [pid 914912:tid 915139] [client 20.104.18.253:5887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/edit.php"] [unique_id "amubBq469-jfU7M1CLh3sQAAAGE"]
[Thu Jul 30 13:42:14.453796 2026] [security2:error] [pid 914912:tid 915070] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubBa469-jfU7M1CLh3pQAAHE8"]
[Thu Jul 30 13:42:14.523967 2026] [autoindex:error] [pid 914912:tid 915075] [client 108.129.155.37:60318] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:42:14.679033 2026] [autoindex:error] [pid 914912:tid 915049] [client 108.129.155.37:35598] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:42:14.770580 2026] [security2:error] [pid 914912:tid 915091] [client 103.242.199.184:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubBq469-jfU7M1CLh3wQAAADE"]
[Thu Jul 30 13:42:14.770696 2026] [security2:error] [pid 914912:tid 915091] [client 103.242.199.184:64075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubBq469-jfU7M1CLh3wQAAADE"]
[Thu Jul 30 13:42:14.774199 2026] [core:error] [pid 914912:tid 915085] [client 158.69.55.148:27186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:42:14.774215 2026] [core:error] [pid 914912:tid 915085] [client 158.69.55.148:27186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:42:14.855381 2026] [security2:error] [pid 914912:tid 915159] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.okcasino-1.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amubBq469-jfU7M1CLh3yAAAAHU"]
[Thu Jul 30 13:42:14.867598 2026] [security2:error] [pid 914912:tid 915076] [client 20.104.18.253:6031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/editor.php"] [unique_id "amubBq469-jfU7M1CLh3ygAAACI"]
[Thu Jul 30 13:42:14.938206 2026] [security2:error] [pid 914912:tid 915104] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubBq469-jfU7M1CLh3sgAAAD4"]
[Thu Jul 30 13:42:15.473662 2026] [security2:error] [pid 914912:tid 915098] [client 20.104.18.253:5824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/editor/filemanager.php"] [unique_id "amubB6469-jfU7M1CLh32wAAADg"]
[Thu Jul 30 13:42:15.529468 2026] [core:error] [pid 914912:tid 915110] [client 158.69.55.148:10887] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:42:15.529492 2026] [core:error] [pid 914912:tid 915110] [client 158.69.55.148:10887] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:42:16.069455 2026] [security2:error] [pid 914912:tid 915094] [client 20.104.18.253:5837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/editor/filemanager/updates.php"] [unique_id "amubCK469-jfU7M1CLh36AAAADQ"]
[Thu Jul 30 13:42:16.136678 2026] [proxy:error] [pid 914912:tid 915115] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:16.136777 2026] [proxy_http:error] [pid 914912:tid 915115] [client 172.202.44.182:49776] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:16.137392 2026] [proxy:error] [pid 914912:tid 915115] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:16.137438 2026] [proxy_http:error] [pid 914912:tid 915115] [client 172.202.44.182:49776] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:16.716928 2026] [security2:error] [pid 914912:tid 915124] [client 20.104.18.253:5844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/ee.php"] [unique_id "amubCK469-jfU7M1CLh3-gAAAFI"]
[Thu Jul 30 13:42:16.959381 2026] [core:notice] [pid 914912:tid 914935] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:17.078604 2026] [security2:error] [pid 914912:tid 915074] [client 172.237.109.114:21966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/admin/pma/server_import.php"] [unique_id "amubCa469-jfU7M1CLh4BgAAACA"]
[Thu Jul 30 13:42:17.081668 2026] [security2:error] [pid 914912:tid 915125] [client 172.237.109.114:59438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/db/server_import.php"] [unique_id "amubCa469-jfU7M1CLh4BwAAAFM"]
[Thu Jul 30 13:42:17.094657 2026] [security2:error] [pid 914912:tid 915121] [client 172.237.109.114:26791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/phpMyAdmin/server_import.php"] [unique_id "amubCa469-jfU7M1CLh4CQAAAE8"]
[Thu Jul 30 13:42:17.124830 2026] [security2:error] [pid 914912:tid 915106] [client 172.237.109.114:1355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/pma/server_import.php"] [unique_id "amubCa469-jfU7M1CLh4CgAAAEA"]
[Thu Jul 30 13:42:17.124867 2026] [security2:error] [pid 914912:tid 915142] [client 172.237.109.114:4844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/PMA/server_import.php"] [unique_id "amubCa469-jfU7M1CLh4CwAAAGQ"]
[Thu Jul 30 13:42:17.124904 2026] [security2:error] [pid 914912:tid 915149] [client 172.237.109.114:49399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/server_import.php"] [unique_id "amubCa469-jfU7M1CLh4DAAAAGs"]
[Thu Jul 30 13:42:17.126499 2026] [security2:error] [pid 914912:tid 915161] [client 172.237.109.114:28309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/admin/server_import.php"] [unique_id "amubCa469-jfU7M1CLh4DQAAAHc"]
[Thu Jul 30 13:42:17.151212 2026] [security2:error] [pid 914912:tid 915102] [client 172.237.109.114:48527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/admin/phpMyAdmin/server_import.php"] [unique_id "amubCa469-jfU7M1CLh4DgAAADw"]
[Thu Jul 30 13:42:17.151232 2026] [security2:error] [pid 914912:tid 915064] [client 172.237.109.114:59673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/phpmyadmin/server_import.php"] [unique_id "amubCa469-jfU7M1CLh4DwAAABY"]
[Thu Jul 30 13:42:17.412463 2026] [security2:error] [pid 914912:tid 915110] [client 20.104.18.253:5860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/ee8.php"] [unique_id "amubCa469-jfU7M1CLh4EQAAAEQ"]
[Thu Jul 30 13:42:17.625788 2026] [core:notice] [pid 914912:tid 914917] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:17.981761 2026] [security2:error] [pid 914912:tid 915136] [client 78.167.1.90:53689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubCa469-jfU7M1CLh4HQAAAF4"]
[Thu Jul 30 13:42:17.982287 2026] [security2:error] [pid 914912:tid 915136] [client 78.167.1.90:53689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubCa469-jfU7M1CLh4HQAAAF4"]
[Thu Jul 30 13:42:18.156995 2026] [security2:error] [pid 914912:tid 915063] [client 20.104.18.253:6057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/eew.php"] [unique_id "amubCq469-jfU7M1CLh4JQAAABU"]
[Thu Jul 30 13:42:18.285503 2026] [core:notice] [pid 914912:tid 915052] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:18.764362 2026] [security2:error] [pid 914912:tid 915097] [client 20.104.18.253:6017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/el.php"] [unique_id "amubCq469-jfU7M1CLh4NgAAADc"]
[Thu Jul 30 13:42:19.025475 2026] [security2:error] [pid 914912:tid 914964] [remote 74.7.243.224:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amubC6469-jfU7M1CLh4OQAAZjM"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 13:42:19.320718 2026] [security2:error] [pid 914912:tid 915167] [client 91.192.10.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4QgAAAH0"]
[Thu Jul 30 13:42:19.416555 2026] [security2:error] [pid 914912:tid 915064] [client 20.104.18.253:5877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/elementor/wp-error_log.php"] [unique_id "amubC6469-jfU7M1CLh4RwAAABY"]
[Thu Jul 30 13:42:19.591001 2026] [security2:error] [pid 914912:tid 915094] [client 91.192.10.101:49840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/.env"] [unique_id "amubC6469-jfU7M1CLh4UAAAADQ"]
[Thu Jul 30 13:42:19.642914 2026] [security2:error] [pid 914912:tid 915042] [client 91.192.10.101:59604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/backend/.env"] [unique_id "amubC6469-jfU7M1CLh4YAAAAAA"]
[Thu Jul 30 13:42:19.642992 2026] [security2:error] [pid 914912:tid 915134] [client 91.192.10.101:59616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lxw.gpl.temporary.site"] [uri "/api/.env"] [unique_id "amubC6469-jfU7M1CLh4YQAAAFw"]
[Thu Jul 30 13:42:19.727164 2026] [security2:error] [pid 914912:tid 915083] [client 91.192.10.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4TwAAACk"]
[Thu Jul 30 13:42:19.793148 2026] [security2:error] [pid 914912:tid 915107] [client 91.192.10.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4WgAAAEE"]
[Thu Jul 30 13:42:19.824482 2026] [security2:error] [pid 914912:tid 915066] [client 91.192.10.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4agAAABg"]
[Thu Jul 30 13:42:19.824801 2026] [security2:error] [pid 914912:tid 915082] [client 91.192.10.101:59622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4ZwAAACg"]
[Thu Jul 30 13:42:19.826471 2026] [security2:error] [pid 914912:tid 915117] [client 91.192.10.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4aAAAAEs"]
[Thu Jul 30 13:42:19.827517 2026] [security2:error] [pid 914912:tid 915068] [client 91.192.10.101:59636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4YgAAABo"]
[Thu Jul 30 13:42:19.833680 2026] [security2:error] [pid 914912:tid 915103] [client 91.192.10.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4awAAAD0"]
[Thu Jul 30 13:42:19.833681 2026] [security2:error] [pid 914912:tid 915045] [client 91.192.10.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lxw.gpl.temporary.site"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4aQAAAAM"]
[Thu Jul 30 13:42:20.265991 2026] [security2:error] [pid 914912:tid 915104] [client 20.104.18.253:5828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/elementor/wp-login.php"] [unique_id "amubDK469-jfU7M1CLh4dwAAAD4"]
[Thu Jul 30 13:42:20.279150 2026] [security2:error] [pid 914912:tid 915109] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4SwAAQxE"]
[Thu Jul 30 13:42:20.531700 2026] [security2:error] [pid 914912:tid 915145] [client 74.7.241.146:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.filmtvyap.com"] [uri "/index.php"] [unique_id "amubC6469-jfU7M1CLh4SgAAAGc"]
[Thu Jul 30 13:42:20.532884 2026] [security2:error] [pid 914912:tid 915061] [client 74.7.241.146:35982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.filmtvyap.com"] [uri "/robots.txt"] [unique_id "amubC6469-jfU7M1CLh4SAAAExA"]
[Thu Jul 30 13:42:20.865464 2026] [security2:error] [pid 914912:tid 915122] [client 20.104.18.253:5850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/elementor/wp-wjvngrh.php"] [unique_id "amubDK469-jfU7M1CLh4jAAAAFA"]
[Thu Jul 30 13:42:21.270739 2026] [security2:error] [pid 914912:tid 915085] [client 185.191.171.15:58468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2023/01/08/manifestantes-invadem-plenario-do-stf-congresso-nacional-e-palacio-do-planalto/"] [unique_id "amubDa469-jfU7M1CLh4lQAAACs"]
[Thu Jul 30 13:42:21.270870 2026] [security2:error] [pid 914912:tid 915085] [client 185.191.171.15:58468] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2023/01/08/manifestantes-invadem-plenario-do-stf-congresso-nacional-e-palacio-do-planalto/"] [unique_id "amubDa469-jfU7M1CLh4lQAAACs"]
[Thu Jul 30 13:42:21.413299 2026] [security2:error] [pid 914912:tid 915080] [client 172.202.44.182:49747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/bolt.php"] [unique_id "amubDa469-jfU7M1CLh4mQAAACY"]
[Thu Jul 30 13:42:21.467382 2026] [security2:error] [pid 914912:tid 915128] [client 20.104.18.253:6016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/elements/filemanager.php"] [unique_id "amubDa469-jfU7M1CLh4mgAAAFY"]
[Thu Jul 30 13:42:22.104244 2026] [security2:error] [pid 914912:tid 915111] [client 20.104.18.253:6036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/elements/udd.php"] [unique_id "amubDq469-jfU7M1CLh4pgAAAEU"]
[Thu Jul 30 13:42:22.211361 2026] [core:notice] [pid 914912:tid 915152] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:22.620326 2026] [core:notice] [pid 914912:tid 915098] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:22.710298 2026] [security2:error] [pid 914912:tid 915168] [client 20.104.18.253:5855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/elements/wp-2019.php"] [unique_id "amubDq469-jfU7M1CLh4tAAAAH4"]
[Thu Jul 30 13:42:22.712838 2026] [proxy:error] [pid 914912:tid 915099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:22.712896 2026] [proxy_http:error] [pid 914912:tid 915099] [client 3.228.112.215:44615] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:22.713457 2026] [proxy:error] [pid 914912:tid 915099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:22.713511 2026] [proxy_http:error] [pid 914912:tid 915099] [client 3.228.112.215:44615] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:22.745678 2026] [proxy:error] [pid 914912:tid 915145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:22.745763 2026] [proxy_http:error] [pid 914912:tid 915145] [client 3.228.112.215:6709] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:22.746361 2026] [proxy:error] [pid 914912:tid 915145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:22.746407 2026] [proxy_http:error] [pid 914912:tid 915145] [client 3.228.112.215:6709] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:23.164101 2026] [security2:error] [pid 914912:tid 914987] [remote 104.248.125.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.125.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "applinex.pro"] [uri "/wp-login.php"] [unique_id "amubD6469-jfU7M1CLh4ygAAeko"]
[Thu Jul 30 13:42:23.310712 2026] [security2:error] [pid 914912:tid 915150] [client 20.104.18.253:5829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/elp.php"] [unique_id "amubD6469-jfU7M1CLh4zAAAAGw"]
[Thu Jul 30 13:42:23.589165 2026] [proxy:error] [pid 914912:tid 915082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:23.589259 2026] [proxy_http:error] [pid 914912:tid 915082] [client 3.228.112.215:5428] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:23.590130 2026] [proxy:error] [pid 914912:tid 915082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:23.590196 2026] [proxy_http:error] [pid 914912:tid 915082] [client 3.228.112.215:5428] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:23.612546 2026] [proxy:error] [pid 914912:tid 915110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:23.612643 2026] [proxy_http:error] [pid 914912:tid 915110] [client 54.87.222.253:28319] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:23.613713 2026] [proxy:error] [pid 914912:tid 915110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:23.613783 2026] [proxy_http:error] [pid 914912:tid 915110] [client 54.87.222.253:28319] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:23.947566 2026] [security2:error] [pid 914912:tid 915124] [client 20.104.18.253:5866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/email.php"] [unique_id "amubD6469-jfU7M1CLh46AAAAFI"]
[Thu Jul 30 13:42:24.460231 2026] [core:notice] [pid 914912:tid 915119] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:24.545914 2026] [security2:error] [pid 914912:tid 915061] [client 20.104.18.253:5843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/endpoints/atomlib.php"] [unique_id "amubEK469-jfU7M1CLh4-gAAABM"]
[Thu Jul 30 13:42:25.157936 2026] [security2:error] [pid 914912:tid 915083] [client 20.104.18.253:5883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/endpoints/class-wp-rest-attachment-controller.php"] [unique_id "amubEa469-jfU7M1CLh5BwAAACk"]
[Thu Jul 30 13:42:25.385941 2026] [security2:error] [pid 914912:tid 915056] [client 103.242.199.184:64606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubEa469-jfU7M1CLh5CwAAAA4"]
[Thu Jul 30 13:42:25.386107 2026] [security2:error] [pid 914912:tid 915056] [client 103.242.199.184:64606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubEa469-jfU7M1CLh5CwAAAA4"]
[Thu Jul 30 13:42:25.510250 2026] [security2:error] [pid 914912:tid 915154] [client 172.202.44.182:49927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/3.php"] [unique_id "amubEa469-jfU7M1CLh5FAAAAHA"]
[Thu Jul 30 13:42:25.753081 2026] [security2:error] [pid 914912:tid 915153] [client 20.104.18.253:5867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/endpoints/index.php"] [unique_id "amubEa469-jfU7M1CLh5GQAAAG8"]
[Thu Jul 30 13:42:26.353109 2026] [security2:error] [pid 914912:tid 915043] [client 20.104.18.253:6029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/env.php"] [unique_id "amubEq469-jfU7M1CLh5JAAAAAE"]
[Thu Jul 30 13:42:26.393101 2026] [security2:error] [pid 914912:tid 914918] [remote 72.167.132.114:34962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wce.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amubEq469-jfU7M1CLh5JQAAZgU"]
[Thu Jul 30 13:42:26.949803 2026] [security2:error] [pid 914912:tid 915089] [client 20.104.18.253:5853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/envato-css.php"] [unique_id "amubEq469-jfU7M1CLh5MQAAAC8"]
[Thu Jul 30 13:42:27.586261 2026] [security2:error] [pid 914912:tid 915076] [client 20.104.18.253:5868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/envato-market/inc/class-envato-market-github.php"] [unique_id "amubE6469-jfU7M1CLh5QgAAACI"]
[Thu Jul 30 13:42:27.994932 2026] [security2:error] [pid 914912:tid 915154] [client 74.7.241.171:41604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.bookario.com"] [uri "/cgi-sys/404.html"] [unique_id "amubE6469-jfU7M1CLh5SQAAcH4"]
[Thu Jul 30 13:42:28.185222 2026] [security2:error] [pid 914912:tid 915117] [client 20.104.18.253:5861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/envs.php"] [unique_id "amubFK469-jfU7M1CLh5UwAAAEs"]
[Thu Jul 30 13:42:28.520863 2026] [security2:error] [pid 914912:tid 915104] [client 78.167.1.90:54073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubFK469-jfU7M1CLh5WQAAAD4"]
[Thu Jul 30 13:42:28.521405 2026] [security2:error] [pid 914912:tid 915104] [client 78.167.1.90:54073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubFK469-jfU7M1CLh5WQAAAD4"]
[Thu Jul 30 13:42:28.602364 2026] [core:notice] [pid 914912:tid 915169] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:28.822658 2026] [security2:error] [pid 914912:tid 915146] [client 20.104.18.253:6025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/epinyins.php"] [unique_id "amubFK469-jfU7M1CLh5aAAAAGg"]
[Thu Jul 30 13:42:29.186638 2026] [security2:error] [pid 914912:tid 914920] [remote 5.182.209.54:54882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahm.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amubFa469-jfU7M1CLh5dQAAVAc"]
[Thu Jul 30 13:42:29.443584 2026] [security2:error] [pid 914912:tid 915095] [client 20.104.18.253:5835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aded-rdc.org"] [uri "/erinyani/asasx.php"] [unique_id "amubFa469-jfU7M1CLh5eAAAADU"]
[Thu Jul 30 13:42:29.648236 2026] [core:notice] [pid 914912:tid 914923] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:30.261439 2026] [security2:error] [pid 914912:tid 915151] [client 54.169.131.194:21890] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-mevius.com"] [uri "/robots.txt"] [unique_id "amubFq469-jfU7M1CLh5kwAAAG0"]
[Thu Jul 30 13:42:30.284906 2026] [security2:error] [pid 914912:tid 915067] [client 135.119.63.61:5878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cakiltheme/idx.php"] [unique_id "amubFq469-jfU7M1CLh5lAAAABk"]
[Thu Jul 30 13:42:30.405434 2026] [core:notice] [pid 914912:tid 914938] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:30.439020 2026] [autoindex:error] [pid 914912:tid 915062] [client 98.87.102.177:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:42:30.454818 2026] [proxy:error] [pid 914912:tid 915133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:30.454885 2026] [proxy_http:error] [pid 914912:tid 915133] [client 18.211.55.47:1737] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:30.455457 2026] [proxy:error] [pid 914912:tid 915133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:30.455510 2026] [proxy_http:error] [pid 914912:tid 915133] [client 18.211.55.47:1737] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:30.467320 2026] [proxy:error] [pid 914912:tid 915074] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:30.467403 2026] [proxy_http:error] [pid 914912:tid 915074] [client 18.211.55.47:16052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:30.468005 2026] [proxy:error] [pid 914912:tid 915074] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:30.468054 2026] [proxy_http:error] [pid 914912:tid 915074] [client 18.211.55.47:16052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:30.507785 2026] [autoindex:error] [pid 914912:tid 915059] [client 44.216.125.112:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:42:31.034055 2026] [core:notice] [pid 914912:tid 914915] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:31.052087 2026] [security2:error] [pid 914912:tid 915090] [client 135.119.63.61:52117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cakiltheme/up.php"] [unique_id "amubF6469-jfU7M1CLh5swAAADA"]
[Thu Jul 30 13:42:31.403797 2026] [security2:error] [pid 914912:tid 915120] [client 74.7.244.10:52850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "zha.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amubF6469-jfU7M1CLh5vgAAAE4"]
[Thu Jul 30 13:42:31.518217 2026] [security2:error] [pid 914912:tid 915076] [client 74.7.241.147:33082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.zha.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amubF6469-jfU7M1CLh5vwAAACI"]
[Thu Jul 30 13:42:31.616903 2026] [security2:error] [pid 914912:tid 915063] [client 172.237.109.114:62684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubF6469-jfU7M1CLh5sQAAABU"]
[Thu Jul 30 13:42:31.647818 2026] [security2:error] [pid 914912:tid 915087] [client 172.202.44.182:49783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/222.php"] [unique_id "amubF6469-jfU7M1CLh5wQAAAC0"]
[Thu Jul 30 13:42:31.825183 2026] [security2:error] [pid 914912:tid 915073] [client 135.119.63.61:34386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/calendar/index.php"] [unique_id "amubF6469-jfU7M1CLh5ywAAAB8"]
[Thu Jul 30 13:42:32.637059 2026] [security2:error] [pid 914912:tid 915145] [client 135.119.63.61:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/canonical.php"] [unique_id "amubGK469-jfU7M1CLh6AwAAAGc"]
[Thu Jul 30 13:42:32.729935 2026] [security2:error] [pid 914912:tid 915109] [client 20.197.178.120:28880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amubGK469-jfU7M1CLh6BwAAAEM"]
[Thu Jul 30 13:42:32.730126 2026] [security2:error] [pid 914912:tid 915109] [client 20.197.178.120:28880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amubGK469-jfU7M1CLh6BwAAAEM"]
[Thu Jul 30 13:42:33.273374 2026] [core:error] [pid 914912:tid 915058] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:42:33.273395 2026] [core:error] [pid 914912:tid 915058] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:42:33.398505 2026] [security2:error] [pid 914912:tid 915089] [client 20.197.178.120:28882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amubGa469-jfU7M1CLh6HAAAAC8"]
[Thu Jul 30 13:42:33.398613 2026] [security2:error] [pid 914912:tid 915089] [client 20.197.178.120:28882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amubGa469-jfU7M1CLh6HAAAAC8"]
[Thu Jul 30 13:42:33.438561 2026] [security2:error] [pid 914912:tid 915146] [client 135.119.63.61:5885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/catalogadmin.php"] [unique_id "amubGa469-jfU7M1CLh6HgAAAGg"]
[Thu Jul 30 13:42:33.815335 2026] [core:notice] [pid 914912:tid 914983] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:34.012050 2026] [security2:error] [pid 914912:tid 915066] [client 20.197.178.120:28885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/wicked.php"] [unique_id "amubGq469-jfU7M1CLh6cwAAABg"]
[Thu Jul 30 13:42:34.012182 2026] [security2:error] [pid 914912:tid 915066] [client 20.197.178.120:28885] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/wicked.php"] [unique_id "amubGq469-jfU7M1CLh6cwAAABg"]
[Thu Jul 30 13:42:34.249679 2026] [security2:error] [pid 914912:tid 915154] [client 135.119.63.61:52097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/catalogalfa.php"] [unique_id "amubGq469-jfU7M1CLh6dQAAAHA"]
[Thu Jul 30 13:42:34.649135 2026] [security2:error] [pid 914912:tid 915059] [client 20.197.178.120:28884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/wpx.php"] [unique_id "amubGq469-jfU7M1CLh6iwAAABE"]
[Thu Jul 30 13:42:34.649224 2026] [security2:error] [pid 914912:tid 915059] [client 20.197.178.120:28884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/wpx.php"] [unique_id "amubGq469-jfU7M1CLh6iwAAABE"]
[Thu Jul 30 13:42:35.134306 2026] [security2:error] [pid 914912:tid 915109] [client 135.119.63.61:5846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/catalogbypass.php"] [unique_id "amubG6469-jfU7M1CLh6lwAAAEM"]
[Thu Jul 30 13:42:35.275527 2026] [security2:error] [pid 914912:tid 915132] [client 20.197.178.120:28873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/images.php"] [unique_id "amubG6469-jfU7M1CLh6mAAAAFo"]
[Thu Jul 30 13:42:35.275821 2026] [security2:error] [pid 914912:tid 915132] [client 20.197.178.120:28873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/images.php"] [unique_id "amubG6469-jfU7M1CLh6mAAAAFo"]
[Thu Jul 30 13:42:35.705604 2026] [security2:error] [pid 914912:tid 914950] [remote 20.233.187.247:28767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.eow.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amubG6469-jfU7M1CLh6pgAAbCU"]
[Thu Jul 30 13:42:35.881930 2026] [security2:error] [pid 914912:tid 915110] [client 20.197.178.120:29422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/1xmomo.php"] [unique_id "amubG6469-jfU7M1CLh6qwAAAEQ"]
[Thu Jul 30 13:42:35.882060 2026] [security2:error] [pid 914912:tid 915110] [client 20.197.178.120:29422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/1xmomo.php"] [unique_id "amubG6469-jfU7M1CLh6qwAAAEQ"]
[Thu Jul 30 13:42:35.930950 2026] [security2:error] [pid 914912:tid 915080] [client 103.242.199.184:65140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubG6469-jfU7M1CLh6rAAAACY"]
[Thu Jul 30 13:42:35.931075 2026] [security2:error] [pid 914912:tid 915080] [client 103.242.199.184:65140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubG6469-jfU7M1CLh6rAAAACY"]
[Thu Jul 30 13:42:36.066621 2026] [security2:error] [pid 914912:tid 915094] [client 135.119.63.61:52130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/catalogk.php"] [unique_id "amubHK469-jfU7M1CLh6tgAAADQ"]
[Thu Jul 30 13:42:36.501962 2026] [core:error] [pid 914912:tid 915015] [remote 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:42:36.501992 2026] [core:error] [pid 914912:tid 915015] [remote 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:42:36.502176 2026] [security2:error] [pid 914912:tid 915103] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "nimna.lk"] [uri "/index.php"] [unique_id "amubHK469-jfU7M1CLh6uwAAPWY"]
[Thu Jul 30 13:42:36.507204 2026] [security2:error] [pid 914912:tid 915143] [client 20.197.178.120:28926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/1revo.php"] [unique_id "amubHK469-jfU7M1CLh6vQAAAGU"]
[Thu Jul 30 13:42:36.507297 2026] [security2:error] [pid 914912:tid 915143] [client 20.197.178.120:28926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/1revo.php"] [unique_id "amubHK469-jfU7M1CLh6vQAAAGU"]
[Thu Jul 30 13:42:36.864702 2026] [security2:error] [pid 914912:tid 915106] [client 135.119.63.61:52159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/catalogwp.php"] [unique_id "amubHK469-jfU7M1CLh6xQAAAEA"]
[Thu Jul 30 13:42:37.118871 2026] [security2:error] [pid 914912:tid 915051] [client 20.197.178.120:28878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/cong.php"] [unique_id "amubHa469-jfU7M1CLh6zwAAAAk"]
[Thu Jul 30 13:42:37.118990 2026] [security2:error] [pid 914912:tid 915051] [client 20.197.178.120:28878] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/cong.php"] [unique_id "amubHa469-jfU7M1CLh6zwAAAAk"]
[Thu Jul 30 13:42:37.377358 2026] [proxy:error] [pid 914912:tid 915047] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:37.377441 2026] [proxy_http:error] [pid 914912:tid 915047] [client 52.202.41.153:42117] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:37.378082 2026] [proxy:error] [pid 914912:tid 915047] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:37.378133 2026] [proxy_http:error] [pid 914912:tid 915047] [client 52.202.41.153:42117] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:37.394447 2026] [autoindex:error] [pid 914912:tid 915081] [client 3.228.112.215:0] AH01276: Cannot serve directory /home1/pnadjbte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:42:37.400388 2026] [proxy:error] [pid 914912:tid 915146] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:37.400463 2026] [proxy_http:error] [pid 914912:tid 915146] [client 52.202.41.153:5421] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:37.401155 2026] [proxy:error] [pid 914912:tid 915146] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:37.401204 2026] [proxy_http:error] [pid 914912:tid 915146] [client 52.202.41.153:5421] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:37.685573 2026] [security2:error] [pid 914912:tid 915164] [client 135.119.63.61:33130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/categories/about.php"] [unique_id "amubHa469-jfU7M1CLh65AAAAHo"]
[Thu Jul 30 13:42:37.712808 2026] [security2:error] [pid 914912:tid 915080] [client 20.197.178.120:29415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/a.php"] [unique_id "amubHa469-jfU7M1CLh65QAAACY"]
[Thu Jul 30 13:42:37.712904 2026] [security2:error] [pid 914912:tid 915080] [client 20.197.178.120:29415] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/a.php"] [unique_id "amubHa469-jfU7M1CLh65QAAACY"]
[Thu Jul 30 13:42:38.329575 2026] [security2:error] [pid 914912:tid 915073] [client 20.197.178.120:28865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/srontol.php"] [unique_id "amubHq469-jfU7M1CLh68gAAAB8"]
[Thu Jul 30 13:42:38.329683 2026] [security2:error] [pid 914912:tid 915073] [client 20.197.178.120:28865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/srontol.php"] [unique_id "amubHq469-jfU7M1CLh68gAAAB8"]
[Thu Jul 30 13:42:38.416690 2026] [security2:error] [pid 914912:tid 915048] [client 135.119.63.61:52103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/category.php"] [unique_id "amubHq469-jfU7M1CLh69AAAAAY"]
[Thu Jul 30 13:42:38.876711 2026] [security2:error] [pid 914912:tid 915121] [client 172.202.44.182:49745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amubHq469-jfU7M1CLh7FgAAAE8"]
[Thu Jul 30 13:42:38.967733 2026] [security2:error] [pid 914912:tid 915163] [client 20.197.178.120:28871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/reop3.php"] [unique_id "amubHq469-jfU7M1CLh7GgAAAHk"]
[Thu Jul 30 13:42:38.967842 2026] [security2:error] [pid 914912:tid 915163] [client 20.197.178.120:28871] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/reop3.php"] [unique_id "amubHq469-jfU7M1CLh7GgAAAHk"]
[Thu Jul 30 13:42:39.231951 2026] [security2:error] [pid 914912:tid 915072] [client 135.119.63.61:52147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cay-van-phong/filemanager.php"] [unique_id "amubH6469-jfU7M1CLh7IgAAAB4"]
[Thu Jul 30 13:42:39.598081 2026] [security2:error] [pid 914912:tid 914914] [remote 216.73.217.142:11145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amubH6469-jfU7M1CLh7LwAAcgE"]
[Thu Jul 30 13:42:39.598131 2026] [security2:error] [pid 914912:tid 915096] [client 20.197.178.120:28913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/file5.php"] [unique_id "amubH6469-jfU7M1CLh7LgAAADY"]
[Thu Jul 30 13:42:39.598236 2026] [security2:error] [pid 914912:tid 915096] [client 20.197.178.120:28913] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/file5.php"] [unique_id "amubH6469-jfU7M1CLh7LgAAADY"]
[Thu Jul 30 13:42:39.694339 2026] [core:notice] [pid 914912:tid 914941] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:40.038399 2026] [security2:error] [pid 914912:tid 915056] [client 135.119.63.61:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cay-van-phong/hehe.php"] [unique_id "amubIK469-jfU7M1CLh7OQAAAA4"]
[Thu Jul 30 13:42:40.240011 2026] [security2:error] [pid 914912:tid 915097] [client 20.197.178.120:29064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/domvf.php"] [unique_id "amubIK469-jfU7M1CLh7RAAAADc"]
[Thu Jul 30 13:42:40.240193 2026] [security2:error] [pid 914912:tid 915097] [client 20.197.178.120:29064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/domvf.php"] [unique_id "amubIK469-jfU7M1CLh7RAAAADc"]
[Thu Jul 30 13:42:40.352288 2026] [core:notice] [pid 914912:tid 914916] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:40.773151 2026] [security2:error] [pid 914912:tid 915062] [client 135.119.63.61:52100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cay-van-phong/skibidi.php"] [unique_id "amubIK469-jfU7M1CLh7TwAAABQ"]
[Thu Jul 30 13:42:40.834923 2026] [security2:error] [pid 914912:tid 915067] [client 20.197.178.120:28905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/zero.php"] [unique_id "amubIK469-jfU7M1CLh7UAAAABk"]
[Thu Jul 30 13:42:40.835053 2026] [security2:error] [pid 914912:tid 915067] [client 20.197.178.120:28905] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/zero.php"] [unique_id "amubIK469-jfU7M1CLh7UAAAABk"]
[Thu Jul 30 13:42:40.855279 2026] [security2:error] [pid 914912:tid 915117] [client 172.202.44.182:49933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amubIK469-jfU7M1CLh7UgAAAEs"]
[Thu Jul 30 13:42:41.438987 2026] [security2:error] [pid 914912:tid 915129] [client 20.197.178.120:28868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/002.php"] [unique_id "amubIa469-jfU7M1CLh7YAAAAFc"]
[Thu Jul 30 13:42:41.439107 2026] [security2:error] [pid 914912:tid 915129] [client 20.197.178.120:28868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/002.php"] [unique_id "amubIa469-jfU7M1CLh7YAAAAFc"]
[Thu Jul 30 13:42:41.590757 2026] [security2:error] [pid 914912:tid 915090] [client 135.119.63.61:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cbgd.php"] [unique_id "amubIa469-jfU7M1CLh7YQAAADA"]
[Thu Jul 30 13:42:41.802654 2026] [proxy:error] [pid 914912:tid 915107] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:41.802753 2026] [proxy_http:error] [pid 914912:tid 915107] [client 34.224.175.62:53167] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:41.803829 2026] [proxy:error] [pid 914912:tid 915107] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:41.803902 2026] [proxy_http:error] [pid 914912:tid 915107] [client 34.224.175.62:53167] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:41.805958 2026] [proxy:error] [pid 914912:tid 915141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:41.806040 2026] [proxy_http:error] [pid 914912:tid 915141] [client 34.224.175.62:16657] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:41.806612 2026] [proxy:error] [pid 914912:tid 915141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:41.806655 2026] [proxy_http:error] [pid 914912:tid 915141] [client 34.224.175.62:16657] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:42.043872 2026] [security2:error] [pid 914912:tid 915080] [client 20.197.178.120:29394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/thoms.php"] [unique_id "amubIq469-jfU7M1CLh7dwAAACY"]
[Thu Jul 30 13:42:42.044000 2026] [security2:error] [pid 914912:tid 915080] [client 20.197.178.120:29394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/thoms.php"] [unique_id "amubIq469-jfU7M1CLh7dwAAACY"]
[Thu Jul 30 13:42:42.375665 2026] [security2:error] [pid 914912:tid 915057] [client 135.119.63.61:33858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cbrfo.php"] [unique_id "amubIq469-jfU7M1CLh7ggAAAA8"]
[Thu Jul 30 13:42:42.637143 2026] [security2:error] [pid 914912:tid 915143] [client 20.197.178.120:29420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/fi22.php"] [unique_id "amubIq469-jfU7M1CLh7hwAAAGU"]
[Thu Jul 30 13:42:42.637274 2026] [security2:error] [pid 914912:tid 915143] [client 20.197.178.120:29420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/fi22.php"] [unique_id "amubIq469-jfU7M1CLh7hwAAAGU"]
[Thu Jul 30 13:42:43.295752 2026] [security2:error] [pid 914912:tid 915060] [client 135.119.63.61:33865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cc.php"] [unique_id "amubI6469-jfU7M1CLh7oAAAABI"]
[Thu Jul 30 13:42:43.330590 2026] [security2:error] [pid 914912:tid 915129] [client 20.197.178.120:28876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.ejournalugj.com"] [uri "/___proxy_subdomain_webmail/wp-content/"] [unique_id "amubI6469-jfU7M1CLh7nwAAAFc"]
[Thu Jul 30 13:42:43.859497 2026] [proxy:error] [pid 914912:tid 915156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:43.859579 2026] [proxy_http:error] [pid 914912:tid 915156] [client 172.202.44.182:49778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:43.860143 2026] [proxy:error] [pid 914912:tid 915156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:43.860187 2026] [proxy_http:error] [pid 914912:tid 915156] [client 172.202.44.182:49778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:43.923096 2026] [security2:error] [pid 914912:tid 915068] [client 20.197.178.120:28876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/82.php"] [unique_id "amubI6469-jfU7M1CLh7vwAAABo"]
[Thu Jul 30 13:42:43.923203 2026] [security2:error] [pid 914912:tid 915068] [client 20.197.178.120:28876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/82.php"] [unique_id "amubI6469-jfU7M1CLh7vwAAABo"]
[Thu Jul 30 13:42:44.139936 2026] [security2:error] [pid 914912:tid 915120] [client 135.119.63.61:33125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/ccaef.php"] [unique_id "amubJK469-jfU7M1CLh7wQAAAE4"]
[Thu Jul 30 13:42:44.224138 2026] [security2:error] [pid 914912:tid 914985] [remote 57.141.0.36:20836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amubJK469-jfU7M1CLh7wwAAU0g"]
[Thu Jul 30 13:42:44.345655 2026] [core:notice] [pid 914912:tid 914954] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:44.937420 2026] [http2:info] [pid 935860:tid 935860] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 13:42:44.953456 2026] [security2:error] [pid 935860:tid 935991] [client 20.197.178.120:29423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/sx.php"] [unique_id "amubJIijB6THqIZZsUL4UgAAAIU"]
[Thu Jul 30 13:42:44.953656 2026] [security2:error] [pid 935860:tid 935991] [client 20.197.178.120:29423] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/sx.php"] [unique_id "amubJIijB6THqIZZsUL4UgAAAIU"]
[Thu Jul 30 13:42:45.238948 2026] [security2:error] [pid 935860:tid 935999] [client 135.119.63.61:33548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/ccx/index.php"] [unique_id "amubJYijB6THqIZZsUL4YwAAAI0"]
[Thu Jul 30 13:42:45.281088 2026] [security2:error] [pid 935860:tid 935871] [remote 51.75.236.146:17560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/althea-wp/"] [unique_id "amubJYijB6THqIZZsUL4ZQAAlQk"]
[Thu Jul 30 13:42:45.281418 2026] [security2:error] [pid 935860:tid 936007] [client 51.75.236.146:17560] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/althea-wp/"] [unique_id "amubJYijB6THqIZZsUL4ZQAAlQk"]
[Thu Jul 30 13:42:45.414510 2026] [autoindex:error] [pid 935860:tid 936026] [client 3.225.222.228:10960] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:42:45.442242 2026] [core:notice] [pid 935860:tid 935872] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:45.607183 2026] [security2:error] [pid 935860:tid 936047] [client 20.197.178.120:29414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/dex.php"] [unique_id "amubJYijB6THqIZZsUL4awAAAL0"]
[Thu Jul 30 13:42:45.607343 2026] [security2:error] [pid 935860:tid 936047] [client 20.197.178.120:29414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/dex.php"] [unique_id "amubJYijB6THqIZZsUL4awAAAL0"]
[Thu Jul 30 13:42:45.928018 2026] [security2:error] [pid 935860:tid 935995] [client 172.202.44.182:49922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/admin.php"] [unique_id "amubJYijB6THqIZZsUL4dAAAAIk"]
[Thu Jul 30 13:42:46.021434 2026] [security2:error] [pid 935860:tid 936054] [client 135.119.63.61:33098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cd.php"] [unique_id "amubJoijB6THqIZZsUL4dQAAAMQ"]
[Thu Jul 30 13:42:46.259294 2026] [security2:error] [pid 935860:tid 936078] [client 20.197.178.120:28910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/fpwch.php"] [unique_id "amubJoijB6THqIZZsUL4fwAAANw"]
[Thu Jul 30 13:42:46.259424 2026] [security2:error] [pid 935860:tid 936078] [client 20.197.178.120:28910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/fpwch.php"] [unique_id "amubJoijB6THqIZZsUL4fwAAANw"]
[Thu Jul 30 13:42:46.322831 2026] [core:notice] [pid 935860:tid 936071] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:46.539254 2026] [security2:error] [pid 935860:tid 936085] [client 103.242.199.184:49293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubJoijB6THqIZZsUL4hAAAAOM"]
[Thu Jul 30 13:42:46.539442 2026] [security2:error] [pid 935860:tid 936085] [client 103.242.199.184:49293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubJoijB6THqIZZsUL4hAAAAOM"]
[Thu Jul 30 13:42:46.697061 2026] [core:notice] [pid 914912:tid 914967] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:46.878923 2026] [security2:error] [pid 935860:tid 936105] [client 20.197.178.120:29405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/black.php"] [unique_id "amubJoijB6THqIZZsUL4jgAAAPc"]
[Thu Jul 30 13:42:46.879076 2026] [security2:error] [pid 935860:tid 936105] [client 20.197.178.120:29405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/black.php"] [unique_id "amubJoijB6THqIZZsUL4jgAAAPc"]
[Thu Jul 30 13:42:46.927240 2026] [security2:error] [pid 935860:tid 936093] [client 135.119.63.61:51828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cdxadmin.php"] [unique_id "amubJoijB6THqIZZsUL4jwAAAOs"]
[Thu Jul 30 13:42:47.530290 2026] [security2:error] [pid 935860:tid 936009] [client 20.197.178.120:28915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/loader.php"] [unique_id "amubJ4ijB6THqIZZsUL4mgAAAJc"]
[Thu Jul 30 13:42:47.530424 2026] [security2:error] [pid 935860:tid 936009] [client 20.197.178.120:28915] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/loader.php"] [unique_id "amubJ4ijB6THqIZZsUL4mgAAAJc"]
[Thu Jul 30 13:42:47.807087 2026] [security2:error] [pid 935860:tid 935994] [client 135.119.63.61:33573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cekidot/alf.php"] [unique_id "amubJ4ijB6THqIZZsUL4oQAAAIg"]
[Thu Jul 30 13:42:48.150305 2026] [security2:error] [pid 935860:tid 936023] [client 20.197.178.120:28927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/file61.php"] [unique_id "amubKIijB6THqIZZsUL4qAAAAKU"]
[Thu Jul 30 13:42:48.150438 2026] [security2:error] [pid 935860:tid 936023] [client 20.197.178.120:28927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/file61.php"] [unique_id "amubKIijB6THqIZZsUL4qAAAAKU"]
[Thu Jul 30 13:42:48.197219 2026] [core:notice] [pid 935860:tid 936010] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:48.210244 2026] [core:error] [pid 935860:tid 936010] [client 89.190.151.105:56779] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:42:48.210414 2026] [security2:error] [pid 935860:tid 936010] [client 89.190.151.105:56779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/login/signIn.html.html.html.html.html.html.html.html.html.html"] [unique_id "amubJ4ijB6THqIZZsUL4pQAAAJg"]
[Thu Jul 30 13:42:48.677090 2026] [security2:error] [pid 935860:tid 936042] [client 135.119.63.61:33105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cekidot/mar.php"] [unique_id "amubKIijB6THqIZZsUL4tAAAALg"]
[Thu Jul 30 13:42:48.783788 2026] [security2:error] [pid 935860:tid 936056] [client 20.197.178.120:29395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/wp-css.php"] [unique_id "amubKIijB6THqIZZsUL4uAAAAMY"]
[Thu Jul 30 13:42:48.783915 2026] [security2:error] [pid 935860:tid 936056] [client 20.197.178.120:29395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/wp-css.php"] [unique_id "amubKIijB6THqIZZsUL4uAAAAMY"]
[Thu Jul 30 13:42:48.892701 2026] [security2:error] [pid 935860:tid 936024] [client 172.202.44.182:49736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-configs.php"] [unique_id "amubKIijB6THqIZZsUL4vQAAAKY"]
[Thu Jul 30 13:42:49.508365 2026] [security2:error] [pid 935860:tid 936071] [client 20.197.178.120:29413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/wp-blink.php"] [unique_id "amubKYijB6THqIZZsUL4ygAAANU"]
[Thu Jul 30 13:42:49.508400 2026] [security2:error] [pid 935860:tid 936070] [client 135.119.63.61:33094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cekidot/mr.php"] [unique_id "amubKYijB6THqIZZsUL4ywAAANQ"]
[Thu Jul 30 13:42:49.508482 2026] [security2:error] [pid 935860:tid 936071] [client 20.197.178.120:29413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/wp-blink.php"] [unique_id "amubKYijB6THqIZZsUL4ygAAANU"]
[Thu Jul 30 13:42:49.670604 2026] [security2:error] [pid 935860:tid 936080] [client 78.167.1.90:55260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubKYijB6THqIZZsUL40wAAAN4"]
[Thu Jul 30 13:42:49.671390 2026] [security2:error] [pid 935860:tid 936080] [client 78.167.1.90:55260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubKYijB6THqIZZsUL40wAAAN4"]
[Thu Jul 30 13:42:49.791548 2026] [core:notice] [pid 935860:tid 936068] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:50.073209 2026] [security2:error] [pid 935860:tid 936083] [client 172.202.44.182:49921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/php.php"] [unique_id "amubKoijB6THqIZZsUL43gAAAOE"]
[Thu Jul 30 13:42:50.145404 2026] [core:notice] [pid 935860:tid 935908] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:42:50.161301 2026] [security2:error] [pid 935860:tid 936019] [client 20.197.178.120:29380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/txets.php"] [unique_id "amubKoijB6THqIZZsUL45gAAAKE"]
[Thu Jul 30 13:42:50.161454 2026] [security2:error] [pid 935860:tid 936019] [client 20.197.178.120:29380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/txets.php"] [unique_id "amubKoijB6THqIZZsUL45gAAAKE"]
[Thu Jul 30 13:42:50.269703 2026] [security2:error] [pid 935860:tid 935997] [client 135.119.63.61:51552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cepair/doc.php"] [unique_id "amubKoijB6THqIZZsUL47gAAAIs"]
[Thu Jul 30 13:42:50.767132 2026] [security2:error] [pid 935860:tid 936063] [client 20.197.178.120:29409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/pucci.php"] [unique_id "amubKoijB6THqIZZsUL4-AAAAM0"]
[Thu Jul 30 13:42:50.767229 2026] [security2:error] [pid 935860:tid 936063] [client 20.197.178.120:29409] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/pucci.php"] [unique_id "amubKoijB6THqIZZsUL4-AAAAM0"]
[Thu Jul 30 13:42:51.047959 2026] [proxy:error] [pid 935860:tid 936085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:51.048042 2026] [proxy_http:error] [pid 935860:tid 936085] [client 44.216.125.112:58673] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:51.048890 2026] [proxy:error] [pid 935860:tid 936085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:51.048936 2026] [proxy_http:error] [pid 935860:tid 936085] [client 44.216.125.112:58673] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:51.084023 2026] [proxy:error] [pid 935860:tid 936103] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:51.084087 2026] [proxy_http:error] [pid 935860:tid 936103] [client 44.216.125.112:55138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:51.084645 2026] [proxy:error] [pid 935860:tid 936103] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:51.084687 2026] [proxy_http:error] [pid 935860:tid 936103] [client 44.216.125.112:55138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:51.113546 2026] [security2:error] [pid 935860:tid 936092] [client 135.119.63.61:51739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/certificates/plugins.php"] [unique_id "amubK4ijB6THqIZZsUL5EQAAAOo"]
[Thu Jul 30 13:42:51.442130 2026] [security2:error] [pid 935860:tid 936034] [client 20.197.178.120:29390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/xwpg.php"] [unique_id "amubK4ijB6THqIZZsUL5IgAAALA"]
[Thu Jul 30 13:42:51.442305 2026] [security2:error] [pid 935860:tid 936034] [client 20.197.178.120:29390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/xwpg.php"] [unique_id "amubK4ijB6THqIZZsUL5IgAAALA"]
[Thu Jul 30 13:42:51.471321 2026] [security2:error] [pid 935860:tid 936094] [client 172.202.44.182:49790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/index.php"] [unique_id "amubK4ijB6THqIZZsUL5IwAAAOw"]
[Thu Jul 30 13:42:51.984328 2026] [security2:error] [pid 935860:tid 936040] [client 135.119.63.61:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cf.php"] [unique_id "amubK4ijB6THqIZZsUL5NQAAALY"]
[Thu Jul 30 13:42:52.017870 2026] [security2:error] [pid 935860:tid 936020] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubK4ijB6THqIZZsUL5IQAAAKI"]
[Thu Jul 30 13:42:52.067206 2026] [security2:error] [pid 935860:tid 936047] [client 20.197.178.120:28924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/ops.php"] [unique_id "amubLIijB6THqIZZsUL5NwAAAL0"]
[Thu Jul 30 13:42:52.067315 2026] [security2:error] [pid 935860:tid 936047] [client 20.197.178.120:28924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/ops.php"] [unique_id "amubLIijB6THqIZZsUL5NwAAAL0"]
[Thu Jul 30 13:42:52.688772 2026] [security2:error] [pid 935860:tid 936029] [client 20.197.178.120:29099] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.ejournalugj.com"] [uri "/1.php"] [unique_id "amubLIijB6THqIZZsUL5RAAAAKs"]
[Thu Jul 30 13:42:52.688893 2026] [security2:error] [pid 935860:tid 936029] [client 20.197.178.120:29099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/1.php"] [unique_id "amubLIijB6THqIZZsUL5RAAAAKs"]
[Thu Jul 30 13:42:52.689008 2026] [security2:error] [pid 935860:tid 936029] [client 20.197.178.120:29099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/1.php"] [unique_id "amubLIijB6THqIZZsUL5RAAAAKs"]
[Thu Jul 30 13:42:52.866891 2026] [security2:error] [pid 935860:tid 936031] [client 135.119.63.61:51539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cfile.php"] [unique_id "amubLIijB6THqIZZsUL5SAAAAK0"]
[Thu Jul 30 13:42:53.216171 2026] [security2:error] [pid 935860:tid 936115] [client 172.202.44.182:49775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/a.php"] [unique_id "amubLYijB6THqIZZsUL5UQAAAQE"]
[Thu Jul 30 13:42:53.331083 2026] [security2:error] [pid 935860:tid 936023] [client 20.197.178.120:28864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/mac.php"] [unique_id "amubLYijB6THqIZZsUL5UwAAAKU"]
[Thu Jul 30 13:42:53.331189 2026] [security2:error] [pid 935860:tid 936023] [client 20.197.178.120:28864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/mac.php"] [unique_id "amubLYijB6THqIZZsUL5UwAAAKU"]
[Thu Jul 30 13:42:53.790672 2026] [security2:error] [pid 935860:tid 936048] [client 135.119.63.61:51787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cgi-binadmin.php"] [unique_id "amubLYijB6THqIZZsUL5XwAAAL4"]
[Thu Jul 30 13:42:53.947506 2026] [security2:error] [pid 935860:tid 936110] [client 20.197.178.120:28897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/wp-admin/js/index.php"] [unique_id "amubLYijB6THqIZZsUL5ZgAAAPw"]
[Thu Jul 30 13:42:53.947604 2026] [security2:error] [pid 935860:tid 936110] [client 20.197.178.120:28897] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/wp-admin/js/index.php"] [unique_id "amubLYijB6THqIZZsUL5ZgAAAPw"]
[Thu Jul 30 13:42:54.524914 2026] [security2:error] [pid 935860:tid 935997] [client 172.237.109.114:14251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubLYijB6THqIZZsUL5ZwAAAIs"]
[Thu Jul 30 13:42:54.632677 2026] [security2:error] [pid 935860:tid 936082] [client 20.197.178.120:28923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/aa.php"] [unique_id "amubLoijB6THqIZZsUL5dAAAAOA"]
[Thu Jul 30 13:42:54.632991 2026] [security2:error] [pid 935860:tid 936082] [client 20.197.178.120:28923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/aa.php"] [unique_id "amubLoijB6THqIZZsUL5dAAAAOA"]
[Thu Jul 30 13:42:54.679226 2026] [security2:error] [pid 935860:tid 936040] [client 135.119.63.61:51493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cgi-binalfa.php"] [unique_id "amubLoijB6THqIZZsUL5dQAAALY"]
[Thu Jul 30 13:42:55.158595 2026] [security2:error] [pid 935860:tid 935949] [remote 82.130.249.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.249.130.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topmoversandpackerssharjah.art"] [uri "/wp-login.php"] [unique_id "amubL4ijB6THqIZZsUL5fwAAqVc"]
[Thu Jul 30 13:42:55.322170 2026] [security2:error] [pid 935860:tid 936079] [client 20.197.178.120:29386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/xyn.php"] [unique_id "amubL4ijB6THqIZZsUL5hAAAAN0"]
[Thu Jul 30 13:42:55.322301 2026] [security2:error] [pid 935860:tid 936079] [client 20.197.178.120:29386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/xyn.php"] [unique_id "amubL4ijB6THqIZZsUL5hAAAAN0"]
[Thu Jul 30 13:42:55.434693 2026] [proxy:error] [pid 935860:tid 936081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:55.434757 2026] [proxy_http:error] [pid 935860:tid 936081] [client 172.202.44.182:49768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:55.435390 2026] [proxy:error] [pid 935860:tid 936081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:55.435438 2026] [proxy_http:error] [pid 935860:tid 936081] [client 172.202.44.182:49768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:55.487553 2026] [security2:error] [pid 935860:tid 936028] [client 135.119.63.61:51475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cgi-binbypass.php"] [unique_id "amubL4ijB6THqIZZsUL5igAAAKo"]
[Thu Jul 30 13:42:55.920218 2026] [security2:error] [pid 935860:tid 936107] [client 20.197.178.120:29383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/wp-wp.php"] [unique_id "amubL4ijB6THqIZZsUL5lAAAAPk"]
[Thu Jul 30 13:42:55.920339 2026] [security2:error] [pid 935860:tid 936107] [client 20.197.178.120:29383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/wp-wp.php"] [unique_id "amubL4ijB6THqIZZsUL5lAAAAPk"]
[Thu Jul 30 13:42:56.222941 2026] [security2:error] [pid 935860:tid 936084] [client 135.119.63.61:51567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.hmhs.ph"] [uri "/cgi-bink.php"] [unique_id "amubMIijB6THqIZZsUL5yAAAAOI"]
[Thu Jul 30 13:42:56.540358 2026] [proxy:error] [pid 935860:tid 936048] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:56.540440 2026] [proxy_http:error] [pid 935860:tid 936048] [client 34.224.175.62:12495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:56.541225 2026] [proxy:error] [pid 935860:tid 936048] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:56.541276 2026] [proxy_http:error] [pid 935860:tid 936048] [client 34.224.175.62:12495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:56.558262 2026] [proxy:error] [pid 935860:tid 936039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:56.558326 2026] [proxy_http:error] [pid 935860:tid 936039] [client 34.224.175.62:51084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:56.558955 2026] [proxy:error] [pid 935860:tid 936039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:56.559015 2026] [proxy_http:error] [pid 935860:tid 936039] [client 34.224.175.62:51084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:56.560236 2026] [security2:error] [pid 935860:tid 936025] [client 20.197.178.120:29385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/aw.php"] [unique_id "amubMIijB6THqIZZsUL51wAAAKc"]
[Thu Jul 30 13:42:56.560389 2026] [security2:error] [pid 935860:tid 936025] [client 20.197.178.120:29385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/aw.php"] [unique_id "amubMIijB6THqIZZsUL51wAAAKc"]
[Thu Jul 30 13:42:57.193937 2026] [security2:error] [pid 935860:tid 936066] [client 20.197.178.120:28917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/classwithtostring.php"] [unique_id "amubMYijB6THqIZZsUL56gAAANA"]
[Thu Jul 30 13:42:57.194060 2026] [security2:error] [pid 935860:tid 936066] [client 20.197.178.120:28917] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/classwithtostring.php"] [unique_id "amubMYijB6THqIZZsUL56gAAANA"]
[Thu Jul 30 13:42:57.207795 2026] [security2:error] [pid 935860:tid 936019] [client 103.242.199.184:49840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubMYijB6THqIZZsUL56wAAAKE"]
[Thu Jul 30 13:42:57.208016 2026] [security2:error] [pid 935860:tid 936019] [client 103.242.199.184:49840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubMYijB6THqIZZsUL56wAAAKE"]
[Thu Jul 30 13:42:57.301765 2026] [security2:error] [pid 935860:tid 936034] [client 146.174.121.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubMIijB6THqIZZsUL5zAAAsBE"], referer: https://allmontecristi.com/
[Thu Jul 30 13:42:57.790115 2026] [security2:error] [pid 935860:tid 936115] [client 20.197.178.120:29066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/yawa.php"] [unique_id "amubMYijB6THqIZZsUL59QAAAQE"]
[Thu Jul 30 13:42:57.790222 2026] [security2:error] [pid 935860:tid 936115] [client 20.197.178.120:29066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/yawa.php"] [unique_id "amubMYijB6THqIZZsUL59QAAAQE"]
[Thu Jul 30 13:42:58.446374 2026] [security2:error] [pid 935860:tid 936057] [client 20.197.178.120:29063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/sym403.php"] [unique_id "amubMoijB6THqIZZsUL6BQAAAMc"]
[Thu Jul 30 13:42:58.446513 2026] [security2:error] [pid 935860:tid 936057] [client 20.197.178.120:29063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/sym403.php"] [unique_id "amubMoijB6THqIZZsUL6BQAAAMc"]
[Thu Jul 30 13:42:58.734862 2026] [security2:error] [pid 935860:tid 936079] [client 14.187.9.200:39001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubMoijB6THqIZZsUL6AwAAAN0"], referer: http://pkf.jo
[Thu Jul 30 13:42:58.735358 2026] [security2:error] [pid 935860:tid 936061] [client 14.185.241.33:56582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubMoijB6THqIZZsUL6AgAAAMs"], referer: http://pkf.jo
[Thu Jul 30 13:42:59.124503 2026] [security2:error] [pid 935860:tid 936090] [client 20.197.178.120:28872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.ejournalugj.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/blue/"] [unique_id "amubM4ijB6THqIZZsUL6GgAAAOg"]
[Thu Jul 30 13:42:59.368058 2026] [security2:error] [pid 935860:tid 936011] [client 123.23.174.144:43111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubMoijB6THqIZZsUL6DgAAAJk"], referer: http://pkf.jo
[Thu Jul 30 13:42:59.741393 2026] [security2:error] [pid 935860:tid 936009] [client 20.197.178.120:28872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/adminner.php"] [unique_id "amubM4ijB6THqIZZsUL6NwAAAJc"]
[Thu Jul 30 13:42:59.741560 2026] [security2:error] [pid 935860:tid 936009] [client 20.197.178.120:28872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/adminner.php"] [unique_id "amubM4ijB6THqIZZsUL6NwAAAJc"]
[Thu Jul 30 13:42:59.909329 2026] [proxy:error] [pid 935860:tid 936100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:59.909430 2026] [proxy_http:error] [pid 935860:tid 936100] [client 172.202.44.182:49766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:42:59.910673 2026] [proxy:error] [pid 935860:tid 936100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:42:59.910724 2026] [proxy_http:error] [pid 935860:tid 936100] [client 172.202.44.182:49766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:00.107673 2026] [security2:error] [pid 935860:tid 936010] [client 66.249.73.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amubM4ijB6THqIZZsUL6PAAAAJg"]
[Thu Jul 30 13:43:00.239057 2026] [security2:error] [pid 935860:tid 936004] [client 119.73.97.132:30745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/wp-admin/post.php"] [unique_id "amubM4ijB6THqIZZsUL6MgAAkiw"], referer: https://www.urwru.club/wp-admin/post.php?post=1073&action=edit
[Thu Jul 30 13:43:00.301465 2026] [security2:error] [pid 935860:tid 936092] [client 84.186.95.195:61083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubMoijB6THqIZZsUL6EQAAAOo"], referer: http://pkf.jo
[Thu Jul 30 13:43:00.301719 2026] [security2:error] [pid 935860:tid 936095] [client 49.150.108.252:27583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubMoijB6THqIZZsUL6EwAAAO0"], referer: http://pkf.jo
[Thu Jul 30 13:43:00.398141 2026] [security2:error] [pid 935860:tid 936024] [client 20.197.178.120:29424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/yup.php"] [unique_id "amubNIijB6THqIZZsUL6SAAAAKY"]
[Thu Jul 30 13:43:00.398257 2026] [security2:error] [pid 935860:tid 936024] [client 20.197.178.120:29424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/yup.php"] [unique_id "amubNIijB6THqIZZsUL6SAAAAKY"]
[Thu Jul 30 13:43:00.980660 2026] [security2:error] [pid 935860:tid 936052] [client 172.202.44.182:49773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amubNIijB6THqIZZsUL6VQAAAMI"]
[Thu Jul 30 13:43:01.122692 2026] [security2:error] [pid 935860:tid 936066] [client 20.197.178.120:28909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/config.json.php"] [unique_id "amubNYijB6THqIZZsUL6XwAAANA"]
[Thu Jul 30 13:43:01.122779 2026] [security2:error] [pid 935860:tid 936066] [client 20.197.178.120:28909] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/config.json.php"] [unique_id "amubNYijB6THqIZZsUL6XwAAANA"]
[Thu Jul 30 13:43:01.223676 2026] [security2:error] [pid 935860:tid 936085] [client 5.162.100.31:35602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubM4ijB6THqIZZsUL6IgAAAOM"], referer: http://pkf.jo
[Thu Jul 30 13:43:01.280898 2026] [security2:error] [pid 935860:tid 936000] [client 103.234.202.237:34368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubNIijB6THqIZZsUL6QwAAAI4"], referer: http://pkf.jo
[Thu Jul 30 13:43:01.287468 2026] [security2:error] [pid 935860:tid 936078] [client 78.167.1.90:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubNYijB6THqIZZsUL6YAAAANw"]
[Thu Jul 30 13:43:01.288192 2026] [security2:error] [pid 935860:tid 936078] [client 78.167.1.90:54922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubNYijB6THqIZZsUL6YAAAANw"]
[Thu Jul 30 13:43:01.294167 2026] [security2:error] [pid 935860:tid 936115] [client 157.100.40.38:58786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubM4ijB6THqIZZsUL6IwAAAQE"], referer: http://pkf.jo
[Thu Jul 30 13:43:01.753815 2026] [security2:error] [pid 935860:tid 935996] [client 20.197.178.120:29425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.ejournalugj.com"] [uri "/___proxy_subdomain_webmail/wp-includes/block-bindings/"] [unique_id "amubNYijB6THqIZZsUL6cwAAAIo"]
[Thu Jul 30 13:43:01.810178 2026] [core:notice] [pid 935860:tid 936113] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:01.871867 2026] [core:notice] [pid 935860:tid 936101] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:02.346606 2026] [security2:error] [pid 935860:tid 936056] [client 20.197.178.120:29425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/2.php"] [unique_id "amubNoijB6THqIZZsUL6ggAAAMY"]
[Thu Jul 30 13:43:02.346688 2026] [security2:error] [pid 935860:tid 936056] [client 20.197.178.120:29425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/2.php"] [unique_id "amubNoijB6THqIZZsUL6ggAAAMY"]
[Thu Jul 30 13:43:03.016539 2026] [security2:error] [pid 935860:tid 936069] [client 20.197.178.120:29408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/f35.update.php"] [unique_id "amubN4ijB6THqIZZsUL6uAAAANM"]
[Thu Jul 30 13:43:03.016670 2026] [security2:error] [pid 935860:tid 936069] [client 20.197.178.120:29408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/f35.update.php"] [unique_id "amubN4ijB6THqIZZsUL6uAAAANM"]
[Thu Jul 30 13:43:03.497781 2026] [security2:error] [pid 935860:tid 936105] [client 172.202.44.182:49283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin.php"] [unique_id "amubN4ijB6THqIZZsUL6wgAAAPc"]
[Thu Jul 30 13:43:03.718457 2026] [security2:error] [pid 935860:tid 936061] [client 20.197.178.120:29432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/k.php"] [unique_id "amubN4ijB6THqIZZsUL6xAAAAMs"]
[Thu Jul 30 13:43:03.718566 2026] [security2:error] [pid 935860:tid 936061] [client 20.197.178.120:29432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/k.php"] [unique_id "amubN4ijB6THqIZZsUL6xAAAAMs"]
[Thu Jul 30 13:43:04.319842 2026] [security2:error] [pid 935860:tid 936065] [client 186.219.137.169:32343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubN4ijB6THqIZZsUL60AAAz38"], referer: https://pkf.jo
[Thu Jul 30 13:43:04.378873 2026] [security2:error] [pid 935860:tid 935997] [client 20.197.178.120:29090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.ejournalugj.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/"] [unique_id "amubOIijB6THqIZZsUL61gAAAIs"]
[Thu Jul 30 13:43:04.531034 2026] [core:notice] [pid 935860:tid 936087] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:04.576514 2026] [security2:error] [pid 935860:tid 936102] [client 17.241.219.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amubOIijB6THqIZZsUL63AAAAPQ"]
[Thu Jul 30 13:43:04.979866 2026] [security2:error] [pid 935860:tid 936018] [client 20.197.178.120:29090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/spadex.php"] [unique_id "amubOIijB6THqIZZsUL66wAAAKA"]
[Thu Jul 30 13:43:04.979964 2026] [security2:error] [pid 935860:tid 936018] [client 20.197.178.120:29090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/spadex.php"] [unique_id "amubOIijB6THqIZZsUL66wAAAKA"]
[Thu Jul 30 13:43:05.472030 2026] [security2:error] [pid 935860:tid 936037] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubOYijB6THqIZZsUL69AAAALM"]
[Thu Jul 30 13:43:05.654506 2026] [security2:error] [pid 935860:tid 936044] [client 20.197.178.120:28876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/mg.php"] [unique_id "amubOYijB6THqIZZsUL6_gAAALo"]
[Thu Jul 30 13:43:05.654608 2026] [security2:error] [pid 935860:tid 936044] [client 20.197.178.120:28876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/mg.php"] [unique_id "amubOYijB6THqIZZsUL6_gAAALo"]
[Thu Jul 30 13:43:06.054021 2026] [security2:error] [pid 935860:tid 936089] [client 172.202.44.182:49738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/size.php"] [unique_id "amubOoijB6THqIZZsUL7CQAAAOc"]
[Thu Jul 30 13:43:06.230847 2026] [security2:error] [pid 935860:tid 936088] [client 37.46.199.86:38124] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amubOoijB6THqIZZsUL7DQAAAOY"]
[Thu Jul 30 13:43:06.231043 2026] [security2:error] [pid 935860:tid 936088] [client 37.46.199.86:38124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amubOoijB6THqIZZsUL7DQAAAOY"]
[Thu Jul 30 13:43:06.301204 2026] [security2:error] [pid 935860:tid 936118] [client 20.197.178.120:28922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/fnstall.php"] [unique_id "amubOoijB6THqIZZsUL7DgAAAQQ"]
[Thu Jul 30 13:43:06.301316 2026] [security2:error] [pid 935860:tid 936118] [client 20.197.178.120:28922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/fnstall.php"] [unique_id "amubOoijB6THqIZZsUL7DgAAAQQ"]
[Thu Jul 30 13:43:06.318591 2026] [security2:error] [pid 935860:tid 935881] [remote 72.167.132.114:58190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amubOoijB6THqIZZsUL7DwAAsBM"]
[Thu Jul 30 13:43:06.729005 2026] [core:notice] [pid 935860:tid 936082] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:06.787615 2026] [core:notice] [pid 935860:tid 936022] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:06.898901 2026] [security2:error] [pid 935860:tid 936100] [client 20.197.178.120:28895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/ortasekerli1.php"] [unique_id "amubOoijB6THqIZZsUL7IgAAAPI"]
[Thu Jul 30 13:43:06.899096 2026] [security2:error] [pid 935860:tid 936100] [client 20.197.178.120:28895] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/ortasekerli1.php"] [unique_id "amubOoijB6THqIZZsUL7IgAAAPI"]
[Thu Jul 30 13:43:07.507395 2026] [security2:error] [pid 935860:tid 936030] [client 68.67.112.221:40744] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amubO4ijB6THqIZZsUL7NwAAAKw"]
[Thu Jul 30 13:43:07.539505 2026] [security2:error] [pid 935860:tid 936059] [client 20.197.178.120:28902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/sump1.php"] [unique_id "amubO4ijB6THqIZZsUL7OgAAAMk"]
[Thu Jul 30 13:43:07.539614 2026] [security2:error] [pid 935860:tid 936059] [client 20.197.178.120:28902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/sump1.php"] [unique_id "amubO4ijB6THqIZZsUL7OgAAAMk"]
[Thu Jul 30 13:43:07.712379 2026] [core:error] [pid 935860:tid 936026] [client 74.7.241.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:43:07.712397 2026] [core:error] [pid 935860:tid 936026] [client 74.7.241.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:43:07.712529 2026] [security2:error] [pid 935860:tid 936026] [client 74.7.241.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.iop.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amubO4ijB6THqIZZsUL7QgAAAKg"]
[Thu Jul 30 13:43:07.714431 2026] [security2:error] [pid 935860:tid 936036] [client 74.7.241.179:38966] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.iop.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amubO4ijB6THqIZZsUL7QAAAsiU"]
[Thu Jul 30 13:43:07.901474 2026] [security2:error] [pid 935860:tid 936044] [client 103.242.199.184:50381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubO4ijB6THqIZZsUL7SAAAALo"]
[Thu Jul 30 13:43:07.901594 2026] [security2:error] [pid 935860:tid 936044] [client 103.242.199.184:50381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubO4ijB6THqIZZsUL7SAAAALo"]
[Thu Jul 30 13:43:08.021570 2026] [security2:error] [pid 935860:tid 935998] [client 74.7.241.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sama-architect.com"] [uri "/index.php"] [unique_id "amubOoijB6THqIZZsUL7HAAAjBg"]
[Thu Jul 30 13:43:08.021596 2026] [security2:error] [pid 935860:tid 935998] [client 74.7.241.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sama-architect.com"] [uri "/index.php"] [unique_id "amubOoijB6THqIZZsUL7HAAAjBg"]
[Thu Jul 30 13:43:08.066367 2026] [security2:error] [pid 935860:tid 936062] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amubPIijB6THqIZZsUL7UQAAAMw"]
[Thu Jul 30 13:43:08.066494 2026] [security2:error] [pid 935860:tid 936062] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amubPIijB6THqIZZsUL7UQAAAMw"]
[Thu Jul 30 13:43:08.164588 2026] [security2:error] [pid 935860:tid 936027] [client 172.202.44.182:49926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amubPIijB6THqIZZsUL7VgAAAKk"]
[Thu Jul 30 13:43:08.199438 2026] [security2:error] [pid 935860:tid 936098] [client 20.197.178.120:28877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/ops.php"] [unique_id "amubPIijB6THqIZZsUL7XQAAAPA"]
[Thu Jul 30 13:43:08.199540 2026] [security2:error] [pid 935860:tid 936098] [client 20.197.178.120:28877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/ops.php"] [unique_id "amubPIijB6THqIZZsUL7XQAAAPA"]
[Thu Jul 30 13:43:08.309965 2026] [security2:error] [pid 935860:tid 936114] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amubPIijB6THqIZZsUL7ZwAAAQA"]
[Thu Jul 30 13:43:08.310103 2026] [security2:error] [pid 935860:tid 936114] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amubPIijB6THqIZZsUL7ZwAAAQA"]
[Thu Jul 30 13:43:08.565164 2026] [security2:error] [pid 935860:tid 936054] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/x.php"] [unique_id "amubPIijB6THqIZZsUL7bAAAAMQ"]
[Thu Jul 30 13:43:08.565276 2026] [security2:error] [pid 935860:tid 936054] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/x.php"] [unique_id "amubPIijB6THqIZZsUL7bAAAAMQ"]
[Thu Jul 30 13:43:08.810436 2026] [security2:error] [pid 935860:tid 936081] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/mgrr.php"] [unique_id "amubPIijB6THqIZZsUL7eQAAAN8"]
[Thu Jul 30 13:43:08.810547 2026] [security2:error] [pid 935860:tid 936081] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/mgrr.php"] [unique_id "amubPIijB6THqIZZsUL7eQAAAN8"]
[Thu Jul 30 13:43:08.823595 2026] [security2:error] [pid 935860:tid 936055] [client 20.197.178.120:29404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/wp-post-data.php"] [unique_id "amubPIijB6THqIZZsUL7egAAAMU"]
[Thu Jul 30 13:43:08.823735 2026] [security2:error] [pid 935860:tid 936055] [client 20.197.178.120:29404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/wp-post-data.php"] [unique_id "amubPIijB6THqIZZsUL7egAAAMU"]
[Thu Jul 30 13:43:08.863762 2026] [security2:error] [pid 935860:tid 936108] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubPIijB6THqIZZsUL7ZAAAAPo"]
[Thu Jul 30 13:43:08.899744 2026] [security2:error] [pid 935860:tid 936099] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubPIijB6THqIZZsUL7ZgAAAPE"]
[Thu Jul 30 13:43:09.049948 2026] [security2:error] [pid 935860:tid 936020] [client 74.7.241.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sama-architect.com"] [uri "/index.php"] [unique_id "amubPIijB6THqIZZsUL7fgAAokI"], referer: https://www.sama-architect.com/robots.txt
[Thu Jul 30 13:43:09.056559 2026] [security2:error] [pid 935860:tid 936027] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/domvf.php"] [unique_id "amubPYijB6THqIZZsUL7hQAAAKk"]
[Thu Jul 30 13:43:09.056663 2026] [security2:error] [pid 935860:tid 936027] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/domvf.php"] [unique_id "amubPYijB6THqIZZsUL7hQAAAKk"]
[Thu Jul 30 13:43:09.160152 2026] [security2:error] [pid 935860:tid 936057] [client 172.202.44.182:49758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/403.php"] [unique_id "amubPYijB6THqIZZsUL7jQAAAMc"]
[Thu Jul 30 13:43:09.297910 2026] [security2:error] [pid 935860:tid 936112] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/yup.php"] [unique_id "amubPYijB6THqIZZsUL7mgAAAP4"]
[Thu Jul 30 13:43:09.298018 2026] [security2:error] [pid 935860:tid 936112] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/yup.php"] [unique_id "amubPYijB6THqIZZsUL7mgAAAP4"]
[Thu Jul 30 13:43:09.506770 2026] [security2:error] [pid 935860:tid 936092] [client 20.197.178.120:28877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/root.php"] [unique_id "amubPYijB6THqIZZsUL7ogAAAOo"]
[Thu Jul 30 13:43:09.506887 2026] [security2:error] [pid 935860:tid 936092] [client 20.197.178.120:28877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/root.php"] [unique_id "amubPYijB6THqIZZsUL7ogAAAOo"]
[Thu Jul 30 13:43:09.542641 2026] [security2:error] [pid 935860:tid 936035] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/X.php"] [unique_id "amubPYijB6THqIZZsUL7owAAALE"]
[Thu Jul 30 13:43:09.542780 2026] [security2:error] [pid 935860:tid 936035] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/X.php"] [unique_id "amubPYijB6THqIZZsUL7owAAALE"]
[Thu Jul 30 13:43:09.564513 2026] [security2:error] [pid 935860:tid 936117] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubPIijB6THqIZZsUL7fQABAzo"]
[Thu Jul 30 13:43:09.795560 2026] [security2:error] [pid 935860:tid 936110] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amubPYijB6THqIZZsUL7swAAAPw"]
[Thu Jul 30 13:43:09.795692 2026] [security2:error] [pid 935860:tid 936110] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amubPYijB6THqIZZsUL7swAAAPw"]
[Thu Jul 30 13:43:10.034971 2026] [security2:error] [pid 935860:tid 936080] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/gec.php"] [unique_id "amubPoijB6THqIZZsUL7uwAAAN4"]
[Thu Jul 30 13:43:10.035097 2026] [security2:error] [pid 935860:tid 936080] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/gec.php"] [unique_id "amubPoijB6THqIZZsUL7uwAAAN4"]
[Thu Jul 30 13:43:10.148940 2026] [security2:error] [pid 935860:tid 936100] [client 20.197.178.120:28883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/v543.php"] [unique_id "amubPoijB6THqIZZsUL7xAAAAPI"]
[Thu Jul 30 13:43:10.149052 2026] [security2:error] [pid 935860:tid 936100] [client 20.197.178.120:28883] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/v543.php"] [unique_id "amubPoijB6THqIZZsUL7xAAAAPI"]
[Thu Jul 30 13:43:10.277538 2026] [security2:error] [pid 935860:tid 935993] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/sky.php"] [unique_id "amubPoijB6THqIZZsUL7xwAAAIc"]
[Thu Jul 30 13:43:10.277625 2026] [security2:error] [pid 935860:tid 935993] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/sky.php"] [unique_id "amubPoijB6THqIZZsUL7xwAAAIc"]
[Thu Jul 30 13:43:10.522169 2026] [security2:error] [pid 935860:tid 936062] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/fffm.php"] [unique_id "amubPoijB6THqIZZsUL7zwAAAMw"]
[Thu Jul 30 13:43:10.522294 2026] [security2:error] [pid 935860:tid 936062] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/fffm.php"] [unique_id "amubPoijB6THqIZZsUL7zwAAAMw"]
[Thu Jul 30 13:43:10.748308 2026] [security2:error] [pid 935860:tid 936051] [client 20.197.178.120:28903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/sixxis.php"] [unique_id "amubPoijB6THqIZZsUL72gAAAME"]
[Thu Jul 30 13:43:10.748396 2026] [security2:error] [pid 935860:tid 936051] [client 20.197.178.120:28903] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/sixxis.php"] [unique_id "amubPoijB6THqIZZsUL72gAAAME"]
[Thu Jul 30 13:43:10.770362 2026] [security2:error] [pid 935860:tid 936113] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/sixxis.php"] [unique_id "amubPoijB6THqIZZsUL72wAAAP8"]
[Thu Jul 30 13:43:10.770452 2026] [security2:error] [pid 935860:tid 936113] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/sixxis.php"] [unique_id "amubPoijB6THqIZZsUL72wAAAP8"]
[Thu Jul 30 13:43:10.774074 2026] [security2:error] [pid 935860:tid 936084] [client 78.167.1.90:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubPoijB6THqIZZsUL73AAAAOI"]
[Thu Jul 30 13:43:10.774675 2026] [security2:error] [pid 935860:tid 936084] [client 78.167.1.90:55216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubPoijB6THqIZZsUL73AAAAOI"]
[Thu Jul 30 13:43:11.023425 2026] [security2:error] [pid 935860:tid 935995] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/yj09.php"] [unique_id "amubP4ijB6THqIZZsUL75gAAAIk"]
[Thu Jul 30 13:43:11.023523 2026] [security2:error] [pid 935860:tid 935995] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/yj09.php"] [unique_id "amubP4ijB6THqIZZsUL75gAAAIk"]
[Thu Jul 30 13:43:11.275335 2026] [security2:error] [pid 935860:tid 936113] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/k.php"] [unique_id "amubP4ijB6THqIZZsUL77wAAAP8"]
[Thu Jul 30 13:43:11.275424 2026] [security2:error] [pid 935860:tid 936113] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/k.php"] [unique_id "amubP4ijB6THqIZZsUL77wAAAP8"]
[Thu Jul 30 13:43:11.348577 2026] [security2:error] [pid 935860:tid 936014] [client 20.197.178.120:28904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/ip.php"] [unique_id "amubP4ijB6THqIZZsUL7-QAAAJw"]
[Thu Jul 30 13:43:11.348668 2026] [security2:error] [pid 935860:tid 936014] [client 20.197.178.120:28904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/ip.php"] [unique_id "amubP4ijB6THqIZZsUL7-QAAAJw"]
[Thu Jul 30 13:43:11.524682 2026] [security2:error] [pid 935860:tid 936079] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/k2.php"] [unique_id "amubP4ijB6THqIZZsUL7_QAAAN0"]
[Thu Jul 30 13:43:11.524768 2026] [security2:error] [pid 935860:tid 936079] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/k2.php"] [unique_id "amubP4ijB6THqIZZsUL7_QAAAN0"]
[Thu Jul 30 13:43:11.760153 2026] [core:notice] [pid 935860:tid 935881] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:11.794582 2026] [security2:error] [pid 935860:tid 936107] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/w.php"] [unique_id "amubP4ijB6THqIZZsUL8DAAAAPk"]
[Thu Jul 30 13:43:11.794995 2026] [security2:error] [pid 935860:tid 936107] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/w.php"] [unique_id "amubP4ijB6THqIZZsUL8DAAAAPk"]
[Thu Jul 30 13:43:11.986900 2026] [security2:error] [pid 935860:tid 936079] [client 20.197.178.120:28899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/kq1.php"] [unique_id "amubP4ijB6THqIZZsUL8EwAAAN0"]
[Thu Jul 30 13:43:11.987016 2026] [security2:error] [pid 935860:tid 936079] [client 20.197.178.120:28899] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/kq1.php"] [unique_id "amubP4ijB6THqIZZsUL8EwAAAN0"]
[Thu Jul 30 13:43:12.040613 2026] [security2:error] [pid 935860:tid 936039] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/fpwch.php"] [unique_id "amubQIijB6THqIZZsUL8FQAAALU"]
[Thu Jul 30 13:43:12.040691 2026] [security2:error] [pid 935860:tid 936039] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/fpwch.php"] [unique_id "amubQIijB6THqIZZsUL8FQAAALU"]
[Thu Jul 30 13:43:12.299779 2026] [security2:error] [pid 935860:tid 936072] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/w2025.php"] [unique_id "amubQIijB6THqIZZsUL8IQAAANY"]
[Thu Jul 30 13:43:12.299909 2026] [security2:error] [pid 935860:tid 936072] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/w2025.php"] [unique_id "amubQIijB6THqIZZsUL8IQAAANY"]
[Thu Jul 30 13:43:12.540841 2026] [security2:error] [pid 935860:tid 936045] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/FWAZ.php"] [unique_id "amubQIijB6THqIZZsUL8KgAAALs"]
[Thu Jul 30 13:43:12.540930 2026] [security2:error] [pid 935860:tid 936045] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/FWAZ.php"] [unique_id "amubQIijB6THqIZZsUL8KgAAALs"]
[Thu Jul 30 13:43:12.584367 2026] [security2:error] [pid 935860:tid 936004] [client 20.197.178.120:29439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ejournalugj.com"] [uri "/fw/faiyy.php"] [unique_id "amubQIijB6THqIZZsUL8KwAAAJI"]
[Thu Jul 30 13:43:12.584466 2026] [security2:error] [pid 935860:tid 936004] [client 20.197.178.120:29439] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ejournalugj.com"] [uri "/fw/faiyy.php"] [unique_id "amubQIijB6THqIZZsUL8KwAAAJI"]
[Thu Jul 30 13:43:12.782498 2026] [security2:error] [pid 935860:tid 936028] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/qterm.php"] [unique_id "amubQIijB6THqIZZsUL8MwAAAKo"]
[Thu Jul 30 13:43:12.782622 2026] [security2:error] [pid 935860:tid 936028] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/qterm.php"] [unique_id "amubQIijB6THqIZZsUL8MwAAAKo"]
[Thu Jul 30 13:43:13.026006 2026] [security2:error] [pid 935860:tid 936029] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/blurbs.php"] [unique_id "amubQYijB6THqIZZsUL8QAAAAKs"]
[Thu Jul 30 13:43:13.026111 2026] [security2:error] [pid 935860:tid 936029] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/blurbs.php"] [unique_id "amubQYijB6THqIZZsUL8QAAAAKs"]
[Thu Jul 30 13:43:13.267709 2026] [security2:error] [pid 935860:tid 936060] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-ws68.php"] [unique_id "amubQYijB6THqIZZsUL8SgAAAMo"]
[Thu Jul 30 13:43:13.267831 2026] [security2:error] [pid 935860:tid 936060] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-ws68.php"] [unique_id "amubQYijB6THqIZZsUL8SgAAAMo"]
[Thu Jul 30 13:43:13.440819 2026] [security2:error] [pid 935860:tid 936059] [client 74.7.175.146:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-786e119e.lld.nyx.temporary.site"] [uri "/index.html"] [unique_id "amubQYijB6THqIZZsUL8VwAAAMk"]
[Thu Jul 30 13:43:13.441881 2026] [security2:error] [pid 935860:tid 936089] [client 74.7.175.146:38176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-786e119e.lld.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amubQYijB6THqIZZsUL8VQAA5zI"]
[Thu Jul 30 13:43:13.506910 2026] [security2:error] [pid 935860:tid 936054] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xyn.php"] [unique_id "amubQYijB6THqIZZsUL8YAAAAMQ"]
[Thu Jul 30 13:43:13.507043 2026] [security2:error] [pid 935860:tid 936054] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xyn.php"] [unique_id "amubQYijB6THqIZZsUL8YAAAAMQ"]
[Thu Jul 30 13:43:13.757585 2026] [security2:error] [pid 935860:tid 936039] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ccc.php"] [unique_id "amubQYijB6THqIZZsUL8ZwAAALU"]
[Thu Jul 30 13:43:13.757727 2026] [security2:error] [pid 935860:tid 936039] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ccc.php"] [unique_id "amubQYijB6THqIZZsUL8ZwAAALU"]
[Thu Jul 30 13:43:14.001695 2026] [security2:error] [pid 935860:tid 936075] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/get.php"] [unique_id "amubQoijB6THqIZZsUL8dAAAANk"]
[Thu Jul 30 13:43:14.001803 2026] [security2:error] [pid 935860:tid 936075] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/get.php"] [unique_id "amubQoijB6THqIZZsUL8dAAAANk"]
[Thu Jul 30 13:43:14.241403 2026] [security2:error] [pid 935860:tid 936027] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/images.php"] [unique_id "amubQoijB6THqIZZsUL8fAAAAKk"]
[Thu Jul 30 13:43:14.241535 2026] [security2:error] [pid 935860:tid 936027] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/images.php"] [unique_id "amubQoijB6THqIZZsUL8fAAAAKk"]
[Thu Jul 30 13:43:14.366808 2026] [security2:error] [pid 935860:tid 936024] [client 172.202.44.182:49755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amubQoijB6THqIZZsUL8igAAAKY"]
[Thu Jul 30 13:43:14.487137 2026] [security2:error] [pid 935860:tid 936033] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/alls.php"] [unique_id "amubQoijB6THqIZZsUL8kAAAAK8"]
[Thu Jul 30 13:43:14.487242 2026] [security2:error] [pid 935860:tid 936033] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/alls.php"] [unique_id "amubQoijB6THqIZZsUL8kAAAAK8"]
[Thu Jul 30 13:43:14.568521 2026] [core:notice] [pid 935860:tid 935977] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:14.571601 2026] [core:notice] [pid 935860:tid 936017] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:14.753226 2026] [security2:error] [pid 935860:tid 936062] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/coffexium.php"] [unique_id "amubQoijB6THqIZZsUL8owAAAMw"]
[Thu Jul 30 13:43:14.753332 2026] [security2:error] [pid 935860:tid 936062] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/coffexium.php"] [unique_id "amubQoijB6THqIZZsUL8owAAAMw"]
[Thu Jul 30 13:43:14.993167 2026] [security2:error] [pid 935860:tid 936095] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/red.php"] [unique_id "amubQoijB6THqIZZsUL8qgAAAO0"]
[Thu Jul 30 13:43:14.993266 2026] [security2:error] [pid 935860:tid 936095] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/red.php"] [unique_id "amubQoijB6THqIZZsUL8qgAAAO0"]
[Thu Jul 30 13:43:15.082728 2026] [core:notice] [pid 935860:tid 935865] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:15.236996 2026] [proxy:error] [pid 935860:tid 936110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.237084 2026] [proxy_http:error] [pid 935860:tid 936110] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.237947 2026] [proxy:error] [pid 935860:tid 936110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.238018 2026] [proxy_http:error] [pid 935860:tid 936110] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.238148 2026] [security2:error] [pid 935860:tid 936110] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubQ4ijB6THqIZZsUL8uAAAAPw"]
[Thu Jul 30 13:43:15.306948 2026] [proxy:error] [pid 935860:tid 936013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.307063 2026] [proxy_http:error] [pid 935860:tid 936013] [client 52.4.19.39:1668] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.307918 2026] [proxy:error] [pid 935860:tid 936013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.307990 2026] [proxy_http:error] [pid 935860:tid 936013] [client 52.4.19.39:1668] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.367275 2026] [proxy:error] [pid 935860:tid 936071] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.367378 2026] [proxy_http:error] [pid 935860:tid 936071] [client 3.225.222.228:5526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.368695 2026] [proxy:error] [pid 935860:tid 936071] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.368765 2026] [proxy_http:error] [pid 935860:tid 936071] [client 3.225.222.228:5526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.480279 2026] [security2:error] [pid 935860:tid 936057] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amubQ4ijB6THqIZZsUL86QAAAMc"]
[Thu Jul 30 13:43:15.480384 2026] [security2:error] [pid 935860:tid 936057] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amubQ4ijB6THqIZZsUL86QAAAMc"]
[Thu Jul 30 13:43:15.501881 2026] [security2:error] [pid 935860:tid 936070] [client 74.7.228.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.xzd.nyx.temporary.site"] [uri "/index.php"] [unique_id "amubQoijB6THqIZZsUL8fwAAANQ"]
[Thu Jul 30 13:43:15.502823 2026] [security2:error] [pid 935860:tid 936109] [client 74.7.228.11:50580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.xzd.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amubQoijB6THqIZZsUL8fQAA-1o"]
[Thu Jul 30 13:43:15.727865 2026] [proxy:error] [pid 935860:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.727948 2026] [proxy_http:error] [pid 935860:tid 935995] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.728773 2026] [proxy:error] [pid 935860:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.728826 2026] [proxy_http:error] [pid 935860:tid 935995] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.728937 2026] [security2:error] [pid 935860:tid 935995] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubQ4ijB6THqIZZsUL9GAAAAIk"]
[Thu Jul 30 13:43:15.753259 2026] [security2:error] [pid 935860:tid 936010] [client 172.202.44.182:49966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/as.php"] [unique_id "amubQ4ijB6THqIZZsUL9HgAAAJg"]
[Thu Jul 30 13:43:15.941730 2026] [security2:error] [pid 935860:tid 935996] [client 74.7.175.138:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.vanguardlegalassociates.team"] [uri "/index.php"] [unique_id "amubQ4ijB6THqIZZsUL8tAAAinA"]
[Thu Jul 30 13:43:15.974329 2026] [proxy:error] [pid 935860:tid 936014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.974414 2026] [proxy_http:error] [pid 935860:tid 936014] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.975283 2026] [proxy:error] [pid 935860:tid 936014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:15.975344 2026] [proxy_http:error] [pid 935860:tid 936014] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:15.975455 2026] [security2:error] [pid 935860:tid 936014] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubQ4ijB6THqIZZsUL9OAAAAJw"]
[Thu Jul 30 13:43:16.218314 2026] [security2:error] [pid 935860:tid 936081] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/index.php"] [unique_id "amubRIijB6THqIZZsUL9PAAAAN8"]
[Thu Jul 30 13:43:16.218424 2026] [security2:error] [pid 935860:tid 936081] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/index.php"] [unique_id "amubRIijB6THqIZZsUL9PAAAAN8"]
[Thu Jul 30 13:43:16.472883 2026] [security2:error] [pid 935860:tid 936107] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amubRIijB6THqIZZsUL9RgAAAPk"]
[Thu Jul 30 13:43:16.473009 2026] [security2:error] [pid 935860:tid 936107] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amubRIijB6THqIZZsUL9RgAAAPk"]
[Thu Jul 30 13:43:16.713945 2026] [security2:error] [pid 935860:tid 936059] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/177.php"] [unique_id "amubRIijB6THqIZZsUL9RwAAAMk"]
[Thu Jul 30 13:43:16.714092 2026] [security2:error] [pid 935860:tid 936059] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/177.php"] [unique_id "amubRIijB6THqIZZsUL9RwAAAMk"]
[Thu Jul 30 13:43:16.953555 2026] [security2:error] [pid 935860:tid 936048] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/199.php"] [unique_id "amubRIijB6THqIZZsUL9UQAAAL4"]
[Thu Jul 30 13:43:16.953698 2026] [security2:error] [pid 935860:tid 936048] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/199.php"] [unique_id "amubRIijB6THqIZZsUL9UQAAAL4"]
[Thu Jul 30 13:43:17.197160 2026] [security2:error] [pid 935860:tid 936112] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file52.php"] [unique_id "amubRYijB6THqIZZsUL9UwAAAP4"]
[Thu Jul 30 13:43:17.197330 2026] [security2:error] [pid 935860:tid 936112] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file52.php"] [unique_id "amubRYijB6THqIZZsUL9UwAAAP4"]
[Thu Jul 30 13:43:17.451318 2026] [security2:error] [pid 935860:tid 936032] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/geck.php"] [unique_id "amubRYijB6THqIZZsUL9WwAAAK4"]
[Thu Jul 30 13:43:17.451410 2026] [security2:error] [pid 935860:tid 936032] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/geck.php"] [unique_id "amubRYijB6THqIZZsUL9WwAAAK4"]
[Thu Jul 30 13:43:17.456553 2026] [security2:error] [pid 935860:tid 936051] [client 172.202.44.182:49777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amubRYijB6THqIZZsUL9XAAAAME"]
[Thu Jul 30 13:43:17.715171 2026] [security2:error] [pid 935860:tid 936021] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/biufile.php"] [unique_id "amubRYijB6THqIZZsUL9aQAAAKM"]
[Thu Jul 30 13:43:17.715273 2026] [security2:error] [pid 935860:tid 936021] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/biufile.php"] [unique_id "amubRYijB6THqIZZsUL9aQAAAKM"]
[Thu Jul 30 13:43:17.962601 2026] [security2:error] [pid 935860:tid 936018] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dejavu.php"] [unique_id "amubRYijB6THqIZZsUL9dQAAAKA"]
[Thu Jul 30 13:43:17.962715 2026] [security2:error] [pid 935860:tid 936018] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dejavu.php"] [unique_id "amubRYijB6THqIZZsUL9dQAAAKA"]
[Thu Jul 30 13:43:18.200928 2026] [security2:error] [pid 935860:tid 936025] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/aaf.php"] [unique_id "amubRoijB6THqIZZsUL9fQAAAKc"]
[Thu Jul 30 13:43:18.201056 2026] [security2:error] [pid 935860:tid 936025] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/aaf.php"] [unique_id "amubRoijB6THqIZZsUL9fQAAAKc"]
[Thu Jul 30 13:43:18.447696 2026] [security2:error] [pid 935860:tid 936013] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ha.php"] [unique_id "amubRoijB6THqIZZsUL9hQAAAJs"]
[Thu Jul 30 13:43:18.447790 2026] [security2:error] [pid 935860:tid 936013] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ha.php"] [unique_id "amubRoijB6THqIZZsUL9hQAAAJs"]
[Thu Jul 30 13:43:18.628641 2026] [core:notice] [pid 935860:tid 936035] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:18.686618 2026] [security2:error] [pid 935860:tid 936029] [client 103.242.199.184:50931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubRoijB6THqIZZsUL9kQAAAKs"]
[Thu Jul 30 13:43:18.686710 2026] [security2:error] [pid 935860:tid 936029] [client 103.242.199.184:50931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubRoijB6THqIZZsUL9kQAAAKs"]
[Thu Jul 30 13:43:18.704080 2026] [security2:error] [pid 935860:tid 936046] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/hur.php"] [unique_id "amubRoijB6THqIZZsUL9kwAAALw"]
[Thu Jul 30 13:43:18.704163 2026] [security2:error] [pid 935860:tid 936046] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/hur.php"] [unique_id "amubRoijB6THqIZZsUL9kwAAALw"]
[Thu Jul 30 13:43:18.947068 2026] [security2:error] [pid 935860:tid 936050] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/h02ugyh.php"] [unique_id "amubRoijB6THqIZZsUL9ngAAAMA"]
[Thu Jul 30 13:43:18.947210 2026] [security2:error] [pid 935860:tid 936050] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/h02ugyh.php"] [unique_id "amubRoijB6THqIZZsUL9ngAAAMA"]
[Thu Jul 30 13:43:19.206368 2026] [security2:error] [pid 935860:tid 936064] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/155.php"] [unique_id "amubR4ijB6THqIZZsUL9qQAAAM4"]
[Thu Jul 30 13:43:19.206476 2026] [security2:error] [pid 935860:tid 936064] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/155.php"] [unique_id "amubR4ijB6THqIZZsUL9qQAAAM4"]
[Thu Jul 30 13:43:19.454381 2026] [security2:error] [pid 935860:tid 936017] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ops.php"] [unique_id "amubR4ijB6THqIZZsUL9rgAAAJ8"]
[Thu Jul 30 13:43:19.454500 2026] [security2:error] [pid 935860:tid 936017] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ops.php"] [unique_id "amubR4ijB6THqIZZsUL9rgAAAJ8"]
[Thu Jul 30 13:43:19.697165 2026] [security2:error] [pid 935860:tid 936021] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ingfo.php"] [unique_id "amubR4ijB6THqIZZsUL9wgAAAKM"]
[Thu Jul 30 13:43:19.697256 2026] [security2:error] [pid 935860:tid 936021] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ingfo.php"] [unique_id "amubR4ijB6THqIZZsUL9wgAAAKM"]
[Thu Jul 30 13:43:19.958393 2026] [security2:error] [pid 935860:tid 936080] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/error_log.php"] [unique_id "amubR4ijB6THqIZZsUL9xQAAAN4"]
[Thu Jul 30 13:43:19.958528 2026] [security2:error] [pid 935860:tid 936080] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/error_log.php"] [unique_id "amubR4ijB6THqIZZsUL9xQAAAN4"]
[Thu Jul 30 13:43:20.204086 2026] [security2:error] [pid 935860:tid 936115] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/koala.php"] [unique_id "amubSIijB6THqIZZsUL90wAAAQE"]
[Thu Jul 30 13:43:20.204171 2026] [security2:error] [pid 935860:tid 936115] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/koala.php"] [unique_id "amubSIijB6THqIZZsUL90wAAAQE"]
[Thu Jul 30 13:43:20.455008 2026] [security2:error] [pid 935860:tid 936008] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/mac.php"] [unique_id "amubSIijB6THqIZZsUL91QAAAJY"]
[Thu Jul 30 13:43:20.455116 2026] [security2:error] [pid 935860:tid 936008] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/mac.php"] [unique_id "amubSIijB6THqIZZsUL91QAAAJY"]
[Thu Jul 30 13:43:20.707712 2026] [security2:error] [pid 935860:tid 936109] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wefile.php"] [unique_id "amubSIijB6THqIZZsUL94QAAAPs"]
[Thu Jul 30 13:43:20.708009 2026] [security2:error] [pid 935860:tid 936109] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wefile.php"] [unique_id "amubSIijB6THqIZZsUL94QAAAPs"]
[Thu Jul 30 13:43:20.843961 2026] [core:notice] [pid 935860:tid 936026] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:20.845180 2026] [core:notice] [pid 935860:tid 936053] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:20.847320 2026] [core:notice] [pid 935860:tid 936116] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:20.855111 2026] [core:notice] [pid 935860:tid 936019] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:20.855243 2026] [core:notice] [pid 935860:tid 935996] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:20.967060 2026] [proxy:error] [pid 935860:tid 936005] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:20.967148 2026] [proxy_http:error] [pid 935860:tid 936005] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:20.967877 2026] [proxy:error] [pid 935860:tid 936005] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:20.967923 2026] [proxy_http:error] [pid 935860:tid 936005] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:20.968030 2026] [security2:error] [pid 935860:tid 936005] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubSIijB6THqIZZsUL95wAAAJM"]
[Thu Jul 30 13:43:21.215557 2026] [proxy:error] [pid 935860:tid 936098] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:21.215633 2026] [proxy_http:error] [pid 935860:tid 936098] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:21.216360 2026] [proxy:error] [pid 935860:tid 936098] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:21.216408 2026] [proxy_http:error] [pid 935860:tid 936098] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:21.216514 2026] [security2:error] [pid 935860:tid 936098] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubSYijB6THqIZZsUL97gAAAPA"]
[Thu Jul 30 13:43:21.469427 2026] [security2:error] [pid 935860:tid 936049] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/makeasmtp.php"] [unique_id "amubSYijB6THqIZZsUL99QAAAL8"]
[Thu Jul 30 13:43:21.469541 2026] [security2:error] [pid 935860:tid 936049] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/makeasmtp.php"] [unique_id "amubSYijB6THqIZZsUL99QAAAL8"]
[Thu Jul 30 13:43:21.710453 2026] [security2:error] [pid 935860:tid 936063] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/2P.php"] [unique_id "amubSYijB6THqIZZsUL9_QAAAM0"]
[Thu Jul 30 13:43:21.710554 2026] [security2:error] [pid 935860:tid 936063] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/2P.php"] [unique_id "amubSYijB6THqIZZsUL9_QAAAM0"]
[Thu Jul 30 13:43:21.821497 2026] [proxy:error] [pid 935860:tid 936077] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:21.821579 2026] [proxy_http:error] [pid 935860:tid 936077] [client 195.96.139.59:35607] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:21.822386 2026] [proxy:error] [pid 935860:tid 936077] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:21.822439 2026] [proxy_http:error] [pid 935860:tid 936077] [client 195.96.139.59:35607] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:21.966114 2026] [security2:error] [pid 935860:tid 936076] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/.well-known/about.php"] [unique_id "amubSYijB6THqIZZsUL-AwAAANo"]
[Thu Jul 30 13:43:21.966261 2026] [security2:error] [pid 935860:tid 936076] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/.well-known/about.php"] [unique_id "amubSYijB6THqIZZsUL-AwAAANo"]
[Thu Jul 30 13:43:22.207727 2026] [security2:error] [pid 935860:tid 936004] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amubSoijB6THqIZZsUL-CgAAAJI"]
[Thu Jul 30 13:43:22.207846 2026] [security2:error] [pid 935860:tid 936004] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amubSoijB6THqIZZsUL-CgAAAJI"]
[Thu Jul 30 13:43:22.307971 2026] [security2:error] [pid 935860:tid 936029] [client 78.167.1.90:56484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubSoijB6THqIZZsUL-DgAAAKs"]
[Thu Jul 30 13:43:22.308122 2026] [security2:error] [pid 935860:tid 936029] [client 78.167.1.90:56484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubSoijB6THqIZZsUL-DgAAAKs"]
[Thu Jul 30 13:43:22.449036 2026] [security2:error] [pid 935860:tid 936034] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/system_log.php"] [unique_id "amubSoijB6THqIZZsUL-DwAAALA"]
[Thu Jul 30 13:43:22.449147 2026] [security2:error] [pid 935860:tid 936034] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/system_log.php"] [unique_id "amubSoijB6THqIZZsUL-DwAAALA"]
[Thu Jul 30 13:43:22.695306 2026] [proxy:error] [pid 935860:tid 936026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:22.695368 2026] [proxy_http:error] [pid 935860:tid 936026] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:22.695954 2026] [proxy:error] [pid 935860:tid 936026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:22.696008 2026] [proxy_http:error] [pid 935860:tid 936026] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:22.696091 2026] [security2:error] [pid 935860:tid 936026] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubSoijB6THqIZZsUL-GAAAAKg"]
[Thu Jul 30 13:43:22.953938 2026] [proxy:error] [pid 935860:tid 936005] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:22.954029 2026] [proxy_http:error] [pid 935860:tid 936005] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:22.954612 2026] [proxy:error] [pid 935860:tid 936005] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:22.954654 2026] [proxy_http:error] [pid 935860:tid 936005] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:22.954742 2026] [security2:error] [pid 935860:tid 936005] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubSoijB6THqIZZsUL-HQAAAJM"]
[Thu Jul 30 13:43:23.214653 2026] [security2:error] [pid 935860:tid 936007] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/crgio.php"] [unique_id "amubS4ijB6THqIZZsUL-JwAAAJU"]
[Thu Jul 30 13:43:23.214758 2026] [security2:error] [pid 935860:tid 936007] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/crgio.php"] [unique_id "amubS4ijB6THqIZZsUL-JwAAAJU"]
[Thu Jul 30 13:43:23.459561 2026] [security2:error] [pid 935860:tid 936097] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/pucci.php"] [unique_id "amubS4ijB6THqIZZsUL-LgAAAO8"]
[Thu Jul 30 13:43:23.459666 2026] [security2:error] [pid 935860:tid 936097] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/pucci.php"] [unique_id "amubS4ijB6THqIZZsUL-LgAAAO8"]
[Thu Jul 30 13:43:23.680616 2026] [security2:error] [pid 935860:tid 935955] [remote 74.7.243.224:36596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/article.php"] [unique_id "amubS4ijB6THqIZZsUL-NAAAiF0"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 13:43:23.702523 2026] [proxy:error] [pid 935860:tid 936031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:23.702608 2026] [proxy_http:error] [pid 935860:tid 936031] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:23.703470 2026] [proxy:error] [pid 935860:tid 936031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:23.703534 2026] [proxy_http:error] [pid 935860:tid 936031] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:23.703650 2026] [security2:error] [pid 935860:tid 936031] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubS4ijB6THqIZZsUL-NQAAAK0"]
[Thu Jul 30 13:43:23.851639 2026] [security2:error] [pid 935860:tid 935964] [remote 57.141.0.32:20900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amubS4ijB6THqIZZsUL-OQAAl2Y"]
[Thu Jul 30 13:43:23.948087 2026] [proxy:error] [pid 935860:tid 936006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:23.948164 2026] [proxy_http:error] [pid 935860:tid 936006] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:23.948818 2026] [proxy:error] [pid 935860:tid 936006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:23.948863 2026] [proxy_http:error] [pid 935860:tid 936006] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:23.948954 2026] [security2:error] [pid 935860:tid 936006] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubS4ijB6THqIZZsUL-PQAAAJQ"]
[Thu Jul 30 13:43:23.996846 2026] [core:notice] [pid 935860:tid 936089] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:24.010530 2026] [security2:error] [pid 935860:tid 936028] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubS4ijB6THqIZZsUL-LQAAAKo"]
[Thu Jul 30 13:43:24.108688 2026] [security2:error] [pid 935860:tid 935996] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubS4ijB6THqIZZsUL-MAAAigg"]
[Thu Jul 30 13:43:24.197214 2026] [security2:error] [pid 935860:tid 936091] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-temp.php"] [unique_id "amubTIijB6THqIZZsUL-QAAAAOk"]
[Thu Jul 30 13:43:24.197349 2026] [security2:error] [pid 935860:tid 936091] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-temp.php"] [unique_id "amubTIijB6THqIZZsUL-QAAAAOk"]
[Thu Jul 30 13:43:24.433614 2026] [security2:error] [pid 935860:tid 936102] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-admin/js/index.php"] [unique_id "amubTIijB6THqIZZsUL-SQAAAPQ"]
[Thu Jul 30 13:43:24.433713 2026] [security2:error] [pid 935860:tid 936102] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-admin/js/index.php"] [unique_id "amubTIijB6THqIZZsUL-SQAAAPQ"]
[Thu Jul 30 13:43:24.506645 2026] [security2:error] [pid 935860:tid 936042] [client 74.7.230.25:39782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aded-rdc.org"] [uri "/index.php"] [unique_id "amubTIijB6THqIZZsUL-SwAAuEk"]
[Thu Jul 30 13:43:24.685782 2026] [security2:error] [pid 935860:tid 936082] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/puc.php"] [unique_id "amubTIijB6THqIZZsUL-TAAAAOA"]
[Thu Jul 30 13:43:24.685897 2026] [security2:error] [pid 935860:tid 936082] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/puc.php"] [unique_id "amubTIijB6THqIZZsUL-TAAAAOA"]
[Thu Jul 30 13:43:24.929973 2026] [security2:error] [pid 935860:tid 935998] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dx.php"] [unique_id "amubTIijB6THqIZZsUL-WgAAAIw"]
[Thu Jul 30 13:43:24.930099 2026] [security2:error] [pid 935860:tid 935998] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dx.php"] [unique_id "amubTIijB6THqIZZsUL-WgAAAIw"]
[Thu Jul 30 13:43:25.175824 2026] [proxy:error] [pid 935860:tid 936065] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:25.175912 2026] [proxy_http:error] [pid 935860:tid 936065] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:25.176779 2026] [proxy:error] [pid 935860:tid 936065] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:25.176840 2026] [proxy_http:error] [pid 935860:tid 936065] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:25.176987 2026] [security2:error] [pid 935860:tid 936065] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubTYijB6THqIZZsUL-YQAAAM8"]
[Thu Jul 30 13:43:25.420941 2026] [security2:error] [pid 935860:tid 936007] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/7.php"] [unique_id "amubTYijB6THqIZZsUL-aQAAAJU"]
[Thu Jul 30 13:43:25.421049 2026] [security2:error] [pid 935860:tid 936007] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/7.php"] [unique_id "amubTYijB6THqIZZsUL-aQAAAJU"]
[Thu Jul 30 13:43:25.495805 2026] [security2:error] [pid 935860:tid 936113] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubTIijB6THqIZZsUL-VwAAAP8"]
[Thu Jul 30 13:43:25.661266 2026] [security2:error] [pid 935860:tid 935994] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/8.php"] [unique_id "amubTYijB6THqIZZsUL-cAAAAIg"]
[Thu Jul 30 13:43:25.661360 2026] [security2:error] [pid 935860:tid 935994] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/8.php"] [unique_id "amubTYijB6THqIZZsUL-cAAAAIg"]
[Thu Jul 30 13:43:25.907147 2026] [security2:error] [pid 935860:tid 935999] [client 4.185.41.66:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amubTYijB6THqIZZsUL-dwAAAI0"]
[Thu Jul 30 13:43:25.907249 2026] [security2:error] [pid 935860:tid 935999] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amubTYijB6THqIZZsUL-dwAAAI0"]
[Thu Jul 30 13:43:25.907322 2026] [security2:error] [pid 935860:tid 935999] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amubTYijB6THqIZZsUL-dwAAAI0"]
[Thu Jul 30 13:43:26.156941 2026] [security2:error] [pid 935860:tid 936050] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amubToijB6THqIZZsUL-fgAAAMA"]
[Thu Jul 30 13:43:26.157104 2026] [security2:error] [pid 935860:tid 936050] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amubToijB6THqIZZsUL-fgAAAMA"]
[Thu Jul 30 13:43:26.339923 2026] [security2:error] [pid 935860:tid 936084] [client 172.202.44.182:49957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amubToijB6THqIZZsUL-ggAAAOI"]
[Thu Jul 30 13:43:26.408304 2026] [security2:error] [pid 935860:tid 936039] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amubToijB6THqIZZsUL-hgAAALU"]
[Thu Jul 30 13:43:26.408399 2026] [security2:error] [pid 935860:tid 936039] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amubToijB6THqIZZsUL-hgAAALU"]
[Thu Jul 30 13:43:26.648657 2026] [security2:error] [pid 935860:tid 936032] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/edit.php"] [unique_id "amubToijB6THqIZZsUL-jQAAAK4"]
[Thu Jul 30 13:43:26.648948 2026] [security2:error] [pid 935860:tid 936032] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/edit.php"] [unique_id "amubToijB6THqIZZsUL-jQAAAK4"]
[Thu Jul 30 13:43:26.888418 2026] [security2:error] [pid 935860:tid 936080] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amubToijB6THqIZZsUL-kAAAAN4"]
[Thu Jul 30 13:43:26.888541 2026] [security2:error] [pid 935860:tid 936080] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amubToijB6THqIZZsUL-kAAAAN4"]
[Thu Jul 30 13:43:27.137544 2026] [security2:error] [pid 935860:tid 936103] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amubT4ijB6THqIZZsUL-_QAAAPU"]
[Thu Jul 30 13:43:27.137647 2026] [security2:error] [pid 935860:tid 936103] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amubT4ijB6THqIZZsUL-_QAAAPU"]
[Thu Jul 30 13:43:27.380121 2026] [security2:error] [pid 935860:tid 936066] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/av.php"] [unique_id "amubT4ijB6THqIZZsUL_HAAAANA"]
[Thu Jul 30 13:43:27.380261 2026] [security2:error] [pid 935860:tid 936066] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/av.php"] [unique_id "amubT4ijB6THqIZZsUL_HAAAANA"]
[Thu Jul 30 13:43:27.627432 2026] [security2:error] [pid 935860:tid 936052] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/classwithtostring.php"] [unique_id "amubT4ijB6THqIZZsUL_UQAAAMI"]
[Thu Jul 30 13:43:27.627534 2026] [security2:error] [pid 935860:tid 936052] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/classwithtostring.php"] [unique_id "amubT4ijB6THqIZZsUL_UQAAAMI"]
[Thu Jul 30 13:43:27.866227 2026] [security2:error] [pid 935860:tid 936050] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/themes/index.php"] [unique_id "amubT4ijB6THqIZZsUL_bQAAAMA"]
[Thu Jul 30 13:43:27.866387 2026] [security2:error] [pid 935860:tid 936050] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/themes/index.php"] [unique_id "amubT4ijB6THqIZZsUL_bQAAAMA"]
[Thu Jul 30 13:43:28.107681 2026] [security2:error] [pid 935860:tid 936084] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-blog.php"] [unique_id "amubUIijB6THqIZZsUL_ewAAAOI"]
[Thu Jul 30 13:43:28.107777 2026] [security2:error] [pid 935860:tid 936084] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-blog.php"] [unique_id "amubUIijB6THqIZZsUL_ewAAAOI"]
[Thu Jul 30 13:43:28.356760 2026] [proxy:error] [pid 935860:tid 936007] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:28.356846 2026] [proxy_http:error] [pid 935860:tid 936007] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:28.357573 2026] [proxy:error] [pid 935860:tid 936007] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:28.357618 2026] [proxy_http:error] [pid 935860:tid 936007] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:28.357719 2026] [security2:error] [pid 935860:tid 936007] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubUIijB6THqIZZsUL_hgAAAJU"]
[Thu Jul 30 13:43:28.526689 2026] [security2:error] [pid 935860:tid 936045] [client 172.202.44.182:49774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/plugins.php"] [unique_id "amubUIijB6THqIZZsUL_iwAAALs"]
[Thu Jul 30 13:43:28.604203 2026] [security2:error] [pid 935860:tid 936021] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amubUIijB6THqIZZsUL_kAAAAKM"]
[Thu Jul 30 13:43:28.604311 2026] [security2:error] [pid 935860:tid 936021] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-content/admin.php"] [unique_id "amubUIijB6THqIZZsUL_kAAAAKM"]
[Thu Jul 30 13:43:28.844923 2026] [security2:error] [pid 935860:tid 936049] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/adminfuns.php"] [unique_id "amubUIijB6THqIZZsUL_lAAAAL8"]
[Thu Jul 30 13:43:28.845100 2026] [security2:error] [pid 935860:tid 936049] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/adminfuns.php"] [unique_id "amubUIijB6THqIZZsUL_lAAAAL8"]
[Thu Jul 30 13:43:29.090039 2026] [security2:error] [pid 935860:tid 936036] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/goods.php"] [unique_id "amubUYijB6THqIZZsUL_ngAAALI"]
[Thu Jul 30 13:43:29.090140 2026] [security2:error] [pid 935860:tid 936036] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/goods.php"] [unique_id "amubUYijB6THqIZZsUL_ngAAALI"]
[Thu Jul 30 13:43:29.337266 2026] [security2:error] [pid 935860:tid 936008] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ms-edit.php"] [unique_id "amubUYijB6THqIZZsUL_pgAAAJY"]
[Thu Jul 30 13:43:29.337383 2026] [security2:error] [pid 935860:tid 936008] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ms-edit.php"] [unique_id "amubUYijB6THqIZZsUL_pgAAAJY"]
[Thu Jul 30 13:43:29.390736 2026] [security2:error] [pid 935860:tid 936078] [client 103.242.199.184:51467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubUYijB6THqIZZsUL_qAAAANw"]
[Thu Jul 30 13:43:29.390862 2026] [security2:error] [pid 935860:tid 936078] [client 103.242.199.184:51467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubUYijB6THqIZZsUL_qAAAANw"]
[Thu Jul 30 13:43:29.584322 2026] [security2:error] [pid 935860:tid 936011] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/222.php"] [unique_id "amubUYijB6THqIZZsUL_rQAAAJk"]
[Thu Jul 30 13:43:29.584415 2026] [security2:error] [pid 935860:tid 936011] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/222.php"] [unique_id "amubUYijB6THqIZZsUL_rQAAAJk"]
[Thu Jul 30 13:43:29.842247 2026] [security2:error] [pid 935860:tid 936116] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/cgi-bin/index.php"] [unique_id "amubUYijB6THqIZZsUL_ugAAAQI"]
[Thu Jul 30 13:43:29.842400 2026] [security2:error] [pid 935860:tid 936116] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/cgi-bin/index.php"] [unique_id "amubUYijB6THqIZZsUL_ugAAAQI"]
[Thu Jul 30 13:43:29.865886 2026] [core:notice] [pid 935860:tid 936014] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:30.097602 2026] [proxy:error] [pid 935860:tid 935993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:30.097708 2026] [proxy_http:error] [pid 935860:tid 935993] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:30.099143 2026] [proxy:error] [pid 935860:tid 935993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:30.099201 2026] [proxy_http:error] [pid 935860:tid 935993] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:30.099347 2026] [security2:error] [pid 935860:tid 935993] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubUoijB6THqIZZsUL_xwAAAIc"]
[Thu Jul 30 13:43:30.356471 2026] [security2:error] [pid 935860:tid 936100] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/BDKR28WP.php"] [unique_id "amubUoijB6THqIZZsUL_1gAAAPI"]
[Thu Jul 30 13:43:30.356571 2026] [security2:error] [pid 935860:tid 936100] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/BDKR28WP.php"] [unique_id "amubUoijB6THqIZZsUL_1gAAAPI"]
[Thu Jul 30 13:43:30.567374 2026] [security2:error] [pid 935860:tid 936053] [client 172.237.109.114:59672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubUYijB6THqIZZsUL_vAAAAMM"]
[Thu Jul 30 13:43:30.606308 2026] [proxy:error] [pid 935860:tid 935994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:30.606408 2026] [proxy_http:error] [pid 935860:tid 935994] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:30.607540 2026] [proxy:error] [pid 935860:tid 935994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:30.607607 2026] [proxy_http:error] [pid 935860:tid 935994] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:30.607751 2026] [security2:error] [pid 935860:tid 935994] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubUoijB6THqIZZsUL_3AAAAIg"]
[Thu Jul 30 13:43:30.870402 2026] [proxy:error] [pid 935860:tid 936106] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:30.870512 2026] [proxy_http:error] [pid 935860:tid 936106] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:30.871408 2026] [proxy:error] [pid 935860:tid 936106] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:30.871473 2026] [proxy_http:error] [pid 935860:tid 936106] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:30.871618 2026] [security2:error] [pid 935860:tid 936106] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubUoijB6THqIZZsUL_6QAAAPg"]
[Thu Jul 30 13:43:30.931044 2026] [security2:error] [pid 935860:tid 936045] [client 68.192.47.149:59934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubUoijB6THqIZZsUL_1wAAALs"], referer: http://pkf.jo
[Thu Jul 30 13:43:31.129778 2026] [security2:error] [pid 935860:tid 936008] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp.php"] [unique_id "amubU4ijB6THqIZZsUL_8AAAAJY"]
[Thu Jul 30 13:43:31.129869 2026] [security2:error] [pid 935860:tid 936008] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp.php"] [unique_id "amubU4ijB6THqIZZsUL_8AAAAJY"]
[Thu Jul 30 13:43:31.397387 2026] [security2:error] [pid 935860:tid 936056] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/abcd.php"] [unique_id "amubU4ijB6THqIZZsUL_-AAAAMY"]
[Thu Jul 30 13:43:31.397480 2026] [security2:error] [pid 935860:tid 936056] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/abcd.php"] [unique_id "amubU4ijB6THqIZZsUL_-AAAAMY"]
[Thu Jul 30 13:43:31.645466 2026] [security2:error] [pid 935860:tid 936085] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/a1.php"] [unique_id "amubU4ijB6THqIZZsUIAAwAAAOM"]
[Thu Jul 30 13:43:31.645617 2026] [security2:error] [pid 935860:tid 936085] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/a1.php"] [unique_id "amubU4ijB6THqIZZsUIAAwAAAOM"]
[Thu Jul 30 13:43:31.713503 2026] [security2:error] [pid 935860:tid 936111] [client 104.243.223.29:36126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubU4ijB6THqIZZsUL_-QAAAP0"], referer: http://pkf.jo
[Thu Jul 30 13:43:31.763944 2026] [security2:error] [pid 935860:tid 936001] [client 103.102.136.179:16577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubU4ijB6THqIZZsUL_-gAAAI8"], referer: http://pkf.jo
[Thu Jul 30 13:43:31.858542 2026] [security2:error] [pid 935860:tid 936109] [client 113.166.163.238:49437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubU4ijB6THqIZZsUL_-wAAAPs"], referer: http://pkf.jo
[Thu Jul 30 13:43:31.898142 2026] [security2:error] [pid 935860:tid 936082] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amubU4ijB6THqIZZsUIACAAAAOA"]
[Thu Jul 30 13:43:31.898259 2026] [security2:error] [pid 935860:tid 936082] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amubU4ijB6THqIZZsUIACAAAAOA"]
[Thu Jul 30 13:43:31.915913 2026] [security2:error] [pid 935860:tid 936026] [client 78.167.1.90:57306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubU4ijB6THqIZZsUIACgAAAKg"]
[Thu Jul 30 13:43:31.916325 2026] [security2:error] [pid 935860:tid 936026] [client 78.167.1.90:57306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubU4ijB6THqIZZsUIACgAAAKg"]
[Thu Jul 30 13:43:32.149567 2026] [security2:error] [pid 935860:tid 936100] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/cgi-bin/admin.php"] [unique_id "amubVIijB6THqIZZsUIAEgAAAPI"]
[Thu Jul 30 13:43:32.149679 2026] [security2:error] [pid 935860:tid 936100] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/cgi-bin/admin.php"] [unique_id "amubVIijB6THqIZZsUIAEgAAAPI"]
[Thu Jul 30 13:43:32.410538 2026] [proxy:error] [pid 935860:tid 936081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:32.410621 2026] [proxy_http:error] [pid 935860:tid 936081] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:32.411214 2026] [proxy:error] [pid 935860:tid 936081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:32.411265 2026] [proxy_http:error] [pid 935860:tid 936081] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:32.411343 2026] [security2:error] [pid 935860:tid 936081] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubVIijB6THqIZZsUIAPgAAAN8"]
[Thu Jul 30 13:43:32.463397 2026] [security2:error] [pid 935860:tid 936000] [client 176.28.176.98:14527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubVIijB6THqIZZsUIAFQAAAI4"], referer: http://pkf.jo
[Thu Jul 30 13:43:32.663189 2026] [security2:error] [pid 935860:tid 935998] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/simple.php"] [unique_id "amubVIijB6THqIZZsUIAhQAAAIw"]
[Thu Jul 30 13:43:32.663313 2026] [security2:error] [pid 935860:tid 935998] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/simple.php"] [unique_id "amubVIijB6THqIZZsUIAhQAAAIw"]
[Thu Jul 30 13:43:32.820740 2026] [security2:error] [pid 935860:tid 936063] [client 74.7.244.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.okcasino-1.com"] [uri "/robots.txt"] [unique_id "amubVIijB6THqIZZsUIAlQAAzXY"]
[Thu Jul 30 13:43:32.838245 2026] [security2:error] [pid 935860:tid 936091] [client 14.191.167.98:14310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubVIijB6THqIZZsUIAUAAAAOk"], referer: http://pkf.jo
[Thu Jul 30 13:43:32.913864 2026] [security2:error] [pid 935860:tid 936087] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xxx.php"] [unique_id "amubVIijB6THqIZZsUIAlgAAAOU"]
[Thu Jul 30 13:43:32.913993 2026] [security2:error] [pid 935860:tid 936087] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xxx.php"] [unique_id "amubVIijB6THqIZZsUIAlgAAAOU"]
[Thu Jul 30 13:43:32.982115 2026] [security2:error] [pid 935860:tid 936094] [client 216.24.212.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amubVIijB6THqIZZsUIAlAAAAOw"], referer: https://cnpinyin.com/category/
[Thu Jul 30 13:43:33.155254 2026] [security2:error] [pid 935860:tid 936017] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/hypo.php"] [unique_id "amubVYijB6THqIZZsUIAmQAAAJ8"]
[Thu Jul 30 13:43:33.155385 2026] [security2:error] [pid 935860:tid 936017] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/hypo.php"] [unique_id "amubVYijB6THqIZZsUIAmQAAAJ8"]
[Thu Jul 30 13:43:33.166146 2026] [security2:error] [pid 935860:tid 936052] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubVIijB6THqIZZsUIAWQAAAMI"]
[Thu Jul 30 13:43:33.413458 2026] [proxy:error] [pid 935860:tid 936067] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:33.413549 2026] [proxy_http:error] [pid 935860:tid 936067] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:33.414189 2026] [proxy:error] [pid 935860:tid 936067] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:33.414238 2026] [proxy_http:error] [pid 935860:tid 936067] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:33.414331 2026] [security2:error] [pid 935860:tid 936067] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubVYijB6THqIZZsUIApQAAANE"]
[Thu Jul 30 13:43:33.671240 2026] [security2:error] [pid 935860:tid 936010] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/chosen.php"] [unique_id "amubVYijB6THqIZZsUIAqgAAAJg"]
[Thu Jul 30 13:43:33.671380 2026] [security2:error] [pid 935860:tid 936010] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/chosen.php"] [unique_id "amubVYijB6THqIZZsUIAqgAAAJg"]
[Thu Jul 30 13:43:33.873153 2026] [security2:error] [pid 935860:tid 936049] [client 197.95.62.185:38978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubVYijB6THqIZZsUIApgAAAL8"], referer: http://pkf.jo
[Thu Jul 30 13:43:33.912813 2026] [proxy:error] [pid 935860:tid 936030] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:33.912887 2026] [proxy_http:error] [pid 935860:tid 936030] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:33.913473 2026] [proxy:error] [pid 935860:tid 936030] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:33.913524 2026] [proxy_http:error] [pid 935860:tid 936030] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:33.913608 2026] [security2:error] [pid 935860:tid 936030] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubVYijB6THqIZZsUIAtQAAAKw"]
[Thu Jul 30 13:43:33.917909 2026] [security2:error] [pid 935860:tid 936041] [client 209.61.12.150:36220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubVYijB6THqIZZsUIApwAAALc"], referer: http://pkf.jo
[Thu Jul 30 13:43:34.000675 2026] [security2:error] [pid 935860:tid 936103] [client 172.202.44.182:49974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/js/index.php"] [unique_id "amubVYijB6THqIZZsUIAtgAAAPU"]
[Thu Jul 30 13:43:34.154810 2026] [security2:error] [pid 935860:tid 936088] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/als.php"] [unique_id "amubVoijB6THqIZZsUIAvQAAAOY"]
[Thu Jul 30 13:43:34.154927 2026] [security2:error] [pid 935860:tid 936088] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/als.php"] [unique_id "amubVoijB6THqIZZsUIAvQAAAOY"]
[Thu Jul 30 13:43:34.416532 2026] [security2:error] [pid 935860:tid 936033] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/pol.php"] [unique_id "amubVoijB6THqIZZsUIAygAAAK8"]
[Thu Jul 30 13:43:34.416653 2026] [security2:error] [pid 935860:tid 936033] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/pol.php"] [unique_id "amubVoijB6THqIZZsUIAygAAAK8"]
[Thu Jul 30 13:43:34.667404 2026] [security2:error] [pid 935860:tid 936005] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file5.php"] [unique_id "amubVoijB6THqIZZsUIAzwAAAJM"]
[Thu Jul 30 13:43:34.667531 2026] [security2:error] [pid 935860:tid 936005] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file5.php"] [unique_id "amubVoijB6THqIZZsUIAzwAAAJM"]
[Thu Jul 30 13:43:34.912946 2026] [security2:error] [pid 935860:tid 936056] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file.php"] [unique_id "amubVoijB6THqIZZsUIA2gAAAMY"]
[Thu Jul 30 13:43:34.913097 2026] [security2:error] [pid 935860:tid 936056] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file.php"] [unique_id "amubVoijB6THqIZZsUIA2gAAAMY"]
[Thu Jul 30 13:43:35.033960 2026] [security2:error] [pid 935860:tid 936071] [client 74.7.175.188:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.online-hope.com"] [uri "/index.php"] [unique_id "amubVoijB6THqIZZsUIAvAAAANU"]
[Thu Jul 30 13:43:35.034137 2026] [security2:error] [pid 935860:tid 936071] [client 74.7.175.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.online-hope.com"] [uri "/index.php"] [unique_id "amubVoijB6THqIZZsUIAvAAAANU"]
[Thu Jul 30 13:43:35.035139 2026] [security2:error] [pid 935860:tid 936058] [client 74.7.175.188:53680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.online-hope.com"] [uri "/robots.txt"] [unique_id "amubVoijB6THqIZZsUIAugAAyCY"]
[Thu Jul 30 13:43:35.155103 2026] [security2:error] [pid 935860:tid 936044] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amubV4ijB6THqIZZsUIA4AAAALo"]
[Thu Jul 30 13:43:35.155229 2026] [security2:error] [pid 935860:tid 936044] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amubV4ijB6THqIZZsUIA4AAAALo"]
[Thu Jul 30 13:43:35.409973 2026] [security2:error] [pid 935860:tid 936108] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/aa2.php"] [unique_id "amubV4ijB6THqIZZsUIA8QAAAPo"]
[Thu Jul 30 13:43:35.410135 2026] [security2:error] [pid 935860:tid 936108] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/aa2.php"] [unique_id "amubV4ijB6THqIZZsUIA8QAAAPo"]
[Thu Jul 30 13:43:35.651803 2026] [security2:error] [pid 935860:tid 936103] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ccou.php"] [unique_id "amubV4ijB6THqIZZsUIA8wAAAPU"]
[Thu Jul 30 13:43:35.651917 2026] [security2:error] [pid 935860:tid 936103] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ccou.php"] [unique_id "amubV4ijB6THqIZZsUIA8wAAAPU"]
[Thu Jul 30 13:43:35.675944 2026] [security2:error] [pid 935860:tid 936049] [client 74.7.175.188:53694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "online-hope.com"] [uri "/robots.txt"] [unique_id "amubV4ijB6THqIZZsUIA9AAAvx4"], referer: https://www.online-hope.com/robots.txt
[Thu Jul 30 13:43:35.882043 2026] [security2:error] [pid 935860:tid 936078] [client 216.24.212.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amubV4ijB6THqIZZsUIA-gAAANw"], referer: https://cnpinyin.com/register
[Thu Jul 30 13:43:35.892952 2026] [security2:error] [pid 935860:tid 936084] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dr.php"] [unique_id "amubV4ijB6THqIZZsUIA_QAAAOI"]
[Thu Jul 30 13:43:35.893070 2026] [security2:error] [pid 935860:tid 936084] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dr.php"] [unique_id "amubV4ijB6THqIZZsUIA_QAAAOI"]
[Thu Jul 30 13:43:36.134451 2026] [security2:error] [pid 935860:tid 936056] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xamp.php"] [unique_id "amubWIijB6THqIZZsUIBBAAAAMY"]
[Thu Jul 30 13:43:36.134599 2026] [security2:error] [pid 935860:tid 936056] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xamp.php"] [unique_id "amubWIijB6THqIZZsUIBBAAAAMY"]
[Thu Jul 30 13:43:36.384417 2026] [security2:error] [pid 935860:tid 936100] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/bless.php"] [unique_id "amubWIijB6THqIZZsUIBCAAAAPI"]
[Thu Jul 30 13:43:36.384558 2026] [security2:error] [pid 935860:tid 936100] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/bless.php"] [unique_id "amubWIijB6THqIZZsUIBCAAAAPI"]
[Thu Jul 30 13:43:36.625642 2026] [security2:error] [pid 935860:tid 936110] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file25.php"] [unique_id "amubWIijB6THqIZZsUIBEAAAAPw"]
[Thu Jul 30 13:43:36.625814 2026] [security2:error] [pid 935860:tid 936110] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file25.php"] [unique_id "amubWIijB6THqIZZsUIBEAAAAPw"]
[Thu Jul 30 13:43:36.867452 2026] [security2:error] [pid 935860:tid 936023] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file6.php"] [unique_id "amubWIijB6THqIZZsUIBFgAAAKU"]
[Thu Jul 30 13:43:36.867581 2026] [security2:error] [pid 935860:tid 936023] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file6.php"] [unique_id "amubWIijB6THqIZZsUIBFgAAAKU"]
[Thu Jul 30 13:43:37.113345 2026] [security2:error] [pid 935860:tid 936041] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/a2.php"] [unique_id "amubWYijB6THqIZZsUIBHQAAALc"]
[Thu Jul 30 13:43:37.113471 2026] [security2:error] [pid 935860:tid 936041] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/a2.php"] [unique_id "amubWYijB6THqIZZsUIBHQAAALc"]
[Thu Jul 30 13:43:37.364027 2026] [security2:error] [pid 935860:tid 936012] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file15.php"] [unique_id "amubWYijB6THqIZZsUIBIgAAAJo"]
[Thu Jul 30 13:43:37.364144 2026] [security2:error] [pid 935860:tid 936012] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file15.php"] [unique_id "amubWYijB6THqIZZsUIBIgAAAJo"]
[Thu Jul 30 13:43:37.606731 2026] [security2:error] [pid 935860:tid 936024] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/f35.php"] [unique_id "amubWYijB6THqIZZsUIBKwAAAKY"]
[Thu Jul 30 13:43:37.606918 2026] [security2:error] [pid 935860:tid 936024] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/f35.php"] [unique_id "amubWYijB6THqIZZsUIBKwAAAKY"]
[Thu Jul 30 13:43:37.845826 2026] [security2:error] [pid 935860:tid 936026] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-load.php"] [unique_id "amubWYijB6THqIZZsUIBLwAAAKg"]
[Thu Jul 30 13:43:37.845973 2026] [security2:error] [pid 935860:tid 936026] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-load.php"] [unique_id "amubWYijB6THqIZZsUIBLwAAAKg"]
[Thu Jul 30 13:43:38.061670 2026] [core:notice] [pid 935860:tid 936040] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:38.085304 2026] [security2:error] [pid 935860:tid 936069] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xwpg.php"] [unique_id "amubWoijB6THqIZZsUIBOQAAANM"]
[Thu Jul 30 13:43:38.085474 2026] [security2:error] [pid 935860:tid 936069] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xwpg.php"] [unique_id "amubWoijB6THqIZZsUIBOQAAANM"]
[Thu Jul 30 13:43:38.122773 2026] [security2:error] [pid 935860:tid 935875] [remote 216.73.217.142:27954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amubWoijB6THqIZZsUIBOwAA5w0"]
[Thu Jul 30 13:43:38.123910 2026] [security2:error] [pid 935860:tid 935952] [remote 216.73.217.142:27954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileloc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "httpd.conf"] [severity "CRITICAL"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amubWoijB6THqIZZsUIBOgAA51o"]
[Thu Jul 30 13:43:38.302004 2026] [security2:error] [pid 935860:tid 935995] [client 172.237.109.114:46315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubWYijB6THqIZZsUIBNAAAAIk"]
[Thu Jul 30 13:43:38.332689 2026] [proxy:error] [pid 935860:tid 936114] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:38.332766 2026] [proxy_http:error] [pid 935860:tid 936114] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:38.333352 2026] [proxy:error] [pid 935860:tid 936114] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:38.333398 2026] [proxy_http:error] [pid 935860:tid 936114] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:38.333516 2026] [security2:error] [pid 935860:tid 936114] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubWoijB6THqIZZsUIBQgAAAQA"]
[Thu Jul 30 13:43:38.583472 2026] [proxy:error] [pid 935860:tid 936025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:38.583574 2026] [proxy_http:error] [pid 935860:tid 936025] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:38.584278 2026] [proxy:error] [pid 935860:tid 936025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:38.584334 2026] [proxy_http:error] [pid 935860:tid 936025] [client 4.185.41.66:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:38.584440 2026] [security2:error] [pid 935860:tid 936025] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amubWoijB6THqIZZsUIBTAAAAKc"]
[Thu Jul 30 13:43:38.835267 2026] [security2:error] [pid 935860:tid 936016] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xstelth.php"] [unique_id "amubWoijB6THqIZZsUIBVgAAAJ4"]
[Thu Jul 30 13:43:38.835369 2026] [security2:error] [pid 935860:tid 936016] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xstelth.php"] [unique_id "amubWoijB6THqIZZsUIBVgAAAJ4"]
[Thu Jul 30 13:43:39.073685 2026] [security2:error] [pid 935860:tid 936046] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amubW4ijB6THqIZZsUIBXgAAALw"]
[Thu Jul 30 13:43:39.073802 2026] [security2:error] [pid 935860:tid 936046] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amubW4ijB6THqIZZsUIBXgAAALw"]
[Thu Jul 30 13:43:39.109715 2026] [security2:error] [pid 935860:tid 936000] [client 172.202.44.182:49756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/go.php"] [unique_id "amubW4ijB6THqIZZsUIBYAAAAI4"]
[Thu Jul 30 13:43:39.313007 2026] [security2:error] [pid 935860:tid 936105] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/aaa.php"] [unique_id "amubW4ijB6THqIZZsUIBYwAAAPc"]
[Thu Jul 30 13:43:39.313133 2026] [security2:error] [pid 935860:tid 936105] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/aaa.php"] [unique_id "amubW4ijB6THqIZZsUIBYwAAAPc"]
[Thu Jul 30 13:43:39.557910 2026] [security2:error] [pid 935860:tid 936109] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/gecko.php"] [unique_id "amubW4ijB6THqIZZsUIBbQAAAPs"]
[Thu Jul 30 13:43:39.558045 2026] [security2:error] [pid 935860:tid 936109] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/gecko.php"] [unique_id "amubW4ijB6THqIZZsUIBbQAAAPs"]
[Thu Jul 30 13:43:39.804101 2026] [security2:error] [pid 935860:tid 936040] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/pbck.php"] [unique_id "amubW4ijB6THqIZZsUIBdQAAALY"]
[Thu Jul 30 13:43:39.804189 2026] [security2:error] [pid 935860:tid 936040] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/pbck.php"] [unique_id "amubW4ijB6THqIZZsUIBdQAAALY"]
[Thu Jul 30 13:43:40.043663 2026] [security2:error] [pid 935860:tid 936076] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xiugai.php"] [unique_id "amubXIijB6THqIZZsUIBeQAAANo"]
[Thu Jul 30 13:43:40.043778 2026] [security2:error] [pid 935860:tid 936076] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xiugai.php"] [unique_id "amubXIijB6THqIZZsUIBeQAAANo"]
[Thu Jul 30 13:43:40.055731 2026] [security2:error] [pid 935860:tid 936052] [client 103.242.199.184:52004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubXIijB6THqIZZsUIBewAAAMI"]
[Thu Jul 30 13:43:40.055821 2026] [security2:error] [pid 935860:tid 936052] [client 103.242.199.184:52004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubXIijB6THqIZZsUIBewAAAMI"]
[Thu Jul 30 13:43:40.159281 2026] [security2:error] [pid 935860:tid 935932] [remote 57.141.0.60:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83688077468/feed/rss2/"] [unique_id "amubXIijB6THqIZZsUIBgQAAn0Y"]
[Thu Jul 30 13:43:40.283891 2026] [security2:error] [pid 935860:tid 936101] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/e.php"] [unique_id "amubXIijB6THqIZZsUIBggAAAPM"]
[Thu Jul 30 13:43:40.284015 2026] [security2:error] [pid 935860:tid 936101] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/e.php"] [unique_id "amubXIijB6THqIZZsUIBggAAAPM"]
[Thu Jul 30 13:43:40.484609 2026] [security2:error] [pid 935860:tid 936039] [client 172.202.44.182:49729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/test1.php"] [unique_id "amubXIijB6THqIZZsUIBiQAAALU"]
[Thu Jul 30 13:43:40.520781 2026] [security2:error] [pid 935860:tid 936095] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/adminner.php"] [unique_id "amubXIijB6THqIZZsUIBigAAAO0"]
[Thu Jul 30 13:43:40.520885 2026] [security2:error] [pid 935860:tid 936095] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/adminner.php"] [unique_id "amubXIijB6THqIZZsUIBigAAAO0"]
[Thu Jul 30 13:43:40.776564 2026] [security2:error] [pid 935860:tid 936016] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file1221.php"] [unique_id "amubXIijB6THqIZZsUIBkQAAAJ4"]
[Thu Jul 30 13:43:40.776707 2026] [security2:error] [pid 935860:tid 936016] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/file1221.php"] [unique_id "amubXIijB6THqIZZsUIBkQAAAJ4"]
[Thu Jul 30 13:43:41.019591 2026] [security2:error] [pid 935860:tid 936036] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/inx.php"] [unique_id "amubXYijB6THqIZZsUIBlgAAALI"]
[Thu Jul 30 13:43:41.019710 2026] [security2:error] [pid 935860:tid 936036] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/inx.php"] [unique_id "amubXYijB6THqIZZsUIBlgAAALI"]
[Thu Jul 30 13:43:41.262555 2026] [security2:error] [pid 935860:tid 936105] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/qqqa.php"] [unique_id "amubXYijB6THqIZZsUIBngAAAPc"]
[Thu Jul 30 13:43:41.262669 2026] [security2:error] [pid 935860:tid 936105] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/qqqa.php"] [unique_id "amubXYijB6THqIZZsUIBngAAAPc"]
[Thu Jul 30 13:43:41.436499 2026] [security2:error] [pid 935860:tid 935963] [remote 57.141.0.31:64164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3293993679/feed/rss2/"] [unique_id "amubXYijB6THqIZZsUIBnAAA9WU"]
[Thu Jul 30 13:43:41.502039 2026] [security2:error] [pid 935860:tid 936024] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/reviall.php"] [unique_id "amubXYijB6THqIZZsUIBogAAAKY"]
[Thu Jul 30 13:43:41.502151 2026] [security2:error] [pid 935860:tid 936024] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/reviall.php"] [unique_id "amubXYijB6THqIZZsUIBogAAAKY"]
[Thu Jul 30 13:43:41.759530 2026] [security2:error] [pid 935860:tid 936082] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/404.php"] [unique_id "amubXYijB6THqIZZsUIBqQAAAOA"]
[Thu Jul 30 13:43:41.759679 2026] [security2:error] [pid 935860:tid 936082] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/404.php"] [unique_id "amubXYijB6THqIZZsUIBqQAAAOA"]
[Thu Jul 30 13:43:42.010717 2026] [security2:error] [pid 935860:tid 936054] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/bolt.php"] [unique_id "amubXoijB6THqIZZsUIBrQAAAMQ"]
[Thu Jul 30 13:43:42.010825 2026] [security2:error] [pid 935860:tid 936054] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/bolt.php"] [unique_id "amubXoijB6THqIZZsUIBrQAAAMQ"]
[Thu Jul 30 13:43:42.254177 2026] [security2:error] [pid 935860:tid 936011] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/File.php"] [unique_id "amubXoijB6THqIZZsUIBsQAAAJk"]
[Thu Jul 30 13:43:42.254316 2026] [security2:error] [pid 935860:tid 936011] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/File.php"] [unique_id "amubXoijB6THqIZZsUIBsQAAAJk"]
[Thu Jul 30 13:43:42.293099 2026] [proxy:error] [pid 935860:tid 936091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:42.293161 2026] [proxy_http:error] [pid 935860:tid 936091] [client 172.202.44.182:49780] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:42.293742 2026] [proxy:error] [pid 935860:tid 936091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:42.293787 2026] [proxy_http:error] [pid 935860:tid 936091] [client 172.202.44.182:49780] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:42.492298 2026] [security2:error] [pid 935860:tid 936087] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/fi22.php"] [unique_id "amubXoijB6THqIZZsUIBuQAAAOU"]
[Thu Jul 30 13:43:42.492416 2026] [security2:error] [pid 935860:tid 936087] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/fi22.php"] [unique_id "amubXoijB6THqIZZsUIBuQAAAOU"]
[Thu Jul 30 13:43:42.520892 2026] [core:notice] [pid 935860:tid 935955] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:42.734326 2026] [security2:error] [pid 935860:tid 936035] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/zero.php"] [unique_id "amubXoijB6THqIZZsUIBvgAAALE"]
[Thu Jul 30 13:43:42.734485 2026] [security2:error] [pid 935860:tid 936035] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/zero.php"] [unique_id "amubXoijB6THqIZZsUIBvgAAALE"]
[Thu Jul 30 13:43:42.984930 2026] [security2:error] [pid 935860:tid 936027] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1xmomo.php"] [unique_id "amubXoijB6THqIZZsUIBywAAAKk"]
[Thu Jul 30 13:43:42.985047 2026] [security2:error] [pid 935860:tid 936027] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1xmomo.php"] [unique_id "amubXoijB6THqIZZsUIBywAAAKk"]
[Thu Jul 30 13:43:43.223406 2026] [security2:error] [pid 935860:tid 936088] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/fmws.php"] [unique_id "amubX4ijB6THqIZZsUIBzgAAAOY"]
[Thu Jul 30 13:43:43.223524 2026] [security2:error] [pid 935860:tid 936088] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/fmws.php"] [unique_id "amubX4ijB6THqIZZsUIBzgAAAOY"]
[Thu Jul 30 13:43:43.466318 2026] [security2:error] [pid 935860:tid 936070] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amubX4ijB6THqIZZsUIB2QAAANQ"]
[Thu Jul 30 13:43:43.466435 2026] [security2:error] [pid 935860:tid 936070] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amubX4ijB6THqIZZsUIB2QAAANQ"]
[Thu Jul 30 13:43:43.705732 2026] [security2:error] [pid 935860:tid 936030] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/hp2.php"] [unique_id "amubX4ijB6THqIZZsUIB2gAAAKw"]
[Thu Jul 30 13:43:43.705842 2026] [security2:error] [pid 935860:tid 936030] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/hp2.php"] [unique_id "amubX4ijB6THqIZZsUIB2gAAAKw"]
[Thu Jul 30 13:43:43.954171 2026] [security2:error] [pid 935860:tid 936054] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/aabb.php"] [unique_id "amubX4ijB6THqIZZsUIB5QAAAMQ"]
[Thu Jul 30 13:43:43.954293 2026] [security2:error] [pid 935860:tid 936054] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/aabb.php"] [unique_id "amubX4ijB6THqIZZsUIB5QAAAMQ"]
[Thu Jul 30 13:43:44.200053 2026] [security2:error] [pid 935860:tid 936053] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1254xx.php"] [unique_id "amubYIijB6THqIZZsUIB5wAAAMM"]
[Thu Jul 30 13:43:44.200171 2026] [security2:error] [pid 935860:tid 936053] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1254xx.php"] [unique_id "amubYIijB6THqIZZsUIB5wAAAMM"]
[Thu Jul 30 13:43:44.370898 2026] [security2:error] [pid 935860:tid 936015] [client 172.202.44.182:49941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/images/index.php"] [unique_id "amubYIijB6THqIZZsUIB7wAAAJ0"]
[Thu Jul 30 13:43:44.446166 2026] [security2:error] [pid 935860:tid 936051] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amubYIijB6THqIZZsUIB8QAAAME"]
[Thu Jul 30 13:43:44.446278 2026] [security2:error] [pid 935860:tid 936051] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amubYIijB6THqIZZsUIB8QAAAME"]
[Thu Jul 30 13:43:44.684923 2026] [security2:error] [pid 935860:tid 936025] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/pms297.php"] [unique_id "amubYIijB6THqIZZsUIB9AAAAKc"]
[Thu Jul 30 13:43:44.685080 2026] [security2:error] [pid 935860:tid 936025] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/pms297.php"] [unique_id "amubYIijB6THqIZZsUIB9AAAAKc"]
[Thu Jul 30 13:43:44.925672 2026] [security2:error] [pid 935860:tid 936095] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amubYIijB6THqIZZsUICAAAAAO0"]
[Thu Jul 30 13:43:44.925783 2026] [security2:error] [pid 935860:tid 936095] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amubYIijB6THqIZZsUICAAAAAO0"]
[Thu Jul 30 13:43:45.167917 2026] [security2:error] [pid 935860:tid 936036] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amubYYijB6THqIZZsUICBAAAALI"]
[Thu Jul 30 13:43:45.168076 2026] [security2:error] [pid 935860:tid 936036] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amubYYijB6THqIZZsUICBAAAALI"]
[Thu Jul 30 13:43:45.412004 2026] [security2:error] [pid 935860:tid 936109] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amubYYijB6THqIZZsUICDgAAAPs"]
[Thu Jul 30 13:43:45.412109 2026] [security2:error] [pid 935860:tid 936109] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amubYYijB6THqIZZsUICDgAAAPs"]
[Thu Jul 30 13:43:45.588282 2026] [security2:error] [pid 935860:tid 936070] [client 78.167.1.90:55145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubYYijB6THqIZZsUICFAAAANQ"]
[Thu Jul 30 13:43:45.589011 2026] [security2:error] [pid 935860:tid 936070] [client 78.167.1.90:55145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubYYijB6THqIZZsUICFAAAANQ"]
[Thu Jul 30 13:43:45.660647 2026] [security2:error] [pid 935860:tid 936005] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amubYYijB6THqIZZsUICFgAAAJM"]
[Thu Jul 30 13:43:45.660752 2026] [security2:error] [pid 935860:tid 936005] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amubYYijB6THqIZZsUICFgAAAJM"]
[Thu Jul 30 13:43:45.908462 2026] [security2:error] [pid 935860:tid 936053] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dyui.php"] [unique_id "amubYYijB6THqIZZsUICHQAAAMM"]
[Thu Jul 30 13:43:45.908626 2026] [security2:error] [pid 935860:tid 936053] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/dyui.php"] [unique_id "amubYYijB6THqIZZsUICHQAAAMM"]
[Thu Jul 30 13:43:46.147780 2026] [security2:error] [pid 935860:tid 936080] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ho.php"] [unique_id "amubYoijB6THqIZZsUICJwAAAN4"]
[Thu Jul 30 13:43:46.147906 2026] [security2:error] [pid 935860:tid 936080] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ho.php"] [unique_id "amubYoijB6THqIZZsUICJwAAAN4"]
[Thu Jul 30 13:43:46.304661 2026] [security2:error] [pid 935860:tid 936051] [client 34.74.242.206:1584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amubYoijB6THqIZZsUICKAAAAME"]
[Thu Jul 30 13:43:46.304814 2026] [security2:error] [pid 935860:tid 936051] [client 34.74.242.206:1584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amubYoijB6THqIZZsUICKAAAAME"]
[Thu Jul 30 13:43:46.387661 2026] [security2:error] [pid 935860:tid 936101] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/66b867516c8f01.php"] [unique_id "amubYoijB6THqIZZsUICLgAAAPM"]
[Thu Jul 30 13:43:46.387751 2026] [security2:error] [pid 935860:tid 936101] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/66b867516c8f01.php"] [unique_id "amubYoijB6THqIZZsUICLgAAAPM"]
[Thu Jul 30 13:43:46.595207 2026] [security2:error] [pid 935860:tid 936011] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubYYijB6THqIZZsUICIQAAAJk"]
[Thu Jul 30 13:43:46.638803 2026] [security2:error] [pid 935860:tid 936106] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ext.php"] [unique_id "amubYoijB6THqIZZsUICOAAAAPg"]
[Thu Jul 30 13:43:46.638889 2026] [security2:error] [pid 935860:tid 936106] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/ext.php"] [unique_id "amubYoijB6THqIZZsUICOAAAAPg"]
[Thu Jul 30 13:43:46.753155 2026] [security2:error] [pid 935860:tid 936116] [client 34.74.242.206:1576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/"] [unique_id "amubYoijB6THqIZZsUICOQAAAQI"]
[Thu Jul 30 13:43:46.753308 2026] [security2:error] [pid 935860:tid 936116] [client 34.74.242.206:1576] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/"] [unique_id "amubYoijB6THqIZZsUICOQAAAQI"]
[Thu Jul 30 13:43:46.894454 2026] [security2:error] [pid 935860:tid 936023] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amubYoijB6THqIZZsUICOwAAAKU"]
[Thu Jul 30 13:43:46.894601 2026] [security2:error] [pid 935860:tid 936023] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amubYoijB6THqIZZsUICOwAAAKU"]
[Thu Jul 30 13:43:47.154084 2026] [security2:error] [pid 935860:tid 936059] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amubY4ijB6THqIZZsUICRgAAAMk"]
[Thu Jul 30 13:43:47.154236 2026] [security2:error] [pid 935860:tid 936059] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amubY4ijB6THqIZZsUICRgAAAMk"]
[Thu Jul 30 13:43:47.393370 2026] [security2:error] [pid 935860:tid 936049] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/584062352875874akp.php"] [unique_id "amubY4ijB6THqIZZsUICSAAAAL8"]
[Thu Jul 30 13:43:47.393468 2026] [security2:error] [pid 935860:tid 936049] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/584062352875874akp.php"] [unique_id "amubY4ijB6THqIZZsUICSAAAAL8"]
[Thu Jul 30 13:43:47.645698 2026] [security2:error] [pid 935860:tid 936098] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/diidi.php"] [unique_id "amubY4ijB6THqIZZsUICUgAAAPA"]
[Thu Jul 30 13:43:47.645796 2026] [security2:error] [pid 935860:tid 936098] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/diidi.php"] [unique_id "amubY4ijB6THqIZZsUICUgAAAPA"]
[Thu Jul 30 13:43:47.888390 2026] [security2:error] [pid 935860:tid 936111] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/clarebypas.php"] [unique_id "amubY4ijB6THqIZZsUICVwAAAP0"]
[Thu Jul 30 13:43:47.888507 2026] [security2:error] [pid 935860:tid 936111] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.bestdogproductguide.com"] [uri "/clarebypas.php"] [unique_id "amubY4ijB6THqIZZsUICVwAAAP0"]
[Thu Jul 30 13:43:50.196708 2026] [security2:error] [pid 935860:tid 935976] [remote 114.119.147.129:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "propertyspro.com"] [uri "/robots.txt"] [unique_id "amubZoijB6THqIZZsUICjwAApHI"], referer: https://propertyspro.com/robots.txt
[Thu Jul 30 13:43:50.751990 2026] [security2:error] [pid 935860:tid 936074] [client 103.242.199.184:52545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubZoijB6THqIZZsUICnwAAANg"]
[Thu Jul 30 13:43:50.752629 2026] [security2:error] [pid 935860:tid 936074] [client 103.242.199.184:52545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubZoijB6THqIZZsUICnwAAANg"]
[Thu Jul 30 13:43:51.860117 2026] [proxy:error] [pid 935860:tid 936106] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:51.860203 2026] [proxy_http:error] [pid 935860:tid 936106] [client 172.202.44.182:49752] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:51.860770 2026] [proxy:error] [pid 935860:tid 936106] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:43:51.860814 2026] [proxy_http:error] [pid 935860:tid 936106] [client 172.202.44.182:49752] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:43:51.889207 2026] [security2:error] [pid 935860:tid 935985] [remote 216.73.217.142:27954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileloc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "httpd.conf"] [severity "CRITICAL"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amubZ4ijB6THqIZZsUICtwAAsHs"]
[Thu Jul 30 13:43:53.302762 2026] [security2:error] [pid 935860:tid 936008] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubaIijB6THqIZZsUICwgAAlgU"]
[Thu Jul 30 13:43:53.727271 2026] [security2:error] [pid 935860:tid 936018] [client 74.7.241.177:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ooj.nyx.temporary.site"] [uri "/index.php"] [unique_id "amubYoijB6THqIZZsUICMQAAAKA"]
[Thu Jul 30 13:43:53.728135 2026] [security2:error] [pid 935860:tid 936100] [client 74.7.241.177:40956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ooj.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amubYoijB6THqIZZsUICLwAA8j0"]
[Thu Jul 30 13:43:54.219071 2026] [security2:error] [pid 935860:tid 936016] [client 78.167.1.90:54795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubaoijB6THqIZZsUIC5wAAAJ4"]
[Thu Jul 30 13:43:54.219602 2026] [security2:error] [pid 935860:tid 936016] [client 78.167.1.90:54795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubaoijB6THqIZZsUIC5wAAAJ4"]
[Thu Jul 30 13:43:54.401721 2026] [security2:error] [pid 935860:tid 936025] [client 172.202.44.182:49728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/asd.php"] [unique_id "amubaoijB6THqIZZsUIC8gAAAKc"]
[Thu Jul 30 13:43:54.569750 2026] [security2:error] [pid 935860:tid 936001] [client 104.254.90.251:51332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amubaoijB6THqIZZsUIC_AAAAI8"]
[Thu Jul 30 13:43:54.569855 2026] [security2:error] [pid 935860:tid 936001] [client 104.254.90.251:51332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amubaoijB6THqIZZsUIC_AAAAI8"]
[Thu Jul 30 13:43:54.988909 2026] [security2:error] [pid 935860:tid 936027] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubaoijB6THqIZZsUIC7wAAAKk"]
[Thu Jul 30 13:43:56.419746 2026] [security2:error] [pid 935860:tid 935933] [remote 57.141.0.18:51630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amubbIijB6THqIZZsUIDHwAArkc"]
[Thu Jul 30 13:43:56.571220 2026] [security2:error] [pid 935860:tid 936096] [client 172.202.44.182:49735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amubbIijB6THqIZZsUIDJgAAAO4"]
[Thu Jul 30 13:43:57.563670 2026] [security2:error] [pid 935860:tid 936115] [client 172.202.44.182:49750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amubbYijB6THqIZZsUIDNwAAAQE"]
[Thu Jul 30 13:43:57.740534 2026] [core:notice] [pid 935860:tid 936001] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:43:58.226785 2026] [security2:error] [pid 935860:tid 935996] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubbYijB6THqIZZsUIDOAAAijc"]
[Thu Jul 30 13:43:59.747936 2026] [security2:error] [pid 935860:tid 936008] [client 172.202.44.182:49288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/atomlib.php"] [unique_id "amubb4ijB6THqIZZsUIDcgAAAJY"]
[Thu Jul 30 13:43:59.771813 2026] [security2:error] [pid 935860:tid 936043] [client 43.133.220.37:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.220.133.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amubb4ijB6THqIZZsUIDZgAAALk"]
[Thu Jul 30 13:44:00.226098 2026] [security2:error] [pid 935860:tid 935980] [remote 157.55.39.60:14964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/uvira-reunion-des-facilitateurs-communautaires-sur-la-rehabilitation-a-base-communautaire-rbc/article.php"] [unique_id "amubb4ijB6THqIZZsUIDdgAApnY"]
[Thu Jul 30 13:44:00.284006 2026] [security2:error] [pid 935860:tid 935925] [remote 47.251.82.1:58008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-aa23bb9f.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amubcIijB6THqIZZsUIDgAAAyD8"]
[Thu Jul 30 13:44:01.314051 2026] [core:error] [pid 935860:tid 936066] [client 74.7.244.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:44:01.314074 2026] [core:error] [pid 935860:tid 936066] [client 74.7.244.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:44:01.314186 2026] [security2:error] [pid 935860:tid 936066] [client 74.7.244.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.ssa.djb.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amubcYijB6THqIZZsUIDlwAAANA"]
[Thu Jul 30 13:44:01.315017 2026] [security2:error] [pid 935860:tid 935996] [client 74.7.244.41:36412] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.ssa.djb.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amubcYijB6THqIZZsUIDkwAAig4"]
[Thu Jul 30 13:44:01.359963 2026] [security2:error] [pid 935860:tid 935994] [client 127.0.0.1:22304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amubcYijB6THqIZZsUIDmQAAAIg"]
[Thu Jul 30 13:44:01.360095 2026] [security2:error] [pid 935860:tid 936089] [client 74.7.175.159:37646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.xyh.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amubcYijB6THqIZZsUIDmAAA538"]
[Thu Jul 30 13:44:01.478458 2026] [security2:error] [pid 935860:tid 936100] [client 103.242.199.184:53088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubcYijB6THqIZZsUIDmgAAAPI"]
[Thu Jul 30 13:44:01.478609 2026] [security2:error] [pid 935860:tid 936100] [client 103.242.199.184:53088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubcYijB6THqIZZsUIDmgAAAPI"]
[Thu Jul 30 13:44:01.720329 2026] [core:error] [pid 935860:tid 936110] [client 66.249.68.36:37123] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:44:01.720360 2026] [core:error] [pid 935860:tid 936110] [client 66.249.68.36:37123] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:44:02.156116 2026] [security2:error] [pid 935860:tid 936025] [client 18.210.58.238:38396] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/02/universidade_federal_da_paraiba_ufpb_joao_pessoa2-400x210.jpg"] [unique_id "amubcoijB6THqIZZsUIDqgAAAKc"]
[Thu Jul 30 13:44:03.051511 2026] [security2:error] [pid 935860:tid 936042] [client 118.179.17.45:55454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubcoijB6THqIZZsUIDtgAAALg"], referer: http://pkf.jo
[Thu Jul 30 13:44:03.601230 2026] [security2:error] [pid 935860:tid 936016] [client 5.162.111.3:55772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubc4ijB6THqIZZsUID2wAAAJ4"], referer: http://pkf.jo
[Thu Jul 30 13:44:03.777742 2026] [security2:error] [pid 935860:tid 936013] [client 78.167.1.90:55750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubc4ijB6THqIZZsUIEBAAAAJs"]
[Thu Jul 30 13:44:03.778190 2026] [security2:error] [pid 935860:tid 936013] [client 78.167.1.90:55750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubc4ijB6THqIZZsUIEBAAAAJs"]
[Thu Jul 30 13:44:04.121002 2026] [security2:error] [pid 935860:tid 936037] [client 103.229.255.229:46332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubc4ijB6THqIZZsUIEBQAAALM"], referer: http://pkf.jo
[Thu Jul 30 13:44:04.760226 2026] [security2:error] [pid 935860:tid 935995] [client 200.181.217.249:24465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubdIijB6THqIZZsUIEJgAAAIk"], referer: http://pkf.jo
[Thu Jul 30 13:44:04.794756 2026] [security2:error] [pid 935860:tid 936091] [client 47.11.111.123:58152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubdIijB6THqIZZsUIEJwAAAOk"], referer: http://pkf.jo
[Thu Jul 30 13:44:05.448768 2026] [security2:error] [pid 935860:tid 935981] [remote 216.73.217.142:27954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileloc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "httpd.conf"] [severity "CRITICAL"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amubdYijB6THqIZZsUIEQQAA4Xc"]
[Thu Jul 30 13:44:05.570760 2026] [core:notice] [pid 935860:tid 936035] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:05.731818 2026] [security2:error] [pid 935860:tid 936018] [client 172.237.109.114:14909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubdYijB6THqIZZsUIENgAAAKA"]
[Thu Jul 30 13:44:06.045177 2026] [security2:error] [pid 935860:tid 936038] [client 178.156.185.127:33644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amubdIijB6THqIZZsUIEKwAAALQ"], referer: https://globalmarks.pk/
[Thu Jul 30 13:44:06.196175 2026] [security2:error] [pid 935860:tid 936073] [client 85.170.113.89:11128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubdYijB6THqIZZsUIERwAAANc"], referer: http://pkf.jo
[Thu Jul 30 13:44:06.459415 2026] [security2:error] [pid 935860:tid 935960] [remote 216.73.217.142:27954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileloc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "httpd.conf"] [severity "CRITICAL"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amubdoijB6THqIZZsUIEVgAAjmI"]
[Thu Jul 30 13:44:06.514412 2026] [security2:error] [pid 935860:tid 936016] [client 161.38.231.39:38418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubdoijB6THqIZZsUIEUQAAAJ4"], referer: http://pkf.jo
[Thu Jul 30 13:44:06.775557 2026] [core:notice] [pid 935860:tid 936106] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:07.632279 2026] [core:notice] [pid 935860:tid 936046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:08.456538 2026] [security2:error] [pid 935860:tid 936021] [client 172.237.109.114:5140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubd4ijB6THqIZZsUIEfwAAAKM"]
[Thu Jul 30 13:44:09.359176 2026] [core:notice] [pid 935860:tid 936010] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:09.370959 2026] [security2:error] [pid 935860:tid 936068] [client 190.120.191.151:37138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubeYijB6THqIZZsUIEmAAAANI"], referer: http://pkf.jo
[Thu Jul 30 13:44:11.096891 2026] [core:notice] [pid 935860:tid 936111] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:12.074052 2026] [security2:error] [pid 935860:tid 935999] [client 103.242.199.184:53635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubfIijB6THqIZZsUIE6wAAAI0"]
[Thu Jul 30 13:44:12.074212 2026] [security2:error] [pid 935860:tid 935999] [client 103.242.199.184:53635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubfIijB6THqIZZsUIE6wAAAI0"]
[Thu Jul 30 13:44:12.186561 2026] [security2:error] [pid 935860:tid 936011] [client 185.191.171.19:46192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amubfIijB6THqIZZsUIE7AAAAJk"]
[Thu Jul 30 13:44:12.186682 2026] [security2:error] [pid 935860:tid 936011] [client 185.191.171.19:46192] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amubfIijB6THqIZZsUIE7AAAAJk"]
[Thu Jul 30 13:44:12.759212 2026] [security2:error] [pid 935860:tid 936099] [client 85.208.96.207:60856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/author/kendeyl/"] [unique_id "amubfIijB6THqIZZsUIE-wAAAPE"]
[Thu Jul 30 13:44:12.759307 2026] [security2:error] [pid 935860:tid 936099] [client 85.208.96.207:60856] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "happyspree.app"] [uri "/author/kendeyl/"] [unique_id "amubfIijB6THqIZZsUIE-wAAAPE"]
[Thu Jul 30 13:44:13.863809 2026] [autoindex:error] [pid 935860:tid 935944] [remote 139.144.212.130:54644] AH01276: Cannot serve directory /home2/nxtudite/public_html/riisesolution.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:44:14.165874 2026] [security2:error] [pid 935860:tid 936084] [client 216.73.217.60:43787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amubfYijB6THqIZZsUIFCgAA4mk"]
[Thu Jul 30 13:44:14.217196 2026] [proxy:error] [pid 935860:tid 936102] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:14.217274 2026] [proxy_http:error] [pid 935860:tid 936102] [client 172.202.44.182:49761] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:14.218061 2026] [proxy:error] [pid 935860:tid 936102] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:14.218120 2026] [proxy_http:error] [pid 935860:tid 936102] [client 172.202.44.182:49761] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:14.378238 2026] [security2:error] [pid 935860:tid 936101] [client 78.167.1.90:55826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubfoijB6THqIZZsUIFKwAAAPM"]
[Thu Jul 30 13:44:14.378725 2026] [security2:error] [pid 935860:tid 936101] [client 78.167.1.90:55826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubfoijB6THqIZZsUIFKwAAAPM"]
[Thu Jul 30 13:44:15.554107 2026] [core:notice] [pid 935860:tid 936017] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:16.649876 2026] [security2:error] [pid 935860:tid 935981] [remote 185.61.152.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.152.61.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kinyeraagro.com"] [uri "/wp-login.php"] [unique_id "amubgIijB6THqIZZsUIFZAAA2Hc"]
[Thu Jul 30 13:44:16.677715 2026] [security2:error] [pid 935860:tid 936024] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubgIijB6THqIZZsUIFWAAAAKY"]
[Thu Jul 30 13:44:16.754913 2026] [security2:error] [pid 935860:tid 935974] [remote 57.141.0.17:47002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/96299823080/feed/rss2/"] [unique_id "amubgIijB6THqIZZsUIFawABBHA"]
[Thu Jul 30 13:44:16.905942 2026] [security2:error] [pid 935860:tid 936018] [client 43.164.129.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "magicmooncorp.com"] [uri "/index.php"] [unique_id "amubfoijB6THqIZZsUIFJwAAAKA"]
[Thu Jul 30 13:44:17.785788 2026] [security2:error] [pid 935860:tid 936087] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubgYijB6THqIZZsUIFeAAAAOU"]
[Thu Jul 30 13:44:18.693295 2026] [security2:error] [pid 935860:tid 936064] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubgoijB6THqIZZsUIFlAAAAM4"]
[Thu Jul 30 13:44:19.139773 2026] [security2:error] [pid 935860:tid 936039] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubgoijB6THqIZZsUIFngAAALU"]
[Thu Jul 30 13:44:20.530141 2026] [security2:error] [pid 935860:tid 936035] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amubhIijB6THqIZZsUIFzgAAALE"]
[Thu Jul 30 13:44:20.530272 2026] [security2:error] [pid 935860:tid 936035] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amubhIijB6THqIZZsUIFzgAAALE"]
[Thu Jul 30 13:44:20.658279 2026] [proxy:error] [pid 935860:tid 936089] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:20.658365 2026] [proxy_http:error] [pid 935860:tid 936089] [client 172.202.44.182:49749] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:20.659121 2026] [proxy:error] [pid 935860:tid 936089] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:20.659173 2026] [proxy_http:error] [pid 935860:tid 936089] [client 172.202.44.182:49749] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:20.802945 2026] [security2:error] [pid 935860:tid 936003] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amubhIijB6THqIZZsUIF1gAAAJE"]
[Thu Jul 30 13:44:20.803081 2026] [security2:error] [pid 935860:tid 936003] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amubhIijB6THqIZZsUIF1gAAAJE"]
[Thu Jul 30 13:44:21.074002 2026] [security2:error] [pid 935860:tid 936098] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/x.php"] [unique_id "amubhYijB6THqIZZsUIF3gAAAPA"]
[Thu Jul 30 13:44:21.074150 2026] [security2:error] [pid 935860:tid 936098] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/x.php"] [unique_id "amubhYijB6THqIZZsUIF3gAAAPA"]
[Thu Jul 30 13:44:21.344431 2026] [security2:error] [pid 935860:tid 936016] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/mgrr.php"] [unique_id "amubhYijB6THqIZZsUIF4gAAAJ4"]
[Thu Jul 30 13:44:21.344543 2026] [security2:error] [pid 935860:tid 936016] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/mgrr.php"] [unique_id "amubhYijB6THqIZZsUIF4gAAAJ4"]
[Thu Jul 30 13:44:21.613890 2026] [security2:error] [pid 935860:tid 936013] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/domvf.php"] [unique_id "amubhYijB6THqIZZsUIF6gAAAJs"]
[Thu Jul 30 13:44:21.614017 2026] [security2:error] [pid 935860:tid 936013] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/domvf.php"] [unique_id "amubhYijB6THqIZZsUIF6gAAAJs"]
[Thu Jul 30 13:44:21.904092 2026] [security2:error] [pid 935860:tid 936091] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/yup.php"] [unique_id "amubhYijB6THqIZZsUIF8QAAAOk"]
[Thu Jul 30 13:44:21.904186 2026] [security2:error] [pid 935860:tid 936091] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/yup.php"] [unique_id "amubhYijB6THqIZZsUIF8QAAAOk"]
[Thu Jul 30 13:44:22.176705 2026] [security2:error] [pid 935860:tid 935999] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/X.php"] [unique_id "amubhoijB6THqIZZsUIF9wAAAI0"]
[Thu Jul 30 13:44:22.176804 2026] [security2:error] [pid 935860:tid 935999] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/X.php"] [unique_id "amubhoijB6THqIZZsUIF9wAAAI0"]
[Thu Jul 30 13:44:22.449381 2026] [security2:error] [pid 935860:tid 936096] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amubhoijB6THqIZZsUIF_gAAAO4"]
[Thu Jul 30 13:44:22.449488 2026] [security2:error] [pid 935860:tid 936096] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amubhoijB6THqIZZsUIF_gAAAO4"]
[Thu Jul 30 13:44:22.710544 2026] [security2:error] [pid 935860:tid 936083] [client 103.242.199.184:54184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubhoijB6THqIZZsUIGAwAAAOE"]
[Thu Jul 30 13:44:22.710661 2026] [security2:error] [pid 935860:tid 936083] [client 103.242.199.184:54184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubhoijB6THqIZZsUIGAwAAAOE"]
[Thu Jul 30 13:44:22.714693 2026] [security2:error] [pid 935860:tid 936101] [client 204.8.98.105:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amubhoijB6THqIZZsUIGBAAAAPM"]
[Thu Jul 30 13:44:22.714772 2026] [security2:error] [pid 935860:tid 936101] [client 204.8.98.105:56950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amubhoijB6THqIZZsUIGBAAAAPM"]
[Thu Jul 30 13:44:22.738856 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/gec.php"] [unique_id "amubhoijB6THqIZZsUIGBQAAAKg"]
[Thu Jul 30 13:44:22.738943 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/gec.php"] [unique_id "amubhoijB6THqIZZsUIGBQAAAKg"]
[Thu Jul 30 13:44:22.903771 2026] [security2:error] [pid 935860:tid 936056] [client 172.202.44.182:49759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amubhoijB6THqIZZsUIGDAAAAMY"]
[Thu Jul 30 13:44:23.016077 2026] [security2:error] [pid 935860:tid 936088] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/sky.php"] [unique_id "amubh4ijB6THqIZZsUIGDgAAAOY"]
[Thu Jul 30 13:44:23.016194 2026] [security2:error] [pid 935860:tid 936088] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/sky.php"] [unique_id "amubh4ijB6THqIZZsUIGDgAAAOY"]
[Thu Jul 30 13:44:23.290856 2026] [security2:error] [pid 935860:tid 936049] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/fffm.php"] [unique_id "amubh4ijB6THqIZZsUIGEgAAAL8"]
[Thu Jul 30 13:44:23.291046 2026] [security2:error] [pid 935860:tid 936049] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/fffm.php"] [unique_id "amubh4ijB6THqIZZsUIGEgAAAL8"]
[Thu Jul 30 13:44:23.561808 2026] [security2:error] [pid 935860:tid 935998] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/sixxis.php"] [unique_id "amubh4ijB6THqIZZsUIGHQAAAIw"]
[Thu Jul 30 13:44:23.561897 2026] [security2:error] [pid 935860:tid 935998] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/sixxis.php"] [unique_id "amubh4ijB6THqIZZsUIGHQAAAIw"]
[Thu Jul 30 13:44:23.829666 2026] [security2:error] [pid 935860:tid 936040] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/yj09.php"] [unique_id "amubh4ijB6THqIZZsUIGHgAAALY"]
[Thu Jul 30 13:44:23.829786 2026] [security2:error] [pid 935860:tid 936040] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/yj09.php"] [unique_id "amubh4ijB6THqIZZsUIGHgAAALY"]
[Thu Jul 30 13:44:23.880884 2026] [security2:error] [pid 935860:tid 935985] [remote 74.7.243.224:33722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amubh4ijB6THqIZZsUIGHwAAkHs"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 13:44:24.005606 2026] [proxy:error] [pid 935860:tid 936093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:24.005662 2026] [proxy_http:error] [pid 935860:tid 936093] [client 74.7.175.182:40406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:24.006322 2026] [proxy:error] [pid 935860:tid 936093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:24.006372 2026] [proxy_http:error] [pid 935860:tid 936093] [client 74.7.175.182:40406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:24.006503 2026] [security2:error] [pid 935860:tid 936093] [client 74.7.175.182:40406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.sar.udi.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amubiIijB6THqIZZsUIGJgAAAOs"]
[Thu Jul 30 13:44:24.098456 2026] [security2:error] [pid 935860:tid 936077] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/k.php"] [unique_id "amubiIijB6THqIZZsUIGLQAAANs"]
[Thu Jul 30 13:44:24.098555 2026] [security2:error] [pid 935860:tid 936077] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/k.php"] [unique_id "amubiIijB6THqIZZsUIGLQAAANs"]
[Thu Jul 30 13:44:24.383701 2026] [security2:error] [pid 935860:tid 936009] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/k2.php"] [unique_id "amubiIijB6THqIZZsUIGLwAAAJc"]
[Thu Jul 30 13:44:24.383817 2026] [security2:error] [pid 935860:tid 936009] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/k2.php"] [unique_id "amubiIijB6THqIZZsUIGLwAAAJc"]
[Thu Jul 30 13:44:24.652131 2026] [security2:error] [pid 935860:tid 936068] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/w.php"] [unique_id "amubiIijB6THqIZZsUIGOwAAANI"]
[Thu Jul 30 13:44:24.652234 2026] [security2:error] [pid 935860:tid 936068] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/w.php"] [unique_id "amubiIijB6THqIZZsUIGOwAAANI"]
[Thu Jul 30 13:44:24.883924 2026] [security2:error] [pid 935860:tid 936023] [client 43.172.198.92:36198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/09/09/sostrene-grene-automne-2016/"] [unique_id "amubiIijB6THqIZZsUIGOQAAAKU"]
[Thu Jul 30 13:44:24.928219 2026] [security2:error] [pid 935860:tid 936097] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/fpwch.php"] [unique_id "amubiIijB6THqIZZsUIGPAAAAO8"]
[Thu Jul 30 13:44:24.928325 2026] [security2:error] [pid 935860:tid 936097] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/fpwch.php"] [unique_id "amubiIijB6THqIZZsUIGPAAAAO8"]
[Thu Jul 30 13:44:24.992682 2026] [security2:error] [pid 935860:tid 936067] [client 78.167.1.90:55603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubiIijB6THqIZZsUIGQQAAANE"]
[Thu Jul 30 13:44:24.993788 2026] [security2:error] [pid 935860:tid 936067] [client 78.167.1.90:55603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubiIijB6THqIZZsUIGQQAAANE"]
[Thu Jul 30 13:44:25.045182 2026] [proxy:error] [pid 935860:tid 936112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:25.045256 2026] [proxy_http:error] [pid 935860:tid 936112] [client 172.202.44.182:49771] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:25.045946 2026] [proxy:error] [pid 935860:tid 936112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:25.046009 2026] [proxy_http:error] [pid 935860:tid 936112] [client 172.202.44.182:49771] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:25.202438 2026] [security2:error] [pid 935860:tid 936090] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/w2025.php"] [unique_id "amubiYijB6THqIZZsUIGSgAAAOg"]
[Thu Jul 30 13:44:25.202576 2026] [security2:error] [pid 935860:tid 936090] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/w2025.php"] [unique_id "amubiYijB6THqIZZsUIGSgAAAOg"]
[Thu Jul 30 13:44:25.494109 2026] [security2:error] [pid 935860:tid 936032] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/FWAZ.php"] [unique_id "amubiYijB6THqIZZsUIGSwAAAK4"]
[Thu Jul 30 13:44:25.494274 2026] [security2:error] [pid 935860:tid 936032] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/FWAZ.php"] [unique_id "amubiYijB6THqIZZsUIGSwAAAK4"]
[Thu Jul 30 13:44:25.614797 2026] [core:notice] [pid 935860:tid 936030] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:25.621025 2026] [security2:error] [pid 935860:tid 936030] [client 43.172.194.193:36846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/09/09/sostrene-grene-automne-2016/"] [unique_id "amubiYijB6THqIZZsUIGUwAAAKw"], referer: https://carnetdeshopping.com/index.php/2016/09/09/sostrene-grene-automne-2016/?replytocom=1635
[Thu Jul 30 13:44:25.765521 2026] [security2:error] [pid 935860:tid 935991] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/qterm.php"] [unique_id "amubiYijB6THqIZZsUIGVAAAAIU"]
[Thu Jul 30 13:44:25.765651 2026] [security2:error] [pid 935860:tid 935991] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/qterm.php"] [unique_id "amubiYijB6THqIZZsUIGVAAAAIU"]
[Thu Jul 30 13:44:26.033857 2026] [security2:error] [pid 935860:tid 936012] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/blurbs.php"] [unique_id "amubioijB6THqIZZsUIGXwAAAJo"]
[Thu Jul 30 13:44:26.033951 2026] [security2:error] [pid 935860:tid 936012] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/blurbs.php"] [unique_id "amubioijB6THqIZZsUIGXwAAAJo"]
[Thu Jul 30 13:44:26.316696 2026] [security2:error] [pid 935860:tid 936093] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-ws68.php"] [unique_id "amubioijB6THqIZZsUIGZwAAAOs"]
[Thu Jul 30 13:44:26.316802 2026] [security2:error] [pid 935860:tid 936093] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-ws68.php"] [unique_id "amubioijB6THqIZZsUIGZwAAAOs"]
[Thu Jul 30 13:44:26.586531 2026] [security2:error] [pid 935860:tid 936058] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xyn.php"] [unique_id "amubioijB6THqIZZsUIGbgAAAMg"]
[Thu Jul 30 13:44:26.586689 2026] [security2:error] [pid 935860:tid 936058] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xyn.php"] [unique_id "amubioijB6THqIZZsUIGbgAAAMg"]
[Thu Jul 30 13:44:26.873002 2026] [security2:error] [pid 935860:tid 936070] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ccc.php"] [unique_id "amubioijB6THqIZZsUIGeQAAANQ"]
[Thu Jul 30 13:44:26.873196 2026] [security2:error] [pid 935860:tid 936070] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ccc.php"] [unique_id "amubioijB6THqIZZsUIGeQAAANQ"]
[Thu Jul 30 13:44:27.140802 2026] [security2:error] [pid 935860:tid 936102] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/get.php"] [unique_id "amubi4ijB6THqIZZsUIGfgAAAPQ"]
[Thu Jul 30 13:44:27.140903 2026] [security2:error] [pid 935860:tid 936102] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/get.php"] [unique_id "amubi4ijB6THqIZZsUIGfgAAAPQ"]
[Thu Jul 30 13:44:27.405552 2026] [security2:error] [pid 935860:tid 936098] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/images.php"] [unique_id "amubi4ijB6THqIZZsUIGhgAAAPA"]
[Thu Jul 30 13:44:27.405686 2026] [security2:error] [pid 935860:tid 936098] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/images.php"] [unique_id "amubi4ijB6THqIZZsUIGhgAAAPA"]
[Thu Jul 30 13:44:27.561398 2026] [security2:error] [pid 935860:tid 936096] [client 172.237.109.114:1128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubioijB6THqIZZsUIGegAAAO4"]
[Thu Jul 30 13:44:27.683668 2026] [security2:error] [pid 935860:tid 936061] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/alls.php"] [unique_id "amubi4ijB6THqIZZsUIGjgAAAMs"]
[Thu Jul 30 13:44:27.683759 2026] [security2:error] [pid 935860:tid 936061] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/alls.php"] [unique_id "amubi4ijB6THqIZZsUIGjgAAAMs"]
[Thu Jul 30 13:44:27.952640 2026] [security2:error] [pid 935860:tid 936106] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/coffexium.php"] [unique_id "amubi4ijB6THqIZZsUIGkwAAAPg"]
[Thu Jul 30 13:44:27.952763 2026] [security2:error] [pid 935860:tid 936106] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/coffexium.php"] [unique_id "amubi4ijB6THqIZZsUIGkwAAAPg"]
[Thu Jul 30 13:44:28.232444 2026] [security2:error] [pid 935860:tid 936069] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/red.php"] [unique_id "amubjIijB6THqIZZsUIGngAAANM"]
[Thu Jul 30 13:44:28.232555 2026] [security2:error] [pid 935860:tid 936069] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/red.php"] [unique_id "amubjIijB6THqIZZsUIGngAAANM"]
[Thu Jul 30 13:44:28.554451 2026] [security2:error] [pid 935860:tid 936004] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/sodium_compat/"] [unique_id "amubjIijB6THqIZZsUIGowAAAJI"]
[Thu Jul 30 13:44:28.701734 2026] [security2:error] [pid 935860:tid 935999] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amubjIijB6THqIZZsUIGqQAAAI0"]
[Thu Jul 30 13:44:28.701832 2026] [security2:error] [pid 935860:tid 935999] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amubjIijB6THqIZZsUIGqQAAAI0"]
[Thu Jul 30 13:44:29.027279 2026] [security2:error] [pid 935860:tid 936063] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/Text/"] [unique_id "amubjIijB6THqIZZsUIGsAAAAM0"]
[Thu Jul 30 13:44:29.216525 2026] [security2:error] [pid 935860:tid 936074] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-content/uploads/"] [unique_id "amubjYijB6THqIZZsUIGtAAAANg"]
[Thu Jul 30 13:44:29.369026 2026] [security2:error] [pid 935860:tid 936102] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/index.php"] [unique_id "amubjYijB6THqIZZsUIGvwAAAPQ"]
[Thu Jul 30 13:44:29.369159 2026] [security2:error] [pid 935860:tid 936102] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/index.php"] [unique_id "amubjYijB6THqIZZsUIGvwAAAPQ"]
[Thu Jul 30 13:44:29.646675 2026] [security2:error] [pid 935860:tid 936031] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amubjYijB6THqIZZsUIGwAAAAK0"]
[Thu Jul 30 13:44:29.646782 2026] [security2:error] [pid 935860:tid 936031] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amubjYijB6THqIZZsUIGwAAAAK0"]
[Thu Jul 30 13:44:29.913675 2026] [security2:error] [pid 935860:tid 936095] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/177.php"] [unique_id "amubjYijB6THqIZZsUIGygAAAO0"]
[Thu Jul 30 13:44:29.913785 2026] [security2:error] [pid 935860:tid 936095] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/177.php"] [unique_id "amubjYijB6THqIZZsUIGygAAAO0"]
[Thu Jul 30 13:44:29.913784 2026] [security2:error] [pid 935860:tid 936116] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubjYijB6THqIZZsUIGvgAAAQI"]
[Thu Jul 30 13:44:30.182615 2026] [proxy:error] [pid 935860:tid 936087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:30.182697 2026] [proxy_http:error] [pid 935860:tid 936087] [client 172.202.44.182:49743] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:30.183295 2026] [security2:error] [pid 935860:tid 936107] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/199.php"] [unique_id "amubjoijB6THqIZZsUIG0wAAAPk"]
[Thu Jul 30 13:44:30.183378 2026] [security2:error] [pid 935860:tid 936107] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/199.php"] [unique_id "amubjoijB6THqIZZsUIG0wAAAPk"]
[Thu Jul 30 13:44:30.183748 2026] [proxy:error] [pid 935860:tid 936087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:30.183798 2026] [proxy_http:error] [pid 935860:tid 936087] [client 172.202.44.182:49743] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:30.266004 2026] [security2:error] [pid 935860:tid 936008] [client 45.76.147.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amubjoijB6THqIZZsUIG0QAAAJY"]
[Thu Jul 30 13:44:30.455285 2026] [security2:error] [pid 935860:tid 936051] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file52.php"] [unique_id "amubjoijB6THqIZZsUIG3gAAAME"]
[Thu Jul 30 13:44:30.455391 2026] [security2:error] [pid 935860:tid 936051] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file52.php"] [unique_id "amubjoijB6THqIZZsUIG3gAAAME"]
[Thu Jul 30 13:44:30.725003 2026] [security2:error] [pid 935860:tid 936042] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/geck.php"] [unique_id "amubjoijB6THqIZZsUIG8AAAALg"]
[Thu Jul 30 13:44:30.725099 2026] [security2:error] [pid 935860:tid 936042] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/geck.php"] [unique_id "amubjoijB6THqIZZsUIG8AAAALg"]
[Thu Jul 30 13:44:30.887577 2026] [security2:error] [pid 935860:tid 936094] [client 38.61.246.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amubjoijB6THqIZZsUIG8wAAAOw"]
[Thu Jul 30 13:44:31.011475 2026] [security2:error] [pid 935860:tid 936112] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/biufile.php"] [unique_id "amubj4ijB6THqIZZsUIG-gAAAP4"]
[Thu Jul 30 13:44:31.011596 2026] [security2:error] [pid 935860:tid 936112] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/biufile.php"] [unique_id "amubj4ijB6THqIZZsUIG-gAAAP4"]
[Thu Jul 30 13:44:31.286664 2026] [security2:error] [pid 935860:tid 936000] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dejavu.php"] [unique_id "amubj4ijB6THqIZZsUIHCwAAAI4"]
[Thu Jul 30 13:44:31.286743 2026] [security2:error] [pid 935860:tid 936000] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dejavu.php"] [unique_id "amubj4ijB6THqIZZsUIHCwAAAI4"]
[Thu Jul 30 13:44:31.560584 2026] [security2:error] [pid 935860:tid 936071] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/aaf.php"] [unique_id "amubj4ijB6THqIZZsUIHGQAAANU"]
[Thu Jul 30 13:44:31.560700 2026] [security2:error] [pid 935860:tid 936071] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/aaf.php"] [unique_id "amubj4ijB6THqIZZsUIHGQAAANU"]
[Thu Jul 30 13:44:31.827928 2026] [security2:error] [pid 935860:tid 936094] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ha.php"] [unique_id "amubj4ijB6THqIZZsUIHJQAAAOw"]
[Thu Jul 30 13:44:31.828056 2026] [security2:error] [pid 935860:tid 936094] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ha.php"] [unique_id "amubj4ijB6THqIZZsUIHJQAAAOw"]
[Thu Jul 30 13:44:32.107180 2026] [security2:error] [pid 935860:tid 936002] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/hur.php"] [unique_id "amubkIijB6THqIZZsUIHMQAAAJA"]
[Thu Jul 30 13:44:32.107304 2026] [security2:error] [pid 935860:tid 936002] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/hur.php"] [unique_id "amubkIijB6THqIZZsUIHMQAAAJA"]
[Thu Jul 30 13:44:32.381244 2026] [security2:error] [pid 935860:tid 936106] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/h02ugyh.php"] [unique_id "amubkIijB6THqIZZsUIHOQAAAPg"]
[Thu Jul 30 13:44:32.381333 2026] [security2:error] [pid 935860:tid 936106] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/h02ugyh.php"] [unique_id "amubkIijB6THqIZZsUIHOQAAAPg"]
[Thu Jul 30 13:44:32.662362 2026] [security2:error] [pid 935860:tid 936064] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/155.php"] [unique_id "amubkIijB6THqIZZsUIHPgAAAM4"]
[Thu Jul 30 13:44:32.662471 2026] [security2:error] [pid 935860:tid 936064] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/155.php"] [unique_id "amubkIijB6THqIZZsUIHPgAAAM4"]
[Thu Jul 30 13:44:32.687019 2026] [security2:error] [pid 935860:tid 935956] [remote 74.7.227.39:39102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amubkIijB6THqIZZsUIHPwAAzF4"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/post-carousel/admin/ElementAddons
[Thu Jul 30 13:44:32.718831 2026] [security2:error] [pid 935860:tid 936078] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubkIijB6THqIZZsUIHMgAA3Hk"]
[Thu Jul 30 13:44:32.981131 2026] [security2:error] [pid 935860:tid 936051] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ops.php"] [unique_id "amubkIijB6THqIZZsUIHRwAAAME"]
[Thu Jul 30 13:44:32.981230 2026] [security2:error] [pid 935860:tid 936051] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ops.php"] [unique_id "amubkIijB6THqIZZsUIHRwAAAME"]
[Thu Jul 30 13:44:33.262156 2026] [security2:error] [pid 935860:tid 936083] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ingfo.php"] [unique_id "amubkYijB6THqIZZsUIHUwAAAOE"]
[Thu Jul 30 13:44:33.262239 2026] [security2:error] [pid 935860:tid 936083] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ingfo.php"] [unique_id "amubkYijB6THqIZZsUIHUwAAAOE"]
[Thu Jul 30 13:44:33.379865 2026] [security2:error] [pid 935860:tid 936071] [client 103.242.199.184:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubkYijB6THqIZZsUIHVQAAANU"]
[Thu Jul 30 13:44:33.380026 2026] [security2:error] [pid 935860:tid 936071] [client 103.242.199.184:54728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubkYijB6THqIZZsUIHVQAAANU"]
[Thu Jul 30 13:44:33.498611 2026] [security2:error] [pid 935860:tid 936101] [client 74.7.175.188:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.fso.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amubkYijB6THqIZZsUIHWwAAAPM"]
[Thu Jul 30 13:44:33.500352 2026] [security2:error] [pid 935860:tid 936035] [client 74.7.175.188:33144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.fso.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amubkYijB6THqIZZsUIHWQAAsRE"]
[Thu Jul 30 13:44:33.531108 2026] [security2:error] [pid 935860:tid 936092] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/error_log.php"] [unique_id "amubkYijB6THqIZZsUIHXAAAAOo"]
[Thu Jul 30 13:44:33.531199 2026] [security2:error] [pid 935860:tid 936092] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/error_log.php"] [unique_id "amubkYijB6THqIZZsUIHXAAAAOo"]
[Thu Jul 30 13:44:33.821519 2026] [security2:error] [pid 935860:tid 936041] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/koala.php"] [unique_id "amubkYijB6THqIZZsUIHZQAAALc"]
[Thu Jul 30 13:44:33.821624 2026] [security2:error] [pid 935860:tid 936041] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/koala.php"] [unique_id "amubkYijB6THqIZZsUIHZQAAALc"]
[Thu Jul 30 13:44:33.985865 2026] [security2:error] [pid 935860:tid 936030] [client 172.237.109.114:45072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/.antproxy.php"] [unique_id "amubkYijB6THqIZZsUIHaQAAAKw"]
[Thu Jul 30 13:44:34.108014 2026] [security2:error] [pid 935860:tid 936069] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/mac.php"] [unique_id "amubkoijB6THqIZZsUIHcQAAANM"]
[Thu Jul 30 13:44:34.108110 2026] [security2:error] [pid 935860:tid 936069] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/mac.php"] [unique_id "amubkoijB6THqIZZsUIHcQAAANM"]
[Thu Jul 30 13:44:34.315232 2026] [autoindex:error] [pid 935860:tid 936040] [client 74.7.241.26:0] AH01276: Cannot serve directory /home1/fsonyxte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:44:34.376731 2026] [security2:error] [pid 935860:tid 936000] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wefile.php"] [unique_id "amubkoijB6THqIZZsUIHeAAAAI4"]
[Thu Jul 30 13:44:34.376840 2026] [security2:error] [pid 935860:tid 936000] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wefile.php"] [unique_id "amubkoijB6THqIZZsUIHeAAAAI4"]
[Thu Jul 30 13:44:34.621950 2026] [security2:error] [pid 935860:tid 936061] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubkoijB6THqIZZsUIHagAAyxM"]
[Thu Jul 30 13:44:34.705106 2026] [security2:error] [pid 935860:tid 936010] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/blocks/post-comments-form/"] [unique_id "amubkoijB6THqIZZsUIHgwAAAJg"]
[Thu Jul 30 13:44:34.823523 2026] [security2:error] [pid 935860:tid 936057] [client 74.7.241.157:39602] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.xxb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amubkYijB6THqIZZsUIHYQAAxyc"]
[Thu Jul 30 13:44:34.904598 2026] [security2:error] [pid 935860:tid 936063] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-admin/js/"] [unique_id "amubkoijB6THqIZZsUIHhwAAAM0"]
[Thu Jul 30 13:44:34.972612 2026] [security2:error] [pid 935860:tid 936022] [client 37.46.199.86:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.199.46.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amubkoijB6THqIZZsUIHiAAAAKQ"]
[Thu Jul 30 13:44:34.972714 2026] [security2:error] [pid 935860:tid 936022] [client 37.46.199.86:59318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amubkoijB6THqIZZsUIHiAAAAKQ"]
[Thu Jul 30 13:44:35.064039 2026] [security2:error] [pid 935860:tid 936059] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/makeasmtp.php"] [unique_id "amubk4ijB6THqIZZsUIHjQAAAMk"]
[Thu Jul 30 13:44:35.064138 2026] [security2:error] [pid 935860:tid 936059] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/makeasmtp.php"] [unique_id "amubk4ijB6THqIZZsUIHjQAAAMk"]
[Thu Jul 30 13:44:35.338280 2026] [security2:error] [pid 935860:tid 936079] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/2P.php"] [unique_id "amubk4ijB6THqIZZsUIHlAAAAN0"]
[Thu Jul 30 13:44:35.338386 2026] [security2:error] [pid 935860:tid 936079] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/2P.php"] [unique_id "amubk4ijB6THqIZZsUIHlAAAAN0"]
[Thu Jul 30 13:44:35.608626 2026] [security2:error] [pid 935860:tid 936056] [client 78.167.1.90:57199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubk4ijB6THqIZZsUIHnAAAAMY"]
[Thu Jul 30 13:44:35.608650 2026] [security2:error] [pid 935860:tid 936053] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/.well-known/about.php"] [unique_id "amubk4ijB6THqIZZsUIHnQAAAMM"]
[Thu Jul 30 13:44:35.608746 2026] [security2:error] [pid 935860:tid 936053] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/.well-known/about.php"] [unique_id "amubk4ijB6THqIZZsUIHnQAAAMM"]
[Thu Jul 30 13:44:35.608841 2026] [security2:error] [pid 935860:tid 936056] [client 78.167.1.90:57199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubk4ijB6THqIZZsUIHnAAAAMY"]
[Thu Jul 30 13:44:35.886747 2026] [security2:error] [pid 935860:tid 936047] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-includes/ID3/about.php"] [unique_id "amubk4ijB6THqIZZsUIHogAAAL0"]
[Thu Jul 30 13:44:35.886845 2026] [security2:error] [pid 935860:tid 936047] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-includes/ID3/about.php"] [unique_id "amubk4ijB6THqIZZsUIHogAAAL0"]
[Thu Jul 30 13:44:36.163857 2026] [security2:error] [pid 935860:tid 936078] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/system_log.php"] [unique_id "amublIijB6THqIZZsUIHrgAAANw"]
[Thu Jul 30 13:44:36.163964 2026] [security2:error] [pid 935860:tid 936078] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/system_log.php"] [unique_id "amublIijB6THqIZZsUIHrgAAANw"]
[Thu Jul 30 13:44:36.470441 2026] [security2:error] [pid 935860:tid 936057] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/"] [unique_id "amublIijB6THqIZZsUIHsgAAAMc"]
[Thu Jul 30 13:44:36.596863 2026] [security2:error] [pid 935860:tid 936066] [client 127.0.0.1:51414] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amublIijB6THqIZZsUIHtgAAANA"]
[Thu Jul 30 13:44:36.596872 2026] [security2:error] [pid 935860:tid 936052] [client 127.0.0.1:51408] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wyt.gpl.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amublIijB6THqIZZsUIHtQAAAMI"]
[Thu Jul 30 13:44:36.597066 2026] [security2:error] [pid 935860:tid 936010] [client 74.7.230.29:56376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wyt.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amublIijB6THqIZZsUIHtAAAmE0"]
[Thu Jul 30 13:44:36.646060 2026] [security2:error] [pid 935860:tid 936102] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/modern/"] [unique_id "amublIijB6THqIZZsUIHuAAAAPQ"]
[Thu Jul 30 13:44:36.793335 2026] [security2:error] [pid 935860:tid 936099] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/crgio.php"] [unique_id "amublIijB6THqIZZsUIH1gAAAPE"]
[Thu Jul 30 13:44:36.793425 2026] [security2:error] [pid 935860:tid 936099] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/crgio.php"] [unique_id "amublIijB6THqIZZsUIH1gAAAPE"]
[Thu Jul 30 13:44:37.066675 2026] [security2:error] [pid 935860:tid 936088] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/pucci.php"] [unique_id "amublYijB6THqIZZsUIH3QAAAOY"]
[Thu Jul 30 13:44:37.066774 2026] [security2:error] [pid 935860:tid 936088] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/pucci.php"] [unique_id "amublYijB6THqIZZsUIH3QAAAOY"]
[Thu Jul 30 13:44:37.372461 2026] [security2:error] [pid 935860:tid 936050] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/blocks/details/"] [unique_id "amublYijB6THqIZZsUIH7AAAAMA"]
[Thu Jul 30 13:44:37.547429 2026] [security2:error] [pid 935860:tid 936102] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/blocks/audio/"] [unique_id "amublYijB6THqIZZsUIH8QAAAPQ"]
[Thu Jul 30 13:44:37.584636 2026] [core:notice] [pid 935860:tid 936010] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:37.686122 2026] [security2:error] [pid 935860:tid 936068] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-temp.php"] [unique_id "amublYijB6THqIZZsUIH_AAAANI"]
[Thu Jul 30 13:44:37.686206 2026] [security2:error] [pid 935860:tid 936068] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-temp.php"] [unique_id "amublYijB6THqIZZsUIH_AAAANI"]
[Thu Jul 30 13:44:37.723937 2026] [core:notice] [pid 935860:tid 936113] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:37.863598 2026] [core:notice] [pid 935860:tid 936104] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:37.909689 2026] [proxy:error] [pid 935860:tid 936018] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:37.909749 2026] [proxy_http:error] [pid 935860:tid 936018] [client 172.202.44.182:49760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:37.910310 2026] [proxy:error] [pid 935860:tid 936018] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:37.910356 2026] [proxy_http:error] [pid 935860:tid 936018] [client 172.202.44.182:49760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:37.957149 2026] [security2:error] [pid 935860:tid 936085] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-admin/js/index.php"] [unique_id "amublYijB6THqIZZsUIIFgAAAOM"]
[Thu Jul 30 13:44:37.957245 2026] [security2:error] [pid 935860:tid 936085] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-admin/js/index.php"] [unique_id "amublYijB6THqIZZsUIIFgAAAOM"]
[Thu Jul 30 13:44:38.246550 2026] [security2:error] [pid 935860:tid 936091] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/puc.php"] [unique_id "amubloijB6THqIZZsUIIIQAAAOk"]
[Thu Jul 30 13:44:38.246661 2026] [security2:error] [pid 935860:tid 936091] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/puc.php"] [unique_id "amubloijB6THqIZZsUIIIQAAAOk"]
[Thu Jul 30 13:44:38.524841 2026] [security2:error] [pid 935860:tid 936025] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dx.php"] [unique_id "amubloijB6THqIZZsUIIJQAAAKc"]
[Thu Jul 30 13:44:38.524955 2026] [security2:error] [pid 935860:tid 936025] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dx.php"] [unique_id "amubloijB6THqIZZsUIIJQAAAKc"]
[Thu Jul 30 13:44:38.828074 2026] [security2:error] [pid 935860:tid 935992] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/Requests/"] [unique_id "amubloijB6THqIZZsUIIMgAAAIY"]
[Thu Jul 30 13:44:38.968704 2026] [security2:error] [pid 935860:tid 936010] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/7.php"] [unique_id "amubloijB6THqIZZsUIIOAAAAJg"]
[Thu Jul 30 13:44:38.968801 2026] [security2:error] [pid 935860:tid 936010] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/7.php"] [unique_id "amubloijB6THqIZZsUIIOAAAAJg"]
[Thu Jul 30 13:44:39.253034 2026] [security2:error] [pid 935860:tid 936097] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/8.php"] [unique_id "amubl4ijB6THqIZZsUIIRAAAAO8"]
[Thu Jul 30 13:44:39.253159 2026] [security2:error] [pid 935860:tid 936097] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/8.php"] [unique_id "amubl4ijB6THqIZZsUIIRAAAAO8"]
[Thu Jul 30 13:44:39.549502 2026] [security2:error] [pid 935860:tid 936096] [client 20.215.216.94:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amubl4ijB6THqIZZsUIISgAAAO4"]
[Thu Jul 30 13:44:39.549617 2026] [security2:error] [pid 935860:tid 936096] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amubl4ijB6THqIZZsUIISgAAAO4"]
[Thu Jul 30 13:44:39.549736 2026] [security2:error] [pid 935860:tid 936096] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amubl4ijB6THqIZZsUIISgAAAO4"]
[Thu Jul 30 13:44:39.869131 2026] [security2:error] [pid 935860:tid 935993] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/about.php"] [unique_id "amubl4ijB6THqIZZsUIIXAAAAIc"]
[Thu Jul 30 13:44:39.869229 2026] [security2:error] [pid 935860:tid 935993] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/about.php"] [unique_id "amubl4ijB6THqIZZsUIIXAAAAIc"]
[Thu Jul 30 13:44:39.993282 2026] [core:notice] [pid 935860:tid 935949] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:40.158386 2026] [security2:error] [pid 935860:tid 936058] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amubmIijB6THqIZZsUIIYgAAAMg"]
[Thu Jul 30 13:44:40.158491 2026] [security2:error] [pid 935860:tid 936058] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amubmIijB6THqIZZsUIIYgAAAMg"]
[Thu Jul 30 13:44:40.252834 2026] [security2:error] [pid 935860:tid 936040] [client 172.202.44.182:49746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/inputs.php"] [unique_id "amubmIijB6THqIZZsUIIZgAAALY"]
[Thu Jul 30 13:44:40.440079 2026] [security2:error] [pid 935860:tid 936010] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/edit.php"] [unique_id "amubmIijB6THqIZZsUIIbgAAAJg"]
[Thu Jul 30 13:44:40.440174 2026] [security2:error] [pid 935860:tid 936010] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/edit.php"] [unique_id "amubmIijB6THqIZZsUIIbgAAAJg"]
[Thu Jul 30 13:44:40.546923 2026] [core:notice] [pid 935860:tid 935931] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:40.711129 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/admin.php"] [unique_id "amubmIijB6THqIZZsUIIegAAAKg"]
[Thu Jul 30 13:44:40.711240 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/admin.php"] [unique_id "amubmIijB6THqIZZsUIIegAAAKg"]
[Thu Jul 30 13:44:40.986025 2026] [security2:error] [pid 935860:tid 936110] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/inputs.php"] [unique_id "amubmIijB6THqIZZsUIIgQAAAPw"]
[Thu Jul 30 13:44:40.986126 2026] [security2:error] [pid 935860:tid 936110] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/inputs.php"] [unique_id "amubmIijB6THqIZZsUIIgQAAAPw"]
[Thu Jul 30 13:44:41.257619 2026] [security2:error] [pid 935860:tid 936086] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/av.php"] [unique_id "amubmYijB6THqIZZsUIIjAAAAOQ"]
[Thu Jul 30 13:44:41.257697 2026] [security2:error] [pid 935860:tid 936086] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/av.php"] [unique_id "amubmYijB6THqIZZsUIIjAAAAOQ"]
[Thu Jul 30 13:44:41.375052 2026] [core:notice] [pid 935860:tid 935918] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:41.532516 2026] [security2:error] [pid 935860:tid 936013] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/classwithtostring.php"] [unique_id "amubmYijB6THqIZZsUIIlQAAAJs"]
[Thu Jul 30 13:44:41.532626 2026] [security2:error] [pid 935860:tid 936013] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/classwithtostring.php"] [unique_id "amubmYijB6THqIZZsUIIlQAAAJs"]
[Thu Jul 30 13:44:41.804919 2026] [core:notice] [pid 935860:tid 935979] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:41.805953 2026] [security2:error] [pid 935860:tid 936061] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/themes/index.php"] [unique_id "amubmYijB6THqIZZsUIIoAAAAMs"]
[Thu Jul 30 13:44:41.806084 2026] [security2:error] [pid 935860:tid 936061] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/themes/index.php"] [unique_id "amubmYijB6THqIZZsUIIoAAAAMs"]
[Thu Jul 30 13:44:41.890605 2026] [proxy:error] [pid 935860:tid 935981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:41.890659 2026] [proxy_http:error] [pid 935860:tid 935981] [remote 74.7.241.155:49224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:41.891246 2026] [proxy:error] [pid 935860:tid 935981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:41.891294 2026] [proxy_http:error] [pid 935860:tid 935981] [remote 74.7.241.155:49224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:42.093372 2026] [security2:error] [pid 935860:tid 936113] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-blog.php"] [unique_id "amubmoijB6THqIZZsUIIswAAAP8"]
[Thu Jul 30 13:44:42.093489 2026] [security2:error] [pid 935860:tid 936113] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-blog.php"] [unique_id "amubmoijB6THqIZZsUIIswAAAP8"]
[Thu Jul 30 13:44:42.405219 2026] [security2:error] [pid 935860:tid 935994] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/js/jquery/"] [unique_id "amubmoijB6THqIZZsUIIuQAAAIg"]
[Thu Jul 30 13:44:42.484121 2026] [core:notice] [pid 935860:tid 935950] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:42.547685 2026] [security2:error] [pid 935860:tid 936011] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/admin.php"] [unique_id "amubmoijB6THqIZZsUIIwwAAAJk"]
[Thu Jul 30 13:44:42.547785 2026] [security2:error] [pid 935860:tid 936011] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-content/admin.php"] [unique_id "amubmoijB6THqIZZsUIIwwAAAJk"]
[Thu Jul 30 13:44:42.734300 2026] [core:notice] [pid 935860:tid 935960] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:42.819103 2026] [security2:error] [pid 935860:tid 936034] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/adminfuns.php"] [unique_id "amubmoijB6THqIZZsUIIywAAALA"]
[Thu Jul 30 13:44:42.819271 2026] [security2:error] [pid 935860:tid 936034] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/adminfuns.php"] [unique_id "amubmoijB6THqIZZsUIIywAAALA"]
[Thu Jul 30 13:44:42.954916 2026] [core:notice] [pid 935860:tid 935975] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:43.108924 2026] [security2:error] [pid 935860:tid 936028] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/goods.php"] [unique_id "amubm4ijB6THqIZZsUII1wAAAKo"]
[Thu Jul 30 13:44:43.109056 2026] [security2:error] [pid 935860:tid 936028] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/goods.php"] [unique_id "amubm4ijB6THqIZZsUII1wAAAKo"]
[Thu Jul 30 13:44:43.376704 2026] [security2:error] [pid 935860:tid 936055] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ms-edit.php"] [unique_id "amubm4ijB6THqIZZsUII3gAAAMU"]
[Thu Jul 30 13:44:43.376850 2026] [security2:error] [pid 935860:tid 936055] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ms-edit.php"] [unique_id "amubm4ijB6THqIZZsUII3gAAAMU"]
[Thu Jul 30 13:44:43.377509 2026] [core:notice] [pid 935860:tid 935984] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:43.684476 2026] [security2:error] [pid 935860:tid 936014] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/222.php"] [unique_id "amubm4ijB6THqIZZsUII8gAAAJw"]
[Thu Jul 30 13:44:43.684593 2026] [security2:error] [pid 935860:tid 936014] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/222.php"] [unique_id "amubm4ijB6THqIZZsUII8gAAAJw"]
[Thu Jul 30 13:44:43.852587 2026] [security2:error] [pid 935860:tid 936059] [client 84.17.60.251:58982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nfi.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amubm4ijB6THqIZZsUII9gAAAMk"]
[Thu Jul 30 13:44:43.962415 2026] [security2:error] [pid 935860:tid 936095] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/cgi-bin/index.php"] [unique_id "amubm4ijB6THqIZZsUII-gAAAO0"]
[Thu Jul 30 13:44:43.962524 2026] [security2:error] [pid 935860:tid 936095] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/cgi-bin/index.php"] [unique_id "amubm4ijB6THqIZZsUII-gAAAO0"]
[Thu Jul 30 13:44:44.094125 2026] [security2:error] [pid 935860:tid 936026] [client 103.242.199.184:55273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubnIijB6THqIZZsUIJBgAAAKg"]
[Thu Jul 30 13:44:44.094223 2026] [security2:error] [pid 935860:tid 936026] [client 103.242.199.184:55273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubnIijB6THqIZZsUIJBgAAAKg"]
[Thu Jul 30 13:44:44.140734 2026] [security2:error] [pid 935860:tid 936030] [client 84.17.60.251:58998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.60.17.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nfi.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amubnIijB6THqIZZsUIJBwAAAKw"]
[Thu Jul 30 13:44:44.267035 2026] [security2:error] [pid 935860:tid 936043] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/css/dist/"] [unique_id "amubnIijB6THqIZZsUIJCAAAALk"]
[Thu Jul 30 13:44:44.406193 2026] [security2:error] [pid 935860:tid 936087] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/BDKR28WP.php"] [unique_id "amubnIijB6THqIZZsUIJCQAAAOU"]
[Thu Jul 30 13:44:44.406301 2026] [security2:error] [pid 935860:tid 936087] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/BDKR28WP.php"] [unique_id "amubnIijB6THqIZZsUIJCQAAAOU"]
[Thu Jul 30 13:44:44.586772 2026] [security2:error] [pid 935860:tid 936098] [client 172.202.44.182:49782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/index.php"] [unique_id "amubnIijB6THqIZZsUIJGwAAAPA"]
[Thu Jul 30 13:44:44.719078 2026] [security2:error] [pid 935860:tid 936077] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/l10n/"] [unique_id "amubnIijB6THqIZZsUIJHQAAANs"]
[Thu Jul 30 13:44:44.900537 2026] [security2:error] [pid 935860:tid 936014] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-content/uploads/"] [unique_id "amubnIijB6THqIZZsUIJIQAAAJw"]
[Thu Jul 30 13:44:45.045048 2026] [security2:error] [pid 935860:tid 936022] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp.php"] [unique_id "amubnYijB6THqIZZsUIJKAAAAKQ"]
[Thu Jul 30 13:44:45.045159 2026] [security2:error] [pid 935860:tid 936022] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp.php"] [unique_id "amubnYijB6THqIZZsUIJKAAAAKQ"]
[Thu Jul 30 13:44:45.321356 2026] [security2:error] [pid 935860:tid 936030] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/abcd.php"] [unique_id "amubnYijB6THqIZZsUIJMgAAAKw"]
[Thu Jul 30 13:44:45.321470 2026] [security2:error] [pid 935860:tid 936030] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/abcd.php"] [unique_id "amubnYijB6THqIZZsUIJMgAAAKw"]
[Thu Jul 30 13:44:45.590386 2026] [security2:error] [pid 935860:tid 935991] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/a1.php"] [unique_id "amubnYijB6THqIZZsUIJOgAAAIU"]
[Thu Jul 30 13:44:45.590510 2026] [security2:error] [pid 935860:tid 935991] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/a1.php"] [unique_id "amubnYijB6THqIZZsUIJOgAAAIU"]
[Thu Jul 30 13:44:45.865670 2026] [security2:error] [pid 935860:tid 936107] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amubnYijB6THqIZZsUIJQAAAAPk"]
[Thu Jul 30 13:44:45.865790 2026] [security2:error] [pid 935860:tid 936107] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amubnYijB6THqIZZsUIJQAAAAPk"]
[Thu Jul 30 13:44:45.885041 2026] [security2:error] [pid 935860:tid 936048] [client 84.17.60.251:59014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nfi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amubnYijB6THqIZZsUIJPgAAAL4"]
[Thu Jul 30 13:44:45.977634 2026] [security2:error] [pid 935860:tid 936111] [client 104.254.90.251:35432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.90.254.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amubnYijB6THqIZZsUIJRAAAAP0"]
[Thu Jul 30 13:44:45.977766 2026] [security2:error] [pid 935860:tid 936111] [client 104.254.90.251:35432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amubnYijB6THqIZZsUIJRAAAAP0"]
[Thu Jul 30 13:44:46.023092 2026] [security2:error] [pid 935860:tid 936028] [client 84.17.60.251:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.60.17.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nfi.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amubnoijB6THqIZZsUIJSQAAAKo"]
[Thu Jul 30 13:44:46.023193 2026] [security2:error] [pid 935860:tid 936028] [client 84.17.60.251:59014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nfi.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amubnoijB6THqIZZsUIJSQAAAKo"]
[Thu Jul 30 13:44:46.153970 2026] [security2:error] [pid 935860:tid 936080] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/cgi-bin/admin.php"] [unique_id "amubnoijB6THqIZZsUIJUwAAAN4"]
[Thu Jul 30 13:44:46.154125 2026] [security2:error] [pid 935860:tid 936080] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/cgi-bin/admin.php"] [unique_id "amubnoijB6THqIZZsUIJUwAAAN4"]
[Thu Jul 30 13:44:46.178534 2026] [security2:error] [pid 935860:tid 936013] [client 78.167.1.90:54555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubnoijB6THqIZZsUIJVAAAAJs"]
[Thu Jul 30 13:44:46.179068 2026] [security2:error] [pid 935860:tid 936013] [client 78.167.1.90:54555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubnoijB6THqIZZsUIJVAAAAJs"]
[Thu Jul 30 13:44:46.468209 2026] [security2:error] [pid 935860:tid 936057] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-content/"] [unique_id "amubnoijB6THqIZZsUIJWwAAAMc"]
[Thu Jul 30 13:44:46.533816 2026] [security2:error] [pid 935860:tid 936090] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubnYijB6THqIZZsUIJPwAA6Aw"]
[Thu Jul 30 13:44:46.607324 2026] [security2:error] [pid 935860:tid 936077] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/simple.php"] [unique_id "amubnoijB6THqIZZsUIJYwAAANs"]
[Thu Jul 30 13:44:46.607432 2026] [security2:error] [pid 935860:tid 936077] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/simple.php"] [unique_id "amubnoijB6THqIZZsUIJYwAAANs"]
[Thu Jul 30 13:44:46.678273 2026] [security2:error] [pid 935860:tid 935886] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.blsspainvisacenterpakistan.site"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amubnoijB6THqIZZsUIJZgAA7xg"]
[Thu Jul 30 13:44:46.800165 2026] [core:notice] [pid 935860:tid 935881] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:46.881232 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xxx.php"] [unique_id "amubnoijB6THqIZZsUIJcAAAAKg"]
[Thu Jul 30 13:44:46.881374 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xxx.php"] [unique_id "amubnoijB6THqIZZsUIJcAAAAKg"]
[Thu Jul 30 13:44:46.943967 2026] [core:notice] [pid 935860:tid 935901] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:47.174715 2026] [security2:error] [pid 935860:tid 936065] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/hypo.php"] [unique_id "amubn4ijB6THqIZZsUIJegAAAM8"]
[Thu Jul 30 13:44:47.174832 2026] [security2:error] [pid 935860:tid 936065] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/hypo.php"] [unique_id "amubn4ijB6THqIZZsUIJegAAAM8"]
[Thu Jul 30 13:44:47.485826 2026] [security2:error] [pid 935860:tid 936114] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/blue/"] [unique_id "amubn4ijB6THqIZZsUIJkAAAAQA"]
[Thu Jul 30 13:44:47.573111 2026] [security2:error] [pid 935860:tid 936079] [client 172.202.44.182:49772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/network/index.php"] [unique_id "amubn4ijB6THqIZZsUIJoAAAAN0"]
[Thu Jul 30 13:44:47.626260 2026] [security2:error] [pid 935860:tid 936118] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/chosen.php"] [unique_id "amubn4ijB6THqIZZsUIJpAAAAQQ"]
[Thu Jul 30 13:44:47.626386 2026] [security2:error] [pid 935860:tid 936118] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/chosen.php"] [unique_id "amubn4ijB6THqIZZsUIJpAAAAQQ"]
[Thu Jul 30 13:44:47.936925 2026] [security2:error] [pid 935860:tid 936052] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/block-bindings/"] [unique_id "amubn4ijB6THqIZZsUIJwAAAAMI"]
[Thu Jul 30 13:44:48.078038 2026] [security2:error] [pid 935860:tid 936019] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/als.php"] [unique_id "amuboIijB6THqIZZsUIJxgAAAKE"]
[Thu Jul 30 13:44:48.078147 2026] [security2:error] [pid 935860:tid 936019] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/als.php"] [unique_id "amuboIijB6THqIZZsUIJxgAAAKE"]
[Thu Jul 30 13:44:48.354718 2026] [security2:error] [pid 935860:tid 936001] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/pol.php"] [unique_id "amuboIijB6THqIZZsUIJ2gAAAI8"]
[Thu Jul 30 13:44:48.354845 2026] [security2:error] [pid 935860:tid 936001] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/pol.php"] [unique_id "amuboIijB6THqIZZsUIJ2gAAAI8"]
[Thu Jul 30 13:44:48.393957 2026] [security2:error] [pid 935860:tid 935997] [client 119.73.97.132:31204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/wp-admin/post.php"] [unique_id "amubn4ijB6THqIZZsUIJvwAAi1k"], referer: https://www.urwru.club/wp-admin/edit.php?post_type=page
[Thu Jul 30 13:44:48.582328 2026] [security2:error] [pid 935860:tid 936082] [client 172.202.44.182:49769] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/1.php"] [unique_id "amuboIijB6THqIZZsUIJ4QAAAOA"]
[Thu Jul 30 13:44:48.582425 2026] [security2:error] [pid 935860:tid 936082] [client 172.202.44.182:49769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/1.php"] [unique_id "amuboIijB6THqIZZsUIJ4QAAAOA"]
[Thu Jul 30 13:44:48.638549 2026] [security2:error] [pid 935860:tid 936042] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file5.php"] [unique_id "amuboIijB6THqIZZsUIJ5AAAALg"]
[Thu Jul 30 13:44:48.638658 2026] [security2:error] [pid 935860:tid 936042] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file5.php"] [unique_id "amuboIijB6THqIZZsUIJ5AAAALg"]
[Thu Jul 30 13:44:48.932995 2026] [security2:error] [pid 935860:tid 936037] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file.php"] [unique_id "amuboIijB6THqIZZsUIJ7wAAALM"]
[Thu Jul 30 13:44:48.933100 2026] [security2:error] [pid 935860:tid 936037] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file.php"] [unique_id "amuboIijB6THqIZZsUIJ7wAAALM"]
[Thu Jul 30 13:44:49.213438 2026] [security2:error] [pid 935860:tid 936049] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.blsspainvisacenterpakistan.site"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuboYijB6THqIZZsUIJ_QAAAL8"]
[Thu Jul 30 13:44:49.226463 2026] [security2:error] [pid 935860:tid 936017] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amuboYijB6THqIZZsUIKAAAAAJ8"]
[Thu Jul 30 13:44:49.226591 2026] [security2:error] [pid 935860:tid 936017] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/admin.php"] [unique_id "amuboYijB6THqIZZsUIKAAAAAJ8"]
[Thu Jul 30 13:44:49.419437 2026] [security2:error] [pid 935860:tid 936063] [client 51.75.23.111:48314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.23.75.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/modules/gsnippetsreviews/ws-gsnippetsreviews.php"] [unique_id "amuboYijB6THqIZZsUIKBwAAAM0"]
[Thu Jul 30 13:44:49.497713 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/aa2.php"] [unique_id "amuboYijB6THqIZZsUIKCAAAAKg"]
[Thu Jul 30 13:44:49.497825 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/aa2.php"] [unique_id "amuboYijB6THqIZZsUIKCAAAAKg"]
[Thu Jul 30 13:44:49.596377 2026] [security2:error] [pid 935860:tid 936087] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuboIijB6THqIZZsUIJ8AAA5Qg"]
[Thu Jul 30 13:44:49.777815 2026] [security2:error] [pid 935860:tid 936089] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ccou.php"] [unique_id "amuboYijB6THqIZZsUIKDwAAAOc"]
[Thu Jul 30 13:44:49.777918 2026] [security2:error] [pid 935860:tid 936089] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ccou.php"] [unique_id "amuboYijB6THqIZZsUIKDwAAAOc"]
[Thu Jul 30 13:44:50.044745 2026] [security2:error] [pid 935860:tid 936047] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dr.php"] [unique_id "amubooijB6THqIZZsUIKFQAAAL0"]
[Thu Jul 30 13:44:50.044891 2026] [security2:error] [pid 935860:tid 936047] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dr.php"] [unique_id "amubooijB6THqIZZsUIKFQAAAL0"]
[Thu Jul 30 13:44:50.313132 2026] [security2:error] [pid 935860:tid 936111] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xamp.php"] [unique_id "amubooijB6THqIZZsUIKHQAAAP0"]
[Thu Jul 30 13:44:50.313248 2026] [security2:error] [pid 935860:tid 936111] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xamp.php"] [unique_id "amubooijB6THqIZZsUIKHQAAAP0"]
[Thu Jul 30 13:44:50.581721 2026] [security2:error] [pid 935860:tid 936118] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/bless.php"] [unique_id "amubooijB6THqIZZsUIKIwAAAQQ"]
[Thu Jul 30 13:44:50.581825 2026] [security2:error] [pid 935860:tid 936118] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/bless.php"] [unique_id "amubooijB6THqIZZsUIKIwAAAQQ"]
[Thu Jul 30 13:44:50.852889 2026] [security2:error] [pid 935860:tid 936106] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file25.php"] [unique_id "amubooijB6THqIZZsUIKKwAAAPg"]
[Thu Jul 30 13:44:50.853012 2026] [security2:error] [pid 935860:tid 936106] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file25.php"] [unique_id "amubooijB6THqIZZsUIKKwAAAPg"]
[Thu Jul 30 13:44:51.140847 2026] [security2:error] [pid 935860:tid 936052] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file6.php"] [unique_id "amubo4ijB6THqIZZsUIKMQAAAMI"]
[Thu Jul 30 13:44:51.141006 2026] [security2:error] [pid 935860:tid 936052] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file6.php"] [unique_id "amubo4ijB6THqIZZsUIKMQAAAMI"]
[Thu Jul 30 13:44:51.415549 2026] [security2:error] [pid 935860:tid 936022] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/a2.php"] [unique_id "amubo4ijB6THqIZZsUIKQgAAAKQ"]
[Thu Jul 30 13:44:51.415640 2026] [security2:error] [pid 935860:tid 936022] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/a2.php"] [unique_id "amubo4ijB6THqIZZsUIKQgAAAKQ"]
[Thu Jul 30 13:44:51.685220 2026] [security2:error] [pid 935860:tid 936084] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file15.php"] [unique_id "amubo4ijB6THqIZZsUIKRwAAAOI"]
[Thu Jul 30 13:44:51.685332 2026] [security2:error] [pid 935860:tid 936084] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file15.php"] [unique_id "amubo4ijB6THqIZZsUIKRwAAAOI"]
[Thu Jul 30 13:44:51.969201 2026] [security2:error] [pid 935860:tid 936018] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/f35.php"] [unique_id "amubo4ijB6THqIZZsUIKUwAAAKA"]
[Thu Jul 30 13:44:51.969316 2026] [security2:error] [pid 935860:tid 936018] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/f35.php"] [unique_id "amubo4ijB6THqIZZsUIKUwAAAKA"]
[Thu Jul 30 13:44:52.022044 2026] [security2:error] [pid 935860:tid 936066] [client 31.218.149.175:55332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubo4ijB6THqIZZsUIKPgAA0AE"]
[Thu Jul 30 13:44:52.253764 2026] [security2:error] [pid 935860:tid 936039] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-load.php"] [unique_id "amubpIijB6THqIZZsUIKXgAAALU"]
[Thu Jul 30 13:44:52.253847 2026] [security2:error] [pid 935860:tid 936039] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-load.php"] [unique_id "amubpIijB6THqIZZsUIKXgAAALU"]
[Thu Jul 30 13:44:52.256618 2026] [autoindex:error] [pid 935860:tid 936023] [client 52.202.41.153:15300] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:44:52.260240 2026] [autoindex:error] [pid 935860:tid 936015] [client 52.202.41.153:19776] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:44:52.525063 2026] [security2:error] [pid 935860:tid 936005] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xwpg.php"] [unique_id "amubpIijB6THqIZZsUIKbgAAAJM"]
[Thu Jul 30 13:44:52.525212 2026] [security2:error] [pid 935860:tid 936005] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xwpg.php"] [unique_id "amubpIijB6THqIZZsUIKbgAAAJM"]
[Thu Jul 30 13:44:52.537779 2026] [security2:error] [pid 935860:tid 936051] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubo4ijB6THqIZZsUIKSQAAwS0"]
[Thu Jul 30 13:44:52.835874 2026] [security2:error] [pid 935860:tid 935999] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-includes/assets/"] [unique_id "amubpIijB6THqIZZsUIKcgAAAI0"]
[Thu Jul 30 13:44:52.928888 2026] [security2:error] [pid 935860:tid 936108] [client 172.202.44.182:49778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/plugin.php"] [unique_id "amubpIijB6THqIZZsUIKeQAAAPo"]
[Thu Jul 30 13:44:53.018871 2026] [security2:error] [pid 935860:tid 936049] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/sunrise/"] [unique_id "amubpIijB6THqIZZsUIKegAAAL8"]
[Thu Jul 30 13:44:53.157255 2026] [security2:error] [pid 935860:tid 936040] [client 57.141.0.39:52904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amubpIijB6THqIZZsUIKcwAAthE"], referer: https://igetvape-australia.com/product-tag/iget-bar-pro-raspberry-grape/
[Thu Jul 30 13:44:53.164883 2026] [security2:error] [pid 935860:tid 936084] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xstelth.php"] [unique_id "amubpYijB6THqIZZsUIKgAAAAOI"]
[Thu Jul 30 13:44:53.164967 2026] [security2:error] [pid 935860:tid 936084] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xstelth.php"] [unique_id "amubpYijB6THqIZZsUIKgAAAAOI"]
[Thu Jul 30 13:44:53.379633 2026] [security2:error] [pid 935860:tid 935904] [remote 216.73.217.142:11637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amubpYijB6THqIZZsUIKhAAAmSo"]
[Thu Jul 30 13:44:53.452508 2026] [security2:error] [pid 935860:tid 936092] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-admin/network/plugins.php"] [unique_id "amubpYijB6THqIZZsUIKhwAAAOo"]
[Thu Jul 30 13:44:53.452607 2026] [security2:error] [pid 935860:tid 936092] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/wp-admin/network/plugins.php"] [unique_id "amubpYijB6THqIZZsUIKhwAAAOo"]
[Thu Jul 30 13:44:53.719556 2026] [security2:error] [pid 935860:tid 936007] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/aaa.php"] [unique_id "amubpYijB6THqIZZsUIKjAAAAJU"]
[Thu Jul 30 13:44:53.719704 2026] [security2:error] [pid 935860:tid 936007] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/aaa.php"] [unique_id "amubpYijB6THqIZZsUIKjAAAAJU"]
[Thu Jul 30 13:44:53.987105 2026] [security2:error] [pid 935860:tid 936083] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/gecko.php"] [unique_id "amubpYijB6THqIZZsUIKlAAAAOE"]
[Thu Jul 30 13:44:53.987203 2026] [security2:error] [pid 935860:tid 936083] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/gecko.php"] [unique_id "amubpYijB6THqIZZsUIKlAAAAOE"]
[Thu Jul 30 13:44:54.263435 2026] [security2:error] [pid 935860:tid 936055] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/pbck.php"] [unique_id "amubpoijB6THqIZZsUIKmQAAAMU"]
[Thu Jul 30 13:44:54.263607 2026] [security2:error] [pid 935860:tid 936055] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/pbck.php"] [unique_id "amubpoijB6THqIZZsUIKmQAAAMU"]
[Thu Jul 30 13:44:54.483886 2026] [security2:error] [pid 935860:tid 936015] [client 172.237.109.114:59484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubpoijB6THqIZZsUIKlQAAAJ0"]
[Thu Jul 30 13:44:54.542587 2026] [security2:error] [pid 935860:tid 936068] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xiugai.php"] [unique_id "amubpoijB6THqIZZsUIKowAAANI"]
[Thu Jul 30 13:44:54.542698 2026] [security2:error] [pid 935860:tid 936068] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xiugai.php"] [unique_id "amubpoijB6THqIZZsUIKowAAANI"]
[Thu Jul 30 13:44:54.629365 2026] [security2:error] [pid 935860:tid 935992] [client 103.242.199.184:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubpoijB6THqIZZsUIKpwAAAIY"]
[Thu Jul 30 13:44:54.629479 2026] [security2:error] [pid 935860:tid 935992] [client 103.242.199.184:55816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubpoijB6THqIZZsUIKpwAAAIY"]
[Thu Jul 30 13:44:54.832217 2026] [security2:error] [pid 935860:tid 935999] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/e.php"] [unique_id "amubpoijB6THqIZZsUIKqQAAAI0"]
[Thu Jul 30 13:44:54.832370 2026] [security2:error] [pid 935860:tid 935999] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/e.php"] [unique_id "amubpoijB6THqIZZsUIKqQAAAI0"]
[Thu Jul 30 13:44:55.101795 2026] [security2:error] [pid 935860:tid 936033] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/adminner.php"] [unique_id "amubp4ijB6THqIZZsUIKtAAAAK8"]
[Thu Jul 30 13:44:55.101911 2026] [security2:error] [pid 935860:tid 936033] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/adminner.php"] [unique_id "amubp4ijB6THqIZZsUIKtAAAAK8"]
[Thu Jul 30 13:44:55.138403 2026] [security2:error] [pid 935860:tid 936078] [client 66.249.73.96:35636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubpoijB6THqIZZsUIKqAAAANw"]
[Thu Jul 30 13:44:55.397311 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file1221.php"] [unique_id "amubp4ijB6THqIZZsUIKugAAAKg"]
[Thu Jul 30 13:44:55.397419 2026] [security2:error] [pid 935860:tid 936026] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/file1221.php"] [unique_id "amubp4ijB6THqIZZsUIKugAAAKg"]
[Thu Jul 30 13:44:55.671232 2026] [security2:error] [pid 935860:tid 936030] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/inx.php"] [unique_id "amubp4ijB6THqIZZsUIKzAAAAKw"]
[Thu Jul 30 13:44:55.671321 2026] [security2:error] [pid 935860:tid 936030] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/inx.php"] [unique_id "amubp4ijB6THqIZZsUIKzAAAAKw"]
[Thu Jul 30 13:44:55.706515 2026] [security2:error] [pid 935860:tid 936092] [client 103.181.74.138:51516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubp4ijB6THqIZZsUIKvQAAAOo"], referer: http://pkf.jo
[Thu Jul 30 13:44:55.950314 2026] [security2:error] [pid 935860:tid 936044] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/qqqa.php"] [unique_id "amubp4ijB6THqIZZsUIK0gAAALo"]
[Thu Jul 30 13:44:55.950431 2026] [security2:error] [pid 935860:tid 936044] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/qqqa.php"] [unique_id "amubp4ijB6THqIZZsUIK0gAAALo"]
[Thu Jul 30 13:44:56.241796 2026] [security2:error] [pid 935860:tid 936117] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/reviall.php"] [unique_id "amubqIijB6THqIZZsUIK3QAAAQM"]
[Thu Jul 30 13:44:56.241961 2026] [security2:error] [pid 935860:tid 936117] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/reviall.php"] [unique_id "amubqIijB6THqIZZsUIK3QAAAQM"]
[Thu Jul 30 13:44:56.302555 2026] [autoindex:error] [pid 935860:tid 936013] [client 103.226.142.125:52378] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:44:56.334064 2026] [security2:error] [pid 935860:tid 936056] [client 193.43.140.208:49146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubp4ijB6THqIZZsUIK1QAAAMY"], referer: http://pkf.jo
[Thu Jul 30 13:44:56.342399 2026] [security2:error] [pid 935860:tid 936072] [client 105.66.133.111:5696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubqIijB6THqIZZsUIK1wAAANY"], referer: http://pkf.jo
[Thu Jul 30 13:44:56.384001 2026] [security2:error] [pid 935860:tid 936024] [client 146.75.187.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amubp4ijB6THqIZZsUIKxQAAAKY"]
[Thu Jul 30 13:44:56.422584 2026] [security2:error] [pid 935860:tid 936028] [client 70.24.72.33:38732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubqIijB6THqIZZsUIK2AAAAKo"], referer: http://pkf.jo
[Thu Jul 30 13:44:56.513057 2026] [security2:error] [pid 935860:tid 936054] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/404.php"] [unique_id "amubqIijB6THqIZZsUIK7gAAAMQ"]
[Thu Jul 30 13:44:56.513212 2026] [security2:error] [pid 935860:tid 936054] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/404.php"] [unique_id "amubqIijB6THqIZZsUIK7gAAAMQ"]
[Thu Jul 30 13:44:56.527227 2026] [autoindex:error] [pid 935860:tid 936045] [client 103.226.142.125:52387] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:44:56.537913 2026] [security2:error] [pid 935860:tid 936101] [client 146.75.187.12:8241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amubp4ijB6THqIZZsUIKwAAA8w0"]
[Thu Jul 30 13:44:56.547723 2026] [security2:error] [pid 935860:tid 936101] [client 146.75.187.12:8241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amubp4ijB6THqIZZsUIKvwAA8xc"]
[Thu Jul 30 13:44:56.630745 2026] [security2:error] [pid 935860:tid 936080] [client 181.129.117.13:42702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubqIijB6THqIZZsUIK3AAAAN4"], referer: http://pkf.jo
[Thu Jul 30 13:44:56.734374 2026] [security2:error] [pid 935860:tid 936078] [client 78.167.1.90:54612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubqIijB6THqIZZsUIK-gAAANw"]
[Thu Jul 30 13:44:56.734568 2026] [security2:error] [pid 935860:tid 936078] [client 78.167.1.90:54612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubqIijB6THqIZZsUIK-gAAANw"]
[Thu Jul 30 13:44:56.799099 2026] [security2:error] [pid 935860:tid 936086] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/bolt.php"] [unique_id "amubqIijB6THqIZZsUIK-wAAAOQ"]
[Thu Jul 30 13:44:56.799236 2026] [security2:error] [pid 935860:tid 936086] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/bolt.php"] [unique_id "amubqIijB6THqIZZsUIK-wAAAOQ"]
[Thu Jul 30 13:44:57.070421 2026] [security2:error] [pid 935860:tid 936106] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/File.php"] [unique_id "amubqYijB6THqIZZsUILAgAAAPg"]
[Thu Jul 30 13:44:57.070542 2026] [security2:error] [pid 935860:tid 936106] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/File.php"] [unique_id "amubqYijB6THqIZZsUILAgAAAPg"]
[Thu Jul 30 13:44:57.183086 2026] [proxy:error] [pid 935860:tid 935917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:57.183140 2026] [proxy_http:error] [pid 935860:tid 935917] [remote 91.92.241.196:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:57.183704 2026] [proxy:error] [pid 935860:tid 935917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:44:57.183747 2026] [proxy_http:error] [pid 935860:tid 935917] [remote 91.92.241.196:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:44:57.328014 2026] [security2:error] [pid 935860:tid 936018] [client 138.0.146.80:26631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubqIijB6THqIZZsUIK9gAAAKA"], referer: http://pkf.jo
[Thu Jul 30 13:44:57.342169 2026] [security2:error] [pid 935860:tid 936077] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/fi22.php"] [unique_id "amubqYijB6THqIZZsUILCgAAANs"]
[Thu Jul 30 13:44:57.342340 2026] [security2:error] [pid 935860:tid 936077] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/fi22.php"] [unique_id "amubqYijB6THqIZZsUILCgAAANs"]
[Thu Jul 30 13:44:57.626213 2026] [security2:error] [pid 935860:tid 936060] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/zero.php"] [unique_id "amubqYijB6THqIZZsUILFAAAAMo"]
[Thu Jul 30 13:44:57.626351 2026] [security2:error] [pid 935860:tid 936060] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/zero.php"] [unique_id "amubqYijB6THqIZZsUILFAAAAMo"]
[Thu Jul 30 13:44:57.871931 2026] [security2:error] [pid 935860:tid 936053] [client 172.202.44.182:49754] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.progroupdoha.com"] [uri "/1.php"] [unique_id "amubqYijB6THqIZZsUILHAAAAMM"]
[Thu Jul 30 13:44:57.872075 2026] [security2:error] [pid 935860:tid 936053] [client 172.202.44.182:49754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/1.php"] [unique_id "amubqYijB6THqIZZsUILHAAAAMM"]
[Thu Jul 30 13:44:57.906128 2026] [security2:error] [pid 935860:tid 936089] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1xmomo.php"] [unique_id "amubqYijB6THqIZZsUILHgAAAOc"]
[Thu Jul 30 13:44:57.906238 2026] [security2:error] [pid 935860:tid 936089] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1xmomo.php"] [unique_id "amubqYijB6THqIZZsUILHgAAAOc"]
[Thu Jul 30 13:44:57.987896 2026] [security2:error] [pid 935860:tid 936033] [client 176.205.133.139:47608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubqYijB6THqIZZsUILFwAAAK8"], referer: http://pkf.jo
[Thu Jul 30 13:44:58.008777 2026] [security2:error] [pid 935860:tid 935868] [remote 57.141.0.66:28450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/485177242/feed/rss2/"] [unique_id "amubqYijB6THqIZZsUILGwAAqgY"]
[Thu Jul 30 13:44:58.175575 2026] [security2:error] [pid 935860:tid 936047] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/fmws.php"] [unique_id "amubqoijB6THqIZZsUILIgAAAL0"]
[Thu Jul 30 13:44:58.175711 2026] [security2:error] [pid 935860:tid 936047] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/fmws.php"] [unique_id "amubqoijB6THqIZZsUILIgAAAL0"]
[Thu Jul 30 13:44:58.467257 2026] [security2:error] [pid 935860:tid 935995] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/3PJcpMFsD8B.php"] [unique_id "amubqoijB6THqIZZsUILMAAAAIk"]
[Thu Jul 30 13:44:58.467348 2026] [security2:error] [pid 935860:tid 935995] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/3PJcpMFsD8B.php"] [unique_id "amubqoijB6THqIZZsUILMAAAAIk"]
[Thu Jul 30 13:44:58.759363 2026] [security2:error] [pid 935860:tid 936093] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/hp2.php"] [unique_id "amubqoijB6THqIZZsUILOAAAAOs"]
[Thu Jul 30 13:44:58.759474 2026] [security2:error] [pid 935860:tid 936093] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/hp2.php"] [unique_id "amubqoijB6THqIZZsUILOAAAAOs"]
[Thu Jul 30 13:44:58.828248 2026] [security2:error] [pid 935860:tid 936034] [client 172.202.44.182:49958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/gg.php"] [unique_id "amubqoijB6THqIZZsUILOwAAALA"]
[Thu Jul 30 13:44:59.036581 2026] [security2:error] [pid 935860:tid 936029] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/aabb.php"] [unique_id "amubq4ijB6THqIZZsUILPwAAAKs"]
[Thu Jul 30 13:44:59.036698 2026] [security2:error] [pid 935860:tid 936029] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/aabb.php"] [unique_id "amubq4ijB6THqIZZsUILPwAAAKs"]
[Thu Jul 30 13:44:59.326293 2026] [security2:error] [pid 935860:tid 936097] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1254xx.php"] [unique_id "amubq4ijB6THqIZZsUILSgAAAO8"]
[Thu Jul 30 13:44:59.326402 2026] [security2:error] [pid 935860:tid 936097] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1254xx.php"] [unique_id "amubq4ijB6THqIZZsUILSgAAAO8"]
[Thu Jul 30 13:44:59.477709 2026] [core:notice] [pid 935860:tid 936021] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:44:59.608299 2026] [security2:error] [pid 935860:tid 936054] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amubq4ijB6THqIZZsUILVAAAAMQ"]
[Thu Jul 30 13:44:59.608401 2026] [security2:error] [pid 935860:tid 936054] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amubq4ijB6THqIZZsUILVAAAAMQ"]
[Thu Jul 30 13:44:59.713971 2026] [security2:error] [pid 935860:tid 936063] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amubq4ijB6THqIZZsUILWAAAAM0"]
[Thu Jul 30 13:44:59.877488 2026] [security2:error] [pid 935860:tid 936033] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/pms297.php"] [unique_id "amubq4ijB6THqIZZsUILXQAAAK8"]
[Thu Jul 30 13:44:59.877614 2026] [security2:error] [pid 935860:tid 936033] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/pms297.php"] [unique_id "amubq4ijB6THqIZZsUILXQAAAK8"]
[Thu Jul 30 13:45:00.147873 2026] [security2:error] [pid 935860:tid 936110] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1PJcpMFsD8B.php"] [unique_id "amubrIijB6THqIZZsUILZAAAAPw"]
[Thu Jul 30 13:45:00.148002 2026] [security2:error] [pid 935860:tid 936110] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1PJcpMFsD8B.php"] [unique_id "amubrIijB6THqIZZsUILZAAAAPw"]
[Thu Jul 30 13:45:00.341036 2026] [security2:error] [pid 935860:tid 936081] [client 20.171.55.167:10134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amubrIijB6THqIZZsUILawAAAN8"]
[Thu Jul 30 13:45:00.418930 2026] [security2:error] [pid 935860:tid 936086] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/4PJcpMFsD8B.php"] [unique_id "amubrIijB6THqIZZsUILbwAAAOQ"]
[Thu Jul 30 13:45:00.419046 2026] [security2:error] [pid 935860:tid 936086] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/4PJcpMFsD8B.php"] [unique_id "amubrIijB6THqIZZsUILbwAAAOQ"]
[Thu Jul 30 13:45:00.640935 2026] [security2:error] [pid 935860:tid 936079] [client 43.172.94.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amubrIijB6THqIZZsUILcwAAAN0"]
[Thu Jul 30 13:45:00.697625 2026] [security2:error] [pid 935860:tid 936025] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amubrIijB6THqIZZsUILeAAAAKc"]
[Thu Jul 30 13:45:00.697732 2026] [security2:error] [pid 935860:tid 936025] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amubrIijB6THqIZZsUILeAAAAKc"]
[Thu Jul 30 13:45:00.965952 2026] [security2:error] [pid 935860:tid 936016] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amubrIijB6THqIZZsUILggAAAJ4"]
[Thu Jul 30 13:45:00.966060 2026] [security2:error] [pid 935860:tid 936016] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amubrIijB6THqIZZsUILggAAAJ4"]
[Thu Jul 30 13:45:01.061880 2026] [security2:error] [pid 935860:tid 936013] [client 20.171.55.167:10129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/404.php"] [unique_id "amubrYijB6THqIZZsUILgwAAAJs"]
[Thu Jul 30 13:45:01.241995 2026] [security2:error] [pid 935860:tid 936046] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dyui.php"] [unique_id "amubrYijB6THqIZZsUILiAAAALw"]
[Thu Jul 30 13:45:01.242087 2026] [security2:error] [pid 935860:tid 936046] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/dyui.php"] [unique_id "amubrYijB6THqIZZsUILiAAAALw"]
[Thu Jul 30 13:45:01.516937 2026] [security2:error] [pid 935860:tid 935997] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ho.php"] [unique_id "amubrYijB6THqIZZsUILlwAAAIs"]
[Thu Jul 30 13:45:01.517091 2026] [security2:error] [pid 935860:tid 935997] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ho.php"] [unique_id "amubrYijB6THqIZZsUILlwAAAIs"]
[Thu Jul 30 13:45:01.791538 2026] [security2:error] [pid 935860:tid 936080] [client 20.171.55.167:9408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-configs.php"] [unique_id "amubrYijB6THqIZZsUILoQAAAN4"]
[Thu Jul 30 13:45:01.792488 2026] [security2:error] [pid 935860:tid 936071] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/66b867516c8f01.php"] [unique_id "amubrYijB6THqIZZsUILogAAANU"]
[Thu Jul 30 13:45:01.792602 2026] [security2:error] [pid 935860:tid 936071] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/66b867516c8f01.php"] [unique_id "amubrYijB6THqIZZsUILogAAANU"]
[Thu Jul 30 13:45:02.082095 2026] [security2:error] [pid 935860:tid 936039] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ext.php"] [unique_id "amubroijB6THqIZZsUILsQAAALU"]
[Thu Jul 30 13:45:02.082181 2026] [security2:error] [pid 935860:tid 936039] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/ext.php"] [unique_id "amubroijB6THqIZZsUILsQAAALU"]
[Thu Jul 30 13:45:02.351826 2026] [security2:error] [pid 935860:tid 936015] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amubroijB6THqIZZsUILugAAAJ0"]
[Thu Jul 30 13:45:02.351932 2026] [security2:error] [pid 935860:tid 936015] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amubroijB6THqIZZsUILugAAAJ0"]
[Thu Jul 30 13:45:02.497612 2026] [security2:error] [pid 935860:tid 936004] [client 20.171.55.167:10150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/simple.php"] [unique_id "amubroijB6THqIZZsUILwAAAAJI"]
[Thu Jul 30 13:45:02.631099 2026] [security2:error] [pid 935860:tid 936012] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amubroijB6THqIZZsUILxgAAAJo"]
[Thu Jul 30 13:45:02.631252 2026] [security2:error] [pid 935860:tid 936012] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amubroijB6THqIZZsUILxgAAAJo"]
[Thu Jul 30 13:45:02.917204 2026] [security2:error] [pid 935860:tid 936053] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/584062352875874akp.php"] [unique_id "amubroijB6THqIZZsUIL1gAAAMM"]
[Thu Jul 30 13:45:02.917303 2026] [security2:error] [pid 935860:tid 936053] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/584062352875874akp.php"] [unique_id "amubroijB6THqIZZsUIL1gAAAMM"]
[Thu Jul 30 13:45:03.224760 2026] [security2:error] [pid 935860:tid 936087] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/diidi.php"] [unique_id "amubr4ijB6THqIZZsUIL4wAAAOU"]
[Thu Jul 30 13:45:03.224882 2026] [security2:error] [pid 935860:tid 936087] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/diidi.php"] [unique_id "amubr4ijB6THqIZZsUIL4wAAAOU"]
[Thu Jul 30 13:45:03.262459 2026] [security2:error] [pid 935860:tid 936099] [client 20.171.55.167:10175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/themes.php"] [unique_id "amubr4ijB6THqIZZsUIL5AAAAPE"]
[Thu Jul 30 13:45:03.547451 2026] [security2:error] [pid 935860:tid 936065] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/clarebypas.php"] [unique_id "amubr4ijB6THqIZZsUIL8AAAAM8"]
[Thu Jul 30 13:45:03.547601 2026] [security2:error] [pid 935860:tid 936065] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/clarebypas.php"] [unique_id "amubr4ijB6THqIZZsUIL8AAAAM8"]
[Thu Jul 30 13:45:03.566194 2026] [security2:error] [pid 935860:tid 936020] [client 172.202.44.182:27802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wk/index.php"] [unique_id "amubr4ijB6THqIZZsUIL8wAAAKI"]
[Thu Jul 30 13:45:03.927556 2026] [security2:error] [pid 935860:tid 936114] [client 220.181.108.167:3264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/issue/view/569"] [unique_id "amubr4ijB6THqIZZsUIL-gAAAQA"]
[Thu Jul 30 13:45:03.934312 2026] [security2:error] [pid 935860:tid 936088] [client 219.76.254.140:11483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2016/01/Boots-cuir-lisse-effet-poulain-Beale.jpg"] [unique_id "amubr4ijB6THqIZZsUIL-wAAAOY"]
[Thu Jul 30 13:45:03.997800 2026] [security2:error] [pid 935860:tid 936025] [client 20.171.55.167:9428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/ini.php"] [unique_id "amubr4ijB6THqIZZsUIL_QAAAKc"]
[Thu Jul 30 13:45:04.278778 2026] [proxy:error] [pid 935860:tid 936002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:04.278876 2026] [proxy_http:error] [pid 935860:tid 936002] [client 172.202.44.182:49935] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:04.280055 2026] [proxy:error] [pid 935860:tid 936002] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:04.280123 2026] [proxy_http:error] [pid 935860:tid 936002] [client 172.202.44.182:49935] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:04.383352 2026] [security2:error] [pid 935860:tid 936037] [client 14.187.108.255:46827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsIijB6THqIZZsUIMBAAAALM"], referer: http://pkf.jo
[Thu Jul 30 13:45:04.388175 2026] [security2:error] [pid 935860:tid 936106] [client 14.228.176.26:42933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsIijB6THqIZZsUIMAgAAAPg"], referer: http://pkf.jo
[Thu Jul 30 13:45:04.667855 2026] [security2:error] [pid 935860:tid 936016] [client 176.29.217.177:51948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsIijB6THqIZZsUIMCQAAAJ4"], referer: http://pkf.jo
[Thu Jul 30 13:45:04.759133 2026] [security2:error] [pid 935860:tid 936046] [client 20.171.55.167:10126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/autoload_classmap.php"] [unique_id "amubsIijB6THqIZZsUIMFwAAALw"]
[Thu Jul 30 13:45:04.896839 2026] [core:notice] [pid 935860:tid 936031] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:05.268462 2026] [security2:error] [pid 935860:tid 936059] [client 173.47.197.38:51732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsIijB6THqIZZsUIMGAAAAMk"], referer: http://pkf.jo
[Thu Jul 30 13:45:05.293942 2026] [security2:error] [pid 935860:tid 936110] [client 103.242.199.184:56351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubsYijB6THqIZZsUIMJwAAAPw"]
[Thu Jul 30 13:45:05.294160 2026] [security2:error] [pid 935860:tid 936110] [client 103.242.199.184:56351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubsYijB6THqIZZsUIMJwAAAPw"]
[Thu Jul 30 13:45:05.391026 2026] [security2:error] [pid 935860:tid 936001] [client 190.110.46.233:33049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsIijB6THqIZZsUIMHwAAAI8"], referer: http://pkf.jo
[Thu Jul 30 13:45:05.444607 2026] [security2:error] [pid 935860:tid 935997] [client 186.32.80.111:48060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsYijB6THqIZZsUIMIwAAAIs"], referer: http://pkf.jo
[Thu Jul 30 13:45:05.466624 2026] [security2:error] [pid 935860:tid 936076] [client 20.171.55.167:9895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/as.php"] [unique_id "amubsYijB6THqIZZsUIMLgAAANo"]
[Thu Jul 30 13:45:05.512173 2026] [core:notice] [pid 935860:tid 936066] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:05.879820 2026] [security2:error] [pid 935860:tid 936116] [client 102.215.12.253:57970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsYijB6THqIZZsUIMNwAAAQI"], referer: http://pkf.jo
[Thu Jul 30 13:45:05.989790 2026] [security2:error] [pid 935860:tid 936005] [client 204.8.98.105:35718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amubsYijB6THqIZZsUIMQQAAAJM"]
[Thu Jul 30 13:45:05.989877 2026] [security2:error] [pid 935860:tid 936005] [client 204.8.98.105:35718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amubsYijB6THqIZZsUIMQQAAAJM"]
[Thu Jul 30 13:45:06.064122 2026] [security2:error] [pid 935860:tid 936088] [client 186.105.202.132:38524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsYijB6THqIZZsUIMOAAAAOY"], referer: http://pkf.jo
[Thu Jul 30 13:45:06.192142 2026] [security2:error] [pid 935860:tid 936056] [client 20.171.55.167:9904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/admin/upload/css.php"] [unique_id "amubsoijB6THqIZZsUIMRwAAAMY"]
[Thu Jul 30 13:45:06.493927 2026] [security2:error] [pid 935860:tid 936077] [client 189.100.69.209:22038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsoijB6THqIZZsUIMQwAAANs"], referer: http://pkf.jo
[Thu Jul 30 13:45:06.611291 2026] [security2:error] [pid 935860:tid 936063] [client 103.127.7.39:45010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubsoijB6THqIZZsUIMTQAAAM0"], referer: http://pkf.jo
[Thu Jul 30 13:45:06.845423 2026] [core:notice] [pid 935860:tid 936059] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:06.961312 2026] [security2:error] [pid 935860:tid 935997] [client 20.171.55.167:9887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/pki-validation/afnew.php"] [unique_id "amubsoijB6THqIZZsUIMZAAAAIs"]
[Thu Jul 30 13:45:07.148956 2026] [security2:error] [pid 935860:tid 936048] [client 172.202.44.182:49938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp.php"] [unique_id "amubs4ijB6THqIZZsUIMcgAAAL4"]
[Thu Jul 30 13:45:07.255679 2026] [core:error] [pid 935860:tid 935940] [remote 74.7.228.38:53336] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:45:07.255704 2026] [core:error] [pid 935860:tid 935940] [remote 74.7.228.38:53336] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:45:07.255894 2026] [security2:error] [pid 935860:tid 935991] [client 74.7.228.38:53336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.carrescia.com.uix.gzj.temporary.site"] [uri "/index.php"] [unique_id "amubs4ijB6THqIZZsUIMeQAAhU4"]
[Thu Jul 30 13:45:07.324362 2026] [security2:error] [pid 935860:tid 936032] [client 78.167.1.90:56330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubs4ijB6THqIZZsUIMegAAAK4"]
[Thu Jul 30 13:45:07.324957 2026] [security2:error] [pid 935860:tid 936032] [client 78.167.1.90:56330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubs4ijB6THqIZZsUIMegAAAK4"]
[Thu Jul 30 13:45:07.680765 2026] [security2:error] [pid 935860:tid 936004] [client 20.171.55.167:9906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/lufix.php"] [unique_id "amubs4ijB6THqIZZsUIMhwAAAJI"]
[Thu Jul 30 13:45:08.294466 2026] [security2:error] [pid 935860:tid 936036] [client 74.7.175.185:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.pvc.hfl.temporary.site"] [uri "/index.php"] [unique_id "amubsoijB6THqIZZsUIMXwAAALI"]
[Thu Jul 30 13:45:08.295247 2026] [security2:error] [pid 935860:tid 936041] [client 74.7.175.185:40762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.pvc.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amubsoijB6THqIZZsUIMXAAAt2U"]
[Thu Jul 30 13:45:08.420340 2026] [security2:error] [pid 935860:tid 936054] [client 172.202.44.182:49951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amubtIijB6THqIZZsUIMmQAAAMQ"]
[Thu Jul 30 13:45:08.434748 2026] [security2:error] [pid 935860:tid 936007] [client 20.171.55.167:9865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/media.php"] [unique_id "amubtIijB6THqIZZsUIMmwAAAJU"]
[Thu Jul 30 13:45:08.930824 2026] [security2:error] [pid 935860:tid 935944] [remote 216.73.217.142:11637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amubtIijB6THqIZZsUIMrgAAwlI"]
[Thu Jul 30 13:45:08.954341 2026] [security2:error] [pid 935860:tid 936047] [client 74.7.244.35:46850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.evergreentransportaionservice.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amubtIijB6THqIZZsUIMrwAAAL0"]
[Thu Jul 30 13:45:09.027344 2026] [security2:error] [pid 935860:tid 936062] [client 103.190.40.154:23442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amubtIijB6THqIZZsUIMqwAAAMw"]
[Thu Jul 30 13:45:09.027551 2026] [security2:error] [pid 935860:tid 936062] [client 103.190.40.154:23442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amubtIijB6THqIZZsUIMqwAAAMw"]
[Thu Jul 30 13:45:09.165009 2026] [security2:error] [pid 935860:tid 936093] [client 20.171.55.167:9888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/simple.php"] [unique_id "amubtYijB6THqIZZsUIMuAAAAOs"]
[Thu Jul 30 13:45:09.934514 2026] [security2:error] [pid 935860:tid 936056] [client 20.171.55.167:9909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/contact.php"] [unique_id "amubtYijB6THqIZZsUIMzAAAAMY"]
[Thu Jul 30 13:45:10.513365 2026] [core:notice] [pid 935860:tid 936097] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:10.624031 2026] [security2:error] [pid 935860:tid 936094] [client 216.73.216.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesounddepot.com"] [uri "/index.php"] [unique_id "amubtIijB6THqIZZsUIMngAA7DE"]
[Thu Jul 30 13:45:10.667034 2026] [security2:error] [pid 935860:tid 936072] [client 20.171.55.167:9907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/byp.php"] [unique_id "amubtoijB6THqIZZsUIM5AAAANY"]
[Thu Jul 30 13:45:10.975120 2026] [security2:error] [pid 935860:tid 936118] [client 172.202.44.182:4601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/av.php"] [unique_id "amubtoijB6THqIZZsUIM7wAAAQQ"]
[Thu Jul 30 13:45:11.129552 2026] [security2:error] [pid 935860:tid 936051] [client 172.202.44.182:49779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/file.php"] [unique_id "amubt4ijB6THqIZZsUIM8wAAAME"]
[Thu Jul 30 13:45:11.345215 2026] [security2:error] [pid 935860:tid 935966] [remote 57.141.18.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amubt4ijB6THqIZZsUIM-QAApGg"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=sony&filter_materials=linen,polyester,denim,aluminum,nylon,steel,titanium&orderby=date&status=instock&unfilter=1
[Thu Jul 30 13:45:11.431629 2026] [security2:error] [pid 935860:tid 936088] [client 20.171.55.167:9858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/upload.php"] [unique_id "amubt4ijB6THqIZZsUIM_AAAAOY"]
[Thu Jul 30 13:45:11.744116 2026] [security2:error] [pid 935860:tid 935965] [remote 57.141.18.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amubt4ijB6THqIZZsUINAwAA9Gc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=sony&filter_materials=linen,polyester,denim,aluminum,nylon,steel,titanium&orderby=date&status=instock&unfilter=1
[Thu Jul 30 13:45:11.883131 2026] [security2:error] [pid 935860:tid 936003] [client 50.6.43.217:28198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amubt4ijB6THqIZZsUINCgAAAJE"]
[Thu Jul 30 13:45:11.937072 2026] [security2:error] [pid 935860:tid 936037] [client 172.202.44.182:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/mini.php"] [unique_id "amubt4ijB6THqIZZsUINEAAAALM"]
[Thu Jul 30 13:45:11.946270 2026] [security2:error] [pid 935860:tid 935979] [remote 216.73.217.142:11637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/doc/source/percona-server-logo.jpg"] [unique_id "amubt4ijB6THqIZZsUINEQAA5XU"]
[Thu Jul 30 13:45:12.014535 2026] [security2:error] [pid 935860:tid 936038] [client 50.6.43.217:28208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amubt4ijB6THqIZZsUINDgAAALQ"]
[Thu Jul 30 13:45:12.043711 2026] [core:notice] [pid 935860:tid 936114] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:12.066324 2026] [security2:error] [pid 935860:tid 936019] [client 216.73.216.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thesounddepot.com"] [uri "/index.php"] [unique_id "amubt4ijB6THqIZZsUINBQAAoXc"], referer: https://thesounddepot.com/sitemap.xml
[Thu Jul 30 13:45:12.159888 2026] [security2:error] [pid 935860:tid 936099] [client 20.171.55.167:9860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "amubuIijB6THqIZZsUINFgAAAPE"]
[Thu Jul 30 13:45:12.976404 2026] [security2:error] [pid 935860:tid 936071] [client 172.202.44.182:27754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/aa.php"] [unique_id "amubuIijB6THqIZZsUINMgAAANU"]
[Thu Jul 30 13:45:13.277387 2026] [security2:error] [pid 935860:tid 936061] [client 74.7.241.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bestdogproductguide.com"] [uri "/robots.txt"] [unique_id "amubuYijB6THqIZZsUINPAAAy2I"]
[Thu Jul 30 13:45:13.371993 2026] [security2:error] [pid 935860:tid 936105] [client 20.171.55.167:10131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cong.php"] [unique_id "amubuYijB6THqIZZsUINPgAAAPc"]
[Thu Jul 30 13:45:14.070715 2026] [security2:error] [pid 935860:tid 936059] [client 20.171.55.167:9899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/about/function.php"] [unique_id "amubuoijB6THqIZZsUINUwAAAMk"]
[Thu Jul 30 13:45:14.777838 2026] [security2:error] [pid 935860:tid 936090] [client 20.171.55.167:9871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/filemanager/dialog.php"] [unique_id "amubuoijB6THqIZZsUINYwAAAOg"]
[Thu Jul 30 13:45:15.232331 2026] [security2:error] [pid 935860:tid 936069] [client 172.202.44.182:27797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/w.php"] [unique_id "amubu4ijB6THqIZZsUINdQAAANM"]
[Thu Jul 30 13:45:15.351447 2026] [security2:error] [pid 935860:tid 936014] [client 123.26.56.248:59209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubu4ijB6THqIZZsUINcAAAAJw"], referer: http://pkf.jo
[Thu Jul 30 13:45:15.525043 2026] [security2:error] [pid 935860:tid 936001] [client 20.171.55.167:10132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/bak.php"] [unique_id "amubu4ijB6THqIZZsUINgAAAAI8"]
[Thu Jul 30 13:45:15.957646 2026] [security2:error] [pid 935860:tid 936072] [client 103.242.199.184:56898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubu4ijB6THqIZZsUINigAAANY"]
[Thu Jul 30 13:45:15.957769 2026] [security2:error] [pid 935860:tid 936072] [client 103.242.199.184:56898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubu4ijB6THqIZZsUINigAAANY"]
[Thu Jul 30 13:45:16.090453 2026] [security2:error] [pid 935860:tid 935880] [remote 57.141.0.4:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amubvIijB6THqIZZsUINkAAA_RI"]
[Thu Jul 30 13:45:16.277527 2026] [security2:error] [pid 935860:tid 936051] [client 20.171.55.167:10156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-info.php"] [unique_id "amubvIijB6THqIZZsUINlAAAAME"]
[Thu Jul 30 13:45:16.457764 2026] [security2:error] [pid 935860:tid 936018] [client 172.202.44.182:4552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/admin.php"] [unique_id "amubvIijB6THqIZZsUINmAAAAKA"]
[Thu Jul 30 13:45:17.024680 2026] [security2:error] [pid 935860:tid 936102] [client 20.171.55.167:9890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/files/index.php"] [unique_id "amubvYijB6THqIZZsUINtAAAAPQ"]
[Thu Jul 30 13:45:17.271653 2026] [core:notice] [pid 935860:tid 935997] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:17.561261 2026] [security2:error] [pid 935860:tid 936058] [client 172.202.44.182:37361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-content/themes/admin.php"] [unique_id "amubvYijB6THqIZZsUINxwAAAMg"]
[Thu Jul 30 13:45:17.749547 2026] [security2:error] [pid 935860:tid 935991] [client 20.171.55.167:9435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/css.php"] [unique_id "amubvYijB6THqIZZsUINyQAAAIU"]
[Thu Jul 30 13:45:18.094381 2026] [core:notice] [pid 935860:tid 936005] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:18.158295 2026] [security2:error] [pid 935860:tid 936109] [client 172.202.44.182:49767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/user/index.php"] [unique_id "amubvoijB6THqIZZsUIN1gAAAPs"]
[Thu Jul 30 13:45:18.249727 2026] [core:notice] [pid 935860:tid 936029] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:18.506470 2026] [security2:error] [pid 935860:tid 936084] [client 20.171.55.167:10112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/css/index.php"] [unique_id "amubvoijB6THqIZZsUIN4gAAAOI"]
[Thu Jul 30 13:45:18.634196 2026] [security2:error] [pid 935860:tid 936087] [client 103.190.40.154:23230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amubvoijB6THqIZZsUIN5AAAAOU"]
[Thu Jul 30 13:45:18.634316 2026] [security2:error] [pid 935860:tid 936087] [client 103.190.40.154:23230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amubvoijB6THqIZZsUIN5AAAAOU"]
[Thu Jul 30 13:45:18.649322 2026] [security2:error] [pid 935860:tid 936053] [client 172.202.44.182:37320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/m.php"] [unique_id "amubvoijB6THqIZZsUIN5wAAAMM"]
[Thu Jul 30 13:45:18.930881 2026] [security2:error] [pid 935860:tid 936009] [client 78.167.1.90:54148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubvoijB6THqIZZsUIN6wAAAJc"]
[Thu Jul 30 13:45:18.931348 2026] [security2:error] [pid 935860:tid 936009] [client 78.167.1.90:54148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubvoijB6THqIZZsUIN6wAAAJc"]
[Thu Jul 30 13:45:19.011169 2026] [core:error] [pid 935860:tid 936097] [client 66.249.74.37:54061] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:45:19.011199 2026] [core:error] [pid 935860:tid 936097] [client 66.249.74.37:54061] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:45:19.212097 2026] [security2:error] [pid 935860:tid 936083] [client 20.171.55.167:10113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/bak.php"] [unique_id "amubv4ijB6THqIZZsUIN9wAAAOE"]
[Thu Jul 30 13:45:19.364878 2026] [proxy:error] [pid 935860:tid 936088] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:19.364966 2026] [proxy_http:error] [pid 935860:tid 936088] [client 172.202.44.182:49781] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:19.365541 2026] [proxy:error] [pid 935860:tid 936088] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:19.365586 2026] [proxy_http:error] [pid 935860:tid 936088] [client 172.202.44.182:49781] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:19.551367 2026] [security2:error] [pid 935860:tid 936115] [client 172.237.109.114:38882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amubvoijB6THqIZZsUIN7QAAAQE"]
[Thu Jul 30 13:45:19.606550 2026] [security2:error] [pid 935860:tid 936015] [client 172.202.44.182:37337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amubv4ijB6THqIZZsUIOAAAAAJ0"]
[Thu Jul 30 13:45:19.919232 2026] [security2:error] [pid 935860:tid 936018] [client 20.171.55.167:9438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/alfa-rex.php7"] [unique_id "amubv4ijB6THqIZZsUIOCQAAAKA"]
[Thu Jul 30 13:45:20.512334 2026] [autoindex:error] [pid 935860:tid 936041] [client 172.202.44.182:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_d35de2e9/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:45:20.630909 2026] [security2:error] [pid 935860:tid 936099] [client 20.171.55.167:10128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/wp-login.php"] [unique_id "amubwIijB6THqIZZsUIOGgAAAPE"]
[Thu Jul 30 13:45:20.671026 2026] [security2:error] [pid 935860:tid 936004] [client 43.172.195.68:58854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amubwIijB6THqIZZsUIOFQAAAJI"]
[Thu Jul 30 13:45:20.741552 2026] [security2:error] [pid 935860:tid 936079] [client 172.202.44.182:27724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/classwithtostring.php"] [unique_id "amubwIijB6THqIZZsUIOIQAAAN0"]
[Thu Jul 30 13:45:21.112100 2026] [core:notice] [pid 935860:tid 936107] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:21.117732 2026] [security2:error] [pid 935860:tid 936107] [client 43.173.181.228:50642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amubwYijB6THqIZZsUIOKAAAAPk"], referer: https://carnetdeshopping.com/index.php/typography/
[Thu Jul 30 13:45:21.234903 2026] [core:notice] [pid 935860:tid 936053] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:21.338011 2026] [security2:error] [pid 935860:tid 936098] [client 20.171.55.167:9919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/cloud.php"] [unique_id "amubwYijB6THqIZZsUIOMgAAAPA"]
[Thu Jul 30 13:45:21.366845 2026] [security2:error] [pid 935860:tid 936033] [client 172.202.44.182:49967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amubwYijB6THqIZZsUIONAAAAK8"]
[Thu Jul 30 13:45:22.074828 2026] [security2:error] [pid 935860:tid 936116] [client 20.171.55.167:9908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/index.php"] [unique_id "amubwoijB6THqIZZsUIOQAAAAQI"]
[Thu Jul 30 13:45:22.150723 2026] [security2:error] [pid 935860:tid 936023] [client 172.202.44.182:37339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/gmo.php"] [unique_id "amubwoijB6THqIZZsUIOQQAAAKU"]
[Thu Jul 30 13:45:22.557919 2026] [security2:error] [pid 935860:tid 936110] [client 172.202.44.182:49764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/index/function.php"] [unique_id "amubwoijB6THqIZZsUIOSwAAAPw"]
[Thu Jul 30 13:45:22.805308 2026] [security2:error] [pid 935860:tid 936094] [client 20.171.55.167:9868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/readme.php"] [unique_id "amubwoijB6THqIZZsUIOUAAAAOw"]
[Thu Jul 30 13:45:23.146596 2026] [proxy:error] [pid 935860:tid 935949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:23.146650 2026] [proxy_http:error] [pid 935860:tid 935949] [remote 74.7.241.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:23.147261 2026] [proxy:error] [pid 935860:tid 935949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:23.147307 2026] [proxy_http:error] [pid 935860:tid 935949] [remote 74.7.241.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:23.225860 2026] [security2:error] [pid 935860:tid 935992] [client 172.202.44.182:36104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-content/languages/index.php"] [unique_id "amubw4ijB6THqIZZsUIOWQAAAIY"]
[Thu Jul 30 13:45:23.525909 2026] [security2:error] [pid 935860:tid 936008] [client 20.171.55.167:9856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/about.php"] [unique_id "amubw4ijB6THqIZZsUIOYwAAAJY"]
[Thu Jul 30 13:45:24.254393 2026] [security2:error] [pid 935860:tid 936112] [client 20.171.55.167:9885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/themes/404.php"] [unique_id "amubxIijB6THqIZZsUIOggAAAP4"]
[Thu Jul 30 13:45:24.993625 2026] [security2:error] [pid 935860:tid 936095] [client 20.171.55.167:9874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/index.php"] [unique_id "amubxIijB6THqIZZsUIOlgAAAO0"]
[Thu Jul 30 13:45:25.489599 2026] [security2:error] [pid 935860:tid 935918] [remote 216.73.217.142:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amubxYijB6THqIZZsUIOpQAAqjg"]
[Thu Jul 30 13:45:25.609462 2026] [proxy:error] [pid 935860:tid 936031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:25.609545 2026] [proxy_http:error] [pid 935860:tid 936031] [client 172.202.44.182:49791] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:25.610185 2026] [proxy:error] [pid 935860:tid 936031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:25.610232 2026] [proxy_http:error] [pid 935860:tid 936031] [client 172.202.44.182:49791] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:25.720874 2026] [security2:error] [pid 935860:tid 936100] [client 20.171.55.167:10174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/themes.php"] [unique_id "amubxYijB6THqIZZsUIOqgAAAPI"]
[Thu Jul 30 13:45:26.206677 2026] [security2:error] [pid 935860:tid 936051] [client 172.202.44.182:36122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-the.php"] [unique_id "amubxoijB6THqIZZsUIOvAAAAME"]
[Thu Jul 30 13:45:26.427274 2026] [security2:error] [pid 935860:tid 936012] [client 20.171.55.167:10121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/dropdown.php"] [unique_id "amubxoijB6THqIZZsUIOwQAAAJo"]
[Thu Jul 30 13:45:26.654298 2026] [security2:error] [pid 935860:tid 936087] [client 103.242.199.184:57446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubxoijB6THqIZZsUIOzAAAAOU"]
[Thu Jul 30 13:45:26.654397 2026] [security2:error] [pid 935860:tid 936087] [client 103.242.199.184:57446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amubxoijB6THqIZZsUIOzAAAAOU"]
[Thu Jul 30 13:45:27.322346 2026] [security2:error] [pid 935860:tid 936093] [client 24.189.37.228:37122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubxoijB6THqIZZsUIO1AAAAOs"], referer: http://pkf.jo
[Thu Jul 30 13:45:27.632317 2026] [security2:error] [pid 935860:tid 935956] [remote 74.7.243.224:58704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amubx4ijB6THqIZZsUIO5QAA7l4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 13:45:27.706447 2026] [security2:error] [pid 935860:tid 936025] [client 20.171.55.167:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/404.php"] [unique_id "amubx4ijB6THqIZZsUIO6wAAAKc"]
[Thu Jul 30 13:45:27.809207 2026] [proxy:error] [pid 935860:tid 936095] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:27.809308 2026] [proxy_http:error] [pid 935860:tid 936095] [client 172.202.44.182:49786] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:27.810145 2026] [proxy:error] [pid 935860:tid 936095] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:27.810202 2026] [proxy_http:error] [pid 935860:tid 936095] [client 172.202.44.182:49786] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:27.906268 2026] [security2:error] [pid 935860:tid 936100] [client 172.202.44.182:36118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/404.php"] [unique_id "amubx4ijB6THqIZZsUIO7gAAAPI"]
[Thu Jul 30 13:45:27.954130 2026] [security2:error] [pid 935860:tid 936062] [client 88.173.151.31:3547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubx4ijB6THqIZZsUIO5wAAAMw"], referer: http://pkf.jo
[Thu Jul 30 13:45:28.057648 2026] [security2:error] [pid 935860:tid 936022] [client 109.151.224.28:45626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubx4ijB6THqIZZsUIO7AAAAKQ"], referer: http://pkf.jo
[Thu Jul 30 13:45:28.434870 2026] [security2:error] [pid 935860:tid 936014] [client 20.171.55.167:10135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/upgrade/index.php"] [unique_id "amubyIijB6THqIZZsUIPAwAAAJw"]
[Thu Jul 30 13:45:29.016020 2026] [security2:error] [pid 935860:tid 936026] [client 172.202.44.182:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/init.php"] [unique_id "amubyYijB6THqIZZsUIPFwAAAKg"]
[Thu Jul 30 13:45:29.016453 2026] [security2:error] [pid 935860:tid 935881] [remote 216.73.217.142:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amubyYijB6THqIZZsUIPGAAAwhM"]
[Thu Jul 30 13:45:29.141156 2026] [security2:error] [pid 935860:tid 936066] [client 20.171.55.167:10127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/file.php"] [unique_id "amubyYijB6THqIZZsUIPHQAAANA"]
[Thu Jul 30 13:45:29.144849 2026] [security2:error] [pid 935860:tid 936072] [client 139.5.11.207:42894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubyIijB6THqIZZsUIPEQAAANY"], referer: http://pkf.jo
[Thu Jul 30 13:45:29.402340 2026] [security2:error] [pid 935860:tid 936068] [client 103.190.40.154:20888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amubyYijB6THqIZZsUIPJwAAANI"]
[Thu Jul 30 13:45:29.402481 2026] [security2:error] [pid 935860:tid 936068] [client 103.190.40.154:20888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amubyYijB6THqIZZsUIPJwAAANI"]
[Thu Jul 30 13:45:29.881641 2026] [security2:error] [pid 935860:tid 936018] [client 20.171.55.167:9889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/index.php"] [unique_id "amubyYijB6THqIZZsUIPOAAAAKA"]
[Thu Jul 30 13:45:30.138003 2026] [core:notice] [pid 935860:tid 936090] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:30.151743 2026] [security2:error] [pid 935860:tid 936000] [client 120.233.109.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amubyYijB6THqIZZsUIPJAAAAI4"]
[Thu Jul 30 13:45:30.447997 2026] [security2:error] [pid 935860:tid 936004] [client 78.167.1.90:53954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubyoijB6THqIZZsUIPSQAAAJI"]
[Thu Jul 30 13:45:30.448438 2026] [security2:error] [pid 935860:tid 936004] [client 78.167.1.90:53954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amubyoijB6THqIZZsUIPSQAAAJI"]
[Thu Jul 30 13:45:30.521111 2026] [security2:error] [pid 935860:tid 935877] [remote 216.73.217.142:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amubyoijB6THqIZZsUIPSgAA3g8"]
[Thu Jul 30 13:45:30.598321 2026] [security2:error] [pid 935860:tid 936003] [client 20.171.55.167:10157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/cloud.php"] [unique_id "amubyoijB6THqIZZsUIPTgAAAJE"]
[Thu Jul 30 13:45:30.964656 2026] [security2:error] [pid 935860:tid 936047] [client 172.202.44.182:4559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/file5.php"] [unique_id "amubyoijB6THqIZZsUIPVwAAAL0"]
[Thu Jul 30 13:45:31.069004 2026] [security2:error] [pid 935860:tid 936106] [client 177.245.228.118:5358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubyoijB6THqIZZsUIPUQAAAPg"], referer: http://pkf.jo
[Thu Jul 30 13:45:31.238013 2026] [security2:error] [pid 935860:tid 936009] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubyoijB6THqIZZsUIPTwAAl0Y"]
[Thu Jul 30 13:45:31.324388 2026] [security2:error] [pid 935860:tid 936111] [client 20.171.55.167:9870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amuby4ijB6THqIZZsUIPZQAAAP0"]
[Thu Jul 30 13:45:31.470013 2026] [security2:error] [pid 935860:tid 936104] [client 172.202.44.182:49975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/aaa.php"] [unique_id "amuby4ijB6THqIZZsUIPbQAAAPY"]
[Thu Jul 30 13:45:31.597275 2026] [security2:error] [pid 935860:tid 936061] [client 20.52.125.110:11217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/011i.php"] [unique_id "amuby4ijB6THqIZZsUIPdAAAAMs"]
[Thu Jul 30 13:45:31.621034 2026] [security2:error] [pid 935860:tid 936109] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuby4ijB6THqIZZsUIPaAAAAPs"]
[Thu Jul 30 13:45:31.990967 2026] [security2:error] [pid 935860:tid 936020] [client 20.52.125.110:11815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/03a005685d.php"] [unique_id "amuby4ijB6THqIZZsUIPfwAAAKI"]
[Thu Jul 30 13:45:32.030914 2026] [security2:error] [pid 935860:tid 936011] [client 20.171.55.167:9861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/404.php"] [unique_id "amubzIijB6THqIZZsUIPgwAAAJk"]
[Thu Jul 30 13:45:32.177041 2026] [security2:error] [pid 935860:tid 935963] [remote 3.7.204.22:53894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.204.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daralnaseemdxb.com"] [uri "/wp-login.php"] [unique_id "amubzIijB6THqIZZsUIPiQAA3WU"]
[Thu Jul 30 13:45:32.388698 2026] [security2:error] [pid 935860:tid 936043] [client 20.52.125.110:11210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/403.php"] [unique_id "amubzIijB6THqIZZsUIPjwAAALk"]
[Thu Jul 30 13:45:32.731084 2026] [security2:error] [pid 935860:tid 936050] [client 20.171.55.167:9875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/function.php"] [unique_id "amubzIijB6THqIZZsUIPmAAAAMA"]
[Thu Jul 30 13:45:32.782127 2026] [security2:error] [pid 935860:tid 936074] [client 20.52.125.110:11203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/404.php"] [unique_id "amubzIijB6THqIZZsUIPmQAAANg"]
[Thu Jul 30 13:45:33.177721 2026] [security2:error] [pid 935860:tid 936048] [client 20.52.125.110:11220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/aa.php"] [unique_id "amubzYijB6THqIZZsUIPpQAAAL4"]
[Thu Jul 30 13:45:33.182040 2026] [security2:error] [pid 935860:tid 935992] [client 172.202.44.182:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/getid3-core.php"] [unique_id "amubzYijB6THqIZZsUIPpwAAAIY"]
[Thu Jul 30 13:45:33.423838 2026] [security2:error] [pid 935860:tid 936054] [client 172.202.44.182:36159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-admin/maint/index.php"] [unique_id "amubzYijB6THqIZZsUIPrAAAAMQ"]
[Thu Jul 30 13:45:33.494526 2026] [security2:error] [pid 935860:tid 936021] [client 20.171.55.167:9897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/file.php"] [unique_id "amubzYijB6THqIZZsUIPrwAAAKM"]
[Thu Jul 30 13:45:33.573365 2026] [security2:error] [pid 935860:tid 936089] [client 20.52.125.110:11785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/aafewc0k.php"] [unique_id "amubzYijB6THqIZZsUIPswAAAOc"]
[Thu Jul 30 13:45:33.970470 2026] [security2:error] [pid 935860:tid 936003] [client 20.52.125.110:11837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/abcd.php"] [unique_id "amubzYijB6THqIZZsUIPugAAAJE"]
[Thu Jul 30 13:45:34.365393 2026] [security2:error] [pid 935860:tid 936035] [client 20.52.125.110:11789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/about.php"] [unique_id "amubzoijB6THqIZZsUIPxQAAALE"]
[Thu Jul 30 13:45:34.640146 2026] [security2:error] [pid 935860:tid 936079] [client 20.171.55.167:9866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/acme-challenge/autoload_classmap.php"] [unique_id "amubzoijB6THqIZZsUIP1gAAAN0"]
[Thu Jul 30 13:45:34.758089 2026] [security2:error] [pid 935860:tid 936109] [client 20.52.125.110:11202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/admin.php"] [unique_id "amubzoijB6THqIZZsUIP2QAAAPs"]
[Thu Jul 30 13:45:34.929026 2026] [security2:error] [pid 935860:tid 936027] [client 152.58.14.165:58158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubzoijB6THqIZZsUIP1QAAAKk"], referer: http://pkf.jo
[Thu Jul 30 13:45:35.123958 2026] [core:notice] [pid 935860:tid 936011] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:35.150104 2026] [security2:error] [pid 935860:tid 936000] [client 20.52.125.110:11206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/adminfuns.php"] [unique_id "amubz4ijB6THqIZZsUIP6QAAAI4"]
[Thu Jul 30 13:45:35.250220 2026] [security2:error] [pid 935860:tid 936061] [client 172.202.44.182:49730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/adminer.php"] [unique_id "amubz4ijB6THqIZZsUIP7AAAAMs"]
[Thu Jul 30 13:45:35.258444 2026] [core:notice] [pid 935860:tid 936023] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:35.293622 2026] [security2:error] [pid 935860:tid 936012] [client 172.202.44.182:4606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/shell.php"] [unique_id "amubz4ijB6THqIZZsUIP7wAAAJo"]
[Thu Jul 30 13:45:35.445966 2026] [security2:error] [pid 935860:tid 936099] [client 74.7.230.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.koinjp189.com"] [uri "/cgi-sys/404.html"] [unique_id "amubz4ijB6THqIZZsUIP8wAAAPE"]
[Thu Jul 30 13:45:35.512657 2026] [security2:error] [pid 935860:tid 936080] [client 20.171.55.167:9420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/themes.php"] [unique_id "amubz4ijB6THqIZZsUIP9gAAAN4"]
[Thu Jul 30 13:45:35.541753 2026] [security2:error] [pid 935860:tid 936083] [client 20.52.125.110:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/albin.php"] [unique_id "amubz4ijB6THqIZZsUIP_AAAAOE"]
[Thu Jul 30 13:45:35.936051 2026] [security2:error] [pid 935860:tid 936054] [client 20.52.125.110:11814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/amfsqvgv.php"] [unique_id "amubz4ijB6THqIZZsUIQRAAAAMQ"]
[Thu Jul 30 13:45:36.024306 2026] [security2:error] [pid 935860:tid 936006] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amubz4ijB6THqIZZsUIP8QAAlEA"]
[Thu Jul 30 13:45:36.093936 2026] [security2:error] [pid 935860:tid 936014] [client 123.24.140.78:34869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amubz4ijB6THqIZZsUIQJQAAAJw"], referer: http://pkf.jo
[Thu Jul 30 13:45:36.241086 2026] [security2:error] [pid 935860:tid 936036] [client 20.171.55.167:9918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/wp-login.php"] [unique_id "amub0IijB6THqIZZsUIQWQAAALI"]
[Thu Jul 30 13:45:36.333519 2026] [security2:error] [pid 935860:tid 936103] [client 20.52.125.110:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/ant.php"] [unique_id "amub0IijB6THqIZZsUIQXgAAAPU"]
[Thu Jul 30 13:45:36.433625 2026] [security2:error] [pid 935860:tid 936039] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amubz4ijB6THqIZZsUIQOwAAALU"]
[Thu Jul 30 13:45:36.495272 2026] [security2:error] [pid 935860:tid 936107] [client 178.238.252.106:46750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub0IijB6THqIZZsUIQWAAAAPk"], referer: http://pkf.jo
[Thu Jul 30 13:45:36.733682 2026] [security2:error] [pid 935860:tid 936019] [client 20.52.125.110:11835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/appreciators.php"] [unique_id "amub0IijB6THqIZZsUIQaAAAAKE"]
[Thu Jul 30 13:45:36.775387 2026] [security2:error] [pid 935860:tid 936013] [client 172.202.44.182:36111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/f35.php"] [unique_id "amub0IijB6THqIZZsUIQagAAAJs"]
[Thu Jul 30 13:45:36.960592 2026] [security2:error] [pid 935860:tid 936008] [client 20.171.55.167:9915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/file.php"] [unique_id "amub0IijB6THqIZZsUIQcgAAAJY"]
[Thu Jul 30 13:45:37.061557 2026] [security2:error] [pid 935860:tid 936007] [client 39.34.134.24:52009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub0IijB6THqIZZsUIQaQAAAJU"], referer: http://pkf.jo
[Thu Jul 30 13:45:37.074018 2026] [security2:error] [pid 935860:tid 935997] [client 103.111.164.22:53210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub0IijB6THqIZZsUIQawAAAIs"], referer: http://pkf.jo
[Thu Jul 30 13:45:37.128803 2026] [security2:error] [pid 935860:tid 935995] [client 20.52.125.110:11828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/archive.php"] [unique_id "amub0YijB6THqIZZsUIQegAAAIk"]
[Thu Jul 30 13:45:37.156851 2026] [proxy:error] [pid 935860:tid 936112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:37.156930 2026] [proxy_http:error] [pid 935860:tid 936112] [client 172.202.44.182:49762] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:37.157771 2026] [proxy:error] [pid 935860:tid 936112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:37.157829 2026] [proxy_http:error] [pid 935860:tid 936112] [client 172.202.44.182:49762] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:37.234784 2026] [security2:error] [pid 935860:tid 936074] [client 103.242.199.184:57985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub0YijB6THqIZZsUIQfwAAANg"]
[Thu Jul 30 13:45:37.234909 2026] [security2:error] [pid 935860:tid 936074] [client 103.242.199.184:57985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub0YijB6THqIZZsUIQfwAAANg"]
[Thu Jul 30 13:45:37.364074 2026] [security2:error] [pid 935860:tid 936004] [client 184.22.38.64:56701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub0YijB6THqIZZsUIQdgAAAJI"], referer: http://pkf.jo
[Thu Jul 30 13:45:37.523086 2026] [security2:error] [pid 935860:tid 936018] [client 20.52.125.110:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/as.php"] [unique_id "amub0YijB6THqIZZsUIQhAAAAKA"]
[Thu Jul 30 13:45:37.704148 2026] [security2:error] [pid 935860:tid 936117] [client 20.171.55.167:9891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-trackback.php"] [unique_id "amub0YijB6THqIZZsUIQjAAAAQM"]
[Thu Jul 30 13:45:37.911567 2026] [security2:error] [pid 935860:tid 936060] [client 118.71.161.31:39676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub0YijB6THqIZZsUIQiwAAAMo"], referer: http://pkf.jo
[Thu Jul 30 13:45:37.918115 2026] [security2:error] [pid 935860:tid 936063] [client 20.52.125.110:11794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/atomlib.php"] [unique_id "amub0YijB6THqIZZsUIQkwAAAM0"]
[Thu Jul 30 13:45:38.272114 2026] [security2:error] [pid 935860:tid 936096] [client 153.67.123.8:33682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub0YijB6THqIZZsUIQlAAAAO4"], referer: http://pkf.jo
[Thu Jul 30 13:45:38.313147 2026] [security2:error] [pid 935860:tid 936011] [client 20.52.125.110:11826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/autoload_classmap.php"] [unique_id "amub0oijB6THqIZZsUIQnwAAAJk"]
[Thu Jul 30 13:45:38.449332 2026] [security2:error] [pid 935860:tid 936020] [client 159.146.17.161:30826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub0oijB6THqIZZsUIQnAAAAKI"], referer: http://pkf.jo
[Thu Jul 30 13:45:38.475941 2026] [security2:error] [pid 935860:tid 936099] [client 20.171.55.167:9468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "amub0oijB6THqIZZsUIQowAAAPE"]
[Thu Jul 30 13:45:38.715209 2026] [security2:error] [pid 935860:tid 936015] [client 20.52.125.110:11820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/bb.php"] [unique_id "amub0oijB6THqIZZsUIQrQAAAJ0"]
[Thu Jul 30 13:45:38.754527 2026] [security2:error] [pid 935860:tid 936109] [client 172.202.44.182:40408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/new.php"] [unique_id "amub0oijB6THqIZZsUIQrwAAAPs"]
[Thu Jul 30 13:45:38.839705 2026] [security2:error] [pid 935860:tid 936103] [client 172.202.44.182:49748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/alfa.php"] [unique_id "amub0oijB6THqIZZsUIQsQAAAPU"]
[Thu Jul 30 13:45:38.892295 2026] [security2:error] [pid 935860:tid 936008] [client 181.85.210.195:44037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub0oijB6THqIZZsUIQpwAAAJY"], referer: http://pkf.jo
[Thu Jul 30 13:45:39.065798 2026] [security2:error] [pid 935860:tid 936055] [client 78.167.1.90:57225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub04ijB6THqIZZsUIQuwAAAMU"]
[Thu Jul 30 13:45:39.066380 2026] [security2:error] [pid 935860:tid 936055] [client 78.167.1.90:57225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub04ijB6THqIZZsUIQuwAAAMU"]
[Thu Jul 30 13:45:39.115219 2026] [security2:error] [pid 935860:tid 936051] [client 20.52.125.110:11834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/bnm.php"] [unique_id "amub04ijB6THqIZZsUIQvQAAAME"]
[Thu Jul 30 13:45:39.210154 2026] [security2:error] [pid 935860:tid 936076] [client 20.171.55.167:9900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/index.php"] [unique_id "amub04ijB6THqIZZsUIQwQAAANo"]
[Thu Jul 30 13:45:39.525606 2026] [security2:error] [pid 935860:tid 936036] [client 20.52.125.110:11796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/bootstrap.php"] [unique_id "amub04ijB6THqIZZsUIQygAAALI"]
[Thu Jul 30 13:45:39.541128 2026] [security2:error] [pid 935860:tid 936009] [client 88.226.2.225:48672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub04ijB6THqIZZsUIQxQAAAJc"], referer: http://pkf.jo
[Thu Jul 30 13:45:39.713778 2026] [security2:error] [pid 935860:tid 935998] [client 172.202.44.182:4585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/adminfuns.php"] [unique_id "amub04ijB6THqIZZsUIQ0QAAAIw"]
[Thu Jul 30 13:45:39.918818 2026] [security2:error] [pid 935860:tid 935991] [client 20.171.55.167:10120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/themes.php"] [unique_id "amub04ijB6THqIZZsUIQ1gAAAIU"]
[Thu Jul 30 13:45:39.919048 2026] [security2:error] [pid 935860:tid 936019] [client 20.52.125.110:11867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/buy.php"] [unique_id "amub04ijB6THqIZZsUIQ1wAAAKE"]
[Thu Jul 30 13:45:40.044917 2026] [security2:error] [pid 935860:tid 936086] [client 111.92.158.100:19327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub04ijB6THqIZZsUIQ0wAAAOQ"], referer: http://pkf.jo
[Thu Jul 30 13:45:40.169700 2026] [security2:error] [pid 935860:tid 936021] [client 103.190.40.154:21690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub1IijB6THqIZZsUIQ3gAAAKM"]
[Thu Jul 30 13:45:40.169848 2026] [security2:error] [pid 935860:tid 936021] [client 103.190.40.154:21690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub1IijB6THqIZZsUIQ3gAAAKM"]
[Thu Jul 30 13:45:40.314140 2026] [security2:error] [pid 935860:tid 936007] [client 20.52.125.110:11213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/chosen.php"] [unique_id "amub1IijB6THqIZZsUIQ5QAAAJU"]
[Thu Jul 30 13:45:40.625377 2026] [security2:error] [pid 935860:tid 936103] [client 20.171.55.167:9426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/cloud.php"] [unique_id "amub1IijB6THqIZZsUIQ7gAAAPU"]
[Thu Jul 30 13:45:40.717861 2026] [security2:error] [pid 935860:tid 936051] [client 20.52.125.110:11207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/class-wp-image.php"] [unique_id "amub1IijB6THqIZZsUIQ7wAAAME"]
[Thu Jul 30 13:45:41.127591 2026] [security2:error] [pid 935860:tid 936042] [client 20.52.125.110:11818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/classsmtps.php"] [unique_id "amub1YijB6THqIZZsUIQ_QAAALg"]
[Thu Jul 30 13:45:41.161745 2026] [core:error] [pid 935860:tid 935873] [remote 216.73.216.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:45:41.161764 2026] [core:error] [pid 935860:tid 935873] [remote 216.73.216.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:45:41.321206 2026] [security2:error] [pid 935860:tid 936108] [client 20.171.55.167:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/wp-load.php"] [unique_id "amub1YijB6THqIZZsUIRBQAAAPo"]
[Thu Jul 30 13:45:41.484107 2026] [proxy:error] [pid 935860:tid 936065] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:41.484185 2026] [proxy_http:error] [pid 935860:tid 936065] [client 172.202.44.182:49960] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:41.484863 2026] [proxy:error] [pid 935860:tid 936065] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:41.484910 2026] [proxy_http:error] [pid 935860:tid 936065] [client 172.202.44.182:49960] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:41.520698 2026] [security2:error] [pid 935860:tid 936078] [client 20.52.125.110:11846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/classwithtostring.php"] [unique_id "amub1YijB6THqIZZsUIRHAAAANw"]
[Thu Jul 30 13:45:41.934463 2026] [security2:error] [pid 935860:tid 936099] [client 20.52.125.110:11825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/config.php"] [unique_id "amub1YijB6THqIZZsUIRMwAAAPE"]
[Thu Jul 30 13:45:42.051273 2026] [security2:error] [pid 935860:tid 936046] [client 20.171.55.167:10149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/file.php"] [unique_id "amub1oijB6THqIZZsUIROwAAALw"]
[Thu Jul 30 13:45:42.330139 2026] [security2:error] [pid 935860:tid 936053] [client 20.52.125.110:11784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/core.php"] [unique_id "amub1oijB6THqIZZsUIRRgAAAMM"]
[Thu Jul 30 13:45:42.513873 2026] [security2:error] [pid 935860:tid 936116] [client 50.6.43.217:35674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amub1YijB6THqIZZsUIRLAAAAQI"]
[Thu Jul 30 13:45:42.708252 2026] [security2:error] [pid 935860:tid 936007] [client 172.237.109.114:44265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amub1oijB6THqIZZsUIRPgAAAJU"]
[Thu Jul 30 13:45:42.716714 2026] [autoindex:error] [pid 935860:tid 936097] [client 172.202.44.182:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_d35de2e9/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:45:42.723354 2026] [security2:error] [pid 935860:tid 936117] [client 20.52.125.110:11817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/css.php"] [unique_id "amub1oijB6THqIZZsUIRXAAAAQM"]
[Thu Jul 30 13:45:42.762138 2026] [security2:error] [pid 935860:tid 936107] [client 20.171.55.167:9410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/makeasmtp.php"] [unique_id "amub1oijB6THqIZZsUIRXQAAAPk"]
[Thu Jul 30 13:45:42.944156 2026] [security2:error] [pid 935860:tid 935997] [client 172.202.44.182:40390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/fm.php"] [unique_id "amub1oijB6THqIZZsUIRfAAAAIs"]
[Thu Jul 30 13:45:43.121348 2026] [security2:error] [pid 935860:tid 936049] [client 20.52.125.110:11807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/database.php"] [unique_id "amub14ijB6THqIZZsUIRfwAAAL8"]
[Thu Jul 30 13:45:43.239733 2026] [security2:error] [pid 935860:tid 936100] [client 172.202.44.182:49924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amub14ijB6THqIZZsUIRhgAAAPI"]
[Thu Jul 30 13:45:43.380761 2026] [security2:error] [pid 935860:tid 936034] [client 50.6.43.217:35684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amub1oijB6THqIZZsUIRSwAAALA"]
[Thu Jul 30 13:45:43.473374 2026] [security2:error] [pid 935860:tid 936102] [client 20.171.55.167:10138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/index.php"] [unique_id "amub14ijB6THqIZZsUIRjQAAAPQ"]
[Thu Jul 30 13:45:43.520745 2026] [security2:error] [pid 935860:tid 936093] [client 20.52.125.110:11792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/db.php"] [unique_id "amub14ijB6THqIZZsUIRjgAAAOs"]
[Thu Jul 30 13:45:43.922279 2026] [security2:error] [pid 935860:tid 936048] [client 20.52.125.110:11795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/default.php"] [unique_id "amub14ijB6THqIZZsUIRmAAAAL4"]
[Thu Jul 30 13:45:44.193567 2026] [security2:error] [pid 935860:tid 936092] [client 20.171.55.167:9902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amub2IijB6THqIZZsUIRnwAAAOo"]
[Thu Jul 30 13:45:44.320107 2026] [security2:error] [pid 935860:tid 936005] [client 20.52.125.110:11839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/dropdown.php"] [unique_id "amub2IijB6THqIZZsUIRpAAAAJM"]
[Thu Jul 30 13:45:44.731049 2026] [security2:error] [pid 935860:tid 936117] [client 20.52.125.110:11799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/edit.php"] [unique_id "amub2IijB6THqIZZsUIRuAAAAQM"]
[Thu Jul 30 13:45:45.124346 2026] [security2:error] [pid 935860:tid 936091] [client 20.52.125.110:11833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/f35.php"] [unique_id "amub2YijB6THqIZZsUIRvAAAAOk"]
[Thu Jul 30 13:45:45.503914 2026] [security2:error] [pid 935860:tid 936015] [client 20.171.55.167:9455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/404.php"] [unique_id "amub2YijB6THqIZZsUIRyQAAAJ0"]
[Thu Jul 30 13:45:45.519157 2026] [security2:error] [pid 935860:tid 936081] [client 20.52.125.110:11219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/f7.php"] [unique_id "amub2YijB6THqIZZsUIRywAAAN8"]
[Thu Jul 30 13:45:45.786534 2026] [security2:error] [pid 935860:tid 936014] [client 213.180.203.7:55650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amub2YijB6THqIZZsUIRyAAAAJw"]
[Thu Jul 30 13:45:46.247645 2026] [security2:error] [pid 935860:tid 936048] [client 20.171.55.167:9911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "amub2oijB6THqIZZsUIR4QAAAL4"]
[Thu Jul 30 13:45:46.620294 2026] [security2:error] [pid 935860:tid 936106] [client 172.202.44.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alanturner.com.au"] [uri "/index.php"] [unique_id "amub2oijB6THqIZZsUIR4AAAAPg"]
[Thu Jul 30 13:45:46.906160 2026] [security2:error] [pid 935860:tid 936026] [client 74.7.228.4:45580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "igetvapesonline.com"] [uri "/robots.txt"] [unique_id "amub2oijB6THqIZZsUISBAAAAKg"]
[Thu Jul 30 13:45:46.992679 2026] [security2:error] [pid 935860:tid 935992] [client 20.171.55.167:10115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/radio.php"] [unique_id "amub2oijB6THqIZZsUISBgAAAIY"]
[Thu Jul 30 13:45:47.032356 2026] [security2:error] [pid 935860:tid 935996] [client 196.127.48.107:57631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub2oijB6THqIZZsUIR_AAAAIo"], referer: http://pkf.jo
[Thu Jul 30 13:45:47.371627 2026] [security2:error] [pid 935860:tid 936050] [client 172.202.44.182:36139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/file.php"] [unique_id "amub24ijB6THqIZZsUISFQAAAMA"]
[Thu Jul 30 13:45:47.649288 2026] [security2:error] [pid 935860:tid 936024] [client 172.237.109.114:5841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amub24ijB6THqIZZsUISCAAAAKY"]
[Thu Jul 30 13:45:47.735177 2026] [security2:error] [pid 935860:tid 936054] [client 20.171.55.167:9912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/themes/index.php"] [unique_id "amub24ijB6THqIZZsUISHQAAAMQ"]
[Thu Jul 30 13:45:47.816617 2026] [security2:error] [pid 935860:tid 936075] [client 172.202.44.182:49731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amub24ijB6THqIZZsUISIQAAANk"]
[Thu Jul 30 13:45:47.902331 2026] [security2:error] [pid 935860:tid 936008] [client 103.242.199.184:58531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub24ijB6THqIZZsUISJQAAAJY"]
[Thu Jul 30 13:45:47.903054 2026] [security2:error] [pid 935860:tid 936008] [client 103.242.199.184:58531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub24ijB6THqIZZsUISJQAAAJY"]
[Thu Jul 30 13:45:48.072417 2026] [security2:error] [pid 935860:tid 936089] [client 170.106.11.6:36068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.11.106.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adbacklink.com"] [uri "/contents.php"] [unique_id "amub3IijB6THqIZZsUISKAAAAOc"]
[Thu Jul 30 13:45:48.317353 2026] [security2:error] [pid 935860:tid 935957] [remote 216.73.217.142:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amub3IijB6THqIZZsUISMQAAs18"]
[Thu Jul 30 13:45:48.473918 2026] [security2:error] [pid 935860:tid 936113] [client 20.171.55.167:9905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/admin.php"] [unique_id "amub3IijB6THqIZZsUISNgAAAP8"]
[Thu Jul 30 13:45:48.499209 2026] [autoindex:error] [pid 935860:tid 936004] [client 172.202.44.182:36135] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_d35de2e9/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:45:48.612305 2026] [security2:error] [pid 935860:tid 936051] [client 172.237.109.114:31605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amub3IijB6THqIZZsUISKgAAAME"]
[Thu Jul 30 13:45:48.681463 2026] [security2:error] [pid 935860:tid 936106] [client 172.202.44.182:49937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amub3IijB6THqIZZsUISNwAAAPg"]
[Thu Jul 30 13:45:48.768681 2026] [security2:error] [pid 935860:tid 936019] [client 172.202.44.182:36135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/bolt.php"] [unique_id "amub3IijB6THqIZZsUISOwAAAKE"]
[Thu Jul 30 13:45:48.819791 2026] [security2:error] [pid 935860:tid 935907] [remote 216.73.217.142:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amub3IijB6THqIZZsUISQQAA3i0"]
[Thu Jul 30 13:45:48.919591 2026] [core:notice] [pid 935860:tid 935946] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:49.199901 2026] [security2:error] [pid 935860:tid 936099] [client 20.171.55.167:10116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/system_log.php"] [unique_id "amub3YijB6THqIZZsUISRwAAAPE"]
[Thu Jul 30 13:45:49.613324 2026] [core:notice] [pid 935860:tid 935914] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:49.625804 2026] [security2:error] [pid 935860:tid 935959] [remote 103.164.173.46:55464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.173.164.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amub3YijB6THqIZZsUISUwAA_WE"]
[Thu Jul 30 13:45:49.810129 2026] [security2:error] [pid 935860:tid 936034] [client 172.202.44.182:49326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/edit.php"] [unique_id "amub3YijB6THqIZZsUISVwAAALA"]
[Thu Jul 30 13:45:49.822415 2026] [security2:error] [pid 935860:tid 935923] [remote 216.73.217.142:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amub3YijB6THqIZZsUISWAAAuD0"]
[Thu Jul 30 13:45:49.959077 2026] [security2:error] [pid 935860:tid 936072] [client 20.171.55.167:10119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/wp-activate.php"] [unique_id "amub3YijB6THqIZZsUISXwAAANY"]
[Thu Jul 30 13:45:50.512999 2026] [security2:error] [pid 935860:tid 936030] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amub3YijB6THqIZZsUISXAAAAKw"]
[Thu Jul 30 13:45:50.646585 2026] [security2:error] [pid 935860:tid 936007] [client 78.167.1.90:55491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub3oijB6THqIZZsUIScAAAAJU"]
[Thu Jul 30 13:45:50.646714 2026] [security2:error] [pid 935860:tid 936007] [client 78.167.1.90:55491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub3oijB6THqIZZsUIScAAAAJU"]
[Thu Jul 30 13:45:50.702943 2026] [security2:error] [pid 935860:tid 936065] [client 20.171.55.167:10151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/makeasmtp.php"] [unique_id "amub3oijB6THqIZZsUIScQAAAM8"]
[Thu Jul 30 13:45:50.827016 2026] [security2:error] [pid 935860:tid 935910] [remote 216.73.217.142:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amub3oijB6THqIZZsUISdgAA6jA"]
[Thu Jul 30 13:45:50.884813 2026] [security2:error] [pid 935860:tid 936107] [client 103.190.40.154:19102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub3oijB6THqIZZsUISdwAAAPk"]
[Thu Jul 30 13:45:50.884947 2026] [security2:error] [pid 935860:tid 936107] [client 103.190.40.154:19102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub3oijB6THqIZZsUISdwAAAPk"]
[Thu Jul 30 13:45:51.082756 2026] [proxy:error] [pid 935860:tid 936036] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:51.082819 2026] [proxy_http:error] [pid 935860:tid 936036] [client 172.202.44.182:49734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:51.083401 2026] [proxy:error] [pid 935860:tid 936036] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:51.083448 2026] [proxy_http:error] [pid 935860:tid 936036] [client 172.202.44.182:49734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:51.358249 2026] [security2:error] [pid 935860:tid 936016] [client 74.7.175.157:47556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.xyh.udi.temporary.site"] [uri "/index.php"] [unique_id "amub3oijB6THqIZZsUISdQAAnio"]
[Thu Jul 30 13:45:51.433417 2026] [security2:error] [pid 935860:tid 936017] [client 20.171.55.167:9879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/user/index.php"] [unique_id "amub34ijB6THqIZZsUISgwAAAJ8"]
[Thu Jul 30 13:45:52.138940 2026] [security2:error] [pid 935860:tid 936006] [client 20.171.55.167:9867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/link.php"] [unique_id "amub4IijB6THqIZZsUISmQAAAJQ"]
[Thu Jul 30 13:45:52.223466 2026] [security2:error] [pid 935860:tid 936029] [client 181.116.200.68:34422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub34ijB6THqIZZsUISkQAAAKs"]
[Thu Jul 30 13:45:52.223594 2026] [security2:error] [pid 935860:tid 936029] [client 181.116.200.68:34422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub34ijB6THqIZZsUISkQAAAKs"]
[Thu Jul 30 13:45:52.301816 2026] [security2:error] [pid 935860:tid 936094] [client 172.202.44.182:4584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/3.php"] [unique_id "amub4IijB6THqIZZsUISoQAAAOw"]
[Thu Jul 30 13:45:52.330660 2026] [security2:error] [pid 935860:tid 935895] [remote 216.73.217.142:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amub4IijB6THqIZZsUISowAA0SE"]
[Thu Jul 30 13:45:52.857311 2026] [security2:error] [pid 935860:tid 936086] [client 20.171.55.167:9869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amub4IijB6THqIZZsUISrwAAAOQ"]
[Thu Jul 30 13:45:53.540557 2026] [proxy:error] [pid 935860:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:53.540663 2026] [proxy_http:error] [pid 935860:tid 935995] [client 172.202.44.182:49964] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:53.541846 2026] [proxy:error] [pid 935860:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:53.541895 2026] [proxy_http:error] [pid 935860:tid 935995] [client 172.202.44.182:49964] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:53.565673 2026] [security2:error] [pid 935860:tid 936056] [client 20.171.55.167:9903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/themes.php"] [unique_id "amub4YijB6THqIZZsUISxQAAAMY"]
[Thu Jul 30 13:45:53.874900 2026] [security2:error] [pid 935860:tid 936031] [client 172.202.44.182:27715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/222.php"] [unique_id "amub4YijB6THqIZZsUIS1gAAAK0"]
[Thu Jul 30 13:45:54.305486 2026] [security2:error] [pid 935860:tid 936101] [client 20.171.55.167:10118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/themes/admin.php"] [unique_id "amub4oijB6THqIZZsUIS4AAAAPM"]
[Thu Jul 30 13:45:54.456367 2026] [security2:error] [pid 935860:tid 935998] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amub4YijB6THqIZZsUIS1QAAAIw"]
[Thu Jul 30 13:45:54.789922 2026] [security2:error] [pid 935860:tid 936118] [client 172.202.44.182:49303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/sf.php"] [unique_id "amub4oijB6THqIZZsUIS6wAAAQQ"]
[Thu Jul 30 13:45:55.033139 2026] [security2:error] [pid 935860:tid 936093] [client 20.171.55.167:9430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amub44ijB6THqIZZsUIS8wAAAOs"]
[Thu Jul 30 13:45:55.140102 2026] [security2:error] [pid 935860:tid 936046] [client 172.202.44.182:36120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-admin/images/admin.php"] [unique_id "amub44ijB6THqIZZsUIS9QAAALw"]
[Thu Jul 30 13:45:55.748966 2026] [security2:error] [pid 935860:tid 936102] [client 20.171.55.167:9440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/function.php"] [unique_id "amub44ijB6THqIZZsUITBAAAAPQ"]
[Thu Jul 30 13:45:56.166679 2026] [core:notice] [pid 935860:tid 936085] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:56.290581 2026] [security2:error] [pid 935860:tid 936048] [client 172.202.44.182:27813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amub5IijB6THqIZZsUITEAAAAL4"]
[Thu Jul 30 13:45:56.897220 2026] [security2:error] [pid 935860:tid 936039] [client 20.171.55.167:10166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/images/wp-login.php"] [unique_id "amub5IijB6THqIZZsUITHQAAALU"]
[Thu Jul 30 13:45:56.970525 2026] [proxy:error] [pid 935860:tid 936069] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:56.970607 2026] [proxy_http:error] [pid 935860:tid 936069] [client 172.202.44.182:49671] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:56.971179 2026] [proxy:error] [pid 935860:tid 936069] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:45:56.971224 2026] [proxy_http:error] [pid 935860:tid 936069] [client 172.202.44.182:49671] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:45:57.200451 2026] [autoindex:error] [pid 935860:tid 936095] [client 172.202.44.182:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_d35de2e9/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:45:57.473107 2026] [security2:error] [pid 935860:tid 935995] [client 172.202.44.182:26054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-content/admin.php"] [unique_id "amub5YijB6THqIZZsUITLQAAAIk"]
[Thu Jul 30 13:45:57.663379 2026] [core:notice] [pid 935860:tid 936011] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:45:57.668561 2026] [security2:error] [pid 935860:tid 936011] [client 66.249.79.8:63679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/citationstylelanguage/get/chicago-author-date"] [unique_id "amub5YijB6THqIZZsUITLAAAAJk"]
[Thu Jul 30 13:45:57.743225 2026] [security2:error] [pid 935860:tid 936103] [client 20.171.55.167:10123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/log.php"] [unique_id "amub5YijB6THqIZZsUITMQAAAPU"]
[Thu Jul 30 13:45:58.444443 2026] [security2:error] [pid 935860:tid 936007] [client 172.202.44.182:36143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-configs.php"] [unique_id "amub5oijB6THqIZZsUITQQAAAJU"]
[Thu Jul 30 13:45:58.480545 2026] [security2:error] [pid 935860:tid 936022] [client 20.171.55.167:9880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/wp-signup.php"] [unique_id "amub5oijB6THqIZZsUITRAAAAKQ"]
[Thu Jul 30 13:45:58.547225 2026] [security2:error] [pid 935860:tid 936073] [client 103.242.199.184:59138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub5oijB6THqIZZsUITRQAAANc"]
[Thu Jul 30 13:45:58.547347 2026] [security2:error] [pid 935860:tid 936073] [client 103.242.199.184:59138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub5oijB6THqIZZsUITRQAAANc"]
[Thu Jul 30 13:45:58.917331 2026] [security2:error] [pid 935860:tid 935993] [client 103.231.161.192:48102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub5oijB6THqIZZsUITSQAAAIc"], referer: http://pkf.jo
[Thu Jul 30 13:45:59.187815 2026] [security2:error] [pid 935860:tid 936084] [client 20.171.55.167:9916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/themes/themes.php"] [unique_id "amub54ijB6THqIZZsUITVAAAAOI"]
[Thu Jul 30 13:45:59.412382 2026] [security2:error] [pid 935860:tid 936058] [client 188.163.26.5:23660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub54ijB6THqIZZsUITUgAAAMg"], referer: http://pkf.jo
[Thu Jul 30 13:45:59.554053 2026] [security2:error] [pid 935860:tid 936036] [client 190.154.123.161:42663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub54ijB6THqIZZsUITVwAAALI"], referer: http://pkf.jo
[Thu Jul 30 13:45:59.764166 2026] [security2:error] [pid 935860:tid 936088] [client 172.202.44.182:59146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wso.php"] [unique_id "amub54ijB6THqIZZsUITYQAAAOY"]
[Thu Jul 30 13:45:59.909312 2026] [security2:error] [pid 935860:tid 936027] [client 20.171.55.167:10137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/radio.php"] [unique_id "amub54ijB6THqIZZsUITYwAAAKk"]
[Thu Jul 30 13:46:00.148852 2026] [security2:error] [pid 935860:tid 935983] [remote 57.141.0.66:41928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amub6IijB6THqIZZsUITawAAuHk"]
[Thu Jul 30 13:46:00.163968 2026] [security2:error] [pid 935860:tid 936116] [client 78.167.1.90:57218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub6IijB6THqIZZsUITbAAAAQI"]
[Thu Jul 30 13:46:00.164765 2026] [security2:error] [pid 935860:tid 936116] [client 78.167.1.90:57218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub6IijB6THqIZZsUITbAAAAQI"]
[Thu Jul 30 13:46:00.283890 2026] [security2:error] [pid 935860:tid 935945] [remote 57.141.0.15:57160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amub6IijB6THqIZZsUITbwAAlVM"]
[Thu Jul 30 13:46:00.624696 2026] [security2:error] [pid 935860:tid 936026] [client 20.171.55.167:9914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-mail.php"] [unique_id "amub6IijB6THqIZZsUITdwAAAKg"]
[Thu Jul 30 13:46:00.998187 2026] [security2:error] [pid 935860:tid 935971] [remote 47.128.96.146:14300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/4907"] [unique_id "amub6IijB6THqIZZsUITeAAAy20"]
[Thu Jul 30 13:46:01.036361 2026] [security2:error] [pid 935860:tid 936109] [client 172.202.44.182:26220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/ioxi-o.php"] [unique_id "amub6YijB6THqIZZsUITgAAAAPs"]
[Thu Jul 30 13:46:01.066928 2026] [core:notice] [pid 935860:tid 935903] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:01.072287 2026] [security2:error] [pid 935860:tid 936111] [client 47.128.96.146:14300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/4907"] [unique_id "amub6YijB6THqIZZsUITgwAA_Sk"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:46:01.227232 2026] [core:notice] [pid 935860:tid 935946] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:01.311415 2026] [core:notice] [pid 935860:tid 935870] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:01.312134 2026] [core:notice] [pid 935860:tid 935925] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:01.359398 2026] [security2:error] [pid 935860:tid 936062] [client 20.171.55.167:9425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amub6YijB6THqIZZsUITjQAAAMw"]
[Thu Jul 30 13:46:01.800097 2026] [security2:error] [pid 935860:tid 936034] [client 103.190.40.154:22531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub6YijB6THqIZZsUITlwAAALA"]
[Thu Jul 30 13:46:01.800240 2026] [security2:error] [pid 935860:tid 936034] [client 103.190.40.154:22531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub6YijB6THqIZZsUITlwAAALA"]
[Thu Jul 30 13:46:02.069255 2026] [security2:error] [pid 935860:tid 936041] [client 20.171.55.167:9859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/admin.php"] [unique_id "amub6oijB6THqIZZsUITnwAAALc"]
[Thu Jul 30 13:46:02.184994 2026] [security2:error] [pid 935860:tid 936042] [client 172.202.44.182:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file56.php"] [unique_id "amub6oijB6THqIZZsUITpQAAALg"]
[Thu Jul 30 13:46:02.228655 2026] [security2:error] [pid 935860:tid 936005] [client 119.73.97.132:29491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/wp-admin/post.php"] [unique_id "amub6YijB6THqIZZsUITkQAAk1w"], referer: https://www.urwru.club/wp-admin/post.php?post=1079&action=edit
[Thu Jul 30 13:46:02.394228 2026] [security2:error] [pid 935860:tid 936117] [client 206.84.95.164:51076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub6oijB6THqIZZsUIToAAAAQM"], referer: http://pkf.jo
[Thu Jul 30 13:46:02.433264 2026] [security2:error] [pid 935860:tid 936026] [client 181.116.200.68:44797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub6oijB6THqIZZsUITqgAAAKg"]
[Thu Jul 30 13:46:02.433372 2026] [security2:error] [pid 935860:tid 936026] [client 181.116.200.68:44797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub6oijB6THqIZZsUITqgAAAKg"]
[Thu Jul 30 13:46:02.791096 2026] [security2:error] [pid 935860:tid 936004] [client 20.40.58.237:55945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amub6oijB6THqIZZsUITsgAAAJI"]
[Thu Jul 30 13:46:02.792154 2026] [security2:error] [pid 935860:tid 936024] [client 20.171.55.167:9882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/wp-login.php"] [unique_id "amub6oijB6THqIZZsUITswAAAKY"]
[Thu Jul 30 13:46:03.111821 2026] [security2:error] [pid 935860:tid 936051] [client 41.82.19.115:52484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub6oijB6THqIZZsUITtAAAAME"], referer: http://pkf.jo
[Thu Jul 30 13:46:03.517210 2026] [security2:error] [pid 935860:tid 936073] [client 20.171.55.167:9877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-links-opml.php"] [unique_id "amub64ijB6THqIZZsUITxAAAANc"]
[Thu Jul 30 13:46:04.185158 2026] [security2:error] [pid 935860:tid 936076] [client 172.202.44.182:26233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amub7IijB6THqIZZsUIT0gAAANo"]
[Thu Jul 30 13:46:04.198276 2026] [core:notice] [pid 935860:tid 936040] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:04.236279 2026] [security2:error] [pid 935860:tid 936005] [client 20.171.55.167:10114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/acme-challenge/radio.php"] [unique_id "amub7IijB6THqIZZsUIT1gAAAJM"]
[Thu Jul 30 13:46:04.336320 2026] [core:notice] [pid 935860:tid 936075] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:04.424576 2026] [security2:error] [pid 935860:tid 936029] [client 204.8.98.105:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amub7IijB6THqIZZsUIT2wAAAKs"]
[Thu Jul 30 13:46:04.424679 2026] [security2:error] [pid 935860:tid 936029] [client 204.8.98.105:51626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amub7IijB6THqIZZsUIT2wAAAKs"]
[Thu Jul 30 13:46:04.541776 2026] [autoindex:error] [pid 935860:tid 936099] [client 124.221.140.98:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:46:04.833615 2026] [core:notice] [pid 935860:tid 936013] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:04.979928 2026] [security2:error] [pid 935860:tid 936101] [client 20.171.55.167:9453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/images/file.php"] [unique_id "amub7IijB6THqIZZsUIT7wAAAPM"]
[Thu Jul 30 13:46:05.176757 2026] [security2:error] [pid 935860:tid 936116] [client 172.202.44.182:26178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-admin/css/index.php"] [unique_id "amub7YijB6THqIZZsUIT9gAAAQI"]
[Thu Jul 30 13:46:05.703049 2026] [security2:error] [pid 935860:tid 936100] [client 20.171.55.167:9892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/upgrade/function.php"] [unique_id "amub7YijB6THqIZZsUIUBwAAAPI"]
[Thu Jul 30 13:46:05.794945 2026] [security2:error] [pid 935860:tid 936035] [client 17.22.253.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amub7IijB6THqIZZsUIT7AAAALE"]
[Thu Jul 30 13:46:05.842172 2026] [security2:error] [pid 935860:tid 936045] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amub7YijB6THqIZZsUIT-QAAALs"]
[Thu Jul 30 13:46:06.152915 2026] [security2:error] [pid 935860:tid 936028] [client 172.202.44.182:49897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/edit.php"] [unique_id "amub7oijB6THqIZZsUIUEQAAAKo"]
[Thu Jul 30 13:46:06.822749 2026] [security2:error] [pid 935860:tid 936078] [client 172.202.44.182:26078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/php.php"] [unique_id "amub7oijB6THqIZZsUIUHgAAANw"]
[Thu Jul 30 13:46:06.827488 2026] [security2:error] [pid 935860:tid 936043] [client 20.171.55.167:10168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/user/themes.php"] [unique_id "amub7oijB6THqIZZsUIUHwAAALk"]
[Thu Jul 30 13:46:07.696427 2026] [security2:error] [pid 935860:tid 936096] [client 20.171.55.167:9883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/radio.php"] [unique_id "amub74ijB6THqIZZsUIUQAAAAO4"]
[Thu Jul 30 13:46:07.784281 2026] [security2:error] [pid 935860:tid 936104] [client 172.202.44.182:4550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-includes/index.php"] [unique_id "amub74ijB6THqIZZsUIUQgAAAPY"]
[Thu Jul 30 13:46:08.108151 2026] [security2:error] [pid 935860:tid 936059] [client 172.202.44.182:49914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/2.php"] [unique_id "amub8IijB6THqIZZsUIUTAAAAMk"]
[Thu Jul 30 13:46:08.174237 2026] [security2:error] [pid 935860:tid 936109] [client 105.196.69.188:46530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub74ijB6THqIZZsUIURgAAAPs"], referer: http://pkf.jo
[Thu Jul 30 13:46:08.347839 2026] [security2:error] [pid 935860:tid 936054] [client 78.182.147.133:55112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub74ijB6THqIZZsUIUSgAAAMQ"], referer: http://pkf.jo
[Thu Jul 30 13:46:08.434138 2026] [security2:error] [pid 935860:tid 936079] [client 20.171.55.167:9913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/license.php"] [unique_id "amub8IijB6THqIZZsUIUVgAAAN0"]
[Thu Jul 30 13:46:08.567452 2026] [security2:error] [pid 935860:tid 936094] [client 196.189.56.25:10113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub8IijB6THqIZZsUIUUQAAAOw"], referer: http://pkf.jo
[Thu Jul 30 13:46:08.773488 2026] [core:notice] [pid 935860:tid 936044] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:09.154479 2026] [security2:error] [pid 935860:tid 936057] [client 103.242.199.184:59960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub8YijB6THqIZZsUIUZAAAAMc"]
[Thu Jul 30 13:46:09.154634 2026] [security2:error] [pid 935860:tid 936057] [client 103.242.199.184:59960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub8YijB6THqIZZsUIUZAAAAMc"]
[Thu Jul 30 13:46:09.161205 2026] [security2:error] [pid 935860:tid 936101] [client 20.171.55.167:10170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/pki-validation/wp-config.php"] [unique_id "amub8YijB6THqIZZsUIUZgAAAPM"]
[Thu Jul 30 13:46:09.227928 2026] [security2:error] [pid 935860:tid 936027] [client 38.25.18.119:8203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub8IijB6THqIZZsUIUUgAAAKk"], referer: http://pkf.jo
[Thu Jul 30 13:46:09.360021 2026] [core:notice] [pid 935860:tid 936038] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:09.527661 2026] [security2:error] [pid 935860:tid 936080] [client 200.202.100.158:60732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub8YijB6THqIZZsUIUZQAAAN4"], referer: http://pkf.jo
[Thu Jul 30 13:46:09.592951 2026] [security2:error] [pid 935860:tid 936062] [client 172.202.44.182:4563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-admin/a.php"] [unique_id "amub8YijB6THqIZZsUIUdAAAAMw"]
[Thu Jul 30 13:46:09.727137 2026] [core:error] [pid 935860:tid 935978] [remote 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:46:09.727158 2026] [core:error] [pid 935860:tid 935978] [remote 138.246.253.24:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:46:09.887564 2026] [security2:error] [pid 935860:tid 936107] [client 104.191.86.187:40557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub8YijB6THqIZZsUIUdQAAAPk"], referer: http://pkf.jo
[Thu Jul 30 13:46:09.902471 2026] [security2:error] [pid 935860:tid 936016] [client 20.171.55.167:10159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/radio.php"] [unique_id "amub8YijB6THqIZZsUIUfwAAAJ4"]
[Thu Jul 30 13:46:10.261214 2026] [security2:error] [pid 935860:tid 935995] [client 119.73.97.132:29549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amub74ijB6THqIZZsUIUQQAAiU0"], referer: https://trello.com/
[Thu Jul 30 13:46:10.382788 2026] [security2:error] [pid 935860:tid 935912] [remote 57.141.0.48:30576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amub8oijB6THqIZZsUIUiQAAmDI"]
[Thu Jul 30 13:46:10.629033 2026] [security2:error] [pid 935860:tid 936011] [client 20.171.55.167:9881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/plugins/about.php"] [unique_id "amub8oijB6THqIZZsUIUkgAAAJk"]
[Thu Jul 30 13:46:10.716891 2026] [security2:error] [pid 935860:tid 936066] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amub8oijB6THqIZZsUIUhQAA0Go"]
[Thu Jul 30 13:46:10.871930 2026] [security2:error] [pid 935860:tid 936081] [client 95.26.44.20:1838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub8oijB6THqIZZsUIUkQAAAN8"], referer: http://pkf.jo
[Thu Jul 30 13:46:10.926355 2026] [security2:error] [pid 935860:tid 936054] [client 78.167.1.90:53627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub8oijB6THqIZZsUIUlwAAAMQ"]
[Thu Jul 30 13:46:10.927154 2026] [security2:error] [pid 935860:tid 936054] [client 78.167.1.90:53627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub8oijB6THqIZZsUIUlwAAAMQ"]
[Thu Jul 30 13:46:11.025165 2026] [security2:error] [pid 935860:tid 936044] [client 20.125.96.254:7562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amub84ijB6THqIZZsUIUnQAAALo"]
[Thu Jul 30 13:46:11.025267 2026] [security2:error] [pid 935860:tid 936044] [client 20.125.96.254:7562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amub84ijB6THqIZZsUIUnQAAALo"]
[Thu Jul 30 13:46:11.365173 2026] [security2:error] [pid 935860:tid 936105] [client 20.171.55.167:9862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amub84ijB6THqIZZsUIUpwAAAPc"]
[Thu Jul 30 13:46:11.384082 2026] [autoindex:error] [pid 935860:tid 936116] [client 172.202.44.182:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_d35de2e9/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:46:11.724938 2026] [autoindex:error] [pid 935860:tid 936017] [client 172.202.44.182:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_d35de2e9/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:46:11.726913 2026] [security2:error] [pid 935860:tid 936038] [client 172.202.44.182:49879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amub84ijB6THqIZZsUIUtwAAALQ"]
[Thu Jul 30 13:46:11.759138 2026] [core:notice] [pid 935860:tid 935986] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:11.762429 2026] [security2:error] [pid 935860:tid 936064] [client 74.7.175.176:35234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-2258ef87.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amub84ijB6THqIZZsUIUuAAAznw"]
[Thu Jul 30 13:46:11.790245 2026] [security2:error] [pid 935860:tid 936095] [client 1.10.219.54:41062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub84ijB6THqIZZsUIUrgAAAO0"], referer: http://pkf.jo
[Thu Jul 30 13:46:12.004930 2026] [security2:error] [pid 935860:tid 936025] [client 172.202.44.182:36129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-includes/Text/about.php"] [unique_id "amub9IijB6THqIZZsUIU5AAAAKc"]
[Thu Jul 30 13:46:12.085202 2026] [security2:error] [pid 935860:tid 936070] [client 20.171.55.167:9429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/wp-login.php"] [unique_id "amub9IijB6THqIZZsUIU6AAAANQ"]
[Thu Jul 30 13:46:12.484315 2026] [security2:error] [pid 935860:tid 936026] [client 103.190.40.154:21937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub9IijB6THqIZZsUIU8gAAAKg"]
[Thu Jul 30 13:46:12.484446 2026] [security2:error] [pid 935860:tid 936026] [client 103.190.40.154:21937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub9IijB6THqIZZsUIU8gAAAKg"]
[Thu Jul 30 13:46:12.577786 2026] [core:notice] [pid 935860:tid 935898] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:12.660261 2026] [security2:error] [pid 935860:tid 936087] [client 74.7.244.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.jto.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "amub9IijB6THqIZZsUIVEQAAAOU"]
[Thu Jul 30 13:46:12.660909 2026] [security2:error] [pid 935860:tid 936004] [client 74.7.244.54:41562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.jto.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amub9IijB6THqIZZsUIVDwAAkkE"]
[Thu Jul 30 13:46:12.731946 2026] [security2:error] [pid 935860:tid 935919] [remote 74.7.227.39:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amub9IijB6THqIZZsUIVFQAA5zk"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 13:46:12.855808 2026] [security2:error] [pid 935860:tid 936006] [client 20.171.55.167:9864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/wp-load.php"] [unique_id "amub9IijB6THqIZZsUIVFgAAAJQ"]
[Thu Jul 30 13:46:13.023150 2026] [security2:error] [pid 935860:tid 936114] [client 181.116.200.68:35988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub9YijB6THqIZZsUIVGAAAAQA"]
[Thu Jul 30 13:46:13.023311 2026] [security2:error] [pid 935860:tid 936114] [client 181.116.200.68:35988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub9YijB6THqIZZsUIVGAAAAQA"]
[Thu Jul 30 13:46:13.326709 2026] [security2:error] [pid 935860:tid 936094] [client 108.49.232.104:58616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub9IijB6THqIZZsUIVFwAAAOw"], referer: http://pkf.jo
[Thu Jul 30 13:46:13.392761 2026] [security2:error] [pid 935860:tid 936067] [client 164.163.49.56:28909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amub9YijB6THqIZZsUIVGwAAANE"], referer: http://pkf.jo
[Thu Jul 30 13:46:13.435141 2026] [security2:error] [pid 935860:tid 936065] [client 172.202.44.182:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-admin.php"] [unique_id "amub9YijB6THqIZZsUIVKgAAAM8"]
[Thu Jul 30 13:46:13.589139 2026] [security2:error] [pid 935860:tid 936118] [client 20.171.55.167:9917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/file.php"] [unique_id "amub9YijB6THqIZZsUIVNAAAAQQ"]
[Thu Jul 30 13:46:13.765458 2026] [security2:error] [pid 935860:tid 936051] [client 172.202.44.182:49871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/mah.php"] [unique_id "amub9YijB6THqIZZsUIVOQAAAME"]
[Thu Jul 30 13:46:14.188687 2026] [security2:error] [pid 935860:tid 936096] [client 119.73.97.132:29569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amub9oijB6THqIZZsUIVOgAA7lE"], referer: https://www.urwru.club/
[Thu Jul 30 13:46:14.347193 2026] [security2:error] [pid 935860:tid 936019] [client 20.171.55.167:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/dropdown.php"] [unique_id "amub9oijB6THqIZZsUIVRQAAAKE"]
[Thu Jul 30 13:46:15.048453 2026] [security2:error] [pid 935860:tid 936104] [client 172.202.44.182:27671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/size.php"] [unique_id "amub94ijB6THqIZZsUIVUAAAAPY"]
[Thu Jul 30 13:46:15.063714 2026] [security2:error] [pid 935860:tid 936037] [client 20.171.55.167:9898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/plugins/dropdown.php"] [unique_id "amub94ijB6THqIZZsUIVUQAAALM"]
[Thu Jul 30 13:46:15.312490 2026] [security2:error] [pid 935860:tid 935947] [remote 216.73.217.142:4392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amub94ijB6THqIZZsUIVXAAAhlU"]
[Thu Jul 30 13:46:15.569167 2026] [security2:error] [pid 935860:tid 936000] [client 20.125.96.254:5809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amub94ijB6THqIZZsUIVYQAAAI4"]
[Thu Jul 30 13:46:15.569276 2026] [security2:error] [pid 935860:tid 936000] [client 20.125.96.254:5809] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amub94ijB6THqIZZsUIVYQAAAI4"]
[Thu Jul 30 13:46:15.731608 2026] [proxy:error] [pid 935860:tid 935930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:15.731667 2026] [proxy_http:error] [pid 935860:tid 935930] [remote 74.7.175.168:59118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:15.732288 2026] [proxy:error] [pid 935860:tid 935930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:15.732336 2026] [proxy_http:error] [pid 935860:tid 935930] [remote 74.7.175.168:59118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:15.788150 2026] [security2:error] [pid 935860:tid 936084] [client 20.171.55.167:9424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/includes/index.php"] [unique_id "amub94ijB6THqIZZsUIVaQAAAOI"]
[Thu Jul 30 13:46:15.811523 2026] [proxy:error] [pid 935860:tid 936117] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:15.811595 2026] [proxy_http:error] [pid 935860:tid 936117] [client 143.244.57.82:40094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:15.812176 2026] [proxy:error] [pid 935860:tid 936117] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:15.812230 2026] [proxy_http:error] [pid 935860:tid 936117] [client 143.244.57.82:40094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:16.092587 2026] [proxy:error] [pid 935860:tid 936096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:16.092648 2026] [proxy_http:error] [pid 935860:tid 936096] [client 143.244.57.82:40110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:16.093236 2026] [proxy:error] [pid 935860:tid 936096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:16.093282 2026] [proxy_http:error] [pid 935860:tid 936096] [client 143.244.57.82:40110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:16.256418 2026] [security2:error] [pid 935860:tid 936017] [client 172.202.44.182:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/send.php"] [unique_id "amub-IijB6THqIZZsUIVpwAAAJ8"]
[Thu Jul 30 13:46:16.376243 2026] [security2:error] [pid 935860:tid 936001] [client 143.244.57.82:40112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amub-IijB6THqIZZsUIVqAAAAI8"]
[Thu Jul 30 13:46:16.493592 2026] [core:notice] [pid 935860:tid 936114] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:16.561344 2026] [security2:error] [pid 935860:tid 936045] [client 172.202.44.182:40428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-includes/wp-class.php"] [unique_id "amub-IijB6THqIZZsUIVrwAAALs"]
[Thu Jul 30 13:46:16.583453 2026] [security2:error] [pid 935860:tid 936066] [client 20.171.55.167:9468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-signup.php"] [unique_id "amub-IijB6THqIZZsUIVsAAAANA"]
[Thu Jul 30 13:46:16.662894 2026] [security2:error] [pid 935860:tid 935991] [client 143.244.57.82:40120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amub-IijB6THqIZZsUIVtAAAAIU"]
[Thu Jul 30 13:46:16.949807 2026] [proxy:error] [pid 935860:tid 936079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:16.949891 2026] [proxy_http:error] [pid 935860:tid 936079] [client 143.244.57.82:38472] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:16.950467 2026] [proxy:error] [pid 935860:tid 936079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:16.950519 2026] [proxy_http:error] [pid 935860:tid 936079] [client 143.244.57.82:38472] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:17.228748 2026] [security2:error] [pid 935860:tid 936032] [client 143.244.57.82:38484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amub-YijB6THqIZZsUIVxAAAAK4"]
[Thu Jul 30 13:46:17.307778 2026] [security2:error] [pid 935860:tid 936072] [client 20.171.55.167:10141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/images/css.php"] [unique_id "amub-YijB6THqIZZsUIVxQAAANY"]
[Thu Jul 30 13:46:17.474122 2026] [security2:error] [pid 935860:tid 935996] [client 20.40.58.237:56503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amub-YijB6THqIZZsUIVygAAAIo"]
[Thu Jul 30 13:46:17.542628 2026] [security2:error] [pid 935860:tid 936118] [client 143.244.57.82:38490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amub-YijB6THqIZZsUIVzQAAAQQ"]
[Thu Jul 30 13:46:17.822270 2026] [security2:error] [pid 935860:tid 936058] [client 143.244.57.82:38492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amub-YijB6THqIZZsUIV1wAAAMg"]
[Thu Jul 30 13:46:18.062148 2026] [security2:error] [pid 935860:tid 936064] [client 20.171.55.167:10171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/chosen.php"] [unique_id "amub-oijB6THqIZZsUIV3wAAAM4"]
[Thu Jul 30 13:46:18.096562 2026] [security2:error] [pid 935860:tid 936096] [client 143.244.57.82:38502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amub-oijB6THqIZZsUIV4AAAAO4"]
[Thu Jul 30 13:46:18.171729 2026] [security2:error] [pid 935860:tid 936084] [client 172.202.44.182:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/403.php"] [unique_id "amub-oijB6THqIZZsUIV4QAAAOI"]
[Thu Jul 30 13:46:18.382361 2026] [security2:error] [pid 935860:tid 936089] [client 143.244.57.82:38514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amub-oijB6THqIZZsUIV6QAAAOc"]
[Thu Jul 30 13:46:18.665116 2026] [security2:error] [pid 935860:tid 936004] [client 143.244.57.82:38530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amub-oijB6THqIZZsUIV7QAAAJI"]
[Thu Jul 30 13:46:18.699173 2026] [security2:error] [pid 935860:tid 936114] [client 74.7.175.147:47838] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "erp.ajakholding.net"] [uri "/cgi-sys/404.html"] [unique_id "amub-oijB6THqIZZsUIV8QABACo"]
[Thu Jul 30 13:46:18.819925 2026] [security2:error] [pid 935860:tid 936054] [client 20.171.55.167:10117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/cong.php"] [unique_id "amub-oijB6THqIZZsUIV8gAAAMQ"]
[Thu Jul 30 13:46:18.891990 2026] [security2:error] [pid 935860:tid 936092] [client 172.202.44.182:49792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amub-oijB6THqIZZsUIV9gAAAOo"]
[Thu Jul 30 13:46:18.951580 2026] [security2:error] [pid 935860:tid 936027] [client 143.244.57.82:38534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amub-oijB6THqIZZsUIV9wAAAKk"]
[Thu Jul 30 13:46:19.252429 2026] [security2:error] [pid 935860:tid 935997] [client 143.244.57.82:38544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amub-4ijB6THqIZZsUIV_gAAAIs"]
[Thu Jul 30 13:46:19.321913 2026] [security2:error] [pid 935860:tid 936034] [client 172.202.44.182:26077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amub-4ijB6THqIZZsUIV_wAAALA"]
[Thu Jul 30 13:46:19.531994 2026] [security2:error] [pid 935860:tid 936056] [client 143.244.57.82:38550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amub-4ijB6THqIZZsUIWBAAAAMY"]
[Thu Jul 30 13:46:19.535989 2026] [security2:error] [pid 935860:tid 936046] [client 20.171.55.167:9863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/mah.php"] [unique_id "amub-4ijB6THqIZZsUIWBQAAALw"]
[Thu Jul 30 13:46:19.779735 2026] [security2:error] [pid 935860:tid 936055] [client 103.242.199.184:60591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub-4ijB6THqIZZsUIWDQAAAMU"]
[Thu Jul 30 13:46:19.779853 2026] [security2:error] [pid 935860:tid 936055] [client 103.242.199.184:60591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amub-4ijB6THqIZZsUIWDQAAAMU"]
[Thu Jul 30 13:46:19.809597 2026] [security2:error] [pid 935860:tid 936100] [client 143.244.57.82:38558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amub-4ijB6THqIZZsUIWDgAAAPI"]
[Thu Jul 30 13:46:19.940904 2026] [proxy:error] [pid 935860:tid 936035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:19.940972 2026] [proxy_http:error] [pid 935860:tid 936035] [client 172.202.44.182:49868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:19.941734 2026] [proxy:error] [pid 935860:tid 936035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:46:19.941779 2026] [proxy_http:error] [pid 935860:tid 936035] [client 172.202.44.182:49868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:46:20.086381 2026] [security2:error] [pid 935860:tid 936065] [client 216.24.212.16:58435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amub-4ijB6THqIZZsUIWDAAAAM8"], referer: https://cnpinyin.com/login/?redirect_to=https%3A%2F%2Fcnpinyin.com
[Thu Jul 30 13:46:20.097644 2026] [security2:error] [pid 935860:tid 936088] [client 143.244.57.82:38566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amub_IijB6THqIZZsUIWGQAAAOY"]
[Thu Jul 30 13:46:20.249191 2026] [security2:error] [pid 935860:tid 935994] [client 20.171.55.167:10164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amub_IijB6THqIZZsUIWHAAAAIg"]
[Thu Jul 30 13:46:20.381053 2026] [security2:error] [pid 935860:tid 936114] [client 143.244.57.82:38574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amub_IijB6THqIZZsUIWIAAAAQA"]
[Thu Jul 30 13:46:20.665369 2026] [security2:error] [pid 935860:tid 936063] [client 143.244.57.82:38586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amub_IijB6THqIZZsUIWKAAAAM0"]
[Thu Jul 30 13:46:20.705799 2026] [security2:error] [pid 935860:tid 936066] [client 172.202.44.182:27652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/as.php"] [unique_id "amub_IijB6THqIZZsUIWKgAAANA"]
[Thu Jul 30 13:46:20.941266 2026] [security2:error] [pid 935860:tid 936072] [client 143.244.57.82:38594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amub_IijB6THqIZZsUIWNwAAANY"]
[Thu Jul 30 13:46:20.967804 2026] [security2:error] [pid 935860:tid 936032] [client 20.125.96.254:7553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/bootstrap.php"] [unique_id "amub_IijB6THqIZZsUIWOAAAAK4"]
[Thu Jul 30 13:46:20.967902 2026] [security2:error] [pid 935860:tid 936032] [client 20.125.96.254:7553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/bootstrap.php"] [unique_id "amub_IijB6THqIZZsUIWOAAAAK4"]
[Thu Jul 30 13:46:21.227520 2026] [security2:error] [pid 935860:tid 936117] [client 143.244.57.82:38606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.qgb.djb.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amub_YijB6THqIZZsUIWQQAAAQM"]
[Thu Jul 30 13:46:21.367454 2026] [security2:error] [pid 935860:tid 936058] [client 78.167.1.90:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub_YijB6THqIZZsUIWRQAAAMg"]
[Thu Jul 30 13:46:21.367888 2026] [security2:error] [pid 935860:tid 936058] [client 78.167.1.90:54042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub_YijB6THqIZZsUIWRQAAAMg"]
[Thu Jul 30 13:46:21.393651 2026] [security2:error] [pid 935860:tid 936003] [client 20.171.55.167:10160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/ova-tools.php"] [unique_id "amub_YijB6THqIZZsUIWRgAAAJE"]
[Thu Jul 30 13:46:21.563559 2026] [core:notice] [pid 935860:tid 935995] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:22.092142 2026] [security2:error] [pid 935860:tid 936065] [client 20.171.55.167:10158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/Requests/about.php"] [unique_id "amub_oijB6THqIZZsUIWhwAAAM8"]
[Thu Jul 30 13:46:22.195860 2026] [core:notice] [pid 935860:tid 936016] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:22.354622 2026] [autoindex:error] [pid 935860:tid 936021] [client 52.202.41.153:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:46:22.354870 2026] [autoindex:error] [pid 935860:tid 936086] [client 54.87.222.253:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:46:22.646601 2026] [security2:error] [pid 935860:tid 936022] [client 172.202.44.182:26050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-admin/includes/index.php"] [unique_id "amub_oijB6THqIZZsUIWngAAAKQ"]
[Thu Jul 30 13:46:22.850585 2026] [security2:error] [pid 935860:tid 936027] [client 20.171.55.167:9896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amub_oijB6THqIZZsUIWowAAAKk"]
[Thu Jul 30 13:46:23.263832 2026] [security2:error] [pid 935860:tid 935996] [client 103.190.40.154:22575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub_4ijB6THqIZZsUIWrwAAAIo"]
[Thu Jul 30 13:46:23.264002 2026] [security2:error] [pid 935860:tid 935996] [client 103.190.40.154:22575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amub_4ijB6THqIZZsUIWrwAAAIo"]
[Thu Jul 30 13:46:23.575733 2026] [security2:error] [pid 935860:tid 936095] [client 181.116.200.68:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub_4ijB6THqIZZsUIWtgAAAO0"]
[Thu Jul 30 13:46:23.575843 2026] [security2:error] [pid 935860:tid 936095] [client 181.116.200.68:59496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amub_4ijB6THqIZZsUIWtgAAAO0"]
[Thu Jul 30 13:46:23.584730 2026] [security2:error] [pid 935860:tid 936074] [client 20.171.55.167:10142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amub_4ijB6THqIZZsUIWtwAAANg"]
[Thu Jul 30 13:46:23.749742 2026] [security2:error] [pid 935860:tid 936091] [client 172.202.44.182:40392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amub_4ijB6THqIZZsUIWuwAAAOk"]
[Thu Jul 30 13:46:23.964310 2026] [security2:error] [pid 935860:tid 936089] [client 216.24.212.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amub_4ijB6THqIZZsUIWvgAAAOc"], referer: https://cnpinyin.com/edit-profile
[Thu Jul 30 13:46:24.057784 2026] [core:notice] [pid 935860:tid 936038] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:24.292609 2026] [security2:error] [pid 935860:tid 936005] [client 20.171.55.167:9415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amucAIijB6THqIZZsUIW0QAAAJM"]
[Thu Jul 30 13:46:24.543850 2026] [core:notice] [pid 935860:tid 935993] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:24.831418 2026] [security2:error] [pid 935860:tid 935864] [remote 216.73.217.142:4392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amucAIijB6THqIZZsUIW3QAA9gI"]
[Thu Jul 30 13:46:24.857459 2026] [security2:error] [pid 935860:tid 936043] [client 172.202.44.182:40443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/plugins.php"] [unique_id "amucAIijB6THqIZZsUIW3wAAALk"]
[Thu Jul 30 13:46:24.994453 2026] [security2:error] [pid 935860:tid 936082] [client 20.171.55.167:10153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/banners/about.php"] [unique_id "amucAIijB6THqIZZsUIW6AAAAOA"]
[Thu Jul 30 13:46:25.099131 2026] [core:notice] [pid 935860:tid 936107] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:25.651296 2026] [security2:error] [pid 935860:tid 936015] [client 172.202.44.182:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/about.php"] [unique_id "amucAYijB6THqIZZsUIXAAAAAJ0"]
[Thu Jul 30 13:46:25.726782 2026] [security2:error] [pid 935860:tid 936084] [client 20.171.55.167:9876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/license.php"] [unique_id "amucAYijB6THqIZZsUIXAQAAAOI"]
[Thu Jul 30 13:46:26.113006 2026] [security2:error] [pid 935860:tid 936053] [client 172.202.44.182:27749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/wp-includes/js/index.php"] [unique_id "amucAoijB6THqIZZsUIXDQAAAMM"]
[Thu Jul 30 13:46:26.336070 2026] [security2:error] [pid 935860:tid 935998] [client 20.125.96.254:7992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/wp-blog-header.php"] [unique_id "amucAoijB6THqIZZsUIXEgAAAIw"]
[Thu Jul 30 13:46:26.336184 2026] [security2:error] [pid 935860:tid 935998] [client 20.125.96.254:7992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/wp-blog-header.php"] [unique_id "amucAoijB6THqIZZsUIXEgAAAIw"]
[Thu Jul 30 13:46:26.390669 2026] [security2:error] [pid 935860:tid 936097] [client 43.173.180.16:41770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/23/une-culotte-de-creatrice-a-gagner-avec-lemon-curve-ca-vous-dit/"] [unique_id "amucAoijB6THqIZZsUIXDgAAAO8"]
[Thu Jul 30 13:46:26.434039 2026] [security2:error] [pid 935860:tid 936006] [client 20.171.55.167:9421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/about.php"] [unique_id "amucAoijB6THqIZZsUIXFAAAAJQ"]
[Thu Jul 30 13:46:26.871676 2026] [core:notice] [pid 935860:tid 936027] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:26.877222 2026] [security2:error] [pid 935860:tid 936027] [client 43.172.197.6:36888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/23/une-culotte-de-creatrice-a-gagner-avec-lemon-curve-ca-vous-dit/"] [unique_id "amucAoijB6THqIZZsUIXJQAAAKk"], referer: https://carnetdeshopping.com/index.php/2012/03/23/une-culotte-de-creatrice-a-gagner-avec-lemon-curve-ca-vous-dit/
[Thu Jul 30 13:46:27.191954 2026] [security2:error] [pid 935860:tid 936033] [client 20.171.55.167:9543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/about.php"] [unique_id "amucA4ijB6THqIZZsUIXLAAAAK8"]
[Thu Jul 30 13:46:27.858417 2026] [security2:error] [pid 935860:tid 936100] [client 84.54.44.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amucA4ijB6THqIZZsUIXOgAAAPI"], referer: http://cnpinyin.com/experience/chinese-customs/the+famous+dragon+dance
[Thu Jul 30 13:46:27.904511 2026] [security2:error] [pid 935860:tid 936096] [client 20.171.55.167:9901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/Text/about.php"] [unique_id "amucA4ijB6THqIZZsUIXQQAAAO4"]
[Thu Jul 30 13:46:28.676987 2026] [security2:error] [pid 935860:tid 936097] [client 20.171.55.167:9558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/ID3/about.php"] [unique_id "amucBIijB6THqIZZsUIXWQAAAO8"]
[Thu Jul 30 13:46:28.956925 2026] [security2:error] [pid 935860:tid 936061] [client 172.202.44.182:49815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/options.php"] [unique_id "amucBIijB6THqIZZsUIXYAAAAMs"]
[Thu Jul 30 13:46:29.139912 2026] [core:notice] [pid 935860:tid 936076] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:29.343186 2026] [security2:error] [pid 935860:tid 936109] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucA4ijB6THqIZZsUIXQgAAAPs"]
[Thu Jul 30 13:46:29.388659 2026] [security2:error] [pid 935860:tid 936025] [client 20.171.55.167:10136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/img/about.php"] [unique_id "amucBYijB6THqIZZsUIXawAAAKc"]
[Thu Jul 30 13:46:29.561365 2026] [core:error] [pid 935860:tid 936115] [client 74.7.230.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:46:29.561391 2026] [core:error] [pid 935860:tid 936115] [client 74.7.230.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:46:29.561516 2026] [security2:error] [pid 935860:tid 936115] [client 74.7.230.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.zdn.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amucBYijB6THqIZZsUIXdgAAAQE"]
[Thu Jul 30 13:46:29.562145 2026] [security2:error] [pid 935860:tid 936042] [client 74.7.230.23:58194] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.zdn.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amucBYijB6THqIZZsUIXcwAAuD4"]
[Thu Jul 30 13:46:29.755044 2026] [security2:error] [pid 935860:tid 936002] [client 43.159.62.129:58816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.62.159.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bookario.com"] [uri "/book.php"] [unique_id "amucBYijB6THqIZZsUIXcgAAAJA"]
[Thu Jul 30 13:46:29.836730 2026] [security2:error] [pid 935860:tid 936058] [client 172.202.44.182:36877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-content/themes/index.php"] [unique_id "amucBYijB6THqIZZsUIXhAAAAMg"]
[Thu Jul 30 13:46:29.845058 2026] [security2:error] [pid 935860:tid 936065] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucBYijB6THqIZZsUIXgAAAAM8"]
[Thu Jul 30 13:46:30.086194 2026] [security2:error] [pid 935860:tid 936011] [client 20.171.55.167:10133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/languages/about.php"] [unique_id "amucBoijB6THqIZZsUIXjQAAAJk"]
[Thu Jul 30 13:46:30.098928 2026] [security2:error] [pid 935860:tid 936114] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucBYijB6THqIZZsUIXiAAAAQA"]
[Thu Jul 30 13:46:30.232796 2026] [security2:error] [pid 935860:tid 935992] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucBYijB6THqIZZsUIXeQAAhkk"]
[Thu Jul 30 13:46:30.308665 2026] [security2:error] [pid 935860:tid 936043] [client 20.125.96.254:3276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/wp-load.php"] [unique_id "amucBoijB6THqIZZsUIXlgAAALk"]
[Thu Jul 30 13:46:30.308768 2026] [security2:error] [pid 935860:tid 936043] [client 20.125.96.254:3276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/wp-load.php"] [unique_id "amucBoijB6THqIZZsUIXlgAAALk"]
[Thu Jul 30 13:46:30.341302 2026] [security2:error] [pid 935860:tid 936078] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucBoijB6THqIZZsUIXkQAAANw"]
[Thu Jul 30 13:46:30.437243 2026] [security2:error] [pid 935860:tid 936061] [client 103.242.199.184:61147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucBoijB6THqIZZsUIXlwAAAMs"]
[Thu Jul 30 13:46:30.437367 2026] [security2:error] [pid 935860:tid 936061] [client 103.242.199.184:61147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucBoijB6THqIZZsUIXlwAAAMs"]
[Thu Jul 30 13:46:30.474062 2026] [security2:error] [pid 935860:tid 936027] [client 185.177.72.22:29162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucBoijB6THqIZZsUIXmgAAAKk"]
[Thu Jul 30 13:46:30.524666 2026] [security2:error] [pid 935860:tid 935949] [remote 74.7.243.224:57508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/article.php"] [unique_id "amucBoijB6THqIZZsUIXnwAA0Vc"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 13:46:30.725251 2026] [security2:error] [pid 935860:tid 936094] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucBoijB6THqIZZsUIXoAAAAOw"]
[Thu Jul 30 13:46:30.792082 2026] [security2:error] [pid 935860:tid 936085] [client 20.171.55.167:9588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/customize/about.php"] [unique_id "amucBoijB6THqIZZsUIXpAAAAOM"]
[Thu Jul 30 13:46:30.857820 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:29162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucBoijB6THqIZZsUIXqAAAANk"]
[Thu Jul 30 13:46:31.049113 2026] [core:notice] [pid 935860:tid 936052] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:31.078778 2026] [security2:error] [pid 935860:tid 936030] [client 172.237.109.114:4631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amucB4ijB6THqIZZsUIXsQAAAKw"]
[Thu Jul 30 13:46:31.103173 2026] [security2:error] [pid 935860:tid 936113] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucBoijB6THqIZZsUIXrQAAAP8"]
[Thu Jul 30 13:46:31.350486 2026] [security2:error] [pid 935860:tid 936038] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucB4ijB6THqIZZsUIXtwAAALQ"]
[Thu Jul 30 13:46:31.511882 2026] [security2:error] [pid 935860:tid 936106] [client 20.171.55.167:9419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amucB4ijB6THqIZZsUIXwQAAAPg"]
[Thu Jul 30 13:46:31.596071 2026] [security2:error] [pid 935860:tid 936023] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucB4ijB6THqIZZsUIXvgAAAKU"]
[Thu Jul 30 13:46:31.601240 2026] [core:notice] [pid 935860:tid 936008] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:31.728317 2026] [security2:error] [pid 935860:tid 935992] [client 185.177.72.22:29162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/api.swp"] [unique_id "amucB4ijB6THqIZZsUIXxQAAAIY"]
[Thu Jul 30 13:46:31.975191 2026] [security2:error] [pid 935860:tid 936082] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucB4ijB6THqIZZsUIXzAAAAOA"]
[Thu Jul 30 13:46:32.218619 2026] [security2:error] [pid 935860:tid 936068] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCIijB6THqIZZsUIX0QAAANI"]
[Thu Jul 30 13:46:32.264017 2026] [security2:error] [pid 935860:tid 936077] [client 20.171.55.167:9423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/widgets/about.php"] [unique_id "amucCIijB6THqIZZsUIX1AAAANs"]
[Thu Jul 30 13:46:32.346482 2026] [security2:error] [pid 935860:tid 936109] [client 185.177.72.22:29162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucCIijB6THqIZZsUIX2gAAAPs"]
[Thu Jul 30 13:46:32.594357 2026] [security2:error] [pid 935860:tid 936024] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCIijB6THqIZZsUIX3wAAAKY"]
[Thu Jul 30 13:46:32.811328 2026] [security2:error] [pid 935860:tid 936029] [client 78.167.1.90:56427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucCIijB6THqIZZsUIX5wAAAKs"]
[Thu Jul 30 13:46:32.811884 2026] [security2:error] [pid 935860:tid 936029] [client 78.167.1.90:56427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucCIijB6THqIZZsUIX5wAAAKs"]
[Thu Jul 30 13:46:32.850853 2026] [security2:error] [pid 935860:tid 936074] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCIijB6THqIZZsUIX4wAAANg"]
[Thu Jul 30 13:46:32.913004 2026] [security2:error] [pid 935860:tid 936090] [client 20.125.96.254:13039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/edit.php"] [unique_id "amucCIijB6THqIZZsUIX6wAAAOg"]
[Thu Jul 30 13:46:32.913105 2026] [security2:error] [pid 935860:tid 936090] [client 20.125.96.254:13039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/edit.php"] [unique_id "amucCIijB6THqIZZsUIX6wAAAOg"]
[Thu Jul 30 13:46:32.981149 2026] [security2:error] [pid 935860:tid 936020] [client 20.171.55.167:10144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/IXR/about.php"] [unique_id "amucCIijB6THqIZZsUIX7wAAAKI"]
[Thu Jul 30 13:46:33.083444 2026] [security2:error] [pid 935860:tid 936088] [client 43.159.128.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amucCIijB6THqIZZsUIX7gAAAOY"]
[Thu Jul 30 13:46:33.095115 2026] [security2:error] [pid 935860:tid 936111] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCIijB6THqIZZsUIX8AAAAP0"]
[Thu Jul 30 13:46:33.345279 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCYijB6THqIZZsUIX9QAAAL0"]
[Thu Jul 30 13:46:33.473758 2026] [security2:error] [pid 935860:tid 936043] [client 185.177.72.22:29162] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.git%00"] [unique_id "amucCYijB6THqIZZsUIX_QAAALk"]
[Thu Jul 30 13:46:33.691866 2026] [security2:error] [pid 935860:tid 936080] [client 20.171.55.167:9409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/js/about.php"] [unique_id "amucCYijB6THqIZZsUIYAgAAAN4"]
[Thu Jul 30 13:46:33.768630 2026] [security2:error] [pid 935860:tid 936022] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCYijB6THqIZZsUIYAQAAAKQ"]
[Thu Jul 30 13:46:34.064972 2026] [security2:error] [pid 935860:tid 936094] [client 103.190.40.154:21861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucCoijB6THqIZZsUIYDwAAAOw"]
[Thu Jul 30 13:46:34.065129 2026] [security2:error] [pid 935860:tid 936094] [client 103.190.40.154:21861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucCoijB6THqIZZsUIYDwAAAOw"]
[Thu Jul 30 13:46:34.137927 2026] [security2:error] [pid 935860:tid 936071] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCoijB6THqIZZsUIYDAAAANU"]
[Thu Jul 30 13:46:34.197145 2026] [security2:error] [pid 935860:tid 936049] [client 181.116.200.68:47097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucCoijB6THqIZZsUIYEwAAAL8"]
[Thu Jul 30 13:46:34.197244 2026] [security2:error] [pid 935860:tid 936049] [client 181.116.200.68:47097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucCoijB6THqIZZsUIYEwAAAL8"]
[Thu Jul 30 13:46:34.383656 2026] [security2:error] [pid 935860:tid 936013] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCoijB6THqIZZsUIYFAAAAJs"]
[Thu Jul 30 13:46:34.410813 2026] [security2:error] [pid 935860:tid 936018] [client 20.171.55.167:10162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amucCoijB6THqIZZsUIYGAAAAKA"]
[Thu Jul 30 13:46:34.621108 2026] [security2:error] [pid 935860:tid 936012] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCoijB6THqIZZsUIYHAAAAJo"]
[Thu Jul 30 13:46:34.876944 2026] [security2:error] [pid 935860:tid 936052] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucCoijB6THqIZZsUIYIAAAAMI"]
[Thu Jul 30 13:46:35.121264 2026] [security2:error] [pid 935860:tid 936058] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucC4ijB6THqIZZsUIYJwAAAMg"]
[Thu Jul 30 13:46:35.131799 2026] [security2:error] [pid 935860:tid 936065] [client 20.171.55.167:9538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/pomo/about.php"] [unique_id "amucC4ijB6THqIZZsUIYKAAAAM8"]
[Thu Jul 30 13:46:35.361837 2026] [security2:error] [pid 935860:tid 936054] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucC4ijB6THqIZZsUIYLAAAAMQ"]
[Thu Jul 30 13:46:35.604208 2026] [security2:error] [pid 935860:tid 936043] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucC4ijB6THqIZZsUIYNAAAALk"]
[Thu Jul 30 13:46:35.635444 2026] [security2:error] [pid 935860:tid 936066] [client 20.125.96.254:3318] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.espairsa.com"] [uri "/cgi-bin"] [unique_id "amucC4ijB6THqIZZsUIYNgAAANA"]
[Thu Jul 30 13:46:35.635542 2026] [security2:error] [pid 935860:tid 936066] [client 20.125.96.254:3318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.espairsa.com"] [uri "/cgi-bin"] [unique_id "amucC4ijB6THqIZZsUIYNgAAANA"]
[Thu Jul 30 13:46:35.759349 2026] [security2:error] [pid 935860:tid 936084] [client 172.202.44.182:36866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/wp-file.php"] [unique_id "amucC4ijB6THqIZZsUIYOwAAAOI"]
[Thu Jul 30 13:46:35.845270 2026] [security2:error] [pid 935860:tid 936072] [client 20.171.55.167:9452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amucC4ijB6THqIZZsUIYPgAAANY"]
[Thu Jul 30 13:46:35.845394 2026] [security2:error] [pid 935860:tid 936116] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucC4ijB6THqIZZsUIYOgAAAQI"]
[Thu Jul 30 13:46:36.082553 2026] [security2:error] [pid 935860:tid 936037] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucC4ijB6THqIZZsUIYRgAAALM"]
[Thu Jul 30 13:46:36.326753 2026] [security2:error] [pid 935860:tid 936059] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucDIijB6THqIZZsUIYTAAAAMk"]
[Thu Jul 30 13:46:36.456435 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:29162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucDIijB6THqIZZsUIYUAAAAOU"]
[Thu Jul 30 13:46:36.592064 2026] [security2:error] [pid 935860:tid 936002] [client 185.177.72.22:29162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucDIijB6THqIZZsUIYVAAAAJA"]
[Thu Jul 30 13:46:36.597738 2026] [security2:error] [pid 935860:tid 936115] [client 20.171.55.167:9872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/updraft/about.php"] [unique_id "amucDIijB6THqIZZsUIYVQAAAQE"]
[Thu Jul 30 13:46:36.602346 2026] [security2:error] [pid 935860:tid 936030] [client 20.125.96.254:3836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/mah.php"] [unique_id "amucDIijB6THqIZZsUIYVgAAAKw"]
[Thu Jul 30 13:46:36.602428 2026] [security2:error] [pid 935860:tid 936030] [client 20.125.96.254:3836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/mah.php"] [unique_id "amucDIijB6THqIZZsUIYVgAAAKw"]
[Thu Jul 30 13:46:36.724233 2026] [security2:error] [pid 935860:tid 936062] [client 185.177.72.22:29162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucDIijB6THqIZZsUIYVwAAAMw"]
[Thu Jul 30 13:46:36.853484 2026] [security2:error] [pid 935860:tid 936061] [client 185.177.72.22:29162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucDIijB6THqIZZsUIYWwAAAMs"]
[Thu Jul 30 13:46:37.102892 2026] [security2:error] [pid 935860:tid 936060] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucDIijB6THqIZZsUIYYgAAAMo"]
[Thu Jul 30 13:46:37.315808 2026] [security2:error] [pid 935860:tid 936106] [client 20.171.55.167:9884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amucDYijB6THqIZZsUIYewAAAPg"]
[Thu Jul 30 13:46:37.360455 2026] [security2:error] [pid 935860:tid 936043] [client 52.238.199.152:11330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "igetvapesonline.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amucDYijB6THqIZZsUIYfgAAALk"]
[Thu Jul 30 13:46:37.372585 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucDYijB6THqIZZsUIYcQAAAJY"]
[Thu Jul 30 13:46:37.617920 2026] [security2:error] [pid 935860:tid 936078] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucDYijB6THqIZZsUIYhQAAANw"]
[Thu Jul 30 13:46:37.688671 2026] [security2:error] [pid 935860:tid 935889] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucDYijB6THqIZZsUIYjAAA7Bs"]
[Thu Jul 30 13:46:37.697876 2026] [security2:error] [pid 935860:tid 936032] [client 74.7.175.182:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bakubrandacademy.com"] [uri "/index.php"] [unique_id "amucDIijB6THqIZZsUIYSAAArnI"]
[Thu Jul 30 13:46:37.697910 2026] [security2:error] [pid 935860:tid 936032] [client 74.7.175.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bakubrandacademy.com"] [uri "/index.php"] [unique_id "amucDIijB6THqIZZsUIYSAAArnI"]
[Thu Jul 30 13:46:37.801097 2026] [autoindex:error] [pid 935860:tid 936037] [client 43.164.133.138:50124] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:46:37.864865 2026] [security2:error] [pid 935860:tid 936003] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucDYijB6THqIZZsUIYkAAAAJE"]
[Thu Jul 30 13:46:38.207651 2026] [security2:error] [pid 935860:tid 936095] [client 172.202.44.182:36889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/sid3.php"] [unique_id "amucDoijB6THqIZZsUIYpgAAAO0"]
[Thu Jul 30 13:46:38.382681 2026] [security2:error] [pid 935860:tid 936086] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucDYijB6THqIZZsUIYjQAA5A0"]
[Thu Jul 30 13:46:38.459522 2026] [security2:error] [pid 935860:tid 935878] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/api.swp"] [unique_id "amucDoijB6THqIZZsUIYtAAAnBA"]
[Thu Jul 30 13:46:38.626388 2026] [security2:error] [pid 935860:tid 936056] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucDoijB6THqIZZsUIYtQAAAMY"]
[Thu Jul 30 13:46:38.678544 2026] [security2:error] [pid 935860:tid 936031] [client 20.171.55.167:9412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/themes/about.php"] [unique_id "amucDoijB6THqIZZsUIYuwAAAK0"]
[Thu Jul 30 13:46:38.820542 2026] [security2:error] [pid 935860:tid 936044] [client 20.125.96.254:3277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/archive.php"] [unique_id "amucDoijB6THqIZZsUIYwwAAALo"]
[Thu Jul 30 13:46:38.820645 2026] [security2:error] [pid 935860:tid 936044] [client 20.125.96.254:3277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/archive.php"] [unique_id "amucDoijB6THqIZZsUIYwwAAALo"]
[Thu Jul 30 13:46:38.912909 2026] [security2:error] [pid 935860:tid 935921] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucDoijB6THqIZZsUIYxQAA7zs"]
[Thu Jul 30 13:46:39.129562 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucD4ijB6THqIZZsUIYxgAAAL0"]
[Thu Jul 30 13:46:39.390314 2026] [security2:error] [pid 935860:tid 936080] [client 20.171.55.167:10155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/includes/about.php"] [unique_id "amucD4ijB6THqIZZsUIY2AAAAN4"]
[Thu Jul 30 13:46:39.686299 2026] [security2:error] [pid 935860:tid 935926] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.git%00"] [unique_id "amucD4ijB6THqIZZsUIY4wAAqkA"]
[Thu Jul 30 13:46:39.793379 2026] [security2:error] [pid 935860:tid 936102] [client 159.69.158.189:48660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amucD4ijB6THqIZZsUIY6wAAAPQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:46:39.906597 2026] [security2:error] [pid 935860:tid 936012] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucD4ijB6THqIZZsUIY7AAAAJo"]
[Thu Jul 30 13:46:40.096378 2026] [security2:error] [pid 935860:tid 935997] [client 20.171.55.167:9469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/images/about.php"] [unique_id "amucEIijB6THqIZZsUIY_wAAAIs"]
[Thu Jul 30 13:46:40.151951 2026] [security2:error] [pid 935860:tid 936058] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEIijB6THqIZZsUIY-wAAAMg"]
[Thu Jul 30 13:46:40.163405 2026] [core:notice] [pid 935860:tid 936011] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:40.167358 2026] [security2:error] [pid 935860:tid 936011] [client 159.69.158.189:48664] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amucEIijB6THqIZZsUIZCQAAAJk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:46:40.406382 2026] [security2:error] [pid 935860:tid 936106] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEIijB6THqIZZsUIZEwAAAPg"]
[Thu Jul 30 13:46:40.542296 2026] [security2:error] [pid 935860:tid 935996] [client 159.69.158.189:48668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amucEIijB6THqIZZsUIZGwAAAIo"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:46:40.647298 2026] [security2:error] [pid 935860:tid 936108] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEIijB6THqIZZsUIZHAAAAPo"]
[Thu Jul 30 13:46:40.656544 2026] [security2:error] [pid 935860:tid 935950] [remote 5.161.62.209:56110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amucEIijB6THqIZZsUIZJAAA3Fg"]
[Thu Jul 30 13:46:40.813732 2026] [security2:error] [pid 935860:tid 936037] [client 20.171.55.167:9555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amucEIijB6THqIZZsUIZKwAAALM"]
[Thu Jul 30 13:46:40.889966 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEIijB6THqIZZsUIZKgAAAJY"]
[Thu Jul 30 13:46:41.091723 2026] [security2:error] [pid 935860:tid 936002] [client 103.242.199.184:61698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucEYijB6THqIZZsUIZOQAAAJA"]
[Thu Jul 30 13:46:41.091872 2026] [security2:error] [pid 935860:tid 936002] [client 103.242.199.184:61698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucEYijB6THqIZZsUIZOQAAAJA"]
[Thu Jul 30 13:46:41.132756 2026] [security2:error] [pid 935860:tid 936051] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEYijB6THqIZZsUIZMgAAAME"]
[Thu Jul 30 13:46:41.376117 2026] [security2:error] [pid 935860:tid 936061] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEYijB6THqIZZsUIZQAAAAMs"]
[Thu Jul 30 13:46:41.395026 2026] [security2:error] [pid 935860:tid 935971] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucEYijB6THqIZZsUIZQgAAxm0"]
[Thu Jul 30 13:46:41.438334 2026] [security2:error] [pid 935860:tid 936015] [client 89.238.167.134:59524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amucEYijB6THqIZZsUIZOgAAAJ0"]
[Thu Jul 30 13:46:41.438464 2026] [security2:error] [pid 935860:tid 936015] [client 89.238.167.134:59524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amucEYijB6THqIZZsUIZOgAAAJ0"]
[Thu Jul 30 13:46:41.525630 2026] [security2:error] [pid 935860:tid 935925] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucEYijB6THqIZZsUIZRgAA9T8"]
[Thu Jul 30 13:46:41.564076 2026] [security2:error] [pid 935860:tid 936079] [client 20.171.55.167:9536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/images/about.php"] [unique_id "amucEYijB6THqIZZsUIZSQAAAN0"]
[Thu Jul 30 13:46:41.624054 2026] [security2:error] [pid 935860:tid 935997] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEYijB6THqIZZsUIZRAAAAIs"]
[Thu Jul 30 13:46:41.659416 2026] [security2:error] [pid 935860:tid 935946] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucEYijB6THqIZZsUIZTQAAwFQ"]
[Thu Jul 30 13:46:41.791061 2026] [security2:error] [pid 935860:tid 935947] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucEYijB6THqIZZsUIZUAAAx1U"]
[Thu Jul 30 13:46:41.868849 2026] [security2:error] [pid 935860:tid 936097] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEYijB6THqIZZsUIZTwAAAO8"]
[Thu Jul 30 13:46:42.125287 2026] [security2:error] [pid 935860:tid 936022] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEYijB6THqIZZsUIZVwAAAKQ"]
[Thu Jul 30 13:46:42.261359 2026] [security2:error] [pid 935860:tid 936040] [client 20.125.96.254:13046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/hosty.php"] [unique_id "amucEoijB6THqIZZsUIZYwAAALY"]
[Thu Jul 30 13:46:42.261468 2026] [security2:error] [pid 935860:tid 936040] [client 20.125.96.254:13046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/hosty.php"] [unique_id "amucEoijB6THqIZZsUIZYwAAALY"]
[Thu Jul 30 13:46:42.302056 2026] [security2:error] [pid 935860:tid 936000] [client 20.171.55.167:9550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/about.php"] [unique_id "amucEoijB6THqIZZsUIZZAAAAI4"]
[Thu Jul 30 13:46:42.369264 2026] [security2:error] [pid 935860:tid 936080] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEoijB6THqIZZsUIZYgAAAN4"]
[Thu Jul 30 13:46:42.507284 2026] [security2:error] [pid 935860:tid 935996] [client 78.167.1.90:55207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucEoijB6THqIZZsUIZbAAAAIo"]
[Thu Jul 30 13:46:42.508246 2026] [security2:error] [pid 935860:tid 935996] [client 78.167.1.90:55207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucEoijB6THqIZZsUIZbAAAAIo"]
[Thu Jul 30 13:46:42.611813 2026] [security2:error] [pid 935860:tid 936004] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEoijB6THqIZZsUIZawAAAJI"]
[Thu Jul 30 13:46:42.856770 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEoijB6THqIZZsUIZeQAAAOU"]
[Thu Jul 30 13:46:42.970181 2026] [security2:error] [pid 935860:tid 936096] [client 74.7.241.185:33808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.pvl.djb.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amucEoijB6THqIZZsUIZgAAA7lw"]
[Thu Jul 30 13:46:43.061006 2026] [security2:error] [pid 935860:tid 936091] [client 20.171.55.167:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/about.php"] [unique_id "amucE4ijB6THqIZZsUIZhAAAAOk"]
[Thu Jul 30 13:46:43.096475 2026] [security2:error] [pid 935860:tid 936059] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucEoijB6THqIZZsUIZgQAAAMk"]
[Thu Jul 30 13:46:43.337909 2026] [security2:error] [pid 935860:tid 936015] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucE4ijB6THqIZZsUIZjQAAAJ0"]
[Thu Jul 30 13:46:43.580129 2026] [security2:error] [pid 935860:tid 936107] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucE4ijB6THqIZZsUIZlAAAAPk"]
[Thu Jul 30 13:46:43.802956 2026] [security2:error] [pid 935860:tid 936115] [client 20.171.55.167:9445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/gallery/about.php"] [unique_id "amucE4ijB6THqIZZsUIZowAAAQE"]
[Thu Jul 30 13:46:43.823478 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucE4ijB6THqIZZsUIZoQAAAL0"]
[Thu Jul 30 13:46:43.952954 2026] [security2:error] [pid 935860:tid 936041] [client 74.7.228.57:34076] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.website-02ad1776.apw.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amucE4ijB6THqIZZsUIZqgAAt0Y"]
[Thu Jul 30 13:46:44.062244 2026] [security2:error] [pid 935860:tid 936000] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucE4ijB6THqIZZsUIZqwAAAI4"]
[Thu Jul 30 13:46:44.308270 2026] [security2:error] [pid 935860:tid 936042] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucFIijB6THqIZZsUIZtAAAALg"]
[Thu Jul 30 13:46:44.553052 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucFIijB6THqIZZsUIZvgAAAOU"]
[Thu Jul 30 13:46:44.563246 2026] [security2:error] [pid 935860:tid 935999] [client 20.171.55.167:10154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/blocks/about.php"] [unique_id "amucFIijB6THqIZZsUIZwQAAAI0"]
[Thu Jul 30 13:46:44.695145 2026] [security2:error] [pid 935860:tid 936039] [client 20.125.96.254:3049] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.espairsa.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "amucFIijB6THqIZZsUIZyAAAALU"]
[Thu Jul 30 13:46:44.695284 2026] [security2:error] [pid 935860:tid 936039] [client 20.125.96.254:3049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.espairsa.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "amucFIijB6THqIZZsUIZyAAAALU"]
[Thu Jul 30 13:46:44.713227 2026] [security2:error] [pid 935860:tid 936091] [client 103.190.40.154:22020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucFIijB6THqIZZsUIZyQAAAOk"]
[Thu Jul 30 13:46:44.713327 2026] [security2:error] [pid 935860:tid 936091] [client 103.190.40.154:22020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucFIijB6THqIZZsUIZyQAAAOk"]
[Thu Jul 30 13:46:44.795509 2026] [security2:error] [pid 935860:tid 936014] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucFIijB6THqIZZsUIZxwAAAJw"]
[Thu Jul 30 13:46:44.863275 2026] [security2:error] [pid 935860:tid 936012] [client 181.116.200.68:58752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucFIijB6THqIZZsUIZ0QAAAJo"]
[Thu Jul 30 13:46:44.863378 2026] [security2:error] [pid 935860:tid 936012] [client 181.116.200.68:58752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucFIijB6THqIZZsUIZ0QAAAJo"]
[Thu Jul 30 13:46:44.974518 2026] [security2:error] [pid 935860:tid 935942] [remote 57.141.0.2:21380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amucFIijB6THqIZZsUIZ2AAAl1A"]
[Thu Jul 30 13:46:45.042688 2026] [security2:error] [pid 935860:tid 935993] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucFIijB6THqIZZsUIZ1AAAAIc"]
[Thu Jul 30 13:46:45.265784 2026] [security2:error] [pid 935860:tid 936093] [client 20.171.55.167:9431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/about.php"] [unique_id "amucFYijB6THqIZZsUIZ4gAAAOs"]
[Thu Jul 30 13:46:45.287665 2026] [security2:error] [pid 935860:tid 936052] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucFYijB6THqIZZsUIZ2wAAAMI"]
[Thu Jul 30 13:46:45.317941 2026] [security2:error] [pid 935860:tid 935911] [remote 173.231.241.109:39680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.241.231.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amucFYijB6THqIZZsUIZ5QAA_jE"]
[Thu Jul 30 13:46:45.526560 2026] [security2:error] [pid 935860:tid 936081] [client 185.177.72.22:29162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucFYijB6THqIZZsUIZ7AAAAN8"]
[Thu Jul 30 13:46:45.792019 2026] [security2:error] [pid 935860:tid 936100] [client 185.177.72.22:11018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/info.php"] [unique_id "amucFYijB6THqIZZsUIZ9wAAAPI"]
[Thu Jul 30 13:46:45.990072 2026] [security2:error] [pid 935860:tid 936016] [client 20.171.55.167:9427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/images/about.php"] [unique_id "amucFYijB6THqIZZsUIaAQAAAJ4"]
[Thu Jul 30 13:46:46.049004 2026] [security2:error] [pid 935860:tid 936017] [client 185.177.72.22:11022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/info.php%257e"] [unique_id "amucFoijB6THqIZZsUIaBAAAAJ8"]
[Thu Jul 30 13:46:46.224422 2026] [security2:error] [pid 935860:tid 936043] [client 20.125.96.254:3823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/admin.php"] [unique_id "amucFoijB6THqIZZsUIaCwAAALk"]
[Thu Jul 30 13:46:46.224536 2026] [security2:error] [pid 935860:tid 936043] [client 20.125.96.254:3823] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/admin.php"] [unique_id "amucFoijB6THqIZZsUIaCwAAALk"]
[Thu Jul 30 13:46:46.311880 2026] [security2:error] [pid 935860:tid 936115] [client 185.177.72.22:11030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/info.php%28%28"] [unique_id "amucFoijB6THqIZZsUIaDwAAAQE"]
[Thu Jul 30 13:46:46.578091 2026] [security2:error] [pid 935860:tid 936025] [client 185.177.72.22:11040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/info.php/"] [unique_id "amucFoijB6THqIZZsUIaGwAAAKc"]
[Thu Jul 30 13:46:46.741300 2026] [security2:error] [pid 935860:tid 936066] [client 20.171.55.167:9442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amucFoijB6THqIZZsUIaHwAAANA"]
[Thu Jul 30 13:46:46.969693 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucFoijB6THqIZZsUIaJQAAANk"]
[Thu Jul 30 13:46:47.220922 2026] [security2:error] [pid 935860:tid 936095] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucF4ijB6THqIZZsUIaMAAAAO0"]
[Thu Jul 30 13:46:47.467042 2026] [security2:error] [pid 935860:tid 936096] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucF4ijB6THqIZZsUIaOQAAAO4"]
[Thu Jul 30 13:46:47.491572 2026] [security2:error] [pid 935860:tid 935995] [client 20.171.55.167:9418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amucF4ijB6THqIZZsUIaQAAAAIk"]
[Thu Jul 30 13:46:47.566700 2026] [security2:error] [pid 935860:tid 935994] [client 20.125.96.254:2166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/av.php"] [unique_id "amucF4ijB6THqIZZsUIaRQAAAIg"]
[Thu Jul 30 13:46:47.566799 2026] [security2:error] [pid 935860:tid 935994] [client 20.125.96.254:2166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/av.php"] [unique_id "amucF4ijB6THqIZZsUIaRQAAAIg"]
[Thu Jul 30 13:46:47.696932 2026] [security2:error] [pid 935860:tid 936039] [client 84.75.148.221:57266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.148.75.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/CARUBAN/index_php/JSHR/issue/current"] [unique_id "amucF4ijB6THqIZZsUIaPQAAALU"]
[Thu Jul 30 13:46:47.718808 2026] [security2:error] [pid 935860:tid 936061] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucF4ijB6THqIZZsUIaRgAAAMs"]
[Thu Jul 30 13:46:47.975684 2026] [security2:error] [pid 935860:tid 936099] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucF4ijB6THqIZZsUIaUQAAAPE"]
[Thu Jul 30 13:46:48.197898 2026] [security2:error] [pid 935860:tid 936029] [client 20.171.55.167:9893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/network/cloud.php"] [unique_id "amucGIijB6THqIZZsUIaYgAAAKs"]
[Thu Jul 30 13:46:48.262099 2026] [security2:error] [pid 935860:tid 935873] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/info.php"] [unique_id "amucGIijB6THqIZZsUIaZAAApws"]
[Thu Jul 30 13:46:48.390618 2026] [security2:error] [pid 935860:tid 935967] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/info.php%257e"] [unique_id "amucGIijB6THqIZZsUIaaQAApmk"]
[Thu Jul 30 13:46:48.520414 2026] [security2:error] [pid 935860:tid 935948] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/info.php%28%28"] [unique_id "amucGIijB6THqIZZsUIacgAAr1Y"]
[Thu Jul 30 13:46:48.652045 2026] [security2:error] [pid 935860:tid 935945] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/info.php/"] [unique_id "amucGIijB6THqIZZsUIadwAAkFM"]
[Thu Jul 30 13:46:48.768659 2026] [security2:error] [pid 935860:tid 936026] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucGIijB6THqIZZsUIaeAAAAKg"]
[Thu Jul 30 13:46:48.774480 2026] [security2:error] [pid 935860:tid 935999] [client 20.125.96.254:8976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/shell.php"] [unique_id "amucGIijB6THqIZZsUIaeQAAAI0"]
[Thu Jul 30 13:46:48.774573 2026] [security2:error] [pid 935860:tid 935999] [client 20.125.96.254:8976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/shell.php"] [unique_id "amucGIijB6THqIZZsUIaeQAAAI0"]
[Thu Jul 30 13:46:48.927009 2026] [security2:error] [pid 935860:tid 936034] [client 185.191.171.12:56732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amucGIijB6THqIZZsUIagQAAALA"]
[Thu Jul 30 13:46:48.927156 2026] [security2:error] [pid 935860:tid 936034] [client 185.191.171.12:56732] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amucGIijB6THqIZZsUIagQAAALA"]
[Thu Jul 30 13:46:48.930603 2026] [security2:error] [pid 935860:tid 936072] [client 20.171.55.167:10139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cloud.php"] [unique_id "amucGIijB6THqIZZsUIaggAAANY"]
[Thu Jul 30 13:46:49.023039 2026] [security2:error] [pid 935860:tid 936051] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucGIijB6THqIZZsUIagAAAAME"]
[Thu Jul 30 13:46:49.280631 2026] [security2:error] [pid 935860:tid 936060] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucGYijB6THqIZZsUIajwAAAMo"]
[Thu Jul 30 13:46:49.542195 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucGYijB6THqIZZsUIamwAAAL0"]
[Thu Jul 30 13:46:49.649183 2026] [security2:error] [pid 935860:tid 936091] [client 119.73.97.132:29724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/wp-admin/post.php"] [unique_id "amucGYijB6THqIZZsUIalAAA6Tw"], referer: https://www.urwru.club/wp-admin/post.php?post=1081&action=edit
[Thu Jul 30 13:46:49.697916 2026] [security2:error] [pid 935860:tid 936093] [client 20.171.55.167:9443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/cloud.php"] [unique_id "amucGYijB6THqIZZsUIapgAAAOs"]
[Thu Jul 30 13:46:49.789867 2026] [security2:error] [pid 935860:tid 936046] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucGYijB6THqIZZsUIapQAAALw"]
[Thu Jul 30 13:46:49.991158 2026] [security2:error] [pid 935860:tid 936109] [client 85.208.96.203:37860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/31/exclusivo-raimundo-lira-envia-mensagem-a-kassab-e-informa-desligamento-do-psd/"] [unique_id "amucGYijB6THqIZZsUIatAAAAPs"]
[Thu Jul 30 13:46:49.991279 2026] [security2:error] [pid 935860:tid 936109] [client 85.208.96.203:37860] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/31/exclusivo-raimundo-lira-envia-mensagem-a-kassab-e-informa-desligamento-do-psd/"] [unique_id "amucGYijB6THqIZZsUIatAAAAPs"]
[Thu Jul 30 13:46:50.418870 2026] [security2:error] [pid 935860:tid 936113] [client 20.171.55.167:9894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/updates.php"] [unique_id "amucGoijB6THqIZZsUIaxQAAAP8"]
[Thu Jul 30 13:46:50.589919 2026] [security2:error] [pid 935860:tid 936096] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucGoijB6THqIZZsUIayQAAAO4"]
[Thu Jul 30 13:46:50.841779 2026] [security2:error] [pid 935860:tid 936007] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucGoijB6THqIZZsUIa1QAAAJU"]
[Thu Jul 30 13:46:51.099899 2026] [security2:error] [pid 935860:tid 936038] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucGoijB6THqIZZsUIa2AAAALQ"]
[Thu Jul 30 13:46:51.155514 2026] [security2:error] [pid 935860:tid 936021] [client 20.171.55.167:10172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/css/cloud.php"] [unique_id "amucG4ijB6THqIZZsUIa5gAAAKM"]
[Thu Jul 30 13:46:51.350438 2026] [security2:error] [pid 935860:tid 936032] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucG4ijB6THqIZZsUIa7AAAAK4"]
[Thu Jul 30 13:46:51.499357 2026] [security2:error] [pid 935860:tid 935875] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "echomemoversalain.casa"] [uri "/wp/xmlrpc.php"] [unique_id "amucG4ijB6THqIZZsUIa9QAA8w0"]
[Thu Jul 30 13:46:51.499528 2026] [security2:error] [pid 935860:tid 936101] [client 72.167.132.114:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "echomemoversalain.casa"] [uri "/wp/xmlrpc.php"] [unique_id "amucG4ijB6THqIZZsUIa9QAA8w0"]
[Thu Jul 30 13:46:51.603223 2026] [security2:error] [pid 935860:tid 936067] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucG4ijB6THqIZZsUIa9AAAANE"]
[Thu Jul 30 13:46:51.778402 2026] [security2:error] [pid 935860:tid 936053] [client 103.242.199.184:62253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucG4ijB6THqIZZsUIbAwAAAMM"]
[Thu Jul 30 13:46:51.778543 2026] [security2:error] [pid 935860:tid 936053] [client 103.242.199.184:62253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucG4ijB6THqIZZsUIbAwAAAMM"]
[Thu Jul 30 13:46:51.790898 2026] [security2:error] [pid 935860:tid 936105] [client 20.125.96.254:8982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/storage/index.php"] [unique_id "amucG4ijB6THqIZZsUIbBQAAAPc"]
[Thu Jul 30 13:46:51.791010 2026] [security2:error] [pid 935860:tid 936105] [client 20.125.96.254:8982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/storage/index.php"] [unique_id "amucG4ijB6THqIZZsUIbBQAAAPc"]
[Thu Jul 30 13:46:51.848603 2026] [security2:error] [pid 935860:tid 936035] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucG4ijB6THqIZZsUIbAgAAALE"]
[Thu Jul 30 13:46:51.867067 2026] [security2:error] [pid 935860:tid 936071] [client 20.171.55.167:9565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/user/cloud.php"] [unique_id "amucG4ijB6THqIZZsUIbCAAAANU"]
[Thu Jul 30 13:46:52.100199 2026] [security2:error] [pid 935860:tid 936090] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucG4ijB6THqIZZsUIbDQAAAOg"]
[Thu Jul 30 13:46:52.111415 2026] [core:notice] [pid 935860:tid 935999] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:52.114754 2026] [security2:error] [pid 935860:tid 935999] [client 94.154.43.183:50156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "carnetdeshopping.com"] [uri "/.env"] [unique_id "amucHIijB6THqIZZsUIbEwAAAI0"]
[Thu Jul 30 13:46:52.161279 2026] [security2:error] [pid 935860:tid 935927] [remote 52.167.144.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/111/108"] [unique_id "amucG4ijB6THqIZZsUIbCQAA8UE"]
[Thu Jul 30 13:46:52.349782 2026] [security2:error] [pid 935860:tid 936045] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHIijB6THqIZZsUIbFwAAALs"]
[Thu Jul 30 13:46:52.373767 2026] [security2:error] [pid 935860:tid 935970] [remote 57.141.0.37:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amucHIijB6THqIZZsUIbHQAAyGw"]
[Thu Jul 30 13:46:52.598675 2026] [security2:error] [pid 935860:tid 936007] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHIijB6THqIZZsUIbIQAAAJU"]
[Thu Jul 30 13:46:52.601438 2026] [security2:error] [pid 935860:tid 936079] [client 20.171.55.167:10152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/img/cloud.php"] [unique_id "amucHIijB6THqIZZsUIbKQAAAN0"]
[Thu Jul 30 13:46:52.848079 2026] [security2:error] [pid 935860:tid 936114] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHIijB6THqIZZsUIbLgAAAQA"]
[Thu Jul 30 13:46:52.862150 2026] [core:notice] [pid 935860:tid 936076] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:53.095835 2026] [security2:error] [pid 935860:tid 935998] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHIijB6THqIZZsUIbNQAAAIw"]
[Thu Jul 30 13:46:53.128476 2026] [security2:error] [pid 935860:tid 936097] [client 78.167.1.90:54710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucHYijB6THqIZZsUIbOQAAAO8"]
[Thu Jul 30 13:46:53.128833 2026] [security2:error] [pid 935860:tid 936097] [client 78.167.1.90:54710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucHYijB6THqIZZsUIbOQAAAO8"]
[Thu Jul 30 13:46:53.307369 2026] [security2:error] [pid 935860:tid 936032] [client 20.171.55.167:9873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amucHYijB6THqIZZsUIbRgAAAK4"]
[Thu Jul 30 13:46:53.349722 2026] [security2:error] [pid 935860:tid 936059] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHYijB6THqIZZsUIbPgAAAMk"]
[Thu Jul 30 13:46:53.735759 2026] [security2:error] [pid 935860:tid 936088] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHYijB6THqIZZsUIbUAAAAOY"]
[Thu Jul 30 13:46:53.982171 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHYijB6THqIZZsUIbXQAAAOU"]
[Thu Jul 30 13:46:54.081476 2026] [security2:error] [pid 935860:tid 936089] [client 20.171.55.167:9847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/images/cloud.php"] [unique_id "amucHoijB6THqIZZsUIbYAAAAOc"]
[Thu Jul 30 13:46:54.365155 2026] [security2:error] [pid 935860:tid 936007] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHoijB6THqIZZsUIbagAAAJU"]
[Thu Jul 30 13:46:54.609050 2026] [security2:error] [pid 935860:tid 936116] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHoijB6THqIZZsUIbdAAAAQI"]
[Thu Jul 30 13:46:54.866412 2026] [security2:error] [pid 935860:tid 936017] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucHoijB6THqIZZsUIbgAAAAJ8"]
[Thu Jul 30 13:46:55.115511 2026] [security2:error] [pid 935860:tid 936067] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucH4ijB6THqIZZsUIbigAAANE"]
[Thu Jul 30 13:46:55.215657 2026] [security2:error] [pid 935860:tid 936031] [client 20.171.55.167:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/avaa.php"] [unique_id "amucH4ijB6THqIZZsUIbkQAAAK0"]
[Thu Jul 30 13:46:55.365658 2026] [security2:error] [pid 935860:tid 936078] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucH4ijB6THqIZZsUIblQAAANw"]
[Thu Jul 30 13:46:55.385138 2026] [security2:error] [pid 935860:tid 936077] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucHoijB6THqIZZsUIbfwAAANs"]
[Thu Jul 30 13:46:55.398754 2026] [security2:error] [pid 935860:tid 936024] [client 181.116.200.68:50757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucH4ijB6THqIZZsUIbmQAAAKY"]
[Thu Jul 30 13:46:55.398858 2026] [security2:error] [pid 935860:tid 936024] [client 181.116.200.68:50757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucH4ijB6THqIZZsUIbmQAAAKY"]
[Thu Jul 30 13:46:55.462958 2026] [security2:error] [pid 935860:tid 936073] [client 103.190.40.154:18811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucH4ijB6THqIZZsUIboAAAANc"]
[Thu Jul 30 13:46:55.463120 2026] [security2:error] [pid 935860:tid 936073] [client 103.190.40.154:18811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucH4ijB6THqIZZsUIboAAAANc"]
[Thu Jul 30 13:46:55.617072 2026] [security2:error] [pid 935860:tid 936001] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucH4ijB6THqIZZsUIboQAAAI8"]
[Thu Jul 30 13:46:55.727743 2026] [security2:error] [pid 935860:tid 935940] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/phpinfo.php"] [unique_id "amucH4ijB6THqIZZsUIb4wAAhk4"]
[Thu Jul 30 13:46:55.857365 2026] [security2:error] [pid 935860:tid 935920] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/phpinfo.php%255f"] [unique_id "amucH4ijB6THqIZZsUIb6AABADo"]
[Thu Jul 30 13:46:55.863334 2026] [security2:error] [pid 935860:tid 936015] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucH4ijB6THqIZZsUIb5AAAAJ0"]
[Thu Jul 30 13:46:55.986357 2026] [security2:error] [pid 935860:tid 935936] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/phpinfo.php%253c"] [unique_id "amucH4ijB6THqIZZsUIb7AAApEo"]
[Thu Jul 30 13:46:56.083431 2026] [security2:error] [pid 935860:tid 936084] [client 20.171.55.167:9834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/images/cloud.php"] [unique_id "amucIIijB6THqIZZsUIb7wAAAOI"]
[Thu Jul 30 13:46:56.111748 2026] [security2:error] [pid 935860:tid 936040] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucH4ijB6THqIZZsUIb7QAAALY"]
[Thu Jul 30 13:46:56.115682 2026] [security2:error] [pid 935860:tid 935921] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/phpinfo.php%255d"] [unique_id "amucIIijB6THqIZZsUIb8AAA4Ds"]
[Thu Jul 30 13:46:56.184864 2026] [core:notice] [pid 935860:tid 936000] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:56.337542 2026] [security2:error] [pid 935860:tid 936112] [client 20.125.96.254:8977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/w.php"] [unique_id "amucIIijB6THqIZZsUIb_wAAAP4"]
[Thu Jul 30 13:46:56.337656 2026] [security2:error] [pid 935860:tid 936112] [client 20.125.96.254:8977] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/w.php"] [unique_id "amucIIijB6THqIZZsUIb_wAAAP4"]
[Thu Jul 30 13:46:56.364778 2026] [security2:error] [pid 935860:tid 936101] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucIIijB6THqIZZsUIb9AAAAPM"]
[Thu Jul 30 13:46:56.620329 2026] [security2:error] [pid 935860:tid 936042] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucIIijB6THqIZZsUIcBQAAALg"]
[Thu Jul 30 13:46:56.818900 2026] [security2:error] [pid 935860:tid 936094] [client 20.171.55.167:9854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amucIIijB6THqIZZsUIcDwAAAOw"]
[Thu Jul 30 13:46:56.868734 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucIIijB6THqIZZsUIcCwAAAJY"]
[Thu Jul 30 13:46:57.113846 2026] [security2:error] [pid 935860:tid 936061] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucIYijB6THqIZZsUIcGAAAAMs"]
[Thu Jul 30 13:46:57.362326 2026] [security2:error] [pid 935860:tid 936050] [client 185.177.72.22:11052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucIYijB6THqIZZsUIcHQAAAMA"]
[Thu Jul 30 13:46:57.478727 2026] [security2:error] [pid 935860:tid 935997] [client 20.125.96.254:3725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/jp.php"] [unique_id "amucIYijB6THqIZZsUIcJgAAAIs"]
[Thu Jul 30 13:46:57.478830 2026] [security2:error] [pid 935860:tid 935997] [client 20.125.96.254:3725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/jp.php"] [unique_id "amucIYijB6THqIZZsUIcJgAAAIs"]
[Thu Jul 30 13:46:57.496443 2026] [security2:error] [pid 935860:tid 936007] [client 185.177.72.22:11052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/phpinfo.php"] [unique_id "amucIYijB6THqIZZsUIcKgAAAJU"]
[Thu Jul 30 13:46:57.544909 2026] [security2:error] [pid 935860:tid 936091] [client 20.171.55.167:9823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amucIYijB6THqIZZsUIcLQAAAOk"]
[Thu Jul 30 13:46:57.676726 2026] [security2:error] [pid 935860:tid 935938] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/core%7e"] [unique_id "amucIYijB6THqIZZsUIcLgABAUw"]
[Thu Jul 30 13:46:57.761680 2026] [security2:error] [pid 935860:tid 936118] [client 185.177.72.22:21476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/phpinfo.php%255f"] [unique_id "amucIYijB6THqIZZsUIcLwAAAQQ"]
[Thu Jul 30 13:46:58.017677 2026] [security2:error] [pid 935860:tid 936097] [client 185.177.72.22:21484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/phpinfo.php%253c"] [unique_id "amucIoijB6THqIZZsUIcOwAAAO8"]
[Thu Jul 30 13:46:58.274674 2026] [security2:error] [pid 935860:tid 935993] [client 185.177.72.22:21494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/phpinfo.php%255d"] [unique_id "amucIoijB6THqIZZsUIcRAAAAIc"]
[Thu Jul 30 13:46:58.309744 2026] [security2:error] [pid 935860:tid 936000] [client 20.171.55.167:9804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amucIoijB6THqIZZsUIcRwAAAI4"]
[Thu Jul 30 13:46:58.557836 2026] [core:notice] [pid 935860:tid 936057] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:46:59.034207 2026] [security2:error] [pid 935860:tid 936039] [client 20.171.55.167:9841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amucI4ijB6THqIZZsUIccAAAALU"]
[Thu Jul 30 13:46:59.460582 2026] [security2:error] [pid 935860:tid 936021] [client 20.125.96.254:2169] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.espairsa.com"] [uri "/php.ini"] [unique_id "amucI4ijB6THqIZZsUIcfwAAAKM"]
[Thu Jul 30 13:46:59.460696 2026] [security2:error] [pid 935860:tid 936021] [client 20.125.96.254:2169] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.espairsa.com"] [uri "/php.ini"] [unique_id "amucI4ijB6THqIZZsUIcfwAAAKM"]
[Thu Jul 30 13:46:59.670538 2026] [security2:error] [pid 935860:tid 936051] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucI4ijB6THqIZZsUIcgwAAAME"]
[Thu Jul 30 13:46:59.778825 2026] [security2:error] [pid 935860:tid 936019] [client 20.171.55.167:9819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amucI4ijB6THqIZZsUIcjgAAAKE"]
[Thu Jul 30 13:46:59.819231 2026] [security2:error] [pid 935860:tid 936027] [client 185.191.171.15:10486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/08/21/anvisa-aprova-nova-norma-para-flexibilizar-regras-de-importacao-de-vacinas-da-covid-19/"] [unique_id "amucI4ijB6THqIZZsUIckAAAAKk"]
[Thu Jul 30 13:46:59.819375 2026] [security2:error] [pid 935860:tid 936027] [client 185.191.171.15:10486] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/08/21/anvisa-aprova-nova-norma-para-flexibilizar-regras-de-importacao-de-vacinas-da-covid-19/"] [unique_id "amucI4ijB6THqIZZsUIckAAAAKk"]
[Thu Jul 30 13:46:59.915919 2026] [security2:error] [pid 935860:tid 936056] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucI4ijB6THqIZZsUIcjwAAAMY"]
[Thu Jul 30 13:47:00.161480 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJIijB6THqIZZsUIcrAAAANk"]
[Thu Jul 30 13:47:00.219952 2026] [security2:error] [pid 935860:tid 936046] [client 172.237.109.114:4018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcnAAAALw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.220101 2026] [security2:error] [pid 935860:tid 936079] [client 172.237.109.114:13600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcmAAAAN0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.220215 2026] [security2:error] [pid 935860:tid 936079] [client 172.237.109.114:13600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcmAAAAN0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.224730 2026] [security2:error] [pid 935860:tid 936025] [client 172.237.109.114:12804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIckwAAAKc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.224956 2026] [security2:error] [pid 935860:tid 936080] [client 172.237.109.114:46310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIclAAAAN4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.225954 2026] [security2:error] [pid 935860:tid 936108] [client 172.237.109.114:46064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIclQAAAPo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.226039 2026] [security2:error] [pid 935860:tid 936108] [client 172.237.109.114:46064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIclQAAAPo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.228418 2026] [security2:error] [pid 935860:tid 936013] [client 172.237.109.114:47451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcngAAAJs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.229166 2026] [security2:error] [pid 935860:tid 936000] [client 172.237.109.114:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcowAAAI4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.229729 2026] [security2:error] [pid 935860:tid 936106] [client 172.237.109.114:42646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIclgAAAPg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.230789 2026] [security2:error] [pid 935860:tid 936054] [client 172.237.109.114:36794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcmQAAAMQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.230881 2026] [security2:error] [pid 935860:tid 936054] [client 172.237.109.114:36794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcmQAAAMQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.231259 2026] [security2:error] [pid 935860:tid 936049] [client 172.237.109.114:9076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcmgAAAL8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.231571 2026] [security2:error] [pid 935860:tid 936028] [client 172.237.109.114:32314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcnQAAAKo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.231607 2026] [security2:error] [pid 935860:tid 936067] [client 172.237.109.114:14003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcmwAAANE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.234276 2026] [security2:error] [pid 935860:tid 935993] [client 172.237.109.114:27488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcnwAAAIc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.235096 2026] [security2:error] [pid 935860:tid 936032] [client 172.237.109.114:9433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcoQAAAK4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.235393 2026] [security2:error] [pid 935860:tid 936011] [client 172.237.109.114:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIclwAAAJk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.236975 2026] [security2:error] [pid 935860:tid 935996] [client 172.237.109.114:13452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcoAAAAIo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.248050 2026] [security2:error] [pid 935860:tid 936101] [client 172.237.109.114:50407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcogAAAPM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.248182 2026] [security2:error] [pid 935860:tid 936101] [client 172.237.109.114:50407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcogAAAPM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.250042 2026] [core:notice] [pid 935860:tid 935905] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:00.250338 2026] [security2:error] [pid 935860:tid 936048] [client 172.237.109.114:36943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcpAAAAL4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.255026 2026] [security2:error] [pid 935860:tid 936006] [client 172.237.109.114:27030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucI4ijB6THqIZZsUIcpQAAAJQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.276064 2026] [security2:error] [pid 935860:tid 936031] [client 172.237.109.114:1870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucJIijB6THqIZZsUIcqAAAAK0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:00.411110 2026] [security2:error] [pid 935860:tid 936036] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJIijB6THqIZZsUIctAAAALI"]
[Thu Jul 30 13:47:00.486818 2026] [security2:error] [pid 935860:tid 936093] [client 20.171.55.167:9725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/cloud.php"] [unique_id "amucJIijB6THqIZZsUIcugAAAOs"]
[Thu Jul 30 13:47:00.652176 2026] [security2:error] [pid 935860:tid 936023] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJIijB6THqIZZsUIcvQAAAKU"]
[Thu Jul 30 13:47:00.779936 2026] [security2:error] [pid 935860:tid 936086] [client 185.177.72.22:21510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/core%7e"] [unique_id "amucJIijB6THqIZZsUIcxwAAAOQ"]
[Thu Jul 30 13:47:01.018875 2026] [security2:error] [pid 935860:tid 936082] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJIijB6THqIZZsUIczQAAAOA"]
[Thu Jul 30 13:47:01.228606 2026] [security2:error] [pid 935860:tid 936097] [client 20.171.55.167:9723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/updates.php"] [unique_id "amucJYijB6THqIZZsUIc2gAAAO8"]
[Thu Jul 30 13:47:01.277125 2026] [security2:error] [pid 935860:tid 936042] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJYijB6THqIZZsUIc1gAAALg"]
[Thu Jul 30 13:47:01.494630 2026] [autoindex:error] [pid 935860:tid 936006] [client 157.143.3.35:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:47:01.542739 2026] [security2:error] [pid 935860:tid 936008] [client 20.125.96.254:3756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/ws77.php"] [unique_id "amucJYijB6THqIZZsUIc5QAAAJY"]
[Thu Jul 30 13:47:01.542831 2026] [security2:error] [pid 935860:tid 936008] [client 20.125.96.254:3756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/ws77.php"] [unique_id "amucJYijB6THqIZZsUIc5QAAAJY"]
[Thu Jul 30 13:47:01.746956 2026] [autoindex:error] [pid 935860:tid 935961] [remote 157.143.3.35:49422] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:47:01.806409 2026] [security2:error] [pid 935860:tid 936009] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJYijB6THqIZZsUIc7QAAAJc"]
[Thu Jul 30 13:47:01.948268 2026] [security2:error] [pid 935860:tid 936016] [client 20.171.55.167:9689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/libraries/legacy/updates.php"] [unique_id "amucJYijB6THqIZZsUIdAAAAAJ4"]
[Thu Jul 30 13:47:02.062174 2026] [security2:error] [pid 935860:tid 936050] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJYijB6THqIZZsUIc_QAAAMA"]
[Thu Jul 30 13:47:02.097665 2026] [proxy:error] [pid 935860:tid 936047] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:47:02.097742 2026] [proxy_http:error] [pid 935860:tid 936047] [client 32.194.121.99:8621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:47:02.098387 2026] [proxy:error] [pid 935860:tid 936047] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:47:02.098442 2026] [proxy_http:error] [pid 935860:tid 936047] [client 32.194.121.99:8621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:47:02.312474 2026] [security2:error] [pid 935860:tid 936096] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJoijB6THqIZZsUIdEAAAAO4"]
[Thu Jul 30 13:47:02.396083 2026] [security2:error] [pid 935860:tid 935933] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/test.php"] [unique_id "amucJoijB6THqIZZsUIdHAAArEc"]
[Thu Jul 30 13:47:02.440820 2026] [security2:error] [pid 935860:tid 936075] [client 103.242.199.184:62806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucJoijB6THqIZZsUIdHgAAANk"]
[Thu Jul 30 13:47:02.440932 2026] [security2:error] [pid 935860:tid 936075] [client 103.242.199.184:62806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucJoijB6THqIZZsUIdHgAAANk"]
[Thu Jul 30 13:47:02.524995 2026] [security2:error] [pid 935860:tid 935895] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/test.php..."] [unique_id "amucJoijB6THqIZZsUIdIwAAmyE"]
[Thu Jul 30 13:47:02.560967 2026] [security2:error] [pid 935860:tid 936077] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJoijB6THqIZZsUIdHQAAANs"]
[Thu Jul 30 13:47:02.653314 2026] [security2:error] [pid 935860:tid 935896] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/test.php%09%09"] [unique_id "amucJoijB6THqIZZsUIdJwAA0SI"]
[Thu Jul 30 13:47:02.689682 2026] [security2:error] [pid 935860:tid 936002] [client 20.171.55.167:9685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amucJoijB6THqIZZsUIdKAAAAJA"]
[Thu Jul 30 13:47:02.782016 2026] [security2:error] [pid 935860:tid 935940] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/test.php...."] [unique_id "amucJoijB6THqIZZsUIdLgAAnE4"]
[Thu Jul 30 13:47:02.812394 2026] [security2:error] [pid 935860:tid 936032] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJoijB6THqIZZsUIdKQAAAK4"]
[Thu Jul 30 13:47:02.920203 2026] [security2:error] [pid 935860:tid 936018] [client 162.219.176.3:54564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amucJoijB6THqIZZsUIdNAAAAKA"]
[Thu Jul 30 13:47:02.920306 2026] [security2:error] [pid 935860:tid 936018] [client 162.219.176.3:54564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amucJoijB6THqIZZsUIdNAAAAKA"]
[Thu Jul 30 13:47:03.056009 2026] [security2:error] [pid 935860:tid 936088] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJoijB6THqIZZsUIdNQAAAOY"]
[Thu Jul 30 13:47:03.308611 2026] [security2:error] [pid 935860:tid 936044] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJ4ijB6THqIZZsUIdPgAAALo"]
[Thu Jul 30 13:47:03.396039 2026] [security2:error] [pid 935860:tid 935995] [client 20.171.55.167:9681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/libraries/vendor/updates.php"] [unique_id "amucJ4ijB6THqIZZsUIdRgAAAIk"]
[Thu Jul 30 13:47:03.552509 2026] [security2:error] [pid 935860:tid 936116] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJ4ijB6THqIZZsUIdSAAAAQI"]
[Thu Jul 30 13:47:03.666950 2026] [security2:error] [pid 935860:tid 935994] [client 78.167.1.90:56702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucJ4ijB6THqIZZsUIdUgAAAIg"]
[Thu Jul 30 13:47:03.667084 2026] [security2:error] [pid 935860:tid 935994] [client 78.167.1.90:56702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucJ4ijB6THqIZZsUIdUgAAAIg"]
[Thu Jul 30 13:47:03.794544 2026] [security2:error] [pid 935860:tid 936003] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucJ4ijB6THqIZZsUIdUwAAAJE"]
[Thu Jul 30 13:47:04.105226 2026] [security2:error] [pid 935860:tid 936086] [client 20.171.55.167:9803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/alfa-rex.php7"] [unique_id "amucKIijB6THqIZZsUIdaQAAAOQ"]
[Thu Jul 30 13:47:04.171577 2026] [security2:error] [pid 935860:tid 936113] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKIijB6THqIZZsUIdZAAAAP8"]
[Thu Jul 30 13:47:04.431605 2026] [security2:error] [pid 935860:tid 936097] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKIijB6THqIZZsUIdbwAAAO8"]
[Thu Jul 30 13:47:04.685388 2026] [security2:error] [pid 935860:tid 936014] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKIijB6THqIZZsUIdfAAAAJw"]
[Thu Jul 30 13:47:04.796154 2026] [security2:error] [pid 935860:tid 935917] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/localhost.sql"] [unique_id "amucKIijB6THqIZZsUIdiQAAsTc"]
[Thu Jul 30 13:47:04.816734 2026] [security2:error] [pid 935860:tid 936018] [client 20.171.55.167:9670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/alfanew.php"] [unique_id "amucKIijB6THqIZZsUIdiwAAAKA"]
[Thu Jul 30 13:47:04.926842 2026] [security2:error] [pid 935860:tid 936093] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKIijB6THqIZZsUIdigAAAOs"]
[Thu Jul 30 13:47:05.166160 2026] [security2:error] [pid 935860:tid 935995] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKYijB6THqIZZsUIdkwAAAIk"]
[Thu Jul 30 13:47:05.402264 2026] [security2:error] [pid 935860:tid 935873] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/db.sql"] [unique_id "amucKYijB6THqIZZsUIdowAA5ws"]
[Thu Jul 30 13:47:05.405261 2026] [security2:error] [pid 935860:tid 936099] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKYijB6THqIZZsUIdnwAAAPE"]
[Thu Jul 30 13:47:05.525242 2026] [security2:error] [pid 935860:tid 936052] [client 20.171.55.167:9711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amucKYijB6THqIZZsUIdqAAAAMI"]
[Thu Jul 30 13:47:05.647355 2026] [security2:error] [pid 935860:tid 936017] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKYijB6THqIZZsUIdqgAAAJ8"]
[Thu Jul 30 13:47:05.886958 2026] [security2:error] [pid 935860:tid 936004] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKYijB6THqIZZsUIdtQAAAJI"]
[Thu Jul 30 13:47:05.959279 2026] [security2:error] [pid 935860:tid 936100] [client 181.116.200.68:23302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucKYijB6THqIZZsUIduQAAAPI"]
[Thu Jul 30 13:47:05.959392 2026] [security2:error] [pid 935860:tid 936100] [client 181.116.200.68:23302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucKYijB6THqIZZsUIduQAAAPI"]
[Thu Jul 30 13:47:06.130128 2026] [security2:error] [pid 935860:tid 936080] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKoijB6THqIZZsUIdvAAAAN4"]
[Thu Jul 30 13:47:06.184247 2026] [security2:error] [pid 935860:tid 936031] [client 103.190.40.154:16271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucKoijB6THqIZZsUIdxgAAAK0"]
[Thu Jul 30 13:47:06.184522 2026] [security2:error] [pid 935860:tid 936031] [client 103.190.40.154:16271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucKoijB6THqIZZsUIdxgAAAK0"]
[Thu Jul 30 13:47:06.237852 2026] [security2:error] [pid 935860:tid 936095] [client 20.125.96.254:7784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/blass.php"] [unique_id "amucKoijB6THqIZZsUIdygAAAO0"]
[Thu Jul 30 13:47:06.238012 2026] [security2:error] [pid 935860:tid 936095] [client 20.125.96.254:7784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/blass.php"] [unique_id "amucKoijB6THqIZZsUIdygAAAO0"]
[Thu Jul 30 13:47:06.263120 2026] [security2:error] [pid 935860:tid 936077] [client 20.171.55.167:9797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amucKoijB6THqIZZsUIdzAAAANs"]
[Thu Jul 30 13:47:06.501007 2026] [security2:error] [pid 935860:tid 936063] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKoijB6THqIZZsUIdzwAAAM0"]
[Thu Jul 30 13:47:06.871150 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKoijB6THqIZZsUId4AAAAL0"]
[Thu Jul 30 13:47:06.985793 2026] [security2:error] [pid 935860:tid 936034] [client 20.171.55.167:9668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-p.php7"] [unique_id "amucKoijB6THqIZZsUId4wAAALA"]
[Thu Jul 30 13:47:07.112969 2026] [security2:error] [pid 935860:tid 936089] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucKoijB6THqIZZsUId5AAAAOc"]
[Thu Jul 30 13:47:07.355821 2026] [security2:error] [pid 935860:tid 936116] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucK4ijB6THqIZZsUId9AAAAQI"]
[Thu Jul 30 13:47:07.601899 2026] [security2:error] [pid 935860:tid 936059] [client 185.177.72.22:21510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucK4ijB6THqIZZsUId-AAAAMk"]
[Thu Jul 30 13:47:07.729820 2026] [security2:error] [pid 935860:tid 935993] [client 185.177.72.22:21510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/test.php"] [unique_id "amucK4ijB6THqIZZsUIeAwAAAIc"]
[Thu Jul 30 13:47:07.747900 2026] [security2:error] [pid 935860:tid 936094] [client 20.171.55.167:9722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/repeater.php"] [unique_id "amucK4ijB6THqIZZsUIeBQAAAOw"]
[Thu Jul 30 13:47:07.988338 2026] [security2:error] [pid 935860:tid 936073] [client 185.177.72.22:61266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/test.php..."] [unique_id "amucK4ijB6THqIZZsUIeCwAAANc"]
[Thu Jul 30 13:47:08.245107 2026] [security2:error] [pid 935860:tid 936018] [client 185.177.72.22:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/test.php%09%09"] [unique_id "amucLIijB6THqIZZsUIeFwAAAKA"]
[Thu Jul 30 13:47:08.515012 2026] [security2:error] [pid 935860:tid 935992] [client 185.177.72.22:61292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/test.php...."] [unique_id "amucLIijB6THqIZZsUIeIQAAAIY"]
[Thu Jul 30 13:47:08.786063 2026] [security2:error] [pid 935860:tid 935907] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/backup.sql"] [unique_id "amucLIijB6THqIZZsUIeMAAAoS0"]
[Thu Jul 30 13:47:08.918262 2026] [security2:error] [pid 935860:tid 935957] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/backup.sql.php"] [unique_id "amucLIijB6THqIZZsUIeNQAA0F8"]
[Thu Jul 30 13:47:08.943802 2026] [security2:error] [pid 935860:tid 936085] [client 20.125.96.254:7801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/wp-info.php"] [unique_id "amucLIijB6THqIZZsUIeNgAAAOM"]
[Thu Jul 30 13:47:08.943933 2026] [security2:error] [pid 935860:tid 936085] [client 20.125.96.254:7801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/wp-info.php"] [unique_id "amucLIijB6THqIZZsUIeNgAAAOM"]
[Thu Jul 30 13:47:08.978218 2026] [security2:error] [pid 935860:tid 936006] [client 20.171.55.167:9721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-includes/repeater.php"] [unique_id "amucLIijB6THqIZZsUIeNwAAAJQ"]
[Thu Jul 30 13:47:09.112744 2026] [security2:error] [pid 935860:tid 935901] [remote 74.7.227.39:43984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amucLYijB6THqIZZsUIePQAAryc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/maintenance
[Thu Jul 30 13:47:09.377262 2026] [security2:error] [pid 935860:tid 936048] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucLYijB6THqIZZsUIeQgAAAL4"]
[Thu Jul 30 13:47:09.620524 2026] [security2:error] [pid 935860:tid 936088] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucLYijB6THqIZZsUIeTQAAAOY"]
[Thu Jul 30 13:47:09.822177 2026] [security2:error] [pid 935860:tid 936045] [client 20.171.55.167:9667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/repeater.php"] [unique_id "amucLYijB6THqIZZsUIeWgAAALs"]
[Thu Jul 30 13:47:09.860373 2026] [security2:error] [pid 935860:tid 936060] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucLYijB6THqIZZsUIeVgAAAMo"]
[Thu Jul 30 13:47:09.993579 2026] [security2:error] [pid 935860:tid 935906] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/index.php"] [unique_id "amucLYijB6THqIZZsUIeYwAAtyw"]
[Thu Jul 30 13:47:10.097568 2026] [security2:error] [pid 935860:tid 936021] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucLYijB6THqIZZsUIeYgAAAKM"]
[Thu Jul 30 13:47:10.123006 2026] [security2:error] [pid 935860:tid 935955] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/index.php%255f"] [unique_id "amucLoijB6THqIZZsUIeawAAtl0"]
[Thu Jul 30 13:47:10.253404 2026] [security2:error] [pid 935860:tid 935933] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/index.php%255d"] [unique_id "amucLoijB6THqIZZsUIecgAA00c"]
[Thu Jul 30 13:47:10.339791 2026] [security2:error] [pid 935860:tid 936034] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucLoijB6THqIZZsUIecQAAALA"]
[Thu Jul 30 13:47:10.383524 2026] [security2:error] [pid 935860:tid 935889] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/index.php.aws"] [unique_id "amucLoijB6THqIZZsUIedwAA0hs"]
[Thu Jul 30 13:47:10.455796 2026] [core:notice] [pid 935860:tid 935895] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:10.478413 2026] [security2:error] [pid 935860:tid 936085] [client 20.125.96.254:4695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/CDX1.php"] [unique_id "amucLoijB6THqIZZsUIeegAAAOM"]
[Thu Jul 30 13:47:10.478572 2026] [security2:error] [pid 935860:tid 936085] [client 20.125.96.254:4695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/CDX1.php"] [unique_id "amucLoijB6THqIZZsUIeegAAAOM"]
[Thu Jul 30 13:47:10.526199 2026] [security2:error] [pid 935860:tid 936019] [client 20.171.55.167:9795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wsoyanz.php"] [unique_id "amucLoijB6THqIZZsUIegAAAAKE"]
[Thu Jul 30 13:47:10.577817 2026] [security2:error] [pid 935860:tid 936037] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucLoijB6THqIZZsUIeeQAAALM"]
[Thu Jul 30 13:47:10.814782 2026] [security2:error] [pid 935860:tid 936028] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucLoijB6THqIZZsUIehgAAAKo"]
[Thu Jul 30 13:47:11.055223 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucLoijB6THqIZZsUIekAAAAJY"]
[Thu Jul 30 13:47:11.179991 2026] [security2:error] [pid 935860:tid 936060] [client 185.177.72.22:61294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/localhost.sql"] [unique_id "amucL4ijB6THqIZZsUIenQAAAMo"]
[Thu Jul 30 13:47:11.223720 2026] [security2:error] [pid 935860:tid 936088] [client 20.171.55.167:9679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/yanz.php"] [unique_id "amucL4ijB6THqIZZsUIeoQAAAOY"]
[Thu Jul 30 13:47:11.421199 2026] [security2:error] [pid 935860:tid 936104] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucL4ijB6THqIZZsUIepQAAAPY"]
[Thu Jul 30 13:47:11.577957 2026] [security2:error] [pid 935860:tid 936106] [client 172.237.109.114:14405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amucLoijB6THqIZZsUIelQAAAPg"]
[Thu Jul 30 13:47:11.660274 2026] [security2:error] [pid 935860:tid 936115] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucL4ijB6THqIZZsUIesAAAAQE"]
[Thu Jul 30 13:47:11.755942 2026] [security2:error] [pid 935860:tid 936058] [client 20.125.96.254:4690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/wpc.php"] [unique_id "amucL4ijB6THqIZZsUIeuQAAAMg"]
[Thu Jul 30 13:47:11.756041 2026] [security2:error] [pid 935860:tid 936058] [client 20.125.96.254:4690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/wpc.php"] [unique_id "amucL4ijB6THqIZZsUIeuQAAAMg"]
[Thu Jul 30 13:47:11.900228 2026] [security2:error] [pid 935860:tid 936034] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucL4ijB6THqIZZsUIevAAAALA"]
[Thu Jul 30 13:47:11.957331 2026] [security2:error] [pid 935860:tid 936084] [client 20.171.55.167:9793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "amucL4ijB6THqIZZsUIewwAAAOI"]
[Thu Jul 30 13:47:12.026839 2026] [security2:error] [pid 935860:tid 936006] [client 185.177.72.22:61294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/db.sql"] [unique_id "amucMIijB6THqIZZsUIexwAAAJQ"]
[Thu Jul 30 13:47:12.262708 2026] [security2:error] [pid 935860:tid 936079] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMIijB6THqIZZsUIeywAAAN0"]
[Thu Jul 30 13:47:12.499940 2026] [security2:error] [pid 935860:tid 936094] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMIijB6THqIZZsUIe0QAAAOw"]
[Thu Jul 30 13:47:12.696832 2026] [security2:error] [pid 935860:tid 936105] [client 20.171.55.167:9608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "amucMIijB6THqIZZsUIe3gAAAPc"]
[Thu Jul 30 13:47:12.739051 2026] [security2:error] [pid 935860:tid 936095] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMIijB6THqIZZsUIe3QAAAO0"]
[Thu Jul 30 13:47:12.974225 2026] [security2:error] [pid 935860:tid 935997] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMIijB6THqIZZsUIe5AAAAIs"]
[Thu Jul 30 13:47:13.160839 2026] [security2:error] [pid 935860:tid 936021] [client 103.242.199.184:63368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucMYijB6THqIZZsUIe8AAAAKM"]
[Thu Jul 30 13:47:13.160963 2026] [security2:error] [pid 935860:tid 936021] [client 103.242.199.184:63368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucMYijB6THqIZZsUIe8AAAAKM"]
[Thu Jul 30 13:47:13.211075 2026] [security2:error] [pid 935860:tid 936040] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMYijB6THqIZZsUIe7wAAALY"]
[Thu Jul 30 13:47:13.420732 2026] [security2:error] [pid 935860:tid 936036] [client 20.171.55.167:9621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cache-compat.php"] [unique_id "amucMYijB6THqIZZsUIe-QAAALI"]
[Thu Jul 30 13:47:13.446576 2026] [security2:error] [pid 935860:tid 936005] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMYijB6THqIZZsUIe9gAAAJM"]
[Thu Jul 30 13:47:13.681434 2026] [security2:error] [pid 935860:tid 936056] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMYijB6THqIZZsUIfAAAAAMY"]
[Thu Jul 30 13:47:13.776452 2026] [security2:error] [pid 935860:tid 936006] [client 20.125.96.254:1387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/jga.php"] [unique_id "amucMYijB6THqIZZsUIfCQAAAJQ"]
[Thu Jul 30 13:47:13.776552 2026] [security2:error] [pid 935860:tid 936006] [client 20.125.96.254:1387] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/jga.php"] [unique_id "amucMYijB6THqIZZsUIfCQAAAJQ"]
[Thu Jul 30 13:47:13.919684 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMYijB6THqIZZsUIfCgAAANk"]
[Thu Jul 30 13:47:14.125333 2026] [security2:error] [pid 935860:tid 936020] [client 20.171.55.167:9635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/ajax-actions.php"] [unique_id "amucMoijB6THqIZZsUIfEwAAAKI"]
[Thu Jul 30 13:47:14.261549 2026] [security2:error] [pid 935860:tid 936100] [client 78.167.1.90:56597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucMoijB6THqIZZsUIfHAAAAPI"]
[Thu Jul 30 13:47:14.262367 2026] [security2:error] [pid 935860:tid 936100] [client 78.167.1.90:56597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucMoijB6THqIZZsUIfHAAAAPI"]
[Thu Jul 30 13:47:14.420022 2026] [security2:error] [pid 935860:tid 935999] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMoijB6THqIZZsUIfDwAAAI0"]
[Thu Jul 30 13:47:14.661185 2026] [security2:error] [pid 935860:tid 936045] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMoijB6THqIZZsUIfIQAAALs"]
[Thu Jul 30 13:47:14.838407 2026] [security2:error] [pid 935860:tid 936093] [client 20.171.55.167:9641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/ajax-actions.php"] [unique_id "amucMoijB6THqIZZsUIfMAAAAOs"]
[Thu Jul 30 13:47:14.896921 2026] [security2:error] [pid 935860:tid 936016] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucMoijB6THqIZZsUIfLwAAAJ4"]
[Thu Jul 30 13:47:15.134367 2026] [security2:error] [pid 935860:tid 936001] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucM4ijB6THqIZZsUIfMwAAAI8"]
[Thu Jul 30 13:47:15.374297 2026] [security2:error] [pid 935860:tid 936012] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucM4ijB6THqIZZsUIfPgAAAJo"]
[Thu Jul 30 13:47:15.453294 2026] [core:notice] [pid 935860:tid 936069] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:15.587563 2026] [security2:error] [pid 935860:tid 936022] [client 20.171.55.167:9662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-consar.php"] [unique_id "amucM4ijB6THqIZZsUIfSgAAAKQ"]
[Thu Jul 30 13:47:15.612549 2026] [security2:error] [pid 935860:tid 936029] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucM4ijB6THqIZZsUIfRwAAAKs"]
[Thu Jul 30 13:47:15.851390 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucM4ijB6THqIZZsUIfUgAAANk"]
[Thu Jul 30 13:47:16.087997 2026] [security2:error] [pid 935860:tid 936024] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucM4ijB6THqIZZsUIfWgAAAKY"]
[Thu Jul 30 13:47:16.211926 2026] [security2:error] [pid 935860:tid 935879] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/settings.php.save"] [unique_id "amucNIijB6THqIZZsUIfZgAA-hE"]
[Thu Jul 30 13:47:16.301606 2026] [security2:error] [pid 935860:tid 935993] [client 20.171.55.167:9684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/repeater.php"] [unique_id "amucNIijB6THqIZZsUIfaAAAAIc"]
[Thu Jul 30 13:47:16.329556 2026] [security2:error] [pid 935860:tid 936011] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucNIijB6THqIZZsUIfZQAAAJk"]
[Thu Jul 30 13:47:16.343662 2026] [security2:error] [pid 935860:tid 935947] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/settings.php.save%5f%5f"] [unique_id "amucNIijB6THqIZZsUIfagAAx1U"]
[Thu Jul 30 13:47:16.473042 2026] [security2:error] [pid 935860:tid 935988] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/settings.php.save%29"] [unique_id "amucNIijB6THqIZZsUIfbgAAnH4"]
[Thu Jul 30 13:47:16.563663 2026] [core:notice] [pid 935860:tid 936060] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:16.568568 2026] [security2:error] [pid 935860:tid 936074] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucNIijB6THqIZZsUIfbQAAANg"]
[Thu Jul 30 13:47:16.602092 2026] [security2:error] [pid 935860:tid 935916] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/settings.php.save.aws"] [unique_id "amucNIijB6THqIZZsUIfcAAAtTY"]
[Thu Jul 30 13:47:16.635269 2026] [security2:error] [pid 935860:tid 936094] [client 181.116.200.68:48699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucNIijB6THqIZZsUIfcQAAAOw"]
[Thu Jul 30 13:47:16.635386 2026] [security2:error] [pid 935860:tid 936094] [client 181.116.200.68:48699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucNIijB6THqIZZsUIfcQAAAOw"]
[Thu Jul 30 13:47:16.698795 2026] [security2:error] [pid 935860:tid 936035] [client 20.125.96.254:1396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.espairsa.com"] [uri "/666.php"] [unique_id "amucNIijB6THqIZZsUIfdgAAALE"]
[Thu Jul 30 13:47:16.698937 2026] [security2:error] [pid 935860:tid 936035] [client 20.125.96.254:1396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.espairsa.com"] [uri "/666.php"] [unique_id "amucNIijB6THqIZZsUIfdgAAALE"]
[Thu Jul 30 13:47:16.806122 2026] [security2:error] [pid 935860:tid 936105] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucNIijB6THqIZZsUIfdQAAAPc"]
[Thu Jul 30 13:47:16.896403 2026] [security2:error] [pid 935860:tid 936055] [client 103.190.40.154:22837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucNIijB6THqIZZsUIfgQAAAMU"]
[Thu Jul 30 13:47:16.896529 2026] [security2:error] [pid 935860:tid 936055] [client 103.190.40.154:22837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucNIijB6THqIZZsUIfgQAAAMU"]
[Thu Jul 30 13:47:17.024193 2026] [security2:error] [pid 935860:tid 936110] [client 20.171.55.167:9706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/admin-post.php"] [unique_id "amucNYijB6THqIZZsUIfhgAAAPw"]
[Thu Jul 30 13:47:17.040237 2026] [security2:error] [pid 935860:tid 936118] [client 185.177.72.22:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucNIijB6THqIZZsUIfhQAAAQQ"]
[Thu Jul 30 13:47:17.168411 2026] [security2:error] [pid 935860:tid 935995] [client 185.177.72.22:61294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/backup.sql"] [unique_id "amucNYijB6THqIZZsUIfiQAAAIk"]
[Thu Jul 30 13:47:17.292009 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:61294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/backup.sql.php"] [unique_id "amucNYijB6THqIZZsUIfjwAAAOU"]
[Thu Jul 30 13:47:17.364831 2026] [security2:error] [pid 935860:tid 935902] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucNYijB6THqIZZsUIfkwAA0ig"]
[Thu Jul 30 13:47:17.660342 2026] [security2:error] [pid 935860:tid 936037] [client 185.177.72.22:19824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucNYijB6THqIZZsUIfmQAAALM"]
[Thu Jul 30 13:47:17.660549 2026] [security2:error] [pid 935860:tid 935900] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucNYijB6THqIZZsUIfmgAAuCY"]
[Thu Jul 30 13:47:17.710465 2026] [core:notice] [pid 935860:tid 935918] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:17.744804 2026] [security2:error] [pid 935860:tid 936046] [client 20.171.55.167:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "amucNYijB6THqIZZsUIfnAAAALw"]
[Thu Jul 30 13:47:17.900863 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:19824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucNYijB6THqIZZsUIfoAAAANk"]
[Thu Jul 30 13:47:18.470512 2026] [security2:error] [pid 935860:tid 935999] [client 20.171.55.167:9798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/dropdown.php"] [unique_id "amucNoijB6THqIZZsUIfuwAAAI0"]
[Thu Jul 30 13:47:18.548079 2026] [security2:error] [pid 935860:tid 935991] [client 185.177.72.22:19824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucNoijB6THqIZZsUIfvwAAAIU"]
[Thu Jul 30 13:47:18.798089 2026] [security2:error] [pid 935860:tid 936063] [client 185.177.72.22:19834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php%255f"] [unique_id "amucNoijB6THqIZZsUIfxAAAAM0"]
[Thu Jul 30 13:47:19.054818 2026] [security2:error] [pid 935860:tid 936005] [client 185.177.72.22:19838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php%255d"] [unique_id "amucN4ijB6THqIZZsUIf0AAAAJM"]
[Thu Jul 30 13:47:19.185922 2026] [security2:error] [pid 935860:tid 936001] [client 20.171.55.167:9638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/index.php"] [unique_id "amucN4ijB6THqIZZsUIf1AAAAI8"]
[Thu Jul 30 13:47:19.217274 2026] [security2:error] [pid 935860:tid 935886] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/database.sql"] [unique_id "amucN4ijB6THqIZZsUIf2AABARg"]
[Thu Jul 30 13:47:19.308671 2026] [security2:error] [pid 935860:tid 936012] [client 185.177.72.22:19854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php.aws"] [unique_id "amucN4ijB6THqIZZsUIf3AAAAJo"]
[Thu Jul 30 13:47:19.678662 2026] [security2:error] [pid 935860:tid 936013] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucN4ijB6THqIZZsUIf5QAAAJs"]
[Thu Jul 30 13:47:19.909860 2026] [security2:error] [pid 935860:tid 936019] [client 20.171.55.167:9671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/dropdown.php"] [unique_id "amucN4ijB6THqIZZsUIf8QAAAKE"]
[Thu Jul 30 13:47:19.920391 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucN4ijB6THqIZZsUIf6wAAANk"]
[Thu Jul 30 13:47:20.158180 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOIijB6THqIZZsUIf9wAAAMc"]
[Thu Jul 30 13:47:20.398300 2026] [security2:error] [pid 935860:tid 936077] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOIijB6THqIZZsUIgAAAAANs"]
[Thu Jul 30 13:47:20.471041 2026] [core:notice] [pid 935860:tid 936093] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:20.625399 2026] [security2:error] [pid 935860:tid 936074] [client 20.171.55.167:9832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/about.php"] [unique_id "amucOIijB6THqIZZsUIgFQAAANg"]
[Thu Jul 30 13:47:20.962614 2026] [security2:error] [pid 935860:tid 936044] [client 172.237.109.114:21865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgIwAAALo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.963126 2026] [security2:error] [pid 935860:tid 936115] [client 172.237.109.114:30016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgJAAAAQE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.963872 2026] [security2:error] [pid 935860:tid 936115] [client 172.237.109.114:14913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgJQAAAQE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.969708 2026] [security2:error] [pid 935860:tid 936012] [client 172.237.109.114:31228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgJgAAAJo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.971216 2026] [security2:error] [pid 935860:tid 936070] [client 172.237.109.114:26306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgJwAAANQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.971294 2026] [security2:error] [pid 935860:tid 936070] [client 172.237.109.114:26306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgJwAAANQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.972473 2026] [security2:error] [pid 935860:tid 936056] [client 172.237.109.114:4847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgKAAAAMY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.972587 2026] [security2:error] [pid 935860:tid 936036] [client 172.237.109.114:14716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgKQAAALI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.973463 2026] [security2:error] [pid 935860:tid 936034] [client 172.237.109.114:19189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgKgAAALA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.974023 2026] [security2:error] [pid 935860:tid 936087] [client 172.237.109.114:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgKwAAAOU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.974050 2026] [security2:error] [pid 935860:tid 936089] [client 172.237.109.114:16670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgLAAAAOc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.978941 2026] [security2:error] [pid 935860:tid 936022] [client 172.237.109.114:36395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgLQAAAKQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.991318 2026] [security2:error] [pid 935860:tid 935998] [client 172.237.109.114:30551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgLwAAAIw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.991906 2026] [security2:error] [pid 935860:tid 936078] [client 172.237.109.114:29799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgMQAAANw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.991934 2026] [security2:error] [pid 935860:tid 936041] [client 172.237.109.114:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgMAAAALc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.992244 2026] [security2:error] [pid 935860:tid 936076] [client 172.237.109.114:44840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgMgAAANo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.992309 2026] [security2:error] [pid 935860:tid 936076] [client 172.237.109.114:44840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgMgAAANo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:20.994210 2026] [security2:error] [pid 935860:tid 936029] [client 172.237.109.114:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOIijB6THqIZZsUIgMwAAAKs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:21.009498 2026] [security2:error] [pid 935860:tid 936084] [client 172.237.109.114:48746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOYijB6THqIZZsUIgNAAAAOI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:21.010244 2026] [security2:error] [pid 935860:tid 936068] [client 172.237.109.114:3643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOYijB6THqIZZsUIgNQAAANI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:21.011482 2026] [security2:error] [pid 935860:tid 936004] [client 172.237.109.114:60129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOYijB6THqIZZsUIgNgAAAJI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:21.011898 2026] [security2:error] [pid 935860:tid 936027] [client 172.237.109.114:45193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucOYijB6THqIZZsUIgNwAAAKk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:21.148493 2026] [security2:error] [pid 935860:tid 936051] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOYijB6THqIZZsUIgOAAAAME"]
[Thu Jul 30 13:47:21.347605 2026] [security2:error] [pid 935860:tid 936107] [client 20.171.55.167:9645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/about.php7"] [unique_id "amucOYijB6THqIZZsUIgRgAAAPk"]
[Thu Jul 30 13:47:21.397284 2026] [security2:error] [pid 935860:tid 935993] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOYijB6THqIZZsUIgRQAAAIc"]
[Thu Jul 30 13:47:21.638662 2026] [security2:error] [pid 935860:tid 936043] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOYijB6THqIZZsUIgTwAAALk"]
[Thu Jul 30 13:47:21.883181 2026] [security2:error] [pid 935860:tid 936038] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOYijB6THqIZZsUIgXQAAALQ"]
[Thu Jul 30 13:47:22.061092 2026] [security2:error] [pid 935860:tid 935991] [client 216.244.66.196:40908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amucOoijB6THqIZZsUIgZgAAAIU"]
[Thu Jul 30 13:47:22.061248 2026] [security2:error] [pid 935860:tid 935991] [client 216.244.66.196:40908] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amucOoijB6THqIZZsUIgZgAAAIU"]
[Thu Jul 30 13:47:22.063711 2026] [security2:error] [pid 935860:tid 936091] [client 20.171.55.167:9705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/alfanew.php7"] [unique_id "amucOoijB6THqIZZsUIgZwAAAOk"]
[Thu Jul 30 13:47:22.125111 2026] [security2:error] [pid 935860:tid 935997] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOoijB6THqIZZsUIgYwAAAIs"]
[Thu Jul 30 13:47:22.366636 2026] [security2:error] [pid 935860:tid 936089] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOoijB6THqIZZsUIgcgAAAOc"]
[Thu Jul 30 13:47:22.604643 2026] [security2:error] [pid 935860:tid 936006] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOoijB6THqIZZsUIgegAAAJQ"]
[Thu Jul 30 13:47:22.793644 2026] [security2:error] [pid 935860:tid 936020] [client 20.171.55.167:9808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/adminfuns.php7"] [unique_id "amucOoijB6THqIZZsUIghgAAAKI"]
[Thu Jul 30 13:47:22.850548 2026] [security2:error] [pid 935860:tid 936066] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOoijB6THqIZZsUIgggAAANA"]
[Thu Jul 30 13:47:23.098630 2026] [security2:error] [pid 935860:tid 936080] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucOoijB6THqIZZsUIgigAAAN4"]
[Thu Jul 30 13:47:23.337219 2026] [core:notice] [pid 935860:tid 936033] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:23.345488 2026] [security2:error] [pid 935860:tid 936111] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucO4ijB6THqIZZsUIglQAAAP0"]
[Thu Jul 30 13:47:23.809228 2026] [security2:error] [pid 935860:tid 936104] [client 103.242.199.184:63923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucO4ijB6THqIZZsUIgrgAAAPY"]
[Thu Jul 30 13:47:23.809342 2026] [security2:error] [pid 935860:tid 936104] [client 103.242.199.184:63923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucO4ijB6THqIZZsUIgrgAAAPY"]
[Thu Jul 30 13:47:24.006655 2026] [security2:error] [pid 935860:tid 936102] [client 20.171.55.167:9604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/ebs.php7"] [unique_id "amucPIijB6THqIZZsUIgtAAAAPQ"]
[Thu Jul 30 13:47:24.884547 2026] [security2:error] [pid 935860:tid 936000] [client 20.171.55.167:9606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/ws.php7"] [unique_id "amucPIijB6THqIZZsUIg2QAAAI4"]
[Thu Jul 30 13:47:25.100368 2026] [security2:error] [pid 935860:tid 936083] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucPIijB6THqIZZsUIg2wAAAOE"]
[Thu Jul 30 13:47:25.341557 2026] [security2:error] [pid 935860:tid 936033] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucPYijB6THqIZZsUIg4gAAAK8"]
[Thu Jul 30 13:47:25.610897 2026] [security2:error] [pid 935860:tid 936043] [client 20.171.55.167:9656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/alfanew2.php7"] [unique_id "amucPYijB6THqIZZsUIg9AAAALk"]
[Thu Jul 30 13:47:25.707936 2026] [security2:error] [pid 935860:tid 936040] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucPYijB6THqIZZsUIg8QAAALY"]
[Thu Jul 30 13:47:25.820750 2026] [security2:error] [pid 935860:tid 936054] [client 78.167.1.90:56701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucPYijB6THqIZZsUIg_QAAAMQ"]
[Thu Jul 30 13:47:25.821345 2026] [security2:error] [pid 935860:tid 936054] [client 78.167.1.90:56701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucPYijB6THqIZZsUIg_QAAAMQ"]
[Thu Jul 30 13:47:25.937318 2026] [core:notice] [pid 935860:tid 936096] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:25.951497 2026] [security2:error] [pid 935860:tid 936118] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucPYijB6THqIZZsUIg_gAAAQQ"]
[Thu Jul 30 13:47:26.109844 2026] [security2:error] [pid 935860:tid 935971] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucPoijB6THqIZZsUIhCQAAmm0"]
[Thu Jul 30 13:47:26.125255 2026] [security2:error] [pid 935860:tid 936103] [client 216.244.66.236:38524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amucPoijB6THqIZZsUIhCgAAAPU"]
[Thu Jul 30 13:47:26.125398 2026] [security2:error] [pid 935860:tid 936103] [client 216.244.66.236:38524] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amucPoijB6THqIZZsUIhCgAAAPU"]
[Thu Jul 30 13:47:26.193458 2026] [security2:error] [pid 935860:tid 936050] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucPoijB6THqIZZsUIhCAAAAMA"]
[Thu Jul 30 13:47:26.240430 2026] [security2:error] [pid 935860:tid 935947] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env%5e"] [unique_id "amucPoijB6THqIZZsUIhCwAAiFU"]
[Thu Jul 30 13:47:26.315035 2026] [security2:error] [pid 935860:tid 936036] [client 20.171.55.167:9643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/alfa-rex2.php7"] [unique_id "amucPoijB6THqIZZsUIhDAAAALI"]
[Thu Jul 30 13:47:26.433716 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucPoijB6THqIZZsUIhDgAAAOU"]
[Thu Jul 30 13:47:26.671940 2026] [security2:error] [pid 935860:tid 936020] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucPoijB6THqIZZsUIhGwAAAKI"]
[Thu Jul 30 13:47:26.911878 2026] [security2:error] [pid 935860:tid 936013] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucPoijB6THqIZZsUIhIgAAAJs"]
[Thu Jul 30 13:47:26.993413 2026] [core:notice] [pid 935860:tid 936075] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:27.026582 2026] [security2:error] [pid 935860:tid 935996] [client 20.171.55.167:9824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/images/index.php"] [unique_id "amucP4ijB6THqIZZsUIhLgAAAIo"]
[Thu Jul 30 13:47:27.148373 2026] [security2:error] [pid 935860:tid 936073] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucP4ijB6THqIZZsUIhLwAAANc"]
[Thu Jul 30 13:47:27.265326 2026] [security2:error] [pid 935860:tid 936109] [client 181.116.200.68:34155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucP4ijB6THqIZZsUIhNQAAAPs"]
[Thu Jul 30 13:47:27.265448 2026] [security2:error] [pid 935860:tid 936109] [client 181.116.200.68:34155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucP4ijB6THqIZZsUIhNQAAAPs"]
[Thu Jul 30 13:47:27.390553 2026] [security2:error] [pid 935860:tid 936077] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucP4ijB6THqIZZsUIhNgAAANs"]
[Thu Jul 30 13:47:27.504283 2026] [security2:error] [pid 935860:tid 935993] [client 85.208.96.205:33410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/politica/filter_by-review_high/"] [unique_id "amucP4ijB6THqIZZsUIhQQAAAIc"]
[Thu Jul 30 13:47:27.504412 2026] [security2:error] [pid 935860:tid 935993] [client 85.208.96.205:33410] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/politica/filter_by-review_high/"] [unique_id "amucP4ijB6THqIZZsUIhQQAAAIc"]
[Thu Jul 30 13:47:27.561961 2026] [security2:error] [pid 935860:tid 936095] [client 103.190.40.154:21137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucP4ijB6THqIZZsUIhQwAAAO0"]
[Thu Jul 30 13:47:27.562138 2026] [security2:error] [pid 935860:tid 936095] [client 103.190.40.154:21137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucP4ijB6THqIZZsUIhQwAAAO0"]
[Thu Jul 30 13:47:27.630022 2026] [security2:error] [pid 935860:tid 936026] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucP4ijB6THqIZZsUIhQgAAAKg"]
[Thu Jul 30 13:47:27.773174 2026] [security2:error] [pid 935860:tid 936055] [client 20.171.55.167:9682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/colors/index.php"] [unique_id "amucP4ijB6THqIZZsUIhSgAAAMU"]
[Thu Jul 30 13:47:27.870513 2026] [security2:error] [pid 935860:tid 936110] [client 185.177.72.22:19862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucP4ijB6THqIZZsUIhSQAAAPw"]
[Thu Jul 30 13:47:27.997218 2026] [security2:error] [pid 935860:tid 936102] [client 185.177.72.22:19862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/settings.php.save"] [unique_id "amucP4ijB6THqIZZsUIhVQAAAPQ"]
[Thu Jul 30 13:47:28.112202 2026] [security2:error] [pid 935860:tid 935969] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/_profiler%00"] [unique_id "amucQIijB6THqIZZsUIhVgAAn2s"]
[Thu Jul 30 13:47:28.247492 2026] [security2:error] [pid 935860:tid 936070] [client 185.177.72.22:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/settings.php.save%5f%5f"] [unique_id "amucQIijB6THqIZZsUIhXgAAANQ"]
[Thu Jul 30 13:47:28.479835 2026] [security2:error] [pid 935860:tid 936036] [client 20.171.55.167:9658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amucQIijB6THqIZZsUIhZgAAALI"]
[Thu Jul 30 13:47:28.516050 2026] [security2:error] [pid 935860:tid 936113] [client 185.177.72.22:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/settings.php.save%29"] [unique_id "amucQIijB6THqIZZsUIhagAAAP8"]
[Thu Jul 30 13:47:28.771471 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:58224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/settings.php.save.aws"] [unique_id "amucQIijB6THqIZZsUIhdQAAANk"]
[Thu Jul 30 13:47:28.993192 2026] [core:notice] [pid 935860:tid 936018] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:29.027331 2026] [security2:error] [pid 935860:tid 936020] [client 216.244.66.236:38536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amucQYijB6THqIZZsUIhgAAAAKI"]
[Thu Jul 30 13:47:29.027443 2026] [security2:error] [pid 935860:tid 936020] [client 216.244.66.236:38536] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amucQYijB6THqIZZsUIhgAAAAKI"]
[Thu Jul 30 13:47:29.142127 2026] [security2:error] [pid 935860:tid 936060] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQYijB6THqIZZsUIhfwAAAMo"]
[Thu Jul 30 13:47:29.191525 2026] [security2:error] [pid 935860:tid 936083] [client 20.171.55.167:9619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "amucQYijB6THqIZZsUIhhwAAAOE"]
[Thu Jul 30 13:47:29.383879 2026] [security2:error] [pid 935860:tid 935993] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQYijB6THqIZZsUIhiAAAAIc"]
[Thu Jul 30 13:47:29.528183 2026] [security2:error] [pid 935860:tid 936104] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.germanyvisasupportcenterislamabad.website"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amucQYijB6THqIZZsUIhlAAAAPY"]
[Thu Jul 30 13:47:29.624515 2026] [security2:error] [pid 935860:tid 936052] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQYijB6THqIZZsUIhkwAAAMI"]
[Thu Jul 30 13:47:29.870200 2026] [security2:error] [pid 935860:tid 936096] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQYijB6THqIZZsUIhngAAAO4"]
[Thu Jul 30 13:47:29.911256 2026] [security2:error] [pid 935860:tid 936091] [client 20.171.55.167:9634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amucQYijB6THqIZZsUIhpAAAAOk"]
[Thu Jul 30 13:47:29.999032 2026] [security2:error] [pid 935860:tid 936068] [client 185.177.72.22:58240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucQYijB6THqIZZsUIhpwAAANI"]
[Thu Jul 30 13:47:30.244194 2026] [security2:error] [pid 935860:tid 936085] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQoijB6THqIZZsUIhrgAAAOM"]
[Thu Jul 30 13:47:30.293198 2026] [core:notice] [pid 935860:tid 936097] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:30.373074 2026] [security2:error] [pid 935860:tid 936049] [client 185.177.72.22:58240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucQoijB6THqIZZsUIhtwAAAL8"]
[Thu Jul 30 13:47:30.642492 2026] [security2:error] [pid 935860:tid 936037] [client 20.171.55.167:10163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "amucQoijB6THqIZZsUIhxAAAALM"]
[Thu Jul 30 13:47:30.745395 2026] [security2:error] [pid 935860:tid 936086] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQoijB6THqIZZsUIhwAAAAOQ"]
[Thu Jul 30 13:47:30.987676 2026] [security2:error] [pid 935860:tid 936081] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQoijB6THqIZZsUIhywAAAN8"]
[Thu Jul 30 13:47:31.229959 2026] [security2:error] [pid 935860:tid 935992] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQ4ijB6THqIZZsUIh1AAAAIY"]
[Thu Jul 30 13:47:31.355802 2026] [security2:error] [pid 935860:tid 936092] [client 20.171.55.167:9718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "amucQ4ijB6THqIZZsUIh2gAAAOo"]
[Thu Jul 30 13:47:31.472496 2026] [security2:error] [pid 935860:tid 936038] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQ4ijB6THqIZZsUIh2wAAALQ"]
[Thu Jul 30 13:47:31.714605 2026] [security2:error] [pid 935860:tid 936118] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQ4ijB6THqIZZsUIh4wAAAQQ"]
[Thu Jul 30 13:47:31.953749 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucQ4ijB6THqIZZsUIh8wAAAOU"]
[Thu Jul 30 13:47:31.982961 2026] [core:notice] [pid 935860:tid 936113] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:32.042421 2026] [core:notice] [pid 935860:tid 936005] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:32.084234 2026] [security2:error] [pid 935860:tid 936089] [client 20.171.55.167:9669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/xmrlpc.php"] [unique_id "amucRIijB6THqIZZsUIh_AAAAOc"]
[Thu Jul 30 13:47:32.199964 2026] [security2:error] [pid 935860:tid 936042] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRIijB6THqIZZsUIh-wAAALg"]
[Thu Jul 30 13:47:32.448549 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRIijB6THqIZZsUIiBwAAANk"]
[Thu Jul 30 13:47:32.537226 2026] [security2:error] [pid 935860:tid 936078] [client 172.237.109.114:27149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amucQ4ijB6THqIZZsUIh9gAAANw"]
[Thu Jul 30 13:47:32.579025 2026] [security2:error] [pid 935860:tid 936009] [client 185.177.72.22:58240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/database.sql"] [unique_id "amucRIijB6THqIZZsUIiDgAAAJc"]
[Thu Jul 30 13:47:32.643268 2026] [security2:error] [pid 935860:tid 935908] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/erp~"] [unique_id "amucRIijB6THqIZZsUIiEAAA7C4"]
[Thu Jul 30 13:47:32.684957 2026] [security2:error] [pid 935860:tid 935917] [remote 74.7.243.224:35816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/article.php"] [unique_id "amucRIijB6THqIZZsUIiEwAA8zc"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 13:47:32.809073 2026] [security2:error] [pid 935860:tid 936014] [client 20.171.55.167:9630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amucRIijB6THqIZZsUIiGwAAAJw"]
[Thu Jul 30 13:47:32.823565 2026] [security2:error] [pid 935860:tid 936109] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRIijB6THqIZZsUIiFQAAAPs"]
[Thu Jul 30 13:47:33.066768 2026] [security2:error] [pid 935860:tid 935993] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRIijB6THqIZZsUIiHgAAAIc"]
[Thu Jul 30 13:47:33.308968 2026] [security2:error] [pid 935860:tid 936104] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRYijB6THqIZZsUIiKAAAAPY"]
[Thu Jul 30 13:47:33.552740 2026] [security2:error] [pid 935860:tid 936017] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRYijB6THqIZZsUIiMAAAAJ8"]
[Thu Jul 30 13:47:33.570528 2026] [security2:error] [pid 935860:tid 936082] [client 20.171.55.167:9600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/css/xmrlpc.php"] [unique_id "amucRYijB6THqIZZsUIiNgAAAOA"]
[Thu Jul 30 13:47:33.796796 2026] [security2:error] [pid 935860:tid 936084] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRYijB6THqIZZsUIiNwAAAOI"]
[Thu Jul 30 13:47:34.167402 2026] [security2:error] [pid 935860:tid 936000] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRoijB6THqIZZsUIiUgAAAI4"]
[Thu Jul 30 13:47:34.298558 2026] [security2:error] [pid 935860:tid 936046] [client 20.171.55.167:9468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amucRoijB6THqIZZsUIiWAAAALw"]
[Thu Jul 30 13:47:34.414737 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRoijB6THqIZZsUIiWQAAANk"]
[Thu Jul 30 13:47:34.433625 2026] [security2:error] [pid 935860:tid 936073] [client 167.71.25.206:35704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "03.adtop.net"] [uri "/"] [unique_id "amucRoijB6THqIZZsUIiYAAAANc"]
[Thu Jul 30 13:47:34.455482 2026] [security2:error] [pid 935860:tid 936101] [client 103.242.199.184:64484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucRoijB6THqIZZsUIiYQAAAPM"]
[Thu Jul 30 13:47:34.456231 2026] [security2:error] [pid 935860:tid 936101] [client 103.242.199.184:64484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucRoijB6THqIZZsUIiYQAAAPM"]
[Thu Jul 30 13:47:34.504955 2026] [security2:error] [pid 935860:tid 935881] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/prod.htaccess"] [unique_id "amucRoijB6THqIZZsUIiZAAA4RM"]
[Thu Jul 30 13:47:34.631825 2026] [security2:error] [pid 935860:tid 935879] [remote 57.141.0.28:39068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/24984966950/feed/rss2/"] [unique_id "amucRoijB6THqIZZsUIiaAAArxE"]
[Thu Jul 30 13:47:34.668569 2026] [security2:error] [pid 935860:tid 936023] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRoijB6THqIZZsUIiZwAAAKU"]
[Thu Jul 30 13:47:34.859680 2026] [core:notice] [pid 935860:tid 936010] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:34.912033 2026] [security2:error] [pid 935860:tid 936021] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucRoijB6THqIZZsUIicAAAAKM"]
[Thu Jul 30 13:47:35.033937 2026] [security2:error] [pid 935860:tid 936092] [client 20.171.55.167:9613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/img/xmrlpc.php"] [unique_id "amucR4ijB6THqIZZsUIiegAAAOo"]
[Thu Jul 30 13:47:35.156877 2026] [security2:error] [pid 935860:tid 936106] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucR4ijB6THqIZZsUIiewAAAPg"]
[Thu Jul 30 13:47:35.331924 2026] [security2:error] [pid 935860:tid 935994] [client 78.167.1.90:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucR4ijB6THqIZZsUIigwAAAIg"]
[Thu Jul 30 13:47:35.332792 2026] [security2:error] [pid 935860:tid 935994] [client 78.167.1.90:56262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucR4ijB6THqIZZsUIigwAAAIg"]
[Thu Jul 30 13:47:35.401518 2026] [security2:error] [pid 935860:tid 936096] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucR4ijB6THqIZZsUIigAAAAO4"]
[Thu Jul 30 13:47:35.651147 2026] [security2:error] [pid 935860:tid 936115] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucR4ijB6THqIZZsUIijwAAAQE"]
[Thu Jul 30 13:47:35.826275 2026] [security2:error] [pid 935860:tid 936069] [client 20.171.55.167:9651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "amucR4ijB6THqIZZsUIilwAAANM"]
[Thu Jul 30 13:47:35.895250 2026] [security2:error] [pid 935860:tid 936071] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucR4ijB6THqIZZsUIilQAAANU"]
[Thu Jul 30 13:47:36.141765 2026] [security2:error] [pid 935860:tid 936011] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSIijB6THqIZZsUIioAAAAJk"]
[Thu Jul 30 13:47:36.382065 2026] [security2:error] [pid 935860:tid 936107] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSIijB6THqIZZsUIiqAAAAPk"]
[Thu Jul 30 13:47:36.558198 2026] [security2:error] [pid 935860:tid 936078] [client 20.171.55.167:9672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "amucSIijB6THqIZZsUIitQAAANw"]
[Thu Jul 30 13:47:36.626201 2026] [security2:error] [pid 935860:tid 936014] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSIijB6THqIZZsUIisQAAAJw"]
[Thu Jul 30 13:47:36.684015 2026] [security2:error] [pid 935860:tid 935961] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env.old"] [unique_id "amucSIijB6THqIZZsUIiuQAAxGM"]
[Thu Jul 30 13:47:36.869773 2026] [security2:error] [pid 935860:tid 936053] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSIijB6THqIZZsUIiugAAAMM"]
[Thu Jul 30 13:47:37.111066 2026] [security2:error] [pid 935860:tid 936060] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSIijB6THqIZZsUIixQAAAMo"]
[Thu Jul 30 13:47:37.299126 2026] [security2:error] [pid 935860:tid 936029] [client 20.171.55.167:9609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/images/xmrlpc.php"] [unique_id "amucSYijB6THqIZZsUIi1wAAAKs"]
[Thu Jul 30 13:47:37.848604 2026] [security2:error] [pid 935860:tid 936079] [client 181.116.200.68:49610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucSYijB6THqIZZsUIi7QAAAN0"]
[Thu Jul 30 13:47:37.849298 2026] [security2:error] [pid 935860:tid 936079] [client 181.116.200.68:49610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucSYijB6THqIZZsUIi7QAAAN0"]
[Thu Jul 30 13:47:37.873180 2026] [security2:error] [pid 935860:tid 936086] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSYijB6THqIZZsUIi6gAAAOQ"]
[Thu Jul 30 13:47:37.966462 2026] [security2:error] [pid 935860:tid 936023] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucSYijB6THqIZZsUIi1QAApXI"]
[Thu Jul 30 13:47:38.024380 2026] [security2:error] [pid 935860:tid 936075] [client 20.171.55.167:9674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "amucSoijB6THqIZZsUIi9AAAANk"]
[Thu Jul 30 13:47:38.117960 2026] [security2:error] [pid 935860:tid 936043] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSoijB6THqIZZsUIi8wAAALk"]
[Thu Jul 30 13:47:38.358291 2026] [security2:error] [pid 935860:tid 935992] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSoijB6THqIZZsUIi_wAAAIY"]
[Thu Jul 30 13:47:38.361997 2026] [security2:error] [pid 935860:tid 936001] [client 103.190.40.154:8179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucSoijB6THqIZZsUIjAAAAAI8"]
[Thu Jul 30 13:47:38.362176 2026] [security2:error] [pid 935860:tid 936001] [client 103.190.40.154:8179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucSoijB6THqIZZsUIjAAAAAI8"]
[Thu Jul 30 13:47:38.601415 2026] [security2:error] [pid 935860:tid 936053] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSoijB6THqIZZsUIjBgAAAMM"]
[Thu Jul 30 13:47:38.757632 2026] [security2:error] [pid 935860:tid 936015] [client 20.171.55.167:9703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "amucSoijB6THqIZZsUIjEwAAAJ0"]
[Thu Jul 30 13:47:38.842726 2026] [security2:error] [pid 935860:tid 936062] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSoijB6THqIZZsUIjEgAAAMw"]
[Thu Jul 30 13:47:38.864574 2026] [security2:error] [pid 935860:tid 935929] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/settings.swp"] [unique_id "amucSoijB6THqIZZsUIjFAAAhUM"]
[Thu Jul 30 13:47:39.099482 2026] [security2:error] [pid 935860:tid 936084] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucSoijB6THqIZZsUIjFwAAAOI"]
[Thu Jul 30 13:47:39.153731 2026] [security2:error] [pid 935860:tid 935931] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env.swp"] [unique_id "amucS4ijB6THqIZZsUIjHgAAoUU"]
[Thu Jul 30 13:47:39.340364 2026] [security2:error] [pid 935860:tid 936036] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucS4ijB6THqIZZsUIjIgAAALI"]
[Thu Jul 30 13:47:39.490419 2026] [security2:error] [pid 935860:tid 936090] [client 20.171.55.167:9601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "amucS4ijB6THqIZZsUIjLwAAAOg"]
[Thu Jul 30 13:47:39.579305 2026] [security2:error] [pid 935860:tid 936046] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucS4ijB6THqIZZsUIjLQAAALw"]
[Thu Jul 30 13:47:39.606663 2026] [core:notice] [pid 935860:tid 936011] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:39.758341 2026] [security2:error] [pid 935860:tid 935928] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.EnV"] [unique_id "amucS4ijB6THqIZZsUIjPgAA20I"]
[Thu Jul 30 13:47:39.819652 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucS4ijB6THqIZZsUIjOwAAANk"]
[Thu Jul 30 13:47:40.202248 2026] [security2:error] [pid 935860:tid 935890] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.EnV^"] [unique_id "amucTIijB6THqIZZsUIjUQAA2hw"]
[Thu Jul 30 13:47:40.355079 2026] [core:notice] [pid 935860:tid 936112] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:40.522841 2026] [security2:error] [pid 935860:tid 936064] [client 20.171.55.167:9627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "amucTIijB6THqIZZsUIjXgAAAM4"]
[Thu Jul 30 13:47:40.649045 2026] [security2:error] [pid 935860:tid 935965] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/authui.htaccess"] [unique_id "amucTIijB6THqIZZsUIjZgAAmmc"]
[Thu Jul 30 13:47:40.938877 2026] [security2:error] [pid 935860:tid 935958] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/test2.php"] [unique_id "amucTIijB6THqIZZsUIjbgAAs2A"]
[Thu Jul 30 13:47:40.964500 2026] [security2:error] [pid 935860:tid 936035] [client 172.237.109.114:55487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTIijB6THqIZZsUIjbwAAALE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:40.964593 2026] [security2:error] [pid 935860:tid 936035] [client 172.237.109.114:55487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTIijB6THqIZZsUIjbwAAALE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:40.992609 2026] [security2:error] [pid 935860:tid 936049] [client 172.237.109.114:22956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTIijB6THqIZZsUIjcQAAAL8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.067404 2026] [security2:error] [pid 935860:tid 935989] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/test2.php%2e%2e%2f%2e%2e%2f"] [unique_id "amucTYijB6THqIZZsUIjdAAArn8"]
[Thu Jul 30 13:47:41.099406 2026] [security2:error] [pid 935860:tid 936056] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucTIijB6THqIZZsUIjcAAAAMY"]
[Thu Jul 30 13:47:41.197472 2026] [security2:error] [pid 935860:tid 935986] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/test2.php.well-known"] [unique_id "amucTYijB6THqIZZsUIjeQAApXw"]
[Thu Jul 30 13:47:41.225867 2026] [core:notice] [pid 935860:tid 936111] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:41.328486 2026] [security2:error] [pid 935860:tid 935956] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/test2.php//"] [unique_id "amucTYijB6THqIZZsUIjfwAA8l4"]
[Thu Jul 30 13:47:41.344828 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucTYijB6THqIZZsUIjewAAAJY"]
[Thu Jul 30 13:47:41.405322 2026] [security2:error] [pid 935860:tid 936079] [client 20.171.55.167:9754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/xmrlpc.php"] [unique_id "amucTYijB6THqIZZsUIjgAAAAN0"]
[Thu Jul 30 13:47:41.458419 2026] [security2:error] [pid 935860:tid 935980] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/config.php.bak"] [unique_id "amucTYijB6THqIZZsUIjgQAA33Y"]
[Thu Jul 30 13:47:41.588703 2026] [security2:error] [pid 935860:tid 935978] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/config.php.bak%257d"] [unique_id "amucTYijB6THqIZZsUIjhgAA23Q"]
[Thu Jul 30 13:47:41.589945 2026] [security2:error] [pid 935860:tid 936114] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucTYijB6THqIZZsUIjggAAAQA"]
[Thu Jul 30 13:47:41.719258 2026] [security2:error] [pid 935860:tid 935966] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/ConFig.Php.bak"] [unique_id "amucTYijB6THqIZZsUIjigAA7Wg"]
[Thu Jul 30 13:47:41.833362 2026] [security2:error] [pid 935860:tid 936055] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucTYijB6THqIZZsUIjiwAAAMU"]
[Thu Jul 30 13:47:41.848843 2026] [security2:error] [pid 935860:tid 935873] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/config.php.bak%0d"] [unique_id "amucTYijB6THqIZZsUIjjQAAlAs"]
[Thu Jul 30 13:47:41.961892 2026] [security2:error] [pid 935860:tid 936038] [client 172.237.109.114:17766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjnAAAALQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.961968 2026] [security2:error] [pid 935860:tid 936038] [client 172.237.109.114:17766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjnAAAALQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.962544 2026] [security2:error] [pid 935860:tid 936001] [client 172.237.109.114:2282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjnQAAAI8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.970606 2026] [security2:error] [pid 935860:tid 936102] [client 172.237.109.114:7676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjngAAAPQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.970629 2026] [security2:error] [pid 935860:tid 936050] [client 172.237.109.114:1769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjnwAAAMA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.971055 2026] [security2:error] [pid 935860:tid 936105] [client 172.237.109.114:21390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjoAAAAPc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.971120 2026] [security2:error] [pid 935860:tid 936052] [client 172.237.109.114:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjoQAAAMI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.971961 2026] [security2:error] [pid 935860:tid 936082] [client 172.237.109.114:50399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjogAAAOA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.973179 2026] [security2:error] [pid 935860:tid 935998] [client 172.237.109.114:23612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjowAAAIw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.978422 2026] [security2:error] [pid 935860:tid 936110] [client 172.237.109.114:25903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjpQAAAPw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.978450 2026] [security2:error] [pid 935860:tid 936058] [client 172.237.109.114:20799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjpAAAAMg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.990368 2026] [security2:error] [pid 935860:tid 936070] [client 172.237.109.114:49261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjqAAAANQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:41.992307 2026] [security2:error] [pid 935860:tid 936053] [client 172.237.109.114:48198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucTYijB6THqIZZsUIjqQAAAMM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:42.008366 2026] [security2:error] [pid 935860:tid 936041] [client 172.237.109.114:1423] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucToijB6THqIZZsUIjrAAAALc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:42.008474 2026] [security2:error] [pid 935860:tid 936041] [client 172.237.109.114:1423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucToijB6THqIZZsUIjrAAAALc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:42.008652 2026] [security2:error] [pid 935860:tid 936076] [client 172.237.109.114:23640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucToijB6THqIZZsUIjqwAAANo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:42.008684 2026] [security2:error] [pid 935860:tid 936106] [client 172.237.109.114:25281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucToijB6THqIZZsUIjqgAAAPg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:42.009289 2026] [security2:error] [pid 935860:tid 936034] [client 172.237.109.114:57590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucToijB6THqIZZsUIjrQAAALA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:42.009316 2026] [security2:error] [pid 935860:tid 935994] [client 172.237.109.114:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucToijB6THqIZZsUIjrgAAAIg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:42.010247 2026] [security2:error] [pid 935860:tid 936060] [client 172.237.109.114:46909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucToijB6THqIZZsUIjrwAAAMo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:47:42.076190 2026] [security2:error] [pid 935860:tid 936021] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucTYijB6THqIZZsUIjmwAAAKM"]
[Thu Jul 30 13:47:42.127186 2026] [security2:error] [pid 935860:tid 935992] [client 20.171.55.167:9767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/text.php"] [unique_id "amucToijB6THqIZZsUIjtAAAAIY"]
[Thu Jul 30 13:47:42.319908 2026] [security2:error] [pid 935860:tid 936067] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucToijB6THqIZZsUIjvgAAANE"]
[Thu Jul 30 13:47:42.448009 2026] [security2:error] [pid 935860:tid 936036] [client 185.177.72.22:58240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucToijB6THqIZZsUIjxAAAALI"]
[Thu Jul 30 13:47:42.577131 2026] [security2:error] [pid 935860:tid 936090] [client 185.177.72.22:58240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env%5e"] [unique_id "amucToijB6THqIZZsUIjxwAAAOg"]
[Thu Jul 30 13:47:42.628190 2026] [security2:error] [pid 935860:tid 935988] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/app_dev.php"] [unique_id "amucToijB6THqIZZsUIjyAAAl34"]
[Thu Jul 30 13:47:42.757490 2026] [security2:error] [pid 935860:tid 935979] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/app_dev.php%2520"] [unique_id "amucToijB6THqIZZsUIj0AAA4XU"]
[Thu Jul 30 13:47:42.821662 2026] [security2:error] [pid 935860:tid 936063] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucToijB6THqIZZsUIjzAAAAM0"]
[Thu Jul 30 13:47:42.886797 2026] [security2:error] [pid 935860:tid 935871] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/app_dev.php%253f"] [unique_id "amucToijB6THqIZZsUIj0QAArwk"]
[Thu Jul 30 13:47:42.895494 2026] [security2:error] [pid 935860:tid 936023] [client 20.171.55.167:9756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/wp-admin/network/index.php"] [unique_id "amucToijB6THqIZZsUIj0gAAAKU"]
[Thu Jul 30 13:47:43.015705 2026] [security2:error] [pid 935860:tid 935897] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/app_dev.php%2524"] [unique_id "amucT4ijB6THqIZZsUIj1wAAkyM"]
[Thu Jul 30 13:47:43.059769 2026] [security2:error] [pid 935860:tid 936074] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucToijB6THqIZZsUIj1AAAANg"]
[Thu Jul 30 13:47:43.188340 2026] [security2:error] [pid 935860:tid 936006] [client 185.177.72.22:58240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucT4ijB6THqIZZsUIj3QAAAJQ"]
[Thu Jul 30 13:47:43.433534 2026] [security2:error] [pid 935860:tid 936110] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucT4ijB6THqIZZsUIj5QAAAPw"]
[Thu Jul 30 13:47:43.611191 2026] [security2:error] [pid 935860:tid 936076] [client 20.171.55.167:9785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "theregentsbarber.com.au"] [uri "/makeasmtp.php"] [unique_id "amucT4ijB6THqIZZsUIj7AAAANo"]
[Thu Jul 30 13:47:43.679621 2026] [security2:error] [pid 935860:tid 936044] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucT4ijB6THqIZZsUIj6wAAALo"]
[Thu Jul 30 13:47:43.922412 2026] [security2:error] [pid 935860:tid 935992] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucT4ijB6THqIZZsUIj9wAAAIY"]
[Thu Jul 30 13:47:44.167665 2026] [security2:error] [pid 935860:tid 936115] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUIijB6THqIZZsUIj_gAAAQE"]
[Thu Jul 30 13:47:44.291568 2026] [core:notice] [pid 935860:tid 936066] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:44.416524 2026] [security2:error] [pid 935860:tid 936037] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUIijB6THqIZZsUIkCwAAALM"]
[Thu Jul 30 13:47:44.661882 2026] [security2:error] [pid 935860:tid 936013] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUIijB6THqIZZsUIkEgAAAJs"]
[Thu Jul 30 13:47:44.913461 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUIijB6THqIZZsUIkHAAAAJY"]
[Thu Jul 30 13:47:45.160485 2026] [security2:error] [pid 935860:tid 936109] [client 185.177.72.22:58240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUYijB6THqIZZsUIkJQAAAPs"]
[Thu Jul 30 13:47:45.188548 2026] [security2:error] [pid 935860:tid 936007] [client 103.242.199.184:65036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucUYijB6THqIZZsUIkKgAAAJU"]
[Thu Jul 30 13:47:45.188691 2026] [security2:error] [pid 935860:tid 936007] [client 103.242.199.184:65036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucUYijB6THqIZZsUIkKgAAAJU"]
[Thu Jul 30 13:47:45.541544 2026] [security2:error] [pid 935860:tid 936054] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUYijB6THqIZZsUIkOQAAAMQ"]
[Thu Jul 30 13:47:45.671352 2026] [security2:error] [pid 935860:tid 936089] [client 185.177.72.22:34332] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/_profiler%00"] [unique_id "amucUYijB6THqIZZsUIkQQAAAOc"]
[Thu Jul 30 13:47:45.727501 2026] [security2:error] [pid 935860:tid 936075] [client 172.237.109.114:43383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amucUYijB6THqIZZsUIkKAAAANk"]
[Thu Jul 30 13:47:45.901734 2026] [security2:error] [pid 935860:tid 935993] [client 78.167.1.90:55262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucUYijB6THqIZZsUIkVAAAAIc"]
[Thu Jul 30 13:47:45.902135 2026] [security2:error] [pid 935860:tid 935993] [client 78.167.1.90:55262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucUYijB6THqIZZsUIkVAAAAIc"]
[Thu Jul 30 13:47:45.929097 2026] [security2:error] [pid 935860:tid 936091] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUYijB6THqIZZsUIkSAAAAOk"]
[Thu Jul 30 13:47:46.175860 2026] [security2:error] [pid 935860:tid 936031] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUoijB6THqIZZsUIkXQAAAK0"]
[Thu Jul 30 13:47:46.426673 2026] [security2:error] [pid 935860:tid 936046] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUoijB6THqIZZsUIkdQAAALw"]
[Thu Jul 30 13:47:46.680057 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUoijB6THqIZZsUIkgQAAAL0"]
[Thu Jul 30 13:47:46.932535 2026] [security2:error] [pid 935860:tid 935999] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucUoijB6THqIZZsUIkhwAAAI0"]
[Thu Jul 30 13:47:47.182383 2026] [security2:error] [pid 935860:tid 936044] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucU4ijB6THqIZZsUIkmQAAALo"]
[Thu Jul 30 13:47:47.391522 2026] [proxy:error] [pid 935860:tid 936045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:47:47.391595 2026] [proxy_http:error] [pid 935860:tid 936045] [client 18.211.55.47:53297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:47:47.392337 2026] [proxy:error] [pid 935860:tid 936045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:47:47.392403 2026] [proxy_http:error] [pid 935860:tid 936045] [client 18.211.55.47:53297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:47:47.408848 2026] [proxy:error] [pid 935860:tid 936065] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:47:47.408927 2026] [proxy_http:error] [pid 935860:tid 936065] [client 18.211.55.47:1737] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:47:47.409582 2026] [proxy:error] [pid 935860:tid 936065] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:47:47.409663 2026] [proxy_http:error] [pid 935860:tid 936065] [client 18.211.55.47:1737] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:47:47.416160 2026] [autoindex:error] [pid 935860:tid 936115] [client 18.211.55.47:57992] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:47:47.425018 2026] [security2:error] [pid 935860:tid 936040] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucU4ijB6THqIZZsUIkpgAAALY"]
[Thu Jul 30 13:47:47.448090 2026] [autoindex:error] [pid 935860:tid 936020] [client 98.87.102.177:56638] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:47:47.673792 2026] [security2:error] [pid 935860:tid 936071] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucU4ijB6THqIZZsUIkuQAAANU"]
[Thu Jul 30 13:47:47.914942 2026] [security2:error] [pid 935860:tid 936107] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucU4ijB6THqIZZsUIkwgAAAPk"]
[Thu Jul 30 13:47:48.159139 2026] [security2:error] [pid 935860:tid 936039] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVIijB6THqIZZsUIkywAAALU"]
[Thu Jul 30 13:47:48.501708 2026] [security2:error] [pid 935860:tid 936077] [client 181.116.200.68:23837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucVIijB6THqIZZsUIk7AAAANs"]
[Thu Jul 30 13:47:48.501794 2026] [security2:error] [pid 935860:tid 936077] [client 181.116.200.68:23837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucVIijB6THqIZZsUIk7AAAANs"]
[Thu Jul 30 13:47:48.532009 2026] [security2:error] [pid 935860:tid 936095] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVIijB6THqIZZsUIk5wAAAO0"]
[Thu Jul 30 13:47:48.779501 2026] [security2:error] [pid 935860:tid 936030] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVIijB6THqIZZsUIk8QAAAKw"]
[Thu Jul 30 13:47:49.019883 2026] [security2:error] [pid 935860:tid 936024] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVIijB6THqIZZsUIk_QAAAKY"]
[Thu Jul 30 13:47:49.051543 2026] [security2:error] [pid 935860:tid 936032] [client 103.190.40.154:22794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucVYijB6THqIZZsUIlBgAAAK4"]
[Thu Jul 30 13:47:49.051689 2026] [security2:error] [pid 935860:tid 936032] [client 103.190.40.154:22794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucVYijB6THqIZZsUIlBgAAAK4"]
[Thu Jul 30 13:47:49.263078 2026] [security2:error] [pid 935860:tid 936065] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVYijB6THqIZZsUIlCAAAAM8"]
[Thu Jul 30 13:47:49.499942 2026] [security2:error] [pid 935860:tid 936118] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVYijB6THqIZZsUIlFgAAAQQ"]
[Thu Jul 30 13:47:49.505180 2026] [http2:info] [pid 935860:tid 936102] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-937,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:47:49.633574 2026] [http2:info] [pid 935860:tid 936056] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-939,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:47:49.740405 2026] [security2:error] [pid 935860:tid 936049] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVYijB6THqIZZsUIlHQAAAL8"]
[Thu Jul 30 13:47:49.761813 2026] [http2:info] [pid 935860:tid 936013] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-941,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:47:49.890149 2026] [http2:info] [pid 935860:tid 936083] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-943,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:47:49.982137 2026] [security2:error] [pid 935860:tid 936101] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVYijB6THqIZZsUIlIQAAAPM"]
[Thu Jul 30 13:47:50.229888 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVoijB6THqIZZsUIlLAAAAJY"]
[Thu Jul 30 13:47:50.468185 2026] [security2:error] [pid 935860:tid 936052] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVoijB6THqIZZsUIlNQAAAMI"]
[Thu Jul 30 13:47:50.644067 2026] [security2:error] [pid 935860:tid 935920] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/_phpinfo.php"] [unique_id "amucVoijB6THqIZZsUIlPwAAhTo"]
[Thu Jul 30 13:47:50.772479 2026] [security2:error] [pid 935860:tid 935895] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/_phpinfo.php.dockerignore"] [unique_id "amucVoijB6THqIZZsUIlSAAAiiE"]
[Thu Jul 30 13:47:50.837967 2026] [security2:error] [pid 935860:tid 936012] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVoijB6THqIZZsUIlRQAAAJo"]
[Thu Jul 30 13:47:50.866732 2026] [security2:error] [pid 935860:tid 936098] [client 74.7.228.24:41260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-b216d526.dlr.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amucVoijB6THqIZZsUIlUgAAAPA"]
[Thu Jul 30 13:47:50.902193 2026] [security2:error] [pid 935860:tid 935921] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/_phpinfo.php%3f"] [unique_id "amucVoijB6THqIZZsUIlUwAApDs"]
[Thu Jul 30 13:47:51.031198 2026] [security2:error] [pid 935860:tid 935987] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/_phpinfo.php%2e%2e%2f%2e%2e%2f"] [unique_id "amucV4ijB6THqIZZsUIlVQAAyH0"]
[Thu Jul 30 13:47:51.076550 2026] [security2:error] [pid 935860:tid 936019] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucVoijB6THqIZZsUIlVAAAAKE"]
[Thu Jul 30 13:47:51.090176 2026] [security2:error] [pid 935860:tid 935942] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.okcasino-1.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amucV4ijB6THqIZZsUIlWQAAklA"]
[Thu Jul 30 13:47:51.160198 2026] [security2:error] [pid 935860:tid 935937] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/wp-config.php"] [unique_id "amucV4ijB6THqIZZsUIlXgAA0Es"]
[Thu Jul 30 13:47:51.288332 2026] [security2:error] [pid 935860:tid 935915] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.ad-company.net"] [uri "/wp-config.php%7c%7c"] [unique_id "amucV4ijB6THqIZZsUIlYgAA9TU"]
[Thu Jul 30 13:47:51.316557 2026] [security2:error] [pid 935860:tid 936035] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucV4ijB6THqIZZsUIlXwAAALE"]
[Thu Jul 30 13:47:51.416523 2026] [security2:error] [pid 935860:tid 935893] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.ad-company.net"] [uri "/wp-config.php%257e"] [unique_id "amucV4ijB6THqIZZsUIlZAAA4x8"]
[Thu Jul 30 13:47:51.545405 2026] [security2:error] [pid 935860:tid 935926] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.ad-company.net"] [uri "/wp-config.php//"] [unique_id "amucV4ijB6THqIZZsUIlZgAA_UA"]
[Thu Jul 30 13:47:51.557630 2026] [security2:error] [pid 935860:tid 936039] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucV4ijB6THqIZZsUIlZQAAALU"]
[Thu Jul 30 13:47:51.629071 2026] [security2:error] [pid 935860:tid 936081] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.okcasino-1.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amucV4ijB6THqIZZsUIlagAAAN8"]
[Thu Jul 30 13:47:51.800428 2026] [security2:error] [pid 935860:tid 935997] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucV4ijB6THqIZZsUIlcAAAAIs"]
[Thu Jul 30 13:47:52.043199 2026] [security2:error] [pid 935860:tid 936052] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucV4ijB6THqIZZsUIlfgAAAMI"]
[Thu Jul 30 13:47:52.290552 2026] [security2:error] [pid 935860:tid 936054] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWIijB6THqIZZsUIlhwAAAMQ"]
[Thu Jul 30 13:47:52.540489 2026] [security2:error] [pid 935860:tid 936092] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWIijB6THqIZZsUIlkgAAAOo"]
[Thu Jul 30 13:47:52.740408 2026] [security2:error] [pid 935860:tid 936062] [client 112.86.225.214:39240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amucWIijB6THqIZZsUIlnwAAAMw"]
[Thu Jul 30 13:47:52.740591 2026] [security2:error] [pid 935860:tid 936062] [client 112.86.225.214:39240] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amucWIijB6THqIZZsUIlnwAAAMw"]
[Thu Jul 30 13:47:52.792332 2026] [security2:error] [pid 935860:tid 936066] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWIijB6THqIZZsUIlmgAAANA"]
[Thu Jul 30 13:47:53.036339 2026] [security2:error] [pid 935860:tid 936108] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWIijB6THqIZZsUIlpQAAAPo"]
[Thu Jul 30 13:47:53.164539 2026] [security2:error] [pid 935860:tid 936027] [client 185.177.72.22:34332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/erp~"] [unique_id "amucWYijB6THqIZZsUIlrQAAAKk"]
[Thu Jul 30 13:47:53.408003 2026] [security2:error] [pid 935860:tid 936016] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWYijB6THqIZZsUIltQAAAJ4"]
[Thu Jul 30 13:47:53.651261 2026] [security2:error] [pid 935860:tid 936018] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWYijB6THqIZZsUIluwAAAKA"]
[Thu Jul 30 13:47:53.846765 2026] [core:notice] [pid 935860:tid 935873] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:53.904579 2026] [security2:error] [pid 935860:tid 936099] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWYijB6THqIZZsUIlyQAAAPE"]
[Thu Jul 30 13:47:54.155632 2026] [security2:error] [pid 935860:tid 936118] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWoijB6THqIZZsUIl0wAAAQQ"]
[Thu Jul 30 13:47:54.416659 2026] [security2:error] [pid 935860:tid 936048] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWoijB6THqIZZsUIl3gAAAL4"]
[Thu Jul 30 13:47:54.663605 2026] [security2:error] [pid 935860:tid 936101] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWoijB6THqIZZsUIl5wAAAPM"]
[Thu Jul 30 13:47:54.806883 2026] [security2:error] [pid 935860:tid 935946] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/server.php"] [unique_id "amucWoijB6THqIZZsUIl9QAAlFQ"]
[Thu Jul 30 13:47:54.895653 2026] [security2:error] [pid 935860:tid 936036] [client 119.73.97.132:29925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amucWoijB6THqIZZsUIl1QAAsjQ"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 13:47:54.912001 2026] [security2:error] [pid 935860:tid 936078] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucWoijB6THqIZZsUIl9AAAANw"]
[Thu Jul 30 13:47:54.939267 2026] [security2:error] [pid 935860:tid 935916] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/server.php.%252e"] [unique_id "amucWoijB6THqIZZsUIl9wAA5DY"]
[Thu Jul 30 13:47:55.068580 2026] [security2:error] [pid 935860:tid 935979] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/server.php%0a"] [unique_id "amucW4ijB6THqIZZsUIl_AAA1HU"]
[Thu Jul 30 13:47:55.199767 2026] [security2:error] [pid 935860:tid 935988] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/server.php%5e"] [unique_id "amucW4ijB6THqIZZsUImAAAA3n4"]
[Thu Jul 30 13:47:55.681632 2026] [security2:error] [pid 935860:tid 936045] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucW4ijB6THqIZZsUImFAAAALs"]
[Thu Jul 30 13:47:55.791616 2026] [security2:error] [pid 935860:tid 936115] [client 103.242.199.184:49209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucW4ijB6THqIZZsUImHgAAAQE"]
[Thu Jul 30 13:47:55.791763 2026] [security2:error] [pid 935860:tid 936115] [client 103.242.199.184:49209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucW4ijB6THqIZZsUImHgAAAQE"]
[Thu Jul 30 13:47:55.927575 2026] [security2:error] [pid 935860:tid 936004] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucW4ijB6THqIZZsUImIQAAAJI"]
[Thu Jul 30 13:47:56.054926 2026] [security2:error] [pid 935860:tid 936049] [client 185.177.72.22:34332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/prod.htaccess"] [unique_id "amucXIijB6THqIZZsUImLAAAAL8"]
[Thu Jul 30 13:47:56.303111 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXIijB6THqIZZsUImLwAAAMc"]
[Thu Jul 30 13:47:56.499247 2026] [security2:error] [pid 935860:tid 936101] [client 78.167.1.90:55308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucXIijB6THqIZZsUImOAAAAPM"]
[Thu Jul 30 13:47:56.499645 2026] [security2:error] [pid 935860:tid 936101] [client 78.167.1.90:55308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucXIijB6THqIZZsUImOAAAAPM"]
[Thu Jul 30 13:47:56.546265 2026] [security2:error] [pid 935860:tid 936039] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXIijB6THqIZZsUImNQAAALU"]
[Thu Jul 30 13:47:56.786557 2026] [security2:error] [pid 935860:tid 935997] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXIijB6THqIZZsUImQQAAAIs"]
[Thu Jul 30 13:47:57.024308 2026] [security2:error] [pid 935860:tid 936064] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXIijB6THqIZZsUImTgAAAM4"]
[Thu Jul 30 13:47:57.266361 2026] [security2:error] [pid 935860:tid 936034] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXYijB6THqIZZsUImWgAAALA"]
[Thu Jul 30 13:47:57.270806 2026] [core:notice] [pid 935860:tid 936022] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:47:57.509536 2026] [security2:error] [pid 935860:tid 935993] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXYijB6THqIZZsUImZgAAAIc"]
[Thu Jul 30 13:47:57.753742 2026] [security2:error] [pid 935860:tid 936011] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXYijB6THqIZZsUImbwAAAJk"]
[Thu Jul 30 13:47:57.790738 2026] [security2:error] [pid 935860:tid 936009] [client 74.7.244.51:46386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-292cfc4e.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amucXYijB6THqIZZsUImdwAAl04"]
[Thu Jul 30 13:47:57.991762 2026] [security2:error] [pid 935860:tid 936026] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXYijB6THqIZZsUImfQAAAKg"]
[Thu Jul 30 13:47:58.233637 2026] [security2:error] [pid 935860:tid 936069] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXoijB6THqIZZsUImhgAAANM"]
[Thu Jul 30 13:47:58.436780 2026] [security2:error] [pid 935860:tid 936029] [client 74.7.241.132:38204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amucXoijB6THqIZZsUImkwAAqwo"]
[Thu Jul 30 13:47:58.473329 2026] [security2:error] [pid 935860:tid 936044] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXoijB6THqIZZsUImkgAAALo"]
[Thu Jul 30 13:47:58.727550 2026] [security2:error] [pid 935860:tid 936040] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXoijB6THqIZZsUImmQAAALY"]
[Thu Jul 30 13:47:59.032273 2026] [security2:error] [pid 935860:tid 936065] [client 181.116.200.68:41830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucX4ijB6THqIZZsUImqwAAAM8"]
[Thu Jul 30 13:47:59.032397 2026] [security2:error] [pid 935860:tid 936065] [client 181.116.200.68:41830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucX4ijB6THqIZZsUImqwAAAM8"]
[Thu Jul 30 13:47:59.094295 2026] [http2:info] [pid 935860:tid 936085] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-1065,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:47:59.103227 2026] [security2:error] [pid 935860:tid 936013] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucXoijB6THqIZZsUImqgAAAJs"]
[Thu Jul 30 13:47:59.222848 2026] [http2:info] [pid 935860:tid 936093] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-1067,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:47:59.232121 2026] [security2:error] [pid 935860:tid 936051] [client 185.177.72.22:34332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env.old"] [unique_id "amucX4ijB6THqIZZsUImsgAAAME"]
[Thu Jul 30 13:47:59.352328 2026] [http2:info] [pid 935860:tid 936027] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-1069,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:47:59.474377 2026] [security2:error] [pid 935860:tid 936023] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucX4ijB6THqIZZsUImtAAAAKU"]
[Thu Jul 30 13:47:59.480874 2026] [http2:info] [pid 935860:tid 936081] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-1071,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:47:59.702723 2026] [security2:error] [pid 935860:tid 936047] [client 103.190.40.154:22021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucX4ijB6THqIZZsUImwAAAAL0"]
[Thu Jul 30 13:47:59.702882 2026] [security2:error] [pid 935860:tid 936047] [client 103.190.40.154:22021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucX4ijB6THqIZZsUImwAAAAL0"]
[Thu Jul 30 13:47:59.715871 2026] [security2:error] [pid 935860:tid 936105] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucX4ijB6THqIZZsUImvQAAAPc"]
[Thu Jul 30 13:47:59.959604 2026] [security2:error] [pid 935860:tid 936090] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucX4ijB6THqIZZsUImxgAAAOg"]
[Thu Jul 30 13:48:00.158946 2026] [security2:error] [pid 935860:tid 936033] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucX4ijB6THqIZZsUImuQAAAK8"]
[Thu Jul 30 13:48:00.212227 2026] [security2:error] [pid 935860:tid 936029] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYIijB6THqIZZsUIm0wAAAKs"]
[Thu Jul 30 13:48:00.582846 2026] [security2:error] [pid 935860:tid 936010] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYIijB6THqIZZsUIm5AAAAJg"]
[Thu Jul 30 13:48:00.826030 2026] [security2:error] [pid 935860:tid 936048] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYIijB6THqIZZsUIm6gAAAL4"]
[Thu Jul 30 13:48:01.067389 2026] [security2:error] [pid 935860:tid 936027] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYIijB6THqIZZsUIm9AAAAKk"]
[Thu Jul 30 13:48:01.308829 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYYijB6THqIZZsUInAgAAAL0"]
[Thu Jul 30 13:48:01.503965 2026] [security2:error] [pid 935860:tid 935966] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env.backup"] [unique_id "amucYYijB6THqIZZsUInDAAA0mg"]
[Thu Jul 30 13:48:01.551186 2026] [security2:error] [pid 935860:tid 936097] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYYijB6THqIZZsUInCAAAAO8"]
[Thu Jul 30 13:48:01.780015 2026] [security2:error] [pid 935860:tid 935986] [remote 216.73.217.142:36445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amucYYijB6THqIZZsUInFgAAinw"]
[Thu Jul 30 13:48:01.791033 2026] [security2:error] [pid 935860:tid 936077] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYYijB6THqIZZsUInFQAAANs"]
[Thu Jul 30 13:48:01.966814 2026] [security2:error] [pid 935860:tid 936115] [client 172.237.109.114:45132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYYijB6THqIZZsUInIgAAAQE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:01.981614 2026] [security2:error] [pid 935860:tid 936025] [client 172.237.109.114:21230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYYijB6THqIZZsUInJAAAAKc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.063861 2026] [security2:error] [pid 935860:tid 936091] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYYijB6THqIZZsUInHwAAAOk"]
[Thu Jul 30 13:48:02.315778 2026] [security2:error] [pid 935860:tid 936065] [client 185.177.72.22:34332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYoijB6THqIZZsUInKwAAAM8"]
[Thu Jul 30 13:48:02.337092 2026] [security2:error] [pid 935860:tid 935881] [remote 57.141.0.62:30676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amucYoijB6THqIZZsUInMgAA1xM"]
[Thu Jul 30 13:48:02.443598 2026] [security2:error] [pid 935860:tid 936094] [client 185.177.72.22:34332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/settings.swp"] [unique_id "amucYoijB6THqIZZsUInOAAAAOw"]
[Thu Jul 30 13:48:02.817839 2026] [security2:error] [pid 935860:tid 936001] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYoijB6THqIZZsUInQAAAAI8"]
[Thu Jul 30 13:48:02.962449 2026] [security2:error] [pid 935860:tid 936113] [client 172.237.109.114:33734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInTgAAAP8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.964062 2026] [security2:error] [pid 935860:tid 936064] [client 172.237.109.114:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInTwAAAM4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.968911 2026] [security2:error] [pid 935860:tid 936046] [client 172.237.109.114:59141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInUAAAALw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.970268 2026] [security2:error] [pid 935860:tid 935996] [client 172.237.109.114:13564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInUQAAAIo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.974355 2026] [security2:error] [pid 935860:tid 936077] [client 172.237.109.114:19334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInUwAAANs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.979771 2026] [security2:error] [pid 935860:tid 936045] [client 172.237.109.114:63079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInVAAAALs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.979846 2026] [security2:error] [pid 935860:tid 936045] [client 172.237.109.114:63079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInVAAAALs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.992835 2026] [security2:error] [pid 935860:tid 936116] [client 172.237.109.114:11013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInVQAAAQI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.993438 2026] [security2:error] [pid 935860:tid 936099] [client 172.237.109.114:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInVgAAAPE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.993746 2026] [security2:error] [pid 935860:tid 936112] [client 172.237.109.114:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInVwAAAP4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:02.994135 2026] [security2:error] [pid 935860:tid 936075] [client 172.237.109.114:48586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucYoijB6THqIZZsUInWAAAANk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:03.008725 2026] [security2:error] [pid 935860:tid 936020] [client 172.237.109.114:14667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucY4ijB6THqIZZsUInWQAAAKI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:03.009677 2026] [security2:error] [pid 935860:tid 936040] [client 172.237.109.114:22621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucY4ijB6THqIZZsUInWgAAALY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:03.010902 2026] [security2:error] [pid 935860:tid 936002] [client 172.237.109.114:55398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucY4ijB6THqIZZsUInWwAAAJA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:03.012063 2026] [security2:error] [pid 935860:tid 936012] [client 172.237.109.114:62057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucY4ijB6THqIZZsUInXQAAAJo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:03.012093 2026] [security2:error] [pid 935860:tid 936019] [client 172.237.109.114:8073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucY4ijB6THqIZZsUInXgAAAKE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:03.012146 2026] [security2:error] [pid 935860:tid 936034] [client 172.237.109.114:62219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucY4ijB6THqIZZsUInXAAAALA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:03.012159 2026] [security2:error] [pid 935860:tid 936041] [client 172.237.109.114:48998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucY4ijB6THqIZZsUInXwAAALc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:03.065129 2026] [security2:error] [pid 935860:tid 936082] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucYoijB6THqIZZsUInTAAAAOA"]
[Thu Jul 30 13:48:03.169257 2026] [security2:error] [pid 935860:tid 936092] [client 213.152.187.215:41862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amucY4ijB6THqIZZsUInZwAAAOo"]
[Thu Jul 30 13:48:03.169414 2026] [security2:error] [pid 935860:tid 936092] [client 213.152.187.215:41862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amucY4ijB6THqIZZsUInZwAAAOo"]
[Thu Jul 30 13:48:03.192602 2026] [security2:error] [pid 935860:tid 936000] [client 185.177.72.22:9116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env.swp"] [unique_id "amucY4ijB6THqIZZsUInaAAAAI4"]
[Thu Jul 30 13:48:03.238439 2026] [security2:error] [pid 935860:tid 935877] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/api.orig"] [unique_id "amucY4ijB6THqIZZsUInaQAA-g8"]
[Thu Jul 30 13:48:03.435522 2026] [security2:error] [pid 935860:tid 936107] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucY4ijB6THqIZZsUInbAAAAPk"]
[Thu Jul 30 13:48:03.562416 2026] [security2:error] [pid 935860:tid 936060] [client 185.177.72.22:9116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env.swp"] [unique_id "amucY4ijB6THqIZZsUIndwAAAMo"]
[Thu Jul 30 13:48:03.806713 2026] [security2:error] [pid 935860:tid 936079] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucY4ijB6THqIZZsUInfQAAAN0"]
[Thu Jul 30 13:48:03.841656 2026] [security2:error] [pid 935860:tid 935863] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/src.orig"] [unique_id "amucY4ijB6THqIZZsUInggAA3gE"]
[Thu Jul 30 13:48:04.010038 2026] [security2:error] [pid 935860:tid 936098] [client 172.237.109.114:30951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucZIijB6THqIZZsUInigAAAPA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:04.050892 2026] [security2:error] [pid 935860:tid 936032] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucY4ijB6THqIZZsUInhAAAAK4"]
[Thu Jul 30 13:48:04.177845 2026] [security2:error] [pid 935860:tid 936112] [client 185.177.72.22:9116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.EnV"] [unique_id "amucZIijB6THqIZZsUInkQAAAP4"]
[Thu Jul 30 13:48:04.354163 2026] [proxy:error] [pid 935860:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:04.354240 2026] [proxy_http:error] [pid 935860:tid 935995] [client 18.211.55.47:65209] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:04.354815 2026] [proxy:error] [pid 935860:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:04.354856 2026] [proxy_http:error] [pid 935860:tid 935995] [client 18.211.55.47:65209] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:04.379720 2026] [proxy:error] [pid 935860:tid 936082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:04.379798 2026] [proxy_http:error] [pid 935860:tid 936082] [client 44.216.125.112:48832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:04.380601 2026] [proxy:error] [pid 935860:tid 936082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:04.380660 2026] [proxy_http:error] [pid 935860:tid 936082] [client 44.216.125.112:48832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:04.435786 2026] [security2:error] [pid 935860:tid 936025] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucZIijB6THqIZZsUInmQAAAKc"]
[Thu Jul 30 13:48:04.682094 2026] [security2:error] [pid 935860:tid 936092] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucZIijB6THqIZZsUInqgAAAOo"]
[Thu Jul 30 13:48:04.811825 2026] [security2:error] [pid 935860:tid 936110] [client 185.177.72.22:9116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.EnV^"] [unique_id "amucZIijB6THqIZZsUIntQAAAPw"]
[Thu Jul 30 13:48:05.052520 2026] [security2:error] [pid 935860:tid 936038] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucZIijB6THqIZZsUInuwAAALQ"]
[Thu Jul 30 13:48:05.294542 2026] [security2:error] [pid 935860:tid 936018] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucZYijB6THqIZZsUInxAAAAKA"]
[Thu Jul 30 13:48:05.456007 2026] [core:notice] [pid 935860:tid 936065] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:05.537682 2026] [security2:error] [pid 935860:tid 936101] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucZYijB6THqIZZsUInzQAAAPM"]
[Thu Jul 30 13:48:05.664538 2026] [security2:error] [pid 935860:tid 936028] [client 185.177.72.22:9116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/authui.htaccess"] [unique_id "amucZYijB6THqIZZsUIn2gAAAKo"]
[Thu Jul 30 13:48:05.912842 2026] [security2:error] [pid 935860:tid 936053] [client 185.177.72.22:9116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucZYijB6THqIZZsUIn3wAAAMM"]
[Thu Jul 30 13:48:06.038536 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:9116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/test2.php"] [unique_id "amucZoijB6THqIZZsUIn6wAAAMc"]
[Thu Jul 30 13:48:06.299864 2026] [security2:error] [pid 935860:tid 936010] [client 185.177.72.22:12838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/test2.php%2e%2e%2f%2e%2e%2f"] [unique_id "amucZoijB6THqIZZsUIn9AAAAJg"]
[Thu Jul 30 13:48:06.537151 2026] [security2:error] [pid 935860:tid 936103] [client 103.242.199.184:49777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucZoijB6THqIZZsUIn_wAAAPU"]
[Thu Jul 30 13:48:06.537886 2026] [security2:error] [pid 935860:tid 936103] [client 103.242.199.184:49777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucZoijB6THqIZZsUIn_wAAAPU"]
[Thu Jul 30 13:48:06.550327 2026] [security2:error] [pid 935860:tid 936078] [client 185.177.72.22:13236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/test2.php.well-known"] [unique_id "amucZoijB6THqIZZsUIoAAAAANw"]
[Thu Jul 30 13:48:06.715668 2026] [security2:error] [pid 935860:tid 936000] [client 172.237.109.114:46644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amucZoijB6THqIZZsUIn7QAAAI4"]
[Thu Jul 30 13:48:06.799941 2026] [security2:error] [pid 935860:tid 936068] [client 185.177.72.22:13294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/test2.php//"] [unique_id "amucZoijB6THqIZZsUIoCgAAANI"]
[Thu Jul 30 13:48:07.065888 2026] [security2:error] [pid 935860:tid 936045] [client 185.177.72.22:59662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/config.php.bak"] [unique_id "amucZ4ijB6THqIZZsUIoFQAAALs"]
[Thu Jul 30 13:48:07.332247 2026] [security2:error] [pid 935860:tid 936053] [client 185.177.72.22:59664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/config.php.bak%257d"] [unique_id "amucZ4ijB6THqIZZsUIoHwAAAMM"]
[Thu Jul 30 13:48:07.585253 2026] [security2:error] [pid 935860:tid 936005] [client 185.177.72.22:59668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/ConFig.Php.bak"] [unique_id "amucZ4ijB6THqIZZsUIoJgAAAJM"]
[Thu Jul 30 13:48:07.711695 2026] [security2:error] [pid 935860:tid 936060] [client 185.177.72.22:59668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/config.php.bak%0d"] [unique_id "amucZ4ijB6THqIZZsUIoLwAAAMo"]
[Thu Jul 30 13:48:08.077475 2026] [security2:error] [pid 935860:tid 936061] [client 185.177.72.22:59672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucZ4ijB6THqIZZsUIoNQAAAMs"]
[Thu Jul 30 13:48:08.157931 2026] [security2:error] [pid 935860:tid 936076] [client 78.167.1.90:55448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucaIijB6THqIZZsUIoPwAAANo"]
[Thu Jul 30 13:48:08.158765 2026] [security2:error] [pid 935860:tid 936076] [client 78.167.1.90:55448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucaIijB6THqIZZsUIoPwAAANo"]
[Thu Jul 30 13:48:08.320595 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:59672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucaIijB6THqIZZsUIoQgAAAL0"]
[Thu Jul 30 13:48:08.436828 2026] [security2:error] [pid 935860:tid 936106] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucZ4ijB6THqIZZsUIoMgAA-Hg"]
[Thu Jul 30 13:48:08.557996 2026] [security2:error] [pid 935860:tid 936089] [client 185.177.72.22:59672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucaIijB6THqIZZsUIoSAAAAOc"]
[Thu Jul 30 13:48:08.797775 2026] [security2:error] [pid 935860:tid 936046] [client 185.177.72.22:59672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucaIijB6THqIZZsUIoUwAAALw"]
[Thu Jul 30 13:48:08.922945 2026] [security2:error] [pid 935860:tid 936082] [client 185.177.72.22:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/app_dev.php"] [unique_id "amucaIijB6THqIZZsUIoXAAAAOA"]
[Thu Jul 30 13:48:09.174720 2026] [security2:error] [pid 935860:tid 936092] [client 185.177.72.22:59688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/app_dev.php%2520"] [unique_id "amucaYijB6THqIZZsUIoagAAAOo"]
[Thu Jul 30 13:48:09.436329 2026] [security2:error] [pid 935860:tid 936023] [client 185.177.72.22:59696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/app_dev.php%253f"] [unique_id "amucaYijB6THqIZZsUIodgAAAKU"]
[Thu Jul 30 13:48:09.576086 2026] [security2:error] [pid 935860:tid 936049] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucaIijB6THqIZZsUIoXwAAAL8"]
[Thu Jul 30 13:48:09.652665 2026] [security2:error] [pid 935860:tid 936107] [client 181.116.200.68:56202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucaYijB6THqIZZsUIofgAAAPk"]
[Thu Jul 30 13:48:09.652782 2026] [security2:error] [pid 935860:tid 936107] [client 181.116.200.68:56202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucaYijB6THqIZZsUIofgAAAPk"]
[Thu Jul 30 13:48:09.685868 2026] [security2:error] [pid 935860:tid 936090] [client 185.177.72.22:59702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/app_dev.php%2524"] [unique_id "amucaYijB6THqIZZsUIoggAAAOg"]
[Thu Jul 30 13:48:10.069405 2026] [security2:error] [pid 935860:tid 936041] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucaYijB6THqIZZsUIolgAAALc"]
[Thu Jul 30 13:48:10.137776 2026] [security2:error] [pid 935860:tid 935979] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/libs~"] [unique_id "amucaoijB6THqIZZsUIooAAA63U"]
[Thu Jul 30 13:48:10.317070 2026] [security2:error] [pid 935860:tid 936005] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucaoijB6THqIZZsUIopgAAAJM"]
[Thu Jul 30 13:48:10.440351 2026] [security2:error] [pid 935860:tid 936003] [client 103.190.40.154:22820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucaoijB6THqIZZsUIorwAAAJE"]
[Thu Jul 30 13:48:10.440519 2026] [security2:error] [pid 935860:tid 936003] [client 103.190.40.154:22820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucaoijB6THqIZZsUIorwAAAJE"]
[Thu Jul 30 13:48:10.559295 2026] [security2:error] [pid 935860:tid 936016] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucaoijB6THqIZZsUIosAAAAJ4"]
[Thu Jul 30 13:48:10.799388 2026] [security2:error] [pid 935860:tid 936018] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucaoijB6THqIZZsUIovAAAAKA"]
[Thu Jul 30 13:48:11.041947 2026] [security2:error] [pid 935860:tid 936020] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucaoijB6THqIZZsUIoyAAAAKI"]
[Thu Jul 30 13:48:11.286719 2026] [security2:error] [pid 935860:tid 936118] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuca4ijB6THqIZZsUIozwAAAQQ"]
[Thu Jul 30 13:48:11.528886 2026] [security2:error] [pid 935860:tid 936045] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuca4ijB6THqIZZsUIo2gAAALs"]
[Thu Jul 30 13:48:11.660095 2026] [security2:error] [pid 935860:tid 936067] [client 141.164.90.92:1057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "radiojelli.com"] [uri "/"] [unique_id "amuca4ijB6THqIZZsUIo4wAAANE"]
[Thu Jul 30 13:48:11.660204 2026] [security2:error] [pid 935860:tid 936067] [client 141.164.90.92:1057] ModSecurity: Warning. Matched phrase "DomainCrawler" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "radiojelli.com"] [uri "/"] [unique_id "amuca4ijB6THqIZZsUIo4wAAANE"]
[Thu Jul 30 13:48:11.771775 2026] [security2:error] [pid 935860:tid 936073] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuca4ijB6THqIZZsUIo4QAAANc"]
[Thu Jul 30 13:48:12.012880 2026] [security2:error] [pid 935860:tid 936076] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuca4ijB6THqIZZsUIo9wAAANo"]
[Thu Jul 30 13:48:12.253309 2026] [security2:error] [pid 935860:tid 936069] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucbIijB6THqIZZsUIo-gAAANM"]
[Thu Jul 30 13:48:12.494141 2026] [security2:error] [pid 935860:tid 936014] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucbIijB6THqIZZsUIpCAAAAJw"]
[Thu Jul 30 13:48:12.735944 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucbIijB6THqIZZsUIpDgAAANk"]
[Thu Jul 30 13:48:12.984125 2026] [security2:error] [pid 935860:tid 936093] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucbIijB6THqIZZsUIpGwAAAOs"]
[Thu Jul 30 13:48:13.141946 2026] [security2:error] [pid 935860:tid 936060] [client 52.238.199.152:56147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amucbYijB6THqIZZsUIpKQAAAMo"]
[Thu Jul 30 13:48:13.228376 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucbYijB6THqIZZsUIpJwAAAMc"]
[Thu Jul 30 13:48:13.308942 2026] [core:notice] [pid 935860:tid 935868] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:13.388696 2026] [security2:error] [pid 935860:tid 936002] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucbIijB6THqIZZsUIpFwAAAJA"]
[Thu Jul 30 13:48:13.480153 2026] [security2:error] [pid 935860:tid 936073] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucbYijB6THqIZZsUIpMQAAANc"]
[Thu Jul 30 13:48:13.721166 2026] [security2:error] [pid 935860:tid 935992] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucbYijB6THqIZZsUIpQQAAAIY"]
[Thu Jul 30 13:48:13.777742 2026] [security2:error] [pid 935860:tid 936047] [client 147.53.112.76:7613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "radiojelli.com"] [uri "/"] [unique_id "amucbYijB6THqIZZsUIpRwAAAL0"]
[Thu Jul 30 13:48:13.777845 2026] [security2:error] [pid 935860:tid 936047] [client 147.53.112.76:7613] ModSecurity: Warning. Matched phrase "DomainCrawler" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "radiojelli.com"] [uri "/"] [unique_id "amucbYijB6THqIZZsUIpRwAAAL0"]
[Thu Jul 30 13:48:13.969240 2026] [security2:error] [pid 935860:tid 936095] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucbYijB6THqIZZsUIpSAAAAO0"]
[Thu Jul 30 13:48:14.214064 2026] [security2:error] [pid 935860:tid 936020] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucboijB6THqIZZsUIpWgAAAKI"]
[Thu Jul 30 13:48:14.454964 2026] [security2:error] [pid 935860:tid 936019] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucboijB6THqIZZsUIpYAAAAKE"]
[Thu Jul 30 13:48:14.669586 2026] [security2:error] [pid 935860:tid 935928] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/wordpress.sql"] [unique_id "amucboijB6THqIZZsUIpZgAAjkI"]
[Thu Jul 30 13:48:14.699642 2026] [security2:error] [pid 935860:tid 936114] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucboijB6THqIZZsUIpZQAAAQA"]
[Thu Jul 30 13:48:14.943466 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucboijB6THqIZZsUIpbAAAAMc"]
[Thu Jul 30 13:48:15.196930 2026] [security2:error] [pid 935860:tid 936051] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucb4ijB6THqIZZsUIpeAAAAME"]
[Thu Jul 30 13:48:15.341947 2026] [security2:error] [pid 935860:tid 936073] [client 127.0.0.1:30962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amucb4ijB6THqIZZsUIpggAAANc"]
[Thu Jul 30 13:48:15.342109 2026] [security2:error] [pid 935860:tid 936102] [client 74.7.228.38:50884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ooj.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amucb4ijB6THqIZZsUIpgQAA9C4"]
[Thu Jul 30 13:48:15.446158 2026] [security2:error] [pid 935860:tid 936100] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucb4ijB6THqIZZsUIpgwAAAPI"]
[Thu Jul 30 13:48:15.686908 2026] [security2:error] [pid 935860:tid 936062] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucb4ijB6THqIZZsUIpjgAAAMw"]
[Thu Jul 30 13:48:15.894279 2026] [security2:error] [pid 935860:tid 936093] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucb4ijB6THqIZZsUIpfwAA6xs"]
[Thu Jul 30 13:48:15.897493 2026] [security2:error] [pid 935860:tid 935876] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env~"] [unique_id "amucb4ijB6THqIZZsUIpmAAAsA4"]
[Thu Jul 30 13:48:15.928908 2026] [security2:error] [pid 935860:tid 936027] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucb4ijB6THqIZZsUIplAAAAKk"]
[Thu Jul 30 13:48:16.166797 2026] [security2:error] [pid 935860:tid 936019] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccIijB6THqIZZsUIpogAAAKE"]
[Thu Jul 30 13:48:16.412586 2026] [security2:error] [pid 935860:tid 936083] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccIijB6THqIZZsUIptAAAAOE"]
[Thu Jul 30 13:48:16.656205 2026] [security2:error] [pid 935860:tid 935999] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccIijB6THqIZZsUIpwwAAAI0"]
[Thu Jul 30 13:48:16.898050 2026] [security2:error] [pid 935860:tid 936063] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccIijB6THqIZZsUIpxwAAAM0"]
[Thu Jul 30 13:48:17.101254 2026] [security2:error] [pid 935860:tid 936087] [client 103.242.199.184:50344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuccYijB6THqIZZsUIp2gAAAOU"]
[Thu Jul 30 13:48:17.101370 2026] [security2:error] [pid 935860:tid 936087] [client 103.242.199.184:50344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuccYijB6THqIZZsUIp2gAAAOU"]
[Thu Jul 30 13:48:17.655670 2026] [security2:error] [pid 935860:tid 936020] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccYijB6THqIZZsUIp6wAAAKI"]
[Thu Jul 30 13:48:17.727935 2026] [security2:error] [pid 935860:tid 936046] [client 78.167.1.90:54903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuccYijB6THqIZZsUIp9AAAALw"]
[Thu Jul 30 13:48:17.728159 2026] [security2:error] [pid 935860:tid 936046] [client 78.167.1.90:54903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuccYijB6THqIZZsUIp9AAAALw"]
[Thu Jul 30 13:48:17.898334 2026] [security2:error] [pid 935860:tid 936066] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccYijB6THqIZZsUIp9wAAANA"]
[Thu Jul 30 13:48:18.052953 2026] [security2:error] [pid 935860:tid 935939] [remote 162.0.217.83:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.217.0.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/wp-login.php"] [unique_id "amuccoijB6THqIZZsUIqBAAA_00"]
[Thu Jul 30 13:48:18.147951 2026] [security2:error] [pid 935860:tid 936005] [client 52.167.144.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.palmtreepools.ca"] [uri "/index.php"] [unique_id "amuccIijB6THqIZZsUIpwgAAAJM"]
[Thu Jul 30 13:48:18.265597 2026] [security2:error] [pid 935860:tid 936026] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccoijB6THqIZZsUIqCgAAAKg"]
[Thu Jul 30 13:48:18.506739 2026] [security2:error] [pid 935860:tid 936016] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccoijB6THqIZZsUIqDwAAAJ4"]
[Thu Jul 30 13:48:18.745965 2026] [security2:error] [pid 935860:tid 936080] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccoijB6THqIZZsUIqGwAAAN4"]
[Thu Jul 30 13:48:18.990243 2026] [security2:error] [pid 935860:tid 936089] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuccoijB6THqIZZsUIqIAAAAOc"]
[Thu Jul 30 13:48:19.235254 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucc4ijB6THqIZZsUIqKgAAANk"]
[Thu Jul 30 13:48:19.363042 2026] [fcgid:warn] [pid 935860:tid 936106] (70014)End of file found: [client 185.177.72.22:59714] mod_fcgid: can't get data from http client
[Thu Jul 30 13:48:19.616728 2026] [fcgid:warn] [pid 935860:tid 936045] (70014)End of file found: [client 185.177.72.22:50136] mod_fcgid: can't get data from http client
[Thu Jul 30 13:48:19.868708 2026] [fcgid:warn] [pid 935860:tid 936037] (70014)End of file found: [client 185.177.72.22:50148] mod_fcgid: can't get data from http client
[Thu Jul 30 13:48:20.116068 2026] [fcgid:warn] [pid 935860:tid 936107] (70014)End of file found: [client 185.177.72.22:50154] mod_fcgid: can't get data from http client
[Thu Jul 30 13:48:20.303560 2026] [security2:error] [pid 935860:tid 936009] [client 181.116.200.68:46401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucdIijB6THqIZZsUIqVgAAAJc"]
[Thu Jul 30 13:48:20.303670 2026] [security2:error] [pid 935860:tid 936009] [client 181.116.200.68:46401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucdIijB6THqIZZsUIqVgAAAJc"]
[Thu Jul 30 13:48:20.488856 2026] [security2:error] [pid 935860:tid 936069] [client 185.177.72.22:50160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucdIijB6THqIZZsUIqVwAAANM"]
[Thu Jul 30 13:48:20.736802 2026] [security2:error] [pid 935860:tid 936058] [client 185.177.72.22:50160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucdIijB6THqIZZsUIqYAAAAMg"]
[Thu Jul 30 13:48:20.952705 2026] [security2:error] [pid 935860:tid 936044] [client 46.232.235.4:37862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-8880a99c.lld.nyx.temporary.site"] [uri "/.env"] [unique_id "amucdIijB6THqIZZsUIqbwAAALo"]
[Thu Jul 30 13:48:20.977867 2026] [security2:error] [pid 935860:tid 936046] [client 185.177.72.22:50160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucdIijB6THqIZZsUIqbAAAALw"]
[Thu Jul 30 13:48:21.066296 2026] [security2:error] [pid 935860:tid 935993] [client 103.190.40.154:22788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucdYijB6THqIZZsUIqcgAAAIc"]
[Thu Jul 30 13:48:21.066436 2026] [security2:error] [pid 935860:tid 935993] [client 103.190.40.154:22788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucdYijB6THqIZZsUIqcgAAAIc"]
[Thu Jul 30 13:48:21.219082 2026] [security2:error] [pid 935860:tid 936106] [client 185.177.72.22:50160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucdYijB6THqIZZsUIqdgAAAPg"]
[Thu Jul 30 13:48:21.454791 2026] [core:notice] [pid 935860:tid 936056] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:21.461150 2026] [security2:error] [pid 935860:tid 936103] [client 185.177.72.22:50160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucdYijB6THqIZZsUIqfwAAAPU"]
[Thu Jul 30 13:48:21.588181 2026] [security2:error] [pid 935860:tid 936110] [client 185.177.72.22:50160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/_phpinfo.php"] [unique_id "amucdYijB6THqIZZsUIqhQAAAPw"]
[Thu Jul 30 13:48:21.852446 2026] [security2:error] [pid 935860:tid 936063] [client 185.177.72.22:50170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/_phpinfo.php.dockerignore"] [unique_id "amucdYijB6THqIZZsUIqlgAAAM0"]
[Thu Jul 30 13:48:22.119407 2026] [security2:error] [pid 935860:tid 936073] [client 185.177.72.22:50184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/_phpinfo.php%3f"] [unique_id "amucdoijB6THqIZZsUIqmQAAANc"]
[Thu Jul 30 13:48:22.225638 2026] [core:notice] [pid 935860:tid 935968] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:22.375848 2026] [security2:error] [pid 935860:tid 936070] [client 185.177.72.22:50194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/_phpinfo.php%2e%2e%2f%2e%2e%2f"] [unique_id "amucdoijB6THqIZZsUIqrAAAANQ"]
[Thu Jul 30 13:48:22.501412 2026] [core:notice] [pid 935860:tid 935953] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:22.549334 2026] [core:error] [pid 935860:tid 936010] [client 46.232.235.4:37878] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:48:22.549362 2026] [core:error] [pid 935860:tid 936010] [client 46.232.235.4:37878] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:48:22.624683 2026] [security2:error] [pid 935860:tid 936004] [client 185.177.72.22:50198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/wp-config.php"] [unique_id "amucdoijB6THqIZZsUIqswAAAJI"]
[Thu Jul 30 13:48:22.893123 2026] [security2:error] [pid 935860:tid 936108] [client 185.177.72.22:50206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.aaapropertiesph.com"] [uri "/wp-config.php%7c%7c"] [unique_id "amucdoijB6THqIZZsUIqvwAAAPo"]
[Thu Jul 30 13:48:23.151363 2026] [security2:error] [pid 935860:tid 936067] [client 185.177.72.22:50210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.aaapropertiesph.com"] [uri "/wp-config.php%257e"] [unique_id "amucd4ijB6THqIZZsUIqxgAAANE"]
[Thu Jul 30 13:48:23.234932 2026] [security2:error] [pid 935860:tid 936011] [client 172.237.109.114:64169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucdoijB6THqIZZsUIqwgAAAJk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.238242 2026] [security2:error] [pid 935860:tid 936053] [client 172.237.109.114:14511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucdoijB6THqIZZsUIqwwAAAMM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.238333 2026] [security2:error] [pid 935860:tid 936053] [client 172.237.109.114:14511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucdoijB6THqIZZsUIqwwAAAMM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.380848 2026] [http2:info] [pid 935860:tid 936088] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-1377,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:48:23.414222 2026] [security2:error] [pid 935860:tid 936040] [client 185.177.72.22:50216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.aaapropertiesph.com"] [uri "/wp-config.php//"] [unique_id "amucd4ijB6THqIZZsUIq0wAAALY"]
[Thu Jul 30 13:48:23.509188 2026] [http2:info] [pid 935860:tid 936025] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-1379,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:48:23.637760 2026] [http2:info] [pid 935860:tid 936006] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-1381,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:48:23.766263 2026] [http2:info] [pid 935860:tid 936023] [client 185.177.72.56:2998] AH10178: h2_stream(935860-419-1383,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Thu Jul 30 13:48:23.970861 2026] [security2:error] [pid 935860:tid 936029] [client 172.237.109.114:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq5AAAAKs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.974304 2026] [security2:error] [pid 935860:tid 936080] [client 172.237.109.114:60266] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq5gAAAN4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.974335 2026] [security2:error] [pid 935860:tid 935992] [client 172.237.109.114:64153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq5QAAAIY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.974433 2026] [security2:error] [pid 935860:tid 936080] [client 172.237.109.114:60266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq5gAAAN4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.974647 2026] [security2:error] [pid 935860:tid 936021] [client 172.237.109.114:13871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq6AAAAKM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.974835 2026] [security2:error] [pid 935860:tid 936069] [client 172.237.109.114:42276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq5wAAANM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.980141 2026] [security2:error] [pid 935860:tid 936064] [client 172.237.109.114:1668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq6QAAAM4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.992899 2026] [security2:error] [pid 935860:tid 936009] [client 172.237.109.114:25782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq6gAAAJc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.993363 2026] [security2:error] [pid 935860:tid 936033] [client 172.237.109.114:25455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq6wAAAK8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.993631 2026] [security2:error] [pid 935860:tid 936076] [client 172.237.109.114:14890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq7AAAANo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.993658 2026] [security2:error] [pid 935860:tid 936042] [client 172.237.109.114:58963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq7gAAALg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.993686 2026] [security2:error] [pid 935860:tid 936062] [client 172.237.109.114:9185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq7QAAAMw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:23.993719 2026] [security2:error] [pid 935860:tid 936042] [client 172.237.109.114:58963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucd4ijB6THqIZZsUIq7gAAALg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:24.011207 2026] [security2:error] [pid 935860:tid 936105] [client 172.237.109.114:16317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuceIijB6THqIZZsUIq7wAAAPc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:24.011237 2026] [security2:error] [pid 935860:tid 936095] [client 172.237.109.114:48628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuceIijB6THqIZZsUIq8QAAAO0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:24.011321 2026] [security2:error] [pid 935860:tid 936095] [client 172.237.109.114:48628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuceIijB6THqIZZsUIq8QAAAO0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:24.011338 2026] [security2:error] [pid 935860:tid 936068] [client 172.237.109.114:16458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuceIijB6THqIZZsUIq8AAAANI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:24.011988 2026] [security2:error] [pid 935860:tid 936001] [client 172.237.109.114:59693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuceIijB6THqIZZsUIq8gAAAI8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:24.012299 2026] [security2:error] [pid 935860:tid 936070] [client 172.237.109.114:4776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuceIijB6THqIZZsUIq8wAAANQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:24.012780 2026] [security2:error] [pid 935860:tid 936097] [client 172.237.109.114:25072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuceIijB6THqIZZsUIq9AAAAO8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:24.304473 2026] [security2:error] [pid 935860:tid 935978] [remote 52.167.144.138:57919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/18285721/humanitariaf.php"] [unique_id "amuceIijB6THqIZZsUIrAAAA_nQ"]
[Thu Jul 30 13:48:24.341845 2026] [security2:error] [pid 935860:tid 935991] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuceIijB6THqIZZsUIq_QAAAIU"]
[Thu Jul 30 13:48:24.682341 2026] [security2:error] [pid 935860:tid 935966] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/en.orig"] [unique_id "amuceIijB6THqIZZsUIrDgAA7Gg"]
[Thu Jul 30 13:48:24.893799 2026] [security2:error] [pid 935860:tid 936053] [client 43.172.196.138:47712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amuceIijB6THqIZZsUIrDQAAAMM"]
[Thu Jul 30 13:48:25.015140 2026] [security2:error] [pid 935860:tid 936003] [client 172.237.109.114:9022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuceYijB6THqIZZsUIrHwAAAJE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:25.374831 2026] [core:notice] [pid 935860:tid 936073] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:25.380007 2026] [security2:error] [pid 935860:tid 936073] [client 43.173.177.160:44772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amuceYijB6THqIZZsUIrMAAAANc"], referer: https://carnetdeshopping.com/index.php/typography/
[Thu Jul 30 13:48:25.544294 2026] [security2:error] [pid 935860:tid 936033] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuceYijB6THqIZZsUIrMwAAAK8"]
[Thu Jul 30 13:48:25.750401 2026] [security2:error] [pid 935860:tid 935881] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/o.php"] [unique_id "amuceYijB6THqIZZsUIrOQAA1BM"]
[Thu Jul 30 13:48:25.805113 2026] [security2:error] [pid 935860:tid 936001] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuceYijB6THqIZZsUIrOAAAAI8"]
[Thu Jul 30 13:48:25.879387 2026] [security2:error] [pid 935860:tid 935916] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/o.php%2f"] [unique_id "amuceYijB6THqIZZsUIrQQAA6zY"]
[Thu Jul 30 13:48:25.936694 2026] [security2:error] [pid 935860:tid 936041] [client 23.23.213.182:13077] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/167/46d15bd3821e8b8bd7170e833339914c.jpg"] [unique_id "amuceYijB6THqIZZsUIrRQAAALc"]
[Thu Jul 30 13:48:26.008116 2026] [security2:error] [pid 935860:tid 935988] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/o.php..."] [unique_id "amuceoijB6THqIZZsUIrRwAAxX4"]
[Thu Jul 30 13:48:26.055092 2026] [security2:error] [pid 935860:tid 936077] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuceYijB6THqIZZsUIrRgAAANs"]
[Thu Jul 30 13:48:26.136898 2026] [security2:error] [pid 935860:tid 935935] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/o.php.swp"] [unique_id "amuceoijB6THqIZZsUIrSAAAsUk"]
[Thu Jul 30 13:48:26.307309 2026] [security2:error] [pid 935860:tid 936115] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuceoijB6THqIZZsUIrSQAAAQE"]
[Thu Jul 30 13:48:26.558185 2026] [security2:error] [pid 935860:tid 936059] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuceoijB6THqIZZsUIrVQAAAMk"]
[Thu Jul 30 13:48:26.814214 2026] [security2:error] [pid 935860:tid 935994] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuceoijB6THqIZZsUIrWwAAAIg"]
[Thu Jul 30 13:48:27.084446 2026] [security2:error] [pid 935860:tid 936034] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuceoijB6THqIZZsUIrawAAALA"]
[Thu Jul 30 13:48:27.162702 2026] [security2:error] [pid 935860:tid 936003] [client 220.181.108.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuce4ijB6THqIZZsUIrcQAAAJE"]
[Thu Jul 30 13:48:27.343541 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuce4ijB6THqIZZsUIreAAAAMc"]
[Thu Jul 30 13:48:27.596107 2026] [security2:error] [pid 935860:tid 936095] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuce4ijB6THqIZZsUIrhAAAAO0"]
[Thu Jul 30 13:48:27.608273 2026] [security2:error] [pid 935860:tid 936021] [client 46.232.235.4:37880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-8880a99c.lld.nyx.temporary.site"] [uri "/.env"] [unique_id "amuce4ijB6THqIZZsUIrhwAAAKM"]
[Thu Jul 30 13:48:27.764000 2026] [security2:error] [pid 935860:tid 936058] [client 103.242.199.184:50907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuce4ijB6THqIZZsUIrjQAAAMg"]
[Thu Jul 30 13:48:27.764135 2026] [security2:error] [pid 935860:tid 936058] [client 103.242.199.184:50907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuce4ijB6THqIZZsUIrjQAAAMg"]
[Thu Jul 30 13:48:27.843766 2026] [security2:error] [pid 935860:tid 936020] [client 185.177.72.22:50218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuce4ijB6THqIZZsUIrjAAAAKI"]
[Thu Jul 30 13:48:27.978856 2026] [security2:error] [pid 935860:tid 936112] [client 185.177.72.22:50218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/server.php"] [unique_id "amuce4ijB6THqIZZsUIrlQAAAP4"]
[Thu Jul 30 13:48:28.230392 2026] [security2:error] [pid 935860:tid 936012] [client 185.177.72.22:16208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/server.php.%252e"] [unique_id "amucfIijB6THqIZZsUIrqgAAAJo"]
[Thu Jul 30 13:48:28.248675 2026] [security2:error] [pid 935860:tid 936085] [client 78.167.1.90:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucfIijB6THqIZZsUIrqwAAAOM"]
[Thu Jul 30 13:48:28.249231 2026] [security2:error] [pid 935860:tid 936085] [client 78.167.1.90:56223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucfIijB6THqIZZsUIrqwAAAOM"]
[Thu Jul 30 13:48:28.306830 2026] [security2:error] [pid 935860:tid 935912] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/app.swp"] [unique_id "amucfIijB6THqIZZsUIrrQAA_DI"]
[Thu Jul 30 13:48:28.480720 2026] [security2:error] [pid 935860:tid 936053] [client 185.177.72.22:16214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/server.php%0a"] [unique_id "amucfIijB6THqIZZsUIrtQAAAMM"]
[Thu Jul 30 13:48:28.721045 2026] [proxy:error] [pid 935860:tid 936015] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:28.721127 2026] [proxy_http:error] [pid 935860:tid 936015] [client 98.87.102.177:15453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:28.721688 2026] [proxy:error] [pid 935860:tid 936015] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:28.721729 2026] [proxy_http:error] [pid 935860:tid 936015] [client 98.87.102.177:15453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:28.727951 2026] [security2:error] [pid 935860:tid 936049] [client 185.177.72.22:16226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/server.php%5e"] [unique_id "amucfIijB6THqIZZsUIrxwAAAL8"]
[Thu Jul 30 13:48:28.756218 2026] [proxy:error] [pid 935860:tid 936061] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:28.756297 2026] [proxy_http:error] [pid 935860:tid 936061] [client 18.211.55.47:41338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:28.757145 2026] [proxy:error] [pid 935860:tid 936061] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:28.757217 2026] [proxy_http:error] [pid 935860:tid 936061] [client 18.211.55.47:41338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:29.067490 2026] [security2:error] [pid 935860:tid 935919] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htpasswd"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.terraform.htpasswd"] [unique_id "amucfYijB6THqIZZsUIr3gAAxTk"]
[Thu Jul 30 13:48:29.516360 2026] [security2:error] [pid 935860:tid 935872] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/log.txt~"] [unique_id "amucfYijB6THqIZZsUIr8AAA8Ao"]
[Thu Jul 30 13:48:29.646735 2026] [security2:error] [pid 935860:tid 935987] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/log.txt.bak"] [unique_id "amucfYijB6THqIZZsUIr9QAAxn0"]
[Thu Jul 30 13:48:29.656694 2026] [security2:error] [pid 935860:tid 936051] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucfYijB6THqIZZsUIr3QAAwUU"]
[Thu Jul 30 13:48:29.658335 2026] [security2:error] [pid 935860:tid 936024] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucfYijB6THqIZZsUIr8QAAAKY"]
[Thu Jul 30 13:48:29.907128 2026] [security2:error] [pid 935860:tid 936074] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucfYijB6THqIZZsUIr_AAAANg"]
[Thu Jul 30 13:48:30.159085 2026] [security2:error] [pid 935860:tid 936039] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucfoijB6THqIZZsUIsAgAAALU"]
[Thu Jul 30 13:48:30.221493 2026] [core:error] [pid 935860:tid 936049] [client 46.232.235.4:37884] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:48:30.221526 2026] [core:error] [pid 935860:tid 936049] [client 46.232.235.4:37884] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:48:30.405665 2026] [security2:error] [pid 935860:tid 936089] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucfoijB6THqIZZsUIsDgAAAOc"]
[Thu Jul 30 13:48:30.906110 2026] [security2:error] [pid 935860:tid 936068] [client 181.116.200.68:20029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucfoijB6THqIZZsUIsJQAAANI"]
[Thu Jul 30 13:48:30.906800 2026] [security2:error] [pid 935860:tid 936068] [client 181.116.200.68:20029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucfoijB6THqIZZsUIsJQAAANI"]
[Thu Jul 30 13:48:30.972837 2026] [security2:error] [pid 935860:tid 936060] [client 172.237.109.114:58488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/ShareMgnt/Usrm_GetAllUsers"] [unique_id "amucfoijB6THqIZZsUIsJwAAAMo"]
[Thu Jul 30 13:48:31.213176 2026] [security2:error] [pid 935860:tid 936031] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucf4ijB6THqIZZsUIsLQAAAK0"]
[Thu Jul 30 13:48:31.461162 2026] [security2:error] [pid 935860:tid 936053] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucf4ijB6THqIZZsUIsNwAAAMM"]
[Thu Jul 30 13:48:31.659033 2026] [security2:error] [pid 935860:tid 935944] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/nodeapi%00"] [unique_id "amucf4ijB6THqIZZsUIsQAAA5VI"]
[Thu Jul 30 13:48:31.709791 2026] [security2:error] [pid 935860:tid 936034] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucf4ijB6THqIZZsUIsPwAAALA"]
[Thu Jul 30 13:48:31.787891 2026] [security2:error] [pid 935860:tid 935980] [remote 216.73.217.142:36445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amucf4ijB6THqIZZsUIsTwAAnXY"]
[Thu Jul 30 13:48:31.788721 2026] [security2:error] [pid 935860:tid 935989] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucf4ijB6THqIZZsUIsUAAAkX8"]
[Thu Jul 30 13:48:31.807837 2026] [security2:error] [pid 935860:tid 936074] [client 103.190.40.154:16306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucf4ijB6THqIZZsUIsUQAAANg"]
[Thu Jul 30 13:48:31.807945 2026] [security2:error] [pid 935860:tid 936074] [client 103.190.40.154:16306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucf4ijB6THqIZZsUIsUQAAANg"]
[Thu Jul 30 13:48:31.919291 2026] [security2:error] [pid 935860:tid 935884] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucf4ijB6THqIZZsUIsUwAA2hY"]
[Thu Jul 30 13:48:31.954849 2026] [security2:error] [pid 935860:tid 936061] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucf4ijB6THqIZZsUIsUgAAAMs"]
[Thu Jul 30 13:48:32.048951 2026] [security2:error] [pid 935860:tid 935926] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucgIijB6THqIZZsUIsVQAAo0A"]
[Thu Jul 30 13:48:32.179413 2026] [security2:error] [pid 935860:tid 935909] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/.env"] [unique_id "amucgIijB6THqIZZsUIsWQAA8S8"]
[Thu Jul 30 13:48:32.201123 2026] [security2:error] [pid 935860:tid 936070] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucgIijB6THqIZZsUIsWAAAANQ"]
[Thu Jul 30 13:48:32.447336 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucgIijB6THqIZZsUIsYgAAANk"]
[Thu Jul 30 13:48:32.695380 2026] [security2:error] [pid 935860:tid 936044] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucgIijB6THqIZZsUIsaAAAALo"]
[Thu Jul 30 13:48:32.942993 2026] [security2:error] [pid 935860:tid 936035] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucgIijB6THqIZZsUIsdgAAALE"]
[Thu Jul 30 13:48:33.152000 2026] [security2:error] [pid 935860:tid 936012] [client 172.237.109.114:43238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/.antproxy.php"] [unique_id "amucgYijB6THqIZZsUIsgwAAAJo"]
[Thu Jul 30 13:48:33.334769 2026] [security2:error] [pid 935860:tid 936040] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucgYijB6THqIZZsUIshAAAALY"]
[Thu Jul 30 13:48:33.595210 2026] [security2:error] [pid 935860:tid 936090] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucgYijB6THqIZZsUIskQAAAOg"]
[Thu Jul 30 13:48:33.847120 2026] [security2:error] [pid 935860:tid 936039] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucgYijB6THqIZZsUIslwAAALU"]
[Thu Jul 30 13:48:34.114798 2026] [security2:error] [pid 935860:tid 936027] [client 185.177.72.22:16234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucgYijB6THqIZZsUIspAAAAKk"]
[Thu Jul 30 13:48:34.248781 2026] [fcgid:warn] [pid 935860:tid 936114] (70014)End of file found: [client 185.177.72.22:16234] mod_fcgid: can't get data from http client
[Thu Jul 30 13:48:34.504155 2026] [fcgid:warn] [pid 935860:tid 936081] (70014)End of file found: [client 185.177.72.22:16246] mod_fcgid: can't get data from http client
[Thu Jul 30 13:48:34.759161 2026] [fcgid:warn] [pid 935860:tid 936069] (70014)End of file found: [client 185.177.72.22:16250] mod_fcgid: can't get data from http client
[Thu Jul 30 13:48:35.013028 2026] [fcgid:warn] [pid 935860:tid 936024] (70014)End of file found: [client 185.177.72.22:16252] mod_fcgid: can't get data from http client
[Thu Jul 30 13:48:35.327471 2026] [security2:error] [pid 935860:tid 935961] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.ad-company.net"] [uri "/projects.bak"] [unique_id "amucg4ijB6THqIZZsUIs1QAAq2M"]
[Thu Jul 30 13:48:35.388264 2026] [security2:error] [pid 935860:tid 936018] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucg4ijB6THqIZZsUIszgAAAKA"]
[Thu Jul 30 13:48:35.460257 2026] [security2:error] [pid 935860:tid 935862] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.ad-company.net"] [uri "/wp-config.php.backup"] [unique_id "amucg4ijB6THqIZZsUIs2QAA1gA"]
[Thu Jul 30 13:48:35.588737 2026] [security2:error] [pid 935860:tid 935894] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.ad-company.net"] [uri "/wp-config.php.backup%253e"] [unique_id "amucg4ijB6THqIZZsUIs3QAAnSA"]
[Thu Jul 30 13:48:35.629678 2026] [security2:error] [pid 935860:tid 936082] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucg4ijB6THqIZZsUIs2gAAAOA"]
[Thu Jul 30 13:48:35.718460 2026] [security2:error] [pid 935860:tid 935891] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.ad-company.net"] [uri "/wp-config.php.backup%7c"] [unique_id "amucg4ijB6THqIZZsUIs3gAA1x0"]
[Thu Jul 30 13:48:35.832301 2026] [security2:error] [pid 935860:tid 936103] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucg4ijB6THqIZZsUIszQAA9V8"]
[Thu Jul 30 13:48:35.847579 2026] [security2:error] [pid 935860:tid 935959] [remote 185.177.72.56:2998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.ad-company.net"] [uri "/wp-config.php.backup.zshrc"] [unique_id "amucg4ijB6THqIZZsUIs4wAAy2E"]
[Thu Jul 30 13:48:35.873504 2026] [security2:error] [pid 935860:tid 936058] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucg4ijB6THqIZZsUIs3wAAAMg"]
[Thu Jul 30 13:48:36.112526 2026] [security2:error] [pid 935860:tid 936026] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucg4ijB6THqIZZsUIs7gAAAKg"]
[Thu Jul 30 13:48:36.353103 2026] [security2:error] [pid 935860:tid 936097] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuchIijB6THqIZZsUIs8gAAAO8"]
[Thu Jul 30 13:48:36.587416 2026] [security2:error] [pid 935860:tid 936112] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuchIijB6THqIZZsUItAQAAAP4"]
[Thu Jul 30 13:48:36.827659 2026] [security2:error] [pid 935860:tid 936002] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuchIijB6THqIZZsUItBAAAAJA"]
[Thu Jul 30 13:48:37.066248 2026] [security2:error] [pid 935860:tid 936016] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuchIijB6THqIZZsUItDwAAAJ4"]
[Thu Jul 30 13:48:37.310112 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuchYijB6THqIZZsUItFwAAAMc"]
[Thu Jul 30 13:48:37.745315 2026] [core:notice] [pid 935860:tid 936095] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:37.932254 2026] [security2:error] [pid 935860:tid 935991] [client 185.177.72.22:16266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env.backup"] [unique_id "amuchYijB6THqIZZsUItPQAAAIU"]
[Thu Jul 30 13:48:38.087031 2026] [fcgid:warn] [pid 935860:tid 936022] (70014)End of file found: [client 172.237.109.114:15355] mod_fcgid: can't get data from http client
[Thu Jul 30 13:48:38.185200 2026] [security2:error] [pid 935860:tid 936093] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuchoijB6THqIZZsUItQgAAAOs"]
[Thu Jul 30 13:48:38.397598 2026] [security2:error] [pid 935860:tid 936005] [client 103.242.199.184:51466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuchoijB6THqIZZsUItVAAAAJM"]
[Thu Jul 30 13:48:38.397756 2026] [security2:error] [pid 935860:tid 936005] [client 103.242.199.184:51466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuchoijB6THqIZZsUItVAAAAJM"]
[Thu Jul 30 13:48:38.426329 2026] [security2:error] [pid 935860:tid 936109] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuchoijB6THqIZZsUItTwAAAPs"]
[Thu Jul 30 13:48:38.664269 2026] [security2:error] [pid 935860:tid 936063] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuchoijB6THqIZZsUItXQAAAM0"]
[Thu Jul 30 13:48:38.789547 2026] [security2:error] [pid 935860:tid 936090] [client 185.177.72.22:16266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env.backup"] [unique_id "amuchoijB6THqIZZsUItYgAAAOg"]
[Thu Jul 30 13:48:39.026110 2026] [security2:error] [pid 935860:tid 936018] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuchoijB6THqIZZsUItaAAAAKA"]
[Thu Jul 30 13:48:39.263064 2026] [security2:error] [pid 935860:tid 936054] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuch4ijB6THqIZZsUItcwAAAMQ"]
[Thu Jul 30 13:48:39.499206 2026] [security2:error] [pid 935860:tid 936083] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuch4ijB6THqIZZsUItdwAAAOE"]
[Thu Jul 30 13:48:39.578175 2026] [security2:error] [pid 935860:tid 936055] [client 85.208.96.206:25990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/crime-em-alagoa-nova/"] [unique_id "amuch4ijB6THqIZZsUItgAAAAMU"]
[Thu Jul 30 13:48:39.578258 2026] [security2:error] [pid 935860:tid 936055] [client 85.208.96.206:25990] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/crime-em-alagoa-nova/"] [unique_id "amuch4ijB6THqIZZsUItgAAAAMU"]
[Thu Jul 30 13:48:39.733474 2026] [security2:error] [pid 935860:tid 936115] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuch4ijB6THqIZZsUIthgAAAQE"]
[Thu Jul 30 13:48:39.846574 2026] [security2:error] [pid 935860:tid 935991] [client 78.167.1.90:56596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuch4ijB6THqIZZsUItiQAAAIU"]
[Thu Jul 30 13:48:39.847367 2026] [security2:error] [pid 935860:tid 935991] [client 78.167.1.90:56596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuch4ijB6THqIZZsUItiQAAAIU"]
[Thu Jul 30 13:48:39.880994 2026] [security2:error] [pid 935860:tid 936071] [client 89.124.71.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyfluoxetine.store"] [uri "/login/index.php"] [unique_id "amuch4ijB6THqIZZsUIthwAAANU"]
[Thu Jul 30 13:48:39.971204 2026] [security2:error] [pid 935860:tid 936048] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuch4ijB6THqIZZsUItigAAAL4"]
[Thu Jul 30 13:48:39.981748 2026] [security2:error] [pid 935860:tid 936050] [client 172.237.109.114:50287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:< ?script|(?:<|< ?/)(?:(?:java|vb)script|about|applet|activex|chrome|qx?ss|embed)|< ?/?i?frame\\\\b)" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1079"] [id "340147"] [rev "141"] [msg "Atomicorp.com WAF Rules: Potential Cross Site Scripting Attack"] [data "<script"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/Visitor/bin/WebStrings.srf"] [unique_id "amuch4ijB6THqIZZsUItjQAAAMA"]
[Thu Jul 30 13:48:40.207619 2026] [security2:error] [pid 935860:tid 936004] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuciIijB6THqIZZsUItlQAAAJI"]
[Thu Jul 30 13:48:40.309048 2026] [security2:error] [pid 935860:tid 935869] [remote 185.177.72.56:60808] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/"] [unique_id "amuciIijB6THqIZZsUItmQAAmQc"]
[Thu Jul 30 13:48:40.444603 2026] [security2:error] [pid 935860:tid 936001] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuciIijB6THqIZZsUItmgAAAI8"]
[Thu Jul 30 13:48:40.569596 2026] [security2:error] [pid 935860:tid 936035] [client 185.177.72.22:16266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/api.orig"] [unique_id "amuciIijB6THqIZZsUItngAAALE"]
[Thu Jul 30 13:48:40.688565 2026] [security2:error] [pid 935860:tid 935873] [remote 185.177.72.56:60836] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/_next"] [unique_id "amuciIijB6THqIZZsUItpQAA_Qs"]
[Thu Jul 30 13:48:40.803816 2026] [security2:error] [pid 935860:tid 936100] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuciIijB6THqIZZsUItpwAAAPI"]
[Thu Jul 30 13:48:41.043000 2026] [security2:error] [pid 935860:tid 935997] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuciIijB6THqIZZsUItqgAAAIs"]
[Thu Jul 30 13:48:41.066065 2026] [security2:error] [pid 935860:tid 935909] [remote 185.177.72.56:60866] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/api"] [unique_id "amuciYijB6THqIZZsUItrgAAvS8"]
[Thu Jul 30 13:48:41.224586 2026] [core:notice] [pid 935860:tid 935981] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:41.279863 2026] [security2:error] [pid 935860:tid 936076] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuciYijB6THqIZZsUIttQAAANo"]
[Thu Jul 30 13:48:41.406989 2026] [security2:error] [pid 935860:tid 936021] [client 185.177.72.22:16266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/src.orig"] [unique_id "amuciYijB6THqIZZsUItvAAAAKM"]
[Thu Jul 30 13:48:41.464850 2026] [security2:error] [pid 935860:tid 935914] [remote 185.177.72.56:56534] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/api/auth"] [unique_id "amuciYijB6THqIZZsUItvQAAvDQ"]
[Thu Jul 30 13:48:41.535027 2026] [security2:error] [pid 935860:tid 936064] [client 181.116.200.68:48860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuciYijB6THqIZZsUItwgAAAM4"]
[Thu Jul 30 13:48:41.535131 2026] [security2:error] [pid 935860:tid 936064] [client 181.116.200.68:48860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuciYijB6THqIZZsUItwgAAAM4"]
[Thu Jul 30 13:48:41.851870 2026] [security2:error] [pid 935860:tid 935903] [remote 185.177.72.56:56540] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/api/auth/callback"] [unique_id "amuciYijB6THqIZZsUIt2QAA0Ck"]
[Thu Jul 30 13:48:42.144941 2026] [security2:error] [pid 935860:tid 936101] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucioijB6THqIZZsUIt3wAAAPM"]
[Thu Jul 30 13:48:42.252322 2026] [security2:error] [pid 935860:tid 935939] [remote 185.177.72.56:56548] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/api/auth/session"] [unique_id "amucioijB6THqIZZsUIt6wAA9k0"]
[Thu Jul 30 13:48:42.382527 2026] [security2:error] [pid 935860:tid 936005] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucioijB6THqIZZsUIt7AAAAJM"]
[Thu Jul 30 13:48:42.477562 2026] [security2:error] [pid 935860:tid 936105] [client 172.237.109.114:35376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuciYijB6THqIZZsUIt3QAAAPc"]
[Thu Jul 30 13:48:42.481036 2026] [security2:error] [pid 935860:tid 936092] [client 103.190.40.154:21884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucioijB6THqIZZsUIuDAAAAOo"]
[Thu Jul 30 13:48:42.481171 2026] [security2:error] [pid 935860:tid 936092] [client 103.190.40.154:21884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucioijB6THqIZZsUIuDAAAAOo"]
[Thu Jul 30 13:48:42.506941 2026] [security2:error] [pid 935860:tid 936034] [client 89.124.71.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyfluoxetine.store"] [uri "/login/index.php"] [unique_id "amucioijB6THqIZZsUIuFwAAALA"]
[Thu Jul 30 13:48:42.618922 2026] [security2:error] [pid 935860:tid 936024] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucioijB6THqIZZsUIuFgAAAKY"]
[Thu Jul 30 13:48:42.658076 2026] [security2:error] [pid 935860:tid 935919] [remote 185.177.72.56:56550] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/_rsc"] [unique_id "amucioijB6THqIZZsUIuHAAA1jk"]
[Thu Jul 30 13:48:42.860434 2026] [security2:error] [pid 935860:tid 936070] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucioijB6THqIZZsUIuIAAAANQ"]
[Thu Jul 30 13:48:43.064729 2026] [security2:error] [pid 935860:tid 935921] [remote 185.177.72.56:56562] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/__rsc"] [unique_id "amuci4ijB6THqIZZsUIuKAAA7Ts"]
[Thu Jul 30 13:48:43.098293 2026] [security2:error] [pid 935860:tid 936055] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucioijB6THqIZZsUIuJgAAAMU"]
[Thu Jul 30 13:48:43.338318 2026] [security2:error] [pid 935860:tid 935991] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuci4ijB6THqIZZsUIuKwAAAIU"]
[Thu Jul 30 13:48:43.451890 2026] [security2:error] [pid 935860:tid 935987] [remote 185.177.72.56:56566] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/.action"] [unique_id "amuci4ijB6THqIZZsUIuOQAA8H0"]
[Thu Jul 30 13:48:43.576230 2026] [security2:error] [pid 935860:tid 936012] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuci4ijB6THqIZZsUIuOgAAAJo"]
[Thu Jul 30 13:48:43.812807 2026] [security2:error] [pid 935860:tid 936002] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuci4ijB6THqIZZsUIuPwAAAJA"]
[Thu Jul 30 13:48:43.832796 2026] [security2:error] [pid 935860:tid 935893] [remote 185.177.72.56:56570] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/__nextjs_action"] [unique_id "amuci4ijB6THqIZZsUIuQwAArx8"]
[Thu Jul 30 13:48:44.054122 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuci4ijB6THqIZZsUIuSAAAAL0"]
[Thu Jul 30 13:48:44.229950 2026] [security2:error] [pid 935860:tid 935885] [remote 185.177.72.56:56582] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/_middleware"] [unique_id "amucjIijB6THqIZZsUIuUwAAihc"]
[Thu Jul 30 13:48:44.306685 2026] [security2:error] [pid 935860:tid 936042] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjIijB6THqIZZsUIuUQAAALg"]
[Thu Jul 30 13:48:44.543415 2026] [security2:error] [pid 935860:tid 936070] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjIijB6THqIZZsUIuYgAAANQ"]
[Thu Jul 30 13:48:44.612242 2026] [security2:error] [pid 935860:tid 935943] [remote 185.177.72.56:56584] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/_next/image"] [unique_id "amucjIijB6THqIZZsUIuZQAA3FE"]
[Thu Jul 30 13:48:44.786038 2026] [security2:error] [pid 935860:tid 936013] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjIijB6THqIZZsUIuZgAAAJs"]
[Thu Jul 30 13:48:44.961334 2026] [security2:error] [pid 935860:tid 936079] [client 172.237.109.114:41086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjIijB6THqIZZsUIucwAAAN0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:44.961379 2026] [security2:error] [pid 935860:tid 936000] [client 172.237.109.114:60895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjIijB6THqIZZsUIucgAAAI4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:44.972750 2026] [security2:error] [pid 935860:tid 936116] [client 172.237.109.114:12603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjIijB6THqIZZsUIudAAAAQI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:44.973188 2026] [security2:error] [pid 935860:tid 936071] [client 172.237.109.114:32393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjIijB6THqIZZsUIudQAAANU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:44.977140 2026] [security2:error] [pid 935860:tid 935994] [client 172.237.109.114:48123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjIijB6THqIZZsUIudgAAAIg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:44.990345 2026] [security2:error] [pid 935860:tid 935876] [remote 185.177.72.56:56588] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/RSC/fpsmc8b2tuc4ulh.txt"] [unique_id "amucjIijB6THqIZZsUIudwAAuw4"]
[Thu Jul 30 13:48:44.990920 2026] [security2:error] [pid 935860:tid 936027] [client 172.237.109.114:27288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjIijB6THqIZZsUIueAAAAKk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:44.992232 2026] [security2:error] [pid 935860:tid 936110] [client 172.237.109.114:38948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjIijB6THqIZZsUIueQAAAPw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:44.993351 2026] [security2:error] [pid 935860:tid 936093] [client 172.237.109.114:57700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjIijB6THqIZZsUIuegAAAOs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.009486 2026] [security2:error] [pid 935860:tid 936069] [client 172.237.109.114:9318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIuewAAANM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.009520 2026] [security2:error] [pid 935860:tid 936067] [client 172.237.109.114:61653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIufAAAANE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.009557 2026] [security2:error] [pid 935860:tid 935991] [client 172.237.109.114:58249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIufgAAAIU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.009682 2026] [security2:error] [pid 935860:tid 936037] [client 172.237.109.114:48310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIufQAAALM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.010715 2026] [security2:error] [pid 935860:tid 936101] [client 172.237.109.114:43359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIufwAAAPM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.011552 2026] [security2:error] [pid 935860:tid 936104] [client 172.237.109.114:52527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIugAAAAPY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.012308 2026] [security2:error] [pid 935860:tid 936050] [client 172.237.109.114:7736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIugQAAAMA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.027525 2026] [security2:error] [pid 935860:tid 936044] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjIijB6THqIZZsUIubgAAALo"]
[Thu Jul 30 13:48:45.292811 2026] [security2:error] [pid 935860:tid 936006] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjYijB6THqIZZsUIugwAAAJQ"]
[Thu Jul 30 13:48:45.378222 2026] [security2:error] [pid 935860:tid 935984] [remote 185.177.72.56:56592] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "autodiscover.ad-company.net"] [uri "/RSC/R/st65yom22wnxef1.txt"] [unique_id "amucjYijB6THqIZZsUIuhwAAzXo"]
[Thu Jul 30 13:48:45.388038 2026] [security2:error] [pid 935860:tid 936085] [client 89.124.71.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyfluoxetine.store"] [uri "/login/index.php"] [unique_id "amucjYijB6THqIZZsUIuiAAAAOM"]
[Thu Jul 30 13:48:45.533769 2026] [security2:error] [pid 935860:tid 936105] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjYijB6THqIZZsUIujAAAAPc"]
[Thu Jul 30 13:48:45.642928 2026] [security2:error] [pid 935860:tid 936102] [client 185.177.72.56:65152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucjYijB6THqIZZsUIulAAAAPQ"]
[Thu Jul 30 13:48:45.705817 2026] [security2:error] [pid 935860:tid 935978] [remote 89.42.136.2:51194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.136.42.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIujgAAwXQ"]
[Thu Jul 30 13:48:45.771888 2026] [security2:error] [pid 935860:tid 936072] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjYijB6THqIZZsUIulQAAANY"]
[Thu Jul 30 13:48:45.893386 2026] [security2:error] [pid 935860:tid 936083] [client 185.177.72.56:65166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amucjYijB6THqIZZsUIunwAAAOE"]
[Thu Jul 30 13:48:45.961347 2026] [security2:error] [pid 935860:tid 936028] [client 172.237.109.114:33922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIuowAAAKo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.970830 2026] [security2:error] [pid 935860:tid 936078] [client 172.237.109.114:57488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIupAAAANw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.970905 2026] [security2:error] [pid 935860:tid 936078] [client 172.237.109.114:57488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIupAAAANw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.991965 2026] [security2:error] [pid 935860:tid 935993] [client 172.237.109.114:56835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIupQAAAIc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:45.992010 2026] [security2:error] [pid 935860:tid 936095] [client 172.237.109.114:1043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjYijB6THqIZZsUIupgAAAO0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:46.010170 2026] [security2:error] [pid 935860:tid 936062] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjYijB6THqIZZsUIuoQAAAMw"]
[Thu Jul 30 13:48:46.011541 2026] [security2:error] [pid 935860:tid 936020] [client 172.237.109.114:38039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucjoijB6THqIZZsUIupwAAAKI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:48:46.158085 2026] [security2:error] [pid 935860:tid 936000] [client 185.177.72.56:65172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucjoijB6THqIZZsUIuqgAAAI4"]
[Thu Jul 30 13:48:46.260636 2026] [security2:error] [pid 935860:tid 936081] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjoijB6THqIZZsUIuqAAAAN8"]
[Thu Jul 30 13:48:46.423034 2026] [security2:error] [pid 935860:tid 936044] [client 185.177.72.56:65182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucjoijB6THqIZZsUIutgAAALo"]
[Thu Jul 30 13:48:46.497630 2026] [security2:error] [pid 935860:tid 936037] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjoijB6THqIZZsUIutAAAALM"]
[Thu Jul 30 13:48:46.686873 2026] [security2:error] [pid 935860:tid 936066] [client 85.208.96.205:33634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/23/brasileiro-matheus-martins-brilha-e-flu-arranca-empate-com-botafogo/"] [unique_id "amucjoijB6THqIZZsUIuuwAAANA"]
[Thu Jul 30 13:48:46.687039 2026] [security2:error] [pid 935860:tid 936066] [client 85.208.96.205:33634] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/23/brasileiro-matheus-martins-brilha-e-flu-arranca-empate-com-botafogo/"] [unique_id "amucjoijB6THqIZZsUIuuwAAANA"]
[Thu Jul 30 13:48:46.689773 2026] [security2:error] [pid 935860:tid 936094] [client 185.177.72.56:65198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucjoijB6THqIZZsUIuvAAAAOw"]
[Thu Jul 30 13:48:46.740033 2026] [security2:error] [pid 935860:tid 936004] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucjoijB6THqIZZsUIuugAAAJI"]
[Thu Jul 30 13:48:46.910757 2026] [security2:error] [pid 935860:tid 936064] [client 74.7.175.163:60426] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.zor.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amucjoijB6THqIZZsUIuxAAAzkA"]
[Thu Jul 30 13:48:46.942903 2026] [security2:error] [pid 935860:tid 936002] [client 185.177.72.56:65204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ad-company.net"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucjoijB6THqIZZsUIuxQAAAJA"]
[Thu Jul 30 13:48:47.476828 2026] [security2:error] [pid 935860:tid 936086] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucj4ijB6THqIZZsUIu0AAAAOQ"]
[Thu Jul 30 13:48:47.715397 2026] [security2:error] [pid 935860:tid 936089] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucj4ijB6THqIZZsUIu3wAAAOc"]
[Thu Jul 30 13:48:47.952786 2026] [security2:error] [pid 935860:tid 936070] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucj4ijB6THqIZZsUIu5AAAANQ"]
[Thu Jul 30 13:48:48.191104 2026] [security2:error] [pid 935860:tid 936093] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuckIijB6THqIZZsUIu8AAAAOs"]
[Thu Jul 30 13:48:48.341356 2026] [security2:error] [pid 935860:tid 936101] [client 89.124.71.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyfluoxetine.store"] [uri "/login/index.php"] [unique_id "amuckIijB6THqIZZsUIu8gAAAPM"]
[Thu Jul 30 13:48:48.929490 2026] [security2:error] [pid 935860:tid 936111] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuckIijB6THqIZZsUIvAQAAAP0"]
[Thu Jul 30 13:48:49.048549 2026] [security2:error] [pid 935860:tid 936063] [client 103.242.199.184:52030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuckYijB6THqIZZsUIvCAAAAM0"]
[Thu Jul 30 13:48:49.048704 2026] [security2:error] [pid 935860:tid 936063] [client 103.242.199.184:52030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuckYijB6THqIZZsUIvCAAAAM0"]
[Thu Jul 30 13:48:49.301792 2026] [security2:error] [pid 935860:tid 936082] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuckYijB6THqIZZsUIvDwAAAOA"]
[Thu Jul 30 13:48:49.385810 2026] [security2:error] [pid 935860:tid 935997] [client 119.73.97.132:30093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuckYijB6THqIZZsUIvEAAAi00"], referer: https://www.urwru.club/wp-admin/post.php?post=1073&action=elementor
[Thu Jul 30 13:48:49.427031 2026] [security2:error] [pid 935860:tid 936084] [client 185.177.72.22:16266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/libs~"] [unique_id "amuckYijB6THqIZZsUIvGAAAAOI"]
[Thu Jul 30 13:48:49.669104 2026] [security2:error] [pid 935860:tid 936041] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuckYijB6THqIZZsUIvGwAAALc"]
[Thu Jul 30 13:48:50.038193 2026] [security2:error] [pid 935860:tid 936078] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuckYijB6THqIZZsUIvIwAAANw"]
[Thu Jul 30 13:48:50.278148 2026] [security2:error] [pid 935860:tid 936070] [client 185.177.72.22:16266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuckoijB6THqIZZsUIvLAAAANQ"]
[Thu Jul 30 13:48:50.467077 2026] [security2:error] [pid 935860:tid 936079] [client 78.167.1.90:55510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuckoijB6THqIZZsUIvMgAAAN0"]
[Thu Jul 30 13:48:50.467569 2026] [security2:error] [pid 935860:tid 936079] [client 78.167.1.90:55510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuckoijB6THqIZZsUIvMgAAAN0"]
[Thu Jul 30 13:48:50.581960 2026] [security2:error] [pid 935860:tid 936071] [client 35.169.102.85:37318] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "radiojelli.com"] [uri "/img/articles/43/thank-you-for-your-forever-kind-friendship.jpg"] [unique_id "amuckoijB6THqIZZsUIvOQAAANU"]
[Thu Jul 30 13:48:51.136740 2026] [security2:error] [pid 935860:tid 936035] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuck4ijB6THqIZZsUIvQwAAALE"]
[Thu Jul 30 13:48:51.192451 2026] [security2:error] [pid 935860:tid 935959] [remote 57.141.0.55:39630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55089810635/feed/rss2/"] [unique_id "amuck4ijB6THqIZZsUIvRwAAxmE"]
[Thu Jul 30 13:48:51.372084 2026] [security2:error] [pid 935860:tid 935998] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuck4ijB6THqIZZsUIvTAAAAIw"]
[Thu Jul 30 13:48:51.616163 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuck4ijB6THqIZZsUIvTwAAAMc"]
[Thu Jul 30 13:48:51.860997 2026] [security2:error] [pid 935860:tid 936021] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuck4ijB6THqIZZsUIvWAAAAKM"]
[Thu Jul 30 13:48:52.034591 2026] [core:notice] [pid 935860:tid 936046] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:52.082383 2026] [security2:error] [pid 935860:tid 936026] [client 89.124.71.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyfluoxetine.store"] [uri "/login/index.php"] [unique_id "amuclIijB6THqIZZsUIvYAAAAKg"]
[Thu Jul 30 13:48:52.095952 2026] [security2:error] [pid 935860:tid 936022] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuck4ijB6THqIZZsUIvXAAAAKQ"]
[Thu Jul 30 13:48:52.124515 2026] [security2:error] [pid 935860:tid 936091] [client 181.116.200.68:55756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuclIijB6THqIZZsUIvZAAAAOk"]
[Thu Jul 30 13:48:52.124607 2026] [security2:error] [pid 935860:tid 936091] [client 181.116.200.68:55756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuclIijB6THqIZZsUIvZAAAAOk"]
[Thu Jul 30 13:48:52.285760 2026] [security2:error] [pid 935860:tid 936049] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuck4ijB6THqIZZsUIvUwAAvyc"]
[Thu Jul 30 13:48:52.714210 2026] [core:notice] [pid 935860:tid 936071] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:52.830571 2026] [security2:error] [pid 935860:tid 936017] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuclIijB6THqIZZsUIvgwAAAJ8"]
[Thu Jul 30 13:48:53.066954 2026] [security2:error] [pid 935860:tid 936029] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuclIijB6THqIZZsUIviQAAAKs"]
[Thu Jul 30 13:48:53.163265 2026] [security2:error] [pid 935860:tid 936064] [client 103.190.40.154:22548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuclYijB6THqIZZsUIvigAAAM4"]
[Thu Jul 30 13:48:53.163433 2026] [security2:error] [pid 935860:tid 936064] [client 103.190.40.154:22548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuclYijB6THqIZZsUIvigAAAM4"]
[Thu Jul 30 13:48:53.315486 2026] [security2:error] [pid 935860:tid 936002] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuclYijB6THqIZZsUIvjgAAAJA"]
[Thu Jul 30 13:48:53.553449 2026] [security2:error] [pid 935860:tid 936072] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuclYijB6THqIZZsUIvlgAAANY"]
[Thu Jul 30 13:48:53.795522 2026] [security2:error] [pid 935860:tid 936034] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuclYijB6THqIZZsUIvnAAAALA"]
[Thu Jul 30 13:48:54.037042 2026] [security2:error] [pid 935860:tid 936118] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuclYijB6THqIZZsUIvqAAAAQQ"]
[Thu Jul 30 13:48:54.279806 2026] [security2:error] [pid 935860:tid 935993] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucloijB6THqIZZsUIvqgAAAIc"]
[Thu Jul 30 13:48:54.519660 2026] [security2:error] [pid 935860:tid 936074] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucloijB6THqIZZsUIvtQAAANg"]
[Thu Jul 30 13:48:54.769621 2026] [security2:error] [pid 935860:tid 935994] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucloijB6THqIZZsUIvtgAAAIg"]
[Thu Jul 30 13:48:55.005783 2026] [security2:error] [pid 935860:tid 936098] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucloijB6THqIZZsUIvwwAAAPA"]
[Thu Jul 30 13:48:55.242154 2026] [security2:error] [pid 935860:tid 936066] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucl4ijB6THqIZZsUIvxAAAANA"]
[Thu Jul 30 13:48:55.480405 2026] [security2:error] [pid 935860:tid 936032] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucl4ijB6THqIZZsUIvyAAAAK4"]
[Thu Jul 30 13:48:55.718151 2026] [security2:error] [pid 935860:tid 936064] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucl4ijB6THqIZZsUIvzwAAAM4"]
[Thu Jul 30 13:48:55.842123 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:22894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/wordpress.sql"] [unique_id "amucl4ijB6THqIZZsUIv1QAAAJY"]
[Thu Jul 30 13:48:56.079109 2026] [security2:error] [pid 935860:tid 936002] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucl4ijB6THqIZZsUIv2wAAAJA"]
[Thu Jul 30 13:48:56.169808 2026] [core:notice] [pid 935860:tid 935956] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:56.174240 2026] [security2:error] [pid 935860:tid 936003] [client 74.7.244.13:59258] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-ab4e48f3.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amucmIijB6THqIZZsUIv3wAAkV4"]
[Thu Jul 30 13:48:56.250526 2026] [core:notice] [pid 935860:tid 935898] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:56.264715 2026] [security2:error] [pid 935860:tid 935997] [client 43.155.27.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuclYijB6THqIZZsUIvpwAAi0U"]
[Thu Jul 30 13:48:56.317800 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucmIijB6THqIZZsUIv4AAAAL0"]
[Thu Jul 30 13:48:56.470183 2026] [security2:error] [pid 935860:tid 936085] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucl4ijB6THqIZZsUIv1wAAAOM"]
[Thu Jul 30 13:48:56.561883 2026] [security2:error] [pid 935860:tid 936089] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucmIijB6THqIZZsUIv6AAAAOc"]
[Thu Jul 30 13:48:57.012611 2026] [security2:error] [pid 935860:tid 935993] [client 89.124.71.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyfluoxetine.store"] [uri "/login/index.php"] [unique_id "amucmYijB6THqIZZsUIv-AAAAIc"]
[Thu Jul 30 13:48:57.178490 2026] [security2:error] [pid 935860:tid 936099] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucmIijB6THqIZZsUIv7gAA8Xg"]
[Thu Jul 30 13:48:57.181305 2026] [security2:error] [pid 935860:tid 936077] [client 185.177.72.22:22894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env~"] [unique_id "amucmYijB6THqIZZsUIv_QAAANs"]
[Thu Jul 30 13:48:57.210196 2026] [security2:error] [pid 935860:tid 935873] [remote 216.73.217.142:11167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amucmYijB6THqIZZsUIv_gAA1As"]
[Thu Jul 30 13:48:57.424260 2026] [security2:error] [pid 935860:tid 936074] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucmYijB6THqIZZsUIwBAAAANg"]
[Thu Jul 30 13:48:57.660141 2026] [security2:error] [pid 935860:tid 936007] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucmYijB6THqIZZsUIwCgAAAJU"]
[Thu Jul 30 13:48:57.784720 2026] [security2:error] [pid 935860:tid 935992] [client 185.177.72.22:22894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env~"] [unique_id "amucmYijB6THqIZZsUIwDgAAAIY"]
[Thu Jul 30 13:48:58.021362 2026] [security2:error] [pid 935860:tid 936111] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucmYijB6THqIZZsUIwEgAAAP0"]
[Thu Jul 30 13:48:58.064622 2026] [security2:error] [pid 935860:tid 935966] [remote 57.141.0.17:52046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amucmoijB6THqIZZsUIwFgAAmWg"]
[Thu Jul 30 13:48:58.145927 2026] [security2:error] [pid 935860:tid 936068] [client 185.177.72.22:22894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env~"] [unique_id "amucmoijB6THqIZZsUIwGgAAANI"]
[Thu Jul 30 13:48:58.384925 2026] [security2:error] [pid 935860:tid 936105] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucmoijB6THqIZZsUIwGwAAAPc"]
[Thu Jul 30 13:48:58.389900 2026] [proxy:error] [pid 935860:tid 935923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:58.389964 2026] [proxy_http:error] [pid 935860:tid 935923] [remote 74.7.241.152:59880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:58.390862 2026] [proxy:error] [pid 935860:tid 935923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:58.390927 2026] [proxy_http:error] [pid 935860:tid 935923] [remote 74.7.241.152:59880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:58.640268 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucmoijB6THqIZZsUIwIQAAAL0"]
[Thu Jul 30 13:48:58.747737 2026] [proxy:error] [pid 935860:tid 936041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:58.747826 2026] [proxy_http:error] [pid 935860:tid 936041] [client 54.87.222.253:17995] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:58.748441 2026] [proxy:error] [pid 935860:tid 936041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:58.748488 2026] [proxy_http:error] [pid 935860:tid 936041] [client 54.87.222.253:17995] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:58.761542 2026] [proxy:error] [pid 935860:tid 936113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:58.761616 2026] [proxy_http:error] [pid 935860:tid 936113] [client 54.87.222.253:31555] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:58.762475 2026] [proxy:error] [pid 935860:tid 936113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:48:58.762543 2026] [proxy_http:error] [pid 935860:tid 936113] [client 54.87.222.253:31555] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:48:58.882490 2026] [security2:error] [pid 935860:tid 936022] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucmoijB6THqIZZsUIwMAAAAKQ"]
[Thu Jul 30 13:48:58.977124 2026] [core:notice] [pid 935860:tid 935908] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:48:58.992757 2026] [security2:error] [pid 935860:tid 936066] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucmoijB6THqIZZsUIwHwAA0Hc"]
[Thu Jul 30 13:48:59.117407 2026] [security2:error] [pid 935860:tid 936099] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucm4ijB6THqIZZsUIwPAAAAPE"]
[Thu Jul 30 13:48:59.357050 2026] [security2:error] [pid 935860:tid 936079] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucm4ijB6THqIZZsUIwQwAAAN0"]
[Thu Jul 30 13:48:59.594437 2026] [security2:error] [pid 935860:tid 936043] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucm4ijB6THqIZZsUIwTQAAALk"]
[Thu Jul 30 13:48:59.744800 2026] [security2:error] [pid 935860:tid 936052] [client 103.242.199.184:52595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucm4ijB6THqIZZsUIwWwAAAMI"]
[Thu Jul 30 13:48:59.744914 2026] [security2:error] [pid 935860:tid 936052] [client 103.242.199.184:52595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucm4ijB6THqIZZsUIwWwAAAMI"]
[Thu Jul 30 13:48:59.837279 2026] [security2:error] [pid 935860:tid 936107] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucm4ijB6THqIZZsUIwWQAAAPk"]
[Thu Jul 30 13:48:59.875712 2026] [security2:error] [pid 935860:tid 936045] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucm4ijB6THqIZZsUIwRgAAALs"]
[Thu Jul 30 13:49:00.067334 2026] [security2:error] [pid 935860:tid 936029] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucm4ijB6THqIZZsUIwTAAAAKs"]
[Thu Jul 30 13:49:00.079531 2026] [security2:error] [pid 935860:tid 936036] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucm4ijB6THqIZZsUIwYAAAALI"]
[Thu Jul 30 13:49:00.097589 2026] [security2:error] [pid 935860:tid 936054] [client 78.167.1.90:54439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucnIijB6THqIZZsUIwZQAAAMQ"]
[Thu Jul 30 13:49:00.098305 2026] [security2:error] [pid 935860:tid 936054] [client 78.167.1.90:54439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucnIijB6THqIZZsUIwZQAAAMQ"]
[Thu Jul 30 13:49:00.100984 2026] [fcgid:warn] [pid 935860:tid 936076] (70014)End of file found: [client 172.237.109.114:1341] mod_fcgid: can't get data from http client
[Thu Jul 30 13:49:00.326547 2026] [security2:error] [pid 935860:tid 936048] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnIijB6THqIZZsUIwbAAAAL4"]
[Thu Jul 30 13:49:00.568236 2026] [security2:error] [pid 935860:tid 936059] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnIijB6THqIZZsUIwcgAAAMk"]
[Thu Jul 30 13:49:00.811363 2026] [security2:error] [pid 935860:tid 936069] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnIijB6THqIZZsUIweAAAANM"]
[Thu Jul 30 13:49:00.987143 2026] [security2:error] [pid 935860:tid 936049] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucnIijB6THqIZZsUIwcAAAvxI"]
[Thu Jul 30 13:49:01.050079 2026] [security2:error] [pid 935860:tid 936071] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnIijB6THqIZZsUIwfQAAANU"]
[Thu Jul 30 13:49:01.292090 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnYijB6THqIZZsUIwggAAAMc"]
[Thu Jul 30 13:49:01.529445 2026] [security2:error] [pid 935860:tid 936061] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnYijB6THqIZZsUIwiQAAAMs"]
[Thu Jul 30 13:49:01.665037 2026] [core:notice] [pid 935860:tid 935865] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:01.768686 2026] [security2:error] [pid 935860:tid 936082] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnYijB6THqIZZsUIwkQAAAOA"]
[Thu Jul 30 13:49:02.006470 2026] [security2:error] [pid 935860:tid 936076] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnYijB6THqIZZsUIwmgAAANo"]
[Thu Jul 30 13:49:02.256461 2026] [security2:error] [pid 935860:tid 936022] [client 89.124.71.45:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.71.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyfluoxetine.store"] [uri "/login/index.php"] [unique_id "amucnoijB6THqIZZsUIwoAAAAKQ"]
[Thu Jul 30 13:49:02.371453 2026] [security2:error] [pid 935860:tid 936030] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnoijB6THqIZZsUIwnwAAAKw"]
[Thu Jul 30 13:49:02.607457 2026] [security2:error] [pid 935860:tid 936099] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnoijB6THqIZZsUIwpwAAAPE"]
[Thu Jul 30 13:49:02.733550 2026] [security2:error] [pid 935860:tid 936088] [client 181.116.200.68:19197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucnoijB6THqIZZsUIwrAAAAOY"]
[Thu Jul 30 13:49:02.733652 2026] [security2:error] [pid 935860:tid 936088] [client 181.116.200.68:19197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucnoijB6THqIZZsUIwrAAAAOY"]
[Thu Jul 30 13:49:02.842722 2026] [security2:error] [pid 935860:tid 936083] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnoijB6THqIZZsUIwqwAAAOE"]
[Thu Jul 30 13:49:03.077529 2026] [security2:error] [pid 935860:tid 936038] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucnoijB6THqIZZsUIwuQAAALQ"]
[Thu Jul 30 13:49:03.319449 2026] [security2:error] [pid 935860:tid 936011] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucn4ijB6THqIZZsUIwvwAAAJk"]
[Thu Jul 30 13:49:03.562478 2026] [security2:error] [pid 935860:tid 936063] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucn4ijB6THqIZZsUIwxgAAAM0"]
[Thu Jul 30 13:49:03.797470 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucn4ijB6THqIZZsUIwywAAAOU"]
[Thu Jul 30 13:49:03.896660 2026] [security2:error] [pid 935860:tid 936100] [client 103.190.40.154:2585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucn4ijB6THqIZZsUIwzwAAAPI"]
[Thu Jul 30 13:49:03.896784 2026] [security2:error] [pid 935860:tid 936100] [client 103.190.40.154:2585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucn4ijB6THqIZZsUIwzwAAAPI"]
[Thu Jul 30 13:49:04.033346 2026] [security2:error] [pid 935860:tid 936025] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucn4ijB6THqIZZsUIw0wAAAKc"]
[Thu Jul 30 13:49:04.153434 2026] [core:notice] [pid 935860:tid 935959] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:04.268942 2026] [security2:error] [pid 935860:tid 935998] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucoIijB6THqIZZsUIw1QAAAIw"]
[Thu Jul 30 13:49:04.503781 2026] [security2:error] [pid 935860:tid 936103] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucoIijB6THqIZZsUIw3wAAAPU"]
[Thu Jul 30 13:49:04.666298 2026] [core:error] [pid 935860:tid 936009] [client 193.47.62.167:59202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:49:04.666330 2026] [core:error] [pid 935860:tid 936009] [client 193.47.62.167:59202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:49:04.739413 2026] [security2:error] [pid 935860:tid 936050] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucoIijB6THqIZZsUIw5AAAAMA"]
[Thu Jul 30 13:49:04.972560 2026] [security2:error] [pid 935860:tid 936015] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucoIijB6THqIZZsUIw6gAAAJ0"]
[Thu Jul 30 13:49:05.208481 2026] [security2:error] [pid 935860:tid 936110] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucoYijB6THqIZZsUIw8AAAAPw"]
[Thu Jul 30 13:49:05.444504 2026] [security2:error] [pid 935860:tid 936089] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucoYijB6THqIZZsUIw9QAAAOc"]
[Thu Jul 30 13:49:05.589552 2026] [autoindex:error] [pid 935860:tid 936007] [client 157.143.3.35:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:49:05.679103 2026] [security2:error] [pid 935860:tid 936053] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucoYijB6THqIZZsUIw_AAAAMM"]
[Thu Jul 30 13:49:05.750334 2026] [autoindex:error] [pid 935860:tid 935955] [remote 157.143.3.35:40968] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:49:05.914465 2026] [security2:error] [pid 935860:tid 936016] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucoYijB6THqIZZsUIxAgAAAJ4"]
[Thu Jul 30 13:49:06.547360 2026] [core:notice] [pid 935860:tid 935910] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:06.647122 2026] [security2:error] [pid 935860:tid 936104] [client 185.177.72.22:22894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucooijB6THqIZZsUIxHwAAAPY"]
[Thu Jul 30 13:49:06.870766 2026] [security2:error] [pid 935860:tid 936022] [client 195.63.29.190:15640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amucooijB6THqIZZsUIxJQAApB0"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 13:49:06.962711 2026] [security2:error] [pid 935860:tid 936065] [client 172.237.109.114:31374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxLgAAAM8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.962810 2026] [security2:error] [pid 935860:tid 936065] [client 172.237.109.114:31374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxLgAAAM8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.963276 2026] [security2:error] [pid 935860:tid 936110] [client 172.237.109.114:53560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxMAAAAPw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.963351 2026] [security2:error] [pid 935860:tid 936110] [client 172.237.109.114:53560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxMAAAAPw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.963813 2026] [security2:error] [pid 935860:tid 936116] [client 172.237.109.114:23126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxLwAAAQI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.969457 2026] [security2:error] [pid 935860:tid 936112] [client 172.237.109.114:49027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxMQAAAP4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.970934 2026] [security2:error] [pid 935860:tid 936074] [client 172.237.109.114:21105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxMgAAANg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.972134 2026] [security2:error] [pid 935860:tid 936114] [client 172.237.109.114:58426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxMwAAAQA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.972214 2026] [security2:error] [pid 935860:tid 935994] [client 172.237.109.114:24175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxNAAAAIg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.972734 2026] [security2:error] [pid 935860:tid 936088] [client 172.237.109.114:11849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxNQAAAOY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.972830 2026] [security2:error] [pid 935860:tid 935994] [client 172.237.109.114:41855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxNgAAAIg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.972948 2026] [security2:error] [pid 935860:tid 936037] [client 172.237.109.114:56634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxNwAAALM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.973546 2026] [security2:error] [pid 935860:tid 936075] [client 172.237.109.114:41053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxOAAAANk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.990716 2026] [security2:error] [pid 935860:tid 936077] [client 172.237.109.114:37215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxOQAAANs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.991611 2026] [security2:error] [pid 935860:tid 936109] [client 172.237.109.114:17805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxOgAAAPs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:06.993352 2026] [security2:error] [pid 935860:tid 936067] [client 172.237.109.114:1779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucooijB6THqIZZsUIxPAAAANE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:07.011234 2026] [security2:error] [pid 935860:tid 936101] [client 172.237.109.114:28608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuco4ijB6THqIZZsUIxQAAAAPM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:07.011493 2026] [security2:error] [pid 935860:tid 936089] [client 172.237.109.114:28866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuco4ijB6THqIZZsUIxQQAAAOc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:07.011717 2026] [security2:error] [pid 935860:tid 936014] [client 172.237.109.114:50422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuco4ijB6THqIZZsUIxPwAAAJw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:07.017093 2026] [security2:error] [pid 935860:tid 936115] [client 185.177.72.22:25826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucooijB6THqIZZsUIxLAAAAQE"]
[Thu Jul 30 13:49:07.259621 2026] [security2:error] [pid 935860:tid 936041] [client 185.177.72.22:25826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuco4ijB6THqIZZsUIxSAAAALc"]
[Thu Jul 30 13:49:07.500942 2026] [security2:error] [pid 935860:tid 936100] [client 185.177.72.22:25826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuco4ijB6THqIZZsUIxUwAAAPI"]
[Thu Jul 30 13:49:07.744040 2026] [security2:error] [pid 935860:tid 936093] [client 185.177.72.22:25826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuco4ijB6THqIZZsUIxWwAAAOs"]
[Thu Jul 30 13:49:07.964731 2026] [security2:error] [pid 935860:tid 936080] [client 172.237.109.114:58082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuco4ijB6THqIZZsUIxYwAAAN4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:07.973260 2026] [security2:error] [pid 935860:tid 936104] [client 172.237.109.114:22469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuco4ijB6THqIZZsUIxZAAAAPY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:07.973363 2026] [security2:error] [pid 935860:tid 936104] [client 172.237.109.114:22469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuco4ijB6THqIZZsUIxZAAAAPY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:07.986232 2026] [security2:error] [pid 935860:tid 936010] [client 185.177.72.22:25826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuco4ijB6THqIZZsUIxYgAAAJg"]
[Thu Jul 30 13:49:08.011899 2026] [security2:error] [pid 935860:tid 936048] [client 172.237.109.114:41959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucpIijB6THqIZZsUIxaAAAAL4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:08.225211 2026] [security2:error] [pid 935860:tid 936099] [client 185.177.72.22:25826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucpIijB6THqIZZsUIxbwAAAPE"]
[Thu Jul 30 13:49:08.469766 2026] [security2:error] [pid 935860:tid 936109] [client 185.177.72.22:25826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucpIijB6THqIZZsUIxegAAAPs"]
[Thu Jul 30 13:49:08.503816 2026] [core:notice] [pid 935860:tid 935980] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:08.612528 2026] [security2:error] [pid 935860:tid 936028] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucpIijB6THqIZZsUIxawAAAKo"]
[Thu Jul 30 13:49:08.714960 2026] [security2:error] [pid 935860:tid 936071] [client 185.177.72.22:25826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucpIijB6THqIZZsUIxgAAAANU"]
[Thu Jul 30 13:49:08.842656 2026] [fcgid:warn] [pid 935860:tid 936008] (70014)End of file found: [client 185.177.72.22:25826] mod_fcgid: can't get data from http client
[Thu Jul 30 13:49:09.091069 2026] [fcgid:warn] [pid 935860:tid 936072] (70014)End of file found: [client 185.177.72.22:46034] mod_fcgid: can't get data from http client
[Thu Jul 30 13:49:09.343195 2026] [fcgid:warn] [pid 935860:tid 935999] (70014)End of file found: [client 185.177.72.22:46054] mod_fcgid: can't get data from http client
[Thu Jul 30 13:49:09.606544 2026] [fcgid:warn] [pid 935860:tid 936036] (70014)End of file found: [client 185.177.72.22:46060] mod_fcgid: can't get data from http client
[Thu Jul 30 13:49:09.972016 2026] [security2:error] [pid 935860:tid 936044] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucpYijB6THqIZZsUIxngAAALo"]
[Thu Jul 30 13:49:10.124696 2026] [proxy:error] [pid 935860:tid 936021] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:10.124766 2026] [proxy_http:error] [pid 935860:tid 936021] [client 32.194.121.99:12762] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:10.125339 2026] [proxy:error] [pid 935860:tid 936021] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:10.125385 2026] [proxy_http:error] [pid 935860:tid 936021] [client 32.194.121.99:12762] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:10.133412 2026] [proxy:error] [pid 935860:tid 936022] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:10.133485 2026] [proxy_http:error] [pid 935860:tid 936022] [client 32.194.121.99:10621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:10.134341 2026] [proxy:error] [pid 935860:tid 936022] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:10.134401 2026] [proxy_http:error] [pid 935860:tid 936022] [client 32.194.121.99:10621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:10.220838 2026] [security2:error] [pid 935860:tid 936013] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucpoijB6THqIZZsUIxpAAAAJs"]
[Thu Jul 30 13:49:10.426824 2026] [security2:error] [pid 935860:tid 936109] [client 103.242.199.184:53153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucpoijB6THqIZZsUIxvQAAAPs"]
[Thu Jul 30 13:49:10.426957 2026] [security2:error] [pid 935860:tid 936109] [client 103.242.199.184:53153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucpoijB6THqIZZsUIxvQAAAPs"]
[Thu Jul 30 13:49:10.442690 2026] [core:notice] [pid 935860:tid 935945] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:10.464603 2026] [security2:error] [pid 935860:tid 936101] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucpoijB6THqIZZsUIxtgAAAPM"]
[Thu Jul 30 13:49:10.631889 2026] [security2:error] [pid 935860:tid 935992] [client 78.167.1.90:53901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucpoijB6THqIZZsUIxzgAAAIY"]
[Thu Jul 30 13:49:10.632659 2026] [security2:error] [pid 935860:tid 935992] [client 78.167.1.90:53901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucpoijB6THqIZZsUIxzgAAAIY"]
[Thu Jul 30 13:49:10.837130 2026] [security2:error] [pid 935860:tid 936063] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucpoijB6THqIZZsUIx1AAAAM0"]
[Thu Jul 30 13:49:10.964934 2026] [security2:error] [pid 935860:tid 936018] [client 185.177.72.22:46064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/en.orig"] [unique_id "amucpoijB6THqIZZsUIx3AAAAKA"]
[Thu Jul 30 13:49:11.012095 2026] [security2:error] [pid 935860:tid 935925] [remote 74.7.227.39:35144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amucp4ijB6THqIZZsUIx3QAAxj8"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementor-pro/modules/query-control/controls
[Thu Jul 30 13:49:11.209149 2026] [security2:error] [pid 935860:tid 936036] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucp4ijB6THqIZZsUIx3gAAALI"]
[Thu Jul 30 13:49:11.454337 2026] [security2:error] [pid 935860:tid 936104] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucp4ijB6THqIZZsUIx8AAAAPY"]
[Thu Jul 30 13:49:11.702744 2026] [security2:error] [pid 935860:tid 936113] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucp4ijB6THqIZZsUIx9gAAAP8"]
[Thu Jul 30 13:49:12.072138 2026] [security2:error] [pid 935860:tid 936053] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucp4ijB6THqIZZsUIyAwAAAMM"]
[Thu Jul 30 13:49:12.316646 2026] [security2:error] [pid 935860:tid 936061] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucqIijB6THqIZZsUIyBwAAAMs"]
[Thu Jul 30 13:49:12.556458 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:46064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucqIijB6THqIZZsUIyEgAAAMc"]
[Thu Jul 30 13:49:12.656048 2026] [security2:error] [pid 935860:tid 936070] [client 5.161.113.195:29630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amucp4ijB6THqIZZsUIx7wAAANQ"], referer: https://globalmarks.pk/
[Thu Jul 30 13:49:12.682642 2026] [security2:error] [pid 935860:tid 936084] [client 185.177.72.22:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/o.php"] [unique_id "amucqIijB6THqIZZsUIyFwAAAOI"]
[Thu Jul 30 13:49:12.932132 2026] [security2:error] [pid 935860:tid 936096] [client 185.177.72.22:46116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/o.php%2f"] [unique_id "amucqIijB6THqIZZsUIyIQAAAO4"]
[Thu Jul 30 13:49:13.180273 2026] [security2:error] [pid 935860:tid 936007] [client 185.177.72.22:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/o.php..."] [unique_id "amucqYijB6THqIZZsUIyJwAAAJU"]
[Thu Jul 30 13:49:13.380009 2026] [security2:error] [pid 935860:tid 935998] [client 181.116.200.68:51637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucqYijB6THqIZZsUIyLgAAAIw"]
[Thu Jul 30 13:49:13.380107 2026] [security2:error] [pid 935860:tid 935998] [client 181.116.200.68:51637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucqYijB6THqIZZsUIyLgAAAIw"]
[Thu Jul 30 13:49:13.446285 2026] [security2:error] [pid 935860:tid 936112] [client 185.177.72.22:46142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/o.php.swp"] [unique_id "amucqYijB6THqIZZsUIyMAAAAP4"]
[Thu Jul 30 13:49:13.555752 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/kool-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:13.585041 2026] [security2:error] [pid 935860:tid 936042] [client 50.6.43.217:59026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucqIijB6THqIZZsUIyFgAAALg"]
[Thu Jul 30 13:49:13.585066 2026] [security2:error] [pid 935860:tid 936042] [client 50.6.43.217:59026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucqIijB6THqIZZsUIyFgAAALg"]
[Thu Jul 30 13:49:13.842290 2026] [security2:error] [pid 935860:tid 936115] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucqYijB6THqIZZsUIyNwAAAQE"]
[Thu Jul 30 13:49:14.096001 2026] [security2:error] [pid 935860:tid 935992] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucqYijB6THqIZZsUIyPwAAAIY"]
[Thu Jul 30 13:49:14.347262 2026] [security2:error] [pid 935860:tid 936023] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucqoijB6THqIZZsUIyQwAAAKU"]
[Thu Jul 30 13:49:14.566881 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/LARK-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:14.599914 2026] [security2:error] [pid 935860:tid 936077] [client 50.6.43.217:59040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucqYijB6THqIZZsUIyMQAAANs"]
[Thu Jul 30 13:49:14.599956 2026] [security2:error] [pid 935860:tid 936077] [client 50.6.43.217:59040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucqYijB6THqIZZsUIyMQAAANs"]
[Thu Jul 30 13:49:14.600496 2026] [security2:error] [pid 935860:tid 936050] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucqoijB6THqIZZsUIyTQAAAMA"]
[Thu Jul 30 13:49:14.660250 2026] [security2:error] [pid 935860:tid 936087] [client 103.190.40.154:19092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucqoijB6THqIZZsUIyUQAAAOU"]
[Thu Jul 30 13:49:14.660403 2026] [security2:error] [pid 935860:tid 936087] [client 103.190.40.154:19092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucqoijB6THqIZZsUIyUQAAAOU"]
[Thu Jul 30 13:49:14.855056 2026] [security2:error] [pid 935860:tid 936078] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucqoijB6THqIZZsUIyWAAAANw"]
[Thu Jul 30 13:49:15.104586 2026] [security2:error] [pid 935860:tid 936022] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucqoijB6THqIZZsUIyXwAAAKQ"]
[Thu Jul 30 13:49:15.354484 2026] [security2:error] [pid 935860:tid 936116] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucq4ijB6THqIZZsUIyZAAAAQI"]
[Thu Jul 30 13:49:15.539700 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe7\x99\xbe\xe6\xa8\x82\xe9\x96\x80-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:15.562945 2026] [security2:error] [pid 935860:tid 936039] [client 50.6.43.217:59084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucqoijB6THqIZZsUIyTgAAALU"]
[Thu Jul 30 13:49:15.562989 2026] [security2:error] [pid 935860:tid 936039] [client 50.6.43.217:59084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucqoijB6THqIZZsUIyTgAAALU"]
[Thu Jul 30 13:49:15.609658 2026] [security2:error] [pid 935860:tid 936042] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucq4ijB6THqIZZsUIyaQAAALg"]
[Thu Jul 30 13:49:16.419238 2026] [security2:error] [pid 935860:tid 935995] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucrIijB6THqIZZsUIygwAAAIk"]
[Thu Jul 30 13:49:16.433691 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe7\xa2\xa7\xe7\xb5\xb2\xe5\xa4\xa2-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:16.456656 2026] [security2:error] [pid 935860:tid 936109] [client 50.6.43.217:59102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucq4ijB6THqIZZsUIybgAAAPs"]
[Thu Jul 30 13:49:16.456684 2026] [security2:error] [pid 935860:tid 936109] [client 50.6.43.217:59102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucq4ijB6THqIZZsUIybgAAAPs"]
[Thu Jul 30 13:49:16.554647 2026] [security2:error] [pid 935860:tid 936041] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/app.swp"] [unique_id "amucrIijB6THqIZZsUIyjgAAALc"]
[Thu Jul 30 13:49:16.701320 2026] [security2:error] [pid 935860:tid 936015] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucq4ijB6THqIZZsUIyeAAAnQk"]
[Thu Jul 30 13:49:16.808106 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucrIijB6THqIZZsUIykwAAAOU"]
[Thu Jul 30 13:49:17.056477 2026] [security2:error] [pid 935860:tid 936007] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucrIijB6THqIZZsUIymgAAAJU"]
[Thu Jul 30 13:49:17.302555 2026] [security2:error] [pid 935860:tid 936000] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucrYijB6THqIZZsUIyoQAAAI4"]
[Thu Jul 30 13:49:17.405825 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\xa5\xbd\xe5\xbd\xa9-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:17.428574 2026] [security2:error] [pid 935860:tid 935997] [client 50.6.43.217:59136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucrIijB6THqIZZsUIyiQAAAIs"]
[Thu Jul 30 13:49:17.428603 2026] [security2:error] [pid 935860:tid 935997] [client 50.6.43.217:59136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucrIijB6THqIZZsUIyiQAAAIs"]
[Thu Jul 30 13:49:17.552698 2026] [security2:error] [pid 935860:tid 936025] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucrYijB6THqIZZsUIyrAAAAKc"]
[Thu Jul 30 13:49:17.638875 2026] [core:notice] [pid 935860:tid 936078] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:17.688297 2026] [security2:error] [pid 935860:tid 936049] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htpasswd"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.terraform.htpasswd"] [unique_id "amucrYijB6THqIZZsUIytgAAAL8"]
[Thu Jul 30 13:49:17.938614 2026] [security2:error] [pid 935860:tid 936003] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucrYijB6THqIZZsUIyuwAAAJE"]
[Thu Jul 30 13:49:18.210801 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/log.txt~"] [unique_id "amucroijB6THqIZZsUIyxAAAAMc"]
[Thu Jul 30 13:49:18.293991 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\x92\x8c\xe5\xb9\xb3-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:18.313828 2026] [security2:error] [pid 935860:tid 936034] [client 50.6.43.217:59170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucrYijB6THqIZZsUIyqgAAALA"]
[Thu Jul 30 13:49:18.313868 2026] [security2:error] [pid 935860:tid 936034] [client 50.6.43.217:59170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucrYijB6THqIZZsUIyqgAAALA"]
[Thu Jul 30 13:49:18.345667 2026] [security2:error] [pid 935860:tid 936018] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/log.txt.bak"] [unique_id "amucroijB6THqIZZsUIyygAAAKA"]
[Thu Jul 30 13:49:18.598646 2026] [security2:error] [pid 935860:tid 936084] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucroijB6THqIZZsUIyywAAAOI"]
[Thu Jul 30 13:49:18.847762 2026] [security2:error] [pid 935860:tid 936050] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucroijB6THqIZZsUIy0gAAAMA"]
[Thu Jul 30 13:49:19.096256 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucroijB6THqIZZsUIy2QAAAOU"]
[Thu Jul 30 13:49:19.164846 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe9\xbb\x91\xe9\xad\x94\xe9\xac\xbc-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:19.185349 2026] [security2:error] [pid 935860:tid 935995] [client 50.6.43.217:59200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucroijB6THqIZZsUIyxQAAAIk"]
[Thu Jul 30 13:49:19.185378 2026] [security2:error] [pid 935860:tid 935995] [client 50.6.43.217:59200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucroijB6THqIZZsUIyxQAAAIk"]
[Thu Jul 30 13:49:19.346924 2026] [security2:error] [pid 935860:tid 936097] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucr4ijB6THqIZZsUIy4wAAAO8"]
[Thu Jul 30 13:49:19.596586 2026] [security2:error] [pid 935860:tid 936067] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucr4ijB6THqIZZsUIy5wAAANE"]
[Thu Jul 30 13:49:19.843798 2026] [security2:error] [pid 935860:tid 936082] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucr4ijB6THqIZZsUIy7gAAAOA"]
[Thu Jul 30 13:49:20.069013 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe9\xa7\xb1\xe9\xa7\x9d-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:20.090669 2026] [security2:error] [pid 935860:tid 936044] [client 50.6.43.217:59220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucr4ijB6THqIZZsUIy3gAAALo"]
[Thu Jul 30 13:49:20.090693 2026] [security2:error] [pid 935860:tid 936044] [client 50.6.43.217:59220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucr4ijB6THqIZZsUIy3gAAALo"]
[Thu Jul 30 13:49:20.091967 2026] [security2:error] [pid 935860:tid 936078] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucr4ijB6THqIZZsUIy8wAAANw"]
[Thu Jul 30 13:49:20.340740 2026] [security2:error] [pid 935860:tid 936003] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucsIijB6THqIZZsUIy-wAAAJE"]
[Thu Jul 30 13:49:20.590423 2026] [security2:error] [pid 935860:tid 936072] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucsIijB6THqIZZsUIzBAAAANY"]
[Thu Jul 30 13:49:20.841327 2026] [security2:error] [pid 935860:tid 936063] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucsIijB6THqIZZsUIzCAAAAM0"]
[Thu Jul 30 13:49:20.983468 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\x81\xa5\xe7\x89\x8c-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:21.002457 2026] [security2:error] [pid 935860:tid 936114] [client 50.6.43.217:59236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucsIijB6THqIZZsUIy9gAAAQA"]
[Thu Jul 30 13:49:21.002482 2026] [security2:error] [pid 935860:tid 936114] [client 50.6.43.217:59236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucsIijB6THqIZZsUIy9gAAAQA"]
[Thu Jul 30 13:49:21.089998 2026] [security2:error] [pid 935860:tid 936006] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucsIijB6THqIZZsUIzEAAAAJQ"]
[Thu Jul 30 13:49:21.110330 2026] [security2:error] [pid 935860:tid 936061] [client 78.167.1.90:54589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucsYijB6THqIZZsUIzFAAAAMs"]
[Thu Jul 30 13:49:21.110892 2026] [security2:error] [pid 935860:tid 936061] [client 78.167.1.90:54589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucsYijB6THqIZZsUIzFAAAAMs"]
[Thu Jul 30 13:49:21.161993 2026] [security2:error] [pid 935860:tid 936005] [client 103.242.199.184:53722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucsYijB6THqIZZsUIzFQAAAJM"]
[Thu Jul 30 13:49:21.162114 2026] [security2:error] [pid 935860:tid 936005] [client 103.242.199.184:53722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucsYijB6THqIZZsUIzFQAAAJM"]
[Thu Jul 30 13:49:21.311428 2026] [security2:error] [pid 935860:tid 936017] [client 189.6.88.213:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucsYijB6THqIZZsUIzEwAAAJ8"]
[Thu Jul 30 13:49:21.311566 2026] [security2:error] [pid 935860:tid 936017] [client 189.6.88.213:51766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucsYijB6THqIZZsUIzEwAAAJ8"]
[Thu Jul 30 13:49:21.339967 2026] [security2:error] [pid 935860:tid 936092] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucsYijB6THqIZZsUIzFgAAAOo"]
[Thu Jul 30 13:49:21.601784 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucsYijB6THqIZZsUIzHQAAAOU"]
[Thu Jul 30 13:49:21.854679 2026] [security2:error] [pid 935860:tid 936009] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucsYijB6THqIZZsUIzIQAAAJc"]
[Thu Jul 30 13:49:21.907973 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe7\xbe\x8e\xe5\x9c\x8b\xe7\xb2\xbe\xe7\xa5\x9e-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:21.926732 2026] [security2:error] [pid 935860:tid 936070] [client 50.6.43.217:12112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucsIijB6THqIZZsUIzEQAAANQ"]
[Thu Jul 30 13:49:21.926755 2026] [security2:error] [pid 935860:tid 936070] [client 50.6.43.217:12112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucsIijB6THqIZZsUIzEQAAANQ"]
[Thu Jul 30 13:49:21.989877 2026] [security2:error] [pid 935860:tid 936074] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/nodeapi%00"] [unique_id "amucsYijB6THqIZZsUIzLAAAANg"]
[Thu Jul 30 13:49:22.124797 2026] [security2:error] [pid 935860:tid 936082] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucsoijB6THqIZZsUIzMgAAAOA"]
[Thu Jul 30 13:49:22.259958 2026] [security2:error] [pid 935860:tid 936038] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucsoijB6THqIZZsUIzNwAAALQ"]
[Thu Jul 30 13:49:22.394735 2026] [security2:error] [pid 935860:tid 936058] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucsoijB6THqIZZsUIzPgAAAMg"]
[Thu Jul 30 13:49:22.529747 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/.env"] [unique_id "amucsoijB6THqIZZsUIzQAAAAJY"]
[Thu Jul 30 13:49:22.692645 2026] [security2:error] [pid 935860:tid 936053] [client 74.7.175.185:47052] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.arteria.us.cc.ghj.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amucsoijB6THqIZZsUIzRQAAAMM"]
[Thu Jul 30 13:49:22.791587 2026] [security2:error] [pid 935860:tid 936072] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucsoijB6THqIZZsUIzRAAAANY"]
[Thu Jul 30 13:49:22.824901 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe4\xb8\x83\xe6\x98\x9f-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:22.846106 2026] [security2:error] [pid 935860:tid 936088] [client 50.6.43.217:12134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucsYijB6THqIZZsUIzKgAAAOY"]
[Thu Jul 30 13:49:22.846130 2026] [security2:error] [pid 935860:tid 936088] [client 50.6.43.217:12134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucsYijB6THqIZZsUIzKgAAAOY"]
[Thu Jul 30 13:49:23.040996 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucsoijB6THqIZZsUIzUgAAAL0"]
[Thu Jul 30 13:49:23.292802 2026] [security2:error] [pid 935860:tid 936095] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucs4ijB6THqIZZsUIzWgAAAO0"]
[Thu Jul 30 13:49:23.481420 2026] [core:notice] [pid 935860:tid 936057] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:23.539823 2026] [security2:error] [pid 935860:tid 936103] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucs4ijB6THqIZZsUIzZAAAAPU"]
[Thu Jul 30 13:49:23.636548 2026] [core:error] [pid 935860:tid 936097] [client 74.7.244.12:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:49:23.636569 2026] [core:error] [pid 935860:tid 936097] [client 74.7.244.12:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:49:23.636688 2026] [security2:error] [pid 935860:tid 936097] [client 74.7.244.12:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.inj.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amucs4ijB6THqIZZsUIzbAAAAO8"]
[Thu Jul 30 13:49:23.637369 2026] [security2:error] [pid 935860:tid 935995] [client 74.7.244.12:46414] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.inj.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amucs4ijB6THqIZZsUIzaAAAiRo"]
[Thu Jul 30 13:49:23.734403 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe8\x90\xac\xe5\xaf\xb6\xe8\xb7\xaf-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:23.755046 2026] [security2:error] [pid 935860:tid 936029] [client 50.6.43.217:12186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucsoijB6THqIZZsUIzTQAAAKs"]
[Thu Jul 30 13:49:23.755081 2026] [security2:error] [pid 935860:tid 936029] [client 50.6.43.217:12186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucsoijB6THqIZZsUIzTQAAAKs"]
[Thu Jul 30 13:49:23.756627 2026] [security2:error] [pid 935860:tid 936020] [client 74.7.228.28:59406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.sby.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amucs4ijB6THqIZZsUIzcAAAAKI"]
[Thu Jul 30 13:49:23.792606 2026] [security2:error] [pid 935860:tid 936116] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucs4ijB6THqIZZsUIzbQAAAQI"]
[Thu Jul 30 13:49:23.999524 2026] [security2:error] [pid 935860:tid 936021] [client 181.116.200.68:53629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucs4ijB6THqIZZsUIzeQAAAKM"]
[Thu Jul 30 13:49:24.000272 2026] [security2:error] [pid 935860:tid 936021] [client 181.116.200.68:53629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucs4ijB6THqIZZsUIzeQAAAKM"]
[Thu Jul 30 13:49:24.042044 2026] [security2:error] [pid 935860:tid 936013] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucs4ijB6THqIZZsUIzdQAAAJs"]
[Thu Jul 30 13:49:24.290258 2026] [security2:error] [pid 935860:tid 936101] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctIijB6THqIZZsUIzfQAAAPM"]
[Thu Jul 30 13:49:24.545913 2026] [security2:error] [pid 935860:tid 936033] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctIijB6THqIZZsUIzgwAAAK8"]
[Thu Jul 30 13:49:24.622521 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe8\x90\xac\xe4\xba\x8b\xe7\x99\xbc-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:24.632157 2026] [proxy:error] [pid 935860:tid 936053] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:24.632218 2026] [proxy_http:error] [pid 935860:tid 936053] [client 34.233.129.35:13142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:24.632785 2026] [proxy:error] [pid 935860:tid 936053] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:24.632827 2026] [proxy_http:error] [pid 935860:tid 936053] [client 34.233.129.35:13142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:24.642969 2026] [security2:error] [pid 935860:tid 936000] [client 50.6.43.217:12214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucs4ijB6THqIZZsUIzbgAAAI4"]
[Thu Jul 30 13:49:24.643025 2026] [security2:error] [pid 935860:tid 936000] [client 50.6.43.217:12214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucs4ijB6THqIZZsUIzbgAAAI4"]
[Thu Jul 30 13:49:24.652652 2026] [proxy:error] [pid 935860:tid 936055] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:24.652741 2026] [proxy_http:error] [pid 935860:tid 936055] [client 34.233.129.35:45946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:24.653885 2026] [proxy:error] [pid 935860:tid 936055] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:24.653949 2026] [proxy_http:error] [pid 935860:tid 936055] [client 34.233.129.35:45946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:24.657567 2026] [autoindex:error] [pid 935860:tid 936072] [client 34.224.175.62:40341] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:49:24.716961 2026] [autoindex:error] [pid 935860:tid 936077] [client 34.233.129.35:1799] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:49:24.799164 2026] [security2:error] [pid 935860:tid 936023] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctIijB6THqIZZsUIzlAAAAKU"]
[Thu Jul 30 13:49:25.050108 2026] [security2:error] [pid 935860:tid 936094] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctIijB6THqIZZsUIzrAAAAOw"]
[Thu Jul 30 13:49:25.273590 2026] [security2:error] [pid 935860:tid 936080] [client 103.190.40.154:19212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuctYijB6THqIZZsUIzvAAAAN4"]
[Thu Jul 30 13:49:25.273730 2026] [security2:error] [pid 935860:tid 936080] [client 103.190.40.154:19212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuctYijB6THqIZZsUIzvAAAAN4"]
[Thu Jul 30 13:49:25.301743 2026] [security2:error] [pid 935860:tid 936036] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctYijB6THqIZZsUIzuAAAALI"]
[Thu Jul 30 13:49:25.524909 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\xb8\x8c\xe6\x9c\x9b-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:25.545059 2026] [security2:error] [pid 935860:tid 936060] [client 50.6.43.217:12230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuctIijB6THqIZZsUIzjwAAAMo"]
[Thu Jul 30 13:49:25.545083 2026] [security2:error] [pid 935860:tid 936060] [client 50.6.43.217:12230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuctIijB6THqIZZsUIzjwAAAMo"]
[Thu Jul 30 13:49:25.558584 2026] [security2:error] [pid 935860:tid 936099] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctYijB6THqIZZsUIzvgAAAPE"]
[Thu Jul 30 13:49:25.815077 2026] [security2:error] [pid 935860:tid 936019] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctYijB6THqIZZsUIzywAAAKE"]
[Thu Jul 30 13:49:26.070600 2026] [security2:error] [pid 935860:tid 936098] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctYijB6THqIZZsUIzzwAAAPA"]
[Thu Jul 30 13:49:26.318038 2026] [security2:error] [pid 935860:tid 936073] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctoijB6THqIZZsUIz2wAAANc"]
[Thu Jul 30 13:49:26.414485 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\x96\x9c\xe5\x8a\x9b-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:26.434469 2026] [security2:error] [pid 935860:tid 936113] [client 50.6.43.217:12272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuctYijB6THqIZZsUIzyAAAAP8"]
[Thu Jul 30 13:49:26.434500 2026] [security2:error] [pid 935860:tid 936113] [client 50.6.43.217:12272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuctYijB6THqIZZsUIzyAAAAP8"]
[Thu Jul 30 13:49:26.525129 2026] [security2:error] [pid 935860:tid 936083] [client 172.237.109.114:42958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuctoijB6THqIZZsUIz0wAAAOE"]
[Thu Jul 30 13:49:26.565125 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctoijB6THqIZZsUIz3wAAANk"]
[Thu Jul 30 13:49:26.709989 2026] [core:notice] [pid 935860:tid 935902] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:26.866154 2026] [security2:error] [pid 935860:tid 935905] [remote 57.141.0.66:36120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuctoijB6THqIZZsUIz7QAAoCs"]
[Thu Jul 30 13:49:26.952111 2026] [security2:error] [pid 935860:tid 936102] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuctoijB6THqIZZsUIz7AAAAPQ"]
[Thu Jul 30 13:49:27.202611 2026] [security2:error] [pid 935860:tid 936118] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuct4ijB6THqIZZsUIz-gAAAQQ"]
[Thu Jul 30 13:49:27.289213 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe9\x9b\xb2\xe6\x96\xaf\xe9\xa0\x93-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:27.309731 2026] [security2:error] [pid 935860:tid 936003] [client 50.6.43.217:12296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuctoijB6THqIZZsUIz3QAAAJE"]
[Thu Jul 30 13:49:27.309761 2026] [security2:error] [pid 935860:tid 936003] [client 50.6.43.217:12296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuctoijB6THqIZZsUIz3QAAAJE"]
[Thu Jul 30 13:49:27.449996 2026] [security2:error] [pid 935860:tid 936009] [client 185.177.72.22:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuct4ijB6THqIZZsUI0JgAAAJc"]
[Thu Jul 30 13:49:27.581124 2026] [security2:error] [pid 935860:tid 936023] [client 121.229.156.22:42598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-4-retro-taupe-haze-3/"] [unique_id "amuct4ijB6THqIZZsUI0KQAAAKU"]
[Thu Jul 30 13:49:27.581295 2026] [security2:error] [pid 935860:tid 936023] [client 121.229.156.22:42598] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-4-retro-taupe-haze-3/"] [unique_id "amuct4ijB6THqIZZsUI0KQAAAKU"]
[Thu Jul 30 13:49:27.585969 2026] [security2:error] [pid 935860:tid 936095] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.aaapropertiesph.com"] [uri "/projects.bak"] [unique_id "amuct4ijB6THqIZZsUI0KwAAAO0"]
[Thu Jul 30 13:49:27.719112 2026] [security2:error] [pid 935860:tid 936013] [client 185.177.72.22:46146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.aaapropertiesph.com"] [uri "/wp-config.php.backup"] [unique_id "amuct4ijB6THqIZZsUI0NQAAAJs"]
[Thu Jul 30 13:49:27.794965 2026] [security2:error] [pid 935860:tid 936104] [client 43.173.178.104:38548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/09/07/apercu-de-la-collection-cindy-crawford-pour-ca/"] [unique_id "amuct4ijB6THqIZZsUI0KAAAAPY"]
[Thu Jul 30 13:49:27.964248 2026] [security2:error] [pid 935860:tid 936025] [client 172.237.109.114:18215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuct4ijB6THqIZZsUI0NgAAAKc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:27.964434 2026] [security2:error] [pid 935860:tid 936043] [client 172.237.109.114:48496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuct4ijB6THqIZZsUI0NwAAALk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:27.966076 2026] [security2:error] [pid 935860:tid 936004] [client 185.177.72.22:22374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.aaapropertiesph.com"] [uri "/wp-config.php.backup%253e"] [unique_id "amuct4ijB6THqIZZsUI0OAAAAJI"]
[Thu Jul 30 13:49:27.970136 2026] [security2:error] [pid 935860:tid 936028] [client 172.237.109.114:43095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuct4ijB6THqIZZsUI0OQAAAKo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:27.971684 2026] [security2:error] [pid 935860:tid 936049] [client 172.237.109.114:34162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuct4ijB6THqIZZsUI0OgAAAL8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:27.973862 2026] [security2:error] [pid 935860:tid 936115] [client 172.237.109.114:64295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuct4ijB6THqIZZsUI0OwAAAQE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:27.979655 2026] [security2:error] [pid 935860:tid 936044] [client 172.237.109.114:32982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuct4ijB6THqIZZsUI0PAAAALo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:27.992231 2026] [security2:error] [pid 935860:tid 936085] [client 172.237.109.114:17872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuct4ijB6THqIZZsUI0PQAAAOM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:27.992917 2026] [security2:error] [pid 935860:tid 936105] [client 172.237.109.114:21002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuct4ijB6THqIZZsUI0PgAAAPc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:28.011221 2026] [security2:error] [pid 935860:tid 936073] [client 172.237.109.114:46301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuIijB6THqIZZsUI0PwAAANc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:28.162288 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe4\xb8\xad\xe8\x8f\xaf-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:28.183477 2026] [security2:error] [pid 935860:tid 935998] [client 50.6.43.217:12314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuct4ijB6THqIZZsUI0JAAAAIw"]
[Thu Jul 30 13:49:28.183507 2026] [security2:error] [pid 935860:tid 935998] [client 50.6.43.217:12314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuct4ijB6THqIZZsUI0JAAAAIw"]
[Thu Jul 30 13:49:28.211947 2026] [security2:error] [pid 935860:tid 936041] [client 185.177.72.22:22378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.aaapropertiesph.com"] [uri "/wp-config.php.backup%7c"] [unique_id "amucuIijB6THqIZZsUI0TQAAALc"]
[Thu Jul 30 13:49:28.463067 2026] [security2:error] [pid 935860:tid 936091] [client 185.177.72.22:22386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.aaapropertiesph.com"] [uri "/wp-config.php.backup.zshrc"] [unique_id "amucuIijB6THqIZZsUI0UQAAAOk"]
[Thu Jul 30 13:49:28.526096 2026] [core:notice] [pid 935860:tid 936015] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:28.531906 2026] [security2:error] [pid 935860:tid 936015] [client 43.172.195.138:54668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/09/07/apercu-de-la-collection-cindy-crawford-pour-ca/"] [unique_id "amucuIijB6THqIZZsUI0UgAAAJ0"], referer: https://carnetdeshopping.com/index.php/2012/09/07/apercu-de-la-collection-cindy-crawford-pour-ca/
[Thu Jul 30 13:49:28.834411 2026] [security2:error] [pid 935860:tid 936096] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucuIijB6THqIZZsUI0WgAAAO4"]
[Thu Jul 30 13:49:28.982082 2026] [core:notice] [pid 935860:tid 936094] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:29.049166 2026] [lsapi:warn] [pid 935860:tid 935991] [client 14.228.203.104:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe4\xb8\xad\xe5\x8d\x97\xe6\xb5\xb7-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:49:29.071338 2026] [security2:error] [pid 935860:tid 936011] [client 50.6.43.217:12342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucuIijB6THqIZZsUI0SAAAAJk"]
[Thu Jul 30 13:49:29.071363 2026] [security2:error] [pid 935860:tid 936011] [client 50.6.43.217:12342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amucuIijB6THqIZZsUI0SAAAAJk"]
[Thu Jul 30 13:49:29.078036 2026] [security2:error] [pid 935860:tid 936110] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucuIijB6THqIZZsUI0YQAAAPw"]
[Thu Jul 30 13:49:29.218051 2026] [security2:error] [pid 935860:tid 936003] [client 172.237.109.114:12811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuIijB6THqIZZsUI0YwAAAJE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.231656 2026] [security2:error] [pid 935860:tid 936029] [client 172.237.109.114:14432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuIijB6THqIZZsUI0ZwAAAKs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.234275 2026] [security2:error] [pid 935860:tid 936060] [client 172.237.109.114:1319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuIijB6THqIZZsUI0YgAAAMo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.234307 2026] [security2:error] [pid 935860:tid 936007] [client 172.237.109.114:46790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuIijB6THqIZZsUI0ZAAAAJU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.237601 2026] [security2:error] [pid 935860:tid 936009] [client 172.237.109.114:3820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuIijB6THqIZZsUI0ZQAAAJc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.254349 2026] [security2:error] [pid 935860:tid 936097] [client 172.237.109.114:27480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuIijB6THqIZZsUI0aAAAAO8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.259409 2026] [security2:error] [pid 935860:tid 935995] [client 172.237.109.114:58345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuYijB6THqIZZsUI0agAAAIk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.260702 2026] [security2:error] [pid 935860:tid 936020] [client 172.237.109.114:58768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuIijB6THqIZZsUI0aQAAAKI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.270581 2026] [security2:error] [pid 935860:tid 936022] [client 172.237.109.114:1422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuYijB6THqIZZsUI0awAAAKQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.273283 2026] [security2:error] [pid 935860:tid 936023] [client 172.237.109.114:41798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuYijB6THqIZZsUI0bAAAAKU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:29.322175 2026] [security2:error] [pid 935860:tid 935994] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucuYijB6THqIZZsUI0cgAAAIg"]
[Thu Jul 30 13:49:29.564347 2026] [security2:error] [pid 935860:tid 936044] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucuYijB6THqIZZsUI0egAAALo"]
[Thu Jul 30 13:49:29.807060 2026] [security2:error] [pid 935860:tid 936075] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucuYijB6THqIZZsUI0ewAAANk"]
[Thu Jul 30 13:49:29.963465 2026] [security2:error] [pid 935860:tid 936063] [client 172.237.109.114:20254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucuYijB6THqIZZsUI0hgAAAM0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:30.047516 2026] [security2:error] [pid 935860:tid 936040] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucuYijB6THqIZZsUI0gwAAALY"]
[Thu Jul 30 13:49:30.287469 2026] [security2:error] [pid 935860:tid 936081] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucuoijB6THqIZZsUI0iQAAAN8"]
[Thu Jul 30 13:49:30.397001 2026] [security2:error] [pid 935860:tid 936045] [client 189.6.88.213:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucuoijB6THqIZZsUI0kgAAALs"]
[Thu Jul 30 13:49:30.397100 2026] [security2:error] [pid 935860:tid 936045] [client 189.6.88.213:52275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucuoijB6THqIZZsUI0kgAAALs"]
[Thu Jul 30 13:49:30.528923 2026] [security2:error] [pid 935860:tid 936010] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucuoijB6THqIZZsUI0lQAAAJg"]
[Thu Jul 30 13:49:30.771848 2026] [security2:error] [pid 935860:tid 936057] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucuoijB6THqIZZsUI0mAAAAMc"]
[Thu Jul 30 13:49:31.414680 2026] [security2:error] [pid 935860:tid 936016] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucuoijB6THqIZZsUI0kQAAnnY"]
[Thu Jul 30 13:49:31.528269 2026] [security2:error] [pid 935860:tid 936004] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucu4ijB6THqIZZsUI0tgAAAJI"]
[Thu Jul 30 13:49:31.536707 2026] [security2:error] [pid 935860:tid 936011] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucuoijB6THqIZZsUI0owAAAJk"]
[Thu Jul 30 13:49:31.713146 2026] [security2:error] [pid 935860:tid 936033] [client 78.167.1.90:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucu4ijB6THqIZZsUI0uwAAAK8"]
[Thu Jul 30 13:49:31.713290 2026] [security2:error] [pid 935860:tid 936033] [client 78.167.1.90:53448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucu4ijB6THqIZZsUI0uwAAAK8"]
[Thu Jul 30 13:49:31.738279 2026] [security2:error] [pid 935860:tid 936106] [client 103.242.199.184:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucu4ijB6THqIZZsUI0vAAAAPg"]
[Thu Jul 30 13:49:31.739021 2026] [security2:error] [pid 935860:tid 936106] [client 103.242.199.184:54286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucu4ijB6THqIZZsUI0vAAAAPg"]
[Thu Jul 30 13:49:31.770790 2026] [security2:error] [pid 935860:tid 936113] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucu4ijB6THqIZZsUI0ugAAAP8"]
[Thu Jul 30 13:49:32.017402 2026] [security2:error] [pid 935860:tid 936109] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucu4ijB6THqIZZsUI0wwAAAPs"]
[Thu Jul 30 13:49:32.260457 2026] [security2:error] [pid 935860:tid 936015] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucvIijB6THqIZZsUI0ywAAAJ0"]
[Thu Jul 30 13:49:32.507650 2026] [security2:error] [pid 935860:tid 936032] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucvIijB6THqIZZsUI00QAAAK4"]
[Thu Jul 30 13:49:32.751592 2026] [security2:error] [pid 935860:tid 936094] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucvIijB6THqIZZsUI02wAAAOw"]
[Thu Jul 30 13:49:32.949615 2026] [security2:error] [pid 935860:tid 936088] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amucu4ijB6THqIZZsUI0xAAAAOY"]
[Thu Jul 30 13:49:33.004581 2026] [security2:error] [pid 935860:tid 936079] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucvIijB6THqIZZsUI04AAAAN0"]
[Thu Jul 30 13:49:33.249663 2026] [security2:error] [pid 935860:tid 936059] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucvYijB6THqIZZsUI06AAAAMk"]
[Thu Jul 30 13:49:33.493433 2026] [security2:error] [pid 935860:tid 936025] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucvYijB6THqIZZsUI06QAAAKc"]
[Thu Jul 30 13:49:33.993723 2026] [security2:error] [pid 935860:tid 936111] [client 185.177.72.22:22398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucvYijB6THqIZZsUI0-AAAAP0"]
[Thu Jul 30 13:49:34.418902 2026] [core:notice] [pid 935860:tid 936094] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:34.543389 2026] [security2:error] [pid 935860:tid 936000] [client 57.141.0.66:44696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amucvoijB6THqIZZsUI1CgAAjlg"], referer: https://igetvape-australia.com/product/iget-bar-cherry-pomegranate-ice/
[Thu Jul 30 13:49:34.594099 2026] [security2:error] [pid 935860:tid 935993] [client 181.116.200.68:25229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucvoijB6THqIZZsUI1IQAAAIc"]
[Thu Jul 30 13:49:34.594220 2026] [security2:error] [pid 935860:tid 935993] [client 181.116.200.68:25229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucvoijB6THqIZZsUI1IQAAAIc"]
[Thu Jul 30 13:49:34.997096 2026] [security2:error] [pid 935860:tid 936110] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucvoijB6THqIZZsUI1FQAAAPw"]
[Thu Jul 30 13:49:35.206199 2026] [security2:error] [pid 935860:tid 936101] [client 185.177.72.22:22426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucv4ijB6THqIZZsUI1KAAAAPM"]
[Thu Jul 30 13:49:35.610182 2026] [security2:error] [pid 935860:tid 935992] [client 185.177.72.22:22430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucv4ijB6THqIZZsUI1NAAAAIY"]
[Thu Jul 30 13:49:35.882119 2026] [security2:error] [pid 935860:tid 935996] [client 103.190.40.154:8396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucv4ijB6THqIZZsUI1QAAAAIo"]
[Thu Jul 30 13:49:35.882245 2026] [security2:error] [pid 935860:tid 935996] [client 103.190.40.154:8396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucv4ijB6THqIZZsUI1QAAAAIo"]
[Thu Jul 30 13:49:36.014498 2026] [security2:error] [pid 935860:tid 936087] [client 185.177.72.22:22434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucv4ijB6THqIZZsUI1PwAAAOU"]
[Thu Jul 30 13:49:36.412765 2026] [security2:error] [pid 935860:tid 936069] [client 185.177.72.22:22446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucwIijB6THqIZZsUI1TAAAANM"]
[Thu Jul 30 13:49:36.595279 2026] [security2:error] [pid 935860:tid 936007] [client 89.238.167.134:34438] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amucwIijB6THqIZZsUI1UAAAAJU"]
[Thu Jul 30 13:49:36.595405 2026] [security2:error] [pid 935860:tid 936007] [client 89.238.167.134:34438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amucwIijB6THqIZZsUI1UAAAAJU"]
[Thu Jul 30 13:49:36.784969 2026] [security2:error] [pid 935860:tid 936065] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucwIijB6THqIZZsUI1SwAAzyU"]
[Thu Jul 30 13:49:36.818674 2026] [security2:error] [pid 935860:tid 936053] [client 185.177.72.22:22448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucwIijB6THqIZZsUI1VAAAAMM"]
[Thu Jul 30 13:49:37.228222 2026] [security2:error] [pid 935860:tid 936006] [client 185.177.72.22:29250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucwYijB6THqIZZsUI1YgAAAJQ"]
[Thu Jul 30 13:49:37.613196 2026] [security2:error] [pid 935860:tid 936024] [client 185.177.72.22:29262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucwYijB6THqIZZsUI1cAAAAKY"]
[Thu Jul 30 13:49:37.623628 2026] [security2:error] [pid 935860:tid 936059] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amucwYijB6THqIZZsUI1XwAAAMk"]
[Thu Jul 30 13:49:37.696905 2026] [security2:error] [pid 935860:tid 936021] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucwIijB6THqIZZsUI1WQAAo08"]
[Thu Jul 30 13:49:38.017050 2026] [security2:error] [pid 935860:tid 936093] [client 185.177.72.22:29276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucwYijB6THqIZZsUI1gQAAAOs"]
[Thu Jul 30 13:49:38.201429 2026] [security2:error] [pid 935860:tid 935936] [remote 57.141.0.70:30234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amucwoijB6THqIZZsUI1kwAAsEo"]
[Thu Jul 30 13:49:38.417620 2026] [security2:error] [pid 935860:tid 936098] [client 185.177.72.22:29292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucwoijB6THqIZZsUI1pgAAAPA"]
[Thu Jul 30 13:49:38.725044 2026] [security2:error] [pid 935860:tid 936058] [client 51.68.111.241:18447] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amucwoijB6THqIZZsUI1uQAAAMg"]
[Thu Jul 30 13:49:38.725180 2026] [security2:error] [pid 935860:tid 936058] [client 51.68.111.241:18447] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amucwoijB6THqIZZsUI1uQAAAMg"]
[Thu Jul 30 13:49:38.814736 2026] [security2:error] [pid 935860:tid 936115] [client 185.177.72.22:29294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucwoijB6THqIZZsUI1uAAAAQE"]
[Thu Jul 30 13:49:39.219482 2026] [security2:error] [pid 935860:tid 936090] [client 185.177.72.22:29298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amucw4ijB6THqIZZsUI1xgAAAOg"]
[Thu Jul 30 13:49:39.801166 2026] [security2:error] [pid 935860:tid 936040] [client 43.157.22.109:46144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.22.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amucw4ijB6THqIZZsUI11gAAALY"]
[Thu Jul 30 13:49:40.011046 2026] [security2:error] [pid 935860:tid 936098] [client 185.177.72.22:29322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucxIijB6THqIZZsUI13AAAAPA"]
[Thu Jul 30 13:49:40.167331 2026] [security2:error] [pid 935860:tid 935913] [remote 57.141.0.32:51422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amucxIijB6THqIZZsUI14AAAvjM"]
[Thu Jul 30 13:49:40.281800 2026] [security2:error] [pid 935860:tid 936008] [client 185.177.72.22:29328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amucxIijB6THqIZZsUI14QAAAJY"]
[Thu Jul 30 13:49:40.544568 2026] [security2:error] [pid 935860:tid 936062] [client 185.177.72.22:29336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucxIijB6THqIZZsUI16AAAAMw"]
[Thu Jul 30 13:49:40.797349 2026] [security2:error] [pid 935860:tid 936113] [client 185.177.72.22:29338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucxIijB6THqIZZsUI17AAAAP8"]
[Thu Jul 30 13:49:41.045561 2026] [security2:error] [pid 935860:tid 936047] [client 185.177.72.22:29344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucxYijB6THqIZZsUI18wAAAL0"]
[Thu Jul 30 13:49:41.205569 2026] [proxy:error] [pid 935860:tid 936003] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:41.205641 2026] [proxy_http:error] [pid 935860:tid 936003] [client 44.216.125.112:57174] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:41.206260 2026] [proxy:error] [pid 935860:tid 936003] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:41.206311 2026] [proxy_http:error] [pid 935860:tid 936003] [client 44.216.125.112:57174] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:41.218302 2026] [proxy:error] [pid 935860:tid 935991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:41.218358 2026] [proxy_http:error] [pid 935860:tid 935991] [client 44.216.125.112:27589] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:41.218911 2026] [proxy:error] [pid 935860:tid 935991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:49:41.218957 2026] [proxy_http:error] [pid 935860:tid 935991] [client 44.216.125.112:27589] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:49:41.296650 2026] [security2:error] [pid 935860:tid 936038] [client 185.177.72.22:29346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aaapropertiesph.com"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amucxYijB6THqIZZsUI2CgAAALQ"]
[Thu Jul 30 13:49:42.157434 2026] [security2:error] [pid 935860:tid 936098] [client 189.6.88.213:52990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucxoijB6THqIZZsUI2KwAAAPA"]
[Thu Jul 30 13:49:42.157536 2026] [security2:error] [pid 935860:tid 936098] [client 189.6.88.213:52990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucxoijB6THqIZZsUI2KwAAAPA"]
[Thu Jul 30 13:49:42.390155 2026] [security2:error] [pid 935860:tid 936104] [client 103.242.199.184:54849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucxoijB6THqIZZsUI2NwAAAPY"]
[Thu Jul 30 13:49:42.390251 2026] [security2:error] [pid 935860:tid 936104] [client 103.242.199.184:54849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amucxoijB6THqIZZsUI2NwAAAPY"]
[Thu Jul 30 13:49:42.446907 2026] [security2:error] [pid 935860:tid 935939] [remote 74.7.243.224:54926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amucxoijB6THqIZZsUI2PAAAqk0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:49:43.258056 2026] [security2:error] [pid 935860:tid 935999] [client 78.167.1.90:53979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucx4ijB6THqIZZsUI2bgAAAI0"]
[Thu Jul 30 13:49:43.258748 2026] [security2:error] [pid 935860:tid 935999] [client 78.167.1.90:53979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucx4ijB6THqIZZsUI2bgAAAI0"]
[Thu Jul 30 13:49:43.505225 2026] [security2:error] [pid 935860:tid 935868] [remote 57.141.0.16:53002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55997217192/feed/rss2/"] [unique_id "amucx4ijB6THqIZZsUI2eQAA5gY"]
[Thu Jul 30 13:49:44.419883 2026] [security2:error] [pid 935860:tid 936115] [client 134.19.179.155:53030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amucyIijB6THqIZZsUI2hwAAAQE"]
[Thu Jul 30 13:49:44.420016 2026] [security2:error] [pid 935860:tid 936115] [client 134.19.179.155:53030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amucyIijB6THqIZZsUI2hwAAAQE"]
[Thu Jul 30 13:49:45.170521 2026] [security2:error] [pid 935860:tid 936010] [client 181.116.200.68:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucyYijB6THqIZZsUI2mgAAAJg"]
[Thu Jul 30 13:49:45.170633 2026] [security2:error] [pid 935860:tid 936010] [client 181.116.200.68:14275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amucyYijB6THqIZZsUI2mgAAAJg"]
[Thu Jul 30 13:49:45.306761 2026] [core:notice] [pid 935860:tid 936047] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:46.563063 2026] [security2:error] [pid 935860:tid 935992] [client 103.190.40.154:15644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucyoijB6THqIZZsUI2vAAAAIY"]
[Thu Jul 30 13:49:46.563222 2026] [security2:error] [pid 935860:tid 935992] [client 103.190.40.154:15644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amucyoijB6THqIZZsUI2vAAAAIY"]
[Thu Jul 30 13:49:46.579461 2026] [core:notice] [pid 935860:tid 935895] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:47.479925 2026] [core:notice] [pid 935860:tid 935962] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:47.606099 2026] [core:notice] [pid 935860:tid 936051] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:47.963338 2026] [security2:error] [pid 935860:tid 936042] [client 172.237.109.114:19789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucy4ijB6THqIZZsUI24QAAALg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:47.969722 2026] [security2:error] [pid 935860:tid 936016] [client 172.237.109.114:62549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucy4ijB6THqIZZsUI24gAAAJ4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:47.972601 2026] [security2:error] [pid 935860:tid 936013] [client 172.237.109.114:14176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucy4ijB6THqIZZsUI24wAAAJs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:47.974410 2026] [security2:error] [pid 935860:tid 936049] [client 172.237.109.114:36423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucy4ijB6THqIZZsUI25AAAAL8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:47.980234 2026] [security2:error] [pid 935860:tid 936067] [client 172.237.109.114:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amucy4ijB6THqIZZsUI25QAAANE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:48.009885 2026] [security2:error] [pid 935860:tid 936060] [client 172.237.109.114:8812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczIijB6THqIZZsUI25gAAAMo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:48.012545 2026] [security2:error] [pid 935860:tid 936088] [client 172.237.109.114:14298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczIijB6THqIZZsUI25wAAAOY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:48.012860 2026] [security2:error] [pid 935860:tid 936015] [client 172.237.109.114:56434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczIijB6THqIZZsUI26AAAAJ0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:48.156852 2026] [security2:error] [pid 935860:tid 935998] [client 74.7.230.18:50106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "allianceadvisorsllc.us.cc.ghj.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuczIijB6THqIZZsUI26QAAAIw"]
[Thu Jul 30 13:49:48.969592 2026] [security2:error] [pid 935860:tid 936064] [client 172.237.109.114:14207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczIijB6THqIZZsUI2-gAAAM4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:48.972764 2026] [security2:error] [pid 935860:tid 936024] [client 172.237.109.114:10928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczIijB6THqIZZsUI2-wAAAKY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:48.990914 2026] [security2:error] [pid 935860:tid 936111] [client 172.237.109.114:22592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczIijB6THqIZZsUI2_AAAAP0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:48.991079 2026] [security2:error] [pid 935860:tid 936111] [client 172.237.109.114:22592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczIijB6THqIZZsUI2_AAAAP0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:48.993315 2026] [security2:error] [pid 935860:tid 936035] [client 172.237.109.114:39285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczIijB6THqIZZsUI2_QAAALE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:48.993712 2026] [security2:error] [pid 935860:tid 936062] [client 172.237.109.114:17554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczIijB6THqIZZsUI2_gAAAMw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:49.590318 2026] [security2:error] [pid 935860:tid 936056] [client 162.219.176.3:52572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuczYijB6THqIZZsUI3DAAAAMY"]
[Thu Jul 30 13:49:49.590410 2026] [security2:error] [pid 935860:tid 936056] [client 162.219.176.3:52572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuczYijB6THqIZZsUI3DAAAAMY"]
[Thu Jul 30 13:49:49.755575 2026] [security2:error] [pid 935860:tid 936074] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuczYijB6THqIZZsUI3AgAA2Ho"]
[Thu Jul 30 13:49:49.962262 2026] [security2:error] [pid 935860:tid 936095] [client 172.237.109.114:63467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczYijB6THqIZZsUI3GQAAAO0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:49.962550 2026] [security2:error] [pid 935860:tid 936020] [client 172.237.109.114:60799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczYijB6THqIZZsUI3GgAAAKI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:49.962623 2026] [security2:error] [pid 935860:tid 936020] [client 172.237.109.114:60799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczYijB6THqIZZsUI3GgAAAKI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:49.972737 2026] [security2:error] [pid 935860:tid 936114] [client 172.237.109.114:33700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczYijB6THqIZZsUI3GwAAAQA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:49.974104 2026] [security2:error] [pid 935860:tid 936042] [client 172.237.109.114:16654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczYijB6THqIZZsUI3HAAAALg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:49.974489 2026] [security2:error] [pid 935860:tid 936097] [client 172.237.109.114:47495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczYijB6THqIZZsUI3HQAAAO8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:49.977002 2026] [security2:error] [pid 935860:tid 936066] [client 172.237.109.114:59735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczYijB6THqIZZsUI3HgAAANA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:50.010246 2026] [security2:error] [pid 935860:tid 936067] [client 172.237.109.114:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuczoijB6THqIZZsUI3IQAAANE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:49:51.201624 2026] [core:notice] [pid 935860:tid 935908] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:51.588666 2026] [core:notice] [pid 935860:tid 936018] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:51.853224 2026] [core:notice] [pid 935860:tid 935977] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:49:51.858101 2026] [security2:error] [pid 935860:tid 936025] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amucz4ijB6THqIZZsUI3WgAAp3I"]
[Thu Jul 30 13:49:52.791557 2026] [security2:error] [pid 935860:tid 936106] [client 78.167.1.90:54433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc0IijB6THqIZZsUI32wAAAPg"]
[Thu Jul 30 13:49:52.791648 2026] [security2:error] [pid 935860:tid 936062] [client 189.6.88.213:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc0IijB6THqIZZsUI33AAAAMw"]
[Thu Jul 30 13:49:52.791804 2026] [security2:error] [pid 935860:tid 936106] [client 78.167.1.90:54433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc0IijB6THqIZZsUI32wAAAPg"]
[Thu Jul 30 13:49:52.791845 2026] [security2:error] [pid 935860:tid 936062] [client 189.6.88.213:53489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc0IijB6THqIZZsUI33AAAAMw"]
[Thu Jul 30 13:49:53.348110 2026] [http2:info] [pid 961194:tid 961194] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 13:49:53.446972 2026] [security2:error] [pid 961194:tid 961328] [client 103.242.199.184:55419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc0fSWp157EsYqB3r6fwAAAAQ"]
[Thu Jul 30 13:49:53.447314 2026] [security2:error] [pid 961194:tid 961328] [client 103.242.199.184:55419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc0fSWp157EsYqB3r6fwAAAAQ"]
[Thu Jul 30 13:49:54.304895 2026] [security2:error] [pid 961194:tid 961432] [client 152.42.198.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuc0vSWp157EsYqB3r6rQAAAGw"]
[Thu Jul 30 13:49:54.942361 2026] [security2:error] [pid 961194:tid 961334] [client 46.110.207.212:48610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc0vSWp157EsYqB3r6uwAAAAo"], referer: http://pkf.jo
[Thu Jul 30 13:49:54.966785 2026] [security2:error] [pid 961194:tid 961364] [client 99.232.202.163:37346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc0vSWp157EsYqB3r6wwAAACg"], referer: http://pkf.jo
[Thu Jul 30 13:49:55.251057 2026] [security2:error] [pid 961194:tid 961370] [client 186.151.96.183:55568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc0vSWp157EsYqB3r6yAAAAC4"], referer: http://pkf.jo
[Thu Jul 30 13:49:55.630919 2026] [security2:error] [pid 961194:tid 961451] [client 31.223.101.140:20485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc0_SWp157EsYqB3r67QAAAH8"], referer: http://pkf.jo
[Thu Jul 30 13:49:55.719195 2026] [security2:error] [pid 961194:tid 961335] [client 181.116.200.68:39758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc0_SWp157EsYqB3r7AQAAAAs"]
[Thu Jul 30 13:49:55.719335 2026] [security2:error] [pid 961194:tid 961335] [client 181.116.200.68:39758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc0_SWp157EsYqB3r7AQAAAAs"]
[Thu Jul 30 13:49:56.264504 2026] [security2:error] [pid 961194:tid 961410] [client 178.135.20.215:3270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc0_SWp157EsYqB3r7CQAAAFY"], referer: http://pkf.jo
[Thu Jul 30 13:49:57.174245 2026] [security2:error] [pid 961194:tid 961389] [client 103.190.40.154:2573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc1fSWp157EsYqB3r7MgAAAEE"]
[Thu Jul 30 13:49:57.174397 2026] [security2:error] [pid 961194:tid 961389] [client 103.190.40.154:2573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc1fSWp157EsYqB3r7MgAAAEE"]
[Thu Jul 30 13:49:57.808188 2026] [security2:error] [pid 961194:tid 961406] [client 74.7.241.132:51868] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "jcsgoeastwood.org"] [uri "/robots.txt"] [unique_id "amuc1fSWp157EsYqB3r7UwAAUiw"]
[Thu Jul 30 13:49:58.468164 2026] [security2:error] [pid 961194:tid 961363] [client 74.7.241.132:51874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.jcsgoeastwood.org"] [uri "/robots.txt"] [unique_id "amuc1vSWp157EsYqB3r7ZwAAJzE"], referer: https://jcsgoeastwood.org/robots.txt
[Thu Jul 30 13:49:58.722850 2026] [security2:error] [pid 961194:tid 961247] [remote 51.68.111.239:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/robots.txt"] [unique_id "amuc1vSWp157EsYqB3r7bgAAQjQ"]
[Thu Jul 30 13:49:58.723030 2026] [security2:error] [pid 961194:tid 961390] [client 51.68.111.239:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spececigarette.com"] [uri "/robots.txt"] [unique_id "amuc1vSWp157EsYqB3r7bgAAQjQ"]
[Thu Jul 30 13:49:58.976384 2026] [core:error] [pid 961194:tid 961386] [client 34.7.146.126:34882] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:49:58.976405 2026] [core:error] [pid 961194:tid 961386] [client 34.7.146.126:34882] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:49:58.976545 2026] [security2:error] [pid 961194:tid 961386] [client 34.7.146.126:34882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "store.carnetdeshopping.com"] [uri "/index.php"] [unique_id "amuc1vSWp157EsYqB3r7hgAAAD4"]
[Thu Jul 30 13:49:59.080449 2026] [security2:error] [pid 961194:tid 961403] [client 102.207.252.67:39132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc1vSWp157EsYqB3r7cwAAAE8"], referer: http://pkf.jo
[Thu Jul 30 13:49:59.289544 2026] [security2:error] [pid 961194:tid 961436] [client 74.7.230.9:43390] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.webotbola.store.qsv.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuc1_SWp157EsYqB3r7lAAAAHA"]
[Thu Jul 30 13:49:59.770543 2026] [security2:error] [pid 961194:tid 961379] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuc1_SWp157EsYqB3r7iwAAN0I"]
[Thu Jul 30 13:50:00.132558 2026] [proxy:error] [pid 961194:tid 961270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:50:00.132629 2026] [proxy_http:error] [pid 961194:tid 961270] [remote 74.7.175.153:40980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:50:00.133585 2026] [proxy:error] [pid 961194:tid 961270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:50:00.133637 2026] [proxy_http:error] [pid 961194:tid 961270] [remote 74.7.175.153:40980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:50:00.244148 2026] [security2:error] [pid 961194:tid 961351] [client 38.50.39.118:53408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc1_SWp157EsYqB3r7sgAAABs"], referer: http://pkf.jo
[Thu Jul 30 13:50:00.984296 2026] [core:error] [pid 961194:tid 961278] [remote 216.73.217.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:00.984319 2026] [core:error] [pid 961194:tid 961278] [remote 216.73.217.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:01.078889 2026] [security2:error] [pid 961194:tid 961336] [client 106.217.81.32:57520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc2PSWp157EsYqB3r7ywAAAAw"], referer: http://pkf.jo
[Thu Jul 30 13:50:01.223644 2026] [security2:error] [pid 961194:tid 961277] [remote 47.128.96.125:48684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/camic/article/view/9057"] [unique_id "amuc2PSWp157EsYqB3r72wAAe1I"]
[Thu Jul 30 13:50:01.241292 2026] [core:notice] [pid 961194:tid 961337] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:01.291424 2026] [core:notice] [pid 961194:tid 961279] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:01.292775 2026] [security2:error] [pid 961194:tid 961362] [client 38.248.176.45:45756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc2fSWp157EsYqB3r75QAAACY"], referer: http://pkf.jo
[Thu Jul 30 13:50:01.297085 2026] [security2:error] [pid 961194:tid 961410] [client 47.128.96.125:48684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/camic/article/view/9057"] [unique_id "amuc2fSWp157EsYqB3r76gAAVlQ"], referer: https://www.ejournalugj.com/index.php/camic/article/view/9057?articlesBySimilarityPage=2
[Thu Jul 30 13:50:01.516184 2026] [security2:error] [pid 961194:tid 961413] [client 206.204.154.46:34160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc2fSWp157EsYqB3r76AAAAFk"], referer: http://pkf.jo
[Thu Jul 30 13:50:01.591093 2026] [core:notice] [pid 961194:tid 961283] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:01.733279 2026] [core:notice] [pid 961194:tid 961285] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:01.733608 2026] [core:notice] [pid 961194:tid 961286] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:02.342113 2026] [security2:error] [pid 961194:tid 961353] [client 189.6.88.213:53947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc2vSWp157EsYqB3r8FQAAAB0"]
[Thu Jul 30 13:50:02.342239 2026] [security2:error] [pid 961194:tid 961353] [client 189.6.88.213:53947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc2vSWp157EsYqB3r8FQAAAB0"]
[Thu Jul 30 13:50:02.533678 2026] [security2:error] [pid 961194:tid 961294] [remote 57.141.0.64:26712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55089810635/feed/rss2/"] [unique_id "amuc2vSWp157EsYqB3r8HQAAKWM"]
[Thu Jul 30 13:50:02.719290 2026] [security2:error] [pid 961194:tid 961409] [client 94.59.233.245:60794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc2vSWp157EsYqB3r8GQAAAFU"], referer: http://pkf.jo
[Thu Jul 30 13:50:03.320844 2026] [security2:error] [pid 961194:tid 961444] [client 78.167.1.90:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc2_SWp157EsYqB3r8MwAAAHg"]
[Thu Jul 30 13:50:03.321414 2026] [security2:error] [pid 961194:tid 961444] [client 78.167.1.90:55718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc2_SWp157EsYqB3r8MwAAAHg"]
[Thu Jul 30 13:50:03.646935 2026] [security2:error] [pid 961194:tid 961378] [client 103.242.199.184:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc2_SWp157EsYqB3r8RAAAADY"]
[Thu Jul 30 13:50:03.647122 2026] [security2:error] [pid 961194:tid 961378] [client 103.242.199.184:55984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc2_SWp157EsYqB3r8RAAAADY"]
[Thu Jul 30 13:50:04.025404 2026] [security2:error] [pid 961194:tid 961417] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuc2_SWp157EsYqB3r8NAAAXWc"]
[Thu Jul 30 13:50:04.029259 2026] [security2:error] [pid 961194:tid 961307] [remote 57.141.0.70:62336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amuc3PSWp157EsYqB3r8TwAACHA"]
[Thu Jul 30 13:50:06.179578 2026] [security2:error] [pid 961194:tid 961196] [remote 74.7.227.39:36614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuc3vSWp157EsYqB3r8hgAAHAE"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/siteseo/main
[Thu Jul 30 13:50:06.347315 2026] [security2:error] [pid 961194:tid 961346] [client 181.116.200.68:26427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc3vSWp157EsYqB3r8hwAAABY"]
[Thu Jul 30 13:50:06.347434 2026] [security2:error] [pid 961194:tid 961346] [client 181.116.200.68:26427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc3vSWp157EsYqB3r8hwAAABY"]
[Thu Jul 30 13:50:06.691563 2026] [security2:error] [pid 961194:tid 961447] [client 52.167.144.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuc3PSWp157EsYqB3r8XAAAAHs"]
[Thu Jul 30 13:50:06.770878 2026] [security2:error] [pid 961194:tid 961414] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuc3vSWp157EsYqB3r8lQAAAFo"]
[Thu Jul 30 13:50:06.928013 2026] [security2:error] [pid 961194:tid 961210] [remote 57.141.0.38:44454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amuc3vSWp157EsYqB3r8owAAUQ8"]
[Thu Jul 30 13:50:06.956532 2026] [security2:error] [pid 961194:tid 961211] [remote 41.185.65.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.65.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "professionalfurnituremovingcompanyllc.store"] [uri "/wp-login.php"] [unique_id "amuc3vSWp157EsYqB3r8ngAAYhA"]
[Thu Jul 30 13:50:07.166964 2026] [security2:error] [pid 961194:tid 961377] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuc3vSWp157EsYqB3r8iwAANQQ"]
[Thu Jul 30 13:50:07.229232 2026] [security2:error] [pid 961194:tid 961212] [remote 216.73.217.142:23752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuc3_SWp157EsYqB3r8sAAAdxE"]
[Thu Jul 30 13:50:08.105358 2026] [security2:error] [pid 961194:tid 961335] [client 103.190.40.154:21940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc4PSWp157EsYqB3r8wAAAAAs"]
[Thu Jul 30 13:50:08.105572 2026] [security2:error] [pid 961194:tid 961335] [client 103.190.40.154:21940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc4PSWp157EsYqB3r8wAAAAAs"]
[Thu Jul 30 13:50:08.968800 2026] [security2:error] [pid 961194:tid 961387] [client 172.237.109.114:30687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4PSWp157EsYqB3r81AAAAD8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:08.972421 2026] [security2:error] [pid 961194:tid 961447] [client 172.237.109.114:53531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4PSWp157EsYqB3r81QAAAHs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:08.990906 2026] [security2:error] [pid 961194:tid 961341] [client 172.237.109.114:60678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4PSWp157EsYqB3r81wAAABE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.010074 2026] [security2:error] [pid 961194:tid 961399] [client 172.237.109.114:26090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r82AAAAEs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.010346 2026] [security2:error] [pid 961194:tid 961401] [client 172.237.109.114:47299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r82QAAAE0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.011297 2026] [security2:error] [pid 961194:tid 961384] [client 172.237.109.114:2162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r82gAAADw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.112567 2026] [security2:error] [pid 961194:tid 961364] [client 167.88.167.87:35704] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bookario.com"] [uri "/"] [unique_id "amuc4fSWp157EsYqB3r82wAAACg"]
[Thu Jul 30 13:50:09.581685 2026] [security2:error] [pid 961194:tid 961393] [client 99.244.211.156:39612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc4fSWp157EsYqB3r85QAAAEU"], referer: http://pkf.jo
[Thu Jul 30 13:50:09.962717 2026] [security2:error] [pid 961194:tid 961357] [client 172.237.109.114:47158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r88wAAACE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.963088 2026] [security2:error] [pid 961194:tid 961370] [client 172.237.109.114:36826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r89AAAAC4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.969435 2026] [security2:error] [pid 961194:tid 961350] [client 172.237.109.114:50498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r89QAAABo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.973505 2026] [security2:error] [pid 961194:tid 961325] [client 172.237.109.114:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r89gAAAAE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.977246 2026] [security2:error] [pid 961194:tid 961392] [client 172.237.109.114:47737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r89wAAAEQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.991847 2026] [security2:error] [pid 961194:tid 961345] [client 172.237.109.114:9543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r8-QAAABU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.991942 2026] [security2:error] [pid 961194:tid 961345] [client 172.237.109.114:9543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r8-QAAABU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:09.992209 2026] [security2:error] [pid 961194:tid 961333] [client 172.237.109.114:5709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4fSWp157EsYqB3r8-AAAAAk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:10.052523 2026] [security2:error] [pid 961194:tid 961359] [client 62.217.129.163:8950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc4fSWp157EsYqB3r87gAAACM"], referer: http://pkf.jo
[Thu Jul 30 13:50:10.115221 2026] [security2:error] [pid 961194:tid 961331] [client 38.159.162.186:59314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc4fSWp157EsYqB3r88gAAAAc"], referer: http://pkf.jo
[Thu Jul 30 13:50:10.356277 2026] [security2:error] [pid 961194:tid 961342] [client 129.222.155.152:26536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc4vSWp157EsYqB3r8-wAAABI"], referer: http://pkf.jo
[Thu Jul 30 13:50:10.553950 2026] [security2:error] [pid 961194:tid 961335] [client 49.144.67.15:33464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc4vSWp157EsYqB3r8_wAAAAs"], referer: http://pkf.jo
[Thu Jul 30 13:50:10.792129 2026] [security2:error] [pid 961194:tid 961363] [client 70.53.241.245:43428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc4vSWp157EsYqB3r9BwAAACc"], referer: http://pkf.jo
[Thu Jul 30 13:50:10.979671 2026] [security2:error] [pid 961194:tid 961386] [client 172.237.109.114:33031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4vSWp157EsYqB3r9EQAAAD4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:10.991153 2026] [security2:error] [pid 961194:tid 961347] [client 172.237.109.114:32220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4vSWp157EsYqB3r9EgAAABc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:10.992411 2026] [security2:error] [pid 961194:tid 961362] [client 172.237.109.114:32784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4vSWp157EsYqB3r9EwAAACY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:10.992965 2026] [security2:error] [pid 961194:tid 961383] [client 172.237.109.114:1266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4vSWp157EsYqB3r9FAAAADs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:10.993599 2026] [security2:error] [pid 961194:tid 961383] [client 172.237.109.114:26341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4vSWp157EsYqB3r9FQAAADs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:11.010618 2026] [security2:error] [pid 961194:tid 961412] [client 172.237.109.114:6959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4_SWp157EsYqB3r9FgAAAFg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:11.321290 2026] [security2:error] [pid 961194:tid 961344] [client 196.188.162.29:2640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc4_SWp157EsYqB3r9FwAAABQ"], referer: http://pkf.jo
[Thu Jul 30 13:50:11.993730 2026] [security2:error] [pid 961194:tid 961430] [client 172.237.109.114:63648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4_SWp157EsYqB3r9KgAAAGo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:11.993894 2026] [security2:error] [pid 961194:tid 961430] [client 172.237.109.114:63648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc4_SWp157EsYqB3r9KgAAAGo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:12.612725 2026] [security2:error] [pid 961194:tid 961253] [remote 57.141.0.69:61864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuc5PSWp157EsYqB3r9NgAAITo"]
[Thu Jul 30 13:50:12.756445 2026] [core:notice] [pid 961194:tid 961450] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:12.863185 2026] [core:notice] [pid 961194:tid 961256] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:12.943778 2026] [security2:error] [pid 961194:tid 961259] [remote 216.73.217.142:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuc5PSWp157EsYqB3r9RQAAY0A"]
[Thu Jul 30 13:50:12.973382 2026] [security2:error] [pid 961194:tid 961260] [remote 51.89.129.168:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "saiqon.net"] [uri "/about/"] [unique_id "amuc5PSWp157EsYqB3r9RwAACEE"]
[Thu Jul 30 13:50:12.973575 2026] [security2:error] [pid 961194:tid 961332] [client 51.89.129.168:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "saiqon.net"] [uri "/about/"] [unique_id "amuc5PSWp157EsYqB3r9RwAACEE"]
[Thu Jul 30 13:50:13.073996 2026] [security2:error] [pid 961194:tid 961351] [client 189.6.88.213:54454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc5fSWp157EsYqB3r9SAAAABs"]
[Thu Jul 30 13:50:13.074138 2026] [security2:error] [pid 961194:tid 961351] [client 189.6.88.213:54454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc5fSWp157EsYqB3r9SAAAABs"]
[Thu Jul 30 13:50:13.079653 2026] [security2:error] [pid 961194:tid 961431] [client 74.7.241.136:54876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/psychology.html"] [unique_id "amuc5PSWp157EsYqB3r9PgAAaz0"], referer: https://bootstraplily.com/robots.txt
[Thu Jul 30 13:50:13.694574 2026] [security2:error] [pid 961194:tid 961406] [client 172.237.109.114:54404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuc5fSWp157EsYqB3r9SQAAAFI"]
[Thu Jul 30 13:50:13.914274 2026] [security2:error] [pid 961194:tid 961387] [client 78.167.1.90:54659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc5fSWp157EsYqB3r9XAAAAD8"]
[Thu Jul 30 13:50:13.914784 2026] [security2:error] [pid 961194:tid 961387] [client 78.167.1.90:54659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc5fSWp157EsYqB3r9XAAAAD8"]
[Thu Jul 30 13:50:14.313012 2026] [security2:error] [pid 961194:tid 961413] [client 103.242.199.184:56546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc5vSWp157EsYqB3r9ZAAAAFk"]
[Thu Jul 30 13:50:14.313147 2026] [security2:error] [pid 961194:tid 961413] [client 103.242.199.184:56546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc5vSWp157EsYqB3r9ZAAAAFk"]
[Thu Jul 30 13:50:14.418651 2026] [security2:error] [pid 961194:tid 961361] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuc5fSWp157EsYqB3r9VQAAJUg"]
[Thu Jul 30 13:50:14.816397 2026] [security2:error] [pid 961194:tid 961377] [client 179.51.97.180:56200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc5vSWp157EsYqB3r9bgAAADU"], referer: http://pkf.jo
[Thu Jul 30 13:50:16.531654 2026] [autoindex:error] [pid 961194:tid 961381] [client 98.87.102.177:15075] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:50:16.912894 2026] [security2:error] [pid 961194:tid 961421] [client 181.116.200.68:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc6PSWp157EsYqB3r9rAAAAGE"]
[Thu Jul 30 13:50:16.913026 2026] [security2:error] [pid 961194:tid 961421] [client 181.116.200.68:64172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc6PSWp157EsYqB3r9rAAAAGE"]
[Thu Jul 30 13:50:16.919023 2026] [core:notice] [pid 961194:tid 961302] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:17.186655 2026] [core:notice] [pid 961194:tid 961304] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:17.232065 2026] [security2:error] [pid 961194:tid 961308] [remote 216.73.217.142:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuc6fSWp157EsYqB3r9uwAADnE"]
[Thu Jul 30 13:50:18.376894 2026] [core:notice] [pid 961194:tid 961384] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:18.534997 2026] [core:notice] [pid 961194:tid 961412] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:19.230125 2026] [security2:error] [pid 961194:tid 961395] [client 103.190.40.154:23434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc6_SWp157EsYqB3r-AAAAAEc"]
[Thu Jul 30 13:50:19.230240 2026] [security2:error] [pid 961194:tid 961395] [client 103.190.40.154:23434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc6_SWp157EsYqB3r-AAAAAEc"]
[Thu Jul 30 13:50:20.805047 2026] [security2:error] [pid 961194:tid 961236] [remote 57.141.0.41:30930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/706661964/feed/rss2/"] [unique_id "amuc7PSWp157EsYqB3r-MQAAWCk"]
[Thu Jul 30 13:50:22.416891 2026] [security2:error] [pid 961194:tid 961254] [remote 57.141.0.8:64886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuc7vSWp157EsYqB3r-XQAAMTs"]
[Thu Jul 30 13:50:23.688789 2026] [security2:error] [pid 961194:tid 961439] [client 189.6.88.213:54975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc7_SWp157EsYqB3r-xQAAAHM"]
[Thu Jul 30 13:50:23.688911 2026] [security2:error] [pid 961194:tid 961439] [client 189.6.88.213:54975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc7_SWp157EsYqB3r-xQAAAHM"]
[Thu Jul 30 13:50:24.556147 2026] [security2:error] [pid 961194:tid 961331] [client 202.188.12.241:60669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc8PSWp157EsYqB3r-0wAAAAc"], referer: http://pkf.jo
[Thu Jul 30 13:50:24.894092 2026] [core:error] [pid 961194:tid 961235] [remote 74.7.241.181:54584] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:24.894126 2026] [core:error] [pid 961194:tid 961235] [remote 74.7.241.181:54584] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:24.894364 2026] [security2:error] [pid 961194:tid 961359] [client 74.7.241.181:54584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-c27acd19.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuc8PSWp157EsYqB3r-6QAAIyg"]
[Thu Jul 30 13:50:24.900297 2026] [security2:error] [pid 961194:tid 961369] [client 103.242.199.184:57102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc8PSWp157EsYqB3r-6gAAAC0"]
[Thu Jul 30 13:50:24.900390 2026] [security2:error] [pid 961194:tid 961369] [client 103.242.199.184:57102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc8PSWp157EsYqB3r-6gAAAC0"]
[Thu Jul 30 13:50:24.900417 2026] [security2:error] [pid 961194:tid 961340] [client 57.141.0.17:52598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuc8PSWp157EsYqB3r-3QAAECY"], referer: https://igetvape-australia.com/store/?product-page=3&add-to-cart=128
[Thu Jul 30 13:50:24.972109 2026] [security2:error] [pid 961194:tid 961388] [client 94.54.26.192:34878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc8PSWp157EsYqB3r-4gAAAEA"], referer: http://pkf.jo
[Thu Jul 30 13:50:25.025666 2026] [security2:error] [pid 961194:tid 961380] [client 126.209.84.86:43004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc8PSWp157EsYqB3r-5AAAADg"], referer: http://pkf.jo
[Thu Jul 30 13:50:25.516281 2026] [security2:error] [pid 961194:tid 961397] [client 2a03:2880:f800:11:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuc8PSWp157EsYqB3r-3gAASSM"]
[Thu Jul 30 13:50:25.696394 2026] [security2:error] [pid 961194:tid 961405] [client 2a03:2880:f800:a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuc8PSWp157EsYqB3r-4wAAUSQ"]
[Thu Jul 30 13:50:26.153803 2026] [security2:error] [pid 961194:tid 961375] [client 186.179.163.30:13407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc8fSWp157EsYqB3r_AgAAADM"], referer: http://pkf.jo
[Thu Jul 30 13:50:26.699481 2026] [security2:error] [pid 961194:tid 961391] [client 190.112.102.17:36358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc8vSWp157EsYqB3r_DgAAAEM"], referer: http://pkf.jo
[Thu Jul 30 13:50:26.952221 2026] [security2:error] [pid 961194:tid 961366] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuc8vSWp157EsYqB3r_DQAAACo"]
[Thu Jul 30 13:50:27.573336 2026] [security2:error] [pid 961194:tid 961384] [client 181.116.200.68:40502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc8_SWp157EsYqB3r_LQAAADw"]
[Thu Jul 30 13:50:27.573472 2026] [security2:error] [pid 961194:tid 961384] [client 181.116.200.68:40502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc8_SWp157EsYqB3r_LQAAADw"]
[Thu Jul 30 13:50:27.892381 2026] [core:error] [pid 961194:tid 961262] [remote 2a09:bac0:1000:c48::21e:14b:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:27.892407 2026] [core:error] [pid 961194:tid 961262] [remote 2a09:bac0:1000:c48::21e:14b:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:27.900296 2026] [core:error] [pid 961194:tid 961259] [remote 2a09:bac0:1000:c48::21e:14b:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:27.900318 2026] [core:error] [pid 961194:tid 961259] [remote 2a09:bac0:1000:c48::21e:14b:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:27.940892 2026] [core:error] [pid 961194:tid 961269] [remote 2a09:bac0:1000:c48::2e9:38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:27.940915 2026] [core:error] [pid 961194:tid 961269] [remote 2a09:bac0:1000:c48::2e9:38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:50:28.430481 2026] [security2:error] [pid 961194:tid 961394] [client 186.54.123.236:38862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuc9PSWp157EsYqB3r_XAAAAEY"], referer: http://pkf.jo
[Thu Jul 30 13:50:28.847633 2026] [security2:error] [pid 961194:tid 961429] [client 134.19.179.155:60280] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuc9PSWp157EsYqB3r_fgAAAGk"]
[Thu Jul 30 13:50:28.847763 2026] [security2:error] [pid 961194:tid 961429] [client 134.19.179.155:60280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuc9PSWp157EsYqB3r_fgAAAGk"]
[Thu Jul 30 13:50:28.972612 2026] [security2:error] [pid 961194:tid 961384] [client 172.237.109.114:13221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9PSWp157EsYqB3r_gAAAADw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:28.992383 2026] [security2:error] [pid 961194:tid 961349] [client 172.237.109.114:14761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9PSWp157EsYqB3r_ggAAABk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.011845 2026] [security2:error] [pid 961194:tid 961402] [client 172.237.109.114:24959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_gwAAAE4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.369637 2026] [security2:error] [pid 961194:tid 961421] [client 85.208.98.23:21674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuc9fSWp157EsYqB3r_jQAAAGE"]
[Thu Jul 30 13:50:29.369737 2026] [security2:error] [pid 961194:tid 961421] [client 85.208.98.23:21674] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuc9fSWp157EsYqB3r_jQAAAGE"]
[Thu Jul 30 13:50:29.844888 2026] [proxy:error] [pid 961194:tid 961358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:50:29.844948 2026] [proxy_http:error] [pid 961194:tid 961358] [client 74.7.230.43:56582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:50:29.845565 2026] [proxy:error] [pid 961194:tid 961358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:50:29.845609 2026] [proxy_http:error] [pid 961194:tid 961358] [client 74.7.230.43:56582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:50:29.845733 2026] [security2:error] [pid 961194:tid 961358] [client 74.7.230.43:56582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.mxv.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuc9fSWp157EsYqB3r_mgAAACI"]
[Thu Jul 30 13:50:29.862581 2026] [security2:error] [pid 961194:tid 961350] [client 103.190.40.154:23133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc9fSWp157EsYqB3r_mwAAABo"]
[Thu Jul 30 13:50:29.862699 2026] [security2:error] [pid 961194:tid 961350] [client 103.190.40.154:23133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuc9fSWp157EsYqB3r_mwAAABo"]
[Thu Jul 30 13:50:29.962404 2026] [security2:error] [pid 961194:tid 961328] [client 172.237.109.114:54737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_nAAAAAQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.962458 2026] [security2:error] [pid 961194:tid 961368] [client 172.237.109.114:16432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_ngAAACw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.962548 2026] [security2:error] [pid 961194:tid 961357] [client 172.237.109.114:10991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_nQAAACE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.971841 2026] [security2:error] [pid 961194:tid 961353] [client 172.237.109.114:65214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_nwAAAB0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.972211 2026] [security2:error] [pid 961194:tid 961327] [client 172.237.109.114:1848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_oAAAAAM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.974239 2026] [security2:error] [pid 961194:tid 961346] [client 172.237.109.114:3015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_ogAAABY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.974303 2026] [security2:error] [pid 961194:tid 961346] [client 172.237.109.114:3015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_ogAAABY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.974420 2026] [security2:error] [pid 961194:tid 961427] [client 172.237.109.114:20223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_oQAAAGc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:29.992550 2026] [security2:error] [pid 961194:tid 961391] [client 172.237.109.114:13941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9fSWp157EsYqB3r_owAAAEM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:30.011892 2026] [security2:error] [pid 961194:tid 961442] [client 172.237.109.114:30665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9vSWp157EsYqB3r_pAAAAHY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:30.962341 2026] [security2:error] [pid 961194:tid 961445] [client 172.237.109.114:62002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9vSWp157EsYqB3r_xQAAAHk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:30.962457 2026] [security2:error] [pid 961194:tid 961445] [client 172.237.109.114:62002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9vSWp157EsYqB3r_xQAAAHk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:30.962593 2026] [security2:error] [pid 961194:tid 961384] [client 172.237.109.114:47912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9vSWp157EsYqB3r_xAAAADw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:31.250138 2026] [security2:error] [pid 961194:tid 961428] [client 59.148.102.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuc9vSWp157EsYqB3r_uwAAAGg"]
[Thu Jul 30 13:50:31.250921 2026] [security2:error] [pid 961194:tid 961344] [client 59.148.102.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuc9vSWp157EsYqB3r_vgAAABQ"]
[Thu Jul 30 13:50:31.280732 2026] [security2:error] [pid 961194:tid 961422] [client 59.148.102.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuc9vSWp157EsYqB3r_wwAAAGI"]
[Thu Jul 30 13:50:31.480028 2026] [security2:error] [pid 961194:tid 961429] [client 59.148.102.27:54663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuc9vSWp157EsYqB3r_vwAAaWc"]
[Thu Jul 30 13:50:31.480150 2026] [security2:error] [pid 961194:tid 961429] [client 59.148.102.27:54663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuc9vSWp157EsYqB3r_wAAAaW8"]
[Thu Jul 30 13:50:31.962417 2026] [security2:error] [pid 961194:tid 961413] [client 172.237.109.114:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9_SWp157EsYqB3oAGgAAAFk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:31.973044 2026] [security2:error] [pid 961194:tid 961449] [client 172.237.109.114:25729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc9_SWp157EsYqB3oAGwAAAH0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:32.009433 2026] [security2:error] [pid 961194:tid 961371] [client 172.237.109.114:47663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc-PSWp157EsYqB3oAHQAAAC8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:32.009591 2026] [security2:error] [pid 961194:tid 961402] [client 172.237.109.114:6764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc-PSWp157EsYqB3oAHgAAAE4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:32.009807 2026] [security2:error] [pid 961194:tid 961335] [client 172.237.109.114:39831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc-PSWp157EsYqB3oAHwAAAAs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:32.236117 2026] [security2:error] [pid 961194:tid 961230] [remote 216.73.217.142:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuc-PSWp157EsYqB3oAIwAAHiM"]
[Thu Jul 30 13:50:32.750439 2026] [security2:error] [pid 961194:tid 961414] [client 59.148.102.27:54666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuc-PSWp157EsYqB3oAKgAAWio"]
[Thu Jul 30 13:50:32.975017 2026] [security2:error] [pid 961194:tid 961338] [client 172.237.109.114:9918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuc-PSWp157EsYqB3oAOQAAAA4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:33.590595 2026] [security2:error] [pid 961194:tid 961383] [client 59.148.102.27:54666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marlboro-shop.com"] [uri "/index.php"] [unique_id "amuc-fSWp157EsYqB3oAPAAAOzQ"]
[Thu Jul 30 13:50:34.401668 2026] [security2:error] [pid 961194:tid 961358] [client 52.167.144.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuc-vSWp157EsYqB3oAUgAAACI"]
[Thu Jul 30 13:50:34.575139 2026] [security2:error] [pid 961194:tid 961326] [client 172.237.109.114:23844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuc-vSWp157EsYqB3oAWAAAAAI"]
[Thu Jul 30 13:50:34.651799 2026] [security2:error] [pid 961194:tid 961408] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuc-vSWp157EsYqB3oAVwAAAFQ"]
[Thu Jul 30 13:50:34.955918 2026] [proxy:error] [pid 961194:tid 961441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:50:34.955994 2026] [proxy_http:error] [pid 961194:tid 961441] [client 138.246.253.24:39624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:50:34.956786 2026] [proxy:error] [pid 961194:tid 961441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:50:34.956838 2026] [proxy_http:error] [pid 961194:tid 961441] [client 138.246.253.24:39624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:50:35.648090 2026] [security2:error] [pid 961194:tid 961330] [client 103.242.199.184:57666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc-_SWp157EsYqB3oAeQAAAAY"]
[Thu Jul 30 13:50:35.648192 2026] [security2:error] [pid 961194:tid 961330] [client 103.242.199.184:57666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuc-_SWp157EsYqB3oAeQAAAAY"]
[Thu Jul 30 13:50:36.794226 2026] [security2:error] [pid 961194:tid 961299] [remote 57.141.0.56:52310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6626375131/feed/rss2/"] [unique_id "amuc_PSWp157EsYqB3oAqAAAYmg"]
[Thu Jul 30 13:50:38.106443 2026] [security2:error] [pid 961194:tid 961446] [client 181.116.200.68:49422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc_vSWp157EsYqB3oAywAAAHo"]
[Thu Jul 30 13:50:38.106570 2026] [security2:error] [pid 961194:tid 961446] [client 181.116.200.68:49422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuc_vSWp157EsYqB3oAywAAAHo"]
[Thu Jul 30 13:50:38.702958 2026] [security2:error] [pid 961194:tid 961320] [remote 74.7.243.224:34260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuc_vSWp157EsYqB3oA5QAADH0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 13:50:40.591393 2026] [security2:error] [pid 961194:tid 961383] [client 103.190.40.154:22456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudAPSWp157EsYqB3oBFwAAADs"]
[Thu Jul 30 13:50:40.591530 2026] [security2:error] [pid 961194:tid 961383] [client 103.190.40.154:22456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudAPSWp157EsYqB3oBFwAAADs"]
[Thu Jul 30 13:50:41.058396 2026] [security2:error] [pid 961194:tid 961217] [remote 47.128.60.144:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tuwaiq-sa.tech"] [uri "/robots.txt"] [unique_id "amudAfSWp157EsYqB3oBKQAAJBY"]
[Thu Jul 30 13:50:41.961254 2026] [core:notice] [pid 961194:tid 961367] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:42.111048 2026] [core:notice] [pid 961194:tid 961449] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:42.147711 2026] [core:notice] [pid 961194:tid 961224] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:42.664444 2026] [core:notice] [pid 961194:tid 961240] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:43.120038 2026] [core:notice] [pid 961194:tid 961333] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:43.680173 2026] [security2:error] [pid 961194:tid 961352] [client 172.237.109.114:19680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudA_SWp157EsYqB3oBdwAAABw"]
[Thu Jul 30 13:50:44.262259 2026] [security2:error] [pid 961194:tid 961420] [client 66.249.64.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.magicmooncorp.com"] [uri "/index.php"] [unique_id "amudAvSWp157EsYqB3oBaQAAAGA"]
[Thu Jul 30 13:50:45.125199 2026] [security2:error] [pid 961194:tid 961252] [remote 5.161.62.209:35680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.inmobiliariadia.com"] [uri "/.env"] [unique_id "amudBfSWp157EsYqB3oBrAAAPjk"]
[Thu Jul 30 13:50:45.275781 2026] [security2:error] [pid 961194:tid 961263] [remote 72.167.132.114:33310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-login.php"] [unique_id "amudBfSWp157EsYqB3oBswAAW0Q"]
[Thu Jul 30 13:50:46.328808 2026] [security2:error] [pid 961194:tid 961383] [client 103.242.199.184:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudBvSWp157EsYqB3oB0wAAADs"]
[Thu Jul 30 13:50:46.328929 2026] [security2:error] [pid 961194:tid 961383] [client 103.242.199.184:58225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudBvSWp157EsYqB3oB0wAAADs"]
[Thu Jul 30 13:50:46.631525 2026] [security2:error] [pid 961194:tid 961408] [client 78.167.1.90:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudBvSWp157EsYqB3oB4QAAAFQ"]
[Thu Jul 30 13:50:46.631638 2026] [security2:error] [pid 961194:tid 961408] [client 78.167.1.90:55255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudBvSWp157EsYqB3oB4QAAAFQ"]
[Thu Jul 30 13:50:48.746690 2026] [security2:error] [pid 961194:tid 961433] [client 181.116.200.68:53229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudCPSWp157EsYqB3oCIQAAAG0"]
[Thu Jul 30 13:50:48.746841 2026] [security2:error] [pid 961194:tid 961433] [client 181.116.200.68:53229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudCPSWp157EsYqB3oCIQAAAG0"]
[Thu Jul 30 13:50:48.803342 2026] [security2:error] [pid 961194:tid 961344] [client 94.154.43.179:42700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jesus.claims"] [uri "/.env"] [unique_id "amudCPSWp157EsYqB3oCIgAAABQ"]
[Thu Jul 30 13:50:50.253687 2026] [security2:error] [pid 961194:tid 961445] [client 172.237.109.114:44602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudCfSWp157EsYqB3oCSQAAAHk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:50.269862 2026] [security2:error] [pid 961194:tid 961425] [client 172.237.109.114:10776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudCvSWp157EsYqB3oCTQAAAGU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:50.270550 2026] [security2:error] [pid 961194:tid 961327] [client 172.237.109.114:3068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudCvSWp157EsYqB3oCTAAAAAM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:50.366078 2026] [security2:error] [pid 961194:tid 961374] [client 51.68.111.215:9213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amudCvSWp157EsYqB3oCXgAAADI"]
[Thu Jul 30 13:50:50.366219 2026] [security2:error] [pid 961194:tid 961374] [client 51.68.111.215:9213] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amudCvSWp157EsYqB3oCXgAAADI"]
[Thu Jul 30 13:50:50.374311 2026] [security2:error] [pid 961194:tid 961207] [remote 57.141.0.43:52338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amudCvSWp157EsYqB3oCXwAAHgw"]
[Thu Jul 30 13:50:50.966014 2026] [security2:error] [pid 961194:tid 961360] [client 172.237.109.114:43498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudCvSWp157EsYqB3oCbAAAACQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:50.971847 2026] [security2:error] [pid 961194:tid 961337] [client 172.237.109.114:41201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudCvSWp157EsYqB3oCbgAAAA0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:50.972815 2026] [security2:error] [pid 961194:tid 961380] [client 172.237.109.114:18987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudCvSWp157EsYqB3oCbwAAADg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:50.994701 2026] [security2:error] [pid 961194:tid 961411] [client 172.237.109.114:42253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudCvSWp157EsYqB3oCcQAAAFc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:50.994728 2026] [security2:error] [pid 961194:tid 961385] [client 172.237.109.114:1139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudCvSWp157EsYqB3oCcAAAAD0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:51.011445 2026] [security2:error] [pid 961194:tid 961353] [client 172.237.109.114:24739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudC_SWp157EsYqB3oCcgAAAB0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:51.011553 2026] [security2:error] [pid 961194:tid 961359] [client 172.237.109.114:50779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudC_SWp157EsYqB3oCcwAAACM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:51.012319 2026] [security2:error] [pid 961194:tid 961381] [client 172.237.109.114:28812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudC_SWp157EsYqB3oCdAAAADk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:51.013695 2026] [security2:error] [pid 961194:tid 961418] [client 172.237.109.114:15661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudC_SWp157EsYqB3oCdQAAAF4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:51.356062 2026] [security2:error] [pid 961194:tid 961449] [client 103.190.40.154:14691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudC_SWp157EsYqB3oCgQAAAH0"]
[Thu Jul 30 13:50:51.356212 2026] [security2:error] [pid 961194:tid 961449] [client 103.190.40.154:14691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudC_SWp157EsYqB3oCgQAAAH0"]
[Thu Jul 30 13:50:51.655666 2026] [security2:error] [pid 961194:tid 961424] [client 20.52.125.110:11494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/011i.php"] [unique_id "amudC_SWp157EsYqB3oCiQAAAGQ"]
[Thu Jul 30 13:50:51.994330 2026] [security2:error] [pid 961194:tid 961407] [client 172.237.109.114:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudC_SWp157EsYqB3oCjQAAAFM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:52.010960 2026] [security2:error] [pid 961194:tid 961423] [client 172.237.109.114:55401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudDPSWp157EsYqB3oCjgAAAGM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:52.049969 2026] [security2:error] [pid 961194:tid 961375] [client 20.52.125.110:11985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/03a005685d.php"] [unique_id "amudDPSWp157EsYqB3oCjwAAADM"]
[Thu Jul 30 13:50:52.442461 2026] [security2:error] [pid 961194:tid 961437] [client 20.52.125.110:11519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/403.php"] [unique_id "amudDPSWp157EsYqB3oCnwAAAHE"]
[Thu Jul 30 13:50:52.835827 2026] [security2:error] [pid 961194:tid 961432] [client 20.52.125.110:11504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/404.php"] [unique_id "amudDPSWp157EsYqB3oCrgAAAGw"]
[Thu Jul 30 13:50:52.974160 2026] [security2:error] [pid 961194:tid 961359] [client 172.237.109.114:11813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudDPSWp157EsYqB3oCrwAAACM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:52.975284 2026] [security2:error] [pid 961194:tid 961381] [client 172.237.109.114:2039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudDPSWp157EsYqB3oCsAAAADk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:52.975352 2026] [security2:error] [pid 961194:tid 961381] [client 172.237.109.114:2039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudDPSWp157EsYqB3oCsAAAADk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:52.993286 2026] [security2:error] [pid 961194:tid 961418] [client 172.237.109.114:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudDPSWp157EsYqB3oCsQAAAF4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:52.996422 2026] [security2:error] [pid 961194:tid 961389] [client 172.237.109.114:33665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudDPSWp157EsYqB3oCsgAAAEE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:53.003809 2026] [security2:error] [pid 961194:tid 961380] [client 74.7.241.139:34854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.bonafideadvisors.com"] [uri "/robots.txt"] [unique_id "amudDfSWp157EsYqB3oCswAAOAE"]
[Thu Jul 30 13:50:53.230109 2026] [security2:error] [pid 961194:tid 961369] [client 20.52.125.110:11457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/aa.php"] [unique_id "amudDfSWp157EsYqB3oCvgAAAC0"]
[Thu Jul 30 13:50:53.633052 2026] [security2:error] [pid 961194:tid 961365] [client 20.52.125.110:11493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/aafewc0k.php"] [unique_id "amudDfSWp157EsYqB3oCxQAAACk"]
[Thu Jul 30 13:50:53.995185 2026] [security2:error] [pid 961194:tid 961339] [client 172.237.109.114:16726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudDfSWp157EsYqB3oCywAAAA8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:53.995284 2026] [security2:error] [pid 961194:tid 961339] [client 172.237.109.114:16726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudDfSWp157EsYqB3oCywAAAA8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:54.009947 2026] [security2:error] [pid 961194:tid 961387] [client 172.237.109.114:1694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudDvSWp157EsYqB3oCzQAAAD8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:50:54.029098 2026] [security2:error] [pid 961194:tid 961395] [client 20.52.125.110:11497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/abcd.php"] [unique_id "amudDvSWp157EsYqB3oCzwAAAEc"]
[Thu Jul 30 13:50:54.427662 2026] [security2:error] [pid 961194:tid 961440] [client 20.52.125.110:11990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/about.php"] [unique_id "amudDvSWp157EsYqB3oC3AAAAHQ"]
[Thu Jul 30 13:50:54.836456 2026] [security2:error] [pid 961194:tid 961415] [client 20.52.125.110:11458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/admin.php"] [unique_id "amudDvSWp157EsYqB3oC5wAAAFs"]
[Thu Jul 30 13:50:55.256095 2026] [security2:error] [pid 961194:tid 961357] [client 20.52.125.110:11976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/adminfuns.php"] [unique_id "amudD_SWp157EsYqB3oC7gAAACE"]
[Thu Jul 30 13:50:55.666338 2026] [security2:error] [pid 961194:tid 961393] [client 20.52.125.110:11983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/albin.php"] [unique_id "amudD_SWp157EsYqB3oC9AAAAEU"]
[Thu Jul 30 13:50:55.930152 2026] [security2:error] [pid 961194:tid 961390] [client 189.6.88.213:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudD_SWp157EsYqB3oC_wAAAEI"]
[Thu Jul 30 13:50:55.930263 2026] [security2:error] [pid 961194:tid 961390] [client 189.6.88.213:56882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudD_SWp157EsYqB3oC_wAAAEI"]
[Thu Jul 30 13:50:56.058771 2026] [security2:error] [pid 961194:tid 961442] [client 20.52.125.110:11986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/amfsqvgv.php"] [unique_id "amudEPSWp157EsYqB3oDAQAAAHY"]
[Thu Jul 30 13:50:56.124951 2026] [security2:error] [pid 961194:tid 961373] [client 216.73.217.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.collectgabon.com"] [uri "/index.php"] [unique_id "amudDvSWp157EsYqB3oC4QAAMSA"]
[Thu Jul 30 13:50:56.158889 2026] [security2:error] [pid 961194:tid 961375] [client 78.167.1.90:55144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudEPSWp157EsYqB3oDAgAAADM"]
[Thu Jul 30 13:50:56.159590 2026] [security2:error] [pid 961194:tid 961375] [client 78.167.1.90:55144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudEPSWp157EsYqB3oDAgAAADM"]
[Thu Jul 30 13:50:56.453039 2026] [security2:error] [pid 961194:tid 961374] [client 20.52.125.110:11496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/ant.php"] [unique_id "amudEPSWp157EsYqB3oDEwAAADI"]
[Thu Jul 30 13:50:56.857334 2026] [security2:error] [pid 961194:tid 961386] [client 20.52.125.110:11487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/appreciators.php"] [unique_id "amudEPSWp157EsYqB3oDGgAAAD4"]
[Thu Jul 30 13:50:56.870592 2026] [security2:error] [pid 961194:tid 961368] [client 103.242.199.184:58788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudEPSWp157EsYqB3oDGwAAACw"]
[Thu Jul 30 13:50:56.870673 2026] [security2:error] [pid 961194:tid 961368] [client 103.242.199.184:58788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudEPSWp157EsYqB3oDGwAAACw"]
[Thu Jul 30 13:50:57.252317 2026] [security2:error] [pid 961194:tid 961346] [client 20.52.125.110:11468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/archive.php"] [unique_id "amudEfSWp157EsYqB3oDJQAAABY"]
[Thu Jul 30 13:50:57.332460 2026] [core:notice] [pid 961194:tid 961270] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:50:57.647056 2026] [security2:error] [pid 961194:tid 961332] [client 20.52.125.110:11476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/as.php"] [unique_id "amudEfSWp157EsYqB3oDNQAAAAg"]
[Thu Jul 30 13:50:58.045652 2026] [security2:error] [pid 961194:tid 961401] [client 20.52.125.110:11969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/atomlib.php"] [unique_id "amudEvSWp157EsYqB3oDRQAAAE0"]
[Thu Jul 30 13:50:58.443826 2026] [security2:error] [pid 961194:tid 961361] [client 20.52.125.110:11469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/autoload_classmap.php"] [unique_id "amudEvSWp157EsYqB3oDTQAAACU"]
[Thu Jul 30 13:50:58.653372 2026] [security2:error] [pid 961194:tid 961413] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudEvSWp157EsYqB3oDRAAAAFk"]
[Thu Jul 30 13:50:58.838047 2026] [security2:error] [pid 961194:tid 961386] [client 20.52.125.110:12021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/bb.php"] [unique_id "amudEvSWp157EsYqB3oDUgAAAD4"]
[Thu Jul 30 13:50:58.881622 2026] [security2:error] [pid 961194:tid 961397] [client 216.73.217.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.collectgabon.com"] [uri "/index.php"] [unique_id "amudEvSWp157EsYqB3oDUQAASVg"]
[Thu Jul 30 13:50:59.234065 2026] [security2:error] [pid 961194:tid 961417] [client 20.52.125.110:11506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/bnm.php"] [unique_id "amudE_SWp157EsYqB3oDXQAAAF0"]
[Thu Jul 30 13:50:59.416047 2026] [security2:error] [pid 961194:tid 961392] [client 181.116.200.68:15797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudE_SWp157EsYqB3oDXwAAAEQ"]
[Thu Jul 30 13:50:59.416158 2026] [security2:error] [pid 961194:tid 961392] [client 181.116.200.68:15797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudE_SWp157EsYqB3oDXwAAAEQ"]
[Thu Jul 30 13:50:59.618236 2026] [security2:error] [pid 961194:tid 961282] [remote 57.141.0.27:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55276018792/feed/rss2/"] [unique_id "amudE_SWp157EsYqB3oDaQAATlc"]
[Thu Jul 30 13:50:59.632281 2026] [security2:error] [pid 961194:tid 961430] [client 20.52.125.110:11484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/bootstrap.php"] [unique_id "amudE_SWp157EsYqB3oDagAAAGo"]
[Thu Jul 30 13:51:00.030470 2026] [security2:error] [pid 961194:tid 961427] [client 20.52.125.110:11475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/buy.php"] [unique_id "amudFPSWp157EsYqB3oDewAAAGc"]
[Thu Jul 30 13:51:00.072427 2026] [proxy:error] [pid 961194:tid 961350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:00.072496 2026] [proxy_http:error] [pid 961194:tid 961350] [client 34.224.175.62:37332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:00.073760 2026] [proxy:error] [pid 961194:tid 961350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:00.073826 2026] [proxy_http:error] [pid 961194:tid 961350] [client 34.224.175.62:37332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:00.115866 2026] [proxy:error] [pid 961194:tid 961367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:00.115942 2026] [proxy_http:error] [pid 961194:tid 961367] [client 34.224.175.62:49494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:00.116571 2026] [proxy:error] [pid 961194:tid 961367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:00.116628 2026] [proxy_http:error] [pid 961194:tid 961367] [client 34.224.175.62:49494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:00.332670 2026] [security2:error] [pid 961194:tid 961386] [client 162.219.176.3:56298] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudFPSWp157EsYqB3oDkAAAAD4"]
[Thu Jul 30 13:51:00.332768 2026] [security2:error] [pid 961194:tid 961386] [client 162.219.176.3:56298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudFPSWp157EsYqB3oDkAAAAD4"]
[Thu Jul 30 13:51:00.425111 2026] [security2:error] [pid 961194:tid 961337] [client 20.52.125.110:11480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/chosen.php"] [unique_id "amudFPSWp157EsYqB3oDkQAAAA0"]
[Thu Jul 30 13:51:00.755282 2026] [core:error] [pid 961194:tid 961449] [client 74.7.230.56:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:51:00.755314 2026] [core:error] [pid 961194:tid 961449] [client 74.7.230.56:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:51:00.755462 2026] [security2:error] [pid 961194:tid 961449] [client 74.7.230.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amudFPSWp157EsYqB3oDngAAAH0"]
[Thu Jul 30 13:51:00.756240 2026] [security2:error] [pid 961194:tid 961345] [client 74.7.230.56:52504] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.ste.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amudFPSWp157EsYqB3oDnAAAFW0"]
[Thu Jul 30 13:51:00.833579 2026] [security2:error] [pid 961194:tid 961392] [client 20.52.125.110:11512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/class-wp-image.php"] [unique_id "amudFPSWp157EsYqB3oDoAAAAEQ"]
[Thu Jul 30 13:51:01.230499 2026] [security2:error] [pid 961194:tid 961442] [client 20.52.125.110:11474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/classsmtps.php"] [unique_id "amudFfSWp157EsYqB3oDtwAAAHY"]
[Thu Jul 30 13:51:01.624585 2026] [security2:error] [pid 961194:tid 961401] [client 20.52.125.110:11466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/classwithtostring.php"] [unique_id "amudFfSWp157EsYqB3oDvAAAAE0"]
[Thu Jul 30 13:51:01.990111 2026] [security2:error] [pid 961194:tid 961333] [client 103.190.40.154:23110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudFfSWp157EsYqB3oDxAAAAAk"]
[Thu Jul 30 13:51:01.990266 2026] [security2:error] [pid 961194:tid 961333] [client 103.190.40.154:23110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudFfSWp157EsYqB3oDxAAAAAk"]
[Thu Jul 30 13:51:02.019533 2026] [security2:error] [pid 961194:tid 961437] [client 20.52.125.110:11987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/config.php"] [unique_id "amudFvSWp157EsYqB3oDxwAAAHE"]
[Thu Jul 30 13:51:02.469745 2026] [security2:error] [pid 961194:tid 961360] [client 20.52.125.110:11503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/core.php"] [unique_id "amudFvSWp157EsYqB3oD0gAAACQ"]
[Thu Jul 30 13:51:02.874124 2026] [security2:error] [pid 961194:tid 961366] [client 20.52.125.110:11461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/css.php"] [unique_id "amudFvSWp157EsYqB3oD3AAAACo"]
[Thu Jul 30 13:51:03.272898 2026] [security2:error] [pid 961194:tid 961365] [client 20.52.125.110:11972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/database.php"] [unique_id "amudF_SWp157EsYqB3oD5AAAACk"]
[Thu Jul 30 13:51:03.347313 2026] [proxy:error] [pid 961194:tid 961207] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:03.347365 2026] [proxy_http:error] [pid 961194:tid 961207] [remote 74.7.244.36:42458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:03.347936 2026] [proxy:error] [pid 961194:tid 961207] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:03.347992 2026] [proxy_http:error] [pid 961194:tid 961207] [remote 74.7.244.36:42458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:03.665182 2026] [security2:error] [pid 961194:tid 961446] [client 20.52.125.110:11975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/db.php"] [unique_id "amudF_SWp157EsYqB3oD8gAAAHo"]
[Thu Jul 30 13:51:03.795400 2026] [security2:error] [pid 961194:tid 961444] [client 52.167.144.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amudF_SWp157EsYqB3oD7QAAAHg"]
[Thu Jul 30 13:51:03.976668 2026] [security2:error] [pid 961194:tid 961213] [remote 160.22.160.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.160.22.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mukasarati.com"] [uri "/xmlrpc.php"] [unique_id "amudF_SWp157EsYqB3oD-gAAUhI"]
[Thu Jul 30 13:51:03.976848 2026] [security2:error] [pid 961194:tid 961406] [client 160.22.160.89:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mukasarati.com"] [uri "/xmlrpc.php"] [unique_id "amudF_SWp157EsYqB3oD-gAAUhI"]
[Thu Jul 30 13:51:04.059200 2026] [security2:error] [pid 961194:tid 961416] [client 20.52.125.110:12031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/default.php"] [unique_id "amudGPSWp157EsYqB3oD-wAAAFw"]
[Thu Jul 30 13:51:04.451882 2026] [security2:error] [pid 961194:tid 961337] [client 20.52.125.110:11492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/dropdown.php"] [unique_id "amudGPSWp157EsYqB3oECwAAAA0"]
[Thu Jul 30 13:51:04.473835 2026] [core:notice] [pid 961194:tid 961412] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:04.846357 2026] [security2:error] [pid 961194:tid 961450] [client 20.52.125.110:11988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/edit.php"] [unique_id "amudGPSWp157EsYqB3oEFgAAAH4"]
[Thu Jul 30 13:51:05.250806 2026] [security2:error] [pid 961194:tid 961335] [client 20.52.125.110:11518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/f35.php"] [unique_id "amudGfSWp157EsYqB3oEHwAAAAs"]
[Thu Jul 30 13:51:05.673631 2026] [security2:error] [pid 961194:tid 961338] [client 20.52.125.110:11491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/f7.php"] [unique_id "amudGfSWp157EsYqB3oEJgAAAA4"]
[Thu Jul 30 13:51:05.688645 2026] [security2:error] [pid 961194:tid 961430] [client 172.237.109.114:44158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudGfSWp157EsYqB3oEGgAAAGo"]
[Thu Jul 30 13:51:06.550744 2026] [security2:error] [pid 961194:tid 961445] [client 189.6.88.213:57525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudGvSWp157EsYqB3oEOQAAAHk"]
[Thu Jul 30 13:51:06.550860 2026] [security2:error] [pid 961194:tid 961445] [client 189.6.88.213:57525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudGvSWp157EsYqB3oEOQAAAHk"]
[Thu Jul 30 13:51:07.565387 2026] [security2:error] [pid 961194:tid 961346] [client 103.242.199.184:59565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudG_SWp157EsYqB3oETwAAABY"]
[Thu Jul 30 13:51:07.565491 2026] [security2:error] [pid 961194:tid 961346] [client 103.242.199.184:59565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudG_SWp157EsYqB3oETwAAABY"]
[Thu Jul 30 13:51:07.771909 2026] [security2:error] [pid 961194:tid 961369] [client 78.167.1.90:56441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudG_SWp157EsYqB3oEUwAAAC0"]
[Thu Jul 30 13:51:07.772410 2026] [security2:error] [pid 961194:tid 961369] [client 78.167.1.90:56441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudG_SWp157EsYqB3oEUwAAAC0"]
[Thu Jul 30 13:51:08.614022 2026] [security2:error] [pid 961194:tid 961335] [client 196.22.131.162:60574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amudHPSWp157EsYqB3oEXQAAAAs"], referer: http://pkf.jo
[Thu Jul 30 13:51:08.828306 2026] [security2:error] [pid 961194:tid 961340] [client 52.167.144.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amudHPSWp157EsYqB3oEYAAAABA"]
[Thu Jul 30 13:51:09.019580 2026] [security2:error] [pid 961194:tid 961226] [remote 47.128.27.91:15720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/search/Nike/page/50/"] [unique_id "amudHfSWp157EsYqB3oEcQAAQB8"]
[Thu Jul 30 13:51:09.350174 2026] [proxy:error] [pid 961194:tid 961356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:09.350241 2026] [proxy_http:error] [pid 961194:tid 961356] [client 52.4.19.39:24065] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:09.350803 2026] [proxy:error] [pid 961194:tid 961356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:09.350845 2026] [proxy_http:error] [pid 961194:tid 961356] [client 52.4.19.39:24065] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:09.377604 2026] [proxy:error] [pid 961194:tid 961395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:09.377681 2026] [proxy_http:error] [pid 961194:tid 961395] [client 52.4.19.39:13258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:09.378273 2026] [proxy:error] [pid 961194:tid 961395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:09.378319 2026] [proxy_http:error] [pid 961194:tid 961395] [client 52.4.19.39:13258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:10.041136 2026] [security2:error] [pid 961194:tid 961443] [client 181.116.200.68:25669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudHvSWp157EsYqB3oEkgAAAHc"]
[Thu Jul 30 13:51:10.041260 2026] [security2:error] [pid 961194:tid 961443] [client 181.116.200.68:25669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudHvSWp157EsYqB3oEkgAAAHc"]
[Thu Jul 30 13:51:10.510579 2026] [security2:error] [pid 961194:tid 961358] [client 52.167.144.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amudHvSWp157EsYqB3oEnwAAACI"]
[Thu Jul 30 13:51:10.969874 2026] [security2:error] [pid 961194:tid 961394] [client 172.237.109.114:32058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudHvSWp157EsYqB3oEtgAAAEY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:10.993108 2026] [security2:error] [pid 961194:tid 961416] [client 172.237.109.114:2814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudHvSWp157EsYqB3oEtwAAAFw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:10.994590 2026] [security2:error] [pid 961194:tid 961342] [client 172.237.109.114:53970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudHvSWp157EsYqB3oEuAAAABI"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:11.963912 2026] [security2:error] [pid 961194:tid 961384] [client 172.237.109.114:26290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudH_SWp157EsYqB3oEywAAADw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:11.964383 2026] [security2:error] [pid 961194:tid 961360] [client 172.237.109.114:14017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudH_SWp157EsYqB3oEzAAAACQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:11.971767 2026] [security2:error] [pid 961194:tid 961400] [client 172.237.109.114:12027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudH_SWp157EsYqB3oEzQAAAEw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:11.973272 2026] [security2:error] [pid 961194:tid 961414] [client 172.237.109.114:36087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudH_SWp157EsYqB3oEzgAAAFo"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:11.973302 2026] [security2:error] [pid 961194:tid 961346] [client 172.237.109.114:10753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudH_SWp157EsYqB3oEzwAAABY"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:11.974386 2026] [security2:error] [pid 961194:tid 961345] [client 172.237.109.114:11829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudH_SWp157EsYqB3oE0AAAABU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:11.991822 2026] [security2:error] [pid 961194:tid 961397] [client 172.237.109.114:56529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudH_SWp157EsYqB3oE0QAAAEk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:12.010091 2026] [security2:error] [pid 961194:tid 961450] [client 172.237.109.114:19422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIPSWp157EsYqB3oE1AAAAH4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:12.011364 2026] [security2:error] [pid 961194:tid 961399] [client 172.237.109.114:6546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIPSWp157EsYqB3oE1QAAAEs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:12.228168 2026] [security2:error] [pid 961194:tid 961264] [remote 57.141.0.5:27258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amudIPSWp157EsYqB3oE2gAAH0U"]
[Thu Jul 30 13:51:12.741229 2026] [security2:error] [pid 961194:tid 961347] [client 103.190.40.154:1701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudIPSWp157EsYqB3oE6AAAABc"]
[Thu Jul 30 13:51:12.741358 2026] [security2:error] [pid 961194:tid 961347] [client 103.190.40.154:1701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudIPSWp157EsYqB3oE6AAAABc"]
[Thu Jul 30 13:51:12.963170 2026] [security2:error] [pid 961194:tid 961405] [client 172.237.109.114:30737] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIPSWp157EsYqB3oE8QAAAFE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:12.963311 2026] [security2:error] [pid 961194:tid 961405] [client 172.237.109.114:30737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIPSWp157EsYqB3oE8QAAAFE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:12.969736 2026] [security2:error] [pid 961194:tid 961373] [client 172.237.109.114:48530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIPSWp157EsYqB3oE8gAAADE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:13.126633 2026] [proxy:error] [pid 961194:tid 961342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:13.126716 2026] [proxy_http:error] [pid 961194:tid 961342] [client 34.233.129.35:53881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:13.127493 2026] [proxy:error] [pid 961194:tid 961342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:13.127568 2026] [proxy_http:error] [pid 961194:tid 961342] [client 34.233.129.35:53881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:13.128163 2026] [proxy:error] [pid 961194:tid 961406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:13.128267 2026] [proxy_http:error] [pid 961194:tid 961406] [client 32.194.121.99:28562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:13.129279 2026] [proxy:error] [pid 961194:tid 961406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:51:13.129347 2026] [proxy_http:error] [pid 961194:tid 961406] [client 32.194.121.99:28562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:51:13.234911 2026] [security2:error] [pid 961194:tid 961359] [client 66.249.74.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.seven-stars-shop.com"] [uri "/index.php"] [unique_id "amudIPSWp157EsYqB3oE5QAAACM"]
[Thu Jul 30 13:51:13.646529 2026] [security2:error] [pid 961194:tid 961400] [client 18.204.152.114:42052] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/facebook-whatsapp-aquisicao-compra-fusao-app-redes-sociais-chamada-logo-logotipo-1392892993503_615x300.jpg"] [unique_id "amudIfSWp157EsYqB3oFDgAAAEw"]
[Thu Jul 30 13:51:13.793387 2026] [security2:error] [pid 961194:tid 961449] [client 213.152.187.215:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amudIfSWp157EsYqB3oFFQAAAH0"]
[Thu Jul 30 13:51:13.793491 2026] [security2:error] [pid 961194:tid 961449] [client 213.152.187.215:57712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amudIfSWp157EsYqB3oFFQAAAH0"]
[Thu Jul 30 13:51:13.971189 2026] [security2:error] [pid 961194:tid 961402] [client 172.237.109.114:18933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIfSWp157EsYqB3oFHgAAAE4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:13.993819 2026] [security2:error] [pid 961194:tid 961420] [client 172.237.109.114:65178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIfSWp157EsYqB3oFHwAAAGA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:13.993897 2026] [security2:error] [pid 961194:tid 961339] [client 172.237.109.114:17900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIfSWp157EsYqB3oFIAAAAA8"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:14.015757 2026] [security2:error] [pid 961194:tid 961391] [client 172.237.109.114:49916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIvSWp157EsYqB3oFIQAAAEM"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:14.103774 2026] [security2:error] [pid 961194:tid 961397] [client 52.167.144.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amudIfSWp157EsYqB3oFEQAAAEk"]
[Thu Jul 30 13:51:14.574787 2026] [security2:error] [pid 961194:tid 961278] [remote 42.96.35.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.35.96.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smartdatahpm.com"] [uri "/wp-login.php"] [unique_id "amudIvSWp157EsYqB3oFLQAAelM"]
[Thu Jul 30 13:51:14.964750 2026] [security2:error] [pid 961194:tid 961416] [client 172.237.109.114:47204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIvSWp157EsYqB3oFNwAAAFw"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:14.974847 2026] [security2:error] [pid 961194:tid 961441] [client 172.237.109.114:25108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudIvSWp157EsYqB3oFOAAAAHU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:15.354511 2026] [security2:error] [pid 961194:tid 961448] [client 52.167.144.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amudI_SWp157EsYqB3oFOwAAAHw"]
[Thu Jul 30 13:51:17.488861 2026] [security2:error] [pid 961194:tid 961329] [client 78.167.1.90:57240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudJfSWp157EsYqB3oFeQAAAAU"]
[Thu Jul 30 13:51:17.489413 2026] [security2:error] [pid 961194:tid 961329] [client 78.167.1.90:57240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudJfSWp157EsYqB3oFeQAAAAU"]
[Thu Jul 30 13:51:17.600081 2026] [security2:error] [pid 961194:tid 961410] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudJPSWp157EsYqB3oFaQAAAFY"]
[Thu Jul 30 13:51:18.206458 2026] [security2:error] [pid 961194:tid 961394] [client 189.6.88.213:58077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudJvSWp157EsYqB3oFigAAAEY"]
[Thu Jul 30 13:51:18.206587 2026] [security2:error] [pid 961194:tid 961394] [client 189.6.88.213:58077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudJvSWp157EsYqB3oFigAAAEY"]
[Thu Jul 30 13:51:18.213443 2026] [security2:error] [pid 961194:tid 961412] [client 103.242.199.184:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudJvSWp157EsYqB3oFiwAAAFg"]
[Thu Jul 30 13:51:18.213565 2026] [security2:error] [pid 961194:tid 961412] [client 103.242.199.184:60288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudJvSWp157EsYqB3oFiwAAAFg"]
[Thu Jul 30 13:51:18.384549 2026] [security2:error] [pid 961194:tid 961304] [remote 66.102.137.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.137.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "widedaddy.com"] [uri "/wp-login.php"] [unique_id "amudJvSWp157EsYqB3oFjwAAcW0"]
[Thu Jul 30 13:51:18.629957 2026] [security2:error] [pid 961194:tid 961351] [client 213.152.187.215:34876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amudJvSWp157EsYqB3oFlgAAABs"]
[Thu Jul 30 13:51:18.630073 2026] [security2:error] [pid 961194:tid 961351] [client 213.152.187.215:34876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amudJvSWp157EsYqB3oFlgAAABs"]
[Thu Jul 30 13:51:20.599877 2026] [security2:error] [pid 961194:tid 961329] [client 172.237.109.114:46987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudKPSWp157EsYqB3oFtwAAAAU"]
[Thu Jul 30 13:51:20.706547 2026] [security2:error] [pid 961194:tid 961349] [client 181.116.200.68:29181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudKPSWp157EsYqB3oFxQAAABk"]
[Thu Jul 30 13:51:20.706648 2026] [security2:error] [pid 961194:tid 961349] [client 181.116.200.68:29181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudKPSWp157EsYqB3oFxQAAABk"]
[Thu Jul 30 13:51:20.720178 2026] [core:notice] [pid 961194:tid 961353] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:23.388162 2026] [security2:error] [pid 961194:tid 961344] [client 103.190.40.154:24432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudK_SWp157EsYqB3oGBQAAABQ"]
[Thu Jul 30 13:51:23.388303 2026] [security2:error] [pid 961194:tid 961344] [client 103.190.40.154:24432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudK_SWp157EsYqB3oGBQAAABQ"]
[Thu Jul 30 13:51:24.657231 2026] [core:notice] [pid 961194:tid 961371] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:24.747546 2026] [security2:error] [pid 961194:tid 961355] [client 52.167.144.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amudLPSWp157EsYqB3oGHAAAAB8"]
[Thu Jul 30 13:51:25.339720 2026] [security2:error] [pid 961194:tid 961402] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudLPSWp157EsYqB3oGIwAAAE4"]
[Thu Jul 30 13:51:27.447804 2026] [security2:error] [pid 961194:tid 961443] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amudL_SWp157EsYqB3oGWgAAAHc"]
[Thu Jul 30 13:51:27.447930 2026] [security2:error] [pid 961194:tid 961443] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amudL_SWp157EsYqB3oGWgAAAHc"]
[Thu Jul 30 13:51:27.760705 2026] [security2:error] [pid 961194:tid 961358] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amudL_SWp157EsYqB3oGZAAAACI"]
[Thu Jul 30 13:51:27.760806 2026] [security2:error] [pid 961194:tid 961358] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amudL_SWp157EsYqB3oGZAAAACI"]
[Thu Jul 30 13:51:27.920432 2026] [security2:error] [pid 961194:tid 961411] [client 78.167.1.90:56962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudL_SWp157EsYqB3oGZQAAAFc"]
[Thu Jul 30 13:51:27.921173 2026] [security2:error] [pid 961194:tid 961411] [client 78.167.1.90:56962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudL_SWp157EsYqB3oGZQAAAFc"]
[Thu Jul 30 13:51:27.967484 2026] [security2:error] [pid 961194:tid 961339] [client 189.6.88.213:58551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudL_SWp157EsYqB3oGZgAAAA8"]
[Thu Jul 30 13:51:27.967597 2026] [security2:error] [pid 961194:tid 961339] [client 189.6.88.213:58551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudL_SWp157EsYqB3oGZgAAAA8"]
[Thu Jul 30 13:51:28.075577 2026] [security2:error] [pid 961194:tid 961357] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amudMPSWp157EsYqB3oGagAAACE"]
[Thu Jul 30 13:51:28.075684 2026] [security2:error] [pid 961194:tid 961357] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amudMPSWp157EsYqB3oGagAAACE"]
[Thu Jul 30 13:51:28.374609 2026] [security2:error] [pid 961194:tid 961428] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/err.php"] [unique_id "amudMPSWp157EsYqB3oGdQAAAGg"]
[Thu Jul 30 13:51:28.374724 2026] [security2:error] [pid 961194:tid 961428] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/err.php"] [unique_id "amudMPSWp157EsYqB3oGdQAAAGg"]
[Thu Jul 30 13:51:28.659271 2026] [core:notice] [pid 961194:tid 961429] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:28.679789 2026] [security2:error] [pid 961194:tid 961350] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/img.php"] [unique_id "amudMPSWp157EsYqB3oGjgAAABo"]
[Thu Jul 30 13:51:28.679901 2026] [security2:error] [pid 961194:tid 961350] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/img.php"] [unique_id "amudMPSWp157EsYqB3oGjgAAABo"]
[Thu Jul 30 13:51:28.829849 2026] [security2:error] [pid 961194:tid 961432] [client 103.242.199.184:60856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudMPSWp157EsYqB3oGjwAAAGw"]
[Thu Jul 30 13:51:28.829993 2026] [security2:error] [pid 961194:tid 961432] [client 103.242.199.184:60856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudMPSWp157EsYqB3oGjwAAAGw"]
[Thu Jul 30 13:51:28.894965 2026] [security2:error] [pid 961194:tid 961440] [client 185.191.171.12:43080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/22/governo-de-transicao-quer-finalizar-texto-da-pec-do-estouro-nesta-semana/"] [unique_id "amudMPSWp157EsYqB3oGkwAAAHQ"]
[Thu Jul 30 13:51:28.895091 2026] [security2:error] [pid 961194:tid 961440] [client 185.191.171.12:43080] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/22/governo-de-transicao-quer-finalizar-texto-da-pec-do-estouro-nesta-semana/"] [unique_id "amudMPSWp157EsYqB3oGkwAAAHQ"]
[Thu Jul 30 13:51:29.002750 2026] [security2:error] [pid 961194:tid 961343] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/aa.php"] [unique_id "amudMfSWp157EsYqB3oGlAAAABM"]
[Thu Jul 30 13:51:29.002890 2026] [security2:error] [pid 961194:tid 961343] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/aa.php"] [unique_id "amudMfSWp157EsYqB3oGlAAAABM"]
[Thu Jul 30 13:51:29.258829 2026] [security2:error] [pid 961194:tid 961368] [client 100.28.122.93:43390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGhAAAACw"]
[Thu Jul 30 13:51:29.266965 2026] [security2:error] [pid 961194:tid 961342] [client 100.28.122.93:43424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGdwAAABI"]
[Thu Jul 30 13:51:29.289211 2026] [security2:error] [pid 961194:tid 961408] [client 100.28.122.93:43434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGfgAAAFQ"]
[Thu Jul 30 13:51:29.298795 2026] [security2:error] [pid 961194:tid 961388] [client 100.28.122.93:43426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGhwAAAEA"]
[Thu Jul 30 13:51:29.318736 2026] [security2:error] [pid 961194:tid 961439] [client 100.28.122.93:43412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGiwAAAHM"]
[Thu Jul 30 13:51:29.321697 2026] [security2:error] [pid 961194:tid 961361] [client 100.28.122.93:43498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGfAAAACU"]
[Thu Jul 30 13:51:29.324270 2026] [security2:error] [pid 961194:tid 961346] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/av.php"] [unique_id "amudMfSWp157EsYqB3oGngAAABY"]
[Thu Jul 30 13:51:29.324389 2026] [security2:error] [pid 961194:tid 961346] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/av.php"] [unique_id "amudMfSWp157EsYqB3oGngAAABY"]
[Thu Jul 30 13:51:29.343643 2026] [security2:error] [pid 961194:tid 961425] [client 100.28.122.93:43466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGegAAAGU"]
[Thu Jul 30 13:51:29.404376 2026] [security2:error] [pid 961194:tid 961352] [client 100.28.122.93:43472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGewAAABw"]
[Thu Jul 30 13:51:29.421680 2026] [security2:error] [pid 961194:tid 961406] [client 100.28.122.93:43452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGeAAAAFI"]
[Thu Jul 30 13:51:29.460605 2026] [security2:error] [pid 961194:tid 961393] [client 85.208.98.24:37848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/01/15/tjpb-condena-energisa-a-indenizar-consumidor-em-r-20-mil-por-demora-na-instalacao-de-energia/"] [unique_id "amudMfSWp157EsYqB3oGogAAAEU"]
[Thu Jul 30 13:51:29.460723 2026] [security2:error] [pid 961194:tid 961393] [client 85.208.98.24:37848] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/01/15/tjpb-condena-energisa-a-indenizar-consumidor-em-r-20-mil-por-demora-na-instalacao-de-energia/"] [unique_id "amudMfSWp157EsYqB3oGogAAAEU"]
[Thu Jul 30 13:51:29.643253 2026] [security2:error] [pid 961194:tid 961328] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/xa.php"] [unique_id "amudMfSWp157EsYqB3oGpwAAAAQ"]
[Thu Jul 30 13:51:29.643353 2026] [security2:error] [pid 961194:tid 961328] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/xa.php"] [unique_id "amudMfSWp157EsYqB3oGpwAAAAQ"]
[Thu Jul 30 13:51:29.976899 2026] [security2:error] [pid 961194:tid 961345] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/media.php"] [unique_id "amudMfSWp157EsYqB3oGrgAAABU"]
[Thu Jul 30 13:51:29.977030 2026] [security2:error] [pid 961194:tid 961345] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/media.php"] [unique_id "amudMfSWp157EsYqB3oGrgAAABU"]
[Thu Jul 30 13:51:30.233725 2026] [security2:error] [pid 961194:tid 961414] [client 100.28.122.93:43480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGiQAAAFo"]
[Thu Jul 30 13:51:30.234652 2026] [security2:error] [pid 961194:tid 961347] [client 100.28.122.93:43428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGfQAAABc"]
[Thu Jul 30 13:51:30.237619 2026] [security2:error] [pid 961194:tid 961442] [client 100.28.122.93:43444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGiAAAAHY"]
[Thu Jul 30 13:51:30.240840 2026] [security2:error] [pid 961194:tid 961333] [client 100.28.122.93:43460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGigAAAAk"]
[Thu Jul 30 13:51:30.242097 2026] [security2:error] [pid 961194:tid 961365] [client 100.28.122.93:43492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGgwAAACk"]
[Thu Jul 30 13:51:30.272618 2026] [security2:error] [pid 961194:tid 961327] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/images.php"] [unique_id "amudMvSWp157EsYqB3oGtQAAAAM"]
[Thu Jul 30 13:51:30.272744 2026] [security2:error] [pid 961194:tid 961327] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/images.php"] [unique_id "amudMvSWp157EsYqB3oGtQAAAAM"]
[Thu Jul 30 13:51:30.323455 2026] [security2:error] [pid 961194:tid 961405] [client 100.28.122.93:43400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amudMPSWp157EsYqB3oGeQAAAFE"]
[Thu Jul 30 13:51:30.589922 2026] [security2:error] [pid 961194:tid 961338] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/gecko.php"] [unique_id "amudMvSWp157EsYqB3oGuQAAAA4"]
[Thu Jul 30 13:51:30.590045 2026] [security2:error] [pid 961194:tid 961338] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/gecko.php"] [unique_id "amudMvSWp157EsYqB3oGuQAAAA4"]
[Thu Jul 30 13:51:30.827090 2026] [security2:error] [pid 961194:tid 961276] [remote 184.168.126.180:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koriusa.info"] [uri "/wp-login.php"] [unique_id "amudMvSWp157EsYqB3oGwQAACFE"]
[Thu Jul 30 13:51:30.895952 2026] [security2:error] [pid 961194:tid 961369] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/82.php"] [unique_id "amudMvSWp157EsYqB3oGxQAAAC0"]
[Thu Jul 30 13:51:30.896108 2026] [security2:error] [pid 961194:tid 961369] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/82.php"] [unique_id "amudMvSWp157EsYqB3oGxQAAAC0"]
[Thu Jul 30 13:51:30.962601 2026] [security2:error] [pid 961194:tid 961329] [client 172.237.109.114:21559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudMvSWp157EsYqB3oGxgAAAAU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:30.963308 2026] [security2:error] [pid 961194:tid 961344] [client 172.237.109.114:18362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudMvSWp157EsYqB3oGxwAAABQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:30.972732 2026] [security2:error] [pid 961194:tid 961450] [client 172.237.109.114:4797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudMvSWp157EsYqB3oGyAAAAH4"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:31.199578 2026] [security2:error] [pid 961194:tid 961404] [client 181.116.200.68:29114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudM_SWp157EsYqB3oGzwAAAFA"]
[Thu Jul 30 13:51:31.199684 2026] [security2:error] [pid 961194:tid 961404] [client 181.116.200.68:29114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudM_SWp157EsYqB3oGzwAAAFA"]
[Thu Jul 30 13:51:31.207827 2026] [security2:error] [pid 961194:tid 961342] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/xstelth.php"] [unique_id "amudM_SWp157EsYqB3oG0AAAABI"]
[Thu Jul 30 13:51:31.207908 2026] [security2:error] [pid 961194:tid 961342] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/xstelth.php"] [unique_id "amudM_SWp157EsYqB3oG0AAAABI"]
[Thu Jul 30 13:51:31.796726 2026] [core:notice] [pid 961194:tid 961400] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:31.964325 2026] [security2:error] [pid 961194:tid 961443] [client 172.237.109.114:61980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudM_SWp157EsYqB3oG4QAAAHc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:31.964443 2026] [security2:error] [pid 961194:tid 961443] [client 172.237.109.114:61980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudM_SWp157EsYqB3oG4QAAAHc"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:31.969057 2026] [security2:error] [pid 961194:tid 961409] [client 172.237.109.114:15509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudM_SWp157EsYqB3oG4gAAAFU"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:31.973422 2026] [security2:error] [pid 961194:tid 961335] [client 172.237.109.114:43610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudM_SWp157EsYqB3oG4wAAAAs"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:31.974094 2026] [security2:error] [pid 961194:tid 961420] [client 172.237.109.114:33592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudM_SWp157EsYqB3oG5AAAAGA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:31.978777 2026] [security2:error] [pid 961194:tid 961436] [client 172.237.109.114:53736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudM_SWp157EsYqB3oG5QAAAHA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:31.980142 2026] [security2:error] [pid 961194:tid 961417] [client 172.237.109.114:40950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudM_SWp157EsYqB3oG5gAAAF0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:31.993129 2026] [security2:error] [pid 961194:tid 961376] [client 172.237.109.114:25690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudM_SWp157EsYqB3oG5wAAADQ"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:31.993504 2026] [security2:error] [pid 961194:tid 961337] [client 172.237.109.114:45928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudM_SWp157EsYqB3oG6AAAAA0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:32.010653 2026] [security2:error] [pid 961194:tid 961324] [client 172.237.109.114:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudNPSWp157EsYqB3oG6wAAAAA"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:32.969949 2026] [security2:error] [pid 961194:tid 961429] [client 172.237.109.114:58206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudNPSWp157EsYqB3oHAAAAAGk"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:33.011782 2026] [security2:error] [pid 961194:tid 961380] [client 172.237.109.114:50761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudNfSWp157EsYqB3oHAQAAADg"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:33.145273 2026] [security2:error] [pid 961194:tid 961402] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/xp.php"] [unique_id "amudNfSWp157EsYqB3oHBwAAAE4"]
[Thu Jul 30 13:51:33.145371 2026] [security2:error] [pid 961194:tid 961402] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/xp.php"] [unique_id "amudNfSWp157EsYqB3oHBwAAAE4"]
[Thu Jul 30 13:51:33.474849 2026] [security2:error] [pid 961194:tid 961444] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/admin.php"] [unique_id "amudNfSWp157EsYqB3oHDgAAAHg"]
[Thu Jul 30 13:51:33.474961 2026] [security2:error] [pid 961194:tid 961444] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/admin.php"] [unique_id "amudNfSWp157EsYqB3oHDgAAAHg"]
[Thu Jul 30 13:51:33.796420 2026] [security2:error] [pid 961194:tid 961346] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/adminner.php"] [unique_id "amudNfSWp157EsYqB3oHFQAAABY"]
[Thu Jul 30 13:51:33.796530 2026] [security2:error] [pid 961194:tid 961346] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/adminner.php"] [unique_id "amudNfSWp157EsYqB3oHFQAAABY"]
[Thu Jul 30 13:51:33.992764 2026] [security2:error] [pid 961194:tid 961353] [client 172.237.109.114:38713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudNfSWp157EsYqB3oHGQAAAB0"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:34.010865 2026] [security2:error] [pid 961194:tid 961437] [client 172.237.109.114:22240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amudNvSWp157EsYqB3oHGgAAAHE"], referer: http://alseermarine.com:80
[Thu Jul 30 13:51:34.066959 2026] [security2:error] [pid 961194:tid 961388] [client 103.190.40.154:22584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudNvSWp157EsYqB3oHGwAAAEA"]
[Thu Jul 30 13:51:34.067117 2026] [security2:error] [pid 961194:tid 961388] [client 103.190.40.154:22584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudNvSWp157EsYqB3oHGwAAAEA"]
[Thu Jul 30 13:51:34.140566 2026] [security2:error] [pid 961194:tid 961398] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/a.php"] [unique_id "amudNvSWp157EsYqB3oHHwAAAEo"]
[Thu Jul 30 13:51:34.140710 2026] [security2:error] [pid 961194:tid 961398] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/a.php"] [unique_id "amudNvSWp157EsYqB3oHHwAAAEo"]
[Thu Jul 30 13:51:34.474692 2026] [security2:error] [pid 961194:tid 961351] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/k.php"] [unique_id "amudNvSWp157EsYqB3oHIwAAABs"]
[Thu Jul 30 13:51:34.474818 2026] [security2:error] [pid 961194:tid 961351] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/k.php"] [unique_id "amudNvSWp157EsYqB3oHIwAAABs"]
[Thu Jul 30 13:51:34.805943 2026] [security2:error] [pid 961194:tid 961391] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/222.php"] [unique_id "amudNvSWp157EsYqB3oHLgAAAEM"]
[Thu Jul 30 13:51:34.806089 2026] [security2:error] [pid 961194:tid 961391] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/222.php"] [unique_id "amudNvSWp157EsYqB3oHLgAAAEM"]
[Thu Jul 30 13:51:35.140458 2026] [security2:error] [pid 961194:tid 961365] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/mac.php"] [unique_id "amudN_SWp157EsYqB3oHMwAAACk"]
[Thu Jul 30 13:51:35.140579 2026] [security2:error] [pid 961194:tid 961365] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/mac.php"] [unique_id "amudN_SWp157EsYqB3oHMwAAACk"]
[Thu Jul 30 13:51:35.480094 2026] [security2:error] [pid 961194:tid 961362] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/cgi-sys/404.html"] [unique_id "amudN_SWp157EsYqB3oHPgAAACY"]
[Thu Jul 30 13:51:35.507695 2026] [security2:error] [pid 961194:tid 961451] [client 172.237.109.114:35466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudN_SWp157EsYqB3oHLwAAAH8"], referer: alseermarine.com:80/MUP
[Thu Jul 30 13:51:35.797292 2026] [security2:error] [pid 961194:tid 961429] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/cgi-sys/404.html"] [unique_id "amudN_SWp157EsYqB3oHRwAAAGk"]
[Thu Jul 30 13:51:35.962927 2026] [security2:error] [pid 961194:tid 961448] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/ops.php"] [unique_id "amudN_SWp157EsYqB3oHSwAAAHw"]
[Thu Jul 30 13:51:35.963088 2026] [security2:error] [pid 961194:tid 961448] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/ops.php"] [unique_id "amudN_SWp157EsYqB3oHSwAAAHw"]
[Thu Jul 30 13:51:36.140631 2026] [security2:error] [pid 961194:tid 961419] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/8.php"] [unique_id "amudOPSWp157EsYqB3oHUgAAAF8"]
[Thu Jul 30 13:51:36.140743 2026] [security2:error] [pid 961194:tid 961419] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/8.php"] [unique_id "amudOPSWp157EsYqB3oHUgAAAF8"]
[Thu Jul 30 13:51:36.449389 2026] [security2:error] [pid 961194:tid 961388] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/FWAZ.php"] [unique_id "amudOPSWp157EsYqB3oHXwAAAEA"]
[Thu Jul 30 13:51:36.449499 2026] [security2:error] [pid 961194:tid 961388] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/FWAZ.php"] [unique_id "amudOPSWp157EsYqB3oHXwAAAEA"]
[Thu Jul 30 13:51:36.757786 2026] [security2:error] [pid 961194:tid 961383] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/biufile.php"] [unique_id "amudOPSWp157EsYqB3oHZQAAADs"]
[Thu Jul 30 13:51:36.757898 2026] [security2:error] [pid 961194:tid 961383] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/biufile.php"] [unique_id "amudOPSWp157EsYqB3oHZQAAADs"]
[Thu Jul 30 13:51:37.083508 2026] [security2:error] [pid 961194:tid 961355] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/coffexium.php"] [unique_id "amudOfSWp157EsYqB3oHbgAAAB8"]
[Thu Jul 30 13:51:37.083647 2026] [security2:error] [pid 961194:tid 961355] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/coffexium.php"] [unique_id "amudOfSWp157EsYqB3oHbgAAAB8"]
[Thu Jul 30 13:51:37.407354 2026] [security2:error] [pid 961194:tid 961424] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/simple.php"] [unique_id "amudOfSWp157EsYqB3oHeAAAAGQ"]
[Thu Jul 30 13:51:37.407465 2026] [security2:error] [pid 961194:tid 961424] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/simple.php"] [unique_id "amudOfSWp157EsYqB3oHeAAAAGQ"]
[Thu Jul 30 13:51:37.739289 2026] [security2:error] [pid 961194:tid 961428] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/fpwch.php"] [unique_id "amudOfSWp157EsYqB3oHfwAAAGg"]
[Thu Jul 30 13:51:37.739380 2026] [security2:error] [pid 961194:tid 961428] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/fpwch.php"] [unique_id "amudOfSWp157EsYqB3oHfwAAAGg"]
[Thu Jul 30 13:51:38.067796 2026] [security2:error] [pid 961194:tid 961427] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/dex.php"] [unique_id "amudOvSWp157EsYqB3oHhgAAAGc"]
[Thu Jul 30 13:51:38.067935 2026] [security2:error] [pid 961194:tid 961427] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/dex.php"] [unique_id "amudOvSWp157EsYqB3oHhgAAAGc"]
[Thu Jul 30 13:51:38.173495 2026] [core:notice] [pid 961194:tid 961363] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:38.233812 2026] [core:error] [pid 961194:tid 961220] (36)File name too long: [remote 104.200.74.95:35230] AH00036: access to /&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;39&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N/A&quot;,&quot;display_price&quot;:199,&quot;display_regular_price&quot;:199,&quot;image&quot;:{&quot;title&quot;:&quot;e2fb19b8-scaled-1.jpg&quot;,&quot;caption&quot;:&quot;&quot;,&quot;url&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/07/e2fb19b8-scaled-1.jpg&quot;,&quot;alt&quot;:&quot;e2fb19b8-scaled-1.jpg&quot;,&quot;src&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/07/e2fb19b8-scaled-1-600x400.jpg&quot;,&quot;srcset&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/07/e2fb19b8-scaled-1-600x400.jpg failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;39&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N'), referer: https://kicksity.com/product/nike-air-jordan-1-low-se-light-steel-grey-2/
[Thu Jul 30 13:51:38.396893 2026] [security2:error] [pid 961194:tid 961343] [client 20.100.203.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/1.php"] [unique_id "amudOvSWp157EsYqB3oHjwAAABM"]
[Thu Jul 30 13:51:38.397031 2026] [security2:error] [pid 961194:tid 961343] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/1.php"] [unique_id "amudOvSWp157EsYqB3oHjwAAABM"]
[Thu Jul 30 13:51:38.397155 2026] [security2:error] [pid 961194:tid 961343] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/1.php"] [unique_id "amudOvSWp157EsYqB3oHjwAAABM"]
[Thu Jul 30 13:51:38.480867 2026] [security2:error] [pid 961194:tid 961448] [client 78.167.1.90:53670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudOvSWp157EsYqB3oHkwAAAHw"]
[Thu Jul 30 13:51:38.481352 2026] [security2:error] [pid 961194:tid 961448] [client 78.167.1.90:53670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudOvSWp157EsYqB3oHkwAAAHw"]
[Thu Jul 30 13:51:38.617216 2026] [security2:error] [pid 961194:tid 961432] [client 189.6.88.213:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudOvSWp157EsYqB3oHlAAAAGw"]
[Thu Jul 30 13:51:38.617337 2026] [security2:error] [pid 961194:tid 961432] [client 189.6.88.213:59061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudOvSWp157EsYqB3oHlAAAAGw"]
[Thu Jul 30 13:51:38.715947 2026] [security2:error] [pid 961194:tid 961450] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/cgi-sys/404.html"] [unique_id "amudOvSWp157EsYqB3oHlQAAAH4"]
[Thu Jul 30 13:51:38.887775 2026] [security2:error] [pid 961194:tid 961444] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/config.json.php"] [unique_id "amudOvSWp157EsYqB3oHmQAAAHg"]
[Thu Jul 30 13:51:38.887910 2026] [security2:error] [pid 961194:tid 961444] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/config.json.php"] [unique_id "amudOvSWp157EsYqB3oHmQAAAHg"]
[Thu Jul 30 13:51:39.187836 2026] [security2:error] [pid 961194:tid 961370] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/k2.php"] [unique_id "amudO_SWp157EsYqB3oHoAAAAC4"]
[Thu Jul 30 13:51:39.187952 2026] [security2:error] [pid 961194:tid 961370] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/k2.php"] [unique_id "amudO_SWp157EsYqB3oHoAAAAC4"]
[Thu Jul 30 13:51:39.458670 2026] [security2:error] [pid 961194:tid 961415] [client 103.242.199.184:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudO_SWp157EsYqB3oHpwAAAFs"]
[Thu Jul 30 13:51:39.458787 2026] [security2:error] [pid 961194:tid 961415] [client 103.242.199.184:61426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudO_SWp157EsYqB3oHpwAAAFs"]
[Thu Jul 30 13:51:39.488397 2026] [security2:error] [pid 961194:tid 961418] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/raw.php"] [unique_id "amudO_SWp157EsYqB3oHqAAAAF4"]
[Thu Jul 30 13:51:39.488487 2026] [security2:error] [pid 961194:tid 961418] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/raw.php"] [unique_id "amudO_SWp157EsYqB3oHqAAAAF4"]
[Thu Jul 30 13:51:39.815856 2026] [security2:error] [pid 961194:tid 961358] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/wp.php"] [unique_id "amudO_SWp157EsYqB3oHsAAAACI"]
[Thu Jul 30 13:51:39.815945 2026] [security2:error] [pid 961194:tid 961358] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/wp.php"] [unique_id "amudO_SWp157EsYqB3oHsAAAACI"]
[Thu Jul 30 13:51:40.122105 2026] [security2:error] [pid 961194:tid 961333] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/fffm.php"] [unique_id "amudPPSWp157EsYqB3oHuAAAAAk"]
[Thu Jul 30 13:51:40.122217 2026] [security2:error] [pid 961194:tid 961333] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/fffm.php"] [unique_id "amudPPSWp157EsYqB3oHuAAAAAk"]
[Thu Jul 30 13:51:40.440401 2026] [security2:error] [pid 961194:tid 961327] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/111.php"] [unique_id "amudPPSWp157EsYqB3oHvgAAAAM"]
[Thu Jul 30 13:51:40.440531 2026] [security2:error] [pid 961194:tid 961327] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/111.php"] [unique_id "amudPPSWp157EsYqB3oHvgAAAAM"]
[Thu Jul 30 13:51:40.585553 2026] [security2:error] [pid 961194:tid 961377] [client 172.237.109.114:63443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudPPSWp157EsYqB3oHtQAAADU"]
[Thu Jul 30 13:51:40.764668 2026] [security2:error] [pid 961194:tid 961359] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/cgi-sys/404.html"] [unique_id "amudPPSWp157EsYqB3oHxQAAACM"]
[Thu Jul 30 13:51:40.945324 2026] [security2:error] [pid 961194:tid 961326] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/ws.php"] [unique_id "amudPPSWp157EsYqB3oHyQAAAAI"]
[Thu Jul 30 13:51:40.945472 2026] [security2:error] [pid 961194:tid 961326] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/ws.php"] [unique_id "amudPPSWp157EsYqB3oHyQAAAAI"]
[Thu Jul 30 13:51:41.250134 2026] [security2:error] [pid 961194:tid 961413] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/coffee.php"] [unique_id "amudPfSWp157EsYqB3oH1gAAAFk"]
[Thu Jul 30 13:51:41.250232 2026] [security2:error] [pid 961194:tid 961413] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/coffee.php"] [unique_id "amudPfSWp157EsYqB3oH1gAAAFk"]
[Thu Jul 30 13:51:41.572902 2026] [security2:error] [pid 961194:tid 961368] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/goods.php"] [unique_id "amudPfSWp157EsYqB3oH3gAAACw"]
[Thu Jul 30 13:51:41.573013 2026] [security2:error] [pid 961194:tid 961368] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/goods.php"] [unique_id "amudPfSWp157EsYqB3oH3gAAACw"]
[Thu Jul 30 13:51:41.713154 2026] [security2:error] [pid 961194:tid 961439] [client 181.116.200.68:55730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudPfSWp157EsYqB3oH5QAAAHM"]
[Thu Jul 30 13:51:41.713286 2026] [security2:error] [pid 961194:tid 961439] [client 181.116.200.68:55730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudPfSWp157EsYqB3oH5QAAAHM"]
[Thu Jul 30 13:51:41.910702 2026] [security2:error] [pid 961194:tid 961378] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/about.php"] [unique_id "amudPfSWp157EsYqB3oH6QAAADY"]
[Thu Jul 30 13:51:41.910801 2026] [security2:error] [pid 961194:tid 961378] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/about.php"] [unique_id "amudPfSWp157EsYqB3oH6QAAADY"]
[Thu Jul 30 13:51:42.214042 2026] [security2:error] [pid 961194:tid 961414] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/about.php"] [unique_id "amudPvSWp157EsYqB3oH8gAAAFo"]
[Thu Jul 30 13:51:42.214160 2026] [security2:error] [pid 961194:tid 961414] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/about.php"] [unique_id "amudPvSWp157EsYqB3oH8gAAAFo"]
[Thu Jul 30 13:51:42.263256 2026] [security2:error] [pid 961194:tid 961390] [client 172.237.109.114:3987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudPfSWp157EsYqB3oH6gAAAEI"]
[Thu Jul 30 13:51:42.532063 2026] [security2:error] [pid 961194:tid 961382] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/admin.php"] [unique_id "amudPvSWp157EsYqB3oH-gAAADo"]
[Thu Jul 30 13:51:42.532181 2026] [security2:error] [pid 961194:tid 961382] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/admin.php"] [unique_id "amudPvSWp157EsYqB3oH-gAAADo"]
[Thu Jul 30 13:51:42.820637 2026] [core:error] [pid 961194:tid 961326] [client 74.7.244.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:51:42.820668 2026] [core:error] [pid 961194:tid 961326] [client 74.7.244.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:51:42.820861 2026] [security2:error] [pid 961194:tid 961326] [client 74.7.244.53:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.santaclaraimports.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amudPvSWp157EsYqB3oIAwAAAAI"]
[Thu Jul 30 13:51:42.822441 2026] [security2:error] [pid 961194:tid 961379] [client 74.7.244.53:36224] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.santaclaraimports.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amudPvSWp157EsYqB3oIAQAANyE"]
[Thu Jul 30 13:51:42.849171 2026] [security2:error] [pid 961194:tid 961329] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/inputs.php"] [unique_id "amudPvSWp157EsYqB3oIBAAAAAU"]
[Thu Jul 30 13:51:42.849271 2026] [security2:error] [pid 961194:tid 961329] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/inputs.php"] [unique_id "amudPvSWp157EsYqB3oIBAAAAAU"]
[Thu Jul 30 13:51:43.143389 2026] [security2:error] [pid 961194:tid 961434] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/inputs.php"] [unique_id "amudP_SWp157EsYqB3oIDgAAAG4"]
[Thu Jul 30 13:51:43.143480 2026] [security2:error] [pid 961194:tid 961434] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/inputs.php"] [unique_id "amudP_SWp157EsYqB3oIDgAAAG4"]
[Thu Jul 30 13:51:43.461506 2026] [security2:error] [pid 961194:tid 961404] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/adminfuns.php"] [unique_id "amudP_SWp157EsYqB3oIFQAAAFA"]
[Thu Jul 30 13:51:43.461620 2026] [security2:error] [pid 961194:tid 961404] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/adminfuns.php"] [unique_id "amudP_SWp157EsYqB3oIFQAAAFA"]
[Thu Jul 30 13:51:43.786591 2026] [security2:error] [pid 961194:tid 961353] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/404.php"] [unique_id "amudP_SWp157EsYqB3oIIAAAAB0"]
[Thu Jul 30 13:51:43.786695 2026] [security2:error] [pid 961194:tid 961353] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/404.php"] [unique_id "amudP_SWp157EsYqB3oIIAAAAB0"]
[Thu Jul 30 13:51:44.101008 2026] [security2:error] [pid 961194:tid 961409] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/xxx.php"] [unique_id "amudQPSWp157EsYqB3oIKAAAAFU"]
[Thu Jul 30 13:51:44.101126 2026] [security2:error] [pid 961194:tid 961409] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/xxx.php"] [unique_id "amudQPSWp157EsYqB3oIKAAAAFU"]
[Thu Jul 30 13:51:44.193646 2026] [security2:error] [pid 961194:tid 961352] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudP_SWp157EsYqB3oIGAAAABw"]
[Thu Jul 30 13:51:44.394650 2026] [security2:error] [pid 961194:tid 961439] [client 172.237.109.114:34426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudQPSWp157EsYqB3oIJwAAAHM"]
[Thu Jul 30 13:51:44.427284 2026] [security2:error] [pid 961194:tid 961371] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/classwithtostring.php"] [unique_id "amudQPSWp157EsYqB3oIMgAAAC8"]
[Thu Jul 30 13:51:44.427436 2026] [security2:error] [pid 961194:tid 961371] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/classwithtostring.php"] [unique_id "amudQPSWp157EsYqB3oIMgAAAC8"]
[Thu Jul 30 13:51:44.748255 2026] [security2:error] [pid 961194:tid 961391] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/234ff.php"] [unique_id "amudQPSWp157EsYqB3oIOQAAAEM"]
[Thu Jul 30 13:51:44.748361 2026] [security2:error] [pid 961194:tid 961391] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/234ff.php"] [unique_id "amudQPSWp157EsYqB3oIOQAAAEM"]
[Thu Jul 30 13:51:44.794256 2026] [security2:error] [pid 961194:tid 961335] [client 103.190.40.154:21690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudQPSWp157EsYqB3oIOgAAAAs"]
[Thu Jul 30 13:51:44.794397 2026] [security2:error] [pid 961194:tid 961335] [client 103.190.40.154:21690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudQPSWp157EsYqB3oIOgAAAAs"]
[Thu Jul 30 13:51:44.854778 2026] [security2:error] [pid 961194:tid 961345] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudQPSWp157EsYqB3oILgAAABU"]
[Thu Jul 30 13:51:45.081044 2026] [security2:error] [pid 961194:tid 961405] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/133.php"] [unique_id "amudQfSWp157EsYqB3oIQgAAAFE"]
[Thu Jul 30 13:51:45.081208 2026] [security2:error] [pid 961194:tid 961405] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/133.php"] [unique_id "amudQfSWp157EsYqB3oIQgAAAFE"]
[Thu Jul 30 13:51:45.163507 2026] [core:notice] [pid 961194:tid 961314] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:45.164740 2026] [security2:error] [pid 961194:tid 961258] [remote 68.183.43.38:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.43.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.spececigarette.com"] [uri "/wp-login.php"] [unique_id "amudQfSWp157EsYqB3oIRQAAFj8"]
[Thu Jul 30 13:51:45.308565 2026] [core:notice] [pid 961194:tid 961396] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:45.384650 2026] [security2:error] [pid 961194:tid 961344] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/wp-ws68.php"] [unique_id "amudQfSWp157EsYqB3oIUQAAABQ"]
[Thu Jul 30 13:51:45.384760 2026] [security2:error] [pid 961194:tid 961344] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/wp-ws68.php"] [unique_id "amudQfSWp157EsYqB3oIUQAAABQ"]
[Thu Jul 30 13:51:45.631296 2026] [security2:error] [pid 961194:tid 961270] [remote 57.141.0.62:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amudQfSWp157EsYqB3oIVwAAOUs"]
[Thu Jul 30 13:51:45.690291 2026] [security2:error] [pid 961194:tid 961342] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/mgrr.php"] [unique_id "amudQfSWp157EsYqB3oIWQAAABI"]
[Thu Jul 30 13:51:45.690412 2026] [security2:error] [pid 961194:tid 961342] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/mgrr.php"] [unique_id "amudQfSWp157EsYqB3oIWQAAABI"]
[Thu Jul 30 13:51:45.856676 2026] [security2:error] [pid 961194:tid 961425] [client 142.132.180.39:55510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amudQfSWp157EsYqB3oIXAAAAGU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:51:46.017768 2026] [security2:error] [pid 961194:tid 961374] [client 20.100.203.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.203.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/55.php"] [unique_id "amudQvSWp157EsYqB3oIYAAAADI"]
[Thu Jul 30 13:51:46.017891 2026] [security2:error] [pid 961194:tid 961374] [client 20.100.203.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dl.truckersofeuropes3mod.com"] [uri "/55.php"] [unique_id "amudQvSWp157EsYqB3oIYAAAADI"]
[Thu Jul 30 13:51:46.293161 2026] [core:notice] [pid 961194:tid 961355] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:46.454458 2026] [core:notice] [pid 961194:tid 961411] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:46.459757 2026] [security2:error] [pid 961194:tid 961411] [client 142.132.180.39:55512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amudQvSWp157EsYqB3oIcgAAAFc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:51:47.094373 2026] [security2:error] [pid 961194:tid 961326] [client 142.132.180.39:55514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amudQ_SWp157EsYqB3oIggAAAAI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:51:47.361780 2026] [core:notice] [pid 961194:tid 961285] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:48.607960 2026] [core:notice] [pid 961194:tid 961376] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:48.950235 2026] [core:notice] [pid 961194:tid 961296] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:49.080709 2026] [core:notice] [pid 961194:tid 961430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:49.129450 2026] [security2:error] [pid 961194:tid 961327] [client 78.167.1.90:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudRfSWp157EsYqB3oIsAAAAAM"]
[Thu Jul 30 13:51:49.129931 2026] [security2:error] [pid 961194:tid 961327] [client 78.167.1.90:54632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudRfSWp157EsYqB3oIsAAAAAM"]
[Thu Jul 30 13:51:49.234021 2026] [security2:error] [pid 961194:tid 961355] [client 189.6.88.213:59567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudRfSWp157EsYqB3oIswAAAB8"]
[Thu Jul 30 13:51:49.234154 2026] [security2:error] [pid 961194:tid 961355] [client 189.6.88.213:59567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudRfSWp157EsYqB3oIswAAAB8"]
[Thu Jul 30 13:51:49.633060 2026] [core:notice] [pid 961194:tid 961310] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:50.151140 2026] [security2:error] [pid 961194:tid 961402] [client 103.242.199.184:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudRvSWp157EsYqB3oIyQAAAE4"]
[Thu Jul 30 13:51:50.151858 2026] [security2:error] [pid 961194:tid 961402] [client 103.242.199.184:61997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudRvSWp157EsYqB3oIyQAAAE4"]
[Thu Jul 30 13:51:50.216368 2026] [security2:error] [pid 961194:tid 961325] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudRfSWp157EsYqB3oIuAAAAWA"]
[Thu Jul 30 13:51:50.369239 2026] [core:notice] [pid 961194:tid 961313] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:50.377138 2026] [core:notice] [pid 961194:tid 961305] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:50.643940 2026] [core:notice] [pid 961194:tid 961319] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:50.660433 2026] [core:notice] [pid 961194:tid 961198] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:51.279837 2026] [security2:error] [pid 961194:tid 961377] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudRvSWp157EsYqB3oIzgAANWk"]
[Thu Jul 30 13:51:51.612242 2026] [security2:error] [pid 961194:tid 961340] [client 89.238.167.134:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amudR_SWp157EsYqB3oI6QAAABA"]
[Thu Jul 30 13:51:51.612337 2026] [security2:error] [pid 961194:tid 961340] [client 89.238.167.134:50814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amudR_SWp157EsYqB3oI6QAAABA"]
[Thu Jul 30 13:51:52.262435 2026] [security2:error] [pid 961194:tid 961363] [client 181.116.200.68:9245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudSPSWp157EsYqB3oI_AAAACc"]
[Thu Jul 30 13:51:52.262557 2026] [security2:error] [pid 961194:tid 961363] [client 181.116.200.68:9245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudSPSWp157EsYqB3oI_AAAACc"]
[Thu Jul 30 13:51:53.793484 2026] [core:notice] [pid 961194:tid 961397] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:54.068126 2026] [core:notice] [pid 961194:tid 961345] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:54.301708 2026] [security2:error] [pid 961194:tid 961328] [client 74.7.230.12:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.heiakujawir.com"] [uri "/robots.txt"] [unique_id "amudSvSWp157EsYqB3oJLwAABBs"]
[Thu Jul 30 13:51:54.435619 2026] [core:notice] [pid 961194:tid 961382] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:54.474913 2026] [security2:error] [pid 961194:tid 961340] [client 43.159.35.188:38128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.35.159.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/job.php"] [unique_id "amudSvSWp157EsYqB3oJLAAAABA"]
[Thu Jul 30 13:51:54.528921 2026] [core:notice] [pid 961194:tid 961396] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:51:55.368266 2026] [security2:error] [pid 961194:tid 961443] [client 74.7.241.140:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-9a905efa.jst.nyx.temporary.site"] [uri "/index.php"] [unique_id "amudSfSWp157EsYqB3oJGQAAAHc"]
[Thu Jul 30 13:51:55.369149 2026] [security2:error] [pid 961194:tid 961407] [client 74.7.241.140:48652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-9a905efa.jst.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amudSfSWp157EsYqB3oJFwAAU38"]
[Thu Jul 30 13:51:55.514426 2026] [security2:error] [pid 961194:tid 961334] [client 103.190.40.154:22576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudS_SWp157EsYqB3oJTQAAAAo"]
[Thu Jul 30 13:51:55.514551 2026] [security2:error] [pid 961194:tid 961334] [client 103.190.40.154:22576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudS_SWp157EsYqB3oJTQAAAAo"]
[Thu Jul 30 13:51:56.701320 2026] [security2:error] [pid 961194:tid 961439] [client 198.20.67.202:34310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "jesus.claims"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "amudTPSWp157EsYqB3oJZAAAAHM"]
[Thu Jul 30 13:51:56.701494 2026] [security2:error] [pid 961194:tid 961439] [client 198.20.67.202:34310] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jesus.claims"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "amudTPSWp157EsYqB3oJZAAAAHM"]
[Thu Jul 30 13:51:57.669166 2026] [security2:error] [pid 961194:tid 961247] [remote 57.141.0.8:61136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amudTfSWp157EsYqB3oJgQAAeTQ"]
[Thu Jul 30 13:51:57.888156 2026] [fcgid:warn] [pid 961194:tid 961335] (70014)End of file found: [client 198.20.67.202:34324] mod_fcgid: can't get data from http client
[Thu Jul 30 13:51:57.904014 2026] [security2:error] [pid 961194:tid 961344] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudTfSWp157EsYqB3oJcwAAABQ"]
[Thu Jul 30 13:51:58.394584 2026] [security2:error] [pid 961194:tid 961392] [client 74.7.175.172:38462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ajg.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amudTvSWp157EsYqB3oJkgAAAEQ"]
[Thu Jul 30 13:51:58.998994 2026] [security2:error] [pid 961194:tid 961436] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudTvSWp157EsYqB3oJlQAAAHA"]
[Thu Jul 30 13:51:59.979063 2026] [security2:error] [pid 961194:tid 961366] [client 189.6.88.213:60083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudT_SWp157EsYqB3oJuQAAACo"]
[Thu Jul 30 13:51:59.979186 2026] [security2:error] [pid 961194:tid 961366] [client 189.6.88.213:60083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudT_SWp157EsYqB3oJuQAAACo"]
[Thu Jul 30 13:52:00.672804 2026] [security2:error] [pid 961194:tid 961364] [client 103.242.199.184:62559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudUPSWp157EsYqB3oJxwAAACg"]
[Thu Jul 30 13:52:00.672931 2026] [security2:error] [pid 961194:tid 961364] [client 103.242.199.184:62559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudUPSWp157EsYqB3oJxwAAACg"]
[Thu Jul 30 13:52:00.878052 2026] [autoindex:error] [pid 961194:tid 961420] [client 98.87.102.177:44955] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_3be08eaf/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:52:01.489001 2026] [core:notice] [pid 961194:tid 961280] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:02.184864 2026] [core:notice] [pid 961194:tid 961288] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:02.397893 2026] [security2:error] [pid 961194:tid 961287] [remote 57.141.0.1:21910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/610298834/feed/rss2/"] [unique_id "amudUvSWp157EsYqB3oJ7gAAaFw"]
[Thu Jul 30 13:52:02.835118 2026] [security2:error] [pid 961194:tid 961342] [client 181.116.200.68:29739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudUvSWp157EsYqB3oJ-wAAABI"]
[Thu Jul 30 13:52:02.835251 2026] [security2:error] [pid 961194:tid 961342] [client 181.116.200.68:29739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudUvSWp157EsYqB3oJ-wAAABI"]
[Thu Jul 30 13:52:03.274917 2026] [security2:error] [pid 961194:tid 961284] [remote 57.141.0.55:62450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/94764231632/feed/rss2/"] [unique_id "amudU_SWp157EsYqB3oKCAAAKFk"]
[Thu Jul 30 13:52:05.423513 2026] [security2:error] [pid 961194:tid 961394] [client 52.167.144.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amudVfSWp157EsYqB3oKNAAAAEY"]
[Thu Jul 30 13:52:05.636052 2026] [security2:error] [pid 961194:tid 961328] [client 172.237.109.114:43978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudVfSWp157EsYqB3oKNgAAAAQ"]
[Thu Jul 30 13:52:06.128430 2026] [security2:error] [pid 961194:tid 961351] [client 103.190.40.154:18470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudVvSWp157EsYqB3oKSAAAABs"]
[Thu Jul 30 13:52:06.128602 2026] [security2:error] [pid 961194:tid 961351] [client 103.190.40.154:18470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudVvSWp157EsYqB3oKSAAAABs"]
[Thu Jul 30 13:52:08.306573 2026] [security2:error] [pid 961194:tid 961407] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudV_SWp157EsYqB3oKdwAAUxk"]
[Thu Jul 30 13:52:09.229346 2026] [core:notice] [pid 961194:tid 961240] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:10.269488 2026] [security2:error] [pid 961194:tid 961450] [client 78.167.1.90:56453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudWvSWp157EsYqB3oKugAAAH4"]
[Thu Jul 30 13:52:10.269627 2026] [security2:error] [pid 961194:tid 961450] [client 78.167.1.90:56453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudWvSWp157EsYqB3oKugAAAH4"]
[Thu Jul 30 13:52:10.547707 2026] [security2:error] [pid 961194:tid 961332] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudWfSWp157EsYqB3oKuQAAAAg"]
[Thu Jul 30 13:52:10.754666 2026] [security2:error] [pid 961194:tid 961389] [client 189.6.88.213:60594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudWvSWp157EsYqB3oKxAAAAEE"]
[Thu Jul 30 13:52:10.754797 2026] [security2:error] [pid 961194:tid 961389] [client 189.6.88.213:60594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudWvSWp157EsYqB3oKxAAAAEE"]
[Thu Jul 30 13:52:11.254146 2026] [security2:error] [pid 961194:tid 961333] [client 103.242.199.184:63125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudW_SWp157EsYqB3oKzgAAAAk"]
[Thu Jul 30 13:52:11.254275 2026] [security2:error] [pid 961194:tid 961333] [client 103.242.199.184:63125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudW_SWp157EsYqB3oKzgAAAAk"]
[Thu Jul 30 13:52:12.754695 2026] [security2:error] [pid 961194:tid 961380] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudXPSWp157EsYqB3oK5QAAADg"]
[Thu Jul 30 13:52:12.988941 2026] [security2:error] [pid 961194:tid 961451] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudXPSWp157EsYqB3oK6QAAfyA"]
[Thu Jul 30 13:52:13.036476 2026] [core:notice] [pid 961194:tid 961330] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:13.056352 2026] [autoindex:error] [pid 961194:tid 961408] [client 165.232.98.159:33764] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:52:13.154781 2026] [security2:error] [pid 961194:tid 961363] [client 198.20.67.202:36798] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jesus.claims"] [uri "/wp-content/themes/Avada/style.css"] [unique_id "amudXfSWp157EsYqB3oLAQAAACc"]
[Thu Jul 30 13:52:13.384394 2026] [security2:error] [pid 961194:tid 961324] [client 181.116.200.68:7794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudXfSWp157EsYqB3oLBAAAAAA"]
[Thu Jul 30 13:52:13.384505 2026] [security2:error] [pid 961194:tid 961324] [client 181.116.200.68:7794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudXfSWp157EsYqB3oLBAAAAAA"]
[Thu Jul 30 13:52:13.579043 2026] [core:notice] [pid 961194:tid 961389] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:13.781730 2026] [autoindex:error] [pid 961194:tid 961446] [client 165.232.98.159:39954] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:52:13.813185 2026] [security2:error] [pid 961194:tid 961391] [client 52.167.144.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amudXfSWp157EsYqB3oLCgAAAEM"]
[Thu Jul 30 13:52:14.328943 2026] [security2:error] [pid 961194:tid 961398] [client 162.219.176.3:35362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amudXvSWp157EsYqB3oLHwAAAEo"]
[Thu Jul 30 13:52:14.329073 2026] [security2:error] [pid 961194:tid 961398] [client 162.219.176.3:35362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amudXvSWp157EsYqB3oLHwAAAEo"]
[Thu Jul 30 13:52:14.632928 2026] [security2:error] [pid 961194:tid 961442] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudXvSWp157EsYqB3oLGAAAdlE"]
[Thu Jul 30 13:52:16.710693 2026] [security2:error] [pid 961194:tid 961382] [client 103.190.40.154:22945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudYPSWp157EsYqB3oLXQAAADo"]
[Thu Jul 30 13:52:16.710840 2026] [security2:error] [pid 961194:tid 961382] [client 103.190.40.154:22945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudYPSWp157EsYqB3oLXQAAADo"]
[Thu Jul 30 13:52:20.576325 2026] [core:notice] [pid 961194:tid 961368] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:21.810265 2026] [security2:error] [pid 961194:tid 961420] [client 78.167.1.90:54209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudZfSWp157EsYqB3oLxQAAAGA"]
[Thu Jul 30 13:52:21.810754 2026] [security2:error] [pid 961194:tid 961420] [client 78.167.1.90:54209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudZfSWp157EsYqB3oLxQAAAGA"]
[Thu Jul 30 13:52:21.916204 2026] [security2:error] [pid 961194:tid 961414] [client 103.242.199.184:63687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudZfSWp157EsYqB3oLzQAAAFo"]
[Thu Jul 30 13:52:21.916347 2026] [security2:error] [pid 961194:tid 961414] [client 103.242.199.184:63687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudZfSWp157EsYqB3oLzQAAAFo"]
[Thu Jul 30 13:52:22.918946 2026] [security2:error] [pid 961194:tid 961381] [client 189.6.88.213:61122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudZvSWp157EsYqB3oL4QAAADk"]
[Thu Jul 30 13:52:22.919070 2026] [security2:error] [pid 961194:tid 961381] [client 189.6.88.213:61122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudZvSWp157EsYqB3oL4QAAADk"]
[Thu Jul 30 13:52:23.018256 2026] [security2:error] [pid 961194:tid 961328] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudZvSWp157EsYqB3oL1wAABBM"]
[Thu Jul 30 13:52:23.123529 2026] [security2:error] [pid 961194:tid 961390] [client 172.237.109.114:61153] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/ShareMgnt/Usrm_GetAllUsers"] [unique_id "amudZ_SWp157EsYqB3oL6QAAAEI"]
[Thu Jul 30 13:52:24.052943 2026] [security2:error] [pid 961194:tid 961405] [client 181.116.200.68:7935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudaPSWp157EsYqB3oL_gAAAFE"]
[Thu Jul 30 13:52:24.053084 2026] [security2:error] [pid 961194:tid 961405] [client 181.116.200.68:7935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudaPSWp157EsYqB3oL_gAAAFE"]
[Thu Jul 30 13:52:24.145742 2026] [security2:error] [pid 961194:tid 961240] [remote 97.74.93.24:37704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-login.php"] [unique_id "amudaPSWp157EsYqB3oL_wAAKy0"]
[Thu Jul 30 13:52:24.798069 2026] [core:notice] [pid 961194:tid 961348] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:27.344886 2026] [security2:error] [pid 961194:tid 961399] [client 103.190.40.154:17485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuda_SWp157EsYqB3oMPwAAAEs"]
[Thu Jul 30 13:52:27.345043 2026] [security2:error] [pid 961194:tid 961399] [client 103.190.40.154:17485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuda_SWp157EsYqB3oMPwAAAEs"]
[Thu Jul 30 13:52:27.543184 2026] [core:notice] [pid 961194:tid 961416] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:27.619444 2026] [proxy:error] [pid 961194:tid 961384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:52:27.619545 2026] [proxy_http:error] [pid 961194:tid 961384] [client 44.216.125.112:37334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:52:27.620138 2026] [proxy:error] [pid 961194:tid 961384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:52:27.620191 2026] [proxy_http:error] [pid 961194:tid 961384] [client 44.216.125.112:37334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:52:27.626883 2026] [proxy:error] [pid 961194:tid 961403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:52:27.626953 2026] [proxy_http:error] [pid 961194:tid 961403] [client 44.216.125.112:59407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:52:27.627805 2026] [proxy:error] [pid 961194:tid 961403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:52:27.627865 2026] [proxy_http:error] [pid 961194:tid 961403] [client 44.216.125.112:59407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:52:28.409149 2026] [core:notice] [pid 961194:tid 961415] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:29.044069 2026] [security2:error] [pid 961194:tid 961378] [client 18.211.55.47:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.55.211.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lms.aetiiph.net"] [uri "/login/index.php"] [unique_id "amudbfSWp157EsYqB3oMcgAAADY"]
[Thu Jul 30 13:52:29.525095 2026] [security2:error] [pid 961194:tid 961359] [client 98.87.102.177:56624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.102.87.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lms.aetiiph.net"] [uri "/login/index.php"] [unique_id "amudbfSWp157EsYqB3oMdwAAACM"]
[Thu Jul 30 13:52:30.702501 2026] [security2:error] [pid 961194:tid 961450] [client 43.173.181.170:41258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/01/16/shopping-a-londres-le-centre-commercial-westfield-london/"] [unique_id "amudbvSWp157EsYqB3oMlAAAAH4"]
[Thu Jul 30 13:52:30.838647 2026] [security2:error] [pid 961194:tid 961280] [remote 57.141.0.21:37750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amudbvSWp157EsYqB3oMmgAAYFU"]
[Thu Jul 30 13:52:31.153802 2026] [security2:error] [pid 961194:tid 961388] [client 172.237.109.114:8199] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:< ?script|(?:<|< ?/)(?:(?:java|vb)script|about|applet|activex|chrome|qx?ss|embed)|< ?/?i?frame\\\\b)" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1079"] [id "340147"] [rev "141"] [msg "Atomicorp.com WAF Rules: Potential Cross Site Scripting Attack"] [data "<script"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/Visitor/bin/WebStrings.srf"] [unique_id "amudb_SWp157EsYqB3oMpQAAAEA"]
[Thu Jul 30 13:52:31.355016 2026] [core:notice] [pid 961194:tid 961367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:31.361195 2026] [security2:error] [pid 961194:tid 961367] [client 43.172.197.110:34656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/01/16/shopping-a-londres-le-centre-commercial-westfield-london/"] [unique_id "amudb_SWp157EsYqB3oMqgAAACs"], referer: https://carnetdeshopping.com/index.php/2014/01/16/shopping-a-londres-le-centre-commercial-westfield-london/?replytocom=1021
[Thu Jul 30 13:52:31.383776 2026] [security2:error] [pid 961194:tid 961375] [client 162.219.176.3:39952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudb_SWp157EsYqB3oMqwAAADM"]
[Thu Jul 30 13:52:31.383859 2026] [security2:error] [pid 961194:tid 961375] [client 162.219.176.3:39952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudb_SWp157EsYqB3oMqwAAADM"]
[Thu Jul 30 13:52:31.445587 2026] [security2:error] [pid 961194:tid 961397] [client 78.167.1.90:55831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudb_SWp157EsYqB3oMrwAAAEk"]
[Thu Jul 30 13:52:31.446076 2026] [security2:error] [pid 961194:tid 961397] [client 78.167.1.90:55831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudb_SWp157EsYqB3oMrwAAAEk"]
[Thu Jul 30 13:52:31.480701 2026] [proxy:error] [pid 961194:tid 961288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:52:31.480752 2026] [proxy_http:error] [pid 961194:tid 961288] [remote 74.7.244.16:48270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:52:31.481326 2026] [proxy:error] [pid 961194:tid 961288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:52:31.481370 2026] [proxy_http:error] [pid 961194:tid 961288] [remote 74.7.244.16:48270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:52:32.346497 2026] [security2:error] [pid 961194:tid 961282] [remote 216.73.217.142:24921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amudcPSWp157EsYqB3oMwAAAdlc"]
[Thu Jul 30 13:52:32.363194 2026] [security2:error] [pid 961194:tid 961284] [remote 57.141.0.59:30488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amudcPSWp157EsYqB3oMxAAALVk"]
[Thu Jul 30 13:52:32.477843 2026] [security2:error] [pid 961194:tid 961399] [client 5.29.13.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amudcPSWp157EsYqB3oMwwAAAEs"], referer: https://cnpinyin.com
[Thu Jul 30 13:52:32.592630 2026] [security2:error] [pid 961194:tid 961344] [client 103.242.199.184:64253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudcPSWp157EsYqB3oMzgAAABQ"]
[Thu Jul 30 13:52:32.592770 2026] [security2:error] [pid 961194:tid 961344] [client 103.242.199.184:64253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudcPSWp157EsYqB3oMzgAAABQ"]
[Thu Jul 30 13:52:32.670320 2026] [security2:error] [pid 961194:tid 961359] [client 57.141.0.23:43340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amudcPSWp157EsYqB3oMvwAAI1g"], referer: https://igetvape-australia.com/product/alibarbar-ingot-passion-fruit-mango-lime-9000-puffs/
[Thu Jul 30 13:52:33.126507 2026] [security2:error] [pid 961194:tid 961437] [client 189.6.88.213:61636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudcfSWp157EsYqB3oM2QAAAHE"]
[Thu Jul 30 13:52:33.126623 2026] [security2:error] [pid 961194:tid 961437] [client 189.6.88.213:61636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudcfSWp157EsYqB3oM2QAAAHE"]
[Thu Jul 30 13:52:33.619493 2026] [security2:error] [pid 961194:tid 961336] [client 172.237.109.114:21384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudcfSWp157EsYqB3oM2AAAAAw"]
[Thu Jul 30 13:52:33.937775 2026] [core:error] [pid 961194:tid 961292] [remote 74.7.228.11:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:52:33.937796 2026] [core:error] [pid 961194:tid 961292] [remote 74.7.228.11:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:52:33.938074 2026] [security2:error] [pid 961194:tid 961448] [client 74.7.228.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.rooferio.enterprises"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amudcfSWp157EsYqB3oM6AAAfGE"]
[Thu Jul 30 13:52:34.637298 2026] [security2:error] [pid 961194:tid 961398] [client 181.116.200.68:49677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudcvSWp157EsYqB3oNAQAAAEo"]
[Thu Jul 30 13:52:34.637429 2026] [security2:error] [pid 961194:tid 961398] [client 181.116.200.68:49677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudcvSWp157EsYqB3oNAQAAAEo"]
[Thu Jul 30 13:52:38.458340 2026] [security2:error] [pid 961194:tid 961420] [client 103.190.40.154:1722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuddvSWp157EsYqB3oNWwAAAGA"]
[Thu Jul 30 13:52:38.458481 2026] [security2:error] [pid 961194:tid 961420] [client 103.190.40.154:1722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuddvSWp157EsYqB3oNWwAAAGA"]
[Thu Jul 30 13:52:39.786043 2026] [security2:error] [pid 961194:tid 961226] [remote 35.204.109.104:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dl.happymod-apk.com.mx"] [uri "/"] [unique_id "amudd_SWp157EsYqB3oNcQAAGR8"]
[Thu Jul 30 13:52:39.786198 2026] [security2:error] [pid 961194:tid 961349] [client 35.204.109.104:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dl.happymod-apk.com.mx"] [uri "/"] [unique_id "amudd_SWp157EsYqB3oNcQAAGR8"]
[Thu Jul 30 13:52:39.974284 2026] [security2:error] [pid 961194:tid 961439] [client 134.19.179.155:53172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amudd_SWp157EsYqB3oNeAAAAHM"]
[Thu Jul 30 13:52:39.974411 2026] [security2:error] [pid 961194:tid 961439] [client 134.19.179.155:53172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amudd_SWp157EsYqB3oNeAAAAHM"]
[Thu Jul 30 13:52:40.229387 2026] [security2:error] [pid 961194:tid 961419] [client 68.67.112.242:29178] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amudePSWp157EsYqB3oNfAAAAF8"]
[Thu Jul 30 13:52:41.623120 2026] [core:notice] [pid 961194:tid 961377] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:41.627627 2026] [security2:error] [pid 961194:tid 961377] [client 3.101.191.121:32506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/01/30/les-10-couleurs-tendances-printemps-ete-2013/"] [unique_id "amudefSWp157EsYqB3oNkAAAADU"]
[Thu Jul 30 13:52:41.786085 2026] [security2:error] [pid 961194:tid 961251] [remote 217.182.128.41:36600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amudefSWp157EsYqB3oNngAATDg"]
[Thu Jul 30 13:52:42.052743 2026] [security2:error] [pid 961194:tid 961444] [client 78.167.1.90:54755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudevSWp157EsYqB3oNowAAAHg"]
[Thu Jul 30 13:52:42.053284 2026] [security2:error] [pid 961194:tid 961444] [client 78.167.1.90:54755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudevSWp157EsYqB3oNowAAAHg"]
[Thu Jul 30 13:52:42.160302 2026] [security2:error] [pid 961194:tid 961448] [client 47.128.111.165:23586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aded-rdc.org"] [uri "/robots.txt"] [unique_id "amudevSWp157EsYqB3oNpwAAAHw"]
[Thu Jul 30 13:52:42.939495 2026] [security2:error] [pid 961194:tid 961442] [client 189.6.88.213:62148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudevSWp157EsYqB3oNugAAAHY"]
[Thu Jul 30 13:52:42.939618 2026] [security2:error] [pid 961194:tid 961442] [client 189.6.88.213:62148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudevSWp157EsYqB3oNugAAAHY"]
[Thu Jul 30 13:52:43.217164 2026] [security2:error] [pid 961194:tid 961344] [client 103.242.199.184:64826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amude_SWp157EsYqB3oNwgAAABQ"]
[Thu Jul 30 13:52:43.217321 2026] [security2:error] [pid 961194:tid 961344] [client 103.242.199.184:64826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amude_SWp157EsYqB3oNwgAAABQ"]
[Thu Jul 30 13:52:45.003193 2026] [core:notice] [pid 961194:tid 961276] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:45.174395 2026] [security2:error] [pid 961194:tid 961432] [client 181.116.200.68:38009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudffSWp157EsYqB3oN7QAAAGw"]
[Thu Jul 30 13:52:45.175134 2026] [security2:error] [pid 961194:tid 961432] [client 181.116.200.68:38009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudffSWp157EsYqB3oN7QAAAGw"]
[Thu Jul 30 13:52:45.296991 2026] [autoindex:error] [pid 961194:tid 961346] [client 34.233.129.35:31109] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:52:45.703539 2026] [security2:error] [pid 961194:tid 961419] [client 223.109.252.162:43900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/arco-iris-alto-oblique-b23/"] [unique_id "amudffSWp157EsYqB3oN_AAAAF8"]
[Thu Jul 30 13:52:45.703629 2026] [security2:error] [pid 961194:tid 961419] [client 223.109.252.162:43900] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/arco-iris-alto-oblique-b23/"] [unique_id "amudffSWp157EsYqB3oN_AAAAF8"]
[Thu Jul 30 13:52:46.235610 2026] [security2:error] [pid 961194:tid 961285] [remote 74.7.243.224:57542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/uploads/partners/login.php"] [unique_id "amudfvSWp157EsYqB3oOCAAACFo"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/uploads/partners/1762340553_pp3.png
[Thu Jul 30 13:52:47.278448 2026] [security2:error] [pid 961194:tid 961296] [remote 57.141.0.59:27624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amudf_SWp157EsYqB3oOIgAAVWU"]
[Thu Jul 30 13:52:47.817423 2026] [security2:error] [pid 961194:tid 961345] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudf_SWp157EsYqB3oOHwAAFVc"]
[Thu Jul 30 13:52:48.143240 2026] [security2:error] [pid 961194:tid 961342] [client 197.26.77.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amudgPSWp157EsYqB3oONwAAABI"], referer: https://cnpinyin.com
[Thu Jul 30 13:52:49.522561 2026] [security2:error] [pid 961194:tid 961389] [client 103.190.40.154:18082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudgfSWp157EsYqB3oOVgAAAEE"]
[Thu Jul 30 13:52:49.522716 2026] [security2:error] [pid 961194:tid 961389] [client 103.190.40.154:18082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudgfSWp157EsYqB3oOVgAAAEE"]
[Thu Jul 30 13:52:49.609749 2026] [core:notice] [pid 961194:tid 961449] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:49.772317 2026] [security2:error] [pid 961194:tid 961410] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudgfSWp157EsYqB3oOTQAAAFY"]
[Thu Jul 30 13:52:50.771833 2026] [autoindex:error] [pid 961194:tid 961434] [client 129.204.188.64:59304] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:52:52.286603 2026] [security2:error] [pid 961194:tid 961380] [client 177.190.209.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amudhPSWp157EsYqB3oOkAAAADg"], referer: https://cnpinyin.com
[Thu Jul 30 13:52:52.674098 2026] [security2:error] [pid 961194:tid 961336] [client 78.167.1.90:56481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudhPSWp157EsYqB3oOnAAAAAw"]
[Thu Jul 30 13:52:52.674467 2026] [security2:error] [pid 961194:tid 961336] [client 78.167.1.90:56481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudhPSWp157EsYqB3oOnAAAAAw"]
[Thu Jul 30 13:52:53.222301 2026] [security2:error] [pid 961194:tid 961430] [client 213.152.187.215:58172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amudhfSWp157EsYqB3oOqQAAAGo"]
[Thu Jul 30 13:52:53.222445 2026] [security2:error] [pid 961194:tid 961430] [client 213.152.187.215:58172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amudhfSWp157EsYqB3oOqQAAAGo"]
[Thu Jul 30 13:52:53.631190 2026] [security2:error] [pid 961194:tid 961423] [client 189.6.88.213:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudhfSWp157EsYqB3oOtwAAAGM"]
[Thu Jul 30 13:52:53.636694 2026] [security2:error] [pid 961194:tid 961423] [client 189.6.88.213:62664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudhfSWp157EsYqB3oOtwAAAGM"]
[Thu Jul 30 13:52:53.924434 2026] [security2:error] [pid 961194:tid 961370] [client 103.242.199.184:65390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudhfSWp157EsYqB3oOuwAAAC4"]
[Thu Jul 30 13:52:53.925136 2026] [security2:error] [pid 961194:tid 961370] [client 103.242.199.184:65390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudhfSWp157EsYqB3oOuwAAAC4"]
[Thu Jul 30 13:52:53.979999 2026] [core:notice] [pid 961194:tid 961424] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:52:55.854838 2026] [security2:error] [pid 961194:tid 961396] [client 181.116.200.68:47892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudh_SWp157EsYqB3oO8QAAAEg"]
[Thu Jul 30 13:52:55.855032 2026] [security2:error] [pid 961194:tid 961396] [client 181.116.200.68:47892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudh_SWp157EsYqB3oO8QAAAEg"]
[Thu Jul 30 13:52:58.236885 2026] [security2:error] [pid 961194:tid 961419] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudifSWp157EsYqB3oPFwAAXzE"]
[Thu Jul 30 13:52:58.411325 2026] [security2:error] [pid 961194:tid 961419] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudifSWp157EsYqB3oPHQAAXyQ"]
[Thu Jul 30 13:53:00.338592 2026] [security2:error] [pid 961194:tid 961352] [client 103.190.40.154:22555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudjPSWp157EsYqB3oPUwAAABw"]
[Thu Jul 30 13:53:00.338759 2026] [security2:error] [pid 961194:tid 961352] [client 103.190.40.154:22555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudjPSWp157EsYqB3oPUwAAABw"]
[Thu Jul 30 13:53:01.110071 2026] [security2:error] [pid 961194:tid 961268] [remote 159.75.55.41:57022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.75.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amudjfSWp157EsYqB3oPaAAAHUk"]
[Thu Jul 30 13:53:02.968779 2026] [security2:error] [pid 961194:tid 961411] [client 134.19.179.155:34484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amudjvSWp157EsYqB3oPlAAAAFc"]
[Thu Jul 30 13:53:02.968925 2026] [security2:error] [pid 961194:tid 961411] [client 134.19.179.155:34484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amudjvSWp157EsYqB3oPlAAAAFc"]
[Thu Jul 30 13:53:03.202388 2026] [security2:error] [pid 961194:tid 961437] [client 78.167.1.90:56187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudj_SWp157EsYqB3oPnAAAAHE"]
[Thu Jul 30 13:53:03.203029 2026] [security2:error] [pid 961194:tid 961437] [client 78.167.1.90:56187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudj_SWp157EsYqB3oPnAAAAHE"]
[Thu Jul 30 13:53:04.287942 2026] [core:error] [pid 961194:tid 961316] [remote 74.7.244.26:45008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:53:04.287966 2026] [core:error] [pid 961194:tid 961316] [remote 74.7.244.26:45008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:53:04.288163 2026] [security2:error] [pid 961194:tid 961449] [client 74.7.244.26:45008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-69ebbb28.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amudkPSWp157EsYqB3oPtwAAfXk"]
[Thu Jul 30 13:53:04.401486 2026] [security2:error] [pid 961194:tid 961429] [client 189.6.88.213:63173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudkPSWp157EsYqB3oPuAAAAGk"]
[Thu Jul 30 13:53:04.401629 2026] [security2:error] [pid 961194:tid 961429] [client 189.6.88.213:63173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudkPSWp157EsYqB3oPuAAAAGk"]
[Thu Jul 30 13:53:04.470628 2026] [security2:error] [pid 961194:tid 961339] [client 172.213.232.128:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/011i.php"] [unique_id "amudkPSWp157EsYqB3oPuQAAAA8"]
[Thu Jul 30 13:53:04.476277 2026] [core:notice] [pid 961194:tid 961282] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:04.575044 2026] [security2:error] [pid 961194:tid 961432] [client 103.242.199.184:49570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudkPSWp157EsYqB3oPuwAAAGw"]
[Thu Jul 30 13:53:04.575171 2026] [security2:error] [pid 961194:tid 961432] [client 103.242.199.184:49570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudkPSWp157EsYqB3oPuwAAAGw"]
[Thu Jul 30 13:53:04.673699 2026] [security2:error] [pid 961194:tid 961345] [client 74.7.230.8:34714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "yqe.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amudkPSWp157EsYqB3oPwAAAFWw"]
[Thu Jul 30 13:53:04.712589 2026] [security2:error] [pid 961194:tid 961337] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudkPSWp157EsYqB3oPsAAADWQ"]
[Thu Jul 30 13:53:05.104359 2026] [security2:error] [pid 961194:tid 961438] [client 5.75.228.162:46446] ModSecurity: Access denied with code 406 (phase 1). Match of "rx (^/administrator/)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "63"] [id "331216"] [rev "2"] [msg "Atomicorp.com WAF Rules: Wordpress DOS Attack Dropped"] [severity "CRITICAL"] [hostname "jesus.claims"] [uri "/wp-load.php"] [unique_id "amudkfSWp157EsYqB3oPywAAAHI"]
[Thu Jul 30 13:53:05.145685 2026] [security2:error] [pid 961194:tid 961405] [client 172.213.232.128:55424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/03a005685d.php"] [unique_id "amudkfSWp157EsYqB3oPzAAAAFE"]
[Thu Jul 30 13:53:05.337260 2026] [core:notice] [pid 961194:tid 961206] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:05.431257 2026] [security2:error] [pid 961194:tid 961338] [client 74.7.230.5:44214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-0e1c5cae.ols.fyv.temporary.site"] [uri "/robots.txt"] [unique_id "amudkfSWp157EsYqB3oP1wAAAA4"]
[Thu Jul 30 13:53:05.568865 2026] [security2:error] [pid 961194:tid 961331] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudkPSWp157EsYqB3oPygAAAAc"]
[Thu Jul 30 13:53:05.725314 2026] [security2:error] [pid 961194:tid 961361] [client 172.213.232.128:60040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/403.php"] [unique_id "amudkfSWp157EsYqB3oP4wAAACU"]
[Thu Jul 30 13:53:05.856758 2026] [core:notice] [pid 961194:tid 961318] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:06.451152 2026] [security2:error] [pid 961194:tid 961427] [client 181.116.200.68:48721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudkvSWp157EsYqB3oP9gAAAGc"]
[Thu Jul 30 13:53:06.451260 2026] [security2:error] [pid 961194:tid 961427] [client 181.116.200.68:48721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudkvSWp157EsYqB3oP9gAAAGc"]
[Thu Jul 30 13:53:07.573650 2026] [core:notice] [pid 961194:tid 961330] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:07.787022 2026] [security2:error] [pid 961194:tid 961340] [client 172.213.232.128:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/404.php"] [unique_id "amudk_SWp157EsYqB3oQDwAAABA"]
[Thu Jul 30 13:53:07.802871 2026] [core:notice] [pid 961194:tid 961424] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:09.567704 2026] [security2:error] [pid 961194:tid 961444] [client 172.213.232.128:55473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/aa.php"] [unique_id "amudlfSWp157EsYqB3oQOgAAAHg"]
[Thu Jul 30 13:53:10.702444 2026] [security2:error] [pid 961194:tid 961451] [client 172.213.232.128:55720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/aafewc0k.php"] [unique_id "amudlvSWp157EsYqB3oQUQAAAH8"]
[Thu Jul 30 13:53:11.140348 2026] [security2:error] [pid 961194:tid 961352] [client 103.190.40.154:15804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudl_SWp157EsYqB3oQWQAAABw"]
[Thu Jul 30 13:53:11.140520 2026] [security2:error] [pid 961194:tid 961352] [client 103.190.40.154:15804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudl_SWp157EsYqB3oQWQAAABw"]
[Thu Jul 30 13:53:11.353244 2026] [core:notice] [pid 961194:tid 961240] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:11.486615 2026] [core:notice] [pid 961194:tid 961407] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:11.762666 2026] [autoindex:error] [pid 961194:tid 961448] [client 3.225.222.228:54178] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:53:11.816950 2026] [security2:error] [pid 961194:tid 961226] [remote 52.167.144.160:15546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/2025/08/17/communityf.php"] [unique_id "amudl_SWp157EsYqB3oQcQAAbR8"]
[Thu Jul 30 13:53:12.001964 2026] [core:notice] [pid 961194:tid 961237] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:12.303369 2026] [security2:error] [pid 961194:tid 961325] [client 172.213.232.128:60041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/abcd.php"] [unique_id "amudmPSWp157EsYqB3oQgQAAAAE"]
[Thu Jul 30 13:53:13.328192 2026] [security2:error] [pid 961194:tid 961431] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudmPSWp157EsYqB3oQfAAAazM"]
[Thu Jul 30 13:53:13.441241 2026] [security2:error] [pid 961194:tid 961386] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amudmPSWp157EsYqB3oQhAAAAD4"], referer: https://smoke-tfhk.com/product/black-stone-wild-strawberry/
[Thu Jul 30 13:53:13.549379 2026] [core:notice] [pid 961194:tid 961320] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:13.551047 2026] [security2:error] [pid 961194:tid 961361] [client 74.7.175.147:38524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-167e4a7a.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amudmfSWp157EsYqB3oQogAAJX0"]
[Thu Jul 30 13:53:13.836734 2026] [security2:error] [pid 961194:tid 961366] [client 78.167.1.90:54290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudmfSWp157EsYqB3oQqQAAACo"]
[Thu Jul 30 13:53:13.837535 2026] [security2:error] [pid 961194:tid 961366] [client 78.167.1.90:54290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudmfSWp157EsYqB3oQqQAAACo"]
[Thu Jul 30 13:53:13.912717 2026] [security2:error] [pid 961194:tid 961411] [client 172.213.232.128:55737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/about.php"] [unique_id "amudmfSWp157EsYqB3oQrQAAAFc"]
[Thu Jul 30 13:53:14.373598 2026] [core:notice] [pid 961194:tid 961227] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:14.441561 2026] [security2:error] [pid 961194:tid 961358] [client 65.109.169.132:39360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amudmvSWp157EsYqB3oQrgAAACI"]
[Thu Jul 30 13:53:14.465851 2026] [security2:error] [pid 961194:tid 961346] [client 172.213.232.128:59978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/admin.php"] [unique_id "amudmvSWp157EsYqB3oQugAAABY"]
[Thu Jul 30 13:53:15.292686 2026] [security2:error] [pid 961194:tid 961373] [client 103.242.199.184:50146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudm_SWp157EsYqB3oQywAAADE"]
[Thu Jul 30 13:53:15.293381 2026] [security2:error] [pid 961194:tid 961373] [client 103.242.199.184:50146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudm_SWp157EsYqB3oQywAAADE"]
[Thu Jul 30 13:53:15.431324 2026] [security2:error] [pid 961194:tid 961356] [client 65.109.169.132:39366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudmvSWp157EsYqB3oQwQAAACA"]
[Thu Jul 30 13:53:16.160185 2026] [security2:error] [pid 961194:tid 961447] [client 189.6.88.213:63686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudnPSWp157EsYqB3oQ3AAAAHs"]
[Thu Jul 30 13:53:16.160293 2026] [security2:error] [pid 961194:tid 961447] [client 189.6.88.213:63686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudnPSWp157EsYqB3oQ3AAAAHs"]
[Thu Jul 30 13:53:16.637822 2026] [security2:error] [pid 961194:tid 961431] [client 172.237.109.114:17798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amudnPSWp157EsYqB3oQ2wAAAGs"]
[Thu Jul 30 13:53:17.048401 2026] [security2:error] [pid 961194:tid 961400] [client 181.116.200.68:28039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudnfSWp157EsYqB3oQ8QAAAEw"]
[Thu Jul 30 13:53:17.048519 2026] [security2:error] [pid 961194:tid 961400] [client 181.116.200.68:28039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudnfSWp157EsYqB3oQ8QAAAEw"]
[Thu Jul 30 13:53:17.506488 2026] [security2:error] [pid 961194:tid 961428] [client 172.213.232.128:55469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/adminfuns.php"] [unique_id "amudnfSWp157EsYqB3oQ_AAAAGg"]
[Thu Jul 30 13:53:19.473814 2026] [security2:error] [pid 961194:tid 961353] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amudn_SWp157EsYqB3oRJQAAAB0"]
[Thu Jul 30 13:53:19.473966 2026] [security2:error] [pid 961194:tid 961353] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amudn_SWp157EsYqB3oRJQAAAB0"]
[Thu Jul 30 13:53:20.039436 2026] [security2:error] [pid 961194:tid 961422] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amudoPSWp157EsYqB3oRMAAAAGI"]
[Thu Jul 30 13:53:20.039539 2026] [security2:error] [pid 961194:tid 961422] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amudoPSWp157EsYqB3oRMAAAAGI"]
[Thu Jul 30 13:53:20.470611 2026] [security2:error] [pid 961194:tid 961425] [client 172.213.232.128:51829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/albin.php"] [unique_id "amudoPSWp157EsYqB3oROAAAAGU"]
[Thu Jul 30 13:53:20.548210 2026] [security2:error] [pid 961194:tid 961374] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/bootstrap.php"] [unique_id "amudoPSWp157EsYqB3oRPAAAADI"]
[Thu Jul 30 13:53:20.548321 2026] [security2:error] [pid 961194:tid 961374] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/bootstrap.php"] [unique_id "amudoPSWp157EsYqB3oRPAAAADI"]
[Thu Jul 30 13:53:21.061613 2026] [security2:error] [pid 961194:tid 961392] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-blog-header.php"] [unique_id "amudofSWp157EsYqB3oRRwAAAEQ"]
[Thu Jul 30 13:53:21.061717 2026] [security2:error] [pid 961194:tid 961392] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-blog-header.php"] [unique_id "amudofSWp157EsYqB3oRRwAAAEQ"]
[Thu Jul 30 13:53:21.192545 2026] [security2:error] [pid 961194:tid 961362] [client 172.213.232.128:55529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/amfsqvgv.php"] [unique_id "amudofSWp157EsYqB3oRSAAAACY"]
[Thu Jul 30 13:53:21.280274 2026] [proxy:error] [pid 961194:tid 961313] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:21.280327 2026] [proxy_http:error] [pid 961194:tid 961313] [remote 91.92.241.196:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:21.280897 2026] [proxy:error] [pid 961194:tid 961313] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:21.280939 2026] [proxy_http:error] [pid 961194:tid 961313] [remote 91.92.241.196:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:21.340760 2026] [security2:error] [pid 961194:tid 961340] [client 20.104.18.253:7982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dirs.php"] [unique_id "amudofSWp157EsYqB3oRTQAAABA"]
[Thu Jul 30 13:53:21.557241 2026] [security2:error] [pid 961194:tid 961417] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-load.php"] [unique_id "amudofSWp157EsYqB3oRVQAAAF0"]
[Thu Jul 30 13:53:21.557336 2026] [security2:error] [pid 961194:tid 961417] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-load.php"] [unique_id "amudofSWp157EsYqB3oRVQAAAF0"]
[Thu Jul 30 13:53:21.832548 2026] [security2:error] [pid 961194:tid 961435] [client 103.190.40.154:22934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudofSWp157EsYqB3oRWgAAAG8"]
[Thu Jul 30 13:53:21.832683 2026] [security2:error] [pid 961194:tid 961435] [client 103.190.40.154:22934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudofSWp157EsYqB3oRWgAAAG8"]
[Thu Jul 30 13:53:21.864999 2026] [security2:error] [pid 961194:tid 961336] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amudofSWp157EsYqB3oRWwAAAAw"]
[Thu Jul 30 13:53:21.943157 2026] [security2:error] [pid 961194:tid 961408] [client 20.104.18.253:7936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/disagimons.php"] [unique_id "amudofSWp157EsYqB3oRXwAAAFQ"]
[Thu Jul 30 13:53:22.056127 2026] [security2:error] [pid 961194:tid 961377] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/edit.php"] [unique_id "amudovSWp157EsYqB3oRZwAAADU"]
[Thu Jul 30 13:53:22.056265 2026] [security2:error] [pid 961194:tid 961377] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/edit.php"] [unique_id "amudovSWp157EsYqB3oRZwAAADU"]
[Thu Jul 30 13:53:22.328534 2026] [security2:error] [pid 961194:tid 961385] [client 172.213.232.128:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/ant.php"] [unique_id "amudovSWp157EsYqB3oRawAAAD0"]
[Thu Jul 30 13:53:22.540222 2026] [security2:error] [pid 961194:tid 961451] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudofSWp157EsYqB3oRYAAAf24"]
[Thu Jul 30 13:53:22.541474 2026] [security2:error] [pid 961194:tid 961349] [client 20.104.18.253:7969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/disagraeosc.php"] [unique_id "amudovSWp157EsYqB3oRcAAAABk"]
[Thu Jul 30 13:53:22.560241 2026] [proxy:error] [pid 961194:tid 961357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:22.560306 2026] [proxy_http:error] [pid 961194:tid 961357] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:22.560892 2026] [proxy:error] [pid 961194:tid 961357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:22.560936 2026] [proxy_http:error] [pid 961194:tid 961357] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:22.561024 2026] [security2:error] [pid 961194:tid 961357] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.nexiummedication.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amudovSWp157EsYqB3oRcQAAACE"]
[Thu Jul 30 13:53:23.077165 2026] [security2:error] [pid 961194:tid 961409] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/mah.php"] [unique_id "amudo_SWp157EsYqB3oRgAAAAFU"]
[Thu Jul 30 13:53:23.077264 2026] [security2:error] [pid 961194:tid 961409] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/mah.php"] [unique_id "amudo_SWp157EsYqB3oRgAAAAFU"]
[Thu Jul 30 13:53:23.139009 2026] [security2:error] [pid 961194:tid 961374] [client 20.104.18.253:7942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/disagreop.php"] [unique_id "amudo_SWp157EsYqB3oRgwAAADI"]
[Thu Jul 30 13:53:23.512846 2026] [security2:error] [pid 961194:tid 961346] [client 172.213.232.128:55549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/appreciators.php"] [unique_id "amudo_SWp157EsYqB3oRjQAAABY"]
[Thu Jul 30 13:53:23.563077 2026] [security2:error] [pid 961194:tid 961330] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/archive.php"] [unique_id "amudo_SWp157EsYqB3oRjwAAAAY"]
[Thu Jul 30 13:53:23.563197 2026] [security2:error] [pid 961194:tid 961330] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/archive.php"] [unique_id "amudo_SWp157EsYqB3oRjwAAAAY"]
[Thu Jul 30 13:53:23.676181 2026] [security2:error] [pid 961194:tid 961380] [client 84.233.212.33:56295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.212.233.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ahk.tqa.temporary.site"] [uri "/phpinfo.php"] [unique_id "amudo_SWp157EsYqB3oRiQAAADg"]
[Thu Jul 30 13:53:23.738754 2026] [security2:error] [pid 961194:tid 961450] [client 20.104.18.253:7173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/about.php"] [unique_id "amudo_SWp157EsYqB3oRlgAAAH4"]
[Thu Jul 30 13:53:23.744905 2026] [security2:error] [pid 961194:tid 961340] [client 68.67.112.87:62528] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amudo_SWp157EsYqB3oRlwAAABA"]
[Thu Jul 30 13:53:23.913478 2026] [security2:error] [pid 961194:tid 961429] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudo_SWp157EsYqB3oRhQAAaXA"]
[Thu Jul 30 13:53:24.051778 2026] [security2:error] [pid 961194:tid 961326] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/hosty.php"] [unique_id "amudpPSWp157EsYqB3oRoQAAAAI"]
[Thu Jul 30 13:53:24.051891 2026] [security2:error] [pid 961194:tid 961326] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/hosty.php"] [unique_id "amudpPSWp157EsYqB3oRoQAAAAI"]
[Thu Jul 30 13:53:24.362914 2026] [security2:error] [pid 961194:tid 961416] [client 78.167.1.90:54470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudpPSWp157EsYqB3oRpgAAAFw"]
[Thu Jul 30 13:53:24.363078 2026] [security2:error] [pid 961194:tid 961416] [client 78.167.1.90:54470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudpPSWp157EsYqB3oRpgAAAFw"]
[Thu Jul 30 13:53:24.383617 2026] [security2:error] [pid 961194:tid 961394] [client 20.104.18.253:7981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/alfa-rex.php"] [unique_id "amudpPSWp157EsYqB3oRqQAAAEY"]
[Thu Jul 30 13:53:24.407128 2026] [security2:error] [pid 961194:tid 961414] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudo_SWp157EsYqB3oRjgAAWgg"]
[Thu Jul 30 13:53:24.604263 2026] [security2:error] [pid 961194:tid 961388] [client 84.233.212.33:56616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.212.233.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ahk.tqa.temporary.site"] [uri "/test.php"] [unique_id "amudpPSWp157EsYqB3oRrwAAAEA"]
[Thu Jul 30 13:53:24.605232 2026] [proxy:error] [pid 961194:tid 961344] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:24.605287 2026] [proxy_http:error] [pid 961194:tid 961344] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:24.605859 2026] [proxy:error] [pid 961194:tid 961344] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:24.605900 2026] [proxy_http:error] [pid 961194:tid 961344] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:24.605971 2026] [security2:error] [pid 961194:tid 961344] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.nexiummedication.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amudpPSWp157EsYqB3oRrgAAABQ"]
[Thu Jul 30 13:53:24.952850 2026] [security2:error] [pid 961194:tid 961408] [client 172.213.232.128:51832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/archive.php"] [unique_id "amudpPSWp157EsYqB3oRuQAAAFQ"]
[Thu Jul 30 13:53:25.109053 2026] [security2:error] [pid 961194:tid 961327] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/admin.php"] [unique_id "amudpfSWp157EsYqB3oRvgAAAAM"]
[Thu Jul 30 13:53:25.109194 2026] [security2:error] [pid 961194:tid 961327] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/admin.php"] [unique_id "amudpfSWp157EsYqB3oRvgAAAAM"]
[Thu Jul 30 13:53:25.110405 2026] [security2:error] [pid 961194:tid 961368] [client 20.104.18.253:7977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/autoload_classmap.php"] [unique_id "amudpfSWp157EsYqB3oRvwAAACw"]
[Thu Jul 30 13:53:25.608291 2026] [security2:error] [pid 961194:tid 961419] [client 172.213.232.128:55714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/as.php"] [unique_id "amudpfSWp157EsYqB3oR0QAAAF8"]
[Thu Jul 30 13:53:25.620886 2026] [security2:error] [pid 961194:tid 961437] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/av.php"] [unique_id "amudpfSWp157EsYqB3oR0gAAAHE"]
[Thu Jul 30 13:53:25.621036 2026] [security2:error] [pid 961194:tid 961437] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/av.php"] [unique_id "amudpfSWp157EsYqB3oR0gAAAHE"]
[Thu Jul 30 13:53:25.663846 2026] [security2:error] [pid 961194:tid 961393] [client 84.233.212.33:56894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ahk.tqa.temporary.site"] [uri "/index.php"] [unique_id "amudpfSWp157EsYqB3oRzgAAAEU"]
[Thu Jul 30 13:53:25.708058 2026] [security2:error] [pid 961194:tid 961359] [client 20.104.18.253:7168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/block-library/admin.php"] [unique_id "amudpfSWp157EsYqB3oR1AAAACM"]
[Thu Jul 30 13:53:25.830022 2026] [security2:error] [pid 961194:tid 961441] [client 103.242.199.184:50719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudpfSWp157EsYqB3oR2QAAAHU"]
[Thu Jul 30 13:53:25.830126 2026] [security2:error] [pid 961194:tid 961441] [client 103.242.199.184:50719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudpfSWp157EsYqB3oR2QAAAHU"]
[Thu Jul 30 13:53:26.313231 2026] [security2:error] [pid 961194:tid 961326] [client 20.104.18.253:7939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/components/about.php"] [unique_id "amudpvSWp157EsYqB3oR6AAAAAI"]
[Thu Jul 30 13:53:26.570993 2026] [security2:error] [pid 961194:tid 961412] [client 84.233.212.33:57249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/.env"] [unique_id "amudpvSWp157EsYqB3oR7AAAAFg"]
[Thu Jul 30 13:53:26.682896 2026] [security2:error] [pid 961194:tid 961362] [client 189.6.88.213:64203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudpvSWp157EsYqB3oR8wAAACY"]
[Thu Jul 30 13:53:26.683054 2026] [security2:error] [pid 961194:tid 961362] [client 189.6.88.213:64203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudpvSWp157EsYqB3oR8wAAACY"]
[Thu Jul 30 13:53:26.910353 2026] [security2:error] [pid 961194:tid 961411] [client 20.104.18.253:7998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/default.php"] [unique_id "amudpvSWp157EsYqB3oR_QAAAFc"]
[Thu Jul 30 13:53:26.989556 2026] [security2:error] [pid 961194:tid 961350] [client 172.213.232.128:60042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/atomlib.php"] [unique_id "amudpvSWp157EsYqB3oR_gAAABo"]
[Thu Jul 30 13:53:27.183035 2026] [security2:error] [pid 961194:tid 961404] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/shell.php"] [unique_id "amudp_SWp157EsYqB3oSCAAAAFA"]
[Thu Jul 30 13:53:27.183149 2026] [security2:error] [pid 961194:tid 961404] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/shell.php"] [unique_id "amudp_SWp157EsYqB3oSCAAAAFA"]
[Thu Jul 30 13:53:27.305156 2026] [security2:error] [pid 961194:tid 961451] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudpvSWp157EsYqB3oR9gAAAH8"]
[Thu Jul 30 13:53:27.488804 2026] [security2:error] [pid 961194:tid 961438] [client 84.233.212.33:57590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/db.sql"] [unique_id "amudp_SWp157EsYqB3oSEAAAAHI"]
[Thu Jul 30 13:53:27.509038 2026] [security2:error] [pid 961194:tid 961365] [client 20.104.18.253:7950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/edit-site/about.php"] [unique_id "amudp_SWp157EsYqB3oSEQAAACk"]
[Thu Jul 30 13:53:27.534169 2026] [security2:error] [pid 961194:tid 961392] [client 172.213.232.128:61207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/autoload_classmap.php"] [unique_id "amudp_SWp157EsYqB3oSEgAAAEQ"]
[Thu Jul 30 13:53:27.697551 2026] [security2:error] [pid 961194:tid 961403] [client 181.116.200.68:2273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudp_SWp157EsYqB3oSHQAAAE8"]
[Thu Jul 30 13:53:27.697659 2026] [security2:error] [pid 961194:tid 961403] [client 181.116.200.68:2273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudp_SWp157EsYqB3oSHQAAAE8"]
[Thu Jul 30 13:53:27.698437 2026] [security2:error] [pid 961194:tid 961433] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/storage/index.php"] [unique_id "amudp_SWp157EsYqB3oSHgAAAG0"]
[Thu Jul 30 13:53:27.698518 2026] [security2:error] [pid 961194:tid 961433] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/storage/index.php"] [unique_id "amudp_SWp157EsYqB3oSHgAAAG0"]
[Thu Jul 30 13:53:28.127097 2026] [security2:error] [pid 961194:tid 961445] [client 20.104.18.253:7970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/edit-widgets/about.php"] [unique_id "amudqPSWp157EsYqB3oSJgAAAHk"]
[Thu Jul 30 13:53:28.208494 2026] [security2:error] [pid 961194:tid 961376] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/w.php"] [unique_id "amudqPSWp157EsYqB3oSLgAAADQ"]
[Thu Jul 30 13:53:28.208622 2026] [security2:error] [pid 961194:tid 961376] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/w.php"] [unique_id "amudqPSWp157EsYqB3oSLgAAADQ"]
[Thu Jul 30 13:53:28.237776 2026] [core:notice] [pid 961194:tid 961241] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:28.311241 2026] [security2:error] [pid 961194:tid 961417] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudp_SWp157EsYqB3oSCwAAXTA"]
[Thu Jul 30 13:53:28.341657 2026] [security2:error] [pid 961194:tid 961331] [client 172.213.232.128:53237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/bb.php"] [unique_id "amudqPSWp157EsYqB3oSMQAAAAc"]
[Thu Jul 30 13:53:28.360076 2026] [security2:error] [pid 961194:tid 961432] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudp_SWp157EsYqB3oSCgAAbCo"]
[Thu Jul 30 13:53:28.413311 2026] [security2:error] [pid 961194:tid 961439] [client 84.233.212.33:57889] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/dump.sql"] [unique_id "amudqPSWp157EsYqB3oSMgAAAHM"]
[Thu Jul 30 13:53:28.723276 2026] [security2:error] [pid 961194:tid 961391] [client 20.104.18.253:7171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/edit-widgets/index.php"] [unique_id "amudqPSWp157EsYqB3oSOgAAAEM"]
[Thu Jul 30 13:53:28.739614 2026] [security2:error] [pid 961194:tid 961413] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/jp.php"] [unique_id "amudqPSWp157EsYqB3oSOwAAAFk"]
[Thu Jul 30 13:53:28.739757 2026] [security2:error] [pid 961194:tid 961413] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/jp.php"] [unique_id "amudqPSWp157EsYqB3oSOwAAAFk"]
[Thu Jul 30 13:53:29.019206 2026] [security2:error] [pid 961194:tid 961425] [client 78.40.199.55:58072] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "78.40.199.55" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "online-hope.com"] [uri "/wp-comments-post.php"] [unique_id "amudqfSWp157EsYqB3oSQwAAAGU"], referer: https://online-hope.com/hello-world/
[Thu Jul 30 13:53:29.019331 2026] [security2:error] [pid 961194:tid 961425] [client 78.40.199.55:58072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/wp-comments-post.php"] [unique_id "amudqfSWp157EsYqB3oSQwAAAGU"], referer: https://online-hope.com/hello-world/
[Thu Jul 30 13:53:29.312163 2026] [security2:error] [pid 961194:tid 961393] [client 84.233.212.33:58168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/database.sql"] [unique_id "amudqfSWp157EsYqB3oSSwAAAEU"]
[Thu Jul 30 13:53:29.322911 2026] [security2:error] [pid 961194:tid 961414] [client 20.104.18.253:7937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/list-reusable-blocks/themes.php"] [unique_id "amudqfSWp157EsYqB3oSTAAAAFo"]
[Thu Jul 30 13:53:29.468921 2026] [security2:error] [pid 961194:tid 961370] [client 172.213.232.128:60054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/bnm.php"] [unique_id "amudqfSWp157EsYqB3oSTQAAAC4"]
[Thu Jul 30 13:53:29.920809 2026] [security2:error] [pid 961194:tid 961389] [client 20.104.18.253:7949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/niil.php"] [unique_id "amudqfSWp157EsYqB3oSWwAAAEE"]
[Thu Jul 30 13:53:30.034123 2026] [security2:error] [pid 961194:tid 961416] [client 172.213.232.128:60092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/bootstrap.php"] [unique_id "amudqvSWp157EsYqB3oSXAAAAFw"]
[Thu Jul 30 13:53:30.199587 2026] [security2:error] [pid 961194:tid 961412] [client 84.233.212.33:58437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/backup.sql"] [unique_id "amudqvSWp157EsYqB3oSYAAAAFg"]
[Thu Jul 30 13:53:30.263766 2026] [security2:error] [pid 961194:tid 961249] [remote 57.141.0.47:42364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/PBB/article/view/7401/2957"] [unique_id "amudqvSWp157EsYqB3oSZAAAezY"]
[Thu Jul 30 13:53:30.341418 2026] [proxy:error] [pid 961194:tid 961439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:30.341489 2026] [proxy_http:error] [pid 961194:tid 961439] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:30.342177 2026] [proxy:error] [pid 961194:tid 961439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:30.342228 2026] [proxy_http:error] [pid 961194:tid 961439] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:30.342329 2026] [security2:error] [pid 961194:tid 961439] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.nexiummedication.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amudqvSWp157EsYqB3oSaQAAAHM"]
[Thu Jul 30 13:53:30.401405 2026] [security2:error] [pid 961194:tid 961326] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudqfSWp157EsYqB3oSWgAAAiA"]
[Thu Jul 30 13:53:30.542465 2026] [security2:error] [pid 961194:tid 961388] [client 20.104.18.253:7207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/test.php"] [unique_id "amudqvSWp157EsYqB3oSbQAAAEA"]
[Thu Jul 30 13:53:30.884714 2026] [security2:error] [pid 961194:tid 961369] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/ws77.php"] [unique_id "amudqvSWp157EsYqB3oSdwAAAC0"]
[Thu Jul 30 13:53:30.884796 2026] [security2:error] [pid 961194:tid 961369] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/ws77.php"] [unique_id "amudqvSWp157EsYqB3oSdwAAAC0"]
[Thu Jul 30 13:53:31.098310 2026] [security2:error] [pid 961194:tid 961438] [client 84.233.212.33:58708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/config/db.sql"] [unique_id "amudq_SWp157EsYqB3oSewAAAHI"]
[Thu Jul 30 13:53:31.140245 2026] [security2:error] [pid 961194:tid 961387] [client 20.104.18.253:7203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/vendor/vcard.php"] [unique_id "amudq_SWp157EsYqB3oSfAAAAD8"]
[Thu Jul 30 13:53:31.431161 2026] [security2:error] [pid 961194:tid 961450] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/blass.php"] [unique_id "amudq_SWp157EsYqB3oSgwAAAH4"]
[Thu Jul 30 13:53:31.431255 2026] [security2:error] [pid 961194:tid 961450] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/blass.php"] [unique_id "amudq_SWp157EsYqB3oSgwAAAH4"]
[Thu Jul 30 13:53:31.739730 2026] [security2:error] [pid 961194:tid 961405] [client 20.104.18.253:7980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/widgets/about.php"] [unique_id "amudq_SWp157EsYqB3oSiAAAAFE"]
[Thu Jul 30 13:53:31.883497 2026] [security2:error] [pid 961194:tid 961379] [client 43.173.180.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/208"] [unique_id "amudq_SWp157EsYqB3oShwAAADc"]
[Thu Jul 30 13:53:31.984479 2026] [security2:error] [pid 961194:tid 961377] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-info.php"] [unique_id "amudq_SWp157EsYqB3oSjwAAADU"]
[Thu Jul 30 13:53:31.984602 2026] [security2:error] [pid 961194:tid 961377] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-info.php"] [unique_id "amudq_SWp157EsYqB3oSjwAAADU"]
[Thu Jul 30 13:53:32.012197 2026] [security2:error] [pid 961194:tid 961389] [client 84.233.212.33:59067] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/sql/db.sql"] [unique_id "amudrPSWp157EsYqB3oSkQAAAEE"]
[Thu Jul 30 13:53:32.060149 2026] [core:notice] [pid 961194:tid 961334] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:32.424615 2026] [core:notice] [pid 961194:tid 961278] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:32.519928 2026] [security2:error] [pid 961194:tid 961378] [client 172.213.232.128:51656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/buy.php"] [unique_id "amudrPSWp157EsYqB3oSnQAAADY"]
[Thu Jul 30 13:53:32.547272 2026] [security2:error] [pid 961194:tid 961430] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/CDX1.php"] [unique_id "amudrPSWp157EsYqB3oSngAAAGo"]
[Thu Jul 30 13:53:32.547376 2026] [security2:error] [pid 961194:tid 961430] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/CDX1.php"] [unique_id "amudrPSWp157EsYqB3oSngAAAGo"]
[Thu Jul 30 13:53:32.599027 2026] [security2:error] [pid 961194:tid 961406] [client 20.104.18.253:7172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dist/wp-login.php"] [unique_id "amudrPSWp157EsYqB3oSlQAAAFI"]
[Thu Jul 30 13:53:32.693890 2026] [core:notice] [pid 961194:tid 961273] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:32.907322 2026] [security2:error] [pid 961194:tid 961348] [client 84.233.212.33:59479] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/data/dump.sql"] [unique_id "amudrPSWp157EsYqB3oSqQAAABg"]
[Thu Jul 30 13:53:33.102147 2026] [security2:error] [pid 961194:tid 961345] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wpc.php"] [unique_id "amudrfSWp157EsYqB3oSrQAAABU"]
[Thu Jul 30 13:53:33.102256 2026] [security2:error] [pid 961194:tid 961345] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wpc.php"] [unique_id "amudrfSWp157EsYqB3oSrQAAABU"]
[Thu Jul 30 13:53:33.130754 2026] [core:notice] [pid 961194:tid 961274] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:33.197423 2026] [security2:error] [pid 961194:tid 961434] [client 20.104.18.253:7961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/distadmin.php"] [unique_id "amudrfSWp157EsYqB3oSsgAAAG4"]
[Thu Jul 30 13:53:33.530193 2026] [security2:error] [pid 961194:tid 961374] [client 172.213.232.128:51693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/chosen.php"] [unique_id "amudrfSWp157EsYqB3oSugAAADI"]
[Thu Jul 30 13:53:33.628618 2026] [security2:error] [pid 961194:tid 961380] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/jga.php"] [unique_id "amudrfSWp157EsYqB3oSuwAAADg"]
[Thu Jul 30 13:53:33.628731 2026] [security2:error] [pid 961194:tid 961380] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/jga.php"] [unique_id "amudrfSWp157EsYqB3oSuwAAADg"]
[Thu Jul 30 13:53:33.798331 2026] [security2:error] [pid 961194:tid 961440] [client 20.104.18.253:7174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/distalfa.php"] [unique_id "amudrfSWp157EsYqB3oSvwAAAHQ"]
[Thu Jul 30 13:53:33.806194 2026] [security2:error] [pid 961194:tid 961340] [client 84.233.212.33:59778] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/backups/database.sql"] [unique_id "amudrfSWp157EsYqB3oSwAAAABA"]
[Thu Jul 30 13:53:34.161096 2026] [security2:error] [pid 961194:tid 961433] [client 172.213.232.128:55360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/class-wp-image.php"] [unique_id "amudrvSWp157EsYqB3oSyAAAAG0"]
[Thu Jul 30 13:53:34.415780 2026] [security2:error] [pid 961194:tid 961435] [client 20.104.18.253:7191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/distbypass.php"] [unique_id "amudrvSWp157EsYqB3oSzAAAAG8"]
[Thu Jul 30 13:53:34.734199 2026] [security2:error] [pid 961194:tid 961412] [client 84.233.212.33:60035] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/mysql.sql"] [unique_id "amudrvSWp157EsYqB3oS1AAAAFg"]
[Thu Jul 30 13:53:34.800190 2026] [proxy:error] [pid 961194:tid 961367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:34.800260 2026] [proxy_http:error] [pid 961194:tid 961367] [client 18.211.55.47:51805] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:34.800873 2026] [proxy:error] [pid 961194:tid 961367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:34.800926 2026] [proxy_http:error] [pid 961194:tid 961367] [client 18.211.55.47:51805] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:34.805798 2026] [proxy:error] [pid 961194:tid 961378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:34.805876 2026] [proxy_http:error] [pid 961194:tid 961378] [client 44.216.125.112:10471] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:34.806449 2026] [proxy:error] [pid 961194:tid 961378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:34.806496 2026] [proxy_http:error] [pid 961194:tid 961378] [client 44.216.125.112:10471] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:34.917694 2026] [security2:error] [pid 961194:tid 961407] [client 78.167.1.90:54402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudrvSWp157EsYqB3oS4wAAAFM"]
[Thu Jul 30 13:53:34.918364 2026] [security2:error] [pid 961194:tid 961407] [client 78.167.1.90:54402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudrvSWp157EsYqB3oS4wAAAFM"]
[Thu Jul 30 13:53:34.971718 2026] [security2:error] [pid 961194:tid 961362] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/666.php"] [unique_id "amudrvSWp157EsYqB3oS6gAAACY"]
[Thu Jul 30 13:53:34.971831 2026] [security2:error] [pid 961194:tid 961362] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/666.php"] [unique_id "amudrvSWp157EsYqB3oS6gAAACY"]
[Thu Jul 30 13:53:35.015517 2026] [security2:error] [pid 961194:tid 961363] [client 20.104.18.253:7996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/distk.php"] [unique_id "amudr_SWp157EsYqB3oS6wAAACc"]
[Thu Jul 30 13:53:35.017577 2026] [security2:error] [pid 961194:tid 961439] [client 103.190.40.154:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudr_SWp157EsYqB3oS7AAAAHM"]
[Thu Jul 30 13:53:35.017705 2026] [security2:error] [pid 961194:tid 961439] [client 103.190.40.154:5508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudr_SWp157EsYqB3oS7AAAAHM"]
[Thu Jul 30 13:53:35.616769 2026] [security2:error] [pid 961194:tid 961446] [client 20.104.18.253:7181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/distwp.php"] [unique_id "amudr_SWp157EsYqB3oS-gAAAHo"]
[Thu Jul 30 13:53:35.647660 2026] [security2:error] [pid 961194:tid 961327] [client 84.233.212.33:60317] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ahk.tqa.temporary.site"] [uri "/db_backup.sql"] [unique_id "amudr_SWp157EsYqB3oS-wAAAAM"]
[Thu Jul 30 13:53:36.213663 2026] [security2:error] [pid 961194:tid 961359] [client 20.104.18.253:7175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/doc.php"] [unique_id "amudsPSWp157EsYqB3oTBgAAACM"]
[Thu Jul 30 13:53:36.488929 2026] [security2:error] [pid 961194:tid 961435] [client 103.242.199.184:51279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudsPSWp157EsYqB3oTEQAAAG8"]
[Thu Jul 30 13:53:36.489114 2026] [security2:error] [pid 961194:tid 961435] [client 103.242.199.184:51279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudsPSWp157EsYqB3oTEQAAAG8"]
[Thu Jul 30 13:53:36.812627 2026] [security2:error] [pid 961194:tid 961447] [client 20.104.18.253:7202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/docadmin.php"] [unique_id "amudsPSWp157EsYqB3oTGgAAAHs"]
[Thu Jul 30 13:53:36.881009 2026] [security2:error] [pid 961194:tid 961406] [client 127.0.0.1:33978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amudsPSWp157EsYqB3oTHgAAAFI"]
[Thu Jul 30 13:53:36.881078 2026] [security2:error] [pid 961194:tid 961430] [client 127.0.0.1:33964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kfo.lku.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amudsPSWp157EsYqB3oTHQAAAGo"]
[Thu Jul 30 13:53:36.881157 2026] [security2:error] [pid 961194:tid 961386] [client 74.7.241.147:44048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kfo.lku.temporary.site"] [uri "/robots.txt"] [unique_id "amudsPSWp157EsYqB3oTHAAAPnI"]
[Thu Jul 30 13:53:37.054754 2026] [security2:error] [pid 961194:tid 961407] [client 50.6.43.217:40432] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amudsfSWp157EsYqB3oTIQAAAFM"]
[Thu Jul 30 13:53:37.079648 2026] [security2:error] [pid 961194:tid 961326] [client 50.6.43.217:40442] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amudsfSWp157EsYqB3oTIwAAAAI"]
[Thu Jul 30 13:53:37.083885 2026] [security2:error] [pid 961194:tid 961336] [client 66.249.73.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.black-devil-shop.com"] [uri "/index.php"] [unique_id "amudsPSWp157EsYqB3oTDgAAAAw"]
[Thu Jul 30 13:53:37.357585 2026] [security2:error] [pid 961194:tid 961345] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/htaccess.php"] [unique_id "amudsfSWp157EsYqB3oTLQAAABU"]
[Thu Jul 30 13:53:37.357698 2026] [security2:error] [pid 961194:tid 961345] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/htaccess.php"] [unique_id "amudsfSWp157EsYqB3oTLQAAABU"]
[Thu Jul 30 13:53:37.411430 2026] [security2:error] [pid 961194:tid 961384] [client 20.104.18.253:7218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/docalfa.php"] [unique_id "amudsfSWp157EsYqB3oTLgAAADw"]
[Thu Jul 30 13:53:38.011693 2026] [security2:error] [pid 961194:tid 961390] [client 20.104.18.253:7945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/docbypass.php"] [unique_id "amudsvSWp157EsYqB3oTRQAAAEI"]
[Thu Jul 30 13:53:38.204541 2026] [security2:error] [pid 961194:tid 961370] [client 181.116.200.68:29569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudsvSWp157EsYqB3oTTAAAAC4"]
[Thu Jul 30 13:53:38.204639 2026] [security2:error] [pid 961194:tid 961370] [client 181.116.200.68:29569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudsvSWp157EsYqB3oTTAAAAC4"]
[Thu Jul 30 13:53:38.558426 2026] [security2:error] [pid 961194:tid 961332] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudsfSWp157EsYqB3oTQwAACAU"]
[Thu Jul 30 13:53:38.607964 2026] [security2:error] [pid 961194:tid 961415] [client 20.104.18.253:7968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/docindex.php"] [unique_id "amudsvSWp157EsYqB3oTVAAAAFs"]
[Thu Jul 30 13:53:38.734876 2026] [security2:error] [pid 961194:tid 961399] [client 172.213.232.128:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/classsmtps.php"] [unique_id "amudsvSWp157EsYqB3oTWAAAAEs"]
[Thu Jul 30 13:53:38.865648 2026] [security2:error] [pid 961194:tid 961446] [client 189.6.88.213:64776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudsvSWp157EsYqB3oTWQAAAHo"]
[Thu Jul 30 13:53:38.865923 2026] [security2:error] [pid 961194:tid 961446] [client 189.6.88.213:64776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudsvSWp157EsYqB3oTWQAAAHo"]
[Thu Jul 30 13:53:39.206078 2026] [security2:error] [pid 961194:tid 961386] [client 20.104.18.253:7991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/dock.php"] [unique_id "amuds_SWp157EsYqB3oTYgAAAD4"]
[Thu Jul 30 13:53:39.464386 2026] [security2:error] [pid 961194:tid 961357] [client 172.213.232.128:61247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/classwithtostring.php"] [unique_id "amuds_SWp157EsYqB3oTaQAAACE"]
[Thu Jul 30 13:53:39.810276 2026] [security2:error] [pid 961194:tid 961391] [client 20.104.18.253:7169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/docsadmin.php"] [unique_id "amuds_SWp157EsYqB3oTcAAAAEM"]
[Thu Jul 30 13:53:39.857066 2026] [security2:error] [pid 961194:tid 961411] [client 50.6.43.217:15684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuds_SWp157EsYqB3oTYQAAAFc"]
[Thu Jul 30 13:53:40.147931 2026] [security2:error] [pid 961194:tid 961392] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/m.php"] [unique_id "amudtPSWp157EsYqB3oTdgAAAEQ"]
[Thu Jul 30 13:53:40.148095 2026] [security2:error] [pid 961194:tid 961392] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/m.php"] [unique_id "amudtPSWp157EsYqB3oTdgAAAEQ"]
[Thu Jul 30 13:53:40.189996 2026] [security2:error] [pid 961194:tid 961334] [client 172.213.232.128:55998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/config.php"] [unique_id "amudtPSWp157EsYqB3oTegAAAAo"]
[Thu Jul 30 13:53:40.410275 2026] [security2:error] [pid 961194:tid 961423] [client 20.104.18.253:7204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/docsalfa.php"] [unique_id "amudtPSWp157EsYqB3oTfgAAAGM"]
[Thu Jul 30 13:53:40.595192 2026] [security2:error] [pid 961194:tid 961434] [client 50.6.43.217:15696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuds_SWp157EsYqB3oTcQAAAG4"]
[Thu Jul 30 13:53:40.646906 2026] [security2:error] [pid 961194:tid 961393] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/file.php"] [unique_id "amudtPSWp157EsYqB3oTggAAAEU"]
[Thu Jul 30 13:53:40.647034 2026] [security2:error] [pid 961194:tid 961393] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/file.php"] [unique_id "amudtPSWp157EsYqB3oTggAAAEU"]
[Thu Jul 30 13:53:41.194092 2026] [security2:error] [pid 961194:tid 961420] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/.dj/index.php"] [unique_id "amudtfSWp157EsYqB3oTjwAAAGA"]
[Thu Jul 30 13:53:41.194186 2026] [security2:error] [pid 961194:tid 961420] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/.dj/index.php"] [unique_id "amudtfSWp157EsYqB3oTjwAAAGA"]
[Thu Jul 30 13:53:41.685949 2026] [security2:error] [pid 961194:tid 961415] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-admin/maint/index.php"] [unique_id "amudtfSWp157EsYqB3oTlwAAAFs"]
[Thu Jul 30 13:53:41.686066 2026] [security2:error] [pid 961194:tid 961415] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-admin/maint/index.php"] [unique_id "amudtfSWp157EsYqB3oTlwAAAFs"]
[Thu Jul 30 13:53:41.931725 2026] [autoindex:error] [pid 961194:tid 961367] [client 3.225.222.228:8798] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:53:41.985421 2026] [autoindex:error] [pid 961194:tid 961344] [client 44.213.206.96:7609] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:53:42.185592 2026] [security2:error] [pid 961194:tid 961230] [remote 5.161.62.209:12958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.kingstarenterprises.com"] [uri "/.env"] [unique_id "amudtvSWp157EsYqB3oTqwAAUyM"]
[Thu Jul 30 13:53:42.196127 2026] [security2:error] [pid 961194:tid 961324] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/pages.php"] [unique_id "amudtvSWp157EsYqB3oTrAAAAAA"]
[Thu Jul 30 13:53:42.196273 2026] [security2:error] [pid 961194:tid 961324] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/pages.php"] [unique_id "amudtvSWp157EsYqB3oTrAAAAAA"]
[Thu Jul 30 13:53:42.269745 2026] [security2:error] [pid 961194:tid 961201] [remote 216.38.28.47:46698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amudtvSWp157EsYqB3oTpwAAFwY"]
[Thu Jul 30 13:53:42.607920 2026] [security2:error] [pid 961194:tid 961242] [remote 74.7.243.224:44886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/uploads/content/login.php"] [unique_id "amudtvSWp157EsYqB3oTugAAfS8"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/uploads/content/1781252056_BAGIRA.jpg
[Thu Jul 30 13:53:42.753448 2026] [security2:error] [pid 961194:tid 961372] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/adminfuns.php"] [unique_id "amudtvSWp157EsYqB3oTvgAAADA"]
[Thu Jul 30 13:53:42.753584 2026] [security2:error] [pid 961194:tid 961372] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/adminfuns.php"] [unique_id "amudtvSWp157EsYqB3oTvgAAADA"]
[Thu Jul 30 13:53:43.118984 2026] [security2:error] [pid 961194:tid 961442] [client 64.118.140.170:27963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2015/08/The-beach-people_beach-majorelle-bag-300x273.jpg"] [unique_id "amudt_SWp157EsYqB3oTxQAAAHY"]
[Thu Jul 30 13:53:43.302738 2026] [security2:error] [pid 961194:tid 961370] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/aa.php"] [unique_id "amudt_SWp157EsYqB3oTygAAAC4"]
[Thu Jul 30 13:53:43.302846 2026] [security2:error] [pid 961194:tid 961370] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/aa.php"] [unique_id "amudt_SWp157EsYqB3oTygAAAC4"]
[Thu Jul 30 13:53:43.438190 2026] [core:notice] [pid 961194:tid 961360] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:43.661680 2026] [core:notice] [pid 961194:tid 961250] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:43.827367 2026] [proxy:error] [pid 961194:tid 961389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:43.827463 2026] [proxy_http:error] [pid 961194:tid 961389] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:43.828391 2026] [proxy:error] [pid 961194:tid 961389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:43.828450 2026] [proxy_http:error] [pid 961194:tid 961389] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:43.828577 2026] [security2:error] [pid 961194:tid 961389] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.nexiummedication.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amudt_SWp157EsYqB3oT1wAAAEE"]
[Thu Jul 30 13:53:44.368264 2026] [security2:error] [pid 961194:tid 961403] [client 172.213.232.128:61229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/core.php"] [unique_id "amuduPSWp157EsYqB3oT4gAAAE8"]
[Thu Jul 30 13:53:44.387678 2026] [security2:error] [pid 961194:tid 961435] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/classwithtostring.php"] [unique_id "amuduPSWp157EsYqB3oT4wAAAG8"]
[Thu Jul 30 13:53:44.387760 2026] [security2:error] [pid 961194:tid 961435] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/classwithtostring.php"] [unique_id "amuduPSWp157EsYqB3oT4wAAAG8"]
[Thu Jul 30 13:53:44.888539 2026] [security2:error] [pid 961194:tid 961391] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/about.php"] [unique_id "amuduPSWp157EsYqB3oT7wAAAEM"]
[Thu Jul 30 13:53:44.888691 2026] [security2:error] [pid 961194:tid 961391] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/about.php"] [unique_id "amuduPSWp157EsYqB3oT7wAAAEM"]
[Thu Jul 30 13:53:45.008316 2026] [core:notice] [pid 961194:tid 961422] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:45.272352 2026] [security2:error] [pid 961194:tid 961428] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuduPSWp157EsYqB3oT5wAAaDM"]
[Thu Jul 30 13:53:45.277749 2026] [security2:error] [pid 961194:tid 961428] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuduPSWp157EsYqB3oT6AAAaDA"]
[Thu Jul 30 13:53:45.312017 2026] [security2:error] [pid 961194:tid 961225] [remote 52.167.144.138:64424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/demo/article.php"] [unique_id "amudufSWp157EsYqB3oT-AAATB4"]
[Thu Jul 30 13:53:45.371668 2026] [core:error] [pid 961194:tid 961419] [client 2a03:2880:10ff:a:::0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:53:45.371697 2026] [core:error] [pid 961194:tid 961419] [client 2a03:2880:10ff:a:::0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:53:45.385044 2026] [security2:error] [pid 961194:tid 961385] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/goods.php"] [unique_id "amudufSWp157EsYqB3oT_AAAAD0"]
[Thu Jul 30 13:53:45.385142 2026] [security2:error] [pid 961194:tid 961385] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/goods.php"] [unique_id "amudufSWp157EsYqB3oT_AAAAD0"]
[Thu Jul 30 13:53:45.521943 2026] [security2:error] [pid 961194:tid 961380] [client 78.167.1.90:54769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudufSWp157EsYqB3oUAQAAADg"]
[Thu Jul 30 13:53:45.522325 2026] [security2:error] [pid 961194:tid 961380] [client 78.167.1.90:54769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudufSWp157EsYqB3oUAQAAADg"]
[Thu Jul 30 13:53:45.585439 2026] [core:notice] [pid 961194:tid 961437] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:45.889249 2026] [security2:error] [pid 961194:tid 961398] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/php8.php"] [unique_id "amudufSWp157EsYqB3oUCgAAAEo"]
[Thu Jul 30 13:53:45.889349 2026] [security2:error] [pid 961194:tid 961398] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/php8.php"] [unique_id "amudufSWp157EsYqB3oUCgAAAEo"]
[Thu Jul 30 13:53:45.907899 2026] [security2:error] [pid 961194:tid 961352] [client 103.190.40.154:22191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudufSWp157EsYqB3oUDAAAABw"]
[Thu Jul 30 13:53:45.908055 2026] [security2:error] [pid 961194:tid 961352] [client 103.190.40.154:22191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudufSWp157EsYqB3oUDAAAABw"]
[Thu Jul 30 13:53:45.937326 2026] [security2:error] [pid 961194:tid 961450] [client 52.167.144.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amudufSWp157EsYqB3oUBAAAAH4"]
[Thu Jul 30 13:53:46.532224 2026] [core:notice] [pid 961194:tid 961367] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:46.658724 2026] [security2:error] [pid 961194:tid 961372] [client 172.213.232.128:53241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/css.php"] [unique_id "amuduvSWp157EsYqB3oUHwAAADA"]
[Thu Jul 30 13:53:47.210814 2026] [security2:error] [pid 961194:tid 961337] [client 103.242.199.184:51847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudu_SWp157EsYqB3oUMQAAAA0"]
[Thu Jul 30 13:53:47.210944 2026] [security2:error] [pid 961194:tid 961337] [client 103.242.199.184:51847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudu_SWp157EsYqB3oUMQAAAA0"]
[Thu Jul 30 13:53:47.477695 2026] [security2:error] [pid 961194:tid 961391] [client 34.10.41.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amudu_SWp157EsYqB3oUMAAAAEM"]
[Thu Jul 30 13:53:47.477718 2026] [security2:error] [pid 961194:tid 961391] [client 34.10.41.220:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amudu_SWp157EsYqB3oUMAAAAEM"]
[Thu Jul 30 13:53:47.478503 2026] [security2:error] [pid 961194:tid 961382] [client 34.10.41.220:38232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "skcarrental.ae"] [uri "/.git/config"] [unique_id "amudu_SWp157EsYqB3oULgAAADo"]
[Thu Jul 30 13:53:48.118687 2026] [security2:error] [pid 961194:tid 961369] [client 172.213.232.128:53198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/database.php"] [unique_id "amudvPSWp157EsYqB3oUSgAAAC0"]
[Thu Jul 30 13:53:48.178970 2026] [security2:error] [pid 961194:tid 961342] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/info.php"] [unique_id "amudvPSWp157EsYqB3oUSwAAABI"]
[Thu Jul 30 13:53:48.179096 2026] [security2:error] [pid 961194:tid 961342] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/info.php"] [unique_id "amudvPSWp157EsYqB3oUSwAAABI"]
[Thu Jul 30 13:53:48.314452 2026] [core:notice] [pid 961194:tid 961338] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:48.698994 2026] [security2:error] [pid 961194:tid 961361] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/class-t.api.php"] [unique_id "amudvPSWp157EsYqB3oUVwAAACU"]
[Thu Jul 30 13:53:48.699124 2026] [security2:error] [pid 961194:tid 961361] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/class-t.api.php"] [unique_id "amudvPSWp157EsYqB3oUVwAAACU"]
[Thu Jul 30 13:53:48.874596 2026] [security2:error] [pid 961194:tid 961376] [client 181.116.200.68:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudvPSWp157EsYqB3oUWQAAADQ"]
[Thu Jul 30 13:53:48.874710 2026] [security2:error] [pid 961194:tid 961376] [client 181.116.200.68:55740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudvPSWp157EsYqB3oUWQAAADQ"]
[Thu Jul 30 13:53:48.982841 2026] [security2:error] [pid 961194:tid 961378] [client 172.213.232.128:55992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/db.php"] [unique_id "amudvPSWp157EsYqB3oUXAAAADY"]
[Thu Jul 30 13:53:49.230475 2026] [security2:error] [pid 961194:tid 961396] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/simple.php"] [unique_id "amudvfSWp157EsYqB3oUZAAAAEg"]
[Thu Jul 30 13:53:49.230624 2026] [security2:error] [pid 961194:tid 961396] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/simple.php"] [unique_id "amudvfSWp157EsYqB3oUZAAAAEg"]
[Thu Jul 30 13:53:49.242693 2026] [security2:error] [pid 961194:tid 961287] [remote 157.66.47.83:52204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.47.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amudvfSWp157EsYqB3oUZQAAWFw"]
[Thu Jul 30 13:53:49.751634 2026] [security2:error] [pid 961194:tid 961422] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/ioxi-o.php"] [unique_id "amudvfSWp157EsYqB3oUbwAAAGI"]
[Thu Jul 30 13:53:49.751729 2026] [security2:error] [pid 961194:tid 961422] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/ioxi-o.php"] [unique_id "amudvfSWp157EsYqB3oUbwAAAGI"]
[Thu Jul 30 13:53:49.778071 2026] [security2:error] [pid 961194:tid 961290] [remote 97.74.93.24:59364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amudvfSWp157EsYqB3oUcQAAJ18"]
[Thu Jul 30 13:53:50.256070 2026] [proxy:error] [pid 961194:tid 961385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:50.256138 2026] [proxy_http:error] [pid 961194:tid 961385] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:50.256693 2026] [proxy:error] [pid 961194:tid 961385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:50.256736 2026] [proxy_http:error] [pid 961194:tid 961385] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:50.256821 2026] [security2:error] [pid 961194:tid 961385] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.nexiummedication.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amudvvSWp157EsYqB3oUfAAAAD0"]
[Thu Jul 30 13:53:50.776736 2026] [security2:error] [pid 961194:tid 961420] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp.php"] [unique_id "amudvvSWp157EsYqB3oUhgAAAGA"]
[Thu Jul 30 13:53:50.776839 2026] [security2:error] [pid 961194:tid 961420] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp.php"] [unique_id "amudvvSWp157EsYqB3oUhgAAAGA"]
[Thu Jul 30 13:53:51.143116 2026] [security2:error] [pid 961194:tid 961437] [client 172.213.232.128:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/default.php"] [unique_id "amudv_SWp157EsYqB3oUjwAAAHE"]
[Thu Jul 30 13:53:52.272998 2026] [core:notice] [pid 961194:tid 961412] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:52.315927 2026] [security2:error] [pid 961194:tid 961436] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/file2.php"] [unique_id "amudwPSWp157EsYqB3oUqwAAAHA"]
[Thu Jul 30 13:53:52.316036 2026] [security2:error] [pid 961194:tid 961436] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/file2.php"] [unique_id "amudwPSWp157EsYqB3oUqwAAAHA"]
[Thu Jul 30 13:53:52.622556 2026] [security2:error] [pid 961194:tid 961300] [remote 40.77.167.72:7364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/11069960395670/aprochef.php"] [unique_id "amudwPSWp157EsYqB3oUtgAARGk"]
[Thu Jul 30 13:53:52.829057 2026] [security2:error] [pid 961194:tid 961418] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/images/class-config.php"] [unique_id "amudwPSWp157EsYqB3oUvAAAAF4"]
[Thu Jul 30 13:53:52.829161 2026] [security2:error] [pid 961194:tid 961418] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/images/class-config.php"] [unique_id "amudwPSWp157EsYqB3oUvAAAAF4"]
[Thu Jul 30 13:53:53.127240 2026] [security2:error] [pid 961194:tid 961353] [client 172.213.232.128:57713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/dropdown.php"] [unique_id "amudwfSWp157EsYqB3oUxQAAAB0"]
[Thu Jul 30 13:53:53.726731 2026] [security2:error] [pid 961194:tid 961209] [remote 40.77.167.72:7364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/181236424603/donatef.php"] [unique_id "amudwfSWp157EsYqB3oU0gAAYQ4"]
[Thu Jul 30 13:53:53.840616 2026] [security2:error] [pid 961194:tid 961360] [client 139.28.219.70:41336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amudwfSWp157EsYqB3oU1gAAACQ"]
[Thu Jul 30 13:53:54.085973 2026] [security2:error] [pid 961194:tid 961330] [client 20.125.96.254:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.nexiummedication.store"] [uri "/1.php"] [unique_id "amudwvSWp157EsYqB3oU2wAAAAY"]
[Thu Jul 30 13:53:54.086112 2026] [security2:error] [pid 961194:tid 961330] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/1.php"] [unique_id "amudwvSWp157EsYqB3oU2wAAAAY"]
[Thu Jul 30 13:53:54.086229 2026] [security2:error] [pid 961194:tid 961330] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/1.php"] [unique_id "amudwvSWp157EsYqB3oU2wAAAAY"]
[Thu Jul 30 13:53:54.127458 2026] [security2:error] [pid 961194:tid 961444] [client 139.28.219.70:41342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereasshop.com"] [uri "/xmlrpc.php"] [unique_id "amudwvSWp157EsYqB3oU3AAAAHg"]
[Thu Jul 30 13:53:54.301243 2026] [security2:error] [pid 961194:tid 961326] [client 172.213.232.128:43563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/edit.php"] [unique_id "amudwvSWp157EsYqB3oU5wAAAAI"]
[Thu Jul 30 13:53:54.639631 2026] [security2:error] [pid 961194:tid 961375] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/222.php"] [unique_id "amudwvSWp157EsYqB3oU7wAAADM"]
[Thu Jul 30 13:53:54.639778 2026] [security2:error] [pid 961194:tid 961375] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/222.php"] [unique_id "amudwvSWp157EsYqB3oU7wAAADM"]
[Thu Jul 30 13:53:55.088260 2026] [security2:error] [pid 961194:tid 961397] [client 139.28.219.70:41354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amudw_SWp157EsYqB3oU-QAAAEk"]
[Thu Jul 30 13:53:55.117191 2026] [security2:error] [pid 961194:tid 961367] [client 88.236.177.171:37010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amudwvSWp157EsYqB3oU5gAAACs"], referer: http://pkf.jo
[Thu Jul 30 13:53:55.158664 2026] [security2:error] [pid 961194:tid 961347] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudwvSWp157EsYqB3oU7gAAABc"]
[Thu Jul 30 13:53:55.159794 2026] [security2:error] [pid 961194:tid 961402] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/themes.php"] [unique_id "amudw_SWp157EsYqB3oU-wAAAE4"]
[Thu Jul 30 13:53:55.159879 2026] [security2:error] [pid 961194:tid 961402] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/themes.php"] [unique_id "amudw_SWp157EsYqB3oU-wAAAE4"]
[Thu Jul 30 13:53:55.313253 2026] [security2:error] [pid 961194:tid 961418] [client 172.213.232.128:51641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/f35.php"] [unique_id "amudw_SWp157EsYqB3oU_wAAAF4"]
[Thu Jul 30 13:53:55.354701 2026] [security2:error] [pid 961194:tid 961380] [client 139.28.219.70:41370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amudw_SWp157EsYqB3oVAwAAADg"]
[Thu Jul 30 13:53:55.618296 2026] [security2:error] [pid 961194:tid 961371] [client 139.28.219.70:41378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amudw_SWp157EsYqB3oVCAAAAC8"]
[Thu Jul 30 13:53:55.637407 2026] [security2:error] [pid 961194:tid 961329] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/admin.php"] [unique_id "amudw_SWp157EsYqB3oVCQAAAAU"]
[Thu Jul 30 13:53:55.637571 2026] [security2:error] [pid 961194:tid 961329] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/admin.php"] [unique_id "amudw_SWp157EsYqB3oVCQAAAAU"]
[Thu Jul 30 13:53:55.891931 2026] [security2:error] [pid 961194:tid 961327] [client 139.28.219.70:41388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amudw_SWp157EsYqB3oVEAAAAAM"]
[Thu Jul 30 13:53:56.033090 2026] [security2:error] [pid 961194:tid 961395] [client 172.213.232.128:51596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carrescia.com"] [uri "/f7.php"] [unique_id "amudxPSWp157EsYqB3oVFAAAAEc"]
[Thu Jul 30 13:53:56.147835 2026] [security2:error] [pid 961194:tid 961417] [client 139.28.219.70:41402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amudxPSWp157EsYqB3oVGAAAAF0"]
[Thu Jul 30 13:53:56.153382 2026] [security2:error] [pid 961194:tid 961389] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/dropdown.php"] [unique_id "amudxPSWp157EsYqB3oVGQAAAEE"]
[Thu Jul 30 13:53:56.153458 2026] [security2:error] [pid 961194:tid 961389] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/dropdown.php"] [unique_id "amudxPSWp157EsYqB3oVGQAAAEE"]
[Thu Jul 30 13:53:56.424163 2026] [security2:error] [pid 961194:tid 961326] [client 139.28.219.70:41410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amudxPSWp157EsYqB3oVIgAAAAI"]
[Thu Jul 30 13:53:56.551663 2026] [security2:error] [pid 961194:tid 961361] [client 181.46.112.123:9138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amudxPSWp157EsYqB3oVGgAAACU"], referer: http://pkf.jo
[Thu Jul 30 13:53:56.590203 2026] [proxy:error] [pid 961194:tid 961435] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:56.590283 2026] [proxy_http:error] [pid 961194:tid 961435] [client 147.90.209.31:50223] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:56.590955 2026] [proxy:error] [pid 961194:tid 961435] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:53:56.591010 2026] [proxy_http:error] [pid 961194:tid 961435] [client 147.90.209.31:50223] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:53:56.677325 2026] [security2:error] [pid 961194:tid 961355] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/inputs.php"] [unique_id "amudxPSWp157EsYqB3oVJwAAAB8"]
[Thu Jul 30 13:53:56.677457 2026] [security2:error] [pid 961194:tid 961355] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/inputs.php"] [unique_id "amudxPSWp157EsYqB3oVJwAAAB8"]
[Thu Jul 30 13:53:56.690494 2026] [security2:error] [pid 961194:tid 961406] [client 103.166.100.166:60394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amudxPSWp157EsYqB3oVIQAAAFI"], referer: http://pkf.jo
[Thu Jul 30 13:53:56.695774 2026] [security2:error] [pid 961194:tid 961383] [client 139.28.219.70:41418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amudxPSWp157EsYqB3oVKAAAADs"]
[Thu Jul 30 13:53:56.761008 2026] [security2:error] [pid 961194:tid 961357] [client 103.190.40.154:21652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudxPSWp157EsYqB3oVKQAAACE"]
[Thu Jul 30 13:53:56.761151 2026] [security2:error] [pid 961194:tid 961357] [client 103.190.40.154:21652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudxPSWp157EsYqB3oVKQAAACE"]
[Thu Jul 30 13:53:56.972505 2026] [security2:error] [pid 961194:tid 961325] [client 139.28.219.70:41420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amudxPSWp157EsYqB3oVMAAAAAE"]
[Thu Jul 30 13:53:57.211452 2026] [security2:error] [pid 961194:tid 961436] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/100.php"] [unique_id "amudxfSWp157EsYqB3oVNQAAAHA"]
[Thu Jul 30 13:53:57.211569 2026] [security2:error] [pid 961194:tid 961436] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/100.php"] [unique_id "amudxfSWp157EsYqB3oVNQAAAHA"]
[Thu Jul 30 13:53:57.239346 2026] [security2:error] [pid 961194:tid 961391] [client 139.28.219.70:41424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amudxfSWp157EsYqB3oVNgAAAEM"]
[Thu Jul 30 13:53:57.512158 2026] [security2:error] [pid 961194:tid 961414] [client 139.28.219.70:41432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amudxfSWp157EsYqB3oVPQAAAFo"]
[Thu Jul 30 13:53:57.775381 2026] [security2:error] [pid 961194:tid 961353] [client 139.28.219.70:41442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amudxfSWp157EsYqB3oVRQAAAB0"]
[Thu Jul 30 13:53:57.836047 2026] [security2:error] [pid 961194:tid 961366] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudxfSWp157EsYqB3oVNAAAKhk"]
[Thu Jul 30 13:53:57.863097 2026] [security2:error] [pid 961194:tid 961403] [client 31.206.138.19:64062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amudxfSWp157EsYqB3oVPgAAAE8"], referer: http://pkf.jo
[Thu Jul 30 13:53:57.872662 2026] [security2:error] [pid 961194:tid 961387] [client 103.242.199.184:52408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudxfSWp157EsYqB3oVTAAAAD8"]
[Thu Jul 30 13:53:57.872760 2026] [security2:error] [pid 961194:tid 961387] [client 103.242.199.184:52408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amudxfSWp157EsYqB3oVTAAAAD8"]
[Thu Jul 30 13:53:58.056896 2026] [security2:error] [pid 961194:tid 961335] [client 139.28.219.70:41454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amudxvSWp157EsYqB3oVUgAAAAs"]
[Thu Jul 30 13:53:58.330477 2026] [security2:error] [pid 961194:tid 961405] [client 139.28.219.70:41466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amudxvSWp157EsYqB3oVWAAAAFE"]
[Thu Jul 30 13:53:58.598136 2026] [security2:error] [pid 961194:tid 961326] [client 139.28.219.70:41476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tereasshop.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amudxvSWp157EsYqB3oVYQAAAAI"]
[Thu Jul 30 13:53:58.983878 2026] [security2:error] [pid 961194:tid 961336] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/autoload_classmap/function.php"] [unique_id "amudxvSWp157EsYqB3oVbAAAAAw"]
[Thu Jul 30 13:53:58.984009 2026] [security2:error] [pid 961194:tid 961336] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/autoload_classmap/function.php"] [unique_id "amudxvSWp157EsYqB3oVbAAAAAw"]
[Thu Jul 30 13:53:59.049879 2026] [security2:error] [pid 961194:tid 961444] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudxvSWp157EsYqB3oVXAAAeB8"]
[Thu Jul 30 13:53:59.138072 2026] [core:notice] [pid 961194:tid 961218] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:59.143391 2026] [security2:error] [pid 961194:tid 961256] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/goh.php"] [unique_id "amudx_SWp157EsYqB3oVcQAAdz0"]
[Thu Jul 30 13:53:59.145801 2026] [security2:error] [pid 961194:tid 961412] [client 40.77.178.149:2692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/$$$call$$$/page/page/css"] [unique_id "amudxvSWp157EsYqB3oVaAAAWBc"], referer: https://ejournalugj.com/index.php/agroswagati/issue/current
[Thu Jul 30 13:53:59.252664 2026] [core:notice] [pid 961194:tid 961253] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:53:59.257919 2026] [security2:error] [pid 961194:tid 961439] [client 40.77.177.198:42881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/$$$call$$$/page/page/css"] [unique_id "amudxvSWp157EsYqB3oVbQAAczo"], referer: https://ejournalugj.com/index.php/agroswagati/issue/current
[Thu Jul 30 13:53:59.468687 2026] [security2:error] [pid 961194:tid 961400] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/php.php"] [unique_id "amudx_SWp157EsYqB3oVewAAAEw"]
[Thu Jul 30 13:53:59.468781 2026] [security2:error] [pid 961194:tid 961400] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/php.php"] [unique_id "amudx_SWp157EsYqB3oVewAAAEw"]
[Thu Jul 30 13:53:59.581023 2026] [security2:error] [pid 961194:tid 961404] [client 181.116.200.68:61793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudx_SWp157EsYqB3oVfwAAAFA"]
[Thu Jul 30 13:53:59.581131 2026] [security2:error] [pid 961194:tid 961404] [client 181.116.200.68:61793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudx_SWp157EsYqB3oVfwAAAFA"]
[Thu Jul 30 13:53:59.844523 2026] [security2:error] [pid 961194:tid 961264] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/gold.php"] [unique_id "amudx_SWp157EsYqB3oVhAAAfUU"]
[Thu Jul 30 13:54:00.022046 2026] [security2:error] [pid 961194:tid 961359] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/t.php"] [unique_id "amudyPSWp157EsYqB3oVhQAAACM"]
[Thu Jul 30 13:54:00.022175 2026] [security2:error] [pid 961194:tid 961359] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/t.php"] [unique_id "amudyPSWp157EsYqB3oVhQAAACM"]
[Thu Jul 30 13:54:00.082588 2026] [security2:error] [pid 961194:tid 961302] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/golden.php"] [unique_id "amudyPSWp157EsYqB3oViQAASms"]
[Thu Jul 30 13:54:00.318904 2026] [security2:error] [pid 961194:tid 961260] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/good.php"] [unique_id "amudyPSWp157EsYqB3oVkAAAX0E"]
[Thu Jul 30 13:54:00.555946 2026] [security2:error] [pid 961194:tid 961231] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/goods.php"] [unique_id "amudyPSWp157EsYqB3oVlwAAdiQ"]
[Thu Jul 30 13:54:00.792802 2026] [security2:error] [pid 961194:tid 961252] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/google-seo-rank/module.php"] [unique_id "amudyPSWp157EsYqB3oVnAAAWzk"]
[Thu Jul 30 13:54:01.032030 2026] [security2:error] [pid 961194:tid 961263] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/goto.php"] [unique_id "amudyfSWp157EsYqB3oVoAAAJkQ"]
[Thu Jul 30 13:54:01.181005 2026] [security2:error] [pid 961194:tid 961401] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-blink.php"] [unique_id "amudyfSWp157EsYqB3oVqAAAAE0"]
[Thu Jul 30 13:54:01.181088 2026] [security2:error] [pid 961194:tid 961401] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-blink.php"] [unique_id "amudyfSWp157EsYqB3oVqAAAAE0"]
[Thu Jul 30 13:54:01.273278 2026] [security2:error] [pid 961194:tid 961227] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/gqksqsxc.php"] [unique_id "amudyfSWp157EsYqB3oVqwAAJSA"]
[Thu Jul 30 13:54:01.413885 2026] [security2:error] [pid 961194:tid 961413] [client 85.208.96.204:25200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/18/candidaturas-laranjas-justica-julga-improcedentes-aijes-que-pediam-cassacao-de-vereadores-em-campina/"] [unique_id "amudyfSWp157EsYqB3oVrQAAAFk"]
[Thu Jul 30 13:54:01.414029 2026] [security2:error] [pid 961194:tid 961413] [client 85.208.96.204:25200] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/18/candidaturas-laranjas-justica-julga-improcedentes-aijes-que-pediam-cassacao-de-vereadores-em-campina/"] [unique_id "amudyfSWp157EsYqB3oVrQAAAFk"]
[Thu Jul 30 13:54:01.533141 2026] [security2:error] [pid 961194:tid 961262] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/gravity_forms/h/e/d/a/yjoxrfglsep.php"] [unique_id "amudyfSWp157EsYqB3oVrgAAZEM"]
[Thu Jul 30 13:54:01.748490 2026] [security2:error] [pid 961194:tid 961412] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/xfun.php"] [unique_id "amudyfSWp157EsYqB3oVtgAAAFg"]
[Thu Jul 30 13:54:01.748590 2026] [security2:error] [pid 961194:tid 961412] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/xfun.php"] [unique_id "amudyfSWp157EsYqB3oVtgAAAFg"]
[Thu Jul 30 13:54:01.770796 2026] [security2:error] [pid 961194:tid 961254] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/great.php"] [unique_id "amudyfSWp157EsYqB3oVtwAAATs"]
[Thu Jul 30 13:54:02.008046 2026] [security2:error] [pid 961194:tid 961279] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/grey.php"] [unique_id "amudyvSWp157EsYqB3oVvAAAaFQ"]
[Thu Jul 30 13:54:02.197114 2026] [security2:error] [pid 961194:tid 961331] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amudyfSWp157EsYqB3oVrwAAB0c"]
[Thu Jul 30 13:54:02.249420 2026] [security2:error] [pid 961194:tid 961276] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/gto.php"] [unique_id "amudyvSWp157EsYqB3oVwwAAN1E"]
[Thu Jul 30 13:54:02.296566 2026] [security2:error] [pid 961194:tid 961402] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/p.php"] [unique_id "amudyvSWp157EsYqB3oVxQAAAE4"]
[Thu Jul 30 13:54:02.296655 2026] [security2:error] [pid 961194:tid 961402] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/p.php"] [unique_id "amudyvSWp157EsYqB3oVxQAAAE4"]
[Thu Jul 30 13:54:02.486598 2026] [security2:error] [pid 961194:tid 961267] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/gtt.php"] [unique_id "amudyvSWp157EsYqB3oVyQAAOkg"]
[Thu Jul 30 13:54:02.562293 2026] [security2:error] [pid 961194:tid 961400] [client 189.7.125.159:9694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amudyvSWp157EsYqB3oVxAAAAEw"], referer: http://pkf.jo
[Thu Jul 30 13:54:02.702284 2026] [security2:error] [pid 961194:tid 961386] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amudyfSWp157EsYqB3oVpwAAPjY"]
[Thu Jul 30 13:54:02.723110 2026] [security2:error] [pid 961194:tid 961280] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/gu.php"] [unique_id "amudyvSWp157EsYqB3oV0AAAT1U"]
[Thu Jul 30 13:54:02.830272 2026] [security2:error] [pid 961194:tid 961441] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/themes/admin.php"] [unique_id "amudyvSWp157EsYqB3oV1AAAAHU"]
[Thu Jul 30 13:54:02.830351 2026] [security2:error] [pid 961194:tid 961441] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/themes/admin.php"] [unique_id "amudyvSWp157EsYqB3oV1AAAAHU"]
[Thu Jul 30 13:54:02.905042 2026] [security2:error] [pid 961194:tid 961285] [remote 57.141.0.2:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amudyvSWp157EsYqB3oV2AAAEFo"]
[Thu Jul 30 13:54:02.974886 2026] [security2:error] [pid 961194:tid 961272] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/gvy6f.php"] [unique_id "amudyvSWp157EsYqB3oV2QAAKE0"]
[Thu Jul 30 13:54:03.211044 2026] [security2:error] [pid 961194:tid 961273] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/gzdecode.php"] [unique_id "amudy_SWp157EsYqB3oV4AAAVk4"]
[Thu Jul 30 13:54:03.447640 2026] [security2:error] [pid 961194:tid 961275] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/h.php"] [unique_id "amudy_SWp157EsYqB3oV6gAAe1A"]
[Thu Jul 30 13:54:03.683283 2026] [security2:error] [pid 961194:tid 961296] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/haf.php"] [unique_id "amudy_SWp157EsYqB3oV7QAAAmU"]
[Thu Jul 30 13:54:03.844487 2026] [security2:error] [pid 961194:tid 961336] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/aaa.php"] [unique_id "amudy_SWp157EsYqB3oV9QAAAAw"]
[Thu Jul 30 13:54:03.844834 2026] [security2:error] [pid 961194:tid 961336] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/aaa.php"] [unique_id "amudy_SWp157EsYqB3oV9QAAAAw"]
[Thu Jul 30 13:54:03.919055 2026] [security2:error] [pid 961194:tid 961299] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/harga.php"] [unique_id "amudy_SWp157EsYqB3oV9wAABGg"]
[Thu Jul 30 13:54:04.156784 2026] [security2:error] [pid 961194:tid 961316] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/has.php"] [unique_id "amudzPSWp157EsYqB3oV_QAAWHk"]
[Thu Jul 30 13:54:04.399784 2026] [security2:error] [pid 961194:tid 961283] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/hava.php"] [unique_id "amudzPSWp157EsYqB3oWCQAAa1g"]
[Thu Jul 30 13:54:04.639600 2026] [security2:error] [pid 961194:tid 961295] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/hax.php"] [unique_id "amudzPSWp157EsYqB3oWEQAAPmQ"]
[Thu Jul 30 13:54:04.875972 2026] [security2:error] [pid 961194:tid 961312] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/he.php"] [unique_id "amudzPSWp157EsYqB3oWGAAAL3U"]
[Thu Jul 30 13:54:04.934259 2026] [security2:error] [pid 961194:tid 961347] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amudzPSWp157EsYqB3oWCAAAABc"]
[Thu Jul 30 13:54:04.962912 2026] [security2:error] [pid 961194:tid 961340] [client 172.237.109.114:42263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/product-details.php"] [unique_id "amudzPSWp157EsYqB3oWGQAAABA"]
[Thu Jul 30 13:54:05.139800 2026] [security2:error] [pid 961194:tid 961206] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/header.php"] [unique_id "amudzfSWp157EsYqB3oWHQAARgs"]
[Thu Jul 30 13:54:05.375789 2026] [security2:error] [pid 961194:tid 961318] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/health.php"] [unique_id "amudzfSWp157EsYqB3oWKwAAQXs"]
[Thu Jul 30 13:54:05.517417 2026] [core:notice] [pid 961194:tid 961301] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:05.521565 2026] [security2:error] [pid 961194:tid 961385] [client 65.184.49.117:44105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/4907"] [unique_id "amudzfSWp157EsYqB3oWHgAAPWo"]
[Thu Jul 30 13:54:05.536411 2026] [security2:error] [pid 961194:tid 961324] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/7.php"] [unique_id "amudzfSWp157EsYqB3oWOwAAAAA"]
[Thu Jul 30 13:54:05.536509 2026] [security2:error] [pid 961194:tid 961324] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/7.php"] [unique_id "amudzfSWp157EsYqB3oWOwAAAAA"]
[Thu Jul 30 13:54:05.612148 2026] [security2:error] [pid 961194:tid 961203] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/hehe.php"] [unique_id "amudzfSWp157EsYqB3oWPAAAVAg"]
[Thu Jul 30 13:54:05.847744 2026] [security2:error] [pid 961194:tid 961234] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/hello-element/footer.php"] [unique_id "amudzfSWp157EsYqB3oWVAAAJSc"]
[Thu Jul 30 13:54:06.040045 2026] [security2:error] [pid 961194:tid 961350] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/file5.php"] [unique_id "amudzvSWp157EsYqB3oWWwAAABo"]
[Thu Jul 30 13:54:06.040151 2026] [security2:error] [pid 961194:tid 961350] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/file5.php"] [unique_id "amudzvSWp157EsYqB3oWWwAAABo"]
[Thu Jul 30 13:54:06.083452 2026] [security2:error] [pid 961194:tid 961245] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/hello.php"] [unique_id "amudzvSWp157EsYqB3oWXAAAeDI"]
[Thu Jul 30 13:54:06.142082 2026] [core:notice] [pid 961194:tid 961238] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:06.318679 2026] [security2:error] [pid 961194:tid 961228] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/hello_dolly_v2.php"] [unique_id "amudzvSWp157EsYqB3oWXwAAQyE"]
[Thu Jul 30 13:54:06.535919 2026] [security2:error] [pid 961194:tid 961349] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/makeasmtp.php"] [unique_id "amudzvSWp157EsYqB3oWZwAAABk"]
[Thu Jul 30 13:54:06.536036 2026] [security2:error] [pid 961194:tid 961349] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/makeasmtp.php"] [unique_id "amudzvSWp157EsYqB3oWZwAAABk"]
[Thu Jul 30 13:54:06.554203 2026] [security2:error] [pid 961194:tid 961244] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/helloapx/wp-apxupx.php"] [unique_id "amudzvSWp157EsYqB3oWagAAazE"]
[Thu Jul 30 13:54:06.650814 2026] [security2:error] [pid 961194:tid 961429] [client 78.167.1.90:57227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudzvSWp157EsYqB3oWawAAAGk"]
[Thu Jul 30 13:54:06.651289 2026] [security2:error] [pid 961194:tid 961429] [client 78.167.1.90:57227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amudzvSWp157EsYqB3oWawAAAGk"]
[Thu Jul 30 13:54:06.790624 2026] [security2:error] [pid 961194:tid 961226] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/hellopress/wp_filemanager.php"] [unique_id "amudzvSWp157EsYqB3oWbAAAUB8"]
[Thu Jul 30 13:54:07.026768 2026] [security2:error] [pid 961194:tid 961253] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.markmocek.com"] [uri "/help.php"] [unique_id "amudz_SWp157EsYqB3oWdAAAKjo"]
[Thu Jul 30 13:54:07.062371 2026] [security2:error] [pid 961194:tid 961420] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/index.php"] [unique_id "amudz_SWp157EsYqB3oWeAAAAGA"]
[Thu Jul 30 13:54:07.062472 2026] [security2:error] [pid 961194:tid 961420] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/index.php"] [unique_id "amudz_SWp157EsYqB3oWeAAAAGA"]
[Thu Jul 30 13:54:07.553334 2026] [security2:error] [pid 961194:tid 961370] [client 41.221.64.225:60204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amudz_SWp157EsYqB3oWegAAAC4"], referer: http://pkf.jo
[Thu Jul 30 13:54:07.628103 2026] [security2:error] [pid 961194:tid 961410] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/atomlib.php"] [unique_id "amudz_SWp157EsYqB3oWhgAAAFY"]
[Thu Jul 30 13:54:07.628218 2026] [security2:error] [pid 961194:tid 961410] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/atomlib.php"] [unique_id "amudz_SWp157EsYqB3oWhgAAAFY"]
[Thu Jul 30 13:54:07.634511 2026] [security2:error] [pid 961194:tid 961440] [client 103.190.40.154:21171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudz_SWp157EsYqB3oWhwAAAHQ"]
[Thu Jul 30 13:54:07.634675 2026] [security2:error] [pid 961194:tid 961440] [client 103.190.40.154:21171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amudz_SWp157EsYqB3oWhwAAAHQ"]
[Thu Jul 30 13:54:08.007568 2026] [core:notice] [pid 961194:tid 961260] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.009764 2026] [core:notice] [pid 961194:tid 961237] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.012241 2026] [core:notice] [pid 961194:tid 961231] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.012346 2026] [security2:error] [pid 961194:tid 961390] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/index_php/index/---call---/page/page/css-name-font.css"] [unique_id "amudz_SWp157EsYqB3oWiwAAQkE"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.014400 2026] [security2:error] [pid 961194:tid 961390] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/index_php/index/---call---/page/page/css-name-stylesheet.css"] [unique_id "amudz_SWp157EsYqB3oWjAAAQio"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.016756 2026] [security2:error] [pid 961194:tid 961390] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/site/pageHeaderTitleImage_id_ID.jpg"] [unique_id "amudz_SWp157EsYqB3oWjQAAQiQ"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.019110 2026] [core:notice] [pid 961194:tid 961243] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.023481 2026] [security2:error] [pid 961194:tid 961390] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/lib/pkp/styles/fontawesome/fontawesome_v-3.3.0.17.css"] [unique_id "amudz_SWp157EsYqB3oWjgAAQjA"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.170235 2026] [security2:error] [pid 961194:tid 961378] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/min.php"] [unique_id "amud0PSWp157EsYqB3oWlgAAADY"]
[Thu Jul 30 13:54:08.170384 2026] [security2:error] [pid 961194:tid 961378] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/min.php"] [unique_id "amud0PSWp157EsYqB3oWlgAAADY"]
[Thu Jul 30 13:54:08.219328 2026] [core:notice] [pid 961194:tid 961258] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.219713 2026] [core:notice] [pid 961194:tid 961263] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.223101 2026] [core:notice] [pid 961194:tid 961227] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.223219 2026] [security2:error] [pid 961194:tid 961336] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWmwAADD8"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.223674 2026] [core:notice] [pid 961194:tid 961262] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.223691 2026] [core:notice] [pid 961194:tid 961261] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.223762 2026] [core:notice] [pid 961194:tid 961314] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.223773 2026] [security2:error] [pid 961194:tid 961336] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/17/journalThumbnail_en_US.png"] [unique_id "amud0PSWp157EsYqB3oWmgAADEQ"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.223823 2026] [core:notice] [pid 961194:tid 961271] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.223926 2026] [core:notice] [pid 961194:tid 961257] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.228361 2026] [security2:error] [pid 961194:tid 961336] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/33/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWoQAADEw"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.228747 2026] [security2:error] [pid 961194:tid 961336] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/32/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWnQAADEI"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.229215 2026] [security2:error] [pid 961194:tid 961336] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/39/journalThumbnail_en_US.png"] [unique_id "amud0PSWp157EsYqB3oWoAAADD4"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.229653 2026] [security2:error] [pid 961194:tid 961336] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/site/images/apranolo/Crossref_Logo_Stacked_RGB_SMALL.png"] [unique_id "amud0PSWp157EsYqB3oWnAAADCA"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.229803 2026] [security2:error] [pid 961194:tid 961336] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/19/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWngAADHc"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.230126 2026] [security2:error] [pid 961194:tid 961336] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/44/journalThumbnail_id_ID.png"] [unique_id "amud0PSWp157EsYqB3oWnwAADEM"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.423239 2026] [core:notice] [pid 961194:tid 961270] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.423582 2026] [core:notice] [pid 961194:tid 961279] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.426773 2026] [security2:error] [pid 961194:tid 961444] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/22/journalThumbnail_en_US.jpg"] [unique_id "amud0PSWp157EsYqB3oWpwAAeEs"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.427240 2026] [security2:error] [pid 961194:tid 961444] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/10/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWpgAAeFQ"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.430638 2026] [core:notice] [pid 961194:tid 961266] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.432184 2026] [core:notice] [pid 961194:tid 961276] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.432396 2026] [core:notice] [pid 961194:tid 961215] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.432447 2026] [core:notice] [pid 961194:tid 961269] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.434298 2026] [security2:error] [pid 961194:tid 961384] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/24/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWqAAAPEc"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.435653 2026] [security2:error] [pid 961194:tid 961384] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/8/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWqQAAPFE"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.435765 2026] [security2:error] [pid 961194:tid 961384] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/21/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWqgAAPBQ"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.435962 2026] [core:notice] [pid 961194:tid 961267] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.436178 2026] [core:notice] [pid 961194:tid 961265] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.436377 2026] [security2:error] [pid 961194:tid 961384] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/20/journalThumbnail_en_US.jpg"] [unique_id "amud0PSWp157EsYqB3oWqwAAPEo"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.440575 2026] [security2:error] [pid 961194:tid 961384] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/6/journalThumbnail_en_US.jpg"] [unique_id "amud0PSWp157EsYqB3oWrAAAPEg"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.440830 2026] [security2:error] [pid 961194:tid 961384] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/7/journalThumbnail_id_ID.png"] [unique_id "amud0PSWp157EsYqB3oWrQAAPEY"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.535100 2026] [security2:error] [pid 961194:tid 961278] [remote 57.141.0.45:55664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/404010317/feed/rss2/"] [unique_id "amud0PSWp157EsYqB3oWsgAAIVM"]
[Thu Jul 30 13:54:08.586669 2026] [security2:error] [pid 961194:tid 961365] [client 103.242.199.184:52973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud0PSWp157EsYqB3oWtgAAACk"]
[Thu Jul 30 13:54:08.586774 2026] [security2:error] [pid 961194:tid 961365] [client 103.242.199.184:52973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud0PSWp157EsYqB3oWtgAAACk"]
[Thu Jul 30 13:54:08.631046 2026] [core:notice] [pid 961194:tid 961281] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.631489 2026] [core:notice] [pid 961194:tid 961288] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.634695 2026] [security2:error] [pid 961194:tid 961429] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/3/journalThumbnail_en_US.jpg"] [unique_id "amud0PSWp157EsYqB3oWtwAAaVY"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.635121 2026] [security2:error] [pid 961194:tid 961429] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/14/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWuAAAaV0"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.637274 2026] [core:notice] [pid 961194:tid 961285] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.638751 2026] [core:notice] [pid 961194:tid 961274] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.638751 2026] [core:notice] [pid 961194:tid 961273] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.639648 2026] [core:notice] [pid 961194:tid 961287] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.641028 2026] [security2:error] [pid 961194:tid 961429] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/4/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWuQAAaVo"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.641896 2026] [security2:error] [pid 961194:tid 961429] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/1/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWvAAAaU4"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.643126 2026] [security2:error] [pid 961194:tid 961429] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/29/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWuwAAaU8"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.643820 2026] [security2:error] [pid 961194:tid 961429] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/35/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWvQAAaVw"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.645123 2026] [core:notice] [pid 961194:tid 961286] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.645255 2026] [core:notice] [pid 961194:tid 961275] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.648271 2026] [security2:error] [pid 961194:tid 961429] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/13/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWvgAAaVs"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.648495 2026] [security2:error] [pid 961194:tid 961429] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/25/journalThumbnail_id_ID.jpg"] [unique_id "amud0PSWp157EsYqB3oWvwAAaVA"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.833998 2026] [core:notice] [pid 961194:tid 961289] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.834027 2026] [core:notice] [pid 961194:tid 961282] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:08.837447 2026] [security2:error] [pid 961194:tid 961420] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/templates/images/ojs_brand.png"] [unique_id "amud0PSWp157EsYqB3oWywAAYFc"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.837769 2026] [security2:error] [pid 961194:tid 961420] [client 103.85.229.221:45103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/public/journals/2/journalThumbnail_id_ID.png"] [unique_id "amud0PSWp157EsYqB3oWygAAYF4"], referer: https://ejournalugj.com/index.php/JGST/article/view/4907
[Thu Jul 30 13:54:08.993465 2026] [security2:error] [pid 961194:tid 961364] [client 172.237.109.114:45092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amud0PSWp157EsYqB3oW1AAAACg"]
[Thu Jul 30 13:54:09.476437 2026] [security2:error] [pid 961194:tid 961326] [client 213.152.187.215:49764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amud0fSWp157EsYqB3oW4gAAAAI"]
[Thu Jul 30 13:54:09.476538 2026] [security2:error] [pid 961194:tid 961326] [client 213.152.187.215:49764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amud0fSWp157EsYqB3oW4gAAAAI"]
[Thu Jul 30 13:54:10.191728 2026] [security2:error] [pid 961194:tid 961381] [client 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amud0fSWp157EsYqB3oW4wAAOXE"]
[Thu Jul 30 13:54:10.205993 2026] [security2:error] [pid 961194:tid 961361] [client 181.116.200.68:57640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud0vSWp157EsYqB3oW8wAAACU"]
[Thu Jul 30 13:54:10.206105 2026] [security2:error] [pid 961194:tid 961361] [client 181.116.200.68:57640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud0vSWp157EsYqB3oW8wAAACU"]
[Thu Jul 30 13:54:10.276583 2026] [security2:error] [pid 961194:tid 961350] [client 102.206.97.16:52584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud0fSWp157EsYqB3oW7QAAABo"], referer: http://pkf.jo
[Thu Jul 30 13:54:10.479991 2026] [security2:error] [pid 961194:tid 961384] [client 200.46.55.130:54590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud0vSWp157EsYqB3oW8gAAADw"], referer: http://pkf.jo
[Thu Jul 30 13:54:10.805578 2026] [security2:error] [pid 961194:tid 961432] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/moon.php"] [unique_id "amud0vSWp157EsYqB3oXAgAAAGw"]
[Thu Jul 30 13:54:10.805713 2026] [security2:error] [pid 961194:tid 961432] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/moon.php"] [unique_id "amud0vSWp157EsYqB3oXAgAAAGw"]
[Thu Jul 30 13:54:11.337688 2026] [security2:error] [pid 961194:tid 961340] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/ws83.php"] [unique_id "amud0_SWp157EsYqB3oXEQAAABA"]
[Thu Jul 30 13:54:11.337791 2026] [security2:error] [pid 961194:tid 961340] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/ws83.php"] [unique_id "amud0_SWp157EsYqB3oXEQAAABA"]
[Thu Jul 30 13:54:11.454693 2026] [security2:error] [pid 961194:tid 961327] [client 178.134.103.44:33282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud0_SWp157EsYqB3oXCgAAAAM"], referer: http://pkf.jo
[Thu Jul 30 13:54:11.863139 2026] [security2:error] [pid 961194:tid 961377] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/403.php"] [unique_id "amud0_SWp157EsYqB3oXHAAAADU"]
[Thu Jul 30 13:54:11.863242 2026] [security2:error] [pid 961194:tid 961377] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/403.php"] [unique_id "amud0_SWp157EsYqB3oXHAAAADU"]
[Thu Jul 30 13:54:12.424532 2026] [security2:error] [pid 961194:tid 961383] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/api.php"] [unique_id "amud1PSWp157EsYqB3oXJgAAADs"]
[Thu Jul 30 13:54:12.424660 2026] [security2:error] [pid 961194:tid 961383] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/api.php"] [unique_id "amud1PSWp157EsYqB3oXJgAAADs"]
[Thu Jul 30 13:54:13.108036 2026] [security2:error] [pid 961194:tid 961391] [client 47.128.121.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amud1PSWp157EsYqB3oXNgAAAEM"]
[Thu Jul 30 13:54:14.082022 2026] [security2:error] [pid 961194:tid 961346] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/3.php"] [unique_id "amud1vSWp157EsYqB3oXTQAAABY"]
[Thu Jul 30 13:54:14.082137 2026] [security2:error] [pid 961194:tid 961346] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/3.php"] [unique_id "amud1vSWp157EsYqB3oXTQAAABY"]
[Thu Jul 30 13:54:14.442887 2026] [security2:error] [pid 961194:tid 961359] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amud1fSWp157EsYqB3oXRgAAIxo"]
[Thu Jul 30 13:54:16.044075 2026] [core:notice] [pid 961194:tid 961402] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:16.710966 2026] [proxy:error] [pid 961194:tid 961416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:16.711056 2026] [proxy_http:error] [pid 961194:tid 961416] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:16.711717 2026] [proxy:error] [pid 961194:tid 961416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:16.711763 2026] [proxy_http:error] [pid 961194:tid 961416] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:16.711870 2026] [security2:error] [pid 961194:tid 961416] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.nexiummedication.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amud2PSWp157EsYqB3oXiAAAAFw"]
[Thu Jul 30 13:54:16.720784 2026] [security2:error] [pid 961194:tid 961353] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amud2PSWp157EsYqB3oXfAAAHSc"]
[Thu Jul 30 13:54:17.227233 2026] [security2:error] [pid 961194:tid 961430] [client 78.167.1.90:54927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud2fSWp157EsYqB3oXmgAAAGo"]
[Thu Jul 30 13:54:17.227794 2026] [security2:error] [pid 961194:tid 961430] [client 78.167.1.90:54927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud2fSWp157EsYqB3oXmgAAAGo"]
[Thu Jul 30 13:54:17.745294 2026] [security2:error] [pid 961194:tid 961364] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amud2fSWp157EsYqB3oXmAAAKDg"]
[Thu Jul 30 13:54:17.778723 2026] [core:notice] [pid 961194:tid 961391] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:18.381301 2026] [security2:error] [pid 961194:tid 961428] [client 116.179.32.70:22526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/grageaku/index"] [unique_id "amud2vSWp157EsYqB3oXtAAAAGg"]
[Thu Jul 30 13:54:18.517251 2026] [security2:error] [pid 961194:tid 961380] [client 103.190.40.154:15799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud2vSWp157EsYqB3oXvwAAADg"]
[Thu Jul 30 13:54:18.517381 2026] [security2:error] [pid 961194:tid 961380] [client 103.190.40.154:15799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud2vSWp157EsYqB3oXvwAAADg"]
[Thu Jul 30 13:54:18.715749 2026] [security2:error] [pid 961194:tid 961393] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/ws77.php"] [unique_id "amud2vSWp157EsYqB3oXxgAAAEU"]
[Thu Jul 30 13:54:18.715864 2026] [security2:error] [pid 961194:tid 961393] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/ws77.php"] [unique_id "amud2vSWp157EsYqB3oXxgAAAEU"]
[Thu Jul 30 13:54:18.771753 2026] [security2:error] [pid 961194:tid 961417] [client 5.161.177.47:55006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amud2fSWp157EsYqB3oXnwAAAF0"], referer: https://globalmarks.pk/
[Thu Jul 30 13:54:19.041938 2026] [core:notice] [pid 961194:tid 961425] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:19.115029 2026] [proxy:error] [pid 961194:tid 961389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:19.115110 2026] [proxy_http:error] [pid 961194:tid 961389] [client 3.225.222.228:53345] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:19.115195 2026] [proxy:error] [pid 961194:tid 961356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:19.115252 2026] [proxy_http:error] [pid 961194:tid 961356] [client 3.225.222.228:57127] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:19.115701 2026] [proxy:error] [pid 961194:tid 961389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:19.115750 2026] [proxy_http:error] [pid 961194:tid 961389] [client 3.225.222.228:53345] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:19.115821 2026] [proxy:error] [pid 961194:tid 961356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:19.115864 2026] [proxy_http:error] [pid 961194:tid 961356] [client 3.225.222.228:57127] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:19.243469 2026] [security2:error] [pid 961194:tid 961412] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/nc4.php"] [unique_id "amud2_SWp157EsYqB3oX3wAAAFg"]
[Thu Jul 30 13:54:19.243587 2026] [security2:error] [pid 961194:tid 961412] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/nc4.php"] [unique_id "amud2_SWp157EsYqB3oX3wAAAFg"]
[Thu Jul 30 13:54:19.252071 2026] [security2:error] [pid 961194:tid 961338] [client 103.242.199.184:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud2_SWp157EsYqB3oX4AAAAA4"]
[Thu Jul 30 13:54:19.252168 2026] [security2:error] [pid 961194:tid 961338] [client 103.242.199.184:53541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud2_SWp157EsYqB3oX4AAAAA4"]
[Thu Jul 30 13:54:19.494908 2026] [security2:error] [pid 961194:tid 961347] [client 196.188.252.140:26267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud2_SWp157EsYqB3oX2wAAABc"], referer: http://pkf.jo
[Thu Jul 30 13:54:19.763538 2026] [security2:error] [pid 961194:tid 961364] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/as.php"] [unique_id "amud2_SWp157EsYqB3oX6wAAACg"]
[Thu Jul 30 13:54:19.763618 2026] [security2:error] [pid 961194:tid 961364] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/as.php"] [unique_id "amud2_SWp157EsYqB3oX6wAAACg"]
[Thu Jul 30 13:54:20.045044 2026] [core:notice] [pid 961194:tid 961448] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:20.252695 2026] [security2:error] [pid 961194:tid 961332] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/k.php"] [unique_id "amud3PSWp157EsYqB3oX_QAAAAg"]
[Thu Jul 30 13:54:20.252813 2026] [security2:error] [pid 961194:tid 961332] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/k.php"] [unique_id "amud3PSWp157EsYqB3oX_QAAAAg"]
[Thu Jul 30 13:54:20.283019 2026] [security2:error] [pid 961194:tid 961365] [client 84.190.184.152:40896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud2_SWp157EsYqB3oX7QAAACk"], referer: http://pkf.jo
[Thu Jul 30 13:54:20.748591 2026] [security2:error] [pid 961194:tid 961348] [client 181.116.200.68:43606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud3PSWp157EsYqB3oYEwAAABg"]
[Thu Jul 30 13:54:20.748713 2026] [security2:error] [pid 961194:tid 961348] [client 181.116.200.68:43606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud3PSWp157EsYqB3oYEwAAABg"]
[Thu Jul 30 13:54:21.049690 2026] [security2:error] [pid 961194:tid 961418] [client 66.249.73.98:56732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud3PSWp157EsYqB3oYDwAAAF4"]
[Thu Jul 30 13:54:21.367330 2026] [security2:error] [pid 961194:tid 961376] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/system_log.php"] [unique_id "amud3fSWp157EsYqB3oYIAAAADQ"]
[Thu Jul 30 13:54:21.367472 2026] [security2:error] [pid 961194:tid 961376] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/system_log.php"] [unique_id "amud3fSWp157EsYqB3oYIAAAADQ"]
[Thu Jul 30 13:54:22.626026 2026] [security2:error] [pid 961194:tid 961361] [client 89.238.167.134:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amud3vSWp157EsYqB3oYQgAAACU"]
[Thu Jul 30 13:54:22.626131 2026] [security2:error] [pid 961194:tid 961361] [client 89.238.167.134:38108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amud3vSWp157EsYqB3oYQgAAACU"]
[Thu Jul 30 13:54:22.716184 2026] [security2:error] [pid 961194:tid 961436] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/x.php"] [unique_id "amud3vSWp157EsYqB3oYQwAAAHA"]
[Thu Jul 30 13:54:22.716296 2026] [security2:error] [pid 961194:tid 961436] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/x.php"] [unique_id "amud3vSWp157EsYqB3oYQwAAAHA"]
[Thu Jul 30 13:54:23.249234 2026] [security2:error] [pid 961194:tid 961449] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/autoload_classmap.php"] [unique_id "amud3_SWp157EsYqB3oYTgAAAH0"]
[Thu Jul 30 13:54:23.249352 2026] [security2:error] [pid 961194:tid 961449] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/autoload_classmap.php"] [unique_id "amud3_SWp157EsYqB3oYTgAAAH0"]
[Thu Jul 30 13:54:23.744373 2026] [core:notice] [pid 961194:tid 961346] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:23.750799 2026] [core:notice] [pid 961194:tid 961335] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:23.757956 2026] [core:notice] [pid 961194:tid 961376] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:23.793227 2026] [security2:error] [pid 961194:tid 961389] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/test1.php"] [unique_id "amud3_SWp157EsYqB3oYYgAAAEE"]
[Thu Jul 30 13:54:23.793330 2026] [security2:error] [pid 961194:tid 961389] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/test1.php"] [unique_id "amud3_SWp157EsYqB3oYYgAAAEE"]
[Thu Jul 30 13:54:23.909713 2026] [security2:error] [pid 961194:tid 961425] [client 116.179.33.73:61393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.33.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/grageaku/$$$call$$$/page/page/css"] [unique_id "amud3_SWp157EsYqB3oYZwAAAGU"], referer: http://www.ejournalugj.com/
[Thu Jul 30 13:54:24.182903 2026] [security2:error] [pid 961194:tid 961437] [client 116.179.33.14:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.33.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/grageaku/$$$call$$$/page/page/css"] [unique_id "amud3_SWp157EsYqB3oYaQAAAHE"], referer: http://www.ejournalugj.com/
[Thu Jul 30 13:54:24.287949 2026] [security2:error] [pid 961194:tid 961405] [client 197.59.160.52:53870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud3_SWp157EsYqB3oYbAAAAFE"], referer: http://pkf.jo
[Thu Jul 30 13:54:24.338306 2026] [proxy:error] [pid 961194:tid 961411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:24.338393 2026] [proxy_http:error] [pid 961194:tid 961411] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:24.339113 2026] [proxy:error] [pid 961194:tid 961411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:24.339164 2026] [proxy_http:error] [pid 961194:tid 961411] [client 20.125.96.254:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:24.339282 2026] [security2:error] [pid 961194:tid 961411] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.nexiummedication.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amud4PSWp157EsYqB3oYcgAAAFc"]
[Thu Jul 30 13:54:24.479672 2026] [core:notice] [pid 961194:tid 961383] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:24.872759 2026] [security2:error] [pid 961194:tid 961436] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-signin.php"] [unique_id "amud4PSWp157EsYqB3oYgAAAAHA"]
[Thu Jul 30 13:54:24.872867 2026] [security2:error] [pid 961194:tid 961436] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-signin.php"] [unique_id "amud4PSWp157EsYqB3oYgAAAAHA"]
[Thu Jul 30 13:54:25.056192 2026] [proxy:error] [pid 961194:tid 961358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:25.056292 2026] [proxy_http:error] [pid 961194:tid 961358] [client 32.194.121.99:41922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:25.057057 2026] [proxy:error] [pid 961194:tid 961358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:25.057106 2026] [proxy_http:error] [pid 961194:tid 961358] [client 32.194.121.99:41922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:25.073538 2026] [proxy:error] [pid 961194:tid 961449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:25.073622 2026] [proxy_http:error] [pid 961194:tid 961449] [client 34.224.175.62:31027] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:25.074430 2026] [proxy:error] [pid 961194:tid 961449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:25.074488 2026] [proxy_http:error] [pid 961194:tid 961449] [client 34.224.175.62:31027] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:25.219699 2026] [security2:error] [pid 961194:tid 961334] [client 138.255.151.39:29277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud4PSWp157EsYqB3oYhAAAAAo"], referer: http://pkf.jo
[Thu Jul 30 13:54:25.359409 2026] [security2:error] [pid 961194:tid 961396] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/gg.php"] [unique_id "amud4fSWp157EsYqB3oYqAAAAEg"]
[Thu Jul 30 13:54:25.359558 2026] [security2:error] [pid 961194:tid 961396] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/gg.php"] [unique_id "amud4fSWp157EsYqB3oYqAAAAEg"]
[Thu Jul 30 13:54:25.629878 2026] [security2:error] [pid 961194:tid 961371] [client 37.228.209.223:30016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud4fSWp157EsYqB3oYpwAAAC8"], referer: http://pkf.jo
[Thu Jul 30 13:54:25.805294 2026] [security2:error] [pid 961194:tid 961392] [client 188.253.217.140:5576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud4fSWp157EsYqB3oYrAAAAEQ"], referer: http://pkf.jo
[Thu Jul 30 13:54:25.870610 2026] [security2:error] [pid 961194:tid 961399] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/class.php"] [unique_id "amud4fSWp157EsYqB3oYuQAAAEs"]
[Thu Jul 30 13:54:25.870706 2026] [security2:error] [pid 961194:tid 961399] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/class.php"] [unique_id "amud4fSWp157EsYqB3oYuQAAAEs"]
[Thu Jul 30 13:54:26.256282 2026] [security2:error] [pid 961194:tid 961325] [client 34.233.129.35:42828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.129.233.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lms.aetiiph.net"] [uri "/login/index.php"] [unique_id "amud4vSWp157EsYqB3oYxQAAAAE"]
[Thu Jul 30 13:54:26.348497 2026] [security2:error] [pid 961194:tid 961384] [client 34.224.175.62:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.175.224.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lms.aetiiph.net"] [uri "/login/index.php"] [unique_id "amud4vSWp157EsYqB3oYxwAAADw"]
[Thu Jul 30 13:54:26.389456 2026] [security2:error] [pid 961194:tid 961439] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/404.php"] [unique_id "amud4vSWp157EsYqB3oYyAAAAHM"]
[Thu Jul 30 13:54:26.389556 2026] [security2:error] [pid 961194:tid 961439] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/404.php"] [unique_id "amud4vSWp157EsYqB3oYyAAAAHM"]
[Thu Jul 30 13:54:26.883577 2026] [security2:error] [pid 961194:tid 961438] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/lite.php"] [unique_id "amud4vSWp157EsYqB3oY0gAAAHI"]
[Thu Jul 30 13:54:26.883671 2026] [security2:error] [pid 961194:tid 961438] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/lite.php"] [unique_id "amud4vSWp157EsYqB3oY0gAAAHI"]
[Thu Jul 30 13:54:27.854025 2026] [security2:error] [pid 961194:tid 961417] [client 78.167.1.90:56750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud4_SWp157EsYqB3oY9gAAAF0"]
[Thu Jul 30 13:54:27.854858 2026] [security2:error] [pid 961194:tid 961417] [client 78.167.1.90:56750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud4_SWp157EsYqB3oY9gAAAF0"]
[Thu Jul 30 13:54:29.284623 2026] [security2:error] [pid 961194:tid 961326] [client 103.190.40.154:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud5fSWp157EsYqB3oZMAAAAAI"]
[Thu Jul 30 13:54:29.284804 2026] [security2:error] [pid 961194:tid 961326] [client 103.190.40.154:21903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud5fSWp157EsYqB3oZMAAAAAI"]
[Thu Jul 30 13:54:29.531854 2026] [security2:error] [pid 961194:tid 961393] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/lock360.php"] [unique_id "amud5fSWp157EsYqB3oZNQAAAEU"]
[Thu Jul 30 13:54:29.532022 2026] [security2:error] [pid 961194:tid 961393] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/lock360.php"] [unique_id "amud5fSWp157EsYqB3oZNQAAAEU"]
[Thu Jul 30 13:54:29.700377 2026] [security2:error] [pid 961194:tid 961439] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amud5fSWp157EsYqB3oZJwAAAHM"]
[Thu Jul 30 13:54:29.876622 2026] [security2:error] [pid 961194:tid 961429] [client 103.242.199.184:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud5fSWp157EsYqB3oZOgAAAGk"]
[Thu Jul 30 13:54:29.876740 2026] [security2:error] [pid 961194:tid 961429] [client 103.242.199.184:54102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud5fSWp157EsYqB3oZOgAAAGk"]
[Thu Jul 30 13:54:30.878735 2026] [security2:error] [pid 961194:tid 961399] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/wp-conflg.php"] [unique_id "amud5vSWp157EsYqB3oZTgAAAEs"]
[Thu Jul 30 13:54:30.878853 2026] [security2:error] [pid 961194:tid 961399] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/wp-conflg.php"] [unique_id "amud5vSWp157EsYqB3oZTgAAAEs"]
[Thu Jul 30 13:54:31.007949 2026] [security2:error] [pid 961194:tid 961373] [client 189.6.88.213:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud5_SWp157EsYqB3oZTwAAADE"]
[Thu Jul 30 13:54:31.008093 2026] [security2:error] [pid 961194:tid 961373] [client 189.6.88.213:51531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud5_SWp157EsYqB3oZTwAAADE"]
[Thu Jul 30 13:54:31.395468 2026] [security2:error] [pid 961194:tid 961435] [client 181.116.200.68:36711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud5_SWp157EsYqB3oZWQAAAG8"]
[Thu Jul 30 13:54:31.395651 2026] [security2:error] [pid 961194:tid 961435] [client 181.116.200.68:36711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud5_SWp157EsYqB3oZWQAAAG8"]
[Thu Jul 30 13:54:31.423683 2026] [security2:error] [pid 961194:tid 961364] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-links-opml.php"] [unique_id "amud5_SWp157EsYqB3oZWgAAACg"]
[Thu Jul 30 13:54:31.423782 2026] [security2:error] [pid 961194:tid 961364] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-links-opml.php"] [unique_id "amud5_SWp157EsYqB3oZWgAAACg"]
[Thu Jul 30 13:54:31.942345 2026] [security2:error] [pid 961194:tid 961365] [client 35.204.109.104:4096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.wro.djb.temporary.site"] [uri "/"] [unique_id "amud5_SWp157EsYqB3oZcgAAACk"]
[Thu Jul 30 13:54:31.942468 2026] [security2:error] [pid 961194:tid 961365] [client 35.204.109.104:4096] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.wro.djb.temporary.site"] [uri "/"] [unique_id "amud5_SWp157EsYqB3oZcgAAACk"]
[Thu Jul 30 13:54:31.971586 2026] [security2:error] [pid 961194:tid 961398] [client 20.125.96.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/uploads/min.php"] [unique_id "amud5_SWp157EsYqB3oZcwAAAEo"]
[Thu Jul 30 13:54:31.971693 2026] [security2:error] [pid 961194:tid 961398] [client 20.125.96.254:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.nexiummedication.store"] [uri "/wp-content/uploads/min.php"] [unique_id "amud5_SWp157EsYqB3oZcwAAAEo"]
[Thu Jul 30 13:54:32.208587 2026] [security2:error] [pid 961194:tid 961374] [client 34.91.115.13:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/"] [unique_id "amud6PSWp157EsYqB3oZeAAAADI"]
[Thu Jul 30 13:54:32.208709 2026] [security2:error] [pid 961194:tid 961374] [client 34.91.115.13:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/"] [unique_id "amud6PSWp157EsYqB3oZeAAAADI"]
[Thu Jul 30 13:54:36.043008 2026] [security2:error] [pid 961194:tid 961367] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amud6_SWp157EsYqB3oZwAAAK3I"]
[Thu Jul 30 13:54:36.597304 2026] [security2:error] [pid 961194:tid 961416] [client 35.204.197.107:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/"] [unique_id "amud7PSWp157EsYqB3oZ2QAAAFw"]
[Thu Jul 30 13:54:36.597423 2026] [security2:error] [pid 961194:tid 961416] [client 35.204.197.107:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/"] [unique_id "amud7PSWp157EsYqB3oZ2QAAAFw"]
[Thu Jul 30 13:54:36.655661 2026] [security2:error] [pid 961194:tid 961221] [remote 51.68.111.239:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/"] [unique_id "amud7PSWp157EsYqB3oZ3QAAGxo"]
[Thu Jul 30 13:54:36.655854 2026] [security2:error] [pid 961194:tid 961351] [client 51.68.111.239:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spececigarette.com"] [uri "/"] [unique_id "amud7PSWp157EsYqB3oZ3QAAGxo"]
[Thu Jul 30 13:54:37.099921 2026] [proxy:error] [pid 961194:tid 961368] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:37.100006 2026] [proxy_http:error] [pid 961194:tid 961368] [client 3.225.222.228:60829] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:37.100598 2026] [proxy:error] [pid 961194:tid 961368] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:37.100644 2026] [proxy_http:error] [pid 961194:tid 961368] [client 3.225.222.228:60829] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:37.115964 2026] [proxy:error] [pid 961194:tid 961332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:37.116037 2026] [proxy_http:error] [pid 961194:tid 961332] [client 3.225.222.228:38768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:37.116598 2026] [proxy:error] [pid 961194:tid 961332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:37.116639 2026] [proxy_http:error] [pid 961194:tid 961332] [client 3.225.222.228:38768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:38.502879 2026] [security2:error] [pid 961194:tid 961377] [client 78.167.1.90:56956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud7vSWp157EsYqB3oaMAAAADU"]
[Thu Jul 30 13:54:38.503017 2026] [security2:error] [pid 961194:tid 961377] [client 78.167.1.90:56956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud7vSWp157EsYqB3oaMAAAADU"]
[Thu Jul 30 13:54:38.586251 2026] [proxy:error] [pid 961194:tid 961432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:38.586345 2026] [proxy_http:error] [pid 961194:tid 961432] [client 32.194.121.99:62320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:38.587249 2026] [proxy:error] [pid 961194:tid 961432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:38.587302 2026] [proxy_http:error] [pid 961194:tid 961432] [client 32.194.121.99:62320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:38.591989 2026] [proxy:error] [pid 961194:tid 961436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:38.592070 2026] [proxy_http:error] [pid 961194:tid 961436] [client 34.224.175.62:62553] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:38.592929 2026] [proxy:error] [pid 961194:tid 961436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:38.593003 2026] [proxy_http:error] [pid 961194:tid 961436] [client 34.224.175.62:62553] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:39.160820 2026] [core:notice] [pid 961194:tid 961225] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:39.167015 2026] [security2:error] [pid 961194:tid 961408] [client 74.7.175.154:57006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-ab4e48f3.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amud7_SWp157EsYqB3oaSAAAVB4"]
[Thu Jul 30 13:54:39.354685 2026] [security2:error] [pid 961194:tid 961419] [client 213.152.187.215:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.187.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amud7_SWp157EsYqB3oaSwAAAF8"]
[Thu Jul 30 13:54:39.354843 2026] [security2:error] [pid 961194:tid 961419] [client 213.152.187.215:60420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amud7_SWp157EsYqB3oaSwAAAF8"]
[Thu Jul 30 13:54:39.374382 2026] [security2:error] [pid 961194:tid 961367] [client 205.169.39.7:19009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amud7vSWp157EsYqB3oaQgAAACs"]
[Thu Jul 30 13:54:39.614323 2026] [security2:error] [pid 961194:tid 961257] [remote 5.161.62.209:10816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lalibanista.com"] [uri "/.env"] [unique_id "amud7_SWp157EsYqB3oaWgAAcT4"]
[Thu Jul 30 13:54:39.919189 2026] [security2:error] [pid 961194:tid 961424] [client 135.119.63.61:6252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admadmin.php"] [unique_id "amud7_SWp157EsYqB3oaYwAAAGQ"]
[Thu Jul 30 13:54:40.036290 2026] [core:notice] [pid 961194:tid 961321] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:40.124890 2026] [security2:error] [pid 961194:tid 961380] [client 103.190.40.154:20162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud8PSWp157EsYqB3oabgAAADg"]
[Thu Jul 30 13:54:40.125046 2026] [security2:error] [pid 961194:tid 961380] [client 103.190.40.154:20162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud8PSWp157EsYqB3oabgAAADg"]
[Thu Jul 30 13:54:40.438032 2026] [security2:error] [pid 961194:tid 961433] [client 103.242.199.184:54659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud8PSWp157EsYqB3oacgAAAG0"]
[Thu Jul 30 13:54:40.438160 2026] [security2:error] [pid 961194:tid 961433] [client 103.242.199.184:54659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud8PSWp157EsYqB3oacgAAAG0"]
[Thu Jul 30 13:54:40.475845 2026] [security2:error] [pid 961194:tid 961347] [client 74.7.228.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jacislamabad.com"] [uri "/index.php"] [unique_id "amud7_SWp157EsYqB3oaSgAAFzU"], referer: https://www.jacislamabad.com/robots.txt
[Thu Jul 30 13:54:40.914147 2026] [security2:error] [pid 961194:tid 961405] [client 135.119.63.61:22152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admalfa.php"] [unique_id "amud8PSWp157EsYqB3oafQAAAFE"]
[Thu Jul 30 13:54:41.497435 2026] [security2:error] [pid 961194:tid 961423] [client 189.6.88.213:52080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud8fSWp157EsYqB3oaiAAAAGM"]
[Thu Jul 30 13:54:41.497562 2026] [security2:error] [pid 961194:tid 961423] [client 189.6.88.213:52080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud8fSWp157EsYqB3oaiAAAAGM"]
[Thu Jul 30 13:54:41.548298 2026] [security2:error] [pid 961194:tid 961429] [client 172.237.109.114:59685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amud8PSWp157EsYqB3oafgAAAGk"]
[Thu Jul 30 13:54:41.888685 2026] [security2:error] [pid 961194:tid 961364] [client 135.119.63.61:31522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admbypass.php"] [unique_id "amud8fSWp157EsYqB3oalQAAACg"]
[Thu Jul 30 13:54:42.108134 2026] [security2:error] [pid 961194:tid 961415] [client 181.116.200.68:62449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud8vSWp157EsYqB3oamQAAAFs"]
[Thu Jul 30 13:54:42.108883 2026] [security2:error] [pid 961194:tid 961415] [client 181.116.200.68:62449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud8vSWp157EsYqB3oamQAAAFs"]
[Thu Jul 30 13:54:42.518073 2026] [security2:error] [pid 961194:tid 961403] [client 162.219.176.3:58302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amud8vSWp157EsYqB3oaoAAAAE8"]
[Thu Jul 30 13:54:42.518175 2026] [security2:error] [pid 961194:tid 961403] [client 162.219.176.3:58302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amud8vSWp157EsYqB3oaoAAAAE8"]
[Thu Jul 30 13:54:42.718731 2026] [core:notice] [pid 961194:tid 961290] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:42.890493 2026] [core:notice] [pid 961194:tid 961262] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:43.302803 2026] [security2:error] [pid 961194:tid 961385] [client 135.119.63.61:6241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admiin.php"] [unique_id "amud8_SWp157EsYqB3oatAAAAD0"]
[Thu Jul 30 13:54:44.622792 2026] [security2:error] [pid 961194:tid 961446] [client 172.213.232.128:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/011i.php"] [unique_id "amud9PSWp157EsYqB3oa2AAAAHo"]
[Thu Jul 30 13:54:44.869858 2026] [security2:error] [pid 961194:tid 961375] [client 135.119.63.61:31809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin%201.php"] [unique_id "amud9PSWp157EsYqB3oa4AAAADM"]
[Thu Jul 30 13:54:45.540768 2026] [core:notice] [pid 961194:tid 961219] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:45.673453 2026] [core:notice] [pid 961194:tid 961211] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:46.742706 2026] [security2:error] [pid 961194:tid 961348] [client 135.119.63.61:31527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin-ajax.php"] [unique_id "amud9vSWp157EsYqB3obCwAAABg"]
[Thu Jul 30 13:54:47.383090 2026] [security2:error] [pid 961194:tid 961414] [client 172.213.232.128:55277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/03a005685d.php"] [unique_id "amud9_SWp157EsYqB3obMgAAAFo"]
[Thu Jul 30 13:54:47.475523 2026] [security2:error] [pid 961194:tid 961438] [client 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amud9vSWp157EsYqB3obCQAAcgo"]
[Thu Jul 30 13:54:47.798273 2026] [security2:error] [pid 961194:tid 961375] [client 135.119.63.61:6222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin-footer.php"] [unique_id "amud9_SWp157EsYqB3obOwAAADM"]
[Thu Jul 30 13:54:47.907037 2026] [security2:error] [pid 961194:tid 961395] [client 74.208.150.73:60495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "alseermarine.com"] [uri "/"] [unique_id "amud9_SWp157EsYqB3obQgAAAEc"]
[Thu Jul 30 13:54:48.248870 2026] [core:notice] [pid 961194:tid 961214] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:48.317027 2026] [security2:error] [pid 961194:tid 961355] [client 74.208.150.73:60691] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "alseermarine.com"] [uri "/"] [unique_id "amud-PSWp157EsYqB3obSAAAAB8"]
[Thu Jul 30 13:54:48.706639 2026] [security2:error] [pid 961194:tid 961327] [client 135.119.63.61:22185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin-functions.php"] [unique_id "amud-PSWp157EsYqB3obUgAAAAM"]
[Thu Jul 30 13:54:49.059805 2026] [security2:error] [pid 961194:tid 961420] [client 78.167.1.90:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud-fSWp157EsYqB3obWwAAAGA"]
[Thu Jul 30 13:54:49.060219 2026] [security2:error] [pid 961194:tid 961420] [client 78.167.1.90:53916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud-fSWp157EsYqB3obWwAAAGA"]
[Thu Jul 30 13:54:49.216309 2026] [core:notice] [pid 961194:tid 961354] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:49.575676 2026] [core:notice] [pid 961194:tid 961350] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:49.598534 2026] [security2:error] [pid 961194:tid 961328] [client 135.119.63.61:6257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin-heade.php"] [unique_id "amud-fSWp157EsYqB3obagAAAAQ"]
[Thu Jul 30 13:54:50.513092 2026] [security2:error] [pid 961194:tid 961438] [client 135.119.63.61:6209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin-header.php"] [unique_id "amud-vSWp157EsYqB3obfwAAAHI"]
[Thu Jul 30 13:54:50.561592 2026] [core:notice] [pid 961194:tid 961241] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:50.636188 2026] [security2:error] [pid 961194:tid 961445] [client 172.237.109.114:7216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amud-vSWp157EsYqB3obdAAAAHk"]
[Thu Jul 30 13:54:50.906635 2026] [security2:error] [pid 961194:tid 961441] [client 103.190.40.154:21924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud-vSWp157EsYqB3objwAAAHU"]
[Thu Jul 30 13:54:50.906747 2026] [security2:error] [pid 961194:tid 961441] [client 103.190.40.154:21924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud-vSWp157EsYqB3objwAAAHU"]
[Thu Jul 30 13:54:51.125400 2026] [security2:error] [pid 961194:tid 961225] [remote 179.43.134.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucky-strike-shop.com"] [uri "/wp-login.php"] [unique_id "amud-vSWp157EsYqB3objgAAWR4"]
[Thu Jul 30 13:54:51.178189 2026] [security2:error] [pid 961194:tid 961383] [client 103.242.199.184:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud-_SWp157EsYqB3obmgAAADs"]
[Thu Jul 30 13:54:51.178321 2026] [security2:error] [pid 961194:tid 961383] [client 103.242.199.184:55218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amud-_SWp157EsYqB3obmgAAADs"]
[Thu Jul 30 13:54:51.618130 2026] [security2:error] [pid 961194:tid 961439] [client 66.249.65.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amud-_SWp157EsYqB3oblgAAAHM"]
[Thu Jul 30 13:54:51.721264 2026] [security2:error] [pid 961194:tid 961361] [client 34.9.172.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amud-_SWp157EsYqB3obogAAJRc"]
[Thu Jul 30 13:54:52.075710 2026] [security2:error] [pid 961194:tid 961406] [client 172.213.232.128:55350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/403.php"] [unique_id "amud_PSWp157EsYqB3obsgAAAFI"]
[Thu Jul 30 13:54:52.261819 2026] [security2:error] [pid 961194:tid 961448] [client 189.6.88.213:52562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud_PSWp157EsYqB3obugAAAHw"]
[Thu Jul 30 13:54:52.262224 2026] [security2:error] [pid 961194:tid 961448] [client 189.6.88.213:52562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amud_PSWp157EsYqB3obugAAAHw"]
[Thu Jul 30 13:54:52.268626 2026] [security2:error] [pid 961194:tid 961353] [client 34.9.172.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amud_PSWp157EsYqB3obtAAAHSQ"]
[Thu Jul 30 13:54:52.635770 2026] [security2:error] [pid 961194:tid 961365] [client 135.119.63.61:6226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin-post.php"] [unique_id "amud_PSWp157EsYqB3obxwAAACk"]
[Thu Jul 30 13:54:52.708627 2026] [security2:error] [pid 961194:tid 961338] [client 181.116.200.68:26764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud_PSWp157EsYqB3obygAAAA4"]
[Thu Jul 30 13:54:52.708725 2026] [security2:error] [pid 961194:tid 961338] [client 181.116.200.68:26764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amud_PSWp157EsYqB3obygAAAA4"]
[Thu Jul 30 13:54:52.895773 2026] [core:notice] [pid 961194:tid 961345] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:53.189639 2026] [security2:error] [pid 961194:tid 961423] [client 172.213.232.128:43460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/404.php"] [unique_id "amud_fSWp157EsYqB3ob1gAAAGM"]
[Thu Jul 30 13:54:53.516771 2026] [security2:error] [pid 961194:tid 961288] [remote 179.43.134.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucky-strike-shop.com"] [uri "/wp-login.php"] [unique_id "amud_fSWp157EsYqB3ob4QAAHl0"], referer: https://lucky-strike-shop.com/wp-admin/
[Thu Jul 30 13:54:53.539966 2026] [security2:error] [pid 961194:tid 961376] [client 135.119.63.61:35609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin-wolf.php"] [unique_id "amud_fSWp157EsYqB3ob4gAAADQ"]
[Thu Jul 30 13:54:53.991013 2026] [security2:error] [pid 961194:tid 961252] [remote 92.222.104.200:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "sharjahfurnituremoversandpackers.space"] [uri "/robots.txt"] [unique_id "amud_fSWp157EsYqB3ob6wAAfTk"]
[Thu Jul 30 13:54:53.991191 2026] [security2:error] [pid 961194:tid 961449] [client 92.222.104.200:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sharjahfurnituremoversandpackers.space"] [uri "/robots.txt"] [unique_id "amud_fSWp157EsYqB3ob6wAAfTk"]
[Thu Jul 30 13:54:54.229588 2026] [security2:error] [pid 961194:tid 961410] [client 172.213.232.128:50496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/aa.php"] [unique_id "amud_vSWp157EsYqB3ob8QAAAFY"]
[Thu Jul 30 13:54:54.513758 2026] [security2:error] [pid 961194:tid 961397] [client 135.119.63.61:22182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin.php"] [unique_id "amud_vSWp157EsYqB3ob9wAAAEk"]
[Thu Jul 30 13:54:54.547282 2026] [security2:error] [pid 961194:tid 961296] [remote 57.141.0.28:48960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amud_vSWp157EsYqB3ob-AAAQWU"]
[Thu Jul 30 13:54:54.556322 2026] [security2:error] [pid 961194:tid 961406] [client 34.9.172.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amud_vSWp157EsYqB3ob9gAAUlI"]
[Thu Jul 30 13:54:54.596710 2026] [core:notice] [pid 961194:tid 961331] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:55.455132 2026] [security2:error] [pid 961194:tid 961266] [remote 54.37.118.74:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "sharjahfurnituremoversandpackers.space"] [uri "/product-category/water-heater/"] [unique_id "amud__SWp157EsYqB3ocDwAAZEc"]
[Thu Jul 30 13:54:55.455358 2026] [security2:error] [pid 961194:tid 961424] [client 54.37.118.74:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sharjahfurnituremoversandpackers.space"] [uri "/product-category/water-heater/"] [unique_id "amud__SWp157EsYqB3ocDwAAZEc"]
[Thu Jul 30 13:54:55.577014 2026] [security2:error] [pid 961194:tid 961419] [client 135.119.63.61:35610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin1.php"] [unique_id "amud__SWp157EsYqB3ocEQAAAF8"]
[Thu Jul 30 13:54:55.855695 2026] [security2:error] [pid 961194:tid 961329] [client 172.213.232.128:45570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/aafewc0k.php"] [unique_id "amud__SWp157EsYqB3ocGAAAAAU"]
[Thu Jul 30 13:54:56.270317 2026] [core:notice] [pid 961194:tid 961368] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:56.490280 2026] [security2:error] [pid 961194:tid 961335] [client 172.213.232.128:50518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/abcd.php"] [unique_id "amueAPSWp157EsYqB3ocLAAAAAs"]
[Thu Jul 30 13:54:56.744188 2026] [security2:error] [pid 961194:tid 961426] [client 135.119.63.61:31488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin403.php"] [unique_id "amueAPSWp157EsYqB3ocMQAAAGY"]
[Thu Jul 30 13:54:56.806760 2026] [core:notice] [pid 961194:tid 961339] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:57.026243 2026] [security2:error] [pid 961194:tid 961415] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueAPSWp157EsYqB3ocKgAAW14"]
[Thu Jul 30 13:54:57.119412 2026] [security2:error] [pid 961194:tid 961324] [client 172.213.232.128:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/about.php"] [unique_id "amueAfSWp157EsYqB3ocOgAAAAA"]
[Thu Jul 30 13:54:57.574962 2026] [security2:error] [pid 961194:tid 961417] [client 135.119.63.61:31530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin404.php"] [unique_id "amueAfSWp157EsYqB3ocRgAAAF0"]
[Thu Jul 30 13:54:58.389321 2026] [security2:error] [pid 961194:tid 961447] [client 172.213.232.128:43458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/admin.php"] [unique_id "amueAvSWp157EsYqB3ocVwAAAHs"]
[Thu Jul 30 13:54:59.057098 2026] [security2:error] [pid 961194:tid 961308] [remote 57.141.0.43:28746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/613058497/feed/rss2/"] [unique_id "amueA_SWp157EsYqB3ocZwAAAXE"]
[Thu Jul 30 13:54:59.112073 2026] [security2:error] [pid 961194:tid 961418] [client 135.119.63.61:22196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admin836.php"] [unique_id "amueA_SWp157EsYqB3ocagAAAF4"]
[Thu Jul 30 13:54:59.309361 2026] [proxy:error] [pid 961194:tid 961367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:59.309423 2026] [proxy_http:error] [pid 961194:tid 961367] [client 52.4.19.39:16278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:59.310050 2026] [proxy:error] [pid 961194:tid 961367] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:59.310109 2026] [proxy_http:error] [pid 961194:tid 961367] [client 52.4.19.39:16278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:59.337520 2026] [proxy:error] [pid 961194:tid 961362] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:59.337620 2026] [proxy_http:error] [pid 961194:tid 961362] [client 3.225.222.228:32305] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:59.338324 2026] [proxy:error] [pid 961194:tid 961362] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:54:59.338372 2026] [proxy_http:error] [pid 961194:tid 961362] [client 3.225.222.228:32305] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:54:59.548613 2026] [core:notice] [pid 961194:tid 961417] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:54:59.586522 2026] [security2:error] [pid 961194:tid 961444] [client 78.167.1.90:55308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueA_SWp157EsYqB3ochgAAAHg"]
[Thu Jul 30 13:54:59.587414 2026] [security2:error] [pid 961194:tid 961444] [client 78.167.1.90:55308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueA_SWp157EsYqB3ochgAAAHg"]
[Thu Jul 30 13:54:59.591535 2026] [security2:error] [pid 961194:tid 961301] [remote 52.167.144.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/29/32"] [unique_id "amueA_SWp157EsYqB3ochwAAcWo"]
[Thu Jul 30 13:54:59.641675 2026] [security2:error] [pid 961194:tid 961378] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueAvSWp157EsYqB3ocYwAANgU"]
[Thu Jul 30 13:55:00.073801 2026] [security2:error] [pid 961194:tid 961364] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amueA_SWp157EsYqB3ocgQAAACg"]
[Thu Jul 30 13:55:00.078317 2026] [security2:error] [pid 961194:tid 961451] [client 135.119.63.61:35631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/adminadmin.php"] [unique_id "amueBPSWp157EsYqB3ocjgAAAH8"]
[Thu Jul 30 13:55:00.635440 2026] [core:notice] [pid 961194:tid 961373] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:00.787179 2026] [security2:error] [pid 961194:tid 961391] [client 172.213.232.128:55157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/adminfuns.php"] [unique_id "amueBPSWp157EsYqB3ocowAAAEM"]
[Thu Jul 30 13:55:00.806053 2026] [security2:error] [pid 961194:tid 961354] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueBPSWp157EsYqB3oclQAAHhs"]
[Thu Jul 30 13:55:01.168824 2026] [security2:error] [pid 961194:tid 961410] [client 135.119.63.61:31550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/adminalfa.php"] [unique_id "amueBfSWp157EsYqB3ocqgAAAFY"]
[Thu Jul 30 13:55:01.639052 2026] [security2:error] [pid 961194:tid 961372] [client 172.213.232.128:55584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/albin.php"] [unique_id "amueBfSWp157EsYqB3ocuAAAADA"]
[Thu Jul 30 13:55:01.653868 2026] [security2:error] [pid 961194:tid 961341] [client 103.190.40.154:20223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueBfSWp157EsYqB3ocuwAAABE"]
[Thu Jul 30 13:55:01.654002 2026] [security2:error] [pid 961194:tid 961341] [client 103.190.40.154:20223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueBfSWp157EsYqB3ocuwAAABE"]
[Thu Jul 30 13:55:01.861096 2026] [security2:error] [pid 961194:tid 961412] [client 103.242.199.184:55772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueBfSWp157EsYqB3ocxQAAAFg"]
[Thu Jul 30 13:55:01.861196 2026] [security2:error] [pid 961194:tid 961412] [client 103.242.199.184:55772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueBfSWp157EsYqB3ocxQAAAFg"]
[Thu Jul 30 13:55:02.095884 2026] [core:notice] [pid 961194:tid 961332] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:02.164163 2026] [security2:error] [pid 961194:tid 961365] [client 135.119.63.61:6208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/adminbypass.php"] [unique_id "amueBvSWp157EsYqB3oczAAAACk"]
[Thu Jul 30 13:55:02.408365 2026] [security2:error] [pid 961194:tid 961388] [client 172.213.232.128:18937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/amfsqvgv.php"] [unique_id "amueBvSWp157EsYqB3oc1QAAAEA"]
[Thu Jul 30 13:55:02.445293 2026] [security2:error] [pid 961194:tid 961393] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amueBfSWp157EsYqB3ocyAAAAEU"]
[Thu Jul 30 13:55:03.034618 2026] [security2:error] [pid 961194:tid 961449] [client 135.119.63.61:35646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/adminer.php"] [unique_id "amueB_SWp157EsYqB3oc5QAAAH0"]
[Thu Jul 30 13:55:03.139667 2026] [security2:error] [pid 961194:tid 961392] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueBvSWp157EsYqB3oc1wAARCU"]
[Thu Jul 30 13:55:03.268606 2026] [security2:error] [pid 961194:tid 961391] [client 181.116.200.68:16030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueB_SWp157EsYqB3oc6wAAAEM"]
[Thu Jul 30 13:55:03.268715 2026] [security2:error] [pid 961194:tid 961391] [client 181.116.200.68:16030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueB_SWp157EsYqB3oc6wAAAEM"]
[Thu Jul 30 13:55:03.346793 2026] [security2:error] [pid 961194:tid 961339] [client 172.213.232.128:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/ant.php"] [unique_id "amueB_SWp157EsYqB3oc7QAAAA8"]
[Thu Jul 30 13:55:03.926217 2026] [security2:error] [pid 961194:tid 961448] [client 135.119.63.61:31546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/adminer/adminer.php"] [unique_id "amueB_SWp157EsYqB3oc_AAAAHw"]
[Thu Jul 30 13:55:04.430014 2026] [security2:error] [pid 961194:tid 961386] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueB_SWp157EsYqB3oc-wAAPjo"]
[Thu Jul 30 13:55:04.434082 2026] [core:notice] [pid 961194:tid 961356] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:04.544819 2026] [security2:error] [pid 961194:tid 961333] [client 172.213.232.128:55558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/appreciators.php"] [unique_id "amueCPSWp157EsYqB3odDAAAAAk"]
[Thu Jul 30 13:55:04.933197 2026] [security2:error] [pid 961194:tid 961400] [client 135.119.63.61:22152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/adminfuns.php"] [unique_id "amueCPSWp157EsYqB3odFAAAAEw"]
[Thu Jul 30 13:55:05.253096 2026] [autoindex:error] [pid 961194:tid 961409] [client 185.177.72.70:0] AH01276: Cannot serve directory /home2/nhzgzjte/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:55:06.292132 2026] [core:notice] [pid 961194:tid 961327] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:06.360884 2026] [security2:error] [pid 961194:tid 961362] [client 135.119.63.61:31522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/administratoradmin.php"] [unique_id "amueCvSWp157EsYqB3odNgAAACY"]
[Thu Jul 30 13:55:06.763560 2026] [security2:error] [pid 961194:tid 961368] [client 172.213.232.128:18934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/archive.php"] [unique_id "amueCvSWp157EsYqB3odRQAAACw"]
[Thu Jul 30 13:55:06.905224 2026] [security2:error] [pid 961194:tid 961435] [client 50.6.43.217:12218] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amueCvSWp157EsYqB3odRwAAAG8"]
[Thu Jul 30 13:55:06.960619 2026] [security2:error] [pid 961194:tid 961423] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueCvSWp157EsYqB3odOgAAYzU"]
[Thu Jul 30 13:55:07.036940 2026] [security2:error] [pid 961194:tid 961373] [client 50.6.43.217:12226] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amueC_SWp157EsYqB3odTwAAADE"]
[Thu Jul 30 13:55:07.286768 2026] [security2:error] [pid 961194:tid 961439] [client 135.119.63.61:22201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/administratoralfa.php"] [unique_id "amueC_SWp157EsYqB3odUwAAAHM"]
[Thu Jul 30 13:55:07.350902 2026] [security2:error] [pid 961194:tid 961331] [client 130.49.76.236:44853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "black-devil-shop.com"] [uri "/index.php"] [unique_id "amueCvSWp157EsYqB3odNwAAB0Y"]
[Thu Jul 30 13:55:07.539273 2026] [core:notice] [pid 961194:tid 961259] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:07.542849 2026] [security2:error] [pid 961194:tid 961445] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueCvSWp157EsYqB3odRgAAeX0"]
[Thu Jul 30 13:55:07.701758 2026] [core:notice] [pid 961194:tid 961287] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:08.340110 2026] [security2:error] [pid 961194:tid 961437] [client 135.119.63.61:35612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/administratorbypass.php"] [unique_id "amueDPSWp157EsYqB3odcAAAAHE"]
[Thu Jul 30 13:55:08.574921 2026] [core:notice] [pid 961194:tid 961369] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:09.129135 2026] [security2:error] [pid 961194:tid 961327] [client 172.213.232.128:61859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/as.php"] [unique_id "amueDfSWp157EsYqB3odggAAAAM"]
[Thu Jul 30 13:55:09.357767 2026] [security2:error] [pid 961194:tid 961380] [client 135.119.63.61:6947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/administratork.php"] [unique_id "amueDfSWp157EsYqB3odhwAAADg"]
[Thu Jul 30 13:55:09.720257 2026] [security2:error] [pid 961194:tid 961270] [remote 47.128.27.65:12684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-se-craft-white-and-phantom/"] [unique_id "amueDfSWp157EsYqB3odkAAAGks"]
[Thu Jul 30 13:55:09.895232 2026] [security2:error] [pid 961194:tid 961334] [client 172.213.232.128:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/atomlib.php"] [unique_id "amueDfSWp157EsYqB3odlAAAAAo"]
[Thu Jul 30 13:55:10.184354 2026] [security2:error] [pid 961194:tid 961409] [client 78.167.1.90:54038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueDvSWp157EsYqB3odmwAAAFU"]
[Thu Jul 30 13:55:10.184895 2026] [security2:error] [pid 961194:tid 961409] [client 78.167.1.90:54038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueDvSWp157EsYqB3odmwAAAFU"]
[Thu Jul 30 13:55:10.483548 2026] [security2:error] [pid 961194:tid 961449] [client 135.119.63.61:31526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/administratorwp.php"] [unique_id "amueDvSWp157EsYqB3odnwAAAH0"]
[Thu Jul 30 13:55:10.563703 2026] [security2:error] [pid 961194:tid 961417] [client 172.213.232.128:55164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/autoload_classmap.php"] [unique_id "amueDvSWp157EsYqB3odoAAAAF0"]
[Thu Jul 30 13:55:10.850838 2026] [security2:error] [pid 961194:tid 961406] [client 74.7.244.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.themushroom.online"] [uri "/index.php"] [unique_id "amueC_SWp157EsYqB3odYgAAAFI"]
[Thu Jul 30 13:55:10.851729 2026] [security2:error] [pid 961194:tid 961335] [client 74.7.244.47:51744] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.themushroom.online"] [uri "/robots.txt"] [unique_id "amueC_SWp157EsYqB3odYAAAC1s"]
[Thu Jul 30 13:55:11.088767 2026] [core:notice] [pid 961194:tid 961275] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:11.531270 2026] [security2:error] [pid 961194:tid 961423] [client 135.119.63.61:35644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/admink.php"] [unique_id "amueD_SWp157EsYqB3oduwAAAGM"]
[Thu Jul 30 13:55:11.918180 2026] [security2:error] [pid 961194:tid 961337] [client 172.213.232.128:64566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/bb.php"] [unique_id "amueD_SWp157EsYqB3odygAAAA0"]
[Thu Jul 30 13:55:12.426369 2026] [security2:error] [pid 961194:tid 961351] [client 103.242.199.184:56329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueEPSWp157EsYqB3od1wAAABs"]
[Thu Jul 30 13:55:12.426548 2026] [security2:error] [pid 961194:tid 961351] [client 103.242.199.184:56329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueEPSWp157EsYqB3od1wAAABs"]
[Thu Jul 30 13:55:12.483943 2026] [security2:error] [pid 961194:tid 961358] [client 172.213.232.128:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/bnm.php"] [unique_id "amueEPSWp157EsYqB3od2gAAACI"]
[Thu Jul 30 13:55:12.498774 2026] [security2:error] [pid 961194:tid 961341] [client 103.190.40.154:8189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueEPSWp157EsYqB3od2wAAABE"]
[Thu Jul 30 13:55:12.499260 2026] [security2:error] [pid 961194:tid 961341] [client 103.190.40.154:8189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueEPSWp157EsYqB3od2wAAABE"]
[Thu Jul 30 13:55:12.611842 2026] [security2:error] [pid 961194:tid 961394] [client 135.119.63.61:28949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/adminwebadmin.php"] [unique_id "amueEPSWp157EsYqB3od3QAAAEY"]
[Thu Jul 30 13:55:12.713516 2026] [security2:error] [pid 961194:tid 961405] [client 172.237.109.114:26114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueEPSWp157EsYqB3odzwAAAFE"]
[Thu Jul 30 13:55:12.868496 2026] [security2:error] [pid 961194:tid 961449] [client 59.14.17.48:28243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amueEPSWp157EsYqB3od4QAAAH0"]
[Thu Jul 30 13:55:13.635696 2026] [security2:error] [pid 961194:tid 961404] [client 135.119.63.61:6923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/adminwebalfa.php"] [unique_id "amueEfSWp157EsYqB3od-QAAAFA"]
[Thu Jul 30 13:55:13.846899 2026] [security2:error] [pid 961194:tid 961399] [client 181.116.200.68:39160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueEfSWp157EsYqB3oeAQAAAEs"]
[Thu Jul 30 13:55:13.847017 2026] [security2:error] [pid 961194:tid 961399] [client 181.116.200.68:39160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueEfSWp157EsYqB3oeAQAAAEs"]
[Thu Jul 30 13:55:14.596346 2026] [security2:error] [pid 961194:tid 961353] [client 135.119.63.61:31509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/adminwebbypass.php"] [unique_id "amueEvSWp157EsYqB3oeEgAAAB0"]
[Thu Jul 30 13:55:14.697626 2026] [security2:error] [pid 961194:tid 961416] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueEvSWp157EsYqB3oeBQAAXGc"]
[Thu Jul 30 13:55:15.495121 2026] [security2:error] [pid 961194:tid 961369] [client 172.202.95.21:44180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "remoteworksit.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amueE_SWp157EsYqB3oeIwAAAC0"]
[Thu Jul 30 13:55:15.495228 2026] [security2:error] [pid 961194:tid 961369] [client 172.202.95.21:44180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "remoteworksit.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amueE_SWp157EsYqB3oeIwAAAC0"]
[Thu Jul 30 13:55:17.457888 2026] [security2:error] [pid 961194:tid 961403] [client 172.237.109.114:2331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueFPSWp157EsYqB3oePwAAAE8"]
[Thu Jul 30 13:55:17.805596 2026] [security2:error] [pid 961194:tid 961378] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amueFfSWp157EsYqB3oeUAAAADY"]
[Thu Jul 30 13:55:18.704092 2026] [security2:error] [pid 961194:tid 961365] [client 172.213.232.128:55838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/bootstrap.php"] [unique_id "amueFvSWp157EsYqB3oebQAAACk"]
[Thu Jul 30 13:55:19.147791 2026] [security2:error] [pid 961194:tid 961348] [client 172.202.95.21:38390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/as.php"] [unique_id "amueF_SWp157EsYqB3oedAAAABg"]
[Thu Jul 30 13:55:19.585313 2026] [security2:error] [pid 961194:tid 961427] [client 127.0.0.1:60536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amueF_SWp157EsYqB3oeiAAAAGc"]
[Thu Jul 30 13:55:19.585395 2026] [security2:error] [pid 961194:tid 961396] [client 74.7.228.35:54524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ily.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amueF_SWp157EsYqB3oehwAAAEg"]
[Thu Jul 30 13:55:20.116653 2026] [security2:error] [pid 961194:tid 961430] [client 172.213.232.128:64542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/buy.php"] [unique_id "amueGPSWp157EsYqB3oeoQAAAGo"]
[Thu Jul 30 13:55:20.269035 2026] [security2:error] [pid 961194:tid 961372] [client 172.202.95.21:38370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/k.php"] [unique_id "amueGPSWp157EsYqB3oeqAAAADA"]
[Thu Jul 30 13:55:20.724878 2026] [security2:error] [pid 961194:tid 961395] [client 78.167.1.90:55862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueGPSWp157EsYqB3oeswAAAEc"]
[Thu Jul 30 13:55:20.725365 2026] [security2:error] [pid 961194:tid 961395] [client 78.167.1.90:55862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueGPSWp157EsYqB3oeswAAAEc"]
[Thu Jul 30 13:55:22.072677 2026] [security2:error] [pid 961194:tid 961383] [client 172.202.95.21:38383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/system_log.php"] [unique_id "amueGvSWp157EsYqB3oe6wAAADs"]
[Thu Jul 30 13:55:22.198268 2026] [security2:error] [pid 961194:tid 961439] [client 172.202.95.21:44161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "remoteworksit.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amueGvSWp157EsYqB3oe8AAAAHM"]
[Thu Jul 30 13:55:22.198370 2026] [security2:error] [pid 961194:tid 961439] [client 172.202.95.21:44161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "remoteworksit.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amueGvSWp157EsYqB3oe8AAAAHM"]
[Thu Jul 30 13:55:22.233508 2026] [autoindex:error] [pid 961194:tid 961359] [client 2001:bc8:1201:733:da5e:d3ff:fe49:8fe4:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:55:22.679454 2026] [security2:error] [pid 961194:tid 961219] [remote 167.71.218.184:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daralnaseemdxb.com"] [uri "/wp-login.php"] [unique_id "amueGvSWp157EsYqB3oe_AAAehg"]
[Thu Jul 30 13:55:22.961250 2026] [proxy:error] [pid 961194:tid 961366] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:22.961320 2026] [proxy_http:error] [pid 961194:tid 961366] [client 52.4.19.39:64434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:22.961903 2026] [proxy:error] [pid 961194:tid 961366] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:22.961948 2026] [proxy_http:error] [pid 961194:tid 961366] [client 52.4.19.39:64434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:22.974690 2026] [proxy:error] [pid 961194:tid 961405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:22.974752 2026] [proxy_http:error] [pid 961194:tid 961405] [client 44.213.206.96:61058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:22.975328 2026] [proxy:error] [pid 961194:tid 961405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:22.975375 2026] [proxy_http:error] [pid 961194:tid 961405] [client 44.213.206.96:61058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:23.004163 2026] [security2:error] [pid 961194:tid 961378] [client 103.242.199.184:56885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueG_SWp157EsYqB3ofFAAAADY"]
[Thu Jul 30 13:55:23.004273 2026] [security2:error] [pid 961194:tid 961378] [client 103.242.199.184:56885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueG_SWp157EsYqB3ofFAAAADY"]
[Thu Jul 30 13:55:23.180064 2026] [security2:error] [pid 961194:tid 961356] [client 103.190.40.154:18679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueG_SWp157EsYqB3ofFQAAACA"]
[Thu Jul 30 13:55:23.180194 2026] [security2:error] [pid 961194:tid 961356] [client 103.190.40.154:18679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueG_SWp157EsYqB3ofFQAAACA"]
[Thu Jul 30 13:55:23.304879 2026] [security2:error] [pid 961194:tid 961402] [client 172.202.95.21:38470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/x.php"] [unique_id "amueG_SWp157EsYqB3ofGAAAAE4"]
[Thu Jul 30 13:55:23.752362 2026] [proxy:error] [pid 961194:tid 961327] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:23.752434 2026] [proxy_http:error] [pid 961194:tid 961327] [client 3.225.222.228:49136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:23.753014 2026] [proxy:error] [pid 961194:tid 961327] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:23.753061 2026] [proxy_http:error] [pid 961194:tid 961327] [client 3.225.222.228:49136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:23.754817 2026] [proxy:error] [pid 961194:tid 961332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:23.754874 2026] [proxy_http:error] [pid 961194:tid 961332] [client 44.213.206.96:12627] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:23.755438 2026] [proxy:error] [pid 961194:tid 961332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:23.755485 2026] [proxy_http:error] [pid 961194:tid 961332] [client 44.213.206.96:12627] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:24.231684 2026] [security2:error] [pid 961194:tid 961436] [client 189.6.88.213:54198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueHPSWp157EsYqB3ofRAAAAHA"]
[Thu Jul 30 13:55:24.231798 2026] [security2:error] [pid 961194:tid 961436] [client 189.6.88.213:54198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueHPSWp157EsYqB3ofRAAAAHA"]
[Thu Jul 30 13:55:24.484711 2026] [security2:error] [pid 961194:tid 961342] [client 181.116.200.68:63835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueHPSWp157EsYqB3ofTgAAABI"]
[Thu Jul 30 13:55:24.484818 2026] [security2:error] [pid 961194:tid 961342] [client 181.116.200.68:63835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueHPSWp157EsYqB3ofTgAAABI"]
[Thu Jul 30 13:55:24.903489 2026] [security2:error] [pid 961194:tid 961349] [client 172.213.232.128:59474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/chosen.php"] [unique_id "amueHPSWp157EsYqB3ofYgAAABk"]
[Thu Jul 30 13:55:25.090058 2026] [security2:error] [pid 961194:tid 961446] [client 172.202.95.21:38381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/autoload_classmap.php"] [unique_id "amueHfSWp157EsYqB3ofawAAAHo"]
[Thu Jul 30 13:55:25.210265 2026] [core:notice] [pid 961194:tid 961329] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:25.351083 2026] [security2:error] [pid 961194:tid 961335] [client 85.215.116.2:62114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "womenclothingbox.com"] [uri "/"] [unique_id "amueHfSWp157EsYqB3ofbQAAAAs"]
[Thu Jul 30 13:55:25.445204 2026] [security2:error] [pid 961194:tid 961374] [client 172.237.109.114:29337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueHPSWp157EsYqB3ofZAAAADI"]
[Thu Jul 30 13:55:25.657291 2026] [security2:error] [pid 961194:tid 961365] [client 172.213.232.128:58999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/class-wp-image.php"] [unique_id "amueHfSWp157EsYqB3ofdwAAACk"]
[Thu Jul 30 13:55:27.066925 2026] [core:notice] [pid 961194:tid 961442] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:27.261124 2026] [security2:error] [pid 961194:tid 961370] [client 172.213.232.128:58968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/classsmtps.php"] [unique_id "amueH_SWp157EsYqB3ofnAAAAC4"]
[Thu Jul 30 13:55:27.364085 2026] [core:notice] [pid 961194:tid 961237] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:27.500543 2026] [security2:error] [pid 961194:tid 961411] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueHvSWp157EsYqB3ofkQAAVzQ"]
[Thu Jul 30 13:55:27.942956 2026] [security2:error] [pid 961194:tid 961395] [client 172.213.232.128:52672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/classwithtostring.php"] [unique_id "amueH_SWp157EsYqB3ofqAAAAEc"]
[Thu Jul 30 13:55:27.953167 2026] [security2:error] [pid 961194:tid 961348] [client 172.202.95.21:38398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/hosty.php"] [unique_id "amueH_SWp157EsYqB3ofqQAAABg"]
[Thu Jul 30 13:55:28.130115 2026] [security2:error] [pid 961194:tid 961381] [client 207.46.13.102:26734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amueIPSWp157EsYqB3ofrQAAOWs"]
[Thu Jul 30 13:55:28.385240 2026] [core:notice] [pid 961194:tid 961384] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:29.185970 2026] [security2:error] [pid 961194:tid 961375] [client 172.213.232.128:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/config.php"] [unique_id "amueIfSWp157EsYqB3of0AAAADM"]
[Thu Jul 30 13:55:29.397709 2026] [security2:error] [pid 961194:tid 961377] [client 176.28.204.204:34937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueIPSWp157EsYqB3ofxAAAADU"]
[Thu Jul 30 13:55:29.722458 2026] [security2:error] [pid 961194:tid 961424] [client 172.202.95.21:38471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/test1.php"] [unique_id "amueIfSWp157EsYqB3of3AAAAGQ"]
[Thu Jul 30 13:55:30.019518 2026] [autoindex:error] [pid 961194:tid 961370] [client 2001:bc8:1201:733:da5e:d3ff:fe49:8fe4:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:55:30.373062 2026] [security2:error] [pid 961194:tid 961405] [client 172.202.95.21:60013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "remoteworksit.com"] [uri "/xstelth.php"] [unique_id "amueIvSWp157EsYqB3of6gAAAFE"]
[Thu Jul 30 13:55:30.373175 2026] [security2:error] [pid 961194:tid 961405] [client 172.202.95.21:60013] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "remoteworksit.com"] [uri "/xstelth.php"] [unique_id "amueIvSWp157EsYqB3of6gAAAFE"]
[Thu Jul 30 13:55:30.640500 2026] [security2:error] [pid 961194:tid 961393] [client 172.237.109.114:48544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueIvSWp157EsYqB3of4QAAAEU"], referer: alseermarine.com:443/MUP
[Thu Jul 30 13:55:30.823674 2026] [security2:error] [pid 961194:tid 961339] [client 172.202.95.21:38706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/zwso.php"] [unique_id "amueIvSWp157EsYqB3of9QAAAA8"]
[Thu Jul 30 13:55:31.317895 2026] [security2:error] [pid 961194:tid 961325] [client 78.167.1.90:53534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueI_SWp157EsYqB3of_gAAAAE"]
[Thu Jul 30 13:55:31.318526 2026] [security2:error] [pid 961194:tid 961325] [client 78.167.1.90:53534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueI_SWp157EsYqB3of_gAAAAE"]
[Thu Jul 30 13:55:31.592460 2026] [security2:error] [pid 961194:tid 961402] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amueIvSWp157EsYqB3of9wAATmI"]
[Thu Jul 30 13:55:31.778206 2026] [security2:error] [pid 961194:tid 961382] [client 172.202.95.21:38715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/fpwch.php"] [unique_id "amueI_SWp157EsYqB3ogBgAAADo"]
[Thu Jul 30 13:55:31.965630 2026] [security2:error] [pid 961194:tid 961433] [client 172.237.109.114:2244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-admin/admin-post.php"] [unique_id "amueI_SWp157EsYqB3ogDQAAAG0"]
[Thu Jul 30 13:55:33.095914 2026] [security2:error] [pid 961194:tid 961373] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueJPSWp157EsYqB3ogGgAAMWw"]
[Thu Jul 30 13:55:33.567827 2026] [security2:error] [pid 961194:tid 961434] [client 85.208.96.209:46444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/09/mulher-e-morta-pelo-ex-marido-ao-sair-do-trabalho-em-joao-pessoa/"] [unique_id "amueJfSWp157EsYqB3ogOQAAAG4"]
[Thu Jul 30 13:55:33.568000 2026] [security2:error] [pid 961194:tid 961434] [client 85.208.96.209:46444] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/09/mulher-e-morta-pelo-ex-marido-ao-sair-do-trabalho-em-joao-pessoa/"] [unique_id "amueJfSWp157EsYqB3ogOQAAAG4"]
[Thu Jul 30 13:55:33.603848 2026] [security2:error] [pid 961194:tid 961365] [client 103.242.199.184:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueJfSWp157EsYqB3ogPQAAACk"]
[Thu Jul 30 13:55:33.603948 2026] [security2:error] [pid 961194:tid 961365] [client 103.242.199.184:57435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueJfSWp157EsYqB3ogPQAAACk"]
[Thu Jul 30 13:55:33.855743 2026] [security2:error] [pid 961194:tid 961360] [client 172.213.232.128:59688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/core.php"] [unique_id "amueJfSWp157EsYqB3ogRAAAACQ"]
[Thu Jul 30 13:55:33.880002 2026] [security2:error] [pid 961194:tid 961418] [client 103.190.40.154:18103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueJfSWp157EsYqB3ogRQAAAF4"]
[Thu Jul 30 13:55:33.880763 2026] [security2:error] [pid 961194:tid 961418] [client 103.190.40.154:18103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueJfSWp157EsYqB3ogRQAAAF4"]
[Thu Jul 30 13:55:34.038690 2026] [security2:error] [pid 961194:tid 961430] [client 172.202.95.21:38714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-blog-header.php"] [unique_id "amueJvSWp157EsYqB3ogTwAAAGo"]
[Thu Jul 30 13:55:34.074833 2026] [security2:error] [pid 961194:tid 961326] [client 121.229.156.118:39198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/air-force-1-dior-print-2/"] [unique_id "amueJvSWp157EsYqB3ogUQAAAAI"]
[Thu Jul 30 13:55:34.075013 2026] [security2:error] [pid 961194:tid 961326] [client 121.229.156.118:39198] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/air-force-1-dior-print-2/"] [unique_id "amueJvSWp157EsYqB3ogUQAAAAI"]
[Thu Jul 30 13:55:34.340468 2026] [security2:error] [pid 961194:tid 961307] [remote 5.161.62.209:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bestdogproductguide.com"] [uri "/.env"] [unique_id "amueJvSWp157EsYqB3ogUwAAJnA"]
[Thu Jul 30 13:55:34.924543 2026] [security2:error] [pid 961194:tid 961338] [client 189.6.88.213:55042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueJvSWp157EsYqB3ogYgAAAA4"]
[Thu Jul 30 13:55:34.924705 2026] [security2:error] [pid 961194:tid 961338] [client 189.6.88.213:55042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueJvSWp157EsYqB3ogYgAAAA4"]
[Thu Jul 30 13:55:35.025896 2026] [security2:error] [pid 961194:tid 961415] [client 181.116.200.68:8394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueJ_SWp157EsYqB3ogawAAAFs"]
[Thu Jul 30 13:55:35.026003 2026] [security2:error] [pid 961194:tid 961415] [client 181.116.200.68:8394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueJ_SWp157EsYqB3ogawAAAFs"]
[Thu Jul 30 13:55:35.176519 2026] [security2:error] [pid 961194:tid 961388] [client 43.173.179.213:42416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/29/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/"] [unique_id "amueJvSWp157EsYqB3ogYwAAAEA"]
[Thu Jul 30 13:55:35.201886 2026] [security2:error] [pid 961194:tid 961344] [client 172.213.232.128:59494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/css.php"] [unique_id "amueJ_SWp157EsYqB3ogbwAAABQ"]
[Thu Jul 30 13:55:35.377560 2026] [security2:error] [pid 961194:tid 961412] [client 172.237.109.114:63600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueJ_SWp157EsYqB3ogbAAAAFg"]
[Thu Jul 30 13:55:35.410833 2026] [core:notice] [pid 961194:tid 961345] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:35.416928 2026] [security2:error] [pid 961194:tid 961345] [client 43.173.178.183:48146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/29/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/"] [unique_id "amueJ_SWp157EsYqB3ogdwAAABU"], referer: https://carnetdeshopping.com/index.php/2012/07/29/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/?replytocom=621
[Thu Jul 30 13:55:35.473175 2026] [security2:error] [pid 961194:tid 961381] [client 43.173.182.197:55430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/06/12/ventes-privees-ete-2015/feed/"] [unique_id "amueJ_SWp157EsYqB3ogcQAAADk"]
[Thu Jul 30 13:55:35.548271 2026] [security2:error] [pid 961194:tid 961401] [client 74.7.244.63:51204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amueJvSWp157EsYqB3ogXgAAAE0"]
[Thu Jul 30 13:55:35.548295 2026] [security2:error] [pid 961194:tid 961401] [client 74.7.244.63:51204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amueJvSWp157EsYqB3ogXgAAAE0"]
[Thu Jul 30 13:55:35.966493 2026] [security2:error] [pid 961194:tid 961334] [client 172.202.95.21:38354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/about/function.php"] [unique_id "amueJ_SWp157EsYqB3oghgAAAAo"]
[Thu Jul 30 13:55:36.224933 2026] [security2:error] [pid 961194:tid 961406] [client 74.7.244.63:56208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amueKPSWp157EsYqB3ogjwAAUgk"], referer: http://northyorksheridanmall.com/robots.txt
[Thu Jul 30 13:55:36.224964 2026] [security2:error] [pid 961194:tid 961406] [client 74.7.244.63:56208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amueKPSWp157EsYqB3ogjwAAUgk"], referer: http://northyorksheridanmall.com/robots.txt
[Thu Jul 30 13:55:36.362869 2026] [security2:error] [pid 961194:tid 961375] [client 107.150.37.82:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.37.150.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/x1823cc/index.php"] [unique_id "amueKPSWp157EsYqB3ogjgAAADM"], referer: https://saifalkhaleejest.com/wp-includes/x1823cc/index.php
[Thu Jul 30 13:55:36.567913 2026] [core:notice] [pid 961194:tid 961200] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:36.581857 2026] [core:notice] [pid 961194:tid 961396] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:36.587557 2026] [security2:error] [pid 961194:tid 961396] [client 43.173.178.206:55778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/06/12/ventes-privees-ete-2015/feed/"] [unique_id "amueKPSWp157EsYqB3ogngAAAEg"], referer: https://carnetdeshopping.com/index.php/2015/06/12/ventes-privees-ete-2015/feed/
[Thu Jul 30 13:55:36.713560 2026] [security2:error] [pid 961194:tid 961372] [client 89.238.167.134:58646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amueKPSWp157EsYqB3ognwAAADA"]
[Thu Jul 30 13:55:36.713673 2026] [security2:error] [pid 961194:tid 961372] [client 89.238.167.134:58646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amueKPSWp157EsYqB3ognwAAADA"]
[Thu Jul 30 13:55:36.947343 2026] [security2:error] [pid 961194:tid 961353] [client 74.7.244.63:56218] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amueKPSWp157EsYqB3ogogAAHRI"], referer: https://northyorksheridanmall.com/robots.txt
[Thu Jul 30 13:55:37.069749 2026] [security2:error] [pid 961194:tid 961338] [client 172.202.95.21:38472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/function/function.php"] [unique_id "amueKfSWp157EsYqB3ogpwAAAA4"]
[Thu Jul 30 13:55:37.088402 2026] [security2:error] [pid 961194:tid 961311] [remote 52.167.144.214:6449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Caruban/article/download/8748/3482/22890"] [unique_id "amueKfSWp157EsYqB3ogqAAAVHQ"]
[Thu Jul 30 13:55:37.109042 2026] [core:error] [pid 961194:tid 961445] [client 87.236.176.121:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:55:37.109073 2026] [core:error] [pid 961194:tid 961445] [client 87.236.176.121:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:55:37.399234 2026] [security2:error] [pid 961194:tid 961351] [client 172.202.95.21:60028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "remoteworksit.com"] [uri "/584062352875874akp.php"] [unique_id "amueKfSWp157EsYqB3oguAAAABs"]
[Thu Jul 30 13:55:37.399344 2026] [security2:error] [pid 961194:tid 961351] [client 172.202.95.21:60028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "remoteworksit.com"] [uri "/584062352875874akp.php"] [unique_id "amueKfSWp157EsYqB3oguAAAABs"]
[Thu Jul 30 13:55:37.664242 2026] [core:notice] [pid 961194:tid 961371] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:38.071828 2026] [security2:error] [pid 961194:tid 961350] [client 172.202.95.21:38687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-signin.php"] [unique_id "amueKvSWp157EsYqB3ogzQAAABo"]
[Thu Jul 30 13:55:38.497760 2026] [security2:error] [pid 961194:tid 961424] [client 172.213.232.128:59501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/database.php"] [unique_id "amueKvSWp157EsYqB3og1QAAAGQ"]
[Thu Jul 30 13:55:38.701550 2026] [security2:error] [pid 961194:tid 961232] [remote 57.141.0.69:52946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/peerreviewers"] [unique_id "amueKvSWp157EsYqB3og3wAADCU"]
[Thu Jul 30 13:55:38.856201 2026] [security2:error] [pid 961194:tid 961363] [client 104.28.161.30:29139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.161.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvape-australia.com"] [uri "/wp-login.php"] [unique_id "amueKvSWp157EsYqB3og3AAAACc"]
[Thu Jul 30 13:55:39.569343 2026] [security2:error] [pid 961194:tid 961419] [client 172.213.232.128:59695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/db.php"] [unique_id "amueK_SWp157EsYqB3og7gAAAF8"]
[Thu Jul 30 13:55:39.759022 2026] [security2:error] [pid 961194:tid 961434] [client 74.7.228.41:47290] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.tlt.zzt.temporary.site"] [uri "/index.php"] [unique_id "amueKfSWp157EsYqB3ogyAAAbhM"]
[Thu Jul 30 13:55:39.830267 2026] [security2:error] [pid 961194:tid 961413] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.lapakjitu78.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amueK_SWp157EsYqB3og-gAAAFk"]
[Thu Jul 30 13:55:40.102365 2026] [security2:error] [pid 961194:tid 961446] [client 172.202.95.21:38717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/f35.php"] [unique_id "amueLPSWp157EsYqB3og-wAAAHo"]
[Thu Jul 30 13:55:40.311854 2026] [core:notice] [pid 961194:tid 961367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:41.093058 2026] [security2:error] [pid 961194:tid 961400] [client 172.213.232.128:62220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/default.php"] [unique_id "amueLfSWp157EsYqB3ohEgAAAEw"]
[Thu Jul 30 13:55:41.180538 2026] [security2:error] [pid 961194:tid 961429] [client 172.202.95.21:38656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/gg.php"] [unique_id "amueLfSWp157EsYqB3ohFAAAAGk"]
[Thu Jul 30 13:55:41.714188 2026] [security2:error] [pid 961194:tid 961218] [remote 148.113.130.163:63636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-se-concord/feed/"] [unique_id "amueLfSWp157EsYqB3ohHgAAdxc"]
[Thu Jul 30 13:55:41.714352 2026] [security2:error] [pid 961194:tid 961443] [client 148.113.130.163:63636] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-se-concord/feed/"] [unique_id "amueLfSWp157EsYqB3ohHgAAdxc"]
[Thu Jul 30 13:55:41.931572 2026] [security2:error] [pid 961194:tid 961415] [client 78.167.1.90:54997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueLfSWp157EsYqB3ohJQAAAFs"]
[Thu Jul 30 13:55:41.932108 2026] [security2:error] [pid 961194:tid 961415] [client 78.167.1.90:54997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueLfSWp157EsYqB3ohJQAAAFs"]
[Thu Jul 30 13:55:42.068786 2026] [security2:error] [pid 961194:tid 961339] [client 172.202.95.21:38380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/class.php"] [unique_id "amueLvSWp157EsYqB3ohKwAAAA8"]
[Thu Jul 30 13:55:42.092475 2026] [security2:error] [pid 961194:tid 961431] [client 172.213.232.128:56037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/dropdown.php"] [unique_id "amueLvSWp157EsYqB3ohLAAAAGs"]
[Thu Jul 30 13:55:42.331003 2026] [security2:error] [pid 961194:tid 961441] [client 57.141.0.29:64264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amueLfSWp157EsYqB3ohKQAAdTM"], referer: https://igetvape-australia.com/product/iget-bar-plus-s3-kit-double-apple/
[Thu Jul 30 13:55:43.237925 2026] [security2:error] [pid 961194:tid 961409] [client 172.202.95.21:38355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/flower.php"] [unique_id "amueL_SWp157EsYqB3ohSAAAAFU"]
[Thu Jul 30 13:55:43.272379 2026] [security2:error] [pid 961194:tid 961324] [client 172.213.232.128:62239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/edit.php"] [unique_id "amueL_SWp157EsYqB3ohSQAAAAA"]
[Thu Jul 30 13:55:44.114174 2026] [security2:error] [pid 961194:tid 961388] [client 172.202.95.21:38426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/motu.php"] [unique_id "amueMPSWp157EsYqB3ohYgAAAEA"]
[Thu Jul 30 13:55:44.329894 2026] [security2:error] [pid 961194:tid 961343] [client 172.213.232.128:50458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/f35.php"] [unique_id "amueMPSWp157EsYqB3ohZAAAABM"]
[Thu Jul 30 13:55:44.332140 2026] [security2:error] [pid 961194:tid 961402] [client 103.242.199.184:57986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueMPSWp157EsYqB3ohZQAAAE4"]
[Thu Jul 30 13:55:44.333013 2026] [security2:error] [pid 961194:tid 961402] [client 103.242.199.184:57986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueMPSWp157EsYqB3ohZQAAAE4"]
[Thu Jul 30 13:55:44.515316 2026] [security2:error] [pid 961194:tid 961449] [client 172.237.109.114:50565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueMPSWp157EsYqB3ohXgAAAH0"]
[Thu Jul 30 13:55:44.702838 2026] [security2:error] [pid 961194:tid 961441] [client 103.190.40.154:17487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueMPSWp157EsYqB3ohbgAAAHU"]
[Thu Jul 30 13:55:44.702962 2026] [security2:error] [pid 961194:tid 961441] [client 103.190.40.154:17487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueMPSWp157EsYqB3ohbgAAAHU"]
[Thu Jul 30 13:55:44.970523 2026] [security2:error] [pid 961194:tid 961420] [client 172.213.232.128:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fireworkskenya.co.ke"] [uri "/f7.php"] [unique_id "amueMPSWp157EsYqB3ohcwAAAGA"]
[Thu Jul 30 13:55:45.181565 2026] [security2:error] [pid 961194:tid 961380] [client 172.202.95.21:38436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/404.php"] [unique_id "amueMfSWp157EsYqB3ohewAAADg"]
[Thu Jul 30 13:55:45.445615 2026] [core:notice] [pid 961194:tid 961390] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:45.591808 2026] [security2:error] [pid 961194:tid 961342] [client 181.116.200.68:59005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueMfSWp157EsYqB3ohhQAAABI"]
[Thu Jul 30 13:55:45.591934 2026] [security2:error] [pid 961194:tid 961342] [client 181.116.200.68:59005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueMfSWp157EsYqB3ohhQAAABI"]
[Thu Jul 30 13:55:45.693569 2026] [security2:error] [pid 961194:tid 961404] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueMfSWp157EsYqB3ohegAAUGI"]
[Thu Jul 30 13:55:45.775828 2026] [core:notice] [pid 961194:tid 961352] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:45.921987 2026] [proxy:error] [pid 961194:tid 961409] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:45.922071 2026] [proxy_http:error] [pid 961194:tid 961409] [client 193.47.62.167:43558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:45.922650 2026] [proxy:error] [pid 961194:tid 961409] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:45.922692 2026] [proxy_http:error] [pid 961194:tid 961409] [client 193.47.62.167:43558] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:46.200908 2026] [security2:error] [pid 961194:tid 961340] [client 172.202.95.21:38424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/lite.php"] [unique_id "amueMvSWp157EsYqB3ohlwAAABA"]
[Thu Jul 30 13:55:46.214773 2026] [core:notice] [pid 961194:tid 961407] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:46.383089 2026] [security2:error] [pid 961194:tid 961450] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueMfSWp157EsYqB3ohfQAAfmg"]
[Thu Jul 30 13:55:46.453888 2026] [core:notice] [pid 961194:tid 961372] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:46.730693 2026] [core:notice] [pid 961194:tid 961371] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:47.006932 2026] [core:notice] [pid 961194:tid 961365] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:47.244870 2026] [security2:error] [pid 961194:tid 961331] [client 172.202.95.21:38403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/lock360.php"] [unique_id "amueM_SWp157EsYqB3ohsAAAAAc"]
[Thu Jul 30 13:55:47.283405 2026] [core:notice] [pid 961194:tid 961408] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:47.602682 2026] [core:notice] [pid 961194:tid 961334] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:48.057457 2026] [security2:error] [pid 961194:tid 961381] [client 172.202.95.21:38402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/wp-conflg.php"] [unique_id "amueNPSWp157EsYqB3ohyAAAADk"]
[Thu Jul 30 13:55:48.145327 2026] [core:notice] [pid 961194:tid 961390] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:48.149035 2026] [security2:error] [pid 961194:tid 961390] [client 157.230.86.105:43666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/P9KrEq.php"] [unique_id "amueM_SWp157EsYqB3ohxwAAAEI"]
[Thu Jul 30 13:55:48.272502 2026] [security2:error] [pid 961194:tid 961398] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amueM_SWp157EsYqB3ohuQAAAEo"]
[Thu Jul 30 13:55:48.424642 2026] [core:notice] [pid 961194:tid 961392] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:48.428114 2026] [security2:error] [pid 961194:tid 961392] [client 157.230.86.105:43666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/JCNBQB.php"] [unique_id "amueNPSWp157EsYqB3oh1AAAAEQ"]
[Thu Jul 30 13:55:48.701611 2026] [fcgid:warn] [pid 961194:tid 961364] (70014)End of file found: [client 18.116.101.220:59350] mod_fcgid: can't get data from http client
[Thu Jul 30 13:55:48.705016 2026] [security2:error] [pid 961194:tid 961210] [remote 74.7.243.224:44106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/content/content/login.php"] [unique_id "amueNPSWp157EsYqB3oh3gAANw8"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/content/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 13:55:48.705089 2026] [core:notice] [pid 961194:tid 961395] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:48.897523 2026] [core:notice] [pid 961194:tid 961202] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:48.936566 2026] [security2:error] [pid 961194:tid 961349] [client 172.202.95.21:38460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-links-opml.php"] [unique_id "amueNPSWp157EsYqB3oh5gAAABk"]
[Thu Jul 30 13:55:49.018306 2026] [core:notice] [pid 961194:tid 961351] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:49.296867 2026] [core:notice] [pid 961194:tid 961347] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:49.576416 2026] [core:notice] [pid 961194:tid 961385] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:49.856626 2026] [core:notice] [pid 961194:tid 961367] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:50.136524 2026] [core:notice] [pid 961194:tid 961442] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:50.200689 2026] [security2:error] [pid 961194:tid 961427] [client 172.202.95.21:38694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/.alf.php"] [unique_id "amueNvSWp157EsYqB3oiBAAAAGc"]
[Thu Jul 30 13:55:50.357604 2026] [security2:error] [pid 961194:tid 961370] [client 172.202.95.21:59994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "remoteworksit.com"] [uri "/newfile.php"] [unique_id "amueNvSWp157EsYqB3oiCwAAAC4"]
[Thu Jul 30 13:55:50.357699 2026] [security2:error] [pid 961194:tid 961370] [client 172.202.95.21:59994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "remoteworksit.com"] [uri "/newfile.php"] [unique_id "amueNvSWp157EsYqB3oiCwAAAC4"]
[Thu Jul 30 13:55:50.455091 2026] [core:notice] [pid 961194:tid 961423] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:50.588142 2026] [security2:error] [pid 961194:tid 961428] [client 189.6.88.213:55583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueNvSWp157EsYqB3oiDQAAAGg"]
[Thu Jul 30 13:55:50.588244 2026] [security2:error] [pid 961194:tid 961428] [client 189.6.88.213:55583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueNvSWp157EsYqB3oiDQAAAGg"]
[Thu Jul 30 13:55:51.055121 2026] [core:notice] [pid 961194:tid 961324] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:51.744190 2026] [core:notice] [pid 961194:tid 961419] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:51.942544 2026] [core:notice] [pid 961194:tid 961368] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.032422 2026] [core:notice] [pid 961194:tid 961374] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.057682 2026] [core:notice] [pid 961194:tid 961325] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.057683 2026] [core:notice] [pid 961194:tid 961431] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.059363 2026] [core:notice] [pid 961194:tid 961376] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.069690 2026] [core:notice] [pid 961194:tid 961426] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.070457 2026] [core:notice] [pid 961194:tid 961394] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.076717 2026] [core:notice] [pid 961194:tid 961385] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.096429 2026] [core:notice] [pid 961194:tid 961333] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.138992 2026] [security2:error] [pid 961194:tid 961393] [client 172.202.95.21:38450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/ws.php"] [unique_id "amueOPSWp157EsYqB3oiSQAAAEU"]
[Thu Jul 30 13:55:52.147995 2026] [core:notice] [pid 961194:tid 961334] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.161903 2026] [core:notice] [pid 961194:tid 961436] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.190492 2026] [core:notice] [pid 961194:tid 961410] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.211782 2026] [core:notice] [pid 961194:tid 961383] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.215893 2026] [core:notice] [pid 961194:tid 961350] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.216133 2026] [core:notice] [pid 961194:tid 961357] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.217082 2026] [core:notice] [pid 961194:tid 961403] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.232647 2026] [core:notice] [pid 961194:tid 961355] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.295737 2026] [core:notice] [pid 961194:tid 961381] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.301010 2026] [core:notice] [pid 961194:tid 961384] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.327192 2026] [security2:error] [pid 961194:tid 961216] [remote 52.167.144.23:61140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/REFORMASI/article/download/4900/2314/13497"] [unique_id "amueOPSWp157EsYqB3oiRQAAUhU"]
[Thu Jul 30 13:55:52.463898 2026] [security2:error] [pid 961194:tid 961379] [client 172.202.95.21:60012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "remoteworksit.com"] [uri "/tBEZGQz.php"] [unique_id "amueOPSWp157EsYqB3oiYAAAADc"]
[Thu Jul 30 13:55:52.464028 2026] [security2:error] [pid 961194:tid 961379] [client 172.202.95.21:60012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "remoteworksit.com"] [uri "/tBEZGQz.php"] [unique_id "amueOPSWp157EsYqB3oiYAAAADc"]
[Thu Jul 30 13:55:52.534561 2026] [core:notice] [pid 961194:tid 961421] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.576147 2026] [core:notice] [pid 961194:tid 961423] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.584732 2026] [core:notice] [pid 961194:tid 961444] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.861206 2026] [core:notice] [pid 961194:tid 961341] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.862224 2026] [core:notice] [pid 961194:tid 961366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:52.879240 2026] [core:notice] [pid 961194:tid 961328] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:53.013369 2026] [security2:error] [pid 961194:tid 961340] [client 172.202.95.21:38448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/css/index.php"] [unique_id "amueOfSWp157EsYqB3oieAAAABA"]
[Thu Jul 30 13:55:53.700213 2026] [core:notice] [pid 961194:tid 961449] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:53.920855 2026] [core:notice] [pid 961194:tid 961440] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:53.927242 2026] [core:notice] [pid 961194:tid 961405] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:53.982752 2026] [core:notice] [pid 961194:tid 961364] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:54.188372 2026] [core:notice] [pid 961194:tid 961353] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:54.211873 2026] [security2:error] [pid 961194:tid 961338] [client 74.7.230.13:46358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.milfordauto.com"] [uri "/cgi-sys/404.html"] [unique_id "amueOvSWp157EsYqB3oiqwAADhk"]
[Thu Jul 30 13:55:54.277110 2026] [core:notice] [pid 961194:tid 961356] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:54.439562 2026] [core:notice] [pid 961194:tid 961340] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:54.539304 2026] [core:notice] [pid 961194:tid 961418] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:54.621132 2026] [core:notice] [pid 961194:tid 961374] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:54.734868 2026] [core:notice] [pid 961194:tid 961376] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:54.788184 2026] [core:notice] [pid 961194:tid 961362] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:54.925113 2026] [core:notice] [pid 961194:tid 961414] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:54.942329 2026] [core:notice] [pid 961194:tid 961346] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.025248 2026] [security2:error] [pid 961194:tid 961408] [client 103.242.199.184:58540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueO_SWp157EsYqB3oi0gAAAFQ"]
[Thu Jul 30 13:55:55.025384 2026] [security2:error] [pid 961194:tid 961408] [client 103.242.199.184:58540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueO_SWp157EsYqB3oi0gAAAFQ"]
[Thu Jul 30 13:55:55.079406 2026] [core:notice] [pid 961194:tid 961384] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.224256 2026] [core:notice] [pid 961194:tid 961404] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.367439 2026] [core:notice] [pid 961194:tid 961411] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.430448 2026] [core:notice] [pid 961194:tid 961400] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.551680 2026] [core:notice] [pid 961194:tid 961353] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.569950 2026] [core:notice] [pid 961194:tid 961371] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.596675 2026] [security2:error] [pid 961194:tid 961370] [client 172.202.95.21:38674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/ioxi-o.php"] [unique_id "amueO_SWp157EsYqB3oi5gAAAC4"]
[Thu Jul 30 13:55:55.624777 2026] [security2:error] [pid 961194:tid 961392] [client 78.167.1.90:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueO_SWp157EsYqB3oi5wAAAEQ"]
[Thu Jul 30 13:55:55.624900 2026] [security2:error] [pid 961194:tid 961392] [client 78.167.1.90:55390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueO_SWp157EsYqB3oi5wAAAEQ"]
[Thu Jul 30 13:55:55.628021 2026] [security2:error] [pid 961194:tid 961421] [client 103.190.40.154:21396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueO_SWp157EsYqB3oi6AAAAGE"]
[Thu Jul 30 13:55:55.628144 2026] [security2:error] [pid 961194:tid 961421] [client 103.190.40.154:21396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueO_SWp157EsYqB3oi6AAAAGE"]
[Thu Jul 30 13:55:55.637993 2026] [core:notice] [pid 961194:tid 961423] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.660088 2026] [security2:error] [pid 961194:tid 961440] [client 52.167.144.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amueO_SWp157EsYqB3oi1wAAAHQ"]
[Thu Jul 30 13:55:55.820245 2026] [core:notice] [pid 961194:tid 961387] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.822477 2026] [core:notice] [pid 961194:tid 961420] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.837957 2026] [core:notice] [pid 961194:tid 961366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:55.849433 2026] [autoindex:error] [pid 961194:tid 961422] [client 32.194.121.99:40026] AH01276: Cannot serve directory /home1/tdunyxte/public_html/svcambodia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:55:55.980043 2026] [core:notice] [pid 961194:tid 961345] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:56.004200 2026] [core:notice] [pid 961194:tid 961451] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:56.083921 2026] [security2:error] [pid 961194:tid 961445] [client 181.116.200.68:54639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuePPSWp157EsYqB3oi_wAAAHk"]
[Thu Jul 30 13:55:56.084064 2026] [security2:error] [pid 961194:tid 961445] [client 181.116.200.68:54639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuePPSWp157EsYqB3oi_wAAAHk"]
[Thu Jul 30 13:55:56.134494 2026] [security2:error] [pid 961194:tid 961337] [client 68.67.112.136:37496] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amuePPSWp157EsYqB3ojAgAAAA0"]
[Thu Jul 30 13:55:56.150465 2026] [proxy:error] [pid 961194:tid 961330] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:56.150552 2026] [proxy_http:error] [pid 961194:tid 961330] [client 52.202.41.153:56496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:56.150871 2026] [proxy:error] [pid 961194:tid 961418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:56.150924 2026] [proxy_http:error] [pid 961194:tid 961418] [client 52.202.41.153:32034] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:56.151128 2026] [proxy:error] [pid 961194:tid 961330] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:56.151175 2026] [proxy_http:error] [pid 961194:tid 961330] [client 52.202.41.153:56496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:56.151486 2026] [proxy:error] [pid 961194:tid 961418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:55:56.151530 2026] [proxy_http:error] [pid 961194:tid 961418] [client 52.202.41.153:32034] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:55:56.155996 2026] [core:notice] [pid 961194:tid 961374] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:56.277926 2026] [core:notice] [pid 961194:tid 961431] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:56.281748 2026] [security2:error] [pid 961194:tid 961382] [client 172.202.95.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "remoteworksit.com"] [uri "/index.php"] [unique_id "amuePPSWp157EsYqB3oi_gAAADo"]
[Thu Jul 30 13:55:56.281781 2026] [security2:error] [pid 961194:tid 961382] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "remoteworksit.com"] [uri "/index.php"] [unique_id "amuePPSWp157EsYqB3oi_gAAADo"]
[Thu Jul 30 13:55:56.282161 2026] [security2:error] [pid 961194:tid 961434] [client 172.202.95.21:60000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "remoteworksit.com"] [uri "/phpinfo"] [unique_id "amuePPSWp157EsYqB3oi_AAAAG4"]
[Thu Jul 30 13:55:56.416623 2026] [core:notice] [pid 961194:tid 961391] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:56.498164 2026] [core:notice] [pid 961194:tid 961436] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:56.656392 2026] [core:notice] [pid 961194:tid 961424] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:56.979070 2026] [core:notice] [pid 961194:tid 961383] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.002155 2026] [core:notice] [pid 961194:tid 961348] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.021013 2026] [core:error] [pid 961194:tid 961354] [client 74.7.244.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:55:57.021038 2026] [core:error] [pid 961194:tid 961354] [client 74.7.244.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:55:57.021139 2026] [security2:error] [pid 961194:tid 961354] [client 74.7.244.35:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.nsp.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuePfSWp157EsYqB3ojKAAAAB4"]
[Thu Jul 30 13:55:57.021750 2026] [security2:error] [pid 961194:tid 961425] [client 74.7.244.35:33210] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.nsp.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuePfSWp157EsYqB3ojJgAAZRw"]
[Thu Jul 30 13:55:57.112933 2026] [core:notice] [pid 961194:tid 961356] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.131130 2026] [core:notice] [pid 961194:tid 961366] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.374453 2026] [core:notice] [pid 961194:tid 961451] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.433677 2026] [core:notice] [pid 961194:tid 961339] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.435179 2026] [core:notice] [pid 961194:tid 961373] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.436060 2026] [core:notice] [pid 961194:tid 961415] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.541860 2026] [core:notice] [pid 961194:tid 961362] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.598717 2026] [core:notice] [pid 961194:tid 961431] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.615877 2026] [core:notice] [pid 961194:tid 961434] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:57.762469 2026] [core:notice] [pid 961194:tid 961326] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:58.085575 2026] [core:notice] [pid 961194:tid 961384] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:55:58.446575 2026] [security2:error] [pid 961194:tid 961389] [client 189.6.88.213:56111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuePvSWp157EsYqB3ojVgAAAEE"]
[Thu Jul 30 13:55:58.446714 2026] [security2:error] [pid 961194:tid 961389] [client 189.6.88.213:56111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuePvSWp157EsYqB3ojVgAAAEE"]
[Thu Jul 30 13:55:58.778324 2026] [security2:error] [pid 961194:tid 961407] [client 172.202.95.21:38675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/ws54.php"] [unique_id "amuePvSWp157EsYqB3ojYQAAAFM"]
[Thu Jul 30 13:55:59.922083 2026] [security2:error] [pid 961194:tid 961398] [client 172.202.95.21:38366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/155.php"] [unique_id "amueP_SWp157EsYqB3ojfAAAAEo"]
[Thu Jul 30 13:55:59.957650 2026] [core:notice] [pid 961194:tid 961331] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:00.023161 2026] [security2:error] [pid 961194:tid 961351] [client 54.241.134.202:24924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuePfSWp157EsYqB3ojNwAAABs"]
[Thu Jul 30 13:56:00.262608 2026] [security2:error] [pid 961194:tid 961361] [client 52.167.144.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amueP_SWp157EsYqB3ojewAAACU"]
[Thu Jul 30 13:56:00.878388 2026] [core:error] [pid 961194:tid 961422] [client 74.7.175.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:56:00.878410 2026] [core:error] [pid 961194:tid 961422] [client 74.7.175.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:56:00.878543 2026] [security2:error] [pid 961194:tid 961422] [client 74.7.175.173:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.1lightroom.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amueQPSWp157EsYqB3ojmQAAAGI"]
[Thu Jul 30 13:56:00.879322 2026] [security2:error] [pid 961194:tid 961421] [client 74.7.175.173:57466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.1lightroom.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amueQPSWp157EsYqB3ojlwAAYWI"]
[Thu Jul 30 13:56:01.068248 2026] [security2:error] [pid 961194:tid 961389] [client 172.202.95.21:38457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/min.php"] [unique_id "amueQfSWp157EsYqB3ojnAAAAEE"]
[Thu Jul 30 13:56:01.196122 2026] [core:notice] [pid 961194:tid 961284] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:01.745648 2026] [security2:error] [pid 961194:tid 961362] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amueQfSWp157EsYqB3ojqwAAJmE"]
[Thu Jul 30 13:56:02.725391 2026] [security2:error] [pid 961194:tid 961300] [remote 216.73.217.142:9261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amueQvSWp157EsYqB3ojzQAALmk"]
[Thu Jul 30 13:56:02.923547 2026] [security2:error] [pid 961194:tid 961410] [client 172.202.95.21:38447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/xmlrpc.php"] [unique_id "amueQvSWp157EsYqB3ojyQAAAFY"]
[Thu Jul 30 13:56:03.175449 2026] [security2:error] [pid 961194:tid 961349] [client 78.167.1.90:55827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueQ_SWp157EsYqB3oj2QAAABk"]
[Thu Jul 30 13:56:03.176000 2026] [security2:error] [pid 961194:tid 961349] [client 78.167.1.90:55827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueQ_SWp157EsYqB3oj2QAAABk"]
[Thu Jul 30 13:56:03.308382 2026] [security2:error] [pid 961194:tid 961437] [client 134.19.179.155:40564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amueQ_SWp157EsYqB3oj4gAAAHE"]
[Thu Jul 30 13:56:03.308480 2026] [security2:error] [pid 961194:tid 961437] [client 134.19.179.155:40564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amueQ_SWp157EsYqB3oj4gAAAHE"]
[Thu Jul 30 13:56:04.003614 2026] [security2:error] [pid 961194:tid 961301] [remote 57.141.0.64:64120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amueRPSWp157EsYqB3oj9AAAEmo"]
[Thu Jul 30 13:56:04.254489 2026] [security2:error] [pid 961194:tid 961403] [client 172.202.95.21:38657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/tinyfilemanager.php"] [unique_id "amueRPSWp157EsYqB3oj-wAAAE8"]
[Thu Jul 30 13:56:04.871497 2026] [core:notice] [pid 961194:tid 961204] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:05.654676 2026] [security2:error] [pid 961194:tid 961437] [client 103.242.199.184:59165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueRfSWp157EsYqB3okHwAAAHE"]
[Thu Jul 30 13:56:05.654793 2026] [security2:error] [pid 961194:tid 961437] [client 103.242.199.184:59165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueRfSWp157EsYqB3okHwAAAHE"]
[Thu Jul 30 13:56:05.789318 2026] [security2:error] [pid 961194:tid 961369] [client 172.202.95.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.remoteworksit.com"] [uri "/index.php"] [unique_id "amueRfSWp157EsYqB3okHgAAAC0"]
[Thu Jul 30 13:56:05.789352 2026] [security2:error] [pid 961194:tid 961369] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.remoteworksit.com"] [uri "/index.php"] [unique_id "amueRfSWp157EsYqB3okHgAAAC0"]
[Thu Jul 30 13:56:05.789592 2026] [security2:error] [pid 961194:tid 961418] [client 172.202.95.21:44173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.remoteworksit.com"] [uri "/phpinfo"] [unique_id "amueRfSWp157EsYqB3okHAAAAF4"]
[Thu Jul 30 13:56:06.522374 2026] [security2:error] [pid 961194:tid 961334] [client 103.190.40.154:22061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueRvSWp157EsYqB3okNQAAAAo"]
[Thu Jul 30 13:56:06.522526 2026] [security2:error] [pid 961194:tid 961334] [client 103.190.40.154:22061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueRvSWp157EsYqB3okNQAAAAo"]
[Thu Jul 30 13:56:06.803628 2026] [security2:error] [pid 961194:tid 961448] [client 66.249.93.2:59150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amueRvSWp157EsYqB3okNAAAAHw"]
[Thu Jul 30 13:56:06.822837 2026] [security2:error] [pid 961194:tid 961330] [client 181.116.200.68:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueRvSWp157EsYqB3okOwAAAAY"]
[Thu Jul 30 13:56:06.823000 2026] [security2:error] [pid 961194:tid 961330] [client 181.116.200.68:15584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueRvSWp157EsYqB3okOwAAAAY"]
[Thu Jul 30 13:56:06.898162 2026] [security2:error] [pid 961194:tid 961375] [client 172.202.95.21:38667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/hplfuns.php"] [unique_id "amueRvSWp157EsYqB3okPAAAADM"]
[Thu Jul 30 13:56:07.597738 2026] [security2:error] [pid 961194:tid 961240] [remote 57.141.0.71:56692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amueR_SWp157EsYqB3okUQAAMS0"]
[Thu Jul 30 13:56:07.642144 2026] [security2:error] [pid 961194:tid 961234] [remote 57.141.0.41:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amueR_SWp157EsYqB3okUgAAcSc"]
[Thu Jul 30 13:56:08.533344 2026] [security2:error] [pid 961194:tid 961401] [client 172.202.95.21:38423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/bthil.php"] [unique_id "amueSPSWp157EsYqB3okZQAAAE0"]
[Thu Jul 30 13:56:09.170969 2026] [security2:error] [pid 961194:tid 961422] [client 189.6.88.213:56647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueSfSWp157EsYqB3okegAAAGI"]
[Thu Jul 30 13:56:09.171119 2026] [security2:error] [pid 961194:tid 961422] [client 189.6.88.213:56647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueSfSWp157EsYqB3okegAAAGI"]
[Thu Jul 30 13:56:09.628235 2026] [security2:error] [pid 961194:tid 961413] [client 172.202.95.21:38416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/cv.php"] [unique_id "amueSfSWp157EsYqB3okhgAAAFk"]
[Thu Jul 30 13:56:10.086232 2026] [proxy:error] [pid 961194:tid 961398] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:10.086301 2026] [proxy_http:error] [pid 961194:tid 961398] [client 32.194.121.99:34942] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:10.086970 2026] [proxy:error] [pid 961194:tid 961398] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:10.087033 2026] [proxy_http:error] [pid 961194:tid 961398] [client 32.194.121.99:34942] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:10.104763 2026] [proxy:error] [pid 961194:tid 961414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:10.104841 2026] [proxy_http:error] [pid 961194:tid 961414] [client 34.233.129.35:47907] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:10.105410 2026] [proxy:error] [pid 961194:tid 961414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:10.105456 2026] [proxy_http:error] [pid 961194:tid 961414] [client 34.233.129.35:47907] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:10.299672 2026] [security2:error] [pid 961194:tid 961378] [client 172.202.95.21:44190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "remoteworksit.com"] [uri "/drykl.php"] [unique_id "amueSvSWp157EsYqB3okoAAAADY"]
[Thu Jul 30 13:56:10.299763 2026] [security2:error] [pid 961194:tid 961378] [client 172.202.95.21:44190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "remoteworksit.com"] [uri "/drykl.php"] [unique_id "amueSvSWp157EsYqB3okoAAAADY"]
[Thu Jul 30 13:56:10.363811 2026] [core:error] [pid 961194:tid 961302] [remote 74.7.230.37:33346] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:56:10.363834 2026] [core:error] [pid 961194:tid 961302] [remote 74.7.230.37:33346] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:56:10.364043 2026] [security2:error] [pid 961194:tid 961356] [client 74.7.230.37:33346] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "alriwaqfurnituremovers.cc"] [uri "/index.php"] [unique_id "amueSvSWp157EsYqB3okogAAIGs"]
[Thu Jul 30 13:56:10.369908 2026] [security2:error] [pid 961194:tid 961367] [client 74.7.244.63:39208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amueSvSWp157EsYqB3okoQAAK34"]
[Thu Jul 30 13:56:10.369929 2026] [security2:error] [pid 961194:tid 961367] [client 74.7.244.63:39208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amueSvSWp157EsYqB3okoQAAK34"]
[Thu Jul 30 13:56:10.485250 2026] [core:notice] [pid 961194:tid 961274] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:10.962362 2026] [security2:error] [pid 961194:tid 961338] [client 172.202.95.21:38765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/sf.php"] [unique_id "amueSvSWp157EsYqB3oktAAAAA4"]
[Thu Jul 30 13:56:11.051071 2026] [security2:error] [pid 961194:tid 961407] [client 74.7.244.63:43192] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amueSvSWp157EsYqB3oktQAAUyQ"], referer: https://northyorksheridanmall.com/robots.txt
[Thu Jul 30 13:56:12.931831 2026] [security2:error] [pid 961194:tid 961437] [client 185.177.72.70:61012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueS_SWp157EsYqB3okxwAAAHE"]
[Thu Jul 30 13:56:13.505929 2026] [security2:error] [pid 961194:tid 961411] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueTPSWp157EsYqB3ok3wAAV1E"]
[Thu Jul 30 13:56:13.522215 2026] [security2:error] [pid 961194:tid 961254] [remote 57.141.0.18:35174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/view/9413"] [unique_id "amueTfSWp157EsYqB3ok9wAAeDs"]
[Thu Jul 30 13:56:13.702631 2026] [security2:error] [pid 961194:tid 961358] [client 172.237.109.114:60198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueTfSWp157EsYqB3ok5QAAACI"]
[Thu Jul 30 13:56:13.808428 2026] [security2:error] [pid 961194:tid 961440] [client 78.167.1.90:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueTfSWp157EsYqB3ok_gAAAHQ"]
[Thu Jul 30 13:56:13.809237 2026] [security2:error] [pid 961194:tid 961440] [client 78.167.1.90:55695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueTfSWp157EsYqB3ok_gAAAHQ"]
[Thu Jul 30 13:56:13.889564 2026] [security2:error] [pid 961194:tid 961371] [client 74.7.244.40:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.sharjahfurnituremoversandpackers.space"] [uri "/index.php"] [unique_id "amueTfSWp157EsYqB3ok7wAAAC8"]
[Thu Jul 30 13:56:13.890326 2026] [security2:error] [pid 961194:tid 961372] [client 74.7.244.40:38484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.sharjahfurnituremoversandpackers.space"] [uri "/robots.txt"] [unique_id "amueTfSWp157EsYqB3ok7QAAMEM"]
[Thu Jul 30 13:56:13.946800 2026] [security2:error] [pid 961194:tid 961349] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueTfSWp157EsYqB3olBAAAABk"]
[Thu Jul 30 13:56:14.206433 2026] [security2:error] [pid 961194:tid 961384] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueTvSWp157EsYqB3olCgAAADw"]
[Thu Jul 30 13:56:14.455598 2026] [security2:error] [pid 961194:tid 961383] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueTvSWp157EsYqB3olEwAAADs"]
[Thu Jul 30 13:56:14.535342 2026] [security2:error] [pid 961194:tid 961319] [remote 47.128.97.51:53118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/al-seer-marine-lists-shares-on-abu-dhabi-securities-exchange/"] [unique_id "amueTvSWp157EsYqB3olGgAAY3w"]
[Thu Jul 30 13:56:14.592816 2026] [security2:error] [pid 961194:tid 961291] [remote 185.177.72.70:1322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueTvSWp157EsYqB3olGwAAUmA"]
[Thu Jul 30 13:56:14.823997 2026] [security2:error] [pid 961194:tid 961345] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueTvSWp157EsYqB3olIQAAABU"]
[Thu Jul 30 13:56:14.959993 2026] [security2:error] [pid 961194:tid 961300] [remote 185.177.72.70:1322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueTvSWp157EsYqB3olKgAAe2k"]
[Thu Jul 30 13:56:15.159035 2026] [security2:error] [pid 961194:tid 961451] [client 52.167.144.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amueTvSWp157EsYqB3olJwAAAH8"]
[Thu Jul 30 13:56:15.223704 2026] [security2:error] [pid 961194:tid 961445] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueT_SWp157EsYqB3olMAAAAHk"]
[Thu Jul 30 13:56:15.482672 2026] [security2:error] [pid 961194:tid 961391] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueT_SWp157EsYqB3olPAAAAEM"]
[Thu Jul 30 13:56:15.733179 2026] [security2:error] [pid 961194:tid 961384] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueT_SWp157EsYqB3olQwAAADw"]
[Thu Jul 30 13:56:15.868334 2026] [security2:error] [pid 961194:tid 961209] [remote 185.177.72.70:1322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/api.swp"] [unique_id "amueT_SWp157EsYqB3olSwAAcQ4"]
[Thu Jul 30 13:56:15.969220 2026] [proxy:error] [pid 961194:tid 961344] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:15.969301 2026] [proxy_http:error] [pid 961194:tid 961344] [client 52.202.41.153:50618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:15.970026 2026] [proxy:error] [pid 961194:tid 961344] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:15.970081 2026] [proxy_http:error] [pid 961194:tid 961344] [client 52.202.41.153:50618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:15.976475 2026] [proxy:error] [pid 961194:tid 961350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:15.976551 2026] [proxy_http:error] [pid 961194:tid 961350] [client 3.228.112.215:8392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:15.977138 2026] [proxy:error] [pid 961194:tid 961350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:15.977186 2026] [proxy_http:error] [pid 961194:tid 961350] [client 3.228.112.215:8392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:16.141996 2026] [proxy:error] [pid 961194:tid 961411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:16.142097 2026] [proxy_http:error] [pid 961194:tid 961411] [client 52.202.41.153:2226] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:16.142779 2026] [proxy:error] [pid 961194:tid 961444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:16.142849 2026] [proxy_http:error] [pid 961194:tid 961444] [client 3.228.112.215:19612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:16.143076 2026] [proxy:error] [pid 961194:tid 961411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:16.143137 2026] [proxy_http:error] [pid 961194:tid 961411] [client 52.202.41.153:2226] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:16.143693 2026] [proxy:error] [pid 961194:tid 961444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:16.143754 2026] [proxy_http:error] [pid 961194:tid 961444] [client 3.228.112.215:19612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:16.191840 2026] [security2:error] [pid 961194:tid 961324] [client 103.242.199.184:59943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueUPSWp157EsYqB3olYAAAAAA"]
[Thu Jul 30 13:56:16.191968 2026] [security2:error] [pid 961194:tid 961324] [client 103.242.199.184:59943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueUPSWp157EsYqB3olYAAAAAA"]
[Thu Jul 30 13:56:16.359692 2026] [autoindex:error] [pid 961194:tid 961346] [client 52.202.41.153:31111] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_3be08eaf/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:56:16.787860 2026] [security2:error] [pid 961194:tid 961341] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueUPSWp157EsYqB3oleQAAABE"]
[Thu Jul 30 13:56:17.296140 2026] [security2:error] [pid 961194:tid 961377] [client 181.116.200.68:58447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueUfSWp157EsYqB3oljAAAADU"]
[Thu Jul 30 13:56:17.296253 2026] [security2:error] [pid 961194:tid 961377] [client 181.116.200.68:58447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueUfSWp157EsYqB3oljAAAADU"]
[Thu Jul 30 13:56:17.303957 2026] [security2:error] [pid 961194:tid 961354] [client 103.190.40.154:20165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueUfSWp157EsYqB3oljQAAAB4"]
[Thu Jul 30 13:56:17.304104 2026] [security2:error] [pid 961194:tid 961354] [client 103.190.40.154:20165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueUfSWp157EsYqB3oljQAAAB4"]
[Thu Jul 30 13:56:17.327620 2026] [fcgid:warn] [pid 961194:tid 961334] (70014)End of file found: [client 66.132.195.51:49460] mod_fcgid: can't get data from http client
[Thu Jul 30 13:56:17.369387 2026] [security2:error] [pid 961194:tid 961404] [client 45.225.118.253:51426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueUfSWp157EsYqB3olhQAAAFA"], referer: http://pkf.jo
[Thu Jul 30 13:56:17.403306 2026] [security2:error] [pid 961194:tid 961442] [client 2a03:2880:f800:46:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueUPSWp157EsYqB3oldwAAdgU"]
[Thu Jul 30 13:56:18.489792 2026] [security2:error] [pid 961194:tid 961243] [remote 57.141.0.2:22870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amueUvSWp157EsYqB3olrwAADzA"]
[Thu Jul 30 13:56:18.596771 2026] [security2:error] [pid 961194:tid 961423] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueUfSWp157EsYqB3olmgAAYyg"]
[Thu Jul 30 13:56:19.247587 2026] [security2:error] [pid 961194:tid 961446] [client 189.218.7.56:57630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueUvSWp157EsYqB3oluAAAAHo"], referer: http://pkf.jo
[Thu Jul 30 13:56:19.340035 2026] [security2:error] [pid 961194:tid 961430] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueU_SWp157EsYqB3olwAAAAGo"]
[Thu Jul 30 13:56:19.528941 2026] [security2:error] [pid 961194:tid 961220] [remote 185.177.72.70:1322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueU_SWp157EsYqB3olzQAAfhk"]
[Thu Jul 30 13:56:19.593905 2026] [security2:error] [pid 961194:tid 961263] [remote 213.180.203.92:64218] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/enhancing-project-management-processes-with-business-consulting/"] [unique_id "amueU_SWp157EsYqB3olzgAARUQ"]
[Thu Jul 30 13:56:19.880821 2026] [security2:error] [pid 961194:tid 961371] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueU_SWp157EsYqB3ol1AAAAC8"]
[Thu Jul 30 13:56:20.166488 2026] [security2:error] [pid 961194:tid 961358] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueVPSWp157EsYqB3ol3gAAACI"]
[Thu Jul 30 13:56:20.489295 2026] [security2:error] [pid 961194:tid 961440] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueVPSWp157EsYqB3ol5QAAAHQ"]
[Thu Jul 30 13:56:20.762191 2026] [security2:error] [pid 961194:tid 961359] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueVPSWp157EsYqB3ol7wAAACM"]
[Thu Jul 30 13:56:20.842683 2026] [core:notice] [pid 961194:tid 961218] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:20.969690 2026] [security2:error] [pid 961194:tid 961260] [remote 185.177.72.70:1322] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.git%00"] [unique_id "amueVPSWp157EsYqB3ol9AAAAkE"]
[Thu Jul 30 13:56:21.360270 2026] [security2:error] [pid 961194:tid 961378] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueVfSWp157EsYqB3ol_gAAADY"]
[Thu Jul 30 13:56:21.974894 2026] [security2:error] [pid 961194:tid 961406] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueVfSWp157EsYqB3omDgAAAFI"]
[Thu Jul 30 13:56:22.233803 2026] [security2:error] [pid 961194:tid 961370] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueVvSWp157EsYqB3omFwAAAC4"]
[Thu Jul 30 13:56:22.487889 2026] [security2:error] [pid 961194:tid 961366] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueVvSWp157EsYqB3omHgAAACo"]
[Thu Jul 30 13:56:22.716319 2026] [security2:error] [pid 961194:tid 961368] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueVvSWp157EsYqB3omKQAAACw"]
[Thu Jul 30 13:56:22.731778 2026] [security2:error] [pid 961194:tid 961278] [remote 216.73.217.142:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amueVvSWp157EsYqB3omLAAAE1M"]
[Thu Jul 30 13:56:22.906034 2026] [security2:error] [pid 961194:tid 961345] [client 190.246.241.13:43784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueVvSWp157EsYqB3omIgAAABU"], referer: http://pkf.jo
[Thu Jul 30 13:56:22.968705 2026] [security2:error] [pid 961194:tid 961339] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueVvSWp157EsYqB3omMAAAAA8"]
[Thu Jul 30 13:56:23.060179 2026] [security2:error] [pid 961194:tid 961385] [client 168.121.190.157:45760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueVvSWp157EsYqB3omLQAAAD0"], referer: http://pkf.jo
[Thu Jul 30 13:56:23.199951 2026] [security2:error] [pid 961194:tid 961403] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueV_SWp157EsYqB3omOgAAAE8"]
[Thu Jul 30 13:56:23.742805 2026] [security2:error] [pid 961194:tid 961383] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueV_SWp157EsYqB3omSAAAADs"]
[Thu Jul 30 13:56:23.979214 2026] [security2:error] [pid 961194:tid 961327] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueV_SWp157EsYqB3omUwAAAAM"]
[Thu Jul 30 13:56:24.211903 2026] [security2:error] [pid 961194:tid 961370] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueWPSWp157EsYqB3omXAAAAC4"]
[Thu Jul 30 13:56:25.310030 2026] [security2:error] [pid 961194:tid 961381] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueWfSWp157EsYqB3omewAAADk"]
[Thu Jul 30 13:56:25.518388 2026] [security2:error] [pid 961194:tid 961345] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amueWPSWp157EsYqB3ombgAAABU"]
[Thu Jul 30 13:56:25.565292 2026] [security2:error] [pid 961194:tid 961211] [remote 185.177.72.70:55104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueWfSWp157EsYqB3omhgAAXBA"]
[Thu Jul 30 13:56:25.695901 2026] [security2:error] [pid 961194:tid 961310] [remote 185.177.72.70:55104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueWfSWp157EsYqB3omhwAAZnM"]
[Thu Jul 30 13:56:25.824134 2026] [security2:error] [pid 961194:tid 961286] [remote 185.177.72.70:55104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueWfSWp157EsYqB3omjgAAAVs"]
[Thu Jul 30 13:56:25.953734 2026] [security2:error] [pid 961194:tid 961300] [remote 185.177.72.70:55104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueWfSWp157EsYqB3omkwAARWk"]
[Thu Jul 30 13:56:26.080112 2026] [security2:error] [pid 961194:tid 961384] [client 103.18.65.138:46246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueWfSWp157EsYqB3omiAAAPGY"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fjavhd.bid
[Thu Jul 30 13:56:26.202961 2026] [security2:error] [pid 961194:tid 961392] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueWvSWp157EsYqB3ommgAAAEQ"]
[Thu Jul 30 13:56:26.454199 2026] [security2:error] [pid 961194:tid 961330] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueWvSWp157EsYqB3omoQAAAAY"]
[Thu Jul 30 13:56:26.705363 2026] [security2:error] [pid 961194:tid 961432] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueWvSWp157EsYqB3omqwAAAGw"]
[Thu Jul 30 13:56:26.855701 2026] [security2:error] [pid 961194:tid 961415] [client 103.242.199.184:60565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueWvSWp157EsYqB3omswAAAFs"]
[Thu Jul 30 13:56:26.855810 2026] [security2:error] [pid 961194:tid 961415] [client 103.242.199.184:60565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueWvSWp157EsYqB3omswAAAFs"]
[Thu Jul 30 13:56:26.955094 2026] [security2:error] [pid 961194:tid 961391] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueWvSWp157EsYqB3omsgAAAEM"]
[Thu Jul 30 13:56:27.388942 2026] [security2:error] [pid 961194:tid 961394] [client 78.167.1.90:56486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueW_SWp157EsYqB3omwwAAAEY"]
[Thu Jul 30 13:56:27.389424 2026] [security2:error] [pid 961194:tid 961394] [client 78.167.1.90:56486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueW_SWp157EsYqB3omwwAAAEY"]
[Thu Jul 30 13:56:27.745095 2026] [security2:error] [pid 961194:tid 961354] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueW_SWp157EsYqB3omzwAAAB4"]
[Thu Jul 30 13:56:27.899726 2026] [security2:error] [pid 961194:tid 961368] [client 74.7.244.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qpsuae.com"] [uri "/index.php"] [unique_id "amueWvSWp157EsYqB3omrAAAACw"]
[Thu Jul 30 13:56:27.924280 2026] [security2:error] [pid 961194:tid 961430] [client 181.116.200.68:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueW_SWp157EsYqB3om0wAAAGo"]
[Thu Jul 30 13:56:27.924381 2026] [security2:error] [pid 961194:tid 961430] [client 181.116.200.68:13261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueW_SWp157EsYqB3om0wAAAGo"]
[Thu Jul 30 13:56:27.982283 2026] [security2:error] [pid 961194:tid 961364] [client 185.177.72.70:55104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueW_SWp157EsYqB3om0QAAKAM"]
[Thu Jul 30 13:56:28.085853 2026] [security2:error] [pid 961194:tid 961334] [client 103.190.40.154:15749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueXPSWp157EsYqB3om2gAAAAo"]
[Thu Jul 30 13:56:28.086008 2026] [security2:error] [pid 961194:tid 961334] [client 103.190.40.154:15749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueXPSWp157EsYqB3om2gAAAAo"]
[Thu Jul 30 13:56:28.371353 2026] [security2:error] [pid 961194:tid 961371] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueXPSWp157EsYqB3om5wAAAC8"]
[Thu Jul 30 13:56:28.463634 2026] [security2:error] [pid 961194:tid 961200] [remote 216.73.217.142:9649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amueXPSWp157EsYqB3om6wAAJAU"]
[Thu Jul 30 13:56:29.080842 2026] [security2:error] [pid 961194:tid 961339] [client 103.238.112.57:35094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueXPSWp157EsYqB3om9wAAAA8"], referer: http://pkf.jo
[Thu Jul 30 13:56:29.167514 2026] [security2:error] [pid 961194:tid 961417] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueXfSWp157EsYqB3onBwAAAF0"]
[Thu Jul 30 13:56:29.179474 2026] [security2:error] [pid 961194:tid 961437] [client 170.82.50.236:46636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueXPSWp157EsYqB3om-wAAcSY"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Ftheporndude.asia
[Thu Jul 30 13:56:29.437004 2026] [security2:error] [pid 961194:tid 961405] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueXfSWp157EsYqB3onEQAAAFE"]
[Thu Jul 30 13:56:29.732531 2026] [security2:error] [pid 961194:tid 961356] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueXfSWp157EsYqB3onHAAAACA"]
[Thu Jul 30 13:56:29.997141 2026] [security2:error] [pid 961194:tid 961376] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueXfSWp157EsYqB3onIwAAADQ"]
[Thu Jul 30 13:56:30.298719 2026] [security2:error] [pid 961194:tid 961353] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueXvSWp157EsYqB3onMgAAAB0"]
[Thu Jul 30 13:56:30.467055 2026] [security2:error] [pid 961194:tid 961397] [client 189.6.88.213:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueXvSWp157EsYqB3onOQAAAEk"]
[Thu Jul 30 13:56:30.467173 2026] [security2:error] [pid 961194:tid 961397] [client 189.6.88.213:57722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueXvSWp157EsYqB3onOQAAAEk"]
[Thu Jul 30 13:56:30.494383 2026] [security2:error] [pid 961194:tid 961379] [client 52.167.144.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amueXvSWp157EsYqB3onMAAAADc"]
[Thu Jul 30 13:56:30.763564 2026] [security2:error] [pid 961194:tid 961260] [remote 51.195.215.199:50062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "smoke-tfhk.com"] [uri "/robots.txt"] [unique_id "amueXvSWp157EsYqB3onRQAADUE"]
[Thu Jul 30 13:56:30.763763 2026] [security2:error] [pid 961194:tid 961337] [client 51.195.215.199:50062] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/robots.txt"] [unique_id "amueXvSWp157EsYqB3onRQAADUE"]
[Thu Jul 30 13:56:30.829257 2026] [security2:error] [pid 961194:tid 961445] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amueXvSWp157EsYqB3onNQAAAHk"]
[Thu Jul 30 13:56:30.844094 2026] [security2:error] [pid 961194:tid 961326] [client 45.237.82.71:49158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueXvSWp157EsYqB3onPgAAAAI"], referer: http://pkf.jo
[Thu Jul 30 13:56:30.938910 2026] [security2:error] [pid 961194:tid 961359] [client 57.141.0.12:56928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amueXvSWp157EsYqB3onPwAAIx0"], referer: https://igetvape-australia.com/product/alibarbar-ingot-strawberry-lychee-ice-9000-puffs/?add-to-cart=928
[Thu Jul 30 13:56:31.074547 2026] [security2:error] [pid 961194:tid 961335] [client 188.53.52.106:7391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueXvSWp157EsYqB3onQwAACxc"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=https%3A%2F%2Fmakemoneyt5.blogspot.com%2F
[Thu Jul 30 13:56:31.516636 2026] [security2:error] [pid 961194:tid 961383] [client 52.167.144.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amueX_SWp157EsYqB3onVwAAADs"]
[Thu Jul 30 13:56:32.153902 2026] [security2:error] [pid 961194:tid 961255] [remote 94.23.188.216:64924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "smoke-tfhk.com"] [uri "/marlboro-hongwan-vs-chunwan/"] [unique_id "amueYPSWp157EsYqB3onagAABDw"]
[Thu Jul 30 13:56:32.154049 2026] [security2:error] [pid 961194:tid 961328] [client 94.23.188.216:64924] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/marlboro-hongwan-vs-chunwan/"] [unique_id "amueYPSWp157EsYqB3onagAABDw"]
[Thu Jul 30 13:56:32.407507 2026] [security2:error] [pid 961194:tid 961231] [remote 103.39.93.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.93.39.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.spececigarette.com"] [uri "/wp-login.php"] [unique_id "amueYPSWp157EsYqB3onbwAAZCQ"]
[Thu Jul 30 13:56:32.980156 2026] [security2:error] [pid 961194:tid 961252] [remote 216.73.217.142:9649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amueYPSWp157EsYqB3onewAAITk"]
[Thu Jul 30 13:56:33.194765 2026] [security2:error] [pid 961194:tid 961417] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueYfSWp157EsYqB3onfgAAAF0"]
[Thu Jul 30 13:56:33.450579 2026] [security2:error] [pid 961194:tid 961368] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueYfSWp157EsYqB3oniQAAACw"]
[Thu Jul 30 13:56:33.600757 2026] [security2:error] [pid 961194:tid 961449] [client 176.29.79.216:25061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueYfSWp157EsYqB3onhgAAfX0"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Ffirstxnxx.com
[Thu Jul 30 13:56:33.711850 2026] [security2:error] [pid 961194:tid 961327] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueYfSWp157EsYqB3onkAAAAAM"]
[Thu Jul 30 13:56:33.960744 2026] [security2:error] [pid 961194:tid 961442] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueYfSWp157EsYqB3onmgAAAHY"]
[Thu Jul 30 13:56:34.012704 2026] [security2:error] [pid 961194:tid 961401] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amueYfSWp157EsYqB3onjQAATV8"]
[Thu Jul 30 13:56:34.215139 2026] [security2:error] [pid 961194:tid 961448] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueYvSWp157EsYqB3onoQAAAHw"]
[Thu Jul 30 13:56:34.484594 2026] [security2:error] [pid 961194:tid 961447] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueYvSWp157EsYqB3onrwAAAHs"]
[Thu Jul 30 13:56:34.524431 2026] [security2:error] [pid 961194:tid 961374] [client 188.163.44.131:44996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueYvSWp157EsYqB3onqQAAADI"], referer: http://pkf.jo
[Thu Jul 30 13:56:34.669758 2026] [fcgid:warn] [pid 961194:tid 961426] (70014)End of file found: [client 18.116.101.220:18440] mod_fcgid: can't get data from http client
[Thu Jul 30 13:56:34.745843 2026] [security2:error] [pid 961194:tid 961399] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueYvSWp157EsYqB3onuAAAAEs"]
[Thu Jul 30 13:56:34.759689 2026] [security2:error] [pid 961194:tid 961440] [client 172.237.109.114:6568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueYvSWp157EsYqB3onogAAAHQ"]
[Thu Jul 30 13:56:34.881076 2026] [security2:error] [pid 961194:tid 961345] [client 176.169.22.49:38382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueYvSWp157EsYqB3ontAAAABU"], referer: http://pkf.jo
[Thu Jul 30 13:56:34.994941 2026] [security2:error] [pid 961194:tid 961403] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueYvSWp157EsYqB3onxAAAAE8"]
[Thu Jul 30 13:56:35.242590 2026] [security2:error] [pid 961194:tid 961387] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueY_SWp157EsYqB3onywAAAD8"]
[Thu Jul 30 13:56:35.490792 2026] [security2:error] [pid 961194:tid 961407] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueYvSWp157EsYqB3onwQAAU2M"]
[Thu Jul 30 13:56:35.492490 2026] [security2:error] [pid 961194:tid 961439] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueY_SWp157EsYqB3on4QAAAHM"]
[Thu Jul 30 13:56:35.742128 2026] [security2:error] [pid 961194:tid 961417] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueY_SWp157EsYqB3on6wAAAF0"]
[Thu Jul 30 13:56:35.992959 2026] [security2:error] [pid 961194:tid 961428] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueY_SWp157EsYqB3on9AAAAGg"]
[Thu Jul 30 13:56:36.249656 2026] [security2:error] [pid 961194:tid 961383] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZPSWp157EsYqB3on-wAAADs"]
[Thu Jul 30 13:56:36.489074 2026] [security2:error] [pid 961194:tid 961373] [client 185.177.72.70:55104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZPSWp157EsYqB3ooAwAAMQA"]
[Thu Jul 30 13:56:36.739478 2026] [security2:error] [pid 961194:tid 961419] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZPSWp157EsYqB3ooCgAAAF8"]
[Thu Jul 30 13:56:36.984902 2026] [security2:error] [pid 961194:tid 961346] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZPSWp157EsYqB3ooFAAAABY"]
[Thu Jul 30 13:56:37.232578 2026] [security2:error] [pid 961194:tid 961436] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZfSWp157EsYqB3ooGgAAAHA"]
[Thu Jul 30 13:56:37.464448 2026] [security2:error] [pid 961194:tid 961443] [client 192.140.82.146:4225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueZfSWp157EsYqB3ooGwAAAHc"], referer: http://pkf.jo
[Thu Jul 30 13:56:37.467543 2026] [security2:error] [pid 961194:tid 961374] [client 103.242.199.184:61113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueZfSWp157EsYqB3ooJQAAADI"]
[Thu Jul 30 13:56:37.467640 2026] [security2:error] [pid 961194:tid 961374] [client 103.242.199.184:61113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueZfSWp157EsYqB3ooJQAAADI"]
[Thu Jul 30 13:56:37.482473 2026] [security2:error] [pid 961194:tid 961329] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZfSWp157EsYqB3ooIQAAAAU"]
[Thu Jul 30 13:56:37.731115 2026] [security2:error] [pid 961194:tid 961399] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZfSWp157EsYqB3ooKAAAAEs"]
[Thu Jul 30 13:56:37.842708 2026] [security2:error] [pid 961194:tid 961222] [remote 5.161.62.209:55268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/.env"] [unique_id "amueZfSWp157EsYqB3ooLgAARhs"]
[Thu Jul 30 13:56:37.861302 2026] [security2:error] [pid 961194:tid 961212] [remote 185.177.72.70:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/info.php"] [unique_id "amueZfSWp157EsYqB3ooMQAACxE"]
[Thu Jul 30 13:56:37.920913 2026] [core:notice] [pid 961194:tid 961352] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:37.989083 2026] [security2:error] [pid 961194:tid 961201] [remote 185.177.72.70:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/info.php%257e"] [unique_id "amueZfSWp157EsYqB3ooOQAATwY"]
[Thu Jul 30 13:56:38.116829 2026] [security2:error] [pid 961194:tid 961243] [remote 185.177.72.70:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/info.php%28%28"] [unique_id "amueZvSWp157EsYqB3ooPQAAIzA"]
[Thu Jul 30 13:56:38.164511 2026] [security2:error] [pid 961194:tid 961364] [client 170.106.72.93:38708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.72.106.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adbacklink.com"] [uri "/bbs/login_check.php"] [unique_id "amueZfSWp157EsYqB3ooMwAAACg"]
[Thu Jul 30 13:56:38.246437 2026] [security2:error] [pid 961194:tid 961311] [remote 185.177.72.70:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/info.php/"] [unique_id "amueZvSWp157EsYqB3ooPgAAIHQ"]
[Thu Jul 30 13:56:38.496782 2026] [security2:error] [pid 961194:tid 961332] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZvSWp157EsYqB3ooRAAAAAg"]
[Thu Jul 30 13:56:38.539965 2026] [security2:error] [pid 961194:tid 961334] [client 181.116.200.68:19299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueZvSWp157EsYqB3ooSQAAAAo"]
[Thu Jul 30 13:56:38.540098 2026] [security2:error] [pid 961194:tid 961334] [client 181.116.200.68:19299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueZvSWp157EsYqB3ooSQAAAAo"]
[Thu Jul 30 13:56:38.725048 2026] [security2:error] [pid 961194:tid 961418] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZvSWp157EsYqB3ooTAAAAF4"]
[Thu Jul 30 13:56:38.928100 2026] [security2:error] [pid 961194:tid 961379] [client 103.190.40.154:21869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueZvSWp157EsYqB3ooWQAAADc"]
[Thu Jul 30 13:56:38.928231 2026] [security2:error] [pid 961194:tid 961379] [client 103.190.40.154:21869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueZvSWp157EsYqB3ooWQAAADc"]
[Thu Jul 30 13:56:38.976759 2026] [security2:error] [pid 961194:tid 961391] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZvSWp157EsYqB3ooVQAAAEM"]
[Thu Jul 30 13:56:39.228962 2026] [security2:error] [pid 961194:tid 961362] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZ_SWp157EsYqB3ooYQAAACY"]
[Thu Jul 30 13:56:39.392491 2026] [security2:error] [pid 961194:tid 961425] [client 190.137.50.29:50965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueZ_SWp157EsYqB3ooXwAAAGU"], referer: http://pkf.jo
[Thu Jul 30 13:56:39.479141 2026] [security2:error] [pid 961194:tid 961347] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueZ_SWp157EsYqB3ooZwAAABc"]
[Thu Jul 30 13:56:39.804567 2026] [autoindex:error] [pid 961194:tid 961437] [client 3.254.69.125:39708] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:56:40.035075 2026] [fcgid:warn] [pid 961194:tid 961356] (70014)End of file found: [client 18.116.101.220:56694] mod_fcgid: can't get data from http client
[Thu Jul 30 13:56:40.275566 2026] [security2:error] [pid 961194:tid 961388] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueaPSWp157EsYqB3oohwAAAEA"]
[Thu Jul 30 13:56:40.526809 2026] [security2:error] [pid 961194:tid 961448] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueaPSWp157EsYqB3oojgAAAHw"]
[Thu Jul 30 13:56:40.754461 2026] [security2:error] [pid 961194:tid 961379] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueaPSWp157EsYqB3oomQAAADc"]
[Thu Jul 30 13:56:41.007179 2026] [security2:error] [pid 961194:tid 961346] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueaPSWp157EsYqB3oonwAAABY"]
[Thu Jul 30 13:56:41.252450 2026] [security2:error] [pid 961194:tid 961425] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueafSWp157EsYqB3ooqAAAAGU"]
[Thu Jul 30 13:56:42.047099 2026] [security2:error] [pid 961194:tid 961364] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueafSWp157EsYqB3oowQAAACg"]
[Thu Jul 30 13:56:42.299273 2026] [security2:error] [pid 961194:tid 961392] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueavSWp157EsYqB3ooywAAAEQ"]
[Thu Jul 30 13:56:42.549819 2026] [security2:error] [pid 961194:tid 961370] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueavSWp157EsYqB3oo0gAAAC4"]
[Thu Jul 30 13:56:42.647644 2026] [autoindex:error] [pid 961194:tid 961386] [client 3.254.69.125:39722] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:56:42.797368 2026] [security2:error] [pid 961194:tid 961385] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueavSWp157EsYqB3oo3AAAAD0"]
[Thu Jul 30 13:56:42.954803 2026] [security2:error] [pid 961194:tid 961270] [remote 74.7.243.224:37520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/login.php"] [unique_id "amueavSWp157EsYqB3oo4wAADUs"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/js/bootstrap.bundle.min.js
[Thu Jul 30 13:56:43.027805 2026] [security2:error] [pid 961194:tid 961412] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueavSWp157EsYqB3oo4gAAAFg"]
[Thu Jul 30 13:56:43.271008 2026] [core:notice] [pid 961194:tid 961423] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:43.548279 2026] [security2:error] [pid 961194:tid 961339] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuea_SWp157EsYqB3oo8gAAAA8"]
[Thu Jul 30 13:56:43.557970 2026] [core:notice] [pid 961194:tid 961335] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:43.779065 2026] [security2:error] [pid 961194:tid 961348] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuea_SWp157EsYqB3oo-gAAABg"]
[Thu Jul 30 13:56:44.259574 2026] [security2:error] [pid 961194:tid 961424] [client 20.104.18.253:5331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/ea3f.php"] [unique_id "amuebPSWp157EsYqB3opDAAAAGQ"]
[Thu Jul 30 13:56:44.308616 2026] [security2:error] [pid 961194:tid 961329] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuebPSWp157EsYqB3opCAAAAAU"]
[Thu Jul 30 13:56:44.513609 2026] [core:notice] [pid 961194:tid 961345] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:44.628491 2026] [fcgid:warn] [pid 961194:tid 961379] (70014)End of file found: [client 199.45.155.87:40932] mod_fcgid: can't get data from http client
[Thu Jul 30 13:56:44.663477 2026] [security2:error] [pid 961194:tid 961398] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuebPSWp157EsYqB3opFwAAAEo"]
[Thu Jul 30 13:56:44.746866 2026] [security2:error] [pid 961194:tid 961371] [client 94.154.43.184:27244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inmobiliariadia.com"] [uri "/.env"] [unique_id "amuebPSWp157EsYqB3opGwAAAC8"]
[Thu Jul 30 13:56:44.852253 2026] [core:notice] [pid 961194:tid 961286] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:44.856130 2026] [security2:error] [pid 961194:tid 961410] [client 38.154.118.42:38620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/1526"] [unique_id "amuebPSWp157EsYqB3opGAAAVls"]
[Thu Jul 30 13:56:44.885988 2026] [security2:error] [pid 961194:tid 961432] [client 20.104.18.253:5367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/eagle.php"] [unique_id "amuebPSWp157EsYqB3opJAAAAGw"]
[Thu Jul 30 13:56:44.892723 2026] [security2:error] [pid 961194:tid 961418] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuebPSWp157EsYqB3opIAAAAF4"]
[Thu Jul 30 13:56:45.121735 2026] [security2:error] [pid 961194:tid 961354] [client 66.249.66.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.portugalvisaapplicationcenterinislamabad.site"] [uri "/index.php"] [unique_id "amuea_SWp157EsYqB3opBAAAHlk"]
[Thu Jul 30 13:56:45.127303 2026] [autoindex:error] [pid 961194:tid 961389] [client 44.213.206.96:4648] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_72d2afbe/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:56:45.172465 2026] [autoindex:error] [pid 961194:tid 961426] [client 3.225.222.228:53531] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_eeee7ca1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:56:45.414076 2026] [security2:error] [pid 961194:tid 961390] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuebfSWp157EsYqB3opMwAAAEI"]
[Thu Jul 30 13:56:45.486078 2026] [security2:error] [pid 961194:tid 961362] [client 20.104.18.253:5372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/ed35f.php"] [unique_id "amuebfSWp157EsYqB3opPQAAACY"]
[Thu Jul 30 13:56:45.789092 2026] [security2:error] [pid 961194:tid 961404] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuebfSWp157EsYqB3opQwAAAFA"]
[Thu Jul 30 13:56:45.850592 2026] [security2:error] [pid 961194:tid 961294] [remote 72.167.132.114:41028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amuebfSWp157EsYqB3opRwAARmM"]
[Thu Jul 30 13:56:45.957132 2026] [security2:error] [pid 961194:tid 961411] [client 78.167.1.90:54288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuebfSWp157EsYqB3opUAAAAFc"]
[Thu Jul 30 13:56:45.957592 2026] [security2:error] [pid 961194:tid 961411] [client 78.167.1.90:54288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuebfSWp157EsYqB3opUAAAAFc"]
[Thu Jul 30 13:56:46.042278 2026] [security2:error] [pid 961194:tid 961338] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuebfSWp157EsYqB3opTgAAAA4"]
[Thu Jul 30 13:56:46.082282 2026] [security2:error] [pid 961194:tid 961424] [client 20.104.18.253:5361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/edit-comments.php"] [unique_id "amuebvSWp157EsYqB3opVwAAAGQ"]
[Thu Jul 30 13:56:46.239416 2026] [security2:error] [pid 961194:tid 961367] [client 151.80.133.238:59656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuebfSWp157EsYqB3opRQAAACs"]
[Thu Jul 30 13:56:46.432643 2026] [security2:error] [pid 961194:tid 961418] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuebvSWp157EsYqB3opXQAAAF4"]
[Thu Jul 30 13:56:46.502588 2026] [core:notice] [pid 961194:tid 961306] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:46.678134 2026] [security2:error] [pid 961194:tid 961355] [client 20.104.18.253:5337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/edit-form.php"] [unique_id "amuebvSWp157EsYqB3opcAAAAB8"]
[Thu Jul 30 13:56:46.683817 2026] [security2:error] [pid 961194:tid 961364] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuebvSWp157EsYqB3opbQAAACg"]
[Thu Jul 30 13:56:46.966677 2026] [security2:error] [pid 961194:tid 961212] [remote 57.141.0.37:20462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/485177242/feed/rss2/"] [unique_id "amuebvSWp157EsYqB3ophQAAUBE"]
[Thu Jul 30 13:56:47.068781 2026] [security2:error] [pid 961194:tid 961370] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuebvSWp157EsYqB3ophAAAAC4"]
[Thu Jul 30 13:56:47.273711 2026] [security2:error] [pid 961194:tid 961414] [client 20.104.18.253:5341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/edit-tags.php"] [unique_id "amueb_SWp157EsYqB3opkgAAAFo"]
[Thu Jul 30 13:56:47.316680 2026] [security2:error] [pid 961194:tid 961402] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueb_SWp157EsYqB3opkAAAAE4"]
[Thu Jul 30 13:56:47.408917 2026] [security2:error] [pid 961194:tid 961368] [client 89.84.120.152:40836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amueb_SWp157EsYqB3opjAAAACw"], referer: http://pkf.jo
[Thu Jul 30 13:56:47.580052 2026] [security2:error] [pid 961194:tid 961339] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueb_SWp157EsYqB3opogAAAA8"]
[Thu Jul 30 13:56:47.751569 2026] [http2:info] [pid 977210:tid 977210] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 13:56:47.753842 2026] [proxy:error] [pid 961194:tid 961386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:47.753928 2026] [proxy_http:error] [pid 961194:tid 961386] [client 52.4.19.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:47.754808 2026] [proxy:error] [pid 961194:tid 961386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:47.754879 2026] [proxy_http:error] [pid 961194:tid 961386] [client 52.4.19.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:47.842281 2026] [security2:error] [pid 961194:tid 961330] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueb_SWp157EsYqB3opsQAAAAY"]
[Thu Jul 30 13:56:47.869622 2026] [security2:error] [pid 961194:tid 961353] [client 20.104.18.253:5573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/edit-wolf.php"] [unique_id "amueb_SWp157EsYqB3optAAAAB0"]
[Thu Jul 30 13:56:47.927723 2026] [security2:error] [pid 961194:tid 961390] [client 141.94.94.121:51364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueb_SWp157EsYqB3oprgAAAEI"]
[Thu Jul 30 13:56:48.104421 2026] [security2:error] [pid 977210:tid 977347] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueb_W1Jl2-fgIeVvqFwgAAAIo"]
[Thu Jul 30 13:56:48.144772 2026] [security2:error] [pid 977210:tid 977349] [client 103.242.199.184:61658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuecPW1Jl2-fgIeVvqFxQAAAIw"]
[Thu Jul 30 13:56:48.144917 2026] [security2:error] [pid 977210:tid 977349] [client 103.242.199.184:61658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuecPW1Jl2-fgIeVvqFxQAAAIw"]
[Thu Jul 30 13:56:48.220851 2026] [proxy:error] [pid 977210:tid 977363] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:48.220950 2026] [proxy_http:error] [pid 977210:tid 977363] [client 52.4.19.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:48.221540 2026] [proxy:error] [pid 977210:tid 977363] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:56:48.221586 2026] [proxy_http:error] [pid 977210:tid 977363] [client 52.4.19.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:56:48.359760 2026] [security2:error] [pid 977210:tid 977365] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuecPW1Jl2-fgIeVvqFzgAAAJw"]
[Thu Jul 30 13:56:48.469354 2026] [security2:error] [pid 961194:tid 961339] [client 20.104.18.253:5572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/edit.php"] [unique_id "amuecPSWp157EsYqB3op5AAAAA8"]
[Thu Jul 30 13:56:48.617080 2026] [security2:error] [pid 977210:tid 977374] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuecPW1Jl2-fgIeVvqF0QAAAKU"]
[Thu Jul 30 13:56:48.760771 2026] [core:notice] [pid 977210:tid 977382] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:48.866855 2026] [security2:error] [pid 961194:tid 961342] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuecPSWp157EsYqB3oqEAAAABI"]
[Thu Jul 30 13:56:49.065625 2026] [security2:error] [pid 961194:tid 961385] [client 20.104.18.253:5375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/editor.php"] [unique_id "amuecfSWp157EsYqB3oqIAAAAD0"]
[Thu Jul 30 13:56:49.110751 2026] [security2:error] [pid 961194:tid 961354] [client 181.116.200.68:43443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuecfSWp157EsYqB3oqIwAAAB4"]
[Thu Jul 30 13:56:49.110853 2026] [security2:error] [pid 961194:tid 961354] [client 181.116.200.68:43443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuecfSWp157EsYqB3oqIwAAAB4"]
[Thu Jul 30 13:56:49.118723 2026] [security2:error] [pid 961194:tid 961445] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuecfSWp157EsYqB3oqHAAAAHk"]
[Thu Jul 30 13:56:49.147540 2026] [proxy_http:error] [pid 961194:tid 961448] (20014)Internal error (specific information not available): [client 171.22.217.93:30834] AH01102: error reading status line from remote server 127.0.0.1:2082
[Thu Jul 30 13:56:49.147559 2026] [proxy:error] [pid 961194:tid 961448] [client 171.22.217.93:30834] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/
[Thu Jul 30 13:56:49.202067 2026] [security2:error] [pid 961194:tid 961265] [remote 64.225.121.94:60872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuecfSWp157EsYqB3oqJgAADkY"]
[Thu Jul 30 13:56:49.370488 2026] [security2:error] [pid 977210:tid 977386] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuecfW1Jl2-fgIeVvqF1gAAALE"]
[Thu Jul 30 13:56:49.606078 2026] [security2:error] [pid 961194:tid 961346] [client 103.190.40.154:22075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuecfSWp157EsYqB3oqMQAAABY"]
[Thu Jul 30 13:56:49.606229 2026] [security2:error] [pid 961194:tid 961346] [client 103.190.40.154:22075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuecfSWp157EsYqB3oqMQAAABY"]
[Thu Jul 30 13:56:49.621987 2026] [security2:error] [pid 977210:tid 977391] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuecfW1Jl2-fgIeVvqF2QAAALY"]
[Thu Jul 30 13:56:49.661652 2026] [security2:error] [pid 961194:tid 961410] [client 20.104.18.253:5569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/editor/filemanager.php"] [unique_id "amuecfSWp157EsYqB3oqNAAAAFY"]
[Thu Jul 30 13:56:49.850133 2026] [security2:error] [pid 977210:tid 977399] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuecfW1Jl2-fgIeVvqF2wAAAL4"]
[Thu Jul 30 13:56:50.101900 2026] [security2:error] [pid 977210:tid 977402] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuecfW1Jl2-fgIeVvqF3QAAAME"]
[Thu Jul 30 13:56:50.257786 2026] [security2:error] [pid 961194:tid 961339] [client 20.104.18.253:5335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/editor/filemanager/updates.php"] [unique_id "amuecvSWp157EsYqB3oqRgAAAA8"]
[Thu Jul 30 13:56:50.350213 2026] [security2:error] [pid 961194:tid 961421] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuecvSWp157EsYqB3oqRAAAAGE"]
[Thu Jul 30 13:56:50.478107 2026] [security2:error] [pid 961194:tid 961256] [remote 185.177.72.70:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/phpinfo.php"] [unique_id "amuecvSWp157EsYqB3oqRwAAID0"]
[Thu Jul 30 13:56:50.603225 2026] [security2:error] [pid 961194:tid 961314] [remote 185.177.72.70:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/phpinfo.php%255f"] [unique_id "amuecvSWp157EsYqB3oqSgAAY3c"]
[Thu Jul 30 13:56:50.718408 2026] [security2:error] [pid 977210:tid 977417] [client 74.7.175.191:37384] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuecvW1Jl2-fgIeVvqF6wAA0A8"]
[Thu Jul 30 13:56:50.728439 2026] [security2:error] [pid 961194:tid 961296] [remote 185.177.72.70:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/phpinfo.php%253c"] [unique_id "amuecvSWp157EsYqB3oqUQAALWU"]
[Thu Jul 30 13:56:50.854284 2026] [security2:error] [pid 961194:tid 961271] [remote 185.177.72.70:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/phpinfo.php%255d"] [unique_id "amuecvSWp157EsYqB3oqUgAAMUw"]
[Thu Jul 30 13:56:50.854927 2026] [security2:error] [pid 977210:tid 977422] [client 20.104.18.253:5326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/ee.php"] [unique_id "amuecvW1Jl2-fgIeVvqF7gAAANU"]
[Thu Jul 30 13:56:51.476105 2026] [security2:error] [pid 977210:tid 977435] [client 20.104.18.253:5373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/ee8.php"] [unique_id "amuec_W1Jl2-fgIeVvqF8wAAAOI"]
[Thu Jul 30 13:56:52.075690 2026] [security2:error] [pid 977210:tid 977444] [client 20.104.18.253:5324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/eew.php"] [unique_id "amuedPW1Jl2-fgIeVvqF-AAAAOs"]
[Thu Jul 30 13:56:52.670195 2026] [security2:error] [pid 961194:tid 961350] [client 20.104.18.253:5370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/el.php"] [unique_id "amuedPSWp157EsYqB3oqjQAAABo"]
[Thu Jul 30 13:56:52.747650 2026] [security2:error] [pid 961194:tid 961364] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuedPSWp157EsYqB3oqiwAAACg"]
[Thu Jul 30 13:56:52.895697 2026] [security2:error] [pid 961194:tid 961330] [client 128.140.106.114:37716] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuedPSWp157EsYqB3oqlgAAAAY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:56:52.993291 2026] [security2:error] [pid 961194:tid 961371] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuedPSWp157EsYqB3oqlQAAAC8"]
[Thu Jul 30 13:56:53.244735 2026] [security2:error] [pid 961194:tid 961329] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuedfSWp157EsYqB3oqnAAAAAU"]
[Thu Jul 30 13:56:53.269419 2026] [security2:error] [pid 961194:tid 961353] [client 20.104.18.253:5577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/elementor/wp-error_log.php"] [unique_id "amuedfSWp157EsYqB3oqpAAAAB0"]
[Thu Jul 30 13:56:53.272525 2026] [core:notice] [pid 977210:tid 977464] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:56:53.277641 2026] [security2:error] [pid 977210:tid 977464] [client 128.140.106.114:37732] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuedfW1Jl2-fgIeVvqGAgAAAP8"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:56:53.494895 2026] [security2:error] [pid 961194:tid 961368] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuedfSWp157EsYqB3oqrQAAACw"]
[Thu Jul 30 13:56:53.670655 2026] [security2:error] [pid 977210:tid 977349] [client 128.140.106.114:37746] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuedfW1Jl2-fgIeVvqGCAAAAIw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 13:56:53.702446 2026] [security2:error] [pid 977210:tid 977436] [client 217.113.16.73:42034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuedfW1Jl2-fgIeVvqGBAAA4xE"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxhamsters.world
[Thu Jul 30 13:56:53.747612 2026] [security2:error] [pid 977210:tid 977357] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuedfW1Jl2-fgIeVvqGBwAAAJQ"]
[Thu Jul 30 13:56:53.875387 2026] [security2:error] [pid 961194:tid 961312] [remote 185.177.72.70:36772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/core%7e"] [unique_id "amuedfSWp157EsYqB3oqtQAABHU"]
[Thu Jul 30 13:56:54.126722 2026] [security2:error] [pid 977210:tid 977359] [client 20.104.18.253:5333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/elementor/wp-login.php"] [unique_id "amuedfW1Jl2-fgIeVvqGDQAAAJY"]
[Thu Jul 30 13:56:54.128106 2026] [security2:error] [pid 961194:tid 961421] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuedvSWp157EsYqB3oqvAAAAGE"]
[Thu Jul 30 13:56:54.376773 2026] [security2:error] [pid 977210:tid 977393] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuedvW1Jl2-fgIeVvqGEgAAALg"]
[Thu Jul 30 13:56:54.610194 2026] [security2:error] [pid 977210:tid 977234] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.dubaiappliance.repair"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuedvW1Jl2-fgIeVvqGFQAAvxU"]
[Thu Jul 30 13:56:54.646872 2026] [security2:error] [pid 977210:tid 977235] [remote 42.96.35.95:7730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.35.96.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amuedvW1Jl2-fgIeVvqGFgAAphY"]
[Thu Jul 30 13:56:54.722903 2026] [security2:error] [pid 961194:tid 961324] [client 20.104.18.253:5330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/elementor/wp-wjvngrh.php"] [unique_id "amuedvSWp157EsYqB3oqzQAAAAA"]
[Thu Jul 30 13:56:54.912360 2026] [security2:error] [pid 961194:tid 961402] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuedvSWp157EsYqB3oq0QAAAE4"]
[Thu Jul 30 13:56:55.160210 2026] [security2:error] [pid 977210:tid 977432] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amued_W1Jl2-fgIeVvqGIgAAAN8"]
[Thu Jul 30 13:56:55.317989 2026] [security2:error] [pid 977210:tid 977433] [client 20.104.18.253:5613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/elements/filemanager.php"] [unique_id "amued_W1Jl2-fgIeVvqGJgAAAOA"]
[Thu Jul 30 13:56:55.382273 2026] [security2:error] [pid 977210:tid 977440] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amued_W1Jl2-fgIeVvqGJAAAAOc"]
[Thu Jul 30 13:56:55.430440 2026] [security2:error] [pid 977210:tid 977457] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.dubaiappliance.repair"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amued_W1Jl2-fgIeVvqGKQAAAPg"]
[Thu Jul 30 13:56:55.720747 2026] [security2:error] [pid 977210:tid 977240] [remote 5.161.62.209:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mahyarjewelry.co"] [uri "/.env"] [unique_id "amued_W1Jl2-fgIeVvqGLgAA_hs"]
[Thu Jul 30 13:56:55.928474 2026] [security2:error] [pid 961194:tid 961340] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amued_SWp157EsYqB3oq5gAAABA"]
[Thu Jul 30 13:56:55.936661 2026] [security2:error] [pid 977210:tid 977468] [client 20.104.18.253:5580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/elements/udd.php"] [unique_id "amued_W1Jl2-fgIeVvqGMgAAAQM"]
[Thu Jul 30 13:56:56.097147 2026] [security2:error] [pid 961194:tid 961411] [client 189.6.88.213:58791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueePSWp157EsYqB3oq8QAAAFc"]
[Thu Jul 30 13:56:56.097235 2026] [security2:error] [pid 961194:tid 961411] [client 189.6.88.213:58791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueePSWp157EsYqB3oq8QAAAFc"]
[Thu Jul 30 13:56:56.154166 2026] [security2:error] [pid 961194:tid 961376] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueePSWp157EsYqB3oq8AAAADQ"]
[Thu Jul 30 13:56:56.283583 2026] [security2:error] [pid 961194:tid 961196] [remote 142.44.225.81:29554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fireworkskenya.com"] [uri "/robots.txt"] [unique_id "amueePSWp157EsYqB3oq8wAAXQE"]
[Thu Jul 30 13:56:56.283777 2026] [security2:error] [pid 961194:tid 961417] [client 142.44.225.81:29554] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fireworkskenya.com"] [uri "/robots.txt"] [unique_id "amueePSWp157EsYqB3oq8wAAXQE"]
[Thu Jul 30 13:56:56.404137 2026] [security2:error] [pid 961194:tid 961387] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueePSWp157EsYqB3oq9QAAAD8"]
[Thu Jul 30 13:56:56.530625 2026] [security2:error] [pid 961194:tid 961336] [client 20.104.18.253:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/elements/wp-2019.php"] [unique_id "amueePSWp157EsYqB3oq_gAAAAw"]
[Thu Jul 30 13:56:57.124715 2026] [security2:error] [pid 961194:tid 961383] [client 20.104.18.253:5349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/elp.php"] [unique_id "amueefSWp157EsYqB3orBQAAADs"]
[Thu Jul 30 13:56:57.721198 2026] [security2:error] [pid 961194:tid 961436] [client 20.104.18.253:5574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/email.php"] [unique_id "amueefSWp157EsYqB3orEwAAAHA"]
[Thu Jul 30 13:56:57.736928 2026] [security2:error] [pid 961194:tid 961322] [remote 198.244.240.22:57326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fireworkskenya.com"] [uri "/"] [unique_id "amueefSWp157EsYqB3orFAAAc38"]
[Thu Jul 30 13:56:57.737128 2026] [security2:error] [pid 961194:tid 961439] [client 198.244.240.22:57326] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fireworkskenya.com"] [uri "/"] [unique_id "amueefSWp157EsYqB3orFAAAc38"]
[Thu Jul 30 13:56:58.217675 2026] [security2:error] [pid 961194:tid 961397] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amueefSWp157EsYqB3orEQAAAEk"]
[Thu Jul 30 13:56:58.317698 2026] [security2:error] [pid 961194:tid 961389] [client 20.104.18.253:5328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/endpoints/atomlib.php"] [unique_id "amueevSWp157EsYqB3orHwAAAEE"]
[Thu Jul 30 13:56:58.765558 2026] [security2:error] [pid 977210:tid 977411] [client 103.242.199.184:62210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueevW1Jl2-fgIeVvqGRAAAAMo"]
[Thu Jul 30 13:56:58.765703 2026] [security2:error] [pid 977210:tid 977411] [client 103.242.199.184:62210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueevW1Jl2-fgIeVvqGRAAAAMo"]
[Thu Jul 30 13:56:58.915170 2026] [security2:error] [pid 977210:tid 977408] [client 20.104.18.253:5321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/endpoints/class-wp-rest-attachment-controller.php"] [unique_id "amueevW1Jl2-fgIeVvqGRQAAAMc"]
[Thu Jul 30 13:56:59.449484 2026] [security2:error] [pid 977210:tid 977428] [client 184.75.223.227:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuee_W1Jl2-fgIeVvqGRwAAANs"]
[Thu Jul 30 13:56:59.449596 2026] [security2:error] [pid 977210:tid 977428] [client 184.75.223.227:50706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuee_W1Jl2-fgIeVvqGRwAAANs"]
[Thu Jul 30 13:56:59.525838 2026] [security2:error] [pid 961194:tid 961438] [client 20.104.18.253:5362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/endpoints/index.php"] [unique_id "amuee_SWp157EsYqB3orLgAAAHI"]
[Thu Jul 30 13:56:59.739304 2026] [security2:error] [pid 977210:tid 977415] [client 181.116.200.68:30322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuee_W1Jl2-fgIeVvqGSgAAAM4"]
[Thu Jul 30 13:56:59.739442 2026] [security2:error] [pid 977210:tid 977415] [client 181.116.200.68:30322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuee_W1Jl2-fgIeVvqGSgAAAM4"]
[Thu Jul 30 13:57:00.121608 2026] [security2:error] [pid 977210:tid 977445] [client 20.104.18.253:5576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/env.php"] [unique_id "amuefPW1Jl2-fgIeVvqGTAAAAOw"]
[Thu Jul 30 13:57:00.253013 2026] [security2:error] [pid 977210:tid 977454] [client 103.190.40.154:20880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuefPW1Jl2-fgIeVvqGTwAAAPU"]
[Thu Jul 30 13:57:00.253159 2026] [security2:error] [pid 977210:tid 977454] [client 103.190.40.154:20880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuefPW1Jl2-fgIeVvqGTwAAAPU"]
[Thu Jul 30 13:57:00.715796 2026] [security2:error] [pid 961194:tid 961338] [client 20.104.18.253:5359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/envato-css.php"] [unique_id "amuefPSWp157EsYqB3orQwAAAA4"]
[Thu Jul 30 13:57:00.960486 2026] [proxy:error] [pid 977210:tid 977435] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:57:00.960555 2026] [proxy_http:error] [pid 977210:tid 977435] [client 167.71.25.206:33632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:57:00.961265 2026] [proxy:error] [pid 977210:tid 977435] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:57:00.961312 2026] [proxy_http:error] [pid 977210:tid 977435] [client 167.71.25.206:33632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:57:01.063259 2026] [security2:error] [pid 977210:tid 977347] [client 189.6.88.213:59330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueffW1Jl2-fgIeVvqGVwAAAIo"]
[Thu Jul 30 13:57:01.063391 2026] [security2:error] [pid 977210:tid 977347] [client 189.6.88.213:59330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueffW1Jl2-fgIeVvqGVwAAAIo"]
[Thu Jul 30 13:57:01.282067 2026] [security2:error] [pid 961194:tid 961274] [remote 17.246.19.19:53286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.19.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amueffSWp157EsYqB3orSAAAW08"], referer: https://lark-shop.com/product/terea/
[Thu Jul 30 13:57:01.313118 2026] [security2:error] [pid 977210:tid 977367] [client 20.104.18.253:5338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/envato-market/inc/class-envato-market-github.php"] [unique_id "amueffW1Jl2-fgIeVvqGWQAAAJ4"]
[Thu Jul 30 13:57:01.681297 2026] [security2:error] [pid 977210:tid 977378] [client 167.71.25.206:52812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cpcalendars.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amueffW1Jl2-fgIeVvqGXAAAAKk"]
[Thu Jul 30 13:57:01.771065 2026] [core:notice] [pid 977210:tid 977246] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:01.916803 2026] [security2:error] [pid 961194:tid 961441] [client 20.104.18.253:5606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/envs.php"] [unique_id "amueffSWp157EsYqB3orWgAAAHU"]
[Thu Jul 30 13:57:02.528594 2026] [security2:error] [pid 961194:tid 961437] [client 20.104.18.253:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/epinyins.php"] [unique_id "amuefvSWp157EsYqB3orYwAAAHE"]
[Thu Jul 30 13:57:02.894022 2026] [security2:error] [pid 961194:tid 961360] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amuefvSWp157EsYqB3orXwAAJHc"]
[Thu Jul 30 13:57:03.781935 2026] [security2:error] [pid 977210:tid 977443] [client 20.104.18.253:5570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/erinyani/asasx.php"] [unique_id "amuef_W1Jl2-fgIeVvqGbQAAAOo"]
[Thu Jul 30 13:57:03.813333 2026] [autoindex:error] [pid 977210:tid 977447] [client 44.213.206.96:32371] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_7475437c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:57:04.635254 2026] [security2:error] [pid 977210:tid 977464] [client 176.205.55.215:33986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuegPW1Jl2-fgIeVvqGdgAAAP8"], referer: http://pkf.jo
[Thu Jul 30 13:57:05.969375 2026] [core:notice] [pid 977210:tid 977384] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:06.118046 2026] [core:notice] [pid 961194:tid 961289] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:06.345436 2026] [security2:error] [pid 961194:tid 961412] [client 4.184.60.71:9412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuegvSWp157EsYqB3orlwAAAFg"]
[Thu Jul 30 13:57:06.345590 2026] [security2:error] [pid 961194:tid 961412] [client 4.184.60.71:9412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuegvSWp157EsYqB3orlwAAAFg"]
[Thu Jul 30 13:57:06.620250 2026] [security2:error] [pid 977210:tid 977420] [client 78.167.1.90:55987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.1.167.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuegvW1Jl2-fgIeVvqGlgAAANM"]
[Thu Jul 30 13:57:06.620380 2026] [security2:error] [pid 977210:tid 977420] [client 78.167.1.90:55987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuegvW1Jl2-fgIeVvqGlgAAANM"]
[Thu Jul 30 13:57:06.679334 2026] [security2:error] [pid 961194:tid 961349] [client 172.237.109.114:24534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuegvSWp157EsYqB3orlQAAABk"]
[Thu Jul 30 13:57:06.783127 2026] [security2:error] [pid 977210:tid 977429] [client 4.184.60.71:9416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuegvW1Jl2-fgIeVvqGmgAAANw"]
[Thu Jul 30 13:57:06.783244 2026] [security2:error] [pid 977210:tid 977429] [client 4.184.60.71:9416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuegvW1Jl2-fgIeVvqGmgAAANw"]
[Thu Jul 30 13:57:07.242018 2026] [security2:error] [pid 977210:tid 977443] [client 4.184.60.71:9417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/images/pearl/index.php"] [unique_id "amueg_W1Jl2-fgIeVvqGpQAAAOo"]
[Thu Jul 30 13:57:07.242124 2026] [security2:error] [pid 977210:tid 977443] [client 4.184.60.71:9417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/images/pearl/index.php"] [unique_id "amueg_W1Jl2-fgIeVvqGpQAAAOo"]
[Thu Jul 30 13:57:07.802441 2026] [security2:error] [pid 977210:tid 977452] [client 4.184.60.71:9461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/bypass.php"] [unique_id "amueg_W1Jl2-fgIeVvqGqwAAAPM"]
[Thu Jul 30 13:57:07.802598 2026] [security2:error] [pid 977210:tid 977452] [client 4.184.60.71:9461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/bypass.php"] [unique_id "amueg_W1Jl2-fgIeVvqGqwAAAPM"]
[Thu Jul 30 13:57:08.232290 2026] [security2:error] [pid 961194:tid 961379] [client 4.184.60.71:9454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/wp-admin/about.php"] [unique_id "amuehPSWp157EsYqB3orsQAAADc"]
[Thu Jul 30 13:57:08.232432 2026] [security2:error] [pid 961194:tid 961379] [client 4.184.60.71:9454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/wp-admin/about.php"] [unique_id "amuehPSWp157EsYqB3orsQAAADc"]
[Thu Jul 30 13:57:08.631521 2026] [security2:error] [pid 977210:tid 977349] [client 4.184.60.71:9437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/12.php"] [unique_id "amuehPW1Jl2-fgIeVvqGswAAAIw"]
[Thu Jul 30 13:57:08.631617 2026] [security2:error] [pid 977210:tid 977349] [client 4.184.60.71:9437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/12.php"] [unique_id "amuehPW1Jl2-fgIeVvqGswAAAIw"]
[Thu Jul 30 13:57:09.241335 2026] [security2:error] [pid 977210:tid 977353] [client 17.22.237.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marlboro-shop.com"] [uri "/index.php"] [unique_id "amuehPW1Jl2-fgIeVvqGuAAAAJA"]
[Thu Jul 30 13:57:09.256940 2026] [security2:error] [pid 977210:tid 977346] [client 4.184.60.71:9485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/nothing2.php"] [unique_id "amuehfW1Jl2-fgIeVvqGvQAAAIk"]
[Thu Jul 30 13:57:09.257106 2026] [security2:error] [pid 977210:tid 977346] [client 4.184.60.71:9485] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/nothing2.php"] [unique_id "amuehfW1Jl2-fgIeVvqGvQAAAIk"]
[Thu Jul 30 13:57:09.493230 2026] [security2:error] [pid 961194:tid 961429] [client 103.242.199.184:62758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuehfSWp157EsYqB3orwAAAAGk"]
[Thu Jul 30 13:57:09.493355 2026] [security2:error] [pid 961194:tid 961429] [client 103.242.199.184:62758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuehfSWp157EsYqB3orwAAAAGk"]
[Thu Jul 30 13:57:09.776019 2026] [security2:error] [pid 961194:tid 961403] [client 4.184.60.71:9465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/media.php"] [unique_id "amuehfSWp157EsYqB3oryAAAAE8"]
[Thu Jul 30 13:57:09.776127 2026] [security2:error] [pid 961194:tid 961403] [client 4.184.60.71:9465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/media.php"] [unique_id "amuehfSWp157EsYqB3oryAAAAE8"]
[Thu Jul 30 13:57:09.927001 2026] [security2:error] [pid 977210:tid 977384] [client 17.22.237.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marlboro-shop.com"] [uri "/index.php"] [unique_id "amuehfW1Jl2-fgIeVvqGxAAAAK8"]
[Thu Jul 30 13:57:10.305340 2026] [security2:error] [pid 961194:tid 961402] [client 4.184.60.71:9419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/file2.php"] [unique_id "amuehvSWp157EsYqB3or0wAAAE4"]
[Thu Jul 30 13:57:10.305454 2026] [security2:error] [pid 961194:tid 961402] [client 4.184.60.71:9419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/file2.php"] [unique_id "amuehvSWp157EsYqB3or0wAAAE4"]
[Thu Jul 30 13:57:10.316716 2026] [security2:error] [pid 977210:tid 977390] [client 103.231.91.59:41028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuehvW1Jl2-fgIeVvqGyAAAALU"]
[Thu Jul 30 13:57:10.316818 2026] [security2:error] [pid 977210:tid 977390] [client 103.231.91.59:41028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuehvW1Jl2-fgIeVvqGyAAAALU"]
[Thu Jul 30 13:57:10.326932 2026] [security2:error] [pid 977210:tid 977408] [client 181.116.200.68:2794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuehvW1Jl2-fgIeVvqGzgAAAMc"]
[Thu Jul 30 13:57:10.327028 2026] [security2:error] [pid 977210:tid 977408] [client 181.116.200.68:2794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuehvW1Jl2-fgIeVvqGzgAAAMc"]
[Thu Jul 30 13:57:10.750381 2026] [security2:error] [pid 961194:tid 961349] [client 4.184.60.71:9490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/simple.php"] [unique_id "amuehvSWp157EsYqB3or2gAAABk"]
[Thu Jul 30 13:57:10.750502 2026] [security2:error] [pid 961194:tid 961349] [client 4.184.60.71:9490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/simple.php"] [unique_id "amuehvSWp157EsYqB3or2gAAABk"]
[Thu Jul 30 13:57:11.030460 2026] [security2:error] [pid 977210:tid 977441] [client 4.184.60.71:9458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/mac.php"] [unique_id "amueh_W1Jl2-fgIeVvqG0wAAAOg"]
[Thu Jul 30 13:57:11.030584 2026] [security2:error] [pid 977210:tid 977441] [client 4.184.60.71:9458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/mac.php"] [unique_id "amueh_W1Jl2-fgIeVvqG0wAAAOg"]
[Thu Jul 30 13:57:11.277436 2026] [security2:error] [pid 961194:tid 961383] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuehvSWp157EsYqB3or1AAAOxY"]
[Thu Jul 30 13:57:11.358972 2026] [security2:error] [pid 977210:tid 977455] [client 4.184.60.71:9480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/install.php"] [unique_id "amueh_W1Jl2-fgIeVvqG1gAAAPY"]
[Thu Jul 30 13:57:11.359130 2026] [security2:error] [pid 977210:tid 977455] [client 4.184.60.71:9480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/install.php"] [unique_id "amueh_W1Jl2-fgIeVvqG1gAAAPY"]
[Thu Jul 30 13:57:11.684718 2026] [security2:error] [pid 961194:tid 961418] [client 4.184.60.71:9528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/wsx.php"] [unique_id "amueh_SWp157EsYqB3or5QAAAF4"]
[Thu Jul 30 13:57:11.684841 2026] [security2:error] [pid 961194:tid 961418] [client 4.184.60.71:9528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/wsx.php"] [unique_id "amueh_SWp157EsYqB3or5QAAAF4"]
[Thu Jul 30 13:57:11.819624 2026] [security2:error] [pid 961194:tid 961394] [client 189.6.88.213:59863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueh_SWp157EsYqB3or6AAAAEY"]
[Thu Jul 30 13:57:11.819749 2026] [security2:error] [pid 961194:tid 961394] [client 189.6.88.213:59863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueh_SWp157EsYqB3or6AAAAEY"]
[Thu Jul 30 13:57:12.018288 2026] [security2:error] [pid 977210:tid 977343] [client 4.184.60.71:9472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/alfa.php"] [unique_id "amueiPW1Jl2-fgIeVvqG3AAAAIY"]
[Thu Jul 30 13:57:12.018413 2026] [security2:error] [pid 977210:tid 977343] [client 4.184.60.71:9472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/alfa.php"] [unique_id "amueiPW1Jl2-fgIeVvqG3AAAAIY"]
[Thu Jul 30 13:57:12.313544 2026] [security2:error] [pid 977210:tid 977379] [client 4.184.60.71:9496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/dlu.php"] [unique_id "amueiPW1Jl2-fgIeVvqG7AAAAKo"]
[Thu Jul 30 13:57:12.313693 2026] [security2:error] [pid 977210:tid 977379] [client 4.184.60.71:9496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/dlu.php"] [unique_id "amueiPW1Jl2-fgIeVvqG7AAAAKo"]
[Thu Jul 30 13:57:12.473124 2026] [security2:error] [pid 961194:tid 961417] [client 172.237.109.114:20941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amueh_SWp157EsYqB3or7gAAAF0"]
[Thu Jul 30 13:57:12.770053 2026] [security2:error] [pid 977210:tid 977386] [client 4.184.60.71:9498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/f6.php"] [unique_id "amueiPW1Jl2-fgIeVvqG8AAAALE"]
[Thu Jul 30 13:57:12.770166 2026] [security2:error] [pid 977210:tid 977386] [client 4.184.60.71:9498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/f6.php"] [unique_id "amueiPW1Jl2-fgIeVvqG8AAAALE"]
[Thu Jul 30 13:57:13.081763 2026] [security2:error] [pid 977210:tid 977373] [client 4.184.60.71:9451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/0x.php"] [unique_id "amueifW1Jl2-fgIeVvqG8wAAAKQ"]
[Thu Jul 30 13:57:13.081859 2026] [security2:error] [pid 977210:tid 977373] [client 4.184.60.71:9451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/0x.php"] [unique_id "amueifW1Jl2-fgIeVvqG8wAAAKQ"]
[Thu Jul 30 13:57:13.334485 2026] [security2:error] [pid 977210:tid 977362] [client 103.190.40.154:21236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueifW1Jl2-fgIeVvqG9wAAAJk"]
[Thu Jul 30 13:57:13.334608 2026] [security2:error] [pid 977210:tid 977362] [client 103.190.40.154:21236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueifW1Jl2-fgIeVvqG9wAAAJk"]
[Thu Jul 30 13:57:13.386820 2026] [security2:error] [pid 977210:tid 977422] [client 4.184.60.71:9489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/geck.php"] [unique_id "amueifW1Jl2-fgIeVvqG-AAAANU"]
[Thu Jul 30 13:57:13.386932 2026] [security2:error] [pid 977210:tid 977422] [client 4.184.60.71:9489] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/geck.php"] [unique_id "amueifW1Jl2-fgIeVvqG-AAAANU"]
[Thu Jul 30 13:57:13.697548 2026] [security2:error] [pid 977210:tid 977429] [client 4.184.60.71:9473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/8.php"] [unique_id "amueifW1Jl2-fgIeVvqG-wAAANw"]
[Thu Jul 30 13:57:13.697649 2026] [security2:error] [pid 977210:tid 977429] [client 4.184.60.71:9473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/8.php"] [unique_id "amueifW1Jl2-fgIeVvqG-wAAANw"]
[Thu Jul 30 13:57:13.861003 2026] [core:notice] [pid 961194:tid 961346] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:14.014456 2026] [security2:error] [pid 977210:tid 977416] [client 4.184.60.71:9500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/133.php"] [unique_id "amueivW1Jl2-fgIeVvqHAAAAAM8"]
[Thu Jul 30 13:57:14.014582 2026] [security2:error] [pid 977210:tid 977416] [client 4.184.60.71:9500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/133.php"] [unique_id "amueivW1Jl2-fgIeVvqHAAAAAM8"]
[Thu Jul 30 13:57:14.620635 2026] [security2:error] [pid 961194:tid 961419] [client 4.184.60.71:9610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/11.php"] [unique_id "amueivSWp157EsYqB3osJAAAAF8"]
[Thu Jul 30 13:57:14.620747 2026] [security2:error] [pid 961194:tid 961419] [client 4.184.60.71:9610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/11.php"] [unique_id "amueivSWp157EsYqB3osJAAAAF8"]
[Thu Jul 30 13:57:14.906787 2026] [security2:error] [pid 977210:tid 977461] [client 4.184.60.71:9423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.shop-peace.com"] [uri "/3.php"] [unique_id "amueivW1Jl2-fgIeVvqHDQAAAPw"]
[Thu Jul 30 13:57:14.906892 2026] [security2:error] [pid 977210:tid 977461] [client 4.184.60.71:9423] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.shop-peace.com"] [uri "/3.php"] [unique_id "amueivW1Jl2-fgIeVvqHDQAAAPw"]
[Thu Jul 30 13:57:14.998778 2026] [security2:error] [pid 977210:tid 977456] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueivW1Jl2-fgIeVvqHDAAAAPc"]
[Thu Jul 30 13:57:15.309288 2026] [core:notice] [pid 977210:tid 977287] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:16.165873 2026] [core:notice] [pid 977210:tid 977353] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:16.284891 2026] [security2:error] [pid 977210:tid 977459] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuei_W1Jl2-fgIeVvqHFQAA-ks"]
[Thu Jul 30 13:57:17.898854 2026] [security2:error] [pid 961194:tid 961366] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.melatipkr.xyz"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuejfSWp157EsYqB3osTQAAACo"]
[Thu Jul 30 13:57:17.962033 2026] [security2:error] [pid 977210:tid 977397] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuejfW1Jl2-fgIeVvqHLAAAALw"]
[Thu Jul 30 13:57:18.226663 2026] [security2:error] [pid 977210:tid 977402] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuejvW1Jl2-fgIeVvqHLQAAAME"]
[Thu Jul 30 13:57:18.517337 2026] [security2:error] [pid 977210:tid 977438] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuejvW1Jl2-fgIeVvqHMAAAAOU"]
[Thu Jul 30 13:57:18.800444 2026] [security2:error] [pid 977210:tid 977450] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuejvW1Jl2-fgIeVvqHNQAAAPE"]
[Thu Jul 30 13:57:18.875687 2026] [security2:error] [pid 961194:tid 961400] [client 64.42.179.51:36220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuejvSWp157EsYqB3osZgAAAEw"]
[Thu Jul 30 13:57:18.875791 2026] [security2:error] [pid 961194:tid 961400] [client 64.42.179.51:36220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuejvSWp157EsYqB3osZgAAAEw"]
[Thu Jul 30 13:57:19.153217 2026] [security2:error] [pid 961194:tid 961370] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuej_SWp157EsYqB3osbAAAAC4"]
[Thu Jul 30 13:57:19.403667 2026] [security2:error] [pid 961194:tid 961426] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuej_SWp157EsYqB3osdQAAAGY"]
[Thu Jul 30 13:57:19.469385 2026] [security2:error] [pid 961194:tid 961389] [client 74.7.241.146:49370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.gka.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuej_SWp157EsYqB3osdgAAAEE"]
[Thu Jul 30 13:57:19.660710 2026] [security2:error] [pid 977210:tid 977455] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuej_W1Jl2-fgIeVvqHNwAAAPY"]
[Thu Jul 30 13:57:19.847998 2026] [security2:error] [pid 977210:tid 977458] [client 64.42.179.51:48600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuej_W1Jl2-fgIeVvqHOgAAAPk"]
[Thu Jul 30 13:57:19.848157 2026] [security2:error] [pid 977210:tid 977458] [client 64.42.179.51:48600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuej_W1Jl2-fgIeVvqHOgAAAPk"]
[Thu Jul 30 13:57:19.914516 2026] [security2:error] [pid 961194:tid 961447] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuej_SWp157EsYqB3oshAAAAHs"]
[Thu Jul 30 13:57:20.117465 2026] [security2:error] [pid 977210:tid 977467] [client 103.242.199.184:63307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuekPW1Jl2-fgIeVvqHRAAAAQI"]
[Thu Jul 30 13:57:20.117606 2026] [security2:error] [pid 977210:tid 977467] [client 103.242.199.184:63307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuekPW1Jl2-fgIeVvqHRAAAAQI"]
[Thu Jul 30 13:57:20.167603 2026] [security2:error] [pid 961194:tid 961440] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekPSWp157EsYqB3osiAAAAHQ"]
[Thu Jul 30 13:57:20.445900 2026] [security2:error] [pid 961194:tid 961390] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekPSWp157EsYqB3osjQAAAEI"]
[Thu Jul 30 13:57:20.694055 2026] [security2:error] [pid 977210:tid 977365] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekPW1Jl2-fgIeVvqHSwAAAJw"]
[Thu Jul 30 13:57:20.929484 2026] [security2:error] [pid 977210:tid 977358] [client 181.116.200.68:45814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuekPW1Jl2-fgIeVvqHTwAAAJU"]
[Thu Jul 30 13:57:20.929609 2026] [security2:error] [pid 977210:tid 977358] [client 181.116.200.68:45814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuekPW1Jl2-fgIeVvqHTwAAAJU"]
[Thu Jul 30 13:57:20.942410 2026] [security2:error] [pid 977210:tid 977379] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekPW1Jl2-fgIeVvqHTgAAAKo"]
[Thu Jul 30 13:57:21.169619 2026] [security2:error] [pid 961194:tid 961405] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekfSWp157EsYqB3osmQAAAFE"]
[Thu Jul 30 13:57:21.418890 2026] [security2:error] [pid 977210:tid 977393] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekfW1Jl2-fgIeVvqHWAAAALg"]
[Thu Jul 30 13:57:21.669694 2026] [security2:error] [pid 961194:tid 961374] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekfSWp157EsYqB3osogAAADI"]
[Thu Jul 30 13:57:21.922927 2026] [security2:error] [pid 977210:tid 977407] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekfW1Jl2-fgIeVvqHZwAAAMY"]
[Thu Jul 30 13:57:21.931604 2026] [security2:error] [pid 977210:tid 977409] [client 184.75.223.227:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuekfW1Jl2-fgIeVvqHaAAAAMg"]
[Thu Jul 30 13:57:21.931687 2026] [security2:error] [pid 977210:tid 977409] [client 184.75.223.227:59286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuekfW1Jl2-fgIeVvqHaAAAAMg"]
[Thu Jul 30 13:57:22.170044 2026] [security2:error] [pid 977210:tid 977392] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekvW1Jl2-fgIeVvqHaQAAALc"]
[Thu Jul 30 13:57:22.552642 2026] [security2:error] [pid 977210:tid 977397] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekvW1Jl2-fgIeVvqHbQAAALw"]
[Thu Jul 30 13:57:22.772994 2026] [core:notice] [pid 977210:tid 977408] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:22.806397 2026] [security2:error] [pid 961194:tid 961413] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekvSWp157EsYqB3osugAAAFk"]
[Thu Jul 30 13:57:23.058364 2026] [security2:error] [pid 961194:tid 961406] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuekvSWp157EsYqB3oswgAAAFI"]
[Thu Jul 30 13:57:23.287249 2026] [security2:error] [pid 977210:tid 977419] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuek_W1Jl2-fgIeVvqHdQAAANI"]
[Thu Jul 30 13:57:23.534163 2026] [security2:error] [pid 961194:tid 961333] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuek_SWp157EsYqB3oszgAAAAk"]
[Thu Jul 30 13:57:23.661833 2026] [security2:error] [pid 961194:tid 961217] [remote 185.177.72.70:28988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/test.php"] [unique_id "amuek_SWp157EsYqB3os0AAAYBY"]
[Thu Jul 30 13:57:23.789087 2026] [security2:error] [pid 961194:tid 961200] [remote 185.177.72.70:28988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/test.php..."] [unique_id "amuek_SWp157EsYqB3os0wAARwU"]
[Thu Jul 30 13:57:23.914553 2026] [core:notice] [pid 977210:tid 977452] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:23.916261 2026] [security2:error] [pid 961194:tid 961216] [remote 185.177.72.70:28988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/test.php%09%09"] [unique_id "amuek_SWp157EsYqB3os1wAAQhU"]
[Thu Jul 30 13:57:23.997905 2026] [security2:error] [pid 977210:tid 977469] [client 64.42.179.51:48622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuek_W1Jl2-fgIeVvqHgQAAAQQ"]
[Thu Jul 30 13:57:23.998024 2026] [security2:error] [pid 977210:tid 977469] [client 64.42.179.51:48622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuek_W1Jl2-fgIeVvqHgQAAAQQ"]
[Thu Jul 30 13:57:24.040021 2026] [security2:error] [pid 961194:tid 961338] [client 189.6.88.213:60403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuelPSWp157EsYqB3os2AAAAA4"]
[Thu Jul 30 13:57:24.040129 2026] [security2:error] [pid 961194:tid 961338] [client 189.6.88.213:60403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuelPSWp157EsYqB3os2AAAAA4"]
[Thu Jul 30 13:57:24.043308 2026] [security2:error] [pid 961194:tid 961212] [remote 185.177.72.70:28988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/test.php...."] [unique_id "amuelPSWp157EsYqB3os2QAAGBE"]
[Thu Jul 30 13:57:24.048777 2026] [security2:error] [pid 977210:tid 977351] [client 103.190.40.154:1681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuelPW1Jl2-fgIeVvqHggAAAI4"]
[Thu Jul 30 13:57:24.048919 2026] [security2:error] [pid 977210:tid 977351] [client 103.190.40.154:1681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuelPW1Jl2-fgIeVvqHggAAAI4"]
[Thu Jul 30 13:57:24.834915 2026] [security2:error] [pid 977210:tid 977432] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuelPW1Jl2-fgIeVvqHhgAAAN8"]
[Thu Jul 30 13:57:25.082523 2026] [security2:error] [pid 977210:tid 977372] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuelPW1Jl2-fgIeVvqHigAAAKM"]
[Thu Jul 30 13:57:25.333673 2026] [security2:error] [pid 961194:tid 961329] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuelfSWp157EsYqB3os9wAAAAU"]
[Thu Jul 30 13:57:25.589170 2026] [security2:error] [pid 977210:tid 977358] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuelfW1Jl2-fgIeVvqHjwAAAJU"]
[Thu Jul 30 13:57:25.845231 2026] [security2:error] [pid 977210:tid 977353] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuelfW1Jl2-fgIeVvqHkQAAAJA"]
[Thu Jul 30 13:57:26.096467 2026] [security2:error] [pid 961194:tid 961437] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuelfSWp157EsYqB3otCAAAAHE"]
[Thu Jul 30 13:57:26.349338 2026] [security2:error] [pid 961194:tid 961345] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuelvSWp157EsYqB3otDwAAABU"]
[Thu Jul 30 13:57:26.606866 2026] [security2:error] [pid 961194:tid 961415] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuelvSWp157EsYqB3otFgAAAFs"]
[Thu Jul 30 13:57:26.736834 2026] [security2:error] [pid 961194:tid 961237] [remote 185.177.72.70:28988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/localhost.sql"] [unique_id "amuelvSWp157EsYqB3otIAAADio"]
[Thu Jul 30 13:57:26.951159 2026] [security2:error] [pid 961194:tid 961363] [client 64.42.179.51:36222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuelvSWp157EsYqB3otKwAAACc"]
[Thu Jul 30 13:57:26.951277 2026] [security2:error] [pid 961194:tid 961363] [client 64.42.179.51:36222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuelvSWp157EsYqB3otKwAAACc"]
[Thu Jul 30 13:57:26.989794 2026] [security2:error] [pid 977210:tid 977393] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuelvW1Jl2-fgIeVvqHmAAAALg"]
[Thu Jul 30 13:57:27.239113 2026] [security2:error] [pid 977210:tid 977409] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuel_W1Jl2-fgIeVvqHnAAAAMg"]
[Thu Jul 30 13:57:27.491932 2026] [security2:error] [pid 977210:tid 977418] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuel_W1Jl2-fgIeVvqHnQAAANE"]
[Thu Jul 30 13:57:27.622562 2026] [security2:error] [pid 961194:tid 961313] [remote 185.177.72.70:28988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/db.sql"] [unique_id "amuel_SWp157EsYqB3otawAAbHY"]
[Thu Jul 30 13:57:27.875753 2026] [security2:error] [pid 977210:tid 977399] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuel_W1Jl2-fgIeVvqHogAAAL4"]
[Thu Jul 30 13:57:28.049603 2026] [autoindex:error] [pid 977210:tid 977416] [client 195.96.139.70:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:57:28.129492 2026] [security2:error] [pid 961194:tid 961351] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemPSWp157EsYqB3otdAAAABs"]
[Thu Jul 30 13:57:28.391388 2026] [security2:error] [pid 977210:tid 977443] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemPW1Jl2-fgIeVvqHrwAAAOo"]
[Thu Jul 30 13:57:28.646944 2026] [security2:error] [pid 961194:tid 961361] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemPSWp157EsYqB3otggAAACU"]
[Thu Jul 30 13:57:28.800228 2026] [security2:error] [pid 977210:tid 977466] [client 113.44.116.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuemPW1Jl2-fgIeVvqHtwAAAQE"], referer: http://cnpinyin.com/dict1?search=%e7%89%b9%e5%8a%9e
[Thu Jul 30 13:57:28.888100 2026] [security2:error] [pid 977210:tid 977345] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemPW1Jl2-fgIeVvqHvAAAAIg"]
[Thu Jul 30 13:57:29.056302 2026] [core:notice] [pid 977210:tid 977351] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:29.086963 2026] [security2:error] [pid 977210:tid 977319] [remote 217.181.84.29:57622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuemfW1Jl2-fgIeVvqHwAAAl2o"], referer: https://deltaedu.net/
[Thu Jul 30 13:57:29.147485 2026] [security2:error] [pid 977210:tid 977356] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemfW1Jl2-fgIeVvqHvQAAAJM"]
[Thu Jul 30 13:57:29.397895 2026] [security2:error] [pid 977210:tid 977370] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemfW1Jl2-fgIeVvqHxgAAAKE"]
[Thu Jul 30 13:57:29.645727 2026] [security2:error] [pid 977210:tid 977354] [client 66.249.73.96:49302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuemfW1Jl2-fgIeVvqHxQAAAJE"]
[Thu Jul 30 13:57:29.652502 2026] [security2:error] [pid 961194:tid 961384] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemfSWp157EsYqB3otlgAAADw"]
[Thu Jul 30 13:57:29.979047 2026] [core:notice] [pid 961194:tid 961374] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:30.166170 2026] [security2:error] [pid 977210:tid 977383] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemvW1Jl2-fgIeVvqHzgAAAK4"]
[Thu Jul 30 13:57:30.413315 2026] [security2:error] [pid 977210:tid 977377] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemvW1Jl2-fgIeVvqH0gAAAKg"]
[Thu Jul 30 13:57:30.527319 2026] [autoindex:error] [pid 977210:tid 977407] [client 54.87.222.253:8427] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_90eeb221/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:57:30.661553 2026] [security2:error] [pid 961194:tid 961441] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemvSWp157EsYqB3otswAAAHU"]
[Thu Jul 30 13:57:30.743127 2026] [security2:error] [pid 961194:tid 961352] [client 103.242.199.184:63859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuemvSWp157EsYqB3otugAAABw"]
[Thu Jul 30 13:57:30.743230 2026] [security2:error] [pid 961194:tid 961352] [client 103.242.199.184:63859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuemvSWp157EsYqB3otugAAABw"]
[Thu Jul 30 13:57:30.912070 2026] [security2:error] [pid 961194:tid 961340] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuemvSWp157EsYqB3otvwAAABA"]
[Thu Jul 30 13:57:31.141653 2026] [security2:error] [pid 977210:tid 977421] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuem_W1Jl2-fgIeVvqH1wAAANQ"]
[Thu Jul 30 13:57:31.182027 2026] [fcgid:warn] [pid 961194:tid 961379] (70014)End of file found: [client 18.116.101.220:34808] mod_fcgid: can't get data from http client
[Thu Jul 30 13:57:31.530576 2026] [security2:error] [pid 961194:tid 961380] [client 181.116.200.68:11455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuem_SWp157EsYqB3otywAAADg"]
[Thu Jul 30 13:57:31.530725 2026] [security2:error] [pid 961194:tid 961380] [client 181.116.200.68:11455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuem_SWp157EsYqB3otywAAADg"]
[Thu Jul 30 13:57:31.690865 2026] [security2:error] [pid 961194:tid 961373] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuem_SWp157EsYqB3otzQAAADE"]
[Thu Jul 30 13:57:31.946379 2026] [security2:error] [pid 977210:tid 977462] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuem_W1Jl2-fgIeVvqH4wAAAP0"]
[Thu Jul 30 13:57:32.201358 2026] [security2:error] [pid 977210:tid 977469] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuenPW1Jl2-fgIeVvqH5wAAAQQ"]
[Thu Jul 30 13:57:32.261810 2026] [core:notice] [pid 977210:tid 977345] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:32.456534 2026] [security2:error] [pid 977210:tid 977360] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuenPW1Jl2-fgIeVvqH7AAAAJc"]
[Thu Jul 30 13:57:32.712005 2026] [security2:error] [pid 961194:tid 961442] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuenPSWp157EsYqB3ot3gAAAHY"]
[Thu Jul 30 13:57:32.943673 2026] [security2:error] [pid 977210:tid 977370] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuenPW1Jl2-fgIeVvqH8QAAAKE"]
[Thu Jul 30 13:57:33.194710 2026] [security2:error] [pid 977210:tid 977382] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuenfW1Jl2-fgIeVvqH9AAAAK0"]
[Thu Jul 30 13:57:33.448782 2026] [security2:error] [pid 961194:tid 961371] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuenfSWp157EsYqB3ot7AAAAC8"]
[Thu Jul 30 13:57:33.583815 2026] [security2:error] [pid 977210:tid 977331] [remote 185.177.72.70:54064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/backup.sql"] [unique_id "amuenfW1Jl2-fgIeVvqH-wAAmXY"]
[Thu Jul 30 13:57:33.717245 2026] [security2:error] [pid 977210:tid 977332] [remote 185.177.72.70:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/backup.sql.php"] [unique_id "amuenfW1Jl2-fgIeVvqH_gAAyHc"]
[Thu Jul 30 13:57:33.973239 2026] [security2:error] [pid 961194:tid 961349] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuenfSWp157EsYqB3ot9QAAABk"]
[Thu Jul 30 13:57:34.072043 2026] [autoindex:error] [pid 977210:tid 977425] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:57:34.072918 2026] [security2:error] [pid 977210:tid 977425] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuenvW1Jl2-fgIeVvqIBgAAANg"]
[Thu Jul 30 13:57:34.073260 2026] [security2:error] [pid 961194:tid 961325] [client 82.102.18.180:39810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-content/uploads/"] [unique_id "amuenvSWp157EsYqB3ot-QAAAAE"]
[Thu Jul 30 13:57:34.227832 2026] [security2:error] [pid 977210:tid 977428] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuenvW1Jl2-fgIeVvqICQAAANs"]
[Thu Jul 30 13:57:34.268588 2026] [security2:error] [pid 977210:tid 977384] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuenfW1Jl2-fgIeVvqH_QAAAK8"]
[Thu Jul 30 13:57:34.273416 2026] [security2:error] [pid 961194:tid 961246] [remote 17.22.237.75:43592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuenvSWp157EsYqB3ot-AAAbDM"], referer: https://lark-shop.com/product/marlboro-7/
[Thu Jul 30 13:57:34.781726 2026] [core:notice] [pid 977210:tid 977345] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:34.823462 2026] [security2:error] [pid 977210:tid 977360] [client 103.190.40.154:21647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuenvW1Jl2-fgIeVvqIHAAAAJc"]
[Thu Jul 30 13:57:34.823605 2026] [security2:error] [pid 977210:tid 977360] [client 103.190.40.154:21647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuenvW1Jl2-fgIeVvqIHAAAAJc"]
[Thu Jul 30 13:57:34.929324 2026] [security2:error] [pid 977210:tid 977339] [remote 185.177.72.70:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuenvW1Jl2-fgIeVvqIHwAA8X4"]
[Thu Jul 30 13:57:35.062818 2026] [security2:error] [pid 977210:tid 977340] [remote 185.177.72.70:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php%255f"] [unique_id "amuen_W1Jl2-fgIeVvqIIQAAqn8"]
[Thu Jul 30 13:57:35.195928 2026] [security2:error] [pid 977210:tid 977214] [remote 185.177.72.70:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php%255d"] [unique_id "amuen_W1Jl2-fgIeVvqIIwAAlQE"]
[Thu Jul 30 13:57:35.329879 2026] [security2:error] [pid 977210:tid 977215] [remote 185.177.72.70:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php.aws"] [unique_id "amuen_W1Jl2-fgIeVvqIJgAAtAI"]
[Thu Jul 30 13:57:35.589254 2026] [security2:error] [pid 977210:tid 977468] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuen_W1Jl2-fgIeVvqIKgAAAQM"]
[Thu Jul 30 13:57:35.596221 2026] [security2:error] [pid 977210:tid 977213] [remote 57.141.0.17:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/610298834/feed/rss2/"] [unique_id "amuen_W1Jl2-fgIeVvqIIgAAngA"]
[Thu Jul 30 13:57:35.845355 2026] [security2:error] [pid 977210:tid 977393] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuen_W1Jl2-fgIeVvqILQAAALg"]
[Thu Jul 30 13:57:35.995340 2026] [security2:error] [pid 977210:tid 977411] [client 43.172.197.114:50570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/04/30/mr-wonderful-fete-des-meres-2016/"] [unique_id "amuen_W1Jl2-fgIeVvqILgAAAMo"]
[Thu Jul 30 13:57:36.086147 2026] [security2:error] [pid 977210:tid 977359] [client 189.6.88.213:60967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueoPW1Jl2-fgIeVvqINQAAAJY"]
[Thu Jul 30 13:57:36.086274 2026] [security2:error] [pid 977210:tid 977359] [client 189.6.88.213:60967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueoPW1Jl2-fgIeVvqINQAAAJY"]
[Thu Jul 30 13:57:36.097751 2026] [security2:error] [pid 977210:tid 977421] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuen_W1Jl2-fgIeVvqINAAAANQ"]
[Thu Jul 30 13:57:36.353749 2026] [security2:error] [pid 961194:tid 961445] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueoPSWp157EsYqB3ouFAAAAHk"]
[Thu Jul 30 13:57:36.403505 2026] [core:notice] [pid 977210:tid 977394] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:36.617045 2026] [core:notice] [pid 977210:tid 977458] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:36.622922 2026] [security2:error] [pid 977210:tid 977458] [client 43.173.176.120:36818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/04/30/mr-wonderful-fete-des-meres-2016/"] [unique_id "amueoPW1Jl2-fgIeVvqIPwAAAPk"], referer: https://carnetdeshopping.com/index.php/2016/04/30/mr-wonderful-fete-des-meres-2016/?replytocom=1607
[Thu Jul 30 13:57:37.021177 2026] [core:notice] [pid 977210:tid 977344] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:37.169213 2026] [security2:error] [pid 977210:tid 977347] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueofW1Jl2-fgIeVvqITgAAAIo"]
[Thu Jul 30 13:57:37.363267 2026] [security2:error] [pid 961194:tid 961396] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amueofSWp157EsYqB3ouIgAASDk"]
[Thu Jul 30 13:57:37.400624 2026] [security2:error] [pid 977210:tid 977371] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueofW1Jl2-fgIeVvqIVAAAAKI"]
[Thu Jul 30 13:57:37.655314 2026] [security2:error] [pid 977210:tid 977374] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueofW1Jl2-fgIeVvqIWwAAAKU"]
[Thu Jul 30 13:57:37.890227 2026] [security2:error] [pid 961194:tid 961403] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueofSWp157EsYqB3ouKQAAAE8"]
[Thu Jul 30 13:57:38.151957 2026] [security2:error] [pid 977210:tid 977388] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueovW1Jl2-fgIeVvqIYwAAALM"]
[Thu Jul 30 13:57:38.413123 2026] [security2:error] [pid 977210:tid 977422] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueovW1Jl2-fgIeVvqIZwAAANU"]
[Thu Jul 30 13:57:38.673045 2026] [security2:error] [pid 961194:tid 961424] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueovSWp157EsYqB3ouPwAAAGQ"]
[Thu Jul 30 13:57:38.931637 2026] [security2:error] [pid 961194:tid 961432] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueovSWp157EsYqB3ouQgAAAGw"]
[Thu Jul 30 13:57:39.196224 2026] [security2:error] [pid 961194:tid 961368] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueo_SWp157EsYqB3ouSQAAACw"]
[Thu Jul 30 13:57:39.451323 2026] [security2:error] [pid 977210:tid 977428] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueo_W1Jl2-fgIeVvqIdAAAANs"]
[Thu Jul 30 13:57:39.915393 2026] [security2:error] [pid 977210:tid 977351] [client 142.93.149.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bestdogproductguide.com"] [uri "/wp-json/batch/v1"] [unique_id "amueo_W1Jl2-fgIeVvqIgQAAAI4"]
[Thu Jul 30 13:57:40.439728 2026] [security2:error] [pid 961194:tid 961406] [client 142.93.149.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bestdogproductguide.com"] [uri "/"] [unique_id "amuepPSWp157EsYqB3ouXAAAAFI"]
[Thu Jul 30 13:57:40.597884 2026] [security2:error] [pid 977210:tid 977240] [remote 57.141.0.45:24578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuepPW1Jl2-fgIeVvqIkQAAnRs"]
[Thu Jul 30 13:57:41.179870 2026] [core:notice] [pid 977210:tid 977410] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:41.184352 2026] [security2:error] [pid 977210:tid 977410] [client 66.249.79.8:62460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JPA/article/view/4101"] [unique_id "amuepPW1Jl2-fgIeVvqImAAAAMk"]
[Thu Jul 30 13:57:41.423520 2026] [security2:error] [pid 961194:tid 961396] [client 103.242.199.184:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuepfSWp157EsYqB3ouagAAAEg"]
[Thu Jul 30 13:57:41.424089 2026] [security2:error] [pid 961194:tid 961396] [client 103.242.199.184:64406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuepfSWp157EsYqB3ouagAAAEg"]
[Thu Jul 30 13:57:41.451568 2026] [core:notice] [pid 961194:tid 961440] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:41.602128 2026] [fcgid:warn] [pid 977210:tid 977408] (70014)End of file found: [client 66.132.195.51:43222] mod_fcgid: can't get data from http client
[Thu Jul 30 13:57:42.113340 2026] [security2:error] [pid 977210:tid 977430] [client 181.116.200.68:49082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuepvW1Jl2-fgIeVvqIqQAAAN0"]
[Thu Jul 30 13:57:42.114042 2026] [security2:error] [pid 977210:tid 977430] [client 181.116.200.68:49082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuepvW1Jl2-fgIeVvqIqQAAAN0"]
[Thu Jul 30 13:57:42.405639 2026] [security2:error] [pid 977210:tid 977391] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuepvW1Jl2-fgIeVvqIsAAAALY"]
[Thu Jul 30 13:57:42.406698 2026] [security2:error] [pid 977210:tid 977362] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuepfW1Jl2-fgIeVvqInAAAmR4"]
[Thu Jul 30 13:57:42.666314 2026] [security2:error] [pid 961194:tid 961324] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuepvSWp157EsYqB3oudQAAAAA"]
[Thu Jul 30 13:57:43.060146 2026] [security2:error] [pid 961194:tid 961357] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuepvSWp157EsYqB3oufAAAACE"]
[Thu Jul 30 13:57:43.321536 2026] [security2:error] [pid 977210:tid 977360] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuep_W1Jl2-fgIeVvqIvQAAAJc"]
[Thu Jul 30 13:57:43.578365 2026] [security2:error] [pid 977210:tid 977358] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuep_W1Jl2-fgIeVvqIxAAAAJU"]
[Thu Jul 30 13:57:43.816226 2026] [security2:error] [pid 977210:tid 977252] [remote 74.7.243.224:33998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/login.php"] [unique_id "amuep_W1Jl2-fgIeVvqIywAAoCc"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/content/1762352356_2.jpg
[Thu Jul 30 13:57:43.834185 2026] [security2:error] [pid 977210:tid 977378] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuep_W1Jl2-fgIeVvqIyQAAAKk"]
[Thu Jul 30 13:57:44.065134 2026] [security2:error] [pid 977210:tid 977405] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuep_W1Jl2-fgIeVvqI1AAAAMQ"]
[Thu Jul 30 13:57:44.170438 2026] [security2:error] [pid 961194:tid 961325] [client 189.6.88.213:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueqPSWp157EsYqB3ouiwAAAAE"]
[Thu Jul 30 13:57:44.170554 2026] [security2:error] [pid 961194:tid 961325] [client 189.6.88.213:61503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueqPSWp157EsYqB3ouiwAAAAE"]
[Thu Jul 30 13:57:44.321952 2026] [security2:error] [pid 977210:tid 977386] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueqPW1Jl2-fgIeVvqI2wAAALE"]
[Thu Jul 30 13:57:44.576864 2026] [security2:error] [pid 977210:tid 977417] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueqPW1Jl2-fgIeVvqI4gAAANA"]
[Thu Jul 30 13:57:44.797709 2026] [security2:error] [pid 977210:tid 977353] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amueqPW1Jl2-fgIeVvqI2gAAAJA"]
[Thu Jul 30 13:57:44.830366 2026] [security2:error] [pid 977210:tid 977394] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueqPW1Jl2-fgIeVvqI7AAAALk"]
[Thu Jul 30 13:57:45.082749 2026] [security2:error] [pid 977210:tid 977426] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueqPW1Jl2-fgIeVvqI9AAAANk"]
[Thu Jul 30 13:57:45.107062 2026] [security2:error] [pid 977210:tid 977408] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amueqPW1Jl2-fgIeVvqI5QAAAMc"]
[Thu Jul 30 13:57:45.114920 2026] [security2:error] [pid 977210:tid 977420] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueqPW1Jl2-fgIeVvqI5gAA0zI"]
[Thu Jul 30 13:57:45.337447 2026] [security2:error] [pid 977210:tid 977467] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueqfW1Jl2-fgIeVvqI-QAAAQI"]
[Thu Jul 30 13:57:45.724357 2026] [security2:error] [pid 977210:tid 977399] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueqfW1Jl2-fgIeVvqI9QAAvjU"]
[Thu Jul 30 13:57:45.727029 2026] [security2:error] [pid 977210:tid 977269] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/settings.php.save"] [unique_id "amueqfW1Jl2-fgIeVvqI_gAApzg"]
[Thu Jul 30 13:57:45.856367 2026] [security2:error] [pid 977210:tid 977268] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/settings.php.save%5f%5f"] [unique_id "amueqfW1Jl2-fgIeVvqJAQAA4jc"]
[Thu Jul 30 13:57:45.888884 2026] [security2:error] [pid 977210:tid 977343] [client 128.1.195.165:42070] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "application/zip"] [severity "WARNING"] [hostname "serverkr.com"] [uri "/"] [unique_id "amueqfW1Jl2-fgIeVvqJAgAAAIY"]
[Thu Jul 30 13:57:45.985491 2026] [security2:error] [pid 977210:tid 977270] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/settings.php.save%29"] [unique_id "amueqfW1Jl2-fgIeVvqJBAAAqzk"]
[Thu Jul 30 13:57:46.122303 2026] [security2:error] [pid 977210:tid 977271] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/settings.php.save.aws"] [unique_id "amueqvW1Jl2-fgIeVvqJBQAA8To"]
[Thu Jul 30 13:57:46.348914 2026] [security2:error] [pid 961194:tid 961379] [client 103.190.40.154:11854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueqvSWp157EsYqB3ouogAAADc"]
[Thu Jul 30 13:57:46.349071 2026] [security2:error] [pid 961194:tid 961379] [client 103.190.40.154:11854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueqvSWp157EsYqB3ouogAAADc"]
[Thu Jul 30 13:57:46.376279 2026] [security2:error] [pid 961194:tid 961404] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueqvSWp157EsYqB3ounwAAAFA"]
[Thu Jul 30 13:57:46.628548 2026] [security2:error] [pid 977210:tid 977377] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueqvW1Jl2-fgIeVvqJDwAAAKg"]
[Thu Jul 30 13:57:46.821010 2026] [security2:error] [pid 977210:tid 977349] [client 184.75.223.227:51798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueqvW1Jl2-fgIeVvqJEwAAAIw"]
[Thu Jul 30 13:57:46.821106 2026] [security2:error] [pid 977210:tid 977349] [client 184.75.223.227:51798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueqvW1Jl2-fgIeVvqJEwAAAIw"]
[Thu Jul 30 13:57:46.880918 2026] [security2:error] [pid 977210:tid 977405] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueqvW1Jl2-fgIeVvqJEgAAAMQ"]
[Thu Jul 30 13:57:47.137044 2026] [security2:error] [pid 977210:tid 977382] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueq_W1Jl2-fgIeVvqJGQAAAK0"]
[Thu Jul 30 13:57:47.269283 2026] [security2:error] [pid 977210:tid 977276] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueq_W1Jl2-fgIeVvqJGgAAvD8"]
[Thu Jul 30 13:57:47.522106 2026] [security2:error] [pid 977210:tid 977421] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueq_W1Jl2-fgIeVvqJHgAAANQ"]
[Thu Jul 30 13:57:47.653298 2026] [security2:error] [pid 977210:tid 977279] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueq_W1Jl2-fgIeVvqJIgAA4EI"]
[Thu Jul 30 13:57:48.013530 2026] [security2:error] [pid 961194:tid 961415] [client 179.43.134.114:21582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tereasshop.com"] [uri "/wp-login.php"] [unique_id "amueq_SWp157EsYqB3outQAAAFs"]
[Thu Jul 30 13:57:48.027689 2026] [core:notice] [pid 977210:tid 977281] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:48.047550 2026] [security2:error] [pid 977210:tid 977449] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueq_W1Jl2-fgIeVvqJJwAAAPA"]
[Thu Jul 30 13:57:48.168213 2026] [autoindex:error] [pid 961194:tid 961396] [client 52.4.19.39:19057] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_90eeb221/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:57:48.300221 2026] [security2:error] [pid 977210:tid 977458] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuerPW1Jl2-fgIeVvqJLQAAAPk"]
[Thu Jul 30 13:57:48.557269 2026] [security2:error] [pid 961194:tid 961409] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuerPSWp157EsYqB3ouxAAAAFU"]
[Thu Jul 30 13:57:48.690843 2026] [core:notice] [pid 961194:tid 961214] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:48.809316 2026] [security2:error] [pid 977210:tid 977465] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuerPW1Jl2-fgIeVvqJMQAAAQA"]
[Thu Jul 30 13:57:49.069368 2026] [security2:error] [pid 961194:tid 961446] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuerPSWp157EsYqB3ou0gAAAHo"]
[Thu Jul 30 13:57:49.106178 2026] [security2:error] [pid 961194:tid 961342] [client 103.231.91.59:57834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuerfSWp157EsYqB3ou2gAAABI"]
[Thu Jul 30 13:57:49.106281 2026] [security2:error] [pid 961194:tid 961342] [client 103.231.91.59:57834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuerfSWp157EsYqB3ou2gAAABI"]
[Thu Jul 30 13:57:49.322390 2026] [security2:error] [pid 977210:tid 977347] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuerfW1Jl2-fgIeVvqJOQAAAIo"]
[Thu Jul 30 13:57:49.340204 2026] [core:notice] [pid 961194:tid 961370] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:49.505881 2026] [core:notice] [pid 977210:tid 977351] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:49.580337 2026] [security2:error] [pid 961194:tid 961397] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuerfSWp157EsYqB3ovCAAAAEk"]
[Thu Jul 30 13:57:49.776337 2026] [core:notice] [pid 977210:tid 977399] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:49.833857 2026] [security2:error] [pid 961194:tid 961341] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuerfSWp157EsYqB3ovDwAAABE"]
[Thu Jul 30 13:57:49.965081 2026] [security2:error] [pid 977210:tid 977289] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/database.sql"] [unique_id "amuerfW1Jl2-fgIeVvqJQwAAu0w"]
[Thu Jul 30 13:57:50.183736 2026] [core:notice] [pid 977210:tid 977378] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:50.220009 2026] [security2:error] [pid 977210:tid 977400] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuervW1Jl2-fgIeVvqJSAAAAL8"]
[Thu Jul 30 13:57:50.367459 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/kool-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:50.370432 2026] [core:notice] [pid 977210:tid 977427] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:50.396250 2026] [security2:error] [pid 977210:tid 977451] [client 50.6.43.217:50436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuerfW1Jl2-fgIeVvqJPAAAAPI"]
[Thu Jul 30 13:57:50.396272 2026] [security2:error] [pid 977210:tid 977451] [client 50.6.43.217:50436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuerfW1Jl2-fgIeVvqJPAAAAPI"]
[Thu Jul 30 13:57:50.481161 2026] [security2:error] [pid 977210:tid 977412] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuervW1Jl2-fgIeVvqJTAAAAMs"]
[Thu Jul 30 13:57:50.681927 2026] [core:notice] [pid 977210:tid 977418] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:50.741852 2026] [security2:error] [pid 977210:tid 977434] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuervW1Jl2-fgIeVvqJUwAAAOE"]
[Thu Jul 30 13:57:50.923190 2026] [core:notice] [pid 977210:tid 977413] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:50.997237 2026] [security2:error] [pid 977210:tid 977419] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuervW1Jl2-fgIeVvqJWQAAANI"]
[Thu Jul 30 13:57:51.083914 2026] [core:notice] [pid 977210:tid 977445] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:51.253863 2026] [security2:error] [pid 977210:tid 977454] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuer_W1Jl2-fgIeVvqJYgAAAPU"]
[Thu Jul 30 13:57:51.336031 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/LARK-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:51.366920 2026] [security2:error] [pid 977210:tid 977429] [client 50.6.43.217:50456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuervW1Jl2-fgIeVvqJTgAAANw"]
[Thu Jul 30 13:57:51.366946 2026] [security2:error] [pid 977210:tid 977429] [client 50.6.43.217:50456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuervW1Jl2-fgIeVvqJTgAAANw"]
[Thu Jul 30 13:57:51.471770 2026] [core:notice] [pid 977210:tid 977345] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:51.645571 2026] [security2:error] [pid 977210:tid 977447] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuer_W1Jl2-fgIeVvqJhAAAAO4"]
[Thu Jul 30 13:57:51.875854 2026] [core:notice] [pid 977210:tid 977342] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:51.900031 2026] [security2:error] [pid 977210:tid 977358] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuer_W1Jl2-fgIeVvqJigAAAJU"]
[Thu Jul 30 13:57:52.111879 2026] [security2:error] [pid 977210:tid 977396] [client 103.242.199.184:64959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuesPW1Jl2-fgIeVvqJjgAAALs"]
[Thu Jul 30 13:57:52.112044 2026] [security2:error] [pid 977210:tid 977396] [client 103.242.199.184:64959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuesPW1Jl2-fgIeVvqJjgAAALs"]
[Thu Jul 30 13:57:52.131068 2026] [security2:error] [pid 977210:tid 977369] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesPW1Jl2-fgIeVvqJjQAAAKA"]
[Thu Jul 30 13:57:52.177815 2026] [security2:error] [pid 977210:tid 977368] [client 74.7.241.189:54316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.01.serverkr.com"] [uri "/cgi-sys/404.html"] [unique_id "amuesPW1Jl2-fgIeVvqJkQAAn3M"]
[Thu Jul 30 13:57:52.271167 2026] [core:notice] [pid 977210:tid 977366] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:52.286934 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe7\x99\xbe\xe6\xa8\x82\xe9\x96\x80-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:52.311918 2026] [security2:error] [pid 977210:tid 977347] [client 50.6.43.217:46694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuer_W1Jl2-fgIeVvqJfwAAAIo"]
[Thu Jul 30 13:57:52.311951 2026] [security2:error] [pid 977210:tid 977347] [client 50.6.43.217:46694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuer_W1Jl2-fgIeVvqJfwAAAIo"]
[Thu Jul 30 13:57:52.393882 2026] [security2:error] [pid 961194:tid 961329] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesPSWp157EsYqB3ovqQAAAAU"]
[Thu Jul 30 13:57:52.655567 2026] [security2:error] [pid 977210:tid 977386] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesPW1Jl2-fgIeVvqJmQAAALE"]
[Thu Jul 30 13:57:52.673810 2026] [core:notice] [pid 977210:tid 977373] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:57:52.751091 2026] [security2:error] [pid 961194:tid 961401] [client 181.116.200.68:14515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuesPSWp157EsYqB3ovsAAAAE0"]
[Thu Jul 30 13:57:52.751203 2026] [security2:error] [pid 961194:tid 961401] [client 181.116.200.68:14515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuesPSWp157EsYqB3ovsAAAAE0"]
[Thu Jul 30 13:57:52.913041 2026] [security2:error] [pid 961194:tid 961448] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesPSWp157EsYqB3ovswAAAHw"]
[Thu Jul 30 13:57:52.975201 2026] [autoindex:error] [pid 961194:tid 961270] [remote 74.7.227.178:49788] AH01276: Cannot serve directory /home2/meggzjte/01.serverkr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:57:53.170963 2026] [security2:error] [pid 961194:tid 961426] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesfSWp157EsYqB3ovuAAAAGY"]
[Thu Jul 30 13:57:53.268284 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe7\xa2\xa7\xe7\xb5\xb2\xe5\xa4\xa2-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:53.288405 2026] [security2:error] [pid 961194:tid 961412] [client 50.6.43.217:46718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuesPSWp157EsYqB3ovqgAAAFg"]
[Thu Jul 30 13:57:53.288437 2026] [security2:error] [pid 961194:tid 961412] [client 50.6.43.217:46718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuesPSWp157EsYqB3ovqgAAAFg"]
[Thu Jul 30 13:57:53.425761 2026] [security2:error] [pid 961194:tid 961414] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesfSWp157EsYqB3ovwwAAAFo"]
[Thu Jul 30 13:57:53.684731 2026] [security2:error] [pid 977210:tid 977453] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesfW1Jl2-fgIeVvqJqgAAAPQ"]
[Thu Jul 30 13:57:53.774396 2026] [fcgid:warn] [pid 977210:tid 977437] (70014)End of file found: [client 18.116.101.220:16008] mod_fcgid: can't get data from http client
[Thu Jul 30 13:57:53.838157 2026] [security2:error] [pid 961194:tid 961387] [client 20.52.125.110:3102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/geju.php"] [unique_id "amuesfSWp157EsYqB3ovyAAAAD8"]
[Thu Jul 30 13:57:53.938522 2026] [security2:error] [pid 977210:tid 977425] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesfW1Jl2-fgIeVvqJtAAAANg"]
[Thu Jul 30 13:57:54.192050 2026] [security2:error] [pid 977210:tid 977469] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesvW1Jl2-fgIeVvqJuAAAAQQ"]
[Thu Jul 30 13:57:54.218265 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\xa5\xbd\xe5\xbd\xa9-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:54.238879 2026] [security2:error] [pid 977210:tid 977407] [client 50.6.43.217:46736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuesfW1Jl2-fgIeVvqJpAAAAMY"]
[Thu Jul 30 13:57:54.238920 2026] [security2:error] [pid 977210:tid 977407] [client 50.6.43.217:46736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuesfW1Jl2-fgIeVvqJpAAAAMY"]
[Thu Jul 30 13:57:54.453073 2026] [security2:error] [pid 977210:tid 977468] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesvW1Jl2-fgIeVvqJxQAAAQM"]
[Thu Jul 30 13:57:54.513185 2026] [security2:error] [pid 977210:tid 977402] [client 185.177.72.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "palison.co"] [uri "/index.php"] [unique_id "amuesfW1Jl2-fgIeVvqJnwAAAME"]
[Thu Jul 30 13:57:54.719434 2026] [security2:error] [pid 977210:tid 977427] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesvW1Jl2-fgIeVvqJywAAANo"]
[Thu Jul 30 13:57:54.965281 2026] [security2:error] [pid 977210:tid 977451] [client 20.52.125.110:3101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuesvW1Jl2-fgIeVvqJ0AAAAPI"]
[Thu Jul 30 13:57:54.974894 2026] [security2:error] [pid 961194:tid 961336] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuesvSWp157EsYqB3ov1AAAAAw"]
[Thu Jul 30 13:57:55.110435 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\x92\x8c\xe5\xb9\xb3-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:55.130819 2026] [security2:error] [pid 977210:tid 977342] [client 50.6.43.217:46758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuesvW1Jl2-fgIeVvqJvgAAAIU"]
[Thu Jul 30 13:57:55.130846 2026] [security2:error] [pid 977210:tid 977342] [client 50.6.43.217:46758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuesvW1Jl2-fgIeVvqJvgAAAIU"]
[Thu Jul 30 13:57:55.396714 2026] [autoindex:error] [pid 977210:tid 977353] [client 185.177.72.9:0] AH01276: Cannot serve directory /home1/zuknyxte/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:57:55.721354 2026] [security2:error] [pid 961194:tid 961330] [client 20.52.125.110:3075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp.php"] [unique_id "amues_SWp157EsYqB3ov3wAAAAY"]
[Thu Jul 30 13:57:55.777148 2026] [security2:error] [pid 961194:tid 961434] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amues_SWp157EsYqB3ov3QAAAG4"]
[Thu Jul 30 13:57:55.814064 2026] [security2:error] [pid 977210:tid 977391] [client 189.6.88.213:62037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amues_W1Jl2-fgIeVvqJ5gAAALY"]
[Thu Jul 30 13:57:55.824013 2026] [security2:error] [pid 977210:tid 977391] [client 189.6.88.213:62037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amues_W1Jl2-fgIeVvqJ5gAAALY"]
[Thu Jul 30 13:57:55.907088 2026] [security2:error] [pid 961194:tid 961366] [client 185.177.72.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "palison.co"] [uri "/index.php"] [unique_id "amues_SWp157EsYqB3ov3gAAACo"]
[Thu Jul 30 13:57:55.988230 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe9\xbb\x91\xe9\xad\x94\xe9\xac\xbc-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:56.008346 2026] [security2:error] [pid 977210:tid 977414] [client 50.6.43.217:46800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amues_W1Jl2-fgIeVvqJ0wAAAM0"]
[Thu Jul 30 13:57:56.008374 2026] [security2:error] [pid 977210:tid 977414] [client 50.6.43.217:46800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amues_W1Jl2-fgIeVvqJ0wAAAM0"]
[Thu Jul 30 13:57:56.031517 2026] [security2:error] [pid 977210:tid 977371] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amues_W1Jl2-fgIeVvqJ7QAAAKI"]
[Thu Jul 30 13:57:56.217091 2026] [security2:error] [pid 961194:tid 961272] [remote 40.77.167.132:21139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/locations-programs/article.php"] [unique_id "amuetPSWp157EsYqB3ov6QAAH00"]
[Thu Jul 30 13:57:56.291373 2026] [security2:error] [pid 961194:tid 961371] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuetPSWp157EsYqB3ov6AAAAC8"]
[Thu Jul 30 13:57:56.553716 2026] [security2:error] [pid 961194:tid 961391] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuetPSWp157EsYqB3ov8AAAAEM"]
[Thu Jul 30 13:57:56.559220 2026] [security2:error] [pid 961194:tid 961449] [client 20.52.125.110:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/aaa.php"] [unique_id "amuetPSWp157EsYqB3ov9AAAAH0"]
[Thu Jul 30 13:57:56.559876 2026] [security2:error] [pid 977210:tid 977350] [client 185.177.72.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "palison.co"] [uri "/index.php"] [unique_id "amuetPW1Jl2-fgIeVvqJ7wAAAI0"]
[Thu Jul 30 13:57:56.806388 2026] [security2:error] [pid 977210:tid 977369] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuetPW1Jl2-fgIeVvqJ9AAAAKA"]
[Thu Jul 30 13:57:56.904702 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe9\xa7\xb1\xe9\xa7\x9d-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:56.923906 2026] [security2:error] [pid 961194:tid 961403] [client 50.6.43.217:46826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amues_SWp157EsYqB3ov5AAAAE8"]
[Thu Jul 30 13:57:56.923935 2026] [security2:error] [pid 961194:tid 961403] [client 50.6.43.217:46826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amues_SWp157EsYqB3ov5AAAAE8"]
[Thu Jul 30 13:57:57.069300 2026] [security2:error] [pid 977210:tid 977348] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuetPW1Jl2-fgIeVvqJ-gAAAIs"]
[Thu Jul 30 13:57:57.326417 2026] [security2:error] [pid 977210:tid 977343] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuetfW1Jl2-fgIeVvqKAAAAAIY"]
[Thu Jul 30 13:57:57.578477 2026] [security2:error] [pid 961194:tid 961345] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuetfSWp157EsYqB3owAAAAABU"]
[Thu Jul 30 13:57:57.596754 2026] [security2:error] [pid 961194:tid 961368] [client 20.52.125.110:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/hoot.php"] [unique_id "amuetfSWp157EsYqB3owAwAAACw"]
[Thu Jul 30 13:57:57.839473 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\x81\xa5\xe7\x89\x8c-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:57.859075 2026] [security2:error] [pid 961194:tid 961419] [client 50.6.43.217:46854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuetPSWp157EsYqB3ov-AAAAF8"]
[Thu Jul 30 13:57:57.859105 2026] [security2:error] [pid 961194:tid 961419] [client 50.6.43.217:46854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuetPSWp157EsYqB3ov-AAAAF8"]
[Thu Jul 30 13:57:58.270512 2026] [security2:error] [pid 977210:tid 977420] [client 103.190.40.154:2573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuetvW1Jl2-fgIeVvqKFgAAANM"]
[Thu Jul 30 13:57:58.270637 2026] [security2:error] [pid 977210:tid 977420] [client 103.190.40.154:2573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuetvW1Jl2-fgIeVvqKFgAAANM"]
[Thu Jul 30 13:57:58.720335 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe7\xbe\x8e\xe5\x9c\x8b\xe7\xb2\xbe\xe7\xa5\x9e-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:58.740606 2026] [security2:error] [pid 977210:tid 977394] [client 50.6.43.217:46896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuetfW1Jl2-fgIeVvqKCwAAALk"]
[Thu Jul 30 13:57:58.740630 2026] [security2:error] [pid 977210:tid 977394] [client 50.6.43.217:46896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuetfW1Jl2-fgIeVvqKCwAAALk"]
[Thu Jul 30 13:57:58.796715 2026] [security2:error] [pid 977210:tid 977387] [client 20.52.125.110:3086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/about.php"] [unique_id "amuetvW1Jl2-fgIeVvqKJgAAALI"]
[Thu Jul 30 13:57:58.930452 2026] [security2:error] [pid 977210:tid 977374] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuetvW1Jl2-fgIeVvqKKQAAAKU"]
[Thu Jul 30 13:57:59.166062 2026] [security2:error] [pid 961194:tid 961340] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuet_SWp157EsYqB3owGgAAABA"]
[Thu Jul 30 13:57:59.325752 2026] [security2:error] [pid 977210:tid 977383] [client 20.52.125.110:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/admin.php"] [unique_id "amuet_W1Jl2-fgIeVvqKMQAAAK4"]
[Thu Jul 30 13:57:59.418303 2026] [security2:error] [pid 977210:tid 977368] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuet_W1Jl2-fgIeVvqKMAAAAJ8"]
[Thu Jul 30 13:57:59.645889 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe4\xb8\x83\xe6\x98\x9f-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:57:59.666693 2026] [security2:error] [pid 977210:tid 977462] [client 50.6.43.217:46924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuetvW1Jl2-fgIeVvqKJAAAAP0"]
[Thu Jul 30 13:57:59.666723 2026] [security2:error] [pid 977210:tid 977462] [client 50.6.43.217:46924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuetvW1Jl2-fgIeVvqKJAAAAP0"]
[Thu Jul 30 13:57:59.672555 2026] [security2:error] [pid 961194:tid 961385] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuet_SWp157EsYqB3owJAAAAD0"]
[Thu Jul 30 13:57:59.906354 2026] [security2:error] [pid 961194:tid 961369] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuet_SWp157EsYqB3owJwAAAC0"]
[Thu Jul 30 13:58:00.112504 2026] [security2:error] [pid 977210:tid 977342] [client 66.249.68.163:49526] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.k2k.tech"] [uri "/robots.txt"] [unique_id "amueuPW1Jl2-fgIeVvqKQgAAAIU"]
[Thu Jul 30 13:58:00.173870 2026] [security2:error] [pid 977210:tid 977367] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueuPW1Jl2-fgIeVvqKQQAAAJ4"]
[Thu Jul 30 13:58:00.305243 2026] [security2:error] [pid 977210:tid 977247] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueuPW1Jl2-fgIeVvqKQwAA9iI"]
[Thu Jul 30 13:58:00.435306 2026] [security2:error] [pid 977210:tid 977248] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env%5e"] [unique_id "amueuPW1Jl2-fgIeVvqKRQAA5CM"]
[Thu Jul 30 13:58:00.444463 2026] [security2:error] [pid 977210:tid 977381] [client 20.52.125.110:3135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amueuPW1Jl2-fgIeVvqKRgAAAKw"]
[Thu Jul 30 13:58:00.537860 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe8\x90\xac\xe5\xaf\xb6\xe8\xb7\xaf-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:58:00.560848 2026] [security2:error] [pid 961194:tid 961430] [client 50.6.43.217:46950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuet_SWp157EsYqB3owJgAAAGo"]
[Thu Jul 30 13:58:00.560879 2026] [security2:error] [pid 961194:tid 961430] [client 50.6.43.217:46950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuet_SWp157EsYqB3owJgAAAGo"]
[Thu Jul 30 13:58:00.696800 2026] [security2:error] [pid 961194:tid 961342] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueuPSWp157EsYqB3owNgAAABI"]
[Thu Jul 30 13:58:00.935477 2026] [security2:error] [pid 977210:tid 977456] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueuPW1Jl2-fgIeVvqKTAAAAPc"]
[Thu Jul 30 13:58:01.065296 2026] [security2:error] [pid 977210:tid 977251] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env"] [unique_id "amueufW1Jl2-fgIeVvqKTQAAiCY"]
[Thu Jul 30 13:58:01.200255 2026] [security2:error] [pid 961194:tid 961437] [client 20.52.125.110:3078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/db-cache.php"] [unique_id "amueufSWp157EsYqB3owSQAAAHE"]
[Thu Jul 30 13:58:01.255057 2026] [security2:error] [pid 977210:tid 977259] [remote 45.146.192.214:32121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.192.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amueufW1Jl2-fgIeVvqKUwAA-C4"]
[Thu Jul 30 13:58:01.328696 2026] [security2:error] [pid 977210:tid 977469] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueufW1Jl2-fgIeVvqKUgAAAQQ"]
[Thu Jul 30 13:58:01.488648 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe8\x90\xac\xe4\xba\x8b\xe7\x99\xbc-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:58:01.510339 2026] [security2:error] [pid 961194:tid 961327] [client 50.6.43.217:46980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amueuPSWp157EsYqB3owNAAAAAM"]
[Thu Jul 30 13:58:01.510368 2026] [security2:error] [pid 961194:tid 961327] [client 50.6.43.217:46980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amueuPSWp157EsYqB3owNAAAAAM"]
[Thu Jul 30 13:58:01.600103 2026] [security2:error] [pid 977210:tid 977365] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueufW1Jl2-fgIeVvqKVwAAAJw"]
[Thu Jul 30 13:58:01.869079 2026] [security2:error] [pid 977210:tid 977348] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueufW1Jl2-fgIeVvqKYQAAAIs"]
[Thu Jul 30 13:58:02.079591 2026] [security2:error] [pid 977210:tid 977376] [client 20.52.125.110:3105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amueuvW1Jl2-fgIeVvqKawAAAKc"]
[Thu Jul 30 13:58:02.130036 2026] [security2:error] [pid 977210:tid 977397] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueuvW1Jl2-fgIeVvqKZAAAALw"]
[Thu Jul 30 13:58:02.180692 2026] [security2:error] [pid 977210:tid 977382] [client 128.2.204.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amueuvW1Jl2-fgIeVvqKaQAAAK0"]
[Thu Jul 30 13:58:02.377653 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\xb8\x8c\xe6\x9c\x9b-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:58:02.387098 2026] [security2:error] [pid 977210:tid 977423] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueuvW1Jl2-fgIeVvqKcwAAANY"]
[Thu Jul 30 13:58:02.398786 2026] [security2:error] [pid 977210:tid 977408] [client 50.6.43.217:40708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amueufW1Jl2-fgIeVvqKWAAAAMc"]
[Thu Jul 30 13:58:02.398816 2026] [security2:error] [pid 977210:tid 977408] [client 50.6.43.217:40708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amueufW1Jl2-fgIeVvqKWAAAAMc"]
[Thu Jul 30 13:58:02.455232 2026] [security2:error] [pid 977210:tid 977464] [client 43.153.35.128:40824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.35.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stunningtouchcleaning.com"] [uri "/xmlrpc.php"] [unique_id "amueuvW1Jl2-fgIeVvqKbgAAAP8"]
[Thu Jul 30 13:58:02.651513 2026] [security2:error] [pid 961194:tid 961445] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueuvSWp157EsYqB3owVwAAAHk"]
[Thu Jul 30 13:58:02.784645 2026] [security2:error] [pid 961194:tid 961339] [client 103.242.199.184:65509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueuvSWp157EsYqB3owYQAAAA8"]
[Thu Jul 30 13:58:02.784782 2026] [security2:error] [pid 961194:tid 961339] [client 103.242.199.184:65509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amueuvSWp157EsYqB3owYQAAAA8"]
[Thu Jul 30 13:58:02.919725 2026] [security2:error] [pid 977210:tid 977463] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueuvW1Jl2-fgIeVvqKegAAAP4"]
[Thu Jul 30 13:58:03.175375 2026] [security2:error] [pid 961194:tid 961354] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueu_SWp157EsYqB3owZgAAAB4"]
[Thu Jul 30 13:58:03.259929 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe5\x96\x9c\xe5\x8a\x9b-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:58:03.280475 2026] [security2:error] [pid 977210:tid 977465] [client 50.6.43.217:40756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amueuvW1Jl2-fgIeVvqKdAAAAQA"]
[Thu Jul 30 13:58:03.280503 2026] [security2:error] [pid 977210:tid 977465] [client 50.6.43.217:40756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amueuvW1Jl2-fgIeVvqKdAAAAQA"]
[Thu Jul 30 13:58:03.328383 2026] [security2:error] [pid 977210:tid 977429] [client 181.116.200.68:14028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueu_W1Jl2-fgIeVvqKggAAANw"]
[Thu Jul 30 13:58:03.328514 2026] [security2:error] [pid 977210:tid 977429] [client 181.116.200.68:14028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amueu_W1Jl2-fgIeVvqKggAAANw"]
[Thu Jul 30 13:58:03.430887 2026] [security2:error] [pid 961194:tid 961409] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueu_SWp157EsYqB3owcwAAAFU"]
[Thu Jul 30 13:58:03.561908 2026] [security2:error] [pid 977210:tid 977263] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/_profiler%00"] [unique_id "amueu_W1Jl2-fgIeVvqKgwAApTI"]
[Thu Jul 30 13:58:03.717847 2026] [security2:error] [pid 977210:tid 977435] [client 20.91.199.21:52821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/011i.php"] [unique_id "amueu_W1Jl2-fgIeVvqKiwAAAOI"]
[Thu Jul 30 13:58:03.794040 2026] [security2:error] [pid 977210:tid 977396] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueu_W1Jl2-fgIeVvqKigAAALs"]
[Thu Jul 30 13:58:03.909787 2026] [security2:error] [pid 977210:tid 977386] [client 184.75.223.227:46996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amueu_W1Jl2-fgIeVvqKjgAAALE"]
[Thu Jul 30 13:58:03.909875 2026] [security2:error] [pid 977210:tid 977386] [client 184.75.223.227:46996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amueu_W1Jl2-fgIeVvqKjgAAALE"]
[Thu Jul 30 13:58:03.943714 2026] [core:notice] [pid 977210:tid 977379] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:58:04.046986 2026] [security2:error] [pid 977210:tid 977349] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueu_W1Jl2-fgIeVvqKkQAAAIw"]
[Thu Jul 30 13:58:04.076450 2026] [core:error] [pid 977210:tid 977389] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:58:04.076470 2026] [core:error] [pid 977210:tid 977389] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:58:04.154114 2026] [security2:error] [pid 961194:tid 961328] [client 20.52.125.110:3127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuevPSWp157EsYqB3owegAAAAQ"]
[Thu Jul 30 13:58:04.155231 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe9\x9b\xb2\xe6\x96\xaf\xe9\xa0\x93-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:58:04.175844 2026] [security2:error] [pid 961194:tid 961324] [client 50.6.43.217:40776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amueu_SWp157EsYqB3owcQAAAAA"]
[Thu Jul 30 13:58:04.175881 2026] [security2:error] [pid 961194:tid 961324] [client 50.6.43.217:40776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amueu_SWp157EsYqB3owcQAAAAA"]
[Thu Jul 30 13:58:04.304395 2026] [security2:error] [pid 977210:tid 977434] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevPW1Jl2-fgIeVvqKnAAAAOE"]
[Thu Jul 30 13:58:04.559636 2026] [security2:error] [pid 977210:tid 977381] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevPW1Jl2-fgIeVvqKpgAAAKw"]
[Thu Jul 30 13:58:04.748758 2026] [security2:error] [pid 977210:tid 977409] [client 20.52.125.110:3117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuevPW1Jl2-fgIeVvqKrQAAAMg"]
[Thu Jul 30 13:58:04.814674 2026] [security2:error] [pid 977210:tid 977420] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevPW1Jl2-fgIeVvqKqwAAANM"]
[Thu Jul 30 13:58:05.032547 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe4\xb8\xad\xe8\x8f\xaf-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:58:05.053498 2026] [security2:error] [pid 977210:tid 977415] [client 50.6.43.217:40798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuevPW1Jl2-fgIeVvqKlgAAAM4"]
[Thu Jul 30 13:58:05.053532 2026] [security2:error] [pid 977210:tid 977415] [client 50.6.43.217:40798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuevPW1Jl2-fgIeVvqKlgAAAM4"]
[Thu Jul 30 13:58:05.073009 2026] [security2:error] [pid 977210:tid 977407] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevPW1Jl2-fgIeVvqKtwAAAMY"]
[Thu Jul 30 13:58:05.333310 2026] [security2:error] [pid 977210:tid 977467] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevfW1Jl2-fgIeVvqKvAAAAQI"]
[Thu Jul 30 13:58:05.546781 2026] [security2:error] [pid 977210:tid 977436] [client 20.52.125.110:4442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuevfW1Jl2-fgIeVvqKwwAAAOM"]
[Thu Jul 30 13:58:05.567531 2026] [security2:error] [pid 961194:tid 961358] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevfSWp157EsYqB3owiQAAACI"]
[Thu Jul 30 13:58:05.917666 2026] [lsapi:warn] [pid 961194:tid 961344] [client 94.154.43.179:0] [host kool-shop.com] Backend log: PHP Warning:  getimagesize(https://kool-shop.com/wp-content/uploads/2025/02/\xe4\xb8\xad\xe5\x8d\x97\xe6\xb5\xb7-150x150.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found\r\n in /home2/dlrdjbte/public_html/website_dd429813/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Thu Jul 30 13:58:05.937632 2026] [security2:error] [pid 977210:tid 977399] [client 50.6.43.217:40840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuevfW1Jl2-fgIeVvqKuQAAAL4"]
[Thu Jul 30 13:58:05.937662 2026] [security2:error] [pid 977210:tid 977399] [client 50.6.43.217:40840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "kool-shop.com"] [uri "/index.php"] [unique_id "amuevfW1Jl2-fgIeVvqKuQAAAL4"]
[Thu Jul 30 13:58:06.081458 2026] [security2:error] [pid 977210:tid 977458] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevfW1Jl2-fgIeVvqKzwAAAPk"]
[Thu Jul 30 13:58:06.318467 2026] [security2:error] [pid 977210:tid 977365] [client 189.6.88.213:62584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuevvW1Jl2-fgIeVvqK1gAAAJw"]
[Thu Jul 30 13:58:06.318601 2026] [security2:error] [pid 977210:tid 977365] [client 189.6.88.213:62584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuevvW1Jl2-fgIeVvqK1gAAAJw"]
[Thu Jul 30 13:58:06.338439 2026] [security2:error] [pid 977210:tid 977419] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevvW1Jl2-fgIeVvqK1AAAANI"]
[Thu Jul 30 13:58:06.446800 2026] [security2:error] [pid 961194:tid 961368] [client 20.52.125.110:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuevvSWp157EsYqB3owlgAAACw"]
[Thu Jul 30 13:58:06.589986 2026] [security2:error] [pid 961194:tid 961361] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevvSWp157EsYqB3owlwAAACU"]
[Thu Jul 30 13:58:06.872750 2026] [security2:error] [pid 977210:tid 977456] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuevvW1Jl2-fgIeVvqK3gAAAPc"]
[Thu Jul 30 13:58:06.999708 2026] [security2:error] [pid 977210:tid 977403] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuevvW1Jl2-fgIeVvqK2AAAwks"]
[Thu Jul 30 13:58:07.101272 2026] [security2:error] [pid 961194:tid 961345] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuev_SWp157EsYqB3owmwAAABU"]
[Thu Jul 30 13:58:07.294562 2026] [autoindex:error] [pid 977210:tid 977416] [client 32.194.121.99:55263] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_72d2afbe/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:58:07.315561 2026] [autoindex:error] [pid 977210:tid 977467] [client 34.233.129.35:14835] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_eeee7ca1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:58:07.358274 2026] [security2:error] [pid 977210:tid 977380] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuev_W1Jl2-fgIeVvqK6wAAAKs"]
[Thu Jul 30 13:58:07.588259 2026] [security2:error] [pid 977210:tid 977401] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuev_W1Jl2-fgIeVvqK8gAAAMA"]
[Thu Jul 30 13:58:07.862589 2026] [security2:error] [pid 977210:tid 977400] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuev_W1Jl2-fgIeVvqK9gAAAL8"]
[Thu Jul 30 13:58:07.932342 2026] [security2:error] [pid 961194:tid 961378] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuev_SWp157EsYqB3ownAAANj4"]
[Thu Jul 30 13:58:08.118781 2026] [security2:error] [pid 961194:tid 961421] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewPSWp157EsYqB3owpwAAAGE"]
[Thu Jul 30 13:58:08.373259 2026] [security2:error] [pid 977210:tid 977419] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewPW1Jl2-fgIeVvqLBgAAANI"]
[Thu Jul 30 13:58:08.470809 2026] [security2:error] [pid 961194:tid 961412] [client 66.249.82.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuevvSWp157EsYqB3owkwAAWCw"]
[Thu Jul 30 13:58:08.603627 2026] [security2:error] [pid 977210:tid 977402] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewPW1Jl2-fgIeVvqLDQAAAME"]
[Thu Jul 30 13:58:08.858550 2026] [security2:error] [pid 961194:tid 961343] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewPSWp157EsYqB3owsAAAABM"]
[Thu Jul 30 13:58:08.880322 2026] [security2:error] [pid 977210:tid 977426] [client 20.91.199.21:50629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/03a005685d.php"] [unique_id "amuewPW1Jl2-fgIeVvqLEAAAANk"]
[Thu Jul 30 13:58:09.113017 2026] [security2:error] [pid 977210:tid 977456] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewfW1Jl2-fgIeVvqLFwAAAPc"]
[Thu Jul 30 13:58:09.256461 2026] [security2:error] [pid 961194:tid 961366] [client 103.190.40.154:20202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuewfSWp157EsYqB3owtgAAACo"]
[Thu Jul 30 13:58:09.256589 2026] [security2:error] [pid 961194:tid 961366] [client 103.190.40.154:20202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuewfSWp157EsYqB3owtgAAACo"]
[Thu Jul 30 13:58:09.511018 2026] [security2:error] [pid 977210:tid 977374] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewfW1Jl2-fgIeVvqLHwAAAKU"]
[Thu Jul 30 13:58:09.764195 2026] [security2:error] [pid 961194:tid 961402] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewfSWp157EsYqB3owvgAAAE4"]
[Thu Jul 30 13:58:09.973687 2026] [security2:error] [pid 977210:tid 977395] [client 20.91.199.21:49661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/403.php"] [unique_id "amuewfW1Jl2-fgIeVvqLKgAAALo"]
[Thu Jul 30 13:58:10.020127 2026] [security2:error] [pid 977210:tid 977389] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewfW1Jl2-fgIeVvqLJgAAALQ"]
[Thu Jul 30 13:58:10.045068 2026] [security2:error] [pid 977210:tid 977398] [client 20.52.125.110:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/content.php"] [unique_id "amuewvW1Jl2-fgIeVvqLLAAAAL0"]
[Thu Jul 30 13:58:10.271297 2026] [security2:error] [pid 977210:tid 977390] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewvW1Jl2-fgIeVvqLLwAAALU"]
[Thu Jul 30 13:58:10.540605 2026] [security2:error] [pid 961194:tid 961391] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewvSWp157EsYqB3owygAAAEM"]
[Thu Jul 30 13:58:10.794038 2026] [security2:error] [pid 977210:tid 977444] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewvW1Jl2-fgIeVvqLOgAAAOs"]
[Thu Jul 30 13:58:11.045883 2026] [security2:error] [pid 977210:tid 977431] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuewvW1Jl2-fgIeVvqLPQAAAN4"]
[Thu Jul 30 13:58:11.298720 2026] [security2:error] [pid 977210:tid 977465] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuew_W1Jl2-fgIeVvqLRgAAAQA"]
[Thu Jul 30 13:58:11.553266 2026] [security2:error] [pid 977210:tid 977369] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuew_W1Jl2-fgIeVvqLSgAAAKA"]
[Thu Jul 30 13:58:11.801721 2026] [security2:error] [pid 961194:tid 961426] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuew_SWp157EsYqB3ow0wAAAGY"]
[Thu Jul 30 13:58:11.934246 2026] [security2:error] [pid 977210:tid 977303] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/erp~"] [unique_id "amuew_W1Jl2-fgIeVvqLUwAAp1o"]
[Thu Jul 30 13:58:11.981693 2026] [core:notice] [pid 977210:tid 977468] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:58:12.041320 2026] [security2:error] [pid 977210:tid 977446] [client 20.91.199.21:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/404.php"] [unique_id "amuexPW1Jl2-fgIeVvqLVwAAAO0"]
[Thu Jul 30 13:58:12.188229 2026] [security2:error] [pid 977210:tid 977418] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuexPW1Jl2-fgIeVvqLWwAAANE"]
[Thu Jul 30 13:58:12.259264 2026] [security2:error] [pid 977210:tid 977441] [client 20.52.125.110:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuexPW1Jl2-fgIeVvqLXgAAAOg"]
[Thu Jul 30 13:58:12.440638 2026] [security2:error] [pid 961194:tid 961379] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuexPSWp157EsYqB3ow2AAAADc"]
[Thu Jul 30 13:58:12.692413 2026] [security2:error] [pid 961194:tid 961334] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuexPSWp157EsYqB3ow2wAAAAo"]
[Thu Jul 30 13:58:12.949294 2026] [security2:error] [pid 961194:tid 961341] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuexPSWp157EsYqB3ow3wAAABE"]
[Thu Jul 30 13:58:13.202828 2026] [security2:error] [pid 961194:tid 961410] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuexfSWp157EsYqB3ow4QAAAFY"]
[Thu Jul 30 13:58:13.236989 2026] [security2:error] [pid 961194:tid 961335] [client 20.52.125.110:3083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuexfSWp157EsYqB3ow5wAAAAs"]
[Thu Jul 30 13:58:13.262906 2026] [security2:error] [pid 977210:tid 977460] [client 20.91.199.21:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/aa.php"] [unique_id "amuexfW1Jl2-fgIeVvqLcAAAAPs"]
[Thu Jul 30 13:58:13.386296 2026] [security2:error] [pid 977210:tid 977372] [client 103.242.199.184:49691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuexfW1Jl2-fgIeVvqLdgAAAKM"]
[Thu Jul 30 13:58:13.386443 2026] [security2:error] [pid 977210:tid 977372] [client 103.242.199.184:49691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuexfW1Jl2-fgIeVvqLdgAAAKM"]
[Thu Jul 30 13:58:13.435550 2026] [security2:error] [pid 977210:tid 977371] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuexfW1Jl2-fgIeVvqLdQAAAKI"]
[Thu Jul 30 13:58:13.695018 2026] [security2:error] [pid 961194:tid 961411] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuexfSWp157EsYqB3ow7gAAAFc"]
[Thu Jul 30 13:58:13.740673 2026] [security2:error] [pid 977210:tid 977453] [client 170.106.148.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kayomanis.com"] [uri "/index.php"] [unique_id "amuexPW1Jl2-fgIeVvqLYwAAAPQ"]
[Thu Jul 30 13:58:13.864736 2026] [security2:error] [pid 961194:tid 961376] [client 181.116.200.68:11881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuexfSWp157EsYqB3ow9AAAADQ"]
[Thu Jul 30 13:58:13.864856 2026] [security2:error] [pid 961194:tid 961376] [client 181.116.200.68:11881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuexfSWp157EsYqB3ow9AAAADQ"]
[Thu Jul 30 13:58:13.874613 2026] [security2:error] [pid 977210:tid 977435] [client 20.52.125.110:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuexfW1Jl2-fgIeVvqLgAAAAOI"]
[Thu Jul 30 13:58:14.121673 2026] [security2:error] [pid 961194:tid 961373] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuexfSWp157EsYqB3ow6wAAADE"]
[Thu Jul 30 13:58:14.510384 2026] [security2:error] [pid 961194:tid 961405] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuexvSWp157EsYqB3ow_wAAAFE"]
[Thu Jul 30 13:58:14.766895 2026] [security2:error] [pid 977210:tid 977399] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuexvW1Jl2-fgIeVvqLjgAAAL4"]
[Thu Jul 30 13:58:14.792868 2026] [security2:error] [pid 961194:tid 961396] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amuexvSWp157EsYqB3ow-wAASF4"]
[Thu Jul 30 13:58:14.897402 2026] [security2:error] [pid 977210:tid 977334] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/prod.htaccess"] [unique_id "amuexvW1Jl2-fgIeVvqLkAAAxXk"]
[Thu Jul 30 13:58:14.953118 2026] [security2:error] [pid 961194:tid 961434] [client 20.52.125.110:3100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuexvSWp157EsYqB3oxBAAAAG4"]
[Thu Jul 30 13:58:15.091194 2026] [security2:error] [pid 977210:tid 977379] [client 20.91.199.21:52640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/aafewc0k.php"] [unique_id "amuex_W1Jl2-fgIeVvqLlQAAAKo"]
[Thu Jul 30 13:58:15.143965 2026] [security2:error] [pid 961194:tid 961402] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuex_SWp157EsYqB3oxBwAAAE4"]
[Thu Jul 30 13:58:15.391433 2026] [security2:error] [pid 961194:tid 961329] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuex_SWp157EsYqB3oxCgAAAAU"]
[Thu Jul 30 13:58:15.528200 2026] [security2:error] [pid 977210:tid 977449] [client 20.52.125.110:3085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuex_W1Jl2-fgIeVvqLoQAAAPA"]
[Thu Jul 30 13:58:15.635998 2026] [security2:error] [pid 977210:tid 977412] [client 193.47.62.167:55278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-b4577515.jvc.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuexvW1Jl2-fgIeVvqLiQAAAMs"]
[Thu Jul 30 13:58:15.638077 2026] [security2:error] [pid 977210:tid 977445] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuex_W1Jl2-fgIeVvqLogAAAOw"]
[Thu Jul 30 13:58:15.887326 2026] [security2:error] [pid 977210:tid 977450] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuex_W1Jl2-fgIeVvqLpgAAAPE"]
[Thu Jul 30 13:58:16.138825 2026] [security2:error] [pid 977210:tid 977377] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueyPW1Jl2-fgIeVvqLqwAAAKg"]
[Thu Jul 30 13:58:16.180827 2026] [security2:error] [pid 977210:tid 977429] [client 189.6.88.213:63107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueyPW1Jl2-fgIeVvqLsQAAANw"]
[Thu Jul 30 13:58:16.180963 2026] [security2:error] [pid 977210:tid 977429] [client 189.6.88.213:63107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amueyPW1Jl2-fgIeVvqLsQAAANw"]
[Thu Jul 30 13:58:16.392089 2026] [security2:error] [pid 977210:tid 977435] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueyPW1Jl2-fgIeVvqLtQAAAOI"]
[Thu Jul 30 13:58:16.649275 2026] [security2:error] [pid 977210:tid 977418] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueyPW1Jl2-fgIeVvqLvgAAANE"]
[Thu Jul 30 13:58:16.906323 2026] [security2:error] [pid 977210:tid 977430] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueyPW1Jl2-fgIeVvqLwgAAAN0"]
[Thu Jul 30 13:58:17.129573 2026] [security2:error] [pid 977210:tid 977348] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueyPW1Jl2-fgIeVvqLuwAAiwQ"]
[Thu Jul 30 13:58:17.160928 2026] [security2:error] [pid 977210:tid 977437] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueyfW1Jl2-fgIeVvqLyQAAAOQ"]
[Thu Jul 30 13:58:17.183835 2026] [security2:error] [pid 977210:tid 977433] [client 20.52.125.110:3094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amueyfW1Jl2-fgIeVvqLzAAAAOA"]
[Thu Jul 30 13:58:17.380790 2026] [security2:error] [pid 977210:tid 977454] [client 20.91.199.21:53447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/abcd.php"] [unique_id "amueyfW1Jl2-fgIeVvqL0wAAAPU"]
[Thu Jul 30 13:58:17.421537 2026] [security2:error] [pid 961194:tid 961360] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueyfSWp157EsYqB3oxHwAAACQ"]
[Thu Jul 30 13:58:17.680830 2026] [security2:error] [pid 977210:tid 977412] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amueyfW1Jl2-fgIeVvqL1wAAAMs"]
[Thu Jul 30 13:58:17.688268 2026] [security2:error] [pid 977210:tid 977447] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueyfW1Jl2-fgIeVvqLxwAA7gY"]
[Thu Jul 30 13:58:17.741361 2026] [security2:error] [pid 977210:tid 977411] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amueyfW1Jl2-fgIeVvqLywAAygk"]
[Thu Jul 30 13:58:17.832402 2026] [security2:error] [pid 977210:tid 977464] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amueyfW1Jl2-fgIeVvqLzgAAAP8"]
[Thu Jul 30 13:58:18.001927 2026] [core:notice] [pid 977210:tid 977399] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:58:18.037631 2026] [security2:error] [pid 961194:tid 961298] [remote 216.73.217.142:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amueyvSWp157EsYqB3oxKwAALGc"]
[Thu Jul 30 13:58:18.535574 2026] [security2:error] [pid 961194:tid 961359] [client 20.52.125.110:3093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amueyvSWp157EsYqB3oxNAAAACM"]
[Thu Jul 30 13:58:19.287086 2026] [security2:error] [pid 977210:tid 977403] [client 20.91.199.21:50835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/about.php"] [unique_id "amuey_W1Jl2-fgIeVvqL5wAAAMI"]
[Thu Jul 30 13:58:19.493156 2026] [security2:error] [pid 977210:tid 977389] [client 20.52.125.110:3099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuey_W1Jl2-fgIeVvqL6AAAALQ"]
[Thu Jul 30 13:58:20.318985 2026] [security2:error] [pid 961194:tid 961442] [client 20.52.125.110:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuezPSWp157EsYqB3oxSAAAAHY"]
[Thu Jul 30 13:58:21.050875 2026] [security2:error] [pid 977210:tid 977425] [client 103.190.40.154:17477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuezfW1Jl2-fgIeVvqL_AAAANg"]
[Thu Jul 30 13:58:21.051009 2026] [security2:error] [pid 977210:tid 977425] [client 103.190.40.154:17477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuezfW1Jl2-fgIeVvqL_AAAANg"]
[Thu Jul 30 13:58:22.350722 2026] [security2:error] [pid 977210:tid 977370] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuezvW1Jl2-fgIeVvqMEAAAAKE"]
[Thu Jul 30 13:58:22.481807 2026] [security2:error] [pid 977210:tid 977235] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env.old"] [unique_id "amuezvW1Jl2-fgIeVvqMEwAAsBY"]
[Thu Jul 30 13:58:22.733936 2026] [security2:error] [pid 977210:tid 977389] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuezvW1Jl2-fgIeVvqMFwAAALQ"]
[Thu Jul 30 13:58:22.987837 2026] [security2:error] [pid 961194:tid 961342] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuezvSWp157EsYqB3oxZgAAABI"]
[Thu Jul 30 13:58:23.122832 2026] [security2:error] [pid 977210:tid 977375] [client 114.119.167.129:49363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "journeywomenscenter.org"] [uri "/robots.txt"] [unique_id "amuez_W1Jl2-fgIeVvqMIQAAAKY"], referer: http://journeywomenscenter.org/robots.txt
[Thu Jul 30 13:58:23.240538 2026] [security2:error] [pid 977210:tid 977416] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuez_W1Jl2-fgIeVvqMIgAAAM8"]
[Thu Jul 30 13:58:23.496190 2026] [security2:error] [pid 977210:tid 977442] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuez_W1Jl2-fgIeVvqMJQAAAOk"]
[Thu Jul 30 13:58:23.501829 2026] [security2:error] [pid 961194:tid 961326] [client 20.91.199.21:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/admin.php"] [unique_id "amuez_SWp157EsYqB3oxcAAAAAI"]
[Thu Jul 30 13:58:23.887485 2026] [security2:error] [pid 961194:tid 961344] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amuez_SWp157EsYqB3oxdAAAABQ"]
[Thu Jul 30 13:58:23.965036 2026] [security2:error] [pid 977210:tid 977357] [client 103.242.199.184:50237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuez_W1Jl2-fgIeVvqMMAAAAJQ"]
[Thu Jul 30 13:58:23.965143 2026] [security2:error] [pid 977210:tid 977357] [client 103.242.199.184:50237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuez_W1Jl2-fgIeVvqMMAAAAJQ"]
[Thu Jul 30 13:58:24.140738 2026] [security2:error] [pid 977210:tid 977399] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0PW1Jl2-fgIeVvqMMwAAAL4"]
[Thu Jul 30 13:58:24.393077 2026] [security2:error] [pid 977210:tid 977347] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0PW1Jl2-fgIeVvqMPAAAAIo"]
[Thu Jul 30 13:58:24.521560 2026] [security2:error] [pid 977210:tid 977356] [client 181.116.200.68:52640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue0PW1Jl2-fgIeVvqMRQAAAJM"]
[Thu Jul 30 13:58:24.521687 2026] [security2:error] [pid 977210:tid 977356] [client 181.116.200.68:52640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue0PW1Jl2-fgIeVvqMRQAAAJM"]
[Thu Jul 30 13:58:24.643528 2026] [security2:error] [pid 977210:tid 977434] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0PW1Jl2-fgIeVvqMSAAAAOE"]
[Thu Jul 30 13:58:24.892774 2026] [security2:error] [pid 977210:tid 977428] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0PW1Jl2-fgIeVvqMUAAAANs"]
[Thu Jul 30 13:58:25.152294 2026] [security2:error] [pid 961194:tid 961345] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0fSWp157EsYqB3oxgAAAABU"]
[Thu Jul 30 13:58:25.182868 2026] [security2:error] [pid 977210:tid 977353] [client 20.91.199.21:53633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/adminfuns.php"] [unique_id "amue0fW1Jl2-fgIeVvqMWQAAAJA"]
[Thu Jul 30 13:58:25.402647 2026] [security2:error] [pid 977210:tid 977425] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0fW1Jl2-fgIeVvqMXgAAANg"]
[Thu Jul 30 13:58:25.655560 2026] [security2:error] [pid 977210:tid 977464] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0fW1Jl2-fgIeVvqMYwAAAP8"]
[Thu Jul 30 13:58:25.787214 2026] [security2:error] [pid 977210:tid 977256] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/settings.swp"] [unique_id "amue0fW1Jl2-fgIeVvqMZgAAsSs"]
[Thu Jul 30 13:58:26.017298 2026] [security2:error] [pid 961194:tid 961428] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0fSWp157EsYqB3oxjAAAAGg"]
[Thu Jul 30 13:58:26.275781 2026] [security2:error] [pid 977210:tid 977371] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0vW1Jl2-fgIeVvqMcAAAAKI"]
[Thu Jul 30 13:58:26.386634 2026] [security2:error] [pid 977210:tid 977433] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amue0fW1Jl2-fgIeVvqMZQAA4C0"]
[Thu Jul 30 13:58:26.409161 2026] [security2:error] [pid 977210:tid 977261] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env.swp"] [unique_id "amue0vW1Jl2-fgIeVvqMdAAAsDA"]
[Thu Jul 30 13:58:26.512538 2026] [security2:error] [pid 961194:tid 961373] [client 20.91.199.21:53649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/albin.php"] [unique_id "amue0vSWp157EsYqB3oxlAAAADE"]
[Thu Jul 30 13:58:26.643610 2026] [security2:error] [pid 977210:tid 977389] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0vW1Jl2-fgIeVvqMegAAALQ"]
[Thu Jul 30 13:58:26.775808 2026] [security2:error] [pid 977210:tid 977269] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.env.swp"] [unique_id "amue0vW1Jl2-fgIeVvqMfAAAxTg"]
[Thu Jul 30 13:58:26.922249 2026] [security2:error] [pid 977210:tid 977462] [client 189.6.88.213:63645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue0vW1Jl2-fgIeVvqMfwAAAP0"]
[Thu Jul 30 13:58:26.922357 2026] [security2:error] [pid 977210:tid 977462] [client 189.6.88.213:63645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue0vW1Jl2-fgIeVvqMfwAAAP0"]
[Thu Jul 30 13:58:27.034489 2026] [security2:error] [pid 977210:tid 977430] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0vW1Jl2-fgIeVvqMfgAAAN0"]
[Thu Jul 30 13:58:27.286012 2026] [security2:error] [pid 977210:tid 977458] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0_W1Jl2-fgIeVvqMhAAAAPk"]
[Thu Jul 30 13:58:27.385682 2026] [security2:error] [pid 977210:tid 977441] [client 74.7.244.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.wrf.zzt.temporary.site"] [uri "/index.php"] [unique_id "amue0PW1Jl2-fgIeVvqMTQAAAOg"]
[Thu Jul 30 13:58:27.385723 2026] [security2:error] [pid 977210:tid 977441] [client 74.7.244.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wrf.zzt.temporary.site"] [uri "/index.php"] [unique_id "amue0PW1Jl2-fgIeVvqMTQAAAOg"]
[Thu Jul 30 13:58:27.386392 2026] [security2:error] [pid 977210:tid 977424] [client 74.7.244.49:45550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.wrf.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amue0PW1Jl2-fgIeVvqMSwAA1yU"]
[Thu Jul 30 13:58:27.417116 2026] [security2:error] [pid 977210:tid 977271] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.EnV"] [unique_id "amue0_W1Jl2-fgIeVvqMigAA3jo"]
[Thu Jul 30 13:58:27.650327 2026] [security2:error] [pid 961194:tid 961442] [client 20.52.125.110:3118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amue0_SWp157EsYqB3oxpwAAAHY"]
[Thu Jul 30 13:58:27.671436 2026] [security2:error] [pid 977210:tid 977460] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0_W1Jl2-fgIeVvqMjgAAAPs"]
[Thu Jul 30 13:58:27.846206 2026] [security2:error] [pid 961194:tid 961350] [client 20.91.199.21:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/amfsqvgv.php"] [unique_id "amue0_SWp157EsYqB3oxqgAAABo"]
[Thu Jul 30 13:58:27.902376 2026] [security2:error] [pid 961194:tid 961430] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue0_SWp157EsYqB3oxqQAAAGo"]
[Thu Jul 30 13:58:27.945683 2026] [security2:error] [pid 977210:tid 977365] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amue0_W1Jl2-fgIeVvqMhgAAnD0"]
[Thu Jul 30 13:58:28.014584 2026] [security2:error] [pid 977210:tid 977413] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amue0_W1Jl2-fgIeVvqMiwAAAMw"]
[Thu Jul 30 13:58:28.031750 2026] [security2:error] [pid 977210:tid 977277] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.EnV"] [unique_id "amue1PW1Jl2-fgIeVvqMlwAAqEA"]
[Thu Jul 30 13:58:28.157960 2026] [security2:error] [pid 977210:tid 977349] [client 74.7.244.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wrf.zzt.temporary.site"] [uri "/index.php"] [unique_id "amue1PW1Jl2-fgIeVvqMmQAAAIw"], referer: https://www.wrf.zzt.temporary.site/robots.txt
[Thu Jul 30 13:58:28.158836 2026] [security2:error] [pid 977210:tid 977438] [client 74.7.244.49:45554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wrf.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amue1PW1Jl2-fgIeVvqMlgAA5UI"], referer: https://www.wrf.zzt.temporary.site/robots.txt
[Thu Jul 30 13:58:28.162778 2026] [security2:error] [pid 977210:tid 977284] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/.EnV^"] [unique_id "amue1PW1Jl2-fgIeVvqMnQABAEc"]
[Thu Jul 30 13:58:28.255912 2026] [security2:error] [pid 977210:tid 977380] [client 20.52.125.110:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/banners/about.php"] [unique_id "amue1PW1Jl2-fgIeVvqMpgAAAKs"]
[Thu Jul 30 13:58:28.426239 2026] [security2:error] [pid 977210:tid 977393] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue1PW1Jl2-fgIeVvqMqwAAALg"]
[Thu Jul 30 13:58:29.078476 2026] [security2:error] [pid 977210:tid 977461] [client 172.237.109.114:55941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/product-details.php"] [unique_id "amue1fW1Jl2-fgIeVvqMuQAAAPw"]
[Thu Jul 30 13:58:29.112278 2026] [security2:error] [pid 977210:tid 977406] [client 20.52.125.110:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/about.php"] [unique_id "amue1fW1Jl2-fgIeVvqMvAAAAMU"]
[Thu Jul 30 13:58:29.534513 2026] [security2:error] [pid 961194:tid 961334] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue1fSWp157EsYqB3oxwAAAAAo"]
[Thu Jul 30 13:58:29.788065 2026] [security2:error] [pid 961194:tid 961433] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue1fSWp157EsYqB3oxwgAAAG0"]
[Thu Jul 30 13:58:29.918573 2026] [security2:error] [pid 977210:tid 977304] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "mail.globaltaxsolaccs.com"] [uri "/authui.htaccess"] [unique_id "amue1fW1Jl2-fgIeVvqMxwAAlFs"]
[Thu Jul 30 13:58:30.170970 2026] [security2:error] [pid 977210:tid 977395] [client 185.177.72.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.globaltaxsolaccs.com"] [uri "/index.php"] [unique_id "amue1vW1Jl2-fgIeVvqMygAAALo"]
[Thu Jul 30 13:58:30.304995 2026] [security2:error] [pid 977210:tid 977293] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/test2.php"] [unique_id "amue1vW1Jl2-fgIeVvqMzwABAFA"]
[Thu Jul 30 13:58:30.434098 2026] [security2:error] [pid 977210:tid 977311] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/test2.php%2e%2e%2f%2e%2e%2f"] [unique_id "amue1vW1Jl2-fgIeVvqM0wAAsmI"]
[Thu Jul 30 13:58:30.549593 2026] [security2:error] [pid 961194:tid 961410] [client 20.52.125.110:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/about.php"] [unique_id "amue1vSWp157EsYqB3oxzQAAAFY"]
[Thu Jul 30 13:58:30.562788 2026] [security2:error] [pid 977210:tid 977309] [remote 185.177.72.70:16688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.globaltaxsolaccs.com"] [uri "/test2.php.well-known"] [unique_id "amue1vW1Jl2-fgIeVvqM1AAAq2A"]
[Thu Jul 30 13:58:31.576396 2026] [autoindex:error] [pid 977210:tid 977396] [client 34.224.175.62:36576] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_7475437c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:58:31.600256 2026] [security2:error] [pid 961194:tid 961365] [client 20.52.125.110:3097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amue1_SWp157EsYqB3ox3wAAACk"]
[Thu Jul 30 13:58:31.707843 2026] [security2:error] [pid 977210:tid 977403] [client 206.135.24.10:47672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amue1_W1Jl2-fgIeVvqM4wAAAMI"]
[Thu Jul 30 13:58:32.014524 2026] [security2:error] [pid 977210:tid 977368] [client 206.135.24.10:45322] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amue2PW1Jl2-fgIeVvqM6gAAAJ8"]
[Thu Jul 30 13:58:32.264619 2026] [security2:error] [pid 961194:tid 961435] [client 103.190.40.154:21238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue2PSWp157EsYqB3ox5gAAAG8"]
[Thu Jul 30 13:58:32.264741 2026] [security2:error] [pid 961194:tid 961435] [client 103.190.40.154:21238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue2PSWp157EsYqB3ox5gAAAG8"]
[Thu Jul 30 13:58:32.522131 2026] [security2:error] [pid 977210:tid 977452] [client 20.52.125.110:4433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amue2PW1Jl2-fgIeVvqM8QAAAPM"]
[Thu Jul 30 13:58:32.672767 2026] [security2:error] [pid 977210:tid 977428] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amue2PW1Jl2-fgIeVvqM6wAA22s"]
[Thu Jul 30 13:58:33.272305 2026] [security2:error] [pid 961194:tid 961405] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amue2PSWp157EsYqB3ox6gAAUWE"]
[Thu Jul 30 13:58:34.572928 2026] [security2:error] [pid 961194:tid 961437] [client 103.242.199.184:50786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amue2vSWp157EsYqB3oyAwAAAHE"]
[Thu Jul 30 13:58:34.573098 2026] [security2:error] [pid 961194:tid 961437] [client 103.242.199.184:50786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amue2vSWp157EsYqB3oyAwAAAHE"]
[Thu Jul 30 13:58:34.662250 2026] [security2:error] [pid 977210:tid 977426] [client 20.52.125.110:4088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/img/about.php"] [unique_id "amue2vW1Jl2-fgIeVvqNBAAAANk"]
[Thu Jul 30 13:58:34.832800 2026] [security2:error] [pid 977210:tid 977355] [client 20.91.199.21:53637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/ant.php"] [unique_id "amue2vW1Jl2-fgIeVvqNBgAAAJI"]
[Thu Jul 30 13:58:34.846252 2026] [proxy:error] [pid 977210:tid 977368] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:58:34.846319 2026] [proxy_http:error] [pid 977210:tid 977368] [client 52.202.41.153:8723] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:58:34.846886 2026] [proxy:error] [pid 977210:tid 977368] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:58:34.846928 2026] [proxy_http:error] [pid 977210:tid 977368] [client 52.202.41.153:8723] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:58:34.874086 2026] [proxy:error] [pid 977210:tid 977460] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:58:34.874168 2026] [proxy_http:error] [pid 977210:tid 977460] [client 52.202.41.153:63385] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:58:34.874956 2026] [proxy:error] [pid 977210:tid 977460] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:58:34.875045 2026] [proxy_http:error] [pid 977210:tid 977460] [client 52.202.41.153:63385] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:58:35.038401 2026] [security2:error] [pid 961194:tid 961447] [client 181.116.200.68:49453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue2_SWp157EsYqB3oyEAAAAHs"]
[Thu Jul 30 13:58:35.038525 2026] [security2:error] [pid 961194:tid 961447] [client 181.116.200.68:49453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue2_SWp157EsYqB3oyEAAAAHs"]
[Thu Jul 30 13:58:35.096161 2026] [security2:error] [pid 977210:tid 977359] [client 172.237.109.114:3509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amue2_W1Jl2-fgIeVvqNEgAAAJY"]
[Thu Jul 30 13:58:35.462078 2026] [security2:error] [pid 977210:tid 977447] [client 20.52.125.110:4062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/languages/about.php"] [unique_id "amue2_W1Jl2-fgIeVvqNFwAAAO4"]
[Thu Jul 30 13:58:36.012835 2026] [security2:error] [pid 961194:tid 961336] [client 20.91.199.21:36082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/appreciators.php"] [unique_id "amue3PSWp157EsYqB3oyIAAAAAw"]
[Thu Jul 30 13:58:36.224153 2026] [security2:error] [pid 961194:tid 961340] [client 20.52.125.110:4086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amue3PSWp157EsYqB3oyIwAAABA"]
[Thu Jul 30 13:58:37.380965 2026] [security2:error] [pid 977210:tid 977420] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amue3PW1Jl2-fgIeVvqNJgAA01k"]
[Thu Jul 30 13:58:37.440661 2026] [security2:error] [pid 977210:tid 977364] [client 20.52.125.110:4444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amue3fW1Jl2-fgIeVvqNLgAAAJs"]
[Thu Jul 30 13:58:37.757823 2026] [security2:error] [pid 977210:tid 977355] [client 184.75.223.227:42024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amue3fW1Jl2-fgIeVvqNMwAAAJI"]
[Thu Jul 30 13:58:37.757912 2026] [security2:error] [pid 977210:tid 977355] [client 184.75.223.227:42024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amue3fW1Jl2-fgIeVvqNMwAAAJI"]
[Thu Jul 30 13:58:38.434843 2026] [security2:error] [pid 977210:tid 977353] [client 20.52.125.110:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amue3vW1Jl2-fgIeVvqNPAAAAJA"]
[Thu Jul 30 13:58:38.514463 2026] [security2:error] [pid 977210:tid 977460] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amue3fW1Jl2-fgIeVvqNNgAAAPs"]
[Thu Jul 30 13:58:38.660931 2026] [core:notice] [pid 961194:tid 961383] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:58:39.636266 2026] [security2:error] [pid 977210:tid 977395] [client 20.52.125.110:3109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amue3_W1Jl2-fgIeVvqNRgAAALo"]
[Thu Jul 30 13:58:40.159379 2026] [security2:error] [pid 977210:tid 977385] [client 20.52.125.110:4087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/js/about.php"] [unique_id "amue4PW1Jl2-fgIeVvqNTAAAALA"]
[Thu Jul 30 13:58:40.407879 2026] [security2:error] [pid 977210:tid 977422] [client 189.6.88.213:64193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue4PW1Jl2-fgIeVvqNTwAAANU"]
[Thu Jul 30 13:58:40.408017 2026] [security2:error] [pid 977210:tid 977422] [client 189.6.88.213:64193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue4PW1Jl2-fgIeVvqNTwAAANU"]
[Thu Jul 30 13:58:40.608352 2026] [security2:error] [pid 977210:tid 977372] [client 20.52.125.110:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amue4PW1Jl2-fgIeVvqNUQAAAKM"]
[Thu Jul 30 13:58:41.308671 2026] [security2:error] [pid 977210:tid 977398] [client 20.91.199.21:36078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/archive.php"] [unique_id "amue4fW1Jl2-fgIeVvqNVwAAAL0"]
[Thu Jul 30 13:58:41.371803 2026] [security2:error] [pid 977210:tid 977443] [client 20.215.191.139:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/--wp-lgj.php"] [unique_id "amue4fW1Jl2-fgIeVvqNWAAAAOo"]
[Thu Jul 30 13:58:41.491625 2026] [security2:error] [pid 961194:tid 961428] [client 20.52.125.110:4064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amue4fSWp157EsYqB3oyaAAAAGg"]
[Thu Jul 30 13:58:42.058528 2026] [security2:error] [pid 977210:tid 977364] [client 20.91.199.21:50058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/as.php"] [unique_id "amue4vW1Jl2-fgIeVvqNXAAAAJs"]
[Thu Jul 30 13:58:42.084644 2026] [security2:error] [pid 977210:tid 977375] [client 20.52.125.110:4071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amue4vW1Jl2-fgIeVvqNXQAAAKY"]
[Thu Jul 30 13:58:42.635688 2026] [proxy:error] [pid 977210:tid 977414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:58:42.635749 2026] [proxy_http:error] [pid 977210:tid 977414] [client 74.7.244.36:55396] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:58:42.636322 2026] [proxy:error] [pid 977210:tid 977414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:58:42.636367 2026] [proxy_http:error] [pid 977210:tid 977414] [client 74.7.244.36:55396] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:58:42.636492 2026] [security2:error] [pid 977210:tid 977414] [client 74.7.244.36:55396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.mxk.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amue4vW1Jl2-fgIeVvqNYQAAAM0"]
[Thu Jul 30 13:58:42.719676 2026] [security2:error] [pid 977210:tid 977426] [client 43.159.143.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amue4vW1Jl2-fgIeVvqNXwAA2XQ"]
[Thu Jul 30 13:58:43.051903 2026] [security2:error] [pid 977210:tid 977409] [client 103.190.40.154:18436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue4_W1Jl2-fgIeVvqNZwAAAMg"]
[Thu Jul 30 13:58:43.052054 2026] [security2:error] [pid 977210:tid 977409] [client 103.190.40.154:18436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue4_W1Jl2-fgIeVvqNZwAAAMg"]
[Thu Jul 30 13:58:43.344658 2026] [core:notice] [pid 977210:tid 977331] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:58:43.355809 2026] [security2:error] [pid 977210:tid 977386] [client 20.52.125.110:4076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amue4_W1Jl2-fgIeVvqNawAAALE"]
[Thu Jul 30 13:58:43.530319 2026] [security2:error] [pid 977210:tid 977457] [client 20.91.199.21:50088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/atomlib.php"] [unique_id "amue4_W1Jl2-fgIeVvqNbQAAAPg"]
[Thu Jul 30 13:58:44.621896 2026] [security2:error] [pid 961194:tid 961426] [client 20.52.125.110:3095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amue5PSWp157EsYqB3oylwAAAGY"]
[Thu Jul 30 13:58:45.290150 2026] [security2:error] [pid 961194:tid 961380] [client 103.242.199.184:51341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amue5fSWp157EsYqB3oynQAAADg"]
[Thu Jul 30 13:58:45.290273 2026] [security2:error] [pid 961194:tid 961380] [client 103.242.199.184:51341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amue5fSWp157EsYqB3oynQAAADg"]
[Thu Jul 30 13:58:45.373088 2026] [security2:error] [pid 977210:tid 977421] [client 20.91.199.21:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/autoload_classmap.php"] [unique_id "amue5fW1Jl2-fgIeVvqNeAAAANQ"]
[Thu Jul 30 13:58:45.559009 2026] [security2:error] [pid 961194:tid 961450] [client 181.116.200.68:53446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue5fSWp157EsYqB3oyowAAAH4"]
[Thu Jul 30 13:58:45.559144 2026] [security2:error] [pid 961194:tid 961450] [client 181.116.200.68:53446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue5fSWp157EsYqB3oyowAAAH4"]
[Thu Jul 30 13:58:45.736015 2026] [security2:error] [pid 977210:tid 977416] [client 20.52.125.110:3116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/about.php"] [unique_id "amue5fW1Jl2-fgIeVvqNfgAAAM8"]
[Thu Jul 30 13:58:45.850141 2026] [security2:error] [pid 977210:tid 977334] [remote 103.77.162.29:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.162.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "laduchessecollections.com"] [uri "/wp-login.php"] [unique_id "amue5fW1Jl2-fgIeVvqNfwAAknk"]
[Thu Jul 30 13:58:45.863732 2026] [security2:error] [pid 977210:tid 977438] [client 3.95.174.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kbaagency.com"] [uri "/index.php"] [unique_id "amue5fW1Jl2-fgIeVvqNfQAA5Xg"], referer: https://kbaagency.com/
[Thu Jul 30 13:58:45.922038 2026] [autoindex:error] [pid 977210:tid 977463] [client 34.224.175.62:50924] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:58:45.941079 2026] [autoindex:error] [pid 977210:tid 977445] [client 34.233.129.35:8357] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:58:46.052344 2026] [security2:error] [pid 977210:tid 977368] [client 20.91.199.21:36630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/bb.php"] [unique_id "amue5vW1Jl2-fgIeVvqNjwAAAJ8"]
[Thu Jul 30 13:58:46.194805 2026] [security2:error] [pid 977210:tid 977460] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amue5vW1Jl2-fgIeVvqNjgAAAPs"]
[Thu Jul 30 13:58:46.205185 2026] [security2:error] [pid 977210:tid 977379] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amue5fW1Jl2-fgIeVvqNfAAAAKo"]
[Thu Jul 30 13:58:46.475021 2026] [security2:error] [pid 961194:tid 961335] [client 185.191.171.15:28900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/02/22/bolsonaro-recebe-senador-bittar-e-e-diz-que-visitara-acre/"] [unique_id "amue5vSWp157EsYqB3oysgAAAAs"]
[Thu Jul 30 13:58:46.475127 2026] [security2:error] [pid 961194:tid 961335] [client 185.191.171.15:28900] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/02/22/bolsonaro-recebe-senador-bittar-e-e-diz-que-visitara-acre/"] [unique_id "amue5vSWp157EsYqB3oysgAAAAs"]
[Thu Jul 30 13:58:46.601623 2026] [security2:error] [pid 977210:tid 977457] [client 20.52.125.110:4059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amue5vW1Jl2-fgIeVvqNmQAAAPg"]
[Thu Jul 30 13:58:46.689605 2026] [security2:error] [pid 977210:tid 977440] [client 20.215.191.139:26245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amue5vW1Jl2-fgIeVvqNmgAAAOc"]
[Thu Jul 30 13:58:46.790483 2026] [security2:error] [pid 977210:tid 977433] [client 20.91.199.21:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/bnm.php"] [unique_id "amue5vW1Jl2-fgIeVvqNnAAAAOA"]
[Thu Jul 30 13:58:47.068735 2026] [security2:error] [pid 977210:tid 977336] [remote 103.75.185.95:35716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amue5_W1Jl2-fgIeVvqNoQAAins"]
[Thu Jul 30 13:58:47.254784 2026] [security2:error] [pid 977210:tid 977340] [remote 89.185.225.24:41414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-login.php"] [unique_id "amue5_W1Jl2-fgIeVvqNpAAAvX8"]
[Thu Jul 30 13:58:47.264950 2026] [security2:error] [pid 977210:tid 977371] [client 20.52.125.110:4089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/images/about.php"] [unique_id "amue5_W1Jl2-fgIeVvqNpQAAAKI"]
[Thu Jul 30 13:58:47.464097 2026] [security2:error] [pid 961194:tid 961369] [client 20.215.191.139:31012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/flower.php"] [unique_id "amue5_SWp157EsYqB3oyvwAAAC0"]
[Thu Jul 30 13:58:47.798194 2026] [security2:error] [pid 977210:tid 977215] [remote 103.28.36.199:36118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amue5_W1Jl2-fgIeVvqNqgAA4QI"]
[Thu Jul 30 13:58:47.851280 2026] [security2:error] [pid 977210:tid 977443] [client 20.91.199.21:36044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/bootstrap.php"] [unique_id "amue5_W1Jl2-fgIeVvqNrQAAAOo"]
[Thu Jul 30 13:58:48.074444 2026] [security2:error] [pid 961194:tid 961434] [client 20.215.191.139:31038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/xleet.php"] [unique_id "amue6PSWp157EsYqB3oyxAAAAG4"]
[Thu Jul 30 13:58:48.464199 2026] [security2:error] [pid 961194:tid 961257] [remote 74.7.243.224:56722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/login.php"] [unique_id "amue6PSWp157EsYqB3oyygAAUT4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/content/1784123347_ed%20inclusive.jpg
[Thu Jul 30 13:58:48.564741 2026] [security2:error] [pid 961194:tid 961285] [remote 87.250.224.4:37390] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/the-largest-container-ship-in-the-world-arrived/"] [unique_id "amue6PSWp157EsYqB3oyzAAAdlo"]
[Thu Jul 30 13:58:49.102197 2026] [security2:error] [pid 977210:tid 977391] [client 20.91.199.21:49396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/buy.php"] [unique_id "amue6fW1Jl2-fgIeVvqNvwAAALY"]
[Thu Jul 30 13:58:49.419896 2026] [security2:error] [pid 977210:tid 977431] [client 20.52.125.110:3922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amue6fW1Jl2-fgIeVvqNwwAAAN4"]
[Thu Jul 30 13:58:49.866096 2026] [security2:error] [pid 977210:tid 977389] [client 20.91.199.21:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/chosen.php"] [unique_id "amue6fW1Jl2-fgIeVvqNzQAAALQ"]
[Thu Jul 30 13:58:49.975386 2026] [security2:error] [pid 961194:tid 961379] [client 20.52.125.110:4432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/images/about.php"] [unique_id "amue6fSWp157EsYqB3oy5AAAADc"]
[Thu Jul 30 13:58:50.077277 2026] [security2:error] [pid 961194:tid 961334] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amue6fSWp157EsYqB3oy4wAACjk"]
[Thu Jul 30 13:58:50.354321 2026] [security2:error] [pid 977210:tid 977222] [remote 57.141.0.60:59612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amue6vW1Jl2-fgIeVvqN1QAAvQk"]
[Thu Jul 30 13:58:50.527864 2026] [security2:error] [pid 977210:tid 977459] [client 20.52.125.110:3073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/about.php"] [unique_id "amue6vW1Jl2-fgIeVvqN1gAAAPo"]
[Thu Jul 30 13:58:51.088916 2026] [security2:error] [pid 977210:tid 977418] [client 20.215.191.139:19752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amue6_W1Jl2-fgIeVvqN4wAAANE"]
[Thu Jul 30 13:58:51.230774 2026] [security2:error] [pid 977210:tid 977432] [client 20.52.125.110:4056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/cgi-bin/about.php"] [unique_id "amue6_W1Jl2-fgIeVvqN5AAAAN8"]
[Thu Jul 30 13:58:51.252058 2026] [fcgid:warn] [pid 977210:tid 977350] (70014)End of file found: [client 18.116.101.220:19136] mod_fcgid: can't get data from http client
[Thu Jul 30 13:58:51.366707 2026] [security2:error] [pid 977210:tid 977464] [client 189.6.88.213:64882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue6_W1Jl2-fgIeVvqN6gAAAP8"]
[Thu Jul 30 13:58:51.366816 2026] [security2:error] [pid 977210:tid 977464] [client 189.6.88.213:64882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue6_W1Jl2-fgIeVvqN6gAAAP8"]
[Thu Jul 30 13:58:51.579625 2026] [security2:error] [pid 977210:tid 977467] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amue6vW1Jl2-fgIeVvqN3gAAAQI"]
[Thu Jul 30 13:58:51.923318 2026] [security2:error] [pid 977210:tid 977395] [client 20.52.125.110:3129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amue6_W1Jl2-fgIeVvqN_AAAALo"]
[Thu Jul 30 13:58:52.148196 2026] [security2:error] [pid 977210:tid 977456] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amue6_W1Jl2-fgIeVvqN8QAA9xU"]
[Thu Jul 30 13:58:52.558802 2026] [security2:error] [pid 977210:tid 977347] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amue6_W1Jl2-fgIeVvqOCAAAAIo"]
[Thu Jul 30 13:58:52.572879 2026] [security2:error] [pid 977210:tid 977405] [client 20.52.125.110:4046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amue7PW1Jl2-fgIeVvqOEgAAAMQ"]
[Thu Jul 30 13:58:52.867073 2026] [security2:error] [pid 977210:tid 977243] [remote 217.182.128.41:57976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amue7PW1Jl2-fgIeVvqOFgAApB4"]
[Thu Jul 30 13:58:53.048844 2026] [security2:error] [pid 977210:tid 977259] [remote 216.73.217.142:36522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amue7fW1Jl2-fgIeVvqOKAAApS4"]
[Thu Jul 30 13:58:53.220039 2026] [security2:error] [pid 977210:tid 977465] [client 20.52.125.110:4443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/about.php"] [unique_id "amue7fW1Jl2-fgIeVvqOKQAAAQA"]
[Thu Jul 30 13:58:53.513656 2026] [security2:error] [pid 977210:tid 977354] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amue7PW1Jl2-fgIeVvqOGgAAkSI"]
[Thu Jul 30 13:58:53.605647 2026] [security2:error] [pid 977210:tid 977349] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amue7fW1Jl2-fgIeVvqOJgAAAIw"]
[Thu Jul 30 13:58:53.643247 2026] [security2:error] [pid 977210:tid 977256] [remote 57.141.0.25:65228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amue7fW1Jl2-fgIeVvqOMwAAqys"]
[Thu Jul 30 13:58:53.927297 2026] [security2:error] [pid 977210:tid 977356] [client 103.190.40.154:20213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue7fW1Jl2-fgIeVvqOOQAAAJM"]
[Thu Jul 30 13:58:53.927435 2026] [security2:error] [pid 977210:tid 977356] [client 103.190.40.154:20213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue7fW1Jl2-fgIeVvqOOQAAAJM"]
[Thu Jul 30 13:58:54.358386 2026] [security2:error] [pid 977210:tid 977468] [client 20.52.125.110:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/images/about.php"] [unique_id "amue7vW1Jl2-fgIeVvqOQQAAAQM"]
[Thu Jul 30 13:58:54.400811 2026] [core:notice] [pid 977210:tid 977375] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:58:54.502360 2026] [security2:error] [pid 977210:tid 977267] [remote 57.141.0.18:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amue7vW1Jl2-fgIeVvqORgAAzzY"]
[Thu Jul 30 13:58:55.103426 2026] [security2:error] [pid 977210:tid 977379] [client 20.52.125.110:4053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amue7_W1Jl2-fgIeVvqOWAAAAKo"]
[Thu Jul 30 13:58:55.964093 2026] [security2:error] [pid 977210:tid 977439] [client 103.242.199.184:51887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amue7_W1Jl2-fgIeVvqOZAAAAOY"]
[Thu Jul 30 13:58:55.964216 2026] [security2:error] [pid 977210:tid 977439] [client 103.242.199.184:51887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amue7_W1Jl2-fgIeVvqOZAAAAOY"]
[Thu Jul 30 13:58:56.182830 2026] [security2:error] [pid 977210:tid 977391] [client 20.215.191.139:5412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amue8PW1Jl2-fgIeVvqOcQAAALY"]
[Thu Jul 30 13:58:56.217313 2026] [security2:error] [pid 977210:tid 977461] [client 181.116.200.68:13797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue8PW1Jl2-fgIeVvqOcgAAAPw"]
[Thu Jul 30 13:58:56.217427 2026] [security2:error] [pid 977210:tid 977461] [client 181.116.200.68:13797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue8PW1Jl2-fgIeVvqOcgAAAPw"]
[Thu Jul 30 13:58:56.531054 2026] [security2:error] [pid 977210:tid 977397] [client 20.52.125.110:3103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amue8PW1Jl2-fgIeVvqOcwAAALw"]
[Thu Jul 30 13:58:56.598802 2026] [security2:error] [pid 977210:tid 977356] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amue8PW1Jl2-fgIeVvqOZwAAAJM"]
[Thu Jul 30 13:58:56.824307 2026] [security2:error] [pid 977210:tid 977353] [client 20.215.191.139:18521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amue8PW1Jl2-fgIeVvqOfQAAAJA"]
[Thu Jul 30 13:58:56.937973 2026] [security2:error] [pid 977210:tid 977285] [remote 89.185.225.24:42202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue8PW1Jl2-fgIeVvqOfgAApEg"]
[Thu Jul 30 13:58:56.938194 2026] [security2:error] [pid 977210:tid 977373] [client 89.185.225.24:42202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue8PW1Jl2-fgIeVvqOfgAApEg"]
[Thu Jul 30 13:58:57.343007 2026] [security2:error] [pid 977210:tid 977387] [client 127.0.0.1:49698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amue8fW1Jl2-fgIeVvqOjAAAALI"]
[Thu Jul 30 13:58:57.343007 2026] [security2:error] [pid 977210:tid 977453] [client 127.0.0.1:49694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amue8fW1Jl2-fgIeVvqOiwAAAPQ"]
[Thu Jul 30 13:58:57.343143 2026] [security2:error] [pid 977210:tid 977409] [client 74.7.230.34:48922] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.austriavisaapplicationcenterinislamabad.site"] [uri "/robots.txt"] [unique_id "amue8fW1Jl2-fgIeVvqOigAAyEk"]
[Thu Jul 30 13:58:57.641499 2026] [security2:error] [pid 977210:tid 977399] [client 20.52.125.110:4067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amue8fW1Jl2-fgIeVvqOkgAAAL4"]
[Thu Jul 30 13:58:57.740317 2026] [security2:error] [pid 977210:tid 977424] [client 20.215.191.139:25826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amue8fW1Jl2-fgIeVvqOlwAAANc"]
[Thu Jul 30 13:58:57.760142 2026] [security2:error] [pid 977210:tid 977464] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amue8fW1Jl2-fgIeVvqOggAA_0U"]
[Thu Jul 30 13:58:57.981842 2026] [security2:error] [pid 977210:tid 977362] [client 66.249.66.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laduchessecollections.com"] [uri "/index.php"] [unique_id "amue8fW1Jl2-fgIeVvqOlgAAmVc"]
[Thu Jul 30 13:58:58.263772 2026] [security2:error] [pid 977210:tid 977343] [client 20.52.125.110:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/cloud.php"] [unique_id "amue8vW1Jl2-fgIeVvqOqAAAAIY"]
[Thu Jul 30 13:58:59.311583 2026] [security2:error] [pid 977210:tid 977388] [client 20.215.191.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amue8_W1Jl2-fgIeVvqOtQAAALM"]
[Thu Jul 30 13:58:59.377344 2026] [security2:error] [pid 977210:tid 977452] [client 20.52.125.110:4043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amue8_W1Jl2-fgIeVvqOxAAAAPM"]
[Thu Jul 30 13:58:59.644067 2026] [security2:error] [pid 977210:tid 977399] [client 20.215.191.139:25821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amue8_W1Jl2-fgIeVvqOxgAAAL4"]
[Thu Jul 30 13:58:59.848683 2026] [security2:error] [pid 977210:tid 977379] [client 20.91.199.21:49382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/class-wp-image.php"] [unique_id "amue8_W1Jl2-fgIeVvqO0wAAAKo"]
[Thu Jul 30 13:59:00.025280 2026] [security2:error] [pid 977210:tid 977447] [client 20.52.125.110:3121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/updates.php"] [unique_id "amue9PW1Jl2-fgIeVvqO1gAAAO4"]
[Thu Jul 30 13:59:00.952264 2026] [security2:error] [pid 977210:tid 977426] [client 20.52.125.110:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/css/cloud.php"] [unique_id "amue9PW1Jl2-fgIeVvqO7QAAANk"]
[Thu Jul 30 13:59:01.404009 2026] [security2:error] [pid 977210:tid 977449] [client 20.91.199.21:54555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/classsmtps.php"] [unique_id "amue9fW1Jl2-fgIeVvqO9wAAAPA"]
[Thu Jul 30 13:59:01.503672 2026] [core:notice] [pid 977210:tid 977355] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:01.689364 2026] [core:notice] [pid 977210:tid 977394] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:01.729381 2026] [security2:error] [pid 977210:tid 977356] [client 20.215.191.139:27362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amue9fW1Jl2-fgIeVvqO_wAAAJM"]
[Thu Jul 30 13:59:01.873227 2026] [security2:error] [pid 977210:tid 977455] [client 20.52.125.110:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amue9fW1Jl2-fgIeVvqPCAAAAPY"]
[Thu Jul 30 13:59:02.477531 2026] [security2:error] [pid 977210:tid 977367] [client 20.91.199.21:49366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/classwithtostring.php"] [unique_id "amue9vW1Jl2-fgIeVvqPGwAAAJ4"]
[Thu Jul 30 13:59:02.786284 2026] [security2:error] [pid 977210:tid 977446] [client 20.215.191.139:26965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amue9vW1Jl2-fgIeVvqPJQAAAO0"]
[Thu Jul 30 13:59:02.807939 2026] [security2:error] [pid 977210:tid 977400] [client 20.52.125.110:4035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/img/cloud.php"] [unique_id "amue9vW1Jl2-fgIeVvqPKQAAAL8"]
[Thu Jul 30 13:59:03.310511 2026] [security2:error] [pid 977210:tid 977224] [remote 157.66.47.83:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.47.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amue9_W1Jl2-fgIeVvqPNgAA7As"]
[Thu Jul 30 13:59:03.693148 2026] [security2:error] [pid 977210:tid 977358] [client 20.52.125.110:4084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amue9_W1Jl2-fgIeVvqPQwAAAJU"]
[Thu Jul 30 13:59:04.147354 2026] [security2:error] [pid 977210:tid 977415] [client 20.215.191.139:18452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.wp-cli/flower.php"] [unique_id "amue-PW1Jl2-fgIeVvqPUQAAAM4"]
[Thu Jul 30 13:59:04.441518 2026] [security2:error] [pid 977210:tid 977434] [client 20.52.125.110:4081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amue-PW1Jl2-fgIeVvqPWAAAAOE"]
[Thu Jul 30 13:59:04.543235 2026] [security2:error] [pid 977210:tid 977407] [client 20.91.199.21:49375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/config.php"] [unique_id "amue-PW1Jl2-fgIeVvqPWQAAAMY"]
[Thu Jul 30 13:59:04.643592 2026] [core:error] [pid 977210:tid 977405] [client 95.108.213.179:55964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:59:04.643617 2026] [core:error] [pid 977210:tid 977405] [client 95.108.213.179:55964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:59:04.748008 2026] [security2:error] [pid 977210:tid 977469] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amue-PW1Jl2-fgIeVvqPVAAAAQQ"]
[Thu Jul 30 13:59:04.946742 2026] [security2:error] [pid 977210:tid 977445] [client 103.190.40.154:20866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue-PW1Jl2-fgIeVvqPaQAAAOw"]
[Thu Jul 30 13:59:04.946876 2026] [security2:error] [pid 977210:tid 977445] [client 103.190.40.154:20866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amue-PW1Jl2-fgIeVvqPaQAAAOw"]
[Thu Jul 30 13:59:05.149169 2026] [security2:error] [pid 977210:tid 977467] [client 20.52.125.110:3104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/avaa.php"] [unique_id "amue-fW1Jl2-fgIeVvqPbgAAAQI"]
[Thu Jul 30 13:59:05.411729 2026] [security2:error] [pid 977210:tid 977365] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amue-PW1Jl2-fgIeVvqPZQAAAJw"]
[Thu Jul 30 13:59:05.675318 2026] [security2:error] [pid 977210:tid 977357] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amue-fW1Jl2-fgIeVvqPagAAlBo"]
[Thu Jul 30 13:59:05.695263 2026] [security2:error] [pid 977210:tid 977352] [client 20.215.191.139:18543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amue-fW1Jl2-fgIeVvqPeQAAAI8"]
[Thu Jul 30 13:59:05.799682 2026] [security2:error] [pid 977210:tid 977431] [client 20.52.125.110:3096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/images/cloud.php"] [unique_id "amue-fW1Jl2-fgIeVvqPfQAAAN4"]
[Thu Jul 30 13:59:06.555061 2026] [security2:error] [pid 977210:tid 977377] [client 20.52.125.110:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amue-vW1Jl2-fgIeVvqPkAAAAKg"]
[Thu Jul 30 13:59:06.573648 2026] [security2:error] [pid 977210:tid 977446] [client 20.215.191.139:19725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amue-vW1Jl2-fgIeVvqPkQAAAO0"]
[Thu Jul 30 13:59:06.585835 2026] [security2:error] [pid 977210:tid 977370] [client 103.242.199.184:52436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amue-vW1Jl2-fgIeVvqPkgAAAKE"]
[Thu Jul 30 13:59:06.585930 2026] [security2:error] [pid 977210:tid 977370] [client 103.242.199.184:52436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amue-vW1Jl2-fgIeVvqPkgAAAKE"]
[Thu Jul 30 13:59:06.791659 2026] [security2:error] [pid 977210:tid 977450] [client 20.91.199.21:54697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/core.php"] [unique_id "amue-vW1Jl2-fgIeVvqPnAAAAPE"]
[Thu Jul 30 13:59:06.812156 2026] [security2:error] [pid 977210:tid 977368] [client 181.116.200.68:25095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue-vW1Jl2-fgIeVvqPnQAAAJ8"]
[Thu Jul 30 13:59:06.812261 2026] [security2:error] [pid 977210:tid 977368] [client 181.116.200.68:25095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amue-vW1Jl2-fgIeVvqPnQAAAJ8"]
[Thu Jul 30 13:59:06.998762 2026] [core:notice] [pid 977210:tid 977413] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:07.154883 2026] [security2:error] [pid 977210:tid 977350] [client 20.52.125.110:3074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amue-_W1Jl2-fgIeVvqPpQAAAI0"]
[Thu Jul 30 13:59:07.373563 2026] [security2:error] [pid 977210:tid 977433] [client 20.215.191.139:5422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amue-_W1Jl2-fgIeVvqPrAAAAOA"]
[Thu Jul 30 13:59:07.921167 2026] [core:error] [pid 977210:tid 977430] [client 185.247.137.203:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:59:07.921189 2026] [core:error] [pid 977210:tid 977430] [client 185.247.137.203:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:59:08.089590 2026] [security2:error] [pid 977210:tid 977447] [client 20.91.199.21:54514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/css.php"] [unique_id "amue_PW1Jl2-fgIeVvqPvwAAAO4"]
[Thu Jul 30 13:59:08.122192 2026] [security2:error] [pid 977210:tid 977383] [client 20.52.125.110:3132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amue_PW1Jl2-fgIeVvqPwQAAAK4"]
[Thu Jul 30 13:59:08.243267 2026] [security2:error] [pid 977210:tid 977446] [client 20.215.191.139:19714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amue_PW1Jl2-fgIeVvqPxQAAAO0"]
[Thu Jul 30 13:59:08.391036 2026] [core:notice] [pid 977210:tid 977269] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:08.663646 2026] [security2:error] [pid 977210:tid 977350] [client 20.52.125.110:3120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amue_PW1Jl2-fgIeVvqP1wAAAI0"]
[Thu Jul 30 13:59:08.954853 2026] [security2:error] [pid 977210:tid 977396] [client 20.215.191.139:5372] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cnpinyin.com"] [uri "/1.php"] [unique_id "amue_PW1Jl2-fgIeVvqP4gAAALs"]
[Thu Jul 30 13:59:08.955026 2026] [security2:error] [pid 977210:tid 977396] [client 20.215.191.139:5372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/1.php"] [unique_id "amue_PW1Jl2-fgIeVvqP4gAAALs"]
[Thu Jul 30 13:59:09.154696 2026] [security2:error] [pid 977210:tid 977431] [client 20.91.199.21:36149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/database.php"] [unique_id "amue_fW1Jl2-fgIeVvqP5gAAAN4"]
[Thu Jul 30 13:59:09.411951 2026] [security2:error] [pid 977210:tid 977397] [client 20.52.125.110:4085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amue_fW1Jl2-fgIeVvqP9AAAALw"]
[Thu Jul 30 13:59:09.772513 2026] [core:notice] [pid 977210:tid 977279] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:10.000536 2026] [core:notice] [pid 977210:tid 977285] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:10.036616 2026] [security2:error] [pid 977210:tid 977468] [client 20.52.125.110:4455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/cloud.php"] [unique_id "amue_vW1Jl2-fgIeVvqQBAAAAQM"]
[Thu Jul 30 13:59:10.072519 2026] [security2:error] [pid 977210:tid 977287] [remote 47.128.27.92:10938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/adidas-samba-xlg-31/"] [unique_id "amue_vW1Jl2-fgIeVvqQBQAAuEo"]
[Thu Jul 30 13:59:10.216600 2026] [security2:error] [pid 977210:tid 977374] [client 20.215.191.139:30491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/admin.php"] [unique_id "amue_vW1Jl2-fgIeVvqQBgAAAKU"]
[Thu Jul 30 13:59:10.690718 2026] [security2:error] [pid 977210:tid 977358] [client 20.52.125.110:4057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/updates.php"] [unique_id "amue_vW1Jl2-fgIeVvqQEQAAAJU"]
[Thu Jul 30 13:59:11.016246 2026] [security2:error] [pid 977210:tid 977296] [remote 195.63.30.203:36146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amue__W1Jl2-fgIeVvqQHwAA-1M"], referer: https://deltaedu.net/
[Thu Jul 30 13:59:11.204282 2026] [security2:error] [pid 977210:tid 977438] [client 20.52.125.110:3119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amue__W1Jl2-fgIeVvqQIwAAAOU"]
[Thu Jul 30 13:59:11.327203 2026] [core:notice] [pid 977210:tid 977372] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:11.700510 2026] [security2:error] [pid 977210:tid 977405] [client 20.215.191.139:19753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/as.php"] [unique_id "amue__W1Jl2-fgIeVvqQMQAAAMQ"]
[Thu Jul 30 13:59:12.373699 2026] [security2:error] [pid 977210:tid 977378] [client 106.117.106.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amufAPW1Jl2-fgIeVvqQOAAAqWA"]
[Thu Jul 30 13:59:12.565395 2026] [security2:error] [pid 977210:tid 977368] [client 20.52.125.110:3090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amufAPW1Jl2-fgIeVvqQQwAAAJ8"]
[Thu Jul 30 13:59:12.585404 2026] [fcgid:warn] [pid 977210:tid 977403] (70014)End of file found: [client 18.116.101.220:35494] mod_fcgid: can't get data from http client
[Thu Jul 30 13:59:12.682230 2026] [security2:error] [pid 977210:tid 977467] [client 20.91.199.21:54708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/db.php"] [unique_id "amufAPW1Jl2-fgIeVvqQSAAAAQI"]
[Thu Jul 30 13:59:13.282863 2026] [security2:error] [pid 977210:tid 977418] [client 20.52.125.110:3110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amufAfW1Jl2-fgIeVvqQVgAAANE"]
[Thu Jul 30 13:59:13.337676 2026] [security2:error] [pid 977210:tid 977408] [client 20.91.199.21:54487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/default.php"] [unique_id "amufAfW1Jl2-fgIeVvqQWAAAAMc"]
[Thu Jul 30 13:59:13.881772 2026] [security2:error] [pid 977210:tid 977430] [client 20.215.191.139:18607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/autoload_classmap.php"] [unique_id "amufAfW1Jl2-fgIeVvqQaQAAAN0"]
[Thu Jul 30 13:59:13.966484 2026] [security2:error] [pid 977210:tid 977409] [client 20.91.199.21:50375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/dropdown.php"] [unique_id "amufAfW1Jl2-fgIeVvqQbQAAAMg"]
[Thu Jul 30 13:59:14.232165 2026] [security2:error] [pid 977210:tid 977407] [client 20.52.125.110:4079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/alfa-rex.php7"] [unique_id "amufAvW1Jl2-fgIeVvqQcgAAAMY"]
[Thu Jul 30 13:59:14.940794 2026] [security2:error] [pid 977210:tid 977350] [client 20.52.125.110:3948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/alfanew.php"] [unique_id "amufAvW1Jl2-fgIeVvqQgAAAAI0"]
[Thu Jul 30 13:59:15.181707 2026] [security2:error] [pid 977210:tid 977469] [client 20.91.199.21:54667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/edit.php"] [unique_id "amufA_W1Jl2-fgIeVvqQhwAAAQQ"]
[Thu Jul 30 13:59:15.283606 2026] [core:notice] [pid 977210:tid 977332] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:15.504820 2026] [security2:error] [pid 977210:tid 977371] [client 103.190.40.154:19132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufA_W1Jl2-fgIeVvqQjQAAAKI"]
[Thu Jul 30 13:59:15.505012 2026] [security2:error] [pid 977210:tid 977371] [client 103.190.40.154:19132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufA_W1Jl2-fgIeVvqQjQAAAKI"]
[Thu Jul 30 13:59:15.548310 2026] [security2:error] [pid 977210:tid 977327] [remote 75.119.132.40:50670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.132.119.75.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amufA_W1Jl2-fgIeVvqQjgAA0XI"]
[Thu Jul 30 13:59:15.560902 2026] [security2:error] [pid 977210:tid 977455] [client 20.215.191.139:21427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/back.php"] [unique_id "amufA_W1Jl2-fgIeVvqQjwAAAPY"]
[Thu Jul 30 13:59:15.749342 2026] [security2:error] [pid 977210:tid 977443] [client 20.52.125.110:4040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amufA_W1Jl2-fgIeVvqQlgAAAOo"]
[Thu Jul 30 13:59:15.933580 2026] [core:notice] [pid 977210:tid 977340] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:16.207083 2026] [security2:error] [pid 977210:tid 977452] [client 20.52.125.110:4094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amufBPW1Jl2-fgIeVvqQpwAAAPM"]
[Thu Jul 30 13:59:16.223755 2026] [security2:error] [pid 977210:tid 977348] [client 20.215.191.139:30471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/c/autoload_classmap.php"] [unique_id "amufBPW1Jl2-fgIeVvqQqgAAAIs"]
[Thu Jul 30 13:59:16.457502 2026] [security2:error] [pid 977210:tid 977380] [client 216.73.217.30:21486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amufBPW1Jl2-fgIeVvqQsgAAqwA"]
[Thu Jul 30 13:59:16.587060 2026] [security2:error] [pid 977210:tid 977439] [client 172.237.109.114:23588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amufBPW1Jl2-fgIeVvqQnQAAAOY"]
[Thu Jul 30 13:59:16.713049 2026] [security2:error] [pid 977210:tid 977392] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufBPW1Jl2-fgIeVvqQoAAAALc"]
[Thu Jul 30 13:59:16.842474 2026] [security2:error] [pid 977210:tid 977395] [client 20.91.199.21:54687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/f35.php"] [unique_id "amufBPW1Jl2-fgIeVvqQvgAAALo"]
[Thu Jul 30 13:59:16.978170 2026] [security2:error] [pid 977210:tid 977358] [client 20.52.125.110:3084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-p.php7"] [unique_id "amufBPW1Jl2-fgIeVvqQwwAAAJU"]
[Thu Jul 30 13:59:17.192879 2026] [security2:error] [pid 977210:tid 977448] [client 103.242.199.184:52997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufBfW1Jl2-fgIeVvqQygAAAO8"]
[Thu Jul 30 13:59:17.192999 2026] [security2:error] [pid 977210:tid 977448] [client 103.242.199.184:52997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufBfW1Jl2-fgIeVvqQygAAAO8"]
[Thu Jul 30 13:59:17.340812 2026] [security2:error] [pid 977210:tid 977454] [client 181.116.200.68:43748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufBfW1Jl2-fgIeVvqQ0QAAAPU"]
[Thu Jul 30 13:59:17.340909 2026] [security2:error] [pid 977210:tid 977454] [client 181.116.200.68:43748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufBfW1Jl2-fgIeVvqQ0QAAAPU"]
[Thu Jul 30 13:59:17.389709 2026] [security2:error] [pid 977210:tid 977344] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufBPW1Jl2-fgIeVvqQvQAAAIc"]
[Thu Jul 30 13:59:17.819591 2026] [security2:error] [pid 977210:tid 977428] [client 20.215.191.139:21387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/c/flower.php"] [unique_id "amufBfW1Jl2-fgIeVvqQ4QAAANs"]
[Thu Jul 30 13:59:17.938922 2026] [security2:error] [pid 977210:tid 977346] [client 20.91.199.21:35729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.laduchessecollections.com"] [uri "/f7.php"] [unique_id "amufBfW1Jl2-fgIeVvqQ5gAAAIk"]
[Thu Jul 30 13:59:18.141035 2026] [security2:error] [pid 977210:tid 977465] [client 20.52.125.110:3080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/repeater.php"] [unique_id "amufBvW1Jl2-fgIeVvqQ8gAAAQA"]
[Thu Jul 30 13:59:18.170561 2026] [core:notice] [pid 977210:tid 977421] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:18.261494 2026] [core:notice] [pid 977210:tid 977263] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:18.321425 2026] [security2:error] [pid 977210:tid 977459] [client 64.42.179.51:48204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amufBvW1Jl2-fgIeVvqRBAAAAPo"]
[Thu Jul 30 13:59:18.321520 2026] [security2:error] [pid 977210:tid 977459] [client 64.42.179.51:48204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amufBvW1Jl2-fgIeVvqRBAAAAPo"]
[Thu Jul 30 13:59:18.664458 2026] [security2:error] [pid 977210:tid 977418] [client 20.52.125.110:4049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/repeater.php"] [unique_id "amufBvW1Jl2-fgIeVvqRCQAAANE"]
[Thu Jul 30 13:59:18.968779 2026] [security2:error] [pid 977210:tid 977270] [remote 74.7.227.39:44454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amufBvW1Jl2-fgIeVvqRDQAA5Dk"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/
[Thu Jul 30 13:59:19.314969 2026] [security2:error] [pid 977210:tid 977375] [client 20.52.125.110:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/repeater.php"] [unique_id "amufB_W1Jl2-fgIeVvqRHQAAAKY"]
[Thu Jul 30 13:59:22.421173 2026] [core:notice] [pid 977210:tid 977319] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:22.864729 2026] [security2:error] [pid 977210:tid 977430] [client 5.161.113.195:13674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amufCvW1Jl2-fgIeVvqRZgAAAN0"], referer: https://globalmarks.pk/
[Thu Jul 30 13:59:25.503784 2026] [security2:error] [pid 977210:tid 977410] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amufDfW1Jl2-fgIeVvqRswAAyX0"]
[Thu Jul 30 13:59:27.883245 2026] [security2:error] [pid 977210:tid 977416] [client 103.242.199.184:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufD_W1Jl2-fgIeVvqR6QAAAM8"]
[Thu Jul 30 13:59:27.883364 2026] [security2:error] [pid 977210:tid 977416] [client 103.242.199.184:53549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufD_W1Jl2-fgIeVvqR6QAAAM8"]
[Thu Jul 30 13:59:28.039653 2026] [security2:error] [pid 977210:tid 977359] [client 181.116.200.68:24129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufEPW1Jl2-fgIeVvqR7QAAAJY"]
[Thu Jul 30 13:59:28.039758 2026] [security2:error] [pid 977210:tid 977359] [client 181.116.200.68:24129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufEPW1Jl2-fgIeVvqR7QAAAJY"]
[Thu Jul 30 13:59:28.105125 2026] [core:notice] [pid 977210:tid 977248] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:28.272947 2026] [core:notice] [pid 977210:tid 977249] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:28.435217 2026] [security2:error] [pid 977210:tid 977346] [client 103.190.40.154:20178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufEPW1Jl2-fgIeVvqR-gAAAIk"]
[Thu Jul 30 13:59:28.435367 2026] [security2:error] [pid 977210:tid 977346] [client 103.190.40.154:20178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufEPW1Jl2-fgIeVvqR-gAAAIk"]
[Thu Jul 30 13:59:29.882111 2026] [core:notice] [pid 977210:tid 977265] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:29.995748 2026] [security2:error] [pid 977210:tid 977392] [client 20.215.191.139:19768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/c/xleet.php"] [unique_id "amufEfW1Jl2-fgIeVvqSHQAAALc"]
[Thu Jul 30 13:59:30.019925 2026] [core:notice] [pid 977210:tid 977270] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:30.046065 2026] [core:notice] [pid 977210:tid 977261] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:30.543920 2026] [core:notice] [pid 977210:tid 977353] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:31.272867 2026] [security2:error] [pid 977210:tid 977378] [client 20.215.191.139:28364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/classwithtostring.php"] [unique_id "amufE_W1Jl2-fgIeVvqSOQAAAKk"]
[Thu Jul 30 13:59:32.051662 2026] [security2:error] [pid 977210:tid 977437] [client 20.215.191.139:27330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/content.php"] [unique_id "amufFPW1Jl2-fgIeVvqSUQAAAOQ"]
[Thu Jul 30 13:59:32.632199 2026] [proxy:error] [pid 977210:tid 977344] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:59:32.632268 2026] [proxy_http:error] [pid 977210:tid 977344] [client 164.92.160.243:48148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:59:32.632860 2026] [proxy:error] [pid 977210:tid 977344] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:59:32.632909 2026] [proxy_http:error] [pid 977210:tid 977344] [client 164.92.160.243:48148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:59:32.771790 2026] [security2:error] [pid 977210:tid 977304] [remote 116.90.32.73:24434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.32.90.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amufFPW1Jl2-fgIeVvqSZAABA1s"]
[Thu Jul 30 13:59:32.897439 2026] [proxy:error] [pid 977210:tid 977343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:59:32.897516 2026] [proxy_http:error] [pid 977210:tid 977343] [client 164.92.160.243:48160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.pvl.djb.temporary.site/
[Thu Jul 30 13:59:32.898179 2026] [proxy:error] [pid 977210:tid 977343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:59:32.898233 2026] [proxy_http:error] [pid 977210:tid 977343] [client 164.92.160.243:48160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.pvl.djb.temporary.site/
[Thu Jul 30 13:59:33.434652 2026] [proxy:error] [pid 977210:tid 977342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:59:33.434707 2026] [proxy_http:error] [pid 977210:tid 977342] [client 164.92.160.243:58386] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:59:33.435386 2026] [proxy:error] [pid 977210:tid 977342] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:59:33.435435 2026] [proxy_http:error] [pid 977210:tid 977342] [client 164.92.160.243:58386] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 13:59:33.497311 2026] [security2:error] [pid 977210:tid 977421] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufFPW1Jl2-fgIeVvqSaAAAANQ"]
[Thu Jul 30 13:59:33.761133 2026] [core:notice] [pid 977210:tid 977390] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:34.482502 2026] [core:error] [pid 977210:tid 977458] [client 74.7.241.175:36318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:59:34.482524 2026] [core:error] [pid 977210:tid 977458] [client 74.7.241.175:36318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 13:59:34.482657 2026] [security2:error] [pid 977210:tid 977458] [client 74.7.241.175:36318] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "bisbeetour.com"] [uri "/index.php"] [unique_id "amufFvW1Jl2-fgIeVvqSjwAAAPk"]
[Thu Jul 30 13:59:35.164253 2026] [security2:error] [pid 977210:tid 977310] [remote 209.42.31.23:53504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.31.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amufFvW1Jl2-fgIeVvqSlwAA3GE"]
[Thu Jul 30 13:59:35.593653 2026] [security2:error] [pid 977210:tid 977315] [remote 57.141.0.13:58766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amufF_W1Jl2-fgIeVvqSpwAA0WY"]
[Thu Jul 30 13:59:35.778059 2026] [security2:error] [pid 977210:tid 977353] [client 185.191.171.12:46798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/12/03/joao-azevedo-diz-que-cenario-das-eleicoes-2020-projeta-pleito-de-2022-e-fala-em-evitar-extremos/"] [unique_id "amufF_W1Jl2-fgIeVvqSrAAAAJA"]
[Thu Jul 30 13:59:35.778191 2026] [security2:error] [pid 977210:tid 977353] [client 185.191.171.12:46798] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/12/03/joao-azevedo-diz-que-cenario-das-eleicoes-2020-projeta-pleito-de-2022-e-fala-em-evitar-extremos/"] [unique_id "amufF_W1Jl2-fgIeVvqSrAAAAJA"]
[Thu Jul 30 13:59:36.141760 2026] [security2:error] [pid 977210:tid 977439] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufF_W1Jl2-fgIeVvqSpgAA5lo"]
[Thu Jul 30 13:59:36.639801 2026] [proxy:error] [pid 977210:tid 977370] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:59:36.639877 2026] [proxy_http:error] [pid 977210:tid 977370] [client 164.92.160.243:58480] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.pvl.djb.temporary.site/
[Thu Jul 30 13:59:36.640475 2026] [proxy:error] [pid 977210:tid 977370] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 13:59:36.640528 2026] [proxy_http:error] [pid 977210:tid 977370] [client 164.92.160.243:58480] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.pvl.djb.temporary.site/
[Thu Jul 30 13:59:37.502790 2026] [security2:error] [pid 977210:tid 977216] [remote 5.161.62.209:60486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.moswey.com"] [uri "/.env"] [unique_id "amufGfW1Jl2-fgIeVvqS3wAAuwM"]
[Thu Jul 30 13:59:37.791615 2026] [security2:error] [pid 977210:tid 977346] [client 20.215.191.139:18585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/doc.php"] [unique_id "amufGfW1Jl2-fgIeVvqS5wAAAIk"]
[Thu Jul 30 13:59:37.899347 2026] [security2:error] [pid 977210:tid 977218] [remote 103.75.185.95:44022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/wp-login.php"] [unique_id "amufGfW1Jl2-fgIeVvqS6AAA5QU"]
[Thu Jul 30 13:59:38.304202 2026] [autoindex:error] [pid 977210:tid 977422] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:59:38.304832 2026] [security2:error] [pid 977210:tid 977422] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufGvW1Jl2-fgIeVvqS9wAAANU"]
[Thu Jul 30 13:59:38.305215 2026] [security2:error] [pid 977210:tid 977397] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/"] [unique_id "amufGvW1Jl2-fgIeVvqS9QAAALw"]
[Thu Jul 30 13:59:38.494828 2026] [security2:error] [pid 977210:tid 977377] [client 20.215.191.139:5993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/dropdown.php"] [unique_id "amufGvW1Jl2-fgIeVvqS-wAAAKg"]
[Thu Jul 30 13:59:38.503990 2026] [security2:error] [pid 977210:tid 977424] [client 103.242.199.184:54104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufGvW1Jl2-fgIeVvqS_AAAANc"]
[Thu Jul 30 13:59:38.504137 2026] [security2:error] [pid 977210:tid 977424] [client 103.242.199.184:54104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufGvW1Jl2-fgIeVvqS_AAAANc"]
[Thu Jul 30 13:59:38.731673 2026] [security2:error] [pid 977210:tid 977360] [client 181.116.200.68:11834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufGvW1Jl2-fgIeVvqTAAAAAJc"]
[Thu Jul 30 13:59:38.731785 2026] [security2:error] [pid 977210:tid 977360] [client 181.116.200.68:11834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufGvW1Jl2-fgIeVvqTAAAAAJc"]
[Thu Jul 30 13:59:38.990080 2026] [autoindex:error] [pid 977210:tid 977364] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:59:38.990760 2026] [security2:error] [pid 977210:tid 977364] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufGvW1Jl2-fgIeVvqTCQAAAJs"]
[Thu Jul 30 13:59:38.991113 2026] [security2:error] [pid 977210:tid 977365] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/css/"] [unique_id "amufGvW1Jl2-fgIeVvqTBwAAAJw"]
[Thu Jul 30 13:59:39.245480 2026] [security2:error] [pid 977210:tid 977358] [client 103.190.40.154:18768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufG_W1Jl2-fgIeVvqTFQAAAJU"]
[Thu Jul 30 13:59:39.245614 2026] [security2:error] [pid 977210:tid 977358] [client 103.190.40.154:18768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufG_W1Jl2-fgIeVvqTFQAAAJU"]
[Thu Jul 30 13:59:39.250116 2026] [security2:error] [pid 977210:tid 977418] [client 20.215.191.139:50989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/ee.php"] [unique_id "amufG_W1Jl2-fgIeVvqTFgAAANE"]
[Thu Jul 30 13:59:39.642405 2026] [autoindex:error] [pid 977210:tid 977380] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:59:39.643052 2026] [security2:error] [pid 977210:tid 977380] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufG_W1Jl2-fgIeVvqTJAAAAKs"]
[Thu Jul 30 13:59:39.643456 2026] [security2:error] [pid 977210:tid 977414] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/ID3/"] [unique_id "amufG_W1Jl2-fgIeVvqTIgAAAM0"]
[Thu Jul 30 13:59:39.994624 2026] [security2:error] [pid 977210:tid 977348] [client 172.237.109.114:33676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/custom-tables/readme.txt"] [unique_id "amufG_W1Jl2-fgIeVvqTKwAAAIs"]
[Thu Jul 30 13:59:40.213587 2026] [autoindex:error] [pid 977210:tid 977344] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:59:40.214300 2026] [security2:error] [pid 977210:tid 977344] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufHPW1Jl2-fgIeVvqTNQAAAIc"]
[Thu Jul 30 13:59:40.214693 2026] [security2:error] [pid 977210:tid 977428] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/IXR/"] [unique_id "amufHPW1Jl2-fgIeVvqTMwAAANs"]
[Thu Jul 30 13:59:40.617848 2026] [security2:error] [pid 977210:tid 977422] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufHPW1Jl2-fgIeVvqTLgAAANU"]
[Thu Jul 30 13:59:40.861189 2026] [autoindex:error] [pid 977210:tid 977393] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:59:40.861824 2026] [security2:error] [pid 977210:tid 977393] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufHPW1Jl2-fgIeVvqTRQAAALg"]
[Thu Jul 30 13:59:40.862176 2026] [security2:error] [pid 977210:tid 977384] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/Requests/"] [unique_id "amufHPW1Jl2-fgIeVvqTQwAAAK8"]
[Thu Jul 30 13:59:41.369735 2026] [security2:error] [pid 977210:tid 977413] [client 20.215.191.139:18619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/flower.php"] [unique_id "amufHfW1Jl2-fgIeVvqTVQAAAMw"]
[Thu Jul 30 13:59:41.456771 2026] [autoindex:error] [pid 977210:tid 977347] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:59:41.457375 2026] [security2:error] [pid 977210:tid 977347] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufHfW1Jl2-fgIeVvqTXwAAAIo"]
[Thu Jul 30 13:59:41.457776 2026] [security2:error] [pid 977210:tid 977402] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/SimplePie/"] [unique_id "amufHfW1Jl2-fgIeVvqTXQAAAME"]
[Thu Jul 30 13:59:42.008933 2026] [autoindex:error] [pid 977210:tid 977423] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:59:42.009683 2026] [security2:error] [pid 977210:tid 977423] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufHfW1Jl2-fgIeVvqTbwAAANY"]
[Thu Jul 30 13:59:42.010157 2026] [security2:error] [pid 977210:tid 977362] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/Text/"] [unique_id "amufHfW1Jl2-fgIeVvqTbQAAAJk"]
[Thu Jul 30 13:59:42.080789 2026] [security2:error] [pid 977210:tid 977375] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufHfW1Jl2-fgIeVvqTYgAAAKY"]
[Thu Jul 30 13:59:43.785130 2026] [security2:error] [pid 977210:tid 977414] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufH_W1Jl2-fgIeVvqTogAAAM0"]
[Thu Jul 30 13:59:43.823889 2026] [core:notice] [pid 977210:tid 977375] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:44.469171 2026] [security2:error] [pid 977210:tid 977364] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufH_W1Jl2-fgIeVvqTtgAAAJs"]
[Thu Jul 30 13:59:44.825375 2026] [security2:error] [pid 977210:tid 977360] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufH_W1Jl2-fgIeVvqTrwAAAJc"]
[Thu Jul 30 13:59:44.825407 2026] [security2:error] [pid 977210:tid 977360] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufH_W1Jl2-fgIeVvqTrwAAAJc"]
[Thu Jul 30 13:59:44.825710 2026] [security2:error] [pid 977210:tid 977368] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-content/mu-plugins-old/"] [unique_id "amufH_W1Jl2-fgIeVvqTrQAAAJ8"]
[Thu Jul 30 13:59:45.798601 2026] [security2:error] [pid 977210:tid 977388] [client 20.215.191.139:18668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/gecko-new.php"] [unique_id "amufIfW1Jl2-fgIeVvqT6gAAALM"]
[Thu Jul 30 13:59:46.362930 2026] [security2:error] [pid 977210:tid 977456] [client 2a03:2880:f800:46:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufIfW1Jl2-fgIeVvqT2QAA91o"]
[Thu Jul 30 13:59:46.379319 2026] [security2:error] [pid 977210:tid 977379] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufIvW1Jl2-fgIeVvqT9wAAAKo"]
[Thu Jul 30 13:59:46.379381 2026] [security2:error] [pid 977210:tid 977379] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufIvW1Jl2-fgIeVvqT9wAAAKo"]
[Thu Jul 30 13:59:46.379669 2026] [security2:error] [pid 977210:tid 977433] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-content/themes/classic/inc/"] [unique_id "amufIvW1Jl2-fgIeVvqT9QAAAOA"]
[Thu Jul 30 13:59:46.443149 2026] [core:notice] [pid 977210:tid 977419] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:46.514406 2026] [security2:error] [pid 977210:tid 977446] [client 20.215.191.139:5435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/m.php"] [unique_id "amufIvW1Jl2-fgIeVvqUAAAAAO0"]
[Thu Jul 30 13:59:46.690568 2026] [core:notice] [pid 977210:tid 977369] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:46.772533 2026] [security2:error] [pid 977210:tid 977381] [client 20.203.148.31:44015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/011i.php"] [unique_id "amufIvW1Jl2-fgIeVvqUCwAAAKw"]
[Thu Jul 30 13:59:47.398108 2026] [security2:error] [pid 977210:tid 977365] [client 20.203.148.31:46117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/03a005685d.php"] [unique_id "amufI_W1Jl2-fgIeVvqUGgAAAJw"]
[Thu Jul 30 13:59:47.838419 2026] [security2:error] [pid 977210:tid 977231] [remote 57.141.0.14:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/94764231632/feed/rss2/"] [unique_id "amufI_W1Jl2-fgIeVvqUJQAA5RI"]
[Thu Jul 30 13:59:48.565822 2026] [security2:error] [pid 977210:tid 977359] [client 20.203.148.31:44004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/403.php"] [unique_id "amufJPW1Jl2-fgIeVvqUQwAAAJY"]
[Thu Jul 30 13:59:48.631278 2026] [security2:error] [pid 977210:tid 977239] [remote 74.7.243.224:54576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/login.php"] [unique_id "amufJPW1Jl2-fgIeVvqURgAA9Ro"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/img/main_image_6a3229a631e84.jpg
[Thu Jul 30 13:59:49.243952 2026] [security2:error] [pid 977210:tid 977372] [client 103.242.199.184:54656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufJfW1Jl2-fgIeVvqUXQAAAKM"]
[Thu Jul 30 13:59:49.244095 2026] [security2:error] [pid 977210:tid 977372] [client 103.242.199.184:54656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufJfW1Jl2-fgIeVvqUXQAAAKM"]
[Thu Jul 30 13:59:49.284633 2026] [security2:error] [pid 977210:tid 977344] [client 181.116.200.68:12289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufJfW1Jl2-fgIeVvqUXwAAAIc"]
[Thu Jul 30 13:59:49.284733 2026] [security2:error] [pid 977210:tid 977344] [client 181.116.200.68:12289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufJfW1Jl2-fgIeVvqUXwAAAIc"]
[Thu Jul 30 13:59:49.376944 2026] [security2:error] [pid 977210:tid 977388] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufJfW1Jl2-fgIeVvqUXAAAALM"]
[Thu Jul 30 13:59:49.376971 2026] [security2:error] [pid 977210:tid 977388] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufJfW1Jl2-fgIeVvqUXAAAALM"]
[Thu Jul 30 13:59:49.377337 2026] [security2:error] [pid 977210:tid 977449] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "amufJfW1Jl2-fgIeVvqUWgAAAPA"]
[Thu Jul 30 13:59:49.890286 2026] [security2:error] [pid 977210:tid 977400] [client 103.190.40.154:19227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufJfW1Jl2-fgIeVvqUdwAAAL8"]
[Thu Jul 30 13:59:49.890479 2026] [security2:error] [pid 977210:tid 977400] [client 103.190.40.154:19227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufJfW1Jl2-fgIeVvqUdwAAAL8"]
[Thu Jul 30 13:59:49.931016 2026] [security2:error] [pid 977210:tid 977431] [client 20.203.148.31:47441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/404.php"] [unique_id "amufJfW1Jl2-fgIeVvqUeAAAAN4"]
[Thu Jul 30 13:59:50.100398 2026] [security2:error] [pid 977210:tid 977404] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufJfW1Jl2-fgIeVvqUbAAAAMM"]
[Thu Jul 30 13:59:50.376857 2026] [autoindex:error] [pid 977210:tid 977416] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 13:59:50.377569 2026] [security2:error] [pid 977210:tid 977416] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufJvW1Jl2-fgIeVvqUhQAAAM8"]
[Thu Jul 30 13:59:50.378000 2026] [security2:error] [pid 977210:tid 977435] [client 82.102.18.180:37616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-content/mu-plugins/"] [unique_id "amufJvW1Jl2-fgIeVvqUgwAAAOI"]
[Thu Jul 30 13:59:51.324024 2026] [security2:error] [pid 977210:tid 977423] [client 20.203.148.31:37475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/aa.php"] [unique_id "amufJ_W1Jl2-fgIeVvqUnwAAANY"]
[Thu Jul 30 13:59:51.655847 2026] [security2:error] [pid 977210:tid 977459] [client 20.215.191.139:21317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amufJ_W1Jl2-fgIeVvqUqAAAAPo"]
[Thu Jul 30 13:59:52.479186 2026] [security2:error] [pid 977210:tid 977433] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufJ_W1Jl2-fgIeVvqUtgAAAOA"]
[Thu Jul 30 13:59:53.015743 2026] [security2:error] [pid 977210:tid 977286] [remote 57.141.0.23:35828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/610298834/feed/rss2/"] [unique_id "amufKPW1Jl2-fgIeVvqUxAAAnkk"]
[Thu Jul 30 13:59:53.064952 2026] [security2:error] [pid 977210:tid 977353] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufKPW1Jl2-fgIeVvqUvQAAkE8"]
[Thu Jul 30 13:59:53.300534 2026] [security2:error] [pid 977210:tid 977349] [client 20.203.148.31:37485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/aafewc0k.php"] [unique_id "amufKfW1Jl2-fgIeVvqU1gAAAIw"]
[Thu Jul 30 13:59:53.404952 2026] [security2:error] [pid 977210:tid 977347] [client 20.215.191.139:21313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mah/flower.php"] [unique_id "amufKfW1Jl2-fgIeVvqU2gAAAIo"]
[Thu Jul 30 13:59:54.355818 2026] [security2:error] [pid 977210:tid 977408] [client 20.215.191.139:5355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mah/xleet.php"] [unique_id "amufKvW1Jl2-fgIeVvqU8wAAAMc"]
[Thu Jul 30 13:59:54.632581 2026] [security2:error] [pid 977210:tid 977332] [remote 57.141.0.1:37084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amufKvW1Jl2-fgIeVvqU_QAA1Xc"]
[Thu Jul 30 13:59:55.301700 2026] [security2:error] [pid 977210:tid 977383] [client 20.203.148.31:45261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/abcd.php"] [unique_id "amufK_W1Jl2-fgIeVvqVEgAAAK4"]
[Thu Jul 30 13:59:56.721393 2026] [core:notice] [pid 977210:tid 977224] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:56.746046 2026] [security2:error] [pid 977210:tid 977461] [client 20.203.148.31:50829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/about.php"] [unique_id "amufLPW1Jl2-fgIeVvqVNwAAAPw"]
[Thu Jul 30 13:59:56.857990 2026] [security2:error] [pid 977210:tid 977338] [remote 5.161.62.209:12126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mty.djb.temporary.site"] [uri "/.env"] [unique_id "amufLPW1Jl2-fgIeVvqVOAAA1X0"]
[Thu Jul 30 13:59:57.822588 2026] [security2:error] [pid 977210:tid 977428] [client 20.215.191.139:28448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mini.php"] [unique_id "amufLfW1Jl2-fgIeVvqVUAAAANs"]
[Thu Jul 30 13:59:59.042232 2026] [core:notice] [pid 977210:tid 977409] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:59.406739 2026] [core:notice] [pid 977210:tid 977411] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:59.498394 2026] [security2:error] [pid 977210:tid 977345] [client 20.203.148.31:44724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/admin.php"] [unique_id "amufL_W1Jl2-fgIeVvqVcgAAAIg"]
[Thu Jul 30 13:59:59.733408 2026] [core:notice] [pid 977210:tid 977343] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 13:59:59.743091 2026] [security2:error] [pid 977210:tid 977416] [client 103.242.199.184:55202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufL_W1Jl2-fgIeVvqVegAAAM8"]
[Thu Jul 30 13:59:59.743174 2026] [security2:error] [pid 977210:tid 977416] [client 103.242.199.184:55202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufL_W1Jl2-fgIeVvqVegAAAM8"]
[Thu Jul 30 13:59:59.820831 2026] [security2:error] [pid 977210:tid 977430] [client 20.215.191.139:28464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/moon.php"] [unique_id "amufL_W1Jl2-fgIeVvqVfgAAAN0"]
[Thu Jul 30 13:59:59.967775 2026] [security2:error] [pid 977210:tid 977431] [client 181.116.200.68:29724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufL_W1Jl2-fgIeVvqVfwAAAN4"]
[Thu Jul 30 13:59:59.967887 2026] [security2:error] [pid 977210:tid 977431] [client 181.116.200.68:29724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufL_W1Jl2-fgIeVvqVfwAAAN4"]
[Thu Jul 30 14:00:00.179282 2026] [security2:error] [pid 977210:tid 977392] [client 103.231.91.59:48990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amufMPW1Jl2-fgIeVvqVhAAAALc"]
[Thu Jul 30 14:00:00.179364 2026] [security2:error] [pid 977210:tid 977392] [client 103.231.91.59:48990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amufMPW1Jl2-fgIeVvqVhAAAALc"]
[Thu Jul 30 14:00:00.590665 2026] [security2:error] [pid 977210:tid 977457] [client 103.190.40.154:18791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufMPW1Jl2-fgIeVvqVjQAAAPg"]
[Thu Jul 30 14:00:00.590794 2026] [security2:error] [pid 977210:tid 977457] [client 103.190.40.154:18791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufMPW1Jl2-fgIeVvqVjQAAAPg"]
[Thu Jul 30 14:00:00.808836 2026] [security2:error] [pid 977210:tid 977423] [client 20.203.148.31:44209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/adminfuns.php"] [unique_id "amufMPW1Jl2-fgIeVvqVlAAAANY"]
[Thu Jul 30 14:00:01.093192 2026] [security2:error] [pid 977210:tid 977466] [client 20.104.16.169:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/classwithtostring.php"] [unique_id "amufMfW1Jl2-fgIeVvqVmAAAAQE"]
[Thu Jul 30 14:00:01.116174 2026] [security2:error] [pid 977210:tid 977439] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amufMPW1Jl2-fgIeVvqVjAAA5ic"]
[Thu Jul 30 14:00:01.693098 2026] [security2:error] [pid 977210:tid 977451] [client 20.104.16.169:35700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/css/index.php"] [unique_id "amufMfW1Jl2-fgIeVvqVpgAAAPI"]
[Thu Jul 30 14:00:02.290527 2026] [security2:error] [pid 977210:tid 977347] [client 20.104.16.169:35689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/error.php"] [unique_id "amufMvW1Jl2-fgIeVvqVuQAAAIo"]
[Thu Jul 30 14:00:02.458565 2026] [security2:error] [pid 977210:tid 977380] [client 74.7.230.12:42476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.avalonoilandgas.us.cc.ghj.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amufMvW1Jl2-fgIeVvqVwQAAAKs"]
[Thu Jul 30 14:00:02.857648 2026] [security2:error] [pid 977210:tid 977350] [client 20.215.191.139:5678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/new.php"] [unique_id "amufMvW1Jl2-fgIeVvqVywAAAI0"]
[Thu Jul 30 14:00:02.917095 2026] [security2:error] [pid 977210:tid 977468] [client 20.104.16.169:35667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/k.php"] [unique_id "amufMvW1Jl2-fgIeVvqVzQAAAQM"]
[Thu Jul 30 14:00:03.060457 2026] [security2:error] [pid 977210:tid 977378] [client 220.181.108.82:46570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/ELPER-Tech/issue/archive"] [unique_id "amufM_W1Jl2-fgIeVvqV0gAAAKk"]
[Thu Jul 30 14:00:03.524591 2026] [security2:error] [pid 977210:tid 977413] [client 20.104.16.169:20497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/lock.php"] [unique_id "amufM_W1Jl2-fgIeVvqV4AAAAMw"]
[Thu Jul 30 14:00:03.590416 2026] [security2:error] [pid 977210:tid 977465] [client 20.215.191.139:20024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/radio.php"] [unique_id "amufM_W1Jl2-fgIeVvqV4QAAAQA"]
[Thu Jul 30 14:00:03.736040 2026] [security2:error] [pid 977210:tid 977345] [client 119.249.100.44:44003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/ELPER-Tech/issue/archive"] [unique_id "amufM_W1Jl2-fgIeVvqV3gAAAIg"]
[Thu Jul 30 14:00:03.840447 2026] [security2:error] [pid 977210:tid 977360] [client 189.6.88.213:52823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufM_W1Jl2-fgIeVvqV6AAAAJc"]
[Thu Jul 30 14:00:03.840557 2026] [security2:error] [pid 977210:tid 977360] [client 189.6.88.213:52823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufM_W1Jl2-fgIeVvqV6AAAAJc"]
[Thu Jul 30 14:00:03.896474 2026] [security2:error] [pid 977210:tid 977458] [client 74.7.241.184:55340] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pkfye.ye"] [uri "/cgi-sys/404.html"] [unique_id "amufM_W1Jl2-fgIeVvqV6wAA-SU"]
[Thu Jul 30 14:00:04.047122 2026] [security2:error] [pid 977210:tid 977451] [client 20.203.148.31:48158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/albin.php"] [unique_id "amufNPW1Jl2-fgIeVvqV8AAAAPI"]
[Thu Jul 30 14:00:04.168671 2026] [security2:error] [pid 977210:tid 977452] [client 20.104.16.169:35703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/lock360.php"] [unique_id "amufNPW1Jl2-fgIeVvqV8QAAAPM"]
[Thu Jul 30 14:00:04.653242 2026] [core:notice] [pid 977210:tid 977365] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:04.759477 2026] [security2:error] [pid 977210:tid 977444] [client 20.215.191.139:19725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/s.php"] [unique_id "amufNPW1Jl2-fgIeVvqV_AAAAOs"]
[Thu Jul 30 14:00:04.777222 2026] [security2:error] [pid 977210:tid 977351] [client 20.104.16.169:35705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/php.php"] [unique_id "amufNPW1Jl2-fgIeVvqV_QAAAI4"]
[Thu Jul 30 14:00:05.376639 2026] [security2:error] [pid 977210:tid 977378] [client 20.104.16.169:35691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/php8.php"] [unique_id "amufNfW1Jl2-fgIeVvqWEwAAAKk"]
[Thu Jul 30 14:00:05.601665 2026] [core:notice] [pid 977210:tid 977404] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:05.613888 2026] [security2:error] [pid 977210:tid 977436] [client 20.203.148.31:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/amfsqvgv.php"] [unique_id "amufNfW1Jl2-fgIeVvqWHgAAAOM"]
[Thu Jul 30 14:00:05.991683 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.16.169:20509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-admin/maint/index.php"] [unique_id "amufNfW1Jl2-fgIeVvqWJQAAAIY"]
[Thu Jul 30 14:00:06.054697 2026] [security2:error] [pid 977210:tid 977355] [client 20.215.191.139:20031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/sim.php"] [unique_id "amufNvW1Jl2-fgIeVvqWJgAAAJI"]
[Thu Jul 30 14:00:06.622885 2026] [security2:error] [pid 977210:tid 977424] [client 20.104.16.169:35677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-config-sample.php"] [unique_id "amufNvW1Jl2-fgIeVvqWNgAAANc"]
[Thu Jul 30 14:00:07.032226 2026] [security2:error] [pid 977210:tid 977380] [client 20.215.191.139:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/text.php"] [unique_id "amufN_W1Jl2-fgIeVvqWQgAAAKs"]
[Thu Jul 30 14:00:07.221699 2026] [security2:error] [pid 977210:tid 977421] [client 20.104.16.169:20526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/themes/index.php"] [unique_id "amufN_W1Jl2-fgIeVvqWQwAAANQ"]
[Thu Jul 30 14:00:07.606359 2026] [core:error] [pid 977210:tid 977329] (36)File name too long: [remote 104.194.200.177:42594] AH00036: access to /&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;39&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N/A&quot;,&quot;display_price&quot;:129,&quot;display_regular_price&quot;:129,&quot;image&quot;:{&quot;title&quot;:&quot;image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp&quot;,&quot;caption&quot;:&quot;&quot;,&quot;url&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/05/image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp&quot;,&quot;alt&quot;:&quot;image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp&quot;,&quot;src&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/05/image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp&quot;,&quot;srcset&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/05/image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;39&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N'), referer: https://kicksity.com/product/louis-vuitton-slides-white/
[Thu Jul 30 14:00:07.851665 2026] [security2:error] [pid 977210:tid 977391] [client 20.104.16.169:20534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "amufN_W1Jl2-fgIeVvqWVAAAALY"]
[Thu Jul 30 14:00:08.464648 2026] [security2:error] [pid 977210:tid 977383] [client 20.104.16.169:35674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wk/index.php"] [unique_id "amufOPW1Jl2-fgIeVvqWYAAAAK4"]
[Thu Jul 30 14:00:08.511685 2026] [core:notice] [pid 977210:tid 977440] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:08.863805 2026] [core:notice] [pid 977210:tid 977361] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:08.985321 2026] [security2:error] [pid 977210:tid 977372] [client 182.180.11.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amufOPW1Jl2-fgIeVvqWbgAAAKM"], referer: https://cnpinyin.com
[Thu Jul 30 14:00:09.072593 2026] [security2:error] [pid 977210:tid 977449] [client 20.104.16.169:35695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-mail.php"] [unique_id "amufOfW1Jl2-fgIeVvqWdQAAAPA"]
[Thu Jul 30 14:00:09.078731 2026] [security2:error] [pid 977210:tid 977351] [client 172.237.109.114:17083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-admin/admin-post.php"] [unique_id "amufOfW1Jl2-fgIeVvqWdgAAAI4"]
[Thu Jul 30 14:00:09.355600 2026] [core:notice] [pid 977210:tid 977334] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:09.499086 2026] [security2:error] [pid 977210:tid 977439] [client 20.215.191.139:23822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/user.php"] [unique_id "amufOfW1Jl2-fgIeVvqWgAAAAOY"]
[Thu Jul 30 14:00:09.675902 2026] [security2:error] [pid 977210:tid 977425] [client 20.104.16.169:20503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp.php"] [unique_id "amufOfW1Jl2-fgIeVvqWhwAAANg"]
[Thu Jul 30 14:00:09.750601 2026] [security2:error] [pid 977210:tid 977429] [client 172.237.109.114:41054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amufOfW1Jl2-fgIeVvqWegAAANw"]
[Thu Jul 30 14:00:09.887762 2026] [core:notice] [pid 977210:tid 977216] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:10.153348 2026] [core:notice] [pid 977210:tid 977214] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:10.277578 2026] [security2:error] [pid 977210:tid 977359] [client 20.104.16.169:20538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/css.php"] [unique_id "amufOvW1Jl2-fgIeVvqWmQAAAJY"]
[Thu Jul 30 14:00:10.355330 2026] [security2:error] [pid 977210:tid 977383] [client 103.242.199.184:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufOvW1Jl2-fgIeVvqWnQAAAK4"]
[Thu Jul 30 14:00:10.355449 2026] [security2:error] [pid 977210:tid 977383] [client 103.242.199.184:55752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufOvW1Jl2-fgIeVvqWnQAAAK4"]
[Thu Jul 30 14:00:10.534893 2026] [security2:error] [pid 977210:tid 977467] [client 181.116.200.68:38314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufOvW1Jl2-fgIeVvqWngAAAQI"]
[Thu Jul 30 14:00:10.535045 2026] [security2:error] [pid 977210:tid 977467] [client 181.116.200.68:38314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufOvW1Jl2-fgIeVvqWngAAAQI"]
[Thu Jul 30 14:00:10.540810 2026] [security2:error] [pid 977210:tid 977409] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufOfW1Jl2-fgIeVvqWjwAAAMg"]
[Thu Jul 30 14:00:10.830312 2026] [security2:error] [pid 977210:tid 977375] [client 20.215.191.139:5883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/webadmin.php"] [unique_id "amufOvW1Jl2-fgIeVvqWqQAAAKY"]
[Thu Jul 30 14:00:10.898253 2026] [security2:error] [pid 977210:tid 977447] [client 20.104.16.169:35710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/files.php"] [unique_id "amufOvW1Jl2-fgIeVvqWrQAAAO4"]
[Thu Jul 30 14:00:11.140459 2026] [security2:error] [pid 977210:tid 977368] [client 20.203.148.31:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/ant.php"] [unique_id "amufO_W1Jl2-fgIeVvqWsAAAAJ8"]
[Thu Jul 30 14:00:11.261875 2026] [security2:error] [pid 977210:tid 977446] [client 103.190.40.154:5559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufO_W1Jl2-fgIeVvqWtAAAAO0"]
[Thu Jul 30 14:00:11.262030 2026] [security2:error] [pid 977210:tid 977446] [client 103.190.40.154:5559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufO_W1Jl2-fgIeVvqWtAAAAO0"]
[Thu Jul 30 14:00:11.298615 2026] [security2:error] [pid 977210:tid 977226] [remote 5.161.62.209:35188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.myabudhabidesertsafari.com"] [uri "/.env"] [unique_id "amufO_W1Jl2-fgIeVvqWuAAAmg0"]
[Thu Jul 30 14:00:11.458060 2026] [core:notice] [pid 977210:tid 977353] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:11.529371 2026] [security2:error] [pid 977210:tid 977378] [client 20.104.16.169:20530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/index/function.php"] [unique_id "amufO_W1Jl2-fgIeVvqWwQAAAKk"]
[Thu Jul 30 14:00:11.573700 2026] [security2:error] [pid 977210:tid 977466] [client 172.237.109.114:24848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amufO_W1Jl2-fgIeVvqWrwAAAQE"]
[Thu Jul 30 14:00:12.016569 2026] [security2:error] [pid 977210:tid 977462] [client 20.203.148.31:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/appreciators.php"] [unique_id "amufPPW1Jl2-fgIeVvqWzQAAAP0"]
[Thu Jul 30 14:00:12.125679 2026] [security2:error] [pid 977210:tid 977428] [client 20.104.16.169:35654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/buy.php"] [unique_id "amufPPW1Jl2-fgIeVvqW0QAAANs"]
[Thu Jul 30 14:00:12.151951 2026] [security2:error] [pid 977210:tid 977430] [client 20.215.191.139:23855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amufPPW1Jl2-fgIeVvqW0gAAAN0"]
[Thu Jul 30 14:00:12.551152 2026] [security2:error] [pid 977210:tid 977396] [client 20.203.148.31:37450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/archive.php"] [unique_id "amufPPW1Jl2-fgIeVvqW3gAAALs"]
[Thu Jul 30 14:00:12.564598 2026] [security2:error] [pid 977210:tid 977453] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufO_W1Jl2-fgIeVvqWzAAA9BE"]
[Thu Jul 30 14:00:12.728266 2026] [security2:error] [pid 977210:tid 977380] [client 20.104.16.169:20490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/info.php"] [unique_id "amufPPW1Jl2-fgIeVvqW4AAAAKs"]
[Thu Jul 30 14:00:12.824180 2026] [security2:error] [pid 977210:tid 977382] [client 20.215.191.139:25217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amufPPW1Jl2-fgIeVvqW5wAAAK0"]
[Thu Jul 30 14:00:13.324988 2026] [security2:error] [pid 977210:tid 977443] [client 20.104.16.169:20537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp.php"] [unique_id "amufPfW1Jl2-fgIeVvqW8gAAAOo"]
[Thu Jul 30 14:00:13.408406 2026] [security2:error] [pid 977210:tid 977378] [client 20.203.148.31:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/as.php"] [unique_id "amufPfW1Jl2-fgIeVvqW8wAAAKk"]
[Thu Jul 30 14:00:13.669641 2026] [security2:error] [pid 977210:tid 977458] [client 20.215.191.139:23813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amufPfW1Jl2-fgIeVvqW9wAAAPk"]
[Thu Jul 30 14:00:13.949260 2026] [security2:error] [pid 977210:tid 977346] [client 20.104.16.169:21057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/uploads/index.php"] [unique_id "amufPfW1Jl2-fgIeVvqW_wAAAIk"]
[Thu Jul 30 14:00:14.152182 2026] [security2:error] [pid 977210:tid 977255] [remote 57.141.0.65:39904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amufPvW1Jl2-fgIeVvqXAQAAqCo"]
[Thu Jul 30 14:00:14.314213 2026] [security2:error] [pid 977210:tid 977401] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufPfW1Jl2-fgIeVvqW-AAAwCc"]
[Thu Jul 30 14:00:14.407137 2026] [security2:error] [pid 977210:tid 977362] [client 20.215.191.139:5823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amufPvW1Jl2-fgIeVvqXEQAAAJk"]
[Thu Jul 30 14:00:14.427370 2026] [security2:error] [pid 977210:tid 977270] [remote 47.128.98.102:15926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/al-seer-marine-lists-shares-on-abu-dhabi-securities-exchange/"] [unique_id "amufPvW1Jl2-fgIeVvqXEgAAyTk"]
[Thu Jul 30 14:00:14.562082 2026] [security2:error] [pid 977210:tid 977400] [client 20.104.16.169:35671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-config-sample.php"] [unique_id "amufPvW1Jl2-fgIeVvqXFgAAAL8"]
[Thu Jul 30 14:00:14.806317 2026] [core:notice] [pid 977210:tid 977387] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:14.941525 2026] [security2:error] [pid 977210:tid 977364] [client 20.215.191.139:18464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amufPvW1Jl2-fgIeVvqXJAAAAJs"]
[Thu Jul 30 14:00:15.202368 2026] [security2:error] [pid 977210:tid 977371] [client 20.104.16.169:20930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/themes/x/bypass.php"] [unique_id "amufP_W1Jl2-fgIeVvqXKwAAAKI"]
[Thu Jul 30 14:00:15.818512 2026] [security2:error] [pid 977210:tid 977424] [client 20.104.16.169:35648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/666.php"] [unique_id "amufP_W1Jl2-fgIeVvqXOQAAANc"]
[Thu Jul 30 14:00:16.366938 2026] [security2:error] [pid 977210:tid 977363] [client 43.130.32.245:60296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.32.130.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/article.php"] [unique_id "amufQPW1Jl2-fgIeVvqXSAAAAJo"]
[Thu Jul 30 14:00:16.458456 2026] [security2:error] [pid 977210:tid 977368] [client 20.104.16.169:35653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/bgymj.php"] [unique_id "amufQPW1Jl2-fgIeVvqXTQAAAJ8"]
[Thu Jul 30 14:00:17.086439 2026] [security2:error] [pid 977210:tid 977367] [client 20.104.16.169:20977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/control.php"] [unique_id "amufQfW1Jl2-fgIeVvqXXwAAAJ4"]
[Thu Jul 30 14:00:17.346061 2026] [security2:error] [pid 977210:tid 977430] [client 20.203.148.31:47439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/atomlib.php"] [unique_id "amufQfW1Jl2-fgIeVvqXYwAAAN0"]
[Thu Jul 30 14:00:17.660790 2026] [security2:error] [pid 977210:tid 977392] [client 50.6.43.217:58650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amufMvW1Jl2-fgIeVvqVswAAALc"]
[Thu Jul 30 14:00:17.710596 2026] [security2:error] [pid 977210:tid 977441] [client 20.104.16.169:35687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/plugins/admin.php"] [unique_id "amufQfW1Jl2-fgIeVvqXbgAAAOg"]
[Thu Jul 30 14:00:18.318188 2026] [security2:error] [pid 977210:tid 977440] [client 20.104.16.169:20541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/adminfuns.php"] [unique_id "amufQvW1Jl2-fgIeVvqXeAAAAOc"]
[Thu Jul 30 14:00:18.981027 2026] [security2:error] [pid 977210:tid 977465] [client 20.104.16.169:20529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/admin.php"] [unique_id "amufQvW1Jl2-fgIeVvqXjAAAAQA"]
[Thu Jul 30 14:00:19.551218 2026] [autoindex:error] [pid 977210:tid 977356] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:00:19.551833 2026] [security2:error] [pid 977210:tid 977356] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufQ_W1Jl2-fgIeVvqXlgAAAJM"]
[Thu Jul 30 14:00:19.552201 2026] [security2:error] [pid 977210:tid 977424] [client 82.102.18.180:50344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "amufQ_W1Jl2-fgIeVvqXlAAAANc"]
[Thu Jul 30 14:00:19.577896 2026] [security2:error] [pid 977210:tid 977437] [client 20.104.16.169:35670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/php8.php"] [unique_id "amufQ_W1Jl2-fgIeVvqXmgAAAOQ"]
[Thu Jul 30 14:00:20.338002 2026] [security2:error] [pid 977210:tid 977469] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/wp-includes/blocks/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXtAAAAQQ"]
[Thu Jul 30 14:00:20.338467 2026] [security2:error] [pid 977210:tid 977402] [client 82.102.18.180:50344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/wp-includes/blocks/"] [unique_id "amufRPW1Jl2-fgIeVvqXsgAAAME"]
[Thu Jul 30 14:00:20.401151 2026] [security2:error] [pid 977210:tid 977355] [client 20.104.16.169:21065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-mail.php"] [unique_id "amufRPW1Jl2-fgIeVvqXtQAAAJI"]
[Thu Jul 30 14:00:20.957077 2026] [security2:error] [pid 977210:tid 977364] [client 103.242.199.184:56307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufRPW1Jl2-fgIeVvqXxQAAAJs"]
[Thu Jul 30 14:00:20.957199 2026] [security2:error] [pid 977210:tid 977364] [client 103.242.199.184:56307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufRPW1Jl2-fgIeVvqXxQAAAJs"]
[Thu Jul 30 14:00:20.962847 2026] [autoindex:error] [pid 977210:tid 977351] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:00:20.963506 2026] [security2:error] [pid 977210:tid 977351] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufRPW1Jl2-fgIeVvqXxAAAAI4"]
[Thu Jul 30 14:00:20.963874 2026] [security2:error] [pid 977210:tid 977449] [client 82.102.18.180:50344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/certificates/"] [unique_id "amufRPW1Jl2-fgIeVvqXwgAAAPA"]
[Thu Jul 30 14:00:21.004244 2026] [security2:error] [pid 977210:tid 977356] [client 20.104.16.169:35704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/a7.php"] [unique_id "amufRfW1Jl2-fgIeVvqX0gAAAJM"]
[Thu Jul 30 14:00:21.142765 2026] [security2:error] [pid 977210:tid 977346] [client 181.116.200.68:21548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufRfW1Jl2-fgIeVvqX3wAAAIk"]
[Thu Jul 30 14:00:21.142879 2026] [security2:error] [pid 977210:tid 977346] [client 181.116.200.68:21548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufRfW1Jl2-fgIeVvqX3wAAAIk"]
[Thu Jul 30 14:00:21.611626 2026] [security2:error] [pid 977210:tid 977399] [client 20.104.16.169:35701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/php.php"] [unique_id "amufRfW1Jl2-fgIeVvqX7wAAAL4"]
[Thu Jul 30 14:00:21.634157 2026] [autoindex:error] [pid 977210:tid 977376] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:00:21.634772 2026] [security2:error] [pid 977210:tid 977376] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufRfW1Jl2-fgIeVvqX8gAAAKc"]
[Thu Jul 30 14:00:21.635246 2026] [security2:error] [pid 977210:tid 977455] [client 82.102.18.180:50344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/customize/"] [unique_id "amufRfW1Jl2-fgIeVvqX8AAAAPY"]
[Thu Jul 30 14:00:21.964433 2026] [security2:error] [pid 977210:tid 977381] [client 103.190.40.154:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufRfW1Jl2-fgIeVvqX-AAAAKw"]
[Thu Jul 30 14:00:21.964601 2026] [security2:error] [pid 977210:tid 977381] [client 103.190.40.154:21795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufRfW1Jl2-fgIeVvqX-AAAAKw"]
[Thu Jul 30 14:00:22.207201 2026] [security2:error] [pid 977210:tid 977371] [client 20.104.16.169:35659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/8.php"] [unique_id "amufRvW1Jl2-fgIeVvqYAAAAAKI"]
[Thu Jul 30 14:00:22.423421 2026] [security2:error] [pid 977210:tid 977410] [client 20.215.191.139:21335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amufRvW1Jl2-fgIeVvqYBQAAAMk"]
[Thu Jul 30 14:00:22.776074 2026] [proxy:error] [pid 977210:tid 977433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:00:22.776144 2026] [proxy_http:error] [pid 977210:tid 977433] [client 3.225.222.228:10598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:00:22.776814 2026] [proxy:error] [pid 977210:tid 977433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:00:22.776860 2026] [proxy_http:error] [pid 977210:tid 977433] [client 3.225.222.228:10598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:00:22.820724 2026] [proxy:error] [pid 977210:tid 977400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:00:22.820817 2026] [proxy_http:error] [pid 977210:tid 977400] [client 52.4.19.39:41695] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:00:22.821667 2026] [proxy:error] [pid 977210:tid 977400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:00:22.821738 2026] [proxy_http:error] [pid 977210:tid 977400] [client 52.4.19.39:41695] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:00:22.847746 2026] [autoindex:error] [pid 977210:tid 977443] [client 20.104.16.169:21088] AH01276: Cannot serve directory /home1/ssadjbte/public_html/deltaedu.net/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:00:23.129743 2026] [security2:error] [pid 977210:tid 977353] [client 20.104.16.169:21088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deltaedu.net"] [uri "/index.php"] [unique_id "amufR_W1Jl2-fgIeVvqYGgAAAJA"]
[Thu Jul 30 14:00:23.327709 2026] [security2:error] [pid 977210:tid 977360] [client 20.104.16.169:21088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amufR_W1Jl2-fgIeVvqYJwAAAJc"]
[Thu Jul 30 14:00:23.332539 2026] [security2:error] [pid 977210:tid 977454] [client 20.203.148.31:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/autoload_classmap.php"] [unique_id "amufR_W1Jl2-fgIeVvqYKAAAAPU"]
[Thu Jul 30 14:00:23.719934 2026] [security2:error] [pid 977210:tid 977416] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufR_W1Jl2-fgIeVvqYGwAAz3c"]
[Thu Jul 30 14:00:23.856534 2026] [security2:error] [pid 977210:tid 977447] [client 20.215.191.139:37157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amufR_W1Jl2-fgIeVvqYOgAAAO4"]
[Thu Jul 30 14:00:24.061906 2026] [security2:error] [pid 977210:tid 977396] [client 20.104.16.169:20954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-includes/assets/ty.php"] [unique_id "amufSPW1Jl2-fgIeVvqYPAAAALs"]
[Thu Jul 30 14:00:24.129969 2026] [security2:error] [pid 977210:tid 977367] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufR_W1Jl2-fgIeVvqYLAAAAJ4"]
[Thu Jul 30 14:00:24.726638 2026] [security2:error] [pid 977210:tid 977435] [client 20.104.16.169:21072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/file61.php"] [unique_id "amufSPW1Jl2-fgIeVvqYSAAAAOI"]
[Thu Jul 30 14:00:24.795847 2026] [security2:error] [pid 977210:tid 977399] [client 189.6.88.213:53936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufSPW1Jl2-fgIeVvqYTQAAAL4"]
[Thu Jul 30 14:00:24.795945 2026] [security2:error] [pid 977210:tid 977399] [client 189.6.88.213:53936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufSPW1Jl2-fgIeVvqYTQAAAL4"]
[Thu Jul 30 14:00:24.962969 2026] [security2:error] [pid 977210:tid 977214] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/pki-validation/afnew.php"] [unique_id "amufSPW1Jl2-fgIeVvqYWgAA2gE"]
[Thu Jul 30 14:00:25.030695 2026] [security2:error] [pid 977210:tid 977390] [client 187.52.21.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amufSPW1Jl2-fgIeVvqYWQAAALU"], referer: https://cnpinyin.com
[Thu Jul 30 14:00:25.351447 2026] [security2:error] [pid 977210:tid 977449] [client 20.104.16.169:20488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/p.php"] [unique_id "amufSfW1Jl2-fgIeVvqYZQAAAPA"]
[Thu Jul 30 14:00:25.430188 2026] [security2:error] [pid 977210:tid 977431] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufSPW1Jl2-fgIeVvqYUAAAAN4"]
[Thu Jul 30 14:00:25.980309 2026] [security2:error] [pid 977210:tid 977344] [client 20.104.16.169:20485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/ms-edit.php"] [unique_id "amufSfW1Jl2-fgIeVvqYcQAAAIc"]
[Thu Jul 30 14:00:26.346172 2026] [security2:error] [pid 977210:tid 977368] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufSfW1Jl2-fgIeVvqYagAAnw8"]
[Thu Jul 30 14:00:26.584706 2026] [security2:error] [pid 977210:tid 977421] [client 20.203.148.31:46529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/bb.php"] [unique_id "amufSvW1Jl2-fgIeVvqYhAAAANQ"]
[Thu Jul 30 14:00:26.671292 2026] [security2:error] [pid 977210:tid 977436] [client 20.104.16.169:20512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deltaedu.net"] [uri "/index.php"] [unique_id "amufSvW1Jl2-fgIeVvqYhQAAAOM"]
[Thu Jul 30 14:00:27.067997 2026] [security2:error] [pid 977210:tid 977397] [client 20.104.16.169:20512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/dx.php"] [unique_id "amufS_W1Jl2-fgIeVvqYkAAAALw"]
[Thu Jul 30 14:00:27.202752 2026] [security2:error] [pid 977210:tid 977363] [client 20.203.148.31:39860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/bnm.php"] [unique_id "amufS_W1Jl2-fgIeVvqYkgAAAJo"]
[Thu Jul 30 14:00:27.704802 2026] [security2:error] [pid 977210:tid 977424] [client 20.104.16.169:20494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-admin/maint/index.php"] [unique_id "amufS_W1Jl2-fgIeVvqYnQAAANc"]
[Thu Jul 30 14:00:27.837680 2026] [security2:error] [pid 977210:tid 977411] [client 13.221.239.180:51270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXxwAAAMo"]
[Thu Jul 30 14:00:27.844358 2026] [security2:error] [pid 977210:tid 977366] [client 13.221.239.180:51296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRfW1Jl2-fgIeVvqX1AAAAJ0"]
[Thu Jul 30 14:00:27.851500 2026] [security2:error] [pid 977210:tid 977457] [client 13.221.239.180:51378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRfW1Jl2-fgIeVvqX1QAAAPg"]
[Thu Jul 30 14:00:27.869443 2026] [security2:error] [pid 977210:tid 977386] [client 13.221.239.180:51366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXygAAALE"]
[Thu Jul 30 14:00:27.875307 2026] [security2:error] [pid 977210:tid 977389] [client 13.221.239.180:51404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXywAAALQ"]
[Thu Jul 30 14:00:27.878204 2026] [security2:error] [pid 977210:tid 977406] [client 13.221.239.180:51286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXzQAAAMU"]
[Thu Jul 30 14:00:27.879279 2026] [security2:error] [pid 977210:tid 977467] [client 13.221.239.180:51374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXzgAAAQI"]
[Thu Jul 30 14:00:27.889767 2026] [security2:error] [pid 977210:tid 977377] [client 13.221.239.180:51302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRfW1Jl2-fgIeVvqX1gAAAKg"]
[Thu Jul 30 14:00:27.920527 2026] [security2:error] [pid 977210:tid 977398] [client 13.221.239.180:51338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXzAAAAL0"]
[Thu Jul 30 14:00:28.021154 2026] [security2:error] [pid 977210:tid 977466] [client 13.221.239.180:51326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRfW1Jl2-fgIeVvqX2AAAAQE"]
[Thu Jul 30 14:00:28.109811 2026] [security2:error] [pid 977210:tid 977350] [client 13.221.239.180:51262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXxgAAAI0"]
[Thu Jul 30 14:00:28.109990 2026] [security2:error] [pid 977210:tid 977444] [client 13.221.239.180:51350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRfW1Jl2-fgIeVvqX1wAAAOs"]
[Thu Jul 30 14:00:28.230765 2026] [security2:error] [pid 977210:tid 977347] [client 13.221.239.180:51290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXyAAAAIo"]
[Thu Jul 30 14:00:28.261134 2026] [security2:error] [pid 977210:tid 977448] [client 13.221.239.180:51390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRPW1Jl2-fgIeVvqXyQAAAO8"]
[Thu Jul 30 14:00:28.276565 2026] [security2:error] [pid 977210:tid 977374] [client 13.221.239.180:51314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.revolutionary-technologies.com"] [uri "/index.php"] [unique_id "amufRfW1Jl2-fgIeVvqX0wAAAKU"]
[Thu Jul 30 14:00:28.384018 2026] [security2:error] [pid 977210:tid 977435] [client 20.104.16.169:20520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "deltaedu.net"] [uri "/index.php"] [unique_id "amufTPW1Jl2-fgIeVvqYqwAAAOI"]
[Thu Jul 30 14:00:28.527526 2026] [security2:error] [pid 977210:tid 977461] [client 20.215.191.139:21362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amufTPW1Jl2-fgIeVvqYtAAAAPw"]
[Thu Jul 30 14:00:28.557956 2026] [security2:error] [pid 977210:tid 977399] [client 20.203.148.31:47571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/bootstrap.php"] [unique_id "amufTPW1Jl2-fgIeVvqYtgAAAL4"]
[Thu Jul 30 14:00:28.575015 2026] [core:notice] [pid 977210:tid 977345] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:28.609738 2026] [security2:error] [pid 977210:tid 977372] [client 20.104.16.169:20520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/doc.php"] [unique_id "amufTPW1Jl2-fgIeVvqYuwAAAKM"]
[Thu Jul 30 14:00:29.207132 2026] [security2:error] [pid 977210:tid 977423] [client 20.104.16.169:35708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/tool.php"] [unique_id "amufTfW1Jl2-fgIeVvqYyAAAANY"]
[Thu Jul 30 14:00:29.842428 2026] [security2:error] [pid 977210:tid 977438] [client 20.104.16.169:20506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/xx.php"] [unique_id "amufTfW1Jl2-fgIeVvqY0wAAAOU"]
[Thu Jul 30 14:00:30.473648 2026] [security2:error] [pid 977210:tid 977428] [client 20.104.16.169:20486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/xxx.php"] [unique_id "amufTvW1Jl2-fgIeVvqY3wAAANs"]
[Thu Jul 30 14:00:30.719570 2026] [security2:error] [pid 977210:tid 977350] [client 20.203.148.31:47567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/buy.php"] [unique_id "amufTvW1Jl2-fgIeVvqY5QAAAI0"]
[Thu Jul 30 14:00:31.171281 2026] [security2:error] [pid 977210:tid 977434] [client 20.104.16.169:20345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/100.php"] [unique_id "amufT_W1Jl2-fgIeVvqY7QAAAOE"]
[Thu Jul 30 14:00:31.524598 2026] [security2:error] [pid 977210:tid 977447] [client 20.215.191.139:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amufT_W1Jl2-fgIeVvqY9AAAAO4"]
[Thu Jul 30 14:00:31.544870 2026] [security2:error] [pid 977210:tid 977452] [client 20.203.148.31:47705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/chosen.php"] [unique_id "amufT_W1Jl2-fgIeVvqY9QAAAPM"]
[Thu Jul 30 14:00:31.556317 2026] [security2:error] [pid 977210:tid 977467] [client 103.242.199.184:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufT_W1Jl2-fgIeVvqY9gAAAQI"]
[Thu Jul 30 14:00:31.556418 2026] [security2:error] [pid 977210:tid 977467] [client 103.242.199.184:56864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufT_W1Jl2-fgIeVvqY9gAAAQI"]
[Thu Jul 30 14:00:31.704308 2026] [security2:error] [pid 977210:tid 977423] [client 181.116.200.68:60946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufT_W1Jl2-fgIeVvqY-gAAANY"]
[Thu Jul 30 14:00:31.704430 2026] [security2:error] [pid 977210:tid 977423] [client 181.116.200.68:60946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufT_W1Jl2-fgIeVvqY-gAAANY"]
[Thu Jul 30 14:00:31.719886 2026] [security2:error] [pid 977210:tid 977275] [remote 216.73.217.142:54931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amufT_W1Jl2-fgIeVvqY-wAAkD4"]
[Thu Jul 30 14:00:31.795180 2026] [security2:error] [pid 977210:tid 977443] [client 20.104.16.169:21159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-admin/network/about.php"] [unique_id "amufT_W1Jl2-fgIeVvqY_gAAAOo"]
[Thu Jul 30 14:00:32.198141 2026] [security2:error] [pid 977210:tid 977444] [client 85.208.96.198:45998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/09/23/caixa-paga-auxilio-emergencial-a-56-milhoes-nesta-quarta-feira/"] [unique_id "amufUPW1Jl2-fgIeVvqZCAAAAOs"]
[Thu Jul 30 14:00:32.198259 2026] [security2:error] [pid 977210:tid 977444] [client 85.208.96.198:45998] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/09/23/caixa-paga-auxilio-emergencial-a-56-milhoes-nesta-quarta-feira/"] [unique_id "amufUPW1Jl2-fgIeVvqZCAAAAOs"]
[Thu Jul 30 14:00:32.241316 2026] [security2:error] [pid 977210:tid 977354] [client 20.215.191.139:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amufUPW1Jl2-fgIeVvqZCQAAAJE"]
[Thu Jul 30 14:00:32.400465 2026] [security2:error] [pid 977210:tid 977383] [client 20.104.16.169:21157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-blog.php"] [unique_id "amufUPW1Jl2-fgIeVvqZEAAAAK4"]
[Thu Jul 30 14:00:32.577089 2026] [security2:error] [pid 977210:tid 977271] [remote 114.119.137.237:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fantasynamelist.com"] [uri "/fantasy-race/gnome-name-generator/"] [unique_id "amufUPW1Jl2-fgIeVvqZEgAAxzo"], referer: https://fantasynamelist.com/fantasy-race/goblin-name-generator/
[Thu Jul 30 14:00:32.590013 2026] [security2:error] [pid 977210:tid 977276] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/index.php"] [unique_id "amufUPW1Jl2-fgIeVvqZEwAA0D8"]
[Thu Jul 30 14:00:32.781403 2026] [security2:error] [pid 977210:tid 977375] [client 103.190.40.154:15653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufUPW1Jl2-fgIeVvqZGAAAAKY"]
[Thu Jul 30 14:00:32.781561 2026] [security2:error] [pid 977210:tid 977375] [client 103.190.40.154:15653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufUPW1Jl2-fgIeVvqZGAAAAKY"]
[Thu Jul 30 14:00:32.930199 2026] [security2:error] [pid 977210:tid 977459] [client 20.215.191.139:28936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/flower.php"] [unique_id "amufUPW1Jl2-fgIeVvqZHwAAAPo"]
[Thu Jul 30 14:00:33.626475 2026] [security2:error] [pid 977210:tid 977291] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amufUfW1Jl2-fgIeVvqZKgAA0U4"]
[Thu Jul 30 14:00:34.442476 2026] [security2:error] [pid 977210:tid 977413] [client 20.203.148.31:39862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/class-wp-image.php"] [unique_id "amufUvW1Jl2-fgIeVvqZPgAAAMw"]
[Thu Jul 30 14:00:34.446108 2026] [security2:error] [pid 977210:tid 977388] [client 20.215.191.139:6212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amufUvW1Jl2-fgIeVvqZPwAAALM"]
[Thu Jul 30 14:00:35.483492 2026] [security2:error] [pid 977210:tid 977322] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/acme-challenge/autoload_classmap.php"] [unique_id "amufU_W1Jl2-fgIeVvqZWgAAnW0"]
[Thu Jul 30 14:00:35.506786 2026] [security2:error] [pid 977210:tid 977401] [client 189.6.88.213:54485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufU_W1Jl2-fgIeVvqZXQAAAMA"]
[Thu Jul 30 14:00:35.506918 2026] [security2:error] [pid 977210:tid 977401] [client 189.6.88.213:54485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufU_W1Jl2-fgIeVvqZXQAAAMA"]
[Thu Jul 30 14:00:35.568878 2026] [security2:error] [pid 977210:tid 977420] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufUvW1Jl2-fgIeVvqZTwAAANM"]
[Thu Jul 30 14:00:35.973434 2026] [security2:error] [pid 977210:tid 977467] [client 20.215.191.139:23468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amufU_W1Jl2-fgIeVvqZaAAAAQI"]
[Thu Jul 30 14:00:36.834301 2026] [core:notice] [pid 977210:tid 977370] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:37.227850 2026] [core:notice] [pid 977210:tid 977299] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:37.391303 2026] [security2:error] [pid 977210:tid 977305] [remote 216.73.217.142:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amufVfW1Jl2-fgIeVvqZkQAA-Fw"]
[Thu Jul 30 14:00:37.992495 2026] [security2:error] [pid 977210:tid 977329] [remote 20.171.55.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/cloud.php"] [unique_id "amufVfW1Jl2-fgIeVvqZqAAAinQ"]
[Thu Jul 30 14:00:38.102163 2026] [core:notice] [pid 977210:tid 977294] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:39.232808 2026] [security2:error] [pid 977210:tid 977353] [client 20.215.191.139:61910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amufV_W1Jl2-fgIeVvqZ2gAAAJA"]
[Thu Jul 30 14:00:39.270155 2026] [security2:error] [pid 977210:tid 977444] [client 103.231.91.59:39444] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amufV_W1Jl2-fgIeVvqZ3QAAAOs"]
[Thu Jul 30 14:00:39.270252 2026] [security2:error] [pid 977210:tid 977444] [client 103.231.91.59:39444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amufV_W1Jl2-fgIeVvqZ3QAAAOs"]
[Thu Jul 30 14:00:39.521009 2026] [security2:error] [pid 977210:tid 977450] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufVvW1Jl2-fgIeVvqZzQAA8Xs"]
[Thu Jul 30 14:00:39.993175 2026] [security2:error] [pid 977210:tid 977346] [client 20.203.148.31:44287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/classsmtps.php"] [unique_id "amufV_W1Jl2-fgIeVvqZ7AAAAIk"]
[Thu Jul 30 14:00:40.046314 2026] [security2:error] [pid 977210:tid 977352] [client 20.215.191.139:21382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amufWPW1Jl2-fgIeVvqZ7QAAAI8"]
[Thu Jul 30 14:00:40.171766 2026] [proxy:error] [pid 977210:tid 977453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:00:40.171849 2026] [proxy_http:error] [pid 977210:tid 977453] [client 3.228.112.215:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:00:40.172435 2026] [proxy:error] [pid 977210:tid 977453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:00:40.172481 2026] [proxy_http:error] [pid 977210:tid 977453] [client 3.228.112.215:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:00:40.287414 2026] [proxy:error] [pid 977210:tid 977382] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:00:40.287492 2026] [proxy_http:error] [pid 977210:tid 977382] [client 52.202.41.153:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:00:40.288124 2026] [proxy:error] [pid 977210:tid 977382] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:00:40.288170 2026] [proxy_http:error] [pid 977210:tid 977382] [client 52.202.41.153:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:00:40.563886 2026] [security2:error] [pid 977210:tid 977224] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/uploads/2016/12/cropped-cnpinyin.com-50s-1-32x32.png"] [unique_id "amufWPW1Jl2-fgIeVvqaAQAAsgs"]
[Thu Jul 30 14:00:40.727461 2026] [security2:error] [pid 977210:tid 977452] [client 43.173.182.191:33594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/oembed/1.0/embed"] [unique_id "amufWPW1Jl2-fgIeVvqZ_QAAAPM"]
[Thu Jul 30 14:00:40.856274 2026] [security2:error] [pid 977210:tid 977374] [client 66.249.73.98:53538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amufVvW1Jl2-fgIeVvqZqQAAAKU"]
[Thu Jul 30 14:00:40.920672 2026] [security2:error] [pid 977210:tid 977223] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/uploads/2016/12/cropped-cnpinyin.com-50s-1-32x32.png"] [unique_id "amufWPW1Jl2-fgIeVvqaEwAAiAo"]
[Thu Jul 30 14:00:40.922734 2026] [security2:error] [pid 977210:tid 977326] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/uploads/2016/12/cropped-cnpinyin.com-50s-1-192x192.png"] [unique_id "amufWPW1Jl2-fgIeVvqaFAAAm3E"]
[Thu Jul 30 14:00:41.023628 2026] [security2:error] [pid 977210:tid 977469] [client 20.203.148.31:44258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/classwithtostring.php"] [unique_id "amufWfW1Jl2-fgIeVvqaFQAAAQQ"]
[Thu Jul 30 14:00:41.279135 2026] [security2:error] [pid 977210:tid 977232] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/uploads/2016/12/cropped-cnpinyin.com-50s-1-192x192.png"] [unique_id "amufWfW1Jl2-fgIeVvqaHwAAzRM"]
[Thu Jul 30 14:00:41.281348 2026] [security2:error] [pid 977210:tid 977219] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/uploads/2016/12/cropped-cnpinyin.com-50s-1-180x180.png"] [unique_id "amufWfW1Jl2-fgIeVvqaIAAAlwY"]
[Thu Jul 30 14:00:41.347316 2026] [core:error] [pid 977210:tid 977451] [client 74.7.228.3:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:00:41.347345 2026] [core:error] [pid 977210:tid 977451] [client 74.7.228.3:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:00:41.347477 2026] [security2:error] [pid 977210:tid 977451] [client 74.7.228.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.srz.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amufWfW1Jl2-fgIeVvqaJwAAAPI"]
[Thu Jul 30 14:00:41.348061 2026] [security2:error] [pid 977210:tid 977461] [client 74.7.228.3:40242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.srz.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amufWfW1Jl2-fgIeVvqaJAAA_A8"]
[Thu Jul 30 14:00:41.352664 2026] [core:notice] [pid 977210:tid 977367] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:41.357772 2026] [security2:error] [pid 977210:tid 977367] [client 43.173.173.162:58430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/oembed/1.0/embed"] [unique_id "amufWfW1Jl2-fgIeVvqaKAAAAJ4"], referer: https://carnetdeshopping.com/index.php/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fcarnetdeshopping.com%2Findex.php%2F2015%2F11%2F02%2Fmanteaux-en-laine-hiver-2015%2F
[Thu Jul 30 14:00:41.475180 2026] [security2:error] [pid 977210:tid 977413] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufWPW1Jl2-fgIeVvqaEgAAAMw"]
[Thu Jul 30 14:00:41.637211 2026] [security2:error] [pid 977210:tid 977239] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/uploads/2016/12/cropped-cnpinyin.com-50s-1-180x180.png"] [unique_id "amufWfW1Jl2-fgIeVvqaMAAAsRo"]
[Thu Jul 30 14:00:41.638608 2026] [security2:error] [pid 977210:tid 977236] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/themes/clean-education-child/style.css"] [unique_id "amufWfW1Jl2-fgIeVvqaMQAAvRc"]
[Thu Jul 30 14:00:41.956031 2026] [security2:error] [pid 977210:tid 977248] [remote 216.73.217.142:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amufWfW1Jl2-fgIeVvqaRgAAkSM"]
[Thu Jul 30 14:00:41.990082 2026] [security2:error] [pid 977210:tid 977382] [client 20.215.191.139:28956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amufWfW1Jl2-fgIeVvqaSAAAAK0"]
[Thu Jul 30 14:00:41.994859 2026] [security2:error] [pid 977210:tid 977241] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/themes/clean-education-child/style.css"] [unique_id "amufWfW1Jl2-fgIeVvqaSQAAvhw"]
[Thu Jul 30 14:00:41.996116 2026] [security2:error] [pid 977210:tid 977256] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/themes/clean-education/css/font-awesome/css/all.min.css"] [unique_id "amufWfW1Jl2-fgIeVvqaSgAApSs"]
[Thu Jul 30 14:00:42.229877 2026] [security2:error] [pid 977210:tid 977460] [client 43.172.198.231:57704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sellvia.womenclothingbox.com"] [uri "/"] [unique_id "amufWfW1Jl2-fgIeVvqaRwAAAPs"], referer: https://carnetdeshopping.com/
[Thu Jul 30 14:00:42.230041 2026] [security2:error] [pid 977210:tid 977388] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amufWvW1Jl2-fgIeVvqaTAAAsyk"]
[Thu Jul 30 14:00:42.253243 2026] [security2:error] [pid 977210:tid 977416] [client 103.242.199.184:57427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufWvW1Jl2-fgIeVvqaUAAAAM8"]
[Thu Jul 30 14:00:42.253367 2026] [security2:error] [pid 977210:tid 977416] [client 103.242.199.184:57427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufWvW1Jl2-fgIeVvqaUAAAAM8"]
[Thu Jul 30 14:00:42.277920 2026] [security2:error] [pid 977210:tid 977347] [client 181.116.200.68:41327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufWvW1Jl2-fgIeVvqaVAAAAIo"]
[Thu Jul 30 14:00:42.278038 2026] [security2:error] [pid 977210:tid 977347] [client 181.116.200.68:41327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufWvW1Jl2-fgIeVvqaVAAAAIo"]
[Thu Jul 30 14:00:42.355437 2026] [security2:error] [pid 977210:tid 977264] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/comments/feed/"] [unique_id "amufWvW1Jl2-fgIeVvqaZQAAnjM"]
[Thu Jul 30 14:00:42.355468 2026] [security2:error] [pid 977210:tid 977268] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/themes/clean-education/css/font-awesome/css/all.min.css"] [unique_id "amufWvW1Jl2-fgIeVvqaZAAAnjc"]
[Thu Jul 30 14:00:42.713052 2026] [security2:error] [pid 977210:tid 977285] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "amufWvW1Jl2-fgIeVvqaawAAlkg"]
[Thu Jul 30 14:00:42.713471 2026] [security2:error] [pid 977210:tid 977275] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/comments/feed/"] [unique_id "amufWvW1Jl2-fgIeVvqabAAAlj4"]
[Thu Jul 30 14:00:42.809804 2026] [security2:error] [pid 977210:tid 977425] [client 20.203.148.31:39951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/config.php"] [unique_id "amufWvW1Jl2-fgIeVvqacQAAANg"]
[Thu Jul 30 14:00:43.076836 2026] [security2:error] [pid 977210:tid 977261] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "amufW_W1Jl2-fgIeVvqadwAAkTA"]
[Thu Jul 30 14:00:43.076956 2026] [security2:error] [pid 977210:tid 977290] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "amufW_W1Jl2-fgIeVvqadgAAkU0"]
[Thu Jul 30 14:00:43.435999 2026] [security2:error] [pid 977210:tid 977281] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-includes/css/dashicons.min.css"] [unique_id "amufW_W1Jl2-fgIeVvqaiQAAiUQ"]
[Thu Jul 30 14:00:43.436148 2026] [security2:error] [pid 977210:tid 977308] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "amufW_W1Jl2-fgIeVvqaiAAAiV8"]
[Thu Jul 30 14:00:43.564652 2026] [security2:error] [pid 977210:tid 977453] [client 103.190.40.154:18810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufW_W1Jl2-fgIeVvqakwAAAPQ"]
[Thu Jul 30 14:00:43.564809 2026] [security2:error] [pid 977210:tid 977453] [client 103.190.40.154:18810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufW_W1Jl2-fgIeVvqakwAAAPQ"]
[Thu Jul 30 14:00:43.793488 2026] [security2:error] [pid 977210:tid 977291] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-includes/css/jquery-ui-dialog.min.css"] [unique_id "amufW_W1Jl2-fgIeVvqamAAA-U4"]
[Thu Jul 30 14:00:43.793633 2026] [security2:error] [pid 977210:tid 977250] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-includes/css/dashicons.min.css"] [unique_id "amufW_W1Jl2-fgIeVvqamQAA-SU"]
[Thu Jul 30 14:00:43.863513 2026] [security2:error] [pid 977210:tid 977388] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufW_W1Jl2-fgIeVvqafwAAALM"]
[Thu Jul 30 14:00:43.936130 2026] [security2:error] [pid 977210:tid 977368] [client 20.215.191.139:25861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amufW_W1Jl2-fgIeVvqaoQAAAJ8"]
[Thu Jul 30 14:00:44.085850 2026] [security2:error] [pid 977210:tid 977450] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufW_W1Jl2-fgIeVvqajwAAAPE"]
[Thu Jul 30 14:00:44.151237 2026] [security2:error] [pid 977210:tid 977273] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-includes/css/jquery-ui-dialog.min.css"] [unique_id "amufXPW1Jl2-fgIeVvqapQAAsDw"]
[Thu Jul 30 14:00:44.151326 2026] [security2:error] [pid 977210:tid 977277] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/themes/clean-education/style.css"] [unique_id "amufXPW1Jl2-fgIeVvqapAAAsEA"]
[Thu Jul 30 14:00:44.508747 2026] [security2:error] [pid 977210:tid 977216] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/fonts/e9c0f812acd6c0ffaedf5f8c93442382.css"] [unique_id "amufXPW1Jl2-fgIeVvqa3gAAzwM"]
[Thu Jul 30 14:00:44.508786 2026] [security2:error] [pid 977210:tid 977334] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/themes/clean-education/style.css"] [unique_id "amufXPW1Jl2-fgIeVvqa3QAAz3k"]
[Thu Jul 30 14:00:44.761154 2026] [core:notice] [pid 977210:tid 977345] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:44.781874 2026] [core:notice] [pid 977210:tid 977224] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:44.797389 2026] [core:notice] [pid 977210:tid 977220] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:44.866494 2026] [security2:error] [pid 977210:tid 977222] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/fonts/e9c0f812acd6c0ffaedf5f8c93442382.css"] [unique_id "amufXPW1Jl2-fgIeVvqa6AAA_Qk"]
[Thu Jul 30 14:00:44.881363 2026] [core:notice] [pid 977210:tid 977221] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:45.035013 2026] [core:notice] [pid 977210:tid 977213] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:46.202664 2026] [security2:error] [pid 977210:tid 977382] [client 189.6.88.213:55024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufXvW1Jl2-fgIeVvqbBAAAAK0"]
[Thu Jul 30 14:00:46.202778 2026] [security2:error] [pid 977210:tid 977382] [client 189.6.88.213:55024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufXvW1Jl2-fgIeVvqbBAAAAK0"]
[Thu Jul 30 14:00:46.866925 2026] [security2:error] [pid 977210:tid 977235] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/themes/clean-education/css/blocks.css"] [unique_id "amufXvW1Jl2-fgIeVvqbFQAAphY"]
[Thu Jul 30 14:00:46.900774 2026] [security2:error] [pid 977210:tid 977342] [client 20.215.191.139:43142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amufXvW1Jl2-fgIeVvqbFgAAAIU"]
[Thu Jul 30 14:00:47.224618 2026] [security2:error] [pid 977210:tid 977242] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/feed/"] [unique_id "amufX_W1Jl2-fgIeVvqbHAAAyB0"]
[Thu Jul 30 14:00:47.227461 2026] [security2:error] [pid 977210:tid 977244] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/themes/clean-education/css/blocks.css"] [unique_id "amufX_W1Jl2-fgIeVvqbHgAAmB8"]
[Thu Jul 30 14:00:47.582340 2026] [security2:error] [pid 977210:tid 977248] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/add-to-any/addtoany.min.css"] [unique_id "amufX_W1Jl2-fgIeVvqbKwAApCM"]
[Thu Jul 30 14:00:47.584825 2026] [security2:error] [pid 977210:tid 977241] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/feed/"] [unique_id "amufX_W1Jl2-fgIeVvqbLAAAkBw"]
[Thu Jul 30 14:00:47.923505 2026] [security2:error] [pid 977210:tid 977350] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufX_W1Jl2-fgIeVvqbJQAAAI0"]
[Thu Jul 30 14:00:47.940131 2026] [security2:error] [pid 977210:tid 977218] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/profile-builder/assets/css/style-front-end.css"] [unique_id "amufX_W1Jl2-fgIeVvqbNgAAmQU"]
[Thu Jul 30 14:00:47.942190 2026] [security2:error] [pid 977210:tid 977259] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/add-to-any/addtoany.min.css"] [unique_id "amufX_W1Jl2-fgIeVvqbNwAAiS4"]
[Thu Jul 30 14:00:48.299760 2026] [security2:error] [pid 977210:tid 977252] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-json/"] [unique_id "amufYPW1Jl2-fgIeVvqbPwAAzSc"]
[Thu Jul 30 14:00:48.300458 2026] [security2:error] [pid 977210:tid 977265] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/profile-builder/assets/css/style-front-end.css"] [unique_id "amufYPW1Jl2-fgIeVvqbQAAAzTQ"]
[Thu Jul 30 14:00:48.372459 2026] [security2:error] [pid 977210:tid 977380] [client 20.215.191.139:29740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amufYPW1Jl2-fgIeVvqbRAAAAKs"]
[Thu Jul 30 14:00:48.422018 2026] [security2:error] [pid 977210:tid 977461] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufX_W1Jl2-fgIeVvqbKQAA_Bk"]
[Thu Jul 30 14:00:48.541626 2026] [security2:error] [pid 977210:tid 977243] [remote 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufX_W1Jl2-fgIeVvqbKgAA0R4"]
[Thu Jul 30 14:00:48.657430 2026] [security2:error] [pid 977210:tid 977251] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-json/wp/v2/pages/43"] [unique_id "amufYPW1Jl2-fgIeVvqbSAAAoiY"]
[Thu Jul 30 14:00:48.658010 2026] [security2:error] [pid 977210:tid 977270] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-json/"] [unique_id "amufYPW1Jl2-fgIeVvqbSQAAojk"]
[Thu Jul 30 14:00:49.015509 2026] [security2:error] [pid 977210:tid 977258] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-json/wp/v2/pages/43"] [unique_id "amufYfW1Jl2-fgIeVvqbVQAA-C0"]
[Thu Jul 30 14:00:49.136445 2026] [security2:error] [pid 977210:tid 977395] [client 20.203.148.31:47011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/core.php"] [unique_id "amufYfW1Jl2-fgIeVvqbVwAAALo"]
[Thu Jul 30 14:00:49.280204 2026] [security2:error] [pid 977210:tid 977268] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/xmlrpc.php"] [unique_id "amufYfW1Jl2-fgIeVvqbVAAA-Dc"]
[Thu Jul 30 14:00:49.373218 2026] [security2:error] [pid 977210:tid 977269] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/xmlrpc.php"] [unique_id "amufYfW1Jl2-fgIeVvqbXgAAsjg"]
[Thu Jul 30 14:00:49.638004 2026] [security2:error] [pid 977210:tid 977267] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amufYfW1Jl2-fgIeVvqbZAAA1zY"]
[Thu Jul 30 14:00:49.730995 2026] [security2:error] [pid 977210:tid 977283] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amufYfW1Jl2-fgIeVvqbZQAAz0Y"]
[Thu Jul 30 14:00:49.995712 2026] [security2:error] [pid 977210:tid 977287] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amufYfW1Jl2-fgIeVvqbewAA8ko"]
[Thu Jul 30 14:00:50.021298 2026] [security2:error] [pid 977210:tid 977440] [client 20.215.191.139:21438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amufYvW1Jl2-fgIeVvqbgQAAAOc"]
[Thu Jul 30 14:00:50.091091 2026] [security2:error] [pid 977210:tid 977297] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amufYvW1Jl2-fgIeVvqbgwAAr1Q"]
[Thu Jul 30 14:00:50.132413 2026] [security2:error] [pid 977210:tid 977464] [client 20.203.148.31:44416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/css.php"] [unique_id "amufYvW1Jl2-fgIeVvqbhAAAAP8"]
[Thu Jul 30 14:00:50.809914 2026] [security2:error] [pid 977210:tid 977361] [client 20.215.191.139:24201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/xleet.php"] [unique_id "amufYvW1Jl2-fgIeVvqblwAAAJg"]
[Thu Jul 30 14:00:50.946382 2026] [security2:error] [pid 977210:tid 977266] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/xmlrpc.php"] [unique_id "amufYvW1Jl2-fgIeVvqbngAA2DU"]
[Thu Jul 30 14:00:51.062227 2026] [security2:error] [pid 977210:tid 977311] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/xmlrpc.php"] [unique_id "amufY_W1Jl2-fgIeVvqbogAAm2I"]
[Thu Jul 30 14:00:51.087147 2026] [core:notice] [pid 977210:tid 977387] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:51.304366 2026] [security2:error] [pid 977210:tid 977306] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/paid-member-subscriptions/assets/css/style-front-end.css"] [unique_id "amufY_W1Jl2-fgIeVvqbpgABAl0"]
[Thu Jul 30 14:00:51.420029 2026] [security2:error] [pid 977210:tid 977307] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-content/plugins/paid-member-subscriptions/assets/css/style-front-end.css"] [unique_id "amufY_W1Jl2-fgIeVvqbqwAAv14"]
[Thu Jul 30 14:00:51.520195 2026] [security2:error] [pid 977210:tid 977424] [client 20.203.148.31:39946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/database.php"] [unique_id "amufY_W1Jl2-fgIeVvqbrgAAANc"]
[Thu Jul 30 14:00:51.635946 2026] [core:notice] [pid 977210:tid 977394] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:51.662033 2026] [security2:error] [pid 977210:tid 977313] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/favicon.ico"] [unique_id "amufY_W1Jl2-fgIeVvqbtQAAwmQ"]
[Thu Jul 30 14:00:51.662033 2026] [security2:error] [pid 977210:tid 977295] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/images/favicon.ico"] [unique_id "amufY_W1Jl2-fgIeVvqbuAAAwlI"]
[Thu Jul 30 14:00:51.662045 2026] [security2:error] [pid 977210:tid 977298] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/favicon.png"] [unique_id "amufY_W1Jl2-fgIeVvqbtwAAwlU"]
[Thu Jul 30 14:00:51.662045 2026] [security2:error] [pid 977210:tid 977293] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/img/favicon.ico"] [unique_id "amufY_W1Jl2-fgIeVvqbtgAAwlA"]
[Thu Jul 30 14:00:51.662066 2026] [security2:error] [pid 977210:tid 977323] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/assets/favicon.ico"] [unique_id "amufY_W1Jl2-fgIeVvqbugAAwm4"]
[Thu Jul 30 14:00:51.662087 2026] [security2:error] [pid 977210:tid 977305] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/icon/favicon.ico"] [unique_id "amufY_W1Jl2-fgIeVvqbuwAAwlw"]
[Thu Jul 30 14:00:51.662327 2026] [security2:error] [pid 977210:tid 977286] [remote 14.116.236.91:22078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/static/favicon.ico"] [unique_id "amufY_W1Jl2-fgIeVvqbuQAAwkk"]
[Thu Jul 30 14:00:51.764565 2026] [security2:error] [pid 977210:tid 977362] [client 20.215.191.139:22667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-config-sample.php"] [unique_id "amufY_W1Jl2-fgIeVvqbvQAAAJk"]
[Thu Jul 30 14:00:52.192256 2026] [security2:error] [pid 977210:tid 977413] [client 14.116.236.91:6760] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/icon/favicon.ico"] [unique_id "amufZPW1Jl2-fgIeVvqbzwAAAMw"]
[Thu Jul 30 14:00:52.195419 2026] [security2:error] [pid 977210:tid 977430] [client 14.116.236.91:25917] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/img/favicon.ico"] [unique_id "amufZPW1Jl2-fgIeVvqb0AAAAN0"]
[Thu Jul 30 14:00:52.198350 2026] [security2:error] [pid 977210:tid 977372] [client 14.116.236.91:5358] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/assets/favicon.ico"] [unique_id "amufZPW1Jl2-fgIeVvqb0QAAAKM"]
[Thu Jul 30 14:00:52.202416 2026] [security2:error] [pid 977210:tid 977410] [client 14.116.236.91:5357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/favicon.ico"] [unique_id "amufZPW1Jl2-fgIeVvqb0gAAAMk"]
[Thu Jul 30 14:00:52.204438 2026] [security2:error] [pid 977210:tid 977444] [client 14.116.236.91:50637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/static/favicon.ico"] [unique_id "amufZPW1Jl2-fgIeVvqb0wAAAOs"]
[Thu Jul 30 14:00:52.207800 2026] [security2:error] [pid 977210:tid 977342] [client 14.116.236.91:50638] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/images/favicon.ico"] [unique_id "amufZPW1Jl2-fgIeVvqb1AAAAIU"]
[Thu Jul 30 14:00:52.208281 2026] [security2:error] [pid 977210:tid 977447] [client 14.116.236.91:25918] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/favicon.png"] [unique_id "amufZPW1Jl2-fgIeVvqb1QAAAO4"]
[Thu Jul 30 14:00:52.634380 2026] [security2:error] [pid 977210:tid 977386] [client 47.128.121.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amufZPW1Jl2-fgIeVvqb4gAAALE"]
[Thu Jul 30 14:00:52.814331 2026] [security2:error] [pid 977210:tid 977417] [client 103.242.199.184:57983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufZPW1Jl2-fgIeVvqb6wAAANA"]
[Thu Jul 30 14:00:52.815116 2026] [security2:error] [pid 977210:tid 977417] [client 103.242.199.184:57983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufZPW1Jl2-fgIeVvqb6wAAANA"]
[Thu Jul 30 14:00:52.826372 2026] [security2:error] [pid 977210:tid 977352] [client 181.116.200.68:13432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufZPW1Jl2-fgIeVvqb7AAAAI8"]
[Thu Jul 30 14:00:52.826541 2026] [security2:error] [pid 977210:tid 977352] [client 181.116.200.68:13432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufZPW1Jl2-fgIeVvqb7AAAAI8"]
[Thu Jul 30 14:00:53.142769 2026] [security2:error] [pid 977210:tid 977215] [remote 74.7.243.224:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/stafff.php"] [unique_id "amufZfW1Jl2-fgIeVvqb-AAAvAI"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 14:00:53.290222 2026] [security2:error] [pid 977210:tid 977421] [client 103.231.91.59:46806] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amufZfW1Jl2-fgIeVvqb_AAAANQ"]
[Thu Jul 30 14:00:53.290366 2026] [security2:error] [pid 977210:tid 977421] [client 103.231.91.59:46806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amufZfW1Jl2-fgIeVvqb_AAAANQ"]
[Thu Jul 30 14:00:53.731093 2026] [security2:error] [pid 977210:tid 977458] [client 184.75.223.227:38322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amufZfW1Jl2-fgIeVvqcBgAAAPk"]
[Thu Jul 30 14:00:53.731198 2026] [security2:error] [pid 977210:tid 977458] [client 184.75.223.227:38322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amufZfW1Jl2-fgIeVvqcBgAAAPk"]
[Thu Jul 30 14:00:54.368321 2026] [security2:error] [pid 977210:tid 977438] [client 103.190.40.154:19128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufZvW1Jl2-fgIeVvqcEwAAAOU"]
[Thu Jul 30 14:00:54.368453 2026] [security2:error] [pid 977210:tid 977438] [client 103.190.40.154:19128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufZvW1Jl2-fgIeVvqcEwAAAOU"]
[Thu Jul 30 14:00:55.068285 2026] [core:notice] [pid 977210:tid 977340] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:55.506419 2026] [autoindex:error] [pid 977210:tid 977362] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:00:55.507074 2026] [security2:error] [pid 977210:tid 977362] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufZ_W1Jl2-fgIeVvqcLgAAAJk"]
[Thu Jul 30 14:00:55.507437 2026] [security2:error] [pid 977210:tid 977437] [client 82.102.18.180:55410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/fonts/"] [unique_id "amufZ_W1Jl2-fgIeVvqcLAAAAOQ"]
[Thu Jul 30 14:00:55.719759 2026] [security2:error] [pid 977210:tid 977433] [client 20.203.148.31:47980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/db.php"] [unique_id "amufZ_W1Jl2-fgIeVvqcNQAAAOA"]
[Thu Jul 30 14:00:55.857904 2026] [autoindex:error] [pid 977210:tid 977372] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:00:55.858555 2026] [security2:error] [pid 977210:tid 977372] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufZ_W1Jl2-fgIeVvqcOwAAAKM"]
[Thu Jul 30 14:00:55.859144 2026] [security2:error] [pid 977210:tid 977367] [client 82.102.18.180:55410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/images/"] [unique_id "amufZ_W1Jl2-fgIeVvqcOQAAAJ4"]
[Thu Jul 30 14:00:56.126155 2026] [core:notice] [pid 977210:tid 977213] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:00:56.338396 2026] [autoindex:error] [pid 977210:tid 977354] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:00:56.339083 2026] [security2:error] [pid 977210:tid 977354] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufaPW1Jl2-fgIeVvqcUAAAAJE"]
[Thu Jul 30 14:00:56.339484 2026] [security2:error] [pid 977210:tid 977401] [client 82.102.18.180:55410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/.well-known/"] [unique_id "amufaPW1Jl2-fgIeVvqcTgAAAMA"]
[Thu Jul 30 14:00:56.919588 2026] [security2:error] [pid 977210:tid 977353] [client 189.6.88.213:55567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufaPW1Jl2-fgIeVvqcXQAAAJA"]
[Thu Jul 30 14:00:56.919698 2026] [security2:error] [pid 977210:tid 977353] [client 189.6.88.213:55567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufaPW1Jl2-fgIeVvqcXQAAAJA"]
[Thu Jul 30 14:00:57.396049 2026] [security2:error] [pid 977210:tid 977350] [client 20.203.148.31:44422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/default.php"] [unique_id "amufafW1Jl2-fgIeVvqcZwAAAI0"]
[Thu Jul 30 14:00:57.591331 2026] [security2:error] [pid 977210:tid 977235] [remote 216.73.217.142:26967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amufafW1Jl2-fgIeVvqcagAA_BY"]
[Thu Jul 30 14:00:59.268061 2026] [security2:error] [pid 977210:tid 977254] [remote 57.141.0.47:45472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amufa_W1Jl2-fgIeVvqcjAAAqCk"]
[Thu Jul 30 14:01:01.099759 2026] [proxy:error] [pid 977210:tid 977380] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:01:01.099821 2026] [proxy_http:error] [pid 977210:tid 977380] [client 44.216.125.112:45080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:01:01.100393 2026] [proxy:error] [pid 977210:tid 977380] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:01:01.100439 2026] [proxy_http:error] [pid 977210:tid 977380] [client 44.216.125.112:45080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:01:01.103125 2026] [proxy:error] [pid 977210:tid 977457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:01:01.103181 2026] [proxy_http:error] [pid 977210:tid 977457] [client 18.211.55.47:54320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:01:01.103729 2026] [proxy:error] [pid 977210:tid 977457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:01:01.103773 2026] [proxy_http:error] [pid 977210:tid 977457] [client 18.211.55.47:54320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:01:02.238155 2026] [security2:error] [pid 977210:tid 977383] [client 172.202.44.182:46249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wk/index.php"] [unique_id "amufbvW1Jl2-fgIeVvqc2gAAAK4"]
[Thu Jul 30 14:01:02.763362 2026] [core:notice] [pid 977210:tid 977261] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:03.040181 2026] [security2:error] [pid 977210:tid 977438] [client 90.55.1.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amufbvW1Jl2-fgIeVvqc7gAAAOU"], referer: https://cnpinyin.com
[Thu Jul 30 14:01:03.421591 2026] [security2:error] [pid 977210:tid 977382] [client 103.242.199.184:58540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufb_W1Jl2-fgIeVvqdAgAAAK0"]
[Thu Jul 30 14:01:03.421722 2026] [security2:error] [pid 977210:tid 977382] [client 103.242.199.184:58540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufb_W1Jl2-fgIeVvqdAgAAAK0"]
[Thu Jul 30 14:01:03.434534 2026] [security2:error] [pid 977210:tid 977349] [client 181.116.200.68:19996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufb_W1Jl2-fgIeVvqdAwAAAIw"]
[Thu Jul 30 14:01:03.435272 2026] [security2:error] [pid 977210:tid 977349] [client 181.116.200.68:19996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufb_W1Jl2-fgIeVvqdAwAAAIw"]
[Thu Jul 30 14:01:03.465909 2026] [core:notice] [pid 977210:tid 977291] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:03.827214 2026] [security2:error] [pid 977210:tid 977431] [client 172.202.44.182:35775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/av.php"] [unique_id "amufb_W1Jl2-fgIeVvqdDgAAAN4"]
[Thu Jul 30 14:01:04.635902 2026] [core:error] [pid 977210:tid 977443] [client 87.250.224.86:43154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:01:04.635926 2026] [core:error] [pid 977210:tid 977443] [client 87.250.224.86:43154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:01:04.782171 2026] [security2:error] [pid 977210:tid 977457] [client 85.208.98.18:57892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amufcPW1Jl2-fgIeVvqdJwAAAPg"]
[Thu Jul 30 14:01:04.782268 2026] [security2:error] [pid 977210:tid 977457] [client 85.208.98.18:57892] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amufcPW1Jl2-fgIeVvqdJwAAAPg"]
[Thu Jul 30 14:01:05.273224 2026] [security2:error] [pid 977210:tid 977348] [client 103.190.40.154:18803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufcfW1Jl2-fgIeVvqdNgAAAIs"]
[Thu Jul 30 14:01:05.273344 2026] [security2:error] [pid 977210:tid 977348] [client 103.190.40.154:18803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufcfW1Jl2-fgIeVvqdNgAAAIs"]
[Thu Jul 30 14:01:05.593460 2026] [security2:error] [pid 977210:tid 977355] [client 172.202.44.182:35770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/mini.php"] [unique_id "amufcfW1Jl2-fgIeVvqdNwAAAJI"]
[Thu Jul 30 14:01:05.964571 2026] [security2:error] [pid 977210:tid 977385] [client 128.2.204.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amufcfW1Jl2-fgIeVvqdRQAAALA"]
[Thu Jul 30 14:01:06.469628 2026] [security2:error] [pid 977210:tid 977450] [client 172.202.44.182:46234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/aa.php"] [unique_id "amufcvW1Jl2-fgIeVvqdVgAAAPE"]
[Thu Jul 30 14:01:06.881643 2026] [security2:error] [pid 977210:tid 977469] [client 57.141.0.2:38376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amufcvW1Jl2-fgIeVvqdVwABBGQ"], referer: https://igetvape-australia.com/product/iget-bar-pro-grape-ice/?add-to-cart=112
[Thu Jul 30 14:01:07.398822 2026] [security2:error] [pid 977210:tid 977294] [remote 216.73.217.142:6752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amufc_W1Jl2-fgIeVvqddQAAvFE"]
[Thu Jul 30 14:01:07.590732 2026] [security2:error] [pid 977210:tid 977373] [client 189.6.88.213:56106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufc_W1Jl2-fgIeVvqddwAAAKQ"]
[Thu Jul 30 14:01:07.590878 2026] [security2:error] [pid 977210:tid 977373] [client 189.6.88.213:56106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufc_W1Jl2-fgIeVvqddwAAAKQ"]
[Thu Jul 30 14:01:08.192741 2026] [security2:error] [pid 977210:tid 977353] [client 172.202.44.182:48991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/w.php"] [unique_id "amufdPW1Jl2-fgIeVvqdhgAAAJA"]
[Thu Jul 30 14:01:08.958886 2026] [security2:error] [pid 977210:tid 977402] [client 20.203.148.31:40275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/dropdown.php"] [unique_id "amufdPW1Jl2-fgIeVvqdoQAAAME"]
[Thu Jul 30 14:01:09.184177 2026] [security2:error] [pid 977210:tid 977443] [client 172.202.44.182:48976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/admin.php"] [unique_id "amufdfW1Jl2-fgIeVvqdqwAAAOo"]
[Thu Jul 30 14:01:09.621365 2026] [security2:error] [pid 977210:tid 977328] [remote 57.141.0.40:43440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amufdfW1Jl2-fgIeVvqdtwAAnnM"]
[Thu Jul 30 14:01:10.209346 2026] [security2:error] [pid 977210:tid 977448] [client 20.203.148.31:48390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/edit.php"] [unique_id "amufdvW1Jl2-fgIeVvqdwQAAAO8"]
[Thu Jul 30 14:01:11.600535 2026] [core:notice] [pid 977210:tid 977347] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:11.986755 2026] [security2:error] [pid 977210:tid 977401] [client 172.202.44.182:46413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/admin.php"] [unique_id "amufd_W1Jl2-fgIeVvqd6QAAAMA"]
[Thu Jul 30 14:01:11.996157 2026] [security2:error] [pid 977210:tid 977219] [remote 216.73.217.142:6752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amufd_W1Jl2-fgIeVvqd6gAAugY"]
[Thu Jul 30 14:01:12.373056 2026] [core:notice] [pid 977210:tid 977346] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:12.454643 2026] [security2:error] [pid 977210:tid 977385] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufd_W1Jl2-fgIeVvqd4wAAsAo"]
[Thu Jul 30 14:01:13.003054 2026] [core:notice] [pid 977210:tid 977458] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:13.210057 2026] [security2:error] [pid 977210:tid 977409] [client 172.202.44.182:46261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/m.php"] [unique_id "amufefW1Jl2-fgIeVvqeEgAAAMg"]
[Thu Jul 30 14:01:13.323528 2026] [security2:error] [pid 977210:tid 977422] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufePW1Jl2-fgIeVvqd7AAA1RA"]
[Thu Jul 30 14:01:13.844173 2026] [security2:error] [pid 977210:tid 977407] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufefW1Jl2-fgIeVvqeDgAAxiM"]
[Thu Jul 30 14:01:14.054251 2026] [security2:error] [pid 977210:tid 977425] [client 181.116.200.68:17436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufevW1Jl2-fgIeVvqeOAAAANg"]
[Thu Jul 30 14:01:14.054362 2026] [security2:error] [pid 977210:tid 977425] [client 181.116.200.68:17436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufevW1Jl2-fgIeVvqeOAAAANg"]
[Thu Jul 30 14:01:14.059180 2026] [security2:error] [pid 977210:tid 977438] [client 103.242.199.184:59169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufevW1Jl2-fgIeVvqeOQAAAOU"]
[Thu Jul 30 14:01:14.059302 2026] [security2:error] [pid 977210:tid 977438] [client 103.242.199.184:59169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufevW1Jl2-fgIeVvqeOQAAAOU"]
[Thu Jul 30 14:01:14.629233 2026] [security2:error] [pid 977210:tid 977380] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufefW1Jl2-fgIeVvqeHgAAqyE"]
[Thu Jul 30 14:01:14.804770 2026] [security2:error] [pid 977210:tid 977387] [client 172.202.44.182:46259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amufevW1Jl2-fgIeVvqeQgAAALI"]
[Thu Jul 30 14:01:15.813344 2026] [security2:error] [pid 977210:tid 977300] [remote 82.130.249.15:60302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.249.130.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amufe_W1Jl2-fgIeVvqeagAA7lc"]
[Thu Jul 30 14:01:16.006573 2026] [security2:error] [pid 977210:tid 977442] [client 103.190.40.154:19202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuffPW1Jl2-fgIeVvqeawAAAOk"]
[Thu Jul 30 14:01:16.006730 2026] [security2:error] [pid 977210:tid 977442] [client 103.190.40.154:19202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuffPW1Jl2-fgIeVvqeawAAAOk"]
[Thu Jul 30 14:01:16.623845 2026] [security2:error] [pid 977210:tid 977380] [client 172.202.44.182:46251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/classwithtostring.php"] [unique_id "amuffPW1Jl2-fgIeVvqeegAAAKs"]
[Thu Jul 30 14:01:16.671012 2026] [security2:error] [pid 977210:tid 977435] [client 20.203.148.31:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/f35.php"] [unique_id "amuffPW1Jl2-fgIeVvqefwAAAOI"]
[Thu Jul 30 14:01:17.271360 2026] [core:notice] [pid 977210:tid 977342] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:17.654746 2026] [security2:error] [pid 977210:tid 977293] [remote 216.73.217.142:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amufffW1Jl2-fgIeVvqekwAA5lA"]
[Thu Jul 30 14:01:18.043987 2026] [security2:error] [pid 977210:tid 977389] [client 172.202.44.182:48987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/gmo.php"] [unique_id "amuffvW1Jl2-fgIeVvqenAAAALQ"]
[Thu Jul 30 14:01:18.095473 2026] [lsapi:error] [pid 977210:tid 977321] [remote 2a03:2880:f800:3:::0] [host allmontecristi.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1120; user ID 1120), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Thu Jul 30 14:01:18.106943 2026] [core:notice] [pid 977210:tid 977436] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:18.338857 2026] [security2:error] [pid 977210:tid 977441] [client 189.6.88.213:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuffvW1Jl2-fgIeVvqerQAAAOg"]
[Thu Jul 30 14:01:18.339013 2026] [security2:error] [pid 977210:tid 977441] [client 189.6.88.213:56652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuffvW1Jl2-fgIeVvqerQAAAOg"]
[Thu Jul 30 14:01:18.963295 2026] [security2:error] [pid 977210:tid 977411] [client 78.95.209.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuffvW1Jl2-fgIeVvqevAAAAMo"], referer: https://cnpinyin.com
[Thu Jul 30 14:01:19.398819 2026] [security2:error] [pid 977210:tid 977422] [client 172.202.44.182:46232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/languages/index.php"] [unique_id "amuff_W1Jl2-fgIeVvqeyQAAANU"]
[Thu Jul 30 14:01:20.724264 2026] [security2:error] [pid 977210:tid 977424] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuffvW1Jl2-fgIeVvqesAAAANc"]
[Thu Jul 30 14:01:20.761265 2026] [security2:error] [pid 977210:tid 977387] [client 172.202.44.182:13614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-the.php"] [unique_id "amufgPW1Jl2-fgIeVvqe7AAAALI"]
[Thu Jul 30 14:01:20.927849 2026] [security2:error] [pid 977210:tid 977466] [client 20.203.148.31:44465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/f7.php"] [unique_id "amufgPW1Jl2-fgIeVvqe9QAAAQE"]
[Thu Jul 30 14:01:21.572366 2026] [security2:error] [pid 977210:tid 977324] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amufgfW1Jl2-fgIeVvqe-QAAnm8"]
[Thu Jul 30 14:01:21.572560 2026] [security2:error] [pid 977210:tid 977367] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amufgfW1Jl2-fgIeVvqe-QAAnm8"]
[Thu Jul 30 14:01:21.999699 2026] [security2:error] [pid 977210:tid 977234] [remote 216.73.217.142:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amufgfW1Jl2-fgIeVvqfDQAA6hU"]
[Thu Jul 30 14:01:22.697360 2026] [security2:error] [pid 977210:tid 977372] [client 172.202.44.182:18078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/404.php"] [unique_id "amufgvW1Jl2-fgIeVvqfHAAAAKM"]
[Thu Jul 30 14:01:23.833272 2026] [security2:error] [pid 977210:tid 977365] [client 149.76.69.84:1043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "journeywomenscenter.org"] [uri "/wp-login.php"] [unique_id "amufg_W1Jl2-fgIeVvqfLgAAnBA"], referer: https://journeywomenscenter.org/wp-login.php?redirect_to=https%3A%2F%2Fjourneywomenscenter.org%2Fwp-admin%2F&reauth=1
[Thu Jul 30 14:01:23.850596 2026] [security2:error] [pid 977210:tid 977338] [remote 57.141.0.53:25434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/519416797/feed/rss2/"] [unique_id "amufg_W1Jl2-fgIeVvqfMgAAl30"]
[Thu Jul 30 14:01:24.497923 2026] [security2:error] [pid 977210:tid 977358] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufgvW1Jl2-fgIeVvqfEwAAlRY"]
[Thu Jul 30 14:01:24.599443 2026] [security2:error] [pid 977210:tid 977440] [client 172.202.44.182:46247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/init.php"] [unique_id "amufhPW1Jl2-fgIeVvqfSQAAAOc"]
[Thu Jul 30 14:01:24.629159 2026] [security2:error] [pid 977210:tid 977464] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufg_W1Jl2-fgIeVvqfKQAA_xc"]
[Thu Jul 30 14:01:24.633410 2026] [security2:error] [pid 977210:tid 977428] [client 181.116.200.68:60788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufhPW1Jl2-fgIeVvqfTQAAANs"]
[Thu Jul 30 14:01:24.633518 2026] [security2:error] [pid 977210:tid 977428] [client 181.116.200.68:60788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufhPW1Jl2-fgIeVvqfTQAAANs"]
[Thu Jul 30 14:01:24.863326 2026] [security2:error] [pid 977210:tid 977448] [client 103.242.199.184:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufhPW1Jl2-fgIeVvqfTgAAAO8"]
[Thu Jul 30 14:01:24.864057 2026] [security2:error] [pid 977210:tid 977448] [client 103.242.199.184:59944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufhPW1Jl2-fgIeVvqfTgAAAO8"]
[Thu Jul 30 14:01:24.973129 2026] [security2:error] [pid 977210:tid 977422] [client 74.7.175.158:37718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "optilexai.com"] [uri "/robots.txt"] [unique_id "amufhPW1Jl2-fgIeVvqfVgAAANU"]
[Thu Jul 30 14:01:25.208251 2026] [security2:error] [pid 977210:tid 977360] [client 74.7.175.158:37718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "optilexai.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amufhfW1Jl2-fgIeVvqfXgAAAJc"], referer: https://optilexai.com/robots.txt
[Thu Jul 30 14:01:25.233356 2026] [autoindex:error] [pid 977210:tid 977452] [client 50.6.43.217:0] AH01276: Cannot serve directory /home2/ojqudite/public_html/indexing-test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:01:25.537505 2026] [security2:error] [pid 977210:tid 977462] [client 172.202.44.182:18533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/file5.php"] [unique_id "amufhfW1Jl2-fgIeVvqfbQAAAP0"]
[Thu Jul 30 14:01:27.110596 2026] [security2:error] [pid 977210:tid 977369] [client 103.190.40.154:24959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufh_W1Jl2-fgIeVvqf5gAAAKA"]
[Thu Jul 30 14:01:27.110741 2026] [security2:error] [pid 977210:tid 977369] [client 103.190.40.154:24959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufh_W1Jl2-fgIeVvqf5gAAAKA"]
[Thu Jul 30 14:01:27.627568 2026] [security2:error] [pid 977210:tid 977326] [remote 216.73.217.142:6326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amufh_W1Jl2-fgIeVvqgCQAAqHE"]
[Thu Jul 30 14:01:28.093519 2026] [security2:error] [pid 977210:tid 977344] [client 172.202.44.182:18060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/maint/index.php"] [unique_id "amufiPW1Jl2-fgIeVvqgJQAAAIc"]
[Thu Jul 30 14:01:28.191460 2026] [security2:error] [pid 977210:tid 977431] [client 66.249.90.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufh_W1Jl2-fgIeVvqgBQAAAN4"]
[Thu Jul 30 14:01:29.012362 2026] [security2:error] [pid 977210:tid 977425] [client 189.6.88.213:57191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufifW1Jl2-fgIeVvqgbAAAANg"]
[Thu Jul 30 14:01:29.012467 2026] [security2:error] [pid 977210:tid 977425] [client 189.6.88.213:57191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufifW1Jl2-fgIeVvqgbAAAANg"]
[Thu Jul 30 14:01:29.353110 2026] [security2:error] [pid 977210:tid 977433] [client 172.202.44.182:13620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/shell.php"] [unique_id "amufifW1Jl2-fgIeVvqgigAAAOA"]
[Thu Jul 30 14:01:29.833190 2026] [security2:error] [pid 977210:tid 977327] [remote 72.167.132.114:47612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amufifW1Jl2-fgIeVvqhLgAA7XI"]
[Thu Jul 30 14:01:32.175305 2026] [security2:error] [pid 977210:tid 977249] [remote 57.141.0.33:35280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amufjPW1Jl2-fgIeVvqhgAAAkCQ"]
[Thu Jul 30 14:01:32.690584 2026] [security2:error] [pid 977210:tid 977393] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufjPW1Jl2-fgIeVvqhfwAAuCo"]
[Thu Jul 30 14:01:33.282045 2026] [security2:error] [pid 977210:tid 977373] [client 172.202.44.182:46429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/f35.php"] [unique_id "amufjfW1Jl2-fgIeVvqhmQAAAKQ"]
[Thu Jul 30 14:01:33.821549 2026] [core:error] [pid 977210:tid 977276] [remote 74.7.241.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:01:33.821576 2026] [core:error] [pid 977210:tid 977276] [remote 74.7.241.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:01:33.821740 2026] [security2:error] [pid 977210:tid 977378] [client 74.7.241.166:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.echomemoversalain.casa"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amufjfW1Jl2-fgIeVvqhqAAAqT8"]
[Thu Jul 30 14:01:34.034701 2026] [security2:error] [pid 977210:tid 977407] [client 157.245.60.239:63078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.60.245.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amufjvW1Jl2-fgIeVvqhrwAAAMY"]
[Thu Jul 30 14:01:34.604775 2026] [security2:error] [pid 977210:tid 977426] [client 172.202.44.182:31815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/new.php"] [unique_id "amufjvW1Jl2-fgIeVvqhugAAANk"]
[Thu Jul 30 14:01:35.233868 2026] [security2:error] [pid 977210:tid 977343] [client 181.116.200.68:15433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufj_W1Jl2-fgIeVvqhyQAAAIY"]
[Thu Jul 30 14:01:35.233999 2026] [security2:error] [pid 977210:tid 977343] [client 181.116.200.68:15433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufj_W1Jl2-fgIeVvqhyQAAAIY"]
[Thu Jul 30 14:01:35.489568 2026] [security2:error] [pid 977210:tid 977458] [client 103.242.199.184:60563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufj_W1Jl2-fgIeVvqhzwAAAPk"]
[Thu Jul 30 14:01:35.489686 2026] [security2:error] [pid 977210:tid 977458] [client 103.242.199.184:60563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufj_W1Jl2-fgIeVvqhzwAAAPk"]
[Thu Jul 30 14:01:37.511156 2026] [security2:error] [pid 977210:tid 977466] [client 172.202.44.182:18053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/adminfuns.php"] [unique_id "amufkfW1Jl2-fgIeVvqh-wAAAQE"]
[Thu Jul 30 14:01:37.590123 2026] [security2:error] [pid 977210:tid 977377] [client 103.190.40.154:11866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufkfW1Jl2-fgIeVvqh_QAAAKg"]
[Thu Jul 30 14:01:37.590263 2026] [security2:error] [pid 977210:tid 977377] [client 103.190.40.154:11866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufkfW1Jl2-fgIeVvqh_QAAAKg"]
[Thu Jul 30 14:01:37.961019 2026] [security2:error] [pid 977210:tid 977410] [client 172.237.109.114:1146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.dist"] [unique_id "amufkfW1Jl2-fgIeVvqiBAAAAMk"]
[Thu Jul 30 14:01:37.961696 2026] [security2:error] [pid 977210:tid 977378] [client 172.237.109.114:59220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.BAK"] [unique_id "amufkfW1Jl2-fgIeVvqiBQAAAKk"]
[Thu Jul 30 14:01:37.971711 2026] [security2:error] [pid 977210:tid 977391] [client 172.237.109.114:47547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.OLD"] [unique_id "amufkfW1Jl2-fgIeVvqiCQAAALY"]
[Thu Jul 30 14:01:37.971895 2026] [security2:error] [pid 977210:tid 977345] [client 172.237.109.114:48256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/.wp-config.php.swp"] [unique_id "amufkfW1Jl2-fgIeVvqiCAAAAIg"]
[Thu Jul 30 14:01:37.972178 2026] [security2:error] [pid 977210:tid 977443] [client 172.237.109.114:49531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-config-sample.php"] [unique_id "amufkfW1Jl2-fgIeVvqiCgAAAOo"]
[Thu Jul 30 14:01:37.972503 2026] [security2:error] [pid 977210:tid 977384] [client 172.237.109.114:17185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.txt"] [unique_id "amufkfW1Jl2-fgIeVvqiCwAAAK8"]
[Thu Jul 30 14:01:37.978072 2026] [security2:error] [pid 977210:tid 977454] [client 172.237.109.114:55581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.old"] [unique_id "amufkfW1Jl2-fgIeVvqiDQAAAPU"]
[Thu Jul 30 14:01:37.990101 2026] [security2:error] [pid 977210:tid 977416] [client 172.237.109.114:7958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-config.php"] [unique_id "amufkfW1Jl2-fgIeVvqiDgAAAM8"]
[Thu Jul 30 14:01:37.990835 2026] [security2:error] [pid 977210:tid 977387] [client 172.237.109.114:4937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.inc"] [unique_id "amufkfW1Jl2-fgIeVvqiDwAAALI"]
[Thu Jul 30 14:01:37.992650 2026] [security2:error] [pid 977210:tid 977424] [client 172.237.109.114:27890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-config.old"] [unique_id "amufkfW1Jl2-fgIeVvqiEAAAANc"]
[Thu Jul 30 14:01:38.009096 2026] [security2:error] [pid 977210:tid 977351] [client 172.237.109.114:17549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.swp"] [unique_id "amufkvW1Jl2-fgIeVvqiEwAAAI4"]
[Thu Jul 30 14:01:38.009451 2026] [security2:error] [pid 977210:tid 977457] [client 172.237.109.114:4187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.bak"] [unique_id "amufkvW1Jl2-fgIeVvqiFAAAAPg"]
[Thu Jul 30 14:01:38.499269 2026] [security2:error] [pid 977210:tid 977397] [client 172.237.109.114:61930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amufkfW1Jl2-fgIeVvqiEgAAALw"]
[Thu Jul 30 14:01:38.548926 2026] [security2:error] [pid 977210:tid 977350] [client 172.237.109.114:36430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amufkfW1Jl2-fgIeVvqiEQAAAI0"]
[Thu Jul 30 14:01:38.894268 2026] [security2:error] [pid 977210:tid 977366] [client 157.245.60.239:64293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.60.245.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amufkvW1Jl2-fgIeVvqiJgAAAJ0"]
[Thu Jul 30 14:01:38.961354 2026] [security2:error] [pid 977210:tid 977361] [client 172.237.109.114:32180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.html"] [unique_id "amufkvW1Jl2-fgIeVvqiKgAAAJg"]
[Thu Jul 30 14:01:38.967873 2026] [security2:error] [pid 977210:tid 977436] [client 172.237.109.114:65150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php-backup"] [unique_id "amufkvW1Jl2-fgIeVvqiKwAAAOM"]
[Thu Jul 30 14:01:38.971109 2026] [security2:error] [pid 977210:tid 977396] [client 172.237.109.114:11338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php~"] [unique_id "amufkvW1Jl2-fgIeVvqiLAAAALs"]
[Thu Jul 30 14:01:38.977067 2026] [security2:error] [pid 977210:tid 977399] [client 172.237.109.114:28791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.SAVE"] [unique_id "amufkvW1Jl2-fgIeVvqiLgAAAL4"]
[Thu Jul 30 14:01:39.010630 2026] [security2:error] [pid 977210:tid 977434] [client 172.237.109.114:63804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.save"] [unique_id "amufk_W1Jl2-fgIeVvqiMgAAAOE"]
[Thu Jul 30 14:01:39.212353 2026] [security2:error] [pid 977210:tid 977382] [client 172.202.44.182:18554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/fm.php"] [unique_id "amufk_W1Jl2-fgIeVvqiOQAAAK0"]
[Thu Jul 30 14:01:39.391686 2026] [security2:error] [pid 977210:tid 977353] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufk_W1Jl2-fgIeVvqiOAAAAJA"]
[Thu Jul 30 14:01:39.391718 2026] [security2:error] [pid 977210:tid 977353] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufk_W1Jl2-fgIeVvqiOAAAAJA"]
[Thu Jul 30 14:01:39.455177 2026] [security2:error] [pid 977210:tid 977417] [client 172.237.109.114:9804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amufkvW1Jl2-fgIeVvqiLQAAANA"]
[Thu Jul 30 14:01:39.510709 2026] [security2:error] [pid 977210:tid 977408] [client 82.102.18.180:38836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/ALFA_DATA/"] [unique_id "amufk_W1Jl2-fgIeVvqiNgAAAMc"]
[Thu Jul 30 14:01:40.386751 2026] [security2:error] [pid 977210:tid 977350] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuflPW1Jl2-fgIeVvqiUwAAAI0"]
[Thu Jul 30 14:01:40.386780 2026] [security2:error] [pid 977210:tid 977350] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuflPW1Jl2-fgIeVvqiUwAAAI0"]
[Thu Jul 30 14:01:40.387128 2026] [security2:error] [pid 977210:tid 977394] [client 82.102.18.180:38836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/.well-knownold/"] [unique_id "amuflPW1Jl2-fgIeVvqiUQAAALk"]
[Thu Jul 30 14:01:40.414051 2026] [core:error] [pid 977210:tid 977445] [client 66.249.73.14:54977] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:01:40.414074 2026] [core:error] [pid 977210:tid 977445] [client 66.249.73.14:54977] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:01:41.330492 2026] [security2:error] [pid 977210:tid 977444] [client 185.191.171.2:49982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/28/pesquisadores-brasileiros-descobrem-linhagens-ineditas-da-omicron-no-pais/"] [unique_id "amuflfW1Jl2-fgIeVvqicAAAAOs"]
[Thu Jul 30 14:01:41.330657 2026] [security2:error] [pid 977210:tid 977444] [client 185.191.171.2:49982] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/28/pesquisadores-brasileiros-descobrem-linhagens-ineditas-da-omicron-no-pais/"] [unique_id "amuflfW1Jl2-fgIeVvqicAAAAOs"]
[Thu Jul 30 14:01:41.435568 2026] [autoindex:error] [pid 977210:tid 977347] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:01:41.436239 2026] [security2:error] [pid 977210:tid 977347] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuflfW1Jl2-fgIeVvqidAAAAIo"]
[Thu Jul 30 14:01:41.436693 2026] [security2:error] [pid 977210:tid 977465] [client 82.102.18.180:38836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/.well-known/acme-challenge/"] [unique_id "amuflfW1Jl2-fgIeVvqicgAAAQA"]
[Thu Jul 30 14:01:41.643878 2026] [security2:error] [pid 977210:tid 977411] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuflfW1Jl2-fgIeVvqiZQAAyj4"]
[Thu Jul 30 14:01:41.751609 2026] [security2:error] [pid 977210:tid 977413] [client 172.202.44.182:46433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/file.php"] [unique_id "amuflfW1Jl2-fgIeVvqigwAAAMw"]
[Thu Jul 30 14:01:42.920545 2026] [security2:error] [pid 977210:tid 977463] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuflvW1Jl2-fgIeVvqijQAA_jM"]
[Thu Jul 30 14:01:43.352256 2026] [security2:error] [pid 977210:tid 977358] [client 172.202.44.182:31826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/bolt.php"] [unique_id "amufl_W1Jl2-fgIeVvqirQAAAJU"]
[Thu Jul 30 14:01:44.567778 2026] [security2:error] [pid 977210:tid 977386] [client 172.202.44.182:46442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/3.php"] [unique_id "amufmPW1Jl2-fgIeVvqixQAAALE"]
[Thu Jul 30 14:01:45.683136 2026] [security2:error] [pid 977210:tid 977452] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufmfW1Jl2-fgIeVvqi1AAAAPM"]
[Thu Jul 30 14:01:45.687629 2026] [security2:error] [pid 977210:tid 977240] [remote 47.128.117.240:24510] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amufmfW1Jl2-fgIeVvqi4AAA0Rs"], referer: https://blackrockanimalhospital.com/robots.txt
[Thu Jul 30 14:01:45.714883 2026] [security2:error] [pid 977210:tid 977399] [client 172.202.44.182:46418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/222.php"] [unique_id "amufmfW1Jl2-fgIeVvqi4QAAAL4"]
[Thu Jul 30 14:01:45.856517 2026] [security2:error] [pid 977210:tid 977444] [client 181.116.200.68:30484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufmfW1Jl2-fgIeVvqi6AAAAOs"]
[Thu Jul 30 14:01:45.857287 2026] [security2:error] [pid 977210:tid 977444] [client 181.116.200.68:30484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufmfW1Jl2-fgIeVvqi6AAAAOs"]
[Thu Jul 30 14:01:46.240630 2026] [security2:error] [pid 977210:tid 977426] [client 103.242.199.184:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufmvW1Jl2-fgIeVvqi9QAAANk"]
[Thu Jul 30 14:01:46.240738 2026] [security2:error] [pid 977210:tid 977426] [client 103.242.199.184:61127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufmvW1Jl2-fgIeVvqi9QAAANk"]
[Thu Jul 30 14:01:46.506713 2026] [core:notice] [pid 977210:tid 977244] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:46.942542 2026] [core:notice] [pid 977210:tid 977249] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:47.028884 2026] [security2:error] [pid 977210:tid 977343] [client 172.202.44.182:18498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/images/admin.php"] [unique_id "amufm_W1Jl2-fgIeVvqjEwAAAIY"]
[Thu Jul 30 14:01:47.589849 2026] [core:notice] [pid 977210:tid 977418] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:48.199363 2026] [core:notice] [pid 977210:tid 977400] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:48.224108 2026] [security2:error] [pid 977210:tid 977300] [remote 203.134.193.134:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.193.134.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amufnPW1Jl2-fgIeVvqjNgAAqlc"]
[Thu Jul 30 14:01:48.386124 2026] [security2:error] [pid 977210:tid 977380] [client 103.190.40.154:18624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufnPW1Jl2-fgIeVvqjPQAAAKs"]
[Thu Jul 30 14:01:48.386284 2026] [security2:error] [pid 977210:tid 977380] [client 103.190.40.154:18624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufnPW1Jl2-fgIeVvqjPQAAAKs"]
[Thu Jul 30 14:01:49.077790 2026] [core:notice] [pid 977210:tid 977351] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:49.270562 2026] [security2:error] [pid 977210:tid 977460] [client 43.167.157.80:40808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.157.167.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amufnfW1Jl2-fgIeVvqjTAAAAPs"]
[Thu Jul 30 14:01:49.986690 2026] [security2:error] [pid 977210:tid 977449] [client 184.75.223.227:33800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amufnfW1Jl2-fgIeVvqjZQAAAPA"]
[Thu Jul 30 14:01:49.986774 2026] [security2:error] [pid 977210:tid 977449] [client 184.75.223.227:33800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amufnfW1Jl2-fgIeVvqjZQAAAPA"]
[Thu Jul 30 14:01:50.038538 2026] [security2:error] [pid 977210:tid 977421] [client 172.202.44.182:46447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amufnvW1Jl2-fgIeVvqjZgAAANQ"]
[Thu Jul 30 14:01:50.239618 2026] [security2:error] [pid 977210:tid 977403] [client 157.245.60.239:65442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.60.245.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amufnvW1Jl2-fgIeVvqjawAAAMI"]
[Thu Jul 30 14:01:50.579544 2026] [security2:error] [pid 977210:tid 977367] [client 189.6.88.213:58238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufnvW1Jl2-fgIeVvqjdgAAAJ4"]
[Thu Jul 30 14:01:50.579664 2026] [security2:error] [pid 977210:tid 977367] [client 189.6.88.213:58238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufnvW1Jl2-fgIeVvqjdgAAAJ4"]
[Thu Jul 30 14:01:51.519287 2026] [security2:error] [pid 977210:tid 977433] [client 172.202.44.182:18557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/admin.php"] [unique_id "amufn_W1Jl2-fgIeVvqjigAAAOA"]
[Thu Jul 30 14:01:51.530944 2026] [core:notice] [pid 977210:tid 977463] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:52.672258 2026] [security2:error] [pid 977210:tid 977278] [remote 52.167.144.23:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/5077"] [unique_id "amufoPW1Jl2-fgIeVvqjqQAAkEE"]
[Thu Jul 30 14:01:52.699905 2026] [security2:error] [pid 977210:tid 977380] [client 172.202.44.182:46410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-configs.php"] [unique_id "amufoPW1Jl2-fgIeVvqjqgAAAKs"]
[Thu Jul 30 14:01:53.052363 2026] [security2:error] [pid 977210:tid 977349] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufoPW1Jl2-fgIeVvqjoQAAAIw"]
[Thu Jul 30 14:01:53.227726 2026] [security2:error] [pid 977210:tid 977446] [client 64.42.179.51:33996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amufofW1Jl2-fgIeVvqjtAAAAO0"]
[Thu Jul 30 14:01:53.227864 2026] [security2:error] [pid 977210:tid 977446] [client 64.42.179.51:33996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amufofW1Jl2-fgIeVvqjtAAAAO0"]
[Thu Jul 30 14:01:53.947587 2026] [security2:error] [pid 977210:tid 977398] [client 172.202.44.182:46450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/php.php"] [unique_id "amufofW1Jl2-fgIeVvqj4QAAAL0"]
[Thu Jul 30 14:01:54.423841 2026] [security2:error] [pid 977210:tid 977380] [client 54.235.158.162:19473] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/unnamed-4-400x266@2x.jpg"] [unique_id "amufovW1Jl2-fgIeVvqj-gAAAKs"]
[Thu Jul 30 14:01:54.613530 2026] [core:notice] [pid 977210:tid 977364] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:54.710164 2026] [security2:error] [pid 977210:tid 977439] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufovW1Jl2-fgIeVvqj5wAA5nE"]
[Thu Jul 30 14:01:55.173109 2026] [security2:error] [pid 977210:tid 977410] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufovW1Jl2-fgIeVvqkAwAAyQY"]
[Thu Jul 30 14:01:56.439310 2026] [security2:error] [pid 977210:tid 977371] [client 181.116.200.68:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufpPW1Jl2-fgIeVvqkPQAAAKI"]
[Thu Jul 30 14:01:56.439425 2026] [security2:error] [pid 977210:tid 977371] [client 181.116.200.68:54933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufpPW1Jl2-fgIeVvqkPQAAAKI"]
[Thu Jul 30 14:01:56.532294 2026] [security2:error] [pid 977210:tid 977388] [client 74.7.175.136:54348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-b4577515.jvc.nyx.temporary.site"] [uri "/index.php"] [unique_id "amufo_W1Jl2-fgIeVvqkGwAAsz0"]
[Thu Jul 30 14:01:56.737404 2026] [core:notice] [pid 977210:tid 977386] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:56.770202 2026] [security2:error] [pid 977210:tid 977400] [client 172.202.44.182:31817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/index.php"] [unique_id "amufpPW1Jl2-fgIeVvqkSQAAAL8"]
[Thu Jul 30 14:01:56.882693 2026] [security2:error] [pid 977210:tid 977370] [client 103.242.199.184:61679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufpPW1Jl2-fgIeVvqkVgAAAKE"]
[Thu Jul 30 14:01:56.882818 2026] [security2:error] [pid 977210:tid 977370] [client 103.242.199.184:61679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufpPW1Jl2-fgIeVvqkVgAAAKE"]
[Thu Jul 30 14:01:57.078689 2026] [security2:error] [pid 977210:tid 977383] [client 47.128.17.11:48452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amufpfW1Jl2-fgIeVvqkWwAAAK4"]
[Thu Jul 30 14:01:57.783361 2026] [security2:error] [pid 977210:tid 977468] [client 117.186.142.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amufpPW1Jl2-fgIeVvqkVAAAAQM"], referer: https://tereashops.com/wp-json/wp/v2/product/3335
[Thu Jul 30 14:01:57.894722 2026] [security2:error] [pid 977210:tid 977250] [remote 74.7.243.224:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/js/stafff.php"] [unique_id "amufpfW1Jl2-fgIeVvqkdwAAniU"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/js/bootstrap.bundle.min.js
[Thu Jul 30 14:01:58.003939 2026] [security2:error] [pid 977210:tid 977358] [client 128.140.41.193:30946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amufpvW1Jl2-fgIeVvqkgQAAAJU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:01:58.366891 2026] [core:notice] [pid 977210:tid 977445] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:58.372294 2026] [security2:error] [pid 977210:tid 977445] [client 128.140.41.193:30952] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amufpvW1Jl2-fgIeVvqkiwAAAOw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:01:58.426600 2026] [core:notice] [pid 977210:tid 977361] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:58.475002 2026] [security2:error] [pid 977210:tid 977426] [client 98.84.70.201:53298] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/unnamed-4-90x60@2x.jpg"] [unique_id "amufpvW1Jl2-fgIeVvqklQAAANk"]
[Thu Jul 30 14:01:58.488809 2026] [security2:error] [pid 977210:tid 977410] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufpfW1Jl2-fgIeVvqkaAAAyVA"]
[Thu Jul 30 14:01:58.528487 2026] [security2:error] [pid 977210:tid 977359] [client 172.202.44.182:13606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/a.php"] [unique_id "amufpvW1Jl2-fgIeVvqklwAAAJY"]
[Thu Jul 30 14:01:58.763536 2026] [security2:error] [pid 977210:tid 977355] [client 128.140.41.193:30964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amufpvW1Jl2-fgIeVvqktAAAAJI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:01:58.826564 2026] [security2:error] [pid 977210:tid 977316] [remote 52.167.144.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/173/index.php/jipkl/about/editorialteam"] [unique_id "amufpvW1Jl2-fgIeVvqktQAA4Gc"]
[Thu Jul 30 14:01:58.899422 2026] [core:notice] [pid 977210:tid 977348] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:01:59.131610 2026] [security2:error] [pid 977210:tid 977295] [remote 20.87.239.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ciunews.com"] [uri "/xmlrpc.php"] [unique_id "amufp_W1Jl2-fgIeVvqkwgAA5VI"]
[Thu Jul 30 14:01:59.131792 2026] [security2:error] [pid 977210:tid 977438] [client 20.87.239.85:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ciunews.com"] [uri "/xmlrpc.php"] [unique_id "amufp_W1Jl2-fgIeVvqkwgAA5VI"]
[Thu Jul 30 14:01:59.239072 2026] [security2:error] [pid 977210:tid 977432] [client 103.190.40.154:19115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufp_W1Jl2-fgIeVvqkzgAAAN8"]
[Thu Jul 30 14:01:59.239203 2026] [security2:error] [pid 977210:tid 977432] [client 103.190.40.154:19115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufp_W1Jl2-fgIeVvqkzgAAAN8"]
[Thu Jul 30 14:01:59.299520 2026] [security2:error] [pid 977210:tid 977442] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufpfW1Jl2-fgIeVvqkdAAA6U0"]
[Thu Jul 30 14:01:59.700734 2026] [security2:error] [pid 977210:tid 977430] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufpvW1Jl2-fgIeVvqkpgAA3QI"]
[Thu Jul 30 14:02:00.819904 2026] [security2:error] [pid 977210:tid 977441] [client 172.202.44.182:46455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/Text/about.php"] [unique_id "amufqPW1Jl2-fgIeVvqlBgAAAOg"]
[Thu Jul 30 14:02:01.798174 2026] [security2:error] [pid 977210:tid 977338] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amufqfW1Jl2-fgIeVvqlPQABAn0"]
[Thu Jul 30 14:02:01.798375 2026] [security2:error] [pid 977210:tid 977467] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amufqfW1Jl2-fgIeVvqlPQABAn0"]
[Thu Jul 30 14:02:01.960953 2026] [security2:error] [pid 977210:tid 977434] [client 172.202.44.182:13608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin.php"] [unique_id "amufqfW1Jl2-fgIeVvqlRQAAAOE"]
[Thu Jul 30 14:02:02.886770 2026] [core:notice] [pid 977210:tid 977313] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:02.964165 2026] [security2:error] [pid 977210:tid 977417] [client 172.237.109.114:59883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/config.php.new"] [unique_id "amufqvW1Jl2-fgIeVvqlkQAAANA"]
[Thu Jul 30 14:02:02.973143 2026] [security2:error] [pid 977210:tid 977416] [client 172.237.109.114:56683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.bk"] [unique_id "amufqvW1Jl2-fgIeVvqllAAAAM8"]
[Thu Jul 30 14:02:02.973358 2026] [security2:error] [pid 977210:tid 977402] [client 172.237.109.114:41168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/common/config.php.new"] [unique_id "amufqvW1Jl2-fgIeVvqlkgAAAME"]
[Thu Jul 30 14:02:02.973386 2026] [security2:error] [pid 977210:tid 977352] [client 172.237.109.114:2266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-config.php_orig"] [unique_id "amufqvW1Jl2-fgIeVvqlkwAAAI8"]
[Thu Jul 30 14:02:02.975154 2026] [security2:error] [pid 977210:tid 977413] [client 172.237.109.114:43418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/config.php.zip"] [unique_id "amufqvW1Jl2-fgIeVvqllgAAAMw"]
[Thu Jul 30 14:02:02.992926 2026] [security2:error] [pid 977210:tid 977410] [client 172.237.109.114:31916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.orig"] [unique_id "amufqvW1Jl2-fgIeVvqlmAAAAMk"]
[Thu Jul 30 14:02:02.994219 2026] [security2:error] [pid 977210:tid 977407] [client 172.237.109.114:51993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/config.php.tar.gz"] [unique_id "amufqvW1Jl2-fgIeVvqlmgAAAMY"]
[Thu Jul 30 14:02:02.994621 2026] [security2:error] [pid 977210:tid 977430] [client 172.237.109.114:14136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-config.backup"] [unique_id "amufqvW1Jl2-fgIeVvqllwAAAN0"]
[Thu Jul 30 14:02:03.012561 2026] [security2:error] [pid 977210:tid 977384] [client 172.237.109.114:30918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.original"] [unique_id "amufq_W1Jl2-fgIeVvqlnAAAAK8"]
[Thu Jul 30 14:02:03.263655 2026] [security2:error] [pid 977210:tid 977462] [client 172.202.44.182:50969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/size.php"] [unique_id "amufq_W1Jl2-fgIeVvqlpAAAAP0"]
[Thu Jul 30 14:02:03.474312 2026] [security2:error] [pid 977210:tid 977436] [client 172.237.109.114:52311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amufqvW1Jl2-fgIeVvqllQAAAOM"]
[Thu Jul 30 14:02:03.507842 2026] [security2:error] [pid 977210:tid 977419] [client 172.237.109.114:55237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amufqvW1Jl2-fgIeVvqlmQAAANI"]
[Thu Jul 30 14:02:03.541930 2026] [core:notice] [pid 977210:tid 977421] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:03.601911 2026] [security2:error] [pid 977210:tid 977374] [client 172.237.109.114:28527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amufq_W1Jl2-fgIeVvqlmwAAAKU"]
[Thu Jul 30 14:02:03.824797 2026] [security2:error] [pid 977210:tid 977358] [client 20.104.16.169:36103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amufq_W1Jl2-fgIeVvqlsgAAAJU"]
[Thu Jul 30 14:02:03.825333 2026] [security2:error] [pid 977210:tid 977358] [client 20.104.16.169:36103] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amufq_W1Jl2-fgIeVvqlsgAAAJU"]
[Thu Jul 30 14:02:04.097205 2026] [core:notice] [pid 977210:tid 977321] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.132496 2026] [core:notice] [pid 977210:tid 977281] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.273687 2026] [core:notice] [pid 977210:tid 977335] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.275188 2026] [core:notice] [pid 977210:tid 977268] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.281742 2026] [core:notice] [pid 977210:tid 977286] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.291901 2026] [core:notice] [pid 977210:tid 977333] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.299196 2026] [core:notice] [pid 977210:tid 977272] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.311890 2026] [core:notice] [pid 977210:tid 977291] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.313677 2026] [core:notice] [pid 977210:tid 977305] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.313715 2026] [core:notice] [pid 977210:tid 977304] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.357574 2026] [core:notice] [pid 977210:tid 977323] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.359302 2026] [core:notice] [pid 977210:tid 977292] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.388887 2026] [core:notice] [pid 977210:tid 977289] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.393823 2026] [core:notice] [pid 977210:tid 977332] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.409876 2026] [core:notice] [pid 977210:tid 977334] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.442348 2026] [core:notice] [pid 977210:tid 977340] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.529041 2026] [core:notice] [pid 977210:tid 977245] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.662260 2026] [core:notice] [pid 977210:tid 977310] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.664455 2026] [core:notice] [pid 977210:tid 977216] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:04.820019 2026] [core:notice] [pid 977210:tid 977224] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:05.433067 2026] [security2:error] [pid 977210:tid 977440] [client 191.232.199.39:10112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wk/index.php"] [unique_id "amufrfW1Jl2-fgIeVvql7wAAAOc"]
[Thu Jul 30 14:02:05.576586 2026] [core:notice] [pid 977210:tid 977362] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:05.735750 2026] [core:notice] [pid 977210:tid 977242] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:05.745995 2026] [core:notice] [pid 977210:tid 977237] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:05.776013 2026] [security2:error] [pid 977210:tid 977448] [client 20.104.16.169:36139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amufrfW1Jl2-fgIeVvql-AAAAO8"]
[Thu Jul 30 14:02:05.776106 2026] [security2:error] [pid 977210:tid 977448] [client 20.104.16.169:36139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amufrfW1Jl2-fgIeVvql-AAAAO8"]
[Thu Jul 30 14:02:05.781773 2026] [core:notice] [pid 977210:tid 977227] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:05.880870 2026] [core:notice] [pid 977210:tid 977228] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:05.890168 2026] [core:notice] [pid 977210:tid 977324] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:05.938011 2026] [security2:error] [pid 977210:tid 977372] [client 172.202.44.182:46416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/wp-class.php"] [unique_id "amufrfW1Jl2-fgIeVvqmAwAAAKM"]
[Thu Jul 30 14:02:06.199336 2026] [core:notice] [pid 977210:tid 977258] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:06.383081 2026] [core:notice] [pid 977210:tid 977254] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:06.563568 2026] [core:notice] [pid 977210:tid 977225] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:06.588322 2026] [core:notice] [pid 977210:tid 977241] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:06.593168 2026] [core:notice] [pid 977210:tid 977218] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:06.882609 2026] [core:notice] [pid 977210:tid 977236] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:07.094889 2026] [core:notice] [pid 977210:tid 977344] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:07.096900 2026] [security2:error] [pid 977210:tid 977344] [client 74.7.228.33:54300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "nordeste1.com"] [uri "/robots.txt"] [unique_id "amufr_W1Jl2-fgIeVvqmJAAAAIc"]
[Thu Jul 30 14:02:07.116927 2026] [core:notice] [pid 977210:tid 977312] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:07.139420 2026] [security2:error] [pid 977210:tid 977382] [client 181.116.200.68:17898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufr_W1Jl2-fgIeVvqmJgAAAK0"]
[Thu Jul 30 14:02:07.139516 2026] [security2:error] [pid 977210:tid 977382] [client 181.116.200.68:17898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufr_W1Jl2-fgIeVvqmJgAAAK0"]
[Thu Jul 30 14:02:07.184898 2026] [security2:error] [pid 977210:tid 977446] [client 172.202.44.182:46460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/403.php"] [unique_id "amufr_W1Jl2-fgIeVvqmJwAAAO0"]
[Thu Jul 30 14:02:07.278545 2026] [security2:error] [pid 977210:tid 977439] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufrvW1Jl2-fgIeVvqmFAAAAOY"]
[Thu Jul 30 14:02:07.280985 2026] [cgid:error] [pid 977210:tid 977346] [client 82.102.18.180:0] AH01265: stderr from /home2/xsygzjte/public_html/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 14:02:07.281637 2026] [security2:error] [pid 977210:tid 977346] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amufr_W1Jl2-fgIeVvqmLgAAAIk"]
[Thu Jul 30 14:02:07.282095 2026] [security2:error] [pid 977210:tid 977356] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-bin/"] [unique_id "amufr_W1Jl2-fgIeVvqmLAAAAJM"]
[Thu Jul 30 14:02:07.313296 2026] [security2:error] [pid 977210:tid 977415] [client 20.104.16.169:36107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/xstelth.php"] [unique_id "amufr_W1Jl2-fgIeVvqmLwAAAM4"]
[Thu Jul 30 14:02:07.313390 2026] [security2:error] [pid 977210:tid 977415] [client 20.104.16.169:36107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/xstelth.php"] [unique_id "amufr_W1Jl2-fgIeVvqmLwAAAM4"]
[Thu Jul 30 14:02:07.522060 2026] [security2:error] [pid 977210:tid 977414] [client 103.242.199.184:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufr_W1Jl2-fgIeVvqmNwAAAM0"]
[Thu Jul 30 14:02:07.522179 2026] [security2:error] [pid 977210:tid 977414] [client 103.242.199.184:62238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufr_W1Jl2-fgIeVvqmNwAAAM0"]
[Thu Jul 30 14:02:07.537563 2026] [core:notice] [pid 977210:tid 977364] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:07.539803 2026] [security2:error] [pid 977210:tid 977364] [client 74.7.228.33:57032] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amufr_W1Jl2-fgIeVvqmOAAAAJs"], referer: http://nordeste1.com/robots.txt
[Thu Jul 30 14:02:07.581288 2026] [core:notice] [pid 977210:tid 977246] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:07.598232 2026] [core:error] [pid 977210:tid 977419] [client 74.7.175.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:07.598252 2026] [core:error] [pid 977210:tid 977419] [client 74.7.175.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:07.598386 2026] [security2:error] [pid 977210:tid 977419] [client 74.7.175.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.hvacairductscleaners.us"] [uri "/___proxy_subdomain_cpanel/website_141a2c45/index.php"] [unique_id "amufr_W1Jl2-fgIeVvqmPAAAANI"]
[Thu Jul 30 14:02:07.599066 2026] [security2:error] [pid 977210:tid 977406] [client 74.7.175.172:60380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.hvacairductscleaners.us"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amufr_W1Jl2-fgIeVvqmOgAAxUI"]
[Thu Jul 30 14:02:07.626703 2026] [security2:error] [pid 977210:tid 977453] [client 74.7.241.153:52442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.jvc.nyx.temporary.site"] [uri "/index.php"] [unique_id "amufr_W1Jl2-fgIeVvqmKwAA9Cw"]
[Thu Jul 30 14:02:07.694388 2026] [security2:error] [pid 977210:tid 977229] [remote 57.141.0.1:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap13.xml"] [unique_id "amufr_W1Jl2-fgIeVvqmPgAAtBA"]
[Thu Jul 30 14:02:07.943425 2026] [security2:error] [pid 977210:tid 977418] [client 191.232.199.39:9381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/av.php"] [unique_id "amufr_W1Jl2-fgIeVvqmSAAAANE"]
[Thu Jul 30 14:02:07.965521 2026] [security2:error] [pid 977210:tid 977384] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufr_W1Jl2-fgIeVvqmQQAAAK8"]
[Thu Jul 30 14:02:07.965572 2026] [security2:error] [pid 977210:tid 977384] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufr_W1Jl2-fgIeVvqmQQAAAK8"]
[Thu Jul 30 14:02:08.083481 2026] [security2:error] [pid 977210:tid 977468] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index/"] [unique_id "amufr_W1Jl2-fgIeVvqmPwAAAQM"]
[Thu Jul 30 14:02:08.393406 2026] [security2:error] [pid 977210:tid 977430] [client 20.104.16.169:36157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/584062352875874akp.php"] [unique_id "amufsPW1Jl2-fgIeVvqmUwAAAN0"]
[Thu Jul 30 14:02:08.393507 2026] [security2:error] [pid 977210:tid 977430] [client 20.104.16.169:36157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/584062352875874akp.php"] [unique_id "amufsPW1Jl2-fgIeVvqmUwAAAN0"]
[Thu Jul 30 14:02:08.413702 2026] [security2:error] [pid 977210:tid 977378] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amufsPW1Jl2-fgIeVvqmVgAAAKk"]
[Thu Jul 30 14:02:08.413834 2026] [security2:error] [pid 977210:tid 977378] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amufsPW1Jl2-fgIeVvqmVgAAAKk"]
[Thu Jul 30 14:02:08.456477 2026] [security2:error] [pid 977210:tid 977362] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amufsPW1Jl2-fgIeVvqmWQAAAJk"]
[Thu Jul 30 14:02:08.456572 2026] [security2:error] [pid 977210:tid 977362] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amufsPW1Jl2-fgIeVvqmWQAAAJk"]
[Thu Jul 30 14:02:08.597984 2026] [security2:error] [pid 977210:tid 977459] [client 172.202.44.182:18559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amufsPW1Jl2-fgIeVvqmXQAAAPo"]
[Thu Jul 30 14:02:08.738867 2026] [security2:error] [pid 977210:tid 977251] [remote 5.161.62.209:4532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.nxt.udi.temporary.site"] [uri "/.env"] [unique_id "amufsPW1Jl2-fgIeVvqmXgAA-SY"]
[Thu Jul 30 14:02:08.777998 2026] [security2:error] [pid 977210:tid 977449] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amufsPW1Jl2-fgIeVvqmXwAAAPA"]
[Thu Jul 30 14:02:08.778098 2026] [security2:error] [pid 977210:tid 977449] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amufsPW1Jl2-fgIeVvqmXwAAAPA"]
[Thu Jul 30 14:02:08.907935 2026] [security2:error] [pid 977210:tid 977398] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amufsPW1Jl2-fgIeVvqmZgAAAL0"]
[Thu Jul 30 14:02:08.908055 2026] [security2:error] [pid 977210:tid 977398] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amufsPW1Jl2-fgIeVvqmZgAAAL0"]
[Thu Jul 30 14:02:09.107582 2026] [security2:error] [pid 977210:tid 977343] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/3PJcpMFsD8B.php"] [unique_id "amufsfW1Jl2-fgIeVvqmbgAAAIY"]
[Thu Jul 30 14:02:09.107661 2026] [security2:error] [pid 977210:tid 977343] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/3PJcpMFsD8B.php"] [unique_id "amufsfW1Jl2-fgIeVvqmbgAAAIY"]
[Thu Jul 30 14:02:09.363055 2026] [core:notice] [pid 977210:tid 977263] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:09.418403 2026] [security2:error] [pid 977210:tid 977381] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/bootstrap.php"] [unique_id "amufsfW1Jl2-fgIeVvqmdAAAAKw"]
[Thu Jul 30 14:02:09.418512 2026] [security2:error] [pid 977210:tid 977381] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/bootstrap.php"] [unique_id "amufsfW1Jl2-fgIeVvqmdAAAAKw"]
[Thu Jul 30 14:02:09.419075 2026] [security2:error] [pid 977210:tid 977405] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/err.php"] [unique_id "amufsfW1Jl2-fgIeVvqmdgAAAMQ"]
[Thu Jul 30 14:02:09.419164 2026] [security2:error] [pid 977210:tid 977405] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/err.php"] [unique_id "amufsfW1Jl2-fgIeVvqmdgAAAMQ"]
[Thu Jul 30 14:02:09.607008 2026] [security2:error] [pid 977210:tid 977419] [client 172.202.44.182:13613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/as.php"] [unique_id "amufsfW1Jl2-fgIeVvqmfwAAANI"]
[Thu Jul 30 14:02:09.674058 2026] [security2:error] [pid 977210:tid 977465] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufsfW1Jl2-fgIeVvqmfAAAAQA"]
[Thu Jul 30 14:02:09.674097 2026] [security2:error] [pid 977210:tid 977465] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufsfW1Jl2-fgIeVvqmfAAAAQA"]
[Thu Jul 30 14:02:09.674415 2026] [security2:error] [pid 977210:tid 977376] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/id/"] [unique_id "amufsfW1Jl2-fgIeVvqmegAAAKc"]
[Thu Jul 30 14:02:09.703912 2026] [security2:error] [pid 977210:tid 977353] [client 20.104.16.169:36140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/newfile.php"] [unique_id "amufsfW1Jl2-fgIeVvqmggAAAJA"]
[Thu Jul 30 14:02:09.704035 2026] [security2:error] [pid 977210:tid 977353] [client 20.104.16.169:36140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/newfile.php"] [unique_id "amufsfW1Jl2-fgIeVvqmggAAAJA"]
[Thu Jul 30 14:02:09.821282 2026] [security2:error] [pid 977210:tid 977444] [client 74.7.228.29:60558] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jvc.nyx.temporary.site"] [uri "/index.php"] [unique_id "amufsfW1Jl2-fgIeVvqmfQAA6wo"]
[Thu Jul 30 14:02:09.920362 2026] [security2:error] [pid 977210:tid 977461] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-blog-header.php"] [unique_id "amufsfW1Jl2-fgIeVvqmgwAAAPw"]
[Thu Jul 30 14:02:09.920499 2026] [security2:error] [pid 977210:tid 977461] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-blog-header.php"] [unique_id "amufsfW1Jl2-fgIeVvqmgwAAAPw"]
[Thu Jul 30 14:02:09.937570 2026] [security2:error] [pid 977210:tid 977391] [client 191.232.199.39:43609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/mini.php"] [unique_id "amufsfW1Jl2-fgIeVvqmhAAAALY"]
[Thu Jul 30 14:02:09.939111 2026] [security2:error] [pid 977210:tid 977285] [remote 40.77.167.72:11336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/jpita.or.jp/aboutf.php"] [unique_id "amufsfW1Jl2-fgIeVvqmhQAApkg"]
[Thu Jul 30 14:02:10.006857 2026] [security2:error] [pid 977210:tid 977363] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/img.php"] [unique_id "amufsvW1Jl2-fgIeVvqmiQAAAJo"]
[Thu Jul 30 14:02:10.006951 2026] [security2:error] [pid 977210:tid 977363] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/img.php"] [unique_id "amufsvW1Jl2-fgIeVvqmiQAAAJo"]
[Thu Jul 30 14:02:10.045953 2026] [security2:error] [pid 977210:tid 977438] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufsfW1Jl2-fgIeVvqmdQAA5S8"]
[Thu Jul 30 14:02:10.139501 2026] [core:notice] [pid 977210:tid 977307] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:10.206499 2026] [security2:error] [pid 977210:tid 977431] [client 103.190.40.154:18685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufsvW1Jl2-fgIeVvqmlAAAAN4"]
[Thu Jul 30 14:02:10.206629 2026] [security2:error] [pid 977210:tid 977431] [client 103.190.40.154:18685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufsvW1Jl2-fgIeVvqmlAAAAN4"]
[Thu Jul 30 14:02:10.368360 2026] [security2:error] [pid 977210:tid 977382] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufsvW1Jl2-fgIeVvqmkwAAAK0"]
[Thu Jul 30 14:02:10.368392 2026] [security2:error] [pid 977210:tid 977382] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufsvW1Jl2-fgIeVvqmkwAAAK0"]
[Thu Jul 30 14:02:10.368703 2026] [security2:error] [pid 977210:tid 977385] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/www/"] [unique_id "amufsvW1Jl2-fgIeVvqmkQAAALA"]
[Thu Jul 30 14:02:10.447792 2026] [security2:error] [pid 977210:tid 977399] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-load.php"] [unique_id "amufsvW1Jl2-fgIeVvqmlQAAAL4"]
[Thu Jul 30 14:02:10.447936 2026] [security2:error] [pid 977210:tid 977399] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-load.php"] [unique_id "amufsvW1Jl2-fgIeVvqmlQAAAL4"]
[Thu Jul 30 14:02:10.563500 2026] [security2:error] [pid 977210:tid 977450] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/aa.php"] [unique_id "amufsvW1Jl2-fgIeVvqmnAAAAPE"]
[Thu Jul 30 14:02:10.563620 2026] [security2:error] [pid 977210:tid 977450] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/aa.php"] [unique_id "amufsvW1Jl2-fgIeVvqmnAAAAPE"]
[Thu Jul 30 14:02:10.821243 2026] [core:notice] [pid 977210:tid 977339] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:10.921371 2026] [security2:error] [pid 977210:tid 977259] [remote 220.181.108.155:40489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/undiz/"] [unique_id "amufsvW1Jl2-fgIeVvqmpQAA5C4"]
[Thu Jul 30 14:02:11.004484 2026] [security2:error] [pid 977210:tid 977370] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/edit.php"] [unique_id "amufs_W1Jl2-fgIeVvqmqQAAAKE"]
[Thu Jul 30 14:02:11.004583 2026] [security2:error] [pid 977210:tid 977370] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/edit.php"] [unique_id "amufs_W1Jl2-fgIeVvqmqQAAAKE"]
[Thu Jul 30 14:02:11.389920 2026] [security2:error] [pid 977210:tid 977411] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/av.php"] [unique_id "amufs_W1Jl2-fgIeVvqmtAAAAMo"]
[Thu Jul 30 14:02:11.390060 2026] [security2:error] [pid 977210:tid 977411] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/av.php"] [unique_id "amufs_W1Jl2-fgIeVvqmtAAAAMo"]
[Thu Jul 30 14:02:11.498447 2026] [security2:error] [pid 977210:tid 977217] [remote 119.249.100.177:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/undiz/"] [unique_id "amufs_W1Jl2-fgIeVvqmtgAAvwQ"]
[Thu Jul 30 14:02:11.548860 2026] [security2:error] [pid 977210:tid 977429] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/___proxy_subdomain_webmail/cgi-bin"] [unique_id "amufs_W1Jl2-fgIeVvqmtwAAANw"]
[Thu Jul 30 14:02:11.708399 2026] [security2:error] [pid 977210:tid 977413] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/xa.php"] [unique_id "amufs_W1Jl2-fgIeVvqmwQAAAMw"]
[Thu Jul 30 14:02:11.708507 2026] [security2:error] [pid 977210:tid 977413] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/xa.php"] [unique_id "amufs_W1Jl2-fgIeVvqmwQAAAMw"]
[Thu Jul 30 14:02:11.796410 2026] [security2:error] [pid 977210:tid 977417] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/mah.php"] [unique_id "amufs_W1Jl2-fgIeVvqmwgAAANA"]
[Thu Jul 30 14:02:11.796522 2026] [security2:error] [pid 977210:tid 977417] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/mah.php"] [unique_id "amufs_W1Jl2-fgIeVvqmwgAAANA"]
[Thu Jul 30 14:02:12.161679 2026] [security2:error] [pid 977210:tid 977436] [client 172.202.44.182:13593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/includes/index.php"] [unique_id "amuftPW1Jl2-fgIeVvqmzAAAAOM"]
[Thu Jul 30 14:02:12.245243 2026] [security2:error] [pid 977210:tid 977302] [remote 119.249.100.50:17769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/undiz/"] [unique_id "amufs_W1Jl2-fgIeVvqmxAAAz1k"]
[Thu Jul 30 14:02:12.293572 2026] [security2:error] [pid 977210:tid 977346] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/archive.php"] [unique_id "amuftPW1Jl2-fgIeVvqm0AAAAIk"]
[Thu Jul 30 14:02:12.293661 2026] [security2:error] [pid 977210:tid 977346] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/archive.php"] [unique_id "amuftPW1Jl2-fgIeVvqm0AAAAIk"]
[Thu Jul 30 14:02:12.606135 2026] [security2:error] [pid 977210:tid 977409] [client 191.232.199.39:35114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/aa.php"] [unique_id "amuftPW1Jl2-fgIeVvqm2QAAAMg"]
[Thu Jul 30 14:02:12.799297 2026] [security2:error] [pid 977210:tid 977452] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/hosty.php"] [unique_id "amuftPW1Jl2-fgIeVvqm6AAAAPM"]
[Thu Jul 30 14:02:12.799412 2026] [security2:error] [pid 977210:tid 977452] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/hosty.php"] [unique_id "amuftPW1Jl2-fgIeVvqm6AAAAPM"]
[Thu Jul 30 14:02:12.839115 2026] [autoindex:error] [pid 977210:tid 977448] [client 194.116.236.215:59772] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:02:12.964919 2026] [security2:error] [pid 977210:tid 977358] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuftPW1Jl2-fgIeVvqm5AAAAJU"]
[Thu Jul 30 14:02:12.964945 2026] [security2:error] [pid 977210:tid 977358] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuftPW1Jl2-fgIeVvqm5AAAAJU"]
[Thu Jul 30 14:02:12.965465 2026] [security2:error] [pid 977210:tid 977354] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/web/"] [unique_id "amuftPW1Jl2-fgIeVvqm4QAAAJE"]
[Thu Jul 30 14:02:13.369896 2026] [security2:error] [pid 977210:tid 977457] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/___proxy_subdomain_webmail/wp-includes/Text/Diff/"] [unique_id "amuftfW1Jl2-fgIeVvqngwAAAPg"]
[Thu Jul 30 14:02:13.371745 2026] [security2:error] [pid 977210:tid 977437] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuftPW1Jl2-fgIeVvqm5QAAAOQ"]
[Thu Jul 30 14:02:13.415352 2026] [security2:error] [pid 977210:tid 977430] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/media.php"] [unique_id "amuftfW1Jl2-fgIeVvqnhQAAAN0"]
[Thu Jul 30 14:02:13.415448 2026] [security2:error] [pid 977210:tid 977430] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/media.php"] [unique_id "amuftfW1Jl2-fgIeVvqnhQAAAN0"]
[Thu Jul 30 14:02:13.508001 2026] [autoindex:error] [pid 977210:tid 977426] [client 194.116.236.215:36568] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:02:13.725660 2026] [security2:error] [pid 977210:tid 977395] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/images.php"] [unique_id "amuftfW1Jl2-fgIeVvqnkwAAALo"]
[Thu Jul 30 14:02:13.725761 2026] [security2:error] [pid 977210:tid 977395] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/images.php"] [unique_id "amuftfW1Jl2-fgIeVvqnkwAAALo"]
[Thu Jul 30 14:02:13.772253 2026] [security2:error] [pid 977210:tid 977375] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuftfW1Jl2-fgIeVvqnjAAAAKY"]
[Thu Jul 30 14:02:13.772281 2026] [security2:error] [pid 977210:tid 977375] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuftfW1Jl2-fgIeVvqnjAAAAKY"]
[Thu Jul 30 14:02:13.773139 2026] [security2:error] [pid 977210:tid 977417] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/uploads/"] [unique_id "amuftfW1Jl2-fgIeVvqnigAAANA"]
[Thu Jul 30 14:02:13.893400 2026] [security2:error] [pid 977210:tid 977399] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/admin.php"] [unique_id "amuftfW1Jl2-fgIeVvqnmAAAAL4"]
[Thu Jul 30 14:02:13.893544 2026] [security2:error] [pid 977210:tid 977399] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/admin.php"] [unique_id "amuftfW1Jl2-fgIeVvqnmAAAAL4"]
[Thu Jul 30 14:02:14.034103 2026] [security2:error] [pid 977210:tid 977408] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/gecko.php"] [unique_id "amuftvW1Jl2-fgIeVvqnmQAAAMc"]
[Thu Jul 30 14:02:14.034212 2026] [security2:error] [pid 977210:tid 977408] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/gecko.php"] [unique_id "amuftvW1Jl2-fgIeVvqnmQAAAMc"]
[Thu Jul 30 14:02:14.275860 2026] [security2:error] [pid 977210:tid 977427] [client 20.104.16.169:34887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/tBEZGQz.php"] [unique_id "amuftvW1Jl2-fgIeVvqnoQAAANo"]
[Thu Jul 30 14:02:14.275956 2026] [security2:error] [pid 977210:tid 977427] [client 20.104.16.169:34887] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/tBEZGQz.php"] [unique_id "amuftvW1Jl2-fgIeVvqnoQAAANo"]
[Thu Jul 30 14:02:14.342581 2026] [security2:error] [pid 977210:tid 977394] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/82.php"] [unique_id "amuftvW1Jl2-fgIeVvqnpQAAALk"]
[Thu Jul 30 14:02:14.342700 2026] [security2:error] [pid 977210:tid 977394] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/82.php"] [unique_id "amuftvW1Jl2-fgIeVvqnpQAAALk"]
[Thu Jul 30 14:02:14.357038 2026] [security2:error] [pid 977210:tid 977413] [client 191.232.199.39:35072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/w.php"] [unique_id "amuftvW1Jl2-fgIeVvqnpgAAAMw"]
[Thu Jul 30 14:02:14.384649 2026] [security2:error] [pid 977210:tid 977364] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/av.php"] [unique_id "amuftvW1Jl2-fgIeVvqnpwAAAJs"]
[Thu Jul 30 14:02:14.384777 2026] [security2:error] [pid 977210:tid 977364] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/av.php"] [unique_id "amuftvW1Jl2-fgIeVvqnpwAAAJs"]
[Thu Jul 30 14:02:14.685351 2026] [security2:error] [pid 977210:tid 977424] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/xstelth.php"] [unique_id "amuftvW1Jl2-fgIeVvqnqAAAANc"]
[Thu Jul 30 14:02:14.685467 2026] [security2:error] [pid 977210:tid 977424] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/xstelth.php"] [unique_id "amuftvW1Jl2-fgIeVvqnqAAAANc"]
[Thu Jul 30 14:02:14.885379 2026] [security2:error] [pid 977210:tid 977371] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuftvW1Jl2-fgIeVvqnqwAAAKI"]
[Thu Jul 30 14:02:14.885419 2026] [security2:error] [pid 977210:tid 977371] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuftvW1Jl2-fgIeVvqnqwAAAKI"]
[Thu Jul 30 14:02:14.885644 2026] [security2:error] [pid 977210:tid 977358] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/upload/"] [unique_id "amuftvW1Jl2-fgIeVvqnqQAAAJU"]
[Thu Jul 30 14:02:14.891122 2026] [security2:error] [pid 977210:tid 977349] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/shell.php"] [unique_id "amuftvW1Jl2-fgIeVvqnuwAAAIw"]
[Thu Jul 30 14:02:14.891212 2026] [security2:error] [pid 977210:tid 977349] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/shell.php"] [unique_id "amuftvW1Jl2-fgIeVvqnuwAAAIw"]
[Thu Jul 30 14:02:15.019085 2026] [security2:error] [pid 977210:tid 977461] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/xp.php"] [unique_id "amuft_W1Jl2-fgIeVvqnvgAAAPw"]
[Thu Jul 30 14:02:15.019230 2026] [security2:error] [pid 977210:tid 977461] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/xp.php"] [unique_id "amuft_W1Jl2-fgIeVvqnvgAAAPw"]
[Thu Jul 30 14:02:15.259747 2026] [security2:error] [pid 977210:tid 977457] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuft_W1Jl2-fgIeVvqnwgAAAPg"]
[Thu Jul 30 14:02:15.718373 2026] [security2:error] [pid 977210:tid 977387] [client 95.15.171.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amuftvW1Jl2-fgIeVvqntAAAALI"], referer: https://shop-mevius.com/product/terea-17/
[Thu Jul 30 14:02:15.872462 2026] [security2:error] [pid 977210:tid 977367] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/storage/index.php"] [unique_id "amuft_W1Jl2-fgIeVvqn9gAAAJ4"]
[Thu Jul 30 14:02:15.872589 2026] [security2:error] [pid 977210:tid 977367] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/storage/index.php"] [unique_id "amuft_W1Jl2-fgIeVvqn9gAAAJ4"]
[Thu Jul 30 14:02:15.956356 2026] [security2:error] [pid 977210:tid 977342] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuft_W1Jl2-fgIeVvqn8gAAAIU"]
[Thu Jul 30 14:02:15.956386 2026] [security2:error] [pid 977210:tid 977342] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuft_W1Jl2-fgIeVvqn8gAAAIU"]
[Thu Jul 30 14:02:15.956638 2026] [security2:error] [pid 977210:tid 977370] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/admin/uploads/"] [unique_id "amuft_W1Jl2-fgIeVvqn8AAAAKE"]
[Thu Jul 30 14:02:16.390115 2026] [security2:error] [pid 977210:tid 977444] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/w.php"] [unique_id "amufuPW1Jl2-fgIeVvqoAAAAAOs"]
[Thu Jul 30 14:02:16.390232 2026] [security2:error] [pid 977210:tid 977444] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/w.php"] [unique_id "amufuPW1Jl2-fgIeVvqoAAAAAOs"]
[Thu Jul 30 14:02:16.942452 2026] [security2:error] [pid 977210:tid 977431] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/jp.php"] [unique_id "amufuPW1Jl2-fgIeVvqoFAAAAN4"]
[Thu Jul 30 14:02:16.942621 2026] [security2:error] [pid 977210:tid 977431] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/jp.php"] [unique_id "amufuPW1Jl2-fgIeVvqoFAAAAN4"]
[Thu Jul 30 14:02:17.036888 2026] [security2:error] [pid 977210:tid 977401] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufuPW1Jl2-fgIeVvqoEAAAAMA"]
[Thu Jul 30 14:02:17.036922 2026] [security2:error] [pid 977210:tid 977401] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufuPW1Jl2-fgIeVvqoEAAAAMA"]
[Thu Jul 30 14:02:17.037145 2026] [security2:error] [pid 977210:tid 977344] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/Admin/uploads/"] [unique_id "amufuPW1Jl2-fgIeVvqoDQAAAIc"]
[Thu Jul 30 14:02:17.062373 2026] [security2:error] [pid 977210:tid 977375] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amufufW1Jl2-fgIeVvqoFQAAAKY"]
[Thu Jul 30 14:02:17.062510 2026] [security2:error] [pid 977210:tid 977375] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amufufW1Jl2-fgIeVvqoFQAAAKY"]
[Thu Jul 30 14:02:17.197306 2026] [security2:error] [pid 977210:tid 977392] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufuPW1Jl2-fgIeVvqoBgAAALc"]
[Thu Jul 30 14:02:17.374926 2026] [security2:error] [pid 977210:tid 977380] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/adminner.php"] [unique_id "amufufW1Jl2-fgIeVvqoHAAAAKs"]
[Thu Jul 30 14:02:17.375061 2026] [security2:error] [pid 977210:tid 977380] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/adminner.php"] [unique_id "amufufW1Jl2-fgIeVvqoHAAAAKs"]
[Thu Jul 30 14:02:17.500737 2026] [security2:error] [pid 977210:tid 977347] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/___proxy_subdomain_webmail/php.ini"] [unique_id "amufufW1Jl2-fgIeVvqoIgAAAIo"]
[Thu Jul 30 14:02:17.532433 2026] [security2:error] [pid 977210:tid 977430] [client 191.232.199.39:35091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/admin.php"] [unique_id "amufufW1Jl2-fgIeVvqoJgAAAN0"]
[Thu Jul 30 14:02:17.619073 2026] [core:error] [pid 977210:tid 977235] [remote 216.73.216.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:17.619093 2026] [core:error] [pid 977210:tid 977235] [remote 216.73.216.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:17.692471 2026] [security2:error] [pid 977210:tid 977406] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/a.php"] [unique_id "amufufW1Jl2-fgIeVvqoKgAAAMU"]
[Thu Jul 30 14:02:17.692601 2026] [security2:error] [pid 977210:tid 977406] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/a.php"] [unique_id "amufufW1Jl2-fgIeVvqoKgAAAMU"]
[Thu Jul 30 14:02:17.714776 2026] [security2:error] [pid 977210:tid 977452] [client 20.104.16.169:34881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.raad.pk"] [uri "/___proxy_subdomain_webdisk/phpinfo"] [unique_id "amufufW1Jl2-fgIeVvqoKwAAAPM"]
[Thu Jul 30 14:02:17.724751 2026] [security2:error] [pid 977210:tid 977374] [client 181.116.200.68:64513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufufW1Jl2-fgIeVvqoLAAAAKU"]
[Thu Jul 30 14:02:17.724880 2026] [security2:error] [pid 977210:tid 977374] [client 181.116.200.68:64513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufufW1Jl2-fgIeVvqoLAAAAKU"]
[Thu Jul 30 14:02:17.785148 2026] [security2:error] [pid 977210:tid 977448] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/ws77.php"] [unique_id "amufufW1Jl2-fgIeVvqoMQAAAO8"]
[Thu Jul 30 14:02:17.785257 2026] [security2:error] [pid 977210:tid 977448] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/ws77.php"] [unique_id "amufufW1Jl2-fgIeVvqoMQAAAO8"]
[Thu Jul 30 14:02:17.880268 2026] [security2:error] [pid 977210:tid 977427] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufufW1Jl2-fgIeVvqoMAAAANo"]
[Thu Jul 30 14:02:17.880294 2026] [security2:error] [pid 977210:tid 977427] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amufufW1Jl2-fgIeVvqoMAAAANo"]
[Thu Jul 30 14:02:17.880722 2026] [security2:error] [pid 977210:tid 977449] [client 82.102.18.180:47614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/admin/"] [unique_id "amufufW1Jl2-fgIeVvqoLgAAAPA"]
[Thu Jul 30 14:02:17.911632 2026] [security2:error] [pid 977210:tid 977434] [client 20.104.16.169:34881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/drykl.php"] [unique_id "amufufW1Jl2-fgIeVvqoPQAAAOE"]
[Thu Jul 30 14:02:17.911734 2026] [security2:error] [pid 977210:tid 977434] [client 20.104.16.169:34881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/drykl.php"] [unique_id "amufufW1Jl2-fgIeVvqoPQAAAOE"]
[Thu Jul 30 14:02:17.998065 2026] [security2:error] [pid 977210:tid 977311] [remote 5.161.62.209:7514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.ocl.djb.temporary.site"] [uri "/.env"] [unique_id "amufufW1Jl2-fgIeVvqoQwAAo2I"]
[Thu Jul 30 14:02:18.020942 2026] [security2:error] [pid 977210:tid 977393] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/k.php"] [unique_id "amufuvW1Jl2-fgIeVvqoRgAAALg"]
[Thu Jul 30 14:02:18.021093 2026] [security2:error] [pid 977210:tid 977393] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/k.php"] [unique_id "amufuvW1Jl2-fgIeVvqoRgAAALg"]
[Thu Jul 30 14:02:18.136732 2026] [core:notice] [pid 977210:tid 977412] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:18.137424 2026] [security2:error] [pid 977210:tid 977384] [client 103.242.199.184:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufuvW1Jl2-fgIeVvqoSQAAAK8"]
[Thu Jul 30 14:02:18.137540 2026] [security2:error] [pid 977210:tid 977384] [client 103.242.199.184:62796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufuvW1Jl2-fgIeVvqoSQAAAK8"]
[Thu Jul 30 14:02:18.159871 2026] [core:notice] [pid 977210:tid 977424] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:18.294862 2026] [security2:error] [pid 977210:tid 977429] [client 172.213.208.20:23648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amufuvW1Jl2-fgIeVvqoTAAAANw"]
[Thu Jul 30 14:02:18.304284 2026] [security2:error] [pid 977210:tid 977349] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/blass.php"] [unique_id "amufuvW1Jl2-fgIeVvqoTQAAAIw"]
[Thu Jul 30 14:02:18.304429 2026] [security2:error] [pid 977210:tid 977349] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/blass.php"] [unique_id "amufuvW1Jl2-fgIeVvqoTQAAAIw"]
[Thu Jul 30 14:02:18.336461 2026] [security2:error] [pid 977210:tid 977462] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/222.php"] [unique_id "amufuvW1Jl2-fgIeVvqoTgAAAP0"]
[Thu Jul 30 14:02:18.336574 2026] [security2:error] [pid 977210:tid 977462] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/222.php"] [unique_id "amufuvW1Jl2-fgIeVvqoTgAAAP0"]
[Thu Jul 30 14:02:18.638704 2026] [security2:error] [pid 977210:tid 977392] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/mac.php"] [unique_id "amufuvW1Jl2-fgIeVvqoYgAAALc"]
[Thu Jul 30 14:02:18.638815 2026] [security2:error] [pid 977210:tid 977392] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/mac.php"] [unique_id "amufuvW1Jl2-fgIeVvqoYgAAALc"]
[Thu Jul 30 14:02:18.828702 2026] [security2:error] [pid 977210:tid 977458] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-info.php"] [unique_id "amufuvW1Jl2-fgIeVvqoZwAAAPk"]
[Thu Jul 30 14:02:18.828810 2026] [security2:error] [pid 977210:tid 977458] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-info.php"] [unique_id "amufuvW1Jl2-fgIeVvqoZwAAAPk"]
[Thu Jul 30 14:02:18.885292 2026] [security2:error] [pid 977210:tid 977459] [client 172.213.208.20:39081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/m.php"] [unique_id "amufuvW1Jl2-fgIeVvqoagAAAPo"]
[Thu Jul 30 14:02:18.942373 2026] [proxy:error] [pid 977210:tid 977408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:18.942462 2026] [proxy_http:error] [pid 977210:tid 977408] [client 20.100.169.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:18.943330 2026] [proxy:error] [pid 977210:tid 977408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:18.943401 2026] [proxy_http:error] [pid 977210:tid 977408] [client 20.100.169.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:18.943496 2026] [security2:error] [pid 977210:tid 977408] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amufuvW1Jl2-fgIeVvqocAAAAMc"]
[Thu Jul 30 14:02:19.346522 2026] [security2:error] [pid 977210:tid 977374] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/CDX1.php"] [unique_id "amufu_W1Jl2-fgIeVvqoewAAAKU"]
[Thu Jul 30 14:02:19.346638 2026] [security2:error] [pid 977210:tid 977374] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/CDX1.php"] [unique_id "amufu_W1Jl2-fgIeVvqoewAAAKU"]
[Thu Jul 30 14:02:19.410991 2026] [security2:error] [pid 977210:tid 977467] [client 191.232.199.39:43613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amufu_W1Jl2-fgIeVvqofwAAAQI"]
[Thu Jul 30 14:02:19.465140 2026] [security2:error] [pid 977210:tid 977413] [client 20.104.16.169:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.raad.pk"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amufu_W1Jl2-fgIeVvqohwAAAMw"]
[Thu Jul 30 14:02:19.510574 2026] [security2:error] [pid 977210:tid 977454] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amufuvW1Jl2-fgIeVvqoaQAA9Uw"]
[Thu Jul 30 14:02:19.618546 2026] [security2:error] [pid 977210:tid 977386] [client 172.202.44.182:46424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amufu_W1Jl2-fgIeVvqolAAAALE"]
[Thu Jul 30 14:02:19.662662 2026] [security2:error] [pid 977210:tid 977393] [client 20.104.16.169:36182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/ls.php"] [unique_id "amufu_W1Jl2-fgIeVvqolQAAALg"]
[Thu Jul 30 14:02:19.662783 2026] [security2:error] [pid 977210:tid 977393] [client 20.104.16.169:36182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/ls.php"] [unique_id "amufu_W1Jl2-fgIeVvqolQAAALg"]
[Thu Jul 30 14:02:19.730311 2026] [security2:error] [pid 977210:tid 977443] [client 172.213.208.20:36901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amufu_W1Jl2-fgIeVvqoiAAAAOo"]
[Thu Jul 30 14:02:19.834996 2026] [security2:error] [pid 977210:tid 977365] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wpc.php"] [unique_id "amufu_W1Jl2-fgIeVvqomwAAAJw"]
[Thu Jul 30 14:02:19.835112 2026] [security2:error] [pid 977210:tid 977365] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wpc.php"] [unique_id "amufu_W1Jl2-fgIeVvqomwAAAJw"]
[Thu Jul 30 14:02:20.114573 2026] [security2:error] [pid 977210:tid 977353] [client 72.143.199.60:31714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amufvPW1Jl2-fgIeVvqopAAAkGk"], referer: https://www.northyorksheridanmall.com/
[Thu Jul 30 14:02:20.344637 2026] [security2:error] [pid 977210:tid 977446] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/jga.php"] [unique_id "amufvPW1Jl2-fgIeVvqosgAAAO0"]
[Thu Jul 30 14:02:20.344738 2026] [security2:error] [pid 977210:tid 977446] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/jga.php"] [unique_id "amufvPW1Jl2-fgIeVvqosgAAAO0"]
[Thu Jul 30 14:02:20.683027 2026] [security2:error] [pid 977210:tid 977436] [client 172.202.44.182:13585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/plugins.php"] [unique_id "amufvPW1Jl2-fgIeVvqovwAAAOM"]
[Thu Jul 30 14:02:20.832135 2026] [security2:error] [pid 977210:tid 977430] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/666.php"] [unique_id "amufvPW1Jl2-fgIeVvqowQAAAN0"]
[Thu Jul 30 14:02:20.832230 2026] [security2:error] [pid 977210:tid 977430] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/666.php"] [unique_id "amufvPW1Jl2-fgIeVvqowQAAAN0"]
[Thu Jul 30 14:02:21.198163 2026] [security2:error] [pid 977210:tid 977415] [client 103.190.40.154:19211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufvfW1Jl2-fgIeVvqozgAAAM4"]
[Thu Jul 30 14:02:21.198317 2026] [security2:error] [pid 977210:tid 977415] [client 103.190.40.154:19211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufvfW1Jl2-fgIeVvqozgAAAM4"]
[Thu Jul 30 14:02:21.345340 2026] [security2:error] [pid 977210:tid 977404] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/htaccess.php"] [unique_id "amufvfW1Jl2-fgIeVvqozwAAAMM"]
[Thu Jul 30 14:02:21.345498 2026] [security2:error] [pid 977210:tid 977404] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/htaccess.php"] [unique_id "amufvfW1Jl2-fgIeVvqozwAAAMM"]
[Thu Jul 30 14:02:21.561353 2026] [proxy:error] [pid 977210:tid 977418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:21.561427 2026] [proxy_http:error] [pid 977210:tid 977418] [client 20.100.169.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:21.562047 2026] [proxy:error] [pid 977210:tid 977418] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:21.562098 2026] [proxy_http:error] [pid 977210:tid 977418] [client 20.100.169.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:21.562200 2026] [security2:error] [pid 977210:tid 977418] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amufvfW1Jl2-fgIeVvqo0wAAANE"]
[Thu Jul 30 14:02:21.690041 2026] [security2:error] [pid 977210:tid 977441] [client 172.213.208.20:38985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wk/index.php"] [unique_id "amufvfW1Jl2-fgIeVvqo2gAAAOg"]
[Thu Jul 30 14:02:21.861542 2026] [security2:error] [pid 977210:tid 977417] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/m.php"] [unique_id "amufvfW1Jl2-fgIeVvqo2wAAANA"]
[Thu Jul 30 14:02:21.861660 2026] [security2:error] [pid 977210:tid 977417] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/m.php"] [unique_id "amufvfW1Jl2-fgIeVvqo2wAAANA"]
[Thu Jul 30 14:02:21.878064 2026] [security2:error] [pid 977210:tid 977383] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/ops.php"] [unique_id "amufvfW1Jl2-fgIeVvqo3wAAAK4"]
[Thu Jul 30 14:02:21.878189 2026] [security2:error] [pid 977210:tid 977383] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/ops.php"] [unique_id "amufvfW1Jl2-fgIeVvqo3wAAAK4"]
[Thu Jul 30 14:02:22.196888 2026] [security2:error] [pid 977210:tid 977439] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/8.php"] [unique_id "amufvvW1Jl2-fgIeVvqo6gAAAOY"]
[Thu Jul 30 14:02:22.196989 2026] [security2:error] [pid 977210:tid 977439] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/8.php"] [unique_id "amufvvW1Jl2-fgIeVvqo6gAAAOY"]
[Thu Jul 30 14:02:22.354753 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/file.php"] [unique_id "amufvvW1Jl2-fgIeVvqo6wAAAIY"]
[Thu Jul 30 14:02:22.354860 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/file.php"] [unique_id "amufvvW1Jl2-fgIeVvqo6wAAAIY"]
[Thu Jul 30 14:02:22.452764 2026] [security2:error] [pid 977210:tid 977423] [client 172.213.208.20:13555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/mini.php"] [unique_id "amufvvW1Jl2-fgIeVvqo7QAAANY"]
[Thu Jul 30 14:02:22.506357 2026] [security2:error] [pid 977210:tid 977376] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/FWAZ.php"] [unique_id "amufvvW1Jl2-fgIeVvqo7gAAAKc"]
[Thu Jul 30 14:02:22.506490 2026] [security2:error] [pid 977210:tid 977376] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/FWAZ.php"] [unique_id "amufvvW1Jl2-fgIeVvqo7gAAAKc"]
[Thu Jul 30 14:02:22.614233 2026] [security2:error] [pid 977210:tid 977344] [client 191.232.199.39:43634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/m.php"] [unique_id "amufvvW1Jl2-fgIeVvqo8gAAAIc"]
[Thu Jul 30 14:02:22.702198 2026] [security2:error] [pid 977210:tid 977420] [client 20.104.16.169:36159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/dx.php"] [unique_id "amufvvW1Jl2-fgIeVvqo-QAAANM"]
[Thu Jul 30 14:02:22.702298 2026] [security2:error] [pid 977210:tid 977420] [client 20.104.16.169:36159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/dx.php"] [unique_id "amufvvW1Jl2-fgIeVvqo-QAAANM"]
[Thu Jul 30 14:02:22.708251 2026] [security2:error] [pid 977210:tid 977422] [client 189.6.88.213:59952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufvvW1Jl2-fgIeVvqo-gAAANU"]
[Thu Jul 30 14:02:22.708338 2026] [security2:error] [pid 977210:tid 977422] [client 189.6.88.213:59952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufvvW1Jl2-fgIeVvqo-gAAANU"]
[Thu Jul 30 14:02:22.748253 2026] [core:error] [pid 977210:tid 977415] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:22.748281 2026] [core:error] [pid 977210:tid 977415] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:22.850259 2026] [security2:error] [pid 977210:tid 977434] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/biufile.php"] [unique_id "amufvvW1Jl2-fgIeVvqo_AAAAOE"]
[Thu Jul 30 14:02:22.850402 2026] [security2:error] [pid 977210:tid 977434] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/biufile.php"] [unique_id "amufvvW1Jl2-fgIeVvqo_AAAAOE"]
[Thu Jul 30 14:02:22.871620 2026] [security2:error] [pid 977210:tid 977404] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/.dj/index.php"] [unique_id "amufvvW1Jl2-fgIeVvqo_QAAAMM"]
[Thu Jul 30 14:02:22.871730 2026] [security2:error] [pid 977210:tid 977404] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/.dj/index.php"] [unique_id "amufvvW1Jl2-fgIeVvqo_QAAAMM"]
[Thu Jul 30 14:02:23.235317 2026] [security2:error] [pid 977210:tid 977464] [client 172.202.44.182:50954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/js/index.php"] [unique_id "amufv_W1Jl2-fgIeVvqpBgAAAP8"]
[Thu Jul 30 14:02:23.425444 2026] [security2:error] [pid 977210:tid 977384] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-admin/maint/index.php"] [unique_id "amufv_W1Jl2-fgIeVvqpDQAAAK8"]
[Thu Jul 30 14:02:23.425544 2026] [security2:error] [pid 977210:tid 977384] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-admin/maint/index.php"] [unique_id "amufv_W1Jl2-fgIeVvqpDQAAAK8"]
[Thu Jul 30 14:02:23.950650 2026] [security2:error] [pid 977210:tid 977459] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/pages.php"] [unique_id "amufv_W1Jl2-fgIeVvqpFwAAAPo"]
[Thu Jul 30 14:02:23.950771 2026] [security2:error] [pid 977210:tid 977459] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/pages.php"] [unique_id "amufv_W1Jl2-fgIeVvqpFwAAAPo"]
[Thu Jul 30 14:02:24.217689 2026] [security2:error] [pid 977210:tid 977359] [client 20.104.16.169:36161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/mac.php"] [unique_id "amufwPW1Jl2-fgIeVvqpHQAAAJY"]
[Thu Jul 30 14:02:24.217781 2026] [security2:error] [pid 977210:tid 977359] [client 20.104.16.169:36161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/mac.php"] [unique_id "amufwPW1Jl2-fgIeVvqpHQAAAJY"]
[Thu Jul 30 14:02:24.282777 2026] [security2:error] [pid 977210:tid 977469] [client 172.213.208.20:36856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/aa.php"] [unique_id "amufwPW1Jl2-fgIeVvqpIgAAAQQ"]
[Thu Jul 30 14:02:24.367531 2026] [security2:error] [pid 977210:tid 977401] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/coffexium.php"] [unique_id "amufwPW1Jl2-fgIeVvqpIwAAAMA"]
[Thu Jul 30 14:02:24.367648 2026] [security2:error] [pid 977210:tid 977401] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/coffexium.php"] [unique_id "amufwPW1Jl2-fgIeVvqpIwAAAMA"]
[Thu Jul 30 14:02:24.487437 2026] [security2:error] [pid 977210:tid 977406] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/adminfuns.php"] [unique_id "amufwPW1Jl2-fgIeVvqpJwAAAMU"]
[Thu Jul 30 14:02:24.487559 2026] [security2:error] [pid 977210:tid 977406] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/adminfuns.php"] [unique_id "amufwPW1Jl2-fgIeVvqpJwAAAMU"]
[Thu Jul 30 14:02:24.685317 2026] [security2:error] [pid 977210:tid 977382] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/simple.php"] [unique_id "amufwPW1Jl2-fgIeVvqpYwAAAK0"]
[Thu Jul 30 14:02:24.685423 2026] [security2:error] [pid 977210:tid 977382] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/simple.php"] [unique_id "amufwPW1Jl2-fgIeVvqpYwAAAK0"]
[Thu Jul 30 14:02:24.805800 2026] [security2:error] [pid 977210:tid 977345] [client 172.202.44.182:46452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/go.php"] [unique_id "amufwPW1Jl2-fgIeVvqpaQAAAIg"]
[Thu Jul 30 14:02:24.984256 2026] [security2:error] [pid 977210:tid 977455] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amufwPW1Jl2-fgIeVvqpJgAAAPY"]
[Thu Jul 30 14:02:25.038441 2026] [security2:error] [pid 977210:tid 977370] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/aa.php"] [unique_id "amufwfW1Jl2-fgIeVvqpcAAAAKE"]
[Thu Jul 30 14:02:25.038530 2026] [security2:error] [pid 977210:tid 977370] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/aa.php"] [unique_id "amufwfW1Jl2-fgIeVvqpcAAAAKE"]
[Thu Jul 30 14:02:25.601279 2026] [security2:error] [pid 977210:tid 977349] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/___proxy_subdomain_webmail/wp-includes/Text/Diff/Engine/"] [unique_id "amufwfW1Jl2-fgIeVvqpuQAAAIw"]
[Thu Jul 30 14:02:25.788516 2026] [security2:error] [pid 977210:tid 977421] [client 191.232.199.39:43632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amufwfW1Jl2-fgIeVvqpqQAAANQ"]
[Thu Jul 30 14:02:25.854388 2026] [security2:error] [pid 977210:tid 977361] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/classwithtostring.php"] [unique_id "amufwfW1Jl2-fgIeVvqqDgAAAJg"]
[Thu Jul 30 14:02:25.854515 2026] [security2:error] [pid 977210:tid 977361] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/classwithtostring.php"] [unique_id "amufwfW1Jl2-fgIeVvqqDgAAAJg"]
[Thu Jul 30 14:02:25.906160 2026] [security2:error] [pid 977210:tid 977403] [client 172.202.44.182:13588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/test1.php"] [unique_id "amufwfW1Jl2-fgIeVvqqEgAAAMI"]
[Thu Jul 30 14:02:26.348174 2026] [security2:error] [pid 977210:tid 977435] [client 20.104.16.169:36154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/485.php"] [unique_id "amufwvW1Jl2-fgIeVvqqGgAAAOI"]
[Thu Jul 30 14:02:26.348282 2026] [security2:error] [pid 977210:tid 977435] [client 20.104.16.169:36154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/485.php"] [unique_id "amufwvW1Jl2-fgIeVvqqGgAAAOI"]
[Thu Jul 30 14:02:26.368159 2026] [security2:error] [pid 977210:tid 977373] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/about.php"] [unique_id "amufwvW1Jl2-fgIeVvqqGwAAAKQ"]
[Thu Jul 30 14:02:26.368246 2026] [security2:error] [pid 977210:tid 977373] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/about.php"] [unique_id "amufwvW1Jl2-fgIeVvqqGwAAAKQ"]
[Thu Jul 30 14:02:26.382353 2026] [security2:error] [pid 977210:tid 977413] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/fpwch.php"] [unique_id "amufwvW1Jl2-fgIeVvqqHAAAAMw"]
[Thu Jul 30 14:02:26.382445 2026] [security2:error] [pid 977210:tid 977413] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/fpwch.php"] [unique_id "amufwvW1Jl2-fgIeVvqqHAAAAMw"]
[Thu Jul 30 14:02:26.658806 2026] [core:error] [pid 977210:tid 977370] [client 152.32.223.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:26.658830 2026] [core:error] [pid 977210:tid 977370] [client 152.32.223.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:26.700231 2026] [security2:error] [pid 977210:tid 977411] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/dex.php"] [unique_id "amufwvW1Jl2-fgIeVvqqJgAAAMo"]
[Thu Jul 30 14:02:26.700329 2026] [security2:error] [pid 977210:tid 977411] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/dex.php"] [unique_id "amufwvW1Jl2-fgIeVvqqJgAAAMo"]
[Thu Jul 30 14:02:26.893713 2026] [security2:error] [pid 977210:tid 977440] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/goods.php"] [unique_id "amufwvW1Jl2-fgIeVvqqLwAAAOc"]
[Thu Jul 30 14:02:26.893812 2026] [security2:error] [pid 977210:tid 977440] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/goods.php"] [unique_id "amufwvW1Jl2-fgIeVvqqLwAAAOc"]
[Thu Jul 30 14:02:27.026379 2026] [security2:error] [pid 977210:tid 977452] [client 20.100.169.152:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amufw_W1Jl2-fgIeVvqqNAAAAPM"]
[Thu Jul 30 14:02:27.026509 2026] [security2:error] [pid 977210:tid 977452] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amufw_W1Jl2-fgIeVvqqNAAAAPM"]
[Thu Jul 30 14:02:27.026641 2026] [security2:error] [pid 977210:tid 977452] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amufw_W1Jl2-fgIeVvqqNAAAAPM"]
[Thu Jul 30 14:02:27.319247 2026] [core:notice] [pid 977210:tid 977455] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:27.345283 2026] [proxy:error] [pid 977210:tid 977348] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:27.345351 2026] [proxy_http:error] [pid 977210:tid 977348] [client 20.100.169.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:27.345957 2026] [proxy:error] [pid 977210:tid 977348] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:27.346017 2026] [proxy_http:error] [pid 977210:tid 977348] [client 20.100.169.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:27.346117 2026] [security2:error] [pid 977210:tid 977348] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amufw_W1Jl2-fgIeVvqqOgAAAIs"]
[Thu Jul 30 14:02:27.435727 2026] [security2:error] [pid 977210:tid 977388] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/php8.php"] [unique_id "amufw_W1Jl2-fgIeVvqqPgAAALM"]
[Thu Jul 30 14:02:27.435822 2026] [security2:error] [pid 977210:tid 977388] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/php8.php"] [unique_id "amufw_W1Jl2-fgIeVvqqPgAAALM"]
[Thu Jul 30 14:02:27.599953 2026] [security2:error] [pid 977210:tid 977358] [client 191.232.199.39:43745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/classwithtostring.php"] [unique_id "amufw_W1Jl2-fgIeVvqqQwAAAJU"]
[Thu Jul 30 14:02:27.646974 2026] [security2:error] [pid 977210:tid 977397] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/config.json.php"] [unique_id "amufw_W1Jl2-fgIeVvqqRAAAALw"]
[Thu Jul 30 14:02:27.647086 2026] [security2:error] [pid 977210:tid 977397] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/config.json.php"] [unique_id "amufw_W1Jl2-fgIeVvqqRAAAALw"]
[Thu Jul 30 14:02:27.728013 2026] [security2:error] [pid 977210:tid 977369] [client 172.202.44.182:46436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/images/index.php"] [unique_id "amufw_W1Jl2-fgIeVvqqRQAAAKA"]
[Thu Jul 30 14:02:27.945936 2026] [security2:error] [pid 977210:tid 977431] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/k2.php"] [unique_id "amufw_W1Jl2-fgIeVvqqTAAAAN4"]
[Thu Jul 30 14:02:27.946063 2026] [security2:error] [pid 977210:tid 977431] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/k2.php"] [unique_id "amufw_W1Jl2-fgIeVvqqTAAAAN4"]
[Thu Jul 30 14:02:27.957744 2026] [security2:error] [pid 977210:tid 977423] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/info.php"] [unique_id "amufw_W1Jl2-fgIeVvqqTQAAANY"]
[Thu Jul 30 14:02:27.957830 2026] [security2:error] [pid 977210:tid 977423] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/info.php"] [unique_id "amufw_W1Jl2-fgIeVvqqTQAAANY"]
[Thu Jul 30 14:02:28.255394 2026] [security2:error] [pid 977210:tid 977456] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/raw.php"] [unique_id "amufxPW1Jl2-fgIeVvqqVgAAAPc"]
[Thu Jul 30 14:02:28.255506 2026] [security2:error] [pid 977210:tid 977456] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/raw.php"] [unique_id "amufxPW1Jl2-fgIeVvqqVgAAAPc"]
[Thu Jul 30 14:02:28.306822 2026] [security2:error] [pid 977210:tid 977430] [client 181.116.200.68:23411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufxPW1Jl2-fgIeVvqqVwAAAN0"]
[Thu Jul 30 14:02:28.306944 2026] [security2:error] [pid 977210:tid 977430] [client 181.116.200.68:23411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufxPW1Jl2-fgIeVvqqVwAAAN0"]
[Thu Jul 30 14:02:28.505551 2026] [security2:error] [pid 977210:tid 977453] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/class-t.api.php"] [unique_id "amufxPW1Jl2-fgIeVvqqZQAAAPQ"]
[Thu Jul 30 14:02:28.505656 2026] [security2:error] [pid 977210:tid 977453] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/class-t.api.php"] [unique_id "amufxPW1Jl2-fgIeVvqqZQAAAPQ"]
[Thu Jul 30 14:02:28.553712 2026] [security2:error] [pid 977210:tid 977351] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/wp.php"] [unique_id "amufxPW1Jl2-fgIeVvqqaAAAAI4"]
[Thu Jul 30 14:02:28.553842 2026] [security2:error] [pid 977210:tid 977351] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/wp.php"] [unique_id "amufxPW1Jl2-fgIeVvqqaAAAAI4"]
[Thu Jul 30 14:02:28.804889 2026] [security2:error] [pid 977210:tid 977393] [client 103.242.199.184:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufxPW1Jl2-fgIeVvqqbAAAALg"]
[Thu Jul 30 14:02:28.805653 2026] [security2:error] [pid 977210:tid 977393] [client 103.242.199.184:63353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufxPW1Jl2-fgIeVvqqbAAAALg"]
[Thu Jul 30 14:02:28.867849 2026] [security2:error] [pid 977210:tid 977398] [client 20.104.16.169:36114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/gelio1.php"] [unique_id "amufxPW1Jl2-fgIeVvqqcwAAAL0"]
[Thu Jul 30 14:02:28.868010 2026] [security2:error] [pid 977210:tid 977398] [client 20.104.16.169:36114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/gelio1.php"] [unique_id "amufxPW1Jl2-fgIeVvqqcwAAAL0"]
[Thu Jul 30 14:02:28.869013 2026] [security2:error] [pid 977210:tid 977379] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/fffm.php"] [unique_id "amufxPW1Jl2-fgIeVvqqdAAAAKo"]
[Thu Jul 30 14:02:28.869089 2026] [security2:error] [pid 977210:tid 977379] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/fffm.php"] [unique_id "amufxPW1Jl2-fgIeVvqqdAAAAKo"]
[Thu Jul 30 14:02:28.993132 2026] [security2:error] [pid 977210:tid 977416] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/simple.php"] [unique_id "amufxPW1Jl2-fgIeVvqqfgAAAM8"]
[Thu Jul 30 14:02:28.993238 2026] [security2:error] [pid 977210:tid 977416] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/simple.php"] [unique_id "amufxPW1Jl2-fgIeVvqqfgAAAM8"]
[Thu Jul 30 14:02:29.056685 2026] [security2:error] [pid 977210:tid 977355] [client 74.7.228.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alanturner.com.au"] [uri "/robots.txt"] [unique_id "amufxfW1Jl2-fgIeVvqqigAAAJI"]
[Thu Jul 30 14:02:29.057393 2026] [security2:error] [pid 977210:tid 977402] [client 74.7.228.10:44064] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alanturner.com.au"] [uri "/robots.txt"] [unique_id "amufxfW1Jl2-fgIeVvqqiAAAwTk"]
[Thu Jul 30 14:02:29.174859 2026] [security2:error] [pid 977210:tid 977458] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/111.php"] [unique_id "amufxfW1Jl2-fgIeVvqqiwAAAPk"]
[Thu Jul 30 14:02:29.174990 2026] [security2:error] [pid 977210:tid 977458] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/111.php"] [unique_id "amufxfW1Jl2-fgIeVvqqiwAAAPk"]
[Thu Jul 30 14:02:29.323733 2026] [security2:error] [pid 977210:tid 977389] [client 2.138.240.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amufxPW1Jl2-fgIeVvqqXQAAALQ"], referer: https://shop-mevius.com/product/terea-17/
[Thu Jul 30 14:02:29.499470 2026] [proxy:error] [pid 977210:tid 977469] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:29.499565 2026] [proxy_http:error] [pid 977210:tid 977469] [client 20.100.169.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:29.500314 2026] [proxy:error] [pid 977210:tid 977469] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:29.500363 2026] [proxy_http:error] [pid 977210:tid 977469] [client 20.100.169.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:29.500482 2026] [security2:error] [pid 977210:tid 977469] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amufxfW1Jl2-fgIeVvqqlAAAAQQ"]
[Thu Jul 30 14:02:29.512277 2026] [security2:error] [pid 977210:tid 977401] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/ioxi-o.php"] [unique_id "amufxfW1Jl2-fgIeVvqqmAAAAMA"]
[Thu Jul 30 14:02:29.512379 2026] [security2:error] [pid 977210:tid 977401] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/ioxi-o.php"] [unique_id "amufxfW1Jl2-fgIeVvqqmAAAAMA"]
[Thu Jul 30 14:02:29.703125 2026] [security2:error] [pid 977210:tid 977367] [client 172.202.44.182:31835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/asd.php"] [unique_id "amufxfW1Jl2-fgIeVvqqogAAAJ4"]
[Thu Jul 30 14:02:30.065021 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/___proxy_subdomain_webmail/wp-admin"] [unique_id "amufxvW1Jl2-fgIeVvqqqQAAAIY"]
[Thu Jul 30 14:02:30.167290 2026] [security2:error] [pid 977210:tid 977386] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/ws.php"] [unique_id "amufxvW1Jl2-fgIeVvqqrgAAALE"]
[Thu Jul 30 14:02:30.167396 2026] [security2:error] [pid 977210:tid 977386] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/ws.php"] [unique_id "amufxvW1Jl2-fgIeVvqqrgAAALE"]
[Thu Jul 30 14:02:30.312475 2026] [security2:error] [pid 977210:tid 977350] [client 20.104.16.169:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/lp6.php"] [unique_id "amufxvW1Jl2-fgIeVvqqrwAAAI0"]
[Thu Jul 30 14:02:30.312613 2026] [security2:error] [pid 977210:tid 977350] [client 20.104.16.169:36144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/lp6.php"] [unique_id "amufxvW1Jl2-fgIeVvqqrwAAAI0"]
[Thu Jul 30 14:02:30.313134 2026] [security2:error] [pid 977210:tid 977365] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp.php"] [unique_id "amufxvW1Jl2-fgIeVvqqsAAAAJw"]
[Thu Jul 30 14:02:30.313291 2026] [security2:error] [pid 977210:tid 977365] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp.php"] [unique_id "amufxvW1Jl2-fgIeVvqqsAAAAJw"]
[Thu Jul 30 14:02:30.405723 2026] [security2:error] [pid 977210:tid 977452] [client 74.7.230.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.lalibanista.com"] [uri "/index.php"] [unique_id "amufxfW1Jl2-fgIeVvqqjAAA8yE"]
[Thu Jul 30 14:02:30.405756 2026] [security2:error] [pid 977210:tid 977452] [client 74.7.230.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lalibanista.com"] [uri "/index.php"] [unique_id "amufxfW1Jl2-fgIeVvqqjAAA8yE"]
[Thu Jul 30 14:02:30.485256 2026] [security2:error] [pid 977210:tid 977393] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/coffee.php"] [unique_id "amufxvW1Jl2-fgIeVvqqtgAAALg"]
[Thu Jul 30 14:02:30.485363 2026] [security2:error] [pid 977210:tid 977393] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/coffee.php"] [unique_id "amufxvW1Jl2-fgIeVvqqtgAAALg"]
[Thu Jul 30 14:02:30.787888 2026] [security2:error] [pid 977210:tid 977441] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/goods.php"] [unique_id "amufxvW1Jl2-fgIeVvqqvQAAAOg"]
[Thu Jul 30 14:02:30.788009 2026] [security2:error] [pid 977210:tid 977441] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/goods.php"] [unique_id "amufxvW1Jl2-fgIeVvqqvQAAAOg"]
[Thu Jul 30 14:02:30.795221 2026] [security2:error] [pid 977210:tid 977363] [client 191.232.199.39:10062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/gmo.php"] [unique_id "amufxvW1Jl2-fgIeVvqqvgAAAJo"]
[Thu Jul 30 14:02:30.836666 2026] [security2:error] [pid 977210:tid 977446] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/file2.php"] [unique_id "amufxvW1Jl2-fgIeVvqqvwAAAO0"]
[Thu Jul 30 14:02:30.836823 2026] [security2:error] [pid 977210:tid 977446] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/file2.php"] [unique_id "amufxvW1Jl2-fgIeVvqqvwAAAO0"]
[Thu Jul 30 14:02:30.936685 2026] [security2:error] [pid 977210:tid 977445] [client 172.213.208.20:38994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/w.php"] [unique_id "amufxvW1Jl2-fgIeVvqqwAAAAOw"]
[Thu Jul 30 14:02:31.108111 2026] [security2:error] [pid 977210:tid 977409] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amufx_W1Jl2-fgIeVvqqzQAAAMg"]
[Thu Jul 30 14:02:31.108221 2026] [security2:error] [pid 977210:tid 977409] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amufx_W1Jl2-fgIeVvqqzQAAAMg"]
[Thu Jul 30 14:02:31.341584 2026] [security2:error] [pid 977210:tid 977439] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/images/class-config.php"] [unique_id "amufx_W1Jl2-fgIeVvqqzgAAAOY"]
[Thu Jul 30 14:02:31.341706 2026] [security2:error] [pid 977210:tid 977439] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/images/class-config.php"] [unique_id "amufx_W1Jl2-fgIeVvqqzgAAAOY"]
[Thu Jul 30 14:02:31.439151 2026] [security2:error] [pid 977210:tid 977405] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amufx_W1Jl2-fgIeVvqqzwAAAMQ"]
[Thu Jul 30 14:02:31.439267 2026] [security2:error] [pid 977210:tid 977405] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amufx_W1Jl2-fgIeVvqqzwAAAMQ"]
[Thu Jul 30 14:02:31.473704 2026] [security2:error] [pid 977210:tid 977424] [client 172.202.44.182:50971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/customize/index.php"] [unique_id "amufx_W1Jl2-fgIeVvqq1AAAANc"]
[Thu Jul 30 14:02:31.562580 2026] [security2:error] [pid 977210:tid 977415] [client 74.7.230.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lalibanista.com"] [uri "/index.php"] [unique_id "amufx_W1Jl2-fgIeVvqq0QAAzlA"], referer: https://www.lalibanista.com/robots.txt
[Thu Jul 30 14:02:31.594953 2026] [security2:error] [pid 977210:tid 977457] [client 172.213.208.20:32379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/admin.php"] [unique_id "amufx_W1Jl2-fgIeVvqq3AAAAPg"]
[Thu Jul 30 14:02:31.611456 2026] [security2:error] [pid 977210:tid 977451] [client 184.75.223.227:34316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amufx_W1Jl2-fgIeVvqq3QAAAPI"]
[Thu Jul 30 14:02:31.611626 2026] [security2:error] [pid 977210:tid 977451] [client 184.75.223.227:34316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amufx_W1Jl2-fgIeVvqq3QAAAPI"]
[Thu Jul 30 14:02:31.755902 2026] [security2:error] [pid 977210:tid 977364] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amufx_W1Jl2-fgIeVvqq4QAAAJs"]
[Thu Jul 30 14:02:31.756057 2026] [security2:error] [pid 977210:tid 977364] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amufx_W1Jl2-fgIeVvqq4QAAAJs"]
[Thu Jul 30 14:02:31.813927 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.16.169:36116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/wp-admin/maint/admin.php"] [unique_id "amufx_W1Jl2-fgIeVvqq4wAAAIY"]
[Thu Jul 30 14:02:31.814056 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.16.169:36116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/wp-admin/maint/admin.php"] [unique_id "amufx_W1Jl2-fgIeVvqq4wAAAIY"]
[Thu Jul 30 14:02:31.833707 2026] [security2:error] [pid 977210:tid 977404] [client 20.104.22.47:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/1.php"] [unique_id "amufx_W1Jl2-fgIeVvqq5AAAAMM"]
[Thu Jul 30 14:02:31.833814 2026] [security2:error] [pid 977210:tid 977404] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/1.php"] [unique_id "amufx_W1Jl2-fgIeVvqq5AAAAMM"]
[Thu Jul 30 14:02:31.833911 2026] [security2:error] [pid 977210:tid 977404] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/1.php"] [unique_id "amufx_W1Jl2-fgIeVvqq5AAAAMM"]
[Thu Jul 30 14:02:31.944330 2026] [security2:error] [pid 977210:tid 977342] [client 103.190.40.154:19103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufx_W1Jl2-fgIeVvqq5gAAAIU"]
[Thu Jul 30 14:02:31.944463 2026] [security2:error] [pid 977210:tid 977342] [client 103.190.40.154:19103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amufx_W1Jl2-fgIeVvqq5gAAAIU"]
[Thu Jul 30 14:02:32.075510 2026] [security2:error] [pid 977210:tid 977440] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amufyPW1Jl2-fgIeVvqq6gAAAOc"]
[Thu Jul 30 14:02:32.075614 2026] [security2:error] [pid 977210:tid 977440] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amufyPW1Jl2-fgIeVvqq6gAAAOc"]
[Thu Jul 30 14:02:32.097502 2026] [security2:error] [pid 977210:tid 977456] [client 191.232.199.39:43642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/languages/index.php"] [unique_id "amufyPW1Jl2-fgIeVvqq7gAAAPc"]
[Thu Jul 30 14:02:32.173595 2026] [security2:error] [pid 977210:tid 977442] [client 172.213.208.20:37648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/404.php"] [unique_id "amufyPW1Jl2-fgIeVvqq8gAAAOk"]
[Thu Jul 30 14:02:32.395326 2026] [security2:error] [pid 977210:tid 977465] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amufyPW1Jl2-fgIeVvqrCwAAAQA"]
[Thu Jul 30 14:02:32.395426 2026] [security2:error] [pid 977210:tid 977465] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amufyPW1Jl2-fgIeVvqrCwAAAQA"]
[Thu Jul 30 14:02:32.720406 2026] [security2:error] [pid 977210:tid 977359] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/adminfuns.php"] [unique_id "amufyPW1Jl2-fgIeVvqrIQAAAJY"]
[Thu Jul 30 14:02:32.720548 2026] [security2:error] [pid 977210:tid 977359] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/adminfuns.php"] [unique_id "amufyPW1Jl2-fgIeVvqrIQAAAJY"]
[Thu Jul 30 14:02:33.029801 2026] [security2:error] [pid 977210:tid 977469] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/404.php"] [unique_id "amufyfW1Jl2-fgIeVvqrLQAAAQQ"]
[Thu Jul 30 14:02:33.029901 2026] [security2:error] [pid 977210:tid 977469] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/404.php"] [unique_id "amufyfW1Jl2-fgIeVvqrLQAAAQQ"]
[Thu Jul 30 14:02:33.362433 2026] [security2:error] [pid 977210:tid 977372] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/xxx.php"] [unique_id "amufyfW1Jl2-fgIeVvqrRAAAAKM"]
[Thu Jul 30 14:02:33.362553 2026] [security2:error] [pid 977210:tid 977372] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/xxx.php"] [unique_id "amufyfW1Jl2-fgIeVvqrRAAAAKM"]
[Thu Jul 30 14:02:33.684334 2026] [security2:error] [pid 977210:tid 977448] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/classwithtostring.php"] [unique_id "amufyfW1Jl2-fgIeVvqrTAAAAO8"]
[Thu Jul 30 14:02:33.684430 2026] [security2:error] [pid 977210:tid 977448] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/classwithtostring.php"] [unique_id "amufyfW1Jl2-fgIeVvqrTAAAAO8"]
[Thu Jul 30 14:02:33.719546 2026] [security2:error] [pid 977210:tid 977421] [client 172.202.44.182:13618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amufyfW1Jl2-fgIeVvqrTwAAANQ"]
[Thu Jul 30 14:02:33.765907 2026] [security2:error] [pid 977210:tid 977456] [client 20.104.16.169:36099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.raad.pk"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amufyfW1Jl2-fgIeVvqrUQAAAPc"]
[Thu Jul 30 14:02:33.774629 2026] [security2:error] [pid 977210:tid 977464] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/222.php"] [unique_id "amufyfW1Jl2-fgIeVvqrUwAAAP8"]
[Thu Jul 30 14:02:33.774737 2026] [security2:error] [pid 977210:tid 977464] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/222.php"] [unique_id "amufyfW1Jl2-fgIeVvqrUwAAAP8"]
[Thu Jul 30 14:02:33.988261 2026] [security2:error] [pid 977210:tid 977353] [client 20.104.16.169:36099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/w3llscc.php"] [unique_id "amufyfW1Jl2-fgIeVvqrWQAAAJA"]
[Thu Jul 30 14:02:33.988450 2026] [security2:error] [pid 977210:tid 977353] [client 20.104.16.169:36099] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/w3llscc.php"] [unique_id "amufyfW1Jl2-fgIeVvqrWQAAAJA"]
[Thu Jul 30 14:02:33.991675 2026] [security2:error] [pid 977210:tid 977416] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/234ff.php"] [unique_id "amufyfW1Jl2-fgIeVvqrWgAAAM8"]
[Thu Jul 30 14:02:33.991757 2026] [security2:error] [pid 977210:tid 977416] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/234ff.php"] [unique_id "amufyfW1Jl2-fgIeVvqrWgAAAM8"]
[Thu Jul 30 14:02:34.283499 2026] [security2:error] [pid 977210:tid 977458] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/themes.php"] [unique_id "amufyvW1Jl2-fgIeVvqrYwAAAPk"]
[Thu Jul 30 14:02:34.283612 2026] [security2:error] [pid 977210:tid 977458] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/themes.php"] [unique_id "amufyvW1Jl2-fgIeVvqrYwAAAPk"]
[Thu Jul 30 14:02:34.332322 2026] [security2:error] [pid 977210:tid 977426] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/133.php"] [unique_id "amufyvW1Jl2-fgIeVvqrZQAAANk"]
[Thu Jul 30 14:02:34.332423 2026] [security2:error] [pid 977210:tid 977426] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/133.php"] [unique_id "amufyvW1Jl2-fgIeVvqrZQAAANk"]
[Thu Jul 30 14:02:34.371994 2026] [security2:error] [pid 977210:tid 977468] [client 191.232.199.39:10100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-the.php"] [unique_id "amufyvW1Jl2-fgIeVvqraAAAAQM"]
[Thu Jul 30 14:02:34.642780 2026] [security2:error] [pid 977210:tid 977407] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/wp-ws68.php"] [unique_id "amufyvW1Jl2-fgIeVvqragAAAMY"]
[Thu Jul 30 14:02:34.642942 2026] [security2:error] [pid 977210:tid 977407] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/wp-ws68.php"] [unique_id "amufyvW1Jl2-fgIeVvqragAAAMY"]
[Thu Jul 30 14:02:34.651459 2026] [fcgid:warn] [pid 977210:tid 977408] (70014)End of file found: [client 66.132.224.82:29572] mod_fcgid: can't get data from http client
[Thu Jul 30 14:02:34.814675 2026] [security2:error] [pid 977210:tid 977390] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/admin.php"] [unique_id "amufyvW1Jl2-fgIeVvqrcgAAALU"]
[Thu Jul 30 14:02:34.814808 2026] [security2:error] [pid 977210:tid 977390] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/admin.php"] [unique_id "amufyvW1Jl2-fgIeVvqrcgAAALU"]
[Thu Jul 30 14:02:34.962740 2026] [security2:error] [pid 977210:tid 977364] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/mgrr.php"] [unique_id "amufyvW1Jl2-fgIeVvqreQAAAJs"]
[Thu Jul 30 14:02:34.962860 2026] [security2:error] [pid 977210:tid 977364] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/mgrr.php"] [unique_id "amufyvW1Jl2-fgIeVvqreQAAAJs"]
[Thu Jul 30 14:02:35.083184 2026] [security2:error] [pid 977210:tid 977362] [client 172.213.208.20:17712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/init.php"] [unique_id "amufy_W1Jl2-fgIeVvqrewAAAJk"]
[Thu Jul 30 14:02:35.294690 2026] [security2:error] [pid 977210:tid 977448] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/55.php"] [unique_id "amufy_W1Jl2-fgIeVvqrggAAAO8"]
[Thu Jul 30 14:02:35.294806 2026] [security2:error] [pid 977210:tid 977448] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.tranquilrootsisb.space"] [uri "/55.php"] [unique_id "amufy_W1Jl2-fgIeVvqrggAAAO8"]
[Thu Jul 30 14:02:35.359703 2026] [security2:error] [pid 977210:tid 977440] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/dropdown.php"] [unique_id "amufy_W1Jl2-fgIeVvqrhgAAAOc"]
[Thu Jul 30 14:02:35.359820 2026] [security2:error] [pid 977210:tid 977440] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/dropdown.php"] [unique_id "amufy_W1Jl2-fgIeVvqrhgAAAOc"]
[Thu Jul 30 14:02:35.569644 2026] [core:notice] [pid 977210:tid 977430] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:35.619753 2026] [security2:error] [pid 977210:tid 977389] [client 172.202.44.182:18530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/atomlib.php"] [unique_id "amufy_W1Jl2-fgIeVvqriAAAALQ"]
[Thu Jul 30 14:02:35.634581 2026] [security2:error] [pid 977210:tid 977434] [client 191.232.199.39:10087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/404.php"] [unique_id "amufy_W1Jl2-fgIeVvqriQAAAOE"]
[Thu Jul 30 14:02:35.786071 2026] [security2:error] [pid 977210:tid 977442] [client 172.213.208.20:40264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/adminfuns.php"] [unique_id "amufy_W1Jl2-fgIeVvqrkwAAAOk"]
[Thu Jul 30 14:02:35.870532 2026] [security2:error] [pid 977210:tid 977446] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/inputs.php"] [unique_id "amufy_W1Jl2-fgIeVvqrmAAAAO0"]
[Thu Jul 30 14:02:35.870658 2026] [security2:error] [pid 977210:tid 977446] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/inputs.php"] [unique_id "amufy_W1Jl2-fgIeVvqrmAAAAO0"]
[Thu Jul 30 14:02:35.878873 2026] [security2:error] [pid 977210:tid 977455] [client 20.104.16.169:34893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/miru3.php"] [unique_id "amufy_W1Jl2-fgIeVvqrmgAAAPY"]
[Thu Jul 30 14:02:35.879034 2026] [security2:error] [pid 977210:tid 977455] [client 20.104.16.169:34893] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/miru3.php"] [unique_id "amufy_W1Jl2-fgIeVvqrmgAAAPY"]
[Thu Jul 30 14:02:36.401404 2026] [security2:error] [pid 977210:tid 977424] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/100.php"] [unique_id "amufzPW1Jl2-fgIeVvqrqQAAANc"]
[Thu Jul 30 14:02:36.401535 2026] [security2:error] [pid 977210:tid 977424] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/100.php"] [unique_id "amufzPW1Jl2-fgIeVvqrqQAAANc"]
[Thu Jul 30 14:02:36.547907 2026] [security2:error] [pid 977210:tid 977363] [client 43.173.132.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iwic.tw"] [uri "/index.php"] [unique_id "amufy_W1Jl2-fgIeVvqregAAmho"]
[Thu Jul 30 14:02:36.909130 2026] [security2:error] [pid 977210:tid 977411] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/autoload_classmap/function.php"] [unique_id "amufzPW1Jl2-fgIeVvqrtgAAAMo"]
[Thu Jul 30 14:02:36.909223 2026] [security2:error] [pid 977210:tid 977411] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/autoload_classmap/function.php"] [unique_id "amufzPW1Jl2-fgIeVvqrtgAAAMo"]
[Thu Jul 30 14:02:36.991918 2026] [security2:error] [pid 977210:tid 977375] [client 172.213.208.20:23352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/file.php"] [unique_id "amufzPW1Jl2-fgIeVvqrvQAAAKY"]
[Thu Jul 30 14:02:37.416847 2026] [security2:error] [pid 977210:tid 977437] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/php.php"] [unique_id "amufzfW1Jl2-fgIeVvqrxQAAAOQ"]
[Thu Jul 30 14:02:37.416950 2026] [security2:error] [pid 977210:tid 977437] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/php.php"] [unique_id "amufzfW1Jl2-fgIeVvqrxQAAAOQ"]
[Thu Jul 30 14:02:37.505919 2026] [security2:error] [pid 977210:tid 977377] [client 172.213.208.20:39036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/222.php"] [unique_id "amufzfW1Jl2-fgIeVvqryQAAAKg"]
[Thu Jul 30 14:02:37.515330 2026] [security2:error] [pid 977210:tid 977452] [client 191.232.199.39:38725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/init.php"] [unique_id "amufzfW1Jl2-fgIeVvqrygAAAPM"]
[Thu Jul 30 14:02:37.933032 2026] [security2:error] [pid 977210:tid 977468] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/t.php"] [unique_id "amufzfW1Jl2-fgIeVvqr0QAAAQM"]
[Thu Jul 30 14:02:37.933152 2026] [security2:error] [pid 977210:tid 977468] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/t.php"] [unique_id "amufzfW1Jl2-fgIeVvqr0QAAAQM"]
[Thu Jul 30 14:02:38.065464 2026] [security2:error] [pid 977210:tid 977240] [remote 57.141.0.55:49524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amufzvW1Jl2-fgIeVvqr1QAA2hs"]
[Thu Jul 30 14:02:38.073055 2026] [security2:error] [pid 977210:tid 977383] [client 20.104.16.169:36162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/autoload_classmap.php"] [unique_id "amufzvW1Jl2-fgIeVvqr1gAAAK4"]
[Thu Jul 30 14:02:38.073173 2026] [security2:error] [pid 977210:tid 977383] [client 20.104.16.169:36162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/autoload_classmap.php"] [unique_id "amufzvW1Jl2-fgIeVvqr1gAAAK4"]
[Thu Jul 30 14:02:38.420949 2026] [security2:error] [pid 977210:tid 977420] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-blink.php"] [unique_id "amufzvW1Jl2-fgIeVvqr4QAAANM"]
[Thu Jul 30 14:02:38.421061 2026] [security2:error] [pid 977210:tid 977420] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-blink.php"] [unique_id "amufzvW1Jl2-fgIeVvqr4QAAANM"]
[Thu Jul 30 14:02:38.877419 2026] [security2:error] [pid 977210:tid 977467] [client 191.232.199.39:9303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/file5.php"] [unique_id "amufzvW1Jl2-fgIeVvqr7AAAAQI"]
[Thu Jul 30 14:02:38.916093 2026] [security2:error] [pid 977210:tid 977345] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/xfun.php"] [unique_id "amufzvW1Jl2-fgIeVvqr7gAAAIg"]
[Thu Jul 30 14:02:38.916208 2026] [security2:error] [pid 977210:tid 977345] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/xfun.php"] [unique_id "amufzvW1Jl2-fgIeVvqr7gAAAIg"]
[Thu Jul 30 14:02:38.972294 2026] [security2:error] [pid 977210:tid 977441] [client 181.116.200.68:58836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufzvW1Jl2-fgIeVvqr8gAAAOg"]
[Thu Jul 30 14:02:38.973047 2026] [security2:error] [pid 977210:tid 977441] [client 181.116.200.68:58836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amufzvW1Jl2-fgIeVvqr8gAAAOg"]
[Thu Jul 30 14:02:39.134736 2026] [security2:error] [pid 977210:tid 977361] [client 172.213.208.20:37632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amufz_W1Jl2-fgIeVvqr_QAAAJg"]
[Thu Jul 30 14:02:39.188971 2026] [security2:error] [pid 977210:tid 977421] [client 172.202.44.182:13584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amufz_W1Jl2-fgIeVvqr_gAAANQ"]
[Thu Jul 30 14:02:39.285697 2026] [security2:error] [pid 977210:tid 977384] [client 20.104.16.169:36187] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.raad.pk"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amufz_W1Jl2-fgIeVvqsAAAAAK8"]
[Thu Jul 30 14:02:39.413248 2026] [security2:error] [pid 977210:tid 977452] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/p.php"] [unique_id "amufz_W1Jl2-fgIeVvqsBAAAAPM"]
[Thu Jul 30 14:02:39.413400 2026] [security2:error] [pid 977210:tid 977452] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/p.php"] [unique_id "amufz_W1Jl2-fgIeVvqsBAAAAPM"]
[Thu Jul 30 14:02:39.463907 2026] [security2:error] [pid 977210:tid 977433] [client 103.242.199.184:63906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufz_W1Jl2-fgIeVvqsCAAAAOA"]
[Thu Jul 30 14:02:39.464015 2026] [security2:error] [pid 977210:tid 977433] [client 103.242.199.184:63906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amufz_W1Jl2-fgIeVvqsCAAAAOA"]
[Thu Jul 30 14:02:39.467824 2026] [security2:error] [pid 977210:tid 977442] [client 68.67.112.51:11340] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amufz_W1Jl2-fgIeVvqsCQAAAOk"]
[Thu Jul 30 14:02:39.893734 2026] [security2:error] [pid 977210:tid 977427] [client 20.104.16.169:36187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/wp-content/themes/index.php"] [unique_id "amufz_W1Jl2-fgIeVvqsEAAAANo"]
[Thu Jul 30 14:02:39.893879 2026] [security2:error] [pid 977210:tid 977427] [client 20.104.16.169:36187] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/wp-content/themes/index.php"] [unique_id "amufz_W1Jl2-fgIeVvqsEAAAANo"]
[Thu Jul 30 14:02:39.911157 2026] [core:error] [pid 977210:tid 977348] [client 172.213.208.20:14565] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:39.911180 2026] [core:error] [pid 977210:tid 977348] [client 172.213.208.20:14565] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:39.918748 2026] [security2:error] [pid 977210:tid 977446] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/themes/admin.php"] [unique_id "amufz_W1Jl2-fgIeVvqsIAAAAO0"]
[Thu Jul 30 14:02:39.918831 2026] [security2:error] [pid 977210:tid 977446] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/themes/admin.php"] [unique_id "amufz_W1Jl2-fgIeVvqsIAAAAO0"]
[Thu Jul 30 14:02:40.139116 2026] [core:error] [pid 977210:tid 977410] [client 66.249.65.172:61261] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:40.139138 2026] [core:error] [pid 977210:tid 977410] [client 66.249.65.172:61261] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:40.402593 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/aaa.php"] [unique_id "amuf0PW1Jl2-fgIeVvqsMwAAAIY"]
[Thu Jul 30 14:02:40.402721 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/aaa.php"] [unique_id "amuf0PW1Jl2-fgIeVvqsMwAAAIY"]
[Thu Jul 30 14:02:40.631745 2026] [security2:error] [pid 977210:tid 977386] [client 20.104.16.169:36141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/av.php"] [unique_id "amuf0PW1Jl2-fgIeVvqsPAAAALE"]
[Thu Jul 30 14:02:40.631853 2026] [security2:error] [pid 977210:tid 977386] [client 20.104.16.169:36141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/av.php"] [unique_id "amuf0PW1Jl2-fgIeVvqsPAAAALE"]
[Thu Jul 30 14:02:40.915936 2026] [security2:error] [pid 977210:tid 977430] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/7.php"] [unique_id "amuf0PW1Jl2-fgIeVvqsRgAAAN0"]
[Thu Jul 30 14:02:40.916059 2026] [security2:error] [pid 977210:tid 977430] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/7.php"] [unique_id "amuf0PW1Jl2-fgIeVvqsRgAAAN0"]
[Thu Jul 30 14:02:41.147290 2026] [security2:error] [pid 977210:tid 977418] [client 223.237.26.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amuf0PW1Jl2-fgIeVvqsMgAAANE"], referer: https://shop-mevius.com/product/terea-17/
[Thu Jul 30 14:02:41.169831 2026] [security2:error] [pid 977210:tid 977376] [client 20.104.16.169:36206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.raad.pk"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuf0fW1Jl2-fgIeVvqsYgAAAKc"]
[Thu Jul 30 14:02:41.183347 2026] [security2:error] [pid 977210:tid 977387] [client 191.232.199.39:39613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuf0fW1Jl2-fgIeVvqsYwAAALI"]
[Thu Jul 30 14:02:41.305270 2026] [security2:error] [pid 977210:tid 977466] [client 85.204.70.94:60166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "amuf0fW1Jl2-fgIeVvqsZAAAAQE"]
[Thu Jul 30 14:02:41.381314 2026] [security2:error] [pid 977210:tid 977359] [client 20.104.16.169:36206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.raad.pk"] [uri "/___proxy_subdomain_webdisk/wordpress/wp-admin/maint/"] [unique_id "amuf0fW1Jl2-fgIeVvqsZQAAAJY"]
[Thu Jul 30 14:02:41.393492 2026] [security2:error] [pid 977210:tid 977426] [client 172.202.44.182:31845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/inputs.php"] [unique_id "amuf0fW1Jl2-fgIeVvqsZgAAANk"]
[Thu Jul 30 14:02:41.431831 2026] [security2:error] [pid 977210:tid 977348] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/file5.php"] [unique_id "amuf0fW1Jl2-fgIeVvqsawAAAIs"]
[Thu Jul 30 14:02:41.431926 2026] [security2:error] [pid 977210:tid 977348] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/file5.php"] [unique_id "amuf0fW1Jl2-fgIeVvqsawAAAIs"]
[Thu Jul 30 14:02:41.578342 2026] [security2:error] [pid 977210:tid 977422] [client 20.104.16.169:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/tiny.php"] [unique_id "amuf0fW1Jl2-fgIeVvqscQAAANU"]
[Thu Jul 30 14:02:41.578432 2026] [security2:error] [pid 977210:tid 977422] [client 20.104.16.169:36206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/tiny.php"] [unique_id "amuf0fW1Jl2-fgIeVvqscQAAANU"]
[Thu Jul 30 14:02:41.803887 2026] [security2:error] [pid 977210:tid 977431] [client 85.204.70.94:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "amuf0fW1Jl2-fgIeVvqseQAAAN4"]
[Thu Jul 30 14:02:41.941242 2026] [security2:error] [pid 977210:tid 977394] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/makeasmtp.php"] [unique_id "amuf0fW1Jl2-fgIeVvqsegAAALk"]
[Thu Jul 30 14:02:41.941352 2026] [security2:error] [pid 977210:tid 977394] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/makeasmtp.php"] [unique_id "amuf0fW1Jl2-fgIeVvqsegAAALk"]
[Thu Jul 30 14:02:42.022728 2026] [security2:error] [pid 977210:tid 977248] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amuf0fW1Jl2-fgIeVvqsbQAAkCM"]
[Thu Jul 30 14:02:42.022911 2026] [security2:error] [pid 977210:tid 977353] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amuf0fW1Jl2-fgIeVvqsbQAAkCM"]
[Thu Jul 30 14:02:42.074212 2026] [security2:error] [pid 977210:tid 977406] [client 20.104.16.169:36210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuf0vW1Jl2-fgIeVvqsfgAAAMU"]
[Thu Jul 30 14:02:42.074309 2026] [security2:error] [pid 977210:tid 977406] [client 20.104.16.169:36210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuf0vW1Jl2-fgIeVvqsfgAAAMU"]
[Thu Jul 30 14:02:42.167701 2026] [core:notice] [pid 977210:tid 977340] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:42.432878 2026] [core:notice] [pid 977210:tid 977245] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:42.458175 2026] [security2:error] [pid 977210:tid 977433] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/index.php"] [unique_id "amuf0vW1Jl2-fgIeVvqsiwAAAOA"]
[Thu Jul 30 14:02:42.458259 2026] [security2:error] [pid 977210:tid 977433] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/index.php"] [unique_id "amuf0vW1Jl2-fgIeVvqsiwAAAOA"]
[Thu Jul 30 14:02:42.602788 2026] [security2:error] [pid 977210:tid 977349] [client 20.104.16.169:36134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/zrrhj.php"] [unique_id "amuf0vW1Jl2-fgIeVvqsjwAAAIw"]
[Thu Jul 30 14:02:42.602915 2026] [security2:error] [pid 977210:tid 977349] [client 20.104.16.169:36134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/zrrhj.php"] [unique_id "amuf0vW1Jl2-fgIeVvqsjwAAAIw"]
[Thu Jul 30 14:02:42.699774 2026] [security2:error] [pid 977210:tid 977346] [client 103.190.40.154:19225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf0vW1Jl2-fgIeVvqskwAAAIk"]
[Thu Jul 30 14:02:42.699938 2026] [security2:error] [pid 977210:tid 977346] [client 103.190.40.154:19225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf0vW1Jl2-fgIeVvqskwAAAIk"]
[Thu Jul 30 14:02:42.779384 2026] [security2:error] [pid 977210:tid 977403] [client 191.232.199.39:51271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/shell.php"] [unique_id "amuf0vW1Jl2-fgIeVvqslwAAAMI"]
[Thu Jul 30 14:02:42.951914 2026] [security2:error] [pid 977210:tid 977429] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/atomlib.php"] [unique_id "amuf0vW1Jl2-fgIeVvqsmwAAANw"]
[Thu Jul 30 14:02:42.952047 2026] [security2:error] [pid 977210:tid 977429] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/atomlib.php"] [unique_id "amuf0vW1Jl2-fgIeVvqsmwAAANw"]
[Thu Jul 30 14:02:42.953580 2026] [security2:error] [pid 977210:tid 977397] [client 85.204.70.94:60198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuf0vW1Jl2-fgIeVvqsnAAAALw"]
[Thu Jul 30 14:02:43.126883 2026] [security2:error] [pid 977210:tid 977350] [client 20.104.16.169:36185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuf0_W1Jl2-fgIeVvqsnQAAAI0"]
[Thu Jul 30 14:02:43.127011 2026] [security2:error] [pid 977210:tid 977350] [client 20.104.16.169:36185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuf0_W1Jl2-fgIeVvqsnQAAAI0"]
[Thu Jul 30 14:02:43.448795 2026] [security2:error] [pid 977210:tid 977427] [client 113.30.194.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuf0_W1Jl2-fgIeVvqsqAAAANo"], referer: https://www.google.com/
[Thu Jul 30 14:02:43.513438 2026] [security2:error] [pid 977210:tid 977375] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/min.php"] [unique_id "amuf0_W1Jl2-fgIeVvqsrgAAAKY"]
[Thu Jul 30 14:02:43.513604 2026] [security2:error] [pid 977210:tid 977375] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/min.php"] [unique_id "amuf0_W1Jl2-fgIeVvqsrgAAAKY"]
[Thu Jul 30 14:02:43.515830 2026] [security2:error] [pid 977210:tid 977370] [client 85.204.70.94:60212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "amuf0_W1Jl2-fgIeVvqsrwAAAKE"]
[Thu Jul 30 14:02:43.612549 2026] [security2:error] [pid 977210:tid 977400] [client 20.104.16.169:36119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/wpgum.php"] [unique_id "amuf0_W1Jl2-fgIeVvqssAAAAL8"]
[Thu Jul 30 14:02:43.612671 2026] [security2:error] [pid 977210:tid 977400] [client 20.104.16.169:36119] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/wpgum.php"] [unique_id "amuf0_W1Jl2-fgIeVvqssAAAAL8"]
[Thu Jul 30 14:02:43.827159 2026] [security2:error] [pid 977210:tid 977434] [client 127.0.0.1:42488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuf0_W1Jl2-fgIeVvqsvgAAAOE"]
[Thu Jul 30 14:02:43.827174 2026] [security2:error] [pid 977210:tid 977418] [client 127.0.0.1:42484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuf0_W1Jl2-fgIeVvqsvQAAANE"]
[Thu Jul 30 14:02:43.827319 2026] [security2:error] [pid 977210:tid 977430] [client 74.7.175.167:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.blsspainvisacenterpakistan.site"] [uri "/robots.txt"] [unique_id "amuf0_W1Jl2-fgIeVvqsuwAA3Qc"]
[Thu Jul 30 14:02:44.032256 2026] [security2:error] [pid 977210:tid 977396] [client 20.104.16.169:36184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/ywwbf.php"] [unique_id "amuf1PW1Jl2-fgIeVvqsxQAAALs"]
[Thu Jul 30 14:02:44.032366 2026] [security2:error] [pid 977210:tid 977396] [client 20.104.16.169:36184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/ywwbf.php"] [unique_id "amuf1PW1Jl2-fgIeVvqsxQAAALs"]
[Thu Jul 30 14:02:44.040362 2026] [security2:error] [pid 977210:tid 977445] [client 85.204.70.94:60220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuf1PW1Jl2-fgIeVvqsxgAAAOw"]
[Thu Jul 30 14:02:44.052905 2026] [security2:error] [pid 977210:tid 977395] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/moon.php"] [unique_id "amuf1PW1Jl2-fgIeVvqsxwAAALo"]
[Thu Jul 30 14:02:44.053109 2026] [security2:error] [pid 977210:tid 977395] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/moon.php"] [unique_id "amuf1PW1Jl2-fgIeVvqsxwAAALo"]
[Thu Jul 30 14:02:44.066178 2026] [core:error] [pid 977210:tid 977359] [client 152.32.223.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:44.066196 2026] [core:error] [pid 977210:tid 977359] [client 152.32.223.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:44.306387 2026] [security2:error] [pid 977210:tid 977352] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuf0_W1Jl2-fgIeVvqstgAAAI8"]
[Thu Jul 30 14:02:44.493395 2026] [security2:error] [pid 977210:tid 977226] [remote 57.141.0.25:30182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/24984966950/feed/rss2/"] [unique_id "amuf1PW1Jl2-fgIeVvqs0AAA2A0"]
[Thu Jul 30 14:02:44.523669 2026] [security2:error] [pid 977210:tid 977423] [client 20.104.16.169:34890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/xoldj.php"] [unique_id "amuf1PW1Jl2-fgIeVvqs5AAAANY"]
[Thu Jul 30 14:02:44.523756 2026] [security2:error] [pid 977210:tid 977423] [client 20.104.16.169:34890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/xoldj.php"] [unique_id "amuf1PW1Jl2-fgIeVvqs5AAAANY"]
[Thu Jul 30 14:02:44.548532 2026] [security2:error] [pid 977210:tid 977397] [client 85.204.70.94:60236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "amuf1PW1Jl2-fgIeVvqs5QAAALw"]
[Thu Jul 30 14:02:44.553321 2026] [security2:error] [pid 977210:tid 977357] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/ws83.php"] [unique_id "amuf1PW1Jl2-fgIeVvqs5gAAAJQ"]
[Thu Jul 30 14:02:44.553394 2026] [security2:error] [pid 977210:tid 977357] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/ws83.php"] [unique_id "amuf1PW1Jl2-fgIeVvqs5gAAAJQ"]
[Thu Jul 30 14:02:44.940185 2026] [security2:error] [pid 977210:tid 977411] [client 37.140.254.44:23301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.254.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/archivarix.cms.php"] [unique_id "amuf1PW1Jl2-fgIeVvqs_gAAAMo"]
[Thu Jul 30 14:02:44.971615 2026] [security2:error] [pid 977210:tid 977457] [client 191.232.199.39:30160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/f35.php"] [unique_id "amuf1PW1Jl2-fgIeVvqs_wAAAPg"]
[Thu Jul 30 14:02:45.045117 2026] [security2:error] [pid 977210:tid 977462] [client 20.104.16.169:34895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/f35.php"] [unique_id "amuf1fW1Jl2-fgIeVvqtBgAAAP0"]
[Thu Jul 30 14:02:45.045207 2026] [security2:error] [pid 977210:tid 977462] [client 20.104.16.169:34895] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/f35.php"] [unique_id "amuf1fW1Jl2-fgIeVvqtBgAAAP0"]
[Thu Jul 30 14:02:45.074333 2026] [security2:error] [pid 977210:tid 977432] [client 172.202.44.182:13574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/index.php"] [unique_id "amuf1fW1Jl2-fgIeVvqtDAAAAN8"]
[Thu Jul 30 14:02:45.082450 2026] [security2:error] [pid 977210:tid 977433] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/403.php"] [unique_id "amuf1fW1Jl2-fgIeVvqtDQAAAOA"]
[Thu Jul 30 14:02:45.082523 2026] [security2:error] [pid 977210:tid 977433] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/403.php"] [unique_id "amuf1fW1Jl2-fgIeVvqtDQAAAOA"]
[Thu Jul 30 14:02:45.119256 2026] [security2:error] [pid 977210:tid 977370] [client 85.204.70.94:60246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuf1fW1Jl2-fgIeVvqtFAAAAKE"]
[Thu Jul 30 14:02:45.607760 2026] [security2:error] [pid 977210:tid 977392] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/api.php"] [unique_id "amuf1fW1Jl2-fgIeVvqtIgAAALc"]
[Thu Jul 30 14:02:45.607876 2026] [security2:error] [pid 977210:tid 977392] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/api.php"] [unique_id "amuf1fW1Jl2-fgIeVvqtIgAAALc"]
[Thu Jul 30 14:02:45.625616 2026] [security2:error] [pid 977210:tid 977449] [client 85.204.70.94:60258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "amuf1fW1Jl2-fgIeVvqtIwAAAPA"]
[Thu Jul 30 14:02:45.696629 2026] [security2:error] [pid 977210:tid 977402] [client 20.104.16.169:36160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/gk.php"] [unique_id "amuf1fW1Jl2-fgIeVvqtJAAAAME"]
[Thu Jul 30 14:02:45.696733 2026] [security2:error] [pid 977210:tid 977402] [client 20.104.16.169:36160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/gk.php"] [unique_id "amuf1fW1Jl2-fgIeVvqtJAAAAME"]
[Thu Jul 30 14:02:45.782506 2026] [security2:error] [pid 977210:tid 977346] [client 85.208.96.195:23002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/05/06/presidente-nacional-da-nokia-diz-que-campina-grande-sera-primeira-cidade-brasileira-a-receber-tecnologia-5g/"] [unique_id "amuf1fW1Jl2-fgIeVvqtKwAAAIk"]
[Thu Jul 30 14:02:45.782657 2026] [security2:error] [pid 977210:tid 977346] [client 85.208.96.195:23002] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/05/06/presidente-nacional-da-nokia-diz-que-campina-grande-sera-primeira-cidade-brasileira-a-receber-tecnologia-5g/"] [unique_id "amuf1fW1Jl2-fgIeVvqtKwAAAIk"]
[Thu Jul 30 14:02:46.132947 2026] [security2:error] [pid 977210:tid 977425] [client 85.204.70.94:60272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuf1vW1Jl2-fgIeVvqtMgAAANg"]
[Thu Jul 30 14:02:46.139927 2026] [security2:error] [pid 977210:tid 977358] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/3.php"] [unique_id "amuf1vW1Jl2-fgIeVvqtMwAAAJU"]
[Thu Jul 30 14:02:46.140023 2026] [security2:error] [pid 977210:tid 977358] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/3.php"] [unique_id "amuf1vW1Jl2-fgIeVvqtMwAAAJU"]
[Thu Jul 30 14:02:46.354852 2026] [security2:error] [pid 977210:tid 977439] [client 20.104.16.169:36164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/584062352875874akp.php"] [unique_id "amuf1vW1Jl2-fgIeVvqtOgAAAOY"]
[Thu Jul 30 14:02:46.354961 2026] [security2:error] [pid 977210:tid 977439] [client 20.104.16.169:36164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/584062352875874akp.php"] [unique_id "amuf1vW1Jl2-fgIeVvqtOgAAAOY"]
[Thu Jul 30 14:02:46.722718 2026] [security2:error] [pid 977210:tid 977361] [client 85.204.70.94:60280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuf1vW1Jl2-fgIeVvqtPwAAAJg"]
[Thu Jul 30 14:02:46.736779 2026] [core:notice] [pid 977210:tid 977276] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:46.969438 2026] [security2:error] [pid 977210:tid 977383] [client 20.104.16.169:34875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/wper3.php"] [unique_id "amuf1vW1Jl2-fgIeVvqtSwAAAK4"]
[Thu Jul 30 14:02:46.969566 2026] [security2:error] [pid 977210:tid 977383] [client 20.104.16.169:34875] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/wper3.php"] [unique_id "amuf1vW1Jl2-fgIeVvqtSwAAAK4"]
[Thu Jul 30 14:02:47.002052 2026] [core:notice] [pid 977210:tid 977316] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:47.184214 2026] [security2:error] [pid 977210:tid 977405] [client 172.202.44.182:46445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/network/index.php"] [unique_id "amuf1_W1Jl2-fgIeVvqtTQAAAMQ"]
[Thu Jul 30 14:02:47.278965 2026] [security2:error] [pid 977210:tid 977348] [client 85.204.70.94:47494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuf1_W1Jl2-fgIeVvqtTgAAAIs"]
[Thu Jul 30 14:02:47.372056 2026] [security2:error] [pid 977210:tid 977362] [client 191.232.199.39:51324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/new.php"] [unique_id "amuf1_W1Jl2-fgIeVvqtUgAAAJk"]
[Thu Jul 30 14:02:47.383877 2026] [security2:error] [pid 977210:tid 977392] [client 20.104.16.169:36163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/bthil.php"] [unique_id "amuf1_W1Jl2-fgIeVvqtVQAAALc"]
[Thu Jul 30 14:02:47.383951 2026] [security2:error] [pid 977210:tid 977392] [client 20.104.16.169:36163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/bthil.php"] [unique_id "amuf1_W1Jl2-fgIeVvqtVQAAALc"]
[Thu Jul 30 14:02:47.831201 2026] [security2:error] [pid 977210:tid 977346] [client 85.204.70.94:60294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "amuf1_W1Jl2-fgIeVvqtWwAAAIk"]
[Thu Jul 30 14:02:47.841742 2026] [security2:error] [pid 977210:tid 977423] [client 20.104.16.169:34896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/wyzer1.php"] [unique_id "amuf1_W1Jl2-fgIeVvqtXQAAANY"]
[Thu Jul 30 14:02:47.841858 2026] [security2:error] [pid 977210:tid 977423] [client 20.104.16.169:34896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/wyzer1.php"] [unique_id "amuf1_W1Jl2-fgIeVvqtXQAAANY"]
[Thu Jul 30 14:02:48.304058 2026] [security2:error] [pid 977210:tid 977427] [client 172.202.44.182:46438] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/1.php"] [unique_id "amuf2PW1Jl2-fgIeVvqtaAAAANo"]
[Thu Jul 30 14:02:48.304199 2026] [security2:error] [pid 977210:tid 977427] [client 172.202.44.182:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/1.php"] [unique_id "amuf2PW1Jl2-fgIeVvqtaAAAANo"]
[Thu Jul 30 14:02:48.325820 2026] [security2:error] [pid 977210:tid 977375] [client 85.204.70.94:60304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "amuf2PW1Jl2-fgIeVvqtaQAAAKY"]
[Thu Jul 30 14:02:48.418949 2026] [security2:error] [pid 977210:tid 977458] [client 43.173.180.100:36582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/12/10/histoire-d-or-cadeaux-noel-2015/"] [unique_id "amuf2PW1Jl2-fgIeVvqtZwAAAPk"]
[Thu Jul 30 14:02:48.621397 2026] [core:notice] [pid 977210:tid 977430] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:48.625921 2026] [security2:error] [pid 977210:tid 977430] [client 43.172.194.90:58264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/12/10/histoire-d-or-cadeaux-noel-2015/"] [unique_id "amuf2PW1Jl2-fgIeVvqtdwAAAN0"], referer: https://carnetdeshopping.com/index.php/2015/12/10/histoire-d-or-cadeaux-noel-2015/
[Thu Jul 30 14:02:48.658646 2026] [security2:error] [pid 977210:tid 977447] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuf2PW1Jl2-fgIeVvqtZgAA7kE"]
[Thu Jul 30 14:02:48.691751 2026] [security2:error] [pid 977210:tid 977396] [client 20.104.16.169:36108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/mh.php"] [unique_id "amuf2PW1Jl2-fgIeVvqteAAAALs"]
[Thu Jul 30 14:02:48.691849 2026] [security2:error] [pid 977210:tid 977396] [client 20.104.16.169:36108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/mh.php"] [unique_id "amuf2PW1Jl2-fgIeVvqteAAAALs"]
[Thu Jul 30 14:02:48.869782 2026] [security2:error] [pid 977210:tid 977453] [client 191.232.199.39:9695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/adminfuns.php"] [unique_id "amuf2PW1Jl2-fgIeVvqteQAAAPQ"]
[Thu Jul 30 14:02:48.893714 2026] [security2:error] [pid 977210:tid 977468] [client 85.204.70.94:60314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.embassyinislamabadad.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuf2PW1Jl2-fgIeVvqtfQAAAQM"]
[Thu Jul 30 14:02:49.555241 2026] [security2:error] [pid 977210:tid 977388] [client 181.116.200.68:65138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuf2fW1Jl2-fgIeVvqtjAAAALM"]
[Thu Jul 30 14:02:49.555345 2026] [security2:error] [pid 977210:tid 977388] [client 181.116.200.68:65138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuf2fW1Jl2-fgIeVvqtjAAAALM"]
[Thu Jul 30 14:02:49.603871 2026] [security2:error] [pid 977210:tid 977408] [client 172.202.44.182:46403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/plugin.php"] [unique_id "amuf2fW1Jl2-fgIeVvqtkAAAAMc"]
[Thu Jul 30 14:02:49.624455 2026] [security2:error] [pid 977210:tid 977451] [client 82.102.18.180:37324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/wp-admin/index.php"] [unique_id "amuf2fW1Jl2-fgIeVvqthgAAAPI"]
[Thu Jul 30 14:02:49.764884 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.16.169:34891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuf2fW1Jl2-fgIeVvqtkgAAAIY"]
[Thu Jul 30 14:02:49.765000 2026] [security2:error] [pid 977210:tid 977343] [client 20.104.16.169:34891] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuf2fW1Jl2-fgIeVvqtkgAAAIY"]
[Thu Jul 30 14:02:50.071330 2026] [core:error] [pid 977210:tid 977367] [client 172.213.208.20:13845] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:50.071350 2026] [core:error] [pid 977210:tid 977367] [client 172.213.208.20:13845] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:50.072154 2026] [security2:error] [pid 977210:tid 977431] [client 103.242.199.184:64465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuf2vW1Jl2-fgIeVvqtnAAAAN4"]
[Thu Jul 30 14:02:50.072252 2026] [security2:error] [pid 977210:tid 977431] [client 103.242.199.184:64465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuf2vW1Jl2-fgIeVvqtnAAAAN4"]
[Thu Jul 30 14:02:50.158573 2026] [core:notice] [pid 977210:tid 977400] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:50.467750 2026] [security2:error] [pid 977210:tid 977432] [client 20.104.16.169:34906] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.raad.pk"] [uri "/1.php"] [unique_id "amuf2vW1Jl2-fgIeVvqtogAAAN8"]
[Thu Jul 30 14:02:50.467885 2026] [security2:error] [pid 977210:tid 977432] [client 20.104.16.169:34906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/1.php"] [unique_id "amuf2vW1Jl2-fgIeVvqtogAAAN8"]
[Thu Jul 30 14:02:50.468001 2026] [security2:error] [pid 977210:tid 977432] [client 20.104.16.169:34906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/1.php"] [unique_id "amuf2vW1Jl2-fgIeVvqtogAAAN8"]
[Thu Jul 30 14:02:50.487057 2026] [security2:error] [pid 977210:tid 977461] [client 82.102.18.180:37324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuf2vW1Jl2-fgIeVvqtowAAAPw"]
[Thu Jul 30 14:02:50.487150 2026] [security2:error] [pid 977210:tid 977461] [client 82.102.18.180:37324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuf2vW1Jl2-fgIeVvqtowAAAPw"]
[Thu Jul 30 14:02:50.735113 2026] [security2:error] [pid 977210:tid 977458] [client 172.213.208.20:37223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/admin.php"] [unique_id "amuf2vW1Jl2-fgIeVvqtsAAAAPk"]
[Thu Jul 30 14:02:51.079462 2026] [security2:error] [pid 977210:tid 977391] [client 191.232.199.39:39601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/fm.php"] [unique_id "amuf2_W1Jl2-fgIeVvqttAAAALY"]
[Thu Jul 30 14:02:51.157995 2026] [security2:error] [pid 977210:tid 977403] [client 20.104.16.169:34885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/chosen.php"] [unique_id "amuf2_W1Jl2-fgIeVvqtvAAAAMI"]
[Thu Jul 30 14:02:51.158097 2026] [security2:error] [pid 977210:tid 977403] [client 20.104.16.169:34885] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/chosen.php"] [unique_id "amuf2_W1Jl2-fgIeVvqtvAAAAMI"]
[Thu Jul 30 14:02:51.175105 2026] [security2:error] [pid 977210:tid 977346] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuf2vW1Jl2-fgIeVvqtqQAAiV0"]
[Thu Jul 30 14:02:51.419537 2026] [security2:error] [pid 977210:tid 977382] [client 172.213.208.20:33383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-configs.php"] [unique_id "amuf2_W1Jl2-fgIeVvqtvgAAAK0"]
[Thu Jul 30 14:02:51.510616 2026] [security2:error] [pid 977210:tid 977375] [client 172.202.44.182:50960] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ftp.hmhs.ph"] [uri "/1.php"] [unique_id "amuf2_W1Jl2-fgIeVvqtwAAAAKY"]
[Thu Jul 30 14:02:51.510743 2026] [security2:error] [pid 977210:tid 977375] [client 172.202.44.182:50960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/1.php"] [unique_id "amuf2_W1Jl2-fgIeVvqtwAAAAKY"]
[Thu Jul 30 14:02:51.893433 2026] [security2:error] [pid 977210:tid 977357] [client 20.104.16.169:36214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/sd.php"] [unique_id "amuf2_W1Jl2-fgIeVvqt0AAAAJQ"]
[Thu Jul 30 14:02:51.893516 2026] [security2:error] [pid 977210:tid 977357] [client 20.104.16.169:36214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/sd.php"] [unique_id "amuf2_W1Jl2-fgIeVvqt0AAAAJQ"]
[Thu Jul 30 14:02:52.368904 2026] [security2:error] [pid 977210:tid 977412] [client 172.202.44.182:46126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/gg.php"] [unique_id "amuf3PW1Jl2-fgIeVvqt3gAAAMs"]
[Thu Jul 30 14:02:52.484815 2026] [security2:error] [pid 977210:tid 977464] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/___proxy_subdomain_webmail/wp-includes/PHPMailer/"] [unique_id "amuf3PW1Jl2-fgIeVvqt4gAAAP8"]
[Thu Jul 30 14:02:52.559553 2026] [security2:error] [pid 977210:tid 977409] [client 66.249.79.2:65159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amuf2_W1Jl2-fgIeVvqtvQAAAMg"], referer: https://stunningtouchcleaning.com/
[Thu Jul 30 14:02:52.787570 2026] [security2:error] [pid 977210:tid 977401] [client 191.232.199.39:39556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/file.php"] [unique_id "amuf3PW1Jl2-fgIeVvqt7QAAAMA"]
[Thu Jul 30 14:02:52.846422 2026] [security2:error] [pid 977210:tid 977343] [client 172.213.208.20:39074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/php.php"] [unique_id "amuf3PW1Jl2-fgIeVvqt7gAAAIY"]
[Thu Jul 30 14:02:53.562807 2026] [security2:error] [pid 977210:tid 977444] [client 20.104.16.169:34827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/z60.php"] [unique_id "amuf3fW1Jl2-fgIeVvquCgAAAOs"]
[Thu Jul 30 14:02:53.562952 2026] [security2:error] [pid 977210:tid 977444] [client 20.104.16.169:34827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/z60.php"] [unique_id "amuf3fW1Jl2-fgIeVvquCgAAAOs"]
[Thu Jul 30 14:02:53.600662 2026] [security2:error] [pid 977210:tid 977417] [client 103.190.40.154:19112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf3fW1Jl2-fgIeVvquCwAAANA"]
[Thu Jul 30 14:02:53.600847 2026] [security2:error] [pid 977210:tid 977417] [client 103.190.40.154:19112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf3fW1Jl2-fgIeVvquCwAAANA"]
[Thu Jul 30 14:02:54.126034 2026] [security2:error] [pid 977210:tid 977447] [client 20.104.16.169:34911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/home.php"] [unique_id "amuf3vW1Jl2-fgIeVvquHgAAAO4"]
[Thu Jul 30 14:02:54.126143 2026] [security2:error] [pid 977210:tid 977447] [client 20.104.16.169:34911] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/home.php"] [unique_id "amuf3vW1Jl2-fgIeVvquHgAAAO4"]
[Thu Jul 30 14:02:54.290283 2026] [security2:error] [pid 977210:tid 977391] [client 172.202.44.182:13615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp.php"] [unique_id "amuf3vW1Jl2-fgIeVvquLwAAALY"]
[Thu Jul 30 14:02:54.576354 2026] [security2:error] [pid 977210:tid 977456] [client 172.213.208.20:32326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/index.php"] [unique_id "amuf3vW1Jl2-fgIeVvquNAAAAPc"]
[Thu Jul 30 14:02:54.637033 2026] [security2:error] [pid 977210:tid 977362] [client 20.104.16.169:34880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/ws58.php"] [unique_id "amuf3vW1Jl2-fgIeVvquNQAAAJk"]
[Thu Jul 30 14:02:54.637171 2026] [security2:error] [pid 977210:tid 977362] [client 20.104.16.169:34880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/ws58.php"] [unique_id "amuf3vW1Jl2-fgIeVvquNQAAAJk"]
[Thu Jul 30 14:02:54.845413 2026] [security2:error] [pid 977210:tid 977469] [client 191.232.199.39:9669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/bolt.php"] [unique_id "amuf3vW1Jl2-fgIeVvquPAAAAQQ"]
[Thu Jul 30 14:02:55.294289 2026] [core:notice] [pid 977210:tid 977437] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:02:55.301841 2026] [security2:error] [pid 977210:tid 977432] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/ws77.php"] [unique_id "amuf3_W1Jl2-fgIeVvquSwAAAN8"]
[Thu Jul 30 14:02:55.301975 2026] [security2:error] [pid 977210:tid 977432] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/ws77.php"] [unique_id "amuf3_W1Jl2-fgIeVvquSwAAAN8"]
[Thu Jul 30 14:02:55.313382 2026] [security2:error] [pid 977210:tid 977454] [client 20.104.16.169:36217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/gulu.php"] [unique_id "amuf3_W1Jl2-fgIeVvquTgAAAPU"]
[Thu Jul 30 14:02:55.313462 2026] [security2:error] [pid 977210:tid 977454] [client 20.104.16.169:36217] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/gulu.php"] [unique_id "amuf3_W1Jl2-fgIeVvquTgAAAPU"]
[Thu Jul 30 14:02:55.816060 2026] [security2:error] [pid 977210:tid 977438] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/nc4.php"] [unique_id "amuf3_W1Jl2-fgIeVvquVwAAAOU"]
[Thu Jul 30 14:02:55.816210 2026] [security2:error] [pid 977210:tid 977438] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/nc4.php"] [unique_id "amuf3_W1Jl2-fgIeVvquVwAAAOU"]
[Thu Jul 30 14:02:56.164925 2026] [security2:error] [pid 977210:tid 977450] [client 20.104.16.169:36204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuf4PW1Jl2-fgIeVvquXwAAAPE"]
[Thu Jul 30 14:02:56.165053 2026] [security2:error] [pid 977210:tid 977450] [client 20.104.16.169:36204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuf4PW1Jl2-fgIeVvquXwAAAPE"]
[Thu Jul 30 14:02:56.351315 2026] [security2:error] [pid 977210:tid 977393] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/as.php"] [unique_id "amuf4PW1Jl2-fgIeVvquaQAAALg"]
[Thu Jul 30 14:02:56.351430 2026] [security2:error] [pid 977210:tid 977393] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/as.php"] [unique_id "amuf4PW1Jl2-fgIeVvquaQAAALg"]
[Thu Jul 30 14:02:56.397028 2026] [security2:error] [pid 977210:tid 977348] [client 191.232.199.39:39570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/3.php"] [unique_id "amuf4PW1Jl2-fgIeVvqubQAAAIs"]
[Thu Jul 30 14:02:56.420584 2026] [security2:error] [pid 977210:tid 977465] [client 172.213.208.20:37204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/a.php"] [unique_id "amuf4PW1Jl2-fgIeVvqubgAAAQA"]
[Thu Jul 30 14:02:56.490665 2026] [security2:error] [pid 977210:tid 977404] [client 172.202.44.182:31854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuf4PW1Jl2-fgIeVvqubwAAAMM"]
[Thu Jul 30 14:02:56.837105 2026] [security2:error] [pid 977210:tid 977360] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/k.php"] [unique_id "amuf4PW1Jl2-fgIeVvqudAAAAJc"]
[Thu Jul 30 14:02:56.837221 2026] [security2:error] [pid 977210:tid 977360] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/k.php"] [unique_id "amuf4PW1Jl2-fgIeVvqudAAAAJc"]
[Thu Jul 30 14:02:56.843860 2026] [security2:error] [pid 977210:tid 977380] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuf4PW1Jl2-fgIeVvquZQAAAKs"]
[Thu Jul 30 14:02:57.369831 2026] [security2:error] [pid 977210:tid 977353] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/system_log.php"] [unique_id "amuf4fW1Jl2-fgIeVvqugAAAAJA"]
[Thu Jul 30 14:02:57.369950 2026] [security2:error] [pid 977210:tid 977353] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/system_log.php"] [unique_id "amuf4fW1Jl2-fgIeVvqugAAAAJA"]
[Thu Jul 30 14:02:57.491331 2026] [proxy:error] [pid 977210:tid 977462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:57.491394 2026] [proxy_http:error] [pid 977210:tid 977462] [client 52.202.41.153:61320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:57.491968 2026] [proxy:error] [pid 977210:tid 977462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:57.492049 2026] [proxy_http:error] [pid 977210:tid 977462] [client 52.202.41.153:61320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:57.552691 2026] [proxy:error] [pid 977210:tid 977426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:57.552763 2026] [proxy_http:error] [pid 977210:tid 977426] [client 3.228.112.215:14210] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:57.553494 2026] [proxy:error] [pid 977210:tid 977426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:02:57.553547 2026] [proxy_http:error] [pid 977210:tid 977426] [client 3.228.112.215:14210] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:02:57.641453 2026] [core:error] [pid 977210:tid 977368] [client 152.32.223.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:57.641476 2026] [core:error] [pid 977210:tid 977368] [client 152.32.223.215:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:57.911337 2026] [security2:error] [pid 977210:tid 977434] [client 172.202.44.182:46402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/file.php"] [unique_id "amuf4fW1Jl2-fgIeVvqumQAAAOE"]
[Thu Jul 30 14:02:57.918190 2026] [security2:error] [pid 977210:tid 977364] [client 191.232.199.39:9702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/222.php"] [unique_id "amuf4fW1Jl2-fgIeVvqumgAAAJs"]
[Thu Jul 30 14:02:58.053704 2026] [security2:error] [pid 977210:tid 977450] [client 20.104.16.169:36126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/wpls.php"] [unique_id "amuf4vW1Jl2-fgIeVvqungAAAPE"]
[Thu Jul 30 14:02:58.053807 2026] [security2:error] [pid 977210:tid 977450] [client 20.104.16.169:36126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/wpls.php"] [unique_id "amuf4vW1Jl2-fgIeVvqungAAAPE"]
[Thu Jul 30 14:02:58.316860 2026] [security2:error] [pid 977210:tid 977346] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/x.php"] [unique_id "amuf4vW1Jl2-fgIeVvquoAAAAIk"]
[Thu Jul 30 14:02:58.317023 2026] [security2:error] [pid 977210:tid 977346] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/x.php"] [unique_id "amuf4vW1Jl2-fgIeVvquoAAAAIk"]
[Thu Jul 30 14:02:58.853618 2026] [security2:error] [pid 977210:tid 977444] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/autoload_classmap.php"] [unique_id "amuf4vW1Jl2-fgIeVvqurgAAAOs"]
[Thu Jul 30 14:02:58.853736 2026] [security2:error] [pid 977210:tid 977444] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/autoload_classmap.php"] [unique_id "amuf4vW1Jl2-fgIeVvqurgAAAOs"]
[Thu Jul 30 14:02:59.246022 2026] [security2:error] [pid 977210:tid 977367] [client 172.202.44.182:13569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/user/index.php"] [unique_id "amuf4_W1Jl2-fgIeVvquvQAAAJ4"]
[Thu Jul 30 14:02:59.334609 2026] [security2:error] [pid 977210:tid 977398] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/test1.php"] [unique_id "amuf4_W1Jl2-fgIeVvquvgAAAL0"]
[Thu Jul 30 14:02:59.334716 2026] [security2:error] [pid 977210:tid 977398] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/test1.php"] [unique_id "amuf4_W1Jl2-fgIeVvquvgAAAL0"]
[Thu Jul 30 14:02:59.421896 2026] [security2:error] [pid 977210:tid 977344] [client 191.232.199.39:9683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuf4_W1Jl2-fgIeVvquvwAAAIc"]
[Thu Jul 30 14:02:59.581971 2026] [core:error] [pid 977210:tid 977458] [client 172.213.208.20:34781] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:59.582003 2026] [core:error] [pid 977210:tid 977458] [client 172.213.208.20:34781] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:02:59.757836 2026] [security2:error] [pid 977210:tid 977428] [client 20.104.16.169:36121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/php.php"] [unique_id "amuf4_W1Jl2-fgIeVvquzAAAANs"]
[Thu Jul 30 14:02:59.757996 2026] [security2:error] [pid 977210:tid 977428] [client 20.104.16.169:36121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/php.php"] [unique_id "amuf4_W1Jl2-fgIeVvquzAAAANs"]
[Thu Jul 30 14:02:59.850193 2026] [security2:error] [pid 977210:tid 977409] [client 158.158.41.78:22222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/themes/admin.php"] [unique_id "amuf4_W1Jl2-fgIeVvquzQAAAMg"]
[Thu Jul 30 14:02:59.890639 2026] [security2:error] [pid 977210:tid 977375] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/___proxy_subdomain_webmail/mini"] [unique_id "amuf4_W1Jl2-fgIeVvquzgAAAKY"]
[Thu Jul 30 14:03:00.131187 2026] [security2:error] [pid 977210:tid 977430] [client 181.116.200.68:51427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu2QAAAN0"]
[Thu Jul 30 14:03:00.131299 2026] [security2:error] [pid 977210:tid 977430] [client 181.116.200.68:51427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu2QAAAN0"]
[Thu Jul 30 14:03:00.180172 2026] [security2:error] [pid 977210:tid 977361] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-signin.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu2gAAAJg"]
[Thu Jul 30 14:03:00.180284 2026] [security2:error] [pid 977210:tid 977361] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-signin.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu2gAAAJg"]
[Thu Jul 30 14:03:00.206076 2026] [core:error] [pid 977210:tid 977402] [client 172.213.208.20:40265] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:03:00.206098 2026] [core:error] [pid 977210:tid 977402] [client 172.213.208.20:40265] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:03:00.452683 2026] [security2:error] [pid 977210:tid 977274] [remote 95.203.26.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.26.203.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "heiakujawir.com"] [uri "/xmlrpc.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu2wAAmj0"]
[Thu Jul 30 14:03:00.452941 2026] [security2:error] [pid 977210:tid 977363] [client 95.203.26.57:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "heiakujawir.com"] [uri "/xmlrpc.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu2wAAmj0"]
[Thu Jul 30 14:03:00.578581 2026] [security2:error] [pid 977210:tid 977406] [client 20.104.16.169:34888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/100.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu4wAAAMU"]
[Thu Jul 30 14:03:00.578686 2026] [security2:error] [pid 977210:tid 977406] [client 20.104.16.169:34888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/100.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu4wAAAMU"]
[Thu Jul 30 14:03:00.705385 2026] [security2:error] [pid 977210:tid 977452] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/gg.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu5wAAAPM"]
[Thu Jul 30 14:03:00.705523 2026] [security2:error] [pid 977210:tid 977452] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/gg.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu5wAAAPM"]
[Thu Jul 30 14:03:00.794239 2026] [security2:error] [pid 977210:tid 977467] [client 172.213.208.20:14535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu6AAAAQI"]
[Thu Jul 30 14:03:00.806415 2026] [security2:error] [pid 977210:tid 977372] [client 103.242.199.184:65026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu6QAAAKM"]
[Thu Jul 30 14:03:00.806498 2026] [security2:error] [pid 977210:tid 977372] [client 103.242.199.184:65026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu6QAAAKM"]
[Thu Jul 30 14:03:00.810162 2026] [security2:error] [pid 977210:tid 977360] [client 191.232.199.39:41090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuf5PW1Jl2-fgIeVvqu6gAAAJc"]
[Thu Jul 30 14:03:01.161368 2026] [security2:error] [pid 977210:tid 977301] [remote 74.7.243.224:45950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/uploads/content/login.php"] [unique_id "amuf5fW1Jl2-fgIeVvqvBAAA6lg"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/uploads/content/1781252056_BAGIRA.jpg
[Thu Jul 30 14:03:01.217854 2026] [security2:error] [pid 977210:tid 977419] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/class.php"] [unique_id "amuf5fW1Jl2-fgIeVvqvBwAAANI"]
[Thu Jul 30 14:03:01.218006 2026] [security2:error] [pid 977210:tid 977419] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/class.php"] [unique_id "amuf5fW1Jl2-fgIeVvqvBwAAANI"]
[Thu Jul 30 14:03:01.305217 2026] [core:notice] [pid 977210:tid 977257] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:01.317076 2026] [core:notice] [pid 977210:tid 977300] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:01.338036 2026] [core:notice] [pid 977210:tid 977266] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:01.338068 2026] [core:notice] [pid 977210:tid 977227] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:01.377798 2026] [core:notice] [pid 977210:tid 977276] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:01.497434 2026] [security2:error] [pid 977210:tid 977456] [client 195.63.21.48:26458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuf5fW1Jl2-fgIeVvqvDgAA9yY"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 14:03:01.723920 2026] [security2:error] [pid 977210:tid 977394] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/404.php"] [unique_id "amuf5fW1Jl2-fgIeVvqvGgAAALk"]
[Thu Jul 30 14:03:01.724028 2026] [security2:error] [pid 977210:tid 977394] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/404.php"] [unique_id "amuf5fW1Jl2-fgIeVvqvGgAAALk"]
[Thu Jul 30 14:03:01.753411 2026] [security2:error] [pid 977210:tid 977369] [client 20.104.16.169:36123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/BDKR28WP.php"] [unique_id "amuf5fW1Jl2-fgIeVvqvHAAAAKA"]
[Thu Jul 30 14:03:01.753502 2026] [security2:error] [pid 977210:tid 977369] [client 20.104.16.169:36123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/BDKR28WP.php"] [unique_id "amuf5fW1Jl2-fgIeVvqvHAAAAKA"]
[Thu Jul 30 14:03:01.886395 2026] [core:notice] [pid 977210:tid 977243] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:01.997904 2026] [core:notice] [pid 977210:tid 977246] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:02.022487 2026] [security2:error] [pid 977210:tid 977309] [remote 57.141.0.70:20180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuf5vW1Jl2-fgIeVvqvJAAA62A"]
[Thu Jul 30 14:03:02.064482 2026] [core:notice] [pid 977210:tid 977262] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:02.248574 2026] [security2:error] [pid 977210:tid 977376] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/lite.php"] [unique_id "amuf5vW1Jl2-fgIeVvqvLwAAAKc"]
[Thu Jul 30 14:03:02.248675 2026] [security2:error] [pid 977210:tid 977376] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/lite.php"] [unique_id "amuf5vW1Jl2-fgIeVvqvLwAAAKc"]
[Thu Jul 30 14:03:02.526727 2026] [security2:error] [pid 977210:tid 977364] [client 191.232.199.39:9679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/admin.php"] [unique_id "amuf5vW1Jl2-fgIeVvqvNAAAAJs"]
[Thu Jul 30 14:03:02.703216 2026] [proxy:error] [pid 977210:tid 977384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:02.703306 2026] [proxy_http:error] [pid 977210:tid 977384] [client 98.87.102.177:24546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:02.703907 2026] [proxy:error] [pid 977210:tid 977384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:02.703959 2026] [proxy_http:error] [pid 977210:tid 977384] [client 98.87.102.177:24546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:02.722877 2026] [proxy:error] [pid 977210:tid 977358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:02.722959 2026] [proxy_http:error] [pid 977210:tid 977358] [client 18.211.55.47:25550] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:02.723837 2026] [proxy:error] [pid 977210:tid 977358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:02.723896 2026] [proxy_http:error] [pid 977210:tid 977358] [client 18.211.55.47:25550] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:02.774585 2026] [security2:error] [pid 977210:tid 977351] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/lock360.php"] [unique_id "amuf5vW1Jl2-fgIeVvqvQwAAAI4"]
[Thu Jul 30 14:03:02.774706 2026] [security2:error] [pid 977210:tid 977351] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/lock360.php"] [unique_id "amuf5vW1Jl2-fgIeVvqvQwAAAI4"]
[Thu Jul 30 14:03:02.789422 2026] [security2:error] [pid 977210:tid 977439] [client 172.213.208.20:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin.php"] [unique_id "amuf5vW1Jl2-fgIeVvqvRAAAAOY"]
[Thu Jul 30 14:03:03.113901 2026] [security2:error] [pid 977210:tid 977402] [client 20.104.16.169:36181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/browse.php"] [unique_id "amuf5_W1Jl2-fgIeVvqvUgAAAME"]
[Thu Jul 30 14:03:03.114015 2026] [security2:error] [pid 977210:tid 977402] [client 20.104.16.169:36181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/browse.php"] [unique_id "amuf5_W1Jl2-fgIeVvqvUgAAAME"]
[Thu Jul 30 14:03:03.281946 2026] [security2:error] [pid 977210:tid 977349] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuf5_W1Jl2-fgIeVvqvWAAAAIw"]
[Thu Jul 30 14:03:03.282051 2026] [security2:error] [pid 977210:tid 977349] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuf5_W1Jl2-fgIeVvqvWAAAAIw"]
[Thu Jul 30 14:03:03.802315 2026] [security2:error] [pid 977210:tid 977459] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-links-opml.php"] [unique_id "amuf5_W1Jl2-fgIeVvqvcQAAAPo"]
[Thu Jul 30 14:03:03.802418 2026] [security2:error] [pid 977210:tid 977459] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-links-opml.php"] [unique_id "amuf5_W1Jl2-fgIeVvqvcQAAAPo"]
[Thu Jul 30 14:03:03.839187 2026] [security2:error] [pid 977210:tid 977467] [client 146.103.116.11:48493] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.116.11" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuf5_W1Jl2-fgIeVvqvcgAAAQI"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 14:03:03.857597 2026] [security2:error] [pid 977210:tid 977385] [client 158.158.41.78:45052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/m.php"] [unique_id "amuf5_W1Jl2-fgIeVvqvdgAAALA"]
[Thu Jul 30 14:03:04.265411 2026] [security2:error] [pid 977210:tid 977387] [client 204.12.208.18:65065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuf6PW1Jl2-fgIeVvqveQAAALI"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 14:03:04.312418 2026] [security2:error] [pid 977210:tid 977348] [client 20.104.22.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/uploads/min.php"] [unique_id "amuf6PW1Jl2-fgIeVvqvgwAAAIs"]
[Thu Jul 30 14:03:04.312523 2026] [security2:error] [pid 977210:tid 977348] [client 20.104.22.47:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.embassyofgermanypakistanllc.de"] [uri "/wp-content/uploads/min.php"] [unique_id "amuf6PW1Jl2-fgIeVvqvgwAAAIs"]
[Thu Jul 30 14:03:04.463068 2026] [core:notice] [pid 977210:tid 977352] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:04.483843 2026] [security2:error] [pid 977210:tid 977429] [client 103.190.40.154:20178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf6PW1Jl2-fgIeVvqvhgAAANw"]
[Thu Jul 30 14:03:04.483969 2026] [security2:error] [pid 977210:tid 977429] [client 103.190.40.154:20178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf6PW1Jl2-fgIeVvqvhgAAANw"]
[Thu Jul 30 14:03:04.640818 2026] [core:error] [pid 977210:tid 977399] [client 95.108.213.186:38566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:03:04.640841 2026] [core:error] [pid 977210:tid 977399] [client 95.108.213.186:38566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:03:04.663754 2026] [core:notice] [pid 977210:tid 977420] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:04.683575 2026] [security2:error] [pid 977210:tid 977381] [client 66.132.224.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "kayomanis.com"] [uri "/index.php"] [unique_id "amuf6PW1Jl2-fgIeVvqviQAAAKw"]
[Thu Jul 30 14:03:04.875664 2026] [security2:error] [pid 977210:tid 977421] [client 204.12.208.18:65076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuf6PW1Jl2-fgIeVvqvlwAAANQ"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 14:03:04.887442 2026] [security2:error] [pid 977210:tid 977406] [client 172.213.208.20:13829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/size.php"] [unique_id "amuf6PW1Jl2-fgIeVvqvmAAAAMU"]
[Thu Jul 30 14:03:04.984892 2026] [security2:error] [pid 977210:tid 977435] [client 191.232.199.39:9882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-configs.php"] [unique_id "amuf6PW1Jl2-fgIeVvqvmgAAAOI"]
[Thu Jul 30 14:03:05.082717 2026] [security2:error] [pid 977210:tid 977437] [client 20.104.16.169:36177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.raad.pk"] [uri "/wp-good.php"] [unique_id "amuf6fW1Jl2-fgIeVvqvmwAAAOQ"]
[Thu Jul 30 14:03:05.082850 2026] [security2:error] [pid 977210:tid 977437] [client 20.104.16.169:36177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.raad.pk"] [uri "/wp-good.php"] [unique_id "amuf6fW1Jl2-fgIeVvqvmwAAAOQ"]
[Thu Jul 30 14:03:05.453041 2026] [security2:error] [pid 977210:tid 977344] [client 189.6.88.213:62166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf6fW1Jl2-fgIeVvqvqAAAAIc"]
[Thu Jul 30 14:03:05.453150 2026] [security2:error] [pid 977210:tid 977344] [client 189.6.88.213:62166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf6fW1Jl2-fgIeVvqvqAAAAIc"]
[Thu Jul 30 14:03:05.487761 2026] [security2:error] [pid 977210:tid 977434] [client 204.12.208.18:65084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuf6fW1Jl2-fgIeVvqvqQAAAOE"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 14:03:05.599489 2026] [security2:error] [pid 977210:tid 977386] [client 158.158.41.78:50118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuf6fW1Jl2-fgIeVvqvpgAAALE"]
[Thu Jul 30 14:03:06.101968 2026] [security2:error] [pid 977210:tid 977224] [remote 47.128.111.58:62460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.igetvapesonline.com"] [uri "/product/gunnpod-banana-papaya-2000-puffs/"] [unique_id "amuf6vW1Jl2-fgIeVvqvugAAqws"]
[Thu Jul 30 14:03:06.362404 2026] [security2:error] [pid 977210:tid 977373] [client 172.202.44.182:18523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuf6vW1Jl2-fgIeVvqvwgAAAKQ"]
[Thu Jul 30 14:03:06.401281 2026] [security2:error] [pid 977210:tid 977442] [client 158.158.41.78:12217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wk/index.php"] [unique_id "amuf6vW1Jl2-fgIeVvqvxAAAAOk"]
[Thu Jul 30 14:03:06.624350 2026] [security2:error] [pid 977210:tid 977352] [client 172.213.208.20:32378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuf6vW1Jl2-fgIeVvqvyAAAAI8"]
[Thu Jul 30 14:03:06.946843 2026] [security2:error] [pid 977210:tid 977382] [client 191.232.199.39:9917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/php.php"] [unique_id "amuf6vW1Jl2-fgIeVvqv0gAAAK0"]
[Thu Jul 30 14:03:07.458782 2026] [security2:error] [pid 977210:tid 977365] [client 158.158.41.78:27622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/mini.php"] [unique_id "amuf6_W1Jl2-fgIeVvqv3AAAAJw"]
[Thu Jul 30 14:03:07.606195 2026] [security2:error] [pid 977210:tid 977434] [client 172.213.208.20:29320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/403.php"] [unique_id "amuf6_W1Jl2-fgIeVvqv3QAAAOE"]
[Thu Jul 30 14:03:08.470759 2026] [security2:error] [pid 977210:tid 977449] [client 172.213.208.20:45276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuf7PW1Jl2-fgIeVvqv8AAAAPA"]
[Thu Jul 30 14:03:08.494080 2026] [security2:error] [pid 977210:tid 977426] [client 172.202.44.182:13617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/index/function.php"] [unique_id "amuf7PW1Jl2-fgIeVvqv8QAAANk"]
[Thu Jul 30 14:03:09.248228 2026] [security2:error] [pid 977210:tid 977430] [client 191.232.199.39:9894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/index.php"] [unique_id "amuf7fW1Jl2-fgIeVvqv_wAAAN0"]
[Thu Jul 30 14:03:09.307570 2026] [security2:error] [pid 977210:tid 977398] [client 172.213.208.20:13730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/as.php"] [unique_id "amuf7fW1Jl2-fgIeVvqwAQAAAL0"]
[Thu Jul 30 14:03:09.650352 2026] [proxy:error] [pid 977210:tid 977450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:09.650425 2026] [proxy_http:error] [pid 977210:tid 977450] [client 3.225.222.228:63824] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:09.651004 2026] [proxy:error] [pid 977210:tid 977450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:09.651053 2026] [proxy_http:error] [pid 977210:tid 977450] [client 3.225.222.228:63824] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:09.704937 2026] [proxy:error] [pid 977210:tid 977364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:09.705024 2026] [proxy_http:error] [pid 977210:tid 977364] [client 44.213.206.96:49267] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:09.705587 2026] [proxy:error] [pid 977210:tid 977364] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:09.705629 2026] [proxy_http:error] [pid 977210:tid 977364] [client 44.213.206.96:49267] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:10.415404 2026] [core:notice] [pid 977210:tid 977360] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:10.519720 2026] [security2:error] [pid 977210:tid 977373] [client 172.202.44.182:31861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/aaa.php"] [unique_id "amuf7vW1Jl2-fgIeVvqwJwAAAKQ"]
[Thu Jul 30 14:03:10.723087 2026] [security2:error] [pid 977210:tid 977423] [client 191.232.199.39:9778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/a.php"] [unique_id "amuf7vW1Jl2-fgIeVvqwLQAAANY"]
[Thu Jul 30 14:03:10.730925 2026] [security2:error] [pid 977210:tid 977469] [client 181.116.200.68:16912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuf7vW1Jl2-fgIeVvqwLgAAAQQ"]
[Thu Jul 30 14:03:10.731040 2026] [security2:error] [pid 977210:tid 977469] [client 181.116.200.68:16912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuf7vW1Jl2-fgIeVvqwLgAAAQQ"]
[Thu Jul 30 14:03:10.809078 2026] [security2:error] [pid 977210:tid 977326] [remote 47.128.28.108:29020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/gg-jacket-black-beige/"] [unique_id "amuf7vW1Jl2-fgIeVvqwLwAA4nE"]
[Thu Jul 30 14:03:10.838622 2026] [security2:error] [pid 977210:tid 977346] [client 85.208.96.210:38748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/04/coreia-do-norte-dispara-missil-e-deixa-japao-em-alerta/"] [unique_id "amuf7vW1Jl2-fgIeVvqwMQAAAIk"]
[Thu Jul 30 14:03:10.838767 2026] [security2:error] [pid 977210:tid 977346] [client 85.208.96.210:38748] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/04/coreia-do-norte-dispara-missil-e-deixa-japao-em-alerta/"] [unique_id "amuf7vW1Jl2-fgIeVvqwMQAAAIk"]
[Thu Jul 30 14:03:11.316381 2026] [proxy:error] [pid 977210:tid 977463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:11.316479 2026] [proxy_http:error] [pid 977210:tid 977463] [client 18.211.55.47:7678] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:11.317330 2026] [proxy:error] [pid 977210:tid 977463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:11.317388 2026] [proxy_http:error] [pid 977210:tid 977463] [client 18.211.55.47:7678] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:11.366457 2026] [security2:error] [pid 977210:tid 977436] [client 172.202.44.182:18548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/getid3-core.php"] [unique_id "amuf7_W1Jl2-fgIeVvqwPgAAAOM"]
[Thu Jul 30 14:03:11.496167 2026] [security2:error] [pid 977210:tid 977363] [client 103.242.199.184:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuf7_W1Jl2-fgIeVvqwQgAAAJo"]
[Thu Jul 30 14:03:11.496285 2026] [security2:error] [pid 977210:tid 977363] [client 103.242.199.184:49200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuf7_W1Jl2-fgIeVvqwQgAAAJo"]
[Thu Jul 30 14:03:11.530863 2026] [security2:error] [pid 977210:tid 977418] [client 158.158.41.78:28295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/aa.php"] [unique_id "amuf7_W1Jl2-fgIeVvqwQwAAANE"]
[Thu Jul 30 14:03:12.700510 2026] [security2:error] [pid 977210:tid 977392] [client 184.75.223.227:48718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuf8PW1Jl2-fgIeVvqwXgAAALc"]
[Thu Jul 30 14:03:12.700602 2026] [security2:error] [pid 977210:tid 977392] [client 184.75.223.227:48718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuf8PW1Jl2-fgIeVvqwXgAAALc"]
[Thu Jul 30 14:03:12.806855 2026] [security2:error] [pid 977210:tid 977347] [client 191.232.199.39:10178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuf8PW1Jl2-fgIeVvqwXwAAAIo"]
[Thu Jul 30 14:03:13.380002 2026] [security2:error] [pid 977210:tid 977451] [client 172.202.44.182:50946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/adminer.php"] [unique_id "amuf8fW1Jl2-fgIeVvqwagAAAPI"]
[Thu Jul 30 14:03:14.947427 2026] [security2:error] [pid 977210:tid 977382] [client 191.232.199.39:9728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin.php"] [unique_id "amuf8vW1Jl2-fgIeVvqwjwAAAK0"]
[Thu Jul 30 14:03:14.991320 2026] [proxy:error] [pid 977210:tid 977410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:14.991393 2026] [proxy_http:error] [pid 977210:tid 977410] [client 100.58.180.145:37430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:14.991993 2026] [proxy:error] [pid 977210:tid 977410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:14.992039 2026] [proxy_http:error] [pid 977210:tid 977410] [client 100.58.180.145:37430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:15.052450 2026] [security2:error] [pid 977210:tid 977426] [client 172.202.44.182:18553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/alfa.php"] [unique_id "amuf8_W1Jl2-fgIeVvqwkQAAANk"]
[Thu Jul 30 14:03:15.373779 2026] [security2:error] [pid 977210:tid 977392] [client 103.190.40.154:19103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf8_W1Jl2-fgIeVvqwnQAAALc"]
[Thu Jul 30 14:03:15.373922 2026] [security2:error] [pid 977210:tid 977392] [client 103.190.40.154:19103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf8_W1Jl2-fgIeVvqwnQAAALc"]
[Thu Jul 30 14:03:16.142938 2026] [security2:error] [pid 977210:tid 977459] [client 189.6.88.213:62718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf9PW1Jl2-fgIeVvqwqAAAAPo"]
[Thu Jul 30 14:03:16.143105 2026] [security2:error] [pid 977210:tid 977459] [client 189.6.88.213:62718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf9PW1Jl2-fgIeVvqwqAAAAPo"]
[Thu Jul 30 14:03:16.164964 2026] [security2:error] [pid 977210:tid 977342] [client 74.7.228.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.baitultateeqmoverscompany.com"] [uri "/index.php"] [unique_id "amuf8_W1Jl2-fgIeVvqwmwAAhSw"]
[Thu Jul 30 14:03:16.165009 2026] [security2:error] [pid 977210:tid 977342] [client 74.7.228.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.baitultateeqmoverscompany.com"] [uri "/index.php"] [unique_id "amuf8_W1Jl2-fgIeVvqwmwAAhSw"]
[Thu Jul 30 14:03:16.460958 2026] [security2:error] [pid 977210:tid 977455] [client 103.231.91.59:34878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuf9PW1Jl2-fgIeVvqwtAAAAPY"]
[Thu Jul 30 14:03:16.461073 2026] [security2:error] [pid 977210:tid 977455] [client 103.231.91.59:34878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuf9PW1Jl2-fgIeVvqwtAAAAPY"]
[Thu Jul 30 14:03:16.736607 2026] [proxy:error] [pid 977210:tid 977419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:16.736684 2026] [proxy_http:error] [pid 977210:tid 977419] [client 34.224.175.62:22820] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:16.737617 2026] [proxy:error] [pid 977210:tid 977419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:16.737675 2026] [proxy_http:error] [pid 977210:tid 977419] [client 34.224.175.62:22820] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:16.771820 2026] [proxy:error] [pid 977210:tid 977401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:16.771905 2026] [proxy_http:error] [pid 977210:tid 977401] [client 34.224.175.62:64010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:16.772631 2026] [proxy:error] [pid 977210:tid 977401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:16.772682 2026] [proxy_http:error] [pid 977210:tid 977401] [client 34.224.175.62:64010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:16.951574 2026] [security2:error] [pid 977210:tid 977443] [client 191.232.199.39:9779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/size.php"] [unique_id "amuf9PW1Jl2-fgIeVvqw0QAAAOo"]
[Thu Jul 30 14:03:17.132501 2026] [security2:error] [pid 977210:tid 977449] [client 74.7.228.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "baitultateeqmoverscompany.com"] [uri "/index.php"] [unique_id "amuf9fW1Jl2-fgIeVvqw0wAA8CE"], referer: https://www.baitultateeqmoverscompany.com/robots.txt
[Thu Jul 30 14:03:17.378779 2026] [security2:error] [pid 977210:tid 977364] [client 115.45.40.3:58273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuf9fW1Jl2-fgIeVvqw0gAAAJs"]
[Thu Jul 30 14:03:17.596877 2026] [security2:error] [pid 977210:tid 977361] [client 172.213.208.20:45293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuf9fW1Jl2-fgIeVvqw3wAAAJg"]
[Thu Jul 30 14:03:17.639575 2026] [security2:error] [pid 977210:tid 977440] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuf9PW1Jl2-fgIeVvqw0AAA500"]
[Thu Jul 30 14:03:18.124887 2026] [security2:error] [pid 977210:tid 977445] [client 172.213.208.20:50909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuf9vW1Jl2-fgIeVvqw7QAAAOw"]
[Thu Jul 30 14:03:18.686315 2026] [security2:error] [pid 977210:tid 977425] [client 191.232.199.39:9782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuf9vW1Jl2-fgIeVvqw-gAAANg"]
[Thu Jul 30 14:03:18.810229 2026] [security2:error] [pid 977210:tid 977428] [client 172.213.208.20:29349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/plugins.php"] [unique_id "amuf9vW1Jl2-fgIeVvqxAwAAANs"]
[Thu Jul 30 14:03:19.523364 2026] [security2:error] [pid 977210:tid 977364] [client 172.202.44.182:46430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuf9_W1Jl2-fgIeVvqxKQAAAJs"]
[Thu Jul 30 14:03:20.199069 2026] [security2:error] [pid 977210:tid 977383] [client 191.232.199.39:9678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/403.php"] [unique_id "amuf-PW1Jl2-fgIeVvqxPQAAAK4"]
[Thu Jul 30 14:03:20.309720 2026] [security2:error] [pid 977210:tid 977413] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuf9_W1Jl2-fgIeVvqxLgAAAMw"]
[Thu Jul 30 14:03:20.533539 2026] [security2:error] [pid 977210:tid 977220] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amuf-PW1Jl2-fgIeVvqxRgAAyAc"]
[Thu Jul 30 14:03:20.533749 2026] [security2:error] [pid 977210:tid 977409] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amuf-PW1Jl2-fgIeVvqxRgAAyAc"]
[Thu Jul 30 14:03:20.687770 2026] [security2:error] [pid 977210:tid 977435] [client 158.158.41.78:12216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/w.php"] [unique_id "amuf-PW1Jl2-fgIeVvqxSwAAAOI"]
[Thu Jul 30 14:03:20.688003 2026] [security2:error] [pid 977210:tid 977363] [client 172.202.44.182:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuf-PW1Jl2-fgIeVvqxTAAAAJo"]
[Thu Jul 30 14:03:20.935829 2026] [core:notice] [pid 977210:tid 977427] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:21.401022 2026] [security2:error] [pid 977210:tid 977453] [client 181.116.200.68:48467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuf-fW1Jl2-fgIeVvqxZgAAAPQ"]
[Thu Jul 30 14:03:21.401170 2026] [security2:error] [pid 977210:tid 977453] [client 181.116.200.68:48467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuf-fW1Jl2-fgIeVvqxZgAAAPQ"]
[Thu Jul 30 14:03:21.413608 2026] [security2:error] [pid 977210:tid 977460] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuf-fW1Jl2-fgIeVvqxXQAAAPs"]
[Thu Jul 30 14:03:21.413633 2026] [security2:error] [pid 977210:tid 977460] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuf-fW1Jl2-fgIeVvqxXQAAAPs"]
[Thu Jul 30 14:03:21.413955 2026] [security2:error] [pid 977210:tid 977414] [client 82.102.18.180:59808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/images/"] [unique_id "amuf-fW1Jl2-fgIeVvqxWwAAAM0"]
[Thu Jul 30 14:03:21.495540 2026] [security2:error] [pid 977210:tid 977359] [client 191.232.199.39:10187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuf-fW1Jl2-fgIeVvqxagAAAJY"]
[Thu Jul 30 14:03:22.015736 2026] [security2:error] [pid 977210:tid 977347] [client 172.213.208.20:29556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuf-vW1Jl2-fgIeVvqxdwAAAIo"]
[Thu Jul 30 14:03:22.137400 2026] [security2:error] [pid 977210:tid 977450] [client 103.242.199.184:49769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuf-vW1Jl2-fgIeVvqxgwAAAPE"]
[Thu Jul 30 14:03:22.137563 2026] [security2:error] [pid 977210:tid 977450] [client 103.242.199.184:49769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuf-vW1Jl2-fgIeVvqxgwAAAPE"]
[Thu Jul 30 14:03:22.361493 2026] [security2:error] [pid 977210:tid 977398] [client 158.158.41.78:32630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/admin.php"] [unique_id "amuf-vW1Jl2-fgIeVvqxiwAAAL0"]
[Thu Jul 30 14:03:22.556104 2026] [security2:error] [pid 977210:tid 977454] [client 172.202.44.182:50987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuf-vW1Jl2-fgIeVvqxkAAAAPU"]
[Thu Jul 30 14:03:23.256045 2026] [security2:error] [pid 977210:tid 977389] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuf-vW1Jl2-fgIeVvqxjAAAtCo"]
[Thu Jul 30 14:03:23.765952 2026] [security2:error] [pid 977210:tid 977435] [client 191.232.199.39:10181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/as.php"] [unique_id "amuf-_W1Jl2-fgIeVvqxuAAAAOI"]
[Thu Jul 30 14:03:23.993960 2026] [security2:error] [pid 977210:tid 977357] [client 172.202.44.182:46414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/edit.php"] [unique_id "amuf-_W1Jl2-fgIeVvqxugAAAJQ"]
[Thu Jul 30 14:03:25.272482 2026] [security2:error] [pid 977210:tid 977414] [client 158.158.41.78:12201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/404.php"] [unique_id "amuf_fW1Jl2-fgIeVvqx4AAAAM0"]
[Thu Jul 30 14:03:25.393487 2026] [security2:error] [pid 977210:tid 977358] [client 172.202.44.182:50994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/sf.php"] [unique_id "amuf_fW1Jl2-fgIeVvqx5gAAAJU"]
[Thu Jul 30 14:03:25.563572 2026] [security2:error] [pid 977210:tid 977458] [client 8.211.147.69:63014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "siatfc.com"] [uri "/"] [unique_id "amuf_fW1Jl2-fgIeVvqx6AAAAPk"]
[Thu Jul 30 14:03:25.644369 2026] [security2:error] [pid 977210:tid 977346] [client 191.232.199.39:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuf_fW1Jl2-fgIeVvqx6wAAAIk"]
[Thu Jul 30 14:03:25.981226 2026] [security2:error] [pid 977210:tid 977445] [client 8.211.147.69:63021] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "siatfc.com"] [uri "/wp-json/batch/v1"] [unique_id "amuf_fW1Jl2-fgIeVvqx9QAAAOw"]
[Thu Jul 30 14:03:26.092100 2026] [security2:error] [pid 977210:tid 977393] [client 158.158.41.78:50827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/init.php"] [unique_id "amuf_vW1Jl2-fgIeVvqx9gAAALg"]
[Thu Jul 30 14:03:26.262671 2026] [security2:error] [pid 977210:tid 977419] [client 103.190.40.154:20199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf_vW1Jl2-fgIeVvqx-gAAANI"]
[Thu Jul 30 14:03:26.262794 2026] [security2:error] [pid 977210:tid 977419] [client 103.190.40.154:20199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf_vW1Jl2-fgIeVvqx-gAAANI"]
[Thu Jul 30 14:03:26.540548 2026] [security2:error] [pid 977210:tid 977355] [client 172.202.44.182:31827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wso.php"] [unique_id "amuf_vW1Jl2-fgIeVvqyAwAAAJI"]
[Thu Jul 30 14:03:26.888535 2026] [security2:error] [pid 977210:tid 977396] [client 189.6.88.213:63268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf_vW1Jl2-fgIeVvqyDAAAALs"]
[Thu Jul 30 14:03:26.888670 2026] [security2:error] [pid 977210:tid 977396] [client 189.6.88.213:63268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuf_vW1Jl2-fgIeVvqyDAAAALs"]
[Thu Jul 30 14:03:27.351550 2026] [security2:error] [pid 977210:tid 977369] [client 172.213.208.20:56002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/go.php"] [unique_id "amuf__W1Jl2-fgIeVvqyEwAAAKA"]
[Thu Jul 30 14:03:27.789924 2026] [security2:error] [pid 977210:tid 977447] [client 172.202.44.182:46440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/ioxi-o.php"] [unique_id "amuf__W1Jl2-fgIeVvqyHQAAAO4"]
[Thu Jul 30 14:03:28.523898 2026] [security2:error] [pid 977210:tid 977378] [client 158.158.41.78:27633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/adminfuns.php"] [unique_id "amugAPW1Jl2-fgIeVvqyOgAAAKk"]
[Thu Jul 30 14:03:29.374496 2026] [security2:error] [pid 977210:tid 977432] [client 172.213.208.20:35610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/aaa.php"] [unique_id "amugAfW1Jl2-fgIeVvqyRgAAAN8"]
[Thu Jul 30 14:03:29.457805 2026] [security2:error] [pid 977210:tid 977361] [client 158.158.41.78:32594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/file.php"] [unique_id "amugAfW1Jl2-fgIeVvqySgAAAJg"]
[Thu Jul 30 14:03:30.163164 2026] [security2:error] [pid 977210:tid 977455] [client 172.213.208.20:14202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/getid3-core.php"] [unique_id "amugAvW1Jl2-fgIeVvqyWwAAAPY"]
[Thu Jul 30 14:03:30.825411 2026] [security2:error] [pid 977210:tid 977347] [client 191.232.199.39:9245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amugAvW1Jl2-fgIeVvqyaAAAAIo"]
[Thu Jul 30 14:03:30.929464 2026] [security2:error] [pid 977210:tid 977411] [client 172.213.208.20:35615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/adminer.php"] [unique_id "amugAvW1Jl2-fgIeVvqyagAAAMo"]
[Thu Jul 30 14:03:31.599802 2026] [security2:error] [pid 977210:tid 977396] [client 158.158.41.78:50171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/222.php"] [unique_id "amugA_W1Jl2-fgIeVvqygwAAALs"]
[Thu Jul 30 14:03:31.687794 2026] [core:notice] [pid 977210:tid 977459] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:31.728106 2026] [security2:error] [pid 977210:tid 977380] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ltr.tqa.temporary.site"] [uri "/index.php"] [unique_id "amugAvW1Jl2-fgIeVvqyXgAAAKs"]
[Thu Jul 30 14:03:31.728876 2026] [security2:error] [pid 977210:tid 977429] [client 74.7.230.1:33720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ltr.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amugAvW1Jl2-fgIeVvqyXAAA3BE"]
[Thu Jul 30 14:03:31.973158 2026] [security2:error] [pid 977210:tid 977361] [client 181.116.200.68:24177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugA_W1Jl2-fgIeVvqyigAAAJg"]
[Thu Jul 30 14:03:31.973279 2026] [security2:error] [pid 977210:tid 977361] [client 181.116.200.68:24177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugA_W1Jl2-fgIeVvqyigAAAJg"]
[Thu Jul 30 14:03:32.090221 2026] [security2:error] [pid 977210:tid 977342] [client 191.232.199.39:9255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/plugins.php"] [unique_id "amugBPW1Jl2-fgIeVvqyjAAAAIU"]
[Thu Jul 30 14:03:32.319379 2026] [security2:error] [pid 977210:tid 977378] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugA_W1Jl2-fgIeVvqyhQAAqRk"]
[Thu Jul 30 14:03:32.542891 2026] [security2:error] [pid 977210:tid 977416] [client 74.7.230.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "daralnaseemdxb.com"] [uri "/index.php"] [unique_id "amugBPW1Jl2-fgIeVvqylQAAAM8"]
[Thu Jul 30 14:03:32.543833 2026] [security2:error] [pid 977210:tid 977402] [client 74.7.230.20:50584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "daralnaseemdxb.com"] [uri "/robots.txt"] [unique_id "amugBPW1Jl2-fgIeVvqykwAAwVU"]
[Thu Jul 30 14:03:32.787621 2026] [security2:error] [pid 977210:tid 977427] [client 103.242.199.184:50336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugBPW1Jl2-fgIeVvqypQAAANo"]
[Thu Jul 30 14:03:32.787761 2026] [security2:error] [pid 977210:tid 977427] [client 103.242.199.184:50336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugBPW1Jl2-fgIeVvqypQAAANo"]
[Thu Jul 30 14:03:33.019141 2026] [security2:error] [pid 977210:tid 977456] [client 172.213.208.20:14857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amugBfW1Jl2-fgIeVvqyqQAAAPc"]
[Thu Jul 30 14:03:33.157721 2026] [security2:error] [pid 977210:tid 977443] [client 172.202.44.182:13617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/file56.php"] [unique_id "amugBfW1Jl2-fgIeVvqyswAAAOo"]
[Thu Jul 30 14:03:33.876142 2026] [core:notice] [pid 977210:tid 977439] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:34.285001 2026] [core:error] [pid 977210:tid 977378] [client 172.213.208.20:26029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:03:34.285030 2026] [core:error] [pid 977210:tid 977378] [client 172.213.208.20:26029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:03:34.358628 2026] [core:notice] [pid 977210:tid 977466] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:34.576504 2026] [security2:error] [pid 977210:tid 977393] [client 172.202.44.182:13587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amugBvW1Jl2-fgIeVvqy0wAAALg"]
[Thu Jul 30 14:03:34.582720 2026] [core:notice] [pid 977210:tid 977469] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:34.653730 2026] [security2:error] [pid 977210:tid 977454] [client 191.232.199.39:9223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/js/index.php"] [unique_id "amugBvW1Jl2-fgIeVvqy2AAAAPU"]
[Thu Jul 30 14:03:34.903063 2026] [security2:error] [pid 977210:tid 977355] [client 158.158.41.78:27595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amugBvW1Jl2-fgIeVvqy3wAAAJI"]
[Thu Jul 30 14:03:35.566197 2026] [security2:error] [pid 977210:tid 977432] [client 172.202.44.182:31813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-admin/css/index.php"] [unique_id "amugB_W1Jl2-fgIeVvqy9AAAAN8"]
[Thu Jul 30 14:03:35.760521 2026] [security2:error] [pid 977210:tid 977450] [client 158.158.41.78:42856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/admin.php"] [unique_id "amugB_W1Jl2-fgIeVvqy-QAAAPE"]
[Thu Jul 30 14:03:36.156209 2026] [security2:error] [pid 977210:tid 977391] [client 191.232.199.39:49619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/go.php"] [unique_id "amugCPW1Jl2-fgIeVvqzBAAAALY"]
[Thu Jul 30 14:03:36.434361 2026] [security2:error] [pid 977210:tid 977416] [client 172.202.44.182:46623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/edit.php"] [unique_id "amugCPW1Jl2-fgIeVvqzDgAAAM8"]
[Thu Jul 30 14:03:36.953605 2026] [proxy:error] [pid 977210:tid 977354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:36.953713 2026] [proxy_http:error] [pid 977210:tid 977354] [client 44.213.206.96:60626] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:36.954570 2026] [proxy:error] [pid 977210:tid 977354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:36.954630 2026] [proxy_http:error] [pid 977210:tid 977354] [client 44.213.206.96:60626] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:37.045093 2026] [proxy:error] [pid 977210:tid 977376] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:37.045173 2026] [proxy_http:error] [pid 977210:tid 977376] [client 44.213.206.96:62851] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:37.045738 2026] [proxy:error] [pid 977210:tid 977376] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:37.045781 2026] [proxy_http:error] [pid 977210:tid 977376] [client 44.213.206.96:62851] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:37.160405 2026] [security2:error] [pid 977210:tid 977351] [client 172.213.208.20:13374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/alfa.php"] [unique_id "amugCfW1Jl2-fgIeVvqzJgAAAI4"]
[Thu Jul 30 14:03:37.191855 2026] [security2:error] [pid 977210:tid 977365] [client 103.190.40.154:19218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugCfW1Jl2-fgIeVvqzJwAAAJw"]
[Thu Jul 30 14:03:37.192083 2026] [security2:error] [pid 977210:tid 977365] [client 103.190.40.154:19218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugCfW1Jl2-fgIeVvqzJwAAAJw"]
[Thu Jul 30 14:03:37.316023 2026] [security2:error] [pid 977210:tid 977258] [remote 57.141.0.51:21082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/44562851719/feed/rss2/"] [unique_id "amugCfW1Jl2-fgIeVvqzKwAA4y0"]
[Thu Jul 30 14:03:37.480268 2026] [security2:error] [pid 977210:tid 977458] [client 172.202.44.182:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/2.php"] [unique_id "amugCfW1Jl2-fgIeVvqzNAAAAPk"]
[Thu Jul 30 14:03:37.670926 2026] [security2:error] [pid 977210:tid 977381] [client 189.6.88.213:63814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugCfW1Jl2-fgIeVvqzNQAAAKw"]
[Thu Jul 30 14:03:37.671076 2026] [security2:error] [pid 977210:tid 977381] [client 189.6.88.213:63814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugCfW1Jl2-fgIeVvqzNQAAAKw"]
[Thu Jul 30 14:03:37.733110 2026] [security2:error] [pid 977210:tid 977372] [client 191.232.199.39:9240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/test1.php"] [unique_id "amugCfW1Jl2-fgIeVvqzPAAAAKM"]
[Thu Jul 30 14:03:37.954249 2026] [security2:error] [pid 977210:tid 977426] [client 158.158.41.78:27606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-configs.php"] [unique_id "amugCfW1Jl2-fgIeVvqzQgAAANk"]
[Thu Jul 30 14:03:38.459206 2026] [security2:error] [pid 977210:tid 977420] [client 172.202.44.182:31821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/uploads/admin.php"] [unique_id "amugCvW1Jl2-fgIeVvqzWgAAANM"]
[Thu Jul 30 14:03:39.620448 2026] [security2:error] [pid 977210:tid 977439] [client 172.237.109.114:54024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amugCvW1Jl2-fgIeVvqzaQAAAOY"]
[Thu Jul 30 14:03:39.642923 2026] [security2:error] [pid 977210:tid 977405] [client 172.202.44.182:31820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/mah.php"] [unique_id "amugC_W1Jl2-fgIeVvqzgAAAAMQ"]
[Thu Jul 30 14:03:39.666082 2026] [security2:error] [pid 977210:tid 977442] [client 191.232.199.39:9252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/images/index.php"] [unique_id "amugC_W1Jl2-fgIeVvqzgQAAAOk"]
[Thu Jul 30 14:03:40.218490 2026] [security2:error] [pid 977210:tid 977382] [client 158.158.41.78:44996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/php.php"] [unique_id "amugDPW1Jl2-fgIeVvqzlgAAAK0"]
[Thu Jul 30 14:03:40.898515 2026] [security2:error] [pid 977210:tid 977435] [client 172.202.44.182:31824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/send.php"] [unique_id "amugDPW1Jl2-fgIeVvqzpQAAAOI"]
[Thu Jul 30 14:03:41.572580 2026] [security2:error] [pid 977210:tid 977342] [client 216.73.216.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amugC_W1Jl2-fgIeVvqzcAAAhTU"], referer: http://www.spececigarette.com/sitemap.xml
[Thu Jul 30 14:03:41.668270 2026] [security2:error] [pid 977210:tid 977238] [remote 57.141.0.42:60766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5351135361/feed/rss2/"] [unique_id "amugDfW1Jl2-fgIeVvqz1AAA5Bk"]
[Thu Jul 30 14:03:42.121465 2026] [security2:error] [pid 977210:tid 977275] [remote 198.38.90.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.90.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jacislamabad.com"] [uri "/wp-login.php"] [unique_id "amugDvW1Jl2-fgIeVvqz5QAA9z4"]
[Thu Jul 30 14:03:42.290132 2026] [security2:error] [pid 977210:tid 977440] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugDfW1Jl2-fgIeVvqz1gAAAOc"]
[Thu Jul 30 14:03:42.326998 2026] [security2:error] [pid 977210:tid 977417] [client 191.232.199.39:9818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/asd.php"] [unique_id "amugDvW1Jl2-fgIeVvqz7gAAANA"]
[Thu Jul 30 14:03:42.351631 2026] [security2:error] [pid 977210:tid 977403] [client 158.158.41.78:29019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/index.php"] [unique_id "amugDvW1Jl2-fgIeVvqz7wAAAMI"]
[Thu Jul 30 14:03:42.498691 2026] [autoindex:error] [pid 977210:tid 977409] [client 3.225.222.228:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:03:42.515507 2026] [security2:error] [pid 977210:tid 977448] [client 181.116.200.68:34784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugDvW1Jl2-fgIeVvqz_AAAAO8"]
[Thu Jul 30 14:03:42.516303 2026] [security2:error] [pid 977210:tid 977448] [client 181.116.200.68:34784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugDvW1Jl2-fgIeVvqz_AAAAO8"]
[Thu Jul 30 14:03:42.532687 2026] [security2:error] [pid 977210:tid 977412] [client 172.237.109.114:9095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amugDfW1Jl2-fgIeVvqz3wAAAMs"]
[Thu Jul 30 14:03:42.793415 2026] [security2:error] [pid 977210:tid 977394] [client 43.173.182.226:38112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/04/23/apercu-de-la-collection-maillots-de-bain-etam-2012/"] [unique_id "amugDvW1Jl2-fgIeVvqz_QAAALk"]
[Thu Jul 30 14:03:42.963436 2026] [security2:error] [pid 977210:tid 977427] [client 172.202.44.182:47363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amugDvW1Jl2-fgIeVvq0DwAAANo"]
[Thu Jul 30 14:03:43.353284 2026] [security2:error] [pid 977210:tid 977431] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugDvW1Jl2-fgIeVvq0CgAAAN4"]
[Thu Jul 30 14:03:43.400454 2026] [core:notice] [pid 977210:tid 977366] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:43.405508 2026] [security2:error] [pid 977210:tid 977366] [client 43.172.196.45:36614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/04/23/apercu-de-la-collection-maillots-de-bain-etam-2012/"] [unique_id "amugD_W1Jl2-fgIeVvq0GQAAAJ0"], referer: https://carnetdeshopping.com/index.php/2012/04/23/apercu-de-la-collection-maillots-de-bain-etam-2012/
[Thu Jul 30 14:03:43.482707 2026] [security2:error] [pid 977210:tid 977421] [client 103.242.199.184:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugD_W1Jl2-fgIeVvq0IAAAANQ"]
[Thu Jul 30 14:03:43.482813 2026] [security2:error] [pid 977210:tid 977421] [client 103.242.199.184:50904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugD_W1Jl2-fgIeVvq0IAAAANQ"]
[Thu Jul 30 14:03:43.694442 2026] [security2:error] [pid 977210:tid 977437] [client 191.232.199.39:9235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amugD_W1Jl2-fgIeVvq0KwAAAOQ"]
[Thu Jul 30 14:03:43.851697 2026] [security2:error] [pid 977210:tid 977395] [client 149.76.69.84:1027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amugD_W1Jl2-fgIeVvq0KgAAunA"], referer: https://jwcpartners.org/wp-login.php?redirect_to=https%3A%2F%2Fjwcpartners.org%2Fwp-admin%2F&reauth=1
[Thu Jul 30 14:03:44.169095 2026] [security2:error] [pid 977210:tid 977380] [client 99.252.209.103:62235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amugEPW1Jl2-fgIeVvq0NAAAq3s"], referer: https://www.northyorksheridanmall.com/
[Thu Jul 30 14:03:44.454186 2026] [security2:error] [pid 977210:tid 977398] [client 172.202.44.182:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/about.php"] [unique_id "amugEPW1Jl2-fgIeVvq0PgAAAL0"]
[Thu Jul 30 14:03:44.711514 2026] [core:notice] [pid 977210:tid 977223] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:44.831300 2026] [authz_core:error] [pid 977210:tid 977462] [client 50.6.43.217:13846] AH01630: client denied by server configuration: /home2/ojqudite/jwcpartners/wp-content/uploads/code-execution.php
[Thu Jul 30 14:03:46.137909 2026] [security2:error] [pid 977210:tid 977452] [client 191.232.199.39:49607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amugEvW1Jl2-fgIeVvq0eAAAAPM"]
[Thu Jul 30 14:03:46.410057 2026] [core:notice] [pid 977210:tid 977231] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:46.965214 2026] [security2:error] [pid 977210:tid 977349] [client 158.158.41.78:44994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/a.php"] [unique_id "amugEvW1Jl2-fgIeVvq0nAAAAIw"]
[Thu Jul 30 14:03:47.466620 2026] [security2:error] [pid 977210:tid 977363] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugEvW1Jl2-fgIeVvq0lQAAmhM"]
[Thu Jul 30 14:03:47.655683 2026] [core:error] [pid 977210:tid 977352] [client 172.213.208.20:51860] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:03:47.655707 2026] [core:error] [pid 977210:tid 977352] [client 172.213.208.20:51860] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:03:48.003968 2026] [security2:error] [pid 977210:tid 977406] [client 191.232.199.39:9262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/atomlib.php"] [unique_id "amugFPW1Jl2-fgIeVvq0uAAAAMU"]
[Thu Jul 30 14:03:48.005183 2026] [security2:error] [pid 977210:tid 977374] [client 103.190.40.154:20805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugFPW1Jl2-fgIeVvq0twAAAKU"]
[Thu Jul 30 14:03:48.005301 2026] [security2:error] [pid 977210:tid 977374] [client 103.190.40.154:20805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugFPW1Jl2-fgIeVvq0twAAAKU"]
[Thu Jul 30 14:03:48.281344 2026] [security2:error] [pid 977210:tid 977445] [client 189.6.88.213:64356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugFPW1Jl2-fgIeVvq0xQAAAOw"]
[Thu Jul 30 14:03:48.281453 2026] [security2:error] [pid 977210:tid 977445] [client 189.6.88.213:64356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugFPW1Jl2-fgIeVvq0xQAAAOw"]
[Thu Jul 30 14:03:48.339797 2026] [security2:error] [pid 977210:tid 977422] [client 172.202.44.182:13581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/options.php"] [unique_id "amugFPW1Jl2-fgIeVvq0yQAAANU"]
[Thu Jul 30 14:03:49.031000 2026] [security2:error] [pid 977210:tid 977215] [remote 57.141.0.4:48860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JSTE/about/aboutThisPublishingSystem"] [unique_id "amugFfW1Jl2-fgIeVvq04QAAvgI"]
[Thu Jul 30 14:03:49.115359 2026] [security2:error] [pid 977210:tid 977348] [client 74.7.241.129:60524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.aptlaw.kr"] [uri "/cgi-sys/404.html"] [unique_id "amugFfW1Jl2-fgIeVvq04wAAiws"]
[Thu Jul 30 14:03:49.188310 2026] [security2:error] [pid 977210:tid 977395] [client 172.202.44.182:46522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-content/themes/index.php"] [unique_id "amugFfW1Jl2-fgIeVvq05gAAALo"]
[Thu Jul 30 14:03:49.729666 2026] [security2:error] [pid 977210:tid 977469] [client 172.213.208.20:39176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amugFfW1Jl2-fgIeVvq1AQAAAQQ"]
[Thu Jul 30 14:03:49.991115 2026] [security2:error] [pid 977210:tid 977394] [client 172.202.44.182:13594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/wp-file.php"] [unique_id "amugFfW1Jl2-fgIeVvq1CwAAALk"]
[Thu Jul 30 14:03:50.518014 2026] [security2:error] [pid 977210:tid 977396] [client 172.213.208.20:30980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amugFvW1Jl2-fgIeVvq1IAAAALs"]
[Thu Jul 30 14:03:50.835557 2026] [security2:error] [pid 977210:tid 977370] [client 158.158.41.78:50162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/Text/about.php"] [unique_id "amugFvW1Jl2-fgIeVvq1KwAAAKE"]
[Thu Jul 30 14:03:51.553148 2026] [security2:error] [pid 977210:tid 977235] [remote 57.141.0.67:26788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amugF_W1Jl2-fgIeVvq1RAAAphY"]
[Thu Jul 30 14:03:51.563738 2026] [security2:error] [pid 977210:tid 977412] [client 158.158.41.78:14940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin.php"] [unique_id "amugF_W1Jl2-fgIeVvq1RQAAAMs"]
[Thu Jul 30 14:03:51.760057 2026] [security2:error] [pid 977210:tid 977365] [client 191.232.199.39:9835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amugF_W1Jl2-fgIeVvq1TwAAAJw"]
[Thu Jul 30 14:03:51.783155 2026] [security2:error] [pid 977210:tid 977413] [client 5.102.173.71:0] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "journeywomenscenter.org"] [uri "/index.php"] [unique_id "amugFvW1Jl2-fgIeVvq1JAAAAMw"]
[Thu Jul 30 14:03:51.783947 2026] [security2:error] [pid 977210:tid 977382] [client 5.102.173.71:33124] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "journeywomenscenter.org"] [uri "/robots.txt"] [unique_id "amugFvW1Jl2-fgIeVvq1IgAAAK0"]
[Thu Jul 30 14:03:52.398090 2026] [security2:error] [pid 977210:tid 977456] [client 172.202.44.182:46285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.hmhs.ph"] [uri "/sid3.php"] [unique_id "amugGPW1Jl2-fgIeVvq1dAAAAPc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 14:03:52.688932 2026] [security2:error] [pid 977210:tid 977377] [client 158.158.41.78:30152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/size.php"] [unique_id "amugGPW1Jl2-fgIeVvq1gQAAAKg"]
[Thu Jul 30 14:03:52.693073 2026] [security2:error] [pid 977210:tid 977461] [client 5.102.173.71:0] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "journeywomenscenter.org"] [uri "/index.php"] [unique_id "amugF_W1Jl2-fgIeVvq1WQAAAPw"]
[Thu Jul 30 14:03:52.693724 2026] [security2:error] [pid 977210:tid 977378] [client 5.102.173.71:33124] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "journeywomenscenter.org"] [uri "/"] [unique_id "amugF_W1Jl2-fgIeVvq1VgAAAKk"]
[Thu Jul 30 14:03:52.870642 2026] [security2:error] [pid 977210:tid 977344] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugGPW1Jl2-fgIeVvq1bQAAAIc"]
[Thu Jul 30 14:03:53.140209 2026] [security2:error] [pid 977210:tid 977398] [client 181.116.200.68:50417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugGfW1Jl2-fgIeVvq1kAAAAL0"]
[Thu Jul 30 14:03:53.140326 2026] [security2:error] [pid 977210:tid 977398] [client 181.116.200.68:50417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugGfW1Jl2-fgIeVvq1kAAAAL0"]
[Thu Jul 30 14:03:53.741481 2026] [security2:error] [pid 977210:tid 977385] [client 172.213.208.20:51899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amugGfW1Jl2-fgIeVvq1sgAAALA"]
[Thu Jul 30 14:03:53.770411 2026] [security2:error] [pid 977210:tid 977354] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugGfW1Jl2-fgIeVvq1kQAAkWg"]
[Thu Jul 30 14:03:54.075606 2026] [security2:error] [pid 977210:tid 977395] [client 103.242.199.184:51469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugGvW1Jl2-fgIeVvq1wAAAALo"]
[Thu Jul 30 14:03:54.075710 2026] [security2:error] [pid 977210:tid 977395] [client 103.242.199.184:51469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugGvW1Jl2-fgIeVvq1wAAAALo"]
[Thu Jul 30 14:03:54.498776 2026] [security2:error] [pid 977210:tid 977368] [client 191.232.199.39:9256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/inputs.php"] [unique_id "amugGvW1Jl2-fgIeVvq1zAAAAJ8"]
[Thu Jul 30 14:03:54.622224 2026] [security2:error] [pid 977210:tid 977379] [client 172.237.109.114:40983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amugGvW1Jl2-fgIeVvq1vwAAAKo"]
[Thu Jul 30 14:03:54.800087 2026] [security2:error] [pid 977210:tid 977451] [client 158.158.41.78:28343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/wp-class.php"] [unique_id "amugGvW1Jl2-fgIeVvq12gAAAPI"]
[Thu Jul 30 14:03:55.731954 2026] [security2:error] [pid 977210:tid 977453] [client 158.158.41.78:50170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/403.php"] [unique_id "amugG_W1Jl2-fgIeVvq1_wAAAPQ"]
[Thu Jul 30 14:03:55.757203 2026] [security2:error] [pid 977210:tid 977359] [client 191.232.199.39:9852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/index.php"] [unique_id "amugG_W1Jl2-fgIeVvq2AAAAAJY"]
[Thu Jul 30 14:03:55.991165 2026] [security2:error] [pid 977210:tid 977419] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amugG_W1Jl2-fgIeVvq2BwAAANI"]
[Thu Jul 30 14:03:55.991310 2026] [security2:error] [pid 977210:tid 977419] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amugG_W1Jl2-fgIeVvq2BwAAANI"]
[Thu Jul 30 14:03:56.195757 2026] [security2:error] [pid 977210:tid 977280] [remote 57.141.0.46:46276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amugHPW1Jl2-fgIeVvq2EQAA7kM"]
[Thu Jul 30 14:03:56.400637 2026] [security2:error] [pid 977210:tid 977381] [client 158.158.41.78:28329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amugHPW1Jl2-fgIeVvq2GAAAAKw"]
[Thu Jul 30 14:03:56.507608 2026] [security2:error] [pid 977210:tid 977468] [client 20.100.187.246:25580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.tmb/LA.php"] [unique_id "amugHPW1Jl2-fgIeVvq2HAAAAQM"]
[Thu Jul 30 14:03:56.534599 2026] [security2:error] [pid 977210:tid 977454] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amugHPW1Jl2-fgIeVvq2HQAAAPU"]
[Thu Jul 30 14:03:56.534688 2026] [security2:error] [pid 977210:tid 977454] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amugHPW1Jl2-fgIeVvq2HQAAAPU"]
[Thu Jul 30 14:03:56.694338 2026] [security2:error] [pid 977210:tid 977465] [client 172.213.208.20:31009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/edit.php"] [unique_id "amugHPW1Jl2-fgIeVvq2JQAAAQA"]
[Thu Jul 30 14:03:57.050939 2026] [security2:error] [pid 977210:tid 977391] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wicked.php"] [unique_id "amugHfW1Jl2-fgIeVvq2MAAAALY"]
[Thu Jul 30 14:03:57.051063 2026] [security2:error] [pid 977210:tid 977391] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wicked.php"] [unique_id "amugHfW1Jl2-fgIeVvq2MAAAALY"]
[Thu Jul 30 14:03:57.074440 2026] [security2:error] [pid 977210:tid 977346] [client 158.158.41.78:28323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/as.php"] [unique_id "amugHfW1Jl2-fgIeVvq2MQAAAIk"]
[Thu Jul 30 14:03:57.585106 2026] [security2:error] [pid 977210:tid 977355] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wpx.php"] [unique_id "amugHfW1Jl2-fgIeVvq2RwAAAJI"]
[Thu Jul 30 14:03:57.585220 2026] [security2:error] [pid 977210:tid 977355] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wpx.php"] [unique_id "amugHfW1Jl2-fgIeVvq2RwAAAJI"]
[Thu Jul 30 14:03:57.599909 2026] [security2:error] [pid 977210:tid 977415] [client 20.100.187.246:25542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.tmb/admin.php"] [unique_id "amugHfW1Jl2-fgIeVvq2SAAAAM4"]
[Thu Jul 30 14:03:57.638257 2026] [security2:error] [pid 977210:tid 977399] [client 149.76.69.84:1034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "journeywomenscenter.org"] [uri "/wp-login.php"] [unique_id "amugHfW1Jl2-fgIeVvq2QAAAvhA"], referer: https://journeywomenscenter.org/wp-admin/update-core.php?action=do-theme-upgrade
[Thu Jul 30 14:03:57.751579 2026] [security2:error] [pid 977210:tid 977361] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugHfW1Jl2-fgIeVvq2RgAAAJg"]
[Thu Jul 30 14:03:57.751606 2026] [security2:error] [pid 977210:tid 977361] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugHfW1Jl2-fgIeVvq2RgAAAJg"]
[Thu Jul 30 14:03:57.751952 2026] [security2:error] [pid 977210:tid 977436] [client 82.102.18.180:35022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/assets/"] [unique_id "amugHfW1Jl2-fgIeVvq2RAAAAOM"]
[Thu Jul 30 14:03:57.799269 2026] [security2:error] [pid 977210:tid 977263] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugHfW1Jl2-fgIeVvq2OgAA5TI"]
[Thu Jul 30 14:03:57.799440 2026] [security2:error] [pid 977210:tid 977438] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugHfW1Jl2-fgIeVvq2OgAA5TI"]
[Thu Jul 30 14:03:57.983658 2026] [proxy:error] [pid 977210:tid 977407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:57.983739 2026] [proxy_http:error] [pid 977210:tid 977407] [client 34.233.129.35:19970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:57.984324 2026] [proxy:error] [pid 977210:tid 977407] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:57.984374 2026] [proxy_http:error] [pid 977210:tid 977407] [client 34.233.129.35:19970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:58.059841 2026] [proxy:error] [pid 977210:tid 977452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:58.059939 2026] [proxy_http:error] [pid 977210:tid 977452] [client 34.233.129.35:29359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:58.061051 2026] [proxy:error] [pid 977210:tid 977452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:03:58.061118 2026] [proxy_http:error] [pid 977210:tid 977452] [client 34.233.129.35:29359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:03:58.103148 2026] [security2:error] [pid 977210:tid 977381] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/images.php"] [unique_id "amugHvW1Jl2-fgIeVvq2YQAAAKw"]
[Thu Jul 30 14:03:58.103276 2026] [security2:error] [pid 977210:tid 977381] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/images.php"] [unique_id "amugHvW1Jl2-fgIeVvq2YQAAAKw"]
[Thu Jul 30 14:03:58.476972 2026] [security2:error] [pid 977210:tid 977368] [client 20.100.187.246:24031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.tmb/class_api.php"] [unique_id "amugHvW1Jl2-fgIeVvq2cwAAAJ8"]
[Thu Jul 30 14:03:58.597786 2026] [security2:error] [pid 977210:tid 977466] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/1xmomo.php"] [unique_id "amugHvW1Jl2-fgIeVvq2dwAAAQE"]
[Thu Jul 30 14:03:58.597876 2026] [security2:error] [pid 977210:tid 977466] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/1xmomo.php"] [unique_id "amugHvW1Jl2-fgIeVvq2dwAAAQE"]
[Thu Jul 30 14:03:58.717882 2026] [security2:error] [pid 977210:tid 977412] [client 191.232.199.39:9263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/network/index.php"] [unique_id "amugHvW1Jl2-fgIeVvq2fQAAAMs"]
[Thu Jul 30 14:03:59.009815 2026] [core:notice] [pid 977210:tid 977399] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:03:59.051097 2026] [security2:error] [pid 977210:tid 977396] [client 189.6.88.213:64909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugH_W1Jl2-fgIeVvq2jAAAALs"]
[Thu Jul 30 14:03:59.051226 2026] [security2:error] [pid 977210:tid 977396] [client 189.6.88.213:64909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugH_W1Jl2-fgIeVvq2jAAAALs"]
[Thu Jul 30 14:03:59.093369 2026] [security2:error] [pid 977210:tid 977394] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/1revo.php"] [unique_id "amugH_W1Jl2-fgIeVvq2jQAAALk"]
[Thu Jul 30 14:03:59.093476 2026] [security2:error] [pid 977210:tid 977394] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/1revo.php"] [unique_id "amugH_W1Jl2-fgIeVvq2jQAAALk"]
[Thu Jul 30 14:03:59.591821 2026] [security2:error] [pid 977210:tid 977409] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/cong.php"] [unique_id "amugH_W1Jl2-fgIeVvq2owAAAMg"]
[Thu Jul 30 14:03:59.591934 2026] [security2:error] [pid 977210:tid 977409] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/cong.php"] [unique_id "amugH_W1Jl2-fgIeVvq2owAAAMg"]
[Thu Jul 30 14:03:59.723451 2026] [core:error] [pid 977210:tid 977356] [client 172.213.208.20:32497] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:03:59.723477 2026] [core:error] [pid 977210:tid 977356] [client 172.213.208.20:32497] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:00.051664 2026] [security2:error] [pid 977210:tid 977421] [client 103.190.40.154:19112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugIPW1Jl2-fgIeVvq2swAAANQ"]
[Thu Jul 30 14:04:00.051796 2026] [security2:error] [pid 977210:tid 977421] [client 103.190.40.154:19112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugIPW1Jl2-fgIeVvq2swAAANQ"]
[Thu Jul 30 14:04:00.080864 2026] [security2:error] [pid 977210:tid 977382] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/a.php"] [unique_id "amugIPW1Jl2-fgIeVvq2tAAAAK0"]
[Thu Jul 30 14:04:00.080958 2026] [security2:error] [pid 977210:tid 977382] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/a.php"] [unique_id "amugIPW1Jl2-fgIeVvq2tAAAAK0"]
[Thu Jul 30 14:04:00.401431 2026] [security2:error] [pid 977210:tid 977405] [client 158.158.41.78:29912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/includes/index.php"] [unique_id "amugIPW1Jl2-fgIeVvq2vwAAAMQ"]
[Thu Jul 30 14:04:00.579048 2026] [security2:error] [pid 977210:tid 977343] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/srontol.php"] [unique_id "amugIPW1Jl2-fgIeVvq2xQAAAIY"]
[Thu Jul 30 14:04:00.579202 2026] [security2:error] [pid 977210:tid 977343] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/srontol.php"] [unique_id "amugIPW1Jl2-fgIeVvq2xQAAAIY"]
[Thu Jul 30 14:04:00.673048 2026] [security2:error] [pid 977210:tid 977295] [remote 57.141.0.14:45674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/56555984686/feed/rss2/"] [unique_id "amugIPW1Jl2-fgIeVvq2xwAAiFI"]
[Thu Jul 30 14:04:00.751856 2026] [security2:error] [pid 977210:tid 977469] [client 191.232.199.39:9731] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "fintn.com"] [uri "/wp-content/1.php"] [unique_id "amugIPW1Jl2-fgIeVvq2yAAAAQQ"]
[Thu Jul 30 14:04:00.752013 2026] [security2:error] [pid 977210:tid 977469] [client 191.232.199.39:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/1.php"] [unique_id "amugIPW1Jl2-fgIeVvq2yAAAAQQ"]
[Thu Jul 30 14:04:00.845716 2026] [security2:error] [pid 977210:tid 977352] [client 20.100.187.246:25588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amugIPW1Jl2-fgIeVvq2zAAAAI8"]
[Thu Jul 30 14:04:00.984338 2026] [core:error] [pid 977210:tid 977441] [client 172.213.208.20:40841] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:00.984364 2026] [core:error] [pid 977210:tid 977441] [client 172.213.208.20:40841] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:01.093037 2026] [security2:error] [pid 977210:tid 977429] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/reop3.php"] [unique_id "amugIfW1Jl2-fgIeVvq21gAAANw"]
[Thu Jul 30 14:04:01.093128 2026] [security2:error] [pid 977210:tid 977429] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/reop3.php"] [unique_id "amugIfW1Jl2-fgIeVvq21gAAANw"]
[Thu Jul 30 14:04:01.526969 2026] [core:notice] [pid 977210:tid 977381] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:01.606195 2026] [security2:error] [pid 977210:tid 977374] [client 158.158.41.78:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amugIfW1Jl2-fgIeVvq24gAAAKU"]
[Thu Jul 30 14:04:01.631771 2026] [security2:error] [pid 977210:tid 977379] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/file5.php"] [unique_id "amugIfW1Jl2-fgIeVvq25AAAAKo"]
[Thu Jul 30 14:04:01.631856 2026] [security2:error] [pid 977210:tid 977379] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/file5.php"] [unique_id "amugIfW1Jl2-fgIeVvq25AAAAKo"]
[Thu Jul 30 14:04:02.142223 2026] [security2:error] [pid 977210:tid 977424] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/domvf.php"] [unique_id "amugIvW1Jl2-fgIeVvq28AAAANc"]
[Thu Jul 30 14:04:02.142324 2026] [security2:error] [pid 977210:tid 977424] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/domvf.php"] [unique_id "amugIvW1Jl2-fgIeVvq28AAAANc"]
[Thu Jul 30 14:04:02.174250 2026] [security2:error] [pid 977210:tid 977215] [remote 198.38.90.25:43928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.90.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-login.php"] [unique_id "amugIvW1Jl2-fgIeVvq28QAAlQI"]
[Thu Jul 30 14:04:02.255045 2026] [core:notice] [pid 977210:tid 977437] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:02.439885 2026] [security2:error] [pid 977210:tid 977462] [client 158.158.41.78:22271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/plugins.php"] [unique_id "amugIvW1Jl2-fgIeVvq2_AAAAP0"]
[Thu Jul 30 14:04:02.558656 2026] [security2:error] [pid 977210:tid 977344] [client 20.100.187.246:25563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.tmb/wp-login.php"] [unique_id "amugIvW1Jl2-fgIeVvq29QAAAIc"]
[Thu Jul 30 14:04:02.698500 2026] [security2:error] [pid 977210:tid 977389] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/zero.php"] [unique_id "amugIvW1Jl2-fgIeVvq3AQAAALQ"]
[Thu Jul 30 14:04:02.698617 2026] [security2:error] [pid 977210:tid 977389] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/zero.php"] [unique_id "amugIvW1Jl2-fgIeVvq3AQAAALQ"]
[Thu Jul 30 14:04:03.226341 2026] [security2:error] [pid 977210:tid 977409] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/002.php"] [unique_id "amugI_W1Jl2-fgIeVvq3DgAAAMg"]
[Thu Jul 30 14:04:03.226454 2026] [security2:error] [pid 977210:tid 977409] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/002.php"] [unique_id "amugI_W1Jl2-fgIeVvq3DgAAAMg"]
[Thu Jul 30 14:04:03.289581 2026] [security2:error] [pid 977210:tid 977405] [client 172.213.208.20:41801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/file5.php"] [unique_id "amugI_W1Jl2-fgIeVvq3DwAAAMQ"]
[Thu Jul 30 14:04:03.435064 2026] [security2:error] [pid 977210:tid 977356] [client 20.100.187.246:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amugI_W1Jl2-fgIeVvq3FAAAAJM"]
[Thu Jul 30 14:04:03.715243 2026] [security2:error] [pid 977210:tid 977467] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/thoms.php"] [unique_id "amugI_W1Jl2-fgIeVvq3HgAAAQI"]
[Thu Jul 30 14:04:03.715343 2026] [security2:error] [pid 977210:tid 977467] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/thoms.php"] [unique_id "amugI_W1Jl2-fgIeVvq3HgAAAQI"]
[Thu Jul 30 14:04:03.715657 2026] [security2:error] [pid 977210:tid 977433] [client 181.116.200.68:64187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugI_W1Jl2-fgIeVvq3HwAAAOA"]
[Thu Jul 30 14:04:03.715751 2026] [security2:error] [pid 977210:tid 977433] [client 181.116.200.68:64187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugI_W1Jl2-fgIeVvq3HwAAAOA"]
[Thu Jul 30 14:04:04.077674 2026] [security2:error] [pid 977210:tid 977460] [client 191.232.199.39:9820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/plugin.php"] [unique_id "amugJPW1Jl2-fgIeVvq3KgAAAPs"]
[Thu Jul 30 14:04:04.201141 2026] [security2:error] [pid 977210:tid 977459] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fi22.php"] [unique_id "amugJPW1Jl2-fgIeVvq3LwAAAPo"]
[Thu Jul 30 14:04:04.201250 2026] [security2:error] [pid 977210:tid 977459] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fi22.php"] [unique_id "amugJPW1Jl2-fgIeVvq3LwAAAPo"]
[Thu Jul 30 14:04:04.245222 2026] [security2:error] [pid 977210:tid 977224] [remote 74.7.243.224:56952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/feed/img/js/uploads/partners/uploads/partners/uploads/partners/communityf.php"] [unique_id "amugJPW1Jl2-fgIeVvq3MAAA5As"], referer: https://aded-rdc.org/feed/img/js/uploads/partners/uploads/partners/uploads/partners/login.php
[Thu Jul 30 14:04:04.510458 2026] [security2:error] [pid 977210:tid 977451] [client 172.213.208.20:16949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/sf.php"] [unique_id "amugJPW1Jl2-fgIeVvq3OgAAAPI"]
[Thu Jul 30 14:04:04.651845 2026] [security2:error] [pid 977210:tid 977389] [client 103.242.199.184:52028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugJPW1Jl2-fgIeVvq3QQAAALQ"]
[Thu Jul 30 14:04:04.652005 2026] [security2:error] [pid 977210:tid 977389] [client 103.242.199.184:52028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugJPW1Jl2-fgIeVvq3QQAAALQ"]
[Thu Jul 30 14:04:04.716337 2026] [core:notice] [pid 977210:tid 977431] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:04.752366 2026] [security2:error] [pid 977210:tid 977395] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/___proxy_subdomain_cpanel/wp-content/"] [unique_id "amugJPW1Jl2-fgIeVvq3QwAAALo"]
[Thu Jul 30 14:04:04.797376 2026] [security2:error] [pid 977210:tid 977337] [remote 47.128.96.133:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/9470"] [unique_id "amugJPW1Jl2-fgIeVvq3OwAAu3w"]
[Thu Jul 30 14:04:04.865698 2026] [core:notice] [pid 977210:tid 977221] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:04.871312 2026] [security2:error] [pid 977210:tid 977429] [client 47.128.96.133:55076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/9470"] [unique_id "amugJPW1Jl2-fgIeVvq3RQAA3Ag"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:04:04.976644 2026] [security2:error] [pid 977210:tid 977352] [client 193.47.62.167:46132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-ecc63488.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amugJPW1Jl2-fgIeVvq3PAAAAI8"]
[Thu Jul 30 14:04:05.027284 2026] [security2:error] [pid 977210:tid 977401] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/82.php"] [unique_id "amugJfW1Jl2-fgIeVvq3TQAAAMA"]
[Thu Jul 30 14:04:05.027430 2026] [security2:error] [pid 977210:tid 977401] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/82.php"] [unique_id "amugJfW1Jl2-fgIeVvq3TQAAAMA"]
[Thu Jul 30 14:04:05.121569 2026] [core:notice] [pid 977210:tid 977330] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:05.232601 2026] [core:notice] [pid 977210:tid 977272] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:05.232684 2026] [core:notice] [pid 977210:tid 977280] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:05.288065 2026] [core:error] [pid 977210:tid 977380] [client 172.213.208.20:13932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:05.288088 2026] [core:error] [pid 977210:tid 977380] [client 172.213.208.20:13932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:05.428728 2026] [autoindex:error] [pid 977210:tid 977426] [client 2600:3c0b::2000:97ff:fee1:5c09:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://n1rmalabet88.com
[Thu Jul 30 14:04:05.535751 2026] [security2:error] [pid 977210:tid 977450] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sx.php"] [unique_id "amugJfW1Jl2-fgIeVvq3YQAAAPE"]
[Thu Jul 30 14:04:05.535894 2026] [security2:error] [pid 977210:tid 977450] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sx.php"] [unique_id "amugJfW1Jl2-fgIeVvq3YQAAAPE"]
[Thu Jul 30 14:04:05.602865 2026] [security2:error] [pid 977210:tid 977343] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugJPW1Jl2-fgIeVvq3SAAAhmo"]
[Thu Jul 30 14:04:05.739197 2026] [security2:error] [pid 977210:tid 977350] [client 78.40.199.55:65033] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "78.40.199.55" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "seven-stars-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amugJfW1Jl2-fgIeVvq3ZwAAAI0"], referer: https://seven-stars-shop.com/hello-world/
[Thu Jul 30 14:04:05.739359 2026] [security2:error] [pid 977210:tid 977350] [client 78.40.199.55:65033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/wp-comments-post.php"] [unique_id "amugJfW1Jl2-fgIeVvq3ZwAAAI0"], referer: https://seven-stars-shop.com/hello-world/
[Thu Jul 30 14:04:05.744138 2026] [security2:error] [pid 977210:tid 977374] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugJfW1Jl2-fgIeVvq3VQAAAKU"]
[Thu Jul 30 14:04:05.843043 2026] [security2:error] [pid 977210:tid 977347] [client 191.232.199.39:39541] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "fintn.com"] [uri "/1.php"] [unique_id "amugJfW1Jl2-fgIeVvq3aQAAAIo"]
[Thu Jul 30 14:04:05.843165 2026] [security2:error] [pid 977210:tid 977347] [client 191.232.199.39:39541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/1.php"] [unique_id "amugJfW1Jl2-fgIeVvq3aQAAAIo"]
[Thu Jul 30 14:04:06.000307 2026] [security2:error] [pid 977210:tid 977437] [client 172.213.208.20:32906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wso.php"] [unique_id "amugJfW1Jl2-fgIeVvq3bgAAAOQ"]
[Thu Jul 30 14:04:06.029273 2026] [security2:error] [pid 977210:tid 977453] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugJfW1Jl2-fgIeVvq3WwAA9Ck"]
[Thu Jul 30 14:04:06.055128 2026] [security2:error] [pid 977210:tid 977469] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/dex.php"] [unique_id "amugJvW1Jl2-fgIeVvq3bwAAAQQ"]
[Thu Jul 30 14:04:06.055224 2026] [security2:error] [pid 977210:tid 977469] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/dex.php"] [unique_id "amugJvW1Jl2-fgIeVvq3bwAAAQQ"]
[Thu Jul 30 14:04:06.376532 2026] [security2:error] [pid 977210:tid 977377] [client 158.158.41.78:12112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/js/index.php"] [unique_id "amugJvW1Jl2-fgIeVvq3ewAAAKg"]
[Thu Jul 30 14:04:06.424507 2026] [security2:error] [pid 977210:tid 977418] [client 20.100.187.246:24787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/991176.php"] [unique_id "amugJvW1Jl2-fgIeVvq3fQAAANE"]
[Thu Jul 30 14:04:06.673658 2026] [security2:error] [pid 977210:tid 977434] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fpwch.php"] [unique_id "amugJvW1Jl2-fgIeVvq3hwAAAOE"]
[Thu Jul 30 14:04:06.673761 2026] [security2:error] [pid 977210:tid 977434] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fpwch.php"] [unique_id "amugJvW1Jl2-fgIeVvq3hwAAAOE"]
[Thu Jul 30 14:04:06.915660 2026] [security2:error] [pid 977210:tid 977417] [client 172.213.208.20:16925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/ioxi-o.php"] [unique_id "amugJvW1Jl2-fgIeVvq3jgAAANA"]
[Thu Jul 30 14:04:07.186176 2026] [security2:error] [pid 977210:tid 977446] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/black.php"] [unique_id "amugJ_W1Jl2-fgIeVvq3oAAAAO0"]
[Thu Jul 30 14:04:07.186257 2026] [security2:error] [pid 977210:tid 977446] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/black.php"] [unique_id "amugJ_W1Jl2-fgIeVvq3oAAAAO0"]
[Thu Jul 30 14:04:07.210356 2026] [security2:error] [pid 977210:tid 977444] [client 20.100.187.246:25536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amugJ_W1Jl2-fgIeVvq3owAAAOs"]
[Thu Jul 30 14:04:07.261044 2026] [security2:error] [pid 977210:tid 977383] [client 191.232.199.39:39524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/gg.php"] [unique_id "amugJ_W1Jl2-fgIeVvq3pQAAAK4"]
[Thu Jul 30 14:04:07.557819 2026] [security2:error] [pid 977210:tid 977394] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugJvW1Jl2-fgIeVvq3kQAAALk"]
[Thu Jul 30 14:04:07.669640 2026] [security2:error] [pid 977210:tid 977342] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/loader.php"] [unique_id "amugJ_W1Jl2-fgIeVvq3yAAAAIU"]
[Thu Jul 30 14:04:07.669744 2026] [security2:error] [pid 977210:tid 977342] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/loader.php"] [unique_id "amugJ_W1Jl2-fgIeVvq3yAAAAIU"]
[Thu Jul 30 14:04:08.013410 2026] [security2:error] [pid 977210:tid 977378] [client 172.213.208.20:36247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/file56.php"] [unique_id "amugKPW1Jl2-fgIeVvq33AAAAKk"]
[Thu Jul 30 14:04:08.209759 2026] [security2:error] [pid 977210:tid 977384] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/file61.php"] [unique_id "amugKPW1Jl2-fgIeVvq34wAAAK8"]
[Thu Jul 30 14:04:08.209887 2026] [security2:error] [pid 977210:tid 977384] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/file61.php"] [unique_id "amugKPW1Jl2-fgIeVvq34wAAAK8"]
[Thu Jul 30 14:04:08.333642 2026] [security2:error] [pid 977210:tid 977373] [client 20.100.187.246:24792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amugKPW1Jl2-fgIeVvq36gAAAKQ"]
[Thu Jul 30 14:04:08.700269 2026] [security2:error] [pid 977210:tid 977415] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-css.php"] [unique_id "amugKPW1Jl2-fgIeVvq38wAAAM4"]
[Thu Jul 30 14:04:08.700460 2026] [security2:error] [pid 977210:tid 977415] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-css.php"] [unique_id "amugKPW1Jl2-fgIeVvq38wAAAM4"]
[Thu Jul 30 14:04:08.904030 2026] [security2:error] [pid 977210:tid 977435] [client 191.232.199.39:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp.php"] [unique_id "amugKPW1Jl2-fgIeVvq3-wAAAOI"]
[Thu Jul 30 14:04:09.121237 2026] [security2:error] [pid 977210:tid 977401] [client 20.100.187.246:25582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amugKfW1Jl2-fgIeVvq4BAAAAMA"]
[Thu Jul 30 14:04:09.203932 2026] [security2:error] [pid 977210:tid 977440] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-blink.php"] [unique_id "amugKfW1Jl2-fgIeVvq4BgAAAOc"]
[Thu Jul 30 14:04:09.204088 2026] [security2:error] [pid 977210:tid 977440] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-blink.php"] [unique_id "amugKfW1Jl2-fgIeVvq4BgAAAOc"]
[Thu Jul 30 14:04:09.583123 2026] [security2:error] [pid 977210:tid 977448] [client 184.75.223.227:33866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amugKfW1Jl2-fgIeVvq4IgAAAO8"]
[Thu Jul 30 14:04:09.583252 2026] [security2:error] [pid 977210:tid 977448] [client 184.75.223.227:33866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amugKfW1Jl2-fgIeVvq4IgAAAO8"]
[Thu Jul 30 14:04:09.702553 2026] [security2:error] [pid 977210:tid 977431] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/txets.php"] [unique_id "amugKfW1Jl2-fgIeVvq4IwAAAN4"]
[Thu Jul 30 14:04:09.702716 2026] [security2:error] [pid 977210:tid 977431] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/txets.php"] [unique_id "amugKfW1Jl2-fgIeVvq4IwAAAN4"]
[Thu Jul 30 14:04:09.727542 2026] [security2:error] [pid 977210:tid 977351] [client 189.6.88.213:65457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugKfW1Jl2-fgIeVvq4JwAAAI4"]
[Thu Jul 30 14:04:09.727669 2026] [security2:error] [pid 977210:tid 977351] [client 189.6.88.213:65457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugKfW1Jl2-fgIeVvq4JwAAAI4"]
[Thu Jul 30 14:04:09.729634 2026] [security2:error] [pid 977210:tid 977462] [client 172.213.208.20:32595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amugKfW1Jl2-fgIeVvq4KAAAAP0"]
[Thu Jul 30 14:04:09.844068 2026] [core:notice] [pid 977210:tid 977248] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:10.049235 2026] [security2:error] [pid 977210:tid 977375] [client 47.236.203.37:53480] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amugKvW1Jl2-fgIeVvq4OwAAAKY"]
[Thu Jul 30 14:04:10.101803 2026] [security2:error] [pid 977210:tid 977441] [client 20.100.187.246:24029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amugKvW1Jl2-fgIeVvq4PQAAAOg"]
[Thu Jul 30 14:04:10.198062 2026] [security2:error] [pid 977210:tid 977372] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/pucci.php"] [unique_id "amugKvW1Jl2-fgIeVvq4QgAAAKM"]
[Thu Jul 30 14:04:10.198170 2026] [security2:error] [pid 977210:tid 977372] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/pucci.php"] [unique_id "amugKvW1Jl2-fgIeVvq4QgAAAKM"]
[Thu Jul 30 14:04:10.216770 2026] [security2:error] [pid 977210:tid 977423] [client 47.236.203.37:53481] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "thdinfinity.com"] [uri "/wp-json/batch/v1"] [unique_id "amugKvW1Jl2-fgIeVvq4RQAAANY"]
[Thu Jul 30 14:04:10.482964 2026] [security2:error] [pid 977210:tid 977399] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugKfW1Jl2-fgIeVvq4LwAAvhk"]
[Thu Jul 30 14:04:10.610193 2026] [security2:error] [pid 977210:tid 977466] [client 172.213.208.20:35978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/css/index.php"] [unique_id "amugKvW1Jl2-fgIeVvq4UAAAAQE"]
[Thu Jul 30 14:04:10.724159 2026] [security2:error] [pid 977210:tid 977460] [client 20.100.187.246:25537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amugKvW1Jl2-fgIeVvq4VAAAAPs"]
[Thu Jul 30 14:04:10.726417 2026] [security2:error] [pid 977210:tid 977437] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xwpg.php"] [unique_id "amugKvW1Jl2-fgIeVvq4VgAAAOQ"]
[Thu Jul 30 14:04:10.726545 2026] [security2:error] [pid 977210:tid 977437] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xwpg.php"] [unique_id "amugKvW1Jl2-fgIeVvq4VgAAAOQ"]
[Thu Jul 30 14:04:10.937367 2026] [security2:error] [pid 977210:tid 977404] [client 191.232.199.39:49648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amugKvW1Jl2-fgIeVvq4XwAAAMM"]
[Thu Jul 30 14:04:11.000572 2026] [security2:error] [pid 977210:tid 977444] [client 78.40.199.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amugKvW1Jl2-fgIeVvq4TwAAAOs"], referer: http://smoke-tfhk.com/hello-world/
[Thu Jul 30 14:04:11.210233 2026] [security2:error] [pid 977210:tid 977459] [client 103.190.40.154:19229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugK_W1Jl2-fgIeVvq4YgAAAPo"]
[Thu Jul 30 14:04:11.210379 2026] [security2:error] [pid 977210:tid 977459] [client 103.190.40.154:19229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugK_W1Jl2-fgIeVvq4YgAAAPo"]
[Thu Jul 30 14:04:11.425727 2026] [security2:error] [pid 977210:tid 977362] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ops.php"] [unique_id "amugK_W1Jl2-fgIeVvq4bQAAAJk"]
[Thu Jul 30 14:04:11.425821 2026] [security2:error] [pid 977210:tid 977362] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ops.php"] [unique_id "amugK_W1Jl2-fgIeVvq4bQAAAJk"]
[Thu Jul 30 14:04:11.627749 2026] [security2:error] [pid 977210:tid 977464] [client 20.100.187.246:24824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amugK_W1Jl2-fgIeVvq4dwAAAP8"]
[Thu Jul 30 14:04:11.668990 2026] [security2:error] [pid 977210:tid 977438] [client 184.75.223.227:44716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugK_W1Jl2-fgIeVvq4eAAAAOU"]
[Thu Jul 30 14:04:11.669098 2026] [security2:error] [pid 977210:tid 977438] [client 184.75.223.227:44716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugK_W1Jl2-fgIeVvq4eAAAAOU"]
[Thu Jul 30 14:04:11.910134 2026] [security2:error] [pid 977210:tid 977368] [client 172.213.208.20:56108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/edit.php"] [unique_id "amugK_W1Jl2-fgIeVvq4fwAAAJ8"]
[Thu Jul 30 14:04:11.913392 2026] [security2:error] [pid 977210:tid 977382] [client 20.48.234.177:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amugK_W1Jl2-fgIeVvq4gAAAAK0"]
[Thu Jul 30 14:04:11.913508 2026] [security2:error] [pid 977210:tid 977382] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amugK_W1Jl2-fgIeVvq4gAAAAK0"]
[Thu Jul 30 14:04:11.913614 2026] [security2:error] [pid 977210:tid 977382] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/1.php"] [unique_id "amugK_W1Jl2-fgIeVvq4gAAAAK0"]
[Thu Jul 30 14:04:12.064075 2026] [security2:error] [pid 977210:tid 977388] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugK_W1Jl2-fgIeVvq4dAAAALM"]
[Thu Jul 30 14:04:12.234401 2026] [security2:error] [pid 977210:tid 977418] [client 68.221.186.136:30764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/011i.php"] [unique_id "amugLPW1Jl2-fgIeVvq4iQAAANE"]
[Thu Jul 30 14:04:12.403238 2026] [security2:error] [pid 977210:tid 977460] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/mac.php"] [unique_id "amugLPW1Jl2-fgIeVvq4jQAAAPs"]
[Thu Jul 30 14:04:12.403341 2026] [security2:error] [pid 977210:tid 977460] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/mac.php"] [unique_id "amugLPW1Jl2-fgIeVvq4jQAAAPs"]
[Thu Jul 30 14:04:12.597831 2026] [proxy:error] [pid 977210:tid 977453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:12.597915 2026] [proxy_http:error] [pid 977210:tid 977453] [client 34.233.129.35:45729] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:12.598793 2026] [proxy:error] [pid 977210:tid 977453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:12.598846 2026] [proxy_http:error] [pid 977210:tid 977453] [client 34.233.129.35:45729] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:12.618928 2026] [security2:error] [pid 977210:tid 977432] [client 172.213.208.20:29770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/2.php"] [unique_id "amugLPW1Jl2-fgIeVvq4mAAAAN8"]
[Thu Jul 30 14:04:12.630910 2026] [security2:error] [pid 977210:tid 977374] [client 191.232.199.39:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/file.php"] [unique_id "amugLPW1Jl2-fgIeVvq4mQAAAKU"]
[Thu Jul 30 14:04:12.935384 2026] [security2:error] [pid 977210:tid 977376] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-admin/js/index.php"] [unique_id "amugLPW1Jl2-fgIeVvq4oQAAAKc"]
[Thu Jul 30 14:04:12.935481 2026] [security2:error] [pid 977210:tid 977376] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-admin/js/index.php"] [unique_id "amugLPW1Jl2-fgIeVvq4oQAAAKc"]
[Thu Jul 30 14:04:13.049068 2026] [security2:error] [pid 977210:tid 977406] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugLPW1Jl2-fgIeVvq4lQAAxXU"]
[Thu Jul 30 14:04:13.341415 2026] [security2:error] [pid 977210:tid 977404] [client 184.75.223.227:44728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amugLfW1Jl2-fgIeVvq4qwAAAMM"]
[Thu Jul 30 14:04:13.341528 2026] [security2:error] [pid 977210:tid 977404] [client 184.75.223.227:44728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amugLfW1Jl2-fgIeVvq4qwAAAMM"]
[Thu Jul 30 14:04:13.425221 2026] [security2:error] [pid 977210:tid 977451] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/aa.php"] [unique_id "amugLfW1Jl2-fgIeVvq4sAAAAPI"]
[Thu Jul 30 14:04:13.425303 2026] [security2:error] [pid 977210:tid 977451] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/aa.php"] [unique_id "amugLfW1Jl2-fgIeVvq4sAAAAPI"]
[Thu Jul 30 14:04:13.689822 2026] [security2:error] [pid 977210:tid 977358] [client 158.158.41.78:45037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/go.php"] [unique_id "amugLfW1Jl2-fgIeVvq4uwAAAJU"]
[Thu Jul 30 14:04:13.957578 2026] [security2:error] [pid 977210:tid 977417] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xyn.php"] [unique_id "amugLfW1Jl2-fgIeVvq4wAAAANA"]
[Thu Jul 30 14:04:13.957710 2026] [security2:error] [pid 977210:tid 977417] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xyn.php"] [unique_id "amugLfW1Jl2-fgIeVvq4wAAAANA"]
[Thu Jul 30 14:04:14.005517 2026] [security2:error] [pid 977210:tid 977377] [client 191.232.199.39:39503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/user/index.php"] [unique_id "amugLvW1Jl2-fgIeVvq4xAAAAKg"]
[Thu Jul 30 14:04:14.027623 2026] [security2:error] [pid 977210:tid 977456] [client 68.221.186.136:46413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/03a005685d.php"] [unique_id "amugLvW1Jl2-fgIeVvq4xgAAAPc"]
[Thu Jul 30 14:04:14.031240 2026] [security2:error] [pid 977210:tid 977350] [client 20.100.187.246:24008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amugLvW1Jl2-fgIeVvq4xwAAAI0"]
[Thu Jul 30 14:04:14.245428 2026] [security2:error] [pid 977210:tid 977403] [client 172.213.208.20:16934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amugLvW1Jl2-fgIeVvq4zgAAAMI"]
[Thu Jul 30 14:04:14.319069 2026] [security2:error] [pid 977210:tid 977438] [client 181.116.200.68:18051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugLvW1Jl2-fgIeVvq40AAAAOU"]
[Thu Jul 30 14:04:14.319175 2026] [security2:error] [pid 977210:tid 977438] [client 181.116.200.68:18051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugLvW1Jl2-fgIeVvq40AAAAOU"]
[Thu Jul 30 14:04:14.568015 2026] [security2:error] [pid 977210:tid 977369] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-wp.php"] [unique_id "amugLvW1Jl2-fgIeVvq43AAAAKA"]
[Thu Jul 30 14:04:14.568096 2026] [security2:error] [pid 977210:tid 977369] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-wp.php"] [unique_id "amugLvW1Jl2-fgIeVvq43AAAAKA"]
[Thu Jul 30 14:04:14.910880 2026] [security2:error] [pid 977210:tid 977404] [client 20.100.187.246:24007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amugLvW1Jl2-fgIeVvq44gAAAMM"]
[Thu Jul 30 14:04:15.074409 2026] [security2:error] [pid 977210:tid 977410] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/aw.php"] [unique_id "amugL_W1Jl2-fgIeVvq46wAAAMk"]
[Thu Jul 30 14:04:15.074500 2026] [security2:error] [pid 977210:tid 977410] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/aw.php"] [unique_id "amugL_W1Jl2-fgIeVvq46wAAAMk"]
[Thu Jul 30 14:04:15.264945 2026] [security2:error] [pid 977210:tid 977361] [client 103.242.199.184:52590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugL_W1Jl2-fgIeVvq5DAAAAJg"]
[Thu Jul 30 14:04:15.265077 2026] [security2:error] [pid 977210:tid 977361] [client 103.242.199.184:52590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugL_W1Jl2-fgIeVvq5DAAAAJg"]
[Thu Jul 30 14:04:15.577713 2026] [security2:error] [pid 977210:tid 977451] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/classwithtostring.php"] [unique_id "amugL_W1Jl2-fgIeVvq5FwAAAPI"]
[Thu Jul 30 14:04:15.577816 2026] [security2:error] [pid 977210:tid 977451] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/classwithtostring.php"] [unique_id "amugL_W1Jl2-fgIeVvq5FwAAAPI"]
[Thu Jul 30 14:04:15.583593 2026] [security2:error] [pid 977210:tid 977385] [client 20.100.187.246:24009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amugL_W1Jl2-fgIeVvq5GAAAALA"]
[Thu Jul 30 14:04:15.707074 2026] [security2:error] [pid 977210:tid 977456] [client 191.232.199.39:49605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amugL_W1Jl2-fgIeVvq5HQAAAPc"]
[Thu Jul 30 14:04:16.087185 2026] [security2:error] [pid 977210:tid 977417] [client 203.175.125.36:50365] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "emmelevate.club"] [uri "/wp-json/batch/v1"] [unique_id "amugMPW1Jl2-fgIeVvq5KgAAANA"]
[Thu Jul 30 14:04:16.116230 2026] [security2:error] [pid 977210:tid 977420] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/yawa.php"] [unique_id "amugMPW1Jl2-fgIeVvq5LgAAANM"]
[Thu Jul 30 14:04:16.116332 2026] [security2:error] [pid 977210:tid 977420] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/yawa.php"] [unique_id "amugMPW1Jl2-fgIeVvq5LgAAANM"]
[Thu Jul 30 14:04:16.533606 2026] [security2:error] [pid 977210:tid 977446] [client 20.100.187.246:25567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amugMPW1Jl2-fgIeVvq5NgAAAO0"]
[Thu Jul 30 14:04:16.633458 2026] [security2:error] [pid 977210:tid 977437] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sym403.php"] [unique_id "amugMPW1Jl2-fgIeVvq5OgAAAOQ"]
[Thu Jul 30 14:04:16.633569 2026] [security2:error] [pid 977210:tid 977437] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sym403.php"] [unique_id "amugMPW1Jl2-fgIeVvq5OgAAAOQ"]
[Thu Jul 30 14:04:16.694176 2026] [core:notice] [pid 977210:tid 977361] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:16.812606 2026] [security2:error] [pid 977210:tid 977350] [client 68.221.186.136:30775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/403.php"] [unique_id "amugMPW1Jl2-fgIeVvq5PwAAAI0"]
[Thu Jul 30 14:04:17.205951 2026] [security2:error] [pid 977210:tid 977379] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/blue/"] [unique_id "amugMfW1Jl2-fgIeVvq5RAAAAKo"]
[Thu Jul 30 14:04:17.465829 2026] [security2:error] [pid 977210:tid 977359] [client 191.232.199.39:9813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/index/function.php"] [unique_id "amugMfW1Jl2-fgIeVvq5TgAAAJY"]
[Thu Jul 30 14:04:17.493749 2026] [security2:error] [pid 977210:tid 977464] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/adminner.php"] [unique_id "amugMfW1Jl2-fgIeVvq5TwAAAP8"]
[Thu Jul 30 14:04:17.493895 2026] [security2:error] [pid 977210:tid 977464] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/adminner.php"] [unique_id "amugMfW1Jl2-fgIeVvq5TwAAAP8"]
[Thu Jul 30 14:04:17.539513 2026] [security2:error] [pid 977210:tid 977442] [client 172.213.208.20:32916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/mah.php"] [unique_id "amugMfW1Jl2-fgIeVvq5UAAAAOk"]
[Thu Jul 30 14:04:17.561885 2026] [core:notice] [pid 977210:tid 977445] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:17.640176 2026] [security2:error] [pid 977210:tid 977345] [client 20.100.187.246:25587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amugMfW1Jl2-fgIeVvq5WgAAAIg"]
[Thu Jul 30 14:04:18.025070 2026] [security2:error] [pid 977210:tid 977360] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/yup.php"] [unique_id "amugMvW1Jl2-fgIeVvq5ZAAAAJc"]
[Thu Jul 30 14:04:18.025174 2026] [security2:error] [pid 977210:tid 977360] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/yup.php"] [unique_id "amugMvW1Jl2-fgIeVvq5ZAAAAJc"]
[Thu Jul 30 14:04:18.091972 2026] [security2:error] [pid 977210:tid 977461] [client 68.221.186.136:23389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/404.php"] [unique_id "amugMvW1Jl2-fgIeVvq5aAAAAPw"]
[Thu Jul 30 14:04:18.237814 2026] [security2:error] [pid 977210:tid 977388] [client 20.100.187.246:25565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amugMvW1Jl2-fgIeVvq5bAAAALM"]
[Thu Jul 30 14:04:18.558328 2026] [security2:error] [pid 977210:tid 977396] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/config.json.php"] [unique_id "amugMvW1Jl2-fgIeVvq5dQAAALs"]
[Thu Jul 30 14:04:18.558449 2026] [security2:error] [pid 977210:tid 977396] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/config.json.php"] [unique_id "amugMvW1Jl2-fgIeVvq5dQAAALs"]
[Thu Jul 30 14:04:18.745996 2026] [security2:error] [pid 977210:tid 977453] [client 158.158.41.78:45035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/aaa.php"] [unique_id "amugMvW1Jl2-fgIeVvq5ggAAAPQ"]
[Thu Jul 30 14:04:18.919433 2026] [security2:error] [pid 977210:tid 977457] [client 20.100.187.246:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amugMvW1Jl2-fgIeVvq5iAAAAPg"]
[Thu Jul 30 14:04:19.132574 2026] [security2:error] [pid 977210:tid 977362] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/___proxy_subdomain_cpanel/wp-includes/block-bindings/"] [unique_id "amugM_W1Jl2-fgIeVvq5igAAAJk"]
[Thu Jul 30 14:04:19.397226 2026] [security2:error] [pid 977210:tid 977429] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/2.php"] [unique_id "amugM_W1Jl2-fgIeVvq5mAAAANw"]
[Thu Jul 30 14:04:19.397370 2026] [security2:error] [pid 977210:tid 977429] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/2.php"] [unique_id "amugM_W1Jl2-fgIeVvq5mAAAANw"]
[Thu Jul 30 14:04:19.654325 2026] [security2:error] [pid 977210:tid 977424] [client 20.100.187.246:25568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/amaxx.php"] [unique_id "amugM_W1Jl2-fgIeVvq5pAAAANc"]
[Thu Jul 30 14:04:19.877187 2026] [security2:error] [pid 977210:tid 977399] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/f35.update.php"] [unique_id "amugM_W1Jl2-fgIeVvq5rQAAAL4"]
[Thu Jul 30 14:04:19.877292 2026] [security2:error] [pid 977210:tid 977399] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/f35.update.php"] [unique_id "amugM_W1Jl2-fgIeVvq5rQAAAL4"]
[Thu Jul 30 14:04:20.019480 2026] [security2:error] [pid 977210:tid 977381] [client 74.7.175.146:44086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amugNPW1Jl2-fgIeVvq5tAAArCM"], referer: https://historiadevenezuela.org/partido-conservador/
[Thu Jul 30 14:04:20.220280 2026] [security2:error] [pid 977210:tid 977356] [client 172.213.17.107:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/about.php"] [unique_id "amugNPW1Jl2-fgIeVvq5uAAAAJM"]
[Thu Jul 30 14:04:20.220442 2026] [security2:error] [pid 977210:tid 977356] [client 172.213.17.107:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/about.php"] [unique_id "amugNPW1Jl2-fgIeVvq5uAAAAJM"]
[Thu Jul 30 14:04:20.305816 2026] [security2:error] [pid 977210:tid 977385] [client 191.232.199.39:49649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/aaa.php"] [unique_id "amugNPW1Jl2-fgIeVvq5ugAAALA"]
[Thu Jul 30 14:04:20.389217 2026] [security2:error] [pid 977210:tid 977436] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/k.php"] [unique_id "amugNPW1Jl2-fgIeVvq5vwAAAOM"]
[Thu Jul 30 14:04:20.389336 2026] [security2:error] [pid 977210:tid 977436] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/k.php"] [unique_id "amugNPW1Jl2-fgIeVvq5vwAAAOM"]
[Thu Jul 30 14:04:20.393166 2026] [security2:error] [pid 977210:tid 977466] [client 172.213.208.20:13583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/send.php"] [unique_id "amugNPW1Jl2-fgIeVvq5wAAAAQE"]
[Thu Jul 30 14:04:20.488290 2026] [security2:error] [pid 977210:tid 977400] [client 189.6.88.213:49885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugNPW1Jl2-fgIeVvq5xQAAAL8"]
[Thu Jul 30 14:04:20.488420 2026] [security2:error] [pid 977210:tid 977400] [client 189.6.88.213:49885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugNPW1Jl2-fgIeVvq5xQAAAL8"]
[Thu Jul 30 14:04:20.688258 2026] [core:notice] [pid 977210:tid 977298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:20.696913 2026] [security2:error] [pid 977210:tid 977411] [client 74.7.175.146:44090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amugNPW1Jl2-fgIeVvq5ywAAylU"], referer: https://womenclothingbox.com/refund-policy/
[Thu Jul 30 14:04:20.903839 2026] [security2:error] [pid 977210:tid 977412] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/"] [unique_id "amugNPW1Jl2-fgIeVvq5zQAAAMs"]
[Thu Jul 30 14:04:21.160342 2026] [security2:error] [pid 977210:tid 977396] [client 77.83.36.161:27227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amugNPW1Jl2-fgIeVvq5zgAAALs"]
[Thu Jul 30 14:04:21.180465 2026] [security2:error] [pid 977210:tid 977457] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/spadex.php"] [unique_id "amugNfW1Jl2-fgIeVvq51wAAAPg"]
[Thu Jul 30 14:04:21.180617 2026] [security2:error] [pid 977210:tid 977457] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/spadex.php"] [unique_id "amugNfW1Jl2-fgIeVvq51wAAAPg"]
[Thu Jul 30 14:04:21.568042 2026] [security2:error] [pid 977210:tid 977409] [client 74.7.175.146:44094] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amugNfW1Jl2-fgIeVvq52wAAyGI"], referer: https://carnetdeshopping.com/
[Thu Jul 30 14:04:21.684310 2026] [security2:error] [pid 977210:tid 977468] [client 158.158.41.78:31716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/getid3-core.php"] [unique_id "amugNfW1Jl2-fgIeVvq54gAAAQM"]
[Thu Jul 30 14:04:21.712060 2026] [security2:error] [pid 977210:tid 977425] [client 77.83.36.161:27748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amugNfW1Jl2-fgIeVvq55AAAANg"]
[Thu Jul 30 14:04:21.743812 2026] [security2:error] [pid 977210:tid 977421] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/mg.php"] [unique_id "amugNfW1Jl2-fgIeVvq55wAAANQ"]
[Thu Jul 30 14:04:21.743926 2026] [security2:error] [pid 977210:tid 977421] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/mg.php"] [unique_id "amugNfW1Jl2-fgIeVvq55wAAANQ"]
[Thu Jul 30 14:04:22.053545 2026] [security2:error] [pid 977210:tid 977370] [client 20.100.187.246:24789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/bek.php"] [unique_id "amugNvW1Jl2-fgIeVvq57wAAAKE"]
[Thu Jul 30 14:04:22.267014 2026] [security2:error] [pid 977210:tid 977448] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fnstall.php"] [unique_id "amugNvW1Jl2-fgIeVvq58gAAAO8"]
[Thu Jul 30 14:04:22.267116 2026] [security2:error] [pid 977210:tid 977448] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fnstall.php"] [unique_id "amugNvW1Jl2-fgIeVvq58gAAAO8"]
[Thu Jul 30 14:04:22.434501 2026] [security2:error] [pid 977210:tid 977350] [client 77.83.36.161:28137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amugNvW1Jl2-fgIeVvq59wAAAI0"]
[Thu Jul 30 14:04:22.760367 2026] [security2:error] [pid 977210:tid 977469] [client 20.100.187.246:24773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amugNvW1Jl2-fgIeVvq6AQAAAQQ"]
[Thu Jul 30 14:04:22.774269 2026] [security2:error] [pid 977210:tid 977361] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ortasekerli1.php"] [unique_id "amugNvW1Jl2-fgIeVvq6AgAAAJg"]
[Thu Jul 30 14:04:22.774351 2026] [security2:error] [pid 977210:tid 977361] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ortasekerli1.php"] [unique_id "amugNvW1Jl2-fgIeVvq6AgAAAJg"]
[Thu Jul 30 14:04:23.089734 2026] [security2:error] [pid 977210:tid 977342] [client 191.232.199.39:9841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/getid3-core.php"] [unique_id "amugN_W1Jl2-fgIeVvq6CwAAAIU"]
[Thu Jul 30 14:04:23.290371 2026] [security2:error] [pid 977210:tid 977396] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sump1.php"] [unique_id "amugN_W1Jl2-fgIeVvq6EAAAALs"]
[Thu Jul 30 14:04:23.290499 2026] [security2:error] [pid 977210:tid 977396] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sump1.php"] [unique_id "amugN_W1Jl2-fgIeVvq6EAAAALs"]
[Thu Jul 30 14:04:23.401884 2026] [security2:error] [pid 977210:tid 977451] [client 20.100.187.246:25589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/class.api.php"] [unique_id "amugN_W1Jl2-fgIeVvq6FwAAAPI"]
[Thu Jul 30 14:04:23.524429 2026] [security2:error] [pid 977210:tid 977438] [client 172.213.208.20:36056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amugN_W1Jl2-fgIeVvq6HQAAAOU"]
[Thu Jul 30 14:04:23.842356 2026] [security2:error] [pid 977210:tid 977420] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ops.php"] [unique_id "amugN_W1Jl2-fgIeVvq6IwAAANM"]
[Thu Jul 30 14:04:23.842484 2026] [security2:error] [pid 977210:tid 977420] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ops.php"] [unique_id "amugN_W1Jl2-fgIeVvq6IwAAANM"]
[Thu Jul 30 14:04:23.862259 2026] [core:notice] [pid 977210:tid 977264] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:24.039238 2026] [security2:error] [pid 977210:tid 977449] [client 18.201.83.134:54398] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/04/favicon-300x300.jpg"] [unique_id "amugOPW1Jl2-fgIeVvq6LQAA8Fo"]
[Thu Jul 30 14:04:24.212899 2026] [security2:error] [pid 977210:tid 977410] [client 20.100.187.246:24825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/cong.php"] [unique_id "amugOPW1Jl2-fgIeVvq6NAAAAMk"]
[Thu Jul 30 14:04:24.231764 2026] [core:notice] [pid 977210:tid 977330] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:24.357172 2026] [security2:error] [pid 977210:tid 977430] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-post-data.php"] [unique_id "amugOPW1Jl2-fgIeVvq6NwAAAN0"]
[Thu Jul 30 14:04:24.357303 2026] [security2:error] [pid 977210:tid 977430] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-post-data.php"] [unique_id "amugOPW1Jl2-fgIeVvq6NwAAAN0"]
[Thu Jul 30 14:04:24.406571 2026] [security2:error] [pid 977210:tid 977370] [client 3.253.88.183:55784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/05/parlx-services-commercial-5.jpg"] [unique_id "amugOPW1Jl2-fgIeVvq6LAAAoVs"]
[Thu Jul 30 14:04:24.596512 2026] [security2:error] [pid 977210:tid 977434] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugN_W1Jl2-fgIeVvq6KwAAAOE"]
[Thu Jul 30 14:04:24.845428 2026] [security2:error] [pid 977210:tid 977388] [client 191.232.199.39:39546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/adminer.php"] [unique_id "amugOPW1Jl2-fgIeVvq6RgAAALM"]
[Thu Jul 30 14:04:24.852230 2026] [security2:error] [pid 977210:tid 977440] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/root.php"] [unique_id "amugOPW1Jl2-fgIeVvq6RwAAAOc"]
[Thu Jul 30 14:04:24.852305 2026] [security2:error] [pid 977210:tid 977440] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/root.php"] [unique_id "amugOPW1Jl2-fgIeVvq6RwAAAOc"]
[Thu Jul 30 14:04:24.893090 2026] [security2:error] [pid 977210:tid 977411] [client 181.116.200.68:32290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugOPW1Jl2-fgIeVvq6UgAAAMo"]
[Thu Jul 30 14:04:24.893187 2026] [security2:error] [pid 977210:tid 977411] [client 181.116.200.68:32290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugOPW1Jl2-fgIeVvq6UgAAAMo"]
[Thu Jul 30 14:04:24.986633 2026] [security2:error] [pid 977210:tid 977457] [client 20.100.187.246:24053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/content.php"] [unique_id "amugOPW1Jl2-fgIeVvq6UwAAAPg"]
[Thu Jul 30 14:04:25.105385 2026] [core:error] [pid 977210:tid 977441] [client 172.213.208.20:39996] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:25.105404 2026] [core:error] [pid 977210:tid 977441] [client 172.213.208.20:39996] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:25.380161 2026] [security2:error] [pid 977210:tid 977416] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/v543.php"] [unique_id "amugOfW1Jl2-fgIeVvq6XAAAAM8"]
[Thu Jul 30 14:04:25.380296 2026] [security2:error] [pid 977210:tid 977416] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/v543.php"] [unique_id "amugOfW1Jl2-fgIeVvq6XAAAAM8"]
[Thu Jul 30 14:04:25.815770 2026] [core:notice] [pid 977210:tid 977461] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:25.892558 2026] [security2:error] [pid 977210:tid 977419] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sixxis.php"] [unique_id "amugOfW1Jl2-fgIeVvq6aQAAANI"]
[Thu Jul 30 14:04:25.892675 2026] [security2:error] [pid 977210:tid 977419] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sixxis.php"] [unique_id "amugOfW1Jl2-fgIeVvq6aQAAANI"]
[Thu Jul 30 14:04:25.895535 2026] [security2:error] [pid 977210:tid 977406] [client 68.221.186.136:23408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/aa.php"] [unique_id "amugOfW1Jl2-fgIeVvq6agAAAMU"]
[Thu Jul 30 14:04:25.923047 2026] [security2:error] [pid 977210:tid 977435] [client 103.242.199.184:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugOfW1Jl2-fgIeVvq6awAAAOI"]
[Thu Jul 30 14:04:25.923148 2026] [security2:error] [pid 977210:tid 977435] [client 103.242.199.184:53146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugOfW1Jl2-fgIeVvq6awAAAOI"]
[Thu Jul 30 14:04:25.928104 2026] [proxy:error] [pid 977210:tid 977374] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:25.928200 2026] [proxy_http:error] [pid 977210:tid 977374] [client 52.202.41.153:43392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:25.928418 2026] [proxy:error] [pid 977210:tid 977378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:25.928474 2026] [proxy_http:error] [pid 977210:tid 977378] [client 52.202.41.153:19286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:25.928776 2026] [proxy:error] [pid 977210:tid 977374] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:25.928821 2026] [proxy_http:error] [pid 977210:tid 977374] [client 52.202.41.153:43392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:25.929076 2026] [proxy:error] [pid 977210:tid 977378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:25.929126 2026] [proxy_http:error] [pid 977210:tid 977378] [client 52.202.41.153:19286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:26.100813 2026] [security2:error] [pid 977210:tid 977383] [client 20.100.187.246:6142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amugOvW1Jl2-fgIeVvq6dwAAAK4"]
[Thu Jul 30 14:04:26.345278 2026] [security2:error] [pid 977210:tid 977385] [client 158.158.41.78:17171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/adminer.php"] [unique_id "amugOvW1Jl2-fgIeVvq6gAAAALA"]
[Thu Jul 30 14:04:26.397603 2026] [security2:error] [pid 977210:tid 977345] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ip.php"] [unique_id "amugOvW1Jl2-fgIeVvq6gQAAAIg"]
[Thu Jul 30 14:04:26.397705 2026] [security2:error] [pid 977210:tid 977345] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ip.php"] [unique_id "amugOvW1Jl2-fgIeVvq6gQAAAIg"]
[Thu Jul 30 14:04:26.747962 2026] [security2:error] [pid 977210:tid 977465] [client 20.100.187.246:24807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/elp.php"] [unique_id "amugOvW1Jl2-fgIeVvq6jQAAAQA"]
[Thu Jul 30 14:04:26.890944 2026] [security2:error] [pid 977210:tid 977398] [client 191.232.199.39:39502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/alfa.php"] [unique_id "amugOvW1Jl2-fgIeVvq6jgAAAL0"]
[Thu Jul 30 14:04:26.965217 2026] [security2:error] [pid 977210:tid 977462] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/kq1.php"] [unique_id "amugOvW1Jl2-fgIeVvq6kAAAAP0"]
[Thu Jul 30 14:04:26.965300 2026] [security2:error] [pid 977210:tid 977462] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/kq1.php"] [unique_id "amugOvW1Jl2-fgIeVvq6kAAAAP0"]
[Thu Jul 30 14:04:27.279902 2026] [security2:error] [pid 977210:tid 977386] [client 20.91.199.21:12634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/geju.php"] [unique_id "amugO_W1Jl2-fgIeVvq6nAAAALE"]
[Thu Jul 30 14:04:27.354446 2026] [security2:error] [pid 977210:tid 977369] [client 20.100.187.246:24831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amugO_W1Jl2-fgIeVvq6nQAAAKA"]
[Thu Jul 30 14:04:27.448397 2026] [security2:error] [pid 977210:tid 977432] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fw/faiyy.php"] [unique_id "amugO_W1Jl2-fgIeVvq6nwAAAN8"]
[Thu Jul 30 14:04:27.448502 2026] [security2:error] [pid 977210:tid 977432] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fw/faiyy.php"] [unique_id "amugO_W1Jl2-fgIeVvq6nwAAAN8"]
[Thu Jul 30 14:04:27.514498 2026] [proxy:error] [pid 977210:tid 977365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:27.514585 2026] [proxy_http:error] [pid 977210:tid 977365] [client 54.87.222.253:2137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:27.515365 2026] [proxy:error] [pid 977210:tid 977365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:27.515417 2026] [proxy_http:error] [pid 977210:tid 977365] [client 54.87.222.253:2137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:27.521704 2026] [proxy:error] [pid 977210:tid 977358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:27.521787 2026] [proxy_http:error] [pid 977210:tid 977358] [client 52.202.41.153:32254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:27.522375 2026] [proxy:error] [pid 977210:tid 977358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:27.522422 2026] [proxy_http:error] [pid 977210:tid 977358] [client 52.202.41.153:32254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:27.697850 2026] [security2:error] [pid 977210:tid 977346] [client 158.158.41.78:25890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/maint/index.php"] [unique_id "amugO_W1Jl2-fgIeVvq6rgAAAIk"]
[Thu Jul 30 14:04:27.918520 2026] [core:error] [pid 977210:tid 977276] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:27.918548 2026] [core:error] [pid 977210:tid 977276] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:27.949225 2026] [security2:error] [pid 977210:tid 977422] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/h02ugyh.php"] [unique_id "amugO_W1Jl2-fgIeVvq6ugAAANU"]
[Thu Jul 30 14:04:27.949316 2026] [security2:error] [pid 977210:tid 977422] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/h02ugyh.php"] [unique_id "amugO_W1Jl2-fgIeVvq6ugAAANU"]
[Thu Jul 30 14:04:27.981683 2026] [security2:error] [pid 977210:tid 977411] [client 68.221.186.136:39634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/aafewc0k.php"] [unique_id "amugO_W1Jl2-fgIeVvq6uwAAAMo"]
[Thu Jul 30 14:04:28.273111 2026] [security2:error] [pid 977210:tid 977366] [client 20.100.187.246:24041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amugPPW1Jl2-fgIeVvq6xgAAAJ0"]
[Thu Jul 30 14:04:28.474426 2026] [security2:error] [pid 977210:tid 977408] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-temp.php"] [unique_id "amugPPW1Jl2-fgIeVvq60QAAAMc"]
[Thu Jul 30 14:04:28.474611 2026] [security2:error] [pid 977210:tid 977408] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-temp.php"] [unique_id "amugPPW1Jl2-fgIeVvq60QAAAMc"]
[Thu Jul 30 14:04:28.548255 2026] [core:error] [pid 977210:tid 977246] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:28.548279 2026] [core:error] [pid 977210:tid 977246] [remote 216.73.217.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:28.679831 2026] [security2:error] [pid 977210:tid 977361] [client 20.91.199.21:11454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amugPPW1Jl2-fgIeVvq62QAAAJg"]
[Thu Jul 30 14:04:28.830313 2026] [security2:error] [pid 977210:tid 977372] [client 191.232.199.39:49615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amugPPW1Jl2-fgIeVvq63QAAAKM"]
[Thu Jul 30 14:04:28.996942 2026] [security2:error] [pid 977210:tid 977353] [client 172.213.208.20:26741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/about.php"] [unique_id "amugPPW1Jl2-fgIeVvq67QAAAJA"]
[Thu Jul 30 14:04:29.016870 2026] [security2:error] [pid 977210:tid 977444] [client 178.156.189.113:53734] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amugO_W1Jl2-fgIeVvq6rAAAAOs"], referer: https://globalmarks.pk/
[Thu Jul 30 14:04:29.052650 2026] [security2:error] [pid 977210:tid 977373] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-content/cong.php"] [unique_id "amugPfW1Jl2-fgIeVvq67gAAAKQ"]
[Thu Jul 30 14:04:29.052903 2026] [security2:error] [pid 977210:tid 977373] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-content/cong.php"] [unique_id "amugPfW1Jl2-fgIeVvq67gAAAKQ"]
[Thu Jul 30 14:04:29.182801 2026] [security2:error] [pid 977210:tid 977406] [client 20.100.187.246:24060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amugPfW1Jl2-fgIeVvq68wAAAMU"]
[Thu Jul 30 14:04:29.604540 2026] [security2:error] [pid 977210:tid 977411] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/___proxy_subdomain_cpanel/wp-admin/js/widget/"] [unique_id "amugPfW1Jl2-fgIeVvq6-wAAAMo"]
[Thu Jul 30 14:04:29.869559 2026] [security2:error] [pid 977210:tid 977366] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-includes/css/index.php"] [unique_id "amugPfW1Jl2-fgIeVvq7BgAAAJ0"]
[Thu Jul 30 14:04:29.869729 2026] [security2:error] [pid 977210:tid 977366] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-includes/css/index.php"] [unique_id "amugPfW1Jl2-fgIeVvq7BgAAAJ0"]
[Thu Jul 30 14:04:30.142164 2026] [security2:error] [pid 977210:tid 977281] [remote 103.75.185.95:51700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/wp-login.php"] [unique_id "amugPvW1Jl2-fgIeVvq7EQAA6EQ"]
[Thu Jul 30 14:04:30.160785 2026] [security2:error] [pid 977210:tid 977439] [client 191.232.199.39:9445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amugPvW1Jl2-fgIeVvq7EgAAAOY"]
[Thu Jul 30 14:04:30.174840 2026] [security2:error] [pid 977210:tid 977429] [client 172.213.208.20:40359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/options.php"] [unique_id "amugPvW1Jl2-fgIeVvq7EwAAANw"]
[Thu Jul 30 14:04:30.279209 2026] [security2:error] [pid 977210:tid 977273] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugPvW1Jl2-fgIeVvq7GQAA4jw"]
[Thu Jul 30 14:04:30.279353 2026] [security2:error] [pid 977210:tid 977435] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugPvW1Jl2-fgIeVvq7GQAA4jw"]
[Thu Jul 30 14:04:30.375131 2026] [security2:error] [pid 977210:tid 977342] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/jj.php"] [unique_id "amugPvW1Jl2-fgIeVvq7HQAAAIU"]
[Thu Jul 30 14:04:30.375236 2026] [security2:error] [pid 977210:tid 977342] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/jj.php"] [unique_id "amugPvW1Jl2-fgIeVvq7HQAAAIU"]
[Thu Jul 30 14:04:30.646150 2026] [security2:error] [pid 977210:tid 977384] [client 158.158.41.78:29139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/alfa.php"] [unique_id "amugPvW1Jl2-fgIeVvq7JAAAAK8"]
[Thu Jul 30 14:04:30.759481 2026] [autoindex:error] [pid 977210:tid 977353] [client 52.202.41.153:31504] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:04:30.783200 2026] [security2:error] [pid 977210:tid 977369] [client 68.221.186.136:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/abcd.php"] [unique_id "amugPvW1Jl2-fgIeVvq7KQAAAKA"]
[Thu Jul 30 14:04:30.811801 2026] [autoindex:error] [pid 977210:tid 977396] [client 54.87.222.253:33024] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:04:30.912880 2026] [security2:error] [pid 977210:tid 977426] [client 85.208.96.193:32252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/05/21/api-realiza-assembleia-extraordinaria-neste-sabado-para-convocar-eleicoes/"] [unique_id "amugPvW1Jl2-fgIeVvq7MwAAANk"]
[Thu Jul 30 14:04:30.913053 2026] [security2:error] [pid 977210:tid 977426] [client 85.208.96.193:32252] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/05/21/api-realiza-assembleia-extraordinaria-neste-sabado-para-convocar-eleicoes/"] [unique_id "amugPvW1Jl2-fgIeVvq7MwAAANk"]
[Thu Jul 30 14:04:30.937552 2026] [security2:error] [pid 977210:tid 977415] [client 172.213.208.20:40338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/index.php"] [unique_id "amugPvW1Jl2-fgIeVvq7NAAAAM4"]
[Thu Jul 30 14:04:30.953286 2026] [security2:error] [pid 977210:tid 977469] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/class-walker-footer-dev.php"] [unique_id "amugPvW1Jl2-fgIeVvq7NQAAAQQ"]
[Thu Jul 30 14:04:30.953375 2026] [security2:error] [pid 977210:tid 977469] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/class-walker-footer-dev.php"] [unique_id "amugPvW1Jl2-fgIeVvq7NQAAAQQ"]
[Thu Jul 30 14:04:31.070878 2026] [core:notice] [pid 977210:tid 977456] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:31.217582 2026] [security2:error] [pid 977210:tid 977423] [client 189.6.88.213:50433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugP_W1Jl2-fgIeVvq7OwAAANY"]
[Thu Jul 30 14:04:31.217687 2026] [security2:error] [pid 977210:tid 977423] [client 189.6.88.213:50433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugP_W1Jl2-fgIeVvq7OwAAANY"]
[Thu Jul 30 14:04:31.496443 2026] [security2:error] [pid 977210:tid 977408] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xpwer1.php"] [unique_id "amugP_W1Jl2-fgIeVvq7RgAAAMc"]
[Thu Jul 30 14:04:31.496590 2026] [security2:error] [pid 977210:tid 977408] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xpwer1.php"] [unique_id "amugP_W1Jl2-fgIeVvq7RgAAAMc"]
[Thu Jul 30 14:04:31.528007 2026] [security2:error] [pid 977210:tid 977351] [client 158.158.41.78:31709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amugP_W1Jl2-fgIeVvq7SQAAAI4"]
[Thu Jul 30 14:04:31.760879 2026] [security2:error] [pid 977210:tid 977370] [client 20.91.199.21:41069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp.php"] [unique_id "amugP_W1Jl2-fgIeVvq7TQAAAKE"]
[Thu Jul 30 14:04:31.783499 2026] [core:notice] [pid 977210:tid 977429] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:32.005424 2026] [security2:error] [pid 977210:tid 977344] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/flox.php"] [unique_id "amugQPW1Jl2-fgIeVvq7VwAAAIc"]
[Thu Jul 30 14:04:32.005535 2026] [security2:error] [pid 977210:tid 977344] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/flox.php"] [unique_id "amugQPW1Jl2-fgIeVvq7VwAAAIc"]
[Thu Jul 30 14:04:32.157526 2026] [security2:error] [pid 977210:tid 977381] [client 191.232.199.39:9433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amugQPW1Jl2-fgIeVvq7XgAAAKw"]
[Thu Jul 30 14:04:32.185100 2026] [security2:error] [pid 977210:tid 977342] [client 172.213.208.20:13628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-file.php"] [unique_id "amugQPW1Jl2-fgIeVvq7XwAAAIU"]
[Thu Jul 30 14:04:32.547079 2026] [security2:error] [pid 977210:tid 977447] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/popo.php"] [unique_id "amugQPW1Jl2-fgIeVvq7dQAAAO4"]
[Thu Jul 30 14:04:32.547196 2026] [security2:error] [pid 977210:tid 977447] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/popo.php"] [unique_id "amugQPW1Jl2-fgIeVvq7dQAAAO4"]
[Thu Jul 30 14:04:32.732942 2026] [security2:error] [pid 977210:tid 977469] [client 68.221.186.136:23397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/about.php"] [unique_id "amugQPW1Jl2-fgIeVvq7jwAAAQQ"]
[Thu Jul 30 14:04:32.968045 2026] [security2:error] [pid 977210:tid 977416] [client 103.190.40.154:17498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugQPW1Jl2-fgIeVvq7pgAAAM8"]
[Thu Jul 30 14:04:32.968201 2026] [security2:error] [pid 977210:tid 977416] [client 103.190.40.154:17498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugQPW1Jl2-fgIeVvq7pgAAAM8"]
[Thu Jul 30 14:04:33.062854 2026] [security2:error] [pid 977210:tid 977350] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/yas.php"] [unique_id "amugQfW1Jl2-fgIeVvq7pwAAAI0"]
[Thu Jul 30 14:04:33.063035 2026] [security2:error] [pid 977210:tid 977350] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/yas.php"] [unique_id "amugQfW1Jl2-fgIeVvq7pwAAAI0"]
[Thu Jul 30 14:04:33.426123 2026] [core:notice] [pid 977210:tid 977296] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:33.496321 2026] [security2:error] [pid 977210:tid 977442] [client 20.91.199.21:3828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/aaa.php"] [unique_id "amugQfW1Jl2-fgIeVvq7uQAAAOk"]
[Thu Jul 30 14:04:33.601735 2026] [security2:error] [pid 977210:tid 977384] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/water.php"] [unique_id "amugQfW1Jl2-fgIeVvq7uwAAAK8"]
[Thu Jul 30 14:04:33.601869 2026] [security2:error] [pid 977210:tid 977384] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/water.php"] [unique_id "amugQfW1Jl2-fgIeVvq7uwAAAK8"]
[Thu Jul 30 14:04:33.724857 2026] [autoindex:error] [pid 977210:tid 977373] [client 98.87.102.177:1517] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:04:33.762461 2026] [autoindex:error] [pid 977210:tid 977382] [client 18.211.55.47:55695] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:04:34.112738 2026] [security2:error] [pid 977210:tid 977446] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/nano.php"] [unique_id "amugQvW1Jl2-fgIeVvq7ygAAAO0"]
[Thu Jul 30 14:04:34.112855 2026] [security2:error] [pid 977210:tid 977446] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/nano.php"] [unique_id "amugQvW1Jl2-fgIeVvq7ygAAAO0"]
[Thu Jul 30 14:04:34.511548 2026] [security2:error] [pid 977210:tid 977469] [client 158.158.41.78:17195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amugQvW1Jl2-fgIeVvq71wAAAQQ"]
[Thu Jul 30 14:04:34.627953 2026] [security2:error] [pid 977210:tid 977378] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/moon.php"] [unique_id "amugQvW1Jl2-fgIeVvq72AAAAKk"]
[Thu Jul 30 14:04:34.628087 2026] [security2:error] [pid 977210:tid 977378] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/moon.php"] [unique_id "amugQvW1Jl2-fgIeVvq72AAAAKk"]
[Thu Jul 30 14:04:34.862139 2026] [security2:error] [pid 977210:tid 977392] [client 20.91.199.21:41255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/hoot.php"] [unique_id "amugQvW1Jl2-fgIeVvq73QAAALc"]
[Thu Jul 30 14:04:34.949078 2026] [security2:error] [pid 977210:tid 977391] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amugQvW1Jl2-fgIeVvq74gAAALY"]
[Thu Jul 30 14:04:34.949209 2026] [security2:error] [pid 977210:tid 977391] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amugQvW1Jl2-fgIeVvq74gAAALY"]
[Thu Jul 30 14:04:35.099487 2026] [security2:error] [pid 977210:tid 977399] [client 68.221.186.136:37217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/admin.php"] [unique_id "amugQ_W1Jl2-fgIeVvq75wAAAL4"]
[Thu Jul 30 14:04:35.148765 2026] [security2:error] [pid 977210:tid 977369] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-info.php"] [unique_id "amugQ_W1Jl2-fgIeVvq76AAAAKA"]
[Thu Jul 30 14:04:35.148861 2026] [security2:error] [pid 977210:tid 977369] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-info.php"] [unique_id "amugQ_W1Jl2-fgIeVvq76AAAAKA"]
[Thu Jul 30 14:04:35.208726 2026] [core:notice] [pid 977210:tid 977288] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:35.271598 2026] [security2:error] [pid 977210:tid 977466] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amugQ_W1Jl2-fgIeVvq76gAAAQE"]
[Thu Jul 30 14:04:35.271711 2026] [security2:error] [pid 977210:tid 977466] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amugQ_W1Jl2-fgIeVvq76gAAAQE"]
[Thu Jul 30 14:04:35.448525 2026] [security2:error] [pid 977210:tid 977424] [client 172.213.208.20:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/sid3.php"] [unique_id "amugQ_W1Jl2-fgIeVvq78gAAANc"]
[Thu Jul 30 14:04:35.554019 2026] [security2:error] [pid 977210:tid 977380] [client 181.116.200.68:53235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugQ_W1Jl2-fgIeVvq7-QAAAKs"]
[Thu Jul 30 14:04:35.554170 2026] [security2:error] [pid 977210:tid 977380] [client 181.116.200.68:53235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugQ_W1Jl2-fgIeVvq7-QAAAKs"]
[Thu Jul 30 14:04:35.587208 2026] [security2:error] [pid 977210:tid 977448] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/3PJcpMFsD8B.php"] [unique_id "amugQ_W1Jl2-fgIeVvq7-gAAAO8"]
[Thu Jul 30 14:04:35.587312 2026] [security2:error] [pid 977210:tid 977448] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/3PJcpMFsD8B.php"] [unique_id "amugQ_W1Jl2-fgIeVvq7-gAAAO8"]
[Thu Jul 30 14:04:35.644232 2026] [security2:error] [pid 977210:tid 977416] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/file5.php"] [unique_id "amugQ_W1Jl2-fgIeVvq7-wAAAM8"]
[Thu Jul 30 14:04:35.644382 2026] [security2:error] [pid 977210:tid 977416] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/file5.php"] [unique_id "amugQ_W1Jl2-fgIeVvq7-wAAAM8"]
[Thu Jul 30 14:04:35.834623 2026] [security2:error] [pid 977210:tid 977440] [client 158.158.41.78:51035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amugQ_W1Jl2-fgIeVvq7_wAAAOc"]
[Thu Jul 30 14:04:35.879056 2026] [security2:error] [pid 977210:tid 977449] [client 20.91.199.21:8582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/about.php"] [unique_id "amugQ_W1Jl2-fgIeVvq8AAAAAPA"]
[Thu Jul 30 14:04:35.933212 2026] [security2:error] [pid 977210:tid 977370] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/err.php"] [unique_id "amugQ_W1Jl2-fgIeVvq8AgAAAKE"]
[Thu Jul 30 14:04:35.933332 2026] [security2:error] [pid 977210:tid 977370] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/err.php"] [unique_id "amugQ_W1Jl2-fgIeVvq8AgAAAKE"]
[Thu Jul 30 14:04:35.947136 2026] [security2:error] [pid 977210:tid 977465] [client 103.231.91.59:49758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugQ_W1Jl2-fgIeVvq8AwAAAQA"]
[Thu Jul 30 14:04:35.947229 2026] [security2:error] [pid 977210:tid 977465] [client 103.231.91.59:49758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugQ_W1Jl2-fgIeVvq8AwAAAQA"]
[Thu Jul 30 14:04:36.140821 2026] [security2:error] [pid 977210:tid 977394] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugQ_W1Jl2-fgIeVvq79wAAuVc"]
[Thu Jul 30 14:04:36.154081 2026] [security2:error] [pid 977210:tid 977390] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/2000.php"] [unique_id "amugRPW1Jl2-fgIeVvq8CwAAALU"]
[Thu Jul 30 14:04:36.154179 2026] [security2:error] [pid 977210:tid 977390] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/2000.php"] [unique_id "amugRPW1Jl2-fgIeVvq8CwAAALU"]
[Thu Jul 30 14:04:36.236214 2026] [security2:error] [pid 977210:tid 977442] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/img.php"] [unique_id "amugRPW1Jl2-fgIeVvq8DAAAAOk"]
[Thu Jul 30 14:04:36.236320 2026] [security2:error] [pid 977210:tid 977442] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/img.php"] [unique_id "amugRPW1Jl2-fgIeVvq8DAAAAOk"]
[Thu Jul 30 14:04:36.405535 2026] [security2:error] [pid 977210:tid 977232] [remote 57.141.0.35:38310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7374488921/feed/rss2/"] [unique_id "amugRPW1Jl2-fgIeVvq8EAAAuhM"]
[Thu Jul 30 14:04:36.456055 2026] [security2:error] [pid 977210:tid 977398] [client 20.100.187.246:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amugRPW1Jl2-fgIeVvq8EgAAAL0"]
[Thu Jul 30 14:04:36.462506 2026] [security2:error] [pid 977210:tid 977461] [client 172.213.208.20:16728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/themes.php"] [unique_id "amugRPW1Jl2-fgIeVvq8EwAAAPw"]
[Thu Jul 30 14:04:36.553953 2026] [security2:error] [pid 977210:tid 977466] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/aa.php"] [unique_id "amugRPW1Jl2-fgIeVvq8GAAAAQE"]
[Thu Jul 30 14:04:36.554059 2026] [security2:error] [pid 977210:tid 977466] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/aa.php"] [unique_id "amugRPW1Jl2-fgIeVvq8GAAAAQE"]
[Thu Jul 30 14:04:36.648380 2026] [security2:error] [pid 977210:tid 977418] [client 191.232.199.39:9467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/edit.php"] [unique_id "amugRPW1Jl2-fgIeVvq8HQAAANE"]
[Thu Jul 30 14:04:36.648718 2026] [security2:error] [pid 977210:tid 977388] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/122.php"] [unique_id "amugRPW1Jl2-fgIeVvq8HgAAALM"]
[Thu Jul 30 14:04:36.648788 2026] [security2:error] [pid 977210:tid 977388] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/122.php"] [unique_id "amugRPW1Jl2-fgIeVvq8HgAAALM"]
[Thu Jul 30 14:04:36.759999 2026] [security2:error] [pid 977210:tid 977358] [client 103.242.199.184:53718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugRPW1Jl2-fgIeVvq8HwAAAJU"]
[Thu Jul 30 14:04:36.760718 2026] [security2:error] [pid 977210:tid 977358] [client 103.242.199.184:53718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugRPW1Jl2-fgIeVvq8HwAAAJU"]
[Thu Jul 30 14:04:36.796778 2026] [security2:error] [pid 977210:tid 977409] [client 68.221.186.136:37761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/adminfuns.php"] [unique_id "amugRPW1Jl2-fgIeVvq8IAAAAMg"]
[Thu Jul 30 14:04:36.855862 2026] [security2:error] [pid 977210:tid 977426] [client 193.47.62.167:59426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.kii.nyx.temporary.site"] [uri "/index.php"] [unique_id "amugQ_W1Jl2-fgIeVvq76wAAANk"]
[Thu Jul 30 14:04:36.875490 2026] [security2:error] [pid 977210:tid 977397] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/av.php"] [unique_id "amugRPW1Jl2-fgIeVvq8JAAAALw"]
[Thu Jul 30 14:04:36.875614 2026] [security2:error] [pid 977210:tid 977397] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/av.php"] [unique_id "amugRPW1Jl2-fgIeVvq8JAAAALw"]
[Thu Jul 30 14:04:37.143414 2026] [security2:error] [pid 977210:tid 977435] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/mds.php"] [unique_id "amugRfW1Jl2-fgIeVvq8MAAAAOI"]
[Thu Jul 30 14:04:37.143511 2026] [security2:error] [pid 977210:tid 977435] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/mds.php"] [unique_id "amugRfW1Jl2-fgIeVvq8MAAAAOI"]
[Thu Jul 30 14:04:37.188082 2026] [security2:error] [pid 977210:tid 977378] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/xa.php"] [unique_id "amugRfW1Jl2-fgIeVvq8MQAAAKk"]
[Thu Jul 30 14:04:37.188169 2026] [security2:error] [pid 977210:tid 977378] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/xa.php"] [unique_id "amugRfW1Jl2-fgIeVvq8MQAAAKk"]
[Thu Jul 30 14:04:37.488945 2026] [security2:error] [pid 977210:tid 977345] [client 172.213.208.20:16539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/index.php"] [unique_id "amugRfW1Jl2-fgIeVvq8NQAAAIg"]
[Thu Jul 30 14:04:37.507954 2026] [security2:error] [pid 977210:tid 977427] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/media.php"] [unique_id "amugRfW1Jl2-fgIeVvq8NgAAANo"]
[Thu Jul 30 14:04:37.508125 2026] [security2:error] [pid 977210:tid 977427] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/media.php"] [unique_id "amugRfW1Jl2-fgIeVvq8NgAAANo"]
[Thu Jul 30 14:04:37.595108 2026] [security2:error] [pid 977210:tid 977419] [client 20.100.187.246:24034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amugRfW1Jl2-fgIeVvq8OAAAANI"]
[Thu Jul 30 14:04:37.631704 2026] [security2:error] [pid 977210:tid 977432] [client 20.91.199.21:41254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/admin.php"] [unique_id "amugRfW1Jl2-fgIeVvq8OQAAAN8"]
[Thu Jul 30 14:04:37.674554 2026] [security2:error] [pid 977210:tid 977354] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/zc-208.php"] [unique_id "amugRfW1Jl2-fgIeVvq8OgAAAJE"]
[Thu Jul 30 14:04:37.674651 2026] [security2:error] [pid 977210:tid 977354] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/zc-208.php"] [unique_id "amugRfW1Jl2-fgIeVvq8OgAAAJE"]
[Thu Jul 30 14:04:37.822634 2026] [security2:error] [pid 977210:tid 977396] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/images.php"] [unique_id "amugRfW1Jl2-fgIeVvq8QgAAALs"]
[Thu Jul 30 14:04:37.822735 2026] [security2:error] [pid 977210:tid 977396] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/images.php"] [unique_id "amugRfW1Jl2-fgIeVvq8QgAAALs"]
[Thu Jul 30 14:04:37.929781 2026] [security2:error] [pid 977210:tid 977464] [client 74.7.230.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.frontierphoenix.site"] [uri "/index.php"] [unique_id "amugRPW1Jl2-fgIeVvq8KAAAAP8"]
[Thu Jul 30 14:04:37.930635 2026] [security2:error] [pid 977210:tid 977447] [client 74.7.230.51:46082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.frontierphoenix.site"] [uri "/robots.txt"] [unique_id "amugRPW1Jl2-fgIeVvq8JgAA7kg"]
[Thu Jul 30 14:04:38.073946 2026] [security2:error] [pid 977210:tid 977425] [client 68.221.186.136:37771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/albin.php"] [unique_id "amugRvW1Jl2-fgIeVvq8SAAAANg"]
[Thu Jul 30 14:04:38.083707 2026] [security2:error] [pid 977210:tid 977448] [client 158.158.41.78:25906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/edit.php"] [unique_id "amugRvW1Jl2-fgIeVvq8SwAAAO8"]
[Thu Jul 30 14:04:38.140722 2026] [security2:error] [pid 977210:tid 977422] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/gecko.php"] [unique_id "amugRvW1Jl2-fgIeVvq8TgAAANU"]
[Thu Jul 30 14:04:38.140805 2026] [security2:error] [pid 977210:tid 977422] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/gecko.php"] [unique_id "amugRvW1Jl2-fgIeVvq8TgAAANU"]
[Thu Jul 30 14:04:38.203495 2026] [security2:error] [pid 977210:tid 977411] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sid4.php"] [unique_id "amugRvW1Jl2-fgIeVvq8UAAAAMo"]
[Thu Jul 30 14:04:38.203597 2026] [security2:error] [pid 977210:tid 977411] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sid4.php"] [unique_id "amugRvW1Jl2-fgIeVvq8UAAAAMo"]
[Thu Jul 30 14:04:38.374094 2026] [security2:error] [pid 977210:tid 977421] [client 20.91.199.21:41042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amugRvW1Jl2-fgIeVvq8VQAAANQ"]
[Thu Jul 30 14:04:38.436321 2026] [security2:error] [pid 977210:tid 977423] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/82.php"] [unique_id "amugRvW1Jl2-fgIeVvq8VgAAANY"]
[Thu Jul 30 14:04:38.436435 2026] [security2:error] [pid 977210:tid 977423] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/82.php"] [unique_id "amugRvW1Jl2-fgIeVvq8VgAAANY"]
[Thu Jul 30 14:04:38.753365 2026] [security2:error] [pid 977210:tid 977404] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/___proxy_subdomain_cpanel/wp-includes/l10n/"] [unique_id "amugRvW1Jl2-fgIeVvq8agAAAMM"]
[Thu Jul 30 14:04:38.776468 2026] [security2:error] [pid 977210:tid 977408] [client 74.7.228.38:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "frontierphoenix.site"] [uri "/index.php"] [unique_id "amugRvW1Jl2-fgIeVvq8aAAAx3Y"]
[Thu Jul 30 14:04:38.785951 2026] [security2:error] [pid 977210:tid 977434] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/xstelth.php"] [unique_id "amugRvW1Jl2-fgIeVvq8bwAAAOE"]
[Thu Jul 30 14:04:38.786060 2026] [security2:error] [pid 977210:tid 977434] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/xstelth.php"] [unique_id "amugRvW1Jl2-fgIeVvq8bwAAAOE"]
[Thu Jul 30 14:04:39.016364 2026] [security2:error] [pid 977210:tid 977442] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wmore1.php"] [unique_id "amugR_W1Jl2-fgIeVvq8dAAAAOk"]
[Thu Jul 30 14:04:39.016463 2026] [security2:error] [pid 977210:tid 977442] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wmore1.php"] [unique_id "amugR_W1Jl2-fgIeVvq8dAAAAOk"]
[Thu Jul 30 14:04:39.084859 2026] [security2:error] [pid 977210:tid 977396] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/xp.php"] [unique_id "amugR_W1Jl2-fgIeVvq8dQAAALs"]
[Thu Jul 30 14:04:39.084956 2026] [security2:error] [pid 977210:tid 977396] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/xp.php"] [unique_id "amugR_W1Jl2-fgIeVvq8dQAAALs"]
[Thu Jul 30 14:04:39.124645 2026] [security2:error] [pid 977210:tid 977362] [client 191.232.199.39:38820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/sf.php"] [unique_id "amugR_W1Jl2-fgIeVvq8eAAAAJk"]
[Thu Jul 30 14:04:39.148163 2026] [security2:error] [pid 977210:tid 977369] [client 158.158.41.78:25863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/file5.php"] [unique_id "amugR_W1Jl2-fgIeVvq8ewAAAKA"]
[Thu Jul 30 14:04:39.418171 2026] [security2:error] [pid 977210:tid 977458] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/admin.php"] [unique_id "amugR_W1Jl2-fgIeVvq8fwAAAPk"]
[Thu Jul 30 14:04:39.418301 2026] [security2:error] [pid 977210:tid 977458] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/admin.php"] [unique_id "amugR_W1Jl2-fgIeVvq8fwAAAPk"]
[Thu Jul 30 14:04:39.500957 2026] [security2:error] [pid 977210:tid 977363] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/solo1.php"] [unique_id "amugR_W1Jl2-fgIeVvq8gAAAAJo"]
[Thu Jul 30 14:04:39.501072 2026] [security2:error] [pid 977210:tid 977363] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/solo1.php"] [unique_id "amugR_W1Jl2-fgIeVvq8gAAAAJo"]
[Thu Jul 30 14:04:39.593493 2026] [security2:error] [pid 977210:tid 977466] [client 20.91.199.21:18535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/db-cache.php"] [unique_id "amugR_W1Jl2-fgIeVvq8hwAAAQE"]
[Thu Jul 30 14:04:39.673972 2026] [core:error] [pid 977210:tid 977379] [client 172.213.208.20:38296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:39.674006 2026] [core:error] [pid 977210:tid 977379] [client 172.213.208.20:38296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:39.763205 2026] [security2:error] [pid 977210:tid 977405] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/adminner.php"] [unique_id "amugR_W1Jl2-fgIeVvq8jAAAAMQ"]
[Thu Jul 30 14:04:39.763307 2026] [security2:error] [pid 977210:tid 977405] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/adminner.php"] [unique_id "amugR_W1Jl2-fgIeVvq8jAAAAMQ"]
[Thu Jul 30 14:04:40.023355 2026] [security2:error] [pid 977210:tid 977347] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/___proxy_subdomain_cpanel/wp-includes/assets/"] [unique_id "amugR_W1Jl2-fgIeVvq8kQAAAIo"]
[Thu Jul 30 14:04:40.112456 2026] [security2:error] [pid 977210:tid 977355] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/a.php"] [unique_id "amugSPW1Jl2-fgIeVvq8lgAAAJI"]
[Thu Jul 30 14:04:40.112553 2026] [security2:error] [pid 977210:tid 977355] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/a.php"] [unique_id "amugSPW1Jl2-fgIeVvq8lgAAAJI"]
[Thu Jul 30 14:04:40.315084 2026] [security2:error] [pid 977210:tid 977374] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/___proxy_subdomain_cpanel/wp-includes/css/"] [unique_id "amugSPW1Jl2-fgIeVvq8ngAAAKU"]
[Thu Jul 30 14:04:40.409886 2026] [security2:error] [pid 977210:tid 977421] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugR_W1Jl2-fgIeVvq8kAAAANQ"]
[Thu Jul 30 14:04:40.441901 2026] [security2:error] [pid 977210:tid 977437] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/k.php"] [unique_id "amugSPW1Jl2-fgIeVvq8nwAAAOQ"]
[Thu Jul 30 14:04:40.442058 2026] [security2:error] [pid 977210:tid 977437] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/k.php"] [unique_id "amugSPW1Jl2-fgIeVvq8nwAAAOQ"]
[Thu Jul 30 14:04:40.574799 2026] [security2:error] [pid 977210:tid 977345] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/public/css.php"] [unique_id "amugSPW1Jl2-fgIeVvq8pQAAAIg"]
[Thu Jul 30 14:04:40.574909 2026] [security2:error] [pid 977210:tid 977345] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/public/css.php"] [unique_id "amugSPW1Jl2-fgIeVvq8pQAAAIg"]
[Thu Jul 30 14:04:40.676757 2026] [security2:error] [pid 977210:tid 977410] [client 20.91.199.21:15929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amugSPW1Jl2-fgIeVvq8pwAAAMk"]
[Thu Jul 30 14:04:40.776621 2026] [security2:error] [pid 977210:tid 977442] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/222.php"] [unique_id "amugSPW1Jl2-fgIeVvq8qwAAAOk"]
[Thu Jul 30 14:04:40.776728 2026] [security2:error] [pid 977210:tid 977442] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/222.php"] [unique_id "amugSPW1Jl2-fgIeVvq8qwAAAOk"]
[Thu Jul 30 14:04:40.879007 2026] [security2:error] [pid 977210:tid 977218] [remote 57.141.0.10:22892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6164509415/feed/rss2/"] [unique_id "amugSPW1Jl2-fgIeVvq8pgAA3AU"]
[Thu Jul 30 14:04:40.883201 2026] [security2:error] [pid 977210:tid 977398] [client 191.232.199.39:38829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wso.php"] [unique_id "amugSPW1Jl2-fgIeVvq8sAAAAL0"]
[Thu Jul 30 14:04:41.078361 2026] [security2:error] [pid 977210:tid 977381] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/output.php"] [unique_id "amugSfW1Jl2-fgIeVvq8sQAAAKw"]
[Thu Jul 30 14:04:41.078480 2026] [security2:error] [pid 977210:tid 977381] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/output.php"] [unique_id "amugSfW1Jl2-fgIeVvq8sQAAAKw"]
[Thu Jul 30 14:04:41.096930 2026] [security2:error] [pid 977210:tid 977373] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/mac.php"] [unique_id "amugSfW1Jl2-fgIeVvq8tAAAAKQ"]
[Thu Jul 30 14:04:41.097065 2026] [security2:error] [pid 977210:tid 977373] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/mac.php"] [unique_id "amugSfW1Jl2-fgIeVvq8tAAAAKQ"]
[Thu Jul 30 14:04:41.496456 2026] [security2:error] [pid 977210:tid 977441] [client 20.91.199.21:18527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amugSfW1Jl2-fgIeVvq8vQAAAOg"]
[Thu Jul 30 14:04:41.531407 2026] [security2:error] [pid 977210:tid 977359] [client 68.221.186.136:33732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/amfsqvgv.php"] [unique_id "amugSfW1Jl2-fgIeVvq8vgAAAJY"]
[Thu Jul 30 14:04:41.569921 2026] [security2:error] [pid 977210:tid 977358] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-file-120.php"] [unique_id "amugSfW1Jl2-fgIeVvq8wAAAAJU"]
[Thu Jul 30 14:04:41.570018 2026] [security2:error] [pid 977210:tid 977358] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-file-120.php"] [unique_id "amugSfW1Jl2-fgIeVvq8wAAAAJU"]
[Thu Jul 30 14:04:41.599966 2026] [proxy:error] [pid 977210:tid 977360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:41.600068 2026] [proxy_http:error] [pid 977210:tid 977360] [client 34.224.175.62:26542] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:41.600639 2026] [proxy:error] [pid 977210:tid 977360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:41.600682 2026] [proxy_http:error] [pid 977210:tid 977360] [client 34.224.175.62:26542] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:41.622813 2026] [proxy:error] [pid 977210:tid 977417] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:41.622880 2026] [proxy_http:error] [pid 977210:tid 977417] [client 32.194.121.99:64347] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:41.623453 2026] [proxy:error] [pid 977210:tid 977417] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:41.623502 2026] [proxy_http:error] [pid 977210:tid 977417] [client 32.194.121.99:64347] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:41.762733 2026] [security2:error] [pid 977210:tid 977416] [client 158.158.41.78:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/sf.php"] [unique_id "amugSfW1Jl2-fgIeVvq80wAAAM8"]
[Thu Jul 30 14:04:41.785019 2026] [proxy:error] [pid 977210:tid 977460] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:41.785085 2026] [proxy_http:error] [pid 977210:tid 977460] [client 4.225.166.222:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:41.785697 2026] [proxy:error] [pid 977210:tid 977460] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:41.785741 2026] [proxy_http:error] [pid 977210:tid 977460] [client 4.225.166.222:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:41.785828 2026] [security2:error] [pid 977210:tid 977460] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amugSfW1Jl2-fgIeVvq81wAAAPs"]
[Thu Jul 30 14:04:42.059407 2026] [security2:error] [pid 977210:tid 977390] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/special.php"] [unique_id "amugSvW1Jl2-fgIeVvq83gAAALU"]
[Thu Jul 30 14:04:42.059553 2026] [security2:error] [pid 977210:tid 977390] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/special.php"] [unique_id "amugSvW1Jl2-fgIeVvq83gAAALU"]
[Thu Jul 30 14:04:42.062829 2026] [security2:error] [pid 977210:tid 977469] [client 189.6.88.213:50992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugSvW1Jl2-fgIeVvq83wAAAQQ"]
[Thu Jul 30 14:04:42.062933 2026] [security2:error] [pid 977210:tid 977469] [client 189.6.88.213:50992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugSvW1Jl2-fgIeVvq83wAAAQQ"]
[Thu Jul 30 14:04:42.113950 2026] [proxy:error] [pid 977210:tid 977354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:42.114025 2026] [proxy_http:error] [pid 977210:tid 977354] [client 4.225.166.222:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:42.114582 2026] [proxy:error] [pid 977210:tid 977354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:42.114624 2026] [proxy_http:error] [pid 977210:tid 977354] [client 4.225.166.222:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:42.114705 2026] [security2:error] [pid 977210:tid 977354] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amugSvW1Jl2-fgIeVvq84QAAAJE"]
[Thu Jul 30 14:04:42.288050 2026] [security2:error] [pid 977210:tid 977437] [client 191.232.199.39:38789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/ioxi-o.php"] [unique_id "amugSvW1Jl2-fgIeVvq85wAAAOQ"]
[Thu Jul 30 14:04:42.412971 2026] [security2:error] [pid 977210:tid 977382] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/ops.php"] [unique_id "amugSvW1Jl2-fgIeVvq88AAAAK0"]
[Thu Jul 30 14:04:42.413082 2026] [security2:error] [pid 977210:tid 977382] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/ops.php"] [unique_id "amugSvW1Jl2-fgIeVvq88AAAAK0"]
[Thu Jul 30 14:04:42.578120 2026] [security2:error] [pid 977210:tid 977363] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/as.php"] [unique_id "amugSvW1Jl2-fgIeVvq88QAAAJo"]
[Thu Jul 30 14:04:42.578236 2026] [security2:error] [pid 977210:tid 977363] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/as.php"] [unique_id "amugSvW1Jl2-fgIeVvq88QAAAJo"]
[Thu Jul 30 14:04:42.626602 2026] [security2:error] [pid 977210:tid 977455] [client 20.91.199.21:41053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amugSvW1Jl2-fgIeVvq89AAAAPY"]
[Thu Jul 30 14:04:42.726876 2026] [security2:error] [pid 977210:tid 977454] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/8.php"] [unique_id "amugSvW1Jl2-fgIeVvq8-QAAAPU"]
[Thu Jul 30 14:04:42.727003 2026] [security2:error] [pid 977210:tid 977454] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/8.php"] [unique_id "amugSvW1Jl2-fgIeVvq8-QAAAPU"]
[Thu Jul 30 14:04:42.799117 2026] [security2:error] [pid 977210:tid 977372] [client 158.158.41.78:31322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wso.php"] [unique_id "amugSvW1Jl2-fgIeVvq8_wAAAKM"]
[Thu Jul 30 14:04:42.939431 2026] [security2:error] [pid 977210:tid 977422] [client 222.253.98.164:53739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugSvW1Jl2-fgIeVvq88gAAANU"], referer: http://pkf.jo
[Thu Jul 30 14:04:42.952199 2026] [security2:error] [pid 977210:tid 977444] [client 123.28.186.169:44072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugSvW1Jl2-fgIeVvq88wAAAOs"], referer: http://pkf.jo
[Thu Jul 30 14:04:43.022996 2026] [security2:error] [pid 977210:tid 977456] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/FWAZ.php"] [unique_id "amugS_W1Jl2-fgIeVvq9BgAAAPc"]
[Thu Jul 30 14:04:43.023109 2026] [security2:error] [pid 977210:tid 977456] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/FWAZ.php"] [unique_id "amugS_W1Jl2-fgIeVvq9BgAAAPc"]
[Thu Jul 30 14:04:43.130942 2026] [core:notice] [pid 977210:tid 977409] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:43.136111 2026] [security2:error] [pid 977210:tid 977435] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/cgi-bin/index.php"] [unique_id "amugS_W1Jl2-fgIeVvq9CQAAAOI"]
[Thu Jul 30 14:04:43.136206 2026] [security2:error] [pid 977210:tid 977435] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/cgi-bin/index.php"] [unique_id "amugS_W1Jl2-fgIeVvq9CQAAAOI"]
[Thu Jul 30 14:04:43.337420 2026] [security2:error] [pid 977210:tid 977405] [client 14.229.214.33:41154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugSvW1Jl2-fgIeVvq8_QAAAMQ"], referer: http://pkf.jo
[Thu Jul 30 14:04:43.623705 2026] [security2:error] [pid 977210:tid 977364] [client 149.76.69.84:1027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amugS_W1Jl2-fgIeVvq9FgAAm2I"], referer: https://jwcpartners.org/wp-admin/update-core.php?action=do-plugin-upgrade
[Thu Jul 30 14:04:43.649741 2026] [security2:error] [pid 977210:tid 977390] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/w1px.php"] [unique_id "amugS_W1Jl2-fgIeVvq9HgAAALU"]
[Thu Jul 30 14:04:43.649849 2026] [security2:error] [pid 977210:tid 977390] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/w1px.php"] [unique_id "amugS_W1Jl2-fgIeVvq9HgAAALU"]
[Thu Jul 30 14:04:43.732534 2026] [proxy:error] [pid 977210:tid 977396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:43.732627 2026] [proxy_http:error] [pid 977210:tid 977396] [client 3.225.222.228:14190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:43.733216 2026] [proxy:error] [pid 977210:tid 977396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:43.733269 2026] [proxy_http:error] [pid 977210:tid 977396] [client 3.225.222.228:14190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:43.768712 2026] [proxy:error] [pid 977210:tid 977369] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:43.768793 2026] [proxy_http:error] [pid 977210:tid 977369] [client 44.213.206.96:39766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:43.769638 2026] [proxy:error] [pid 977210:tid 977369] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:43.769695 2026] [proxy_http:error] [pid 977210:tid 977369] [client 44.213.206.96:39766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:43.807683 2026] [security2:error] [pid 977210:tid 977365] [client 103.190.40.154:14719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugS_W1Jl2-fgIeVvq9LwAAAJw"]
[Thu Jul 30 14:04:43.807849 2026] [security2:error] [pid 977210:tid 977365] [client 103.190.40.154:14719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugS_W1Jl2-fgIeVvq9LwAAAJw"]
[Thu Jul 30 14:04:44.145991 2026] [security2:error] [pid 977210:tid 977413] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/js.php"] [unique_id "amugTPW1Jl2-fgIeVvq9OAAAAMw"]
[Thu Jul 30 14:04:44.146098 2026] [security2:error] [pid 977210:tid 977413] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/js.php"] [unique_id "amugTPW1Jl2-fgIeVvq9OAAAAMw"]
[Thu Jul 30 14:04:44.231243 2026] [security2:error] [pid 977210:tid 977380] [client 158.47.244.228:19484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugSvW1Jl2-fgIeVvq9AgAAAKs"], referer: http://pkf.jo
[Thu Jul 30 14:04:44.248034 2026] [core:error] [pid 977210:tid 977359] [client 172.213.208.20:41030] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:44.248068 2026] [core:error] [pid 977210:tid 977359] [client 172.213.208.20:41030] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:44.272707 2026] [security2:error] [pid 977210:tid 977350] [client 109.23.238.45:38710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugSvW1Jl2-fgIeVvq9AwAAAI0"], referer: http://pkf.jo
[Thu Jul 30 14:04:44.301143 2026] [security2:error] [pid 977210:tid 977401] [client 83.36.83.66:59390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugS_W1Jl2-fgIeVvq9BwAAAMA"], referer: http://pkf.jo
[Thu Jul 30 14:04:44.421144 2026] [security2:error] [pid 977210:tid 977425] [client 191.232.199.39:9578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/file56.php"] [unique_id "amugTPW1Jl2-fgIeVvq9RgAAANg"]
[Thu Jul 30 14:04:44.633729 2026] [security2:error] [pid 977210:tid 977453] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/core.php"] [unique_id "amugTPW1Jl2-fgIeVvq9SAAAAPQ"]
[Thu Jul 30 14:04:44.633869 2026] [security2:error] [pid 977210:tid 977453] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/core.php"] [unique_id "amugTPW1Jl2-fgIeVvq9SAAAAPQ"]
[Thu Jul 30 14:04:44.733110 2026] [security2:error] [pid 977210:tid 977438] [client 20.100.187.246:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amugTPW1Jl2-fgIeVvq9SQAAAOU"]
[Thu Jul 30 14:04:45.015823 2026] [security2:error] [pid 977210:tid 977410] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/biufile.php"] [unique_id "amugTfW1Jl2-fgIeVvq9VAAAAMk"]
[Thu Jul 30 14:04:45.016011 2026] [security2:error] [pid 977210:tid 977410] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/biufile.php"] [unique_id "amugTfW1Jl2-fgIeVvq9VAAAAMk"]
[Thu Jul 30 14:04:45.133434 2026] [security2:error] [pid 977210:tid 977344] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fffm.php"] [unique_id "amugTfW1Jl2-fgIeVvq9VQAAAIc"]
[Thu Jul 30 14:04:45.133591 2026] [security2:error] [pid 977210:tid 977344] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fffm.php"] [unique_id "amugTfW1Jl2-fgIeVvq9VQAAAIc"]
[Thu Jul 30 14:04:45.264683 2026] [security2:error] [pid 977210:tid 977445] [client 158.158.41.78:28471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/ioxi-o.php"] [unique_id "amugTfW1Jl2-fgIeVvq9VwAAAOw"]
[Thu Jul 30 14:04:45.275851 2026] [security2:error] [pid 977210:tid 977378] [client 64.202.37.215:38314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugS_W1Jl2-fgIeVvq9DQAAAKk"], referer: http://pkf.jo
[Thu Jul 30 14:04:45.330936 2026] [security2:error] [pid 977210:tid 977383] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/coffexium.php"] [unique_id "amugTfW1Jl2-fgIeVvq9WwAAAK4"]
[Thu Jul 30 14:04:45.331278 2026] [security2:error] [pid 977210:tid 977383] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/coffexium.php"] [unique_id "amugTfW1Jl2-fgIeVvq9WwAAAK4"]
[Thu Jul 30 14:04:45.467793 2026] [security2:error] [pid 977210:tid 977407] [client 68.221.186.136:46403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/ant.php"] [unique_id "amugTfW1Jl2-fgIeVvq9YgAAAMY"]
[Thu Jul 30 14:04:45.593055 2026] [autoindex:error] [pid 977210:tid 977379] [client 98.87.102.177:20278] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:04:45.599574 2026] [autoindex:error] [pid 977210:tid 977400] [client 18.211.55.47:44535] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:04:45.656956 2026] [security2:error] [pid 977210:tid 977352] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/simple.php"] [unique_id "amugTfW1Jl2-fgIeVvq9cwAAAI8"]
[Thu Jul 30 14:04:45.657070 2026] [security2:error] [pid 977210:tid 977352] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/simple.php"] [unique_id "amugTfW1Jl2-fgIeVvq9cwAAAI8"]
[Thu Jul 30 14:04:45.669708 2026] [security2:error] [pid 977210:tid 977385] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ww.php"] [unique_id "amugTfW1Jl2-fgIeVvq9dAAAALA"]
[Thu Jul 30 14:04:45.669784 2026] [security2:error] [pid 977210:tid 977385] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ww.php"] [unique_id "amugTfW1Jl2-fgIeVvq9dAAAALA"]
[Thu Jul 30 14:04:45.684813 2026] [security2:error] [pid 977210:tid 977467] [client 172.213.208.20:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/images/index.php"] [unique_id "amugTfW1Jl2-fgIeVvq9dQAAAQI"]
[Thu Jul 30 14:04:45.831065 2026] [security2:error] [pid 977210:tid 977437] [client 20.100.187.246:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amugTfW1Jl2-fgIeVvq9dgAAAOQ"]
[Thu Jul 30 14:04:45.971551 2026] [security2:error] [pid 977210:tid 977409] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/fpwch.php"] [unique_id "amugTfW1Jl2-fgIeVvq9fQAAAMg"]
[Thu Jul 30 14:04:45.971657 2026] [security2:error] [pid 977210:tid 977409] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/fpwch.php"] [unique_id "amugTfW1Jl2-fgIeVvq9fQAAAMg"]
[Thu Jul 30 14:04:46.079766 2026] [security2:error] [pid 977210:tid 977350] [client 20.91.199.21:15910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amugTvW1Jl2-fgIeVvq9gQAAAI0"]
[Thu Jul 30 14:04:46.116034 2026] [security2:error] [pid 977210:tid 977388] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugTfW1Jl2-fgIeVvq9aQAAALM"]
[Thu Jul 30 14:04:46.185844 2026] [security2:error] [pid 977210:tid 977449] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/domvf.php"] [unique_id "amugTvW1Jl2-fgIeVvq9hQAAAPA"]
[Thu Jul 30 14:04:46.185932 2026] [security2:error] [pid 977210:tid 977449] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/domvf.php"] [unique_id "amugTvW1Jl2-fgIeVvq9hQAAAPA"]
[Thu Jul 30 14:04:46.206652 2026] [security2:error] [pid 977210:tid 977351] [client 181.116.200.68:37049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugTvW1Jl2-fgIeVvq9hgAAAI4"]
[Thu Jul 30 14:04:46.206768 2026] [security2:error] [pid 977210:tid 977351] [client 181.116.200.68:37049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugTvW1Jl2-fgIeVvq9hgAAAI4"]
[Thu Jul 30 14:04:46.230586 2026] [security2:error] [pid 977210:tid 977419] [client 38.25.84.51:30484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugS_W1Jl2-fgIeVvq9HAAAANI"], referer: http://pkf.jo
[Thu Jul 30 14:04:46.231105 2026] [security2:error] [pid 977210:tid 977392] [client 177.246.84.86:10684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugS_W1Jl2-fgIeVvq9GgAAALc"], referer: http://pkf.jo
[Thu Jul 30 14:04:46.233066 2026] [security2:error] [pid 977210:tid 977353] [client 14.191.105.43:20065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugS_W1Jl2-fgIeVvq9JwAAAJA"], referer: http://pkf.jo
[Thu Jul 30 14:04:46.234956 2026] [security2:error] [pid 977210:tid 977433] [client 181.43.218.201:1702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugS_W1Jl2-fgIeVvq9HwAAAOA"], referer: http://pkf.jo
[Thu Jul 30 14:04:46.235545 2026] [security2:error] [pid 977210:tid 977448] [client 41.215.233.18:59298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugS_W1Jl2-fgIeVvq9MgAAAO8"], referer: http://pkf.jo
[Thu Jul 30 14:04:46.303945 2026] [security2:error] [pid 977210:tid 977374] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/dex.php"] [unique_id "amugTvW1Jl2-fgIeVvq9iAAAAKU"]
[Thu Jul 30 14:04:46.304063 2026] [security2:error] [pid 977210:tid 977374] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/dex.php"] [unique_id "amugTvW1Jl2-fgIeVvq9iAAAAKU"]
[Thu Jul 30 14:04:46.349262 2026] [security2:error] [pid 977210:tid 977377] [client 188.33.8.112:18644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugTfW1Jl2-fgIeVvq9VgAAAKg"], referer: http://pkf.jo
[Thu Jul 30 14:04:46.560067 2026] [security2:error] [pid 977210:tid 977436] [client 191.232.199.39:10002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amugTvW1Jl2-fgIeVvq9lAAAAOM"]
[Thu Jul 30 14:04:46.635720 2026] [security2:error] [pid 977210:tid 977375] [client 172.213.208.20:43704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/num.php"] [unique_id "amugTvW1Jl2-fgIeVvq9lQAAAKY"]
[Thu Jul 30 14:04:46.641918 2026] [security2:error] [pid 977210:tid 977406] [client 4.225.166.222:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/1.php"] [unique_id "amugTvW1Jl2-fgIeVvq9lgAAAMU"]
[Thu Jul 30 14:04:46.642017 2026] [security2:error] [pid 977210:tid 977406] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/1.php"] [unique_id "amugTvW1Jl2-fgIeVvq9lgAAAMU"]
[Thu Jul 30 14:04:46.642095 2026] [security2:error] [pid 977210:tid 977406] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/1.php"] [unique_id "amugTvW1Jl2-fgIeVvq9lgAAAMU"]
[Thu Jul 30 14:04:46.706289 2026] [security2:error] [pid 977210:tid 977458] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/echkm.php"] [unique_id "amugTvW1Jl2-fgIeVvq9lwAAAPk"]
[Thu Jul 30 14:04:46.706409 2026] [security2:error] [pid 977210:tid 977458] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/echkm.php"] [unique_id "amugTvW1Jl2-fgIeVvq9lwAAAPk"]
[Thu Jul 30 14:04:46.775491 2026] [security2:error] [pid 977210:tid 977434] [client 20.100.187.246:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amugTvW1Jl2-fgIeVvq9mAAAAOE"]
[Thu Jul 30 14:04:46.956631 2026] [proxy:error] [pid 977210:tid 977372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:46.956695 2026] [proxy_http:error] [pid 977210:tid 977372] [client 4.225.166.222:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:46.957282 2026] [proxy:error] [pid 977210:tid 977372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:46.957328 2026] [proxy_http:error] [pid 977210:tid 977372] [client 4.225.166.222:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:46.957403 2026] [security2:error] [pid 977210:tid 977372] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amugTvW1Jl2-fgIeVvq9oAAAAKM"]
[Thu Jul 30 14:04:47.029111 2026] [security2:error] [pid 977210:tid 977451] [client 158.158.41.78:28479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/file56.php"] [unique_id "amugT_W1Jl2-fgIeVvq9oQAAAPI"]
[Thu Jul 30 14:04:47.039134 2026] [security2:error] [pid 977210:tid 977469] [client 68.221.186.136:24110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/appreciators.php"] [unique_id "amugT_W1Jl2-fgIeVvq9ogAAAQQ"]
[Thu Jul 30 14:04:47.184539 2026] [security2:error] [pid 977210:tid 977411] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ano.php"] [unique_id "amugT_W1Jl2-fgIeVvq9pwAAAMo"]
[Thu Jul 30 14:04:47.184649 2026] [security2:error] [pid 977210:tid 977411] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ano.php"] [unique_id "amugT_W1Jl2-fgIeVvq9pwAAAMo"]
[Thu Jul 30 14:04:47.299485 2026] [security2:error] [pid 977210:tid 977347] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/config.json.php"] [unique_id "amugT_W1Jl2-fgIeVvq9qAAAAIo"]
[Thu Jul 30 14:04:47.299601 2026] [security2:error] [pid 977210:tid 977347] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/config.json.php"] [unique_id "amugT_W1Jl2-fgIeVvq9qAAAAIo"]
[Thu Jul 30 14:04:47.429033 2026] [security2:error] [pid 977210:tid 977368] [client 20.100.187.246:24786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amugT_W1Jl2-fgIeVvq9sAAAAJ8"]
[Thu Jul 30 14:04:47.475394 2026] [security2:error] [pid 977210:tid 977386] [client 103.242.199.184:54281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugT_W1Jl2-fgIeVvq9sQAAALE"]
[Thu Jul 30 14:04:47.475513 2026] [security2:error] [pid 977210:tid 977386] [client 103.242.199.184:54281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugT_W1Jl2-fgIeVvq9sQAAALE"]
[Thu Jul 30 14:04:47.635848 2026] [security2:error] [pid 977210:tid 977462] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/k2.php"] [unique_id "amugT_W1Jl2-fgIeVvq9tQAAAP0"]
[Thu Jul 30 14:04:47.636011 2026] [security2:error] [pid 977210:tid 977462] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/k2.php"] [unique_id "amugT_W1Jl2-fgIeVvq9tQAAAP0"]
[Thu Jul 30 14:04:47.681762 2026] [security2:error] [pid 977210:tid 977415] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ah25.php"] [unique_id "amugT_W1Jl2-fgIeVvq9tgAAAM4"]
[Thu Jul 30 14:04:47.681874 2026] [security2:error] [pid 977210:tid 977415] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ah25.php"] [unique_id "amugT_W1Jl2-fgIeVvq9tgAAAM4"]
[Thu Jul 30 14:04:47.947407 2026] [security2:error] [pid 977210:tid 977431] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/raw.php"] [unique_id "amugT_W1Jl2-fgIeVvq9vQAAAN4"]
[Thu Jul 30 14:04:47.947550 2026] [security2:error] [pid 977210:tid 977431] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/raw.php"] [unique_id "amugT_W1Jl2-fgIeVvq9vQAAAN4"]
[Thu Jul 30 14:04:48.201306 2026] [security2:error] [pid 977210:tid 977403] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/term.php"] [unique_id "amugUPW1Jl2-fgIeVvq9xAAAAMI"]
[Thu Jul 30 14:04:48.201403 2026] [security2:error] [pid 977210:tid 977403] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/term.php"] [unique_id "amugUPW1Jl2-fgIeVvq9xAAAAMI"]
[Thu Jul 30 14:04:48.252937 2026] [security2:error] [pid 977210:tid 977396] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/wp.php"] [unique_id "amugUPW1Jl2-fgIeVvq9xQAAALs"]
[Thu Jul 30 14:04:48.253065 2026] [security2:error] [pid 977210:tid 977396] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/wp.php"] [unique_id "amugUPW1Jl2-fgIeVvq9xQAAALs"]
[Thu Jul 30 14:04:48.370730 2026] [security2:error] [pid 977210:tid 977419] [client 191.232.199.39:9998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-admin/css/index.php"] [unique_id "amugUPW1Jl2-fgIeVvq9xwAAANI"]
[Thu Jul 30 14:04:48.385860 2026] [security2:error] [pid 977210:tid 977448] [client 20.100.187.246:24775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amugUPW1Jl2-fgIeVvq9ygAAAO8"]
[Thu Jul 30 14:04:48.421597 2026] [security2:error] [pid 977210:tid 977430] [client 158.158.41.78:26328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amugUPW1Jl2-fgIeVvq9ywAAAN0"]
[Thu Jul 30 14:04:48.561879 2026] [security2:error] [pid 977210:tid 977344] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/fffm.php"] [unique_id "amugUPW1Jl2-fgIeVvq90QAAAIc"]
[Thu Jul 30 14:04:48.562002 2026] [security2:error] [pid 977210:tid 977344] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/fffm.php"] [unique_id "amugUPW1Jl2-fgIeVvq90QAAAIc"]
[Thu Jul 30 14:04:48.760843 2026] [security2:error] [pid 977210:tid 977418] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/we.php"] [unique_id "amugUPW1Jl2-fgIeVvq93QAAANE"]
[Thu Jul 30 14:04:48.760939 2026] [security2:error] [pid 977210:tid 977418] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/we.php"] [unique_id "amugUPW1Jl2-fgIeVvq93QAAANE"]
[Thu Jul 30 14:04:48.874262 2026] [security2:error] [pid 977210:tid 977469] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/111.php"] [unique_id "amugUPW1Jl2-fgIeVvq95gAAAQQ"]
[Thu Jul 30 14:04:48.874355 2026] [security2:error] [pid 977210:tid 977469] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/111.php"] [unique_id "amugUPW1Jl2-fgIeVvq95gAAAQQ"]
[Thu Jul 30 14:04:49.104053 2026] [security2:error] [pid 977210:tid 977451] [client 20.100.187.246:6286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amugUfW1Jl2-fgIeVvq98QAAAPI"]
[Thu Jul 30 14:04:49.180817 2026] [proxy:error] [pid 977210:tid 977414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:49.180894 2026] [proxy_http:error] [pid 977210:tid 977414] [client 4.225.166.222:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:49.181479 2026] [proxy:error] [pid 977210:tid 977414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:04:49.181525 2026] [proxy_http:error] [pid 977210:tid 977414] [client 4.225.166.222:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:04:49.181637 2026] [security2:error] [pid 977210:tid 977414] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amugUfW1Jl2-fgIeVvq99QAAAM0"]
[Thu Jul 30 14:04:49.212634 2026] [security2:error] [pid 977210:tid 977349] [client 66.249.65.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugUPW1Jl2-fgIeVvq91gAAAIw"]
[Thu Jul 30 14:04:49.274438 2026] [security2:error] [pid 977210:tid 977410] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/zip-onee.php"] [unique_id "amugUfW1Jl2-fgIeVvq9-AAAAMk"]
[Thu Jul 30 14:04:49.274589 2026] [security2:error] [pid 977210:tid 977410] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/zip-onee.php"] [unique_id "amugUfW1Jl2-fgIeVvq9-AAAAMk"]
[Thu Jul 30 14:04:49.435467 2026] [security2:error] [pid 977210:tid 977346] [client 20.91.199.21:18533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amugUfW1Jl2-fgIeVvq9_AAAAIk"]
[Thu Jul 30 14:04:49.483186 2026] [security2:error] [pid 977210:tid 977362] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/ws.php"] [unique_id "amugUfW1Jl2-fgIeVvq9_QAAAJk"]
[Thu Jul 30 14:04:49.483287 2026] [security2:error] [pid 977210:tid 977362] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/ws.php"] [unique_id "amugUfW1Jl2-fgIeVvq9_QAAAJk"]
[Thu Jul 30 14:04:49.693509 2026] [security2:error] [pid 977210:tid 977388] [client 158.158.41.78:18682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/css/index.php"] [unique_id "amugUfW1Jl2-fgIeVvq-HAAAALM"]
[Thu Jul 30 14:04:49.783027 2026] [security2:error] [pid 977210:tid 977442] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/il.php"] [unique_id "amugUfW1Jl2-fgIeVvq-HgAAAOk"]
[Thu Jul 30 14:04:49.783133 2026] [security2:error] [pid 977210:tid 977442] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/il.php"] [unique_id "amugUfW1Jl2-fgIeVvq-HgAAAOk"]
[Thu Jul 30 14:04:50.037608 2026] [security2:error] [pid 977210:tid 977448] [client 20.100.187.246:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amugUvW1Jl2-fgIeVvq-IgAAAO8"]
[Thu Jul 30 14:04:50.099747 2026] [security2:error] [pid 977210:tid 977393] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/coffee.php"] [unique_id "amugUvW1Jl2-fgIeVvq-IwAAALg"]
[Thu Jul 30 14:04:50.099892 2026] [security2:error] [pid 977210:tid 977393] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/coffee.php"] [unique_id "amugUvW1Jl2-fgIeVvq-IwAAALg"]
[Thu Jul 30 14:04:50.305778 2026] [security2:error] [pid 977210:tid 977435] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/one.php"] [unique_id "amugUvW1Jl2-fgIeVvq-KgAAAOI"]
[Thu Jul 30 14:04:50.305878 2026] [security2:error] [pid 977210:tid 977435] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/one.php"] [unique_id "amugUvW1Jl2-fgIeVvq-KgAAAOI"]
[Thu Jul 30 14:04:50.346364 2026] [security2:error] [pid 977210:tid 977421] [client 191.232.199.39:10021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/edit.php"] [unique_id "amugUvW1Jl2-fgIeVvq-KwAAANQ"]
[Thu Jul 30 14:04:50.428907 2026] [security2:error] [pid 977210:tid 977408] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/goods.php"] [unique_id "amugUvW1Jl2-fgIeVvq-MAAAAMc"]
[Thu Jul 30 14:04:50.429075 2026] [security2:error] [pid 977210:tid 977408] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/goods.php"] [unique_id "amugUvW1Jl2-fgIeVvq-MAAAAMc"]
[Thu Jul 30 14:04:50.510368 2026] [security2:error] [pid 977210:tid 977300] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.appliancerepairservice.one"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amugUvW1Jl2-fgIeVvq-MQAA8lc"]
[Thu Jul 30 14:04:50.598634 2026] [security2:error] [pid 977210:tid 977320] [remote 74.7.227.39:38022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amugUvW1Jl2-fgIeVvq-MgAA_ms"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/includes/pa-display-conditions/conditions
[Thu Jul 30 14:04:50.661628 2026] [core:error] [pid 977210:tid 977423] [client 172.213.208.20:17879] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:50.661651 2026] [core:error] [pid 977210:tid 977423] [client 172.213.208.20:17879] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:50.764558 2026] [security2:error] [pid 977210:tid 977346] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/about.php"] [unique_id "amugUvW1Jl2-fgIeVvq-PAAAAIk"]
[Thu Jul 30 14:04:50.764713 2026] [security2:error] [pid 977210:tid 977346] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/about.php"] [unique_id "amugUvW1Jl2-fgIeVvq-PAAAAIk"]
[Thu Jul 30 14:04:50.801359 2026] [security2:error] [pid 977210:tid 977429] [client 158.158.41.78:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/edit.php"] [unique_id "amugUvW1Jl2-fgIeVvq-PgAAANw"]
[Thu Jul 30 14:04:50.849752 2026] [security2:error] [pid 977210:tid 977374] [client 20.100.187.246:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amugUvW1Jl2-fgIeVvq-PwAAAKU"]
[Thu Jul 30 14:04:50.864385 2026] [security2:error] [pid 977210:tid 977381] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/002.php"] [unique_id "amugUvW1Jl2-fgIeVvq-QAAAAKw"]
[Thu Jul 30 14:04:50.864471 2026] [security2:error] [pid 977210:tid 977381] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/002.php"] [unique_id "amugUvW1Jl2-fgIeVvq-QAAAAKw"]
[Thu Jul 30 14:04:51.014130 2026] [security2:error] [pid 977210:tid 977375] [client 68.221.186.136:33728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/archive.php"] [unique_id "amugU_W1Jl2-fgIeVvq-RQAAAKY"]
[Thu Jul 30 14:04:51.098005 2026] [security2:error] [pid 977210:tid 977425] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/about.php"] [unique_id "amugU_W1Jl2-fgIeVvq-RgAAANg"]
[Thu Jul 30 14:04:51.098109 2026] [security2:error] [pid 977210:tid 977425] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/about.php"] [unique_id "amugU_W1Jl2-fgIeVvq-RgAAANg"]
[Thu Jul 30 14:04:51.228051 2026] [security2:error] [pid 977210:tid 977360] [client 20.91.199.21:19878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/content.php"] [unique_id "amugU_W1Jl2-fgIeVvq-TAAAAJc"]
[Thu Jul 30 14:04:51.383092 2026] [security2:error] [pid 977210:tid 977458] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/file1.php"] [unique_id "amugU_W1Jl2-fgIeVvq-UQAAAPk"]
[Thu Jul 30 14:04:51.383194 2026] [security2:error] [pid 977210:tid 977458] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/file1.php"] [unique_id "amugU_W1Jl2-fgIeVvq-UQAAAPk"]
[Thu Jul 30 14:04:51.412879 2026] [security2:error] [pid 977210:tid 977388] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/admin.php"] [unique_id "amugU_W1Jl2-fgIeVvq-UgAAALM"]
[Thu Jul 30 14:04:51.413001 2026] [security2:error] [pid 977210:tid 977388] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/admin.php"] [unique_id "amugU_W1Jl2-fgIeVvq-UgAAALM"]
[Thu Jul 30 14:04:51.548169 2026] [core:error] [pid 977210:tid 977422] [client 172.213.208.20:16514] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:51.548191 2026] [core:error] [pid 977210:tid 977422] [client 172.213.208.20:16514] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:51.614444 2026] [security2:error] [pid 977210:tid 977441] [client 158.158.41.78:11269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/2.php"] [unique_id "amugU_W1Jl2-fgIeVvq-VwAAAOg"]
[Thu Jul 30 14:04:51.753068 2026] [security2:error] [pid 977210:tid 977448] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/inputs.php"] [unique_id "amugU_W1Jl2-fgIeVvq-WwAAAO8"]
[Thu Jul 30 14:04:51.753177 2026] [security2:error] [pid 977210:tid 977448] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/inputs.php"] [unique_id "amugU_W1Jl2-fgIeVvq-WwAAAO8"]
[Thu Jul 30 14:04:51.872991 2026] [security2:error] [pid 977210:tid 977380] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/akimet.php"] [unique_id "amugU_W1Jl2-fgIeVvq-XwAAAKs"]
[Thu Jul 30 14:04:51.873100 2026] [security2:error] [pid 977210:tid 977380] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/akimet.php"] [unique_id "amugU_W1Jl2-fgIeVvq-XwAAAKs"]
[Thu Jul 30 14:04:51.992276 2026] [security2:error] [pid 977210:tid 977400] [client 68.221.186.136:33764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/as.php"] [unique_id "amugU_W1Jl2-fgIeVvq-ZAAAAL8"]
[Thu Jul 30 14:04:52.068932 2026] [security2:error] [pid 977210:tid 977415] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/inputs.php"] [unique_id "amugVPW1Jl2-fgIeVvq-ZgAAAM4"]
[Thu Jul 30 14:04:52.069054 2026] [security2:error] [pid 977210:tid 977415] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/inputs.php"] [unique_id "amugVPW1Jl2-fgIeVvq-ZgAAAM4"]
[Thu Jul 30 14:04:52.072914 2026] [security2:error] [pid 977210:tid 977412] [client 107.170.60.13:39454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.yaz.gzj.temporary.site"] [uri "/.env"] [unique_id "amugVPW1Jl2-fgIeVvq-ZwAAAMs"]
[Thu Jul 30 14:04:52.273031 2026] [security2:error] [pid 977210:tid 977358] [client 191.232.199.39:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/2.php"] [unique_id "amugVPW1Jl2-fgIeVvq-awAAAJU"]
[Thu Jul 30 14:04:52.378680 2026] [security2:error] [pid 977210:tid 977449] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/adminfuns.php"] [unique_id "amugVPW1Jl2-fgIeVvq-bAAAAPA"]
[Thu Jul 30 14:04:52.378792 2026] [security2:error] [pid 977210:tid 977449] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/adminfuns.php"] [unique_id "amugVPW1Jl2-fgIeVvq-bAAAAPA"]
[Thu Jul 30 14:04:52.388114 2026] [security2:error] [pid 977210:tid 977433] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/reop3.php"] [unique_id "amugVPW1Jl2-fgIeVvq-bQAAAOA"]
[Thu Jul 30 14:04:52.388192 2026] [security2:error] [pid 977210:tid 977433] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/reop3.php"] [unique_id "amugVPW1Jl2-fgIeVvq-bQAAAOA"]
[Thu Jul 30 14:04:52.507638 2026] [security2:error] [pid 977210:tid 977416] [client 172.213.208.20:43653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amugVPW1Jl2-fgIeVvq-dAAAAM8"]
[Thu Jul 30 14:04:52.628267 2026] [security2:error] [pid 977210:tid 977344] [client 20.100.187.246:24023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amugVPW1Jl2-fgIeVvq-dgAAAIc"]
[Thu Jul 30 14:04:52.687484 2026] [security2:error] [pid 977210:tid 977391] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/404.php"] [unique_id "amugVPW1Jl2-fgIeVvq-dwAAALY"]
[Thu Jul 30 14:04:52.687610 2026] [security2:error] [pid 977210:tid 977391] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/404.php"] [unique_id "amugVPW1Jl2-fgIeVvq-dwAAALY"]
[Thu Jul 30 14:04:52.788359 2026] [security2:error] [pid 977210:tid 977423] [client 189.6.88.213:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugVPW1Jl2-fgIeVvq-fAAAANY"]
[Thu Jul 30 14:04:52.788444 2026] [security2:error] [pid 977210:tid 977423] [client 189.6.88.213:51564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugVPW1Jl2-fgIeVvq-fAAAANY"]
[Thu Jul 30 14:04:52.816287 2026] [security2:error] [pid 977210:tid 977421] [client 158.158.41.78:18640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/uploads/admin.php"] [unique_id "amugVPW1Jl2-fgIeVvq-fQAAANQ"]
[Thu Jul 30 14:04:52.897130 2026] [security2:error] [pid 977210:tid 977402] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/h.php"] [unique_id "amugVPW1Jl2-fgIeVvq-gwAAAME"]
[Thu Jul 30 14:04:52.897206 2026] [security2:error] [pid 977210:tid 977402] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/h.php"] [unique_id "amugVPW1Jl2-fgIeVvq-gwAAAME"]
[Thu Jul 30 14:04:53.022951 2026] [security2:error] [pid 977210:tid 977405] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/xxx.php"] [unique_id "amugVfW1Jl2-fgIeVvq-hQAAAMQ"]
[Thu Jul 30 14:04:53.023070 2026] [security2:error] [pid 977210:tid 977405] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/xxx.php"] [unique_id "amugVfW1Jl2-fgIeVvq-hQAAAMQ"]
[Thu Jul 30 14:04:53.044527 2026] [security2:error] [pid 977210:tid 977465] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.appliancerepairservice.one"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amugVfW1Jl2-fgIeVvq-hgAAAQA"]
[Thu Jul 30 14:04:53.336555 2026] [security2:error] [pid 977210:tid 977388] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/classwithtostring.php"] [unique_id "amugVfW1Jl2-fgIeVvq-jQAAALM"]
[Thu Jul 30 14:04:53.336656 2026] [security2:error] [pid 977210:tid 977388] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/classwithtostring.php"] [unique_id "amugVfW1Jl2-fgIeVvq-jQAAALM"]
[Thu Jul 30 14:04:53.404796 2026] [security2:error] [pid 977210:tid 977466] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/2x.php"] [unique_id "amugVfW1Jl2-fgIeVvq-jgAAAQE"]
[Thu Jul 30 14:04:53.404899 2026] [security2:error] [pid 977210:tid 977466] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/2x.php"] [unique_id "amugVfW1Jl2-fgIeVvq-jgAAAQE"]
[Thu Jul 30 14:04:53.633680 2026] [security2:error] [pid 977210:tid 977442] [client 158.158.41.78:18265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/mah.php"] [unique_id "amugVfW1Jl2-fgIeVvq-mwAAAOk"]
[Thu Jul 30 14:04:53.647316 2026] [security2:error] [pid 977210:tid 977469] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/234ff.php"] [unique_id "amugVfW1Jl2-fgIeVvq-nAAAAQQ"]
[Thu Jul 30 14:04:53.647393 2026] [security2:error] [pid 977210:tid 977469] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/234ff.php"] [unique_id "amugVfW1Jl2-fgIeVvq-nAAAAQQ"]
[Thu Jul 30 14:04:53.862892 2026] [security2:error] [pid 977210:tid 977357] [client 191.232.199.39:30214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amugVfW1Jl2-fgIeVvq-owAAAJQ"]
[Thu Jul 30 14:04:53.872829 2026] [security2:error] [pid 977210:tid 977352] [client 20.100.187.246:25566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amugVfW1Jl2-fgIeVvq-pAAAAI8"]
[Thu Jul 30 14:04:53.902061 2026] [security2:error] [pid 977210:tid 977455] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/petx.php"] [unique_id "amugVfW1Jl2-fgIeVvq-pQAAAPY"]
[Thu Jul 30 14:04:53.902146 2026] [security2:error] [pid 977210:tid 977455] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/petx.php"] [unique_id "amugVfW1Jl2-fgIeVvq-pQAAAPY"]
[Thu Jul 30 14:04:53.959066 2026] [security2:error] [pid 977210:tid 977404] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/133.php"] [unique_id "amugVfW1Jl2-fgIeVvq-qgAAAMM"]
[Thu Jul 30 14:04:53.959165 2026] [security2:error] [pid 977210:tid 977404] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/133.php"] [unique_id "amugVfW1Jl2-fgIeVvq-qgAAAMM"]
[Thu Jul 30 14:04:54.015782 2026] [security2:error] [pid 977210:tid 977424] [client 172.213.208.20:43271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amugVvW1Jl2-fgIeVvq-qwAAANc"]
[Thu Jul 30 14:04:54.257598 2026] [security2:error] [pid 977210:tid 977396] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/wp-ws68.php"] [unique_id "amugVvW1Jl2-fgIeVvq-rwAAALs"]
[Thu Jul 30 14:04:54.257738 2026] [security2:error] [pid 977210:tid 977396] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/wp-ws68.php"] [unique_id "amugVvW1Jl2-fgIeVvq-rwAAALs"]
[Thu Jul 30 14:04:54.389441 2026] [security2:error] [pid 977210:tid 977419] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/zxz.php"] [unique_id "amugVvW1Jl2-fgIeVvq-swAAANI"]
[Thu Jul 30 14:04:54.389545 2026] [security2:error] [pid 977210:tid 977419] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/zxz.php"] [unique_id "amugVvW1Jl2-fgIeVvq-swAAANI"]
[Thu Jul 30 14:04:54.496254 2026] [security2:error] [pid 977210:tid 977369] [client 103.190.40.154:15758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugVvW1Jl2-fgIeVvq-uAAAAKA"]
[Thu Jul 30 14:04:54.496382 2026] [security2:error] [pid 977210:tid 977369] [client 103.190.40.154:15758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugVvW1Jl2-fgIeVvq-uAAAAKA"]
[Thu Jul 30 14:04:54.516491 2026] [security2:error] [pid 977210:tid 977436] [client 2a03:2880:f800:a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugVfW1Jl2-fgIeVvq-pgAA4zY"]
[Thu Jul 30 14:04:54.559125 2026] [security2:error] [pid 977210:tid 977374] [client 172.213.208.20:29034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "amugVvW1Jl2-fgIeVvq-vAAAAKU"]
[Thu Jul 30 14:04:54.919273 2026] [security2:error] [pid 977210:tid 977367] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/2.php"] [unique_id "amugVvW1Jl2-fgIeVvq-xAAAAJ4"]
[Thu Jul 30 14:04:54.919362 2026] [security2:error] [pid 977210:tid 977367] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/2.php"] [unique_id "amugVvW1Jl2-fgIeVvq-xAAAAJ4"]
[Thu Jul 30 14:04:54.976688 2026] [security2:error] [pid 977210:tid 977461] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/mgrr.php"] [unique_id "amugVvW1Jl2-fgIeVvq-yAAAAPw"]
[Thu Jul 30 14:04:54.976817 2026] [security2:error] [pid 977210:tid 977461] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/mgrr.php"] [unique_id "amugVvW1Jl2-fgIeVvq-yAAAAPw"]
[Thu Jul 30 14:04:55.024794 2026] [security2:error] [pid 977210:tid 977462] [client 20.100.187.246:24030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amugV_W1Jl2-fgIeVvq-yQAAAP0"]
[Thu Jul 30 14:04:55.132478 2026] [security2:error] [pid 977210:tid 977441] [client 68.221.186.136:39633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.emmanueljrodriguez.com"] [uri "/atomlib.php"] [unique_id "amugV_W1Jl2-fgIeVvq-ygAAAOg"]
[Thu Jul 30 14:04:55.303674 2026] [security2:error] [pid 977210:tid 977427] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/55.php"] [unique_id "amugV_W1Jl2-fgIeVvq-0QAAANo"]
[Thu Jul 30 14:04:55.303767 2026] [security2:error] [pid 977210:tid 977427] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.buyfluoxetine.store"] [uri "/55.php"] [unique_id "amugV_W1Jl2-fgIeVvq-0QAAANo"]
[Thu Jul 30 14:04:55.446789 2026] [security2:error] [pid 977210:tid 977423] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/op.php"] [unique_id "amugV_W1Jl2-fgIeVvq-1wAAANY"]
[Thu Jul 30 14:04:55.446893 2026] [security2:error] [pid 977210:tid 977423] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/op.php"] [unique_id "amugV_W1Jl2-fgIeVvq-1wAAANY"]
[Thu Jul 30 14:04:55.681864 2026] [security2:error] [pid 977210:tid 977439] [client 20.91.199.21:41274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amugV_W1Jl2-fgIeVvq-2QAAAOY"]
[Thu Jul 30 14:04:55.691850 2026] [security2:error] [pid 977210:tid 977371] [client 158.158.41.78:28470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/send.php"] [unique_id "amugV_W1Jl2-fgIeVvq-2gAAAKI"]
[Thu Jul 30 14:04:55.778614 2026] [security2:error] [pid 977210:tid 977406] [client 172.213.208.20:41045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/gifclass.php"] [unique_id "amugV_W1Jl2-fgIeVvq-3gAAAMU"]
[Thu Jul 30 14:04:55.923308 2026] [core:notice] [pid 977210:tid 977465] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:55.931101 2026] [security2:error] [pid 977210:tid 977360] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/a5.php"] [unique_id "amugV_W1Jl2-fgIeVvq-5AAAAJc"]
[Thu Jul 30 14:04:55.931229 2026] [security2:error] [pid 977210:tid 977360] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/a5.php"] [unique_id "amugV_W1Jl2-fgIeVvq-5AAAAJc"]
[Thu Jul 30 14:04:56.229428 2026] [http2:info] [pid 1004636:tid 1004636] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 14:04:56.416209 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ws80.php"] [unique_id "amugWO_uyupB2NyFtxJ1YQAAAAU"]
[Thu Jul 30 14:04:56.416376 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ws80.php"] [unique_id "amugWO_uyupB2NyFtxJ1YQAAAAU"]
[Thu Jul 30 14:04:56.795025 2026] [security2:error] [pid 1004636:tid 1004829] [client 181.116.200.68:42107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugWO_uyupB2NyFtxJ1bwAAAAc"]
[Thu Jul 30 14:04:56.795174 2026] [security2:error] [pid 1004636:tid 1004829] [client 181.116.200.68:42107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugWO_uyupB2NyFtxJ1bwAAAAc"]
[Thu Jul 30 14:04:56.907302 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xa.php"] [unique_id "amugWO_uyupB2NyFtxJ1cwAAACM"]
[Thu Jul 30 14:04:56.907420 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xa.php"] [unique_id "amugWO_uyupB2NyFtxJ1cwAAACM"]
[Thu Jul 30 14:04:56.993803 2026] [security2:error] [pid 1004636:tid 1004861] [client 172.237.109.114:55047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/knews/readme.txt"] [unique_id "amugWO_uyupB2NyFtxJ1dAAAACU"]
[Thu Jul 30 14:04:57.265548 2026] [security2:error] [pid 1004636:tid 1004843] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugWO_uyupB2NyFtxJ1bAAAABQ"]
[Thu Jul 30 14:04:57.429317 2026] [security2:error] [pid 1004636:tid 1004892] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/asd67.php"] [unique_id "amugWe_uyupB2NyFtxJ1hgAAAEM"]
[Thu Jul 30 14:04:57.429441 2026] [security2:error] [pid 1004636:tid 1004892] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/asd67.php"] [unique_id "amugWe_uyupB2NyFtxJ1hgAAAEM"]
[Thu Jul 30 14:04:57.517987 2026] [core:notice] [pid 1004636:tid 1004898] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:04:57.656968 2026] [core:error] [pid 1004636:tid 1004888] [client 172.213.208.20:38288] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:57.657003 2026] [core:error] [pid 1004636:tid 1004888] [client 172.213.208.20:38288] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:04:57.935364 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/bk.php"] [unique_id "amugWe_uyupB2NyFtxJ1lAAAAF4"]
[Thu Jul 30 14:04:57.935480 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/bk.php"] [unique_id "amugWe_uyupB2NyFtxJ1lAAAAF4"]
[Thu Jul 30 14:04:58.064062 2026] [security2:error] [pid 1004636:tid 1004921] [client 103.242.199.184:54844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugWu_uyupB2NyFtxJ1mQAAAF8"]
[Thu Jul 30 14:04:58.064198 2026] [security2:error] [pid 1004636:tid 1004921] [client 103.242.199.184:54844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugWu_uyupB2NyFtxJ1mQAAAF8"]
[Thu Jul 30 14:04:58.137095 2026] [security2:error] [pid 1004636:tid 1004823] [client 158.158.41.78:28439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amugWu_uyupB2NyFtxJ1nQAAAAE"]
[Thu Jul 30 14:04:58.161760 2026] [security2:error] [pid 1004636:tid 1004915] [client 191.232.199.39:10005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/mah.php"] [unique_id "amugWu_uyupB2NyFtxJ1ngAAAFk"]
[Thu Jul 30 14:04:58.441817 2026] [security2:error] [pid 1004636:tid 1004938] [client 172.213.208.20:43315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amugWu_uyupB2NyFtxJ1owAAAG4"]
[Thu Jul 30 14:04:58.444723 2026] [security2:error] [pid 1004636:tid 1004945] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-links.php"] [unique_id "amugWu_uyupB2NyFtxJ1pAAAAHU"]
[Thu Jul 30 14:04:58.444898 2026] [security2:error] [pid 1004636:tid 1004945] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-links.php"] [unique_id "amugWu_uyupB2NyFtxJ1pAAAAHU"]
[Thu Jul 30 14:04:58.931272 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/mosty.php"] [unique_id "amugWu_uyupB2NyFtxJ1sgAAAA8"]
[Thu Jul 30 14:04:58.931369 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/mosty.php"] [unique_id "amugWu_uyupB2NyFtxJ1sgAAAA8"]
[Thu Jul 30 14:04:59.011232 2026] [security2:error] [pid 1004636:tid 1004842] [client 172.213.208.20:41036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/css/index.php"] [unique_id "amugW-_uyupB2NyFtxJ1swAAABM"]
[Thu Jul 30 14:04:59.432947 2026] [security2:error] [pid 1004636:tid 1004883] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sump3.php"] [unique_id "amugW-_uyupB2NyFtxJ1wQAAADo"]
[Thu Jul 30 14:04:59.433092 2026] [security2:error] [pid 1004636:tid 1004883] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/sump3.php"] [unique_id "amugW-_uyupB2NyFtxJ1wQAAADo"]
[Thu Jul 30 14:04:59.936205 2026] [security2:error] [pid 1004636:tid 1004893] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/first.php"] [unique_id "amugW-_uyupB2NyFtxJ1zAAAAEQ"]
[Thu Jul 30 14:04:59.936325 2026] [security2:error] [pid 1004636:tid 1004893] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/first.php"] [unique_id "amugW-_uyupB2NyFtxJ1zAAAAEQ"]
[Thu Jul 30 14:05:00.344618 2026] [security2:error] [pid 1004636:tid 1004880] [client 172.213.208.20:43278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-cron.php"] [unique_id "amugXO_uyupB2NyFtxJ10wAAADg"]
[Thu Jul 30 14:05:00.427539 2026] [security2:error] [pid 1004636:tid 1004914] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/acp.php"] [unique_id "amugXO_uyupB2NyFtxJ11wAAAFg"]
[Thu Jul 30 14:05:00.427655 2026] [security2:error] [pid 1004636:tid 1004914] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/acp.php"] [unique_id "amugXO_uyupB2NyFtxJ11wAAAFg"]
[Thu Jul 30 14:05:00.599369 2026] [security2:error] [pid 1004636:tid 1004822] [client 20.91.199.21:11432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amugXO_uyupB2NyFtxJ12AAAAAA"]
[Thu Jul 30 14:05:00.619384 2026] [core:notice] [pid 1004636:tid 1004887] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:00.906312 2026] [core:notice] [pid 1004636:tid 1004942] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:00.928472 2026] [security2:error] [pid 1004636:tid 1004940] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-good.php"] [unique_id "amugXO_uyupB2NyFtxJ15AAAAHA"]
[Thu Jul 30 14:05:00.928579 2026] [security2:error] [pid 1004636:tid 1004940] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-good.php"] [unique_id "amugXO_uyupB2NyFtxJ15AAAAHA"]
[Thu Jul 30 14:05:00.929791 2026] [security2:error] [pid 1004636:tid 1004909] [client 191.232.199.39:9577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/send.php"] [unique_id "amugXO_uyupB2NyFtxJ15QAAAFM"]
[Thu Jul 30 14:05:01.043058 2026] [security2:error] [pid 1004636:tid 1004729] [remote 57.141.0.49:42752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3981330618/feed/rss2/"] [unique_id "amugXe_uyupB2NyFtxJ15gAAaig"]
[Thu Jul 30 14:05:01.438829 2026] [security2:error] [pid 1004636:tid 1004846] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/daerl3.php"] [unique_id "amugXe_uyupB2NyFtxJ19AAAABc"]
[Thu Jul 30 14:05:01.438950 2026] [security2:error] [pid 1004636:tid 1004846] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/daerl3.php"] [unique_id "amugXe_uyupB2NyFtxJ19AAAABc"]
[Thu Jul 30 14:05:01.677757 2026] [security2:error] [pid 1004636:tid 1004842] [client 158.158.41.78:31357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/about.php"] [unique_id "amugXe_uyupB2NyFtxJ1-wAAABM"]
[Thu Jul 30 14:05:01.744682 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.91.199.21:41247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amugXe_uyupB2NyFtxJ1_gAAABk"]
[Thu Jul 30 14:05:01.799763 2026] [security2:error] [pid 977210:tid 977392] [client 20.100.187.246:25837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amugXfW1Jl2-fgIeVvq-5QAAALc"]
[Thu Jul 30 14:05:01.927155 2026] [security2:error] [pid 1004636:tid 1004734] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugXe_uyupB2NyFtxJ18wAAdy0"]
[Thu Jul 30 14:05:01.927336 2026] [security2:error] [pid 1004636:tid 1004947] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugXe_uyupB2NyFtxJ18wAAdy0"]
[Thu Jul 30 14:05:01.964919 2026] [security2:error] [pid 1004636:tid 1004879] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/php5.php"] [unique_id "amugXe_uyupB2NyFtxJ2BQAAADc"]
[Thu Jul 30 14:05:01.965035 2026] [security2:error] [pid 1004636:tid 1004879] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/php5.php"] [unique_id "amugXe_uyupB2NyFtxJ2BQAAADc"]
[Thu Jul 30 14:05:02.483292 2026] [security2:error] [pid 1004636:tid 1004930] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xoot.php"] [unique_id "amugXu_uyupB2NyFtxJ2HAAAAGc"]
[Thu Jul 30 14:05:02.483471 2026] [security2:error] [pid 1004636:tid 1004930] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/xoot.php"] [unique_id "amugXu_uyupB2NyFtxJ2HAAAAGc"]
[Thu Jul 30 14:05:02.744205 2026] [security2:error] [pid 1004636:tid 1004909] [client 188.119.13.37:10221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugXu_uyupB2NyFtxJ2OQAAAFM"]
[Thu Jul 30 14:05:02.866589 2026] [core:notice] [pid 1004636:tid 1004937] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:02.913853 2026] [security2:error] [pid 1004636:tid 1004842] [client 158.158.41.78:12262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/options.php"] [unique_id "amugXu_uyupB2NyFtxJ2QQAAABM"]
[Thu Jul 30 14:05:02.980664 2026] [security2:error] [pid 1004636:tid 1004867] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/clxcc.php"] [unique_id "amugXu_uyupB2NyFtxJ2QgAAACs"]
[Thu Jul 30 14:05:02.980773 2026] [security2:error] [pid 1004636:tid 1004867] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/clxcc.php"] [unique_id "amugXu_uyupB2NyFtxJ2QgAAACs"]
[Thu Jul 30 14:05:03.104355 2026] [security2:error] [pid 1004636:tid 1004857] [client 191.232.199.39:9426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amugX-_uyupB2NyFtxJ2SQAAACE"]
[Thu Jul 30 14:05:03.206337 2026] [security2:error] [pid 1004636:tid 1004841] [client 20.91.199.21:3589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amugX-_uyupB2NyFtxJ2TAAAABI"]
[Thu Jul 30 14:05:03.328493 2026] [security2:error] [pid 1004636:tid 1004943] [client 20.100.187.246:25804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amugX-_uyupB2NyFtxJ2hwAAAHM"]
[Thu Jul 30 14:05:03.366163 2026] [security2:error] [pid 1004636:tid 1004823] [client 188.119.13.37:11170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugX-_uyupB2NyFtxJ2iwAAAAE"]
[Thu Jul 30 14:05:03.507023 2026] [security2:error] [pid 1004636:tid 1004887] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ai.php"] [unique_id "amugX-_uyupB2NyFtxJ2kQAAAD4"]
[Thu Jul 30 14:05:03.507121 2026] [security2:error] [pid 1004636:tid 1004887] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ai.php"] [unique_id "amugX-_uyupB2NyFtxJ2kQAAAD4"]
[Thu Jul 30 14:05:03.539968 2026] [security2:error] [pid 1004636:tid 1004949] [client 189.6.88.213:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugX-_uyupB2NyFtxJ2lgAAAHk"]
[Thu Jul 30 14:05:03.540080 2026] [security2:error] [pid 1004636:tid 1004949] [client 189.6.88.213:52138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugX-_uyupB2NyFtxJ2lgAAAHk"]
[Thu Jul 30 14:05:03.584169 2026] [security2:error] [pid 1004636:tid 1004930] [client 158.158.41.78:26269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/themes/index.php"] [unique_id "amugX-_uyupB2NyFtxJ2lwAAAGc"]
[Thu Jul 30 14:05:03.897670 2026] [security2:error] [pid 1004636:tid 1004909] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amugX-_uyupB2NyFtxJ2oAAAAFM"]
[Thu Jul 30 14:05:03.979323 2026] [security2:error] [pid 1004636:tid 1004910] [client 188.119.13.37:10631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugX-_uyupB2NyFtxJ2oQAAAFQ"]
[Thu Jul 30 14:05:04.022183 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/nwflm.php"] [unique_id "amugYO_uyupB2NyFtxJ2owAAAAk"]
[Thu Jul 30 14:05:04.022293 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/nwflm.php"] [unique_id "amugYO_uyupB2NyFtxJ2owAAAAk"]
[Thu Jul 30 14:05:04.025085 2026] [security2:error] [pid 1004636:tid 1004717] [remote 57.141.0.54:63324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/674008491/feed/rss2/"] [unique_id "amugYO_uyupB2NyFtxJ2pAAAGRw"]
[Thu Jul 30 14:05:04.194704 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.100.187.246:24471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amugYO_uyupB2NyFtxJ2qQAAAAs"]
[Thu Jul 30 14:05:04.258808 2026] [core:notice] [pid 1004636:tid 1004933] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:04.512209 2026] [security2:error] [pid 1004636:tid 1004866] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/hypo.php"] [unique_id "amugYO_uyupB2NyFtxJ2swAAACo"]
[Thu Jul 30 14:05:04.512319 2026] [security2:error] [pid 1004636:tid 1004866] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/hypo.php"] [unique_id "amugYO_uyupB2NyFtxJ2swAAACo"]
[Thu Jul 30 14:05:04.608531 2026] [security2:error] [pid 1004636:tid 1004849] [client 188.119.13.37:10428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugYO_uyupB2NyFtxJ2uQAAABo"]
[Thu Jul 30 14:05:04.646312 2026] [core:error] [pid 1004636:tid 1004874] [client 95.108.213.79:62070] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:04.646333 2026] [core:error] [pid 1004636:tid 1004874] [client 95.108.213.79:62070] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:04.963451 2026] [security2:error] [pid 1004636:tid 1004926] [client 191.232.199.39:9419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/about.php"] [unique_id "amugYO_uyupB2NyFtxJ2xQAAAGM"]
[Thu Jul 30 14:05:05.054458 2026] [security2:error] [pid 1004636:tid 1004843] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/api.swp"] [unique_id "amugYe_uyupB2NyFtxJ2xgAAABQ"]
[Thu Jul 30 14:05:05.057126 2026] [security2:error] [pid 1004636:tid 1004889] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/w3llscc.php"] [unique_id "amugYe_uyupB2NyFtxJ2xwAAAEA"]
[Thu Jul 30 14:05:05.057207 2026] [security2:error] [pid 1004636:tid 1004889] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/w3llscc.php"] [unique_id "amugYe_uyupB2NyFtxJ2xwAAAEA"]
[Thu Jul 30 14:05:05.240865 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.91.199.21:18555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amugYe_uyupB2NyFtxJ2zAAAAAc"]
[Thu Jul 30 14:05:05.242710 2026] [security2:error] [pid 1004636:tid 1004923] [client 188.119.13.37:10123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugYe_uyupB2NyFtxJ2zQAAAGA"]
[Thu Jul 30 14:05:05.262345 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.100.187.246:20563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amugYe_uyupB2NyFtxJ2zgAAADk"]
[Thu Jul 30 14:05:05.333952 2026] [security2:error] [pid 1004636:tid 1004904] [client 103.190.40.154:20202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugYe_uyupB2NyFtxJ20gAAAE4"]
[Thu Jul 30 14:05:05.334093 2026] [security2:error] [pid 1004636:tid 1004904] [client 103.190.40.154:20202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugYe_uyupB2NyFtxJ20gAAAE4"]
[Thu Jul 30 14:05:05.576148 2026] [security2:error] [pid 1004636:tid 1004846] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/11PJcpMFsD8B.php"] [unique_id "amugYe_uyupB2NyFtxJ22gAAABc"]
[Thu Jul 30 14:05:05.576239 2026] [security2:error] [pid 1004636:tid 1004846] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/11PJcpMFsD8B.php"] [unique_id "amugYe_uyupB2NyFtxJ22gAAABc"]
[Thu Jul 30 14:05:05.692307 2026] [security2:error] [pid 1004636:tid 1004955] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amugYe_uyupB2NyFtxJ23gAAAH8"]
[Thu Jul 30 14:05:05.854431 2026] [security2:error] [pid 1004636:tid 1004901] [client 188.119.13.37:10390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugYe_uyupB2NyFtxJ24AAAAEs"]
[Thu Jul 30 14:05:05.981268 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.91.199.21:3795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amugYe_uyupB2NyFtxJ26AAAAAY"]
[Thu Jul 30 14:05:06.058374 2026] [security2:error] [pid 1004636:tid 1004825] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/8.php"] [unique_id "amugYu_uyupB2NyFtxJ26gAAAAM"]
[Thu Jul 30 14:05:06.058490 2026] [security2:error] [pid 1004636:tid 1004825] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/8.php"] [unique_id "amugYu_uyupB2NyFtxJ26gAAAAM"]
[Thu Jul 30 14:05:06.061857 2026] [security2:error] [pid 1004636:tid 1004731] [remote 57.141.0.12:25018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amugYu_uyupB2NyFtxJ26QAARio"]
[Thu Jul 30 14:05:06.429692 2026] [security2:error] [pid 1004636:tid 1004917] [client 20.100.187.246:20582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amugYu_uyupB2NyFtxJ29AAAAFs"]
[Thu Jul 30 14:05:06.463937 2026] [security2:error] [pid 1004636:tid 1004842] [client 191.232.199.39:9993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/options.php"] [unique_id "amugYu_uyupB2NyFtxJ2-QAAABM"]
[Thu Jul 30 14:05:06.494890 2026] [security2:error] [pid 1004636:tid 1004844] [client 188.119.13.37:10938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugYu_uyupB2NyFtxJ2-gAAABU"]
[Thu Jul 30 14:05:06.550538 2026] [security2:error] [pid 1004636:tid 1004947] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fnstall.php"] [unique_id "amugYu_uyupB2NyFtxJ2-wAAAHc"]
[Thu Jul 30 14:05:06.550651 2026] [security2:error] [pid 1004636:tid 1004947] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fnstall.php"] [unique_id "amugYu_uyupB2NyFtxJ2-wAAAHc"]
[Thu Jul 30 14:05:06.754816 2026] [fcgid:warn] [pid 1004636:tid 1004866] (70014)End of file found: [client 165.154.11.52:47432] mod_fcgid: can't get data from http client
[Thu Jul 30 14:05:06.843003 2026] [security2:error] [pid 1004636:tid 1004849] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.git%00"] [unique_id "amugYu_uyupB2NyFtxJ3AgAAABo"]
[Thu Jul 30 14:05:07.034804 2026] [security2:error] [pid 1004636:tid 1004841] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/edorxrr.php"] [unique_id "amugY-_uyupB2NyFtxJ3CgAAABI"]
[Thu Jul 30 14:05:07.034903 2026] [security2:error] [pid 1004636:tid 1004841] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/edorxrr.php"] [unique_id "amugY-_uyupB2NyFtxJ3CgAAABI"]
[Thu Jul 30 14:05:07.547355 2026] [security2:error] [pid 1004636:tid 1004862] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/setup.php"] [unique_id "amugY-_uyupB2NyFtxJ3JQAAACY"]
[Thu Jul 30 14:05:07.547538 2026] [security2:error] [pid 1004636:tid 1004862] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/setup.php"] [unique_id "amugY-_uyupB2NyFtxJ3JQAAACY"]
[Thu Jul 30 14:05:07.552896 2026] [security2:error] [pid 1004636:tid 1004919] [client 181.116.200.68:4798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugY-_uyupB2NyFtxJ3JgAAAF0"]
[Thu Jul 30 14:05:07.553013 2026] [security2:error] [pid 1004636:tid 1004919] [client 181.116.200.68:4798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugY-_uyupB2NyFtxJ3JgAAAF0"]
[Thu Jul 30 14:05:07.645389 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.91.199.21:41216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amugY-_uyupB2NyFtxJ3KAAAAAg"]
[Thu Jul 30 14:05:07.944878 2026] [security2:error] [pid 1004636:tid 1004847] [client 191.232.199.39:30215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-content/themes/index.php"] [unique_id "amugY-_uyupB2NyFtxJ3LwAAABg"]
[Thu Jul 30 14:05:08.059073 2026] [security2:error] [pid 1004636:tid 1004840] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/6.php"] [unique_id "amugZO_uyupB2NyFtxJ3NwAAABE"]
[Thu Jul 30 14:05:08.059203 2026] [security2:error] [pid 1004636:tid 1004840] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/6.php"] [unique_id "amugZO_uyupB2NyFtxJ3NwAAABE"]
[Thu Jul 30 14:05:08.067593 2026] [security2:error] [pid 1004636:tid 1004907] [client 20.100.187.246:24488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amugZO_uyupB2NyFtxJ3OAAAAFE"]
[Thu Jul 30 14:05:08.364358 2026] [security2:error] [pid 1004636:tid 1004832] [client 20.91.199.21:3790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amugZO_uyupB2NyFtxJ3PwAAAAo"]
[Thu Jul 30 14:05:08.416746 2026] [security2:error] [pid 1004636:tid 1004860] [client 158.158.41.78:25867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-file.php"] [unique_id "amugZO_uyupB2NyFtxJ3QQAAACQ"]
[Thu Jul 30 14:05:08.565417 2026] [security2:error] [pid 1004636:tid 1004930] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/w3lls.php"] [unique_id "amugZO_uyupB2NyFtxJ3SgAAAGc"]
[Thu Jul 30 14:05:08.565522 2026] [security2:error] [pid 1004636:tid 1004930] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/w3lls.php"] [unique_id "amugZO_uyupB2NyFtxJ3SgAAAGc"]
[Thu Jul 30 14:05:08.672525 2026] [security2:error] [pid 1004636:tid 1004941] [client 103.242.199.184:55404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugZO_uyupB2NyFtxJ3UAAAAHE"]
[Thu Jul 30 14:05:08.672673 2026] [security2:error] [pid 1004636:tid 1004941] [client 103.242.199.184:55404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugZO_uyupB2NyFtxJ3UAAAAHE"]
[Thu Jul 30 14:05:08.825965 2026] [security2:error] [pid 1004636:tid 1004770] [remote 5.161.62.209:10098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.plumbingplumb.com"] [uri "/.env"] [unique_id "amugZO_uyupB2NyFtxJ3VwAAU08"]
[Thu Jul 30 14:05:08.960350 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.100.187.246:27998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amugZO_uyupB2NyFtxJ3WwAAAAU"]
[Thu Jul 30 14:05:09.044739 2026] [security2:error] [pid 1004636:tid 1004925] [client 190.60.58.165:36068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugZO_uyupB2NyFtxJ3UQAAAGI"], referer: http://pkf.jo
[Thu Jul 30 14:05:09.047801 2026] [security2:error] [pid 1004636:tid 1004899] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/99.php"] [unique_id "amugZe_uyupB2NyFtxJ3YgAAAEk"]
[Thu Jul 30 14:05:09.047924 2026] [security2:error] [pid 1004636:tid 1004899] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/99.php"] [unique_id "amugZe_uyupB2NyFtxJ3YgAAAEk"]
[Thu Jul 30 14:05:09.403130 2026] [security2:error] [pid 1004636:tid 1004952] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amugZe_uyupB2NyFtxJ3bAAAAHw"]
[Thu Jul 30 14:05:09.470647 2026] [security2:error] [pid 1004636:tid 1004934] [client 191.232.199.39:9933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/wp-file.php"] [unique_id "amugZe_uyupB2NyFtxJ3bQAAAGs"]
[Thu Jul 30 14:05:09.524750 2026] [security2:error] [pid 1004636:tid 1004869] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-content/admin.php"] [unique_id "amugZe_uyupB2NyFtxJ3bgAAAC0"]
[Thu Jul 30 14:05:09.524865 2026] [security2:error] [pid 1004636:tid 1004869] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-content/admin.php"] [unique_id "amugZe_uyupB2NyFtxJ3bgAAAC0"]
[Thu Jul 30 14:05:09.526032 2026] [security2:error] [pid 1004636:tid 1004889] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amugZe_uyupB2NyFtxJ3bwAAAEA"]
[Thu Jul 30 14:05:09.574931 2026] [security2:error] [pid 1004636:tid 1004885] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugZO_uyupB2NyFtxJ3XQAAPD8"]
[Thu Jul 30 14:05:09.576926 2026] [security2:error] [pid 1004636:tid 1004743] [remote 74.7.243.224:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amugZe_uyupB2NyFtxJ3cwAAZTY"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:05:09.649745 2026] [security2:error] [pid 1004636:tid 1004908] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amugZe_uyupB2NyFtxJ3dwAAAFI"]
[Thu Jul 30 14:05:09.772786 2026] [security2:error] [pid 1004636:tid 1004846] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amugZe_uyupB2NyFtxJ3eAAAABc"]
[Thu Jul 30 14:05:10.004550 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/media.php"] [unique_id "amugZu_uyupB2NyFtxJ3gAAAAE0"]
[Thu Jul 30 14:05:10.004668 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/media.php"] [unique_id "amugZu_uyupB2NyFtxJ3gAAAAE0"]
[Thu Jul 30 14:05:10.280244 2026] [security2:error] [pid 1004636:tid 1004832] [client 20.52.125.110:6734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.tmb/LA.php"] [unique_id "amugZu_uyupB2NyFtxJ3igAAAAo"]
[Thu Jul 30 14:05:10.384529 2026] [security2:error] [pid 1004636:tid 1004915] [client 20.100.187.246:27484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amugZu_uyupB2NyFtxJ3jwAAAFk"]
[Thu Jul 30 14:05:10.411159 2026] [security2:error] [pid 1004636:tid 1004897] [client 158.158.41.78:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/sid3.php"] [unique_id "amugZu_uyupB2NyFtxJ3kQAAAEc"]
[Thu Jul 30 14:05:10.520613 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amugZu_uyupB2NyFtxJ3kgAAACM"]
[Thu Jul 30 14:05:10.520736 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amugZu_uyupB2NyFtxJ3kgAAACM"]
[Thu Jul 30 14:05:10.685446 2026] [security2:error] [pid 1004636:tid 1004921] [client 20.52.125.110:6695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.tmb/admin.php"] [unique_id "amugZu_uyupB2NyFtxJ3mwAAAF8"]
[Thu Jul 30 14:05:10.853249 2026] [security2:error] [pid 1004636:tid 1004920] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugZu_uyupB2NyFtxJ3iQAAXlU"]
[Thu Jul 30 14:05:11.056586 2026] [security2:error] [pid 1004636:tid 1004865] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/222.php"] [unique_id "amugZ-_uyupB2NyFtxJ3pAAAACk"]
[Thu Jul 30 14:05:11.056685 2026] [security2:error] [pid 1004636:tid 1004865] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/222.php"] [unique_id "amugZ-_uyupB2NyFtxJ3pAAAACk"]
[Thu Jul 30 14:05:11.120231 2026] [security2:error] [pid 1004636:tid 1004844] [client 20.100.187.246:27976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amugZ-_uyupB2NyFtxJ3qgAAABU"]
[Thu Jul 30 14:05:11.120260 2026] [security2:error] [pid 1004636:tid 1004856] [client 20.52.125.110:6701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.tmb/class_api.php"] [unique_id "amugZ-_uyupB2NyFtxJ3qQAAACA"]
[Thu Jul 30 14:05:11.165018 2026] [security2:error] [pid 1004636:tid 1004891] [client 158.158.41.78:26303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/themes.php"] [unique_id "amugZ-_uyupB2NyFtxJ3rQAAAEI"]
[Thu Jul 30 14:05:11.179511 2026] [proxy:error] [pid 1004636:tid 1004883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:05:11.179591 2026] [proxy_http:error] [pid 1004636:tid 1004883] [client 98.87.102.177:24540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:05:11.180210 2026] [proxy:error] [pid 1004636:tid 1004883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:05:11.180257 2026] [proxy_http:error] [pid 1004636:tid 1004883] [client 98.87.102.177:24540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:05:11.189648 2026] [proxy:error] [pid 1004636:tid 1004926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:05:11.189715 2026] [proxy_http:error] [pid 1004636:tid 1004926] [client 18.211.55.47:62376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:05:11.190401 2026] [proxy:error] [pid 1004636:tid 1004926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:05:11.190454 2026] [proxy_http:error] [pid 1004636:tid 1004926] [client 18.211.55.47:62376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:05:11.348780 2026] [security2:error] [pid 1004636:tid 1004858] [client 188.119.13.37:11079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugZ-_uyupB2NyFtxJ3twAAACI"]
[Thu Jul 30 14:05:11.577683 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.52.125.110:6689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amugZ-_uyupB2NyFtxJ3vwAAAFU"]
[Thu Jul 30 14:05:11.607700 2026] [security2:error] [pid 1004636:tid 1004908] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-load.php"] [unique_id "amugZ-_uyupB2NyFtxJ3wgAAAFI"]
[Thu Jul 30 14:05:11.607805 2026] [security2:error] [pid 1004636:tid 1004908] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-load.php"] [unique_id "amugZ-_uyupB2NyFtxJ3wgAAAFI"]
[Thu Jul 30 14:05:11.947392 2026] [security2:error] [pid 1004636:tid 1004846] [client 77.83.36.161:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amugZ-_uyupB2NyFtxJ3zQAAABc"]
[Thu Jul 30 14:05:11.983030 2026] [security2:error] [pid 1004636:tid 1004905] [client 188.119.13.37:10287] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugZ-_uyupB2NyFtxJ3zwAAAE8"]
[Thu Jul 30 14:05:12.018744 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.52.125.110:6733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.tmb/wp-login.php"] [unique_id "amugaO_uyupB2NyFtxJ30AAAAEs"]
[Thu Jul 30 14:05:12.056496 2026] [security2:error] [pid 1004636:tid 1004841] [client 20.100.187.246:20591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amugaO_uyupB2NyFtxJ30QAAABI"]
[Thu Jul 30 14:05:12.148908 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-content/themes/index.php"] [unique_id "amugaO_uyupB2NyFtxJ31gAAAFQ"]
[Thu Jul 30 14:05:12.149033 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-content/themes/index.php"] [unique_id "amugaO_uyupB2NyFtxJ31gAAAFQ"]
[Thu Jul 30 14:05:12.304558 2026] [core:notice] [pid 1004636:tid 1004915] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:12.430258 2026] [core:notice] [pid 1004636:tid 1004943] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:12.444661 2026] [security2:error] [pid 1004636:tid 1004927] [client 20.52.125.110:6660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amugaO_uyupB2NyFtxJ33wAAAGQ"]
[Thu Jul 30 14:05:12.517273 2026] [security2:error] [pid 1004636:tid 1004860] [client 77.83.36.161:55575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amugaO_uyupB2NyFtxJ34wAAACQ"]
[Thu Jul 30 14:05:12.622431 2026] [security2:error] [pid 1004636:tid 1004921] [client 188.119.13.37:11254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugaO_uyupB2NyFtxJ36AAAAF8"]
[Thu Jul 30 14:05:12.668855 2026] [security2:error] [pid 1004636:tid 1004899] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-admin/js/index.php"] [unique_id "amugaO_uyupB2NyFtxJ36QAAAEk"]
[Thu Jul 30 14:05:12.668935 2026] [security2:error] [pid 1004636:tid 1004899] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-admin/js/index.php"] [unique_id "amugaO_uyupB2NyFtxJ36QAAAEk"]
[Thu Jul 30 14:05:12.778812 2026] [security2:error] [pid 1004636:tid 1004904] [client 191.232.199.39:9991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fintn.com"] [uri "/sid3.php"] [unique_id "amugaO_uyupB2NyFtxJ37gAAAE4"]
[Thu Jul 30 14:05:12.930751 2026] [security2:error] [pid 1004636:tid 1004877] [client 20.52.125.110:6723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/991176.php"] [unique_id "amugaO_uyupB2NyFtxJ38AAAADU"]
[Thu Jul 30 14:05:13.061802 2026] [security2:error] [pid 1004636:tid 1004950] [client 77.83.36.161:55895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amugae_uyupB2NyFtxJ39QAAAHo"]
[Thu Jul 30 14:05:13.221689 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/memberfuns.php"] [unique_id "amugae_uyupB2NyFtxJ3-gAAAFU"]
[Thu Jul 30 14:05:13.221792 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/memberfuns.php"] [unique_id "amugae_uyupB2NyFtxJ3-gAAAFU"]
[Thu Jul 30 14:05:13.240521 2026] [security2:error] [pid 1004636:tid 1004885] [client 188.119.13.37:10244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugae_uyupB2NyFtxJ3_AAAADw"]
[Thu Jul 30 14:05:13.358623 2026] [security2:error] [pid 1004636:tid 1004893] [client 20.52.125.110:6725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amugae_uyupB2NyFtxJ4AQAAAEQ"]
[Thu Jul 30 14:05:13.694318 2026] [security2:error] [pid 1004636:tid 1004862] [client 172.213.208.20:34871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-block.php"] [unique_id "amugae_uyupB2NyFtxJ4EQAAACY"]
[Thu Jul 30 14:05:13.742035 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/orange3.php"] [unique_id "amugae_uyupB2NyFtxJ4EgAAAB0"]
[Thu Jul 30 14:05:13.742152 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/orange3.php"] [unique_id "amugae_uyupB2NyFtxJ4EgAAAB0"]
[Thu Jul 30 14:05:13.818768 2026] [security2:error] [pid 1004636:tid 1004902] [client 20.52.125.110:6721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amugae_uyupB2NyFtxJ4GgAAAEw"]
[Thu Jul 30 14:05:13.864518 2026] [security2:error] [pid 1004636:tid 1004898] [client 158.158.41.78:46968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/plugins/index.php"] [unique_id "amugae_uyupB2NyFtxJ4GwAAAEg"]
[Thu Jul 30 14:05:13.866640 2026] [security2:error] [pid 1004636:tid 1004828] [client 188.119.13.37:11273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugae_uyupB2NyFtxJ4HAAAAAY"]
[Thu Jul 30 14:05:13.974286 2026] [security2:error] [pid 1004636:tid 1004906] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amugae_uyupB2NyFtxJ4FgAAAFA"]
[Thu Jul 30 14:05:13.990570 2026] [security2:error] [pid 1004636:tid 1004944] [client 20.100.187.246:26124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amugae_uyupB2NyFtxJ4HwAAAHQ"]
[Thu Jul 30 14:05:14.011706 2026] [security2:error] [pid 1004636:tid 1004866] [client 20.91.199.21:3641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amugau_uyupB2NyFtxJ4IQAAACo"]
[Thu Jul 30 14:05:14.275437 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.52.125.110:6737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amugau_uyupB2NyFtxJ4KgAAAG4"]
[Thu Jul 30 14:05:14.277025 2026] [security2:error] [pid 1004636:tid 1004861] [client 189.6.88.213:52684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugau_uyupB2NyFtxJ4KwAAACU"]
[Thu Jul 30 14:05:14.277117 2026] [security2:error] [pid 1004636:tid 1004861] [client 189.6.88.213:52684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugau_uyupB2NyFtxJ4KwAAACU"]
[Thu Jul 30 14:05:14.282971 2026] [security2:error] [pid 1004636:tid 1004883] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amugau_uyupB2NyFtxJ4LAAAADo"]
[Thu Jul 30 14:05:14.283135 2026] [security2:error] [pid 1004636:tid 1004883] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amugau_uyupB2NyFtxJ4LAAAADo"]
[Thu Jul 30 14:05:14.337693 2026] [security2:error] [pid 1004636:tid 1004863] [client 14.191.214.217:32217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugau_uyupB2NyFtxJ4JQAAACc"], referer: http://pkf.jo
[Thu Jul 30 14:05:14.351236 2026] [security2:error] [pid 1004636:tid 1004872] [client 172.213.208.20:41246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "amugau_uyupB2NyFtxJ4LgAAADA"]
[Thu Jul 30 14:05:14.493742 2026] [security2:error] [pid 1004636:tid 1004926] [client 188.119.13.37:10072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugau_uyupB2NyFtxJ4MwAAAGM"]
[Thu Jul 30 14:05:14.719953 2026] [security2:error] [pid 1004636:tid 1004822] [client 20.52.125.110:6700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amugau_uyupB2NyFtxJ4PQAAAAA"]
[Thu Jul 30 14:05:14.787281 2026] [security2:error] [pid 1004636:tid 1004826] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-the.php"] [unique_id "amugau_uyupB2NyFtxJ4PwAAAAQ"]
[Thu Jul 30 14:05:14.787386 2026] [security2:error] [pid 1004636:tid 1004826] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/wp-the.php"] [unique_id "amugau_uyupB2NyFtxJ4PwAAAAQ"]
[Thu Jul 30 14:05:15.035246 2026] [security2:error] [pid 1004636:tid 1004930] [client 153.117.20.132:57514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugau_uyupB2NyFtxJ4PgAAAGc"], referer: http://pkf.jo
[Thu Jul 30 14:05:15.039458 2026] [security2:error] [pid 1004636:tid 1004869] [client 20.91.199.21:41221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuga-_uyupB2NyFtxJ4RQAAAC0"]
[Thu Jul 30 14:05:15.102632 2026] [core:error] [pid 1004636:tid 1004955] [client 66.249.68.169:49493] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:15.102657 2026] [core:error] [pid 1004636:tid 1004955] [client 66.249.68.169:49493] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:15.105316 2026] [security2:error] [pid 1004636:tid 1004839] [client 188.119.13.37:10246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuga-_uyupB2NyFtxJ4SwAAABA"]
[Thu Jul 30 14:05:15.198169 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.52.125.110:6676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuga-_uyupB2NyFtxJ4TAAAABQ"]
[Thu Jul 30 14:05:15.296640 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/crgio.php"] [unique_id "amuga-_uyupB2NyFtxJ4UQAAABk"]
[Thu Jul 30 14:05:15.296735 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/crgio.php"] [unique_id "amuga-_uyupB2NyFtxJ4UQAAABk"]
[Thu Jul 30 14:05:15.628050 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.100.187.246:24532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuga-_uyupB2NyFtxJ4YAAAAFU"]
[Thu Jul 30 14:05:15.670856 2026] [core:error] [pid 1004636:tid 1004948] [client 172.213.208.20:43647] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:15.670877 2026] [core:error] [pid 1004636:tid 1004948] [client 172.213.208.20:43647] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:15.727483 2026] [security2:error] [pid 1004636:tid 1004849] [client 188.119.13.37:10236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amuga-_uyupB2NyFtxJ4YwAAABo"]
[Thu Jul 30 14:05:15.777345 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.52.125.110:6662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuga-_uyupB2NyFtxJ4awAAADQ"]
[Thu Jul 30 14:05:15.803797 2026] [security2:error] [pid 1004636:tid 1004866] [client 217.142.18.143:9060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuga-_uyupB2NyFtxJ4WgAAACo"], referer: http://pkf.jo
[Thu Jul 30 14:05:15.804822 2026] [security2:error] [pid 1004636:tid 1004871] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ws13.php"] [unique_id "amuga-_uyupB2NyFtxJ4bAAAAC8"]
[Thu Jul 30 14:05:15.804903 2026] [security2:error] [pid 1004636:tid 1004871] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ws13.php"] [unique_id "amuga-_uyupB2NyFtxJ4bAAAAC8"]
[Thu Jul 30 14:05:16.062455 2026] [security2:error] [pid 1004636:tid 1004878] [client 158.158.41.78:18685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/images/index.php"] [unique_id "amugbO_uyupB2NyFtxJ4dQAAADY"]
[Thu Jul 30 14:05:16.064972 2026] [security2:error] [pid 1004636:tid 1004886] [client 196.189.226.6:47699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuga-_uyupB2NyFtxJ4ZgAAAD0"], referer: http://pkf.jo
[Thu Jul 30 14:05:16.204694 2026] [security2:error] [pid 1004636:tid 1004938] [client 131.161.178.154:62584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuga-_uyupB2NyFtxJ4bgAAAG4"], referer: http://pkf.jo
[Thu Jul 30 14:05:16.215736 2026] [security2:error] [pid 1004636:tid 1004904] [client 103.190.40.154:1685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugbO_uyupB2NyFtxJ4egAAAE4"]
[Thu Jul 30 14:05:16.215895 2026] [security2:error] [pid 1004636:tid 1004904] [client 103.190.40.154:1685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugbO_uyupB2NyFtxJ4egAAAE4"]
[Thu Jul 30 14:05:16.255130 2026] [core:notice] [pid 1004636:tid 1004929] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:16.261701 2026] [security2:error] [pid 1004636:tid 1004858] [client 20.52.125.110:6728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amugbO_uyupB2NyFtxJ4fQAAACI"]
[Thu Jul 30 14:05:16.285329 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/srontol.php"] [unique_id "amugbO_uyupB2NyFtxJ4ggAAAH4"]
[Thu Jul 30 14:05:16.285427 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/srontol.php"] [unique_id "amugbO_uyupB2NyFtxJ4ggAAAH4"]
[Thu Jul 30 14:05:16.400647 2026] [security2:error] [pid 1004636:tid 1004950] [client 20.100.187.246:5974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amugbO_uyupB2NyFtxJ4gwAAAHo"]
[Thu Jul 30 14:05:16.544456 2026] [security2:error] [pid 1004636:tid 1004952] [client 172.213.208.20:41242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/classwithtostring.php"] [unique_id "amugbO_uyupB2NyFtxJ4iAAAAHw"]
[Thu Jul 30 14:05:16.565190 2026] [security2:error] [pid 1004636:tid 1004908] [client 113.184.112.100:38938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugbO_uyupB2NyFtxJ4fwAAAFI"], referer: http://pkf.jo
[Thu Jul 30 14:05:16.753839 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.52.125.110:6658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amugbO_uyupB2NyFtxJ4kQAAAE0"]
[Thu Jul 30 14:05:16.788674 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/miru3.php"] [unique_id "amugbO_uyupB2NyFtxJ4kgAAAAg"]
[Thu Jul 30 14:05:16.788783 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/miru3.php"] [unique_id "amugbO_uyupB2NyFtxJ4kgAAAAg"]
[Thu Jul 30 14:05:16.803074 2026] [core:notice] [pid 1004636:tid 1004831] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:16.885003 2026] [security2:error] [pid 1004636:tid 1004888] [client 113.88.76.2:62634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amugau_uyupB2NyFtxJ4OAAAAD8"]
[Thu Jul 30 14:05:17.202767 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.52.125.110:6708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amugbe_uyupB2NyFtxJ4oQAAAAY"]
[Thu Jul 30 14:05:17.263839 2026] [security2:error] [pid 1004636:tid 1004896] [client 20.100.187.246:24154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amugbe_uyupB2NyFtxJ4owAAAEY"]
[Thu Jul 30 14:05:17.292544 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ingfo.php"] [unique_id "amugbe_uyupB2NyFtxJ4pAAAAAs"]
[Thu Jul 30 14:05:17.292666 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ingfo.php"] [unique_id "amugbe_uyupB2NyFtxJ4pAAAAAs"]
[Thu Jul 30 14:05:17.386465 2026] [security2:error] [pid 1004636:tid 1004864] [client 186.132.229.151:51038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugbe_uyupB2NyFtxJ4nAAAACg"], referer: http://pkf.jo
[Thu Jul 30 14:05:17.390041 2026] [security2:error] [pid 1004636:tid 1004700] [remote 57.141.0.65:27952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amugbe_uyupB2NyFtxJ4qgAAcww"]
[Thu Jul 30 14:05:17.653689 2026] [security2:error] [pid 1004636:tid 1004948] [client 82.65.68.25:42732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugbe_uyupB2NyFtxJ4qQAAAHg"], referer: http://pkf.jo
[Thu Jul 30 14:05:17.701162 2026] [security2:error] [pid 1004636:tid 1004866] [client 20.52.125.110:6738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amugbe_uyupB2NyFtxJ4tAAAACo"]
[Thu Jul 30 14:05:17.741009 2026] [security2:error] [pid 1004636:tid 1004859] [client 79.230.51.80:43848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugbe_uyupB2NyFtxJ4qwAAACM"], referer: http://pkf.jo
[Thu Jul 30 14:05:17.804477 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ey5.php"] [unique_id "amugbe_uyupB2NyFtxJ4vAAAAFM"]
[Thu Jul 30 14:05:17.804606 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/ey5.php"] [unique_id "amugbe_uyupB2NyFtxJ4vAAAAFM"]
[Thu Jul 30 14:05:18.006190 2026] [security2:error] [pid 1004636:tid 1004923] [client 185.187.78.230:47117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugbe_uyupB2NyFtxJ4tQAAAGA"], referer: http://pkf.jo
[Thu Jul 30 14:05:18.086949 2026] [security2:error] [pid 1004636:tid 1004872] [client 181.116.200.68:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugbu_uyupB2NyFtxJ4xgAAADA"]
[Thu Jul 30 14:05:18.087099 2026] [security2:error] [pid 1004636:tid 1004872] [client 181.116.200.68:61185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugbu_uyupB2NyFtxJ4xgAAADA"]
[Thu Jul 30 14:05:18.121863 2026] [security2:error] [pid 1004636:tid 1004885] [client 20.52.125.110:6735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amugbu_uyupB2NyFtxJ4yQAAADw"]
[Thu Jul 30 14:05:18.301423 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fine.php"] [unique_id "amugbu_uyupB2NyFtxJ40QAAAEs"]
[Thu Jul 30 14:05:18.301548 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.prolineroofingservices.homes"] [uri "/fine.php"] [unique_id "amugbu_uyupB2NyFtxJ40QAAAEs"]
[Thu Jul 30 14:05:18.478790 2026] [security2:error] [pid 1004636:tid 1004950] [client 41.208.191.112:18849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugbu_uyupB2NyFtxJ4xwAAAHo"], referer: http://pkf.jo
[Thu Jul 30 14:05:18.575968 2026] [security2:error] [pid 1004636:tid 1004824] [client 20.52.125.110:6713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amugbu_uyupB2NyFtxJ43AAAAAI"]
[Thu Jul 30 14:05:18.748272 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.100.187.246:5990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amugbu_uyupB2NyFtxJ47gAAAA8"]
[Thu Jul 30 14:05:18.831963 2026] [security2:error] [pid 1004636:tid 1004893] [client 186.168.243.163:60520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugbu_uyupB2NyFtxJ42gAAAEQ"], referer: http://pkf.jo
[Thu Jul 30 14:05:19.000467 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.52.125.110:6671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amugbu_uyupB2NyFtxJ4-wAAAAY"]
[Thu Jul 30 14:05:19.111305 2026] [security2:error] [pid 1004636:tid 1004836] [client 172.213.208.20:39767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/test1.php"] [unique_id "amugb-_uyupB2NyFtxJ4_gAAAA4"]
[Thu Jul 30 14:05:19.327388 2026] [security2:error] [pid 1004636:tid 1004883] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/info.php"] [unique_id "amugb-_uyupB2NyFtxJ5BgAAADo"]
[Thu Jul 30 14:05:19.375525 2026] [security2:error] [pid 1004636:tid 1004924] [client 103.242.199.184:55970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugb-_uyupB2NyFtxJ5CAAAAGE"]
[Thu Jul 30 14:05:19.375686 2026] [security2:error] [pid 1004636:tid 1004924] [client 103.242.199.184:55970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugb-_uyupB2NyFtxJ5CAAAAGE"]
[Thu Jul 30 14:05:19.398542 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.52.125.110:6683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/amaxx.php"] [unique_id "amugb-_uyupB2NyFtxJ5CwAAAEU"]
[Thu Jul 30 14:05:19.550122 2026] [core:notice] [pid 1004636:tid 1004764] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:19.556764 2026] [security2:error] [pid 1004636:tid 1004873] [client 20.100.187.246:5752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amugb-_uyupB2NyFtxJ5EAAAADE"]
[Thu Jul 30 14:05:19.568616 2026] [security2:error] [pid 1004636:tid 1004907] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/info.php%257e"] [unique_id "amugb-_uyupB2NyFtxJ5EQAAAFE"]
[Thu Jul 30 14:05:19.810253 2026] [security2:error] [pid 1004636:tid 1004952] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/info.php%28%28"] [unique_id "amugb-_uyupB2NyFtxJ5LgAAAHw"]
[Thu Jul 30 14:05:19.845221 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.52.125.110:6698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/bek.php"] [unique_id "amugb-_uyupB2NyFtxJ5LwAAAH4"]
[Thu Jul 30 14:05:19.872188 2026] [core:error] [pid 1004636:tid 1004840] [client 172.213.208.20:22062] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:19.872207 2026] [core:error] [pid 1004636:tid 1004840] [client 172.213.208.20:22062] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:19.888462 2026] [core:notice] [pid 1004636:tid 1004778] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:19.984034 2026] [security2:error] [pid 1004636:tid 1004915] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugb-_uyupB2NyFtxJ5BwAAWS0"]
[Thu Jul 30 14:05:20.056060 2026] [security2:error] [pid 1004636:tid 1004955] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/info.php/"] [unique_id "amugcO_uyupB2NyFtxJ5QAAAAH8"]
[Thu Jul 30 14:05:20.260658 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.52.125.110:6688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amugcO_uyupB2NyFtxJ5RgAAAAg"]
[Thu Jul 30 14:05:20.666835 2026] [security2:error] [pid 1004636:tid 1004896] [client 20.52.125.110:6729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/class.api.php"] [unique_id "amugcO_uyupB2NyFtxJ5VQAAAEY"]
[Thu Jul 30 14:05:21.075906 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.100.187.246:26568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amugcO_uyupB2NyFtxJ5XQAAAC4"]
[Thu Jul 30 14:05:21.110346 2026] [security2:error] [pid 1004636:tid 1004834] [client 172.213.208.20:43607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/images/index.php"] [unique_id "amugce_uyupB2NyFtxJ5ZwAAAAw"]
[Thu Jul 30 14:05:21.203339 2026] [security2:error] [pid 1004636:tid 1004874] [client 20.52.125.110:6731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/cong.php"] [unique_id "amugce_uyupB2NyFtxJ5agAAADI"]
[Thu Jul 30 14:05:21.573837 2026] [security2:error] [pid 1004636:tid 1004917] [client 158.158.41.78:24688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/num.php"] [unique_id "amugce_uyupB2NyFtxJ5eQAAAFs"]
[Thu Jul 30 14:05:21.626867 2026] [security2:error] [pid 1004636:tid 1004858] [client 20.52.125.110:6753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/content.php"] [unique_id "amugce_uyupB2NyFtxJ5fAAAACI"]
[Thu Jul 30 14:05:21.703078 2026] [security2:error] [pid 1004636:tid 1004877] [client 20.91.199.21:15888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/banners/about.php"] [unique_id "amugce_uyupB2NyFtxJ5fwAAADU"]
[Thu Jul 30 14:05:22.107457 2026] [security2:error] [pid 1004636:tid 1004840] [client 20.52.125.110:6702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amugcu_uyupB2NyFtxJ5jQAAABE"]
[Thu Jul 30 14:05:22.151994 2026] [core:notice] [pid 1004636:tid 1004807] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:22.155410 2026] [security2:error] [pid 1004636:tid 1004954] [client 74.7.244.39:44604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amugcu_uyupB2NyFtxJ5jwAAfnM"], referer: https://blackrockanimalhospital.com/robots.txt
[Thu Jul 30 14:05:22.552538 2026] [security2:error] [pid 1004636:tid 1004888] [client 20.52.125.110:6661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/elp.php"] [unique_id "amugcu_uyupB2NyFtxJ5nwAAAD8"]
[Thu Jul 30 14:05:22.581114 2026] [security2:error] [pid 1004636:tid 1004897] [client 20.91.199.21:3982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/about.php"] [unique_id "amugcu_uyupB2NyFtxJ5oAAAAEc"]
[Thu Jul 30 14:05:23.060531 2026] [security2:error] [pid 1004636:tid 1004947] [client 20.52.125.110:6780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amugc-_uyupB2NyFtxJ5rwAAAHc"]
[Thu Jul 30 14:05:23.187427 2026] [security2:error] [pid 1004636:tid 1004879] [client 135.119.63.61:36245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/011i.php"] [unique_id "amugc-_uyupB2NyFtxJ5sQAAADc"]
[Thu Jul 30 14:05:23.267930 2026] [core:notice] [pid 1004636:tid 1004825] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:23.503175 2026] [security2:error] [pid 1004636:tid 1004943] [client 20.91.199.21:19856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/about.php"] [unique_id "amugc-_uyupB2NyFtxJ5uwAAAHM"]
[Thu Jul 30 14:05:23.503460 2026] [security2:error] [pid 1004636:tid 1004945] [client 20.52.125.110:6711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amugc-_uyupB2NyFtxJ5vAAAAHU"]
[Thu Jul 30 14:05:23.942316 2026] [security2:error] [pid 1004636:tid 1004931] [client 20.52.125.110:6751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amugc-_uyupB2NyFtxJ50AAAAGg"]
[Thu Jul 30 14:05:24.234593 2026] [core:error] [pid 1004636:tid 1004952] [client 172.213.208.20:22066] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:24.234614 2026] [core:error] [pid 1004636:tid 1004952] [client 172.213.208.20:22066] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:24.325399 2026] [security2:error] [pid 1004636:tid 1004923] [client 135.119.63.61:7762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/03a005685d.php"] [unique_id "amugdO_uyupB2NyFtxJ53QAAAGA"]
[Thu Jul 30 14:05:24.336549 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.52.125.110:6785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amugdO_uyupB2NyFtxJ53wAAAEs"]
[Thu Jul 30 14:05:24.398227 2026] [core:notice] [pid 1004636:tid 1004704] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:24.806483 2026] [security2:error] [pid 1004636:tid 1004893] [client 20.52.125.110:6740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amugdO_uyupB2NyFtxJ57gAAAEQ"]
[Thu Jul 30 14:05:24.981091 2026] [security2:error] [pid 1004636:tid 1004842] [client 20.91.199.21:18514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amugdO_uyupB2NyFtxJ5-AAAABM"]
[Thu Jul 30 14:05:25.005415 2026] [security2:error] [pid 1004636:tid 1004828] [client 189.6.88.213:53243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugde_uyupB2NyFtxJ5-QAAAAY"]
[Thu Jul 30 14:05:25.005520 2026] [security2:error] [pid 1004636:tid 1004828] [client 189.6.88.213:53243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugde_uyupB2NyFtxJ5-QAAAAY"]
[Thu Jul 30 14:05:25.089481 2026] [security2:error] [pid 1004636:tid 1004948] [client 158.158.41.78:18647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/images/admin.php"] [unique_id "amugde_uyupB2NyFtxJ5-gAAAHg"]
[Thu Jul 30 14:05:25.267263 2026] [security2:error] [pid 1004636:tid 1004866] [client 20.52.125.110:6778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amugde_uyupB2NyFtxJ6AwAAACo"]
[Thu Jul 30 14:05:25.665747 2026] [security2:error] [pid 1004636:tid 1004907] [client 20.52.125.110:6697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amugde_uyupB2NyFtxJ6DgAAAFE"]
[Thu Jul 30 14:05:25.861045 2026] [security2:error] [pid 1004636:tid 1004827] [client 135.119.63.61:7805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/403.php"] [unique_id "amugde_uyupB2NyFtxJ6EwAAAAU"]
[Thu Jul 30 14:05:26.159746 2026] [security2:error] [pid 1004636:tid 1004931] [client 20.52.125.110:6736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amugdu_uyupB2NyFtxJ6HwAAAGg"]
[Thu Jul 30 14:05:26.204676 2026] [security2:error] [pid 1004636:tid 1004925] [client 158.158.41.78:27547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/upgrade/index.php"] [unique_id "amugdu_uyupB2NyFtxJ6IQAAAGI"]
[Thu Jul 30 14:05:26.532045 2026] [security2:error] [pid 1004636:tid 1004878] [client 172.213.208.20:22029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/asd.php"] [unique_id "amugdu_uyupB2NyFtxJ6KQAAADY"]
[Thu Jul 30 14:05:26.579662 2026] [security2:error] [pid 1004636:tid 1004941] [client 20.52.125.110:6712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amugdu_uyupB2NyFtxJ6LQAAAHE"]
[Thu Jul 30 14:05:27.054155 2026] [security2:error] [pid 1004636:tid 1004884] [client 20.52.125.110:6706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amugd-_uyupB2NyFtxJ6OwAAADs"]
[Thu Jul 30 14:05:27.095420 2026] [security2:error] [pid 1004636:tid 1004835] [client 135.119.63.61:7785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/404.php"] [unique_id "amugd-_uyupB2NyFtxJ6PAAAAA0"]
[Thu Jul 30 14:05:27.120701 2026] [security2:error] [pid 1004636:tid 1004860] [client 103.190.40.154:20834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugd-_uyupB2NyFtxJ6QAAAACQ"]
[Thu Jul 30 14:05:27.120824 2026] [security2:error] [pid 1004636:tid 1004860] [client 103.190.40.154:20834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugd-_uyupB2NyFtxJ6QAAAACQ"]
[Thu Jul 30 14:05:27.623828 2026] [security2:error] [pid 1004636:tid 1004865] [client 50.6.43.217:57790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amugdu_uyupB2NyFtxJ6NQAAACk"]
[Thu Jul 30 14:05:27.661449 2026] [security2:error] [pid 1004636:tid 1004864] [client 20.52.125.110:6749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amugd-_uyupB2NyFtxJ6TwAAACg"]
[Thu Jul 30 14:05:27.722233 2026] [security2:error] [pid 1004636:tid 1004875] [client 158.158.41.78:23008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "amugd-_uyupB2NyFtxJ6UQAAADM"]
[Thu Jul 30 14:05:27.863910 2026] [security2:error] [pid 1004636:tid 1004945] [client 223.109.252.211:39346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/cloudbust-thunder-knit-fabric-low-sneakers/"] [unique_id "amugd-_uyupB2NyFtxJ6UwAAAHU"]
[Thu Jul 30 14:05:27.864069 2026] [security2:error] [pid 1004636:tid 1004945] [client 223.109.252.211:39346] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/cloudbust-thunder-knit-fabric-low-sneakers/"] [unique_id "amugd-_uyupB2NyFtxJ6UwAAAHU"]
[Thu Jul 30 14:05:28.116529 2026] [security2:error] [pid 1004636:tid 1004938] [client 135.119.63.61:23248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/aa.php"] [unique_id "amugeO_uyupB2NyFtxJ6XgAAAG4"]
[Thu Jul 30 14:05:28.167020 2026] [security2:error] [pid 1004636:tid 1004953] [client 20.52.125.110:6691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amugeO_uyupB2NyFtxJ6YQAAAH0"]
[Thu Jul 30 14:05:28.336678 2026] [security2:error] [pid 1004636:tid 1004910] [client 188.119.13.37:10188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "jcsgoeastwood.org"] [uri "/index.php"] [unique_id "amugeO_uyupB2NyFtxJ6bAAAAFQ"]
[Thu Jul 30 14:05:28.339701 2026] [security2:error] [pid 1004636:tid 1004914] [client 50.6.43.217:57804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amugd-_uyupB2NyFtxJ6SwAAAFg"]
[Thu Jul 30 14:05:28.455996 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.91.199.21:18515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amugeO_uyupB2NyFtxJ6bgAAADA"]
[Thu Jul 30 14:05:28.651650 2026] [security2:error] [pid 1004636:tid 1004830] [client 181.116.200.68:29677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugeO_uyupB2NyFtxJ6egAAAAg"]
[Thu Jul 30 14:05:28.651765 2026] [security2:error] [pid 1004636:tid 1004830] [client 181.116.200.68:29677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugeO_uyupB2NyFtxJ6egAAAAg"]
[Thu Jul 30 14:05:28.713415 2026] [security2:error] [pid 1004636:tid 1004897] [client 158.158.41.78:33356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/gifclass.php"] [unique_id "amugeO_uyupB2NyFtxJ6fQAAAEc"]
[Thu Jul 30 14:05:28.719436 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.52.125.110:6682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amugeO_uyupB2NyFtxJ6fgAAAA8"]
[Thu Jul 30 14:05:29.212738 2026] [security2:error] [pid 1004636:tid 1004934] [client 20.52.125.110:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amugee_uyupB2NyFtxJ6jwAAAGs"]
[Thu Jul 30 14:05:29.393060 2026] [security2:error] [pid 1004636:tid 1004854] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugeO_uyupB2NyFtxJ6ggAAAB4"]
[Thu Jul 30 14:05:29.438926 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.203.148.31:62536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/json.php"] [unique_id "amugee_uyupB2NyFtxJ6nAAAAEU"]
[Thu Jul 30 14:05:29.508100 2026] [security2:error] [pid 1004636:tid 1004903] [client 158.158.41.78:18670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/plugins/admin.php"] [unique_id "amugee_uyupB2NyFtxJ6nQAAAE0"]
[Thu Jul 30 14:05:29.584777 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.91.199.21:19900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/img/about.php"] [unique_id "amugee_uyupB2NyFtxJ6nwAAAFM"]
[Thu Jul 30 14:05:29.649085 2026] [security2:error] [pid 1004636:tid 1004863] [client 188.213.202.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.202.213.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tiger388.shop"] [uri "/wp-login.php"] [unique_id "amugee_uyupB2NyFtxJ6lgAAACc"]
[Thu Jul 30 14:05:29.693385 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.52.125.110:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amugee_uyupB2NyFtxJ6oQAAAG4"]
[Thu Jul 30 14:05:29.947847 2026] [security2:error] [pid 1004636:tid 1004910] [client 103.242.199.184:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugee_uyupB2NyFtxJ6rAAAAFQ"]
[Thu Jul 30 14:05:29.948011 2026] [security2:error] [pid 1004636:tid 1004910] [client 103.242.199.184:56526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugee_uyupB2NyFtxJ6rAAAAFQ"]
[Thu Jul 30 14:05:29.973708 2026] [security2:error] [pid 1004636:tid 1004952] [client 216.73.216.4:7118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.aaapropertiesph.com"] [uri "/index.php"] [unique_id "amugee_uyupB2NyFtxJ6qQAAfEg"]
[Thu Jul 30 14:05:30.171630 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.52.125.110:6681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amugeu_uyupB2NyFtxJ6sgAAAAk"]
[Thu Jul 30 14:05:30.318832 2026] [security2:error] [pid 1004636:tid 1004927] [client 43.203.254.38:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.254.203.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-login.php"] [unique_id "amugeu_uyupB2NyFtxJ6twAAAGQ"]
[Thu Jul 30 14:05:30.604509 2026] [security2:error] [pid 1004636:tid 1004951] [client 20.52.125.110:6679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amugeu_uyupB2NyFtxJ6wQAAAHs"]
[Thu Jul 30 14:05:30.702436 2026] [security2:error] [pid 1004636:tid 1004876] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/phpinfo.php"] [unique_id "amugeu_uyupB2NyFtxJ6wgAAADQ"]
[Thu Jul 30 14:05:30.946795 2026] [security2:error] [pid 1004636:tid 1004857] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/phpinfo.php%255f"] [unique_id "amugeu_uyupB2NyFtxJ6zAAAACE"]
[Thu Jul 30 14:05:31.103096 2026] [security2:error] [pid 1004636:tid 1004918] [client 20.52.125.110:6763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuge-_uyupB2NyFtxJ60AAAAFw"]
[Thu Jul 30 14:05:31.190342 2026] [security2:error] [pid 1004636:tid 1004865] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/phpinfo.php%253c"] [unique_id "amuge-_uyupB2NyFtxJ61AAAACk"]
[Thu Jul 30 14:05:31.314562 2026] [security2:error] [pid 1004636:tid 1004892] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/phpinfo.php%255d"] [unique_id "amuge-_uyupB2NyFtxJ62AAAAEM"]
[Thu Jul 30 14:05:31.338083 2026] [security2:error] [pid 1004636:tid 1004891] [client 135.119.63.61:50382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/011i.php"] [unique_id "amuge-_uyupB2NyFtxJ63AAAAEI"]
[Thu Jul 30 14:05:31.494894 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.203.148.31:37361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/mini.php"] [unique_id "amuge-_uyupB2NyFtxJ63gAAADk"]
[Thu Jul 30 14:05:31.502325 2026] [security2:error] [pid 1004636:tid 1004877] [client 20.52.125.110:6717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuge-_uyupB2NyFtxJ63wAAADU"]
[Thu Jul 30 14:05:31.752324 2026] [security2:error] [pid 1004636:tid 1004861] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuge-_uyupB2NyFtxJ60wAAACU"]
[Thu Jul 30 14:05:31.846094 2026] [security2:error] [pid 1004636:tid 1004942] [client 135.119.63.61:38672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/aafewc0k.php"] [unique_id "amuge-_uyupB2NyFtxJ66QAAAHI"]
[Thu Jul 30 14:05:31.964880 2026] [security2:error] [pid 1004636:tid 1004869] [client 20.52.125.110:6684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuge-_uyupB2NyFtxJ67QAAAC0"]
[Thu Jul 30 14:05:32.283618 2026] [security2:error] [pid 1004636:tid 1004841] [client 172.213.208.20:22041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amugfO_uyupB2NyFtxJ68wAAABI"]
[Thu Jul 30 14:05:32.324013 2026] [core:notice] [pid 1004636:tid 1004758] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:32.380823 2026] [security2:error] [pid 1004636:tid 1004936] [client 20.52.125.110:6816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amugfO_uyupB2NyFtxJ6-wAAAGw"]
[Thu Jul 30 14:05:32.495298 2026] [security2:error] [pid 1004636:tid 1004906] [client 20.203.148.31:58301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amugfO_uyupB2NyFtxJ6_wAAAFA"]
[Thu Jul 30 14:05:32.789637 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.52.125.110:6724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amugfO_uyupB2NyFtxJ7BQAAACQ"]
[Thu Jul 30 14:05:32.791209 2026] [core:notice] [pid 1004636:tid 1004777] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:32.999498 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.203.148.31:58298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/kj.php"] [unique_id "amugfO_uyupB2NyFtxJ7DwAAAAY"]
[Thu Jul 30 14:05:33.024082 2026] [core:notice] [pid 1004636:tid 1004743] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:33.106809 2026] [security2:error] [pid 1004636:tid 1004920] [client 103.82.27.41:62967] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.kicksity.com"] [uri "/"] [unique_id "amugfe_uyupB2NyFtxJ7EgAAAF4"]
[Thu Jul 30 14:05:33.264100 2026] [security2:error] [pid 1004636:tid 1004865] [client 20.52.125.110:6745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amugfe_uyupB2NyFtxJ7FwAAACk"]
[Thu Jul 30 14:05:33.422936 2026] [security2:error] [pid 1004636:tid 1004852] [client 135.119.63.61:42297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/03a005685d.php"] [unique_id "amugfe_uyupB2NyFtxJ7HwAAAB0"]
[Thu Jul 30 14:05:33.472725 2026] [security2:error] [pid 1004636:tid 1004895] [client 103.82.27.41:62988] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.kicksity.com"] [uri "/wp-json/batch/v1"] [unique_id "amugfe_uyupB2NyFtxJ7IAAAAEU"]
[Thu Jul 30 14:05:33.621089 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.203.148.31:59395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/wp-files.php"] [unique_id "amugfe_uyupB2NyFtxJ7JgAAAG4"]
[Thu Jul 30 14:05:33.662055 2026] [security2:error] [pid 1004636:tid 1004779] [remote 97.74.93.24:48242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amugfe_uyupB2NyFtxJ7JwAAIlg"]
[Thu Jul 30 14:05:33.671646 2026] [security2:error] [pid 1004636:tid 1004953] [client 20.52.125.110:6707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amugfe_uyupB2NyFtxJ7KAAAAH0"]
[Thu Jul 30 14:05:33.972573 2026] [security2:error] [pid 1004636:tid 1004952] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugfe_uyupB2NyFtxJ7LwAAAHw"]
[Thu Jul 30 14:05:33.972595 2026] [security2:error] [pid 1004636:tid 1004952] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugfe_uyupB2NyFtxJ7LwAAAHw"]
[Thu Jul 30 14:05:33.972867 2026] [security2:error] [pid 1004636:tid 1004889] [client 82.102.18.180:42822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "amugfe_uyupB2NyFtxJ7LQAAAEA"]
[Thu Jul 30 14:05:33.994561 2026] [security2:error] [pid 1004636:tid 1004916] [client 135.119.63.61:7807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/abcd.php"] [unique_id "amugfe_uyupB2NyFtxJ7NwAAAFo"]
[Thu Jul 30 14:05:34.004267 2026] [security2:error] [pid 1004636:tid 1004914] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/core%7e"] [unique_id "amugfu_uyupB2NyFtxJ7OAAAAFg"]
[Thu Jul 30 14:05:34.096922 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.52.125.110:6727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amugfu_uyupB2NyFtxJ7OQAAAE4"]
[Thu Jul 30 14:05:34.109145 2026] [security2:error] [pid 1004636:tid 1004924] [client 158.158.41.78:33392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/css/index.php"] [unique_id "amugfu_uyupB2NyFtxJ7OgAAAGE"]
[Thu Jul 30 14:05:34.529179 2026] [security2:error] [pid 1004636:tid 1004911] [client 135.119.63.61:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/403.php"] [unique_id "amugfu_uyupB2NyFtxJ7SwAAAFU"]
[Thu Jul 30 14:05:34.533495 2026] [security2:error] [pid 1004636:tid 1004871] [client 20.52.125.110:6758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amugfu_uyupB2NyFtxJ7TAAAAC8"]
[Thu Jul 30 14:05:34.783836 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.203.148.31:61040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/wp-setup.php"] [unique_id "amugfu_uyupB2NyFtxJ7UgAAAAg"]
[Thu Jul 30 14:05:34.797652 2026] [security2:error] [pid 1004636:tid 1004941] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugfu_uyupB2NyFtxJ7QAAAAHE"]
[Thu Jul 30 14:05:34.956991 2026] [security2:error] [pid 1004636:tid 1004926] [client 20.52.125.110:6678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amugfu_uyupB2NyFtxJ7VgAAAGM"]
[Thu Jul 30 14:05:35.045214 2026] [security2:error] [pid 1004636:tid 1004867] [client 158.158.41.78:27554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-cron.php"] [unique_id "amugf-_uyupB2NyFtxJ7XAAAACs"]
[Thu Jul 30 14:05:35.131186 2026] [security2:error] [pid 1004636:tid 1004873] [client 135.119.63.61:7776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/about.php"] [unique_id "amugf-_uyupB2NyFtxJ7XQAAADE"]
[Thu Jul 30 14:05:35.361059 2026] [security2:error] [pid 1004636:tid 1004919] [client 20.203.148.31:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/defaults.php"] [unique_id "amugf-_uyupB2NyFtxJ7ZAAAAF0"]
[Thu Jul 30 14:05:35.372125 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.52.125.110:6704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amugf-_uyupB2NyFtxJ7ZQAAAB0"]
[Thu Jul 30 14:05:35.544019 2026] [security2:error] [pid 1004636:tid 1004903] [client 135.119.63.61:22532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/404.php"] [unique_id "amugf-_uyupB2NyFtxJ7bgAAAE0"]
[Thu Jul 30 14:05:35.738059 2026] [security2:error] [pid 1004636:tid 1004895] [client 189.6.88.213:53805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugf-_uyupB2NyFtxJ7cQAAAEU"]
[Thu Jul 30 14:05:35.738179 2026] [security2:error] [pid 1004636:tid 1004895] [client 189.6.88.213:53805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugf-_uyupB2NyFtxJ7cQAAAEU"]
[Thu Jul 30 14:05:35.792696 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.91.199.21:19844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/languages/about.php"] [unique_id "amugf-_uyupB2NyFtxJ7dQAAABk"]
[Thu Jul 30 14:05:35.826651 2026] [security2:error] [pid 1004636:tid 1004949] [client 20.52.125.110:6814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amugf-_uyupB2NyFtxJ7ewAAAHk"]
[Thu Jul 30 14:05:35.943109 2026] [security2:error] [pid 1004636:tid 1004842] [client 172.213.208.20:43612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amugf-_uyupB2NyFtxJ7fAAAABM"]
[Thu Jul 30 14:05:36.247806 2026] [security2:error] [pid 1004636:tid 1004917] [client 20.52.125.110:6739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuggO_uyupB2NyFtxJ7igAAAFs"]
[Thu Jul 30 14:05:36.425409 2026] [security2:error] [pid 1004636:tid 1004803] [remote 47.128.126.104:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fantasynamelist.com"] [uri "/favicon.ico"] [unique_id "amuggO_uyupB2NyFtxJ7jwAADG8"], referer: https://fantasynamelist.com/world-culture/korean-name-generator/
[Thu Jul 30 14:05:36.443799 2026] [security2:error] [pid 1004636:tid 1004872] [client 135.119.63.61:36868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/admin.php"] [unique_id "amuggO_uyupB2NyFtxJ7kAAAADA"]
[Thu Jul 30 14:05:36.668225 2026] [security2:error] [pid 1004636:tid 1004897] [client 20.91.199.21:41259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuggO_uyupB2NyFtxJ7ngAAAEc"]
[Thu Jul 30 14:05:36.681580 2026] [security2:error] [pid 1004636:tid 1004940] [client 20.52.125.110:6918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuggO_uyupB2NyFtxJ7nwAAAHA"]
[Thu Jul 30 14:05:37.037714 2026] [security2:error] [pid 1004636:tid 1004847] [client 20.203.148.31:60996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/gtc.php"] [unique_id "amugge_uyupB2NyFtxJ7pgAAABg"]
[Thu Jul 30 14:05:37.094899 2026] [security2:error] [pid 1004636:tid 1004868] [client 135.119.63.61:50377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/aa.php"] [unique_id "amugge_uyupB2NyFtxJ7qgAAACw"]
[Thu Jul 30 14:05:37.110723 2026] [security2:error] [pid 1004636:tid 1004887] [client 20.52.125.110:6705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amugge_uyupB2NyFtxJ7qwAAAD4"]
[Thu Jul 30 14:05:37.225825 2026] [security2:error] [pid 1004636:tid 1004850] [client 20.91.199.21:11400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amugge_uyupB2NyFtxJ7swAAABs"]
[Thu Jul 30 14:05:37.411048 2026] [security2:error] [pid 1004636:tid 1004934] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugge_uyupB2NyFtxJ7tgAAAGs"]
[Thu Jul 30 14:05:37.411089 2026] [security2:error] [pid 1004636:tid 1004934] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugge_uyupB2NyFtxJ7tgAAAGs"]
[Thu Jul 30 14:05:37.411267 2026] [security2:error] [pid 1004636:tid 1004856] [client 82.102.18.180:42822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/upload/image/"] [unique_id "amugge_uyupB2NyFtxJ7tAAAACA"]
[Thu Jul 30 14:05:37.524549 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.52.125.110:6715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amugge_uyupB2NyFtxJ7vgAAAE0"]
[Thu Jul 30 14:05:37.877273 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.203.148.31:34605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/import.php"] [unique_id "amugge_uyupB2NyFtxJ7ygAAAEs"]
[Thu Jul 30 14:05:38.227247 2026] [security2:error] [pid 1004636:tid 1004955] [client 135.119.63.61:36238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/adminfuns.php"] [unique_id "amuggu_uyupB2NyFtxJ71gAAAH8"]
[Thu Jul 30 14:05:38.242056 2026] [security2:error] [pid 1004636:tid 1004937] [client 103.190.40.154:21147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuggu_uyupB2NyFtxJ71wAAAG0"]
[Thu Jul 30 14:05:38.242179 2026] [security2:error] [pid 1004636:tid 1004937] [client 103.190.40.154:21147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuggu_uyupB2NyFtxJ71wAAAG0"]
[Thu Jul 30 14:05:38.256114 2026] [security2:error] [pid 1004636:tid 1004927] [client 20.91.199.21:15887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuggu_uyupB2NyFtxJ72AAAAGQ"]
[Thu Jul 30 14:05:38.390427 2026] [security2:error] [pid 1004636:tid 1004936] [client 135.119.63.61:42248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/aafewc0k.php"] [unique_id "amuggu_uyupB2NyFtxJ73AAAAGw"]
[Thu Jul 30 14:05:38.641592 2026] [security2:error] [pid 1004636:tid 1004860] [client 170.83.2.223:38454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuggu_uyupB2NyFtxJ72QAAACQ"], referer: http://pkf.jo
[Thu Jul 30 14:05:38.784759 2026] [security2:error] [pid 1004636:tid 1004941] [client 110.235.235.230:60498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuggu_uyupB2NyFtxJ74QAAAHE"], referer: http://pkf.jo
[Thu Jul 30 14:05:38.941445 2026] [security2:error] [pid 1004636:tid 1004885] [client 172.213.208.20:21042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/atomlib.php"] [unique_id "amuggu_uyupB2NyFtxJ78AAAADw"]
[Thu Jul 30 14:05:39.101486 2026] [security2:error] [pid 1004636:tid 1004918] [client 135.119.63.61:36883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/albin.php"] [unique_id "amugg-_uyupB2NyFtxJ79QAAAFw"]
[Thu Jul 30 14:05:39.246330 2026] [security2:error] [pid 1004636:tid 1004827] [client 135.119.63.61:42252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/abcd.php"] [unique_id "amugg-_uyupB2NyFtxJ7-wAAAAU"]
[Thu Jul 30 14:05:39.323785 2026] [security2:error] [pid 1004636:tid 1004868] [client 181.116.200.68:36739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugg-_uyupB2NyFtxJ8AgAAACw"]
[Thu Jul 30 14:05:39.323888 2026] [security2:error] [pid 1004636:tid 1004868] [client 181.116.200.68:36739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugg-_uyupB2NyFtxJ8AgAAACw"]
[Thu Jul 30 14:05:39.403717 2026] [security2:error] [pid 1004636:tid 1004865] [client 38.25.22.45:63815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuggu_uyupB2NyFtxJ77AAAACk"], referer: http://pkf.jo
[Thu Jul 30 14:05:39.474917 2026] [security2:error] [pid 1004636:tid 1004900] [client 196.177.215.46:34158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuggu_uyupB2NyFtxJ77gAAAEo"], referer: http://pkf.jo
[Thu Jul 30 14:05:39.814221 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.203.148.31:34576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/lufix.php"] [unique_id "amugg-_uyupB2NyFtxJ8HQAAAFM"]
[Thu Jul 30 14:05:40.198867 2026] [core:notice] [pid 1004636:tid 1004857] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:40.238450 2026] [security2:error] [pid 1004636:tid 1004938] [client 105.163.2.64:2509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugg-_uyupB2NyFtxJ79wAAAG4"], referer: http://pkf.jo
[Thu Jul 30 14:05:40.293431 2026] [security2:error] [pid 1004636:tid 1004872] [client 135.119.63.61:50399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/about.php"] [unique_id "amughO_uyupB2NyFtxJ8KwAAADA"]
[Thu Jul 30 14:05:40.298083 2026] [security2:error] [pid 1004636:tid 1004848] [client 37.32.71.75:43456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugg-_uyupB2NyFtxJ8AAAAABk"], referer: http://pkf.jo
[Thu Jul 30 14:05:40.343916 2026] [core:error] [pid 1004636:tid 1004947] [client 172.213.208.20:34151] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:40.343948 2026] [core:error] [pid 1004636:tid 1004947] [client 172.213.208.20:34151] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:40.459803 2026] [security2:error] [pid 1004636:tid 1004907] [client 135.119.63.61:36865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/amfsqvgv.php"] [unique_id "amughO_uyupB2NyFtxJ8MwAAAFE"]
[Thu Jul 30 14:05:40.553749 2026] [security2:error] [pid 1004636:tid 1004873] [client 103.242.199.184:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amughO_uyupB2NyFtxJ8OAAAADE"]
[Thu Jul 30 14:05:40.553848 2026] [security2:error] [pid 1004636:tid 1004873] [client 103.242.199.184:57094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amughO_uyupB2NyFtxJ8OAAAADE"]
[Thu Jul 30 14:05:40.567881 2026] [security2:error] [pid 1004636:tid 1004933] [client 158.158.41.78:33354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-block.php"] [unique_id "amughO_uyupB2NyFtxJ8OQAAAGo"]
[Thu Jul 30 14:05:40.649013 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.203.148.31:34617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/Geforce.php"] [unique_id "amughO_uyupB2NyFtxJ8PAAAAAg"]
[Thu Jul 30 14:05:40.871237 2026] [security2:error] [pid 1004636:tid 1004858] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amughO_uyupB2NyFtxJ8RAAAACI"]
[Thu Jul 30 14:05:40.871357 2026] [security2:error] [pid 1004636:tid 1004858] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amughO_uyupB2NyFtxJ8RAAAACI"]
[Thu Jul 30 14:05:40.957856 2026] [core:notice] [pid 1004636:tid 1004839] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:41.186040 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amughe_uyupB2NyFtxJ8TgAAABc"]
[Thu Jul 30 14:05:41.186136 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amughe_uyupB2NyFtxJ8TgAAABc"]
[Thu Jul 30 14:05:41.325497 2026] [core:error] [pid 1004636:tid 1004918] [client 172.213.208.20:39755] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:41.325525 2026] [core:error] [pid 1004636:tid 1004918] [client 172.213.208.20:39755] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:41.409196 2026] [core:notice] [pid 1004636:tid 1004841] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:41.456047 2026] [security2:error] [pid 1004636:tid 1004871] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/x.php"] [unique_id "amughe_uyupB2NyFtxJ8XQAAAC8"]
[Thu Jul 30 14:05:41.456147 2026] [security2:error] [pid 1004636:tid 1004871] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/x.php"] [unique_id "amughe_uyupB2NyFtxJ8XQAAAC8"]
[Thu Jul 30 14:05:41.545715 2026] [security2:error] [pid 1004636:tid 1004912] [client 135.119.63.61:22562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/admin.php"] [unique_id "amughe_uyupB2NyFtxJ8YwAAAFY"]
[Thu Jul 30 14:05:41.563730 2026] [security2:error] [pid 1004636:tid 1004932] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/test.php"] [unique_id "amughe_uyupB2NyFtxJ8ZAAAAGk"]
[Thu Jul 30 14:05:41.666862 2026] [security2:error] [pid 1004636:tid 1004844] [client 20.52.125.110:16613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/json.php"] [unique_id "amughe_uyupB2NyFtxJ8aQAAABU"]
[Thu Jul 30 14:05:41.679576 2026] [security2:error] [pid 1004636:tid 1004893] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amughe_uyupB2NyFtxJ8YAAAAEQ"]
[Thu Jul 30 14:05:41.679601 2026] [security2:error] [pid 1004636:tid 1004893] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amughe_uyupB2NyFtxJ8YAAAAEQ"]
[Thu Jul 30 14:05:41.679828 2026] [security2:error] [pid 1004636:tid 1004870] [client 82.102.18.180:42822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/assets/images/"] [unique_id "amughe_uyupB2NyFtxJ8XgAAAC4"]
[Thu Jul 30 14:05:41.747797 2026] [security2:error] [pid 1004636:tid 1004860] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/mgrr.php"] [unique_id "amughe_uyupB2NyFtxJ8awAAACQ"]
[Thu Jul 30 14:05:41.747900 2026] [security2:error] [pid 1004636:tid 1004860] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/mgrr.php"] [unique_id "amughe_uyupB2NyFtxJ8awAAACQ"]
[Thu Jul 30 14:05:41.808474 2026] [security2:error] [pid 1004636:tid 1004905] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/test.php..."] [unique_id "amughe_uyupB2NyFtxJ8bAAAAE8"]
[Thu Jul 30 14:05:41.885755 2026] [security2:error] [pid 1004636:tid 1004923] [client 135.119.63.61:36256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/ant.php"] [unique_id "amughe_uyupB2NyFtxJ8cwAAAGA"]
[Thu Jul 30 14:05:42.025960 2026] [security2:error] [pid 1004636:tid 1004941] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/domvf.php"] [unique_id "amughu_uyupB2NyFtxJ8dQAAAHE"]
[Thu Jul 30 14:05:42.026098 2026] [security2:error] [pid 1004636:tid 1004941] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/domvf.php"] [unique_id "amughu_uyupB2NyFtxJ8dQAAAHE"]
[Thu Jul 30 14:05:42.051138 2026] [security2:error] [pid 1004636:tid 1004929] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/test.php%09%09"] [unique_id "amughu_uyupB2NyFtxJ8dgAAAGY"]
[Thu Jul 30 14:05:42.079431 2026] [security2:error] [pid 1004636:tid 1004942] [client 20.91.199.21:3835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amughu_uyupB2NyFtxJ8dwAAAHI"]
[Thu Jul 30 14:05:42.101625 2026] [security2:error] [pid 1004636:tid 1004877] [client 217.181.93.243:59302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amughe_uyupB2NyFtxJ8dAAANSU"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 14:05:42.142786 2026] [security2:error] [pid 1004636:tid 1004897] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amughe_uyupB2NyFtxJ8YgAARyE"]
[Thu Jul 30 14:05:42.285696 2026] [security2:error] [pid 1004636:tid 1004888] [client 88.175.14.168:18616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugg-_uyupB2NyFtxJ8BwAAAD8"], referer: http://pkf.jo
[Thu Jul 30 14:05:42.292333 2026] [security2:error] [pid 1004636:tid 1004858] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/test.php...."] [unique_id "amughu_uyupB2NyFtxJ8fQAAACI"]
[Thu Jul 30 14:05:42.296626 2026] [security2:error] [pid 1004636:tid 1004855] [client 190.8.87.17:58316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugg-_uyupB2NyFtxJ8DAAAAB8"], referer: http://pkf.jo
[Thu Jul 30 14:05:42.337585 2026] [security2:error] [pid 1004636:tid 1004930] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/yup.php"] [unique_id "amughu_uyupB2NyFtxJ8ggAAAGc"]
[Thu Jul 30 14:05:42.337679 2026] [security2:error] [pid 1004636:tid 1004930] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/yup.php"] [unique_id "amughu_uyupB2NyFtxJ8ggAAAGc"]
[Thu Jul 30 14:05:42.533488 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.52.125.110:17114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/mini.php"] [unique_id "amughu_uyupB2NyFtxJ8igAAAAU"]
[Thu Jul 30 14:05:42.577277 2026] [security2:error] [pid 1004636:tid 1004895] [client 135.119.63.61:50379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/adminfuns.php"] [unique_id "amughu_uyupB2NyFtxJ8jAAAAEU"]
[Thu Jul 30 14:05:42.638091 2026] [security2:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/X.php"] [unique_id "amughu_uyupB2NyFtxJ8jQAAAAo"]
[Thu Jul 30 14:05:42.638195 2026] [security2:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/X.php"] [unique_id "amughu_uyupB2NyFtxJ8jQAAAAo"]
[Thu Jul 30 14:05:42.927934 2026] [security2:error] [pid 1004636:tid 1004921] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amughu_uyupB2NyFtxJ8nAAAAF8"]
[Thu Jul 30 14:05:42.928060 2026] [security2:error] [pid 1004636:tid 1004921] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amughu_uyupB2NyFtxJ8nAAAAF8"]
[Thu Jul 30 14:05:43.196454 2026] [security2:error] [pid 1004636:tid 1004828] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/gec.php"] [unique_id "amugh-_uyupB2NyFtxJ8owAAAAY"]
[Thu Jul 30 14:05:43.196572 2026] [security2:error] [pid 1004636:tid 1004828] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/gec.php"] [unique_id "amugh-_uyupB2NyFtxJ8owAAAAY"]
[Thu Jul 30 14:05:43.246810 2026] [security2:error] [pid 1004636:tid 1004851] [client 156.201.201.138:36368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugg-_uyupB2NyFtxJ8GgAAABw"], referer: http://pkf.jo
[Thu Jul 30 14:05:43.249689 2026] [security2:error] [pid 1004636:tid 1004937] [client 37.236.31.34:50250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugg-_uyupB2NyFtxJ8HwAAAG0"], referer: http://pkf.jo
[Thu Jul 30 14:05:43.255298 2026] [security2:error] [pid 1004636:tid 1004910] [client 78.120.130.106:13418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugg-_uyupB2NyFtxJ8DQAAAFQ"], referer: http://pkf.jo
[Thu Jul 30 14:05:43.264547 2026] [security2:error] [pid 1004636:tid 1004927] [client 131.221.54.147:9287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugg-_uyupB2NyFtxJ8IQAAAGQ"], referer: http://pkf.jo
[Thu Jul 30 14:05:43.273753 2026] [security2:error] [pid 1004636:tid 1004883] [client 179.106.147.147:56422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amughO_uyupB2NyFtxJ8KQAAADo"], referer: http://pkf.jo
[Thu Jul 30 14:05:43.492782 2026] [security2:error] [pid 1004636:tid 1004874] [client 20.203.148.31:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/a4.php"] [unique_id "amugh-_uyupB2NyFtxJ8rAAAADI"]
[Thu Jul 30 14:05:43.648257 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.52.125.110:16580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/chosen.php"] [unique_id "amugh-_uyupB2NyFtxJ8tAAAAC4"]
[Thu Jul 30 14:05:43.666001 2026] [security2:error] [pid 1004636:tid 1004840] [client 158.158.41.78:18247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/fonts/admin.php"] [unique_id "amugh-_uyupB2NyFtxJ8tQAAABE"]
[Thu Jul 30 14:05:43.831825 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/sky.php"] [unique_id "amugh-_uyupB2NyFtxJ8uQAAADE"]
[Thu Jul 30 14:05:43.831938 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/sky.php"] [unique_id "amugh-_uyupB2NyFtxJ8uQAAADE"]
[Thu Jul 30 14:05:43.897783 2026] [security2:error] [pid 1004636:tid 1004920] [client 172.213.208.20:14019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amugh-_uyupB2NyFtxJ8wQAAAF4"]
[Thu Jul 30 14:05:44.091509 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.91.199.21:11430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-admin/js/about.php"] [unique_id "amugiO_uyupB2NyFtxJ8zAAAAH4"]
[Thu Jul 30 14:05:44.147604 2026] [security2:error] [pid 1004636:tid 1004865] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/fffm.php"] [unique_id "amugiO_uyupB2NyFtxJ8zgAAACk"]
[Thu Jul 30 14:05:44.147699 2026] [security2:error] [pid 1004636:tid 1004865] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/fffm.php"] [unique_id "amugiO_uyupB2NyFtxJ8zgAAACk"]
[Thu Jul 30 14:05:44.229401 2026] [security2:error] [pid 1004636:tid 1004878] [client 176.29.4.55:15933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amughO_uyupB2NyFtxJ8RgAAADY"], referer: http://pkf.jo
[Thu Jul 30 14:05:44.298490 2026] [security2:error] [pid 1004636:tid 1004863] [client 37.154.99.126:31257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amughO_uyupB2NyFtxJ8PQAAJw4"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxxvideo.tattoo
[Thu Jul 30 14:05:44.345597 2026] [security2:error] [pid 1004636:tid 1004856] [client 20.52.125.110:17113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/kj.php"] [unique_id "amugiO_uyupB2NyFtxJ81AAAACA"]
[Thu Jul 30 14:05:44.352598 2026] [security2:error] [pid 1004636:tid 1004857] [client 189.37.64.178:9707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amughe_uyupB2NyFtxJ8ZQAAACE"], referer: http://pkf.jo
[Thu Jul 30 14:05:44.353287 2026] [security2:error] [pid 1004636:tid 1004876] [client 186.128.97.248:41594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amughe_uyupB2NyFtxJ8VwAAADQ"], referer: http://pkf.jo
[Thu Jul 30 14:05:44.390317 2026] [security2:error] [pid 1004636:tid 1004847] [client 91.160.13.21:60521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amughu_uyupB2NyFtxJ8iAAAABg"], referer: http://pkf.jo
[Thu Jul 30 14:05:44.420967 2026] [security2:error] [pid 1004636:tid 1004884] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/sixxis.php"] [unique_id "amugiO_uyupB2NyFtxJ82AAAADs"]
[Thu Jul 30 14:05:44.421079 2026] [security2:error] [pid 1004636:tid 1004884] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/sixxis.php"] [unique_id "amugiO_uyupB2NyFtxJ82AAAADs"]
[Thu Jul 30 14:05:44.456410 2026] [security2:error] [pid 1004636:tid 1004889] [client 135.119.63.61:52154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cakiltheme/idx.php"] [unique_id "amugiO_uyupB2NyFtxJ82gAAAEA"]
[Thu Jul 30 14:05:44.610306 2026] [security2:error] [pid 1004636:tid 1004822] [client 135.119.63.61:50410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/albin.php"] [unique_id "amugiO_uyupB2NyFtxJ84wAAAAA"]
[Thu Jul 30 14:05:44.688337 2026] [security2:error] [pid 1004636:tid 1004913] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/yj09.php"] [unique_id "amugiO_uyupB2NyFtxJ85gAAAFc"]
[Thu Jul 30 14:05:44.688476 2026] [security2:error] [pid 1004636:tid 1004913] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/yj09.php"] [unique_id "amugiO_uyupB2NyFtxJ85gAAAFc"]
[Thu Jul 30 14:05:44.756063 2026] [security2:error] [pid 1004636:tid 1004909] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugiO_uyupB2NyFtxJ84gAAAFM"]
[Thu Jul 30 14:05:44.756091 2026] [security2:error] [pid 1004636:tid 1004909] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugiO_uyupB2NyFtxJ84gAAAFM"]
[Thu Jul 30 14:05:44.756491 2026] [security2:error] [pid 1004636:tid 1004849] [client 82.102.18.180:42822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/Public/"] [unique_id "amugiO_uyupB2NyFtxJ84AAAABo"]
[Thu Jul 30 14:05:44.896163 2026] [security2:error] [pid 1004636:tid 1004890] [client 20.52.125.110:16635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-files.php"] [unique_id "amugiO_uyupB2NyFtxJ86gAAAEE"]
[Thu Jul 30 14:05:44.964018 2026] [security2:error] [pid 1004636:tid 1004947] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/k.php"] [unique_id "amugiO_uyupB2NyFtxJ87AAAAHc"]
[Thu Jul 30 14:05:44.964127 2026] [security2:error] [pid 1004636:tid 1004947] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/k.php"] [unique_id "amugiO_uyupB2NyFtxJ87AAAAHc"]
[Thu Jul 30 14:05:45.107319 2026] [core:error] [pid 1004636:tid 1004921] [client 172.213.208.20:34113] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:45.107351 2026] [core:error] [pid 1004636:tid 1004921] [client 172.213.208.20:34113] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:45.153690 2026] [security2:error] [pid 1004636:tid 1004885] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/localhost.sql"] [unique_id "amugie_uyupB2NyFtxJ8_AAAADw"]
[Thu Jul 30 14:05:45.174080 2026] [security2:error] [pid 1004636:tid 1004845] [client 158.158.41.78:42292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/classwithtostring.php"] [unique_id "amugie_uyupB2NyFtxJ8_QAAABY"]
[Thu Jul 30 14:05:45.210638 2026] [security2:error] [pid 1004636:tid 1004848] [client 135.119.63.61:51444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cakiltheme/up.php"] [unique_id "amugie_uyupB2NyFtxJ8_wAAABk"]
[Thu Jul 30 14:05:45.249555 2026] [security2:error] [pid 1004636:tid 1004887] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/k2.php"] [unique_id "amugie_uyupB2NyFtxJ9AAAAAD4"]
[Thu Jul 30 14:05:45.249689 2026] [security2:error] [pid 1004636:tid 1004887] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/k2.php"] [unique_id "amugie_uyupB2NyFtxJ9AAAAAD4"]
[Thu Jul 30 14:05:45.279355 2026] [security2:error] [pid 1004636:tid 1004914] [client 176.42.139.31:28441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugh-_uyupB2NyFtxJ8uwAAWCs"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxxhd.yachts
[Thu Jul 30 14:05:45.459805 2026] [security2:error] [pid 1004636:tid 1004825] [client 135.119.63.61:42288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/amfsqvgv.php"] [unique_id "amugie_uyupB2NyFtxJ9BQAAAAM"]
[Thu Jul 30 14:05:45.520193 2026] [security2:error] [pid 1004636:tid 1004861] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/w.php"] [unique_id "amugie_uyupB2NyFtxJ9BwAAACU"]
[Thu Jul 30 14:05:45.520313 2026] [security2:error] [pid 1004636:tid 1004861] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/w.php"] [unique_id "amugie_uyupB2NyFtxJ9BwAAACU"]
[Thu Jul 30 14:05:45.562143 2026] [security2:error] [pid 1004636:tid 1004924] [client 46.60.99.116:35528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugiO_uyupB2NyFtxJ86wAAYT4"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxnxx.sex
[Thu Jul 30 14:05:45.803915 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.52.125.110:17097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-setup.php"] [unique_id "amugie_uyupB2NyFtxJ9DwAAAE0"]
[Thu Jul 30 14:05:45.916422 2026] [security2:error] [pid 1004636:tid 1004858] [client 158.158.41.78:28085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/test1.php"] [unique_id "amugie_uyupB2NyFtxJ9FAAAACI"]
[Thu Jul 30 14:05:45.950220 2026] [security2:error] [pid 1004636:tid 1004898] [client 135.119.63.61:51420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/calendar/index.php"] [unique_id "amugie_uyupB2NyFtxJ9FQAAAEg"]
[Thu Jul 30 14:05:46.077549 2026] [security2:error] [pid 1004636:tid 1004931] [client 20.203.148.31:34573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/accueil.php"] [unique_id "amugiu_uyupB2NyFtxJ9GQAAAGg"]
[Thu Jul 30 14:05:46.109657 2026] [security2:error] [pid 1004636:tid 1004889] [client 20.91.199.21:15873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amugiu_uyupB2NyFtxJ9GgAAAEA"]
[Thu Jul 30 14:05:46.226405 2026] [security2:error] [pid 1004636:tid 1004778] [remote 72.167.132.114:57206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-74678686.jvc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amugiu_uyupB2NyFtxJ9HwAAelc"]
[Thu Jul 30 14:05:46.265395 2026] [security2:error] [pid 1004636:tid 1004871] [client 46.185.165.201:47082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugie_uyupB2NyFtxJ9FgAAAC8"], referer: http://pkf.jo
[Thu Jul 30 14:05:46.352884 2026] [security2:error] [pid 1004636:tid 1004917] [client 91.90.11.12:55480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugiu_uyupB2NyFtxJ9FwAAWzQ"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=https%3A%2F%2Ft.me%2Ffilmfilmfilmes%2F24
[Thu Jul 30 14:05:46.397683 2026] [security2:error] [pid 1004636:tid 1004832] [client 189.6.88.213:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugiu_uyupB2NyFtxJ9JQAAAAo"]
[Thu Jul 30 14:05:46.397910 2026] [security2:error] [pid 1004636:tid 1004832] [client 189.6.88.213:54358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugiu_uyupB2NyFtxJ9JQAAAAo"]
[Thu Jul 30 14:05:46.401531 2026] [security2:error] [pid 1004636:tid 1004905] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/db.sql"] [unique_id "amugiu_uyupB2NyFtxJ9JgAAAE8"]
[Thu Jul 30 14:05:46.717103 2026] [security2:error] [pid 1004636:tid 1004946] [client 135.119.63.61:5938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/canonical.php"] [unique_id "amugiu_uyupB2NyFtxJ9MwAAAHY"]
[Thu Jul 30 14:05:46.742127 2026] [security2:error] [pid 1004636:tid 1004833] [client 52.167.144.170:24320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amugiu_uyupB2NyFtxJ9LgAAC2I"]
[Thu Jul 30 14:05:46.810458 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.52.125.110:16582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/defaults.php"] [unique_id "amugiu_uyupB2NyFtxJ9OQAAAFQ"]
[Thu Jul 30 14:05:46.958781 2026] [security2:error] [pid 1004636:tid 1004877] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amugiu_uyupB2NyFtxJ9PgAAADU"]
[Thu Jul 30 14:05:46.976958 2026] [security2:error] [pid 1004636:tid 1004879] [client 20.91.199.21:11440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amugiu_uyupB2NyFtxJ9PwAAADc"]
[Thu Jul 30 14:05:47.089494 2026] [security2:error] [pid 1004636:tid 1004913] [client 84.82.27.170:46640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugiu_uyupB2NyFtxJ9NAAAV2A"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fbrazzer.click
[Thu Jul 30 14:05:47.307970 2026] [security2:error] [pid 1004636:tid 1004916] [client 135.119.63.61:42250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/ant.php"] [unique_id "amugi-_uyupB2NyFtxJ9RgAAAFo"]
[Thu Jul 30 14:05:47.465964 2026] [security2:error] [pid 1004636:tid 1004829] [client 135.119.63.61:5935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/catalogadmin.php"] [unique_id "amugi-_uyupB2NyFtxJ9TQAAAAc"]
[Thu Jul 30 14:05:47.636271 2026] [security2:error] [pid 1004636:tid 1004900] [client 14.228.186.59:36874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugi-_uyupB2NyFtxJ9RwAAAEo"], referer: http://pkf.jo
[Thu Jul 30 14:05:47.636775 2026] [security2:error] [pid 1004636:tid 1004918] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/fpwch.php"] [unique_id "amugi-_uyupB2NyFtxJ9UAAAAFw"]
[Thu Jul 30 14:05:47.636862 2026] [security2:error] [pid 1004636:tid 1004918] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/fpwch.php"] [unique_id "amugi-_uyupB2NyFtxJ9UAAAAFw"]
[Thu Jul 30 14:05:47.751061 2026] [security2:error] [pid 1004636:tid 1004861] [client 20.52.125.110:17098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/gtc.php"] [unique_id "amugi-_uyupB2NyFtxJ9UgAAACU"]
[Thu Jul 30 14:05:47.756377 2026] [security2:error] [pid 1004636:tid 1004912] [client 45.239.102.164:33010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugi-_uyupB2NyFtxJ9SQAAVmk"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxvideos.cc%2Fhot-mature-pawg-sara-jay-gives-fit-sidney-a-fun-lesbian.html
[Thu Jul 30 14:05:47.757886 2026] [security2:error] [pid 1004636:tid 1004876] [client 205.209.65.111:51856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugi-_uyupB2NyFtxJ9TgAAADQ"], referer: http://pkf.jo
[Thu Jul 30 14:05:47.908335 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/w2025.php"] [unique_id "amugi-_uyupB2NyFtxJ9WwAAABU"]
[Thu Jul 30 14:05:47.908450 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/w2025.php"] [unique_id "amugi-_uyupB2NyFtxJ9WwAAABU"]
[Thu Jul 30 14:05:48.164713 2026] [security2:error] [pid 1004636:tid 1004939] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugi-_uyupB2NyFtxJ9XwAAAG8"]
[Thu Jul 30 14:05:48.164751 2026] [security2:error] [pid 1004636:tid 1004939] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugi-_uyupB2NyFtxJ9XwAAAG8"]
[Thu Jul 30 14:05:48.165036 2026] [security2:error] [pid 1004636:tid 1004950] [client 82.102.18.180:42822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/vendor/"] [unique_id "amugi-_uyupB2NyFtxJ9XAAAAHo"]
[Thu Jul 30 14:05:48.181630 2026] [security2:error] [pid 1004636:tid 1004945] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/FWAZ.php"] [unique_id "amugjO_uyupB2NyFtxJ9aAAAAHU"]
[Thu Jul 30 14:05:48.181706 2026] [security2:error] [pid 1004636:tid 1004945] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/FWAZ.php"] [unique_id "amugjO_uyupB2NyFtxJ9aAAAAHU"]
[Thu Jul 30 14:05:48.194410 2026] [security2:error] [pid 1004636:tid 1004849] [client 135.119.63.61:46721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/catalogalfa.php"] [unique_id "amugjO_uyupB2NyFtxJ9aQAAABo"]
[Thu Jul 30 14:05:48.334651 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.52.125.110:17095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/import.php"] [unique_id "amugjO_uyupB2NyFtxJ9bwAAAE8"]
[Thu Jul 30 14:05:48.338753 2026] [security2:error] [pid 1004636:tid 1004955] [client 135.119.63.61:38663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/appreciators.php"] [unique_id "amugjO_uyupB2NyFtxJ9cAAAAH8"]
[Thu Jul 30 14:05:48.454805 2026] [security2:error] [pid 1004636:tid 1004845] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/qterm.php"] [unique_id "amugjO_uyupB2NyFtxJ9dgAAABY"]
[Thu Jul 30 14:05:48.454914 2026] [security2:error] [pid 1004636:tid 1004845] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/qterm.php"] [unique_id "amugjO_uyupB2NyFtxJ9dgAAABY"]
[Thu Jul 30 14:05:48.744349 2026] [security2:error] [pid 1004636:tid 1004897] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/blurbs.php"] [unique_id "amugjO_uyupB2NyFtxJ9gAAAAEc"]
[Thu Jul 30 14:05:48.744495 2026] [security2:error] [pid 1004636:tid 1004897] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/blurbs.php"] [unique_id "amugjO_uyupB2NyFtxJ9gAAAAEc"]
[Thu Jul 30 14:05:48.803043 2026] [security2:error] [pid 1004636:tid 1004862] [client 77.240.41.183:49221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugjO_uyupB2NyFtxJ9dQAAJnE"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fthisvid.asia
[Thu Jul 30 14:05:48.890475 2026] [security2:error] [pid 1004636:tid 1004908] [client 135.119.63.61:52059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/catalogbypass.php"] [unique_id "amugjO_uyupB2NyFtxJ9hgAAAFI"]
[Thu Jul 30 14:05:48.959950 2026] [security2:error] [pid 1004636:tid 1004830] [client 189.133.249.21:48750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugjO_uyupB2NyFtxJ9fgAAAAg"], referer: http://pkf.jo
[Thu Jul 30 14:05:48.989207 2026] [security2:error] [pid 1004636:tid 1004889] [client 135.119.63.61:50430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/appreciators.php"] [unique_id "amugjO_uyupB2NyFtxJ9iQAAAEA"]
[Thu Jul 30 14:05:49.028201 2026] [security2:error] [pid 1004636:tid 1004839] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-ws68.php"] [unique_id "amugje_uyupB2NyFtxJ9jAAAABA"]
[Thu Jul 30 14:05:49.028306 2026] [security2:error] [pid 1004636:tid 1004839] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-ws68.php"] [unique_id "amugje_uyupB2NyFtxJ9jAAAABA"]
[Thu Jul 30 14:05:49.225642 2026] [security2:error] [pid 1004636:tid 1004873] [client 186.158.145.206:24439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugjO_uyupB2NyFtxJ9hAAAMXc"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fpakistanporn.top
[Thu Jul 30 14:05:49.302386 2026] [security2:error] [pid 1004636:tid 1004919] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xyn.php"] [unique_id "amugje_uyupB2NyFtxJ9kAAAAF0"]
[Thu Jul 30 14:05:49.302505 2026] [security2:error] [pid 1004636:tid 1004919] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xyn.php"] [unique_id "amugje_uyupB2NyFtxJ9kAAAAF0"]
[Thu Jul 30 14:05:49.507669 2026] [security2:error] [pid 1004636:tid 1004868] [client 135.119.63.61:19813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/archive.php"] [unique_id "amugje_uyupB2NyFtxJ9mwAAACw"]
[Thu Jul 30 14:05:49.558431 2026] [security2:error] [pid 1004636:tid 1004948] [client 103.190.40.154:21783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugje_uyupB2NyFtxJ9oAAAAHg"]
[Thu Jul 30 14:05:49.558623 2026] [security2:error] [pid 1004636:tid 1004948] [client 103.190.40.154:21783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugje_uyupB2NyFtxJ9oAAAAHg"]
[Thu Jul 30 14:05:49.562615 2026] [core:error] [pid 1004636:tid 1004925] [client 172.213.208.20:29861] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:49.562639 2026] [core:error] [pid 1004636:tid 1004925] [client 172.213.208.20:29861] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:49.574803 2026] [security2:error] [pid 1004636:tid 1004951] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ccc.php"] [unique_id "amugje_uyupB2NyFtxJ9ogAAAHs"]
[Thu Jul 30 14:05:49.574903 2026] [security2:error] [pid 1004636:tid 1004951] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ccc.php"] [unique_id "amugje_uyupB2NyFtxJ9ogAAAHs"]
[Thu Jul 30 14:05:49.631328 2026] [security2:error] [pid 1004636:tid 1004865] [client 91.116.33.9:1804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugje_uyupB2NyFtxJ9kQAAACk"], referer: http://pkf.jo
[Thu Jul 30 14:05:49.664389 2026] [security2:error] [pid 1004636:tid 1004918] [client 135.119.63.61:5810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/catalogk.php"] [unique_id "amugje_uyupB2NyFtxJ9pQAAAFw"]
[Thu Jul 30 14:05:49.821790 2026] [security2:error] [pid 1004636:tid 1004898] [client 5.30.214.242:57934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugje_uyupB2NyFtxJ9ngAAAEg"], referer: http://pkf.jo
[Thu Jul 30 14:05:49.846060 2026] [security2:error] [pid 1004636:tid 1004846] [client 20.52.125.110:16577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/lufix.php"] [unique_id "amugje_uyupB2NyFtxJ9pwAAABc"]
[Thu Jul 30 14:05:49.857578 2026] [security2:error] [pid 1004636:tid 1004893] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/get.php"] [unique_id "amugje_uyupB2NyFtxJ9qAAAAEQ"]
[Thu Jul 30 14:05:49.857660 2026] [security2:error] [pid 1004636:tid 1004893] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/get.php"] [unique_id "amugje_uyupB2NyFtxJ9qAAAAEQ"]
[Thu Jul 30 14:05:49.889291 2026] [security2:error] [pid 1004636:tid 1004876] [client 181.116.200.68:41502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugje_uyupB2NyFtxJ9rQAAADQ"]
[Thu Jul 30 14:05:49.889400 2026] [security2:error] [pid 1004636:tid 1004876] [client 181.116.200.68:41502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugje_uyupB2NyFtxJ9rQAAADQ"]
[Thu Jul 30 14:05:49.933342 2026] [security2:error] [pid 1004636:tid 1004936] [client 142.68.130.89:46724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugje_uyupB2NyFtxJ9pAAAAGw"], referer: http://pkf.jo
[Thu Jul 30 14:05:50.250436 2026] [security2:error] [pid 1004636:tid 1004891] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/images.php"] [unique_id "amugju_uyupB2NyFtxJ9uQAAAEI"]
[Thu Jul 30 14:05:50.250549 2026] [security2:error] [pid 1004636:tid 1004891] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/images.php"] [unique_id "amugju_uyupB2NyFtxJ9uQAAAEI"]
[Thu Jul 30 14:05:50.363339 2026] [security2:error] [pid 1004636:tid 1004828] [client 45.177.218.48:51867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugje_uyupB2NyFtxJ9rgAABnw"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=https%3A%2F%2Fpadmavani.org%2F
[Thu Jul 30 14:05:50.426111 2026] [security2:error] [pid 1004636:tid 1004921] [client 135.119.63.61:5932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/catalogwp.php"] [unique_id "amugju_uyupB2NyFtxJ9wgAAAF8"]
[Thu Jul 30 14:05:50.498041 2026] [security2:error] [pid 1004636:tid 1004899] [client 152.58.37.174:58606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugju_uyupB2NyFtxJ9twAAAEk"], referer: http://pkf.jo
[Thu Jul 30 14:05:50.525548 2026] [security2:error] [pid 1004636:tid 1004933] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/alls.php"] [unique_id "amugju_uyupB2NyFtxJ9xgAAAGo"]
[Thu Jul 30 14:05:50.525653 2026] [security2:error] [pid 1004636:tid 1004933] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/alls.php"] [unique_id "amugju_uyupB2NyFtxJ9xgAAAGo"]
[Thu Jul 30 14:05:50.835067 2026] [security2:error] [pid 1004636:tid 1004879] [client 20.91.199.21:3596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amugju_uyupB2NyFtxJ90AAAADc"]
[Thu Jul 30 14:05:50.872418 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/coffexium.php"] [unique_id "amugju_uyupB2NyFtxJ90QAAADE"]
[Thu Jul 30 14:05:50.872511 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/coffexium.php"] [unique_id "amugju_uyupB2NyFtxJ90QAAADE"]
[Thu Jul 30 14:05:51.002302 2026] [security2:error] [pid 1004636:tid 1004954] [client 74.7.244.40:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ymk.udi.temporary.site"] [uri "/index.php"] [unique_id "amugju_uyupB2NyFtxJ9vQAAAH4"]
[Thu Jul 30 14:05:51.003276 2026] [security2:error] [pid 1004636:tid 1004867] [client 74.7.244.40:48300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ymk.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amugju_uyupB2NyFtxJ9uwAAK38"]
[Thu Jul 30 14:05:51.127555 2026] [security2:error] [pid 1004636:tid 1004825] [client 135.119.63.61:5783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/categories/about.php"] [unique_id "amugj-_uyupB2NyFtxJ93QAAAAM"]
[Thu Jul 30 14:05:51.164429 2026] [security2:error] [pid 1004636:tid 1004866] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/red.php"] [unique_id "amugj-_uyupB2NyFtxJ93wAAACo"]
[Thu Jul 30 14:05:51.164509 2026] [security2:error] [pid 1004636:tid 1004866] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/red.php"] [unique_id "amugj-_uyupB2NyFtxJ93wAAACo"]
[Thu Jul 30 14:05:51.173230 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.203.148.31:34240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/dashboard.php"] [unique_id "amugj-_uyupB2NyFtxJ94AAAAF4"]
[Thu Jul 30 14:05:51.243376 2026] [security2:error] [pid 1004636:tid 1004951] [client 103.242.199.184:57659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugj-_uyupB2NyFtxJ94gAAAHs"]
[Thu Jul 30 14:05:51.243497 2026] [security2:error] [pid 1004636:tid 1004951] [client 103.242.199.184:57659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugj-_uyupB2NyFtxJ94gAAAHs"]
[Thu Jul 30 14:05:51.290341 2026] [security2:error] [pid 1004636:tid 1004925] [client 20.52.125.110:17099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/Geforce.php"] [unique_id "amugj-_uyupB2NyFtxJ94wAAAGI"]
[Thu Jul 30 14:05:51.429447 2026] [security2:error] [pid 1004636:tid 1004901] [client 95.212.163.57:56322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugj-_uyupB2NyFtxJ93gAAAEs"], referer: http://pkf.jo
[Thu Jul 30 14:05:51.480692 2026] [core:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:51.480717 2026] [core:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:51.480813 2026] [security2:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugj-_uyupB2NyFtxJ96wAAAAo"]
[Thu Jul 30 14:05:51.562794 2026] [security2:error] [pid 1004636:tid 1004953] [client 135.119.63.61:37453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/as.php"] [unique_id "amugj-_uyupB2NyFtxJ97wAAAH0"]
[Thu Jul 30 14:05:51.668349 2026] [security2:error] [pid 1004636:tid 1004895] [client 186.224.78.74:7890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugj-_uyupB2NyFtxJ95QAAAEU"], referer: http://pkf.jo
[Thu Jul 30 14:05:51.786794 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amugj-_uyupB2NyFtxJ9-AAAAH8"]
[Thu Jul 30 14:05:51.786877 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amugj-_uyupB2NyFtxJ9-AAAAH8"]
[Thu Jul 30 14:05:51.819720 2026] [security2:error] [pid 1004636:tid 1004944] [client 20.52.125.110:16584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/a4.php"] [unique_id "amugj-_uyupB2NyFtxJ9-QAAAHQ"]
[Thu Jul 30 14:05:51.843268 2026] [security2:error] [pid 1004636:tid 1004931] [client 135.119.63.61:50402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/archive.php"] [unique_id "amugj-_uyupB2NyFtxJ9-gAAAGg"]
[Thu Jul 30 14:05:51.897500 2026] [security2:error] [pid 1004636:tid 1004905] [client 135.119.63.61:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/category.php"] [unique_id "amugj-_uyupB2NyFtxJ9_AAAAE8"]
[Thu Jul 30 14:05:52.077638 2026] [core:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:52.077668 2026] [core:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:52.077782 2026] [security2:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugkO_uyupB2NyFtxJ-BAAAACY"]
[Thu Jul 30 14:05:52.112835 2026] [security2:error] [pid 1004636:tid 1004877] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/backup.sql"] [unique_id "amugkO_uyupB2NyFtxJ-BQAAADU"]
[Thu Jul 30 14:05:52.163337 2026] [security2:error] [pid 1004636:tid 1004936] [client 20.91.199.21:3621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amugkO_uyupB2NyFtxJ-CQAAAGw"]
[Thu Jul 30 14:05:52.240994 2026] [security2:error] [pid 1004636:tid 1004873] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/backup.sql.php"] [unique_id "amugkO_uyupB2NyFtxJ-DQAAADE"]
[Thu Jul 30 14:05:52.354404 2026] [security2:error] [pid 1004636:tid 1004928] [client 20.52.125.110:16585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/accueil.php"] [unique_id "amugkO_uyupB2NyFtxJ-DwAAAGU"]
[Thu Jul 30 14:05:52.383012 2026] [security2:error] [pid 1004636:tid 1004879] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugkO_uyupB2NyFtxJ-DAAAADc"]
[Thu Jul 30 14:05:52.383053 2026] [security2:error] [pid 1004636:tid 1004879] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugkO_uyupB2NyFtxJ-DAAAADc"]
[Thu Jul 30 14:05:52.383215 2026] [security2:error] [pid 1004636:tid 1004888] [client 82.102.18.180:42822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/local/"] [unique_id "amugkO_uyupB2NyFtxJ-CgAAAD8"]
[Thu Jul 30 14:05:52.384786 2026] [core:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:52.384809 2026] [core:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:52.384887 2026] [security2:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugkO_uyupB2NyFtxJ-EAAAAEo"]
[Thu Jul 30 14:05:52.593301 2026] [security2:error] [pid 1004636:tid 1004896] [client 135.119.63.61:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cay-van-phong/filemanager.php"] [unique_id "amugkO_uyupB2NyFtxJ-GQAAAEY"]
[Thu Jul 30 14:05:52.625182 2026] [security2:error] [pid 1004636:tid 1004924] [client 187.103.219.146:41842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugkO_uyupB2NyFtxJ-DgAAAGE"], referer: http://pkf.jo
[Thu Jul 30 14:05:52.677970 2026] [security2:error] [pid 1004636:tid 1004909] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/index.php"] [unique_id "amugkO_uyupB2NyFtxJ-GwAAAFM"]
[Thu Jul 30 14:05:52.678095 2026] [security2:error] [pid 1004636:tid 1004909] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/index.php"] [unique_id "amugkO_uyupB2NyFtxJ-GwAAAFM"]
[Thu Jul 30 14:05:52.787004 2026] [security2:error] [pid 1004636:tid 1004825] [client 20.91.199.21:3778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amugkO_uyupB2NyFtxJ-HwAAAAM"]
[Thu Jul 30 14:05:52.953822 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amugkO_uyupB2NyFtxJ-IgAAABU"]
[Thu Jul 30 14:05:52.953934 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amugkO_uyupB2NyFtxJ-IgAAABU"]
[Thu Jul 30 14:05:53.191803 2026] [security2:error] [pid 1004636:tid 1004947] [client 20.52.125.110:16609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/dashboard.php"] [unique_id "amugke_uyupB2NyFtxJ-LgAAAHc"]
[Thu Jul 30 14:05:53.233675 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.203.148.31:34798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/radio.php"] [unique_id "amugke_uyupB2NyFtxJ-LwAAAE0"]
[Thu Jul 30 14:05:53.234412 2026] [security2:error] [pid 1004636:tid 1004874] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/177.php"] [unique_id "amugke_uyupB2NyFtxJ-MAAAADI"]
[Thu Jul 30 14:05:53.234492 2026] [security2:error] [pid 1004636:tid 1004874] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/177.php"] [unique_id "amugke_uyupB2NyFtxJ-MAAAADI"]
[Thu Jul 30 14:05:53.335014 2026] [security2:error] [pid 1004636:tid 1004950] [client 135.119.63.61:52105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cay-van-phong/hehe.php"] [unique_id "amugke_uyupB2NyFtxJ-NwAAAHo"]
[Thu Jul 30 14:05:53.350013 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.91.199.21:41225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/themes/about.php"] [unique_id "amugke_uyupB2NyFtxJ-OAAAAEU"]
[Thu Jul 30 14:05:53.500055 2026] [security2:error] [pid 1004636:tid 1004931] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/199.php"] [unique_id "amugke_uyupB2NyFtxJ-OgAAAGg"]
[Thu Jul 30 14:05:53.500164 2026] [security2:error] [pid 1004636:tid 1004931] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/199.php"] [unique_id "amugke_uyupB2NyFtxJ-OgAAAGg"]
[Thu Jul 30 14:05:53.528099 2026] [security2:error] [pid 1004636:tid 1004828] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.php"] [unique_id "amugke_uyupB2NyFtxJ-PQAAAAY"]
[Thu Jul 30 14:05:53.585153 2026] [security2:error] [pid 1004636:tid 1004843] [client 94.239.158.149:48006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugke_uyupB2NyFtxJ-NQAAABQ"], referer: http://pkf.jo
[Thu Jul 30 14:05:53.703859 2026] [security2:error] [pid 1004636:tid 1004885] [client 135.119.63.61:37893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/atomlib.php"] [unique_id "amugke_uyupB2NyFtxJ-RgAAADw"]
[Thu Jul 30 14:05:53.763061 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.52.125.110:16615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/radio.php"] [unique_id "amugke_uyupB2NyFtxJ-RwAAACM"]
[Thu Jul 30 14:05:53.765819 2026] [security2:error] [pid 1004636:tid 1004855] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file52.php"] [unique_id "amugke_uyupB2NyFtxJ-SAAAAB8"]
[Thu Jul 30 14:05:53.765895 2026] [security2:error] [pid 1004636:tid 1004855] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file52.php"] [unique_id "amugke_uyupB2NyFtxJ-SAAAAB8"]
[Thu Jul 30 14:05:53.770225 2026] [security2:error] [pid 1004636:tid 1004930] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.php%255f"] [unique_id "amugke_uyupB2NyFtxJ-SQAAAGc"]
[Thu Jul 30 14:05:54.013880 2026] [security2:error] [pid 1004636:tid 1004928] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.php%255d"] [unique_id "amugku_uyupB2NyFtxJ-TQAAAGU"]
[Thu Jul 30 14:05:54.036254 2026] [security2:error] [pid 1004636:tid 1004906] [client 135.119.63.61:51467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cay-van-phong/skibidi.php"] [unique_id "amugku_uyupB2NyFtxJ-TgAAAFA"]
[Thu Jul 30 14:05:54.043909 2026] [core:error] [pid 1004636:tid 1004849] [client 172.213.208.20:37611] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:54.043925 2026] [core:error] [pid 1004636:tid 1004849] [client 172.213.208.20:37611] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:54.244394 2026] [security2:error] [pid 1004636:tid 1004912] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/geck.php"] [unique_id "amugku_uyupB2NyFtxJ-VwAAAFY"]
[Thu Jul 30 14:05:54.244499 2026] [security2:error] [pid 1004636:tid 1004912] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/geck.php"] [unique_id "amugku_uyupB2NyFtxJ-VwAAAFY"]
[Thu Jul 30 14:05:54.255136 2026] [security2:error] [pid 1004636:tid 1004823] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/index.php.aws"] [unique_id "amugku_uyupB2NyFtxJ-WAAAAAE"]
[Thu Jul 30 14:05:54.396687 2026] [security2:error] [pid 1004636:tid 1004880] [client 78.142.33.42:42930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugku_uyupB2NyFtxJ-UwAAADg"], referer: http://pkf.jo
[Thu Jul 30 14:05:54.568785 2026] [security2:error] [pid 1004636:tid 1004948] [client 20.52.125.110:17105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wpsml-sys.php"] [unique_id "amugku_uyupB2NyFtxJ-XwAAAHg"]
[Thu Jul 30 14:05:54.688024 2026] [core:error] [pid 1004636:tid 1004842] [client 172.213.208.20:42538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:54.688045 2026] [core:error] [pid 1004636:tid 1004842] [client 172.213.208.20:42538] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:54.709392 2026] [security2:error] [pid 1004636:tid 1004890] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/biufile.php"] [unique_id "amugku_uyupB2NyFtxJ-aAAAAEE"]
[Thu Jul 30 14:05:54.709477 2026] [security2:error] [pid 1004636:tid 1004890] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/biufile.php"] [unique_id "amugku_uyupB2NyFtxJ-aAAAAEE"]
[Thu Jul 30 14:05:54.721531 2026] [core:notice] [pid 1004636:tid 1004858] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:54.811358 2026] [security2:error] [pid 1004636:tid 1004925] [client 135.119.63.61:51511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cbgd.php"] [unique_id "amugku_uyupB2NyFtxJ-bgAAAGI"]
[Thu Jul 30 14:05:54.959320 2026] [security2:error] [pid 1004636:tid 1004932] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amugku_uyupB2NyFtxJ-dQAAAGk"]
[Thu Jul 30 14:05:54.984331 2026] [security2:error] [pid 1004636:tid 1004895] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dejavu.php"] [unique_id "amugku_uyupB2NyFtxJ-dgAAAEU"]
[Thu Jul 30 14:05:54.984415 2026] [security2:error] [pid 1004636:tid 1004895] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dejavu.php"] [unique_id "amugku_uyupB2NyFtxJ-dgAAAEU"]
[Thu Jul 30 14:05:55.015218 2026] [security2:error] [pid 1004636:tid 1004946] [client 172.237.109.114:7780] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/nextgen-gallery/readme.txt"] [unique_id "amugk-_uyupB2NyFtxJ-dwAAAHY"]
[Thu Jul 30 14:05:55.266364 2026] [security2:error] [pid 1004636:tid 1004892] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/aaf.php"] [unique_id "amugk-_uyupB2NyFtxJ-hAAAAEM"]
[Thu Jul 30 14:05:55.266490 2026] [security2:error] [pid 1004636:tid 1004892] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/aaf.php"] [unique_id "amugk-_uyupB2NyFtxJ-hAAAAEM"]
[Thu Jul 30 14:05:55.272553 2026] [security2:error] [pid 1004636:tid 1004864] [client 20.203.148.31:58270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/wpsml-sys.php"] [unique_id "amugk-_uyupB2NyFtxJ-hQAAACg"]
[Thu Jul 30 14:05:55.442179 2026] [security2:error] [pid 1004636:tid 1004859] [client 172.213.208.20:13395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/inputs.php"] [unique_id "amugk-_uyupB2NyFtxJ-jQAAACM"]
[Thu Jul 30 14:05:55.442212 2026] [security2:error] [pid 1004636:tid 1004830] [client 158.158.41.78:43697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/images/index.php"] [unique_id "amugk-_uyupB2NyFtxJ-jgAAAAg"]
[Thu Jul 30 14:05:55.518405 2026] [security2:error] [pid 1004636:tid 1004877] [client 135.119.63.61:51502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cbrfo.php"] [unique_id "amugk-_uyupB2NyFtxJ-jwAAADU"]
[Thu Jul 30 14:05:55.550553 2026] [security2:error] [pid 1004636:tid 1004862] [client 37.236.9.5:36700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugk-_uyupB2NyFtxJ-fwAAJjE"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxvideos.cc%2Fhot-bbc-stretching-and-cumming-on-white-whores-combo-7.html
[Thu Jul 30 14:05:55.621540 2026] [security2:error] [pid 1004636:tid 1004855] [client 89.93.246.165:9406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugk-_uyupB2NyFtxJ-hwAAAB8"], referer: http://pkf.jo
[Thu Jul 30 14:05:55.701262 2026] [security2:error] [pid 1004636:tid 1004902] [client 20.52.125.110:16626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/02.php"] [unique_id "amugk-_uyupB2NyFtxJ-lQAAAEw"]
[Thu Jul 30 14:05:55.740839 2026] [security2:error] [pid 1004636:tid 1004919] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ha.php"] [unique_id "amugk-_uyupB2NyFtxJ-lwAAAF0"]
[Thu Jul 30 14:05:55.740924 2026] [security2:error] [pid 1004636:tid 1004919] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ha.php"] [unique_id "amugk-_uyupB2NyFtxJ-lwAAAF0"]
[Thu Jul 30 14:05:56.040235 2026] [security2:error] [pid 1004636:tid 1004880] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/hur.php"] [unique_id "amuglO_uyupB2NyFtxJ-nwAAADg"]
[Thu Jul 30 14:05:56.040355 2026] [security2:error] [pid 1004636:tid 1004880] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/hur.php"] [unique_id "amuglO_uyupB2NyFtxJ-nwAAADg"]
[Thu Jul 30 14:05:56.142658 2026] [security2:error] [pid 1004636:tid 1004908] [client 20.91.199.21:12612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuglO_uyupB2NyFtxJ-ogAAAFI"]
[Thu Jul 30 14:05:56.322008 2026] [security2:error] [pid 1004636:tid 1004909] [client 172.213.208.20:43077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/index.php"] [unique_id "amuglO_uyupB2NyFtxJ-qwAAAFM"]
[Thu Jul 30 14:05:56.364052 2026] [security2:error] [pid 1004636:tid 1004866] [client 135.119.63.61:51507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cc.php"] [unique_id "amuglO_uyupB2NyFtxJ-rAAAACo"]
[Thu Jul 30 14:05:56.374012 2026] [security2:error] [pid 1004636:tid 1004924] [client 176.187.103.194:59986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuglO_uyupB2NyFtxJ-oQAAAGE"], referer: http://pkf.jo
[Thu Jul 30 14:05:56.508481 2026] [security2:error] [pid 1004636:tid 1004929] [client 135.119.63.61:7280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/autoload_classmap.php"] [unique_id "amuglO_uyupB2NyFtxJ-sQAAAGY"]
[Thu Jul 30 14:05:56.647341 2026] [security2:error] [pid 1004636:tid 1004874] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/h02ugyh.php"] [unique_id "amuglO_uyupB2NyFtxJ-tAAAADI"]
[Thu Jul 30 14:05:56.647463 2026] [security2:error] [pid 1004636:tid 1004874] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/h02ugyh.php"] [unique_id "amuglO_uyupB2NyFtxJ-tAAAADI"]
[Thu Jul 30 14:05:56.922959 2026] [security2:error] [pid 1004636:tid 1004897] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/155.php"] [unique_id "amuglO_uyupB2NyFtxJ-wAAAAEc"]
[Thu Jul 30 14:05:56.923077 2026] [security2:error] [pid 1004636:tid 1004897] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/155.php"] [unique_id "amuglO_uyupB2NyFtxJ-wAAAAEc"]
[Thu Jul 30 14:05:56.978155 2026] [security2:error] [pid 1004636:tid 1004903] [client 189.6.88.213:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuglO_uyupB2NyFtxJ-wgAAAE0"]
[Thu Jul 30 14:05:56.978256 2026] [security2:error] [pid 1004636:tid 1004903] [client 189.6.88.213:54922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuglO_uyupB2NyFtxJ-wgAAAE0"]
[Thu Jul 30 14:05:56.993674 2026] [security2:error] [pid 1004636:tid 1004907] [client 172.213.208.20:13398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuglO_uyupB2NyFtxJ-wwAAAFE"]
[Thu Jul 30 14:05:57.096872 2026] [core:notice] [pid 1004636:tid 1004759] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:05:57.126508 2026] [security2:error] [pid 1004636:tid 1004870] [client 135.119.63.61:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/ccaef.php"] [unique_id "amugle_uyupB2NyFtxJ-xwAAAC4"]
[Thu Jul 30 14:05:57.253271 2026] [security2:error] [pid 1004636:tid 1004930] [client 158.158.41.78:28498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/asd.php"] [unique_id "amugle_uyupB2NyFtxJ-zAAAAGc"]
[Thu Jul 30 14:05:57.423503 2026] [security2:error] [pid 1004636:tid 1004928] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amugle_uyupB2NyFtxJ-1AAAAGU"]
[Thu Jul 30 14:05:57.423683 2026] [security2:error] [pid 1004636:tid 1004928] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amugle_uyupB2NyFtxJ-1AAAAGU"]
[Thu Jul 30 14:05:57.683790 2026] [security2:error] [pid 1004636:tid 1004881] [client 66.249.64.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amugk-_uyupB2NyFtxJ-iwAAOUk"]
[Thu Jul 30 14:05:57.741927 2026] [security2:error] [pid 1004636:tid 1004941] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ingfo.php"] [unique_id "amugle_uyupB2NyFtxJ-3gAAAHE"]
[Thu Jul 30 14:05:57.742062 2026] [security2:error] [pid 1004636:tid 1004941] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ingfo.php"] [unique_id "amugle_uyupB2NyFtxJ-3gAAAHE"]
[Thu Jul 30 14:05:57.808431 2026] [security2:error] [pid 1004636:tid 1004902] [client 102.211.145.247:36598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugle_uyupB2NyFtxJ-0QAATDw"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxvideos.cc%2Fhot-hidden-camera-films-reality-sex-scene.html
[Thu Jul 30 14:05:57.951110 2026] [security2:error] [pid 1004636:tid 1004856] [client 135.119.63.61:61998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/ccx/index.php"] [unique_id "amugle_uyupB2NyFtxJ-5gAAACA"]
[Thu Jul 30 14:05:58.023290 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/error_log.php"] [unique_id "amuglu_uyupB2NyFtxJ-7AAAABU"]
[Thu Jul 30 14:05:58.023380 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/error_log.php"] [unique_id "amuglu_uyupB2NyFtxJ-7AAAABU"]
[Thu Jul 30 14:05:58.137421 2026] [security2:error] [pid 1004636:tid 1004889] [client 20.91.199.21:18520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/images/about.php"] [unique_id "amuglu_uyupB2NyFtxJ-7gAAAEA"]
[Thu Jul 30 14:05:58.142390 2026] [security2:error] [pid 1004636:tid 1004938] [client 172.213.208.20:34167] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/1.php"] [unique_id "amuglu_uyupB2NyFtxJ-7wAAAG4"]
[Thu Jul 30 14:05:58.142479 2026] [security2:error] [pid 1004636:tid 1004938] [client 172.213.208.20:34167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/1.php"] [unique_id "amuglu_uyupB2NyFtxJ-7wAAAG4"]
[Thu Jul 30 14:05:58.224790 2026] [security2:error] [pid 1004636:tid 1004868] [client 20.203.148.31:61353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/02.php"] [unique_id "amuglu_uyupB2NyFtxJ-8AAAACw"]
[Thu Jul 30 14:05:58.261033 2026] [security2:error] [pid 1004636:tid 1004777] [remote 57.141.0.30:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/73667776610/feed/rss2/"] [unique_id "amuglu_uyupB2NyFtxJ-8gAAF1Y"]
[Thu Jul 30 14:05:58.307562 2026] [security2:error] [pid 1004636:tid 1004937] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/koala.php"] [unique_id "amuglu_uyupB2NyFtxJ-9gAAAG0"]
[Thu Jul 30 14:05:58.307678 2026] [security2:error] [pid 1004636:tid 1004937] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/koala.php"] [unique_id "amuglu_uyupB2NyFtxJ-9gAAAG0"]
[Thu Jul 30 14:05:58.364095 2026] [security2:error] [pid 1004636:tid 1004886] [client 77.236.31.71:36802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuglu_uyupB2NyFtxJ-6wAAPUI"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxvideos.cc%2Fhot-gets-fucked-so-good-angela-white.html
[Thu Jul 30 14:05:58.466599 2026] [security2:error] [pid 1004636:tid 1004773] [remote 57.141.0.18:21164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/73667776610/feed/rss2/"] [unique_id "amuglu_uyupB2NyFtxJ--wAANFI"]
[Thu Jul 30 14:05:58.712777 2026] [security2:error] [pid 1004636:tid 1004950] [client 135.119.63.61:21598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cd.php"] [unique_id "amuglu_uyupB2NyFtxJ_BwAAAHo"]
[Thu Jul 30 14:05:58.817352 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.203.148.31:58279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/infos.php"] [unique_id "amuglu_uyupB2NyFtxJ_DQAAABQ"]
[Thu Jul 30 14:05:58.868219 2026] [security2:error] [pid 1004636:tid 1004887] [client 135.119.63.61:35241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/bb.php"] [unique_id "amuglu_uyupB2NyFtxJ_DgAAAD4"]
[Thu Jul 30 14:05:58.906177 2026] [security2:error] [pid 1004636:tid 1004864] [client 172.213.208.20:13421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/plugin.php"] [unique_id "amuglu_uyupB2NyFtxJ_EwAAACg"]
[Thu Jul 30 14:05:58.941702 2026] [security2:error] [pid 1004636:tid 1004877] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amuglu_uyupB2NyFtxJ_FAAAADU"]
[Thu Jul 30 14:05:58.941786 2026] [security2:error] [pid 1004636:tid 1004877] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amuglu_uyupB2NyFtxJ_FAAAADU"]
[Thu Jul 30 14:05:59.116899 2026] [security2:error] [pid 1004636:tid 1004743] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amugl-_uyupB2NyFtxJ_FwAAOjY"]
[Thu Jul 30 14:05:59.155734 2026] [security2:error] [pid 1004636:tid 1004906] [client 184.75.223.227:39762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amugl-_uyupB2NyFtxJ_GwAAAFA"]
[Thu Jul 30 14:05:59.155814 2026] [security2:error] [pid 1004636:tid 1004906] [client 184.75.223.227:39762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amugl-_uyupB2NyFtxJ_GwAAAFA"]
[Thu Jul 30 14:05:59.182785 2026] [security2:error] [pid 1004636:tid 1004893] [client 20.52.125.110:16633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/infos.php"] [unique_id "amugl-_uyupB2NyFtxJ_HAAAAEQ"]
[Thu Jul 30 14:05:59.246206 2026] [security2:error] [pid 1004636:tid 1004831] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wefile.php"] [unique_id "amugl-_uyupB2NyFtxJ_HQAAAAk"]
[Thu Jul 30 14:05:59.246312 2026] [security2:error] [pid 1004636:tid 1004831] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wefile.php"] [unique_id "amugl-_uyupB2NyFtxJ_HQAAAAk"]
[Thu Jul 30 14:05:59.501430 2026] [security2:error] [pid 1004636:tid 1004884] [client 135.119.63.61:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cdxadmin.php"] [unique_id "amugl-_uyupB2NyFtxJ_KAAAADs"]
[Thu Jul 30 14:05:59.516318 2026] [core:error] [pid 1004636:tid 1004842] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:59.516339 2026] [core:error] [pid 1004636:tid 1004842] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:05:59.516445 2026] [security2:error] [pid 1004636:tid 1004842] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugl-_uyupB2NyFtxJ_KQAAABM"]
[Thu Jul 30 14:05:59.622621 2026] [security2:error] [pid 1004636:tid 1004917] [client 172.213.208.20:34174] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.bisbeetour.com"] [uri "/1.php"] [unique_id "amugl-_uyupB2NyFtxJ_LwAAAFs"]
[Thu Jul 30 14:05:59.622744 2026] [security2:error] [pid 1004636:tid 1004917] [client 172.213.208.20:34174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/1.php"] [unique_id "amugl-_uyupB2NyFtxJ_LwAAAFs"]
[Thu Jul 30 14:05:59.672244 2026] [security2:error] [pid 1004636:tid 1004898] [client 158.158.41.78:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/customize/index.php"] [unique_id "amugl-_uyupB2NyFtxJ_MwAAAEg"]
[Thu Jul 30 14:05:59.780598 2026] [security2:error] [pid 1004636:tid 1004838] [client 213.230.86.75:5875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugl-_uyupB2NyFtxJ_JwAAAA8"], referer: http://pkf.jo
[Thu Jul 30 14:05:59.836677 2026] [security2:error] [pid 1004636:tid 1004889] [client 20.52.125.110:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/updates.php"] [unique_id "amugl-_uyupB2NyFtxJ_NgAAAEA"]
[Thu Jul 30 14:05:59.919493 2026] [security2:error] [pid 1004636:tid 1004955] [client 20.91.199.21:18516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amugl-_uyupB2NyFtxJ_OwAAAH8"]
[Thu Jul 30 14:06:00.068891 2026] [security2:error] [pid 1004636:tid 1004891] [client 20.203.148.31:61326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/updates.php"] [unique_id "amugmO_uyupB2NyFtxJ_QQAAAEI"]
[Thu Jul 30 14:06:00.125514 2026] [core:error] [pid 1004636:tid 1004926] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:00.125541 2026] [core:error] [pid 1004636:tid 1004926] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:00.125671 2026] [security2:error] [pid 1004636:tid 1004926] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugmO_uyupB2NyFtxJ_QgAAAGM"]
[Thu Jul 30 14:06:00.280573 2026] [security2:error] [pid 1004636:tid 1004904] [client 172.213.208.20:13383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/gg.php"] [unique_id "amugmO_uyupB2NyFtxJ_SAAAAE4"]
[Thu Jul 30 14:06:00.308708 2026] [security2:error] [pid 1004636:tid 1004903] [client 135.119.63.61:51466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cekidot/alf.php"] [unique_id "amugmO_uyupB2NyFtxJ_SgAAAE0"]
[Thu Jul 30 14:06:00.365480 2026] [security2:error] [pid 1004636:tid 1004933] [client 103.190.40.154:21201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugmO_uyupB2NyFtxJ_TAAAAGo"]
[Thu Jul 30 14:06:00.365630 2026] [security2:error] [pid 1004636:tid 1004933] [client 103.190.40.154:21201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugmO_uyupB2NyFtxJ_TAAAAGo"]
[Thu Jul 30 14:06:00.445667 2026] [security2:error] [pid 1004636:tid 1004911] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/makeasmtp.php"] [unique_id "amugmO_uyupB2NyFtxJ_UQAAAFU"]
[Thu Jul 30 14:06:00.445753 2026] [security2:error] [pid 1004636:tid 1004911] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/makeasmtp.php"] [unique_id "amugmO_uyupB2NyFtxJ_UQAAAFU"]
[Thu Jul 30 14:06:00.518060 2026] [security2:error] [pid 1004636:tid 1004913] [client 103.120.170.70:25642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugmO_uyupB2NyFtxJ_RwAAAFc"], referer: http://pkf.jo
[Thu Jul 30 14:06:00.608029 2026] [security2:error] [pid 1004636:tid 1004930] [client 181.116.200.68:19306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugmO_uyupB2NyFtxJ_WAAAAGc"]
[Thu Jul 30 14:06:00.608703 2026] [security2:error] [pid 1004636:tid 1004930] [client 181.116.200.68:19306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugmO_uyupB2NyFtxJ_WAAAAGc"]
[Thu Jul 30 14:06:00.717239 2026] [security2:error] [pid 1004636:tid 1004867] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/2P.php"] [unique_id "amugmO_uyupB2NyFtxJ_WwAAACs"]
[Thu Jul 30 14:06:00.717379 2026] [security2:error] [pid 1004636:tid 1004867] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/2P.php"] [unique_id "amugmO_uyupB2NyFtxJ_WwAAACs"]
[Thu Jul 30 14:06:00.740844 2026] [security2:error] [pid 1004636:tid 1004824] [client 20.52.125.110:16519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/user.php"] [unique_id "amugmO_uyupB2NyFtxJ_XwAAAAI"]
[Thu Jul 30 14:06:00.898459 2026] [security2:error] [pid 1004636:tid 1004856] [client 181.46.136.11:21878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugmO_uyupB2NyFtxJ_VQAAIFw"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=https%3A%2F%2Fpadmavani.org%2F
[Thu Jul 30 14:06:00.919223 2026] [security2:error] [pid 1004636:tid 1004786] [remote 57.141.0.17:43258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amugmO_uyupB2NyFtxJ_YwAAcV8"]
[Thu Jul 30 14:06:00.933537 2026] [security2:error] [pid 1004636:tid 1004873] [client 86.41.217.242:41230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugmO_uyupB2NyFtxJ_VwAAMV4"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxvideos.cc%2Fhot-pissing-into-her-girlfriend-s-mouth-and-cumming-from-13887.html
[Thu Jul 30 14:06:00.965316 2026] [security2:error] [pid 1004636:tid 1004841] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugmO_uyupB2NyFtxJ_SwAAElc"]
[Thu Jul 30 14:06:00.990466 2026] [security2:error] [pid 1004636:tid 1004866] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/.well-known/about.php"] [unique_id "amugmO_uyupB2NyFtxJ_aQAAACo"]
[Thu Jul 30 14:06:00.990585 2026] [security2:error] [pid 1004636:tid 1004866] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/.well-known/about.php"] [unique_id "amugmO_uyupB2NyFtxJ_aQAAACo"]
[Thu Jul 30 14:06:01.062537 2026] [security2:error] [pid 1004636:tid 1004823] [client 158.158.41.78:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amugme_uyupB2NyFtxJ_agAAAAE"]
[Thu Jul 30 14:06:01.104630 2026] [security2:error] [pid 1004636:tid 1004875] [client 135.119.63.61:51485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cekidot/mar.php"] [unique_id "amugme_uyupB2NyFtxJ_bAAAADM"]
[Thu Jul 30 14:06:01.262758 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "amugme_uyupB2NyFtxJ_dAAAAH8"]
[Thu Jul 30 14:06:01.262868 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "amugme_uyupB2NyFtxJ_dAAAAH8"]
[Thu Jul 30 14:06:01.277276 2026] [security2:error] [pid 1004636:tid 1004896] [client 20.91.199.21:41246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/images/about.php"] [unique_id "amugme_uyupB2NyFtxJ_dQAAAEY"]
[Thu Jul 30 14:06:01.326453 2026] [core:error] [pid 1004636:tid 1004880] [client 172.213.208.20:37630] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:01.326477 2026] [core:error] [pid 1004636:tid 1004880] [client 172.213.208.20:37630] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:01.335188 2026] [security2:error] [pid 1004636:tid 1004827] [client 135.119.63.61:42256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/as.php"] [unique_id "amugme_uyupB2NyFtxJ_dwAAAAU"]
[Thu Jul 30 14:06:01.532836 2026] [security2:error] [pid 1004636:tid 1004892] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/system_log.php"] [unique_id "amugme_uyupB2NyFtxJ_fwAAAEM"]
[Thu Jul 30 14:06:01.532938 2026] [security2:error] [pid 1004636:tid 1004892] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/system_log.php"] [unique_id "amugme_uyupB2NyFtxJ_fwAAAEM"]
[Thu Jul 30 14:06:01.807577 2026] [core:error] [pid 1004636:tid 1004936] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:01.807603 2026] [core:error] [pid 1004636:tid 1004936] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:01.807737 2026] [security2:error] [pid 1004636:tid 1004936] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugme_uyupB2NyFtxJ_ggAAAGw"]
[Thu Jul 30 14:06:01.904288 2026] [security2:error] [pid 1004636:tid 1004901] [client 135.119.63.61:62003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cekidot/mr.php"] [unique_id "amugme_uyupB2NyFtxJ_hwAAAEs"]
[Thu Jul 30 14:06:01.955621 2026] [security2:error] [pid 1004636:tid 1004865] [client 103.242.199.184:58233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugme_uyupB2NyFtxJ_iAAAACk"]
[Thu Jul 30 14:06:01.955760 2026] [security2:error] [pid 1004636:tid 1004865] [client 103.242.199.184:58233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugme_uyupB2NyFtxJ_iAAAACk"]
[Thu Jul 30 14:06:02.050701 2026] [security2:error] [pid 1004636:tid 1004870] [client 172.213.208.20:37572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/languages/index.php"] [unique_id "amugmu_uyupB2NyFtxJ_jgAAAC4"]
[Thu Jul 30 14:06:02.120737 2026] [core:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:02.120763 2026] [core:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:02.120883 2026] [security2:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugmu_uyupB2NyFtxJ_kgAAAEo"]
[Thu Jul 30 14:06:02.144857 2026] [security2:error] [pid 1004636:tid 1004933] [client 74.7.228.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rustore.teknomalay.com"] [uri "/robots.txt"] [unique_id "amugmu_uyupB2NyFtxJ_lAAAamQ"]
[Thu Jul 30 14:06:02.153722 2026] [security2:error] [pid 1004636:tid 1004877] [client 135.119.63.61:29529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/bnm.php"] [unique_id "amugmu_uyupB2NyFtxJ_lQAAADU"]
[Thu Jul 30 14:06:02.199012 2026] [security2:error] [pid 1004636:tid 1004889] [client 20.52.125.110:17116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/admin-ajax.php"] [unique_id "amugmu_uyupB2NyFtxJ_lgAAAEA"]
[Thu Jul 30 14:06:02.240233 2026] [security2:error] [pid 1004636:tid 1004855] [client 20.203.148.31:37147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/user.php"] [unique_id "amugmu_uyupB2NyFtxJ_lwAAAB8"]
[Thu Jul 30 14:06:02.356016 2026] [core:notice] [pid 1004636:tid 1004780] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:02.375218 2026] [core:notice] [pid 1004636:tid 1004796] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:02.410408 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/crgio.php"] [unique_id "amugmu_uyupB2NyFtxJ_ogAAABU"]
[Thu Jul 30 14:06:02.410494 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/crgio.php"] [unique_id "amugmu_uyupB2NyFtxJ_ogAAABU"]
[Thu Jul 30 14:06:02.649687 2026] [security2:error] [pid 1004636:tid 1004938] [client 172.213.208.20:44140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp.php"] [unique_id "amugmu_uyupB2NyFtxJ_qgAAAG4"]
[Thu Jul 30 14:06:02.699215 2026] [security2:error] [pid 1004636:tid 1004954] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/pucci.php"] [unique_id "amugmu_uyupB2NyFtxJ_rAAAAH4"]
[Thu Jul 30 14:06:02.699304 2026] [security2:error] [pid 1004636:tid 1004954] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/pucci.php"] [unique_id "amugmu_uyupB2NyFtxJ_rAAAAH4"]
[Thu Jul 30 14:06:02.712927 2026] [security2:error] [pid 1004636:tid 1004845] [client 135.119.63.61:21586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cepair/doc.php"] [unique_id "amugmu_uyupB2NyFtxJ_rQAAABY"]
[Thu Jul 30 14:06:02.725402 2026] [security2:error] [pid 1004636:tid 1004916] [client 158.158.41.78:23015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/atomlib.php"] [unique_id "amugmu_uyupB2NyFtxJ_rgAAAFo"]
[Thu Jul 30 14:06:02.786469 2026] [security2:error] [pid 1004636:tid 1004884] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/settings.php.save"] [unique_id "amugmu_uyupB2NyFtxJ_rwAAADs"]
[Thu Jul 30 14:06:02.824956 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.52.125.110:16619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/alfa.php"] [unique_id "amugmu_uyupB2NyFtxJ_swAAAAw"]
[Thu Jul 30 14:06:02.983740 2026] [core:error] [pid 1004636:tid 1004910] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:02.983763 2026] [core:error] [pid 1004636:tid 1004910] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:02.983867 2026] [security2:error] [pid 1004636:tid 1004910] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugmu_uyupB2NyFtxJ_tAAAAFQ"]
[Thu Jul 30 14:06:03.032193 2026] [security2:error] [pid 1004636:tid 1004945] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/settings.php.save%5f%5f"] [unique_id "amugm-_uyupB2NyFtxJ_tQAAAHU"]
[Thu Jul 30 14:06:03.144449 2026] [security2:error] [pid 1004636:tid 1004876] [client 172.213.208.20:21040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amugm-_uyupB2NyFtxJ_vAAAADQ"]
[Thu Jul 30 14:06:03.274492 2026] [security2:error] [pid 1004636:tid 1004843] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/settings.php.save%29"] [unique_id "amugm-_uyupB2NyFtxJ_vQAAABQ"]
[Thu Jul 30 14:06:03.311054 2026] [core:error] [pid 1004636:tid 1004925] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:03.311075 2026] [core:error] [pid 1004636:tid 1004925] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:03.311178 2026] [security2:error] [pid 1004636:tid 1004925] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugm-_uyupB2NyFtxJ_vwAAAGI"]
[Thu Jul 30 14:06:03.387661 2026] [security2:error] [pid 1004636:tid 1004824] [client 20.91.199.21:41060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/about.php"] [unique_id "amugm-_uyupB2NyFtxJ_wwAAAAI"]
[Thu Jul 30 14:06:03.464081 2026] [security2:error] [pid 1004636:tid 1004926] [client 135.119.63.61:51497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/certificates/plugins.php"] [unique_id "amugm-_uyupB2NyFtxJ_xgAAAGM"]
[Thu Jul 30 14:06:03.473675 2026] [security2:error] [pid 1004636:tid 1004940] [client 20.203.148.31:34799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/admin-ajax.php"] [unique_id "amugm-_uyupB2NyFtxJ_xwAAAHA"]
[Thu Jul 30 14:06:03.517400 2026] [security2:error] [pid 1004636:tid 1004865] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/settings.php.save.aws"] [unique_id "amugm-_uyupB2NyFtxJ_yAAAACk"]
[Thu Jul 30 14:06:03.536831 2026] [security2:error] [pid 1004636:tid 1004888] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amugm-_uyupB2NyFtxJ_yQAAAD8"]
[Thu Jul 30 14:06:03.587506 2026] [security2:error] [pid 1004636:tid 1004928] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-temp.php"] [unique_id "amugm-_uyupB2NyFtxJ_0AAAAGU"]
[Thu Jul 30 14:06:03.587638 2026] [security2:error] [pid 1004636:tid 1004928] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-temp.php"] [unique_id "amugm-_uyupB2NyFtxJ_0AAAAGU"]
[Thu Jul 30 14:06:03.589272 2026] [security2:error] [pid 1004636:tid 1004893] [client 20.52.125.110:16611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/hehe.php"] [unique_id "amugm-_uyupB2NyFtxJ_0gAAAEQ"]
[Thu Jul 30 14:06:03.600237 2026] [security2:error] [pid 1004636:tid 1004949] [client 185.169.7.129:13047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugm-_uyupB2NyFtxJ_vgAAAHk"], referer: http://pkf.jo
[Thu Jul 30 14:06:03.689529 2026] [security2:error] [pid 1004636:tid 1004901] [client 135.119.63.61:50374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/atomlib.php"] [unique_id "amugm-_uyupB2NyFtxJ_1gAAAEs"]
[Thu Jul 30 14:06:03.784456 2026] [security2:error] [pid 1004636:tid 1004921] [client 182.253.9.33:54604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugm-_uyupB2NyFtxJ_xAAAX3U"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxvideos.cc%2Fhot-big-tits-indian-bhabhi-devar-threesome.html
[Thu Jul 30 14:06:03.877721 2026] [security2:error] [pid 1004636:tid 1004852] [client 135.119.63.61:7251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/bootstrap.php"] [unique_id "amugm-_uyupB2NyFtxJ_2QAAAB0"]
[Thu Jul 30 14:06:04.214790 2026] [security2:error] [pid 1004636:tid 1004930] [client 20.52.125.110:17118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/rk2.php"] [unique_id "amugnO_uyupB2NyFtxJ_5gAAAGc"]
[Thu Jul 30 14:06:04.279579 2026] [security2:error] [pid 1004636:tid 1004856] [client 135.119.63.61:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cf.php"] [unique_id "amugnO_uyupB2NyFtxJ_5wAAACA"]
[Thu Jul 30 14:06:04.344096 2026] [security2:error] [pid 1004636:tid 1004863] [client 41.193.162.117:58181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugm-_uyupB2NyFtxJ_3QAAJ3o"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Ftxxx.work
[Thu Jul 30 14:06:04.521685 2026] [security2:error] [pid 1004636:tid 1004818] [remote 57.141.0.44:64416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/7226"] [unique_id "amugnO_uyupB2NyFtxJ_7wAACn0"]
[Thu Jul 30 14:06:04.589040 2026] [security2:error] [pid 1004636:tid 1004689] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugnO_uyupB2NyFtxJ_9AAAMgI"]
[Thu Jul 30 14:06:04.589243 2026] [security2:error] [pid 1004636:tid 1004874] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugnO_uyupB2NyFtxJ_9AAAMgI"]
[Thu Jul 30 14:06:04.683645 2026] [security2:error] [pid 1004636:tid 1004836] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-admin/js/index.php"] [unique_id "amugnO_uyupB2NyFtxJ_-AAAAA4"]
[Thu Jul 30 14:06:04.683737 2026] [security2:error] [pid 1004636:tid 1004836] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-admin/js/index.php"] [unique_id "amugnO_uyupB2NyFtxJ_-AAAAA4"]
[Thu Jul 30 14:06:04.699877 2026] [security2:error] [pid 1004636:tid 1004688] [remote 57.141.0.19:62922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Euclid/article/view/9222"] [unique_id "amugnO_uyupB2NyFtxJ__AAAFgE"]
[Thu Jul 30 14:06:04.824197 2026] [security2:error] [pid 1004636:tid 1004891] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amugnO_uyupB2NyFtxJ__gAAAEI"]
[Thu Jul 30 14:06:04.862715 2026] [security2:error] [pid 1004636:tid 1004834] [client 135.119.63.61:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/buy.php"] [unique_id "amugnO_uyupB2NyFtxJ__wAAAAw"]
[Thu Jul 30 14:06:04.963888 2026] [security2:error] [pid 1004636:tid 1004887] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/puc.php"] [unique_id "amugnO_uyupB2NyFtxKABAAAAD4"]
[Thu Jul 30 14:06:04.963993 2026] [security2:error] [pid 1004636:tid 1004887] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/puc.php"] [unique_id "amugnO_uyupB2NyFtxKABAAAAD4"]
[Thu Jul 30 14:06:05.037534 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.203.148.31:34773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/alfa.php"] [unique_id "amugne_uyupB2NyFtxKABgAAABk"]
[Thu Jul 30 14:06:05.059744 2026] [security2:error] [pid 1004636:tid 1004840] [client 135.119.63.61:34315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cfile.php"] [unique_id "amugne_uyupB2NyFtxKABwAAABE"]
[Thu Jul 30 14:06:05.206644 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.52.125.110:16598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/setup-config.php"] [unique_id "amugne_uyupB2NyFtxKADQAAABQ"]
[Thu Jul 30 14:06:05.217285 2026] [security2:error] [pid 1004636:tid 1004949] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amugne_uyupB2NyFtxKADgAAAHk"]
[Thu Jul 30 14:06:05.276537 2026] [security2:error] [pid 1004636:tid 1004933] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dx.php"] [unique_id "amugne_uyupB2NyFtxKAEgAAAGo"]
[Thu Jul 30 14:06:05.276669 2026] [security2:error] [pid 1004636:tid 1004933] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dx.php"] [unique_id "amugne_uyupB2NyFtxKAEgAAAGo"]
[Thu Jul 30 14:06:05.436267 2026] [security2:error] [pid 1004636:tid 1004888] [client 135.119.63.61:22869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/autoload_classmap.php"] [unique_id "amugne_uyupB2NyFtxKAFQAAAD8"]
[Thu Jul 30 14:06:05.700901 2026] [security2:error] [pid 1004636:tid 1004827] [client 38.246.74.236:52359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugne_uyupB2NyFtxKAFAAAAAU"], referer: http://pkf.jo
[Thu Jul 30 14:06:05.873828 2026] [security2:error] [pid 1004636:tid 1004902] [client 135.119.63.61:51504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cgi-binadmin.php"] [unique_id "amugne_uyupB2NyFtxKAIwAAAEw"]
[Thu Jul 30 14:06:06.052679 2026] [security2:error] [pid 1004636:tid 1004866] [client 172.213.208.20:13397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/file.php"] [unique_id "amugnu_uyupB2NyFtxKAKAAAACo"]
[Thu Jul 30 14:06:06.099619 2026] [core:error] [pid 1004636:tid 1004856] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:06.099640 2026] [core:error] [pid 1004636:tid 1004856] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:06.099754 2026] [security2:error] [pid 1004636:tid 1004856] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugnu_uyupB2NyFtxKAKQAAACA"]
[Thu Jul 30 14:06:06.151945 2026] [security2:error] [pid 1004636:tid 1004948] [client 20.52.125.110:16606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/a7.php"] [unique_id "amugnu_uyupB2NyFtxKAKwAAAHg"]
[Thu Jul 30 14:06:06.183550 2026] [security2:error] [pid 1004636:tid 1004942] [client 135.119.63.61:35352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/chosen.php"] [unique_id "amugnu_uyupB2NyFtxKALAAAAHI"]
[Thu Jul 30 14:06:06.291109 2026] [security2:error] [pid 1004636:tid 1004875] [client 135.119.63.61:22860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/bb.php"] [unique_id "amugnu_uyupB2NyFtxKAMgAAADM"]
[Thu Jul 30 14:06:06.370028 2026] [security2:error] [pid 1004636:tid 1004896] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/7.php"] [unique_id "amugnu_uyupB2NyFtxKAOAAAAEY"]
[Thu Jul 30 14:06:06.370122 2026] [security2:error] [pid 1004636:tid 1004896] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/7.php"] [unique_id "amugnu_uyupB2NyFtxKAOAAAAEY"]
[Thu Jul 30 14:06:06.651387 2026] [security2:error] [pid 1004636:tid 1004945] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amugnu_uyupB2NyFtxKAPwAAAHU"]
[Thu Jul 30 14:06:06.651471 2026] [security2:error] [pid 1004636:tid 1004945] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amugnu_uyupB2NyFtxKAPwAAAHU"]
[Thu Jul 30 14:06:06.771014 2026] [security2:error] [pid 1004636:tid 1004860] [client 135.119.63.61:21594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cgi-binalfa.php"] [unique_id "amugnu_uyupB2NyFtxKARwAAACQ"]
[Thu Jul 30 14:06:06.939163 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amugnu_uyupB2NyFtxKATAAAAGs"]
[Thu Jul 30 14:06:06.939282 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amugnu_uyupB2NyFtxKATAAAAGs"]
[Thu Jul 30 14:06:06.939407 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amugnu_uyupB2NyFtxKATAAAAGs"]
[Thu Jul 30 14:06:06.981576 2026] [security2:error] [pid 1004636:tid 1004845] [client 20.52.125.110:17135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/f7.php"] [unique_id "amugnu_uyupB2NyFtxKATQAAABY"]
[Thu Jul 30 14:06:07.123058 2026] [security2:error] [pid 1004636:tid 1004919] [client 20.91.199.21:41025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/cgi-bin/about.php"] [unique_id "amugn-_uyupB2NyFtxKAUgAAAF0"]
[Thu Jul 30 14:06:07.224697 2026] [security2:error] [pid 1004636:tid 1004857] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amugn-_uyupB2NyFtxKAVAAAACE"]
[Thu Jul 30 14:06:07.224834 2026] [security2:error] [pid 1004636:tid 1004857] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amugn-_uyupB2NyFtxKAVAAAACE"]
[Thu Jul 30 14:06:07.306819 2026] [security2:error] [pid 1004636:tid 1004940] [client 135.119.63.61:35347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/class-wp-image.php"] [unique_id "amugn-_uyupB2NyFtxKAWgAAAHA"]
[Thu Jul 30 14:06:07.521022 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amugn-_uyupB2NyFtxKAYwAAADE"]
[Thu Jul 30 14:06:07.521136 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amugn-_uyupB2NyFtxKAYwAAADE"]
[Thu Jul 30 14:06:07.672008 2026] [security2:error] [pid 1004636:tid 1004927] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/database.sql"] [unique_id "amugn-_uyupB2NyFtxKAZQAAAGQ"]
[Thu Jul 30 14:06:07.675207 2026] [security2:error] [pid 1004636:tid 1004872] [client 135.119.63.61:51487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cgi-binbypass.php"] [unique_id "amugn-_uyupB2NyFtxKAZgAAADA"]
[Thu Jul 30 14:06:07.699649 2026] [security2:error] [pid 1004636:tid 1004921] [client 189.6.88.213:55477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugn-_uyupB2NyFtxKAZwAAAF8"]
[Thu Jul 30 14:06:07.699736 2026] [security2:error] [pid 1004636:tid 1004921] [client 189.6.88.213:55477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugn-_uyupB2NyFtxKAZwAAAF8"]
[Thu Jul 30 14:06:07.825965 2026] [security2:error] [pid 1004636:tid 1004930] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/edit.php"] [unique_id "amugn-_uyupB2NyFtxKAaQAAAGc"]
[Thu Jul 30 14:06:07.826075 2026] [security2:error] [pid 1004636:tid 1004930] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/edit.php"] [unique_id "amugn-_uyupB2NyFtxKAaQAAAGc"]
[Thu Jul 30 14:06:08.108065 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amugoO_uyupB2NyFtxKAdQAAADM"]
[Thu Jul 30 14:06:08.108212 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amugoO_uyupB2NyFtxKAdQAAADM"]
[Thu Jul 30 14:06:08.373021 2026] [security2:error] [pid 1004636:tid 1004836] [client 162.141.167.36:56538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lalibanista.com"] [uri "/.env"] [unique_id "amugoO_uyupB2NyFtxKAewAAAA4"]
[Thu Jul 30 14:06:08.467619 2026] [security2:error] [pid 1004636:tid 1004828] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/inputs.php"] [unique_id "amugoO_uyupB2NyFtxKAgAAAAAY"]
[Thu Jul 30 14:06:08.467714 2026] [security2:error] [pid 1004636:tid 1004828] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/inputs.php"] [unique_id "amugoO_uyupB2NyFtxKAgAAAAAY"]
[Thu Jul 30 14:06:08.468905 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.203.148.31:65334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/hehe.php"] [unique_id "amugoO_uyupB2NyFtxKAgQAAAAs"]
[Thu Jul 30 14:06:08.504661 2026] [security2:error] [pid 1004636:tid 1004896] [client 135.119.63.61:34339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/cgi-bink.php"] [unique_id "amugoO_uyupB2NyFtxKAggAAAEY"]
[Thu Jul 30 14:06:08.545626 2026] [security2:error] [pid 1004636:tid 1004916] [client 20.52.125.110:16541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/nw.php"] [unique_id "amugoO_uyupB2NyFtxKAgwAAAFo"]
[Thu Jul 30 14:06:08.556137 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.91.199.21:11677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amugoO_uyupB2NyFtxKAhAAAAEU"]
[Thu Jul 30 14:06:08.830437 2026] [core:notice] [pid 1004636:tid 1004832] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:08.876199 2026] [security2:error] [pid 1004636:tid 1004840] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/av.php"] [unique_id "amugoO_uyupB2NyFtxKAjwAAABE"]
[Thu Jul 30 14:06:08.876297 2026] [security2:error] [pid 1004636:tid 1004840] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/av.php"] [unique_id "amugoO_uyupB2NyFtxKAjwAAABE"]
[Thu Jul 30 14:06:09.211388 2026] [security2:error] [pid 1004636:tid 1004883] [client 135.119.63.61:50397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/bnm.php"] [unique_id "amugoe_uyupB2NyFtxKAoAAAADo"]
[Thu Jul 30 14:06:09.216992 2026] [security2:error] [pid 1004636:tid 1004906] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/classwithtostring.php"] [unique_id "amugoe_uyupB2NyFtxKAoQAAAFA"]
[Thu Jul 30 14:06:09.217105 2026] [security2:error] [pid 1004636:tid 1004906] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/classwithtostring.php"] [unique_id "amugoe_uyupB2NyFtxKAoQAAAFA"]
[Thu Jul 30 14:06:09.269630 2026] [security2:error] [pid 1004636:tid 1004857] [client 20.52.125.110:16588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/ova.php"] [unique_id "amugoe_uyupB2NyFtxKAowAAACE"]
[Thu Jul 30 14:06:09.274896 2026] [security2:error] [pid 1004636:tid 1004885] [client 20.203.148.31:37307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/rk2.php"] [unique_id "amugoe_uyupB2NyFtxKApAAAADw"]
[Thu Jul 30 14:06:09.492013 2026] [security2:error] [pid 1004636:tid 1004858] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/themes/index.php"] [unique_id "amugoe_uyupB2NyFtxKArwAAACI"]
[Thu Jul 30 14:06:09.492154 2026] [security2:error] [pid 1004636:tid 1004858] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/themes/index.php"] [unique_id "amugoe_uyupB2NyFtxKArwAAACI"]
[Thu Jul 30 14:06:09.519877 2026] [security2:error] [pid 1004636:tid 1004847] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugoO_uyupB2NyFtxKAlQAAABg"]
[Thu Jul 30 14:06:09.563704 2026] [security2:error] [pid 1004636:tid 1004900] [client 135.119.63.61:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/classsmtps.php"] [unique_id "amugoe_uyupB2NyFtxKAsAAAAEo"]
[Thu Jul 30 14:06:09.764494 2026] [security2:error] [pid 1004636:tid 1004863] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-blog.php"] [unique_id "amugoe_uyupB2NyFtxKAtgAAACc"]
[Thu Jul 30 14:06:09.764646 2026] [security2:error] [pid 1004636:tid 1004863] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-blog.php"] [unique_id "amugoe_uyupB2NyFtxKAtgAAACc"]
[Thu Jul 30 14:06:10.016414 2026] [security2:error] [pid 1004636:tid 1004942] [client 20.52.125.110:17088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/robots.php"] [unique_id "amugou_uyupB2NyFtxKAvwAAAHI"]
[Thu Jul 30 14:06:10.034176 2026] [security2:error] [pid 1004636:tid 1004826] [client 162.141.167.36:56538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lalibanista.com"] [uri "/api/.env"] [unique_id "amugou_uyupB2NyFtxKAwAAAAAQ"]
[Thu Jul 30 14:06:10.044922 2026] [core:error] [pid 1004636:tid 1004909] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:10.044940 2026] [core:error] [pid 1004636:tid 1004909] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:10.045038 2026] [security2:error] [pid 1004636:tid 1004909] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugou_uyupB2NyFtxKAwQAAAFM"]
[Thu Jul 30 14:06:10.054283 2026] [security2:error] [pid 1004636:tid 1004943] [client 172.213.208.20:38386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/user/index.php"] [unique_id "amugou_uyupB2NyFtxKAwgAAAHM"]
[Thu Jul 30 14:06:10.328665 2026] [security2:error] [pid 1004636:tid 1004926] [client 162.141.167.36:57168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lalibanista.com"] [uri "/index.php"] [unique_id "amugou_uyupB2NyFtxKAxwAAAGM"]
[Thu Jul 30 14:06:10.443069 2026] [security2:error] [pid 1004636:tid 1004850] [client 20.91.199.21:11409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amugou_uyupB2NyFtxKAzQAAABs"]
[Thu Jul 30 14:06:10.445815 2026] [security2:error] [pid 1004636:tid 1004876] [client 162.141.167.36:56538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lalibanista.com"] [uri "/backend/.env"] [unique_id "amugou_uyupB2NyFtxKAzgAAADQ"]
[Thu Jul 30 14:06:10.484542 2026] [security2:error] [pid 1004636:tid 1004932] [client 135.119.63.61:29525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/classwithtostring.php"] [unique_id "amugou_uyupB2NyFtxKA0QAAAGk"]
[Thu Jul 30 14:06:10.524079 2026] [security2:error] [pid 1004636:tid 1004848] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amugou_uyupB2NyFtxKA1AAAABk"]
[Thu Jul 30 14:06:10.524167 2026] [security2:error] [pid 1004636:tid 1004848] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amugou_uyupB2NyFtxKA1AAAABk"]
[Thu Jul 30 14:06:10.571336 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.52.125.110:16595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/alf.php"] [unique_id "amugou_uyupB2NyFtxKA1gAAACQ"]
[Thu Jul 30 14:06:10.740766 2026] [security2:error] [pid 1004636:tid 1004856] [client 135.119.63.61:50391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/bootstrap.php"] [unique_id "amugou_uyupB2NyFtxKA2wAAACA"]
[Thu Jul 30 14:06:10.751727 2026] [security2:error] [pid 1004636:tid 1004737] [remote 74.7.243.224:34650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amugou_uyupB2NyFtxKA3QAAPjA"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:06:10.809160 2026] [security2:error] [pid 1004636:tid 1004944] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/adminfuns.php"] [unique_id "amugou_uyupB2NyFtxKA4AAAAHQ"]
[Thu Jul 30 14:06:10.809256 2026] [security2:error] [pid 1004636:tid 1004944] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/adminfuns.php"] [unique_id "amugou_uyupB2NyFtxKA4AAAAHQ"]
[Thu Jul 30 14:06:10.894761 2026] [security2:error] [pid 1004636:tid 1004870] [client 162.141.167.36:56538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lalibanista.com"] [uri "/index.php"] [unique_id "amugou_uyupB2NyFtxKA3gAAAC4"]
[Thu Jul 30 14:06:10.945095 2026] [security2:error] [pid 1004636:tid 1004832] [client 197.184.111.140:2533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugou_uyupB2NyFtxKA1QAACkE"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxvideos.cc%2Fhot-hidden-camera-films-reality-sex-scene.html
[Thu Jul 30 14:06:11.155584 2026] [security2:error] [pid 1004636:tid 1004841] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/goods.php"] [unique_id "amugo-_uyupB2NyFtxKA6wAAABI"]
[Thu Jul 30 14:06:11.155676 2026] [security2:error] [pid 1004636:tid 1004841] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/goods.php"] [unique_id "amugo-_uyupB2NyFtxKA6wAAABI"]
[Thu Jul 30 14:06:11.172335 2026] [security2:error] [pid 1004636:tid 1004869] [client 158.158.41.78:50535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amugo-_uyupB2NyFtxKA7AAAAC0"]
[Thu Jul 30 14:06:11.188881 2026] [security2:error] [pid 1004636:tid 1004940] [client 181.116.200.68:40389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugo-_uyupB2NyFtxKA7QAAAHA"]
[Thu Jul 30 14:06:11.189014 2026] [security2:error] [pid 1004636:tid 1004940] [client 181.116.200.68:40389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugo-_uyupB2NyFtxKA7QAAAHA"]
[Thu Jul 30 14:06:11.355035 2026] [core:error] [pid 1004636:tid 1004834] [client 172.213.208.20:38337] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:11.355063 2026] [core:error] [pid 1004636:tid 1004834] [client 172.213.208.20:38337] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:11.412170 2026] [security2:error] [pid 1004636:tid 1004948] [client 20.203.148.31:61772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/setup-config.php"] [unique_id "amugo-_uyupB2NyFtxKA9AAAAHg"]
[Thu Jul 30 14:06:11.427235 2026] [security2:error] [pid 1004636:tid 1004907] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ms-edit.php"] [unique_id "amugo-_uyupB2NyFtxKA9QAAAFE"]
[Thu Jul 30 14:06:11.427352 2026] [security2:error] [pid 1004636:tid 1004907] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ms-edit.php"] [unique_id "amugo-_uyupB2NyFtxKA9QAAAFE"]
[Thu Jul 30 14:06:11.487087 2026] [core:notice] [pid 1004636:tid 1004762] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:11.554327 2026] [security2:error] [pid 1004636:tid 1004928] [client 20.52.125.110:16618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/feedback.php"] [unique_id "amugo-_uyupB2NyFtxKA-wAAAGU"]
[Thu Jul 30 14:06:11.717178 2026] [security2:error] [pid 1004636:tid 1004871] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/222.php"] [unique_id "amugo-_uyupB2NyFtxKBAAAAAC8"]
[Thu Jul 30 14:06:11.717288 2026] [security2:error] [pid 1004636:tid 1004871] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/222.php"] [unique_id "amugo-_uyupB2NyFtxKBAAAAAC8"]
[Thu Jul 30 14:06:11.826712 2026] [security2:error] [pid 1004636:tid 1004920] [client 172.213.208.20:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amugo-_uyupB2NyFtxKBBQAAAF4"]
[Thu Jul 30 14:06:11.873188 2026] [security2:error] [pid 1004636:tid 1004918] [client 103.190.40.154:21376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugo-_uyupB2NyFtxKBBgAAAFw"]
[Thu Jul 30 14:06:11.873308 2026] [security2:error] [pid 1004636:tid 1004918] [client 103.190.40.154:21376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugo-_uyupB2NyFtxKBBgAAAFw"]
[Thu Jul 30 14:06:11.908807 2026] [security2:error] [pid 1004636:tid 1004883] [client 20.91.199.21:41279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-admin/css/about.php"] [unique_id "amugo-_uyupB2NyFtxKBCAAAADo"]
[Thu Jul 30 14:06:11.990365 2026] [security2:error] [pid 1004636:tid 1004874] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/cgi-bin/index.php"] [unique_id "amugo-_uyupB2NyFtxKBDAAAADI"]
[Thu Jul 30 14:06:11.990483 2026] [security2:error] [pid 1004636:tid 1004874] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/cgi-bin/index.php"] [unique_id "amugo-_uyupB2NyFtxKBDAAAADI"]
[Thu Jul 30 14:06:12.123542 2026] [core:notice] [pid 1004636:tid 1004702] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:12.176875 2026] [security2:error] [pid 1004636:tid 1004946] [client 20.203.148.31:34761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/a7.php"] [unique_id "amugpO_uyupB2NyFtxKBFgAAAHY"]
[Thu Jul 30 14:06:12.284918 2026] [core:error] [pid 1004636:tid 1004859] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:12.284941 2026] [core:error] [pid 1004636:tid 1004859] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:12.285062 2026] [security2:error] [pid 1004636:tid 1004859] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugpO_uyupB2NyFtxKBGQAAACM"]
[Thu Jul 30 14:06:12.322482 2026] [security2:error] [pid 1004636:tid 1004930] [client 135.119.63.61:22897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/buy.php"] [unique_id "amugpO_uyupB2NyFtxKBGgAAAGc"]
[Thu Jul 30 14:06:12.555876 2026] [security2:error] [pid 1004636:tid 1004877] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/BDKR28WP.php"] [unique_id "amugpO_uyupB2NyFtxKBIgAAADU"]
[Thu Jul 30 14:06:12.555971 2026] [security2:error] [pid 1004636:tid 1004877] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/BDKR28WP.php"] [unique_id "amugpO_uyupB2NyFtxKBIgAAADU"]
[Thu Jul 30 14:06:12.602198 2026] [security2:error] [pid 1004636:tid 1004887] [client 103.242.199.184:58798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugpO_uyupB2NyFtxKBJQAAAD4"]
[Thu Jul 30 14:06:12.602318 2026] [security2:error] [pid 1004636:tid 1004887] [client 103.242.199.184:58798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugpO_uyupB2NyFtxKBJQAAAD4"]
[Thu Jul 30 14:06:12.622419 2026] [security2:error] [pid 1004636:tid 1004943] [client 135.119.63.61:34510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/config.php"] [unique_id "amugpO_uyupB2NyFtxKBJwAAAHM"]
[Thu Jul 30 14:06:12.834696 2026] [core:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:12.834728 2026] [core:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:12.834870 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugpO_uyupB2NyFtxKBMAAAABU"]
[Thu Jul 30 14:06:13.003508 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.52.125.110:16576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/gettest.php"] [unique_id "amugpe_uyupB2NyFtxKBNQAAAAc"]
[Thu Jul 30 14:06:13.056766 2026] [security2:error] [pid 1004636:tid 1004933] [client 20.203.148.31:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/f7.php"] [unique_id "amugpe_uyupB2NyFtxKBNwAAAGo"]
[Thu Jul 30 14:06:13.351489 2026] [core:error] [pid 1004636:tid 1004863] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:13.351516 2026] [core:error] [pid 1004636:tid 1004863] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:13.351648 2026] [security2:error] [pid 1004636:tid 1004863] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugpe_uyupB2NyFtxKBQgAAACc"]
[Thu Jul 30 14:06:13.372649 2026] [security2:error] [pid 1004636:tid 1004858] [client 135.119.63.61:42253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/chosen.php"] [unique_id "amugpe_uyupB2NyFtxKBQwAAACI"]
[Thu Jul 30 14:06:13.593439 2026] [security2:error] [pid 1004636:tid 1004872] [client 135.119.63.61:7244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/core.php"] [unique_id "amugpe_uyupB2NyFtxKBTgAAADA"]
[Thu Jul 30 14:06:13.626185 2026] [security2:error] [pid 1004636:tid 1004890] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp.php"] [unique_id "amugpe_uyupB2NyFtxKBUwAAAEE"]
[Thu Jul 30 14:06:13.626304 2026] [security2:error] [pid 1004636:tid 1004890] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp.php"] [unique_id "amugpe_uyupB2NyFtxKBUwAAAEE"]
[Thu Jul 30 14:06:13.684640 2026] [security2:error] [pid 1004636:tid 1004868] [client 20.203.148.31:61369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/nw.php"] [unique_id "amugpe_uyupB2NyFtxKBVQAAACw"]
[Thu Jul 30 14:06:13.735020 2026] [security2:error] [pid 1004636:tid 1004852] [client 158.158.41.78:50611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/inputs.php"] [unique_id "amugpe_uyupB2NyFtxKBWQAAAB0"]
[Thu Jul 30 14:06:13.897899 2026] [security2:error] [pid 1004636:tid 1004914] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/abcd.php"] [unique_id "amugpe_uyupB2NyFtxKBWwAAAFg"]
[Thu Jul 30 14:06:13.898052 2026] [security2:error] [pid 1004636:tid 1004914] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/abcd.php"] [unique_id "amugpe_uyupB2NyFtxKBWwAAAFg"]
[Thu Jul 30 14:06:14.152614 2026] [security2:error] [pid 1004636:tid 1004930] [client 162.141.167.36:35354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lalibanista.com"] [uri "/index.php"] [unique_id "amugpu_uyupB2NyFtxKBZQAAAGc"]
[Thu Jul 30 14:06:14.177934 2026] [security2:error] [pid 1004636:tid 1004839] [client 162.141.167.36:35356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lalibanista.com"] [uri "/index.php"] [unique_id "amugpu_uyupB2NyFtxKBZAAAABA"]
[Thu Jul 30 14:06:14.186764 2026] [security2:error] [pid 1004636:tid 1004904] [client 162.141.167.36:35338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lalibanista.com"] [uri "/index.php"] [unique_id "amugpu_uyupB2NyFtxKBaQAAAE4"]
[Thu Jul 30 14:06:14.191737 2026] [security2:error] [pid 1004636:tid 1004840] [client 162.141.167.36:35394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lalibanista.com"] [uri "/index.php"] [unique_id "amugpu_uyupB2NyFtxKBZwAAABE"]
[Thu Jul 30 14:06:14.192906 2026] [security2:error] [pid 1004636:tid 1004860] [client 162.141.167.36:35372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lalibanista.com"] [uri "/index.php"] [unique_id "amugpu_uyupB2NyFtxKBZgAAACQ"]
[Thu Jul 30 14:06:14.193935 2026] [security2:error] [pid 1004636:tid 1004845] [client 162.141.167.36:35360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lalibanista.com"] [uri "/index.php"] [unique_id "amugpu_uyupB2NyFtxKBaAAAABY"]
[Thu Jul 30 14:06:14.245361 2026] [security2:error] [pid 1004636:tid 1004855] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/a1.php"] [unique_id "amugpu_uyupB2NyFtxKBcwAAAB8"]
[Thu Jul 30 14:06:14.245473 2026] [security2:error] [pid 1004636:tid 1004855] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/a1.php"] [unique_id "amugpu_uyupB2NyFtxKBcwAAAB8"]
[Thu Jul 30 14:06:14.379796 2026] [security2:error] [pid 1004636:tid 1004919] [client 135.119.63.61:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/css.php"] [unique_id "amugpu_uyupB2NyFtxKBeQAAAF0"]
[Thu Jul 30 14:06:14.444363 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.52.125.110:17092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/maint.php"] [unique_id "amugpu_uyupB2NyFtxKBewAAAD0"]
[Thu Jul 30 14:06:14.450812 2026] [security2:error] [pid 1004636:tid 1004911] [client 135.119.63.61:50389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/class-wp-image.php"] [unique_id "amugpu_uyupB2NyFtxKBfQAAAFU"]
[Thu Jul 30 14:06:14.455849 2026] [security2:error] [pid 1004636:tid 1004873] [client 113.199.252.252:42438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amugpu_uyupB2NyFtxKBagAAMVQ"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=https%3A%2F%2Ft.me%2Ffilmfilmfilmes%2F24
[Thu Jul 30 14:06:14.532235 2026] [security2:error] [pid 1004636:tid 1004905] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amugpu_uyupB2NyFtxKBgQAAAE8"]
[Thu Jul 30 14:06:14.532331 2026] [security2:error] [pid 1004636:tid 1004905] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amugpu_uyupB2NyFtxKBgQAAAE8"]
[Thu Jul 30 14:06:14.546043 2026] [security2:error] [pid 1004636:tid 1004876] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugpe_uyupB2NyFtxKBXwAAADQ"]
[Thu Jul 30 14:06:14.690041 2026] [security2:error] [pid 1004636:tid 1004953] [client 103.231.91.59:49198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amugpu_uyupB2NyFtxKBhwAAAH0"]
[Thu Jul 30 14:06:14.690173 2026] [security2:error] [pid 1004636:tid 1004953] [client 103.231.91.59:49198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amugpu_uyupB2NyFtxKBhwAAAH0"]
[Thu Jul 30 14:06:14.825054 2026] [security2:error] [pid 1004636:tid 1004863] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/cgi-bin/admin.php"] [unique_id "amugpu_uyupB2NyFtxKBjQAAACc"]
[Thu Jul 30 14:06:14.825157 2026] [security2:error] [pid 1004636:tid 1004863] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/cgi-bin/admin.php"] [unique_id "amugpu_uyupB2NyFtxKBjQAAACc"]
[Thu Jul 30 14:06:15.048315 2026] [security2:error] [pid 1004636:tid 1004938] [client 158.158.41.78:27529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/index.php"] [unique_id "amugp-_uyupB2NyFtxKBkgAAAG4"]
[Thu Jul 30 14:06:15.063675 2026] [security2:error] [pid 1004636:tid 1004898] [client 20.52.125.110:16620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/files.php"] [unique_id "amugp-_uyupB2NyFtxKBlAAAAEg"]
[Thu Jul 30 14:06:15.097177 2026] [core:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:15.097201 2026] [core:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:15.097316 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugp-_uyupB2NyFtxKBlgAAADM"]
[Thu Jul 30 14:06:15.385691 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/simple.php"] [unique_id "amugp-_uyupB2NyFtxKBnwAAAAg"]
[Thu Jul 30 14:06:15.385804 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/simple.php"] [unique_id "amugp-_uyupB2NyFtxKBnwAAAAg"]
[Thu Jul 30 14:06:15.670721 2026] [security2:error] [pid 1004636:tid 1004859] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xxx.php"] [unique_id "amugp-_uyupB2NyFtxKBpwAAACM"]
[Thu Jul 30 14:06:15.670834 2026] [security2:error] [pid 1004636:tid 1004859] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xxx.php"] [unique_id "amugp-_uyupB2NyFtxKBpwAAACM"]
[Thu Jul 30 14:06:15.939375 2026] [security2:error] [pid 1004636:tid 1004870] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/hypo.php"] [unique_id "amugp-_uyupB2NyFtxKBsgAAAC4"]
[Thu Jul 30 14:06:15.939467 2026] [security2:error] [pid 1004636:tid 1004870] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/hypo.php"] [unique_id "amugp-_uyupB2NyFtxKBsgAAAC4"]
[Thu Jul 30 14:06:15.949215 2026] [security2:error] [pid 1004636:tid 1004854] [client 172.213.208.20:14274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/index/function.php"] [unique_id "amugp-_uyupB2NyFtxKBswAAAB4"]
[Thu Jul 30 14:06:16.032595 2026] [security2:error] [pid 1004636:tid 1004929] [client 135.119.63.61:50387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/classsmtps.php"] [unique_id "amugqO_uyupB2NyFtxKBtQAAAGY"]
[Thu Jul 30 14:06:16.134440 2026] [security2:error] [pid 1004636:tid 1004925] [client 20.52.125.110:16578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/gecko.php"] [unique_id "amugqO_uyupB2NyFtxKBvQAAAGI"]
[Thu Jul 30 14:06:16.136895 2026] [security2:error] [pid 1004636:tid 1004852] [client 135.119.63.61:29507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/database.php"] [unique_id "amugqO_uyupB2NyFtxKBvgAAAB0"]
[Thu Jul 30 14:06:16.291322 2026] [core:error] [pid 1004636:tid 1004876] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:16.291342 2026] [core:error] [pid 1004636:tid 1004876] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:16.291438 2026] [security2:error] [pid 1004636:tid 1004876] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugqO_uyupB2NyFtxKBwwAAADQ"]
[Thu Jul 30 14:06:16.648518 2026] [core:notice] [pid 1004636:tid 1004778] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:16.650693 2026] [security2:error] [pid 1004636:tid 1004928] [client 74.7.244.39:38270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amugqO_uyupB2NyFtxKBzQAAZVc"], referer: https://blackrockanimalhospital.com/robots.txt
[Thu Jul 30 14:06:16.678415 2026] [security2:error] [pid 1004636:tid 1004939] [client 20.52.125.110:16607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/zwso.php"] [unique_id "amugqO_uyupB2NyFtxKBzgAAAG8"]
[Thu Jul 30 14:06:16.957871 2026] [security2:error] [pid 1004636:tid 1004952] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugqO_uyupB2NyFtxKBuQAAAHw"]
[Thu Jul 30 14:06:17.073581 2026] [security2:error] [pid 1004636:tid 1004892] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amugqe_uyupB2NyFtxKB3QAAAEM"]
[Thu Jul 30 14:06:17.197461 2026] [security2:error] [pid 1004636:tid 1004954] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env%5e"] [unique_id "amugqe_uyupB2NyFtxKB3wAAAH4"]
[Thu Jul 30 14:06:17.302061 2026] [security2:error] [pid 1004636:tid 1004903] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/chosen.php"] [unique_id "amugqe_uyupB2NyFtxKB4AAAAE0"]
[Thu Jul 30 14:06:17.302175 2026] [security2:error] [pid 1004636:tid 1004903] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/chosen.php"] [unique_id "amugqe_uyupB2NyFtxKB4AAAAE0"]
[Thu Jul 30 14:06:17.623370 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.91.199.21:19901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-admin/images/about.php"] [unique_id "amugqe_uyupB2NyFtxKB6wAAABQ"]
[Thu Jul 30 14:06:17.631138 2026] [core:error] [pid 1004636:tid 1004893] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:17.631169 2026] [core:error] [pid 1004636:tid 1004893] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:17.631306 2026] [security2:error] [pid 1004636:tid 1004893] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugqe_uyupB2NyFtxKB7QAAAEQ"]
[Thu Jul 30 14:06:17.951033 2026] [security2:error] [pid 1004636:tid 1004925] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/als.php"] [unique_id "amugqe_uyupB2NyFtxKB-AAAAGI"]
[Thu Jul 30 14:06:17.951131 2026] [security2:error] [pid 1004636:tid 1004925] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/als.php"] [unique_id "amugqe_uyupB2NyFtxKB-AAAAGI"]
[Thu Jul 30 14:06:18.085795 2026] [security2:error] [pid 1004636:tid 1004906] [client 135.119.63.61:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/db.php"] [unique_id "amugqu_uyupB2NyFtxKB_gAAAFA"]
[Thu Jul 30 14:06:18.262558 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/pol.php"] [unique_id "amugqu_uyupB2NyFtxKCAAAAABU"]
[Thu Jul 30 14:06:18.262718 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/pol.php"] [unique_id "amugqu_uyupB2NyFtxKCAAAAABU"]
[Thu Jul 30 14:06:18.292421 2026] [security2:error] [pid 1004636:tid 1004849] [client 20.52.125.110:16639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/13.php"] [unique_id "amugqu_uyupB2NyFtxKCAQAAABo"]
[Thu Jul 30 14:06:18.453258 2026] [security2:error] [pid 1004636:tid 1004905] [client 189.6.88.213:56024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugqu_uyupB2NyFtxKCCAAAAE8"]
[Thu Jul 30 14:06:18.453462 2026] [security2:error] [pid 1004636:tid 1004905] [client 189.6.88.213:56024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugqu_uyupB2NyFtxKCCAAAAE8"]
[Thu Jul 30 14:06:18.666816 2026] [security2:error] [pid 1004636:tid 1004949] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file5.php"] [unique_id "amugqu_uyupB2NyFtxKCEAAAAHk"]
[Thu Jul 30 14:06:18.666896 2026] [security2:error] [pid 1004636:tid 1004949] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file5.php"] [unique_id "amugqu_uyupB2NyFtxKCEAAAAHk"]
[Thu Jul 30 14:06:18.899425 2026] [security2:error] [pid 1004636:tid 1004835] [client 20.91.199.21:3184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amugqu_uyupB2NyFtxKCEwAAAA0"]
[Thu Jul 30 14:06:18.950701 2026] [security2:error] [pid 1004636:tid 1004938] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file.php"] [unique_id "amugqu_uyupB2NyFtxKCFgAAAG4"]
[Thu Jul 30 14:06:18.950789 2026] [security2:error] [pid 1004636:tid 1004938] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file.php"] [unique_id "amugqu_uyupB2NyFtxKCFgAAAG4"]
[Thu Jul 30 14:06:18.988336 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.52.125.110:17093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/ava.php"] [unique_id "amugqu_uyupB2NyFtxKCGgAAAA8"]
[Thu Jul 30 14:06:19.048560 2026] [core:error] [pid 1004636:tid 1004913] [client 172.213.208.20:42521] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:19.048592 2026] [core:error] [pid 1004636:tid 1004913] [client 172.213.208.20:42521] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:19.197534 2026] [security2:error] [pid 1004636:tid 1004863] [client 135.119.63.61:34498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/default.php"] [unique_id "amugq-_uyupB2NyFtxKCIQAAACc"]
[Thu Jul 30 14:06:19.232212 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amugq-_uyupB2NyFtxKCIwAAAAg"]
[Thu Jul 30 14:06:19.232319 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amugq-_uyupB2NyFtxKCIwAAAAg"]
[Thu Jul 30 14:06:19.499935 2026] [security2:error] [pid 1004636:tid 1004839] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/aa2.php"] [unique_id "amugq-_uyupB2NyFtxKCLQAAABA"]
[Thu Jul 30 14:06:19.500034 2026] [security2:error] [pid 1004636:tid 1004839] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/aa2.php"] [unique_id "amugq-_uyupB2NyFtxKCLQAAABA"]
[Thu Jul 30 14:06:19.656863 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.203.148.31:61328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/ova.php"] [unique_id "amugq-_uyupB2NyFtxKCMgAAAFY"]
[Thu Jul 30 14:06:19.811064 2026] [security2:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ccou.php"] [unique_id "amugq-_uyupB2NyFtxKCNgAAAAo"]
[Thu Jul 30 14:06:19.811181 2026] [security2:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ccou.php"] [unique_id "amugq-_uyupB2NyFtxKCNgAAAAo"]
[Thu Jul 30 14:06:20.003893 2026] [security2:error] [pid 1004636:tid 1004881] [client 135.119.63.61:29514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/dropdown.php"] [unique_id "amugrO_uyupB2NyFtxKCPAAAADk"]
[Thu Jul 30 14:06:20.142282 2026] [security2:error] [pid 1004636:tid 1004852] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dr.php"] [unique_id "amugrO_uyupB2NyFtxKCQQAAAB0"]
[Thu Jul 30 14:06:20.142364 2026] [security2:error] [pid 1004636:tid 1004852] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dr.php"] [unique_id "amugrO_uyupB2NyFtxKCQQAAAB0"]
[Thu Jul 30 14:06:20.261088 2026] [security2:error] [pid 1004636:tid 1004822] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/_profiler%00"] [unique_id "amugrO_uyupB2NyFtxKCRgAAAAA"]
[Thu Jul 30 14:06:20.261722 2026] [core:error] [pid 1004636:tid 1004893] [client 172.213.208.20:21001] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:20.261741 2026] [core:error] [pid 1004636:tid 1004893] [client 172.213.208.20:21001] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:20.408512 2026] [security2:error] [pid 1004636:tid 1004824] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xamp.php"] [unique_id "amugrO_uyupB2NyFtxKCSAAAAAI"]
[Thu Jul 30 14:06:20.408661 2026] [security2:error] [pid 1004636:tid 1004824] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xamp.php"] [unique_id "amugrO_uyupB2NyFtxKCSAAAAAI"]
[Thu Jul 30 14:06:20.693126 2026] [security2:error] [pid 1004636:tid 1004858] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/bless.php"] [unique_id "amugrO_uyupB2NyFtxKCUQAAACI"]
[Thu Jul 30 14:06:20.693221 2026] [security2:error] [pid 1004636:tid 1004858] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/bless.php"] [unique_id "amugrO_uyupB2NyFtxKCUQAAACI"]
[Thu Jul 30 14:06:20.781067 2026] [security2:error] [pid 1004636:tid 1004884] [client 135.119.63.61:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/edit.php"] [unique_id "amugrO_uyupB2NyFtxKCVwAAADs"]
[Thu Jul 30 14:06:20.852521 2026] [security2:error] [pid 1004636:tid 1004925] [client 135.119.63.61:22852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/classwithtostring.php"] [unique_id "amugrO_uyupB2NyFtxKCWAAAAGI"]
[Thu Jul 30 14:06:21.130712 2026] [security2:error] [pid 1004636:tid 1004826] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file25.php"] [unique_id "amugre_uyupB2NyFtxKCYQAAAAQ"]
[Thu Jul 30 14:06:21.130806 2026] [security2:error] [pid 1004636:tid 1004826] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file25.php"] [unique_id "amugre_uyupB2NyFtxKCYQAAAAQ"]
[Thu Jul 30 14:06:21.371018 2026] [core:notice] [pid 1004636:tid 1004916] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:21.441189 2026] [security2:error] [pid 1004636:tid 1004892] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file6.php"] [unique_id "amugre_uyupB2NyFtxKCaQAAAEM"]
[Thu Jul 30 14:06:21.441307 2026] [security2:error] [pid 1004636:tid 1004892] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file6.php"] [unique_id "amugre_uyupB2NyFtxKCaQAAAEM"]
[Thu Jul 30 14:06:21.642323 2026] [core:notice] [pid 1004636:tid 1004820] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:21.652885 2026] [security2:error] [pid 1004636:tid 1004897] [client 135.119.63.61:34531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/f35.php"] [unique_id "amugre_uyupB2NyFtxKCcgAAAEc"]
[Thu Jul 30 14:06:21.712700 2026] [security2:error] [pid 1004636:tid 1004932] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/a2.php"] [unique_id "amugre_uyupB2NyFtxKCdAAAAGk"]
[Thu Jul 30 14:06:21.712803 2026] [security2:error] [pid 1004636:tid 1004932] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/a2.php"] [unique_id "amugre_uyupB2NyFtxKCdAAAAGk"]
[Thu Jul 30 14:06:21.725803 2026] [security2:error] [pid 1004636:tid 1004691] [remote 5.161.62.209:25648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.psz.dtn.temporary.site"] [uri "/.env"] [unique_id "amugre_uyupB2NyFtxKCdQAAWAQ"]
[Thu Jul 30 14:06:21.781401 2026] [security2:error] [pid 1004636:tid 1004845] [client 181.116.200.68:43569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugre_uyupB2NyFtxKCdgAAABY"]
[Thu Jul 30 14:06:21.781504 2026] [security2:error] [pid 1004636:tid 1004845] [client 181.116.200.68:43569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugre_uyupB2NyFtxKCdgAAABY"]
[Thu Jul 30 14:06:21.984879 2026] [security2:error] [pid 1004636:tid 1004943] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file15.php"] [unique_id "amugre_uyupB2NyFtxKCfAAAAHM"]
[Thu Jul 30 14:06:21.985016 2026] [security2:error] [pid 1004636:tid 1004943] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file15.php"] [unique_id "amugre_uyupB2NyFtxKCfAAAAHM"]
[Thu Jul 30 14:06:21.986395 2026] [security2:error] [pid 1004636:tid 1004898] [client 158.158.41.78:22992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/network/index.php"] [unique_id "amugre_uyupB2NyFtxKCfQAAAEg"]
[Thu Jul 30 14:06:22.209151 2026] [security2:error] [pid 1004636:tid 1004854] [client 20.203.148.31:36874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/robots.php"] [unique_id "amugru_uyupB2NyFtxKChwAAAB4"]
[Thu Jul 30 14:06:22.246042 2026] [security2:error] [pid 1004636:tid 1004857] [client 135.119.63.61:22867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/config.php"] [unique_id "amugru_uyupB2NyFtxKCiAAAACE"]
[Thu Jul 30 14:06:22.256766 2026] [security2:error] [pid 1004636:tid 1004869] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/f35.php"] [unique_id "amugru_uyupB2NyFtxKCiQAAAC0"]
[Thu Jul 30 14:06:22.256849 2026] [security2:error] [pid 1004636:tid 1004869] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/f35.php"] [unique_id "amugru_uyupB2NyFtxKCiQAAAC0"]
[Thu Jul 30 14:06:22.370621 2026] [core:notice] [pid 1004636:tid 1004697] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:22.892388 2026] [security2:error] [pid 1004636:tid 1004899] [client 20.91.199.21:11458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amugru_uyupB2NyFtxKCnAAAAEk"]
[Thu Jul 30 14:06:22.947623 2026] [security2:error] [pid 1004636:tid 1004827] [client 135.119.63.61:34552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.globalmarks.pk"] [uri "/f7.php"] [unique_id "amugru_uyupB2NyFtxKCnQAAAAU"]
[Thu Jul 30 14:06:23.111383 2026] [security2:error] [pid 1004636:tid 1004862] [client 103.190.40.154:21651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugr-_uyupB2NyFtxKCogAAACY"]
[Thu Jul 30 14:06:23.111517 2026] [security2:error] [pid 1004636:tid 1004862] [client 103.190.40.154:21651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugr-_uyupB2NyFtxKCogAAACY"]
[Thu Jul 30 14:06:23.166529 2026] [security2:error] [pid 1004636:tid 1004907] [client 20.52.125.110:16625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/main.php"] [unique_id "amugr-_uyupB2NyFtxKCpwAAAFE"]
[Thu Jul 30 14:06:23.186670 2026] [security2:error] [pid 1004636:tid 1004915] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-load.php"] [unique_id "amugr-_uyupB2NyFtxKCqAAAAFk"]
[Thu Jul 30 14:06:23.186756 2026] [security2:error] [pid 1004636:tid 1004915] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-load.php"] [unique_id "amugr-_uyupB2NyFtxKCqAAAAFk"]
[Thu Jul 30 14:06:23.197002 2026] [security2:error] [pid 1004636:tid 1004948] [client 135.119.63.61:22579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/core.php"] [unique_id "amugr-_uyupB2NyFtxKCqQAAAHg"]
[Thu Jul 30 14:06:23.304711 2026] [security2:error] [pid 1004636:tid 1004924] [client 103.242.199.184:59552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugr-_uyupB2NyFtxKCrgAAAGE"]
[Thu Jul 30 14:06:23.304831 2026] [security2:error] [pid 1004636:tid 1004924] [client 103.242.199.184:59552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugr-_uyupB2NyFtxKCrgAAAGE"]
[Thu Jul 30 14:06:23.404743 2026] [security2:error] [pid 1004636:tid 1004704] [remote 103.39.93.98:42712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.93.39.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dov.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amugr-_uyupB2NyFtxKCsAAAfBA"]
[Thu Jul 30 14:06:23.454372 2026] [security2:error] [pid 1004636:tid 1004903] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xwpg.php"] [unique_id "amugr-_uyupB2NyFtxKCtQAAAE0"]
[Thu Jul 30 14:06:23.454464 2026] [security2:error] [pid 1004636:tid 1004903] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xwpg.php"] [unique_id "amugr-_uyupB2NyFtxKCtQAAAE0"]
[Thu Jul 30 14:06:23.548267 2026] [security2:error] [pid 1004636:tid 1004851] [client 158.158.41.78:50604] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/1.php"] [unique_id "amugr-_uyupB2NyFtxKCtwAAABw"]
[Thu Jul 30 14:06:23.548396 2026] [security2:error] [pid 1004636:tid 1004851] [client 158.158.41.78:50604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/1.php"] [unique_id "amugr-_uyupB2NyFtxKCtwAAABw"]
[Thu Jul 30 14:06:23.730933 2026] [core:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:23.730955 2026] [core:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:23.731058 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugr-_uyupB2NyFtxKCwgAAABQ"]
[Thu Jul 30 14:06:23.747369 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.52.125.110:17117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-file.php"] [unique_id "amugr-_uyupB2NyFtxKCxAAAACM"]
[Thu Jul 30 14:06:23.911373 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.91.199.21:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amugr-_uyupB2NyFtxKCxgAAAE4"]
[Thu Jul 30 14:06:24.068286 2026] [core:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:24.068310 2026] [core:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:24.068401 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "greecevisaassistanceislamabad.online"] [uri "/index.php"] [unique_id "amugsO_uyupB2NyFtxKCzQAAADE"]
[Thu Jul 30 14:06:24.195419 2026] [security2:error] [pid 1004636:tid 1004865] [client 20.203.148.31:36904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/alf.php"] [unique_id "amugsO_uyupB2NyFtxKC1QAAACk"]
[Thu Jul 30 14:06:24.355696 2026] [security2:error] [pid 1004636:tid 1004940] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xstelth.php"] [unique_id "amugsO_uyupB2NyFtxKC2AAAAHA"]
[Thu Jul 30 14:06:24.355815 2026] [security2:error] [pid 1004636:tid 1004940] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xstelth.php"] [unique_id "amugsO_uyupB2NyFtxKC2AAAAHA"]
[Thu Jul 30 14:06:24.388898 2026] [security2:error] [pid 1004636:tid 1004861] [client 20.52.125.110:17100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-signin.php"] [unique_id "amugsO_uyupB2NyFtxKC2QAAACU"]
[Thu Jul 30 14:06:24.546563 2026] [security2:error] [pid 1004636:tid 1004888] [client 135.119.63.61:42243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/css.php"] [unique_id "amugsO_uyupB2NyFtxKC3wAAAD8"]
[Thu Jul 30 14:06:24.660908 2026] [security2:error] [pid 1004636:tid 1004949] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-admin/network/plugins.php"] [unique_id "amugsO_uyupB2NyFtxKC4gAAAHk"]
[Thu Jul 30 14:06:24.661020 2026] [security2:error] [pid 1004636:tid 1004949] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/wp-admin/network/plugins.php"] [unique_id "amugsO_uyupB2NyFtxKC4gAAAHk"]
[Thu Jul 30 14:06:24.804060 2026] [security2:error] [pid 1004636:tid 1004854] [client 158.158.41.78:50511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/plugin.php"] [unique_id "amugsO_uyupB2NyFtxKC6QAAAB4"]
[Thu Jul 30 14:06:24.942332 2026] [security2:error] [pid 1004636:tid 1004938] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/aaa.php"] [unique_id "amugsO_uyupB2NyFtxKC6wAAAG4"]
[Thu Jul 30 14:06:24.942448 2026] [security2:error] [pid 1004636:tid 1004938] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/aaa.php"] [unique_id "amugsO_uyupB2NyFtxKC6wAAAG4"]
[Thu Jul 30 14:06:25.175444 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.52.125.110:16631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/simi.php"] [unique_id "amugse_uyupB2NyFtxKC9wAAAA8"]
[Thu Jul 30 14:06:25.230539 2026] [security2:error] [pid 1004636:tid 1004825] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/gecko.php"] [unique_id "amugse_uyupB2NyFtxKC-wAAAAM"]
[Thu Jul 30 14:06:25.230631 2026] [security2:error] [pid 1004636:tid 1004825] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/gecko.php"] [unique_id "amugse_uyupB2NyFtxKC-wAAAAM"]
[Thu Jul 30 14:06:25.405352 2026] [security2:error] [pid 1004636:tid 1004933] [client 135.119.63.61:22882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/database.php"] [unique_id "amugse_uyupB2NyFtxKDAQAAAGo"]
[Thu Jul 30 14:06:25.507506 2026] [security2:error] [pid 1004636:tid 1004860] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/pbck.php"] [unique_id "amugse_uyupB2NyFtxKDCAAAACQ"]
[Thu Jul 30 14:06:25.507616 2026] [security2:error] [pid 1004636:tid 1004860] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/pbck.php"] [unique_id "amugse_uyupB2NyFtxKDCAAAACQ"]
[Thu Jul 30 14:06:25.778500 2026] [security2:error] [pid 1004636:tid 1004919] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xiugai.php"] [unique_id "amugse_uyupB2NyFtxKDEAAAAF0"]
[Thu Jul 30 14:06:25.778603 2026] [security2:error] [pid 1004636:tid 1004919] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xiugai.php"] [unique_id "amugse_uyupB2NyFtxKDEAAAAF0"]
[Thu Jul 30 14:06:26.060220 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.52.125.110:17112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-conf.php"] [unique_id "amugsu_uyupB2NyFtxKDHQAAAD0"]
[Thu Jul 30 14:06:26.062121 2026] [security2:error] [pid 1004636:tid 1004953] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/e.php"] [unique_id "amugsu_uyupB2NyFtxKDHgAAAH0"]
[Thu Jul 30 14:06:26.062194 2026] [security2:error] [pid 1004636:tid 1004953] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/e.php"] [unique_id "amugsu_uyupB2NyFtxKDHgAAAH0"]
[Thu Jul 30 14:06:26.148354 2026] [core:notice] [pid 1004636:tid 1004870] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:26.307164 2026] [security2:error] [pid 1004636:tid 1004941] [client 135.119.63.61:22862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/db.php"] [unique_id "amugsu_uyupB2NyFtxKDLgAAAHE"]
[Thu Jul 30 14:06:26.358768 2026] [security2:error] [pid 1004636:tid 1004913] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/adminner.php"] [unique_id "amugsu_uyupB2NyFtxKDNAAAAFc"]
[Thu Jul 30 14:06:26.358903 2026] [security2:error] [pid 1004636:tid 1004913] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/adminner.php"] [unique_id "amugsu_uyupB2NyFtxKDNAAAAFc"]
[Thu Jul 30 14:06:26.632973 2026] [security2:error] [pid 1004636:tid 1004874] [client 172.237.109.114:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amugsu_uyupB2NyFtxKDJgAAADI"]
[Thu Jul 30 14:06:26.644918 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file1221.php"] [unique_id "amugsu_uyupB2NyFtxKDOwAAAGs"]
[Thu Jul 30 14:06:26.645049 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/file1221.php"] [unique_id "amugsu_uyupB2NyFtxKDOwAAAGs"]
[Thu Jul 30 14:06:26.754114 2026] [security2:error] [pid 1004636:tid 1004924] [client 20.203.148.31:37302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/feedback.php"] [unique_id "amugsu_uyupB2NyFtxKDPgAAAGE"]
[Thu Jul 30 14:06:26.923500 2026] [security2:error] [pid 1004636:tid 1004867] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/inx.php"] [unique_id "amugsu_uyupB2NyFtxKDRwAAACs"]
[Thu Jul 30 14:06:26.923596 2026] [security2:error] [pid 1004636:tid 1004867] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/inx.php"] [unique_id "amugsu_uyupB2NyFtxKDRwAAACs"]
[Thu Jul 30 14:06:27.205117 2026] [security2:error] [pid 1004636:tid 1004849] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/qqqa.php"] [unique_id "amugs-_uyupB2NyFtxKDUAAAABo"]
[Thu Jul 30 14:06:27.205223 2026] [security2:error] [pid 1004636:tid 1004849] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/qqqa.php"] [unique_id "amugs-_uyupB2NyFtxKDUAAAABo"]
[Thu Jul 30 14:06:27.335914 2026] [security2:error] [pid 1004636:tid 1004873] [client 20.203.148.31:36870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/gettest.php"] [unique_id "amugs-_uyupB2NyFtxKDWQAAADE"]
[Thu Jul 30 14:06:27.476777 2026] [security2:error] [pid 1004636:tid 1004902] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/reviall.php"] [unique_id "amugs-_uyupB2NyFtxKDWwAAAEw"]
[Thu Jul 30 14:06:27.476891 2026] [security2:error] [pid 1004636:tid 1004902] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/reviall.php"] [unique_id "amugs-_uyupB2NyFtxKDWwAAAEw"]
[Thu Jul 30 14:06:27.491750 2026] [security2:error] [pid 1004636:tid 1004949] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/erp~"] [unique_id "amugs-_uyupB2NyFtxKDXAAAAHk"]
[Thu Jul 30 14:06:27.743479 2026] [security2:error] [pid 1004636:tid 1004946] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/404.php"] [unique_id "amugs-_uyupB2NyFtxKDYwAAAHY"]
[Thu Jul 30 14:06:27.743631 2026] [security2:error] [pid 1004636:tid 1004946] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/404.php"] [unique_id "amugs-_uyupB2NyFtxKDYwAAAHY"]
[Thu Jul 30 14:06:27.807066 2026] [security2:error] [pid 1004636:tid 1004933] [client 20.52.125.110:16548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/WZGHHra0r3.php"] [unique_id "amugs-_uyupB2NyFtxKDZQAAAGo"]
[Thu Jul 30 14:06:27.873714 2026] [security2:error] [pid 1004636:tid 1004875] [client 20.203.148.31:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/maint.php"] [unique_id "amugs-_uyupB2NyFtxKDawAAADM"]
[Thu Jul 30 14:06:28.016891 2026] [security2:error] [pid 1004636:tid 1004916] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/bolt.php"] [unique_id "amugtO_uyupB2NyFtxKDdAAAAFo"]
[Thu Jul 30 14:06:28.017016 2026] [security2:error] [pid 1004636:tid 1004916] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/bolt.php"] [unique_id "amugtO_uyupB2NyFtxKDdAAAAFo"]
[Thu Jul 30 14:06:28.169783 2026] [security2:error] [pid 1004636:tid 1004887] [client 135.119.63.61:50380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/default.php"] [unique_id "amugtO_uyupB2NyFtxKDeQAAAD4"]
[Thu Jul 30 14:06:28.295030 2026] [security2:error] [pid 1004636:tid 1004851] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/File.php"] [unique_id "amugtO_uyupB2NyFtxKDfwAAABw"]
[Thu Jul 30 14:06:28.295137 2026] [security2:error] [pid 1004636:tid 1004851] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/File.php"] [unique_id "amugtO_uyupB2NyFtxKDfwAAABw"]
[Thu Jul 30 14:06:28.399763 2026] [security2:error] [pid 1004636:tid 1004897] [client 20.52.125.110:16527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/bala.php"] [unique_id "amugtO_uyupB2NyFtxKDhAAAAEc"]
[Thu Jul 30 14:06:28.424439 2026] [security2:error] [pid 1004636:tid 1004835] [client 158.158.41.78:33081] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jcsgoeastwood.org"] [uri "/1.php"] [unique_id "amugtO_uyupB2NyFtxKDiAAAAA0"]
[Thu Jul 30 14:06:28.424582 2026] [security2:error] [pid 1004636:tid 1004835] [client 158.158.41.78:33081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/1.php"] [unique_id "amugtO_uyupB2NyFtxKDiAAAAA0"]
[Thu Jul 30 14:06:28.586425 2026] [security2:error] [pid 1004636:tid 1004929] [client 74.208.111.47:53788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inmobiliariadia.com"] [uri "/.env"] [unique_id "amugtO_uyupB2NyFtxKDjgAAAGY"]
[Thu Jul 30 14:06:28.592036 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/fi22.php"] [unique_id "amugtO_uyupB2NyFtxKDkQAAAH8"]
[Thu Jul 30 14:06:28.592128 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/fi22.php"] [unique_id "amugtO_uyupB2NyFtxKDkQAAAH8"]
[Thu Jul 30 14:06:28.660972 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.91.199.21:18084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/cloud.php"] [unique_id "amugtO_uyupB2NyFtxKDlAAAADQ"]
[Thu Jul 30 14:06:28.711907 2026] [security2:error] [pid 1004636:tid 1004842] [client 20.203.148.31:59429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/files.php"] [unique_id "amugtO_uyupB2NyFtxKDlQAAABM"]
[Thu Jul 30 14:06:28.860070 2026] [security2:error] [pid 1004636:tid 1004822] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/zero.php"] [unique_id "amugtO_uyupB2NyFtxKDmQAAAAA"]
[Thu Jul 30 14:06:28.860182 2026] [security2:error] [pid 1004636:tid 1004822] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/zero.php"] [unique_id "amugtO_uyupB2NyFtxKDmQAAAAA"]
[Thu Jul 30 14:06:29.089994 2026] [security2:error] [pid 1004636:tid 1004871] [client 135.119.63.61:22903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/dropdown.php"] [unique_id "amugte_uyupB2NyFtxKDpQAAAC8"]
[Thu Jul 30 14:06:29.194918 2026] [security2:error] [pid 1004636:tid 1004865] [client 189.6.88.213:56578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugte_uyupB2NyFtxKDqAAAACk"]
[Thu Jul 30 14:06:29.195031 2026] [security2:error] [pid 1004636:tid 1004865] [client 189.6.88.213:56578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugte_uyupB2NyFtxKDqAAAACk"]
[Thu Jul 30 14:06:29.282617 2026] [security2:error] [pid 1004636:tid 1004834] [client 74.208.111.47:53837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inmobiliariadia.com"] [uri "/.env"] [unique_id "amugte_uyupB2NyFtxKDqwAAAAw"]
[Thu Jul 30 14:06:29.379256 2026] [security2:error] [pid 1004636:tid 1004849] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugtO_uyupB2NyFtxKDmAAAABo"]
[Thu Jul 30 14:06:29.409047 2026] [security2:error] [pid 1004636:tid 1004921] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1xmomo.php"] [unique_id "amugte_uyupB2NyFtxKDpgAAAF8"]
[Thu Jul 30 14:06:29.409172 2026] [security2:error] [pid 1004636:tid 1004921] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1xmomo.php"] [unique_id "amugte_uyupB2NyFtxKDpgAAAF8"]
[Thu Jul 30 14:06:29.491319 2026] [security2:error] [pid 1004636:tid 1004866] [client 20.203.148.31:62150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/gecko.php"] [unique_id "amugte_uyupB2NyFtxKDswAAACo"]
[Thu Jul 30 14:06:29.575518 2026] [security2:error] [pid 1004636:tid 1004841] [client 20.52.125.110:16616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/bk.php"] [unique_id "amugte_uyupB2NyFtxKDtgAAABI"]
[Thu Jul 30 14:06:29.701617 2026] [security2:error] [pid 1004636:tid 1004926] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/fmws.php"] [unique_id "amugte_uyupB2NyFtxKDvAAAAGM"]
[Thu Jul 30 14:06:29.701735 2026] [security2:error] [pid 1004636:tid 1004926] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/fmws.php"] [unique_id "amugte_uyupB2NyFtxKDvAAAAGM"]
[Thu Jul 30 14:06:29.853277 2026] [core:notice] [pid 1004636:tid 1004887] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:29.971994 2026] [security2:error] [pid 1004636:tid 1004845] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/3PJcpMFsD8B.php"] [unique_id "amugte_uyupB2NyFtxKDyAAAABY"]
[Thu Jul 30 14:06:29.972103 2026] [security2:error] [pid 1004636:tid 1004845] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/3PJcpMFsD8B.php"] [unique_id "amugte_uyupB2NyFtxKDyAAAABY"]
[Thu Jul 30 14:06:29.990438 2026] [security2:error] [pid 1004636:tid 1004883] [client 74.7.175.132:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.muu.udi.temporary.site"] [uri "/index.php"] [unique_id "amugs-_uyupB2NyFtxKDcQAAADo"]
[Thu Jul 30 14:06:29.991365 2026] [security2:error] [pid 1004636:tid 1004862] [client 74.7.175.132:33462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.muu.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amugs-_uyupB2NyFtxKDbQAAJlE"]
[Thu Jul 30 14:06:30.030931 2026] [security2:error] [pid 1004636:tid 1004843] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/prod.htaccess"] [unique_id "amugtu_uyupB2NyFtxKDygAAABQ"]
[Thu Jul 30 14:06:30.133501 2026] [security2:error] [pid 1004636:tid 1004917] [client 20.91.199.21:3372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amugtu_uyupB2NyFtxKDzgAAAFs"]
[Thu Jul 30 14:06:30.242194 2026] [security2:error] [pid 1004636:tid 1004881] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/hp2.php"] [unique_id "amugtu_uyupB2NyFtxKD0QAAADk"]
[Thu Jul 30 14:06:30.242376 2026] [security2:error] [pid 1004636:tid 1004881] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/hp2.php"] [unique_id "amugtu_uyupB2NyFtxKD0QAAADk"]
[Thu Jul 30 14:06:30.247371 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.52.125.110:17111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/ahax.php"] [unique_id "amugtu_uyupB2NyFtxKD0gAAAFY"]
[Thu Jul 30 14:06:30.479198 2026] [core:notice] [pid 1004636:tid 1004857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:30.527120 2026] [security2:error] [pid 1004636:tid 1004861] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/aabb.php"] [unique_id "amugtu_uyupB2NyFtxKD3QAAACU"]
[Thu Jul 30 14:06:30.527203 2026] [security2:error] [pid 1004636:tid 1004861] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/aabb.php"] [unique_id "amugtu_uyupB2NyFtxKD3QAAACU"]
[Thu Jul 30 14:06:30.562752 2026] [security2:error] [pid 1004636:tid 1004863] [client 135.119.63.61:50431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/edit.php"] [unique_id "amugtu_uyupB2NyFtxKD3wAAACc"]
[Thu Jul 30 14:06:30.572463 2026] [security2:error] [pid 1004636:tid 1004835] [client 20.203.148.31:65323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/zwso.php"] [unique_id "amugtu_uyupB2NyFtxKD4AAAAA0"]
[Thu Jul 30 14:06:30.709597 2026] [security2:error] [pid 1004636:tid 1004770] [remote 72.167.132.114:47194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jgp.fxh.temporary.site"] [uri "/wp-login.php"] [unique_id "amugtu_uyupB2NyFtxKD5QAAVU8"]
[Thu Jul 30 14:06:30.802006 2026] [security2:error] [pid 1004636:tid 1004884] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1254xx.php"] [unique_id "amugtu_uyupB2NyFtxKD5wAAADs"]
[Thu Jul 30 14:06:30.802102 2026] [security2:error] [pid 1004636:tid 1004884] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1254xx.php"] [unique_id "amugtu_uyupB2NyFtxKD5wAAADs"]
[Thu Jul 30 14:06:31.119429 2026] [security2:error] [pid 1004636:tid 1004866] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amugt-_uyupB2NyFtxKD9gAAACo"]
[Thu Jul 30 14:06:31.119530 2026] [security2:error] [pid 1004636:tid 1004866] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amugt-_uyupB2NyFtxKD9gAAACo"]
[Thu Jul 30 14:06:31.323538 2026] [security2:error] [pid 1004636:tid 1004940] [client 20.91.199.21:5723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-content/updates.php"] [unique_id "amugt-_uyupB2NyFtxKD_wAAAHA"]
[Thu Jul 30 14:06:31.389227 2026] [core:notice] [pid 1004636:tid 1004918] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:31.401057 2026] [security2:error] [pid 1004636:tid 1004932] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/pms297.php"] [unique_id "amugt-_uyupB2NyFtxKEBQAAAGk"]
[Thu Jul 30 14:06:31.401168 2026] [security2:error] [pid 1004636:tid 1004932] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/pms297.php"] [unique_id "amugt-_uyupB2NyFtxKEBQAAAGk"]
[Thu Jul 30 14:06:31.664458 2026] [security2:error] [pid 1004636:tid 1004902] [client 158.158.41.78:50507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/gg.php"] [unique_id "amugt-_uyupB2NyFtxKEEQAAAEw"]
[Thu Jul 30 14:06:31.676159 2026] [security2:error] [pid 1004636:tid 1004931] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1PJcpMFsD8B.php"] [unique_id "amugt-_uyupB2NyFtxKEEwAAAGg"]
[Thu Jul 30 14:06:31.676247 2026] [security2:error] [pid 1004636:tid 1004931] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1PJcpMFsD8B.php"] [unique_id "amugt-_uyupB2NyFtxKEEwAAAGg"]
[Thu Jul 30 14:06:31.868963 2026] [security2:error] [pid 1004636:tid 1004864] [client 20.203.148.31:65342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/13.php"] [unique_id "amugt-_uyupB2NyFtxKEFQAAACg"]
[Thu Jul 30 14:06:31.891436 2026] [security2:error] [pid 1004636:tid 1004845] [client 135.119.63.61:42283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/f35.php"] [unique_id "amugt-_uyupB2NyFtxKEFgAAABY"]
[Thu Jul 30 14:06:31.937954 2026] [security2:error] [pid 1004636:tid 1004919] [client 20.91.199.21:3361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/css/cloud.php"] [unique_id "amugt-_uyupB2NyFtxKEGAAAAF0"]
[Thu Jul 30 14:06:31.965649 2026] [security2:error] [pid 1004636:tid 1004829] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/4PJcpMFsD8B.php"] [unique_id "amugt-_uyupB2NyFtxKEHAAAAAc"]
[Thu Jul 30 14:06:31.965754 2026] [security2:error] [pid 1004636:tid 1004829] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/4PJcpMFsD8B.php"] [unique_id "amugt-_uyupB2NyFtxKEHAAAAAc"]
[Thu Jul 30 14:06:32.244281 2026] [security2:error] [pid 1004636:tid 1004870] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuguO_uyupB2NyFtxKEJQAAAC4"]
[Thu Jul 30 14:06:32.244378 2026] [security2:error] [pid 1004636:tid 1004870] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuguO_uyupB2NyFtxKEJQAAAC4"]
[Thu Jul 30 14:06:32.337210 2026] [core:notice] [pid 1004636:tid 1004784] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:32.469389 2026] [security2:error] [pid 1004636:tid 1004863] [client 181.116.200.68:64857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuguO_uyupB2NyFtxKEKgAAACc"]
[Thu Jul 30 14:06:32.469493 2026] [security2:error] [pid 1004636:tid 1004863] [client 181.116.200.68:64857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuguO_uyupB2NyFtxKEKgAAACc"]
[Thu Jul 30 14:06:32.534665 2026] [security2:error] [pid 1004636:tid 1004928] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuguO_uyupB2NyFtxKELQAAAGU"]
[Thu Jul 30 14:06:32.534758 2026] [security2:error] [pid 1004636:tid 1004928] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuguO_uyupB2NyFtxKELQAAAGU"]
[Thu Jul 30 14:06:32.837781 2026] [security2:error] [pid 1004636:tid 1004952] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dyui.php"] [unique_id "amuguO_uyupB2NyFtxKEOAAAAHw"]
[Thu Jul 30 14:06:32.837865 2026] [security2:error] [pid 1004636:tid 1004952] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/dyui.php"] [unique_id "amuguO_uyupB2NyFtxKEOAAAAHw"]
[Thu Jul 30 14:06:32.838592 2026] [security2:error] [pid 1004636:tid 1004938] [client 158.158.41.78:22995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-content/languages/index.php"] [unique_id "amuguO_uyupB2NyFtxKEOQAAAG4"]
[Thu Jul 30 14:06:32.842540 2026] [security2:error] [pid 1004636:tid 1004907] [client 20.203.148.31:58278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/ava.php"] [unique_id "amuguO_uyupB2NyFtxKEOgAAAFE"]
[Thu Jul 30 14:06:32.973660 2026] [core:notice] [pid 1004636:tid 1004793] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:33.129834 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ho.php"] [unique_id "amugue_uyupB2NyFtxKERAAAAGs"]
[Thu Jul 30 14:06:33.130008 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ho.php"] [unique_id "amugue_uyupB2NyFtxKERAAAAGs"]
[Thu Jul 30 14:06:33.394368 2026] [security2:error] [pid 1004636:tid 1004897] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/66b867516c8f01.php"] [unique_id "amugue_uyupB2NyFtxKETAAAAEc"]
[Thu Jul 30 14:06:33.394492 2026] [security2:error] [pid 1004636:tid 1004897] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/66b867516c8f01.php"] [unique_id "amugue_uyupB2NyFtxKETAAAAEc"]
[Thu Jul 30 14:06:33.467509 2026] [security2:error] [pid 1004636:tid 1004930] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env.old"] [unique_id "amugue_uyupB2NyFtxKETQAAAGc"]
[Thu Jul 30 14:06:33.665772 2026] [security2:error] [pid 1004636:tid 1004898] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ext.php"] [unique_id "amugue_uyupB2NyFtxKEVgAAAEg"]
[Thu Jul 30 14:06:33.665874 2026] [security2:error] [pid 1004636:tid 1004898] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/ext.php"] [unique_id "amugue_uyupB2NyFtxKEVgAAAEg"]
[Thu Jul 30 14:06:33.905118 2026] [security2:error] [pid 1004636:tid 1004847] [client 103.242.199.184:60232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugue_uyupB2NyFtxKEYwAAABg"]
[Thu Jul 30 14:06:33.905258 2026] [security2:error] [pid 1004636:tid 1004847] [client 103.242.199.184:60232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugue_uyupB2NyFtxKEYwAAABg"]
[Thu Jul 30 14:06:33.982314 2026] [security2:error] [pid 1004636:tid 1004886] [client 103.190.40.154:21767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugue_uyupB2NyFtxKEZQAAAD0"]
[Thu Jul 30 14:06:33.982530 2026] [security2:error] [pid 1004636:tid 1004886] [client 103.190.40.154:21767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugue_uyupB2NyFtxKEZQAAAD0"]
[Thu Jul 30 14:06:34.189774 2026] [security2:error] [pid 1004636:tid 1004895] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuguu_uyupB2NyFtxKEbgAAAEU"]
[Thu Jul 30 14:06:34.189873 2026] [security2:error] [pid 1004636:tid 1004895] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuguu_uyupB2NyFtxKEbgAAAEU"]
[Thu Jul 30 14:06:34.276106 2026] [security2:error] [pid 1004636:tid 1004850] [client 135.119.63.61:22891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/f7.php"] [unique_id "amuguu_uyupB2NyFtxKEcAAAABs"]
[Thu Jul 30 14:06:34.439835 2026] [core:notice] [pid 1004636:tid 1004812] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:34.463014 2026] [core:error] [pid 1004636:tid 1004803] [remote 104.210.140.136:44947] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:34.463033 2026] [core:error] [pid 1004636:tid 1004803] [remote 104.210.140.136:44947] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:34.554918 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.7.241.170:42078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.qsv.hfl.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuguu_uyupB2NyFtxKEegAAADM"]
[Thu Jul 30 14:06:34.772854 2026] [security2:error] [pid 1004636:tid 1004940] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuguu_uyupB2NyFtxKEgQAAAHA"]
[Thu Jul 30 14:06:34.772958 2026] [security2:error] [pid 1004636:tid 1004940] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuguu_uyupB2NyFtxKEgQAAAHA"]
[Thu Jul 30 14:06:34.949146 2026] [autoindex:error] [pid 1004636:tid 1004838] [client 34.233.129.35:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:06:35.042397 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/584062352875874akp.php"] [unique_id "amugu-_uyupB2NyFtxKEigAAAGs"]
[Thu Jul 30 14:06:35.042512 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/584062352875874akp.php"] [unique_id "amugu-_uyupB2NyFtxKEigAAAGs"]
[Thu Jul 30 14:06:35.120690 2026] [core:notice] [pid 1004636:tid 1004814] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:35.181734 2026] [security2:error] [pid 1004636:tid 1004829] [client 158.158.41.78:50449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp.php"] [unique_id "amugu-_uyupB2NyFtxKEkQAAAAc"]
[Thu Jul 30 14:06:35.512719 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/diidi.php"] [unique_id "amugu-_uyupB2NyFtxKEnQAAAH8"]
[Thu Jul 30 14:06:35.512852 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/diidi.php"] [unique_id "amugu-_uyupB2NyFtxKEnQAAAH8"]
[Thu Jul 30 14:06:35.699766 2026] [security2:error] [pid 1004636:tid 1004840] [client 20.203.148.31:36867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/main.php"] [unique_id "amugu-_uyupB2NyFtxKEpgAAABE"]
[Thu Jul 30 14:06:35.779111 2026] [core:notice] [pid 1004636:tid 1004817] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:35.802062 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greecevisaassistanceislamabad.online"] [uri "/clarebypas.php"] [unique_id "amugu-_uyupB2NyFtxKEqQAAABc"]
[Thu Jul 30 14:06:35.802146 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "greecevisaassistanceislamabad.online"] [uri "/clarebypas.php"] [unique_id "amugu-_uyupB2NyFtxKEqQAAABc"]
[Thu Jul 30 14:06:35.922938 2026] [core:notice] [pid 1004636:tid 1004690] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:36.022257 2026] [core:notice] [pid 1004636:tid 1004696] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:36.669188 2026] [security2:error] [pid 1004636:tid 1004693] [remote 57.141.0.16:36172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7158905679/feed/rss2/"] [unique_id "amugvO_uyupB2NyFtxKEwwAAPwY"]
[Thu Jul 30 14:06:36.927539 2026] [security2:error] [pid 1004636:tid 1004913] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/settings.swp"] [unique_id "amugvO_uyupB2NyFtxKEzAAAAFc"]
[Thu Jul 30 14:06:37.231829 2026] [security2:error] [pid 1004636:tid 1004873] [client 158.158.41.78:50623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-includes/blocks/about.php"] [unique_id "amugve_uyupB2NyFtxKE1QAAADE"]
[Thu Jul 30 14:06:37.306291 2026] [security2:error] [pid 1004636:tid 1004930] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env.swp"] [unique_id "amugve_uyupB2NyFtxKE2QAAAGc"]
[Thu Jul 30 14:06:37.310145 2026] [security2:error] [pid 1004636:tid 1004863] [client 20.203.148.31:61803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/wp-file.php"] [unique_id "amugve_uyupB2NyFtxKE2gAAACc"]
[Thu Jul 30 14:06:37.320359 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.91.199.21:3217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.milfordauto.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amugve_uyupB2NyFtxKE2wAAADQ"]
[Thu Jul 30 14:06:37.380454 2026] [core:notice] [pid 1004636:tid 1004701] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:38.196714 2026] [security2:error] [pid 1004636:tid 1004893] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.EnV"] [unique_id "amugvu_uyupB2NyFtxKE-wAAAEQ"]
[Thu Jul 30 14:06:38.280051 2026] [security2:error] [pid 1004636:tid 1004919] [client 20.203.148.31:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/wp-signin.php"] [unique_id "amugvu_uyupB2NyFtxKFAAAAAF0"]
[Thu Jul 30 14:06:38.295195 2026] [security2:error] [pid 1004636:tid 1004908] [client 170.106.35.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amugvu_uyupB2NyFtxKE-gAAAFI"]
[Thu Jul 30 14:06:38.534246 2026] [security2:error] [pid 1004636:tid 1004824] [client 158.158.41.78:30791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/file.php"] [unique_id "amugvu_uyupB2NyFtxKFCAAAAAI"]
[Thu Jul 30 14:06:38.826215 2026] [security2:error] [pid 1004636:tid 1004825] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.EnV^"] [unique_id "amugvu_uyupB2NyFtxKFGQAAAAM"]
[Thu Jul 30 14:06:38.848820 2026] [core:notice] [pid 1004636:tid 1004717] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:39.182115 2026] [core:notice] [pid 1004636:tid 1004718] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:39.359315 2026] [security2:error] [pid 1004636:tid 1004834] [client 216.73.216.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.embassyofbelgiumislamabad.cc"] [uri "/index.php"] [unique_id "amugvu_uyupB2NyFtxKE_wAADCI"]
[Thu Jul 30 14:06:39.453056 2026] [security2:error] [pid 1004636:tid 1004845] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/authui.htaccess"] [unique_id "amugv-_uyupB2NyFtxKFMQAAABY"]
[Thu Jul 30 14:06:39.594506 2026] [proxy:error] [pid 1004636:tid 1004835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:06:39.594587 2026] [proxy_http:error] [pid 1004636:tid 1004835] [client 193.47.62.167:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:06:39.595202 2026] [proxy:error] [pid 1004636:tid 1004835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:06:39.595248 2026] [proxy_http:error] [pid 1004636:tid 1004835] [client 193.47.62.167:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:06:39.709821 2026] [security2:error] [pid 1004636:tid 1004740] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugv-_uyupB2NyFtxKFJgAABzM"]
[Thu Jul 30 14:06:39.710014 2026] [security2:error] [pid 1004636:tid 1004829] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amugv-_uyupB2NyFtxKFJgAABzM"]
[Thu Jul 30 14:06:39.729380 2026] [security2:error] [pid 1004636:tid 1004839] [client 158.158.41.78:50541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/user/index.php"] [unique_id "amugv-_uyupB2NyFtxKFOQAAABA"]
[Thu Jul 30 14:06:39.828254 2026] [security2:error] [pid 1004636:tid 1004939] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/test2.php"] [unique_id "amugv-_uyupB2NyFtxKFPAAAAG8"]
[Thu Jul 30 14:06:39.840772 2026] [security2:error] [pid 1004636:tid 1004840] [client 189.6.88.213:57124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugv-_uyupB2NyFtxKFPgAAABE"]
[Thu Jul 30 14:06:39.840896 2026] [security2:error] [pid 1004636:tid 1004840] [client 189.6.88.213:57124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugv-_uyupB2NyFtxKFPgAAABE"]
[Thu Jul 30 14:06:40.071188 2026] [security2:error] [pid 1004636:tid 1004934] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/test2.php%2e%2e%2f%2e%2e%2f"] [unique_id "amugwO_uyupB2NyFtxKFQwAAAGs"]
[Thu Jul 30 14:06:40.298709 2026] [core:notice] [pid 1004636:tid 1004765] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:40.313859 2026] [security2:error] [pid 1004636:tid 1004916] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/test2.php.well-known"] [unique_id "amugwO_uyupB2NyFtxKFSwAAAFo"]
[Thu Jul 30 14:06:40.516342 2026] [security2:error] [pid 1004636:tid 1004951] [client 158.158.41.78:30820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amugwO_uyupB2NyFtxKFUwAAAHs"]
[Thu Jul 30 14:06:40.555270 2026] [security2:error] [pid 1004636:tid 1004918] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/test2.php//"] [unique_id "amugwO_uyupB2NyFtxKFVAAAAFw"]
[Thu Jul 30 14:06:40.596108 2026] [security2:error] [pid 1004636:tid 1004938] [client 89.124.124.95:63895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.124.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stunningtouchcleaning.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amugwO_uyupB2NyFtxKFVQAAAG4"], referer: http://stunningtouchcleaning.com/services/post-construction-cleaning/
[Thu Jul 30 14:06:40.794784 2026] [security2:error] [pid 1004636:tid 1004930] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/config.php.bak"] [unique_id "amugwO_uyupB2NyFtxKFXwAAAGc"]
[Thu Jul 30 14:06:40.894935 2026] [security2:error] [pid 1004636:tid 1004887] [client 20.203.148.31:59935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/simi.php"] [unique_id "amugwO_uyupB2NyFtxKFZgAAAD4"]
[Thu Jul 30 14:06:41.035935 2026] [security2:error] [pid 1004636:tid 1004943] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/config.php.bak%257d"] [unique_id "amugwe_uyupB2NyFtxKFagAAAHM"]
[Thu Jul 30 14:06:41.279984 2026] [security2:error] [pid 1004636:tid 1004835] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/ConFig.Php.bak"] [unique_id "amugwe_uyupB2NyFtxKFcgAAAA0"]
[Thu Jul 30 14:06:41.433280 2026] [security2:error] [pid 1004636:tid 1004904] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugwe_uyupB2NyFtxKFcQAAAE4"]
[Thu Jul 30 14:06:41.433315 2026] [security2:error] [pid 1004636:tid 1004904] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amugwe_uyupB2NyFtxKFcQAAAE4"]
[Thu Jul 30 14:06:41.520156 2026] [security2:error] [pid 1004636:tid 1004953] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/config.php.bak%0d"] [unique_id "amugwe_uyupB2NyFtxKFdgAAAH0"]
[Thu Jul 30 14:06:41.550439 2026] [security2:error] [pid 1004636:tid 1004869] [client 82.102.18.180:35474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/Site/"] [unique_id "amugwe_uyupB2NyFtxKFbwAAAC0"]
[Thu Jul 30 14:06:41.635302 2026] [security2:error] [pid 1004636:tid 1004880] [client 158.158.41.78:23434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/index/function.php"] [unique_id "amugwe_uyupB2NyFtxKFegAAADg"]
[Thu Jul 30 14:06:41.744318 2026] [core:notice] [pid 1004636:tid 1004777] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:42.800791 2026] [security2:error] [pid 1004636:tid 1004883] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/app_dev.php"] [unique_id "amugwu_uyupB2NyFtxKFnQAAADo"]
[Thu Jul 30 14:06:43.010342 2026] [security2:error] [pid 1004636:tid 1004938] [client 89.124.93.110:57327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.93.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/ELPER-Tech/user/"] [unique_id "amugw-_uyupB2NyFtxKFngAAAG4"], referer: https://ejournalugj.com/index.php/ELPER-Tech/user//
[Thu Jul 30 14:06:43.011072 2026] [security2:error] [pid 1004636:tid 1004948] [client 181.116.200.68:13652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugw-_uyupB2NyFtxKFoAAAAHg"]
[Thu Jul 30 14:06:43.011148 2026] [security2:error] [pid 1004636:tid 1004948] [client 181.116.200.68:13652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugw-_uyupB2NyFtxKFoAAAAHg"]
[Thu Jul 30 14:06:43.038887 2026] [security2:error] [pid 1004636:tid 1004930] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/app_dev.php%2520"] [unique_id "amugw-_uyupB2NyFtxKFowAAAGc"]
[Thu Jul 30 14:06:43.191462 2026] [core:notice] [pid 1004636:tid 1004774] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:43.276678 2026] [security2:error] [pid 1004636:tid 1004822] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/app_dev.php%253f"] [unique_id "amugw-_uyupB2NyFtxKFqwAAAAA"]
[Thu Jul 30 14:06:43.505658 2026] [core:notice] [pid 1004636:tid 1004942] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:43.509913 2026] [security2:error] [pid 1004636:tid 1004942] [client 89.124.93.110:57365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php/ELPER-Tech/user/"] [unique_id "amugw-_uyupB2NyFtxKFtAAAAHI"], referer: https://ejournalugj.com/index.php/ELPER-Tech/user/
[Thu Jul 30 14:06:43.518658 2026] [security2:error] [pid 1004636:tid 1004911] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/app_dev.php%2524"] [unique_id "amugw-_uyupB2NyFtxKFtQAAAFU"]
[Thu Jul 30 14:06:43.588039 2026] [security2:error] [pid 1004636:tid 1004845] [client 43.173.176.196:52540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/12/05/new-york-bonnes-adresses-de-restaurants/feed/"] [unique_id "amugw-_uyupB2NyFtxKFrwAAABY"]
[Thu Jul 30 14:06:43.869207 2026] [security2:error] [pid 1004636:tid 1004839] [client 20.203.148.31:64677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/wp-conf.php"] [unique_id "amugw-_uyupB2NyFtxKFwQAAABA"]
[Thu Jul 30 14:06:44.004815 2026] [core:notice] [pid 1004636:tid 1004908] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:44.009107 2026] [autoindex:error] [pid 1004636:tid 1004908] [client 89.124.93.110:57405] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_ab4e48f3/index.php/ELPER-Tech/user: No matching DirectoryIndex (none) found, and server-generated directory index forbidden by Options directive, referer: https://ejournalugj.com/index.php/ELPER-Tech/user
[Thu Jul 30 14:06:44.009307 2026] [security2:error] [pid 1004636:tid 1004908] [client 89.124.93.110:57405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/ELPER-Tech/user"] [unique_id "amugxO_uyupB2NyFtxKFwwAAAFI"], referer: https://ejournalugj.com/index.php/ELPER-Tech/user
[Thu Jul 30 14:06:44.230114 2026] [core:notice] [pid 1004636:tid 1004900] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:44.238025 2026] [security2:error] [pid 1004636:tid 1004900] [client 43.173.173.55:35636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/12/05/new-york-bonnes-adresses-de-restaurants/feed/"] [unique_id "amugxO_uyupB2NyFtxKFzgAAAEo"], referer: https://carnetdeshopping.com/index.php/2011/12/05/new-york-bonnes-adresses-de-restaurants/feed/
[Thu Jul 30 14:06:44.467677 2026] [security2:error] [pid 1004636:tid 1004921] [client 20.203.148.31:37219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/WZGHHra0r3.php"] [unique_id "amugxO_uyupB2NyFtxKF2AAAAF8"]
[Thu Jul 30 14:06:44.506797 2026] [core:notice] [pid 1004636:tid 1004890] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:44.562707 2026] [security2:error] [pid 1004636:tid 1004874] [client 103.242.199.184:60811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugxO_uyupB2NyFtxKF2wAAADI"]
[Thu Jul 30 14:06:44.562816 2026] [security2:error] [pid 1004636:tid 1004874] [client 103.242.199.184:60811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugxO_uyupB2NyFtxKF2wAAADI"]
[Thu Jul 30 14:06:44.640730 2026] [core:notice] [pid 1004636:tid 1004785] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:45.261739 2026] [core:notice] [pid 1004636:tid 1004862] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:45.265936 2026] [security2:error] [pid 1004636:tid 1004862] [client 89.124.93.110:57539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php"] [unique_id "amugxe_uyupB2NyFtxKF8wAAACY"], referer: https://ejournalugj.com/index.php
[Thu Jul 30 14:06:45.528786 2026] [security2:error] [pid 1004636:tid 1004904] [client 103.59.160.164:52572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "chicago-mfg.com"] [uri "/index.php"] [unique_id "amugxe_uyupB2NyFtxKF_QAAAE4"]
[Thu Jul 30 14:06:45.531455 2026] [security2:error] [pid 1004636:tid 1004885] [client 20.203.148.31:64740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/bala.php"] [unique_id "amugxe_uyupB2NyFtxKF_gAAADw"]
[Thu Jul 30 14:06:45.781528 2026] [core:notice] [pid 1004636:tid 1004946] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:45.784621 2026] [security2:error] [pid 1004636:tid 1004946] [client 89.124.93.110:57609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php"] [unique_id "amugxe_uyupB2NyFtxKGCAAAAHY"], referer: https://ejournalugj.com/index.php
[Thu Jul 30 14:06:45.811641 2026] [security2:error] [pid 1004636:tid 1004949] [client 85.208.96.206:54282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2024/07/13/em-coletiva-explosiva-bielsa-detona-organizacao-da-copa-america-questiona-ameacas-e-ironiza-eua/"] [unique_id "amugxe_uyupB2NyFtxKGCgAAAHk"]
[Thu Jul 30 14:06:45.811734 2026] [security2:error] [pid 1004636:tid 1004949] [client 85.208.96.206:54282] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2024/07/13/em-coletiva-explosiva-bielsa-detona-organizacao-da-copa-america-questiona-ameacas-e-ironiza-eua/"] [unique_id "amugxe_uyupB2NyFtxKGCgAAAHk"]
[Thu Jul 30 14:06:46.011856 2026] [security2:error] [pid 1004636:tid 1004899] [client 172.237.109.114:7026] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/securimage-wp/readme.txt"] [unique_id "amugxu_uyupB2NyFtxKGEAAAAEk"]
[Thu Jul 30 14:06:46.085661 2026] [core:notice] [pid 1004636:tid 1004801] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:46.188828 2026] [security2:error] [pid 1004636:tid 1004906] [client 20.203.148.31:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/bk.php"] [unique_id "amugxu_uyupB2NyFtxKGGAAAAFA"]
[Thu Jul 30 14:06:46.281166 2026] [core:notice] [pid 1004636:tid 1004780] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:46.282342 2026] [core:notice] [pid 1004636:tid 1004940] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:46.286468 2026] [security2:error] [pid 1004636:tid 1004940] [client 89.124.93.110:57655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php"] [unique_id "amugxu_uyupB2NyFtxKGGgAAAHA"], referer: https://ejournalugj.com/index.php
[Thu Jul 30 14:06:46.495992 2026] [security2:error] [pid 1004636:tid 1004826] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugxe_uyupB2NyFtxKGCwAABGo"]
[Thu Jul 30 14:06:46.780416 2026] [core:notice] [pid 1004636:tid 1004930] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:46.784342 2026] [security2:error] [pid 1004636:tid 1004930] [client 89.124.93.110:57709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php"] [unique_id "amugxu_uyupB2NyFtxKGKgAAAGc"], referer: https://ejournalugj.com/index.php
[Thu Jul 30 14:06:47.010486 2026] [security2:error] [pid 1004636:tid 1004864] [client 20.203.148.31:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bonafideadvisors.com"] [uri "/ahax.php"] [unique_id "amugx-_uyupB2NyFtxKGMwAAACg"]
[Thu Jul 30 14:06:47.072593 2026] [security2:error] [pid 1004636:tid 1004834] [client 103.190.40.154:21226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugx-_uyupB2NyFtxKGNAAAAAw"]
[Thu Jul 30 14:06:47.072730 2026] [security2:error] [pid 1004636:tid 1004834] [client 103.190.40.154:21226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugx-_uyupB2NyFtxKGNAAAAAw"]
[Thu Jul 30 14:06:47.533243 2026] [core:notice] [pid 1004636:tid 1004810] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:47.609775 2026] [proxy:error] [pid 1004636:tid 1004805] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:06:47.609828 2026] [proxy_http:error] [pid 1004636:tid 1004805] [remote 74.7.228.43:43598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:06:47.610456 2026] [proxy:error] [pid 1004636:tid 1004805] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:06:47.610503 2026] [proxy_http:error] [pid 1004636:tid 1004805] [remote 74.7.228.43:43598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:06:48.005619 2026] [core:notice] [pid 1004636:tid 1004900] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:48.699410 2026] [core:notice] [pid 1004636:tid 1004836] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:48.981935 2026] [core:notice] [pid 1004636:tid 1004724] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:50.427609 2026] [core:notice] [pid 1004636:tid 1004738] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:50.578416 2026] [security2:error] [pid 1004636:tid 1004940] [client 189.6.88.213:57787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugyu_uyupB2NyFtxKGwwAAAHA"]
[Thu Jul 30 14:06:50.578572 2026] [security2:error] [pid 1004636:tid 1004940] [client 189.6.88.213:57787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amugyu_uyupB2NyFtxKGwwAAAHA"]
[Thu Jul 30 14:06:51.177112 2026] [security2:error] [pid 1004636:tid 1004913] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugyu_uyupB2NyFtxKGwgAAAFc"]
[Thu Jul 30 14:06:51.570140 2026] [core:notice] [pid 1004636:tid 1004747] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:51.776429 2026] [security2:error] [pid 1004636:tid 1004834] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugy-_uyupB2NyFtxKG2QAAAAw"]
[Thu Jul 30 14:06:51.832754 2026] [security2:error] [pid 1004636:tid 1004869] [client 40.77.178.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amugy-_uyupB2NyFtxKG4QAAAC0"]
[Thu Jul 30 14:06:52.065111 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amugzO_uyupB2NyFtxKG9AAAAAU"]
[Thu Jul 30 14:06:52.065244 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amugzO_uyupB2NyFtxKG9AAAAAU"]
[Thu Jul 30 14:06:52.528215 2026] [security2:error] [pid 1004636:tid 1004932] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amugzO_uyupB2NyFtxKHAQAAAGk"]
[Thu Jul 30 14:06:52.528332 2026] [security2:error] [pid 1004636:tid 1004932] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amugzO_uyupB2NyFtxKHAQAAAGk"]
[Thu Jul 30 14:06:52.769002 2026] [security2:error] [pid 1004636:tid 1004868] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/3PJcpMFsD8B.php"] [unique_id "amugzO_uyupB2NyFtxKHCgAAACw"]
[Thu Jul 30 14:06:52.769136 2026] [security2:error] [pid 1004636:tid 1004868] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/3PJcpMFsD8B.php"] [unique_id "amugzO_uyupB2NyFtxKHCgAAACw"]
[Thu Jul 30 14:06:53.035266 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/err.php"] [unique_id "amugze_uyupB2NyFtxKHEAAAAEs"]
[Thu Jul 30 14:06:53.035372 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/err.php"] [unique_id "amugze_uyupB2NyFtxKHEAAAAEs"]
[Thu Jul 30 14:06:53.286092 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/img.php"] [unique_id "amugze_uyupB2NyFtxKHFgAAAH4"]
[Thu Jul 30 14:06:53.286204 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/img.php"] [unique_id "amugze_uyupB2NyFtxKHFgAAAH4"]
[Thu Jul 30 14:06:53.317665 2026] [fcgid:warn] [pid 1004636:tid 1004911] (70014)End of file found: [client 172.71.127.142:13506] mod_fcgid: can't get data from http client
[Thu Jul 30 14:06:53.529805 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/aa.php"] [unique_id "amugze_uyupB2NyFtxKHHgAAAEU"]
[Thu Jul 30 14:06:53.529911 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/aa.php"] [unique_id "amugze_uyupB2NyFtxKHHgAAAEU"]
[Thu Jul 30 14:06:53.561186 2026] [fcgid:warn] [pid 1004636:tid 1004878] (70014)End of file found: [client 172.71.127.142:13513] mod_fcgid: can't get data from http client
[Thu Jul 30 14:06:53.727085 2026] [security2:error] [pid 1004636:tid 1004829] [client 181.116.200.68:4719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugze_uyupB2NyFtxKHJgAAAAc"]
[Thu Jul 30 14:06:53.727812 2026] [security2:error] [pid 1004636:tid 1004829] [client 181.116.200.68:4719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amugze_uyupB2NyFtxKHJgAAAAc"]
[Thu Jul 30 14:06:53.786176 2026] [security2:error] [pid 1004636:tid 1004955] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/av.php"] [unique_id "amugze_uyupB2NyFtxKHJwAAAH8"]
[Thu Jul 30 14:06:53.786274 2026] [security2:error] [pid 1004636:tid 1004955] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/av.php"] [unique_id "amugze_uyupB2NyFtxKHJwAAAH8"]
[Thu Jul 30 14:06:53.805128 2026] [fcgid:warn] [pid 1004636:tid 1004910] (70014)End of file found: [client 172.71.127.141:13367] mod_fcgid: can't get data from http client
[Thu Jul 30 14:06:54.044355 2026] [security2:error] [pid 1004636:tid 1004941] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/xa.php"] [unique_id "amugzu_uyupB2NyFtxKHLwAAAHE"]
[Thu Jul 30 14:06:54.044463 2026] [security2:error] [pid 1004636:tid 1004941] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/xa.php"] [unique_id "amugzu_uyupB2NyFtxKHLwAAAHE"]
[Thu Jul 30 14:06:54.046809 2026] [fcgid:warn] [pid 1004636:tid 1004900] (70014)End of file found: [client 172.71.127.141:13374] mod_fcgid: can't get data from http client
[Thu Jul 30 14:06:54.289684 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/media.php"] [unique_id "amugzu_uyupB2NyFtxKHNQAAAAY"]
[Thu Jul 30 14:06:54.289787 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/media.php"] [unique_id "amugzu_uyupB2NyFtxKHNQAAAAY"]
[Thu Jul 30 14:06:54.563121 2026] [security2:error] [pid 1004636:tid 1004921] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/images.php"] [unique_id "amugzu_uyupB2NyFtxKHPgAAAF8"]
[Thu Jul 30 14:06:54.563210 2026] [security2:error] [pid 1004636:tid 1004921] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/images.php"] [unique_id "amugzu_uyupB2NyFtxKHPgAAAF8"]
[Thu Jul 30 14:06:54.584721 2026] [security2:error] [pid 1004636:tid 1004879] [client 43.161.251.162:50810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.251.161.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/services.php"] [unique_id "amugzu_uyupB2NyFtxKHPwAAADc"]
[Thu Jul 30 14:06:54.800712 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/gecko.php"] [unique_id "amugzu_uyupB2NyFtxKHSgAAAG4"]
[Thu Jul 30 14:06:54.800817 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/gecko.php"] [unique_id "amugzu_uyupB2NyFtxKHSgAAAG4"]
[Thu Jul 30 14:06:55.036768 2026] [security2:error] [pid 1004636:tid 1004836] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/82.php"] [unique_id "amugz-_uyupB2NyFtxKHVAAAAA4"]
[Thu Jul 30 14:06:55.036866 2026] [security2:error] [pid 1004636:tid 1004836] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/82.php"] [unique_id "amugz-_uyupB2NyFtxKHVAAAAA4"]
[Thu Jul 30 14:06:55.274839 2026] [security2:error] [pid 1004636:tid 1004864] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/xstelth.php"] [unique_id "amugz-_uyupB2NyFtxKHXQAAACg"]
[Thu Jul 30 14:06:55.274948 2026] [security2:error] [pid 1004636:tid 1004864] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/xstelth.php"] [unique_id "amugz-_uyupB2NyFtxKHXQAAACg"]
[Thu Jul 30 14:06:55.309339 2026] [security2:error] [pid 1004636:tid 1004905] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/_phpinfo.php"] [unique_id "amugz-_uyupB2NyFtxKHXgAAAE8"]
[Thu Jul 30 14:06:55.324140 2026] [security2:error] [pid 1004636:tid 1004954] [client 103.242.199.184:61371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugz-_uyupB2NyFtxKHXwAAAH4"]
[Thu Jul 30 14:06:55.324282 2026] [security2:error] [pid 1004636:tid 1004954] [client 103.242.199.184:61371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amugz-_uyupB2NyFtxKHXwAAAH4"]
[Thu Jul 30 14:06:55.428150 2026] [security2:error] [pid 1004636:tid 1004840] [client 74.7.230.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "designmenow.net"] [uri "/public/robots.txt"] [unique_id "amugz-_uyupB2NyFtxKHYQAAETs"]
[Thu Jul 30 14:06:55.514531 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/xp.php"] [unique_id "amugz-_uyupB2NyFtxKHZQAAADA"]
[Thu Jul 30 14:06:55.514652 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/xp.php"] [unique_id "amugz-_uyupB2NyFtxKHZQAAADA"]
[Thu Jul 30 14:06:55.549830 2026] [security2:error] [pid 1004636:tid 1004834] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/_phpinfo.php.dockerignore"] [unique_id "amugz-_uyupB2NyFtxKHZwAAAAw"]
[Thu Jul 30 14:06:55.754250 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amugz-_uyupB2NyFtxKHbAAAAAc"]
[Thu Jul 30 14:06:55.754366 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amugz-_uyupB2NyFtxKHbAAAAAc"]
[Thu Jul 30 14:06:55.790483 2026] [security2:error] [pid 1004636:tid 1004910] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/_phpinfo.php%3f"] [unique_id "amugz-_uyupB2NyFtxKHbgAAAFQ"]
[Thu Jul 30 14:06:55.834295 2026] [core:notice] [pid 1004636:tid 1004741] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:06:56.000355 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/adminner.php"] [unique_id "amugz-_uyupB2NyFtxKHeQAAAAk"]
[Thu Jul 30 14:06:56.000483 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/adminner.php"] [unique_id "amugz-_uyupB2NyFtxKHeQAAAAk"]
[Thu Jul 30 14:06:56.034435 2026] [security2:error] [pid 1004636:tid 1004909] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/_phpinfo.php%2e%2e%2f%2e%2e%2f"] [unique_id "amug0O_uyupB2NyFtxKHegAAAFM"]
[Thu Jul 30 14:06:56.161284 2026] [security2:error] [pid 1004636:tid 1004860] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amugz-_uyupB2NyFtxKHZgAAJFI"]
[Thu Jul 30 14:06:56.236732 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/a.php"] [unique_id "amug0O_uyupB2NyFtxKHfAAAAAY"]
[Thu Jul 30 14:06:56.236871 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/a.php"] [unique_id "amug0O_uyupB2NyFtxKHfAAAAAY"]
[Thu Jul 30 14:06:56.508368 2026] [security2:error] [pid 1004636:tid 1004896] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amugz-_uyupB2NyFtxKHdQAAAEY"]
[Thu Jul 30 14:06:56.775798 2026] [security2:error] [pid 1004636:tid 1004897] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/k.php"] [unique_id "amug0O_uyupB2NyFtxKHjAAAAEc"]
[Thu Jul 30 14:06:56.775939 2026] [security2:error] [pid 1004636:tid 1004897] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/k.php"] [unique_id "amug0O_uyupB2NyFtxKHjAAAAEc"]
[Thu Jul 30 14:06:56.931827 2026] [core:error] [pid 1004636:tid 1004908] [client 74.7.228.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:56.931853 2026] [core:error] [pid 1004636:tid 1004908] [client 74.7.228.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:06:56.931994 2026] [security2:error] [pid 1004636:tid 1004908] [client 74.7.228.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amug0O_uyupB2NyFtxKHtAAAAFI"]
[Thu Jul 30 14:06:56.932552 2026] [security2:error] [pid 1004636:tid 1004948] [client 74.7.228.46:47612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.heatstickhk.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amug0O_uyupB2NyFtxKHsgAAeHw"]
[Thu Jul 30 14:06:57.033887 2026] [security2:error] [pid 1004636:tid 1004900] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/222.php"] [unique_id "amug0e_uyupB2NyFtxKHtgAAAEo"]
[Thu Jul 30 14:06:57.034006 2026] [security2:error] [pid 1004636:tid 1004900] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/222.php"] [unique_id "amug0e_uyupB2NyFtxKHtgAAAEo"]
[Thu Jul 30 14:06:57.282679 2026] [security2:error] [pid 1004636:tid 1004849] [client 103.190.40.154:21143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug0e_uyupB2NyFtxKHuwAAABo"]
[Thu Jul 30 14:06:57.282814 2026] [security2:error] [pid 1004636:tid 1004849] [client 103.190.40.154:21143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug0e_uyupB2NyFtxKHuwAAABo"]
[Thu Jul 30 14:06:57.283372 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/mac.php"] [unique_id "amug0e_uyupB2NyFtxKHvAAAABQ"]
[Thu Jul 30 14:06:57.283443 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/mac.php"] [unique_id "amug0e_uyupB2NyFtxKHvAAAABQ"]
[Thu Jul 30 14:06:57.558997 2026] [security2:error] [pid 1004636:tid 1004871] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpanel/wp-content/uploads/"] [unique_id "amug0e_uyupB2NyFtxKHxQAAAC8"]
[Thu Jul 30 14:06:57.671411 2026] [security2:error] [pid 1004636:tid 1004687] [remote 95.108.213.101:64652] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/tag/logistics/"] [unique_id "amug0e_uyupB2NyFtxKHyQAAXQA"]
[Thu Jul 30 14:06:57.717931 2026] [security2:error] [pid 1004636:tid 1004842] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpanel/wp-includes/Text/"] [unique_id "amug0e_uyupB2NyFtxKHygAAABM"]
[Thu Jul 30 14:06:57.840974 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/ops.php"] [unique_id "amug0e_uyupB2NyFtxKHzgAAAAw"]
[Thu Jul 30 14:06:57.841099 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/ops.php"] [unique_id "amug0e_uyupB2NyFtxKHzgAAAAw"]
[Thu Jul 30 14:06:57.894873 2026] [security2:error] [pid 1004636:tid 1004923] [client 191.232.199.39:36284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wk/index.php"] [unique_id "amug0e_uyupB2NyFtxKH0gAAAGA"]
[Thu Jul 30 14:06:58.082911 2026] [security2:error] [pid 1004636:tid 1004943] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/8.php"] [unique_id "amug0u_uyupB2NyFtxKH1gAAAHM"]
[Thu Jul 30 14:06:58.083034 2026] [security2:error] [pid 1004636:tid 1004943] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/8.php"] [unique_id "amug0u_uyupB2NyFtxKH1gAAAHM"]
[Thu Jul 30 14:06:58.347709 2026] [security2:error] [pid 1004636:tid 1004854] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/FWAZ.php"] [unique_id "amug0u_uyupB2NyFtxKH3wAAAB4"]
[Thu Jul 30 14:06:58.347824 2026] [security2:error] [pid 1004636:tid 1004854] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/FWAZ.php"] [unique_id "amug0u_uyupB2NyFtxKH3wAAAB4"]
[Thu Jul 30 14:06:58.607343 2026] [security2:error] [pid 1004636:tid 1004888] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/biufile.php"] [unique_id "amug0u_uyupB2NyFtxKH6wAAAD8"]
[Thu Jul 30 14:06:58.607428 2026] [security2:error] [pid 1004636:tid 1004888] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/biufile.php"] [unique_id "amug0u_uyupB2NyFtxKH6wAAAD8"]
[Thu Jul 30 14:06:58.846316 2026] [security2:error] [pid 1004636:tid 1004951] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/coffexium.php"] [unique_id "amug0u_uyupB2NyFtxKH8gAAAHs"]
[Thu Jul 30 14:06:58.846432 2026] [security2:error] [pid 1004636:tid 1004951] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/coffexium.php"] [unique_id "amug0u_uyupB2NyFtxKH8gAAAHs"]
[Thu Jul 30 14:06:59.105651 2026] [security2:error] [pid 1004636:tid 1004902] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/simple.php"] [unique_id "amug0-_uyupB2NyFtxKH_QAAAEw"]
[Thu Jul 30 14:06:59.105751 2026] [security2:error] [pid 1004636:tid 1004902] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/simple.php"] [unique_id "amug0-_uyupB2NyFtxKH_QAAAEw"]
[Thu Jul 30 14:06:59.213598 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.208.111.47:57235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.inmobiliariadia.com"] [uri "/.env"] [unique_id "amug0-_uyupB2NyFtxKIAQAAABQ"]
[Thu Jul 30 14:06:59.588636 2026] [security2:error] [pid 1004636:tid 1004921] [client 191.232.199.39:4264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/av.php"] [unique_id "amug0-_uyupB2NyFtxKICwAAAF8"]
[Thu Jul 30 14:06:59.939659 2026] [security2:error] [pid 1004636:tid 1004868] [client 74.208.111.47:57254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.inmobiliariadia.com"] [uri "/.env"] [unique_id "amug0-_uyupB2NyFtxKIEAAAACw"]
[Thu Jul 30 14:06:59.968606 2026] [security2:error] [pid 1004636:tid 1004939] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/fpwch.php"] [unique_id "amug0-_uyupB2NyFtxKIEQAAAG8"]
[Thu Jul 30 14:06:59.968696 2026] [security2:error] [pid 1004636:tid 1004939] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/fpwch.php"] [unique_id "amug0-_uyupB2NyFtxKIEQAAAG8"]
[Thu Jul 30 14:06:59.995677 2026] [security2:error] [pid 1004636:tid 1004842] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/server.php"] [unique_id "amug0-_uyupB2NyFtxKIEgAAABM"]
[Thu Jul 30 14:07:00.118241 2026] [security2:error] [pid 1004636:tid 1004931] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/server.php.%252e"] [unique_id "amug1O_uyupB2NyFtxKIFwAAAGg"]
[Thu Jul 30 14:07:00.208941 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/dex.php"] [unique_id "amug1O_uyupB2NyFtxKIHAAAAB0"]
[Thu Jul 30 14:07:00.209054 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/dex.php"] [unique_id "amug1O_uyupB2NyFtxKIHAAAAB0"]
[Thu Jul 30 14:07:00.357412 2026] [security2:error] [pid 1004636:tid 1004927] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/server.php%0a"] [unique_id "amug1O_uyupB2NyFtxKIIQAAAGQ"]
[Thu Jul 30 14:07:00.447393 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.203.142.71:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amug1O_uyupB2NyFtxKIIwAAADk"]
[Thu Jul 30 14:07:00.447508 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amug1O_uyupB2NyFtxKIIwAAADk"]
[Thu Jul 30 14:07:00.447630 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amug1O_uyupB2NyFtxKIIwAAADk"]
[Thu Jul 30 14:07:00.597117 2026] [security2:error] [pid 1004636:tid 1004953] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/server.php%5e"] [unique_id "amug1O_uyupB2NyFtxKIJAAAAH0"]
[Thu Jul 30 14:07:00.733056 2026] [security2:error] [pid 1004636:tid 1004867] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/modern/"] [unique_id "amug1O_uyupB2NyFtxKIKgAAACs"]
[Thu Jul 30 14:07:00.870041 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/config.json.php"] [unique_id "amug1O_uyupB2NyFtxKIMQAAAEs"]
[Thu Jul 30 14:07:00.870142 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/config.json.php"] [unique_id "amug1O_uyupB2NyFtxKIMQAAAEs"]
[Thu Jul 30 14:07:00.871900 2026] [security2:error] [pid 1004636:tid 1004877] [client 191.232.199.39:42051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/mini.php"] [unique_id "amug1O_uyupB2NyFtxKIMgAAADU"]
[Thu Jul 30 14:07:01.127300 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/k2.php"] [unique_id "amug1e_uyupB2NyFtxKINAAAAE0"]
[Thu Jul 30 14:07:01.127396 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/k2.php"] [unique_id "amug1e_uyupB2NyFtxKINAAAAE0"]
[Thu Jul 30 14:07:01.324146 2026] [security2:error] [pid 1004636:tid 1004860] [client 189.6.88.213:58598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug1e_uyupB2NyFtxKIPAAAACQ"]
[Thu Jul 30 14:07:01.324262 2026] [security2:error] [pid 1004636:tid 1004860] [client 189.6.88.213:58598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug1e_uyupB2NyFtxKIPAAAACQ"]
[Thu Jul 30 14:07:01.401764 2026] [security2:error] [pid 1004636:tid 1004932] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/raw.php"] [unique_id "amug1e_uyupB2NyFtxKIQQAAAGk"]
[Thu Jul 30 14:07:01.401861 2026] [security2:error] [pid 1004636:tid 1004932] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/raw.php"] [unique_id "amug1e_uyupB2NyFtxKIQQAAAGk"]
[Thu Jul 30 14:07:01.656459 2026] [security2:error] [pid 1004636:tid 1004950] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/wp.php"] [unique_id "amug1e_uyupB2NyFtxKIRAAAAHo"]
[Thu Jul 30 14:07:01.656585 2026] [security2:error] [pid 1004636:tid 1004950] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/wp.php"] [unique_id "amug1e_uyupB2NyFtxKIRAAAAHo"]
[Thu Jul 30 14:07:01.913636 2026] [security2:error] [pid 1004636:tid 1004924] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/fffm.php"] [unique_id "amug1e_uyupB2NyFtxKIUQAAAGE"]
[Thu Jul 30 14:07:01.913768 2026] [security2:error] [pid 1004636:tid 1004924] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/fffm.php"] [unique_id "amug1e_uyupB2NyFtxKIUQAAAGE"]
[Thu Jul 30 14:07:01.945034 2026] [security2:error] [pid 1004636:tid 1004849] [client 170.106.35.153:45170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.35.106.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adbacklink.com"] [uri "/bbs/login.php"] [unique_id "amug1e_uyupB2NyFtxKIRgAAABo"]
[Thu Jul 30 14:07:02.174193 2026] [security2:error] [pid 1004636:tid 1004857] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/111.php"] [unique_id "amug1u_uyupB2NyFtxKIVQAAACE"]
[Thu Jul 30 14:07:02.174304 2026] [security2:error] [pid 1004636:tid 1004857] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/111.php"] [unique_id "amug1u_uyupB2NyFtxKIVQAAACE"]
[Thu Jul 30 14:07:02.451720 2026] [security2:error] [pid 1004636:tid 1004897] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/___proxy_subdomain_cpanel/wp-includes/Requests/"] [unique_id "amug1u_uyupB2NyFtxKIYgAAAEc"]
[Thu Jul 30 14:07:02.577460 2026] [security2:error] [pid 1004636:tid 1004953] [client 191.232.199.39:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/aa.php"] [unique_id "amug1u_uyupB2NyFtxKIZAAAAH0"]
[Thu Jul 30 14:07:02.580452 2026] [security2:error] [pid 1004636:tid 1004883] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/ws.php"] [unique_id "amug1u_uyupB2NyFtxKIZQAAADo"]
[Thu Jul 30 14:07:02.580627 2026] [security2:error] [pid 1004636:tid 1004883] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/ws.php"] [unique_id "amug1u_uyupB2NyFtxKIZQAAADo"]
[Thu Jul 30 14:07:02.820889 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/coffee.php"] [unique_id "amug1u_uyupB2NyFtxKIbgAAAAw"]
[Thu Jul 30 14:07:02.820997 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/coffee.php"] [unique_id "amug1u_uyupB2NyFtxKIbgAAAAw"]
[Thu Jul 30 14:07:03.085343 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/goods.php"] [unique_id "amug1-_uyupB2NyFtxKIdAAAAAE"]
[Thu Jul 30 14:07:03.085450 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/goods.php"] [unique_id "amug1-_uyupB2NyFtxKIdAAAAAE"]
[Thu Jul 30 14:07:03.111703 2026] [security2:error] [pid 1004636:tid 1004889] [client 49.13.130.29:42628] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amug1-_uyupB2NyFtxKIdQAAAEA"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:07:03.227769 2026] [security2:error] [pid 1004636:tid 1004716] [remote 198.38.94.87:55974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amug1-_uyupB2NyFtxKIdwAAcxs"]
[Thu Jul 30 14:07:03.251694 2026] [security2:error] [pid 1004636:tid 1004723] [remote 154.192.103.45:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amug1-_uyupB2NyFtxKIewAARSI"]
[Thu Jul 30 14:07:03.251826 2026] [security2:error] [pid 1004636:tid 1004895] [client 154.192.103.45:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "zweepup.com"] [uri "/xmlrpc.php"] [unique_id "amug1-_uyupB2NyFtxKIewAARSI"]
[Thu Jul 30 14:07:03.330811 2026] [security2:error] [pid 1004636:tid 1004867] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amug1-_uyupB2NyFtxKIgAAAACs"]
[Thu Jul 30 14:07:03.330916 2026] [security2:error] [pid 1004636:tid 1004867] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amug1-_uyupB2NyFtxKIgAAAACs"]
[Thu Jul 30 14:07:03.560772 2026] [proxy:error] [pid 1004636:tid 1004835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:03.560859 2026] [proxy_http:error] [pid 1004636:tid 1004835] [client 32.194.121.99:65145] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:03.561482 2026] [proxy:error] [pid 1004636:tid 1004835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:03.561530 2026] [proxy_http:error] [pid 1004636:tid 1004835] [client 32.194.121.99:65145] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:03.583322 2026] [proxy:error] [pid 1004636:tid 1004877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:03.583406 2026] [proxy_http:error] [pid 1004636:tid 1004877] [client 32.194.121.99:37398] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:03.584331 2026] [proxy:error] [pid 1004636:tid 1004877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:03.584399 2026] [proxy_http:error] [pid 1004636:tid 1004877] [client 32.194.121.99:37398] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:03.594631 2026] [security2:error] [pid 1004636:tid 1004918] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amug1-_uyupB2NyFtxKIjwAAAFw"]
[Thu Jul 30 14:07:03.594729 2026] [security2:error] [pid 1004636:tid 1004918] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amug1-_uyupB2NyFtxKIjwAAAFw"]
[Thu Jul 30 14:07:03.729141 2026] [core:notice] [pid 1004636:tid 1004891] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:03.733850 2026] [security2:error] [pid 1004636:tid 1004891] [client 49.13.130.29:42630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amug1-_uyupB2NyFtxKIlQAAAEI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:07:03.875371 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amug1-_uyupB2NyFtxKInQAAAFY"]
[Thu Jul 30 14:07:03.875483 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amug1-_uyupB2NyFtxKInQAAAFY"]
[Thu Jul 30 14:07:04.006000 2026] [security2:error] [pid 1004636:tid 1004941] [client 191.232.199.39:36264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/w.php"] [unique_id "amug2O_uyupB2NyFtxKIowAAAHE"]
[Thu Jul 30 14:07:04.129766 2026] [security2:error] [pid 1004636:tid 1004906] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amug2O_uyupB2NyFtxKIpQAAAFA"]
[Thu Jul 30 14:07:04.129869 2026] [security2:error] [pid 1004636:tid 1004906] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amug2O_uyupB2NyFtxKIpQAAAFA"]
[Thu Jul 30 14:07:04.146020 2026] [security2:error] [pid 1004636:tid 1004826] [client 49.13.130.29:42644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amug2O_uyupB2NyFtxKIpwAAAAQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:07:04.269098 2026] [security2:error] [pid 1004636:tid 1004938] [client 181.116.200.68:20862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amug2O_uyupB2NyFtxKIqwAAAG4"]
[Thu Jul 30 14:07:04.269196 2026] [security2:error] [pid 1004636:tid 1004938] [client 181.116.200.68:20862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amug2O_uyupB2NyFtxKIqwAAAG4"]
[Thu Jul 30 14:07:04.396340 2026] [security2:error] [pid 1004636:tid 1004937] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amug2O_uyupB2NyFtxKIsgAAAG0"]
[Thu Jul 30 14:07:04.396419 2026] [security2:error] [pid 1004636:tid 1004937] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amug2O_uyupB2NyFtxKIsgAAAG0"]
[Thu Jul 30 14:07:04.649303 2026] [core:error] [pid 1004636:tid 1004846] [client 5.255.231.124:46048] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:07:04.649331 2026] [core:error] [pid 1004636:tid 1004846] [client 5.255.231.124:46048] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:07:04.666885 2026] [security2:error] [pid 1004636:tid 1004913] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/adminfuns.php"] [unique_id "amug2O_uyupB2NyFtxKIvAAAAFc"]
[Thu Jul 30 14:07:04.666972 2026] [security2:error] [pid 1004636:tid 1004913] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/adminfuns.php"] [unique_id "amug2O_uyupB2NyFtxKIvAAAAFc"]
[Thu Jul 30 14:07:04.923420 2026] [security2:error] [pid 1004636:tid 1004908] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/404.php"] [unique_id "amug2O_uyupB2NyFtxKIxAAAAFI"]
[Thu Jul 30 14:07:04.923498 2026] [security2:error] [pid 1004636:tid 1004908] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/404.php"] [unique_id "amug2O_uyupB2NyFtxKIxAAAAFI"]
[Thu Jul 30 14:07:05.161991 2026] [security2:error] [pid 1004636:tid 1004855] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/xxx.php"] [unique_id "amug2e_uyupB2NyFtxKIzAAAAB8"]
[Thu Jul 30 14:07:05.162081 2026] [security2:error] [pid 1004636:tid 1004855] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/xxx.php"] [unique_id "amug2e_uyupB2NyFtxKIzAAAAB8"]
[Thu Jul 30 14:07:05.233849 2026] [core:notice] [pid 1004636:tid 1004954] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:05.347252 2026] [core:notice] [pid 1004636:tid 1004874] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:05.353135 2026] [core:notice] [pid 1004636:tid 1004891] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:05.407541 2026] [security2:error] [pid 1004636:tid 1004944] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/classwithtostring.php"] [unique_id "amug2e_uyupB2NyFtxKI2QAAAHQ"]
[Thu Jul 30 14:07:05.407989 2026] [security2:error] [pid 1004636:tid 1004944] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/classwithtostring.php"] [unique_id "amug2e_uyupB2NyFtxKI2QAAAHQ"]
[Thu Jul 30 14:07:05.550921 2026] [core:notice] [pid 1004636:tid 1004921] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:05.654776 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/234ff.php"] [unique_id "amug2e_uyupB2NyFtxKI5gAAAHw"]
[Thu Jul 30 14:07:05.654886 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/234ff.php"] [unique_id "amug2e_uyupB2NyFtxKI5gAAAHw"]
[Thu Jul 30 14:07:05.844056 2026] [core:notice] [pid 1004636:tid 1004751] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:05.849782 2026] [security2:error] [pid 1004636:tid 1004896] [client 48.44.107.134:37947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/category/pret-a-porter/page/2/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/09/structured-cardigan-massimo-dutti.jpg"] [unique_id "amug2e_uyupB2NyFtxKI5AAARj0"], referer: https://carnetdeshopping.com/index.php/category/pret-a-porter/page/2/
[Thu Jul 30 14:07:05.879356 2026] [core:notice] [pid 1004636:tid 1004758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:05.885124 2026] [security2:error] [pid 1004636:tid 1004838] [client 48.44.107.134:18509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/the-beach-people/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/08/The-beach-people-serviette-ronde-majorelle.jpg"] [unique_id "amug2e_uyupB2NyFtxKI5QAAD0Q"], referer: https://carnetdeshopping.com/index.php/tag/the-beach-people/
[Thu Jul 30 14:07:05.907613 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/133.php"] [unique_id "amug2e_uyupB2NyFtxKI6QAAADA"]
[Thu Jul 30 14:07:05.907702 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/133.php"] [unique_id "amug2e_uyupB2NyFtxKI6QAAADA"]
[Thu Jul 30 14:07:05.927682 2026] [fcgid:warn] [pid 1004636:tid 1004868] (70014)End of file found: [client 104.23.229.147:14102] mod_fcgid: can't get data from http client
[Thu Jul 30 14:07:06.021145 2026] [security2:error] [pid 1004636:tid 1004830] [client 103.242.199.184:61930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amug2u_uyupB2NyFtxKI8QAAAAg"]
[Thu Jul 30 14:07:06.021296 2026] [security2:error] [pid 1004636:tid 1004830] [client 103.242.199.184:61930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amug2u_uyupB2NyFtxKI8QAAAAg"]
[Thu Jul 30 14:07:06.026452 2026] [core:notice] [pid 1004636:tid 1004906] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:06.153782 2026] [security2:error] [pid 1004636:tid 1004955] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/wp-ws68.php"] [unique_id "amug2u_uyupB2NyFtxKI9wAAAH8"]
[Thu Jul 30 14:07:06.153888 2026] [security2:error] [pid 1004636:tid 1004955] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/wp-ws68.php"] [unique_id "amug2u_uyupB2NyFtxKI9wAAAH8"]
[Thu Jul 30 14:07:06.167507 2026] [fcgid:warn] [pid 1004636:tid 1004829] (70014)End of file found: [client 104.23.229.147:14106] mod_fcgid: can't get data from http client
[Thu Jul 30 14:07:06.250320 2026] [core:notice] [pid 1004636:tid 1004911] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:06.397127 2026] [security2:error] [pid 1004636:tid 1004889] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/mgrr.php"] [unique_id "amug2u_uyupB2NyFtxKI-gAAAEA"]
[Thu Jul 30 14:07:06.397234 2026] [security2:error] [pid 1004636:tid 1004889] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/mgrr.php"] [unique_id "amug2u_uyupB2NyFtxKI-gAAAEA"]
[Thu Jul 30 14:07:06.407686 2026] [fcgid:warn] [pid 1004636:tid 1004930] (70014)End of file found: [client 104.23.229.147:14109] mod_fcgid: can't get data from http client
[Thu Jul 30 14:07:06.473302 2026] [core:notice] [pid 1004636:tid 1004864] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:06.640352 2026] [security2:error] [pid 1004636:tid 1004900] [client 20.203.142.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.142.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/55.php"] [unique_id "amug2u_uyupB2NyFtxKJBwAAAEo"]
[Thu Jul 30 14:07:06.640433 2026] [security2:error] [pid 1004636:tid 1004900] [client 20.203.142.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.tranquilrootsisb.space"] [uri "/55.php"] [unique_id "amug2u_uyupB2NyFtxKJBwAAAEo"]
[Thu Jul 30 14:07:06.650084 2026] [fcgid:warn] [pid 1004636:tid 1004888] (70014)End of file found: [client 104.23.229.146:13059] mod_fcgid: can't get data from http client
[Thu Jul 30 14:07:06.697101 2026] [core:notice] [pid 1004636:tid 1004946] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:06.920767 2026] [core:notice] [pid 1004636:tid 1004909] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:07.144068 2026] [core:notice] [pid 1004636:tid 1004870] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:07.367457 2026] [core:notice] [pid 1004636:tid 1004851] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:07.555643 2026] [security2:error] [pid 1004636:tid 1004920] [client 191.232.199.39:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/admin.php"] [unique_id "amug2-_uyupB2NyFtxKJHwAAAF4"]
[Thu Jul 30 14:07:07.591180 2026] [core:notice] [pid 1004636:tid 1004845] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:07.817152 2026] [core:notice] [pid 1004636:tid 1004859] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:08.119453 2026] [security2:error] [pid 1004636:tid 1004834] [client 103.190.40.154:1685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug3O_uyupB2NyFtxKJMAAAAAw"]
[Thu Jul 30 14:07:08.119582 2026] [security2:error] [pid 1004636:tid 1004834] [client 103.190.40.154:1685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug3O_uyupB2NyFtxKJMAAAAAw"]
[Thu Jul 30 14:07:08.805833 2026] [security2:error] [pid 1004636:tid 1004898] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amug3O_uyupB2NyFtxKJQwAAAEg"]
[Thu Jul 30 14:07:09.239737 2026] [security2:error] [pid 1004636:tid 1004911] [client 191.232.199.39:36227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amug3e_uyupB2NyFtxKJUAAAAFU"]
[Thu Jul 30 14:07:09.609925 2026] [autoindex:error] [pid 1004636:tid 1004907] [client 32.194.121.99:18493] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:09.824840 2026] [autoindex:error] [pid 1004636:tid 1004845] [client 34.233.129.35:46276] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:10.626527 2026] [security2:error] [pid 1004636:tid 1004938] [client 191.232.199.39:42050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/m.php"] [unique_id "amug3u_uyupB2NyFtxKJbwAAAG4"]
[Thu Jul 30 14:07:11.379630 2026] [security2:error] [pid 1004636:tid 1004712] [remote 47.128.28.108:42378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-11-retro-jubilee-25th-anniversary-2/"] [unique_id "amug3-_uyupB2NyFtxKJngAAThg"]
[Thu Jul 30 14:07:11.838212 2026] [security2:error] [pid 1004636:tid 1004835] [client 74.7.230.55:33036] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aetiiph.net.smo.zzt.temporary.site"] [uri "/index.php"] [unique_id "amug3-_uyupB2NyFtxKJpAAADRE"]
[Thu Jul 30 14:07:12.125250 2026] [security2:error] [pid 1004636:tid 1004911] [client 189.6.88.213:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug4O_uyupB2NyFtxKJqQAAAFU"]
[Thu Jul 30 14:07:12.125370 2026] [security2:error] [pid 1004636:tid 1004911] [client 189.6.88.213:59150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug4O_uyupB2NyFtxKJqQAAAFU"]
[Thu Jul 30 14:07:13.025834 2026] [security2:error] [pid 1004636:tid 1004860] [client 191.232.199.39:36229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amug4O_uyupB2NyFtxKJtwAAACQ"]
[Thu Jul 30 14:07:13.076363 2026] [security2:error] [pid 1004636:tid 1004859] [client 74.7.175.187:53348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aetiiph.net"] [uri "/index.php"] [unique_id "amug4e_uyupB2NyFtxKJvwAAIxc"]
[Thu Jul 30 14:07:13.808323 2026] [core:notice] [pid 1004636:tid 1004934] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:13.809192 2026] [core:notice] [pid 1004636:tid 1004910] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:13.894727 2026] [security2:error] [pid 1004636:tid 1004728] [remote 74.7.243.224:55808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amug4e_uyupB2NyFtxKJ1QAAACc"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:07:14.743281 2026] [core:notice] [pid 1004636:tid 1004916] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:14.747674 2026] [core:notice] [pid 1004636:tid 1004851] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:14.861623 2026] [security2:error] [pid 1004636:tid 1004848] [client 181.116.200.68:46186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amug4u_uyupB2NyFtxKJ7QAAABk"]
[Thu Jul 30 14:07:14.862398 2026] [security2:error] [pid 1004636:tid 1004848] [client 181.116.200.68:46186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amug4u_uyupB2NyFtxKJ7QAAABk"]
[Thu Jul 30 14:07:14.932911 2026] [core:notice] [pid 1004636:tid 1004737] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:14.983692 2026] [core:notice] [pid 1004636:tid 1004755] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:15.615065 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amug4-_uyupB2NyFtxKKBQAAACM"]
[Thu Jul 30 14:07:15.615174 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amug4-_uyupB2NyFtxKKBQAAACM"]
[Thu Jul 30 14:07:15.658101 2026] [autoindex:error] [pid 1004636:tid 1004863] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:15.735312 2026] [core:error] [pid 1004636:tid 1004836] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:07:15.735332 2026] [core:error] [pid 1004636:tid 1004836] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:07:16.075709 2026] [security2:error] [pid 1004636:tid 1004864] [client 191.232.199.39:36258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/classwithtostring.php"] [unique_id "amug5O_uyupB2NyFtxKKFgAAACg"]
[Thu Jul 30 14:07:16.116728 2026] [security2:error] [pid 1004636:tid 1004822] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amug5O_uyupB2NyFtxKKFwAAAAA"]
[Thu Jul 30 14:07:16.116835 2026] [security2:error] [pid 1004636:tid 1004822] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amug5O_uyupB2NyFtxKKFwAAAAA"]
[Thu Jul 30 14:07:16.642683 2026] [security2:error] [pid 1004636:tid 1004835] [client 103.242.199.184:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amug5O_uyupB2NyFtxKKJAAAAA0"]
[Thu Jul 30 14:07:16.642837 2026] [security2:error] [pid 1004636:tid 1004835] [client 103.242.199.184:62411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amug5O_uyupB2NyFtxKKJAAAAA0"]
[Thu Jul 30 14:07:16.643727 2026] [security2:error] [pid 1004636:tid 1004865] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/xstelth.php"] [unique_id "amug5O_uyupB2NyFtxKKJQAAACk"]
[Thu Jul 30 14:07:16.643835 2026] [security2:error] [pid 1004636:tid 1004865] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/xstelth.php"] [unique_id "amug5O_uyupB2NyFtxKKJQAAACk"]
[Thu Jul 30 14:07:16.739907 2026] [proxy:error] [pid 1004636:tid 1004944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:16.740004 2026] [proxy_http:error] [pid 1004636:tid 1004944] [client 18.211.55.47:6191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:16.740560 2026] [proxy:error] [pid 1004636:tid 1004944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:16.740620 2026] [proxy_http:error] [pid 1004636:tid 1004944] [client 18.211.55.47:6191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:17.018908 2026] [autoindex:error] [pid 1004636:tid 1004827] [client 18.211.55.47:34073] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:17.191582 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/584062352875874akp.php"] [unique_id "amug5e_uyupB2NyFtxKKOQAAAAg"]
[Thu Jul 30 14:07:17.191692 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/584062352875874akp.php"] [unique_id "amug5e_uyupB2NyFtxKKOQAAAAg"]
[Thu Jul 30 14:07:17.407839 2026] [security2:error] [pid 1004636:tid 1004895] [client 191.232.199.39:42070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/gmo.php"] [unique_id "amug5e_uyupB2NyFtxKKPgAAAEU"]
[Thu Jul 30 14:07:17.695889 2026] [security2:error] [pid 1004636:tid 1004927] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/newfile.php"] [unique_id "amug5e_uyupB2NyFtxKKSQAAAGQ"]
[Thu Jul 30 14:07:17.696127 2026] [security2:error] [pid 1004636:tid 1004927] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/newfile.php"] [unique_id "amug5e_uyupB2NyFtxKKSQAAAGQ"]
[Thu Jul 30 14:07:18.210680 2026] [security2:error] [pid 1004636:tid 1004946] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/tBEZGQz.php"] [unique_id "amug5u_uyupB2NyFtxKKWQAAAHY"]
[Thu Jul 30 14:07:18.210829 2026] [security2:error] [pid 1004636:tid 1004946] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/tBEZGQz.php"] [unique_id "amug5u_uyupB2NyFtxKKWQAAAHY"]
[Thu Jul 30 14:07:18.311876 2026] [core:notice] [pid 1004636:tid 1004769] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:18.742117 2026] [security2:error] [pid 1004636:tid 1004855] [client 191.232.199.39:42074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/languages/index.php"] [unique_id "amug5u_uyupB2NyFtxKKbgAAAB8"]
[Thu Jul 30 14:07:18.761375 2026] [security2:error] [pid 1004636:tid 1004877] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/phpinfo"] [unique_id "amug5u_uyupB2NyFtxKKcAAAADU"]
[Thu Jul 30 14:07:18.761510 2026] [security2:error] [pid 1004636:tid 1004877] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/phpinfo"] [unique_id "amug5u_uyupB2NyFtxKKcAAAADU"]
[Thu Jul 30 14:07:19.081174 2026] [security2:error] [pid 1004636:tid 1004830] [client 103.190.40.154:21139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug5-_uyupB2NyFtxKKeAAAAAg"]
[Thu Jul 30 14:07:19.081287 2026] [security2:error] [pid 1004636:tid 1004830] [client 103.190.40.154:21139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug5-_uyupB2NyFtxKKeAAAAAg"]
[Thu Jul 30 14:07:19.283407 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/drykl.php"] [unique_id "amug5-_uyupB2NyFtxKKfQAAAAc"]
[Thu Jul 30 14:07:19.283522 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/drykl.php"] [unique_id "amug5-_uyupB2NyFtxKKfQAAAAc"]
[Thu Jul 30 14:07:19.821840 2026] [security2:error] [pid 1004636:tid 1004948] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amug5-_uyupB2NyFtxKKiQAAAHg"]
[Thu Jul 30 14:07:19.821944 2026] [security2:error] [pid 1004636:tid 1004948] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amug5-_uyupB2NyFtxKKiQAAAHg"]
[Thu Jul 30 14:07:20.337607 2026] [security2:error] [pid 1004636:tid 1004891] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ls.php"] [unique_id "amug6O_uyupB2NyFtxKKlQAAAEI"]
[Thu Jul 30 14:07:20.337750 2026] [security2:error] [pid 1004636:tid 1004891] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ls.php"] [unique_id "amug6O_uyupB2NyFtxKKlQAAAEI"]
[Thu Jul 30 14:07:20.780042 2026] [core:notice] [pid 1004636:tid 1004802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:20.813362 2026] [core:notice] [pid 1004636:tid 1004804] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:20.843591 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/dx.php"] [unique_id "amug6O_uyupB2NyFtxKKpAAAAAY"]
[Thu Jul 30 14:07:20.843739 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/dx.php"] [unique_id "amug6O_uyupB2NyFtxKKpAAAAAY"]
[Thu Jul 30 14:07:20.875611 2026] [proxy:error] [pid 1004636:tid 1004884] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:20.875670 2026] [proxy_http:error] [pid 1004636:tid 1004884] [client 87.236.176.25:43285] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:20.876532 2026] [proxy:error] [pid 1004636:tid 1004884] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:20.876594 2026] [proxy_http:error] [pid 1004636:tid 1004884] [client 87.236.176.25:43285] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:21.002281 2026] [security2:error] [pid 1004636:tid 1004844] [client 84.37.35.193:21802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amug6O_uyupB2NyFtxKKkQAAFWI"]
[Thu Jul 30 14:07:21.313331 2026] [security2:error] [pid 1004636:tid 1004852] [client 191.232.199.39:36251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-the.php"] [unique_id "amug6e_uyupB2NyFtxKKsQAAAB0"]
[Thu Jul 30 14:07:21.402862 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/mac.php"] [unique_id "amug6e_uyupB2NyFtxKKtAAAAE8"]
[Thu Jul 30 14:07:21.403003 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/mac.php"] [unique_id "amug6e_uyupB2NyFtxKKtAAAAE8"]
[Thu Jul 30 14:07:21.461690 2026] [core:notice] [pid 1004636:tid 1004808] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:21.467658 2026] [security2:error] [pid 1004636:tid 1004876] [client 147.185.115.145:36290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/category/pret-a-porter/page/2/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/10/cape-courte-zara.jpg"] [unique_id "amug6e_uyupB2NyFtxKKqgAANHQ"], referer: https://carnetdeshopping.com/index.php/category/pret-a-porter/page/2/
[Thu Jul 30 14:07:21.930900 2026] [security2:error] [pid 1004636:tid 1004898] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/485.php"] [unique_id "amug6e_uyupB2NyFtxKKwgAAAEg"]
[Thu Jul 30 14:07:21.931012 2026] [security2:error] [pid 1004636:tid 1004898] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/485.php"] [unique_id "amug6e_uyupB2NyFtxKKwgAAAEg"]
[Thu Jul 30 14:07:22.411457 2026] [security2:error] [pid 1004636:tid 1004689] [remote 45.252.248.45:55106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.248.252.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amug6u_uyupB2NyFtxKKzgAAYQI"]
[Thu Jul 30 14:07:22.457971 2026] [security2:error] [pid 1004636:tid 1004887] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gelio1.php"] [unique_id "amug6u_uyupB2NyFtxKKzwAAAD4"]
[Thu Jul 30 14:07:22.458131 2026] [security2:error] [pid 1004636:tid 1004887] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gelio1.php"] [unique_id "amug6u_uyupB2NyFtxKKzwAAAD4"]
[Thu Jul 30 14:07:22.755048 2026] [security2:error] [pid 1004636:tid 1004846] [client 191.232.199.39:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/404.php"] [unique_id "amug6u_uyupB2NyFtxKK2AAAABc"]
[Thu Jul 30 14:07:22.780161 2026] [security2:error] [pid 1004636:tid 1004875] [client 189.6.88.213:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug6u_uyupB2NyFtxKK2gAAADM"]
[Thu Jul 30 14:07:22.780530 2026] [security2:error] [pid 1004636:tid 1004875] [client 189.6.88.213:59706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug6u_uyupB2NyFtxKK2gAAADM"]
[Thu Jul 30 14:07:22.965728 2026] [security2:error] [pid 1004636:tid 1004932] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/lp6.php"] [unique_id "amug6u_uyupB2NyFtxKK3gAAAGk"]
[Thu Jul 30 14:07:22.965835 2026] [security2:error] [pid 1004636:tid 1004932] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/lp6.php"] [unique_id "amug6u_uyupB2NyFtxKK3gAAAGk"]
[Thu Jul 30 14:07:23.491495 2026] [security2:error] [pid 1004636:tid 1004896] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug6-_uyupB2NyFtxKK5QAAAEY"]
[Thu Jul 30 14:07:23.491526 2026] [security2:error] [pid 1004636:tid 1004896] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug6-_uyupB2NyFtxKK5QAAAEY"]
[Thu Jul 30 14:07:23.491802 2026] [security2:error] [pid 1004636:tid 1004848] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/system/"] [unique_id "amug6-_uyupB2NyFtxKK4gAAABk"]
[Thu Jul 30 14:07:24.175912 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/maint/admin.php"] [unique_id "amug7O_uyupB2NyFtxKK-QAAADk"]
[Thu Jul 30 14:07:24.176076 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/maint/admin.php"] [unique_id "amug7O_uyupB2NyFtxKK-QAAADk"]
[Thu Jul 30 14:07:24.190963 2026] [security2:error] [pid 1004636:tid 1004937] [client 191.232.199.39:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/init.php"] [unique_id "amug7O_uyupB2NyFtxKK-gAAAG0"]
[Thu Jul 30 14:07:24.713471 2026] [security2:error] [pid 1004636:tid 1004874] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-includes/sodium_compat/"] [unique_id "amug7O_uyupB2NyFtxKLBQAAADI"]
[Thu Jul 30 14:07:24.713578 2026] [security2:error] [pid 1004636:tid 1004874] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-includes/sodium_compat/"] [unique_id "amug7O_uyupB2NyFtxKLBQAAADI"]
[Thu Jul 30 14:07:25.110661 2026] [security2:error] [pid 1004636:tid 1004828] [client 74.7.230.24:50512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "shorewooddaycare.com"] [uri "/robots.txt"] [unique_id "amug7e_uyupB2NyFtxKLEwAAAAY"]
[Thu Jul 30 14:07:25.214751 2026] [security2:error] [pid 1004636:tid 1004884] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/w3llscc.php"] [unique_id "amug7e_uyupB2NyFtxKLFAAAADs"]
[Thu Jul 30 14:07:25.214863 2026] [security2:error] [pid 1004636:tid 1004884] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/w3llscc.php"] [unique_id "amug7e_uyupB2NyFtxKLFAAAADs"]
[Thu Jul 30 14:07:25.424423 2026] [security2:error] [pid 1004636:tid 1004823] [client 181.116.200.68:40915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amug7e_uyupB2NyFtxKLHgAAAAE"]
[Thu Jul 30 14:07:25.424512 2026] [security2:error] [pid 1004636:tid 1004823] [client 181.116.200.68:40915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amug7e_uyupB2NyFtxKLHgAAAAE"]
[Thu Jul 30 14:07:25.483447 2026] [security2:error] [pid 1004636:tid 1004945] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug7e_uyupB2NyFtxKLGgAAAHU"]
[Thu Jul 30 14:07:25.483480 2026] [security2:error] [pid 1004636:tid 1004945] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug7e_uyupB2NyFtxKLGgAAAHU"]
[Thu Jul 30 14:07:25.483860 2026] [security2:error] [pid 1004636:tid 1004844] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/template/"] [unique_id "amug7e_uyupB2NyFtxKLFwAAABU"]
[Thu Jul 30 14:07:25.704522 2026] [security2:error] [pid 1004636:tid 1004863] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/miru3.php"] [unique_id "amug7e_uyupB2NyFtxKLIgAAACc"]
[Thu Jul 30 14:07:25.704680 2026] [security2:error] [pid 1004636:tid 1004863] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/miru3.php"] [unique_id "amug7e_uyupB2NyFtxKLIgAAACc"]
[Thu Jul 30 14:07:25.745069 2026] [security2:error] [pid 1004636:tid 1004892] [client 74.7.230.24:55650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shorewooddaycare.com"] [uri "/robots.txt"] [unique_id "amug7e_uyupB2NyFtxKLJgAAQw0"], referer: http://shorewooddaycare.com/robots.txt
[Thu Jul 30 14:07:25.992932 2026] [security2:error] [pid 1004636:tid 1004948] [client 172.237.109.114:27822] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/slideshow-jquery-image-gallery/readme.txt"] [unique_id "amug7e_uyupB2NyFtxKLNAAAAHg"]
[Thu Jul 30 14:07:26.137334 2026] [security2:error] [pid 1004636:tid 1004827] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug7e_uyupB2NyFtxKLMQAAAAU"]
[Thu Jul 30 14:07:26.137365 2026] [security2:error] [pid 1004636:tid 1004827] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug7e_uyupB2NyFtxKLMQAAAAU"]
[Thu Jul 30 14:07:26.137783 2026] [security2:error] [pid 1004636:tid 1004866] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/shop/"] [unique_id "amug7e_uyupB2NyFtxKLLwAAACo"]
[Thu Jul 30 14:07:26.225211 2026] [security2:error] [pid 1004636:tid 1004924] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/autoload_classmap.php"] [unique_id "amug7u_uyupB2NyFtxKLOAAAAGE"]
[Thu Jul 30 14:07:26.225360 2026] [security2:error] [pid 1004636:tid 1004924] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/autoload_classmap.php"] [unique_id "amug7u_uyupB2NyFtxKLOAAAAGE"]
[Thu Jul 30 14:07:26.744559 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-content/"] [unique_id "amug7u_uyupB2NyFtxKLSAAAAFM"]
[Thu Jul 30 14:07:26.744685 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-content/"] [unique_id "amug7u_uyupB2NyFtxKLSAAAAFM"]
[Thu Jul 30 14:07:26.809307 2026] [security2:error] [pid 1004636:tid 1004941] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug7u_uyupB2NyFtxKLRwAAAHE"]
[Thu Jul 30 14:07:26.809334 2026] [security2:error] [pid 1004636:tid 1004941] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug7u_uyupB2NyFtxKLRwAAAHE"]
[Thu Jul 30 14:07:26.809779 2026] [security2:error] [pid 1004636:tid 1004839] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/files/"] [unique_id "amug7u_uyupB2NyFtxKLRQAAABA"]
[Thu Jul 30 14:07:27.216818 2026] [core:notice] [pid 1004636:tid 1004854] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:27.251218 2026] [security2:error] [pid 1004636:tid 1004852] [client 103.242.199.184:62622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.199.242.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amug7-_uyupB2NyFtxKLWAAAAB0"]
[Thu Jul 30 14:07:27.251331 2026] [security2:error] [pid 1004636:tid 1004852] [client 103.242.199.184:62622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amug7-_uyupB2NyFtxKLWAAAAB0"]
[Thu Jul 30 14:07:27.260249 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-content/themes/index.php"] [unique_id "amug7-_uyupB2NyFtxKLWQAAAAg"]
[Thu Jul 30 14:07:27.260335 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-content/themes/index.php"] [unique_id "amug7-_uyupB2NyFtxKLWQAAAAg"]
[Thu Jul 30 14:07:27.572796 2026] [security2:error] [pid 1004636:tid 1004890] [client 191.232.199.39:36279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/file5.php"] [unique_id "amug7-_uyupB2NyFtxKLZgAAAEE"]
[Thu Jul 30 14:07:27.784503 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/av.php"] [unique_id "amug7-_uyupB2NyFtxKLagAAACQ"]
[Thu Jul 30 14:07:27.784618 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/av.php"] [unique_id "amug7-_uyupB2NyFtxKLagAAACQ"]
[Thu Jul 30 14:07:27.952012 2026] [security2:error] [pid 1004636:tid 1004942] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug7-_uyupB2NyFtxKLaQAAAHI"]
[Thu Jul 30 14:07:27.952043 2026] [security2:error] [pid 1004636:tid 1004942] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug7-_uyupB2NyFtxKLaQAAAHI"]
[Thu Jul 30 14:07:27.952288 2026] [security2:error] [pid 1004636:tid 1004933] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/admin/editor/"] [unique_id "amug7-_uyupB2NyFtxKLZwAAAGo"]
[Thu Jul 30 14:07:28.144759 2026] [security2:error] [pid 1004636:tid 1004916] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amug7-_uyupB2NyFtxKLYgAAAFo"]
[Thu Jul 30 14:07:28.290302 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-includes/l10n/"] [unique_id "amug8O_uyupB2NyFtxKLewAAAHw"]
[Thu Jul 30 14:07:28.290415 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-includes/l10n/"] [unique_id "amug8O_uyupB2NyFtxKLewAAAHw"]
[Thu Jul 30 14:07:28.791873 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amug8O_uyupB2NyFtxKLkwAAAAY"]
[Thu Jul 30 14:07:28.792034 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amug8O_uyupB2NyFtxKLkwAAAAY"]
[Thu Jul 30 14:07:28.893303 2026] [security2:error] [pid 1004636:tid 1004901] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug8O_uyupB2NyFtxKLkgAAAEs"]
[Thu Jul 30 14:07:28.893333 2026] [security2:error] [pid 1004636:tid 1004901] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug8O_uyupB2NyFtxKLkgAAAEs"]
[Thu Jul 30 14:07:28.894002 2026] [security2:error] [pid 1004636:tid 1004950] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/include/"] [unique_id "amug8O_uyupB2NyFtxKLkAAAAHo"]
[Thu Jul 30 14:07:29.261423 2026] [security2:error] [pid 1004636:tid 1004877] [client 191.232.199.39:36262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amug8e_uyupB2NyFtxKLoQAAADU"]
[Thu Jul 30 14:07:29.310507 2026] [security2:error] [pid 1004636:tid 1004835] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/tiny.php"] [unique_id "amug8e_uyupB2NyFtxKLogAAAA0"]
[Thu Jul 30 14:07:29.310657 2026] [security2:error] [pid 1004636:tid 1004835] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/tiny.php"] [unique_id "amug8e_uyupB2NyFtxKLogAAAA0"]
[Thu Jul 30 14:07:29.399404 2026] [core:notice] [pid 1004636:tid 1004919] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:29.769080 2026] [security2:error] [pid 1004636:tid 1004871] [client 103.190.40.154:21435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug8e_uyupB2NyFtxKLsAAAAC8"]
[Thu Jul 30 14:07:29.769247 2026] [security2:error] [pid 1004636:tid 1004871] [client 103.190.40.154:21435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug8e_uyupB2NyFtxKLsAAAAC8"]
[Thu Jul 30 14:07:29.777094 2026] [core:notice] [pid 1004636:tid 1004748] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:29.815192 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amug8e_uyupB2NyFtxKLsgAAADk"]
[Thu Jul 30 14:07:29.815301 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amug8e_uyupB2NyFtxKLsgAAADk"]
[Thu Jul 30 14:07:29.821400 2026] [security2:error] [pid 1004636:tid 1004859] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug8e_uyupB2NyFtxKLrwAAACM"]
[Thu Jul 30 14:07:29.821420 2026] [security2:error] [pid 1004636:tid 1004859] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug8e_uyupB2NyFtxKLrwAAACM"]
[Thu Jul 30 14:07:29.821797 2026] [security2:error] [pid 1004636:tid 1004943] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/Assets/"] [unique_id "amug8e_uyupB2NyFtxKLrQAAAHM"]
[Thu Jul 30 14:07:30.290299 2026] [core:notice] [pid 1004636:tid 1004758] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:30.338869 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/zrrhj.php"] [unique_id "amug8u_uyupB2NyFtxKLwAAAAD0"]
[Thu Jul 30 14:07:30.339004 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/zrrhj.php"] [unique_id "amug8u_uyupB2NyFtxKLwAAAAD0"]
[Thu Jul 30 14:07:30.508791 2026] [security2:error] [pid 1004636:tid 1004829] [client 191.232.199.39:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/shell.php"] [unique_id "amug8u_uyupB2NyFtxKLxAAAAAc"]
[Thu Jul 30 14:07:30.825028 2026] [security2:error] [pid 1004636:tid 1004841] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amug8u_uyupB2NyFtxKL_AAAABI"]
[Thu Jul 30 14:07:30.825152 2026] [security2:error] [pid 1004636:tid 1004841] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amug8u_uyupB2NyFtxKL_AAAABI"]
[Thu Jul 30 14:07:30.928150 2026] [security2:error] [pid 1004636:tid 1004855] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug8u_uyupB2NyFtxKL-wAAAB8"]
[Thu Jul 30 14:07:30.928179 2026] [security2:error] [pid 1004636:tid 1004855] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug8u_uyupB2NyFtxKL-wAAAB8"]
[Thu Jul 30 14:07:30.928452 2026] [security2:error] [pid 1004636:tid 1004899] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/images/stories/"] [unique_id "amug8u_uyupB2NyFtxKL-QAAAEk"]
[Thu Jul 30 14:07:31.317253 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wpgum.php"] [unique_id "amug8-_uyupB2NyFtxKMBwAAADQ"]
[Thu Jul 30 14:07:31.317348 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wpgum.php"] [unique_id "amug8-_uyupB2NyFtxKMBwAAADQ"]
[Thu Jul 30 14:07:31.837014 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ywwbf.php"] [unique_id "amug8-_uyupB2NyFtxKMHwAAACQ"]
[Thu Jul 30 14:07:31.837123 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ywwbf.php"] [unique_id "amug8-_uyupB2NyFtxKMHwAAACQ"]
[Thu Jul 30 14:07:31.990093 2026] [security2:error] [pid 1004636:tid 1004859] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug8-_uyupB2NyFtxKMHQAAACM"]
[Thu Jul 30 14:07:31.990128 2026] [security2:error] [pid 1004636:tid 1004859] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug8-_uyupB2NyFtxKMHQAAACM"]
[Thu Jul 30 14:07:31.990599 2026] [security2:error] [pid 1004636:tid 1004869] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/plugins/"] [unique_id "amug8-_uyupB2NyFtxKMGwAAAC0"]
[Thu Jul 30 14:07:32.013772 2026] [security2:error] [pid 1004636:tid 1004914] [client 191.232.199.39:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/f35.php"] [unique_id "amug9O_uyupB2NyFtxKMKgAAAFg"]
[Thu Jul 30 14:07:32.317803 2026] [security2:error] [pid 1004636:tid 1004701] [remote 57.141.0.46:21966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amug9O_uyupB2NyFtxKMNgAAPA0"]
[Thu Jul 30 14:07:32.412243 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/xoldj.php"] [unique_id "amug9O_uyupB2NyFtxKMNwAAAE4"]
[Thu Jul 30 14:07:32.412362 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/xoldj.php"] [unique_id "amug9O_uyupB2NyFtxKMNwAAAE4"]
[Thu Jul 30 14:07:32.593436 2026] [security2:error] [pid 1004636:tid 1004857] [client 50.6.43.217:60650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amug8-_uyupB2NyFtxKMHgAAACE"]
[Thu Jul 30 14:07:32.949683 2026] [security2:error] [pid 1004636:tid 1004908] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/f35.php"] [unique_id "amug9O_uyupB2NyFtxKMTQAAAFI"]
[Thu Jul 30 14:07:32.949837 2026] [security2:error] [pid 1004636:tid 1004908] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/f35.php"] [unique_id "amug9O_uyupB2NyFtxKMTQAAAFI"]
[Thu Jul 30 14:07:33.293772 2026] [security2:error] [pid 1004636:tid 1004868] [client 191.232.199.39:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/new.php"] [unique_id "amug9e_uyupB2NyFtxKMWwAAACw"]
[Thu Jul 30 14:07:33.344959 2026] [security2:error] [pid 1004636:tid 1004897] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug9e_uyupB2NyFtxKMUwAAAEc"]
[Thu Jul 30 14:07:33.345014 2026] [security2:error] [pid 1004636:tid 1004897] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug9e_uyupB2NyFtxKMUwAAAEc"]
[Thu Jul 30 14:07:33.345383 2026] [security2:error] [pid 1004636:tid 1004925] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/php/"] [unique_id "amug9e_uyupB2NyFtxKMUQAAAGI"]
[Thu Jul 30 14:07:33.399913 2026] [security2:error] [pid 1004636:tid 1004883] [client 50.6.43.217:60664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amug9O_uyupB2NyFtxKMOAAAADo"]
[Thu Jul 30 14:07:33.460786 2026] [security2:error] [pid 1004636:tid 1004955] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gk.php"] [unique_id "amug9e_uyupB2NyFtxKMXAAAAH8"]
[Thu Jul 30 14:07:33.460943 2026] [security2:error] [pid 1004636:tid 1004955] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gk.php"] [unique_id "amug9e_uyupB2NyFtxKMXAAAAH8"]
[Thu Jul 30 14:07:33.499348 2026] [security2:error] [pid 1004636:tid 1004838] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amug9O_uyupB2NyFtxKMSgAADyY"]
[Thu Jul 30 14:07:33.527407 2026] [security2:error] [pid 1004636:tid 1004923] [client 189.6.88.213:60250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug9e_uyupB2NyFtxKMXgAAAGA"]
[Thu Jul 30 14:07:33.527605 2026] [security2:error] [pid 1004636:tid 1004923] [client 189.6.88.213:60250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug9e_uyupB2NyFtxKMXgAAAGA"]
[Thu Jul 30 14:07:33.730606 2026] [security2:error] [pid 1004636:tid 1004725] [remote 57.141.0.53:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amug9e_uyupB2NyFtxKMXQAADCQ"]
[Thu Jul 30 14:07:33.949793 2026] [security2:error] [pid 1004636:tid 1004822] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/584062352875874akp.php"] [unique_id "amug9e_uyupB2NyFtxKMgwAAAAA"]
[Thu Jul 30 14:07:33.949876 2026] [security2:error] [pid 1004636:tid 1004822] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/584062352875874akp.php"] [unique_id "amug9e_uyupB2NyFtxKMgwAAAAA"]
[Thu Jul 30 14:07:33.992788 2026] [security2:error] [pid 1004636:tid 1004829] [client 172.237.109.114:56364] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amug9e_uyupB2NyFtxKMhAAAAAc"]
[Thu Jul 30 14:07:34.429277 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wper3.php"] [unique_id "amug9u_uyupB2NyFtxKMmAAAABQ"]
[Thu Jul 30 14:07:34.429383 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wper3.php"] [unique_id "amug9u_uyupB2NyFtxKMmAAAABQ"]
[Thu Jul 30 14:07:34.629229 2026] [security2:error] [pid 1004636:tid 1004902] [client 191.232.199.39:4311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/adminfuns.php"] [unique_id "amug9u_uyupB2NyFtxKMmgAAAEw"]
[Thu Jul 30 14:07:34.668495 2026] [autoindex:error] [pid 1004636:tid 1004921] [client 82.102.18.180:43150] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:34.669166 2026] [security2:error] [pid 1004636:tid 1004921] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amug9u_uyupB2NyFtxKMmQAAAF8"]
[Thu Jul 30 14:07:34.923116 2026] [security2:error] [pid 1004636:tid 1004844] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/bthil.php"] [unique_id "amug9u_uyupB2NyFtxKMpgAAABU"]
[Thu Jul 30 14:07:34.923236 2026] [security2:error] [pid 1004636:tid 1004844] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/bthil.php"] [unique_id "amug9u_uyupB2NyFtxKMpgAAABU"]
[Thu Jul 30 14:07:35.429869 2026] [security2:error] [pid 1004636:tid 1004942] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wyzer1.php"] [unique_id "amug9-_uyupB2NyFtxKMtgAAAHI"]
[Thu Jul 30 14:07:35.429973 2026] [security2:error] [pid 1004636:tid 1004942] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wyzer1.php"] [unique_id "amug9-_uyupB2NyFtxKMtgAAAHI"]
[Thu Jul 30 14:07:35.465262 2026] [security2:error] [pid 1004636:tid 1004863] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug9-_uyupB2NyFtxKMrQAAACc"]
[Thu Jul 30 14:07:35.465290 2026] [security2:error] [pid 1004636:tid 1004863] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug9-_uyupB2NyFtxKMrQAAACc"]
[Thu Jul 30 14:07:35.465612 2026] [security2:error] [pid 1004636:tid 1004938] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "amug9-_uyupB2NyFtxKMqwAAAG4"]
[Thu Jul 30 14:07:35.939868 2026] [security2:error] [pid 1004636:tid 1004913] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/mh.php"] [unique_id "amug9-_uyupB2NyFtxKMwgAAAFc"]
[Thu Jul 30 14:07:35.939990 2026] [security2:error] [pid 1004636:tid 1004913] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/mh.php"] [unique_id "amug9-_uyupB2NyFtxKMwgAAAFc"]
[Thu Jul 30 14:07:35.972823 2026] [security2:error] [pid 1004636:tid 1004923] [client 181.116.200.68:41309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amug9-_uyupB2NyFtxKMxgAAAGA"]
[Thu Jul 30 14:07:35.972933 2026] [security2:error] [pid 1004636:tid 1004923] [client 181.116.200.68:41309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amug9-_uyupB2NyFtxKMxgAAAGA"]
[Thu Jul 30 14:07:36.047780 2026] [security2:error] [pid 1004636:tid 1004859] [client 185.200.116.211:60604] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amug9-_uyupB2NyFtxKMvQAAACM"]
[Thu Jul 30 14:07:36.047944 2026] [security2:error] [pid 1004636:tid 1004859] [client 185.200.116.211:60604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amug9-_uyupB2NyFtxKMvQAAACM"]
[Thu Jul 30 14:07:36.468299 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amug-O_uyupB2NyFtxKMzwAAAFU"]
[Thu Jul 30 14:07:36.468388 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amug-O_uyupB2NyFtxKMzwAAAFU"]
[Thu Jul 30 14:07:36.759289 2026] [security2:error] [pid 1004636:tid 1004951] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug-O_uyupB2NyFtxKM1QAAAHs"]
[Thu Jul 30 14:07:36.759321 2026] [security2:error] [pid 1004636:tid 1004951] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amug-O_uyupB2NyFtxKM1QAAAHs"]
[Thu Jul 30 14:07:36.759585 2026] [security2:error] [pid 1004636:tid 1004879] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-content/cache/"] [unique_id "amug-O_uyupB2NyFtxKM0wAAADc"]
[Thu Jul 30 14:07:36.966223 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/1.php"] [unique_id "amug-O_uyupB2NyFtxKM4QAAAF4"]
[Thu Jul 30 14:07:36.966321 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/1.php"] [unique_id "amug-O_uyupB2NyFtxKM4QAAAF4"]
[Thu Jul 30 14:07:36.966414 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/1.php"] [unique_id "amug-O_uyupB2NyFtxKM4QAAAF4"]
[Thu Jul 30 14:07:37.115931 2026] [autoindex:error] [pid 1004636:tid 1004835] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:37.468377 2026] [security2:error] [pid 1004636:tid 1004930] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/chosen.php"] [unique_id "amug-e_uyupB2NyFtxKM7AAAAGc"]
[Thu Jul 30 14:07:37.468474 2026] [security2:error] [pid 1004636:tid 1004930] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/chosen.php"] [unique_id "amug-e_uyupB2NyFtxKM7AAAAGc"]
[Thu Jul 30 14:07:37.500143 2026] [security2:error] [pid 1004636:tid 1004868] [client 191.232.199.39:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/fm.php"] [unique_id "amug-e_uyupB2NyFtxKM7QAAACw"]
[Thu Jul 30 14:07:37.993674 2026] [security2:error] [pid 1004636:tid 1004929] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/sd.php"] [unique_id "amug-e_uyupB2NyFtxKM9wAAAGY"]
[Thu Jul 30 14:07:37.993825 2026] [security2:error] [pid 1004636:tid 1004929] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/sd.php"] [unique_id "amug-e_uyupB2NyFtxKM9wAAAGY"]
[Thu Jul 30 14:07:38.116912 2026] [autoindex:error] [pid 1004636:tid 1004948] [client 82.102.18.180:43150] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:38.117664 2026] [security2:error] [pid 1004636:tid 1004948] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amug-u_uyupB2NyFtxKM-wAAAHg"]
[Thu Jul 30 14:07:38.555258 2026] [security2:error] [pid 1004636:tid 1004946] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/z60.php"] [unique_id "amug-u_uyupB2NyFtxKNBQAAAHY"]
[Thu Jul 30 14:07:38.555351 2026] [security2:error] [pid 1004636:tid 1004946] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/z60.php"] [unique_id "amug-u_uyupB2NyFtxKNBQAAAHY"]
[Thu Jul 30 14:07:38.608700 2026] [core:notice] [pid 1004636:tid 1004802] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:38.736256 2026] [authz_core:error] [pid 1004636:tid 1004900] [client 82.102.18.180:0] AH01630: client denied by server configuration: /home2/xsygzjte/public_html/wp-content/plugins/akismet/
[Thu Jul 30 14:07:38.737007 2026] [security2:error] [pid 1004636:tid 1004900] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amug-u_uyupB2NyFtxKNDwAAAEo"]
[Thu Jul 30 14:07:38.737316 2026] [security2:error] [pid 1004636:tid 1004839] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/akismet/"] [unique_id "amug-u_uyupB2NyFtxKNDQAAABA"]
[Thu Jul 30 14:07:39.067926 2026] [security2:error] [pid 1004636:tid 1004950] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/home.php"] [unique_id "amug--_uyupB2NyFtxKNGQAAAHo"]
[Thu Jul 30 14:07:39.068071 2026] [security2:error] [pid 1004636:tid 1004950] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/home.php"] [unique_id "amug--_uyupB2NyFtxKNGQAAAHo"]
[Thu Jul 30 14:07:39.356802 2026] [security2:error] [pid 1004636:tid 1004951] [client 191.232.199.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amug--_uyupB2NyFtxKNFQAAAHs"]
[Thu Jul 30 14:07:39.518136 2026] [core:notice] [pid 1004636:tid 1004884] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:39.567197 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ws58.php"] [unique_id "amug--_uyupB2NyFtxKNIQAAAE8"]
[Thu Jul 30 14:07:39.567275 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ws58.php"] [unique_id "amug--_uyupB2NyFtxKNIQAAAE8"]
[Thu Jul 30 14:07:39.881541 2026] [autoindex:error] [pid 1004636:tid 1004890] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:39.882176 2026] [security2:error] [pid 1004636:tid 1004890] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amug--_uyupB2NyFtxKNKwAAAEE"]
[Thu Jul 30 14:07:39.882702 2026] [security2:error] [pid 1004636:tid 1004892] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/assets/"] [unique_id "amug--_uyupB2NyFtxKNKQAAAEM"]
[Thu Jul 30 14:07:40.062879 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gulu.php"] [unique_id "amug_O_uyupB2NyFtxKNLQAAAEU"]
[Thu Jul 30 14:07:40.063002 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/gulu.php"] [unique_id "amug_O_uyupB2NyFtxKNLQAAAEU"]
[Thu Jul 30 14:07:40.151626 2026] [autoindex:error] [pid 1004636:tid 1004893] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:40.152268 2026] [security2:error] [pid 1004636:tid 1004893] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amug_O_uyupB2NyFtxKNNgAAAEQ"]
[Thu Jul 30 14:07:40.152659 2026] [security2:error] [pid 1004636:tid 1004849] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/block-patterns/"] [unique_id "amug_O_uyupB2NyFtxKNNAAAABo"]
[Thu Jul 30 14:07:40.374796 2026] [security2:error] [pid 1004636:tid 1004916] [client 191.232.199.39:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/file.php"] [unique_id "amug_O_uyupB2NyFtxKNOwAAAFo"]
[Thu Jul 30 14:07:40.561942 2026] [security2:error] [pid 1004636:tid 1004836] [client 103.190.40.154:21666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug_O_uyupB2NyFtxKNPwAAAA4"]
[Thu Jul 30 14:07:40.562103 2026] [security2:error] [pid 1004636:tid 1004836] [client 103.190.40.154:21666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amug_O_uyupB2NyFtxKNPwAAAA4"]
[Thu Jul 30 14:07:40.602652 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amug_O_uyupB2NyFtxKNQwAAAAs"]
[Thu Jul 30 14:07:40.602738 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amug_O_uyupB2NyFtxKNQwAAAAs"]
[Thu Jul 30 14:07:40.804605 2026] [core:notice] [pid 1004636:tid 1004827] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:41.121439 2026] [security2:error] [pid 1004636:tid 1004851] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wpls.php"] [unique_id "amug_e_uyupB2NyFtxKNTgAAABw"]
[Thu Jul 30 14:07:41.121528 2026] [security2:error] [pid 1004636:tid 1004851] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wpls.php"] [unique_id "amug_e_uyupB2NyFtxKNTgAAABw"]
[Thu Jul 30 14:07:41.601804 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/php.php"] [unique_id "amug_e_uyupB2NyFtxKNVwAAABQ"]
[Thu Jul 30 14:07:41.601904 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/php.php"] [unique_id "amug_e_uyupB2NyFtxKNVwAAABQ"]
[Thu Jul 30 14:07:41.677010 2026] [autoindex:error] [pid 1004636:tid 1004839] [client 191.232.199.39:4315] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:42.021011 2026] [security2:error] [pid 1004636:tid 1004936] [client 191.232.199.39:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/bolt.php"] [unique_id "amug_u_uyupB2NyFtxKNYAAAAGw"]
[Thu Jul 30 14:07:42.103273 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/100.php"] [unique_id "amug_u_uyupB2NyFtxKNYQAAAF4"]
[Thu Jul 30 14:07:42.103374 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/100.php"] [unique_id "amug_u_uyupB2NyFtxKNYQAAAF4"]
[Thu Jul 30 14:07:42.580385 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/BDKR28WP.php"] [unique_id "amug_u_uyupB2NyFtxKNawAAAAE"]
[Thu Jul 30 14:07:42.580513 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/BDKR28WP.php"] [unique_id "amug_u_uyupB2NyFtxKNawAAAAE"]
[Thu Jul 30 14:07:42.887491 2026] [autoindex:error] [pid 1004636:tid 1004938] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:42.888175 2026] [security2:error] [pid 1004636:tid 1004938] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amug_u_uyupB2NyFtxKNdwAAAG4"]
[Thu Jul 30 14:07:42.888608 2026] [security2:error] [pid 1004636:tid 1004927] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/block-supports/"] [unique_id "amug_u_uyupB2NyFtxKNdQAAAGQ"]
[Thu Jul 30 14:07:43.100462 2026] [security2:error] [pid 1004636:tid 1004849] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/browse.php"] [unique_id "amug_-_uyupB2NyFtxKNeAAAABo"]
[Thu Jul 30 14:07:43.100744 2026] [security2:error] [pid 1004636:tid 1004849] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/browse.php"] [unique_id "amug_-_uyupB2NyFtxKNeAAAABo"]
[Thu Jul 30 14:07:43.307057 2026] [autoindex:error] [pid 1004636:tid 1004830] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:43.307701 2026] [security2:error] [pid 1004636:tid 1004830] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amug_-_uyupB2NyFtxKNggAAAAg"]
[Thu Jul 30 14:07:43.308120 2026] [security2:error] [pid 1004636:tid 1004869] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/html-api/"] [unique_id "amug_-_uyupB2NyFtxKNgAAAAC0"]
[Thu Jul 30 14:07:43.341881 2026] [security2:error] [pid 1004636:tid 1004868] [client 191.232.199.39:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/3.php"] [unique_id "amug_-_uyupB2NyFtxKNhQAAACw"]
[Thu Jul 30 14:07:43.608894 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-good.php"] [unique_id "amug_-_uyupB2NyFtxKNiAAAACM"]
[Thu Jul 30 14:07:43.609061 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-good.php"] [unique_id "amug_-_uyupB2NyFtxKNiAAAACM"]
[Thu Jul 30 14:07:43.662918 2026] [autoindex:error] [pid 1004636:tid 1004854] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:43.663553 2026] [security2:error] [pid 1004636:tid 1004854] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amug_-_uyupB2NyFtxKNjgAAAB4"]
[Thu Jul 30 14:07:43.663928 2026] [security2:error] [pid 1004636:tid 1004952] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/js/"] [unique_id "amug_-_uyupB2NyFtxKNjAAAAHw"]
[Thu Jul 30 14:07:43.801679 2026] [fcgid:warn] [pid 1004636:tid 1004944] (70014)End of file found: [client 123.58.196.49:51882] mod_fcgid: can't get data from http client
[Thu Jul 30 14:07:44.076885 2026] [autoindex:error] [pid 1004636:tid 1004932] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:44.077565 2026] [security2:error] [pid 1004636:tid 1004932] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhAO_uyupB2NyFtxKNoAAAAGk"]
[Thu Jul 30 14:07:44.078079 2026] [security2:error] [pid 1004636:tid 1004900] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/php-compat/"] [unique_id "amuhAO_uyupB2NyFtxKNngAAAEo"]
[Thu Jul 30 14:07:44.119130 2026] [security2:error] [pid 1004636:tid 1004950] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/8573.php"] [unique_id "amuhAO_uyupB2NyFtxKNoQAAAHo"]
[Thu Jul 30 14:07:44.119247 2026] [security2:error] [pid 1004636:tid 1004950] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/8573.php"] [unique_id "amuhAO_uyupB2NyFtxKNoQAAAHo"]
[Thu Jul 30 14:07:44.283469 2026] [security2:error] [pid 1004636:tid 1004906] [client 189.6.88.213:60811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhAO_uyupB2NyFtxKNpwAAAFA"]
[Thu Jul 30 14:07:44.283583 2026] [security2:error] [pid 1004636:tid 1004906] [client 189.6.88.213:60811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhAO_uyupB2NyFtxKNpwAAAFA"]
[Thu Jul 30 14:07:44.358419 2026] [core:notice] [pid 1004636:tid 1004953] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:44.408273 2026] [autoindex:error] [pid 1004636:tid 1004920] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:44.408948 2026] [security2:error] [pid 1004636:tid 1004920] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhAO_uyupB2NyFtxKNrAAAAF4"]
[Thu Jul 30 14:07:44.409366 2026] [security2:error] [pid 1004636:tid 1004855] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "amuhAO_uyupB2NyFtxKNqgAAAB8"]
[Thu Jul 30 14:07:44.456210 2026] [security2:error] [pid 1004636:tid 1004835] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amug_-_uyupB2NyFtxKNegAADQA"]
[Thu Jul 30 14:07:44.564170 2026] [security2:error] [pid 1004636:tid 1004909] [client 172.237.109.114:9952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amug_-_uyupB2NyFtxKNnQAAAFM"]
[Thu Jul 30 14:07:44.626674 2026] [security2:error] [pid 1004636:tid 1004840] [client 191.232.199.39:5032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/222.php"] [unique_id "amuhAO_uyupB2NyFtxKNswAAABE"]
[Thu Jul 30 14:07:44.720191 2026] [security2:error] [pid 1004636:tid 1004867] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/install.php"] [unique_id "amuhAO_uyupB2NyFtxKNuAAAACs"]
[Thu Jul 30 14:07:44.720321 2026] [security2:error] [pid 1004636:tid 1004867] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/install.php"] [unique_id "amuhAO_uyupB2NyFtxKNuAAAACs"]
[Thu Jul 30 14:07:44.728808 2026] [autoindex:error] [pid 1004636:tid 1004888] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:44.729460 2026] [security2:error] [pid 1004636:tid 1004888] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhAO_uyupB2NyFtxKNtgAAAD8"]
[Thu Jul 30 14:07:44.729940 2026] [security2:error] [pid 1004636:tid 1004877] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/pomo/"] [unique_id "amuhAO_uyupB2NyFtxKNtAAAADU"]
[Thu Jul 30 14:07:45.237581 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/classwithtostring.php"] [unique_id "amuhAe_uyupB2NyFtxKNwwAAACQ"]
[Thu Jul 30 14:07:45.237703 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/classwithtostring.php"] [unique_id "amuhAe_uyupB2NyFtxKNwwAAACQ"]
[Thu Jul 30 14:07:45.466632 2026] [security2:error] [pid 1004636:tid 1004947] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhAe_uyupB2NyFtxKNyAAAAHc"]
[Thu Jul 30 14:07:45.466660 2026] [security2:error] [pid 1004636:tid 1004947] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhAe_uyupB2NyFtxKNyAAAAHc"]
[Thu Jul 30 14:07:45.466937 2026] [security2:error] [pid 1004636:tid 1004912] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-includes/random_compat/"] [unique_id "amuhAe_uyupB2NyFtxKNxQAAAFY"]
[Thu Jul 30 14:07:45.787664 2026] [security2:error] [pid 1004636:tid 1004924] [client 191.232.199.39:4331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuhAe_uyupB2NyFtxKN0wAAAGE"]
[Thu Jul 30 14:07:45.895931 2026] [security2:error] [pid 1004636:tid 1004874] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ohct.php"] [unique_id "amuhAe_uyupB2NyFtxKN3wAAADI"]
[Thu Jul 30 14:07:45.896052 2026] [security2:error] [pid 1004636:tid 1004874] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ohct.php"] [unique_id "amuhAe_uyupB2NyFtxKN3wAAADI"]
[Thu Jul 30 14:07:46.544215 2026] [security2:error] [pid 1004636:tid 1004896] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/bless.php"] [unique_id "amuhAu_uyupB2NyFtxKOIgAAAEY"]
[Thu Jul 30 14:07:46.544335 2026] [security2:error] [pid 1004636:tid 1004896] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/bless.php"] [unique_id "amuhAu_uyupB2NyFtxKOIgAAAEY"]
[Thu Jul 30 14:07:46.544344 2026] [security2:error] [pid 1004636:tid 1004906] [client 181.116.200.68:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhAu_uyupB2NyFtxKOIwAAAFA"]
[Thu Jul 30 14:07:46.545020 2026] [security2:error] [pid 1004636:tid 1004906] [client 181.116.200.68:5057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhAu_uyupB2NyFtxKOIwAAAFA"]
[Thu Jul 30 14:07:46.598236 2026] [autoindex:error] [pid 1004636:tid 1004852] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:46.598845 2026] [security2:error] [pid 1004636:tid 1004852] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhAu_uyupB2NyFtxKOJwAAAB0"]
[Thu Jul 30 14:07:46.599202 2026] [security2:error] [pid 1004636:tid 1004870] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/rest-api/"] [unique_id "amuhAu_uyupB2NyFtxKOJQAAAC4"]
[Thu Jul 30 14:07:46.679139 2026] [security2:error] [pid 1004636:tid 1004897] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhAu_uyupB2NyFtxKN5QAARwc"]
[Thu Jul 30 14:07:47.028509 2026] [security2:error] [pid 1004636:tid 1004849] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/about.php"] [unique_id "amuhA-_uyupB2NyFtxKOMQAAABo"]
[Thu Jul 30 14:07:47.028604 2026] [security2:error] [pid 1004636:tid 1004849] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/about.php"] [unique_id "amuhA-_uyupB2NyFtxKOMQAAABo"]
[Thu Jul 30 14:07:47.190202 2026] [autoindex:error] [pid 1004636:tid 1004847] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:47.190845 2026] [security2:error] [pid 1004636:tid 1004847] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhA-_uyupB2NyFtxKONAAAABg"]
[Thu Jul 30 14:07:47.191269 2026] [security2:error] [pid 1004636:tid 1004842] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/sitemaps/"] [unique_id "amuhA-_uyupB2NyFtxKOMgAAABM"]
[Thu Jul 30 14:07:47.219117 2026] [security2:error] [pid 1004636:tid 1004930] [client 191.232.199.39:4330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuhA-_uyupB2NyFtxKONQAAAGc"]
[Thu Jul 30 14:07:47.485137 2026] [autoindex:error] [pid 1004636:tid 1004858] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:47.485811 2026] [security2:error] [pid 1004636:tid 1004858] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhA-_uyupB2NyFtxKOQQAAACI"]
[Thu Jul 30 14:07:47.486188 2026] [security2:error] [pid 1004636:tid 1004915] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amuhA-_uyupB2NyFtxKOPwAAAFk"]
[Thu Jul 30 14:07:47.520350 2026] [security2:error] [pid 1004636:tid 1004933] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuhA-_uyupB2NyFtxKOQgAAAGo"]
[Thu Jul 30 14:07:47.520462 2026] [security2:error] [pid 1004636:tid 1004933] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuhA-_uyupB2NyFtxKOQgAAAGo"]
[Thu Jul 30 14:07:48.010639 2026] [security2:error] [pid 1004636:tid 1004875] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ta0ol.php"] [unique_id "amuhBO_uyupB2NyFtxKOTwAAADM"]
[Thu Jul 30 14:07:48.010748 2026] [security2:error] [pid 1004636:tid 1004875] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ta0ol.php"] [unique_id "amuhBO_uyupB2NyFtxKOTwAAADM"]
[Thu Jul 30 14:07:48.316550 2026] [security2:error] [pid 1004636:tid 1004913] [client 74.7.229.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhA-_uyupB2NyFtxKOSgAAV2k"]
[Thu Jul 30 14:07:48.345289 2026] [autoindex:error] [pid 1004636:tid 1004839] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:48.345912 2026] [security2:error] [pid 1004636:tid 1004839] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhBO_uyupB2NyFtxKOVwAAABA"]
[Thu Jul 30 14:07:48.346375 2026] [security2:error] [pid 1004636:tid 1004900] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/style-engine/"] [unique_id "amuhBO_uyupB2NyFtxKOVAAAAEo"]
[Thu Jul 30 14:07:48.510377 2026] [security2:error] [pid 1004636:tid 1004955] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/sa.php7"] [unique_id "amuhBO_uyupB2NyFtxKOYAAAAH8"]
[Thu Jul 30 14:07:48.510475 2026] [security2:error] [pid 1004636:tid 1004955] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/sa.php7"] [unique_id "amuhBO_uyupB2NyFtxKOYAAAAH8"]
[Thu Jul 30 14:07:48.753899 2026] [autoindex:error] [pid 1004636:tid 1004905] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:48.754756 2026] [security2:error] [pid 1004636:tid 1004905] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhBO_uyupB2NyFtxKObwAAAE8"]
[Thu Jul 30 14:07:48.755149 2026] [security2:error] [pid 1004636:tid 1004852] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/theme-compat/"] [unique_id "amuhBO_uyupB2NyFtxKObQAAAB0"]
[Thu Jul 30 14:07:49.003089 2026] [security2:error] [pid 1004636:tid 1004934] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-class.php"] [unique_id "amuhBe_uyupB2NyFtxKOdQAAAGs"]
[Thu Jul 30 14:07:49.003187 2026] [security2:error] [pid 1004636:tid 1004934] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-class.php"] [unique_id "amuhBe_uyupB2NyFtxKOdQAAAGs"]
[Thu Jul 30 14:07:49.186910 2026] [autoindex:error] [pid 1004636:tid 1004825] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:49.187603 2026] [security2:error] [pid 1004636:tid 1004825] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhBe_uyupB2NyFtxKOhAAAAAM"]
[Thu Jul 30 14:07:49.187973 2026] [security2:error] [pid 1004636:tid 1004893] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-includes/widgets/"] [unique_id "amuhBe_uyupB2NyFtxKOggAAAEQ"]
[Thu Jul 30 14:07:49.503237 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/8.php"] [unique_id "amuhBe_uyupB2NyFtxKOiAAAAA8"]
[Thu Jul 30 14:07:49.503325 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/8.php"] [unique_id "amuhBe_uyupB2NyFtxKOiAAAAA8"]
[Thu Jul 30 14:07:49.571891 2026] [autoindex:error] [pid 1004636:tid 1004858] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:49.936027 2026] [security2:error] [pid 1004636:tid 1004918] [client 191.232.199.39:5008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/admin.php"] [unique_id "amuhBe_uyupB2NyFtxKOmQAAAFw"]
[Thu Jul 30 14:07:50.008184 2026] [security2:error] [pid 1004636:tid 1004851] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/bootstrap.php"] [unique_id "amuhBu_uyupB2NyFtxKOnQAAABw"]
[Thu Jul 30 14:07:50.008313 2026] [security2:error] [pid 1004636:tid 1004851] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/bootstrap.php"] [unique_id "amuhBu_uyupB2NyFtxKOnQAAABw"]
[Thu Jul 30 14:07:50.277928 2026] [proxy:error] [pid 1004636:tid 1004891] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:50.278020 2026] [proxy_http:error] [pid 1004636:tid 1004891] [client 98.87.102.177:59766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:50.278650 2026] [proxy:error] [pid 1004636:tid 1004891] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:50.278696 2026] [proxy_http:error] [pid 1004636:tid 1004891] [client 98.87.102.177:59766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:50.281169 2026] [proxy:error] [pid 1004636:tid 1004879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:50.281240 2026] [proxy_http:error] [pid 1004636:tid 1004879] [client 44.216.125.112:46644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:50.282004 2026] [proxy:error] [pid 1004636:tid 1004879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:07:50.282066 2026] [proxy_http:error] [pid 1004636:tid 1004879] [client 44.216.125.112:46644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:07:50.513756 2026] [security2:error] [pid 1004636:tid 1004867] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-blog-header.php"] [unique_id "amuhBu_uyupB2NyFtxKOuAAAACs"]
[Thu Jul 30 14:07:50.513887 2026] [security2:error] [pid 1004636:tid 1004867] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-blog-header.php"] [unique_id "amuhBu_uyupB2NyFtxKOuAAAACs"]
[Thu Jul 30 14:07:50.613680 2026] [autoindex:error] [pid 1004636:tid 1004864] [client 82.102.18.180:43150] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:50.614346 2026] [security2:error] [pid 1004636:tid 1004864] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhBu_uyupB2NyFtxKOuQAAACg"]
[Thu Jul 30 14:07:51.060240 2026] [security2:error] [pid 1004636:tid 1004899] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/aa.php"] [unique_id "amuhB-_uyupB2NyFtxKOyQAAAEk"]
[Thu Jul 30 14:07:51.060320 2026] [security2:error] [pid 1004636:tid 1004899] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/aa.php"] [unique_id "amuhB-_uyupB2NyFtxKOyQAAAEk"]
[Thu Jul 30 14:07:51.565991 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/tx79.php"] [unique_id "amuhB-_uyupB2NyFtxKO3AAAAFY"]
[Thu Jul 30 14:07:51.566097 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/tx79.php"] [unique_id "amuhB-_uyupB2NyFtxKO3AAAAFY"]
[Thu Jul 30 14:07:52.193584 2026] [security2:error] [pid 1004636:tid 1004952] [client 103.190.40.154:21169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhCO_uyupB2NyFtxKO6gAAAHw"]
[Thu Jul 30 14:07:52.193745 2026] [security2:error] [pid 1004636:tid 1004952] [client 103.190.40.154:21169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhCO_uyupB2NyFtxKO6gAAAHw"]
[Thu Jul 30 14:07:52.373472 2026] [security2:error] [pid 1004636:tid 1004856] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/motu.php"] [unique_id "amuhCO_uyupB2NyFtxKO8QAAACA"]
[Thu Jul 30 14:07:52.373583 2026] [security2:error] [pid 1004636:tid 1004856] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/motu.php"] [unique_id "amuhCO_uyupB2NyFtxKO8QAAACA"]
[Thu Jul 30 14:07:52.548751 2026] [core:error] [pid 1004636:tid 1004896] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:07:52.548774 2026] [core:error] [pid 1004636:tid 1004896] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:07:52.864389 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-head.php"] [unique_id "amuhCO_uyupB2NyFtxKO-wAAADQ"]
[Thu Jul 30 14:07:52.864496 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-head.php"] [unique_id "amuhCO_uyupB2NyFtxKO-wAAADQ"]
[Thu Jul 30 14:07:53.067231 2026] [security2:error] [pid 1004636:tid 1004872] [client 191.232.199.39:4915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-configs.php"] [unique_id "amuhCe_uyupB2NyFtxKO_wAAADA"]
[Thu Jul 30 14:07:53.337192 2026] [core:notice] [pid 1004636:tid 1004847] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:53.354081 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuhCe_uyupB2NyFtxKPCQAAAG4"]
[Thu Jul 30 14:07:53.354214 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuhCe_uyupB2NyFtxKPCQAAAG4"]
[Thu Jul 30 14:07:53.838491 2026] [security2:error] [pid 1004636:tid 1004851] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/60856e3a4findex.php"] [unique_id "amuhCe_uyupB2NyFtxKPGAAAABw"]
[Thu Jul 30 14:07:53.838639 2026] [security2:error] [pid 1004636:tid 1004851] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/60856e3a4findex.php"] [unique_id "amuhCe_uyupB2NyFtxKPGAAAABw"]
[Thu Jul 30 14:07:54.329316 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-the.php"] [unique_id "amuhCu_uyupB2NyFtxKPIwAAAFQ"]
[Thu Jul 30 14:07:54.329417 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp-the.php"] [unique_id "amuhCu_uyupB2NyFtxKPIwAAAFQ"]
[Thu Jul 30 14:07:54.452350 2026] [security2:error] [pid 1004636:tid 1004827] [client 191.232.199.39:4911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/php.php"] [unique_id "amuhCu_uyupB2NyFtxKPJwAAAAU"]
[Thu Jul 30 14:07:54.487748 2026] [core:notice] [pid 1004636:tid 1004913] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:54.610840 2026] [autoindex:error] [pid 1004636:tid 1004907] [client 82.102.18.180:43150] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:54.611562 2026] [security2:error] [pid 1004636:tid 1004907] [client 82.102.18.180:43150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhCu_uyupB2NyFtxKPKgAAAFE"]
[Thu Jul 30 14:07:54.846040 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp.php"] [unique_id "amuhCu_uyupB2NyFtxKPNQAAAFM"]
[Thu Jul 30 14:07:54.846147 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wp.php"] [unique_id "amuhCu_uyupB2NyFtxKPNQAAAFM"]
[Thu Jul 30 14:07:54.960497 2026] [security2:error] [pid 1004636:tid 1004880] [client 189.6.88.213:61356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhCu_uyupB2NyFtxKPOAAAADg"]
[Thu Jul 30 14:07:54.960651 2026] [security2:error] [pid 1004636:tid 1004880] [client 189.6.88.213:61356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhCu_uyupB2NyFtxKPOAAAADg"]
[Thu Jul 30 14:07:55.398637 2026] [security2:error] [pid 1004636:tid 1004927] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/users.php"] [unique_id "amuhC-_uyupB2NyFtxKPZgAAAGQ"]
[Thu Jul 30 14:07:55.398791 2026] [security2:error] [pid 1004636:tid 1004927] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/users.php"] [unique_id "amuhC-_uyupB2NyFtxKPZgAAAGQ"]
[Thu Jul 30 14:07:55.955278 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/tinysd.php"] [unique_id "amuhC-_uyupB2NyFtxKPjAAAAE4"]
[Thu Jul 30 14:07:55.955409 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/tinysd.php"] [unique_id "amuhC-_uyupB2NyFtxKPjAAAAE4"]
[Thu Jul 30 14:07:56.276815 2026] [security2:error] [pid 1004636:tid 1004881] [client 191.232.199.39:35844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/index.php"] [unique_id "amuhDO_uyupB2NyFtxKPlQAAADk"]
[Thu Jul 30 14:07:56.405601 2026] [security2:error] [pid 1004636:tid 1004828] [client 85.204.70.116:38302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.siw.lku.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuhDO_uyupB2NyFtxKPmgAAAAY"]
[Thu Jul 30 14:07:56.481381 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ws78.php"] [unique_id "amuhDO_uyupB2NyFtxKPmwAAAAc"]
[Thu Jul 30 14:07:56.481533 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ws78.php"] [unique_id "amuhDO_uyupB2NyFtxKPmwAAAAc"]
[Thu Jul 30 14:07:56.715494 2026] [core:notice] [pid 1004636:tid 1004844] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:56.991251 2026] [security2:error] [pid 1004636:tid 1004941] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/elp.php"] [unique_id "amuhDO_uyupB2NyFtxKPrgAAAHE"]
[Thu Jul 30 14:07:56.991394 2026] [security2:error] [pid 1004636:tid 1004941] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/elp.php"] [unique_id "amuhDO_uyupB2NyFtxKPrgAAAHE"]
[Thu Jul 30 14:07:57.178055 2026] [security2:error] [pid 1004636:tid 1004909] [client 181.116.200.68:29601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhDe_uyupB2NyFtxKPtgAAAFM"]
[Thu Jul 30 14:07:57.178156 2026] [security2:error] [pid 1004636:tid 1004909] [client 181.116.200.68:29601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhDe_uyupB2NyFtxKPtgAAAFM"]
[Thu Jul 30 14:07:57.487138 2026] [security2:error] [pid 1004636:tid 1004836] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/atomlib.php"] [unique_id "amuhDe_uyupB2NyFtxKPwgAAAA4"]
[Thu Jul 30 14:07:57.487252 2026] [security2:error] [pid 1004636:tid 1004836] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/atomlib.php"] [unique_id "amuhDe_uyupB2NyFtxKPwgAAAA4"]
[Thu Jul 30 14:07:57.578098 2026] [security2:error] [pid 1004636:tid 1004849] [client 191.232.199.39:5027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/a.php"] [unique_id "amuhDe_uyupB2NyFtxKPxAAAABo"]
[Thu Jul 30 14:07:58.023726 2026] [security2:error] [pid 1004636:tid 1004861] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wyzer3.php"] [unique_id "amuhDu_uyupB2NyFtxKP1QAAACU"]
[Thu Jul 30 14:07:58.023882 2026] [security2:error] [pid 1004636:tid 1004861] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/wyzer3.php"] [unique_id "amuhDu_uyupB2NyFtxKP1QAAACU"]
[Thu Jul 30 14:07:58.286641 2026] [security2:error] [pid 1004636:tid 1004881] [client 85.204.70.116:53592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siw.lku.temporary.site"] [uri "/index.php"] [unique_id "amuhDu_uyupB2NyFtxKP2gAAADk"]
[Thu Jul 30 14:07:58.364700 2026] [security2:error] [pid 1004636:tid 1004897] [client 206.72.255.149:53109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuhC-_uyupB2NyFtxKPVgAARw8"], referer: https://jwcpartners.org/
[Thu Jul 30 14:07:58.365058 2026] [security2:error] [pid 1004636:tid 1004897] [client 206.72.255.149:53109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuhC-_uyupB2NyFtxKPTAAAR1A"], referer: https://jwcpartners.org/
[Thu Jul 30 14:07:58.366606 2026] [security2:error] [pid 1004636:tid 1004897] [client 206.72.255.149:53109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuhC-_uyupB2NyFtxKPTQAAR0U"], referer: https://jwcpartners.org/
[Thu Jul 30 14:07:58.366687 2026] [security2:error] [pid 1004636:tid 1004897] [client 206.72.255.149:53109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuhC-_uyupB2NyFtxKPWQAAR0s"], referer: https://jwcpartners.org/
[Thu Jul 30 14:07:58.386163 2026] [security2:error] [pid 1004636:tid 1004897] [client 206.72.255.149:53109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuhC-_uyupB2NyFtxKPdgAAR1k"], referer: https://jwcpartners.org/
[Thu Jul 30 14:07:58.386310 2026] [security2:error] [pid 1004636:tid 1004897] [client 206.72.255.149:53109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuhC-_uyupB2NyFtxKPWwAAR0I"], referer: https://jwcpartners.org/
[Thu Jul 30 14:07:58.420850 2026] [security2:error] [pid 1004636:tid 1004896] [client 85.204.70.116:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.siw.lku.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuhDu_uyupB2NyFtxKP5wAAAEY"]
[Thu Jul 30 14:07:58.420961 2026] [security2:error] [pid 1004636:tid 1004896] [client 85.204.70.116:53592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.siw.lku.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuhDu_uyupB2NyFtxKP5wAAAEY"]
[Thu Jul 30 14:07:58.554193 2026] [security2:error] [pid 1004636:tid 1004852] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env.backup"] [unique_id "amuhDu_uyupB2NyFtxKP6wAAAB0"]
[Thu Jul 30 14:07:58.833616 2026] [security2:error] [pid 1004636:tid 1004905] [client 50.6.43.217:35572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuhDu_uyupB2NyFtxKP7AAAAE8"]
[Thu Jul 30 14:07:58.974775 2026] [core:notice] [pid 1004636:tid 1004936] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:07:59.109350 2026] [security2:error] [pid 1004636:tid 1004883] [client 50.6.43.217:35574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amuhDu_uyupB2NyFtxKP9gAAADo"]
[Thu Jul 30 14:07:59.267363 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/max.php"] [unique_id "amuhD-_uyupB2NyFtxKQCAAAAFY"]
[Thu Jul 30 14:07:59.267521 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/max.php"] [unique_id "amuhD-_uyupB2NyFtxKQCAAAAFY"]
[Thu Jul 30 14:07:59.729718 2026] [autoindex:error] [pid 1004636:tid 1004944] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:07:59.830135 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ftde.php"] [unique_id "amuhD-_uyupB2NyFtxKQHAAAAHw"]
[Thu Jul 30 14:07:59.830220 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.homemoversandpackersabudhabi.fit"] [uri "/ftde.php"] [unique_id "amuhD-_uyupB2NyFtxKQHAAAAHw"]
[Thu Jul 30 14:08:00.125861 2026] [autoindex:error] [pid 1004636:tid 1004907] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:00.491902 2026] [security2:error] [pid 1004636:tid 1004845] [client 191.232.199.39:35888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuhEO_uyupB2NyFtxKQMwAAABY"]
[Thu Jul 30 14:08:00.670504 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.7.175.179:59592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tereasshop.com"] [uri "/robots.txt"] [unique_id "amuhEO_uyupB2NyFtxKQOwAAABU"]
[Thu Jul 30 14:08:01.239994 2026] [security2:error] [pid 1004636:tid 1004926] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/api.orig"] [unique_id "amuhEe_uyupB2NyFtxKQTwAAAGM"]
[Thu Jul 30 14:08:01.485914 2026] [core:notice] [pid 1004636:tid 1004742] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:01.732728 2026] [security2:error] [pid 1004636:tid 1004933] [client 191.232.199.39:4894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin.php"] [unique_id "amuhEe_uyupB2NyFtxKQXwAAAGo"]
[Thu Jul 30 14:08:02.132083 2026] [security2:error] [pid 1004636:tid 1004907] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/src.orig"] [unique_id "amuhEu_uyupB2NyFtxKQbwAAAFE"]
[Thu Jul 30 14:08:02.844718 2026] [core:notice] [pid 1004636:tid 1004826] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:03.024368 2026] [security2:error] [pid 1004636:tid 1004931] [client 103.190.40.154:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhE-_uyupB2NyFtxKQhAAAAGg"]
[Thu Jul 30 14:08:03.024484 2026] [security2:error] [pid 1004636:tid 1004931] [client 103.190.40.154:20910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhE-_uyupB2NyFtxKQhAAAAGg"]
[Thu Jul 30 14:08:04.458522 2026] [core:notice] [pid 1004636:tid 1004773] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:05.335127 2026] [security2:error] [pid 1004636:tid 1004863] [client 191.232.199.39:4893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/size.php"] [unique_id "amuhFe_uyupB2NyFtxKQ1QAAACc"]
[Thu Jul 30 14:08:05.670670 2026] [security2:error] [pid 1004636:tid 1004885] [client 189.6.88.213:61903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhFe_uyupB2NyFtxKQ3AAAADw"]
[Thu Jul 30 14:08:05.670798 2026] [security2:error] [pid 1004636:tid 1004885] [client 189.6.88.213:61903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhFe_uyupB2NyFtxKQ3AAAADw"]
[Thu Jul 30 14:08:05.704540 2026] [core:notice] [pid 1004636:tid 1004940] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:05.708880 2026] [security2:error] [pid 1004636:tid 1004940] [client 74.0.19.30:49081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/view/2722"] [unique_id "amuhFe_uyupB2NyFtxKQ2gAAAHA"]
[Thu Jul 30 14:08:06.289431 2026] [security2:error] [pid 1004636:tid 1004899] [client 167.88.167.87:46454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alseermarine.com"] [uri "/"] [unique_id "amuhFu_uyupB2NyFtxKQ6wAAAEk"]
[Thu Jul 30 14:08:06.386184 2026] [core:notice] [pid 1004636:tid 1004794] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:06.819498 2026] [security2:error] [pid 1004636:tid 1004860] [client 191.232.199.39:4750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuhFu_uyupB2NyFtxKRAQAAACQ"]
[Thu Jul 30 14:08:06.849154 2026] [core:notice] [pid 1004636:tid 1004868] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:07.805318 2026] [security2:error] [pid 1004636:tid 1004856] [client 181.116.200.68:23661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhF-_uyupB2NyFtxKRHgAAACA"]
[Thu Jul 30 14:08:07.805462 2026] [security2:error] [pid 1004636:tid 1004856] [client 181.116.200.68:23661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhF-_uyupB2NyFtxKRHgAAACA"]
[Thu Jul 30 14:08:08.035478 2026] [core:notice] [pid 1004636:tid 1004872] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:08.040798 2026] [security2:error] [pid 1004636:tid 1004872] [client 74.7.230.41:44100] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuhGO_uyupB2NyFtxKRLAAAADA"]
[Thu Jul 30 14:08:08.403962 2026] [security2:error] [pid 1004636:tid 1004867] [client 191.232.199.39:5018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/403.php"] [unique_id "amuhGO_uyupB2NyFtxKRNwAAACs"]
[Thu Jul 30 14:08:08.915295 2026] [security2:error] [pid 1004636:tid 1004899] [client 74.7.230.41:40586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuhGO_uyupB2NyFtxKRQwAASWw"], referer: http://carnetdeshopping.com/robots.txt
[Thu Jul 30 14:08:09.174293 2026] [core:notice] [pid 1004636:tid 1004805] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:09.179574 2026] [security2:error] [pid 1004636:tid 1004888] [client 94.176.93.120:40211] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/9470"] [unique_id "amuhGO_uyupB2NyFtxKRTAAAP3E"], referer: https://www.ejournalugj.com/
[Thu Jul 30 14:08:09.657615 2026] [security2:error] [pid 1004636:tid 1004868] [client 151.80.133.130:49702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.133.80.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuhGe_uyupB2NyFtxKRWQAAACw"]
[Thu Jul 30 14:08:09.674267 2026] [security2:error] [pid 1004636:tid 1004874] [client 191.232.199.39:4995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuhGe_uyupB2NyFtxKRZAAAADI"]
[Thu Jul 30 14:08:10.143710 2026] [security2:error] [pid 1004636:tid 1004902] [client 51.75.23.111:40002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.23.75.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuhGu_uyupB2NyFtxKRdAAAAEw"]
[Thu Jul 30 14:08:10.647532 2026] [security2:error] [pid 1004636:tid 1004936] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/libs~"] [unique_id "amuhGu_uyupB2NyFtxKRgQAAAGw"]
[Thu Jul 30 14:08:11.300652 2026] [security2:error] [pid 1004636:tid 1004909] [client 191.232.199.39:5013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/as.php"] [unique_id "amuhG-_uyupB2NyFtxKRjQAAAFM"]
[Thu Jul 30 14:08:12.200807 2026] [security2:error] [pid 1004636:tid 1004687] [remote 207.46.13.9:25730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/uploads/2019/08/login.php"] [unique_id "amuhHO_uyupB2NyFtxKRqAAAGwA"]
[Thu Jul 30 14:08:12.733160 2026] [core:notice] [pid 1004636:tid 1004705] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:13.448558 2026] [core:notice] [pid 1004636:tid 1004895] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:13.625940 2026] [security2:error] [pid 1004636:tid 1004951] [client 191.232.199.39:35849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuhHe_uyupB2NyFtxKRzAAAAHs"]
[Thu Jul 30 14:08:13.800758 2026] [security2:error] [pid 1004636:tid 1004849] [client 103.190.40.154:5542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhHe_uyupB2NyFtxKR1wAAABo"]
[Thu Jul 30 14:08:13.800887 2026] [security2:error] [pid 1004636:tid 1004849] [client 103.190.40.154:5542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhHe_uyupB2NyFtxKR1wAAABo"]
[Thu Jul 30 14:08:14.088630 2026] [security2:error] [pid 1004636:tid 1004915] [client 145.239.87.55:44982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.87.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuhHu_uyupB2NyFtxKR3AAAAFk"]
[Thu Jul 30 14:08:14.383489 2026] [security2:error] [pid 1004636:tid 1004918] [client 141.94.94.103:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.94.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuhHu_uyupB2NyFtxKR6QAAAFw"]
[Thu Jul 30 14:08:14.627985 2026] [core:notice] [pid 1004636:tid 1004879] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:14.641432 2026] [security2:error] [pid 1004636:tid 1004842] [client 51.77.211.229:57124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.211.77.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuhHu_uyupB2NyFtxKR9QAAABM"]
[Thu Jul 30 14:08:14.864963 2026] [security2:error] [pid 1004636:tid 1004846] [client 4.248.40.85:57919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/plugins/about.php"] [unique_id "amuhHu_uyupB2NyFtxKR8gAAABc"]
[Thu Jul 30 14:08:14.925316 2026] [security2:error] [pid 1004636:tid 1004889] [client 213.32.68.76:39076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.68.32.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuhHu_uyupB2NyFtxKSAwAAAEA"]
[Thu Jul 30 14:08:14.971700 2026] [security2:error] [pid 1004636:tid 1004841] [client 4.248.40.85:57953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/inputs.php"] [unique_id "amuhHu_uyupB2NyFtxKR9gAAABI"]
[Thu Jul 30 14:08:15.046958 2026] [security2:error] [pid 1004636:tid 1004896] [client 4.248.40.85:58141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-admin/network/index.php"] [unique_id "amuhH-_uyupB2NyFtxKSCAAAAEY"]
[Thu Jul 30 14:08:15.073750 2026] [core:notice] [pid 1004636:tid 1004725] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.078587 2026] [security2:error] [pid 1004636:tid 1004865] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/lib/pkp/styles/fontawesome/fontawesome_v-3.3.0.17.css"] [unique_id "amuhHu_uyupB2NyFtxKR-gAAKSQ"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.087453 2026] [core:notice] [pid 1004636:tid 1004760] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.088800 2026] [core:notice] [pid 1004636:tid 1004753] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.092285 2026] [security2:error] [pid 1004636:tid 1004865] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/index_php/index/---call---/page/page/css-name-font.css"] [unique_id "amuhHu_uyupB2NyFtxKR-QAAKUY"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.095129 2026] [security2:error] [pid 1004636:tid 1004865] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/index_php/index/---call---/page/page/css-name-stylesheet.css"] [unique_id "amuhHu_uyupB2NyFtxKR-AAAKT8"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.213277 2026] [core:notice] [pid 1004636:tid 1004940] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.236904 2026] [core:notice] [pid 1004636:tid 1004744] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.237022 2026] [core:notice] [pid 1004636:tid 1004755] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.240389 2026] [security2:error] [pid 1004636:tid 1004848] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/17/journalThumbnail_en_US.png"] [unique_id "amuhH-_uyupB2NyFtxKSDAAAGTc"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.240799 2026] [security2:error] [pid 1004636:tid 1004848] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/site/pageHeaderTitleImage_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSCwAAGUE"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.244328 2026] [core:notice] [pid 1004636:tid 1004738] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.244657 2026] [core:notice] [pid 1004636:tid 1004730] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.244722 2026] [core:notice] [pid 1004636:tid 1004728] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.244731 2026] [core:notice] [pid 1004636:tid 1004763] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.244818 2026] [core:notice] [pid 1004636:tid 1004742] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.244896 2026] [core:notice] [pid 1004636:tid 1004736] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.248109 2026] [security2:error] [pid 1004636:tid 1004951] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/32/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSDgAAeyk"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.248527 2026] [security2:error] [pid 1004636:tid 1004951] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/44/journalThumbnail_id_ID.png"] [unique_id "amuhH-_uyupB2NyFtxKSEQAAezE"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.249577 2026] [security2:error] [pid 1004636:tid 1004951] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSDQAAeyc"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.249946 2026] [security2:error] [pid 1004636:tid 1004951] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/site/images/apranolo/Crossref_Logo_Stacked_RGB_SMALL.png"] [unique_id "amuhH-_uyupB2NyFtxKSDwAAezU"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.250339 2026] [security2:error] [pid 1004636:tid 1004951] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/19/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSEAAAe0g"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.250722 2026] [security2:error] [pid 1004636:tid 1004951] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/39/journalThumbnail_en_US.png"] [unique_id "amuhH-_uyupB2NyFtxKSEgAAey8"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.438338 2026] [core:notice] [pid 1004636:tid 1004706] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.438351 2026] [core:notice] [pid 1004636:tid 1004723] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.438743 2026] [core:notice] [pid 1004636:tid 1004722] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.438819 2026] [core:notice] [pid 1004636:tid 1004729] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.438854 2026] [core:notice] [pid 1004636:tid 1004721] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.438855 2026] [core:notice] [pid 1004636:tid 1004747] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.438895 2026] [core:notice] [pid 1004636:tid 1004708] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.439348 2026] [core:notice] [pid 1004636:tid 1004727] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.442817 2026] [security2:error] [pid 1004636:tid 1004917] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/10/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSGQAAWxI"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.443126 2026] [security2:error] [pid 1004636:tid 1004917] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/20/journalThumbnail_en_US.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSHgAAWyI"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.443794 2026] [security2:error] [pid 1004636:tid 1004917] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/33/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSGAAAWyE"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.444112 2026] [security2:error] [pid 1004636:tid 1004917] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/6/journalThumbnail_en_US.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSHwAAWyA"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.444809 2026] [security2:error] [pid 1004636:tid 1004917] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/21/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSHAAAWzk"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.445171 2026] [security2:error] [pid 1004636:tid 1004917] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/24/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSGgAAWyg"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.445461 2026] [security2:error] [pid 1004636:tid 1004917] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/22/journalThumbnail_en_US.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSHQAAWyY"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.446266 2026] [security2:error] [pid 1004636:tid 1004917] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/8/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSGwAAWxQ"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.585547 2026] [core:notice] [pid 1004636:tid 1004726] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.585547 2026] [core:notice] [pid 1004636:tid 1004767] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.585792 2026] [core:notice] [pid 1004636:tid 1004733] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.586003 2026] [core:notice] [pid 1004636:tid 1004775] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.588136 2026] [core:notice] [pid 1004636:tid 1004719] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.589045 2026] [security2:error] [pid 1004636:tid 1004830] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/3/journalThumbnail_en_US.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSJwAACCU"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.589215 2026] [security2:error] [pid 1004636:tid 1004830] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/14/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSKAAACEw"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.589393 2026] [core:notice] [pid 1004636:tid 1004768] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.589525 2026] [core:notice] [pid 1004636:tid 1004757] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.590779 2026] [security2:error] [pid 1004636:tid 1004830] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/7/journalThumbnail_id_ID.png"] [unique_id "amuhH-_uyupB2NyFtxKSKQAACCw"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.591617 2026] [security2:error] [pid 1004636:tid 1004830] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/4/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSKgAACFQ"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.592091 2026] [security2:error] [pid 1004636:tid 1004830] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/1/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSKwAACB4"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.593927 2026] [security2:error] [pid 1004636:tid 1004830] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/35/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSLQAACEM"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.595138 2026] [security2:error] [pid 1004636:tid 1004830] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/29/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSLAAACE0"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.596494 2026] [core:notice] [pid 1004636:tid 1004740] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.599904 2026] [security2:error] [pid 1004636:tid 1004830] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/13/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSLgAACDM"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.630292 2026] [security2:error] [pid 1004636:tid 1004845] [client 191.232.199.39:5040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuhH-_uyupB2NyFtxKSLwAAABY"]
[Thu Jul 30 14:08:15.726412 2026] [core:notice] [pid 1004636:tid 1004751] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.729797 2026] [security2:error] [pid 1004636:tid 1004928] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/25/journalThumbnail_id_ID.jpg"] [unique_id "amuhH-_uyupB2NyFtxKSMQAAZT0"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.734861 2026] [core:notice] [pid 1004636:tid 1004735] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.734877 2026] [core:notice] [pid 1004636:tid 1004790] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:15.737895 2026] [security2:error] [pid 1004636:tid 1004926] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/templates/images/ojs_brand.png"] [unique_id "amuhH-_uyupB2NyFtxKSNAAAYy4"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:15.738100 2026] [security2:error] [pid 1004636:tid 1004926] [client 69.164.96.235:35751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/public/journals/2/journalThumbnail_id_ID.png"] [unique_id "amuhH-_uyupB2NyFtxKSMwAAY2M"], referer: https://www.ejournalugj.com/index.php/Perspective/article/view/9470?articlesBySimilarityPage=2
[Thu Jul 30 14:08:16.076251 2026] [security2:error] [pid 1004636:tid 1004933] [client 49.51.36.179:38610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.36.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/partnerf.php"] [unique_id "amuhIO_uyupB2NyFtxKSSQAAAGo"]
[Thu Jul 30 14:08:16.423808 2026] [security2:error] [pid 1004636:tid 1004950] [client 189.6.88.213:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhIO_uyupB2NyFtxKSUAAAAHo"]
[Thu Jul 30 14:08:16.423913 2026] [security2:error] [pid 1004636:tid 1004950] [client 189.6.88.213:62462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhIO_uyupB2NyFtxKSUAAAAHo"]
[Thu Jul 30 14:08:16.877436 2026] [security2:error] [pid 1004636:tid 1004905] [client 4.248.40.85:59123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/geju.php"] [unique_id "amuhIO_uyupB2NyFtxKSYAAAAE8"]
[Thu Jul 30 14:08:16.879594 2026] [security2:error] [pid 1004636:tid 1004873] [client 4.248.40.85:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/edit-tags.php"] [unique_id "amuhIO_uyupB2NyFtxKSYQAAADE"]
[Thu Jul 30 14:08:16.893043 2026] [security2:error] [pid 1004636:tid 1004896] [client 4.248.40.85:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-admin/js/index.php"] [unique_id "amuhIO_uyupB2NyFtxKSYgAAAEY"]
[Thu Jul 30 14:08:17.064374 2026] [security2:error] [pid 1004636:tid 1004902] [client 191.232.199.39:4836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/plugins.php"] [unique_id "amuhIe_uyupB2NyFtxKSagAAAEw"]
[Thu Jul 30 14:08:17.260163 2026] [security2:error] [pid 1004636:tid 1004938] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/wordpress.sql"] [unique_id "amuhIe_uyupB2NyFtxKSbwAAAG4"]
[Thu Jul 30 14:08:18.131885 2026] [security2:error] [pid 1004636:tid 1004789] [remote 74.7.243.224:40102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amuhIu_uyupB2NyFtxKSiwAACWI"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:08:18.311861 2026] [security2:error] [pid 1004636:tid 1004948] [client 181.116.200.68:54954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhIu_uyupB2NyFtxKSkQAAAHg"]
[Thu Jul 30 14:08:18.312007 2026] [security2:error] [pid 1004636:tid 1004948] [client 181.116.200.68:54954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhIu_uyupB2NyFtxKSkQAAAHg"]
[Thu Jul 30 14:08:18.609312 2026] [security2:error] [pid 1004636:tid 1004901] [client 191.232.199.39:4846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuhIu_uyupB2NyFtxKSlwAAAEs"]
[Thu Jul 30 14:08:18.629964 2026] [security2:error] [pid 1004636:tid 1004939] [client 172.237.109.114:19245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuhIu_uyupB2NyFtxKShwAAAG8"]
[Thu Jul 30 14:08:18.677128 2026] [security2:error] [pid 1004636:tid 1004864] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env~"] [unique_id "amuhIu_uyupB2NyFtxKSoAAAACg"]
[Thu Jul 30 14:08:19.585990 2026] [security2:error] [pid 1004636:tid 1004859] [client 4.248.40.85:60473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/admin.php"] [unique_id "amuhI-_uyupB2NyFtxKSuAAAACM"]
[Thu Jul 30 14:08:19.586343 2026] [security2:error] [pid 1004636:tid 1004849] [client 4.248.40.85:60455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp.php"] [unique_id "amuhI-_uyupB2NyFtxKSuQAAABo"]
[Thu Jul 30 14:08:19.603011 2026] [security2:error] [pid 1004636:tid 1004925] [client 4.248.40.85:60484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-admin/images/index.php"] [unique_id "amuhI-_uyupB2NyFtxKSuwAAAGI"]
[Thu Jul 30 14:08:20.059789 2026] [security2:error] [pid 1004636:tid 1004877] [client 191.232.199.39:4900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/go.php"] [unique_id "amuhJO_uyupB2NyFtxKSyAAAADU"]
[Thu Jul 30 14:08:20.749470 2026] [security2:error] [pid 1004636:tid 1004924] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhJO_uyupB2NyFtxKSygAAYTg"]
[Thu Jul 30 14:08:21.639307 2026] [security2:error] [pid 1004636:tid 1004852] [client 191.232.199.39:4850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/test1.php"] [unique_id "amuhJe_uyupB2NyFtxKS-AAAAB0"]
[Thu Jul 30 14:08:21.653115 2026] [security2:error] [pid 1004636:tid 1004863] [client 74.7.228.14:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.brx.dtn.temporary.site"] [uri "/index.php"] [unique_id "amuhJO_uyupB2NyFtxKS5AAAACc"]
[Thu Jul 30 14:08:21.653683 2026] [security2:error] [pid 1004636:tid 1004851] [client 74.7.228.14:48590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.brx.dtn.temporary.site"] [uri "/robots.txt"] [unique_id "amuhJO_uyupB2NyFtxKS4gAAHDo"]
[Thu Jul 30 14:08:21.921878 2026] [security2:error] [pid 1004636:tid 1004923] [client 4.248.40.85:61720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/backup/inputs.php"] [unique_id "amuhJe_uyupB2NyFtxKTBAAAAGA"]
[Thu Jul 30 14:08:21.972930 2026] [security2:error] [pid 1004636:tid 1004887] [client 4.248.40.85:61734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-admin/css/index.php"] [unique_id "amuhJe_uyupB2NyFtxKTBQAAAD4"]
[Thu Jul 30 14:08:22.312527 2026] [security2:error] [pid 1004636:tid 1004925] [client 4.248.40.85:61712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/plugins/about.php"] [unique_id "amuhJu_uyupB2NyFtxKTDQAAAGI"]
[Thu Jul 30 14:08:22.624102 2026] [security2:error] [pid 1004636:tid 1004904] [client 172.237.109.114:11230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuhJu_uyupB2NyFtxKTBwAAAE4"]
[Thu Jul 30 14:08:23.126908 2026] [autoindex:error] [pid 1004636:tid 1004921] [client 191.232.199.39:4829] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:23.525297 2026] [security2:error] [pid 1004636:tid 1004873] [client 4.248.40.85:62570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/uploads/inputs.php"] [unique_id "amuhJ-_uyupB2NyFtxKTMQAAADE"]
[Thu Jul 30 14:08:23.549392 2026] [security2:error] [pid 1004636:tid 1004896] [client 4.248.40.85:62580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-includes/SimplePie/Content/Type/index.php"] [unique_id "amuhJ-_uyupB2NyFtxKTMgAAAEY"]
[Thu Jul 30 14:08:23.553040 2026] [security2:error] [pid 1004636:tid 1004823] [client 191.232.199.39:4829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/images/index.php"] [unique_id "amuhJ-_uyupB2NyFtxKTMwAAAAE"]
[Thu Jul 30 14:08:24.093305 2026] [security2:error] [pid 1004636:tid 1004903] [client 4.248.40.85:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/geju.php"] [unique_id "amuhKO_uyupB2NyFtxKTRAAAAE0"]
[Thu Jul 30 14:08:24.812834 2026] [security2:error] [pid 1004636:tid 1004780] [remote 57.141.0.66:29686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3390535976/feed/rss2/"] [unique_id "amuhKO_uyupB2NyFtxKTVAAAP1k"]
[Thu Jul 30 14:08:24.913806 2026] [security2:error] [pid 1004636:tid 1004944] [client 103.190.40.154:20882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhKO_uyupB2NyFtxKTWQAAAHQ"]
[Thu Jul 30 14:08:24.913998 2026] [security2:error] [pid 1004636:tid 1004944] [client 103.190.40.154:20882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhKO_uyupB2NyFtxKTWQAAAHQ"]
[Thu Jul 30 14:08:25.233119 2026] [security2:error] [pid 1004636:tid 1004697] [remote 57.141.0.67:26018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuhKe_uyupB2NyFtxKTYwAAJQk"]
[Thu Jul 30 14:08:25.256830 2026] [autoindex:error] [pid 1004636:tid 1004843] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:25.403775 2026] [security2:error] [pid 1004636:tid 1004707] [remote 57.141.0.43:23840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuhKe_uyupB2NyFtxKTagAAShM"]
[Thu Jul 30 14:08:25.499646 2026] [security2:error] [pid 1004636:tid 1004692] [remote 57.141.0.18:57522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55089810635/feed/rss2/"] [unique_id "amuhKe_uyupB2NyFtxKTcQAABwU"]
[Thu Jul 30 14:08:25.631176 2026] [security2:error] [pid 1004636:tid 1004892] [client 191.232.199.39:4817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/asd.php"] [unique_id "amuhKe_uyupB2NyFtxKTdgAAAEM"]
[Thu Jul 30 14:08:25.905039 2026] [security2:error] [pid 1004636:tid 1004910] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhKe_uyupB2NyFtxKTZwAAVA0"]
[Thu Jul 30 14:08:25.909388 2026] [security2:error] [pid 1004636:tid 1004899] [client 4.248.40.85:63867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/plugins/inputs.php"] [unique_id "amuhKe_uyupB2NyFtxKTewAAAEk"]
[Thu Jul 30 14:08:25.932284 2026] [security2:error] [pid 1004636:tid 1004875] [client 4.248.40.85:63868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-includes/Requests/Auth/index.php"] [unique_id "amuhKe_uyupB2NyFtxKTfgAAADM"]
[Thu Jul 30 14:08:26.448806 2026] [security2:error] [pid 1004636:tid 1004895] [client 4.248.40.85:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp.php"] [unique_id "amuhKu_uyupB2NyFtxKTjAAAAEU"]
[Thu Jul 30 14:08:27.058456 2026] [security2:error] [pid 1004636:tid 1004847] [client 191.232.199.39:4394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuhK-_uyupB2NyFtxKTmwAAABg"]
[Thu Jul 30 14:08:27.137970 2026] [security2:error] [pid 1004636:tid 1004822] [client 189.6.88.213:63016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhK-_uyupB2NyFtxKTowAAAAA"]
[Thu Jul 30 14:08:27.138084 2026] [security2:error] [pid 1004636:tid 1004822] [client 189.6.88.213:63016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhK-_uyupB2NyFtxKTowAAAAA"]
[Thu Jul 30 14:08:27.510946 2026] [security2:error] [pid 1004636:tid 1004827] [client 4.248.40.85:64569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-admin/css/colors/index.php"] [unique_id "amuhK-_uyupB2NyFtxKTqQAAAAU"]
[Thu Jul 30 14:08:27.525169 2026] [security2:error] [pid 1004636:tid 1004955] [client 4.248.40.85:64546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/themes/inputs.php"] [unique_id "amuhK-_uyupB2NyFtxKTqgAAAH8"]
[Thu Jul 30 14:08:27.640626 2026] [security2:error] [pid 1004636:tid 1004831] [client 74.7.230.24:34296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shorewooddaycare.com"] [uri "/robots.txt"] [unique_id "amuhK-_uyupB2NyFtxKTsQAACT8"]
[Thu Jul 30 14:08:27.838219 2026] [security2:error] [pid 1004636:tid 1004744] [remote 74.7.227.39:46210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuhK-_uyupB2NyFtxKTtQAAaTc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementskit-lite
[Thu Jul 30 14:08:28.600142 2026] [core:notice] [pid 1004636:tid 1004717] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:28.854474 2026] [core:notice] [pid 1004636:tid 1004851] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:28.912381 2026] [security2:error] [pid 1004636:tid 1004852] [client 181.116.200.68:36030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhLO_uyupB2NyFtxKT4QAAAB0"]
[Thu Jul 30 14:08:28.912507 2026] [security2:error] [pid 1004636:tid 1004852] [client 181.116.200.68:36030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhLO_uyupB2NyFtxKT4QAAAB0"]
[Thu Jul 30 14:08:28.950991 2026] [security2:error] [pid 1004636:tid 1004896] [client 191.232.199.39:4390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuhLO_uyupB2NyFtxKT4gAAAEY"]
[Thu Jul 30 14:08:29.004638 2026] [security2:error] [pid 1004636:tid 1004949] [client 185.200.116.211:39774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuhLe_uyupB2NyFtxKT5AAAAHk"]
[Thu Jul 30 14:08:29.004762 2026] [security2:error] [pid 1004636:tid 1004949] [client 185.200.116.211:39774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuhLe_uyupB2NyFtxKT5AAAAHk"]
[Thu Jul 30 14:08:29.314065 2026] [core:notice] [pid 1004636:tid 1004854] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:29.413715 2026] [security2:error] [pid 1004636:tid 1004850] [client 4.248.40.85:49472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/languages/index.php"] [unique_id "amuhLe_uyupB2NyFtxKT9AAAABs"]
[Thu Jul 30 14:08:29.439195 2026] [security2:error] [pid 1004636:tid 1004955] [client 4.248.40.85:49475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/userfuns.php"] [unique_id "amuhLe_uyupB2NyFtxKT9gAAAH8"]
[Thu Jul 30 14:08:29.722864 2026] [security2:error] [pid 1004636:tid 1004716] [remote 57.141.0.51:59516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuhLe_uyupB2NyFtxKT_wAAJBs"]
[Thu Jul 30 14:08:30.086830 2026] [security2:error] [pid 1004636:tid 1004884] [client 47.128.121.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuhLe_uyupB2NyFtxKUCAAAADs"]
[Thu Jul 30 14:08:30.201172 2026] [security2:error] [pid 1004636:tid 1004900] [client 191.232.199.39:4816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/atomlib.php"] [unique_id "amuhLu_uyupB2NyFtxKUEQAAAEo"]
[Thu Jul 30 14:08:30.303206 2026] [security2:error] [pid 1004636:tid 1004768] [remote 57.141.0.50:22390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/589953950/feed/rss2/"] [unique_id "amuhLu_uyupB2NyFtxKUFwAAK00"]
[Thu Jul 30 14:08:30.649951 2026] [security2:error] [pid 1004636:tid 1004891] [client 114.119.158.138:62319] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuhLu_uyupB2NyFtxKUGgAAAEI"], referer: http://www.alseermarine.com/robots.txt
[Thu Jul 30 14:08:30.811011 2026] [security2:error] [pid 1004636:tid 1004927] [client 4.248.40.85:50242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuhLu_uyupB2NyFtxKUJAAAAGQ"]
[Thu Jul 30 14:08:30.839871 2026] [security2:error] [pid 1004636:tid 1004849] [client 4.248.40.85:50258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/plugins/userfuns.php"] [unique_id "amuhLu_uyupB2NyFtxKUJwAAABo"]
[Thu Jul 30 14:08:30.917680 2026] [fcgid:warn] [pid 1004636:tid 1004836] (70014)End of file found: [client 172.71.118.238:12898] mod_fcgid: can't get data from http client
[Thu Jul 30 14:08:31.164558 2026] [fcgid:warn] [pid 1004636:tid 1004928] (70014)End of file found: [client 172.71.118.238:12899] mod_fcgid: can't get data from http client
[Thu Jul 30 14:08:31.404968 2026] [fcgid:warn] [pid 1004636:tid 1004827] (70014)End of file found: [client 172.71.118.238:12900] mod_fcgid: can't get data from http client
[Thu Jul 30 14:08:31.448154 2026] [core:notice] [pid 1004636:tid 1004772] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:31.800796 2026] [fcgid:warn] [pid 1004636:tid 1004914] (70014)End of file found: [client 172.71.118.238:11723] mod_fcgid: can't get data from http client
[Thu Jul 30 14:08:31.893841 2026] [security2:error] [pid 1004636:tid 1004939] [client 4.248.40.85:50936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/IXR/index.php"] [unique_id "amuhL-_uyupB2NyFtxKURwAAAG8"]
[Thu Jul 30 14:08:31.952346 2026] [security2:error] [pid 1004636:tid 1004901] [client 4.248.40.85:50951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/themes/userfuns.php"] [unique_id "amuhL-_uyupB2NyFtxKUSwAAAEs"]
[Thu Jul 30 14:08:32.339258 2026] [autoindex:error] [pid 1004636:tid 1004798] [remote 85.17.145.101:40820] AH01276: Cannot serve directory /home2/nxtudite/public_html/riisesolution.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:32.478947 2026] [core:notice] [pid 1004636:tid 1004794] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:32.533437 2026] [security2:error] [pid 1004636:tid 1004863] [client 4.248.40.85:51209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-admin/css/about.php"] [unique_id "amuhMO_uyupB2NyFtxKUYAAAACc"]
[Thu Jul 30 14:08:32.628433 2026] [security2:error] [pid 1004636:tid 1004826] [client 172.237.109.114:5655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuhMO_uyupB2NyFtxKUUAAAAAQ"]
[Thu Jul 30 14:08:33.061134 2026] [security2:error] [pid 1004636:tid 1004847] [client 4.248.40.85:51471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-content/themes/about.php"] [unique_id "amuhMe_uyupB2NyFtxKUcwAAABg"]
[Thu Jul 30 14:08:33.198225 2026] [security2:error] [pid 1004636:tid 1004866] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/en.orig"] [unique_id "amuhMe_uyupB2NyFtxKUdwAAACo"]
[Thu Jul 30 14:08:33.220486 2026] [security2:error] [pid 1004636:tid 1004944] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuhMe_uyupB2NyFtxKUdQAAAHQ"]
[Thu Jul 30 14:08:33.487994 2026] [autoindex:error] [pid 1004636:tid 1004909] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:33.926420 2026] [autoindex:error] [pid 1004636:tid 1004881] [client 191.232.199.39:38649] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:33.940363 2026] [security2:error] [pid 1004636:tid 1004838] [client 4.248.40.85:51745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.40.248.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "google-search.org"] [uri "/wp-login.php"] [unique_id "amuhMe_uyupB2NyFtxKUiwAAAA8"]
[Thu Jul 30 14:08:34.301263 2026] [security2:error] [pid 1004636:tid 1004934] [client 191.232.199.39:38649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuhMu_uyupB2NyFtxKUogAAAGs"]
[Thu Jul 30 14:08:34.583690 2026] [security2:error] [pid 1004636:tid 1004848] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/o.php"] [unique_id "amuhMu_uyupB2NyFtxKUrwAAABk"]
[Thu Jul 30 14:08:34.822637 2026] [security2:error] [pid 1004636:tid 1004849] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/o.php%2f"] [unique_id "amuhMu_uyupB2NyFtxKUtQAAABo"]
[Thu Jul 30 14:08:35.062418 2026] [security2:error] [pid 1004636:tid 1004859] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/o.php..."] [unique_id "amuhM-_uyupB2NyFtxKUwAAAACM"]
[Thu Jul 30 14:08:35.303546 2026] [security2:error] [pid 1004636:tid 1004920] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/o.php.swp"] [unique_id "amuhM-_uyupB2NyFtxKUxAAAAF4"]
[Thu Jul 30 14:08:35.753856 2026] [security2:error] [pid 1004636:tid 1004909] [client 103.190.40.154:8394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhM-_uyupB2NyFtxKU1wAAAFM"]
[Thu Jul 30 14:08:35.753971 2026] [security2:error] [pid 1004636:tid 1004909] [client 103.190.40.154:8394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhM-_uyupB2NyFtxKU1wAAAFM"]
[Thu Jul 30 14:08:35.925741 2026] [autoindex:error] [pid 1004636:tid 1004871] [client 191.232.199.39:38635] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:36.295714 2026] [autoindex:error] [pid 1004636:tid 1004898] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/blocks/block/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:36.701866 2026] [autoindex:error] [pid 1004636:tid 1004902] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:37.047302 2026] [core:notice] [pid 1004636:tid 1004930] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:37.047527 2026] [security2:error] [pid 1004636:tid 1004951] [client 191.232.199.39:38635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/inputs.php"] [unique_id "amuhNe_uyupB2NyFtxKVEAAAAHs"]
[Thu Jul 30 14:08:37.337714 2026] [security2:error] [pid 1004636:tid 1004914] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhNO_uyupB2NyFtxKVAgAAWBo"]
[Thu Jul 30 14:08:37.832847 2026] [security2:error] [pid 1004636:tid 1004862] [client 189.6.88.213:63566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhNe_uyupB2NyFtxKVKgAAACY"]
[Thu Jul 30 14:08:37.832969 2026] [security2:error] [pid 1004636:tid 1004862] [client 189.6.88.213:63566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhNe_uyupB2NyFtxKVKgAAACY"]
[Thu Jul 30 14:08:38.366056 2026] [security2:error] [pid 1004636:tid 1004841] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/app.swp"] [unique_id "amuhNu_uyupB2NyFtxKVPAAAABI"]
[Thu Jul 30 14:08:38.771169 2026] [security2:error] [pid 1004636:tid 1004864] [client 191.232.199.39:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/index.php"] [unique_id "amuhNu_uyupB2NyFtxKVSwAAACg"]
[Thu Jul 30 14:08:38.864489 2026] [security2:error] [pid 1004636:tid 1004897] [client 66.249.76.65:55206] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "abudhabifurnituremoverspackers.com"] [uri "/robots.txt"] [unique_id "amuhNu_uyupB2NyFtxKVTwAAAEc"]
[Thu Jul 30 14:08:39.479459 2026] [security2:error] [pid 1004636:tid 1004916] [client 181.116.200.68:47337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhN-_uyupB2NyFtxKVYgAAAFo"]
[Thu Jul 30 14:08:39.479581 2026] [security2:error] [pid 1004636:tid 1004916] [client 181.116.200.68:47337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhN-_uyupB2NyFtxKVYgAAAFo"]
[Thu Jul 30 14:08:39.517984 2026] [security2:error] [pid 1004636:tid 1004915] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htpasswd"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.terraform.htpasswd"] [unique_id "amuhN-_uyupB2NyFtxKVYwAAAFk"]
[Thu Jul 30 14:08:40.113834 2026] [security2:error] [pid 1004636:tid 1004762] [remote 57.141.18.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuhOO_uyupB2NyFtxKViQAAF0c"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,lycra,plastic,steel,wood,nylon&filter_size=extra-extra-large,extra-large,small&orderby=rating&status=sale&tax_product_cat=suit&unfilter=1
[Thu Jul 30 14:08:40.135454 2026] [security2:error] [pid 1004636:tid 1004892] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuhOO_uyupB2NyFtxKViwAAAEM"]
[Thu Jul 30 14:08:40.135542 2026] [security2:error] [pid 1004636:tid 1004892] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuhOO_uyupB2NyFtxKViwAAAEM"]
[Thu Jul 30 14:08:40.154207 2026] [security2:error] [pid 1004636:tid 1004948] [client 191.232.199.39:4199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuhOO_uyupB2NyFtxKVjQAAAHg"]
[Thu Jul 30 14:08:40.157646 2026] [security2:error] [pid 1004636:tid 1004880] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/log.txt~"] [unique_id "amuhOO_uyupB2NyFtxKVjgAAADg"]
[Thu Jul 30 14:08:40.283173 2026] [security2:error] [pid 1004636:tid 1004889] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/log.txt.bak"] [unique_id "amuhOO_uyupB2NyFtxKVkwAAAEA"]
[Thu Jul 30 14:08:40.395166 2026] [security2:error] [pid 1004636:tid 1004774] [remote 57.141.0.11:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amuhOO_uyupB2NyFtxKVmgAAIVM"]
[Thu Jul 30 14:08:40.414956 2026] [security2:error] [pid 1004636:tid 1004823] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuhOO_uyupB2NyFtxKVnAAAAAE"]
[Thu Jul 30 14:08:40.415061 2026] [security2:error] [pid 1004636:tid 1004823] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuhOO_uyupB2NyFtxKVnAAAAAE"]
[Thu Jul 30 14:08:40.591840 2026] [security2:error] [pid 1004636:tid 1004792] [remote 57.141.18.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuhOO_uyupB2NyFtxKVogAAT2U"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,lycra,plastic,steel,wood,nylon&filter_size=extra-extra-large,extra-large,small&orderby=rating&status=sale&tax_product_cat=suit&unfilter=1
[Thu Jul 30 14:08:40.602397 2026] [security2:error] [pid 1004636:tid 1004941] [client 31.59.20.243:50009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuhOO_uyupB2NyFtxKVkQAAAHE"], referer: https://cnpinyin.com/login/?redirect_to=https%3A%2F%2Fcnpinyin.com
[Thu Jul 30 14:08:40.709926 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/x.php"] [unique_id "amuhOO_uyupB2NyFtxKVpwAAACg"]
[Thu Jul 30 14:08:40.710056 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/x.php"] [unique_id "amuhOO_uyupB2NyFtxKVpwAAACg"]
[Thu Jul 30 14:08:40.799513 2026] [security2:error] [pid 1004636:tid 1004921] [client 20.215.191.139:55830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/011i.php"] [unique_id "amuhOO_uyupB2NyFtxKVrAAAAF8"]
[Thu Jul 30 14:08:40.922665 2026] [security2:error] [pid 1004636:tid 1004876] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhOO_uyupB2NyFtxKVlQAANFI"]
[Thu Jul 30 14:08:40.987248 2026] [security2:error] [pid 1004636:tid 1004847] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/mgrr.php"] [unique_id "amuhOO_uyupB2NyFtxKVsQAAABg"]
[Thu Jul 30 14:08:40.987378 2026] [security2:error] [pid 1004636:tid 1004847] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/mgrr.php"] [unique_id "amuhOO_uyupB2NyFtxKVsQAAABg"]
[Thu Jul 30 14:08:41.273310 2026] [security2:error] [pid 1004636:tid 1004920] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/domvf.php"] [unique_id "amuhOe_uyupB2NyFtxKVugAAAF4"]
[Thu Jul 30 14:08:41.273516 2026] [security2:error] [pid 1004636:tid 1004920] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/domvf.php"] [unique_id "amuhOe_uyupB2NyFtxKVugAAAF4"]
[Thu Jul 30 14:08:41.426939 2026] [security2:error] [pid 1004636:tid 1004883] [client 191.232.199.39:51880] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/1.php"] [unique_id "amuhOe_uyupB2NyFtxKVxgAAADo"]
[Thu Jul 30 14:08:41.427081 2026] [security2:error] [pid 1004636:tid 1004883] [client 191.232.199.39:51880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/1.php"] [unique_id "amuhOe_uyupB2NyFtxKVxgAAADo"]
[Thu Jul 30 14:08:41.559229 2026] [security2:error] [pid 1004636:tid 1004904] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/yup.php"] [unique_id "amuhOe_uyupB2NyFtxKVyQAAAE4"]
[Thu Jul 30 14:08:41.559360 2026] [security2:error] [pid 1004636:tid 1004904] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/yup.php"] [unique_id "amuhOe_uyupB2NyFtxKVyQAAAE4"]
[Thu Jul 30 14:08:41.649804 2026] [security2:error] [pid 1004636:tid 1004888] [client 20.215.191.139:55831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/03a005685d.php"] [unique_id "amuhOe_uyupB2NyFtxKVzAAAAD8"]
[Thu Jul 30 14:08:41.839960 2026] [security2:error] [pid 1004636:tid 1004910] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/X.php"] [unique_id "amuhOe_uyupB2NyFtxKV1QAAAFQ"]
[Thu Jul 30 14:08:41.840115 2026] [security2:error] [pid 1004636:tid 1004910] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/X.php"] [unique_id "amuhOe_uyupB2NyFtxKV1QAAAFQ"]
[Thu Jul 30 14:08:42.109704 2026] [security2:error] [pid 1004636:tid 1004857] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuhOu_uyupB2NyFtxKV4QAAACE"]
[Thu Jul 30 14:08:42.109823 2026] [security2:error] [pid 1004636:tid 1004857] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuhOu_uyupB2NyFtxKV4QAAACE"]
[Thu Jul 30 14:08:42.378297 2026] [security2:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/gec.php"] [unique_id "amuhOu_uyupB2NyFtxKV6wAAAAo"]
[Thu Jul 30 14:08:42.378408 2026] [security2:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/gec.php"] [unique_id "amuhOu_uyupB2NyFtxKV6wAAAAo"]
[Thu Jul 30 14:08:42.661508 2026] [security2:error] [pid 1004636:tid 1004872] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/sky.php"] [unique_id "amuhOu_uyupB2NyFtxKV9wAAADA"]
[Thu Jul 30 14:08:42.661611 2026] [security2:error] [pid 1004636:tid 1004872] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/sky.php"] [unique_id "amuhOu_uyupB2NyFtxKV9wAAADA"]
[Thu Jul 30 14:08:42.826574 2026] [security2:error] [pid 1004636:tid 1004865] [client 129.227.44.38:60083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ncg.udi.temporary.site"] [uri "/wp-login.php"] [unique_id "amuhOu_uyupB2NyFtxKV5gAAACk"]
[Thu Jul 30 14:08:42.957859 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/fffm.php"] [unique_id "amuhOu_uyupB2NyFtxKWCAAAABQ"]
[Thu Jul 30 14:08:42.958004 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/fffm.php"] [unique_id "amuhOu_uyupB2NyFtxKWCAAAABQ"]
[Thu Jul 30 14:08:43.093044 2026] [security2:error] [pid 1004636:tid 1004836] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuhOu_uyupB2NyFtxKV-gAAAA4"]
[Thu Jul 30 14:08:43.227599 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/sixxis.php"] [unique_id "amuhO-_uyupB2NyFtxKWFAAAABc"]
[Thu Jul 30 14:08:43.227766 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/sixxis.php"] [unique_id "amuhO-_uyupB2NyFtxKWFAAAABc"]
[Thu Jul 30 14:08:43.309318 2026] [security2:error] [pid 1004636:tid 1004927] [client 191.232.199.39:4188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/plugin.php"] [unique_id "amuhO-_uyupB2NyFtxKWFgAAAGQ"]
[Thu Jul 30 14:08:43.314879 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.215.191.139:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/403.php"] [unique_id "amuhO-_uyupB2NyFtxKWGAAAAAk"]
[Thu Jul 30 14:08:43.469321 2026] [security2:error] [pid 1004636:tid 1004940] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhOu_uyupB2NyFtxKV_gAAcHI"]
[Thu Jul 30 14:08:43.508697 2026] [security2:error] [pid 1004636:tid 1004880] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/yj09.php"] [unique_id "amuhO-_uyupB2NyFtxKWHgAAADg"]
[Thu Jul 30 14:08:43.508798 2026] [security2:error] [pid 1004636:tid 1004880] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/yj09.php"] [unique_id "amuhO-_uyupB2NyFtxKWHgAAADg"]
[Thu Jul 30 14:08:43.636050 2026] [security2:error] [pid 1004636:tid 1004863] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/nodeapi%00"] [unique_id "amuhO-_uyupB2NyFtxKWJQAAACc"]
[Thu Jul 30 14:08:43.760868 2026] [security2:error] [pid 1004636:tid 1004919] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amuhO-_uyupB2NyFtxKWLAAAAF0"]
[Thu Jul 30 14:08:43.786433 2026] [security2:error] [pid 1004636:tid 1004823] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/k.php"] [unique_id "amuhO-_uyupB2NyFtxKWLQAAAAE"]
[Thu Jul 30 14:08:43.786529 2026] [security2:error] [pid 1004636:tid 1004823] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/k.php"] [unique_id "amuhO-_uyupB2NyFtxKWLQAAAAE"]
[Thu Jul 30 14:08:43.885224 2026] [security2:error] [pid 1004636:tid 1004900] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amuhO-_uyupB2NyFtxKWMAAAAEo"]
[Thu Jul 30 14:08:44.010390 2026] [security2:error] [pid 1004636:tid 1004869] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amuhPO_uyupB2NyFtxKWMwAAAC0"]
[Thu Jul 30 14:08:44.063845 2026] [security2:error] [pid 1004636:tid 1004938] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/k2.php"] [unique_id "amuhPO_uyupB2NyFtxKWNQAAAG4"]
[Thu Jul 30 14:08:44.063948 2026] [security2:error] [pid 1004636:tid 1004938] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/k2.php"] [unique_id "amuhPO_uyupB2NyFtxKWNQAAAG4"]
[Thu Jul 30 14:08:44.137214 2026] [security2:error] [pid 1004636:tid 1004949] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/.env"] [unique_id "amuhPO_uyupB2NyFtxKWOAAAAHk"]
[Thu Jul 30 14:08:44.211143 2026] [security2:error] [pid 1004636:tid 1004892] [client 31.59.20.243:49831] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuhO-_uyupB2NyFtxKWJwAAAEM"], referer: https://cnpinyin.com/%e5%a5%87%e6%80%aa%e7%9a%84%e4%b8%ad%e8%8d%af%e8%8d%af%e9%85%92strange-brew/
[Thu Jul 30 14:08:44.327011 2026] [security2:error] [pid 1004636:tid 1004892] [client 31.59.20.243:49831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuhO-_uyupB2NyFtxKWJwAAAEM"], referer: https://cnpinyin.com/%e5%a5%87%e6%80%aa%e7%9a%84%e4%b8%ad%e8%8d%af%e8%8d%af%e9%85%92strange-brew/
[Thu Jul 30 14:08:44.327083 2026] [security2:error] [pid 1004636:tid 1004892] [client 31.59.20.243:49831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/wp-comments-post.php"] [unique_id "amuhO-_uyupB2NyFtxKWJwAAAEM"], referer: https://cnpinyin.com/%e5%a5%87%e6%80%aa%e7%9a%84%e4%b8%ad%e8%8d%af%e8%8d%af%e9%85%92strange-brew/
[Thu Jul 30 14:08:44.336507 2026] [security2:error] [pid 1004636:tid 1004920] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/w.php"] [unique_id "amuhPO_uyupB2NyFtxKWQgAAAF4"]
[Thu Jul 30 14:08:44.336668 2026] [security2:error] [pid 1004636:tid 1004920] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/w.php"] [unique_id "amuhPO_uyupB2NyFtxKWQgAAAF4"]
[Thu Jul 30 14:08:44.609071 2026] [security2:error] [pid 1004636:tid 1004944] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/fpwch.php"] [unique_id "amuhPO_uyupB2NyFtxKWTQAAAHQ"]
[Thu Jul 30 14:08:44.609190 2026] [security2:error] [pid 1004636:tid 1004944] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/fpwch.php"] [unique_id "amuhPO_uyupB2NyFtxKWTQAAAHQ"]
[Thu Jul 30 14:08:44.673877 2026] [security2:error] [pid 1004636:tid 1004847] [client 191.232.199.39:38653] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ghggeneralcontracting.com"] [uri "/1.php"] [unique_id "amuhPO_uyupB2NyFtxKWTwAAABg"]
[Thu Jul 30 14:08:44.674015 2026] [security2:error] [pid 1004636:tid 1004847] [client 191.232.199.39:38653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/1.php"] [unique_id "amuhPO_uyupB2NyFtxKWTwAAABg"]
[Thu Jul 30 14:08:44.892002 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/w2025.php"] [unique_id "amuhPO_uyupB2NyFtxKWXQAAABc"]
[Thu Jul 30 14:08:44.892113 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/w2025.php"] [unique_id "amuhPO_uyupB2NyFtxKWXQAAABc"]
[Thu Jul 30 14:08:45.072774 2026] [security2:error] [pid 1004636:tid 1004844] [client 144.172.114.51:36012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuhPe_uyupB2NyFtxKWYwAAABU"]
[Thu Jul 30 14:08:45.140582 2026] [security2:error] [pid 1004636:tid 1004940] [client 129.227.44.38:60087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.ncg.udi.temporary.site"] [uri "/wp-login.php"] [unique_id "amuhPe_uyupB2NyFtxKWZQAAAHA"]
[Thu Jul 30 14:08:45.167792 2026] [security2:error] [pid 1004636:tid 1004886] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/FWAZ.php"] [unique_id "amuhPe_uyupB2NyFtxKWaQAAAD0"]
[Thu Jul 30 14:08:45.167880 2026] [security2:error] [pid 1004636:tid 1004886] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/FWAZ.php"] [unique_id "amuhPe_uyupB2NyFtxKWaQAAAD0"]
[Thu Jul 30 14:08:45.345082 2026] [security2:error] [pid 1004636:tid 1004832] [client 20.215.191.139:50090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/404.php"] [unique_id "amuhPe_uyupB2NyFtxKWbwAAAAo"]
[Thu Jul 30 14:08:45.445546 2026] [security2:error] [pid 1004636:tid 1004941] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/qterm.php"] [unique_id "amuhPe_uyupB2NyFtxKWcQAAAHE"]
[Thu Jul 30 14:08:45.445646 2026] [security2:error] [pid 1004636:tid 1004941] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/qterm.php"] [unique_id "amuhPe_uyupB2NyFtxKWcQAAAHE"]
[Thu Jul 30 14:08:45.715558 2026] [security2:error] [pid 1004636:tid 1004826] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/blurbs.php"] [unique_id "amuhPe_uyupB2NyFtxKWegAAAAQ"]
[Thu Jul 30 14:08:45.715665 2026] [security2:error] [pid 1004636:tid 1004826] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/blurbs.php"] [unique_id "amuhPe_uyupB2NyFtxKWegAAAAQ"]
[Thu Jul 30 14:08:45.987687 2026] [security2:error] [pid 1004636:tid 1004920] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-ws68.php"] [unique_id "amuhPe_uyupB2NyFtxKWgQAAAF4"]
[Thu Jul 30 14:08:45.987839 2026] [security2:error] [pid 1004636:tid 1004920] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-ws68.php"] [unique_id "amuhPe_uyupB2NyFtxKWgQAAAF4"]
[Thu Jul 30 14:08:46.105107 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.215.191.139:58123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/aa.php"] [unique_id "amuhPu_uyupB2NyFtxKWhgAAADQ"]
[Thu Jul 30 14:08:46.209197 2026] [security2:error] [pid 1004636:tid 1004864] [client 191.232.199.39:38636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/gg.php"] [unique_id "amuhPu_uyupB2NyFtxKWjgAAACg"]
[Thu Jul 30 14:08:46.270323 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xyn.php"] [unique_id "amuhPu_uyupB2NyFtxKWjwAAABQ"]
[Thu Jul 30 14:08:46.270424 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xyn.php"] [unique_id "amuhPu_uyupB2NyFtxKWjwAAABQ"]
[Thu Jul 30 14:08:46.560851 2026] [security2:error] [pid 1004636:tid 1004945] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ccc.php"] [unique_id "amuhPu_uyupB2NyFtxKWnQAAAHU"]
[Thu Jul 30 14:08:46.560957 2026] [security2:error] [pid 1004636:tid 1004945] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ccc.php"] [unique_id "amuhPu_uyupB2NyFtxKWnQAAAHU"]
[Thu Jul 30 14:08:46.597091 2026] [security2:error] [pid 1004636:tid 1004925] [client 103.190.40.154:20860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhPu_uyupB2NyFtxKWngAAAGI"]
[Thu Jul 30 14:08:46.597230 2026] [security2:error] [pid 1004636:tid 1004925] [client 103.190.40.154:20860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhPu_uyupB2NyFtxKWngAAAGI"]
[Thu Jul 30 14:08:46.741417 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.215.191.139:50153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/aafewc0k.php"] [unique_id "amuhPu_uyupB2NyFtxKWpQAAAAc"]
[Thu Jul 30 14:08:46.830273 2026] [security2:error] [pid 1004636:tid 1004948] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/get.php"] [unique_id "amuhPu_uyupB2NyFtxKWqQAAAHg"]
[Thu Jul 30 14:08:46.830380 2026] [security2:error] [pid 1004636:tid 1004948] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/get.php"] [unique_id "amuhPu_uyupB2NyFtxKWqQAAAHg"]
[Thu Jul 30 14:08:47.108703 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/images.php"] [unique_id "amuhP-_uyupB2NyFtxKWswAAAGs"]
[Thu Jul 30 14:08:47.108821 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/images.php"] [unique_id "amuhP-_uyupB2NyFtxKWswAAAGs"]
[Thu Jul 30 14:08:47.132058 2026] [security2:error] [pid 1004636:tid 1004870] [client 52.167.144.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuhPu_uyupB2NyFtxKWqAAAAC4"]
[Thu Jul 30 14:08:47.405826 2026] [security2:error] [pid 1004636:tid 1004942] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/alls.php"] [unique_id "amuhP-_uyupB2NyFtxKWwgAAAHI"]
[Thu Jul 30 14:08:47.405928 2026] [security2:error] [pid 1004636:tid 1004942] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/alls.php"] [unique_id "amuhP-_uyupB2NyFtxKWwgAAAHI"]
[Thu Jul 30 14:08:47.464609 2026] [security2:error] [pid 1004636:tid 1004822] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhPu_uyupB2NyFtxKWrAAAAFs"]
[Thu Jul 30 14:08:47.533021 2026] [autoindex:error] [pid 1004636:tid 1004911] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/images/crystal/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:47.684296 2026] [security2:error] [pid 1004636:tid 1004876] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/coffexium.php"] [unique_id "amuhP-_uyupB2NyFtxKWzwAAADQ"]
[Thu Jul 30 14:08:47.684393 2026] [security2:error] [pid 1004636:tid 1004876] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/coffexium.php"] [unique_id "amuhP-_uyupB2NyFtxKWzwAAADQ"]
[Thu Jul 30 14:08:47.876061 2026] [security2:error] [pid 1004636:tid 1004855] [client 191.232.199.39:51862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp.php"] [unique_id "amuhP-_uyupB2NyFtxKW3QAAAB8"]
[Thu Jul 30 14:08:47.954252 2026] [security2:error] [pid 1004636:tid 1004909] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/red.php"] [unique_id "amuhP-_uyupB2NyFtxKW4gAAAFM"]
[Thu Jul 30 14:08:47.954341 2026] [security2:error] [pid 1004636:tid 1004909] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/red.php"] [unique_id "amuhP-_uyupB2NyFtxKW4gAAAFM"]
[Thu Jul 30 14:08:48.015991 2026] [security2:error] [pid 1004636:tid 1004843] [client 52.167.144.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuhP-_uyupB2NyFtxKW2AAAABQ"]
[Thu Jul 30 14:08:48.018911 2026] [security2:error] [pid 1004636:tid 1004841] [client 20.215.191.139:50236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/abcd.php"] [unique_id "amuhQO_uyupB2NyFtxKW6AAAABI"]
[Thu Jul 30 14:08:48.116543 2026] [security2:error] [pid 1004636:tid 1004847] [client 52.167.144.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuhP-_uyupB2NyFtxKW3AAAABg"]
[Thu Jul 30 14:08:48.262245 2026] [autoindex:error] [pid 1004636:tid 1004863] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:48.263036 2026] [security2:error] [pid 1004636:tid 1004863] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhQO_uyupB2NyFtxKW8gAAACc"]
[Thu Jul 30 14:08:48.330704 2026] [security2:error] [pid 1004636:tid 1004858] [client 129.227.44.38:61083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ncg.udi.temporary.site"] [uri "/wp-login.php"] [unique_id "amuhQO_uyupB2NyFtxKW8wAAACI"]
[Thu Jul 30 14:08:48.412380 2026] [security2:error] [pid 1004636:tid 1004926] [client 74.7.175.136:33040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuhP-_uyupB2NyFtxKW4wAAYzc"]
[Thu Jul 30 14:08:48.413702 2026] [security2:error] [pid 1004636:tid 1004923] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuhQO_uyupB2NyFtxKW_gAAAGA"]
[Thu Jul 30 14:08:48.413817 2026] [security2:error] [pid 1004636:tid 1004923] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuhQO_uyupB2NyFtxKW_gAAAGA"]
[Thu Jul 30 14:08:48.442690 2026] [security2:error] [pid 1004636:tid 1004899] [client 74.7.229.101:43860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuhQO_uyupB2NyFtxKW6gAASRg"]
[Thu Jul 30 14:08:48.517080 2026] [security2:error] [pid 1004636:tid 1004889] [client 52.167.144.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuhQO_uyupB2NyFtxKW8QAAAEA"]
[Thu Jul 30 14:08:48.537005 2026] [security2:error] [pid 1004636:tid 1004875] [client 189.6.88.213:64113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhQO_uyupB2NyFtxKXBAAAADM"]
[Thu Jul 30 14:08:48.537128 2026] [security2:error] [pid 1004636:tid 1004875] [client 189.6.88.213:64113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhQO_uyupB2NyFtxKXBAAAADM"]
[Thu Jul 30 14:08:48.719290 2026] [autoindex:error] [pid 1004636:tid 1004861] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:48.720033 2026] [security2:error] [pid 1004636:tid 1004861] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhQO_uyupB2NyFtxKXDQAAACU"]
[Thu Jul 30 14:08:48.879529 2026] [autoindex:error] [pid 1004636:tid 1004952] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:48.880257 2026] [security2:error] [pid 1004636:tid 1004952] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhQO_uyupB2NyFtxKXGwAAAHw"]
[Thu Jul 30 14:08:49.019603 2026] [security2:error] [pid 1004636:tid 1004903] [client 52.167.144.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuhQO_uyupB2NyFtxKXFgAAAE0"]
[Thu Jul 30 14:08:49.025067 2026] [security2:error] [pid 1004636:tid 1004888] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/index.php"] [unique_id "amuhQe_uyupB2NyFtxKXIQAAAD8"]
[Thu Jul 30 14:08:49.025190 2026] [security2:error] [pid 1004636:tid 1004888] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/index.php"] [unique_id "amuhQe_uyupB2NyFtxKXIQAAAD8"]
[Thu Jul 30 14:08:49.057200 2026] [security2:error] [pid 1004636:tid 1004846] [client 185.177.72.5:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/projects.bak"] [unique_id "amuhQe_uyupB2NyFtxKXIgAAABc"]
[Thu Jul 30 14:08:49.136292 2026] [security2:error] [pid 1004636:tid 1004916] [client 191.232.199.39:4200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuhQe_uyupB2NyFtxKXJgAAAFo"]
[Thu Jul 30 14:08:49.231719 2026] [core:notice] [pid 1004636:tid 1004955] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:49.295751 2026] [security2:error] [pid 1004636:tid 1004925] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/admin.php"] [unique_id "amuhQe_uyupB2NyFtxKXLAAAAGI"]
[Thu Jul 30 14:08:49.295835 2026] [security2:error] [pid 1004636:tid 1004925] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/admin.php"] [unique_id "amuhQe_uyupB2NyFtxKXLAAAAGI"]
[Thu Jul 30 14:08:49.371145 2026] [security2:error] [pid 1004636:tid 1004912] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuhQO_uyupB2NyFtxKXEwAAAFY"]
[Thu Jul 30 14:08:49.550986 2026] [security2:error] [pid 1004636:tid 1004849] [client 20.215.191.139:58854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/about.php"] [unique_id "amuhQe_uyupB2NyFtxKXOQAAABo"]
[Thu Jul 30 14:08:49.569593 2026] [security2:error] [pid 1004636:tid 1004867] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/177.php"] [unique_id "amuhQe_uyupB2NyFtxKXOgAAACs"]
[Thu Jul 30 14:08:49.569722 2026] [security2:error] [pid 1004636:tid 1004867] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/177.php"] [unique_id "amuhQe_uyupB2NyFtxKXOgAAACs"]
[Thu Jul 30 14:08:49.848045 2026] [security2:error] [pid 1004636:tid 1004918] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/199.php"] [unique_id "amuhQe_uyupB2NyFtxKXSwAAAFw"]
[Thu Jul 30 14:08:49.848122 2026] [security2:error] [pid 1004636:tid 1004918] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/199.php"] [unique_id "amuhQe_uyupB2NyFtxKXSwAAAFw"]
[Thu Jul 30 14:08:50.122280 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file52.php"] [unique_id "amuhQu_uyupB2NyFtxKXWQAAAAg"]
[Thu Jul 30 14:08:50.122372 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file52.php"] [unique_id "amuhQu_uyupB2NyFtxKXWQAAAAg"]
[Thu Jul 30 14:08:50.188992 2026] [security2:error] [pid 1004636:tid 1004873] [client 181.116.200.68:54152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhQu_uyupB2NyFtxKXWgAAADE"]
[Thu Jul 30 14:08:50.189091 2026] [security2:error] [pid 1004636:tid 1004873] [client 181.116.200.68:54152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhQu_uyupB2NyFtxKXWgAAADE"]
[Thu Jul 30 14:08:50.266132 2026] [security2:error] [pid 1004636:tid 1004914] [client 20.215.191.139:50185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/admin.php"] [unique_id "amuhQu_uyupB2NyFtxKXXAAAAFg"]
[Thu Jul 30 14:08:50.401889 2026] [security2:error] [pid 1004636:tid 1004839] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/geck.php"] [unique_id "amuhQu_uyupB2NyFtxKXYQAAABA"]
[Thu Jul 30 14:08:50.402003 2026] [security2:error] [pid 1004636:tid 1004839] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/geck.php"] [unique_id "amuhQu_uyupB2NyFtxKXYQAAABA"]
[Thu Jul 30 14:08:50.673889 2026] [security2:error] [pid 1004636:tid 1004845] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/biufile.php"] [unique_id "amuhQu_uyupB2NyFtxKXbwAAABY"]
[Thu Jul 30 14:08:50.674004 2026] [security2:error] [pid 1004636:tid 1004845] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/biufile.php"] [unique_id "amuhQu_uyupB2NyFtxKXbwAAABY"]
[Thu Jul 30 14:08:50.702514 2026] [security2:error] [pid 1004636:tid 1004865] [client 191.232.199.39:4207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/file.php"] [unique_id "amuhQu_uyupB2NyFtxKXcAAAACk"]
[Thu Jul 30 14:08:50.895827 2026] [core:error] [pid 1004636:tid 1004851] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:08:50.895847 2026] [core:error] [pid 1004636:tid 1004851] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:08:50.964019 2026] [security2:error] [pid 1004636:tid 1004891] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dejavu.php"] [unique_id "amuhQu_uyupB2NyFtxKXdQAAAEI"]
[Thu Jul 30 14:08:50.964130 2026] [security2:error] [pid 1004636:tid 1004891] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dejavu.php"] [unique_id "amuhQu_uyupB2NyFtxKXdQAAAEI"]
[Thu Jul 30 14:08:51.081191 2026] [security2:error] [pid 1004636:tid 1004889] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhQu_uyupB2NyFtxKXZQAAQCs"]
[Thu Jul 30 14:08:51.150474 2026] [security2:error] [pid 1004636:tid 1004931] [client 20.215.191.139:50093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/adminfuns.php"] [unique_id "amuhQ-_uyupB2NyFtxKXfwAAAGg"]
[Thu Jul 30 14:08:51.248585 2026] [security2:error] [pid 1004636:tid 1004871] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/aaf.php"] [unique_id "amuhQ-_uyupB2NyFtxKXgwAAAC8"]
[Thu Jul 30 14:08:51.248722 2026] [security2:error] [pid 1004636:tid 1004871] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/aaf.php"] [unique_id "amuhQ-_uyupB2NyFtxKXgwAAAC8"]
[Thu Jul 30 14:08:51.448085 2026] [security2:error] [pid 1004636:tid 1004939] [client 216.244.66.233:45366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuhQ-_uyupB2NyFtxKXhgAAAG8"]
[Thu Jul 30 14:08:51.448233 2026] [security2:error] [pid 1004636:tid 1004939] [client 216.244.66.233:45366] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuhQ-_uyupB2NyFtxKXhgAAAG8"]
[Thu Jul 30 14:08:51.521859 2026] [security2:error] [pid 1004636:tid 1004868] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ha.php"] [unique_id "amuhQ-_uyupB2NyFtxKXjAAAACw"]
[Thu Jul 30 14:08:51.522029 2026] [security2:error] [pid 1004636:tid 1004868] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ha.php"] [unique_id "amuhQ-_uyupB2NyFtxKXjAAAACw"]
[Thu Jul 30 14:08:51.794161 2026] [security2:error] [pid 1004636:tid 1004848] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/hur.php"] [unique_id "amuhQ-_uyupB2NyFtxKXlQAAABk"]
[Thu Jul 30 14:08:51.794288 2026] [security2:error] [pid 1004636:tid 1004848] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/hur.php"] [unique_id "amuhQ-_uyupB2NyFtxKXlQAAABk"]
[Thu Jul 30 14:08:51.963249 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.215.191.139:50213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/albin.php"] [unique_id "amuhQ-_uyupB2NyFtxKXlwAAAB0"]
[Thu Jul 30 14:08:52.069139 2026] [security2:error] [pid 1004636:tid 1004917] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/h02ugyh.php"] [unique_id "amuhRO_uyupB2NyFtxKXnAAAAFs"]
[Thu Jul 30 14:08:52.069234 2026] [security2:error] [pid 1004636:tid 1004917] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/h02ugyh.php"] [unique_id "amuhRO_uyupB2NyFtxKXnAAAAFs"]
[Thu Jul 30 14:08:52.356265 2026] [security2:error] [pid 1004636:tid 1004914] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/155.php"] [unique_id "amuhRO_uyupB2NyFtxKXpQAAAFg"]
[Thu Jul 30 14:08:52.356425 2026] [security2:error] [pid 1004636:tid 1004914] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/155.php"] [unique_id "amuhRO_uyupB2NyFtxKXpQAAAFg"]
[Thu Jul 30 14:08:52.615310 2026] [security2:error] [pid 1004636:tid 1004862] [client 20.215.191.139:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/amfsqvgv.php"] [unique_id "amuhRO_uyupB2NyFtxKXrwAAACY"]
[Thu Jul 30 14:08:52.645531 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ops.php"] [unique_id "amuhRO_uyupB2NyFtxKXsAAAABQ"]
[Thu Jul 30 14:08:52.645627 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ops.php"] [unique_id "amuhRO_uyupB2NyFtxKXsAAAABQ"]
[Thu Jul 30 14:08:52.826323 2026] [security2:error] [pid 1004636:tid 1004928] [client 191.232.199.39:38634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuhRO_uyupB2NyFtxKXuAAAAGU"]
[Thu Jul 30 14:08:52.917296 2026] [security2:error] [pid 1004636:tid 1004828] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ingfo.php"] [unique_id "amuhRO_uyupB2NyFtxKXuQAAAAY"]
[Thu Jul 30 14:08:52.917445 2026] [security2:error] [pid 1004636:tid 1004828] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ingfo.php"] [unique_id "amuhRO_uyupB2NyFtxKXuQAAAAY"]
[Thu Jul 30 14:08:53.120294 2026] [proxy:error] [pid 1004636:tid 1004734] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:08:53.120345 2026] [proxy_http:error] [pid 1004636:tid 1004734] [remote 74.7.244.58:38846] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:08:53.120952 2026] [proxy:error] [pid 1004636:tid 1004734] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:08:53.121012 2026] [proxy_http:error] [pid 1004636:tid 1004734] [remote 74.7.244.58:38846] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:08:53.150067 2026] [security2:error] [pid 1004636:tid 1004858] [client 43.165.167.69:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.167.165.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuhRe_uyupB2NyFtxKXwwAAACI"]
[Thu Jul 30 14:08:53.189197 2026] [security2:error] [pid 1004636:tid 1004950] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/error_log.php"] [unique_id "amuhRe_uyupB2NyFtxKXxQAAAHo"]
[Thu Jul 30 14:08:53.189281 2026] [security2:error] [pid 1004636:tid 1004950] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/error_log.php"] [unique_id "amuhRe_uyupB2NyFtxKXxQAAAHo"]
[Thu Jul 30 14:08:53.454077 2026] [security2:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/koala.php"] [unique_id "amuhRe_uyupB2NyFtxKXzQAAAEo"]
[Thu Jul 30 14:08:53.454155 2026] [security2:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/koala.php"] [unique_id "amuhRe_uyupB2NyFtxKXzQAAAEo"]
[Thu Jul 30 14:08:53.734759 2026] [security2:error] [pid 1004636:tid 1004930] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/mac.php"] [unique_id "amuhRe_uyupB2NyFtxKX2gAAAGc"]
[Thu Jul 30 14:08:53.734906 2026] [security2:error] [pid 1004636:tid 1004930] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/mac.php"] [unique_id "amuhRe_uyupB2NyFtxKX2gAAAGc"]
[Thu Jul 30 14:08:54.008651 2026] [security2:error] [pid 1004636:tid 1004944] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wefile.php"] [unique_id "amuhRu_uyupB2NyFtxKX4AAAAHQ"]
[Thu Jul 30 14:08:54.008797 2026] [security2:error] [pid 1004636:tid 1004944] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wefile.php"] [unique_id "amuhRu_uyupB2NyFtxKX4AAAAHQ"]
[Thu Jul 30 14:08:54.112438 2026] [core:notice] [pid 1004636:tid 1004822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:54.296905 2026] [security2:error] [pid 1004636:tid 1004915] [client 20.215.191.139:58825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/ant.php"] [unique_id "amuhRu_uyupB2NyFtxKX8gAAAFk"]
[Thu Jul 30 14:08:54.298999 2026] [autoindex:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:54.299736 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhRu_uyupB2NyFtxKX8QAAABc"]
[Thu Jul 30 14:08:54.494131 2026] [security2:error] [pid 1004636:tid 1004914] [client 191.232.199.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuhRu_uyupB2NyFtxKX7AAAAFg"]
[Thu Jul 30 14:08:54.504589 2026] [autoindex:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:54.505355 2026] [security2:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhRu_uyupB2NyFtxKX8wAAACY"]
[Thu Jul 30 14:08:54.642004 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/makeasmtp.php"] [unique_id "amuhRu_uyupB2NyFtxKX9wAAAH8"]
[Thu Jul 30 14:08:54.642104 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/makeasmtp.php"] [unique_id "amuhRu_uyupB2NyFtxKX9wAAAH8"]
[Thu Jul 30 14:08:54.857014 2026] [security2:error] [pid 1004636:tid 1004943] [client 20.215.191.139:49881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/appreciators.php"] [unique_id "amuhRu_uyupB2NyFtxKX_wAAAHM"]
[Thu Jul 30 14:08:54.910189 2026] [security2:error] [pid 1004636:tid 1004910] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/2P.php"] [unique_id "amuhRu_uyupB2NyFtxKYAAAAAFQ"]
[Thu Jul 30 14:08:54.910326 2026] [security2:error] [pid 1004636:tid 1004910] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/2P.php"] [unique_id "amuhRu_uyupB2NyFtxKYAAAAAFQ"]
[Thu Jul 30 14:08:55.187010 2026] [security2:error] [pid 1004636:tid 1004923] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/.well-known/about.php"] [unique_id "amuhR-_uyupB2NyFtxKYCAAAAGA"]
[Thu Jul 30 14:08:55.187107 2026] [security2:error] [pid 1004636:tid 1004923] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/.well-known/about.php"] [unique_id "amuhR-_uyupB2NyFtxKYCAAAAGA"]
[Thu Jul 30 14:08:55.286374 2026] [security2:error] [pid 1004636:tid 1004867] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuhR-_uyupB2NyFtxKYCQAAACs"]
[Thu Jul 30 14:08:55.421327 2026] [security2:error] [pid 1004636:tid 1004899] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amuhR-_uyupB2NyFtxKYDQAAAEk"]
[Thu Jul 30 14:08:55.456927 2026] [security2:error] [pid 1004636:tid 1004946] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuhR-_uyupB2NyFtxKYDgAAAHY"]
[Thu Jul 30 14:08:55.457101 2026] [security2:error] [pid 1004636:tid 1004946] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuhR-_uyupB2NyFtxKYDgAAAHY"]
[Thu Jul 30 14:08:55.562817 2026] [security2:error] [pid 1004636:tid 1004921] [client 191.232.199.39:38592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuhR-_uyupB2NyFtxKYDwAAAF8"]
[Thu Jul 30 14:08:55.679550 2026] [security2:error] [pid 1004636:tid 1004885] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuhR-_uyupB2NyFtxKYFAAAADw"]
[Thu Jul 30 14:08:55.725891 2026] [security2:error] [pid 1004636:tid 1004852] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/system_log.php"] [unique_id "amuhR-_uyupB2NyFtxKYGQAAAB0"]
[Thu Jul 30 14:08:55.725993 2026] [security2:error] [pid 1004636:tid 1004852] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/system_log.php"] [unique_id "amuhR-_uyupB2NyFtxKYGQAAAB0"]
[Thu Jul 30 14:08:55.815786 2026] [security2:error] [pid 1004636:tid 1004856] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuhR-_uyupB2NyFtxKYGgAAACA"]
[Thu Jul 30 14:08:56.069200 2026] [security2:error] [pid 1004636:tid 1004917] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuhSO_uyupB2NyFtxKYHwAAAFs"]
[Thu Jul 30 14:08:56.093582 2026] [autoindex:error] [pid 1004636:tid 1004954] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:56.094328 2026] [security2:error] [pid 1004636:tid 1004954] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhSO_uyupB2NyFtxKYHgAAAH4"]
[Thu Jul 30 14:08:56.183930 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.215.191.139:49859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/archive.php"] [unique_id "amuhSO_uyupB2NyFtxKYJAAAACM"]
[Thu Jul 30 14:08:56.307030 2026] [autoindex:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:56.307813 2026] [security2:error] [pid 1004636:tid 1004846] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhSO_uyupB2NyFtxKYJwAAABc"]
[Thu Jul 30 14:08:56.319934 2026] [security2:error] [pid 1004636:tid 1004878] [client 185.177.72.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.abudhabifurnituremoversandpackers.site"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuhSO_uyupB2NyFtxKYKAAAADY"]
[Thu Jul 30 14:08:56.353058 2026] [core:notice] [pid 1004636:tid 1004930] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:56.454399 2026] [security2:error] [pid 1004636:tid 1004945] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/crgio.php"] [unique_id "amuhSO_uyupB2NyFtxKYLQAAAHU"]
[Thu Jul 30 14:08:56.454493 2026] [security2:error] [pid 1004636:tid 1004945] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/crgio.php"] [unique_id "amuhSO_uyupB2NyFtxKYLQAAAHU"]
[Thu Jul 30 14:08:56.724859 2026] [security2:error] [pid 1004636:tid 1004845] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/pucci.php"] [unique_id "amuhSO_uyupB2NyFtxKYMwAAABY"]
[Thu Jul 30 14:08:56.724970 2026] [security2:error] [pid 1004636:tid 1004845] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/pucci.php"] [unique_id "amuhSO_uyupB2NyFtxKYMwAAABY"]
[Thu Jul 30 14:08:56.798557 2026] [core:notice] [pid 1004636:tid 1004815] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:57.017747 2026] [autoindex:error] [pid 1004636:tid 1004950] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:57.018458 2026] [security2:error] [pid 1004636:tid 1004950] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhSe_uyupB2NyFtxKYPAAAAHo"]
[Thu Jul 30 14:08:57.172053 2026] [autoindex:error] [pid 1004636:tid 1004860] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:57.172776 2026] [security2:error] [pid 1004636:tid 1004860] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhSe_uyupB2NyFtxKYPQAAACQ"]
[Thu Jul 30 14:08:57.311107 2026] [security2:error] [pid 1004636:tid 1004941] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-temp.php"] [unique_id "amuhSe_uyupB2NyFtxKYRAAAAHE"]
[Thu Jul 30 14:08:57.311230 2026] [security2:error] [pid 1004636:tid 1004941] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-temp.php"] [unique_id "amuhSe_uyupB2NyFtxKYRAAAAHE"]
[Thu Jul 30 14:08:57.480364 2026] [security2:error] [pid 1004636:tid 1004868] [client 52.238.199.152:15116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuhSe_uyupB2NyFtxKYSAAAACw"]
[Thu Jul 30 14:08:57.492678 2026] [security2:error] [pid 1004636:tid 1004867] [client 103.190.40.154:1675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhSe_uyupB2NyFtxKYSgAAACs"]
[Thu Jul 30 14:08:57.492842 2026] [security2:error] [pid 1004636:tid 1004867] [client 103.190.40.154:1675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhSe_uyupB2NyFtxKYSgAAACs"]
[Thu Jul 30 14:08:57.583439 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/js/index.php"] [unique_id "amuhSe_uyupB2NyFtxKYSwAAADM"]
[Thu Jul 30 14:08:57.583562 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/js/index.php"] [unique_id "amuhSe_uyupB2NyFtxKYSwAAADM"]
[Thu Jul 30 14:08:57.856710 2026] [security2:error] [pid 1004636:tid 1004913] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/puc.php"] [unique_id "amuhSe_uyupB2NyFtxKYVgAAAFc"]
[Thu Jul 30 14:08:57.856807 2026] [security2:error] [pid 1004636:tid 1004913] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/puc.php"] [unique_id "amuhSe_uyupB2NyFtxKYVgAAAFc"]
[Thu Jul 30 14:08:57.866230 2026] [security2:error] [pid 1004636:tid 1004931] [client 191.232.199.39:4389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/index/function.php"] [unique_id "amuhSe_uyupB2NyFtxKYWAAAAGg"]
[Thu Jul 30 14:08:58.148023 2026] [security2:error] [pid 1004636:tid 1004855] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dx.php"] [unique_id "amuhSu_uyupB2NyFtxKYXQAAAB8"]
[Thu Jul 30 14:08:58.148142 2026] [security2:error] [pid 1004636:tid 1004855] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dx.php"] [unique_id "amuhSu_uyupB2NyFtxKYXQAAAB8"]
[Thu Jul 30 14:08:58.433801 2026] [autoindex:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:58.434558 2026] [security2:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhSu_uyupB2NyFtxKYZQAAACY"]
[Thu Jul 30 14:08:58.572088 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/7.php"] [unique_id "amuhSu_uyupB2NyFtxKYbQAAACg"]
[Thu Jul 30 14:08:58.572211 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/7.php"] [unique_id "amuhSu_uyupB2NyFtxKYbQAAACg"]
[Thu Jul 30 14:08:58.739137 2026] [security2:error] [pid 1004636:tid 1004910] [client 144.172.114.51:59720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuhSu_uyupB2NyFtxKYcQAAAFQ"]
[Thu Jul 30 14:08:58.840073 2026] [security2:error] [pid 1004636:tid 1004950] [client 213.152.161.219:48134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuhSu_uyupB2NyFtxKYeAAAAHo"]
[Thu Jul 30 14:08:58.840186 2026] [security2:error] [pid 1004636:tid 1004950] [client 213.152.161.219:48134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuhSu_uyupB2NyFtxKYeAAAAHo"]
[Thu Jul 30 14:08:58.843408 2026] [security2:error] [pid 1004636:tid 1004953] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/8.php"] [unique_id "amuhSu_uyupB2NyFtxKYeQAAAH0"]
[Thu Jul 30 14:08:58.843494 2026] [security2:error] [pid 1004636:tid 1004953] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/8.php"] [unique_id "amuhSu_uyupB2NyFtxKYeQAAAH0"]
[Thu Jul 30 14:08:58.980812 2026] [core:notice] [pid 1004636:tid 1004692] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:59.117239 2026] [security2:error] [pid 1004636:tid 1004847] [client 74.248.24.145:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1.php"] [unique_id "amuhS-_uyupB2NyFtxKYgwAAABg"]
[Thu Jul 30 14:08:59.117347 2026] [security2:error] [pid 1004636:tid 1004847] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1.php"] [unique_id "amuhS-_uyupB2NyFtxKYgwAAABg"]
[Thu Jul 30 14:08:59.117442 2026] [security2:error] [pid 1004636:tid 1004847] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1.php"] [unique_id "amuhS-_uyupB2NyFtxKYgwAAABg"]
[Thu Jul 30 14:08:59.245045 2026] [autoindex:error] [pid 1004636:tid 1004899] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:59.275848 2026] [security2:error] [pid 1004636:tid 1004883] [client 189.6.88.213:64663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhS-_uyupB2NyFtxKYiwAAADo"]
[Thu Jul 30 14:08:59.275952 2026] [security2:error] [pid 1004636:tid 1004883] [client 189.6.88.213:64663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhS-_uyupB2NyFtxKYiwAAADo"]
[Thu Jul 30 14:08:59.323535 2026] [security2:error] [pid 1004636:tid 1004929] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhS-_uyupB2NyFtxKYhgAAAGY"]
[Thu Jul 30 14:08:59.323566 2026] [security2:error] [pid 1004636:tid 1004929] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhS-_uyupB2NyFtxKYhgAAAGY"]
[Thu Jul 30 14:08:59.384658 2026] [security2:error] [pid 1004636:tid 1004869] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/about.php"] [unique_id "amuhS-_uyupB2NyFtxKYkQAAAC0"]
[Thu Jul 30 14:08:59.384739 2026] [security2:error] [pid 1004636:tid 1004869] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/about.php"] [unique_id "amuhS-_uyupB2NyFtxKYkQAAAC0"]
[Thu Jul 30 14:08:59.414503 2026] [core:notice] [pid 1004636:tid 1004919] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:59.444859 2026] [security2:error] [pid 1004636:tid 1004886] [client 82.102.18.180:51920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "amuhS-_uyupB2NyFtxKYhAAAAD0"]
[Thu Jul 30 14:08:59.543848 2026] [core:notice] [pid 1004636:tid 1004913] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:08:59.651748 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/admin.php"] [unique_id "amuhS-_uyupB2NyFtxKYmAAAAAg"]
[Thu Jul 30 14:08:59.651883 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/admin.php"] [unique_id "amuhS-_uyupB2NyFtxKYmAAAAAg"]
[Thu Jul 30 14:08:59.687937 2026] [autoindex:error] [pid 1004636:tid 1004905] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:08:59.917797 2026] [security2:error] [pid 1004636:tid 1004916] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/edit.php"] [unique_id "amuhS-_uyupB2NyFtxKYogAAAFo"]
[Thu Jul 30 14:08:59.917899 2026] [security2:error] [pid 1004636:tid 1004916] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/edit.php"] [unique_id "amuhS-_uyupB2NyFtxKYogAAAFo"]
[Thu Jul 30 14:09:00.121250 2026] [security2:error] [pid 1004636:tid 1004834] [client 191.232.199.39:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/aaa.php"] [unique_id "amuhTO_uyupB2NyFtxKYpgAAAAw"]
[Thu Jul 30 14:09:00.211823 2026] [security2:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/admin.php"] [unique_id "amuhTO_uyupB2NyFtxKYpwAAACY"]
[Thu Jul 30 14:09:00.211960 2026] [security2:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/admin.php"] [unique_id "amuhTO_uyupB2NyFtxKYpwAAACY"]
[Thu Jul 30 14:09:00.256762 2026] [core:notice] [pid 1004636:tid 1004776] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:00.331118 2026] [security2:error] [pid 1004636:tid 1004897] [client 20.215.191.139:55631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/as.php"] [unique_id "amuhTO_uyupB2NyFtxKYqQAAAEc"]
[Thu Jul 30 14:09:00.494705 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/inputs.php"] [unique_id "amuhTO_uyupB2NyFtxKYsQAAACg"]
[Thu Jul 30 14:09:00.494803 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/inputs.php"] [unique_id "amuhTO_uyupB2NyFtxKYsQAAACg"]
[Thu Jul 30 14:09:00.756829 2026] [security2:error] [pid 1004636:tid 1004955] [client 181.116.200.68:46930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhTO_uyupB2NyFtxKYvgAAAH8"]
[Thu Jul 30 14:09:00.757015 2026] [security2:error] [pid 1004636:tid 1004955] [client 181.116.200.68:46930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhTO_uyupB2NyFtxKYvgAAAH8"]
[Thu Jul 30 14:09:00.768367 2026] [security2:error] [pid 1004636:tid 1004953] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/av.php"] [unique_id "amuhTO_uyupB2NyFtxKYvwAAAH0"]
[Thu Jul 30 14:09:00.768464 2026] [security2:error] [pid 1004636:tid 1004953] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/av.php"] [unique_id "amuhTO_uyupB2NyFtxKYvwAAAH0"]
[Thu Jul 30 14:09:00.795868 2026] [security2:error] [pid 1004636:tid 1004836] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhTO_uyupB2NyFtxKYugAAAA4"]
[Thu Jul 30 14:09:00.795895 2026] [security2:error] [pid 1004636:tid 1004836] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhTO_uyupB2NyFtxKYugAAAA4"]
[Thu Jul 30 14:09:00.796334 2026] [security2:error] [pid 1004636:tid 1004932] [client 82.102.18.180:51920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/sites/default/files/"] [unique_id "amuhTO_uyupB2NyFtxKYuAAAAGk"]
[Thu Jul 30 14:09:01.049281 2026] [security2:error] [pid 1004636:tid 1004868] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/classwithtostring.php"] [unique_id "amuhTe_uyupB2NyFtxKYywAAACw"]
[Thu Jul 30 14:09:01.049451 2026] [security2:error] [pid 1004636:tid 1004868] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/classwithtostring.php"] [unique_id "amuhTe_uyupB2NyFtxKYywAAACw"]
[Thu Jul 30 14:09:01.198087 2026] [security2:error] [pid 1004636:tid 1004847] [client 74.7.228.10:38542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.abudhabifurnituremoverspackers.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuhTe_uyupB2NyFtxKY0gAAABg"]
[Thu Jul 30 14:09:01.331815 2026] [security2:error] [pid 1004636:tid 1004937] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/themes/index.php"] [unique_id "amuhTe_uyupB2NyFtxKY1AAAAG0"]
[Thu Jul 30 14:09:01.331935 2026] [security2:error] [pid 1004636:tid 1004937] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/themes/index.php"] [unique_id "amuhTe_uyupB2NyFtxKY1AAAAG0"]
[Thu Jul 30 14:09:01.498579 2026] [security2:error] [pid 1004636:tid 1004823] [client 191.232.199.39:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/getid3-core.php"] [unique_id "amuhTe_uyupB2NyFtxKY2AAAAAE"]
[Thu Jul 30 14:09:01.617503 2026] [security2:error] [pid 1004636:tid 1004822] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-blog.php"] [unique_id "amuhTe_uyupB2NyFtxKY4AAAAAA"]
[Thu Jul 30 14:09:01.617625 2026] [security2:error] [pid 1004636:tid 1004822] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-blog.php"] [unique_id "amuhTe_uyupB2NyFtxKY4AAAAAA"]
[Thu Jul 30 14:09:01.827082 2026] [security2:error] [pid 1004636:tid 1004879] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhTe_uyupB2NyFtxKY5QAAADc"]
[Thu Jul 30 14:09:01.827107 2026] [security2:error] [pid 1004636:tid 1004879] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhTe_uyupB2NyFtxKY5QAAADc"]
[Thu Jul 30 14:09:01.827390 2026] [security2:error] [pid 1004636:tid 1004902] [client 82.102.18.180:51920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/admin/controller/extension/extension/"] [unique_id "amuhTe_uyupB2NyFtxKY4wAAAEw"]
[Thu Jul 30 14:09:01.919797 2026] [autoindex:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:01.920884 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhTe_uyupB2NyFtxKY5gAAADE"]
[Thu Jul 30 14:09:02.033121 2026] [core:notice] [pid 1004636:tid 1004753] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:02.125014 2026] [core:notice] [pid 1004636:tid 1004855] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:02.191721 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/admin.php"] [unique_id "amuhTu_uyupB2NyFtxKY-gAAACg"]
[Thu Jul 30 14:09:02.191863 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/admin.php"] [unique_id "amuhTu_uyupB2NyFtxKY-gAAACg"]
[Thu Jul 30 14:09:02.472272 2026] [security2:error] [pid 1004636:tid 1004865] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/adminfuns.php"] [unique_id "amuhTu_uyupB2NyFtxKY-wAAACk"]
[Thu Jul 30 14:09:02.472396 2026] [security2:error] [pid 1004636:tid 1004865] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/adminfuns.php"] [unique_id "amuhTu_uyupB2NyFtxKY-wAAACk"]
[Thu Jul 30 14:09:02.747098 2026] [security2:error] [pid 1004636:tid 1004842] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/goods.php"] [unique_id "amuhTu_uyupB2NyFtxKZBQAAABM"]
[Thu Jul 30 14:09:02.747257 2026] [security2:error] [pid 1004636:tid 1004842] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/goods.php"] [unique_id "amuhTu_uyupB2NyFtxKZBQAAABM"]
[Thu Jul 30 14:09:02.984985 2026] [security2:error] [pid 1004636:tid 1004910] [client 191.232.199.39:5025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/adminer.php"] [unique_id "amuhTu_uyupB2NyFtxKZCQAAAFQ"]
[Thu Jul 30 14:09:03.024821 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ms-edit.php"] [unique_id "amuhT-_uyupB2NyFtxKZCgAAABU"]
[Thu Jul 30 14:09:03.024968 2026] [security2:error] [pid 1004636:tid 1004844] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ms-edit.php"] [unique_id "amuhT-_uyupB2NyFtxKZCgAAABU"]
[Thu Jul 30 14:09:03.034361 2026] [security2:error] [pid 1004636:tid 1004870] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhTu_uyupB2NyFtxKZCAAAAC4"]
[Thu Jul 30 14:09:03.034384 2026] [security2:error] [pid 1004636:tid 1004870] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhTu_uyupB2NyFtxKZCAAAAC4"]
[Thu Jul 30 14:09:03.035021 2026] [security2:error] [pid 1004636:tid 1004832] [client 82.102.18.180:51920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "amuhTu_uyupB2NyFtxKZBgAAAAo"]
[Thu Jul 30 14:09:03.183807 2026] [security2:error] [pid 1004636:tid 1004942] [client 20.215.191.139:59177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/atomlib.php"] [unique_id "amuhT-_uyupB2NyFtxKZFAAAAHI"]
[Thu Jul 30 14:09:03.295652 2026] [security2:error] [pid 1004636:tid 1004940] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/222.php"] [unique_id "amuhT-_uyupB2NyFtxKZFwAAAHA"]
[Thu Jul 30 14:09:03.295792 2026] [security2:error] [pid 1004636:tid 1004940] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/222.php"] [unique_id "amuhT-_uyupB2NyFtxKZFwAAAHA"]
[Thu Jul 30 14:09:03.382401 2026] [core:notice] [pid 1004636:tid 1004929] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:03.565919 2026] [security2:error] [pid 1004636:tid 1004951] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-bin/index.php"] [unique_id "amuhT-_uyupB2NyFtxKZHQAAAHs"]
[Thu Jul 30 14:09:03.566217 2026] [security2:error] [pid 1004636:tid 1004951] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-bin/index.php"] [unique_id "amuhT-_uyupB2NyFtxKZHQAAAHs"]
[Thu Jul 30 14:09:03.863621 2026] [autoindex:error] [pid 1004636:tid 1004917] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:03.864305 2026] [security2:error] [pid 1004636:tid 1004917] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhT-_uyupB2NyFtxKZKAAAAFs"]
[Thu Jul 30 14:09:04.023454 2026] [security2:error] [pid 1004636:tid 1004879] [client 20.215.191.139:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/autoload_classmap.php"] [unique_id "amuhUO_uyupB2NyFtxKZLAAAADc"]
[Thu Jul 30 14:09:04.118750 2026] [security2:error] [pid 1004636:tid 1004888] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhT-_uyupB2NyFtxKZKwAAAD8"]
[Thu Jul 30 14:09:04.118791 2026] [security2:error] [pid 1004636:tid 1004888] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhT-_uyupB2NyFtxKZKwAAAD8"]
[Thu Jul 30 14:09:04.119014 2026] [security2:error] [pid 1004636:tid 1004898] [client 82.102.18.180:51920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/components/"] [unique_id "amuhT-_uyupB2NyFtxKZKQAAAEg"]
[Thu Jul 30 14:09:04.135522 2026] [security2:error] [pid 1004636:tid 1004912] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/BDKR28WP.php"] [unique_id "amuhUO_uyupB2NyFtxKZMAAAAFY"]
[Thu Jul 30 14:09:04.135623 2026] [security2:error] [pid 1004636:tid 1004912] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/BDKR28WP.php"] [unique_id "amuhUO_uyupB2NyFtxKZMAAAAFY"]
[Thu Jul 30 14:09:04.418687 2026] [autoindex:error] [pid 1004636:tid 1004925] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:04.419378 2026] [security2:error] [pid 1004636:tid 1004925] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhUO_uyupB2NyFtxKZOgAAAGI"]
[Thu Jul 30 14:09:04.536763 2026] [security2:error] [pid 1004636:tid 1004909] [client 191.232.199.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuhUO_uyupB2NyFtxKZNgAAAFM"]
[Thu Jul 30 14:09:04.571543 2026] [autoindex:error] [pid 1004636:tid 1004876] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:04.572317 2026] [security2:error] [pid 1004636:tid 1004876] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhUO_uyupB2NyFtxKZOwAAADQ"]
[Thu Jul 30 14:09:04.682480 2026] [security2:error] [pid 1004636:tid 1004927] [client 20.215.191.139:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/bb.php"] [unique_id "amuhUO_uyupB2NyFtxKZQAAAAGQ"]
[Thu Jul 30 14:09:04.708787 2026] [security2:error] [pid 1004636:tid 1004849] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp.php"] [unique_id "amuhUO_uyupB2NyFtxKZQwAAABo"]
[Thu Jul 30 14:09:04.708883 2026] [security2:error] [pid 1004636:tid 1004849] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp.php"] [unique_id "amuhUO_uyupB2NyFtxKZQwAAABo"]
[Thu Jul 30 14:09:04.938823 2026] [core:error] [pid 1004636:tid 1004950] [client 95.108.213.152:37802] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:04.938848 2026] [core:error] [pid 1004636:tid 1004950] [client 95.108.213.152:37802] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:04.976286 2026] [security2:error] [pid 1004636:tid 1004893] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/abcd.php"] [unique_id "amuhUO_uyupB2NyFtxKZSwAAAEQ"]
[Thu Jul 30 14:09:04.976379 2026] [security2:error] [pid 1004636:tid 1004893] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/abcd.php"] [unique_id "amuhUO_uyupB2NyFtxKZSwAAAEQ"]
[Thu Jul 30 14:09:05.251667 2026] [security2:error] [pid 1004636:tid 1004835] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/a1.php"] [unique_id "amuhUe_uyupB2NyFtxKZUwAAAA0"]
[Thu Jul 30 14:09:05.251771 2026] [security2:error] [pid 1004636:tid 1004835] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/a1.php"] [unique_id "amuhUe_uyupB2NyFtxKZUwAAAA0"]
[Thu Jul 30 14:09:05.339954 2026] [security2:error] [pid 1004636:tid 1004946] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhUe_uyupB2NyFtxKZUQAAAHY"]
[Thu Jul 30 14:09:05.339991 2026] [security2:error] [pid 1004636:tid 1004946] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhUe_uyupB2NyFtxKZUQAAAHY"]
[Thu Jul 30 14:09:05.340291 2026] [security2:error] [pid 1004636:tid 1004926] [client 82.102.18.180:51920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/admin/uploads/images/"] [unique_id "amuhUe_uyupB2NyFtxKZTgAAAGM"]
[Thu Jul 30 14:09:05.535585 2026] [security2:error] [pid 1004636:tid 1004880] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuhUe_uyupB2NyFtxKZXgAAADg"]
[Thu Jul 30 14:09:05.535686 2026] [security2:error] [pid 1004636:tid 1004880] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuhUe_uyupB2NyFtxKZXgAAADg"]
[Thu Jul 30 14:09:05.561037 2026] [security2:error] [pid 1004636:tid 1004856] [client 191.232.199.39:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/alfa.php"] [unique_id "amuhUe_uyupB2NyFtxKZYAAAACA"]
[Thu Jul 30 14:09:05.706606 2026] [security2:error] [pid 1004636:tid 1004874] [client 20.215.191.139:57227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/bnm.php"] [unique_id "amuhUe_uyupB2NyFtxKZZAAAADI"]
[Thu Jul 30 14:09:05.805405 2026] [core:error] [pid 1004636:tid 1004902] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:05.805427 2026] [core:error] [pid 1004636:tid 1004902] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:05.825430 2026] [security2:error] [pid 1004636:tid 1004888] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-bin/admin.php"] [unique_id "amuhUe_uyupB2NyFtxKZbAAAAD8"]
[Thu Jul 30 14:09:05.825515 2026] [security2:error] [pid 1004636:tid 1004888] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-bin/admin.php"] [unique_id "amuhUe_uyupB2NyFtxKZbAAAAD8"]
[Thu Jul 30 14:09:05.904506 2026] [core:error] [pid 1004636:tid 1004822] [client 32.193.60.217:40128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:05.904526 2026] [core:error] [pid 1004636:tid 1004822] [client 32.193.60.217:40128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:06.144902 2026] [security2:error] [pid 1004636:tid 1004862] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-content/index.php"] [unique_id "amuhUu_uyupB2NyFtxKZcgAAACY"]
[Thu Jul 30 14:09:06.295577 2026] [security2:error] [pid 1004636:tid 1004903] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/simple.php"] [unique_id "amuhUu_uyupB2NyFtxKZdwAAAE0"]
[Thu Jul 30 14:09:06.295691 2026] [security2:error] [pid 1004636:tid 1004903] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/simple.php"] [unique_id "amuhUu_uyupB2NyFtxKZdwAAAE0"]
[Thu Jul 30 14:09:06.576103 2026] [security2:error] [pid 1004636:tid 1004858] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xxx.php"] [unique_id "amuhUu_uyupB2NyFtxKZgAAAACI"]
[Thu Jul 30 14:09:06.576230 2026] [security2:error] [pid 1004636:tid 1004858] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xxx.php"] [unique_id "amuhUu_uyupB2NyFtxKZgAAAACI"]
[Thu Jul 30 14:09:06.845798 2026] [security2:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/hypo.php"] [unique_id "amuhUu_uyupB2NyFtxKZhwAAAEo"]
[Thu Jul 30 14:09:06.845938 2026] [security2:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/hypo.php"] [unique_id "amuhUu_uyupB2NyFtxKZhwAAAEo"]
[Thu Jul 30 14:09:07.133102 2026] [autoindex:error] [pid 1004636:tid 1004887] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:07.180770 2026] [autoindex:error] [pid 1004636:tid 1004906] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:07.181475 2026] [security2:error] [pid 1004636:tid 1004906] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhU-_uyupB2NyFtxKZmgAAAFA"]
[Thu Jul 30 14:09:07.318070 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/chosen.php"] [unique_id "amuhU-_uyupB2NyFtxKZrAAAABQ"]
[Thu Jul 30 14:09:07.318229 2026] [security2:error] [pid 1004636:tid 1004843] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/chosen.php"] [unique_id "amuhU-_uyupB2NyFtxKZrAAAABQ"]
[Thu Jul 30 14:09:07.482834 2026] [security2:error] [pid 1004636:tid 1004858] [client 191.232.199.39:4247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuhU-_uyupB2NyFtxKZvwAAACI"]
[Thu Jul 30 14:09:07.603160 2026] [autoindex:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:07.604011 2026] [security2:error] [pid 1004636:tid 1004900] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhU-_uyupB2NyFtxKZwwAAAEo"]
[Thu Jul 30 14:09:07.743410 2026] [security2:error] [pid 1004636:tid 1004841] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/als.php"] [unique_id "amuhU-_uyupB2NyFtxKZxAAAABI"]
[Thu Jul 30 14:09:07.743545 2026] [security2:error] [pid 1004636:tid 1004841] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/als.php"] [unique_id "amuhU-_uyupB2NyFtxKZxAAAABI"]
[Thu Jul 30 14:09:07.745045 2026] [security2:error] [pid 1004636:tid 1004838] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhU-_uyupB2NyFtxKZwgAAAA8"]
[Thu Jul 30 14:09:07.745092 2026] [security2:error] [pid 1004636:tid 1004838] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhU-_uyupB2NyFtxKZwgAAAA8"]
[Thu Jul 30 14:09:07.745341 2026] [security2:error] [pid 1004636:tid 1004844] [client 82.102.18.180:51920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "amuhU-_uyupB2NyFtxKZwAAAABU"]
[Thu Jul 30 14:09:07.966589 2026] [fcgid:warn] [pid 1004636:tid 1004945] (70014)End of file found: [client 152.32.223.215:47018] mod_fcgid: can't get data from http client
[Thu Jul 30 14:09:08.037432 2026] [security2:error] [pid 1004636:tid 1004848] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/pol.php"] [unique_id "amuhVO_uyupB2NyFtxKZ0wAAABk"]
[Thu Jul 30 14:09:08.037515 2026] [security2:error] [pid 1004636:tid 1004848] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/pol.php"] [unique_id "amuhVO_uyupB2NyFtxKZ0wAAABk"]
[Thu Jul 30 14:09:08.149467 2026] [security2:error] [pid 1004636:tid 1004892] [client 103.190.40.154:19233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhVO_uyupB2NyFtxKZ1QAAAEM"]
[Thu Jul 30 14:09:08.149607 2026] [security2:error] [pid 1004636:tid 1004892] [client 103.190.40.154:19233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhVO_uyupB2NyFtxKZ1QAAAEM"]
[Thu Jul 30 14:09:08.317245 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file5.php"] [unique_id "amuhVO_uyupB2NyFtxKZ2QAAAAg"]
[Thu Jul 30 14:09:08.317391 2026] [security2:error] [pid 1004636:tid 1004830] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file5.php"] [unique_id "amuhVO_uyupB2NyFtxKZ2QAAAAg"]
[Thu Jul 30 14:09:08.355177 2026] [security2:error] [pid 1004636:tid 1004881] [client 74.7.230.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mshandco.org"] [uri "/index.php"] [unique_id "amuhTu_uyupB2NyFtxKY7AAAADk"]
[Thu Jul 30 14:09:08.355949 2026] [security2:error] [pid 1004636:tid 1004859] [client 74.7.230.4:47934] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mshandco.org"] [uri "/robots.txt"] [unique_id "amuhTu_uyupB2NyFtxKY6gAAIyo"]
[Thu Jul 30 14:09:08.540200 2026] [autoindex:error] [pid 1004636:tid 1004916] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-content/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:08.540810 2026] [security2:error] [pid 1004636:tid 1004916] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhVO_uyupB2NyFtxKZ4wAAAFo"]
[Thu Jul 30 14:09:08.541221 2026] [security2:error] [pid 1004636:tid 1004904] [client 82.102.18.180:51920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-content/fonts/"] [unique_id "amuhVO_uyupB2NyFtxKZ4QAAAE4"]
[Thu Jul 30 14:09:08.603938 2026] [security2:error] [pid 1004636:tid 1004914] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file.php"] [unique_id "amuhVO_uyupB2NyFtxKZ5AAAAFg"]
[Thu Jul 30 14:09:08.604087 2026] [security2:error] [pid 1004636:tid 1004914] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file.php"] [unique_id "amuhVO_uyupB2NyFtxKZ5AAAAFg"]
[Thu Jul 30 14:09:08.678640 2026] [security2:error] [pid 1004636:tid 1004906] [client 20.215.191.139:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/bootstrap.php"] [unique_id "amuhVO_uyupB2NyFtxKZ6AAAAFA"]
[Thu Jul 30 14:09:08.874200 2026] [security2:error] [pid 1004636:tid 1004855] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/admin.php"] [unique_id "amuhVO_uyupB2NyFtxKZ7QAAAB8"]
[Thu Jul 30 14:09:08.874285 2026] [security2:error] [pid 1004636:tid 1004855] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/admin.php"] [unique_id "amuhVO_uyupB2NyFtxKZ7QAAAB8"]
[Thu Jul 30 14:09:09.154179 2026] [security2:error] [pid 1004636:tid 1004869] [client 144.172.114.51:60854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/.env.backup"] [unique_id "amuhVe_uyupB2NyFtxKZ9AAAAC0"]
[Thu Jul 30 14:09:09.157681 2026] [security2:error] [pid 1004636:tid 1004876] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/aa2.php"] [unique_id "amuhVe_uyupB2NyFtxKZ9QAAADQ"]
[Thu Jul 30 14:09:09.157757 2026] [security2:error] [pid 1004636:tid 1004876] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/aa2.php"] [unique_id "amuhVe_uyupB2NyFtxKZ9QAAADQ"]
[Thu Jul 30 14:09:09.158207 2026] [security2:error] [pid 1004636:tid 1004897] [client 191.232.199.39:42064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuhVe_uyupB2NyFtxKZ9gAAAEc"]
[Thu Jul 30 14:09:09.249844 2026] [security2:error] [pid 1004636:tid 1004925] [client 20.215.191.139:56655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/buy.php"] [unique_id "amuhVe_uyupB2NyFtxKZ-gAAAGI"]
[Thu Jul 30 14:09:09.318901 2026] [security2:error] [pid 1004636:tid 1004927] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhVe_uyupB2NyFtxKZ8wAAAGQ"]
[Thu Jul 30 14:09:09.318929 2026] [security2:error] [pid 1004636:tid 1004927] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhVe_uyupB2NyFtxKZ8wAAAGQ"]
[Thu Jul 30 14:09:09.319879 2026] [security2:error] [pid 1004636:tid 1004831] [client 82.102.18.180:51920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "amuhVe_uyupB2NyFtxKZ8QAAAAk"]
[Thu Jul 30 14:09:09.427717 2026] [security2:error] [pid 1004636:tid 1004919] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ccou.php"] [unique_id "amuhVe_uyupB2NyFtxKaAwAAAF0"]
[Thu Jul 30 14:09:09.427804 2026] [security2:error] [pid 1004636:tid 1004919] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ccou.php"] [unique_id "amuhVe_uyupB2NyFtxKaAwAAAF0"]
[Thu Jul 30 14:09:09.696144 2026] [security2:error] [pid 1004636:tid 1004939] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dr.php"] [unique_id "amuhVe_uyupB2NyFtxKaCAAAAG8"]
[Thu Jul 30 14:09:09.696262 2026] [security2:error] [pid 1004636:tid 1004939] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dr.php"] [unique_id "amuhVe_uyupB2NyFtxKaCAAAAG8"]
[Thu Jul 30 14:09:09.955630 2026] [security2:error] [pid 1004636:tid 1004850] [client 189.6.88.213:65210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhVe_uyupB2NyFtxKaFAAAABs"]
[Thu Jul 30 14:09:09.955718 2026] [security2:error] [pid 1004636:tid 1004850] [client 189.6.88.213:65210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhVe_uyupB2NyFtxKaFAAAABs"]
[Thu Jul 30 14:09:09.968109 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xamp.php"] [unique_id "amuhVe_uyupB2NyFtxKaFgAAADM"]
[Thu Jul 30 14:09:09.968211 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xamp.php"] [unique_id "amuhVe_uyupB2NyFtxKaFgAAADM"]
[Thu Jul 30 14:09:10.236827 2026] [security2:error] [pid 1004636:tid 1004840] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/bless.php"] [unique_id "amuhVu_uyupB2NyFtxKaGgAAABE"]
[Thu Jul 30 14:09:10.236944 2026] [security2:error] [pid 1004636:tid 1004840] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/bless.php"] [unique_id "amuhVu_uyupB2NyFtxKaGgAAABE"]
[Thu Jul 30 14:09:10.273907 2026] [security2:error] [pid 1004636:tid 1004940] [client 20.215.191.139:55379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/chosen.php"] [unique_id "amuhVu_uyupB2NyFtxKaHgAAAHA"]
[Thu Jul 30 14:09:10.477078 2026] [core:notice] [pid 1004636:tid 1004873] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:10.524027 2026] [security2:error] [pid 1004636:tid 1004949] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file25.php"] [unique_id "amuhVu_uyupB2NyFtxKaJwAAAHk"]
[Thu Jul 30 14:09:10.524139 2026] [security2:error] [pid 1004636:tid 1004949] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file25.php"] [unique_id "amuhVu_uyupB2NyFtxKaJwAAAHk"]
[Thu Jul 30 14:09:10.803459 2026] [security2:error] [pid 1004636:tid 1004834] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file6.php"] [unique_id "amuhVu_uyupB2NyFtxKaLgAAAAw"]
[Thu Jul 30 14:09:10.803606 2026] [security2:error] [pid 1004636:tid 1004834] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file6.php"] [unique_id "amuhVu_uyupB2NyFtxKaLgAAAAw"]
[Thu Jul 30 14:09:11.072525 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/a2.php"] [unique_id "amuhV-_uyupB2NyFtxKaOAAAAH8"]
[Thu Jul 30 14:09:11.072651 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/a2.php"] [unique_id "amuhV-_uyupB2NyFtxKaOAAAAH8"]
[Thu Jul 30 14:09:11.173850 2026] [security2:error] [pid 1004636:tid 1004880] [client 191.232.199.39:42510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuhV-_uyupB2NyFtxKaOgAAADg"]
[Thu Jul 30 14:09:11.300809 2026] [security2:error] [pid 1004636:tid 1004851] [client 20.215.191.139:55416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/class-wp-image.php"] [unique_id "amuhV-_uyupB2NyFtxKaOwAAABw"]
[Thu Jul 30 14:09:11.344733 2026] [security2:error] [pid 1004636:tid 1004911] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file15.php"] [unique_id "amuhV-_uyupB2NyFtxKaPAAAAFU"]
[Thu Jul 30 14:09:11.344883 2026] [security2:error] [pid 1004636:tid 1004911] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file15.php"] [unique_id "amuhV-_uyupB2NyFtxKaPAAAAFU"]
[Thu Jul 30 14:09:11.372634 2026] [security2:error] [pid 1004636:tid 1004943] [client 181.116.200.68:14075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhV-_uyupB2NyFtxKaPwAAAHM"]
[Thu Jul 30 14:09:11.372743 2026] [security2:error] [pid 1004636:tid 1004943] [client 181.116.200.68:14075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhV-_uyupB2NyFtxKaPwAAAHM"]
[Thu Jul 30 14:09:11.621717 2026] [security2:error] [pid 1004636:tid 1004842] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/f35.php"] [unique_id "amuhV-_uyupB2NyFtxKaWwAAABM"]
[Thu Jul 30 14:09:11.621803 2026] [security2:error] [pid 1004636:tid 1004842] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/f35.php"] [unique_id "amuhV-_uyupB2NyFtxKaWwAAABM"]
[Thu Jul 30 14:09:11.709129 2026] [security2:error] [pid 1004636:tid 1004914] [client 116.179.37.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhVu_uyupB2NyFtxKaLQAAWH4"]
[Thu Jul 30 14:09:11.902950 2026] [security2:error] [pid 1004636:tid 1004947] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-load.php"] [unique_id "amuhV-_uyupB2NyFtxKaZAAAAHc"]
[Thu Jul 30 14:09:11.903104 2026] [security2:error] [pid 1004636:tid 1004947] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-load.php"] [unique_id "amuhV-_uyupB2NyFtxKaZAAAAHc"]
[Thu Jul 30 14:09:12.172840 2026] [security2:error] [pid 1004636:tid 1004937] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xwpg.php"] [unique_id "amuhWO_uyupB2NyFtxKaaAAAAG0"]
[Thu Jul 30 14:09:12.172965 2026] [security2:error] [pid 1004636:tid 1004937] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xwpg.php"] [unique_id "amuhWO_uyupB2NyFtxKaaAAAAG0"]
[Thu Jul 30 14:09:12.457379 2026] [autoindex:error] [pid 1004636:tid 1004861] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:12.458126 2026] [security2:error] [pid 1004636:tid 1004861] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhWO_uyupB2NyFtxKacQAAACU"]
[Thu Jul 30 14:09:12.661829 2026] [autoindex:error] [pid 1004636:tid 1004913] [client 74.248.24.145:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_6cfcc7a4/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:12.662711 2026] [security2:error] [pid 1004636:tid 1004913] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/cgi-sys/403.html"] [unique_id "amuhWO_uyupB2NyFtxKadQAAAFc"]
[Thu Jul 30 14:09:12.800187 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xstelth.php"] [unique_id "amuhWO_uyupB2NyFtxKagQAAADE"]
[Thu Jul 30 14:09:12.800297 2026] [security2:error] [pid 1004636:tid 1004873] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xstelth.php"] [unique_id "amuhWO_uyupB2NyFtxKagQAAADE"]
[Thu Jul 30 14:09:13.090386 2026] [security2:error] [pid 1004636:tid 1004904] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuhWe_uyupB2NyFtxKahgAAAE4"]
[Thu Jul 30 14:09:13.090530 2026] [security2:error] [pid 1004636:tid 1004904] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuhWe_uyupB2NyFtxKahgAAAE4"]
[Thu Jul 30 14:09:13.323991 2026] [security2:error] [pid 1004636:tid 1004905] [client 191.232.199.39:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/edit.php"] [unique_id "amuhWe_uyupB2NyFtxKalgAAAE8"]
[Thu Jul 30 14:09:13.367963 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/aaa.php"] [unique_id "amuhWe_uyupB2NyFtxKalwAAAGs"]
[Thu Jul 30 14:09:13.368086 2026] [security2:error] [pid 1004636:tid 1004934] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/aaa.php"] [unique_id "amuhWe_uyupB2NyFtxKalwAAAGs"]
[Thu Jul 30 14:09:13.547606 2026] [security2:error] [pid 1004636:tid 1004747] [remote 52.167.144.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/index.php/JIPKL/article/view/7/9"] [unique_id "amuhWe_uyupB2NyFtxKamwAAITk"]
[Thu Jul 30 14:09:13.655237 2026] [security2:error] [pid 1004636:tid 1004851] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/gecko.php"] [unique_id "amuhWe_uyupB2NyFtxKaogAAABw"]
[Thu Jul 30 14:09:13.655324 2026] [security2:error] [pid 1004636:tid 1004851] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/gecko.php"] [unique_id "amuhWe_uyupB2NyFtxKaogAAABw"]
[Thu Jul 30 14:09:13.929595 2026] [security2:error] [pid 1004636:tid 1004865] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/pbck.php"] [unique_id "amuhWe_uyupB2NyFtxKarAAAACk"]
[Thu Jul 30 14:09:13.929701 2026] [security2:error] [pid 1004636:tid 1004865] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/pbck.php"] [unique_id "amuhWe_uyupB2NyFtxKarAAAACk"]
[Thu Jul 30 14:09:14.157037 2026] [core:notice] [pid 1004636:tid 1004840] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:14.202727 2026] [security2:error] [pid 1004636:tid 1004893] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xiugai.php"] [unique_id "amuhWu_uyupB2NyFtxKatgAAAEQ"]
[Thu Jul 30 14:09:14.202825 2026] [security2:error] [pid 1004636:tid 1004893] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xiugai.php"] [unique_id "amuhWu_uyupB2NyFtxKatgAAAEQ"]
[Thu Jul 30 14:09:14.416890 2026] [security2:error] [pid 1004636:tid 1004884] [client 20.215.191.139:58829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/classsmtps.php"] [unique_id "amuhWu_uyupB2NyFtxKauwAAADs"]
[Thu Jul 30 14:09:14.481792 2026] [security2:error] [pid 1004636:tid 1004850] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/e.php"] [unique_id "amuhWu_uyupB2NyFtxKawAAAABs"]
[Thu Jul 30 14:09:14.481890 2026] [security2:error] [pid 1004636:tid 1004850] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/e.php"] [unique_id "amuhWu_uyupB2NyFtxKawAAAABs"]
[Thu Jul 30 14:09:14.616895 2026] [autoindex:error] [pid 1004636:tid 1004881] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:14.756535 2026] [security2:error] [pid 1004636:tid 1004951] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/adminner.php"] [unique_id "amuhWu_uyupB2NyFtxKa4AAAAHs"]
[Thu Jul 30 14:09:14.756666 2026] [security2:error] [pid 1004636:tid 1004951] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/adminner.php"] [unique_id "amuhWu_uyupB2NyFtxKa4AAAAHs"]
[Thu Jul 30 14:09:14.791697 2026] [core:notice] [pid 1004636:tid 1004848] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:15.026078 2026] [security2:error] [pid 1004636:tid 1004952] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file1221.php"] [unique_id "amuhW-_uyupB2NyFtxKa6AAAAHw"]
[Thu Jul 30 14:09:15.026264 2026] [security2:error] [pid 1004636:tid 1004952] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/file1221.php"] [unique_id "amuhW-_uyupB2NyFtxKa6AAAAHw"]
[Thu Jul 30 14:09:15.306940 2026] [security2:error] [pid 1004636:tid 1004827] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/inx.php"] [unique_id "amuhW-_uyupB2NyFtxKa8AAAAAU"]
[Thu Jul 30 14:09:15.307119 2026] [security2:error] [pid 1004636:tid 1004827] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/inx.php"] [unique_id "amuhW-_uyupB2NyFtxKa8AAAAAU"]
[Thu Jul 30 14:09:15.484684 2026] [security2:error] [pid 1004636:tid 1004905] [client 191.232.199.39:4477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/sf.php"] [unique_id "amuhW-_uyupB2NyFtxKa9wAAAE8"]
[Thu Jul 30 14:09:15.599217 2026] [security2:error] [pid 1004636:tid 1004878] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/qqqa.php"] [unique_id "amuhW-_uyupB2NyFtxKa-AAAADY"]
[Thu Jul 30 14:09:15.599350 2026] [security2:error] [pid 1004636:tid 1004878] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/qqqa.php"] [unique_id "amuhW-_uyupB2NyFtxKa-AAAADY"]
[Thu Jul 30 14:09:15.874970 2026] [security2:error] [pid 1004636:tid 1004943] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/reviall.php"] [unique_id "amuhW-_uyupB2NyFtxKa_wAAAHM"]
[Thu Jul 30 14:09:15.875143 2026] [security2:error] [pid 1004636:tid 1004943] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/reviall.php"] [unique_id "amuhW-_uyupB2NyFtxKa_wAAAHM"]
[Thu Jul 30 14:09:16.159008 2026] [security2:error] [pid 1004636:tid 1004836] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/404.php"] [unique_id "amuhXO_uyupB2NyFtxKbCwAAAA4"]
[Thu Jul 30 14:09:16.159128 2026] [security2:error] [pid 1004636:tid 1004836] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/404.php"] [unique_id "amuhXO_uyupB2NyFtxKbCwAAAA4"]
[Thu Jul 30 14:09:16.280447 2026] [proxy:error] [pid 1004636:tid 1004811] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:09:16.280500 2026] [proxy_http:error] [pid 1004636:tid 1004811] [remote 74.7.241.151:50570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:09:16.281170 2026] [proxy:error] [pid 1004636:tid 1004811] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:09:16.281219 2026] [proxy_http:error] [pid 1004636:tid 1004811] [remote 74.7.241.151:50570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:09:16.393331 2026] [security2:error] [pid 1004636:tid 1004896] [client 20.215.191.139:50179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/classwithtostring.php"] [unique_id "amuhXO_uyupB2NyFtxKbDwAAAEY"]
[Thu Jul 30 14:09:16.435189 2026] [security2:error] [pid 1004636:tid 1004840] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/bolt.php"] [unique_id "amuhXO_uyupB2NyFtxKbEAAAABE"]
[Thu Jul 30 14:09:16.435282 2026] [security2:error] [pid 1004636:tid 1004840] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/bolt.php"] [unique_id "amuhXO_uyupB2NyFtxKbEAAAABE"]
[Thu Jul 30 14:09:16.704270 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/File.php"] [unique_id "amuhXO_uyupB2NyFtxKbHQAAADM"]
[Thu Jul 30 14:09:16.704369 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/File.php"] [unique_id "amuhXO_uyupB2NyFtxKbHQAAADM"]
[Thu Jul 30 14:09:16.769633 2026] [autoindex:error] [pid 1004636:tid 1004950] [client 191.232.199.39:4565] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:16.982293 2026] [security2:error] [pid 1004636:tid 1004823] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/fi22.php"] [unique_id "amuhXO_uyupB2NyFtxKbHwAAAAE"]
[Thu Jul 30 14:09:16.982436 2026] [security2:error] [pid 1004636:tid 1004823] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/fi22.php"] [unique_id "amuhXO_uyupB2NyFtxKbHwAAAAE"]
[Thu Jul 30 14:09:17.117810 2026] [security2:error] [pid 1004636:tid 1004874] [client 191.232.199.39:4565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wso.php"] [unique_id "amuhXe_uyupB2NyFtxKbJgAAADI"]
[Thu Jul 30 14:09:17.176966 2026] [security2:error] [pid 1004636:tid 1004856] [client 135.119.63.61:13730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/adminwebk.php"] [unique_id "amuhXe_uyupB2NyFtxKbKgAAACA"]
[Thu Jul 30 14:09:17.257289 2026] [security2:error] [pid 1004636:tid 1004888] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/zero.php"] [unique_id "amuhXe_uyupB2NyFtxKbKwAAAD8"]
[Thu Jul 30 14:09:17.257397 2026] [security2:error] [pid 1004636:tid 1004888] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/zero.php"] [unique_id "amuhXe_uyupB2NyFtxKbKwAAAD8"]
[Thu Jul 30 14:09:17.526929 2026] [security2:error] [pid 1004636:tid 1004906] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1xmomo.php"] [unique_id "amuhXe_uyupB2NyFtxKbLwAAAFA"]
[Thu Jul 30 14:09:17.527069 2026] [security2:error] [pid 1004636:tid 1004906] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1xmomo.php"] [unique_id "amuhXe_uyupB2NyFtxKbLwAAAFA"]
[Thu Jul 30 14:09:17.555994 2026] [core:notice] [pid 1004636:tid 1004822] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:17.771386 2026] [security2:error] [pid 1004636:tid 1004948] [client 20.215.191.139:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/config.php"] [unique_id "amuhXe_uyupB2NyFtxKbOgAAAHg"]
[Thu Jul 30 14:09:17.792456 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/fmws.php"] [unique_id "amuhXe_uyupB2NyFtxKbOwAAACg"]
[Thu Jul 30 14:09:17.792541 2026] [security2:error] [pid 1004636:tid 1004864] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/fmws.php"] [unique_id "amuhXe_uyupB2NyFtxKbOwAAACg"]
[Thu Jul 30 14:09:18.059047 2026] [security2:error] [pid 1004636:tid 1004915] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuhXu_uyupB2NyFtxKbPQAAAFk"]
[Thu Jul 30 14:09:18.059170 2026] [security2:error] [pid 1004636:tid 1004915] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuhXu_uyupB2NyFtxKbPQAAAFk"]
[Thu Jul 30 14:09:18.230027 2026] [security2:error] [pid 1004636:tid 1004907] [client 135.119.63.61:14040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/adminwebwp.php"] [unique_id "amuhXu_uyupB2NyFtxKbRgAAAFE"]
[Thu Jul 30 14:09:18.255073 2026] [core:notice] [pid 1004636:tid 1004891] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:18.352863 2026] [security2:error] [pid 1004636:tid 1004903] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/hp2.php"] [unique_id "amuhXu_uyupB2NyFtxKbSQAAAE0"]
[Thu Jul 30 14:09:18.352971 2026] [security2:error] [pid 1004636:tid 1004903] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/hp2.php"] [unique_id "amuhXu_uyupB2NyFtxKbSQAAAE0"]
[Thu Jul 30 14:09:18.538590 2026] [security2:error] [pid 1004636:tid 1004912] [client 191.232.199.39:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/ioxi-o.php"] [unique_id "amuhXu_uyupB2NyFtxKbSgAAAFY"]
[Thu Jul 30 14:09:18.627318 2026] [security2:error] [pid 1004636:tid 1004842] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/aabb.php"] [unique_id "amuhXu_uyupB2NyFtxKbTwAAABM"]
[Thu Jul 30 14:09:18.627439 2026] [security2:error] [pid 1004636:tid 1004842] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/aabb.php"] [unique_id "amuhXu_uyupB2NyFtxKbTwAAABM"]
[Thu Jul 30 14:09:18.660366 2026] [security2:error] [pid 1004636:tid 1004851] [client 144.172.114.51:55488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/.env.bak"] [unique_id "amuhXu_uyupB2NyFtxKbVgAAABw"]
[Thu Jul 30 14:09:18.718642 2026] [security2:error] [pid 1004636:tid 1004828] [client 185.191.171.7:42022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/02/09/medico-odontologo-morre-em-acidente-a-caminho-do-consultorio-na-br-101/"] [unique_id "amuhXu_uyupB2NyFtxKbWgAAAAY"]
[Thu Jul 30 14:09:18.718770 2026] [security2:error] [pid 1004636:tid 1004828] [client 185.191.171.7:42022] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/02/09/medico-odontologo-morre-em-acidente-a-caminho-do-consultorio-na-br-101/"] [unique_id "amuhXu_uyupB2NyFtxKbWgAAAAY"]
[Thu Jul 30 14:09:18.857830 2026] [security2:error] [pid 1004636:tid 1004923] [client 103.190.40.154:19256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhXu_uyupB2NyFtxKbWwAAAGA"]
[Thu Jul 30 14:09:18.857994 2026] [security2:error] [pid 1004636:tid 1004923] [client 103.190.40.154:19256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhXu_uyupB2NyFtxKbWwAAAGA"]
[Thu Jul 30 14:09:18.897249 2026] [security2:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1254xx.php"] [unique_id "amuhXu_uyupB2NyFtxKbXAAAAAo"]
[Thu Jul 30 14:09:18.897346 2026] [security2:error] [pid 1004636:tid 1004832] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1254xx.php"] [unique_id "amuhXu_uyupB2NyFtxKbXAAAAAo"]
[Thu Jul 30 14:09:19.179889 2026] [security2:error] [pid 1004636:tid 1004890] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuhX-_uyupB2NyFtxKbYAAAAEE"]
[Thu Jul 30 14:09:19.180031 2026] [security2:error] [pid 1004636:tid 1004890] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuhX-_uyupB2NyFtxKbYAAAAEE"]
[Thu Jul 30 14:09:19.467760 2026] [security2:error] [pid 1004636:tid 1004944] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/pms297.php"] [unique_id "amuhX-_uyupB2NyFtxKbaQAAAHQ"]
[Thu Jul 30 14:09:19.467879 2026] [security2:error] [pid 1004636:tid 1004944] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/pms297.php"] [unique_id "amuhX-_uyupB2NyFtxKbaQAAAHQ"]
[Thu Jul 30 14:09:19.752454 2026] [security2:error] [pid 1004636:tid 1004888] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuhX-_uyupB2NyFtxKbcAAAAD8"]
[Thu Jul 30 14:09:19.752567 2026] [security2:error] [pid 1004636:tid 1004888] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuhX-_uyupB2NyFtxKbcAAAAD8"]
[Thu Jul 30 14:09:20.027581 2026] [security2:error] [pid 1004636:tid 1004822] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuhYO_uyupB2NyFtxKbdAAAAAA"]
[Thu Jul 30 14:09:20.027700 2026] [security2:error] [pid 1004636:tid 1004822] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuhYO_uyupB2NyFtxKbdAAAAAA"]
[Thu Jul 30 14:09:20.129132 2026] [security2:error] [pid 1004636:tid 1004871] [client 135.119.63.61:33621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/adminwp.php"] [unique_id "amuhYO_uyupB2NyFtxKbdgAAAC8"]
[Thu Jul 30 14:09:20.151526 2026] [security2:error] [pid 1004636:tid 1004866] [client 191.232.199.39:42248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/file56.php"] [unique_id "amuhYO_uyupB2NyFtxKbegAAACo"]
[Thu Jul 30 14:09:20.311002 2026] [security2:error] [pid 1004636:tid 1004878] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuhYO_uyupB2NyFtxKbgQAAADY"]
[Thu Jul 30 14:09:20.311106 2026] [security2:error] [pid 1004636:tid 1004878] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuhYO_uyupB2NyFtxKbgQAAADY"]
[Thu Jul 30 14:09:20.440394 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.215.191.139:49528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/core.php"] [unique_id "amuhYO_uyupB2NyFtxKbggAAAFM"]
[Thu Jul 30 14:09:20.601488 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuhYO_uyupB2NyFtxKbgwAAAH8"]
[Thu Jul 30 14:09:20.601612 2026] [security2:error] [pid 1004636:tid 1004955] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuhYO_uyupB2NyFtxKbgwAAAH8"]
[Thu Jul 30 14:09:20.621629 2026] [security2:error] [pid 1004636:tid 1004855] [client 189.6.88.213:49366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhYO_uyupB2NyFtxKbhAAAAB8"]
[Thu Jul 30 14:09:20.621721 2026] [security2:error] [pid 1004636:tid 1004855] [client 189.6.88.213:49366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhYO_uyupB2NyFtxKbhAAAAB8"]
[Thu Jul 30 14:09:20.877197 2026] [security2:error] [pid 1004636:tid 1004887] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dyui.php"] [unique_id "amuhYO_uyupB2NyFtxKbkAAAAD4"]
[Thu Jul 30 14:09:20.877292 2026] [security2:error] [pid 1004636:tid 1004887] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/dyui.php"] [unique_id "amuhYO_uyupB2NyFtxKbkAAAAD4"]
[Thu Jul 30 14:09:21.000367 2026] [security2:error] [pid 1004636:tid 1004946] [client 135.119.63.61:33622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/admwp.php"] [unique_id "amuhYO_uyupB2NyFtxKbkQAAAHY"]
[Thu Jul 30 14:09:21.146045 2026] [security2:error] [pid 1004636:tid 1004840] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ho.php"] [unique_id "amuhYe_uyupB2NyFtxKbkgAAABE"]
[Thu Jul 30 14:09:21.146161 2026] [security2:error] [pid 1004636:tid 1004840] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ho.php"] [unique_id "amuhYe_uyupB2NyFtxKbkgAAABE"]
[Thu Jul 30 14:09:21.147937 2026] [core:notice] [pid 1004636:tid 1004812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:21.288950 2026] [security2:error] [pid 1004636:tid 1004842] [client 20.215.191.139:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/css.php"] [unique_id "amuhYe_uyupB2NyFtxKbmwAAABM"]
[Thu Jul 30 14:09:21.417936 2026] [security2:error] [pid 1004636:tid 1004890] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/66b867516c8f01.php"] [unique_id "amuhYe_uyupB2NyFtxKboAAAAEE"]
[Thu Jul 30 14:09:21.418074 2026] [security2:error] [pid 1004636:tid 1004890] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/66b867516c8f01.php"] [unique_id "amuhYe_uyupB2NyFtxKboAAAAEE"]
[Thu Jul 30 14:09:21.464723 2026] [security2:error] [pid 1004636:tid 1004841] [client 191.232.199.39:4505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuhYe_uyupB2NyFtxKboQAAABI"]
[Thu Jul 30 14:09:21.477095 2026] [security2:error] [pid 1004636:tid 1004931] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhYO_uyupB2NyFtxKbjwAAaFk"]
[Thu Jul 30 14:09:21.694564 2026] [security2:error] [pid 1004636:tid 1004928] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ext.php"] [unique_id "amuhYe_uyupB2NyFtxKbowAAAGU"]
[Thu Jul 30 14:09:21.694704 2026] [security2:error] [pid 1004636:tid 1004928] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/ext.php"] [unique_id "amuhYe_uyupB2NyFtxKbowAAAGU"]
[Thu Jul 30 14:09:21.963514 2026] [security2:error] [pid 1004636:tid 1004823] [client 181.116.200.68:27227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhYe_uyupB2NyFtxKbrwAAAAE"]
[Thu Jul 30 14:09:21.964211 2026] [security2:error] [pid 1004636:tid 1004823] [client 181.116.200.68:27227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhYe_uyupB2NyFtxKbrwAAAAE"]
[Thu Jul 30 14:09:21.965875 2026] [security2:error] [pid 1004636:tid 1004839] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuhYe_uyupB2NyFtxKbsAAAABA"]
[Thu Jul 30 14:09:21.965953 2026] [security2:error] [pid 1004636:tid 1004839] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuhYe_uyupB2NyFtxKbsAAAABA"]
[Thu Jul 30 14:09:22.190141 2026] [security2:error] [pid 1004636:tid 1004873] [client 135.119.63.61:33612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/adriv.php"] [unique_id "amuhYu_uyupB2NyFtxKbsgAAADE"]
[Thu Jul 30 14:09:22.238050 2026] [security2:error] [pid 1004636:tid 1004871] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuhYu_uyupB2NyFtxKbtgAAAC8"]
[Thu Jul 30 14:09:22.238184 2026] [security2:error] [pid 1004636:tid 1004871] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuhYu_uyupB2NyFtxKbtgAAAC8"]
[Thu Jul 30 14:09:22.379953 2026] [core:notice] [pid 1004636:tid 1004701] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:22.511280 2026] [security2:error] [pid 1004636:tid 1004909] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/584062352875874akp.php"] [unique_id "amuhYu_uyupB2NyFtxKbvgAAAFM"]
[Thu Jul 30 14:09:22.511388 2026] [security2:error] [pid 1004636:tid 1004909] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/584062352875874akp.php"] [unique_id "amuhYu_uyupB2NyFtxKbvgAAAFM"]
[Thu Jul 30 14:09:22.591040 2026] [security2:error] [pid 1004636:tid 1004955] [client 85.208.98.18:24592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amuhYu_uyupB2NyFtxKbvwAAAH8"]
[Thu Jul 30 14:09:22.591170 2026] [security2:error] [pid 1004636:tid 1004955] [client 85.208.98.18:24592] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amuhYu_uyupB2NyFtxKbvwAAAH8"]
[Thu Jul 30 14:09:22.647668 2026] [security2:error] [pid 1004636:tid 1004847] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhYu_uyupB2NyFtxKbsQAAGEU"]
[Thu Jul 30 14:09:22.782690 2026] [security2:error] [pid 1004636:tid 1004907] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/diidi.php"] [unique_id "amuhYu_uyupB2NyFtxKbxAAAAFE"]
[Thu Jul 30 14:09:22.782784 2026] [security2:error] [pid 1004636:tid 1004907] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/diidi.php"] [unique_id "amuhYu_uyupB2NyFtxKbxAAAAFE"]
[Thu Jul 30 14:09:22.828464 2026] [security2:error] [pid 1004636:tid 1004903] [client 144.172.114.51:47098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/.env.old"] [unique_id "amuhYu_uyupB2NyFtxKbxQAAAE0"]
[Thu Jul 30 14:09:22.879148 2026] [security2:error] [pid 1004636:tid 1004930] [client 20.215.191.139:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/database.php"] [unique_id "amuhYu_uyupB2NyFtxKbyQAAAGc"]
[Thu Jul 30 14:09:23.067770 2026] [security2:error] [pid 1004636:tid 1004833] [client 74.248.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/clarebypas.php"] [unique_id "amuhY-_uyupB2NyFtxKbzQAAAAs"]
[Thu Jul 30 14:09:23.067884 2026] [security2:error] [pid 1004636:tid 1004833] [client 74.248.24.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/clarebypas.php"] [unique_id "amuhY-_uyupB2NyFtxKbzQAAAAs"]
[Thu Jul 30 14:09:23.196938 2026] [security2:error] [pid 1004636:tid 1004911] [client 191.232.199.39:36438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuhY-_uyupB2NyFtxKbzgAAAFU"]
[Thu Jul 30 14:09:23.273222 2026] [security2:error] [pid 1004636:tid 1004920] [client 135.119.63.61:33625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/ads.php"] [unique_id "amuhY-_uyupB2NyFtxKbzwAAAF4"]
[Thu Jul 30 14:09:23.310024 2026] [security2:error] [pid 1004636:tid 1004705] [remote 57.141.0.24:35406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JSHR/about/submissions"] [unique_id "amuhY-_uyupB2NyFtxKb0gAAaRE"]
[Thu Jul 30 14:09:24.045307 2026] [security2:error] [pid 1004636:tid 1004931] [client 47.128.48.23:64880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/robots.txt"] [unique_id "amuhZO_uyupB2NyFtxKb5wAAAGg"]
[Thu Jul 30 14:09:24.376033 2026] [security2:error] [pid 1004636:tid 1004914] [client 135.119.63.61:33645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/ae.php"] [unique_id "amuhZO_uyupB2NyFtxKb7gAAAFg"]
[Thu Jul 30 14:09:24.432428 2026] [security2:error] [pid 1004636:tid 1004879] [client 191.232.199.39:42298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/edit.php"] [unique_id "amuhZO_uyupB2NyFtxKb8gAAADc"]
[Thu Jul 30 14:09:24.435512 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.215.191.139:58078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/db.php"] [unique_id "amuhZO_uyupB2NyFtxKb8wAAACQ"]
[Thu Jul 30 14:09:25.070594 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.215.191.139:50175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/default.php"] [unique_id "amuhZe_uyupB2NyFtxKcAAAAABQ"]
[Thu Jul 30 14:09:25.557253 2026] [security2:error] [pid 1004636:tid 1004852] [client 135.119.63.61:33659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/af32.php"] [unique_id "amuhZe_uyupB2NyFtxKcCAAAAB0"]
[Thu Jul 30 14:09:25.602873 2026] [core:notice] [pid 1004636:tid 1004736] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:25.874062 2026] [security2:error] [pid 1004636:tid 1004901] [client 191.232.199.39:48586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/2.php"] [unique_id "amuhZe_uyupB2NyFtxKcDwAAAEs"]
[Thu Jul 30 14:09:26.261397 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.215.191.139:49919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/dropdown.php"] [unique_id "amuhZu_uyupB2NyFtxKcGQAAAAk"]
[Thu Jul 30 14:09:26.836306 2026] [core:notice] [pid 1004636:tid 1004863] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:27.378720 2026] [security2:error] [pid 1004636:tid 1004937] [client 20.215.191.139:50203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/edit.php"] [unique_id "amuhZ-_uyupB2NyFtxKcLwAAAG0"]
[Thu Jul 30 14:09:27.428284 2026] [security2:error] [pid 1004636:tid 1004924] [client 135.119.63.61:13710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/afnew.php"] [unique_id "amuhZ-_uyupB2NyFtxKcMAAAAGE"]
[Thu Jul 30 14:09:28.022599 2026] [security2:error] [pid 1004636:tid 1004846] [client 20.215.191.139:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/f35.php"] [unique_id "amuhaO_uyupB2NyFtxKcPwAAABc"]
[Thu Jul 30 14:09:28.179326 2026] [security2:error] [pid 1004636:tid 1004892] [client 191.232.199.39:36447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuhaO_uyupB2NyFtxKcQwAAAEM"]
[Thu Jul 30 14:09:28.424881 2026] [security2:error] [pid 1004636:tid 1004857] [client 135.119.63.61:13868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/ah.php"] [unique_id "amuhaO_uyupB2NyFtxKcTAAAACE"]
[Thu Jul 30 14:09:29.482359 2026] [security2:error] [pid 1004636:tid 1004929] [client 135.119.63.61:14293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/ahax.php"] [unique_id "amuhae_uyupB2NyFtxKcbgAAAGY"]
[Thu Jul 30 14:09:29.649347 2026] [security2:error] [pid 1004636:tid 1004856] [client 103.190.40.154:19209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhae_uyupB2NyFtxKcbwAAACA"]
[Thu Jul 30 14:09:29.649497 2026] [security2:error] [pid 1004636:tid 1004856] [client 103.190.40.154:19209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhae_uyupB2NyFtxKcbwAAACA"]
[Thu Jul 30 14:09:30.351694 2026] [security2:error] [pid 1004636:tid 1004937] [client 191.232.199.39:4981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/mah.php"] [unique_id "amuhau_uyupB2NyFtxKciAAAAG0"]
[Thu Jul 30 14:09:30.475564 2026] [security2:error] [pid 1004636:tid 1004843] [client 24.206.65.32:55269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuhau_uyupB2NyFtxKcjAAAFHk"], referer: https://www.northyorksheridanmall.com/store/
[Thu Jul 30 14:09:30.565339 2026] [security2:error] [pid 1004636:tid 1004914] [client 20.215.191.139:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/f7.php"] [unique_id "amuhau_uyupB2NyFtxKckgAAAFg"]
[Thu Jul 30 14:09:30.669694 2026] [security2:error] [pid 1004636:tid 1004811] [remote 47.128.24.52:23508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-mevius.com"] [uri "/product/marlboro-12/"] [unique_id "amuhau_uyupB2NyFtxKckwAAT3c"]
[Thu Jul 30 14:09:30.717998 2026] [security2:error] [pid 1004636:tid 1004855] [client 144.172.114.51:44792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecre.ae"] [uri "/wp-config.php"] [unique_id "amuhau_uyupB2NyFtxKckAAAAB8"]
[Thu Jul 30 14:09:31.414225 2026] [security2:error] [pid 1004636:tid 1004851] [client 189.6.88.213:50175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuha-_uyupB2NyFtxKcoQAAABw"]
[Thu Jul 30 14:09:31.414324 2026] [security2:error] [pid 1004636:tid 1004851] [client 189.6.88.213:50175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuha-_uyupB2NyFtxKcoQAAABw"]
[Thu Jul 30 14:09:31.641853 2026] [security2:error] [pid 1004636:tid 1004953] [client 191.232.199.39:4718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/send.php"] [unique_id "amuha-_uyupB2NyFtxKcqQAAAH0"]
[Thu Jul 30 14:09:31.651972 2026] [security2:error] [pid 1004636:tid 1004955] [client 135.119.63.61:14284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/ai.php"] [unique_id "amuha-_uyupB2NyFtxKcqgAAAH8"]
[Thu Jul 30 14:09:32.626023 2026] [security2:error] [pid 1004636:tid 1004929] [client 181.116.200.68:38303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhbO_uyupB2NyFtxKcxQAAAGY"]
[Thu Jul 30 14:09:32.626144 2026] [security2:error] [pid 1004636:tid 1004929] [client 181.116.200.68:38303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhbO_uyupB2NyFtxKcxQAAAGY"]
[Thu Jul 30 14:09:32.993306 2026] [security2:error] [pid 1004636:tid 1004944] [client 191.232.199.39:4719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuhbO_uyupB2NyFtxKczAAAAHQ"]
[Thu Jul 30 14:09:33.279191 2026] [security2:error] [pid 1004636:tid 1004832] [client 135.119.63.61:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/ajax-actions.php"] [unique_id "amuhbe_uyupB2NyFtxKc0QAAAAo"]
[Thu Jul 30 14:09:33.858390 2026] [core:notice] [pid 1004636:tid 1004819] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:34.450996 2026] [autoindex:error] [pid 1004636:tid 1004884] [client 191.232.199.39:0] AH01276: Cannot serve directory /home1/bahdjbte/public_html/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:34.499780 2026] [autoindex:error] [pid 1004636:tid 1004954] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-content/plugins/contact-form-7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:09:34.500467 2026] [security2:error] [pid 1004636:tid 1004954] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhbu_uyupB2NyFtxKc-gAAAH4"]
[Thu Jul 30 14:09:34.500819 2026] [security2:error] [pid 1004636:tid 1004856] [client 82.102.18.180:53986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "amuhbu_uyupB2NyFtxKc9wAAACA"]
[Thu Jul 30 14:09:34.690149 2026] [security2:error] [pid 1004636:tid 1004861] [client 135.119.63.61:13534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/ak.php"] [unique_id "amuhbu_uyupB2NyFtxKdAAAAACU"]
[Thu Jul 30 14:09:34.780951 2026] [core:error] [pid 1004636:tid 1004866] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:34.780973 2026] [core:error] [pid 1004636:tid 1004866] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:34.799594 2026] [security2:error] [pid 1004636:tid 1004879] [client 191.232.199.39:48596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/about.php"] [unique_id "amuhbu_uyupB2NyFtxKdAwAAADc"]
[Thu Jul 30 14:09:34.962370 2026] [fcgid:warn] [pid 1004636:tid 1004864] (70014)End of file found: [client 118.26.38.251:60356] mod_fcgid: can't get data from http client
[Thu Jul 30 14:09:34.990959 2026] [core:notice] [pid 1004636:tid 1004906] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:35.013603 2026] [security2:error] [pid 1004636:tid 1004916] [client 18.116.205.62:11134] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuhbu_uyupB2NyFtxKdBAAAAFo"], referer: https://globalmarks.pk/
[Thu Jul 30 14:09:35.100265 2026] [security2:error] [pid 1004636:tid 1004924] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhbu_uyupB2NyFtxKdBwAAAGE"]
[Thu Jul 30 14:09:35.100290 2026] [security2:error] [pid 1004636:tid 1004924] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhbu_uyupB2NyFtxKdBwAAAGE"]
[Thu Jul 30 14:09:35.100618 2026] [security2:error] [pid 1004636:tid 1004822] [client 82.102.18.180:53986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wordpress/"] [unique_id "amuhbu_uyupB2NyFtxKdBQAAAAA"]
[Thu Jul 30 14:09:35.448500 2026] [core:notice] [pid 1004636:tid 1004832] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:35.621614 2026] [security2:error] [pid 1004636:tid 1004854] [client 135.119.63.61:13448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/akc.php"] [unique_id "amuhb-_uyupB2NyFtxKdHAAAAB4"]
[Thu Jul 30 14:09:35.759240 2026] [security2:error] [pid 1004636:tid 1004899] [client 185.191.171.13:41700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/03/transicao-propoe-pec-para-viabilizar-propostas-de-campanha-de-lula/"] [unique_id "amuhb-_uyupB2NyFtxKdIQAAAEk"]
[Thu Jul 30 14:09:35.759346 2026] [security2:error] [pid 1004636:tid 1004899] [client 185.191.171.13:41700] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/03/transicao-propoe-pec-para-viabilizar-propostas-de-campanha-de-lula/"] [unique_id "amuhb-_uyupB2NyFtxKdIQAAAEk"]
[Thu Jul 30 14:09:35.781907 2026] [security2:error] [pid 1004636:tid 1004714] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.homemoversandpackersabudhabi.fit"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuhb-_uyupB2NyFtxKdIgAAHRk"]
[Thu Jul 30 14:09:36.187031 2026] [security2:error] [pid 1004636:tid 1004909] [client 191.232.199.39:48857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/options.php"] [unique_id "amuhcO_uyupB2NyFtxKdKwAAAFM"]
[Thu Jul 30 14:09:36.243733 2026] [security2:error] [pid 1004636:tid 1004953] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.homemoversandpackersabudhabi.fit"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuhcO_uyupB2NyFtxKdLgAAAH0"]
[Thu Jul 30 14:09:36.676183 2026] [security2:error] [pid 1004636:tid 1004858] [client 135.119.63.61:13445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/akcc.php"] [unique_id "amuhcO_uyupB2NyFtxKdOgAAACI"]
[Thu Jul 30 14:09:37.533217 2026] [security2:error] [pid 1004636:tid 1004906] [client 135.119.63.61:13497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/akp.php"] [unique_id "amuhce_uyupB2NyFtxKdTwAAAFA"]
[Thu Jul 30 14:09:38.465109 2026] [security2:error] [pid 1004636:tid 1004951] [client 191.232.199.39:48863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuhcu_uyupB2NyFtxKdZQAAAHs"]
[Thu Jul 30 14:09:38.477696 2026] [security2:error] [pid 1004636:tid 1004857] [client 135.119.63.61:34458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/aks.php"] [unique_id "amuhcu_uyupB2NyFtxKdZgAAACE"]
[Thu Jul 30 14:09:39.284691 2026] [security2:error] [pid 1004636:tid 1004867] [client 135.119.63.61:28581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/aksinet.php"] [unique_id "amuhc-_uyupB2NyFtxKdeQAAACs"]
[Thu Jul 30 14:09:39.541840 2026] [security2:error] [pid 1004636:tid 1004903] [client 144.172.114.51:44802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ecre.ae"] [uri "/wp-config.php.old"] [unique_id "amuhc-_uyupB2NyFtxKdfQAAAE0"]
[Thu Jul 30 14:09:39.933788 2026] [security2:error] [pid 1004636:tid 1004825] [client 191.232.199.39:48877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-file.php"] [unique_id "amuhc-_uyupB2NyFtxKdhAAAAAM"]
[Thu Jul 30 14:09:40.410991 2026] [security2:error] [pid 1004636:tid 1004914] [client 103.190.40.154:19259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhdO_uyupB2NyFtxKdkgAAAFg"]
[Thu Jul 30 14:09:40.411177 2026] [security2:error] [pid 1004636:tid 1004914] [client 103.190.40.154:19259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhdO_uyupB2NyFtxKdkgAAAFg"]
[Thu Jul 30 14:09:40.583660 2026] [security2:error] [pid 1004636:tid 1004917] [client 135.119.63.61:22388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/al.php"] [unique_id "amuhdO_uyupB2NyFtxKdlgAAAFs"]
[Thu Jul 30 14:09:41.802235 2026] [security2:error] [pid 1004636:tid 1004953] [client 191.232.199.39:48627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/sid3.php"] [unique_id "amuhde_uyupB2NyFtxKdrwAAAH0"]
[Thu Jul 30 14:09:42.184090 2026] [security2:error] [pid 1004636:tid 1004896] [client 189.6.88.213:50722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhdu_uyupB2NyFtxKduQAAAEY"]
[Thu Jul 30 14:09:42.184209 2026] [security2:error] [pid 1004636:tid 1004896] [client 189.6.88.213:50722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhdu_uyupB2NyFtxKduQAAAEY"]
[Thu Jul 30 14:09:42.278600 2026] [core:notice] [pid 1004636:tid 1004873] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:42.282393 2026] [security2:error] [pid 1004636:tid 1004886] [client 135.119.63.61:22348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alera/alpha.php"] [unique_id "amuhdu_uyupB2NyFtxKduwAAAD0"]
[Thu Jul 30 14:09:43.103181 2026] [core:notice] [pid 1004636:tid 1004942] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:43.104265 2026] [core:notice] [pid 1004636:tid 1004915] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:43.185384 2026] [security2:error] [pid 1004636:tid 1004929] [client 181.116.200.68:58318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhd-_uyupB2NyFtxKd1gAAAGY"]
[Thu Jul 30 14:09:43.185515 2026] [security2:error] [pid 1004636:tid 1004929] [client 181.116.200.68:58318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhd-_uyupB2NyFtxKd1gAAAGY"]
[Thu Jul 30 14:09:43.469441 2026] [security2:error] [pid 1004636:tid 1004822] [client 135.119.63.61:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alexus.php"] [unique_id "amuhd-_uyupB2NyFtxKd3QAAAAA"]
[Thu Jul 30 14:09:44.508765 2026] [security2:error] [pid 1004636:tid 1004863] [client 135.119.63.61:20462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alexuse.php"] [unique_id "amuheO_uyupB2NyFtxKd9AAAACc"]
[Thu Jul 30 14:09:45.050616 2026] [security2:error] [pid 1004636:tid 1004864] [client 144.172.114.51:60360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ecre.ae"] [uri "/wp-config.php~"] [unique_id "amuhee_uyupB2NyFtxKeAwAAACg"]
[Thu Jul 30 14:09:45.142239 2026] [security2:error] [pid 1004636:tid 1004825] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuhee_uyupB2NyFtxKeBQAAAAM"]
[Thu Jul 30 14:09:45.142348 2026] [security2:error] [pid 1004636:tid 1004825] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuhee_uyupB2NyFtxKeBQAAAAM"]
[Thu Jul 30 14:09:45.155739 2026] [core:notice] [pid 1004636:tid 1004754] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:45.562504 2026] [security2:error] [pid 1004636:tid 1004885] [client 43.173.175.172:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.175.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/09/04/10-chaussures-reperees-rentree-2014/"] [unique_id "amuhee_uyupB2NyFtxKeCAAAADw"]
[Thu Jul 30 14:09:45.645331 2026] [security2:error] [pid 1004636:tid 1004917] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuhee_uyupB2NyFtxKeGQAAAFs"]
[Thu Jul 30 14:09:45.645421 2026] [security2:error] [pid 1004636:tid 1004917] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuhee_uyupB2NyFtxKeGQAAAFs"]
[Thu Jul 30 14:09:45.813285 2026] [security2:error] [pid 1004636:tid 1004834] [client 135.119.63.61:13673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alexusmailer-2.0.php"] [unique_id "amuhee_uyupB2NyFtxKeHQAAAAw"]
[Thu Jul 30 14:09:45.914070 2026] [core:notice] [pid 1004636:tid 1004874] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:46.186648 2026] [security2:error] [pid 1004636:tid 1004947] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/bootstrap.php"] [unique_id "amuheu_uyupB2NyFtxKeJgAAAHc"]
[Thu Jul 30 14:09:46.186756 2026] [security2:error] [pid 1004636:tid 1004947] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/bootstrap.php"] [unique_id "amuheu_uyupB2NyFtxKeJgAAAHc"]
[Thu Jul 30 14:09:46.187519 2026] [core:notice] [pid 1004636:tid 1004900] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:46.193562 2026] [security2:error] [pid 1004636:tid 1004900] [client 43.172.194.41:45728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/09/04/10-chaussures-reperees-rentree-2014/"] [unique_id "amuheu_uyupB2NyFtxKeJQAAAEo"], referer: https://carnetdeshopping.com/index.php/2014/09/04/10-chaussures-reperees-rentree-2014/?replytocom=1341
[Thu Jul 30 14:09:46.717346 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-blog-header.php"] [unique_id "amuheu_uyupB2NyFtxKeMQAAAA8"]
[Thu Jul 30 14:09:46.717455 2026] [security2:error] [pid 1004636:tid 1004838] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-blog-header.php"] [unique_id "amuheu_uyupB2NyFtxKeMQAAAA8"]
[Thu Jul 30 14:09:46.913873 2026] [security2:error] [pid 1004636:tid 1004851] [client 135.119.63.61:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alf.php"] [unique_id "amuheu_uyupB2NyFtxKeNgAAABw"]
[Thu Jul 30 14:09:47.261910 2026] [security2:error] [pid 1004636:tid 1004926] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-load.php"] [unique_id "amuhe-_uyupB2NyFtxKePwAAAGM"]
[Thu Jul 30 14:09:47.262025 2026] [security2:error] [pid 1004636:tid 1004926] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-load.php"] [unique_id "amuhe-_uyupB2NyFtxKePwAAAGM"]
[Thu Jul 30 14:09:47.804510 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/edit.php"] [unique_id "amuhe-_uyupB2NyFtxKeTQAAAHw"]
[Thu Jul 30 14:09:47.804687 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/edit.php"] [unique_id "amuhe-_uyupB2NyFtxKeTQAAAHw"]
[Thu Jul 30 14:09:48.071890 2026] [security2:error] [pid 1004636:tid 1004886] [client 135.119.63.61:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alf4.php"] [unique_id "amuhfO_uyupB2NyFtxKeUwAAAD0"]
[Thu Jul 30 14:09:48.342968 2026] [security2:error] [pid 1004636:tid 1004849] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/cgi-bin"] [unique_id "amuhfO_uyupB2NyFtxKeWgAAABo"]
[Thu Jul 30 14:09:48.355412 2026] [security2:error] [pid 1004636:tid 1004768] [remote 57.141.0.8:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amuhfO_uyupB2NyFtxKeWwAALU0"]
[Thu Jul 30 14:09:48.425735 2026] [core:error] [pid 1004636:tid 1004912] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:48.425761 2026] [core:error] [pid 1004636:tid 1004912] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:48.906788 2026] [security2:error] [pid 1004636:tid 1004924] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuhfO_uyupB2NyFtxKebAAAAGE"]
[Thu Jul 30 14:09:49.189628 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/mah.php"] [unique_id "amuhfe_uyupB2NyFtxKecwAAAC4"]
[Thu Jul 30 14:09:49.189781 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/mah.php"] [unique_id "amuhfe_uyupB2NyFtxKecwAAAC4"]
[Thu Jul 30 14:09:49.236194 2026] [security2:error] [pid 1004636:tid 1004865] [client 20.104.18.253:44604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/011i.php"] [unique_id "amuhfe_uyupB2NyFtxKedwAAACk"]
[Thu Jul 30 14:09:49.482674 2026] [security2:error] [pid 1004636:tid 1004863] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/archive.php"] [unique_id "amuhfe_uyupB2NyFtxKeeAAAACc"]
[Thu Jul 30 14:09:49.482804 2026] [security2:error] [pid 1004636:tid 1004863] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/archive.php"] [unique_id "amuhfe_uyupB2NyFtxKeeAAAACc"]
[Thu Jul 30 14:09:49.512208 2026] [security2:error] [pid 1004636:tid 1004940] [client 135.119.63.61:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alfa-ioxi.php"] [unique_id "amuhfe_uyupB2NyFtxKeeQAAAHA"]
[Thu Jul 30 14:09:50.013738 2026] [security2:error] [pid 1004636:tid 1004856] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/hosty.php"] [unique_id "amuhfu_uyupB2NyFtxKehAAAACA"]
[Thu Jul 30 14:09:50.013855 2026] [security2:error] [pid 1004636:tid 1004856] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/hosty.php"] [unique_id "amuhfu_uyupB2NyFtxKehAAAACA"]
[Thu Jul 30 14:09:50.216327 2026] [security2:error] [pid 1004636:tid 1004861] [client 20.104.18.253:42236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/03a005685d.php"] [unique_id "amuhfu_uyupB2NyFtxKeiQAAACU"]
[Thu Jul 30 14:09:50.609954 2026] [security2:error] [pid 1004636:tid 1004925] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/wp-includes/Text/Diff/"] [unique_id "amuhfu_uyupB2NyFtxKekgAAAGI"]
[Thu Jul 30 14:09:50.885120 2026] [security2:error] [pid 1004636:tid 1004862] [client 135.119.63.61:27208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alfa-rex.php"] [unique_id "amuhfu_uyupB2NyFtxKelgAAACY"]
[Thu Jul 30 14:09:50.943154 2026] [security2:error] [pid 1004636:tid 1004836] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuhfu_uyupB2NyFtxKemgAAAA4"]
[Thu Jul 30 14:09:50.998680 2026] [security2:error] [pid 1004636:tid 1004914] [client 20.104.18.253:28424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/403.php"] [unique_id "amuhfu_uyupB2NyFtxKemwAAAFg"]
[Thu Jul 30 14:09:51.267585 2026] [security2:error] [pid 1004636:tid 1004891] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/admin.php"] [unique_id "amuhf-_uyupB2NyFtxKeogAAAEI"]
[Thu Jul 30 14:09:51.267702 2026] [security2:error] [pid 1004636:tid 1004891] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/admin.php"] [unique_id "amuhf-_uyupB2NyFtxKeogAAAEI"]
[Thu Jul 30 14:09:51.832111 2026] [security2:error] [pid 1004636:tid 1004890] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/av.php"] [unique_id "amuhf-_uyupB2NyFtxKesAAAAEE"]
[Thu Jul 30 14:09:51.832222 2026] [security2:error] [pid 1004636:tid 1004890] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/av.php"] [unique_id "amuhf-_uyupB2NyFtxKesAAAAEE"]
[Thu Jul 30 14:09:51.837342 2026] [security2:error] [pid 1004636:tid 1004876] [client 135.119.63.61:20421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alfa-shell-v4.php"] [unique_id "amuhf-_uyupB2NyFtxKesQAAADQ"]
[Thu Jul 30 14:09:51.845486 2026] [security2:error] [pid 1004636:tid 1004924] [client 20.104.18.253:40934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/404.php"] [unique_id "amuhf-_uyupB2NyFtxKesgAAAGE"]
[Thu Jul 30 14:09:52.389646 2026] [security2:error] [pid 1004636:tid 1004850] [client 103.190.40.154:19238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhgO_uyupB2NyFtxKewAAAABs"]
[Thu Jul 30 14:09:52.389809 2026] [security2:error] [pid 1004636:tid 1004850] [client 103.190.40.154:19238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhgO_uyupB2NyFtxKewAAAABs"]
[Thu Jul 30 14:09:52.392750 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/shell.php"] [unique_id "amuhgO_uyupB2NyFtxKewQAAAAg"]
[Thu Jul 30 14:09:52.392899 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/shell.php"] [unique_id "amuhgO_uyupB2NyFtxKewQAAAAg"]
[Thu Jul 30 14:09:52.436747 2026] [security2:error] [pid 1004636:tid 1004918] [client 74.7.241.155:42844] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kicksity.com"] [uri "/index.html"] [unique_id "amuhgO_uyupB2NyFtxKetwAAXBg"], referer: https://viplangit69.com/robots.txt
[Thu Jul 30 14:09:52.737274 2026] [security2:error] [pid 1004636:tid 1004856] [client 20.104.18.253:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/aa.php"] [unique_id "amuhgO_uyupB2NyFtxKezQAAACA"]
[Thu Jul 30 14:09:52.845061 2026] [security2:error] [pid 1004636:tid 1004934] [client 135.119.63.61:26573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alfa-v4.php"] [unique_id "amuhgO_uyupB2NyFtxKe0QAAAGs"]
[Thu Jul 30 14:09:53.013002 2026] [security2:error] [pid 1004636:tid 1004847] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/storage/index.php"] [unique_id "amuhge_uyupB2NyFtxKe0gAAABg"]
[Thu Jul 30 14:09:53.013152 2026] [security2:error] [pid 1004636:tid 1004847] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/storage/index.php"] [unique_id "amuhge_uyupB2NyFtxKe0gAAABg"]
[Thu Jul 30 14:09:53.646568 2026] [security2:error] [pid 1004636:tid 1004857] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/w.php"] [unique_id "amuhge_uyupB2NyFtxKe5QAAACE"]
[Thu Jul 30 14:09:53.646698 2026] [security2:error] [pid 1004636:tid 1004857] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/w.php"] [unique_id "amuhge_uyupB2NyFtxKe5QAAACE"]
[Thu Jul 30 14:09:53.833589 2026] [security2:error] [pid 1004636:tid 1004833] [client 181.116.200.68:62766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhge_uyupB2NyFtxKe7AAAAAs"]
[Thu Jul 30 14:09:53.833729 2026] [security2:error] [pid 1004636:tid 1004833] [client 181.116.200.68:62766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhge_uyupB2NyFtxKe7AAAAAs"]
[Thu Jul 30 14:09:53.937452 2026] [security2:error] [pid 1004636:tid 1004862] [client 189.6.88.213:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhge_uyupB2NyFtxKe8QAAACY"]
[Thu Jul 30 14:09:53.937589 2026] [security2:error] [pid 1004636:tid 1004862] [client 189.6.88.213:51290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhge_uyupB2NyFtxKe8QAAACY"]
[Thu Jul 30 14:09:54.106375 2026] [security2:error] [pid 1004636:tid 1004955] [client 135.119.63.61:27257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alfa.php"] [unique_id "amuhgu_uyupB2NyFtxKe9QAAAH8"]
[Thu Jul 30 14:09:54.196218 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/jp.php"] [unique_id "amuhgu_uyupB2NyFtxKe9gAAAC4"]
[Thu Jul 30 14:09:54.196359 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/jp.php"] [unique_id "amuhgu_uyupB2NyFtxKe9gAAAC4"]
[Thu Jul 30 14:09:54.667777 2026] [core:notice] [pid 1004636:tid 1004858] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:09:54.776427 2026] [authz_core:error] [pid 1004636:tid 1004850] [client 20.9.4.9:0] AH01630: client denied by server configuration: /home1/vwhhflte/public_html/website_ffa422ec/php.ini
[Thu Jul 30 14:09:54.777172 2026] [security2:error] [pid 1004636:tid 1004850] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "propertyspro.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhgu_uyupB2NyFtxKfAgAAABs"]
[Thu Jul 30 14:09:54.981445 2026] [security2:error] [pid 1004636:tid 1004949] [client 135.119.63.61:26623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/alfa123.php"] [unique_id "amuhgu_uyupB2NyFtxKfCgAAAHk"]
[Thu Jul 30 14:09:55.095321 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/ws77.php"] [unique_id "amuhg-_uyupB2NyFtxKfCwAAAAE"]
[Thu Jul 30 14:09:55.095426 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/ws77.php"] [unique_id "amuhg-_uyupB2NyFtxKfCwAAAAE"]
[Thu Jul 30 14:09:55.416013 2026] [security2:error] [pid 1004636:tid 1004855] [client 20.104.18.253:44555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/aafewc0k.php"] [unique_id "amuhg-_uyupB2NyFtxKfFQAAAB8"]
[Thu Jul 30 14:09:55.726696 2026] [security2:error] [pid 1004636:tid 1004866] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/blass.php"] [unique_id "amuhg-_uyupB2NyFtxKfHAAAACo"]
[Thu Jul 30 14:09:55.726792 2026] [security2:error] [pid 1004636:tid 1004866] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/blass.php"] [unique_id "amuhg-_uyupB2NyFtxKfHAAAACo"]
[Thu Jul 30 14:09:55.800040 2026] [security2:error] [pid 1004636:tid 1004930] [client 144.172.114.51:57558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuhg-_uyupB2NyFtxKfHQAAAGc"]
[Thu Jul 30 14:09:56.187534 2026] [security2:error] [pid 1004636:tid 1004926] [client 20.104.18.253:55225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/abcd.php"] [unique_id "amuhhO_uyupB2NyFtxKfKQAAAGM"]
[Thu Jul 30 14:09:56.263717 2026] [security2:error] [pid 1004636:tid 1004857] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-info.php"] [unique_id "amuhhO_uyupB2NyFtxKfKgAAACE"]
[Thu Jul 30 14:09:56.263828 2026] [security2:error] [pid 1004636:tid 1004857] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-info.php"] [unique_id "amuhhO_uyupB2NyFtxKfKgAAACE"]
[Thu Jul 30 14:09:56.830318 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/CDX1.php"] [unique_id "amuhhO_uyupB2NyFtxKfNwAAAC4"]
[Thu Jul 30 14:09:56.830511 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/CDX1.php"] [unique_id "amuhhO_uyupB2NyFtxKfNwAAAC4"]
[Thu Jul 30 14:09:57.233206 2026] [security2:error] [pid 1004636:tid 1004936] [client 20.104.18.253:52760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/about.php"] [unique_id "amuhhe_uyupB2NyFtxKfSAAAAGw"]
[Thu Jul 30 14:09:57.370912 2026] [security2:error] [pid 1004636:tid 1004896] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wpc.php"] [unique_id "amuhhe_uyupB2NyFtxKfTAAAAEY"]
[Thu Jul 30 14:09:57.371048 2026] [security2:error] [pid 1004636:tid 1004896] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wpc.php"] [unique_id "amuhhe_uyupB2NyFtxKfTAAAAEY"]
[Thu Jul 30 14:09:57.374944 2026] [security2:error] [pid 1004636:tid 1004868] [client 144.172.114.51:57568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecre.ae"] [uri "/phpinfo.php"] [unique_id "amuhhe_uyupB2NyFtxKfTQAAACw"]
[Thu Jul 30 14:09:57.604064 2026] [fcgid:warn] [pid 1004636:tid 1004856] (70014)End of file found: [client 128.14.225.253:42274] mod_fcgid: can't get data from http client
[Thu Jul 30 14:09:57.613558 2026] [security2:error] [pid 1004636:tid 1004824] [client 118.26.38.251:42178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wce.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuhhe_uyupB2NyFtxKfTgAAAAI"]
[Thu Jul 30 14:09:57.903897 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/jga.php"] [unique_id "amuhhe_uyupB2NyFtxKfXQAAACQ"]
[Thu Jul 30 14:09:57.904036 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/jga.php"] [unique_id "amuhhe_uyupB2NyFtxKfXQAAACQ"]
[Thu Jul 30 14:09:58.496218 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/666.php"] [unique_id "amuhhu_uyupB2NyFtxKfbQAAAEs"]
[Thu Jul 30 14:09:58.496330 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/666.php"] [unique_id "amuhhu_uyupB2NyFtxKfbQAAAEs"]
[Thu Jul 30 14:09:58.584669 2026] [proxy:error] [pid 1004636:tid 1004857] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:09:58.584752 2026] [proxy_http:error] [pid 1004636:tid 1004857] [client 128.14.225.253:42286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:09:58.585342 2026] [proxy:error] [pid 1004636:tid 1004857] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:09:58.585403 2026] [proxy_http:error] [pid 1004636:tid 1004857] [client 128.14.225.253:42286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:09:58.595048 2026] [security2:error] [pid 1004636:tid 1004929] [client 20.104.18.253:22761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/admin.php"] [unique_id "amuhhu_uyupB2NyFtxKfcgAAAGY"]
[Thu Jul 30 14:09:58.837849 2026] [core:error] [pid 1004636:tid 1004945] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:58.837873 2026] [core:error] [pid 1004636:tid 1004945] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:09:59.035995 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/htaccess.php"] [unique_id "amuhh-_uyupB2NyFtxKffgAAAC4"]
[Thu Jul 30 14:09:59.036154 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/htaccess.php"] [unique_id "amuhh-_uyupB2NyFtxKffgAAAC4"]
[Thu Jul 30 14:09:59.377966 2026] [security2:error] [pid 1004636:tid 1004808] [remote 47.128.117.64:16812] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuhh-_uyupB2NyFtxKfiQAAbHQ"]
[Thu Jul 30 14:09:59.477415 2026] [security2:error] [pid 1004636:tid 1004845] [client 20.104.18.253:52782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/adminfuns.php"] [unique_id "amuhh-_uyupB2NyFtxKfiwAAABY"]
[Thu Jul 30 14:09:59.493678 2026] [security2:error] [pid 1004636:tid 1004850] [client 213.152.161.219:60816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuhh-_uyupB2NyFtxKfjAAAABs"]
[Thu Jul 30 14:09:59.493776 2026] [security2:error] [pid 1004636:tid 1004850] [client 213.152.161.219:60816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuhh-_uyupB2NyFtxKfjAAAABs"]
[Thu Jul 30 14:09:59.555790 2026] [security2:error] [pid 1004636:tid 1004873] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/m.php"] [unique_id "amuhh-_uyupB2NyFtxKfjQAAADE"]
[Thu Jul 30 14:09:59.555947 2026] [security2:error] [pid 1004636:tid 1004873] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/m.php"] [unique_id "amuhh-_uyupB2NyFtxKfjQAAADE"]
[Thu Jul 30 14:10:00.105313 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/file.php"] [unique_id "amuhiO_uyupB2NyFtxKfmgAAAFU"]
[Thu Jul 30 14:10:00.105431 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/file.php"] [unique_id "amuhiO_uyupB2NyFtxKfmgAAAFU"]
[Thu Jul 30 14:10:00.121002 2026] [security2:error] [pid 1004636:tid 1004952] [client 145.223.140.108:58976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.140.223.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/2817/1699"] [unique_id "amuhh-_uyupB2NyFtxKfmAAAAHw"]
[Thu Jul 30 14:10:00.328347 2026] [proxy:error] [pid 1004636:tid 1004950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:00.328443 2026] [proxy_http:error] [pid 1004636:tid 1004950] [client 128.14.225.253:42292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:00.329446 2026] [proxy:error] [pid 1004636:tid 1004950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:00.329507 2026] [proxy_http:error] [pid 1004636:tid 1004950] [client 128.14.225.253:42292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:00.634522 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/.dj/index.php"] [unique_id "amuhiO_uyupB2NyFtxKfpgAAAAw"]
[Thu Jul 30 14:10:00.634690 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/.dj/index.php"] [unique_id "amuhiO_uyupB2NyFtxKfpgAAAAw"]
[Thu Jul 30 14:10:00.924623 2026] [security2:error] [pid 1004636:tid 1004914] [client 20.104.18.253:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/albin.php"] [unique_id "amuhiO_uyupB2NyFtxKftQAAAFg"]
[Thu Jul 30 14:10:01.233212 2026] [security2:error] [pid 1004636:tid 1004924] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuhie_uyupB2NyFtxKfuwAAAGE"]
[Thu Jul 30 14:10:01.233309 2026] [security2:error] [pid 1004636:tid 1004924] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuhie_uyupB2NyFtxKfuwAAAGE"]
[Thu Jul 30 14:10:01.647122 2026] [security2:error] [pid 1004636:tid 1004931] [client 118.26.38.251:32838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wce.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuhie_uyupB2NyFtxKfyAAAAGg"]
[Thu Jul 30 14:10:01.728742 2026] [proxy:error] [pid 1004636:tid 1004940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:01.728829 2026] [proxy_http:error] [pid 1004636:tid 1004940] [client 128.14.225.253:32772] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:01.729645 2026] [proxy:error] [pid 1004636:tid 1004940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:01.729698 2026] [proxy_http:error] [pid 1004636:tid 1004940] [client 128.14.225.253:32772] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:01.793939 2026] [security2:error] [pid 1004636:tid 1004873] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/pages.php"] [unique_id "amuhie_uyupB2NyFtxKfzwAAADE"]
[Thu Jul 30 14:10:01.794081 2026] [security2:error] [pid 1004636:tid 1004873] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/pages.php"] [unique_id "amuhie_uyupB2NyFtxKfzwAAADE"]
[Thu Jul 30 14:10:01.954092 2026] [security2:error] [pid 1004636:tid 1004844] [client 20.104.18.253:22774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/amfsqvgv.php"] [unique_id "amuhie_uyupB2NyFtxKf1gAAABU"]
[Thu Jul 30 14:10:02.331907 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/adminfuns.php"] [unique_id "amuhiu_uyupB2NyFtxKf4AAAACQ"]
[Thu Jul 30 14:10:02.332016 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/adminfuns.php"] [unique_id "amuhiu_uyupB2NyFtxKf4AAAACQ"]
[Thu Jul 30 14:10:02.410861 2026] [security2:error] [pid 1004636:tid 1004917] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuhiu_uyupB2NyFtxKf4gAAAFs"]
[Thu Jul 30 14:10:02.411006 2026] [security2:error] [pid 1004636:tid 1004917] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuhiu_uyupB2NyFtxKf4gAAAFs"]
[Thu Jul 30 14:10:02.440101 2026] [security2:error] [pid 1004636:tid 1004904] [client 127.0.0.1:40128] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuhiu_uyupB2NyFtxKf4wAAAE4"]
[Thu Jul 30 14:10:02.440238 2026] [security2:error] [pid 1004636:tid 1004856] [client 74.7.244.20:55564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bitcoinfungibletoken.com"] [uri "/robots.txt"] [unique_id "amuhiu_uyupB2NyFtxKf4QAAACA"]
[Thu Jul 30 14:10:02.664525 2026] [security2:error] [pid 1004636:tid 1004834] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuhiu_uyupB2NyFtxKf6AAAAAw"]
[Thu Jul 30 14:10:02.664682 2026] [security2:error] [pid 1004636:tid 1004834] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuhiu_uyupB2NyFtxKf6AAAAAw"]
[Thu Jul 30 14:10:02.868998 2026] [security2:error] [pid 1004636:tid 1004928] [client 3.222.85.38:32439] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/noticia/1293/bebe-nasce-com-22-semanas-460g-e-do-tamanho-da-palma-da-mao.html"] [unique_id "amuhiu_uyupB2NyFtxKf8AAAAGU"]
[Thu Jul 30 14:10:02.886830 2026] [security2:error] [pid 1004636:tid 1004875] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/aa.php"] [unique_id "amuhiu_uyupB2NyFtxKf8QAAADM"]
[Thu Jul 30 14:10:02.886914 2026] [security2:error] [pid 1004636:tid 1004875] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/aa.php"] [unique_id "amuhiu_uyupB2NyFtxKf8QAAADM"]
[Thu Jul 30 14:10:02.917362 2026] [security2:error] [pid 1004636:tid 1004891] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/x.php"] [unique_id "amuhiu_uyupB2NyFtxKf8gAAAEI"]
[Thu Jul 30 14:10:02.917447 2026] [security2:error] [pid 1004636:tid 1004891] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/x.php"] [unique_id "amuhiu_uyupB2NyFtxKf8gAAAEI"]
[Thu Jul 30 14:10:03.072041 2026] [security2:error] [pid 1004636:tid 1004869] [client 20.104.18.253:41461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/ant.php"] [unique_id "amuhi-_uyupB2NyFtxKf9wAAAC0"]
[Thu Jul 30 14:10:03.162289 2026] [security2:error] [pid 1004636:tid 1004876] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/mgrr.php"] [unique_id "amuhi-_uyupB2NyFtxKf-QAAADQ"]
[Thu Jul 30 14:10:03.162393 2026] [security2:error] [pid 1004636:tid 1004876] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/mgrr.php"] [unique_id "amuhi-_uyupB2NyFtxKf-QAAADQ"]
[Thu Jul 30 14:10:03.173617 2026] [core:notice] [pid 1004636:tid 1004945] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:03.186274 2026] [security2:error] [pid 1004636:tid 1004924] [client 103.190.40.154:18076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhi-_uyupB2NyFtxKf-wAAAGE"]
[Thu Jul 30 14:10:03.186391 2026] [security2:error] [pid 1004636:tid 1004924] [client 103.190.40.154:18076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhi-_uyupB2NyFtxKf-wAAAGE"]
[Thu Jul 30 14:10:03.261036 2026] [security2:error] [pid 1004636:tid 1004785] [remote 54.37.118.90:63138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/tableau-de-bord-des-offres-demploi/"] [unique_id "amuhi-_uyupB2NyFtxKf_AAAPF4"]
[Thu Jul 30 14:10:03.261196 2026] [security2:error] [pid 1004636:tid 1004885] [client 54.37.118.90:63138] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/tableau-de-bord-des-offres-demploi/"] [unique_id "amuhi-_uyupB2NyFtxKf_AAAPF4"]
[Thu Jul 30 14:10:03.325801 2026] [autoindex:error] [pid 1004636:tid 1004870] [client 82.102.18.180:58472] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:10:03.326594 2026] [security2:error] [pid 1004636:tid 1004870] [client 82.102.18.180:58472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhi-_uyupB2NyFtxKf_QAAAC4"]
[Thu Jul 30 14:10:03.420313 2026] [security2:error] [pid 1004636:tid 1004850] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/domvf.php"] [unique_id "amuhi-_uyupB2NyFtxKgBgAAABs"]
[Thu Jul 30 14:10:03.420414 2026] [security2:error] [pid 1004636:tid 1004850] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/domvf.php"] [unique_id "amuhi-_uyupB2NyFtxKgBgAAABs"]
[Thu Jul 30 14:10:03.441184 2026] [security2:error] [pid 1004636:tid 1004879] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "amuhi-_uyupB2NyFtxKgCAAAADc"]
[Thu Jul 30 14:10:03.465850 2026] [security2:error] [pid 1004636:tid 1004890] [client 189.6.88.213:51845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhi-_uyupB2NyFtxKgCwAAAEE"]
[Thu Jul 30 14:10:03.465992 2026] [security2:error] [pid 1004636:tid 1004890] [client 189.6.88.213:51845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhi-_uyupB2NyFtxKgCwAAAEE"]
[Thu Jul 30 14:10:03.671658 2026] [security2:error] [pid 1004636:tid 1004910] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/yup.php"] [unique_id "amuhi-_uyupB2NyFtxKgDwAAAFQ"]
[Thu Jul 30 14:10:03.671783 2026] [security2:error] [pid 1004636:tid 1004910] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/yup.php"] [unique_id "amuhi-_uyupB2NyFtxKgDwAAAFQ"]
[Thu Jul 30 14:10:03.697178 2026] [core:notice] [pid 1004636:tid 1004918] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:03.708871 2026] [proxy:error] [pid 1004636:tid 1004934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:03.708942 2026] [proxy_http:error] [pid 1004636:tid 1004934] [client 128.14.225.253:32784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:03.709528 2026] [proxy:error] [pid 1004636:tid 1004934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:03.709586 2026] [proxy_http:error] [pid 1004636:tid 1004934] [client 128.14.225.253:32784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:03.798533 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuhi-_uyupB2NyFtxKgEgAAAAE"]
[Thu Jul 30 14:10:03.918526 2026] [security2:error] [pid 1004636:tid 1004826] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/X.php"] [unique_id "amuhi-_uyupB2NyFtxKgHAAAAAQ"]
[Thu Jul 30 14:10:03.918647 2026] [security2:error] [pid 1004636:tid 1004826] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/X.php"] [unique_id "amuhi-_uyupB2NyFtxKgHAAAAAQ"]
[Thu Jul 30 14:10:04.103746 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/classwithtostring.php"] [unique_id "amuhjO_uyupB2NyFtxKgIAAAAE4"]
[Thu Jul 30 14:10:04.103863 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/classwithtostring.php"] [unique_id "amuhjO_uyupB2NyFtxKgIAAAAE4"]
[Thu Jul 30 14:10:04.173696 2026] [security2:error] [pid 1004636:tid 1004930] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuhjO_uyupB2NyFtxKgIgAAAGc"]
[Thu Jul 30 14:10:04.173802 2026] [security2:error] [pid 1004636:tid 1004930] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuhjO_uyupB2NyFtxKgIgAAAGc"]
[Thu Jul 30 14:10:04.356606 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.104.18.253:35149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/appreciators.php"] [unique_id "amuhjO_uyupB2NyFtxKgJAAAAE0"]
[Thu Jul 30 14:10:04.411971 2026] [security2:error] [pid 1004636:tid 1004887] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/gec.php"] [unique_id "amuhjO_uyupB2NyFtxKgKAAAAD4"]
[Thu Jul 30 14:10:04.412091 2026] [security2:error] [pid 1004636:tid 1004887] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/gec.php"] [unique_id "amuhjO_uyupB2NyFtxKgKAAAAD4"]
[Thu Jul 30 14:10:04.523487 2026] [security2:error] [pid 1004636:tid 1004841] [client 181.116.200.68:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhjO_uyupB2NyFtxKgLQAAABI"]
[Thu Jul 30 14:10:04.523625 2026] [security2:error] [pid 1004636:tid 1004841] [client 181.116.200.68:42494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhjO_uyupB2NyFtxKgLQAAABI"]
[Thu Jul 30 14:10:04.682746 2026] [security2:error] [pid 1004636:tid 1004908] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/sky.php"] [unique_id "amuhjO_uyupB2NyFtxKgMgAAAFI"]
[Thu Jul 30 14:10:04.682845 2026] [security2:error] [pid 1004636:tid 1004908] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/sky.php"] [unique_id "amuhjO_uyupB2NyFtxKgMgAAAFI"]
[Thu Jul 30 14:10:04.754280 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/about.php"] [unique_id "amuhjO_uyupB2NyFtxKgNgAAAF4"]
[Thu Jul 30 14:10:04.754436 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/about.php"] [unique_id "amuhjO_uyupB2NyFtxKgNgAAAF4"]
[Thu Jul 30 14:10:04.761495 2026] [autoindex:error] [pid 1004636:tid 1004932] [client 82.102.18.180:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:10:04.762126 2026] [security2:error] [pid 1004636:tid 1004932] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhjO_uyupB2NyFtxKgNQAAAGk"]
[Thu Jul 30 14:10:04.762471 2026] [security2:error] [pid 1004636:tid 1004912] [client 82.102.18.180:58472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "amuhjO_uyupB2NyFtxKgMwAAAFY"]
[Thu Jul 30 14:10:04.877837 2026] [security2:error] [pid 1004636:tid 1004948] [client 66.249.73.96:37646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhjO_uyupB2NyFtxKgLAAAAHg"]
[Thu Jul 30 14:10:04.946444 2026] [security2:error] [pid 1004636:tid 1004836] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/fffm.php"] [unique_id "amuhjO_uyupB2NyFtxKgPAAAAA4"]
[Thu Jul 30 14:10:04.946549 2026] [security2:error] [pid 1004636:tid 1004836] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/fffm.php"] [unique_id "amuhjO_uyupB2NyFtxKgPAAAAA4"]
[Thu Jul 30 14:10:04.954351 2026] [security2:error] [pid 1004636:tid 1004947] [client 118.26.38.251:32852] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.wce.gzj.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amuhjO_uyupB2NyFtxKgPQAAAHc"]
[Thu Jul 30 14:10:05.100193 2026] [security2:error] [pid 1004636:tid 1004884] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "amuhje_uyupB2NyFtxKgRwAAADs"]
[Thu Jul 30 14:10:05.100591 2026] [security2:error] [pid 1004636:tid 1004831] [client 82.102.18.180:58472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "amuhje_uyupB2NyFtxKgRQAAAAk"]
[Thu Jul 30 14:10:05.194590 2026] [security2:error] [pid 1004636:tid 1004936] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/sixxis.php"] [unique_id "amuhje_uyupB2NyFtxKgSAAAAGw"]
[Thu Jul 30 14:10:05.194706 2026] [security2:error] [pid 1004636:tid 1004936] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/sixxis.php"] [unique_id "amuhje_uyupB2NyFtxKgSAAAAGw"]
[Thu Jul 30 14:10:05.327322 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/goods.php"] [unique_id "amuhje_uyupB2NyFtxKgSQAAADk"]
[Thu Jul 30 14:10:05.327474 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/goods.php"] [unique_id "amuhje_uyupB2NyFtxKgSQAAADk"]
[Thu Jul 30 14:10:05.430130 2026] [security2:error] [pid 1004636:tid 1004940] [client 20.104.18.253:28626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/archive.php"] [unique_id "amuhje_uyupB2NyFtxKgTAAAAHA"]
[Thu Jul 30 14:10:05.437118 2026] [security2:error] [pid 1004636:tid 1004850] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/yj09.php"] [unique_id "amuhje_uyupB2NyFtxKgTQAAABs"]
[Thu Jul 30 14:10:05.437202 2026] [security2:error] [pid 1004636:tid 1004850] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/yj09.php"] [unique_id "amuhje_uyupB2NyFtxKgTQAAABs"]
[Thu Jul 30 14:10:05.674653 2026] [security2:error] [pid 1004636:tid 1004873] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhje_uyupB2NyFtxKgUgAAADE"]
[Thu Jul 30 14:10:05.674695 2026] [security2:error] [pid 1004636:tid 1004873] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhje_uyupB2NyFtxKgUgAAADE"]
[Thu Jul 30 14:10:05.674961 2026] [security2:error] [pid 1004636:tid 1004868] [client 82.102.18.180:58472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/js/"] [unique_id "amuhje_uyupB2NyFtxKgUAAAACw"]
[Thu Jul 30 14:10:05.691040 2026] [security2:error] [pid 1004636:tid 1004825] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/k.php"] [unique_id "amuhje_uyupB2NyFtxKgWQAAAAM"]
[Thu Jul 30 14:10:05.691147 2026] [security2:error] [pid 1004636:tid 1004825] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/k.php"] [unique_id "amuhje_uyupB2NyFtxKgWQAAAAM"]
[Thu Jul 30 14:10:05.852973 2026] [core:error] [pid 1004636:tid 1004905] [client 128.14.225.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:10:05.853006 2026] [core:error] [pid 1004636:tid 1004905] [client 128.14.225.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:10:05.897347 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/php8.php"] [unique_id "amuhje_uyupB2NyFtxKgXQAAAAU"]
[Thu Jul 30 14:10:05.897504 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/php8.php"] [unique_id "amuhje_uyupB2NyFtxKgXQAAAAU"]
[Thu Jul 30 14:10:05.944166 2026] [security2:error] [pid 1004636:tid 1004952] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/k2.php"] [unique_id "amuhje_uyupB2NyFtxKgXwAAAHw"]
[Thu Jul 30 14:10:05.944277 2026] [security2:error] [pid 1004636:tid 1004952] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/k2.php"] [unique_id "amuhje_uyupB2NyFtxKgXwAAAHw"]
[Thu Jul 30 14:10:06.191857 2026] [security2:error] [pid 1004636:tid 1004927] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/w.php"] [unique_id "amuhju_uyupB2NyFtxKgbQAAAGQ"]
[Thu Jul 30 14:10:06.191959 2026] [security2:error] [pid 1004636:tid 1004927] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/w.php"] [unique_id "amuhju_uyupB2NyFtxKgbQAAAGQ"]
[Thu Jul 30 14:10:06.438206 2026] [security2:error] [pid 1004636:tid 1004841] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/fpwch.php"] [unique_id "amuhju_uyupB2NyFtxKgbgAAABI"]
[Thu Jul 30 14:10:06.438330 2026] [security2:error] [pid 1004636:tid 1004841] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/fpwch.php"] [unique_id "amuhju_uyupB2NyFtxKgbgAAABI"]
[Thu Jul 30 14:10:06.500102 2026] [security2:error] [pid 1004636:tid 1004946] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/info.php"] [unique_id "amuhju_uyupB2NyFtxKgcAAAAHY"]
[Thu Jul 30 14:10:06.500216 2026] [security2:error] [pid 1004636:tid 1004946] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/info.php"] [unique_id "amuhju_uyupB2NyFtxKgcAAAAHY"]
[Thu Jul 30 14:10:06.504584 2026] [security2:error] [pid 1004636:tid 1004929] [client 54.225.199.17:43038] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/07/baiano-3-400x300@2x.jpg"] [unique_id "amuhju_uyupB2NyFtxKgcQAAAGY"]
[Thu Jul 30 14:10:06.695874 2026] [security2:error] [pid 1004636:tid 1004948] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/w2025.php"] [unique_id "amuhju_uyupB2NyFtxKgewAAAHg"]
[Thu Jul 30 14:10:06.695961 2026] [security2:error] [pid 1004636:tid 1004948] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/w2025.php"] [unique_id "amuhju_uyupB2NyFtxKgewAAAHg"]
[Thu Jul 30 14:10:06.942568 2026] [security2:error] [pid 1004636:tid 1004955] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/FWAZ.php"] [unique_id "amuhju_uyupB2NyFtxKgfgAAAH8"]
[Thu Jul 30 14:10:06.942700 2026] [security2:error] [pid 1004636:tid 1004955] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/FWAZ.php"] [unique_id "amuhju_uyupB2NyFtxKgfgAAAH8"]
[Thu Jul 30 14:10:07.203585 2026] [security2:error] [pid 1004636:tid 1004881] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/qterm.php"] [unique_id "amuhj-_uyupB2NyFtxKgiAAAADk"]
[Thu Jul 30 14:10:07.203733 2026] [security2:error] [pid 1004636:tid 1004881] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/qterm.php"] [unique_id "amuhj-_uyupB2NyFtxKgiAAAADk"]
[Thu Jul 30 14:10:07.474861 2026] [security2:error] [pid 1004636:tid 1004872] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/blurbs.php"] [unique_id "amuhj-_uyupB2NyFtxKgigAAADA"]
[Thu Jul 30 14:10:07.474973 2026] [security2:error] [pid 1004636:tid 1004872] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/blurbs.php"] [unique_id "amuhj-_uyupB2NyFtxKgigAAADA"]
[Thu Jul 30 14:10:07.701774 2026] [security2:error] [pid 1004636:tid 1004839] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/class-t.api.php"] [unique_id "amuhj-_uyupB2NyFtxKglAAAABA"]
[Thu Jul 30 14:10:07.701882 2026] [security2:error] [pid 1004636:tid 1004839] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/class-t.api.php"] [unique_id "amuhj-_uyupB2NyFtxKglAAAABA"]
[Thu Jul 30 14:10:07.758955 2026] [security2:error] [pid 1004636:tid 1004864] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-ws68.php"] [unique_id "amuhj-_uyupB2NyFtxKglgAAACg"]
[Thu Jul 30 14:10:07.759080 2026] [security2:error] [pid 1004636:tid 1004864] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-ws68.php"] [unique_id "amuhj-_uyupB2NyFtxKglgAAACg"]
[Thu Jul 30 14:10:08.014157 2026] [security2:error] [pid 1004636:tid 1004897] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xyn.php"] [unique_id "amuhkO_uyupB2NyFtxKgmgAAAEc"]
[Thu Jul 30 14:10:08.014279 2026] [security2:error] [pid 1004636:tid 1004897] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xyn.php"] [unique_id "amuhkO_uyupB2NyFtxKgmgAAAEc"]
[Thu Jul 30 14:10:08.087185 2026] [security2:error] [pid 1004636:tid 1004940] [client 20.104.18.253:28666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/as.php"] [unique_id "amuhkO_uyupB2NyFtxKgnQAAAHA"]
[Thu Jul 30 14:10:08.267019 2026] [security2:error] [pid 1004636:tid 1004892] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ccc.php"] [unique_id "amuhkO_uyupB2NyFtxKgpgAAAEM"]
[Thu Jul 30 14:10:08.267141 2026] [security2:error] [pid 1004636:tid 1004892] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ccc.php"] [unique_id "amuhkO_uyupB2NyFtxKgpgAAAEM"]
[Thu Jul 30 14:10:08.273834 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/simple.php"] [unique_id "amuhkO_uyupB2NyFtxKgpwAAAAw"]
[Thu Jul 30 14:10:08.273933 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/simple.php"] [unique_id "amuhkO_uyupB2NyFtxKgpwAAAAw"]
[Thu Jul 30 14:10:08.534698 2026] [security2:error] [pid 1004636:tid 1004927] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/get.php"] [unique_id "amuhkO_uyupB2NyFtxKgqAAAAGQ"]
[Thu Jul 30 14:10:08.534806 2026] [security2:error] [pid 1004636:tid 1004927] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/get.php"] [unique_id "amuhkO_uyupB2NyFtxKgqAAAAGQ"]
[Thu Jul 30 14:10:08.790914 2026] [security2:error] [pid 1004636:tid 1004947] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/images.php"] [unique_id "amuhkO_uyupB2NyFtxKguQAAAHc"]
[Thu Jul 30 14:10:08.791026 2026] [security2:error] [pid 1004636:tid 1004947] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/images.php"] [unique_id "amuhkO_uyupB2NyFtxKguQAAAHc"]
[Thu Jul 30 14:10:08.811677 2026] [security2:error] [pid 1004636:tid 1004832] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/ioxi-o.php"] [unique_id "amuhkO_uyupB2NyFtxKgugAAAAo"]
[Thu Jul 30 14:10:08.811762 2026] [security2:error] [pid 1004636:tid 1004832] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/ioxi-o.php"] [unique_id "amuhkO_uyupB2NyFtxKgugAAAAo"]
[Thu Jul 30 14:10:08.905401 2026] [security2:error] [pid 1004636:tid 1004943] [client 139.28.219.70:33914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuhkO_uyupB2NyFtxKguwAAAHM"]
[Thu Jul 30 14:10:09.031317 2026] [security2:error] [pid 1004636:tid 1004862] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/alls.php"] [unique_id "amuhke_uyupB2NyFtxKgvAAAACY"]
[Thu Jul 30 14:10:09.031463 2026] [security2:error] [pid 1004636:tid 1004862] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/alls.php"] [unique_id "amuhke_uyupB2NyFtxKgvAAAACY"]
[Thu Jul 30 14:10:09.061076 2026] [security2:error] [pid 1004636:tid 1004948] [client 20.104.18.253:51983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/atomlib.php"] [unique_id "amuhke_uyupB2NyFtxKgvQAAAHg"]
[Thu Jul 30 14:10:09.270436 2026] [security2:error] [pid 1004636:tid 1004747] [remote 5.255.231.32:63238] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/the-largest-container-ship-in-the-world-arrived/"] [unique_id "amuhke_uyupB2NyFtxKgyQAAPDk"]
[Thu Jul 30 14:10:09.286876 2026] [security2:error] [pid 1004636:tid 1004936] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/coffexium.php"] [unique_id "amuhke_uyupB2NyFtxKgygAAAGw"]
[Thu Jul 30 14:10:09.286989 2026] [security2:error] [pid 1004636:tid 1004936] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/coffexium.php"] [unique_id "amuhke_uyupB2NyFtxKgygAAAGw"]
[Thu Jul 30 14:10:09.387876 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/wp-admin"] [unique_id "amuhke_uyupB2NyFtxKgywAAAAk"]
[Thu Jul 30 14:10:09.537785 2026] [security2:error] [pid 1004636:tid 1004879] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/red.php"] [unique_id "amuhke_uyupB2NyFtxKgzQAAADc"]
[Thu Jul 30 14:10:09.537901 2026] [security2:error] [pid 1004636:tid 1004879] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/red.php"] [unique_id "amuhke_uyupB2NyFtxKgzQAAADc"]
[Thu Jul 30 14:10:09.568427 2026] [security2:error] [pid 1004636:tid 1004855] [client 139.28.219.70:33928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuhke_uyupB2NyFtxKgzgAAAB8"]
[Thu Jul 30 14:10:09.699402 2026] [security2:error] [pid 1004636:tid 1004830] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuhke_uyupB2NyFtxKg0wAAAAg"]
[Thu Jul 30 14:10:09.796567 2026] [security2:error] [pid 1004636:tid 1004865] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuhke_uyupB2NyFtxKg2gAAACk"]
[Thu Jul 30 14:10:09.873177 2026] [security2:error] [pid 1004636:tid 1004940] [client 139.28.219.70:33932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuhke_uyupB2NyFtxKg2wAAAHA"]
[Thu Jul 30 14:10:09.932883 2026] [security2:error] [pid 1004636:tid 1004875] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuhke_uyupB2NyFtxKg3AAAADM"]
[Thu Jul 30 14:10:09.933030 2026] [security2:error] [pid 1004636:tid 1004875] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuhke_uyupB2NyFtxKg3AAAADM"]
[Thu Jul 30 14:10:09.979816 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp.php"] [unique_id "amuhke_uyupB2NyFtxKg3QAAAAU"]
[Thu Jul 30 14:10:09.979968 2026] [security2:error] [pid 1004636:tid 1004827] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp.php"] [unique_id "amuhke_uyupB2NyFtxKg3QAAAAU"]
[Thu Jul 30 14:10:10.079241 2026] [security2:error] [pid 1004636:tid 1004897] [client 20.104.18.253:35154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/autoload_classmap.php"] [unique_id "amuhku_uyupB2NyFtxKg3gAAAEc"]
[Thu Jul 30 14:10:10.184256 2026] [security2:error] [pid 1004636:tid 1004937] [client 139.28.219.70:33948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuhku_uyupB2NyFtxKg4gAAAG0"]
[Thu Jul 30 14:10:10.197582 2026] [security2:error] [pid 1004636:tid 1004877] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/"] [unique_id "amuhku_uyupB2NyFtxKg4wAAADU"]
[Thu Jul 30 14:10:10.347881 2026] [security2:error] [pid 1004636:tid 1004841] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuhku_uyupB2NyFtxKg7QAAABI"]
[Thu Jul 30 14:10:10.362388 2026] [core:notice] [pid 1004636:tid 1004952] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:10.364311 2026] [core:notice] [pid 1004636:tid 1004838] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:10.453493 2026] [security2:error] [pid 1004636:tid 1004901] [client 139.28.219.70:33964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuhku_uyupB2NyFtxKg8QAAAEs"]
[Thu Jul 30 14:10:10.470637 2026] [security2:error] [pid 1004636:tid 1004908] [client 44.212.106.171:26820] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/20150321053303.jpg"] [unique_id "amuhku_uyupB2NyFtxKg8gAAAFI"]
[Thu Jul 30 14:10:10.482002 2026] [security2:error] [pid 1004636:tid 1004932] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/index.php"] [unique_id "amuhku_uyupB2NyFtxKg8wAAAGk"]
[Thu Jul 30 14:10:10.482094 2026] [security2:error] [pid 1004636:tid 1004932] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/index.php"] [unique_id "amuhku_uyupB2NyFtxKg8wAAAGk"]
[Thu Jul 30 14:10:10.497743 2026] [core:notice] [pid 1004636:tid 1004923] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:10.530997 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/file2.php"] [unique_id "amuhku_uyupB2NyFtxKg9QAAAF4"]
[Thu Jul 30 14:10:10.531150 2026] [security2:error] [pid 1004636:tid 1004920] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/file2.php"] [unique_id "amuhku_uyupB2NyFtxKg9QAAAF4"]
[Thu Jul 30 14:10:10.722295 2026] [security2:error] [pid 1004636:tid 1004891] [client 139.28.219.70:57982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuhku_uyupB2NyFtxKg-QAAAEI"]
[Thu Jul 30 14:10:10.735057 2026] [security2:error] [pid 1004636:tid 1004921] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuhku_uyupB2NyFtxKg-gAAAF8"]
[Thu Jul 30 14:10:10.735175 2026] [security2:error] [pid 1004636:tid 1004921] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuhku_uyupB2NyFtxKg-gAAAF8"]
[Thu Jul 30 14:10:10.774018 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.104.18.253:40282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/bb.php"] [unique_id "amuhku_uyupB2NyFtxKg_gAAAD0"]
[Thu Jul 30 14:10:10.989244 2026] [security2:error] [pid 1004636:tid 1004939] [client 139.28.219.70:57998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuhku_uyupB2NyFtxKhAwAAAG8"]
[Thu Jul 30 14:10:10.990556 2026] [security2:error] [pid 1004636:tid 1004900] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/177.php"] [unique_id "amuhku_uyupB2NyFtxKhBAAAAEo"]
[Thu Jul 30 14:10:10.990656 2026] [security2:error] [pid 1004636:tid 1004900] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/177.php"] [unique_id "amuhku_uyupB2NyFtxKhBAAAAEo"]
[Thu Jul 30 14:10:11.034881 2026] [security2:error] [pid 1004636:tid 1004895] [client 213.152.161.219:50982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuhk-_uyupB2NyFtxKhBQAAAEU"]
[Thu Jul 30 14:10:11.035086 2026] [security2:error] [pid 1004636:tid 1004895] [client 213.152.161.219:50982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuhk-_uyupB2NyFtxKhBQAAAEU"]
[Thu Jul 30 14:10:11.157307 2026] [security2:error] [pid 1004636:tid 1004858] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/images/class-config.php"] [unique_id "amuhk-_uyupB2NyFtxKhBwAAACI"]
[Thu Jul 30 14:10:11.157418 2026] [security2:error] [pid 1004636:tid 1004858] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/images/class-config.php"] [unique_id "amuhk-_uyupB2NyFtxKhBwAAACI"]
[Thu Jul 30 14:10:11.239589 2026] [security2:error] [pid 1004636:tid 1004876] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/199.php"] [unique_id "amuhk-_uyupB2NyFtxKhCwAAADQ"]
[Thu Jul 30 14:10:11.239699 2026] [security2:error] [pid 1004636:tid 1004876] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/199.php"] [unique_id "amuhk-_uyupB2NyFtxKhCwAAADQ"]
[Thu Jul 30 14:10:11.277825 2026] [security2:error] [pid 1004636:tid 1004855] [client 139.28.219.70:58004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuhk-_uyupB2NyFtxKhDQAAAB8"]
[Thu Jul 30 14:10:11.459313 2026] [core:error] [pid 1004636:tid 1004888] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:10:11.459338 2026] [core:error] [pid 1004636:tid 1004888] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:10:11.495495 2026] [security2:error] [pid 1004636:tid 1004864] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file52.php"] [unique_id "amuhk-_uyupB2NyFtxKhFAAAACg"]
[Thu Jul 30 14:10:11.495652 2026] [security2:error] [pid 1004636:tid 1004864] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file52.php"] [unique_id "amuhk-_uyupB2NyFtxKhFAAAACg"]
[Thu Jul 30 14:10:11.563914 2026] [security2:error] [pid 1004636:tid 1004839] [client 139.28.219.70:58020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuhk-_uyupB2NyFtxKhFQAAABA"]
[Thu Jul 30 14:10:11.738029 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.9.4.9:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "propertyspro.com"] [uri "/1.php"] [unique_id "amuhk-_uyupB2NyFtxKhFgAAAAE"]
[Thu Jul 30 14:10:11.738133 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/1.php"] [unique_id "amuhk-_uyupB2NyFtxKhFgAAAAE"]
[Thu Jul 30 14:10:11.738241 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/1.php"] [unique_id "amuhk-_uyupB2NyFtxKhFgAAAAE"]
[Thu Jul 30 14:10:11.774691 2026] [security2:error] [pid 1004636:tid 1004918] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/geck.php"] [unique_id "amuhk-_uyupB2NyFtxKhGAAAAFw"]
[Thu Jul 30 14:10:11.774790 2026] [security2:error] [pid 1004636:tid 1004918] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/geck.php"] [unique_id "amuhk-_uyupB2NyFtxKhGAAAAFw"]
[Thu Jul 30 14:10:11.839786 2026] [core:error] [pid 1004636:tid 1004827] [client 128.14.225.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:10:11.839812 2026] [core:error] [pid 1004636:tid 1004827] [client 128.14.225.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:10:11.843021 2026] [security2:error] [pid 1004636:tid 1004897] [client 139.28.219.70:58036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuhk-_uyupB2NyFtxKhIAAAAEc"]
[Thu Jul 30 14:10:11.848027 2026] [security2:error] [pid 1004636:tid 1004934] [client 20.104.18.253:40275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/bnm.php"] [unique_id "amuhk-_uyupB2NyFtxKhIgAAAGs"]
[Thu Jul 30 14:10:12.016671 2026] [security2:error] [pid 1004636:tid 1004915] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/biufile.php"] [unique_id "amuhlO_uyupB2NyFtxKhJgAAAFk"]
[Thu Jul 30 14:10:12.016820 2026] [security2:error] [pid 1004636:tid 1004915] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/biufile.php"] [unique_id "amuhlO_uyupB2NyFtxKhJgAAAFk"]
[Thu Jul 30 14:10:12.130757 2026] [security2:error] [pid 1004636:tid 1004903] [client 139.28.219.70:58040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuhlO_uyupB2NyFtxKhJwAAAE0"]
[Thu Jul 30 14:10:12.276096 2026] [security2:error] [pid 1004636:tid 1004867] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dejavu.php"] [unique_id "amuhlO_uyupB2NyFtxKhKAAAACs"]
[Thu Jul 30 14:10:12.276222 2026] [security2:error] [pid 1004636:tid 1004867] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dejavu.php"] [unique_id "amuhlO_uyupB2NyFtxKhKAAAACs"]
[Thu Jul 30 14:10:12.331640 2026] [security2:error] [pid 1004636:tid 1004851] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/222.php"] [unique_id "amuhlO_uyupB2NyFtxKhLAAAABw"]
[Thu Jul 30 14:10:12.331721 2026] [security2:error] [pid 1004636:tid 1004851] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/222.php"] [unique_id "amuhlO_uyupB2NyFtxKhLAAAABw"]
[Thu Jul 30 14:10:12.387644 2026] [security2:error] [pid 1004636:tid 1004857] [client 139.28.219.70:58046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuhlO_uyupB2NyFtxKhMAAAACE"]
[Thu Jul 30 14:10:12.524888 2026] [security2:error] [pid 1004636:tid 1004840] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/aaf.php"] [unique_id "amuhlO_uyupB2NyFtxKhNAAAABE"]
[Thu Jul 30 14:10:12.525011 2026] [security2:error] [pid 1004636:tid 1004840] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/aaf.php"] [unique_id "amuhlO_uyupB2NyFtxKhNAAAABE"]
[Thu Jul 30 14:10:12.682542 2026] [security2:error] [pid 1004636:tid 1004905] [client 139.28.219.70:58050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuhlO_uyupB2NyFtxKhNQAAAE8"]
[Thu Jul 30 14:10:12.770168 2026] [security2:error] [pid 1004636:tid 1004874] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ha.php"] [unique_id "amuhlO_uyupB2NyFtxKhNgAAADI"]
[Thu Jul 30 14:10:12.770278 2026] [security2:error] [pid 1004636:tid 1004874] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ha.php"] [unique_id "amuhlO_uyupB2NyFtxKhNgAAADI"]
[Thu Jul 30 14:10:12.825815 2026] [security2:error] [pid 1004636:tid 1004921] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/themes.php"] [unique_id "amuhlO_uyupB2NyFtxKhOgAAAF8"]
[Thu Jul 30 14:10:12.825921 2026] [security2:error] [pid 1004636:tid 1004921] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/themes.php"] [unique_id "amuhlO_uyupB2NyFtxKhOgAAAF8"]
[Thu Jul 30 14:10:12.962894 2026] [security2:error] [pid 1004636:tid 1004836] [client 139.28.219.70:58058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuhlO_uyupB2NyFtxKhPgAAAA4"]
[Thu Jul 30 14:10:13.025740 2026] [security2:error] [pid 1004636:tid 1004919] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/hur.php"] [unique_id "amuhle_uyupB2NyFtxKhQgAAAF0"]
[Thu Jul 30 14:10:13.025835 2026] [security2:error] [pid 1004636:tid 1004919] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/hur.php"] [unique_id "amuhle_uyupB2NyFtxKhQgAAAF0"]
[Thu Jul 30 14:10:13.034999 2026] [security2:error] [pid 1004636:tid 1004889] [client 20.104.18.253:22724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/bootstrap.php"] [unique_id "amuhle_uyupB2NyFtxKhQwAAAEA"]
[Thu Jul 30 14:10:13.224928 2026] [security2:error] [pid 1004636:tid 1004931] [client 139.28.219.70:58072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adbacklink.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuhle_uyupB2NyFtxKhRAAAAGg"]
[Thu Jul 30 14:10:13.262933 2026] [security2:error] [pid 1004636:tid 1004939] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/h02ugyh.php"] [unique_id "amuhle_uyupB2NyFtxKhRQAAAG8"]
[Thu Jul 30 14:10:13.263047 2026] [security2:error] [pid 1004636:tid 1004939] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/h02ugyh.php"] [unique_id "amuhle_uyupB2NyFtxKhRQAAAG8"]
[Thu Jul 30 14:10:13.377112 2026] [security2:error] [pid 1004636:tid 1004863] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/admin.php"] [unique_id "amuhle_uyupB2NyFtxKhSQAAACc"]
[Thu Jul 30 14:10:13.377215 2026] [security2:error] [pid 1004636:tid 1004863] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/admin.php"] [unique_id "amuhle_uyupB2NyFtxKhSQAAACc"]
[Thu Jul 30 14:10:13.517718 2026] [security2:error] [pid 1004636:tid 1004954] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/155.php"] [unique_id "amuhle_uyupB2NyFtxKhUAAAAH4"]
[Thu Jul 30 14:10:13.517801 2026] [security2:error] [pid 1004636:tid 1004954] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/155.php"] [unique_id "amuhle_uyupB2NyFtxKhUAAAAH4"]
[Thu Jul 30 14:10:13.768835 2026] [security2:error] [pid 1004636:tid 1004926] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ops.php"] [unique_id "amuhle_uyupB2NyFtxKhUgAAAGM"]
[Thu Jul 30 14:10:13.768952 2026] [security2:error] [pid 1004636:tid 1004926] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ops.php"] [unique_id "amuhle_uyupB2NyFtxKhUgAAAGM"]
[Thu Jul 30 14:10:13.782511 2026] [security2:error] [pid 1004636:tid 1004949] [client 20.104.18.253:48089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/buy.php"] [unique_id "amuhle_uyupB2NyFtxKhUwAAAHk"]
[Thu Jul 30 14:10:14.014423 2026] [security2:error] [pid 1004636:tid 1004847] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ingfo.php"] [unique_id "amuhlu_uyupB2NyFtxKhXQAAABg"]
[Thu Jul 30 14:10:14.014556 2026] [security2:error] [pid 1004636:tid 1004847] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ingfo.php"] [unique_id "amuhlu_uyupB2NyFtxKhXQAAABg"]
[Thu Jul 30 14:10:14.015791 2026] [security2:error] [pid 1004636:tid 1004875] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/dropdown.php"] [unique_id "amuhlu_uyupB2NyFtxKhXgAAADM"]
[Thu Jul 30 14:10:14.015902 2026] [security2:error] [pid 1004636:tid 1004875] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/dropdown.php"] [unique_id "amuhlu_uyupB2NyFtxKhXgAAADM"]
[Thu Jul 30 14:10:14.233556 2026] [security2:error] [pid 1004636:tid 1004925] [client 189.6.88.213:52407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhlu_uyupB2NyFtxKhYAAAAGI"]
[Thu Jul 30 14:10:14.233677 2026] [security2:error] [pid 1004636:tid 1004925] [client 189.6.88.213:52407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhlu_uyupB2NyFtxKhYAAAAGI"]
[Thu Jul 30 14:10:14.267767 2026] [security2:error] [pid 1004636:tid 1004826] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/error_log.php"] [unique_id "amuhlu_uyupB2NyFtxKhYQAAAAQ"]
[Thu Jul 30 14:10:14.267892 2026] [security2:error] [pid 1004636:tid 1004826] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/error_log.php"] [unique_id "amuhlu_uyupB2NyFtxKhYQAAAAQ"]
[Thu Jul 30 14:10:14.519172 2026] [security2:error] [pid 1004636:tid 1004901] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/koala.php"] [unique_id "amuhlu_uyupB2NyFtxKhcgAAAEs"]
[Thu Jul 30 14:10:14.519289 2026] [security2:error] [pid 1004636:tid 1004901] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/koala.php"] [unique_id "amuhlu_uyupB2NyFtxKhcgAAAEs"]
[Thu Jul 30 14:10:14.584698 2026] [security2:error] [pid 1004636:tid 1004840] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/inputs.php"] [unique_id "amuhlu_uyupB2NyFtxKhcwAAABE"]
[Thu Jul 30 14:10:14.584801 2026] [security2:error] [pid 1004636:tid 1004840] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/inputs.php"] [unique_id "amuhlu_uyupB2NyFtxKhcwAAABE"]
[Thu Jul 30 14:10:14.586781 2026] [security2:error] [pid 1004636:tid 1004866] [client 20.104.18.253:35192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/chosen.php"] [unique_id "amuhlu_uyupB2NyFtxKhdAAAACo"]
[Thu Jul 30 14:10:14.746447 2026] [core:error] [pid 1004636:tid 1004886] [client 128.14.225.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:10:14.746471 2026] [core:error] [pid 1004636:tid 1004886] [client 128.14.225.253:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:10:14.770424 2026] [security2:error] [pid 1004636:tid 1004854] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/mac.php"] [unique_id "amuhlu_uyupB2NyFtxKhewAAAB4"]
[Thu Jul 30 14:10:14.770523 2026] [security2:error] [pid 1004636:tid 1004854] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/mac.php"] [unique_id "amuhlu_uyupB2NyFtxKhewAAAB4"]
[Thu Jul 30 14:10:14.932358 2026] [autoindex:error] [pid 1004636:tid 1004924] [client 192.71.12.10:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://tiger388.shop/
[Thu Jul 30 14:10:15.040666 2026] [security2:error] [pid 1004636:tid 1004834] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wefile.php"] [unique_id "amuhl-_uyupB2NyFtxKhhwAAAAw"]
[Thu Jul 30 14:10:15.040781 2026] [security2:error] [pid 1004636:tid 1004834] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wefile.php"] [unique_id "amuhl-_uyupB2NyFtxKhhwAAAAw"]
[Thu Jul 30 14:10:15.050190 2026] [security2:error] [pid 1004636:tid 1004921] [client 181.116.200.68:25367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhl-_uyupB2NyFtxKhiAAAAF8"]
[Thu Jul 30 14:10:15.050305 2026] [security2:error] [pid 1004636:tid 1004921] [client 181.116.200.68:25367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhl-_uyupB2NyFtxKhiAAAAF8"]
[Thu Jul 30 14:10:15.129502 2026] [security2:error] [pid 1004636:tid 1004892] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/100.php"] [unique_id "amuhl-_uyupB2NyFtxKhiQAAAEM"]
[Thu Jul 30 14:10:15.129692 2026] [security2:error] [pid 1004636:tid 1004892] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/100.php"] [unique_id "amuhl-_uyupB2NyFtxKhiQAAAEM"]
[Thu Jul 30 14:10:15.159303 2026] [security2:error] [pid 1004636:tid 1004907] [client 103.190.40.154:20180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhl-_uyupB2NyFtxKhiwAAAFE"]
[Thu Jul 30 14:10:15.159525 2026] [security2:error] [pid 1004636:tid 1004907] [client 103.190.40.154:20180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhl-_uyupB2NyFtxKhiwAAAFE"]
[Thu Jul 30 14:10:15.298406 2026] [security2:error] [pid 1004636:tid 1004884] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/post-comments-form/"] [unique_id "amuhl-_uyupB2NyFtxKhjwAAADs"]
[Thu Jul 30 14:10:15.442526 2026] [security2:error] [pid 1004636:tid 1004890] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/"] [unique_id "amuhl-_uyupB2NyFtxKhlAAAAEE"]
[Thu Jul 30 14:10:15.571071 2026] [security2:error] [pid 1004636:tid 1004944] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/makeasmtp.php"] [unique_id "amuhl-_uyupB2NyFtxKhnQAAAHQ"]
[Thu Jul 30 14:10:15.571221 2026] [security2:error] [pid 1004636:tid 1004944] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/makeasmtp.php"] [unique_id "amuhl-_uyupB2NyFtxKhnQAAAHQ"]
[Thu Jul 30 14:10:15.648466 2026] [security2:error] [pid 1004636:tid 1004885] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhl-_uyupB2NyFtxKhhgAAPD4"]
[Thu Jul 30 14:10:15.713003 2026] [security2:error] [pid 1004636:tid 1004877] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/autoload_classmap/function.php"] [unique_id "amuhl-_uyupB2NyFtxKhngAAADU"]
[Thu Jul 30 14:10:15.713117 2026] [security2:error] [pid 1004636:tid 1004877] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/autoload_classmap/function.php"] [unique_id "amuhl-_uyupB2NyFtxKhngAAADU"]
[Thu Jul 30 14:10:15.766719 2026] [security2:error] [pid 1004636:tid 1004825] [client 20.104.18.253:52039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/class-wp-image.php"] [unique_id "amuhl-_uyupB2NyFtxKhnwAAAAM"]
[Thu Jul 30 14:10:15.791133 2026] [security2:error] [pid 1004636:tid 1004827] [client 184.75.221.211:51306] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuhl-_uyupB2NyFtxKhmQAAAAU"]
[Thu Jul 30 14:10:15.791225 2026] [security2:error] [pid 1004636:tid 1004827] [client 184.75.221.211:51306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuhl-_uyupB2NyFtxKhmQAAAAU"]
[Thu Jul 30 14:10:15.808098 2026] [security2:error] [pid 1004636:tid 1004880] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/2P.php"] [unique_id "amuhl-_uyupB2NyFtxKhowAAADg"]
[Thu Jul 30 14:10:15.808203 2026] [security2:error] [pid 1004636:tid 1004880] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/2P.php"] [unique_id "amuhl-_uyupB2NyFtxKhowAAADg"]
[Thu Jul 30 14:10:16.052617 2026] [security2:error] [pid 1004636:tid 1004901] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/.well-known/about.php"] [unique_id "amuhmO_uyupB2NyFtxKhqgAAAEs"]
[Thu Jul 30 14:10:16.052702 2026] [security2:error] [pid 1004636:tid 1004901] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/.well-known/about.php"] [unique_id "amuhmO_uyupB2NyFtxKhqgAAAEs"]
[Thu Jul 30 14:10:16.289026 2026] [security2:error] [pid 1004636:tid 1004908] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/php.php"] [unique_id "amuhmO_uyupB2NyFtxKhrwAAAFI"]
[Thu Jul 30 14:10:16.289133 2026] [security2:error] [pid 1004636:tid 1004908] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/php.php"] [unique_id "amuhmO_uyupB2NyFtxKhrwAAAFI"]
[Thu Jul 30 14:10:16.306945 2026] [security2:error] [pid 1004636:tid 1004952] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuhmO_uyupB2NyFtxKhsAAAAHw"]
[Thu Jul 30 14:10:16.307071 2026] [security2:error] [pid 1004636:tid 1004952] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuhmO_uyupB2NyFtxKhsAAAAHw"]
[Thu Jul 30 14:10:16.499529 2026] [security2:error] [pid 1004636:tid 1004891] [client 85.204.70.116:40410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuhmO_uyupB2NyFtxKhtAAAAEI"]
[Thu Jul 30 14:10:16.547453 2026] [security2:error] [pid 1004636:tid 1004934] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/system_log.php"] [unique_id "amuhmO_uyupB2NyFtxKhuAAAAGs"]
[Thu Jul 30 14:10:16.547561 2026] [security2:error] [pid 1004636:tid 1004934] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/system_log.php"] [unique_id "amuhmO_uyupB2NyFtxKhuAAAAGs"]
[Thu Jul 30 14:10:16.809739 2026] [security2:error] [pid 1004636:tid 1004870] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/"] [unique_id "amuhmO_uyupB2NyFtxKhvQAAAC4"]
[Thu Jul 30 14:10:16.845688 2026] [security2:error] [pid 1004636:tid 1004936] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/t.php"] [unique_id "amuhmO_uyupB2NyFtxKhvgAAAGw"]
[Thu Jul 30 14:10:16.845802 2026] [security2:error] [pid 1004636:tid 1004936] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/t.php"] [unique_id "amuhmO_uyupB2NyFtxKhvgAAAGw"]
[Thu Jul 30 14:10:16.953720 2026] [security2:error] [pid 1004636:tid 1004843] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amuhmO_uyupB2NyFtxKhvwAAABQ"]
[Thu Jul 30 14:10:17.089657 2026] [security2:error] [pid 1004636:tid 1004845] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/crgio.php"] [unique_id "amuhme_uyupB2NyFtxKhxwAAABY"]
[Thu Jul 30 14:10:17.089774 2026] [security2:error] [pid 1004636:tid 1004845] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/crgio.php"] [unique_id "amuhme_uyupB2NyFtxKhxwAAABY"]
[Thu Jul 30 14:10:17.141749 2026] [security2:error] [pid 1004636:tid 1004955] [client 85.204.70.116:40424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/xmlrpc.php"] [unique_id "amuhme_uyupB2NyFtxKhywAAAH8"]
[Thu Jul 30 14:10:17.337275 2026] [security2:error] [pid 1004636:tid 1004949] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/pucci.php"] [unique_id "amuhme_uyupB2NyFtxKhzwAAAHk"]
[Thu Jul 30 14:10:17.337370 2026] [security2:error] [pid 1004636:tid 1004949] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/pucci.php"] [unique_id "amuhme_uyupB2NyFtxKhzwAAAHk"]
[Thu Jul 30 14:10:17.452874 2026] [security2:error] [pid 1004636:tid 1004888] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-blink.php"] [unique_id "amuhme_uyupB2NyFtxKh0AAAAD8"]
[Thu Jul 30 14:10:17.453004 2026] [security2:error] [pid 1004636:tid 1004888] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-blink.php"] [unique_id "amuhme_uyupB2NyFtxKh0AAAAD8"]
[Thu Jul 30 14:10:17.600565 2026] [security2:error] [pid 1004636:tid 1004918] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/details/"] [unique_id "amuhme_uyupB2NyFtxKh1wAAAFw"]
[Thu Jul 30 14:10:17.684335 2026] [security2:error] [pid 1004636:tid 1004836] [client 20.104.18.253:48100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/classsmtps.php"] [unique_id "amuhme_uyupB2NyFtxKh2QAAAA4"]
[Thu Jul 30 14:10:17.749503 2026] [security2:error] [pid 1004636:tid 1004839] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/blocks/audio/"] [unique_id "amuhme_uyupB2NyFtxKh3QAAABA"]
[Thu Jul 30 14:10:17.885200 2026] [security2:error] [pid 1004636:tid 1004873] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-temp.php"] [unique_id "amuhme_uyupB2NyFtxKh3gAAADE"]
[Thu Jul 30 14:10:17.885334 2026] [security2:error] [pid 1004636:tid 1004873] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-temp.php"] [unique_id "amuhme_uyupB2NyFtxKh3gAAADE"]
[Thu Jul 30 14:10:18.017823 2026] [security2:error] [pid 1004636:tid 1004875] [client 85.204.70.116:50854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuhmu_uyupB2NyFtxKh4gAAADM"]
[Thu Jul 30 14:10:18.137479 2026] [security2:error] [pid 1004636:tid 1004847] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-admin/js/index.php"] [unique_id "amuhmu_uyupB2NyFtxKh6QAAABg"]
[Thu Jul 30 14:10:18.137614 2026] [security2:error] [pid 1004636:tid 1004847] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-admin/js/index.php"] [unique_id "amuhmu_uyupB2NyFtxKh6QAAABg"]
[Thu Jul 30 14:10:18.391068 2026] [security2:error] [pid 1004636:tid 1004852] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/puc.php"] [unique_id "amuhmu_uyupB2NyFtxKh6wAAAB0"]
[Thu Jul 30 14:10:18.391184 2026] [security2:error] [pid 1004636:tid 1004852] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/puc.php"] [unique_id "amuhmu_uyupB2NyFtxKh6wAAAB0"]
[Thu Jul 30 14:10:18.522857 2026] [security2:error] [pid 1004636:tid 1004813] [remote 160.191.139.115:46398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.139.191.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuhmu_uyupB2NyFtxKh7wAALHk"]
[Thu Jul 30 14:10:18.523834 2026] [security2:error] [pid 1004636:tid 1004927] [client 85.204.70.116:55381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuhmu_uyupB2NyFtxKh8AAAAGQ"]
[Thu Jul 30 14:10:18.639605 2026] [security2:error] [pid 1004636:tid 1004840] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dx.php"] [unique_id "amuhmu_uyupB2NyFtxKh9wAAABE"]
[Thu Jul 30 14:10:18.639719 2026] [security2:error] [pid 1004636:tid 1004840] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dx.php"] [unique_id "amuhmu_uyupB2NyFtxKh9wAAABE"]
[Thu Jul 30 14:10:18.897337 2026] [security2:error] [pid 1004636:tid 1004924] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amuhmu_uyupB2NyFtxKiAgAAAGE"]
[Thu Jul 30 14:10:18.947489 2026] [security2:error] [pid 1004636:tid 1004867] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhmu_uyupB2NyFtxKh6gAAK3w"]
[Thu Jul 30 14:10:19.027441 2026] [security2:error] [pid 1004636:tid 1004936] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/7.php"] [unique_id "amuhm-_uyupB2NyFtxKiBwAAAGw"]
[Thu Jul 30 14:10:19.027544 2026] [security2:error] [pid 1004636:tid 1004936] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/7.php"] [unique_id "amuhm-_uyupB2NyFtxKiBwAAAGw"]
[Thu Jul 30 14:10:19.117301 2026] [security2:error] [pid 1004636:tid 1004886] [client 85.204.70.116:40456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuhm-_uyupB2NyFtxKiDgAAAD0"]
[Thu Jul 30 14:10:19.262069 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/xfun.php"] [unique_id "amuhm-_uyupB2NyFtxKiDwAAADA"]
[Thu Jul 30 14:10:19.262191 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/xfun.php"] [unique_id "amuhm-_uyupB2NyFtxKiDwAAADA"]
[Thu Jul 30 14:10:19.269754 2026] [security2:error] [pid 1004636:tid 1004879] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/8.php"] [unique_id "amuhm-_uyupB2NyFtxKiEQAAADc"]
[Thu Jul 30 14:10:19.269849 2026] [security2:error] [pid 1004636:tid 1004879] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/8.php"] [unique_id "amuhm-_uyupB2NyFtxKiEQAAADc"]
[Thu Jul 30 14:10:19.515729 2026] [security2:error] [pid 1004636:tid 1004844] [client 4.185.41.66:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amuhm-_uyupB2NyFtxKiFAAAABU"]
[Thu Jul 30 14:10:19.515877 2026] [security2:error] [pid 1004636:tid 1004844] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amuhm-_uyupB2NyFtxKiFAAAABU"]
[Thu Jul 30 14:10:19.516026 2026] [security2:error] [pid 1004636:tid 1004844] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amuhm-_uyupB2NyFtxKiFAAAABU"]
[Thu Jul 30 14:10:19.685516 2026] [security2:error] [pid 1004636:tid 1004861] [client 85.204.70.116:40458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuhm-_uyupB2NyFtxKiHQAAACU"]
[Thu Jul 30 14:10:19.758779 2026] [security2:error] [pid 1004636:tid 1004826] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amuhm-_uyupB2NyFtxKiIAAAAAQ"]
[Thu Jul 30 14:10:19.758885 2026] [security2:error] [pid 1004636:tid 1004826] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amuhm-_uyupB2NyFtxKiIAAAAAQ"]
[Thu Jul 30 14:10:19.838466 2026] [security2:error] [pid 1004636:tid 1004825] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/p.php"] [unique_id "amuhm-_uyupB2NyFtxKiIgAAAAM"]
[Thu Jul 30 14:10:19.838582 2026] [security2:error] [pid 1004636:tid 1004825] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/p.php"] [unique_id "amuhm-_uyupB2NyFtxKiIgAAAAM"]
[Thu Jul 30 14:10:20.004518 2026] [security2:error] [pid 1004636:tid 1004856] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuhnO_uyupB2NyFtxKiJgAAACA"]
[Thu Jul 30 14:10:20.004670 2026] [security2:error] [pid 1004636:tid 1004856] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuhnO_uyupB2NyFtxKiJgAAACA"]
[Thu Jul 30 14:10:20.078883 2026] [security2:error] [pid 1004636:tid 1004849] [client 172.237.109.114:10964] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/custom-tables/readme.txt"] [unique_id "amuhnO_uyupB2NyFtxKiJwAAABo"]
[Thu Jul 30 14:10:20.223300 2026] [security2:error] [pid 1004636:tid 1004904] [client 85.204.70.116:40462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuhnO_uyupB2NyFtxKiLgAAAE4"]
[Thu Jul 30 14:10:20.265910 2026] [security2:error] [pid 1004636:tid 1004946] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/edit.php"] [unique_id "amuhnO_uyupB2NyFtxKiLwAAAHY"]
[Thu Jul 30 14:10:20.266041 2026] [security2:error] [pid 1004636:tid 1004946] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/edit.php"] [unique_id "amuhnO_uyupB2NyFtxKiLwAAAHY"]
[Thu Jul 30 14:10:20.432667 2026] [security2:error] [pid 1004636:tid 1004934] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuhnO_uyupB2NyFtxKiMwAAAGs"]
[Thu Jul 30 14:10:20.432786 2026] [security2:error] [pid 1004636:tid 1004934] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuhnO_uyupB2NyFtxKiMwAAAGs"]
[Thu Jul 30 14:10:20.524037 2026] [security2:error] [pid 1004636:tid 1004947] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/admin.php"] [unique_id "amuhnO_uyupB2NyFtxKiNAAAAHc"]
[Thu Jul 30 14:10:20.524146 2026] [security2:error] [pid 1004636:tid 1004947] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/admin.php"] [unique_id "amuhnO_uyupB2NyFtxKiNAAAAHc"]
[Thu Jul 30 14:10:20.793423 2026] [security2:error] [pid 1004636:tid 1004892] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amuhnO_uyupB2NyFtxKiPgAAAEM"]
[Thu Jul 30 14:10:20.793544 2026] [security2:error] [pid 1004636:tid 1004892] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amuhnO_uyupB2NyFtxKiPgAAAEM"]
[Thu Jul 30 14:10:20.795627 2026] [security2:error] [pid 1004636:tid 1004835] [client 85.204.70.116:53948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuhnO_uyupB2NyFtxKiPwAAAA0"]
[Thu Jul 30 14:10:20.875931 2026] [security2:error] [pid 1004636:tid 1004901] [client 20.104.18.253:40264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/classwithtostring.php"] [unique_id "amuhnO_uyupB2NyFtxKiQwAAAEs"]
[Thu Jul 30 14:10:21.036420 2026] [security2:error] [pid 1004636:tid 1004871] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/av.php"] [unique_id "amuhne_uyupB2NyFtxKiRAAAAC8"]
[Thu Jul 30 14:10:21.036548 2026] [security2:error] [pid 1004636:tid 1004871] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/av.php"] [unique_id "amuhne_uyupB2NyFtxKiRAAAAC8"]
[Thu Jul 30 14:10:21.045745 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/aaa.php"] [unique_id "amuhne_uyupB2NyFtxKiRQAAADA"]
[Thu Jul 30 14:10:21.045864 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/aaa.php"] [unique_id "amuhne_uyupB2NyFtxKiRQAAADA"]
[Thu Jul 30 14:10:21.286232 2026] [security2:error] [pid 1004636:tid 1004850] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/classwithtostring.php"] [unique_id "amuhne_uyupB2NyFtxKiTwAAABs"]
[Thu Jul 30 14:10:21.286340 2026] [security2:error] [pid 1004636:tid 1004850] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/classwithtostring.php"] [unique_id "amuhne_uyupB2NyFtxKiTwAAABs"]
[Thu Jul 30 14:10:21.296559 2026] [security2:error] [pid 1004636:tid 1004948] [client 85.204.70.116:40482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuhne_uyupB2NyFtxKiUAAAAHg"]
[Thu Jul 30 14:10:21.329397 2026] [security2:error] [pid 1004636:tid 1004698] [remote 47.251.82.1:39816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amuhne_uyupB2NyFtxKiUwAAZwo"]
[Thu Jul 30 14:10:21.540303 2026] [security2:error] [pid 1004636:tid 1004862] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/themes/index.php"] [unique_id "amuhne_uyupB2NyFtxKiWgAAACY"]
[Thu Jul 30 14:10:21.540411 2026] [security2:error] [pid 1004636:tid 1004862] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/themes/index.php"] [unique_id "amuhne_uyupB2NyFtxKiWgAAACY"]
[Thu Jul 30 14:10:21.584898 2026] [security2:error] [pid 1004636:tid 1004873] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/7.php"] [unique_id "amuhne_uyupB2NyFtxKiWwAAADE"]
[Thu Jul 30 14:10:21.585028 2026] [security2:error] [pid 1004636:tid 1004873] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/7.php"] [unique_id "amuhne_uyupB2NyFtxKiWwAAADE"]
[Thu Jul 30 14:10:21.791087 2026] [security2:error] [pid 1004636:tid 1004899] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-blog.php"] [unique_id "amuhne_uyupB2NyFtxKiZQAAAEk"]
[Thu Jul 30 14:10:21.791214 2026] [security2:error] [pid 1004636:tid 1004899] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-blog.php"] [unique_id "amuhne_uyupB2NyFtxKiZQAAAEk"]
[Thu Jul 30 14:10:21.891192 2026] [security2:error] [pid 1004636:tid 1004925] [client 85.204.70.116:17433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuhne_uyupB2NyFtxKiaQAAAGI"]
[Thu Jul 30 14:10:21.895498 2026] [fcgid:warn] [pid 1004636:tid 1004950] (70014)End of file found: [client 128.14.236.30:33436] mod_fcgid: can't get data from http client
[Thu Jul 30 14:10:21.926197 2026] [security2:error] [pid 1004636:tid 1004839] [client 20.104.18.253:40296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/config.php"] [unique_id "amuhne_uyupB2NyFtxKiawAAABA"]
[Thu Jul 30 14:10:21.977079 2026] [security2:error] [pid 1004636:tid 1004829] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhne_uyupB2NyFtxKiVQAABwc"]
[Thu Jul 30 14:10:22.029071 2026] [security2:error] [pid 1004636:tid 1004822] [client 45.131.194.249:41009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuhnu_uyupB2NyFtxKibAAAAAA"]
[Thu Jul 30 14:10:22.054987 2026] [security2:error] [pid 1004636:tid 1004838] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/js/jquery/"] [unique_id "amuhnu_uyupB2NyFtxKibgAAAA8"]
[Thu Jul 30 14:10:22.189151 2026] [security2:error] [pid 1004636:tid 1004854] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/admin.php"] [unique_id "amuhnu_uyupB2NyFtxKicwAAAB4"]
[Thu Jul 30 14:10:22.189251 2026] [security2:error] [pid 1004636:tid 1004854] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-content/admin.php"] [unique_id "amuhnu_uyupB2NyFtxKicwAAAB4"]
[Thu Jul 30 14:10:22.226309 2026] [security2:error] [pid 1004636:tid 1004934] [client 144.172.114.51:43724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuhnu_uyupB2NyFtxKicgAAAGs"]
[Thu Jul 30 14:10:22.452782 2026] [security2:error] [pid 1004636:tid 1004901] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/adminfuns.php"] [unique_id "amuhnu_uyupB2NyFtxKifgAAAEs"]
[Thu Jul 30 14:10:22.452922 2026] [security2:error] [pid 1004636:tid 1004901] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/adminfuns.php"] [unique_id "amuhnu_uyupB2NyFtxKifgAAAEs"]
[Thu Jul 30 14:10:22.481841 2026] [security2:error] [pid 1004636:tid 1004897] [client 85.204.70.116:40500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuhnu_uyupB2NyFtxKifwAAAEc"]
[Thu Jul 30 14:10:22.654510 2026] [security2:error] [pid 1004636:tid 1004896] [client 85.208.96.195:54172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/24/fcja-firma-parceria-para-curso-de-seguranca-patrimonial/"] [unique_id "amuhnu_uyupB2NyFtxKihQAAAEY"]
[Thu Jul 30 14:10:22.654649 2026] [security2:error] [pid 1004636:tid 1004896] [client 85.208.96.195:54172] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/24/fcja-firma-parceria-para-curso-de-seguranca-patrimonial/"] [unique_id "amuhnu_uyupB2NyFtxKihQAAAEY"]
[Thu Jul 30 14:10:22.666616 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.104.18.253:55746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/core.php"] [unique_id "amuhnu_uyupB2NyFtxKihgAAAD0"]
[Thu Jul 30 14:10:22.694702 2026] [security2:error] [pid 1004636:tid 1004893] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/goods.php"] [unique_id "amuhnu_uyupB2NyFtxKihwAAAEQ"]
[Thu Jul 30 14:10:22.694788 2026] [security2:error] [pid 1004636:tid 1004893] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/goods.php"] [unique_id "amuhnu_uyupB2NyFtxKihwAAAEQ"]
[Thu Jul 30 14:10:22.847373 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/file5.php"] [unique_id "amuhnu_uyupB2NyFtxKijwAAAE8"]
[Thu Jul 30 14:10:22.847509 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/file5.php"] [unique_id "amuhnu_uyupB2NyFtxKijwAAAE8"]
[Thu Jul 30 14:10:22.896071 2026] [security2:error] [pid 1004636:tid 1004826] [client 45.146.54.28:38401] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuhnu_uyupB2NyFtxKilQAAAAQ"]
[Thu Jul 30 14:10:22.948257 2026] [security2:error] [pid 1004636:tid 1004860] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ms-edit.php"] [unique_id "amuhnu_uyupB2NyFtxKilgAAACQ"]
[Thu Jul 30 14:10:22.948388 2026] [security2:error] [pid 1004636:tid 1004860] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ms-edit.php"] [unique_id "amuhnu_uyupB2NyFtxKilgAAACQ"]
[Thu Jul 30 14:10:22.991411 2026] [security2:error] [pid 1004636:tid 1004874] [client 85.204.70.116:14345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuhnu_uyupB2NyFtxKimAAAADI"]
[Thu Jul 30 14:10:23.199244 2026] [security2:error] [pid 1004636:tid 1004925] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/222.php"] [unique_id "amuhn-_uyupB2NyFtxKioAAAAGI"]
[Thu Jul 30 14:10:23.199348 2026] [security2:error] [pid 1004636:tid 1004925] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/222.php"] [unique_id "amuhn-_uyupB2NyFtxKioAAAAGI"]
[Thu Jul 30 14:10:23.399418 2026] [security2:error] [pid 1004636:tid 1004846] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/makeasmtp.php"] [unique_id "amuhn-_uyupB2NyFtxKipwAAABc"]
[Thu Jul 30 14:10:23.399530 2026] [security2:error] [pid 1004636:tid 1004846] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/makeasmtp.php"] [unique_id "amuhn-_uyupB2NyFtxKipwAAABc"]
[Thu Jul 30 14:10:23.447349 2026] [security2:error] [pid 1004636:tid 1004859] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/cgi-bin/index.php"] [unique_id "amuhn-_uyupB2NyFtxKirQAAACM"]
[Thu Jul 30 14:10:23.447481 2026] [security2:error] [pid 1004636:tid 1004859] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/cgi-bin/index.php"] [unique_id "amuhn-_uyupB2NyFtxKirQAAACM"]
[Thu Jul 30 14:10:23.452222 2026] [security2:error] [pid 1004636:tid 1004866] [client 144.172.114.51:43738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuhn-_uyupB2NyFtxKiqQAAACo"]
[Thu Jul 30 14:10:23.591134 2026] [security2:error] [pid 1004636:tid 1004822] [client 85.204.70.116:64075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuhn-_uyupB2NyFtxKisQAAAAA"]
[Thu Jul 30 14:10:23.707498 2026] [security2:error] [pid 1004636:tid 1004947] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/dist/"] [unique_id "amuhn-_uyupB2NyFtxKiswAAAHc"]
[Thu Jul 30 14:10:23.748328 2026] [security2:error] [pid 1004636:tid 1004917] [client 45.131.194.244:41397] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/media/system/js/core.js"] [unique_id "amuhn-_uyupB2NyFtxKitAAAAFs"]
[Thu Jul 30 14:10:23.839190 2026] [security2:error] [pid 1004636:tid 1004936] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/BDKR28WP.php"] [unique_id "amuhn-_uyupB2NyFtxKiuAAAAGw"]
[Thu Jul 30 14:10:23.839320 2026] [security2:error] [pid 1004636:tid 1004936] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/BDKR28WP.php"] [unique_id "amuhn-_uyupB2NyFtxKiuAAAAGw"]
[Thu Jul 30 14:10:23.889718 2026] [security2:error] [pid 1004636:tid 1004842] [client 20.104.18.253:26900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/css.php"] [unique_id "amuhn-_uyupB2NyFtxKivAAAABM"]
[Thu Jul 30 14:10:23.919203 2026] [security2:error] [pid 1004636:tid 1004835] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/index.php"] [unique_id "amuhn-_uyupB2NyFtxKivgAAAA0"]
[Thu Jul 30 14:10:23.919313 2026] [security2:error] [pid 1004636:tid 1004835] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/index.php"] [unique_id "amuhn-_uyupB2NyFtxKivgAAAA0"]
[Thu Jul 30 14:10:24.099899 2026] [security2:error] [pid 1004636:tid 1004893] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuhoO_uyupB2NyFtxKixgAAAEQ"]
[Thu Jul 30 14:10:24.187374 2026] [security2:error] [pid 1004636:tid 1004830] [client 85.204.70.116:61868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuhoO_uyupB2NyFtxKixwAAAAg"]
[Thu Jul 30 14:10:24.244407 2026] [security2:error] [pid 1004636:tid 1004844] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuhoO_uyupB2NyFtxKiyAAAABU"]
[Thu Jul 30 14:10:24.373590 2026] [security2:error] [pid 1004636:tid 1004888] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp.php"] [unique_id "amuhoO_uyupB2NyFtxKizAAAAD8"]
[Thu Jul 30 14:10:24.373717 2026] [security2:error] [pid 1004636:tid 1004888] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp.php"] [unique_id "amuhoO_uyupB2NyFtxKizAAAAD8"]
[Thu Jul 30 14:10:24.477330 2026] [security2:error] [pid 1004636:tid 1004826] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/atomlib.php"] [unique_id "amuhoO_uyupB2NyFtxKizgAAAAQ"]
[Thu Jul 30 14:10:24.477431 2026] [security2:error] [pid 1004636:tid 1004826] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/atomlib.php"] [unique_id "amuhoO_uyupB2NyFtxKizgAAAAQ"]
[Thu Jul 30 14:10:24.619796 2026] [security2:error] [pid 1004636:tid 1004903] [client 144.172.114.51:43748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuhoO_uyupB2NyFtxKi1AAAAE0"]
[Thu Jul 30 14:10:24.622088 2026] [security2:error] [pid 1004636:tid 1004832] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/abcd.php"] [unique_id "amuhoO_uyupB2NyFtxKi1QAAAAo"]
[Thu Jul 30 14:10:24.622194 2026] [security2:error] [pid 1004636:tid 1004832] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/abcd.php"] [unique_id "amuhoO_uyupB2NyFtxKi1QAAAAo"]
[Thu Jul 30 14:10:24.727398 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.104.18.253:57337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/database.php"] [unique_id "amuhoO_uyupB2NyFtxKi2QAAAE8"]
[Thu Jul 30 14:10:24.746418 2026] [security2:error] [pid 1004636:tid 1004902] [client 85.204.70.116:55404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuhoO_uyupB2NyFtxKi2gAAAEw"]
[Thu Jul 30 14:10:24.881542 2026] [security2:error] [pid 1004636:tid 1004942] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/a1.php"] [unique_id "amuhoO_uyupB2NyFtxKi5AAAAHI"]
[Thu Jul 30 14:10:24.881650 2026] [security2:error] [pid 1004636:tid 1004942] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/a1.php"] [unique_id "amuhoO_uyupB2NyFtxKi5AAAAHI"]
[Thu Jul 30 14:10:24.903393 2026] [security2:error] [pid 1004636:tid 1004879] [client 189.6.88.213:52953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhoO_uyupB2NyFtxKi5QAAADc"]
[Thu Jul 30 14:10:24.903479 2026] [security2:error] [pid 1004636:tid 1004879] [client 189.6.88.213:52953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhoO_uyupB2NyFtxKi5QAAADc"]
[Thu Jul 30 14:10:25.036073 2026] [security2:error] [pid 1004636:tid 1004947] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/min.php"] [unique_id "amuhoe_uyupB2NyFtxKi8AAAAHc"]
[Thu Jul 30 14:10:25.036165 2026] [security2:error] [pid 1004636:tid 1004947] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/min.php"] [unique_id "amuhoe_uyupB2NyFtxKi8AAAAHc"]
[Thu Jul 30 14:10:25.132615 2026] [security2:error] [pid 1004636:tid 1004917] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuhoe_uyupB2NyFtxKi8QAAAFs"]
[Thu Jul 30 14:10:25.132728 2026] [security2:error] [pid 1004636:tid 1004917] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuhoe_uyupB2NyFtxKi8QAAAFs"]
[Thu Jul 30 14:10:25.260912 2026] [security2:error] [pid 1004636:tid 1004877] [client 85.204.70.116:55416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuhoe_uyupB2NyFtxKi9AAAADU"]
[Thu Jul 30 14:10:25.375781 2026] [security2:error] [pid 1004636:tid 1004863] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/cgi-bin/admin.php"] [unique_id "amuhoe_uyupB2NyFtxKi-AAAACc"]
[Thu Jul 30 14:10:25.375892 2026] [security2:error] [pid 1004636:tid 1004863] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/cgi-bin/admin.php"] [unique_id "amuhoe_uyupB2NyFtxKi-AAAACc"]
[Thu Jul 30 14:10:25.631715 2026] [security2:error] [pid 1004636:tid 1004895] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuhoe_uyupB2NyFtxKjAAAAAEU"]
[Thu Jul 30 14:10:25.687121 2026] [security2:error] [pid 1004636:tid 1004841] [client 181.116.200.68:10250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhoe_uyupB2NyFtxKjAQAAABI"]
[Thu Jul 30 14:10:25.687862 2026] [security2:error] [pid 1004636:tid 1004841] [client 181.116.200.68:10250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhoe_uyupB2NyFtxKjAQAAABI"]
[Thu Jul 30 14:10:25.764866 2026] [security2:error] [pid 1004636:tid 1004871] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/simple.php"] [unique_id "amuhoe_uyupB2NyFtxKjAgAAAC8"]
[Thu Jul 30 14:10:25.765020 2026] [security2:error] [pid 1004636:tid 1004871] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/simple.php"] [unique_id "amuhoe_uyupB2NyFtxKjAgAAAC8"]
[Thu Jul 30 14:10:25.793678 2026] [security2:error] [pid 1004636:tid 1004897] [client 85.204.70.116:55430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuhoe_uyupB2NyFtxKjAwAAAEc"]
[Thu Jul 30 14:10:25.809550 2026] [core:notice] [pid 1004636:tid 1004936] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:26.005324 2026] [security2:error] [pid 1004636:tid 1004933] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/moon.php"] [unique_id "amuhou_uyupB2NyFtxKjCwAAAGo"]
[Thu Jul 30 14:10:26.005432 2026] [security2:error] [pid 1004636:tid 1004933] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/moon.php"] [unique_id "amuhou_uyupB2NyFtxKjCwAAAGo"]
[Thu Jul 30 14:10:26.005749 2026] [security2:error] [pid 1004636:tid 1004830] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xxx.php"] [unique_id "amuhou_uyupB2NyFtxKjDAAAAAg"]
[Thu Jul 30 14:10:26.005815 2026] [security2:error] [pid 1004636:tid 1004830] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xxx.php"] [unique_id "amuhou_uyupB2NyFtxKjDAAAAAg"]
[Thu Jul 30 14:10:26.254770 2026] [security2:error] [pid 1004636:tid 1004862] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/hypo.php"] [unique_id "amuhou_uyupB2NyFtxKjEAAAACY"]
[Thu Jul 30 14:10:26.254882 2026] [security2:error] [pid 1004636:tid 1004862] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/hypo.php"] [unique_id "amuhou_uyupB2NyFtxKjEAAAACY"]
[Thu Jul 30 14:10:26.519745 2026] [security2:error] [pid 1004636:tid 1004948] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuhou_uyupB2NyFtxKjFgAAAHg"]
[Thu Jul 30 14:10:26.566332 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/ws83.php"] [unique_id "amuhou_uyupB2NyFtxKjGgAAACQ"]
[Thu Jul 30 14:10:26.566482 2026] [security2:error] [pid 1004636:tid 1004860] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/ws83.php"] [unique_id "amuhou_uyupB2NyFtxKjGgAAACQ"]
[Thu Jul 30 14:10:26.567276 2026] [security2:error] [pid 1004636:tid 1004885] [client 103.190.40.154:20222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhou_uyupB2NyFtxKjGwAAADw"]
[Thu Jul 30 14:10:26.567441 2026] [security2:error] [pid 1004636:tid 1004885] [client 103.190.40.154:20222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhou_uyupB2NyFtxKjGwAAADw"]
[Thu Jul 30 14:10:26.650343 2026] [security2:error] [pid 1004636:tid 1004905] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/chosen.php"] [unique_id "amuhou_uyupB2NyFtxKjIAAAAE8"]
[Thu Jul 30 14:10:26.650444 2026] [security2:error] [pid 1004636:tid 1004905] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/chosen.php"] [unique_id "amuhou_uyupB2NyFtxKjIAAAAE8"]
[Thu Jul 30 14:10:26.915052 2026] [security2:error] [pid 1004636:tid 1004904] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/block-bindings/"] [unique_id "amuhou_uyupB2NyFtxKjIgAAAE4"]
[Thu Jul 30 14:10:27.044706 2026] [security2:error] [pid 1004636:tid 1004952] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/als.php"] [unique_id "amuho-_uyupB2NyFtxKjQgAAAHw"]
[Thu Jul 30 14:10:27.044814 2026] [security2:error] [pid 1004636:tid 1004952] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/als.php"] [unique_id "amuho-_uyupB2NyFtxKjQgAAAHw"]
[Thu Jul 30 14:10:27.056486 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/403.php"] [unique_id "amuho-_uyupB2NyFtxKjQwAAAAc"]
[Thu Jul 30 14:10:27.056569 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/403.php"] [unique_id "amuho-_uyupB2NyFtxKjQwAAAAc"]
[Thu Jul 30 14:10:27.293078 2026] [security2:error] [pid 1004636:tid 1004916] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/pol.php"] [unique_id "amuho-_uyupB2NyFtxKjaAAAAFo"]
[Thu Jul 30 14:10:27.293166 2026] [security2:error] [pid 1004636:tid 1004916] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/pol.php"] [unique_id "amuho-_uyupB2NyFtxKjaAAAAFo"]
[Thu Jul 30 14:10:27.375794 2026] [security2:error] [pid 1004636:tid 1004942] [client 151.80.133.238:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.133.80.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amuho-_uyupB2NyFtxKjRwAAAHI"]
[Thu Jul 30 14:10:27.535122 2026] [security2:error] [pid 1004636:tid 1004944] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file5.php"] [unique_id "amuho-_uyupB2NyFtxKjdgAAAHQ"]
[Thu Jul 30 14:10:27.535218 2026] [security2:error] [pid 1004636:tid 1004944] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file5.php"] [unique_id "amuho-_uyupB2NyFtxKjdgAAAHQ"]
[Thu Jul 30 14:10:27.617571 2026] [security2:error] [pid 1004636:tid 1004835] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/api.php"] [unique_id "amuho-_uyupB2NyFtxKjeQAAAA0"]
[Thu Jul 30 14:10:27.617710 2026] [security2:error] [pid 1004636:tid 1004835] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/api.php"] [unique_id "amuho-_uyupB2NyFtxKjeQAAAA0"]
[Thu Jul 30 14:10:27.783551 2026] [security2:error] [pid 1004636:tid 1004945] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file.php"] [unique_id "amuho-_uyupB2NyFtxKjfgAAAHU"]
[Thu Jul 30 14:10:27.783682 2026] [security2:error] [pid 1004636:tid 1004945] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file.php"] [unique_id "amuho-_uyupB2NyFtxKjfgAAAHU"]
[Thu Jul 30 14:10:27.841321 2026] [security2:error] [pid 1004636:tid 1004901] [client 51.75.21.177:36610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.21.75.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amuho-_uyupB2NyFtxKjgQAAAEs"]
[Thu Jul 30 14:10:28.032970 2026] [security2:error] [pid 1004636:tid 1004893] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuhpO_uyupB2NyFtxKjiwAAAEQ"]
[Thu Jul 30 14:10:28.033112 2026] [security2:error] [pid 1004636:tid 1004893] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuhpO_uyupB2NyFtxKjiwAAAEQ"]
[Thu Jul 30 14:10:28.148297 2026] [security2:error] [pid 1004636:tid 1004936] [client 20.104.18.253:30397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/db.php"] [unique_id "amuhpO_uyupB2NyFtxKjkwAAAGw"]
[Thu Jul 30 14:10:28.231974 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/3.php"] [unique_id "amuhpO_uyupB2NyFtxKjnQAAABk"]
[Thu Jul 30 14:10:28.232136 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/3.php"] [unique_id "amuhpO_uyupB2NyFtxKjnQAAABk"]
[Thu Jul 30 14:10:28.276536 2026] [security2:error] [pid 1004636:tid 1004832] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/aa2.php"] [unique_id "amuhpO_uyupB2NyFtxKjnwAAAAo"]
[Thu Jul 30 14:10:28.276642 2026] [security2:error] [pid 1004636:tid 1004832] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/aa2.php"] [unique_id "amuhpO_uyupB2NyFtxKjnwAAAAo"]
[Thu Jul 30 14:10:28.535563 2026] [security2:error] [pid 1004636:tid 1004868] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ccou.php"] [unique_id "amuhpO_uyupB2NyFtxKjpAAAACw"]
[Thu Jul 30 14:10:28.535709 2026] [security2:error] [pid 1004636:tid 1004868] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ccou.php"] [unique_id "amuhpO_uyupB2NyFtxKjpAAAACw"]
[Thu Jul 30 14:10:28.792114 2026] [security2:error] [pid 1004636:tid 1004851] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dr.php"] [unique_id "amuhpO_uyupB2NyFtxKjsAAAABw"]
[Thu Jul 30 14:10:28.792260 2026] [security2:error] [pid 1004636:tid 1004851] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dr.php"] [unique_id "amuhpO_uyupB2NyFtxKjsAAAABw"]
[Thu Jul 30 14:10:28.980463 2026] [security2:error] [pid 1004636:tid 1004823] [client 91.106.41.131:43382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhpO_uyupB2NyFtxKjrQAAAAE"], referer: http://pkf.jo
[Thu Jul 30 14:10:29.048558 2026] [security2:error] [pid 1004636:tid 1004955] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xamp.php"] [unique_id "amuhpe_uyupB2NyFtxKjvAAAAH8"]
[Thu Jul 30 14:10:29.048721 2026] [security2:error] [pid 1004636:tid 1004955] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xamp.php"] [unique_id "amuhpe_uyupB2NyFtxKjvAAAAH8"]
[Thu Jul 30 14:10:29.247351 2026] [security2:error] [pid 1004636:tid 1004866] [client 119.73.97.132:30766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuhpO_uyupB2NyFtxKjswAAKho"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 14:10:29.291091 2026] [security2:error] [pid 1004636:tid 1004902] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/bless.php"] [unique_id "amuhpe_uyupB2NyFtxKj1AAAAEw"]
[Thu Jul 30 14:10:29.291205 2026] [security2:error] [pid 1004636:tid 1004902] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/bless.php"] [unique_id "amuhpe_uyupB2NyFtxKj1AAAAEw"]
[Thu Jul 30 14:10:29.527673 2026] [security2:error] [pid 1004636:tid 1004940] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file25.php"] [unique_id "amuhpe_uyupB2NyFtxKj2gAAAHA"]
[Thu Jul 30 14:10:29.527820 2026] [security2:error] [pid 1004636:tid 1004940] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file25.php"] [unique_id "amuhpe_uyupB2NyFtxKj2gAAAHA"]
[Thu Jul 30 14:10:29.772351 2026] [security2:error] [pid 1004636:tid 1004880] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file6.php"] [unique_id "amuhpe_uyupB2NyFtxKj6wAAADg"]
[Thu Jul 30 14:10:29.772453 2026] [security2:error] [pid 1004636:tid 1004880] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file6.php"] [unique_id "amuhpe_uyupB2NyFtxKj6wAAADg"]
[Thu Jul 30 14:10:30.018896 2026] [security2:error] [pid 1004636:tid 1004861] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/a2.php"] [unique_id "amuhpu_uyupB2NyFtxKj7gAAACU"]
[Thu Jul 30 14:10:30.019043 2026] [security2:error] [pid 1004636:tid 1004861] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/a2.php"] [unique_id "amuhpu_uyupB2NyFtxKj7gAAACU"]
[Thu Jul 30 14:10:30.079633 2026] [security2:error] [pid 1004636:tid 1004937] [client 78.178.128.21:18232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhpe_uyupB2NyFtxKj7AAAAG0"], referer: http://pkf.jo
[Thu Jul 30 14:10:30.119710 2026] [security2:error] [pid 1004636:tid 1004743] [remote 57.141.0.62:42392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/93381591101/feed/rss2/"] [unique_id "amuhpu_uyupB2NyFtxKj8wAALDY"]
[Thu Jul 30 14:10:30.135778 2026] [security2:error] [pid 1004636:tid 1004915] [client 149.202.48.220:46948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.48.202.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amuhpe_uyupB2NyFtxKj7QAAAFk"]
[Thu Jul 30 14:10:30.273135 2026] [security2:error] [pid 1004636:tid 1004851] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file15.php"] [unique_id "amuhpu_uyupB2NyFtxKj-AAAABw"]
[Thu Jul 30 14:10:30.273226 2026] [security2:error] [pid 1004636:tid 1004851] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file15.php"] [unique_id "amuhpu_uyupB2NyFtxKj-AAAABw"]
[Thu Jul 30 14:10:30.374653 2026] [security2:error] [pid 1004636:tid 1004947] [client 20.104.18.253:57301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/default.php"] [unique_id "amuhpu_uyupB2NyFtxKj_AAAAHc"]
[Thu Jul 30 14:10:30.480221 2026] [security2:error] [pid 1004636:tid 1004863] [client 141.94.95.76:41540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.95.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amuhpu_uyupB2NyFtxKj_QAAACc"]
[Thu Jul 30 14:10:30.531023 2026] [security2:error] [pid 1004636:tid 1004939] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/f35.php"] [unique_id "amuhpu_uyupB2NyFtxKj_gAAAG8"]
[Thu Jul 30 14:10:30.531126 2026] [security2:error] [pid 1004636:tid 1004939] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/f35.php"] [unique_id "amuhpu_uyupB2NyFtxKj_gAAAG8"]
[Thu Jul 30 14:10:30.543377 2026] [security2:error] [pid 1004636:tid 1004842] [client 151.80.133.130:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.133.80.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amuhpu_uyupB2NyFtxKj_wAAABM"]
[Thu Jul 30 14:10:30.613146 2026] [security2:error] [pid 1004636:tid 1004845] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/wp-includes/PHPMailer/"] [unique_id "amuhpu_uyupB2NyFtxKkAwAAABY"]
[Thu Jul 30 14:10:30.786438 2026] [security2:error] [pid 1004636:tid 1004901] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-load.php"] [unique_id "amuhpu_uyupB2NyFtxKkBwAAAEs"]
[Thu Jul 30 14:10:30.786536 2026] [security2:error] [pid 1004636:tid 1004901] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-load.php"] [unique_id "amuhpu_uyupB2NyFtxKkBwAAAEs"]
[Thu Jul 30 14:10:30.899187 2026] [security2:error] [pid 1004636:tid 1004893] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuhpu_uyupB2NyFtxKkCwAAAEQ"]
[Thu Jul 30 14:10:31.041657 2026] [security2:error] [pid 1004636:tid 1004858] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xwpg.php"] [unique_id "amuhp-_uyupB2NyFtxKkEQAAACI"]
[Thu Jul 30 14:10:31.041798 2026] [security2:error] [pid 1004636:tid 1004858] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xwpg.php"] [unique_id "amuhp-_uyupB2NyFtxKkEQAAACI"]
[Thu Jul 30 14:10:31.054474 2026] [security2:error] [pid 1004636:tid 1004872] [client 141.94.94.61:53136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.94.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amuhp-_uyupB2NyFtxKkEgAAADA"]
[Thu Jul 30 14:10:31.201492 2026] [security2:error] [pid 1004636:tid 1004930] [client 20.104.18.253:28630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/dropdown.php"] [unique_id "amuhp-_uyupB2NyFtxKkHgAAAGc"]
[Thu Jul 30 14:10:31.307199 2026] [security2:error] [pid 1004636:tid 1004860] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-includes/assets/"] [unique_id "amuhp-_uyupB2NyFtxKkIgAAACQ"]
[Thu Jul 30 14:10:31.456600 2026] [security2:error] [pid 1004636:tid 1004938] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/sunrise/"] [unique_id "amuhp-_uyupB2NyFtxKkJgAAAG4"]
[Thu Jul 30 14:10:31.589874 2026] [security2:error] [pid 1004636:tid 1004833] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xstelth.php"] [unique_id "amuhp-_uyupB2NyFtxKkLQAAAAs"]
[Thu Jul 30 14:10:31.590002 2026] [security2:error] [pid 1004636:tid 1004833] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xstelth.php"] [unique_id "amuhp-_uyupB2NyFtxKkLQAAAAs"]
[Thu Jul 30 14:10:31.841594 2026] [security2:error] [pid 1004636:tid 1004929] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuhp-_uyupB2NyFtxKkNgAAAGY"]
[Thu Jul 30 14:10:31.841694 2026] [security2:error] [pid 1004636:tid 1004929] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuhp-_uyupB2NyFtxKkNgAAAGY"]
[Thu Jul 30 14:10:32.056092 2026] [security2:error] [pid 1004636:tid 1004932] [client 20.104.18.253:23005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/edit.php"] [unique_id "amuhqO_uyupB2NyFtxKkOwAAAGk"]
[Thu Jul 30 14:10:32.096288 2026] [security2:error] [pid 1004636:tid 1004861] [client 39.32.55.127:36370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhp-_uyupB2NyFtxKkMwAAACU"], referer: http://pkf.jo
[Thu Jul 30 14:10:32.101412 2026] [security2:error] [pid 1004636:tid 1004864] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/aaa.php"] [unique_id "amuhqO_uyupB2NyFtxKkPAAAACg"]
[Thu Jul 30 14:10:32.101514 2026] [security2:error] [pid 1004636:tid 1004864] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/aaa.php"] [unique_id "amuhqO_uyupB2NyFtxKkPAAAACg"]
[Thu Jul 30 14:10:32.179295 2026] [security2:error] [pid 1004636:tid 1004879] [client 170.231.18.119:45032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhp-_uyupB2NyFtxKkOQAAADc"], referer: http://pkf.jo
[Thu Jul 30 14:10:32.322113 2026] [security2:error] [pid 1004636:tid 1004899] [client 110.249.202.33:31154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "smoke-tfhk.com"] [uri "/robots.txt"] [unique_id "amuhqO_uyupB2NyFtxKkSwAAAEk"]
[Thu Jul 30 14:10:32.346826 2026] [security2:error] [pid 1004636:tid 1004945] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/gecko.php"] [unique_id "amuhqO_uyupB2NyFtxKkTAAAAHU"]
[Thu Jul 30 14:10:32.346999 2026] [security2:error] [pid 1004636:tid 1004945] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/gecko.php"] [unique_id "amuhqO_uyupB2NyFtxKkTAAAAHU"]
[Thu Jul 30 14:10:32.409072 2026] [security2:error] [pid 1004636:tid 1004846] [client 113.211.214.25:6539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhqO_uyupB2NyFtxKkPQAAABc"], referer: http://pkf.jo
[Thu Jul 30 14:10:32.463391 2026] [security2:error] [pid 1004636:tid 1004850] [client 115.164.80.175:48309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhqO_uyupB2NyFtxKkQQAAABs"], referer: http://pkf.jo
[Thu Jul 30 14:10:32.565742 2026] [security2:error] [pid 1004636:tid 1004823] [client 197.214.238.188:6841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhqO_uyupB2NyFtxKkSQAAAAE"], referer: http://pkf.jo
[Thu Jul 30 14:10:32.587090 2026] [security2:error] [pid 1004636:tid 1004855] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/pbck.php"] [unique_id "amuhqO_uyupB2NyFtxKkUAAAAB8"]
[Thu Jul 30 14:10:32.587187 2026] [security2:error] [pid 1004636:tid 1004855] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/pbck.php"] [unique_id "amuhqO_uyupB2NyFtxKkUAAAAB8"]
[Thu Jul 30 14:10:32.808695 2026] [security2:error] [pid 1004636:tid 1004917] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuhqO_uyupB2NyFtxKkQgAAAFs"]
[Thu Jul 30 14:10:32.838368 2026] [security2:error] [pid 1004636:tid 1004896] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xiugai.php"] [unique_id "amuhqO_uyupB2NyFtxKkWAAAAEY"]
[Thu Jul 30 14:10:32.838463 2026] [security2:error] [pid 1004636:tid 1004896] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xiugai.php"] [unique_id "amuhqO_uyupB2NyFtxKkWAAAAEY"]
[Thu Jul 30 14:10:33.091337 2026] [security2:error] [pid 1004636:tid 1004847] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/e.php"] [unique_id "amuhqe_uyupB2NyFtxKkXAAAABg"]
[Thu Jul 30 14:10:33.091444 2026] [security2:error] [pid 1004636:tid 1004847] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/e.php"] [unique_id "amuhqe_uyupB2NyFtxKkXAAAABg"]
[Thu Jul 30 14:10:33.168800 2026] [security2:error] [pid 1004636:tid 1004888] [client 20.104.18.253:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/f35.php"] [unique_id "amuhqe_uyupB2NyFtxKkXQAAAD8"]
[Thu Jul 30 14:10:33.336954 2026] [security2:error] [pid 1004636:tid 1004903] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/adminner.php"] [unique_id "amuhqe_uyupB2NyFtxKkZQAAAE0"]
[Thu Jul 30 14:10:33.337102 2026] [security2:error] [pid 1004636:tid 1004903] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/adminner.php"] [unique_id "amuhqe_uyupB2NyFtxKkZQAAAE0"]
[Thu Jul 30 14:10:33.518262 2026] [security2:error] [pid 1004636:tid 1004940] [client 177.35.193.193:23899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhqe_uyupB2NyFtxKkXgAAAHA"], referer: http://pkf.jo
[Thu Jul 30 14:10:33.581948 2026] [security2:error] [pid 1004636:tid 1004875] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file1221.php"] [unique_id "amuhqe_uyupB2NyFtxKkaQAAADM"]
[Thu Jul 30 14:10:33.582091 2026] [security2:error] [pid 1004636:tid 1004875] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/file1221.php"] [unique_id "amuhqe_uyupB2NyFtxKkaQAAADM"]
[Thu Jul 30 14:10:33.591671 2026] [proxy:error] [pid 1004636:tid 1004911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:33.591734 2026] [proxy_http:error] [pid 1004636:tid 1004911] [client 52.4.19.39:48487] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:33.592367 2026] [proxy:error] [pid 1004636:tid 1004911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:33.592415 2026] [proxy_http:error] [pid 1004636:tid 1004911] [client 52.4.19.39:48487] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:33.665740 2026] [proxy:error] [pid 1004636:tid 1004878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:33.665812 2026] [proxy_http:error] [pid 1004636:tid 1004878] [client 3.225.222.228:43184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:33.666703 2026] [proxy:error] [pid 1004636:tid 1004878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:33.666764 2026] [proxy_http:error] [pid 1004636:tid 1004878] [client 3.225.222.228:43184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:33.826365 2026] [security2:error] [pid 1004636:tid 1004912] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/inx.php"] [unique_id "amuhqe_uyupB2NyFtxKkgAAAAFY"]
[Thu Jul 30 14:10:33.826471 2026] [security2:error] [pid 1004636:tid 1004912] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/inx.php"] [unique_id "amuhqe_uyupB2NyFtxKkgAAAAFY"]
[Thu Jul 30 14:10:34.058771 2026] [security2:error] [pid 1004636:tid 1004939] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/ws77.php"] [unique_id "amuhqu_uyupB2NyFtxKkhwAAAG8"]
[Thu Jul 30 14:10:34.058944 2026] [security2:error] [pid 1004636:tid 1004939] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/ws77.php"] [unique_id "amuhqu_uyupB2NyFtxKkhwAAAG8"]
[Thu Jul 30 14:10:34.086239 2026] [security2:error] [pid 1004636:tid 1004849] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/qqqa.php"] [unique_id "amuhqu_uyupB2NyFtxKkiAAAABo"]
[Thu Jul 30 14:10:34.086327 2026] [security2:error] [pid 1004636:tid 1004849] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/qqqa.php"] [unique_id "amuhqu_uyupB2NyFtxKkiAAAABo"]
[Thu Jul 30 14:10:34.125077 2026] [security2:error] [pid 1004636:tid 1004864] [client 206.1.80.141:38532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhqe_uyupB2NyFtxKkfgAAACg"], referer: http://pkf.jo
[Thu Jul 30 14:10:34.131851 2026] [security2:error] [pid 1004636:tid 1004915] [client 85.100.183.109:36614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhqe_uyupB2NyFtxKkfwAAAFk"], referer: http://pkf.jo
[Thu Jul 30 14:10:34.328839 2026] [security2:error] [pid 1004636:tid 1004953] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/reviall.php"] [unique_id "amuhqu_uyupB2NyFtxKkiwAAAH0"]
[Thu Jul 30 14:10:34.329001 2026] [security2:error] [pid 1004636:tid 1004953] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/reviall.php"] [unique_id "amuhqu_uyupB2NyFtxKkiwAAAH0"]
[Thu Jul 30 14:10:34.564823 2026] [security2:error] [pid 1004636:tid 1004865] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/404.php"] [unique_id "amuhqu_uyupB2NyFtxKklQAAACk"]
[Thu Jul 30 14:10:34.564918 2026] [security2:error] [pid 1004636:tid 1004865] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/404.php"] [unique_id "amuhqu_uyupB2NyFtxKklQAAACk"]
[Thu Jul 30 14:10:34.634109 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/nc4.php"] [unique_id "amuhqu_uyupB2NyFtxKkmQAAAD0"]
[Thu Jul 30 14:10:34.634225 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/nc4.php"] [unique_id "amuhqu_uyupB2NyFtxKkmQAAAD0"]
[Thu Jul 30 14:10:34.805164 2026] [security2:error] [pid 1004636:tid 1004954] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/bolt.php"] [unique_id "amuhqu_uyupB2NyFtxKknQAAAH4"]
[Thu Jul 30 14:10:34.805300 2026] [security2:error] [pid 1004636:tid 1004954] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/bolt.php"] [unique_id "amuhqu_uyupB2NyFtxKknQAAAH4"]
[Thu Jul 30 14:10:34.858106 2026] [security2:error] [pid 1004636:tid 1004840] [client 20.104.18.253:22980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/f7.php"] [unique_id "amuhqu_uyupB2NyFtxKknwAAABE"]
[Thu Jul 30 14:10:35.045717 2026] [security2:error] [pid 1004636:tid 1004885] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/File.php"] [unique_id "amuhq-_uyupB2NyFtxKkrgAAADw"]
[Thu Jul 30 14:10:35.045796 2026] [security2:error] [pid 1004636:tid 1004885] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/File.php"] [unique_id "amuhq-_uyupB2NyFtxKkrgAAADw"]
[Thu Jul 30 14:10:35.178314 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/as.php"] [unique_id "amuhq-_uyupB2NyFtxKksAAAAFU"]
[Thu Jul 30 14:10:35.178425 2026] [security2:error] [pid 1004636:tid 1004911] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/as.php"] [unique_id "amuhq-_uyupB2NyFtxKksAAAAFU"]
[Thu Jul 30 14:10:35.291877 2026] [security2:error] [pid 1004636:tid 1004942] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/fi22.php"] [unique_id "amuhq-_uyupB2NyFtxKktQAAAHI"]
[Thu Jul 30 14:10:35.291970 2026] [security2:error] [pid 1004636:tid 1004942] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/fi22.php"] [unique_id "amuhq-_uyupB2NyFtxKktQAAAHI"]
[Thu Jul 30 14:10:35.554253 2026] [security2:error] [pid 1004636:tid 1004835] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/zero.php"] [unique_id "amuhq-_uyupB2NyFtxKkxgAAAA0"]
[Thu Jul 30 14:10:35.554346 2026] [security2:error] [pid 1004636:tid 1004835] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/zero.php"] [unique_id "amuhq-_uyupB2NyFtxKkxgAAAA0"]
[Thu Jul 30 14:10:35.627236 2026] [security2:error] [pid 1004636:tid 1004912] [client 189.6.88.213:53502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhq-_uyupB2NyFtxKkyQAAAFY"]
[Thu Jul 30 14:10:35.627362 2026] [security2:error] [pid 1004636:tid 1004912] [client 189.6.88.213:53502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhq-_uyupB2NyFtxKkyQAAAFY"]
[Thu Jul 30 14:10:35.694622 2026] [security2:error] [pid 1004636:tid 1004855] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/k.php"] [unique_id "amuhq-_uyupB2NyFtxKkzAAAAB8"]
[Thu Jul 30 14:10:35.694711 2026] [security2:error] [pid 1004636:tid 1004855] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/k.php"] [unique_id "amuhq-_uyupB2NyFtxKkzAAAAB8"]
[Thu Jul 30 14:10:35.806027 2026] [security2:error] [pid 1004636:tid 1004895] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1xmomo.php"] [unique_id "amuhq-_uyupB2NyFtxKk0wAAAEU"]
[Thu Jul 30 14:10:35.806156 2026] [security2:error] [pid 1004636:tid 1004895] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1xmomo.php"] [unique_id "amuhq-_uyupB2NyFtxKk0wAAAEU"]
[Thu Jul 30 14:10:36.052627 2026] [proxy:error] [pid 1004636:tid 1004768] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:36.052686 2026] [proxy_http:error] [pid 1004636:tid 1004768] [remote 74.7.228.46:49384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:36.053472 2026] [proxy:error] [pid 1004636:tid 1004768] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:36.053518 2026] [proxy_http:error] [pid 1004636:tid 1004768] [remote 74.7.228.46:49384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:36.056510 2026] [security2:error] [pid 1004636:tid 1004858] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/fmws.php"] [unique_id "amuhrO_uyupB2NyFtxKk5AAAACI"]
[Thu Jul 30 14:10:36.056614 2026] [security2:error] [pid 1004636:tid 1004858] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/fmws.php"] [unique_id "amuhrO_uyupB2NyFtxKk5AAAACI"]
[Thu Jul 30 14:10:36.258425 2026] [security2:error] [pid 1004636:tid 1004918] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/system_log.php"] [unique_id "amuhrO_uyupB2NyFtxKk6gAAAFw"]
[Thu Jul 30 14:10:36.258545 2026] [security2:error] [pid 1004636:tid 1004918] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/system_log.php"] [unique_id "amuhrO_uyupB2NyFtxKk6gAAAFw"]
[Thu Jul 30 14:10:36.295113 2026] [security2:error] [pid 1004636:tid 1004872] [client 181.116.200.68:19552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhrO_uyupB2NyFtxKk7AAAADA"]
[Thu Jul 30 14:10:36.295225 2026] [security2:error] [pid 1004636:tid 1004872] [client 181.116.200.68:19552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhrO_uyupB2NyFtxKk7AAAADA"]
[Thu Jul 30 14:10:36.312302 2026] [security2:error] [pid 1004636:tid 1004941] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuhrO_uyupB2NyFtxKk7QAAAHE"]
[Thu Jul 30 14:10:36.312408 2026] [security2:error] [pid 1004636:tid 1004941] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuhrO_uyupB2NyFtxKk7QAAAHE"]
[Thu Jul 30 14:10:36.567548 2026] [security2:error] [pid 1004636:tid 1004842] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/hp2.php"] [unique_id "amuhrO_uyupB2NyFtxKlAAAAABM"]
[Thu Jul 30 14:10:36.567677 2026] [security2:error] [pid 1004636:tid 1004842] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/hp2.php"] [unique_id "amuhrO_uyupB2NyFtxKlAAAAABM"]
[Thu Jul 30 14:10:36.815931 2026] [security2:error] [pid 1004636:tid 1004921] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/aabb.php"] [unique_id "amuhrO_uyupB2NyFtxKlBgAAAF8"]
[Thu Jul 30 14:10:36.816062 2026] [security2:error] [pid 1004636:tid 1004921] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/aabb.php"] [unique_id "amuhrO_uyupB2NyFtxKlBgAAAF8"]
[Thu Jul 30 14:10:36.844720 2026] [security2:error] [pid 1004636:tid 1004929] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/x.php"] [unique_id "amuhrO_uyupB2NyFtxKlBwAAAGY"]
[Thu Jul 30 14:10:36.844829 2026] [security2:error] [pid 1004636:tid 1004929] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/x.php"] [unique_id "amuhrO_uyupB2NyFtxKlBwAAAGY"]
[Thu Jul 30 14:10:37.059107 2026] [security2:error] [pid 1004636:tid 1004895] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1254xx.php"] [unique_id "amuhre_uyupB2NyFtxKlDgAAAEU"]
[Thu Jul 30 14:10:37.059252 2026] [security2:error] [pid 1004636:tid 1004895] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1254xx.php"] [unique_id "amuhre_uyupB2NyFtxKlDgAAAEU"]
[Thu Jul 30 14:10:37.302857 2026] [security2:error] [pid 1004636:tid 1004907] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuhre_uyupB2NyFtxKlFgAAAFE"]
[Thu Jul 30 14:10:37.302968 2026] [security2:error] [pid 1004636:tid 1004907] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuhre_uyupB2NyFtxKlFgAAAFE"]
[Thu Jul 30 14:10:37.475571 2026] [security2:error] [pid 1004636:tid 1004902] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/autoload_classmap.php"] [unique_id "amuhre_uyupB2NyFtxKlGgAAAEw"]
[Thu Jul 30 14:10:37.475694 2026] [security2:error] [pid 1004636:tid 1004902] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/autoload_classmap.php"] [unique_id "amuhre_uyupB2NyFtxKlGgAAAEw"]
[Thu Jul 30 14:10:37.521402 2026] [security2:error] [pid 1004636:tid 1004890] [client 103.190.40.154:19202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhre_uyupB2NyFtxKlGwAAAEE"]
[Thu Jul 30 14:10:37.521565 2026] [security2:error] [pid 1004636:tid 1004890] [client 103.190.40.154:19202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhre_uyupB2NyFtxKlGwAAAEE"]
[Thu Jul 30 14:10:37.553487 2026] [security2:error] [pid 1004636:tid 1004865] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/pms297.php"] [unique_id "amuhre_uyupB2NyFtxKlHAAAACk"]
[Thu Jul 30 14:10:37.553651 2026] [security2:error] [pid 1004636:tid 1004865] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/pms297.php"] [unique_id "amuhre_uyupB2NyFtxKlHAAAACk"]
[Thu Jul 30 14:10:37.797860 2026] [security2:error] [pid 1004636:tid 1004825] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuhre_uyupB2NyFtxKlIwAAAAM"]
[Thu Jul 30 14:10:37.797991 2026] [security2:error] [pid 1004636:tid 1004825] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuhre_uyupB2NyFtxKlIwAAAAM"]
[Thu Jul 30 14:10:37.836559 2026] [security2:error] [pid 1004636:tid 1004904] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuhre_uyupB2NyFtxKlFQAATgE"]
[Thu Jul 30 14:10:37.886232 2026] [security2:error] [pid 1004636:tid 1004848] [client 129.227.44.38:48591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.axm.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuhrO_uyupB2NyFtxKlCwAAABk"]
[Thu Jul 30 14:10:37.907810 2026] [security2:error] [pid 1004636:tid 1004876] [client 129.227.44.38:48579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.mshandco.org"] [uri "/wp-login.php"] [unique_id "amuhrO_uyupB2NyFtxKk8wAAADQ"]
[Thu Jul 30 14:10:37.938198 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.7.241.175:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.widedaddy.com"] [uri "/index.php"] [unique_id "amuhq-_uyupB2NyFtxKkwAAAMwM"]
[Thu Jul 30 14:10:37.938227 2026] [security2:error] [pid 1004636:tid 1004875] [client 74.7.241.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.widedaddy.com"] [uri "/index.php"] [unique_id "amuhq-_uyupB2NyFtxKkwAAAMwM"]
[Thu Jul 30 14:10:38.033848 2026] [security2:error] [pid 1004636:tid 1004885] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/test1.php"] [unique_id "amuhru_uyupB2NyFtxKlKAAAADw"]
[Thu Jul 30 14:10:38.033997 2026] [security2:error] [pid 1004636:tid 1004885] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/test1.php"] [unique_id "amuhru_uyupB2NyFtxKlKAAAADw"]
[Thu Jul 30 14:10:38.048400 2026] [security2:error] [pid 1004636:tid 1004860] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuhru_uyupB2NyFtxKlKQAAACQ"]
[Thu Jul 30 14:10:38.048499 2026] [security2:error] [pid 1004636:tid 1004860] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuhru_uyupB2NyFtxKlKQAAACQ"]
[Thu Jul 30 14:10:38.179849 2026] [security2:error] [pid 1004636:tid 1004933] [client 171.227.179.151:42686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhre_uyupB2NyFtxKlJAAAAGo"], referer: http://pkf.jo
[Thu Jul 30 14:10:38.303178 2026] [security2:error] [pid 1004636:tid 1004906] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuhru_uyupB2NyFtxKlNwAAAFA"]
[Thu Jul 30 14:10:38.303329 2026] [security2:error] [pid 1004636:tid 1004906] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuhru_uyupB2NyFtxKlNwAAAFA"]
[Thu Jul 30 14:10:38.554966 2026] [security2:error] [pid 1004636:tid 1004915] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuhru_uyupB2NyFtxKlQAAAAFk"]
[Thu Jul 30 14:10:38.555073 2026] [security2:error] [pid 1004636:tid 1004915] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuhru_uyupB2NyFtxKlQAAAAFk"]
[Thu Jul 30 14:10:38.578872 2026] [security2:error] [pid 1004636:tid 1004845] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "propertyspro.com"] [uri "/mini"] [unique_id "amuhru_uyupB2NyFtxKlQQAAABY"]
[Thu Jul 30 14:10:38.664339 2026] [core:notice] [pid 1004636:tid 1004747] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:38.800263 2026] [security2:error] [pid 1004636:tid 1004834] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dyui.php"] [unique_id "amuhru_uyupB2NyFtxKlRwAAAAw"]
[Thu Jul 30 14:10:38.800380 2026] [security2:error] [pid 1004636:tid 1004834] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/dyui.php"] [unique_id "amuhru_uyupB2NyFtxKlRwAAAAw"]
[Thu Jul 30 14:10:38.911126 2026] [core:notice] [pid 1004636:tid 1004717] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:38.915217 2026] [security2:error] [pid 1004636:tid 1004850] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "propertyspro.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuhru_uyupB2NyFtxKlSAAAABs"]
[Thu Jul 30 14:10:39.045678 2026] [security2:error] [pid 1004636:tid 1004827] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ho.php"] [unique_id "amuhr-_uyupB2NyFtxKlUAAAAAU"]
[Thu Jul 30 14:10:39.045780 2026] [security2:error] [pid 1004636:tid 1004827] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ho.php"] [unique_id "amuhr-_uyupB2NyFtxKlUAAAAAU"]
[Thu Jul 30 14:10:39.217197 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-signin.php"] [unique_id "amuhr-_uyupB2NyFtxKlVwAAAD0"]
[Thu Jul 30 14:10:39.217294 2026] [security2:error] [pid 1004636:tid 1004886] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-signin.php"] [unique_id "amuhr-_uyupB2NyFtxKlVwAAAD0"]
[Thu Jul 30 14:10:39.300155 2026] [security2:error] [pid 1004636:tid 1004843] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/66b867516c8f01.php"] [unique_id "amuhr-_uyupB2NyFtxKlWAAAABQ"]
[Thu Jul 30 14:10:39.300264 2026] [security2:error] [pid 1004636:tid 1004843] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/66b867516c8f01.php"] [unique_id "amuhr-_uyupB2NyFtxKlWAAAABQ"]
[Thu Jul 30 14:10:39.544540 2026] [security2:error] [pid 1004636:tid 1004866] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ext.php"] [unique_id "amuhr-_uyupB2NyFtxKlZQAAACo"]
[Thu Jul 30 14:10:39.544696 2026] [security2:error] [pid 1004636:tid 1004866] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/ext.php"] [unique_id "amuhr-_uyupB2NyFtxKlZQAAACo"]
[Thu Jul 30 14:10:39.731298 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/gg.php"] [unique_id "amuhr-_uyupB2NyFtxKlbQAAADQ"]
[Thu Jul 30 14:10:39.731386 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/gg.php"] [unique_id "amuhr-_uyupB2NyFtxKlbQAAADQ"]
[Thu Jul 30 14:10:39.802929 2026] [security2:error] [pid 1004636:tid 1004875] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuhr-_uyupB2NyFtxKlbgAAADM"]
[Thu Jul 30 14:10:39.803037 2026] [security2:error] [pid 1004636:tid 1004875] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuhr-_uyupB2NyFtxKlbgAAADM"]
[Thu Jul 30 14:10:39.815372 2026] [security2:error] [pid 1004636:tid 1004856] [client 20.251.58.190:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuhr-_uyupB2NyFtxKlZgAAACA"]
[Thu Jul 30 14:10:39.815468 2026] [security2:error] [pid 1004636:tid 1004856] [client 20.251.58.190:43924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuhr-_uyupB2NyFtxKlZgAAACA"]
[Thu Jul 30 14:10:40.038399 2026] [security2:error] [pid 1004636:tid 1004909] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuhsO_uyupB2NyFtxKlcgAAAFM"]
[Thu Jul 30 14:10:40.038509 2026] [security2:error] [pid 1004636:tid 1004909] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuhsO_uyupB2NyFtxKlcgAAAFM"]
[Thu Jul 30 14:10:40.171569 2026] [security2:error] [pid 1004636:tid 1004844] [client 82.79.153.131:53370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhr-_uyupB2NyFtxKlbwAAABU"], referer: http://pkf.jo
[Thu Jul 30 14:10:40.292811 2026] [security2:error] [pid 1004636:tid 1004917] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/584062352875874akp.php"] [unique_id "amuhsO_uyupB2NyFtxKlfQAAAFs"]
[Thu Jul 30 14:10:40.292921 2026] [security2:error] [pid 1004636:tid 1004917] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/584062352875874akp.php"] [unique_id "amuhsO_uyupB2NyFtxKlfQAAAFs"]
[Thu Jul 30 14:10:40.312474 2026] [security2:error] [pid 1004636:tid 1004934] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/class.php"] [unique_id "amuhsO_uyupB2NyFtxKlfgAAAGs"]
[Thu Jul 30 14:10:40.312613 2026] [security2:error] [pid 1004636:tid 1004934] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/class.php"] [unique_id "amuhsO_uyupB2NyFtxKlfgAAAGs"]
[Thu Jul 30 14:10:40.391347 2026] [security2:error] [pid 1004636:tid 1004906] [client 20.251.58.190:33483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuhsO_uyupB2NyFtxKlfwAAAFA"]
[Thu Jul 30 14:10:40.391496 2026] [security2:error] [pid 1004636:tid 1004906] [client 20.251.58.190:33483] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuhsO_uyupB2NyFtxKlfwAAAFA"]
[Thu Jul 30 14:10:40.532814 2026] [security2:error] [pid 1004636:tid 1004955] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/diidi.php"] [unique_id "amuhsO_uyupB2NyFtxKlgAAAAH8"]
[Thu Jul 30 14:10:40.532935 2026] [security2:error] [pid 1004636:tid 1004955] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/diidi.php"] [unique_id "amuhsO_uyupB2NyFtxKlgAAAAH8"]
[Thu Jul 30 14:10:40.657101 2026] [core:notice] [pid 1004636:tid 1004949] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:40.781243 2026] [security2:error] [pid 1004636:tid 1004924] [client 4.185.41.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.185.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/clarebypas.php"] [unique_id "amuhsO_uyupB2NyFtxKljAAAAGE"]
[Thu Jul 30 14:10:40.781352 2026] [security2:error] [pid 1004636:tid 1004924] [client 4.185.41.66:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.tranquilrootsisb.space"] [uri "/clarebypas.php"] [unique_id "amuhsO_uyupB2NyFtxKljAAAAGE"]
[Thu Jul 30 14:10:40.933169 2026] [security2:error] [pid 1004636:tid 1004855] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/404.php"] [unique_id "amuhsO_uyupB2NyFtxKljgAAAB8"]
[Thu Jul 30 14:10:40.933324 2026] [security2:error] [pid 1004636:tid 1004855] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/404.php"] [unique_id "amuhsO_uyupB2NyFtxKljgAAAB8"]
[Thu Jul 30 14:10:41.002641 2026] [security2:error] [pid 1004636:tid 1004945] [client 20.251.58.190:43913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/x.php"] [unique_id "amuhse_uyupB2NyFtxKljwAAAHU"]
[Thu Jul 30 14:10:41.002763 2026] [security2:error] [pid 1004636:tid 1004945] [client 20.251.58.190:43913] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/x.php"] [unique_id "amuhse_uyupB2NyFtxKljwAAAHU"]
[Thu Jul 30 14:10:41.460236 2026] [security2:error] [pid 1004636:tid 1004926] [client 20.251.58.190:16865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/by.php"] [unique_id "amuhse_uyupB2NyFtxKlnAAAAGM"]
[Thu Jul 30 14:10:41.460342 2026] [security2:error] [pid 1004636:tid 1004926] [client 20.251.58.190:16865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/by.php"] [unique_id "amuhse_uyupB2NyFtxKlnAAAAGM"]
[Thu Jul 30 14:10:41.528127 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/lite.php"] [unique_id "amuhse_uyupB2NyFtxKlngAAAAs"]
[Thu Jul 30 14:10:41.528256 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/lite.php"] [unique_id "amuhse_uyupB2NyFtxKlngAAAAs"]
[Thu Jul 30 14:10:41.824694 2026] [security2:error] [pid 1004636:tid 1004930] [client 78.163.176.82:1652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhse_uyupB2NyFtxKlnQAAAGc"], referer: http://pkf.jo
[Thu Jul 30 14:10:41.900938 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.251.58.190:47705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/cxs.php"] [unique_id "amuhse_uyupB2NyFtxKlqwAAAFM"]
[Thu Jul 30 14:10:41.901072 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.251.58.190:47705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/cxs.php"] [unique_id "amuhse_uyupB2NyFtxKlqwAAAFM"]
[Thu Jul 30 14:10:42.065226 2026] [security2:error] [pid 1004636:tid 1004916] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/lock360.php"] [unique_id "amuhsu_uyupB2NyFtxKlrQAAAFo"]
[Thu Jul 30 14:10:42.065345 2026] [security2:error] [pid 1004636:tid 1004916] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/lock360.php"] [unique_id "amuhsu_uyupB2NyFtxKlrQAAAFo"]
[Thu Jul 30 14:10:42.208234 2026] [security2:error] [pid 1004636:tid 1004903] [client 79.235.89.228:60320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhse_uyupB2NyFtxKlrAAAAE0"], referer: http://pkf.jo
[Thu Jul 30 14:10:42.314851 2026] [security2:error] [pid 1004636:tid 1004888] [client 20.251.58.190:43972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/coffexium.php"] [unique_id "amuhsu_uyupB2NyFtxKltAAAAD8"]
[Thu Jul 30 14:10:42.314956 2026] [security2:error] [pid 1004636:tid 1004888] [client 20.251.58.190:43972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/coffexium.php"] [unique_id "amuhsu_uyupB2NyFtxKltAAAAD8"]
[Thu Jul 30 14:10:42.651241 2026] [security2:error] [pid 1004636:tid 1004877] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuhsu_uyupB2NyFtxKlzgAAADU"]
[Thu Jul 30 14:10:42.651401 2026] [security2:error] [pid 1004636:tid 1004877] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "amuhsu_uyupB2NyFtxKlzgAAADU"]
[Thu Jul 30 14:10:42.716622 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.251.58.190:16883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/asdf.php"] [unique_id "amuhsu_uyupB2NyFtxKlzwAAAH4"]
[Thu Jul 30 14:10:42.716733 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.251.58.190:16883] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/asdf.php"] [unique_id "amuhsu_uyupB2NyFtxKlzwAAAH4"]
[Thu Jul 30 14:10:43.243836 2026] [security2:error] [pid 1004636:tid 1004936] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-links-opml.php"] [unique_id "amuhs-_uyupB2NyFtxKl2gAAAGw"]
[Thu Jul 30 14:10:43.243943 2026] [security2:error] [pid 1004636:tid 1004936] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-links-opml.php"] [unique_id "amuhs-_uyupB2NyFtxKl2gAAAGw"]
[Thu Jul 30 14:10:43.247476 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.251.58.190:33408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/red.php"] [unique_id "amuhs-_uyupB2NyFtxKl2wAAAFY"]
[Thu Jul 30 14:10:43.247556 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.251.58.190:33408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/red.php"] [unique_id "amuhs-_uyupB2NyFtxKl2wAAAFY"]
[Thu Jul 30 14:10:43.685096 2026] [security2:error] [pid 1004636:tid 1004880] [client 20.251.58.190:43946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.kendarikomputer.com"] [uri "/cgi-sys/404.html"] [unique_id "amuhs-_uyupB2NyFtxKl7wAAADg"]
[Thu Jul 30 14:10:43.780134 2026] [core:notice] [pid 1004636:tid 1004848] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:43.780523 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/uploads/min.php"] [unique_id "amuhs-_uyupB2NyFtxKl9wAAAAk"]
[Thu Jul 30 14:10:43.780653 2026] [security2:error] [pid 1004636:tid 1004831] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "propertyspro.com"] [uri "/wp-content/uploads/min.php"] [unique_id "amuhs-_uyupB2NyFtxKl9wAAAAk"]
[Thu Jul 30 14:10:43.832991 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.251.58.190:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuhs-_uyupB2NyFtxKl-AAAADQ"]
[Thu Jul 30 14:10:43.833085 2026] [security2:error] [pid 1004636:tid 1004876] [client 20.251.58.190:43946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuhs-_uyupB2NyFtxKl-AAAADQ"]
[Thu Jul 30 14:10:44.202701 2026] [security2:error] [pid 1004636:tid 1004923] [client 20.251.58.190:16892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.kendarikomputer.com"] [uri "/cgi-sys/404.html"] [unique_id "amuhtO_uyupB2NyFtxKmEAAAAGA"]
[Thu Jul 30 14:10:44.350969 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.251.58.190:16892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/footer.php"] [unique_id "amuhtO_uyupB2NyFtxKmGQAAAG4"]
[Thu Jul 30 14:10:44.351119 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.251.58.190:16892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/footer.php"] [unique_id "amuhtO_uyupB2NyFtxKmGQAAAG4"]
[Thu Jul 30 14:10:44.639827 2026] [security2:error] [pid 1004636:tid 1004829] [client 144.172.114.51:40994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuhtO_uyupB2NyFtxKmKwAAAAc"]
[Thu Jul 30 14:10:44.889898 2026] [security2:error] [pid 1004636:tid 1004898] [client 20.251.58.190:43927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.kendarikomputer.com"] [uri "/cgi-sys/404.html"] [unique_id "amuhtO_uyupB2NyFtxKmNAAAAEg"]
[Thu Jul 30 14:10:45.075315 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.251.58.190:43927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/wp-content/index.php"] [unique_id "amuhte_uyupB2NyFtxKmPwAAAE4"]
[Thu Jul 30 14:10:45.075446 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.251.58.190:43927] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/wp-content/index.php"] [unique_id "amuhte_uyupB2NyFtxKmPwAAAE4"]
[Thu Jul 30 14:10:45.469512 2026] [security2:error] [pid 1004636:tid 1004930] [client 129.227.44.38:23025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "axm.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuhte_uyupB2NyFtxKmTAAAAGc"]
[Thu Jul 30 14:10:45.588383 2026] [security2:error] [pid 1004636:tid 1004873] [client 97.119.162.23:46346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhte_uyupB2NyFtxKmSgAAADE"], referer: http://pkf.jo
[Thu Jul 30 14:10:45.598127 2026] [security2:error] [pid 1004636:tid 1004867] [client 200.75.125.231:60130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhte_uyupB2NyFtxKmTQAAACs"], referer: http://pkf.jo
[Thu Jul 30 14:10:45.645678 2026] [security2:error] [pid 1004636:tid 1004910] [client 129.227.44.38:23029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.mshandco.org"] [uri "/wp-login.php"] [unique_id "amuhte_uyupB2NyFtxKmVAAAAFQ"]
[Thu Jul 30 14:10:45.658554 2026] [security2:error] [pid 1004636:tid 1004843] [client 54.163.136.244:59740] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2014/07/IMG_20140728_183330052.jpg"] [unique_id "amuhte_uyupB2NyFtxKmXAAAABQ"]
[Thu Jul 30 14:10:45.881097 2026] [autoindex:error] [pid 1004636:tid 1004892] [client 20.251.58.190:43910] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_d5b66369/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:10:45.881702 2026] [security2:error] [pid 1004636:tid 1004892] [client 20.251.58.190:43910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.kendarikomputer.com"] [uri "/cgi-sys/403.html"] [unique_id "amuhte_uyupB2NyFtxKmZwAAAEM"]
[Thu Jul 30 14:10:46.036067 2026] [security2:error] [pid 1004636:tid 1004944] [client 20.251.58.190:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/zoro.php"] [unique_id "amuhtu_uyupB2NyFtxKmcQAAAHQ"]
[Thu Jul 30 14:10:46.036176 2026] [security2:error] [pid 1004636:tid 1004944] [client 20.251.58.190:43910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/zoro.php"] [unique_id "amuhtu_uyupB2NyFtxKmcQAAAHQ"]
[Thu Jul 30 14:10:46.272777 2026] [security2:error] [pid 1004636:tid 1004872] [client 144.172.114.51:41002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuhtu_uyupB2NyFtxKmdQAAADA"]
[Thu Jul 30 14:10:46.351905 2026] [security2:error] [pid 1004636:tid 1004937] [client 189.6.88.213:54049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhtu_uyupB2NyFtxKmdwAAAG0"]
[Thu Jul 30 14:10:46.352037 2026] [security2:error] [pid 1004636:tid 1004937] [client 189.6.88.213:54049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhtu_uyupB2NyFtxKmdwAAAG0"]
[Thu Jul 30 14:10:46.449268 2026] [core:notice] [pid 1004636:tid 1004945] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:46.547024 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.251.58.190:33481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/wm.php"] [unique_id "amuhtu_uyupB2NyFtxKmgwAAAEU"]
[Thu Jul 30 14:10:46.547154 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.251.58.190:33481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/wm.php"] [unique_id "amuhtu_uyupB2NyFtxKmgwAAAEU"]
[Thu Jul 30 14:10:46.713369 2026] [security2:error] [pid 1004636:tid 1004901] [client 129.227.44.38:23037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mshandco.org"] [uri "/wp-login.php"] [unique_id "amuhtu_uyupB2NyFtxKmgQAAAEs"]
[Thu Jul 30 14:10:46.946294 2026] [security2:error] [pid 1004636:tid 1004841] [client 181.116.200.68:21271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhtu_uyupB2NyFtxKmjQAAABI"]
[Thu Jul 30 14:10:46.946472 2026] [security2:error] [pid 1004636:tid 1004841] [client 181.116.200.68:21271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhtu_uyupB2NyFtxKmjQAAABI"]
[Thu Jul 30 14:10:47.113360 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.251.58.190:33468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/bajah.php"] [unique_id "amuht-_uyupB2NyFtxKmlwAAAB0"]
[Thu Jul 30 14:10:47.113445 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.251.58.190:33468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/bajah.php"] [unique_id "amuht-_uyupB2NyFtxKmlwAAAB0"]
[Thu Jul 30 14:10:47.184522 2026] [core:notice] [pid 1004636:tid 1004862] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:47.579817 2026] [core:notice] [pid 1004636:tid 1004725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:47.646510 2026] [security2:error] [pid 1004636:tid 1004915] [client 129.227.44.38:23029] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "mail.mshandco.org"] [uri "/wp-includes/js/jquery/jquery.min.js"] [unique_id "amuht-_uyupB2NyFtxKmqwAAAFk"]
[Thu Jul 30 14:10:47.669951 2026] [core:notice] [pid 1004636:tid 1004942] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:47.770820 2026] [security2:error] [pid 1004636:tid 1004900] [client 20.251.58.190:33461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/cream1.php"] [unique_id "amuht-_uyupB2NyFtxKmrgAAAEo"]
[Thu Jul 30 14:10:47.770924 2026] [security2:error] [pid 1004636:tid 1004900] [client 20.251.58.190:33461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/cream1.php"] [unique_id "amuht-_uyupB2NyFtxKmrgAAAEo"]
[Thu Jul 30 14:10:47.906770 2026] [core:notice] [pid 1004636:tid 1004944] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:47.915094 2026] [core:notice] [pid 1004636:tid 1004924] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:47.959416 2026] [security2:error] [pid 1004636:tid 1004831] [client 129.227.44.38:23015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ull.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuht-_uyupB2NyFtxKmkAAAAAk"]
[Thu Jul 30 14:10:48.194093 2026] [core:notice] [pid 1004636:tid 1004727] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:48.289654 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.251.58.190:33463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/lim.php"] [unique_id "amuhuO_uyupB2NyFtxKmxQAAAEU"]
[Thu Jul 30 14:10:48.289780 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.251.58.190:33463] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/lim.php"] [unique_id "amuhuO_uyupB2NyFtxKmxQAAAEU"]
[Thu Jul 30 14:10:48.317231 2026] [security2:error] [pid 1004636:tid 1004939] [client 57.141.0.56:59362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuht-_uyupB2NyFtxKmtwAAbxQ"], referer: https://igetvape-australia.com/product/iget-bar-strawberry-lemon-ice-3500-puffs/?add-to-cart=119
[Thu Jul 30 14:10:48.333759 2026] [security2:error] [pid 1004636:tid 1004844] [client 103.190.40.154:11842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhuO_uyupB2NyFtxKmxgAAABU"]
[Thu Jul 30 14:10:48.333881 2026] [security2:error] [pid 1004636:tid 1004844] [client 103.190.40.154:11842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhuO_uyupB2NyFtxKmxgAAABU"]
[Thu Jul 30 14:10:48.371995 2026] [security2:error] [pid 1004636:tid 1004947] [client 74.7.230.17:40462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.lvp.hfl.temporary.site"] [uri "/index.php"] [unique_id "amuht-_uyupB2NyFtxKmlAAAdzU"]
[Thu Jul 30 14:10:48.499605 2026] [core:notice] [pid 1004636:tid 1004723] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:48.694889 2026] [core:notice] [pid 1004636:tid 1004878] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:48.700403 2026] [core:notice] [pid 1004636:tid 1004940] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:48.881764 2026] [core:notice] [pid 1004636:tid 1004716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:48.956681 2026] [core:notice] [pid 1004636:tid 1004852] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:48.965879 2026] [core:notice] [pid 1004636:tid 1004884] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:48.978525 2026] [security2:error] [pid 1004636:tid 1004927] [client 20.251.58.190:33448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/heat3.php"] [unique_id "amuhuO_uyupB2NyFtxKm3QAAAGQ"]
[Thu Jul 30 14:10:48.978612 2026] [security2:error] [pid 1004636:tid 1004927] [client 20.251.58.190:33448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/heat3.php"] [unique_id "amuhuO_uyupB2NyFtxKm3QAAAGQ"]
[Thu Jul 30 14:10:49.138218 2026] [core:notice] [pid 1004636:tid 1004702] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:49.211534 2026] [core:notice] [pid 1004636:tid 1004843] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:49.226324 2026] [core:notice] [pid 1004636:tid 1004893] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:49.363669 2026] [security2:error] [pid 1004636:tid 1004919] [client 74.7.175.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ashbournerow.com"] [uri "/index.php"] [unique_id "amuhue_uyupB2NyFtxKm7QAAXVw"]
[Thu Jul 30 14:10:49.466581 2026] [core:notice] [pid 1004636:tid 1004899] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:49.486514 2026] [core:notice] [pid 1004636:tid 1004847] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:49.489156 2026] [security2:error] [pid 1004636:tid 1004900] [client 20.251.58.190:33477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/greap.php"] [unique_id "amuhue_uyupB2NyFtxKm8wAAAEo"]
[Thu Jul 30 14:10:49.489239 2026] [security2:error] [pid 1004636:tid 1004900] [client 20.251.58.190:33477] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/greap.php"] [unique_id "amuhue_uyupB2NyFtxKm8wAAAEo"]
[Thu Jul 30 14:10:49.494296 2026] [security2:error] [pid 1004636:tid 1004890] [client 172.237.109.114:8332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuhuO_uyupB2NyFtxKm3wAAAEE"]
[Thu Jul 30 14:10:49.720527 2026] [core:notice] [pid 1004636:tid 1004905] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:49.727941 2026] [core:notice] [pid 1004636:tid 1004801] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:49.747171 2026] [core:notice] [pid 1004636:tid 1004936] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:49.771175 2026] [security2:error] [pid 1004636:tid 1004874] [client 129.227.44.38:50929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.axm.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuhue_uyupB2NyFtxKm-AAAADI"]
[Thu Jul 30 14:10:49.916642 2026] [security2:error] [pid 1004636:tid 1004872] [client 54.147.238.89:48453] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2014/07/IMG_20140728_183919330.jpg"] [unique_id "amuhue_uyupB2NyFtxKnAgAAADA"]
[Thu Jul 30 14:10:49.987132 2026] [core:notice] [pid 1004636:tid 1004939] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:50.007259 2026] [core:notice] [pid 1004636:tid 1004877] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:50.070793 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.251.58.190:16849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/177.php"] [unique_id "amuhuu_uyupB2NyFtxKnBwAAAH4"]
[Thu Jul 30 14:10:50.070881 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.251.58.190:16849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/177.php"] [unique_id "amuhuu_uyupB2NyFtxKnBwAAAH4"]
[Thu Jul 30 14:10:50.242491 2026] [core:notice] [pid 1004636:tid 1004866] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:50.267690 2026] [core:notice] [pid 1004636:tid 1004878] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:50.475667 2026] [proxy:error] [pid 1004636:tid 1004824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:50.475743 2026] [proxy_http:error] [pid 1004636:tid 1004824] [client 52.202.41.153:36708] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:50.476313 2026] [proxy:error] [pid 1004636:tid 1004824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:10:50.476362 2026] [proxy_http:error] [pid 1004636:tid 1004824] [client 52.202.41.153:36708] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:10:50.499454 2026] [core:notice] [pid 1004636:tid 1004832] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:50.517693 2026] [security2:error] [pid 1004636:tid 1004840] [client 170.244.255.4:2510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhuu_uyupB2NyFtxKnDAAAABE"], referer: http://pkf.jo
[Thu Jul 30 14:10:50.527927 2026] [core:notice] [pid 1004636:tid 1004859] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:50.755042 2026] [core:notice] [pid 1004636:tid 1004902] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:50.788540 2026] [core:notice] [pid 1004636:tid 1004848] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:50.840491 2026] [security2:error] [pid 1004636:tid 1004868] [client 131.255.186.170:37477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhuu_uyupB2NyFtxKnHAAAACw"], referer: http://pkf.jo
[Thu Jul 30 14:10:50.971562 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.251.58.190:33532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/199.php"] [unique_id "amuhuu_uyupB2NyFtxKnKgAAAFQ"]
[Thu Jul 30 14:10:50.971688 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.251.58.190:33532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/199.php"] [unique_id "amuhuu_uyupB2NyFtxKnKgAAAFQ"]
[Thu Jul 30 14:10:51.675298 2026] [security2:error] [pid 1004636:tid 1004939] [client 20.251.58.190:43997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/file52.php"] [unique_id "amuhu-_uyupB2NyFtxKnQgAAAG8"]
[Thu Jul 30 14:10:51.675432 2026] [security2:error] [pid 1004636:tid 1004939] [client 20.251.58.190:43997] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/file52.php"] [unique_id "amuhu-_uyupB2NyFtxKnQgAAAG8"]
[Thu Jul 30 14:10:51.696079 2026] [security2:error] [pid 1004636:tid 1004881] [client 27.147.202.211:43298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhu-_uyupB2NyFtxKnOwAAADk"], referer: http://pkf.jo
[Thu Jul 30 14:10:52.078070 2026] [security2:error] [pid 1004636:tid 1004826] [client 172.237.109.114:26772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.swp"] [unique_id "amuhvO_uyupB2NyFtxKnTgAAAAQ"]
[Thu Jul 30 14:10:52.093392 2026] [security2:error] [pid 1004636:tid 1004941] [client 172.237.109.114:6396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.BAK"] [unique_id "amuhvO_uyupB2NyFtxKnTwAAAHE"]
[Thu Jul 30 14:10:52.093531 2026] [security2:error] [pid 1004636:tid 1004943] [client 172.237.109.114:56154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php~"] [unique_id "amuhvO_uyupB2NyFtxKnUAAAAHM"]
[Thu Jul 30 14:10:52.094105 2026] [security2:error] [pid 1004636:tid 1004878] [client 172.237.109.114:7543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.save"] [unique_id "amuhvO_uyupB2NyFtxKnUQAAADY"]
[Thu Jul 30 14:10:52.094417 2026] [security2:error] [pid 1004636:tid 1004861] [client 172.237.109.114:48000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php-backup"] [unique_id "amuhvO_uyupB2NyFtxKnUgAAACU"]
[Thu Jul 30 14:10:52.096827 2026] [security2:error] [pid 1004636:tid 1004940] [client 172.237.109.114:39050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-config.old"] [unique_id "amuhvO_uyupB2NyFtxKnUwAAAHA"]
[Thu Jul 30 14:10:52.103001 2026] [security2:error] [pid 1004636:tid 1004932] [client 172.237.109.114:28082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.txt"] [unique_id "amuhvO_uyupB2NyFtxKnVQAAAGk"]
[Thu Jul 30 14:10:52.120109 2026] [security2:error] [pid 1004636:tid 1004896] [client 172.237.109.114:43204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.old"] [unique_id "amuhvO_uyupB2NyFtxKnVwAAAEY"]
[Thu Jul 30 14:10:52.120767 2026] [security2:error] [pid 1004636:tid 1004845] [client 172.237.109.114:48010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.bak"] [unique_id "amuhvO_uyupB2NyFtxKnWAAAABY"]
[Thu Jul 30 14:10:52.121688 2026] [security2:error] [pid 1004636:tid 1004907] [client 172.237.109.114:16848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.html"] [unique_id "amuhvO_uyupB2NyFtxKnWgAAAFE"]
[Thu Jul 30 14:10:52.122487 2026] [security2:error] [pid 1004636:tid 1004824] [client 172.237.109.114:16771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-config-sample.php"] [unique_id "amuhvO_uyupB2NyFtxKnWwAAAAI"]
[Thu Jul 30 14:10:52.123992 2026] [security2:error] [pid 1004636:tid 1004828] [client 172.237.109.114:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-config.php"] [unique_id "amuhvO_uyupB2NyFtxKnXAAAAAY"]
[Thu Jul 30 14:10:52.150492 2026] [security2:error] [pid 1004636:tid 1004832] [client 172.237.109.114:1882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.dist"] [unique_id "amuhvO_uyupB2NyFtxKnXgAAAAo"]
[Thu Jul 30 14:10:52.150680 2026] [security2:error] [pid 1004636:tid 1004823] [client 172.237.109.114:33980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.OLD"] [unique_id "amuhvO_uyupB2NyFtxKnXwAAAAE"]
[Thu Jul 30 14:10:52.151071 2026] [security2:error] [pid 1004636:tid 1004849] [client 172.237.109.114:39885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.SAVE"] [unique_id "amuhvO_uyupB2NyFtxKnYgAAABo"]
[Thu Jul 30 14:10:52.151183 2026] [security2:error] [pid 1004636:tid 1004852] [client 172.237.109.114:4417] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.inc"] [unique_id "amuhvO_uyupB2NyFtxKnYwAAAB0"]
[Thu Jul 30 14:10:52.151495 2026] [security2:error] [pid 1004636:tid 1004840] [client 172.237.109.114:33047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/.wp-config.php.swp"] [unique_id "amuhvO_uyupB2NyFtxKnYQAAABE"]
[Thu Jul 30 14:10:52.373268 2026] [security2:error] [pid 1004636:tid 1004825] [client 129.227.44.38:0] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "mail.axm.gzj.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuhvO_uyupB2NyFtxKnZwAAAAM"]
[Thu Jul 30 14:10:52.373717 2026] [security2:error] [pid 1004636:tid 1004946] [client 129.227.44.38:50929] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "mail.axm.gzj.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuhvO_uyupB2NyFtxKnZQAAAHY"]
[Thu Jul 30 14:10:52.575261 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.251.58.190:33478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/122.php"] [unique_id "amuhvO_uyupB2NyFtxKnbwAAAE8"]
[Thu Jul 30 14:10:52.575411 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.251.58.190:33478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/122.php"] [unique_id "amuhvO_uyupB2NyFtxKnbwAAAE8"]
[Thu Jul 30 14:10:52.621940 2026] [security2:error] [pid 1004636:tid 1004904] [client 172.237.109.114:40908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuhvO_uyupB2NyFtxKnVAAAAE4"]
[Thu Jul 30 14:10:52.677163 2026] [security2:error] [pid 1004636:tid 1004791] [remote 57.141.0.35:59694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/94764231632/feed/rss2/"] [unique_id "amuhvO_uyupB2NyFtxKndgAADGQ"]
[Thu Jul 30 14:10:52.719724 2026] [security2:error] [pid 1004636:tid 1004918] [client 172.237.109.114:53848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuhvO_uyupB2NyFtxKnZAAAAFw"]
[Thu Jul 30 14:10:52.728877 2026] [security2:error] [pid 1004636:tid 1004859] [client 172.237.109.114:39345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuhvO_uyupB2NyFtxKnYAAAACM"]
[Thu Jul 30 14:10:53.087004 2026] [security2:error] [pid 1004636:tid 1004895] [client 144.172.114.51:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/backup/.env"] [unique_id "amuhve_uyupB2NyFtxKnfQAAAEU"]
[Thu Jul 30 14:10:53.246222 2026] [security2:error] [pid 1004636:tid 1004921] [client 20.251.58.190:43931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/green1.php"] [unique_id "amuhve_uyupB2NyFtxKngQAAAF8"]
[Thu Jul 30 14:10:53.246307 2026] [security2:error] [pid 1004636:tid 1004921] [client 20.251.58.190:43931] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/green1.php"] [unique_id "amuhve_uyupB2NyFtxKngQAAAF8"]
[Thu Jul 30 14:10:53.635171 2026] [security2:error] [pid 1004636:tid 1004832] [client 18.205.91.101:11675] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2014/07/IMG_20140728_183810184.jpg"] [unique_id "amuhve_uyupB2NyFtxKnigAAAAo"]
[Thu Jul 30 14:10:53.752354 2026] [security2:error] [pid 1004636:tid 1004896] [client 45.230.250.59:58262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhve_uyupB2NyFtxKniAAAAEY"], referer: http://pkf.jo
[Thu Jul 30 14:10:53.900691 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.251.58.190:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/sukce.php"] [unique_id "amuhve_uyupB2NyFtxKnlgAAAAs"]
[Thu Jul 30 14:10:53.900785 2026] [security2:error] [pid 1004636:tid 1004833] [client 20.251.58.190:33486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/sukce.php"] [unique_id "amuhve_uyupB2NyFtxKnlgAAAAs"]
[Thu Jul 30 14:10:53.946750 2026] [core:notice] [pid 1004636:tid 1004802] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:53.951524 2026] [security2:error] [pid 1004636:tid 1004866] [client 104.194.203.206:38312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/ikea/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2016/01/Ikea-TILLF\\xc3\\x84LLE-housse-de-coussin.jpg"] [unique_id "amuhve_uyupB2NyFtxKniwAAKm4"], referer: https://carnetdeshopping.com/index.php/tag/ikea/
[Thu Jul 30 14:10:53.967790 2026] [core:notice] [pid 1004636:tid 1004775] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:53.972447 2026] [security2:error] [pid 1004636:tid 1004845] [client 104.194.203.206:38324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/ikea/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/09/ikea_collection_sittning_pichet.jpg"] [unique_id "amuhve_uyupB2NyFtxKnjAAAFlQ"], referer: https://carnetdeshopping.com/index.php/tag/ikea/
[Thu Jul 30 14:10:54.590850 2026] [core:notice] [pid 1004636:tid 1004805] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:54.634364 2026] [core:notice] [pid 1004636:tid 1004689] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:54.719300 2026] [autoindex:error] [pid 1004636:tid 1004926] [client 3.228.112.215:4828] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:10:54.910357 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.251.58.190:44011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/xb.php"] [unique_id "amuhvu_uyupB2NyFtxKnrwAAAAw"]
[Thu Jul 30 14:10:54.910469 2026] [security2:error] [pid 1004636:tid 1004834] [client 20.251.58.190:44011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/xb.php"] [unique_id "amuhvu_uyupB2NyFtxKnrwAAAAw"]
[Thu Jul 30 14:10:55.411204 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.251.58.190:43911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/biufile.php"] [unique_id "amuhv-_uyupB2NyFtxKnvAAAAEU"]
[Thu Jul 30 14:10:55.411314 2026] [security2:error] [pid 1004636:tid 1004895] [client 20.251.58.190:43911] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/biufile.php"] [unique_id "amuhv-_uyupB2NyFtxKnvAAAAEU"]
[Thu Jul 30 14:10:55.449183 2026] [security2:error] [pid 1004636:tid 1004838] [client 95.13.154.128:34518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhv-_uyupB2NyFtxKnswAAAA8"], referer: http://pkf.jo
[Thu Jul 30 14:10:55.986119 2026] [core:notice] [pid 1004636:tid 1004700] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:56.045145 2026] [core:notice] [pid 1004636:tid 1004787] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:56.338515 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.251.58.190:16880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/wpconf.php"] [unique_id "amuhwO_uyupB2NyFtxKn1AAAABk"]
[Thu Jul 30 14:10:56.338645 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.251.58.190:16880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/wpconf.php"] [unique_id "amuhwO_uyupB2NyFtxKn1AAAABk"]
[Thu Jul 30 14:10:56.602072 2026] [security2:error] [pid 1004636:tid 1004873] [client 131.100.101.127:45506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhwO_uyupB2NyFtxKn0gAAADE"], referer: http://pkf.jo
[Thu Jul 30 14:10:56.895930 2026] [security2:error] [pid 1004636:tid 1004847] [client 20.251.58.190:43991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/ultradybbuks.php"] [unique_id "amuhwO_uyupB2NyFtxKn3wAAABg"]
[Thu Jul 30 14:10:56.896053 2026] [security2:error] [pid 1004636:tid 1004847] [client 20.251.58.190:43991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/ultradybbuks.php"] [unique_id "amuhwO_uyupB2NyFtxKn3wAAABg"]
[Thu Jul 30 14:10:57.091358 2026] [security2:error] [pid 1004636:tid 1004871] [client 189.6.88.213:54593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhwe_uyupB2NyFtxKn5QAAAC8"]
[Thu Jul 30 14:10:57.091963 2026] [security2:error] [pid 1004636:tid 1004871] [client 189.6.88.213:54593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhwe_uyupB2NyFtxKn5QAAAC8"]
[Thu Jul 30 14:10:57.363723 2026] [security2:error] [pid 1004636:tid 1004844] [client 20.251.58.190:43979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/novax.php"] [unique_id "amuhwe_uyupB2NyFtxKn6QAAABU"]
[Thu Jul 30 14:10:57.363838 2026] [security2:error] [pid 1004636:tid 1004844] [client 20.251.58.190:43979] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/novax.php"] [unique_id "amuhwe_uyupB2NyFtxKn6QAAABU"]
[Thu Jul 30 14:10:57.435316 2026] [security2:error] [pid 1004636:tid 1004912] [client 38.52.137.133:47136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhwe_uyupB2NyFtxKn5wAAAFY"], referer: http://pkf.jo
[Thu Jul 30 14:10:57.472141 2026] [security2:error] [pid 1004636:tid 1004859] [client 181.116.200.68:28407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhwe_uyupB2NyFtxKn8wAAACM"]
[Thu Jul 30 14:10:57.472266 2026] [security2:error] [pid 1004636:tid 1004859] [client 181.116.200.68:28407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhwe_uyupB2NyFtxKn8wAAACM"]
[Thu Jul 30 14:10:57.588521 2026] [security2:error] [pid 1004636:tid 1004953] [client 46.143.185.60:58048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhwe_uyupB2NyFtxKn6AAAAH0"], referer: http://pkf.jo
[Thu Jul 30 14:10:57.648091 2026] [core:notice] [pid 1004636:tid 1004838] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:57.703832 2026] [security2:error] [pid 1004636:tid 1004850] [client 50.19.79.213:18016] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2014/07/IMG_20140728_183832234.jpg"] [unique_id "amuhwe_uyupB2NyFtxKn-AAAABs"]
[Thu Jul 30 14:10:57.905080 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.251.58.190:16873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/mosty.php"] [unique_id "amuhwe_uyupB2NyFtxKn-gAAAH4"]
[Thu Jul 30 14:10:57.905184 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.251.58.190:16873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/mosty.php"] [unique_id "amuhwe_uyupB2NyFtxKn-gAAAH4"]
[Thu Jul 30 14:10:58.076555 2026] [security2:error] [pid 1004636:tid 1004832] [client 144.172.114.51:48336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/test/.env"] [unique_id "amuhwu_uyupB2NyFtxKoAAAAAAo"]
[Thu Jul 30 14:10:58.458997 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.251.58.190:33474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/dejavu.php"] [unique_id "amuhwu_uyupB2NyFtxKoCAAAAHw"]
[Thu Jul 30 14:10:58.459089 2026] [security2:error] [pid 1004636:tid 1004952] [client 20.251.58.190:33474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/dejavu.php"] [unique_id "amuhwu_uyupB2NyFtxKoCAAAAHw"]
[Thu Jul 30 14:10:58.839635 2026] [security2:error] [pid 1004636:tid 1004941] [client 20.251.58.190:33452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/aaf.php"] [unique_id "amuhwu_uyupB2NyFtxKoEAAAAHE"]
[Thu Jul 30 14:10:58.839749 2026] [security2:error] [pid 1004636:tid 1004941] [client 20.251.58.190:33452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/aaf.php"] [unique_id "amuhwu_uyupB2NyFtxKoEAAAAHE"]
[Thu Jul 30 14:10:58.963718 2026] [core:notice] [pid 1004636:tid 1004800] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:10:58.985474 2026] [security2:error] [pid 1004636:tid 1004822] [client 91.151.136.219:7050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuhwu_uyupB2NyFtxKoDwAAAAA"], referer: http://pkf.jo
[Thu Jul 30 14:10:59.014776 2026] [security2:error] [pid 1004636:tid 1004858] [client 103.190.40.154:20219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhw-_uyupB2NyFtxKoGQAAACI"]
[Thu Jul 30 14:10:59.014889 2026] [security2:error] [pid 1004636:tid 1004858] [client 103.190.40.154:20219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhw-_uyupB2NyFtxKoGQAAACI"]
[Thu Jul 30 14:10:59.210666 2026] [security2:error] [pid 1004636:tid 1004869] [client 20.251.58.190:44001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/b00869ae6e.php"] [unique_id "amuhw-_uyupB2NyFtxKoHwAAAC0"]
[Thu Jul 30 14:10:59.210775 2026] [security2:error] [pid 1004636:tid 1004869] [client 20.251.58.190:44001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/b00869ae6e.php"] [unique_id "amuhw-_uyupB2NyFtxKoHwAAAC0"]
[Thu Jul 30 14:10:59.684787 2026] [security2:error] [pid 1004636:tid 1004953] [client 20.251.58.190:16860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/term.php"] [unique_id "amuhw-_uyupB2NyFtxKoLwAAAH0"]
[Thu Jul 30 14:10:59.684895 2026] [security2:error] [pid 1004636:tid 1004953] [client 20.251.58.190:16860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/term.php"] [unique_id "amuhw-_uyupB2NyFtxKoLwAAAH0"]
[Thu Jul 30 14:11:00.140049 2026] [security2:error] [pid 1004636:tid 1004892] [client 20.251.58.190:44019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/wander.php"] [unique_id "amuhxO_uyupB2NyFtxKoOAAAAEM"]
[Thu Jul 30 14:11:00.140154 2026] [security2:error] [pid 1004636:tid 1004892] [client 20.251.58.190:44019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/wander.php"] [unique_id "amuhxO_uyupB2NyFtxKoOAAAAEM"]
[Thu Jul 30 14:11:00.843682 2026] [security2:error] [pid 1004636:tid 1004885] [client 20.251.58.190:44022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/ha.php"] [unique_id "amuhxO_uyupB2NyFtxKoSAAAADw"]
[Thu Jul 30 14:11:00.843781 2026] [security2:error] [pid 1004636:tid 1004885] [client 20.251.58.190:44022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/ha.php"] [unique_id "amuhxO_uyupB2NyFtxKoSAAAADw"]
[Thu Jul 30 14:11:01.166527 2026] [security2:error] [pid 1004636:tid 1004715] [remote 66.7.213.120:55904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.213.7.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amuhxO_uyupB2NyFtxKoSQAAFxo"]
[Thu Jul 30 14:11:01.512410 2026] [security2:error] [pid 1004636:tid 1004890] [client 113.44.124.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuhxe_uyupB2NyFtxKoVwAAAEE"]
[Thu Jul 30 14:11:01.638701 2026] [security2:error] [pid 1004636:tid 1004946] [client 20.251.58.190:43952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/hur.php"] [unique_id "amuhxe_uyupB2NyFtxKoXAAAAHY"]
[Thu Jul 30 14:11:01.638900 2026] [security2:error] [pid 1004636:tid 1004946] [client 20.251.58.190:43952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/hur.php"] [unique_id "amuhxe_uyupB2NyFtxKoXAAAAHY"]
[Thu Jul 30 14:11:02.199422 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.251.58.190:43962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/2222.php"] [unique_id "amuhxu_uyupB2NyFtxKoaQAAAFY"]
[Thu Jul 30 14:11:02.199513 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.251.58.190:43962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/2222.php"] [unique_id "amuhxu_uyupB2NyFtxKoaQAAAFY"]
[Thu Jul 30 14:11:02.299517 2026] [proxy:error] [pid 1004636:tid 1004831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:02.299604 2026] [proxy_http:error] [pid 1004636:tid 1004831] [client 3.228.112.215:64191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:02.300186 2026] [proxy:error] [pid 1004636:tid 1004831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:02.300232 2026] [proxy_http:error] [pid 1004636:tid 1004831] [client 3.228.112.215:64191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:02.308571 2026] [proxy:error] [pid 1004636:tid 1004886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:02.308635 2026] [proxy_http:error] [pid 1004636:tid 1004886] [client 54.87.222.253:25239] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:02.309197 2026] [proxy:error] [pid 1004636:tid 1004886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:02.309242 2026] [proxy_http:error] [pid 1004636:tid 1004886] [client 54.87.222.253:25239] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:02.772759 2026] [security2:error] [pid 1004636:tid 1004916] [client 20.251.58.190:33444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/h02ugyh.php"] [unique_id "amuhxu_uyupB2NyFtxKoiwAAAFo"]
[Thu Jul 30 14:11:02.772884 2026] [security2:error] [pid 1004636:tid 1004916] [client 20.251.58.190:33444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/h02ugyh.php"] [unique_id "amuhxu_uyupB2NyFtxKoiwAAAFo"]
[Thu Jul 30 14:11:03.244280 2026] [security2:error] [pid 1004636:tid 1004943] [client 20.251.58.190:33492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/seiso.php"] [unique_id "amuhx-_uyupB2NyFtxKongAAAHM"]
[Thu Jul 30 14:11:03.244376 2026] [security2:error] [pid 1004636:tid 1004943] [client 20.251.58.190:33492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/seiso.php"] [unique_id "amuhx-_uyupB2NyFtxKongAAAHM"]
[Thu Jul 30 14:11:03.841198 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.251.58.190:44025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/155.php"] [unique_id "amuhx-_uyupB2NyFtxKosgAAAG4"]
[Thu Jul 30 14:11:03.841289 2026] [security2:error] [pid 1004636:tid 1004938] [client 20.251.58.190:44025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/155.php"] [unique_id "amuhx-_uyupB2NyFtxKosgAAAG4"]
[Thu Jul 30 14:11:04.368148 2026] [security2:error] [pid 1004636:tid 1004824] [client 20.251.58.190:33414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/ppp.php"] [unique_id "amuhyO_uyupB2NyFtxKoxAAAAAI"]
[Thu Jul 30 14:11:04.368249 2026] [security2:error] [pid 1004636:tid 1004824] [client 20.251.58.190:33414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/ppp.php"] [unique_id "amuhyO_uyupB2NyFtxKoxAAAAAI"]
[Thu Jul 30 14:11:04.831837 2026] [security2:error] [pid 1004636:tid 1004823] [client 144.172.114.51:35782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/staging/.env"] [unique_id "amuhyO_uyupB2NyFtxKo0gAAAAE"]
[Thu Jul 30 14:11:04.951608 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.251.58.190:33415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/201.php"] [unique_id "amuhyO_uyupB2NyFtxKo0wAAAFQ"]
[Thu Jul 30 14:11:04.951720 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.251.58.190:33415] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/201.php"] [unique_id "amuhyO_uyupB2NyFtxKo0wAAAFQ"]
[Thu Jul 30 14:11:05.093236 2026] [security2:error] [pid 1004636:tid 1004833] [client 185.191.171.16:21168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/07/27/esposa-de-cid-moreira-rebate-acusacoes-de-carcere-privado-loucura/"] [unique_id "amuhye_uyupB2NyFtxKo1wAAAAs"]
[Thu Jul 30 14:11:05.093339 2026] [security2:error] [pid 1004636:tid 1004833] [client 185.191.171.16:21168] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/07/27/esposa-de-cid-moreira-rebate-acusacoes-de-carcere-privado-loucura/"] [unique_id "amuhye_uyupB2NyFtxKo1wAAAAs"]
[Thu Jul 30 14:11:05.467421 2026] [core:error] [pid 1004636:tid 1004847] [client 213.180.203.16:56192] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:11:05.467445 2026] [core:error] [pid 1004636:tid 1004847] [client 213.180.203.16:56192] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:11:05.585009 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.251.58.190:33411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/ops.php"] [unique_id "amuhye_uyupB2NyFtxKo4wAAAE4"]
[Thu Jul 30 14:11:05.585155 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.251.58.190:33411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/ops.php"] [unique_id "amuhye_uyupB2NyFtxKo4wAAAE4"]
[Thu Jul 30 14:11:06.218589 2026] [security2:error] [pid 1004636:tid 1004880] [client 20.251.58.190:20405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/samll.php"] [unique_id "amuhyu_uyupB2NyFtxKo9AAAADg"]
[Thu Jul 30 14:11:06.218728 2026] [security2:error] [pid 1004636:tid 1004880] [client 20.251.58.190:20405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/samll.php"] [unique_id "amuhyu_uyupB2NyFtxKo9AAAADg"]
[Thu Jul 30 14:11:06.843443 2026] [core:notice] [pid 1004636:tid 1004861] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:06.944639 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.251.58.190:33503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/ingfo.php"] [unique_id "amuhyu_uyupB2NyFtxKpCwAAAC4"]
[Thu Jul 30 14:11:06.944738 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.251.58.190:33503] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/ingfo.php"] [unique_id "amuhyu_uyupB2NyFtxKpCwAAAC4"]
[Thu Jul 30 14:11:06.968104 2026] [core:notice] [pid 1004636:tid 1004774] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:07.474266 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.251.58.190:16847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/error_log.php"] [unique_id "amuhy-_uyupB2NyFtxKpFgAAABQ"]
[Thu Jul 30 14:11:07.474414 2026] [security2:error] [pid 1004636:tid 1004843] [client 20.251.58.190:16847] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/error_log.php"] [unique_id "amuhy-_uyupB2NyFtxKpFgAAABQ"]
[Thu Jul 30 14:11:07.726708 2026] [security2:error] [pid 1004636:tid 1004899] [client 189.6.88.213:55132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhy-_uyupB2NyFtxKpGgAAAEk"]
[Thu Jul 30 14:11:07.726813 2026] [security2:error] [pid 1004636:tid 1004899] [client 189.6.88.213:55132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhy-_uyupB2NyFtxKpGgAAAEk"]
[Thu Jul 30 14:11:08.095274 2026] [security2:error] [pid 1004636:tid 1004891] [client 20.251.58.190:20377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/xenon1337.php"] [unique_id "amuhzO_uyupB2NyFtxKpIQAAAEI"]
[Thu Jul 30 14:11:08.095382 2026] [security2:error] [pid 1004636:tid 1004891] [client 20.251.58.190:20377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/xenon1337.php"] [unique_id "amuhzO_uyupB2NyFtxKpIQAAAEI"]
[Thu Jul 30 14:11:08.161239 2026] [security2:error] [pid 1004636:tid 1004893] [client 181.116.200.68:5457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhzO_uyupB2NyFtxKpIgAAAEQ"]
[Thu Jul 30 14:11:08.161366 2026] [security2:error] [pid 1004636:tid 1004893] [client 181.116.200.68:5457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuhzO_uyupB2NyFtxKpIgAAAEQ"]
[Thu Jul 30 14:11:08.422020 2026] [core:notice] [pid 1004636:tid 1004791] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:08.785996 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.251.58.190:43917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.58.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kendarikomputer.com"] [uri "/test11.php"] [unique_id "amuhzO_uyupB2NyFtxKpLAAAACM"]
[Thu Jul 30 14:11:08.786113 2026] [security2:error] [pid 1004636:tid 1004859] [client 20.251.58.190:43917] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kendarikomputer.com"] [uri "/test11.php"] [unique_id "amuhzO_uyupB2NyFtxKpLAAAACM"]
[Thu Jul 30 14:11:10.542927 2026] [security2:error] [pid 1004636:tid 1004884] [client 103.190.40.154:20160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhzu_uyupB2NyFtxKpVQAAADs"]
[Thu Jul 30 14:11:10.543104 2026] [security2:error] [pid 1004636:tid 1004884] [client 103.190.40.154:20160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuhzu_uyupB2NyFtxKpVQAAADs"]
[Thu Jul 30 14:11:11.220687 2026] [security2:error] [pid 1004636:tid 1004900] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhz-_uyupB2NyFtxKpYwAAAEo"]
[Thu Jul 30 14:11:11.220711 2026] [security2:error] [pid 1004636:tid 1004900] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuhz-_uyupB2NyFtxKpYwAAAEo"]
[Thu Jul 30 14:11:11.374142 2026] [security2:error] [pid 1004636:tid 1004871] [client 82.102.18.180:34710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "amuhz-_uyupB2NyFtxKpYQAAAC8"]
[Thu Jul 30 14:11:11.498799 2026] [security2:error] [pid 1004636:tid 1004748] [remote 47.128.27.93:46248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-dunk-high-crimson-tint/"] [unique_id "amuhz-_uyupB2NyFtxKpagAAejo"]
[Thu Jul 30 14:11:13.337747 2026] [security2:error] [pid 1004636:tid 1004823] [client 119.73.97.132:31030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuh0e_uyupB2NyFtxKpjgAAAXs"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 14:11:13.566064 2026] [core:notice] [pid 1004636:tid 1004913] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:13.580325 2026] [security2:error] [pid 1004636:tid 1004840] [client 172.237.109.114:45221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuh0O_uyupB2NyFtxKpigAAABE"]
[Thu Jul 30 14:11:15.104039 2026] [security2:error] [pid 1004636:tid 1004925] [client 20.40.58.237:63493] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuh0-_uyupB2NyFtxKpuQAAAGI"]
[Thu Jul 30 14:11:15.762474 2026] [core:notice] [pid 1004636:tid 1004876] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:17.077395 2026] [security2:error] [pid 1004636:tid 1004858] [client 172.237.109.114:12082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/common/config.php.new"] [unique_id "amuh1e_uyupB2NyFtxKp4gAAACI"]
[Thu Jul 30 14:11:17.078410 2026] [security2:error] [pid 1004636:tid 1004946] [client 172.237.109.114:3208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "alseermarine.com"] [uri "/wp-config.backup"] [unique_id "amuh1e_uyupB2NyFtxKp4QAAAHY"]
[Thu Jul 30 14:11:17.078879 2026] [security2:error] [pid 1004636:tid 1004941] [client 172.237.109.114:34900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/config.php.tar.gz"] [unique_id "amuh1e_uyupB2NyFtxKp4wAAAHE"]
[Thu Jul 30 14:11:17.093009 2026] [security2:error] [pid 1004636:tid 1004893] [client 172.237.109.114:33619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.original"] [unique_id "amuh1e_uyupB2NyFtxKp5AAAAEQ"]
[Thu Jul 30 14:11:17.093499 2026] [security2:error] [pid 1004636:tid 1004906] [client 172.237.109.114:42781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.orig"] [unique_id "amuh1e_uyupB2NyFtxKp5gAAAFA"]
[Thu Jul 30 14:11:17.093882 2026] [security2:error] [pid 1004636:tid 1004839] [client 172.237.109.114:44405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-config.php_orig"] [unique_id "amuh1e_uyupB2NyFtxKp5QAAABA"]
[Thu Jul 30 14:11:17.123243 2026] [security2:error] [pid 1004636:tid 1004879] [client 172.237.109.114:4349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alseermarine.com"] [uri "/wp-config.php.bk"] [unique_id "amuh1e_uyupB2NyFtxKp6AAAADc"]
[Thu Jul 30 14:11:17.148149 2026] [security2:error] [pid 1004636:tid 1004827] [client 172.237.109.114:28937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/config.php.zip"] [unique_id "amuh1e_uyupB2NyFtxKp6gAAAAU"]
[Thu Jul 30 14:11:17.150489 2026] [security2:error] [pid 1004636:tid 1004923] [client 172.237.109.114:55283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/config.php.new"] [unique_id "amuh1e_uyupB2NyFtxKp6wAAAGA"]
[Thu Jul 30 14:11:17.370809 2026] [core:notice] [pid 1004636:tid 1004955] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:17.572927 2026] [security2:error] [pid 1004636:tid 1004949] [client 172.237.109.114:2913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuh1e_uyupB2NyFtxKp5wAAAHk"]
[Thu Jul 30 14:11:17.694806 2026] [security2:error] [pid 1004636:tid 1004938] [client 172.237.109.114:37387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuh1e_uyupB2NyFtxKp7AAAAG4"]
[Thu Jul 30 14:11:17.700777 2026] [security2:error] [pid 1004636:tid 1004881] [client 172.237.109.114:56193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuh1e_uyupB2NyFtxKp6QAAADk"]
[Thu Jul 30 14:11:18.440726 2026] [security2:error] [pid 1004636:tid 1004861] [client 172.237.109.114:55074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuh1e_uyupB2NyFtxKqBQAAACU"]
[Thu Jul 30 14:11:18.561031 2026] [security2:error] [pid 1004636:tid 1004933] [client 189.6.88.213:55683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh1u_uyupB2NyFtxKqFAAAAGo"]
[Thu Jul 30 14:11:18.561141 2026] [security2:error] [pid 1004636:tid 1004933] [client 189.6.88.213:55683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh1u_uyupB2NyFtxKqFAAAAGo"]
[Thu Jul 30 14:11:18.737567 2026] [security2:error] [pid 1004636:tid 1004856] [client 181.116.200.68:41532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuh1u_uyupB2NyFtxKqGwAAACA"]
[Thu Jul 30 14:11:18.737689 2026] [security2:error] [pid 1004636:tid 1004856] [client 181.116.200.68:41532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuh1u_uyupB2NyFtxKqGwAAACA"]
[Thu Jul 30 14:11:21.267462 2026] [security2:error] [pid 1004636:tid 1004874] [client 13.211.141.215:51007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.141.211.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lilyinspires.com"] [uri "/wp-login.php"] [unique_id "amuh2e_uyupB2NyFtxKqSgAAADI"]
[Thu Jul 30 14:11:21.337132 2026] [security2:error] [pid 1004636:tid 1004872] [client 13.211.141.215:51004] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "lilyinspires.com"] [uri "/wp-login.php"] [unique_id "amuh2O_uyupB2NyFtxKqSAAAADA"]
[Thu Jul 30 14:11:21.469830 2026] [security2:error] [pid 1004636:tid 1004846] [client 13.211.141.215:51005] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.lilyinspires.com"] [uri "/___proxy_subdomain_cpcontacts/wp-login.php"] [unique_id "amuh2O_uyupB2NyFtxKqSQAAABc"]
[Thu Jul 30 14:11:21.521958 2026] [security2:error] [pid 1004636:tid 1004823] [client 13.211.141.215:51011] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.lilyinspires.com"] [uri "/wp-login.php"] [unique_id "amuh2e_uyupB2NyFtxKqWAAAAAE"]
[Thu Jul 30 14:11:21.776687 2026] [security2:error] [pid 1004636:tid 1004855] [client 13.211.141.215:51016] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.lilyinspires.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "amuh2e_uyupB2NyFtxKqYwAAAB8"]
[Thu Jul 30 14:11:21.851839 2026] [security2:error] [pid 1004636:tid 1004919] [client 144.172.114.51:35780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecre.ae"] [uri "/admin/phpinfo.php"] [unique_id "amuh2e_uyupB2NyFtxKqZAAAAF0"]
[Thu Jul 30 14:11:21.890258 2026] [security2:error] [pid 1004636:tid 1004835] [client 13.211.141.215:51018] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.lilyinspires.com"] [uri "/___proxy_subdomain_cpcalendars/wp-login.php"] [unique_id "amuh2e_uyupB2NyFtxKqZQAAAA0"]
[Thu Jul 30 14:11:22.299568 2026] [security2:error] [pid 1004636:tid 1004879] [client 103.190.40.154:24415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh2u_uyupB2NyFtxKqbwAAADc"]
[Thu Jul 30 14:11:22.299718 2026] [security2:error] [pid 1004636:tid 1004879] [client 103.190.40.154:24415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh2u_uyupB2NyFtxKqbwAAADc"]
[Thu Jul 30 14:11:24.137405 2026] [proxy:error] [pid 1004636:tid 1004887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:24.137493 2026] [proxy_http:error] [pid 1004636:tid 1004887] [client 74.7.228.30:36454] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:24.138077 2026] [proxy:error] [pid 1004636:tid 1004887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:24.138122 2026] [proxy_http:error] [pid 1004636:tid 1004887] [client 74.7.228.30:36454] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:24.138248 2026] [security2:error] [pid 1004636:tid 1004887] [client 74.7.228.30:36454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.asd.fyv.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuh3O_uyupB2NyFtxKqjAAAAD4"]
[Thu Jul 30 14:11:24.745482 2026] [core:notice] [pid 1004636:tid 1004719] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:26.753822 2026] [core:notice] [pid 1004636:tid 1004785] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:26.828320 2026] [security2:error] [pid 1004636:tid 1004805] [remote 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuh3u_uyupB2NyFtxKqwAAABXE"]
[Thu Jul 30 14:11:29.085790 2026] [security2:error] [pid 1004636:tid 1004929] [client 185.200.116.211:57242] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh4O_uyupB2NyFtxKq-AAAAGY"]
[Thu Jul 30 14:11:29.085900 2026] [security2:error] [pid 1004636:tid 1004929] [client 185.200.116.211:57242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh4O_uyupB2NyFtxKq-AAAAGY"]
[Thu Jul 30 14:11:29.265147 2026] [security2:error] [pid 1004636:tid 1004871] [client 189.6.88.213:56221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh4e_uyupB2NyFtxKrAgAAAC8"]
[Thu Jul 30 14:11:29.265260 2026] [security2:error] [pid 1004636:tid 1004871] [client 189.6.88.213:56221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh4e_uyupB2NyFtxKrAgAAAC8"]
[Thu Jul 30 14:11:29.325573 2026] [security2:error] [pid 1004636:tid 1004831] [client 181.116.200.68:37298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuh4e_uyupB2NyFtxKrAwAAAAk"]
[Thu Jul 30 14:11:29.325723 2026] [security2:error] [pid 1004636:tid 1004831] [client 181.116.200.68:37298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuh4e_uyupB2NyFtxKrAwAAAAk"]
[Thu Jul 30 14:11:29.412043 2026] [fcgid:warn] [pid 1004636:tid 1004945] (70014)End of file found: [client 199.45.154.146:37952] mod_fcgid: can't get data from http client
[Thu Jul 30 14:11:30.424732 2026] [security2:error] [pid 1004636:tid 1004914] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-26b933cb.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amuh4e_uyupB2NyFtxKrBgAAAFg"]
[Thu Jul 30 14:11:30.425545 2026] [security2:error] [pid 1004636:tid 1004886] [client 74.7.244.52:52884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-26b933cb.ear.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuh4e_uyupB2NyFtxKrBAAAPXs"]
[Thu Jul 30 14:11:32.243564 2026] [security2:error] [pid 1004636:tid 1004945] [client 103.190.40.154:21153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh5O_uyupB2NyFtxKrSwAAAHU"]
[Thu Jul 30 14:11:32.243713 2026] [security2:error] [pid 1004636:tid 1004945] [client 103.190.40.154:21153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh5O_uyupB2NyFtxKrSwAAAHU"]
[Thu Jul 30 14:11:34.771290 2026] [security2:error] [pid 1004636:tid 1004866] [client 185.200.116.211:57246] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuh5u_uyupB2NyFtxKrlAAAACo"]
[Thu Jul 30 14:11:34.771432 2026] [security2:error] [pid 1004636:tid 1004866] [client 185.200.116.211:57246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuh5u_uyupB2NyFtxKrlAAAACo"]
[Thu Jul 30 14:11:36.676868 2026] [security2:error] [pid 1004636:tid 1004929] [client 144.172.114.51:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecre.ae"] [uri "/private/config.php"] [unique_id "amuh6O_uyupB2NyFtxKrugAAAGY"]
[Thu Jul 30 14:11:38.271856 2026] [core:notice] [pid 1004636:tid 1004783] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:38.951897 2026] [core:notice] [pid 1004636:tid 1004897] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:39.907380 2026] [security2:error] [pid 1004636:tid 1004844] [client 181.116.200.68:8686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuh6-_uyupB2NyFtxKsBgAAABU"]
[Thu Jul 30 14:11:39.907487 2026] [security2:error] [pid 1004636:tid 1004844] [client 181.116.200.68:8686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuh6-_uyupB2NyFtxKsBgAAABU"]
[Thu Jul 30 14:11:39.966941 2026] [security2:error] [pid 1004636:tid 1004832] [client 189.6.88.213:56774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh6-_uyupB2NyFtxKsBwAAAAo"]
[Thu Jul 30 14:11:39.967075 2026] [security2:error] [pid 1004636:tid 1004832] [client 189.6.88.213:56774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh6-_uyupB2NyFtxKsBwAAAAo"]
[Thu Jul 30 14:11:40.528165 2026] [security2:error] [pid 1004636:tid 1004891] [client 118.26.38.251:60714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wce.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuh7O_uyupB2NyFtxKsEgAAAEI"]
[Thu Jul 30 14:11:41.268254 2026] [core:notice] [pid 1004636:tid 1004807] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:41.527481 2026] [core:notice] [pid 1004636:tid 1004777] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:41.570526 2026] [security2:error] [pid 1004636:tid 1004846] [client 172.237.109.114:37722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuh7O_uyupB2NyFtxKsHAAAABc"]
[Thu Jul 30 14:11:42.994043 2026] [security2:error] [pid 1004636:tid 1004865] [client 103.190.40.154:11874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh7u_uyupB2NyFtxKsaQAAACk"]
[Thu Jul 30 14:11:42.994165 2026] [security2:error] [pid 1004636:tid 1004865] [client 103.190.40.154:11874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh7u_uyupB2NyFtxKsaQAAACk"]
[Thu Jul 30 14:11:44.093066 2026] [security2:error] [pid 1004636:tid 1004877] [client 85.208.96.209:15934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/30/petrobras-reduz-preco-do-diesel-em-21-e-da-gasolina-em-19/"] [unique_id "amuh8O_uyupB2NyFtxKsfwAAADU"]
[Thu Jul 30 14:11:44.093207 2026] [security2:error] [pid 1004636:tid 1004877] [client 85.208.96.209:15934] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/30/petrobras-reduz-preco-do-diesel-em-21-e-da-gasolina-em-19/"] [unique_id "amuh8O_uyupB2NyFtxKsfwAAADU"]
[Thu Jul 30 14:11:44.229003 2026] [security2:error] [pid 1004636:tid 1004778] [remote 57.141.0.50:29226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/404010317/feed/rss2/"] [unique_id "amuh8O_uyupB2NyFtxKshQAASVc"]
[Thu Jul 30 14:11:44.991861 2026] [security2:error] [pid 1004636:tid 1004887] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuh8O_uyupB2NyFtxKshwAAPmw"]
[Thu Jul 30 14:11:45.251073 2026] [security2:error] [pid 1004636:tid 1004930] [client 74.7.241.148:51274] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.erp.ajakholding.net"] [uri "/cgi-sys/404.html"] [unique_id "amuh8e_uyupB2NyFtxKsmwAAZxk"]
[Thu Jul 30 14:11:45.308022 2026] [security2:error] [pid 1004636:tid 1004705] [remote 160.22.160.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.160.22.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medaxco.com"] [uri "/wp-login.php"] [unique_id "amuh8e_uyupB2NyFtxKsnwAAURE"]
[Thu Jul 30 14:11:45.707215 2026] [core:error] [pid 1004636:tid 1004909] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://vanguardlegalassociates.team/
[Thu Jul 30 14:11:45.707237 2026] [core:error] [pid 1004636:tid 1004909] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://vanguardlegalassociates.team/
[Thu Jul 30 14:11:46.487198 2026] [security2:error] [pid 1004636:tid 1004860] [client 172.237.109.114:18305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuh8u_uyupB2NyFtxKssgAAACQ"]
[Thu Jul 30 14:11:50.560249 2026] [security2:error] [pid 1004636:tid 1004824] [client 181.116.200.68:60095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuh9u_uyupB2NyFtxKtEQAAAAI"]
[Thu Jul 30 14:11:50.560362 2026] [security2:error] [pid 1004636:tid 1004824] [client 181.116.200.68:60095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuh9u_uyupB2NyFtxKtEQAAAAI"]
[Thu Jul 30 14:11:50.705406 2026] [security2:error] [pid 1004636:tid 1004879] [client 189.6.88.213:57313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh9u_uyupB2NyFtxKtEgAAADc"]
[Thu Jul 30 14:11:50.705533 2026] [security2:error] [pid 1004636:tid 1004879] [client 189.6.88.213:57313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh9u_uyupB2NyFtxKtEgAAADc"]
[Thu Jul 30 14:11:51.105062 2026] [proxy:error] [pid 1004636:tid 1004920] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:51.105127 2026] [proxy_http:error] [pid 1004636:tid 1004920] [client 104.218.165.188:33804] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:51.105694 2026] [proxy:error] [pid 1004636:tid 1004920] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:51.105735 2026] [proxy_http:error] [pid 1004636:tid 1004920] [client 104.218.165.188:33804] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:51.661479 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.203.135.57:26296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuh9-_uyupB2NyFtxKtKQAAABk"]
[Thu Jul 30 14:11:51.661605 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.203.135.57:26296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuh9-_uyupB2NyFtxKtKQAAABk"]
[Thu Jul 30 14:11:51.867110 2026] [security2:error] [pid 1004636:tid 1004945] [client 135.119.63.61:64067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/on-settingssl.php"] [unique_id "amuh9-_uyupB2NyFtxKtLgAAAHU"]
[Thu Jul 30 14:11:52.170334 2026] [core:notice] [pid 1004636:tid 1004796] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:52.457023 2026] [core:notice] [pid 1004636:tid 1004757] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:52.754392 2026] [security2:error] [pid 1004636:tid 1004919] [client 185.200.116.211:41260] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuh-O_uyupB2NyFtxKtQwAAAF0"]
[Thu Jul 30 14:11:52.754493 2026] [security2:error] [pid 1004636:tid 1004919] [client 185.200.116.211:41260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuh-O_uyupB2NyFtxKtQwAAAF0"]
[Thu Jul 30 14:11:52.828786 2026] [core:notice] [pid 1004636:tid 1004730] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:52.892515 2026] [security2:error] [pid 1004636:tid 1004924] [client 135.119.63.61:18929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/opss.php"] [unique_id "amuh-O_uyupB2NyFtxKtSQAAAGE"]
[Thu Jul 30 14:11:53.255468 2026] [core:notice] [pid 1004636:tid 1004807] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:53.313255 2026] [core:notice] [pid 1004636:tid 1004791] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:11:53.807587 2026] [security2:error] [pid 1004636:tid 1004859] [client 103.190.40.154:20894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh-e_uyupB2NyFtxKtZAAAACM"]
[Thu Jul 30 14:11:53.807721 2026] [security2:error] [pid 1004636:tid 1004859] [client 103.190.40.154:20894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuh-e_uyupB2NyFtxKtZAAAACM"]
[Thu Jul 30 14:11:53.861104 2026] [security2:error] [pid 1004636:tid 1004865] [client 135.119.63.61:18882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/optimizer.php"] [unique_id "amuh-e_uyupB2NyFtxKtZQAAACk"]
[Thu Jul 30 14:11:53.974148 2026] [proxy:error] [pid 1004636:tid 1004930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:53.974222 2026] [proxy_http:error] [pid 1004636:tid 1004930] [client 104.218.165.188:35450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:53.974922 2026] [proxy:error] [pid 1004636:tid 1004930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:11:53.974971 2026] [proxy_http:error] [pid 1004636:tid 1004930] [client 104.218.165.188:35450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:11:54.808539 2026] [security2:error] [pid 1004636:tid 1004850] [client 135.119.63.61:19074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/option.php"] [unique_id "amuh-u_uyupB2NyFtxKtfQAAABs"]
[Thu Jul 30 14:11:55.364448 2026] [security2:error] [pid 1004636:tid 1004948] [client 144.172.114.51:37914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuh--_uyupB2NyFtxKtjAAAAHg"]
[Thu Jul 30 14:11:55.446742 2026] [security2:error] [pid 1004636:tid 1004926] [client 172.237.109.114:20225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuh-u_uyupB2NyFtxKtgwAAAGM"]
[Thu Jul 30 14:11:55.635345 2026] [security2:error] [pid 1004636:tid 1004929] [client 135.119.63.61:18912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/options-general.php"] [unique_id "amuh--_uyupB2NyFtxKtmQAAAGY"]
[Thu Jul 30 14:11:56.533195 2026] [security2:error] [pid 1004636:tid 1004885] [client 135.119.63.61:19229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/options-reading.php"] [unique_id "amuh_O_uyupB2NyFtxKtpgAAADw"]
[Thu Jul 30 14:11:57.678560 2026] [security2:error] [pid 1004636:tid 1004873] [client 135.119.63.61:19231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/options-writing.php"] [unique_id "amuh_e_uyupB2NyFtxKtwQAAADE"]
[Thu Jul 30 14:11:58.679377 2026] [security2:error] [pid 1004636:tid 1004868] [client 135.119.63.61:19203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/options.php"] [unique_id "amuh_u_uyupB2NyFtxKt1AAAACw"]
[Thu Jul 30 14:11:59.705596 2026] [security2:error] [pid 1004636:tid 1004901] [client 135.119.63.61:19208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/orange.php"] [unique_id "amuh_-_uyupB2NyFtxKt6AAAAEs"]
[Thu Jul 30 14:11:59.738129 2026] [security2:error] [pid 1004636:tid 1004849] [client 144.172.114.51:47736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuh_-_uyupB2NyFtxKt6QAAABo"]
[Thu Jul 30 14:12:00.174416 2026] [proxy:error] [pid 1004636:tid 1004858] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:12:00.174509 2026] [proxy_http:error] [pid 1004636:tid 1004858] [client 104.218.165.188:35466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:12:00.175087 2026] [proxy:error] [pid 1004636:tid 1004858] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:12:00.175133 2026] [proxy_http:error] [pid 1004636:tid 1004858] [client 104.218.165.188:35466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:12:00.347304 2026] [security2:error] [pid 1004636:tid 1004759] [remote 103.174.51.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.51.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "embassyinislamabadad.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amuiAO_uyupB2NyFtxKt9AAAbUU"]
[Thu Jul 30 14:12:00.347599 2026] [security2:error] [pid 1004636:tid 1004937] [client 103.174.51.100:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "embassyinislamabadad.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amuiAO_uyupB2NyFtxKt9AAAbUU"]
[Thu Jul 30 14:12:00.705592 2026] [security2:error] [pid 1004636:tid 1004847] [client 135.119.63.61:19259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/orm.php"] [unique_id "amuiAO_uyupB2NyFtxKuAwAAABg"]
[Thu Jul 30 14:12:01.280815 2026] [security2:error] [pid 1004636:tid 1004823] [client 181.116.200.68:14684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuiAe_uyupB2NyFtxKuFAAAAAE"]
[Thu Jul 30 14:12:01.281009 2026] [security2:error] [pid 1004636:tid 1004823] [client 181.116.200.68:14684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuiAe_uyupB2NyFtxKuFAAAAAE"]
[Thu Jul 30 14:12:01.462894 2026] [security2:error] [pid 1004636:tid 1004910] [client 144.172.114.51:47162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ecre.ae"] [uri "/administrator/.env"] [unique_id "amuiAe_uyupB2NyFtxKuHwAAAFQ"]
[Thu Jul 30 14:12:01.508440 2026] [security2:error] [pid 1004636:tid 1004872] [client 189.6.88.213:58098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiAe_uyupB2NyFtxKuIAAAADA"]
[Thu Jul 30 14:12:01.508553 2026] [security2:error] [pid 1004636:tid 1004872] [client 189.6.88.213:58098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiAe_uyupB2NyFtxKuIAAAADA"]
[Thu Jul 30 14:12:01.635170 2026] [security2:error] [pid 1004636:tid 1004864] [client 20.203.135.57:25622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuiAe_uyupB2NyFtxKuJgAAACg"]
[Thu Jul 30 14:12:01.635312 2026] [security2:error] [pid 1004636:tid 1004864] [client 20.203.135.57:25622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuiAe_uyupB2NyFtxKuJgAAACg"]
[Thu Jul 30 14:12:01.711377 2026] [security2:error] [pid 1004636:tid 1004884] [client 135.119.63.61:19241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ot.php"] [unique_id "amuiAe_uyupB2NyFtxKuKAAAADs"]
[Thu Jul 30 14:12:02.593870 2026] [security2:error] [pid 1004636:tid 1004939] [client 135.119.63.61:19209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ota.php"] [unique_id "amuiAu_uyupB2NyFtxKuOwAAAG8"]
[Thu Jul 30 14:12:02.926056 2026] [security2:error] [pid 1004636:tid 1004896] [client 118.26.38.251:45060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wce.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuiAu_uyupB2NyFtxKuPgAAAEY"]
[Thu Jul 30 14:12:03.389353 2026] [security2:error] [pid 1004636:tid 1004828] [client 144.172.114.51:47168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/cms/.env"] [unique_id "amuiA-_uyupB2NyFtxKuSAAAAAY"]
[Thu Jul 30 14:12:03.738872 2026] [security2:error] [pid 1004636:tid 1004906] [client 135.119.63.61:19084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/otuz1.php"] [unique_id "amuiA-_uyupB2NyFtxKuUgAAAFA"]
[Thu Jul 30 14:12:04.663901 2026] [security2:error] [pid 1004636:tid 1004862] [client 135.119.63.61:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/outscout.php"] [unique_id "amuiBO_uyupB2NyFtxKuYwAAACY"]
[Thu Jul 30 14:12:04.986760 2026] [security2:error] [pid 1004636:tid 1004897] [client 20.171.55.167:8291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuiBO_uyupB2NyFtxKucwAAAEc"]
[Thu Jul 30 14:12:05.106048 2026] [proxy:error] [pid 1004636:tid 1004865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:12:05.106113 2026] [proxy_http:error] [pid 1004636:tid 1004865] [client 104.218.165.188:42054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:12:05.106683 2026] [proxy:error] [pid 1004636:tid 1004865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:12:05.106727 2026] [proxy_http:error] [pid 1004636:tid 1004865] [client 104.218.165.188:42054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:12:05.700519 2026] [security2:error] [pid 1004636:tid 1004931] [client 20.171.55.167:8293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/404.php"] [unique_id "amuiBe_uyupB2NyFtxKujgAAAGg"]
[Thu Jul 30 14:12:06.044019 2026] [security2:error] [pid 1004636:tid 1004831] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuiBe_uyupB2NyFtxKuhQAAAAk"]
[Thu Jul 30 14:12:06.126050 2026] [security2:error] [pid 1004636:tid 1004888] [client 103.190.40.154:18759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiBu_uyupB2NyFtxKulAAAAD8"]
[Thu Jul 30 14:12:06.126175 2026] [security2:error] [pid 1004636:tid 1004888] [client 103.190.40.154:18759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiBu_uyupB2NyFtxKulAAAAD8"]
[Thu Jul 30 14:12:06.343410 2026] [security2:error] [pid 1004636:tid 1004874] [client 135.119.63.61:64378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ova.php"] [unique_id "amuiBu_uyupB2NyFtxKunAAAADI"]
[Thu Jul 30 14:12:06.482017 2026] [security2:error] [pid 1004636:tid 1004823] [client 20.171.55.167:8298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-configs.php"] [unique_id "amuiBu_uyupB2NyFtxKunQAAAAE"]
[Thu Jul 30 14:12:07.076409 2026] [security2:error] [pid 1004636:tid 1004885] [client 172.237.109.114:7705] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amuiB-_uyupB2NyFtxKuqQAAADw"]
[Thu Jul 30 14:12:07.214162 2026] [security2:error] [pid 1004636:tid 1004873] [client 20.171.55.167:8295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/simple.php"] [unique_id "amuiB-_uyupB2NyFtxKurQAAADE"]
[Thu Jul 30 14:12:07.324477 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.203.135.57:25610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/xstelth.php"] [unique_id "amuiB-_uyupB2NyFtxKusgAAAB0"]
[Thu Jul 30 14:12:07.324570 2026] [security2:error] [pid 1004636:tid 1004852] [client 20.203.135.57:25610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/xstelth.php"] [unique_id "amuiB-_uyupB2NyFtxKusgAAAB0"]
[Thu Jul 30 14:12:07.356266 2026] [security2:error] [pid 1004636:tid 1004857] [client 135.119.63.61:19260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/owl.php"] [unique_id "amuiB-_uyupB2NyFtxKuswAAACE"]
[Thu Jul 30 14:12:07.976201 2026] [security2:error] [pid 1004636:tid 1004954] [client 20.171.55.167:8286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/themes.php"] [unique_id "amuiB-_uyupB2NyFtxKuwgAAAH4"]
[Thu Jul 30 14:12:08.116890 2026] [security2:error] [pid 1004636:tid 1004927] [client 118.26.38.251:45066] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.wce.gzj.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amuiCO_uyupB2NyFtxKuwwAAAGQ"]
[Thu Jul 30 14:12:08.369017 2026] [security2:error] [pid 1004636:tid 1004844] [client 135.119.63.61:19219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/p.php"] [unique_id "amuiCO_uyupB2NyFtxKuygAAABU"]
[Thu Jul 30 14:12:08.626157 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.203.135.57:5965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/584062352875874akp.php"] [unique_id "amuiCO_uyupB2NyFtxKuzgAAAC4"]
[Thu Jul 30 14:12:08.626273 2026] [security2:error] [pid 1004636:tid 1004870] [client 20.203.135.57:5965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/584062352875874akp.php"] [unique_id "amuiCO_uyupB2NyFtxKuzgAAAC4"]
[Thu Jul 30 14:12:08.692741 2026] [security2:error] [pid 1004636:tid 1004904] [client 20.171.55.167:8260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ini.php"] [unique_id "amuiCO_uyupB2NyFtxKuzwAAAE4"]
[Thu Jul 30 14:12:09.184713 2026] [security2:error] [pid 1004636:tid 1004877] [client 135.119.63.61:64358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pDPTEa.php"] [unique_id "amuiCe_uyupB2NyFtxKu2wAAADU"]
[Thu Jul 30 14:12:09.406388 2026] [security2:error] [pid 1004636:tid 1004849] [client 20.171.55.167:8269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/autoload_classmap.php"] [unique_id "amuiCe_uyupB2NyFtxKu4wAAABo"]
[Thu Jul 30 14:12:09.442752 2026] [security2:error] [pid 1004636:tid 1004888] [client 185.191.171.16:51376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/04/na-ucrania-maior-usina-nuclear-da-europa-e-incendiada/"] [unique_id "amuiCe_uyupB2NyFtxKu5AAAAD8"]
[Thu Jul 30 14:12:09.442868 2026] [security2:error] [pid 1004636:tid 1004888] [client 185.191.171.16:51376] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/04/na-ucrania-maior-usina-nuclear-da-europa-e-incendiada/"] [unique_id "amuiCe_uyupB2NyFtxKu5AAAAD8"]
[Thu Jul 30 14:12:10.044145 2026] [security2:error] [pid 1004636:tid 1004884] [client 135.119.63.61:19233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pHpINJ.php"] [unique_id "amuiCu_uyupB2NyFtxKu-QAAADs"]
[Thu Jul 30 14:12:10.115691 2026] [security2:error] [pid 1004636:tid 1004941] [client 20.171.55.167:8300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/as.php"] [unique_id "amuiCu_uyupB2NyFtxKu-gAAAHE"]
[Thu Jul 30 14:12:10.363308 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.203.135.57:53806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/newfile.php"] [unique_id "amuiCu_uyupB2NyFtxKu_AAAAFM"]
[Thu Jul 30 14:12:10.363424 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.203.135.57:53806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/newfile.php"] [unique_id "amuiCu_uyupB2NyFtxKu_AAAAFM"]
[Thu Jul 30 14:12:10.786626 2026] [security2:error] [pid 1004636:tid 1004949] [client 3.77.67.4:44406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuiCu_uyupB2NyFtxKvBwAAAHk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:12:10.856560 2026] [security2:error] [pid 1004636:tid 1004902] [client 20.171.55.167:8317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/admin/upload/css.php"] [unique_id "amuiCu_uyupB2NyFtxKvCAAAAEw"]
[Thu Jul 30 14:12:10.899296 2026] [security2:error] [pid 1004636:tid 1004953] [client 91.140.29.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuiCu_uyupB2NyFtxKu-wAAfQQ"], referer: https://flixon.net/?post_type=any&s=Spiderman+&search=&search_filter=post_types&_wpnonce=ab8659ecbd
[Thu Jul 30 14:12:10.939857 2026] [security2:error] [pid 1004636:tid 1004831] [client 135.119.63.61:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/packed.php"] [unique_id "amuiCu_uyupB2NyFtxKvDwAAAAk"]
[Thu Jul 30 14:12:11.342112 2026] [core:notice] [pid 1004636:tid 1004896] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:11.378826 2026] [core:notice] [pid 1004636:tid 1004849] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:11.383868 2026] [security2:error] [pid 1004636:tid 1004849] [client 3.77.67.4:44408] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuiC-_uyupB2NyFtxKvFQAAABo"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:12:11.551885 2026] [security2:error] [pid 1004636:tid 1004893] [client 20.203.135.57:49350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/tBEZGQz.php"] [unique_id "amuiC-_uyupB2NyFtxKvIAAAAEQ"]
[Thu Jul 30 14:12:11.552022 2026] [security2:error] [pid 1004636:tid 1004893] [client 20.203.135.57:49350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/tBEZGQz.php"] [unique_id "amuiC-_uyupB2NyFtxKvIAAAAEQ"]
[Thu Jul 30 14:12:11.572727 2026] [security2:error] [pid 1004636:tid 1004848] [client 20.171.55.167:8310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/pki-validation/afnew.php"] [unique_id "amuiC-_uyupB2NyFtxKvJAAAABk"]
[Thu Jul 30 14:12:11.840779 2026] [security2:error] [pid 1004636:tid 1004862] [client 181.116.200.68:37799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.200.116.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuiC-_uyupB2NyFtxKvJQAAACY"]
[Thu Jul 30 14:12:11.840897 2026] [security2:error] [pid 1004636:tid 1004862] [client 181.116.200.68:37799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuiC-_uyupB2NyFtxKvJQAAACY"]
[Thu Jul 30 14:12:11.882501 2026] [security2:error] [pid 1004636:tid 1004947] [client 3.77.67.4:44424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuiC-_uyupB2NyFtxKvJgAAAHc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:12:11.931260 2026] [security2:error] [pid 1004636:tid 1004916] [client 74.7.244.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amuiC-_uyupB2NyFtxKvHgAAWlA"]
[Thu Jul 30 14:12:11.931294 2026] [security2:error] [pid 1004636:tid 1004916] [client 74.7.244.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amuiC-_uyupB2NyFtxKvHgAAWlA"]
[Thu Jul 30 14:12:12.112484 2026] [security2:error] [pid 1004636:tid 1004918] [client 135.119.63.61:64381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/page.php"] [unique_id "amuiDO_uyupB2NyFtxKvLwAAAFw"]
[Thu Jul 30 14:12:12.257316 2026] [security2:error] [pid 1004636:tid 1004948] [client 189.6.88.213:58765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiDO_uyupB2NyFtxKvMwAAAHg"]
[Thu Jul 30 14:12:12.257420 2026] [security2:error] [pid 1004636:tid 1004948] [client 189.6.88.213:58765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiDO_uyupB2NyFtxKvMwAAAHg"]
[Thu Jul 30 14:12:12.403214 2026] [security2:error] [pid 1004636:tid 1004707] [remote 74.7.243.224:53286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amuiDO_uyupB2NyFtxKvNQAAGBM"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:12:12.418779 2026] [security2:error] [pid 1004636:tid 1004934] [client 20.203.135.57:18732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.xexrecords.online"] [uri "/___proxy_subdomain_webdisk/phpinfo"] [unique_id "amuiDO_uyupB2NyFtxKvNgAAAGs"]
[Thu Jul 30 14:12:12.504571 2026] [security2:error] [pid 1004636:tid 1004954] [client 144.172.114.51:47180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/dashboard/.env"] [unique_id "amuiDO_uyupB2NyFtxKvPAAAAH4"]
[Thu Jul 30 14:12:12.568744 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.203.135.57:18732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/drykl.php"] [unique_id "amuiDO_uyupB2NyFtxKvPgAAAAY"]
[Thu Jul 30 14:12:12.568846 2026] [security2:error] [pid 1004636:tid 1004828] [client 20.203.135.57:18732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/drykl.php"] [unique_id "amuiDO_uyupB2NyFtxKvPgAAAAY"]
[Thu Jul 30 14:12:12.956360 2026] [security2:error] [pid 1004636:tid 1004819] [remote 57.141.0.10:37372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuiDO_uyupB2NyFtxKvRAAATX4"]
[Thu Jul 30 14:12:12.987281 2026] [security2:error] [pid 1004636:tid 1004905] [client 20.171.55.167:8308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/lufix.php"] [unique_id "amuiDO_uyupB2NyFtxKvSAAAAE8"]
[Thu Jul 30 14:12:13.199869 2026] [security2:error] [pid 1004636:tid 1004845] [client 135.119.63.61:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/page/2/wp-login.php"] [unique_id "amuiDO_uyupB2NyFtxKvQwAAABY"]
[Thu Jul 30 14:12:13.709669 2026] [security2:error] [pid 1004636:tid 1004946] [client 172.237.109.114:4754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuiDe_uyupB2NyFtxKvTgAAAHY"]
[Thu Jul 30 14:12:13.730424 2026] [security2:error] [pid 1004636:tid 1004872] [client 20.171.55.167:8323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/media.php"] [unique_id "amuiDe_uyupB2NyFtxKvXwAAADA"]
[Thu Jul 30 14:12:13.921287 2026] [security2:error] [pid 1004636:tid 1004895] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuiDe_uyupB2NyFtxKvUwAAAEU"]
[Thu Jul 30 14:12:14.144090 2026] [security2:error] [pid 1004636:tid 1004836] [client 135.119.63.61:64493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pageb.php"] [unique_id "amuiDu_uyupB2NyFtxKvawAAAA4"]
[Thu Jul 30 14:12:14.163563 2026] [security2:error] [pid 1004636:tid 1004918] [client 20.203.135.57:6080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.xexrecords.online"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuiDu_uyupB2NyFtxKvbQAAAFw"]
[Thu Jul 30 14:12:14.458363 2026] [security2:error] [pid 1004636:tid 1004855] [client 20.171.55.167:8331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/simple.php"] [unique_id "amuiDu_uyupB2NyFtxKvcAAAAB8"]
[Thu Jul 30 14:12:14.965586 2026] [security2:error] [pid 1004636:tid 1004826] [client 20.203.135.57:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/ls.php"] [unique_id "amuiDu_uyupB2NyFtxKvfAAAAAQ"]
[Thu Jul 30 14:12:14.965702 2026] [security2:error] [pid 1004636:tid 1004826] [client 20.203.135.57:6080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/ls.php"] [unique_id "amuiDu_uyupB2NyFtxKvfAAAAAQ"]
[Thu Jul 30 14:12:15.044132 2026] [security2:error] [pid 1004636:tid 1004923] [client 135.119.63.61:64506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pages.php"] [unique_id "amuiD-_uyupB2NyFtxKvhgAAAGA"]
[Thu Jul 30 14:12:15.194123 2026] [security2:error] [pid 1004636:tid 1004909] [client 20.171.55.167:8320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/contact.php"] [unique_id "amuiD-_uyupB2NyFtxKvjAAAAFM"]
[Thu Jul 30 14:12:15.205917 2026] [security2:error] [pid 1004636:tid 1004869] [client 40.77.167.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuiDu_uyupB2NyFtxKvfwAAAC0"]
[Thu Jul 30 14:12:15.763320 2026] [security2:error] [pid 1004636:tid 1004891] [client 20.203.135.57:60030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/dx.php"] [unique_id "amuiD-_uyupB2NyFtxKvmQAAAEI"]
[Thu Jul 30 14:12:15.763408 2026] [security2:error] [pid 1004636:tid 1004891] [client 20.203.135.57:60030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/dx.php"] [unique_id "amuiD-_uyupB2NyFtxKvmQAAAEI"]
[Thu Jul 30 14:12:15.919380 2026] [security2:error] [pid 1004636:tid 1004899] [client 20.171.55.167:8810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/byp.php"] [unique_id "amuiD-_uyupB2NyFtxKvmwAAAEk"]
[Thu Jul 30 14:12:16.321032 2026] [security2:error] [pid 1004636:tid 1004906] [client 135.119.63.61:64376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pagesadmin.php"] [unique_id "amuiEO_uyupB2NyFtxKvqQAAAFA"]
[Thu Jul 30 14:12:16.614542 2026] [security2:error] [pid 1004636:tid 1004854] [client 185.191.171.13:10724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2023/07/cara-memperbaiki-sinyal-internet"] [unique_id "amuiEO_uyupB2NyFtxKvrQAAAB4"]
[Thu Jul 30 14:12:16.614674 2026] [security2:error] [pid 1004636:tid 1004854] [client 185.191.171.13:10724] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2023/07/cara-memperbaiki-sinyal-internet"] [unique_id "amuiEO_uyupB2NyFtxKvrQAAAB4"]
[Thu Jul 30 14:12:16.626308 2026] [security2:error] [pid 1004636:tid 1004907] [client 20.171.55.167:8820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/upload.php"] [unique_id "amuiEO_uyupB2NyFtxKvrwAAAFE"]
[Thu Jul 30 14:12:16.946808 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.203.135.57:33574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/mac.php"] [unique_id "amuiEO_uyupB2NyFtxKvuwAAAE0"]
[Thu Jul 30 14:12:16.946949 2026] [security2:error] [pid 1004636:tid 1004903] [client 20.203.135.57:33574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/mac.php"] [unique_id "amuiEO_uyupB2NyFtxKvuwAAAE0"]
[Thu Jul 30 14:12:17.335491 2026] [security2:error] [pid 1004636:tid 1004923] [client 135.119.63.61:64373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pagesalfa.php"] [unique_id "amuiEe_uyupB2NyFtxKvxwAAAGA"]
[Thu Jul 30 14:12:17.383519 2026] [security2:error] [pid 1004636:tid 1004840] [client 20.171.55.167:8791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "amuiEe_uyupB2NyFtxKvyAAAABE"]
[Thu Jul 30 14:12:17.818884 2026] [core:notice] [pid 1004636:tid 1004895] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:17.882801 2026] [security2:error] [pid 1004636:tid 1004889] [client 103.190.40.154:8431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.40.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiEe_uyupB2NyFtxKv1AAAAEA"]
[Thu Jul 30 14:12:17.882914 2026] [security2:error] [pid 1004636:tid 1004889] [client 103.190.40.154:8431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiEe_uyupB2NyFtxKv1AAAAEA"]
[Thu Jul 30 14:12:18.092144 2026] [security2:error] [pid 1004636:tid 1004910] [client 20.171.55.167:8792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cong.php"] [unique_id "amuiEu_uyupB2NyFtxKv1QAAAFQ"]
[Thu Jul 30 14:12:18.180771 2026] [security2:error] [pid 1004636:tid 1004872] [client 135.119.63.61:19095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pagesbypass.php"] [unique_id "amuiEu_uyupB2NyFtxKv1gAAADA"]
[Thu Jul 30 14:12:18.676807 2026] [core:notice] [pid 1004636:tid 1004938] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:18.826191 2026] [security2:error] [pid 1004636:tid 1004881] [client 20.171.55.167:8803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/about/function.php"] [unique_id "amuiEu_uyupB2NyFtxKv5wAAADk"]
[Thu Jul 30 14:12:19.263994 2026] [security2:error] [pid 1004636:tid 1004828] [client 135.119.63.61:64352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pagesk.php"] [unique_id "amuiE-_uyupB2NyFtxKv7wAAAAY"]
[Thu Jul 30 14:12:19.566227 2026] [security2:error] [pid 1004636:tid 1004931] [client 20.171.55.167:8831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/filemanager/dialog.php"] [unique_id "amuiE-_uyupB2NyFtxKv9gAAAGg"]
[Thu Jul 30 14:12:20.093902 2026] [security2:error] [pid 1004636:tid 1004876] [client 135.119.63.61:19087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pageswp.php"] [unique_id "amuiFO_uyupB2NyFtxKwAQAAADQ"]
[Thu Jul 30 14:12:20.129068 2026] [security2:error] [pid 1004636:tid 1004833] [client 185.191.171.9:24536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/12/12/na-cultura-celio-alves-volta-a-apresentar-o-x-da-questao-e-entrevista-o-governador-joao-azevedo-neste-sabado/"] [unique_id "amuiFO_uyupB2NyFtxKwAgAAAAs"]
[Thu Jul 30 14:12:20.129196 2026] [security2:error] [pid 1004636:tid 1004833] [client 185.191.171.9:24536] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/12/12/na-cultura-celio-alves-volta-a-apresentar-o-x-da-questao-e-entrevista-o-governador-joao-azevedo-neste-sabado/"] [unique_id "amuiFO_uyupB2NyFtxKwAgAAAAs"]
[Thu Jul 30 14:12:20.305903 2026] [security2:error] [pid 1004636:tid 1004829] [client 20.171.55.167:8776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/bak.php"] [unique_id "amuiFO_uyupB2NyFtxKwBgAAAAc"]
[Thu Jul 30 14:12:20.809350 2026] [security2:error] [pid 1004636:tid 1004883] [client 20.203.135.57:41101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/485.php"] [unique_id "amuiFO_uyupB2NyFtxKwFwAAADo"]
[Thu Jul 30 14:12:20.809446 2026] [security2:error] [pid 1004636:tid 1004883] [client 20.203.135.57:41101] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/485.php"] [unique_id "amuiFO_uyupB2NyFtxKwFwAAADo"]
[Thu Jul 30 14:12:20.989511 2026] [security2:error] [pid 1004636:tid 1004944] [client 135.119.63.61:64511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/parx.php"] [unique_id "amuiFO_uyupB2NyFtxKwGwAAAHQ"]
[Thu Jul 30 14:12:21.016398 2026] [security2:error] [pid 1004636:tid 1004912] [client 20.171.55.167:8267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-info.php"] [unique_id "amuiFe_uyupB2NyFtxKwHwAAAFY"]
[Thu Jul 30 14:12:21.777964 2026] [security2:error] [pid 1004636:tid 1004879] [client 20.171.55.167:8256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/files/index.php"] [unique_id "amuiFe_uyupB2NyFtxKwKgAAADc"]
[Thu Jul 30 14:12:21.870454 2026] [security2:error] [pid 1004636:tid 1004841] [client 135.119.63.61:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/pass.php"] [unique_id "amuiFe_uyupB2NyFtxKwLgAAABI"]
[Thu Jul 30 14:12:22.500822 2026] [security2:error] [pid 1004636:tid 1004842] [client 20.171.55.167:8802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/css.php"] [unique_id "amuiFu_uyupB2NyFtxKwOgAAABM"]
[Thu Jul 30 14:12:22.940727 2026] [security2:error] [pid 1004636:tid 1004876] [client 135.119.63.61:19204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/past.php"] [unique_id "amuiFu_uyupB2NyFtxKwRwAAADQ"]
[Thu Jul 30 14:12:23.009066 2026] [security2:error] [pid 1004636:tid 1004900] [client 189.6.88.213:59314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiF-_uyupB2NyFtxKwSAAAAEo"]
[Thu Jul 30 14:12:23.009173 2026] [security2:error] [pid 1004636:tid 1004900] [client 189.6.88.213:59314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiF-_uyupB2NyFtxKwSAAAAEo"]
[Thu Jul 30 14:12:23.232700 2026] [security2:error] [pid 1004636:tid 1004836] [client 20.171.55.167:8787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/css/index.php"] [unique_id "amuiF-_uyupB2NyFtxKwTwAAAA4"]
[Thu Jul 30 14:12:23.937664 2026] [security2:error] [pid 1004636:tid 1004822] [client 20.171.55.167:8781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/bak.php"] [unique_id "amuiF-_uyupB2NyFtxKwWQAAAAA"]
[Thu Jul 30 14:12:24.327922 2026] [security2:error] [pid 1004636:tid 1004926] [client 20.203.135.57:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/gelio1.php"] [unique_id "amuiGO_uyupB2NyFtxKwaAAAAGM"]
[Thu Jul 30 14:12:24.328058 2026] [security2:error] [pid 1004636:tid 1004926] [client 20.203.135.57:59972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/gelio1.php"] [unique_id "amuiGO_uyupB2NyFtxKwaAAAAGM"]
[Thu Jul 30 14:12:24.463534 2026] [core:notice] [pid 1004636:tid 1004773] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:24.644003 2026] [security2:error] [pid 1004636:tid 1004902] [client 20.171.55.167:8817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/alfa-rex.php7"] [unique_id "amuiGO_uyupB2NyFtxKwcQAAAEw"]
[Thu Jul 30 14:12:25.666470 2026] [http2:info] [pid 1021791:tid 1021791] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 14:12:25.925895 2026] [security2:error] [pid 1021791:tid 1021923] [client 20.171.55.167:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/wp-login.php"] [unique_id "amuiGRGd_N1Op4Iu5U81GAAAAQw"]
[Thu Jul 30 14:12:26.014516 2026] [autoindex:error] [pid 1021791:tid 1021946] [client 199.45.155.108:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:12:26.672835 2026] [security2:error] [pid 1021791:tid 1021969] [client 20.171.55.167:8809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/cloud.php"] [unique_id "amuiGhGd_N1Op4Iu5U81QQAAATo"]
[Thu Jul 30 14:12:26.856676 2026] [core:notice] [pid 1021791:tid 1021836] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:27.108866 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.203.135.57:45910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/lp6.php"] [unique_id "amuiGxGd_N1Op4Iu5U81XQAAAVc"]
[Thu Jul 30 14:12:27.109026 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.203.135.57:45910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/lp6.php"] [unique_id "amuiGxGd_N1Op4Iu5U81XQAAAVc"]
[Thu Jul 30 14:12:27.383825 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.171.55.167:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/index.php"] [unique_id "amuiGxGd_N1Op4Iu5U81YQAAAVg"]
[Thu Jul 30 14:12:28.597124 2026] [security2:error] [pid 1021791:tid 1022043] [client 20.171.55.167:8790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/readme.php"] [unique_id "amuiHBGd_N1Op4Iu5U81hAAAAYQ"]
[Thu Jul 30 14:12:29.328822 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.171.55.167:8801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/about.php"] [unique_id "amuiHRGd_N1Op4Iu5U81jwAAAS8"]
[Thu Jul 30 14:12:29.679637 2026] [security2:error] [pid 1021791:tid 1021974] [client 144.172.114.51:50760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/mailer/.env"] [unique_id "amuiHRGd_N1Op4Iu5U81mQAAAT8"]
[Thu Jul 30 14:12:29.895272 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.203.135.57:6383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuiHRGd_N1Op4Iu5U81mgAAARY"]
[Thu Jul 30 14:12:29.895394 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.203.135.57:6383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuiHRGd_N1Op4Iu5U81mgAAARY"]
[Thu Jul 30 14:12:30.067893 2026] [security2:error] [pid 1021791:tid 1021969] [client 20.171.55.167:8769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/themes/404.php"] [unique_id "amuiHhGd_N1Op4Iu5U81oQAAATo"]
[Thu Jul 30 14:12:30.785836 2026] [security2:error] [pid 1021791:tid 1021976] [client 20.171.55.167:8829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/index.php"] [unique_id "amuiHhGd_N1Op4Iu5U81rAAAAUE"]
[Thu Jul 30 14:12:31.227022 2026] [security2:error] [pid 1021791:tid 1022029] [client 47.128.122.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuiHxGd_N1Op4Iu5U81twAAAXY"]
[Thu Jul 30 14:12:31.511843 2026] [security2:error] [pid 1021791:tid 1021921] [client 20.203.135.57:58175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.xexrecords.online"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuiHxGd_N1Op4Iu5U81wgAAAQo"]
[Thu Jul 30 14:12:31.551351 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.171.55.167:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/themes.php"] [unique_id "amuiHxGd_N1Op4Iu5U81xgAAAYU"]
[Thu Jul 30 14:12:31.635353 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.203.135.57:58175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/w3llscc.php"] [unique_id "amuiHxGd_N1Op4Iu5U81ywAAARM"]
[Thu Jul 30 14:12:31.635458 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.203.135.57:58175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/w3llscc.php"] [unique_id "amuiHxGd_N1Op4Iu5U81ywAAARM"]
[Thu Jul 30 14:12:32.276702 2026] [security2:error] [pid 1021791:tid 1021949] [client 20.171.55.167:8824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/dropdown.php"] [unique_id "amuiIBGd_N1Op4Iu5U811wAAASY"]
[Thu Jul 30 14:12:32.781439 2026] [security2:error] [pid 1021791:tid 1021926] [client 43.135.182.43:50728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.182.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samirkhalifa.net"] [uri "/contact.php"] [unique_id "amuiIBGd_N1Op4Iu5U812QAAAQ8"]
[Thu Jul 30 14:12:32.804191 2026] [security2:error] [pid 1021791:tid 1021974] [client 52.54.249.218:13581] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "ghggeneralcontracting.com"] [uri "/"] [unique_id "amuiIBGd_N1Op4Iu5U814wAAAT8"]
[Thu Jul 30 14:12:33.024463 2026] [security2:error] [pid 1021791:tid 1021989] [client 20.171.55.167:8292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/404.php"] [unique_id "amuiIRGd_N1Op4Iu5U815AAAAU4"]
[Thu Jul 30 14:12:33.752721 2026] [security2:error] [pid 1021791:tid 1022023] [client 20.171.55.167:8785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuiIRGd_N1Op4Iu5U81-AAAAXA"]
[Thu Jul 30 14:12:33.789430 2026] [security2:error] [pid 1021791:tid 1022015] [client 189.6.88.213:59854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiIRGd_N1Op4Iu5U81_AAAAWg"]
[Thu Jul 30 14:12:33.789541 2026] [security2:error] [pid 1021791:tid 1022015] [client 189.6.88.213:59854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiIRGd_N1Op4Iu5U81_AAAAWg"]
[Thu Jul 30 14:12:33.905476 2026] [security2:error] [pid 1021791:tid 1021888] [remote 162.55.110.18:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.110.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesounddepot.com"] [uri "/wp-login.php"] [unique_id "amuiIRGd_N1Op4Iu5U819AABcWA"]
[Thu Jul 30 14:12:33.968501 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.203.135.57:21115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/miru3.php"] [unique_id "amuiIRGd_N1Op4Iu5U81_QAAAYg"]
[Thu Jul 30 14:12:33.968620 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.203.135.57:21115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/miru3.php"] [unique_id "amuiIRGd_N1Op4Iu5U81_QAAAYg"]
[Thu Jul 30 14:12:34.517149 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.171.55.167:8784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/file.php"] [unique_id "amuiIhGd_N1Op4Iu5U82CAAAAQs"]
[Thu Jul 30 14:12:34.693792 2026] [core:notice] [pid 1021791:tid 1021896] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:35.243668 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.171.55.167:8434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/index.php"] [unique_id "amuiIxGd_N1Op4Iu5U82FwAAARI"]
[Thu Jul 30 14:12:35.607069 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.203.135.57:21065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/autoload_classmap.php"] [unique_id "amuiIxGd_N1Op4Iu5U82IgAAAQ8"]
[Thu Jul 30 14:12:35.607181 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.203.135.57:21065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/autoload_classmap.php"] [unique_id "amuiIxGd_N1Op4Iu5U82IgAAAQ8"]
[Thu Jul 30 14:12:35.962098 2026] [security2:error] [pid 1021791:tid 1021986] [client 20.171.55.167:8860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/cloud.php"] [unique_id "amuiIxGd_N1Op4Iu5U82LAAAAUs"]
[Thu Jul 30 14:12:36.700763 2026] [security2:error] [pid 1021791:tid 1022011] [client 20.171.55.167:8862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amuiJBGd_N1Op4Iu5U82OgAAAWQ"]
[Thu Jul 30 14:12:37.239815 2026] [core:notice] [pid 1021791:tid 1022043] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:37.245885 2026] [security2:error] [pid 1021791:tid 1022044] [client 82.102.18.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuiJRGd_N1Op4Iu5U82RgAAAYU"]
[Thu Jul 30 14:12:37.245904 2026] [security2:error] [pid 1021791:tid 1022044] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuiJRGd_N1Op4Iu5U82RgAAAYU"]
[Thu Jul 30 14:12:37.320572 2026] [security2:error] [pid 1021791:tid 1021941] [client 20.203.135.57:31238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.xexrecords.online"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuiJRGd_N1Op4Iu5U82TQAAAR4"]
[Thu Jul 30 14:12:37.362450 2026] [security2:error] [pid 1021791:tid 1022017] [client 82.102.18.180:62272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "amuiJRGd_N1Op4Iu5U82RAAAAWo"]
[Thu Jul 30 14:12:37.408018 2026] [security2:error] [pid 1021791:tid 1021935] [client 20.171.55.167:8855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/404.php"] [unique_id "amuiJRGd_N1Op4Iu5U82UAAAARg"]
[Thu Jul 30 14:12:37.589367 2026] [security2:error] [pid 1021791:tid 1021963] [client 20.203.135.57:31238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/wp-content/themes/index.php"] [unique_id "amuiJRGd_N1Op4Iu5U82VwAAATQ"]
[Thu Jul 30 14:12:37.589483 2026] [security2:error] [pid 1021791:tid 1021963] [client 20.203.135.57:31238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/wp-content/themes/index.php"] [unique_id "amuiJRGd_N1Op4Iu5U82VwAAATQ"]
[Thu Jul 30 14:12:38.131242 2026] [security2:error] [pid 1021791:tid 1021980] [client 20.171.55.167:8882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/function.php"] [unique_id "amuiJhGd_N1Op4Iu5U82ZAAAAUU"]
[Thu Jul 30 14:12:38.605839 2026] [security2:error] [pid 1021791:tid 1022009] [client 127.0.0.1:23260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuiJhGd_N1Op4Iu5U82cQAAAWI"]
[Thu Jul 30 14:12:38.605870 2026] [security2:error] [pid 1021791:tid 1021987] [client 127.0.0.1:23256] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.zmt.fcn.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuiJhGd_N1Op4Iu5U82cAAAAUw"]
[Thu Jul 30 14:12:38.606015 2026] [security2:error] [pid 1021791:tid 1022003] [client 74.7.228.23:39926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.zmt.fcn.temporary.site"] [uri "/robots.txt"] [unique_id "amuiJhGd_N1Op4Iu5U82bwABXAk"]
[Thu Jul 30 14:12:38.623329 2026] [security2:error] [pid 1021791:tid 1022012] [client 20.203.135.57:29188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/av.php"] [unique_id "amuiJhGd_N1Op4Iu5U82cgAAAWU"]
[Thu Jul 30 14:12:38.623422 2026] [security2:error] [pid 1021791:tid 1022012] [client 20.203.135.57:29188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/av.php"] [unique_id "amuiJhGd_N1Op4Iu5U82cgAAAWU"]
[Thu Jul 30 14:12:39.459046 2026] [security2:error] [pid 1021791:tid 1022036] [client 20.171.55.167:8845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/file.php"] [unique_id "amuiJxGd_N1Op4Iu5U82gwAAAX0"]
[Thu Jul 30 14:12:39.595546 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.203.135.57:28573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.xexrecords.online"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuiJxGd_N1Op4Iu5U82iwAAAYU"]
[Thu Jul 30 14:12:39.612929 2026] [core:notice] [pid 1021791:tid 1021921] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:39.643862 2026] [security2:error] [pid 1021791:tid 1021939] [client 82.102.18.180:62272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuiJxGd_N1Op4Iu5U82hgAAARw"]
[Thu Jul 30 14:12:39.643896 2026] [security2:error] [pid 1021791:tid 1021939] [client 82.102.18.180:62272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amuiJxGd_N1Op4Iu5U82hgAAARw"]
[Thu Jul 30 14:12:39.732601 2026] [security2:error] [pid 1021791:tid 1021936] [client 20.203.135.57:28573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.xexrecords.online"] [uri "/___proxy_subdomain_webdisk/wordpress/wp-admin/maint/"] [unique_id "amuiJxGd_N1Op4Iu5U82jQAAARk"]
[Thu Jul 30 14:12:39.856668 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.203.135.57:28573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/tiny.php"] [unique_id "amuiJxGd_N1Op4Iu5U82jgAAARM"]
[Thu Jul 30 14:12:39.856792 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.203.135.57:28573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/tiny.php"] [unique_id "amuiJxGd_N1Op4Iu5U82jgAAARM"]
[Thu Jul 30 14:12:40.177332 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.171.55.167:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/acme-challenge/autoload_classmap.php"] [unique_id "amuiKBGd_N1Op4Iu5U82mAAAASA"]
[Thu Jul 30 14:12:40.603749 2026] [fcgid:warn] [pid 1021791:tid 1021961] (70014)End of file found: [client 199.45.155.86:43138] mod_fcgid: can't get data from http client
[Thu Jul 30 14:12:40.691396 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.203.135.57:25234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuiKBGd_N1Op4Iu5U82pQAAAUI"]
[Thu Jul 30 14:12:40.691489 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.203.135.57:25234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuiKBGd_N1Op4Iu5U82pQAAAUI"]
[Thu Jul 30 14:12:40.787606 2026] [security2:error] [pid 1021791:tid 1021988] [client 144.172.114.51:48552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/docker/.env"] [unique_id "amuiKBGd_N1Op4Iu5U82pgAAAU0"]
[Thu Jul 30 14:12:40.848545 2026] [security2:error] [pid 1021791:tid 1021948] [client 82.102.18.180:62272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuiKBGd_N1Op4Iu5U82pAAAASU"]
[Thu Jul 30 14:12:40.883325 2026] [security2:error] [pid 1021791:tid 1021982] [client 20.171.55.167:8447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/themes.php"] [unique_id "amuiKBGd_N1Op4Iu5U82qgAAAUc"]
[Thu Jul 30 14:12:41.615610 2026] [security2:error] [pid 1021791:tid 1022002] [client 20.171.55.167:8421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/wp-login.php"] [unique_id "amuiKRGd_N1Op4Iu5U82ugAAAVs"]
[Thu Jul 30 14:12:41.633674 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.203.135.57:34612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/zrrhj.php"] [unique_id "amuiKRGd_N1Op4Iu5U82vAAAAWY"]
[Thu Jul 30 14:12:41.633764 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.203.135.57:34612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/zrrhj.php"] [unique_id "amuiKRGd_N1Op4Iu5U82vAAAAWY"]
[Thu Jul 30 14:12:42.333798 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.171.55.167:8442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/file.php"] [unique_id "amuiKhGd_N1Op4Iu5U82zQAAAYg"]
[Thu Jul 30 14:12:42.351361 2026] [security2:error] [pid 1021791:tid 1022043] [client 20.203.135.57:32293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuiKhGd_N1Op4Iu5U82zgAAAYQ"]
[Thu Jul 30 14:12:42.351443 2026] [security2:error] [pid 1021791:tid 1022043] [client 20.203.135.57:32293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuiKhGd_N1Op4Iu5U82zgAAAYQ"]
[Thu Jul 30 14:12:42.581815 2026] [security2:error] [pid 1021791:tid 1022016] [client 103.82.27.41:54612] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.evergreentransportaionservice.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuiKhGd_N1Op4Iu5U821AAAAWk"]
[Thu Jul 30 14:12:42.910375 2026] [security2:error] [pid 1021791:tid 1021950] [client 103.82.27.41:54636] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.evergreentransportaionservice.com"] [uri "/___proxy_subdomain_cpanel/wp-json/batch/v1"] [unique_id "amuiKhGd_N1Op4Iu5U822wAAASc"]
[Thu Jul 30 14:12:43.042633 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.171.55.167:8393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-trackback.php"] [unique_id "amuiKxGd_N1Op4Iu5U823wAAASA"]
[Thu Jul 30 14:12:43.165416 2026] [security2:error] [pid 1021791:tid 1021978] [client 20.203.135.57:21079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/wpgum.php"] [unique_id "amuiKxGd_N1Op4Iu5U824QAAAUM"]
[Thu Jul 30 14:12:43.165523 2026] [security2:error] [pid 1021791:tid 1021978] [client 20.203.135.57:21079] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/wpgum.php"] [unique_id "amuiKxGd_N1Op4Iu5U824QAAAUM"]
[Thu Jul 30 14:12:43.474612 2026] [security2:error] [pid 1021791:tid 1021985] [client 13.203.76.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "echomemoversalain.casa"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuiKxGd_N1Op4Iu5U827gAAAUo"]
[Thu Jul 30 14:12:43.495193 2026] [security2:error] [pid 1021791:tid 1021975] [client 13.203.76.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "echomemoversalain.casa"] [uri "/media/system/js/core.js"] [unique_id "amuiKxGd_N1Op4Iu5U828AAAAUA"]
[Thu Jul 30 14:12:43.555547 2026] [core:notice] [pid 1021791:tid 1021933] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:43.557292 2026] [security2:error] [pid 1021791:tid 1021933] [client 135.181.74.155:35740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amuiKxGd_N1Op4Iu5U828QAAARY"]
[Thu Jul 30 14:12:43.708783 2026] [security2:error] [pid 1021791:tid 1022009] [client 20.203.135.57:31250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/ywwbf.php"] [unique_id "amuiKxGd_N1Op4Iu5U829gAAAWI"]
[Thu Jul 30 14:12:43.708907 2026] [security2:error] [pid 1021791:tid 1022009] [client 20.203.135.57:31250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/ywwbf.php"] [unique_id "amuiKxGd_N1Op4Iu5U829gAAAWI"]
[Thu Jul 30 14:12:43.746618 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.171.55.167:8407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "amuiKxGd_N1Op4Iu5U82-gAAATU"]
[Thu Jul 30 14:12:43.752937 2026] [security2:error] [pid 1021791:tid 1021986] [client 135.181.74.155:35754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "sv.radiojelli.com"] [uri "/robots.txt"] [unique_id "amuiKxGd_N1Op4Iu5U82-wAAAUs"]
[Thu Jul 30 14:12:43.906857 2026] [core:notice] [pid 1021791:tid 1022019] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:44.016039 2026] [core:notice] [pid 1021791:tid 1022031] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:44.018561 2026] [security2:error] [pid 1021791:tid 1022031] [client 135.181.74.155:35764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/why-you-should-embrace-your-sexuality.html"] [unique_id "amuiLBGd_N1Op4Iu5U83AQAAAXg"]
[Thu Jul 30 14:12:44.189195 2026] [security2:error] [pid 1021791:tid 1022046] [client 20.203.135.57:25158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/xoldj.php"] [unique_id "amuiLBGd_N1Op4Iu5U83BQAAAYc"]
[Thu Jul 30 14:12:44.189300 2026] [security2:error] [pid 1021791:tid 1022046] [client 20.203.135.57:25158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/xoldj.php"] [unique_id "amuiLBGd_N1Op4Iu5U83BQAAAYc"]
[Thu Jul 30 14:12:44.211004 2026] [security2:error] [pid 1021791:tid 1022026] [client 135.181.74.155:35740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuiKxGd_N1Op4Iu5U82_wAAAWw"]
[Thu Jul 30 14:12:44.502690 2026] [security2:error] [pid 1021791:tid 1022001] [client 20.171.55.167:8841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/index.php"] [unique_id "amuiLBGd_N1Op4Iu5U83DgAAAVo"]
[Thu Jul 30 14:12:44.510118 2026] [security2:error] [pid 1021791:tid 1022033] [client 189.6.88.213:60404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiLBGd_N1Op4Iu5U83DwAAAXo"]
[Thu Jul 30 14:12:44.510223 2026] [security2:error] [pid 1021791:tid 1022033] [client 189.6.88.213:60404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiLBGd_N1Op4Iu5U83DwAAAXo"]
[Thu Jul 30 14:12:44.815177 2026] [core:notice] [pid 1021791:tid 1021860] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:44.827391 2026] [security2:error] [pid 1021791:tid 1021967] [client 20.203.135.57:40876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/f35.php"] [unique_id "amuiLBGd_N1Op4Iu5U83FwAAATg"]
[Thu Jul 30 14:12:44.827492 2026] [security2:error] [pid 1021791:tid 1021967] [client 20.203.135.57:40876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/f35.php"] [unique_id "amuiLBGd_N1Op4Iu5U83FwAAATg"]
[Thu Jul 30 14:12:44.914742 2026] [security2:error] [pid 1021791:tid 1021946] [client 135.181.74.155:35776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "sv.radiojelli.com"] [uri "/20-signs-you-re-an-ambivert"] [unique_id "amuiLBGd_N1Op4Iu5U83HAAAASM"]
[Thu Jul 30 14:12:45.066964 2026] [core:notice] [pid 1021791:tid 1021948] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:45.207378 2026] [security2:error] [pid 1021791:tid 1021963] [client 20.171.55.167:8433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/themes.php"] [unique_id "amuiLRGd_N1Op4Iu5U83KAAAATQ"]
[Thu Jul 30 14:12:45.223040 2026] [security2:error] [pid 1021791:tid 1021996] [client 135.181.74.155:35764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/money.html"] [unique_id "amuiLRGd_N1Op4Iu5U83HgAAASU"]
[Thu Jul 30 14:12:45.294124 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.203.135.57:32263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/gk.php"] [unique_id "amuiLRGd_N1Op4Iu5U83LAAAARY"]
[Thu Jul 30 14:12:45.294220 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.203.135.57:32263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/gk.php"] [unique_id "amuiLRGd_N1Op4Iu5U83LAAAARY"]
[Thu Jul 30 14:12:45.885264 2026] [security2:error] [pid 1021791:tid 1022025] [client 20.203.135.57:34616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/584062352875874akp.php"] [unique_id "amuiLRGd_N1Op4Iu5U83PAAAAXI"]
[Thu Jul 30 14:12:45.885362 2026] [security2:error] [pid 1021791:tid 1022025] [client 20.203.135.57:34616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/584062352875874akp.php"] [unique_id "amuiLRGd_N1Op4Iu5U83PAAAAXI"]
[Thu Jul 30 14:12:45.911351 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.171.55.167:8430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/cloud.php"] [unique_id "amuiLRGd_N1Op4Iu5U83PQAAAUw"]
[Thu Jul 30 14:12:46.287400 2026] [core:notice] [pid 1021791:tid 1022026] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:46.462392 2026] [security2:error] [pid 1021791:tid 1021942] [client 20.203.135.57:40839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/wper3.php"] [unique_id "amuiLhGd_N1Op4Iu5U83SgAAAR8"]
[Thu Jul 30 14:12:46.462490 2026] [security2:error] [pid 1021791:tid 1021942] [client 20.203.135.57:40839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/wper3.php"] [unique_id "amuiLhGd_N1Op4Iu5U83SgAAAR8"]
[Thu Jul 30 14:12:46.615813 2026] [security2:error] [pid 1021791:tid 1022015] [client 20.171.55.167:8789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/wp-load.php"] [unique_id "amuiLhGd_N1Op4Iu5U83TgAAAWg"]
[Thu Jul 30 14:12:46.886872 2026] [core:notice] [pid 1021791:tid 1021971] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:47.173353 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.203.135.57:6545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/bthil.php"] [unique_id "amuiLxGd_N1Op4Iu5U83WgAAAT4"]
[Thu Jul 30 14:12:47.173465 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.203.135.57:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/bthil.php"] [unique_id "amuiLxGd_N1Op4Iu5U83WgAAAT4"]
[Thu Jul 30 14:12:47.319986 2026] [security2:error] [pid 1021791:tid 1021938] [client 20.171.55.167:8394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/file.php"] [unique_id "amuiLxGd_N1Op4Iu5U83XgAAARs"]
[Thu Jul 30 14:12:48.026132 2026] [security2:error] [pid 1021791:tid 1021983] [client 20.171.55.167:8422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/makeasmtp.php"] [unique_id "amuiMBGd_N1Op4Iu5U83bgAAAUg"]
[Thu Jul 30 14:12:48.549770 2026] [core:notice] [pid 1021791:tid 1022003] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:48.553150 2026] [security2:error] [pid 1021791:tid 1022003] [client 135.181.74.155:35764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/why-you-should-forget-what-your-mother-told-you-and-date-the-slut.html"] [unique_id "amuiMBGd_N1Op4Iu5U83egAAAVw"]
[Thu Jul 30 14:12:48.616016 2026] [security2:error] [pid 1021791:tid 1022010] [client 122.154.74.204:48394] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuiMBGd_N1Op4Iu5U83ewAAAWM"]
[Thu Jul 30 14:12:48.690702 2026] [security2:error] [pid 1021791:tid 1022013] [client 122.154.74.204:34568] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuiMBGd_N1Op4Iu5U83fAAAAWY"]
[Thu Jul 30 14:12:48.737406 2026] [security2:error] [pid 1021791:tid 1021989] [client 20.171.55.167:8768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/index.php"] [unique_id "amuiMBGd_N1Op4Iu5U83fQAAAU4"]
[Thu Jul 30 14:12:49.230855 2026] [security2:error] [pid 1021791:tid 1022044] [client 68.67.112.134:36740] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuiMRGd_N1Op4Iu5U83hwAAAYU"]
[Thu Jul 30 14:12:49.442953 2026] [security2:error] [pid 1021791:tid 1022033] [client 20.171.55.167:8837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amuiMRGd_N1Op4Iu5U83jgAAAXo"]
[Thu Jul 30 14:12:49.500150 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.203.135.57:5782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/wyzer1.php"] [unique_id "amuiMRGd_N1Op4Iu5U83kQAAAT4"]
[Thu Jul 30 14:12:49.500251 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.203.135.57:5782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/wyzer1.php"] [unique_id "amuiMRGd_N1Op4Iu5U83kQAAAT4"]
[Thu Jul 30 14:12:49.870710 2026] [core:notice] [pid 1021791:tid 1022022] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:50.172411 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.171.55.167:8780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/404.php"] [unique_id "amuiMhGd_N1Op4Iu5U83rAAAARY"]
[Thu Jul 30 14:12:50.341792 2026] [security2:error] [pid 1021791:tid 1021974] [client 20.203.135.57:11041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/mh.php"] [unique_id "amuiMhGd_N1Op4Iu5U83rQAAAT8"]
[Thu Jul 30 14:12:50.341913 2026] [security2:error] [pid 1021791:tid 1021974] [client 20.203.135.57:11041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/mh.php"] [unique_id "amuiMhGd_N1Op4Iu5U83rQAAAT8"]
[Thu Jul 30 14:12:50.514250 2026] [security2:error] [pid 1021791:tid 1021989] [client 144.172.114.51:58514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/helm/.env"] [unique_id "amuiMhGd_N1Op4Iu5U83uwAAAU4"]
[Thu Jul 30 14:12:50.893191 2026] [security2:error] [pid 1021791:tid 1022018] [client 20.171.55.167:8963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "amuiMhGd_N1Op4Iu5U83xQAAAWs"]
[Thu Jul 30 14:12:50.984668 2026] [core:notice] [pid 1021791:tid 1022044] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:50.986440 2026] [core:notice] [pid 1021791:tid 1021941] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:50.995804 2026] [core:notice] [pid 1021791:tid 1021936] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:51.077631 2026] [core:notice] [pid 1021791:tid 1021928] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:51.131753 2026] [security2:error] [pid 1021791:tid 1022045] [client 82.102.18.180:47544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuiMhGd_N1Op4Iu5U83xwAAAYY"]
[Thu Jul 30 14:12:51.346132 2026] [security2:error] [pid 1021791:tid 1021952] [client 20.203.135.57:6532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuiMxGd_N1Op4Iu5U830gAAASk"]
[Thu Jul 30 14:12:51.346251 2026] [security2:error] [pid 1021791:tid 1021952] [client 20.203.135.57:6532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuiMxGd_N1Op4Iu5U830gAAASk"]
[Thu Jul 30 14:12:51.380855 2026] [security2:error] [pid 1021791:tid 1021951] [client 144.172.114.51:58530] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/terraform/.env"] [unique_id "amuiMxGd_N1Op4Iu5U831QAAASg"]
[Thu Jul 30 14:12:51.606443 2026] [security2:error] [pid 1021791:tid 1021955] [client 146.103.115.7:56573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.103.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tereashops.com"] [uri "/my-account/"] [unique_id "amuiMxGd_N1Op4Iu5U833QAAASw"], referer: https://tereashops.com/
[Thu Jul 30 14:12:51.664632 2026] [security2:error] [pid 1021791:tid 1021991] [client 82.102.18.180:47544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuiMxGd_N1Op4Iu5U834QAAAVA"]
[Thu Jul 30 14:12:51.664734 2026] [security2:error] [pid 1021791:tid 1021991] [client 82.102.18.180:47544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuiMxGd_N1Op4Iu5U834QAAAVA"]
[Thu Jul 30 14:12:51.971563 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.171.55.167:9004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/radio.php"] [unique_id "amuiMxGd_N1Op4Iu5U836AAAASI"]
[Thu Jul 30 14:12:52.025824 2026] [core:notice] [pid 1021791:tid 1021995] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:52.271923 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.203.135.57:39226] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.xexrecords.online"] [uri "/1.php"] [unique_id "amuiNBGd_N1Op4Iu5U839AAAAVg"]
[Thu Jul 30 14:12:52.272068 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.203.135.57:39226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/1.php"] [unique_id "amuiNBGd_N1Op4Iu5U839AAAAVg"]
[Thu Jul 30 14:12:52.272163 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.203.135.57:39226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/1.php"] [unique_id "amuiNBGd_N1Op4Iu5U839AAAAVg"]
[Thu Jul 30 14:12:52.829941 2026] [security2:error] [pid 1021791:tid 1022046] [client 20.171.55.167:8998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuiNBGd_N1Op4Iu5U84AgAAAYc"]
[Thu Jul 30 14:12:53.159354 2026] [core:notice] [pid 1021791:tid 1022014] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:53.472878 2026] [security2:error] [pid 1021791:tid 1021923] [client 20.203.135.57:40844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/chosen.php"] [unique_id "amuiNRGd_N1Op4Iu5U84EwAAAQw"]
[Thu Jul 30 14:12:53.473047 2026] [security2:error] [pid 1021791:tid 1021923] [client 20.203.135.57:40844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/chosen.php"] [unique_id "amuiNRGd_N1Op4Iu5U84EwAAAQw"]
[Thu Jul 30 14:12:53.531683 2026] [security2:error] [pid 1021791:tid 1021943] [client 52.238.199.152:13188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuiNRGd_N1Op4Iu5U84FwAAASA"]
[Thu Jul 30 14:12:53.532429 2026] [security2:error] [pid 1021791:tid 1021940] [client 20.171.55.167:8980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/admin.php"] [unique_id "amuiNRGd_N1Op4Iu5U84GAAAAR0"]
[Thu Jul 30 14:12:54.256670 2026] [security2:error] [pid 1021791:tid 1022022] [client 20.171.55.167:8996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/system_log.php"] [unique_id "amuiNhGd_N1Op4Iu5U84LwAAAW8"]
[Thu Jul 30 14:12:54.473062 2026] [security2:error] [pid 1021791:tid 1022044] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuiNRGd_N1Op4Iu5U84IwABhQo"]
[Thu Jul 30 14:12:54.723706 2026] [security2:error] [pid 1021791:tid 1022044] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuiNhGd_N1Op4Iu5U84JwABhRw"]
[Thu Jul 30 14:12:54.916796 2026] [security2:error] [pid 1021791:tid 1022019] [client 20.203.135.57:25166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/sd.php"] [unique_id "amuiNhGd_N1Op4Iu5U84PQAAAWw"]
[Thu Jul 30 14:12:54.916910 2026] [security2:error] [pid 1021791:tid 1022019] [client 20.203.135.57:25166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/sd.php"] [unique_id "amuiNhGd_N1Op4Iu5U84PQAAAWw"]
[Thu Jul 30 14:12:54.926813 2026] [core:notice] [pid 1021791:tid 1021925] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:55.002042 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.171.55.167:9016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/wp-activate.php"] [unique_id "amuiNxGd_N1Op4Iu5U84PwAAAWY"]
[Thu Jul 30 14:12:55.146910 2026] [security2:error] [pid 1021791:tid 1022032] [client 189.6.88.213:60975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiNxGd_N1Op4Iu5U84RwAAAXk"]
[Thu Jul 30 14:12:55.147046 2026] [security2:error] [pid 1021791:tid 1022032] [client 189.6.88.213:60975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiNxGd_N1Op4Iu5U84RwAAAXk"]
[Thu Jul 30 14:12:55.671107 2026] [security2:error] [pid 1021791:tid 1022023] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuiNxGd_N1Op4Iu5U84QgAAAXA"]
[Thu Jul 30 14:12:55.728268 2026] [security2:error] [pid 1021791:tid 1021923] [client 20.171.55.167:8417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/makeasmtp.php"] [unique_id "amuiNxGd_N1Op4Iu5U84VgAAAQw"]
[Thu Jul 30 14:12:56.467832 2026] [security2:error] [pid 1021791:tid 1021975] [client 20.171.55.167:9001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuiOBGd_N1Op4Iu5U84bwAAAUA"]
[Thu Jul 30 14:12:56.915339 2026] [core:notice] [pid 1021791:tid 1022012] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:56.918587 2026] [security2:error] [pid 1021791:tid 1022012] [client 135.181.74.155:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/why-you-should-refuse-to-lower-your-standards-one-hundred-percent-of-the-time.html"] [unique_id "amuiOBGd_N1Op4Iu5U84fAAAAWU"]
[Thu Jul 30 14:12:56.945880 2026] [core:error] [pid 1021791:tid 1022011] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:12:56.945899 2026] [core:error] [pid 1021791:tid 1022011] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:12:57.175817 2026] [proxy:error] [pid 1021791:tid 1022036] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:12:57.175868 2026] [proxy_http:error] [pid 1021791:tid 1022036] [client 34.233.129.35:2036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:12:57.176456 2026] [proxy:error] [pid 1021791:tid 1022036] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:12:57.176501 2026] [proxy_http:error] [pid 1021791:tid 1022036] [client 34.233.129.35:2036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:12:57.186324 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.171.55.167:8978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/link.php"] [unique_id "amuiORGd_N1Op4Iu5U84igAAAW4"]
[Thu Jul 30 14:12:57.210819 2026] [proxy:error] [pid 1021791:tid 1021941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:12:57.210896 2026] [proxy_http:error] [pid 1021791:tid 1021941] [client 32.194.121.99:58631] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:12:57.211510 2026] [proxy:error] [pid 1021791:tid 1021941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:12:57.211564 2026] [proxy_http:error] [pid 1021791:tid 1021941] [client 32.194.121.99:58631] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:12:57.520841 2026] [security2:error] [pid 1021791:tid 1021923] [client 20.203.135.57:57024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/z60.php"] [unique_id "amuiORGd_N1Op4Iu5U84ngAAAQw"]
[Thu Jul 30 14:12:57.520944 2026] [security2:error] [pid 1021791:tid 1021923] [client 20.203.135.57:57024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/z60.php"] [unique_id "amuiORGd_N1Op4Iu5U84ngAAAQw"]
[Thu Jul 30 14:12:57.923484 2026] [security2:error] [pid 1021791:tid 1021960] [client 20.171.55.167:9003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuiORGd_N1Op4Iu5U84rwAAATE"]
[Thu Jul 30 14:12:58.163131 2026] [security2:error] [pid 1021791:tid 1022025] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuiORGd_N1Op4Iu5U84oQAAAXI"]
[Thu Jul 30 14:12:58.654957 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.171.55.167:9022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/themes.php"] [unique_id "amuiOhGd_N1Op4Iu5U84wgAAAVg"]
[Thu Jul 30 14:12:59.307701 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.203.135.57:36827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/home.php"] [unique_id "amuiOxGd_N1Op4Iu5U84zQAAATU"]
[Thu Jul 30 14:12:59.307814 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.203.135.57:36827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/home.php"] [unique_id "amuiOxGd_N1Op4Iu5U84zQAAATU"]
[Thu Jul 30 14:12:59.395351 2026] [security2:error] [pid 1021791:tid 1022039] [client 20.171.55.167:8961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuiOxGd_N1Op4Iu5U840AAAAYA"]
[Thu Jul 30 14:12:59.815694 2026] [core:notice] [pid 1021791:tid 1021935] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:12:59.820164 2026] [security2:error] [pid 1021791:tid 1021935] [client 135.181.74.155:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/why-your-fear-of-dying-alone-means-you-re-not-really-living.html"] [unique_id "amuiOxGd_N1Op4Iu5U841wAAARg"]
[Thu Jul 30 14:13:00.124348 2026] [security2:error] [pid 1021791:tid 1022023] [client 20.171.55.167:8976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuiPBGd_N1Op4Iu5U844QAAAXA"]
[Thu Jul 30 14:13:00.295546 2026] [security2:error] [pid 1021791:tid 1022031] [client 146.103.115.7:57980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amuiOhGd_N1Op4Iu5U84wQAAAXg"], referer: https://tereashops.com/xmlrpc.php
[Thu Jul 30 14:13:00.380673 2026] [security2:error] [pid 1021791:tid 1021856] [remote 74.7.243.224:34794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amuiPBGd_N1Op4Iu5U845wABSUA"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:13:00.403625 2026] [security2:error] [pid 1021791:tid 1021985] [client 20.203.135.57:36821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/ws58.php"] [unique_id "amuiPBGd_N1Op4Iu5U846AAAAUo"]
[Thu Jul 30 14:13:00.403732 2026] [security2:error] [pid 1021791:tid 1021985] [client 20.203.135.57:36821] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/ws58.php"] [unique_id "amuiPBGd_N1Op4Iu5U846AAAAUo"]
[Thu Jul 30 14:13:00.861697 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.171.55.167:8994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/function.php"] [unique_id "amuiPBGd_N1Op4Iu5U84-wAAARU"]
[Thu Jul 30 14:13:01.599773 2026] [security2:error] [pid 1021791:tid 1022020] [client 20.171.55.167:8401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/images/wp-login.php"] [unique_id "amuiPRGd_N1Op4Iu5U85CwAAAW0"]
[Thu Jul 30 14:13:01.803058 2026] [security2:error] [pid 1021791:tid 1022011] [client 135.119.63.61:62014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cakiltheme/idx.php"] [unique_id "amuiPRGd_N1Op4Iu5U85EAAAAWQ"]
[Thu Jul 30 14:13:02.343452 2026] [security2:error] [pid 1021791:tid 1021983] [client 20.171.55.167:9032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/log.php"] [unique_id "amuiPhGd_N1Op4Iu5U85HgAAAUg"]
[Thu Jul 30 14:13:02.464352 2026] [security2:error] [pid 1021791:tid 1021995] [client 146.103.115.7:58289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tereashops.com"] [uri "/xmlrpc.php"] [unique_id "amuiPBGd_N1Op4Iu5U849wAAAVQ"], referer: https://tereashops.com/xmlrpc.php
[Thu Jul 30 14:13:02.540721 2026] [security2:error] [pid 1021791:tid 1021944] [client 135.119.63.61:28029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cakiltheme/up.php"] [unique_id "amuiPhGd_N1Op4Iu5U85KQAAASE"]
[Thu Jul 30 14:13:02.825915 2026] [core:notice] [pid 1021791:tid 1021967] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:02.831439 2026] [security2:error] [pid 1021791:tid 1021967] [client 135.181.74.155:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/why-your-heartbreak-is-the-best-thing-to-ever-happen-to-you.html"] [unique_id "amuiPhGd_N1Op4Iu5U85MAAAATg"]
[Thu Jul 30 14:13:03.076647 2026] [security2:error] [pid 1021791:tid 1021978] [client 20.171.55.167:9068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "amuiPxGd_N1Op4Iu5U85NwAAAUM"]
[Thu Jul 30 14:13:03.117853 2026] [security2:error] [pid 1021791:tid 1021979] [client 20.203.135.57:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/gulu.php"] [unique_id "amuiPxGd_N1Op4Iu5U85OwAAAUQ"]
[Thu Jul 30 14:13:03.117963 2026] [security2:error] [pid 1021791:tid 1021979] [client 20.203.135.57:26614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/gulu.php"] [unique_id "amuiPxGd_N1Op4Iu5U85OwAAAUQ"]
[Thu Jul 30 14:13:03.232921 2026] [security2:error] [pid 1021791:tid 1021991] [client 135.119.63.61:5758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/calendar/index.php"] [unique_id "amuiPxGd_N1Op4Iu5U85PwAAAVA"]
[Thu Jul 30 14:13:03.800575 2026] [security2:error] [pid 1021791:tid 1021937] [client 20.171.55.167:9082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/themes/themes.php"] [unique_id "amuiPxGd_N1Op4Iu5U85SgAAARo"]
[Thu Jul 30 14:13:03.967858 2026] [security2:error] [pid 1021791:tid 1022030] [client 135.119.63.61:5757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/canonical.php"] [unique_id "amuiPxGd_N1Op4Iu5U85YgAAAXc"]
[Thu Jul 30 14:13:03.996171 2026] [core:notice] [pid 1021791:tid 1021982] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:04.543922 2026] [security2:error] [pid 1021791:tid 1022002] [client 20.171.55.167:9028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/radio.php"] [unique_id "amuiQBGd_N1Op4Iu5U85dwAAAVs"]
[Thu Jul 30 14:13:04.736819 2026] [security2:error] [pid 1021791:tid 1021964] [client 135.119.63.61:5748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/catalogadmin.php"] [unique_id "amuiQBGd_N1Op4Iu5U85ggAAATU"]
[Thu Jul 30 14:13:04.860512 2026] [security2:error] [pid 1021791:tid 1022033] [client 20.203.135.57:6570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuiQBGd_N1Op4Iu5U85iQAAAXo"]
[Thu Jul 30 14:13:04.860657 2026] [security2:error] [pid 1021791:tid 1022033] [client 20.203.135.57:6570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuiQBGd_N1Op4Iu5U85iQAAAXo"]
[Thu Jul 30 14:13:05.286688 2026] [security2:error] [pid 1021791:tid 1022028] [client 20.171.55.167:8409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-mail.php"] [unique_id "amuiQRGd_N1Op4Iu5U85lAAAAXU"]
[Thu Jul 30 14:13:05.474991 2026] [security2:error] [pid 1021791:tid 1022047] [client 135.119.63.61:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/catalogalfa.php"] [unique_id "amuiQRGd_N1Op4Iu5U85lQAAAYg"]
[Thu Jul 30 14:13:05.821212 2026] [security2:error] [pid 1021791:tid 1021995] [client 189.6.88.213:61524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiQRGd_N1Op4Iu5U85oAAAAVQ"]
[Thu Jul 30 14:13:05.821328 2026] [security2:error] [pid 1021791:tid 1021995] [client 189.6.88.213:61524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiQRGd_N1Op4Iu5U85oAAAAVQ"]
[Thu Jul 30 14:13:05.942641 2026] [core:notice] [pid 1021791:tid 1021988] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:05.946218 2026] [security2:error] [pid 1021791:tid 1021988] [client 135.181.74.155:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/wiki.html"] [unique_id "amuiQRGd_N1Op4Iu5U85oQAAAU0"]
[Thu Jul 30 14:13:05.990373 2026] [security2:error] [pid 1021791:tid 1021924] [client 20.171.55.167:9077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuiQRGd_N1Op4Iu5U85ogAAAQ0"]
[Thu Jul 30 14:13:06.201449 2026] [security2:error] [pid 1021791:tid 1021984] [client 135.119.63.61:5715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/catalogbypass.php"] [unique_id "amuiQhGd_N1Op4Iu5U85qQAAAUk"]
[Thu Jul 30 14:13:06.504109 2026] [security2:error] [pid 1021791:tid 1022021] [client 146.103.115.7:58886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/wp-admin/post-new.php"] [unique_id "amuiQBGd_N1Op4Iu5U85fQAAAW4"], referer: https://tereashops.com/my-account/?action=register&xoo_el_reg_email=gb_warrenjohn8483%40falderewonek.site&xoo_el_reg_fname=Horace&xoo_el_reg_lname=Papst&xoo_el_reg_pass=9OW3o%21s8Trqkh3&xoo_el_reg_pass_again=9OW3o%21s8Trqkh3&xoo_el_reg_terms=yes&_xoo_el_form=register&xoo_el_redirect=%2Fmy-account%2F%3Faction%3Dregister
[Thu Jul 30 14:13:06.555428 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.203.135.57:26564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/wpls.php"] [unique_id "amuiQhGd_N1Op4Iu5U85rwAAAYU"]
[Thu Jul 30 14:13:06.555556 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.203.135.57:26564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/wpls.php"] [unique_id "amuiQhGd_N1Op4Iu5U85rwAAAYU"]
[Thu Jul 30 14:13:06.692431 2026] [security2:error] [pid 1021791:tid 1021979] [client 20.171.55.167:9085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/admin.php"] [unique_id "amuiQhGd_N1Op4Iu5U85tgAAAUQ"]
[Thu Jul 30 14:13:06.973675 2026] [security2:error] [pid 1021791:tid 1022009] [client 135.119.63.61:5722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/catalogk.php"] [unique_id "amuiQhGd_N1Op4Iu5U85vwAAAWI"]
[Thu Jul 30 14:13:07.428935 2026] [security2:error] [pid 1021791:tid 1022041] [client 20.171.55.167:9051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuiQxGd_N1Op4Iu5U85zQAAAYI"]
[Thu Jul 30 14:13:07.726449 2026] [security2:error] [pid 1021791:tid 1021976] [client 135.119.63.61:28009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/catalogwp.php"] [unique_id "amuiQxGd_N1Op4Iu5U850gAAAUE"]
[Thu Jul 30 14:13:07.973668 2026] [security2:error] [pid 1021791:tid 1021994] [client 146.103.115.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuiQhGd_N1Op4Iu5U85wgAAAVM"], referer: https://tereashops.com/wp-admin/post-new.php
[Thu Jul 30 14:13:08.138753 2026] [security2:error] [pid 1021791:tid 1022034] [client 20.171.55.167:9079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-links-opml.php"] [unique_id "amuiRBGd_N1Op4Iu5U852wAAAXs"]
[Thu Jul 30 14:13:08.412193 2026] [security2:error] [pid 1021791:tid 1022000] [client 20.203.135.57:30850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/php.php"] [unique_id "amuiRBGd_N1Op4Iu5U855AAAAVk"]
[Thu Jul 30 14:13:08.412286 2026] [security2:error] [pid 1021791:tid 1022000] [client 20.203.135.57:30850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/php.php"] [unique_id "amuiRBGd_N1Op4Iu5U855AAAAVk"]
[Thu Jul 30 14:13:08.521013 2026] [security2:error] [pid 1021791:tid 1021819] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amuiRBGd_N1Op4Iu5U855gABNBs"]
[Thu Jul 30 14:13:08.521635 2026] [security2:error] [pid 1021791:tid 1021995] [client 135.119.63.61:33881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/categories/about.php"] [unique_id "amuiRBGd_N1Op4Iu5U855wAAAVQ"]
[Thu Jul 30 14:13:08.572046 2026] [core:notice] [pid 1021791:tid 1021951] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:09.255435 2026] [security2:error] [pid 1021791:tid 1022006] [client 135.119.63.61:5709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/category.php"] [unique_id "amuiRRGd_N1Op4Iu5U85-AAAAV8"]
[Thu Jul 30 14:13:09.355604 2026] [security2:error] [pid 1021791:tid 1021986] [client 144.172.114.51:57706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuiRRGd_N1Op4Iu5U85-QAAAUs"]
[Thu Jul 30 14:13:09.472822 2026] [security2:error] [pid 1021791:tid 1021928] [client 20.171.55.167:9027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/acme-challenge/radio.php"] [unique_id "amuiRRGd_N1Op4Iu5U85_gAAARE"]
[Thu Jul 30 14:13:09.520201 2026] [security2:error] [pid 1021791:tid 1021975] [client 146.103.115.7:59354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/wp-admin/edit-tags.php"] [unique_id "amuiRBGd_N1Op4Iu5U856QAAAUA"], referer: https://tereashops.com/404/
[Thu Jul 30 14:13:09.990591 2026] [security2:error] [pid 1021791:tid 1022025] [client 135.119.63.61:28015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cay-van-phong/filemanager.php"] [unique_id "amuiRRGd_N1Op4Iu5U86CQAAAXI"]
[Thu Jul 30 14:13:10.181901 2026] [security2:error] [pid 1021791:tid 1021931] [client 20.171.55.167:8962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/images/file.php"] [unique_id "amuiRhGd_N1Op4Iu5U86EAAAARQ"]
[Thu Jul 30 14:13:10.191687 2026] [core:notice] [pid 1021791:tid 1022037] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:10.196004 2026] [security2:error] [pid 1021791:tid 1022037] [client 135.181.74.155:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/words-that-sound-racist-but-in-fact-are-not.html"] [unique_id "amuiRhGd_N1Op4Iu5U86EQAAAX4"]
[Thu Jul 30 14:13:10.755821 2026] [security2:error] [pid 1021791:tid 1021926] [client 135.119.63.61:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cay-van-phong/hehe.php"] [unique_id "amuiRhGd_N1Op4Iu5U86HQAAAQ8"]
[Thu Jul 30 14:13:10.909457 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.171.55.167:9072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/upgrade/function.php"] [unique_id "amuiRhGd_N1Op4Iu5U86IgAAAYk"]
[Thu Jul 30 14:13:10.942753 2026] [security2:error] [pid 1021791:tid 1022003] [client 146.103.115.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuiRhGd_N1Op4Iu5U86DQAAAVw"], referer: https://tereashops.com/wp-admin/edit-tags.php?taxonomy=category
[Thu Jul 30 14:13:11.017353 2026] [security2:error] [pid 1021791:tid 1022039] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amuiRxGd_N1Op4Iu5U86JwAAAYA"]
[Thu Jul 30 14:13:11.044875 2026] [security2:error] [pid 1021791:tid 1021976] [client 144.172.114.51:42828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecre.ae"] [uri "/config/smtp.php"] [unique_id "amuiRxGd_N1Op4Iu5U86KAAAAUE"]
[Thu Jul 30 14:13:11.123193 2026] [core:notice] [pid 1021791:tid 1021986] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:11.456788 2026] [security2:error] [pid 1021791:tid 1021961] [client 20.203.135.57:43671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.135.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xexrecords.online"] [uri "/100.php"] [unique_id "amuiRxGd_N1Op4Iu5U86MgAAATI"]
[Thu Jul 30 14:13:11.456900 2026] [security2:error] [pid 1021791:tid 1021961] [client 20.203.135.57:43671] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.xexrecords.online"] [uri "/100.php"] [unique_id "amuiRxGd_N1Op4Iu5U86MgAAATI"]
[Thu Jul 30 14:13:11.479753 2026] [security2:error] [pid 1021791:tid 1021972] [client 135.119.63.61:33860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cay-van-phong/skibidi.php"] [unique_id "amuiRxGd_N1Op4Iu5U86MwAAAT0"]
[Thu Jul 30 14:13:11.644024 2026] [security2:error] [pid 1021791:tid 1021950] [client 20.171.55.167:8960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/user/themes.php"] [unique_id "amuiRxGd_N1Op4Iu5U86PQAAASc"]
[Thu Jul 30 14:13:11.941264 2026] [core:notice] [pid 1021791:tid 1021943] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:11.946118 2026] [security2:error] [pid 1021791:tid 1021943] [client 66.249.79.1:62886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php/jka"] [unique_id "amuiRxGd_N1Op4Iu5U86QAAAASA"]
[Thu Jul 30 14:13:12.157716 2026] [security2:error] [pid 1021791:tid 1021995] [client 82.102.18.180:43922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuiRxGd_N1Op4Iu5U86RQAAAVQ"]
[Thu Jul 30 14:13:12.262473 2026] [security2:error] [pid 1021791:tid 1021981] [client 135.119.63.61:28028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cbgd.php"] [unique_id "amuiSBGd_N1Op4Iu5U86TQAAAUY"]
[Thu Jul 30 14:13:12.360849 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.171.55.167:8384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/radio.php"] [unique_id "amuiSBGd_N1Op4Iu5U86TgAAARM"]
[Thu Jul 30 14:13:12.545898 2026] [security2:error] [pid 1021791:tid 1022035] [client 144.172.114.51:42838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuiSBGd_N1Op4Iu5U86VgAAAXw"]
[Thu Jul 30 14:13:12.599423 2026] [security2:error] [pid 1021791:tid 1021975] [client 146.103.115.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuiRxGd_N1Op4Iu5U86QQAAAUA"], referer: https://tereashops.com/404/
[Thu Jul 30 14:13:12.617156 2026] [core:notice] [pid 1021791:tid 1022005] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:13.089043 2026] [security2:error] [pid 1021791:tid 1021983] [client 135.119.63.61:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cbrfo.php"] [unique_id "amuiSRGd_N1Op4Iu5U86agAAAUg"]
[Thu Jul 30 14:13:13.094551 2026] [security2:error] [pid 1021791:tid 1022006] [client 20.171.55.167:8995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/license.php"] [unique_id "amuiSRGd_N1Op4Iu5U86bAAAAV8"]
[Thu Jul 30 14:13:13.636730 2026] [core:notice] [pid 1021791:tid 1022034] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:13.640222 2026] [security2:error] [pid 1021791:tid 1022034] [client 135.181.74.155:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/words.html"] [unique_id "amuiSRGd_N1Op4Iu5U86egAAAXs"]
[Thu Jul 30 14:13:13.675326 2026] [security2:error] [pid 1021791:tid 1022027] [client 66.249.73.96:37329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuiSRGd_N1Op4Iu5U86bgAAAXQ"]
[Thu Jul 30 14:13:13.807073 2026] [security2:error] [pid 1021791:tid 1021961] [client 135.119.63.61:5704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cc.php"] [unique_id "amuiSRGd_N1Op4Iu5U86fgAAATI"]
[Thu Jul 30 14:13:13.807497 2026] [security2:error] [pid 1021791:tid 1021923] [client 20.171.55.167:9017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/pki-validation/wp-config.php"] [unique_id "amuiSRGd_N1Op4Iu5U86fwAAAQw"]
[Thu Jul 30 14:13:14.155628 2026] [security2:error] [pid 1021791:tid 1021996] [client 136.158.70.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuiShGd_N1Op4Iu5U86hQAAAVU"], referer: http://cnpinyin.com
[Thu Jul 30 14:13:14.249674 2026] [security2:error] [pid 1021791:tid 1021986] [client 146.103.115.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuiSRGd_N1Op4Iu5U86cQAAAUs"], referer: https://tereashops.com/404/
[Thu Jul 30 14:13:14.344202 2026] [core:notice] [pid 1021791:tid 1021865] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:14.523392 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.171.55.167:9074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/radio.php"] [unique_id "amuiShGd_N1Op4Iu5U86lAAAAYU"]
[Thu Jul 30 14:13:14.606041 2026] [security2:error] [pid 1021791:tid 1021930] [client 135.119.63.61:28031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/ccaef.php"] [unique_id "amuiShGd_N1Op4Iu5U86lgAAARM"]
[Thu Jul 30 14:13:15.233806 2026] [security2:error] [pid 1021791:tid 1022020] [client 20.171.55.167:9058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuiSxGd_N1Op4Iu5U86owAAAW0"]
[Thu Jul 30 14:13:15.477622 2026] [security2:error] [pid 1021791:tid 1021947] [client 135.119.63.61:52962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/ccx/index.php"] [unique_id "amuiSxGd_N1Op4Iu5U86pAAAASQ"]
[Thu Jul 30 14:13:15.879132 2026] [security2:error] [pid 1021791:tid 1021962] [client 146.103.115.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuiShGd_N1Op4Iu5U86mQAAATM"], referer: https://tereashops.com/404/
[Thu Jul 30 14:13:15.969554 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.171.55.167:8977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuiSxGd_N1Op4Iu5U86sQAAAVM"]
[Thu Jul 30 14:13:16.287563 2026] [security2:error] [pid 1021791:tid 1021938] [client 135.119.63.61:52135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cd.php"] [unique_id "amuiTBGd_N1Op4Iu5U86uwAAARs"]
[Thu Jul 30 14:13:16.489477 2026] [security2:error] [pid 1021791:tid 1021969] [client 189.6.88.213:62071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiTBGd_N1Op4Iu5U86vAAAATo"]
[Thu Jul 30 14:13:16.489597 2026] [security2:error] [pid 1021791:tid 1021969] [client 189.6.88.213:62071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiTBGd_N1Op4Iu5U86vAAAATo"]
[Thu Jul 30 14:13:16.687139 2026] [security2:error] [pid 1021791:tid 1021960] [client 20.171.55.167:9076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/wp-login.php"] [unique_id "amuiTBGd_N1Op4Iu5U86yQAAATE"]
[Thu Jul 30 14:13:17.092497 2026] [security2:error] [pid 1021791:tid 1021930] [client 135.119.63.61:6050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cdxadmin.php"] [unique_id "amuiTRGd_N1Op4Iu5U860wAAARM"]
[Thu Jul 30 14:13:17.427674 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.171.55.167:9056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/wp-load.php"] [unique_id "amuiTRGd_N1Op4Iu5U863gAAASI"]
[Thu Jul 30 14:13:17.529711 2026] [security2:error] [pid 1021791:tid 1021965] [client 146.103.115.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuiTBGd_N1Op4Iu5U86xQAAATY"], referer: https://tereashops.com/404/
[Thu Jul 30 14:13:17.724247 2026] [security2:error] [pid 1021791:tid 1021999] [client 50.6.43.217:34016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuiTBGd_N1Op4Iu5U86zQAAAVg"]
[Thu Jul 30 14:13:17.786370 2026] [security2:error] [pid 1021791:tid 1021987] [client 213.152.161.219:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuiTRGd_N1Op4Iu5U867AAAAUw"]
[Thu Jul 30 14:13:17.786497 2026] [security2:error] [pid 1021791:tid 1021987] [client 213.152.161.219:57068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuiTRGd_N1Op4Iu5U867AAAAUw"]
[Thu Jul 30 14:13:17.838841 2026] [security2:error] [pid 1021791:tid 1021989] [client 135.119.63.61:31892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cekidot/alf.php"] [unique_id "amuiTRGd_N1Op4Iu5U867gAAAU4"]
[Thu Jul 30 14:13:18.075470 2026] [security2:error] [pid 1021791:tid 1021990] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuiTRGd_N1Op4Iu5U863QABT10"]
[Thu Jul 30 14:13:18.155716 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.171.55.167:9040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/file.php"] [unique_id "amuiThGd_N1Op4Iu5U869QAAAWA"]
[Thu Jul 30 14:13:18.343752 2026] [security2:error] [pid 1021791:tid 1021985] [client 127.0.0.1:13298] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuiThGd_N1Op4Iu5U87AAAAAUo"]
[Thu Jul 30 14:13:18.343752 2026] [security2:error] [pid 1021791:tid 1021970] [client 127.0.0.1:13290] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.parkingandtransport.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuiThGd_N1Op4Iu5U86_wAAATs"]
[Thu Jul 30 14:13:18.343946 2026] [security2:error] [pid 1021791:tid 1021921] [client 74.7.244.18:47204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.parkingandtransport.com"] [uri "/robots.txt"] [unique_id "amuiThGd_N1Op4Iu5U86_gABCmc"]
[Thu Jul 30 14:13:18.478835 2026] [security2:error] [pid 1021791:tid 1021976] [client 50.6.43.217:34046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuiTRGd_N1Op4Iu5U866AAAAUE"]
[Thu Jul 30 14:13:18.531114 2026] [security2:error] [pid 1021791:tid 1022017] [client 185.247.137.111:41937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuiTRGd_N1Op4Iu5U868AABalw"]
[Thu Jul 30 14:13:18.553188 2026] [core:notice] [pid 1021791:tid 1021978] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:18.556516 2026] [security2:error] [pid 1021791:tid 1021978] [client 135.181.74.155:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/words/1.html"] [unique_id "amuiThGd_N1Op4Iu5U87AQAAAUM"]
[Thu Jul 30 14:13:18.562907 2026] [security2:error] [pid 1021791:tid 1021977] [client 135.119.63.61:6038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cekidot/mar.php"] [unique_id "amuiThGd_N1Op4Iu5U87AgAAAUI"]
[Thu Jul 30 14:13:18.888714 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.171.55.167:9049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/dropdown.php"] [unique_id "amuiThGd_N1Op4Iu5U87EQAAATA"]
[Thu Jul 30 14:13:19.095675 2026] [security2:error] [pid 1021791:tid 1022023] [client 146.103.115.7:60503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tereashops.com"] [uri "/wp-admin/post-new.php"] [unique_id "amuiThGd_N1Op4Iu5U86-gAAAXA"], referer: https://tereashops.com/404/?xoo_el_reg_email=&xoo_el_reg_fname=Lauri&xoo_el_reg_lname=Atkins&xoo_el_reg_pass=&xoo_el_reg_pass_again=&xoo_el_reg_terms=yes&_xoo_el_form=register&xoo_el_redirect=%2F404%2F
[Thu Jul 30 14:13:19.309845 2026] [security2:error] [pid 1021791:tid 1021933] [client 135.119.63.61:31888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cekidot/mr.php"] [unique_id "amuiTxGd_N1Op4Iu5U87GwAAARY"]
[Thu Jul 30 14:13:19.623785 2026] [security2:error] [pid 1021791:tid 1022033] [client 20.171.55.167:9060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/dropdown.php"] [unique_id "amuiTxGd_N1Op4Iu5U87JAAAAXo"]
[Thu Jul 30 14:13:20.002932 2026] [security2:error] [pid 1021791:tid 1022011] [client 135.119.63.61:62761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cepair/doc.php"] [unique_id "amuiUBGd_N1Op4Iu5U87MAAAAWQ"]
[Thu Jul 30 14:13:20.382620 2026] [security2:error] [pid 1021791:tid 1021928] [client 20.171.55.167:8985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuiUBGd_N1Op4Iu5U87RQAAARE"]
[Thu Jul 30 14:13:20.518209 2026] [security2:error] [pid 1021791:tid 1022024] [client 146.103.115.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amuiTxGd_N1Op4Iu5U87IwAAAXE"], referer: https://tereashops.com/wp-admin/post-new.php
[Thu Jul 30 14:13:20.702559 2026] [security2:error] [pid 1021791:tid 1021997] [client 135.119.63.61:62759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/certificates/plugins.php"] [unique_id "amuiUBGd_N1Op4Iu5U87ZQAAAVY"]
[Thu Jul 30 14:13:21.102274 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.171.55.167:9071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-signup.php"] [unique_id "amuiURGd_N1Op4Iu5U87cgAAAYU"]
[Thu Jul 30 14:13:21.183951 2026] [security2:error] [pid 1021791:tid 1021939] [client 74.7.244.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mgr3.com"] [uri "/index.php"] [unique_id "amuiTxGd_N1Op4Iu5U87LwAAARw"]
[Thu Jul 30 14:13:21.400678 2026] [security2:error] [pid 1021791:tid 1022023] [client 135.119.63.61:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cf.php"] [unique_id "amuiURGd_N1Op4Iu5U87gAAAAXA"]
[Thu Jul 30 14:13:21.851938 2026] [security2:error] [pid 1021791:tid 1022003] [client 20.171.55.167:9087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/images/css.php"] [unique_id "amuiURGd_N1Op4Iu5U87jwAAAVw"]
[Thu Jul 30 14:13:22.097332 2026] [security2:error] [pid 1021791:tid 1022028] [client 135.119.63.61:52107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cfile.php"] [unique_id "amuiUhGd_N1Op4Iu5U87mwAAAXU"]
[Thu Jul 30 14:13:22.310485 2026] [core:notice] [pid 1021791:tid 1021958] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:22.570083 2026] [security2:error] [pid 1021791:tid 1021938] [client 20.171.55.167:8973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/chosen.php"] [unique_id "amuiUhGd_N1Op4Iu5U87sQAAARs"]
[Thu Jul 30 14:13:22.801809 2026] [security2:error] [pid 1021791:tid 1022037] [client 135.119.63.61:62723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-binadmin.php"] [unique_id "amuiUhGd_N1Op4Iu5U87uQAAAX4"]
[Thu Jul 30 14:13:22.824787 2026] [security2:error] [pid 1021791:tid 1022014] [client 154.12.24.136:51541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.24.12.154.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/backup01.php"] [unique_id "amuiUhGd_N1Op4Iu5U87ugAAAWc"]
[Thu Jul 30 14:13:23.294236 2026] [core:notice] [pid 1021791:tid 1021947] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:23.298147 2026] [security2:error] [pid 1021791:tid 1021947] [client 135.181.74.155:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/writing-a-save-the-date-email-that-won-t-piss-people-off.html"] [unique_id "amuiUxGd_N1Op4Iu5U87xgAAASQ"]
[Thu Jul 30 14:13:23.325684 2026] [security2:error] [pid 1021791:tid 1022005] [client 20.171.55.167:8389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/cong.php"] [unique_id "amuiUxGd_N1Op4Iu5U87xwAAAV4"]
[Thu Jul 30 14:13:23.506011 2026] [security2:error] [pid 1021791:tid 1021926] [client 135.119.63.61:52103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-binalfa.php"] [unique_id "amuiUxGd_N1Op4Iu5U870gAAAQ8"]
[Thu Jul 30 14:13:23.674032 2026] [security2:error] [pid 1021791:tid 1022030] [client 47.128.119.72:60510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cnpinyin.com"] [uri "/robots.txt"] [unique_id "amuiUxGd_N1Op4Iu5U871gAAAXc"]
[Thu Jul 30 14:13:24.051944 2026] [security2:error] [pid 1021791:tid 1022018] [client 20.171.55.167:9084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/mah.php"] [unique_id "amuiVBGd_N1Op4Iu5U873QAAAWs"]
[Thu Jul 30 14:13:24.196316 2026] [security2:error] [pid 1021791:tid 1021985] [client 135.119.63.61:31907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-binbypass.php"] [unique_id "amuiVBGd_N1Op4Iu5U874QAAAUo"]
[Thu Jul 30 14:13:24.343886 2026] [security2:error] [pid 1021791:tid 1021949] [client 13.203.76.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tranquilrootsisb.space"] [uri "/"] [unique_id "amuiVBGd_N1Op4Iu5U874gAAASY"]
[Thu Jul 30 14:13:24.353571 2026] [security2:error] [pid 1021791:tid 1021988] [client 13.203.76.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tranquilrootsisb.space"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuiVBGd_N1Op4Iu5U874wAAAU0"]
[Thu Jul 30 14:13:24.364688 2026] [security2:error] [pid 1021791:tid 1021994] [client 13.203.76.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tranquilrootsisb.space"] [uri "/media/system/js/core.js"] [unique_id "amuiVBGd_N1Op4Iu5U875AAAAVM"]
[Thu Jul 30 14:13:24.792139 2026] [security2:error] [pid 1021791:tid 1021938] [client 20.171.55.167:9086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuiVBGd_N1Op4Iu5U878QAAARs"]
[Thu Jul 30 14:13:24.878069 2026] [security2:error] [pid 1021791:tid 1022026] [client 135.119.63.61:52128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/cgi-bink.php"] [unique_id "amuiVBGd_N1Op4Iu5U878gAAAXM"]
[Thu Jul 30 14:13:25.510352 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.171.55.167:9065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ova-tools.php"] [unique_id "amuiVRGd_N1Op4Iu5U88AwAAARY"]
[Thu Jul 30 14:13:25.642296 2026] [security2:error] [pid 1021791:tid 1021971] [client 82.102.18.180:24601] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuiVRGd_N1Op4Iu5U87_QAAATw"]
[Thu Jul 30 14:13:25.666719 2026] [core:notice] [pid 1021791:tid 1021964] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:25.669962 2026] [security2:error] [pid 1021791:tid 1021964] [client 135.181.74.155:39880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/yes-love-is-painful.html"] [unique_id "amuiVRGd_N1Op4Iu5U88CgAAATU"]
[Thu Jul 30 14:13:26.109344 2026] [security2:error] [pid 1021791:tid 1022032] [client 82.102.18.180:24601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuiVhGd_N1Op4Iu5U88EAAAAXk"]
[Thu Jul 30 14:13:26.109451 2026] [security2:error] [pid 1021791:tid 1022032] [client 82.102.18.180:24601] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuiVhGd_N1Op4Iu5U88EAAAAXk"]
[Thu Jul 30 14:13:26.563993 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.171.55.167:9043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuiVhGd_N1Op4Iu5U88GAAAAQ8"]
[Thu Jul 30 14:13:27.099025 2026] [security2:error] [pid 1021791:tid 1021982] [client 189.6.88.213:62625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiVxGd_N1Op4Iu5U88JAAAAUc"]
[Thu Jul 30 14:13:27.099128 2026] [security2:error] [pid 1021791:tid 1021982] [client 189.6.88.213:62625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiVxGd_N1Op4Iu5U88JAAAAUc"]
[Thu Jul 30 14:13:27.425692 2026] [security2:error] [pid 1021791:tid 1021956] [client 20.171.55.167:9059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuiVxGd_N1Op4Iu5U88LQAAAS0"]
[Thu Jul 30 14:13:28.050994 2026] [security2:error] [pid 1021791:tid 1021999] [client 212.58.119.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuiVxGd_N1Op4Iu5U88OwAAAVg"], referer: http://cnpinyin.com
[Thu Jul 30 14:13:28.153707 2026] [security2:error] [pid 1021791:tid 1021943] [client 213.152.161.219:50438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuiWBGd_N1Op4Iu5U88QQAAASA"]
[Thu Jul 30 14:13:28.153800 2026] [security2:error] [pid 1021791:tid 1021943] [client 213.152.161.219:50438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuiWBGd_N1Op4Iu5U88QQAAASA"]
[Thu Jul 30 14:13:28.180036 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.171.55.167:9063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuiWBGd_N1Op4Iu5U88RAAAAVA"]
[Thu Jul 30 14:13:28.249786 2026] [security2:error] [pid 1021791:tid 1021972] [client 13.203.76.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/"] [unique_id "amuiWBGd_N1Op4Iu5U88TAAAAT0"]
[Thu Jul 30 14:13:28.260723 2026] [security2:error] [pid 1021791:tid 1022038] [client 13.203.76.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-includes/css/buttons.css"] [unique_id "amuiWBGd_N1Op4Iu5U88TQAAAX8"]
[Thu Jul 30 14:13:28.271566 2026] [security2:error] [pid 1021791:tid 1021934] [client 13.203.76.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/media/system/js/core.js"] [unique_id "amuiWBGd_N1Op4Iu5U88TgAAARc"]
[Thu Jul 30 14:13:28.862327 2026] [fcgid:warn] [pid 1021791:tid 1021994] (70014)End of file found: [client 144.172.114.51:38450] mod_fcgid: can't get data from http client
[Thu Jul 30 14:13:28.890778 2026] [security2:error] [pid 1021791:tid 1022046] [client 20.171.55.167:8997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuiWBGd_N1Op4Iu5U88XwAAAYc"]
[Thu Jul 30 14:13:29.397584 2026] [security2:error] [pid 1021791:tid 1022025] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuiWBGd_N1Op4Iu5U88WgABcmY"]
[Thu Jul 30 14:13:29.662150 2026] [security2:error] [pid 1021791:tid 1021966] [client 20.171.55.167:8971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuiWRGd_N1Op4Iu5U88bwAAATc"]
[Thu Jul 30 14:13:30.389200 2026] [security2:error] [pid 1021791:tid 1022041] [client 20.171.55.167:8969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/license.php"] [unique_id "amuiWhGd_N1Op4Iu5U88gwAAAYI"]
[Thu Jul 30 14:13:30.635261 2026] [core:notice] [pid 1021791:tid 1021998] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:30.990198 2026] [security2:error] [pid 1021791:tid 1021914] [remote 47.128.24.5:53514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-mevius.com"] [uri "/product/marlboro-12/"] [unique_id "amuiWhGd_N1Op4Iu5U88jwABdHo"]
[Thu Jul 30 14:13:31.132020 2026] [security2:error] [pid 1021791:tid 1022034] [client 20.171.55.167:9007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/about.php"] [unique_id "amuiWxGd_N1Op4Iu5U88kQAAAXs"]
[Thu Jul 30 14:13:31.866096 2026] [security2:error] [pid 1021791:tid 1021971] [client 20.171.55.167:8400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/about.php"] [unique_id "amuiWxGd_N1Op4Iu5U88pQAAATw"]
[Thu Jul 30 14:13:32.366405 2026] [security2:error] [pid 1021791:tid 1021959] [client 74.7.244.2:34300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.knpdongmin2215.com"] [uri "/robots.txt"] [unique_id "amuiXBGd_N1Op4Iu5U88rwAAATA"]
[Thu Jul 30 14:13:32.586723 2026] [security2:error] [pid 1021791:tid 1021962] [client 20.171.55.167:8412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuiXBGd_N1Op4Iu5U88twAAATM"]
[Thu Jul 30 14:13:32.924089 2026] [security2:error] [pid 1021791:tid 1022029] [client 144.172.114.51:38436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuiXBGd_N1Op4Iu5U88vgAAAXY"]
[Thu Jul 30 14:13:33.353914 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.171.55.167:8388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuiXRGd_N1Op4Iu5U88yQAAARI"]
[Thu Jul 30 14:13:33.659735 2026] [security2:error] [pid 1021791:tid 1021990] [client 114.119.142.72:45515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/investment-calculator/"] [unique_id "amuiXRGd_N1Op4Iu5U880wAAAU8"], referer: https://alseermarine.com/investor-relations-2/share-graph
[Thu Jul 30 14:13:33.784244 2026] [core:error] [pid 1021791:tid 1022033] [client 74.7.241.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:13:33.784272 2026] [core:error] [pid 1021791:tid 1022033] [client 74.7.241.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:13:33.784431 2026] [security2:error] [pid 1021791:tid 1022033] [client 74.7.241.144:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/index.php"] [unique_id "amuiXRGd_N1Op4Iu5U881gAAAXo"]
[Thu Jul 30 14:13:33.785056 2026] [security2:error] [pid 1021791:tid 1022034] [client 74.7.241.144:40848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/robots.txt"] [unique_id "amuiXRGd_N1Op4Iu5U881AABews"]
[Thu Jul 30 14:13:34.012873 2026] [security2:error] [pid 1021791:tid 1021816] [remote 57.141.0.41:63302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap13.xml"] [unique_id "amuiXhGd_N1Op4Iu5U884wABORg"]
[Thu Jul 30 14:13:34.071302 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.171.55.167:8396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/img/about.php"] [unique_id "amuiXhGd_N1Op4Iu5U885QAAAS8"]
[Thu Jul 30 14:13:34.180096 2026] [security2:error] [pid 1021791:tid 1022035] [client 184.75.221.211:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuiXhGd_N1Op4Iu5U885gAAAXw"]
[Thu Jul 30 14:13:34.180206 2026] [security2:error] [pid 1021791:tid 1022035] [client 184.75.221.211:48726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuiXhGd_N1Op4Iu5U885gAAAXw"]
[Thu Jul 30 14:13:34.830152 2026] [security2:error] [pid 1021791:tid 1022040] [client 20.171.55.167:8436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuiXhGd_N1Op4Iu5U888QAAAYE"]
[Thu Jul 30 14:13:35.479362 2026] [security2:error] [pid 1021791:tid 1022041] [client 114.119.156.225:37121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2022/05/sao-paulo-x-everton-05052022205936805.jpeg"] [unique_id "amuiXxGd_N1Op4Iu5U89AgAAAYI"], referer: https://www.nordeste1.com/2022/05/06/em-jogo-fraco-sao-paulo-empata-sem-gols-com-o-everton-no-chile/
[Thu Jul 30 14:13:35.538122 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.171.55.167:8979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuiXxGd_N1Op4Iu5U89BgAAAYg"]
[Thu Jul 30 14:13:35.898755 2026] [security2:error] [pid 1021791:tid 1022007] [client 184.75.221.211:48736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuiXxGd_N1Op4Iu5U89CwAAAWA"]
[Thu Jul 30 14:13:35.898866 2026] [security2:error] [pid 1021791:tid 1022007] [client 184.75.221.211:48736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuiXxGd_N1Op4Iu5U89CwAAAWA"]
[Thu Jul 30 14:13:36.255821 2026] [security2:error] [pid 1021791:tid 1022033] [client 20.171.55.167:8970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuiYBGd_N1Op4Iu5U89FwAAAXo"]
[Thu Jul 30 14:13:36.499046 2026] [core:notice] [pid 1021791:tid 1021829] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:36.844013 2026] [security2:error] [pid 1021791:tid 1021837] [remote 216.73.217.142:21835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuiYBGd_N1Op4Iu5U89HAABLy0"]
[Thu Jul 30 14:13:36.973509 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.171.55.167:8982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuiYBGd_N1Op4Iu5U89KgAAAUw"]
[Thu Jul 30 14:13:37.377798 2026] [security2:error] [pid 1021791:tid 1021953] [client 144.172.114.51:35578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuiYRGd_N1Op4Iu5U89OQAAASo"]
[Thu Jul 30 14:13:37.667846 2026] [security2:error] [pid 1021791:tid 1021930] [client 189.6.88.213:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiYRGd_N1Op4Iu5U89QQAAARM"]
[Thu Jul 30 14:13:37.667948 2026] [security2:error] [pid 1021791:tid 1021930] [client 189.6.88.213:63254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiYRGd_N1Op4Iu5U89QQAAARM"]
[Thu Jul 30 14:13:37.737666 2026] [security2:error] [pid 1021791:tid 1022005] [client 20.171.55.167:8392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuiYRGd_N1Op4Iu5U89RwAAAV4"]
[Thu Jul 30 14:13:37.944700 2026] [core:notice] [pid 1021791:tid 1021992] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:38.405828 2026] [security2:error] [pid 1021791:tid 1021935] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuiYhGd_N1Op4Iu5U89VAAAARg"]
[Thu Jul 30 14:13:38.405943 2026] [security2:error] [pid 1021791:tid 1021935] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuiYhGd_N1Op4Iu5U89VAAAARg"]
[Thu Jul 30 14:13:38.478195 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.171.55.167:9002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuiYhGd_N1Op4Iu5U89VQAAAQ8"]
[Thu Jul 30 14:13:38.507877 2026] [core:notice] [pid 1021791:tid 1021867] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:38.723056 2026] [security2:error] [pid 1021791:tid 1022024] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuiYhGd_N1Op4Iu5U89XQAAAXE"]
[Thu Jul 30 14:13:38.723158 2026] [security2:error] [pid 1021791:tid 1022024] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuiYhGd_N1Op4Iu5U89XQAAAXE"]
[Thu Jul 30 14:13:39.017893 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuiYxGd_N1Op4Iu5U89ZAAAAUw"]
[Thu Jul 30 14:13:39.018032 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuiYxGd_N1Op4Iu5U89ZAAAAUw"]
[Thu Jul 30 14:13:39.248398 2026] [security2:error] [pid 1021791:tid 1022004] [client 20.171.55.167:8391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuiYxGd_N1Op4Iu5U89awAAAV0"]
[Thu Jul 30 14:13:39.331610 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/err.php"] [unique_id "amuiYxGd_N1Op4Iu5U89bwAAARU"]
[Thu Jul 30 14:13:39.331705 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/err.php"] [unique_id "amuiYxGd_N1Op4Iu5U89bwAAARU"]
[Thu Jul 30 14:13:39.592317 2026] [core:notice] [pid 1021791:tid 1021872] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:39.659474 2026] [security2:error] [pid 1021791:tid 1022043] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/img.php"] [unique_id "amuiYxGd_N1Op4Iu5U89cwAAAYQ"]
[Thu Jul 30 14:13:39.659570 2026] [security2:error] [pid 1021791:tid 1022043] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/img.php"] [unique_id "amuiYxGd_N1Op4Iu5U89cwAAAYQ"]
[Thu Jul 30 14:13:39.977720 2026] [security2:error] [pid 1021791:tid 1021942] [client 20.171.55.167:8408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuiYxGd_N1Op4Iu5U89fAAAAR8"]
[Thu Jul 30 14:13:39.983627 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/aa.php"] [unique_id "amuiYxGd_N1Op4Iu5U89fQAAAVQ"]
[Thu Jul 30 14:13:39.983702 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/aa.php"] [unique_id "amuiYxGd_N1Op4Iu5U89fQAAAVQ"]
[Thu Jul 30 14:13:40.291878 2026] [security2:error] [pid 1021791:tid 1022027] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/av.php"] [unique_id "amuiZBGd_N1Op4Iu5U89hQAAAXQ"]
[Thu Jul 30 14:13:40.292015 2026] [security2:error] [pid 1021791:tid 1022027] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/av.php"] [unique_id "amuiZBGd_N1Op4Iu5U89hQAAAXQ"]
[Thu Jul 30 14:13:40.350704 2026] [core:notice] [pid 1021791:tid 1021877] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:40.588735 2026] [security2:error] [pid 1021791:tid 1022008] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/xa.php"] [unique_id "amuiZBGd_N1Op4Iu5U89igAAAWE"]
[Thu Jul 30 14:13:40.588868 2026] [security2:error] [pid 1021791:tid 1022008] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/xa.php"] [unique_id "amuiZBGd_N1Op4Iu5U89igAAAWE"]
[Thu Jul 30 14:13:40.757101 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.171.55.167:8402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuiZBGd_N1Op4Iu5U89jgAAAUk"]
[Thu Jul 30 14:13:40.898560 2026] [security2:error] [pid 1021791:tid 1021921] [client 185.191.171.6:57216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/02/04/12a-vara-federal-divulga-prestacao-de-contas-de-entidade-cadastrada-em-2020/"] [unique_id "amuiZBGd_N1Op4Iu5U89lQAAAQo"]
[Thu Jul 30 14:13:40.898706 2026] [security2:error] [pid 1021791:tid 1021921] [client 185.191.171.6:57216] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/02/04/12a-vara-federal-divulga-prestacao-de-contas-de-entidade-cadastrada-em-2020/"] [unique_id "amuiZBGd_N1Op4Iu5U89lQAAAQo"]
[Thu Jul 30 14:13:40.899923 2026] [security2:error] [pid 1021791:tid 1021982] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/media.php"] [unique_id "amuiZBGd_N1Op4Iu5U89lgAAAUc"]
[Thu Jul 30 14:13:40.900018 2026] [security2:error] [pid 1021791:tid 1021982] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/media.php"] [unique_id "amuiZBGd_N1Op4Iu5U89lgAAAUc"]
[Thu Jul 30 14:13:41.199520 2026] [security2:error] [pid 1021791:tid 1022045] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/images.php"] [unique_id "amuiZRGd_N1Op4Iu5U89lwAAAYY"]
[Thu Jul 30 14:13:41.199673 2026] [security2:error] [pid 1021791:tid 1022045] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/images.php"] [unique_id "amuiZRGd_N1Op4Iu5U89lwAAAYY"]
[Thu Jul 30 14:13:41.484517 2026] [security2:error] [pid 1021791:tid 1021951] [client 20.171.55.167:8975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuiZRGd_N1Op4Iu5U89oQAAASg"]
[Thu Jul 30 14:13:41.489219 2026] [security2:error] [pid 1021791:tid 1022026] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/gecko.php"] [unique_id "amuiZRGd_N1Op4Iu5U89ogAAAXM"]
[Thu Jul 30 14:13:41.489293 2026] [security2:error] [pid 1021791:tid 1022026] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/gecko.php"] [unique_id "amuiZRGd_N1Op4Iu5U89ogAAAXM"]
[Thu Jul 30 14:13:41.801217 2026] [security2:error] [pid 1021791:tid 1022022] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/82.php"] [unique_id "amuiZRGd_N1Op4Iu5U89qQAAAW8"]
[Thu Jul 30 14:13:41.801321 2026] [security2:error] [pid 1021791:tid 1022022] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/82.php"] [unique_id "amuiZRGd_N1Op4Iu5U89qQAAAW8"]
[Thu Jul 30 14:13:42.076710 2026] [security2:error] [pid 1021791:tid 1022047] [client 114.119.150.64:22997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/soldes-etam-hiver-2016/etam-pull-cachemire-col-v/redaction%40carnetdeshopping.com"] [unique_id "amuiZhGd_N1Op4Iu5U89sAAAAYg"], referer: https://www.carnetdeshopping.com/soldes-etam-hiver-2016/etam-pull-cachemire-col-v/redaction%40carnetdeshopping.com
[Thu Jul 30 14:13:42.111701 2026] [security2:error] [pid 1021791:tid 1022005] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/xstelth.php"] [unique_id "amuiZhGd_N1Op4Iu5U89sQAAAV4"]
[Thu Jul 30 14:13:42.111823 2026] [security2:error] [pid 1021791:tid 1022005] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/xstelth.php"] [unique_id "amuiZhGd_N1Op4Iu5U89sQAAAV4"]
[Thu Jul 30 14:13:42.189796 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.171.55.167:8399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuiZhGd_N1Op4Iu5U89sgAAARM"]
[Thu Jul 30 14:13:42.420525 2026] [security2:error] [pid 1021791:tid 1021936] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/xp.php"] [unique_id "amuiZhGd_N1Op4Iu5U89vAAAARk"]
[Thu Jul 30 14:13:42.420641 2026] [security2:error] [pid 1021791:tid 1021936] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/xp.php"] [unique_id "amuiZhGd_N1Op4Iu5U89vAAAARk"]
[Thu Jul 30 14:13:42.720793 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/admin.php"] [unique_id "amuiZhGd_N1Op4Iu5U89wAAAAUk"]
[Thu Jul 30 14:13:42.720907 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/admin.php"] [unique_id "amuiZhGd_N1Op4Iu5U89wAAAAUk"]
[Thu Jul 30 14:13:42.918705 2026] [security2:error] [pid 1021791:tid 1022028] [client 20.171.55.167:9014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuiZhGd_N1Op4Iu5U89xQAAAXU"]
[Thu Jul 30 14:13:43.017961 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/adminner.php"] [unique_id "amuiZxGd_N1Op4Iu5U89zAAAAVM"]
[Thu Jul 30 14:13:43.018089 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/adminner.php"] [unique_id "amuiZxGd_N1Op4Iu5U89zAAAAVM"]
[Thu Jul 30 14:13:43.313280 2026] [security2:error] [pid 1021791:tid 1022045] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/a.php"] [unique_id "amuiZxGd_N1Op4Iu5U89zQAAAYY"]
[Thu Jul 30 14:13:43.313428 2026] [security2:error] [pid 1021791:tid 1022045] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/a.php"] [unique_id "amuiZxGd_N1Op4Iu5U89zQAAAYY"]
[Thu Jul 30 14:13:43.608092 2026] [security2:error] [pid 1021791:tid 1022040] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/k.php"] [unique_id "amuiZxGd_N1Op4Iu5U891wAAAYE"]
[Thu Jul 30 14:13:43.608213 2026] [security2:error] [pid 1021791:tid 1022040] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/k.php"] [unique_id "amuiZxGd_N1Op4Iu5U891wAAAYE"]
[Thu Jul 30 14:13:43.625245 2026] [security2:error] [pid 1021791:tid 1022035] [client 20.171.55.167:8990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuiZxGd_N1Op4Iu5U892AAAAXw"]
[Thu Jul 30 14:13:43.693253 2026] [core:notice] [pid 1021791:tid 1022021] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:43.921030 2026] [security2:error] [pid 1021791:tid 1021957] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/222.php"] [unique_id "amuiZxGd_N1Op4Iu5U893gAAAS4"]
[Thu Jul 30 14:13:43.921145 2026] [security2:error] [pid 1021791:tid 1021957] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/222.php"] [unique_id "amuiZxGd_N1Op4Iu5U893gAAAS4"]
[Thu Jul 30 14:13:44.208274 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/mac.php"] [unique_id "amuiaBGd_N1Op4Iu5U896AAAATU"]
[Thu Jul 30 14:13:44.208388 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/mac.php"] [unique_id "amuiaBGd_N1Op4Iu5U896AAAATU"]
[Thu Jul 30 14:13:44.798392 2026] [security2:error] [pid 1021791:tid 1021934] [client 20.171.55.167:8966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/images/about.php"] [unique_id "amuiaBGd_N1Op4Iu5U899wAAARc"]
[Thu Jul 30 14:13:45.050560 2026] [security2:error] [pid 1021791:tid 1022032] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "jookreview.com"] [uri "/index.cgi"] [unique_id "amuiaBGd_N1Op4Iu5U898AAAAXk"]
[Thu Jul 30 14:13:45.164191 2026] [core:notice] [pid 1021791:tid 1021921] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:45.300307 2026] [security2:error] [pid 1021791:tid 1021968] [client 212.237.119.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuiaRGd_N1Op4Iu5U8-BgAAATk"], referer: http://cnpinyin.com
[Thu Jul 30 14:13:45.538444 2026] [security2:error] [pid 1021791:tid 1022007] [client 172.237.109.114:23745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuiaBGd_N1Op4Iu5U89-AAAAWA"]
[Thu Jul 30 14:13:45.552356 2026] [security2:error] [pid 1021791:tid 1021946] [client 20.171.55.167:8403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuiaRGd_N1Op4Iu5U8-DgAAASM"]
[Thu Jul 30 14:13:45.757272 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "jookreview.com"] [uri "/index.cgi"] [unique_id "amuiaRGd_N1Op4Iu5U8-BwAAAVM"]
[Thu Jul 30 14:13:45.911720 2026] [security2:error] [pid 1021791:tid 1021951] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/ops.php"] [unique_id "amuiaRGd_N1Op4Iu5U8-FgAAASg"]
[Thu Jul 30 14:13:45.911821 2026] [security2:error] [pid 1021791:tid 1021951] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/ops.php"] [unique_id "amuiaRGd_N1Op4Iu5U8-FgAAASg"]
[Thu Jul 30 14:13:46.209954 2026] [security2:error] [pid 1021791:tid 1022020] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/8.php"] [unique_id "amuiahGd_N1Op4Iu5U8-JAAAAW0"]
[Thu Jul 30 14:13:46.210074 2026] [security2:error] [pid 1021791:tid 1022020] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/8.php"] [unique_id "amuiahGd_N1Op4Iu5U8-JAAAAW0"]
[Thu Jul 30 14:13:46.294347 2026] [security2:error] [pid 1021791:tid 1021970] [client 20.171.55.167:8964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuiahGd_N1Op4Iu5U8-JQAAATs"]
[Thu Jul 30 14:13:46.520593 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/FWAZ.php"] [unique_id "amuiahGd_N1Op4Iu5U8-JwAAARU"]
[Thu Jul 30 14:13:46.520713 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/FWAZ.php"] [unique_id "amuiahGd_N1Op4Iu5U8-JwAAARU"]
[Thu Jul 30 14:13:46.583940 2026] [security2:error] [pid 1021791:tid 1021799] [remote 216.73.217.142:21835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuiahGd_N1Op4Iu5U8-KwABQAc"]
[Thu Jul 30 14:13:46.620464 2026] [core:notice] [pid 1021791:tid 1021797] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:46.686560 2026] [security2:error] [pid 1021791:tid 1021962] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuiahGd_N1Op4Iu5U8-HAAAATM"]
[Thu Jul 30 14:13:46.757098 2026] [core:notice] [pid 1021791:tid 1021937] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:46.761114 2026] [security2:error] [pid 1021791:tid 1021937] [client 135.181.74.155:58544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-are-allowed-to-break-up-with-a-good-guy.html"] [unique_id "amuiahGd_N1Op4Iu5U8-MwAAARo"]
[Thu Jul 30 14:13:47.030890 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.171.55.167:8778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/about.php"] [unique_id "amuiaxGd_N1Op4Iu5U8-NAAAARM"]
[Thu Jul 30 14:13:47.381514 2026] [core:notice] [pid 1021791:tid 1021933] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:47.737785 2026] [security2:error] [pid 1021791:tid 1022033] [client 20.171.55.167:8432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/about.php"] [unique_id "amuiaxGd_N1Op4Iu5U8-TAAAAXo"]
[Thu Jul 30 14:13:47.834618 2026] [security2:error] [pid 1021791:tid 1021963] [client 144.172.114.51:45146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuiaxGd_N1Op4Iu5U8-TgAAATQ"]
[Thu Jul 30 14:13:47.892634 2026] [security2:error] [pid 1021791:tid 1022045] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/biufile.php"] [unique_id "amuiaxGd_N1Op4Iu5U8-TwAAAYY"]
[Thu Jul 30 14:13:47.892786 2026] [security2:error] [pid 1021791:tid 1022045] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/biufile.php"] [unique_id "amuiaxGd_N1Op4Iu5U8-TwAAAYY"]
[Thu Jul 30 14:13:48.204099 2026] [security2:error] [pid 1021791:tid 1021951] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/coffexium.php"] [unique_id "amuibBGd_N1Op4Iu5U8-WgAAASg"]
[Thu Jul 30 14:13:48.204216 2026] [security2:error] [pid 1021791:tid 1021951] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/coffexium.php"] [unique_id "amuibBGd_N1Op4Iu5U8-WgAAASg"]
[Thu Jul 30 14:13:48.313927 2026] [security2:error] [pid 1021791:tid 1021973] [client 189.6.88.213:63866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuibBGd_N1Op4Iu5U8-YQAAAT4"]
[Thu Jul 30 14:13:48.314044 2026] [security2:error] [pid 1021791:tid 1021973] [client 189.6.88.213:63866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuibBGd_N1Op4Iu5U8-YQAAAT4"]
[Thu Jul 30 14:13:48.387639 2026] [security2:error] [pid 1021791:tid 1022031] [client 88.243.155.19:21094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuibBGd_N1Op4Iu5U8-UgAAAXg"], referer: http://pkf.jo
[Thu Jul 30 14:13:48.469464 2026] [security2:error] [pid 1021791:tid 1021927] [client 20.171.55.167:8983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuibBGd_N1Op4Iu5U8-ZAAAARA"]
[Thu Jul 30 14:13:48.509569 2026] [security2:error] [pid 1021791:tid 1021970] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/simple.php"] [unique_id "amuibBGd_N1Op4Iu5U8-ZgAAATs"]
[Thu Jul 30 14:13:48.509671 2026] [security2:error] [pid 1021791:tid 1021970] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/simple.php"] [unique_id "amuibBGd_N1Op4Iu5U8-ZgAAATs"]
[Thu Jul 30 14:13:48.577291 2026] [core:error] [pid 1021791:tid 1021820] (36)File name too long: [remote 185.194.118.111:59264] AH00036: access to /&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;43&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N/A&quot;,&quot;display_price&quot;:199,&quot;display_regular_price&quot;:199,&quot;image&quot;:{&quot;title&quot;:&quot;e2fb19b8-scaled-1.jpg&quot;,&quot;caption&quot;:&quot;&quot;,&quot;url&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/07/e2fb19b8-scaled-1.jpg&quot;,&quot;alt&quot;:&quot;e2fb19b8-scaled-1.jpg&quot;,&quot;src&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/07/e2fb19b8-scaled-1-600x400.jpg&quot;,&quot;srcset&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/07/e2fb19b8-scaled-1-600x400.jpg failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;43&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N'), referer: https://kicksity.com/product/nike-air-jordan-1-low-se-light-steel-grey-2/
[Thu Jul 30 14:13:48.809450 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/fpwch.php"] [unique_id "amuibBGd_N1Op4Iu5U8-bwAAARI"]
[Thu Jul 30 14:13:48.809553 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/fpwch.php"] [unique_id "amuibBGd_N1Op4Iu5U8-bwAAARI"]
[Thu Jul 30 14:13:49.138683 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/dex.php"] [unique_id "amuibRGd_N1Op4Iu5U8-dQAAASE"]
[Thu Jul 30 14:13:49.138791 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/dex.php"] [unique_id "amuibRGd_N1Op4Iu5U8-dQAAASE"]
[Thu Jul 30 14:13:49.181720 2026] [security2:error] [pid 1021791:tid 1021950] [client 20.171.55.167:8431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuibRGd_N1Op4Iu5U8-eAAAASc"]
[Thu Jul 30 14:13:49.235865 2026] [security2:error] [pid 1021791:tid 1022025] [client 94.60.195.215:57644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuiaxGd_N1Op4Iu5U8-UAAAAXI"], referer: http://pkf.jo
[Thu Jul 30 14:13:49.264386 2026] [security2:error] [pid 1021791:tid 1021987] [client 14.191.32.69:25767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuibBGd_N1Op4Iu5U8-VgAAAUw"], referer: http://pkf.jo
[Thu Jul 30 14:13:49.335051 2026] [security2:error] [pid 1021791:tid 1022010] [client 81.4.226.88:46050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuibBGd_N1Op4Iu5U8-WwAAAWM"], referer: http://pkf.jo
[Thu Jul 30 14:13:49.431448 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.91.208.34:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jookreview.com"] [uri "/1.php"] [unique_id "amuibRGd_N1Op4Iu5U8-ggAAAYk"]
[Thu Jul 30 14:13:49.431567 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/1.php"] [unique_id "amuibRGd_N1Op4Iu5U8-ggAAAYk"]
[Thu Jul 30 14:13:49.431656 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/1.php"] [unique_id "amuibRGd_N1Op4Iu5U8-ggAAAYk"]
[Thu Jul 30 14:13:49.450377 2026] [security2:error] [pid 1021791:tid 1021952] [client 213.152.161.181:43440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuibRGd_N1Op4Iu5U8-gwAAASk"]
[Thu Jul 30 14:13:49.450470 2026] [security2:error] [pid 1021791:tid 1021952] [client 213.152.161.181:43440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuibRGd_N1Op4Iu5U8-gwAAASk"]
[Thu Jul 30 14:13:49.914363 2026] [security2:error] [pid 1021791:tid 1021967] [client 79.126.69.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuibRGd_N1Op4Iu5U8-hAABOCE"], referer: https://allmontecristi.com
[Thu Jul 30 14:13:49.940735 2026] [security2:error] [pid 1021791:tid 1022036] [client 20.171.55.167:8798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuibRGd_N1Op4Iu5U8-jwAAAX0"]
[Thu Jul 30 14:13:50.267919 2026] [security2:error] [pid 1021791:tid 1021966] [client 88.225.33.13:39254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuibBGd_N1Op4Iu5U8-YAAAATc"], referer: http://pkf.jo
[Thu Jul 30 14:13:50.647125 2026] [security2:error] [pid 1021791:tid 1021957] [client 20.171.55.167:8423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuibhGd_N1Op4Iu5U8-mgAAAS4"]
[Thu Jul 30 14:13:50.717540 2026] [security2:error] [pid 1021791:tid 1022046] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "jookreview.com"] [uri "/index.cgi"] [unique_id "amuibhGd_N1Op4Iu5U8-kwAAAYc"]
[Thu Jul 30 14:13:50.798616 2026] [security2:error] [pid 1021791:tid 1021973] [client 135.119.63.61:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/compat.php"] [unique_id "amuibhGd_N1Op4Iu5U8-nwAAAT4"]
[Thu Jul 30 14:13:50.882210 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/config.json.php"] [unique_id "amuibhGd_N1Op4Iu5U8-oAAAARw"]
[Thu Jul 30 14:13:50.882322 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/config.json.php"] [unique_id "amuibhGd_N1Op4Iu5U8-oAAAARw"]
[Thu Jul 30 14:13:51.169104 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/k2.php"] [unique_id "amuibxGd_N1Op4Iu5U8-pwAAARI"]
[Thu Jul 30 14:13:51.169214 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/k2.php"] [unique_id "amuibxGd_N1Op4Iu5U8-pwAAARI"]
[Thu Jul 30 14:13:51.300409 2026] [security2:error] [pid 1021791:tid 1022023] [client 223.184.138.155:22874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuibBGd_N1Op4Iu5U8-awAAAXA"], referer: http://pkf.jo
[Thu Jul 30 14:13:51.326510 2026] [security2:error] [pid 1021791:tid 1022016] [client 176.224.164.153:55114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuibBGd_N1Op4Iu5U8-ZQAAAWk"], referer: http://pkf.jo
[Thu Jul 30 14:13:51.389381 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.171.55.167:9013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuibxGd_N1Op4Iu5U8-rgAAAWY"]
[Thu Jul 30 14:13:51.504881 2026] [security2:error] [pid 1021791:tid 1021979] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/raw.php"] [unique_id "amuibxGd_N1Op4Iu5U8-sgAAAUQ"]
[Thu Jul 30 14:13:51.505003 2026] [security2:error] [pid 1021791:tid 1021979] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/raw.php"] [unique_id "amuibxGd_N1Op4Iu5U8-sgAAAUQ"]
[Thu Jul 30 14:13:51.808158 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/wp.php"] [unique_id "amuibxGd_N1Op4Iu5U8-tgAAAUk"]
[Thu Jul 30 14:13:51.808253 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/wp.php"] [unique_id "amuibxGd_N1Op4Iu5U8-tgAAAUk"]
[Thu Jul 30 14:13:51.850211 2026] [security2:error] [pid 1021791:tid 1021934] [client 135.119.63.61:55743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/complianz-gdpr/cookiebanner/admin/admin.php"] [unique_id "amuibxGd_N1Op4Iu5U8-twAAARc"]
[Thu Jul 30 14:13:52.123397 2026] [security2:error] [pid 1021791:tid 1022032] [client 20.171.55.167:8800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuicBGd_N1Op4Iu5U8-vwAAAXk"]
[Thu Jul 30 14:13:52.130330 2026] [security2:error] [pid 1021791:tid 1021946] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/fffm.php"] [unique_id "amuicBGd_N1Op4Iu5U8-wAAAASM"]
[Thu Jul 30 14:13:52.130404 2026] [security2:error] [pid 1021791:tid 1021946] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/fffm.php"] [unique_id "amuicBGd_N1Op4Iu5U8-wAAAASM"]
[Thu Jul 30 14:13:52.214752 2026] [security2:error] [pid 1021791:tid 1022001] [client 184.75.221.211:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuicBGd_N1Op4Iu5U8-wQAAAVo"]
[Thu Jul 30 14:13:52.214891 2026] [security2:error] [pid 1021791:tid 1022001] [client 184.75.221.211:52848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuicBGd_N1Op4Iu5U8-wQAAAVo"]
[Thu Jul 30 14:13:52.224002 2026] [security2:error] [pid 1021791:tid 1022039] [client 212.102.51.91:18815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuibRGd_N1Op4Iu5U8-hQAAAYA"], referer: http://pkf.jo
[Thu Jul 30 14:13:52.226838 2026] [security2:error] [pid 1021791:tid 1021922] [client 167.63.230.107:54766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuibRGd_N1Op4Iu5U8-gQAAAQs"], referer: http://pkf.jo
[Thu Jul 30 14:13:52.257540 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.215.191.139:29714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/--wp-lgj.php"] [unique_id "amuicBGd_N1Op4Iu5U8-wgAAAVQ"]
[Thu Jul 30 14:13:52.288964 2026] [security2:error] [pid 1021791:tid 1021846] [remote 216.73.217.142:64249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuicBGd_N1Op4Iu5U8-xgABcTY"]
[Thu Jul 30 14:13:52.318057 2026] [security2:error] [pid 1021791:tid 1021847] [remote 74.7.227.39:38488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuicBGd_N1Op4Iu5U8-xwABajc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/tiny-compress-images/src
[Thu Jul 30 14:13:52.455068 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/111.php"] [unique_id "amuicBGd_N1Op4Iu5U8-ygAAASU"]
[Thu Jul 30 14:13:52.455183 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/111.php"] [unique_id "amuicBGd_N1Op4Iu5U8-ygAAASU"]
[Thu Jul 30 14:13:52.775568 2026] [security2:error] [pid 1021791:tid 1021997] [client 135.119.63.61:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/componentsadmin.php"] [unique_id "amuicBGd_N1Op4Iu5U8-0QAAAVY"]
[Thu Jul 30 14:13:52.830493 2026] [security2:error] [pid 1021791:tid 1021931] [client 20.171.55.167:9001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuicBGd_N1Op4Iu5U8-1gAAARQ"]
[Thu Jul 30 14:13:53.262226 2026] [security2:error] [pid 1021791:tid 1021955] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "jookreview.com"] [uri "/index.cgi"] [unique_id "amuicBGd_N1Op4Iu5U8-0AAAASw"]
[Thu Jul 30 14:13:53.417749 2026] [security2:error] [pid 1021791:tid 1021940] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/ws.php"] [unique_id "amuicRGd_N1Op4Iu5U8-5QAAAR0"]
[Thu Jul 30 14:13:53.417869 2026] [security2:error] [pid 1021791:tid 1021940] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/ws.php"] [unique_id "amuicRGd_N1Op4Iu5U8-5QAAAR0"]
[Thu Jul 30 14:13:53.537300 2026] [security2:error] [pid 1021791:tid 1022019] [client 20.171.55.167:8992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cloud.php"] [unique_id "amuicRGd_N1Op4Iu5U8-6QAAAWw"]
[Thu Jul 30 14:13:53.723208 2026] [security2:error] [pid 1021791:tid 1021996] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/coffee.php"] [unique_id "amuicRGd_N1Op4Iu5U8-8QAAAVU"]
[Thu Jul 30 14:13:53.723313 2026] [security2:error] [pid 1021791:tid 1021996] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/coffee.php"] [unique_id "amuicRGd_N1Op4Iu5U8-8QAAAVU"]
[Thu Jul 30 14:13:54.036577 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/goods.php"] [unique_id "amuichGd_N1Op4Iu5U8-9QAAAQ8"]
[Thu Jul 30 14:13:54.036686 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/goods.php"] [unique_id "amuichGd_N1Op4Iu5U8-9QAAAQ8"]
[Thu Jul 30 14:13:54.244595 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.171.55.167:8398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuichGd_N1Op4Iu5U8-_AAAAVg"]
[Thu Jul 30 14:13:54.342419 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/about.php"] [unique_id "amuichGd_N1Op4Iu5U8_AAAAAVQ"]
[Thu Jul 30 14:13:54.342525 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/about.php"] [unique_id "amuichGd_N1Op4Iu5U8_AAAAAVQ"]
[Thu Jul 30 14:13:54.636723 2026] [security2:error] [pid 1021791:tid 1021971] [client 135.119.63.61:54039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/componentsalfa.php"] [unique_id "amuichGd_N1Op4Iu5U8_BgAAATw"]
[Thu Jul 30 14:13:54.657543 2026] [security2:error] [pid 1021791:tid 1022035] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/about.php"] [unique_id "amuichGd_N1Op4Iu5U8_CQAAAXw"]
[Thu Jul 30 14:13:54.657649 2026] [security2:error] [pid 1021791:tid 1022035] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/about.php"] [unique_id "amuichGd_N1Op4Iu5U8_CQAAAXw"]
[Thu Jul 30 14:13:54.663497 2026] [security2:error] [pid 1021791:tid 1021938] [client 20.215.191.139:20408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuichGd_N1Op4Iu5U8_CgAAARs"]
[Thu Jul 30 14:13:54.763125 2026] [fcgid:warn] [pid 1021791:tid 1021981] (70014)End of file found: [client 152.32.208.116:37862] mod_fcgid: can't get data from http client
[Thu Jul 30 14:13:54.970280 2026] [security2:error] [pid 1021791:tid 1021931] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/admin.php"] [unique_id "amuichGd_N1Op4Iu5U8_EgAAARQ"]
[Thu Jul 30 14:13:54.970390 2026] [security2:error] [pid 1021791:tid 1021931] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/admin.php"] [unique_id "amuichGd_N1Op4Iu5U8_EgAAARQ"]
[Thu Jul 30 14:13:54.986710 2026] [security2:error] [pid 1021791:tid 1021969] [client 20.171.55.167:8414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/updates.php"] [unique_id "amuichGd_N1Op4Iu5U8_EwAAATo"]
[Thu Jul 30 14:13:55.280845 2026] [security2:error] [pid 1021791:tid 1021947] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/inputs.php"] [unique_id "amuicxGd_N1Op4Iu5U8_GgAAASQ"]
[Thu Jul 30 14:13:55.280995 2026] [security2:error] [pid 1021791:tid 1021947] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/inputs.php"] [unique_id "amuicxGd_N1Op4Iu5U8_GgAAASQ"]
[Thu Jul 30 14:13:55.612953 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/inputs.php"] [unique_id "amuicxGd_N1Op4Iu5U8_IAAAAVc"]
[Thu Jul 30 14:13:55.613107 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/inputs.php"] [unique_id "amuicxGd_N1Op4Iu5U8_IAAAAVc"]
[Thu Jul 30 14:13:55.692380 2026] [security2:error] [pid 1021791:tid 1021942] [client 20.171.55.167:8786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/css/cloud.php"] [unique_id "amuicxGd_N1Op4Iu5U8_JAAAAR8"]
[Thu Jul 30 14:13:55.698010 2026] [security2:error] [pid 1021791:tid 1022042] [client 114.119.132.52:25253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/mostbet-platformas-n-n-tam-i-cmal-yeni-ba-layanl-6436/"] [unique_id "amuicxGd_N1Op4Iu5U8_JQAAAYM"], referer: https://saifalkhaleejest.com/grado-mejorando-casino-jettbet-europa-play-earn/
[Thu Jul 30 14:13:55.763642 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.215.191.139:18898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/flower.php"] [unique_id "amuicxGd_N1Op4Iu5U8_KQAAAVA"]
[Thu Jul 30 14:13:55.904768 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/adminfuns.php"] [unique_id "amuicxGd_N1Op4Iu5U8_LQAAAS8"]
[Thu Jul 30 14:13:55.904912 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/adminfuns.php"] [unique_id "amuicxGd_N1Op4Iu5U8_LQAAAS8"]
[Thu Jul 30 14:13:56.182923 2026] [security2:error] [pid 1021791:tid 1022027] [client 135.119.63.61:12903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/componentsbypass.php"] [unique_id "amuidBGd_N1Op4Iu5U8_MQAAAXQ"]
[Thu Jul 30 14:13:56.208558 2026] [security2:error] [pid 1021791:tid 1022008] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/404.php"] [unique_id "amuidBGd_N1Op4Iu5U8_MwAAAWE"]
[Thu Jul 30 14:13:56.208669 2026] [security2:error] [pid 1021791:tid 1022008] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/404.php"] [unique_id "amuidBGd_N1Op4Iu5U8_MwAAAWE"]
[Thu Jul 30 14:13:56.302690 2026] [security2:error] [pid 1021791:tid 1022009] [client 2803:2d60:110f:5b5:6941:b914:1e08:26cf:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuicxGd_N1Op4Iu5U8_HwABYk8"], referer: https://allmontecristi.com
[Thu Jul 30 14:13:56.413537 2026] [security2:error] [pid 1021791:tid 1021988] [client 144.172.114.51:35974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuidBGd_N1Op4Iu5U8_NgAAAU0"]
[Thu Jul 30 14:13:56.424337 2026] [security2:error] [pid 1021791:tid 1022018] [client 20.171.55.167:8779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuidBGd_N1Op4Iu5U8_OgAAAWs"]
[Thu Jul 30 14:13:56.531143 2026] [security2:error] [pid 1021791:tid 1021952] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/xxx.php"] [unique_id "amuidBGd_N1Op4Iu5U8_OwAAASk"]
[Thu Jul 30 14:13:56.531255 2026] [security2:error] [pid 1021791:tid 1021952] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/xxx.php"] [unique_id "amuidBGd_N1Op4Iu5U8_OwAAASk"]
[Thu Jul 30 14:13:56.589017 2026] [security2:error] [pid 1021791:tid 1021872] [remote 216.73.217.142:64249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuidBGd_N1Op4Iu5U8_PAABXFA"]
[Thu Jul 30 14:13:56.836009 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/classwithtostring.php"] [unique_id "amuidBGd_N1Op4Iu5U8_RAAAAWc"]
[Thu Jul 30 14:13:56.836120 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/classwithtostring.php"] [unique_id "amuidBGd_N1Op4Iu5U8_RAAAAWc"]
[Thu Jul 30 14:13:57.146607 2026] [security2:error] [pid 1021791:tid 1022024] [client 20.171.55.167:8828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/img/cloud.php"] [unique_id "amuidRGd_N1Op4Iu5U8_SwAAAXE"]
[Thu Jul 30 14:13:57.152137 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/234ff.php"] [unique_id "amuidRGd_N1Op4Iu5U8_TAAAASU"]
[Thu Jul 30 14:13:57.152299 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/234ff.php"] [unique_id "amuidRGd_N1Op4Iu5U8_TAAAASU"]
[Thu Jul 30 14:13:57.170482 2026] [security2:error] [pid 1021791:tid 1021949] [client 135.119.63.61:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/componentsk.php"] [unique_id "amuidRGd_N1Op4Iu5U8_TQAAASY"]
[Thu Jul 30 14:13:57.193190 2026] [security2:error] [pid 1021791:tid 1021995] [client 181.199.41.25:41163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuidBGd_N1Op4Iu5U8_RQAAAVQ"], referer: http://pkf.jo
[Thu Jul 30 14:13:57.466036 2026] [security2:error] [pid 1021791:tid 1021970] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/133.php"] [unique_id "amuidRGd_N1Op4Iu5U8_VwAAATs"]
[Thu Jul 30 14:13:57.466134 2026] [security2:error] [pid 1021791:tid 1021970] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/133.php"] [unique_id "amuidRGd_N1Op4Iu5U8_VwAAATs"]
[Thu Jul 30 14:13:57.611239 2026] [core:notice] [pid 1021791:tid 1022012] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:13:57.761481 2026] [security2:error] [pid 1021791:tid 1021877] [remote 114.119.157.108:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/index_php/JIPKL/withdraw"] [unique_id "amuidRGd_N1Op4Iu5U8_XwABWVU"], referer: https://www.jipkl.com/index.php/JIPKL/issue/view/16
[Thu Jul 30 14:13:57.776753 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/wp-ws68.php"] [unique_id "amuidRGd_N1Op4Iu5U8_YAAAATU"]
[Thu Jul 30 14:13:57.776860 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/wp-ws68.php"] [unique_id "amuidRGd_N1Op4Iu5U8_YAAAATU"]
[Thu Jul 30 14:13:57.894001 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.171.55.167:8397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuidRGd_N1Op4Iu5U8_ZAAAAT4"]
[Thu Jul 30 14:13:58.065516 2026] [security2:error] [pid 1021791:tid 1022042] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/mgrr.php"] [unique_id "amuidhGd_N1Op4Iu5U8_aAAAAYM"]
[Thu Jul 30 14:13:58.065631 2026] [security2:error] [pid 1021791:tid 1022042] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/mgrr.php"] [unique_id "amuidhGd_N1Op4Iu5U8_aAAAAYM"]
[Thu Jul 30 14:13:58.095816 2026] [security2:error] [pid 1021791:tid 1021998] [client 135.119.63.61:54028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/componentswp.php"] [unique_id "amuidhGd_N1Op4Iu5U8_aQAAAVc"]
[Thu Jul 30 14:13:58.280274 2026] [security2:error] [pid 1021791:tid 1022040] [client 20.215.191.139:22669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/xleet.php"] [unique_id "amuidhGd_N1Op4Iu5U8_bgAAAYE"]
[Thu Jul 30 14:13:58.366648 2026] [security2:error] [pid 1021791:tid 1021953] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jookreview.com"] [uri "/55.php"] [unique_id "amuidhGd_N1Op4Iu5U8_cgAAASo"]
[Thu Jul 30 14:13:58.366739 2026] [security2:error] [pid 1021791:tid 1021953] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jookreview.com"] [uri "/55.php"] [unique_id "amuidhGd_N1Op4Iu5U8_cgAAASo"]
[Thu Jul 30 14:13:58.617809 2026] [security2:error] [pid 1021791:tid 1022025] [client 20.171.55.167:8808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuidhGd_N1Op4Iu5U8_dgAAAXI"]
[Thu Jul 30 14:13:58.887427 2026] [security2:error] [pid 1021791:tid 1021936] [client 20.215.191.139:18902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuidhGd_N1Op4Iu5U8_fQAAARk"]
[Thu Jul 30 14:13:58.950159 2026] [security2:error] [pid 1021791:tid 1021980] [client 189.6.88.213:64424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuidhGd_N1Op4Iu5U8_fgAAAUU"]
[Thu Jul 30 14:13:58.950265 2026] [security2:error] [pid 1021791:tid 1021980] [client 189.6.88.213:64424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuidhGd_N1Op4Iu5U8_fgAAAUU"]
[Thu Jul 30 14:13:59.285134 2026] [security2:error] [pid 1021791:tid 1022048] [client 135.119.63.61:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/composer.php"] [unique_id "amuidxGd_N1Op4Iu5U8_gwAAAYk"]
[Thu Jul 30 14:13:59.352842 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.171.55.167:8419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/avaa.php"] [unique_id "amuidxGd_N1Op4Iu5U8_iQAAAWA"]
[Thu Jul 30 14:13:59.669273 2026] [security2:error] [pid 1021791:tid 1022037] [client 20.215.191.139:18900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuidxGd_N1Op4Iu5U8_kwAAAX4"]
[Thu Jul 30 14:13:59.709844 2026] [security2:error] [pid 1021791:tid 1021893] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-login.php"] [unique_id "amuidxGd_N1Op4Iu5U8_iwABamU"], referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:13:59.978343 2026] [security2:error] [pid 1021791:tid 1021892] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/blog/wp-login.php"] [unique_id "amuidxGd_N1Op4Iu5U8_mgABJGQ"], referer: https://germanyvisasupportcenterislamabad.website/blog/
[Thu Jul 30 14:14:00.023489 2026] [core:notice] [pid 1021791:tid 1021945] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:00.096088 2026] [security2:error] [pid 1021791:tid 1022012] [client 135.119.63.61:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/con.php"] [unique_id "amuieBGd_N1Op4Iu5U8_nwAAAWU"]
[Thu Jul 30 14:14:00.110361 2026] [security2:error] [pid 1021791:tid 1022046] [client 20.171.55.167:8972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/images/cloud.php"] [unique_id "amuieBGd_N1Op4Iu5U8_oAAAAYc"]
[Thu Jul 30 14:14:00.627395 2026] [security2:error] [pid 1021791:tid 1021905] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wordpress/wp-login.php"] [unique_id "amuieBGd_N1Op4Iu5U8_rwABDnE"], referer: https://germanyvisasupportcenterislamabad.website/wordpress/
[Thu Jul 30 14:14:00.816293 2026] [security2:error] [pid 1021791:tid 1022002] [client 20.215.191.139:25868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuieBGd_N1Op4Iu5U8_sQAAAVs"]
[Thu Jul 30 14:14:00.937025 2026] [security2:error] [pid 1021791:tid 1022038] [client 57.141.0.69:33130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuieBGd_N1Op4Iu5U8_qgABf28"], referer: https://igetvape-australia.com/product/alibarbar-ice-adjust-12000-puffs-blackberry/
[Thu Jul 30 14:14:01.208714 2026] [security2:error] [pid 1021791:tid 1021915] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp/wp-login.php"] [unique_id "amuieRGd_N1Op4Iu5U8_vQABTHs"], referer: https://germanyvisasupportcenterislamabad.website/wp/
[Thu Jul 30 14:14:01.228956 2026] [security2:error] [pid 1021791:tid 1022025] [client 105.107.197.26:35468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuieBGd_N1Op4Iu5U8_tQAAAXI"], referer: http://pkf.jo
[Thu Jul 30 14:14:01.351461 2026] [core:notice] [pid 1021791:tid 1021910] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:01.391124 2026] [security2:error] [pid 1021791:tid 1021946] [client 20.171.55.167:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuieRGd_N1Op4Iu5U8_xQAAASM"]
[Thu Jul 30 14:14:01.483443 2026] [security2:error] [pid 1021791:tid 1021999] [client 114.119.159.6:41845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kingstarenterprises.com"] [uri "/product-category/gym-club-accessories/knee-wraps"] [unique_id "amuieRGd_N1Op4Iu5U8_yQAAAVg"], referer: https://www.kingstarenterprises.com/product-category/gym-club-accessories/knee-wraps?wc_view_mode=list
[Thu Jul 30 14:14:01.493221 2026] [security2:error] [pid 1021791:tid 1022039] [client 20.215.191.139:18891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuieRGd_N1Op4Iu5U8_ygAAAYA"]
[Thu Jul 30 14:14:01.560376 2026] [security2:error] [pid 1021791:tid 1022011] [client 177.226.175.236:11737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuieRGd_N1Op4Iu5U8_vgAAAWQ"], referer: http://pkf.jo
[Thu Jul 30 14:14:01.840591 2026] [security2:error] [pid 1021791:tid 1021913] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/cms/wp-login.php"] [unique_id "amuieRGd_N1Op4Iu5U8_0wABMHk"], referer: https://germanyvisasupportcenterislamabad.website/cms/
[Thu Jul 30 14:14:02.098902 2026] [security2:error] [pid 1021791:tid 1021969] [client 20.171.55.167:9103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuiehGd_N1Op4Iu5U8_2gAAATo"]
[Thu Jul 30 14:14:02.404959 2026] [security2:error] [pid 1021791:tid 1021798] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/site/wp-login.php"] [unique_id "amuiehGd_N1Op4Iu5U8_3gABVwY"], referer: https://germanyvisasupportcenterislamabad.website/site/
[Thu Jul 30 14:14:02.501053 2026] [core:notice] [pid 1021791:tid 1021795] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:02.509956 2026] [security2:error] [pid 1021791:tid 1022042] [client 114.119.156.134:26375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/docs/5cfb7b-portsmouth-kit-20/5cfb7b-weekly-horoscopes"] [unique_id "amuiehGd_N1Op4Iu5U8_5QAAAYM"], referer: https://arabiandubaisafari.com/docs/5cfb7b-portsmouth-kit-20/5cfb7b-weekly-horoscopes
[Thu Jul 30 14:14:02.670351 2026] [security2:error] [pid 1021791:tid 1021792] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/main/wp-login.php"] [unique_id "amuiehGd_N1Op4Iu5U8_6AABKgA"], referer: https://germanyvisasupportcenterislamabad.website/main/
[Thu Jul 30 14:14:02.738652 2026] [security2:error] [pid 1021791:tid 1022022] [client 144.172.114.51:52390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuiehGd_N1Op4Iu5U8_6wAAAW8"]
[Thu Jul 30 14:14:02.838647 2026] [security2:error] [pid 1021791:tid 1021950] [client 20.171.55.167:8967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuiehGd_N1Op4Iu5U8_7AAAASc"]
[Thu Jul 30 14:14:02.898341 2026] [security2:error] [pid 1021791:tid 1021934] [client 114.119.158.112:47571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabian-tours.com"] [uri "/site/les-miserables-%281998-vs-2012%29-56216b"] [unique_id "amuiehGd_N1Op4Iu5U8_7QAAARc"], referer: https://arabian-tours.com/site/badass-female-dragon-names-56216b
[Thu Jul 30 14:14:02.931361 2026] [security2:error] [pid 1021791:tid 1021809] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/new/wp-login.php"] [unique_id "amuiehGd_N1Op4Iu5U8_7wABRBE"], referer: https://germanyvisasupportcenterislamabad.website/new/
[Thu Jul 30 14:14:03.180281 2026] [core:notice] [pid 1021791:tid 1021813] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:03.237592 2026] [security2:error] [pid 1021791:tid 1021808] [remote 57.141.0.17:64032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/485177242/feed/rss2/"] [unique_id "amuiexGd_N1Op4Iu5U8_-gABeBA"]
[Thu Jul 30 14:14:03.273418 2026] [security2:error] [pid 1021791:tid 1022028] [client 135.119.63.61:55711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/con7.php"] [unique_id "amuiexGd_N1Op4Iu5U8_-wAAAXU"]
[Thu Jul 30 14:14:03.296349 2026] [security2:error] [pid 1021791:tid 1021922] [client 114.119.143.11:31625] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiantourz.com"] [uri "/etiquette-produit/petit-bateau/"] [unique_id "amuiexGd_N1Op4Iu5U8__AAAAQs"], referer: https://www.arabiantourz.com/soldes/femme-petit-bateau-filou-noir-t-shirts-polos/
[Thu Jul 30 14:14:03.312080 2026] [security2:error] [pid 1021791:tid 1021946] [client 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-login.php"] [unique_id "amuiexGd_N1Op4Iu5U8__QAAASM"], referer: http://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:03.460559 2026] [proxy:error] [pid 1021791:tid 1022014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:03.460657 2026] [proxy_http:error] [pid 1021791:tid 1022014] [client 193.47.62.167:46846] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:03.461231 2026] [proxy:error] [pid 1021791:tid 1022014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:03.461278 2026] [proxy_http:error] [pid 1021791:tid 1022014] [client 193.47.62.167:46846] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:03.559714 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.171.55.167:9089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuiexGd_N1Op4Iu5U9AAgAAAWY"]
[Thu Jul 30 14:14:03.704513 2026] [security2:error] [pid 1021791:tid 1021923] [client 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/blog/wp-login.php"] [unique_id "amuiexGd_N1Op4Iu5U9ABwAAAQw"], referer: http://germanyvisasupportcenterislamabad.website/blog/
[Thu Jul 30 14:14:03.935060 2026] [core:error] [pid 1021791:tid 1021945] [client 20.215.191.139:18880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:14:03.935084 2026] [core:error] [pid 1021791:tid 1021945] [client 20.215.191.139:18880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:14:04.077885 2026] [security2:error] [pid 1021791:tid 1021970] [client 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wordpress/wp-login.php"] [unique_id "amuifBGd_N1Op4Iu5U9AEAAAATs"], referer: http://germanyvisasupportcenterislamabad.website/wordpress/
[Thu Jul 30 14:14:04.279297 2026] [security2:error] [pid 1021791:tid 1022017] [client 20.171.55.167:9106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuifBGd_N1Op4Iu5U9AFwAAAWo"]
[Thu Jul 30 14:14:04.342575 2026] [security2:error] [pid 1021791:tid 1021931] [client 135.119.63.61:12890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/con7ext.php"] [unique_id "amuifBGd_N1Op4Iu5U9AGAAAARQ"]
[Thu Jul 30 14:14:04.481782 2026] [security2:error] [pid 1021791:tid 1022046] [client 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp/wp-login.php"] [unique_id "amuifBGd_N1Op4Iu5U9AGQAAAYc"], referer: http://germanyvisasupportcenterislamabad.website/wp/
[Thu Jul 30 14:14:04.885346 2026] [security2:error] [pid 1021791:tid 1022041] [client 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/cms/wp-login.php"] [unique_id "amuifBGd_N1Op4Iu5U9AIwAAAYI"], referer: http://germanyvisasupportcenterislamabad.website/cms/
[Thu Jul 30 14:14:04.993954 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.171.55.167:8981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuifBGd_N1Op4Iu5U9AJAAAASA"]
[Thu Jul 30 14:14:05.219176 2026] [core:notice] [pid 1021791:tid 1022022] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:05.222885 2026] [security2:error] [pid 1021791:tid 1022022] [client 135.181.74.155:48188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-are-allowed-to-cut-toxic-people-out-of-your-life.html"] [unique_id "amuifRGd_N1Op4Iu5U9AKwAAAW8"]
[Thu Jul 30 14:14:05.240780 2026] [security2:error] [pid 1021791:tid 1021833] [remote 74.7.243.224:52384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amuifRGd_N1Op4Iu5U9ALAABDik"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:14:05.280711 2026] [security2:error] [pid 1021791:tid 1022026] [client 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/site/wp-login.php"] [unique_id "amuifRGd_N1Op4Iu5U9ALgAAAXM"], referer: http://germanyvisasupportcenterislamabad.website/site/
[Thu Jul 30 14:14:05.298793 2026] [security2:error] [pid 1021791:tid 1021993] [client 20.215.191.139:18895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuifRGd_N1Op4Iu5U9AMQAAAVI"]
[Thu Jul 30 14:14:05.640131 2026] [security2:error] [pid 1021791:tid 1022038] [client 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/main/wp-login.php"] [unique_id "amuifRGd_N1Op4Iu5U9AQQAAAX8"], referer: http://germanyvisasupportcenterislamabad.website/main/
[Thu Jul 30 14:14:05.660847 2026] [security2:error] [pid 1021791:tid 1022025] [client 135.119.63.61:55729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/conf1g.php"] [unique_id "amuifRGd_N1Op4Iu5U9AQgAAAXI"]
[Thu Jul 30 14:14:05.705378 2026] [security2:error] [pid 1021791:tid 1021946] [client 20.171.55.167:9140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/updates.php"] [unique_id "amuifRGd_N1Op4Iu5U9AQwAAASM"]
[Thu Jul 30 14:14:06.013291 2026] [security2:error] [pid 1021791:tid 1021961] [client 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/new/wp-login.php"] [unique_id "amuifhGd_N1Op4Iu5U9ARwAAATI"], referer: http://germanyvisasupportcenterislamabad.website/new/
[Thu Jul 30 14:14:06.442910 2026] [security2:error] [pid 1021791:tid 1021974] [client 20.171.55.167:9118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuifhGd_N1Op4Iu5U9AUQAAAT8"]
[Thu Jul 30 14:14:06.498017 2026] [security2:error] [pid 1021791:tid 1021985] [client 135.119.63.61:12906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/config.bak.php"] [unique_id "amuifhGd_N1Op4Iu5U9AUgAAAUo"]
[Thu Jul 30 14:14:06.927337 2026] [core:error] [pid 1021791:tid 1021840] [remote 93.123.109.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:06.927374 2026] [core:error] [pid 1021791:tid 1021840] [remote 93.123.109.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:06.989182 2026] [security2:error] [pid 1021791:tid 1021923] [client 20.215.191.139:29734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuifhGd_N1Op4Iu5U9AYgAAAQw"]
[Thu Jul 30 14:14:07.148664 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.171.55.167:9136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuifxGd_N1Op4Iu5U9AZgAAAVA"]
[Thu Jul 30 14:14:07.348748 2026] [security2:error] [pid 1021791:tid 1022008] [client 135.119.63.61:12925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/config.php"] [unique_id "amuifxGd_N1Op4Iu5U9AawAAAWE"]
[Thu Jul 30 14:14:07.460817 2026] [security2:error] [pid 1021791:tid 1021845] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-login.php"] [unique_id "amuifxGd_N1Op4Iu5U9AbwABTDU"], referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:07.611337 2026] [security2:error] [pid 1021791:tid 1021968] [client 144.172.114.51:52402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuifxGd_N1Op4Iu5U9AcgAAATk"]
[Thu Jul 30 14:14:07.845041 2026] [security2:error] [pid 1021791:tid 1021952] [client 20.215.191.139:20762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuifxGd_N1Op4Iu5U9AeQAAASk"]
[Thu Jul 30 14:14:07.858115 2026] [security2:error] [pid 1021791:tid 1022003] [client 20.171.55.167:9126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuifxGd_N1Op4Iu5U9AegAAAVw"]
[Thu Jul 30 14:14:08.238843 2026] [security2:error] [pid 1021791:tid 1022038] [client 135.119.63.61:12920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/configadmin.php"] [unique_id "amuigBGd_N1Op4Iu5U9AhgAAAX8"]
[Thu Jul 30 14:14:08.517075 2026] [core:notice] [pid 1021791:tid 1021959] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:08.521700 2026] [security2:error] [pid 1021791:tid 1021959] [client 135.181.74.155:48188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-are-allowed-to-sit-back-and-relax.html"] [unique_id "amuigBGd_N1Op4Iu5U9AiwAAATA"]
[Thu Jul 30 14:14:08.582418 2026] [security2:error] [pid 1021791:tid 1021954] [client 20.171.55.167:9098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/alfa-rex.php7"] [unique_id "amuigBGd_N1Op4Iu5U9AjwAAASs"]
[Thu Jul 30 14:14:09.091408 2026] [security2:error] [pid 1021791:tid 1021941] [client 135.119.63.61:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/configalfa.php"] [unique_id "amuigRGd_N1Op4Iu5U9AnAAAAR4"]
[Thu Jul 30 14:14:09.309771 2026] [security2:error] [pid 1021791:tid 1022042] [client 20.171.55.167:8446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/alfanew.php"] [unique_id "amuigRGd_N1Op4Iu5U9ApQAAAYM"]
[Thu Jul 30 14:14:09.364099 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.215.191.139:29361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuigRGd_N1Op4Iu5U9AqQAAARw"]
[Thu Jul 30 14:14:09.401841 2026] [core:error] [pid 1021791:tid 1021869] [remote 93.123.109.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:09.401862 2026] [core:error] [pid 1021791:tid 1021869] [remote 93.123.109.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:09.546994 2026] [security2:error] [pid 1021791:tid 1021953] [client 189.6.88.213:64989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuigRGd_N1Op4Iu5U9ArQAAASo"]
[Thu Jul 30 14:14:09.547116 2026] [security2:error] [pid 1021791:tid 1021953] [client 189.6.88.213:64989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuigRGd_N1Op4Iu5U9ArQAAASo"]
[Thu Jul 30 14:14:09.578243 2026] [core:notice] [pid 1021791:tid 1021871] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:10.031713 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.171.55.167:9111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuighGd_N1Op4Iu5U9AwQAAAUI"]
[Thu Jul 30 14:14:10.139787 2026] [security2:error] [pid 1021791:tid 1022018] [client 179.43.134.114:37016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kbsgg.click"] [uri "/wp-login.php"] [unique_id "amuigRGd_N1Op4Iu5U9AswAAAWs"]
[Thu Jul 30 14:14:10.154026 2026] [security2:error] [pid 1021791:tid 1022014] [client 135.119.63.61:12864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/configbypass.php"] [unique_id "amuighGd_N1Op4Iu5U9AxwAAAWc"]
[Thu Jul 30 14:14:10.191661 2026] [security2:error] [pid 1021791:tid 1021982] [client 20.215.191.139:29314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuighGd_N1Op4Iu5U9AygAAAUc"]
[Thu Jul 30 14:14:10.770740 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.171.55.167:9107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuighGd_N1Op4Iu5U9A1gAAAVc"]
[Thu Jul 30 14:14:10.771588 2026] [core:error] [pid 1021791:tid 1021890] [remote 93.123.109.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:10.771606 2026] [core:error] [pid 1021791:tid 1021890] [remote 93.123.109.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:10.987705 2026] [core:error] [pid 1021791:tid 1021895] [remote 93.123.109.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:10.987732 2026] [core:error] [pid 1021791:tid 1021895] [remote 93.123.109.166:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:11.050672 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.215.191.139:29644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuigxGd_N1Op4Iu5U9A4AAAAYg"]
[Thu Jul 30 14:14:11.329723 2026] [security2:error] [pid 1021791:tid 1022043] [client 114.119.156.165:40967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/4/"] [unique_id "amuigxGd_N1Op4Iu5U9A5wAAAYQ"], referer: https://kicksity.com/shop/?filtering=1&filter_product_cat=254%2C201%2C217%2C144
[Thu Jul 30 14:14:11.357162 2026] [core:notice] [pid 1021791:tid 1021933] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:11.361680 2026] [security2:error] [pid 1021791:tid 1021933] [client 135.181.74.155:48188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-are-everything-i-want.html"] [unique_id "amuigxGd_N1Op4Iu5U9A6AAAARY"]
[Thu Jul 30 14:14:11.374805 2026] [security2:error] [pid 1021791:tid 1021991] [client 135.119.63.61:55738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/configk.php"] [unique_id "amuigxGd_N1Op4Iu5U9A6gAAAVA"]
[Thu Jul 30 14:14:11.476744 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.171.55.167:9094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-p.php7"] [unique_id "amuigxGd_N1Op4Iu5U9A7gAAAQ8"]
[Thu Jul 30 14:14:11.907740 2026] [security2:error] [pid 1021791:tid 1021884] [remote 93.123.109.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index.php"] [unique_id "amuigxGd_N1Op4Iu5U9A9wABWlw"], referer: https://germanyvisasupportcenterislamabad.website/
[Thu Jul 30 14:14:12.042762 2026] [security2:error] [pid 1021791:tid 1022034] [client 144.172.114.51:48394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuihBGd_N1Op4Iu5U9A_wAAAXs"]
[Thu Jul 30 14:14:12.206923 2026] [security2:error] [pid 1021791:tid 1021949] [client 20.171.55.167:9133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuihBGd_N1Op4Iu5U9BAwAAASY"]
[Thu Jul 30 14:14:12.703941 2026] [security2:error] [pid 1021791:tid 1021938] [client 20.215.191.139:20764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuihBGd_N1Op4Iu5U9BEAAAARs"]
[Thu Jul 30 14:14:12.722448 2026] [security2:error] [pid 1021791:tid 1022006] [client 135.119.63.61:54037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/configure.php"] [unique_id "amuihBGd_N1Op4Iu5U9BEQAAAV8"]
[Thu Jul 30 14:14:12.897168 2026] [proxy:error] [pid 1021791:tid 1021931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:12.897255 2026] [proxy_http:error] [pid 1021791:tid 1021931] [client 18.211.55.47:53123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:12.898077 2026] [proxy:error] [pid 1021791:tid 1021931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:12.898145 2026] [proxy_http:error] [pid 1021791:tid 1021931] [client 18.211.55.47:53123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:12.940207 2026] [proxy:error] [pid 1021791:tid 1021975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:12.940281 2026] [proxy_http:error] [pid 1021791:tid 1021975] [client 44.216.125.112:1055] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:12.940867 2026] [proxy:error] [pid 1021791:tid 1021975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:12.940917 2026] [proxy_http:error] [pid 1021791:tid 1021975] [client 44.216.125.112:1055] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:13.072431 2026] [security2:error] [pid 1021791:tid 1021985] [client 172.202.44.182:41254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wk/index.php"] [unique_id "amuihRGd_N1Op4Iu5U9BJAAAAUo"]
[Thu Jul 30 14:14:13.288671 2026] [security2:error] [pid 1021791:tid 1021943] [client 74.7.228.0:48476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ghj.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuihRGd_N1Op4Iu5U9BKQAAASA"]
[Thu Jul 30 14:14:13.433600 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.215.191.139:20744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuihRGd_N1Op4Iu5U9BLQAAARw"]
[Thu Jul 30 14:14:13.475502 2026] [security2:error] [pid 1021791:tid 1021940] [client 20.171.55.167:9146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuihRGd_N1Op4Iu5U9BLgAAAR0"]
[Thu Jul 30 14:14:13.997228 2026] [security2:error] [pid 1021791:tid 1021921] [client 135.119.63.61:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/configwp.php"] [unique_id "amuihRGd_N1Op4Iu5U9BOgAAAQo"]
[Thu Jul 30 14:14:14.208697 2026] [security2:error] [pid 1021791:tid 1021971] [client 20.171.55.167:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/repeater.php"] [unique_id "amuihhGd_N1Op4Iu5U9BRAAAATw"]
[Thu Jul 30 14:14:14.333155 2026] [core:notice] [pid 1021791:tid 1022018] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:14.336515 2026] [security2:error] [pid 1021791:tid 1022018] [client 135.181.74.155:48188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-are-my-breath-of-fresh-air.html"] [unique_id "amuihhGd_N1Op4Iu5U9BRQAAAWs"]
[Thu Jul 30 14:14:14.451333 2026] [security2:error] [pid 1021791:tid 1022031] [client 169.224.68.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuihRGd_N1Op4Iu5U9BNQABeG0"], referer: https://allmontecristi.com
[Thu Jul 30 14:14:14.827092 2026] [security2:error] [pid 1021791:tid 1021972] [client 135.119.63.61:55701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/cong.php"] [unique_id "amuihhGd_N1Op4Iu5U9BUQAAAT0"]
[Thu Jul 30 14:14:14.921157 2026] [security2:error] [pid 1021791:tid 1021941] [client 20.171.55.167:8286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wsoyanz.php"] [unique_id "amuihhGd_N1Op4Iu5U9BVQAAAR4"]
[Thu Jul 30 14:14:15.481392 2026] [security2:error] [pid 1021791:tid 1022006] [client 20.215.191.139:20778] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bisbeetour.com"] [uri "/1.php"] [unique_id "amuihxGd_N1Op4Iu5U9BXwAAAV8"]
[Thu Jul 30 14:14:15.481493 2026] [security2:error] [pid 1021791:tid 1022006] [client 20.215.191.139:20778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/1.php"] [unique_id "amuihxGd_N1Op4Iu5U9BXwAAAV8"]
[Thu Jul 30 14:14:15.529181 2026] [core:notice] [pid 1021791:tid 1021808] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:15.579005 2026] [security2:error] [pid 1021791:tid 1021929] [client 172.202.44.182:22340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/av.php"] [unique_id "amuihxGd_N1Op4Iu5U9BYQAAARI"]
[Thu Jul 30 14:14:15.658519 2026] [security2:error] [pid 1021791:tid 1021936] [client 20.171.55.167:8406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/yanz.php"] [unique_id "amuihxGd_N1Op4Iu5U9BYgAAARk"]
[Thu Jul 30 14:14:15.692472 2026] [security2:error] [pid 1021791:tid 1022039] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/index.php"] [unique_id "amuihxGd_N1Op4Iu5U9BZwAAAYA"]
[Thu Jul 30 14:14:15.692851 2026] [security2:error] [pid 1021791:tid 1021921] [client 82.102.18.180:52652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/wp-content/plugins/"] [unique_id "amuihxGd_N1Op4Iu5U9BZAAAAQo"]
[Thu Jul 30 14:14:15.717465 2026] [security2:error] [pid 1021791:tid 1021967] [client 135.119.63.61:55714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/conn.php"] [unique_id "amuihxGd_N1Op4Iu5U9BaQAAATg"]
[Thu Jul 30 14:14:16.205234 2026] [security2:error] [pid 1021791:tid 1021945] [client 82.102.18.180:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuiiBGd_N1Op4Iu5U9BdgAAASI"]
[Thu Jul 30 14:14:16.205661 2026] [security2:error] [pid 1021791:tid 1021964] [client 82.102.18.180:52652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "safaratraveltours.com"] [uri "/wp-content/themes/"] [unique_id "amuiiBGd_N1Op4Iu5U9BdAAAATU"]
[Thu Jul 30 14:14:16.378413 2026] [security2:error] [pid 1021791:tid 1021947] [client 20.171.55.167:9018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "amuiiBGd_N1Op4Iu5U9BfQAAASQ"]
[Thu Jul 30 14:14:16.445818 2026] [autoindex:error] [pid 1021791:tid 1022046] [client 82.102.18.180:52652] AH01276: Cannot serve directory /home2/xsygzjte/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:14:16.446648 2026] [security2:error] [pid 1021791:tid 1022046] [client 82.102.18.180:52652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "safaratraveltours.com"] [uri "/cgi-sys/403.html"] [unique_id "amuiiBGd_N1Op4Iu5U9BfgAAAYc"]
[Thu Jul 30 14:14:16.585050 2026] [core:notice] [pid 1021791:tid 1021815] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:16.667883 2026] [security2:error] [pid 1021791:tid 1021989] [client 114.119.139.183:46093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuiiBGd_N1Op4Iu5U9BhAAAAU4"], referer: https://www.toscanamall.com/fr?remove_item=fc2c7c47b918d0c2d792a719dfb602ef
[Thu Jul 30 14:14:16.893586 2026] [security2:error] [pid 1021791:tid 1021965] [client 135.119.63.61:55707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/connector.php"] [unique_id "amuiiBGd_N1Op4Iu5U9BjAAAATY"]
[Thu Jul 30 14:14:17.029825 2026] [security2:error] [pid 1021791:tid 1021950] [client 82.102.18.180:52652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/wp-admin/index.php"] [unique_id "amuiiBGd_N1Op4Iu5U9BiwAAASc"]
[Thu Jul 30 14:14:17.085811 2026] [security2:error] [pid 1021791:tid 1022041] [client 20.171.55.167:9125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "amuiiRGd_N1Op4Iu5U9BkQAAAYI"]
[Thu Jul 30 14:14:17.118181 2026] [security2:error] [pid 1021791:tid 1021983] [client 20.215.191.139:22662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/admin.php"] [unique_id "amuiiRGd_N1Op4Iu5U9BkgAAAUg"]
[Thu Jul 30 14:14:17.394326 2026] [security2:error] [pid 1021791:tid 1022012] [client 172.202.44.182:22377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/mini.php"] [unique_id "amuiiRGd_N1Op4Iu5U9BnAAAAWU"]
[Thu Jul 30 14:14:17.771400 2026] [core:notice] [pid 1021791:tid 1021991] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:17.820144 2026] [security2:error] [pid 1021791:tid 1021968] [client 20.171.55.167:9131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cache-compat.php"] [unique_id "amuiiRGd_N1Op4Iu5U9BpwAAATk"]
[Thu Jul 30 14:14:17.863467 2026] [security2:error] [pid 1021791:tid 1022011] [client 135.119.63.61:54023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "amuiiRGd_N1Op4Iu5U9BqAAAAWQ"]
[Thu Jul 30 14:14:18.075485 2026] [security2:error] [pid 1021791:tid 1021982] [client 20.215.191.139:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/as.php"] [unique_id "amuiihGd_N1Op4Iu5U9BqwAAAUc"]
[Thu Jul 30 14:14:18.299039 2026] [security2:error] [pid 1021791:tid 1021997] [client 144.172.114.51:48400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuiihGd_N1Op4Iu5U9BsAAAAVY"]
[Thu Jul 30 14:14:18.531632 2026] [security2:error] [pid 1021791:tid 1022015] [client 172.213.208.20:40438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuiihGd_N1Op4Iu5U9BtgAAAWg"]
[Thu Jul 30 14:14:18.578671 2026] [security2:error] [pid 1021791:tid 1021938] [client 20.171.55.167:9116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ajax-actions.php"] [unique_id "amuiihGd_N1Op4Iu5U9BugAAARs"]
[Thu Jul 30 14:14:18.689347 2026] [security2:error] [pid 1021791:tid 1021931] [client 20.215.191.139:20799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/autoload_classmap.php"] [unique_id "amuiihGd_N1Op4Iu5U9BuwAAARQ"]
[Thu Jul 30 14:14:19.123919 2026] [security2:error] [pid 1021791:tid 1022046] [client 135.119.63.61:54049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/contact.php"] [unique_id "amuiixGd_N1Op4Iu5U9BxQAAAYc"]
[Thu Jul 30 14:14:19.265375 2026] [security2:error] [pid 1021791:tid 1021984] [client 172.213.208.20:34275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/m.php"] [unique_id "amuiixGd_N1Op4Iu5U9BxgAAAUk"]
[Thu Jul 30 14:14:19.291157 2026] [security2:error] [pid 1021791:tid 1022042] [client 20.171.55.167:9141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/ajax-actions.php"] [unique_id "amuiixGd_N1Op4Iu5U9BxwAAAYM"]
[Thu Jul 30 14:14:19.666075 2026] [security2:error] [pid 1021791:tid 1021925] [client 114.119.155.115:40045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/our-people/mr-ehsan-damen"] [unique_id "amuiixGd_N1Op4Iu5U9B0gAAAQ4"], referer: https://pkf.jo/our-people/mr-ehsan-damen
[Thu Jul 30 14:14:19.676125 2026] [security2:error] [pid 1021791:tid 1022026] [client 20.215.191.139:24253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/back.php"] [unique_id "amuiixGd_N1Op4Iu5U9B1QAAAXM"]
[Thu Jul 30 14:14:19.859957 2026] [security2:error] [pid 1021791:tid 1021993] [client 135.119.63.61:55709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/contacts.php"] [unique_id "amuiixGd_N1Op4Iu5U9B2QAAAVI"]
[Thu Jul 30 14:14:20.023315 2026] [security2:error] [pid 1021791:tid 1021953] [client 20.171.55.167:9008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-consar.php"] [unique_id "amuijBGd_N1Op4Iu5U9B3wAAASo"]
[Thu Jul 30 14:14:20.194679 2026] [security2:error] [pid 1021791:tid 1022028] [client 189.6.88.213:49154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuijBGd_N1Op4Iu5U9B5wAAAXU"]
[Thu Jul 30 14:14:20.194783 2026] [security2:error] [pid 1021791:tid 1022028] [client 189.6.88.213:49154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuijBGd_N1Op4Iu5U9B5wAAAXU"]
[Thu Jul 30 14:14:20.321325 2026] [security2:error] [pid 1021791:tid 1021987] [client 187.187.228.156:35196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuiixGd_N1Op4Iu5U9B3gAAAUw"], referer: http://pkf.jo
[Thu Jul 30 14:14:20.552423 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.215.191.139:28362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuijBGd_N1Op4Iu5U9B7wAAAUI"]
[Thu Jul 30 14:14:20.562559 2026] [security2:error] [pid 1021791:tid 1022011] [client 172.202.44.182:8341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/aa.php"] [unique_id "amuijBGd_N1Op4Iu5U9B8wAAAWQ"]
[Thu Jul 30 14:14:20.744724 2026] [security2:error] [pid 1021791:tid 1021927] [client 20.171.55.167:9143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/repeater.php"] [unique_id "amuijBGd_N1Op4Iu5U9B_AAAARA"]
[Thu Jul 30 14:14:20.818658 2026] [security2:error] [pid 1021791:tid 1022016] [client 41.36.235.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuijBGd_N1Op4Iu5U9B-gAAAWk"], referer: https://cnpinyin.com
[Thu Jul 30 14:14:21.206272 2026] [security2:error] [pid 1021791:tid 1022022] [client 172.213.208.20:40389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuijBGd_N1Op4Iu5U9CBAAAAW8"]
[Thu Jul 30 14:14:21.421854 2026] [security2:error] [pid 1021791:tid 1021965] [client 114.119.158.113:37991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product-tag/hope-%e5%b8%8c%e6%9c%9b%e9%a6%99%e7%85%99%e8%96%84%e8%8d%b78mg%e6%97%a5%e6%9c%ac%e6%9c%ac%e5%9c%9f%e5%85%8d%e7%a8%85%e9%a6%99%e6%b8%af%e7%8f%be%e8%b2%a8"] [unique_id "amuijRGd_N1Op4Iu5U9CDAAAATY"], referer: https://online-hope.com/product-tag/hope-%e5%b8%8c%e6%9c%9b%e9%a6%99%e7%85%99%e8%96%84%e8%8d%b78mg%e6%97%a5%e6%9c%ac%e6%9c%ac%e5%9c%9f%e5%85%8d%e7%a8%85%e9%a6%99%e6%b8%af%e7%8f%be%e8%b2%a8
[Thu Jul 30 14:14:21.438824 2026] [security2:error] [pid 1021791:tid 1022009] [client 45.163.113.16:33011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuijRGd_N1Op4Iu5U9CBQAAAWI"], referer: http://pkf.jo
[Thu Jul 30 14:14:21.477662 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.171.55.167:8796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/admin-post.php"] [unique_id "amuijRGd_N1Op4Iu5U9CEQAAARw"]
[Thu Jul 30 14:14:21.495000 2026] [security2:error] [pid 1021791:tid 1022042] [client 135.119.63.61:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/content-management/content.php"] [unique_id "amuijRGd_N1Op4Iu5U9CEgAAAYM"]
[Thu Jul 30 14:14:21.737384 2026] [security2:error] [pid 1021791:tid 1022040] [client 212.154.121.179:52448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuijRGd_N1Op4Iu5U9CDQAAAYE"], referer: http://pkf.jo
[Thu Jul 30 14:14:22.127522 2026] [security2:error] [pid 1021791:tid 1021843] [remote 57.141.0.60:56090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amuijRGd_N1Op4Iu5U9CFgABajM"]
[Thu Jul 30 14:14:22.195404 2026] [security2:error] [pid 1021791:tid 1021921] [client 20.171.55.167:8822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "amuijhGd_N1Op4Iu5U9CIgAAAQo"]
[Thu Jul 30 14:14:22.427280 2026] [security2:error] [pid 1021791:tid 1022004] [client 76.18.70.11:50833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuijhGd_N1Op4Iu5U9CIQAAAV0"], referer: http://pkf.jo
[Thu Jul 30 14:14:22.475223 2026] [core:notice] [pid 1021791:tid 1022000] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:22.486270 2026] [core:notice] [pid 1021791:tid 1021981] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:22.547199 2026] [security2:error] [pid 1021791:tid 1021929] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuijRGd_N1Op4Iu5U9CGQAAARI"]
[Thu Jul 30 14:14:22.548959 2026] [security2:error] [pid 1021791:tid 1021949] [client 172.202.44.182:8355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/w.php"] [unique_id "amuijhGd_N1Op4Iu5U9CNAAAASY"]
[Thu Jul 30 14:14:22.565417 2026] [core:notice] [pid 1021791:tid 1021954] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:22.594533 2026] [core:notice] [pid 1021791:tid 1021959] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:22.608207 2026] [core:notice] [pid 1021791:tid 1022024] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:22.928222 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.171.55.167:9010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/dropdown.php"] [unique_id "amuijhGd_N1Op4Iu5U9CPQAAAXc"]
[Thu Jul 30 14:14:22.929780 2026] [security2:error] [pid 1021791:tid 1021992] [client 110.226.231.197:35392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuijhGd_N1Op4Iu5U9COAAAAVE"], referer: http://pkf.jo
[Thu Jul 30 14:14:23.135661 2026] [security2:error] [pid 1021791:tid 1021979] [client 74.248.33.8:28066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/test1.php"] [unique_id "amuijxGd_N1Op4Iu5U9CRQAAAUQ"]
[Thu Jul 30 14:14:23.219079 2026] [core:notice] [pid 1021791:tid 1022041] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:23.226487 2026] [security2:error] [pid 1021791:tid 1022022] [client 20.215.191.139:23439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/c/flower.php"] [unique_id "amuijxGd_N1Op4Iu5U9CRwAAAW8"]
[Thu Jul 30 14:14:23.647500 2026] [security2:error] [pid 1021791:tid 1021978] [client 20.171.55.167:9019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuijxGd_N1Op4Iu5U9CVAAAAUM"]
[Thu Jul 30 14:14:23.692058 2026] [security2:error] [pid 1021791:tid 1022033] [client 135.119.63.61:53179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/content.php"] [unique_id "amuijxGd_N1Op4Iu5U9CVQAAAXo"]
[Thu Jul 30 14:14:23.755824 2026] [security2:error] [pid 1021791:tid 1021957] [client 213.152.161.219:38394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuijxGd_N1Op4Iu5U9CWwAAAS4"]
[Thu Jul 30 14:14:23.755957 2026] [security2:error] [pid 1021791:tid 1021957] [client 213.152.161.219:38394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuijxGd_N1Op4Iu5U9CWwAAAS4"]
[Thu Jul 30 14:14:23.772481 2026] [core:notice] [pid 1021791:tid 1021953] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:23.776204 2026] [security2:error] [pid 1021791:tid 1021953] [client 135.181.74.155:51854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-are-not-hard-to-love.html"] [unique_id "amuijxGd_N1Op4Iu5U9CXAAAASo"]
[Thu Jul 30 14:14:23.884053 2026] [security2:error] [pid 1021791:tid 1021882] [remote 114.119.149.81:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "emmanueljrodriguez.com"] [uri "/what-is-the-von-mises-stress/"] [unique_id "amuijxGd_N1Op4Iu5U9CagABf1o"], referer: https://emmanueljrodriguez.com/what-is-the-von-mises-stress/
[Thu Jul 30 14:14:24.051555 2026] [core:notice] [pid 1021791:tid 1021988] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:24.290775 2026] [security2:error] [pid 1021791:tid 1022014] [client 172.202.44.182:33351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/admin.php"] [unique_id "amuikBGd_N1Op4Iu5U9ChwAAAWc"]
[Thu Jul 30 14:14:24.385931 2026] [security2:error] [pid 1021791:tid 1022004] [client 20.171.55.167:9021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/dropdown.php"] [unique_id "amuikBGd_N1Op4Iu5U9CjAAAAV0"]
[Thu Jul 30 14:14:24.499694 2026] [security2:error] [pid 1021791:tid 1021945] [client 74.248.33.8:31397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-admin/maint/index.php"] [unique_id "amuikBGd_N1Op4Iu5U9CjQAAASI"]
[Thu Jul 30 14:14:24.714402 2026] [security2:error] [pid 1021791:tid 1022015] [client 202.1.186.151:59008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuikBGd_N1Op4Iu5U9CiwAAAWg"], referer: http://pkf.jo
[Thu Jul 30 14:14:24.739198 2026] [security2:error] [pid 1021791:tid 1021997] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuikBGd_N1Op4Iu5U9ChgAAAVY"]
[Thu Jul 30 14:14:25.031765 2026] [security2:error] [pid 1021791:tid 1021973] [client 172.202.44.182:8353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuikRGd_N1Op4Iu5U9CmgAAAT4"]
[Thu Jul 30 14:14:25.112381 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.171.55.167:8439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/about.php"] [unique_id "amuikRGd_N1Op4Iu5U9CngAAAW4"]
[Thu Jul 30 14:14:25.261437 2026] [security2:error] [pid 1021791:tid 1021964] [client 135.119.63.61:55682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/contentadmin.php"] [unique_id "amuikRGd_N1Op4Iu5U9CogAAATU"]
[Thu Jul 30 14:14:25.532714 2026] [security2:error] [pid 1021791:tid 1022043] [client 74.7.241.165:53040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.vls.hfl.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuikRGd_N1Op4Iu5U9CpwABhHo"]
[Thu Jul 30 14:14:25.679430 2026] [security2:error] [pid 1021791:tid 1022023] [client 45.224.189.5:38456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuikRGd_N1Op4Iu5U9CowAAAXA"], referer: http://pkf.jo
[Thu Jul 30 14:14:25.854123 2026] [security2:error] [pid 1021791:tid 1022042] [client 20.215.191.139:24242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/c/xleet.php"] [unique_id "amuikRGd_N1Op4Iu5U9CrgAAAYM"]
[Thu Jul 30 14:14:25.855155 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.171.55.167:8387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/about.php7"] [unique_id "amuikRGd_N1Op4Iu5U9CrwAAARw"]
[Thu Jul 30 14:14:26.205143 2026] [security2:error] [pid 1021791:tid 1021925] [client 152.59.182.5:40726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuikRGd_N1Op4Iu5U9CsAAAAQ4"], referer: http://pkf.jo
[Thu Jul 30 14:14:26.244847 2026] [security2:error] [pid 1021791:tid 1022033] [client 135.119.63.61:53152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/contentalfa.php"] [unique_id "amuikhGd_N1Op4Iu5U9CuAAAAXo"]
[Thu Jul 30 14:14:26.356805 2026] [security2:error] [pid 1021791:tid 1021957] [client 2.49.124.147:38546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuikhGd_N1Op4Iu5U9CsQAAAS4"], referer: http://pkf.jo
[Thu Jul 30 14:14:26.440453 2026] [security2:error] [pid 1021791:tid 1021953] [client 172.213.208.20:33581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wk/index.php"] [unique_id "amuikhGd_N1Op4Iu5U9CwQAAASo"]
[Thu Jul 30 14:14:26.947892 2026] [core:notice] [pid 1021791:tid 1021912] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:27.042821 2026] [security2:error] [pid 1021791:tid 1022014] [client 172.202.44.182:33387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/m.php"] [unique_id "amuikxGd_N1Op4Iu5U9CzAAAAWc"]
[Thu Jul 30 14:14:27.138027 2026] [security2:error] [pid 1021791:tid 1021926] [client 175.107.212.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuikhGd_N1Op4Iu5U9CvAABDwM"], referer: https://allmontecristi.com
[Thu Jul 30 14:14:27.176612 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.215.191.139:20739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/classwithtostring.php"] [unique_id "amuikxGd_N1Op4Iu5U9C1AAAAVQ"]
[Thu Jul 30 14:14:27.252562 2026] [security2:error] [pid 1021791:tid 1021927] [client 20.171.55.167:9145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/alfanew.php7"] [unique_id "amuikxGd_N1Op4Iu5U9C1QAAARA"]
[Thu Jul 30 14:14:27.580720 2026] [security2:error] [pid 1021791:tid 1021990] [client 204.12.208.18:58735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuikxGd_N1Op4Iu5U9C4gAAAU8"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 14:14:27.591265 2026] [security2:error] [pid 1021791:tid 1021934] [client 74.248.33.8:31671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/uploads/min.php"] [unique_id "amuikxGd_N1Op4Iu5U9C5AAAARc"]
[Thu Jul 30 14:14:28.004205 2026] [security2:error] [pid 1021791:tid 1021970] [client 135.119.63.61:54032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/contentbypass.php"] [unique_id "amuilBGd_N1Op4Iu5U9C7QAAATs"]
[Thu Jul 30 14:14:28.013808 2026] [security2:error] [pid 1021791:tid 1022040] [client 20.171.55.167:9011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/adminfuns.php7"] [unique_id "amuilBGd_N1Op4Iu5U9C7gAAAYE"]
[Thu Jul 30 14:14:28.025274 2026] [security2:error] [pid 1021791:tid 1021951] [client 85.208.96.210:53796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/26/forro-fogo-comeca-nesta-sexta-feira-26-com-show-de-xand-aviao-confira-programacao/"] [unique_id "amuilBGd_N1Op4Iu5U9C7wAAASg"]
[Thu Jul 30 14:14:28.025390 2026] [security2:error] [pid 1021791:tid 1021951] [client 85.208.96.210:53796] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/26/forro-fogo-comeca-nesta-sexta-feira-26-com-show-de-xand-aviao-confira-programacao/"] [unique_id "amuilBGd_N1Op4Iu5U9C7wAAASg"]
[Thu Jul 30 14:14:28.067479 2026] [security2:error] [pid 1021791:tid 1022024] [client 172.213.208.20:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/mini.php"] [unique_id "amuilBGd_N1Op4Iu5U9C8AAAAXE"]
[Thu Jul 30 14:14:28.189574 2026] [security2:error] [pid 1021791:tid 1022045] [client 204.12.208.18:58797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuilBGd_N1Op4Iu5U9C9AAAAYY"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 14:14:28.643818 2026] [security2:error] [pid 1021791:tid 1021966] [client 20.215.191.139:22660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/content.php"] [unique_id "amuilBGd_N1Op4Iu5U9DAAAAATc"]
[Thu Jul 30 14:14:28.734115 2026] [security2:error] [pid 1021791:tid 1022025] [client 20.171.55.167:8987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ebs.php7"] [unique_id "amuilBGd_N1Op4Iu5U9DBwAAAXI"]
[Thu Jul 30 14:14:28.759989 2026] [autoindex:error] [pid 1021791:tid 1021981] [client 87.236.176.81:43853] AH01276: Cannot serve directory /home2/qnjgzjte/hris.rgserve.ph/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:14:28.810662 2026] [security2:error] [pid 1021791:tid 1022032] [client 204.12.208.18:58836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuilBGd_N1Op4Iu5U9DCgAAAXk"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 14:14:28.877174 2026] [security2:error] [pid 1021791:tid 1022001] [client 172.213.208.20:22817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/aa.php"] [unique_id "amuilBGd_N1Op4Iu5U9DDgAAAVo"]
[Thu Jul 30 14:14:29.010532 2026] [security2:error] [pid 1021791:tid 1021953] [client 135.119.63.61:64782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/contentk.php"] [unique_id "amuilRGd_N1Op4Iu5U9DDwAAASo"]
[Thu Jul 30 14:14:29.014144 2026] [security2:error] [pid 1021791:tid 1022013] [client 172.202.44.182:19075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuilBGd_N1Op4Iu5U9DCQAAAWY"]
[Thu Jul 30 14:14:29.326362 2026] [security2:error] [pid 1021791:tid 1021824] [remote 57.141.0.30:64842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/1064/pdf"] [unique_id "amuilRGd_N1Op4Iu5U9DGgABTiA"]
[Thu Jul 30 14:14:29.327626 2026] [core:notice] [pid 1021791:tid 1021941] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:29.332334 2026] [security2:error] [pid 1021791:tid 1021941] [client 135.181.74.155:51860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-are-not-truly-moving-on-unless-you-experience-these-5-feelings.html"] [unique_id "amuilRGd_N1Op4Iu5U9DGwAAAR4"]
[Thu Jul 30 14:14:29.349069 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.215.191.139:29648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/doc.php"] [unique_id "amuilRGd_N1Op4Iu5U9DHAAAAW4"]
[Thu Jul 30 14:14:29.459072 2026] [security2:error] [pid 1021791:tid 1021955] [client 20.171.55.167:8770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/ws.php7"] [unique_id "amuilRGd_N1Op4Iu5U9DIQAAASw"]
[Thu Jul 30 14:14:29.803920 2026] [security2:error] [pid 1021791:tid 1022029] [client 172.213.208.20:11817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/w.php"] [unique_id "amuilRGd_N1Op4Iu5U9DIgAAAXY"]
[Thu Jul 30 14:14:29.805603 2026] [core:notice] [pid 1021791:tid 1021927] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:30.005196 2026] [security2:error] [pid 1021791:tid 1021794] [remote 159.223.76.255:55360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.76.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amuilRGd_N1Op4Iu5U9DJAABMwI"]
[Thu Jul 30 14:14:30.172543 2026] [security2:error] [pid 1021791:tid 1021965] [client 20.171.55.167:8795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/alfanew2.php7"] [unique_id "amuilhGd_N1Op4Iu5U9DLwAAATY"]
[Thu Jul 30 14:14:30.213328 2026] [security2:error] [pid 1021791:tid 1021928] [client 114.119.130.13:22295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/birthday-sparklers/"] [unique_id "amuilhGd_N1Op4Iu5U9DMAAAARE"], referer: https://fireworkskenya.co.ke/our-products/consumer-fireworks/small-display-cakes/ideal-guest-z1063-square-cake-25-shots/
[Thu Jul 30 14:14:30.574291 2026] [core:notice] [pid 1021791:tid 1021948] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:30.805364 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.215.191.139:24215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/dropdown.php"] [unique_id "amuilhGd_N1Op4Iu5U9DUQAAARM"]
[Thu Jul 30 14:14:30.857098 2026] [security2:error] [pid 1021791:tid 1022039] [client 172.213.208.20:11837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/admin.php"] [unique_id "amuilhGd_N1Op4Iu5U9DVAAAAYA"]
[Thu Jul 30 14:14:30.899390 2026] [security2:error] [pid 1021791:tid 1021967] [client 189.6.88.213:49973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuilhGd_N1Op4Iu5U9DVQAAATg"]
[Thu Jul 30 14:14:30.899483 2026] [security2:error] [pid 1021791:tid 1021967] [client 189.6.88.213:49973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuilhGd_N1Op4Iu5U9DVQAAATg"]
[Thu Jul 30 14:14:30.910066 2026] [security2:error] [pid 1021791:tid 1022034] [client 20.171.55.167:8445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/alfa-rex2.php7"] [unique_id "amuilhGd_N1Op4Iu5U9DVgAAAXs"]
[Thu Jul 30 14:14:30.912398 2026] [security2:error] [pid 1021791:tid 1021984] [client 74.248.33.8:31661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/zoom1.php"] [unique_id "amuilhGd_N1Op4Iu5U9DVwAAAUk"]
[Thu Jul 30 14:14:30.923939 2026] [security2:error] [pid 1021791:tid 1021968] [client 172.202.44.182:22247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/classwithtostring.php"] [unique_id "amuilhGd_N1Op4Iu5U9DWAAAATk"]
[Thu Jul 30 14:14:31.625705 2026] [security2:error] [pid 1021791:tid 1021956] [client 74.248.33.8:43658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/lock360.php"] [unique_id "amuilxGd_N1Op4Iu5U9DYwAAAS0"]
[Thu Jul 30 14:14:31.625753 2026] [security2:error] [pid 1021791:tid 1021997] [client 20.171.55.167:9127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuilxGd_N1Op4Iu5U9DYgAAAVY"]
[Thu Jul 30 14:14:31.953030 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.215.191.139:22190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/ee.php"] [unique_id "amuilxGd_N1Op4Iu5U9DbQAAARU"]
[Thu Jul 30 14:14:32.375421 2026] [security2:error] [pid 1021791:tid 1022019] [client 20.171.55.167:9015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "amuimBGd_N1Op4Iu5U9DfgAAAWw"]
[Thu Jul 30 14:14:32.417296 2026] [proxy:error] [pid 1021791:tid 1021935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:32.417381 2026] [proxy_http:error] [pid 1021791:tid 1021935] [client 98.87.102.177:64057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:32.418093 2026] [proxy:error] [pid 1021791:tid 1021935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:32.418150 2026] [proxy_http:error] [pid 1021791:tid 1021935] [client 98.87.102.177:64057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:32.418840 2026] [proxy:error] [pid 1021791:tid 1021976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:32.418900 2026] [proxy_http:error] [pid 1021791:tid 1021976] [client 18.211.55.47:10471] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:32.419621 2026] [proxy:error] [pid 1021791:tid 1021976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:32.419683 2026] [proxy_http:error] [pid 1021791:tid 1021976] [client 18.211.55.47:10471] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:32.585123 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.215.191.139:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/flower.php"] [unique_id "amuimBGd_N1Op4Iu5U9DiwAAAYg"]
[Thu Jul 30 14:14:33.047404 2026] [security2:error] [pid 1021791:tid 1021948] [client 172.202.44.182:28152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/gmo.php"] [unique_id "amuimRGd_N1Op4Iu5U9DlQAAASU"]
[Thu Jul 30 14:14:33.100033 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.171.55.167:8773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuimRGd_N1Op4Iu5U9DlgAAAVc"]
[Thu Jul 30 14:14:33.147868 2026] [security2:error] [pid 1021791:tid 1021970] [client 74.248.33.8:31419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/r.php"] [unique_id "amuimRGd_N1Op4Iu5U9DmAAAATs"]
[Thu Jul 30 14:14:33.149957 2026] [security2:error] [pid 1021791:tid 1022020] [client 172.237.109.114:31500] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/knews/readme.txt"] [unique_id "amuimRGd_N1Op4Iu5U9DmQAAAW0"]
[Thu Jul 30 14:14:33.192421 2026] [security2:error] [pid 1021791:tid 1022018] [client 144.172.114.51:58396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuimRGd_N1Op4Iu5U9DlwAAAWs"]
[Thu Jul 30 14:14:33.292292 2026] [security2:error] [pid 1021791:tid 1021987] [client 114.119.157.111:32977] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/shop/page/8/"] [unique_id "amuimRGd_N1Op4Iu5U9DmwAAAUw"], referer: https://lark-shop.com/shop/page/6
[Thu Jul 30 14:14:33.525855 2026] [security2:error] [pid 1021791:tid 1021967] [client 170.84.192.250:38938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuimRGd_N1Op4Iu5U9DmgAAATg"], referer: http://pkf.jo
[Thu Jul 30 14:14:33.559317 2026] [security2:error] [pid 1021791:tid 1022015] [client 172.213.208.20:26949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/404.php"] [unique_id "amuimRGd_N1Op4Iu5U9DpQAAAWg"]
[Thu Jul 30 14:14:33.811331 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.171.55.167:8818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "amuimRGd_N1Op4Iu5U9DpgAAAS8"]
[Thu Jul 30 14:14:33.889216 2026] [core:notice] [pid 1021791:tid 1022016] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:33.893567 2026] [security2:error] [pid 1021791:tid 1022016] [client 135.181.74.155:51860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-are-not-weak-for-loving-someone-with-all-your-heart.html"] [unique_id "amuimRGd_N1Op4Iu5U9DrAAAAWk"]
[Thu Jul 30 14:14:33.978682 2026] [security2:error] [pid 1021791:tid 1022013] [client 74.248.33.8:28057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/sf.php"] [unique_id "amuimRGd_N1Op4Iu5U9DsAAAAWY"]
[Thu Jul 30 14:14:34.442741 2026] [core:notice] [pid 1021791:tid 1022046] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:34.483660 2026] [security2:error] [pid 1021791:tid 1021973] [client 172.213.208.20:46130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/init.php"] [unique_id "amuimhGd_N1Op4Iu5U9DuwAAAT4"]
[Thu Jul 30 14:14:34.540537 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.171.55.167:8993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuimhGd_N1Op4Iu5U9DvwAAASA"]
[Thu Jul 30 14:14:34.759587 2026] [security2:error] [pid 1021791:tid 1022014] [client 74.248.33.8:31618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/t.php"] [unique_id "amuimhGd_N1Op4Iu5U9DwAAAAWc"]
[Thu Jul 30 14:14:35.210675 2026] [security2:error] [pid 1021791:tid 1021946] [client 114.119.141.232:54281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dhowcruisedinner.com"] [uri "/images/logo.png"] [unique_id "amuimxGd_N1Op4Iu5U9DywAAASM"], referer: http://dhowcruisedinner.com/
[Thu Jul 30 14:14:35.254466 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.171.55.167:8428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "amuimxGd_N1Op4Iu5U9DzAAAAWA"]
[Thu Jul 30 14:14:35.920878 2026] [security2:error] [pid 1021791:tid 1022018] [client 105.113.81.1:3748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuimxGd_N1Op4Iu5U9D4AAAAWs"], referer: http://pkf.jo
[Thu Jul 30 14:14:35.961094 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.171.55.167:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "amuimxGd_N1Op4Iu5U9D5AAAAUk"]
[Thu Jul 30 14:14:36.247354 2026] [security2:error] [pid 1021791:tid 1021995] [client 172.202.44.182:28131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuinBGd_N1Op4Iu5U9D7QAAAVQ"]
[Thu Jul 30 14:14:36.694336 2026] [security2:error] [pid 1021791:tid 1021954] [client 20.171.55.167:9005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xmrlpc.php"] [unique_id "amuinBGd_N1Op4Iu5U9D9wAAASs"]
[Thu Jul 30 14:14:36.695223 2026] [security2:error] [pid 1021791:tid 1021956] [client 114.119.158.216:46125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cnpinyin.com"] [uri "/gravity"] [unique_id "amuinBGd_N1Op4Iu5U9D-AAAAS0"], referer: https://cnpinyin.com/wp-sitemap-posts-page-1.xml
[Thu Jul 30 14:14:37.091092 2026] [security2:error] [pid 1021791:tid 1021959] [client 74.248.33.8:31662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/7.php"] [unique_id "amuinRGd_N1Op4Iu5U9EAgAAATA"]
[Thu Jul 30 14:14:37.311881 2026] [core:notice] [pid 1021791:tid 1021962] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:37.316335 2026] [security2:error] [pid 1021791:tid 1021962] [client 135.181.74.155:51860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-aren-t-obligated-to-do-anything.html"] [unique_id "amuinRGd_N1Op4Iu5U9ECwAAATM"]
[Thu Jul 30 14:14:37.425481 2026] [security2:error] [pid 1021791:tid 1021961] [client 20.171.55.167:8395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuinRGd_N1Op4Iu5U9EDAAAATI"]
[Thu Jul 30 14:14:37.647041 2026] [security2:error] [pid 1021791:tid 1021938] [client 172.202.44.182:28140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-the.php"] [unique_id "amuinRGd_N1Op4Iu5U9EFgAAARs"]
[Thu Jul 30 14:14:37.672609 2026] [security2:error] [pid 1021791:tid 1022026] [client 20.215.191.139:58494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/gecko-new.php"] [unique_id "amuinRGd_N1Op4Iu5U9EFwAAAXM"]
[Thu Jul 30 14:14:38.167888 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.171.55.167:9099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/css/xmrlpc.php"] [unique_id "amuinhGd_N1Op4Iu5U9EHgAAAWA"]
[Thu Jul 30 14:14:38.287632 2026] [security2:error] [pid 1021791:tid 1021971] [client 114.119.145.102:64035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/laughable/mash2119566.html"] [unique_id "amuinhGd_N1Op4Iu5U9EIgAAATw"], referer: https://www.shorewooddaycare.com/laughable/mash2119566.html
[Thu Jul 30 14:14:38.489332 2026] [security2:error] [pid 1021791:tid 1022043] [client 144.172.114.51:58426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecre.ae"] [uri "/api/index.php/v1/config/application"] [unique_id "amuinhGd_N1Op4Iu5U9EIwAAAYQ"]
[Thu Jul 30 14:14:38.711573 2026] [security2:error] [pid 1021791:tid 1021946] [client 74.248.33.8:28093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/b.php"] [unique_id "amuinhGd_N1Op4Iu5U9ELgAAASM"]
[Thu Jul 30 14:14:38.870354 2026] [core:notice] [pid 1021791:tid 1021809] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:38.886050 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.171.55.167:8415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuinhGd_N1Op4Iu5U9EMQAAAUw"]
[Thu Jul 30 14:14:38.929266 2026] [security2:error] [pid 1021791:tid 1021927] [client 172.213.208.20:27209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/adminfuns.php"] [unique_id "amuinhGd_N1Op4Iu5U9EMgAAARA"]
[Thu Jul 30 14:14:39.019709 2026] [security2:error] [pid 1021791:tid 1021801] [remote 89.185.225.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fantasynamelist.com"] [uri "/wp-login.php"] [unique_id "amuinxGd_N1Op4Iu5U9EMwABeQk"]
[Thu Jul 30 14:14:39.167525 2026] [security2:error] [pid 1021791:tid 1022010] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuinhGd_N1Op4Iu5U9EJAABYwY"]
[Thu Jul 30 14:14:39.459200 2026] [security2:error] [pid 1021791:tid 1021942] [client 172.213.208.20:35050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/file.php"] [unique_id "amuinxGd_N1Op4Iu5U9EPQAAAR8"]
[Thu Jul 30 14:14:39.664647 2026] [security2:error] [pid 1021791:tid 1021950] [client 20.171.55.167:8772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/img/xmrlpc.php"] [unique_id "amuinxGd_N1Op4Iu5U9EQQAAASc"]
[Thu Jul 30 14:14:39.713943 2026] [security2:error] [pid 1021791:tid 1021985] [client 20.215.191.139:25266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/m.php"] [unique_id "amuinxGd_N1Op4Iu5U9ERAAAAUo"]
[Thu Jul 30 14:14:39.786190 2026] [security2:error] [pid 1021791:tid 1021933] [client 178.156.185.231:1234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuinxGd_N1Op4Iu5U9EPwAAARY"], referer: https://globalmarks.pk/
[Thu Jul 30 14:14:40.209512 2026] [security2:error] [pid 1021791:tid 1021964] [client 172.202.44.182:22211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/404.php"] [unique_id "amuioBGd_N1Op4Iu5U9ETgAAATU"]
[Thu Jul 30 14:14:40.388672 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.171.55.167:8988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "amuioBGd_N1Op4Iu5U9EVQAAASA"]
[Thu Jul 30 14:14:40.621405 2026] [core:notice] [pid 1021791:tid 1021816] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:40.733472 2026] [security2:error] [pid 1021791:tid 1021826] [remote 47.86.33.52:10852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxt.udi.temporary.site"] [uri "/wp-login.php"] [unique_id "amuioBGd_N1Op4Iu5U9EXAABGyI"]
[Thu Jul 30 14:14:41.144508 2026] [security2:error] [pid 1021791:tid 1021971] [client 20.171.55.167:8405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "amuioRGd_N1Op4Iu5U9EZAAAATw"]
[Thu Jul 30 14:14:41.348474 2026] [core:notice] [pid 1021791:tid 1022019] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:41.503918 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.215.191.139:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuioRGd_N1Op4Iu5U9EcAAAAYg"]
[Thu Jul 30 14:14:41.562395 2026] [security2:error] [pid 1021791:tid 1021995] [client 168.144.138.14:55771] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "pkf.jo"] [uri "/wp-json/batch/v1"] [unique_id "amuioRGd_N1Op4Iu5U9EcQAAAVQ"]
[Thu Jul 30 14:14:41.618777 2026] [security2:error] [pid 1021791:tid 1021983] [client 189.6.88.213:50549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuioRGd_N1Op4Iu5U9EcgAAAUg"]
[Thu Jul 30 14:14:41.618917 2026] [security2:error] [pid 1021791:tid 1021983] [client 189.6.88.213:50549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuioRGd_N1Op4Iu5U9EcgAAAUg"]
[Thu Jul 30 14:14:41.842673 2026] [security2:error] [pid 1021791:tid 1021940] [client 172.202.44.182:22254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/init.php"] [unique_id "amuioRGd_N1Op4Iu5U9EeQAAAR0"]
[Thu Jul 30 14:14:41.858319 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.171.55.167:8989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/images/xmrlpc.php"] [unique_id "amuioRGd_N1Op4Iu5U9EewAAASI"]
[Thu Jul 30 14:14:42.620106 2026] [security2:error] [pid 1021791:tid 1021935] [client 172.213.208.20:33087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/222.php"] [unique_id "amuiohGd_N1Op4Iu5U9EkQAAARg"]
[Thu Jul 30 14:14:42.752758 2026] [security2:error] [pid 1021791:tid 1021972] [client 20.215.191.139:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mah/flower.php"] [unique_id "amuiohGd_N1Op4Iu5U9ElQAAAT0"]
[Thu Jul 30 14:14:42.817343 2026] [core:notice] [pid 1021791:tid 1021951] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:42.821578 2026] [security2:error] [pid 1021791:tid 1021951] [client 135.181.74.155:38286] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-aren-t-powerless.html"] [unique_id "amuiohGd_N1Op4Iu5U9ElgAAASg"]
[Thu Jul 30 14:14:43.097831 2026] [security2:error] [pid 1021791:tid 1021976] [client 20.171.55.167:9012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "amuioxGd_N1Op4Iu5U9EnwAAAUE"]
[Thu Jul 30 14:14:43.203327 2026] [security2:error] [pid 1021791:tid 1021993] [client 172.202.44.182:21945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/file5.php"] [unique_id "amuioxGd_N1Op4Iu5U9EoAAAAVI"]
[Thu Jul 30 14:14:43.295053 2026] [security2:error] [pid 1021791:tid 1022038] [client 172.213.208.20:42363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuioxGd_N1Op4Iu5U9EpAAAAX8"]
[Thu Jul 30 14:14:43.420314 2026] [security2:error] [pid 1021791:tid 1022043] [client 114.119.141.139:26917] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/events/retreat-dates/eventsbyday/2026/4/9/-"] [unique_id "amuioxGd_N1Op4Iu5U9EqQAAAYQ"], referer: https://www.hmhs.ph/events/retreat-dates/monthcalendar/2026/4/-
[Thu Jul 30 14:14:43.512447 2026] [security2:error] [pid 1021791:tid 1022020] [client 20.215.191.139:21719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mah/xleet.php"] [unique_id "amuioxGd_N1Op4Iu5U9ErAAAAW0"]
[Thu Jul 30 14:14:43.694602 2026] [core:notice] [pid 1021791:tid 1021908] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:44.012962 2026] [security2:error] [pid 1021791:tid 1021967] [client 172.237.109.114:1938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/sdk/vimService.wsdl"] [unique_id "amuipBGd_N1Op4Iu5U9EuAAAATg"]
[Thu Jul 30 14:14:44.030767 2026] [security2:error] [pid 1021791:tid 1022031] [client 20.171.55.167:8830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "amuipBGd_N1Op4Iu5U9EuQAAAXg"]
[Thu Jul 30 14:14:44.118269 2026] [security2:error] [pid 1021791:tid 1021921] [client 74.248.33.8:28075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/buy.php"] [unique_id "amuipBGd_N1Op4Iu5U9EugAAAQo"]
[Thu Jul 30 14:14:44.357757 2026] [security2:error] [pid 1021791:tid 1021995] [client 172.202.44.182:26245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuipBGd_N1Op4Iu5U9EvgAAAVQ"]
[Thu Jul 30 14:14:44.782330 2026] [security2:error] [pid 1021791:tid 1021969] [client 20.171.55.167:8386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "amuipBGd_N1Op4Iu5U9ExwAAATo"]
[Thu Jul 30 14:14:44.958155 2026] [security2:error] [pid 1021791:tid 1021949] [client 20.215.191.139:5588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mini.php"] [unique_id "amuipBGd_N1Op4Iu5U9EzgAAASY"]
[Thu Jul 30 14:14:45.501100 2026] [security2:error] [pid 1021791:tid 1021938] [client 20.171.55.167:8404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "amuipRGd_N1Op4Iu5U9FDQAAARs"]
[Thu Jul 30 14:14:45.765945 2026] [security2:error] [pid 1021791:tid 1022000] [client 172.202.44.182:26264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/shell.php"] [unique_id "amuipRGd_N1Op4Iu5U9FFAAAAVk"]
[Thu Jul 30 14:14:45.872305 2026] [security2:error] [pid 1021791:tid 1022019] [client 172.213.208.20:44821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/admin.php"] [unique_id "amuipRGd_N1Op4Iu5U9FGAAAAWw"]
[Thu Jul 30 14:14:46.131003 2026] [security2:error] [pid 1021791:tid 1022030] [client 74.248.33.8:43652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/config.php"] [unique_id "amuiphGd_N1Op4Iu5U9FIAAAAXc"]
[Thu Jul 30 14:14:46.217032 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.171.55.167:8823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/xmrlpc.php"] [unique_id "amuiphGd_N1Op4Iu5U9FIQAAAUk"]
[Thu Jul 30 14:14:46.361458 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.215.191.139:25268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/moon.php"] [unique_id "amuiphGd_N1Op4Iu5U9FIgAAAQs"]
[Thu Jul 30 14:14:46.725853 2026] [security2:error] [pid 1021791:tid 1021953] [client 172.213.208.20:21896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-configs.php"] [unique_id "amuiphGd_N1Op4Iu5U9FLAAAASo"]
[Thu Jul 30 14:14:46.832474 2026] [security2:error] [pid 1021791:tid 1021958] [client 74.248.33.8:31418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/num.php"] [unique_id "amuiphGd_N1Op4Iu5U9FLQAAAS8"]
[Thu Jul 30 14:14:46.930105 2026] [core:error] [pid 1021791:tid 1021944] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:14:46.930130 2026] [core:error] [pid 1021791:tid 1021944] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:14:46.973310 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.171.55.167:8826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/text.php"] [unique_id "amuiphGd_N1Op4Iu5U9FMgAAARU"]
[Thu Jul 30 14:14:47.694882 2026] [security2:error] [pid 1021791:tid 1022035] [client 20.171.55.167:8444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuipxGd_N1Op4Iu5U9FTgAAAXw"]
[Thu Jul 30 14:14:47.756420 2026] [security2:error] [pid 1021791:tid 1021979] [client 172.237.109.114:7281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuipxGd_N1Op4Iu5U9FOQAAAUQ"]
[Thu Jul 30 14:14:47.844480 2026] [security2:error] [pid 1021791:tid 1021928] [client 172.202.44.182:60654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/f35.php"] [unique_id "amuipxGd_N1Op4Iu5U9FUAAAARE"]
[Thu Jul 30 14:14:47.999460 2026] [security2:error] [pid 1021791:tid 1021970] [client 172.213.208.20:44829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/php.php"] [unique_id "amuipxGd_N1Op4Iu5U9FVQAAATs"]
[Thu Jul 30 14:14:48.056967 2026] [security2:error] [pid 1021791:tid 1021990] [client 20.215.191.139:5591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/new.php"] [unique_id "amuiqBGd_N1Op4Iu5U9FWQAAAU8"]
[Thu Jul 30 14:14:48.114601 2026] [security2:error] [pid 1021791:tid 1021968] [client 144.172.114.51:34366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuiqBGd_N1Op4Iu5U9FXAAAATk"]
[Thu Jul 30 14:14:48.324596 2026] [security2:error] [pid 1021791:tid 1021938] [client 180.243.59.178:57169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuiqBGd_N1Op4Iu5U9FWgAAARs"]
[Thu Jul 30 14:14:48.324795 2026] [security2:error] [pid 1021791:tid 1021938] [client 180.243.59.178:57169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuiqBGd_N1Op4Iu5U9FWgAAARs"]
[Thu Jul 30 14:14:48.413138 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.171.55.167:8429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/makeasmtp.php"] [unique_id "amuiqBGd_N1Op4Iu5U9FXwAAAUw"]
[Thu Jul 30 14:14:49.049141 2026] [security2:error] [pid 1021791:tid 1021947] [client 197.32.164.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuiqBGd_N1Op4Iu5U9FbwAAASQ"], referer: https://cnpinyin.com
[Thu Jul 30 14:14:49.119251 2026] [core:notice] [pid 1021791:tid 1021953] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:49.120652 2026] [security2:error] [pid 1021791:tid 1021953] [client 135.181.74.155:34760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amuiqRGd_N1Op4Iu5U9FdgAAASo"]
[Thu Jul 30 14:14:49.586888 2026] [core:notice] [pid 1021791:tid 1021962] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:49.590771 2026] [security2:error] [pid 1021791:tid 1021962] [client 135.181.74.155:34776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-can-always-build-yourself-up-again.html"] [unique_id "amuiqRGd_N1Op4Iu5U9FgAAAATM"]
[Thu Jul 30 14:14:49.895661 2026] [security2:error] [pid 1021791:tid 1021939] [client 144.172.114.51:34378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuiqRGd_N1Op4Iu5U9FhQAAARw"]
[Thu Jul 30 14:14:50.479306 2026] [security2:error] [pid 1021791:tid 1021979] [client 114.119.131.2:27349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ejournalugj.com"] [uri "/index_php/grageaku/search"] [unique_id "amuiqhGd_N1Op4Iu5U9FjwAAAUQ"], referer: https://www.ejournalugj.com/index.php/grageaku/issue/current
[Thu Jul 30 14:14:51.076412 2026] [security2:error] [pid 1021791:tid 1022039] [client 172.202.44.182:28129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/new.php"] [unique_id "amuiqxGd_N1Op4Iu5U9FnAAAAYA"]
[Thu Jul 30 14:14:51.128660 2026] [security2:error] [pid 1021791:tid 1021981] [client 172.237.109.114:56614] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/nextgen-gallery/readme.txt"] [unique_id "amuiqxGd_N1Op4Iu5U9FnQAAAUY"]
[Thu Jul 30 14:14:52.281184 2026] [security2:error] [pid 1021791:tid 1021932] [client 189.6.88.213:51104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuirBGd_N1Op4Iu5U9FvgAAARU"]
[Thu Jul 30 14:14:52.281296 2026] [security2:error] [pid 1021791:tid 1021932] [client 189.6.88.213:51104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuirBGd_N1Op4Iu5U9FvgAAARU"]
[Thu Jul 30 14:14:52.628614 2026] [security2:error] [pid 1021791:tid 1021980] [client 172.213.208.20:49647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/index.php"] [unique_id "amuirBGd_N1Op4Iu5U9FxgAAAUU"]
[Thu Jul 30 14:14:52.947549 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.215.191.139:6206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/radio.php"] [unique_id "amuirBGd_N1Op4Iu5U9F0AAAAVM"]
[Thu Jul 30 14:14:53.056347 2026] [security2:error] [pid 1021791:tid 1021934] [client 172.202.44.182:60637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/adminfuns.php"] [unique_id "amuirRGd_N1Op4Iu5U9F0gAAARc"]
[Thu Jul 30 14:14:53.149238 2026] [proxy:error] [pid 1021791:tid 1022037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:53.149312 2026] [proxy_http:error] [pid 1021791:tid 1022037] [client 44.213.206.96:28788] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:53.150426 2026] [proxy:error] [pid 1021791:tid 1022037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:53.150477 2026] [proxy_http:error] [pid 1021791:tid 1022037] [client 44.213.206.96:28788] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:53.156799 2026] [proxy:error] [pid 1021791:tid 1021928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:53.156858 2026] [proxy_http:error] [pid 1021791:tid 1021928] [client 44.213.206.96:53182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:53.157456 2026] [proxy:error] [pid 1021791:tid 1021928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:14:53.157502 2026] [proxy_http:error] [pid 1021791:tid 1021928] [client 44.213.206.96:53182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:14:53.189625 2026] [security2:error] [pid 1021791:tid 1022035] [client 154.250.11.167:34732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuirBGd_N1Op4Iu5U9FzgAAAXw"], referer: http://pkf.jo
[Thu Jul 30 14:14:53.235443 2026] [security2:error] [pid 1021791:tid 1021948] [client 31.13.250.29:64166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuirBGd_N1Op4Iu5U9FzwAAASU"], referer: http://pkf.jo
[Thu Jul 30 14:14:53.343237 2026] [core:notice] [pid 1021791:tid 1022039] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:53.345506 2026] [security2:error] [pid 1021791:tid 1022039] [client 135.181.74.155:34776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-can-t-be-fat-and-happy.html"] [unique_id "amuirRGd_N1Op4Iu5U9F4wAAAYA"]
[Thu Jul 30 14:14:53.397662 2026] [security2:error] [pid 1021791:tid 1022018] [client 172.213.208.20:42314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/a.php"] [unique_id "amuirRGd_N1Op4Iu5U9F5QAAAWs"]
[Thu Jul 30 14:14:53.534871 2026] [security2:error] [pid 1021791:tid 1021991] [client 103.179.252.171:43442] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuirRGd_N1Op4Iu5U9F0QAAAVA"]
[Thu Jul 30 14:14:53.692079 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.215.191.139:27949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/s.php"] [unique_id "amuirRGd_N1Op4Iu5U9F6gAAAYk"]
[Thu Jul 30 14:14:53.718812 2026] [security2:error] [pid 1021791:tid 1021991] [client 103.179.252.171:43442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuirRGd_N1Op4Iu5U9F0QAAAVA"]
[Thu Jul 30 14:14:53.894005 2026] [security2:error] [pid 1021791:tid 1021929] [client 79.101.230.32:58320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuirRGd_N1Op4Iu5U9F5gAAARI"], referer: http://pkf.jo
[Thu Jul 30 14:14:54.182121 2026] [core:notice] [pid 1021791:tid 1022025] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:54.313809 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.215.191.139:6125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/sim.php"] [unique_id "amuirhGd_N1Op4Iu5U9F_AAAASE"]
[Thu Jul 30 14:14:54.421655 2026] [core:notice] [pid 1021791:tid 1021960] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:54.530098 2026] [security2:error] [pid 1021791:tid 1021941] [client 172.237.109.114:11631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuirhGd_N1Op4Iu5U9F8wAAAR4"]
[Thu Jul 30 14:14:54.658601 2026] [security2:error] [pid 1021791:tid 1022041] [client 103.179.252.171:43480] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuirhGd_N1Op4Iu5U9GAQAAAYI"]
[Thu Jul 30 14:14:54.702785 2026] [security2:error] [pid 1021791:tid 1021975] [client 172.202.44.182:28100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/fm.php"] [unique_id "amuirhGd_N1Op4Iu5U9GAgAAAUA"]
[Thu Jul 30 14:14:54.847201 2026] [security2:error] [pid 1021791:tid 1022041] [client 103.179.252.171:43480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuirhGd_N1Op4Iu5U9GAQAAAYI"]
[Thu Jul 30 14:14:55.102065 2026] [security2:error] [pid 1021791:tid 1022045] [client 172.213.208.20:39899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuirxGd_N1Op4Iu5U9GDgAAAYY"]
[Thu Jul 30 14:14:55.136005 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.215.191.139:20341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/text.php"] [unique_id "amuirxGd_N1Op4Iu5U9GDwAAARw"]
[Thu Jul 30 14:14:55.490208 2026] [security2:error] [pid 1021791:tid 1021926] [client 159.89.206.24:63739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.206.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/wp-login.php"] [unique_id "amuirxGd_N1Op4Iu5U9GGQAAAQ8"], referer: https://www.google.com/search?q=wordpress
[Thu Jul 30 14:14:55.700449 2026] [security2:error] [pid 1021791:tid 1021945] [client 74.7.175.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.caflchimneysweeper.com"] [uri "/index.php"] [unique_id "amuirRGd_N1Op4Iu5U9F8QABInQ"]
[Thu Jul 30 14:14:55.700478 2026] [security2:error] [pid 1021791:tid 1021945] [client 74.7.175.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.caflchimneysweeper.com"] [uri "/index.php"] [unique_id "amuirRGd_N1Op4Iu5U9F8QABInQ"]
[Thu Jul 30 14:14:55.807847 2026] [security2:error] [pid 1021791:tid 1021928] [client 103.179.252.171:43512] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuirxGd_N1Op4Iu5U9GHQAAARE"]
[Thu Jul 30 14:14:55.984090 2026] [security2:error] [pid 1021791:tid 1021928] [client 103.179.252.171:43512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuirxGd_N1Op4Iu5U9GHQAAARE"]
[Thu Jul 30 14:14:56.078057 2026] [core:notice] [pid 1021791:tid 1021927] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:56.081827 2026] [security2:error] [pid 1021791:tid 1021927] [client 135.181.74.155:34776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-can-t-really-love-someone-forever.html"] [unique_id "amuisBGd_N1Op4Iu5U9GJgAAARA"]
[Thu Jul 30 14:14:56.187600 2026] [security2:error] [pid 1021791:tid 1022039] [client 20.215.191.139:25272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/user.php"] [unique_id "amuisBGd_N1Op4Iu5U9GJwAAAYA"]
[Thu Jul 30 14:14:56.328475 2026] [security2:error] [pid 1021791:tid 1022001] [client 144.172.114.51:54326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuisBGd_N1Op4Iu5U9GKgAAAVo"]
[Thu Jul 30 14:14:56.344607 2026] [security2:error] [pid 1021791:tid 1021990] [client 222.254.197.38:56173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuisBGd_N1Op4Iu5U9GJQAAAU8"], referer: http://pkf.jo
[Thu Jul 30 14:14:56.915681 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.215.191.139:5466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/webadmin.php"] [unique_id "amuisBGd_N1Op4Iu5U9GNwAAAVQ"]
[Thu Jul 30 14:14:56.942103 2026] [security2:error] [pid 1021791:tid 1022016] [client 103.179.252.171:43546] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuisBGd_N1Op4Iu5U9GOgAAAWk"]
[Thu Jul 30 14:14:57.122205 2026] [security2:error] [pid 1021791:tid 1022016] [client 103.179.252.171:43546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuisBGd_N1Op4Iu5U9GOgAAAWk"]
[Thu Jul 30 14:14:57.326808 2026] [security2:error] [pid 1021791:tid 1021872] [remote 216.73.217.142:59565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuisRGd_N1Op4Iu5U9GRQABX1A"]
[Thu Jul 30 14:14:57.470859 2026] [security2:error] [pid 1021791:tid 1021924] [client 123.21.140.40:48457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuisRGd_N1Op4Iu5U9GQgAAAQ0"], referer: http://pkf.jo
[Thu Jul 30 14:14:57.501003 2026] [security2:error] [pid 1021791:tid 1021954] [client 14.186.87.36:38992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuisRGd_N1Op4Iu5U9GRAAAASs"], referer: http://pkf.jo
[Thu Jul 30 14:14:57.535263 2026] [security2:error] [pid 1021791:tid 1021992] [client 172.237.109.114:53955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuisRGd_N1Op4Iu5U9GPAAAAVE"]
[Thu Jul 30 14:14:58.070256 2026] [security2:error] [pid 1021791:tid 1021939] [client 103.179.252.171:43568] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuishGd_N1Op4Iu5U9GWAAAARw"]
[Thu Jul 30 14:14:58.127513 2026] [security2:error] [pid 1021791:tid 1021937] [client 74.248.33.8:43653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/areak1.php"] [unique_id "amuishGd_N1Op4Iu5U9GXAAAARo"]
[Thu Jul 30 14:14:58.254315 2026] [security2:error] [pid 1021791:tid 1021939] [client 103.179.252.171:43568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuishGd_N1Op4Iu5U9GWAAAARw"]
[Thu Jul 30 14:14:58.339101 2026] [core:notice] [pid 1021791:tid 1021964] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:58.548136 2026] [security2:error] [pid 1021791:tid 1022035] [client 172.213.208.20:42988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin.php"] [unique_id "amuishGd_N1Op4Iu5U9GYwAAAXw"]
[Thu Jul 30 14:14:58.576065 2026] [security2:error] [pid 1021791:tid 1021982] [client 172.202.44.182:28136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/file.php"] [unique_id "amuishGd_N1Op4Iu5U9GZQAAAUc"]
[Thu Jul 30 14:14:58.845414 2026] [security2:error] [pid 1021791:tid 1022039] [client 180.243.59.178:57717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuishGd_N1Op4Iu5U9GaQAAAYA"]
[Thu Jul 30 14:14:58.845594 2026] [security2:error] [pid 1021791:tid 1022039] [client 180.243.59.178:57717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuishGd_N1Op4Iu5U9GaQAAAYA"]
[Thu Jul 30 14:14:58.911267 2026] [security2:error] [pid 1021791:tid 1022011] [client 74.248.33.8:31395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/vc.php"] [unique_id "amuishGd_N1Op4Iu5U9GagAAAWQ"]
[Thu Jul 30 14:14:59.197079 2026] [security2:error] [pid 1021791:tid 1022002] [client 103.179.252.171:43598] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuisxGd_N1Op4Iu5U9GdAAAAVs"]
[Thu Jul 30 14:14:59.223024 2026] [security2:error] [pid 1021791:tid 1021950] [client 184.75.221.211:41054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuisxGd_N1Op4Iu5U9GdQAAASc"]
[Thu Jul 30 14:14:59.223135 2026] [security2:error] [pid 1021791:tid 1021950] [client 184.75.221.211:41054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuisxGd_N1Op4Iu5U9GdQAAASc"]
[Thu Jul 30 14:14:59.377825 2026] [security2:error] [pid 1021791:tid 1022002] [client 103.179.252.171:43598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuisxGd_N1Op4Iu5U9GdAAAAVs"]
[Thu Jul 30 14:14:59.487248 2026] [security2:error] [pid 1021791:tid 1021980] [client 20.215.191.139:27907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amuisxGd_N1Op4Iu5U9GeAAAAUU"]
[Thu Jul 30 14:14:59.632642 2026] [security2:error] [pid 1021791:tid 1022022] [client 74.248.33.8:28086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuisxGd_N1Op4Iu5U9GgAAAAW8"]
[Thu Jul 30 14:14:59.904015 2026] [core:notice] [pid 1021791:tid 1021952] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:14:59.907526 2026] [security2:error] [pid 1021791:tid 1021952] [client 135.181.74.155:34776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-deserve-better-than-me.html"] [unique_id "amuisxGd_N1Op4Iu5U9GggAAASk"]
[Thu Jul 30 14:15:00.086327 2026] [security2:error] [pid 1021791:tid 1022009] [client 43.153.216.191:62772] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alseermarine.com"] [uri "/2026/07/28/al-seer-marine-delivers-aed-89-2-million-operating-profit-with-around-aed-579-million-in-total-revenue-for-the-first-half-of-2026"] [unique_id "amuitBGd_N1Op4Iu5U9GiQAAAWI"]
[Thu Jul 30 14:15:00.104090 2026] [security2:error] [pid 1021791:tid 1021935] [client 112.86.225.160:47058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/"] [unique_id "amuitBGd_N1Op4Iu5U9GigAAARg"]
[Thu Jul 30 14:15:00.104203 2026] [security2:error] [pid 1021791:tid 1021935] [client 112.86.225.160:47058] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "happyspree.app"] [uri "/"] [unique_id "amuitBGd_N1Op4Iu5U9GigAAARg"]
[Thu Jul 30 14:15:00.262449 2026] [security2:error] [pid 1021791:tid 1021861] [remote 185.146.22.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.22.146.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espairsa.com"] [uri "/wp-login.php"] [unique_id "amuitBGd_N1Op4Iu5U9GjgABZUU"]
[Thu Jul 30 14:15:00.304836 2026] [security2:error] [pid 1021791:tid 1021975] [client 103.179.252.171:43614] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuitBGd_N1Op4Iu5U9GjwAAAUA"]
[Thu Jul 30 14:15:00.318333 2026] [security2:error] [pid 1021791:tid 1022033] [client 121.229.156.29:55116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amuitBGd_N1Op4Iu5U9GkAAAAXo"]
[Thu Jul 30 14:15:00.318428 2026] [security2:error] [pid 1021791:tid 1022033] [client 121.229.156.29:55116] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amuitBGd_N1Op4Iu5U9GkAAAAXo"]
[Thu Jul 30 14:15:00.487217 2026] [security2:error] [pid 1021791:tid 1021975] [client 103.179.252.171:43614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuitBGd_N1Op4Iu5U9GjwAAAUA"]
[Thu Jul 30 14:15:00.675762 2026] [security2:error] [pid 1021791:tid 1022029] [client 172.213.208.20:44838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/size.php"] [unique_id "amuitBGd_N1Op4Iu5U9GmAAAAXY"]
[Thu Jul 30 14:15:00.831746 2026] [security2:error] [pid 1021791:tid 1021974] [client 20.215.191.139:18540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amuitBGd_N1Op4Iu5U9GnAAAAT8"]
[Thu Jul 30 14:15:00.870969 2026] [security2:error] [pid 1021791:tid 1021971] [client 152.58.15.165:49402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuitBGd_N1Op4Iu5U9GlAAAATw"], referer: http://pkf.jo
[Thu Jul 30 14:15:01.424096 2026] [security2:error] [pid 1021791:tid 1021948] [client 103.179.252.171:43644] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuitRGd_N1Op4Iu5U9GqAAAASU"]
[Thu Jul 30 14:15:01.478567 2026] [security2:error] [pid 1021791:tid 1022018] [client 20.215.191.139:27905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amuitRGd_N1Op4Iu5U9GqQAAAWs"]
[Thu Jul 30 14:15:01.574951 2026] [security2:error] [pid 1021791:tid 1021927] [client 172.213.208.20:49671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuitRGd_N1Op4Iu5U9GrQAAARA"]
[Thu Jul 30 14:15:01.633947 2026] [security2:error] [pid 1021791:tid 1021948] [client 103.179.252.171:43644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuitRGd_N1Op4Iu5U9GqAAAASU"]
[Thu Jul 30 14:15:02.125648 2026] [core:notice] [pid 1021791:tid 1021984] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:02.411740 2026] [security2:error] [pid 1021791:tid 1022042] [client 172.202.44.182:60625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/bolt.php"] [unique_id "amuithGd_N1Op4Iu5U9GwgAAAYM"]
[Thu Jul 30 14:15:02.565906 2026] [security2:error] [pid 1021791:tid 1022008] [client 103.179.252.171:43660] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuithGd_N1Op4Iu5U9GwwAAAWE"]
[Thu Jul 30 14:15:02.698287 2026] [security2:error] [pid 1021791:tid 1021952] [client 20.215.191.139:6193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amuithGd_N1Op4Iu5U9GygAAASk"]
[Thu Jul 30 14:15:02.741011 2026] [security2:error] [pid 1021791:tid 1021827] [remote 40.77.167.67:15998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/8853/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amuithGd_N1Op4Iu5U9GzAABgiM"]
[Thu Jul 30 14:15:02.745138 2026] [security2:error] [pid 1021791:tid 1022008] [client 103.179.252.171:43660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuithGd_N1Op4Iu5U9GwwAAAWE"]
[Thu Jul 30 14:15:02.973257 2026] [security2:error] [pid 1021791:tid 1021962] [client 189.6.88.213:51681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuithGd_N1Op4Iu5U9GzwAAATM"]
[Thu Jul 30 14:15:02.973373 2026] [security2:error] [pid 1021791:tid 1021962] [client 189.6.88.213:51681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuithGd_N1Op4Iu5U9GzwAAATM"]
[Thu Jul 30 14:15:03.199887 2026] [proxy:error] [pid 1021791:tid 1021983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:03.199949 2026] [proxy_http:error] [pid 1021791:tid 1021983] [client 3.228.112.215:63022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:03.200513 2026] [proxy:error] [pid 1021791:tid 1021983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:03.200558 2026] [proxy_http:error] [pid 1021791:tid 1021983] [client 3.228.112.215:63022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:03.220536 2026] [proxy:error] [pid 1021791:tid 1021974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:03.220610 2026] [proxy_http:error] [pid 1021791:tid 1021974] [client 52.202.41.153:23510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:03.221244 2026] [proxy:error] [pid 1021791:tid 1021974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:03.221302 2026] [proxy_http:error] [pid 1021791:tid 1021974] [client 52.202.41.153:23510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:03.351880 2026] [security2:error] [pid 1021791:tid 1022038] [client 20.215.191.139:19685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amuitxGd_N1Op4Iu5U9G6gAAAX8"]
[Thu Jul 30 14:15:03.673720 2026] [security2:error] [pid 1021791:tid 1021956] [client 205.169.39.15:12125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuitxGd_N1Op4Iu5U9G6QAAAS0"]
[Thu Jul 30 14:15:03.724375 2026] [security2:error] [pid 1021791:tid 1021968] [client 103.179.252.171:43686] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuitxGd_N1Op4Iu5U9G8gAAATk"]
[Thu Jul 30 14:15:03.901249 2026] [security2:error] [pid 1021791:tid 1021968] [client 103.179.252.171:43686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "raad.pk"] [uri "/wp-comments-post.php"] [unique_id "amuitxGd_N1Op4Iu5U9G8gAAATk"]
[Thu Jul 30 14:15:04.120603 2026] [core:notice] [pid 1021791:tid 1021973] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:04.125700 2026] [security2:error] [pid 1021791:tid 1021973] [client 135.181.74.155:34776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-deserve-the-love-you-keep-trying-to-give-everyone-else.html"] [unique_id "amuiuBGd_N1Op4Iu5U9G_AAAAT4"]
[Thu Jul 30 14:15:04.427284 2026] [security2:error] [pid 1021791:tid 1022042] [client 159.89.206.24:49597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.206.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/wp-login.php"] [unique_id "amuiuBGd_N1Op4Iu5U9HBwAAAYM"], referer: https://www.google.com/search?q=wordpress
[Thu Jul 30 14:15:04.503991 2026] [security2:error] [pid 1021791:tid 1021955] [client 172.237.109.114:10070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuiuBGd_N1Op4Iu5U9G-QAAASw"]
[Thu Jul 30 14:15:04.603259 2026] [security2:error] [pid 1021791:tid 1021981] [client 172.202.44.182:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/3.php"] [unique_id "amuiuBGd_N1Op4Iu5U9HCAAAAUY"]
[Thu Jul 30 14:15:04.678331 2026] [security2:error] [pid 1021791:tid 1021999] [client 172.237.109.114:61230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuiuBGd_N1Op4Iu5U9G_wAAAVg"]
[Thu Jul 30 14:15:04.692442 2026] [security2:error] [pid 1021791:tid 1021924] [client 74.7.230.9:33304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-e4b10ebb.xfy.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuiuBGd_N1Op4Iu5U9HDAAAAQ0"]
[Thu Jul 30 14:15:05.341880 2026] [core:notice] [pid 1021791:tid 1021916] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:05.424293 2026] [security2:error] [pid 1021791:tid 1022024] [client 172.213.208.20:11891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/403.php"] [unique_id "amuiuRGd_N1Op4Iu5U9HIQAAAXE"]
[Thu Jul 30 14:15:05.617988 2026] [security2:error] [pid 1021791:tid 1021996] [client 172.202.44.182:45507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/222.php"] [unique_id "amuiuRGd_N1Op4Iu5U9HIwAAAVU"]
[Thu Jul 30 14:15:05.864296 2026] [security2:error] [pid 1021791:tid 1021966] [client 20.215.191.139:27919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amuiuRGd_N1Op4Iu5U9HKwAAATc"]
[Thu Jul 30 14:15:06.113970 2026] [core:error] [pid 1021791:tid 1022018] [client 95.108.213.152:32932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:15:06.114010 2026] [core:error] [pid 1021791:tid 1022018] [client 95.108.213.152:32932] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:15:06.536505 2026] [security2:error] [pid 1021791:tid 1021957] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuiuRGd_N1Op4Iu5U9HLgABLng"]
[Thu Jul 30 14:15:06.945060 2026] [security2:error] [pid 1021791:tid 1021808] [remote 74.7.243.224:52978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amuiuhGd_N1Op4Iu5U9HRAABiRA"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:15:07.074677 2026] [security2:error] [pid 1021791:tid 1021967] [client 172.202.44.182:32302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuiuxGd_N1Op4Iu5U9HRgAAATg"]
[Thu Jul 30 14:15:07.095352 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.215.191.139:27925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuiuxGd_N1Op4Iu5U9HSAAAAVA"]
[Thu Jul 30 14:15:07.142698 2026] [core:notice] [pid 1021791:tid 1021971] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:07.584367 2026] [security2:error] [pid 1021791:tid 1021954] [client 172.213.208.20:11912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuiuxGd_N1Op4Iu5U9HWwAAASs"]
[Thu Jul 30 14:15:07.620962 2026] [security2:error] [pid 1021791:tid 1022006] [client 172.237.109.114:7278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuiuxGd_N1Op4Iu5U9HSgAAAV8"]
[Thu Jul 30 14:15:07.953211 2026] [security2:error] [pid 1021791:tid 1021976] [client 20.215.191.139:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amuiuxGd_N1Op4Iu5U9HYgAAAUE"]
[Thu Jul 30 14:15:08.126812 2026] [security2:error] [pid 1021791:tid 1021993] [client 172.202.44.182:32279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuivBGd_N1Op4Iu5U9HaAAAAVI"]
[Thu Jul 30 14:15:08.610094 2026] [security2:error] [pid 1021791:tid 1021999] [client 74.248.33.8:43650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/core.php"] [unique_id "amuivBGd_N1Op4Iu5U9HegAAAVg"]
[Thu Jul 30 14:15:08.719730 2026] [security2:error] [pid 1021791:tid 1022032] [client 79.106.211.104:11909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuivBGd_N1Op4Iu5U9HcgAAAXk"], referer: http://pkf.jo
[Thu Jul 30 14:15:08.855507 2026] [core:notice] [pid 1021791:tid 1021984] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:08.859604 2026] [security2:error] [pid 1021791:tid 1021984] [client 135.181.74.155:34776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-didn-t-know-you-wanted-to-know-about-this.html"] [unique_id "amuivBGd_N1Op4Iu5U9HfQAAAUk"]
[Thu Jul 30 14:15:08.874242 2026] [security2:error] [pid 1021791:tid 1022003] [client 144.172.114.51:43856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuivBGd_N1Op4Iu5U9HfAAAAVw"]
[Thu Jul 30 14:15:09.009621 2026] [security2:error] [pid 1021791:tid 1021950] [client 180.243.59.178:58180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuivRGd_N1Op4Iu5U9HhgAAASc"]
[Thu Jul 30 14:15:09.009748 2026] [security2:error] [pid 1021791:tid 1021950] [client 180.243.59.178:58180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuivRGd_N1Op4Iu5U9HhgAAASc"]
[Thu Jul 30 14:15:10.229052 2026] [security2:error] [pid 1021791:tid 1021938] [client 74.248.33.8:28064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/min.php"] [unique_id "amuivhGd_N1Op4Iu5U9HqAAAARs"]
[Thu Jul 30 14:15:10.780805 2026] [security2:error] [pid 1021791:tid 1021997] [client 135.119.63.61:8939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/file_uploadsadmin.php"] [unique_id "amuivhGd_N1Op4Iu5U9HtgAAAVY"]
[Thu Jul 30 14:15:10.800945 2026] [security2:error] [pid 1021791:tid 1021855] [remote 57.141.0.36:37788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amuivhGd_N1Op4Iu5U9HtwABHz8"]
[Thu Jul 30 14:15:11.097019 2026] [security2:error] [pid 1021791:tid 1022032] [client 74.248.33.8:31638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "amuivxGd_N1Op4Iu5U9HwgAAAXk"]
[Thu Jul 30 14:15:11.621359 2026] [security2:error] [pid 1021791:tid 1021981] [client 74.248.33.8:43672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/ws37.php"] [unique_id "amuivxGd_N1Op4Iu5U9HzgAAAUY"]
[Thu Jul 30 14:15:11.849615 2026] [security2:error] [pid 1021791:tid 1021853] [remote 47.128.27.65:33362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moose-knuckles-jacket-black-10/"] [unique_id "amuivxGd_N1Op4Iu5U9H0wABOz0"]
[Thu Jul 30 14:15:12.149870 2026] [security2:error] [pid 1021791:tid 1021959] [client 172.213.208.20:37850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/as.php"] [unique_id "amuiwBGd_N1Op4Iu5U9H6AAAATA"]
[Thu Jul 30 14:15:12.212963 2026] [security2:error] [pid 1021791:tid 1021983] [client 41.90.144.182:6448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuivxGd_N1Op4Iu5U9H1AAAAUg"], referer: http://pkf.jo
[Thu Jul 30 14:15:12.273509 2026] [security2:error] [pid 1021791:tid 1021955] [client 135.119.63.61:56955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/file_uploadsalfa.php"] [unique_id "amuiwBGd_N1Op4Iu5U9IBAAAASw"]
[Thu Jul 30 14:15:13.519553 2026] [security2:error] [pid 1021791:tid 1022042] [client 189.6.88.213:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiwRGd_N1Op4Iu5U9IdwAAAYM"]
[Thu Jul 30 14:15:13.520015 2026] [security2:error] [pid 1021791:tid 1022042] [client 189.6.88.213:52239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuiwRGd_N1Op4Iu5U9IdwAAAYM"]
[Thu Jul 30 14:15:13.639360 2026] [core:notice] [pid 1021791:tid 1022015] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:13.840625 2026] [security2:error] [pid 1021791:tid 1022010] [client 74.248.33.8:28067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/new.php"] [unique_id "amuiwRGd_N1Op4Iu5U9IiQAAAWM"]
[Thu Jul 30 14:15:13.949865 2026] [core:notice] [pid 1021791:tid 1022040] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:14.055839 2026] [security2:error] [pid 1021791:tid 1021838] [remote 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuiwRGd_N1Op4Iu5U9IdgABNi4"]
[Thu Jul 30 14:15:14.063067 2026] [security2:error] [pid 1021791:tid 1021969] [client 135.119.63.61:8938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/file_uploadsbypass.php"] [unique_id "amuiwhGd_N1Op4Iu5U9ImwAAATo"]
[Thu Jul 30 14:15:14.192287 2026] [security2:error] [pid 1021791:tid 1021923] [client 172.202.44.182:32270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/admin.php"] [unique_id "amuiwhGd_N1Op4Iu5U9IogAAAQw"]
[Thu Jul 30 14:15:14.692435 2026] [security2:error] [pid 1021791:tid 1021960] [client 74.248.33.8:43694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/il.php"] [unique_id "amuiwhGd_N1Op4Iu5U9IsAAAATE"]
[Thu Jul 30 14:15:14.798380 2026] [core:notice] [pid 1021791:tid 1022048] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:14.801925 2026] [security2:error] [pid 1021791:tid 1022048] [client 135.181.74.155:37686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-don-t-deserve-the-pain-you-re-clinging-to.html"] [unique_id "amuiwhGd_N1Op4Iu5U9ItwAAAYk"]
[Thu Jul 30 14:15:15.051269 2026] [security2:error] [pid 1021791:tid 1021929] [client 135.119.63.61:8902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/file_uploadsk.php"] [unique_id "amuiwxGd_N1Op4Iu5U9IvQAAARI"]
[Thu Jul 30 14:15:15.476308 2026] [security2:error] [pid 1021791:tid 1021924] [client 172.202.44.182:32256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-configs.php"] [unique_id "amuiwxGd_N1Op4Iu5U9IyAAAAQ0"]
[Thu Jul 30 14:15:16.077286 2026] [security2:error] [pid 1021791:tid 1022040] [client 172.237.109.114:44293] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/securimage-wp/readme.txt"] [unique_id "amuixBGd_N1Op4Iu5U9I1gAAAYE"]
[Thu Jul 30 14:15:16.108887 2026] [security2:error] [pid 1021791:tid 1021979] [client 135.119.63.61:8947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/file_uploadswp.php"] [unique_id "amuixBGd_N1Op4Iu5U9I1wAAAUQ"]
[Thu Jul 30 14:15:16.303216 2026] [core:notice] [pid 1021791:tid 1021915] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:16.328192 2026] [security2:error] [pid 1021791:tid 1021971] [client 172.202.44.182:28141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/php.php"] [unique_id "amuixBGd_N1Op4Iu5U9I3AAAATw"]
[Thu Jul 30 14:15:16.920987 2026] [security2:error] [pid 1021791:tid 1022013] [client 135.119.63.61:57921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/file_uploadwp.php"] [unique_id "amuixBGd_N1Op4Iu5U9I7AAAAWY"]
[Thu Jul 30 14:15:16.921610 2026] [proxy:error] [pid 1021791:tid 1021909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:16.921656 2026] [proxy_http:error] [pid 1021791:tid 1021909] [remote 74.7.175.138:44252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:16.922233 2026] [proxy:error] [pid 1021791:tid 1021909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:16.922283 2026] [proxy_http:error] [pid 1021791:tid 1021909] [remote 74.7.175.138:44252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:16.974330 2026] [security2:error] [pid 1021791:tid 1021923] [client 172.213.208.20:11880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuixBGd_N1Op4Iu5U9I7gAAAQw"]
[Thu Jul 30 14:15:17.251329 2026] [security2:error] [pid 1021791:tid 1021941] [client 20.215.191.139:57980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amuixRGd_N1Op4Iu5U9I8QAAAR4"]
[Thu Jul 30 14:15:17.272403 2026] [security2:error] [pid 1021791:tid 1021973] [client 74.248.33.8:42933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/images/index.php"] [unique_id "amuixRGd_N1Op4Iu5U9I8wAAAT4"]
[Thu Jul 30 14:15:17.841334 2026] [security2:error] [pid 1021791:tid 1021813] [remote 194.116.184.179:35453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuixRGd_N1Op4Iu5U9JBgABXxU"]
[Thu Jul 30 14:15:17.938989 2026] [core:error] [pid 1021791:tid 1022043] [client 74.7.228.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:15:17.939014 2026] [core:error] [pid 1021791:tid 1022043] [client 74.7.228.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:15:17.939132 2026] [security2:error] [pid 1021791:tid 1022043] [client 74.7.228.38:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.wrl.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuixRGd_N1Op4Iu5U9JDwAAAYQ"]
[Thu Jul 30 14:15:17.939804 2026] [security2:error] [pid 1021791:tid 1022038] [client 74.7.228.38:36630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.wrl.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuixRGd_N1Op4Iu5U9JCwABfwk"]
[Thu Jul 30 14:15:17.979256 2026] [security2:error] [pid 1021791:tid 1021962] [client 20.215.191.139:37217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amuixRGd_N1Op4Iu5U9JEQAAATM"]
[Thu Jul 30 14:15:18.088433 2026] [security2:error] [pid 1021791:tid 1022023] [client 172.213.208.20:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuixhGd_N1Op4Iu5U9JEgAAAXA"]
[Thu Jul 30 14:15:18.300173 2026] [core:notice] [pid 1021791:tid 1021971] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:18.303988 2026] [security2:error] [pid 1021791:tid 1021971] [client 135.181.74.155:37686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-don-t-give-a-damn-about-me-and-it-s-slowly-killing-me.html"] [unique_id "amuixhGd_N1Op4Iu5U9JFAAAATw"]
[Thu Jul 30 14:15:18.407507 2026] [security2:error] [pid 1021791:tid 1021940] [client 213.152.161.181:35224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuixhGd_N1Op4Iu5U9JGgAAAR0"]
[Thu Jul 30 14:15:18.407615 2026] [security2:error] [pid 1021791:tid 1021940] [client 213.152.161.181:35224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuixhGd_N1Op4Iu5U9JGgAAAR0"]
[Thu Jul 30 14:15:18.462107 2026] [security2:error] [pid 1021791:tid 1021921] [client 144.172.114.51:44850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amuixhGd_N1Op4Iu5U9JHQAAAQo"]
[Thu Jul 30 14:15:18.745449 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.215.191.139:25563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/flower.php"] [unique_id "amuixhGd_N1Op4Iu5U9JJAAAAUI"]
[Thu Jul 30 14:15:19.137009 2026] [security2:error] [pid 1021791:tid 1022042] [client 74.248.33.8:42941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/lite.php"] [unique_id "amuixxGd_N1Op4Iu5U9JMQAAAYM"]
[Thu Jul 30 14:15:19.167531 2026] [security2:error] [pid 1021791:tid 1021954] [client 135.119.63.61:56906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/fileadmin.php"] [unique_id "amuixxGd_N1Op4Iu5U9JMgAAASs"]
[Thu Jul 30 14:15:19.242784 2026] [security2:error] [pid 1021791:tid 1021934] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuixhGd_N1Op4Iu5U9JIwABFxM"]
[Thu Jul 30 14:15:19.448944 2026] [security2:error] [pid 1021791:tid 1021944] [client 180.243.59.178:58654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuixxGd_N1Op4Iu5U9JOQAAASE"]
[Thu Jul 30 14:15:19.449097 2026] [security2:error] [pid 1021791:tid 1021944] [client 180.243.59.178:58654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuixxGd_N1Op4Iu5U9JOQAAASE"]
[Thu Jul 30 14:15:19.511563 2026] [security2:error] [pid 1021791:tid 1022048] [client 172.213.208.20:49673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/plugins.php"] [unique_id "amuixxGd_N1Op4Iu5U9JPAAAAYk"]
[Thu Jul 30 14:15:19.572422 2026] [security2:error] [pid 1021791:tid 1021929] [client 172.202.44.182:27750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/index.php"] [unique_id "amuixxGd_N1Op4Iu5U9JPgAAARI"]
[Thu Jul 30 14:15:19.633771 2026] [security2:error] [pid 1021791:tid 1021967] [client 20.215.191.139:18516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amuixxGd_N1Op4Iu5U9JQAAAATg"]
[Thu Jul 30 14:15:19.935039 2026] [security2:error] [pid 1021791:tid 1021988] [client 20.100.173.28:5599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuixxGd_N1Op4Iu5U9JQQAAAU0"]
[Thu Jul 30 14:15:19.935166 2026] [security2:error] [pid 1021791:tid 1021988] [client 20.100.173.28:5599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuixxGd_N1Op4Iu5U9JQQAAAU0"]
[Thu Jul 30 14:15:20.073068 2026] [fcgid:warn] [pid 1021791:tid 1021979] (70014)End of file found: [client 152.32.208.106:52856] mod_fcgid: can't get data from http client
[Thu Jul 30 14:15:20.319194 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.215.191.139:37240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amuiyBGd_N1Op4Iu5U9JTwAAATU"]
[Thu Jul 30 14:15:20.474764 2026] [security2:error] [pid 1021791:tid 1021943] [client 135.119.63.61:8922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filealfa.php"] [unique_id "amuiyBGd_N1Op4Iu5U9JWAAAASA"]
[Thu Jul 30 14:15:20.942036 2026] [security2:error] [pid 1021791:tid 1022002] [client 20.215.191.139:23024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amuiyBGd_N1Op4Iu5U9JZgAAAVs"]
[Thu Jul 30 14:15:21.043018 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.100.173.28:28844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuiyRGd_N1Op4Iu5U9JagAAAWc"]
[Thu Jul 30 14:15:21.043119 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.100.173.28:28844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuiyRGd_N1Op4Iu5U9JagAAAWc"]
[Thu Jul 30 14:15:21.733603 2026] [security2:error] [pid 1021791:tid 1022005] [client 135.119.63.61:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filebypass.php"] [unique_id "amuiyRGd_N1Op4Iu5U9JeQAAAV4"]
[Thu Jul 30 14:15:21.791500 2026] [fcgid:warn] [pid 1021791:tid 1021949] (70014)End of file found: [client 104.218.165.188:50148] mod_fcgid: can't get data from http client
[Thu Jul 30 14:15:21.868152 2026] [core:notice] [pid 1021791:tid 1022048] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:21.892705 2026] [core:notice] [pid 1021791:tid 1021944] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:21.925693 2026] [core:notice] [pid 1021791:tid 1021951] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:21.929123 2026] [security2:error] [pid 1021791:tid 1021951] [client 135.181.74.155:37686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-don-t-have-to-forget-your-past.html"] [unique_id "amuiyRGd_N1Op4Iu5U9JgAAAASg"]
[Thu Jul 30 14:15:22.333959 2026] [security2:error] [pid 1021791:tid 1022042] [client 20.215.191.139:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuiyhGd_N1Op4Iu5U9JigAAAYM"]
[Thu Jul 30 14:15:22.555790 2026] [security2:error] [pid 1021791:tid 1021931] [client 74.248.33.8:35608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/load.php"] [unique_id "amuiyhGd_N1Op4Iu5U9JlQAAARQ"]
[Thu Jul 30 14:15:22.793270 2026] [security2:error] [pid 1021791:tid 1021986] [client 20.100.173.28:28568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/xstelth.php"] [unique_id "amuiyhGd_N1Op4Iu5U9JmQAAAUs"]
[Thu Jul 30 14:15:22.793411 2026] [security2:error] [pid 1021791:tid 1021986] [client 20.100.173.28:28568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/xstelth.php"] [unique_id "amuiyhGd_N1Op4Iu5U9JmQAAAUs"]
[Thu Jul 30 14:15:22.813300 2026] [security2:error] [pid 1021791:tid 1022037] [client 172.202.44.182:52622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/a.php"] [unique_id "amuiyhGd_N1Op4Iu5U9JmgAAAX4"]
[Thu Jul 30 14:15:22.995749 2026] [security2:error] [pid 1021791:tid 1022028] [client 135.119.63.61:56909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filedokumenadmin.php"] [unique_id "amuiyhGd_N1Op4Iu5U9JnAAAAXU"]
[Thu Jul 30 14:15:23.239058 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.215.191.139:18534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuiyxGd_N1Op4Iu5U9JpgAAAXc"]
[Thu Jul 30 14:15:23.920171 2026] [security2:error] [pid 1021791:tid 1022036] [client 20.215.191.139:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amuiyxGd_N1Op4Iu5U9JswAAAX0"]
[Thu Jul 30 14:15:24.094444 2026] [security2:error] [pid 1021791:tid 1021953] [client 135.119.63.61:8897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filedokumenalfa.php"] [unique_id "amuizBGd_N1Op4Iu5U9JtwAAASo"]
[Thu Jul 30 14:15:24.221616 2026] [security2:error] [pid 1021791:tid 1021934] [client 189.6.88.213:52792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuizBGd_N1Op4Iu5U9JuwAAARc"]
[Thu Jul 30 14:15:24.221711 2026] [security2:error] [pid 1021791:tid 1021934] [client 189.6.88.213:52792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuizBGd_N1Op4Iu5U9JuwAAARc"]
[Thu Jul 30 14:15:24.355443 2026] [core:notice] [pid 1021791:tid 1021942] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:24.605358 2026] [proxy:error] [pid 1021791:tid 1022004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:24.605430 2026] [proxy_http:error] [pid 1021791:tid 1022004] [client 104.218.165.188:34804] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:24.606089 2026] [proxy:error] [pid 1021791:tid 1022004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:24.606136 2026] [proxy_http:error] [pid 1021791:tid 1022004] [client 104.218.165.188:34804] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:24.753454 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.100.173.28:5627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/584062352875874akp.php"] [unique_id "amuizBGd_N1Op4Iu5U9JxwAAAVA"]
[Thu Jul 30 14:15:24.753603 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.100.173.28:5627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/584062352875874akp.php"] [unique_id "amuizBGd_N1Op4Iu5U9JxwAAAVA"]
[Thu Jul 30 14:15:24.758182 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.215.191.139:37211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuizBGd_N1Op4Iu5U9JyAAAAQs"]
[Thu Jul 30 14:15:24.953178 2026] [security2:error] [pid 1021791:tid 1022042] [client 135.119.63.61:56944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filedokumenbypass.php"] [unique_id "amuizBGd_N1Op4Iu5U9JzQAAAYM"]
[Thu Jul 30 14:15:25.305904 2026] [security2:error] [pid 1021791:tid 1021956] [client 74.248.33.8:36317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-themes.php"] [unique_id "amuizRGd_N1Op4Iu5U9J1wAAAS0"]
[Thu Jul 30 14:15:25.439721 2026] [core:notice] [pid 1021791:tid 1022022] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:25.445310 2026] [security2:error] [pid 1021791:tid 1022022] [client 135.181.74.155:37686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-don-t-need-to-say-anything.html"] [unique_id "amuizRGd_N1Op4Iu5U9J2wAAAW8"]
[Thu Jul 30 14:15:25.473063 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.100.173.28:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/newfile.php"] [unique_id "amuizRGd_N1Op4Iu5U9J3AAAAS8"]
[Thu Jul 30 14:15:25.473156 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.100.173.28:49030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/newfile.php"] [unique_id "amuizRGd_N1Op4Iu5U9J3AAAAS8"]
[Thu Jul 30 14:15:25.709248 2026] [security2:error] [pid 1021791:tid 1021876] [remote 74.7.227.39:33888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amuizRGd_N1Op4Iu5U9J4QABdVQ"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:15:25.908665 2026] [security2:error] [pid 1021791:tid 1021921] [client 43.164.190.28:55344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.190.164.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.remoteworksit.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuizRGd_N1Op4Iu5U9J4AAAAQo"]
[Thu Jul 30 14:15:26.119079 2026] [security2:error] [pid 1021791:tid 1021928] [client 74.248.33.8:35639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/xda.php"] [unique_id "amuizhGd_N1Op4Iu5U9J7QAAARE"]
[Thu Jul 30 14:15:26.190704 2026] [security2:error] [pid 1021791:tid 1022041] [client 20.100.173.28:50422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/tBEZGQz.php"] [unique_id "amuizhGd_N1Op4Iu5U9J8QAAAYI"]
[Thu Jul 30 14:15:26.190863 2026] [security2:error] [pid 1021791:tid 1022041] [client 20.100.173.28:50422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/tBEZGQz.php"] [unique_id "amuizhGd_N1Op4Iu5U9J8QAAAYI"]
[Thu Jul 30 14:15:26.319130 2026] [security2:error] [pid 1021791:tid 1021937] [client 74.7.228.60:39964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "google-search.org.meg.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuizhGd_N1Op4Iu5U9J9gABGmQ"]
[Thu Jul 30 14:15:26.438915 2026] [security2:error] [pid 1021791:tid 1021941] [client 172.213.208.20:42957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuizhGd_N1Op4Iu5U9J-gAAAR4"]
[Thu Jul 30 14:15:26.585958 2026] [security2:error] [pid 1021791:tid 1022014] [client 172.237.109.114:36435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuizhGd_N1Op4Iu5U9J6wAAAWc"]
[Thu Jul 30 14:15:26.623901 2026] [security2:error] [pid 1021791:tid 1022047] [client 135.119.63.61:56959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filedokumenk.php"] [unique_id "amuizhGd_N1Op4Iu5U9J_gAAAYg"]
[Thu Jul 30 14:15:26.759967 2026] [security2:error] [pid 1021791:tid 1021957] [client 20.100.173.28:28998] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.serverkr.com"] [uri "/phpinfo"] [unique_id "amuizhGd_N1Op4Iu5U9KBQAAAS4"]
[Thu Jul 30 14:15:26.760097 2026] [security2:error] [pid 1021791:tid 1021957] [client 20.100.173.28:28998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.serverkr.com"] [uri "/phpinfo"] [unique_id "amuizhGd_N1Op4Iu5U9KBQAAAS4"]
[Thu Jul 30 14:15:27.433477 2026] [security2:error] [pid 1021791:tid 1021940] [client 20.100.173.28:49835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/drykl.php"] [unique_id "amuizxGd_N1Op4Iu5U9KFwAAAR0"]
[Thu Jul 30 14:15:27.433575 2026] [security2:error] [pid 1021791:tid 1021940] [client 20.100.173.28:49835] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/drykl.php"] [unique_id "amuizxGd_N1Op4Iu5U9KFwAAAR0"]
[Thu Jul 30 14:15:27.721761 2026] [core:notice] [pid 1021791:tid 1022040] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:27.952908 2026] [core:notice] [pid 1021791:tid 1021923] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:28.002932 2026] [security2:error] [pid 1021791:tid 1022031] [client 20.215.191.139:18550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amui0BGd_N1Op4Iu5U9KIwAAAXg"]
[Thu Jul 30 14:15:28.109887 2026] [security2:error] [pid 1021791:tid 1022017] [client 74.248.33.8:35634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/.trash7206/index.php"] [unique_id "amui0BGd_N1Op4Iu5U9KJAAAAWo"]
[Thu Jul 30 14:15:28.121080 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.100.173.28:55300] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.serverkr.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amui0BGd_N1Op4Iu5U9KJQAAASU"]
[Thu Jul 30 14:15:28.121159 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.100.173.28:55300] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.serverkr.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amui0BGd_N1Op4Iu5U9KJQAAASU"]
[Thu Jul 30 14:15:28.183484 2026] [security2:error] [pid 1021791:tid 1022003] [client 172.202.44.182:34903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amui0BGd_N1Op4Iu5U9KJgAAAVw"]
[Thu Jul 30 14:15:28.200182 2026] [security2:error] [pid 1021791:tid 1021924] [client 172.213.208.20:49686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/go.php"] [unique_id "amui0BGd_N1Op4Iu5U9KKgAAAQ0"]
[Thu Jul 30 14:15:28.223764 2026] [proxy:error] [pid 1021791:tid 1022041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:28.223847 2026] [proxy_http:error] [pid 1021791:tid 1022041] [client 104.218.165.188:34812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:28.224426 2026] [proxy:error] [pid 1021791:tid 1022041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:28.224471 2026] [proxy_http:error] [pid 1021791:tid 1022041] [client 104.218.165.188:34812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:28.246802 2026] [security2:error] [pid 1021791:tid 1021971] [client 135.119.63.61:8908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filedokumenwp.php"] [unique_id "amui0BGd_N1Op4Iu5U9KMQAAATw"]
[Thu Jul 30 14:15:28.259256 2026] [security2:error] [pid 1021791:tid 1022001] [client 144.172.114.51:41588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amui0BGd_N1Op4Iu5U9KMAAAAVo"]
[Thu Jul 30 14:15:28.369698 2026] [core:notice] [pid 1021791:tid 1022000] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:28.374319 2026] [security2:error] [pid 1021791:tid 1022000] [client 135.181.74.155:37686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-have-the-power-to-change-your-life.html"] [unique_id "amui0BGd_N1Op4Iu5U9KMgAAAVk"]
[Thu Jul 30 14:15:28.691016 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.215.191.139:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amui0BGd_N1Op4Iu5U9KPQAAASA"]
[Thu Jul 30 14:15:29.001489 2026] [security2:error] [pid 1021791:tid 1022024] [client 20.100.173.28:52264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/ls.php"] [unique_id "amui0RGd_N1Op4Iu5U9KRwAAAXE"]
[Thu Jul 30 14:15:29.001627 2026] [security2:error] [pid 1021791:tid 1022024] [client 20.100.173.28:52264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/ls.php"] [unique_id "amui0RGd_N1Op4Iu5U9KRwAAAXE"]
[Thu Jul 30 14:15:29.059761 2026] [security2:error] [pid 1021791:tid 1021988] [client 144.172.114.51:41572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amui0RGd_N1Op4Iu5U9KSAAAAU0"]
[Thu Jul 30 14:15:29.059875 2026] [security2:error] [pid 1021791:tid 1022045] [client 57.141.0.4:64600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amui0BGd_N1Op4Iu5U9KOwABhms"], referer: https://igetvape-australia.com/product/iget-one-strawberry-raspberry/
[Thu Jul 30 14:15:29.145478 2026] [security2:error] [pid 1021791:tid 1021970] [client 135.119.63.61:56940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filefuns.php"] [unique_id "amui0RGd_N1Op4Iu5U9KSwAAATs"]
[Thu Jul 30 14:15:29.338883 2026] [security2:error] [pid 1021791:tid 1021926] [client 172.202.44.182:36241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin.php"] [unique_id "amui0RGd_N1Op4Iu5U9KUAAAAQ8"]
[Thu Jul 30 14:15:29.576074 2026] [security2:error] [pid 1021791:tid 1022038] [client 172.237.109.114:43629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amui0RGd_N1Op4Iu5U9KSQAAAX8"]
[Thu Jul 30 14:15:29.727007 2026] [security2:error] [pid 1021791:tid 1022027] [client 172.213.208.20:42989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/aaa.php"] [unique_id "amui0RGd_N1Op4Iu5U9KXgAAAXQ"]
[Thu Jul 30 14:15:30.016560 2026] [security2:error] [pid 1021791:tid 1022043] [client 180.243.59.178:14021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui0hGd_N1Op4Iu5U9KZwAAAYQ"]
[Thu Jul 30 14:15:30.016708 2026] [security2:error] [pid 1021791:tid 1022043] [client 180.243.59.178:14021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui0hGd_N1Op4Iu5U9KZwAAAYQ"]
[Thu Jul 30 14:15:30.146471 2026] [security2:error] [pid 1021791:tid 1021947] [client 20.100.173.28:42028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/dx.php"] [unique_id "amui0hGd_N1Op4Iu5U9KbAAAASQ"]
[Thu Jul 30 14:15:30.146576 2026] [security2:error] [pid 1021791:tid 1021947] [client 20.100.173.28:42028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/dx.php"] [unique_id "amui0hGd_N1Op4Iu5U9KbAAAASQ"]
[Thu Jul 30 14:15:30.232928 2026] [security2:error] [pid 1021791:tid 1022030] [client 172.213.208.20:49698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/getid3-core.php"] [unique_id "amui0hGd_N1Op4Iu5U9KbQAAAXc"]
[Thu Jul 30 14:15:30.357934 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.215.191.139:20291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/xleet.php"] [unique_id "amui0hGd_N1Op4Iu5U9KcQAAAWY"]
[Thu Jul 30 14:15:30.843207 2026] [proxy:error] [pid 1021791:tid 1021795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:30.843263 2026] [proxy_http:error] [pid 1021791:tid 1021795] [remote 216.73.216.19:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:30.844026 2026] [proxy:error] [pid 1021791:tid 1021795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:30.844077 2026] [proxy_http:error] [pid 1021791:tid 1021795] [remote 216.73.216.19:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:30.864160 2026] [security2:error] [pid 1021791:tid 1021980] [client 20.100.173.28:40879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/mac.php"] [unique_id "amui0hGd_N1Op4Iu5U9KfAAAAUU"]
[Thu Jul 30 14:15:30.864269 2026] [security2:error] [pid 1021791:tid 1021980] [client 20.100.173.28:40879] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/mac.php"] [unique_id "amui0hGd_N1Op4Iu5U9KfAAAAUU"]
[Thu Jul 30 14:15:31.187238 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.215.191.139:22993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-config-sample.php"] [unique_id "amui0xGd_N1Op4Iu5U9KgwAAAYk"]
[Thu Jul 30 14:15:31.228760 2026] [security2:error] [pid 1021791:tid 1021991] [client 172.213.208.20:11906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/adminer.php"] [unique_id "amui0xGd_N1Op4Iu5U9KhAAAAVA"]
[Thu Jul 30 14:15:31.387073 2026] [security2:error] [pid 1021791:tid 1022029] [client 135.119.63.61:8900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filek.php"] [unique_id "amui0xGd_N1Op4Iu5U9KjAAAAXY"]
[Thu Jul 30 14:15:31.664848 2026] [security2:error] [pid 1021791:tid 1021956] [client 20.100.173.28:29279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/485.php"] [unique_id "amui0xGd_N1Op4Iu5U9KlQAAAS0"]
[Thu Jul 30 14:15:31.664939 2026] [security2:error] [pid 1021791:tid 1021956] [client 20.100.173.28:29279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/485.php"] [unique_id "amui0xGd_N1Op4Iu5U9KlQAAAS0"]
[Thu Jul 30 14:15:32.111051 2026] [core:notice] [pid 1021791:tid 1022026] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:32.461731 2026] [security2:error] [pid 1021791:tid 1021933] [client 135.119.63.61:56911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filemanager/connectors/php/upload.php"] [unique_id "amui1BGd_N1Op4Iu5U9KpAAAARY"]
[Thu Jul 30 14:15:32.609058 2026] [security2:error] [pid 1021791:tid 1022025] [client 172.202.44.182:52615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/size.php"] [unique_id "amui1BGd_N1Op4Iu5U9KqQAAAXI"]
[Thu Jul 30 14:15:32.681427 2026] [security2:error] [pid 1021791:tid 1021947] [client 20.100.173.28:29114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/gelio1.php"] [unique_id "amui1BGd_N1Op4Iu5U9KrQAAASQ"]
[Thu Jul 30 14:15:32.681564 2026] [security2:error] [pid 1021791:tid 1021947] [client 20.100.173.28:29114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/gelio1.php"] [unique_id "amui1BGd_N1Op4Iu5U9KrQAAASQ"]
[Thu Jul 30 14:15:32.844789 2026] [security2:error] [pid 1021791:tid 1021802] [remote 216.73.217.142:49279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amui1BGd_N1Op4Iu5U9KrgABeQo"]
[Thu Jul 30 14:15:32.986794 2026] [proxy:error] [pid 1021791:tid 1021937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:32.986918 2026] [proxy_http:error] [pid 1021791:tid 1021937] [client 104.218.165.188:34822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:32.987607 2026] [proxy:error] [pid 1021791:tid 1021937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:32.987653 2026] [proxy_http:error] [pid 1021791:tid 1021937] [client 104.218.165.188:34822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:33.351255 2026] [security2:error] [pid 1021791:tid 1021975] [client 135.119.63.61:56954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filemanageradmin.php"] [unique_id "amui1RGd_N1Op4Iu5U9KvgAAAUA"]
[Thu Jul 30 14:15:33.556515 2026] [security2:error] [pid 1021791:tid 1021995] [client 213.152.161.219:40452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amui1RGd_N1Op4Iu5U9KwgAAAVQ"]
[Thu Jul 30 14:15:33.556638 2026] [security2:error] [pid 1021791:tid 1021995] [client 213.152.161.219:40452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amui1RGd_N1Op4Iu5U9KwgAAAVQ"]
[Thu Jul 30 14:15:33.981881 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.100.173.28:53050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/lp6.php"] [unique_id "amui1RGd_N1Op4Iu5U9KzQAAAVg"]
[Thu Jul 30 14:15:33.982006 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.100.173.28:53050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/lp6.php"] [unique_id "amui1RGd_N1Op4Iu5U9KzQAAAVg"]
[Thu Jul 30 14:15:34.040787 2026] [core:notice] [pid 1021791:tid 1021983] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:34.045577 2026] [security2:error] [pid 1021791:tid 1021983] [client 135.181.74.155:60476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-have-to-love-an-introvert-differently.html"] [unique_id "amui1hGd_N1Op4Iu5U9KzgAAAUg"]
[Thu Jul 30 14:15:34.050533 2026] [security2:error] [pid 1021791:tid 1022008] [client 172.202.44.182:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amui1hGd_N1Op4Iu5U9K0AAAAWE"]
[Thu Jul 30 14:15:34.112832 2026] [security2:error] [pid 1021791:tid 1022039] [client 172.213.208.20:44643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amui1hGd_N1Op4Iu5U9K0gAAAYA"]
[Thu Jul 30 14:15:34.215382 2026] [security2:error] [pid 1021791:tid 1021939] [client 135.119.63.61:8942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filemanagerbypass.php"] [unique_id "amui1hGd_N1Op4Iu5U9K2gAAARw"]
[Thu Jul 30 14:15:34.543409 2026] [security2:error] [pid 1021791:tid 1022018] [client 172.237.109.114:43142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amui1RGd_N1Op4Iu5U9KzAAAAWs"]
[Thu Jul 30 14:15:34.559468 2026] [security2:error] [pid 1021791:tid 1022011] [client 74.248.33.8:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/doc.php"] [unique_id "amui1hGd_N1Op4Iu5U9K4AAAAWQ"]
[Thu Jul 30 14:15:34.597992 2026] [security2:error] [pid 1021791:tid 1021925] [client 144.172.114.51:55364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amui1hGd_N1Op4Iu5U9K4QAAAQ4"]
[Thu Jul 30 14:15:34.806963 2026] [security2:error] [pid 1021791:tid 1021818] [remote 57.141.18.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amui1hGd_N1Op4Iu5U9K3wABEBo"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,cotton,linen,titanium,nylon,steel&min_price=300&orderby=popularity&rating=5&status=sale&tax_product_cat=electronics&unfilter=1
[Thu Jul 30 14:15:34.925056 2026] [security2:error] [pid 1021791:tid 1022028] [client 189.6.88.213:53339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amui1hGd_N1Op4Iu5U9K6AAAAXU"]
[Thu Jul 30 14:15:34.925413 2026] [security2:error] [pid 1021791:tid 1022028] [client 189.6.88.213:53339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amui1hGd_N1Op4Iu5U9K6AAAAXU"]
[Thu Jul 30 14:15:35.039557 2026] [security2:error] [pid 1021791:tid 1022043] [client 172.202.44.182:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/403.php"] [unique_id "amui1xGd_N1Op4Iu5U9K7AAAAYQ"]
[Thu Jul 30 14:15:35.239153 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.100.173.28:61168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amui1xGd_N1Op4Iu5U9K8QAAATA"]
[Thu Jul 30 14:15:35.239258 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.100.173.28:61168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amui1xGd_N1Op4Iu5U9K8QAAATA"]
[Thu Jul 30 14:15:35.251528 2026] [security2:error] [pid 1021791:tid 1022009] [client 135.119.63.61:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filemanagerk.php"] [unique_id "amui1xGd_N1Op4Iu5U9K8gAAAWI"]
[Thu Jul 30 14:15:35.449360 2026] [security2:error] [pid 1021791:tid 1021837] [remote 57.141.18.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amui1xGd_N1Op4Iu5U9K8AABWi0"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,cotton,linen,titanium,nylon,steel&min_price=300&orderby=popularity&rating=5&status=sale&tax_product_cat=electronics&unfilter=1
[Thu Jul 30 14:15:35.574838 2026] [security2:error] [pid 1021791:tid 1021941] [client 172.213.208.20:44658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/alfa.php"] [unique_id "amui1xGd_N1Op4Iu5U9K_AAAAR4"]
[Thu Jul 30 14:15:36.019786 2026] [security2:error] [pid 1021791:tid 1021973] [client 74.248.33.8:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/storage/index.php"] [unique_id "amui2BGd_N1Op4Iu5U9LBgAAAT4"]
[Thu Jul 30 14:15:36.381344 2026] [security2:error] [pid 1021791:tid 1021980] [client 172.213.208.20:37424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amui2BGd_N1Op4Iu5U9LDwAAAUU"]
[Thu Jul 30 14:15:36.607879 2026] [security2:error] [pid 1021791:tid 1021986] [client 20.100.173.28:52646] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.serverkr.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amui2BGd_N1Op4Iu5U9LEwAAAUs"]
[Thu Jul 30 14:15:36.608007 2026] [security2:error] [pid 1021791:tid 1021986] [client 20.100.173.28:52646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.serverkr.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amui2BGd_N1Op4Iu5U9LEwAAAUs"]
[Thu Jul 30 14:15:36.714347 2026] [security2:error] [pid 1021791:tid 1021961] [client 135.119.63.61:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filemanagerwp.php"] [unique_id "amui2BGd_N1Op4Iu5U9LFAAAATI"]
[Thu Jul 30 14:15:36.769192 2026] [security2:error] [pid 1021791:tid 1021962] [client 172.202.44.182:52644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amui2BGd_N1Op4Iu5U9LGAAAATM"]
[Thu Jul 30 14:15:36.827550 2026] [proxy:error] [pid 1021791:tid 1021974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:36.827627 2026] [proxy_http:error] [pid 1021791:tid 1021974] [client 104.218.165.188:53908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:36.828208 2026] [proxy:error] [pid 1021791:tid 1021974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:36.828256 2026] [proxy_http:error] [pid 1021791:tid 1021974] [client 104.218.165.188:53908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:36.947047 2026] [security2:error] [pid 1021791:tid 1021996] [client 172.213.208.20:37871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amui2BGd_N1Op4Iu5U9LHQAAAVU"]
[Thu Jul 30 14:15:37.009947 2026] [core:notice] [pid 1021791:tid 1022011] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:37.125316 2026] [security2:error] [pid 1021791:tid 1021921] [client 172.237.109.114:38929] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/slideshow-jquery-image-gallery/readme.txt"] [unique_id "amui2RGd_N1Op4Iu5U9LIwAAAQo"]
[Thu Jul 30 14:15:37.182296 2026] [security2:error] [pid 1021791:tid 1021843] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dirs.php"] [unique_id "amui2RGd_N1Op4Iu5U9LJAABazM"]
[Thu Jul 30 14:15:37.389311 2026] [security2:error] [pid 1021791:tid 1021918] [remote 216.73.217.142:49279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amui2RGd_N1Op4Iu5U9LLQABgn4"]
[Thu Jul 30 14:15:37.467171 2026] [security2:error] [pid 1021791:tid 1022039] [client 74.248.33.8:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content.php"] [unique_id "amui2RGd_N1Op4Iu5U9LLgAAAYA"]
[Thu Jul 30 14:15:37.565715 2026] [security2:error] [pid 1021791:tid 1021964] [client 172.237.109.114:5614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amui2RGd_N1Op4Iu5U9LIgAAATU"]
[Thu Jul 30 14:15:37.675225 2026] [security2:error] [pid 1021791:tid 1022014] [client 144.172.114.51:55376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amui2RGd_N1Op4Iu5U9LNAAAAWc"]
[Thu Jul 30 14:15:37.687318 2026] [security2:error] [pid 1021791:tid 1022025] [client 135.119.63.61:56922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/files.php"] [unique_id "amui2RGd_N1Op4Iu5U9LNgAAAXI"]
[Thu Jul 30 14:15:37.940802 2026] [security2:error] [pid 1021791:tid 1021814] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/disagimons.php"] [unique_id "amui2RGd_N1Op4Iu5U9LPgABKhY"]
[Thu Jul 30 14:15:38.044776 2026] [security2:error] [pid 1021791:tid 1022017] [client 172.213.208.20:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amui2hGd_N1Op4Iu5U9LPwAAAWo"]
[Thu Jul 30 14:15:38.058108 2026] [core:notice] [pid 1021791:tid 1022013] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:38.184353 2026] [security2:error] [pid 1021791:tid 1021836] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/disagraeosc.php"] [unique_id "amui2hGd_N1Op4Iu5U9LRQABiSw"]
[Thu Jul 30 14:15:38.336544 2026] [security2:error] [pid 1021791:tid 1021810] [remote 74.7.227.39:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amui2hGd_N1Op4Iu5U9LSQABhhI"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:15:38.442495 2026] [security2:error] [pid 1021791:tid 1021868] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/disagreop.php"] [unique_id "amui2hGd_N1Op4Iu5U9LTQABNEw"]
[Thu Jul 30 14:15:38.609390 2026] [security2:error] [pid 1021791:tid 1021967] [client 74.248.33.8:38110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-includes/ID3/index.php"] [unique_id "amui2hGd_N1Op4Iu5U9LTwAAATg"]
[Thu Jul 30 14:15:38.685952 2026] [security2:error] [pid 1021791:tid 1021844] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/about.php"] [unique_id "amui2hGd_N1Op4Iu5U9LUwABLTQ"]
[Thu Jul 30 14:15:38.930192 2026] [security2:error] [pid 1021791:tid 1022010] [client 135.119.63.61:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filled.php"] [unique_id "amui2hGd_N1Op4Iu5U9LVwAAAWM"]
[Thu Jul 30 14:15:38.941191 2026] [security2:error] [pid 1021791:tid 1021848] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/alfa-rex.php"] [unique_id "amui2hGd_N1Op4Iu5U9LWgABgzg"]
[Thu Jul 30 14:15:39.053768 2026] [security2:error] [pid 1021791:tid 1022037] [client 172.213.208.20:37887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/edit.php"] [unique_id "amui2xGd_N1Op4Iu5U9LXQAAAX4"]
[Thu Jul 30 14:15:39.184268 2026] [security2:error] [pid 1021791:tid 1021890] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/autoload_classmap.php"] [unique_id "amui2xGd_N1Op4Iu5U9LYQABT2I"]
[Thu Jul 30 14:15:39.443184 2026] [security2:error] [pid 1021791:tid 1021886] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/block-library/admin.php"] [unique_id "amui2xGd_N1Op4Iu5U9LawABPV4"]
[Thu Jul 30 14:15:39.687290 2026] [security2:error] [pid 1021791:tid 1021878] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/components/about.php"] [unique_id "amui2xGd_N1Op4Iu5U9LbgABgVY"]
[Thu Jul 30 14:15:39.943097 2026] [security2:error] [pid 1021791:tid 1021874] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/default.php"] [unique_id "amui2xGd_N1Op4Iu5U9LegABPlI"]
[Thu Jul 30 14:15:40.022909 2026] [security2:error] [pid 1021791:tid 1022012] [client 135.119.63.61:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/filter.php"] [unique_id "amui3BGd_N1Op4Iu5U9LggAAAWU"]
[Thu Jul 30 14:15:40.202230 2026] [security2:error] [pid 1021791:tid 1021889] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/edit-site/about.php"] [unique_id "amui3BGd_N1Op4Iu5U9LhgABNmE"]
[Thu Jul 30 14:15:40.212702 2026] [core:notice] [pid 1021791:tid 1021964] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:40.291790 2026] [security2:error] [pid 1021791:tid 1021940] [client 74.248.33.8:22629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-includes/min.php"] [unique_id "amui3BGd_N1Op4Iu5U9LiAAAAR0"]
[Thu Jul 30 14:15:40.322130 2026] [security2:error] [pid 1021791:tid 1021986] [client 20.100.173.28:54025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/w3llscc.php"] [unique_id "amui3BGd_N1Op4Iu5U9LjAAAAUs"]
[Thu Jul 30 14:15:40.322211 2026] [security2:error] [pid 1021791:tid 1021986] [client 20.100.173.28:54025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/w3llscc.php"] [unique_id "amui3BGd_N1Op4Iu5U9LjAAAAUs"]
[Thu Jul 30 14:15:40.373475 2026] [security2:error] [pid 1021791:tid 1021991] [client 172.202.44.182:52630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/as.php"] [unique_id "amui3BGd_N1Op4Iu5U9LjQAAAVA"]
[Thu Jul 30 14:15:40.445565 2026] [security2:error] [pid 1021791:tid 1021888] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/edit-widgets/about.php"] [unique_id "amui3BGd_N1Op4Iu5U9LkQABLWA"]
[Thu Jul 30 14:15:40.461799 2026] [security2:error] [pid 1021791:tid 1021994] [client 74.7.175.177:38372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bss.nyx.temporary.site"] [uri "/index.php"] [unique_id "amui2hGd_N1Op4Iu5U9LRAABUws"]
[Thu Jul 30 14:15:40.539532 2026] [core:notice] [pid 1021791:tid 1021982] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:40.543041 2026] [security2:error] [pid 1021791:tid 1021982] [client 135.181.74.155:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-keep-me-safe-and-i-ll-keep-you-wild.html"] [unique_id "amui3BGd_N1Op4Iu5U9LlQAAAUc"]
[Thu Jul 30 14:15:40.702179 2026] [security2:error] [pid 1021791:tid 1021830] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/edit-widgets/index.php"] [unique_id "amui3BGd_N1Op4Iu5U9LlgABMSY"]
[Thu Jul 30 14:15:40.789605 2026] [core:notice] [pid 1021791:tid 1021993] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:40.804669 2026] [security2:error] [pid 1021791:tid 1022010] [client 180.243.59.178:59639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui3BGd_N1Op4Iu5U9LmgAAAWM"]
[Thu Jul 30 14:15:40.804797 2026] [security2:error] [pid 1021791:tid 1022010] [client 180.243.59.178:59639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui3BGd_N1Op4Iu5U9LmgAAAWM"]
[Thu Jul 30 14:15:40.915490 2026] [security2:error] [pid 1021791:tid 1021984] [client 135.119.63.61:57940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/finley/min.php"] [unique_id "amui3BGd_N1Op4Iu5U9LnwAAAUk"]
[Thu Jul 30 14:15:40.951480 2026] [security2:error] [pid 1021791:tid 1021857] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/list-reusable-blocks/themes.php"] [unique_id "amui3BGd_N1Op4Iu5U9LoQABF0E"]
[Thu Jul 30 14:15:41.153502 2026] [proxy:error] [pid 1021791:tid 1021972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:41.153595 2026] [proxy_http:error] [pid 1021791:tid 1021972] [client 32.194.121.99:12818] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:41.154159 2026] [proxy:error] [pid 1021791:tid 1021972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:41.154202 2026] [proxy_http:error] [pid 1021791:tid 1021972] [client 32.194.121.99:12818] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:41.193265 2026] [proxy:error] [pid 1021791:tid 1021971] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:41.193347 2026] [proxy_http:error] [pid 1021791:tid 1021971] [client 32.194.121.99:48153] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:41.193925 2026] [proxy:error] [pid 1021791:tid 1021971] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:15:41.193988 2026] [proxy_http:error] [pid 1021791:tid 1021971] [client 32.194.121.99:48153] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:15:41.200005 2026] [security2:error] [pid 1021791:tid 1021870] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/niil.php"] [unique_id "amui3RGd_N1Op4Iu5U9LsAABgE4"]
[Thu Jul 30 14:15:41.444333 2026] [security2:error] [pid 1021791:tid 1021869] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/test.php"] [unique_id "amui3RGd_N1Op4Iu5U9LtwABHk0"]
[Thu Jul 30 14:15:41.627432 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.100.173.28:65016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/miru3.php"] [unique_id "amui3RGd_N1Op4Iu5U9LvwAAAWY"]
[Thu Jul 30 14:15:41.627555 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.100.173.28:65016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/miru3.php"] [unique_id "amui3RGd_N1Op4Iu5U9LvwAAAWY"]
[Thu Jul 30 14:15:41.699578 2026] [security2:error] [pid 1021791:tid 1021897] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/vendor/vcard.php"] [unique_id "amui3RGd_N1Op4Iu5U9LwAABZWk"]
[Thu Jul 30 14:15:41.949445 2026] [security2:error] [pid 1021791:tid 1021902] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/widgets/about.php"] [unique_id "amui3RGd_N1Op4Iu5U9LyQABhm4"]
[Thu Jul 30 14:15:41.949519 2026] [security2:error] [pid 1021791:tid 1022029] [client 74.248.33.8:14134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/cache.php"] [unique_id "amui3RGd_N1Op4Iu5U9LygAAAXY"]
[Thu Jul 30 14:15:42.036129 2026] [security2:error] [pid 1021791:tid 1021951] [client 135.119.63.61:9757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/fitnessbase/404.php"] [unique_id "amui3hGd_N1Op4Iu5U9LywAAASg"]
[Thu Jul 30 14:15:42.063450 2026] [core:notice] [pid 1021791:tid 1022006] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:42.391526 2026] [security2:error] [pid 1021791:tid 1021915] [remote 216.73.217.142:49279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amui3hGd_N1Op4Iu5U9L0QABMns"]
[Thu Jul 30 14:15:42.478452 2026] [security2:error] [pid 1021791:tid 1021873] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dist/wp-login.php"] [unique_id "amui3hGd_N1Op4Iu5U9L0AABeVE"]
[Thu Jul 30 14:15:42.718534 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.100.173.28:64964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/autoload_classmap.php"] [unique_id "amui3hGd_N1Op4Iu5U9L3QAAARY"]
[Thu Jul 30 14:15:42.718654 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.100.173.28:64964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/autoload_classmap.php"] [unique_id "amui3hGd_N1Op4Iu5U9L3QAAARY"]
[Thu Jul 30 14:15:42.733638 2026] [security2:error] [pid 1021791:tid 1021911] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/distadmin.php"] [unique_id "amui3hGd_N1Op4Iu5U9L3gABfnc"]
[Thu Jul 30 14:15:42.738431 2026] [security2:error] [pid 1021791:tid 1021967] [client 74.248.33.8:38080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/filemanager.php"] [unique_id "amui3hGd_N1Op4Iu5U9L3wAAATg"]
[Thu Jul 30 14:15:42.982534 2026] [security2:error] [pid 1021791:tid 1021894] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/distalfa.php"] [unique_id "amui3hGd_N1Op4Iu5U9L4QABc2Y"]
[Thu Jul 30 14:15:42.984058 2026] [security2:error] [pid 1021791:tid 1021987] [client 135.119.63.61:57979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/fitnessbase/crp.php"] [unique_id "amui3hGd_N1Op4Iu5U9L4gAAAUw"]
[Thu Jul 30 14:15:43.230720 2026] [security2:error] [pid 1021791:tid 1021795] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/distbypass.php"] [unique_id "amui3xGd_N1Op4Iu5U9L8gABgQM"]
[Thu Jul 30 14:15:43.273446 2026] [security2:error] [pid 1021791:tid 1021792] [remote 57.141.0.44:57424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/5351135361/feed/rss2/"] [unique_id "amui3xGd_N1Op4Iu5U9L9AABFwA"]
[Thu Jul 30 14:15:43.283368 2026] [security2:error] [pid 1021791:tid 1021913] [remote 57.141.0.8:54200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amui3xGd_N1Op4Iu5U9L9QABenk"]
[Thu Jul 30 14:15:43.446202 2026] [security2:error] [pid 1021791:tid 1022025] [client 172.202.44.182:28114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amui3xGd_N1Op4Iu5U9L-QAAAXI"]
[Thu Jul 30 14:15:43.481619 2026] [security2:error] [pid 1021791:tid 1021793] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/distk.php"] [unique_id "amui3xGd_N1Op4Iu5U9L_AABHgE"]
[Thu Jul 30 14:15:43.617053 2026] [core:notice] [pid 1021791:tid 1021922] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:43.620530 2026] [security2:error] [pid 1021791:tid 1021922] [client 135.181.74.155:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-ll-never-get-over-him-if-you-talk-to-him-every-day.html"] [unique_id "amui3xGd_N1Op4Iu5U9MAwAAAQs"]
[Thu Jul 30 14:15:43.719053 2026] [security2:error] [pid 1021791:tid 1022000] [client 74.248.33.8:38138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-blog.php"] [unique_id "amui3xGd_N1Op4Iu5U9MBQAAAVk"]
[Thu Jul 30 14:15:43.734111 2026] [security2:error] [pid 1021791:tid 1021813] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/distwp.php"] [unique_id "amui3xGd_N1Op4Iu5U9MBgABdhU"]
[Thu Jul 30 14:15:43.984797 2026] [security2:error] [pid 1021791:tid 1021883] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/doc.php"] [unique_id "amui3xGd_N1Op4Iu5U9MCAABb1s"]
[Thu Jul 30 14:15:44.098163 2026] [security2:error] [pid 1021791:tid 1022012] [client 135.119.63.61:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/fitnessbase/dev.php"] [unique_id "amui4BGd_N1Op4Iu5U9MEAAAAWU"]
[Thu Jul 30 14:15:44.236249 2026] [security2:error] [pid 1021791:tid 1021801] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/docadmin.php"] [unique_id "amui4BGd_N1Op4Iu5U9MFQABFAk"]
[Thu Jul 30 14:15:44.486735 2026] [security2:error] [pid 1021791:tid 1021799] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/docalfa.php"] [unique_id "amui4BGd_N1Op4Iu5U9MGAABLwc"]
[Thu Jul 30 14:15:44.737655 2026] [security2:error] [pid 1021791:tid 1021808] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/docbypass.php"] [unique_id "amui4BGd_N1Op4Iu5U9MHQABRhA"]
[Thu Jul 30 14:15:44.935465 2026] [security2:error] [pid 1021791:tid 1021928] [client 20.100.173.28:5529] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.serverkr.com"] [uri "/wp-content/"] [unique_id "amui4BGd_N1Op4Iu5U9MJwAAARE"]
[Thu Jul 30 14:15:44.935554 2026] [security2:error] [pid 1021791:tid 1021928] [client 20.100.173.28:5529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.serverkr.com"] [uri "/wp-content/"] [unique_id "amui4BGd_N1Op4Iu5U9MJwAAARE"]
[Thu Jul 30 14:15:44.987767 2026] [security2:error] [pid 1021791:tid 1021811] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/docindex.php"] [unique_id "amui4BGd_N1Op4Iu5U9MKwABdxM"]
[Thu Jul 30 14:15:45.185578 2026] [security2:error] [pid 1021791:tid 1021939] [client 172.213.208.20:52681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/file5.php"] [unique_id "amui4RGd_N1Op4Iu5U9MMQAAARw"]
[Thu Jul 30 14:15:45.238559 2026] [security2:error] [pid 1021791:tid 1021809] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/dock.php"] [unique_id "amui4RGd_N1Op4Iu5U9MMwABchE"]
[Thu Jul 30 14:15:45.300766 2026] [security2:error] [pid 1021791:tid 1021932] [client 74.248.33.8:14092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/xmlrpc.php"] [unique_id "amui4RGd_N1Op4Iu5U9MLQAAARU"]
[Thu Jul 30 14:15:45.426212 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.100.173.28:63448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/wp-content/themes/index.php"] [unique_id "amui4RGd_N1Op4Iu5U9MOAAAASE"]
[Thu Jul 30 14:15:45.426369 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.100.173.28:63448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/wp-content/themes/index.php"] [unique_id "amui4RGd_N1Op4Iu5U9MOAAAASE"]
[Thu Jul 30 14:15:45.490159 2026] [security2:error] [pid 1021791:tid 1021825] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/docsadmin.php"] [unique_id "amui4RGd_N1Op4Iu5U9MOwABeyE"]
[Thu Jul 30 14:15:45.546244 2026] [security2:error] [pid 1021791:tid 1022014] [client 189.6.88.213:53895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amui4RGd_N1Op4Iu5U9MPgAAAWc"]
[Thu Jul 30 14:15:45.546357 2026] [security2:error] [pid 1021791:tid 1022014] [client 189.6.88.213:53895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amui4RGd_N1Op4Iu5U9MPgAAAWc"]
[Thu Jul 30 14:15:45.740678 2026] [security2:error] [pid 1021791:tid 1021835] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/docsalfa.php"] [unique_id "amui4RGd_N1Op4Iu5U9MQgABWCs"]
[Thu Jul 30 14:15:45.850149 2026] [security2:error] [pid 1021791:tid 1021968] [client 172.202.44.182:28096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amui4RGd_N1Op4Iu5U9MRwAAATk"]
[Thu Jul 30 14:15:45.932373 2026] [security2:error] [pid 1021791:tid 1022036] [client 135.119.63.61:9783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/fix.php"] [unique_id "amui4RGd_N1Op4Iu5U9MSwAAAX0"]
[Thu Jul 30 14:15:46.235294 2026] [security2:error] [pid 1021791:tid 1021951] [client 74.248.33.8:22634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/cd.php"] [unique_id "amui4hGd_N1Op4Iu5U9MWAAAASg"]
[Thu Jul 30 14:15:46.486648 2026] [core:error] [pid 1021791:tid 1021974] [client 74.7.175.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:15:46.486673 2026] [core:error] [pid 1021791:tid 1021974] [client 74.7.175.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:15:46.486799 2026] [security2:error] [pid 1021791:tid 1021974] [client 74.7.175.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.wrl.gzj.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amui4hGd_N1Op4Iu5U9MXwAAAT8"]
[Thu Jul 30 14:15:46.487437 2026] [security2:error] [pid 1021791:tid 1022026] [client 74.7.175.158:49662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.wrl.gzj.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amui4hGd_N1Op4Iu5U9MWwABcyQ"]
[Thu Jul 30 14:15:46.743510 2026] [security2:error] [pid 1021791:tid 1022006] [client 172.213.208.20:52729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/sf.php"] [unique_id "amui4hGd_N1Op4Iu5U9MZgAAAV8"]
[Thu Jul 30 14:15:47.047060 2026] [security2:error] [pid 1021791:tid 1022003] [client 135.119.63.61:9750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/fix/as.php"] [unique_id "amui4xGd_N1Op4Iu5U9MaAAAAVw"]
[Thu Jul 30 14:15:47.361320 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.100.173.28:28478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/av.php"] [unique_id "amui4xGd_N1Op4Iu5U9McgAAARI"]
[Thu Jul 30 14:15:47.361437 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.100.173.28:28478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/av.php"] [unique_id "amui4xGd_N1Op4Iu5U9McgAAARI"]
[Thu Jul 30 14:15:47.518335 2026] [security2:error] [pid 1021791:tid 1021990] [client 172.202.44.182:28127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/plugins.php"] [unique_id "amui4xGd_N1Op4Iu5U9MdQAAAU8"]
[Thu Jul 30 14:15:47.655494 2026] [security2:error] [pid 1021791:tid 1021955] [client 74.248.33.8:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/css.php"] [unique_id "amui4xGd_N1Op4Iu5U9MgQAAASw"]
[Thu Jul 30 14:15:47.691893 2026] [security2:error] [pid 1021791:tid 1021968] [client 172.213.208.20:35753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wso.php"] [unique_id "amui4xGd_N1Op4Iu5U9MggAAATk"]
[Thu Jul 30 14:15:47.860276 2026] [security2:error] [pid 1021791:tid 1021856] [remote 57.141.0.63:25064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amui4xGd_N1Op4Iu5U9MhgABWUA"]
[Thu Jul 30 14:15:48.058787 2026] [core:notice] [pid 1021791:tid 1021926] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:48.063069 2026] [security2:error] [pid 1021791:tid 1021926] [client 135.181.74.155:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-look-at-her-the-way-i-look-at-you.html"] [unique_id "amui5BGd_N1Op4Iu5U9MhwAAAQ8"]
[Thu Jul 30 14:15:48.109036 2026] [security2:error] [pid 1021791:tid 1021794] [remote 216.73.217.142:12635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amui5BGd_N1Op4Iu5U9MiwABUwI"]
[Thu Jul 30 14:15:48.133275 2026] [security2:error] [pid 1021791:tid 1021942] [client 135.119.63.61:9769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/fix/up-constructor.php"] [unique_id "amui5BGd_N1Op4Iu5U9MjAAAAR8"]
[Thu Jul 30 14:15:48.850045 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.100.173.28:51395] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.serverkr.com"] [uri "/wp-includes/l10n/"] [unique_id "amui5BGd_N1Op4Iu5U9MoAAAAXc"]
[Thu Jul 30 14:15:48.850160 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.100.173.28:51395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.serverkr.com"] [uri "/wp-includes/l10n/"] [unique_id "amui5BGd_N1Op4Iu5U9MoAAAAXc"]
[Thu Jul 30 14:15:49.240559 2026] [security2:error] [pid 1021791:tid 1021928] [client 74.248.33.8:22623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/lu4.php"] [unique_id "amui5RGd_N1Op4Iu5U9MqQAAARE"]
[Thu Jul 30 14:15:49.292581 2026] [security2:error] [pid 1021791:tid 1022043] [client 135.119.63.61:57959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chicago-mfg.com"] [uri "/fix/up.php"] [unique_id "amui5RGd_N1Op4Iu5U9MqwAAAYQ"]
[Thu Jul 30 14:15:49.331436 2026] [security2:error] [pid 1021791:tid 1021964] [client 185.200.116.211:39946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amui5RGd_N1Op4Iu5U9MrwAAATU"]
[Thu Jul 30 14:15:49.331553 2026] [security2:error] [pid 1021791:tid 1021964] [client 185.200.116.211:39946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amui5RGd_N1Op4Iu5U9MrwAAATU"]
[Thu Jul 30 14:15:49.427590 2026] [security2:error] [pid 1021791:tid 1021937] [client 66.249.71.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.palmtreepools.ca"] [uri "/index.php"] [unique_id "amui5RGd_N1Op4Iu5U9MpQAAARo"]
[Thu Jul 30 14:15:49.451077 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.100.173.28:55389] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.serverkr.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amui5RGd_N1Op4Iu5U9MsAAAASE"]
[Thu Jul 30 14:15:49.451196 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.100.173.28:55389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.serverkr.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amui5RGd_N1Op4Iu5U9MsAAAASE"]
[Thu Jul 30 14:15:49.787525 2026] [security2:error] [pid 1021791:tid 1021950] [client 172.202.44.182:52629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/js/index.php"] [unique_id "amui5RGd_N1Op4Iu5U9MwwAAASc"]
[Thu Jul 30 14:15:49.789316 2026] [security2:error] [pid 1021791:tid 1022014] [client 172.213.208.20:44619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/ioxi-o.php"] [unique_id "amui5RGd_N1Op4Iu5U9MxAAAAWc"]
[Thu Jul 30 14:15:50.125469 2026] [security2:error] [pid 1021791:tid 1022029] [client 74.248.33.8:35425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "amui5hGd_N1Op4Iu5U9MyQAAAXY"]
[Thu Jul 30 14:15:50.565479 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.100.173.28:47069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/tiny.php"] [unique_id "amui5hGd_N1Op4Iu5U9M2AAAAW4"]
[Thu Jul 30 14:15:50.565604 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.100.173.28:47069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/tiny.php"] [unique_id "amui5hGd_N1Op4Iu5U9M2AAAAW4"]
[Thu Jul 30 14:15:50.572708 2026] [security2:error] [pid 1021791:tid 1021987] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.massageandspaislamabad.rest"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amui5hGd_N1Op4Iu5U9M2QAAAUw"]
[Thu Jul 30 14:15:50.640737 2026] [security2:error] [pid 1021791:tid 1021936] [client 172.213.208.20:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/file56.php"] [unique_id "amui5hGd_N1Op4Iu5U9M2gAAARk"]
[Thu Jul 30 14:15:50.923899 2026] [security2:error] [pid 1021791:tid 1022015] [client 172.202.44.182:28101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/go.php"] [unique_id "amui5hGd_N1Op4Iu5U9M6AAAAWg"]
[Thu Jul 30 14:15:50.934194 2026] [core:notice] [pid 1021791:tid 1022033] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:50.938686 2026] [security2:error] [pid 1021791:tid 1022033] [client 135.181.74.155:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/you-might-not-get-over-him.html"] [unique_id "amui5hGd_N1Op4Iu5U9M6QAAAXo"]
[Thu Jul 30 14:15:51.050316 2026] [security2:error] [pid 1021791:tid 1021971] [client 180.243.59.178:60108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui5xGd_N1Op4Iu5U9M6gAAATw"]
[Thu Jul 30 14:15:51.050459 2026] [security2:error] [pid 1021791:tid 1021971] [client 180.243.59.178:60108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui5xGd_N1Op4Iu5U9M6gAAATw"]
[Thu Jul 30 14:15:51.635208 2026] [security2:error] [pid 1021791:tid 1021946] [client 172.213.208.20:11962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amui5xGd_N1Op4Iu5U9M-AAAASM"]
[Thu Jul 30 14:15:51.890675 2026] [security2:error] [pid 1021791:tid 1021929] [client 82.102.18.180:34706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "safaratraveltours.com"] [uri "/wp-admin/index.php"] [unique_id "amui5xGd_N1Op4Iu5U9M-QAAARI"]
[Thu Jul 30 14:15:52.133958 2026] [security2:error] [pid 1021791:tid 1021961] [client 74.248.33.8:41940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/plugins/index.php"] [unique_id "amui6BGd_N1Op4Iu5U9NAwAAATI"]
[Thu Jul 30 14:15:52.248996 2026] [security2:error] [pid 1021791:tid 1022038] [client 172.202.44.182:28148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/test1.php"] [unique_id "amui6BGd_N1Op4Iu5U9NBAAAAX8"]
[Thu Jul 30 14:15:52.396883 2026] [security2:error] [pid 1021791:tid 1021867] [remote 216.73.217.142:12635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amui6BGd_N1Op4Iu5U9NCgABM0s"]
[Thu Jul 30 14:15:52.461774 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.100.173.28:58251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amui6BGd_N1Op4Iu5U9NDQAAAW4"]
[Thu Jul 30 14:15:52.461867 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.100.173.28:58251] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amui6BGd_N1Op4Iu5U9NDQAAAW4"]
[Thu Jul 30 14:15:52.647919 2026] [security2:error] [pid 1021791:tid 1021942] [client 172.213.208.20:37285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/index.php"] [unique_id "amui6BGd_N1Op4Iu5U9NEgAAAR8"]
[Thu Jul 30 14:15:52.800420 2026] [security2:error] [pid 1021791:tid 1022002] [client 74.248.33.8:41958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/upgrade/index.php"] [unique_id "amui6BGd_N1Op4Iu5U9NHQAAAVs"]
[Thu Jul 30 14:15:53.132910 2026] [security2:error] [pid 1021791:tid 1022017] [client 144.172.114.51:41328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amui6RGd_N1Op4Iu5U9NJgAAAWo"]
[Thu Jul 30 14:15:53.535115 2026] [security2:error] [pid 1021791:tid 1021995] [client 82.102.18.180:34706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amui6RGd_N1Op4Iu5U9NMQAAAVQ"]
[Thu Jul 30 14:15:53.535243 2026] [security2:error] [pid 1021791:tid 1021995] [client 82.102.18.180:34706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amui6RGd_N1Op4Iu5U9NMQAAAVQ"]
[Thu Jul 30 14:15:53.721457 2026] [core:notice] [pid 1021791:tid 1021964] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:53.964408 2026] [security2:error] [pid 1021791:tid 1021973] [client 74.248.33.8:35414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amui6RGd_N1Op4Iu5U9NPgAAAT4"]
[Thu Jul 30 14:15:53.978318 2026] [security2:error] [pid 1021791:tid 1021956] [client 172.202.44.182:28105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/images/index.php"] [unique_id "amui6RGd_N1Op4Iu5U9NPwAAAS0"]
[Thu Jul 30 14:15:53.991620 2026] [security2:error] [pid 1021791:tid 1021945] [client 172.237.109.114:65494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/l.fcgi"] [unique_id "amui6RGd_N1Op4Iu5U9NQAAAASI"]
[Thu Jul 30 14:15:54.578133 2026] [security2:error] [pid 1021791:tid 1022021] [client 74.248.33.8:35401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/ant.php"] [unique_id "amui6hGd_N1Op4Iu5U9NTAAAAW4"]
[Thu Jul 30 14:15:54.742131 2026] [core:notice] [pid 1021791:tid 1022006] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:54.759367 2026] [core:notice] [pid 1021791:tid 1021793] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:54.762364 2026] [core:notice] [pid 1021791:tid 1021943] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:54.767434 2026] [security2:error] [pid 1021791:tid 1021943] [client 135.181.74.155:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/7-different-body-types-that-reflect-how-steamy-your-sex-life-is.html"] [unique_id "amui6hGd_N1Op4Iu5U9NVQAAASA"]
[Thu Jul 30 14:15:55.199036 2026] [core:notice] [pid 1021791:tid 1022028] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:56.196612 2026] [security2:error] [pid 1021791:tid 1022041] [client 189.6.88.213:54443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.88.6.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amui7BGd_N1Op4Iu5U9NdwAAAYI"]
[Thu Jul 30 14:15:56.196702 2026] [security2:error] [pid 1021791:tid 1022041] [client 189.6.88.213:54443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amui7BGd_N1Op4Iu5U9NdwAAAYI"]
[Thu Jul 30 14:15:57.685602 2026] [core:notice] [pid 1021791:tid 1022005] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:57.690309 2026] [security2:error] [pid 1021791:tid 1022005] [client 135.181.74.155:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/10-things-that-happen-when-you-get-used-to-being-on-your-own.html"] [unique_id "amui7RGd_N1Op4Iu5U9NnwAAAV4"]
[Thu Jul 30 14:15:57.731553 2026] [security2:error] [pid 1021791:tid 1021953] [client 74.248.33.8:35422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/autoload_classmap.php"] [unique_id "amui7RGd_N1Op4Iu5U9NoQAAASo"]
[Thu Jul 30 14:15:57.893675 2026] [security2:error] [pid 1021791:tid 1022024] [client 43.173.173.74:33880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/wp/v2/posts/6558"] [unique_id "amui7RGd_N1Op4Iu5U9NpgAAAXE"]
[Thu Jul 30 14:15:58.064156 2026] [security2:error] [pid 1021791:tid 1022013] [client 43.173.176.233:35454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/30/on-va-decouvrir-la-collection-pe14-naf-naf-avec-leighton-meester/"] [unique_id "amui7RGd_N1Op4Iu5U9NpQAAAWY"]
[Thu Jul 30 14:15:58.135444 2026] [security2:error] [pid 1021791:tid 1021806] [remote 216.73.217.142:38844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amui7hGd_N1Op4Iu5U9NqAABNw4"]
[Thu Jul 30 14:15:58.189307 2026] [security2:error] [pid 1021791:tid 1021950] [client 140.245.34.60:54185] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "saifalkhaleejest.com"] [uri "/wp-json/batch/v1"] [unique_id "amui7hGd_N1Op4Iu5U9NrAAAASc"]
[Thu Jul 30 14:15:58.253754 2026] [security2:error] [pid 1021791:tid 1022020] [client 140.245.34.60:54185] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "saifalkhaleejest.com"] [uri "/"] [unique_id "amui7hGd_N1Op4Iu5U9NrQAAAW0"]
[Thu Jul 30 14:15:58.260797 2026] [core:notice] [pid 1021791:tid 1021945] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:58.499017 2026] [security2:error] [pid 1021791:tid 1021949] [client 172.202.44.182:52613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/asd.php"] [unique_id "amui7hGd_N1Op4Iu5U9NtQAAASY"]
[Thu Jul 30 14:15:58.546175 2026] [core:notice] [pid 1021791:tid 1022045] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:58.551641 2026] [security2:error] [pid 1021791:tid 1022045] [client 43.172.195.234:40616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/wp-json/wp/v2/posts/6558"] [unique_id "amui7hGd_N1Op4Iu5U9NtgAAAYY"], referer: https://carnetdeshopping.com/index.php/wp-json/wp/v2/posts/6558
[Thu Jul 30 14:15:58.900617 2026] [core:notice] [pid 1021791:tid 1021967] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:15:58.905859 2026] [security2:error] [pid 1021791:tid 1021967] [client 43.173.178.31:37852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/30/on-va-decouvrir-la-collection-pe14-naf-naf-avec-leighton-meester/"] [unique_id "amui7hGd_N1Op4Iu5U9NwQAAATg"], referer: https://carnetdeshopping.com/index.php/2014/03/30/on-va-decouvrir-la-collection-pe14-naf-naf-avec-leighton-meester/?replytocom=1193
[Thu Jul 30 14:15:59.174134 2026] [security2:error] [pid 1021791:tid 1021938] [client 74.248.33.8:36352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/storage/rip.php"] [unique_id "amui7xGd_N1Op4Iu5U9NxQAAARs"]
[Thu Jul 30 14:15:59.467150 2026] [security2:error] [pid 1021791:tid 1021940] [client 172.202.44.182:52619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amui7xGd_N1Op4Iu5U9NzgAAAR0"]
[Thu Jul 30 14:15:59.821017 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.91.199.21:31365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/--wp-lgj.php"] [unique_id "amui7xGd_N1Op4Iu5U9N2AAAAXc"]
[Thu Jul 30 14:16:00.873883 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.100.173.28:54035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/zrrhj.php"] [unique_id "amui8BGd_N1Op4Iu5U9N-AAAAYg"]
[Thu Jul 30 14:16:00.873958 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.100.173.28:54035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/zrrhj.php"] [unique_id "amui8BGd_N1Op4Iu5U9N-AAAAYg"]
[Thu Jul 30 14:16:01.096760 2026] [security2:error] [pid 1021791:tid 1021976] [client 180.243.59.178:60575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui8RGd_N1Op4Iu5U9N_AAAAUE"]
[Thu Jul 30 14:16:01.096906 2026] [security2:error] [pid 1021791:tid 1021976] [client 180.243.59.178:60575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui8RGd_N1Op4Iu5U9N_AAAAUE"]
[Thu Jul 30 14:16:01.137597 2026] [security2:error] [pid 1021791:tid 1022048] [client 172.213.208.20:34414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/edit.php"] [unique_id "amui8RGd_N1Op4Iu5U9N_QAAAYk"]
[Thu Jul 30 14:16:01.346162 2026] [security2:error] [pid 1021791:tid 1021992] [client 74.248.33.8:7491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/tinyfilemanager.php"] [unique_id "amui8RGd_N1Op4Iu5U9OBAAAAVE"]
[Thu Jul 30 14:16:01.670645 2026] [core:notice] [pid 1021791:tid 1021921] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:01.675171 2026] [security2:error] [pid 1021791:tid 1021921] [client 135.181.74.155:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/13-things-you-need-to-know-about-dating-a-gemini.html"] [unique_id "amui8RGd_N1Op4Iu5U9OCAAAAQo"]
[Thu Jul 30 14:16:01.921137 2026] [security2:error] [pid 1021791:tid 1022002] [client 20.100.173.28:28467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amui8RGd_N1Op4Iu5U9OFAAAAVs"]
[Thu Jul 30 14:16:01.921264 2026] [security2:error] [pid 1021791:tid 1022002] [client 20.100.173.28:28467] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amui8RGd_N1Op4Iu5U9OFAAAAVs"]
[Thu Jul 30 14:16:02.199737 2026] [security2:error] [pid 1021791:tid 1022046] [client 50.6.43.217:56560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amui8hGd_N1Op4Iu5U9OFgAAAYc"]
[Thu Jul 30 14:16:02.324324 2026] [security2:error] [pid 1021791:tid 1021937] [client 50.6.43.217:56570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amui8hGd_N1Op4Iu5U9OGgAAARo"]
[Thu Jul 30 14:16:02.405951 2026] [security2:error] [pid 1021791:tid 1021836] [remote 216.73.217.142:38844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amui8hGd_N1Op4Iu5U9OIQABeSw"]
[Thu Jul 30 14:16:02.564847 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.91.199.21:19372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amui8hGd_N1Op4Iu5U9OJQAAASI"]
[Thu Jul 30 14:16:02.696563 2026] [security2:error] [pid 1021791:tid 1022017] [client 172.213.208.20:43743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/2.php"] [unique_id "amui8hGd_N1Op4Iu5U9OJwAAAWo"]
[Thu Jul 30 14:16:02.750223 2026] [security2:error] [pid 1021791:tid 1022031] [client 20.100.173.28:26252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.173.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.serverkr.com"] [uri "/wpgum.php"] [unique_id "amui8hGd_N1Op4Iu5U9OKAAAAXg"]
[Thu Jul 30 14:16:02.750382 2026] [security2:error] [pid 1021791:tid 1022031] [client 20.100.173.28:26252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.serverkr.com"] [uri "/wpgum.php"] [unique_id "amui8hGd_N1Op4Iu5U9OKAAAAXg"]
[Thu Jul 30 14:16:02.828038 2026] [security2:error] [pid 1021791:tid 1021966] [client 172.202.44.182:34885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amui8hGd_N1Op4Iu5U9OKQAAATc"]
[Thu Jul 30 14:16:03.756920 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.91.199.21:25894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/flower.php"] [unique_id "amui8xGd_N1Op4Iu5U9OQwAAAVM"]
[Thu Jul 30 14:16:03.763200 2026] [security2:error] [pid 1021791:tid 1021921] [client 74.248.33.8:36363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/403.php"] [unique_id "amui8xGd_N1Op4Iu5U9ORAAAAQo"]
[Thu Jul 30 14:16:03.889572 2026] [security2:error] [pid 1021791:tid 1021989] [client 172.213.208.20:52696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amui8xGd_N1Op4Iu5U9ORwAAAU4"]
[Thu Jul 30 14:16:04.018599 2026] [security2:error] [pid 1021791:tid 1021991] [client 144.172.114.51:41338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amui8xGd_N1Op4Iu5U9OUAAAAVA"]
[Thu Jul 30 14:16:04.241484 2026] [security2:error] [pid 1021791:tid 1021939] [client 195.63.23.233:50420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amui9BGd_N1Op4Iu5U9OVQABHF4"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 14:16:04.332601 2026] [security2:error] [pid 1021791:tid 1022046] [client 20.91.199.21:24228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/xleet.php"] [unique_id "amui9BGd_N1Op4Iu5U9OVwAAAYc"]
[Thu Jul 30 14:16:04.371964 2026] [security2:error] [pid 1021791:tid 1021978] [client 172.202.44.182:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/atomlib.php"] [unique_id "amui9BGd_N1Op4Iu5U9OWAAAAUM"]
[Thu Jul 30 14:16:04.579448 2026] [security2:error] [pid 1021791:tid 1021924] [client 172.213.208.20:52727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/mah.php"] [unique_id "amui9BGd_N1Op4Iu5U9OYgAAAQ0"]
[Thu Jul 30 14:16:05.659704 2026] [security2:error] [pid 1021791:tid 1021955] [client 172.213.208.20:37987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/send.php"] [unique_id "amui9RGd_N1Op4Iu5U9OdgAAASw"]
[Thu Jul 30 14:16:05.674126 2026] [core:notice] [pid 1021791:tid 1021968] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:05.692157 2026] [security2:error] [pid 1021791:tid 1021993] [client 74.248.33.8:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/av.php"] [unique_id "amui9RGd_N1Op4Iu5U9OeAAAAVI"]
[Thu Jul 30 14:16:05.913457 2026] [core:notice] [pid 1021791:tid 1021976] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:05.964829 2026] [security2:error] [pid 1021791:tid 1021974] [client 20.91.199.21:26388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amui9RGd_N1Op4Iu5U9OegAAAT8"]
[Thu Jul 30 14:16:06.002300 2026] [core:notice] [pid 1021791:tid 1021961] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:06.007323 2026] [security2:error] [pid 1021791:tid 1021961] [client 135.181.74.155:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/15-things-that-happen-when-you-fall-in-love-with-your-life-instead-of-a-person.html"] [unique_id "amui9hGd_N1Op4Iu5U9OfgAAATI"]
[Thu Jul 30 14:16:06.152348 2026] [security2:error] [pid 1021791:tid 1022004] [client 172.202.44.182:21994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amui9hGd_N1Op4Iu5U9OiwAAAV0"]
[Thu Jul 30 14:16:06.494454 2026] [security2:error] [pid 1021791:tid 1021921] [client 74.248.33.8:7297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/tool.php"] [unique_id "amui9hGd_N1Op4Iu5U9OjgAAAQo"]
[Thu Jul 30 14:16:06.965316 2026] [security2:error] [pid 1021791:tid 1021940] [client 20.91.199.21:30584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amui9hGd_N1Op4Iu5U9OmAAAAR0"]
[Thu Jul 30 14:16:07.084604 2026] [core:notice] [pid 1021791:tid 1021942] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:07.318507 2026] [security2:error] [pid 1021791:tid 1022007] [client 172.213.208.20:11959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amui9xGd_N1Op4Iu5U9OsQAAAWA"]
[Thu Jul 30 14:16:07.370240 2026] [core:notice] [pid 1021791:tid 1022003] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:07.487745 2026] [security2:error] [pid 1021791:tid 1021979] [client 74.248.33.8:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-admin/index.php"] [unique_id "amui9xGd_N1Op4Iu5U9OtAAAAUQ"]
[Thu Jul 30 14:16:07.642063 2026] [core:notice] [pid 1021791:tid 1022024] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:07.911534 2026] [security2:error] [pid 1021791:tid 1021952] [client 20.91.199.21:26886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amui9xGd_N1Op4Iu5U9OwAAAASk"]
[Thu Jul 30 14:16:07.930925 2026] [security2:error] [pid 1021791:tid 1021983] [client 172.202.44.182:34912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/inputs.php"] [unique_id "amui9xGd_N1Op4Iu5U9OwQAAAUg"]
[Thu Jul 30 14:16:08.088077 2026] [security2:error] [pid 1021791:tid 1021911] [remote 216.73.217.142:47238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amui-BGd_N1Op4Iu5U9OxAABZ3c"]
[Thu Jul 30 14:16:08.519163 2026] [security2:error] [pid 1021791:tid 1021923] [client 144.172.114.51:50350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amui-BGd_N1Op4Iu5U9OzwAAAQw"]
[Thu Jul 30 14:16:08.738905 2026] [security2:error] [pid 1021791:tid 1021963] [client 20.91.199.21:25903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amui-BGd_N1Op4Iu5U9O2QAAATQ"]
[Thu Jul 30 14:16:08.950623 2026] [security2:error] [pid 1021791:tid 1021987] [client 172.202.44.182:34938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/index.php"] [unique_id "amui-BGd_N1Op4Iu5U9O2wAAAUw"]
[Thu Jul 30 14:16:09.535839 2026] [security2:error] [pid 1021791:tid 1021942] [client 172.213.208.20:43056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/about.php"] [unique_id "amui-RGd_N1Op4Iu5U9O5wAAAR8"]
[Thu Jul 30 14:16:09.651900 2026] [security2:error] [pid 1021791:tid 1021957] [client 150.5.132.226:59633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amui-BGd_N1Op4Iu5U9OzgAAAS4"]
[Thu Jul 30 14:16:10.357315 2026] [security2:error] [pid 1021791:tid 1022038] [client 74.248.33.8:7527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amui-hGd_N1Op4Iu5U9PAgAAAX8"]
[Thu Jul 30 14:16:11.298563 2026] [security2:error] [pid 1021791:tid 1022041] [client 74.248.33.8:36397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "amui-xGd_N1Op4Iu5U9PEwAAAYI"]
[Thu Jul 30 14:16:11.381912 2026] [security2:error] [pid 1021791:tid 1021990] [client 172.213.208.20:37428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/options.php"] [unique_id "amui-xGd_N1Op4Iu5U9PFwAAAU8"]
[Thu Jul 30 14:16:11.602948 2026] [security2:error] [pid 1021791:tid 1021935] [client 172.202.44.182:22002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/network/index.php"] [unique_id "amui-xGd_N1Op4Iu5U9PHgAAARg"]
[Thu Jul 30 14:16:11.807635 2026] [core:notice] [pid 1021791:tid 1022030] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:11.833904 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.91.199.21:18774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amui-xGd_N1Op4Iu5U9PIwAAATA"]
[Thu Jul 30 14:16:12.083238 2026] [security2:error] [pid 1021791:tid 1021978] [client 172.213.208.20:39840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/themes/index.php"] [unique_id "amui_BGd_N1Op4Iu5U9PLQAAAUM"]
[Thu Jul 30 14:16:12.249823 2026] [security2:error] [pid 1021791:tid 1021997] [client 180.243.59.178:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui_BGd_N1Op4Iu5U9PLgAAAVY"]
[Thu Jul 30 14:16:12.250001 2026] [security2:error] [pid 1021791:tid 1021997] [client 180.243.59.178:61091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amui_BGd_N1Op4Iu5U9PLgAAAVY"]
[Thu Jul 30 14:16:12.358144 2026] [core:notice] [pid 1021791:tid 1022039] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:12.361797 2026] [security2:error] [pid 1021791:tid 1022039] [client 135.181.74.155:52484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/5-easy-ways-to-trap-him-in-the-friendzone.html"] [unique_id "amui_BGd_N1Op4Iu5U9PNQAAAYA"]
[Thu Jul 30 14:16:12.463892 2026] [security2:error] [pid 1021791:tid 1022047] [client 74.248.33.8:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-trackback.php"] [unique_id "amui_BGd_N1Op4Iu5U9PPwAAAYg"]
[Thu Jul 30 14:16:12.637204 2026] [security2:error] [pid 1021791:tid 1021835] [remote 74.7.243.224:36106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amui_BGd_N1Op4Iu5U9PQAABQCs"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:16:12.726720 2026] [security2:error] [pid 1021791:tid 1022038] [client 172.213.208.20:37396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-file.php"] [unique_id "amui_BGd_N1Op4Iu5U9PQQAAAX8"]
[Thu Jul 30 14:16:12.784655 2026] [security2:error] [pid 1021791:tid 1022029] [client 20.91.199.21:34772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amui_BGd_N1Op4Iu5U9PQgAAAXY"]
[Thu Jul 30 14:16:13.204358 2026] [security2:error] [pid 1021791:tid 1021961] [client 172.202.44.182:21966] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "carnetdeshopping.com"] [uri "/wp-content/1.php"] [unique_id "amui_RGd_N1Op4Iu5U9PUAAAATI"]
[Thu Jul 30 14:16:13.204490 2026] [security2:error] [pid 1021791:tid 1021961] [client 172.202.44.182:21966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/1.php"] [unique_id "amui_RGd_N1Op4Iu5U9PUAAAATI"]
[Thu Jul 30 14:16:13.258549 2026] [security2:error] [pid 1021791:tid 1021962] [client 68.67.112.147:16399] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amui_RGd_N1Op4Iu5U9PUQAAATM"]
[Thu Jul 30 14:16:13.594095 2026] [security2:error] [pid 1021791:tid 1022041] [client 20.91.199.21:25893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amui_RGd_N1Op4Iu5U9PXAAAAYI"]
[Thu Jul 30 14:16:13.680160 2026] [security2:error] [pid 1021791:tid 1022040] [client 74.248.33.8:7547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/ws.php"] [unique_id "amui_RGd_N1Op4Iu5U9PXQAAAYE"]
[Thu Jul 30 14:16:13.927208 2026] [security2:error] [pid 1021791:tid 1022026] [client 144.172.114.51:37222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amui_RGd_N1Op4Iu5U9PYQAAAXM"]
[Thu Jul 30 14:16:14.162880 2026] [security2:error] [pid 1021791:tid 1021941] [client 20.91.199.21:32013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.wp-cli/flower.php"] [unique_id "amui_hGd_N1Op4Iu5U9PaQAAAR4"]
[Thu Jul 30 14:16:14.234288 2026] [core:notice] [pid 1021791:tid 1021851] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:14.634298 2026] [security2:error] [pid 1021791:tid 1022005] [client 74.248.33.8:53460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/0.php"] [unique_id "amui_hGd_N1Op4Iu5U9PeAAAAV4"]
[Thu Jul 30 14:16:14.689549 2026] [core:notice] [pid 1021791:tid 1021953] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:14.693581 2026] [security2:error] [pid 1021791:tid 1021953] [client 54.151.125.182:10035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/about/aboutThisPublishingSystem"] [unique_id "amui_hGd_N1Op4Iu5U9PbQAAASo"]
[Thu Jul 30 14:16:14.885257 2026] [security2:error] [pid 1021791:tid 1021960] [client 172.202.44.182:22011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/plugin.php"] [unique_id "amui_hGd_N1Op4Iu5U9PeQAAATE"]
[Thu Jul 30 14:16:15.489203 2026] [core:notice] [pid 1021791:tid 1021946] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:16.151365 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.91.199.21:25857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.wp-cli/xleet.php"] [unique_id "amujABGd_N1Op4Iu5U9PlwAAASI"]
[Thu Jul 30 14:16:16.243524 2026] [security2:error] [pid 1021791:tid 1021936] [client 172.213.208.20:42014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/sid3.php"] [unique_id "amujABGd_N1Op4Iu5U9PmAAAARk"]
[Thu Jul 30 14:16:16.541506 2026] [security2:error] [pid 1021791:tid 1022021] [client 74.248.33.8:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/1index.php"] [unique_id "amujABGd_N1Op4Iu5U9PpQAAAW4"]
[Thu Jul 30 14:16:16.889868 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.91.199.21:18769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amujABGd_N1Op4Iu5U9PqgAAASU"]
[Thu Jul 30 14:16:17.052783 2026] [proxy:error] [pid 1021791:tid 1022035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:16:17.052841 2026] [proxy_http:error] [pid 1021791:tid 1022035] [client 74.7.230.11:49718] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:16:17.053415 2026] [proxy:error] [pid 1021791:tid 1022035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:16:17.053461 2026] [proxy_http:error] [pid 1021791:tid 1022035] [client 74.7.230.11:49718] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:16:17.053567 2026] [security2:error] [pid 1021791:tid 1022035] [client 74.7.230.11:49718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.rqc.hfl.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amujARGd_N1Op4Iu5U9PrwAAAXw"]
[Thu Jul 30 14:16:17.155215 2026] [core:notice] [pid 1021791:tid 1021924] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:17.159613 2026] [security2:error] [pid 1021791:tid 1021924] [client 135.181.74.155:52484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/9-serial-killers-and-the-specific-way-they-selected-their-victims.html"] [unique_id "amujARGd_N1Op4Iu5U9PtgAAAQ0"]
[Thu Jul 30 14:16:17.322478 2026] [security2:error] [pid 1021791:tid 1022015] [client 172.213.208.20:11949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/themes.php"] [unique_id "amujARGd_N1Op4Iu5U9PuQAAAWg"]
[Thu Jul 30 14:16:17.397759 2026] [security2:error] [pid 1021791:tid 1021839] [remote 57.141.0.61:65194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amujARGd_N1Op4Iu5U9PugABRy8"]
[Thu Jul 30 14:16:17.410223 2026] [security2:error] [pid 1021791:tid 1021872] [remote 216.73.217.142:47238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amujARGd_N1Op4Iu5U9PuwABVVA"]
[Thu Jul 30 14:16:17.549394 2026] [security2:error] [pid 1021791:tid 1021979] [client 74.248.33.8:7533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/autoload_classmap/function.php"] [unique_id "amujARGd_N1Op4Iu5U9PvwAAAUQ"]
[Thu Jul 30 14:16:17.698145 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.91.199.21:19091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/flower.php"] [unique_id "amujARGd_N1Op4Iu5U9PxgAAAVQ"]
[Thu Jul 30 14:16:18.564686 2026] [security2:error] [pid 1021791:tid 1021993] [client 74.248.33.8:7493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/dvve.php"] [unique_id "amujAhGd_N1Op4Iu5U9P2AAAAVI"]
[Thu Jul 30 14:16:18.675116 2026] [security2:error] [pid 1021791:tid 1021987] [client 172.213.208.20:31057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/index.php"] [unique_id "amujAhGd_N1Op4Iu5U9P3AAAAUw"]
[Thu Jul 30 14:16:18.880769 2026] [security2:error] [pid 1021791:tid 1021994] [client 74.7.241.140:60032] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pls.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amujAhGd_N1Op4Iu5U9P4wABU1Q"]
[Thu Jul 30 14:16:19.090153 2026] [autoindex:error] [pid 1021791:tid 1021892] [remote 74.7.227.178:60188] AH01276: Cannot serve directory /home2/plsudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:16:19.132772 2026] [core:notice] [pid 1021791:tid 1021885] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:19.953825 2026] [security2:error] [pid 1021791:tid 1021930] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujAxGd_N1Op4Iu5U9P8AABE1I"]
[Thu Jul 30 14:16:20.314238 2026] [security2:error] [pid 1021791:tid 1021922] [client 172.213.208.20:11427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/images/index.php"] [unique_id "amujBBGd_N1Op4Iu5U9QEQAAAQs"]
[Thu Jul 30 14:16:20.551454 2026] [security2:error] [pid 1021791:tid 1022035] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujAxGd_N1Op4Iu5U9QAAABfEc"]
[Thu Jul 30 14:16:20.571835 2026] [security2:error] [pid 1021791:tid 1021949] [client 172.202.44.182:21570] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "carnetdeshopping.com"] [uri "/1.php"] [unique_id "amujBBGd_N1Op4Iu5U9QEgAAASY"]
[Thu Jul 30 14:16:20.571961 2026] [security2:error] [pid 1021791:tid 1021949] [client 172.202.44.182:21570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/1.php"] [unique_id "amujBBGd_N1Op4Iu5U9QEgAAASY"]
[Thu Jul 30 14:16:20.935178 2026] [security2:error] [pid 1021791:tid 1021990] [client 172.213.208.20:37383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/num.php"] [unique_id "amujBBGd_N1Op4Iu5U9QHwAAAU8"]
[Thu Jul 30 14:16:21.280790 2026] [core:notice] [pid 1021791:tid 1021994] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:21.285457 2026] [security2:error] [pid 1021791:tid 1021994] [client 135.181.74.155:52484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/a-letter-to-my-future-self.html"] [unique_id "amujBRGd_N1Op4Iu5U9QIwAAAVM"]
[Thu Jul 30 14:16:21.361520 2026] [security2:error] [pid 1021791:tid 1022020] [client 85.204.70.98:50638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "journeywomenscenter.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amujBRGd_N1Op4Iu5U9QKgAAAW0"]
[Thu Jul 30 14:16:21.517992 2026] [security2:error] [pid 1021791:tid 1021995] [client 17.22.253.204:48454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.siatfc.com"] [uri "/index.php"] [unique_id "amujBBGd_N1Op4Iu5U9QCgAAAVQ"]
[Thu Jul 30 14:16:21.975101 2026] [security2:error] [pid 1021791:tid 1022013] [client 85.204.70.98:45454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "journeywomenscenter.org"] [uri "/xmlrpc.php"] [unique_id "amujBRGd_N1Op4Iu5U9QOQAAAWY"]
[Thu Jul 30 14:16:22.061701 2026] [security2:error] [pid 1021791:tid 1021929] [client 172.202.44.182:21959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/gg.php"] [unique_id "amujBhGd_N1Op4Iu5U9QPQAAARI"]
[Thu Jul 30 14:16:22.089124 2026] [security2:error] [pid 1021791:tid 1022043] [client 20.91.199.21:26928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amujBhGd_N1Op4Iu5U9QPgAAAYQ"]
[Thu Jul 30 14:16:22.206908 2026] [security2:error] [pid 1021791:tid 1021982] [client 74.248.33.8:14599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/ws77.php"] [unique_id "amujBhGd_N1Op4Iu5U9QPwAAAUc"]
[Thu Jul 30 14:16:22.544707 2026] [security2:error] [pid 1021791:tid 1021988] [client 180.243.59.178:61568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujBhGd_N1Op4Iu5U9QSgAAAU0"]
[Thu Jul 30 14:16:22.544853 2026] [security2:error] [pid 1021791:tid 1021988] [client 180.243.59.178:61568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujBhGd_N1Op4Iu5U9QSgAAAU0"]
[Thu Jul 30 14:16:22.696856 2026] [security2:error] [pid 1021791:tid 1021961] [client 172.213.208.20:39704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amujBhGd_N1Op4Iu5U9QTwAAATI"]
[Thu Jul 30 14:16:22.787558 2026] [security2:error] [pid 1021791:tid 1022023] [client 20.91.199.21:23264] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.raad.pk"] [uri "/1.php"] [unique_id "amujBhGd_N1Op4Iu5U9QVAAAAXA"]
[Thu Jul 30 14:16:22.787690 2026] [security2:error] [pid 1021791:tid 1022023] [client 20.91.199.21:23264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/1.php"] [unique_id "amujBhGd_N1Op4Iu5U9QVAAAAXA"]
[Thu Jul 30 14:16:22.923329 2026] [core:notice] [pid 1021791:tid 1022011] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:23.094320 2026] [security2:error] [pid 1021791:tid 1021911] [remote 216.73.217.142:36300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujBxGd_N1Op4Iu5U9QZAABZ3c"]
[Thu Jul 30 14:16:23.122865 2026] [security2:error] [pid 1021791:tid 1021978] [client 74.248.33.8:7520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amujBxGd_N1Op4Iu5U9QZQAAAUM"]
[Thu Jul 30 14:16:23.160359 2026] [security2:error] [pid 1021791:tid 1022046] [client 172.202.44.182:21603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp.php"] [unique_id "amujBxGd_N1Op4Iu5U9QZwAAAYc"]
[Thu Jul 30 14:16:23.348720 2026] [security2:error] [pid 1021791:tid 1022030] [client 172.213.208.20:42022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amujBxGd_N1Op4Iu5U9QcAAAAXc"]
[Thu Jul 30 14:16:23.649339 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.91.199.21:33253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/admin.php"] [unique_id "amujBxGd_N1Op4Iu5U9QeAAAAVc"]
[Thu Jul 30 14:16:23.918890 2026] [security2:error] [pid 1021791:tid 1021960] [client 74.248.33.8:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/admin/function.php"] [unique_id "amujBxGd_N1Op4Iu5U9QgAAAATE"]
[Thu Jul 30 14:16:24.109758 2026] [security2:error] [pid 1021791:tid 1022016] [client 213.180.203.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amujBxGd_N1Op4Iu5U9QhAAAAWk"]
[Thu Jul 30 14:16:24.967070 2026] [security2:error] [pid 1021791:tid 1021962] [client 85.204.70.98:45468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "journeywomenscenter.org"] [uri "/xmlrpc.php"] [unique_id "amujCBGd_N1Op4Iu5U9QnAAAATM"]
[Thu Jul 30 14:16:24.967159 2026] [security2:error] [pid 1021791:tid 1021962] [client 85.204.70.98:45468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "journeywomenscenter.org"] [uri "/xmlrpc.php"] [unique_id "amujCBGd_N1Op4Iu5U9QnAAAATM"]
[Thu Jul 30 14:16:25.034621 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.91.199.21:29041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/as.php"] [unique_id "amujCRGd_N1Op4Iu5U9QoQAAAT4"]
[Thu Jul 30 14:16:25.530592 2026] [security2:error] [pid 1021791:tid 1021988] [client 172.202.44.182:34930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amujCRGd_N1Op4Iu5U9QqAAAAU0"]
[Thu Jul 30 14:16:25.567863 2026] [core:notice] [pid 1021791:tid 1021932] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:25.571376 2026] [security2:error] [pid 1021791:tid 1021932] [client 135.181.74.155:52484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/a-reminder-to-my-best-friends.html"] [unique_id "amujCRGd_N1Op4Iu5U9QrAAAARU"]
[Thu Jul 30 14:16:26.839164 2026] [security2:error] [pid 1021791:tid 1021942] [client 74.248.33.8:14625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-admin/css/index.php"] [unique_id "amujChGd_N1Op4Iu5U9QxwAAAR8"]
[Thu Jul 30 14:16:26.954236 2026] [core:notice] [pid 1021791:tid 1021832] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:27.121856 2026] [security2:error] [pid 1021791:tid 1022032] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujChGd_N1Op4Iu5U9QvwABeRE"]
[Thu Jul 30 14:16:27.336280 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.91.199.21:30547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/autoload_classmap.php"] [unique_id "amujCxGd_N1Op4Iu5U9Q1QAAAVQ"]
[Thu Jul 30 14:16:27.420642 2026] [security2:error] [pid 1021791:tid 1021806] [remote 216.73.217.142:36300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujCxGd_N1Op4Iu5U9Q1gABTw4"]
[Thu Jul 30 14:16:28.067374 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.91.199.21:33262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/back.php"] [unique_id "amujDBGd_N1Op4Iu5U9Q5wAAAVA"]
[Thu Jul 30 14:16:28.294123 2026] [security2:error] [pid 1021791:tid 1021969] [client 172.213.208.20:42046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "amujDBGd_N1Op4Iu5U9Q8AAAATo"]
[Thu Jul 30 14:16:28.459154 2026] [security2:error] [pid 1021791:tid 1021998] [client 74.248.33.8:7323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/xx.php"] [unique_id "amujDBGd_N1Op4Iu5U9Q9AAAAVc"]
[Thu Jul 30 14:16:28.544747 2026] [security2:error] [pid 1021791:tid 1022021] [client 172.202.44.182:21998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/file.php"] [unique_id "amujDBGd_N1Op4Iu5U9Q-AAAAW4"]
[Thu Jul 30 14:16:28.653306 2026] [security2:error] [pid 1021791:tid 1021996] [client 20.91.199.21:26331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/c/autoload_classmap.php"] [unique_id "amujDBGd_N1Op4Iu5U9Q_QAAAVU"]
[Thu Jul 30 14:16:28.975477 2026] [security2:error] [pid 1021791:tid 1021817] [remote 57.141.0.67:64390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/9525"] [unique_id "amujDBGd_N1Op4Iu5U9RBAABNhk"]
[Thu Jul 30 14:16:29.601032 2026] [security2:error] [pid 1021791:tid 1022023] [client 20.91.199.21:31044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/c/flower.php"] [unique_id "amujDRGd_N1Op4Iu5U9REgAAAXA"]
[Thu Jul 30 14:16:29.863990 2026] [security2:error] [pid 1021791:tid 1021986] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amujDRGd_N1Op4Iu5U9RGAAAAUs"]
[Thu Jul 30 14:16:30.543129 2026] [security2:error] [pid 1021791:tid 1021963] [client 172.202.44.182:34913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/user/index.php"] [unique_id "amujDhGd_N1Op4Iu5U9RJQAAATQ"]
[Thu Jul 30 14:16:30.841011 2026] [security2:error] [pid 1021791:tid 1021959] [client 172.213.208.20:37392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/gifclass.php"] [unique_id "amujDhGd_N1Op4Iu5U9RLwAAATA"]
[Thu Jul 30 14:16:31.615844 2026] [security2:error] [pid 1021791:tid 1022018] [client 47.128.122.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amujDxGd_N1Op4Iu5U9RPQAAAWs"]
[Thu Jul 30 14:16:31.683134 2026] [security2:error] [pid 1021791:tid 1022025] [client 172.213.208.20:37400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amujDxGd_N1Op4Iu5U9RQgAAAXI"]
[Thu Jul 30 14:16:31.782376 2026] [security2:error] [pid 1021791:tid 1022010] [client 213.152.161.181:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amujDxGd_N1Op4Iu5U9RRwAAAWM"]
[Thu Jul 30 14:16:31.782462 2026] [security2:error] [pid 1021791:tid 1022010] [client 213.152.161.181:39270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amujDxGd_N1Op4Iu5U9RRwAAAWM"]
[Thu Jul 30 14:16:32.135189 2026] [security2:error] [pid 1021791:tid 1022002] [client 20.91.199.21:33301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/c/xleet.php"] [unique_id "amujEBGd_N1Op4Iu5U9RTQAAAVs"]
[Thu Jul 30 14:16:32.424801 2026] [core:notice] [pid 1021791:tid 1021986] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:32.582755 2026] [core:notice] [pid 1021791:tid 1022027] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:32.653986 2026] [security2:error] [pid 1021791:tid 1021836] [remote 57.141.0.45:36006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amujEBGd_N1Op4Iu5U9RXwABSiw"]
[Thu Jul 30 14:16:32.768737 2026] [security2:error] [pid 1021791:tid 1021973] [client 180.243.59.178:62073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujEBGd_N1Op4Iu5U9RZAAAAT4"]
[Thu Jul 30 14:16:32.768857 2026] [security2:error] [pid 1021791:tid 1021973] [client 180.243.59.178:62073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujEBGd_N1Op4Iu5U9RZAAAAT4"]
[Thu Jul 30 14:16:33.096329 2026] [security2:error] [pid 1021791:tid 1021848] [remote 57.141.0.33:54140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amujERGd_N1Op4Iu5U9RawABbTg"]
[Thu Jul 30 14:16:33.272494 2026] [security2:error] [pid 1021791:tid 1022030] [client 85.208.96.200:60530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/17/sergio-cabral-tem-23-condenacoes-que-somam-430-anos-prisao-dele-foi-revogada-pela-2a-turma-do-stf/"] [unique_id "amujERGd_N1Op4Iu5U9RbwAAAXc"]
[Thu Jul 30 14:16:33.272616 2026] [security2:error] [pid 1021791:tid 1022030] [client 85.208.96.200:60530] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/17/sergio-cabral-tem-23-condenacoes-que-somam-430-anos-prisao-dele-foi-revogada-pela-2a-turma-do-stf/"] [unique_id "amujERGd_N1Op4Iu5U9RbwAAAXc"]
[Thu Jul 30 14:16:33.289489 2026] [security2:error] [pid 1021791:tid 1021908] [remote 216.73.217.142:8553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amujERGd_N1Op4Iu5U9RcgABXHQ"]
[Thu Jul 30 14:16:33.677651 2026] [security2:error] [pid 1021791:tid 1021972] [client 74.248.33.8:7897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/about.php"] [unique_id "amujERGd_N1Op4Iu5U9RdwAAAT0"]
[Thu Jul 30 14:16:33.859627 2026] [core:notice] [pid 1021791:tid 1022018] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:33.864453 2026] [security2:error] [pid 1021791:tid 1022018] [client 135.181.74.155:47934] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/how-to-live-with-your-ex-after-you-break-up.html"] [unique_id "amujERGd_N1Op4Iu5U9RgAAAAWs"]
[Thu Jul 30 14:16:33.874209 2026] [security2:error] [pid 1021791:tid 1021979] [client 144.172.114.51:55510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amujERGd_N1Op4Iu5U9RfgAAAUQ"]
[Thu Jul 30 14:16:34.042541 2026] [security2:error] [pid 1021791:tid 1021980] [client 172.213.208.20:37390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/css/index.php"] [unique_id "amujEhGd_N1Op4Iu5U9RhgAAAUU"]
[Thu Jul 30 14:16:34.355393 2026] [security2:error] [pid 1021791:tid 1021961] [client 74.248.33.8:7308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-includes/assets/index.php"] [unique_id "amujEhGd_N1Op4Iu5U9RjQAAATI"]
[Thu Jul 30 14:16:34.584688 2026] [security2:error] [pid 1021791:tid 1022019] [client 172.213.208.20:11967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-cron.php"] [unique_id "amujEhGd_N1Op4Iu5U9RlwAAAWw"]
[Thu Jul 30 14:16:35.329456 2026] [security2:error] [pid 1021791:tid 1022036] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amujEhGd_N1Op4Iu5U9RmgAAAX0"]
[Thu Jul 30 14:16:35.689367 2026] [core:notice] [pid 1021791:tid 1021993] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:35.925456 2026] [security2:error] [pid 1021791:tid 1021988] [client 172.202.44.182:52614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amujExGd_N1Op4Iu5U9RvAAAAU0"]
[Thu Jul 30 14:16:37.065573 2026] [security2:error] [pid 1021791:tid 1022011] [client 20.91.199.21:27561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/classwithtostring.php"] [unique_id "amujFRGd_N1Op4Iu5U9R4AAAAWQ"]
[Thu Jul 30 14:16:37.438462 2026] [security2:error] [pid 1021791:tid 1021913] [remote 216.73.217.142:8553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujFRGd_N1Op4Iu5U9R5QABYXk"]
[Thu Jul 30 14:16:37.862062 2026] [security2:error] [pid 1021791:tid 1022007] [client 172.202.44.182:21981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index/function.php"] [unique_id "amujFRGd_N1Op4Iu5U9R7QAAAWA"]
[Thu Jul 30 14:16:37.875206 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.91.199.21:19133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/content.php"] [unique_id "amujFRGd_N1Op4Iu5U9R7gAAAVM"]
[Thu Jul 30 14:16:38.585384 2026] [security2:error] [pid 1021791:tid 1021929] [client 144.172.114.51:55522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amujFhGd_N1Op4Iu5U9R-wAAARI"]
[Thu Jul 30 14:16:38.827824 2026] [security2:error] [pid 1021791:tid 1021968] [client 74.248.33.8:8150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-the.php"] [unique_id "amujFhGd_N1Op4Iu5U9SAwAAATk"]
[Thu Jul 30 14:16:38.974750 2026] [security2:error] [pid 1021791:tid 1021996] [client 85.208.96.212:22184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/robots.txt"] [unique_id "amujFhGd_N1Op4Iu5U9SBAAAAVU"]
[Thu Jul 30 14:16:38.974888 2026] [security2:error] [pid 1021791:tid 1021996] [client 85.208.96.212:22184] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/robots.txt"] [unique_id "amujFhGd_N1Op4Iu5U9SBAAAAVU"]
[Thu Jul 30 14:16:39.155647 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.91.199.21:19320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/doc.php"] [unique_id "amujFxGd_N1Op4Iu5U9SCwAAAVg"]
[Thu Jul 30 14:16:39.771841 2026] [security2:error] [pid 1021791:tid 1022048] [client 85.208.96.211:65004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/service-page/8-weeks-coaching"] [unique_id "amujFxGd_N1Op4Iu5U9SGAAAAYk"]
[Thu Jul 30 14:16:39.771967 2026] [security2:error] [pid 1021791:tid 1022048] [client 85.208.96.211:65004] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/service-page/8-weeks-coaching"] [unique_id "amujFxGd_N1Op4Iu5U9SGAAAAYk"]
[Thu Jul 30 14:16:39.844827 2026] [security2:error] [pid 1021791:tid 1022029] [client 144.172.114.51:55530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amujFxGd_N1Op4Iu5U9SGQAAAXY"]
[Thu Jul 30 14:16:40.440432 2026] [core:notice] [pid 1021791:tid 1021937] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:40.716403 2026] [core:notice] [pid 1021791:tid 1022030] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:40.902069 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.91.199.21:30344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/dropdown.php"] [unique_id "amujGBGd_N1Op4Iu5U9SNAAAASA"]
[Thu Jul 30 14:16:40.955119 2026] [security2:error] [pid 1021791:tid 1021933] [client 172.202.44.182:21588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/aaa.php"] [unique_id "amujGBGd_N1Op4Iu5U9SNQAAARY"]
[Thu Jul 30 14:16:40.958204 2026] [core:notice] [pid 1021791:tid 1022043] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:40.962457 2026] [security2:error] [pid 1021791:tid 1022043] [client 135.181.74.155:47944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/it-s-never-too-late-to-start-over.html"] [unique_id "amujGBGd_N1Op4Iu5U9SNgAAAYQ"]
[Thu Jul 30 14:16:41.046612 2026] [security2:error] [pid 1021791:tid 1022000] [client 74.7.241.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.pkf.com.jo"] [uri "/cgi-sys/404.html"] [unique_id "amujGRGd_N1Op4Iu5U9SOgAAAVk"]
[Thu Jul 30 14:16:41.047240 2026] [security2:error] [pid 1021791:tid 1021935] [client 74.7.241.174:44986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.pkf.com.jo"] [uri "/robots.txt"] [unique_id "amujGRGd_N1Op4Iu5U9SOAABGCE"]
[Thu Jul 30 14:16:41.075966 2026] [security2:error] [pid 1021791:tid 1021930] [client 74.248.33.8:7706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/ws81.php"] [unique_id "amujGRGd_N1Op4Iu5U9SOwAAARM"]
[Thu Jul 30 14:16:41.570973 2026] [security2:error] [pid 1021791:tid 1021967] [client 172.213.208.20:37266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-block.php"] [unique_id "amujGRGd_N1Op4Iu5U9SRgAAATg"]
[Thu Jul 30 14:16:41.640322 2026] [security2:error] [pid 1021791:tid 1022013] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujGBGd_N1Op4Iu5U9SNwABZig"]
[Thu Jul 30 14:16:41.832816 2026] [security2:error] [pid 1021791:tid 1021992] [client 20.91.199.21:30569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/ee.php"] [unique_id "amujGRGd_N1Op4Iu5U9SVAAAAVE"]
[Thu Jul 30 14:16:41.837335 2026] [autoindex:error] [pid 1021791:tid 1021949] [client 74.7.242.6:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:16:41.892345 2026] [security2:error] [pid 1021791:tid 1021978] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujGRGd_N1Op4Iu5U9SRQABQw4"]
[Thu Jul 30 14:16:41.960015 2026] [security2:error] [pid 1021791:tid 1021925] [client 74.248.33.8:7692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/3.php"] [unique_id "amujGRGd_N1Op4Iu5U9SVQAAAQ4"]
[Thu Jul 30 14:16:42.660332 2026] [security2:error] [pid 1021791:tid 1022007] [client 172.202.44.182:21991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/getid3-core.php"] [unique_id "amujGhGd_N1Op4Iu5U9SXwAAAWA"]
[Thu Jul 30 14:16:42.838708 2026] [security2:error] [pid 1021791:tid 1022020] [client 20.91.199.21:32249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/flower.php"] [unique_id "amujGhGd_N1Op4Iu5U9SZgAAAW0"]
[Thu Jul 30 14:16:42.842076 2026] [security2:error] [pid 1021791:tid 1022021] [client 74.248.33.8:8132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/a1.php"] [unique_id "amujGhGd_N1Op4Iu5U9SZwAAAW4"]
[Thu Jul 30 14:16:43.047964 2026] [security2:error] [pid 1021791:tid 1021991] [client 172.213.208.20:37426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "amujGxGd_N1Op4Iu5U9SbgAAAVA"]
[Thu Jul 30 14:16:43.100733 2026] [security2:error] [pid 1021791:tid 1021935] [client 180.243.59.178:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujGxGd_N1Op4Iu5U9ScgAAARg"]
[Thu Jul 30 14:16:43.100865 2026] [security2:error] [pid 1021791:tid 1021935] [client 180.243.59.178:62546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujGxGd_N1Op4Iu5U9ScgAAARg"]
[Thu Jul 30 14:16:43.516958 2026] [security2:error] [pid 1021791:tid 1022034] [client 74.248.33.8:7930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/ca5.php"] [unique_id "amujGxGd_N1Op4Iu5U9SfAAAAXs"]
[Thu Jul 30 14:16:43.596937 2026] [security2:error] [pid 1021791:tid 1021999] [client 172.202.44.182:21569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/adminer.php"] [unique_id "amujGxGd_N1Op4Iu5U9SfQAAAVg"]
[Thu Jul 30 14:16:44.495998 2026] [security2:error] [pid 1021791:tid 1021927] [client 74.248.33.8:18287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/install.php"] [unique_id "amujHBGd_N1Op4Iu5U9SlAAAARA"]
[Thu Jul 30 14:16:44.611737 2026] [security2:error] [pid 1021791:tid 1022014] [client 144.172.114.51:45040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[$]{[\\\\w{}\\\\-:$]*j[\\\\w{}\\\\-:$]*n[\\\\w{}\\\\-:$]*d[\\\\w{}\\\\-:$]*i[\\\\w{}\\\\-:$]*:.*}" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1535"] [id "345117"] [rev "2"] [msg "Atomicorp.com WAF Rules - Virtual Just In Time Patch: log4j CVE-2021-44228 broad scope obfuscated attack blocked"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/"] [unique_id "amujHBGd_N1Op4Iu5U9SlgAAAWc"]
[Thu Jul 30 14:16:44.892397 2026] [security2:error] [pid 1021791:tid 1021946] [client 20.91.199.21:19280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/gecko-new.php"] [unique_id "amujHBGd_N1Op4Iu5U9SmgAAASM"]
[Thu Jul 30 14:16:44.895665 2026] [core:notice] [pid 1021791:tid 1021963] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:44.899296 2026] [security2:error] [pid 1021791:tid 1021963] [client 135.181.74.155:47944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/da-sub/meet-setsu-chan-the-cat-with-the-best-so-ugly-it-s-cute-sleepy-face-in-the-world.html"] [unique_id "amujHBGd_N1Op4Iu5U9SmwAAATQ"]
[Thu Jul 30 14:16:45.346616 2026] [security2:error] [pid 1021791:tid 1021998] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amujHRGd_N1Op4Iu5U9SpAAAAVc"]
[Thu Jul 30 14:16:45.467706 2026] [security2:error] [pid 1021791:tid 1021969] [client 74.248.33.8:18303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/radio.php"] [unique_id "amujHRGd_N1Op4Iu5U9SpwAAATo"]
[Thu Jul 30 14:16:45.714857 2026] [security2:error] [pid 1021791:tid 1022036] [client 20.91.199.21:32203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/m.php"] [unique_id "amujHRGd_N1Op4Iu5U9SrgAAAX0"]
[Thu Jul 30 14:16:45.965413 2026] [security2:error] [pid 1021791:tid 1021985] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujHRGd_N1Op4Iu5U9SogABSjA"]
[Thu Jul 30 14:16:47.249609 2026] [security2:error] [pid 1021791:tid 1021972] [client 74.248.33.8:18249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-signin.php"] [unique_id "amujHxGd_N1Op4Iu5U9S0QAAAT0"]
[Thu Jul 30 14:16:47.510340 2026] [security2:error] [pid 1021791:tid 1021949] [client 43.135.183.82:49960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.183.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adbacklink.com"] [uri "/theme/darm_theme_basic01/page_html/online_form.php"] [unique_id "amujHxGd_N1Op4Iu5U9S0gAAASY"]
[Thu Jul 30 14:16:47.799706 2026] [security2:error] [pid 1021791:tid 1021944] [client 172.213.208.20:35717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/classwithtostring.php"] [unique_id "amujHxGd_N1Op4Iu5U9S6AAAASE"]
[Thu Jul 30 14:16:48.035898 2026] [security2:error] [pid 1021791:tid 1021876] [remote 45.119.213.111:40814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.213.119.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dov.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amujHxGd_N1Op4Iu5U9S5wABJ1Q"]
[Thu Jul 30 14:16:48.263280 2026] [security2:error] [pid 1021791:tid 1021929] [client 74.248.33.8:39396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/Ov-Simple1.php"] [unique_id "amujIBGd_N1Op4Iu5U9S8gAAARI"]
[Thu Jul 30 14:16:48.319255 2026] [fcgid:warn] [pid 1021791:tid 1022005] (70014)End of file found: [client 152.32.208.73:52802] mod_fcgid: can't get data from http client
[Thu Jul 30 14:16:48.524137 2026] [security2:error] [pid 1021791:tid 1021930] [client 172.213.208.20:37414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/test1.php"] [unique_id "amujIBGd_N1Op4Iu5U9S-AAAARM"]
[Thu Jul 30 14:16:48.996187 2026] [security2:error] [pid 1021791:tid 1022007] [client 74.7.230.61:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amujHxGd_N1Op4Iu5U9S5gAAAWA"]
[Thu Jul 30 14:16:48.997036 2026] [security2:error] [pid 1021791:tid 1021978] [client 74.7.230.61:37018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ubp.hmu.temporary.site"] [uri "/robots.txt"] [unique_id "amujHxGd_N1Op4Iu5U9S5AABQ0M"]
[Thu Jul 30 14:16:49.670576 2026] [security2:error] [pid 1021791:tid 1022042] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amujIRGd_N1Op4Iu5U9TBQAAAYM"]
[Thu Jul 30 14:16:50.096889 2026] [security2:error] [pid 1021791:tid 1021948] [client 172.213.208.20:52722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/images/index.php"] [unique_id "amujIhGd_N1Op4Iu5U9THwAAASU"]
[Thu Jul 30 14:16:50.259042 2026] [core:notice] [pid 1021791:tid 1022014] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:50.372126 2026] [core:notice] [pid 1021791:tid 1021985] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:50.377170 2026] [core:notice] [pid 1021791:tid 1021944] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:50.378282 2026] [security2:error] [pid 1021791:tid 1021944] [client 135.181.74.155:59184] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amujIhGd_N1Op4Iu5U9TLAAAASE"]
[Thu Jul 30 14:16:50.491127 2026] [security2:error] [pid 1021791:tid 1021956] [client 172.202.44.182:21990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/alfa.php"] [unique_id "amujIhGd_N1Op4Iu5U9TMAAAAS0"]
[Thu Jul 30 14:16:50.696818 2026] [security2:error] [pid 1021791:tid 1021951] [client 20.91.199.21:30572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/mah/autoload_classmap.php"] [unique_id "amujIhGd_N1Op4Iu5U9TMQAAASg"]
[Thu Jul 30 14:16:50.733823 2026] [security2:error] [pid 1021791:tid 1022020] [client 74.248.33.8:39374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/fm.php"] [unique_id "amujIhGd_N1Op4Iu5U9TNgAAAW0"]
[Thu Jul 30 14:16:50.840074 2026] [core:notice] [pid 1021791:tid 1022005] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:50.844707 2026] [security2:error] [pid 1021791:tid 1022005] [client 135.181.74.155:59188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/17-men-on-what-gives-them-second-thoughts-after-a-breakup.html"] [unique_id "amujIhGd_N1Op4Iu5U9TPgAAAV4"]
[Thu Jul 30 14:16:50.847906 2026] [security2:error] [pid 1021791:tid 1021979] [client 144.172.114.51:45046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amujIhGd_N1Op4Iu5U9TPQAAAUQ"]
[Thu Jul 30 14:16:50.885713 2026] [security2:error] [pid 1021791:tid 1022018] [client 172.213.208.20:44621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/asd.php"] [unique_id "amujIhGd_N1Op4Iu5U9TPwAAAWs"]
[Thu Jul 30 14:16:51.535104 2026] [core:notice] [pid 1021791:tid 1021974] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:51.671469 2026] [security2:error] [pid 1021791:tid 1022009] [client 172.213.208.20:11913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amujIxGd_N1Op4Iu5U9TSwAAAWI"]
[Thu Jul 30 14:16:51.775834 2026] [security2:error] [pid 1021791:tid 1022013] [client 172.202.44.182:21651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amujIxGd_N1Op4Iu5U9TTwAAAWY"]
[Thu Jul 30 14:16:52.289702 2026] [security2:error] [pid 1021791:tid 1021992] [client 74.248.33.8:33224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/ftde.php"] [unique_id "amujJBGd_N1Op4Iu5U9TWQAAAVE"]
[Thu Jul 30 14:16:52.458166 2026] [security2:error] [pid 1021791:tid 1021925] [client 118.194.249.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.tfy.udi.temporary.site"] [uri "/index.php"] [unique_id "amujJBGd_N1Op4Iu5U9TXwAAAQ4"]
[Thu Jul 30 14:16:52.727042 2026] [security2:error] [pid 1021791:tid 1021963] [client 172.202.44.182:22277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amujJBGd_N1Op4Iu5U9TZAAAATQ"]
[Thu Jul 30 14:16:52.990171 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.91.199.21:31605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/mah/flower.php"] [unique_id "amujJBGd_N1Op4Iu5U9TdAAAAQs"]
[Thu Jul 30 14:16:53.280895 2026] [security2:error] [pid 1021791:tid 1022022] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujJBGd_N1Op4Iu5U9TYwABb3Y"]
[Thu Jul 30 14:16:53.601266 2026] [security2:error] [pid 1021791:tid 1021966] [client 180.243.59.178:63068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujJRGd_N1Op4Iu5U9ThAAAATc"]
[Thu Jul 30 14:16:53.601408 2026] [security2:error] [pid 1021791:tid 1021966] [client 180.243.59.178:63068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujJRGd_N1Op4Iu5U9ThAAAATc"]
[Thu Jul 30 14:16:53.706218 2026] [security2:error] [pid 1021791:tid 1021930] [client 172.202.44.182:22327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amujJRGd_N1Op4Iu5U9ThQAAARM"]
[Thu Jul 30 14:16:53.782367 2026] [security2:error] [pid 1021791:tid 1022010] [client 20.91.199.21:28009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/mah/xleet.php"] [unique_id "amujJRGd_N1Op4Iu5U9ThgAAAWM"]
[Thu Jul 30 14:16:53.815959 2026] [security2:error] [pid 1021791:tid 1022001] [client 172.213.208.20:52685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amujJRGd_N1Op4Iu5U9ThwAAAVo"]
[Thu Jul 30 14:16:53.982370 2026] [security2:error] [pid 1021791:tid 1021831] [remote 216.73.217.142:60820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amujJRGd_N1Op4Iu5U9TkQABTyc"]
[Thu Jul 30 14:16:54.517110 2026] [security2:error] [pid 1021791:tid 1021999] [client 172.202.44.182:22314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/edit.php"] [unique_id "amujJhGd_N1Op4Iu5U9ToAAAAVg"]
[Thu Jul 30 14:16:54.703281 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.91.199.21:30557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/mini.php"] [unique_id "amujJhGd_N1Op4Iu5U9ToQAAAYU"]
[Thu Jul 30 14:16:55.242838 2026] [core:notice] [pid 1021791:tid 1022021] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:55.250551 2026] [security2:error] [pid 1021791:tid 1022021] [client 135.181.74.155:59188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/37-hot-songs-that-will-make-you-need-sex-immediately.html"] [unique_id "amujJxGd_N1Op4Iu5U9TqwAAAW4"]
[Thu Jul 30 14:16:55.328234 2026] [security2:error] [pid 1021791:tid 1021985] [client 144.172.114.51:43090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amujJxGd_N1Op4Iu5U9TrAAAAUo"]
[Thu Jul 30 14:16:55.788877 2026] [core:notice] [pid 1021791:tid 1021932] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:55.998544 2026] [security2:error] [pid 1021791:tid 1021935] [client 74.248.33.8:18255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/hplfuns.php"] [unique_id "amujJxGd_N1Op4Iu5U9TvQAAARg"]
[Thu Jul 30 14:16:56.021175 2026] [core:notice] [pid 1021791:tid 1022047] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:56.107331 2026] [security2:error] [pid 1021791:tid 1022030] [client 172.213.208.20:39680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/atomlib.php"] [unique_id "amujKBGd_N1Op4Iu5U9TwgAAAXc"]
[Thu Jul 30 14:16:56.251732 2026] [security2:error] [pid 1021791:tid 1022016] [client 172.202.44.182:22000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/sf.php"] [unique_id "amujKBGd_N1Op4Iu5U9TwwAAAWk"]
[Thu Jul 30 14:16:57.320728 2026] [security2:error] [pid 1021791:tid 1021978] [client 74.248.33.8:7697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/log.php"] [unique_id "amujKRGd_N1Op4Iu5U9T1gAAAUM"]
[Thu Jul 30 14:16:57.616555 2026] [security2:error] [pid 1021791:tid 1022042] [client 43.172.197.254:43908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/01/16/10-jolis-calendriers-2015/"] [unique_id "amujKRGd_N1Op4Iu5U9T1wAAAYM"]
[Thu Jul 30 14:16:58.239865 2026] [core:notice] [pid 1021791:tid 1022027] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:58.244323 2026] [security2:error] [pid 1021791:tid 1022027] [client 43.173.182.166:48854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/01/16/10-jolis-calendriers-2015/"] [unique_id "amujKhGd_N1Op4Iu5U9T6wAAAXQ"], referer: https://carnetdeshopping.com/index.php/2015/01/16/10-jolis-calendriers-2015/
[Thu Jul 30 14:16:59.176009 2026] [security2:error] [pid 1021791:tid 1022016] [client 172.213.208.20:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amujKxGd_N1Op4Iu5U9UAwAAAWk"]
[Thu Jul 30 14:16:59.217079 2026] [security2:error] [pid 1021791:tid 1021818] [remote 57.141.0.5:34480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amujKxGd_N1Op4Iu5U9UBwABUBo"]
[Thu Jul 30 14:16:59.228592 2026] [security2:error] [pid 1021791:tid 1021938] [client 74.248.33.8:7710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/test.php"] [unique_id "amujKxGd_N1Op4Iu5U9UCAAAARs"]
[Thu Jul 30 14:16:59.273112 2026] [core:notice] [pid 1021791:tid 1022005] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:59.326948 2026] [security2:error] [pid 1021791:tid 1021932] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujKhGd_N1Op4Iu5U9T-AABFQw"]
[Thu Jul 30 14:16:59.348476 2026] [core:notice] [pid 1021791:tid 1021998] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:16:59.352278 2026] [security2:error] [pid 1021791:tid 1021998] [client 135.181.74.155:59188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/congratulations-you-just-won-the-game.html"] [unique_id "amujKxGd_N1Op4Iu5U9UDgAAAVc"]
[Thu Jul 30 14:16:59.525061 2026] [security2:error] [pid 1021791:tid 1021995] [client 172.202.44.182:34925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wso.php"] [unique_id "amujKxGd_N1Op4Iu5U9UFQAAAVQ"]
[Thu Jul 30 14:16:59.598656 2026] [security2:error] [pid 1021791:tid 1021842] [remote 57.141.0.65:46274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amujKxGd_N1Op4Iu5U9UGQABHjI"]
[Thu Jul 30 14:16:59.910095 2026] [security2:error] [pid 1021791:tid 1022008] [client 74.248.33.8:39382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/txets.php"] [unique_id "amujKxGd_N1Op4Iu5U9UIQAAAWE"]
[Thu Jul 30 14:17:00.578852 2026] [security2:error] [pid 1021791:tid 1021931] [client 172.213.208.20:39271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/inputs.php"] [unique_id "amujLBGd_N1Op4Iu5U9UMwAAARQ"]
[Thu Jul 30 14:17:00.599782 2026] [security2:error] [pid 1021791:tid 1021969] [client 172.202.44.182:22015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/ioxi-o.php"] [unique_id "amujLBGd_N1Op4Iu5U9UNAAAATo"]
[Thu Jul 30 14:17:01.203254 2026] [security2:error] [pid 1021791:tid 1021928] [client 74.248.33.8:39381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-admin.php"] [unique_id "amujLRGd_N1Op4Iu5U9UaAAAARE"]
[Thu Jul 30 14:17:01.260293 2026] [security2:error] [pid 1021791:tid 1021830] [remote 57.141.0.8:31080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amujLRGd_N1Op4Iu5U9UaQABKSY"]
[Thu Jul 30 14:17:01.780839 2026] [security2:error] [pid 1021791:tid 1021950] [client 20.91.199.21:30894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/moon.php"] [unique_id "amujLRGd_N1Op4Iu5U9UfgAAASc"]
[Thu Jul 30 14:17:01.885291 2026] [security2:error] [pid 1021791:tid 1021938] [client 172.202.44.182:34909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/file56.php"] [unique_id "amujLRGd_N1Op4Iu5U9UhQAAARs"]
[Thu Jul 30 14:17:02.767947 2026] [security2:error] [pid 1021791:tid 1022008] [client 20.91.199.21:22985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/new.php"] [unique_id "amujLhGd_N1Op4Iu5U9UoAAAAWE"]
[Thu Jul 30 14:17:02.940003 2026] [security2:error] [pid 1021791:tid 1021933] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujLhGd_N1Op4Iu5U9UkgABFkg"]
[Thu Jul 30 14:17:03.293367 2026] [security2:error] [pid 1021791:tid 1022036] [client 172.202.44.182:22286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amujLxGd_N1Op4Iu5U9UrQAAAX0"]
[Thu Jul 30 14:17:03.375255 2026] [security2:error] [pid 1021791:tid 1022000] [client 74.248.33.8:7719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-config-sample.php"] [unique_id "amujLxGd_N1Op4Iu5U9UrwAAAVk"]
[Thu Jul 30 14:17:03.406248 2026] [security2:error] [pid 1021791:tid 1021913] [remote 57.141.0.63:61432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amujLxGd_N1Op4Iu5U9UsAABbXk"]
[Thu Jul 30 14:17:03.423289 2026] [security2:error] [pid 1021791:tid 1021891] [remote 65.181.111.156:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.111.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amujLxGd_N1Op4Iu5U9UsQABRWM"]
[Thu Jul 30 14:17:03.423443 2026] [security2:error] [pid 1021791:tid 1021980] [client 65.181.111.156:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amujLxGd_N1Op4Iu5U9UsQABRWM"]
[Thu Jul 30 14:17:04.155007 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.91.199.21:18968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/radio.php"] [unique_id "amujMBGd_N1Op4Iu5U9UyQAAAXc"]
[Thu Jul 30 14:17:04.331617 2026] [security2:error] [pid 1021791:tid 1021932] [client 74.248.33.8:7696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroup.jo"] [uri "/wp-content/packed.php"] [unique_id "amujMBGd_N1Op4Iu5U9UzQAAARU"]
[Thu Jul 30 14:17:04.856526 2026] [security2:error] [pid 1021791:tid 1022044] [client 180.243.59.178:63590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujMBGd_N1Op4Iu5U9U2wAAAYU"]
[Thu Jul 30 14:17:04.856664 2026] [security2:error] [pid 1021791:tid 1022044] [client 180.243.59.178:63590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujMBGd_N1Op4Iu5U9U2wAAAYU"]
[Thu Jul 30 14:17:04.952170 2026] [core:notice] [pid 1021791:tid 1021940] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:04.957087 2026] [security2:error] [pid 1021791:tid 1021940] [client 135.181.74.155:37016] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/how-mistypes-have-warped-the-descriptions-of-each-intuitive-mbti-type.html"] [unique_id "amujMBGd_N1Op4Iu5U9U3wAAAR0"]
[Thu Jul 30 14:17:05.076181 2026] [security2:error] [pid 1021791:tid 1021987] [client 185.200.116.219:48408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amujMRGd_N1Op4Iu5U9U5gAAAUw"]
[Thu Jul 30 14:17:05.076273 2026] [security2:error] [pid 1021791:tid 1021987] [client 185.200.116.219:48408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amujMRGd_N1Op4Iu5U9U5gAAAUw"]
[Thu Jul 30 14:17:05.132347 2026] [security2:error] [pid 1021791:tid 1022015] [client 20.91.199.21:19007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/s.php"] [unique_id "amujMRGd_N1Op4Iu5U9U6AAAAWg"]
[Thu Jul 30 14:17:05.723242 2026] [security2:error] [pid 1021791:tid 1022048] [client 172.202.44.182:34936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-admin/css/index.php"] [unique_id "amujMRGd_N1Op4Iu5U9U8gAAAYk"]
[Thu Jul 30 14:17:05.874790 2026] [core:error] [pid 1021791:tid 1022045] [client 138.197.43.1:56005] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:05.874813 2026] [core:error] [pid 1021791:tid 1022045] [client 138.197.43.1:56005] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:05.918524 2026] [core:notice] [pid 1021791:tid 1021796] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:06.036402 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.91.199.21:26101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/sim.php"] [unique_id "amujMhGd_N1Op4Iu5U9U_AAAAWA"]
[Thu Jul 30 14:17:06.293087 2026] [security2:error] [pid 1021791:tid 1021809] [remote 57.141.0.16:36088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/491057609/feed/rss2/"] [unique_id "amujMhGd_N1Op4Iu5U9VAQABGxE"]
[Thu Jul 30 14:17:06.532392 2026] [security2:error] [pid 1021791:tid 1021929] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujMRGd_N1Op4Iu5U9U-AABEiE"]
[Thu Jul 30 14:17:06.760533 2026] [security2:error] [pid 1021791:tid 1022028] [client 152.32.208.73:59298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "website-3f57df65.evk.gpl.temporary.site"] [uri "/index.php"] [unique_id "amujMhGd_N1Op4Iu5U9VDAAAAXU"]
[Thu Jul 30 14:17:06.871162 2026] [core:error] [pid 1021791:tid 1021927] [client 138.197.43.1:56015] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:06.871189 2026] [core:error] [pid 1021791:tid 1021927] [client 138.197.43.1:56015] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:07.789292 2026] [security2:error] [pid 1021791:tid 1021961] [client 172.202.44.182:52611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/edit.php"] [unique_id "amujMxGd_N1Op4Iu5U9VIQAAATI"]
[Thu Jul 30 14:17:07.942869 2026] [security2:error] [pid 1021791:tid 1021851] [remote 57.141.0.67:31900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/article/view/9881"] [unique_id "amujMxGd_N1Op4Iu5U9VIwABSTs"]
[Thu Jul 30 14:17:09.500106 2026] [security2:error] [pid 1021791:tid 1021953] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.koinjp189.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amujNRGd_N1Op4Iu5U9VSQAAASo"]
[Thu Jul 30 14:17:09.520442 2026] [security2:error] [pid 1021791:tid 1021927] [client 82.102.18.188:36398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amujNRGd_N1Op4Iu5U9VSgAAARA"]
[Thu Jul 30 14:17:09.857355 2026] [core:notice] [pid 1021791:tid 1022038] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:09.861083 2026] [security2:error] [pid 1021791:tid 1022038] [client 135.181.74.155:37016] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/i-am-so-much-more-than-just-a-pretty-face.html"] [unique_id "amujNRGd_N1Op4Iu5U9VVQAAAX8"]
[Thu Jul 30 14:17:10.107018 2026] [security2:error] [pid 1021791:tid 1021933] [client 82.102.18.188:36408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amujNhGd_N1Op4Iu5U9VWQAAARY"]
[Thu Jul 30 14:17:10.397698 2026] [security2:error] [pid 1021791:tid 1021956] [client 82.102.18.188:36410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amujNhGd_N1Op4Iu5U9VZAAAAS0"]
[Thu Jul 30 14:17:10.753956 2026] [security2:error] [pid 1021791:tid 1021936] [client 82.102.18.188:36426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amujNhGd_N1Op4Iu5U9VbgAAARk"]
[Thu Jul 30 14:17:10.770578 2026] [core:notice] [pid 1021791:tid 1021982] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:11.029948 2026] [security2:error] [pid 1021791:tid 1021958] [client 82.102.18.188:30078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amujNxGd_N1Op4Iu5U9VcAAAAS8"]
[Thu Jul 30 14:17:11.321077 2026] [security2:error] [pid 1021791:tid 1021967] [client 82.102.18.188:36438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amujNxGd_N1Op4Iu5U9VfQAAATg"]
[Thu Jul 30 14:17:11.361147 2026] [security2:error] [pid 1021791:tid 1021924] [client 103.131.71.140:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amujNxGd_N1Op4Iu5U9VeQAAAQ0"]
[Thu Jul 30 14:17:11.361842 2026] [security2:error] [pid 1021791:tid 1021955] [client 103.131.71.140:43687] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cnpinyin.com"] [uri "/robots.txt"] [unique_id "amujNxGd_N1Op4Iu5U9VdwAAASw"]
[Thu Jul 30 14:17:11.595869 2026] [security2:error] [pid 1021791:tid 1022013] [client 82.102.18.188:36448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amujNxGd_N1Op4Iu5U9VfwAAAWY"]
[Thu Jul 30 14:17:11.644146 2026] [fcgid:warn] [pid 1021791:tid 1021929] (70014)End of file found: [client 107.150.117.121:60466] mod_fcgid: can't get data from http client
[Thu Jul 30 14:17:11.671482 2026] [security2:error] [pid 1021791:tid 1022027] [client 172.202.44.182:22191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/2.php"] [unique_id "amujNxGd_N1Op4Iu5U9VhAAAAXQ"]
[Thu Jul 30 14:17:11.880132 2026] [security2:error] [pid 1021791:tid 1021932] [client 82.102.18.188:53905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amujNxGd_N1Op4Iu5U9ViwAAARU"]
[Thu Jul 30 14:17:11.933995 2026] [security2:error] [pid 1021791:tid 1022020] [client 74.7.175.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.lark-shop.com"] [uri "/index.php"] [unique_id "amujNhGd_N1Op4Iu5U9VXwAAAW0"]
[Thu Jul 30 14:17:11.935109 2026] [security2:error] [pid 1021791:tid 1022014] [client 74.7.175.189:55850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.lark-shop.com"] [uri "/robots.txt"] [unique_id "amujNhGd_N1Op4Iu5U9VXQABZ0A"]
[Thu Jul 30 14:17:11.991663 2026] [security2:error] [pid 1021791:tid 1021954] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujNxGd_N1Op4Iu5U9VfgABKxI"]
[Thu Jul 30 14:17:12.163973 2026] [security2:error] [pid 1021791:tid 1021983] [client 82.102.18.188:36460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amujOBGd_N1Op4Iu5U9VkgAAAUg"]
[Thu Jul 30 14:17:12.464112 2026] [security2:error] [pid 1021791:tid 1021990] [client 82.102.18.188:36468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amujOBGd_N1Op4Iu5U9VmgAAAU8"]
[Thu Jul 30 14:17:12.636796 2026] [security2:error] [pid 1021791:tid 1021943] [client 172.202.44.182:52608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amujOBGd_N1Op4Iu5U9VnAAAASA"]
[Thu Jul 30 14:17:12.750235 2026] [security2:error] [pid 1021791:tid 1022036] [client 82.102.18.188:36480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amujOBGd_N1Op4Iu5U9VpAAAAX0"]
[Thu Jul 30 14:17:12.785903 2026] [security2:error] [pid 1021791:tid 1021926] [client 172.237.109.114:37604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujOBGd_N1Op4Iu5U9VkAAAAQ8"]
[Thu Jul 30 14:17:12.935843 2026] [security2:error] [pid 1021791:tid 1021998] [client 144.172.114.51:56410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amujOBGd_N1Op4Iu5U9VrAAAAVc"]
[Thu Jul 30 14:17:13.055543 2026] [security2:error] [pid 1021791:tid 1021994] [client 82.102.18.188:36488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amujORGd_N1Op4Iu5U9VrQAAAVM"]
[Thu Jul 30 14:17:13.267776 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.91.199.21:29679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/text.php"] [unique_id "amujORGd_N1Op4Iu5U9VtwAAAW4"]
[Thu Jul 30 14:17:13.334395 2026] [security2:error] [pid 1021791:tid 1021957] [client 82.102.18.188:14713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amujORGd_N1Op4Iu5U9VvQAAAS4"]
[Thu Jul 30 14:17:13.548772 2026] [security2:error] [pid 1021791:tid 1022013] [client 103.131.71.136:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amujORGd_N1Op4Iu5U9VwQAAAWY"]
[Thu Jul 30 14:17:13.549357 2026] [security2:error] [pid 1021791:tid 1021959] [client 103.131.71.136:19965] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amujORGd_N1Op4Iu5U9VvwAAATA"]
[Thu Jul 30 14:17:13.622909 2026] [security2:error] [pid 1021791:tid 1021989] [client 82.102.18.188:36510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amujORGd_N1Op4Iu5U9VxQAAAU4"]
[Thu Jul 30 14:17:13.761310 2026] [security2:error] [pid 1021791:tid 1021961] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujORGd_N1Op4Iu5U9VsQABMi4"]
[Thu Jul 30 14:17:13.798465 2026] [security2:error] [pid 1021791:tid 1021986] [client 172.202.44.182:22204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/mah.php"] [unique_id "amujORGd_N1Op4Iu5U9VygAAAUs"]
[Thu Jul 30 14:17:13.901096 2026] [security2:error] [pid 1021791:tid 1021922] [client 82.102.18.188:45446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amujORGd_N1Op4Iu5U9V0QAAAQs"]
[Thu Jul 30 14:17:14.181936 2026] [security2:error] [pid 1021791:tid 1021983] [client 82.102.18.188:45458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amujOhGd_N1Op4Iu5U9V0gAAAUg"]
[Thu Jul 30 14:17:14.467289 2026] [security2:error] [pid 1021791:tid 1021935] [client 82.102.18.188:45462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.pvl.djb.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amujOhGd_N1Op4Iu5U9V5AAAARg"]
[Thu Jul 30 14:17:14.657550 2026] [security2:error] [pid 1021791:tid 1022047] [client 144.172.114.51:53806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amujOhGd_N1Op4Iu5U9V6AAAAYg"]
[Thu Jul 30 14:17:14.866311 2026] [security2:error] [pid 1021791:tid 1022017] [client 172.213.208.20:44625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/index.php"] [unique_id "amujOhGd_N1Op4Iu5U9V7gAAAWo"]
[Thu Jul 30 14:17:14.869554 2026] [security2:error] [pid 1021791:tid 1021829] [remote 74.7.243.224:33998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amujOhGd_N1Op4Iu5U9V7wABbyU"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:17:14.919194 2026] [security2:error] [pid 1021791:tid 1021949] [client 20.91.199.21:64786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/user.php"] [unique_id "amujOhGd_N1Op4Iu5U9V9AAAASY"]
[Thu Jul 30 14:17:15.383363 2026] [security2:error] [pid 1021791:tid 1022044] [client 152.32.208.73:59872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "website-3f57df65.evk.gpl.temporary.site"] [uri "/index.php"] [unique_id "amujOxGd_N1Op4Iu5U9V_AAAAYU"]
[Thu Jul 30 14:17:15.642639 2026] [security2:error] [pid 1021791:tid 1021989] [client 103.131.71.136:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amujOxGd_N1Op4Iu5U9WBQAAAU4"]
[Thu Jul 30 14:17:15.643631 2026] [security2:error] [pid 1021791:tid 1021984] [client 103.131.71.136:27753] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cnpinyin.com"] [uri "/listening-test/"] [unique_id "amujOxGd_N1Op4Iu5U9WAwAAAUk"]
[Thu Jul 30 14:17:15.889874 2026] [security2:error] [pid 1021791:tid 1021972] [client 20.91.199.21:19070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/webadmin.php"] [unique_id "amujOxGd_N1Op4Iu5U9WDAAAAT0"]
[Thu Jul 30 14:17:16.306905 2026] [core:notice] [pid 1021791:tid 1021948] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:16.358204 2026] [security2:error] [pid 1021791:tid 1021962] [client 88.99.80.227:7840] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amujPBGd_N1Op4Iu5U9WFAAAATM"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:17:16.739579 2026] [core:notice] [pid 1021791:tid 1021987] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:16.745006 2026] [security2:error] [pid 1021791:tid 1021987] [client 88.99.80.227:7852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amujPBGd_N1Op4Iu5U9WJAAAAUw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:17:17.031599 2026] [core:notice] [pid 1021791:tid 1022016] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:17.035510 2026] [security2:error] [pid 1021791:tid 1022016] [client 135.181.74.155:49304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/i-have-no-boobs.html"] [unique_id "amujPRGd_N1Op4Iu5U9WLgAAAWk"]
[Thu Jul 30 14:17:17.363915 2026] [security2:error] [pid 1021791:tid 1021970] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amujPRGd_N1Op4Iu5U9WMAAAATs"]
[Thu Jul 30 14:17:17.364060 2026] [security2:error] [pid 1021791:tid 1021970] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amujPRGd_N1Op4Iu5U9WMAAAATs"]
[Thu Jul 30 14:17:17.604379 2026] [security2:error] [pid 1021791:tid 1021966] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amujPRGd_N1Op4Iu5U9WOwAAATc"]
[Thu Jul 30 14:17:17.604531 2026] [security2:error] [pid 1021791:tid 1021966] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amujPRGd_N1Op4Iu5U9WOwAAATc"]
[Thu Jul 30 14:17:17.784603 2026] [security2:error] [pid 1021791:tid 1021983] [client 20.91.199.21:30538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amujPRGd_N1Op4Iu5U9WPAAAAUg"]
[Thu Jul 30 14:17:17.845777 2026] [security2:error] [pid 1021791:tid 1021985] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/3PJcpMFsD8B.php"] [unique_id "amujPRGd_N1Op4Iu5U9WPQAAAUo"]
[Thu Jul 30 14:17:17.845887 2026] [security2:error] [pid 1021791:tid 1021985] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/3PJcpMFsD8B.php"] [unique_id "amujPRGd_N1Op4Iu5U9WPQAAAUo"]
[Thu Jul 30 14:17:18.081020 2026] [security2:error] [pid 1021791:tid 1021984] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/err.php"] [unique_id "amujPhGd_N1Op4Iu5U9WSwAAAUk"]
[Thu Jul 30 14:17:18.081131 2026] [security2:error] [pid 1021791:tid 1021984] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/err.php"] [unique_id "amujPhGd_N1Op4Iu5U9WSwAAAUk"]
[Thu Jul 30 14:17:18.267888 2026] [security2:error] [pid 1021791:tid 1022011] [client 88.99.80.227:14696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amujPhGd_N1Op4Iu5U9WTAAAAWQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:17:18.332674 2026] [security2:error] [pid 1021791:tid 1022006] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/img.php"] [unique_id "amujPhGd_N1Op4Iu5U9WTQAAAV8"]
[Thu Jul 30 14:17:18.332813 2026] [security2:error] [pid 1021791:tid 1022006] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/img.php"] [unique_id "amujPhGd_N1Op4Iu5U9WTQAAAV8"]
[Thu Jul 30 14:17:18.568797 2026] [security2:error] [pid 1021791:tid 1022007] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/aa.php"] [unique_id "amujPhGd_N1Op4Iu5U9WVAAAAWA"]
[Thu Jul 30 14:17:18.568894 2026] [security2:error] [pid 1021791:tid 1022007] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/aa.php"] [unique_id "amujPhGd_N1Op4Iu5U9WVAAAAWA"]
[Thu Jul 30 14:17:18.804002 2026] [security2:error] [pid 1021791:tid 1021986] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/av.php"] [unique_id "amujPhGd_N1Op4Iu5U9WWAAAAUs"]
[Thu Jul 30 14:17:18.804147 2026] [security2:error] [pid 1021791:tid 1021986] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/av.php"] [unique_id "amujPhGd_N1Op4Iu5U9WWAAAAUs"]
[Thu Jul 30 14:17:19.038149 2026] [security2:error] [pid 1021791:tid 1021931] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/xa.php"] [unique_id "amujPxGd_N1Op4Iu5U9WXAAAARQ"]
[Thu Jul 30 14:17:19.038252 2026] [security2:error] [pid 1021791:tid 1021931] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/xa.php"] [unique_id "amujPxGd_N1Op4Iu5U9WXAAAARQ"]
[Thu Jul 30 14:17:19.273854 2026] [security2:error] [pid 1021791:tid 1022045] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/media.php"] [unique_id "amujPxGd_N1Op4Iu5U9WYwAAAYY"]
[Thu Jul 30 14:17:19.273956 2026] [security2:error] [pid 1021791:tid 1022045] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/media.php"] [unique_id "amujPxGd_N1Op4Iu5U9WYwAAAYY"]
[Thu Jul 30 14:17:19.359274 2026] [security2:error] [pid 1021791:tid 1021976] [client 172.202.44.182:22158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/send.php"] [unique_id "amujPxGd_N1Op4Iu5U9WZAAAAUE"]
[Thu Jul 30 14:17:19.482697 2026] [security2:error] [pid 1021791:tid 1021883] [remote 74.7.227.39:34756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amujPxGd_N1Op4Iu5U9WaAABD1s"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:17:19.658384 2026] [security2:error] [pid 1021791:tid 1021982] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/images.php"] [unique_id "amujPxGd_N1Op4Iu5U9WegAAAUc"]
[Thu Jul 30 14:17:19.658487 2026] [security2:error] [pid 1021791:tid 1021982] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/images.php"] [unique_id "amujPxGd_N1Op4Iu5U9WegAAAUc"]
[Thu Jul 30 14:17:19.932838 2026] [security2:error] [pid 1021791:tid 1021979] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/gecko.php"] [unique_id "amujPxGd_N1Op4Iu5U9WfAAAAUQ"]
[Thu Jul 30 14:17:19.932969 2026] [security2:error] [pid 1021791:tid 1021979] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/gecko.php"] [unique_id "amujPxGd_N1Op4Iu5U9WfAAAAUQ"]
[Thu Jul 30 14:17:19.942616 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.91.199.21:19040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amujPxGd_N1Op4Iu5U9WfgAAAWc"]
[Thu Jul 30 14:17:20.185527 2026] [security2:error] [pid 1021791:tid 1022011] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/82.php"] [unique_id "amujQBGd_N1Op4Iu5U9WiQAAAWQ"]
[Thu Jul 30 14:17:20.185638 2026] [security2:error] [pid 1021791:tid 1022011] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/82.php"] [unique_id "amujQBGd_N1Op4Iu5U9WiQAAAWQ"]
[Thu Jul 30 14:17:20.449379 2026] [security2:error] [pid 1021791:tid 1021999] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/xstelth.php"] [unique_id "amujQBGd_N1Op4Iu5U9WjAAAAVg"]
[Thu Jul 30 14:17:20.449497 2026] [security2:error] [pid 1021791:tid 1021999] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/xstelth.php"] [unique_id "amujQBGd_N1Op4Iu5U9WjAAAAVg"]
[Thu Jul 30 14:17:20.650858 2026] [security2:error] [pid 1021791:tid 1022042] [client 172.213.208.20:37994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/network/index.php"] [unique_id "amujQBGd_N1Op4Iu5U9WkwAAAYM"]
[Thu Jul 30 14:17:20.700012 2026] [security2:error] [pid 1021791:tid 1021992] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/xp.php"] [unique_id "amujQBGd_N1Op4Iu5U9WlgAAAVE"]
[Thu Jul 30 14:17:20.700125 2026] [security2:error] [pid 1021791:tid 1021992] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/xp.php"] [unique_id "amujQBGd_N1Op4Iu5U9WlgAAAVE"]
[Thu Jul 30 14:17:20.882449 2026] [security2:error] [pid 1021791:tid 1021965] [client 20.91.199.21:19021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amujQBGd_N1Op4Iu5U9WmQAAATY"]
[Thu Jul 30 14:17:20.906277 2026] [security2:error] [pid 1021791:tid 1021929] [client 172.202.44.182:22442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amujQBGd_N1Op4Iu5U9WnQAAARI"]
[Thu Jul 30 14:17:20.911886 2026] [security2:error] [pid 1021791:tid 1021975] [client 85.208.96.212:21498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amujQBGd_N1Op4Iu5U9WngAAAUA"]
[Thu Jul 30 14:17:20.912009 2026] [security2:error] [pid 1021791:tid 1021975] [client 85.208.96.212:21498] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amujQBGd_N1Op4Iu5U9WngAAAUA"]
[Thu Jul 30 14:17:20.953631 2026] [security2:error] [pid 1021791:tid 1021981] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/admin.php"] [unique_id "amujQBGd_N1Op4Iu5U9WnwAAAUY"]
[Thu Jul 30 14:17:20.953775 2026] [security2:error] [pid 1021791:tid 1021981] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/admin.php"] [unique_id "amujQBGd_N1Op4Iu5U9WnwAAAUY"]
[Thu Jul 30 14:17:21.188181 2026] [security2:error] [pid 1021791:tid 1021969] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/adminner.php"] [unique_id "amujQRGd_N1Op4Iu5U9WpgAAATo"]
[Thu Jul 30 14:17:21.188262 2026] [security2:error] [pid 1021791:tid 1021969] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/adminner.php"] [unique_id "amujQRGd_N1Op4Iu5U9WpgAAATo"]
[Thu Jul 30 14:17:21.330832 2026] [core:notice] [pid 1021791:tid 1021832] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:21.516130 2026] [security2:error] [pid 1021791:tid 1021970] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/a.php"] [unique_id "amujQRGd_N1Op4Iu5U9WrgAAATs"]
[Thu Jul 30 14:17:21.516248 2026] [security2:error] [pid 1021791:tid 1021970] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/a.php"] [unique_id "amujQRGd_N1Op4Iu5U9WrgAAATs"]
[Thu Jul 30 14:17:21.582610 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.91.199.21:27179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amujQRGd_N1Op4Iu5U9WsQAAAQ8"]
[Thu Jul 30 14:17:21.754373 2026] [security2:error] [pid 1021791:tid 1022019] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/k.php"] [unique_id "amujQRGd_N1Op4Iu5U9WuAAAAWw"]
[Thu Jul 30 14:17:21.754478 2026] [security2:error] [pid 1021791:tid 1022019] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/k.php"] [unique_id "amujQRGd_N1Op4Iu5U9WuAAAAWw"]
[Thu Jul 30 14:17:21.918528 2026] [security2:error] [pid 1021791:tid 1022017] [client 85.208.96.195:16296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ejournalugj.com"] [uri "/index.php/JSHR/issue/current"] [unique_id "amujQRGd_N1Op4Iu5U9WvAAAAWo"]
[Thu Jul 30 14:17:21.918675 2026] [security2:error] [pid 1021791:tid 1022017] [client 85.208.96.195:16296] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejournalugj.com"] [uri "/index.php/JSHR/issue/current"] [unique_id "amujQRGd_N1Op4Iu5U9WvAAAAWo"]
[Thu Jul 30 14:17:21.931845 2026] [core:notice] [pid 1021791:tid 1022003] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:21.936448 2026] [security2:error] [pid 1021791:tid 1022003] [client 135.181.74.155:49304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/i-never-thought-i-d-thank-you-for-letting-me-go.html"] [unique_id "amujQRGd_N1Op4Iu5U9WvQAAAVw"]
[Thu Jul 30 14:17:21.996643 2026] [security2:error] [pid 1021791:tid 1021945] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/222.php"] [unique_id "amujQRGd_N1Op4Iu5U9WvgAAASI"]
[Thu Jul 30 14:17:21.996808 2026] [security2:error] [pid 1021791:tid 1021945] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/222.php"] [unique_id "amujQRGd_N1Op4Iu5U9WvgAAASI"]
[Thu Jul 30 14:17:22.164677 2026] [security2:error] [pid 1021791:tid 1021990] [client 172.213.208.20:52675] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/1.php"] [unique_id "amujQhGd_N1Op4Iu5U9WwwAAAU8"]
[Thu Jul 30 14:17:22.164786 2026] [security2:error] [pid 1021791:tid 1021990] [client 172.213.208.20:52675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/1.php"] [unique_id "amujQhGd_N1Op4Iu5U9WwwAAAU8"]
[Thu Jul 30 14:17:22.243811 2026] [security2:error] [pid 1021791:tid 1021942] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/mac.php"] [unique_id "amujQhGd_N1Op4Iu5U9WyAAAAR8"]
[Thu Jul 30 14:17:22.243924 2026] [security2:error] [pid 1021791:tid 1021942] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/mac.php"] [unique_id "amujQhGd_N1Op4Iu5U9WyAAAAR8"]
[Thu Jul 30 14:17:22.493896 2026] [security2:error] [pid 1021791:tid 1022028] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.echomemoversalain.casa"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amujQhGd_N1Op4Iu5U9WzwAAAXU"]
[Thu Jul 30 14:17:22.615015 2026] [security2:error] [pid 1021791:tid 1021946] [client 68.67.112.221:33316] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amujQhGd_N1Op4Iu5U9W0AAAASM"]
[Thu Jul 30 14:17:22.642211 2026] [security2:error] [pid 1021791:tid 1022042] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.echomemoversalain.casa"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/"] [unique_id "amujQhGd_N1Op4Iu5U9W0gAAAYM"]
[Thu Jul 30 14:17:22.764373 2026] [security2:error] [pid 1021791:tid 1021992] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/ops.php"] [unique_id "amujQhGd_N1Op4Iu5U9W1gAAAVE"]
[Thu Jul 30 14:17:22.764467 2026] [security2:error] [pid 1021791:tid 1021992] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/ops.php"] [unique_id "amujQhGd_N1Op4Iu5U9W1gAAAVE"]
[Thu Jul 30 14:17:23.004031 2026] [security2:error] [pid 1021791:tid 1021981] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/8.php"] [unique_id "amujQxGd_N1Op4Iu5U9W4AAAAUY"]
[Thu Jul 30 14:17:23.004171 2026] [security2:error] [pid 1021791:tid 1021981] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/8.php"] [unique_id "amujQxGd_N1Op4Iu5U9W4AAAAUY"]
[Thu Jul 30 14:17:23.095311 2026] [core:notice] [pid 1021791:tid 1022023] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:23.249888 2026] [security2:error] [pid 1021791:tid 1022039] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/FWAZ.php"] [unique_id "amujQxGd_N1Op4Iu5U9W5QAAAYA"]
[Thu Jul 30 14:17:23.250032 2026] [security2:error] [pid 1021791:tid 1022039] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/FWAZ.php"] [unique_id "amujQxGd_N1Op4Iu5U9W5QAAAYA"]
[Thu Jul 30 14:17:23.427373 2026] [security2:error] [pid 1021791:tid 1022040] [client 172.202.44.182:22420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/about.php"] [unique_id "amujQxGd_N1Op4Iu5U9W7AAAAYE"]
[Thu Jul 30 14:17:23.495478 2026] [security2:error] [pid 1021791:tid 1021936] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/biufile.php"] [unique_id "amujQxGd_N1Op4Iu5U9W7QAAARk"]
[Thu Jul 30 14:17:23.495582 2026] [security2:error] [pid 1021791:tid 1021936] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/biufile.php"] [unique_id "amujQxGd_N1Op4Iu5U9W7QAAARk"]
[Thu Jul 30 14:17:23.509001 2026] [security2:error] [pid 1021791:tid 1021842] [remote 57.141.0.58:38536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/copyrightandlicense"] [unique_id "amujQxGd_N1Op4Iu5U9W7gABUjI"]
[Thu Jul 30 14:17:23.678730 2026] [security2:error] [pid 1021791:tid 1022015] [client 20.91.199.21:30555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amujQxGd_N1Op4Iu5U9W8QAAAWg"]
[Thu Jul 30 14:17:23.739702 2026] [security2:error] [pid 1021791:tid 1022001] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/coffexium.php"] [unique_id "amujQxGd_N1Op4Iu5U9W8wAAAVo"]
[Thu Jul 30 14:17:23.739796 2026] [security2:error] [pid 1021791:tid 1022001] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/coffexium.php"] [unique_id "amujQxGd_N1Op4Iu5U9W8wAAAVo"]
[Thu Jul 30 14:17:23.974564 2026] [security2:error] [pid 1021791:tid 1022025] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/simple.php"] [unique_id "amujQxGd_N1Op4Iu5U9XAQAAAXI"]
[Thu Jul 30 14:17:23.974673 2026] [security2:error] [pid 1021791:tid 1022025] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/simple.php"] [unique_id "amujQxGd_N1Op4Iu5U9XAQAAAXI"]
[Thu Jul 30 14:17:24.225843 2026] [security2:error] [pid 1021791:tid 1022029] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/fpwch.php"] [unique_id "amujRBGd_N1Op4Iu5U9XCAAAAXY"]
[Thu Jul 30 14:17:24.225961 2026] [security2:error] [pid 1021791:tid 1022029] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/fpwch.php"] [unique_id "amujRBGd_N1Op4Iu5U9XCAAAAXY"]
[Thu Jul 30 14:17:24.458694 2026] [security2:error] [pid 1021791:tid 1021944] [client 172.202.44.182:21701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/options.php"] [unique_id "amujRBGd_N1Op4Iu5U9XFAAAASE"]
[Thu Jul 30 14:17:24.459106 2026] [security2:error] [pid 1021791:tid 1021946] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/dex.php"] [unique_id "amujRBGd_N1Op4Iu5U9XFQAAASM"]
[Thu Jul 30 14:17:24.459185 2026] [security2:error] [pid 1021791:tid 1021946] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/dex.php"] [unique_id "amujRBGd_N1Op4Iu5U9XFQAAASM"]
[Thu Jul 30 14:17:24.536557 2026] [security2:error] [pid 1021791:tid 1022027] [client 172.237.109.114:17902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujRBGd_N1Op4Iu5U9XAgAAAXQ"]
[Thu Jul 30 14:17:24.653483 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.100.187.246:24010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.tmb/LA.php"] [unique_id "amujRBGd_N1Op4Iu5U9XFgAAAUk"]
[Thu Jul 30 14:17:24.730113 2026] [security2:error] [pid 1021791:tid 1022012] [client 172.213.208.20:11905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/plugin.php"] [unique_id "amujRBGd_N1Op4Iu5U9XGgAAAWU"]
[Thu Jul 30 14:17:24.730912 2026] [security2:error] [pid 1021791:tid 1021923] [client 172.213.225.181:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.echomemoversalain.casa"] [uri "/1.php"] [unique_id "amujRBGd_N1Op4Iu5U9XGwAAAQw"]
[Thu Jul 30 14:17:24.731067 2026] [security2:error] [pid 1021791:tid 1021923] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/1.php"] [unique_id "amujRBGd_N1Op4Iu5U9XGwAAAQw"]
[Thu Jul 30 14:17:24.731204 2026] [security2:error] [pid 1021791:tid 1021923] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/1.php"] [unique_id "amujRBGd_N1Op4Iu5U9XGwAAAQw"]
[Thu Jul 30 14:17:24.980132 2026] [security2:error] [pid 1021791:tid 1022016] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.echomemoversalain.casa"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amujRBGd_N1Op4Iu5U9XJwAAAWk"]
[Thu Jul 30 14:17:25.100764 2026] [security2:error] [pid 1021791:tid 1021993] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/config.json.php"] [unique_id "amujRRGd_N1Op4Iu5U9XKgAAAVI"]
[Thu Jul 30 14:17:25.100924 2026] [security2:error] [pid 1021791:tid 1021993] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/config.json.php"] [unique_id "amujRRGd_N1Op4Iu5U9XKgAAAVI"]
[Thu Jul 30 14:17:25.340327 2026] [security2:error] [pid 1021791:tid 1021947] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/k2.php"] [unique_id "amujRRGd_N1Op4Iu5U9XLwAAASQ"]
[Thu Jul 30 14:17:25.340427 2026] [security2:error] [pid 1021791:tid 1021947] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/k2.php"] [unique_id "amujRRGd_N1Op4Iu5U9XLwAAASQ"]
[Thu Jul 30 14:17:25.469056 2026] [security2:error] [pid 1021791:tid 1022022] [client 172.213.208.20:37273] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.mydubaidesertsafari.com"] [uri "/1.php"] [unique_id "amujRRGd_N1Op4Iu5U9XOAAAAW8"]
[Thu Jul 30 14:17:25.469190 2026] [security2:error] [pid 1021791:tid 1022022] [client 172.213.208.20:37273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/1.php"] [unique_id "amujRRGd_N1Op4Iu5U9XOAAAAW8"]
[Thu Jul 30 14:17:25.575557 2026] [security2:error] [pid 1021791:tid 1022029] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/raw.php"] [unique_id "amujRRGd_N1Op4Iu5U9XOwAAAXY"]
[Thu Jul 30 14:17:25.575694 2026] [security2:error] [pid 1021791:tid 1022029] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/raw.php"] [unique_id "amujRRGd_N1Op4Iu5U9XOwAAAXY"]
[Thu Jul 30 14:17:25.650082 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.91.199.21:18945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amujRRGd_N1Op4Iu5U9XPAAAAWY"]
[Thu Jul 30 14:17:25.826451 2026] [security2:error] [pid 1021791:tid 1021951] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/wp.php"] [unique_id "amujRRGd_N1Op4Iu5U9XPQAAASg"]
[Thu Jul 30 14:17:25.826567 2026] [security2:error] [pid 1021791:tid 1021951] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/wp.php"] [unique_id "amujRRGd_N1Op4Iu5U9XPQAAASg"]
[Thu Jul 30 14:17:25.849209 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.100.187.246:24033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.tmb/admin.php"] [unique_id "amujRRGd_N1Op4Iu5U9XPwAAAW4"]
[Thu Jul 30 14:17:25.954840 2026] [security2:error] [pid 1021791:tid 1022003] [client 180.243.59.178:64561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujRRGd_N1Op4Iu5U9XRwAAAVw"]
[Thu Jul 30 14:17:25.954974 2026] [security2:error] [pid 1021791:tid 1022003] [client 180.243.59.178:64561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujRRGd_N1Op4Iu5U9XRwAAAVw"]
[Thu Jul 30 14:17:26.062620 2026] [security2:error] [pid 1021791:tid 1021984] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/fffm.php"] [unique_id "amujRhGd_N1Op4Iu5U9XSwAAAUk"]
[Thu Jul 30 14:17:26.062712 2026] [security2:error] [pid 1021791:tid 1021984] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/fffm.php"] [unique_id "amujRhGd_N1Op4Iu5U9XSwAAAUk"]
[Thu Jul 30 14:17:26.065621 2026] [security2:error] [pid 1021791:tid 1022015] [client 172.202.44.182:22169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-content/themes/index.php"] [unique_id "amujRhGd_N1Op4Iu5U9XTAAAAWg"]
[Thu Jul 30 14:17:26.305371 2026] [security2:error] [pid 1021791:tid 1022047] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/111.php"] [unique_id "amujRhGd_N1Op4Iu5U9XUgAAAYg"]
[Thu Jul 30 14:17:26.305491 2026] [security2:error] [pid 1021791:tid 1022047] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/111.php"] [unique_id "amujRhGd_N1Op4Iu5U9XUgAAAYg"]
[Thu Jul 30 14:17:26.464902 2026] [security2:error] [pid 1021791:tid 1022018] [client 20.91.199.21:30589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amujRhGd_N1Op4Iu5U9XVgAAAWs"]
[Thu Jul 30 14:17:26.481126 2026] [core:notice] [pid 1021791:tid 1022035] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:26.485233 2026] [security2:error] [pid 1021791:tid 1022035] [client 135.181.74.155:49304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/other-articles.html"] [unique_id "amujRhGd_N1Op4Iu5U9XVwAAAXw"]
[Thu Jul 30 14:17:26.525765 2026] [security2:error] [pid 1021791:tid 1021962] [client 172.213.208.20:39695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/gg.php"] [unique_id "amujRhGd_N1Op4Iu5U9XWwAAATM"]
[Thu Jul 30 14:17:26.567492 2026] [security2:error] [pid 1021791:tid 1022023] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.echomemoversalain.casa"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amujRhGd_N1Op4Iu5U9XXwAAAXA"]
[Thu Jul 30 14:17:26.693460 2026] [security2:error] [pid 1021791:tid 1022031] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/ws.php"] [unique_id "amujRhGd_N1Op4Iu5U9XYQAAAXg"]
[Thu Jul 30 14:17:26.693568 2026] [security2:error] [pid 1021791:tid 1022031] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/ws.php"] [unique_id "amujRhGd_N1Op4Iu5U9XYQAAAXg"]
[Thu Jul 30 14:17:26.716908 2026] [security2:error] [pid 1021791:tid 1021931] [client 20.100.187.246:26027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.tmb/class_api.php"] [unique_id "amujRhGd_N1Op4Iu5U9XYwAAARQ"]
[Thu Jul 30 14:17:26.779781 2026] [security2:error] [pid 1021791:tid 1022012] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amujRhGd_N1Op4Iu5U9XUQAAAWU"]
[Thu Jul 30 14:17:26.832059 2026] [security2:error] [pid 1021791:tid 1021987] [client 152.32.208.73:36038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-3f57df65.evk.gpl.temporary.site"] [uri "/index.php"] [unique_id "amujRhGd_N1Op4Iu5U9XZAAAAUw"]
[Thu Jul 30 14:17:26.935333 2026] [security2:error] [pid 1021791:tid 1021943] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/coffee.php"] [unique_id "amujRhGd_N1Op4Iu5U9XbQAAASA"]
[Thu Jul 30 14:17:26.935431 2026] [security2:error] [pid 1021791:tid 1021943] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/coffee.php"] [unique_id "amujRhGd_N1Op4Iu5U9XbQAAASA"]
[Thu Jul 30 14:17:27.067184 2026] [security2:error] [pid 1021791:tid 1021936] [client 20.91.199.21:18953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amujRxGd_N1Op4Iu5U9XdwAAARk"]
[Thu Jul 30 14:17:27.174476 2026] [security2:error] [pid 1021791:tid 1022022] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/goods.php"] [unique_id "amujRxGd_N1Op4Iu5U9XeAAAAW8"]
[Thu Jul 30 14:17:27.174629 2026] [security2:error] [pid 1021791:tid 1022022] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/goods.php"] [unique_id "amujRxGd_N1Op4Iu5U9XeAAAAW8"]
[Thu Jul 30 14:17:27.471368 2026] [security2:error] [pid 1021791:tid 1022030] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/about.php"] [unique_id "amujRxGd_N1Op4Iu5U9XegAAAXc"]
[Thu Jul 30 14:17:27.471553 2026] [security2:error] [pid 1021791:tid 1022030] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/about.php"] [unique_id "amujRxGd_N1Op4Iu5U9XegAAAXc"]
[Thu Jul 30 14:17:27.723965 2026] [security2:error] [pid 1021791:tid 1022000] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/about.php"] [unique_id "amujRxGd_N1Op4Iu5U9XhwAAAVk"]
[Thu Jul 30 14:17:27.724092 2026] [security2:error] [pid 1021791:tid 1022000] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/about.php"] [unique_id "amujRxGd_N1Op4Iu5U9XhwAAAVk"]
[Thu Jul 30 14:17:27.975655 2026] [security2:error] [pid 1021791:tid 1022027] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/admin.php"] [unique_id "amujRxGd_N1Op4Iu5U9XiAAAAXQ"]
[Thu Jul 30 14:17:27.975774 2026] [security2:error] [pid 1021791:tid 1022027] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/admin.php"] [unique_id "amujRxGd_N1Op4Iu5U9XiAAAAXQ"]
[Thu Jul 30 14:17:28.046170 2026] [core:notice] [pid 1021791:tid 1022017] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:28.228476 2026] [security2:error] [pid 1021791:tid 1022023] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/inputs.php"] [unique_id "amujSBGd_N1Op4Iu5U9XlwAAAXA"]
[Thu Jul 30 14:17:28.228578 2026] [security2:error] [pid 1021791:tid 1022023] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/inputs.php"] [unique_id "amujSBGd_N1Op4Iu5U9XlwAAAXA"]
[Thu Jul 30 14:17:28.238698 2026] [security2:error] [pid 1021791:tid 1022003] [client 172.202.44.182:22096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/wp-file.php"] [unique_id "amujSBGd_N1Op4Iu5U9XmAAAAVw"]
[Thu Jul 30 14:17:28.465448 2026] [security2:error] [pid 1021791:tid 1021939] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/inputs.php"] [unique_id "amujSBGd_N1Op4Iu5U9XnQAAARw"]
[Thu Jul 30 14:17:28.465574 2026] [security2:error] [pid 1021791:tid 1021939] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/inputs.php"] [unique_id "amujSBGd_N1Op4Iu5U9XnQAAARw"]
[Thu Jul 30 14:17:28.558933 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.100.187.246:26038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amujSBGd_N1Op4Iu5U9XoQAAAUI"]
[Thu Jul 30 14:17:28.710724 2026] [security2:error] [pid 1021791:tid 1021940] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/adminfuns.php"] [unique_id "amujSBGd_N1Op4Iu5U9XqgAAAR0"]
[Thu Jul 30 14:17:28.710813 2026] [security2:error] [pid 1021791:tid 1021940] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/adminfuns.php"] [unique_id "amujSBGd_N1Op4Iu5U9XqgAAAR0"]
[Thu Jul 30 14:17:28.895392 2026] [security2:error] [pid 1021791:tid 1021875] [remote 57.141.0.20:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amujSBGd_N1Op4Iu5U9XqwABSFM"]
[Thu Jul 30 14:17:28.954036 2026] [security2:error] [pid 1021791:tid 1022034] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/404.php"] [unique_id "amujSBGd_N1Op4Iu5U9XrAAAAXs"]
[Thu Jul 30 14:17:28.954158 2026] [security2:error] [pid 1021791:tid 1022034] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/404.php"] [unique_id "amujSBGd_N1Op4Iu5U9XrAAAAXs"]
[Thu Jul 30 14:17:29.061031 2026] [security2:error] [pid 1021791:tid 1022045] [client 172.202.44.182:22444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/sid3.php"] [unique_id "amujSRGd_N1Op4Iu5U9XrwAAAYY"]
[Thu Jul 30 14:17:29.133307 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.91.199.21:30562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amujSRGd_N1Op4Iu5U9XswAAASA"]
[Thu Jul 30 14:17:29.192353 2026] [security2:error] [pid 1021791:tid 1021937] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/xxx.php"] [unique_id "amujSRGd_N1Op4Iu5U9XuAAAARo"]
[Thu Jul 30 14:17:29.192452 2026] [security2:error] [pid 1021791:tid 1021937] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/xxx.php"] [unique_id "amujSRGd_N1Op4Iu5U9XuAAAARo"]
[Thu Jul 30 14:17:29.433638 2026] [security2:error] [pid 1021791:tid 1021945] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/classwithtostring.php"] [unique_id "amujSRGd_N1Op4Iu5U9XuQAAASI"]
[Thu Jul 30 14:17:29.433784 2026] [security2:error] [pid 1021791:tid 1021945] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/classwithtostring.php"] [unique_id "amujSRGd_N1Op4Iu5U9XuQAAASI"]
[Thu Jul 30 14:17:29.669041 2026] [security2:error] [pid 1021791:tid 1021996] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/234ff.php"] [unique_id "amujSRGd_N1Op4Iu5U9XwQAAAVU"]
[Thu Jul 30 14:17:29.669123 2026] [security2:error] [pid 1021791:tid 1021996] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/234ff.php"] [unique_id "amujSRGd_N1Op4Iu5U9XwQAAAVU"]
[Thu Jul 30 14:17:29.712217 2026] [security2:error] [pid 1021791:tid 1022022] [client 20.100.187.246:24552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.tmb/wp-login.php"] [unique_id "amujSRGd_N1Op4Iu5U9XugAAAW8"]
[Thu Jul 30 14:17:29.917730 2026] [security2:error] [pid 1021791:tid 1021954] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/133.php"] [unique_id "amujSRGd_N1Op4Iu5U9XygAAASs"]
[Thu Jul 30 14:17:29.917832 2026] [security2:error] [pid 1021791:tid 1021954] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/133.php"] [unique_id "amujSRGd_N1Op4Iu5U9XygAAASs"]
[Thu Jul 30 14:17:29.967570 2026] [security2:error] [pid 1021791:tid 1022017] [client 172.213.208.20:44648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-content/languages/index.php"] [unique_id "amujSRGd_N1Op4Iu5U9XzQAAAWo"]
[Thu Jul 30 14:17:30.165851 2026] [security2:error] [pid 1021791:tid 1021952] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/wp-ws68.php"] [unique_id "amujShGd_N1Op4Iu5U9X0QAAASk"]
[Thu Jul 30 14:17:30.165941 2026] [security2:error] [pid 1021791:tid 1021952] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/wp-ws68.php"] [unique_id "amujShGd_N1Op4Iu5U9X0QAAASk"]
[Thu Jul 30 14:17:30.248701 2026] [security2:error] [pid 1021791:tid 1021946] [client 20.91.199.21:18822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amujShGd_N1Op4Iu5U9X1wAAASM"]
[Thu Jul 30 14:17:30.411386 2026] [security2:error] [pid 1021791:tid 1022041] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/mgrr.php"] [unique_id "amujShGd_N1Op4Iu5U9X2gAAAYI"]
[Thu Jul 30 14:17:30.411533 2026] [security2:error] [pid 1021791:tid 1022041] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/mgrr.php"] [unique_id "amujShGd_N1Op4Iu5U9X2gAAAYI"]
[Thu Jul 30 14:17:30.484765 2026] [security2:error] [pid 1021791:tid 1022006] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amujSRGd_N1Op4Iu5U9XyAAAAV8"]
[Thu Jul 30 14:17:30.668225 2026] [security2:error] [pid 1021791:tid 1021925] [client 172.213.225.181:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.225.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.echomemoversalain.casa"] [uri "/55.php"] [unique_id "amujShGd_N1Op4Iu5U9X3gAAAQ4"]
[Thu Jul 30 14:17:30.668342 2026] [security2:error] [pid 1021791:tid 1021925] [client 172.213.225.181:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.echomemoversalain.casa"] [uri "/55.php"] [unique_id "amujShGd_N1Op4Iu5U9X3gAAAQ4"]
[Thu Jul 30 14:17:30.755762 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.100.187.246:28273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amujShGd_N1Op4Iu5U9X4gAAARM"]
[Thu Jul 30 14:17:31.088151 2026] [security2:error] [pid 1021791:tid 1022039] [client 172.213.208.20:44022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp.php"] [unique_id "amujSxGd_N1Op4Iu5U9X5wAAAYA"]
[Thu Jul 30 14:17:31.447428 2026] [security2:error] [pid 1021791:tid 1021982] [client 152.32.208.73:36048] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "website-3f57df65.evk.gpl.temporary.site"] [uri "/wp-content/plugins/*\\",\\"/readme.txt"] [unique_id "amujSxGd_N1Op4Iu5U9X9AAAAUc"]
[Thu Jul 30 14:17:31.662520 2026] [security2:error] [pid 1021791:tid 1022001] [client 20.91.199.21:25060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/flower.php"] [unique_id "amujSxGd_N1Op4Iu5U9X9gAAAVo"]
[Thu Jul 30 14:17:31.668076 2026] [security2:error] [pid 1021791:tid 1021940] [client 20.100.187.246:28245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/991176.php"] [unique_id "amujSxGd_N1Op4Iu5U9X9wAAAR0"]
[Thu Jul 30 14:17:32.316751 2026] [security2:error] [pid 1021791:tid 1021978] [client 152.32.208.73:36050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-3f57df65.evk.gpl.temporary.site"] [uri "/index.php"] [unique_id "amujTBGd_N1Op4Iu5U9YBwAAAUM"]
[Thu Jul 30 14:17:32.408397 2026] [security2:error] [pid 1021791:tid 1021963] [client 20.91.199.21:46338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amujTBGd_N1Op4Iu5U9YCwAAATQ"]
[Thu Jul 30 14:17:32.528355 2026] [security2:error] [pid 1021791:tid 1021942] [client 20.100.187.246:24776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amujTBGd_N1Op4Iu5U9YDwAAAR8"]
[Thu Jul 30 14:17:32.690599 2026] [security2:error] [pid 1021791:tid 1021953] [client 172.213.208.20:11907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amujTBGd_N1Op4Iu5U9YEgAAASo"]
[Thu Jul 30 14:17:33.195004 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.91.199.21:30578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/maint/flower.php"] [unique_id "amujTRGd_N1Op4Iu5U9YHgAAARY"]
[Thu Jul 30 14:17:33.327303 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.100.187.246:24545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amujTRGd_N1Op4Iu5U9YJQAAAUI"]
[Thu Jul 30 14:17:33.970425 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.100.187.246:24564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amujTRGd_N1Op4Iu5U9YMwAAAVM"]
[Thu Jul 30 14:17:34.030765 2026] [core:notice] [pid 1021791:tid 1021858] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:34.179770 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.91.199.21:30582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amujThGd_N1Op4Iu5U9YNQAAAWc"]
[Thu Jul 30 14:17:34.322696 2026] [security2:error] [pid 1021791:tid 1021976] [client 57.141.0.25:33266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amujTRGd_N1Op4Iu5U9YMgABQW4"], referer: https://igetvape-australia.com/product/alibarbar-ingot-cool-mint-9000-puffs/?add-to-cart=929
[Thu Jul 30 14:17:34.514189 2026] [security2:error] [pid 1021791:tid 1021987] [client 172.213.208.20:44626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/file.php"] [unique_id "amujThGd_N1Op4Iu5U9YPwAAAUw"]
[Thu Jul 30 14:17:35.595835 2026] [core:notice] [pid 1021791:tid 1022043] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:35.705575 2026] [security2:error] [pid 1021791:tid 1021793] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amujTxGd_N1Op4Iu5U9YWQABPgE"]
[Thu Jul 30 14:17:35.705747 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amujTxGd_N1Op4Iu5U9YWQABPgE"]
[Thu Jul 30 14:17:35.748057 2026] [security2:error] [pid 1021791:tid 1021883] [remote 57.141.0.52:57970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amujTxGd_N1Op4Iu5U9YWgABc1s"]
[Thu Jul 30 14:17:36.008892 2026] [core:notice] [pid 1021791:tid 1021807] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:36.079541 2026] [security2:error] [pid 1021791:tid 1021799] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amujUBGd_N1Op4Iu5U9YZQABhQc"]
[Thu Jul 30 14:17:36.079694 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amujUBGd_N1Op4Iu5U9YZQABhQc"]
[Thu Jul 30 14:17:36.217268 2026] [security2:error] [pid 1021791:tid 1021912] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/x.php"] [unique_id "amujUBGd_N1Op4Iu5U9YZgABV3g"]
[Thu Jul 30 14:17:36.217431 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/x.php"] [unique_id "amujUBGd_N1Op4Iu5U9YZgABV3g"]
[Thu Jul 30 14:17:36.263971 2026] [security2:error] [pid 1021791:tid 1021974] [client 180.243.59.178:65056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujUBGd_N1Op4Iu5U9YZwAAAT8"]
[Thu Jul 30 14:17:36.264125 2026] [security2:error] [pid 1021791:tid 1021974] [client 180.243.59.178:65056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujUBGd_N1Op4Iu5U9YZwAAAT8"]
[Thu Jul 30 14:17:36.345393 2026] [security2:error] [pid 1021791:tid 1021887] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/mgrr.php"] [unique_id "amujUBGd_N1Op4Iu5U9YaAABeV8"]
[Thu Jul 30 14:17:36.345619 2026] [security2:error] [pid 1021791:tid 1022032] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/mgrr.php"] [unique_id "amujUBGd_N1Op4Iu5U9YaAABeV8"]
[Thu Jul 30 14:17:36.482854 2026] [security2:error] [pid 1021791:tid 1021816] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/domvf.php"] [unique_id "amujUBGd_N1Op4Iu5U9YbwABUxg"]
[Thu Jul 30 14:17:36.483015 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/domvf.php"] [unique_id "amujUBGd_N1Op4Iu5U9YbwABUxg"]
[Thu Jul 30 14:17:36.617920 2026] [security2:error] [pid 1021791:tid 1021811] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/yup.php"] [unique_id "amujUBGd_N1Op4Iu5U9YcwABYBM"]
[Thu Jul 30 14:17:36.618082 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/yup.php"] [unique_id "amujUBGd_N1Op4Iu5U9YcwABYBM"]
[Thu Jul 30 14:17:36.756154 2026] [security2:error] [pid 1021791:tid 1021797] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/X.php"] [unique_id "amujUBGd_N1Op4Iu5U9YdAABZwU"]
[Thu Jul 30 14:17:36.756349 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/X.php"] [unique_id "amujUBGd_N1Op4Iu5U9YdAABZwU"]
[Thu Jul 30 14:17:36.881465 2026] [security2:error] [pid 1021791:tid 1021808] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amujUBGd_N1Op4Iu5U9YdQABIhA"]
[Thu Jul 30 14:17:36.881695 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amujUBGd_N1Op4Iu5U9YdQABIhA"]
[Thu Jul 30 14:17:36.997343 2026] [core:notice] [pid 1021791:tid 1022027] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:37.001142 2026] [security2:error] [pid 1021791:tid 1022027] [client 135.181.74.155:41490] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/sometimes-it-s-okay-to-let-her-go.html"] [unique_id "amujUBGd_N1Op4Iu5U9YeQAAAXQ"]
[Thu Jul 30 14:17:37.018727 2026] [security2:error] [pid 1021791:tid 1021812] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/gec.php"] [unique_id "amujURGd_N1Op4Iu5U9YfAABRBQ"]
[Thu Jul 30 14:17:37.018940 2026] [security2:error] [pid 1021791:tid 1021979] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/gec.php"] [unique_id "amujURGd_N1Op4Iu5U9YfAABRBQ"]
[Thu Jul 30 14:17:37.143530 2026] [security2:error] [pid 1021791:tid 1021901] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/sky.php"] [unique_id "amujURGd_N1Op4Iu5U9YgQABHm0"]
[Thu Jul 30 14:17:37.143718 2026] [security2:error] [pid 1021791:tid 1021941] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/sky.php"] [unique_id "amujURGd_N1Op4Iu5U9YgQABHm0"]
[Thu Jul 30 14:17:37.280367 2026] [security2:error] [pid 1021791:tid 1021809] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/fffm.php"] [unique_id "amujURGd_N1Op4Iu5U9YggABIRE"]
[Thu Jul 30 14:17:37.280545 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/fffm.php"] [unique_id "amujURGd_N1Op4Iu5U9YggABIRE"]
[Thu Jul 30 14:17:37.409506 2026] [security2:error] [pid 1021791:tid 1021825] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/sixxis.php"] [unique_id "amujURGd_N1Op4Iu5U9YhgABYiE"]
[Thu Jul 30 14:17:37.409673 2026] [security2:error] [pid 1021791:tid 1022009] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/sixxis.php"] [unique_id "amujURGd_N1Op4Iu5U9YhgABYiE"]
[Thu Jul 30 14:17:37.500503 2026] [fcgid:warn] [pid 1021791:tid 1022015] (70014)End of file found: [client 199.45.154.132:49302] mod_fcgid: can't get data from http client
[Thu Jul 30 14:17:37.550178 2026] [security2:error] [pid 1021791:tid 1021802] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/yj09.php"] [unique_id "amujURGd_N1Op4Iu5U9YkwABbAo"]
[Thu Jul 30 14:17:37.550335 2026] [security2:error] [pid 1021791:tid 1022019] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/yj09.php"] [unique_id "amujURGd_N1Op4Iu5U9YkwABbAo"]
[Thu Jul 30 14:17:37.598947 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.91.199.21:23311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amujURGd_N1Op4Iu5U9YlQAAAUk"]
[Thu Jul 30 14:17:37.687791 2026] [security2:error] [pid 1021791:tid 1021820] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/k.php"] [unique_id "amujURGd_N1Op4Iu5U9YlgABEBw"]
[Thu Jul 30 14:17:37.687958 2026] [security2:error] [pid 1021791:tid 1021927] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/k.php"] [unique_id "amujURGd_N1Op4Iu5U9YlgABEBw"]
[Thu Jul 30 14:17:37.697234 2026] [security2:error] [pid 1021791:tid 1021946] [client 172.213.208.20:35733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/user/index.php"] [unique_id "amujURGd_N1Op4Iu5U9YlwAAASM"]
[Thu Jul 30 14:17:37.838483 2026] [security2:error] [pid 1021791:tid 1021854] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/k2.php"] [unique_id "amujURGd_N1Op4Iu5U9YmQABEj4"]
[Thu Jul 30 14:17:37.838665 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/k2.php"] [unique_id "amujURGd_N1Op4Iu5U9YmQABEj4"]
[Thu Jul 30 14:17:37.860084 2026] [core:notice] [pid 1021791:tid 1022020] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:37.965210 2026] [security2:error] [pid 1021791:tid 1021800] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/w.php"] [unique_id "amujURGd_N1Op4Iu5U9YngABDgg"]
[Thu Jul 30 14:17:37.965361 2026] [security2:error] [pid 1021791:tid 1021925] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/w.php"] [unique_id "amujURGd_N1Op4Iu5U9YngABDgg"]
[Thu Jul 30 14:17:38.101629 2026] [security2:error] [pid 1021791:tid 1021824] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/fpwch.php"] [unique_id "amujUhGd_N1Op4Iu5U9YpQABNiA"]
[Thu Jul 30 14:17:38.101796 2026] [security2:error] [pid 1021791:tid 1021965] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/fpwch.php"] [unique_id "amujUhGd_N1Op4Iu5U9YpQABNiA"]
[Thu Jul 30 14:17:38.230393 2026] [security2:error] [pid 1021791:tid 1021817] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/w2025.php"] [unique_id "amujUhGd_N1Op4Iu5U9YpwABRRk"]
[Thu Jul 30 14:17:38.230555 2026] [security2:error] [pid 1021791:tid 1021980] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/w2025.php"] [unique_id "amujUhGd_N1Op4Iu5U9YpwABRRk"]
[Thu Jul 30 14:17:38.368108 2026] [security2:error] [pid 1021791:tid 1021828] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/FWAZ.php"] [unique_id "amujUhGd_N1Op4Iu5U9YqAABaSQ"]
[Thu Jul 30 14:17:38.368349 2026] [security2:error] [pid 1021791:tid 1022016] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/FWAZ.php"] [unique_id "amujUhGd_N1Op4Iu5U9YqAABaSQ"]
[Thu Jul 30 14:17:38.499305 2026] [security2:error] [pid 1021791:tid 1021853] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/qterm.php"] [unique_id "amujUhGd_N1Op4Iu5U9YrAABXT0"]
[Thu Jul 30 14:17:38.499548 2026] [security2:error] [pid 1021791:tid 1022004] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/qterm.php"] [unique_id "amujUhGd_N1Op4Iu5U9YrAABXT0"]
[Thu Jul 30 14:17:38.635701 2026] [security2:error] [pid 1021791:tid 1021822] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/blurbs.php"] [unique_id "amujUhGd_N1Op4Iu5U9YsgABUB4"]
[Thu Jul 30 14:17:38.635852 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/blurbs.php"] [unique_id "amujUhGd_N1Op4Iu5U9YsgABUB4"]
[Thu Jul 30 14:17:38.761675 2026] [security2:error] [pid 1021791:tid 1021918] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-ws68.php"] [unique_id "amujUhGd_N1Op4Iu5U9YtAABeX4"]
[Thu Jul 30 14:17:38.761847 2026] [security2:error] [pid 1021791:tid 1022032] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-ws68.php"] [unique_id "amujUhGd_N1Op4Iu5U9YtAABeX4"]
[Thu Jul 30 14:17:38.775549 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.100.187.246:24792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amujUhGd_N1Op4Iu5U9YtQAAARU"]
[Thu Jul 30 14:17:38.900300 2026] [security2:error] [pid 1021791:tid 1021872] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/xyn.php"] [unique_id "amujUhGd_N1Op4Iu5U9YtgABR1A"]
[Thu Jul 30 14:17:38.900475 2026] [security2:error] [pid 1021791:tid 1021982] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/xyn.php"] [unique_id "amujUhGd_N1Op4Iu5U9YtgABR1A"]
[Thu Jul 30 14:17:39.019922 2026] [security2:error] [pid 1021791:tid 1022036] [client 20.91.199.21:64818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/flower.php"] [unique_id "amujUxGd_N1Op4Iu5U9YugAAAX0"]
[Thu Jul 30 14:17:39.025408 2026] [security2:error] [pid 1021791:tid 1021841] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/ccc.php"] [unique_id "amujUxGd_N1Op4Iu5U9YuwABSzE"]
[Thu Jul 30 14:17:39.025559 2026] [security2:error] [pid 1021791:tid 1021986] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/ccc.php"] [unique_id "amujUxGd_N1Op4Iu5U9YuwABSzE"]
[Thu Jul 30 14:17:39.165446 2026] [security2:error] [pid 1021791:tid 1021833] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/get.php"] [unique_id "amujUxGd_N1Op4Iu5U9YwgABSCk"]
[Thu Jul 30 14:17:39.165632 2026] [security2:error] [pid 1021791:tid 1021983] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/get.php"] [unique_id "amujUxGd_N1Op4Iu5U9YwgABSCk"]
[Thu Jul 30 14:17:39.291899 2026] [security2:error] [pid 1021791:tid 1021840] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/images.php"] [unique_id "amujUxGd_N1Op4Iu5U9YwwABFjA"]
[Thu Jul 30 14:17:39.292122 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/images.php"] [unique_id "amujUxGd_N1Op4Iu5U9YwwABFjA"]
[Thu Jul 30 14:17:39.436038 2026] [security2:error] [pid 1021791:tid 1021849] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/alls.php"] [unique_id "amujUxGd_N1Op4Iu5U9YxAABTzk"]
[Thu Jul 30 14:17:39.436211 2026] [security2:error] [pid 1021791:tid 1021990] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/alls.php"] [unique_id "amujUxGd_N1Op4Iu5U9YxAABTzk"]
[Thu Jul 30 14:17:39.573164 2026] [security2:error] [pid 1021791:tid 1021834] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/coffexium.php"] [unique_id "amujUxGd_N1Op4Iu5U9YyAABdio"]
[Thu Jul 30 14:17:39.573347 2026] [security2:error] [pid 1021791:tid 1022029] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/coffexium.php"] [unique_id "amujUxGd_N1Op4Iu5U9YyAABdio"]
[Thu Jul 30 14:17:39.663141 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.100.187.246:28270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amujUxGd_N1Op4Iu5U9YzwAAASI"]
[Thu Jul 30 14:17:39.740059 2026] [security2:error] [pid 1021791:tid 1021843] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/red.php"] [unique_id "amujUxGd_N1Op4Iu5U9Y0QABbjM"]
[Thu Jul 30 14:17:39.740212 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/red.php"] [unique_id "amujUxGd_N1Op4Iu5U9Y0QABbjM"]
[Thu Jul 30 14:17:39.887071 2026] [core:error] [pid 1021791:tid 1021855] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:39.887093 2026] [core:error] [pid 1021791:tid 1021855] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:39.887293 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujUxGd_N1Op4Iu5U9Y0gABTD8"]
[Thu Jul 30 14:17:40.028294 2026] [security2:error] [pid 1021791:tid 1021885] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y1gABb10"]
[Thu Jul 30 14:17:40.028459 2026] [security2:error] [pid 1021791:tid 1022022] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y1gABb10"]
[Thu Jul 30 14:17:40.165598 2026] [core:error] [pid 1021791:tid 1021856] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:40.165630 2026] [core:error] [pid 1021791:tid 1021856] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:40.165830 2026] [security2:error] [pid 1021791:tid 1021992] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y2gABUUA"]
[Thu Jul 30 14:17:40.305087 2026] [core:error] [pid 1021791:tid 1021868] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:40.305109 2026] [core:error] [pid 1021791:tid 1021868] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:40.305286 2026] [security2:error] [pid 1021791:tid 1022019] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y2wABbEw"]
[Thu Jul 30 14:17:40.326671 2026] [security2:error] [pid 1021791:tid 1021810] [remote 57.141.0.24:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/404010317/feed/rss2/"] [unique_id "amujVBGd_N1Op4Iu5U9Y3AABFxI"]
[Thu Jul 30 14:17:40.442912 2026] [security2:error] [pid 1021791:tid 1021889] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/index.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y4AABEGE"]
[Thu Jul 30 14:17:40.443102 2026] [security2:error] [pid 1021791:tid 1021927] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/index.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y4AABEGE"]
[Thu Jul 30 14:17:40.579788 2026] [security2:error] [pid 1021791:tid 1021848] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/admin.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y5gABazg"]
[Thu Jul 30 14:17:40.579920 2026] [security2:error] [pid 1021791:tid 1022018] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/admin.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y5gABazg"]
[Thu Jul 30 14:17:40.607698 2026] [security2:error] [pid 1021791:tid 1022003] [client 20.100.187.246:24825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y5wAAAVw"]
[Thu Jul 30 14:17:40.712891 2026] [security2:error] [pid 1021791:tid 1021859] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/177.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y7wABPEM"]
[Thu Jul 30 14:17:40.713036 2026] [security2:error] [pid 1021791:tid 1021971] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/177.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y7wABPEM"]
[Thu Jul 30 14:17:40.739560 2026] [security2:error] [pid 1021791:tid 1021946] [client 20.91.199.21:25049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/xleet.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y8AAAASM"]
[Thu Jul 30 14:17:40.852020 2026] [security2:error] [pid 1021791:tid 1021898] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/199.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y8QABamo"]
[Thu Jul 30 14:17:40.852210 2026] [security2:error] [pid 1021791:tid 1022017] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/199.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y8QABamo"]
[Thu Jul 30 14:17:40.983942 2026] [security2:error] [pid 1021791:tid 1021836] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/file52.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y8wABRSw"]
[Thu Jul 30 14:17:40.984128 2026] [security2:error] [pid 1021791:tid 1021980] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/file52.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y8wABRSw"]
[Thu Jul 30 14:17:41.023836 2026] [security2:error] [pid 1021791:tid 1021954] [client 216.73.217.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y4gABK3I"], referer: http://allmontecristi.com/sitemap.xml
[Thu Jul 30 14:17:41.115718 2026] [security2:error] [pid 1021791:tid 1021890] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/geck.php"] [unique_id "amujVRGd_N1Op4Iu5U9Y9wABM2I"]
[Thu Jul 30 14:17:41.115855 2026] [security2:error] [pid 1021791:tid 1021962] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/geck.php"] [unique_id "amujVRGd_N1Op4Iu5U9Y9wABM2I"]
[Thu Jul 30 14:17:41.247008 2026] [security2:error] [pid 1021791:tid 1021892] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/biufile.php"] [unique_id "amujVRGd_N1Op4Iu5U9Y_gABJ2Q"]
[Thu Jul 30 14:17:41.247169 2026] [security2:error] [pid 1021791:tid 1021950] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/biufile.php"] [unique_id "amujVRGd_N1Op4Iu5U9Y_gABJ2Q"]
[Thu Jul 30 14:17:41.378725 2026] [security2:error] [pid 1021791:tid 1021875] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/dejavu.php"] [unique_id "amujVRGd_N1Op4Iu5U9Y_wABeVM"]
[Thu Jul 30 14:17:41.378906 2026] [security2:error] [pid 1021791:tid 1022032] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/dejavu.php"] [unique_id "amujVRGd_N1Op4Iu5U9Y_wABeVM"]
[Thu Jul 30 14:17:41.511393 2026] [security2:error] [pid 1021791:tid 1021879] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/aaf.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZAAABR1c"]
[Thu Jul 30 14:17:41.511560 2026] [security2:error] [pid 1021791:tid 1021982] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/aaf.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZAAABR1c"]
[Thu Jul 30 14:17:41.543559 2026] [security2:error] [pid 1021791:tid 1021965] [client 172.237.109.114:24775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujVBGd_N1Op4Iu5U9Y8gAAATY"]
[Thu Jul 30 14:17:41.598373 2026] [security2:error] [pid 1021791:tid 1021970] [client 20.91.199.21:64792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZBQAAATs"]
[Thu Jul 30 14:17:41.643179 2026] [security2:error] [pid 1021791:tid 1021830] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/ha.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZBwABNSY"]
[Thu Jul 30 14:17:41.643363 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/ha.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZBwABNSY"]
[Thu Jul 30 14:17:41.777264 2026] [security2:error] [pid 1021791:tid 1021866] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/hur.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZDwABZ0o"]
[Thu Jul 30 14:17:41.777408 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/hur.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZDwABZ0o"]
[Thu Jul 30 14:17:41.890456 2026] [security2:error] [pid 1021791:tid 1021990] [client 172.213.208.20:37959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZEAAAAU8"]
[Thu Jul 30 14:17:41.915740 2026] [security2:error] [pid 1021791:tid 1021877] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/h02ugyh.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZEQABZlU"]
[Thu Jul 30 14:17:41.915944 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/h02ugyh.php"] [unique_id "amujVRGd_N1Op4Iu5U9ZEQABZlU"]
[Thu Jul 30 14:17:42.049235 2026] [security2:error] [pid 1021791:tid 1021880] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/155.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZEwABdFg"]
[Thu Jul 30 14:17:42.049426 2026] [security2:error] [pid 1021791:tid 1022027] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/155.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZEwABdFg"]
[Thu Jul 30 14:17:42.181496 2026] [security2:error] [pid 1021791:tid 1021895] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/ops.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZFwABd2c"]
[Thu Jul 30 14:17:42.181672 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/ops.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZFwABd2c"]
[Thu Jul 30 14:17:42.313995 2026] [security2:error] [pid 1021791:tid 1021888] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/ingfo.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZHgABQ2A"]
[Thu Jul 30 14:17:42.314162 2026] [security2:error] [pid 1021791:tid 1021978] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/ingfo.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZHgABQ2A"]
[Thu Jul 30 14:17:42.346871 2026] [security2:error] [pid 1021791:tid 1021979] [client 20.91.199.21:31358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/user/flower.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZHwAAAUQ"]
[Thu Jul 30 14:17:42.446152 2026] [security2:error] [pid 1021791:tid 1021863] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/error_log.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZIAABJUc"]
[Thu Jul 30 14:17:42.446372 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/error_log.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZIAABJUc"]
[Thu Jul 30 14:17:42.579047 2026] [security2:error] [pid 1021791:tid 1021870] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/koala.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZJAABME4"]
[Thu Jul 30 14:17:42.579253 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/koala.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZJAABME4"]
[Thu Jul 30 14:17:42.714607 2026] [security2:error] [pid 1021791:tid 1021857] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/mac.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZKAABD0E"]
[Thu Jul 30 14:17:42.714738 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/mac.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZKAABD0E"]
[Thu Jul 30 14:17:42.725414 2026] [security2:error] [pid 1021791:tid 1021995] [client 172.213.208.20:41790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/index/function.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZKwAAAVQ"]
[Thu Jul 30 14:17:42.882359 2026] [security2:error] [pid 1021791:tid 1021867] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wefile.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZMAABXEs"]
[Thu Jul 30 14:17:42.882564 2026] [security2:error] [pid 1021791:tid 1022003] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wefile.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZMAABXEs"]
[Thu Jul 30 14:17:42.963284 2026] [security2:error] [pid 1021791:tid 1022042] [client 20.100.187.246:24774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amujVhGd_N1Op4Iu5U9ZMQAAAYM"]
[Thu Jul 30 14:17:43.018409 2026] [core:error] [pid 1021791:tid 1021907] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:43.018443 2026] [core:error] [pid 1021791:tid 1021907] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:43.018631 2026] [security2:error] [pid 1021791:tid 1021956] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZMgABLXM"]
[Thu Jul 30 14:17:43.163833 2026] [core:error] [pid 1021791:tid 1021915] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:43.163856 2026] [core:error] [pid 1021791:tid 1021915] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:43.164043 2026] [security2:error] [pid 1021791:tid 1021968] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZMwABOXs"]
[Thu Jul 30 14:17:43.192301 2026] [core:notice] [pid 1021791:tid 1021957] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:43.195375 2026] [security2:error] [pid 1021791:tid 1021957] [client 135.181.74.155:59206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/this-is-the-right-way-to-ask-a-girl-out-over-text.html"] [unique_id "amujVxGd_N1Op4Iu5U9ZNwAAAS4"]
[Thu Jul 30 14:17:43.297960 2026] [security2:error] [pid 1021791:tid 1021884] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/makeasmtp.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZOwABaVw"]
[Thu Jul 30 14:17:43.298113 2026] [security2:error] [pid 1021791:tid 1022016] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/makeasmtp.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZOwABaVw"]
[Thu Jul 30 14:17:43.430732 2026] [security2:error] [pid 1021791:tid 1021827] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/2P.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZPwABCyM"]
[Thu Jul 30 14:17:43.431025 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/2P.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZPwABCyM"]
[Thu Jul 30 14:17:43.524458 2026] [security2:error] [pid 1021791:tid 1021961] [client 20.91.199.21:31298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/user/xleet.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZQAAAATI"]
[Thu Jul 30 14:17:43.566919 2026] [security2:error] [pid 1021791:tid 1021909] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/.well-known/about.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZQQABJ3U"]
[Thu Jul 30 14:17:43.567105 2026] [security2:error] [pid 1021791:tid 1021950] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/.well-known/about.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZQQABJ3U"]
[Thu Jul 30 14:17:43.653428 2026] [security2:error] [pid 1021791:tid 1021928] [client 20.100.187.246:24038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZQgAAARE"]
[Thu Jul 30 14:17:43.704658 2026] [security2:error] [pid 1021791:tid 1021903] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZQwABV28"]
[Thu Jul 30 14:17:43.704868 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZQwABV28"]
[Thu Jul 30 14:17:43.838290 2026] [security2:error] [pid 1021791:tid 1021914] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/system_log.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZTQABL3o"]
[Thu Jul 30 14:17:43.838439 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/system_log.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZTQABL3o"]
[Thu Jul 30 14:17:43.977328 2026] [core:error] [pid 1021791:tid 1021910] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:43.977353 2026] [core:error] [pid 1021791:tid 1021910] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:43.977537 2026] [security2:error] [pid 1021791:tid 1022001] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZUQABWnY"]
[Thu Jul 30 14:17:44.115047 2026] [core:error] [pid 1021791:tid 1021864] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:44.115075 2026] [core:error] [pid 1021791:tid 1021864] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:44.115302 2026] [security2:error] [pid 1021791:tid 1021969] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZUgABOkg"]
[Thu Jul 30 14:17:44.250349 2026] [security2:error] [pid 1021791:tid 1021795] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/crgio.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZVwABFQM"]
[Thu Jul 30 14:17:44.250529 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/crgio.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZVwABFQM"]
[Thu Jul 30 14:17:44.383264 2026] [security2:error] [pid 1021791:tid 1021916] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/pucci.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZXgABd3w"]
[Thu Jul 30 14:17:44.383469 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/pucci.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZXgABd3w"]
[Thu Jul 30 14:17:44.456986 2026] [security2:error] [pid 1021791:tid 1022045] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amujVxGd_N1Op4Iu5U9ZTAAAAYY"]
[Thu Jul 30 14:17:44.521501 2026] [core:error] [pid 1021791:tid 1021917] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:44.521531 2026] [core:error] [pid 1021791:tid 1021917] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:44.521717 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZYQABIn0"]
[Thu Jul 30 14:17:44.660005 2026] [security2:error] [pid 1021791:tid 1021793] [remote 57.141.0.28:42578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amujWBGd_N1Op4Iu5U9ZYwABfgE"]
[Thu Jul 30 14:17:44.688094 2026] [core:error] [pid 1021791:tid 1021883] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:44.688116 2026] [core:error] [pid 1021791:tid 1021883] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:44.688273 2026] [security2:error] [pid 1021791:tid 1022022] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZZAABb1s"]
[Thu Jul 30 14:17:44.821221 2026] [security2:error] [pid 1021791:tid 1021801] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-temp.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZawABaAk"]
[Thu Jul 30 14:17:44.821408 2026] [security2:error] [pid 1021791:tid 1022015] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-temp.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZawABaAk"]
[Thu Jul 30 14:17:44.953567 2026] [security2:error] [pid 1021791:tid 1021807] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-admin/js/index.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZcgABTg8"]
[Thu Jul 30 14:17:44.953715 2026] [security2:error] [pid 1021791:tid 1021989] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-admin/js/index.php"] [unique_id "amujWBGd_N1Op4Iu5U9ZcgABTg8"]
[Thu Jul 30 14:17:45.046314 2026] [security2:error] [pid 1021791:tid 1022023] [client 68.67.112.136:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "itrnetwork.org"] [uri "/prof-dr-andres-baez-moreno/"] [unique_id "amujWRGd_N1Op4Iu5U9ZdAAAAXA"]
[Thu Jul 30 14:17:45.087501 2026] [security2:error] [pid 1021791:tid 1021912] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/puc.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZdQABRng"]
[Thu Jul 30 14:17:45.087672 2026] [security2:error] [pid 1021791:tid 1021981] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/puc.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZdQABRng"]
[Thu Jul 30 14:17:45.222258 2026] [security2:error] [pid 1021791:tid 1021887] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/dx.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZdwABPl8"]
[Thu Jul 30 14:17:45.222433 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/dx.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZdwABPl8"]
[Thu Jul 30 14:17:45.359649 2026] [core:error] [pid 1021791:tid 1021919] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:45.359672 2026] [core:error] [pid 1021791:tid 1021919] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:45.359855 2026] [security2:error] [pid 1021791:tid 1021925] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZewABDn8"]
[Thu Jul 30 14:17:45.401144 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.100.187.246:6310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZfwAAAUw"]
[Thu Jul 30 14:17:45.496054 2026] [security2:error] [pid 1021791:tid 1021811] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/7.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZgwABXRM"]
[Thu Jul 30 14:17:45.496308 2026] [security2:error] [pid 1021791:tid 1022004] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/7.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZgwABXRM"]
[Thu Jul 30 14:17:45.525359 2026] [security2:error] [pid 1021791:tid 1022006] [client 219.76.254.140:18281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2016/05/Ikea-ANVANDBAR-beurrier-585x439.jpg"] [unique_id "amujWRGd_N1Op4Iu5U9ZhAAAAV8"]
[Thu Jul 30 14:17:45.629436 2026] [security2:error] [pid 1021791:tid 1021797] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/8.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZhQABMwU"]
[Thu Jul 30 14:17:45.629610 2026] [security2:error] [pid 1021791:tid 1021962] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/8.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZhQABMwU"]
[Thu Jul 30 14:17:45.763968 2026] [security2:error] [pid 1021791:tid 1021808] [remote 20.203.133.142:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.allmontecristi.com"] [uri "/1.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZhgABghA"]
[Thu Jul 30 14:17:45.764098 2026] [security2:error] [pid 1021791:tid 1021808] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/1.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZhgABghA"]
[Thu Jul 30 14:17:45.764318 2026] [security2:error] [pid 1021791:tid 1022041] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/1.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZhgABghA"]
[Thu Jul 30 14:17:45.896506 2026] [security2:error] [pid 1021791:tid 1021805] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/about.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZjgABPQ0"]
[Thu Jul 30 14:17:45.896670 2026] [security2:error] [pid 1021791:tid 1021972] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/about.php"] [unique_id "amujWRGd_N1Op4Iu5U9ZjgABPQ0"]
[Thu Jul 30 14:17:46.055933 2026] [security2:error] [pid 1021791:tid 1021901] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/admin.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZlAABWm0"]
[Thu Jul 30 14:17:46.056113 2026] [security2:error] [pid 1021791:tid 1022001] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/admin.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZlAABWm0"]
[Thu Jul 30 14:17:46.188701 2026] [security2:error] [pid 1021791:tid 1021825] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/edit.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZlwABHCE"]
[Thu Jul 30 14:17:46.188853 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/edit.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZlwABHCE"]
[Thu Jul 30 14:17:46.321856 2026] [security2:error] [pid 1021791:tid 1021835] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/admin.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZmQABZis"]
[Thu Jul 30 14:17:46.322041 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/admin.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZmQABZis"]
[Thu Jul 30 14:17:46.456204 2026] [security2:error] [pid 1021791:tid 1021821] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/inputs.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZoQABHh0"]
[Thu Jul 30 14:17:46.456380 2026] [security2:error] [pid 1021791:tid 1021941] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/inputs.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZoQABHh0"]
[Thu Jul 30 14:17:46.591026 2026] [security2:error] [pid 1021791:tid 1021819] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/av.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZqAABYhs"]
[Thu Jul 30 14:17:46.591252 2026] [security2:error] [pid 1021791:tid 1022009] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/av.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZqAABYhs"]
[Thu Jul 30 14:17:46.693331 2026] [security2:error] [pid 1021791:tid 1021990] [client 20.100.187.246:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZqQAAAU8"]
[Thu Jul 30 14:17:46.726277 2026] [security2:error] [pid 1021791:tid 1021800] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/classwithtostring.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZqwABNwg"]
[Thu Jul 30 14:17:46.726424 2026] [security2:error] [pid 1021791:tid 1021966] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/classwithtostring.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZqwABNwg"]
[Thu Jul 30 14:17:46.786021 2026] [security2:error] [pid 1021791:tid 1021949] [client 20.91.199.21:18867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/xleet.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZrQAAASY"]
[Thu Jul 30 14:17:46.859468 2026] [security2:error] [pid 1021791:tid 1021824] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/themes/index.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZtAABECA"]
[Thu Jul 30 14:17:46.859722 2026] [security2:error] [pid 1021791:tid 1021927] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/themes/index.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZtAABECA"]
[Thu Jul 30 14:17:46.993474 2026] [security2:error] [pid 1021791:tid 1021853] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-blog.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZugABgz0"]
[Thu Jul 30 14:17:46.993633 2026] [security2:error] [pid 1021791:tid 1022042] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-blog.php"] [unique_id "amujWhGd_N1Op4Iu5U9ZugABgz0"]
[Thu Jul 30 14:17:47.135524 2026] [core:error] [pid 1021791:tid 1021845] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:47.135557 2026] [core:error] [pid 1021791:tid 1021845] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:47.135767 2026] [security2:error] [pid 1021791:tid 1021957] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujWxGd_N1Op4Iu5U9ZvQABLjU"]
[Thu Jul 30 14:17:47.144497 2026] [security2:error] [pid 1021791:tid 1021938] [client 180.243.59.178:49194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujWxGd_N1Op4Iu5U9ZvgAAARs"]
[Thu Jul 30 14:17:47.144619 2026] [security2:error] [pid 1021791:tid 1021938] [client 180.243.59.178:49194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujWxGd_N1Op4Iu5U9ZvgAAARs"]
[Thu Jul 30 14:17:47.268195 2026] [security2:error] [pid 1021791:tid 1021837] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/admin.php"] [unique_id "amujWxGd_N1Op4Iu5U9ZxAABMy0"]
[Thu Jul 30 14:17:47.268322 2026] [security2:error] [pid 1021791:tid 1021962] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-content/admin.php"] [unique_id "amujWxGd_N1Op4Iu5U9ZxAABMy0"]
[Thu Jul 30 14:17:47.403354 2026] [security2:error] [pid 1021791:tid 1021841] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/adminfuns.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z0QABUDE"]
[Thu Jul 30 14:17:47.403575 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/adminfuns.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z0QABUDE"]
[Thu Jul 30 14:17:47.529485 2026] [security2:error] [pid 1021791:tid 1021961] [client 20.100.187.246:24016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z3AAAATI"]
[Thu Jul 30 14:17:47.540392 2026] [security2:error] [pid 1021791:tid 1021839] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/goods.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z3QABYS8"]
[Thu Jul 30 14:17:47.540543 2026] [security2:error] [pid 1021791:tid 1022008] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/goods.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z3QABYS8"]
[Thu Jul 30 14:17:47.673697 2026] [security2:error] [pid 1021791:tid 1021834] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/ms-edit.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z5QABKCo"]
[Thu Jul 30 14:17:47.673890 2026] [security2:error] [pid 1021791:tid 1021951] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/ms-edit.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z5QABKCo"]
[Thu Jul 30 14:17:47.692090 2026] [core:notice] [pid 1021791:tid 1022007] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:47.694348 2026] [security2:error] [pid 1021791:tid 1021954] [client 20.91.199.21:19250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-config-sample.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z5wAAASs"]
[Thu Jul 30 14:17:47.824900 2026] [security2:error] [pid 1021791:tid 1021847] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/222.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z6gABYjc"]
[Thu Jul 30 14:17:47.825055 2026] [security2:error] [pid 1021791:tid 1022009] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/222.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z6gABYjc"]
[Thu Jul 30 14:17:47.895346 2026] [core:error] [pid 1021791:tid 1021983] [client 74.7.244.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:47.895365 2026] [core:error] [pid 1021791:tid 1021983] [client 74.7.244.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:47.895485 2026] [security2:error] [pid 1021791:tid 1021983] [client 74.7.244.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.dug.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z7QAAAUg"]
[Thu Jul 30 14:17:47.896111 2026] [security2:error] [pid 1021791:tid 1021924] [client 74.7.244.42:50408] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.dug.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amujWxGd_N1Op4Iu5U9Z6wABDTw"]
[Thu Jul 30 14:17:47.958640 2026] [security2:error] [pid 1021791:tid 1021855] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/cgi-bin/index.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z8QABIT8"]
[Thu Jul 30 14:17:47.958857 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/cgi-bin/index.php"] [unique_id "amujWxGd_N1Op4Iu5U9Z8QABIT8"]
[Thu Jul 30 14:17:48.027430 2026] [security2:error] [pid 1021791:tid 1021865] [remote 104.210.56.224:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.56.210.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/citationstylelanguage/get/apa"] [unique_id "amujXBGd_N1Op4Iu5U9Z9QABIkk"]
[Thu Jul 30 14:17:48.110811 2026] [core:error] [pid 1021791:tid 1021856] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:48.110837 2026] [core:error] [pid 1021791:tid 1021856] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:48.111078 2026] [security2:error] [pid 1021791:tid 1021980] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujXBGd_N1Op4Iu5U9Z_gABRUA"]
[Thu Jul 30 14:17:48.250241 2026] [security2:error] [pid 1021791:tid 1021810] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/BDKR28WP.php"] [unique_id "amujXBGd_N1Op4Iu5U9aAwABERI"]
[Thu Jul 30 14:17:48.250433 2026] [security2:error] [pid 1021791:tid 1021928] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/BDKR28WP.php"] [unique_id "amujXBGd_N1Op4Iu5U9aAwABERI"]
[Thu Jul 30 14:17:48.385942 2026] [core:error] [pid 1021791:tid 1021794] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:48.385961 2026] [core:error] [pid 1021791:tid 1021794] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:48.386119 2026] [security2:error] [pid 1021791:tid 1021969] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujXBGd_N1Op4Iu5U9aDwABOgI"]
[Thu Jul 30 14:17:48.521827 2026] [core:error] [pid 1021791:tid 1021900] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:48.521846 2026] [core:error] [pid 1021791:tid 1021900] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:48.522013 2026] [security2:error] [pid 1021791:tid 1021953] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujXBGd_N1Op4Iu5U9aNQABKmw"]
[Thu Jul 30 14:17:48.663845 2026] [security2:error] [pid 1021791:tid 1021836] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp.php"] [unique_id "amujXBGd_N1Op4Iu5U9aOwABVSw"]
[Thu Jul 30 14:17:48.664033 2026] [security2:error] [pid 1021791:tid 1021996] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp.php"] [unique_id "amujXBGd_N1Op4Iu5U9aOwABVSw"]
[Thu Jul 30 14:17:48.797640 2026] [security2:error] [pid 1021791:tid 1021906] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/abcd.php"] [unique_id "amujXBGd_N1Op4Iu5U9aPQABQHI"]
[Thu Jul 30 14:17:48.797842 2026] [security2:error] [pid 1021791:tid 1021975] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/abcd.php"] [unique_id "amujXBGd_N1Op4Iu5U9aPQABQHI"]
[Thu Jul 30 14:17:48.823215 2026] [core:notice] [pid 1021791:tid 1021969] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:48.828277 2026] [security2:error] [pid 1021791:tid 1021969] [client 135.181.74.155:59216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/de-sub/this-is-what-the-holidays-are-like-when-you-ve-lost-a-loved-one.html"] [unique_id "amujXBGd_N1Op4Iu5U9aPgAAATo"]
[Thu Jul 30 14:17:48.936060 2026] [security2:error] [pid 1021791:tid 1021890] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/a1.php"] [unique_id "amujXBGd_N1Op4Iu5U9aSAABHWI"]
[Thu Jul 30 14:17:48.936246 2026] [security2:error] [pid 1021791:tid 1021940] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/a1.php"] [unique_id "amujXBGd_N1Op4Iu5U9aSAABHWI"]
[Thu Jul 30 14:17:49.071477 2026] [security2:error] [pid 1021791:tid 1021875] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amujXRGd_N1Op4Iu5U9aawABRVM"]
[Thu Jul 30 14:17:49.071695 2026] [security2:error] [pid 1021791:tid 1021980] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amujXRGd_N1Op4Iu5U9aawABRVM"]
[Thu Jul 30 14:17:49.190437 2026] [security2:error] [pid 1021791:tid 1021975] [client 82.102.27.195:53076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amujXRGd_N1Op4Iu5U9aegAAAUA"]
[Thu Jul 30 14:17:49.190535 2026] [security2:error] [pid 1021791:tid 1021975] [client 82.102.27.195:53076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amujXRGd_N1Op4Iu5U9aegAAAUA"]
[Thu Jul 30 14:17:49.205806 2026] [security2:error] [pid 1021791:tid 1021879] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/cgi-bin/admin.php"] [unique_id "amujXRGd_N1Op4Iu5U9afQABfFc"]
[Thu Jul 30 14:17:49.205999 2026] [security2:error] [pid 1021791:tid 1022035] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/cgi-bin/admin.php"] [unique_id "amujXRGd_N1Op4Iu5U9afQABfFc"]
[Thu Jul 30 14:17:49.210282 2026] [core:notice] [pid 1021791:tid 1021994] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:49.322163 2026] [security2:error] [pid 1021791:tid 1022022] [client 20.100.187.246:24799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amujXRGd_N1Op4Iu5U9ajAAAAW8"]
[Thu Jul 30 14:17:49.365392 2026] [core:error] [pid 1021791:tid 1021886] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:49.365421 2026] [core:error] [pid 1021791:tid 1021886] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:49.365626 2026] [security2:error] [pid 1021791:tid 1022023] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujXRGd_N1Op4Iu5U9ajwABcF4"]
[Thu Jul 30 14:17:49.499239 2026] [security2:error] [pid 1021791:tid 1021830] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/simple.php"] [unique_id "amujXRGd_N1Op4Iu5U9alQABPSY"]
[Thu Jul 30 14:17:49.499470 2026] [security2:error] [pid 1021791:tid 1021972] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/simple.php"] [unique_id "amujXRGd_N1Op4Iu5U9alQABPSY"]
[Thu Jul 30 14:17:49.638808 2026] [security2:error] [pid 1021791:tid 1021874] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/xxx.php"] [unique_id "amujXRGd_N1Op4Iu5U9amQABblI"]
[Thu Jul 30 14:17:49.639019 2026] [security2:error] [pid 1021791:tid 1022021] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/xxx.php"] [unique_id "amujXRGd_N1Op4Iu5U9amQABblI"]
[Thu Jul 30 14:17:49.771384 2026] [security2:error] [pid 1021791:tid 1021866] [remote 57.141.0.8:44342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4754262821/feed/rss2/"] [unique_id "amujXRGd_N1Op4Iu5U9aoAABG0o"]
[Thu Jul 30 14:17:49.772212 2026] [security2:error] [pid 1021791:tid 1021877] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/hypo.php"] [unique_id "amujXRGd_N1Op4Iu5U9aoQABL1U"]
[Thu Jul 30 14:17:49.772441 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/hypo.php"] [unique_id "amujXRGd_N1Op4Iu5U9aoQABL1U"]
[Thu Jul 30 14:17:49.909645 2026] [core:error] [pid 1021791:tid 1021895] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:49.909677 2026] [core:error] [pid 1021791:tid 1021895] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:49.909940 2026] [security2:error] [pid 1021791:tid 1021931] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujXRGd_N1Op4Iu5U9apwABFGc"]
[Thu Jul 30 14:17:50.042888 2026] [security2:error] [pid 1021791:tid 1021860] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/chosen.php"] [unique_id "amujXhGd_N1Op4Iu5U9atQABTkQ"]
[Thu Jul 30 14:17:50.043055 2026] [security2:error] [pid 1021791:tid 1021989] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/chosen.php"] [unique_id "amujXhGd_N1Op4Iu5U9atQABTkQ"]
[Thu Jul 30 14:17:50.180763 2026] [core:error] [pid 1021791:tid 1021888] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:50.180783 2026] [core:error] [pid 1021791:tid 1021888] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:50.180925 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujXhGd_N1Op4Iu5U9avQABMGA"]
[Thu Jul 30 14:17:50.318657 2026] [security2:error] [pid 1021791:tid 1021878] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/als.php"] [unique_id "amujXhGd_N1Op4Iu5U9ayAABC1Y"]
[Thu Jul 30 14:17:50.318811 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/als.php"] [unique_id "amujXhGd_N1Op4Iu5U9ayAABC1Y"]
[Thu Jul 30 14:17:50.392210 2026] [security2:error] [pid 1021791:tid 1021870] [remote 57.141.0.15:21052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amujXhGd_N1Op4Iu5U9aywABZE4"]
[Thu Jul 30 14:17:50.452025 2026] [security2:error] [pid 1021791:tid 1021899] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/pol.php"] [unique_id "amujXhGd_N1Op4Iu5U9azQABGms"]
[Thu Jul 30 14:17:50.452177 2026] [security2:error] [pid 1021791:tid 1021937] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/pol.php"] [unique_id "amujXhGd_N1Op4Iu5U9azQABGms"]
[Thu Jul 30 14:17:50.584909 2026] [security2:error] [pid 1021791:tid 1021857] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/file5.php"] [unique_id "amujXhGd_N1Op4Iu5U9a0wABc0E"]
[Thu Jul 30 14:17:50.585085 2026] [security2:error] [pid 1021791:tid 1022026] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/file5.php"] [unique_id "amujXhGd_N1Op4Iu5U9a0wABc0E"]
[Thu Jul 30 14:17:50.664161 2026] [fcgid:warn] [pid 1021791:tid 1021958] (70014)End of file found: [client 118.194.249.72:45022] mod_fcgid: can't get data from http client
[Thu Jul 30 14:17:50.718516 2026] [security2:error] [pid 1021791:tid 1021869] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/file.php"] [unique_id "amujXhGd_N1Op4Iu5U9a2gABU00"]
[Thu Jul 30 14:17:50.718671 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/file.php"] [unique_id "amujXhGd_N1Op4Iu5U9a2gABU00"]
[Thu Jul 30 14:17:50.851291 2026] [security2:error] [pid 1021791:tid 1021915] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/admin.php"] [unique_id "amujXhGd_N1Op4Iu5U9a5wABLHs"]
[Thu Jul 30 14:17:50.851425 2026] [security2:error] [pid 1021791:tid 1021955] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/admin.php"] [unique_id "amujXhGd_N1Op4Iu5U9a5wABLHs"]
[Thu Jul 30 14:17:50.984923 2026] [security2:error] [pid 1021791:tid 1021897] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/aa2.php"] [unique_id "amujXhGd_N1Op4Iu5U9a7gABiGk"]
[Thu Jul 30 14:17:50.985151 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/aa2.php"] [unique_id "amujXhGd_N1Op4Iu5U9a7gABiGk"]
[Thu Jul 30 14:17:51.022864 2026] [core:notice] [pid 1021791:tid 1021927] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:51.120270 2026] [security2:error] [pid 1021791:tid 1021884] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/ccou.php"] [unique_id "amujXxGd_N1Op4Iu5U9a8gABMFw"]
[Thu Jul 30 14:17:51.120453 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/ccou.php"] [unique_id "amujXxGd_N1Op4Iu5U9a8gABMFw"]
[Thu Jul 30 14:17:51.257098 2026] [security2:error] [pid 1021791:tid 1021827] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/dr.php"] [unique_id "amujXxGd_N1Op4Iu5U9a_AABEiM"]
[Thu Jul 30 14:17:51.257306 2026] [security2:error] [pid 1021791:tid 1021929] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/dr.php"] [unique_id "amujXxGd_N1Op4Iu5U9a_AABEiM"]
[Thu Jul 30 14:17:51.406498 2026] [security2:error] [pid 1021791:tid 1021894] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/xamp.php"] [unique_id "amujXxGd_N1Op4Iu5U9bBQABGmY"]
[Thu Jul 30 14:17:51.406683 2026] [security2:error] [pid 1021791:tid 1021937] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/xamp.php"] [unique_id "amujXxGd_N1Op4Iu5U9bBQABGmY"]
[Thu Jul 30 14:17:51.499633 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.100.187.246:24017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amujXxGd_N1Op4Iu5U9bBwAAAT4"]
[Thu Jul 30 14:17:51.518497 2026] [security2:error] [pid 1021791:tid 1021991] [client 172.237.109.114:24672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujXxGd_N1Op4Iu5U9a7wAAAVA"]
[Thu Jul 30 14:17:51.562345 2026] [security2:error] [pid 1021791:tid 1021911] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/bless.php"] [unique_id "amujXxGd_N1Op4Iu5U9bCAABeXc"]
[Thu Jul 30 14:17:51.562526 2026] [security2:error] [pid 1021791:tid 1022032] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/bless.php"] [unique_id "amujXxGd_N1Op4Iu5U9bCAABeXc"]
[Thu Jul 30 14:17:51.696034 2026] [security2:error] [pid 1021791:tid 1021914] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/file25.php"] [unique_id "amujXxGd_N1Op4Iu5U9bCwABc3o"]
[Thu Jul 30 14:17:51.696199 2026] [security2:error] [pid 1021791:tid 1022026] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/file25.php"] [unique_id "amujXxGd_N1Op4Iu5U9bCwABc3o"]
[Thu Jul 30 14:17:51.830180 2026] [security2:error] [pid 1021791:tid 1021910] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/file6.php"] [unique_id "amujXxGd_N1Op4Iu5U9bDwABZXY"]
[Thu Jul 30 14:17:51.830329 2026] [security2:error] [pid 1021791:tid 1022012] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/file6.php"] [unique_id "amujXxGd_N1Op4Iu5U9bDwABZXY"]
[Thu Jul 30 14:17:51.975495 2026] [security2:error] [pid 1021791:tid 1021831] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/a2.php"] [unique_id "amujXxGd_N1Op4Iu5U9bFwABeCc"]
[Thu Jul 30 14:17:51.975640 2026] [security2:error] [pid 1021791:tid 1022031] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/a2.php"] [unique_id "amujXxGd_N1Op4Iu5U9bFwABeCc"]
[Thu Jul 30 14:17:52.086200 2026] [security2:error] [pid 1021791:tid 1021957] [client 20.100.187.246:24030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/amaxx.php"] [unique_id "amujYBGd_N1Op4Iu5U9bHwAAAS4"]
[Thu Jul 30 14:17:52.111124 2026] [security2:error] [pid 1021791:tid 1021891] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/file15.php"] [unique_id "amujYBGd_N1Op4Iu5U9bIgABF2M"]
[Thu Jul 30 14:17:52.111321 2026] [security2:error] [pid 1021791:tid 1021934] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/file15.php"] [unique_id "amujYBGd_N1Op4Iu5U9bIgABF2M"]
[Thu Jul 30 14:17:52.189368 2026] [security2:error] [pid 1021791:tid 1021981] [client 152.32.208.73:41054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-3f57df65.evk.gpl.temporary.site"] [uri "/index.php"] [unique_id "amujYBGd_N1Op4Iu5U9bIQAAAUY"]
[Thu Jul 30 14:17:52.244278 2026] [security2:error] [pid 1021791:tid 1021858] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/f35.php"] [unique_id "amujYBGd_N1Op4Iu5U9bLAABIkI"]
[Thu Jul 30 14:17:52.244453 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/f35.php"] [unique_id "amujYBGd_N1Op4Iu5U9bLAABIkI"]
[Thu Jul 30 14:17:52.378211 2026] [security2:error] [pid 1021791:tid 1021883] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-load.php"] [unique_id "amujYBGd_N1Op4Iu5U9bNAABQFs"]
[Thu Jul 30 14:17:52.378415 2026] [security2:error] [pid 1021791:tid 1021975] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-load.php"] [unique_id "amujYBGd_N1Op4Iu5U9bNAABQFs"]
[Thu Jul 30 14:17:52.524866 2026] [security2:error] [pid 1021791:tid 1021896] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/xwpg.php"] [unique_id "amujYBGd_N1Op4Iu5U9bPgABgWg"]
[Thu Jul 30 14:17:52.525073 2026] [security2:error] [pid 1021791:tid 1022040] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/xwpg.php"] [unique_id "amujYBGd_N1Op4Iu5U9bPgABgWg"]
[Thu Jul 30 14:17:52.679892 2026] [core:error] [pid 1021791:tid 1021807] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:52.679912 2026] [core:error] [pid 1021791:tid 1021807] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:52.680093 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujYBGd_N1Op4Iu5U9bRAABhQ8"]
[Thu Jul 30 14:17:52.816574 2026] [core:error] [pid 1021791:tid 1021792] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:52.816607 2026] [core:error] [pid 1021791:tid 1021792] [remote 20.203.133.142:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:17:52.816777 2026] [security2:error] [pid 1021791:tid 1022015] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "webmail.allmontecristi.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amujYBGd_N1Op4Iu5U9bSAABaAA"]
[Thu Jul 30 14:17:52.825105 2026] [security2:error] [pid 1021791:tid 1021912] [remote 57.141.0.56:28778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amujYBGd_N1Op4Iu5U9bSQABOng"]
[Thu Jul 30 14:17:52.841076 2026] [security2:error] [pid 1021791:tid 1021887] [remote 207.46.13.154:29004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/en-us/indexf.php"] [unique_id "amujYBGd_N1Op4Iu5U9bSgABI18"]
[Thu Jul 30 14:17:52.960264 2026] [security2:error] [pid 1021791:tid 1021919] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/xstelth.php"] [unique_id "amujYBGd_N1Op4Iu5U9bTwABZ38"]
[Thu Jul 30 14:17:52.960410 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/xstelth.php"] [unique_id "amujYBGd_N1Op4Iu5U9bTwABZ38"]
[Thu Jul 30 14:17:53.014078 2026] [security2:error] [pid 1021791:tid 1021997] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujYBGd_N1Op4Iu5U9bMwABVgE"]
[Thu Jul 30 14:17:53.093337 2026] [security2:error] [pid 1021791:tid 1021816] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amujYRGd_N1Op4Iu5U9bVQABPxg"]
[Thu Jul 30 14:17:53.093469 2026] [security2:error] [pid 1021791:tid 1021974] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amujYRGd_N1Op4Iu5U9bVQABPxg"]
[Thu Jul 30 14:17:53.231525 2026] [security2:error] [pid 1021791:tid 1021811] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/aaa.php"] [unique_id "amujYRGd_N1Op4Iu5U9bWwABHxM"]
[Thu Jul 30 14:17:53.231702 2026] [security2:error] [pid 1021791:tid 1021942] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/aaa.php"] [unique_id "amujYRGd_N1Op4Iu5U9bWwABHxM"]
[Thu Jul 30 14:17:53.251834 2026] [security2:error] [pid 1021791:tid 1021985] [client 20.100.187.246:28235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/bek.php"] [unique_id "amujYRGd_N1Op4Iu5U9bXwAAAUo"]
[Thu Jul 30 14:17:53.380398 2026] [security2:error] [pid 1021791:tid 1021805] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/gecko.php"] [unique_id "amujYRGd_N1Op4Iu5U9bZwABCw0"]
[Thu Jul 30 14:17:53.380541 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/gecko.php"] [unique_id "amujYRGd_N1Op4Iu5U9bZwABCw0"]
[Thu Jul 30 14:17:53.512621 2026] [security2:error] [pid 1021791:tid 1021854] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/pbck.php"] [unique_id "amujYRGd_N1Op4Iu5U9bcgABNz4"]
[Thu Jul 30 14:17:53.512771 2026] [security2:error] [pid 1021791:tid 1021966] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/pbck.php"] [unique_id "amujYRGd_N1Op4Iu5U9bcgABNz4"]
[Thu Jul 30 14:17:53.656516 2026] [security2:error] [pid 1021791:tid 1021832] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/xiugai.php"] [unique_id "amujYRGd_N1Op4Iu5U9bfgABYCg"]
[Thu Jul 30 14:17:53.656685 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/xiugai.php"] [unique_id "amujYRGd_N1Op4Iu5U9bfgABYCg"]
[Thu Jul 30 14:17:53.816651 2026] [security2:error] [pid 1021791:tid 1021800] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/e.php"] [unique_id "amujYRGd_N1Op4Iu5U9bgwABiQg"]
[Thu Jul 30 14:17:53.816833 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/e.php"] [unique_id "amujYRGd_N1Op4Iu5U9bgwABiQg"]
[Thu Jul 30 14:17:53.958447 2026] [security2:error] [pid 1021791:tid 1021862] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/adminner.php"] [unique_id "amujYRGd_N1Op4Iu5U9bjAABLEY"]
[Thu Jul 30 14:17:53.958639 2026] [security2:error] [pid 1021791:tid 1021955] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/adminner.php"] [unique_id "amujYRGd_N1Op4Iu5U9bjAABLEY"]
[Thu Jul 30 14:17:54.094305 2026] [security2:error] [pid 1021791:tid 1021853] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/file1221.php"] [unique_id "amujYhGd_N1Op4Iu5U9bkwABND0"]
[Thu Jul 30 14:17:54.094509 2026] [security2:error] [pid 1021791:tid 1021963] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/file1221.php"] [unique_id "amujYhGd_N1Op4Iu5U9bkwABND0"]
[Thu Jul 30 14:17:54.237299 2026] [security2:error] [pid 1021791:tid 1021817] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/inx.php"] [unique_id "amujYhGd_N1Op4Iu5U9blQABRBk"]
[Thu Jul 30 14:17:54.237528 2026] [security2:error] [pid 1021791:tid 1021979] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/inx.php"] [unique_id "amujYhGd_N1Op4Iu5U9blQABRBk"]
[Thu Jul 30 14:17:54.382328 2026] [security2:error] [pid 1021791:tid 1021850] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/qqqa.php"] [unique_id "amujYhGd_N1Op4Iu5U9bpgABMzo"]
[Thu Jul 30 14:17:54.382504 2026] [security2:error] [pid 1021791:tid 1021962] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/qqqa.php"] [unique_id "amujYhGd_N1Op4Iu5U9bpgABMzo"]
[Thu Jul 30 14:17:54.614647 2026] [security2:error] [pid 1021791:tid 1021900] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/reviall.php"] [unique_id "amujYhGd_N1Op4Iu5U9bxgABhWw"]
[Thu Jul 30 14:17:54.614795 2026] [security2:error] [pid 1021791:tid 1022044] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/reviall.php"] [unique_id "amujYhGd_N1Op4Iu5U9bxgABhWw"]
[Thu Jul 30 14:17:54.681876 2026] [security2:error] [pid 1021791:tid 1021926] [client 20.100.187.246:24037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amujYhGd_N1Op4Iu5U9byAAAAQ8"]
[Thu Jul 30 14:17:54.755199 2026] [security2:error] [pid 1021791:tid 1021859] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/404.php"] [unique_id "amujYhGd_N1Op4Iu5U9bzAABZUM"]
[Thu Jul 30 14:17:54.755342 2026] [security2:error] [pid 1021791:tid 1022012] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/404.php"] [unique_id "amujYhGd_N1Op4Iu5U9bzAABZUM"]
[Thu Jul 30 14:17:54.890842 2026] [security2:error] [pid 1021791:tid 1021836] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/bolt.php"] [unique_id "amujYhGd_N1Op4Iu5U9bzgABKCw"]
[Thu Jul 30 14:17:54.891174 2026] [security2:error] [pid 1021791:tid 1021951] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/bolt.php"] [unique_id "amujYhGd_N1Op4Iu5U9bzgABKCw"]
[Thu Jul 30 14:17:55.025072 2026] [security2:error] [pid 1021791:tid 1021838] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/File.php"] [unique_id "amujYxGd_N1Op4Iu5U9b2gABTi4"]
[Thu Jul 30 14:17:55.025252 2026] [security2:error] [pid 1021791:tid 1021989] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/File.php"] [unique_id "amujYxGd_N1Op4Iu5U9b2gABTi4"]
[Thu Jul 30 14:17:55.180931 2026] [security2:error] [pid 1021791:tid 1021886] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/fi22.php"] [unique_id "amujYxGd_N1Op4Iu5U9b4QABNV4"]
[Thu Jul 30 14:17:55.181140 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/fi22.php"] [unique_id "amujYxGd_N1Op4Iu5U9b4QABNV4"]
[Thu Jul 30 14:17:55.330278 2026] [security2:error] [pid 1021791:tid 1021830] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/zero.php"] [unique_id "amujYxGd_N1Op4Iu5U9b5QABSiY"]
[Thu Jul 30 14:17:55.330455 2026] [security2:error] [pid 1021791:tid 1021985] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/zero.php"] [unique_id "amujYxGd_N1Op4Iu5U9b5QABSiY"]
[Thu Jul 30 14:17:55.383620 2026] [security2:error] [pid 1021791:tid 1021961] [client 152.32.208.73:58362] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "website-3f57df65.evk.gpl.temporary.site"] [uri "/wp-content/plugins/*\\",\\"/readme.txt"] [unique_id "amujYxGd_N1Op4Iu5U9b5gAAATI"]
[Thu Jul 30 14:17:55.406604 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.100.187.246:24019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/class.api.php"] [unique_id "amujYxGd_N1Op4Iu5U9b5wAAAT4"]
[Thu Jul 30 14:17:55.502574 2026] [security2:error] [pid 1021791:tid 1021904] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/1xmomo.php"] [unique_id "amujYxGd_N1Op4Iu5U9b7gABXHA"]
[Thu Jul 30 14:17:55.502768 2026] [security2:error] [pid 1021791:tid 1022003] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/1xmomo.php"] [unique_id "amujYxGd_N1Op4Iu5U9b7gABXHA"]
[Thu Jul 30 14:17:55.631728 2026] [security2:error] [pid 1021791:tid 1021877] [remote 57.141.0.13:25330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amujYxGd_N1Op4Iu5U9b8gABElU"]
[Thu Jul 30 14:17:55.650920 2026] [security2:error] [pid 1021791:tid 1021895] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/fmws.php"] [unique_id "amujYxGd_N1Op4Iu5U9b9AABLWc"]
[Thu Jul 30 14:17:55.651092 2026] [security2:error] [pid 1021791:tid 1021956] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/fmws.php"] [unique_id "amujYxGd_N1Op4Iu5U9b9AABLWc"]
[Thu Jul 30 14:17:55.805811 2026] [security2:error] [pid 1021791:tid 1021880] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amujYxGd_N1Op4Iu5U9b9gABd1g"]
[Thu Jul 30 14:17:55.806042 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amujYxGd_N1Op4Iu5U9b9gABd1g"]
[Thu Jul 30 14:17:55.911645 2026] [security2:error] [pid 1021791:tid 1021978] [client 74.7.230.45:50644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amujYxGd_N1Op4Iu5U9b9wABQ2o"]
[Thu Jul 30 14:17:55.951245 2026] [security2:error] [pid 1021791:tid 1021888] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/hp2.php"] [unique_id "amujYxGd_N1Op4Iu5U9b_gABQmA"]
[Thu Jul 30 14:17:55.951446 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/hp2.php"] [unique_id "amujYxGd_N1Op4Iu5U9b_gABQmA"]
[Thu Jul 30 14:17:56.083618 2026] [security2:error] [pid 1021791:tid 1021863] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/aabb.php"] [unique_id "amujZBGd_N1Op4Iu5U9cBQABFUc"]
[Thu Jul 30 14:17:56.083856 2026] [security2:error] [pid 1021791:tid 1021932] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/aabb.php"] [unique_id "amujZBGd_N1Op4Iu5U9cBQABFUc"]
[Thu Jul 30 14:17:56.246312 2026] [security2:error] [pid 1021791:tid 1021870] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/1254xx.php"] [unique_id "amujZBGd_N1Op4Iu5U9cCQABDk4"]
[Thu Jul 30 14:17:56.246488 2026] [security2:error] [pid 1021791:tid 1021925] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/1254xx.php"] [unique_id "amujZBGd_N1Op4Iu5U9cCQABDk4"]
[Thu Jul 30 14:17:56.392543 2026] [security2:error] [pid 1021791:tid 1021899] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amujZBGd_N1Op4Iu5U9cCwABiWs"]
[Thu Jul 30 14:17:56.392721 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amujZBGd_N1Op4Iu5U9cCwABiWs"]
[Thu Jul 30 14:17:56.523047 2026] [security2:error] [pid 1021791:tid 1021926] [client 152.32.208.73:58374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-3f57df65.evk.gpl.temporary.site"] [uri "/index.php"] [unique_id "amujZBGd_N1Op4Iu5U9cEwAAAQ8"]
[Thu Jul 30 14:17:56.551241 2026] [security2:error] [pid 1021791:tid 1021869] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/pms297.php"] [unique_id "amujZBGd_N1Op4Iu5U9cFwABfk0"]
[Thu Jul 30 14:17:56.551400 2026] [security2:error] [pid 1021791:tid 1022037] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/pms297.php"] [unique_id "amujZBGd_N1Op4Iu5U9cFwABfk0"]
[Thu Jul 30 14:17:56.557887 2026] [security2:error] [pid 1021791:tid 1021969] [client 20.100.187.246:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/cong.php"] [unique_id "amujZBGd_N1Op4Iu5U9cGAAAATo"]
[Thu Jul 30 14:17:56.687534 2026] [security2:error] [pid 1021791:tid 1021915] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amujZBGd_N1Op4Iu5U9cHAABb3s"]
[Thu Jul 30 14:17:56.687722 2026] [security2:error] [pid 1021791:tid 1022022] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amujZBGd_N1Op4Iu5U9cHAABb3s"]
[Thu Jul 30 14:17:56.836318 2026] [security2:error] [pid 1021791:tid 1021897] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amujZBGd_N1Op4Iu5U9cIQABV2k"]
[Thu Jul 30 14:17:56.836526 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amujZBGd_N1Op4Iu5U9cIQABV2k"]
[Thu Jul 30 14:17:56.972026 2026] [security2:error] [pid 1021791:tid 1021884] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amujZBGd_N1Op4Iu5U9cIwABJlw"]
[Thu Jul 30 14:17:56.972181 2026] [security2:error] [pid 1021791:tid 1021949] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amujZBGd_N1Op4Iu5U9cIwABJlw"]
[Thu Jul 30 14:17:57.107166 2026] [security2:error] [pid 1021791:tid 1021873] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amujZRGd_N1Op4Iu5U9cKQABaVE"]
[Thu Jul 30 14:17:57.107336 2026] [security2:error] [pid 1021791:tid 1022016] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amujZRGd_N1Op4Iu5U9cKQABaVE"]
[Thu Jul 30 14:17:57.257285 2026] [security2:error] [pid 1021791:tid 1021903] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/dyui.php"] [unique_id "amujZRGd_N1Op4Iu5U9cLwABLW8"]
[Thu Jul 30 14:17:57.257485 2026] [security2:error] [pid 1021791:tid 1021956] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/dyui.php"] [unique_id "amujZRGd_N1Op4Iu5U9cLwABLW8"]
[Thu Jul 30 14:17:57.295429 2026] [security2:error] [pid 1021791:tid 1022036] [client 180.243.59.178:49688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujZRGd_N1Op4Iu5U9cMAAAAX0"]
[Thu Jul 30 14:17:57.295555 2026] [security2:error] [pid 1021791:tid 1022036] [client 180.243.59.178:49688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujZRGd_N1Op4Iu5U9cMAAAAX0"]
[Thu Jul 30 14:17:57.402723 2026] [security2:error] [pid 1021791:tid 1021894] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/ho.php"] [unique_id "amujZRGd_N1Op4Iu5U9cMgABQWY"]
[Thu Jul 30 14:17:57.402891 2026] [security2:error] [pid 1021791:tid 1021976] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/ho.php"] [unique_id "amujZRGd_N1Op4Iu5U9cMgABQWY"]
[Thu Jul 30 14:17:57.552880 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.100.187.246:28253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/content.php"] [unique_id "amujZRGd_N1Op4Iu5U9cOQAAAWY"]
[Thu Jul 30 14:17:57.566575 2026] [security2:error] [pid 1021791:tid 1021902] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/66b867516c8f01.php"] [unique_id "amujZRGd_N1Op4Iu5U9cOgABUG4"]
[Thu Jul 30 14:17:57.566715 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/66b867516c8f01.php"] [unique_id "amujZRGd_N1Op4Iu5U9cOgABUG4"]
[Thu Jul 30 14:17:57.682140 2026] [core:notice] [pid 1021791:tid 1021924] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:17:57.686535 2026] [security2:error] [pid 1021791:tid 1021924] [client 135.181.74.155:45666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/divorcing-your-best-friend-is-one-of-the-most-difficult-things-you-ll-go-through.html"] [unique_id "amujZRGd_N1Op4Iu5U9cPwAAAQ0"]
[Thu Jul 30 14:17:57.702170 2026] [security2:error] [pid 1021791:tid 1021864] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/ext.php"] [unique_id "amujZRGd_N1Op4Iu5U9cQQABGUg"]
[Thu Jul 30 14:17:57.702351 2026] [security2:error] [pid 1021791:tid 1021936] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/ext.php"] [unique_id "amujZRGd_N1Op4Iu5U9cQQABGUg"]
[Thu Jul 30 14:17:57.835193 2026] [security2:error] [pid 1021791:tid 1021831] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amujZRGd_N1Op4Iu5U9cRQABUSc"]
[Thu Jul 30 14:17:57.835375 2026] [security2:error] [pid 1021791:tid 1021992] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amujZRGd_N1Op4Iu5U9cRQABUSc"]
[Thu Jul 30 14:17:57.985847 2026] [security2:error] [pid 1021791:tid 1021916] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amujZRGd_N1Op4Iu5U9cSAABO3w"]
[Thu Jul 30 14:17:57.986019 2026] [security2:error] [pid 1021791:tid 1021970] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amujZRGd_N1Op4Iu5U9cSAABO3w"]
[Thu Jul 30 14:17:58.127477 2026] [security2:error] [pid 1021791:tid 1021917] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amujZhGd_N1Op4Iu5U9cTgABiX0"]
[Thu Jul 30 14:17:58.127697 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/584062352875874akp.php"] [unique_id "amujZhGd_N1Op4Iu5U9cTgABiX0"]
[Thu Jul 30 14:17:58.260741 2026] [security2:error] [pid 1021791:tid 1021801] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/diidi.php"] [unique_id "amujZhGd_N1Op4Iu5U9cVgABVgk"]
[Thu Jul 30 14:17:58.260925 2026] [security2:error] [pid 1021791:tid 1021997] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/diidi.php"] [unique_id "amujZhGd_N1Op4Iu5U9cVgABVgk"]
[Thu Jul 30 14:17:58.393139 2026] [security2:error] [pid 1021791:tid 1021807] [remote 20.203.133.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.133.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allmontecristi.com"] [uri "/clarebypas.php"] [unique_id "amujZhGd_N1Op4Iu5U9cVwABWQ8"]
[Thu Jul 30 14:17:58.393341 2026] [security2:error] [pid 1021791:tid 1022000] [client 20.203.133.142:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.allmontecristi.com"] [uri "/clarebypas.php"] [unique_id "amujZhGd_N1Op4Iu5U9cVwABWQ8"]
[Thu Jul 30 14:17:58.449355 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.100.187.246:25903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amujZhGd_N1Op4Iu5U9cWAAAAVM"]
[Thu Jul 30 14:17:58.462096 2026] [security2:error] [pid 1021791:tid 1021922] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujZRGd_N1Op4Iu5U9cRgABC2M"]
[Thu Jul 30 14:17:59.323821 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.100.187.246:28269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/elp.php"] [unique_id "amujZxGd_N1Op4Iu5U9cbAAAARM"]
[Thu Jul 30 14:18:00.530100 2026] [security2:error] [pid 1021791:tid 1022024] [client 20.100.187.246:26603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amujaBGd_N1Op4Iu5U9chQAAAXE"]
[Thu Jul 30 14:18:00.964280 2026] [security2:error] [pid 1021791:tid 1022002] [client 172.237.109.114:8390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/l.fcgi"] [unique_id "amujaBGd_N1Op4Iu5U9ckgAAAVs"]
[Thu Jul 30 14:18:01.845703 2026] [security2:error] [pid 1021791:tid 1022027] [client 20.100.187.246:26604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amujaRGd_N1Op4Iu5U9cqgAAAXQ"]
[Thu Jul 30 14:18:02.868807 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.100.187.246:26611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amujahGd_N1Op4Iu5U9cygAAAYg"]
[Thu Jul 30 14:18:03.869251 2026] [core:notice] [pid 1021791:tid 1021845] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:03.869631 2026] [security2:error] [pid 1021791:tid 1021960] [client 20.100.187.246:24036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amujaxGd_N1Op4Iu5U9c3gAAATE"]
[Thu Jul 30 14:18:04.489259 2026] [security2:error] [pid 1021791:tid 1022021] [client 74.248.33.8:50818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amujbBGd_N1Op4Iu5U9c7wAAAW4"]
[Thu Jul 30 14:18:04.576429 2026] [security2:error] [pid 1021791:tid 1022020] [client 172.237.109.114:11223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujaxGd_N1Op4Iu5U9c5AAAAW0"]
[Thu Jul 30 14:18:04.786473 2026] [proxy:error] [pid 1021791:tid 1021957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:04.786557 2026] [proxy_http:error] [pid 1021791:tid 1021957] [client 34.224.175.62:22971] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:04.787148 2026] [proxy:error] [pid 1021791:tid 1021957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:04.787193 2026] [proxy_http:error] [pid 1021791:tid 1021957] [client 34.224.175.62:22971] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:04.819467 2026] [proxy:error] [pid 1021791:tid 1021972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:04.819582 2026] [proxy_http:error] [pid 1021791:tid 1021972] [client 32.194.121.99:20743] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:04.820385 2026] [proxy:error] [pid 1021791:tid 1021972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:04.820439 2026] [proxy_http:error] [pid 1021791:tid 1021972] [client 32.194.121.99:20743] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:04.884430 2026] [core:notice] [pid 1021791:tid 1021918] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:05.521651 2026] [security2:error] [pid 1021791:tid 1021997] [client 74.248.33.8:49078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/m.php"] [unique_id "amujbRGd_N1Op4Iu5U9dDwAAAVY"]
[Thu Jul 30 14:18:05.834024 2026] [security2:error] [pid 1021791:tid 1021852] [remote 57.141.0.39:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6151894337/feed/rss2/"] [unique_id "amujbRGd_N1Op4Iu5U9dGwABJzw"]
[Thu Jul 30 14:18:06.819498 2026] [security2:error] [pid 1021791:tid 1021937] [client 74.248.33.8:52049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amujbhGd_N1Op4Iu5U9dMAAAARo"]
[Thu Jul 30 14:18:06.883436 2026] [fcgid:warn] [pid 1021791:tid 1021948] (70014)End of file found: [client 118.193.35.202:58866] mod_fcgid: can't get data from http client
[Thu Jul 30 14:18:07.155063 2026] [proxy:error] [pid 1021791:tid 1021945] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:07.155168 2026] [proxy_http:error] [pid 1021791:tid 1021945] [client 52.4.19.39:7950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:07.155763 2026] [proxy:error] [pid 1021791:tid 1021945] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:07.155808 2026] [proxy_http:error] [pid 1021791:tid 1021945] [client 52.4.19.39:7950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:07.191888 2026] [proxy:error] [pid 1021791:tid 1022024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:07.191959 2026] [proxy_http:error] [pid 1021791:tid 1022024] [client 3.225.222.228:65371] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:07.192581 2026] [proxy:error] [pid 1021791:tid 1022024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:07.192641 2026] [proxy_http:error] [pid 1021791:tid 1022024] [client 3.225.222.228:65371] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:07.454073 2026] [security2:error] [pid 1021791:tid 1021972] [client 172.237.109.114:30143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujbhGd_N1Op4Iu5U9dNQAAAT0"]
[Thu Jul 30 14:18:07.622657 2026] [security2:error] [pid 1021791:tid 1022047] [client 180.243.59.178:50173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujbxGd_N1Op4Iu5U9dUAAAAYg"]
[Thu Jul 30 14:18:07.622772 2026] [security2:error] [pid 1021791:tid 1022047] [client 180.243.59.178:50173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujbxGd_N1Op4Iu5U9dUAAAAYg"]
[Thu Jul 30 14:18:07.733827 2026] [core:notice] [pid 1021791:tid 1021997] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:07.738066 2026] [security2:error] [pid 1021791:tid 1021997] [client 135.181.74.155:53316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/el-sub/18-tragic-signs-you-aren-t-satisfying-your-partner-sexually.html"] [unique_id "amujbxGd_N1Op4Iu5U9dVgAAAVY"]
[Thu Jul 30 14:18:08.499344 2026] [security2:error] [pid 1021791:tid 1021930] [client 172.237.109.114:58297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujbxGd_N1Op4Iu5U9dVwAAARM"]
[Thu Jul 30 14:18:08.963569 2026] [security2:error] [pid 1021791:tid 1022004] [client 118.194.249.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.tfy.udi.temporary.site"] [uri "/index.php"] [unique_id "amujcBGd_N1Op4Iu5U9dcwAAAV0"]
[Thu Jul 30 14:18:10.175142 2026] [core:notice] [pid 1021791:tid 1021874] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:10.943375 2026] [security2:error] [pid 1021791:tid 1021929] [client 85.208.96.208:56684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/16/miguel-falabella-recebe-1a-dose-da-vacina-contra-covid-19/"] [unique_id "amujchGd_N1Op4Iu5U9dqQAAARI"]
[Thu Jul 30 14:18:10.943498 2026] [security2:error] [pid 1021791:tid 1021929] [client 85.208.96.208:56684] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/16/miguel-falabella-recebe-1a-dose-da-vacina-contra-covid-19/"] [unique_id "amujchGd_N1Op4Iu5U9dqQAAARI"]
[Thu Jul 30 14:18:11.193643 2026] [security2:error] [pid 1021791:tid 1021950] [client 74.248.33.8:48140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wk/index.php"] [unique_id "amujcxGd_N1Op4Iu5U9dqgAAASc"]
[Thu Jul 30 14:18:12.289360 2026] [security2:error] [pid 1021791:tid 1021915] [remote 57.141.0.56:28386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/1801"] [unique_id "amujdBGd_N1Op4Iu5U9dxQABH3s"]
[Thu Jul 30 14:18:12.389508 2026] [core:notice] [pid 1021791:tid 1022014] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:12.393476 2026] [security2:error] [pid 1021791:tid 1022014] [client 135.181.74.155:53316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/el-sub/7-hard-truths-about-why-you-re-failing-at-life.html"] [unique_id "amujdBGd_N1Op4Iu5U9dzAAAAWc"]
[Thu Jul 30 14:18:12.650791 2026] [security2:error] [pid 1021791:tid 1021959] [client 74.248.33.8:52046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/mini.php"] [unique_id "amujdBGd_N1Op4Iu5U9d0wAAATA"]
[Thu Jul 30 14:18:12.662083 2026] [security2:error] [pid 1021791:tid 1021827] [remote 68.183.43.38:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.43.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/wp-includes/wp-login.php"] [unique_id "amujdBGd_N1Op4Iu5U9d1AABTCM"]
[Thu Jul 30 14:18:13.253626 2026] [security2:error] [pid 1021791:tid 1022021] [client 47.128.57.106:31686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amujdRGd_N1Op4Iu5U9d4gAAAW4"]
[Thu Jul 30 14:18:13.718738 2026] [security2:error] [pid 1021791:tid 1022045] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujdRGd_N1Op4Iu5U9d4QABhnc"]
[Thu Jul 30 14:18:13.794623 2026] [security2:error] [pid 1021791:tid 1021950] [client 74.248.33.8:51326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/aa.php"] [unique_id "amujdRGd_N1Op4Iu5U9d7QAAASc"]
[Thu Jul 30 14:18:15.284664 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.100.187.246:17136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amujdxGd_N1Op4Iu5U9eCQAAAVM"]
[Thu Jul 30 14:18:15.804364 2026] [security2:error] [pid 1021791:tid 1021826] [remote 74.7.227.39:44244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amujdxGd_N1Op4Iu5U9eFgABGyI"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:18:16.060832 2026] [security2:error] [pid 1021791:tid 1021975] [client 20.100.187.246:25883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amujeBGd_N1Op4Iu5U9eHwAAAUA"]
[Thu Jul 30 14:18:16.102544 2026] [core:notice] [pid 1021791:tid 1021813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:16.107079 2026] [security2:error] [pid 1021791:tid 1021953] [client 47.128.96.150:19858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/679"] [unique_id "amujdxGd_N1Op4Iu5U9eFwABKhU"]
[Thu Jul 30 14:18:16.349416 2026] [core:notice] [pid 1021791:tid 1021921] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:16.352914 2026] [security2:error] [pid 1021791:tid 1021921] [client 135.181.74.155:53316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/fr-sub/articles/3.html"] [unique_id "amujeBGd_N1Op4Iu5U9eJgAAAQo"]
[Thu Jul 30 14:18:16.396698 2026] [core:notice] [pid 1021791:tid 1021887] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:16.529530 2026] [core:notice] [pid 1021791:tid 1021793] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:16.529530 2026] [core:notice] [pid 1021791:tid 1021919] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:16.591601 2026] [security2:error] [pid 1021791:tid 1021996] [client 20.100.187.246:25863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amujeBGd_N1Op4Iu5U9eLwAAAVU"]
[Thu Jul 30 14:18:17.565265 2026] [security2:error] [pid 1021791:tid 1021932] [client 172.237.109.114:19608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujeRGd_N1Op4Iu5U9eOQAAARU"]
[Thu Jul 30 14:18:17.692176 2026] [security2:error] [pid 1021791:tid 1021796] [remote 216.73.217.142:19298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujeRGd_N1Op4Iu5U9eSQABgwQ"]
[Thu Jul 30 14:18:17.927387 2026] [security2:error] [pid 1021791:tid 1022017] [client 20.100.187.246:24013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amujeRGd_N1Op4Iu5U9eTQAAAWo"]
[Thu Jul 30 14:18:17.948486 2026] [security2:error] [pid 1021791:tid 1021809] [remote 74.7.243.224:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amujeRGd_N1Op4Iu5U9eUAABYxE"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:18:18.045234 2026] [security2:error] [pid 1021791:tid 1021999] [client 74.248.33.8:52067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/w.php"] [unique_id "amujehGd_N1Op4Iu5U9eVQAAAVg"]
[Thu Jul 30 14:18:18.395116 2026] [security2:error] [pid 1021791:tid 1021924] [client 180.243.59.178:50681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujehGd_N1Op4Iu5U9eXAAAAQ0"]
[Thu Jul 30 14:18:18.395304 2026] [security2:error] [pid 1021791:tid 1021924] [client 180.243.59.178:50681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujehGd_N1Op4Iu5U9eXAAAAQ0"]
[Thu Jul 30 14:18:19.987536 2026] [security2:error] [pid 1021791:tid 1021926] [client 162.141.167.72:58860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amujexGd_N1Op4Iu5U9efAAAAQ8"]
[Thu Jul 30 14:18:20.545363 2026] [security2:error] [pid 1021791:tid 1021958] [client 162.141.167.72:45590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mty.djb.temporary.site"] [uri "/backend/.env"] [unique_id "amujfBGd_N1Op4Iu5U9ekAAAAS8"]
[Thu Jul 30 14:18:20.552758 2026] [security2:error] [pid 1021791:tid 1021938] [client 162.141.167.72:45604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mty.djb.temporary.site"] [uri "/api/.env"] [unique_id "amujfBGd_N1Op4Iu5U9elwAAARs"]
[Thu Jul 30 14:18:20.742567 2026] [security2:error] [pid 1021791:tid 1022026] [client 162.141.167.72:45590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mty.djb.temporary.site"] [uri "/.env"] [unique_id "amujfBGd_N1Op4Iu5U9enQAAAXM"]
[Thu Jul 30 14:18:20.810566 2026] [security2:error] [pid 1021791:tid 1021959] [client 162.141.167.72:45624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amujfBGd_N1Op4Iu5U9elQAAATA"]
[Thu Jul 30 14:18:20.818790 2026] [security2:error] [pid 1021791:tid 1021987] [client 162.141.167.72:45582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amujfBGd_N1Op4Iu5U9ekQAAAUw"]
[Thu Jul 30 14:18:21.189917 2026] [core:notice] [pid 1021791:tid 1021992] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:21.194739 2026] [security2:error] [pid 1021791:tid 1021992] [client 135.181.74.155:53316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/fr-sub/i-can-t-keep-pretending-i-m-okay.html"] [unique_id "amujfRGd_N1Op4Iu5U9evwAAAVE"]
[Thu Jul 30 14:18:21.252012 2026] [security2:error] [pid 1021791:tid 1021940] [client 162.141.167.72:45630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amujfBGd_N1Op4Iu5U9elAAAAR0"]
[Thu Jul 30 14:18:21.254716 2026] [security2:error] [pid 1021791:tid 1022019] [client 162.141.167.72:45614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amujfBGd_N1Op4Iu5U9emAAAAWw"]
[Thu Jul 30 14:18:21.254747 2026] [security2:error] [pid 1021791:tid 1021976] [client 162.141.167.72:45562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amujfBGd_N1Op4Iu5U9ekwAAAUE"]
[Thu Jul 30 14:18:21.302986 2026] [security2:error] [pid 1021791:tid 1021961] [client 162.141.167.72:45556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amujfBGd_N1Op4Iu5U9ekgAAATI"]
[Thu Jul 30 14:18:21.304694 2026] [security2:error] [pid 1021791:tid 1022013] [client 162.141.167.72:45566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amujfBGd_N1Op4Iu5U9elgAAAWY"]
[Thu Jul 30 14:18:21.305892 2026] [security2:error] [pid 1021791:tid 1022017] [client 162.141.167.72:45526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amujfBGd_N1Op4Iu5U9emQAAAWo"]
[Thu Jul 30 14:18:21.362612 2026] [security2:error] [pid 1021791:tid 1021993] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amujfRGd_N1Op4Iu5U9evQAAAVI"]
[Thu Jul 30 14:18:22.403246 2026] [security2:error] [pid 1021791:tid 1021973] [client 74.248.33.8:51279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/admin.php"] [unique_id "amujfhGd_N1Op4Iu5U9e1wAAAT4"]
[Thu Jul 30 14:18:22.487405 2026] [security2:error] [pid 1021791:tid 1021963] [client 172.237.109.114:2157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujfRGd_N1Op4Iu5U9ezQAAATQ"]
[Thu Jul 30 14:18:22.693721 2026] [security2:error] [pid 1021791:tid 1021865] [remote 216.73.217.142:19298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amujfhGd_N1Op4Iu5U9e4QABgUk"]
[Thu Jul 30 14:18:23.634531 2026] [security2:error] [pid 1021791:tid 1022024] [client 20.100.187.246:17105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amujfxGd_N1Op4Iu5U9e8AAAAXE"]
[Thu Jul 30 14:18:24.448254 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.100.187.246:17142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amujgBGd_N1Op4Iu5U9fAwAAAUI"]
[Thu Jul 30 14:18:25.052179 2026] [core:notice] [pid 1021791:tid 1022005] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:25.057428 2026] [security2:error] [pid 1021791:tid 1022005] [client 135.181.74.155:53316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/fr-sub/i-ve-spent-over-1700-at-sephora-this-year.html"] [unique_id "amujgRGd_N1Op4Iu5U9fEQAAAV4"]
[Thu Jul 30 14:18:25.193783 2026] [security2:error] [pid 1021791:tid 1021952] [client 82.102.27.195:37432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amujgRGd_N1Op4Iu5U9fEwAAASk"]
[Thu Jul 30 14:18:25.193887 2026] [security2:error] [pid 1021791:tid 1021952] [client 82.102.27.195:37432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amujgRGd_N1Op4Iu5U9fEwAAASk"]
[Thu Jul 30 14:18:25.599344 2026] [security2:error] [pid 1021791:tid 1022015] [client 74.7.244.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.iwic.tw"] [uri "/index.php"] [unique_id "amujgBGd_N1Op4Iu5U9e-QABaFQ"]
[Thu Jul 30 14:18:25.599378 2026] [security2:error] [pid 1021791:tid 1022015] [client 74.7.244.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iwic.tw"] [uri "/index.php"] [unique_id "amujgBGd_N1Op4Iu5U9e-QABaFQ"]
[Thu Jul 30 14:18:26.041995 2026] [core:notice] [pid 1021791:tid 1021879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:26.732162 2026] [security2:error] [pid 1021791:tid 1021967] [client 20.100.187.246:24008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amujghGd_N1Op4Iu5U9fMwAAATg"]
[Thu Jul 30 14:18:27.372251 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.100.187.246:25862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amujgxGd_N1Op4Iu5U9fRQAAATA"]
[Thu Jul 30 14:18:27.568379 2026] [security2:error] [pid 1021791:tid 1021979] [client 172.237.109.114:32735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujgxGd_N1Op4Iu5U9fPgAAAUQ"]
[Thu Jul 30 14:18:27.980469 2026] [core:notice] [pid 1021791:tid 1021878] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:28.394673 2026] [security2:error] [pid 1021791:tid 1021964] [client 180.243.59.178:51155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujhBGd_N1Op4Iu5U9fYwAAATU"]
[Thu Jul 30 14:18:28.394819 2026] [security2:error] [pid 1021791:tid 1021964] [client 180.243.59.178:51155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujhBGd_N1Op4Iu5U9fYwAAATU"]
[Thu Jul 30 14:18:28.523658 2026] [security2:error] [pid 1021791:tid 1021965] [client 20.215.191.139:19018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/--wp-lgj.php"] [unique_id "amujhBGd_N1Op4Iu5U9fZwAAATY"]
[Thu Jul 30 14:18:28.683028 2026] [security2:error] [pid 1021791:tid 1022041] [client 20.100.187.246:17097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amujhBGd_N1Op4Iu5U9faQAAAYI"]
[Thu Jul 30 14:18:28.706300 2026] [security2:error] [pid 1021791:tid 1021867] [remote 216.73.217.142:58460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujhBGd_N1Op4Iu5U9fagABMUs"]
[Thu Jul 30 14:18:28.756327 2026] [security2:error] [pid 1021791:tid 1022004] [client 74.248.33.8:52075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/404.php"] [unique_id "amujhBGd_N1Op4Iu5U9fawAAAV0"]
[Thu Jul 30 14:18:28.811620 2026] [fcgid:warn] [pid 1021791:tid 1021973] (70014)End of file found: [client 152.32.176.68:37524] mod_fcgid: can't get data from http client
[Thu Jul 30 14:18:28.815763 2026] [autoindex:error] [pid 1021791:tid 1022027] [client 4.240.96.129:63308] AH01276: Cannot serve directory /home1/pvldjbte/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 14:18:29.620479 2026] [proxy:error] [pid 1021791:tid 1021974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:29.620561 2026] [proxy_http:error] [pid 1021791:tid 1021974] [client 152.32.176.68:37534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:29.621340 2026] [proxy:error] [pid 1021791:tid 1021974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:29.621389 2026] [proxy_http:error] [pid 1021791:tid 1021974] [client 152.32.176.68:37534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:29.627432 2026] [security2:error] [pid 1021791:tid 1021922] [client 172.237.109.114:31848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujhRGd_N1Op4Iu5U9fdwAAAQs"]
[Thu Jul 30 14:18:29.714723 2026] [security2:error] [pid 1021791:tid 1021957] [client 74.248.33.8:48185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/init.php"] [unique_id "amujhRGd_N1Op4Iu5U9fgwAAAS4"]
[Thu Jul 30 14:18:30.250101 2026] [proxy:error] [pid 1021791:tid 1021961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:30.250208 2026] [proxy_http:error] [pid 1021791:tid 1021961] [client 152.32.176.68:37544] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:30.251059 2026] [proxy:error] [pid 1021791:tid 1021961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:30.251116 2026] [proxy_http:error] [pid 1021791:tid 1021961] [client 152.32.176.68:37544] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:30.689855 2026] [security2:error] [pid 1021791:tid 1021945] [client 20.100.187.246:26634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amujhhGd_N1Op4Iu5U9fnAAAASI"]
[Thu Jul 30 14:18:31.164920 2026] [core:notice] [pid 1021791:tid 1022047] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:31.168448 2026] [security2:error] [pid 1021791:tid 1022047] [client 135.181.74.155:43462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/fr-sub/sponsorise.html"] [unique_id "amujhxGd_N1Op4Iu5U9fpgAAAYg"]
[Thu Jul 30 14:18:31.351745 2026] [security2:error] [pid 1021791:tid 1021944] [client 20.100.187.246:28182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amujhxGd_N1Op4Iu5U9fpwAAASE"]
[Thu Jul 30 14:18:31.670985 2026] [proxy:error] [pid 1021791:tid 1022035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:31.671075 2026] [proxy_http:error] [pid 1021791:tid 1022035] [client 152.32.176.68:37552] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:31.671647 2026] [proxy:error] [pid 1021791:tid 1022035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:31.671689 2026] [proxy_http:error] [pid 1021791:tid 1022035] [client 152.32.176.68:37552] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:32.039541 2026] [security2:error] [pid 1021791:tid 1021942] [client 52.167.144.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nafmedical.com"] [uri "/index.php"] [unique_id "amujhxGd_N1Op4Iu5U9fsgABH3k"]
[Thu Jul 30 14:18:32.237554 2026] [security2:error] [pid 1021791:tid 1021956] [client 20.100.187.246:28166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amujiBGd_N1Op4Iu5U9fvAAAAS0"]
[Thu Jul 30 14:18:32.276774 2026] [core:error] [pid 1021791:tid 1021826] [remote 216.73.216.194:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:18:32.276794 2026] [core:error] [pid 1021791:tid 1021826] [remote 216.73.216.194:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:18:32.716640 2026] [security2:error] [pid 1021791:tid 1021799] [remote 216.73.217.142:58460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujiBGd_N1Op4Iu5U9fyAABMgc"]
[Thu Jul 30 14:18:32.944674 2026] [core:error] [pid 1021791:tid 1021887] [remote 216.73.216.194:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:18:32.944694 2026] [core:error] [pid 1021791:tid 1021887] [remote 216.73.216.194:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:18:33.078008 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.100.187.246:26656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amujiRGd_N1Op4Iu5U9fzgAAAVc"]
[Thu Jul 30 14:18:33.196170 2026] [proxy:error] [pid 1021791:tid 1021930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:33.196239 2026] [proxy_http:error] [pid 1021791:tid 1021930] [client 152.32.176.68:37564] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:33.196820 2026] [proxy:error] [pid 1021791:tid 1021930] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:18:33.196871 2026] [proxy_http:error] [pid 1021791:tid 1021930] [client 152.32.176.68:37564] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:18:33.714738 2026] [security2:error] [pid 1021791:tid 1022042] [client 20.100.187.246:25609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amujiRGd_N1Op4Iu5U9f4wAAAYM"]
[Thu Jul 30 14:18:33.935472 2026] [security2:error] [pid 1021791:tid 1021954] [client 172.237.69.220:54007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.69.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-login.php"] [unique_id "amujiRGd_N1Op4Iu5U9f2QAAASs"], referer: https://www.facebook.com/
[Thu Jul 30 14:18:34.030211 2026] [security2:error] [pid 1021791:tid 1021926] [client 74.7.244.8:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-ee4ca56f.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amujiRGd_N1Op4Iu5U9f2AAAAQ8"]
[Thu Jul 30 14:18:34.031073 2026] [security2:error] [pid 1021791:tid 1022037] [client 74.7.244.8:36282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-ee4ca56f.dlr.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amujiRGd_N1Op4Iu5U9f1gABfhg"]
[Thu Jul 30 14:18:34.301306 2026] [security2:error] [pid 1021791:tid 1022026] [client 20.215.191.139:29604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amujihGd_N1Op4Iu5U9f8wAAAXM"]
[Thu Jul 30 14:18:34.545444 2026] [security2:error] [pid 1021791:tid 1021980] [client 172.237.109.114:10572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujiRGd_N1Op4Iu5U9f5gAAAUU"]
[Thu Jul 30 14:18:34.700966 2026] [security2:error] [pid 1021791:tid 1021942] [client 74.7.228.20:59272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop-kent.com"] [uri "/robots.txt"] [unique_id "amujihGd_N1Op4Iu5U9f-AABHyE"]
[Thu Jul 30 14:18:34.726675 2026] [security2:error] [pid 1021791:tid 1021934] [client 20.100.187.246:17088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amujihGd_N1Op4Iu5U9f_AAAARc"]
[Thu Jul 30 14:18:34.956163 2026] [core:notice] [pid 1021791:tid 1021806] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:35.164051 2026] [security2:error] [pid 1021791:tid 1022011] [client 20.215.191.139:37457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/LA.php"] [unique_id "amujixGd_N1Op4Iu5U9gCQAAAWQ"]
[Thu Jul 30 14:18:35.173310 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.215.191.139:26907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/flower.php"] [unique_id "amujixGd_N1Op4Iu5U9gDAAAAQs"]
[Thu Jul 30 14:18:35.269206 2026] [security2:error] [pid 1021791:tid 1021982] [client 172.237.69.220:54416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.69.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-login.php"] [unique_id "amujixGd_N1Op4Iu5U9gDwAAAUc"], referer: https://www.google.com/
[Thu Jul 30 14:18:35.487078 2026] [core:notice] [pid 1021791:tid 1021800] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:35.637802 2026] [security2:error] [pid 1021791:tid 1021981] [client 20.100.187.246:26681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amujixGd_N1Op4Iu5U9gGgAAAUY"]
[Thu Jul 30 14:18:35.932918 2026] [fcgid:warn] [pid 1021791:tid 1021941] (70014)End of file found: [client 66.132.186.200:26640] mod_fcgid: can't get data from http client
[Thu Jul 30 14:18:35.992709 2026] [security2:error] [pid 1021791:tid 1022001] [client 74.248.33.8:50051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/adminfuns.php"] [unique_id "amujixGd_N1Op4Iu5U9gLgAAAVo"]
[Thu Jul 30 14:18:36.250354 2026] [security2:error] [pid 1021791:tid 1021936] [client 146.190.17.120:44792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "montageluxuryhotel.com"] [uri "/index.php"] [unique_id "amujjBGd_N1Op4Iu5U9gLwAAARk"], referer: http://montageluxuryhotel.com/
[Thu Jul 30 14:18:36.267307 2026] [security2:error] [pid 1021791:tid 1022040] [client 20.215.191.139:37388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/admin.php"] [unique_id "amujjBGd_N1Op4Iu5U9gMwAAAYE"]
[Thu Jul 30 14:18:36.480378 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.100.187.246:17117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amujjBGd_N1Op4Iu5U9gOgAAAUw"]
[Thu Jul 30 14:18:36.837644 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.215.191.139:25050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/xleet.php"] [unique_id "amujjBGd_N1Op4Iu5U9gQwAAAYg"]
[Thu Jul 30 14:18:37.381533 2026] [security2:error] [pid 1021791:tid 1021817] [remote 57.141.0.54:48456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amujjRGd_N1Op4Iu5U9gTwABORk"]
[Thu Jul 30 14:18:37.945445 2026] [core:notice] [pid 1021791:tid 1021967] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:37.949606 2026] [security2:error] [pid 1021791:tid 1021967] [client 135.181.74.155:35206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/fr-sub/when-you-tell-a-broken-girl-she-s-beautiful.html"] [unique_id "amujjRGd_N1Op4Iu5U9gZAAAATg"]
[Thu Jul 30 14:18:38.650839 2026] [security2:error] [pid 1021791:tid 1021924] [client 172.237.109.114:15156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujjhGd_N1Op4Iu5U9gZwAAAQ0"]
[Thu Jul 30 14:18:38.710380 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.100.187.246:26631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amujjhGd_N1Op4Iu5U9geQAAAQs"]
[Thu Jul 30 14:18:38.727865 2026] [security2:error] [pid 1021791:tid 1022002] [client 20.215.191.139:37499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/class_api.php"] [unique_id "amujjhGd_N1Op4Iu5U9gegAAAVs"]
[Thu Jul 30 14:18:39.642000 2026] [security2:error] [pid 1021791:tid 1021947] [client 180.243.59.178:51675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujjxGd_N1Op4Iu5U9glQAAASQ"]
[Thu Jul 30 14:18:39.642130 2026] [security2:error] [pid 1021791:tid 1021947] [client 180.243.59.178:51675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujjxGd_N1Op4Iu5U9glQAAASQ"]
[Thu Jul 30 14:18:39.727886 2026] [security2:error] [pid 1021791:tid 1021949] [client 20.100.187.246:28191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amujjxGd_N1Op4Iu5U9glgAAASY"]
[Thu Jul 30 14:18:39.835301 2026] [security2:error] [pid 1021791:tid 1021962] [client 20.215.191.139:41353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amujjxGd_N1Op4Iu5U9glwAAATM"]
[Thu Jul 30 14:18:41.006298 2026] [security2:error] [pid 1021791:tid 1021951] [client 20.215.191.139:60682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/wp-login.php"] [unique_id "amujkBGd_N1Op4Iu5U9grQAAASg"]
[Thu Jul 30 14:18:41.076352 2026] [security2:error] [pid 1021791:tid 1022029] [client 20.100.187.246:26654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amujkRGd_N1Op4Iu5U9gtQAAAXY"]
[Thu Jul 30 14:18:41.638245 2026] [security2:error] [pid 1021791:tid 1022034] [client 20.215.191.139:38063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amujkRGd_N1Op4Iu5U9gxAAAAXs"]
[Thu Jul 30 14:18:41.823543 2026] [core:notice] [pid 1021791:tid 1021999] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:41.843576 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.100.187.246:17121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amujkRGd_N1Op4Iu5U9gxwAAAWc"]
[Thu Jul 30 14:18:42.152691 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.215.191.139:25069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amujkhGd_N1Op4Iu5U9g0AAAAWY"]
[Thu Jul 30 14:18:42.219995 2026] [security2:error] [pid 1021791:tid 1021932] [client 40.77.167.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amujkRGd_N1Op4Iu5U9gyAABFVQ"]
[Thu Jul 30 14:18:42.487603 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.215.191.139:38027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/991176.php"] [unique_id "amujkhGd_N1Op4Iu5U9g0wAAASU"]
[Thu Jul 30 14:18:42.721246 2026] [security2:error] [pid 1021791:tid 1021886] [remote 216.73.217.142:15140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amujkhGd_N1Op4Iu5U9g3QABhl4"]
[Thu Jul 30 14:18:43.498785 2026] [security2:error] [pid 1021791:tid 1021983] [client 20.215.191.139:26936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amujkxGd_N1Op4Iu5U9g6gAAAUg"]
[Thu Jul 30 14:18:43.505113 2026] [core:notice] [pid 1021791:tid 1021973] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:43.953274 2026] [security2:error] [pid 1021791:tid 1022043] [client 20.215.191.139:37464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amujkxGd_N1Op4Iu5U9g9QAAAYQ"]
[Thu Jul 30 14:18:43.986757 2026] [core:error] [pid 1021791:tid 1022036] [client 20.193.250.173:50945] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Thu Jul 30 14:18:43.986778 2026] [core:error] [pid 1021791:tid 1022036] [client 20.193.250.173:50945] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: binance.com
[Thu Jul 30 14:18:44.596731 2026] [security2:error] [pid 1021791:tid 1022024] [client 20.215.191.139:32821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amujlBGd_N1Op4Iu5U9hAwAAAXE"]
[Thu Jul 30 14:18:44.652295 2026] [security2:error] [pid 1021791:tid 1022018] [client 20.215.191.139:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amujlBGd_N1Op4Iu5U9hBwAAAWs"]
[Thu Jul 30 14:18:45.078330 2026] [security2:error] [pid 1021791:tid 1022003] [client 20.100.187.246:26649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amujlRGd_N1Op4Iu5U9hDwAAAVw"]
[Thu Jul 30 14:18:45.423362 2026] [security2:error] [pid 1021791:tid 1021987] [client 184.154.76.13:34358] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bisbeewalk.com"] [uri "/Bisbee_panoramas_from_off_the_wall.htm"] [unique_id "amujlRGd_N1Op4Iu5U9hGgAAAUw"]
[Thu Jul 30 14:18:45.482292 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.215.191.139:38025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amujlRGd_N1Op4Iu5U9hHAAAATA"]
[Thu Jul 30 14:18:46.015790 2026] [security2:error] [pid 1021791:tid 1021884] [remote 47.128.124.44:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "emmanueljrodriguez.com"] [uri "/robots.txt"] [unique_id "amujlhGd_N1Op4Iu5U9hJgABY1w"]
[Thu Jul 30 14:18:46.148747 2026] [security2:error] [pid 1021791:tid 1021921] [client 20.100.187.246:26684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amujlhGd_N1Op4Iu5U9hKQAAAQo"]
[Thu Jul 30 14:18:46.778159 2026] [security2:error] [pid 1021791:tid 1021931] [client 20.215.191.139:25487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amujlhGd_N1Op4Iu5U9hOAAAARQ"]
[Thu Jul 30 14:18:46.960932 2026] [fcgid:warn] [pid 1021791:tid 1022034] (70014)End of file found: [client 128.14.236.30:45748] mod_fcgid: can't get data from http client
[Thu Jul 30 14:18:46.966484 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.215.191.139:60686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amujlhGd_N1Op4Iu5U9hPQAAAYg"]
[Thu Jul 30 14:18:47.004124 2026] [core:notice] [pid 1021791:tid 1022023] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:47.009783 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.100.187.246:24200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amujlxGd_N1Op4Iu5U9hPwAAASA"]
[Thu Jul 30 14:18:47.010046 2026] [security2:error] [pid 1021791:tid 1022023] [client 135.181.74.155:59588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/fr-sub/why-my-dog-is-probably-jesus.html"] [unique_id "amujlxGd_N1Op4Iu5U9hPgAAAXA"]
[Thu Jul 30 14:18:48.038267 2026] [security2:error] [pid 1021791:tid 1021987] [client 20.215.191.139:25514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amujmBGd_N1Op4Iu5U9hWQAAAUw"]
[Thu Jul 30 14:18:48.306575 2026] [security2:error] [pid 1021791:tid 1021980] [client 20.100.187.246:28186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amujmBGd_N1Op4Iu5U9hYAAAAUU"]
[Thu Jul 30 14:18:48.667013 2026] [security2:error] [pid 1021791:tid 1021959] [client 74.248.33.8:49972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/file.php"] [unique_id "amujmBGd_N1Op4Iu5U9haAAAATA"]
[Thu Jul 30 14:18:48.991195 2026] [security2:error] [pid 1021791:tid 1022001] [client 20.215.191.139:60725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amujmBGd_N1Op4Iu5U9hdwAAAVo"]
[Thu Jul 30 14:18:49.319917 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.215.191.139:32721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amujmRGd_N1Op4Iu5U9hfAAAAWA"]
[Thu Jul 30 14:18:49.434567 2026] [security2:error] [pid 1021791:tid 1021994] [client 74.248.33.8:49947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/222.php"] [unique_id "amujmRGd_N1Op4Iu5U9hgQAAAVM"]
[Thu Jul 30 14:18:49.654480 2026] [security2:error] [pid 1021791:tid 1021964] [client 180.243.59.178:52144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujmRGd_N1Op4Iu5U9hiAAAATU"]
[Thu Jul 30 14:18:49.654613 2026] [security2:error] [pid 1021791:tid 1021964] [client 180.243.59.178:52144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujmRGd_N1Op4Iu5U9hiAAAATU"]
[Thu Jul 30 14:18:50.229463 2026] [security2:error] [pid 1021791:tid 1021934] [client 20.215.191.139:40761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amujmhGd_N1Op4Iu5U9hlAAAARc"]
[Thu Jul 30 14:18:50.294360 2026] [security2:error] [pid 1021791:tid 1021995] [client 74.248.33.8:50063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amujmhGd_N1Op4Iu5U9hlQAAAVQ"]
[Thu Jul 30 14:18:50.538818 2026] [security2:error] [pid 1021791:tid 1022011] [client 184.154.76.13:34362] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bisbeewalk.com"] [uri "/Bisbee_RodneyLeeSmith_thewalkingguide.htm"] [unique_id "amujmhGd_N1Op4Iu5U9hnAAAAWQ"]
[Thu Jul 30 14:18:50.548243 2026] [security2:error] [pid 1021791:tid 1021963] [client 20.215.191.139:25494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amujmhGd_N1Op4Iu5U9hnQAAATQ"]
[Thu Jul 30 14:18:50.792314 2026] [security2:error] [pid 1021791:tid 1021941] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujmhGd_N1Op4Iu5U9hkwABHgE"]
[Thu Jul 30 14:18:50.963102 2026] [security2:error] [pid 1021791:tid 1021808] [remote 57.141.0.7:34358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amujmhGd_N1Op4Iu5U9hpAABbBA"]
[Thu Jul 30 14:18:51.053507 2026] [autoindex:error] [pid 1021791:tid 1022044] [client 74.248.33.8:8894] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:18:51.194265 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.215.191.139:18017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amujmxGd_N1Op4Iu5U9hrQAAAQs"]
[Thu Jul 30 14:18:51.228202 2026] [autoindex:error] [pid 1021791:tid 1022041] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:18:51.315246 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.215.191.139:22756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.wp-cli/flower.php"] [unique_id "amujmxGd_N1Op4Iu5U9hsQAAAUI"]
[Thu Jul 30 14:18:51.457904 2026] [security2:error] [pid 1021791:tid 1022047] [client 74.248.33.8:8894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/admin.php"] [unique_id "amujmxGd_N1Op4Iu5U9huAAAAYg"]
[Thu Jul 30 14:18:51.595166 2026] [core:notice] [pid 1021791:tid 1021989] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:51.596519 2026] [security2:error] [pid 1021791:tid 1021989] [client 135.181.74.155:59594] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amujmxGd_N1Op4Iu5U9hvwAAAU4"]
[Thu Jul 30 14:18:51.758538 2026] [core:notice] [pid 1021791:tid 1022018] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:51.762490 2026] [security2:error] [pid 1021791:tid 1022018] [client 135.181.74.155:59588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/12-inspirational-quotes-that-made-me-a-better-person.html"] [unique_id "amujmxGd_N1Op4Iu5U9hwAAAAWs"]
[Thu Jul 30 14:18:52.074512 2026] [security2:error] [pid 1021791:tid 1021952] [client 20.100.187.246:28194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amujnBGd_N1Op4Iu5U9hzgAAASk"]
[Thu Jul 30 14:18:52.300362 2026] [security2:error] [pid 1021791:tid 1021998] [client 74.248.33.8:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-configs.php"] [unique_id "amujnBGd_N1Op4Iu5U9h0AAAAVc"]
[Thu Jul 30 14:18:52.430870 2026] [security2:error] [pid 1021791:tid 1021832] [remote 57.141.0.34:30786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amujnBGd_N1Op4Iu5U9h0wABMyg"]
[Thu Jul 30 14:18:52.568006 2026] [security2:error] [pid 1021791:tid 1022014] [client 20.215.191.139:40756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amujnBGd_N1Op4Iu5U9h2QAAAWc"]
[Thu Jul 30 14:18:52.661497 2026] [security2:error] [pid 1021791:tid 1021824] [remote 57.141.0.5:42810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amujnBGd_N1Op4Iu5U9h3AABgSA"]
[Thu Jul 30 14:18:52.719239 2026] [core:notice] [pid 1021791:tid 1022004] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:52.724993 2026] [security2:error] [pid 1021791:tid 1021828] [remote 216.73.217.142:9708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amujnBGd_N1Op4Iu5U9h3gABQSQ"]
[Thu Jul 30 14:18:52.757478 2026] [security2:error] [pid 1021791:tid 1021800] [remote 57.141.0.44:28242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amujnBGd_N1Op4Iu5U9h3wABGAg"]
[Thu Jul 30 14:18:53.226949 2026] [security2:error] [pid 1021791:tid 1021968] [client 74.7.243.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iwic.tw"] [uri "/index.php"] [unique_id "amujnRGd_N1Op4Iu5U9h5AABORQ"], referer: https://www.iwic.tw/about.html
[Thu Jul 30 14:18:53.396799 2026] [security2:error] [pid 1021791:tid 1022010] [client 20.100.187.246:24594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amujnRGd_N1Op4Iu5U9h6wAAAWM"]
[Thu Jul 30 14:18:53.445166 2026] [security2:error] [pid 1021791:tid 1022009] [client 74.248.33.8:8845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/php.php"] [unique_id "amujnRGd_N1Op4Iu5U9h7AAAAWI"]
[Thu Jul 30 14:18:53.888005 2026] [security2:error] [pid 1021791:tid 1021959] [client 20.215.191.139:38055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amujnRGd_N1Op4Iu5U9h9wAAATA"]
[Thu Jul 30 14:18:54.109032 2026] [security2:error] [pid 1021791:tid 1021943] [client 20.100.187.246:24004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amujnhGd_N1Op4Iu5U9h_gAAASA"]
[Thu Jul 30 14:18:54.405439 2026] [security2:error] [pid 1021791:tid 1022031] [client 20.215.191.139:18016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amujnhGd_N1Op4Iu5U9iAwAAAXg"]
[Thu Jul 30 14:18:54.464688 2026] [core:notice] [pid 1021791:tid 1022005] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:55.309500 2026] [security2:error] [pid 1021791:tid 1022039] [client 20.215.191.139:40748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amujnxGd_N1Op4Iu5U9iHwAAAYA"]
[Thu Jul 30 14:18:55.485860 2026] [security2:error] [pid 1021791:tid 1021941] [client 43.173.173.17:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/12/08/vente-exceptionnelle-naf-naf-paris-du-12-au-15-decembre-2012/"] [unique_id "amujnxGd_N1Op4Iu5U9iIAAAAR4"]
[Thu Jul 30 14:18:55.509821 2026] [security2:error] [pid 1021791:tid 1021961] [client 20.100.187.246:28193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amujnxGd_N1Op4Iu5U9iHgAAATI"]
[Thu Jul 30 14:18:55.819456 2026] [core:notice] [pid 1021791:tid 1021922] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:55.823688 2026] [security2:error] [pid 1021791:tid 1021922] [client 135.181.74.155:59588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/13-promises-to-my-dog.html"] [unique_id "amujnxGd_N1Op4Iu5U9iKwAAAQs"]
[Thu Jul 30 14:18:56.061454 2026] [security2:error] [pid 1021791:tid 1021930] [client 20.215.191.139:40733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amujoBGd_N1Op4Iu5U9iLgAAARM"]
[Thu Jul 30 14:18:56.217411 2026] [core:notice] [pid 1021791:tid 1022032] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:56.222949 2026] [security2:error] [pid 1021791:tid 1022032] [client 43.172.197.127:34094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/12/08/vente-exceptionnelle-naf-naf-paris-du-12-au-15-decembre-2012/"] [unique_id "amujoBGd_N1Op4Iu5U9iNgAAAXk"], referer: https://carnetdeshopping.com/index.php/2012/12/08/vente-exceptionnelle-naf-naf-paris-du-12-au-15-decembre-2012/
[Thu Jul 30 14:18:56.860605 2026] [autoindex:error] [pid 1021791:tid 1022026] [client 109.205.214.111:0] AH01276: Cannot serve directory /home2/mbmudite/ok.koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:18:56.931865 2026] [security2:error] [pid 1021791:tid 1021989] [client 20.215.191.139:55158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amujoBGd_N1Op4Iu5U9iSgAAAU4"]
[Thu Jul 30 14:18:57.544489 2026] [security2:error] [pid 1021791:tid 1021981] [client 66.249.73.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nco.zzt.temporary.site"] [uri "/index.php"] [unique_id "amujoBGd_N1Op4Iu5U9iTQAAAUY"]
[Thu Jul 30 14:18:57.626567 2026] [autoindex:error] [pid 1021791:tid 1022008] [client 109.205.214.111:0] AH01276: Cannot serve directory /home2/mbmudite/ok.koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ok.koidomino.click
[Thu Jul 30 14:18:58.247845 2026] [autoindex:error] [pid 1021791:tid 1021940] [client 109.205.214.111:0] AH01276: Cannot serve directory /home2/mbmudite/ok.koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:18:58.395932 2026] [security2:error] [pid 1021791:tid 1021830] [remote 216.73.217.142:16906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujohGd_N1Op4Iu5U9ieQABUCY"]
[Thu Jul 30 14:18:58.697914 2026] [security2:error] [pid 1021791:tid 1021949] [client 74.248.33.8:50494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/index.php"] [unique_id "amujohGd_N1Op4Iu5U9iewAAASY"]
[Thu Jul 30 14:18:58.825036 2026] [security2:error] [pid 1021791:tid 1022003] [client 109.205.214.111:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ok.koidomino.click"] [uri "/.env"] [unique_id "amujohGd_N1Op4Iu5U9iiAAAAVw"]
[Thu Jul 30 14:18:58.992524 2026] [security2:error] [pid 1021791:tid 1022037] [client 119.73.97.132:29313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amujohGd_N1Op4Iu5U9ihwABfko"], referer: https://www.urwru.club/wp-admin/edit.php?post_type=page
[Thu Jul 30 14:18:59.263003 2026] [core:notice] [pid 1021791:tid 1021971] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:59.267645 2026] [security2:error] [pid 1021791:tid 1021971] [client 135.181.74.155:59588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/16-dolphin-puns-that-will-make-you-flip-out.html"] [unique_id "amujoxGd_N1Op4Iu5U9ikAAAATw"]
[Thu Jul 30 14:18:59.282162 2026] [core:notice] [pid 1021791:tid 1022048] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:18:59.334019 2026] [security2:error] [pid 1021791:tid 1022032] [client 20.215.191.139:55139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/amaxx.php"] [unique_id "amujoxGd_N1Op4Iu5U9ilwAAAXk"]
[Thu Jul 30 14:19:00.148918 2026] [security2:error] [pid 1021791:tid 1022027] [client 74.248.33.8:18793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/a.php"] [unique_id "amujpBGd_N1Op4Iu5U9irQAAAXQ"]
[Thu Jul 30 14:19:00.252372 2026] [security2:error] [pid 1021791:tid 1021973] [client 20.215.191.139:35394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/bek.php"] [unique_id "amujpBGd_N1Op4Iu5U9isQAAAT4"]
[Thu Jul 30 14:19:00.468106 2026] [security2:error] [pid 1021791:tid 1021956] [client 180.243.59.178:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujpBGd_N1Op4Iu5U9iugAAAS0"]
[Thu Jul 30 14:19:00.468222 2026] [security2:error] [pid 1021791:tid 1021956] [client 180.243.59.178:52658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujpBGd_N1Op4Iu5U9iugAAAS0"]
[Thu Jul 30 14:19:00.828667 2026] [security2:error] [pid 1021791:tid 1022031] [client 109.205.214.111:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ok.koidomino.click"] [uri "/api/.env"] [unique_id "amujpBGd_N1Op4Iu5U9iwwAAAXg"]
[Thu Jul 30 14:19:00.948532 2026] [security2:error] [pid 1021791:tid 1022003] [client 109.205.214.111:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ok.koidomino.click"] [uri "/backend/.env"] [unique_id "amujpBGd_N1Op4Iu5U9izgAAAVw"]
[Thu Jul 30 14:19:01.136203 2026] [core:notice] [pid 1021791:tid 1021948] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:01.290278 2026] [security2:error] [pid 1021791:tid 1021996] [client 20.215.191.139:43343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amujpRGd_N1Op4Iu5U9i2wAAAVU"]
[Thu Jul 30 14:19:01.300549 2026] [core:notice] [pid 1021791:tid 1021962] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:01.850914 2026] [autoindex:error] [pid 1021791:tid 1022013] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:19:01.865290 2026] [core:notice] [pid 1021791:tid 1021941] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:02.030545 2026] [autoindex:error] [pid 1021791:tid 1022025] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:19:02.179776 2026] [security2:error] [pid 1021791:tid 1022007] [client 74.248.33.8:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amujphGd_N1Op4Iu5U9i_gAAAWA"]
[Thu Jul 30 14:19:02.265452 2026] [security2:error] [pid 1021791:tid 1022020] [client 20.215.191.139:43084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/class.api.php"] [unique_id "amujphGd_N1Op4Iu5U9i_wAAAW0"]
[Thu Jul 30 14:19:02.418443 2026] [core:notice] [pid 1021791:tid 1021953] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:02.961112 2026] [core:notice] [pid 1021791:tid 1022037] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:03.019578 2026] [security2:error] [pid 1021791:tid 1022019] [client 20.215.191.139:17514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/cong.php"] [unique_id "amujpxGd_N1Op4Iu5U9jFwAAAWw"]
[Thu Jul 30 14:19:03.090163 2026] [security2:error] [pid 1021791:tid 1022042] [client 119.73.97.132:29313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/wp-admin/post.php"] [unique_id "amujphGd_N1Op4Iu5U9jCgABgw8"], referer: https://www.urwru.club/wp-admin/edit.php?post_type=page
[Thu Jul 30 14:19:03.459596 2026] [core:notice] [pid 1021791:tid 1021929] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:03.703568 2026] [core:notice] [pid 1021791:tid 1022039] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:03.711714 2026] [security2:error] [pid 1021791:tid 1022039] [client 135.181.74.155:59588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/25-adults-on-their-childhood-horror-story-that-still-haunts-them-to-this-day.html"] [unique_id "amujpxGd_N1Op4Iu5U9jKAAAAYA"]
[Thu Jul 30 14:19:03.919211 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.215.191.139:31419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amujpxGd_N1Op4Iu5U9jMQAAARw"]
[Thu Jul 30 14:19:04.362731 2026] [security2:error] [pid 1021791:tid 1021978] [client 74.248.33.8:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin.php"] [unique_id "amujqBGd_N1Op4Iu5U9jPgAAAUM"]
[Thu Jul 30 14:19:04.640349 2026] [autoindex:error] [pid 1021791:tid 1022031] [client 172.232.212.237:57078] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:19:04.710177 2026] [security2:error] [pid 1021791:tid 1021997] [client 20.215.191.139:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/content.php"] [unique_id "amujqBGd_N1Op4Iu5U9jSgAAAVY"]
[Thu Jul 30 14:19:06.392102 2026] [security2:error] [pid 1021791:tid 1021872] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ea3f.php"] [unique_id "amujqhGd_N1Op4Iu5U9jcAABQlA"]
[Thu Jul 30 14:19:06.418141 2026] [security2:error] [pid 1021791:tid 1021938] [client 185.200.116.219:46442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amujqhGd_N1Op4Iu5U9jcQAAARs"]
[Thu Jul 30 14:19:06.418230 2026] [security2:error] [pid 1021791:tid 1021938] [client 185.200.116.219:46442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amujqhGd_N1Op4Iu5U9jcQAAARs"]
[Thu Jul 30 14:19:06.530249 2026] [security2:error] [pid 1021791:tid 1021991] [client 20.215.191.139:36817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amujqhGd_N1Op4Iu5U9jcgAAAVA"]
[Thu Jul 30 14:19:06.773239 2026] [security2:error] [pid 1021791:tid 1022047] [client 74.248.33.8:49825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/size.php"] [unique_id "amujqhGd_N1Op4Iu5U9jegAAAYg"]
[Thu Jul 30 14:19:07.129313 2026] [core:error] [pid 1021791:tid 1022042] [client 152.32.160.252:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:07.129337 2026] [core:error] [pid 1021791:tid 1022042] [client 152.32.160.252:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:07.203276 2026] [security2:error] [pid 1021791:tid 1021846] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/eagle.php"] [unique_id "amujqxGd_N1Op4Iu5U9jhwABXjY"]
[Thu Jul 30 14:19:07.278022 2026] [security2:error] [pid 1021791:tid 1021987] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujqhGd_N1Op4Iu5U9jdgABTAw"]
[Thu Jul 30 14:19:07.489611 2026] [security2:error] [pid 1021791:tid 1021865] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ed35f.php"] [unique_id "amujqxGd_N1Op4Iu5U9jkwABNUk"]
[Thu Jul 30 14:19:07.530610 2026] [security2:error] [pid 1021791:tid 1022026] [client 74.248.33.8:8679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amujqxGd_N1Op4Iu5U9jlAAAAXM"]
[Thu Jul 30 14:19:07.579771 2026] [core:notice] [pid 1021791:tid 1021944] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:07.585430 2026] [security2:error] [pid 1021791:tid 1021944] [client 135.181.74.155:59588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/30-red-flags-you-might-be-dating-a-narcissist.html"] [unique_id "amujqxGd_N1Op4Iu5U9jlQAAASE"]
[Thu Jul 30 14:19:07.768741 2026] [security2:error] [pid 1021791:tid 1021843] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/edit-comments.php"] [unique_id "amujqxGd_N1Op4Iu5U9jnwABWzM"]
[Thu Jul 30 14:19:07.877126 2026] [security2:error] [pid 1021791:tid 1022028] [client 20.215.191.139:36805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/elp.php"] [unique_id "amujqxGd_N1Op4Iu5U9joAAAAXU"]
[Thu Jul 30 14:19:08.054831 2026] [security2:error] [pid 1021791:tid 1021839] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/edit-form.php"] [unique_id "amujrBGd_N1Op4Iu5U9jpAABDi8"]
[Thu Jul 30 14:19:08.141560 2026] [security2:error] [pid 1021791:tid 1022007] [client 74.7.228.54:46244] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.buildmaster.pnimanpower.net"] [uri "/cgi-sys/404.html"] [unique_id "amujrBGd_N1Op4Iu5U9jpQABYCo"]
[Thu Jul 30 14:19:08.331340 2026] [security2:error] [pid 1021791:tid 1021871] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/edit-tags.php"] [unique_id "amujrBGd_N1Op4Iu5U9jrAABG08"]
[Thu Jul 30 14:19:08.616859 2026] [security2:error] [pid 1021791:tid 1021848] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/edit-wolf.php"] [unique_id "amujrBGd_N1Op4Iu5U9jsAABGTg"]
[Thu Jul 30 14:19:08.796185 2026] [security2:error] [pid 1021791:tid 1021960] [client 74.248.33.8:51585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/403.php"] [unique_id "amujrBGd_N1Op4Iu5U9jtQAAATE"]
[Thu Jul 30 14:19:08.865504 2026] [security2:error] [pid 1021791:tid 1021955] [client 20.215.191.139:61064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amujrBGd_N1Op4Iu5U9juQAAASw"]
[Thu Jul 30 14:19:08.880277 2026] [security2:error] [pid 1021791:tid 1022019] [client 195.154.59.122:43320] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amujrBGd_N1Op4Iu5U9jugAAAWw"]
[Thu Jul 30 14:19:08.888570 2026] [security2:error] [pid 1021791:tid 1021890] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/edit.php"] [unique_id "amujrBGd_N1Op4Iu5U9juwABUmI"]
[Thu Jul 30 14:19:08.927355 2026] [core:notice] [pid 1021791:tid 1021927] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:08.930304 2026] [autoindex:error] [pid 1021791:tid 1021844] [remote 74.7.242.56:41464] AH01276: Cannot serve directory /home2/zorudite/buildmaster.pnimanpower.net/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:19:09.020287 2026] [security2:error] [pid 1021791:tid 1021948] [client 195.154.59.122:45900] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amujrRGd_N1Op4Iu5U9jwgAAASU"]
[Thu Jul 30 14:19:09.190630 2026] [security2:error] [pid 1021791:tid 1021892] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/editor.php"] [unique_id "amujrRGd_N1Op4Iu5U9jwwABYmQ"]
[Thu Jul 30 14:19:09.462946 2026] [security2:error] [pid 1021791:tid 1021906] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/editor/filemanager.php"] [unique_id "amujrRGd_N1Op4Iu5U9jzwABMnI"]
[Thu Jul 30 14:19:09.463764 2026] [core:notice] [pid 1021791:tid 1021946] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:09.583247 2026] [security2:error] [pid 1021791:tid 1021939] [client 74.7.228.32:49748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "knpdongmin2215.com"] [uri "/robots.txt"] [unique_id "amujrRGd_N1Op4Iu5U9j0AAAARw"]
[Thu Jul 30 14:19:09.588894 2026] [security2:error] [pid 1021791:tid 1022023] [client 20.215.191.139:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amujrRGd_N1Op4Iu5U9j0QAAAXA"]
[Thu Jul 30 14:19:09.751121 2026] [security2:error] [pid 1021791:tid 1021838] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/editor/filemanager/updates.php"] [unique_id "amujrRGd_N1Op4Iu5U9j0wABPy4"]
[Thu Jul 30 14:19:10.035264 2026] [security2:error] [pid 1021791:tid 1021874] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ee.php"] [unique_id "amujrhGd_N1Op4Iu5U9j4QABb1I"]
[Thu Jul 30 14:19:10.319539 2026] [security2:error] [pid 1021791:tid 1021877] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/ee8.php"] [unique_id "amujrhGd_N1Op4Iu5U9j5wABLVU"]
[Thu Jul 30 14:19:10.406082 2026] [security2:error] [pid 1021791:tid 1022011] [client 74.248.33.8:50222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amujrhGd_N1Op4Iu5U9j6wAAAWQ"]
[Thu Jul 30 14:19:10.604466 2026] [security2:error] [pid 1021791:tid 1021904] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/eew.php"] [unique_id "amujrhGd_N1Op4Iu5U9j7wABPHA"]
[Thu Jul 30 14:19:10.748123 2026] [security2:error] [pid 1021791:tid 1021955] [client 20.215.191.139:61651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amujrhGd_N1Op4Iu5U9j8AAAASw"]
[Thu Jul 30 14:19:10.888341 2026] [security2:error] [pid 1021791:tid 1021863] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/el.php"] [unique_id "amujrhGd_N1Op4Iu5U9j9wABCkc"]
[Thu Jul 30 14:19:10.957649 2026] [core:notice] [pid 1021791:tid 1021997] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:11.172605 2026] [security2:error] [pid 1021791:tid 1021860] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/elementor/wp-error_log.php"] [unique_id "amujrxGd_N1Op4Iu5U9j_gABgUQ"]
[Thu Jul 30 14:19:11.192775 2026] [security2:error] [pid 1021791:tid 1022016] [client 180.243.59.178:53168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujrxGd_N1Op4Iu5U9j_wAAAWk"]
[Thu Jul 30 14:19:11.192894 2026] [security2:error] [pid 1021791:tid 1022016] [client 180.243.59.178:53168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujrxGd_N1Op4Iu5U9j_wAAAWk"]
[Thu Jul 30 14:19:11.624653 2026] [security2:error] [pid 1021791:tid 1021936] [client 20.215.191.139:36814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amujrxGd_N1Op4Iu5U9kCwAAARk"]
[Thu Jul 30 14:19:11.721198 2026] [security2:error] [pid 1021791:tid 1021857] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/elementor/wp-login.php"] [unique_id "amujrxGd_N1Op4Iu5U9kBgABWUE"]
[Thu Jul 30 14:19:11.753993 2026] [security2:error] [pid 1021791:tid 1022005] [client 172.237.109.114:58837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amujrxGd_N1Op4Iu5U9j_QAAAV4"]
[Thu Jul 30 14:19:11.797449 2026] [core:notice] [pid 1021791:tid 1021975] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:11.855698 2026] [security2:error] [pid 1021791:tid 1021924] [client 20.215.191.139:20916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amujrxGd_N1Op4Iu5U9kEAAAAQ0"]
[Thu Jul 30 14:19:12.013905 2026] [security2:error] [pid 1021791:tid 1021818] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/elementor/wp-wjvngrh.php"] [unique_id "amujsBGd_N1Op4Iu5U9kGgABPho"]
[Thu Jul 30 14:19:12.039146 2026] [core:notice] [pid 1021791:tid 1022025] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:12.045769 2026] [security2:error] [pid 1021791:tid 1022025] [client 135.181.74.155:59588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/43-people-share-the-most-inspiring.html"] [unique_id "amujsBGd_N1Op4Iu5U9kGwAAAXI"]
[Thu Jul 30 14:19:12.298159 2026] [security2:error] [pid 1021791:tid 1021905] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/elements/filemanager.php"] [unique_id "amujsBGd_N1Op4Iu5U9kHAABFHE"]
[Thu Jul 30 14:19:12.385836 2026] [security2:error] [pid 1021791:tid 1022006] [client 20.215.191.139:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amujsBGd_N1Op4Iu5U9kIgAAAV8"]
[Thu Jul 30 14:19:12.581567 2026] [security2:error] [pid 1021791:tid 1021827] [remote 47.128.28.117:61504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/ro-black-white-2/"] [unique_id "amujsBGd_N1Op4Iu5U9kKwABcSM"]
[Thu Jul 30 14:19:12.581888 2026] [security2:error] [pid 1021791:tid 1021869] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/elements/udd.php"] [unique_id "amujsBGd_N1Op4Iu5U9kKgABME0"]
[Thu Jul 30 14:19:12.679586 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.215.191.139:29076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amujsBGd_N1Op4Iu5U9kLAAAAVg"]
[Thu Jul 30 14:19:12.738380 2026] [security2:error] [pid 1021791:tid 1021903] [remote 216.73.217.142:16906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujsBGd_N1Op4Iu5U9kLQABWm8"]
[Thu Jul 30 14:19:12.865886 2026] [security2:error] [pid 1021791:tid 1021873] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/elements/wp-2019.php"] [unique_id "amujsBGd_N1Op4Iu5U9kLgABMVE"]
[Thu Jul 30 14:19:13.150700 2026] [security2:error] [pid 1021791:tid 1021864] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/elp.php"] [unique_id "amujsRGd_N1Op4Iu5U9kOgABhkg"]
[Thu Jul 30 14:19:13.402048 2026] [security2:error] [pid 1021791:tid 1022019] [client 20.215.191.139:60759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amujsRGd_N1Op4Iu5U9kOwAAAWw"]
[Thu Jul 30 14:19:13.435904 2026] [security2:error] [pid 1021791:tid 1021911] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/email.php"] [unique_id "amujsRGd_N1Op4Iu5U9kPwABaXc"]
[Thu Jul 30 14:19:13.721481 2026] [security2:error] [pid 1021791:tid 1021858] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/endpoints/atomlib.php"] [unique_id "amujsRGd_N1Op4Iu5U9kSQABJEI"]
[Thu Jul 30 14:19:14.009050 2026] [security2:error] [pid 1021791:tid 1021916] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/endpoints/class-wp-rest-attachment-controller.php"] [unique_id "amujshGd_N1Op4Iu5U9kTQABHHw"]
[Thu Jul 30 14:19:14.058576 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.215.191.139:20877] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.arabian-tours.com"] [uri "/1.php"] [unique_id "amujshGd_N1Op4Iu5U9kUQAAAS8"]
[Thu Jul 30 14:19:14.058689 2026] [security2:error] [pid 1021791:tid 1021958] [client 20.215.191.139:20877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/1.php"] [unique_id "amujshGd_N1Op4Iu5U9kUQAAAS8"]
[Thu Jul 30 14:19:14.301441 2026] [security2:error] [pid 1021791:tid 1021826] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/endpoints/index.php"] [unique_id "amujshGd_N1Op4Iu5U9kVQABJyI"]
[Thu Jul 30 14:19:14.435915 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.215.191.139:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amujshGd_N1Op4Iu5U9kVgAAASU"]
[Thu Jul 30 14:19:14.585719 2026] [security2:error] [pid 1021791:tid 1021813] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/env.php"] [unique_id "amujshGd_N1Op4Iu5U9kWgABXxU"]
[Thu Jul 30 14:19:14.731077 2026] [security2:error] [pid 1021791:tid 1021913] [remote 57.141.0.9:39020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amujshGd_N1Op4Iu5U9kYgABD3k"]
[Thu Jul 30 14:19:14.869896 2026] [security2:error] [pid 1021791:tid 1021807] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/envato-css.php"] [unique_id "amujshGd_N1Op4Iu5U9kZAABGw8"]
[Thu Jul 30 14:19:15.000793 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.215.191.139:20923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/admin.php"] [unique_id "amujsxGd_N1Op4Iu5U9kZgAAAUI"]
[Thu Jul 30 14:19:15.154523 2026] [security2:error] [pid 1021791:tid 1021798] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/envato-market/inc/class-envato-market-github.php"] [unique_id "amujsxGd_N1Op4Iu5U9kbQABKQY"]
[Thu Jul 30 14:19:15.438999 2026] [security2:error] [pid 1021791:tid 1021808] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/envs.php"] [unique_id "amujsxGd_N1Op4Iu5U9kcQABGhA"]
[Thu Jul 30 14:19:15.722662 2026] [security2:error] [pid 1021791:tid 1021816] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/epinyins.php"] [unique_id "amujsxGd_N1Op4Iu5U9keAABShg"]
[Thu Jul 30 14:19:15.902230 2026] [security2:error] [pid 1021791:tid 1021929] [client 74.248.33.8:49475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/as.php"] [unique_id "amujsxGd_N1Op4Iu5U9kfQAAARI"]
[Thu Jul 30 14:19:16.006648 2026] [security2:error] [pid 1021791:tid 1021825] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.markmocek.com"] [uri "/erinyani/asasx.php"] [unique_id "amujtBGd_N1Op4Iu5U9kfgABQSE"]
[Thu Jul 30 14:19:16.265416 2026] [core:notice] [pid 1021791:tid 1021963] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:16.272372 2026] [security2:error] [pid 1021791:tid 1021963] [client 135.181.74.155:59588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/50-of-the-most-disturbing.html"] [unique_id "amujtBGd_N1Op4Iu5U9kkQAAATQ"]
[Thu Jul 30 14:19:16.490284 2026] [core:error] [pid 1021791:tid 1021933] [client 152.32.160.252:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:16.490304 2026] [core:error] [pid 1021791:tid 1021933] [client 152.32.160.252:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:16.720172 2026] [security2:error] [pid 1021791:tid 1021800] [remote 74.7.227.39:60068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amujtBGd_N1Op4Iu5U9koAABHQg"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:19:17.250691 2026] [security2:error] [pid 1021791:tid 1022048] [client 45.148.10.120:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.koidomino.click"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amujtRGd_N1Op4Iu5U9krAAAAYk"]
[Thu Jul 30 14:19:18.469772 2026] [security2:error] [pid 1021791:tid 1021974] [client 82.102.27.195:59114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amujthGd_N1Op4Iu5U9kyAAAAT8"]
[Thu Jul 30 14:19:18.469881 2026] [security2:error] [pid 1021791:tid 1021974] [client 82.102.27.195:59114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amujthGd_N1Op4Iu5U9kyAAAAT8"]
[Thu Jul 30 14:19:18.583315 2026] [security2:error] [pid 1021791:tid 1021846] [remote 185.191.171.9:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sagalandfilms.com"] [uri "/about/"] [unique_id "amujthGd_N1Op4Iu5U9kyQABITY"]
[Thu Jul 30 14:19:18.583489 2026] [security2:error] [pid 1021791:tid 1021944] [client 185.191.171.9:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sagalandfilms.com"] [uri "/about/"] [unique_id "amujthGd_N1Op4Iu5U9kyQABITY"]
[Thu Jul 30 14:19:18.647799 2026] [security2:error] [pid 1021791:tid 1021958] [client 74.248.33.8:18757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amujthGd_N1Op4Iu5U9kygAAAS8"]
[Thu Jul 30 14:19:18.764259 2026] [security2:error] [pid 1021791:tid 1021983] [client 179.43.134.114:35044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingstarenterprises.com"] [uri "/wp-login.php"] [unique_id "amujthGd_N1Op4Iu5U9kzgAAAUg"]
[Thu Jul 30 14:19:19.233894 2026] [security2:error] [pid 1021791:tid 1022031] [client 74.248.33.8:50204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amujtxGd_N1Op4Iu5U9k1wAAAXg"]
[Thu Jul 30 14:19:19.624881 2026] [core:error] [pid 1021791:tid 1021952] [client 152.32.160.252:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:19.624901 2026] [core:error] [pid 1021791:tid 1021952] [client 152.32.160.252:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:19.838044 2026] [autoindex:error] [pid 1021791:tid 1021990] [client 179.43.134.114:35050] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:19:20.331780 2026] [security2:error] [pid 1021791:tid 1022045] [client 74.248.33.8:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/plugins.php"] [unique_id "amujuBGd_N1Op4Iu5U9k_wAAAYY"]
[Thu Jul 30 14:19:20.458812 2026] [core:notice] [pid 1021791:tid 1022023] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:20.463257 2026] [security2:error] [pid 1021791:tid 1022023] [client 135.181.74.155:59588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/condoms-and-cupcakes.html"] [unique_id "amujuBGd_N1Op4Iu5U9lCQAAAXA"]
[Thu Jul 30 14:19:21.040750 2026] [security2:error] [pid 1021791:tid 1022039] [client 119.73.97.132:29401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amujuBGd_N1Op4Iu5U9lLwABgHE"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 14:19:21.079894 2026] [security2:error] [pid 1021791:tid 1022024] [client 20.215.191.139:38112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amujuRGd_N1Op4Iu5U9lTAAAAXE"]
[Thu Jul 30 14:19:21.159557 2026] [security2:error] [pid 1021791:tid 1022020] [client 180.243.59.178:53644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujuRGd_N1Op4Iu5U9lTQAAAW0"]
[Thu Jul 30 14:19:21.159719 2026] [security2:error] [pid 1021791:tid 1022020] [client 180.243.59.178:53644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujuRGd_N1Op4Iu5U9lTQAAAW0"]
[Thu Jul 30 14:19:21.512124 2026] [security2:error] [pid 1021791:tid 1021935] [client 74.248.33.8:49926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/js/index.php"] [unique_id "amujuRGd_N1Op4Iu5U9lVgAAARg"]
[Thu Jul 30 14:19:21.801620 2026] [security2:error] [pid 1021791:tid 1021990] [client 20.215.191.139:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amujuRGd_N1Op4Iu5U9lbQAAAU8"]
[Thu Jul 30 14:19:22.202621 2026] [security2:error] [pid 1021791:tid 1021962] [client 20.215.191.139:21539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/as.php"] [unique_id "amujuhGd_N1Op4Iu5U9leAAAATM"]
[Thu Jul 30 14:19:22.261858 2026] [fcgid:warn] [pid 1021791:tid 1021995] (70014)End of file found: [client 152.32.160.252:48674] mod_fcgid: can't get data from http client
[Thu Jul 30 14:19:22.316080 2026] [security2:error] [pid 1021791:tid 1022043] [client 74.248.33.8:51359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/go.php"] [unique_id "amujuhGd_N1Op4Iu5U9lggAAAYQ"]
[Thu Jul 30 14:19:22.502223 2026] [security2:error] [pid 1021791:tid 1021992] [client 20.215.191.139:18213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amujuhGd_N1Op4Iu5U9llwAAAVE"]
[Thu Jul 30 14:19:22.649140 2026] [security2:error] [pid 1021791:tid 1021972] [client 149.76.69.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "journeywomenscenter.org"] [uri "/index.php"] [unique_id "amujuhGd_N1Op4Iu5U9lkQAAAT0"]
[Thu Jul 30 14:19:22.739920 2026] [security2:error] [pid 1021791:tid 1022026] [client 149.76.69.16:3074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "journeywomenscenter.org"] [uri "/index.php"] [unique_id "amujuhGd_N1Op4Iu5U9lhwABcx0"]
[Thu Jul 30 14:19:22.742790 2026] [security2:error] [pid 1021791:tid 1022026] [client 149.76.69.16:3074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "journeywomenscenter.org"] [uri "/index.php"] [unique_id "amujuhGd_N1Op4Iu5U9liAABcwo"]
[Thu Jul 30 14:19:22.743462 2026] [security2:error] [pid 1021791:tid 1021841] [remote 216.73.217.142:36028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujuhGd_N1Op4Iu5U9lnwABXTE"]
[Thu Jul 30 14:19:23.338528 2026] [security2:error] [pid 1021791:tid 1021931] [client 20.215.191.139:17754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amujuxGd_N1Op4Iu5U9lswAAARQ"]
[Thu Jul 30 14:19:23.504864 2026] [proxy:error] [pid 1021791:tid 1022029] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:23.504933 2026] [proxy_http:error] [pid 1021791:tid 1022029] [client 34.224.175.62:19983] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:23.505549 2026] [proxy:error] [pid 1021791:tid 1022029] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:23.505616 2026] [proxy_http:error] [pid 1021791:tid 1022029] [client 34.224.175.62:19983] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:23.507723 2026] [proxy:error] [pid 1021791:tid 1021942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:23.507811 2026] [proxy_http:error] [pid 1021791:tid 1021942] [client 34.233.129.35:29945] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:23.508392 2026] [proxy:error] [pid 1021791:tid 1021942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:23.508437 2026] [proxy_http:error] [pid 1021791:tid 1021942] [client 34.233.129.35:29945] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:23.515257 2026] [security2:error] [pid 1021791:tid 1022033] [client 74.248.33.8:49473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/aaa.php"] [unique_id "amujuxGd_N1Op4Iu5U9lvgAAAXo"]
[Thu Jul 30 14:19:23.720675 2026] [core:notice] [pid 1021791:tid 1021983] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:23.721184 2026] [security2:error] [pid 1021791:tid 1021871] [remote 74.7.243.224:36872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amujuxGd_N1Op4Iu5U9lyQABXE8"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:19:24.058902 2026] [core:notice] [pid 1021791:tid 1021977] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:24.257139 2026] [proxy:error] [pid 1021791:tid 1021992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:24.257216 2026] [proxy_http:error] [pid 1021791:tid 1021992] [client 152.32.160.252:48680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:24.257782 2026] [proxy:error] [pid 1021791:tid 1021992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:24.257823 2026] [proxy_http:error] [pid 1021791:tid 1021992] [client 152.32.160.252:48680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:24.283696 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.215.191.139:18202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amujvBGd_N1Op4Iu5U9l2gAAAUk"]
[Thu Jul 30 14:19:24.546782 2026] [core:notice] [pid 1021791:tid 1021930] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:24.766135 2026] [proxy:error] [pid 1021791:tid 1022039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:24.766213 2026] [proxy_http:error] [pid 1021791:tid 1022039] [client 44.216.125.112:35787] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:24.767060 2026] [proxy:error] [pid 1021791:tid 1022039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:24.767111 2026] [proxy_http:error] [pid 1021791:tid 1022039] [client 44.216.125.112:35787] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:24.866919 2026] [core:error] [pid 1021791:tid 1021986] [client 118.193.35.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:24.866942 2026] [core:error] [pid 1021791:tid 1021986] [client 118.193.35.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:25.033055 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.215.191.139:17783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amujvRGd_N1Op4Iu5U9l7gAAAWA"]
[Thu Jul 30 14:19:25.159993 2026] [security2:error] [pid 1021791:tid 1021925] [client 20.215.191.139:25120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/autoload_classmap.php"] [unique_id "amujvRGd_N1Op4Iu5U9l9gAAAQ4"]
[Thu Jul 30 14:19:25.423209 2026] [security2:error] [pid 1021791:tid 1022043] [client 74.248.33.8:49485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/getid3-core.php"] [unique_id "amujvRGd_N1Op4Iu5U9l-wAAAYQ"]
[Thu Jul 30 14:19:25.799315 2026] [security2:error] [pid 1021791:tid 1021955] [client 20.215.191.139:37368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/back.php"] [unique_id "amujvRGd_N1Op4Iu5U9mBgAAASw"]
[Thu Jul 30 14:19:26.226687 2026] [security2:error] [pid 1021791:tid 1021993] [client 74.248.33.8:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/adminer.php"] [unique_id "amujvhGd_N1Op4Iu5U9mDAAAAVI"]
[Thu Jul 30 14:19:26.529785 2026] [security2:error] [pid 1021791:tid 1021998] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amujvRGd_N1Op4Iu5U9l_wABVzQ"]
[Thu Jul 30 14:19:26.560758 2026] [proxy:error] [pid 1021791:tid 1022027] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:26.560837 2026] [proxy_http:error] [pid 1021791:tid 1022027] [client 152.32.160.252:56168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:26.561409 2026] [proxy:error] [pid 1021791:tid 1022027] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:26.561455 2026] [proxy_http:error] [pid 1021791:tid 1022027] [client 152.32.160.252:56168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:26.635229 2026] [security2:error] [pid 1021791:tid 1022028] [client 20.215.191.139:36458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/c/autoload_classmap.php"] [unique_id "amujvhGd_N1Op4Iu5U9mFgAAAXU"]
[Thu Jul 30 14:19:27.133683 2026] [security2:error] [pid 1021791:tid 1022025] [client 20.215.191.139:17751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amujvxGd_N1Op4Iu5U9mIAAAAXI"]
[Thu Jul 30 14:19:27.521739 2026] [security2:error] [pid 1021791:tid 1021922] [client 20.215.191.139:29553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/c/flower.php"] [unique_id "amujvxGd_N1Op4Iu5U9mKgAAAQs"]
[Thu Jul 30 14:19:27.630219 2026] [security2:error] [pid 1021791:tid 1022001] [client 74.248.33.8:49535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amujvxGd_N1Op4Iu5U9mKwAAAVo"]
[Thu Jul 30 14:19:28.392172 2026] [security2:error] [pid 1021791:tid 1021899] [remote 216.73.217.142:44306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujwBGd_N1Op4Iu5U9mPwABVWs"]
[Thu Jul 30 14:19:28.553077 2026] [security2:error] [pid 1021791:tid 1021997] [client 20.215.191.139:37350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/c/xleet.php"] [unique_id "amujwBGd_N1Op4Iu5U9mQwAAAVY"]
[Thu Jul 30 14:19:28.586795 2026] [proxy:error] [pid 1021791:tid 1021955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:28.586853 2026] [proxy_http:error] [pid 1021791:tid 1021955] [client 152.32.160.252:56174] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:28.587432 2026] [proxy:error] [pid 1021791:tid 1021955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:28.587478 2026] [proxy_http:error] [pid 1021791:tid 1021955] [client 152.32.160.252:56174] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:28.736792 2026] [core:error] [pid 1021791:tid 1021970] [client 118.193.35.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:28.736811 2026] [core:error] [pid 1021791:tid 1021970] [client 118.193.35.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:29.348494 2026] [security2:error] [pid 1021791:tid 1022046] [client 20.215.191.139:29055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/classwithtostring.php"] [unique_id "amujwRGd_N1Op4Iu5U9mYwAAAYc"]
[Thu Jul 30 14:19:29.892168 2026] [security2:error] [pid 1021791:tid 1021884] [remote 57.141.0.34:31462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amujwRGd_N1Op4Iu5U9mbgABX1w"]
[Thu Jul 30 14:19:30.306565 2026] [security2:error] [pid 1021791:tid 1021933] [client 20.215.191.139:19503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/content.php"] [unique_id "amujwhGd_N1Op4Iu5U9mewAAARY"]
[Thu Jul 30 14:19:30.347506 2026] [security2:error] [pid 1021791:tid 1022036] [client 74.248.33.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kayomanis.com"] [uri "/index.php"] [unique_id "amujwRGd_N1Op4Iu5U9maQAAAX0"]
[Thu Jul 30 14:19:30.388816 2026] [proxy:error] [pid 1021791:tid 1021967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:30.388902 2026] [proxy_http:error] [pid 1021791:tid 1021967] [client 152.32.160.252:56176] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:30.389484 2026] [proxy:error] [pid 1021791:tid 1021967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:19:30.389529 2026] [proxy_http:error] [pid 1021791:tid 1021967] [client 152.32.160.252:56176] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:19:30.606692 2026] [security2:error] [pid 1021791:tid 1021941] [client 64.225.71.150:57255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "moswey.com"] [uri "/wp-json/batch/v1"] [unique_id "amujwhGd_N1Op4Iu5U9mhAAAAR4"]
[Thu Jul 30 14:19:30.661790 2026] [security2:error] [pid 1021791:tid 1022035] [client 74.248.33.8:18758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/alfa.php"] [unique_id "amujwhGd_N1Op4Iu5U9miAAAAXw"]
[Thu Jul 30 14:19:30.865719 2026] [security2:error] [pid 1021791:tid 1021981] [client 64.225.71.150:57260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "moswey.com"] [uri "/"] [unique_id "amujwhGd_N1Op4Iu5U9miQAAAUY"]
[Thu Jul 30 14:19:30.912997 2026] [core:notice] [pid 1021791:tid 1021997] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:30.916682 2026] [security2:error] [pid 1021791:tid 1021997] [client 135.181.74.155:32980] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/falling-in-love-with-the-idea-of-him.html"] [unique_id "amujwhGd_N1Op4Iu5U9migAAAVY"]
[Thu Jul 30 14:19:30.986803 2026] [security2:error] [pid 1021791:tid 1021962] [client 20.215.191.139:23195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/doc.php"] [unique_id "amujwhGd_N1Op4Iu5U9mjgAAATM"]
[Thu Jul 30 14:19:31.131136 2026] [security2:error] [pid 1021791:tid 1022032] [client 64.225.71.150:57263] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "moswey.com"] [uri "/wp-json/batch/v1"] [unique_id "amujwxGd_N1Op4Iu5U9mlQAAAXk"]
[Thu Jul 30 14:19:31.224812 2026] [security2:error] [pid 1021791:tid 1021964] [client 20.215.191.139:18193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amujwxGd_N1Op4Iu5U9mmQAAATU"]
[Thu Jul 30 14:19:31.453963 2026] [core:notice] [pid 1021791:tid 1021978] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:31.503337 2026] [authz_core:error] [pid 1021791:tid 1021947] [client 74.248.33.8:0] AH01630: client denied by server configuration: /home1/eardjbte/public_html/website_2f97271e/wp-content/uploads/index.php
[Thu Jul 30 14:19:31.662696 2026] [security2:error] [pid 1021791:tid 1022020] [client 74.248.33.8:51354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amujwxGd_N1Op4Iu5U9mqAAAAW0"]
[Thu Jul 30 14:19:31.998272 2026] [security2:error] [pid 1021791:tid 1022011] [client 20.215.191.139:38434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amujwxGd_N1Op4Iu5U9mrAAAAWQ"]
[Thu Jul 30 14:19:32.151002 2026] [security2:error] [pid 1021791:tid 1021952] [client 172.237.109.114:54467] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/l.fcgi"] [unique_id "amujxBGd_N1Op4Iu5U9mswAAASk"]
[Thu Jul 30 14:19:32.226256 2026] [core:error] [pid 1021791:tid 1021813] [remote 74.7.241.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:32.226279 2026] [core:error] [pid 1021791:tid 1021813] [remote 74.7.241.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:32.226440 2026] [security2:error] [pid 1021791:tid 1022006] [client 74.7.241.179:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amujxBGd_N1Op4Iu5U9mtwABXxU"]
[Thu Jul 30 14:19:32.246786 2026] [security2:error] [pid 1021791:tid 1021943] [client 180.243.59.178:54161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujxBGd_N1Op4Iu5U9muAAAASA"]
[Thu Jul 30 14:19:32.246893 2026] [security2:error] [pid 1021791:tid 1021943] [client 180.243.59.178:54161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujxBGd_N1Op4Iu5U9muAAAASA"]
[Thu Jul 30 14:19:32.391192 2026] [core:error] [pid 1021791:tid 1022022] [client 118.193.35.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:32.391212 2026] [core:error] [pid 1021791:tid 1022022] [client 118.193.35.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:32.623760 2026] [security2:error] [pid 1021791:tid 1021967] [client 20.215.191.139:17788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amujxBGd_N1Op4Iu5U9mvwAAATg"]
[Thu Jul 30 14:19:32.644324 2026] [security2:error] [pid 1021791:tid 1022029] [client 74.248.33.8:49961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amujxBGd_N1Op4Iu5U9mwAAAAXY"]
[Thu Jul 30 14:19:32.751158 2026] [core:notice] [pid 1021791:tid 1021922] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:33.698063 2026] [security2:error] [pid 1021791:tid 1022014] [client 74.248.33.8:8837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amujxRGd_N1Op4Iu5U9m2wAAAWc"]
[Thu Jul 30 14:19:34.011294 2026] [security2:error] [pid 1021791:tid 1022000] [client 20.215.191.139:17760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amujxhGd_N1Op4Iu5U9m4AAAAVk"]
[Thu Jul 30 14:19:34.552357 2026] [security2:error] [pid 1021791:tid 1021988] [client 74.248.33.8:51376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/edit.php"] [unique_id "amujxhGd_N1Op4Iu5U9m6wAAAU0"]
[Thu Jul 30 14:19:35.026338 2026] [security2:error] [pid 1021791:tid 1022011] [client 20.215.191.139:17741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amujxxGd_N1Op4Iu5U9m9gAAAWQ"]
[Thu Jul 30 14:19:35.423908 2026] [security2:error] [pid 1021791:tid 1022031] [client 20.215.191.139:19494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/dropdown.php"] [unique_id "amujxxGd_N1Op4Iu5U9m_gAAAXg"]
[Thu Jul 30 14:19:35.470112 2026] [autoindex:error] [pid 1021791:tid 1021921] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:19:35.643242 2026] [authz_core:error] [pid 1021791:tid 1021954] [client 74.248.33.8:0] AH01630: client denied by server configuration: /home1/eardjbte/public_html/website_2f97271e/wp-content/index.php
[Thu Jul 30 14:19:35.827256 2026] [security2:error] [pid 1021791:tid 1021955] [client 74.248.33.8:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/file5.php"] [unique_id "amujxxGd_N1Op4Iu5U9nDAAAASw"]
[Thu Jul 30 14:19:35.831755 2026] [security2:error] [pid 1021791:tid 1022045] [client 20.215.191.139:38450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amujxxGd_N1Op4Iu5U9nDQAAAYY"]
[Thu Jul 30 14:19:36.519781 2026] [core:error] [pid 1021791:tid 1022027] [client 118.193.35.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:36.519803 2026] [core:error] [pid 1021791:tid 1022027] [client 118.193.35.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:36.653938 2026] [security2:error] [pid 1021791:tid 1021996] [client 185.25.107.186:34665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greensparkle.net"] [uri "/index.php"] [unique_id "amujxxGd_N1Op4Iu5U9nCwABVSg"], referer: https://greensparkle.net/paving-products-
[Thu Jul 30 14:19:36.778897 2026] [security2:error] [pid 1021791:tid 1021974] [client 20.215.191.139:20113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/ee.php"] [unique_id "amujyBGd_N1Op4Iu5U9nIgAAAT8"]
[Thu Jul 30 14:19:37.750367 2026] [security2:error] [pid 1021791:tid 1021821] [remote 216.73.217.142:44306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amujyRGd_N1Op4Iu5U9nOwABXB0"]
[Thu Jul 30 14:19:38.287514 2026] [security2:error] [pid 1021791:tid 1021988] [client 20.215.191.139:20123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/flower.php"] [unique_id "amujyhGd_N1Op4Iu5U9nRQAAAU0"]
[Thu Jul 30 14:19:38.902006 2026] [security2:error] [pid 1021791:tid 1021938] [client 20.215.191.139:19512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/gecko-new.php"] [unique_id "amujyhGd_N1Op4Iu5U9nUwAAARs"]
[Thu Jul 30 14:19:39.413112 2026] [security2:error] [pid 1021791:tid 1022017] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amujyhGd_N1Op4Iu5U9nUgAAAWo"]
[Thu Jul 30 14:19:39.569254 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.215.191.139:29007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/m.php"] [unique_id "amujyxGd_N1Op4Iu5U9nZQAAAVc"]
[Thu Jul 30 14:19:39.994316 2026] [security2:error] [pid 1021791:tid 1021995] [client 74.248.33.8:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/sf.php"] [unique_id "amujyxGd_N1Op4Iu5U9nawAAAVQ"]
[Thu Jul 30 14:19:40.292670 2026] [security2:error] [pid 1021791:tid 1021928] [client 20.215.191.139:40246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amujzBGd_N1Op4Iu5U9newAAARE"]
[Thu Jul 30 14:19:40.488864 2026] [security2:error] [pid 1021791:tid 1021948] [client 20.215.191.139:21877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amujzBGd_N1Op4Iu5U9nfAAAASU"]
[Thu Jul 30 14:19:40.845328 2026] [security2:error] [pid 1021791:tid 1021943] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amujzBGd_N1Op4Iu5U9negAAASA"]
[Thu Jul 30 14:19:41.228160 2026] [security2:error] [pid 1021791:tid 1022045] [client 20.215.191.139:21829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/mah/flower.php"] [unique_id "amujzRGd_N1Op4Iu5U9nkQAAAYY"]
[Thu Jul 30 14:19:41.396845 2026] [security2:error] [pid 1021791:tid 1021970] [client 20.215.191.139:38411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amujzRGd_N1Op4Iu5U9nlQAAATs"]
[Thu Jul 30 14:19:41.573409 2026] [core:notice] [pid 1021791:tid 1021958] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:41.578945 2026] [security2:error] [pid 1021791:tid 1021958] [client 135.181.74.155:51090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/for-all-the-girls-who-are-scared-of-commitment.html"] [unique_id "amujzRGd_N1Op4Iu5U9nmQAAAS8"]
[Thu Jul 30 14:19:41.619481 2026] [security2:error] [pid 1021791:tid 1021925] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amujzRGd_N1Op4Iu5U9nigAAAQ4"]
[Thu Jul 30 14:19:41.939879 2026] [security2:error] [pid 1021791:tid 1021987] [client 112.86.225.18:58404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/air-jordan-1-low-black-white-2/"] [unique_id "amujzRGd_N1Op4Iu5U9nowAAAUw"]
[Thu Jul 30 14:19:41.940031 2026] [security2:error] [pid 1021791:tid 1021987] [client 112.86.225.18:58404] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/air-jordan-1-low-black-white-2/"] [unique_id "amujzRGd_N1Op4Iu5U9nowAAAUw"]
[Thu Jul 30 14:19:42.045755 2026] [security2:error] [pid 1021791:tid 1021998] [client 20.215.191.139:39675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amujzhGd_N1Op4Iu5U9npQAAAVc"]
[Thu Jul 30 14:19:42.115492 2026] [autoindex:error] [pid 1021791:tid 1021947] [client 74.248.33.8:50699] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:19:42.140799 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.215.191.139:19495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/mah/xleet.php"] [unique_id "amujzhGd_N1Op4Iu5U9nqgAAARw"]
[Thu Jul 30 14:19:42.363722 2026] [security2:error] [pid 1021791:tid 1022042] [client 74.248.33.8:50699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wso.php"] [unique_id "amujzhGd_N1Op4Iu5U9nsgAAAYM"]
[Thu Jul 30 14:19:42.751222 2026] [security2:error] [pid 1021791:tid 1022002] [client 180.243.59.178:54664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujzhGd_N1Op4Iu5U9nuQAAAVs"]
[Thu Jul 30 14:19:42.751371 2026] [security2:error] [pid 1021791:tid 1022002] [client 180.243.59.178:54664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amujzhGd_N1Op4Iu5U9nuQAAAVs"]
[Thu Jul 30 14:19:43.215966 2026] [security2:error] [pid 1021791:tid 1021985] [client 20.215.191.139:39666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amujzxGd_N1Op4Iu5U9nxgAAAUo"]
[Thu Jul 30 14:19:44.179808 2026] [core:notice] [pid 1021791:tid 1021878] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:44.531003 2026] [security2:error] [pid 1021791:tid 1022041] [client 74.248.33.8:47628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/ioxi-o.php"] [unique_id "amuj0BGd_N1Op4Iu5U9n5wAAAYI"]
[Thu Jul 30 14:19:44.666710 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.215.191.139:21873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/mini.php"] [unique_id "amuj0BGd_N1Op4Iu5U9n6QAAARw"]
[Thu Jul 30 14:19:45.195848 2026] [security2:error] [pid 1021791:tid 1022044] [client 178.156.189.249:35728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amujzxGd_N1Op4Iu5U9n2wAAAYU"], referer: https://globalmarks.pk/
[Thu Jul 30 14:19:45.400695 2026] [security2:error] [pid 1021791:tid 1021934] [client 20.215.191.139:39655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuj0RGd_N1Op4Iu5U9n-QAAARc"]
[Thu Jul 30 14:19:46.097028 2026] [security2:error] [pid 1021791:tid 1021943] [client 74.248.33.8:8599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/file56.php"] [unique_id "amuj0hGd_N1Op4Iu5U9oDAAAASA"]
[Thu Jul 30 14:19:46.526428 2026] [security2:error] [pid 1021791:tid 1021831] [remote 103.124.95.168:48668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-login.php"] [unique_id "amuj0hGd_N1Op4Iu5U9oEgABUSc"]
[Thu Jul 30 14:19:46.544695 2026] [security2:error] [pid 1021791:tid 1022003] [client 20.215.191.139:21883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/moon.php"] [unique_id "amuj0hGd_N1Op4Iu5U9oJAAAAVw"]
[Thu Jul 30 14:19:46.572733 2026] [core:notice] [pid 1021791:tid 1022007] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:46.577731 2026] [security2:error] [pid 1021791:tid 1022007] [client 135.181.74.155:51090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/he-doesn-t-want-you.html"] [unique_id "amuj0hGd_N1Op4Iu5U9oJQAAAWA"]
[Thu Jul 30 14:19:46.717747 2026] [security2:error] [pid 1021791:tid 1021919] [remote 57.141.0.63:59260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/grageaku/article/view/123"] [unique_id "amuj0hGd_N1Op4Iu5U9oJwABNn8"]
[Thu Jul 30 14:19:46.876001 2026] [security2:error] [pid 1021791:tid 1021967] [client 20.215.191.139:40243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuj0hGd_N1Op4Iu5U9oKgAAATg"]
[Thu Jul 30 14:19:47.025489 2026] [security2:error] [pid 1021791:tid 1021949] [client 74.248.33.8:47648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuj0xGd_N1Op4Iu5U9oMwAAASY"]
[Thu Jul 30 14:19:48.007583 2026] [core:notice] [pid 1021791:tid 1021930] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:48.089307 2026] [security2:error] [pid 1021791:tid 1021935] [client 20.215.191.139:39622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuj1BGd_N1Op4Iu5U9oSwAAARg"]
[Thu Jul 30 14:19:48.321024 2026] [security2:error] [pid 1021791:tid 1022005] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuj0xGd_N1Op4Iu5U9oPQABXgQ"]
[Thu Jul 30 14:19:48.495406 2026] [security2:error] [pid 1021791:tid 1021956] [client 20.215.191.139:19505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/new.php"] [unique_id "amuj1BGd_N1Op4Iu5U9oUgAAAS0"]
[Thu Jul 30 14:19:48.496987 2026] [security2:error] [pid 1021791:tid 1021989] [client 74.248.33.8:47796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuj1BGd_N1Op4Iu5U9oUwAAAU4"]
[Thu Jul 30 14:19:48.677783 2026] [core:error] [pid 1021791:tid 1021955] [client 66.249.74.39:49427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:48.677807 2026] [core:error] [pid 1021791:tid 1021955] [client 66.249.74.39:49427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:19:48.902266 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.215.191.139:42304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuj1BGd_N1Op4Iu5U9oWAAAAWY"]
[Thu Jul 30 14:19:49.019174 2026] [core:notice] [pid 1021791:tid 1022026] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:49.448144 2026] [security2:error] [pid 1021791:tid 1021937] [client 20.215.191.139:31785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/radio.php"] [unique_id "amuj1RGd_N1Op4Iu5U9obwAAARo"]
[Thu Jul 30 14:19:49.990073 2026] [security2:error] [pid 1021791:tid 1021965] [client 74.248.33.8:8628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/edit.php"] [unique_id "amuj1RGd_N1Op4Iu5U9ogQAAATY"]
[Thu Jul 30 14:19:50.484120 2026] [core:notice] [pid 1021791:tid 1021935] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:50.489297 2026] [security2:error] [pid 1021791:tid 1021935] [client 135.181.74.155:51090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/here-s-29-insensitive-and-rude-questions-people-have-actually-been-asked.html"] [unique_id "amuj1hGd_N1Op4Iu5U9ojwAAARg"]
[Thu Jul 30 14:19:50.716881 2026] [security2:error] [pid 1021791:tid 1021993] [client 20.215.191.139:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuj1hGd_N1Op4Iu5U9omwAAAVI"]
[Thu Jul 30 14:19:50.728186 2026] [security2:error] [pid 1021791:tid 1022027] [client 74.248.33.8:47653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/2.php"] [unique_id "amuj1hGd_N1Op4Iu5U9onAAAAXQ"]
[Thu Jul 30 14:19:51.469242 2026] [security2:error] [pid 1021791:tid 1021995] [client 20.215.191.139:39658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuj1xGd_N1Op4Iu5U9oqgAAAVQ"]
[Thu Jul 30 14:19:51.918418 2026] [security2:error] [pid 1021791:tid 1021996] [client 20.215.191.139:26845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/s.php"] [unique_id "amuj1xGd_N1Op4Iu5U9otwAAAVU"]
[Thu Jul 30 14:19:51.961024 2026] [fcgid:warn] [pid 1021791:tid 1021926] (70014)End of file found: [client 123.58.200.21:51238] mod_fcgid: can't get data from http client
[Thu Jul 30 14:19:52.369526 2026] [security2:error] [pid 1021791:tid 1022030] [client 20.215.191.139:35067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuj2BGd_N1Op4Iu5U9owgAAAXc"]
[Thu Jul 30 14:19:52.640060 2026] [security2:error] [pid 1021791:tid 1021972] [client 74.248.33.8:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuj2BGd_N1Op4Iu5U9oxwAAAT0"]
[Thu Jul 30 14:19:52.707729 2026] [security2:error] [pid 1021791:tid 1022031] [client 20.215.191.139:18789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/sim.php"] [unique_id "amuj2BGd_N1Op4Iu5U9oywAAAXg"]
[Thu Jul 30 14:19:52.888310 2026] [security2:error] [pid 1021791:tid 1021927] [client 20.215.191.139:38456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuj2BGd_N1Op4Iu5U9o0gAAARA"]
[Thu Jul 30 14:19:52.961058 2026] [security2:error] [pid 1021791:tid 1021966] [client 180.243.59.178:55155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuj2BGd_N1Op4Iu5U9o0wAAATc"]
[Thu Jul 30 14:19:52.961211 2026] [security2:error] [pid 1021791:tid 1021966] [client 180.243.59.178:55155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuj2BGd_N1Op4Iu5U9o0wAAATc"]
[Thu Jul 30 14:19:53.100379 2026] [core:notice] [pid 1021791:tid 1021997] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:54.049105 2026] [security2:error] [pid 1021791:tid 1022013] [client 20.215.191.139:18760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/text.php"] [unique_id "amuj2hGd_N1Op4Iu5U9o7AAAAWY"]
[Thu Jul 30 14:19:54.666352 2026] [security2:error] [pid 1021791:tid 1021992] [client 20.215.191.139:39627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuj2hGd_N1Op4Iu5U9o-gAAAVE"]
[Thu Jul 30 14:19:55.297435 2026] [security2:error] [pid 1021791:tid 1021952] [client 74.248.33.8:49505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/mah.php"] [unique_id "amuj2xGd_N1Op4Iu5U9pDQAAASk"]
[Thu Jul 30 14:19:55.656547 2026] [security2:error] [pid 1021791:tid 1022048] [client 20.215.191.139:24059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/user.php"] [unique_id "amuj2xGd_N1Op4Iu5U9pEgAAAYk"]
[Thu Jul 30 14:19:55.800188 2026] [core:notice] [pid 1021791:tid 1021928] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:56.152711 2026] [core:notice] [pid 1021791:tid 1021963] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:56.156360 2026] [security2:error] [pid 1021791:tid 1021963] [client 135.181.74.155:48844] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/i-can-t-forget-your-love-and-i-can-t-forget-you.html"] [unique_id "amuj3BGd_N1Op4Iu5U9pHwAAATQ"]
[Thu Jul 30 14:19:56.777327 2026] [security2:error] [pid 1021791:tid 1022016] [client 20.215.191.139:35039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuj3BGd_N1Op4Iu5U9pNAAAAWk"]
[Thu Jul 30 14:19:56.798609 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.203.148.31:32514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/LA.php"] [unique_id "amuj3BGd_N1Op4Iu5U9pRgAAARw"]
[Thu Jul 30 14:19:57.324581 2026] [security2:error] [pid 1021791:tid 1022003] [client 20.215.191.139:29029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/webadmin.php"] [unique_id "amuj3RGd_N1Op4Iu5U9pUQAAAVw"]
[Thu Jul 30 14:19:57.608234 2026] [security2:error] [pid 1021791:tid 1022043] [client 43.173.182.238:36814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/10/23/les-soeurs-grene-la-defense/feed/"] [unique_id "amuj3RGd_N1Op4Iu5U9pVQAAAYQ"]
[Thu Jul 30 14:19:57.756010 2026] [security2:error] [pid 1021791:tid 1021798] [remote 216.73.217.142:64457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuj3RGd_N1Op4Iu5U9pWgABOwY"]
[Thu Jul 30 14:19:57.781316 2026] [security2:error] [pid 1021791:tid 1021957] [client 20.203.148.31:47387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/admin.php"] [unique_id "amuj3RGd_N1Op4Iu5U9pXQAAAS4"]
[Thu Jul 30 14:19:58.190235 2026] [security2:error] [pid 1021791:tid 1022017] [client 20.215.191.139:27479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amuj3hGd_N1Op4Iu5U9pZwAAAWo"]
[Thu Jul 30 14:19:58.297261 2026] [core:notice] [pid 1021791:tid 1021958] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:58.302878 2026] [security2:error] [pid 1021791:tid 1021958] [client 43.173.181.124:33998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/10/23/les-soeurs-grene-la-defense/feed/"] [unique_id "amuj3hGd_N1Op4Iu5U9pagAAAS8"], referer: https://carnetdeshopping.com/index.php/2015/10/23/les-soeurs-grene-la-defense/feed/
[Thu Jul 30 14:19:58.534111 2026] [security2:error] [pid 1021791:tid 1022037] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuj3RGd_N1Op4Iu5U9pZAABfhA"]
[Thu Jul 30 14:19:58.618072 2026] [security2:error] [pid 1021791:tid 1021901] [remote 57.141.0.27:48582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuj3hGd_N1Op4Iu5U9pdwABYm0"]
[Thu Jul 30 14:19:59.353370 2026] [security2:error] [pid 1021791:tid 1021951] [client 74.248.33.8:50494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/send.php"] [unique_id "amuj3xGd_N1Op4Iu5U9piAAAASg"]
[Thu Jul 30 14:19:59.535076 2026] [core:notice] [pid 1021791:tid 1021975] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:19:59.593423 2026] [security2:error] [pid 1021791:tid 1021984] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuj3hGd_N1Op4Iu5U9pcgABSQ0"]
[Thu Jul 30 14:20:00.170648 2026] [security2:error] [pid 1021791:tid 1021967] [client 20.215.191.139:21460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amuj4BGd_N1Op4Iu5U9powAAATg"]
[Thu Jul 30 14:20:00.656744 2026] [security2:error] [pid 1021791:tid 1021963] [client 20.203.148.31:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/class_api.php"] [unique_id "amuj4BGd_N1Op4Iu5U9prwAAATQ"]
[Thu Jul 30 14:20:00.853386 2026] [security2:error] [pid 1021791:tid 1022026] [client 20.215.191.139:27518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amuj4BGd_N1Op4Iu5U9psAAAAXM"]
[Thu Jul 30 14:20:01.028230 2026] [security2:error] [pid 1021791:tid 1022045] [client 74.248.33.8:8857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuj4RGd_N1Op4Iu5U9pswAAAYY"]
[Thu Jul 30 14:20:01.175660 2026] [security2:error] [pid 1021791:tid 1022047] [client 20.203.148.31:33730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuj4RGd_N1Op4Iu5U9puwAAAYg"]
[Thu Jul 30 14:20:01.573310 2026] [security2:error] [pid 1021791:tid 1021968] [client 85.208.96.198:37150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/12/03/corpo-de-bombeiros-comeca-inscrever-para-o-cfo-2021/"] [unique_id "amuj4RGd_N1Op4Iu5U9pvwAAATk"]
[Thu Jul 30 14:20:01.573436 2026] [security2:error] [pid 1021791:tid 1021968] [client 85.208.96.198:37150] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/12/03/corpo-de-bombeiros-comeca-inscrever-para-o-cfo-2021/"] [unique_id "amuj4RGd_N1Op4Iu5U9pvwAAATk"]
[Thu Jul 30 14:20:02.109675 2026] [core:notice] [pid 1021791:tid 1022002] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:02.114619 2026] [security2:error] [pid 1021791:tid 1022002] [client 135.181.74.155:48848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hi-sub/the-9-kinds-of-hot-guys-there-are.html"] [unique_id "amuj4hGd_N1Op4Iu5U9pywAAAVs"]
[Thu Jul 30 14:20:02.172083 2026] [security2:error] [pid 1021791:tid 1021822] [remote 57.141.0.33:31850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuj4hGd_N1Op4Iu5U9pzwABdh4"]
[Thu Jul 30 14:20:02.282792 2026] [security2:error] [pid 1021791:tid 1021984] [client 20.203.148.31:31007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuj4hGd_N1Op4Iu5U9pxwAAAUk"]
[Thu Jul 30 14:20:02.533426 2026] [security2:error] [pid 1021791:tid 1021939] [client 20.215.191.139:33520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amuj4hGd_N1Op4Iu5U9p2gAAARw"]
[Thu Jul 30 14:20:03.002309 2026] [security2:error] [pid 1021791:tid 1021965] [client 180.243.59.178:55656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuj4xGd_N1Op4Iu5U9p5QAAATY"]
[Thu Jul 30 14:20:03.002516 2026] [security2:error] [pid 1021791:tid 1021965] [client 180.243.59.178:55656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuj4xGd_N1Op4Iu5U9p5QAAATY"]
[Thu Jul 30 14:20:03.056852 2026] [security2:error] [pid 1021791:tid 1021999] [client 20.203.148.31:33766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuj4xGd_N1Op4Iu5U9p5gAAAVg"]
[Thu Jul 30 14:20:03.310056 2026] [security2:error] [pid 1021791:tid 1021988] [client 20.215.191.139:27461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amuj4xGd_N1Op4Iu5U9p8AAAAU0"]
[Thu Jul 30 14:20:03.365466 2026] [security2:error] [pid 1021791:tid 1021852] [remote 216.73.217.142:60501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuj4xGd_N1Op4Iu5U9p8QABbjw"]
[Thu Jul 30 14:20:03.790626 2026] [core:notice] [pid 1021791:tid 1021962] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:04.451572 2026] [security2:error] [pid 1021791:tid 1021950] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuj4xGd_N1Op4Iu5U9qBAAAASc"]
[Thu Jul 30 14:20:05.321710 2026] [core:notice] [pid 1021791:tid 1021929] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:05.326085 2026] [core:notice] [pid 1021791:tid 1022042] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:05.406356 2026] [security2:error] [pid 1021791:tid 1021977] [client 20.215.191.139:24004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amuj5RGd_N1Op4Iu5U9qRQAAAUI"]
[Thu Jul 30 14:20:05.707846 2026] [core:notice] [pid 1021791:tid 1022027] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:05.711385 2026] [security2:error] [pid 1021791:tid 1022027] [client 135.181.74.155:48848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hr-sub/10-perks-of-dating-a-chubby-guy-that-women-need-to-know-about.html"] [unique_id "amuj5RGd_N1Op4Iu5U9qVAAAAXQ"]
[Thu Jul 30 14:20:07.147498 2026] [security2:error] [pid 1021791:tid 1021997] [client 123.58.200.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.tfy.udi.temporary.site"] [uri "/index.php"] [unique_id "amuj5xGd_N1Op4Iu5U9qmQAAAVY"]
[Thu Jul 30 14:20:07.744105 2026] [security2:error] [pid 1021791:tid 1021937] [client 185.200.116.219:46100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuj5xGd_N1Op4Iu5U9qwwAAARo"]
[Thu Jul 30 14:20:07.744197 2026] [security2:error] [pid 1021791:tid 1021937] [client 185.200.116.219:46100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuj5xGd_N1Op4Iu5U9qwwAAARo"]
[Thu Jul 30 14:20:07.948182 2026] [security2:error] [pid 1021791:tid 1021954] [client 20.40.58.237:50640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuj5xGd_N1Op4Iu5U9q1AAAASs"]
[Thu Jul 30 14:20:08.801522 2026] [security2:error] [pid 1021791:tid 1021974] [client 20.215.191.139:26865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuj6BGd_N1Op4Iu5U9q5AAAAT8"]
[Thu Jul 30 14:20:09.130993 2026] [core:notice] [pid 1021791:tid 1022014] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:09.135245 2026] [security2:error] [pid 1021791:tid 1022014] [client 135.181.74.155:48848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hr-sub/100-little-things-worth-being-happy-about.html"] [unique_id "amuj6RGd_N1Op4Iu5U9q8wAAAWc"]
[Thu Jul 30 14:20:09.602082 2026] [security2:error] [pid 1021791:tid 1021933] [client 123.58.200.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.tfy.udi.temporary.site"] [uri "/index.php"] [unique_id "amuj6RGd_N1Op4Iu5U9rAgAAARY"]
[Thu Jul 30 14:20:09.701487 2026] [security2:error] [pid 1021791:tid 1022007] [client 20.203.148.31:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/991176.php"] [unique_id "amuj6RGd_N1Op4Iu5U9rCgAAAWA"]
[Thu Jul 30 14:20:09.786407 2026] [security2:error] [pid 1021791:tid 1021956] [client 20.215.191.139:26831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amuj6RGd_N1Op4Iu5U9rDAAAAS0"]
[Thu Jul 30 14:20:09.960717 2026] [security2:error] [pid 1021791:tid 1021947] [client 203.177.217.222:60264] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj6RGd_N1Op4Iu5U9q9gAAASQ"]
[Thu Jul 30 14:20:10.309897 2026] [security2:error] [pid 1021791:tid 1021947] [client 203.177.217.222:60264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj6RGd_N1Op4Iu5U9q9gAAASQ"]
[Thu Jul 30 14:20:10.926203 2026] [autoindex:error] [pid 1021791:tid 1022005] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:20:11.075690 2026] [security2:error] [pid 1021791:tid 1022015] [client 74.248.33.8:8887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/about.php"] [unique_id "amuj6xGd_N1Op4Iu5U9rNwAAAWg"]
[Thu Jul 30 14:20:11.644644 2026] [security2:error] [pid 1021791:tid 1021993] [client 203.177.217.222:60304] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj6xGd_N1Op4Iu5U9rRgAAAVI"]
[Thu Jul 30 14:20:11.728454 2026] [security2:error] [pid 1021791:tid 1022012] [client 20.215.191.139:21837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amuj6xGd_N1Op4Iu5U9rRwAAAWU"]
[Thu Jul 30 14:20:11.736897 2026] [security2:error] [pid 1021791:tid 1021994] [client 20.203.148.31:32542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuj6xGd_N1Op4Iu5U9rSAAAAVM"]
[Thu Jul 30 14:20:11.751763 2026] [security2:error] [pid 1021791:tid 1022001] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.melatipkr.xyz"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amuj6xGd_N1Op4Iu5U9rSQAAAVo"]
[Thu Jul 30 14:20:11.961836 2026] [security2:error] [pid 1021791:tid 1021993] [client 203.177.217.222:60304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj6xGd_N1Op4Iu5U9rRgAAAVI"]
[Thu Jul 30 14:20:12.115459 2026] [http2:info] [pid 1045527:tid 1045527] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 14:20:12.485611 2026] [security2:error] [pid 1045527:tid 1045657] [client 20.215.191.139:26829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amuj7DbFEG16qLV_6ZdUmgAAAAA"]
[Thu Jul 30 14:20:12.703799 2026] [security2:error] [pid 1045527:tid 1045662] [client 74.248.33.8:47745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/options.php"] [unique_id "amuj7DbFEG16qLV_6ZdUoQAAAAU"]
[Thu Jul 30 14:20:12.763285 2026] [security2:error] [pid 1045527:tid 1045529] [remote 57.141.0.60:30856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuj7DbFEG16qLV_6ZdUogAABAE"]
[Thu Jul 30 14:20:12.921627 2026] [security2:error] [pid 1045527:tid 1045660] [client 20.203.148.31:42768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuj7DbFEG16qLV_6ZdUpwAAAAM"]
[Thu Jul 30 14:20:13.417002 2026] [core:notice] [pid 1045527:tid 1045704] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:13.420997 2026] [security2:error] [pid 1045527:tid 1045704] [client 135.181.74.155:51428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hr-sub/holidays.html"] [unique_id "amuj7TbFEG16qLV_6ZdUtQAAAC8"]
[Thu Jul 30 14:20:13.436835 2026] [security2:error] [pid 1045527:tid 1045698] [client 20.215.191.139:24053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/flower.php"] [unique_id "amuj7TbFEG16qLV_6ZdUtgAAACk"]
[Thu Jul 30 14:20:13.578240 2026] [security2:error] [pid 1045527:tid 1045707] [client 74.248.33.8:8836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuj7TbFEG16qLV_6ZdUuQAAADI"]
[Thu Jul 30 14:20:13.775750 2026] [security2:error] [pid 1045527:tid 1045714] [client 180.243.59.178:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuj7TbFEG16qLV_6ZdUvgAAADk"]
[Thu Jul 30 14:20:13.776005 2026] [security2:error] [pid 1045527:tid 1045714] [client 180.243.59.178:56210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuj7TbFEG16qLV_6ZdUvgAAADk"]
[Thu Jul 30 14:20:14.053400 2026] [security2:error] [pid 1045527:tid 1045672] [client 203.177.217.222:60342] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj7jbFEG16qLV_6ZdUxwAAAA8"]
[Thu Jul 30 14:20:14.288116 2026] [security2:error] [pid 1045527:tid 1045734] [client 20.215.191.139:31800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amuj7jbFEG16qLV_6ZdU0wAAAE0"]
[Thu Jul 30 14:20:14.367400 2026] [security2:error] [pid 1045527:tid 1045733] [client 2.144.22.46:36666] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "speed.cloudflare.com"] [uri "/"] [unique_id "amuj7jbFEG16qLV_6ZdU1AAAAEw"]
[Thu Jul 30 14:20:14.391683 2026] [security2:error] [pid 1045527:tid 1045672] [client 203.177.217.222:60342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj7jbFEG16qLV_6ZdUxwAAAA8"]
[Thu Jul 30 14:20:14.445123 2026] [core:notice] [pid 1045527:tid 1045719] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:14.550790 2026] [security2:error] [pid 1045527:tid 1045741] [client 74.248.33.8:8614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-file.php"] [unique_id "amuj7jbFEG16qLV_6ZdU1gAAAFQ"]
[Thu Jul 30 14:20:15.040401 2026] [security2:error] [pid 1045527:tid 1045782] [client 20.215.191.139:31781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amuj7zbFEG16qLV_6ZdU4wAAAH0"]
[Thu Jul 30 14:20:15.299238 2026] [security2:error] [pid 1045527:tid 1045783] [client 2.144.22.46:36680] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "speed.cloudflare.com"] [uri "/"] [unique_id "amuj7zbFEG16qLV_6ZdU7gAAAH4"]
[Thu Jul 30 14:20:15.535141 2026] [security2:error] [pid 1045527:tid 1045673] [client 20.203.148.31:42813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuj7zbFEG16qLV_6ZdU9gAAABA"]
[Thu Jul 30 14:20:15.698732 2026] [security2:error] [pid 1045527:tid 1045690] [client 20.215.191.139:25920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amuj7zbFEG16qLV_6ZdU_AAAACE"]
[Thu Jul 30 14:20:15.722875 2026] [security2:error] [pid 1045527:tid 1045675] [client 203.177.217.222:60384] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj7zbFEG16qLV_6ZdU_gAAABI"]
[Thu Jul 30 14:20:16.038570 2026] [security2:error] [pid 1045527:tid 1045675] [client 203.177.217.222:60384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj7zbFEG16qLV_6ZdU_gAAABI"]
[Thu Jul 30 14:20:16.656156 2026] [security2:error] [pid 1045527:tid 1045664] [client 74.248.33.8:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/sid3.php"] [unique_id "amuj8DbFEG16qLV_6ZdVDwAAAAc"]
[Thu Jul 30 14:20:16.658371 2026] [core:notice] [pid 1045527:tid 1045573] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:16.965363 2026] [security2:error] [pid 1045527:tid 1045714] [client 20.215.191.139:24042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuj8DbFEG16qLV_6ZdVGwAAADk"]
[Thu Jul 30 14:20:17.225359 2026] [core:notice] [pid 1045527:tid 1045765] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:17.234131 2026] [security2:error] [pid 1045527:tid 1045765] [client 135.181.74.155:51428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hr-sub/how-to-tell-if-he-s-cheating-on-you-or-you-re-being-a-paranoid-fuck.html"] [unique_id "amuj8TbFEG16qLV_6ZdVIQAAAGw"]
[Thu Jul 30 14:20:17.416550 2026] [core:notice] [pid 1045527:tid 1045584] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:17.472866 2026] [security2:error] [pid 1045527:tid 1045760] [client 203.177.217.222:60414] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj8TbFEG16qLV_6ZdVKgAAAGc"]
[Thu Jul 30 14:20:17.774699 2026] [security2:error] [pid 1045527:tid 1045658] [client 20.215.191.139:20852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuj8TbFEG16qLV_6ZdVMQAAAAE"]
[Thu Jul 30 14:20:17.789477 2026] [security2:error] [pid 1045527:tid 1045760] [client 203.177.217.222:60414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj8TbFEG16qLV_6ZdVKgAAAGc"]
[Thu Jul 30 14:20:18.035794 2026] [security2:error] [pid 1045527:tid 1045662] [client 159.89.206.24:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.206.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.erp.qgb.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuj8jbFEG16qLV_6ZdVNgAAAAU"], referer: https://www.bing.com/
[Thu Jul 30 14:20:18.479715 2026] [security2:error] [pid 1045527:tid 1045592] [remote 74.7.227.39:46692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amuj8jbFEG16qLV_6ZdVPgAAI0A"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:20:18.564679 2026] [security2:error] [pid 1045527:tid 1045690] [client 20.215.191.139:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amuj8jbFEG16qLV_6ZdVQgAAACE"]
[Thu Jul 30 14:20:18.579221 2026] [security2:error] [pid 1045527:tid 1045706] [client 20.203.148.31:29482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuj8jbFEG16qLV_6ZdVQwAAADE"]
[Thu Jul 30 14:20:18.995253 2026] [security2:error] [pid 1045527:tid 1045687] [client 74.248.33.8:23517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/themes.php"] [unique_id "amuj8jbFEG16qLV_6ZdVTgAAAB4"]
[Thu Jul 30 14:20:19.190950 2026] [security2:error] [pid 1045527:tid 1045710] [client 203.177.217.222:60464] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj8zbFEG16qLV_6ZdVVgAAADU"]
[Thu Jul 30 14:20:19.476490 2026] [security2:error] [pid 1045527:tid 1045735] [client 20.203.148.31:32552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuj8zbFEG16qLV_6ZdVXwAAAE4"]
[Thu Jul 30 14:20:19.503933 2026] [security2:error] [pid 1045527:tid 1045724] [client 20.215.191.139:26868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuj8zbFEG16qLV_6ZdVYAAAAEM"]
[Thu Jul 30 14:20:19.540369 2026] [security2:error] [pid 1045527:tid 1045710] [client 203.177.217.222:60464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj8zbFEG16qLV_6ZdVVgAAADU"]
[Thu Jul 30 14:20:20.205114 2026] [security2:error] [pid 1045527:tid 1045658] [client 20.203.148.31:32548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuj9DbFEG16qLV_6ZdVdQAAAAE"]
[Thu Jul 30 14:20:20.257466 2026] [security2:error] [pid 1045527:tid 1045659] [client 20.215.191.139:24054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amuj9DbFEG16qLV_6ZdVdgAAAAI"]
[Thu Jul 30 14:20:20.664299 2026] [security2:error] [pid 1045527:tid 1045780] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuj8zbFEG16qLV_6ZdVbQAAe1E"]
[Thu Jul 30 14:20:20.699453 2026] [security2:error] [pid 1045527:tid 1045673] [client 20.203.148.31:47417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuj9DbFEG16qLV_6ZdVgwAAABA"]
[Thu Jul 30 14:20:20.706158 2026] [core:notice] [pid 1045527:tid 1045657] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:20.709925 2026] [security2:error] [pid 1045527:tid 1045657] [client 135.181.74.155:51428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hr-sub/zdravlje.html"] [unique_id "amuj9DbFEG16qLV_6ZdVhAAAAAA"]
[Thu Jul 30 14:20:20.923553 2026] [security2:error] [pid 1045527:tid 1045682] [client 203.177.217.222:60516] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj9DbFEG16qLV_6ZdViwAAABk"]
[Thu Jul 30 14:20:21.264820 2026] [security2:error] [pid 1045527:tid 1045682] [client 203.177.217.222:60516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj9DbFEG16qLV_6ZdViwAAABk"]
[Thu Jul 30 14:20:21.324825 2026] [security2:error] [pid 1045527:tid 1045664] [client 20.203.148.31:32519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuj9TbFEG16qLV_6ZdVkwAAAAc"]
[Thu Jul 30 14:20:21.912846 2026] [core:error] [pid 1045527:tid 1045781] [client 74.7.241.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:20:21.912866 2026] [core:error] [pid 1045527:tid 1045781] [client 74.7.241.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:20:21.913036 2026] [security2:error] [pid 1045527:tid 1045781] [client 74.7.241.147:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.aletihadfurnituretransportllc.cc"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuj9TbFEG16qLV_6ZdVpgAAAHw"]
[Thu Jul 30 14:20:21.913613 2026] [security2:error] [pid 1045527:tid 1045758] [client 74.7.241.147:33810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.aletihadfurnituretransportllc.cc"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuj9TbFEG16qLV_6ZdVowAAZV4"]
[Thu Jul 30 14:20:22.051088 2026] [security2:error] [pid 1045527:tid 1045770] [client 20.203.148.31:42784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuj9jbFEG16qLV_6ZdVqgAAAHE"]
[Thu Jul 30 14:20:22.458221 2026] [core:notice] [pid 1045527:tid 1045628] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:22.601047 2026] [security2:error] [pid 1045527:tid 1045659] [client 203.177.217.222:60564] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj9jbFEG16qLV_6ZdVuQAAAAI"]
[Thu Jul 30 14:20:22.904928 2026] [security2:error] [pid 1045527:tid 1045693] [client 135.237.126.217:42414] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.6.43.217"] [uri "/index.cgi"] [unique_id "amuj9jbFEG16qLV_6ZdVvwAAACQ"]
[Thu Jul 30 14:20:22.955425 2026] [security2:error] [pid 1045527:tid 1045659] [client 203.177.217.222:60564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj9jbFEG16qLV_6ZdVuQAAAAI"]
[Thu Jul 30 14:20:23.161913 2026] [core:notice] [pid 1045527:tid 1045635] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:23.449152 2026] [security2:error] [pid 1045527:tid 1045743] [client 20.215.191.139:32518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amuj9zbFEG16qLV_6ZdV0QAAAFY"]
[Thu Jul 30 14:20:23.951540 2026] [proxy:error] [pid 1045527:tid 1045779] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:20:23.951602 2026] [proxy_http:error] [pid 1045527:tid 1045779] [client 193.47.62.167:48658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:20:23.952297 2026] [proxy:error] [pid 1045527:tid 1045779] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:20:23.952343 2026] [proxy_http:error] [pid 1045527:tid 1045779] [client 193.47.62.167:48658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:20:24.112254 2026] [security2:error] [pid 1045527:tid 1045774] [client 180.243.59.178:57020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuj-DbFEG16qLV_6ZdV7AAAAHU"]
[Thu Jul 30 14:20:24.112394 2026] [security2:error] [pid 1045527:tid 1045774] [client 180.243.59.178:57020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuj-DbFEG16qLV_6ZdV7AAAAHU"]
[Thu Jul 30 14:20:24.304463 2026] [security2:error] [pid 1045527:tid 1045771] [client 203.177.217.222:60604] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj-DbFEG16qLV_6ZdV7gAAAHI"]
[Thu Jul 30 14:20:24.324098 2026] [core:notice] [pid 1045527:tid 1045702] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:24.647773 2026] [security2:error] [pid 1045527:tid 1045771] [client 203.177.217.222:60604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj-DbFEG16qLV_6ZdV7gAAAHI"]
[Thu Jul 30 14:20:24.964183 2026] [security2:error] [pid 1045527:tid 1045705] [client 20.215.191.139:32565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuj-DbFEG16qLV_6ZdWBQAAADA"]
[Thu Jul 30 14:20:25.810805 2026] [security2:error] [pid 1045527:tid 1045536] [remote 57.141.0.25:27782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuj-TbFEG16qLV_6ZdWFgAAPgg"]
[Thu Jul 30 14:20:25.991297 2026] [security2:error] [pid 1045527:tid 1045755] [client 203.177.217.222:60654] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj-TbFEG16qLV_6ZdWGwAAAGI"]
[Thu Jul 30 14:20:26.046553 2026] [security2:error] [pid 1045527:tid 1045779] [client 159.89.206.24:56233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.206.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.erp.qgb.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuj-jbFEG16qLV_6ZdWIgAAAHo"], referer: https://www.bing.com/
[Thu Jul 30 14:20:26.216810 2026] [core:error] [pid 1045527:tid 1045676] [client 184.154.139.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=prestigemassagestudio.cfd&yahoo.com
[Thu Jul 30 14:20:26.216833 2026] [core:error] [pid 1045527:tid 1045676] [client 184.154.139.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=prestigemassagestudio.cfd&yahoo.com
[Thu Jul 30 14:20:26.336700 2026] [security2:error] [pid 1045527:tid 1045755] [client 203.177.217.222:60654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "riyadhprinter.com"] [uri "/wp-comments-post.php"] [unique_id "amuj-TbFEG16qLV_6ZdWGwAAAGI"]
[Thu Jul 30 14:20:26.528151 2026] [core:notice] [pid 1045527:tid 1045679] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:26.528428 2026] [fcgid:warn] [pid 1045527:tid 1045697] (70014)End of file found: [client 66.132.224.232:32178] mod_fcgid: can't get data from http client
[Thu Jul 30 14:20:26.533374 2026] [security2:error] [pid 1045527:tid 1045679] [client 135.181.74.155:41720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/hu-sub/key-factors-to-help-you-know-if-your-first-date-went-well.html"] [unique_id "amuj-jbFEG16qLV_6ZdWKwAAABY"]
[Thu Jul 30 14:20:26.660840 2026] [security2:error] [pid 1045527:tid 1045689] [client 74.248.33.8:48879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/plugins/index.php"] [unique_id "amuj-jbFEG16qLV_6ZdWMgAAACA"]
[Thu Jul 30 14:20:26.728974 2026] [security2:error] [pid 1045527:tid 1045685] [client 20.215.191.139:14293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-config-sample.php"] [unique_id "amuj-jbFEG16qLV_6ZdWMwAAABw"]
[Thu Jul 30 14:20:27.314397 2026] [core:notice] [pid 1045527:tid 1045551] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:27.325526 2026] [core:notice] [pid 1045527:tid 1045552] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:27.342445 2026] [security2:error] [pid 1045527:tid 1045670] [client 119.73.97.132:29793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuj-jbFEG16qLV_6ZdWLQAADQ4"], referer: https://www.urwru.club/wp-admin/post.php?post=685&action=elementor
[Thu Jul 30 14:20:27.506505 2026] [proxy:error] [pid 1045527:tid 1045692] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:20:27.506588 2026] [proxy_http:error] [pid 1045527:tid 1045692] [client 44.213.206.96:60641] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:20:27.507187 2026] [proxy:error] [pid 1045527:tid 1045692] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:20:27.507233 2026] [proxy_http:error] [pid 1045527:tid 1045692] [client 44.213.206.96:60641] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:20:27.521657 2026] [proxy:error] [pid 1045527:tid 1045733] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:20:27.521738 2026] [proxy_http:error] [pid 1045527:tid 1045733] [client 52.4.19.39:35482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:20:27.522639 2026] [proxy:error] [pid 1045527:tid 1045733] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:20:27.522702 2026] [proxy_http:error] [pid 1045527:tid 1045733] [client 52.4.19.39:35482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:20:27.672890 2026] [security2:error] [pid 1045527:tid 1045658] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuj-zbFEG16qLV_6ZdWPgAAARU"]
[Thu Jul 30 14:20:27.856409 2026] [security2:error] [pid 1045527:tid 1045724] [client 74.248.33.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kayomanis.com"] [uri "/index.php"] [unique_id "amuj-zbFEG16qLV_6ZdWSQAAAEM"]
[Thu Jul 30 14:20:27.956335 2026] [core:notice] [pid 1045527:tid 1045570] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:27.982340 2026] [core:notice] [pid 1045527:tid 1045562] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:28.098170 2026] [core:error] [pid 1045527:tid 1045595] [remote 74.7.244.58:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:20:28.098193 2026] [core:error] [pid 1045527:tid 1045595] [remote 74.7.244.58:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:20:28.098353 2026] [security2:error] [pid 1045527:tid 1045680] [client 74.7.244.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.lucky-strike-shop.com"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuj_DbFEG16qLV_6ZdWgwAAF0M"]
[Thu Jul 30 14:20:28.175512 2026] [autoindex:error] [pid 1045527:tid 1045684] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/css/dist/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:20:28.324051 2026] [security2:error] [pid 1045527:tid 1045726] [client 74.248.33.8:48896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuj_DbFEG16qLV_6ZdWlAAAAEU"]
[Thu Jul 30 14:20:29.277523 2026] [security2:error] [pid 1045527:tid 1045583] [remote 74.7.243.224:55612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amuj_TbFEG16qLV_6ZdXBgAAezc"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:20:29.901350 2026] [security2:error] [pid 1045527:tid 1045702] [client 74.248.33.8:9142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/num.php"] [unique_id "amuj_TbFEG16qLV_6ZdXEwAAAC0"]
[Thu Jul 30 14:20:30.070617 2026] [fcgid:warn] [pid 1045527:tid 1045750] (70014)End of file found: [client 118.26.38.251:37954] mod_fcgid: can't get data from http client
[Thu Jul 30 14:20:30.255523 2026] [security2:error] [pid 1045527:tid 1045667] [client 117.5.147.46:31726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj8zbFEG16qLV_6ZdVbgAAAAo"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.255523 2026] [security2:error] [pid 1045527:tid 1045776] [client 27.125.245.1:59493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj8zbFEG16qLV_6ZdVawAAAHc"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.256402 2026] [security2:error] [pid 1021791:tid 1021989] [client 5.37.200.151:34622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6RGd_N1Op4Iu5U9q9wAAAU4"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.256588 2026] [security2:error] [pid 1021791:tid 1021957] [client 176.145.162.50:50500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6BGd_N1Op4Iu5U9q6wAAAS4"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.257844 2026] [security2:error] [pid 1021791:tid 1022027] [client 191.11.223.23:48806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6xGd_N1Op4Iu5U9rPAAAAXQ"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.258222 2026] [security2:error] [pid 1021791:tid 1022002] [client 92.40.200.160:16099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6xGd_N1Op4Iu5U9rOwAAAVs"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.262092 2026] [security2:error] [pid 1021791:tid 1022030] [client 181.85.208.45:55279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6hGd_N1Op4Iu5U9rGAAAAXc"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.263180 2026] [security2:error] [pid 1045527:tid 1045727] [client 79.229.9.234:42964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9TbFEG16qLV_6ZdVjQAAAEY"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.265007 2026] [security2:error] [pid 1045527:tid 1045741] [client 46.160.187.49:4817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9TbFEG16qLV_6ZdVnAAAAFQ"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.265035 2026] [security2:error] [pid 1021791:tid 1022028] [client 92.29.32.25:50532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6RGd_N1Op4Iu5U9q9AAAAXU"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.266207 2026] [security2:error] [pid 1045527:tid 1045754] [client 88.147.173.212:2688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9TbFEG16qLV_6ZdVlwAAAGE"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.266253 2026] [security2:error] [pid 1021791:tid 1021921] [client 123.28.122.148:54350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6BGd_N1Op4Iu5U9q4wAAAQo"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.266376 2026] [security2:error] [pid 1045527:tid 1045732] [client 180.191.75.38:34382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9DbFEG16qLV_6ZdVjAAAAEs"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.267667 2026] [security2:error] [pid 1021791:tid 1021949] [client 103.93.219.254:22323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6hGd_N1Op4Iu5U9rHQAAASY"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.268127 2026] [security2:error] [pid 1045527:tid 1045740] [client 176.29.27.181:4557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9TbFEG16qLV_6ZdVjgAAAFM"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.271305 2026] [security2:error] [pid 1045527:tid 1045739] [client 5.238.215.195:56630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9TbFEG16qLV_6ZdVkgAAAFI"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.271302 2026] [security2:error] [pid 1021791:tid 1021955] [client 80.0.64.172:36578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6RGd_N1Op4Iu5U9q9QAAASw"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.271761 2026] [security2:error] [pid 1021791:tid 1022033] [client 45.173.197.191:35662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6RGd_N1Op4Iu5U9rCwAAAXo"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.272012 2026] [security2:error] [pid 1021791:tid 1021931] [client 102.38.18.184:41362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6hGd_N1Op4Iu5U9rGQAAARQ"], referer: http://pkf.jo
[Thu Jul 30 14:20:30.331232 2026] [core:notice] [pid 1045527:tid 1045692] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:30.620187 2026] [security2:error] [pid 1045527:tid 1045680] [client 20.203.148.31:42776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuj_jbFEG16qLV_6ZdXIgAAABc"]
[Thu Jul 30 14:20:31.063483 2026] [security2:error] [pid 1045527:tid 1045753] [client 20.203.148.31:42815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuj_zbFEG16qLV_6ZdXLgAAAGA"]
[Thu Jul 30 14:20:31.224478 2026] [security2:error] [pid 1021791:tid 1021964] [client 77.175.194.169:42398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6RGd_N1Op4Iu5U9q8gAAATU"], referer: http://pkf.jo
[Thu Jul 30 14:20:31.228834 2026] [security2:error] [pid 1021791:tid 1021946] [client 105.9.200.78:56516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6hGd_N1Op4Iu5U9rJQAAASM"], referer: http://pkf.jo
[Thu Jul 30 14:20:31.229464 2026] [security2:error] [pid 1045527:tid 1045699] [client 196.3.204.228:55284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9DbFEG16qLV_6ZdVfwAAACo"], referer: http://pkf.jo
[Thu Jul 30 14:20:31.229642 2026] [security2:error] [pid 1021791:tid 1021930] [client 97.96.206.181:37199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj6RGd_N1Op4Iu5U9rEAAAARM"], referer: http://pkf.jo
[Thu Jul 30 14:20:31.229870 2026] [security2:error] [pid 1045527:tid 1045669] [client 38.166.72.4:59400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9DbFEG16qLV_6ZdVdAAAAAw"], referer: http://pkf.jo
[Thu Jul 30 14:20:31.945943 2026] [security2:error] [pid 1045527:tid 1045761] [client 20.203.148.31:11713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuj_zbFEG16qLV_6ZdXWQAAAGg"]
[Thu Jul 30 14:20:32.056274 2026] [core:notice] [pid 1045527:tid 1045713] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:32.059917 2026] [security2:error] [pid 1045527:tid 1045713] [client 135.181.74.155:41732] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/it-sub/college.html"] [unique_id "amukADbFEG16qLV_6ZdXXQAAADg"]
[Thu Jul 30 14:20:33.603344 2026] [security2:error] [pid 1045527:tid 1045675] [client 20.203.148.31:42770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amukATbFEG16qLV_6ZdXjAAAABI"]
[Thu Jul 30 14:20:34.068215 2026] [security2:error] [pid 1045527:tid 1045739] [client 185.191.171.6:19932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/14/ex-apresentador-da-record-e-encontrado-morto-dentro-de-casa-em-porto-alegre/"] [unique_id "amukAjbFEG16qLV_6ZdXoAAAAFI"]
[Thu Jul 30 14:20:34.068378 2026] [security2:error] [pid 1045527:tid 1045739] [client 185.191.171.6:19932] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/14/ex-apresentador-da-record-e-encontrado-morto-dentro-de-casa-em-porto-alegre/"] [unique_id "amukAjbFEG16qLV_6ZdXoAAAAFI"]
[Thu Jul 30 14:20:34.083240 2026] [autoindex:error] [pid 1045527:tid 1045674] [client 87.236.176.227:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://koidomino.click:2082
[Thu Jul 30 14:20:34.099379 2026] [core:notice] [pid 1045527:tid 1045686] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:34.909817 2026] [security2:error] [pid 1045527:tid 1045699] [client 180.243.59.178:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukAjbFEG16qLV_6ZdXsgAAACo"]
[Thu Jul 30 14:20:34.910017 2026] [security2:error] [pid 1045527:tid 1045699] [client 180.243.59.178:57619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukAjbFEG16qLV_6ZdXsgAAACo"]
[Thu Jul 30 14:20:35.262336 2026] [security2:error] [pid 1045527:tid 1045666] [client 169.0.200.37:44988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9jbFEG16qLV_6ZdVvQAAAAk"], referer: http://pkf.jo
[Thu Jul 30 14:20:35.267643 2026] [security2:error] [pid 1045527:tid 1045778] [client 181.42.227.210:12732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj-jbFEG16qLV_6ZdWHAAAAHk"], referer: http://pkf.jo
[Thu Jul 30 14:20:35.270004 2026] [security2:error] [pid 1045527:tid 1045716] [client 191.253.40.239:50580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9jbFEG16qLV_6ZdVwwAAADs"], referer: http://pkf.jo
[Thu Jul 30 14:20:35.271752 2026] [security2:error] [pid 1045527:tid 1045731] [client 186.99.147.123:40024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj9zbFEG16qLV_6ZdV1QAAAEo"], referer: http://pkf.jo
[Thu Jul 30 14:20:35.274810 2026] [security2:error] [pid 1045527:tid 1045670] [client 20.203.148.31:32691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/amaxx.php"] [unique_id "amukAzbFEG16qLV_6ZdXvQAAAA0"]
[Thu Jul 30 14:20:35.298929 2026] [core:notice] [pid 1045527:tid 1045700] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:36.246813 2026] [security2:error] [pid 1045527:tid 1045701] [client 187.189.34.225:35058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj_zbFEG16qLV_6ZdXLwAAACw"], referer: http://pkf.jo
[Thu Jul 30 14:20:36.252341 2026] [security2:error] [pid 1045527:tid 1045661] [client 14.162.79.144:47085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj_jbFEG16qLV_6ZdXLQAAAAQ"], referer: http://pkf.jo
[Thu Jul 30 14:20:36.276925 2026] [core:notice] [pid 1045527:tid 1045715] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:36.482006 2026] [autoindex:error] [pid 1045527:tid 1045724] [client 74.248.33.8:38155] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:20:36.495364 2026] [security2:error] [pid 1045527:tid 1045675] [client 20.203.148.31:29697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/bek.php"] [unique_id "amukBDbFEG16qLV_6ZdX1wAAABI"]
[Thu Jul 30 14:20:36.951295 2026] [core:notice] [pid 1045527:tid 1045694] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:37.016056 2026] [security2:error] [pid 1045527:tid 1045755] [client 74.248.33.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kayomanis.com"] [uri "/index.php"] [unique_id "amukBDbFEG16qLV_6ZdX4AAAAGI"]
[Thu Jul 30 14:20:37.194358 2026] [core:notice] [pid 1045527:tid 1045777] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:37.198765 2026] [security2:error] [pid 1045527:tid 1045777] [client 66.249.79.8:61069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/download/2554/pdf/8312"] [unique_id "amukBDbFEG16qLV_6ZdX6AAAAHg"]
[Thu Jul 30 14:20:37.243739 2026] [security2:error] [pid 1045527:tid 1045718] [client 76.154.227.221:43032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj_zbFEG16qLV_6ZdXRAAAAD0"], referer: http://pkf.jo
[Thu Jul 30 14:20:37.243849 2026] [security2:error] [pid 1045527:tid 1045712] [client 189.231.69.169:35342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuj_zbFEG16qLV_6ZdXPQAAADc"], referer: http://pkf.jo
[Thu Jul 30 14:20:37.291623 2026] [security2:error] [pid 1045527:tid 1045733] [client 20.203.148.31:47387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amukBTbFEG16qLV_6ZdX8AAAAEw"]
[Thu Jul 30 14:20:37.312772 2026] [security2:error] [pid 1045527:tid 1045722] [client 74.248.33.8:38155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amukBTbFEG16qLV_6ZdX8wAAAEE"]
[Thu Jul 30 14:20:37.951227 2026] [security2:error] [pid 1045527:tid 1045734] [client 74.248.33.8:48931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amukBTbFEG16qLV_6ZdYAQAAAE0"]
[Thu Jul 30 14:20:38.122868 2026] [core:notice] [pid 1045527:tid 1045538] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:38.232777 2026] [security2:error] [pid 1045527:tid 1045779] [client 2.91.233.123:33062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amukATbFEG16qLV_6ZdXngAAAHo"], referer: http://pkf.jo
[Thu Jul 30 14:20:38.275538 2026] [security2:error] [pid 1045527:tid 1045669] [client 201.164.152.206:49201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amukAjbFEG16qLV_6ZdXsQAAAAw"], referer: http://pkf.jo
[Thu Jul 30 14:20:38.294163 2026] [security2:error] [pid 1045527:tid 1045753] [client 201.114.106.135:41173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amukAjbFEG16qLV_6ZdXpgAAAGA"], referer: http://pkf.jo
[Thu Jul 30 14:20:38.333079 2026] [security2:error] [pid 1045527:tid 1045714] [client 186.131.174.16:41004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amukAzbFEG16qLV_6ZdXxAAAADk"], referer: http://pkf.jo
[Thu Jul 30 14:20:39.137197 2026] [core:notice] [pid 1045527:tid 1045745] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:39.142072 2026] [security2:error] [pid 1045527:tid 1045745] [client 135.181.74.155:37726] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/it-sub/i-m-christian-my-husband-is-muslim-this-is-how-it-works.html"] [unique_id "amukBzbFEG16qLV_6ZdYGwAAAFg"]
[Thu Jul 30 14:20:39.184301 2026] [security2:error] [pid 1045527:tid 1045674] [client 74.248.33.8:48920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "amukBzbFEG16qLV_6ZdYHgAAABE"]
[Thu Jul 30 14:20:39.366100 2026] [security2:error] [pid 1045527:tid 1045660] [client 20.203.148.31:32652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/class.api.php"] [unique_id "amukBzbFEG16qLV_6ZdYJQAAAAM"]
[Thu Jul 30 14:20:39.962318 2026] [security2:error] [pid 1045527:tid 1045566] [remote 167.71.132.111:54472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amukBzbFEG16qLV_6ZdYMwAAKCY"]
[Thu Jul 30 14:20:40.023387 2026] [core:notice] [pid 1045527:tid 1045553] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:40.280783 2026] [security2:error] [pid 1045527:tid 1045773] [client 20.203.148.31:47375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/cong.php"] [unique_id "amukCDbFEG16qLV_6ZdYOQAAAHQ"]
[Thu Jul 30 14:20:40.407711 2026] [security2:error] [pid 1045527:tid 1045679] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amukBzbFEG16qLV_6ZdYLgAAFiQ"]
[Thu Jul 30 14:20:40.412480 2026] [security2:error] [pid 1045527:tid 1045716] [client 198.244.240.208:46922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.toscanamall.com"] [uri "/fi/"] [unique_id "amukCDbFEG16qLV_6ZdYPAAAADs"]
[Thu Jul 30 14:20:40.412637 2026] [security2:error] [pid 1045527:tid 1045716] [client 198.244.240.208:46922] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fi/"] [unique_id "amukCDbFEG16qLV_6ZdYPAAAADs"]
[Thu Jul 30 14:20:40.793607 2026] [security2:error] [pid 1045527:tid 1045690] [client 74.248.33.8:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/gifclass.php"] [unique_id "amukCDbFEG16qLV_6ZdYQwAAACE"]
[Thu Jul 30 14:20:41.206925 2026] [security2:error] [pid 1045527:tid 1045557] [remote 57.141.0.71:25792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amukCTbFEG16qLV_6ZdYSgAASB0"]
[Thu Jul 30 14:20:41.514729 2026] [security2:error] [pid 1045527:tid 1045692] [client 85.208.96.198:46474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product/lark-11/"] [unique_id "amukCTbFEG16qLV_6ZdYVAAAACM"]
[Thu Jul 30 14:20:41.514853 2026] [security2:error] [pid 1045527:tid 1045692] [client 85.208.96.198:46474] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "online-hope.com"] [uri "/product/lark-11/"] [unique_id "amukCTbFEG16qLV_6ZdYVAAAACM"]
[Thu Jul 30 14:20:41.552081 2026] [security2:error] [pid 1045527:tid 1045661] [client 82.102.27.195:47432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amukCTbFEG16qLV_6ZdYVQAAAAQ"]
[Thu Jul 30 14:20:41.552167 2026] [security2:error] [pid 1045527:tid 1045661] [client 82.102.27.195:47432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amukCTbFEG16qLV_6ZdYVQAAAAQ"]
[Thu Jul 30 14:20:41.931962 2026] [security2:error] [pid 1045527:tid 1045748] [client 20.203.148.31:32054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/content.php"] [unique_id "amukCTbFEG16qLV_6ZdYYAAAAFs"]
[Thu Jul 30 14:20:41.941405 2026] [autoindex:error] [pid 1045527:tid 1045703] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:20:42.142337 2026] [security2:error] [pid 1045527:tid 1045694] [client 74.248.33.8:15601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amukCjbFEG16qLV_6ZdYZAAAACU"]
[Thu Jul 30 14:20:42.762365 2026] [security2:error] [pid 1045527:tid 1045759] [client 74.248.33.8:46773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/css/index.php"] [unique_id "amukCjbFEG16qLV_6ZdYcgAAAGY"]
[Thu Jul 30 14:20:43.819997 2026] [security2:error] [pid 1045527:tid 1045679] [client 74.248.33.8:52300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-cron.php"] [unique_id "amukCzbFEG16qLV_6ZdYiAAAABY"]
[Thu Jul 30 14:20:44.313600 2026] [security2:error] [pid 1045527:tid 1045762] [client 85.208.96.208:16656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/28/tse-proibe-manifestacao-pro-lula-no-lollapalooza-e-define-multa/"] [unique_id "amukDDbFEG16qLV_6ZdYkgAAAGk"]
[Thu Jul 30 14:20:44.313724 2026] [security2:error] [pid 1045527:tid 1045762] [client 85.208.96.208:16656] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/28/tse-proibe-manifestacao-pro-lula-no-lollapalooza-e-define-multa/"] [unique_id "amukDDbFEG16qLV_6ZdYkgAAAGk"]
[Thu Jul 30 14:20:44.476860 2026] [security2:error] [pid 1045527:tid 1045746] [client 20.203.148.31:32696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amukDDbFEG16qLV_6ZdYmgAAAFk"]
[Thu Jul 30 14:20:45.368256 2026] [security2:error] [pid 1045527:tid 1045664] [client 180.243.59.178:58138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukDTbFEG16qLV_6ZdYqwAAAAc"]
[Thu Jul 30 14:20:45.368444 2026] [security2:error] [pid 1045527:tid 1045664] [client 180.243.59.178:58138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukDTbFEG16qLV_6ZdYqwAAAAc"]
[Thu Jul 30 14:20:45.381401 2026] [security2:error] [pid 1045527:tid 1045748] [client 20.203.148.31:42762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/elp.php"] [unique_id "amukDTbFEG16qLV_6ZdYrAAAAFs"]
[Thu Jul 30 14:20:45.832449 2026] [core:notice] [pid 1045527:tid 1045773] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:45.836007 2026] [security2:error] [pid 1045527:tid 1045773] [client 135.181.74.155:57226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/it-sub/money.html"] [unique_id "amukDTbFEG16qLV_6ZdYtgAAAHQ"]
[Thu Jul 30 14:20:46.070668 2026] [security2:error] [pid 1045527:tid 1045701] [client 74.248.33.8:48539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-block.php"] [unique_id "amukDjbFEG16qLV_6ZdYwAAAACw"]
[Thu Jul 30 14:20:46.258884 2026] [security2:error] [pid 1045527:tid 1045738] [client 20.203.148.31:47400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amukDjbFEG16qLV_6ZdYwQAAAFE"]
[Thu Jul 30 14:20:46.301987 2026] [security2:error] [pid 1045527:tid 1045722] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukDTbFEG16qLV_6ZdYtQAAAEE"]
[Thu Jul 30 14:20:47.916652 2026] [security2:error] [pid 1045527:tid 1045729] [client 74.248.33.8:48519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "amukDzbFEG16qLV_6ZdY4QAAAEg"]
[Thu Jul 30 14:20:48.680949 2026] [security2:error] [pid 1045527:tid 1045688] [client 118.26.38.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.tdh.nyx.temporary.site"] [uri "/index.php"] [unique_id "amukEDbFEG16qLV_6ZdY7QAAAB8"]
[Thu Jul 30 14:20:49.689824 2026] [security2:error] [pid 1045527:tid 1045696] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amukETbFEG16qLV_6ZdZAAAAJ3E"]
[Thu Jul 30 14:20:49.841829 2026] [security2:error] [pid 1045527:tid 1045743] [client 73.109.28.246:62645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.kendarikomputer.com"] [uri "/p/contact.html"] [unique_id "amukETbFEG16qLV_6ZdZDQAAAFY"]
[Thu Jul 30 14:20:50.100281 2026] [autoindex:error] [pid 1045527:tid 1045723] [client 74.248.33.8:50962] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:20:50.128304 2026] [core:notice] [pid 1045527:tid 1045761] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:20:50.132737 2026] [security2:error] [pid 1045527:tid 1045761] [client 135.181.74.155:57226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/it-sub/this-is-what-being-faithful-means-because-it-s-more-than-not-sleeping-around.html"] [unique_id "amukEjbFEG16qLV_6ZdZFQAAAGg"]
[Thu Jul 30 14:20:50.248358 2026] [security2:error] [pid 1045527:tid 1045715] [client 74.248.33.8:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/classwithtostring.php"] [unique_id "amukEjbFEG16qLV_6ZdZGQAAADo"]
[Thu Jul 30 14:20:50.514370 2026] [security2:error] [pid 1045527:tid 1045750] [client 20.203.148.31:11994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amukEjbFEG16qLV_6ZdZGgAAAF0"]
[Thu Jul 30 14:20:50.969204 2026] [security2:error] [pid 1045527:tid 1045767] [client 74.248.33.8:23595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/test1.php"] [unique_id "amukEjbFEG16qLV_6ZdZJAAAAG4"]
[Thu Jul 30 14:20:51.622865 2026] [autoindex:error] [pid 1045527:tid 1045709] [client 74.248.33.8:50533] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:20:51.661931 2026] [security2:error] [pid 1045527:tid 1045772] [client 20.203.148.31:32665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amukEzbFEG16qLV_6ZdZMwAAAHM"]
[Thu Jul 30 14:20:51.810712 2026] [security2:error] [pid 1045527:tid 1045777] [client 74.248.33.8:50533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/images/index.php"] [unique_id "amukEzbFEG16qLV_6ZdZOgAAAHg"]
[Thu Jul 30 14:20:52.035313 2026] [proxy:error] [pid 1045527:tid 1045712] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:20:52.035402 2026] [proxy_http:error] [pid 1045527:tid 1045712] [client 44.213.206.96:42548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:20:52.035986 2026] [proxy:error] [pid 1045527:tid 1045712] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:20:52.036031 2026] [proxy_http:error] [pid 1045527:tid 1045712] [client 44.213.206.96:42548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:20:52.443808 2026] [autoindex:error] [pid 1045527:tid 1045718] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:20:52.592034 2026] [security2:error] [pid 1045527:tid 1045734] [client 74.248.33.8:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/asd.php"] [unique_id "amukFDbFEG16qLV_6ZdZSwAAAE0"]
[Thu Jul 30 14:20:52.592192 2026] [security2:error] [pid 1045527:tid 1045688] [client 20.203.148.31:11764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amukFDbFEG16qLV_6ZdZTAAAAB8"]
[Thu Jul 30 14:20:52.732995 2026] [security2:error] [pid 1045527:tid 1045644] [remote 152.228.213.32:50016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lld.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amukFDbFEG16qLV_6ZdZUAAAO3Q"]
[Thu Jul 30 14:20:53.171763 2026] [security2:error] [pid 1045527:tid 1045681] [client 20.203.148.31:42764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amukFTbFEG16qLV_6ZdZVwAAABg"]
[Thu Jul 30 14:20:53.282080 2026] [security2:error] [pid 1045527:tid 1045753] [client 74.248.33.8:15927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amukFTbFEG16qLV_6ZdZXQAAAGA"]
[Thu Jul 30 14:20:53.669803 2026] [security2:error] [pid 1045527:tid 1045774] [client 157.34.51.178:37798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amukFTbFEG16qLV_6ZdZYgAAAHU"], referer: http://pkf.jo
[Thu Jul 30 14:20:54.004640 2026] [security2:error] [pid 1045527:tid 1045776] [client 20.203.148.31:40689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amukFjbFEG16qLV_6ZdZcQAAAHc"]
[Thu Jul 30 14:20:54.089232 2026] [security2:error] [pid 1045527:tid 1045664] [client 74.248.33.8:15931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amukFjbFEG16qLV_6ZdZcgAAAAc"]
[Thu Jul 30 14:20:56.376070 2026] [security2:error] [pid 1045527:tid 1045667] [client 74.248.33.8:47382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/atomlib.php"] [unique_id "amukGDbFEG16qLV_6ZdZngAAAAo"]
[Thu Jul 30 14:20:56.698399 2026] [security2:error] [pid 1045527:tid 1045677] [client 180.243.59.178:58694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukGDbFEG16qLV_6ZdZqQAAABQ"]
[Thu Jul 30 14:20:56.698560 2026] [security2:error] [pid 1045527:tid 1045677] [client 180.243.59.178:58694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukGDbFEG16qLV_6ZdZqQAAABQ"]
[Thu Jul 30 14:20:56.922676 2026] [security2:error] [pid 1045527:tid 1045541] [remote 170.106.113.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.113.106.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/xmlrpc.php"] [unique_id "amukGDbFEG16qLV_6ZdZnwAAOQ0"]
[Thu Jul 30 14:20:57.461348 2026] [autoindex:error] [pid 1045527:tid 1045685] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:20:57.680216 2026] [autoindex:error] [pid 1045527:tid 1045730] [client 74.248.33.8:47374] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:20:57.828137 2026] [security2:error] [pid 1045527:tid 1045704] [client 74.248.33.8:47374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amukGTbFEG16qLV_6ZdZwAAAAC8"]
[Thu Jul 30 14:20:57.891642 2026] [security2:error] [pid 1045527:tid 1045737] [client 20.52.125.110:3329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/geju.php"] [unique_id "amukGTbFEG16qLV_6ZdZwQAAAFA"]
[Thu Jul 30 14:20:58.080186 2026] [security2:error] [pid 1045527:tid 1045777] [client 20.203.148.31:32659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amukGjbFEG16qLV_6ZdZywAAAHg"]
[Thu Jul 30 14:20:58.542446 2026] [security2:error] [pid 1045527:tid 1045778] [client 20.52.125.110:3596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/about.php"] [unique_id "amukGjbFEG16qLV_6ZdZ0wAAAHk"]
[Thu Jul 30 14:20:58.724924 2026] [security2:error] [pid 1045527:tid 1045552] [remote 57.141.0.18:62062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4754262821/feed/rss2/"] [unique_id "amukGjbFEG16qLV_6ZdZ2gAALBg"]
[Thu Jul 30 14:21:00.076916 2026] [security2:error] [pid 1045527:tid 1045713] [client 20.203.148.31:30587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amukHDbFEG16qLV_6ZdZ8wAAADg"]
[Thu Jul 30 14:21:00.569484 2026] [autoindex:error] [pid 1045527:tid 1045780] [client 74.248.33.8:52593] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:00.710175 2026] [security2:error] [pid 1045527:tid 1045568] [remote 57.141.0.49:41060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7514146397/feed/rss2/"] [unique_id "amukHDbFEG16qLV_6ZdaAAAAbig"]
[Thu Jul 30 14:21:00.728538 2026] [security2:error] [pid 1045527:tid 1045674] [client 20.52.125.110:3637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp.php"] [unique_id "amukHDbFEG16qLV_6ZdaAQAAABE"]
[Thu Jul 30 14:21:00.783127 2026] [autoindex:error] [pid 1045527:tid 1045736] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/blocks/block/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:00.900489 2026] [core:notice] [pid 1045527:tid 1045678] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:00.902017 2026] [security2:error] [pid 1045527:tid 1045678] [client 135.181.74.155:36976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amukHDbFEG16qLV_6ZdaCAAAABU"]
[Thu Jul 30 14:21:00.961048 2026] [autoindex:error] [pid 1045527:tid 1045733] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:01.138920 2026] [autoindex:error] [pid 1045527:tid 1045698] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:01.352459 2026] [security2:error] [pid 1045527:tid 1045725] [client 74.248.33.8:52593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/inputs.php"] [unique_id "amukHTbFEG16qLV_6ZdaGgAAAEQ"]
[Thu Jul 30 14:21:01.360699 2026] [core:notice] [pid 1045527:tid 1045718] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:01.365066 2026] [security2:error] [pid 1045527:tid 1045718] [client 135.181.74.155:36980] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/ja-sub/13-warning-signs-you-re-falling-in-love-with-a-narcissist.html"] [unique_id "amukHTbFEG16qLV_6ZdaGwAAAD0"]
[Thu Jul 30 14:21:01.379061 2026] [security2:error] [pid 1045527:tid 1045726] [client 136.158.67.64:7264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amukHTbFEG16qLV_6ZdaDAAAAEU"], referer: http://pkf.jo
[Thu Jul 30 14:21:01.610370 2026] [security2:error] [pid 1045527:tid 1045706] [client 20.52.125.110:3631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/aaa.php"] [unique_id "amukHTbFEG16qLV_6ZdaHgAAADE"]
[Thu Jul 30 14:21:01.708636 2026] [core:notice] [pid 1045527:tid 1045673] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:02.267823 2026] [core:notice] [pid 1045527:tid 1045669] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:02.367359 2026] [security2:error] [pid 1045527:tid 1045658] [client 74.248.33.8:45524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/index.php"] [unique_id "amukHjbFEG16qLV_6ZdaPAAAAAE"]
[Thu Jul 30 14:21:02.444135 2026] [security2:error] [pid 1045527:tid 1045727] [client 187.191.39.120:14185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amukHjbFEG16qLV_6ZdaLwAAAEY"], referer: http://pkf.jo
[Thu Jul 30 14:21:02.539408 2026] [security2:error] [pid 1045527:tid 1045676] [client 45.166.25.223:27577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amukHjbFEG16qLV_6ZdaMwAAABM"], referer: http://pkf.jo
[Thu Jul 30 14:21:02.867926 2026] [security2:error] [pid 1045527:tid 1045675] [client 66.24.232.244:46287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amukHjbFEG16qLV_6ZdaPQAAABI"], referer: http://pkf.jo
[Thu Jul 30 14:21:02.887433 2026] [security2:error] [pid 1045527:tid 1045739] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukHjbFEG16qLV_6ZdaOAAAAFI"]
[Thu Jul 30 14:21:02.907970 2026] [security2:error] [pid 1045527:tid 1045760] [client 20.203.148.31:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amukHjbFEG16qLV_6ZdaSQAAAGc"]
[Thu Jul 30 14:21:03.140777 2026] [core:notice] [pid 1045527:tid 1045703] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:03.919111 2026] [security2:error] [pid 1045527:tid 1045775] [client 20.52.125.110:3642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/hoot.php"] [unique_id "amukHzbFEG16qLV_6ZdaYgAAAHY"]
[Thu Jul 30 14:21:04.135356 2026] [security2:error] [pid 1045527:tid 1045782] [client 74.248.33.8:50307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/network/index.php"] [unique_id "amukIDbFEG16qLV_6ZdaZQAAAH0"]
[Thu Jul 30 14:21:04.159219 2026] [security2:error] [pid 1045527:tid 1045711] [client 20.203.148.31:30989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amukIDbFEG16qLV_6ZdaZgAAADY"]
[Thu Jul 30 14:21:04.188496 2026] [security2:error] [pid 1045527:tid 1045765] [client 119.73.97.132:29985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amukHzbFEG16qLV_6ZdaZAAAbDM"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 14:21:04.610226 2026] [security2:error] [pid 1045527:tid 1045702] [client 20.52.125.110:3615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/about.php"] [unique_id "amukIDbFEG16qLV_6ZdacAAAAC0"]
[Thu Jul 30 14:21:04.974093 2026] [security2:error] [pid 1045527:tid 1045668] [client 20.203.148.31:30557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amukIDbFEG16qLV_6ZdaegAAAAs"]
[Thu Jul 30 14:21:05.413398 2026] [security2:error] [pid 1045527:tid 1045613] [remote 57.141.0.42:49804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amukITbFEG16qLV_6ZdahAAADFU"]
[Thu Jul 30 14:21:05.511145 2026] [core:notice] [pid 1045527:tid 1045606] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:05.575240 2026] [security2:error] [pid 1045527:tid 1045783] [client 20.52.125.110:3584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/admin.php"] [unique_id "amukITbFEG16qLV_6ZdajQAAAH4"]
[Thu Jul 30 14:21:05.601816 2026] [core:notice] [pid 1045527:tid 1045616] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:05.631128 2026] [fcgid:warn] [pid 1045527:tid 1045736] (70014)End of file found: [client 199.45.155.64:38630] mod_fcgid: can't get data from http client
[Thu Jul 30 14:21:05.839857 2026] [security2:error] [pid 1045527:tid 1045745] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukITbFEG16qLV_6ZdafQAAAFg"]
[Thu Jul 30 14:21:06.167048 2026] [security2:error] [pid 1045527:tid 1045691] [client 180.243.59.178:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukIjbFEG16qLV_6ZdanAAAACI"]
[Thu Jul 30 14:21:06.167179 2026] [security2:error] [pid 1045527:tid 1045691] [client 180.243.59.178:59162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukIjbFEG16qLV_6ZdanAAAACI"]
[Thu Jul 30 14:21:06.568332 2026] [security2:error] [pid 1045527:tid 1045760] [client 74.248.33.8:47475] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kayomanis.com"] [uri "/wp-content/1.php"] [unique_id "amukIjbFEG16qLV_6ZdapgAAAGc"]
[Thu Jul 30 14:21:06.568466 2026] [security2:error] [pid 1045527:tid 1045760] [client 74.248.33.8:47475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/1.php"] [unique_id "amukIjbFEG16qLV_6ZdapgAAAGc"]
[Thu Jul 30 14:21:06.664284 2026] [security2:error] [pid 1045527:tid 1045666] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukIjbFEG16qLV_6ZdamwAAAAk"]
[Thu Jul 30 14:21:07.174186 2026] [security2:error] [pid 1045527:tid 1045704] [client 20.52.125.110:3587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/admin.php"] [unique_id "amukIzbFEG16qLV_6ZdatAAAAC8"]
[Thu Jul 30 14:21:07.535464 2026] [core:notice] [pid 1045527:tid 1045702] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:07.540542 2026] [security2:error] [pid 1045527:tid 1045702] [client 135.181.74.155:38780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/ja-sub/17-signs-you-re-what-s-known-as-an-indigo-child.html"] [unique_id "amukIzbFEG16qLV_6ZdauwAAAC0"]
[Thu Jul 30 14:21:07.567941 2026] [security2:error] [pid 1045527:tid 1045681] [client 20.203.148.31:30381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amukIzbFEG16qLV_6ZdavQAAABg"]
[Thu Jul 30 14:21:07.621962 2026] [security2:error] [pid 1045527:tid 1045738] [client 74.248.33.8:47456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/plugin.php"] [unique_id "amukIzbFEG16qLV_6ZdawAAAAFE"]
[Thu Jul 30 14:21:08.082733 2026] [security2:error] [pid 1045527:tid 1045746] [client 20.52.125.110:3351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/db-cache.php"] [unique_id "amukJDbFEG16qLV_6ZdayQAAAFk"]
[Thu Jul 30 14:21:08.347378 2026] [security2:error] [pid 1045527:tid 1045767] [client 74.248.33.8:52567] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kayomanis.com"] [uri "/1.php"] [unique_id "amukJDbFEG16qLV_6ZdazgAAAG4"]
[Thu Jul 30 14:21:08.347523 2026] [security2:error] [pid 1045527:tid 1045767] [client 74.248.33.8:52567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/1.php"] [unique_id "amukJDbFEG16qLV_6ZdazgAAAG4"]
[Thu Jul 30 14:21:08.748846 2026] [security2:error] [pid 1045527:tid 1045665] [client 172.237.109.114:24633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukJDbFEG16qLV_6ZdazQAAAAg"]
[Thu Jul 30 14:21:08.804372 2026] [security2:error] [pid 1045527:tid 1045737] [client 20.52.125.110:3618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amukJDbFEG16qLV_6Zda3AAAAFA"]
[Thu Jul 30 14:21:08.829878 2026] [security2:error] [pid 1045527:tid 1045772] [client 20.203.148.31:30357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amukJDbFEG16qLV_6Zda3QAAAHM"]
[Thu Jul 30 14:21:09.800165 2026] [security2:error] [pid 1045527:tid 1045730] [client 74.248.33.8:51571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/gg.php"] [unique_id "amukJTbFEG16qLV_6Zda9QAAAEk"]
[Thu Jul 30 14:21:09.921397 2026] [security2:error] [pid 1045527:tid 1045682] [client 20.52.125.110:3610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amukJTbFEG16qLV_6Zda9gAAABk"]
[Thu Jul 30 14:21:10.661810 2026] [security2:error] [pid 1045527:tid 1045702] [client 20.203.148.31:42877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amukJjbFEG16qLV_6ZdbBQAAAC0"]
[Thu Jul 30 14:21:11.077841 2026] [core:notice] [pid 1045527:tid 1045671] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:11.327591 2026] [security2:error] [pid 1045527:tid 1045783] [client 20.52.125.110:3616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amukJzbFEG16qLV_6ZdbFQAAAH4"]
[Thu Jul 30 14:21:11.333973 2026] [security2:error] [pid 1045527:tid 1045746] [client 20.203.148.31:42832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amukJzbFEG16qLV_6ZdbFgAAAFk"]
[Thu Jul 30 14:21:12.195757 2026] [core:notice] [pid 1045527:tid 1045659] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:12.200890 2026] [security2:error] [pid 1045527:tid 1045659] [client 135.181.74.155:38780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radiojelli.com"] [uri "/ja-sub/26-men-share-the-secrets-that-transform-a-woman-into-a-sex-goddess.html"] [unique_id "amukKDbFEG16qLV_6ZdbJAAAAAI"]
[Thu Jul 30 14:21:12.270788 2026] [security2:error] [pid 1045527:tid 1045678] [client 20.52.125.110:3589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amukKDbFEG16qLV_6ZdbKAAAABU"]
[Thu Jul 30 14:21:12.531431 2026] [security2:error] [pid 1045527:tid 1045531] [remote 213.180.203.92:37386] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/2024/02/27/the-largest-container-ship-in-the-world-arrived/"] [unique_id "amukKDbFEG16qLV_6ZdbLwAACQM"]
[Thu Jul 30 14:21:12.582463 2026] [core:notice] [pid 1045527:tid 1045703] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:12.610526 2026] [autoindex:error] [pid 1045527:tid 1045711] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/images/crystal/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:12.759360 2026] [security2:error] [pid 1045527:tid 1045763] [client 74.248.33.8:42502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-content/languages/index.php"] [unique_id "amukKDbFEG16qLV_6ZdbOgAAAGo"]
[Thu Jul 30 14:21:12.985249 2026] [security2:error] [pid 1045527:tid 1045714] [client 20.52.125.110:3594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amukKDbFEG16qLV_6ZdbPgAAADk"]
[Thu Jul 30 14:21:13.144184 2026] [security2:error] [pid 1045527:tid 1045760] [client 20.203.148.31:30542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amukKTbFEG16qLV_6ZdbQAAAAGc"]
[Thu Jul 30 14:21:13.599750 2026] [security2:error] [pid 1045527:tid 1045770] [client 74.248.33.8:14479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp.php"] [unique_id "amukKTbFEG16qLV_6ZdbSwAAAHE"]
[Thu Jul 30 14:21:13.823230 2026] [security2:error] [pid 1045527:tid 1045758] [client 20.203.148.31:11621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amukKTbFEG16qLV_6ZdbVQAAAGU"]
[Thu Jul 30 14:21:14.942429 2026] [security2:error] [pid 1045527:tid 1045697] [client 114.119.151.83:38147] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nimna.lk"] [uri "/images/awards/121.jpg"] [unique_id "amukKjbFEG16qLV_6ZdbcQAAACg"], referer: https://www.nimna.lk/awards.html
[Thu Jul 30 14:21:15.210061 2026] [security2:error] [pid 1045527:tid 1045683] [client 74.248.33.8:46659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amukKzbFEG16qLV_6ZdbcwAAABo"]
[Thu Jul 30 14:21:15.609073 2026] [security2:error] [pid 1045527:tid 1045753] [client 20.52.125.110:3347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/content.php"] [unique_id "amukKzbFEG16qLV_6ZdbfQAAAGA"]
[Thu Jul 30 14:21:15.907096 2026] [security2:error] [pid 1045527:tid 1045740] [client 20.203.148.31:28914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amukKzbFEG16qLV_6ZdbjgAAAFM"]
[Thu Jul 30 14:21:16.450786 2026] [security2:error] [pid 1045527:tid 1045589] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/as.php"] [unique_id "amukLDbFEG16qLV_6ZdbogAAQz0"]
[Thu Jul 30 14:21:16.476756 2026] [security2:error] [pid 1045527:tid 1045694] [client 74.248.33.8:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/file.php"] [unique_id "amukLDbFEG16qLV_6ZdbpwAAACU"]
[Thu Jul 30 14:21:16.531970 2026] [security2:error] [pid 1045527:tid 1045781] [client 66.249.65.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukKzbFEG16qLV_6ZdbkgAAAHw"]
[Thu Jul 30 14:21:16.670700 2026] [security2:error] [pid 1045527:tid 1045755] [client 20.203.148.31:11597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amukLDbFEG16qLV_6ZdbqgAAAGI"]
[Thu Jul 30 14:21:16.807657 2026] [security2:error] [pid 1045527:tid 1045766] [client 20.52.125.110:3633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amukLDbFEG16qLV_6ZdbqwAAAG0"]
[Thu Jul 30 14:21:16.938085 2026] [security2:error] [pid 1045527:tid 1045728] [client 180.243.59.178:59698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukLDbFEG16qLV_6ZdbsQAAAEc"]
[Thu Jul 30 14:21:16.938223 2026] [security2:error] [pid 1045527:tid 1045728] [client 180.243.59.178:59698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukLDbFEG16qLV_6ZdbsQAAAEc"]
[Thu Jul 30 14:21:17.265006 2026] [security2:error] [pid 1045527:tid 1045585] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/k.php"] [unique_id "amukLTbFEG16qLV_6ZdbuAAARTk"]
[Thu Jul 30 14:21:17.551443 2026] [security2:error] [pid 1045527:tid 1045573] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/system_log.php"] [unique_id "amukLTbFEG16qLV_6ZdbxAAAdS0"]
[Thu Jul 30 14:21:17.617458 2026] [security2:error] [pid 1045527:tid 1045747] [client 20.52.125.110:3613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amukLTbFEG16qLV_6ZdbxwAAAFo"]
[Thu Jul 30 14:21:17.700325 2026] [security2:error] [pid 1045527:tid 1045708] [client 74.248.33.8:50640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/user/index.php"] [unique_id "amukLTbFEG16qLV_6ZdbywAAADM"]
[Thu Jul 30 14:21:17.832672 2026] [security2:error] [pid 1045527:tid 1045571] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/x.php"] [unique_id "amukLTbFEG16qLV_6ZdbzAAAXis"]
[Thu Jul 30 14:21:17.965876 2026] [security2:error] [pid 1045527:tid 1045734] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amukLTbFEG16qLV_6ZdbuQAATTw"]
[Thu Jul 30 14:21:18.099517 2026] [security2:error] [pid 1045527:tid 1045680] [client 20.52.125.110:3647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amukLjbFEG16qLV_6Zdb2AAAABc"]
[Thu Jul 30 14:21:18.176170 2026] [security2:error] [pid 1045527:tid 1045574] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amukLjbFEG16qLV_6Zdb2QAASC4"]
[Thu Jul 30 14:21:18.531423 2026] [security2:error] [pid 1045527:tid 1045610] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/hosty.php"] [unique_id "amukLjbFEG16qLV_6Zdb7gAAeFI"]
[Thu Jul 30 14:21:18.773852 2026] [security2:error] [pid 1045527:tid 1045772] [client 74.248.33.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kayomanis.com"] [uri "/index.php"] [unique_id "amukLjbFEG16qLV_6Zdb6AAAAHM"]
[Thu Jul 30 14:21:18.809895 2026] [security2:error] [pid 1045527:tid 1045606] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/test1.php"] [unique_id "amukLjbFEG16qLV_6Zdb9wAARE4"]
[Thu Jul 30 14:21:18.895902 2026] [security2:error] [pid 1045527:tid 1045608] [remote 167.71.218.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baitultateeqmoverscompany.com"] [uri "/wp/xmlrpc.php"] [unique_id "amukLjbFEG16qLV_6Zdb-QAAPVA"]
[Thu Jul 30 14:21:18.896085 2026] [security2:error] [pid 1045527:tid 1045718] [client 167.71.218.184:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "baitultateeqmoverscompany.com"] [uri "/wp/xmlrpc.php"] [unique_id "amukLjbFEG16qLV_6Zdb-QAAPVA"]
[Thu Jul 30 14:21:19.103868 2026] [security2:error] [pid 1045527:tid 1045682] [client 74.248.33.8:21571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amukLzbFEG16qLV_6ZdcAwAAABk"]
[Thu Jul 30 14:21:19.125631 2026] [security2:error] [pid 1045527:tid 1045618] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/zwso.php"] [unique_id "amukLzbFEG16qLV_6ZdcBAAAUlo"]
[Thu Jul 30 14:21:19.407370 2026] [security2:error] [pid 1045527:tid 1045627] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/fpwch.php"] [unique_id "amukLzbFEG16qLV_6ZdcCAAAXWM"]
[Thu Jul 30 14:21:19.412726 2026] [security2:error] [pid 1045527:tid 1045634] [remote 57.141.18.73:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amukLzbFEG16qLV_6ZdcBQAARWo"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,linen,lycra,polyester,silicon,steel,titanium,plastic,cotton,nylon,wood,denim&min_price=300&orderby=date&status=instock&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 14:21:19.608643 2026] [security2:error] [pid 1045527:tid 1045724] [client 20.203.148.31:28925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amukLzbFEG16qLV_6ZdcDwAAAEM"]
[Thu Jul 30 14:21:19.660738 2026] [security2:error] [pid 1045527:tid 1045727] [client 20.52.125.110:3620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amukLzbFEG16qLV_6ZdcEgAAAEY"]
[Thu Jul 30 14:21:19.828453 2026] [security2:error] [pid 1045527:tid 1045696] [client 74.248.33.8:16803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/index/function.php"] [unique_id "amukLzbFEG16qLV_6ZdcFgAAACc"]
[Thu Jul 30 14:21:19.952822 2026] [security2:error] [pid 1045527:tid 1045620] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-blog-header.php"] [unique_id "amukLzbFEG16qLV_6ZdcGAAAM1w"]
[Thu Jul 30 14:21:20.057181 2026] [security2:error] [pid 1045527:tid 1045641] [remote 57.141.18.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amukLzbFEG16qLV_6ZdcFQAAY3E"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,linen,lycra,polyester,silicon,steel,titanium,plastic,cotton,nylon,wood,denim&min_price=300&orderby=date&status=instock&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 14:21:20.231770 2026] [security2:error] [pid 1045527:tid 1045628] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/about/function.php"] [unique_id "amukMDbFEG16qLV_6ZdcIgAAB2Q"]
[Thu Jul 30 14:21:20.385122 2026] [security2:error] [pid 1045527:tid 1045701] [client 20.52.125.110:3353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amukMDbFEG16qLV_6ZdcIwAAACw"]
[Thu Jul 30 14:21:20.478962 2026] [autoindex:error] [pid 1045527:tid 1045729] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:20.510174 2026] [security2:error] [pid 1045527:tid 1045635] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/function/function.php"] [unique_id "amukMDbFEG16qLV_6ZdcKAAAQGs"]
[Thu Jul 30 14:21:20.654536 2026] [autoindex:error] [pid 1045527:tid 1045768] [client 74.248.33.8:0] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_2f97271e/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:20.789210 2026] [security2:error] [pid 1045527:tid 1045637] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-signin.php"] [unique_id "amukMDbFEG16qLV_6ZdcOAAAc20"]
[Thu Jul 30 14:21:21.072400 2026] [security2:error] [pid 1045527:tid 1045636] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/f35.php"] [unique_id "amukMTbFEG16qLV_6ZdcPQAAIGw"]
[Thu Jul 30 14:21:21.201649 2026] [security2:error] [pid 1045527:tid 1045670] [client 20.52.125.110:3346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amukMTbFEG16qLV_6ZdcRAAAAA0"]
[Thu Jul 30 14:21:21.330192 2026] [security2:error] [pid 1045527:tid 1045639] [remote 74.7.227.39:52948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amukMTbFEG16qLV_6ZdcRQAAcG8"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:21:21.342534 2026] [security2:error] [pid 1045527:tid 1045644] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/gg.php"] [unique_id "amukMTbFEG16qLV_6ZdcRgAAA3Q"]
[Thu Jul 30 14:21:21.685786 2026] [security2:error] [pid 1045527:tid 1045647] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/class.php"] [unique_id "amukMTbFEG16qLV_6ZdcTQAAaXc"]
[Thu Jul 30 14:21:21.768245 2026] [security2:error] [pid 1045527:tid 1045751] [client 20.203.148.31:31737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amukMTbFEG16qLV_6ZdcUQAAAF4"]
[Thu Jul 30 14:21:21.959885 2026] [security2:error] [pid 1045527:tid 1045652] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/flower.php"] [unique_id "amukMTbFEG16qLV_6ZdcUgAAJ3w"]
[Thu Jul 30 14:21:22.151601 2026] [security2:error] [pid 1045527:tid 1045715] [client 20.52.125.110:3335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/Requests/about.php"] [unique_id "amukMjbFEG16qLV_6ZdcWwAAADo"]
[Thu Jul 30 14:21:22.236313 2026] [security2:error] [pid 1045527:tid 1045648] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/motu.php"] [unique_id "amukMjbFEG16qLV_6ZdcXwAATXg"]
[Thu Jul 30 14:21:22.565385 2026] [security2:error] [pid 1045527:tid 1045699] [client 172.237.109.114:20487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukMjbFEG16qLV_6ZdcUwAAACo"]
[Thu Jul 30 14:21:22.583376 2026] [security2:error] [pid 1045527:tid 1045529] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/404.php"] [unique_id "amukMjbFEG16qLV_6ZdcYgAAQgE"]
[Thu Jul 30 14:21:22.687083 2026] [security2:error] [pid 1045527:tid 1045740] [client 172.237.109.114:26908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukMjbFEG16qLV_6ZdcWQAAAFM"]
[Thu Jul 30 14:21:22.854970 2026] [security2:error] [pid 1045527:tid 1045539] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/lite.php"] [unique_id "amukMjbFEG16qLV_6ZdcbAAAfAs"]
[Thu Jul 30 14:21:23.132306 2026] [security2:error] [pid 1045527:tid 1045548] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/lock360.php"] [unique_id "amukMzbFEG16qLV_6ZdccAAAAhQ"]
[Thu Jul 30 14:21:23.407712 2026] [security2:error] [pid 1045527:tid 1045531] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "amukMzbFEG16qLV_6ZdceAAANwM"]
[Thu Jul 30 14:21:23.584689 2026] [security2:error] [pid 1045527:tid 1045709] [client 20.52.125.110:3338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amukMzbFEG16qLV_6ZdceQAAADQ"]
[Thu Jul 30 14:21:23.680349 2026] [security2:error] [pid 1045527:tid 1045535] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-links-opml.php"] [unique_id "amukMzbFEG16qLV_6ZdcgQAAEAc"]
[Thu Jul 30 14:21:23.954511 2026] [security2:error] [pid 1045527:tid 1045537] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.alf.php"] [unique_id "amukMzbFEG16qLV_6ZdciAAAOQk"]
[Thu Jul 30 14:21:23.974588 2026] [security2:error] [pid 1045527:tid 1045752] [client 172.237.109.114:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/inizio.php"] [unique_id "amukMzbFEG16qLV_6ZdciQAAAF8"], referer: http://alseermarine.com:80/inizio.php
[Thu Jul 30 14:21:24.268018 2026] [security2:error] [pid 1045527:tid 1045674] [client 20.203.148.31:30552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amukNDbFEG16qLV_6ZdckAAAABE"]
[Thu Jul 30 14:21:24.305298 2026] [security2:error] [pid 1045527:tid 1045538] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/ws.php"] [unique_id "amukNDbFEG16qLV_6ZdckQAAWgo"]
[Thu Jul 30 14:21:24.579743 2026] [security2:error] [pid 1045527:tid 1045655] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/css/index.php"] [unique_id "amukNDbFEG16qLV_6ZdcmAAADn8"]
[Thu Jul 30 14:21:24.853932 2026] [security2:error] [pid 1045527:tid 1045653] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/ioxi-o.php"] [unique_id "amukNDbFEG16qLV_6ZdcogAAF30"]
[Thu Jul 30 14:21:25.126998 2026] [security2:error] [pid 1045527:tid 1045530] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/ws54.php"] [unique_id "amukNTbFEG16qLV_6ZdcpAAAQAI"]
[Thu Jul 30 14:21:25.149184 2026] [security2:error] [pid 1045527:tid 1045550] [remote 57.141.0.58:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/380060334/feed/rss2/"] [unique_id "amukNTbFEG16qLV_6ZdcpQAAUxY"]
[Thu Jul 30 14:21:25.401427 2026] [security2:error] [pid 1045527:tid 1045566] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/155.php"] [unique_id "amukNTbFEG16qLV_6ZdcsQAABiY"]
[Thu Jul 30 14:21:25.536086 2026] [security2:error] [pid 1045527:tid 1045724] [client 20.52.125.110:3623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amukNTbFEG16qLV_6ZdcsgAAAEM"]
[Thu Jul 30 14:21:25.671669 2026] [security2:error] [pid 1045527:tid 1045569] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-includes/min.php"] [unique_id "amukNTbFEG16qLV_6ZdctgAARCk"]
[Thu Jul 30 14:21:25.846158 2026] [core:notice] [pid 1045527:tid 1045707] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:26.412889 2026] [security2:error] [pid 1045527:tid 1045776] [client 20.52.125.110:3622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amukNjbFEG16qLV_6ZdcxgAAAHc"]
[Thu Jul 30 14:21:27.017197 2026] [security2:error] [pid 1045527:tid 1045684] [client 20.52.125.110:3339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/banners/about.php"] [unique_id "amukNzbFEG16qLV_6Zdc3AAAABs"]
[Thu Jul 30 14:21:27.263809 2026] [security2:error] [pid 1045527:tid 1045664] [client 20.203.148.31:11630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amukNzbFEG16qLV_6Zdc4QAAAAc"]
[Thu Jul 30 14:21:27.405893 2026] [security2:error] [pid 1045527:tid 1045589] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/xmlrpc.php"] [unique_id "amukNzbFEG16qLV_6Zdc3QAAWD0"]
[Thu Jul 30 14:21:27.425062 2026] [security2:error] [pid 1045527:tid 1045729] [client 180.243.59.178:60219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukNzbFEG16qLV_6Zdc5wAAAEg"]
[Thu Jul 30 14:21:27.425152 2026] [security2:error] [pid 1045527:tid 1045729] [client 180.243.59.178:60219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukNzbFEG16qLV_6Zdc5wAAAEg"]
[Thu Jul 30 14:21:27.670350 2026] [security2:error] [pid 1045527:tid 1045757] [client 20.52.125.110:3531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/about.php"] [unique_id "amukNzbFEG16qLV_6Zdc8AAAAGQ"]
[Thu Jul 30 14:21:27.685968 2026] [security2:error] [pid 1045527:tid 1045575] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/tinyfilemanager.php"] [unique_id "amukNzbFEG16qLV_6Zdc8QAAVC8"]
[Thu Jul 30 14:21:28.028571 2026] [security2:error] [pid 1045527:tid 1045753] [client 74.7.228.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "investigations.worldofwhiskers.com"] [uri "/index.php"] [unique_id "amukNjbFEG16qLV_6Zdc0AAAYCI"], referer: https://www.investigations.worldofwhiskers.com/robots.txt
[Thu Jul 30 14:21:28.253823 2026] [security2:error] [pid 1045527:tid 1045578] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/hplfuns.php"] [unique_id "amukODbFEG16qLV_6ZddAAAAFTI"]
[Thu Jul 30 14:21:28.531333 2026] [security2:error] [pid 1045527:tid 1045742] [client 74.7.175.158:44176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.xyh.udi.temporary.site"] [uri "/index.php"] [unique_id "amukNzbFEG16qLV_6Zdc-AAAVTA"]
[Thu Jul 30 14:21:28.532118 2026] [security2:error] [pid 1045527:tid 1045710] [client 20.52.125.110:3359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/.well-known/about.php"] [unique_id "amukODbFEG16qLV_6ZddCAAAADU"]
[Thu Jul 30 14:21:28.575041 2026] [security2:error] [pid 1045527:tid 1045587] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/bthil.php"] [unique_id "amukODbFEG16qLV_6ZddCwAAajs"]
[Thu Jul 30 14:21:28.847410 2026] [security2:error] [pid 1045527:tid 1045596] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/cv.php"] [unique_id "amukODbFEG16qLV_6ZddFAAAQUQ"]
[Thu Jul 30 14:21:29.096037 2026] [security2:error] [pid 1045527:tid 1045765] [client 20.52.125.110:3348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/Text/about.php"] [unique_id "amukOTbFEG16qLV_6ZddHgAAAGw"]
[Thu Jul 30 14:21:29.182234 2026] [security2:error] [pid 1045527:tid 1045601] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/sf.php"] [unique_id "amukOTbFEG16qLV_6ZddHwAAK0k"]
[Thu Jul 30 14:21:29.452870 2026] [security2:error] [pid 1045527:tid 1045595] [remote 57.141.0.13:38808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3981330618/feed/rss2/"] [unique_id "amukOTbFEG16qLV_6ZddIAAAE0M"]
[Thu Jul 30 14:21:29.457930 2026] [security2:error] [pid 1045527:tid 1045599] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-content.php"] [unique_id "amukOTbFEG16qLV_6ZddJgAAI0c"]
[Thu Jul 30 14:21:29.756751 2026] [security2:error] [pid 1045527:tid 1045761] [client 20.203.148.31:30529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amukOTbFEG16qLV_6ZddLQAAAGg"]
[Thu Jul 30 14:21:30.136481 2026] [security2:error] [pid 1045527:tid 1045616] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/txets.php"] [unique_id "amukOjbFEG16qLV_6ZddOwAAZFg"]
[Thu Jul 30 14:21:30.465562 2026] [security2:error] [pid 1045527:tid 1045618] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wk/index.php"] [unique_id "amukOjbFEG16qLV_6ZddPwAAAVo"]
[Thu Jul 30 14:21:30.529103 2026] [security2:error] [pid 1045527:tid 1045741] [client 20.203.148.31:31008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amukOjbFEG16qLV_6ZddQAAAAFQ"]
[Thu Jul 30 14:21:30.608401 2026] [core:notice] [pid 1045527:tid 1045777] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:30.628442 2026] [security2:error] [pid 1045527:tid 1045758] [client 20.52.125.110:3331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/ID3/about.php"] [unique_id "amukOjbFEG16qLV_6ZddSgAAAGU"]
[Thu Jul 30 14:21:30.792405 2026] [security2:error] [pid 1045527:tid 1045634] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/222.php"] [unique_id "amukOjbFEG16qLV_6ZddTAAAJGo"]
[Thu Jul 30 14:21:31.063749 2026] [security2:error] [pid 1045527:tid 1045632] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/new.php"] [unique_id "amukOzbFEG16qLV_6ZddVgAANWg"]
[Thu Jul 30 14:21:31.155830 2026] [security2:error] [pid 1045527:tid 1045716] [client 20.52.125.110:3388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/img/about.php"] [unique_id "amukOzbFEG16qLV_6ZddWgAAADs"]
[Thu Jul 30 14:21:31.226499 2026] [core:notice] [pid 1045527:tid 1045750] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:31.358683 2026] [security2:error] [pid 1045527:tid 1045641] [remote 74.7.243.224:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amukOzbFEG16qLV_6ZddYAAAZ3E"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:21:31.369429 2026] [security2:error] [pid 1045527:tid 1045631] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amukOzbFEG16qLV_6ZddYQAAXmc"]
[Thu Jul 30 14:21:31.586678 2026] [core:notice] [pid 1045527:tid 1045773] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:31.604350 2026] [security2:error] [pid 1045527:tid 1045769] [client 20.203.148.31:30532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amukOzbFEG16qLV_6ZddagAAAHA"]
[Thu Jul 30 14:21:31.655095 2026] [security2:error] [pid 1045527:tid 1045715] [client 20.52.125.110:3333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/languages/about.php"] [unique_id "amukOzbFEG16qLV_6ZddawAAADo"]
[Thu Jul 30 14:21:31.693851 2026] [security2:error] [pid 1045527:tid 1045623] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.trash7206/index.php"] [unique_id "amukOzbFEG16qLV_6ZddbAAAe18"]
[Thu Jul 30 14:21:31.797084 2026] [security2:error] [pid 1045527:tid 1045685] [client 114.119.134.212:30067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/robots.txt"] [unique_id "amukOzbFEG16qLV_6ZddcgAAABw"], referer: http://lark-shop.com/robots.txt
[Thu Jul 30 14:21:31.798912 2026] [security2:error] [pid 1045527:tid 1045621] [remote 40.77.167.151:34547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/nos-ressources/rapport/aboutf.php"] [unique_id "amukOzbFEG16qLV_6ZddcQAAbl0"]
[Thu Jul 30 14:21:31.962588 2026] [security2:error] [pid 1045527:tid 1045638] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amukOzbFEG16qLV_6ZdddAAAEm4"]
[Thu Jul 30 14:21:31.962923 2026] [core:notice] [pid 1045527:tid 1045733] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:32.235290 2026] [security2:error] [pid 1045527:tid 1045640] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/error.php"] [unique_id "amukPDbFEG16qLV_6ZddewAAbXA"]
[Thu Jul 30 14:21:32.330406 2026] [security2:error] [pid 1045527:tid 1045781] [client 20.52.125.110:3563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/customize/about.php"] [unique_id "amukPDbFEG16qLV_6ZddfAAAAHw"]
[Thu Jul 30 14:21:32.337672 2026] [core:notice] [pid 1045527:tid 1045681] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:32.572338 2026] [security2:error] [pid 1045527:tid 1045639] [remote 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/a7.php"] [unique_id "amukPDbFEG16qLV_6ZddhAAAeG8"]
[Thu Jul 30 14:21:32.730201 2026] [core:notice] [pid 1045527:tid 1045724] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:33.126938 2026] [core:notice] [pid 1045527:tid 1045710] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:33.170776 2026] [security2:error] [pid 1045527:tid 1045782] [client 20.52.125.110:3332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amukPTbFEG16qLV_6ZddlQAAAH0"]
[Thu Jul 30 14:21:33.527848 2026] [core:notice] [pid 1045527:tid 1045754] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:33.847824 2026] [security2:error] [pid 1045527:tid 1045773] [client 20.52.125.110:3638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/widgets/about.php"] [unique_id "amukPTbFEG16qLV_6ZddogAAAHQ"]
[Thu Jul 30 14:21:33.982009 2026] [core:notice] [pid 1045527:tid 1045780] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:34.346839 2026] [security2:error] [pid 1045527:tid 1045539] [remote 57.141.0.1:37534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amukPjbFEG16qLV_6ZddtAAAHAs"]
[Thu Jul 30 14:21:34.412761 2026] [core:notice] [pid 1045527:tid 1045695] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:34.763768 2026] [security2:error] [pid 1045527:tid 1045764] [client 20.203.148.31:32650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amukPjbFEG16qLV_6ZddwgAAAGs"]
[Thu Jul 30 14:21:34.838535 2026] [security2:error] [pid 1045527:tid 1045781] [client 20.52.125.110:3591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/IXR/about.php"] [unique_id "amukPjbFEG16qLV_6ZddwwAAAHw"]
[Thu Jul 30 14:21:34.948603 2026] [security2:error] [pid 1045527:tid 1045531] [remote 216.73.217.142:43216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amukPjbFEG16qLV_6ZddyAAAHQM"]
[Thu Jul 30 14:21:35.483726 2026] [security2:error] [pid 1045527:tid 1045671] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amukPjbFEG16qLV_6ZddxAAADkY"]
[Thu Jul 30 14:21:35.486683 2026] [security2:error] [pid 1045527:tid 1045677] [client 20.203.148.31:11504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amukPzbFEG16qLV_6Zdd1gAAABQ"]
[Thu Jul 30 14:21:35.486760 2026] [security2:error] [pid 1045527:tid 1045742] [client 20.52.125.110:3366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/js/about.php"] [unique_id "amukPzbFEG16qLV_6Zdd1QAAAFU"]
[Thu Jul 30 14:21:35.611817 2026] [security2:error] [pid 1045527:tid 1045776] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amukPzbFEG16qLV_6Zdd1wAAAHc"]
[Thu Jul 30 14:21:35.611943 2026] [security2:error] [pid 1045527:tid 1045776] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amukPzbFEG16qLV_6Zdd1wAAAHc"]
[Thu Jul 30 14:21:35.713573 2026] [security2:error] [pid 1045527:tid 1045693] [client 172.237.109.114:9192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukPzbFEG16qLV_6ZddywAAACQ"]
[Thu Jul 30 14:21:35.920525 2026] [security2:error] [pid 1045527:tid 1045747] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amukPzbFEG16qLV_6Zdd5QAAAFo"]
[Thu Jul 30 14:21:35.920631 2026] [security2:error] [pid 1045527:tid 1045747] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amukPzbFEG16qLV_6Zdd5QAAAFo"]
[Thu Jul 30 14:21:36.023295 2026] [security2:error] [pid 1045527:tid 1045722] [client 20.52.125.110:3345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amukQDbFEG16qLV_6Zdd6QAAAEE"]
[Thu Jul 30 14:21:36.242462 2026] [security2:error] [pid 1045527:tid 1045694] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/3PJcpMFsD8B.php"] [unique_id "amukQDbFEG16qLV_6Zdd8QAAACU"]
[Thu Jul 30 14:21:36.242606 2026] [security2:error] [pid 1045527:tid 1045694] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/3PJcpMFsD8B.php"] [unique_id "amukQDbFEG16qLV_6Zdd8QAAACU"]
[Thu Jul 30 14:21:36.433991 2026] [security2:error] [pid 1045527:tid 1045561] [remote 57.141.0.37:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amukQDbFEG16qLV_6Zdd8wAAEyE"]
[Thu Jul 30 14:21:36.495759 2026] [security2:error] [pid 1045527:tid 1045699] [client 20.52.125.110:3342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/pomo/about.php"] [unique_id "amukQDbFEG16qLV_6Zdd9AAAACo"]
[Thu Jul 30 14:21:36.545714 2026] [security2:error] [pid 1045527:tid 1045755] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/err.php"] [unique_id "amukQDbFEG16qLV_6Zdd-AAAAGI"]
[Thu Jul 30 14:21:36.545825 2026] [security2:error] [pid 1045527:tid 1045755] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/err.php"] [unique_id "amukQDbFEG16qLV_6Zdd-AAAAGI"]
[Thu Jul 30 14:21:36.626639 2026] [security2:error] [pid 1045527:tid 1045678] [client 119.73.97.132:30055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amukQDbFEG16qLV_6Zdd8gAAFRY"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 14:21:36.833427 2026] [security2:error] [pid 1045527:tid 1045658] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/img.php"] [unique_id "amukQDbFEG16qLV_6ZdeAAAAAAE"]
[Thu Jul 30 14:21:36.833537 2026] [security2:error] [pid 1045527:tid 1045658] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/img.php"] [unique_id "amukQDbFEG16qLV_6ZdeAAAAAAE"]
[Thu Jul 30 14:21:37.066625 2026] [security2:error] [pid 1045527:tid 1045552] [remote 165.22.136.47:50958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.136.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.zjp.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amukQDbFEG16qLV_6Zdd_wAAcBg"]
[Thu Jul 30 14:21:37.134442 2026] [security2:error] [pid 1045527:tid 1045771] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/aa.php"] [unique_id "amukQTbFEG16qLV_6ZdeCAAAAHI"]
[Thu Jul 30 14:21:37.134562 2026] [security2:error] [pid 1045527:tid 1045771] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/aa.php"] [unique_id "amukQTbFEG16qLV_6ZdeCAAAAHI"]
[Thu Jul 30 14:21:37.324104 2026] [security2:error] [pid 1045527:tid 1045741] [client 20.52.125.110:3585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amukQTbFEG16qLV_6ZdeEAAAAFQ"]
[Thu Jul 30 14:21:37.443419 2026] [security2:error] [pid 1045527:tid 1045671] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/av.php"] [unique_id "amukQTbFEG16qLV_6ZdeEQAAAA4"]
[Thu Jul 30 14:21:37.443574 2026] [security2:error] [pid 1045527:tid 1045671] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/av.php"] [unique_id "amukQTbFEG16qLV_6ZdeEQAAAA4"]
[Thu Jul 30 14:21:37.747313 2026] [security2:error] [pid 1045527:tid 1045751] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/xa.php"] [unique_id "amukQTbFEG16qLV_6ZdeGgAAAF4"]
[Thu Jul 30 14:21:37.747409 2026] [security2:error] [pid 1045527:tid 1045751] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/xa.php"] [unique_id "amukQTbFEG16qLV_6ZdeGgAAAF4"]
[Thu Jul 30 14:21:37.878428 2026] [security2:error] [pid 1045527:tid 1045762] [client 20.52.125.110:3373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/updraft/about.php"] [unique_id "amukQTbFEG16qLV_6ZdeHgAAAGk"]
[Thu Jul 30 14:21:38.047321 2026] [security2:error] [pid 1045527:tid 1045747] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/media.php"] [unique_id "amukQjbFEG16qLV_6ZdeIgAAAFo"]
[Thu Jul 30 14:21:38.047418 2026] [security2:error] [pid 1045527:tid 1045747] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/media.php"] [unique_id "amukQjbFEG16qLV_6ZdeIgAAAFo"]
[Thu Jul 30 14:21:38.118231 2026] [security2:error] [pid 1045527:tid 1045721] [client 74.7.228.18:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.embassyofitalyislamabad.vip"] [uri "/index.php"] [unique_id "amukQDbFEG16qLV_6ZdeAQAAQCk"]
[Thu Jul 30 14:21:38.353329 2026] [security2:error] [pid 1045527:tid 1045711] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/images.php"] [unique_id "amukQjbFEG16qLV_6ZdeLAAAADY"]
[Thu Jul 30 14:21:38.353466 2026] [security2:error] [pid 1045527:tid 1045711] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/images.php"] [unique_id "amukQjbFEG16qLV_6ZdeLAAAADY"]
[Thu Jul 30 14:21:38.415520 2026] [security2:error] [pid 1045527:tid 1045717] [client 20.52.125.110:3604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amukQjbFEG16qLV_6ZdeLQAAADw"]
[Thu Jul 30 14:21:38.454201 2026] [security2:error] [pid 1045527:tid 1045680] [client 180.243.59.178:60757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukQjbFEG16qLV_6ZdeLgAAABc"]
[Thu Jul 30 14:21:38.454340 2026] [security2:error] [pid 1045527:tid 1045680] [client 180.243.59.178:60757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukQjbFEG16qLV_6ZdeLgAAABc"]
[Thu Jul 30 14:21:38.657802 2026] [security2:error] [pid 1045527:tid 1045676] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/gecko.php"] [unique_id "amukQjbFEG16qLV_6ZdeNQAAABM"]
[Thu Jul 30 14:21:38.657904 2026] [security2:error] [pid 1045527:tid 1045676] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/gecko.php"] [unique_id "amukQjbFEG16qLV_6ZdeNQAAABM"]
[Thu Jul 30 14:21:38.777363 2026] [core:notice] [pid 1045527:tid 1045756] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:38.897842 2026] [security2:error] [pid 1045527:tid 1045719] [client 20.52.125.110:3350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/themes/about.php"] [unique_id "amukQjbFEG16qLV_6ZdePgAAAD4"]
[Thu Jul 30 14:21:38.977765 2026] [security2:error] [pid 1045527:tid 1045740] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/82.php"] [unique_id "amukQjbFEG16qLV_6ZdePwAAAFM"]
[Thu Jul 30 14:21:38.977915 2026] [security2:error] [pid 1045527:tid 1045740] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/82.php"] [unique_id "amukQjbFEG16qLV_6ZdePwAAAFM"]
[Thu Jul 30 14:21:39.303944 2026] [security2:error] [pid 1045527:tid 1045753] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/xstelth.php"] [unique_id "amukQzbFEG16qLV_6ZdeSAAAAGA"]
[Thu Jul 30 14:21:39.304059 2026] [security2:error] [pid 1045527:tid 1045753] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/xstelth.php"] [unique_id "amukQzbFEG16qLV_6ZdeSAAAAGA"]
[Thu Jul 30 14:21:39.428858 2026] [security2:error] [pid 1045527:tid 1045584] [remote 216.73.217.142:43216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amukQzbFEG16qLV_6ZdeTgAAQzg"]
[Thu Jul 30 14:21:39.498849 2026] [security2:error] [pid 1045527:tid 1045712] [client 20.52.125.110:3646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/includes/about.php"] [unique_id "amukQzbFEG16qLV_6ZdeTwAAADc"]
[Thu Jul 30 14:21:39.566337 2026] [security2:error] [pid 1045527:tid 1045568] [remote 57.141.0.8:28946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amukQzbFEG16qLV_6ZdeUgAAcCg"]
[Thu Jul 30 14:21:39.616994 2026] [security2:error] [pid 1045527:tid 1045682] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/xp.php"] [unique_id "amukQzbFEG16qLV_6ZdeUwAAABk"]
[Thu Jul 30 14:21:39.617124 2026] [security2:error] [pid 1045527:tid 1045682] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/xp.php"] [unique_id "amukQzbFEG16qLV_6ZdeUwAAABk"]
[Thu Jul 30 14:21:39.911873 2026] [security2:error] [pid 1045527:tid 1045774] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/admin.php"] [unique_id "amukQzbFEG16qLV_6ZdeXAAAAHU"]
[Thu Jul 30 14:21:39.911995 2026] [security2:error] [pid 1045527:tid 1045774] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/admin.php"] [unique_id "amukQzbFEG16qLV_6ZdeXAAAAHU"]
[Thu Jul 30 14:21:40.037876 2026] [security2:error] [pid 1045527:tid 1045759] [client 74.7.175.134:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.kevinderarslanian.com"] [uri "/index.php"] [unique_id "amukQjbFEG16qLV_6ZdeMQAAAGY"]
[Thu Jul 30 14:21:40.038848 2026] [security2:error] [pid 1045527:tid 1045736] [client 74.7.175.134:55658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.kevinderarslanian.com"] [uri "/robots.txt"] [unique_id "amukQjbFEG16qLV_6ZdeLwAAT0w"]
[Thu Jul 30 14:21:40.224196 2026] [security2:error] [pid 1045527:tid 1045760] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/adminner.php"] [unique_id "amukRDbFEG16qLV_6ZdeYQAAAGc"]
[Thu Jul 30 14:21:40.224314 2026] [security2:error] [pid 1045527:tid 1045760] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/adminner.php"] [unique_id "amukRDbFEG16qLV_6ZdeYQAAAGc"]
[Thu Jul 30 14:21:40.226529 2026] [security2:error] [pid 1045527:tid 1045673] [client 20.52.125.110:3628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/images/about.php"] [unique_id "amukRDbFEG16qLV_6ZdeYgAAABA"]
[Thu Jul 30 14:21:40.545119 2026] [security2:error] [pid 1045527:tid 1045761] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/a.php"] [unique_id "amukRDbFEG16qLV_6ZdebQAAAGg"]
[Thu Jul 30 14:21:40.545243 2026] [security2:error] [pid 1045527:tid 1045761] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/a.php"] [unique_id "amukRDbFEG16qLV_6ZdebQAAAGg"]
[Thu Jul 30 14:21:40.825074 2026] [security2:error] [pid 1045527:tid 1045746] [client 20.52.125.110:3621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amukRDbFEG16qLV_6ZdecQAAAFk"]
[Thu Jul 30 14:21:40.860339 2026] [security2:error] [pid 1045527:tid 1045714] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/k.php"] [unique_id "amukRDbFEG16qLV_6ZdecgAAADk"]
[Thu Jul 30 14:21:40.860429 2026] [security2:error] [pid 1045527:tid 1045714] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/k.php"] [unique_id "amukRDbFEG16qLV_6ZdecgAAADk"]
[Thu Jul 30 14:21:40.995760 2026] [security2:error] [pid 1045527:tid 1045587] [remote 57.141.0.35:20946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amukRDbFEG16qLV_6ZdefAAAFzs"]
[Thu Jul 30 14:21:41.166543 2026] [security2:error] [pid 1045527:tid 1045740] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/222.php"] [unique_id "amukRTbFEG16qLV_6ZdefQAAAFM"]
[Thu Jul 30 14:21:41.166694 2026] [security2:error] [pid 1045527:tid 1045740] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/222.php"] [unique_id "amukRTbFEG16qLV_6ZdefQAAAFM"]
[Thu Jul 30 14:21:41.379808 2026] [security2:error] [pid 1045527:tid 1045777] [client 185.200.116.219:41068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amukRTbFEG16qLV_6ZdehAAAAHg"]
[Thu Jul 30 14:21:41.379898 2026] [security2:error] [pid 1045527:tid 1045777] [client 185.200.116.219:41068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amukRTbFEG16qLV_6ZdehAAAAHg"]
[Thu Jul 30 14:21:41.397832 2026] [security2:error] [pid 1045527:tid 1045781] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amukRTbFEG16qLV_6ZdehQAAAHw"]
[Thu Jul 30 14:21:41.450389 2026] [security2:error] [pid 1045527:tid 1045725] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/mac.php"] [unique_id "amukRTbFEG16qLV_6ZdeiQAAAEQ"]
[Thu Jul 30 14:21:41.450480 2026] [security2:error] [pid 1045527:tid 1045725] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/mac.php"] [unique_id "amukRTbFEG16qLV_6ZdeiQAAAEQ"]
[Thu Jul 30 14:21:41.628198 2026] [security2:error] [pid 1045527:tid 1045687] [client 20.52.125.110:3357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/images/about.php"] [unique_id "amukRTbFEG16qLV_6ZdeigAAAB4"]
[Thu Jul 30 14:21:42.354699 2026] [security2:error] [pid 1045527:tid 1045742] [client 20.52.125.110:3639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/about.php"] [unique_id "amukRjbFEG16qLV_6ZdelQAAAFU"]
[Thu Jul 30 14:21:43.088445 2026] [security2:error] [pid 1045527:tid 1045673] [client 74.7.241.137:60960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "jjp.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amukRzbFEG16qLV_6ZdepwAAEEM"]
[Thu Jul 30 14:21:43.135887 2026] [security2:error] [pid 1045527:tid 1045704] [client 20.52.125.110:3354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/cgi-bin/about.php"] [unique_id "amukRzbFEG16qLV_6ZdeqwAAAC8"]
[Thu Jul 30 14:21:43.573234 2026] [core:notice] [pid 1045527:tid 1045612] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:43.668506 2026] [autoindex:error] [pid 1045527:tid 1045680] [client 4.225.166.222:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_82d9fe69/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:43.669275 2026] [security2:error] [pid 1045527:tid 1045680] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.appliancerepairservice.one"] [uri "/cgi-sys/403.html"] [unique_id "amukRzbFEG16qLV_6ZdetwAAABc"]
[Thu Jul 30 14:21:43.753877 2026] [security2:error] [pid 1045527:tid 1045717] [client 20.203.148.31:11722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amukRzbFEG16qLV_6ZdeuAAAADw"]
[Thu Jul 30 14:21:43.850630 2026] [autoindex:error] [pid 1045527:tid 1045729] [client 4.225.166.222:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_82d9fe69/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:43.851376 2026] [security2:error] [pid 1045527:tid 1045729] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.appliancerepairservice.one"] [uri "/cgi-sys/403.html"] [unique_id "amukRzbFEG16qLV_6ZdeuQAAAEg"]
[Thu Jul 30 14:21:43.907850 2026] [autoindex:error] [pid 1045527:tid 1045605] [remote 74.7.227.136:54932] AH01276: Cannot serve directory /home2/jjpgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:44.020608 2026] [security2:error] [pid 1045527:tid 1045753] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/ops.php"] [unique_id "amukSDbFEG16qLV_6ZdewQAAAGA"]
[Thu Jul 30 14:21:44.020732 2026] [security2:error] [pid 1045527:tid 1045753] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/ops.php"] [unique_id "amukSDbFEG16qLV_6ZdewQAAAGA"]
[Thu Jul 30 14:21:44.339996 2026] [security2:error] [pid 1045527:tid 1045757] [client 20.52.125.110:3362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/gallery/about.php"] [unique_id "amukSDbFEG16qLV_6ZdexgAAAGQ"]
[Thu Jul 30 14:21:44.343446 2026] [security2:error] [pid 1045527:tid 1045724] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/8.php"] [unique_id "amukSDbFEG16qLV_6ZdexwAAAEM"]
[Thu Jul 30 14:21:44.343562 2026] [security2:error] [pid 1045527:tid 1045724] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/8.php"] [unique_id "amukSDbFEG16qLV_6ZdexwAAAEM"]
[Thu Jul 30 14:21:44.655823 2026] [security2:error] [pid 1045527:tid 1045749] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/FWAZ.php"] [unique_id "amukSDbFEG16qLV_6ZdezgAAAFw"]
[Thu Jul 30 14:21:44.655935 2026] [security2:error] [pid 1045527:tid 1045749] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/FWAZ.php"] [unique_id "amukSDbFEG16qLV_6ZdezgAAAFw"]
[Thu Jul 30 14:21:44.961056 2026] [security2:error] [pid 1045527:tid 1045750] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/biufile.php"] [unique_id "amukSDbFEG16qLV_6Zde1gAAAF0"]
[Thu Jul 30 14:21:44.961167 2026] [security2:error] [pid 1045527:tid 1045750] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/biufile.php"] [unique_id "amukSDbFEG16qLV_6Zde1gAAAF0"]
[Thu Jul 30 14:21:45.059426 2026] [security2:error] [pid 1045527:tid 1045632] [remote 216.73.217.142:14358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukSTbFEG16qLV_6Zde3AAAVWg"]
[Thu Jul 30 14:21:45.153187 2026] [security2:error] [pid 1045527:tid 1045759] [client 172.237.109.114:42121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/l.fcgi"] [unique_id "amukSTbFEG16qLV_6Zde3QAAAGY"]
[Thu Jul 30 14:21:45.255503 2026] [security2:error] [pid 1045527:tid 1045778] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/coffexium.php"] [unique_id "amukSTbFEG16qLV_6Zde3wAAAHk"]
[Thu Jul 30 14:21:45.255620 2026] [security2:error] [pid 1045527:tid 1045778] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/coffexium.php"] [unique_id "amukSTbFEG16qLV_6Zde3wAAAHk"]
[Thu Jul 30 14:21:45.256661 2026] [security2:error] [pid 1045527:tid 1045713] [client 20.52.125.110:3599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/blocks/about.php"] [unique_id "amukSTbFEG16qLV_6Zde4AAAADg"]
[Thu Jul 30 14:21:45.576297 2026] [security2:error] [pid 1045527:tid 1045745] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/simple.php"] [unique_id "amukSTbFEG16qLV_6Zde6wAAAFg"]
[Thu Jul 30 14:21:45.576391 2026] [security2:error] [pid 1045527:tid 1045745] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/simple.php"] [unique_id "amukSTbFEG16qLV_6Zde6wAAAFg"]
[Thu Jul 30 14:21:45.899006 2026] [security2:error] [pid 1045527:tid 1045755] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/fpwch.php"] [unique_id "amukSTbFEG16qLV_6Zde9QAAAGI"]
[Thu Jul 30 14:21:45.899114 2026] [security2:error] [pid 1045527:tid 1045755] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/fpwch.php"] [unique_id "amukSTbFEG16qLV_6Zde9QAAAGI"]
[Thu Jul 30 14:21:46.199557 2026] [security2:error] [pid 1045527:tid 1045764] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/dex.php"] [unique_id "amukSjbFEG16qLV_6Zde_gAAAGs"]
[Thu Jul 30 14:21:46.199697 2026] [security2:error] [pid 1045527:tid 1045764] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/dex.php"] [unique_id "amukSjbFEG16qLV_6Zde_gAAAGs"]
[Thu Jul 30 14:21:46.502535 2026] [security2:error] [pid 1045527:tid 1045726] [client 4.225.166.222:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.appliancerepairservice.one"] [uri "/1.php"] [unique_id "amukSjbFEG16qLV_6ZdfBQAAAEU"]
[Thu Jul 30 14:21:46.502642 2026] [security2:error] [pid 1045527:tid 1045726] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/1.php"] [unique_id "amukSjbFEG16qLV_6ZdfBQAAAEU"]
[Thu Jul 30 14:21:46.502730 2026] [security2:error] [pid 1045527:tid 1045726] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/1.php"] [unique_id "amukSjbFEG16qLV_6ZdfBQAAAEU"]
[Thu Jul 30 14:21:46.671483 2026] [security2:error] [pid 1045527:tid 1045682] [client 20.52.125.110:3607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/css/about.php"] [unique_id "amukSjbFEG16qLV_6ZdfCgAAABk"]
[Thu Jul 30 14:21:47.018953 2026] [security2:error] [pid 1045527:tid 1045627] [remote 212.80.9.235:56166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/wp-login.php"] [unique_id "amukSzbFEG16qLV_6ZdfEAAARGM"]
[Thu Jul 30 14:21:47.205471 2026] [autoindex:error] [pid 1045527:tid 1045771] [client 4.225.166.222:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_82d9fe69/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:47.206406 2026] [security2:error] [pid 1045527:tid 1045771] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.appliancerepairservice.one"] [uri "/cgi-sys/403.html"] [unique_id "amukSzbFEG16qLV_6ZdfGAAAAHI"]
[Thu Jul 30 14:21:47.387953 2026] [security2:error] [pid 1045527:tid 1045705] [client 20.52.125.110:3190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/images/about.php"] [unique_id "amukSzbFEG16qLV_6ZdfGgAAADA"]
[Thu Jul 30 14:21:47.392271 2026] [security2:error] [pid 1045527:tid 1045751] [client 103.82.27.41:64955] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.daralnaseemdxb.com"] [uri "/"] [unique_id "amukSzbFEG16qLV_6ZdfGwAAAF4"]
[Thu Jul 30 14:21:47.432074 2026] [security2:error] [pid 1045527:tid 1045702] [client 20.203.148.31:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amukSzbFEG16qLV_6ZdfIQAAAC0"]
[Thu Jul 30 14:21:47.684641 2026] [security2:error] [pid 1045527:tid 1045750] [client 172.237.109.114:18097] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukSzbFEG16qLV_6ZdfFwAAAF0"]
[Thu Jul 30 14:21:47.727189 2026] [security2:error] [pid 1045527:tid 1045659] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/config.json.php"] [unique_id "amukSzbFEG16qLV_6ZdfLQAAAAI"]
[Thu Jul 30 14:21:47.727340 2026] [security2:error] [pid 1045527:tid 1045659] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/config.json.php"] [unique_id "amukSzbFEG16qLV_6ZdfLQAAAAI"]
[Thu Jul 30 14:21:47.730672 2026] [security2:error] [pid 1045527:tid 1045701] [client 103.82.27.41:64994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.daralnaseemdxb.com"] [uri "/wp-json/batch/v1"] [unique_id "amukSzbFEG16qLV_6ZdfLgAAACw"]
[Thu Jul 30 14:21:48.033566 2026] [security2:error] [pid 1045527:tid 1045740] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/k2.php"] [unique_id "amukTDbFEG16qLV_6ZdfMwAAAFM"]
[Thu Jul 30 14:21:48.033729 2026] [security2:error] [pid 1045527:tid 1045740] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/k2.php"] [unique_id "amukTDbFEG16qLV_6ZdfMwAAAFM"]
[Thu Jul 30 14:21:48.189642 2026] [security2:error] [pid 1045527:tid 1045719] [client 180.243.59.178:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukTDbFEG16qLV_6ZdfOgAAAD4"]
[Thu Jul 30 14:21:48.189786 2026] [security2:error] [pid 1045527:tid 1045719] [client 180.243.59.178:61239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukTDbFEG16qLV_6ZdfOgAAAD4"]
[Thu Jul 30 14:21:48.290797 2026] [security2:error] [pid 1045527:tid 1045729] [client 20.52.125.110:3199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amukTDbFEG16qLV_6ZdfOwAAAEg"]
[Thu Jul 30 14:21:48.329534 2026] [security2:error] [pid 1045527:tid 1045658] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/raw.php"] [unique_id "amukTDbFEG16qLV_6ZdfPAAAAAE"]
[Thu Jul 30 14:21:48.329637 2026] [security2:error] [pid 1045527:tid 1045658] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/raw.php"] [unique_id "amukTDbFEG16qLV_6ZdfPAAAAAE"]
[Thu Jul 30 14:21:48.483133 2026] [security2:error] [pid 1045527:tid 1045687] [client 49.51.38.193:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.38.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amukTDbFEG16qLV_6ZdfQAAAAB4"]
[Thu Jul 30 14:21:48.486866 2026] [security2:error] [pid 1045527:tid 1045717] [client 20.203.148.31:29727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amukTDbFEG16qLV_6ZdfQQAAADw"]
[Thu Jul 30 14:21:48.639579 2026] [security2:error] [pid 1045527:tid 1045677] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/wp.php"] [unique_id "amukTDbFEG16qLV_6ZdfRQAAABQ"]
[Thu Jul 30 14:21:48.639680 2026] [security2:error] [pid 1045527:tid 1045677] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/wp.php"] [unique_id "amukTDbFEG16qLV_6ZdfRQAAABQ"]
[Thu Jul 30 14:21:48.947402 2026] [security2:error] [pid 1045527:tid 1045783] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/fffm.php"] [unique_id "amukTDbFEG16qLV_6ZdfSwAAAH4"]
[Thu Jul 30 14:21:48.947519 2026] [security2:error] [pid 1045527:tid 1045783] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/fffm.php"] [unique_id "amukTDbFEG16qLV_6ZdfSwAAAH4"]
[Thu Jul 30 14:21:48.973323 2026] [security2:error] [pid 1045527:tid 1045672] [client 20.52.125.110:3183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amukTDbFEG16qLV_6ZdfTAAAAA8"]
[Thu Jul 30 14:21:49.264524 2026] [security2:error] [pid 1045527:tid 1045747] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/111.php"] [unique_id "amukTTbFEG16qLV_6ZdfVwAAAFo"]
[Thu Jul 30 14:21:49.264625 2026] [security2:error] [pid 1045527:tid 1045747] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/111.php"] [unique_id "amukTTbFEG16qLV_6ZdfVwAAAFo"]
[Thu Jul 30 14:21:49.410963 2026] [security2:error] [pid 1045527:tid 1045710] [client 20.203.148.31:47383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amukTTbFEG16qLV_6ZdfWAAAADU"]
[Thu Jul 30 14:21:49.435556 2026] [security2:error] [pid 1045527:tid 1045531] [remote 216.73.217.142:14358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amukTTbFEG16qLV_6ZdfWQAABAM"]
[Thu Jul 30 14:21:49.580362 2026] [autoindex:error] [pid 1045527:tid 1045721] [client 4.225.166.222:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_82d9fe69/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:21:49.581112 2026] [security2:error] [pid 1045527:tid 1045721] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.appliancerepairservice.one"] [uri "/cgi-sys/403.html"] [unique_id "amukTTbFEG16qLV_6ZdfXQAAAEA"]
[Thu Jul 30 14:21:49.658899 2026] [security2:error] [pid 1045527:tid 1045668] [client 20.52.125.110:3137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/network/cloud.php"] [unique_id "amukTTbFEG16qLV_6ZdfYQAAAAs"]
[Thu Jul 30 14:21:49.820908 2026] [security2:error] [pid 1045527:tid 1045544] [remote 57.141.18.93:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amukTTbFEG16qLV_6ZdfZwAAEhA"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=linen,nylon,polyester,steel&filter_size=extra-large,medium&rating=5&unfilter=1
[Thu Jul 30 14:21:49.928715 2026] [security2:error] [pid 1045527:tid 1045554] [remote 57.141.18.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amukTTbFEG16qLV_6ZdfYgAABho"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=linen,nylon,polyester,steel&filter_size=extra-large,medium&rating=5&unfilter=1
[Thu Jul 30 14:21:50.337545 2026] [security2:error] [pid 1045527:tid 1045698] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/ws.php"] [unique_id "amukTjbFEG16qLV_6ZdfcgAAACk"]
[Thu Jul 30 14:21:50.337674 2026] [security2:error] [pid 1045527:tid 1045698] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/ws.php"] [unique_id "amukTjbFEG16qLV_6ZdfcgAAACk"]
[Thu Jul 30 14:21:50.348909 2026] [security2:error] [pid 1045527:tid 1045746] [client 20.52.125.110:3168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/cloud.php"] [unique_id "amukTjbFEG16qLV_6ZdfdAAAAFk"]
[Thu Jul 30 14:21:50.474082 2026] [security2:error] [pid 1045527:tid 1045738] [client 118.193.45.234:1148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.248"] [uri "/index.cgi"] [unique_id "amukTjbFEG16qLV_6ZdfdQAAAFE"]
[Thu Jul 30 14:21:50.600171 2026] [security2:error] [pid 1045527:tid 1045678] [client 20.203.148.31:29740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amukTjbFEG16qLV_6ZdfcwAAABU"]
[Thu Jul 30 14:21:50.629361 2026] [security2:error] [pid 1045527:tid 1045664] [client 172.237.109.114:41937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukTjbFEG16qLV_6ZdfawAAAAc"]
[Thu Jul 30 14:21:50.638584 2026] [security2:error] [pid 1045527:tid 1045781] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/coffee.php"] [unique_id "amukTjbFEG16qLV_6ZdfeQAAAHw"]
[Thu Jul 30 14:21:50.638752 2026] [security2:error] [pid 1045527:tid 1045781] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/coffee.php"] [unique_id "amukTjbFEG16qLV_6ZdfeQAAAHw"]
[Thu Jul 30 14:21:50.667306 2026] [security2:error] [pid 1045527:tid 1045729] [client 118.193.45.234:1240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.248"] [uri "/index.cgi"] [unique_id "amukTjbFEG16qLV_6ZdfegAAAEg"]
[Thu Jul 30 14:21:50.853676 2026] [security2:error] [pid 1045527:tid 1045677] [client 118.193.45.234:1334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.248"] [uri "/index.cgi"] [unique_id "amukTjbFEG16qLV_6ZdfggAAABQ"]
[Thu Jul 30 14:21:51.047367 2026] [security2:error] [pid 1045527:tid 1045667] [client 118.193.45.234:1406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.248"] [uri "/index.cgi"] [unique_id "amukTzbFEG16qLV_6ZdfgwAAAAo"]
[Thu Jul 30 14:21:51.063826 2026] [security2:error] [pid 1045527:tid 1045682] [client 20.52.125.110:3174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/cgi-bin/cloud.php"] [unique_id "amukTzbFEG16qLV_6ZdfhgAAABk"]
[Thu Jul 30 14:21:51.237614 2026] [security2:error] [pid 1045527:tid 1045683] [client 118.193.45.234:1512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.6.43.248"] [uri "/index.cgi"] [unique_id "amukTzbFEG16qLV_6ZdfjAAAABo"]
[Thu Jul 30 14:21:51.460118 2026] [security2:error] [pid 1045527:tid 1045743] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/goods.php"] [unique_id "amukTzbFEG16qLV_6ZdfkAAAAFY"]
[Thu Jul 30 14:21:51.460268 2026] [security2:error] [pid 1045527:tid 1045743] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/goods.php"] [unique_id "amukTzbFEG16qLV_6ZdfkAAAAFY"]
[Thu Jul 30 14:21:51.568101 2026] [security2:error] [pid 1045527:tid 1045686] [client 172.237.109.114:58264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukTzbFEG16qLV_6ZdfiAAAAB0"]
[Thu Jul 30 14:21:51.659498 2026] [security2:error] [pid 1045527:tid 1045713] [client 20.52.125.110:3636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/updates.php"] [unique_id "amukTzbFEG16qLV_6ZdflgAAADg"]
[Thu Jul 30 14:21:51.741874 2026] [security2:error] [pid 1045527:tid 1045692] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/about.php"] [unique_id "amukTzbFEG16qLV_6ZdfmgAAACM"]
[Thu Jul 30 14:21:51.741974 2026] [security2:error] [pid 1045527:tid 1045692] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/about.php"] [unique_id "amukTzbFEG16qLV_6ZdfmgAAACM"]
[Thu Jul 30 14:21:52.049818 2026] [security2:error] [pid 1045527:tid 1045739] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/about.php"] [unique_id "amukUDbFEG16qLV_6ZdfngAAAFI"]
[Thu Jul 30 14:21:52.049937 2026] [security2:error] [pid 1045527:tid 1045739] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/about.php"] [unique_id "amukUDbFEG16qLV_6ZdfngAAAFI"]
[Thu Jul 30 14:21:52.341044 2026] [security2:error] [pid 1045527:tid 1045768] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/admin.php"] [unique_id "amukUDbFEG16qLV_6ZdfqAAAAG8"]
[Thu Jul 30 14:21:52.341169 2026] [security2:error] [pid 1045527:tid 1045768] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/admin.php"] [unique_id "amukUDbFEG16qLV_6ZdfqAAAAG8"]
[Thu Jul 30 14:21:52.592447 2026] [security2:error] [pid 1045527:tid 1045780] [client 20.52.125.110:3158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/css/cloud.php"] [unique_id "amukUDbFEG16qLV_6ZdfrgAAAHs"]
[Thu Jul 30 14:21:52.650754 2026] [security2:error] [pid 1045527:tid 1045764] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/inputs.php"] [unique_id "amukUDbFEG16qLV_6ZdfrwAAAGs"]
[Thu Jul 30 14:21:52.650858 2026] [security2:error] [pid 1045527:tid 1045764] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/inputs.php"] [unique_id "amukUDbFEG16qLV_6ZdfrwAAAGs"]
[Thu Jul 30 14:21:52.962505 2026] [security2:error] [pid 1045527:tid 1045716] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/inputs.php"] [unique_id "amukUDbFEG16qLV_6ZdfuwAAADs"]
[Thu Jul 30 14:21:52.962602 2026] [security2:error] [pid 1045527:tid 1045716] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/inputs.php"] [unique_id "amukUDbFEG16qLV_6ZdfuwAAADs"]
[Thu Jul 30 14:21:53.258505 2026] [security2:error] [pid 1045527:tid 1045754] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/adminfuns.php"] [unique_id "amukUTbFEG16qLV_6ZdfwQAAAGE"]
[Thu Jul 30 14:21:53.258655 2026] [security2:error] [pid 1045527:tid 1045754] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/adminfuns.php"] [unique_id "amukUTbFEG16qLV_6ZdfwQAAAGE"]
[Thu Jul 30 14:21:53.601507 2026] [security2:error] [pid 1045527:tid 1045737] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/404.php"] [unique_id "amukUTbFEG16qLV_6ZdfywAAAFA"]
[Thu Jul 30 14:21:53.601591 2026] [security2:error] [pid 1045527:tid 1045737] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/404.php"] [unique_id "amukUTbFEG16qLV_6ZdfywAAAFA"]
[Thu Jul 30 14:21:53.845957 2026] [security2:error] [pid 1045527:tid 1045776] [client 66.249.70.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kbaagency.com"] [uri "/index.php"] [unique_id "amukTzbFEG16qLV_6ZdfkQAAdyM"]
[Thu Jul 30 14:21:53.908138 2026] [security2:error] [pid 1045527:tid 1045739] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/xxx.php"] [unique_id "amukUTbFEG16qLV_6Zdf0wAAAFI"]
[Thu Jul 30 14:21:53.908228 2026] [security2:error] [pid 1045527:tid 1045739] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/xxx.php"] [unique_id "amukUTbFEG16qLV_6Zdf0wAAAFI"]
[Thu Jul 30 14:21:54.027247 2026] [security2:error] [pid 1045527:tid 1045672] [client 20.52.125.110:3597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/user/cloud.php"] [unique_id "amukUjbFEG16qLV_6Zdf1wAAAA8"]
[Thu Jul 30 14:21:54.220693 2026] [security2:error] [pid 1045527:tid 1045734] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/classwithtostring.php"] [unique_id "amukUjbFEG16qLV_6Zdf2QAAAE0"]
[Thu Jul 30 14:21:54.220858 2026] [security2:error] [pid 1045527:tid 1045734] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/classwithtostring.php"] [unique_id "amukUjbFEG16qLV_6Zdf2QAAAE0"]
[Thu Jul 30 14:21:54.514092 2026] [security2:error] [pid 1045527:tid 1045719] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/234ff.php"] [unique_id "amukUjbFEG16qLV_6Zdf4wAAAD4"]
[Thu Jul 30 14:21:54.514178 2026] [security2:error] [pid 1045527:tid 1045719] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/234ff.php"] [unique_id "amukUjbFEG16qLV_6Zdf4wAAAD4"]
[Thu Jul 30 14:21:54.801527 2026] [security2:error] [pid 1045527:tid 1045658] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/133.php"] [unique_id "amukUjbFEG16qLV_6Zdf5wAAAAE"]
[Thu Jul 30 14:21:54.801631 2026] [security2:error] [pid 1045527:tid 1045658] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/133.php"] [unique_id "amukUjbFEG16qLV_6Zdf5wAAAAE"]
[Thu Jul 30 14:21:55.052964 2026] [security2:error] [pid 1045527:tid 1045586] [remote 216.73.217.142:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukUzbFEG16qLV_6Zdf8AAAOjo"]
[Thu Jul 30 14:21:55.083808 2026] [security2:error] [pid 1045527:tid 1045741] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/wp-ws68.php"] [unique_id "amukUzbFEG16qLV_6Zdf8QAAAFQ"]
[Thu Jul 30 14:21:55.083954 2026] [security2:error] [pid 1045527:tid 1045741] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/wp-ws68.php"] [unique_id "amukUzbFEG16qLV_6Zdf8QAAAFQ"]
[Thu Jul 30 14:21:55.126894 2026] [security2:error] [pid 1045527:tid 1045731] [client 20.52.125.110:3193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/img/cloud.php"] [unique_id "amukUzbFEG16qLV_6Zdf8gAAAEo"]
[Thu Jul 30 14:21:55.377248 2026] [security2:error] [pid 1045527:tid 1045660] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/mgrr.php"] [unique_id "amukUzbFEG16qLV_6Zdf-AAAAAM"]
[Thu Jul 30 14:21:55.377339 2026] [security2:error] [pid 1045527:tid 1045660] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/mgrr.php"] [unique_id "amukUzbFEG16qLV_6Zdf-AAAAAM"]
[Thu Jul 30 14:21:55.677086 2026] [security2:error] [pid 1045527:tid 1045754] [client 20.52.125.110:3191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amukUzbFEG16qLV_6Zdf_gAAAGE"]
[Thu Jul 30 14:21:55.680913 2026] [security2:error] [pid 1045527:tid 1045747] [client 4.225.166.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.166.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.appliancerepairservice.one"] [uri "/55.php"] [unique_id "amukUzbFEG16qLV_6Zdf_wAAAFo"]
[Thu Jul 30 14:21:55.681040 2026] [security2:error] [pid 1045527:tid 1045747] [client 4.225.166.222:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.appliancerepairservice.one"] [uri "/55.php"] [unique_id "amukUzbFEG16qLV_6Zdf_wAAAFo"]
[Thu Jul 30 14:21:55.831984 2026] [security2:error] [pid 1045527:tid 1045732] [client 82.102.27.195:48996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amukUzbFEG16qLV_6ZdgAAAAAEs"]
[Thu Jul 30 14:21:55.832099 2026] [security2:error] [pid 1045527:tid 1045732] [client 82.102.27.195:48996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amukUzbFEG16qLV_6ZdgAAAAAEs"]
[Thu Jul 30 14:21:56.618233 2026] [security2:error] [pid 1045527:tid 1045758] [client 20.52.125.110:3136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/images/cloud.php"] [unique_id "amukVDbFEG16qLV_6ZdgEwAAAGU"]
[Thu Jul 30 14:21:56.771559 2026] [security2:error] [pid 1045527:tid 1045573] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amukVDbFEG16qLV_6ZdgFQAAAi0"]
[Thu Jul 30 14:21:57.348762 2026] [security2:error] [pid 1045527:tid 1045698] [client 20.52.125.110:3166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/avaa.php"] [unique_id "amukVTbFEG16qLV_6ZdgIAAAACk"]
[Thu Jul 30 14:21:58.487089 2026] [security2:error] [pid 1045527:tid 1045715] [client 43.173.174.65:54300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amukVjbFEG16qLV_6ZdgOwAAADo"]
[Thu Jul 30 14:21:59.001351 2026] [core:notice] [pid 1045527:tid 1045747] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:59.095182 2026] [core:notice] [pid 1045527:tid 1045744] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:21:59.100370 2026] [security2:error] [pid 1045527:tid 1045744] [client 43.172.195.7:36788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amukVzbFEG16qLV_6ZdgZAAAAFc"], referer: https://carnetdeshopping.com/index.php/typography/
[Thu Jul 30 14:21:59.249400 2026] [security2:error] [pid 1045527:tid 1045737] [client 180.243.59.178:61784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukVzbFEG16qLV_6ZdgZQAAAFA"]
[Thu Jul 30 14:21:59.249561 2026] [security2:error] [pid 1045527:tid 1045737] [client 180.243.59.178:61784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukVzbFEG16qLV_6ZdgZQAAAFA"]
[Thu Jul 30 14:21:59.272964 2026] [security2:error] [pid 1045527:tid 1045699] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amukVzbFEG16qLV_6ZdgaAAAACo"]
[Thu Jul 30 14:21:59.451072 2026] [security2:error] [pid 1045527:tid 1045626] [remote 216.73.217.142:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukVzbFEG16qLV_6ZdgagAAbmI"]
[Thu Jul 30 14:21:59.925380 2026] [security2:error] [pid 1045527:tid 1045735] [client 220.181.108.90:3042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/1816"] [unique_id "amukVzbFEG16qLV_6ZdgdwAAAE4"]
[Thu Jul 30 14:22:00.050757 2026] [security2:error] [pid 1045527:tid 1045746] [client 20.52.125.110:3163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/images/cloud.php"] [unique_id "amukWDbFEG16qLV_6ZdgfAAAAFk"]
[Thu Jul 30 14:22:00.168326 2026] [core:notice] [pid 1045527:tid 1045772] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:00.593105 2026] [security2:error] [pid 1045527:tid 1045775] [client 116.179.37.97:21537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/livezilla/image.php"] [unique_id "amukWDbFEG16qLV_6ZdgmgAAAHY"], referer: https://www.toscanamall.com/fr/e-liquides/24-e-liquide-avec-saveur-de-pall-mall.html
[Thu Jul 30 14:22:00.609292 2026] [core:notice] [pid 1045527:tid 1045688] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:00.763206 2026] [security2:error] [pid 1045527:tid 1045697] [client 20.52.125.110:3626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amukWDbFEG16qLV_6ZdgpAAAACg"]
[Thu Jul 30 14:22:01.168588 2026] [core:notice] [pid 1045527:tid 1045767] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:01.501697 2026] [security2:error] [pid 1045527:tid 1045784] [client 20.52.125.110:3169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amukWTbFEG16qLV_6ZdgvQAAAH8"]
[Thu Jul 30 14:22:01.592226 2026] [security2:error] [pid 1045527:tid 1045707] [client 127.0.0.1:13106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amukWTbFEG16qLV_6ZdgwQAAADI"]
[Thu Jul 30 14:22:01.592320 2026] [security2:error] [pid 1045527:tid 1045720] [client 74.7.241.158:50892] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.greensparkle.net"] [uri "/robots.txt"] [unique_id "amukWTbFEG16qLV_6ZdgwAAAP3s"]
[Thu Jul 30 14:22:01.944970 2026] [security2:error] [pid 1045527:tid 1045757] [client 74.7.175.165:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.tiger388.shop"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amukWTbFEG16qLV_6ZdgzAAAAGQ"]
[Thu Jul 30 14:22:02.297879 2026] [security2:error] [pid 1045527:tid 1045729] [client 20.52.125.110:3154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amukWjbFEG16qLV_6Zdg1QAAAEg"]
[Thu Jul 30 14:22:02.465123 2026] [core:notice] [pid 1045527:tid 1045782] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:02.847715 2026] [core:notice] [pid 1045527:tid 1045685] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:02.979956 2026] [security2:error] [pid 1045527:tid 1045743] [client 20.52.125.110:3184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amukWjbFEG16qLV_6Zdg5gAAAFY"]
[Thu Jul 30 14:22:03.431341 2026] [core:notice] [pid 1045527:tid 1045701] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:03.862623 2026] [security2:error] [pid 1045527:tid 1045750] [client 20.52.125.110:3334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amukWzbFEG16qLV_6Zdg-gAAAF0"]
[Thu Jul 30 14:22:03.870338 2026] [core:notice] [pid 1045527:tid 1045704] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:03.925944 2026] [core:notice] [pid 1045527:tid 1045735] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:04.167610 2026] [security2:error] [pid 1045527:tid 1045779] [client 74.7.175.176:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "santaclaraimports.com"] [uri "/index.php"] [unique_id "amukWjbFEG16qLV_6Zdg2wAAegY"]
[Thu Jul 30 14:22:04.257807 2026] [core:notice] [pid 1045527:tid 1045784] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:04.484891 2026] [security2:error] [pid 1045527:tid 1045766] [client 20.52.125.110:3148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/cloud.php"] [unique_id "amukXDbFEG16qLV_6ZdhDAAAAG0"]
[Thu Jul 30 14:22:05.443308 2026] [security2:error] [pid 1045527:tid 1045748] [client 20.52.125.110:3143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/updates.php"] [unique_id "amukXTbFEG16qLV_6ZdhHwAAAFs"]
[Thu Jul 30 14:22:05.581403 2026] [security2:error] [pid 1045527:tid 1045731] [client 172.237.109.114:53982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukXTbFEG16qLV_6ZdhFgAAAEo"]
[Thu Jul 30 14:22:05.700467 2026] [security2:error] [pid 1045527:tid 1045702] [client 216.73.217.138:1507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.upns.ca"] [uri "/index.php"] [unique_id "amukXTbFEG16qLV_6ZdhJAAALQI"]
[Thu Jul 30 14:22:06.085242 2026] [security2:error] [pid 1045527:tid 1045751] [client 20.52.125.110:3630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/libraries/legacy/updates.php"] [unique_id "amukXjbFEG16qLV_6ZdhMAAAAF4"]
[Thu Jul 30 14:22:06.300153 2026] [core:notice] [pid 1045527:tid 1045778] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:06.656154 2026] [security2:error] [pid 1045527:tid 1045659] [client 20.52.125.110:3197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amukXjbFEG16qLV_6ZdhOwAAAAI"]
[Thu Jul 30 14:22:07.179935 2026] [security2:error] [pid 1045527:tid 1045780] [client 82.102.27.195:58242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amukXzbFEG16qLV_6ZdhRgAAAHs"]
[Thu Jul 30 14:22:07.180062 2026] [security2:error] [pid 1045527:tid 1045780] [client 82.102.27.195:58242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amukXzbFEG16qLV_6ZdhRgAAAHs"]
[Thu Jul 30 14:22:07.527276 2026] [security2:error] [pid 1045527:tid 1045709] [client 20.52.125.110:3593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/libraries/vendor/updates.php"] [unique_id "amukXzbFEG16qLV_6ZdhTgAAADQ"]
[Thu Jul 30 14:22:08.030680 2026] [security2:error] [pid 1045527:tid 1045763] [client 20.52.125.110:3605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/alfa-rex.php7"] [unique_id "amukYDbFEG16qLV_6ZdhWAAAAGo"]
[Thu Jul 30 14:22:08.791943 2026] [security2:error] [pid 1045527:tid 1045747] [client 20.52.125.110:3161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/alfanew.php"] [unique_id "amukYDbFEG16qLV_6ZdhbQAAAFo"]
[Thu Jul 30 14:22:08.836264 2026] [core:error] [pid 1045527:tid 1045567] [remote 185.223.152.8:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:22:08.836284 2026] [core:error] [pid 1045527:tid 1045567] [remote 185.223.152.8:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:22:09.054120 2026] [security2:error] [pid 1045527:tid 1045765] [client 127.0.0.1:13108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amukYTbFEG16qLV_6ZdhcwAAAGw"]
[Thu Jul 30 14:22:09.054224 2026] [security2:error] [pid 1045527:tid 1045737] [client 74.7.241.146:40626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ecvh.ae"] [uri "/robots.txt"] [unique_id "amukYTbFEG16qLV_6ZdhcgAAUD0"]
[Thu Jul 30 14:22:09.455761 2026] [security2:error] [pid 1045527:tid 1045575] [remote 216.73.217.142:19287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amukYTbFEG16qLV_6ZdhfAAATC8"]
[Thu Jul 30 14:22:09.466389 2026] [security2:error] [pid 1045527:tid 1045659] [client 20.52.125.110:3175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amukYTbFEG16qLV_6ZdhfQAAAAI"]
[Thu Jul 30 14:22:09.966748 2026] [security2:error] [pid 1045527:tid 1045780] [client 180.243.59.178:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukYTbFEG16qLV_6ZdhiwAAAHs"]
[Thu Jul 30 14:22:09.966886 2026] [security2:error] [pid 1045527:tid 1045780] [client 180.243.59.178:62310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukYTbFEG16qLV_6ZdhiwAAAHs"]
[Thu Jul 30 14:22:10.061819 2026] [security2:error] [pid 1045527:tid 1045756] [client 20.52.125.110:3168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amukYjbFEG16qLV_6ZdhjwAAAGM"]
[Thu Jul 30 14:22:11.063810 2026] [security2:error] [pid 1045527:tid 1045688] [client 20.52.125.110:3155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-p.php7"] [unique_id "amukYzbFEG16qLV_6ZdhoAAAAB8"]
[Thu Jul 30 14:22:12.750744 2026] [security2:error] [pid 1045527:tid 1045730] [client 20.52.125.110:3138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/repeater.php"] [unique_id "amukZDbFEG16qLV_6ZdhwQAAAEk"]
[Thu Jul 30 14:22:13.441081 2026] [security2:error] [pid 1045527:tid 1045784] [client 20.52.125.110:3608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/repeater.php"] [unique_id "amukZTbFEG16qLV_6Zdh2AAAAH8"]
[Thu Jul 30 14:22:14.234411 2026] [security2:error] [pid 1045527:tid 1045715] [client 20.52.125.110:3192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/repeater.php"] [unique_id "amukZjbFEG16qLV_6Zdh5QAAADo"]
[Thu Jul 30 14:22:15.080509 2026] [security2:error] [pid 1045527:tid 1045611] [remote 216.73.217.142:44442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukZzbFEG16qLV_6Zdh9wAAdFM"]
[Thu Jul 30 14:22:15.563920 2026] [security2:error] [pid 1045527:tid 1045671] [client 193.47.62.167:44302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whe.djb.temporary.site"] [uri "/index.php"] [unique_id "amukYjbFEG16qLV_6ZdhkwAAAA4"]
[Thu Jul 30 14:22:16.539216 2026] [autoindex:error] [pid 1045527:tid 1045629] [remote 20.9.4.9:0] AH01276: Cannot serve directory /home2/xsygzjte/public_html/website_ac45cffc/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:22:17.846212 2026] [security2:error] [pid 1045527:tid 1045713] [client 198.235.24.97:49865] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "sh00085.hostgator.com"] [uri "/"] [unique_id "amukaTbFEG16qLV_6ZdiNgAAADg"]
[Thu Jul 30 14:22:18.736870 2026] [security2:error] [pid 1045527:tid 1045743] [client 172.237.109.114:6599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukajbFEG16qLV_6ZdiQQAAAFY"]
[Thu Jul 30 14:22:18.797804 2026] [security2:error] [pid 1045527:tid 1045673] [client 118.26.38.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.tdh.nyx.temporary.site"] [uri "/index.php"] [unique_id "amukajbFEG16qLV_6ZdiRAAAABA"]
[Thu Jul 30 14:22:20.466427 2026] [security2:error] [pid 1045527:tid 1045752] [client 180.243.59.178:62842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukbDbFEG16qLV_6ZdicgAAAF8"]
[Thu Jul 30 14:22:20.466579 2026] [security2:error] [pid 1045527:tid 1045752] [client 180.243.59.178:62842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukbDbFEG16qLV_6ZdicgAAAF8"]
[Thu Jul 30 14:22:20.740951 2026] [core:notice] [pid 1045527:tid 1045756] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:22.323691 2026] [proxy:error] [pid 1045527:tid 1045666] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:22.323754 2026] [proxy_http:error] [pid 1045527:tid 1045666] [client 74.7.175.142:47920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:22.324378 2026] [proxy:error] [pid 1045527:tid 1045666] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:22.324425 2026] [proxy_http:error] [pid 1045527:tid 1045666] [client 74.7.175.142:47920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:22.324546 2026] [security2:error] [pid 1045527:tid 1045666] [client 74.7.175.142:47920] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.eaw.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amukbjbFEG16qLV_6ZdingAAAAk"]
[Thu Jul 30 14:22:23.128421 2026] [security2:error] [pid 1045527:tid 1045670] [client 216.244.66.243:35532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amukbzbFEG16qLV_6ZdirgAAAA0"]
[Thu Jul 30 14:22:23.128533 2026] [security2:error] [pid 1045527:tid 1045670] [client 216.244.66.243:35532] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amukbzbFEG16qLV_6ZdirgAAAA0"]
[Thu Jul 30 14:22:23.257335 2026] [security2:error] [pid 1045527:tid 1045725] [client 18.192.166.72:38474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amukbzbFEG16qLV_6ZditQAAAEQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:22:23.756776 2026] [core:notice] [pid 1045527:tid 1045692] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:23.761582 2026] [security2:error] [pid 1045527:tid 1045692] [client 18.192.166.72:38484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amukbzbFEG16qLV_6ZdivAAAACM"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:22:23.791394 2026] [security2:error] [pid 1045527:tid 1045550] [remote 97.74.93.24:39204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emj.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amukbzbFEG16qLV_6ZdiwAAAPRY"]
[Thu Jul 30 14:22:24.157269 2026] [security2:error] [pid 1045527:tid 1045761] [client 18.192.166.72:38490] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amukcDbFEG16qLV_6ZdixQAAAGg"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:22:24.460260 2026] [security2:error] [pid 1045527:tid 1045553] [remote 216.73.217.142:44442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukcDbFEG16qLV_6ZdizwAAfBk"]
[Thu Jul 30 14:22:24.778345 2026] [security2:error] [pid 1045527:tid 1045771] [client 82.114.68.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amukbjbFEG16qLV_6ZdirAAAAHI"], referer: https://tereashops.com/product/ploom-x-aura-mevius-muscat-option%E9%9D%92%E6%8F%90%E7%88%86%E7%8F%A0%E7%85%99%E5%BD%88/
[Thu Jul 30 14:22:25.301699 2026] [security2:error] [pid 1045527:tid 1045668] [client 82.102.27.195:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amukcTbFEG16qLV_6Zdi5wAAAAs"]
[Thu Jul 30 14:22:25.301785 2026] [security2:error] [pid 1045527:tid 1045668] [client 82.102.27.195:43330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amukcTbFEG16qLV_6Zdi5wAAAAs"]
[Thu Jul 30 14:22:25.793971 2026] [core:notice] [pid 1045527:tid 1045725] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:26.281372 2026] [core:notice] [pid 1045527:tid 1045674] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:26.623134 2026] [security2:error] [pid 1045527:tid 1045570] [remote 74.7.227.39:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amukcjbFEG16qLV_6Zdi_QAAJSo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:22:27.149553 2026] [proxy:error] [pid 1045527:tid 1045757] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:27.149647 2026] [proxy_http:error] [pid 1045527:tid 1045757] [client 32.194.121.99:51977] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:27.150425 2026] [proxy:error] [pid 1045527:tid 1045757] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:27.150478 2026] [proxy_http:error] [pid 1045527:tid 1045757] [client 32.194.121.99:51977] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:27.180875 2026] [proxy:error] [pid 1045527:tid 1045741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:27.180952 2026] [proxy_http:error] [pid 1045527:tid 1045741] [client 34.224.175.62:21571] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:27.181522 2026] [proxy:error] [pid 1045527:tid 1045741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:27.181568 2026] [proxy_http:error] [pid 1045527:tid 1045741] [client 34.224.175.62:21571] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:27.266096 2026] [security2:error] [pid 1045527:tid 1045766] [client 34.77.166.77:38468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.xdi.djb.temporary.site"] [uri "/"] [unique_id "amukczbFEG16qLV_6ZdjIQAAAG0"]
[Thu Jul 30 14:22:27.453814 2026] [security2:error] [pid 1045527:tid 1045689] [client 34.76.80.239:48448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.xdi.djb.temporary.site"] [uri "/"] [unique_id "amukczbFEG16qLV_6ZdjKQAAACA"]
[Thu Jul 30 14:22:28.690656 2026] [proxy:error] [pid 1045527:tid 1045745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:28.690763 2026] [proxy_http:error] [pid 1045527:tid 1045745] [client 34.233.129.35:47701] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:28.691642 2026] [proxy:error] [pid 1045527:tid 1045745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:28.691704 2026] [proxy_http:error] [pid 1045527:tid 1045745] [client 34.233.129.35:47701] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:28.872149 2026] [security2:error] [pid 1045527:tid 1045659] [client 74.7.175.147:58870] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.greensparkle.net"] [uri "/robots.txt"] [unique_id "amukdDbFEG16qLV_6ZdjUAAAAk8"]
[Thu Jul 30 14:22:29.226826 2026] [core:notice] [pid 1045527:tid 1045663] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:29.369803 2026] [core:notice] [pid 1045527:tid 1045690] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:29.759718 2026] [security2:error] [pid 1045527:tid 1045783] [client 127.0.0.1:51012] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amukdTbFEG16qLV_6ZdjegAAAH4"]
[Thu Jul 30 14:22:29.759789 2026] [security2:error] [pid 1045527:tid 1045716] [client 74.7.228.44:40452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.cal-sync.co"] [uri "/robots.txt"] [unique_id "amukdTbFEG16qLV_6ZdjeQAAO2g"]
[Thu Jul 30 14:22:30.070122 2026] [security2:error] [pid 1045527:tid 1045629] [remote 216.73.217.142:8455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukdjbFEG16qLV_6ZdjiAAAKGU"]
[Thu Jul 30 14:22:30.869418 2026] [proxy:error] [pid 1045527:tid 1045647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:30.869483 2026] [proxy_http:error] [pid 1045527:tid 1045647] [remote 74.7.175.167:46326] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:30.870225 2026] [proxy:error] [pid 1045527:tid 1045647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:30.870273 2026] [proxy_http:error] [pid 1045527:tid 1045647] [remote 74.7.175.167:46326] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:31.786281 2026] [security2:error] [pid 1045527:tid 1045749] [client 180.243.59.178:63426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukdzbFEG16qLV_6ZdjuwAAAFw"]
[Thu Jul 30 14:22:31.786454 2026] [security2:error] [pid 1045527:tid 1045749] [client 180.243.59.178:63426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukdzbFEG16qLV_6ZdjuwAAAFw"]
[Thu Jul 30 14:22:32.578496 2026] [core:notice] [pid 1045527:tid 1045754] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:32.937770 2026] [core:notice] [pid 1045527:tid 1045680] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:33.363004 2026] [security2:error] [pid 1045527:tid 1045722] [client 220.181.108.159:35975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/user/register"] [unique_id "amukeDbFEG16qLV_6Zdj1wAAAEE"]
[Thu Jul 30 14:22:34.467031 2026] [security2:error] [pid 1045527:tid 1045558] [remote 216.73.217.142:8455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukejbFEG16qLV_6ZdkBgAASB4"]
[Thu Jul 30 14:22:34.576396 2026] [core:notice] [pid 1045527:tid 1045675] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:35.757468 2026] [core:notice] [pid 1045527:tid 1045754] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:36.002342 2026] [security2:error] [pid 1045527:tid 1045756] [client 120.240.178.154:55242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amukeTbFEG16qLV_6Zdj6QAAAGM"]
[Thu Jul 30 14:22:36.279854 2026] [security2:error] [pid 1045527:tid 1045578] [remote 57.141.0.5:43490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap2.xml"] [unique_id "amukfDbFEG16qLV_6ZdkNQAAQTI"]
[Thu Jul 30 14:22:36.372047 2026] [security2:error] [pid 1045527:tid 1045562] [remote 74.7.243.224:50394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amukfDbFEG16qLV_6ZdkOwAARyI"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:22:36.453067 2026] [core:notice] [pid 1045527:tid 1045701] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:36.911672 2026] [core:notice] [pid 1045527:tid 1045687] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:38.710861 2026] [security2:error] [pid 1045527:tid 1045663] [client 190.141.120.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amukfTbFEG16qLV_6ZdkdQAAAAY"], referer: https://tereashops.com/product/ploom-x-aura-mevius-muscat-option%E9%9D%92%E6%8F%90%E7%88%86%E7%8F%A0%E7%85%99%E5%BD%88/
[Thu Jul 30 14:22:39.468414 2026] [security2:error] [pid 1045527:tid 1045627] [remote 216.73.217.142:8455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukfzbFEG16qLV_6ZdkoQAAfWM"]
[Thu Jul 30 14:22:41.271960 2026] [security2:error] [pid 1045527:tid 1045720] [client 180.243.59.178:63897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukgTbFEG16qLV_6ZdkzAAAAD8"]
[Thu Jul 30 14:22:41.272193 2026] [security2:error] [pid 1045527:tid 1045720] [client 180.243.59.178:63897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukgTbFEG16qLV_6ZdkzAAAAD8"]
[Thu Jul 30 14:22:42.594505 2026] [security2:error] [pid 1045527:tid 1045619] [remote 103.59.160.210:61513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.aetiiph.net"] [uri "/login/index.php"] [unique_id "amukgjbFEG16qLV_6Zdk5QAAGVs"]
[Thu Jul 30 14:22:42.940920 2026] [core:notice] [pid 1045527:tid 1045746] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:44.099949 2026] [security2:error] [pid 1045527:tid 1045777] [client 68.221.186.136:35249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/011i.php"] [unique_id "amukhDbFEG16qLV_6ZdlCgAAAHg"]
[Thu Jul 30 14:22:45.116304 2026] [security2:error] [pid 1045527:tid 1045546] [remote 216.73.217.142:51849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukhTbFEG16qLV_6ZdlIAAALBI"]
[Thu Jul 30 14:22:45.719875 2026] [core:notice] [pid 1045527:tid 1045561] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:46.929775 2026] [security2:error] [pid 1045527:tid 1045770] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amukhjbFEG16qLV_6ZdlPQAAcR8"]
[Thu Jul 30 14:22:47.616139 2026] [security2:error] [pid 1045527:tid 1045715] [client 74.7.244.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.jto.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amukhzbFEG16qLV_6ZdlbwAAADo"]
[Thu Jul 30 14:22:47.616826 2026] [security2:error] [pid 1045527:tid 1045736] [client 74.7.244.25:40342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.jto.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amukhzbFEG16qLV_6ZdlbAAATzg"]
[Thu Jul 30 14:22:47.629529 2026] [security2:error] [pid 1045527:tid 1045722] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukhjbFEG16qLV_6ZdlXQAAAEE"]
[Thu Jul 30 14:22:49.473488 2026] [security2:error] [pid 1045527:tid 1045562] [remote 216.73.217.142:51849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukiTbFEG16qLV_6ZdlkAAAACI"]
[Thu Jul 30 14:22:49.485085 2026] [core:notice] [pid 1045527:tid 1045588] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:50.423935 2026] [security2:error] [pid 1045527:tid 1045704] [client 68.221.186.136:30586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/03a005685d.php"] [unique_id "amukijbFEG16qLV_6ZdlqQAAAC8"]
[Thu Jul 30 14:22:50.649382 2026] [security2:error] [pid 1045527:tid 1045602] [remote 57.141.0.56:34062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amukijbFEG16qLV_6ZdlrgAAT0o"]
[Thu Jul 30 14:22:50.906937 2026] [proxy:error] [pid 1045527:tid 1045688] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:50.907038 2026] [proxy_http:error] [pid 1045527:tid 1045688] [client 52.4.19.39:11342] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:50.907620 2026] [proxy:error] [pid 1045527:tid 1045688] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:50.907663 2026] [proxy_http:error] [pid 1045527:tid 1045688] [client 52.4.19.39:11342] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:50.929023 2026] [proxy:error] [pid 1045527:tid 1045685] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:50.929092 2026] [proxy_http:error] [pid 1045527:tid 1045685] [client 44.213.206.96:35962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:50.929872 2026] [proxy:error] [pid 1045527:tid 1045685] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:22:50.929931 2026] [proxy_http:error] [pid 1045527:tid 1045685] [client 44.213.206.96:35962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:22:51.112435 2026] [core:notice] [pid 1045527:tid 1045600] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:51.114803 2026] [security2:error] [pid 1045527:tid 1045661] [client 74.7.241.131:45624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amukizbFEG16qLV_6ZdlxQAABEg"], referer: https://insurancecouncilinc.com/
[Thu Jul 30 14:22:51.324068 2026] [core:notice] [pid 1045527:tid 1045607] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:22:51.326125 2026] [security2:error] [pid 1045527:tid 1045754] [client 74.7.241.131:45624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/category/politica/"] [unique_id "amukizbFEG16qLV_6ZdlzAAAYU8"], referer: https://www.nordeste1.com/category/policiais/
[Thu Jul 30 14:22:51.753661 2026] [security2:error] [pid 1045527:tid 1045662] [client 180.243.59.178:64421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukizbFEG16qLV_6Zdl2AAAAAU"]
[Thu Jul 30 14:22:51.753826 2026] [security2:error] [pid 1045527:tid 1045662] [client 180.243.59.178:64421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukizbFEG16qLV_6Zdl2AAAAAU"]
[Thu Jul 30 14:22:52.576024 2026] [security2:error] [pid 1045527:tid 1045698] [client 185.152.38.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amukizbFEG16qLV_6Zdl2wAAACk"]
[Thu Jul 30 14:22:52.889456 2026] [security2:error] [pid 1045527:tid 1045746] [client 68.221.186.136:32793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/403.php"] [unique_id "amukjDbFEG16qLV_6Zdl9wAAAFk"]
[Thu Jul 30 14:22:54.382946 2026] [core:error] [pid 1045527:tid 1045579] [remote 74.7.230.18:44844] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:22:54.382972 2026] [core:error] [pid 1045527:tid 1045579] [remote 74.7.230.18:44844] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:22:54.383270 2026] [security2:error] [pid 1045527:tid 1045723] [client 74.7.230.18:44844] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/index.php"] [unique_id "amukjjbFEG16qLV_6ZdmGwAAQjM"]
[Thu Jul 30 14:22:54.474971 2026] [security2:error] [pid 1045527:tid 1045623] [remote 216.73.217.142:51849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukjjbFEG16qLV_6ZdmHAAAYF8"]
[Thu Jul 30 14:22:55.222948 2026] [security2:error] [pid 1045527:tid 1045621] [remote 103.164.173.46:60606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.173.164.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/wp-login.php"] [unique_id "amukjzbFEG16qLV_6ZdmLAAAHF0"]
[Thu Jul 30 14:22:55.256930 2026] [security2:error] [pid 1045527:tid 1045736] [client 68.221.186.136:38030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/404.php"] [unique_id "amukjzbFEG16qLV_6ZdmLgAAAE8"]
[Thu Jul 30 14:22:55.272345 2026] [core:error] [pid 1045527:tid 1045630] [remote 74.7.175.182:45610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:22:55.272363 2026] [core:error] [pid 1045527:tid 1045630] [remote 74.7.175.182:45610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:22:55.272552 2026] [security2:error] [pid 1045527:tid 1045752] [client 74.7.175.182:45610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-e91d45c4.wrf.zzt.temporary.site"] [uri "/index.php"] [unique_id "amukjzbFEG16qLV_6ZdmMQAAX2Y"]
[Thu Jul 30 14:22:55.868300 2026] [security2:error] [pid 1045527:tid 1045762] [client 68.221.186.136:33361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/aa.php"] [unique_id "amukjzbFEG16qLV_6ZdmPQAAAGk"]
[Thu Jul 30 14:22:56.243861 2026] [core:error] [pid 1045527:tid 1045705] [client 74.7.230.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:22:56.243886 2026] [core:error] [pid 1045527:tid 1045705] [client 74.7.230.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:22:56.244066 2026] [security2:error] [pid 1045527:tid 1045705] [client 74.7.230.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.frontierphoenix.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amukkDbFEG16qLV_6ZdmRgAAADA"]
[Thu Jul 30 14:22:56.245989 2026] [security2:error] [pid 1045527:tid 1045754] [client 74.7.230.9:45318] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.frontierphoenix.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amukkDbFEG16qLV_6ZdmRAAAYXA"]
[Thu Jul 30 14:22:56.445584 2026] [security2:error] [pid 1045527:tid 1045676] [client 68.221.186.136:33390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/aafewc0k.php"] [unique_id "amukkDbFEG16qLV_6ZdmTQAAABM"]
[Thu Jul 30 14:22:56.682936 2026] [fcgid:warn] [pid 1045527:tid 1045749] (70014)End of file found: [client 167.94.146.55:21856] mod_fcgid: can't get data from http client
[Thu Jul 30 14:22:57.228450 2026] [security2:error] [pid 1045527:tid 1045765] [client 74.7.244.62:57404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.greensparkle.net"] [uri "/robots.txt"] [unique_id "amukkTbFEG16qLV_6ZdmZAAAbAE"]
[Thu Jul 30 14:22:58.729939 2026] [security2:error] [pid 1045527:tid 1045669] [client 82.102.18.116:33186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/wp-includes/wlwmanifest.xml"] [unique_id "amukkjbFEG16qLV_6ZdmhwAAAAw"]
[Thu Jul 30 14:22:58.788249 2026] [security2:error] [pid 1045527:tid 1045746] [client 93.152.221.138:56351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amukkjbFEG16qLV_6ZdmgwAAAFk"]
[Thu Jul 30 14:22:59.277199 2026] [security2:error] [pid 1045527:tid 1045776] [client 93.152.221.138:56472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amukkzbFEG16qLV_6ZdmlAAAAHc"], referer: https://t.co/
[Thu Jul 30 14:22:59.288437 2026] [security2:error] [pid 1045527:tid 1045740] [client 82.102.18.116:33196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/fr/xmlrpc.php"] [unique_id "amukkzbFEG16qLV_6ZdmlQAAAFM"]
[Thu Jul 30 14:22:59.345442 2026] [security2:error] [pid 1045527:tid 1045710] [client 74.7.241.164:51468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.pyn.nyx.temporary.site"] [uri "/index.php"] [unique_id "amukkTbFEG16qLV_6ZdmYAAANXY"]
[Thu Jul 30 14:22:59.345482 2026] [security2:error] [pid 1045527:tid 1045710] [client 74.7.241.164:51468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.pyn.nyx.temporary.site"] [uri "/index.php"] [unique_id "amukkTbFEG16qLV_6ZdmYAAANXY"]
[Thu Jul 30 14:22:59.477194 2026] [security2:error] [pid 1045527:tid 1045541] [remote 216.73.217.142:51849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukkzbFEG16qLV_6ZdmmQAACg0"]
[Thu Jul 30 14:22:59.989316 2026] [security2:error] [pid 1045527:tid 1045666] [client 82.102.18.116:33210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/blog/wp-includes/wlwmanifest.xml"] [unique_id "amukkzbFEG16qLV_6ZdmpgAAAAk"]
[Thu Jul 30 14:23:00.097408 2026] [security2:error] [pid 1045527:tid 1045737] [client 74.7.241.164:51470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pyn.nyx.temporary.site"] [uri "/index.php"] [unique_id "amukkzbFEG16qLV_6ZdmpQAAUAo"], referer: https://www.pyn.nyx.temporary.site/robots.txt
[Thu Jul 30 14:23:00.568394 2026] [security2:error] [pid 1045527:tid 1045708] [client 82.102.18.116:33212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/web/wp-includes/wlwmanifest.xml"] [unique_id "amuklDbFEG16qLV_6ZdmsgAAADM"]
[Thu Jul 30 14:23:00.705240 2026] [security2:error] [pid 1045527:tid 1045727] [client 68.221.186.136:34151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/abcd.php"] [unique_id "amuklDbFEG16qLV_6ZdmuQAAAEY"]
[Thu Jul 30 14:23:00.728345 2026] [security2:error] [pid 1045527:tid 1045543] [remote 57.141.0.58:36892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuklDbFEG16qLV_6ZdmugAAJQ8"]
[Thu Jul 30 14:23:01.120476 2026] [security2:error] [pid 1045527:tid 1045768] [client 82.102.18.116:33214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/website/wp-includes/wlwmanifest.xml"] [unique_id "amuklTbFEG16qLV_6ZdmwgAAAG8"]
[Thu Jul 30 14:23:01.691628 2026] [security2:error] [pid 1045527:tid 1045693] [client 82.102.18.116:33230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuklTbFEG16qLV_6Zdm0wAAACQ"]
[Thu Jul 30 14:23:01.842719 2026] [security2:error] [pid 1045527:tid 1045740] [client 180.243.59.178:64917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuklTbFEG16qLV_6Zdm2gAAAFM"]
[Thu Jul 30 14:23:01.842867 2026] [security2:error] [pid 1045527:tid 1045740] [client 180.243.59.178:64917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuklTbFEG16qLV_6Zdm2gAAAFM"]
[Thu Jul 30 14:23:01.931290 2026] [security2:error] [pid 1045527:tid 1045707] [client 74.7.175.132:38494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pyn.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuklTbFEG16qLV_6Zdm2QAAMiA"]
[Thu Jul 30 14:23:02.044702 2026] [security2:error] [pid 1045527:tid 1045698] [client 93.152.221.138:56549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/wp-login.php"] [unique_id "amukljbFEG16qLV_6Zdm4AAAACk"]
[Thu Jul 30 14:23:02.271633 2026] [security2:error] [pid 1045527:tid 1045720] [client 82.102.18.116:33232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/news/wp-includes/wlwmanifest.xml"] [unique_id "amukljbFEG16qLV_6Zdm6AAAAD8"]
[Thu Jul 30 14:23:02.823467 2026] [security2:error] [pid 1045527:tid 1045717] [client 82.102.18.116:33248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/2018/wp-includes/wlwmanifest.xml"] [unique_id "amukljbFEG16qLV_6Zdm9AAAADw"]
[Thu Jul 30 14:23:03.389003 2026] [security2:error] [pid 1045527:tid 1045705] [client 82.102.18.116:33258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuklzbFEG16qLV_6ZdnAAAAADA"]
[Thu Jul 30 14:23:03.402078 2026] [security2:error] [pid 1045527:tid 1045758] [client 68.183.121.117:49106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.worldofwhiskers.com.bkv.gpl.temporary.site"] [uri "/"] [unique_id "amuklzbFEG16qLV_6ZdnAQAAAGU"]
[Thu Jul 30 14:23:03.950456 2026] [security2:error] [pid 1045527:tid 1045672] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuklzbFEG16qLV_6Zdm_wAADxw"]
[Thu Jul 30 14:23:03.969736 2026] [security2:error] [pid 1045527:tid 1045686] [client 82.102.18.116:25313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuklzbFEG16qLV_6ZdnEQAAAB0"]
[Thu Jul 30 14:23:04.492874 2026] [security2:error] [pid 1045527:tid 1045770] [client 68.221.186.136:38805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/about.php"] [unique_id "amukmDbFEG16qLV_6ZdnIQAAAHE"]
[Thu Jul 30 14:23:04.539576 2026] [security2:error] [pid 1045527:tid 1045716] [client 82.102.18.116:44982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amukmDbFEG16qLV_6ZdnIgAAADs"]
[Thu Jul 30 14:23:04.730530 2026] [security2:error] [pid 1045527:tid 1045670] [client 50.6.43.217:37720] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amukmDbFEG16qLV_6ZdnJgAAAA0"]
[Thu Jul 30 14:23:04.861808 2026] [security2:error] [pid 1045527:tid 1045692] [client 50.6.43.217:37726] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amukmDbFEG16qLV_6ZdnLgAAACM"]
[Thu Jul 30 14:23:04.866031 2026] [security2:error] [pid 1045527:tid 1045696] [client 135.181.3.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "black-devil-shop.com"] [uri "/index.php"] [unique_id "amukmDbFEG16qLV_6ZdnFAAAACc"]
[Thu Jul 30 14:23:05.086820 2026] [security2:error] [pid 1045527:tid 1045671] [client 82.102.18.116:44994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/test/wp-includes/wlwmanifest.xml"] [unique_id "amukmTbFEG16qLV_6ZdnMQAAAA4"]
[Thu Jul 30 14:23:05.170882 2026] [security2:error] [pid 1045527:tid 1045571] [remote 216.73.217.142:5095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukmTbFEG16qLV_6ZdnNQAAais"]
[Thu Jul 30 14:23:05.406013 2026] [security2:error] [pid 1045527:tid 1045719] [client 216.73.216.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ciunews.com"] [uri "/index.php"] [unique_id "amukmTbFEG16qLV_6ZdnOAAAAD4"]
[Thu Jul 30 14:23:05.641717 2026] [security2:error] [pid 1045527:tid 1045682] [client 82.102.18.116:44998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/media/wp-includes/wlwmanifest.xml"] [unique_id "amukmTbFEG16qLV_6ZdnSAAAABk"]
[Thu Jul 30 14:23:06.184301 2026] [security2:error] [pid 1045527:tid 1045678] [client 82.102.18.116:20638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amukmjbFEG16qLV_6ZdnVgAAABU"]
[Thu Jul 30 14:23:06.243275 2026] [security2:error] [pid 1045527:tid 1045658] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amukmTbFEG16qLV_6ZdnRwAAAT4"]
[Thu Jul 30 14:23:06.760244 2026] [security2:error] [pid 1045527:tid 1045720] [client 82.102.18.116:45024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/site/wp-includes/wlwmanifest.xml"] [unique_id "amukmjbFEG16qLV_6ZdnZQAAAD8"]
[Thu Jul 30 14:23:07.341844 2026] [security2:error] [pid 1045527:tid 1045732] [client 82.102.18.116:45038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/cms/wp-includes/wlwmanifest.xml"] [unique_id "amukmzbFEG16qLV_6ZdncwAAAEs"]
[Thu Jul 30 14:23:07.889500 2026] [security2:error] [pid 1045527:tid 1045772] [client 82.102.18.116:45052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.toscanamall.com"] [uri "/fr/sito/wp-includes/wlwmanifest.xml"] [unique_id "amukmzbFEG16qLV_6ZdnfQAAAHM"]
[Thu Jul 30 14:23:08.218851 2026] [security2:error] [pid 1045527:tid 1045766] [client 68.221.186.136:40185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/admin.php"] [unique_id "amuknDbFEG16qLV_6ZdnhAAAAG0"]
[Thu Jul 30 14:23:08.848396 2026] [security2:error] [pid 1045527:tid 1045690] [client 68.221.186.136:34111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/adminfuns.php"] [unique_id "amuknDbFEG16qLV_6ZdnkwAAACE"]
[Thu Jul 30 14:23:09.431712 2026] [core:error] [pid 1045527:tid 1045689] [client 74.7.241.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:23:09.431735 2026] [core:error] [pid 1045527:tid 1045689] [client 74.7.241.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:23:09.431865 2026] [security2:error] [pid 1045527:tid 1045689] [client 74.7.241.180:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.xyt.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuknTbFEG16qLV_6ZdnoQAAACA"]
[Thu Jul 30 14:23:09.432449 2026] [security2:error] [pid 1045527:tid 1045739] [client 74.7.241.180:35362] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.xyt.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuknTbFEG16qLV_6ZdnnwAAUmo"]
[Thu Jul 30 14:23:09.488395 2026] [security2:error] [pid 1045527:tid 1045629] [remote 216.73.217.142:5095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuknTbFEG16qLV_6ZdnogAAKGU"]
[Thu Jul 30 14:23:11.860689 2026] [proxy:error] [pid 1045527:tid 1045740] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:23:11.860792 2026] [proxy_http:error] [pid 1045527:tid 1045740] [client 98.87.102.177:11515] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:23:11.861589 2026] [proxy:error] [pid 1045527:tid 1045740] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:23:11.861651 2026] [proxy_http:error] [pid 1045527:tid 1045740] [client 98.87.102.177:11515] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:23:11.884025 2026] [proxy:error] [pid 1045527:tid 1045709] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:23:11.884105 2026] [proxy_http:error] [pid 1045527:tid 1045709] [client 98.87.102.177:34774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:23:11.884910 2026] [proxy:error] [pid 1045527:tid 1045709] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:23:11.884969 2026] [proxy_http:error] [pid 1045527:tid 1045709] [client 98.87.102.177:34774] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:23:11.955180 2026] [security2:error] [pid 1045527:tid 1045689] [client 82.102.27.195:57926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuknzbFEG16qLV_6Zdn4wAAACA"]
[Thu Jul 30 14:23:11.955269 2026] [security2:error] [pid 1045527:tid 1045689] [client 82.102.27.195:57926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuknzbFEG16qLV_6Zdn4wAAACA"]
[Thu Jul 30 14:23:12.526617 2026] [security2:error] [pid 1045527:tid 1045703] [client 180.243.59.178:65460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukoDbFEG16qLV_6Zdn9gAAAC4"]
[Thu Jul 30 14:23:12.526739 2026] [security2:error] [pid 1045527:tid 1045703] [client 180.243.59.178:65460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukoDbFEG16qLV_6Zdn9gAAAC4"]
[Thu Jul 30 14:23:12.655126 2026] [security2:error] [pid 1045527:tid 1045693] [client 68.221.186.136:23410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/albin.php"] [unique_id "amukoDbFEG16qLV_6Zdn-AAAACQ"]
[Thu Jul 30 14:23:13.254663 2026] [security2:error] [pid 1045527:tid 1045542] [remote 47.128.27.33:54510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/gg-suit-jacket-brown/"] [unique_id "amukoTbFEG16qLV_6ZdoAgAAGg4"]
[Thu Jul 30 14:23:14.709558 2026] [security2:error] [pid 1045527:tid 1045718] [client 82.102.27.195:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amukojbFEG16qLV_6ZdoIgAAAD0"]
[Thu Jul 30 14:23:14.709710 2026] [security2:error] [pid 1045527:tid 1045718] [client 82.102.27.195:57928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amukojbFEG16qLV_6ZdoIgAAAD0"]
[Thu Jul 30 14:23:15.105717 2026] [security2:error] [pid 1045527:tid 1045538] [remote 216.73.217.142:57101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukozbFEG16qLV_6ZdoJgAARQo"]
[Thu Jul 30 14:23:15.920415 2026] [security2:error] [pid 1045527:tid 1045763] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amukozbFEG16qLV_6ZdoQAAAAGo"]
[Thu Jul 30 14:23:16.130137 2026] [security2:error] [pid 1045527:tid 1045773] [client 116.68.203.120:51387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.203.68.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/xmlrpc.php"] [unique_id "amukpDbFEG16qLV_6ZdoSQAAAHQ"]
[Thu Jul 30 14:23:16.130295 2026] [security2:error] [pid 1045527:tid 1045773] [client 116.68.203.120:51387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adbacklink.online"] [uri "/xmlrpc.php"] [unique_id "amukpDbFEG16qLV_6ZdoSQAAAHQ"]
[Thu Jul 30 14:23:16.642355 2026] [core:notice] [pid 1045527:tid 1045749] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:16.726962 2026] [security2:error] [pid 1045527:tid 1045567] [remote 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amukpDbFEG16qLV_6ZdoSAAAbic"]
[Thu Jul 30 14:23:16.982002 2026] [security2:error] [pid 1045527:tid 1045766] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukpDbFEG16qLV_6ZdoVQAAAG0"]
[Thu Jul 30 14:23:17.015459 2026] [core:notice] [pid 1045527:tid 1045734] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:17.451571 2026] [security2:error] [pid 1045527:tid 1045664] [client 68.221.186.136:23915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/amfsqvgv.php"] [unique_id "amukpTbFEG16qLV_6ZdobwAAAAc"]
[Thu Jul 30 14:23:17.549509 2026] [security2:error] [pid 1045527:tid 1045776] [client 119.73.97.132:30613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amukpTbFEG16qLV_6ZdoZwAAdx4"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 14:23:18.241604 2026] [security2:error] [pid 1045527:tid 1045691] [client 127.0.0.1:10676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amukpjbFEG16qLV_6ZdogwAAACI"]
[Thu Jul 30 14:23:18.241733 2026] [security2:error] [pid 1045527:tid 1045681] [client 74.7.244.42:58430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.alnukhbafurnituremovers.cc"] [uri "/robots.txt"] [unique_id "amukpjbFEG16qLV_6ZdoggAAGC4"]
[Thu Jul 30 14:23:18.401733 2026] [security2:error] [pid 1045527:tid 1045751] [client 185.200.116.219:46214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amukpjbFEG16qLV_6ZdohwAAAF4"]
[Thu Jul 30 14:23:18.403169 2026] [security2:error] [pid 1045527:tid 1045751] [client 185.200.116.219:46214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amukpjbFEG16qLV_6ZdohwAAAF4"]
[Thu Jul 30 14:23:18.415446 2026] [security2:error] [pid 1045527:tid 1045688] [client 18.205.213.231:48742] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/noticia/164/raniery-fica-surpreso-com-apoio-de-toscano.html"] [unique_id "amukpjbFEG16qLV_6ZdoiAAAAB8"]
[Thu Jul 30 14:23:19.505936 2026] [security2:error] [pid 1045527:tid 1045600] [remote 216.73.217.142:57101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukpzbFEG16qLV_6ZdopAAAX0g"]
[Thu Jul 30 14:23:20.397127 2026] [security2:error] [pid 1045527:tid 1045717] [client 68.221.186.136:34090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/ant.php"] [unique_id "amukqDbFEG16qLV_6ZdoswAAADw"]
[Thu Jul 30 14:23:20.490109 2026] [core:notice] [pid 1045527:tid 1045745] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:22.021243 2026] [core:error] [pid 1045527:tid 1045692] [client 158.173.25.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:23:22.021276 2026] [core:error] [pid 1045527:tid 1045692] [client 158.173.25.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:23:22.718380 2026] [security2:error] [pid 1045527:tid 1045675] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amukqjbFEG16qLV_6Zdo4gAAEmc"]
[Thu Jul 30 14:23:22.827494 2026] [security2:error] [pid 1045527:tid 1045717] [client 180.243.59.178:49597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukqjbFEG16qLV_6Zdo8gAAADw"]
[Thu Jul 30 14:23:22.827655 2026] [security2:error] [pid 1045527:tid 1045717] [client 180.243.59.178:49597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukqjbFEG16qLV_6Zdo8gAAADw"]
[Thu Jul 30 14:23:22.993005 2026] [core:notice] [pid 1045527:tid 1045727] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:23.780332 2026] [security2:error] [pid 1045527:tid 1045713] [client 68.221.186.136:23564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/appreciators.php"] [unique_id "amukqzbFEG16qLV_6ZdpCwAAADg"]
[Thu Jul 30 14:23:25.225226 2026] [security2:error] [pid 1045527:tid 1045597] [remote 216.73.217.142:29316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukrTbFEG16qLV_6ZdpIQAAfUU"]
[Thu Jul 30 14:23:25.597220 2026] [security2:error] [pid 1045527:tid 1045736] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukrTbFEG16qLV_6ZdpJwAAAE8"]
[Thu Jul 30 14:23:25.743419 2026] [security2:error] [pid 1045527:tid 1045647] [remote 57.141.0.10:42684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amukrTbFEG16qLV_6ZdpMQAAJHc"]
[Thu Jul 30 14:23:25.808016 2026] [security2:error] [pid 1045527:tid 1045762] [client 74.7.241.189:39944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pvl.djb.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amukrTbFEG16qLV_6ZdpNQAAaXI"]
[Thu Jul 30 14:23:26.219536 2026] [security2:error] [pid 1045527:tid 1045648] [remote 57.141.0.17:30740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amukrjbFEG16qLV_6ZdpPgAAdHg"]
[Thu Jul 30 14:23:26.566873 2026] [security2:error] [pid 1045527:tid 1045539] [remote 57.141.0.32:27820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amukrjbFEG16qLV_6ZdpSwAAPgs"]
[Thu Jul 30 14:23:26.723347 2026] [security2:error] [pid 1045527:tid 1045532] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.urbanshiftmovingcompany.one"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amukrjbFEG16qLV_6ZdpTgAAegQ"]
[Thu Jul 30 14:23:26.805520 2026] [security2:error] [pid 1045527:tid 1045764] [client 68.221.186.136:23560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/archive.php"] [unique_id "amukrjbFEG16qLV_6ZdpUwAAAGs"]
[Thu Jul 30 14:23:26.867958 2026] [security2:error] [pid 1045527:tid 1045701] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukrjbFEG16qLV_6ZdpQQAAACw"]
[Thu Jul 30 14:23:27.213172 2026] [security2:error] [pid 1045527:tid 1045697] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.urbanshiftmovingcompany.one"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amukrzbFEG16qLV_6ZdpWwAAACg"]
[Thu Jul 30 14:23:27.324738 2026] [security2:error] [pid 1045527:tid 1045619] [remote 57.141.0.44:49406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amukrzbFEG16qLV_6ZdpXwAAKVs"]
[Thu Jul 30 14:23:27.848436 2026] [security2:error] [pid 1045527:tid 1045534] [remote 74.7.227.39:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amukrzbFEG16qLV_6ZdpawAASAY"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:23:28.068187 2026] [core:notice] [pid 1045527:tid 1045755] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:29.009811 2026] [security2:error] [pid 1045527:tid 1045738] [client 68.221.186.136:24037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/as.php"] [unique_id "amuksTbFEG16qLV_6ZdpigAAAFE"]
[Thu Jul 30 14:23:29.501776 2026] [security2:error] [pid 1045527:tid 1045655] [remote 65.181.111.156:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.111.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baitultateeqmoverscompany.com"] [uri "/wp/wp-login.php"] [unique_id "amuksTbFEG16qLV_6ZdpkwAATH8"]
[Thu Jul 30 14:23:29.508473 2026] [security2:error] [pid 1045527:tid 1045530] [remote 216.73.217.142:29316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuksTbFEG16qLV_6ZdpmgAAQgI"]
[Thu Jul 30 14:23:29.939195 2026] [security2:error] [pid 1045527:tid 1045744] [client 68.221.186.136:29894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/atomlib.php"] [unique_id "amuksTbFEG16qLV_6ZdpogAAAFc"]
[Thu Jul 30 14:23:32.596714 2026] [security2:error] [pid 1045527:tid 1045693] [client 68.221.186.136:24057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/autoload_classmap.php"] [unique_id "amuktDbFEG16qLV_6Zdp2gAAACQ"]
[Thu Jul 30 14:23:33.463429 2026] [core:notice] [pid 1045527:tid 1045588] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:34.395102 2026] [security2:error] [pid 1045527:tid 1045773] [client 180.243.59.178:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuktjbFEG16qLV_6Zdp_AAAAHQ"]
[Thu Jul 30 14:23:34.395239 2026] [security2:error] [pid 1045527:tid 1045773] [client 180.243.59.178:50196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuktjbFEG16qLV_6Zdp_AAAAHQ"]
[Thu Jul 30 14:23:35.180237 2026] [security2:error] [pid 1045527:tid 1045600] [remote 216.73.217.142:59205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuktzbFEG16qLV_6ZdqCwAABEg"]
[Thu Jul 30 14:23:35.779777 2026] [core:notice] [pid 1045527:tid 1045715] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:35.815073 2026] [fcgid:warn] [pid 1045527:tid 1045776] (70014)End of file found: [client 152.32.217.163:34740] mod_fcgid: can't get data from http client
[Thu Jul 30 14:23:36.702588 2026] [security2:error] [pid 1045527:tid 1045618] [remote 74.7.243.224:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amukuDbFEG16qLV_6ZdqKQAASVo"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:23:37.172776 2026] [security2:error] [pid 1045527:tid 1045746] [client 74.7.230.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.dubaiappliance.repair"] [uri "/robots.txt"] [unique_id "amukuTbFEG16qLV_6ZdqNAAAWWE"]
[Thu Jul 30 14:23:37.929744 2026] [security2:error] [pid 1045527:tid 1045742] [client 68.221.186.136:24046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/bb.php"] [unique_id "amukuTbFEG16qLV_6ZdqRQAAAFU"]
[Thu Jul 30 14:23:38.157877 2026] [security2:error] [pid 1045527:tid 1045775] [client 193.47.62.167:34006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nxt.udi.temporary.site"] [uri "/index.php"] [unique_id "amuktzbFEG16qLV_6ZdqCgAAAHY"]
[Thu Jul 30 14:23:39.740508 2026] [core:notice] [pid 1045527:tid 1045779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:39.850792 2026] [core:notice] [pid 1045527:tid 1045647] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:40.763768 2026] [security2:error] [pid 1045527:tid 1045687] [client 68.221.186.136:23601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/bnm.php"] [unique_id "amukvDbFEG16qLV_6ZdqiQAAAB4"]
[Thu Jul 30 14:23:44.120233 2026] [security2:error] [pid 1045527:tid 1045738] [client 180.243.59.178:50688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukwDbFEG16qLV_6ZdqzQAAAFE"]
[Thu Jul 30 14:23:44.120423 2026] [security2:error] [pid 1045527:tid 1045738] [client 180.243.59.178:50688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukwDbFEG16qLV_6ZdqzQAAAFE"]
[Thu Jul 30 14:23:44.206704 2026] [core:notice] [pid 1045527:tid 1045781] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:44.368762 2026] [security2:error] [pid 1045527:tid 1045543] [remote 47.128.112.127:54580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kendarikomputer.com"] [uri "/p/disclaimer.html"] [unique_id "amukwDbFEG16qLV_6Zdq1QAADQ8"]
[Thu Jul 30 14:23:45.187370 2026] [security2:error] [pid 1045527:tid 1045674] [client 185.200.116.219:57790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amukwTbFEG16qLV_6Zdq8AAAABE"]
[Thu Jul 30 14:23:45.187508 2026] [security2:error] [pid 1045527:tid 1045674] [client 185.200.116.219:57790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amukwTbFEG16qLV_6Zdq8AAAABE"]
[Thu Jul 30 14:23:45.814459 2026] [core:notice] [pid 1045527:tid 1045713] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:49.528061 2026] [security2:error] [pid 1045527:tid 1045580] [remote 216.73.217.142:59205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amukxTbFEG16qLV_6ZdrRwAALzQ"]
[Thu Jul 30 14:23:50.047021 2026] [security2:error] [pid 1045527:tid 1045737] [client 74.7.175.150:37108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.sby.gzj.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amukxjbFEG16qLV_6ZdrUQAAAFA"]
[Thu Jul 30 14:23:50.696305 2026] [fcgid:warn] [pid 1045527:tid 1045765] (70014)End of file found: [client 152.32.202.244:54062] mod_fcgid: can't get data from http client
[Thu Jul 30 14:23:51.032235 2026] [security2:error] [pid 1045527:tid 1045740] [client 68.221.186.136:40219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/bootstrap.php"] [unique_id "amukxzbFEG16qLV_6ZdrkAAAAFM"]
[Thu Jul 30 14:23:51.553583 2026] [security2:error] [pid 1045527:tid 1045747] [client 68.221.186.136:40167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/buy.php"] [unique_id "amukxzbFEG16qLV_6ZdrqQAAAFo"]
[Thu Jul 30 14:23:51.591802 2026] [core:notice] [pid 1045527:tid 1045531] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:52.125727 2026] [core:notice] [pid 1045527:tid 1045534] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:52.507336 2026] [security2:error] [pid 1045527:tid 1045691] [client 172.237.109.114:17308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amukxzbFEG16qLV_6ZdrvAAAACI"]
[Thu Jul 30 14:23:53.144036 2026] [security2:error] [pid 1045527:tid 1045723] [client 68.221.186.136:34088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/chosen.php"] [unique_id "amukyTbFEG16qLV_6Zdr2gAAAEI"]
[Thu Jul 30 14:23:53.561311 2026] [core:notice] [pid 1045527:tid 1045561] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:54.395817 2026] [security2:error] [pid 1045527:tid 1045748] [client 68.221.186.136:29931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/class-wp-image.php"] [unique_id "amukyjbFEG16qLV_6Zdr_gAAAFs"]
[Thu Jul 30 14:23:55.108741 2026] [security2:error] [pid 1045527:tid 1045692] [client 180.243.59.178:51258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukyzbFEG16qLV_6ZdsCwAAACM"]
[Thu Jul 30 14:23:55.108869 2026] [security2:error] [pid 1045527:tid 1045692] [client 180.243.59.178:51258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amukyzbFEG16qLV_6ZdsCwAAACM"]
[Thu Jul 30 14:23:55.125364 2026] [core:notice] [pid 1045527:tid 1045565] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:55.357314 2026] [security2:error] [pid 1045527:tid 1045725] [client 68.221.186.136:35693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.progroupdoha.com"] [uri "/classsmtps.php"] [unique_id "amukyzbFEG16qLV_6ZdsEwAAAEQ"]
[Thu Jul 30 14:23:56.689991 2026] [core:notice] [pid 1045527:tid 1045582] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:57.776214 2026] [security2:error] [pid 1045527:tid 1045719] [client 85.208.96.195:63462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/01/08/mega-sena-pode-pagar-r-6-milhoes-neste-sabado/"] [unique_id "amukzTbFEG16qLV_6ZdsRAAAAD4"]
[Thu Jul 30 14:23:57.776372 2026] [security2:error] [pid 1045527:tid 1045719] [client 85.208.96.195:63462] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/01/08/mega-sena-pode-pagar-r-6-milhoes-neste-sabado/"] [unique_id "amukzTbFEG16qLV_6ZdsRAAAAD4"]
[Thu Jul 30 14:23:58.126025 2026] [security2:error] [pid 1045527:tid 1045689] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amukzTbFEG16qLV_6ZdsRwAAACA"]
[Thu Jul 30 14:23:58.247138 2026] [core:notice] [pid 1045527:tid 1045556] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:58.377768 2026] [core:notice] [pid 1045527:tid 1045752] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:58.486465 2026] [security2:error] [pid 1045527:tid 1045697] [client 74.248.33.8:34231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wk/index.php"] [unique_id "amukzjbFEG16qLV_6ZdsWQAAACg"]
[Thu Jul 30 14:23:59.748563 2026] [security2:error] [pid 1045527:tid 1045779] [client 74.248.33.8:45238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/av.php"] [unique_id "amukzzbFEG16qLV_6ZdscgAAAHo"]
[Thu Jul 30 14:23:59.789156 2026] [core:notice] [pid 1045527:tid 1045601] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:23:59.796829 2026] [security2:error] [pid 1045527:tid 1045631] [remote 5.161.62.209:46590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mails.moswey.com"] [uri "/.env"] [unique_id "amukzzbFEG16qLV_6ZdsdAAAVWc"]
[Thu Jul 30 14:24:00.424941 2026] [core:error] [pid 1045527:tid 1045612] [remote 74.7.228.60:40094] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:00.424989 2026] [core:error] [pid 1045527:tid 1045612] [remote 74.7.228.60:40094] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:00.425238 2026] [security2:error] [pid 1045527:tid 1045665] [client 74.7.228.60:40094] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-dc09cfb9.jud.zzt.temporary.site"] [uri "/website_dc09cfb9/index.php"] [unique_id "amuk0DbFEG16qLV_6ZdsgAAACFQ"]
[Thu Jul 30 14:24:00.539345 2026] [security2:error] [pid 1045527:tid 1045770] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amukzzbFEG16qLV_6ZdsdQAAcWs"]
[Thu Jul 30 14:24:00.546838 2026] [security2:error] [pid 1045527:tid 1045707] [client 43.172.196.172:55722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/01/31/quelques-jours-shopping-a-barcelone/"] [unique_id "amuk0DbFEG16qLV_6ZdshQAAADI"]
[Thu Jul 30 14:24:00.943116 2026] [security2:error] [pid 1045527:tid 1045719] [client 43.172.197.78:55398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/02/05/jimmy-choo-bridal-collection-2014/"] [unique_id "amuk0DbFEG16qLV_6ZdsiwAAAD4"]
[Thu Jul 30 14:24:01.255260 2026] [core:notice] [pid 1045527:tid 1045752] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:01.261159 2026] [security2:error] [pid 1045527:tid 1045752] [client 43.172.195.95:36138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/01/31/quelques-jours-shopping-a-barcelone/"] [unique_id "amuk0TbFEG16qLV_6ZdslwAAAF8"], referer: https://carnetdeshopping.com/index.php/2012/01/31/quelques-jours-shopping-a-barcelone/?replytocom=271
[Thu Jul 30 14:24:01.322020 2026] [core:notice] [pid 1045527:tid 1045587] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:01.496257 2026] [security2:error] [pid 1045527:tid 1045731] [client 177.6.106.101:55520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk0TbFEG16qLV_6ZdslQAAAEo"]
[Thu Jul 30 14:24:01.496462 2026] [security2:error] [pid 1045527:tid 1045731] [client 177.6.106.101:55520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk0TbFEG16qLV_6ZdslQAAAEo"]
[Thu Jul 30 14:24:01.657067 2026] [security2:error] [pid 1045527:tid 1045625] [remote 57.141.0.61:24688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuk0TbFEG16qLV_6ZdsoAAAK2E"]
[Thu Jul 30 14:24:01.723464 2026] [core:notice] [pid 1045527:tid 1045674] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:01.728624 2026] [security2:error] [pid 1045527:tid 1045674] [client 43.173.180.99:50386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/02/05/jimmy-choo-bridal-collection-2014/"] [unique_id "amuk0TbFEG16qLV_6ZdsowAAABE"], referer: https://carnetdeshopping.com/index.php/2014/02/05/jimmy-choo-bridal-collection-2014/
[Thu Jul 30 14:24:01.885909 2026] [security2:error] [pid 1045527:tid 1045698] [client 74.248.33.8:10910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/mini.php"] [unique_id "amuk0TbFEG16qLV_6ZdspQAAACk"]
[Thu Jul 30 14:24:02.650789 2026] [security2:error] [pid 1045527:tid 1045572] [remote 97.74.87.194:33658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuk0jbFEG16qLV_6ZdstAAAHSw"]
[Thu Jul 30 14:24:02.718481 2026] [security2:error] [pid 1045527:tid 1045673] [client 74.248.33.8:37234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/aa.php"] [unique_id "amuk0jbFEG16qLV_6ZdsuAAAABA"]
[Thu Jul 30 14:24:02.861887 2026] [core:notice] [pid 1045527:tid 1045623] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:04.041717 2026] [security2:error] [pid 1045527:tid 1045718] [client 74.248.33.8:10316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/w.php"] [unique_id "amuk1DbFEG16qLV_6Zds1AAAAD0"]
[Thu Jul 30 14:24:04.402557 2026] [core:notice] [pid 1045527:tid 1045608] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:04.533268 2026] [security2:error] [pid 1045527:tid 1045641] [remote 216.73.217.142:59205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuk1DbFEG16qLV_6Zds4gAAK3E"]
[Thu Jul 30 14:24:05.291416 2026] [security2:error] [pid 1045527:tid 1045703] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuk1DbFEG16qLV_6Zds3wAALmA"]
[Thu Jul 30 14:24:05.310237 2026] [security2:error] [pid 1045527:tid 1045783] [client 74.248.33.8:37207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/admin.php"] [unique_id "amuk1TbFEG16qLV_6Zds-AAAAH4"]
[Thu Jul 30 14:24:05.825570 2026] [security2:error] [pid 1045527:tid 1045662] [client 180.243.59.178:51799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk1TbFEG16qLV_6ZdtBAAAAAU"]
[Thu Jul 30 14:24:05.825697 2026] [security2:error] [pid 1045527:tid 1045662] [client 180.243.59.178:51799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk1TbFEG16qLV_6ZdtBAAAAAU"]
[Thu Jul 30 14:24:06.240453 2026] [core:notice] [pid 1045527:tid 1045722] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:06.310961 2026] [core:notice] [pid 1045527:tid 1045739] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:06.353566 2026] [core:notice] [pid 1045527:tid 1045782] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:06.354614 2026] [core:notice] [pid 1045527:tid 1045719] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:06.730689 2026] [core:notice] [pid 1045527:tid 1045708] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:06.875310 2026] [core:notice] [pid 1045527:tid 1045769] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:07.243575 2026] [autoindex:error] [pid 1045527:tid 1045741] [client 94.154.43.184:40430] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:24:07.278909 2026] [security2:error] [pid 1045527:tid 1045730] [client 74.248.33.8:10357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuk1zbFEG16qLV_6ZdtJgAAAEk"]
[Thu Jul 30 14:24:07.325826 2026] [proxy:error] [pid 1045527:tid 1045765] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:07.325892 2026] [proxy_http:error] [pid 1045527:tid 1045765] [client 52.202.41.153:61787] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:07.326462 2026] [proxy:error] [pid 1045527:tid 1045765] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:07.326506 2026] [proxy_http:error] [pid 1045527:tid 1045765] [client 52.202.41.153:61787] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:07.345072 2026] [proxy:error] [pid 1045527:tid 1045675] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:07.345132 2026] [proxy_http:error] [pid 1045527:tid 1045675] [client 52.202.41.153:47142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:07.345709 2026] [proxy:error] [pid 1045527:tid 1045675] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:07.345752 2026] [proxy_http:error] [pid 1045527:tid 1045675] [client 52.202.41.153:47142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:07.395455 2026] [security2:error] [pid 1045527:tid 1045756] [client 50.6.43.217:50944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuk1zbFEG16qLV_6ZdtNwAAAGM"]
[Thu Jul 30 14:24:07.407086 2026] [security2:error] [pid 1045527:tid 1045743] [client 50.6.43.217:50952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuk1zbFEG16qLV_6ZdtOAAAAFY"]
[Thu Jul 30 14:24:07.417230 2026] [security2:error] [pid 1045527:tid 1045728] [client 50.6.43.217:50958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuk1zbFEG16qLV_6ZdtQgAAAEc"]
[Thu Jul 30 14:24:07.971273 2026] [security2:error] [pid 1045527:tid 1045713] [client 172.237.109.114:31202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/sdk/vimService.wsdl"] [unique_id "amuk1zbFEG16qLV_6ZdtZwAAADg"]
[Thu Jul 30 14:24:09.630910 2026] [security2:error] [pid 1045527:tid 1045577] [remote 136.112.109.176:35986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "magicmooncorp.com"] [uri "/"] [unique_id "amuk2TbFEG16qLV_6ZdtqwAAHzE"], referer: https://magicmooncorp.com/
[Thu Jul 30 14:24:09.745373 2026] [security2:error] [pid 1045527:tid 1045632] [remote 57.141.0.54:20546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuk2TbFEG16qLV_6ZdtswAAZmg"]
[Thu Jul 30 14:24:10.291934 2026] [security2:error] [pid 1045527:tid 1045606] [remote 216.73.217.142:25915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuk2jbFEG16qLV_6ZdtwAAACU4"]
[Thu Jul 30 14:24:10.787331 2026] [security2:error] [pid 1045527:tid 1045735] [client 177.6.106.101:55927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk2jbFEG16qLV_6ZdtzQAAAE4"]
[Thu Jul 30 14:24:10.787438 2026] [security2:error] [pid 1045527:tid 1045735] [client 177.6.106.101:55927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk2jbFEG16qLV_6ZdtzQAAAE4"]
[Thu Jul 30 14:24:11.039277 2026] [security2:error] [pid 1045527:tid 1045784] [client 172.213.232.128:38792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/--wp-lgj.php"] [unique_id "amuk2zbFEG16qLV_6ZdtzwAAAH8"]
[Thu Jul 30 14:24:11.869830 2026] [security2:error] [pid 1045527:tid 1045687] [client 49.51.132.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuk2zbFEG16qLV_6Zdt5AAAAB4"]
[Thu Jul 30 14:24:12.352603 2026] [security2:error] [pid 1045527:tid 1045688] [client 172.213.232.128:30686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuk3DbFEG16qLV_6Zdt9AAAAB8"]
[Thu Jul 30 14:24:12.614435 2026] [security2:error] [pid 1045527:tid 1045746] [client 124.31.105.2:12090] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cnpinyin.com"] [uri "/"] [unique_id "amuk3DbFEG16qLV_6Zdt9gAAAFk"]
[Thu Jul 30 14:24:12.828586 2026] [security2:error] [pid 1045527:tid 1045710] [client 74.248.33.8:10487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/m.php"] [unique_id "amuk3DbFEG16qLV_6ZduAgAAADU"]
[Thu Jul 30 14:24:13.392535 2026] [security2:error] [pid 1045527:tid 1045671] [client 172.213.232.128:32564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/flower.php"] [unique_id "amuk3TbFEG16qLV_6ZduDQAAAA4"]
[Thu Jul 30 14:24:14.647074 2026] [security2:error] [pid 1045527:tid 1045727] [client 172.213.232.128:37071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/xleet.php"] [unique_id "amuk3jbFEG16qLV_6ZduJwAAAEY"]
[Thu Jul 30 14:24:14.768644 2026] [security2:error] [pid 1045527:tid 1045649] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuk3jbFEG16qLV_6ZduKwAAHXk"]
[Thu Jul 30 14:24:14.768825 2026] [security2:error] [pid 1045527:tid 1045686] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuk3jbFEG16qLV_6ZduKwAAHXk"]
[Thu Jul 30 14:24:14.806664 2026] [security2:error] [pid 1045527:tid 1045539] [remote 216.73.217.142:25915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuk3jbFEG16qLV_6ZduLwAABgs"]
[Thu Jul 30 14:24:15.273031 2026] [security2:error] [pid 1045527:tid 1045772] [client 172.213.232.128:35881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuk3zbFEG16qLV_6ZduNgAAAHM"]
[Thu Jul 30 14:24:15.711125 2026] [security2:error] [pid 1045527:tid 1045739] [client 49.51.132.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuk3zbFEG16qLV_6ZduPwAAAFI"], referer: http://cnpinyin.com/learning-progress
[Thu Jul 30 14:24:15.773286 2026] [security2:error] [pid 1045527:tid 1045534] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuk3zbFEG16qLV_6ZduRQAAPwY"]
[Thu Jul 30 14:24:15.773486 2026] [security2:error] [pid 1045527:tid 1045720] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuk3zbFEG16qLV_6ZduRQAAPwY"]
[Thu Jul 30 14:24:15.916161 2026] [security2:error] [pid 1045527:tid 1045762] [client 180.243.59.178:52324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk3zbFEG16qLV_6ZduUQAAAGk"]
[Thu Jul 30 14:24:15.916292 2026] [security2:error] [pid 1045527:tid 1045762] [client 180.243.59.178:52324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk3zbFEG16qLV_6ZduUQAAAGk"]
[Thu Jul 30 14:24:15.988360 2026] [proxy:error] [pid 1045527:tid 1045697] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:15.988449 2026] [proxy_http:error] [pid 1045527:tid 1045697] [client 98.87.102.177:38014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:15.989173 2026] [proxy:error] [pid 1045527:tid 1045697] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:15.989224 2026] [proxy_http:error] [pid 1045527:tid 1045697] [client 98.87.102.177:38014] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:16.034541 2026] [proxy:error] [pid 1045527:tid 1045753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:16.034626 2026] [proxy_http:error] [pid 1045527:tid 1045753] [client 44.216.125.112:28821] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:16.035457 2026] [proxy:error] [pid 1045527:tid 1045753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:16.035516 2026] [proxy_http:error] [pid 1045527:tid 1045753] [client 44.216.125.112:28821] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:16.259816 2026] [security2:error] [pid 1045527:tid 1045561] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wicked.php"] [unique_id "amuk4DbFEG16qLV_6ZduYwAAdyE"]
[Thu Jul 30 14:24:16.260000 2026] [security2:error] [pid 1045527:tid 1045776] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wicked.php"] [unique_id "amuk4DbFEG16qLV_6ZduYwAAdyE"]
[Thu Jul 30 14:24:16.305667 2026] [security2:error] [pid 1045527:tid 1045708] [client 74.248.33.8:34226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuk4DbFEG16qLV_6ZduYAAAADM"]
[Thu Jul 30 14:24:16.664778 2026] [security2:error] [pid 1045527:tid 1045538] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wpx.php"] [unique_id "amuk4DbFEG16qLV_6ZducAAAHQo"]
[Thu Jul 30 14:24:16.664968 2026] [security2:error] [pid 1045527:tid 1045686] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wpx.php"] [unique_id "amuk4DbFEG16qLV_6ZducAAAHQo"]
[Thu Jul 30 14:24:16.753572 2026] [security2:error] [pid 1045527:tid 1045646] [remote 57.141.0.26:32766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/56555984686/feed/rss2/"] [unique_id "amuk4DbFEG16qLV_6ZdudwAALnY"]
[Thu Jul 30 14:24:16.837505 2026] [security2:error] [pid 1045527:tid 1045666] [client 172.213.232.128:48671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuk4DbFEG16qLV_6ZdueQAAAAk"]
[Thu Jul 30 14:24:17.111112 2026] [security2:error] [pid 1045527:tid 1045591] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/images.php"] [unique_id "amuk4TbFEG16qLV_6ZduiAAASz8"]
[Thu Jul 30 14:24:17.111266 2026] [security2:error] [pid 1045527:tid 1045732] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/images.php"] [unique_id "amuk4TbFEG16qLV_6ZduiAAASz8"]
[Thu Jul 30 14:24:17.290870 2026] [core:notice] [pid 1045527:tid 1045619] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:17.473701 2026] [core:error] [pid 1045527:tid 1045720] [client 152.32.176.68:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:17.473733 2026] [core:error] [pid 1045527:tid 1045720] [client 152.32.176.68:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:17.567457 2026] [security2:error] [pid 1045527:tid 1045553] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/1xmomo.php"] [unique_id "amuk4TbFEG16qLV_6ZdulwAAURk"]
[Thu Jul 30 14:24:17.567708 2026] [security2:error] [pid 1045527:tid 1045738] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/1xmomo.php"] [unique_id "amuk4TbFEG16qLV_6ZdulwAAURk"]
[Thu Jul 30 14:24:17.851019 2026] [security2:error] [pid 1045527:tid 1045762] [client 119.73.97.132:31002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuk4TbFEG16qLV_6ZdumAAAaR0"], referer: https://www.urwru.club/emm-elevate/?preview_id=685&preview_nonce=6cdd8f071f&preview=true&aaeid=1
[Thu Jul 30 14:24:17.925684 2026] [core:error] [pid 1045527:tid 1045767] [client 74.248.33.8:10921] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:17.925713 2026] [core:error] [pid 1045527:tid 1045767] [client 74.248.33.8:10921] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:18.026693 2026] [security2:error] [pid 1045527:tid 1045547] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/1revo.php"] [unique_id "amuk4jbFEG16qLV_6ZdupAAAVxM"]
[Thu Jul 30 14:24:18.026845 2026] [security2:error] [pid 1045527:tid 1045744] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/1revo.php"] [unique_id "amuk4jbFEG16qLV_6ZdupAAAVxM"]
[Thu Jul 30 14:24:18.088488 2026] [security2:error] [pid 1045527:tid 1045697] [client 172.213.232.128:48685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuk4jbFEG16qLV_6ZdupwAAACg"]
[Thu Jul 30 14:24:18.144097 2026] [security2:error] [pid 1045527:tid 1045781] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuk4TbFEG16qLV_6ZduogAAAHw"]
[Thu Jul 30 14:24:18.276932 2026] [security2:error] [pid 1045527:tid 1045721] [client 49.51.132.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuk4jbFEG16qLV_6ZdurAAAAEA"], referer: http://cnpinyin.com/learning-progress/
[Thu Jul 30 14:24:18.398768 2026] [fcgid:warn] [pid 1045527:tid 1045743] (70014)End of file found: [client 66.132.195.53:48110] mod_fcgid: can't get data from http client
[Thu Jul 30 14:24:18.469492 2026] [security2:error] [pid 1045527:tid 1045670] [client 74.248.33.8:10909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/classwithtostring.php"] [unique_id "amuk4jbFEG16qLV_6ZdusQAAAA0"]
[Thu Jul 30 14:24:18.477045 2026] [security2:error] [pid 1045527:tid 1045549] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/cong.php"] [unique_id "amuk4jbFEG16qLV_6ZduswAAfhU"]
[Thu Jul 30 14:24:18.477172 2026] [security2:error] [pid 1045527:tid 1045783] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/cong.php"] [unique_id "amuk4jbFEG16qLV_6ZduswAAfhU"]
[Thu Jul 30 14:24:18.934880 2026] [security2:error] [pid 1045527:tid 1045558] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/a.php"] [unique_id "amuk4jbFEG16qLV_6ZduugAAVR4"]
[Thu Jul 30 14:24:18.935091 2026] [security2:error] [pid 1045527:tid 1045742] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/a.php"] [unique_id "amuk4jbFEG16qLV_6ZduugAAVR4"]
[Thu Jul 30 14:24:19.139795 2026] [security2:error] [pid 1045527:tid 1045686] [client 172.202.44.182:32001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wk/index.php"] [unique_id "amuk4zbFEG16qLV_6ZduwgAAAB0"]
[Thu Jul 30 14:24:19.295078 2026] [security2:error] [pid 1045527:tid 1045778] [client 172.213.232.128:35852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuk4zbFEG16qLV_6ZduyAAAAHk"]
[Thu Jul 30 14:24:19.317803 2026] [core:notice] [pid 1045527:tid 1045668] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:19.398756 2026] [security2:error] [pid 1045527:tid 1045589] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/srontol.php"] [unique_id "amuk4zbFEG16qLV_6ZduygAAHz0"]
[Thu Jul 30 14:24:19.398990 2026] [security2:error] [pid 1045527:tid 1045688] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/srontol.php"] [unique_id "amuk4zbFEG16qLV_6ZduygAAHz0"]
[Thu Jul 30 14:24:19.812674 2026] [security2:error] [pid 1045527:tid 1045574] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/reop3.php"] [unique_id "amuk4zbFEG16qLV_6Zdu2gAAIC4"]
[Thu Jul 30 14:24:19.812861 2026] [security2:error] [pid 1045527:tid 1045689] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/reop3.php"] [unique_id "amuk4zbFEG16qLV_6Zdu2gAAIC4"]
[Thu Jul 30 14:24:19.883227 2026] [security2:error] [pid 1045527:tid 1045690] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuk4zbFEG16qLV_6ZduxwAAACE"]
[Thu Jul 30 14:24:19.943316 2026] [security2:error] [pid 1045527:tid 1045682] [client 74.7.241.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-d35de2e9.ear.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuk4zbFEG16qLV_6Zdu4AAAABk"]
[Thu Jul 30 14:24:19.944056 2026] [security2:error] [pid 1045527:tid 1045701] [client 74.7.241.148:52874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-d35de2e9.ear.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuk4zbFEG16qLV_6Zdu3AAALCs"]
[Thu Jul 30 14:24:20.035553 2026] [security2:error] [pid 1045527:tid 1045738] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuk4zbFEG16qLV_6Zdu2QAAAFE"]
[Thu Jul 30 14:24:20.215840 2026] [core:notice] [pid 1045527:tid 1045581] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:20.232432 2026] [security2:error] [pid 1045527:tid 1045596] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/file5.php"] [unique_id "amuk5DbFEG16qLV_6Zdu8wAAVkQ"]
[Thu Jul 30 14:24:20.232591 2026] [security2:error] [pid 1045527:tid 1045743] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/file5.php"] [unique_id "amuk5DbFEG16qLV_6Zdu8wAAVkQ"]
[Thu Jul 30 14:24:20.434380 2026] [security2:error] [pid 1045527:tid 1045602] [remote 216.73.217.142:51246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuk5DbFEG16qLV_6Zdu9AAAdEo"]
[Thu Jul 30 14:24:20.598297 2026] [security2:error] [pid 1045527:tid 1045684] [client 172.202.44.182:32011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/av.php"] [unique_id "amuk5DbFEG16qLV_6Zdu-wAAABs"]
[Thu Jul 30 14:24:20.672356 2026] [security2:error] [pid 1045527:tid 1045601] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/domvf.php"] [unique_id "amuk5DbFEG16qLV_6ZdvAAAAEEk"]
[Thu Jul 30 14:24:20.672525 2026] [security2:error] [pid 1045527:tid 1045673] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/domvf.php"] [unique_id "amuk5DbFEG16qLV_6ZdvAAAAEEk"]
[Thu Jul 30 14:24:20.738480 2026] [security2:error] [pid 1045527:tid 1045749] [client 74.248.33.8:10319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/gmo.php"] [unique_id "amuk5DbFEG16qLV_6ZdvBAAAAFw"]
[Thu Jul 30 14:24:20.807870 2026] [security2:error] [pid 1045527:tid 1045607] [remote 57.141.0.37:28784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/626900273/feed/rss2/"] [unique_id "amuk5DbFEG16qLV_6ZdvBQAAW08"]
[Thu Jul 30 14:24:21.099687 2026] [security2:error] [pid 1045527:tid 1045577] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/zero.php"] [unique_id "amuk5TbFEG16qLV_6ZdvDQAAPzE"]
[Thu Jul 30 14:24:21.099900 2026] [security2:error] [pid 1045527:tid 1045720] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/zero.php"] [unique_id "amuk5TbFEG16qLV_6ZdvDQAAPzE"]
[Thu Jul 30 14:24:21.206211 2026] [core:error] [pid 1045527:tid 1045661] [client 152.32.176.68:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:21.206235 2026] [core:error] [pid 1045527:tid 1045661] [client 152.32.176.68:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:21.390064 2026] [security2:error] [pid 1045527:tid 1045779] [client 177.6.106.101:56488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk5TbFEG16qLV_6ZdvFQAAAHo"]
[Thu Jul 30 14:24:21.390213 2026] [security2:error] [pid 1045527:tid 1045779] [client 177.6.106.101:56488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk5TbFEG16qLV_6ZdvFQAAAHo"]
[Thu Jul 30 14:24:21.533305 2026] [security2:error] [pid 1045527:tid 1045610] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/002.php"] [unique_id "amuk5TbFEG16qLV_6ZdvFgAABlI"]
[Thu Jul 30 14:24:21.533561 2026] [security2:error] [pid 1045527:tid 1045663] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/002.php"] [unique_id "amuk5TbFEG16qLV_6ZdvFgAABlI"]
[Thu Jul 30 14:24:21.779466 2026] [security2:error] [pid 1045527:tid 1045718] [client 74.248.33.8:10306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuk5TbFEG16qLV_6ZdvHQAAAD0"]
[Thu Jul 30 14:24:21.802365 2026] [security2:error] [pid 1045527:tid 1045739] [client 172.202.44.182:32013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/mini.php"] [unique_id "amuk5TbFEG16qLV_6ZdvHgAAAFI"]
[Thu Jul 30 14:24:21.872135 2026] [security2:error] [pid 1045527:tid 1045735] [client 127.0.0.1:18982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuk5TbFEG16qLV_6ZdvIQAAAE4"]
[Thu Jul 30 14:24:21.872329 2026] [security2:error] [pid 1045527:tid 1045737] [client 74.7.230.17:49736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.dtx.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuk5TbFEG16qLV_6ZdvHwAAUGg"]
[Thu Jul 30 14:24:21.938479 2026] [security2:error] [pid 1045527:tid 1045616] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/thoms.php"] [unique_id "amuk5TbFEG16qLV_6ZdvJAAAZVg"]
[Thu Jul 30 14:24:21.938657 2026] [security2:error] [pid 1045527:tid 1045758] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/thoms.php"] [unique_id "amuk5TbFEG16qLV_6ZdvJAAAZVg"]
[Thu Jul 30 14:24:22.380521 2026] [security2:error] [pid 1045527:tid 1045606] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/fi22.php"] [unique_id "amuk5jbFEG16qLV_6ZdvLgAAFk4"]
[Thu Jul 30 14:24:22.380697 2026] [security2:error] [pid 1045527:tid 1045679] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/fi22.php"] [unique_id "amuk5jbFEG16qLV_6ZdvLgAAFk4"]
[Thu Jul 30 14:24:22.628824 2026] [core:notice] [pid 1045527:tid 1045657] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:22.666273 2026] [security2:error] [pid 1045527:tid 1045722] [client 74.248.33.8:10911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-the.php"] [unique_id "amuk5jbFEG16qLV_6ZdvNgAAAEE"]
[Thu Jul 30 14:24:22.785322 2026] [core:notice] [pid 1045527:tid 1045746] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:22.799842 2026] [core:notice] [pid 1045527:tid 1045595] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:22.802432 2026] [security2:error] [pid 1045527:tid 1045678] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "teknomalay.com"] [uri "/wp-content.html"] [unique_id "amuk5jbFEG16qLV_6ZdvOwAAFUM"]
[Thu Jul 30 14:24:22.894445 2026] [core:notice] [pid 1045527:tid 1045773] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:22.987669 2026] [security2:error] [pid 1045527:tid 1045751] [client 172.202.44.182:34243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/aa.php"] [unique_id "amuk5jbFEG16qLV_6ZdvQAAAAF4"]
[Thu Jul 30 14:24:23.057938 2026] [core:notice] [pid 1045527:tid 1045590] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:23.193744 2026] [core:notice] [pid 1045527:tid 1045749] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:23.276606 2026] [security2:error] [pid 1045527:tid 1045738] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuk5jbFEG16qLV_6ZdvOAAAUWU"]
[Thu Jul 30 14:24:23.299757 2026] [security2:error] [pid 1045527:tid 1045706] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amuk5zbFEG16qLV_6ZdvQgAAMT4"]
[Thu Jul 30 14:24:23.452503 2026] [security2:error] [pid 1045527:tid 1045729] [client 172.213.232.128:30692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuk5zbFEG16qLV_6ZdvUwAAAEg"]
[Thu Jul 30 14:24:23.466618 2026] [security2:error] [pid 1045527:tid 1045742] [client 74.248.33.8:37195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/404.php"] [unique_id "amuk5zbFEG16qLV_6ZdvVAAAAFU"]
[Thu Jul 30 14:24:23.577823 2026] [security2:error] [pid 1045527:tid 1045700] [client 172.237.109.114:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuk5jbFEG16qLV_6ZdvQQAAACs"]
[Thu Jul 30 14:24:24.280628 2026] [security2:error] [pid 1045527:tid 1045744] [client 135.119.63.61:5328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cakiltheme/idx.php"] [unique_id "amuk6DbFEG16qLV_6ZdvZwAAAFc"]
[Thu Jul 30 14:24:24.393189 2026] [security2:error] [pid 1045527:tid 1045641] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/82.php"] [unique_id "amuk6DbFEG16qLV_6ZdvcAAAM3E"]
[Thu Jul 30 14:24:24.393369 2026] [security2:error] [pid 1045527:tid 1045708] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/82.php"] [unique_id "amuk6DbFEG16qLV_6ZdvcAAAM3E"]
[Thu Jul 30 14:24:24.813154 2026] [security2:error] [pid 1045527:tid 1045597] [remote 216.73.217.142:51246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuk6DbFEG16qLV_6ZdveQAAG0U"]
[Thu Jul 30 14:24:24.816754 2026] [security2:error] [pid 1045527:tid 1045624] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/sx.php"] [unique_id "amuk6DbFEG16qLV_6ZdvegAAfmA"]
[Thu Jul 30 14:24:24.816931 2026] [security2:error] [pid 1045527:tid 1045783] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/sx.php"] [unique_id "amuk6DbFEG16qLV_6ZdvegAAfmA"]
[Thu Jul 30 14:24:25.046471 2026] [core:error] [pid 1045527:tid 1045748] [client 152.32.176.68:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:25.046495 2026] [core:error] [pid 1045527:tid 1045748] [client 152.32.176.68:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:25.069968 2026] [security2:error] [pid 1045527:tid 1045757] [client 135.119.63.61:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cakiltheme/up.php"] [unique_id "amuk6TbFEG16qLV_6ZdviAAAAGQ"]
[Thu Jul 30 14:24:25.234396 2026] [security2:error] [pid 1045527:tid 1045647] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/dex.php"] [unique_id "amuk6TbFEG16qLV_6ZdviQAAOHc"]
[Thu Jul 30 14:24:25.234663 2026] [security2:error] [pid 1045527:tid 1045713] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/dex.php"] [unique_id "amuk6TbFEG16qLV_6ZdviQAAOHc"]
[Thu Jul 30 14:24:25.339252 2026] [security2:error] [pid 1045527:tid 1045718] [client 74.248.33.8:37231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/init.php"] [unique_id "amuk6TbFEG16qLV_6ZdvmQAAAD0"]
[Thu Jul 30 14:24:25.581339 2026] [security2:error] [pid 1045527:tid 1045726] [client 172.202.44.182:18138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/w.php"] [unique_id "amuk6TbFEG16qLV_6ZdvoQAAAEU"]
[Thu Jul 30 14:24:25.660994 2026] [security2:error] [pid 1045527:tid 1045530] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/fpwch.php"] [unique_id "amuk6TbFEG16qLV_6ZdvtAAAQgI"]
[Thu Jul 30 14:24:25.661165 2026] [security2:error] [pid 1045527:tid 1045723] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/fpwch.php"] [unique_id "amuk6TbFEG16qLV_6ZdvtAAAQgI"]
[Thu Jul 30 14:24:25.725351 2026] [security2:error] [pid 1045527:tid 1045714] [client 172.213.232.128:30702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuk6TbFEG16qLV_6ZdvtQAAADk"]
[Thu Jul 30 14:24:25.823854 2026] [security2:error] [pid 1045527:tid 1045682] [client 135.119.63.61:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/calendar/index.php"] [unique_id "amuk6TbFEG16qLV_6ZdvugAAABk"]
[Thu Jul 30 14:24:25.909602 2026] [security2:error] [pid 1045527:tid 1045671] [client 180.243.59.178:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk6TbFEG16qLV_6ZdvyAAAAA4"]
[Thu Jul 30 14:24:25.909721 2026] [security2:error] [pid 1045527:tid 1045671] [client 180.243.59.178:52834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk6TbFEG16qLV_6ZdvyAAAAA4"]
[Thu Jul 30 14:24:26.090128 2026] [security2:error] [pid 1045527:tid 1045557] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/black.php"] [unique_id "amuk6jbFEG16qLV_6ZdvzgAAAB0"]
[Thu Jul 30 14:24:26.090274 2026] [security2:error] [pid 1045527:tid 1045657] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/black.php"] [unique_id "amuk6jbFEG16qLV_6ZdvzgAAAB0"]
[Thu Jul 30 14:24:26.515901 2026] [security2:error] [pid 1045527:tid 1045592] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/loader.php"] [unique_id "amuk6jbFEG16qLV_6Zdv6gAAWUA"]
[Thu Jul 30 14:24:26.516085 2026] [security2:error] [pid 1045527:tid 1045746] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/loader.php"] [unique_id "amuk6jbFEG16qLV_6Zdv6gAAWUA"]
[Thu Jul 30 14:24:26.547647 2026] [security2:error] [pid 1045527:tid 1045716] [client 172.213.232.128:38842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuk6jbFEG16qLV_6Zdv7QAAADs"]
[Thu Jul 30 14:24:26.557897 2026] [security2:error] [pid 1045527:tid 1045694] [client 135.119.63.61:5644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/canonical.php"] [unique_id "amuk6jbFEG16qLV_6Zdv7wAAACU"]
[Thu Jul 30 14:24:26.923920 2026] [security2:error] [pid 1045527:tid 1045607] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/file61.php"] [unique_id "amuk6jbFEG16qLV_6Zdv_wAALU8"]
[Thu Jul 30 14:24:26.924082 2026] [security2:error] [pid 1045527:tid 1045702] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/file61.php"] [unique_id "amuk6jbFEG16qLV_6Zdv_wAALU8"]
[Thu Jul 30 14:24:27.246850 2026] [security2:error] [pid 1045527:tid 1045750] [client 135.119.63.61:5641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/catalogadmin.php"] [unique_id "amuk6zbFEG16qLV_6ZdwCgAAAF0"]
[Thu Jul 30 14:24:27.366240 2026] [security2:error] [pid 1045527:tid 1045612] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-css.php"] [unique_id "amuk6zbFEG16qLV_6ZdwDQAAIVQ"]
[Thu Jul 30 14:24:27.366438 2026] [security2:error] [pid 1045527:tid 1045690] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-css.php"] [unique_id "amuk6zbFEG16qLV_6ZdwDQAAIVQ"]
[Thu Jul 30 14:24:27.393860 2026] [security2:error] [pid 1045527:tid 1045697] [client 74.248.33.8:10925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/file5.php"] [unique_id "amuk6zbFEG16qLV_6ZdwDwAAACg"]
[Thu Jul 30 14:24:27.443850 2026] [security2:error] [pid 1045527:tid 1045779] [client 172.213.232.128:33996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuk6zbFEG16qLV_6ZdwEgAAAHo"]
[Thu Jul 30 14:24:27.701333 2026] [core:error] [pid 1045527:tid 1045721] [client 223.85.251.55:52572] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Jul 30 14:24:27.782093 2026] [security2:error] [pid 1045527:tid 1045599] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-blink.php"] [unique_id "amuk6zbFEG16qLV_6ZdwGgAADkc"]
[Thu Jul 30 14:24:27.782277 2026] [security2:error] [pid 1045527:tid 1045671] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-blink.php"] [unique_id "amuk6zbFEG16qLV_6ZdwGgAADkc"]
[Thu Jul 30 14:24:28.018747 2026] [security2:error] [pid 1045527:tid 1045771] [client 135.119.63.61:52963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/catalogalfa.php"] [unique_id "amuk7DbFEG16qLV_6ZdwIgAAAHI"]
[Thu Jul 30 14:24:28.205857 2026] [security2:error] [pid 1045527:tid 1045595] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/txets.php"] [unique_id "amuk7DbFEG16qLV_6ZdwJwAADUM"]
[Thu Jul 30 14:24:28.206064 2026] [security2:error] [pid 1045527:tid 1045670] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/txets.php"] [unique_id "amuk7DbFEG16qLV_6ZdwJwAADUM"]
[Thu Jul 30 14:24:28.352383 2026] [security2:error] [pid 1045527:tid 1045776] [client 74.248.33.8:34191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuk7DbFEG16qLV_6ZdwLAAAAHc"]
[Thu Jul 30 14:24:28.598471 2026] [security2:error] [pid 1045527:tid 1045691] [client 172.213.232.128:34794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuk7DbFEG16qLV_6ZdwNAAAACI"]
[Thu Jul 30 14:24:28.611553 2026] [security2:error] [pid 1045527:tid 1045579] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/pucci.php"] [unique_id "amuk7DbFEG16qLV_6ZdwNQAAAjM"]
[Thu Jul 30 14:24:28.611721 2026] [security2:error] [pid 1045527:tid 1045659] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/pucci.php"] [unique_id "amuk7DbFEG16qLV_6ZdwNQAAAjM"]
[Thu Jul 30 14:24:28.752331 2026] [security2:error] [pid 1045527:tid 1045712] [client 135.119.63.61:5320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/catalogbypass.php"] [unique_id "amuk7DbFEG16qLV_6ZdwOQAAADc"]
[Thu Jul 30 14:24:28.938272 2026] [core:error] [pid 1045527:tid 1045702] [client 152.32.176.68:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:28.938297 2026] [core:error] [pid 1045527:tid 1045702] [client 152.32.176.68:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:29.018213 2026] [security2:error] [pid 1045527:tid 1045626] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/xwpg.php"] [unique_id "amuk7TbFEG16qLV_6ZdwRAAAK2I"]
[Thu Jul 30 14:24:29.018366 2026] [security2:error] [pid 1045527:tid 1045700] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/xwpg.php"] [unique_id "amuk7TbFEG16qLV_6ZdwRAAAK2I"]
[Thu Jul 30 14:24:29.244765 2026] [security2:error] [pid 1045527:tid 1045678] [client 172.202.44.182:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/admin.php"] [unique_id "amuk7TbFEG16qLV_6ZdwRwAAABU"]
[Thu Jul 30 14:24:29.431369 2026] [security2:error] [pid 1045527:tid 1045641] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ops.php"] [unique_id "amuk7TbFEG16qLV_6ZdwTAAAZnE"]
[Thu Jul 30 14:24:29.431524 2026] [security2:error] [pid 1045527:tid 1045759] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ops.php"] [unique_id "amuk7TbFEG16qLV_6ZdwTAAAZnE"]
[Thu Jul 30 14:24:29.444335 2026] [security2:error] [pid 1045527:tid 1045762] [client 135.119.63.61:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/catalogk.php"] [unique_id "amuk7TbFEG16qLV_6ZdwTQAAAGk"]
[Thu Jul 30 14:24:29.608098 2026] [security2:error] [pid 1045527:tid 1045732] [client 172.213.232.128:35069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuk7TbFEG16qLV_6ZdwWAAAAEs"]
[Thu Jul 30 14:24:29.880609 2026] [security2:error] [pid 1045527:tid 1045624] [remote 52.165.196.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "teknomalay.com"] [uri "/1.php"] [unique_id "amuk7TbFEG16qLV_6ZdwWgAAUmA"]
[Thu Jul 30 14:24:29.880723 2026] [security2:error] [pid 1045527:tid 1045624] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/1.php"] [unique_id "amuk7TbFEG16qLV_6ZdwWgAAUmA"]
[Thu Jul 30 14:24:29.880907 2026] [security2:error] [pid 1045527:tid 1045739] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/1.php"] [unique_id "amuk7TbFEG16qLV_6ZdwWgAAUmA"]
[Thu Jul 30 14:24:30.021731 2026] [security2:error] [pid 1045527:tid 1045615] [remote 74.7.227.39:44974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuk7jbFEG16qLV_6ZdwWwAAGVc"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/broken-link-checker
[Thu Jul 30 14:24:30.143233 2026] [security2:error] [pid 1045527:tid 1045710] [client 135.119.63.61:5358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/catalogwp.php"] [unique_id "amuk7jbFEG16qLV_6ZdwYgAAADU"]
[Thu Jul 30 14:24:30.231277 2026] [security2:error] [pid 1045527:tid 1045689] [client 66.132.195.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuk7TbFEG16qLV_6ZdwUgAAACA"]
[Thu Jul 30 14:24:30.322680 2026] [security2:error] [pid 1045527:tid 1045647] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/mac.php"] [unique_id "amuk7jbFEG16qLV_6ZdwaAAAAXc"]
[Thu Jul 30 14:24:30.322853 2026] [security2:error] [pid 1045527:tid 1045658] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/mac.php"] [unique_id "amuk7jbFEG16qLV_6ZdwaAAAAXc"]
[Thu Jul 30 14:24:30.463739 2026] [security2:error] [pid 1045527:tid 1045627] [remote 216.73.217.142:6575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuk7jbFEG16qLV_6ZdwaQAAG2M"]
[Thu Jul 30 14:24:30.475814 2026] [security2:error] [pid 1045527:tid 1045735] [client 185.191.171.9:37522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/12/29/uniao-europeia-decide-comprar-mais-100-milhoes-de-unidades-da-vacina-da-pfizer/"] [unique_id "amuk7jbFEG16qLV_6ZdwagAAAE4"]
[Thu Jul 30 14:24:30.475935 2026] [security2:error] [pid 1045527:tid 1045735] [client 185.191.171.9:37522] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/12/29/uniao-europeia-decide-comprar-mais-100-milhoes-de-unidades-da-vacina-da-pfizer/"] [unique_id "amuk7jbFEG16qLV_6ZdwagAAAE4"]
[Thu Jul 30 14:24:30.532617 2026] [security2:error] [pid 1045527:tid 1045669] [client 172.213.232.128:35057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuk7jbFEG16qLV_6ZdwawAAAAw"]
[Thu Jul 30 14:24:30.740932 2026] [security2:error] [pid 1045527:tid 1045642] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuk7jbFEG16qLV_6ZdwcgAAXHI"]
[Thu Jul 30 14:24:30.741152 2026] [security2:error] [pid 1045527:tid 1045749] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuk7jbFEG16qLV_6ZdwcgAAXHI"]
[Thu Jul 30 14:24:30.842500 2026] [security2:error] [pid 1045527:tid 1045741] [client 135.119.63.61:51416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/categories/about.php"] [unique_id "amuk7jbFEG16qLV_6ZdwdgAAAFQ"]
[Thu Jul 30 14:24:31.044763 2026] [security2:error] [pid 1045527:tid 1045649] [remote 57.141.0.26:40568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55997217192/feed/rss2/"] [unique_id "amuk7zbFEG16qLV_6ZdwdwAAF3k"]
[Thu Jul 30 14:24:31.146789 2026] [security2:error] [pid 1045527:tid 1045640] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/aa.php"] [unique_id "amuk7zbFEG16qLV_6ZdwewAAP3A"]
[Thu Jul 30 14:24:31.146962 2026] [security2:error] [pid 1045527:tid 1045720] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/aa.php"] [unique_id "amuk7zbFEG16qLV_6ZdwewAAP3A"]
[Thu Jul 30 14:24:31.323537 2026] [security2:error] [pid 1045527:tid 1045685] [client 172.213.232.128:38315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuk7zbFEG16qLV_6ZdwggAAABw"]
[Thu Jul 30 14:24:31.428804 2026] [core:notice] [pid 1045527:tid 1045772] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:31.433668 2026] [security2:error] [pid 1045527:tid 1045772] [client 195.23.32.200:59192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/feed/atom/"] [unique_id "amuk7zbFEG16qLV_6ZdwgwAAAHM"]
[Thu Jul 30 14:24:31.531333 2026] [security2:error] [pid 1045527:tid 1045775] [client 135.119.63.61:51411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/category.php"] [unique_id "amuk7zbFEG16qLV_6ZdwhAAAAHY"]
[Thu Jul 30 14:24:31.565342 2026] [security2:error] [pid 1045527:tid 1045531] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/xyn.php"] [unique_id "amuk7zbFEG16qLV_6ZdwhQAAHwM"]
[Thu Jul 30 14:24:31.565558 2026] [security2:error] [pid 1045527:tid 1045688] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/xyn.php"] [unique_id "amuk7zbFEG16qLV_6ZdwhQAAHwM"]
[Thu Jul 30 14:24:31.570259 2026] [security2:error] [pid 1045527:tid 1045706] [client 74.248.33.8:38070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/shell.php"] [unique_id "amuk7zbFEG16qLV_6ZdwhgAAADE"]
[Thu Jul 30 14:24:31.840732 2026] [security2:error] [pid 1045527:tid 1045712] [client 177.6.106.101:56871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk7zbFEG16qLV_6ZdwkAAAADc"]
[Thu Jul 30 14:24:31.841033 2026] [security2:error] [pid 1045527:tid 1045712] [client 177.6.106.101:56871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk7zbFEG16qLV_6ZdwkAAAADc"]
[Thu Jul 30 14:24:31.979512 2026] [security2:error] [pid 1045527:tid 1045645] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-wp.php"] [unique_id "amuk7zbFEG16qLV_6ZdwlAAAf3U"]
[Thu Jul 30 14:24:31.979694 2026] [security2:error] [pid 1045527:tid 1045784] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-wp.php"] [unique_id "amuk7zbFEG16qLV_6ZdwlAAAf3U"]
[Thu Jul 30 14:24:32.014967 2026] [security2:error] [pid 1045527:tid 1045726] [client 216.244.66.242:47388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingstarenterprises.com"] [uri "/robots.txt"] [unique_id "amuk8DbFEG16qLV_6ZdwlQAAAEU"]
[Thu Jul 30 14:24:32.015086 2026] [security2:error] [pid 1045527:tid 1045726] [client 216.244.66.242:47388] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kingstarenterprises.com"] [uri "/robots.txt"] [unique_id "amuk8DbFEG16qLV_6ZdwlQAAAEU"]
[Thu Jul 30 14:24:32.096665 2026] [security2:error] [pid 1045527:tid 1045763] [client 57.141.0.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuk7zbFEG16qLV_6ZdwjwAAAGo"]
[Thu Jul 30 14:24:32.107038 2026] [security2:error] [pid 1045527:tid 1045665] [client 66.249.68.169:61880] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "k2k.tech"] [uri "/robots.txt"] [unique_id "amuk8DbFEG16qLV_6ZdwmQAAAAg"]
[Thu Jul 30 14:24:32.240927 2026] [security2:error] [pid 1045527:tid 1045676] [client 135.119.63.61:52947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cay-van-phong/filemanager.php"] [unique_id "amuk8DbFEG16qLV_6ZdwngAAABM"]
[Thu Jul 30 14:24:32.395802 2026] [security2:error] [pid 1045527:tid 1045559] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/aw.php"] [unique_id "amuk8DbFEG16qLV_6ZdwoAAAKR8"]
[Thu Jul 30 14:24:32.395972 2026] [security2:error] [pid 1045527:tid 1045698] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/aw.php"] [unique_id "amuk8DbFEG16qLV_6ZdwoAAAKR8"]
[Thu Jul 30 14:24:32.675653 2026] [core:notice] [pid 1045527:tid 1045781] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:32.679469 2026] [security2:error] [pid 1045527:tid 1045781] [client 195.23.32.200:59266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/feed/atom/"] [unique_id "amuk8DbFEG16qLV_6ZdwpwAAAHw"]
[Thu Jul 30 14:24:32.805272 2026] [security2:error] [pid 1045527:tid 1045540] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/classwithtostring.php"] [unique_id "amuk8DbFEG16qLV_6ZdwrgAAeww"]
[Thu Jul 30 14:24:32.805435 2026] [security2:error] [pid 1045527:tid 1045780] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/classwithtostring.php"] [unique_id "amuk8DbFEG16qLV_6ZdwrgAAeww"]
[Thu Jul 30 14:24:32.919898 2026] [security2:error] [pid 1045527:tid 1045737] [client 172.213.232.128:16667] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.arabian-tours.com"] [uri "/1.php"] [unique_id "amuk8DbFEG16qLV_6ZdwrwAAAFA"]
[Thu Jul 30 14:24:32.920079 2026] [security2:error] [pid 1045527:tid 1045737] [client 172.213.232.128:16667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/1.php"] [unique_id "amuk8DbFEG16qLV_6ZdwrwAAAFA"]
[Thu Jul 30 14:24:32.941776 2026] [security2:error] [pid 1045527:tid 1045686] [client 135.119.63.61:52990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cay-van-phong/hehe.php"] [unique_id "amuk8DbFEG16qLV_6ZdwsAAAAB0"]
[Thu Jul 30 14:24:33.213764 2026] [security2:error] [pid 1045527:tid 1045561] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/yawa.php"] [unique_id "amuk8TbFEG16qLV_6ZdwtwAAKyE"]
[Thu Jul 30 14:24:33.213985 2026] [security2:error] [pid 1045527:tid 1045700] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/yawa.php"] [unique_id "amuk8TbFEG16qLV_6ZdwtwAAKyE"]
[Thu Jul 30 14:24:33.562291 2026] [security2:error] [pid 1045527:tid 1045551] [remote 116.179.37.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuk8TbFEG16qLV_6ZdwuwAAYhc"], referer: https://nafmedical.com/pages/about-tidy/
[Thu Jul 30 14:24:33.643423 2026] [security2:error] [pid 1045527:tid 1045530] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/sym403.php"] [unique_id "amuk8TbFEG16qLV_6ZdwvwAABQI"]
[Thu Jul 30 14:24:33.643601 2026] [security2:error] [pid 1045527:tid 1045662] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/sym403.php"] [unique_id "amuk8TbFEG16qLV_6ZdwvwAABQI"]
[Thu Jul 30 14:24:33.652754 2026] [security2:error] [pid 1045527:tid 1045759] [client 135.119.63.61:51397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cay-van-phong/skibidi.php"] [unique_id "amuk8TbFEG16qLV_6ZdwwAAAAGY"]
[Thu Jul 30 14:24:33.669004 2026] [security2:error] [pid 1045527:tid 1045538] [remote 116.179.37.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuk8TbFEG16qLV_6ZdwwQAAWwo"], referer: https://nafmedical.com/pages/about-tidy/
[Thu Jul 30 14:24:33.889536 2026] [security2:error] [pid 1045527:tid 1045701] [client 74.248.33.8:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/f35.php"] [unique_id "amuk8TbFEG16qLV_6ZdwzQAAACw"]
[Thu Jul 30 14:24:33.928995 2026] [proxy:error] [pid 1045527:tid 1045744] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:33.929078 2026] [proxy_http:error] [pid 1045527:tid 1045744] [client 54.87.222.253:9512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:33.929892 2026] [proxy:error] [pid 1045527:tid 1045744] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:33.929948 2026] [proxy_http:error] [pid 1045527:tid 1045744] [client 54.87.222.253:9512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:33.969497 2026] [proxy:error] [pid 1045527:tid 1045739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:33.969574 2026] [proxy_http:error] [pid 1045527:tid 1045739] [client 54.87.222.253:51939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:33.970143 2026] [proxy:error] [pid 1045527:tid 1045739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:33.970189 2026] [proxy_http:error] [pid 1045527:tid 1045739] [client 54.87.222.253:51939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:34.064641 2026] [core:notice] [pid 1045527:tid 1045565] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:34.070876 2026] [security2:error] [pid 1045527:tid 1045736] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "teknomalay.com"] [uri "/wp-admin/css/colors/blue.html"] [unique_id "amuk8jbFEG16qLV_6Zdw2gAATyU"]
[Thu Jul 30 14:24:34.286684 2026] [security2:error] [pid 1045527:tid 1045767] [client 195.23.32.200:59340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuk8TbFEG16qLV_6ZdwzAAAAG4"]
[Thu Jul 30 14:24:34.329499 2026] [core:notice] [pid 1045527:tid 1045566] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:34.345118 2026] [security2:error] [pid 1045527:tid 1045735] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amuk8jbFEG16qLV_6Zdw4wAATiY"]
[Thu Jul 30 14:24:34.361210 2026] [security2:error] [pid 1045527:tid 1045727] [client 135.119.63.61:5931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cbgd.php"] [unique_id "amuk8jbFEG16qLV_6Zdw5AAAAEY"]
[Thu Jul 30 14:24:34.826080 2026] [security2:error] [pid 1045527:tid 1045553] [remote 216.73.217.142:6575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuk8jbFEG16qLV_6Zdw7gAACRk"]
[Thu Jul 30 14:24:34.997048 2026] [security2:error] [pid 1045527:tid 1045661] [client 136.112.109.176:55382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "magicmooncorp.com"] [uri "/"] [unique_id "amuk8jbFEG16qLV_6Zdw8wAAAAQ"]
[Thu Jul 30 14:24:35.062840 2026] [security2:error] [pid 1045527:tid 1045761] [client 135.119.63.61:51421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cbrfo.php"] [unique_id "amuk8zbFEG16qLV_6Zdw9AAAAGg"]
[Thu Jul 30 14:24:35.391183 2026] [security2:error] [pid 1045527:tid 1045547] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/adminner.php"] [unique_id "amuk8zbFEG16qLV_6ZdxAgAACxM"]
[Thu Jul 30 14:24:35.391308 2026] [security2:error] [pid 1045527:tid 1045668] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/adminner.php"] [unique_id "amuk8zbFEG16qLV_6ZdxAgAACxM"]
[Thu Jul 30 14:24:35.744765 2026] [security2:error] [pid 1045527:tid 1045742] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuk8zbFEG16qLV_6Zdw-gAAAFU"]
[Thu Jul 30 14:24:35.769613 2026] [security2:error] [pid 1045527:tid 1045764] [client 135.119.63.61:31873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cc.php"] [unique_id "amuk8zbFEG16qLV_6ZdxCQAAAGs"]
[Thu Jul 30 14:24:35.906242 2026] [security2:error] [pid 1045527:tid 1045749] [client 98.93.205.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuk8jbFEG16qLV_6Zdw6gAAAFw"]
[Thu Jul 30 14:24:35.934185 2026] [security2:error] [pid 1045527:tid 1045586] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/yup.php"] [unique_id "amuk8zbFEG16qLV_6ZdxEQAAVDo"]
[Thu Jul 30 14:24:35.934410 2026] [security2:error] [pid 1045527:tid 1045741] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/yup.php"] [unique_id "amuk8zbFEG16qLV_6ZdxEQAAVDo"]
[Thu Jul 30 14:24:36.073771 2026] [security2:error] [pid 1045527:tid 1045686] [client 74.248.33.8:45185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/new.php"] [unique_id "amuk9DbFEG16qLV_6ZdxEwAAAB0"]
[Thu Jul 30 14:24:36.375699 2026] [proxy:error] [pid 1045527:tid 1045773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:36.375780 2026] [proxy_http:error] [pid 1045527:tid 1045773] [client 54.87.222.253:43040] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:36.376437 2026] [proxy:error] [pid 1045527:tid 1045773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:36.376501 2026] [proxy_http:error] [pid 1045527:tid 1045773] [client 54.87.222.253:43040] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:36.433960 2026] [proxy:error] [pid 1045527:tid 1045574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:36.434058 2026] [proxy_http:error] [pid 1045527:tid 1045574] [remote 74.7.230.5:51332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:36.435389 2026] [proxy:error] [pid 1045527:tid 1045574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:36.435461 2026] [proxy_http:error] [pid 1045527:tid 1045574] [remote 74.7.230.5:51332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:36.474893 2026] [security2:error] [pid 1045527:tid 1045682] [client 180.243.59.178:53373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk9DbFEG16qLV_6ZdxJAAAABk"]
[Thu Jul 30 14:24:36.475044 2026] [security2:error] [pid 1045527:tid 1045682] [client 180.243.59.178:53373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk9DbFEG16qLV_6ZdxJAAAABk"]
[Thu Jul 30 14:24:36.475952 2026] [security2:error] [pid 1045527:tid 1045698] [client 135.119.63.61:52959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/ccaef.php"] [unique_id "amuk9DbFEG16qLV_6ZdxJQAAACk"]
[Thu Jul 30 14:24:36.506651 2026] [security2:error] [pid 1045527:tid 1045567] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/config.json.php"] [unique_id "amuk9DbFEG16qLV_6ZdxKQAAfCc"]
[Thu Jul 30 14:24:36.506834 2026] [security2:error] [pid 1045527:tid 1045781] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/config.json.php"] [unique_id "amuk9DbFEG16qLV_6ZdxKQAAfCc"]
[Thu Jul 30 14:24:36.655527 2026] [security2:error] [pid 1045527:tid 1045751] [client 172.202.44.182:32056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuk9DbFEG16qLV_6ZdxKwAAAF4"]
[Thu Jul 30 14:24:36.787401 2026] [security2:error] [pid 1045527:tid 1045729] [client 172.213.232.128:38089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/admin.php"] [unique_id "amuk9DbFEG16qLV_6ZdxLwAAAEg"]
[Thu Jul 30 14:24:37.063439 2026] [core:notice] [pid 1045527:tid 1045556] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:37.065063 2026] [security2:error] [pid 1045527:tid 1045770] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "teknomalay.com"] [uri "/wp-includes/block-bindings.html"] [unique_id "amuk9TbFEG16qLV_6ZdxOwAAcRw"]
[Thu Jul 30 14:24:37.179236 2026] [security2:error] [pid 1045527:tid 1045685] [client 135.119.63.61:5365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/ccx/index.php"] [unique_id "amuk9TbFEG16qLV_6ZdxPAAAABw"]
[Thu Jul 30 14:24:37.234663 2026] [security2:error] [pid 1045527:tid 1045708] [client 98.93.205.121:45792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amuk9DbFEG16qLV_6ZdxFwAAMzk"]
[Thu Jul 30 14:24:37.461049 2026] [core:notice] [pid 1045527:tid 1045602] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:37.476435 2026] [security2:error] [pid 1045527:tid 1045723] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amuk9TbFEG16qLV_6ZdxRgAAQko"]
[Thu Jul 30 14:24:37.649410 2026] [security2:error] [pid 1045527:tid 1045720] [client 172.213.232.128:34797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/as.php"] [unique_id "amuk9TbFEG16qLV_6ZdxTQAAAD8"]
[Thu Jul 30 14:24:37.671517 2026] [security2:error] [pid 1045527:tid 1045765] [client 74.248.33.8:34218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/adminfuns.php"] [unique_id "amuk9TbFEG16qLV_6ZdxTgAAAGw"]
[Thu Jul 30 14:24:37.873240 2026] [security2:error] [pid 1045527:tid 1045749] [client 135.119.63.61:51449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cd.php"] [unique_id "amuk9TbFEG16qLV_6ZdxUwAAAFw"]
[Thu Jul 30 14:24:38.023431 2026] [security2:error] [pid 1045527:tid 1045618] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/2.php"] [unique_id "amuk9jbFEG16qLV_6ZdxWAAADVo"]
[Thu Jul 30 14:24:38.023673 2026] [security2:error] [pid 1045527:tid 1045670] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/2.php"] [unique_id "amuk9jbFEG16qLV_6ZdxWAAADVo"]
[Thu Jul 30 14:24:38.057421 2026] [security2:error] [pid 1045527:tid 1045577] [remote 74.7.243.224:36028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amuk9jbFEG16qLV_6ZdxWQAAHTE"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:24:38.154907 2026] [security2:error] [pid 1045527:tid 1045660] [client 172.202.44.182:51467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/m.php"] [unique_id "amuk9jbFEG16qLV_6ZdxXQAAAAM"]
[Thu Jul 30 14:24:38.275433 2026] [core:error] [pid 1045527:tid 1045735] [client 74.248.33.8:45198] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:38.275458 2026] [core:error] [pid 1045527:tid 1045735] [client 74.248.33.8:45198] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:38.285157 2026] [security2:error] [pid 1045527:tid 1045771] [client 74.7.244.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kbtfinancezambia.com"] [uri "/index.php"] [unique_id "amuk9DbFEG16qLV_6ZdxHwAAcio"]
[Thu Jul 30 14:24:38.285193 2026] [security2:error] [pid 1045527:tid 1045771] [client 74.7.244.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kbtfinancezambia.com"] [uri "/index.php"] [unique_id "amuk9DbFEG16qLV_6ZdxHwAAcio"]
[Thu Jul 30 14:24:38.431689 2026] [security2:error] [pid 1045527:tid 1045613] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/f35.update.php"] [unique_id "amuk9jbFEG16qLV_6ZdxYwAAfFU"]
[Thu Jul 30 14:24:38.431889 2026] [security2:error] [pid 1045527:tid 1045781] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/f35.update.php"] [unique_id "amuk9jbFEG16qLV_6ZdxYwAAfFU"]
[Thu Jul 30 14:24:38.583740 2026] [security2:error] [pid 1045527:tid 1045776] [client 135.119.63.61:31907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cdxadmin.php"] [unique_id "amuk9jbFEG16qLV_6ZdxagAAAHc"]
[Thu Jul 30 14:24:38.867812 2026] [security2:error] [pid 1045527:tid 1045632] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/k.php"] [unique_id "amuk9jbFEG16qLV_6ZdxbwAALWg"]
[Thu Jul 30 14:24:38.868078 2026] [security2:error] [pid 1045527:tid 1045702] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/k.php"] [unique_id "amuk9jbFEG16qLV_6ZdxbwAALWg"]
[Thu Jul 30 14:24:39.047366 2026] [security2:error] [pid 1045527:tid 1045752] [client 172.213.232.128:16427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/autoload_classmap.php"] [unique_id "amuk9zbFEG16qLV_6ZdxcwAAAF8"]
[Thu Jul 30 14:24:39.073949 2026] [core:error] [pid 1045527:tid 1045718] [client 74.248.33.8:10341] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:39.073968 2026] [core:error] [pid 1045527:tid 1045718] [client 74.248.33.8:10341] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:39.222894 2026] [security2:error] [pid 1045527:tid 1045746] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuk9jbFEG16qLV_6ZdxYgAAWVI"]
[Thu Jul 30 14:24:39.299500 2026] [security2:error] [pid 1045527:tid 1045688] [client 135.119.63.61:5361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cekidot/alf.php"] [unique_id "amuk9zbFEG16qLV_6ZdxewAAAB8"]
[Thu Jul 30 14:24:39.302485 2026] [core:notice] [pid 1045527:tid 1045587] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:39.307222 2026] [security2:error] [pid 1045527:tid 1045750] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "teknomalay.com"] [uri "/wp-admin/css.html"] [unique_id "amuk9zbFEG16qLV_6ZdxfAAAXTs"]
[Thu Jul 30 14:24:39.560618 2026] [core:notice] [pid 1045527:tid 1045606] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:39.576148 2026] [security2:error] [pid 1045527:tid 1045764] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amuk9zbFEG16qLV_6ZdxgwAAa04"]
[Thu Jul 30 14:24:39.874425 2026] [security2:error] [pid 1045527:tid 1045742] [client 74.248.33.8:34219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/fm.php"] [unique_id "amuk9zbFEG16qLV_6ZdxigAAAFU"]
[Thu Jul 30 14:24:40.018192 2026] [security2:error] [pid 1045527:tid 1045701] [client 135.119.63.61:31924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cekidot/mar.php"] [unique_id "amuk-DbFEG16qLV_6ZdxjgAAACw"]
[Thu Jul 30 14:24:40.023912 2026] [security2:error] [pid 1045527:tid 1045784] [client 172.213.232.128:16385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/back.php"] [unique_id "amuk-DbFEG16qLV_6ZdxkAAAAH8"]
[Thu Jul 30 14:24:40.268647 2026] [security2:error] [pid 1045527:tid 1045761] [client 172.202.44.182:32040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuk-DbFEG16qLV_6ZdxiwAAAGg"]
[Thu Jul 30 14:24:40.315696 2026] [security2:error] [pid 1045527:tid 1045634] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/spadex.php"] [unique_id "amuk-DbFEG16qLV_6ZdxlAAAdGo"]
[Thu Jul 30 14:24:40.315868 2026] [security2:error] [pid 1045527:tid 1045773] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/spadex.php"] [unique_id "amuk-DbFEG16qLV_6ZdxlAAAdGo"]
[Thu Jul 30 14:24:40.516372 2026] [security2:error] [pid 1045527:tid 1045623] [remote 216.73.217.142:18496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuk-DbFEG16qLV_6ZdxmAAAVl8"]
[Thu Jul 30 14:24:40.725742 2026] [security2:error] [pid 1045527:tid 1045579] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/mg.php"] [unique_id "amuk-DbFEG16qLV_6ZdxogAACTM"]
[Thu Jul 30 14:24:40.726004 2026] [security2:error] [pid 1045527:tid 1045666] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/mg.php"] [unique_id "amuk-DbFEG16qLV_6ZdxogAACTM"]
[Thu Jul 30 14:24:40.762514 2026] [security2:error] [pid 1045527:tid 1045660] [client 135.119.63.61:51437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cekidot/mr.php"] [unique_id "amuk-DbFEG16qLV_6ZdxpQAAAAM"]
[Thu Jul 30 14:24:41.054755 2026] [security2:error] [pid 1045527:tid 1045588] [remote 97.74.87.194:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.eow.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuk-TbFEG16qLV_6ZdxrwAAETw"]
[Thu Jul 30 14:24:41.139996 2026] [security2:error] [pid 1045527:tid 1045626] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/fnstall.php"] [unique_id "amuk-TbFEG16qLV_6ZdxtQAAL2I"]
[Thu Jul 30 14:24:41.140191 2026] [security2:error] [pid 1045527:tid 1045704] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/fnstall.php"] [unique_id "amuk-TbFEG16qLV_6ZdxtQAAL2I"]
[Thu Jul 30 14:24:41.298362 2026] [core:error] [pid 1045527:tid 1045737] [client 74.248.33.8:34187] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:41.298385 2026] [core:error] [pid 1045527:tid 1045737] [client 74.248.33.8:34187] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:41.365005 2026] [security2:error] [pid 1045527:tid 1045732] [client 172.213.232.128:34802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuk-TbFEG16qLV_6ZdxuQAAAEs"]
[Thu Jul 30 14:24:41.461391 2026] [security2:error] [pid 1045527:tid 1045733] [client 135.119.63.61:31899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cepair/doc.php"] [unique_id "amuk-TbFEG16qLV_6ZdxvQAAAEw"]
[Thu Jul 30 14:24:41.562919 2026] [security2:error] [pid 1045527:tid 1045641] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ortasekerli1.php"] [unique_id "amuk-TbFEG16qLV_6ZdxvgAAM3E"]
[Thu Jul 30 14:24:41.563143 2026] [security2:error] [pid 1045527:tid 1045708] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ortasekerli1.php"] [unique_id "amuk-TbFEG16qLV_6ZdxvgAAM3E"]
[Thu Jul 30 14:24:41.567941 2026] [security2:error] [pid 1045527:tid 1045724] [client 172.202.44.182:26504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/classwithtostring.php"] [unique_id "amuk-TbFEG16qLV_6ZdxvwAAAEM"]
[Thu Jul 30 14:24:42.018476 2026] [security2:error] [pid 1045527:tid 1045608] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/sump1.php"] [unique_id "amuk-jbFEG16qLV_6ZdxyQAALFA"]
[Thu Jul 30 14:24:42.018694 2026] [security2:error] [pid 1045527:tid 1045701] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/sump1.php"] [unique_id "amuk-jbFEG16qLV_6ZdxyQAALFA"]
[Thu Jul 30 14:24:42.135334 2026] [security2:error] [pid 1045527:tid 1045676] [client 107.20.255.194:43629] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2018/06/WhatsApp-Image-2018-06-30-at-21.41.51-1024x768.jpeg"] [unique_id "amuk-jbFEG16qLV_6Zdx0AAAABM"]
[Thu Jul 30 14:24:42.144626 2026] [security2:error] [pid 1045527:tid 1045714] [client 172.213.232.128:16485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/c/flower.php"] [unique_id "amuk-jbFEG16qLV_6Zdx0QAAADk"]
[Thu Jul 30 14:24:42.214784 2026] [security2:error] [pid 1045527:tid 1045741] [client 135.119.63.61:51420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/certificates/plugins.php"] [unique_id "amuk-jbFEG16qLV_6Zdx1QAAAFQ"]
[Thu Jul 30 14:24:42.429024 2026] [security2:error] [pid 1045527:tid 1045688] [client 177.6.106.101:57232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk-jbFEG16qLV_6Zdx1gAAAB8"]
[Thu Jul 30 14:24:42.431132 2026] [security2:error] [pid 1045527:tid 1045688] [client 177.6.106.101:57232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk-jbFEG16qLV_6Zdx1gAAAB8"]
[Thu Jul 30 14:24:42.457814 2026] [security2:error] [pid 1045527:tid 1045615] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ops.php"] [unique_id "amuk-jbFEG16qLV_6Zdx1wAAQVc"]
[Thu Jul 30 14:24:42.457960 2026] [security2:error] [pid 1045527:tid 1045722] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ops.php"] [unique_id "amuk-jbFEG16qLV_6Zdx1wAAQVc"]
[Thu Jul 30 14:24:42.515496 2026] [security2:error] [pid 1045527:tid 1045644] [remote 20.54.134.42:2387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koriusa.info"] [uri "/wp-login.php"] [unique_id "amuk-jbFEG16qLV_6Zdx3gAAcXQ"]
[Thu Jul 30 14:24:42.648847 2026] [security2:error] [pid 1045527:tid 1045749] [client 172.202.44.182:32016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/gmo.php"] [unique_id "amuk-jbFEG16qLV_6Zdx4wAAAFw"]
[Thu Jul 30 14:24:42.692111 2026] [security2:error] [pid 1045527:tid 1045683] [client 74.248.33.8:38042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/file.php"] [unique_id "amuk-jbFEG16qLV_6Zdx5wAAABo"]
[Thu Jul 30 14:24:42.833601 2026] [security2:error] [pid 1045527:tid 1045665] [client 172.213.232.128:35655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/c/xleet.php"] [unique_id "amuk-jbFEG16qLV_6Zdx6AAAAAg"]
[Thu Jul 30 14:24:42.870988 2026] [security2:error] [pid 1045527:tid 1045539] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-post-data.php"] [unique_id "amuk-jbFEG16qLV_6Zdx6QAAZAs"]
[Thu Jul 30 14:24:42.871247 2026] [security2:error] [pid 1045527:tid 1045757] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-post-data.php"] [unique_id "amuk-jbFEG16qLV_6Zdx6QAAZAs"]
[Thu Jul 30 14:24:42.925085 2026] [security2:error] [pid 1045527:tid 1045729] [client 135.119.63.61:52949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cf.php"] [unique_id "amuk-jbFEG16qLV_6Zdx6gAAAEg"]
[Thu Jul 30 14:24:43.426387 2026] [security2:error] [pid 1045527:tid 1045649] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/root.php"] [unique_id "amuk-zbFEG16qLV_6Zdx9QAAMXk"]
[Thu Jul 30 14:24:43.426582 2026] [security2:error] [pid 1045527:tid 1045706] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/root.php"] [unique_id "amuk-zbFEG16qLV_6Zdx9QAAMXk"]
[Thu Jul 30 14:24:43.617348 2026] [security2:error] [pid 1045527:tid 1045772] [client 135.119.63.61:31890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cfile.php"] [unique_id "amuk-zbFEG16qLV_6Zdx-gAAAHM"]
[Thu Jul 30 14:24:43.737838 2026] [core:error] [pid 1045527:tid 1045750] [client 74.248.33.8:44520] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:43.737862 2026] [core:error] [pid 1045527:tid 1045750] [client 74.248.33.8:44520] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:43.800670 2026] [security2:error] [pid 1045527:tid 1045662] [client 172.202.44.182:32024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuk-zbFEG16qLV_6ZdyBQAAAAU"]
[Thu Jul 30 14:24:43.865498 2026] [security2:error] [pid 1045527:tid 1045531] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/v543.php"] [unique_id "amuk-zbFEG16qLV_6ZdyBgAAaQM"]
[Thu Jul 30 14:24:43.865727 2026] [security2:error] [pid 1045527:tid 1045762] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/v543.php"] [unique_id "amuk-zbFEG16qLV_6ZdyBgAAaQM"]
[Thu Jul 30 14:24:44.304240 2026] [security2:error] [pid 1045527:tid 1045645] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/sixxis.php"] [unique_id "amuk_DbFEG16qLV_6ZdyEAAAVHU"]
[Thu Jul 30 14:24:44.304541 2026] [security2:error] [pid 1045527:tid 1045741] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/sixxis.php"] [unique_id "amuk_DbFEG16qLV_6ZdyEAAAVHU"]
[Thu Jul 30 14:24:44.326991 2026] [security2:error] [pid 1045527:tid 1045676] [client 135.119.63.61:52978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cgi-binadmin.php"] [unique_id "amuk_DbFEG16qLV_6ZdyEQAAABM"]
[Thu Jul 30 14:24:44.480497 2026] [security2:error] [pid 1045527:tid 1045713] [client 172.213.232.128:35705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/classwithtostring.php"] [unique_id "amuk_DbFEG16qLV_6ZdyEgAAADg"]
[Thu Jul 30 14:24:44.739741 2026] [security2:error] [pid 1045527:tid 1045536] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ip.php"] [unique_id "amuk_DbFEG16qLV_6ZdyFgAAHQg"]
[Thu Jul 30 14:24:44.739946 2026] [security2:error] [pid 1045527:tid 1045686] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ip.php"] [unique_id "amuk_DbFEG16qLV_6ZdyFgAAHQg"]
[Thu Jul 30 14:24:44.797137 2026] [security2:error] [pid 1045527:tid 1045766] [client 172.202.44.182:19520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-the.php"] [unique_id "amuk_DbFEG16qLV_6ZdyGwAAAG0"]
[Thu Jul 30 14:24:44.839501 2026] [security2:error] [pid 1045527:tid 1045559] [remote 216.73.217.142:18496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuk_DbFEG16qLV_6ZdyHgAAGh8"]
[Thu Jul 30 14:24:45.024851 2026] [security2:error] [pid 1045527:tid 1045716] [client 135.119.63.61:52977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cgi-binalfa.php"] [unique_id "amuk_TbFEG16qLV_6ZdyIQAAADs"]
[Thu Jul 30 14:24:45.292738 2026] [security2:error] [pid 1045527:tid 1045684] [client 172.213.232.128:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/content.php"] [unique_id "amuk_TbFEG16qLV_6ZdyKwAAABs"]
[Thu Jul 30 14:24:45.312238 2026] [security2:error] [pid 1045527:tid 1045540] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/kq1.php"] [unique_id "amuk_TbFEG16qLV_6ZdyLAAALww"]
[Thu Jul 30 14:24:45.312411 2026] [security2:error] [pid 1045527:tid 1045704] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/kq1.php"] [unique_id "amuk_TbFEG16qLV_6ZdyLAAALww"]
[Thu Jul 30 14:24:45.721434 2026] [security2:error] [pid 1045527:tid 1045674] [client 172.202.44.182:51502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/404.php"] [unique_id "amuk_TbFEG16qLV_6ZdyNQAAABE"]
[Thu Jul 30 14:24:45.736670 2026] [security2:error] [pid 1045527:tid 1045733] [client 135.119.63.61:51433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cgi-binbypass.php"] [unique_id "amuk_TbFEG16qLV_6ZdyNgAAAEw"]
[Thu Jul 30 14:24:45.747825 2026] [security2:error] [pid 1045527:tid 1045534] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/fw/faiyy.php"] [unique_id "amuk_TbFEG16qLV_6ZdyNwAACwY"]
[Thu Jul 30 14:24:45.748038 2026] [security2:error] [pid 1045527:tid 1045668] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/fw/faiyy.php"] [unique_id "amuk_TbFEG16qLV_6ZdyNwAACwY"]
[Thu Jul 30 14:24:46.025336 2026] [security2:error] [pid 1045527:tid 1045781] [client 82.102.27.195:60064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuk_jbFEG16qLV_6ZdyQgAAAHw"]
[Thu Jul 30 14:24:46.025444 2026] [security2:error] [pid 1045527:tid 1045781] [client 82.102.27.195:60064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuk_jbFEG16qLV_6ZdyQgAAAHw"]
[Thu Jul 30 14:24:46.210641 2026] [security2:error] [pid 1045527:tid 1045646] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/h02ugyh.php"] [unique_id "amuk_jbFEG16qLV_6ZdySAAAUnY"]
[Thu Jul 30 14:24:46.210842 2026] [security2:error] [pid 1045527:tid 1045739] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/h02ugyh.php"] [unique_id "amuk_jbFEG16qLV_6ZdySAAAUnY"]
[Thu Jul 30 14:24:46.429372 2026] [security2:error] [pid 1045527:tid 1045701] [client 135.119.63.61:5350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/cgi-bink.php"] [unique_id "amuk_jbFEG16qLV_6ZdyTwAAACw"]
[Thu Jul 30 14:24:46.571707 2026] [security2:error] [pid 1045527:tid 1045784] [client 219.76.254.140:21391] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuk_jbFEG16qLV_6ZdyUAAAAH8"]
[Thu Jul 30 14:24:46.642912 2026] [security2:error] [pid 1045527:tid 1045545] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-temp.php"] [unique_id "amuk_jbFEG16qLV_6ZdyVgAAQRE"]
[Thu Jul 30 14:24:46.643091 2026] [security2:error] [pid 1045527:tid 1045722] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-temp.php"] [unique_id "amuk_jbFEG16qLV_6ZdyVgAAQRE"]
[Thu Jul 30 14:24:46.723750 2026] [security2:error] [pid 1045527:tid 1045742] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuk_jbFEG16qLV_6ZdyRgAAVQo"]
[Thu Jul 30 14:24:47.125109 2026] [security2:error] [pid 1045527:tid 1045564] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/cong.php"] [unique_id "amuk_zbFEG16qLV_6ZdyYAAALiQ"]
[Thu Jul 30 14:24:47.125300 2026] [security2:error] [pid 1045527:tid 1045703] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-content/cong.php"] [unique_id "amuk_zbFEG16qLV_6ZdyYAAALiQ"]
[Thu Jul 30 14:24:47.297964 2026] [security2:error] [pid 1045527:tid 1045687] [client 23.23.99.55:55019] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2019/08/governadoress-300x120.jpg"] [unique_id "amuk_zbFEG16qLV_6ZdyZAAAAB4"]
[Thu Jul 30 14:24:47.422442 2026] [security2:error] [pid 1045527:tid 1045727] [client 172.202.44.182:34247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/init.php"] [unique_id "amuk_zbFEG16qLV_6ZdyagAAAEY"]
[Thu Jul 30 14:24:47.441186 2026] [security2:error] [pid 1045527:tid 1045754] [client 180.243.59.178:53942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk_zbFEG16qLV_6ZdybQAAAGE"]
[Thu Jul 30 14:24:47.441339 2026] [security2:error] [pid 1045527:tid 1045754] [client 180.243.59.178:53942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuk_zbFEG16qLV_6ZdybQAAAGE"]
[Thu Jul 30 14:24:47.536627 2026] [core:notice] [pid 1045527:tid 1045560] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:47.541079 2026] [security2:error] [pid 1045527:tid 1045737] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "teknomalay.com"] [uri "/wp-admin/js/widget.html"] [unique_id "amuk_zbFEG16qLV_6ZdybwAAUCA"]
[Thu Jul 30 14:24:47.802092 2026] [core:notice] [pid 1045527:tid 1045584] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:47.818438 2026] [security2:error] [pid 1045527:tid 1045759] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amuk_zbFEG16qLV_6ZdycwAAZjg"]
[Thu Jul 30 14:24:48.388700 2026] [security2:error] [pid 1045527:tid 1045563] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/css/index.php"] [unique_id "amulADbFEG16qLV_6ZdygAAAQyM"]
[Thu Jul 30 14:24:48.388894 2026] [security2:error] [pid 1045527:tid 1045724] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-includes/css/index.php"] [unique_id "amulADbFEG16qLV_6ZdygAAAQyM"]
[Thu Jul 30 14:24:48.847037 2026] [security2:error] [pid 1045527:tid 1045562] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/jj.php"] [unique_id "amulADbFEG16qLV_6ZdyjgAAKiI"]
[Thu Jul 30 14:24:48.847200 2026] [security2:error] [pid 1045527:tid 1045699] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/jj.php"] [unique_id "amulADbFEG16qLV_6ZdyjgAAKiI"]
[Thu Jul 30 14:24:49.257309 2026] [security2:error] [pid 1045527:tid 1045574] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amulATbFEG16qLV_6ZdylQAAay4"]
[Thu Jul 30 14:24:49.257552 2026] [security2:error] [pid 1045527:tid 1045764] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amulATbFEG16qLV_6ZdylQAAay4"]
[Thu Jul 30 14:24:49.301045 2026] [core:notice] [pid 1045527:tid 1045573] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:49.718895 2026] [security2:error] [pid 1045527:tid 1045593] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/xpwer1.php"] [unique_id "amulATbFEG16qLV_6ZdypQAAG0E"]
[Thu Jul 30 14:24:49.719096 2026] [security2:error] [pid 1045527:tid 1045684] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/xpwer1.php"] [unique_id "amulATbFEG16qLV_6ZdypQAAG0E"]
[Thu Jul 30 14:24:49.875358 2026] [security2:error] [pid 1045527:tid 1045784] [client 172.202.44.182:32010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/file5.php"] [unique_id "amulATbFEG16qLV_6ZdyqQAAAH8"]
[Thu Jul 30 14:24:50.189800 2026] [security2:error] [pid 1045527:tid 1045602] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/flox.php"] [unique_id "amulAjbFEG16qLV_6ZdysQAAeko"]
[Thu Jul 30 14:24:50.190022 2026] [security2:error] [pid 1045527:tid 1045779] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/flox.php"] [unique_id "amulAjbFEG16qLV_6ZdysQAAeko"]
[Thu Jul 30 14:24:50.368788 2026] [core:notice] [pid 1045527:tid 1045677] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:50.509602 2026] [security2:error] [pid 1045527:tid 1045568] [remote 216.73.217.142:54534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulAjbFEG16qLV_6ZdytgAAYCg"]
[Thu Jul 30 14:24:50.613580 2026] [security2:error] [pid 1045527:tid 1045618] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/popo.php"] [unique_id "amulAjbFEG16qLV_6ZdyugAAH1o"]
[Thu Jul 30 14:24:50.613759 2026] [security2:error] [pid 1045527:tid 1045688] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/popo.php"] [unique_id "amulAjbFEG16qLV_6ZdyugAAH1o"]
[Thu Jul 30 14:24:51.068753 2026] [security2:error] [pid 1045527:tid 1045549] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/yas.php"] [unique_id "amulAzbFEG16qLV_6ZdyxgAAMRU"]
[Thu Jul 30 14:24:51.069042 2026] [security2:error] [pid 1045527:tid 1045706] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/yas.php"] [unique_id "amulAzbFEG16qLV_6ZdyxgAAMRU"]
[Thu Jul 30 14:24:51.079535 2026] [security2:error] [pid 1045527:tid 1045635] [remote 72.167.132.114:42832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/wp-login.php"] [unique_id "amulAzbFEG16qLV_6ZdyxwAAb2s"]
[Thu Jul 30 14:24:51.103439 2026] [security2:error] [pid 1045527:tid 1045668] [client 3.133.226.214:52706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amulAjbFEG16qLV_6ZdyxAAAAAs"], referer: https://globalmarks.pk/
[Thu Jul 30 14:24:51.245930 2026] [security2:error] [pid 1045527:tid 1045777] [client 172.213.232.128:38111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/doc.php"] [unique_id "amulAzbFEG16qLV_6Zdy0QAAAHg"]
[Thu Jul 30 14:24:51.496782 2026] [security2:error] [pid 1045527:tid 1045607] [remote 57.141.0.58:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/view/9369/4144"] [unique_id "amulAzbFEG16qLV_6Zdy1gAAV08"]
[Thu Jul 30 14:24:51.506699 2026] [security2:error] [pid 1045527:tid 1045612] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/water.php"] [unique_id "amulAzbFEG16qLV_6Zdy1wAAAVQ"]
[Thu Jul 30 14:24:51.506862 2026] [security2:error] [pid 1045527:tid 1045658] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/water.php"] [unique_id "amulAzbFEG16qLV_6Zdy1wAAAVQ"]
[Thu Jul 30 14:24:51.936499 2026] [security2:error] [pid 1045527:tid 1045604] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/nano.php"] [unique_id "amulAzbFEG16qLV_6Zdy3gAACkw"]
[Thu Jul 30 14:24:51.936701 2026] [security2:error] [pid 1045527:tid 1045667] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/nano.php"] [unique_id "amulAzbFEG16qLV_6Zdy3gAACkw"]
[Thu Jul 30 14:24:51.970290 2026] [security2:error] [pid 1045527:tid 1045770] [client 82.102.27.195:47464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amulAzbFEG16qLV_6Zdy4gAAAHE"]
[Thu Jul 30 14:24:51.970398 2026] [security2:error] [pid 1045527:tid 1045770] [client 82.102.27.195:47464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amulAzbFEG16qLV_6Zdy4gAAAHE"]
[Thu Jul 30 14:24:52.271482 2026] [security2:error] [pid 1045527:tid 1045772] [client 172.213.232.128:33062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/dropdown.php"] [unique_id "amulBDbFEG16qLV_6Zdy6QAAAHM"]
[Thu Jul 30 14:24:52.379944 2026] [security2:error] [pid 1045527:tid 1045599] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/moon.php"] [unique_id "amulBDbFEG16qLV_6Zdy6gAAf0c"]
[Thu Jul 30 14:24:52.380214 2026] [security2:error] [pid 1045527:tid 1045784] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/moon.php"] [unique_id "amulBDbFEG16qLV_6Zdy6gAAf0c"]
[Thu Jul 30 14:24:52.531631 2026] [security2:error] [pid 1045527:tid 1045701] [client 172.202.44.182:19562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amulBDbFEG16qLV_6Zdy7gAAACw"]
[Thu Jul 30 14:24:52.878620 2026] [security2:error] [pid 1045527:tid 1045617] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-info.php"] [unique_id "amulBDbFEG16qLV_6Zdy-QAABFk"]
[Thu Jul 30 14:24:52.878802 2026] [security2:error] [pid 1045527:tid 1045661] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-info.php"] [unique_id "amulBDbFEG16qLV_6Zdy-QAABFk"]
[Thu Jul 30 14:24:52.927514 2026] [security2:error] [pid 1045527:tid 1045730] [client 74.248.33.8:44485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/bolt.php"] [unique_id "amulBDbFEG16qLV_6Zdy_AAAAEk"]
[Thu Jul 30 14:24:53.292023 2026] [security2:error] [pid 1045527:tid 1045623] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/file5.php"] [unique_id "amulBTbFEG16qLV_6ZdzAQAAWl8"]
[Thu Jul 30 14:24:53.292273 2026] [security2:error] [pid 1045527:tid 1045747] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/file5.php"] [unique_id "amulBTbFEG16qLV_6ZdzAQAAWl8"]
[Thu Jul 30 14:24:53.527425 2026] [security2:error] [pid 1045527:tid 1045746] [client 172.202.44.182:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/shell.php"] [unique_id "amulBTbFEG16qLV_6ZdzCAAAAFk"]
[Thu Jul 30 14:24:53.704370 2026] [security2:error] [pid 1045527:tid 1045579] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/2000.php"] [unique_id "amulBTbFEG16qLV_6ZdzCQAAAzM"]
[Thu Jul 30 14:24:53.704587 2026] [security2:error] [pid 1045527:tid 1045660] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/2000.php"] [unique_id "amulBTbFEG16qLV_6ZdzCQAAAzM"]
[Thu Jul 30 14:24:53.731724 2026] [security2:error] [pid 1045527:tid 1045687] [client 172.213.232.128:30126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/ee.php"] [unique_id "amulBTbFEG16qLV_6ZdzCgAAAB4"]
[Thu Jul 30 14:24:54.111077 2026] [security2:error] [pid 1045527:tid 1045626] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/122.php"] [unique_id "amulBjbFEG16qLV_6ZdzFQAADWI"]
[Thu Jul 30 14:24:54.111315 2026] [security2:error] [pid 1045527:tid 1045670] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/122.php"] [unique_id "amulBjbFEG16qLV_6ZdzFQAADWI"]
[Thu Jul 30 14:24:54.131020 2026] [security2:error] [pid 1045527:tid 1045760] [client 74.248.33.8:10889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/3.php"] [unique_id "amulBjbFEG16qLV_6ZdzFgAAAGc"]
[Thu Jul 30 14:24:54.522780 2026] [security2:error] [pid 1045527:tid 1045636] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/mds.php"] [unique_id "amulBjbFEG16qLV_6ZdzIwAAd2w"]
[Thu Jul 30 14:24:54.522946 2026] [security2:error] [pid 1045527:tid 1045776] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/mds.php"] [unique_id "amulBjbFEG16qLV_6ZdzIwAAd2w"]
[Thu Jul 30 14:24:54.620061 2026] [security2:error] [pid 1045527:tid 1045729] [client 172.237.109.114:53234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulBjbFEG16qLV_6ZdzFAAAAEg"]
[Thu Jul 30 14:24:54.844003 2026] [security2:error] [pid 1045527:tid 1045608] [remote 216.73.217.142:54534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulBjbFEG16qLV_6ZdzKQAAcVA"]
[Thu Jul 30 14:24:54.935767 2026] [security2:error] [pid 1045527:tid 1045637] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/zc-208.php"] [unique_id "amulBjbFEG16qLV_6ZdzLQAAAm0"]
[Thu Jul 30 14:24:54.935937 2026] [security2:error] [pid 1045527:tid 1045659] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/zc-208.php"] [unique_id "amulBjbFEG16qLV_6ZdzLQAAAm0"]
[Thu Jul 30 14:24:55.069254 2026] [core:notice] [pid 1045527:tid 1045644] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:55.152440 2026] [security2:error] [pid 1045527:tid 1045691] [client 74.248.33.8:44483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/222.php"] [unique_id "amulBzbFEG16qLV_6ZdzMgAAACI"]
[Thu Jul 30 14:24:55.341322 2026] [security2:error] [pid 1045527:tid 1045622] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/sid4.php"] [unique_id "amulBzbFEG16qLV_6ZdzMwAAI14"]
[Thu Jul 30 14:24:55.341615 2026] [security2:error] [pid 1045527:tid 1045692] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/sid4.php"] [unique_id "amulBzbFEG16qLV_6ZdzMwAAI14"]
[Thu Jul 30 14:24:55.366461 2026] [security2:error] [pid 1045527:tid 1045735] [client 172.213.232.128:35658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/flower.php"] [unique_id "amulBzbFEG16qLV_6ZdzNAAAAE4"]
[Thu Jul 30 14:24:55.629830 2026] [core:notice] [pid 1045527:tid 1045664] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:55.749956 2026] [core:notice] [pid 1045527:tid 1045597] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:55.751824 2026] [security2:error] [pid 1045527:tid 1045779] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "teknomalay.com"] [uri "/wp-includes/l10n.html"] [unique_id "amulBzbFEG16qLV_6ZdzQgAAekU"]
[Thu Jul 30 14:24:56.027642 2026] [core:notice] [pid 1045527:tid 1045642] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:56.043601 2026] [security2:error] [pid 1045527:tid 1045747] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amulCDbFEG16qLV_6ZdzSQAAWnI"]
[Thu Jul 30 14:24:56.100676 2026] [security2:error] [pid 1045527:tid 1045649] [remote 57.141.0.7:36942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amulCDbFEG16qLV_6ZdzSgAAPnk"]
[Thu Jul 30 14:24:56.283611 2026] [core:error] [pid 1045527:tid 1045647] [remote 74.7.244.23:43376] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:56.283643 2026] [core:error] [pid 1045527:tid 1045647] [remote 74.7.244.23:43376] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:24:56.283866 2026] [security2:error] [pid 1045527:tid 1045671] [client 74.7.244.23:43376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-dc09cfb9.jud.zzt.temporary.site"] [uri "/website_dc09cfb9/index.php"] [unique_id "amulCDbFEG16qLV_6ZdzTgAADnc"]
[Thu Jul 30 14:24:56.446236 2026] [proxy:error] [pid 1045527:tid 1045781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:56.446309 2026] [proxy_http:error] [pid 1045527:tid 1045781] [client 34.233.129.35:23779] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:56.446389 2026] [proxy:error] [pid 1045527:tid 1045752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:56.446447 2026] [proxy_http:error] [pid 1045527:tid 1045752] [client 34.233.129.35:51889] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:56.446895 2026] [proxy:error] [pid 1045527:tid 1045781] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:56.446938 2026] [proxy_http:error] [pid 1045527:tid 1045781] [client 34.233.129.35:23779] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:56.447191 2026] [proxy:error] [pid 1045527:tid 1045752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:24:56.447244 2026] [proxy_http:error] [pid 1045527:tid 1045752] [client 34.233.129.35:51889] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:24:56.481698 2026] [security2:error] [pid 1045527:tid 1045724] [client 172.213.232.128:30809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/gecko-new.php"] [unique_id "amulCDbFEG16qLV_6ZdzYQAAAEM"]
[Thu Jul 30 14:24:56.560219 2026] [security2:error] [pid 1045527:tid 1045529] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wmore1.php"] [unique_id "amulCDbFEG16qLV_6ZdzZQAAQQE"]
[Thu Jul 30 14:24:56.560405 2026] [security2:error] [pid 1045527:tid 1045722] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wmore1.php"] [unique_id "amulCDbFEG16qLV_6ZdzZQAAQQE"]
[Thu Jul 30 14:24:56.668719 2026] [security2:error] [pid 1045527:tid 1045748] [client 172.202.44.182:19548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/f35.php"] [unique_id "amulCDbFEG16qLV_6ZdzagAAAFs"]
[Thu Jul 30 14:24:56.986031 2026] [security2:error] [pid 1045527:tid 1045533] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/solo1.php"] [unique_id "amulCDbFEG16qLV_6ZdzcQAANgU"]
[Thu Jul 30 14:24:56.986213 2026] [security2:error] [pid 1045527:tid 1045711] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/solo1.php"] [unique_id "amulCDbFEG16qLV_6ZdzcQAANgU"]
[Thu Jul 30 14:24:57.394646 2026] [core:notice] [pid 1045527:tid 1045535] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:57.397171 2026] [security2:error] [pid 1045527:tid 1045718] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "teknomalay.com"] [uri "/wp-includes/assets.html"] [unique_id "amulCTbFEG16qLV_6ZdzfgAAPQc"]
[Thu Jul 30 14:24:57.651571 2026] [core:notice] [pid 1045527:tid 1045541] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:57.667106 2026] [security2:error] [pid 1045527:tid 1045708] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amulCTbFEG16qLV_6ZdziAAAMw0"]
[Thu Jul 30 14:24:57.897637 2026] [security2:error] [pid 1045527:tid 1045726] [client 180.243.59.178:54482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulCTbFEG16qLV_6ZdzjwAAAEU"]
[Thu Jul 30 14:24:57.897774 2026] [security2:error] [pid 1045527:tid 1045726] [client 180.243.59.178:54482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulCTbFEG16qLV_6ZdzjwAAAEU"]
[Thu Jul 30 14:24:58.207254 2026] [core:notice] [pid 1045527:tid 1045653] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:58.209708 2026] [security2:error] [pid 1045527:tid 1045745] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "teknomalay.com"] [uri "/wp-includes/css.html"] [unique_id "amulCjbFEG16qLV_6ZdzlgAAWH0"]
[Thu Jul 30 14:24:58.485189 2026] [security2:error] [pid 1045527:tid 1045734] [client 138.246.253.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amulCDbFEG16qLV_6ZdzbAAATQA"]
[Thu Jul 30 14:24:58.548843 2026] [security2:error] [pid 1045527:tid 1045704] [client 172.202.44.182:51468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/new.php"] [unique_id "amulCjbFEG16qLV_6ZdznwAAAC8"]
[Thu Jul 30 14:24:58.705217 2026] [core:notice] [pid 1045527:tid 1045530] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:58.946315 2026] [core:notice] [pid 1045527:tid 1045565] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:59.155192 2026] [security2:error] [pid 1045527:tid 1045715] [client 172.213.232.128:35673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/m.php"] [unique_id "amulCzbFEG16qLV_6ZdzuQAAADo"]
[Thu Jul 30 14:24:59.232686 2026] [security2:error] [pid 1045527:tid 1045721] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amulCjbFEG16qLV_6ZdzpQAAAEA"]
[Thu Jul 30 14:24:59.415691 2026] [security2:error] [pid 1045527:tid 1045686] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amulCjbFEG16qLV_6ZdzsQAAHSU"]
[Thu Jul 30 14:24:59.613282 2026] [core:notice] [pid 1045527:tid 1045654] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:24:59.638627 2026] [security2:error] [pid 1045527:tid 1045770] [client 172.237.109.114:46090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulCzbFEG16qLV_6ZdztwAAAHE"]
[Thu Jul 30 14:25:00.031050 2026] [security2:error] [pid 1045527:tid 1045762] [client 172.202.44.182:19526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/adminfuns.php"] [unique_id "amulDDbFEG16qLV_6Zdz0AAAAGk"]
[Thu Jul 30 14:25:00.035438 2026] [security2:error] [pid 1045527:tid 1045701] [client 172.213.232.128:30790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amulDDbFEG16qLV_6Zdz0QAAACw"]
[Thu Jul 30 14:25:00.096249 2026] [security2:error] [pid 1045527:tid 1045685] [client 74.248.33.8:45203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amulDDbFEG16qLV_6Zdz1AAAABw"]
[Thu Jul 30 14:25:00.151440 2026] [core:notice] [pid 1045527:tid 1045672] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:00.438161 2026] [security2:error] [pid 1045527:tid 1045586] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/public/css.php"] [unique_id "amulDDbFEG16qLV_6Zdz3wAAIDo"]
[Thu Jul 30 14:25:00.438290 2026] [security2:error] [pid 1045527:tid 1045689] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/public/css.php"] [unique_id "amulDDbFEG16qLV_6Zdz3wAAIDo"]
[Thu Jul 30 14:25:00.474179 2026] [security2:error] [pid 1045527:tid 1045582] [remote 216.73.217.142:37768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amulDDbFEG16qLV_6Zdz4AAAKjY"]
[Thu Jul 30 14:25:00.707884 2026] [security2:error] [pid 1045527:tid 1045567] [remote 57.141.0.11:56680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amulDDbFEG16qLV_6Zdz7gAANCc"]
[Thu Jul 30 14:25:00.811647 2026] [security2:error] [pid 1045527:tid 1045702] [client 172.213.232.128:31741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/mah/flower.php"] [unique_id "amulDDbFEG16qLV_6Zdz8gAAAC0"]
[Thu Jul 30 14:25:01.040145 2026] [security2:error] [pid 1045527:tid 1045585] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/output.php"] [unique_id "amulDTbFEG16qLV_6Zdz9wAAczk"]
[Thu Jul 30 14:25:01.040395 2026] [security2:error] [pid 1045527:tid 1045772] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/output.php"] [unique_id "amulDTbFEG16qLV_6Zdz9wAAczk"]
[Thu Jul 30 14:25:01.684543 2026] [security2:error] [pid 1045527:tid 1045618] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-file-120.php"] [unique_id "amulDTbFEG16qLV_6Zd0CgAAWlo"]
[Thu Jul 30 14:25:01.684752 2026] [security2:error] [pid 1045527:tid 1045747] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-file-120.php"] [unique_id "amulDTbFEG16qLV_6Zd0CgAAWlo"]
[Thu Jul 30 14:25:02.151897 2026] [security2:error] [pid 1045527:tid 1045669] [client 172.237.109.114:26463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/inizio.php"] [unique_id "amulDjbFEG16qLV_6Zd0FwAAAAw"], referer: https://alseermarine.com:443/inizio.php
[Thu Jul 30 14:25:02.283606 2026] [security2:error] [pid 1045527:tid 1045607] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/special.php"] [unique_id "amulDjbFEG16qLV_6Zd0IQAACE8"]
[Thu Jul 30 14:25:02.283782 2026] [security2:error] [pid 1045527:tid 1045665] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/special.php"] [unique_id "amulDjbFEG16qLV_6Zd0IQAACE8"]
[Thu Jul 30 14:25:02.842834 2026] [security2:error] [pid 1045527:tid 1045570] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/as.php"] [unique_id "amulDjbFEG16qLV_6Zd0LAAAKSo"]
[Thu Jul 30 14:25:02.843035 2026] [security2:error] [pid 1045527:tid 1045698] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/as.php"] [unique_id "amulDjbFEG16qLV_6Zd0LAAAKSo"]
[Thu Jul 30 14:25:03.414304 2026] [security2:error] [pid 1045527:tid 1045748] [client 172.213.232.128:30844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/mah/xleet.php"] [unique_id "amulDzbFEG16qLV_6Zd0OAAAAFs"]
[Thu Jul 30 14:25:03.522637 2026] [security2:error] [pid 1045527:tid 1045599] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/cgi-bin/index.php"] [unique_id "amulDzbFEG16qLV_6Zd0OQAAAEc"]
[Thu Jul 30 14:25:03.522869 2026] [security2:error] [pid 1045527:tid 1045657] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/cgi-bin/index.php"] [unique_id "amulDzbFEG16qLV_6Zd0OQAAAEc"]
[Thu Jul 30 14:25:03.730252 2026] [security2:error] [pid 1045527:tid 1045678] [client 177.6.106.101:54513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulDzbFEG16qLV_6Zd0PQAAABU"]
[Thu Jul 30 14:25:03.730388 2026] [security2:error] [pid 1045527:tid 1045678] [client 177.6.106.101:54513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulDzbFEG16qLV_6Zd0PQAAABU"]
[Thu Jul 30 14:25:04.108381 2026] [security2:error] [pid 1045527:tid 1045623] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/w1px.php"] [unique_id "amulEDbFEG16qLV_6Zd0SQAAY18"]
[Thu Jul 30 14:25:04.108607 2026] [security2:error] [pid 1045527:tid 1045756] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/w1px.php"] [unique_id "amulEDbFEG16qLV_6Zd0SQAAY18"]
[Thu Jul 30 14:25:04.193912 2026] [security2:error] [pid 1045527:tid 1045779] [client 172.213.232.128:30131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/mini.php"] [unique_id "amulEDbFEG16qLV_6Zd0SgAAAHo"]
[Thu Jul 30 14:25:04.315862 2026] [security2:error] [pid 1045527:tid 1045769] [client 74.248.33.8:10917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amulEDbFEG16qLV_6Zd0TQAAAHA"]
[Thu Jul 30 14:25:04.319689 2026] [security2:error] [pid 1045527:tid 1045747] [client 95.108.213.120:46924] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/robots.txt"] [unique_id "amulEDbFEG16qLV_6Zd0TwAAAFo"]
[Thu Jul 30 14:25:04.734754 2026] [security2:error] [pid 1045527:tid 1045572] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/js.php"] [unique_id "amulEDbFEG16qLV_6Zd0VwAADCw"]
[Thu Jul 30 14:25:04.734929 2026] [security2:error] [pid 1045527:tid 1045669] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/js.php"] [unique_id "amulEDbFEG16qLV_6Zd0VwAADCw"]
[Thu Jul 30 14:25:04.847729 2026] [security2:error] [pid 1045527:tid 1045626] [remote 216.73.217.142:37768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulEDbFEG16qLV_6Zd0XgAATWI"]
[Thu Jul 30 14:25:05.288753 2026] [security2:error] [pid 1045527:tid 1045636] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/core.php"] [unique_id "amulETbFEG16qLV_6Zd0ZAAAJ2w"]
[Thu Jul 30 14:25:05.288944 2026] [security2:error] [pid 1045527:tid 1045696] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/core.php"] [unique_id "amulETbFEG16qLV_6Zd0ZAAAJ2w"]
[Thu Jul 30 14:25:05.629811 2026] [security2:error] [pid 1045527:tid 1045675] [client 172.213.232.128:30784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/moon.php"] [unique_id "amulETbFEG16qLV_6Zd0cwAAABI"]
[Thu Jul 30 14:25:05.840685 2026] [security2:error] [pid 1045527:tid 1045651] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/fffm.php"] [unique_id "amulETbFEG16qLV_6Zd0eQAAFXs"]
[Thu Jul 30 14:25:05.840900 2026] [security2:error] [pid 1045527:tid 1045678] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/fffm.php"] [unique_id "amulETbFEG16qLV_6Zd0eQAAFXs"]
[Thu Jul 30 14:25:05.944016 2026] [core:notice] [pid 1045527:tid 1045749] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:06.126305 2026] [core:notice] [pid 1045527:tid 1045722] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:06.256399 2026] [core:notice] [pid 1045527:tid 1045721] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:06.422114 2026] [security2:error] [pid 1045527:tid 1045553] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ww.php"] [unique_id "amulEjbFEG16qLV_6Zd0sQAAUxk"]
[Thu Jul 30 14:25:06.422283 2026] [security2:error] [pid 1045527:tid 1045740] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ww.php"] [unique_id "amulEjbFEG16qLV_6Zd0sQAAUxk"]
[Thu Jul 30 14:25:06.742533 2026] [security2:error] [pid 1045527:tid 1045669] [client 172.213.232.128:30061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/new.php"] [unique_id "amulEjbFEG16qLV_6Zd0twAAAAw"]
[Thu Jul 30 14:25:06.820429 2026] [security2:error] [pid 1045527:tid 1045731] [client 172.202.44.182:34274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/fm.php"] [unique_id "amulEjbFEG16qLV_6Zd0uAAAAEo"]
[Thu Jul 30 14:25:06.982877 2026] [security2:error] [pid 1045527:tid 1045584] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/domvf.php"] [unique_id "amulEjbFEG16qLV_6Zd0wgAASDg"]
[Thu Jul 30 14:25:06.983028 2026] [security2:error] [pid 1045527:tid 1045729] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/domvf.php"] [unique_id "amulEjbFEG16qLV_6Zd0wgAASDg"]
[Thu Jul 30 14:25:07.338251 2026] [core:error] [pid 1045527:tid 1045735] [client 74.248.33.8:44492] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:07.338277 2026] [core:error] [pid 1045527:tid 1045735] [client 74.248.33.8:44492] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:07.618837 2026] [security2:error] [pid 1045527:tid 1045586] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/echkm.php"] [unique_id "amulEzbFEG16qLV_6Zd00AAAFTo"]
[Thu Jul 30 14:25:07.619074 2026] [security2:error] [pid 1045527:tid 1045678] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/echkm.php"] [unique_id "amulEzbFEG16qLV_6Zd00AAAFTo"]
[Thu Jul 30 14:25:07.974245 2026] [security2:error] [pid 1045527:tid 1045690] [client 74.248.33.8:34199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/admin.php"] [unique_id "amulEzbFEG16qLV_6Zd02AAAACE"]
[Thu Jul 30 14:25:08.181111 2026] [security2:error] [pid 1045527:tid 1045580] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ano.php"] [unique_id "amulFDbFEG16qLV_6Zd02wAAJDQ"]
[Thu Jul 30 14:25:08.181382 2026] [security2:error] [pid 1045527:tid 1045693] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ano.php"] [unique_id "amulFDbFEG16qLV_6Zd02wAAJDQ"]
[Thu Jul 30 14:25:08.564473 2026] [security2:error] [pid 1045527:tid 1045747] [client 172.213.232.128:32057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/radio.php"] [unique_id "amulFDbFEG16qLV_6Zd05wAAAFo"]
[Thu Jul 30 14:25:08.705077 2026] [security2:error] [pid 1045527:tid 1045719] [client 180.243.59.178:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulFDbFEG16qLV_6Zd06gAAAD4"]
[Thu Jul 30 14:25:08.705238 2026] [security2:error] [pid 1045527:tid 1045719] [client 180.243.59.178:55038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulFDbFEG16qLV_6Zd06gAAAD4"]
[Thu Jul 30 14:25:08.754195 2026] [security2:error] [pid 1045527:tid 1045558] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ah25.php"] [unique_id "amulFDbFEG16qLV_6Zd07AAABh4"]
[Thu Jul 30 14:25:08.754376 2026] [security2:error] [pid 1045527:tid 1045663] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ah25.php"] [unique_id "amulFDbFEG16qLV_6Zd07AAABh4"]
[Thu Jul 30 14:25:09.309343 2026] [security2:error] [pid 1045527:tid 1045579] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/term.php"] [unique_id "amulFTbFEG16qLV_6Zd1GAAASzM"]
[Thu Jul 30 14:25:09.309499 2026] [security2:error] [pid 1045527:tid 1045732] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/term.php"] [unique_id "amulFTbFEG16qLV_6Zd1GAAASzM"]
[Thu Jul 30 14:25:09.749651 2026] [security2:error] [pid 1045527:tid 1045673] [client 172.213.232.128:41306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/s.php"] [unique_id "amulFTbFEG16qLV_6Zd1JgAAABA"]
[Thu Jul 30 14:25:09.859767 2026] [security2:error] [pid 1045527:tid 1045626] [remote 57.141.18.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amulFTbFEG16qLV_6Zd1IwAAI2I"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,cotton,denim,plastic,nylon,wood,lycra,silicon&orderby=menu_order&rating=5&status=instock&filter_brand=american-apparel&unfilter=1
[Thu Jul 30 14:25:09.954681 2026] [security2:error] [pid 1045527:tid 1045621] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/we.php"] [unique_id "amulFTbFEG16qLV_6Zd1LAAAFF0"]
[Thu Jul 30 14:25:09.954877 2026] [security2:error] [pid 1045527:tid 1045677] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/we.php"] [unique_id "amulFTbFEG16qLV_6Zd1LAAAFF0"]
[Thu Jul 30 14:25:09.970616 2026] [security2:error] [pid 1045527:tid 1045628] [remote 57.141.18.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amulFTbFEG16qLV_6Zd1JAAAKmQ"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,cotton,denim,plastic,nylon,wood,lycra,silicon&orderby=menu_order&rating=5&status=instock&filter_brand=american-apparel&unfilter=1
[Thu Jul 30 14:25:10.502262 2026] [security2:error] [pid 1045527:tid 1045622] [remote 216.73.217.142:12444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amulFjbFEG16qLV_6Zd1NwAAFV4"]
[Thu Jul 30 14:25:10.527809 2026] [security2:error] [pid 1045527:tid 1045633] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/zip-onee.php"] [unique_id "amulFjbFEG16qLV_6Zd1OAAARGk"]
[Thu Jul 30 14:25:10.527958 2026] [security2:error] [pid 1045527:tid 1045725] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/zip-onee.php"] [unique_id "amulFjbFEG16qLV_6Zd1OAAARGk"]
[Thu Jul 30 14:25:10.530922 2026] [security2:error] [pid 1045527:tid 1045666] [client 52.6.5.24:22968] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2019/09/AAF4Q26.jpg"] [unique_id "amulFjbFEG16qLV_6Zd1OQAAAAk"]
[Thu Jul 30 14:25:10.614078 2026] [security2:error] [pid 1045527:tid 1045597] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amulFjbFEG16qLV_6Zd1PgAALkU"]
[Thu Jul 30 14:25:10.614209 2026] [security2:error] [pid 1045527:tid 1045703] [client 72.167.132.114:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vanguardlegalassociates.team"] [uri "/xmlrpc.php"] [unique_id "amulFjbFEG16qLV_6Zd1PgAALkU"]
[Thu Jul 30 14:25:10.840117 2026] [core:notice] [pid 1045527:tid 1045728] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:10.846043 2026] [core:notice] [pid 1045527:tid 1045767] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:11.004721 2026] [security2:error] [pid 1045527:tid 1045680] [client 172.213.232.128:41296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/sim.php"] [unique_id "amulFzbFEG16qLV_6Zd1RwAAABc"]
[Thu Jul 30 14:25:11.076244 2026] [security2:error] [pid 1045527:tid 1045649] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/il.php"] [unique_id "amulFzbFEG16qLV_6Zd1SAAAK3k"]
[Thu Jul 30 14:25:11.076508 2026] [security2:error] [pid 1045527:tid 1045700] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/il.php"] [unique_id "amulFzbFEG16qLV_6Zd1SAAAK3k"]
[Thu Jul 30 14:25:11.638443 2026] [security2:error] [pid 1045527:tid 1045720] [client 172.213.232.128:34518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/text.php"] [unique_id "amulFzbFEG16qLV_6Zd1VwAAAD8"]
[Thu Jul 30 14:25:11.647905 2026] [security2:error] [pid 1045527:tid 1045611] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/one.php"] [unique_id "amulFzbFEG16qLV_6Zd1WAAAJVM"]
[Thu Jul 30 14:25:11.648066 2026] [security2:error] [pid 1045527:tid 1045694] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/one.php"] [unique_id "amulFzbFEG16qLV_6Zd1WAAAJVM"]
[Thu Jul 30 14:25:12.212497 2026] [security2:error] [pid 1045527:tid 1045645] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/002.php"] [unique_id "amulGDbFEG16qLV_6Zd1YQAAVXU"]
[Thu Jul 30 14:25:12.212699 2026] [security2:error] [pid 1045527:tid 1045742] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/002.php"] [unique_id "amulGDbFEG16qLV_6Zd1YQAAVXU"]
[Thu Jul 30 14:25:12.449374 2026] [security2:error] [pid 1045527:tid 1045782] [client 74.248.33.8:10460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-configs.php"] [unique_id "amulGDbFEG16qLV_6Zd1aAAAAH0"]
[Thu Jul 30 14:25:12.774092 2026] [security2:error] [pid 1045527:tid 1045535] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/file1.php"] [unique_id "amulGDbFEG16qLV_6Zd1cwAAYQc"]
[Thu Jul 30 14:25:12.774239 2026] [security2:error] [pid 1045527:tid 1045754] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/file1.php"] [unique_id "amulGDbFEG16qLV_6Zd1cwAAYQc"]
[Thu Jul 30 14:25:12.992601 2026] [security2:error] [pid 1045527:tid 1045737] [client 172.213.232.128:30021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/user.php"] [unique_id "amulGDbFEG16qLV_6Zd1dQAAAFA"]
[Thu Jul 30 14:25:13.255177 2026] [security2:error] [pid 1045527:tid 1045674] [client 74.248.33.8:44525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/php.php"] [unique_id "amulGTbFEG16qLV_6Zd1fgAAABE"]
[Thu Jul 30 14:25:13.354740 2026] [security2:error] [pid 1045527:tid 1045545] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/akimet.php"] [unique_id "amulGTbFEG16qLV_6Zd1gwAAYBE"]
[Thu Jul 30 14:25:13.354912 2026] [security2:error] [pid 1045527:tid 1045753] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/akimet.php"] [unique_id "amulGTbFEG16qLV_6Zd1gwAAYBE"]
[Thu Jul 30 14:25:13.901458 2026] [security2:error] [pid 1045527:tid 1045552] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/reop3.php"] [unique_id "amulGTbFEG16qLV_6Zd1jwAAQBg"]
[Thu Jul 30 14:25:13.901614 2026] [security2:error] [pid 1045527:tid 1045721] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/reop3.php"] [unique_id "amulGTbFEG16qLV_6Zd1jwAAQBg"]
[Thu Jul 30 14:25:14.212084 2026] [security2:error] [pid 1045527:tid 1045741] [client 177.6.106.101:54891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulGjbFEG16qLV_6Zd1kwAAAFQ"]
[Thu Jul 30 14:25:14.212233 2026] [security2:error] [pid 1045527:tid 1045741] [client 177.6.106.101:54891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulGjbFEG16qLV_6Zd1kwAAAFQ"]
[Thu Jul 30 14:25:14.274418 2026] [security2:error] [pid 1045527:tid 1045765] [client 172.213.232.128:30073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/webadmin.php"] [unique_id "amulGjbFEG16qLV_6Zd1lAAAAGw"]
[Thu Jul 30 14:25:14.459242 2026] [security2:error] [pid 1045527:tid 1045652] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/h.php"] [unique_id "amulGjbFEG16qLV_6Zd1nAAAKnw"]
[Thu Jul 30 14:25:14.459422 2026] [security2:error] [pid 1045527:tid 1045699] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/h.php"] [unique_id "amulGjbFEG16qLV_6Zd1nAAAKnw"]
[Thu Jul 30 14:25:14.461568 2026] [security2:error] [pid 1045527:tid 1045783] [client 185.247.137.118:49011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amulGjbFEG16qLV_6Zd1mwAAfhY"]
[Thu Jul 30 14:25:14.521729 2026] [security2:error] [pid 1045527:tid 1045705] [client 74.248.33.8:10882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/index.php"] [unique_id "amulGjbFEG16qLV_6Zd1oAAAADA"]
[Thu Jul 30 14:25:14.762348 2026] [security2:error] [pid 1045527:tid 1045658] [client 92.63.205.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amulGjbFEG16qLV_6Zd1pAAAAAE"], referer: https://cnpinyin.com
[Thu Jul 30 14:25:14.858208 2026] [security2:error] [pid 1045527:tid 1045654] [remote 216.73.217.142:12444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amulGjbFEG16qLV_6Zd1qgAAAn4"]
[Thu Jul 30 14:25:15.028634 2026] [security2:error] [pid 1045527:tid 1045583] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/2x.php"] [unique_id "amulGzbFEG16qLV_6Zd1rgAAZDc"]
[Thu Jul 30 14:25:15.028827 2026] [security2:error] [pid 1045527:tid 1045757] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/2x.php"] [unique_id "amulGzbFEG16qLV_6Zd1rgAAZDc"]
[Thu Jul 30 14:25:15.548426 2026] [security2:error] [pid 1045527:tid 1045738] [client 172.213.232.128:34539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amulGzbFEG16qLV_6Zd1uQAAAFE"]
[Thu Jul 30 14:25:15.581239 2026] [security2:error] [pid 1045527:tid 1045563] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/petx.php"] [unique_id "amulGzbFEG16qLV_6Zd1ugAAFyM"]
[Thu Jul 30 14:25:15.581420 2026] [security2:error] [pid 1045527:tid 1045680] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/petx.php"] [unique_id "amulGzbFEG16qLV_6Zd1ugAAFyM"]
[Thu Jul 30 14:25:16.128609 2026] [security2:error] [pid 1045527:tid 1045589] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/zxz.php"] [unique_id "amulHDbFEG16qLV_6Zd1ygAAQz0"]
[Thu Jul 30 14:25:16.128790 2026] [security2:error] [pid 1045527:tid 1045724] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/zxz.php"] [unique_id "amulHDbFEG16qLV_6Zd1ygAAQz0"]
[Thu Jul 30 14:25:16.187194 2026] [core:notice] [pid 1045527:tid 1045701] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:16.435642 2026] [security2:error] [pid 1045527:tid 1045750] [client 128.199.8.140:45323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amulHDbFEG16qLV_6Zd1zwAAXS0"]
[Thu Jul 30 14:25:16.563438 2026] [core:notice] [pid 1045527:tid 1045567] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:16.684403 2026] [security2:error] [pid 1045527:tid 1045571] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/2.php"] [unique_id "amulHDbFEG16qLV_6Zd12gAAfis"]
[Thu Jul 30 14:25:16.684615 2026] [security2:error] [pid 1045527:tid 1045783] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/2.php"] [unique_id "amulHDbFEG16qLV_6Zd12gAAfis"]
[Thu Jul 30 14:25:17.059759 2026] [security2:error] [pid 1045527:tid 1045698] [client 74.248.33.8:44509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/a.php"] [unique_id "amulHTbFEG16qLV_6Zd14gAAACk"]
[Thu Jul 30 14:25:17.240142 2026] [security2:error] [pid 1045527:tid 1045612] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/op.php"] [unique_id "amulHTbFEG16qLV_6Zd15gAAV1Q"]
[Thu Jul 30 14:25:17.240415 2026] [security2:error] [pid 1045527:tid 1045744] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/op.php"] [unique_id "amulHTbFEG16qLV_6Zd15gAAV1Q"]
[Thu Jul 30 14:25:17.664637 2026] [security2:error] [pid 1045527:tid 1045702] [client 172.213.232.128:41293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amulHTbFEG16qLV_6Zd18QAAAC0"]
[Thu Jul 30 14:25:17.794572 2026] [security2:error] [pid 1045527:tid 1045609] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/a5.php"] [unique_id "amulHTbFEG16qLV_6Zd19gAAGlE"]
[Thu Jul 30 14:25:17.794742 2026] [security2:error] [pid 1045527:tid 1045683] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/a5.php"] [unique_id "amulHTbFEG16qLV_6Zd19gAAGlE"]
[Thu Jul 30 14:25:18.084955 2026] [security2:error] [pid 1045527:tid 1045733] [client 74.7.228.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.wvq.nyx.temporary.site"] [uri "/index.php"] [unique_id "amulGzbFEG16qLV_6Zd1wwAAAEw"]
[Thu Jul 30 14:25:18.085832 2026] [security2:error] [pid 1045527:tid 1045706] [client 74.7.228.51:49190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.wvq.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amulGzbFEG16qLV_6Zd1wQAAMTo"]
[Thu Jul 30 14:25:18.371369 2026] [security2:error] [pid 1045527:tid 1045632] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ws80.php"] [unique_id "amulHjbFEG16qLV_6Zd2BQAAX2g"]
[Thu Jul 30 14:25:18.371641 2026] [security2:error] [pid 1045527:tid 1045752] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ws80.php"] [unique_id "amulHjbFEG16qLV_6Zd2BQAAX2g"]
[Thu Jul 30 14:25:18.409015 2026] [core:error] [pid 1045527:tid 1045751] [client 74.248.33.8:44540] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:18.409051 2026] [core:error] [pid 1045527:tid 1045751] [client 74.248.33.8:44540] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:18.915961 2026] [security2:error] [pid 1045527:tid 1045616] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/xa.php"] [unique_id "amulHjbFEG16qLV_6Zd2EwAAbVg"]
[Thu Jul 30 14:25:18.916150 2026] [security2:error] [pid 1045527:tid 1045766] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/xa.php"] [unique_id "amulHjbFEG16qLV_6Zd2EwAAbVg"]
[Thu Jul 30 14:25:19.163580 2026] [core:error] [pid 1045527:tid 1045694] [client 74.248.33.8:34186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:19.163609 2026] [core:error] [pid 1045527:tid 1045694] [client 74.248.33.8:34186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:19.332468 2026] [core:error] [pid 1045527:tid 1045614] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:19.332492 2026] [core:error] [pid 1045527:tid 1045614] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:19.466548 2026] [security2:error] [pid 1045527:tid 1045655] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/asd67.php"] [unique_id "amulHzbFEG16qLV_6Zd2IwAAfX8"]
[Thu Jul 30 14:25:19.466723 2026] [security2:error] [pid 1045527:tid 1045782] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/asd67.php"] [unique_id "amulHzbFEG16qLV_6Zd2IwAAfX8"]
[Thu Jul 30 14:25:19.569006 2026] [security2:error] [pid 1045527:tid 1045665] [client 180.243.59.178:55594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulHzbFEG16qLV_6Zd2JQAAAAg"]
[Thu Jul 30 14:25:19.569134 2026] [security2:error] [pid 1045527:tid 1045665] [client 180.243.59.178:55594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulHzbFEG16qLV_6Zd2JQAAAAg"]
[Thu Jul 30 14:25:19.860300 2026] [security2:error] [pid 1045527:tid 1045625] [remote 216.73.217.142:12444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulHzbFEG16qLV_6Zd2LwAAPWE"]
[Thu Jul 30 14:25:20.017006 2026] [security2:error] [pid 1045527:tid 1045629] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/bk.php"] [unique_id "amulIDbFEG16qLV_6Zd2MAAAEGU"]
[Thu Jul 30 14:25:20.017285 2026] [security2:error] [pid 1045527:tid 1045673] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/bk.php"] [unique_id "amulIDbFEG16qLV_6Zd2MAAAEGU"]
[Thu Jul 30 14:25:20.138205 2026] [security2:error] [pid 1045527:tid 1045756] [client 74.248.33.8:10887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amulIDbFEG16qLV_6Zd2NAAAAGM"]
[Thu Jul 30 14:25:20.585670 2026] [security2:error] [pid 1045527:tid 1045588] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-links.php"] [unique_id "amulIDbFEG16qLV_6Zd2PQAAMzw"]
[Thu Jul 30 14:25:20.585846 2026] [security2:error] [pid 1045527:tid 1045708] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-links.php"] [unique_id "amulIDbFEG16qLV_6Zd2PQAAMzw"]
[Thu Jul 30 14:25:21.142144 2026] [security2:error] [pid 1045527:tid 1045621] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/mosty.php"] [unique_id "amulITbFEG16qLV_6Zd2SwAAX10"]
[Thu Jul 30 14:25:21.142339 2026] [security2:error] [pid 1045527:tid 1045752] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/mosty.php"] [unique_id "amulITbFEG16qLV_6Zd2SwAAX10"]
[Thu Jul 30 14:25:21.519367 2026] [core:notice] [pid 1045527:tid 1045687] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:21.695221 2026] [security2:error] [pid 1045527:tid 1045622] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/sump3.php"] [unique_id "amulITbFEG16qLV_6Zd2WAAASF4"]
[Thu Jul 30 14:25:21.695386 2026] [security2:error] [pid 1045527:tid 1045729] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/sump3.php"] [unique_id "amulITbFEG16qLV_6Zd2WAAASF4"]
[Thu Jul 30 14:25:21.738661 2026] [core:error] [pid 1045527:tid 1045633] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:21.738684 2026] [core:error] [pid 1045527:tid 1045633] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:21.957734 2026] [security2:error] [pid 1045527:tid 1045777] [client 172.202.44.182:26533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/file.php"] [unique_id "amulITbFEG16qLV_6Zd2YAAAAHg"]
[Thu Jul 30 14:25:22.244407 2026] [security2:error] [pid 1045527:tid 1045642] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/first.php"] [unique_id "amulIjbFEG16qLV_6Zd2aAAAUnI"]
[Thu Jul 30 14:25:22.244632 2026] [security2:error] [pid 1045527:tid 1045739] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/first.php"] [unique_id "amulIjbFEG16qLV_6Zd2aAAAUnI"]
[Thu Jul 30 14:25:22.476999 2026] [security2:error] [pid 1045527:tid 1045691] [client 154.159.252.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amulIjbFEG16qLV_6Zd2bgAAACI"], referer: https://cnpinyin.com
[Thu Jul 30 14:25:22.793918 2026] [security2:error] [pid 1045527:tid 1045542] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/acp.php"] [unique_id "amulIjbFEG16qLV_6Zd2fwAACQ4"]
[Thu Jul 30 14:25:22.794143 2026] [security2:error] [pid 1045527:tid 1045666] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/acp.php"] [unique_id "amulIjbFEG16qLV_6Zd2fwAACQ4"]
[Thu Jul 30 14:25:23.193691 2026] [security2:error] [pid 1045527:tid 1045784] [client 172.202.44.182:26558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/bolt.php"] [unique_id "amulIzbFEG16qLV_6Zd2hQAAAH8"]
[Thu Jul 30 14:25:23.226486 2026] [security2:error] [pid 1045527:tid 1045744] [client 74.248.33.8:44490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin.php"] [unique_id "amulIzbFEG16qLV_6Zd2hwAAAFc"]
[Thu Jul 30 14:25:23.361297 2026] [security2:error] [pid 1045527:tid 1045538] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-good.php"] [unique_id "amulIzbFEG16qLV_6Zd2jAAASwo"]
[Thu Jul 30 14:25:23.361541 2026] [security2:error] [pid 1045527:tid 1045732] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-good.php"] [unique_id "amulIzbFEG16qLV_6Zd2jAAASwo"]
[Thu Jul 30 14:25:23.362498 2026] [security2:error] [pid 1045527:tid 1045700] [client 172.213.232.128:32040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amulIzbFEG16qLV_6Zd2jQAAACs"]
[Thu Jul 30 14:25:23.451584 2026] [security2:error] [pid 1045527:tid 1045740] [client 74.7.175.176:48324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.zbj.udi.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amulIzbFEG16qLV_6Zd2kQAAAFM"]
[Thu Jul 30 14:25:23.919032 2026] [security2:error] [pid 1045527:tid 1045755] [client 74.248.33.8:44506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/size.php"] [unique_id "amulIzbFEG16qLV_6Zd2mwAAAGI"]
[Thu Jul 30 14:25:23.919518 2026] [security2:error] [pid 1045527:tid 1045765] [client 172.213.232.128:34521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amulIzbFEG16qLV_6Zd2nAAAAGw"]
[Thu Jul 30 14:25:23.980544 2026] [security2:error] [pid 1045527:tid 1045545] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/daerl3.php"] [unique_id "amulIzbFEG16qLV_6Zd2ngAAbRE"]
[Thu Jul 30 14:25:23.980710 2026] [security2:error] [pid 1045527:tid 1045766] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/daerl3.php"] [unique_id "amulIzbFEG16qLV_6Zd2ngAAbRE"]
[Thu Jul 30 14:25:24.536650 2026] [security2:error] [pid 1045527:tid 1045544] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/php5.php"] [unique_id "amulJDbFEG16qLV_6Zd2qQAAYRA"]
[Thu Jul 30 14:25:24.536853 2026] [security2:error] [pid 1045527:tid 1045754] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/php5.php"] [unique_id "amulJDbFEG16qLV_6Zd2qQAAYRA"]
[Thu Jul 30 14:25:24.755864 2026] [security2:error] [pid 1045527:tid 1045776] [client 172.213.232.128:32003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amulJDbFEG16qLV_6Zd2sAAAAHc"]
[Thu Jul 30 14:25:24.874136 2026] [security2:error] [pid 1045527:tid 1045672] [client 177.6.106.101:55446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulJDbFEG16qLV_6Zd2sQAAAA8"]
[Thu Jul 30 14:25:24.874283 2026] [security2:error] [pid 1045527:tid 1045672] [client 177.6.106.101:55446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulJDbFEG16qLV_6Zd2sQAAAA8"]
[Thu Jul 30 14:25:25.094795 2026] [security2:error] [pid 1045527:tid 1045554] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/xoot.php"] [unique_id "amulJTbFEG16qLV_6Zd2tQAAWRo"]
[Thu Jul 30 14:25:25.095002 2026] [security2:error] [pid 1045527:tid 1045746] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/xoot.php"] [unique_id "amulJTbFEG16qLV_6Zd2tQAAWRo"]
[Thu Jul 30 14:25:25.256456 2026] [security2:error] [pid 1045527:tid 1045715] [client 172.202.44.182:34713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/3.php"] [unique_id "amulJTbFEG16qLV_6Zd2uwAAADo"]
[Thu Jul 30 14:25:25.657441 2026] [security2:error] [pid 1045527:tid 1045550] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/clxcc.php"] [unique_id "amulJTbFEG16qLV_6Zd2wAAAXBY"]
[Thu Jul 30 14:25:25.657695 2026] [security2:error] [pid 1045527:tid 1045749] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/clxcc.php"] [unique_id "amulJTbFEG16qLV_6Zd2wAAAXBY"]
[Thu Jul 30 14:25:25.692715 2026] [security2:error] [pid 1045527:tid 1045566] [remote 216.73.217.142:24122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulJTbFEG16qLV_6Zd2wgAAayY"]
[Thu Jul 30 14:25:25.938142 2026] [core:notice] [pid 1045527:tid 1045743] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:26.101674 2026] [security2:error] [pid 1045527:tid 1045763] [client 85.208.96.207:36520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2023/07/cara-memperbaiki-bluetooth-pada"] [unique_id "amulJjbFEG16qLV_6Zd2zAAAAGo"]
[Thu Jul 30 14:25:26.101831 2026] [security2:error] [pid 1045527:tid 1045763] [client 85.208.96.207:36520] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2023/07/cara-memperbaiki-bluetooth-pada"] [unique_id "amulJjbFEG16qLV_6Zd2zAAAAGo"]
[Thu Jul 30 14:25:26.191165 2026] [security2:error] [pid 1045527:tid 1045724] [client 172.202.44.182:34740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/222.php"] [unique_id "amulJjbFEG16qLV_6Zd2zQAAAEM"]
[Thu Jul 30 14:25:26.215908 2026] [security2:error] [pid 1045527:tid 1045643] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ai.php"] [unique_id "amulJjbFEG16qLV_6Zd2zgAAL3M"]
[Thu Jul 30 14:25:26.216090 2026] [security2:error] [pid 1045527:tid 1045704] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ai.php"] [unique_id "amulJjbFEG16qLV_6Zd2zgAAL3M"]
[Thu Jul 30 14:25:26.320776 2026] [core:notice] [pid 1045527:tid 1045771] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:26.322319 2026] [security2:error] [pid 1045527:tid 1045728] [client 172.213.232.128:41317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amulJjbFEG16qLV_6Zd21gAAAEc"]
[Thu Jul 30 14:25:26.659616 2026] [core:notice] [pid 1045527:tid 1045712] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:26.661815 2026] [core:notice] [pid 1045527:tid 1045699] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:26.662967 2026] [core:notice] [pid 1045527:tid 1045705] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:26.667352 2026] [core:notice] [pid 1045527:tid 1045758] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:26.685887 2026] [core:notice] [pid 1045527:tid 1045677] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:26.692586 2026] [core:notice] [pid 1045527:tid 1045777] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:26.780183 2026] [security2:error] [pid 1045527:tid 1045546] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/nwflm.php"] [unique_id "amulJjbFEG16qLV_6Zd24wAAcxI"]
[Thu Jul 30 14:25:26.780341 2026] [security2:error] [pid 1045527:tid 1045772] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/nwflm.php"] [unique_id "amulJjbFEG16qLV_6Zd24wAAcxI"]
[Thu Jul 30 14:25:26.825903 2026] [security2:error] [pid 1045527:tid 1045720] [client 185.200.116.219:44230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amulJjbFEG16qLV_6Zd25AAAAD8"]
[Thu Jul 30 14:25:26.826002 2026] [security2:error] [pid 1045527:tid 1045720] [client 185.200.116.219:44230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amulJjbFEG16qLV_6Zd25AAAAD8"]
[Thu Jul 30 14:25:27.001740 2026] [core:notice] [pid 1045527:tid 1045754] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:27.004898 2026] [core:notice] [pid 1045527:tid 1045718] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:27.006808 2026] [core:notice] [pid 1045527:tid 1045711] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:27.102371 2026] [core:notice] [pid 1045527:tid 1045745] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:27.212053 2026] [security2:error] [pid 1045527:tid 1045739] [client 172.202.44.182:34725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amulJzbFEG16qLV_6Zd27wAAAFI"]
[Thu Jul 30 14:25:27.327572 2026] [security2:error] [pid 1045527:tid 1045557] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/hypo.php"] [unique_id "amulJzbFEG16qLV_6Zd28wAAAh0"]
[Thu Jul 30 14:25:27.327771 2026] [security2:error] [pid 1045527:tid 1045659] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/hypo.php"] [unique_id "amulJzbFEG16qLV_6Zd28wAAAh0"]
[Thu Jul 30 14:25:27.453990 2026] [core:notice] [pid 1045527:tid 1045746] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:27.457026 2026] [core:notice] [pid 1045527:tid 1045681] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:27.469576 2026] [core:notice] [pid 1045527:tid 1045666] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:27.671243 2026] [core:notice] [pid 1045527:tid 1045547] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:27.868480 2026] [security2:error] [pid 1045527:tid 1045580] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/w3llscc.php"] [unique_id "amulJzbFEG16qLV_6Zd3AwAATDQ"]
[Thu Jul 30 14:25:27.868670 2026] [security2:error] [pid 1045527:tid 1045733] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/w3llscc.php"] [unique_id "amulJzbFEG16qLV_6Zd3AwAATDQ"]
[Thu Jul 30 14:25:27.900098 2026] [core:notice] [pid 1045527:tid 1045759] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:28.425626 2026] [security2:error] [pid 1045527:tid 1045571] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amulKDbFEG16qLV_6Zd3GAAANys"]
[Thu Jul 30 14:25:28.425818 2026] [security2:error] [pid 1045527:tid 1045712] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amulKDbFEG16qLV_6Zd3GAAANys"]
[Thu Jul 30 14:25:28.702775 2026] [core:notice] [pid 1045527:tid 1045710] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:28.810087 2026] [security2:error] [pid 1045527:tid 1045668] [client 172.202.44.182:34728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amulKDbFEG16qLV_6Zd3JAAAAAs"]
[Thu Jul 30 14:25:28.981816 2026] [security2:error] [pid 1045527:tid 1045604] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/8.php"] [unique_id "amulKDbFEG16qLV_6Zd3KQAAD0w"]
[Thu Jul 30 14:25:28.981959 2026] [security2:error] [pid 1045527:tid 1045672] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/8.php"] [unique_id "amulKDbFEG16qLV_6Zd3KQAAD0w"]
[Thu Jul 30 14:25:29.060719 2026] [security2:error] [pid 1045527:tid 1045610] [remote 5.255.231.110:37936] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/tag/supplychain/"] [unique_id "amulKTbFEG16qLV_6Zd3KgAAdVI"]
[Thu Jul 30 14:25:29.099060 2026] [security2:error] [pid 1045527:tid 1045765] [client 74.248.33.8:44524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amulKTbFEG16qLV_6Zd3KwAAAGw"]
[Thu Jul 30 14:25:29.282907 2026] [security2:error] [pid 1045527:tid 1045756] [client 172.213.232.128:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amulKTbFEG16qLV_6Zd3MAAAAGM"]
[Thu Jul 30 14:25:29.587928 2026] [security2:error] [pid 1045527:tid 1045549] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/fnstall.php"] [unique_id "amulKTbFEG16qLV_6Zd3OAAAGRU"]
[Thu Jul 30 14:25:29.588146 2026] [security2:error] [pid 1045527:tid 1045682] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/fnstall.php"] [unique_id "amulKTbFEG16qLV_6Zd3OAAAGRU"]
[Thu Jul 30 14:25:29.865874 2026] [security2:error] [pid 1045527:tid 1045623] [remote 216.73.217.142:24122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulKTbFEG16qLV_6Zd3PQAAe18"]
[Thu Jul 30 14:25:30.122297 2026] [security2:error] [pid 1045527:tid 1045719] [client 172.213.232.128:30853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amulKjbFEG16qLV_6Zd3RQAAAD4"]
[Thu Jul 30 14:25:30.143926 2026] [security2:error] [pid 1045527:tid 1045632] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/edorxrr.php"] [unique_id "amulKjbFEG16qLV_6Zd3RgAASmg"]
[Thu Jul 30 14:25:30.144096 2026] [security2:error] [pid 1045527:tid 1045731] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/edorxrr.php"] [unique_id "amulKjbFEG16qLV_6Zd3RgAASmg"]
[Thu Jul 30 14:25:30.231317 2026] [security2:error] [pid 1045527:tid 1045700] [client 172.202.44.182:34707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/admin.php"] [unique_id "amulKjbFEG16qLV_6Zd3RwAAACs"]
[Thu Jul 30 14:25:30.532709 2026] [security2:error] [pid 1045527:tid 1045669] [client 180.243.59.178:56189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulKjbFEG16qLV_6Zd3UQAAAAw"]
[Thu Jul 30 14:25:30.532842 2026] [security2:error] [pid 1045527:tid 1045669] [client 180.243.59.178:56189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulKjbFEG16qLV_6Zd3UQAAAAw"]
[Thu Jul 30 14:25:30.684605 2026] [core:notice] [pid 1045527:tid 1045734] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:30.690016 2026] [security2:error] [pid 1045527:tid 1045599] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/setup.php"] [unique_id "amulKjbFEG16qLV_6Zd3VgAAA0c"]
[Thu Jul 30 14:25:30.690196 2026] [security2:error] [pid 1045527:tid 1045660] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/setup.php"] [unique_id "amulKjbFEG16qLV_6Zd3VgAAA0c"]
[Thu Jul 30 14:25:31.255030 2026] [security2:error] [pid 1045527:tid 1045635] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/6.php"] [unique_id "amulKzbFEG16qLV_6Zd3YQAASGs"]
[Thu Jul 30 14:25:31.255252 2026] [security2:error] [pid 1045527:tid 1045729] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/6.php"] [unique_id "amulKzbFEG16qLV_6Zd3YQAASGs"]
[Thu Jul 30 14:25:31.651959 2026] [security2:error] [pid 1045527:tid 1045596] [remote 74.7.227.39:42376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amulKzbFEG16qLV_6Zd3bwAAYUQ"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:25:31.801091 2026] [security2:error] [pid 1045527:tid 1045555] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/w3lls.php"] [unique_id "amulKzbFEG16qLV_6Zd3cAAAaBs"]
[Thu Jul 30 14:25:31.801280 2026] [security2:error] [pid 1045527:tid 1045761] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/w3lls.php"] [unique_id "amulKzbFEG16qLV_6Zd3cAAAaBs"]
[Thu Jul 30 14:25:32.342402 2026] [security2:error] [pid 1045527:tid 1045629] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/99.php"] [unique_id "amulLDbFEG16qLV_6Zd3ewAAPGU"]
[Thu Jul 30 14:25:32.342657 2026] [security2:error] [pid 1045527:tid 1045717] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/99.php"] [unique_id "amulLDbFEG16qLV_6Zd3ewAAPGU"]
[Thu Jul 30 14:25:32.895741 2026] [security2:error] [pid 1045527:tid 1045590] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/admin.php"] [unique_id "amulLDbFEG16qLV_6Zd3hQAAKz4"]
[Thu Jul 30 14:25:32.896025 2026] [security2:error] [pid 1045527:tid 1045700] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-content/admin.php"] [unique_id "amulLDbFEG16qLV_6Zd3hQAAKz4"]
[Thu Jul 30 14:25:33.292933 2026] [core:notice] [pid 1045527:tid 1045723] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:33.434926 2026] [security2:error] [pid 1045527:tid 1045576] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/media.php"] [unique_id "amulLTbFEG16qLV_6Zd3kQAAbzA"]
[Thu Jul 30 14:25:33.435215 2026] [security2:error] [pid 1045527:tid 1045768] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/media.php"] [unique_id "amulLTbFEG16qLV_6Zd3kQAAbzA"]
[Thu Jul 30 14:25:33.767918 2026] [security2:error] [pid 1045527:tid 1045693] [client 172.213.232.128:41314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amulLTbFEG16qLV_6Zd3nAAAACQ"]
[Thu Jul 30 14:25:33.987061 2026] [security2:error] [pid 1045527:tid 1045719] [client 172.202.44.182:34724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-configs.php"] [unique_id "amulLTbFEG16qLV_6Zd3ngAAAD4"]
[Thu Jul 30 14:25:33.991284 2026] [security2:error] [pid 1045527:tid 1045608] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amulLTbFEG16qLV_6Zd3nwAAJVA"]
[Thu Jul 30 14:25:33.991447 2026] [security2:error] [pid 1045527:tid 1045694] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amulLTbFEG16qLV_6Zd3nwAAJVA"]
[Thu Jul 30 14:25:34.623780 2026] [security2:error] [pid 1045527:tid 1045633] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/222.php"] [unique_id "amulLjbFEG16qLV_6Zd3tgAAOmk"]
[Thu Jul 30 14:25:34.623960 2026] [security2:error] [pid 1045527:tid 1045715] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/222.php"] [unique_id "amulLjbFEG16qLV_6Zd3tgAAOmk"]
[Thu Jul 30 14:25:34.768994 2026] [security2:error] [pid 1045527:tid 1045784] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulLjbFEG16qLV_6Zd3ugAAAH8"]
[Thu Jul 30 14:25:35.171081 2026] [security2:error] [pid 1045527:tid 1045732] [client 74.248.33.8:10963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/403.php"] [unique_id "amulLzbFEG16qLV_6Zd3yQAAAEs"]
[Thu Jul 30 14:25:35.171286 2026] [security2:error] [pid 1045527:tid 1045644] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-load.php"] [unique_id "amulLzbFEG16qLV_6Zd3ygAASnQ"]
[Thu Jul 30 14:25:35.171444 2026] [security2:error] [pid 1045527:tid 1045731] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-load.php"] [unique_id "amulLzbFEG16qLV_6Zd3ygAASnQ"]
[Thu Jul 30 14:25:35.254181 2026] [security2:error] [pid 1045527:tid 1045774] [client 177.6.106.101:55932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulLzbFEG16qLV_6Zd35gAAAHU"]
[Thu Jul 30 14:25:35.254291 2026] [security2:error] [pid 1045527:tid 1045774] [client 177.6.106.101:55932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulLzbFEG16qLV_6Zd35gAAAHU"]
[Thu Jul 30 14:25:35.526790 2026] [security2:error] [pid 1045527:tid 1045544] [remote 216.73.217.142:28162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulLzbFEG16qLV_6Zd36QAADhA"]
[Thu Jul 30 14:25:35.540955 2026] [security2:error] [pid 1045527:tid 1045741] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/api.swp"] [unique_id "amulLzbFEG16qLV_6Zd36gAAAFQ"]
[Thu Jul 30 14:25:35.731813 2026] [security2:error] [pid 1045527:tid 1045559] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/themes/index.php"] [unique_id "amulLzbFEG16qLV_6Zd38gAAYh8"]
[Thu Jul 30 14:25:35.731961 2026] [security2:error] [pid 1045527:tid 1045755] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-content/themes/index.php"] [unique_id "amulLzbFEG16qLV_6Zd38gAAYh8"]
[Thu Jul 30 14:25:35.823849 2026] [security2:error] [pid 1045527:tid 1045771] [client 74.248.33.8:10922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amulLzbFEG16qLV_6Zd39gAAAHI"]
[Thu Jul 30 14:25:35.947954 2026] [security2:error] [pid 1045527:tid 1045728] [client 172.202.44.182:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/php.php"] [unique_id "amulLzbFEG16qLV_6Zd3-wAAAEc"]
[Thu Jul 30 14:25:35.992513 2026] [security2:error] [pid 1045527:tid 1045772] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulLzbFEG16qLV_6Zd3_AAAAHM"]
[Thu Jul 30 14:25:36.317560 2026] [security2:error] [pid 1045527:tid 1045654] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/js/index.php"] [unique_id "amulMDbFEG16qLV_6Zd4CwAABH4"]
[Thu Jul 30 14:25:36.317750 2026] [security2:error] [pid 1045527:tid 1045661] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-admin/js/index.php"] [unique_id "amulMDbFEG16qLV_6Zd4CwAABH4"]
[Thu Jul 30 14:25:36.870795 2026] [security2:error] [pid 1045527:tid 1045676] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.git%00"] [unique_id "amulMDbFEG16qLV_6Zd4GQAAABM"]
[Thu Jul 30 14:25:36.877477 2026] [security2:error] [pid 1045527:tid 1045569] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/memberfuns.php"] [unique_id "amulMDbFEG16qLV_6Zd4GgAAUSk"]
[Thu Jul 30 14:25:36.877694 2026] [security2:error] [pid 1045527:tid 1045738] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/memberfuns.php"] [unique_id "amulMDbFEG16qLV_6Zd4GgAAUSk"]
[Thu Jul 30 14:25:36.975578 2026] [security2:error] [pid 1045527:tid 1045727] [client 172.213.232.128:16527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amulMDbFEG16qLV_6Zd4GwAAAEY"]
[Thu Jul 30 14:25:37.250310 2026] [security2:error] [pid 1045527:tid 1045686] [client 172.202.44.182:51326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/index.php"] [unique_id "amulMTbFEG16qLV_6Zd4IQAAAB0"]
[Thu Jul 30 14:25:37.477989 2026] [security2:error] [pid 1045527:tid 1045685] [client 172.213.232.128:16559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/flower.php"] [unique_id "amulMTbFEG16qLV_6Zd4KgAAABw"]
[Thu Jul 30 14:25:37.540818 2026] [security2:error] [pid 1045527:tid 1045529] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/orange3.php"] [unique_id "amulMTbFEG16qLV_6Zd4KwAAZgE"]
[Thu Jul 30 14:25:37.541101 2026] [security2:error] [pid 1045527:tid 1045759] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/orange3.php"] [unique_id "amulMTbFEG16qLV_6Zd4KwAAZgE"]
[Thu Jul 30 14:25:38.105450 2026] [security2:error] [pid 1045527:tid 1045573] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amulMjbFEG16qLV_6Zd4PQAAZS0"]
[Thu Jul 30 14:25:38.105741 2026] [security2:error] [pid 1045527:tid 1045758] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amulMjbFEG16qLV_6Zd4PQAAZS0"]
[Thu Jul 30 14:25:38.229454 2026] [security2:error] [pid 1045527:tid 1045660] [client 172.202.44.182:19615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/a.php"] [unique_id "amulMjbFEG16qLV_6Zd4PwAAAAM"]
[Thu Jul 30 14:25:38.289436 2026] [security2:error] [pid 1045527:tid 1045705] [client 54.84.169.196:45169] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2018/06/WhatsApp-Image-2018-06-30-at-21.41.52.jpeg"] [unique_id "amulMjbFEG16qLV_6Zd4QwAAADA"]
[Thu Jul 30 14:25:38.615747 2026] [security2:error] [pid 1045527:tid 1045696] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulMjbFEG16qLV_6Zd4TwAAACc"]
[Thu Jul 30 14:25:38.661407 2026] [security2:error] [pid 1045527:tid 1045593] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-the.php"] [unique_id "amulMjbFEG16qLV_6Zd4UAAAcUE"]
[Thu Jul 30 14:25:38.661621 2026] [security2:error] [pid 1045527:tid 1045770] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/wp-the.php"] [unique_id "amulMjbFEG16qLV_6Zd4UAAAcUE"]
[Thu Jul 30 14:25:38.738636 2026] [security2:error] [pid 1045527:tid 1045691] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulMjbFEG16qLV_6Zd4UgAAACI"]
[Thu Jul 30 14:25:38.858621 2026] [security2:error] [pid 1045527:tid 1045753] [client 98.93.205.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lark-shop.com"] [uri "/index.php"] [unique_id "amulMTbFEG16qLV_6Zd4LwAAAGA"], referer: https://lark-shop.com/
[Thu Jul 30 14:25:38.862257 2026] [security2:error] [pid 1045527:tid 1045736] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulMjbFEG16qLV_6Zd4WQAAAE8"]
[Thu Jul 30 14:25:38.986077 2026] [security2:error] [pid 1045527:tid 1045726] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulMjbFEG16qLV_6Zd4XQAAAEU"]
[Thu Jul 30 14:25:39.210341 2026] [security2:error] [pid 1045527:tid 1045567] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/crgio.php"] [unique_id "amulMzbFEG16qLV_6Zd4XwAAGSc"]
[Thu Jul 30 14:25:39.210603 2026] [security2:error] [pid 1045527:tid 1045682] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/crgio.php"] [unique_id "amulMzbFEG16qLV_6Zd4XwAAGSc"]
[Thu Jul 30 14:25:39.533862 2026] [security2:error] [pid 1045527:tid 1045712] [client 172.213.232.128:16536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amulMzbFEG16qLV_6Zd4awAAADc"]
[Thu Jul 30 14:25:39.622254 2026] [core:notice] [pid 1045527:tid 1045727] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:39.733760 2026] [security2:error] [pid 1045527:tid 1045725] [client 180.243.59.178:56929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulMzbFEG16qLV_6Zd4bgAAAEQ"]
[Thu Jul 30 14:25:39.733923 2026] [security2:error] [pid 1045527:tid 1045725] [client 180.243.59.178:56929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulMzbFEG16qLV_6Zd4bgAAAEQ"]
[Thu Jul 30 14:25:39.874009 2026] [security2:error] [pid 1045527:tid 1045604] [remote 216.73.217.142:28162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulMzbFEG16qLV_6Zd4cwAAaUw"]
[Thu Jul 30 14:25:39.945736 2026] [security2:error] [pid 1045527:tid 1045601] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ws13.php"] [unique_id "amulMzbFEG16qLV_6Zd4eAAAKEk"]
[Thu Jul 30 14:25:39.945867 2026] [security2:error] [pid 1045527:tid 1045697] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ws13.php"] [unique_id "amulMzbFEG16qLV_6Zd4eAAAKEk"]
[Thu Jul 30 14:25:40.008141 2026] [security2:error] [pid 1045527:tid 1045609] [remote 47.128.112.186:24990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kendarikomputer.com"] [uri "/p/disclaimer.html"] [unique_id "amulNDbFEG16qLV_6Zd4fwAAbVE"]
[Thu Jul 30 14:25:40.159537 2026] [security2:error] [pid 1045527:tid 1045657] [client 74.248.33.8:10896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/as.php"] [unique_id "amulNDbFEG16qLV_6Zd4gQAAAAA"]
[Thu Jul 30 14:25:40.236250 2026] [security2:error] [pid 1045527:tid 1045671] [client 172.213.232.128:31071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amulNDbFEG16qLV_6Zd4ggAAAA4"]
[Thu Jul 30 14:25:40.314185 2026] [security2:error] [pid 1045527:tid 1045703] [client 109.205.214.111:49250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ocl.djb.temporary.site"] [uri "/index.php"] [unique_id "amulNDbFEG16qLV_6Zd4gwAAAC4"]
[Thu Jul 30 14:25:40.677068 2026] [security2:error] [pid 1045527:tid 1045623] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/srontol.php"] [unique_id "amulNDbFEG16qLV_6Zd4kQAAI18"]
[Thu Jul 30 14:25:40.677324 2026] [security2:error] [pid 1045527:tid 1045692] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/srontol.php"] [unique_id "amulNDbFEG16qLV_6Zd4kQAAI18"]
[Thu Jul 30 14:25:40.750154 2026] [core:notice] [pid 1045527:tid 1045720] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:40.802241 2026] [security2:error] [pid 1045527:tid 1045694] [client 172.213.232.128:17102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amulNDbFEG16qLV_6Zd4lAAAACU"]
[Thu Jul 30 14:25:40.946852 2026] [security2:error] [pid 1045527:tid 1045661] [client 172.202.44.182:34723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amulNDbFEG16qLV_6Zd4mQAAAAQ"]
[Thu Jul 30 14:25:41.229265 2026] [security2:error] [pid 1045527:tid 1045760] [client 74.248.33.8:44519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amulNTbFEG16qLV_6Zd4ogAAAGc"]
[Thu Jul 30 14:25:41.243588 2026] [security2:error] [pid 1045527:tid 1045631] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/miru3.php"] [unique_id "amulNTbFEG16qLV_6Zd4owAAH2c"]
[Thu Jul 30 14:25:41.243758 2026] [security2:error] [pid 1045527:tid 1045688] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/miru3.php"] [unique_id "amulNTbFEG16qLV_6Zd4owAAH2c"]
[Thu Jul 30 14:25:41.419780 2026] [security2:error] [pid 1045527:tid 1045599] [remote 74.7.243.224:52996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/article.php"] [unique_id "amulNTbFEG16qLV_6Zd4qQAACkc"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/content/img/1784117929_IMG_3676.jpg
[Thu Jul 30 14:25:41.825055 2026] [security2:error] [pid 1045527:tid 1045764] [client 109.205.214.111:49250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ocl.djb.temporary.site"] [uri "/index.php"] [unique_id "amulNTbFEG16qLV_6Zd4tgAAAGs"]
[Thu Jul 30 14:25:41.845973 2026] [security2:error] [pid 1045527:tid 1045577] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ingfo.php"] [unique_id "amulNTbFEG16qLV_6Zd4uAAARDE"]
[Thu Jul 30 14:25:41.846192 2026] [security2:error] [pid 1045527:tid 1045725] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ingfo.php"] [unique_id "amulNTbFEG16qLV_6Zd4uAAARDE"]
[Thu Jul 30 14:25:41.941875 2026] [security2:error] [pid 1045527:tid 1045727] [client 74.248.33.8:44481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amulNTbFEG16qLV_6Zd4vAAAAEY"]
[Thu Jul 30 14:25:42.303867 2026] [security2:error] [pid 1045527:tid 1045747] [client 172.213.232.128:29343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amulNjbFEG16qLV_6Zd4xwAAAFo"]
[Thu Jul 30 14:25:42.418127 2026] [security2:error] [pid 1045527:tid 1045655] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ey5.php"] [unique_id "amulNjbFEG16qLV_6Zd4yQAASX8"]
[Thu Jul 30 14:25:42.418382 2026] [security2:error] [pid 1045527:tid 1045730] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/ey5.php"] [unique_id "amulNjbFEG16qLV_6Zd4yQAASX8"]
[Thu Jul 30 14:25:42.602176 2026] [security2:error] [pid 1045527:tid 1045685] [client 172.237.109.114:10855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulNTbFEG16qLV_6Zd4vgAAABw"]
[Thu Jul 30 14:25:42.965114 2026] [security2:error] [pid 1045527:tid 1045625] [remote 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/fine.php"] [unique_id "amulNjbFEG16qLV_6Zd42gAAKWE"]
[Thu Jul 30 14:25:42.965319 2026] [security2:error] [pid 1045527:tid 1045698] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "teknomalay.com"] [uri "/fine.php"] [unique_id "amulNjbFEG16qLV_6Zd42gAAKWE"]
[Thu Jul 30 14:25:43.357244 2026] [security2:error] [pid 1045527:tid 1045703] [client 172.202.44.182:19608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin.php"] [unique_id "amulNzbFEG16qLV_6Zd46AAAAC4"]
[Thu Jul 30 14:25:43.768548 2026] [security2:error] [pid 1045527:tid 1045763] [client 74.248.33.8:41787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/plugins.php"] [unique_id "amulNzbFEG16qLV_6Zd49AAAAGo"]
[Thu Jul 30 14:25:44.382503 2026] [security2:error] [pid 1045527:tid 1045751] [client 74.248.33.8:23632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/js/index.php"] [unique_id "amulODbFEG16qLV_6Zd5AwAAAF4"]
[Thu Jul 30 14:25:44.875930 2026] [security2:error] [pid 1045527:tid 1045621] [remote 216.73.217.142:28162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulODbFEG16qLV_6Zd5EAAAU10"]
[Thu Jul 30 14:25:44.977940 2026] [security2:error] [pid 1045527:tid 1045749] [client 172.202.44.182:51302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/size.php"] [unique_id "amulODbFEG16qLV_6Zd5EgAAAFw"]
[Thu Jul 30 14:25:45.563147 2026] [security2:error] [pid 1045527:tid 1045706] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/info.php"] [unique_id "amulOTbFEG16qLV_6Zd5IAAAADE"]
[Thu Jul 30 14:25:45.802047 2026] [security2:error] [pid 1045527:tid 1045711] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/info.php%257e"] [unique_id "amulOTbFEG16qLV_6Zd5KAAAADY"]
[Thu Jul 30 14:25:45.991326 2026] [security2:error] [pid 1045527:tid 1045766] [client 177.6.106.101:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulOTbFEG16qLV_6Zd5LwAAAG0"]
[Thu Jul 30 14:25:45.991475 2026] [security2:error] [pid 1045527:tid 1045766] [client 177.6.106.101:56387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulOTbFEG16qLV_6Zd5LwAAAG0"]
[Thu Jul 30 14:25:46.046315 2026] [security2:error] [pid 1045527:tid 1045703] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/info.php%28%28"] [unique_id "amulOjbFEG16qLV_6Zd5MAAAAC4"]
[Thu Jul 30 14:25:46.285827 2026] [security2:error] [pid 1045527:tid 1045658] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/info.php/"] [unique_id "amulOjbFEG16qLV_6Zd5NwAAAAE"]
[Thu Jul 30 14:25:46.458279 2026] [security2:error] [pid 1045527:tid 1045687] [client 74.248.33.8:10989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/go.php"] [unique_id "amulOjbFEG16qLV_6Zd5PgAAAB4"]
[Thu Jul 30 14:25:46.532972 2026] [security2:error] [pid 1045527:tid 1045719] [client 172.202.44.182:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amulOjbFEG16qLV_6Zd5QAAAAD4"]
[Thu Jul 30 14:25:47.629144 2026] [security2:error] [pid 1045527:tid 1045744] [client 74.248.33.8:10952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/test1.php"] [unique_id "amulOzbFEG16qLV_6Zd5WgAAAFc"]
[Thu Jul 30 14:25:47.694529 2026] [security2:error] [pid 1045527:tid 1045752] [client 172.213.232.128:34306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amulOzbFEG16qLV_6Zd5XwAAAF8"]
[Thu Jul 30 14:25:47.817084 2026] [security2:error] [pid 1045527:tid 1045730] [client 172.202.44.182:19634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/403.php"] [unique_id "amulOzbFEG16qLV_6Zd5YAAAAEk"]
[Thu Jul 30 14:25:48.741079 2026] [security2:error] [pid 1045527:tid 1045715] [client 172.213.232.128:37381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amulPDbFEG16qLV_6Zd5fgAAADo"]
[Thu Jul 30 14:25:48.981882 2026] [core:error] [pid 1045527:tid 1045676] [client 138.246.253.24:49804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:48.981903 2026] [core:error] [pid 1045527:tid 1045676] [client 138.246.253.24:49804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:49.328698 2026] [security2:error] [pid 1045527:tid 1045741] [client 172.202.44.182:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amulPTbFEG16qLV_6Zd5jgAAAFQ"]
[Thu Jul 30 14:25:49.344735 2026] [core:error] [pid 1045527:tid 1045784] [client 74.248.33.8:41743] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:49.344765 2026] [core:error] [pid 1045527:tid 1045784] [client 74.248.33.8:41743] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:50.242295 2026] [security2:error] [pid 1045527:tid 1045776] [client 180.243.59.178:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulPjbFEG16qLV_6Zd5uQAAAHc"]
[Thu Jul 30 14:25:50.242464 2026] [security2:error] [pid 1045527:tid 1045776] [client 180.243.59.178:57557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulPjbFEG16qLV_6Zd5uQAAAHc"]
[Thu Jul 30 14:25:50.522324 2026] [security2:error] [pid 1045527:tid 1045598] [remote 216.73.217.142:56626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amulPjbFEG16qLV_6Zd5vwAALEY"]
[Thu Jul 30 14:25:50.772439 2026] [security2:error] [pid 1045527:tid 1045679] [client 172.213.232.128:37380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amulPjbFEG16qLV_6Zd5ywAAABY"]
[Thu Jul 30 14:25:51.339305 2026] [security2:error] [pid 1045527:tid 1045674] [client 172.213.232.128:31161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amulPzbFEG16qLV_6Zd52QAAABE"]
[Thu Jul 30 14:25:52.550338 2026] [security2:error] [pid 1045527:tid 1045755] [client 172.202.44.182:51645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/as.php"] [unique_id "amulQDbFEG16qLV_6Zd5-wAAAGI"]
[Thu Jul 30 14:25:53.222903 2026] [security2:error] [pid 1045527:tid 1045677] [client 172.213.232.128:16568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amulQTbFEG16qLV_6Zd6FAAAABQ"]
[Thu Jul 30 14:25:53.425755 2026] [security2:error] [pid 1045527:tid 1045710] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/phpinfo.php"] [unique_id "amulQTbFEG16qLV_6Zd6FgAAADU"]
[Thu Jul 30 14:25:53.587949 2026] [security2:error] [pid 1045527:tid 1045560] [remote 172.93.219.170:48482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.219.93.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amulQTbFEG16qLV_6Zd6GgAACyA"]
[Thu Jul 30 14:25:53.664324 2026] [security2:error] [pid 1045527:tid 1045742] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/phpinfo.php%255f"] [unique_id "amulQTbFEG16qLV_6Zd6HwAAAFU"]
[Thu Jul 30 14:25:53.766362 2026] [core:notice] [pid 1045527:tid 1045719] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:53.780018 2026] [security2:error] [pid 1045527:tid 1045667] [client 74.7.175.136:41424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.prednisone60mg.store.qsv.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amulQTbFEG16qLV_6Zd6KgAAAAo"]
[Thu Jul 30 14:25:53.904735 2026] [security2:error] [pid 1045527:tid 1045769] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/phpinfo.php%253c"] [unique_id "amulQTbFEG16qLV_6Zd6KwAAAHA"]
[Thu Jul 30 14:25:53.992272 2026] [security2:error] [pid 1045527:tid 1045773] [client 172.213.232.128:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-admin/xleet.php"] [unique_id "amulQTbFEG16qLV_6Zd6LAAAAHQ"]
[Thu Jul 30 14:25:54.011398 2026] [core:notice] [pid 1045527:tid 1045582] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:54.041552 2026] [security2:error] [pid 1045527:tid 1045688] [client 74.248.33.8:23636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/images/index.php"] [unique_id "amulQjbFEG16qLV_6Zd6LgAAAB8"]
[Thu Jul 30 14:25:54.146635 2026] [security2:error] [pid 1045527:tid 1045657] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/phpinfo.php%255d"] [unique_id "amulQjbFEG16qLV_6Zd6NwAAAAA"]
[Thu Jul 30 14:25:54.232324 2026] [security2:error] [pid 1045527:tid 1045747] [client 172.202.44.182:19638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amulQjbFEG16qLV_6Zd6OQAAAFo"]
[Thu Jul 30 14:25:54.541381 2026] [security2:error] [pid 1045527:tid 1045729] [client 172.213.232.128:29802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabian-tours.com"] [uri "/wp-config-sample.php"] [unique_id "amulQjbFEG16qLV_6Zd6QAAAAEg"]
[Thu Jul 30 14:25:54.638079 2026] [core:error] [pid 1045527:tid 1045698] [client 74.248.33.8:10998] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:54.638103 2026] [core:error] [pid 1045527:tid 1045698] [client 74.248.33.8:10998] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:25:54.747330 2026] [security2:error] [pid 1045527:tid 1045782] [client 50.6.43.217:15610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amulQjbFEG16qLV_6Zd6RQAAAH0"]
[Thu Jul 30 14:25:54.881261 2026] [security2:error] [pid 1045527:tid 1045571] [remote 216.73.217.142:56626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulQjbFEG16qLV_6Zd6UAAAYys"]
[Thu Jul 30 14:25:54.884520 2026] [security2:error] [pid 1045527:tid 1045690] [client 50.6.43.217:15618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amulQjbFEG16qLV_6Zd6SwAAACE"]
[Thu Jul 30 14:25:55.374632 2026] [security2:error] [pid 1045527:tid 1045705] [client 74.248.33.8:10945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/asd.php"] [unique_id "amulQzbFEG16qLV_6Zd6YgAAADA"]
[Thu Jul 30 14:25:55.423862 2026] [security2:error] [pid 1045527:tid 1045753] [client 172.202.44.182:51636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amulQzbFEG16qLV_6Zd6ZQAAAGA"]
[Thu Jul 30 14:25:55.832154 2026] [security2:error] [pid 1045527:tid 1045734] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/core%7e"] [unique_id "amulQzbFEG16qLV_6Zd6bgAAAE0"]
[Thu Jul 30 14:25:56.294209 2026] [security2:error] [pid 1045527:tid 1045700] [client 177.6.106.101:56786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulRDbFEG16qLV_6Zd6eAAAACs"]
[Thu Jul 30 14:25:56.294330 2026] [security2:error] [pid 1045527:tid 1045700] [client 177.6.106.101:56786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulRDbFEG16qLV_6Zd6eAAAACs"]
[Thu Jul 30 14:25:56.405118 2026] [security2:error] [pid 1045527:tid 1045669] [client 74.248.33.8:41788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amulRDbFEG16qLV_6Zd6fwAAAAw"]
[Thu Jul 30 14:25:56.830932 2026] [security2:error] [pid 1045527:tid 1045660] [client 172.202.44.182:51633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/plugins.php"] [unique_id "amulRDbFEG16qLV_6Zd6jwAAAAM"]
[Thu Jul 30 14:25:57.783010 2026] [security2:error] [pid 1045527:tid 1045767] [client 172.202.44.182:51585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/js/index.php"] [unique_id "amulRTbFEG16qLV_6Zd6qgAAAG4"]
[Thu Jul 30 14:25:58.507426 2026] [core:notice] [pid 1045527:tid 1045616] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:58.511693 2026] [core:notice] [pid 1045527:tid 1045655] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:25:59.262503 2026] [security2:error] [pid 1045527:tid 1045729] [client 172.202.44.182:44493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/go.php"] [unique_id "amulRzbFEG16qLV_6Zd61wAAAEg"]
[Thu Jul 30 14:25:59.661727 2026] [security2:error] [pid 1045527:tid 1045728] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amulRzbFEG16qLV_6Zd60gAAR2U"]
[Thu Jul 30 14:25:59.913501 2026] [core:notice] [pid 1045527:tid 1045595] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:00.018405 2026] [security2:error] [pid 1045527:tid 1045670] [client 74.248.33.8:43882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amulSDbFEG16qLV_6Zd67wAAAA0"]
[Thu Jul 30 14:26:00.548464 2026] [security2:error] [pid 1045527:tid 1045641] [remote 216.73.217.142:31180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulSDbFEG16qLV_6Zd6_wAAdXE"]
[Thu Jul 30 14:26:00.578678 2026] [core:notice] [pid 1045527:tid 1045636] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:00.588434 2026] [security2:error] [pid 1045527:tid 1045693] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/test.php"] [unique_id "amulSDbFEG16qLV_6Zd7BAAAACQ"]
[Thu Jul 30 14:26:00.690633 2026] [security2:error] [pid 1045527:tid 1045685] [client 74.248.33.8:14746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/atomlib.php"] [unique_id "amulSDbFEG16qLV_6Zd7CAAAABw"]
[Thu Jul 30 14:26:00.829204 2026] [security2:error] [pid 1045527:tid 1045759] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/test.php..."] [unique_id "amulSDbFEG16qLV_6Zd7CQAAAGY"]
[Thu Jul 30 14:26:00.913749 2026] [security2:error] [pid 1045527:tid 1045739] [client 180.243.59.178:58102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulSDbFEG16qLV_6Zd7DQAAAFI"]
[Thu Jul 30 14:26:00.913895 2026] [security2:error] [pid 1045527:tid 1045739] [client 180.243.59.178:58102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulSDbFEG16qLV_6Zd7DQAAAFI"]
[Thu Jul 30 14:26:01.072415 2026] [security2:error] [pid 1045527:tid 1045732] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/test.php%09%09"] [unique_id "amulSTbFEG16qLV_6Zd7DgAAAEs"]
[Thu Jul 30 14:26:01.147099 2026] [security2:error] [pid 1045527:tid 1045763] [client 172.202.44.182:44516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/test1.php"] [unique_id "amulSTbFEG16qLV_6Zd7EgAAAGo"]
[Thu Jul 30 14:26:01.313509 2026] [security2:error] [pid 1045527:tid 1045775] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/test.php...."] [unique_id "amulSTbFEG16qLV_6Zd7FgAAAHY"]
[Thu Jul 30 14:26:01.861246 2026] [core:error] [pid 1045527:tid 1045673] [client 74.248.33.8:43869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:01.861282 2026] [core:error] [pid 1045527:tid 1045673] [client 74.248.33.8:43869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:02.535106 2026] [security2:error] [pid 1045527:tid 1045751] [client 172.237.109.114:22436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulSTbFEG16qLV_6Zd7KQAAAF4"]
[Thu Jul 30 14:26:02.856042 2026] [security2:error] [pid 1045527:tid 1045739] [client 172.202.44.182:36714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/images/index.php"] [unique_id "amulSjbFEG16qLV_6Zd7SQAAAFI"]
[Thu Jul 30 14:26:02.984357 2026] [core:error] [pid 1045527:tid 1045773] [client 74.248.33.8:42986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:02.984380 2026] [core:error] [pid 1045527:tid 1045773] [client 74.248.33.8:42986] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:03.499794 2026] [security2:error] [pid 1045527:tid 1045662] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/localhost.sql"] [unique_id "amulSzbFEG16qLV_6Zd7YAAAAAU"]
[Thu Jul 30 14:26:03.552992 2026] [security2:error] [pid 1045527:tid 1045611] [remote 57.141.0.18:39394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/485177242/feed/rss2/"] [unique_id "amulSzbFEG16qLV_6Zd7YQAAdlM"]
[Thu Jul 30 14:26:04.107472 2026] [security2:error] [pid 1045527:tid 1045750] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/db.sql"] [unique_id "amulTDbFEG16qLV_6Zd7bwAAAF0"]
[Thu Jul 30 14:26:04.123421 2026] [security2:error] [pid 1045527:tid 1045741] [client 172.202.44.182:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/asd.php"] [unique_id "amulTDbFEG16qLV_6Zd7cAAAAFQ"]
[Thu Jul 30 14:26:04.885018 2026] [security2:error] [pid 1045527:tid 1045528] [remote 216.73.217.142:31180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amulTDbFEG16qLV_6Zd7igAAVgA"]
[Thu Jul 30 14:26:05.061901 2026] [security2:error] [pid 1045527:tid 1045777] [client 172.202.44.182:51664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amulTTbFEG16qLV_6Zd7jAAAAHg"]
[Thu Jul 30 14:26:05.882085 2026] [core:error] [pid 1045527:tid 1045696] [client 152.32.208.106:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:05.882108 2026] [core:error] [pid 1045527:tid 1045696] [client 152.32.208.106:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:06.117489 2026] [security2:error] [pid 1045527:tid 1045766] [client 172.202.44.182:51599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amulTjbFEG16qLV_6Zd7sQAAAG0"]
[Thu Jul 30 14:26:06.166104 2026] [security2:error] [pid 1045527:tid 1045772] [client 74.248.33.8:41079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amulTjbFEG16qLV_6Zd7sgAAAHM"]
[Thu Jul 30 14:26:06.950797 2026] [security2:error] [pid 1045527:tid 1045754] [client 177.6.106.101:57193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulTjbFEG16qLV_6Zd7zgAAAGE"]
[Thu Jul 30 14:26:06.950902 2026] [security2:error] [pid 1045527:tid 1045754] [client 177.6.106.101:57193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulTjbFEG16qLV_6Zd7zgAAAGE"]
[Thu Jul 30 14:26:07.079081 2026] [security2:error] [pid 1045527:tid 1045770] [client 43.130.71.237:49858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amulTjbFEG16qLV_6Zd7zwAAAHE"]
[Thu Jul 30 14:26:07.579731 2026] [security2:error] [pid 1045527:tid 1045765] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/backup.sql"] [unique_id "amulTzbFEG16qLV_6Zd8AwAAAGw"]
[Thu Jul 30 14:26:07.703450 2026] [security2:error] [pid 1045527:tid 1045732] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/backup.sql.php"] [unique_id "amulTzbFEG16qLV_6Zd8GAAAAEs"]
[Thu Jul 30 14:26:07.880728 2026] [security2:error] [pid 1045527:tid 1045691] [client 172.202.44.182:51649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/atomlib.php"] [unique_id "amulTzbFEG16qLV_6Zd8GwAAACI"]
[Thu Jul 30 14:26:08.456331 2026] [core:error] [pid 1045527:tid 1045769] [client 74.248.33.8:42953] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:08.456355 2026] [core:error] [pid 1045527:tid 1045769] [client 74.248.33.8:42953] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:08.904524 2026] [security2:error] [pid 1045527:tid 1045739] [client 166.205.97.96:33065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amulTzbFEG16qLV_6Zd76QAAUjg"], referer: https://jwcpartners.org/
[Thu Jul 30 14:26:08.904863 2026] [security2:error] [pid 1045527:tid 1045739] [client 166.205.97.96:33065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amulTzbFEG16qLV_6Zd8DgAAUlY"], referer: https://jwcpartners.org/
[Thu Jul 30 14:26:08.904972 2026] [security2:error] [pid 1045527:tid 1045739] [client 166.205.97.96:33065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amulTzbFEG16qLV_6Zd77AAAUi0"], referer: https://jwcpartners.org/
[Thu Jul 30 14:26:08.918781 2026] [security2:error] [pid 1045527:tid 1045725] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/index.php"] [unique_id "amulUDbFEG16qLV_6Zd8OwAAAEQ"]
[Thu Jul 30 14:26:09.159170 2026] [security2:error] [pid 1045527:tid 1045754] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/index.php%255f"] [unique_id "amulUTbFEG16qLV_6Zd8QQAAAGE"]
[Thu Jul 30 14:26:09.398704 2026] [security2:error] [pid 1045527:tid 1045685] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/index.php%255d"] [unique_id "amulUTbFEG16qLV_6Zd8TgAAABw"]
[Thu Jul 30 14:26:09.460990 2026] [security2:error] [pid 1045527:tid 1045714] [client 172.237.109.114:3566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulUDbFEG16qLV_6Zd8PAAAADk"]
[Thu Jul 30 14:26:09.530575 2026] [core:error] [pid 1045527:tid 1045659] [client 74.248.33.8:41067] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:09.530612 2026] [core:error] [pid 1045527:tid 1045659] [client 74.248.33.8:41067] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:09.642099 2026] [security2:error] [pid 1045527:tid 1045743] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/index.php.aws"] [unique_id "amulUTbFEG16qLV_6Zd8XQAAAFY"]
[Thu Jul 30 14:26:10.140995 2026] [security2:error] [pid 1045527:tid 1045764] [client 78.142.18.40:58632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/wp-login.php"] [unique_id "amulUjbFEG16qLV_6Zd8bQAAAGs"]
[Thu Jul 30 14:26:10.490138 2026] [proxy:error] [pid 1045527:tid 1045753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:26:10.490208 2026] [proxy_http:error] [pid 1045527:tid 1045753] [client 143.244.57.82:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:26:10.490768 2026] [proxy:error] [pid 1045527:tid 1045753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:26:10.490809 2026] [proxy_http:error] [pid 1045527:tid 1045753] [client 143.244.57.82:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:26:10.641954 2026] [security2:error] [pid 1045527:tid 1045666] [client 172.202.44.182:51667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amulUjbFEG16qLV_6Zd8ggAAAAk"]
[Thu Jul 30 14:26:10.744917 2026] [proxy:error] [pid 1045527:tid 1045698] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:26:10.744997 2026] [proxy_http:error] [pid 1045527:tid 1045698] [client 143.244.57.82:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:26:10.745548 2026] [proxy:error] [pid 1045527:tid 1045698] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:26:10.745599 2026] [proxy_http:error] [pid 1045527:tid 1045698] [client 143.244.57.82:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:26:10.998132 2026] [security2:error] [pid 1045527:tid 1045784] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amulUjbFEG16qLV_6Zd8jwAAAH8"]
[Thu Jul 30 14:26:11.053923 2026] [security2:error] [pid 1045527:tid 1045707] [client 180.243.59.178:58613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulUzbFEG16qLV_6Zd8lQAAADI"]
[Thu Jul 30 14:26:11.054061 2026] [security2:error] [pid 1045527:tid 1045707] [client 180.243.59.178:58613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulUzbFEG16qLV_6Zd8lQAAADI"]
[Thu Jul 30 14:26:11.257562 2026] [security2:error] [pid 1045527:tid 1045693] [client 143.244.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/xmlrpc.php"] [unique_id "amulUzbFEG16qLV_6Zd8mAAAACQ"]
[Thu Jul 30 14:26:11.264146 2026] [security2:error] [pid 1045527:tid 1045733] [client 181.188.216.140:35472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amulUzbFEG16qLV_6Zd8kQAAAEw"]
[Thu Jul 30 14:26:11.512618 2026] [proxy:error] [pid 1045527:tid 1045742] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:26:11.512693 2026] [proxy_http:error] [pid 1045527:tid 1045742] [client 143.244.57.82:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:26:11.513477 2026] [proxy:error] [pid 1045527:tid 1045742] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:26:11.513528 2026] [proxy_http:error] [pid 1045527:tid 1045742] [client 143.244.57.82:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:26:11.765916 2026] [security2:error] [pid 1045527:tid 1045777] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amulUzbFEG16qLV_6Zd8qAAAAHg"]
[Thu Jul 30 14:26:11.817199 2026] [security2:error] [pid 1045527:tid 1045716] [client 172.202.44.182:44497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wk/index.php"] [unique_id "amulUzbFEG16qLV_6Zd8rgAAADs"]
[Thu Jul 30 14:26:12.019161 2026] [security2:error] [pid 1045527:tid 1045696] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amulVDbFEG16qLV_6Zd8uAAAACc"]
[Thu Jul 30 14:26:12.271936 2026] [security2:error] [pid 1045527:tid 1045672] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amulVDbFEG16qLV_6Zd8uwAAAA8"]
[Thu Jul 30 14:26:12.342754 2026] [security2:error] [pid 1045527:tid 1045720] [client 172.202.44.182:44485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/inputs.php"] [unique_id "amulVDbFEG16qLV_6Zd8wAAAAD8"]
[Thu Jul 30 14:26:12.387857 2026] [core:error] [pid 1045527:tid 1045781] [client 74.248.33.8:16854] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:12.387879 2026] [core:error] [pid 1045527:tid 1045781] [client 74.248.33.8:16854] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:12.522277 2026] [security2:error] [pid 1045527:tid 1045674] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amulVDbFEG16qLV_6Zd8yAAAABE"]
[Thu Jul 30 14:26:12.685559 2026] [security2:error] [pid 1045527:tid 1045658] [client 172.202.44.182:36731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/av.php"] [unique_id "amulVDbFEG16qLV_6Zd8ywAAAAE"]
[Thu Jul 30 14:26:12.773071 2026] [security2:error] [pid 1045527:tid 1045736] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amulVDbFEG16qLV_6Zd8zAAAAE8"]
[Thu Jul 30 14:26:12.945390 2026] [core:error] [pid 1045527:tid 1045670] [client 152.32.208.106:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:12.945412 2026] [core:error] [pid 1045527:tid 1045670] [client 152.32.208.106:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:13.022723 2026] [security2:error] [pid 1045527:tid 1045677] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amulVTbFEG16qLV_6Zd82AAAABQ"]
[Thu Jul 30 14:26:13.132128 2026] [security2:error] [pid 1045527:tid 1045559] [remote 97.74.93.24:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amulVTbFEG16qLV_6Zd83QAAGh8"]
[Thu Jul 30 14:26:13.272206 2026] [security2:error] [pid 1045527:tid 1045724] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amulVTbFEG16qLV_6Zd83wAAAEM"]
[Thu Jul 30 14:26:13.435691 2026] [security2:error] [pid 1045527:tid 1045700] [client 74.248.33.8:16866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/inputs.php"] [unique_id "amulVTbFEG16qLV_6Zd85AAAACs"]
[Thu Jul 30 14:26:13.525156 2026] [security2:error] [pid 1045527:tid 1045748] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amulVTbFEG16qLV_6Zd86AAAAFs"]
[Thu Jul 30 14:26:13.776103 2026] [security2:error] [pid 1045527:tid 1045673] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amulVTbFEG16qLV_6Zd87gAAABA"]
[Thu Jul 30 14:26:14.030021 2026] [security2:error] [pid 1045527:tid 1045675] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amulVjbFEG16qLV_6Zd8-QAAABI"]
[Thu Jul 30 14:26:14.280898 2026] [security2:error] [pid 1045527:tid 1045772] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amulVjbFEG16qLV_6Zd9BAAAAHM"]
[Thu Jul 30 14:26:14.375569 2026] [security2:error] [pid 1045527:tid 1045566] [remote 57.141.0.40:41906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amulVjbFEG16qLV_6Zd9BgAARSY"]
[Thu Jul 30 14:26:14.535717 2026] [security2:error] [pid 1045527:tid 1045725] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amulVjbFEG16qLV_6Zd9EQAAAEQ"]
[Thu Jul 30 14:26:14.569157 2026] [security2:error] [pid 1045527:tid 1045782] [client 66.249.73.98:64185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amulUzbFEG16qLV_6Zd8sgAAAH0"]
[Thu Jul 30 14:26:14.805136 2026] [security2:error] [pid 1045527:tid 1045747] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amulVjbFEG16qLV_6Zd9GAAAAFo"]
[Thu Jul 30 14:26:14.828879 2026] [core:notice] [pid 1045527:tid 1045706] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:14.992120 2026] [security2:error] [pid 1045527:tid 1045682] [client 172.202.44.182:51664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/mini.php"] [unique_id "amulVjbFEG16qLV_6Zd9JwAAABk"]
[Thu Jul 30 14:26:15.059312 2026] [security2:error] [pid 1045527:tid 1045673] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amulVzbFEG16qLV_6Zd9LAAAABA"]
[Thu Jul 30 14:26:15.310355 2026] [security2:error] [pid 1045527:tid 1045684] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amulVzbFEG16qLV_6Zd9NAAAABs"]
[Thu Jul 30 14:26:15.485727 2026] [security2:error] [pid 1045527:tid 1045770] [client 43.157.20.63:56354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adviseassociates.com"] [uri "/index.php"] [unique_id "amulVjbFEG16qLV_6Zd8_wAAAHE"]
[Thu Jul 30 14:26:15.565201 2026] [security2:error] [pid 1045527:tid 1045776] [client 143.244.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalrelaxspa.sbs"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amulVzbFEG16qLV_6Zd9PQAAAHc"]
[Thu Jul 30 14:26:15.813075 2026] [security2:error] [pid 1045527:tid 1045726] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/settings.php.save"] [unique_id "amulVzbFEG16qLV_6Zd9RAAAAEU"]
[Thu Jul 30 14:26:15.814298 2026] [security2:error] [pid 1045527:tid 1045688] [client 172.202.44.182:51291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/index.php"] [unique_id "amulVzbFEG16qLV_6Zd9RQAAAB8"]
[Thu Jul 30 14:26:16.028079 2026] [core:error] [pid 1045527:tid 1045699] [client 152.32.208.106:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:16.028102 2026] [core:error] [pid 1045527:tid 1045699] [client 152.32.208.106:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:16.056892 2026] [security2:error] [pid 1045527:tid 1045703] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/settings.php.save%5f%5f"] [unique_id "amulWDbFEG16qLV_6Zd9TAAAAC4"]
[Thu Jul 30 14:26:16.299122 2026] [security2:error] [pid 1045527:tid 1045708] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/settings.php.save%29"] [unique_id "amulWDbFEG16qLV_6Zd9VAAAADM"]
[Thu Jul 30 14:26:16.376299 2026] [security2:error] [pid 1045527:tid 1045668] [client 74.248.33.8:11198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/index.php"] [unique_id "amulWDbFEG16qLV_6Zd9VQAAAAs"]
[Thu Jul 30 14:26:16.537812 2026] [security2:error] [pid 1045527:tid 1045683] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/settings.php.save.aws"] [unique_id "amulWDbFEG16qLV_6Zd9WAAAABo"]
[Thu Jul 30 14:26:17.021914 2026] [security2:error] [pid 1045527:tid 1045691] [client 172.202.44.182:51663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/aa.php"] [unique_id "amulWTbFEG16qLV_6Zd9awAAACI"]
[Thu Jul 30 14:26:17.426653 2026] [security2:error] [pid 1045527:tid 1045696] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulWTbFEG16qLV_6Zd9dwAAACc"]
[Thu Jul 30 14:26:17.484655 2026] [security2:error] [pid 1045527:tid 1045680] [client 172.237.109.114:2062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulWTbFEG16qLV_6Zd9agAAABc"]
[Thu Jul 30 14:26:17.662468 2026] [security2:error] [pid 1045527:tid 1045751] [client 177.6.106.101:53589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulWTbFEG16qLV_6Zd9fgAAAF4"]
[Thu Jul 30 14:26:17.662583 2026] [security2:error] [pid 1045527:tid 1045751] [client 177.6.106.101:53589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulWTbFEG16qLV_6Zd9fgAAAF4"]
[Thu Jul 30 14:26:17.714018 2026] [security2:error] [pid 1045527:tid 1045756] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulWTbFEG16qLV_6Zd9gQAAAGM"]
[Thu Jul 30 14:26:17.848852 2026] [security2:error] [pid 1045527:tid 1045549] [remote 57.141.0.36:64982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amulWTbFEG16qLV_6Zd9eQAAGxU"]
[Thu Jul 30 14:26:18.432311 2026] [security2:error] [pid 1045527:tid 1045752] [client 74.248.33.8:16935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/network/index.php"] [unique_id "amulWjbFEG16qLV_6Zd9lQAAAF8"]
[Thu Jul 30 14:26:18.501448 2026] [security2:error] [pid 1045527:tid 1045672] [client 172.202.44.182:36728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/network/index.php"] [unique_id "amulWjbFEG16qLV_6Zd9lwAAAA8"]
[Thu Jul 30 14:26:18.836818 2026] [security2:error] [pid 1045527:tid 1045715] [client 172.202.44.182:51667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/w.php"] [unique_id "amulWjbFEG16qLV_6Zd9pAAAADo"]
[Thu Jul 30 14:26:19.290266 2026] [security2:error] [pid 1045527:tid 1045673] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/database.sql"] [unique_id "amulWzbFEG16qLV_6Zd9sgAAABA"]
[Thu Jul 30 14:26:19.390073 2026] [security2:error] [pid 1045527:tid 1045722] [client 172.202.44.182:36693] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kicksity.com"] [uri "/wp-content/1.php"] [unique_id "amulWzbFEG16qLV_6Zd9tgAAAEE"]
[Thu Jul 30 14:26:19.390200 2026] [security2:error] [pid 1045527:tid 1045722] [client 172.202.44.182:36693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/1.php"] [unique_id "amulWzbFEG16qLV_6Zd9tgAAAEE"]
[Thu Jul 30 14:26:19.852275 2026] [security2:error] [pid 1045527:tid 1045732] [client 172.202.44.182:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/admin.php"] [unique_id "amulWzbFEG16qLV_6Zd9yQAAAEs"]
[Thu Jul 30 14:26:21.038514 2026] [security2:error] [pid 1045527:tid 1045724] [client 172.202.44.182:44514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/plugin.php"] [unique_id "amulXTbFEG16qLV_6Zd99AAAAEM"]
[Thu Jul 30 14:26:21.043924 2026] [security2:error] [pid 1045527:tid 1045614] [remote 57.141.0.8:65236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55089810635/feed/rss2/"] [unique_id "amulXDbFEG16qLV_6Zd95gAAHlY"]
[Thu Jul 30 14:26:21.133641 2026] [security2:error] [pid 1045527:tid 1045779] [client 172.202.44.182:44517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amulXTbFEG16qLV_6Zd99gAAAHo"]
[Thu Jul 30 14:26:21.250714 2026] [security2:error] [pid 1045527:tid 1045745] [client 74.248.33.8:11186] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.svcambodia.com"] [uri "/wp-content/1.php"] [unique_id "amulXTbFEG16qLV_6Zd9_AAAAFg"]
[Thu Jul 30 14:26:21.250830 2026] [security2:error] [pid 1045527:tid 1045745] [client 74.248.33.8:11186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/1.php"] [unique_id "amulXTbFEG16qLV_6Zd9_AAAAFg"]
[Thu Jul 30 14:26:21.523348 2026] [security2:error] [pid 1045527:tid 1045748] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amulXDbFEG16qLV_6Zd98gAAW10"]
[Thu Jul 30 14:26:21.605781 2026] [autoindex:error] [pid 1045527:tid 1045699] [client 195.96.139.179:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.otbola.click:2082
[Thu Jul 30 14:26:21.663661 2026] [security2:error] [pid 1045527:tid 1045664] [client 74.7.230.35:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.parkingandtransport.com"] [uri "/404.html"] [unique_id "amulXTbFEG16qLV_6Zd-CwAAAAc"]
[Thu Jul 30 14:26:21.664214 2026] [security2:error] [pid 1045527:tid 1045775] [client 74.7.230.35:56012] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.parkingandtransport.com"] [uri "/robots.txt"] [unique_id "amulXTbFEG16qLV_6Zd-CQAAdjA"]
[Thu Jul 30 14:26:22.473369 2026] [security2:error] [pid 1045527:tid 1045729] [client 172.237.109.114:12617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulXTbFEG16qLV_6Zd-GgAAAEg"]
[Thu Jul 30 14:26:22.517725 2026] [security2:error] [pid 1045527:tid 1045685] [client 180.243.59.178:59208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulXjbFEG16qLV_6Zd-LQAAABw"]
[Thu Jul 30 14:26:22.517828 2026] [security2:error] [pid 1045527:tid 1045685] [client 180.243.59.178:59208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulXjbFEG16qLV_6Zd-LQAAABw"]
[Thu Jul 30 14:26:22.568715 2026] [security2:error] [pid 1045527:tid 1045723] [client 172.202.44.182:51709] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kicksity.com"] [uri "/1.php"] [unique_id "amulXjbFEG16qLV_6Zd-LwAAAEI"]
[Thu Jul 30 14:26:22.568835 2026] [security2:error] [pid 1045527:tid 1045723] [client 172.202.44.182:51709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/1.php"] [unique_id "amulXjbFEG16qLV_6Zd-LwAAAEI"]
[Thu Jul 30 14:26:22.596368 2026] [security2:error] [pid 1045527:tid 1045712] [client 54.209.100.30:57219] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/10/preso-300x172.jpg"] [unique_id "amulXjbFEG16qLV_6Zd-MAAAADc"]
[Thu Jul 30 14:26:23.241831 2026] [security2:error] [pid 1045527:tid 1045754] [client 74.248.33.8:16939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/plugin.php"] [unique_id "amulXzbFEG16qLV_6Zd-QQAAAGE"]
[Thu Jul 30 14:26:23.486237 2026] [rewrite:error] [pid 1045527:tid 1045769] [client 185.177.72.10:0] AH10508: Unsafe URL with %3f URL rewritten without UnsafeAllow3F
[Thu Jul 30 14:26:23.554070 2026] [security2:error] [pid 1045527:tid 1045690] [client 172.202.44.182:36690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/gg.php"] [unique_id "amulXzbFEG16qLV_6Zd-TwAAACE"]
[Thu Jul 30 14:26:23.574625 2026] [security2:error] [pid 1045527:tid 1045658] [client 172.202.44.182:51705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/m.php"] [unique_id "amulXzbFEG16qLV_6Zd-UAAAAAE"]
[Thu Jul 30 14:26:23.898729 2026] [security2:error] [pid 1045527:tid 1045670] [client 74.248.33.8:10270] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.svcambodia.com"] [uri "/1.php"] [unique_id "amulXzbFEG16qLV_6Zd-VQAAAA0"]
[Thu Jul 30 14:26:23.898853 2026] [security2:error] [pid 1045527:tid 1045670] [client 74.248.33.8:10270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/1.php"] [unique_id "amulXzbFEG16qLV_6Zd-VQAAAA0"]
[Thu Jul 30 14:26:24.496900 2026] [security2:error] [pid 1045527:tid 1045762] [client 34.238.253.213:36254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amulYDbFEG16qLV_6Zd-YQAAaSU"]
[Thu Jul 30 14:26:24.521163 2026] [security2:error] [pid 1045527:tid 1045706] [client 172.202.44.182:51599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amulYDbFEG16qLV_6Zd-agAAADE"]
[Thu Jul 30 14:26:24.761805 2026] [security2:error] [pid 1045527:tid 1045682] [client 74.248.33.8:17750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/gg.php"] [unique_id "amulYDbFEG16qLV_6Zd-bwAAABk"]
[Thu Jul 30 14:26:25.074658 2026] [security2:error] [pid 1045527:tid 1045763] [client 172.202.44.182:51662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp.php"] [unique_id "amulYTbFEG16qLV_6Zd-hwAAAGo"]
[Thu Jul 30 14:26:25.476904 2026] [core:error] [pid 1045527:tid 1045693] [client 74.248.33.8:19726] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:25.476926 2026] [core:error] [pid 1045527:tid 1045693] [client 74.248.33.8:19726] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:26.232429 2026] [security2:error] [pid 1045527:tid 1045742] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulYjbFEG16qLV_6Zd-xQAAAFU"]
[Thu Jul 30 14:26:26.359380 2026] [security2:error] [pid 1045527:tid 1045781] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env%5e"] [unique_id "amulYjbFEG16qLV_6Zd-xgAAAHw"]
[Thu Jul 30 14:26:26.661864 2026] [security2:error] [pid 1045527:tid 1045730] [client 74.248.33.8:10824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp.php"] [unique_id "amulYjbFEG16qLV_6Zd-0gAAAEk"]
[Thu Jul 30 14:26:26.844823 2026] [security2:error] [pid 1045527:tid 1045747] [client 172.202.44.182:36709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amulYjbFEG16qLV_6Zd-2gAAAFo"]
[Thu Jul 30 14:26:26.856028 2026] [autoindex:error] [pid 1045527:tid 1045675] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:26:27.088209 2026] [security2:error] [pid 1045527:tid 1045713] [client 172.202.44.182:51686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/classwithtostring.php"] [unique_id "amulYzbFEG16qLV_6Zd-4QAAADg"]
[Thu Jul 30 14:26:27.272769 2026] [core:notice] [pid 1045527:tid 1045665] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:27.558716 2026] [fcgid:warn] [pid 1045527:tid 1045759] (70014)End of file found: [client 118.193.69.177:55332] mod_fcgid: can't get data from http client
[Thu Jul 30 14:26:27.770779 2026] [security2:error] [pid 1045527:tid 1045663] [client 158.158.105.63:54000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amulYzbFEG16qLV_6Zd--AAAAAY"]
[Thu Jul 30 14:26:27.770884 2026] [security2:error] [pid 1045527:tid 1045663] [client 158.158.105.63:54000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amulYzbFEG16qLV_6Zd--AAAAAY"]
[Thu Jul 30 14:26:27.776544 2026] [security2:error] [pid 1045527:tid 1045757] [client 172.202.44.182:51707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/file.php"] [unique_id "amulYzbFEG16qLV_6Zd--QAAAGQ"]
[Thu Jul 30 14:26:28.094510 2026] [security2:error] [pid 1045527:tid 1045783] [client 177.6.106.101:53976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulZDbFEG16qLV_6Zd-_wAAAH4"]
[Thu Jul 30 14:26:28.094643 2026] [security2:error] [pid 1045527:tid 1045783] [client 177.6.106.101:53976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulZDbFEG16qLV_6Zd-_wAAAH4"]
[Thu Jul 30 14:26:28.244477 2026] [security2:error] [pid 1045527:tid 1045753] [client 74.248.33.8:10850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amulZDbFEG16qLV_6Zd_DAAAAGA"]
[Thu Jul 30 14:26:28.274286 2026] [security2:error] [pid 1045527:tid 1045739] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/_profiler%00"] [unique_id "amulZDbFEG16qLV_6Zd_DQAAAFI"]
[Thu Jul 30 14:26:28.888997 2026] [rewrite:error] [pid 1045527:tid 1045724] [client 185.177.72.10:0] AH10508: Unsafe URL with %3f URL rewritten without UnsafeAllow3F
[Thu Jul 30 14:26:29.493718 2026] [security2:error] [pid 1045527:tid 1045683] [client 172.237.109.114:47870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulZTbFEG16qLV_6Zd_IgAAABo"]
[Thu Jul 30 14:26:29.894517 2026] [security2:error] [pid 1045527:tid 1045704] [client 172.202.44.182:51656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/gmo.php"] [unique_id "amulZTbFEG16qLV_6Zd_QgAAAC8"]
[Thu Jul 30 14:26:31.120352 2026] [rewrite:error] [pid 1045527:tid 1045685] [client 185.177.72.10:0] AH10508: Unsafe URL with %3f URL rewritten without UnsafeAllow3F
[Thu Jul 30 14:26:31.383726 2026] [security2:error] [pid 1045527:tid 1045702] [client 172.202.44.182:51669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-content/languages/index.php"] [unique_id "amulZzbFEG16qLV_6Zd_bgAAAC0"]
[Thu Jul 30 14:26:31.667611 2026] [security2:error] [pid 1045527:tid 1045775] [client 172.202.44.182:51704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/user/index.php"] [unique_id "amulZzbFEG16qLV_6Zd_dgAAAHY"]
[Thu Jul 30 14:26:32.234199 2026] [security2:error] [pid 1045527:tid 1045667] [client 180.243.59.178:59717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulaDbFEG16qLV_6Zd_hQAAAAo"]
[Thu Jul 30 14:26:32.234357 2026] [security2:error] [pid 1045527:tid 1045667] [client 180.243.59.178:59717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulaDbFEG16qLV_6Zd_hQAAAAo"]
[Thu Jul 30 14:26:32.247117 2026] [security2:error] [pid 1045527:tid 1045770] [client 172.202.44.182:36674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-the.php"] [unique_id "amulaDbFEG16qLV_6Zd_hgAAAHE"]
[Thu Jul 30 14:26:32.387139 2026] [security2:error] [pid 1045527:tid 1045747] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amulZzbFEG16qLV_6Zd_dAAAWmM"]
[Thu Jul 30 14:26:32.662295 2026] [core:notice] [pid 1045527:tid 1045736] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:33.065225 2026] [security2:error] [pid 1045527:tid 1045710] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/erp~"] [unique_id "amulaTbFEG16qLV_6Zd_nwAAADU"]
[Thu Jul 30 14:26:33.895842 2026] [security2:error] [pid 1045527:tid 1045717] [client 172.202.44.182:36702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/404.php"] [unique_id "amulaTbFEG16qLV_6Zd_rAAAADw"]
[Thu Jul 30 14:26:34.529683 2026] [security2:error] [pid 1045527:tid 1045530] [remote 74.7.227.39:43284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amulajbFEG16qLV_6Zd_wgAAZgI"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:26:35.125434 2026] [security2:error] [pid 1045527:tid 1045667] [client 172.202.44.182:51716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/init.php"] [unique_id "amulazbFEG16qLV_6Zd_2QAAAAo"]
[Thu Jul 30 14:26:35.204337 2026] [core:notice] [pid 1045527:tid 1045727] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:35.612914 2026] [security2:error] [pid 1045527:tid 1045660] [client 172.202.44.182:44521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amulazbFEG16qLV_6Zd_6QAAAAM"]
[Thu Jul 30 14:26:35.694246 2026] [security2:error] [pid 1045527:tid 1045676] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/prod.htaccess"] [unique_id "amulazbFEG16qLV_6Zd_7QAAABM"]
[Thu Jul 30 14:26:35.965081 2026] [security2:error] [pid 1045527:tid 1045695] [client 74.248.33.8:10838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/file.php"] [unique_id "amulazbFEG16qLV_6Zd_8QAAACY"]
[Thu Jul 30 14:26:35.973028 2026] [security2:error] [pid 1045527:tid 1045771] [client 57.141.0.31:32026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amulazbFEG16qLV_6Zd_6AAAcgQ"], referer: https://igetvape-australia.com/product/iget-bar-plus-s3-pod-double-apple/
[Thu Jul 30 14:26:36.024182 2026] [core:notice] [pid 1045527:tid 1045653] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:36.106322 2026] [security2:error] [pid 1045527:tid 1045781] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amulazbFEG16qLV_6Zd_4AAAAHw"]
[Thu Jul 30 14:26:36.131837 2026] [core:notice] [pid 1045527:tid 1045665] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:36.509199 2026] [security2:error] [pid 1045527:tid 1045760] [client 81.171.74.60:43000] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeABwAAAGc"]
[Thu Jul 30 14:26:36.513342 2026] [security2:error] [pid 1045527:tid 1045677] [client 91.148.244.131:37764] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeACAAAABQ"]
[Thu Jul 30 14:26:36.514274 2026] [security2:error] [pid 1045527:tid 1045767] [client 91.148.244.131:37772] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeACQAAAG4"]
[Thu Jul 30 14:26:36.524747 2026] [security2:error] [pid 1045527:tid 1045755] [client 81.171.74.60:43022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeACwAAAGI"]
[Thu Jul 30 14:26:36.527290 2026] [security2:error] [pid 1045527:tid 1045749] [client 91.148.244.131:37762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeADQAAAFw"]
[Thu Jul 30 14:26:36.541360 2026] [security2:error] [pid 1045527:tid 1045741] [client 81.171.72.135:59378] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeADwAAAFQ"]
[Thu Jul 30 14:26:36.542602 2026] [security2:error] [pid 1045527:tid 1045747] [client 81.171.72.135:59376] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAEAAAAFo"]
[Thu Jul 30 14:26:36.548520 2026] [security2:error] [pid 1045527:tid 1045770] [client 81.171.74.60:43002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAEQAAAHE"]
[Thu Jul 30 14:26:36.551933 2026] [security2:error] [pid 1045527:tid 1045784] [client 91.148.245.81:42002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAEgAAAH8"]
[Thu Jul 30 14:26:36.554418 2026] [security2:error] [pid 1045527:tid 1045681] [client 91.148.245.81:41992] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAEwAAABg"]
[Thu Jul 30 14:26:36.556455 2026] [security2:error] [pid 1045527:tid 1045678] [client 91.148.245.81:41994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAFAAAABU"]
[Thu Jul 30 14:26:36.557710 2026] [security2:error] [pid 1045527:tid 1045688] [client 81.171.72.135:59380] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAFQAAAB8"]
[Thu Jul 30 14:26:36.564582 2026] [security2:error] [pid 1045527:tid 1045715] [client 91.148.245.81:42018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAFgAAADo"]
[Thu Jul 30 14:26:36.566088 2026] [security2:error] [pid 1045527:tid 1045657] [client 91.148.245.81:42034] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAFwAAAAA"]
[Thu Jul 30 14:26:36.729636 2026] [security2:error] [pid 1045527:tid 1045780] [client 91.148.245.81:42042] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAHwAAAHs"]
[Thu Jul 30 14:26:36.740743 2026] [security2:error] [pid 1045527:tid 1045698] [client 91.148.245.81:42038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAIAAAACk"]
[Thu Jul 30 14:26:36.746824 2026] [security2:error] [pid 1045527:tid 1045667] [client 91.148.245.81:42040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/"] [unique_id "amulbDbFEG16qLV_6ZeAIQAAAAo"]
[Thu Jul 30 14:26:36.891921 2026] [security2:error] [pid 1045527:tid 1045756] [client 74.248.33.8:19748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/user/index.php"] [unique_id "amulbDbFEG16qLV_6ZeAIwAAAGM"]
[Thu Jul 30 14:26:37.042365 2026] [core:notice] [pid 1045527:tid 1045528] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:37.049717 2026] [core:notice] [pid 1045527:tid 1045552] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:37.052066 2026] [core:notice] [pid 1045527:tid 1045652] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:37.153530 2026] [security2:error] [pid 1045527:tid 1045664] [client 91.148.244.131:37782] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/api/.env"] [unique_id "amulbTbFEG16qLV_6ZeALwAAAAc"]
[Thu Jul 30 14:26:37.154037 2026] [security2:error] [pid 1045527:tid 1045734] [client 91.148.244.131:37784] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/backup.zip"] [unique_id "amulbTbFEG16qLV_6ZeAMAAAAE0"]
[Thu Jul 30 14:26:37.154064 2026] [security2:error] [pid 1045527:tid 1045699] [client 81.171.74.60:43040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/config.php"] [unique_id "amulbTbFEG16qLV_6ZeAMQAAACo"]
[Thu Jul 30 14:26:37.161849 2026] [security2:error] [pid 1045527:tid 1045769] [client 91.148.244.131:37790] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/dump.sql"] [unique_id "amulbTbFEG16qLV_6ZeANAAAAHA"]
[Thu Jul 30 14:26:37.162610 2026] [security2:error] [pid 1045527:tid 1045674] [client 81.171.74.60:43050] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/wp-config.php"] [unique_id "amulbTbFEG16qLV_6ZeANQAAABE"]
[Thu Jul 30 14:26:37.178468 2026] [security2:error] [pid 1045527:tid 1045708] [client 81.171.74.60:43028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/storage/logs/laravel.log"] [unique_id "amulbTbFEG16qLV_6ZeANwAAADM"]
[Thu Jul 30 14:26:37.180490 2026] [security2:error] [pid 1045527:tid 1045707] [client 91.148.244.131:37786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/storage/logs/laravel.log"] [unique_id "amulbTbFEG16qLV_6ZeAOQAAADI"]
[Thu Jul 30 14:26:37.182900 2026] [security2:error] [pid 1045527:tid 1045744] [client 91.148.245.81:42090] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/storage/logs/laravel.log"] [unique_id "amulbTbFEG16qLV_6ZeAOgAAAFc"]
[Thu Jul 30 14:26:37.189800 2026] [security2:error] [pid 1045527:tid 1045781] [client 81.171.72.135:59422] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/_vti_pvt/service.pwd"] [unique_id "amulbTbFEG16qLV_6ZeAPAAAAHw"]
[Thu Jul 30 14:26:37.193686 2026] [core:notice] [pid 1045527:tid 1045539] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:37.195755 2026] [security2:error] [pid 1045527:tid 1045737] [client 81.171.72.135:59428] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/storage/logs/laravel.log"] [unique_id "amulbTbFEG16qLV_6ZeAPgAAAFA"]
[Thu Jul 30 14:26:37.196362 2026] [security2:error] [pid 1045527:tid 1045742] [client 91.148.245.81:42078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/backup.zip"] [unique_id "amulbTbFEG16qLV_6ZeAPwAAAFU"]
[Thu Jul 30 14:26:37.203022 2026] [core:notice] [pid 1045527:tid 1045643] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:37.206699 2026] [security2:error] [pid 1045527:tid 1045683] [client 91.148.245.81:42114] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/storage/logs/laravel.log"] [unique_id "amulbTbFEG16qLV_6ZeAQQAAABo"]
[Thu Jul 30 14:26:37.207042 2026] [security2:error] [pid 1045527:tid 1045746] [client 91.148.245.81:42122] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/config.xml"] [unique_id "amulbTbFEG16qLV_6ZeAQgAAAFk"]
[Thu Jul 30 14:26:37.209149 2026] [security2:error] [pid 1045527:tid 1045774] [client 91.148.245.81:42058] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/config.xml"] [unique_id "amulbTbFEG16qLV_6ZeAQwAAAHU"]
[Thu Jul 30 14:26:37.212772 2026] [security2:error] [pid 1045527:tid 1045685] [client 91.148.245.81:42072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/wp-admin/setup-config.php"] [unique_id "amulbTbFEG16qLV_6ZeARAAAABw"]
[Thu Jul 30 14:26:37.228630 2026] [security2:error] [pid 1045527:tid 1045719] [client 91.148.245.81:42124] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/database.sql"] [unique_id "amulbTbFEG16qLV_6ZeARQAAAD4"]
[Thu Jul 30 14:26:37.246437 2026] [core:notice] [pid 1045527:tid 1045564] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:37.357514 2026] [security2:error] [pid 1045527:tid 1045665] [client 81.171.72.135:59398] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/etc/ssl/private/server.key"] [unique_id "amulbTbFEG16qLV_6ZeASAAAAAg"]
[Thu Jul 30 14:26:37.461080 2026] [security2:error] [pid 1045527:tid 1045739] [client 91.148.245.81:42160] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/actuator/heapdump"] [unique_id "amulbTbFEG16qLV_6ZeASgAAAFI"]
[Thu Jul 30 14:26:37.489130 2026] [security2:error] [pid 1045527:tid 1045752] [client 91.148.245.81:42138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/storage/logs/laravel.log"] [unique_id "amulbTbFEG16qLV_6ZeATwAAAF8"]
[Thu Jul 30 14:26:37.497419 2026] [security2:error] [pid 1045527:tid 1045729] [client 91.148.245.81:42136] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/user_secrets.yml"] [unique_id "amulbTbFEG16qLV_6ZeAUAAAAEg"]
[Thu Jul 30 14:26:37.776913 2026] [security2:error] [pid 1045527:tid 1045751] [client 91.148.244.131:37834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.svn/wc.db"] [unique_id "amulbTbFEG16qLV_6ZeAXAAAAF4"]
[Thu Jul 30 14:26:37.789137 2026] [security2:error] [pid 1045527:tid 1045692] [client 91.148.244.131:37824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/actuator/heapdump"] [unique_id "amulbTbFEG16qLV_6ZeAXQAAACM"]
[Thu Jul 30 14:26:37.789477 2026] [security2:error] [pid 1045527:tid 1045717] [client 81.171.74.60:43090] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.ssh/id_ed25519"] [unique_id "amulbTbFEG16qLV_6ZeAXgAAADw"]
[Thu Jul 30 14:26:37.798934 2026] [security2:error] [pid 1045527:tid 1045695] [client 91.148.244.131:37858] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.ssh/id_ecdsa"] [unique_id "amulbTbFEG16qLV_6ZeAXwAAACY"]
[Thu Jul 30 14:26:37.803481 2026] [security2:error] [pid 1045527:tid 1045771] [client 91.148.244.131:37820] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/backup.tar.gz"] [unique_id "amulbTbFEG16qLV_6ZeAYAAAAHI"]
[Thu Jul 30 14:26:37.806898 2026] [security2:error] [pid 1045527:tid 1045700] [client 81.171.74.60:43058] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.svn/wc.db"] [unique_id "amulbTbFEG16qLV_6ZeAYgAAACs"]
[Thu Jul 30 14:26:37.813510 2026] [security2:error] [pid 1045527:tid 1045690] [client 91.148.245.81:42188] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.svn/wc.db"] [unique_id "amulbTbFEG16qLV_6ZeAZAAAACE"]
[Thu Jul 30 14:26:37.813756 2026] [security2:error] [pid 1045527:tid 1045658] [client 91.148.245.81:42258] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/dump.sql"] [unique_id "amulbTbFEG16qLV_6ZeAZQAAAAE"]
[Thu Jul 30 14:26:37.814054 2026] [security2:error] [pid 1045527:tid 1045731] [client 91.148.245.81:42222] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/backup.sql"] [unique_id "amulbTbFEG16qLV_6ZeAZgAAAEo"]
[Thu Jul 30 14:26:37.814202 2026] [security2:error] [pid 1045527:tid 1045673] [client 81.171.74.60:43068] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/backup.zip"] [unique_id "amulbTbFEG16qLV_6ZeAZwAAABA"]
[Thu Jul 30 14:26:37.816341 2026] [security2:error] [pid 1045527:tid 1045718] [client 91.148.245.81:42168] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/backup.tar.gz"] [unique_id "amulbTbFEG16qLV_6ZeAaAAAAD0"]
[Thu Jul 30 14:26:37.817718 2026] [security2:error] [pid 1045527:tid 1045728] [client 91.148.245.81:42186] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/actuator/heapdump"] [unique_id "amulbTbFEG16qLV_6ZeAaQAAAEc"]
[Thu Jul 30 14:26:37.827894 2026] [security2:error] [pid 1045527:tid 1045661] [client 81.171.74.60:43086] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/actuator/heapdump"] [unique_id "amulbTbFEG16qLV_6ZeAbAAAAAQ"]
[Thu Jul 30 14:26:37.844556 2026] [security2:error] [pid 1045527:tid 1045689] [client 91.148.245.81:42202] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.ssh/id_ed25519"] [unique_id "amulbTbFEG16qLV_6ZeAbQAAACA"]
[Thu Jul 30 14:26:37.844911 2026] [security2:error] [pid 1045527:tid 1045699] [client 81.171.72.135:59464] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.env.production"] [unique_id "amulbTbFEG16qLV_6ZeAbgAAACo"]
[Thu Jul 30 14:26:37.845634 2026] [security2:error] [pid 1045527:tid 1045704] [client 91.148.245.81:42240] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/config.php"] [unique_id "amulbTbFEG16qLV_6ZeAbwAAAC8"]
[Thu Jul 30 14:26:37.863504 2026] [security2:error] [pid 1045527:tid 1045734] [client 81.171.72.135:59444] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.git/HEAD"] [unique_id "amulbTbFEG16qLV_6ZeAcAAAAE0"]
[Thu Jul 30 14:26:37.864708 2026] [security2:error] [pid 1045527:tid 1045773] [client 81.171.72.135:59462] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/api/.env"] [unique_id "amulbTbFEG16qLV_6ZeAcQAAAHQ"]
[Thu Jul 30 14:26:37.867292 2026] [security2:error] [pid 1045527:tid 1045769] [client 81.171.72.135:59450] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/wp-admin/setup-config.php"] [unique_id "amulbTbFEG16qLV_6ZeAcgAAAHA"]
[Thu Jul 30 14:26:37.900576 2026] [security2:error] [pid 1045527:tid 1045760] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "amulbTbFEG16qLV_6ZeAcwAAAGc"]
[Thu Jul 30 14:26:37.924417 2026] [security2:error] [pid 1045527:tid 1045775] [client 91.148.244.131:37848] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.ssh/id_ed25519"] [unique_id "amulbTbFEG16qLV_6ZeAdAAAAHY"]
[Thu Jul 30 14:26:37.925266 2026] [security2:error] [pid 1045527:tid 1045740] [client 91.148.244.131:37806] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/backup.sql"] [unique_id "amulbTbFEG16qLV_6ZeAdQAAAFM"]
[Thu Jul 30 14:26:37.931013 2026] [security2:error] [pid 1045527:tid 1045759] [client 81.171.74.60:43084] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/docker-compose.yml"] [unique_id "amulbTbFEG16qLV_6ZeAdgAAAGY"]
[Thu Jul 30 14:26:37.946271 2026] [core:notice] [pid 1045527:tid 1045598] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:37.947656 2026] [security2:error] [pid 1045527:tid 1045779] [client 91.148.245.81:42264] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.env"] [unique_id "amulbTbFEG16qLV_6ZeAeAAAAHo"]
[Thu Jul 30 14:26:37.958372 2026] [security2:error] [pid 1045527:tid 1045716] [client 172.202.44.182:36681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/index/function.php"] [unique_id "amulbTbFEG16qLV_6ZeAeQAAADs"]
[Thu Jul 30 14:26:37.999653 2026] [security2:error] [pid 1045527:tid 1045674] [client 81.171.72.135:59468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.env"] [unique_id "amulbTbFEG16qLV_6ZeAegAAABE"]
[Thu Jul 30 14:26:38.064143 2026] [core:notice] [pid 1045527:tid 1045550] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:38.064158 2026] [core:error] [pid 1045527:tid 1045659] [client 74.248.33.8:10660] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:38.064177 2026] [core:error] [pid 1045527:tid 1045659] [client 74.248.33.8:10660] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:38.185207 2026] [core:notice] [pid 1045527:tid 1045589] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:38.324558 2026] [security2:error] [pid 1045527:tid 1045705] [client 91.148.244.131:37882] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/database.sql"] [unique_id "amulbjbFEG16qLV_6ZeAjwAAADA"]
[Thu Jul 30 14:26:38.341791 2026] [security2:error] [pid 1045527:tid 1045697] [client 91.148.244.131:37884] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/database_backup.sql"] [unique_id "amulbjbFEG16qLV_6ZeAkAAAACg"]
[Thu Jul 30 14:26:38.347626 2026] [security2:error] [pid 1045527:tid 1045780] [client 91.148.244.131:37912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/config.xml"] [unique_id "amulbjbFEG16qLV_6ZeAkQAAAHs"]
[Thu Jul 30 14:26:38.357068 2026] [security2:error] [pid 1045527:tid 1045680] [client 91.148.244.131:37902] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/wp-config.php"] [unique_id "amulbjbFEG16qLV_6ZeAkwAAABc"]
[Thu Jul 30 14:26:38.362956 2026] [security2:error] [pid 1045527:tid 1045756] [client 81.171.74.60:43112] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.ssh/id_rsa"] [unique_id "amulbjbFEG16qLV_6ZeAlAAAAGM"]
[Thu Jul 30 14:26:38.363675 2026] [security2:error] [pid 1045527:tid 1045733] [client 91.148.245.81:42316] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/_vti_pvt/service.pwd"] [unique_id "amulbjbFEG16qLV_6ZeAlQAAAEw"]
[Thu Jul 30 14:26:38.365573 2026] [security2:error] [pid 1045527:tid 1045670] [client 91.148.245.81:42306] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/backup.sql"] [unique_id "amulbjbFEG16qLV_6ZeAlgAAAA0"]
[Thu Jul 30 14:26:38.366465 2026] [security2:error] [pid 1045527:tid 1045712] [client 91.148.245.81:42298] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.ssh/id_rsa"] [unique_id "amulbjbFEG16qLV_6ZeAlwAAADc"]
[Thu Jul 30 14:26:38.374155 2026] [security2:error] [pid 1045527:tid 1045781] [client 81.171.74.60:43102] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.ssh/id_ecdsa"] [unique_id "amulbjbFEG16qLV_6ZeAmAAAAHw"]
[Thu Jul 30 14:26:38.381083 2026] [security2:error] [pid 1045527:tid 1045686] [client 81.171.74.60:43126] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/_vti_pvt/service.pwd"] [unique_id "amulbjbFEG16qLV_6ZeAmQAAAB0"]
[Thu Jul 30 14:26:38.434223 2026] [core:notice] [pid 1045527:tid 1045556] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:38.472789 2026] [security2:error] [pid 1045527:tid 1045751] [client 91.148.244.131:37924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/config.php"] [unique_id "amulbjbFEG16qLV_6ZeAmwAAAF4"]
[Thu Jul 30 14:26:38.490342 2026] [security2:error] [pid 1045527:tid 1045707] [client 91.148.244.131:37904] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/server.key"] [unique_id "amulbjbFEG16qLV_6ZeAnAAAADI"]
[Thu Jul 30 14:26:38.505093 2026] [security2:error] [pid 1045527:tid 1045750] [client 91.148.245.81:42154] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/config.php"] [unique_id "amulbjbFEG16qLV_6ZeAnQAAAF0"]
[Thu Jul 30 14:26:38.506163 2026] [security2:error] [pid 1045527:tid 1045744] [client 91.148.245.81:42292] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/config.php"] [unique_id "amulbjbFEG16qLV_6ZeAngAAAFc"]
[Thu Jul 30 14:26:38.508600 2026] [security2:error] [pid 1045527:tid 1045664] [client 91.148.245.81:42276] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/dump.sql"] [unique_id "amulbjbFEG16qLV_6ZeAnwAAAAc"]
[Thu Jul 30 14:26:38.514859 2026] [security2:error] [pid 1045527:tid 1045682] [client 91.148.245.81:42328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/database.sql"] [unique_id "amulbjbFEG16qLV_6ZeAoQAAABk"]
[Thu Jul 30 14:26:38.515939 2026] [security2:error] [pid 1045527:tid 1045718] [client 81.171.74.60:43138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/wp-admin/setup-config.php"] [unique_id "amulbjbFEG16qLV_6ZeAogAAAD0"]
[Thu Jul 30 14:26:38.522032 2026] [security2:error] [pid 1045527:tid 1045673] [client 81.171.74.60:43146] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.git/HEAD"] [unique_id "amulbjbFEG16qLV_6ZeAowAAABA"]
[Thu Jul 30 14:26:38.530298 2026] [security2:error] [pid 1045527:tid 1045661] [client 81.171.72.135:59484] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/config/production.json"] [unique_id "amulbjbFEG16qLV_6ZeApAAAAAQ"]
[Thu Jul 30 14:26:38.537836 2026] [security2:error] [pid 1045527:tid 1045689] [client 81.171.72.135:59490] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.vscode/sftp.json"] [unique_id "amulbjbFEG16qLV_6ZeApQAAACA"]
[Thu Jul 30 14:26:38.539380 2026] [security2:error] [pid 1045527:tid 1045699] [client 81.171.72.135:59496] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/server.key"] [unique_id "amulbjbFEG16qLV_6ZeApwAAACo"]
[Thu Jul 30 14:26:38.539408 2026] [security2:error] [pid 1045527:tid 1045704] [client 81.171.72.135:59508] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/docker-compose.yml"] [unique_id "amulbjbFEG16qLV_6ZeAqAAAAC8"]
[Thu Jul 30 14:26:38.587429 2026] [security2:error] [pid 1045527:tid 1045708] [client 177.6.106.101:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulbjbFEG16qLV_6ZeAqQAAADM"]
[Thu Jul 30 14:26:38.587625 2026] [security2:error] [pid 1045527:tid 1045708] [client 177.6.106.101:54380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulbjbFEG16qLV_6ZeAqQAAADM"]
[Thu Jul 30 14:26:38.673074 2026] [security2:error] [pid 1045527:tid 1045746] [client 81.171.72.135:59506] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/phpinfo.php"] [unique_id "amulbjbFEG16qLV_6ZeAsAAAAFk"]
[Thu Jul 30 14:26:38.674017 2026] [security2:error] [pid 1045527:tid 1045683] [client 81.171.72.135:59470] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/user_secrets.yml"] [unique_id "amulbjbFEG16qLV_6ZeAsQAAABo"]
[Thu Jul 30 14:26:38.676630 2026] [security2:error] [pid 1045527:tid 1045702] [client 81.171.72.135:59512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.npmrc"] [unique_id "amulbjbFEG16qLV_6ZeAsgAAAC0"]
[Thu Jul 30 14:26:38.884959 2026] [security2:error] [pid 1045527:tid 1045671] [client 91.148.244.131:37942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/phpinfo.php"] [unique_id "amulbjbFEG16qLV_6ZeAuwAAAA4"]
[Thu Jul 30 14:26:38.890840 2026] [security2:error] [pid 1045527:tid 1045772] [client 91.148.244.131:37946] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/user_secrets.yml"] [unique_id "amulbjbFEG16qLV_6ZeAvAAAAHM"]
[Thu Jul 30 14:26:38.904182 2026] [security2:error] [pid 1045527:tid 1045743] [client 91.148.244.131:37938] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.env.production"] [unique_id "amulbjbFEG16qLV_6ZeAvQAAAFY"]
[Thu Jul 30 14:26:38.920026 2026] [core:notice] [pid 1045527:tid 1045571] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:38.923519 2026] [security2:error] [pid 1045527:tid 1045724] [client 81.171.74.60:43162] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/phpinfo.php"] [unique_id "amulbjbFEG16qLV_6ZeAwAAAAEM"]
[Thu Jul 30 14:26:38.928662 2026] [security2:error] [pid 1045527:tid 1045669] [client 81.171.74.60:43200] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.env"] [unique_id "amulbjbFEG16qLV_6ZeAwQAAAAw"]
[Thu Jul 30 14:26:38.931828 2026] [security2:error] [pid 1045527:tid 1045752] [client 81.171.74.60:43188] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/api/.env"] [unique_id "amulbjbFEG16qLV_6ZeAwgAAAF8"]
[Thu Jul 30 14:26:38.945504 2026] [security2:error] [pid 1045527:tid 1045729] [client 81.171.74.60:43174] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/backup.tar.gz"] [unique_id "amulbjbFEG16qLV_6ZeAwwAAAEg"]
[Thu Jul 30 14:26:38.953607 2026] [core:notice] [pid 1045527:tid 1045609] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:38.999987 2026] [security2:error] [pid 1045527:tid 1045658] [client 91.148.244.131:37962] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/docker-compose.yml"] [unique_id "amulbjbFEG16qLV_6ZeAxQAAAAE"]
[Thu Jul 30 14:26:39.025233 2026] [security2:error] [pid 1045527:tid 1045717] [client 91.148.244.131:37956] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.ssh/id_rsa"] [unique_id "amulbzbFEG16qLV_6ZeAxgAAADw"]
[Thu Jul 30 14:26:39.032908 2026] [security2:error] [pid 1045527:tid 1045731] [client 91.148.244.131:37964] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/etc/ssl/private/server.key"] [unique_id "amulbzbFEG16qLV_6ZeAxwAAAEo"]
[Thu Jul 30 14:26:39.038839 2026] [core:notice] [pid 1045527:tid 1045610] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:39.044343 2026] [security2:error] [pid 1045527:tid 1045695] [client 91.148.244.131:37948] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/config/production.json"] [unique_id "amulbzbFEG16qLV_6ZeAyQAAACY"]
[Thu Jul 30 14:26:39.054630 2026] [security2:error] [pid 1045527:tid 1045666] [client 81.171.74.60:43208] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/user_secrets.yml"] [unique_id "amulbzbFEG16qLV_6ZeAygAAAAk"]
[Thu Jul 30 14:26:39.121672 2026] [core:notice] [pid 1045527:tid 1045601] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:39.174391 2026] [security2:error] [pid 1045527:tid 1045728] [client 81.171.72.135:59530] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/config.xml"] [unique_id "amulbzbFEG16qLV_6ZeA0AAAAEc"]
[Thu Jul 30 14:26:39.179918 2026] [security2:error] [pid 1045527:tid 1045725] [client 81.171.72.135:59546] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/secrets.json"] [unique_id "amulbzbFEG16qLV_6ZeA0QAAAEQ"]
[Thu Jul 30 14:26:39.181097 2026] [security2:error] [pid 1045527:tid 1045672] [client 81.171.72.135:59582] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/wp-config.php"] [unique_id "amulbzbFEG16qLV_6ZeA0gAAAA8"]
[Thu Jul 30 14:26:39.181283 2026] [security2:error] [pid 1045527:tid 1045773] [client 81.171.72.135:59564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/config.php"] [unique_id "amulbzbFEG16qLV_6ZeA0wAAAHQ"]
[Thu Jul 30 14:26:39.256139 2026] [core:notice] [pid 1045527:tid 1045581] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:39.300378 2026] [core:notice] [pid 1045527:tid 1045613] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:39.306124 2026] [security2:error] [pid 1045527:tid 1045675] [client 81.171.72.135:59528] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.bash_history"] [unique_id "amulbzbFEG16qLV_6ZeA3AAAABI"]
[Thu Jul 30 14:26:39.313867 2026] [security2:error] [pid 1045527:tid 1045769] [client 81.171.72.135:59578] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/dump.sql"] [unique_id "amulbzbFEG16qLV_6ZeA3QAAAHA"]
[Thu Jul 30 14:26:39.322506 2026] [security2:error] [pid 1045527:tid 1045760] [client 81.171.72.135:59558] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/backup.sql"] [unique_id "amulbzbFEG16qLV_6ZeA3wAAAGc"]
[Thu Jul 30 14:26:39.456373 2026] [security2:error] [pid 1045527:tid 1045726] [client 81.171.74.60:43264] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/etc/ssl/private/server.key"] [unique_id "amulbzbFEG16qLV_6ZeA5AAAAEU"]
[Thu Jul 30 14:26:39.456438 2026] [security2:error] [pid 1045527:tid 1045762] [client 81.171.74.60:43276] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/server.key"] [unique_id "amulbzbFEG16qLV_6ZeA5QAAAGk"]
[Thu Jul 30 14:26:39.467683 2026] [security2:error] [pid 1045527:tid 1045768] [client 81.171.74.60:43242] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/config/production.json"] [unique_id "amulbzbFEG16qLV_6ZeA5gAAAG8"]
[Thu Jul 30 14:26:39.482463 2026] [security2:error] [pid 1045527:tid 1045693] [client 172.202.44.182:36703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/file5.php"] [unique_id "amulbzbFEG16qLV_6ZeA6AAAACQ"]
[Thu Jul 30 14:26:39.487004 2026] [security2:error] [pid 1045527:tid 1045757] [client 81.171.74.60:43254] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.env.production"] [unique_id "amulbzbFEG16qLV_6ZeA6QAAAGQ"]
[Thu Jul 30 14:26:39.518049 2026] [security2:error] [pid 1045527:tid 1045735] [client 91.148.244.131:38018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/wp-admin/setup-config.php"] [unique_id "amulbzbFEG16qLV_6ZeA6gAAAE4"]
[Thu Jul 30 14:26:39.520707 2026] [security2:error] [pid 1045527:tid 1045659] [client 91.148.244.131:38020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.git/HEAD"] [unique_id "amulbzbFEG16qLV_6ZeA6wAAAAI"]
[Thu Jul 30 14:26:39.522363 2026] [security2:error] [pid 1045527:tid 1045727] [client 91.148.244.131:37976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/_vti_pvt/service.pwd"] [unique_id "amulbzbFEG16qLV_6ZeA7AAAAEY"]
[Thu Jul 30 14:26:39.525711 2026] [security2:error] [pid 1045527:tid 1045715] [client 91.148.244.131:37980] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.env"] [unique_id "amulbzbFEG16qLV_6ZeA7QAAADo"]
[Thu Jul 30 14:26:39.598130 2026] [security2:error] [pid 1045527:tid 1045746] [client 81.171.74.60:43296] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/secrets.json"] [unique_id "amulbzbFEG16qLV_6ZeA7wAAAFk"]
[Thu Jul 30 14:26:39.605113 2026] [security2:error] [pid 1045527:tid 1045683] [client 81.171.74.60:43312] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.vscode/sftp.json"] [unique_id "amulbzbFEG16qLV_6ZeA8AAAABo"]
[Thu Jul 30 14:26:39.606186 2026] [security2:error] [pid 1045527:tid 1045782] [client 81.171.74.60:43284] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.npmrc"] [unique_id "amulbzbFEG16qLV_6ZeA8QAAAH0"]
[Thu Jul 30 14:26:39.625196 2026] [security2:error] [pid 1045527:tid 1045722] [client 81.171.72.135:59596] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/backup.tar.gz"] [unique_id "amulbzbFEG16qLV_6ZeA8wAAAEE"]
[Thu Jul 30 14:26:39.656686 2026] [security2:error] [pid 1045527:tid 1045696] [client 91.148.244.131:38002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.vscode/sftp.json"] [unique_id "amulbzbFEG16qLV_6ZeA9gAAACc"]
[Thu Jul 30 14:26:39.657818 2026] [security2:error] [pid 1045527:tid 1045732] [client 91.148.244.131:37978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.npmrc"] [unique_id "amulbzbFEG16qLV_6ZeA9wAAAEs"]
[Thu Jul 30 14:26:39.695824 2026] [core:notice] [pid 1045527:tid 1045587] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:39.939838 2026] [security2:error] [pid 1045527:tid 1045778] [client 91.148.244.131:38038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/secrets.json"] [unique_id "amulbzbFEG16qLV_6ZeBBgAAAHk"]
[Thu Jul 30 14:26:39.939838 2026] [security2:error] [pid 1045527:tid 1045719] [client 91.148.244.131:38034] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net"] [uri "/.bash_history"] [unique_id "amulbzbFEG16qLV_6ZeBBQAAAD4"]
[Thu Jul 30 14:26:39.949193 2026] [security2:error] [pid 1045527:tid 1045682] [client 81.171.72.135:59642] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/database_backup.sql"] [unique_id "amulbzbFEG16qLV_6ZeBBwAAABk"]
[Thu Jul 30 14:26:39.952667 2026] [security2:error] [pid 1045527:tid 1045718] [client 81.171.72.135:59620] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/actuator/heapdump"] [unique_id "amulbzbFEG16qLV_6ZeBCAAAAD0"]
[Thu Jul 30 14:26:39.971640 2026] [security2:error] [pid 1045527:tid 1045709] [client 81.171.72.135:59606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/database.sql"] [unique_id "amulbzbFEG16qLV_6ZeBCQAAADQ"]
[Thu Jul 30 14:26:40.018290 2026] [security2:error] [pid 1045527:tid 1045704] [client 81.171.74.60:43362] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/backup.sql"] [unique_id "amulcDbFEG16qLV_6ZeBCwAAAC8"]
[Thu Jul 30 14:26:40.022543 2026] [security2:error] [pid 1045527:tid 1045754] [client 81.171.74.60:43356] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/dump.sql"] [unique_id "amulcDbFEG16qLV_6ZeBDAAAAGE"]
[Thu Jul 30 14:26:40.026659 2026] [security2:error] [pid 1045527:tid 1045708] [client 81.171.74.60:43332] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/config.xml"] [unique_id "amulcDbFEG16qLV_6ZeBDQAAADM"]
[Thu Jul 30 14:26:40.043353 2026] [security2:error] [pid 1045527:tid 1045720] [client 81.171.74.60:43330] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/.bash_history"] [unique_id "amulcDbFEG16qLV_6ZeBDgAAAD8"]
[Thu Jul 30 14:26:40.087331 2026] [security2:error] [pid 1045527:tid 1045673] [client 81.171.72.135:59654] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/backup.zip"] [unique_id "amulcDbFEG16qLV_6ZeBEAAAABA"]
[Thu Jul 30 14:26:40.089251 2026] [security2:error] [pid 1045527:tid 1045740] [client 81.171.72.135:59668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.svn/wc.db"] [unique_id "amulcDbFEG16qLV_6ZeBEQAAAFM"]
[Thu Jul 30 14:26:40.163873 2026] [security2:error] [pid 1045527:tid 1045770] [client 81.171.74.60:43328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/database.sql"] [unique_id "amulcDbFEG16qLV_6ZeBEwAAAHE"]
[Thu Jul 30 14:26:40.166645 2026] [security2:error] [pid 1045527:tid 1045678] [client 81.171.74.60:43354] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.greensparkle.net"] [uri "/database_backup.sql"] [unique_id "amulcDbFEG16qLV_6ZeBFAAAABU"]
[Thu Jul 30 14:26:40.188326 2026] [security2:error] [pid 1045527:tid 1045762] [client 158.158.105.63:58749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amulcDbFEG16qLV_6ZeBGAAAAGk"]
[Thu Jul 30 14:26:40.188428 2026] [security2:error] [pid 1045527:tid 1045762] [client 158.158.105.63:58749] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amulcDbFEG16qLV_6ZeBGAAAAGk"]
[Thu Jul 30 14:26:40.249240 2026] [security2:error] [pid 1045527:tid 1045757] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/settings.swp"] [unique_id "amulcDbFEG16qLV_6ZeBGQAAAGQ"]
[Thu Jul 30 14:26:40.474137 2026] [core:notice] [pid 1045527:tid 1045594] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:40.544571 2026] [security2:error] [pid 1045527:tid 1045658] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "amulcDbFEG16qLV_6ZeBJgAAAAE"]
[Thu Jul 30 14:26:40.593303 2026] [security2:error] [pid 1045527:tid 1045756] [client 172.202.44.182:51742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/aaa.php"] [unique_id "amulcDbFEG16qLV_6ZeBJwAAAGM"]
[Thu Jul 30 14:26:40.600937 2026] [security2:error] [pid 1045527:tid 1045780] [client 81.171.72.135:59704] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.ssh/id_ed25519"] [unique_id "amulcDbFEG16qLV_6ZeBKAAAAHs"]
[Thu Jul 30 14:26:40.601363 2026] [security2:error] [pid 1045527:tid 1045696] [client 81.171.72.135:59682] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.ssh/id_rsa"] [unique_id "amulcDbFEG16qLV_6ZeBKQAAACc"]
[Thu Jul 30 14:26:40.610462 2026] [security2:error] [pid 1045527:tid 1045702] [client 81.171.72.135:59676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "greensparkle.net.lom.gzj.temporary.site"] [uri "/.ssh/id_ecdsa"] [unique_id "amulcDbFEG16qLV_6ZeBKgAAAC0"]
[Thu Jul 30 14:26:40.620571 2026] [security2:error] [pid 1045527:tid 1045742] [client 172.202.44.182:44523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amulcDbFEG16qLV_6ZeBKwAAAFU"]
[Thu Jul 30 14:26:40.751389 2026] [core:notice] [pid 1045527:tid 1045568] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:41.165077 2026] [security2:error] [pid 1045527:tid 1045699] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.EnV"] [unique_id "amulcTbFEG16qLV_6ZeBOwAAACo"]
[Thu Jul 30 14:26:41.290828 2026] [rewrite:error] [pid 1045527:tid 1045778] [client 185.177.72.10:0] AH10508: Unsafe URL with %3f URL rewritten without UnsafeAllow3F
[Thu Jul 30 14:26:41.593298 2026] [core:notice] [pid 1045527:tid 1045625] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:26:41.616859 2026] [security2:error] [pid 1045527:tid 1045721] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.EnV^"] [unique_id "amulcTbFEG16qLV_6ZeBTwAAAEA"]
[Thu Jul 30 14:26:41.913924 2026] [security2:error] [pid 1045527:tid 1045728] [client 172.202.44.182:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/getid3-core.php"] [unique_id "amulcTbFEG16qLV_6ZeBWwAAAEc"]
[Thu Jul 30 14:26:42.052243 2026] [security2:error] [pid 1045527:tid 1045673] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amulcTbFEG16qLV_6ZeBTQAAABA"]
[Thu Jul 30 14:26:42.067013 2026] [security2:error] [pid 1045527:tid 1045667] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/authui.htaccess"] [unique_id "amulcjbFEG16qLV_6ZeBYAAAAAo"]
[Thu Jul 30 14:26:42.353774 2026] [security2:error] [pid 1045527:tid 1045693] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/test2.php"] [unique_id "amulcjbFEG16qLV_6ZeBZgAAACQ"]
[Thu Jul 30 14:26:42.562179 2026] [security2:error] [pid 1045527:tid 1045659] [client 172.237.109.114:15766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulcTbFEG16qLV_6ZeBXAAAAAI"], referer: http://alseermarine.com:80/index.html
[Thu Jul 30 14:26:42.595172 2026] [security2:error] [pid 1045527:tid 1045703] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/test2.php%2e%2e%2f%2e%2e%2f"] [unique_id "amulcjbFEG16qLV_6ZeBbgAAAC4"]
[Thu Jul 30 14:26:42.837350 2026] [security2:error] [pid 1045527:tid 1045683] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/test2.php.well-known"] [unique_id "amulcjbFEG16qLV_6ZeBcgAAABo"]
[Thu Jul 30 14:26:42.913503 2026] [security2:error] [pid 1045527:tid 1045746] [client 172.202.44.182:44526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/shell.php"] [unique_id "amulcjbFEG16qLV_6ZeBdgAAAFk"]
[Thu Jul 30 14:26:42.923562 2026] [security2:error] [pid 1045527:tid 1045781] [client 172.202.44.182:51690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/adminer.php"] [unique_id "amulcjbFEG16qLV_6ZeBdwAAAHw"]
[Thu Jul 30 14:26:43.081864 2026] [security2:error] [pid 1045527:tid 1045675] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/test2.php//"] [unique_id "amulczbFEG16qLV_6ZeBewAAABI"]
[Thu Jul 30 14:26:43.125716 2026] [security2:error] [pid 1045527:tid 1045657] [client 91.148.245.81:51264] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.env.production"] [unique_id "amulczbFEG16qLV_6ZeBfAAAAAA"]
[Thu Jul 30 14:26:43.126301 2026] [security2:error] [pid 1045527:tid 1045689] [client 91.148.245.81:51238] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/config.xml"] [unique_id "amulczbFEG16qLV_6ZeBfQAAACA"]
[Thu Jul 30 14:26:43.127303 2026] [security2:error] [pid 1045527:tid 1045694] [client 91.148.245.81:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/config/production.json"] [unique_id "amulczbFEG16qLV_6ZeBfgAAACU"]
[Thu Jul 30 14:26:43.132189 2026] [security2:error] [pid 1045527:tid 1045734] [client 91.148.245.81:51254] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/etc/ssl/private/server.key"] [unique_id "amulczbFEG16qLV_6ZeBfwAAAE0"]
[Thu Jul 30 14:26:43.270285 2026] [security2:error] [pid 1045527:tid 1045719] [client 91.148.245.81:51288] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/backup.tar.gz"] [unique_id "amulczbFEG16qLV_6ZeBgAAAAD4"]
[Thu Jul 30 14:26:43.325766 2026] [security2:error] [pid 1045527:tid 1045680] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/config.php.bak"] [unique_id "amulczbFEG16qLV_6ZeBgQAAABc"]
[Thu Jul 30 14:26:43.343422 2026] [security2:error] [pid 1045527:tid 1045718] [client 91.148.245.81:51352] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/api/.env"] [unique_id "amulczbFEG16qLV_6ZeBhAAAAD0"]
[Thu Jul 30 14:26:43.346574 2026] [security2:error] [pid 1045527:tid 1045709] [client 91.148.245.81:51304] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/phpinfo.php"] [unique_id "amulczbFEG16qLV_6ZeBhgAAADQ"]
[Thu Jul 30 14:26:43.347351 2026] [security2:error] [pid 1045527:tid 1045682] [client 91.148.245.81:51332] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/etc/ssl/private/server.key"] [unique_id "amulczbFEG16qLV_6ZeBhwAAABk"]
[Thu Jul 30 14:26:43.349723 2026] [security2:error] [pid 1045527:tid 1045753] [client 91.148.245.81:51336] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/docker-compose.yml"] [unique_id "amulczbFEG16qLV_6ZeBiAAAAGA"]
[Thu Jul 30 14:26:43.391722 2026] [security2:error] [pid 1045527:tid 1045713] [client 180.243.59.178:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulczbFEG16qLV_6ZeBigAAADg"]
[Thu Jul 30 14:26:43.391840 2026] [security2:error] [pid 1045527:tid 1045713] [client 180.243.59.178:60290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulczbFEG16qLV_6ZeBigAAADg"]
[Thu Jul 30 14:26:43.486993 2026] [security2:error] [pid 1045527:tid 1045747] [client 91.148.245.81:51318] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/user_secrets.yml"] [unique_id "amulczbFEG16qLV_6ZeBkAAAAFo"]
[Thu Jul 30 14:26:43.565067 2026] [security2:error] [pid 1045527:tid 1045777] [client 158.158.105.63:44923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amulczbFEG16qLV_6ZeBkgAAAHg"]
[Thu Jul 30 14:26:43.565168 2026] [security2:error] [pid 1045527:tid 1045777] [client 158.158.105.63:44923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amulczbFEG16qLV_6ZeBkgAAAHg"]
[Thu Jul 30 14:26:43.569155 2026] [security2:error] [pid 1045527:tid 1045700] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/config.php.bak%257d"] [unique_id "amulczbFEG16qLV_6ZeBkwAAACs"]
[Thu Jul 30 14:26:43.813102 2026] [security2:error] [pid 1045527:tid 1045751] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/ConFig.Php.bak"] [unique_id "amulczbFEG16qLV_6ZeBlAAAAF4"]
[Thu Jul 30 14:26:43.870419 2026] [security2:error] [pid 1045527:tid 1045668] [client 91.148.245.81:51372] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.env.production"] [unique_id "amulczbFEG16qLV_6ZeBlQAAAAs"]
[Thu Jul 30 14:26:43.901560 2026] [security2:error] [pid 1045527:tid 1045742] [client 91.148.245.81:51430] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.ssh/id_rsa"] [unique_id "amulczbFEG16qLV_6ZeBmQAAAFU"]
[Thu Jul 30 14:26:43.909962 2026] [security2:error] [pid 1045527:tid 1045702] [client 91.148.245.81:51476] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/server.key"] [unique_id "amulczbFEG16qLV_6ZeBmgAAAC0"]
[Thu Jul 30 14:26:43.912046 2026] [security2:error] [pid 1045527:tid 1045685] [client 74.248.33.8:36750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amulczbFEG16qLV_6ZeBmwAAABw"]
[Thu Jul 30 14:26:43.915562 2026] [security2:error] [pid 1045527:tid 1045772] [client 91.148.245.81:51398] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/config/production.json"] [unique_id "amulczbFEG16qLV_6ZeBnAAAAHM"]
[Thu Jul 30 14:26:43.916915 2026] [security2:error] [pid 1045527:tid 1045780] [client 91.148.245.81:51376] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.vscode/sftp.json"] [unique_id "amulczbFEG16qLV_6ZeBnQAAAHs"]
[Thu Jul 30 14:26:43.926405 2026] [security2:error] [pid 1045527:tid 1045717] [client 91.148.245.81:51464] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.svn/wc.db"] [unique_id "amulczbFEG16qLV_6ZeBngAAADw"]
[Thu Jul 30 14:26:43.936795 2026] [security2:error] [pid 1045527:tid 1045731] [client 91.148.245.81:51432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.ssh/id_ed25519"] [unique_id "amulczbFEG16qLV_6ZeBnwAAAEo"]
[Thu Jul 30 14:26:43.938605 2026] [security2:error] [pid 1045527:tid 1045707] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/config.php.bak%0d"] [unique_id "amulczbFEG16qLV_6ZeBoAAAADI"]
[Thu Jul 30 14:26:44.005363 2026] [security2:error] [pid 1045527:tid 1045712] [client 91.148.245.81:51480] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/server.key"] [unique_id "amuldDbFEG16qLV_6ZeBpwAAADc"]
[Thu Jul 30 14:26:44.023696 2026] [security2:error] [pid 1045527:tid 1045659] [client 91.148.245.81:51488] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/secrets.json"] [unique_id "amuldDbFEG16qLV_6ZeBqAAAAAI"]
[Thu Jul 30 14:26:44.043167 2026] [security2:error] [pid 1045527:tid 1045666] [client 91.148.245.81:51526] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.env.production"] [unique_id "amuldDbFEG16qLV_6ZeBqQAAAAk"]
[Thu Jul 30 14:26:44.056899 2026] [security2:error] [pid 1045527:tid 1045737] [client 91.148.245.81:51512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.ssh/id_ecdsa"] [unique_id "amuldDbFEG16qLV_6ZeBqgAAAFA"]
[Thu Jul 30 14:26:44.057445 2026] [security2:error] [pid 1045527:tid 1045697] [client 91.148.245.81:51520] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/wp-config.php"] [unique_id "amuldDbFEG16qLV_6ZeBqwAAACg"]
[Thu Jul 30 14:26:44.059018 2026] [security2:error] [pid 1045527:tid 1045703] [client 91.148.245.81:51540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/database_backup.sql"] [unique_id "amuldDbFEG16qLV_6ZeBrAAAAC4"]
[Thu Jul 30 14:26:44.191562 2026] [security2:error] [pid 1045527:tid 1045677] [client 91.148.245.81:51510] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/phpinfo.php"] [unique_id "amuldDbFEG16qLV_6ZeBrgAAABQ"]
[Thu Jul 30 14:26:44.400231 2026] [security2:error] [pid 1045527:tid 1045706] [client 91.148.245.81:51582] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.ssh/id_ed25519"] [unique_id "amuldDbFEG16qLV_6ZeBswAAADE"]
[Thu Jul 30 14:26:44.419416 2026] [security2:error] [pid 1045527:tid 1045770] [client 91.148.245.81:51546] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.bash_history"] [unique_id "amuldDbFEG16qLV_6ZeBtgAAAHE"]
[Thu Jul 30 14:26:44.424384 2026] [security2:error] [pid 1045527:tid 1045716] [client 91.148.245.81:51574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.npmrc"] [unique_id "amuldDbFEG16qLV_6ZeBuAAAADs"]
[Thu Jul 30 14:26:44.534954 2026] [security2:error] [pid 1045527:tid 1045722] [client 172.202.44.182:51739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/alfa.php"] [unique_id "amuldDbFEG16qLV_6ZeBvQAAAEE"]
[Thu Jul 30 14:26:44.542000 2026] [security2:error] [pid 1045527:tid 1045687] [client 91.148.245.81:51586] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/database_backup.sql"] [unique_id "amuldDbFEG16qLV_6ZeBvgAAAB4"]
[Thu Jul 30 14:26:44.543144 2026] [security2:error] [pid 1045527:tid 1045768] [client 91.148.245.81:51606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.vscode/sftp.json"] [unique_id "amuldDbFEG16qLV_6ZeBvwAAAG8"]
[Thu Jul 30 14:26:44.546311 2026] [security2:error] [pid 1045527:tid 1045710] [client 91.148.245.81:51608] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/secrets.json"] [unique_id "amuldDbFEG16qLV_6ZeBwAAAADU"]
[Thu Jul 30 14:26:44.554943 2026] [security2:error] [pid 1045527:tid 1045761] [client 91.148.245.81:51610] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.npmrc"] [unique_id "amuldDbFEG16qLV_6ZeBwQAAAGg"]
[Thu Jul 30 14:26:44.564218 2026] [security2:error] [pid 1045527:tid 1045698] [client 91.148.245.81:51600] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/backup.zip"] [unique_id "amuldDbFEG16qLV_6ZeBwgAAACk"]
[Thu Jul 30 14:26:44.588618 2026] [security2:error] [pid 1045527:tid 1045667] [client 91.148.245.81:51718] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/user_secrets.yml"] [unique_id "amuldDbFEG16qLV_6ZeBwwAAAAo"]
[Thu Jul 30 14:26:44.595144 2026] [security2:error] [pid 1045527:tid 1045735] [client 91.148.245.81:51690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.git/HEAD"] [unique_id "amuldDbFEG16qLV_6ZeBxgAAAE4"]
[Thu Jul 30 14:26:44.595293 2026] [security2:error] [pid 1045527:tid 1045673] [client 91.148.245.81:51714] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/docker-compose.yml"] [unique_id "amuldDbFEG16qLV_6ZeBxQAAABA"]
[Thu Jul 30 14:26:44.603149 2026] [security2:error] [pid 1045527:tid 1045730] [client 91.148.245.81:51678] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/api/.env"] [unique_id "amuldDbFEG16qLV_6ZeByAAAAEk"]
[Thu Jul 30 14:26:44.687238 2026] [security2:error] [pid 1045527:tid 1045747] [client 91.148.245.81:51646] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/dump.sql"] [unique_id "amuldDbFEG16qLV_6ZeBzgAAAFo"]
[Thu Jul 30 14:26:44.687256 2026] [security2:error] [pid 1045527:tid 1045711] [client 91.148.245.81:51662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/database.sql"] [unique_id "amuldDbFEG16qLV_6ZeBzwAAADY"]
[Thu Jul 30 14:26:44.695957 2026] [security2:error] [pid 1045527:tid 1045727] [client 91.148.245.81:51644] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.ssh/id_ecdsa"] [unique_id "amuldDbFEG16qLV_6ZeB0AAAAEY"]
[Thu Jul 30 14:26:44.728499 2026] [security2:error] [pid 1045527:tid 1045745] [client 91.148.245.81:51704] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.vscode/sftp.json"] [unique_id "amuldDbFEG16qLV_6ZeB0QAAAFg"]
[Thu Jul 30 14:26:44.830397 2026] [security2:error] [pid 1045527:tid 1045657] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/app_dev.php"] [unique_id "amuldDbFEG16qLV_6ZeB0gAAAAA"]
[Thu Jul 30 14:26:44.939706 2026] [security2:error] [pid 1045527:tid 1045699] [client 91.148.245.81:51750] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/wp-config.php"] [unique_id "amuldDbFEG16qLV_6ZeB2AAAACo"]
[Thu Jul 30 14:26:44.952731 2026] [security2:error] [pid 1045527:tid 1045746] [client 91.148.245.81:51780] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.svn/wc.db"] [unique_id "amuldDbFEG16qLV_6ZeB2QAAAFk"]
[Thu Jul 30 14:26:45.071285 2026] [security2:error] [pid 1045527:tid 1045682] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/app_dev.php%2520"] [unique_id "amuldTbFEG16qLV_6ZeB3QAAABk"]
[Thu Jul 30 14:26:45.095608 2026] [security2:error] [pid 1045527:tid 1045764] [client 91.148.245.81:51822] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/backup.tar.gz"] [unique_id "amuldTbFEG16qLV_6ZeB4QAAAGs"]
[Thu Jul 30 14:26:45.097773 2026] [security2:error] [pid 1045527:tid 1045684] [client 172.202.44.182:36727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/f35.php"] [unique_id "amuldTbFEG16qLV_6ZeB4gAAABs"]
[Thu Jul 30 14:26:45.103816 2026] [security2:error] [pid 1045527:tid 1045674] [client 91.148.245.81:51812] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/actuator/heapdump"] [unique_id "amuldTbFEG16qLV_6ZeB4wAAABE"]
[Thu Jul 30 14:26:45.119357 2026] [security2:error] [pid 1045527:tid 1045720] [client 91.148.245.81:51852] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/etc/ssl/private/server.key"] [unique_id "amuldTbFEG16qLV_6ZeB5QAAAD8"]
[Thu Jul 30 14:26:45.121008 2026] [security2:error] [pid 1045527:tid 1045783] [client 91.148.245.81:51846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/server.key"] [unique_id "amuldTbFEG16qLV_6ZeB5gAAAH4"]
[Thu Jul 30 14:26:45.243877 2026] [security2:error] [pid 1045527:tid 1045665] [client 91.148.245.81:51880] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.bash_history"] [unique_id "amuldTbFEG16qLV_6ZeB6AAAAAg"]
[Thu Jul 30 14:26:45.255169 2026] [security2:error] [pid 1045527:tid 1045741] [client 91.148.245.81:51912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.env"] [unique_id "amuldTbFEG16qLV_6ZeB6gAAAFQ"]
[Thu Jul 30 14:26:45.256132 2026] [security2:error] [pid 1045527:tid 1045765] [client 91.148.245.81:51886] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/phpinfo.php"] [unique_id "amuldTbFEG16qLV_6ZeB6wAAAGw"]
[Thu Jul 30 14:26:45.259450 2026] [security2:error] [pid 1045527:tid 1045723] [client 91.148.245.81:51910] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/config/production.json"] [unique_id "amuldTbFEG16qLV_6ZeB7AAAAEI"]
[Thu Jul 30 14:26:45.311238 2026] [security2:error] [pid 1045527:tid 1045679] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/app_dev.php%253f"] [unique_id "amuldTbFEG16qLV_6ZeB7QAAABY"]
[Thu Jul 30 14:26:45.493886 2026] [security2:error] [pid 1045527:tid 1045768] [client 91.148.245.81:51920] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/backup.sql"] [unique_id "amuldTbFEG16qLV_6ZeB8wAAAG8"]
[Thu Jul 30 14:26:45.554019 2026] [security2:error] [pid 1045527:tid 1045776] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/app_dev.php%2524"] [unique_id "amuldTbFEG16qLV_6ZeB-QAAAHc"]
[Thu Jul 30 14:26:45.608122 2026] [security2:error] [pid 1045527:tid 1045688] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuldDbFEG16qLV_6ZeB0wAAH00"]
[Thu Jul 30 14:26:45.641081 2026] [security2:error] [pid 1045527:tid 1045714] [client 91.148.245.81:51968] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.bash_history"] [unique_id "amuldTbFEG16qLV_6ZeB-wAAADk"]
[Thu Jul 30 14:26:45.642025 2026] [security2:error] [pid 1045527:tid 1045717] [client 91.148.245.81:51954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/.npmrc"] [unique_id "amuldTbFEG16qLV_6ZeB_AAAADw"]
[Thu Jul 30 14:26:45.670905 2026] [security2:error] [pid 1045527:tid 1045767] [client 91.148.245.81:51976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.greensparkle.net"] [uri "/secrets.json"] [unique_id "amuldTbFEG16qLV_6ZeB_wAAAG4"]
[Thu Jul 30 14:26:45.778762 2026] [security2:error] [pid 1045527:tid 1045779] [client 158.158.105.63:54015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/err.php"] [unique_id "amuldTbFEG16qLV_6ZeCAAAAAHo"]
[Thu Jul 30 14:26:45.778873 2026] [security2:error] [pid 1045527:tid 1045779] [client 158.158.105.63:54015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/err.php"] [unique_id "amuldTbFEG16qLV_6ZeCAAAAAHo"]
[Thu Jul 30 14:26:45.921529 2026] [security2:error] [pid 1045527:tid 1045660] [client 91.148.245.81:52060] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/wp-admin/setup-config.php"] [unique_id "amuldTbFEG16qLV_6ZeCAwAAAAM"]
[Thu Jul 30 14:26:45.925396 2026] [security2:error] [pid 1045527:tid 1045666] [client 91.148.245.81:52046] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/api/.env"] [unique_id "amuldTbFEG16qLV_6ZeCBAAAAAk"]
[Thu Jul 30 14:26:46.013438 2026] [security2:error] [pid 1045527:tid 1045675] [client 74.248.33.8:20981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/index/function.php"] [unique_id "amuldjbFEG16qLV_6ZeCDAAAABI"]
[Thu Jul 30 14:26:46.092063 2026] [security2:error] [pid 1045527:tid 1045772] [client 91.148.245.81:52012] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/database_backup.sql"] [unique_id "amuldjbFEG16qLV_6ZeCDQAAAHM"]
[Thu Jul 30 14:26:46.096630 2026] [security2:error] [pid 1045527:tid 1045727] [client 91.148.245.81:51980] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/wp-config.php"] [unique_id "amuldjbFEG16qLV_6ZeCDgAAAEY"]
[Thu Jul 30 14:26:46.156582 2026] [security2:error] [pid 1045527:tid 1045725] [client 172.202.44.182:51683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuldjbFEG16qLV_6ZeCEwAAAEQ"]
[Thu Jul 30 14:26:46.283560 2026] [rewrite:error] [pid 1045527:tid 1045674] [client 185.177.72.10:0] AH10508: Unsafe URL with %3f URL rewritten without UnsafeAllow3F
[Thu Jul 30 14:26:46.309750 2026] [security2:error] [pid 1045527:tid 1045530] [remote 74.7.243.224:48300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amuldjbFEG16qLV_6ZeCFQAANAI"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:26:46.555773 2026] [security2:error] [pid 1045527:tid 1045720] [client 91.148.245.81:52072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/_vti_pvt/service.pwd"] [unique_id "amuldjbFEG16qLV_6ZeCGgAAAD8"]
[Thu Jul 30 14:26:46.556225 2026] [security2:error] [pid 1045527:tid 1045701] [client 91.148.245.81:52102] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/backup.zip"] [unique_id "amuldjbFEG16qLV_6ZeCGwAAACw"]
[Thu Jul 30 14:26:46.579101 2026] [security2:error] [pid 1045527:tid 1045716] [client 91.148.245.81:52068] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.git/HEAD"] [unique_id "amuldjbFEG16qLV_6ZeCHwAAADs"]
[Thu Jul 30 14:26:46.628062 2026] [security2:error] [pid 1045527:tid 1045726] [client 91.148.245.81:52104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/.env"] [unique_id "amuldjbFEG16qLV_6ZeCIgAAAEU"]
[Thu Jul 30 14:26:46.847687 2026] [security2:error] [pid 1045527:tid 1045742] [client 158.158.105.63:39813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/img.php"] [unique_id "amuldjbFEG16qLV_6ZeCJwAAAFU"]
[Thu Jul 30 14:26:46.847784 2026] [security2:error] [pid 1045527:tid 1045742] [client 158.158.105.63:39813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/img.php"] [unique_id "amuldjbFEG16qLV_6ZeCJwAAAFU"]
[Thu Jul 30 14:26:47.109401 2026] [security2:error] [pid 1045527:tid 1045667] [client 43.166.129.247:48280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.129.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adbacklink.com"] [uri "/theme/darm_theme_basic01/page_html/company_history.php"] [unique_id "amuldjbFEG16qLV_6ZeCKAAAAAo"]
[Thu Jul 30 14:26:47.128903 2026] [security2:error] [pid 1045527:tid 1045713] [client 172.202.44.182:51724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/new.php"] [unique_id "amuldzbFEG16qLV_6ZeCMgAAADg"]
[Thu Jul 30 14:26:47.382397 2026] [security2:error] [pid 1045527:tid 1045751] [client 91.148.245.81:52152] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.greensparkle.net"] [uri "/docker-compose.yml"] [unique_id "amuldzbFEG16qLV_6ZeCOAAAAF4"]
[Thu Jul 30 14:26:48.290527 2026] [security2:error] [pid 1045527:tid 1045740] [client 185.191.171.10:58308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/robots.txt"] [unique_id "amuleDbFEG16qLV_6ZeCUQAAAFM"]
[Thu Jul 30 14:26:48.290641 2026] [security2:error] [pid 1045527:tid 1045740] [client 185.191.171.10:58308] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/robots.txt"] [unique_id "amuleDbFEG16qLV_6ZeCUQAAAFM"]
[Thu Jul 30 14:26:48.426622 2026] [security2:error] [pid 1045527:tid 1045682] [client 158.158.105.63:46113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/aa.php"] [unique_id "amuleDbFEG16qLV_6ZeCVAAAABk"]
[Thu Jul 30 14:26:48.426738 2026] [security2:error] [pid 1045527:tid 1045682] [client 158.158.105.63:46113] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/aa.php"] [unique_id "amuleDbFEG16qLV_6ZeCVAAAABk"]
[Thu Jul 30 14:26:49.005485 2026] [security2:error] [pid 1045527:tid 1045761] [client 185.191.171.16:24722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/en/queens/1312-captain-kidd-eliquid-by-queens-flavors.html"] [unique_id "amuleTbFEG16qLV_6ZeCaAAAAGg"]
[Thu Jul 30 14:26:49.005584 2026] [security2:error] [pid 1045527:tid 1045761] [client 185.191.171.16:24722] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/en/queens/1312-captain-kidd-eliquid-by-queens-flavors.html"] [unique_id "amuleTbFEG16qLV_6ZeCaAAAAGg"]
[Thu Jul 30 14:26:49.064876 2026] [security2:error] [pid 1045527:tid 1045528] [remote 57.141.0.8:23766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amuleTbFEG16qLV_6ZeCagAAGAA"]
[Thu Jul 30 14:26:49.067711 2026] [security2:error] [pid 1045527:tid 1045671] [client 172.202.44.182:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/adminfuns.php"] [unique_id "amuleTbFEG16qLV_6ZeCawAAAA4"]
[Thu Jul 30 14:26:49.072375 2026] [security2:error] [pid 1045527:tid 1045684] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuleDbFEG16qLV_6ZeCVwAAABs"]
[Thu Jul 30 14:26:49.136011 2026] [security2:error] [pid 1045527:tid 1045725] [client 177.6.106.101:54794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuleTbFEG16qLV_6ZeCbgAAAEQ"]
[Thu Jul 30 14:26:49.136115 2026] [security2:error] [pid 1045527:tid 1045725] [client 177.6.106.101:54794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuleTbFEG16qLV_6ZeCbgAAAEQ"]
[Thu Jul 30 14:26:49.167670 2026] [core:error] [pid 1045527:tid 1045698] [client 74.7.228.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:49.167692 2026] [core:error] [pid 1045527:tid 1045698] [client 74.7.228.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:49.167815 2026] [security2:error] [pid 1045527:tid 1045698] [client 74.7.228.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.embassyofgermanypakistan.de"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuleTbFEG16qLV_6ZeCcgAAACk"]
[Thu Jul 30 14:26:49.168435 2026] [security2:error] [pid 1045527:tid 1045679] [client 74.7.228.50:43330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.embassyofgermanypakistan.de"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuleTbFEG16qLV_6ZeCcAAAFhg"]
[Thu Jul 30 14:26:49.442490 2026] [security2:error] [pid 1045527:tid 1045714] [client 158.158.105.63:35739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/av.php"] [unique_id "amuleTbFEG16qLV_6ZeCfAAAADk"]
[Thu Jul 30 14:26:49.442642 2026] [security2:error] [pid 1045527:tid 1045714] [client 158.158.105.63:35739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/av.php"] [unique_id "amuleTbFEG16qLV_6ZeCfAAAADk"]
[Thu Jul 30 14:26:50.013887 2026] [core:error] [pid 1045527:tid 1045693] [client 74.248.33.8:20931] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:50.013912 2026] [core:error] [pid 1045527:tid 1045693] [client 74.248.33.8:20931] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:50.456682 2026] [security2:error] [pid 1045527:tid 1045663] [client 91.148.245.81:52166] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/_vti_pvt/service.pwd"] [unique_id "amulejbFEG16qLV_6ZeCnQAAAAY"]
[Thu Jul 30 14:26:50.459991 2026] [security2:error] [pid 1045527:tid 1045677] [client 91.148.245.81:52164] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.ssh/id_rsa"] [unique_id "amulejbFEG16qLV_6ZeCngAAABQ"]
[Thu Jul 30 14:26:50.472445 2026] [security2:error] [pid 1045527:tid 1045682] [client 91.148.245.81:52196] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.ssh/id_ecdsa"] [unique_id "amulejbFEG16qLV_6ZeCnwAAABk"]
[Thu Jul 30 14:26:50.473393 2026] [security2:error] [pid 1045527:tid 1045770] [client 91.148.245.81:52192] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/.git/HEAD"] [unique_id "amulejbFEG16qLV_6ZeCoAAAAHE"]
[Thu Jul 30 14:26:50.599303 2026] [security2:error] [pid 1045527:tid 1045783] [client 91.148.245.81:52180] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.greensparkle.net"] [uri "/wp-admin/setup-config.php"] [unique_id "amulejbFEG16qLV_6ZeCowAAAH4"]
[Thu Jul 30 14:26:50.703506 2026] [core:error] [pid 1045527:tid 1045716] [client 74.248.33.8:20933] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:50.703534 2026] [core:error] [pid 1045527:tid 1045716] [client 74.248.33.8:20933] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:50.942600 2026] [security2:error] [pid 1045527:tid 1045730] [client 82.102.18.188:2803] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amulejbFEG16qLV_6ZeCsQAAAEk"]
[Thu Jul 30 14:26:51.118953 2026] [security2:error] [pid 1045527:tid 1045705] [client 158.158.105.63:23873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/xa.php"] [unique_id "amulezbFEG16qLV_6ZeCswAAADA"]
[Thu Jul 30 14:26:51.119084 2026] [security2:error] [pid 1045527:tid 1045705] [client 158.158.105.63:23873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/xa.php"] [unique_id "amulezbFEG16qLV_6ZeCswAAADA"]
[Thu Jul 30 14:26:51.238658 2026] [security2:error] [pid 1045527:tid 1045702] [client 82.102.18.188:41634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ad-company.net"] [uri "/xmlrpc.php"] [unique_id "amulezbFEG16qLV_6ZeCuAAAAC0"]
[Thu Jul 30 14:26:51.500502 2026] [security2:error] [pid 1045527:tid 1045751] [client 82.102.18.188:41642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amulezbFEG16qLV_6ZeCwgAAAF4"]
[Thu Jul 30 14:26:51.756026 2026] [rewrite:error] [pid 1045527:tid 1045779] [client 185.177.72.10:0] AH10508: Unsafe URL with %3f URL rewritten without UnsafeAllow3F
[Thu Jul 30 14:26:51.768958 2026] [security2:error] [pid 1045527:tid 1045707] [client 74.248.33.8:20804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/aaa.php"] [unique_id "amulezbFEG16qLV_6ZeCyAAAADI"]
[Thu Jul 30 14:26:51.771558 2026] [security2:error] [pid 1045527:tid 1045696] [client 172.202.44.182:44501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amulezbFEG16qLV_6ZeCyQAAACc"]
[Thu Jul 30 14:26:51.774998 2026] [security2:error] [pid 1045527:tid 1045659] [client 82.102.18.188:41644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amulezbFEG16qLV_6ZeCygAAAAI"]
[Thu Jul 30 14:26:52.070731 2026] [security2:error] [pid 1045527:tid 1045719] [client 82.102.18.188:41654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amulfDbFEG16qLV_6ZeC1gAAAD4"]
[Thu Jul 30 14:26:52.239746 2026] [fcgid:warn] [pid 1045527:tid 1045695] (70014)End of file found: [client 104.23.229.129:11468] mod_fcgid: can't get data from http client
[Thu Jul 30 14:26:52.340528 2026] [security2:error] [pid 1045527:tid 1045764] [client 82.102.18.188:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amulfDbFEG16qLV_6ZeC3gAAAGs"]
[Thu Jul 30 14:26:52.483381 2026] [fcgid:warn] [pid 1045527:tid 1045723] (70014)End of file found: [client 104.23.229.129:11470] mod_fcgid: can't get data from http client
[Thu Jul 30 14:26:52.605341 2026] [security2:error] [pid 1045527:tid 1045690] [client 82.102.18.188:41662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amulfDbFEG16qLV_6ZeC6AAAACE"]
[Thu Jul 30 14:26:52.724841 2026] [fcgid:warn] [pid 1045527:tid 1045736] (70014)End of file found: [client 104.23.229.129:11477] mod_fcgid: can't get data from http client
[Thu Jul 30 14:26:52.895073 2026] [security2:error] [pid 1045527:tid 1045694] [client 82.102.18.188:41676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amulfDbFEG16qLV_6ZeC8gAAACU"]
[Thu Jul 30 14:26:52.895513 2026] [security2:error] [pid 1045527:tid 1045669] [client 158.158.105.63:23904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/media.php"] [unique_id "amulfDbFEG16qLV_6ZeC8wAAAAw"]
[Thu Jul 30 14:26:52.895606 2026] [security2:error] [pid 1045527:tid 1045669] [client 158.158.105.63:23904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/media.php"] [unique_id "amulfDbFEG16qLV_6ZeC8wAAAAw"]
[Thu Jul 30 14:26:52.969032 2026] [fcgid:warn] [pid 1045527:tid 1045760] (70014)End of file found: [client 104.23.229.129:11480] mod_fcgid: can't get data from http client
[Thu Jul 30 14:26:53.283085 2026] [security2:error] [pid 1045527:tid 1045702] [client 180.243.59.178:60799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulfTbFEG16qLV_6ZeC-gAAAC0"]
[Thu Jul 30 14:26:53.283233 2026] [security2:error] [pid 1045527:tid 1045702] [client 180.243.59.178:60799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulfTbFEG16qLV_6ZeC-gAAAC0"]
[Thu Jul 30 14:26:53.427910 2026] [security2:error] [pid 1045527:tid 1045774] [client 82.102.18.188:41692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amulfTbFEG16qLV_6ZeDAwAAAHU"]
[Thu Jul 30 14:26:53.613819 2026] [autoindex:error] [pid 1045527:tid 1045782] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:26:53.685191 2026] [security2:error] [pid 1045527:tid 1045685] [client 82.102.18.188:41708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amulfTbFEG16qLV_6ZeDCwAAABw"]
[Thu Jul 30 14:26:53.713695 2026] [security2:error] [pid 1045527:tid 1045706] [client 172.202.44.182:51665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amulfTbFEG16qLV_6ZeDDQAAADE"]
[Thu Jul 30 14:26:53.815432 2026] [security2:error] [pid 1045527:tid 1045716] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amulfTbFEG16qLV_6ZeC-AAAOyI"]
[Thu Jul 30 14:26:53.840953 2026] [security2:error] [pid 1045527:tid 1045660] [client 172.202.44.182:44494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/fm.php"] [unique_id "amulfTbFEG16qLV_6ZeDEQAAAAM"]
[Thu Jul 30 14:26:53.851506 2026] [security2:error] [pid 1045527:tid 1045710] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/_phpinfo.php"] [unique_id "amulfTbFEG16qLV_6ZeDEgAAADU"]
[Thu Jul 30 14:26:53.957881 2026] [security2:error] [pid 1045527:tid 1045697] [client 82.102.18.188:57236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amulfTbFEG16qLV_6ZeDFgAAACg"]
[Thu Jul 30 14:26:54.091796 2026] [security2:error] [pid 1045527:tid 1045695] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/_phpinfo.php.dockerignore"] [unique_id "amulfjbFEG16qLV_6ZeDGgAAACY"]
[Thu Jul 30 14:26:54.226182 2026] [security2:error] [pid 1045527:tid 1045674] [client 82.102.18.188:57238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amulfjbFEG16qLV_6ZeDGwAAABE"]
[Thu Jul 30 14:26:54.332682 2026] [security2:error] [pid 1045527:tid 1045721] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/_phpinfo.php%3f"] [unique_id "amulfjbFEG16qLV_6ZeDHAAAAEA"]
[Thu Jul 30 14:26:54.495832 2026] [security2:error] [pid 1045527:tid 1045783] [client 82.102.18.188:57246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amulfjbFEG16qLV_6ZeDJQAAAH4"]
[Thu Jul 30 14:26:54.542960 2026] [security2:error] [pid 1045527:tid 1045758] [client 74.248.33.8:20946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/getid3-core.php"] [unique_id "amulfjbFEG16qLV_6ZeDJgAAAGU"]
[Thu Jul 30 14:26:54.572794 2026] [security2:error] [pid 1045527:tid 1045748] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/_phpinfo.php%2e%2e%2f%2e%2e%2f"] [unique_id "amulfjbFEG16qLV_6ZeDKgAAAFs"]
[Thu Jul 30 14:26:54.764850 2026] [security2:error] [pid 1045527:tid 1045726] [client 82.102.18.188:59741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amulfjbFEG16qLV_6ZeDKwAAAEU"]
[Thu Jul 30 14:26:54.976777 2026] [security2:error] [pid 1045527:tid 1045681] [client 158.158.105.63:19968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/images.php"] [unique_id "amulfjbFEG16qLV_6ZeDNgAAABg"]
[Thu Jul 30 14:26:54.976902 2026] [security2:error] [pid 1045527:tid 1045681] [client 158.158.105.63:19968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/images.php"] [unique_id "amulfjbFEG16qLV_6ZeDNgAAABg"]
[Thu Jul 30 14:26:55.119099 2026] [security2:error] [pid 1045527:tid 1045705] [client 82.102.18.188:57264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.ad-company.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amulfzbFEG16qLV_6ZeDOwAAADA"]
[Thu Jul 30 14:26:55.434686 2026] [security2:error] [pid 1045527:tid 1045679] [client 74.248.33.8:15407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/adminer.php"] [unique_id "amulfzbFEG16qLV_6ZeDRAAAABY"]
[Thu Jul 30 14:26:56.307523 2026] [security2:error] [pid 1045527:tid 1045701] [client 172.202.44.182:36679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/edit.php"] [unique_id "amulgDbFEG16qLV_6ZeDWwAAACw"]
[Thu Jul 30 14:26:56.320970 2026] [security2:error] [pid 1045527:tid 1045719] [client 158.158.105.63:22153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/gecko.php"] [unique_id "amulgDbFEG16qLV_6ZeDXAAAAD4"]
[Thu Jul 30 14:26:56.321103 2026] [security2:error] [pid 1045527:tid 1045719] [client 158.158.105.63:22153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/gecko.php"] [unique_id "amulgDbFEG16qLV_6ZeDXAAAAD4"]
[Thu Jul 30 14:26:56.879293 2026] [core:error] [pid 1045527:tid 1045695] [client 74.248.33.8:40486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:56.879315 2026] [core:error] [pid 1045527:tid 1045695] [client 74.248.33.8:40486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:26:57.318936 2026] [security2:error] [pid 1045527:tid 1045681] [client 158.158.105.63:55757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/82.php"] [unique_id "amulgTbFEG16qLV_6ZeDewAAABg"]
[Thu Jul 30 14:26:57.319101 2026] [security2:error] [pid 1045527:tid 1045681] [client 158.158.105.63:55757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/82.php"] [unique_id "amulgTbFEG16qLV_6ZeDewAAABg"]
[Thu Jul 30 14:26:57.674857 2026] [security2:error] [pid 1045527:tid 1045703] [client 172.202.44.182:51680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/file.php"] [unique_id "amulgTbFEG16qLV_6ZeDhQAAAC4"]
[Thu Jul 30 14:26:57.706733 2026] [security2:error] [pid 1045527:tid 1045752] [client 74.248.33.8:40493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/alfa.php"] [unique_id "amulgTbFEG16qLV_6ZeDhwAAAF8"]
[Thu Jul 30 14:26:58.224608 2026] [security2:error] [pid 1045527:tid 1045778] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/server.php"] [unique_id "amulgjbFEG16qLV_6ZeDmgAAAHk"]
[Thu Jul 30 14:26:58.295276 2026] [security2:error] [pid 1045527:tid 1045697] [client 158.158.105.63:27852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/xstelth.php"] [unique_id "amulgjbFEG16qLV_6ZeDngAAACg"]
[Thu Jul 30 14:26:58.295369 2026] [security2:error] [pid 1045527:tid 1045697] [client 158.158.105.63:27852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/xstelth.php"] [unique_id "amulgjbFEG16qLV_6ZeDngAAACg"]
[Thu Jul 30 14:26:58.468705 2026] [security2:error] [pid 1045527:tid 1045675] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/server.php.%252e"] [unique_id "amulgjbFEG16qLV_6ZeDoQAAABI"]
[Thu Jul 30 14:26:58.653260 2026] [autoindex:error] [pid 1045527:tid 1045749] [client 172.202.44.182:60355] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:26:58.708365 2026] [security2:error] [pid 1045527:tid 1045770] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/server.php%0a"] [unique_id "amulgjbFEG16qLV_6ZeDqgAAAHE"]
[Thu Jul 30 14:26:58.893347 2026] [security2:error] [pid 1045527:tid 1045748] [client 172.202.44.182:51675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/sf.php"] [unique_id "amulgjbFEG16qLV_6ZeDrwAAAFs"]
[Thu Jul 30 14:26:58.947951 2026] [security2:error] [pid 1045527:tid 1045704] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/server.php%5e"] [unique_id "amulgjbFEG16qLV_6ZeDsAAAAC8"]
[Thu Jul 30 14:26:58.958223 2026] [security2:error] [pid 1045527:tid 1045700] [client 158.158.105.63:55778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/xp.php"] [unique_id "amulgjbFEG16qLV_6ZeDsQAAACs"]
[Thu Jul 30 14:26:58.958326 2026] [security2:error] [pid 1045527:tid 1045700] [client 158.158.105.63:55778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/xp.php"] [unique_id "amulgjbFEG16qLV_6ZeDsQAAACs"]
[Thu Jul 30 14:26:58.997220 2026] [security2:error] [pid 1045527:tid 1045724] [client 172.202.44.182:60355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/bolt.php"] [unique_id "amulgjbFEG16qLV_6ZeDsgAAAEM"]
[Thu Jul 30 14:26:59.703836 2026] [security2:error] [pid 1045527:tid 1045746] [client 177.6.106.101:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulgzbFEG16qLV_6ZeDwgAAAFk"]
[Thu Jul 30 14:26:59.703995 2026] [security2:error] [pid 1045527:tid 1045746] [client 177.6.106.101:55188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulgzbFEG16qLV_6ZeDwgAAAFk"]
[Thu Jul 30 14:26:59.800536 2026] [security2:error] [pid 1045527:tid 1045673] [client 158.158.105.63:30515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/admin.php"] [unique_id "amulgzbFEG16qLV_6ZeDwwAAABA"]
[Thu Jul 30 14:26:59.800644 2026] [security2:error] [pid 1045527:tid 1045673] [client 158.158.105.63:30515] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/admin.php"] [unique_id "amulgzbFEG16qLV_6ZeDwwAAABA"]
[Thu Jul 30 14:27:00.582431 2026] [security2:error] [pid 1045527:tid 1045737] [client 158.158.105.63:23932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/adminner.php"] [unique_id "amulhDbFEG16qLV_6ZeD4wAAAFA"]
[Thu Jul 30 14:27:00.582578 2026] [security2:error] [pid 1045527:tid 1045737] [client 158.158.105.63:23932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/adminner.php"] [unique_id "amulhDbFEG16qLV_6ZeD4wAAAFA"]
[Thu Jul 30 14:27:00.748550 2026] [security2:error] [pid 1045527:tid 1045659] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amulhDbFEG16qLV_6ZeD1AAAAAI"]
[Thu Jul 30 14:27:01.419215 2026] [security2:error] [pid 1045527:tid 1045738] [client 172.202.44.182:51752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/3.php"] [unique_id "amulhTbFEG16qLV_6ZeD-QAAAFE"]
[Thu Jul 30 14:27:02.054481 2026] [security2:error] [pid 1045527:tid 1045730] [client 158.158.105.63:55007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/a.php"] [unique_id "amulhjbFEG16qLV_6ZeEDwAAAEk"]
[Thu Jul 30 14:27:02.054576 2026] [security2:error] [pid 1045527:tid 1045730] [client 158.158.105.63:55007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/a.php"] [unique_id "amulhjbFEG16qLV_6ZeEDwAAAEk"]
[Thu Jul 30 14:27:02.455450 2026] [security2:error] [pid 1045527:tid 1045684] [client 172.237.109.114:13459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulhTbFEG16qLV_6ZeECAAAABs"]
[Thu Jul 30 14:27:02.540159 2026] [security2:error] [pid 1045527:tid 1045774] [client 47.128.25.42:46156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kayomanis.com"] [uri "/robots.txt"] [unique_id "amulhjbFEG16qLV_6ZeEIAAAAHU"]
[Thu Jul 30 14:27:02.559129 2026] [core:error] [pid 1045527:tid 1045667] [client 74.248.33.8:34764] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:02.559151 2026] [core:error] [pid 1045527:tid 1045667] [client 74.248.33.8:34764] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:02.915943 2026] [security2:error] [pid 1045527:tid 1045559] [remote 57.141.0.71:31142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amulhjbFEG16qLV_6ZeEKwAAch8"]
[Thu Jul 30 14:27:03.075873 2026] [security2:error] [pid 1045527:tid 1045735] [client 172.202.44.182:42900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/222.php"] [unique_id "amulhzbFEG16qLV_6ZeEMgAAAE4"]
[Thu Jul 30 14:27:03.125701 2026] [security2:error] [pid 1045527:tid 1045675] [client 158.158.105.63:7561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/k.php"] [unique_id "amulhzbFEG16qLV_6ZeEMwAAABI"]
[Thu Jul 30 14:27:03.125793 2026] [security2:error] [pid 1045527:tid 1045675] [client 158.158.105.63:7561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/k.php"] [unique_id "amulhzbFEG16qLV_6ZeEMwAAABI"]
[Thu Jul 30 14:27:03.138955 2026] [fcgid:warn] [pid 1045527:tid 1045743] (70014)End of file found: [client 172.71.123.115:13204] mod_fcgid: can't get data from http client
[Thu Jul 30 14:27:03.276915 2026] [security2:error] [pid 1045527:tid 1045666] [client 74.248.33.8:34144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amulhzbFEG16qLV_6ZeEOwAAAAk"]
[Thu Jul 30 14:27:03.380579 2026] [fcgid:warn] [pid 1045527:tid 1045695] (70014)End of file found: [client 172.71.123.116:10462] mod_fcgid: can't get data from http client
[Thu Jul 30 14:27:03.622276 2026] [fcgid:warn] [pid 1045527:tid 1045763] (70014)End of file found: [client 172.71.123.115:11634] mod_fcgid: can't get data from http client
[Thu Jul 30 14:27:03.864802 2026] [fcgid:warn] [pid 1045527:tid 1045673] (70014)End of file found: [client 172.71.123.116:10470] mod_fcgid: can't get data from http client
[Thu Jul 30 14:27:04.056330 2026] [security2:error] [pid 1045527:tid 1045528] [remote 57.141.0.54:62944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/640974427/feed/rss2/"] [unique_id "amulhzbFEG16qLV_6ZeERwAADAA"]
[Thu Jul 30 14:27:04.094079 2026] [security2:error] [pid 1045527:tid 1045783] [client 180.243.59.178:61360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuliDbFEG16qLV_6ZeESgAAAH4"]
[Thu Jul 30 14:27:04.094207 2026] [security2:error] [pid 1045527:tid 1045783] [client 180.243.59.178:61360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuliDbFEG16qLV_6ZeESgAAAH4"]
[Thu Jul 30 14:27:04.231011 2026] [security2:error] [pid 1045527:tid 1045687] [client 158.158.105.63:37914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/222.php"] [unique_id "amuliDbFEG16qLV_6ZeEUgAAAB4"]
[Thu Jul 30 14:27:04.231115 2026] [security2:error] [pid 1045527:tid 1045687] [client 158.158.105.63:37914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/222.php"] [unique_id "amuliDbFEG16qLV_6ZeEUgAAAB4"]
[Thu Jul 30 14:27:04.448473 2026] [security2:error] [pid 1045527:tid 1045756] [client 172.202.44.182:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuliDbFEG16qLV_6ZeEWQAAAGM"]
[Thu Jul 30 14:27:05.199507 2026] [security2:error] [pid 1045527:tid 1045719] [client 172.202.44.182:42881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wso.php"] [unique_id "amuliTbFEG16qLV_6ZeEbgAAAD4"]
[Thu Jul 30 14:27:05.202959 2026] [security2:error] [pid 1045527:tid 1045701] [client 158.158.105.63:30485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/mac.php"] [unique_id "amuliTbFEG16qLV_6ZeEbwAAACw"]
[Thu Jul 30 14:27:05.203076 2026] [security2:error] [pid 1045527:tid 1045701] [client 158.158.105.63:30485] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/mac.php"] [unique_id "amuliTbFEG16qLV_6ZeEbwAAACw"]
[Thu Jul 30 14:27:05.375671 2026] [security2:error] [pid 1045527:tid 1045721] [client 114.119.153.105:27597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuliTbFEG16qLV_6ZeEdwAAAEA"], referer: https://www.nordeste1.com/robots.txt
[Thu Jul 30 14:27:05.833390 2026] [core:notice] [pid 1045527:tid 1045770] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:06.060771 2026] [security2:error] [pid 1045527:tid 1045678] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "amulijbFEG16qLV_6ZeEigAAABU"]
[Thu Jul 30 14:27:06.081618 2026] [security2:error] [pid 1045527:tid 1045757] [client 172.202.44.182:51728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/ioxi-o.php"] [unique_id "amulijbFEG16qLV_6ZeEiwAAAGQ"]
[Thu Jul 30 14:27:06.099136 2026] [security2:error] [pid 1045527:tid 1045714] [client 172.202.44.182:60410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amulijbFEG16qLV_6ZeEjAAAADk"]
[Thu Jul 30 14:27:06.293805 2026] [security2:error] [pid 1045527:tid 1045784] [client 158.158.105.63:46095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.carnetdeshopping.com"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amulijbFEG16qLV_6ZeEkQAAAH8"]
[Thu Jul 30 14:27:06.449184 2026] [security2:error] [pid 1045527:tid 1045753] [client 158.158.105.63:46095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.carnetdeshopping.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/"] [unique_id "amulijbFEG16qLV_6ZeEmQAAAGA"]
[Thu Jul 30 14:27:06.552356 2026] [security2:error] [pid 1045527:tid 1045550] [remote 57.141.0.45:34916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amulijbFEG16qLV_6ZeEmwAAEBY"]
[Thu Jul 30 14:27:06.717818 2026] [security2:error] [pid 1045527:tid 1045728] [client 158.158.105.63:46095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/ops.php"] [unique_id "amulijbFEG16qLV_6ZeEnQAAAEc"]
[Thu Jul 30 14:27:06.717905 2026] [security2:error] [pid 1045527:tid 1045728] [client 158.158.105.63:46095] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/ops.php"] [unique_id "amulijbFEG16qLV_6ZeEnQAAAEc"]
[Thu Jul 30 14:27:06.971697 2026] [security2:error] [pid 1045527:tid 1045775] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amulijbFEG16qLV_6ZeEowAAAHY"]
[Thu Jul 30 14:27:07.205916 2026] [security2:error] [pid 1045527:tid 1045773] [client 172.202.44.182:51741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/file56.php"] [unique_id "amulizbFEG16qLV_6ZeErgAAAHQ"]
[Thu Jul 30 14:27:07.425675 2026] [security2:error] [pid 1045527:tid 1045749] [client 158.158.105.63:23407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carnetdeshopping.com"] [uri "/8.php"] [unique_id "amulizbFEG16qLV_6ZeEuQAAAFw"]
[Thu Jul 30 14:27:07.425788 2026] [security2:error] [pid 1045527:tid 1045749] [client 158.158.105.63:23407] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.carnetdeshopping.com"] [uri "/8.php"] [unique_id "amulizbFEG16qLV_6ZeEuQAAAFw"]
[Thu Jul 30 14:27:07.532800 2026] [autoindex:error] [pid 1045527:tid 1045677] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:27:07.813334 2026] [security2:error] [pid 1045527:tid 1045704] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/api.orig"] [unique_id "amulizbFEG16qLV_6ZeEwgAAAC8"]
[Thu Jul 30 14:27:07.829080 2026] [security2:error] [pid 1045527:tid 1045700] [client 172.202.44.182:51746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-content/admin.php"] [unique_id "amulizbFEG16qLV_6ZeEwwAAACs"]
[Thu Jul 30 14:27:08.265098 2026] [security2:error] [pid 1045527:tid 1045732] [client 172.202.44.182:60380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuljDbFEG16qLV_6ZeEzgAAAEs"]
[Thu Jul 30 14:27:08.428933 2026] [security2:error] [pid 1045527:tid 1045784] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/src.orig"] [unique_id "amuljDbFEG16qLV_6ZeE1QAAAH8"]
[Thu Jul 30 14:27:09.040446 2026] [security2:error] [pid 1045527:tid 1045781] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuljDbFEG16qLV_6ZeE5QAAAHw"]
[Thu Jul 30 14:27:09.522191 2026] [security2:error] [pid 1045527:tid 1045610] [remote 57.141.0.13:61514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3981330618/feed/rss2/"] [unique_id "amuljTbFEG16qLV_6ZeE8wAAA1I"]
[Thu Jul 30 14:27:09.997252 2026] [security2:error] [pid 1045527:tid 1045774] [client 172.202.44.182:19881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-configs.php"] [unique_id "amuljTbFEG16qLV_6ZeFBQAAAHU"]
[Thu Jul 30 14:27:10.332204 2026] [security2:error] [pid 1045527:tid 1045689] [client 177.6.106.101:55813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuljjbFEG16qLV_6ZeFCwAAACA"]
[Thu Jul 30 14:27:10.332376 2026] [security2:error] [pid 1045527:tid 1045689] [client 177.6.106.101:55813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuljjbFEG16qLV_6ZeFCwAAACA"]
[Thu Jul 30 14:27:11.239596 2026] [security2:error] [pid 1045527:tid 1045744] [client 127.0.0.1:14550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuljzbFEG16qLV_6ZeFJgAAAFc"]
[Thu Jul 30 14:27:11.239612 2026] [security2:error] [pid 1045527:tid 1045711] [client 127.0.0.1:14542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fso.nyx.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuljzbFEG16qLV_6ZeFJQAAADY"]
[Thu Jul 30 14:27:11.239742 2026] [security2:error] [pid 1045527:tid 1045705] [client 74.7.175.159:43900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.fso.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuljzbFEG16qLV_6ZeFJAAAMF8"]
[Thu Jul 30 14:27:11.355198 2026] [security2:error] [pid 1045527:tid 1045757] [client 172.202.44.182:42942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuljzbFEG16qLV_6ZeFKwAAAGQ"]
[Thu Jul 30 14:27:11.471548 2026] [security2:error] [pid 1045527:tid 1045717] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuljzbFEG16qLV_6ZeFKgAAADw"]
[Thu Jul 30 14:27:12.273525 2026] [security2:error] [pid 1045527:tid 1045667] [client 172.202.44.182:42921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/php.php"] [unique_id "amulkDbFEG16qLV_6ZeFSAAAAAo"]
[Thu Jul 30 14:27:12.977069 2026] [security2:error] [pid 1045527:tid 1045660] [client 172.202.44.182:19869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/edit.php"] [unique_id "amulkDbFEG16qLV_6ZeFXwAAAAM"]
[Thu Jul 30 14:27:13.115090 2026] [core:notice] [pid 1045527:tid 1045784] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:13.118145 2026] [security2:error] [pid 1045527:tid 1045784] [client 144.31.35.72:56338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ejournalugj.com"] [uri "/-yanz/Content_analysis.pdf"] [unique_id "amulkTbFEG16qLV_6ZeFZwAAAH8"]
[Thu Jul 30 14:27:13.326469 2026] [core:notice] [pid 1045527:tid 1045665] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:13.447759 2026] [security2:error] [pid 1045527:tid 1045606] [remote 47.128.27.78:34046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-13-retro-white-lucky-orange/"] [unique_id "amulkTbFEG16qLV_6ZeFcQAAfU4"]
[Thu Jul 30 14:27:13.499971 2026] [security2:error] [pid 1045527:tid 1045732] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amulkDbFEG16qLV_6ZeFWQAAS2U"]
[Thu Jul 30 14:27:13.531425 2026] [security2:error] [pid 1045527:tid 1045602] [remote 65.98.127.3:33382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.127.98.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amulkTbFEG16qLV_6ZeFdAAAFko"]
[Thu Jul 30 14:27:13.599161 2026] [security2:error] [pid 1045527:tid 1045748] [client 66.249.73.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nco.zzt.temporary.site"] [uri "/index.php"] [unique_id "amulkDbFEG16qLV_6ZeFYAAAAFs"]
[Thu Jul 30 14:27:13.955157 2026] [security2:error] [pid 1045527:tid 1045658] [client 172.202.44.182:51841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-includes/index.php"] [unique_id "amulkTbFEG16qLV_6ZeFgAAAAAE"]
[Thu Jul 30 14:27:14.313832 2026] [security2:error] [pid 1045527:tid 1045661] [client 180.243.59.178:61877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulkjbFEG16qLV_6ZeFkQAAAAQ"]
[Thu Jul 30 14:27:14.314355 2026] [security2:error] [pid 1045527:tid 1045661] [client 180.243.59.178:61877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulkjbFEG16qLV_6ZeFkQAAAAQ"]
[Thu Jul 30 14:27:14.588066 2026] [proxy:error] [pid 1045527:tid 1045641] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:14.588129 2026] [proxy_http:error] [pid 1045527:tid 1045641] [remote 74.7.241.160:36504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:14.588691 2026] [proxy:error] [pid 1045527:tid 1045641] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:14.588733 2026] [proxy_http:error] [pid 1045527:tid 1045641] [remote 74.7.241.160:36504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:14.853480 2026] [security2:error] [pid 1045527:tid 1045766] [client 172.202.44.182:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/2.php"] [unique_id "amulkjbFEG16qLV_6ZeFogAAAG0"]
[Thu Jul 30 14:27:14.962950 2026] [security2:error] [pid 1045527:tid 1045690] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/libs~"] [unique_id "amulkjbFEG16qLV_6ZeFpgAAACE"]
[Thu Jul 30 14:27:16.211745 2026] [security2:error] [pid 1045527:tid 1045683] [client 172.202.44.182:19852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amullDbFEG16qLV_6ZeF0wAAABo"]
[Thu Jul 30 14:27:16.237813 2026] [security2:error] [pid 1045527:tid 1045727] [client 139.28.219.70:41070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amullDbFEG16qLV_6ZeF1QAAAEY"]
[Thu Jul 30 14:27:16.704396 2026] [security2:error] [pid 1045527:tid 1045754] [client 74.248.33.8:34791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amullDbFEG16qLV_6ZeF4AAAAGE"]
[Thu Jul 30 14:27:17.142096 2026] [security2:error] [pid 1045527:tid 1045723] [client 139.28.219.70:41072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/xmlrpc.php"] [unique_id "amullDbFEG16qLV_6ZeF7AAAAEI"]
[Thu Jul 30 14:27:17.519875 2026] [security2:error] [pid 1045527:tid 1045731] [client 172.202.44.182:20350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/a.php"] [unique_id "amullTbFEG16qLV_6ZeF_QAAAEo"]
[Thu Jul 30 14:27:17.654914 2026] [security2:error] [pid 1045527:tid 1045741] [client 139.28.219.70:41076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amullTbFEG16qLV_6ZeGAAAAAFQ"]
[Thu Jul 30 14:27:17.735229 2026] [security2:error] [pid 1045527:tid 1045776] [client 172.202.44.182:20016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/mah.php"] [unique_id "amullTbFEG16qLV_6ZeGBAAAAHc"]
[Thu Jul 30 14:27:17.839309 2026] [core:notice] [pid 1045527:tid 1045668] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:18.091400 2026] [security2:error] [pid 1045527:tid 1045745] [client 74.248.33.8:21907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amulljbFEG16qLV_6ZeGDwAAAFg"]
[Thu Jul 30 14:27:18.194118 2026] [security2:error] [pid 1045527:tid 1045722] [client 139.28.219.70:41088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amulljbFEG16qLV_6ZeGEQAAAEE"]
[Thu Jul 30 14:27:18.821450 2026] [security2:error] [pid 1045527:tid 1045667] [client 52.176.39.128:3138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.39.176.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amulljbFEG16qLV_6ZeGHQAAAAo"]
[Thu Jul 30 14:27:18.830161 2026] [security2:error] [pid 1045527:tid 1045777] [client 139.28.219.70:41094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amulljbFEG16qLV_6ZeGJAAAAHg"]
[Thu Jul 30 14:27:19.003145 2026] [security2:error] [pid 1045527:tid 1045695] [client 74.248.33.8:39165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/edit.php"] [unique_id "amullzbFEG16qLV_6ZeGLgAAACY"]
[Thu Jul 30 14:27:19.028302 2026] [autoindex:error] [pid 1045527:tid 1045738] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:27:19.285895 2026] [autoindex:error] [pid 1045527:tid 1045676] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:27:19.330763 2026] [security2:error] [pid 1045527:tid 1045670] [client 172.202.44.182:17455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/send.php"] [unique_id "amullzbFEG16qLV_6ZeGOwAAAA0"]
[Thu Jul 30 14:27:19.366537 2026] [security2:error] [pid 1045527:tid 1045746] [client 139.28.219.70:41098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amullzbFEG16qLV_6ZeGPAAAAFk"]
[Thu Jul 30 14:27:19.627011 2026] [security2:error] [pid 1045527:tid 1045748] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/wordpress.sql"] [unique_id "amullzbFEG16qLV_6ZeGRAAAAFs"]
[Thu Jul 30 14:27:19.726132 2026] [security2:error] [pid 1045527:tid 1045757] [client 172.202.44.182:19725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amullzbFEG16qLV_6ZeGRgAAAGQ"]
[Thu Jul 30 14:27:19.892322 2026] [security2:error] [pid 1045527:tid 1045678] [client 139.28.219.70:41114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amullzbFEG16qLV_6ZeGSwAAABU"]
[Thu Jul 30 14:27:20.415900 2026] [security2:error] [pid 1045527:tid 1045674] [client 139.28.219.70:41124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amulmDbFEG16qLV_6ZeGYQAAABE"]
[Thu Jul 30 14:27:20.437016 2026] [security2:error] [pid 1045527:tid 1045740] [client 59.173.230.213:51525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amulmDbFEG16qLV_6ZeGWgAAAFM"]
[Thu Jul 30 14:27:20.890959 2026] [security2:error] [pid 1045527:tid 1045766] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "amulmDbFEG16qLV_6ZeGcgAAAG0"]
[Thu Jul 30 14:27:20.938356 2026] [security2:error] [pid 1045527:tid 1045725] [client 139.28.219.70:47484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amulmDbFEG16qLV_6ZeGcwAAAEQ"]
[Thu Jul 30 14:27:20.966219 2026] [core:error] [pid 1045527:tid 1045679] [client 74.248.33.8:39128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:20.966241 2026] [core:error] [pid 1045527:tid 1045679] [client 74.248.33.8:39128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:21.017496 2026] [security2:error] [pid 1045527:tid 1045705] [client 172.202.44.182:19978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amulmTbFEG16qLV_6ZeGdwAAADA"]
[Thu Jul 30 14:27:21.018315 2026] [autoindex:error] [pid 1045527:tid 1045657] [client 43.154.127.188:45560] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:27:21.201704 2026] [security2:error] [pid 1045527:tid 1045739] [client 177.6.106.101:56451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulmTbFEG16qLV_6ZeGfwAAAFI"]
[Thu Jul 30 14:27:21.201877 2026] [security2:error] [pid 1045527:tid 1045739] [client 177.6.106.101:56451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulmTbFEG16qLV_6ZeGfwAAAFI"]
[Thu Jul 30 14:27:21.240238 2026] [security2:error] [pid 1045527:tid 1045732] [client 172.202.44.182:20316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin.php"] [unique_id "amulmTbFEG16qLV_6ZeGgAAAAEs"]
[Thu Jul 30 14:27:21.404312 2026] [core:notice] [pid 1045527:tid 1045733] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:21.529932 2026] [security2:error] [pid 1045527:tid 1045784] [client 139.28.219.70:47490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amulmTbFEG16qLV_6ZeGhwAAAH8"]
[Thu Jul 30 14:27:22.118003 2026] [security2:error] [pid 1045527:tid 1045707] [client 139.28.219.70:47500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amulmjbFEG16qLV_6ZeGmAAAADI"]
[Thu Jul 30 14:27:22.636109 2026] [security2:error] [pid 1045527:tid 1045664] [client 139.28.219.70:47512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amulmjbFEG16qLV_6ZeGpgAAAAc"]
[Thu Jul 30 14:27:22.924264 2026] [security2:error] [pid 1045527:tid 1045678] [client 172.202.44.182:20326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/size.php"] [unique_id "amulmjbFEG16qLV_6ZeGsAAAABU"]
[Thu Jul 30 14:27:22.978431 2026] [security2:error] [pid 1045527:tid 1045695] [client 172.202.44.182:17461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/about.php"] [unique_id "amulmjbFEG16qLV_6ZeGswAAACY"]
[Thu Jul 30 14:27:23.153790 2026] [security2:error] [pid 1045527:tid 1045734] [client 139.28.219.70:47526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amulmzbFEG16qLV_6ZeGuAAAAE0"]
[Thu Jul 30 14:27:23.269724 2026] [core:error] [pid 1045527:tid 1045778] [client 74.248.33.8:21904] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:23.269749 2026] [core:error] [pid 1045527:tid 1045778] [client 74.248.33.8:21904] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:23.573230 2026] [security2:error] [pid 1045527:tid 1045681] [client 172.237.109.114:36071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulmjbFEG16qLV_6ZeGsgAAABg"], referer: http://alseermarine.com:80/index.html
[Thu Jul 30 14:27:23.676936 2026] [security2:error] [pid 1045527:tid 1045730] [client 139.28.219.70:47530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amulmzbFEG16qLV_6ZeGzAAAAEk"]
[Thu Jul 30 14:27:23.962858 2026] [security2:error] [pid 1045527:tid 1045776] [client 74.248.33.8:21938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/sf.php"] [unique_id "amulmzbFEG16qLV_6ZeG1gAAAHc"]
[Thu Jul 30 14:27:24.204312 2026] [security2:error] [pid 1045527:tid 1045728] [client 139.28.219.70:47546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lark-shop.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amulnDbFEG16qLV_6ZeG2wAAAEc"]
[Thu Jul 30 14:27:24.398775 2026] [security2:error] [pid 1045527:tid 1045746] [client 172.202.44.182:20348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/options.php"] [unique_id "amulnDbFEG16qLV_6ZeG4wAAAFk"]
[Thu Jul 30 14:27:24.449921 2026] [security2:error] [pid 1045527:tid 1045693] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amulmzbFEG16qLV_6ZeG1AAAJEY"]
[Thu Jul 30 14:27:24.882720 2026] [security2:error] [pid 1045527:tid 1045666] [client 180.243.59.178:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulnDbFEG16qLV_6ZeG8QAAAAk"]
[Thu Jul 30 14:27:24.882851 2026] [security2:error] [pid 1045527:tid 1045666] [client 180.243.59.178:62415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulnDbFEG16qLV_6ZeG8QAAAAk"]
[Thu Jul 30 14:27:24.891107 2026] [security2:error] [pid 1045527:tid 1045551] [remote 57.141.0.9:59668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/404010317/feed/rss2/"] [unique_id "amulnDbFEG16qLV_6ZeG8gAAeBc"]
[Thu Jul 30 14:27:25.491045 2026] [core:error] [pid 1045527:tid 1045727] [client 74.248.33.8:34155] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:25.491070 2026] [core:error] [pid 1045527:tid 1045727] [client 74.248.33.8:34155] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:25.619304 2026] [core:notice] [pid 1045527:tid 1045726] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:25.696186 2026] [security2:error] [pid 1045527:tid 1045743] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amulnTbFEG16qLV_6ZeG-gAAVn4"]
[Thu Jul 30 14:27:26.264668 2026] [security2:error] [pid 1045527:tid 1045567] [remote 57.141.0.24:31504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amulnjbFEG16qLV_6ZeHHwAAdSc"]
[Thu Jul 30 14:27:26.898594 2026] [security2:error] [pid 1045527:tid 1045742] [client 172.202.44.182:20340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/themes/index.php"] [unique_id "amulnjbFEG16qLV_6ZeHMwAAAFU"]
[Thu Jul 30 14:27:27.388943 2026] [security2:error] [pid 1045527:tid 1045603] [remote 57.141.0.51:48562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amulnzbFEG16qLV_6ZeHQgAAaks"]
[Thu Jul 30 14:27:27.394930 2026] [security2:error] [pid 1045527:tid 1045740] [client 74.248.33.8:21922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wso.php"] [unique_id "amulnzbFEG16qLV_6ZeHQwAAAFM"]
[Thu Jul 30 14:27:27.431955 2026] [security2:error] [pid 1045527:tid 1045685] [client 172.202.44.182:50930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amulnzbFEG16qLV_6ZeHRwAAABw"]
[Thu Jul 30 14:27:28.247110 2026] [security2:error] [pid 1045527:tid 1045600] [remote 77.88.47.11:57924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.47.88.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/11/20/love-creative-people-eshop-deco/"] [unique_id "amuloDbFEG16qLV_6ZeHWgAAEEg"]
[Thu Jul 30 14:27:28.619839 2026] [security2:error] [pid 1045527:tid 1045730] [client 172.202.44.182:19716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/403.php"] [unique_id "amuloDbFEG16qLV_6ZeHcQAAAEk"]
[Thu Jul 30 14:27:28.631927 2026] [fcgid:warn] [pid 1045527:tid 1045728] (70014)End of file found: [client 172.71.119.70:9418] mod_fcgid: can't get data from http client
[Thu Jul 30 14:27:28.789903 2026] [security2:error] [pid 1045527:tid 1045713] [client 74.248.33.8:20847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/ioxi-o.php"] [unique_id "amuloDbFEG16qLV_6ZeHcwAAADg"]
[Thu Jul 30 14:27:28.871448 2026] [fcgid:warn] [pid 1045527:tid 1045675] (70014)End of file found: [client 172.71.119.69:12805] mod_fcgid: can't get data from http client
[Thu Jul 30 14:27:29.118046 2026] [fcgid:warn] [pid 1045527:tid 1045683] (70014)End of file found: [client 172.71.119.69:12806] mod_fcgid: can't get data from http client
[Thu Jul 30 14:27:29.360016 2026] [fcgid:warn] [pid 1045527:tid 1045720] (70014)End of file found: [client 172.71.119.69:12811] mod_fcgid: can't get data from http client
[Thu Jul 30 14:27:29.451671 2026] [security2:error] [pid 1045527:tid 1045780] [client 89.130.156.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuloTbFEG16qLV_6ZeHggAAAHs"], referer: https://cnpinyin.com
[Thu Jul 30 14:27:29.937303 2026] [security2:error] [pid 1045527:tid 1045663] [client 18.193.252.127:9532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuloTbFEG16qLV_6ZeHlQAAAAY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:27:30.398177 2026] [security2:error] [pid 1045527:tid 1045709] [client 74.248.33.8:34140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/file56.php"] [unique_id "amulojbFEG16qLV_6ZeHpAAAADQ"]
[Thu Jul 30 14:27:30.400438 2026] [security2:error] [pid 1045527:tid 1045717] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/en.orig"] [unique_id "amulojbFEG16qLV_6ZeHowAAADw"]
[Thu Jul 30 14:27:30.423126 2026] [core:notice] [pid 1045527:tid 1045750] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:30.427530 2026] [security2:error] [pid 1045527:tid 1045750] [client 18.193.252.127:9548] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amulojbFEG16qLV_6ZeHpQAAAF0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:27:30.646916 2026] [security2:error] [pid 1045527:tid 1045706] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amulojbFEG16qLV_6ZeHogAAADE"]
[Thu Jul 30 14:27:31.024890 2026] [security2:error] [pid 1045527:tid 1045728] [client 18.193.252.127:9562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amulozbFEG16qLV_6ZeHugAAAEc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:27:31.393994 2026] [security2:error] [pid 1045527:tid 1045718] [client 172.202.44.182:11746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wk/index.php"] [unique_id "amulozbFEG16qLV_6ZeHyAAAAD0"]
[Thu Jul 30 14:27:31.521307 2026] [security2:error] [pid 1045527:tid 1045689] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/o.php"] [unique_id "amulozbFEG16qLV_6ZeHyQAAACA"]
[Thu Jul 30 14:27:31.764971 2026] [security2:error] [pid 1045527:tid 1045745] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/o.php%2f"] [unique_id "amulozbFEG16qLV_6ZeH0wAAAFg"]
[Thu Jul 30 14:27:32.010266 2026] [security2:error] [pid 1045527:tid 1045723] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/o.php..."] [unique_id "amulpDbFEG16qLV_6ZeH1AAAAEI"]
[Thu Jul 30 14:27:32.250433 2026] [security2:error] [pid 1045527:tid 1045750] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/o.php.swp"] [unique_id "amulpDbFEG16qLV_6ZeH4AAAAF0"]
[Thu Jul 30 14:27:32.283327 2026] [security2:error] [pid 1045527:tid 1045671] [client 172.202.44.182:19731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amulpDbFEG16qLV_6ZeH1QAAAA4"]
[Thu Jul 30 14:27:32.776429 2026] [security2:error] [pid 1045527:tid 1045685] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amulpDbFEG16qLV_6ZeH3AAAHGQ"]
[Thu Jul 30 14:27:33.313458 2026] [security2:error] [pid 1045527:tid 1045739] [client 177.6.106.101:57131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulpTbFEG16qLV_6ZeH_gAAAFI"]
[Thu Jul 30 14:27:33.313576 2026] [security2:error] [pid 1045527:tid 1045739] [client 177.6.106.101:57131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulpTbFEG16qLV_6ZeH_gAAAFI"]
[Thu Jul 30 14:27:33.762530 2026] [security2:error] [pid 1045527:tid 1045719] [client 74.248.33.8:17750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amulpTbFEG16qLV_6ZeICAAAAD4"]
[Thu Jul 30 14:27:33.787117 2026] [security2:error] [pid 1045527:tid 1045687] [client 172.202.44.182:19686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/as.php"] [unique_id "amulpTbFEG16qLV_6ZeICwAAAB4"]
[Thu Jul 30 14:27:33.831844 2026] [security2:error] [pid 1045527:tid 1045771] [client 172.202.44.182:50927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-file.php"] [unique_id "amulpTbFEG16qLV_6ZeIDgAAAHI"]
[Thu Jul 30 14:27:34.336377 2026] [security2:error] [pid 1045527:tid 1045775] [client 186.29.130.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amulpjbFEG16qLV_6ZeIHwAAAHY"], referer: https://cnpinyin.com
[Thu Jul 30 14:27:34.608731 2026] [security2:error] [pid 1045527:tid 1045671] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/app.swp"] [unique_id "amulpjbFEG16qLV_6ZeIJwAAAA4"]
[Thu Jul 30 14:27:34.620272 2026] [security2:error] [pid 1045527:tid 1045740] [client 172.237.109.114:56409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulpjbFEG16qLV_6ZeIFwAAAFM"]
[Thu Jul 30 14:27:34.972039 2026] [security2:error] [pid 1045527:tid 1045723] [client 74.248.33.8:20817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-admin/css/index.php"] [unique_id "amulpjbFEG16qLV_6ZeINQAAAEI"]
[Thu Jul 30 14:27:35.216336 2026] [security2:error] [pid 1045527:tid 1045750] [client 172.202.44.182:51852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/sid3.php"] [unique_id "amulpzbFEG16qLV_6ZeIOgAAAF0"]
[Thu Jul 30 14:27:35.387291 2026] [security2:error] [pid 1045527:tid 1045782] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htpasswd"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.terraform.htpasswd"] [unique_id "amulpzbFEG16qLV_6ZeIRAAAAH0"]
[Thu Jul 30 14:27:35.464121 2026] [security2:error] [pid 1045527:tid 1045742] [client 180.243.59.178:62985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulpzbFEG16qLV_6ZeIRQAAAFU"]
[Thu Jul 30 14:27:35.464442 2026] [security2:error] [pid 1045527:tid 1045742] [client 180.243.59.178:62985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulpzbFEG16qLV_6ZeIRQAAAFU"]
[Thu Jul 30 14:27:35.678313 2026] [security2:error] [pid 1045527:tid 1045542] [remote 74.7.227.39:41160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amulpzbFEG16qLV_6ZeITgAAIw4"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin
[Thu Jul 30 14:27:35.834124 2026] [security2:error] [pid 1045527:tid 1045721] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/log.txt~"] [unique_id "amulpzbFEG16qLV_6ZeIXQAAAEA"]
[Thu Jul 30 14:27:35.948441 2026] [security2:error] [pid 1045527:tid 1045677] [client 74.248.33.8:20821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/edit.php"] [unique_id "amulpzbFEG16qLV_6ZeIXgAAABQ"]
[Thu Jul 30 14:27:35.960433 2026] [security2:error] [pid 1045527:tid 1045764] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/log.txt.bak"] [unique_id "amulpzbFEG16qLV_6ZeIXwAAAGs"]
[Thu Jul 30 14:27:36.283231 2026] [security2:error] [pid 1045527:tid 1045682] [client 172.202.44.182:50901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amulqDbFEG16qLV_6ZeIagAAABk"]
[Thu Jul 30 14:27:36.968770 2026] [security2:error] [pid 1045527:tid 1045745] [client 172.202.44.182:11505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/av.php"] [unique_id "amulqDbFEG16qLV_6ZeIgwAAAFg"]
[Thu Jul 30 14:27:38.035917 2026] [security2:error] [pid 1045527:tid 1045778] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/nodeapi%00"] [unique_id "amulqjbFEG16qLV_6ZeIoQAAAHk"]
[Thu Jul 30 14:27:38.162263 2026] [security2:error] [pid 1045527:tid 1045677] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulqjbFEG16qLV_6ZeIowAAABQ"]
[Thu Jul 30 14:27:38.243614 2026] [security2:error] [pid 1045527:tid 1045781] [client 74.248.33.8:34160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/2.php"] [unique_id "amulqjbFEG16qLV_6ZeIpAAAAHw"]
[Thu Jul 30 14:27:38.287488 2026] [security2:error] [pid 1045527:tid 1045743] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulqjbFEG16qLV_6ZeIpQAAAFY"]
[Thu Jul 30 14:27:38.414309 2026] [security2:error] [pid 1045527:tid 1045759] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulqjbFEG16qLV_6ZeIrQAAAGY"]
[Thu Jul 30 14:27:38.538866 2026] [security2:error] [pid 1045527:tid 1045714] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amulqjbFEG16qLV_6ZeIsAAAADk"]
[Thu Jul 30 14:27:38.556275 2026] [security2:error] [pid 1045527:tid 1045569] [remote 57.141.0.46:27640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amulqjbFEG16qLV_6ZeItAAAACk"]
[Thu Jul 30 14:27:39.987531 2026] [security2:error] [pid 1045527:tid 1045769] [client 172.202.44.182:11765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/mini.php"] [unique_id "amulqzbFEG16qLV_6ZeI2wAAAHA"]
[Thu Jul 30 14:27:40.799144 2026] [rewrite:error] [pid 1045527:tid 1045663] [client 185.177.72.10:0] AH10508: Unsafe URL with %3f URL rewritten without UnsafeAllow3F
[Thu Jul 30 14:27:40.878144 2026] [security2:error] [pid 1045527:tid 1045571] [remote 57.141.0.58:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amulrDbFEG16qLV_6ZeI-AAARis"]
[Thu Jul 30 14:27:41.774816 2026] [security2:error] [pid 1045527:tid 1045686] [client 185.177.72.10:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/projects.bak"] [unique_id "amulrTbFEG16qLV_6ZeJFAAAAB0"]
[Thu Jul 30 14:27:41.791751 2026] [security2:error] [pid 1045527:tid 1045678] [client 74.248.33.8:40503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amulrTbFEG16qLV_6ZeJFQAAABU"]
[Thu Jul 30 14:27:41.961364 2026] [security2:error] [pid 1045527:tid 1045706] [client 172.202.44.182:19650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amulrTbFEG16qLV_6ZeJFwAAADE"]
[Thu Jul 30 14:27:42.734453 2026] [core:error] [pid 1045527:tid 1045732] [client 74.7.230.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:42.734480 2026] [core:error] [pid 1045527:tid 1045732] [client 74.7.230.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:42.734638 2026] [security2:error] [pid 1045527:tid 1045732] [client 74.7.230.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.qjl.dlq.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amulrjbFEG16qLV_6ZeJLwAAAEs"]
[Thu Jul 30 14:27:42.735253 2026] [security2:error] [pid 1045527:tid 1045753] [client 74.7.230.45:48376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.qjl.dlq.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amulrjbFEG16qLV_6ZeJLQAAYEc"]
[Thu Jul 30 14:27:42.975066 2026] [security2:error] [pid 1045527:tid 1045784] [client 172.202.44.182:20437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/plugins.php"] [unique_id "amulrjbFEG16qLV_6ZeJNQAAAH8"]
[Thu Jul 30 14:27:43.098867 2026] [security2:error] [pid 1045527:tid 1045719] [client 172.202.44.182:11773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/aa.php"] [unique_id "amulrzbFEG16qLV_6ZeJOwAAAD4"]
[Thu Jul 30 14:27:43.125668 2026] [security2:error] [pid 1045527:tid 1045734] [client 177.6.106.101:53736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulrzbFEG16qLV_6ZeJPAAAAE0"]
[Thu Jul 30 14:27:43.125864 2026] [security2:error] [pid 1045527:tid 1045734] [client 177.6.106.101:53736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulrzbFEG16qLV_6ZeJPAAAAE0"]
[Thu Jul 30 14:27:43.521065 2026] [security2:error] [pid 1045527:tid 1045717] [client 172.237.109.114:39141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulrjbFEG16qLV_6ZeJOAAAADw"]
[Thu Jul 30 14:27:43.791475 2026] [security2:error] [pid 1045527:tid 1045696] [client 74.248.33.8:10667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/mah.php"] [unique_id "amulrzbFEG16qLV_6ZeJTgAAACc"]
[Thu Jul 30 14:27:44.035875 2026] [security2:error] [pid 1045527:tid 1045665] [client 172.202.44.182:39917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-includes/js/index.php"] [unique_id "amulsDbFEG16qLV_6ZeJUwAAAAg"]
[Thu Jul 30 14:27:44.220071 2026] [security2:error] [pid 1045527:tid 1045747] [client 172.202.44.182:11725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/w.php"] [unique_id "amulsDbFEG16qLV_6ZeJXAAAAFo"]
[Thu Jul 30 14:27:44.384696 2026] [security2:error] [pid 1045527:tid 1045758] [client 57.141.0.6:53648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amulrjbFEG16qLV_6ZeJHwAAZRU"]
[Thu Jul 30 14:27:44.573558 2026] [security2:error] [pid 1045527:tid 1045595] [remote 209.42.21.22:38396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mshandco.org"] [uri "/wp-login.php"] [unique_id "amulsDbFEG16qLV_6ZeJbAAAO0M"]
[Thu Jul 30 14:27:44.998282 2026] [security2:error] [pid 1045527:tid 1045703] [client 172.202.44.182:11502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/admin.php"] [unique_id "amulsDbFEG16qLV_6ZeJewAAAC4"]
[Thu Jul 30 14:27:45.848841 2026] [security2:error] [pid 1045527:tid 1045635] [remote 159.75.55.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.55.75.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imailearninghub.com"] [uri "/wp-login.php"] [unique_id "amulsTbFEG16qLV_6ZeJmAAAeGs"]
[Thu Jul 30 14:27:45.961807 2026] [security2:error] [pid 1045527:tid 1045770] [client 172.202.44.182:11592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/themes/admin.php"] [unique_id "amulsTbFEG16qLV_6ZeJmgAAAHE"]
[Thu Jul 30 14:27:46.461103 2026] [security2:error] [pid 1045527:tid 1045694] [client 66.249.73.97:50898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amulsjbFEG16qLV_6ZeJmwAAACU"]
[Thu Jul 30 14:27:46.476402 2026] [security2:error] [pid 1045527:tid 1045648] [remote 57.141.0.67:41348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/404010317/feed/rss2/"] [unique_id "amulsjbFEG16qLV_6ZeJqAAABXg"]
[Thu Jul 30 14:27:46.950103 2026] [security2:error] [pid 1045527:tid 1045725] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amulsjbFEG16qLV_6ZeJswAAAEQ"]
[Thu Jul 30 14:27:47.066188 2026] [security2:error] [pid 1045527:tid 1045781] [client 180.243.59.178:63590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulszbFEG16qLV_6ZeJtgAAAHw"]
[Thu Jul 30 14:27:47.066336 2026] [security2:error] [pid 1045527:tid 1045781] [client 180.243.59.178:63590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulszbFEG16qLV_6ZeJtgAAAHw"]
[Thu Jul 30 14:27:47.084998 2026] [security2:error] [pid 1045527:tid 1045677] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amulszbFEG16qLV_6ZeJtwAAABQ"]
[Thu Jul 30 14:27:47.188613 2026] [security2:error] [pid 1045527:tid 1045714] [client 74.248.33.8:40280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/send.php"] [unique_id "amulszbFEG16qLV_6ZeJvAAAADk"]
[Thu Jul 30 14:27:47.333705 2026] [security2:error] [pid 1045527:tid 1045784] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amulszbFEG16qLV_6ZeJwgAAAH8"]
[Thu Jul 30 14:27:47.590700 2026] [security2:error] [pid 1045527:tid 1045684] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amulszbFEG16qLV_6ZeJxwAAABs"]
[Thu Jul 30 14:27:47.612481 2026] [security2:error] [pid 1045527:tid 1045723] [client 172.237.109.114:41724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulszbFEG16qLV_6ZeJuAAAAEI"]
[Thu Jul 30 14:27:47.725560 2026] [security2:error] [pid 1045527:tid 1045755] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amulszbFEG16qLV_6ZeJywAAAGI"]
[Thu Jul 30 14:27:47.986233 2026] [security2:error] [pid 1045527:tid 1045713] [client 185.177.72.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amulszbFEG16qLV_6ZeJ0gAAADg"]
[Thu Jul 30 14:27:48.173438 2026] [security2:error] [pid 1045527:tid 1045733] [client 172.202.44.182:11752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/m.php"] [unique_id "amultDbFEG16qLV_6ZeJ1gAAAEw"]
[Thu Jul 30 14:27:48.309713 2026] [security2:error] [pid 1045527:tid 1045639] [remote 74.7.243.224:49840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amultDbFEG16qLV_6ZeJ1wAAJm8"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:27:48.453488 2026] [security2:error] [pid 1045527:tid 1045666] [client 74.248.33.8:36749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amultDbFEG16qLV_6ZeJ3wAAAAk"]
[Thu Jul 30 14:27:48.475937 2026] [security2:error] [pid 1045527:tid 1045698] [client 172.202.44.182:19699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/go.php"] [unique_id "amultDbFEG16qLV_6ZeJ4AAAACk"]
[Thu Jul 30 14:27:48.477385 2026] [core:notice] [pid 1045527:tid 1045640] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:49.091002 2026] [security2:error] [pid 1045527:tid 1045724] [client 34.7.8.86:57520] ModSecurity: Warning. Matched phrase "Bolt" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "kendarikomputer.com"] [uri "/ads.txt"] [unique_id "amultTbFEG16qLV_6ZeJ7gAAAEM"]
[Thu Jul 30 14:27:49.207599 2026] [security2:error] [pid 1045527:tid 1045694] [client 172.202.44.182:11733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amultTbFEG16qLV_6ZeJ8wAAACU"]
[Thu Jul 30 14:27:49.303899 2026] [core:notice] [pid 1045527:tid 1045535] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:49.578966 2026] [core:error] [pid 1045527:tid 1045677] [client 74.248.33.8:10242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:49.579006 2026] [core:error] [pid 1045527:tid 1045677] [client 74.248.33.8:10242] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:27:49.853240 2026] [security2:error] [pid 1045527:tid 1045725] [client 20.199.183.73:10932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/wk/index.php"] [unique_id "amultTbFEG16qLV_6ZeKBgAAAEQ"]
[Thu Jul 30 14:27:50.261484 2026] [security2:error] [pid 1045527:tid 1045735] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amultTbFEG16qLV_6ZeKAgAAAE4"]
[Thu Jul 30 14:27:50.673924 2026] [security2:error] [pid 1045527:tid 1045696] [client 20.199.183.73:26491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/av.php"] [unique_id "amultjbFEG16qLV_6ZeKHAAAACc"]
[Thu Jul 30 14:27:50.712328 2026] [security2:error] [pid 1045527:tid 1045702] [client 172.202.44.182:20181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/test1.php"] [unique_id "amultjbFEG16qLV_6ZeKHQAAAC0"]
[Thu Jul 30 14:27:50.862443 2026] [security2:error] [pid 1045527:tid 1045709] [client 74.7.230.41:50890] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.sar.udi.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amultjbFEG16qLV_6ZeKIQAAADQ"]
[Thu Jul 30 14:27:51.089230 2026] [security2:error] [pid 1045527:tid 1045662] [client 172.202.44.182:11736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/classwithtostring.php"] [unique_id "amultzbFEG16qLV_6ZeKKQAAAAU"]
[Thu Jul 30 14:27:51.270347 2026] [security2:error] [pid 1045527:tid 1045707] [client 74.248.33.8:11190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/about.php"] [unique_id "amultzbFEG16qLV_6ZeKLQAAADI"]
[Thu Jul 30 14:27:51.276989 2026] [security2:error] [pid 1045527:tid 1045747] [client 20.199.183.73:44373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/mini.php"] [unique_id "amultzbFEG16qLV_6ZeKLgAAAFo"]
[Thu Jul 30 14:27:51.726057 2026] [core:notice] [pid 1045527:tid 1045598] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:52.056317 2026] [security2:error] [pid 1045527:tid 1045671] [client 172.202.44.182:11596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/gmo.php"] [unique_id "amuluDbFEG16qLV_6ZeKOgAAAA4"]
[Thu Jul 30 14:27:52.188413 2026] [security2:error] [pid 1045527:tid 1045668] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amultzbFEG16qLV_6ZeKJQAACyM"]
[Thu Jul 30 14:27:52.717107 2026] [autoindex:error] [pid 1045527:tid 1045680] [client 172.202.44.182:19495] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:27:52.903074 2026] [security2:error] [pid 1045527:tid 1045717] [client 74.248.33.8:38806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/options.php"] [unique_id "amuluDbFEG16qLV_6ZeKUAAAADw"]
[Thu Jul 30 14:27:52.944459 2026] [security2:error] [pid 1045527:tid 1045761] [client 172.202.44.182:19495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/images/index.php"] [unique_id "amuluDbFEG16qLV_6ZeKUgAAAGg"]
[Thu Jul 30 14:27:53.080182 2026] [security2:error] [pid 1045527:tid 1045746] [client 172.202.44.182:11614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/languages/index.php"] [unique_id "amuluTbFEG16qLV_6ZeKUwAAAFk"]
[Thu Jul 30 14:27:53.125074 2026] [core:notice] [pid 1045527:tid 1045592] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:53.214179 2026] [core:notice] [pid 1045527:tid 1045547] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:53.704579 2026] [core:notice] [pid 1045527:tid 1045567] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:53.709571 2026] [security2:error] [pid 1045527:tid 1045755] [client 177.6.106.101:54161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuluTbFEG16qLV_6ZeKZwAAAGI"]
[Thu Jul 30 14:27:53.709715 2026] [security2:error] [pid 1045527:tid 1045755] [client 177.6.106.101:54161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuluTbFEG16qLV_6ZeKZwAAAGI"]
[Thu Jul 30 14:27:53.870563 2026] [autoindex:error] [pid 1045527:tid 1045694] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:27:54.110741 2026] [security2:error] [pid 1045527:tid 1045670] [client 172.202.44.182:19507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/asd.php"] [unique_id "amulujbFEG16qLV_6ZeKcgAAAA0"]
[Thu Jul 30 14:27:54.124908 2026] [proxy:error] [pid 1045527:tid 1045732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:54.125007 2026] [proxy_http:error] [pid 1045527:tid 1045732] [client 143.244.57.82:56190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:54.125753 2026] [proxy:error] [pid 1045527:tid 1045732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:54.125801 2026] [proxy_http:error] [pid 1045527:tid 1045732] [client 143.244.57.82:56190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:54.414392 2026] [proxy:error] [pid 1045527:tid 1045776] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:54.414475 2026] [proxy_http:error] [pid 1045527:tid 1045776] [client 143.244.57.82:33622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:54.415069 2026] [proxy:error] [pid 1045527:tid 1045776] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:54.415114 2026] [proxy_http:error] [pid 1045527:tid 1045776] [client 143.244.57.82:33622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:54.707002 2026] [security2:error] [pid 1045527:tid 1045754] [client 143.244.57.82:3467] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amulujbFEG16qLV_6ZeKgwAAAGE"]
[Thu Jul 30 14:27:54.921218 2026] [security2:error] [pid 1045527:tid 1045675] [client 74.248.33.8:38812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-content/themes/index.php"] [unique_id "amulujbFEG16qLV_6ZeKjQAAABI"]
[Thu Jul 30 14:27:54.992471 2026] [security2:error] [pid 1045527:tid 1045761] [client 143.244.57.82:56216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amulujbFEG16qLV_6ZeKkAAAAGg"]
[Thu Jul 30 14:27:55.272854 2026] [proxy:error] [pid 1045527:tid 1045705] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:55.272923 2026] [proxy_http:error] [pid 1045527:tid 1045705] [client 143.244.57.82:56224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:55.273577 2026] [proxy:error] [pid 1045527:tid 1045705] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:55.273632 2026] [proxy_http:error] [pid 1045527:tid 1045705] [client 143.244.57.82:56224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:55.326779 2026] [security2:error] [pid 1045527:tid 1045768] [client 172.202.44.182:19512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuluzbFEG16qLV_6ZeKmQAAAG8"]
[Thu Jul 30 14:27:55.552819 2026] [security2:error] [pid 1045527:tid 1045722] [client 143.244.57.82:56232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuluzbFEG16qLV_6ZeKnQAAAEE"]
[Thu Jul 30 14:27:55.658629 2026] [security2:error] [pid 1045527:tid 1045718] [client 109.235.50.35:58840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuluzbFEG16qLV_6ZeKoQAAAD0"]
[Thu Jul 30 14:27:55.658728 2026] [security2:error] [pid 1045527:tid 1045718] [client 109.235.50.35:58840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuluzbFEG16qLV_6ZeKoQAAAD0"]
[Thu Jul 30 14:27:55.843446 2026] [security2:error] [pid 1045527:tid 1045758] [client 143.244.57.82:56234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuluzbFEG16qLV_6ZeKqAAAAGU"]
[Thu Jul 30 14:27:55.994311 2026] [proxy:error] [pid 1045527:tid 1045738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:55.994372 2026] [proxy_http:error] [pid 1045527:tid 1045738] [client 118.194.249.72:37124] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:55.995124 2026] [proxy:error] [pid 1045527:tid 1045738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:27:55.995177 2026] [proxy_http:error] [pid 1045527:tid 1045738] [client 118.194.249.72:37124] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:27:56.105642 2026] [security2:error] [pid 1045527:tid 1045750] [client 74.248.33.8:41050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/wp-file.php"] [unique_id "amulvDbFEG16qLV_6ZeKrQAAAF0"]
[Thu Jul 30 14:27:56.137210 2026] [security2:error] [pid 1045527:tid 1045741] [client 143.244.57.82:56236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amulvDbFEG16qLV_6ZeKrgAAAFQ"]
[Thu Jul 30 14:27:56.273777 2026] [core:notice] [pid 1045527:tid 1045771] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:27:56.418173 2026] [security2:error] [pid 1045527:tid 1045753] [client 143.244.57.82:56244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amulvDbFEG16qLV_6ZeKtwAAAGA"]
[Thu Jul 30 14:27:56.594636 2026] [security2:error] [pid 1045527:tid 1045714] [client 172.202.44.182:11716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-the.php"] [unique_id "amulvDbFEG16qLV_6ZeKuwAAADk"]
[Thu Jul 30 14:27:56.596053 2026] [security2:error] [pid 1045527:tid 1045716] [client 20.199.183.73:38709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/aa.php"] [unique_id "amulvDbFEG16qLV_6ZeKvAAAADs"]
[Thu Jul 30 14:27:56.598446 2026] [security2:error] [pid 1045527:tid 1045763] [client 180.243.59.178:64079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulvDbFEG16qLV_6ZeKvQAAAGo"]
[Thu Jul 30 14:27:56.598547 2026] [security2:error] [pid 1045527:tid 1045763] [client 180.243.59.178:64079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulvDbFEG16qLV_6ZeKvQAAAGo"]
[Thu Jul 30 14:27:56.697243 2026] [security2:error] [pid 1045527:tid 1045737] [client 143.244.57.82:56248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amulvDbFEG16qLV_6ZeKvwAAAFA"]
[Thu Jul 30 14:27:56.989616 2026] [security2:error] [pid 1045527:tid 1045672] [client 143.244.57.82:36264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amulvDbFEG16qLV_6ZeKxwAAAA8"]
[Thu Jul 30 14:27:57.273071 2026] [security2:error] [pid 1045527:tid 1045690] [client 143.244.57.82:36278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amulvTbFEG16qLV_6ZeKzAAAACE"]
[Thu Jul 30 14:27:57.506848 2026] [security2:error] [pid 1045527:tid 1045693] [client 172.202.44.182:11753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/404.php"] [unique_id "amulvTbFEG16qLV_6ZeK1gAAACQ"]
[Thu Jul 30 14:27:57.557343 2026] [security2:error] [pid 1045527:tid 1045768] [client 143.244.57.82:36288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amulvTbFEG16qLV_6ZeK2QAAAG8"]
[Thu Jul 30 14:27:57.875512 2026] [security2:error] [pid 1045527:tid 1045777] [client 143.244.57.82:36294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amulvTbFEG16qLV_6ZeK3gAAAHg"]
[Thu Jul 30 14:27:58.155138 2026] [security2:error] [pid 1045527:tid 1045767] [client 143.244.57.82:36296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amulvjbFEG16qLV_6ZeK5QAAAG4"]
[Thu Jul 30 14:27:58.447928 2026] [security2:error] [pid 1045527:tid 1045673] [client 20.199.183.73:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/w.php"] [unique_id "amulvjbFEG16qLV_6ZeK6gAAABA"]
[Thu Jul 30 14:27:58.455508 2026] [security2:error] [pid 1045527:tid 1045751] [client 143.244.57.82:36304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amulvjbFEG16qLV_6ZeK6wAAAF4"]
[Thu Jul 30 14:27:58.728734 2026] [security2:error] [pid 1045527:tid 1045775] [client 143.244.57.82:36320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amulvjbFEG16qLV_6ZeK8wAAAHY"]
[Thu Jul 30 14:27:58.912225 2026] [security2:error] [pid 1045527:tid 1045667] [client 172.202.44.182:28814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amulvjbFEG16qLV_6ZeK9gAAAAo"]
[Thu Jul 30 14:27:59.011691 2026] [security2:error] [pid 1045527:tid 1045719] [client 143.244.57.82:36332] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amulvzbFEG16qLV_6ZeK-wAAAD4"]
[Thu Jul 30 14:27:59.301358 2026] [security2:error] [pid 1045527:tid 1045681] [client 143.244.57.82:36340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glb.nyx.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amulvzbFEG16qLV_6ZeLAQAAABg"]
[Thu Jul 30 14:27:59.415617 2026] [security2:error] [pid 1045527:tid 1045732] [client 74.248.33.8:34220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.33.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/sid3.php"] [unique_id "amulvzbFEG16qLV_6ZeLAgAAAEs"]
[Thu Jul 30 14:27:59.440769 2026] [security2:error] [pid 1045527:tid 1045734] [client 217.64.127.195:35430] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amulvzbFEG16qLV_6ZeK_wAAAE0"]
[Thu Jul 30 14:27:59.440859 2026] [security2:error] [pid 1045527:tid 1045734] [client 217.64.127.195:35430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amulvzbFEG16qLV_6ZeK_wAAAE0"]
[Thu Jul 30 14:27:59.637650 2026] [security2:error] [pid 1045527:tid 1045626] [remote 94.154.43.229:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lucky-strike-shop.com"] [uri "/.env"] [unique_id "amulvzbFEG16qLV_6ZeLDQAAaGI"]
[Thu Jul 30 14:28:00.127185 2026] [security2:error] [pid 1045527:tid 1045688] [client 172.202.44.182:11713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/init.php"] [unique_id "amulwDbFEG16qLV_6ZeLFAAAAB8"]
[Thu Jul 30 14:28:00.185417 2026] [security2:error] [pid 1045527:tid 1045730] [client 172.202.44.182:28855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/atomlib.php"] [unique_id "amulwDbFEG16qLV_6ZeLGAAAAEk"]
[Thu Jul 30 14:28:01.184088 2026] [autoindex:error] [pid 1045527:tid 1045662] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:28:01.345560 2026] [security2:error] [pid 1045527:tid 1045739] [client 20.199.183.73:38666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/admin.php"] [unique_id "amulwTbFEG16qLV_6ZeLMwAAAFI"]
[Thu Jul 30 14:28:01.515222 2026] [autoindex:error] [pid 1045527:tid 1045753] [client 172.202.44.182:19489] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:28:01.641009 2026] [security2:error] [pid 1045527:tid 1045677] [client 172.202.44.182:11642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/file5.php"] [unique_id "amulwTbFEG16qLV_6ZeLPAAAABQ"]
[Thu Jul 30 14:28:01.657221 2026] [security2:error] [pid 1045527:tid 1045751] [client 172.237.109.114:55994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amulwTbFEG16qLV_6ZeLLAAAAF4"]
[Thu Jul 30 14:28:01.801296 2026] [security2:error] [pid 1045527:tid 1045774] [client 172.202.44.182:19489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amulwTbFEG16qLV_6ZeLQQAAAHU"]
[Thu Jul 30 14:28:02.415697 2026] [security2:error] [pid 1045527:tid 1045732] [client 20.199.183.73:10984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amulwjbFEG16qLV_6ZeLTQAAAEs"]
[Thu Jul 30 14:28:02.785633 2026] [proxy:error] [pid 1045527:tid 1045741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:02.785709 2026] [proxy_http:error] [pid 1045527:tid 1045741] [client 118.194.249.72:46282] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:02.786465 2026] [proxy:error] [pid 1045527:tid 1045741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:02.786517 2026] [proxy_http:error] [pid 1045527:tid 1045741] [client 118.194.249.72:46282] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:03.184725 2026] [security2:error] [pid 1045527:tid 1045726] [client 177.6.106.101:54699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulwzbFEG16qLV_6ZeLXwAAAEU"]
[Thu Jul 30 14:28:03.184927 2026] [security2:error] [pid 1045527:tid 1045726] [client 177.6.106.101:54699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulwzbFEG16qLV_6ZeLXwAAAEU"]
[Thu Jul 30 14:28:03.412262 2026] [core:notice] [pid 1045527:tid 1045542] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:03.444140 2026] [core:notice] [pid 1045527:tid 1045707] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:03.845023 2026] [autoindex:error] [pid 1045527:tid 1045733] [client 172.202.44.182:13794] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:28:04.105103 2026] [autoindex:error] [pid 1045527:tid 1045720] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/blocks/block/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:28:04.448510 2026] [autoindex:error] [pid 1045527:tid 1045692] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:28:04.737792 2026] [security2:error] [pid 1045527:tid 1045773] [client 172.202.44.182:13794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/inputs.php"] [unique_id "amulxDbFEG16qLV_6ZeLhgAAAHQ"]
[Thu Jul 30 14:28:05.005143 2026] [security2:error] [pid 1045527:tid 1045689] [client 172.202.44.182:11622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/maint/index.php"] [unique_id "amulxTbFEG16qLV_6ZeLjwAAACA"]
[Thu Jul 30 14:28:05.039054 2026] [security2:error] [pid 1045527:tid 1045559] [remote 110.249.201.201:48602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/product/natural-american-spirit-6/"] [unique_id "amulxTbFEG16qLV_6ZeLkAAAHx8"]
[Thu Jul 30 14:28:05.269701 2026] [security2:error] [pid 1045527:tid 1045749] [client 20.199.183.73:33140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/m.php"] [unique_id "amulxTbFEG16qLV_6ZeLlwAAAFw"]
[Thu Jul 30 14:28:05.448811 2026] [security2:error] [pid 1045527:tid 1045700] [client 43.172.195.72:56670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/09/18/bershka-et-stradivarius-ouvrent-leur-boutique-en-ligne/"] [unique_id "amulxTbFEG16qLV_6ZeLngAAACs"]
[Thu Jul 30 14:28:05.922365 2026] [core:notice] [pid 1045527:tid 1045744] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:05.927393 2026] [security2:error] [pid 1045527:tid 1045744] [client 43.173.180.97:37410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/09/18/bershka-et-stradivarius-ouvrent-leur-boutique-en-ligne/"] [unique_id "amulxTbFEG16qLV_6ZeLqAAAAFc"], referer: https://carnetdeshopping.com/index.php/2011/09/18/bershka-et-stradivarius-ouvrent-leur-boutique-en-ligne/
[Thu Jul 30 14:28:06.024161 2026] [security2:error] [pid 1045527:tid 1045767] [client 172.202.44.182:11354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/shell.php"] [unique_id "amulxjbFEG16qLV_6ZeLqgAAAG4"]
[Thu Jul 30 14:28:06.255535 2026] [security2:error] [pid 1045527:tid 1045674] [client 20.199.183.73:15469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amulxjbFEG16qLV_6ZeLqQAAABE"]
[Thu Jul 30 14:28:06.865456 2026] [security2:error] [pid 1045527:tid 1045668] [client 109.235.50.35:55824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amulxjbFEG16qLV_6ZeLuwAAAAs"]
[Thu Jul 30 14:28:06.865614 2026] [security2:error] [pid 1045527:tid 1045668] [client 109.235.50.35:55824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amulxjbFEG16qLV_6ZeLuwAAAAs"]
[Thu Jul 30 14:28:07.139237 2026] [security2:error] [pid 1045527:tid 1045672] [client 180.243.59.178:64627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulxzbFEG16qLV_6ZeLwwAAAA8"]
[Thu Jul 30 14:28:07.139345 2026] [security2:error] [pid 1045527:tid 1045672] [client 180.243.59.178:64627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulxzbFEG16qLV_6ZeLwwAAAA8"]
[Thu Jul 30 14:28:07.369066 2026] [security2:error] [pid 1045527:tid 1045757] [client 172.202.44.182:34519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-content/index.php"] [unique_id "amulxzbFEG16qLV_6ZeLxwAAAGQ"]
[Thu Jul 30 14:28:07.536036 2026] [proxy:error] [pid 1045527:tid 1045699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:07.536119 2026] [proxy_http:error] [pid 1045527:tid 1045699] [client 118.194.249.72:46290] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:07.536682 2026] [proxy:error] [pid 1045527:tid 1045699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:07.536726 2026] [proxy_http:error] [pid 1045527:tid 1045699] [client 118.194.249.72:46290] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:08.517661 2026] [security2:error] [pid 1045527:tid 1045745] [client 154.57.218.68:44621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amulyDbFEG16qLV_6ZeL2wAAWDc"], referer: https://trello.com/
[Thu Jul 30 14:28:08.597992 2026] [security2:error] [pid 1045527:tid 1045718] [client 172.202.44.182:19804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/network/index.php"] [unique_id "amulyDbFEG16qLV_6ZeL4gAAAD0"]
[Thu Jul 30 14:28:09.059408 2026] [security2:error] [pid 1045527:tid 1045719] [client 172.202.44.182:11330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/f35.php"] [unique_id "amulyTbFEG16qLV_6ZeL7QAAAD4"]
[Thu Jul 30 14:28:09.279800 2026] [security2:error] [pid 1045527:tid 1045667] [client 4.184.60.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amulyTbFEG16qLV_6ZeL9AAAAAo"]
[Thu Jul 30 14:28:09.279943 2026] [security2:error] [pid 1045527:tid 1045667] [client 4.184.60.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amulyTbFEG16qLV_6ZeL9AAAAAo"]
[Thu Jul 30 14:28:09.404125 2026] [security2:error] [pid 1045527:tid 1045714] [client 89.238.167.134:58670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amulyTbFEG16qLV_6ZeL_QAAADk"]
[Thu Jul 30 14:28:09.404207 2026] [security2:error] [pid 1045527:tid 1045714] [client 89.238.167.134:58670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amulyTbFEG16qLV_6ZeL_QAAADk"]
[Thu Jul 30 14:28:09.733366 2026] [security2:error] [pid 1045527:tid 1045759] [client 66.249.65.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amulyTbFEG16qLV_6ZeL8AAAAGY"]
[Thu Jul 30 14:28:10.003737 2026] [security2:error] [pid 1045527:tid 1045677] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amulyTbFEG16qLV_6ZeMAAAAABQ"]
[Thu Jul 30 14:28:10.514749 2026] [core:error] [pid 1045527:tid 1045693] [client 74.7.175.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:28:10.514771 2026] [core:error] [pid 1045527:tid 1045693] [client 74.7.175.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:28:10.514878 2026] [security2:error] [pid 1045527:tid 1045693] [client 74.7.175.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.sharjahfurnituremoversandpackers.space"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amulyjbFEG16qLV_6ZeMFQAAACQ"]
[Thu Jul 30 14:28:10.516456 2026] [security2:error] [pid 1045527:tid 1045732] [client 74.7.175.162:48146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.sharjahfurnituremoversandpackers.space"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amulyjbFEG16qLV_6ZeMEwAASzY"]
[Thu Jul 30 14:28:11.373832 2026] [security2:error] [pid 1045527:tid 1045745] [client 172.202.44.182:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/new.php"] [unique_id "amulyzbFEG16qLV_6ZeMKAAAAFg"]
[Thu Jul 30 14:28:11.447766 2026] [security2:error] [pid 1045527:tid 1045692] [client 172.202.44.182:20287] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kool-shop.com"] [uri "/wp-content/1.php"] [unique_id "amulyzbFEG16qLV_6ZeMKQAAACM"]
[Thu Jul 30 14:28:11.447923 2026] [security2:error] [pid 1045527:tid 1045692] [client 172.202.44.182:20287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-content/1.php"] [unique_id "amulyzbFEG16qLV_6ZeMKQAAACM"]
[Thu Jul 30 14:28:11.797375 2026] [security2:error] [pid 1045527:tid 1045767] [client 20.199.183.73:10572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/classwithtostring.php"] [unique_id "amulyzbFEG16qLV_6ZeMMwAAAG4"]
[Thu Jul 30 14:28:12.209612 2026] [security2:error] [pid 1045527:tid 1045740] [client 31.0.32.45:4671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.32.0.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/xmlrpc.php"] [unique_id "amulzDbFEG16qLV_6ZeMOwAAAFM"]
[Thu Jul 30 14:28:12.209728 2026] [security2:error] [pid 1045527:tid 1045740] [client 31.0.32.45:4671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aded-rdc.org"] [uri "/xmlrpc.php"] [unique_id "amulzDbFEG16qLV_6ZeMOwAAAFM"]
[Thu Jul 30 14:28:12.335569 2026] [proxy:error] [pid 1045527:tid 1045769] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:12.335664 2026] [proxy_http:error] [pid 1045527:tid 1045769] [client 118.194.249.72:54642] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:12.336235 2026] [proxy:error] [pid 1045527:tid 1045769] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:12.336279 2026] [proxy_http:error] [pid 1045527:tid 1045769] [client 118.194.249.72:54642] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:13.497153 2026] [security2:error] [pid 1045527:tid 1045570] [remote 207.46.13.102:27156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/formation-sur-les-techniques-agricoles-en-faveur-des-jeunes-de-16-a-25-ans-a-kahororo-kawizi-et-rutemba/login.php"] [unique_id "amulzTbFEG16qLV_6ZeMVwAASio"]
[Thu Jul 30 14:28:13.783316 2026] [security2:error] [pid 1045527:tid 1045750] [client 177.6.106.101:55123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulzTbFEG16qLV_6ZeMXwAAAF0"]
[Thu Jul 30 14:28:13.783508 2026] [security2:error] [pid 1045527:tid 1045750] [client 177.6.106.101:55123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amulzTbFEG16qLV_6ZeMXwAAAF0"]
[Thu Jul 30 14:28:13.990582 2026] [security2:error] [pid 1045527:tid 1045676] [client 144.126.196.225:49724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "aetiiph.net"] [uri "/index.php"] [unique_id "amulzTbFEG16qLV_6ZeMYwAAABM"], referer: http://aetiiph.net/
[Thu Jul 30 14:28:14.430553 2026] [security2:error] [pid 1045527:tid 1045669] [client 172.202.44.182:19819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/plugin.php"] [unique_id "amulzjbFEG16qLV_6ZeMdAAAAAw"]
[Thu Jul 30 14:28:15.051280 2026] [security2:error] [pid 1045527:tid 1045663] [client 20.199.183.73:34108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/gmo.php"] [unique_id "amulzzbFEG16qLV_6ZeMfAAAAAY"]
[Thu Jul 30 14:28:15.682927 2026] [security2:error] [pid 1045527:tid 1045784] [client 172.202.44.182:20245] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kool-shop.com"] [uri "/1.php"] [unique_id "amulzzbFEG16qLV_6ZeMhwAAAH8"]
[Thu Jul 30 14:28:15.683078 2026] [security2:error] [pid 1045527:tid 1045784] [client 172.202.44.182:20245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/1.php"] [unique_id "amulzzbFEG16qLV_6ZeMhwAAAH8"]
[Thu Jul 30 14:28:17.108765 2026] [security2:error] [pid 1045527:tid 1045692] [client 5.255.231.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amul0DbFEG16qLV_6ZeMqAAAACM"]
[Thu Jul 30 14:28:17.222785 2026] [security2:error] [pid 1045527:tid 1045718] [client 180.243.59.178:65136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul0TbFEG16qLV_6ZeMrQAAAD0"]
[Thu Jul 30 14:28:17.222946 2026] [security2:error] [pid 1045527:tid 1045718] [client 180.243.59.178:65136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul0TbFEG16qLV_6ZeMrQAAAD0"]
[Thu Jul 30 14:28:17.550460 2026] [security2:error] [pid 1045527:tid 1045709] [client 172.202.44.182:20247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/gg.php"] [unique_id "amul0TbFEG16qLV_6ZeMtAAAADQ"]
[Thu Jul 30 14:28:18.224785 2026] [security2:error] [pid 1045527:tid 1045754] [client 20.199.183.73:30628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/wp-content/languages/index.php"] [unique_id "amul0jbFEG16qLV_6ZeMwgAAAGE"]
[Thu Jul 30 14:28:20.024476 2026] [security2:error] [pid 1045527:tid 1045746] [client 20.199.183.73:24152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/wp-the.php"] [unique_id "amul1DbFEG16qLV_6ZeM8wAAAFk"]
[Thu Jul 30 14:28:20.459655 2026] [security2:error] [pid 1045527:tid 1045771] [client 172.202.44.182:65233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/adminfuns.php"] [unique_id "amul1DbFEG16qLV_6ZeNAAAAAHI"]
[Thu Jul 30 14:28:20.896707 2026] [core:notice] [pid 1045527:tid 1045725] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:20.989603 2026] [autoindex:error] [pid 1045527:tid 1045783] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/images/crystal/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:28:21.396752 2026] [security2:error] [pid 1045527:tid 1045677] [client 172.202.44.182:20235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp.php"] [unique_id "amul1TbFEG16qLV_6ZeNEwAAABQ"]
[Thu Jul 30 14:28:21.530165 2026] [security2:error] [pid 1045527:tid 1045720] [client 20.199.183.73:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/404.php"] [unique_id "amul1TbFEG16qLV_6ZeNGgAAAD8"]
[Thu Jul 30 14:28:22.583221 2026] [security2:error] [pid 1045527:tid 1045775] [client 172.202.44.182:20411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amul1jbFEG16qLV_6ZeNNQAAAHY"]
[Thu Jul 30 14:28:23.408242 2026] [security2:error] [pid 1045527:tid 1045727] [client 172.202.44.182:65268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/fm.php"] [unique_id "amul1zbFEG16qLV_6ZeNRQAAAEY"]
[Thu Jul 30 14:28:23.530478 2026] [security2:error] [pid 1045527:tid 1045729] [client 172.202.44.182:39901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/file.php"] [unique_id "amul1zbFEG16qLV_6ZeNSQAAAEg"]
[Thu Jul 30 14:28:23.592060 2026] [security2:error] [pid 1045527:tid 1045663] [client 20.199.183.73:11046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/init.php"] [unique_id "amul1zbFEG16qLV_6ZeNTQAAAAY"]
[Thu Jul 30 14:28:24.070892 2026] [security2:error] [pid 1045527:tid 1045742] [client 74.7.241.171:52166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "arabian-tours.com"] [uri "/cgi-sys/404.html"] [unique_id "amul2DbFEG16qLV_6ZeNVAAAVXM"]
[Thu Jul 30 14:28:24.174858 2026] [security2:error] [pid 1045527:tid 1045764] [client 20.199.183.73:15477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/file5.php"] [unique_id "amul2DbFEG16qLV_6ZeNWwAAAGs"]
[Thu Jul 30 14:28:24.408159 2026] [security2:error] [pid 1045527:tid 1045773] [client 177.6.106.101:55861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul2DbFEG16qLV_6ZeNYgAAAHQ"]
[Thu Jul 30 14:28:24.408285 2026] [security2:error] [pid 1045527:tid 1045773] [client 177.6.106.101:55861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul2DbFEG16qLV_6ZeNYgAAAHQ"]
[Thu Jul 30 14:28:24.550340 2026] [security2:error] [pid 1045527:tid 1045720] [client 172.202.44.182:39918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/user/index.php"] [unique_id "amul2DbFEG16qLV_6ZeNZAAAAD8"]
[Thu Jul 30 14:28:25.922577 2026] [security2:error] [pid 1045527:tid 1045769] [client 4.184.60.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/admin.php"] [unique_id "amul2TbFEG16qLV_6ZeNhQAAAHA"]
[Thu Jul 30 14:28:25.922692 2026] [security2:error] [pid 1045527:tid 1045769] [client 4.184.60.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "emmanueljrodriguez.com"] [uri "/.well-known/admin.php"] [unique_id "amul2TbFEG16qLV_6ZeNhQAAAHA"]
[Thu Jul 30 14:28:26.282110 2026] [security2:error] [pid 1045527:tid 1045553] [remote 195.250.26.52:58416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.26.250.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-login.php"] [unique_id "amul2jbFEG16qLV_6ZeNkQAAYRk"]
[Thu Jul 30 14:28:26.296745 2026] [security2:error] [pid 1045527:tid 1045716] [client 35.204.109.104:4096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.ecvh.ae"] [uri "/"] [unique_id "amul2jbFEG16qLV_6ZeNkgAAADs"]
[Thu Jul 30 14:28:26.296827 2026] [security2:error] [pid 1045527:tid 1045716] [client 35.204.109.104:4096] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ecvh.ae"] [uri "/"] [unique_id "amul2jbFEG16qLV_6ZeNkgAAADs"]
[Thu Jul 30 14:28:27.732843 2026] [security2:error] [pid 1045527:tid 1045728] [client 172.237.109.114:22487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amul2zbFEG16qLV_6ZeNqgAAAEc"]
[Thu Jul 30 14:28:27.953811 2026] [security2:error] [pid 1045527:tid 1045739] [client 180.243.59.178:49313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul2zbFEG16qLV_6ZeNvgAAAFI"]
[Thu Jul 30 14:28:27.953934 2026] [security2:error] [pid 1045527:tid 1045739] [client 180.243.59.178:49313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul2zbFEG16qLV_6ZeNvgAAAFI"]
[Thu Jul 30 14:28:28.229341 2026] [security2:error] [pid 1045527:tid 1045753] [client 172.202.44.182:20403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amul3DbFEG16qLV_6ZeNyAAAAGA"]
[Thu Jul 30 14:28:28.425277 2026] [core:notice] [pid 1045527:tid 1045574] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:28.957624 2026] [security2:error] [pid 1045527:tid 1045750] [client 172.202.44.182:65246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/file.php"] [unique_id "amul3DbFEG16qLV_6ZeN3AAAAF0"]
[Thu Jul 30 14:28:29.359477 2026] [security2:error] [pid 1045527:tid 1045660] [client 172.202.44.182:20260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/index/function.php"] [unique_id "amul3TbFEG16qLV_6ZeN4wAAAAM"]
[Thu Jul 30 14:28:29.393676 2026] [security2:error] [pid 1045527:tid 1045578] [remote 216.73.217.142:63760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amul3TbFEG16qLV_6ZeN6AAAVDI"]
[Thu Jul 30 14:28:29.587007 2026] [core:notice] [pid 1045527:tid 1045587] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:29.991560 2026] [core:notice] [pid 1045527:tid 1045600] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:30.583471 2026] [core:notice] [pid 1045527:tid 1045682] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:30.604360 2026] [http2:info] [pid 17707:tid 17707] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 14:28:31.003323 2026] [security2:error] [pid 17707:tid 17709] [remote 57.141.0.6:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amul3rJM3qlhBlpwZyAKOgAAhwE"]
[Thu Jul 30 14:28:31.273358 2026] [fcgid:warn] [pid 17707:tid 17860] (70014)End of file found: [client 118.194.249.72:37712] mod_fcgid: can't get data from http client
[Thu Jul 30 14:28:31.485569 2026] [security2:error] [pid 17707:tid 17713] [remote 57.141.0.50:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amul37JM3qlhBlpwZyAKRgAAmgU"]
[Thu Jul 30 14:28:31.579569 2026] [security2:error] [pid 17707:tid 17848] [client 172.202.44.182:35778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/bolt.php"] [unique_id "amul37JM3qlhBlpwZyAKSgAAAJA"]
[Thu Jul 30 14:28:31.589659 2026] [security2:error] [pid 17707:tid 17877] [client 139.28.219.70:52882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amul37JM3qlhBlpwZyAKSwAAAK0"]
[Thu Jul 30 14:28:31.715549 2026] [autoindex:error] [pid 17707:tid 17884] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:28:31.842700 2026] [security2:error] [pid 17707:tid 17716] [remote 57.141.0.16:22440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amul37JM3qlhBlpwZyAKVAAArgg"]
[Thu Jul 30 14:28:31.866339 2026] [security2:error] [pid 17707:tid 17894] [client 139.28.219.70:52884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ecre.ae"] [uri "/xmlrpc.php"] [unique_id "amul37JM3qlhBlpwZyAKVQAAAL4"]
[Thu Jul 30 14:28:32.546526 2026] [security2:error] [pid 17707:tid 17922] [client 139.28.219.70:52894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amul4LJM3qlhBlpwZyAKYwAAANo"]
[Thu Jul 30 14:28:32.816423 2026] [security2:error] [pid 17707:tid 17931] [client 139.28.219.70:52904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amul4LJM3qlhBlpwZyAKZwAAAOM"]
[Thu Jul 30 14:28:32.963236 2026] [autoindex:error] [pid 17707:tid 17935] [client 172.202.44.182:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_dd429813/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:28:33.087398 2026] [security2:error] [pid 17707:tid 17943] [client 139.28.219.70:52912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amul4bJM3qlhBlpwZyAKbgAAAO8"]
[Thu Jul 30 14:28:33.213492 2026] [security2:error] [pid 17707:tid 17952] [client 172.202.44.182:19777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/aaa.php"] [unique_id "amul4bJM3qlhBlpwZyAKdQAAAPg"]
[Thu Jul 30 14:28:33.347254 2026] [security2:error] [pid 17707:tid 17956] [client 139.28.219.70:52916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amul4bJM3qlhBlpwZyAKdgAAAPw"]
[Thu Jul 30 14:28:33.602929 2026] [security2:error] [pid 17707:tid 17955] [client 20.226.5.174:34401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/011i.php"] [unique_id "amul4bJM3qlhBlpwZyAKfQAAAPs"]
[Thu Jul 30 14:28:33.606430 2026] [security2:error] [pid 17707:tid 17846] [client 139.28.219.70:52922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amul4bJM3qlhBlpwZyAKfgAAAI4"]
[Thu Jul 30 14:28:33.869799 2026] [security2:error] [pid 17707:tid 17856] [client 139.28.219.70:52932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amul4bJM3qlhBlpwZyAKhwAAAJg"]
[Thu Jul 30 14:28:34.139688 2026] [security2:error] [pid 17707:tid 17861] [client 139.28.219.70:52936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amul4rJM3qlhBlpwZyAKiwAAAJ0"]
[Thu Jul 30 14:28:34.418789 2026] [security2:error] [pid 17707:tid 17885] [client 139.28.219.70:52940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amul4rJM3qlhBlpwZyAKkgAAALU"]
[Thu Jul 30 14:28:34.685621 2026] [security2:error] [pid 17707:tid 17896] [client 139.28.219.70:52944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amul4rJM3qlhBlpwZyAKmQAAAMA"]
[Thu Jul 30 14:28:34.774165 2026] [security2:error] [pid 17707:tid 17877] [client 20.226.5.174:34388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/03a005685d.php"] [unique_id "amul4rJM3qlhBlpwZyAKngAAAK0"]
[Thu Jul 30 14:28:34.779627 2026] [proxy:error] [pid 17707:tid 17906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:34.779688 2026] [proxy_http:error] [pid 17707:tid 17906] [client 118.194.249.72:37714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:34.780353 2026] [proxy:error] [pid 17707:tid 17906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:34.780399 2026] [proxy_http:error] [pid 17707:tid 17906] [client 118.194.249.72:37714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:34.955753 2026] [security2:error] [pid 17707:tid 17912] [client 139.28.219.70:52946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amul4rJM3qlhBlpwZyAKpQAAANA"]
[Thu Jul 30 14:28:34.975776 2026] [security2:error] [pid 17707:tid 17866] [client 177.6.106.101:56453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul4rJM3qlhBlpwZyAKpgAAAKI"]
[Thu Jul 30 14:28:34.975990 2026] [security2:error] [pid 17707:tid 17866] [client 177.6.106.101:56453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul4rJM3qlhBlpwZyAKpgAAAKI"]
[Thu Jul 30 14:28:35.012260 2026] [security2:error] [pid 17707:tid 17892] [client 172.202.44.182:45340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/3.php"] [unique_id "amul47JM3qlhBlpwZyAKpwAAALw"]
[Thu Jul 30 14:28:35.231006 2026] [security2:error] [pid 17707:tid 17927] [client 139.28.219.70:52960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amul47JM3qlhBlpwZyAKrgAAAN8"]
[Thu Jul 30 14:28:35.503653 2026] [security2:error] [pid 17707:tid 17919] [client 139.28.219.70:52962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ecre.ae"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amul47JM3qlhBlpwZyAKtQAAANc"]
[Thu Jul 30 14:28:35.850246 2026] [security2:error] [pid 17707:tid 17940] [client 172.202.44.182:11788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/222.php"] [unique_id "amul47JM3qlhBlpwZyAKwAAAAOw"]
[Thu Jul 30 14:28:35.930041 2026] [security2:error] [pid 17707:tid 17934] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amul47JM3qlhBlpwZyAKswAAAOY"]
[Thu Jul 30 14:28:36.090399 2026] [security2:error] [pid 17707:tid 17950] [client 20.226.5.174:34383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/403.php"] [unique_id "amul5LJM3qlhBlpwZyAKxAAAAPY"]
[Thu Jul 30 14:28:36.121245 2026] [core:notice] [pid 17707:tid 17744] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:36.488788 2026] [security2:error] [pid 17707:tid 17897] [client 172.202.44.182:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kool-shop.com"] [uri "/getid3-core.php"] [unique_id "amul5LJM3qlhBlpwZyAK0AAAAME"]
[Thu Jul 30 14:28:38.052877 2026] [security2:error] [pid 17707:tid 17878] [client 129.227.44.35:18901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "143"] [id "900402"] [msg "Joomla administrator POST logging"] [data "303"] [hostname "bitcoinfungibletoken.com"] [uri "/administrator/index.php"] [unique_id "amul5bJM3qlhBlpwZyAK9QAAAK4"]
[Thu Jul 30 14:28:38.063262 2026] [core:notice] [pid 17707:tid 17759] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:38.178727 2026] [security2:error] [pid 17707:tid 17918] [client 172.202.44.182:45361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/images/admin.php"] [unique_id "amul5rJM3qlhBlpwZyAK_wAAANY"]
[Thu Jul 30 14:28:38.204881 2026] [security2:error] [pid 17707:tid 17890] [client 20.226.5.174:34376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/404.php"] [unique_id "amul5rJM3qlhBlpwZyALAAAAALo"]
[Thu Jul 30 14:28:38.279460 2026] [security2:error] [pid 17707:tid 17954] [client 180.243.59.178:49849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul5rJM3qlhBlpwZyALBAAAAPo"]
[Thu Jul 30 14:28:38.279612 2026] [security2:error] [pid 17707:tid 17954] [client 180.243.59.178:49849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul5rJM3qlhBlpwZyALBAAAAPo"]
[Thu Jul 30 14:28:38.818607 2026] [proxy:error] [pid 17707:tid 17850] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:38.818681 2026] [proxy_http:error] [pid 17707:tid 17850] [client 118.194.249.72:37730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:38.819245 2026] [proxy:error] [pid 17707:tid 17850] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:38.819291 2026] [proxy_http:error] [pid 17707:tid 17850] [client 118.194.249.72:37730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:39.301221 2026] [security2:error] [pid 17707:tid 17860] [client 20.226.5.174:34398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aa.php"] [unique_id "amul57JM3qlhBlpwZyALGAAAAJw"]
[Thu Jul 30 14:28:39.809559 2026] [core:notice] [pid 17707:tid 17770] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:28:40.193926 2026] [security2:error] [pid 17707:tid 17955] [client 172.202.44.182:65335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amul6LJM3qlhBlpwZyALMwAAAPs"]
[Thu Jul 30 14:28:41.069181 2026] [security2:error] [pid 17707:tid 17939] [client 20.226.5.174:34370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/aafewc0k.php"] [unique_id "amul6bJM3qlhBlpwZyALRgAAAOs"]
[Thu Jul 30 14:28:41.389519 2026] [security2:error] [pid 17707:tid 17781] [remote 74.7.227.39:60634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amul6bJM3qlhBlpwZyALSgAAi0k"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/includes/pa-display-conditions/conditions
[Thu Jul 30 14:28:42.237173 2026] [security2:error] [pid 17707:tid 17789] [remote 57.141.0.20:52084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amul6rJM3qlhBlpwZyALYQAAnlE"]
[Thu Jul 30 14:28:42.319741 2026] [security2:error] [pid 17707:tid 17922] [client 20.226.5.174:34381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/abcd.php"] [unique_id "amul6rJM3qlhBlpwZyALYgAAANo"]
[Thu Jul 30 14:28:42.813833 2026] [proxy:error] [pid 17707:tid 17888] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:42.813904 2026] [proxy_http:error] [pid 17707:tid 17888] [client 118.194.249.72:50330] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:42.814499 2026] [proxy:error] [pid 17707:tid 17888] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:42.814544 2026] [proxy_http:error] [pid 17707:tid 17888] [client 118.194.249.72:50330] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:43.353775 2026] [security2:error] [pid 17707:tid 17902] [client 20.226.5.174:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/about.php"] [unique_id "amul67JM3qlhBlpwZyALeQAAAMY"]
[Thu Jul 30 14:28:46.266561 2026] [security2:error] [pid 17707:tid 17842] [client 20.226.5.174:34371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/admin.php"] [unique_id "amul7rJM3qlhBlpwZyALtwAAAIo"]
[Thu Jul 30 14:28:46.586404 2026] [fcgid:warn] [pid 17707:tid 17919] (70014)End of file found: [client 165.154.138.79:36760] mod_fcgid: can't get data from http client
[Thu Jul 30 14:28:46.602592 2026] [proxy:error] [pid 17707:tid 17923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:46.602673 2026] [proxy_http:error] [pid 17707:tid 17923] [client 118.194.249.72:50338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:46.603247 2026] [proxy:error] [pid 17707:tid 17923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:46.603294 2026] [proxy_http:error] [pid 17707:tid 17923] [client 118.194.249.72:50338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:47.128877 2026] [security2:error] [pid 17707:tid 17849] [client 177.6.106.101:57131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul77JM3qlhBlpwZyALywAAAJE"]
[Thu Jul 30 14:28:47.129098 2026] [security2:error] [pid 17707:tid 17849] [client 177.6.106.101:57131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul77JM3qlhBlpwZyALywAAAJE"]
[Thu Jul 30 14:28:47.266390 2026] [security2:error] [pid 17707:tid 17870] [client 172.202.44.182:11784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/admin.php"] [unique_id "amul77JM3qlhBlpwZyALzwAAAKY"]
[Thu Jul 30 14:28:47.326495 2026] [security2:error] [pid 17707:tid 17958] [client 20.226.5.174:51224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/smm.php"] [unique_id "amul77JM3qlhBlpwZyAL0wAAAP4"]
[Thu Jul 30 14:28:47.484845 2026] [security2:error] [pid 17707:tid 17893] [client 20.226.5.174:34393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/adminfuns.php"] [unique_id "amul77JM3qlhBlpwZyAL2gAAAL0"]
[Thu Jul 30 14:28:48.379108 2026] [security2:error] [pid 17707:tid 17948] [client 20.226.5.174:51227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/snd.php"] [unique_id "amul8LJM3qlhBlpwZyAL6wAAAPQ"]
[Thu Jul 30 14:28:48.566664 2026] [security2:error] [pid 17707:tid 17885] [client 20.226.5.174:34420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/albin.php"] [unique_id "amul8LJM3qlhBlpwZyAL9AAAALU"]
[Thu Jul 30 14:28:48.732494 2026] [proxy:error] [pid 17707:tid 17903] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:48.732579 2026] [proxy_http:error] [pid 17707:tid 17903] [client 143.244.57.82:59606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:48.733315 2026] [proxy:error] [pid 17707:tid 17903] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:48.733365 2026] [proxy_http:error] [pid 17707:tid 17903] [client 143.244.57.82:59606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:49.016838 2026] [proxy:error] [pid 17707:tid 17910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:49.016936 2026] [proxy_http:error] [pid 17707:tid 17910] [client 143.244.57.82:59618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:49.017582 2026] [proxy:error] [pid 17707:tid 17910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:49.017639 2026] [proxy_http:error] [pid 17707:tid 17910] [client 143.244.57.82:59618] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:49.060545 2026] [security2:error] [pid 17707:tid 17927] [client 172.202.44.182:12225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-configs.php"] [unique_id "amul8bJM3qlhBlpwZyAMAAAAAN8"]
[Thu Jul 30 14:28:49.166911 2026] [security2:error] [pid 17707:tid 17877] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amul8LJM3qlhBlpwZyAL8wAAAK0"]
[Thu Jul 30 14:28:49.298530 2026] [security2:error] [pid 17707:tid 17919] [client 143.244.57.82:43267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amul8bJM3qlhBlpwZyAMAwAAANc"]
[Thu Jul 30 14:28:49.320611 2026] [security2:error] [pid 17707:tid 17926] [client 180.243.59.178:50424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul8bJM3qlhBlpwZyAMBAAAAN4"]
[Thu Jul 30 14:28:49.320971 2026] [security2:error] [pid 17707:tid 17926] [client 180.243.59.178:50424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul8bJM3qlhBlpwZyAMBAAAAN4"]
[Thu Jul 30 14:28:49.490310 2026] [security2:error] [pid 17707:tid 17848] [client 20.226.5.174:51203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/sol.php"] [unique_id "amul8bJM3qlhBlpwZyAMDgAAAJA"]
[Thu Jul 30 14:28:49.578150 2026] [security2:error] [pid 17707:tid 17963] [client 143.244.57.82:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amul8bJM3qlhBlpwZyAMEgAAAQM"]
[Thu Jul 30 14:28:49.874291 2026] [proxy:error] [pid 17707:tid 17913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:49.874363 2026] [proxy_http:error] [pid 17707:tid 17913] [client 143.244.57.82:59650] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:49.874945 2026] [proxy:error] [pid 17707:tid 17913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:28:49.875004 2026] [proxy_http:error] [pid 17707:tid 17913] [client 143.244.57.82:59650] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:28:50.157599 2026] [security2:error] [pid 17707:tid 17933] [client 143.244.57.82:59660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amul8rJM3qlhBlpwZyAMIQAAAOU"]
[Thu Jul 30 14:28:50.433710 2026] [security2:error] [pid 17707:tid 17861] [client 143.244.57.82:59676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amul8rJM3qlhBlpwZyAMJwAAAJ0"]
[Thu Jul 30 14:28:50.566544 2026] [security2:error] [pid 17707:tid 17839] [client 20.226.5.174:49091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/soumen.php"] [unique_id "amul8rJM3qlhBlpwZyAMLAAAAIc"]
[Thu Jul 30 14:28:50.747004 2026] [security2:error] [pid 17707:tid 17851] [client 143.244.57.82:59692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amul8rJM3qlhBlpwZyAMMQAAAJM"]
[Thu Jul 30 14:28:50.954932 2026] [security2:error] [pid 17707:tid 17938] [client 20.226.5.174:34385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/amfsqvgv.php"] [unique_id "amul8rJM3qlhBlpwZyAMOwAAAOo"]
[Thu Jul 30 14:28:51.032397 2026] [security2:error] [pid 17707:tid 17876] [client 143.244.57.82:59702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amul87JM3qlhBlpwZyAMPAAAAKw"]
[Thu Jul 30 14:28:51.186342 2026] [security2:error] [pid 17707:tid 17931] [client 172.202.44.182:12224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/php.php"] [unique_id "amul87JM3qlhBlpwZyAMQAAAAOM"]
[Thu Jul 30 14:28:51.317310 2026] [security2:error] [pid 17707:tid 17842] [client 143.244.57.82:59708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amul87JM3qlhBlpwZyAMRAAAAIo"]
[Thu Jul 30 14:28:51.595255 2026] [security2:error] [pid 17707:tid 17936] [client 143.244.57.82:59724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amul87JM3qlhBlpwZyAMTAAAAOg"]
[Thu Jul 30 14:28:51.620821 2026] [security2:error] [pid 17707:tid 17921] [client 20.226.5.174:49112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/source.php"] [unique_id "amul87JM3qlhBlpwZyAMUgAAANk"]
[Thu Jul 30 14:28:51.880067 2026] [security2:error] [pid 17707:tid 17890] [client 143.244.57.82:59734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amul87JM3qlhBlpwZyAMUwAAALo"]
[Thu Jul 30 14:28:52.152722 2026] [security2:error] [pid 17707:tid 17912] [client 143.244.57.82:59736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amul9LJM3qlhBlpwZyAMXgAAANA"]
[Thu Jul 30 14:28:52.448782 2026] [security2:error] [pid 17707:tid 17879] [client 143.244.57.82:59752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amul9LJM3qlhBlpwZyAMYgAAAK8"]
[Thu Jul 30 14:28:52.686636 2026] [security2:error] [pid 17707:tid 17844] [client 20.226.5.174:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/sow.php"] [unique_id "amul9LJM3qlhBlpwZyAMagAAAIw"]
[Thu Jul 30 14:28:52.727131 2026] [security2:error] [pid 17707:tid 17869] [client 143.244.57.82:59762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amul9LJM3qlhBlpwZyAMawAAAKU"]
[Thu Jul 30 14:28:52.777234 2026] [security2:error] [pid 17707:tid 17939] [client 172.202.44.182:65327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/index.php"] [unique_id "amul9LJM3qlhBlpwZyAMbAAAAOs"]
[Thu Jul 30 14:28:52.798596 2026] [security2:error] [pid 17707:tid 17843] [client 20.226.5.174:34392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/ant.php"] [unique_id "amul9LJM3qlhBlpwZyAMbQAAAIs"]
[Thu Jul 30 14:28:53.011878 2026] [security2:error] [pid 17707:tid 17736] [remote 74.7.243.224:43098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amul9bJM3qlhBlpwZyAMcgAA9Rw"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:28:53.019447 2026] [security2:error] [pid 17707:tid 17948] [client 143.244.57.82:59764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amul9bJM3qlhBlpwZyAMcwAAAPQ"]
[Thu Jul 30 14:28:53.316411 2026] [security2:error] [pid 17707:tid 17866] [client 143.244.57.82:59772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amul9bJM3qlhBlpwZyAMfQAAAKI"]
[Thu Jul 30 14:28:53.590002 2026] [security2:error] [pid 17707:tid 17927] [client 143.244.57.82:59786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amul9bJM3qlhBlpwZyAMgQAAAN8"]
[Thu Jul 30 14:28:53.820259 2026] [security2:error] [pid 17707:tid 17902] [client 20.226.5.174:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/spam.php"] [unique_id "amul9bJM3qlhBlpwZyAMiQAAAMY"]
[Thu Jul 30 14:28:53.877815 2026] [security2:error] [pid 17707:tid 17921] [client 143.244.57.82:59792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amul9bJM3qlhBlpwZyAMigAAANk"]
[Thu Jul 30 14:28:54.143618 2026] [security2:error] [pid 17707:tid 17894] [client 129.227.44.35:52905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "143"] [id "900402"] [msg "Joomla administrator POST logging"] [data "303"] [hostname "bitcoinfungibletoken.com"] [uri "/administrator/index.php"] [unique_id "amul9bJM3qlhBlpwZyAMjAAAAL4"]
[Thu Jul 30 14:28:54.165526 2026] [security2:error] [pid 17707:tid 17745] [remote 187.127.191.163:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.191.127.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caflchimneysweeper.com"] [uri "/wp/xmlrpc.php"] [unique_id "amul9bJM3qlhBlpwZyAMiwAA-SU"]
[Thu Jul 30 14:28:54.165742 2026] [security2:error] [pid 17707:tid 17953] [client 187.127.191.163:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "caflchimneysweeper.com"] [uri "/wp/xmlrpc.php"] [unique_id "amul9bJM3qlhBlpwZyAMiwAA-SU"]
[Thu Jul 30 14:28:54.383108 2026] [security2:error] [pid 17707:tid 17954] [client 85.208.96.195:13132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/30/velorio-de-pele-tera-24-horas-de-duracao-e-sera-aberto-ao-publico-na-vila-belmiro/"] [unique_id "amul9rJM3qlhBlpwZyAMmwAAAPo"]
[Thu Jul 30 14:28:54.383299 2026] [security2:error] [pid 17707:tid 17954] [client 85.208.96.195:13132] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/30/velorio-de-pele-tera-24-horas-de-duracao-e-sera-aberto-ao-publico-na-vila-belmiro/"] [unique_id "amul9rJM3qlhBlpwZyAMmwAAAPo"]
[Thu Jul 30 14:28:54.679793 2026] [security2:error] [pid 17707:tid 17842] [client 20.226.5.174:34402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/appreciators.php"] [unique_id "amul9rJM3qlhBlpwZyAMpAAAAIo"]
[Thu Jul 30 14:28:54.946677 2026] [security2:error] [pid 17707:tid 17872] [client 20.226.5.174:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/special.php"] [unique_id "amul9rJM3qlhBlpwZyAMrgAAAKg"]
[Thu Jul 30 14:28:55.136918 2026] [security2:error] [pid 17707:tid 17873] [client 172.202.44.182:12276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/a.php"] [unique_id "amul97JM3qlhBlpwZyAMtAAAAKk"]
[Thu Jul 30 14:28:55.732002 2026] [security2:error] [pid 17707:tid 17911] [client 114.119.153.25:52353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amul97JM3qlhBlpwZyAMwAAAAM8"], referer: https://womenclothingbox.com/robots.txt
[Thu Jul 30 14:28:55.975443 2026] [security2:error] [pid 17707:tid 17858] [client 20.226.5.174:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/specials.php"] [unique_id "amul97JM3qlhBlpwZyAMywAAAJo"]
[Thu Jul 30 14:28:56.080513 2026] [security2:error] [pid 17707:tid 17855] [client 177.6.106.101:54134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul-LJM3qlhBlpwZyAMzwAAAJc"]
[Thu Jul 30 14:28:56.080649 2026] [security2:error] [pid 17707:tid 17855] [client 177.6.106.101:54134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul-LJM3qlhBlpwZyAMzwAAAJc"]
[Thu Jul 30 14:28:56.891029 2026] [core:error] [pid 17707:tid 17893] [client 193.47.62.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:28:56.891050 2026] [core:error] [pid 17707:tid 17893] [client 193.47.62.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:28:57.144339 2026] [security2:error] [pid 17707:tid 17859] [client 20.226.5.174:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/sql.php"] [unique_id "amul-bJM3qlhBlpwZyAM5wAAAJs"]
[Thu Jul 30 14:28:57.475103 2026] [security2:error] [pid 17707:tid 17840] [client 20.226.5.174:34409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/archive.php"] [unique_id "amul-bJM3qlhBlpwZyAM8QAAAIg"]
[Thu Jul 30 14:28:57.592464 2026] [security2:error] [pid 17707:tid 17845] [client 172.237.109.114:10984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amul-LJM3qlhBlpwZyAM5QAAAI0"], referer: http://alseermarine.com:80/index.html
[Thu Jul 30 14:28:57.943165 2026] [security2:error] [pid 17707:tid 17786] [remote 40.77.167.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/32"] [unique_id "amul-bJM3qlhBlpwZyAM_wAA604"]
[Thu Jul 30 14:28:58.233566 2026] [security2:error] [pid 17707:tid 17885] [client 20.226.5.174:49104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/src/Core/Curve25519-items.php"] [unique_id "amul-rJM3qlhBlpwZyANBwAAALU"]
[Thu Jul 30 14:28:58.424857 2026] [security2:error] [pid 17707:tid 17850] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amul-bJM3qlhBlpwZyAM-AAAkkw"]
[Thu Jul 30 14:28:58.570370 2026] [security2:error] [pid 17707:tid 17884] [client 103.231.91.59:39154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amul-rJM3qlhBlpwZyANDwAAALQ"]
[Thu Jul 30 14:28:58.570472 2026] [security2:error] [pid 17707:tid 17884] [client 103.231.91.59:39154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amul-rJM3qlhBlpwZyANDwAAALQ"]
[Thu Jul 30 14:28:58.824306 2026] [security2:error] [pid 17707:tid 17912] [client 172.202.44.182:12248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/Text/about.php"] [unique_id "amul-rJM3qlhBlpwZyANFwAAANA"]
[Thu Jul 30 14:28:58.864394 2026] [security2:error] [pid 17707:tid 17796] [remote 40.77.167.30:23384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/144143078451/vloloteerf.php"] [unique_id "amul-rJM3qlhBlpwZyANGQAA41g"]
[Thu Jul 30 14:28:59.456820 2026] [security2:error] [pid 17707:tid 17821] [remote 216.73.217.142:30366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amul-7JM3qlhBlpwZyANOgAA7HE"]
[Thu Jul 30 14:28:59.503183 2026] [security2:error] [pid 17707:tid 17962] [client 20.226.5.174:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/src/Core/Curve25519/Ge/wp_blog.php"] [unique_id "amul-7JM3qlhBlpwZyANPQAAAQI"]
[Thu Jul 30 14:28:59.553219 2026] [security2:error] [pid 17707:tid 17847] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amul-rJM3qlhBlpwZyANGwAAj1k"]
[Thu Jul 30 14:28:59.811841 2026] [security2:error] [pid 17707:tid 17851] [client 180.243.59.178:50961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul-7JM3qlhBlpwZyANSQAAAJM"]
[Thu Jul 30 14:28:59.812011 2026] [security2:error] [pid 17707:tid 17851] [client 180.243.59.178:50961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amul-7JM3qlhBlpwZyANSQAAAJM"]
[Thu Jul 30 14:28:59.957222 2026] [security2:error] [pid 17707:tid 17860] [client 20.226.5.174:34403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/as.php"] [unique_id "amul-7JM3qlhBlpwZyANTgAAAJw"]
[Thu Jul 30 14:29:00.649613 2026] [security2:error] [pid 17707:tid 17928] [client 20.226.5.174:49132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/src/Core32/Curve25519/Ge/Core32.php"] [unique_id "amul_LJM3qlhBlpwZyANdAAAAOA"]
[Thu Jul 30 14:29:00.692843 2026] [security2:error] [pid 17707:tid 17733] [remote 57.141.18.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amul_LJM3qlhBlpwZyANdQAA0hk"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon%2Csilicon%2Clinen%2Caluminum%2Ccotton%2Csteel%2Cwood%2Clycra%2Cplastic&min_price=300&orderby=popularity&rating=5&status=sale&unfilter=1
[Thu Jul 30 14:29:01.010138 2026] [security2:error] [pid 17707:tid 17736] [remote 57.141.18.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amul_LJM3qlhBlpwZyANfAAA_xw"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=vitra&filter_materials=carbon%2Csilicon%2Clinen%2Caluminum%2Ccotton%2Csteel%2Cwood%2Clycra%2Cplastic&min_price=300&orderby=popularity&rating=5&status=sale&unfilter=1
[Thu Jul 30 14:29:01.306926 2026] [security2:error] [pid 17707:tid 17912] [client 20.226.5.174:34382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/atomlib.php"] [unique_id "amul_bJM3qlhBlpwZyANqAAAANA"]
[Thu Jul 30 14:29:01.805719 2026] [security2:error] [pid 17707:tid 17847] [client 20.226.5.174:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/src/Exception/Http/about.php"] [unique_id "amul_bJM3qlhBlpwZyANvAAAAI8"]
[Thu Jul 30 14:29:01.827567 2026] [security2:error] [pid 17707:tid 17909] [client 74.7.230.61:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "inmobiliariadia.com"] [uri "/cgi-sys/404.html"] [unique_id "amul_bJM3qlhBlpwZyANvwAAAM0"]
[Thu Jul 30 14:29:01.828256 2026] [security2:error] [pid 17707:tid 17947] [client 74.7.230.61:49794] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "inmobiliariadia.com"] [uri "/robots.txt"] [unique_id "amul_bJM3qlhBlpwZyANvQAA80o"]
[Thu Jul 30 14:29:02.460051 2026] [security2:error] [pid 17707:tid 17838] [client 66.249.66.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.allmontecristi.com"] [uri "/index.php"] [unique_id "amul_bJM3qlhBlpwZyANswAAhkg"]
[Thu Jul 30 14:29:02.887605 2026] [security2:error] [pid 17707:tid 17895] [client 109.235.50.35:52406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amul_rJM3qlhBlpwZyAN8AAAAL8"]
[Thu Jul 30 14:29:02.887733 2026] [security2:error] [pid 17707:tid 17895] [client 109.235.50.35:52406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amul_rJM3qlhBlpwZyAN8AAAAL8"]
[Thu Jul 30 14:29:03.093260 2026] [security2:error] [pid 17707:tid 17957] [client 20.226.5.174:51219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/src/Proxy.php"] [unique_id "amul_7JM3qlhBlpwZyAN9gAAAP0"]
[Thu Jul 30 14:29:04.070298 2026] [security2:error] [pid 17707:tid 17842] [client 66.249.65.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amul_7JM3qlhBlpwZyAOBAAAAIo"]
[Thu Jul 30 14:29:04.186431 2026] [security2:error] [pid 17707:tid 17830] [remote 52.167.144.191:47583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/14335047/Policyf.php"] [unique_id "amumALJM3qlhBlpwZyAOFwAA6no"]
[Thu Jul 30 14:29:04.238450 2026] [security2:error] [pid 17707:tid 17837] [client 20.226.5.174:51215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/src/alfa-rex.php"] [unique_id "amumALJM3qlhBlpwZyAOGAAAAIU"]
[Thu Jul 30 14:29:04.617261 2026] [security2:error] [pid 17707:tid 17932] [client 172.202.44.182:37799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin.php"] [unique_id "amumALJM3qlhBlpwZyAOIAAAAOQ"]
[Thu Jul 30 14:29:04.980497 2026] [core:notice] [pid 17707:tid 17909] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:05.103597 2026] [security2:error] [pid 17707:tid 17713] [remote 216.73.217.142:41670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amumAbJM3qlhBlpwZyAOLQAA4AU"]
[Thu Jul 30 14:29:05.248532 2026] [security2:error] [pid 17707:tid 17711] [remote 173.231.241.109:36336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.241.231.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amumAbJM3qlhBlpwZyAOLwAAlwM"]
[Thu Jul 30 14:29:05.248724 2026] [security2:error] [pid 17707:tid 17855] [client 173.231.241.109:36336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amumAbJM3qlhBlpwZyAOLwAAlwM"]
[Thu Jul 30 14:29:05.381718 2026] [security2:error] [pid 17707:tid 17847] [client 66.249.66.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumALJM3qlhBlpwZyAOJAAAjwA"]
[Thu Jul 30 14:29:05.449553 2026] [security2:error] [pid 17707:tid 17848] [client 20.226.5.174:51208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/src/index.php"] [unique_id "amumAbJM3qlhBlpwZyAONgAAAJA"]
[Thu Jul 30 14:29:05.599180 2026] [core:notice] [pid 17707:tid 17715] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:05.707798 2026] [security2:error] [pid 17707:tid 17956] [client 20.226.5.174:34372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/autoload_classmap.php"] [unique_id "amumAbJM3qlhBlpwZyAOPAAAAPw"]
[Thu Jul 30 14:29:06.020055 2026] [security2:error] [pid 17707:tid 17859] [client 95.142.47.113:61103] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "95.142.47.113" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amumArJM3qlhBlpwZyAORgAAAJs"], referer: https://deltaedu.net/2016/11/04/university-scholarship-2017/#comment-25
[Thu Jul 30 14:29:06.020220 2026] [security2:error] [pid 17707:tid 17859] [client 95.142.47.113:61103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amumArJM3qlhBlpwZyAORgAAAJs"], referer: https://deltaedu.net/2016/11/04/university-scholarship-2017/#comment-25
[Thu Jul 30 14:29:06.594058 2026] [security2:error] [pid 17707:tid 17854] [client 20.226.5.174:51218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/srx.php"] [unique_id "amumArJM3qlhBlpwZyAObwAAAJY"]
[Thu Jul 30 14:29:06.771308 2026] [security2:error] [pid 17707:tid 17874] [client 20.226.5.174:34377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/bb.php"] [unique_id "amumArJM3qlhBlpwZyAOcwAAAKo"]
[Thu Jul 30 14:29:06.790825 2026] [security2:error] [pid 17707:tid 17839] [client 177.6.106.101:54566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumArJM3qlhBlpwZyAOdAAAAIc"]
[Thu Jul 30 14:29:06.790937 2026] [security2:error] [pid 17707:tid 17839] [client 177.6.106.101:54566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumArJM3qlhBlpwZyAOdAAAAIc"]
[Thu Jul 30 14:29:07.050740 2026] [security2:error] [pid 17707:tid 17899] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumArJM3qlhBlpwZyAOfQAAAMM"]
[Thu Jul 30 14:29:07.383341 2026] [security2:error] [pid 17707:tid 17934] [client 172.202.44.182:37807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/size.php"] [unique_id "amumA7JM3qlhBlpwZyAOiAAAAOY"]
[Thu Jul 30 14:29:07.434063 2026] [security2:error] [pid 17707:tid 17949] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumArJM3qlhBlpwZyAOfgAA9Tc"]
[Thu Jul 30 14:29:07.798449 2026] [security2:error] [pid 17707:tid 17890] [client 20.226.5.174:51202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/ss.php"] [unique_id "amumA7JM3qlhBlpwZyAOkgAAALo"]
[Thu Jul 30 14:29:07.854431 2026] [security2:error] [pid 17707:tid 17770] [remote 57.141.0.4:29010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amumA7JM3qlhBlpwZyAOlQAAkT4"]
[Thu Jul 30 14:29:07.907493 2026] [security2:error] [pid 17707:tid 17765] [remote 47.128.96.165:44060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/agro_sintesa/article/view/1923"] [unique_id "amumA7JM3qlhBlpwZyAOiQAA-jk"]
[Thu Jul 30 14:29:07.979118 2026] [core:notice] [pid 17707:tid 17764] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:07.983773 2026] [security2:error] [pid 17707:tid 17857] [client 47.128.96.165:44060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agro_sintesa/article/view/1923"] [unique_id "amumA7JM3qlhBlpwZyAOmAAAmTg"], referer: https://ejournalugj.com/index.php/agro_sintesa/article/view/1923
[Thu Jul 30 14:29:08.145426 2026] [core:notice] [pid 17707:tid 17774] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:08.180583 2026] [security2:error] [pid 17707:tid 17844] [client 94.204.163.226:37392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amumBLJM3qlhBlpwZyAOmQAAjDs"], referer: https://skcarrental.ae/car-type/monthly-car/?gad_source=1&gad_campaignid=23407362884&gclid=CjwKCAjw7KvTBhA6EiwAWnutYXJrOS5wbTPlOqfX8N7M_WRMOZ5dV0ZWFb450pGH4eSqjU3rkqOhDRoCW60QAvD_BwE
[Thu Jul 30 14:29:08.232040 2026] [core:notice] [pid 17707:tid 17751] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:08.296153 2026] [core:notice] [pid 17707:tid 17773] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:08.412702 2026] [security2:error] [pid 17707:tid 17912] [client 20.226.5.174:34386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/bnm.php"] [unique_id "amumBLJM3qlhBlpwZyAOrgAAANA"]
[Thu Jul 30 14:29:08.422564 2026] [security2:error] [pid 17707:tid 17925] [client 52.167.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amumArJM3qlhBlpwZyAObgAAAN0"]
[Thu Jul 30 14:29:08.832065 2026] [security2:error] [pid 17707:tid 17838] [client 20.226.5.174:51220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/ssa.php"] [unique_id "amumBLJM3qlhBlpwZyAOuAAAAIY"]
[Thu Jul 30 14:29:08.929890 2026] [security2:error] [pid 17707:tid 17952] [client 52.167.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amumBLJM3qlhBlpwZyAOsQAAAPg"]
[Thu Jul 30 14:29:09.021032 2026] [security2:error] [pid 17707:tid 17948] [client 172.202.44.182:36189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/wp-class.php"] [unique_id "amumBbJM3qlhBlpwZyAOwgAAAPQ"]
[Thu Jul 30 14:29:09.585722 2026] [security2:error] [pid 17707:tid 17935] [client 52.238.199.152:38015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/gmo.php"] [unique_id "amumBbJM3qlhBlpwZyAO0AAAAOc"]
[Thu Jul 30 14:29:09.772339 2026] [security2:error] [pid 17707:tid 17957] [client 20.226.5.174:34384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/bootstrap.php"] [unique_id "amumBbJM3qlhBlpwZyAO0gAAAP0"]
[Thu Jul 30 14:29:10.047174 2026] [security2:error] [pid 17707:tid 17901] [client 20.226.5.174:51209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/ssk.php"] [unique_id "amumBrJM3qlhBlpwZyAO2wAAAMU"]
[Thu Jul 30 14:29:10.207304 2026] [security2:error] [pid 17707:tid 17938] [client 180.243.59.178:51493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumBrJM3qlhBlpwZyAO3gAAAOo"]
[Thu Jul 30 14:29:10.207462 2026] [security2:error] [pid 17707:tid 17938] [client 180.243.59.178:51493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumBrJM3qlhBlpwZyAO3gAAAOo"]
[Thu Jul 30 14:29:10.537571 2026] [security2:error] [pid 17707:tid 17939] [client 52.238.199.152:52643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/nakrip.php"] [unique_id "amumBrJM3qlhBlpwZyAO6AAAAOs"]
[Thu Jul 30 14:29:10.581083 2026] [security2:error] [pid 17707:tid 17850] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amumBrJM3qlhBlpwZyAO6QAAAJI"]
[Thu Jul 30 14:29:10.630028 2026] [security2:error] [pid 17707:tid 17841] [client 52.1.106.130:51236] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/12/16f4e95c-70a1-461e-a5fd-15afee8b2b7a-169x300.jpg"] [unique_id "amumBrJM3qlhBlpwZyAO7QAAAIk"]
[Thu Jul 30 14:29:10.784665 2026] [core:notice] [pid 17707:tid 17876] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:10.797378 2026] [security2:error] [pid 17707:tid 17922] [client 172.202.44.182:11403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/403.php"] [unique_id "amumBrJM3qlhBlpwZyAO8wAAANo"]
[Thu Jul 30 14:29:10.921265 2026] [security2:error] [pid 17707:tid 17921] [client 20.226.5.174:34408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/buy.php"] [unique_id "amumBrJM3qlhBlpwZyAO-AAAANk"]
[Thu Jul 30 14:29:11.023744 2026] [security2:error] [pid 17707:tid 17877] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amumBrJM3qlhBlpwZyAO8AAAAK0"]
[Thu Jul 30 14:29:11.119146 2026] [security2:error] [pid 17707:tid 17941] [client 45.94.31.73:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/xmlrpc.php"] [unique_id "amumBrJM3qlhBlpwZyAO9AAAAO0"]
[Thu Jul 30 14:29:11.137953 2026] [security2:error] [pid 17707:tid 17943] [client 20.226.5.174:51222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/st.php"] [unique_id "amumB7JM3qlhBlpwZyAO_wAAAO8"]
[Thu Jul 30 14:29:11.259681 2026] [core:notice] [pid 17707:tid 17953] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:11.399161 2026] [security2:error] [pid 17707:tid 17840] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumBrJM3qlhBlpwZyAO5wAAiFg"]
[Thu Jul 30 14:29:11.547743 2026] [security2:error] [pid 17707:tid 17906] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amumB7JM3qlhBlpwZyAPAwAAAMo"]
[Thu Jul 30 14:29:12.398734 2026] [security2:error] [pid 17707:tid 17844] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amumCLJM3qlhBlpwZyAPGgAAAIw"]
[Thu Jul 30 14:29:12.502429 2026] [security2:error] [pid 17707:tid 17883] [client 20.226.5.174:51211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/star.php"] [unique_id "amumCLJM3qlhBlpwZyAPHQAAALM"]
[Thu Jul 30 14:29:12.557363 2026] [core:notice] [pid 17707:tid 17880] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:12.597187 2026] [security2:error] [pid 17707:tid 17892] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amumCLJM3qlhBlpwZyAPIwAAALw"]
[Thu Jul 30 14:29:12.967070 2026] [security2:error] [pid 17707:tid 17944] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amumCLJM3qlhBlpwZyAPLAAAAPA"]
[Thu Jul 30 14:29:13.087855 2026] [security2:error] [pid 17707:tid 17931] [client 52.238.199.152:37964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/radio.php"] [unique_id "amumCbJM3qlhBlpwZyAPMwAAAOM"]
[Thu Jul 30 14:29:13.262441 2026] [security2:error] [pid 17707:tid 17939] [client 20.226.5.174:34417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/chosen.php"] [unique_id "amumCbJM3qlhBlpwZyAPNwAAAOs"]
[Thu Jul 30 14:29:13.273047 2026] [security2:error] [pid 17707:tid 17932] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumCLJM3qlhBlpwZyAPKAAAAOQ"]
[Thu Jul 30 14:29:13.329828 2026] [security2:error] [pid 17707:tid 17963] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amumCbJM3qlhBlpwZyAPOAAAAQM"]
[Thu Jul 30 14:29:13.700904 2026] [security2:error] [pid 17707:tid 17899] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amumCbJM3qlhBlpwZyAPQwAAAMM"]
[Thu Jul 30 14:29:13.770371 2026] [security2:error] [pid 17707:tid 17928] [client 20.226.5.174:51214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/stats.php"] [unique_id "amumCbJM3qlhBlpwZyAPRwAAAOA"]
[Thu Jul 30 14:29:14.142333 2026] [security2:error] [pid 17707:tid 17846] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amumCrJM3qlhBlpwZyAPVAAAAI4"]
[Thu Jul 30 14:29:14.209000 2026] [security2:error] [pid 17707:tid 17902] [client 172.202.44.182:37805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amumCrJM3qlhBlpwZyAPVwAAAMY"]
[Thu Jul 30 14:29:14.422483 2026] [security2:error] [pid 17707:tid 17878] [client 94.204.163.226:52134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amumCrJM3qlhBlpwZyAPWQAArno"], referer: https://skcarrental.ae/car-type/monthly-car,suv-car/?post_types=cars
[Thu Jul 30 14:29:14.533024 2026] [security2:error] [pid 17707:tid 17852] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amumCrJM3qlhBlpwZyAPaQAAAJQ"]
[Thu Jul 30 14:29:14.737504 2026] [security2:error] [pid 17707:tid 17863] [client 52.238.199.152:38005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-singin.php"] [unique_id "amumCrJM3qlhBlpwZyAPbQAAAJ8"]
[Thu Jul 30 14:29:14.927611 2026] [security2:error] [pid 17707:tid 17926] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amumCrJM3qlhBlpwZyAPdAAAAN4"]
[Thu Jul 30 14:29:15.014546 2026] [security2:error] [pid 17707:tid 17910] [client 20.226.5.174:51241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/status.php"] [unique_id "amumC7JM3qlhBlpwZyAPdQAAAM4"]
[Thu Jul 30 14:29:15.121539 2026] [security2:error] [pid 17707:tid 17917] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumCrJM3qlhBlpwZyAPZwAAANU"]
[Thu Jul 30 14:29:15.358520 2026] [security2:error] [pid 17707:tid 17877] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amumC7JM3qlhBlpwZyAPggAAAK0"]
[Thu Jul 30 14:29:15.769711 2026] [security2:error] [pid 17707:tid 17941] [client 52.238.199.152:16421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/as.php"] [unique_id "amumC7JM3qlhBlpwZyAPiQAAAO0"]
[Thu Jul 30 14:29:15.798095 2026] [security2:error] [pid 17707:tid 17848] [client 217.64.127.195:55914] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amumC7JM3qlhBlpwZyAPiwAAAJA"]
[Thu Jul 30 14:29:15.798199 2026] [security2:error] [pid 17707:tid 17848] [client 217.64.127.195:55914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amumC7JM3qlhBlpwZyAPiwAAAJA"]
[Thu Jul 30 14:29:15.809861 2026] [security2:error] [pid 17707:tid 17953] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amumC7JM3qlhBlpwZyAPjgAAAPk"]
[Thu Jul 30 14:29:16.178168 2026] [security2:error] [pid 17707:tid 17895] [client 20.226.5.174:51223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/stindex.php"] [unique_id "amumDLJM3qlhBlpwZyAPlQAAAL8"]
[Thu Jul 30 14:29:16.225617 2026] [security2:error] [pid 17707:tid 17879] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amumDLJM3qlhBlpwZyAPlgAAAK8"]
[Thu Jul 30 14:29:16.585891 2026] [security2:error] [pid 17707:tid 17882] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amumDLJM3qlhBlpwZyAPnQAAALI"]
[Thu Jul 30 14:29:16.766223 2026] [security2:error] [pid 17707:tid 17921] [client 172.202.44.182:11425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/as.php"] [unique_id "amumDLJM3qlhBlpwZyAPpAAAANk"]
[Thu Jul 30 14:29:17.052771 2026] [security2:error] [pid 17707:tid 17837] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amumDbJM3qlhBlpwZyAPrAAAAIU"]
[Thu Jul 30 14:29:17.121809 2026] [security2:error] [pid 17707:tid 17964] [client 52.238.199.152:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/x.php"] [unique_id "amumDbJM3qlhBlpwZyAPvgAAAQQ"]
[Thu Jul 30 14:29:17.325578 2026] [security2:error] [pid 17707:tid 17957] [client 177.6.106.101:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumDbJM3qlhBlpwZyAPwgAAAP0"]
[Thu Jul 30 14:29:17.325718 2026] [security2:error] [pid 17707:tid 17957] [client 177.6.106.101:55064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumDbJM3qlhBlpwZyAPwgAAAP0"]
[Thu Jul 30 14:29:17.394238 2026] [security2:error] [pid 17707:tid 17847] [client 20.226.5.174:34374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/class-wp-image.php"] [unique_id "amumDbJM3qlhBlpwZyAPwwAAAI8"]
[Thu Jul 30 14:29:17.470343 2026] [security2:error] [pid 17707:tid 17858] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amumDbJM3qlhBlpwZyAPyQAAAJo"]
[Thu Jul 30 14:29:17.540965 2026] [security2:error] [pid 17707:tid 17850] [client 20.226.5.174:51204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/storage/download/admin.php"] [unique_id "amumDbJM3qlhBlpwZyAPywAAAJI"]
[Thu Jul 30 14:29:17.571821 2026] [security2:error] [pid 17707:tid 17839] [client 172.237.109.114:15827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amumDLJM3qlhBlpwZyAPqwAAAIc"]
[Thu Jul 30 14:29:17.855768 2026] [core:notice] [pid 17707:tid 17919] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:17.873044 2026] [security2:error] [pid 17707:tid 17912] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amumDbJM3qlhBlpwZyAP0wAAANA"]
[Thu Jul 30 14:29:17.999176 2026] [security2:error] [pid 17707:tid 17945] [client 52.167.144.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amumDbJM3qlhBlpwZyAP0QAAAPE"]
[Thu Jul 30 14:29:18.290770 2026] [security2:error] [pid 17707:tid 17932] [client 172.202.44.182:36194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/includes/index.php"] [unique_id "amumDrJM3qlhBlpwZyAP3gAAAOQ"]
[Thu Jul 30 14:29:18.346046 2026] [security2:error] [pid 17707:tid 17889] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.embassyofgermanypakistanllc.de"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amumDrJM3qlhBlpwZyAP3wAAALk"]
[Thu Jul 30 14:29:18.646855 2026] [security2:error] [pid 17707:tid 17916] [client 20.226.5.174:33808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/classsmtps.php"] [unique_id "amumDrJM3qlhBlpwZyAP5gAAANQ"]
[Thu Jul 30 14:29:18.650390 2026] [proxy:error] [pid 17707:tid 17762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:29:18.650436 2026] [proxy_http:error] [pid 17707:tid 17762] [remote 74.7.175.137:42686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:29:18.651016 2026] [proxy:error] [pid 17707:tid 17762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:29:18.651059 2026] [proxy_http:error] [pid 17707:tid 17762] [remote 74.7.175.137:42686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:29:19.168655 2026] [security2:error] [pid 17707:tid 17902] [client 20.226.5.174:51213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/storage/download/alfa.php"] [unique_id "amumD7JM3qlhBlpwZyAP-AAAAMY"]
[Thu Jul 30 14:29:19.223936 2026] [security2:error] [pid 17707:tid 17845] [client 40.77.167.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amumD7JM3qlhBlpwZyAP9wAAAI0"]
[Thu Jul 30 14:29:19.822881 2026] [security2:error] [pid 17707:tid 17853] [client 20.226.5.174:33804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/classwithtostring.php"] [unique_id "amumD7JM3qlhBlpwZyAQCQAAAJU"]
[Thu Jul 30 14:29:19.965850 2026] [security2:error] [pid 17707:tid 17876] [client 85.208.96.195:23166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/24/uepb-abre-inscricoes-de-processo-seletivo-para-refugiados/"] [unique_id "amumD7JM3qlhBlpwZyAQDQAAAKw"]
[Thu Jul 30 14:29:19.965962 2026] [security2:error] [pid 17707:tid 17876] [client 85.208.96.195:23166] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/24/uepb-abre-inscricoes-de-processo-seletivo-para-refugiados/"] [unique_id "amumD7JM3qlhBlpwZyAQDQAAAKw"]
[Thu Jul 30 14:29:20.313035 2026] [security2:error] [pid 17707:tid 17867] [client 20.226.5.174:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/storage/download/index.php"] [unique_id "amumELJM3qlhBlpwZyAQFgAAAKM"]
[Thu Jul 30 14:29:20.315236 2026] [security2:error] [pid 17707:tid 17943] [client 219.76.254.140:11969] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2015/10/bottine-basse-lailka_Guess-300x300.jpg"] [unique_id "amumELJM3qlhBlpwZyAQFwAAAO8"]
[Thu Jul 30 14:29:20.397116 2026] [security2:error] [pid 17707:tid 17941] [client 217.64.127.195:50288] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amumELJM3qlhBlpwZyAQGAAAAO0"]
[Thu Jul 30 14:29:20.397222 2026] [security2:error] [pid 17707:tid 17941] [client 217.64.127.195:50288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amumELJM3qlhBlpwZyAQGAAAAO0"]
[Thu Jul 30 14:29:20.547344 2026] [security2:error] [pid 17707:tid 17901] [client 172.202.44.182:36211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amumELJM3qlhBlpwZyAQHwAAAMU"]
[Thu Jul 30 14:29:20.853317 2026] [security2:error] [pid 17707:tid 17951] [client 52.238.199.152:16447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/item.php"] [unique_id "amumELJM3qlhBlpwZyAQJAAAAPc"]
[Thu Jul 30 14:29:20.991170 2026] [security2:error] [pid 17707:tid 17940] [client 20.226.5.174:33809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/config.php"] [unique_id "amumELJM3qlhBlpwZyAQKAAAAOw"]
[Thu Jul 30 14:29:21.013898 2026] [security2:error] [pid 17707:tid 17959] [client 66.249.73.96:51327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumELJM3qlhBlpwZyAQIAAAAP8"]
[Thu Jul 30 14:29:21.165380 2026] [security2:error] [pid 17707:tid 17872] [client 180.243.59.178:52056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumEbJM3qlhBlpwZyAQLAAAAKg"]
[Thu Jul 30 14:29:21.165525 2026] [security2:error] [pid 17707:tid 17872] [client 180.243.59.178:52056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumEbJM3qlhBlpwZyAQLAAAAKg"]
[Thu Jul 30 14:29:21.804193 2026] [security2:error] [pid 17707:tid 17878] [client 20.226.5.174:49099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/storage/download/k.php"] [unique_id "amumEbJM3qlhBlpwZyAQNgAAAK4"]
[Thu Jul 30 14:29:22.373790 2026] [security2:error] [pid 17707:tid 17849] [client 172.202.44.182:36191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/plugins.php"] [unique_id "amumErJM3qlhBlpwZyAQQAAAAJE"]
[Thu Jul 30 14:29:22.999595 2026] [security2:error] [pid 17707:tid 17866] [client 52.238.199.152:37962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/app.php"] [unique_id "amumErJM3qlhBlpwZyAQTgAAAKI"]
[Thu Jul 30 14:29:23.309915 2026] [security2:error] [pid 17707:tid 17850] [client 20.226.5.174:33828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/core.php"] [unique_id "amumE7JM3qlhBlpwZyAQVQAAAJI"]
[Thu Jul 30 14:29:23.323500 2026] [security2:error] [pid 17707:tid 17885] [client 20.226.5.174:51221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/storage/download/wp.php"] [unique_id "amumE7JM3qlhBlpwZyAQVgAAALU"]
[Thu Jul 30 14:29:23.957165 2026] [security2:error] [pid 17707:tid 17841] [client 52.238.199.152:49619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/k.php"] [unique_id "amumE7JM3qlhBlpwZyAQYAAAAIk"]
[Thu Jul 30 14:29:24.420423 2026] [security2:error] [pid 17707:tid 17951] [client 20.226.5.174:51235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/storage/upload/admin.php"] [unique_id "amumFLJM3qlhBlpwZyAQawAAAPc"]
[Thu Jul 30 14:29:24.436681 2026] [security2:error] [pid 17707:tid 17918] [client 172.237.109.114:3937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amumE7JM3qlhBlpwZyAQYQAAANY"], referer: http://alseermarine.com:80/index.html
[Thu Jul 30 14:29:24.516425 2026] [security2:error] [pid 17707:tid 17843] [client 172.202.44.182:11455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/js/index.php"] [unique_id "amumFLJM3qlhBlpwZyAQbwAAAIs"]
[Thu Jul 30 14:29:24.719100 2026] [security2:error] [pid 17707:tid 17868] [client 20.226.5.174:33815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/css.php"] [unique_id "amumFLJM3qlhBlpwZyAQdgAAAKQ"]
[Thu Jul 30 14:29:25.706985 2026] [security2:error] [pid 17707:tid 17927] [client 172.202.44.182:11416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/go.php"] [unique_id "amumFbJM3qlhBlpwZyAQigAAAN8"]
[Thu Jul 30 14:29:26.012416 2026] [security2:error] [pid 17707:tid 17847] [client 20.226.5.174:33798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/database.php"] [unique_id "amumFrJM3qlhBlpwZyAQkAAAAI8"]
[Thu Jul 30 14:29:27.312395 2026] [security2:error] [pid 17707:tid 17903] [client 20.226.5.174:33797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/db.php"] [unique_id "amumF7JM3qlhBlpwZyAQqQAAAMc"]
[Thu Jul 30 14:29:27.653571 2026] [security2:error] [pid 17707:tid 17864] [client 172.202.44.182:37914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/test1.php"] [unique_id "amumF7JM3qlhBlpwZyAQrgAAAKA"]
[Thu Jul 30 14:29:27.718339 2026] [security2:error] [pid 17707:tid 17840] [client 177.6.106.101:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumF7JM3qlhBlpwZyAQrwAAAIg"]
[Thu Jul 30 14:29:27.718490 2026] [security2:error] [pid 17707:tid 17840] [client 177.6.106.101:55718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumF7JM3qlhBlpwZyAQrwAAAIg"]
[Thu Jul 30 14:29:28.395006 2026] [security2:error] [pid 17707:tid 17921] [client 20.226.5.174:33823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/default.php"] [unique_id "amumGLJM3qlhBlpwZyAQxAAAANk"]
[Thu Jul 30 14:29:28.447635 2026] [security2:error] [pid 17707:tid 17897] [client 52.238.199.152:16445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-fmfile.php"] [unique_id "amumGLJM3qlhBlpwZyAQyAAAAME"]
[Thu Jul 30 14:29:29.515620 2026] [security2:error] [pid 17707:tid 17909] [client 20.226.5.174:33826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/dropdown.php"] [unique_id "amumGbJM3qlhBlpwZyAQ4gAAAM0"]
[Thu Jul 30 14:29:30.064213 2026] [security2:error] [pid 17707:tid 17828] [remote 216.73.217.142:10233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amumGrJM3qlhBlpwZyAQ5QAA9Xg"]
[Thu Jul 30 14:29:30.843805 2026] [security2:error] [pid 17707:tid 17904] [client 172.202.44.182:37766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/images/index.php"] [unique_id "amumGrJM3qlhBlpwZyAQ9wAAAMg"]
[Thu Jul 30 14:29:30.933527 2026] [security2:error] [pid 17707:tid 17906] [client 20.226.5.174:33803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/edit.php"] [unique_id "amumGrJM3qlhBlpwZyAQ-wAAAMo"]
[Thu Jul 30 14:29:31.061754 2026] [autoindex:error] [pid 17707:tid 17932] [client 170.106.113.235:49996] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:29:31.250057 2026] [core:error] [pid 17707:tid 17868] [client 74.7.241.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:29:31.250082 2026] [core:error] [pid 17707:tid 17868] [client 74.7.241.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:29:31.250241 2026] [security2:error] [pid 17707:tid 17868] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.brx.dtn.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amumG7JM3qlhBlpwZyARAwAAAKQ"]
[Thu Jul 30 14:29:31.250917 2026] [security2:error] [pid 17707:tid 17883] [client 74.7.241.158:48544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.brx.dtn.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amumG7JM3qlhBlpwZyARAQAAs34"]
[Thu Jul 30 14:29:31.453680 2026] [security2:error] [pid 17707:tid 17873] [client 180.243.59.178:52585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumG7JM3qlhBlpwZyARCwAAAKk"]
[Thu Jul 30 14:29:31.453800 2026] [security2:error] [pid 17707:tid 17873] [client 180.243.59.178:52585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumG7JM3qlhBlpwZyARCwAAAKk"]
[Thu Jul 30 14:29:31.456202 2026] [security2:error] [pid 17707:tid 17955] [client 172.237.109.114:25205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amumGrJM3qlhBlpwZyAQ_AAAAPs"], referer: http://alseermarine.com:80/index.html
[Thu Jul 30 14:29:32.023626 2026] [fcgid:warn] [pid 17707:tid 17871] (70014)End of file found: [client 152.32.208.106:50684] mod_fcgid: can't get data from http client
[Thu Jul 30 14:29:32.091924 2026] [security2:error] [pid 17707:tid 17964] [client 20.226.5.174:33835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/f35.php"] [unique_id "amumHLJM3qlhBlpwZyARGQAAAQQ"]
[Thu Jul 30 14:29:32.169565 2026] [security2:error] [pid 17707:tid 17876] [client 52.238.199.152:16401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wi.php"] [unique_id "amumHLJM3qlhBlpwZyARGgAAAKw"]
[Thu Jul 30 14:29:33.502800 2026] [security2:error] [pid 17707:tid 17846] [client 172.202.44.182:37770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/asd.php"] [unique_id "amumHbJM3qlhBlpwZyARNQAAAI4"]
[Thu Jul 30 14:29:33.548740 2026] [security2:error] [pid 17707:tid 17920] [client 20.226.5.174:33795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/f7.php"] [unique_id "amumHbJM3qlhBlpwZyAROQAAANg"]
[Thu Jul 30 14:29:33.865233 2026] [security2:error] [pid 17707:tid 17881] [client 52.238.199.152:37971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/php8.php"] [unique_id "amumHbJM3qlhBlpwZyARPwAAALE"]
[Thu Jul 30 14:29:34.475946 2026] [security2:error] [pid 17707:tid 17947] [client 172.202.44.182:37804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/customize/index.php"] [unique_id "amumHrJM3qlhBlpwZyARSwAAAPM"]
[Thu Jul 30 14:29:34.822654 2026] [core:notice] [pid 17707:tid 17936] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:35.606702 2026] [security2:error] [pid 17707:tid 17958] [client 172.202.44.182:37922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amumH7JM3qlhBlpwZyARagAAAP4"]
[Thu Jul 30 14:29:36.577650 2026] [core:error] [pid 17707:tid 17768] [remote 157.143.3.35:57692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:29:36.577677 2026] [core:error] [pid 17707:tid 17768] [remote 157.143.3.35:57692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:29:37.181129 2026] [core:notice] [pid 17707:tid 17880] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:37.483965 2026] [security2:error] [pid 17707:tid 17864] [client 172.202.44.182:56294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/atomlib.php"] [unique_id "amumIbJM3qlhBlpwZyARnwAAAKA"]
[Thu Jul 30 14:29:38.459769 2026] [security2:error] [pid 17707:tid 17866] [client 177.6.106.101:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumIrJM3qlhBlpwZyARtgAAAKI"]
[Thu Jul 30 14:29:38.459900 2026] [security2:error] [pid 17707:tid 17866] [client 177.6.106.101:56302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumIrJM3qlhBlpwZyARtgAAAKI"]
[Thu Jul 30 14:29:38.628457 2026] [security2:error] [pid 17707:tid 17891] [client 52.238.199.152:37976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/tes.php"] [unique_id "amumIrJM3qlhBlpwZyARuAAAALs"]
[Thu Jul 30 14:29:39.248789 2026] [security2:error] [pid 17707:tid 17904] [client 68.67.112.87:4432] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amumI7JM3qlhBlpwZyARygAAAMg"]
[Thu Jul 30 14:29:40.002263 2026] [security2:error] [pid 17707:tid 17896] [client 172.202.44.182:56263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amumJLJM3qlhBlpwZyAR4QAAAMA"]
[Thu Jul 30 14:29:41.736124 2026] [security2:error] [pid 17707:tid 17826] [remote 57.141.18.109:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amumJbJM3qlhBlpwZyASGgAA-HY"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,cotton,linen,lycra,polyester,steel&rating=5&tax_product_cat=suit&filter_size=small&unfilter=1
[Thu Jul 30 14:29:41.904229 2026] [security2:error] [pid 17707:tid 17827] [remote 57.141.18.81:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amumJbJM3qlhBlpwZyASGQAA2Xc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,cotton,linen,lycra,polyester,steel&rating=5&tax_product_cat=suit&filter_size=small&unfilter=1
[Thu Jul 30 14:29:41.906807 2026] [security2:error] [pid 17707:tid 17843] [client 180.243.59.178:53127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumJbJM3qlhBlpwZyASHwAAAIs"]
[Thu Jul 30 14:29:41.907076 2026] [security2:error] [pid 17707:tid 17843] [client 180.243.59.178:53127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumJbJM3qlhBlpwZyASHwAAAIs"]
[Thu Jul 30 14:29:42.130670 2026] [core:notice] [pid 17707:tid 17844] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:42.588619 2026] [security2:error] [pid 17707:tid 17927] [client 20.226.5.174:8448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fjpeb.php"] [unique_id "amumJrJM3qlhBlpwZyASMAAAAN8"]
[Thu Jul 30 14:29:42.699457 2026] [security2:error] [pid 17707:tid 17892] [client 52.238.199.152:37958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/about.php"] [unique_id "amumJrJM3qlhBlpwZyASNQAAALw"]
[Thu Jul 30 14:29:43.488714 2026] [security2:error] [pid 17707:tid 17937] [client 172.202.44.182:56275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/inputs.php"] [unique_id "amumJ7JM3qlhBlpwZyASRwAAAOk"]
[Thu Jul 30 14:29:43.576834 2026] [security2:error] [pid 17707:tid 17850] [client 20.226.5.174:8455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/flame.php"] [unique_id "amumJ7JM3qlhBlpwZyASSQAAAJI"]
[Thu Jul 30 14:29:43.593902 2026] [security2:error] [pid 17707:tid 17838] [client 172.237.109.114:5806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amumJ7JM3qlhBlpwZyASPQAAAIY"]
[Thu Jul 30 14:29:44.542442 2026] [security2:error] [pid 17707:tid 17843] [client 20.226.5.174:8449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/flower.php"] [unique_id "amumKLJM3qlhBlpwZyASWwAAAIs"]
[Thu Jul 30 14:29:44.608694 2026] [security2:error] [pid 17707:tid 17883] [client 52.238.199.152:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/headers.php"] [unique_id "amumKLJM3qlhBlpwZyASYAAAALM"]
[Thu Jul 30 14:29:44.700341 2026] [security2:error] [pid 17707:tid 17903] [client 172.202.44.182:37945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/index.php"] [unique_id "amumKLJM3qlhBlpwZyASZQAAAMc"]
[Thu Jul 30 14:29:45.256023 2026] [core:notice] [pid 17707:tid 17841] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:45.501038 2026] [security2:error] [pid 17707:tid 17933] [client 20.226.5.174:8470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fm.php"] [unique_id "amumKbJM3qlhBlpwZyASdQAAAOU"]
[Thu Jul 30 14:29:45.607377 2026] [security2:error] [pid 17707:tid 17879] [client 172.202.44.182:37903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/network/index.php"] [unique_id "amumKbJM3qlhBlpwZyASdgAAAK8"]
[Thu Jul 30 14:29:45.806050 2026] [autoindex:error] [pid 17707:tid 17904] [client 3.225.222.228:26720] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:29:45.812710 2026] [proxy:error] [pid 17707:tid 17852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:29:45.812789 2026] [proxy_http:error] [pid 17707:tid 17852] [client 3.225.222.228:5238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:29:45.813396 2026] [proxy:error] [pid 17707:tid 17852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:29:45.813448 2026] [proxy_http:error] [pid 17707:tid 17852] [client 3.225.222.228:5238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:29:45.816858 2026] [autoindex:error] [pid 17707:tid 17959] [client 52.4.19.39:41062] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:29:45.830576 2026] [proxy:error] [pid 17707:tid 17916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:29:45.830666 2026] [proxy_http:error] [pid 17707:tid 17916] [client 52.4.19.39:44649] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:29:45.831391 2026] [proxy:error] [pid 17707:tid 17916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:29:45.831443 2026] [proxy_http:error] [pid 17707:tid 17916] [client 52.4.19.39:44649] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:29:45.866548 2026] [autoindex:error] [pid 17707:tid 17865] [client 3.225.222.228:16942] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:29:46.146341 2026] [security2:error] [pid 17707:tid 17919] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumKLJM3qlhBlpwZyASYQAA1wc"]
[Thu Jul 30 14:29:46.541430 2026] [security2:error] [pid 17707:tid 17910] [client 20.226.5.174:8467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fm1.php"] [unique_id "amumKrJM3qlhBlpwZyASlwAAAM4"]
[Thu Jul 30 14:29:46.968037 2026] [security2:error] [pid 17707:tid 17908] [client 52.238.199.152:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amumKrJM3qlhBlpwZyASngAAAMw"]
[Thu Jul 30 14:29:47.135157 2026] [security2:error] [pid 17707:tid 17946] [client 172.202.44.182:12115] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/1.php"] [unique_id "amumK7JM3qlhBlpwZyASogAAAPI"]
[Thu Jul 30 14:29:47.135297 2026] [security2:error] [pid 17707:tid 17946] [client 172.202.44.182:12115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/1.php"] [unique_id "amumK7JM3qlhBlpwZyASogAAAPI"]
[Thu Jul 30 14:29:47.604168 2026] [security2:error] [pid 17707:tid 17875] [client 20.226.5.174:8456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fmadmin.php"] [unique_id "amumK7JM3qlhBlpwZyASrgAAAKs"]
[Thu Jul 30 14:29:48.188394 2026] [security2:error] [pid 17707:tid 17852] [client 116.179.32.164:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/issue/view/5"] [unique_id "amumK7JM3qlhBlpwZyAStQAAAJQ"]
[Thu Jul 30 14:29:48.572406 2026] [security2:error] [pid 17707:tid 17898] [client 20.226.5.174:8468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fmxt.php"] [unique_id "amumLLJM3qlhBlpwZyASwQAAAMI"]
[Thu Jul 30 14:29:48.741349 2026] [core:notice] [pid 17707:tid 17719] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:48.912853 2026] [security2:error] [pid 17707:tid 17890] [client 177.6.106.101:57035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumLLJM3qlhBlpwZyASygAAALo"]
[Thu Jul 30 14:29:48.913020 2026] [security2:error] [pid 17707:tid 17890] [client 177.6.106.101:57035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumLLJM3qlhBlpwZyASygAAALo"]
[Thu Jul 30 14:29:49.066648 2026] [core:notice] [pid 17707:tid 17720] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:49.134814 2026] [fcgid:warn] [pid 17707:tid 17871] (70014)End of file found: [client 128.14.226.191:33888] mod_fcgid: can't get data from http client
[Thu Jul 30 14:29:49.334112 2026] [core:notice] [pid 17707:tid 17864] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:49.539344 2026] [security2:error] [pid 17707:tid 17847] [client 20.226.5.174:8472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fontawesome-webfont.php"] [unique_id "amumLbJM3qlhBlpwZyAS3AAAAI8"]
[Thu Jul 30 14:29:49.631108 2026] [security2:error] [pid 17707:tid 17943] [client 3.229.164.203:35677] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/01/ijj-1-400x366.jpg"] [unique_id "amumLbJM3qlhBlpwZyAS4AAAAO8"]
[Thu Jul 30 14:29:50.251796 2026] [security2:error] [pid 17707:tid 17952] [client 52.238.199.152:38003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/flower.php"] [unique_id "amumLrJM3qlhBlpwZyAS6gAAAPg"]
[Thu Jul 30 14:29:50.414860 2026] [security2:error] [pid 17707:tid 17747] [remote 216.73.217.142:30188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amumLrJM3qlhBlpwZyAS8QAAlSc"]
[Thu Jul 30 14:29:50.475430 2026] [security2:error] [pid 17707:tid 17913] [client 20.226.5.174:8488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fonts/dev.php"] [unique_id "amumLrJM3qlhBlpwZyAS9QAAANE"]
[Thu Jul 30 14:29:51.293995 2026] [security2:error] [pid 17707:tid 17873] [client 52.238.199.152:37987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amumL7JM3qlhBlpwZyATBQAAAKk"]
[Thu Jul 30 14:29:51.361472 2026] [core:notice] [pid 17707:tid 17751] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:51.408365 2026] [security2:error] [pid 17707:tid 17837] [client 20.226.5.174:8452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fonts/iqb.php"] [unique_id "amumL7JM3qlhBlpwZyATBwAAAIU"]
[Thu Jul 30 14:29:51.468621 2026] [security2:error] [pid 17707:tid 17921] [client 172.237.109.114:15370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amumLrJM3qlhBlpwZyAS_QAAANk"]
[Thu Jul 30 14:29:52.227052 2026] [security2:error] [pid 17707:tid 17923] [client 180.243.59.178:53657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumMLJM3qlhBlpwZyATHAAAANs"]
[Thu Jul 30 14:29:52.227169 2026] [security2:error] [pid 17707:tid 17923] [client 180.243.59.178:53657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumMLJM3qlhBlpwZyATHAAAANs"]
[Thu Jul 30 14:29:52.347884 2026] [security2:error] [pid 17707:tid 17884] [client 20.226.5.174:8473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/footer.php"] [unique_id "amumMLJM3qlhBlpwZyATHQAAALQ"]
[Thu Jul 30 14:29:52.380831 2026] [security2:error] [pid 17707:tid 17886] [client 52.238.199.152:49605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content.php"] [unique_id "amumMLJM3qlhBlpwZyATHgAAALY"]
[Thu Jul 30 14:29:53.270401 2026] [security2:error] [pid 17707:tid 17961] [client 20.226.5.174:8464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/footerm.php"] [unique_id "amumMbJM3qlhBlpwZyATMQAAAQE"]
[Thu Jul 30 14:29:53.556355 2026] [security2:error] [pid 17707:tid 17893] [client 52.238.199.152:37966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/function.php"] [unique_id "amumMbJM3qlhBlpwZyATMgAAAL0"]
[Thu Jul 30 14:29:53.917847 2026] [autoindex:error] [pid 17707:tid 17938] [client 98.87.102.177:26791] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_a59f0c15/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:29:54.163893 2026] [security2:error] [pid 17707:tid 17897] [client 20.226.5.174:8469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fopen.php"] [unique_id "amumMrJM3qlhBlpwZyATSwAAAME"]
[Thu Jul 30 14:29:54.248876 2026] [security2:error] [pid 17707:tid 17900] [client 172.202.44.182:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/plugin.php"] [unique_id "amumMrJM3qlhBlpwZyATTwAAAMQ"]
[Thu Jul 30 14:29:54.276048 2026] [core:notice] [pid 17707:tid 17839] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:54.283890 2026] [core:notice] [pid 17707:tid 17903] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:54.294493 2026] [core:notice] [pid 17707:tid 17871] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:54.297110 2026] [core:notice] [pid 17707:tid 17947] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:54.297113 2026] [core:notice] [pid 17707:tid 17922] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:54.298916 2026] [core:notice] [pid 17707:tid 17855] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:54.315359 2026] [core:notice] [pid 17707:tid 17927] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:54.326158 2026] [core:notice] [pid 17707:tid 17856] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:54.338465 2026] [core:notice] [pid 17707:tid 17934] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:54.807529 2026] [security2:error] [pid 17707:tid 17864] [client 52.238.199.152:16400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amumMrJM3qlhBlpwZyATaAAAAKA"]
[Thu Jul 30 14:29:55.098304 2026] [security2:error] [pid 17707:tid 17892] [client 20.226.5.174:8459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/forbiden.php"] [unique_id "amumM7JM3qlhBlpwZyATagAAALw"]
[Thu Jul 30 14:29:55.412400 2026] [autoindex:error] [pid 17707:tid 17895] [client 82.102.18.118:49964] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:29:55.568323 2026] [autoindex:error] [pid 17707:tid 17937] [client 82.102.18.118:49964] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:29:55.571814 2026] [security2:error] [pid 17707:tid 17906] [client 109.235.50.35:60314] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amumM7JM3qlhBlpwZyATegAAAMo"]
[Thu Jul 30 14:29:55.571920 2026] [security2:error] [pid 17707:tid 17906] [client 109.235.50.35:60314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amumM7JM3qlhBlpwZyATegAAAMo"]
[Thu Jul 30 14:29:55.728168 2026] [security2:error] [pid 17707:tid 17958] [client 82.102.18.118:49964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amumM7JM3qlhBlpwZyATfgAAAP4"]
[Thu Jul 30 14:29:55.994383 2026] [security2:error] [pid 17707:tid 17949] [client 64.233.173.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amumM7JM3qlhBlpwZyATdQAA9Vs"]
[Thu Jul 30 14:29:56.032825 2026] [security2:error] [pid 17707:tid 17961] [client 20.226.5.174:9218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/form.php"] [unique_id "amumNLJM3qlhBlpwZyAThwAAAQE"]
[Thu Jul 30 14:29:56.047214 2026] [security2:error] [pid 17707:tid 17940] [client 82.102.18.118:49966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hhmoaf.org"] [uri "/xmlrpc.php"] [unique_id "amumNLJM3qlhBlpwZyATiAAAAOw"]
[Thu Jul 30 14:29:56.287596 2026] [core:notice] [pid 17707:tid 17780] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:56.364207 2026] [autoindex:error] [pid 17707:tid 17854] [client 82.102.18.118:49968] AH01276: Cannot serve directory /home1/wrlgzjte/hhmoaf.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:29:56.408390 2026] [security2:error] [pid 17707:tid 17946] [client 172.202.44.182:39545] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.jesus.claims"] [uri "/1.php"] [unique_id "amumNLJM3qlhBlpwZyATlQAAAPI"]
[Thu Jul 30 14:29:56.408495 2026] [security2:error] [pid 17707:tid 17946] [client 172.202.44.182:39545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1.php"] [unique_id "amumNLJM3qlhBlpwZyATlQAAAPI"]
[Thu Jul 30 14:29:56.511808 2026] [security2:error] [pid 17707:tid 17883] [client 82.102.18.118:49968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amumNLJM3qlhBlpwZyATlgAAALM"]
[Thu Jul 30 14:29:56.806359 2026] [security2:error] [pid 17707:tid 17856] [client 82.102.18.118:49982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amumNLJM3qlhBlpwZyATnAAAAJg"]
[Thu Jul 30 14:29:56.949541 2026] [security2:error] [pid 17707:tid 17839] [client 20.226.5.174:8462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/formatting.php"] [unique_id "amumNLJM3qlhBlpwZyATogAAAIc"]
[Thu Jul 30 14:29:57.098299 2026] [security2:error] [pid 17707:tid 17864] [client 82.102.18.118:60048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amumNbJM3qlhBlpwZyATpAAAAKA"]
[Thu Jul 30 14:29:57.357452 2026] [security2:error] [pid 17707:tid 17816] [remote 74.7.243.224:45800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/article.php"] [unique_id "amumNbJM3qlhBlpwZyATrAABAGw"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/content/js/bootstrap.bundle.min.js
[Thu Jul 30 14:29:57.435895 2026] [security2:error] [pid 17707:tid 17912] [client 82.102.18.118:49988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amumNbJM3qlhBlpwZyATsAAAANA"]
[Thu Jul 30 14:29:57.675184 2026] [core:notice] [pid 17707:tid 17794] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:57.703383 2026] [security2:error] [pid 17707:tid 17842] [client 3.133.226.214:26262] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amumNLJM3qlhBlpwZyATlAAAAIo"], referer: https://globalmarks.pk/
[Thu Jul 30 14:29:57.738100 2026] [security2:error] [pid 17707:tid 17951] [client 82.102.18.118:49994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amumNbJM3qlhBlpwZyATtQAAAPc"]
[Thu Jul 30 14:29:57.740768 2026] [security2:error] [pid 17707:tid 17939] [client 103.168.67.159:37166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/wp-login.php"] [unique_id "amumNbJM3qlhBlpwZyATsgAAAOs"], referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:29:57.917579 2026] [security2:error] [pid 17707:tid 17875] [client 20.226.5.174:8463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fosil.php"] [unique_id "amumNbJM3qlhBlpwZyATwQAAAKs"]
[Thu Jul 30 14:29:58.029563 2026] [security2:error] [pid 17707:tid 17865] [client 82.102.18.118:49998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amumNrJM3qlhBlpwZyATwwAAAKE"]
[Thu Jul 30 14:29:58.325697 2026] [security2:error] [pid 17707:tid 17961] [client 82.102.18.118:5486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amumNrJM3qlhBlpwZyATxAAAAQE"]
[Thu Jul 30 14:29:58.556938 2026] [core:notice] [pid 17707:tid 17946] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:58.621720 2026] [security2:error] [pid 17707:tid 17935] [client 82.102.18.118:50008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amumNrJM3qlhBlpwZyATzwAAAOc"]
[Thu Jul 30 14:29:58.800433 2026] [security2:error] [pid 17707:tid 17949] [client 103.168.67.159:37178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/blog/wp-login.php"] [unique_id "amumNrJM3qlhBlpwZyAT0AAAAPU"], referer: https://webdisk.smoke-tfhk.com/blog/
[Thu Jul 30 14:29:58.838321 2026] [security2:error] [pid 17707:tid 17862] [client 20.226.5.174:8479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/foter.php"] [unique_id "amumNrJM3qlhBlpwZyAT0QAAAJ4"]
[Thu Jul 30 14:29:58.921515 2026] [security2:error] [pid 17707:tid 17871] [client 82.102.18.118:50014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amumNrJM3qlhBlpwZyAT1QAAAKc"]
[Thu Jul 30 14:29:58.958405 2026] [core:notice] [pid 17707:tid 17826] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:29:59.222903 2026] [security2:error] [pid 17707:tid 17930] [client 82.102.18.118:50030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amumN7JM3qlhBlpwZyAT3gAAAOI"]
[Thu Jul 30 14:29:59.540764 2026] [security2:error] [pid 17707:tid 17892] [client 82.102.18.118:50040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amumN7JM3qlhBlpwZyAT6AAAALw"]
[Thu Jul 30 14:29:59.568533 2026] [security2:error] [pid 17707:tid 17844] [client 177.6.106.101:53449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumN7JM3qlhBlpwZyAT6gAAAIw"]
[Thu Jul 30 14:29:59.568678 2026] [security2:error] [pid 17707:tid 17844] [client 177.6.106.101:53449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumN7JM3qlhBlpwZyAT6gAAAIw"]
[Thu Jul 30 14:29:59.835950 2026] [security2:error] [pid 17707:tid 17958] [client 82.102.18.118:41909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amumN7JM3qlhBlpwZyAT7gAAAP4"]
[Thu Jul 30 14:29:59.854221 2026] [security2:error] [pid 17707:tid 17846] [client 20.226.5.174:8323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fox.php"] [unique_id "amumN7JM3qlhBlpwZyAT7wAAAI4"]
[Thu Jul 30 14:30:00.154769 2026] [security2:error] [pid 17707:tid 17861] [client 82.102.18.118:50064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hhmoaf.org"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amumOLJM3qlhBlpwZyAT-gAAAJ0"]
[Thu Jul 30 14:30:00.638090 2026] [security2:error] [pid 17707:tid 17917] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumOLJM3qlhBlpwZyAT8wAA1XQ"]
[Thu Jul 30 14:30:00.706819 2026] [security2:error] [pid 17707:tid 17853] [client 52.238.199.152:52654] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.bonafideadvisors.com"] [uri "/1.php"] [unique_id "amumOLJM3qlhBlpwZyAUBQAAAJU"]
[Thu Jul 30 14:30:00.706947 2026] [security2:error] [pid 17707:tid 17853] [client 52.238.199.152:52654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/1.php"] [unique_id "amumOLJM3qlhBlpwZyAUBQAAAJU"]
[Thu Jul 30 14:30:00.835459 2026] [security2:error] [pid 17707:tid 17896] [client 20.226.5.174:8333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/foxx.php"] [unique_id "amumOLJM3qlhBlpwZyAUCQAAAMA"]
[Thu Jul 30 14:30:00.969796 2026] [security2:error] [pid 17707:tid 17938] [client 103.168.67.159:37194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/wordpress/wp-login.php"] [unique_id "amumOLJM3qlhBlpwZyAUCgAAAOo"], referer: https://webdisk.smoke-tfhk.com/wordpress/
[Thu Jul 30 14:30:01.006320 2026] [security2:error] [pid 17707:tid 17888] [client 172.202.44.182:61616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/gg.php"] [unique_id "amumObJM3qlhBlpwZyAUDgAAALg"]
[Thu Jul 30 14:30:01.768123 2026] [security2:error] [pid 17707:tid 17930] [client 20.226.5.174:9225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fr.php"] [unique_id "amumObJM3qlhBlpwZyAUJAAAAOI"]
[Thu Jul 30 14:30:02.771865 2026] [security2:error] [pid 17707:tid 17859] [client 20.226.5.174:8453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fucku.php"] [unique_id "amumOrJM3qlhBlpwZyAUPwAAAJs"]
[Thu Jul 30 14:30:02.898736 2026] [security2:error] [pid 17707:tid 17918] [client 103.168.67.159:37198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/wp/wp-login.php"] [unique_id "amumOrJM3qlhBlpwZyAUQQAAANY"], referer: https://webdisk.smoke-tfhk.com/wp/
[Thu Jul 30 14:30:03.131423 2026] [security2:error] [pid 17707:tid 17896] [client 172.202.44.182:39513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp.php"] [unique_id "amumO7JM3qlhBlpwZyAURwAAAMA"]
[Thu Jul 30 14:30:03.171534 2026] [security2:error] [pid 17707:tid 17873] [client 180.243.59.178:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumO7JM3qlhBlpwZyAUSAAAAKk"]
[Thu Jul 30 14:30:03.171837 2026] [security2:error] [pid 17707:tid 17873] [client 180.243.59.178:54217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumO7JM3qlhBlpwZyAUSAAAAKk"]
[Thu Jul 30 14:30:03.345953 2026] [security2:error] [pid 17707:tid 17736] [remote 57.141.0.49:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amumO7JM3qlhBlpwZyAUTwAAlRw"]
[Thu Jul 30 14:30:03.702541 2026] [security2:error] [pid 17707:tid 17752] [remote 52.167.144.191:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/moyens-de-subsistance-et-autonomisation/communityf.php"] [unique_id "amumO7JM3qlhBlpwZyAUVQAA6Cw"]
[Thu Jul 30 14:30:03.756692 2026] [security2:error] [pid 17707:tid 17876] [client 20.226.5.174:8329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/function.php"] [unique_id "amumO7JM3qlhBlpwZyAUWAAAAKw"]
[Thu Jul 30 14:30:03.853277 2026] [security2:error] [pid 17707:tid 17860] [client 103.168.67.159:37208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/cms/wp-login.php"] [unique_id "amumO7JM3qlhBlpwZyAUXQAAAJw"], referer: https://webdisk.smoke-tfhk.com/cms/
[Thu Jul 30 14:30:04.718537 2026] [security2:error] [pid 17707:tid 17902] [client 103.168.67.159:47004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/site/wp-login.php"] [unique_id "amumPLJM3qlhBlpwZyAUbAAAAMY"], referer: https://webdisk.smoke-tfhk.com/site/
[Thu Jul 30 14:30:04.720645 2026] [security2:error] [pid 17707:tid 17933] [client 20.226.5.174:8475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/functions.php"] [unique_id "amumPLJM3qlhBlpwZyAUbQAAAOU"]
[Thu Jul 30 14:30:05.265899 2026] [security2:error] [pid 17707:tid 17955] [client 172.202.44.182:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/blocks/about.php"] [unique_id "amumPbJM3qlhBlpwZyAUfAAAAPs"]
[Thu Jul 30 14:30:05.637936 2026] [security2:error] [pid 17707:tid 17886] [client 103.168.67.159:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/main/wp-login.php"] [unique_id "amumPbJM3qlhBlpwZyAUhQAAALY"], referer: https://webdisk.smoke-tfhk.com/main/
[Thu Jul 30 14:30:05.656697 2026] [security2:error] [pid 17707:tid 17879] [client 20.226.5.174:8332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/functionsf.php"] [unique_id "amumPbJM3qlhBlpwZyAUhgAAAK8"]
[Thu Jul 30 14:30:06.308742 2026] [security2:error] [pid 17707:tid 17888] [client 52.238.199.152:37981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/lv.php"] [unique_id "amumPrJM3qlhBlpwZyAUkgAAALg"]
[Thu Jul 30 14:30:06.581120 2026] [security2:error] [pid 17707:tid 17854] [client 20.226.5.174:8481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fungsi.php"] [unique_id "amumPrJM3qlhBlpwZyAUmgAAAJY"]
[Thu Jul 30 14:30:06.644466 2026] [security2:error] [pid 17707:tid 17934] [client 103.168.67.159:47018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/new/wp-login.php"] [unique_id "amumPrJM3qlhBlpwZyAUmwAAAOY"], referer: https://webdisk.smoke-tfhk.com/new/
[Thu Jul 30 14:30:07.295794 2026] [security2:error] [pid 17707:tid 17863] [client 103.168.67.159:3484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/wp-login.php"] [unique_id "amumP7JM3qlhBlpwZyAUqAAAAJ8"], referer: http://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:07.429345 2026] [security2:error] [pid 17707:tid 17873] [client 172.202.44.182:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/file.php"] [unique_id "amumP7JM3qlhBlpwZyAUrwAAAKk"]
[Thu Jul 30 14:30:07.544967 2026] [security2:error] [pid 17707:tid 17905] [client 20.226.5.174:8486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fw.php"] [unique_id "amumP7JM3qlhBlpwZyAUswAAAMk"]
[Thu Jul 30 14:30:07.816541 2026] [security2:error] [pid 17707:tid 17852] [client 103.168.67.159:3488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/blog/wp-login.php"] [unique_id "amumP7JM3qlhBlpwZyAUtQAAAJQ"], referer: http://webdisk.smoke-tfhk.com/blog/
[Thu Jul 30 14:30:07.843744 2026] [core:notice] [pid 17707:tid 17913] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:08.121251 2026] [security2:error] [pid 17707:tid 17932] [client 52.238.199.152:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/css.php"] [unique_id "amumQLJM3qlhBlpwZyAUwAAAAOQ"]
[Thu Jul 30 14:30:08.411068 2026] [security2:error] [pid 17707:tid 17903] [client 103.168.67.159:3500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/wordpress/wp-login.php"] [unique_id "amumQLJM3qlhBlpwZyAUxQAAAMc"], referer: http://webdisk.smoke-tfhk.com/wordpress/
[Thu Jul 30 14:30:08.453568 2026] [security2:error] [pid 17707:tid 17929] [client 20.226.5.174:8484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fx-mini.php"] [unique_id "amumQLJM3qlhBlpwZyAUxgAAAOE"]
[Thu Jul 30 14:30:08.628576 2026] [security2:error] [pid 17707:tid 17897] [client 172.202.44.182:61505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/user/index.php"] [unique_id "amumQLJM3qlhBlpwZyAUzgAAAME"]
[Thu Jul 30 14:30:08.677284 2026] [security2:error] [pid 17707:tid 17754] [remote 57.141.0.9:55426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amumQLJM3qlhBlpwZyAUzwAAmC4"]
[Thu Jul 30 14:30:08.853406 2026] [security2:error] [pid 17707:tid 17908] [client 74.7.228.18:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amumQLJM3qlhBlpwZyAU0wAAAMw"]
[Thu Jul 30 14:30:08.853815 2026] [security2:error] [pid 17707:tid 17864] [client 74.7.228.18:37144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amumQLJM3qlhBlpwZyAU0QAAAKA"]
[Thu Jul 30 14:30:08.926650 2026] [security2:error] [pid 17707:tid 17858] [client 52.238.199.152:16403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/gecko.php"] [unique_id "amumQLJM3qlhBlpwZyAU2QAAAJo"]
[Thu Jul 30 14:30:08.959198 2026] [security2:error] [pid 17707:tid 17883] [client 103.168.67.159:3516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/wp/wp-login.php"] [unique_id "amumQLJM3qlhBlpwZyAU2wAAALM"], referer: http://webdisk.smoke-tfhk.com/wp/
[Thu Jul 30 14:30:09.425048 2026] [security2:error] [pid 17707:tid 17963] [client 20.226.5.174:8495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/fx.php"] [unique_id "amumQbJM3qlhBlpwZyAU6gAAAQM"]
[Thu Jul 30 14:30:09.569245 2026] [security2:error] [pid 17707:tid 17909] [client 103.168.67.159:3524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/cms/wp-login.php"] [unique_id "amumQbJM3qlhBlpwZyAU8wAAAM0"], referer: http://webdisk.smoke-tfhk.com/cms/
[Thu Jul 30 14:30:09.586660 2026] [security2:error] [pid 17707:tid 17795] [remote 216.73.217.142:30188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/doc/source/percona-server-logo.jpg"] [unique_id "amumQbJM3qlhBlpwZyAU9gAAnVc"]
[Thu Jul 30 14:30:09.987365 2026] [security2:error] [pid 17707:tid 17873] [client 177.6.106.101:53874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumQbJM3qlhBlpwZyAU_QAAAKk"]
[Thu Jul 30 14:30:09.987504 2026] [security2:error] [pid 17707:tid 17873] [client 177.6.106.101:53874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumQbJM3qlhBlpwZyAU_QAAAKk"]
[Thu Jul 30 14:30:10.252999 2026] [security2:error] [pid 17707:tid 17886] [client 103.168.67.159:3540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/site/wp-login.php"] [unique_id "amumQrJM3qlhBlpwZyAVCQAAALY"], referer: http://webdisk.smoke-tfhk.com/site/
[Thu Jul 30 14:30:10.372854 2026] [security2:error] [pid 17707:tid 17916] [client 52.238.199.152:49655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/xmlrpc.php"] [unique_id "amumQrJM3qlhBlpwZyAVBAAAANQ"]
[Thu Jul 30 14:30:10.637162 2026] [security2:error] [pid 17707:tid 17865] [client 20.226.5.174:8451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/g.php"] [unique_id "amumQrJM3qlhBlpwZyAVFQAAAKE"]
[Thu Jul 30 14:30:10.913932 2026] [security2:error] [pid 17707:tid 17853] [client 99.252.2.175:54613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amumQrJM3qlhBlpwZyAVFgAAlV4"], referer: https://www.northyorksheridanmall.com/
[Thu Jul 30 14:30:10.967475 2026] [security2:error] [pid 17707:tid 17857] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumQrJM3qlhBlpwZyAVCgAAmWM"]
[Thu Jul 30 14:30:11.509465 2026] [security2:error] [pid 17707:tid 17915] [client 52.238.199.152:37991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/f35.php"] [unique_id "amumQ7JM3qlhBlpwZyAVKQAAANM"]
[Thu Jul 30 14:30:11.554919 2026] [security2:error] [pid 17707:tid 17941] [client 20.226.5.174:9224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/g1.php"] [unique_id "amumQ7JM3qlhBlpwZyAVLQAAAO0"]
[Thu Jul 30 14:30:11.584482 2026] [security2:error] [pid 17707:tid 17863] [client 119.73.97.132:30730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amumQ7JM3qlhBlpwZyAVKAAAn2c"], referer: https://trello.com/
[Thu Jul 30 14:30:11.986349 2026] [security2:error] [pid 17707:tid 17958] [client 34.74.242.206:1791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mediaspawn.com"] [uri "/robots.txt"] [unique_id "amumQ7JM3qlhBlpwZyAVNQAAAP4"]
[Thu Jul 30 14:30:11.986494 2026] [security2:error] [pid 17707:tid 17958] [client 34.74.242.206:1791] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.mediaspawn.com"] [uri "/robots.txt"] [unique_id "amumQ7JM3qlhBlpwZyAVNQAAAP4"]
[Thu Jul 30 14:30:12.118478 2026] [security2:error] [pid 17707:tid 17893] [client 103.168.67.159:3548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/main/wp-login.php"] [unique_id "amumRLJM3qlhBlpwZyAVOQAAAL0"], referer: http://webdisk.smoke-tfhk.com/main/
[Thu Jul 30 14:30:12.291961 2026] [core:notice] [pid 17707:tid 17852] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:12.320289 2026] [security2:error] [pid 17707:tid 17955] [client 127.0.0.1:60894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amumRLJM3qlhBlpwZyAVQwAAAPs"]
[Thu Jul 30 14:30:12.320297 2026] [security2:error] [pid 17707:tid 17918] [client 127.0.0.1:60882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.shop-mevius.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amumRLJM3qlhBlpwZyAVQgAAANY"]
[Thu Jul 30 14:30:12.320408 2026] [security2:error] [pid 17707:tid 17851] [client 74.7.241.143:44548] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.shop-mevius.com"] [uri "/robots.txt"] [unique_id "amumRLJM3qlhBlpwZyAVQAAAk2U"]
[Thu Jul 30 14:30:12.451151 2026] [security2:error] [pid 17707:tid 17862] [client 34.74.242.206:1775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mediaspawn.com"] [uri "/"] [unique_id "amumRLJM3qlhBlpwZyAVRQAAAJ4"]
[Thu Jul 30 14:30:12.451238 2026] [security2:error] [pid 17707:tid 17862] [client 34.74.242.206:1775] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.mediaspawn.com"] [uri "/"] [unique_id "amumRLJM3qlhBlpwZyAVRQAAAJ4"]
[Thu Jul 30 14:30:12.463205 2026] [security2:error] [pid 17707:tid 17961] [client 20.226.5.174:8320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/g3.php"] [unique_id "amumRLJM3qlhBlpwZyAVRgAAAQE"]
[Thu Jul 30 14:30:12.655772 2026] [security2:error] [pid 17707:tid 17859] [client 52.238.199.152:37980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/autoload_classmap.php"] [unique_id "amumRLJM3qlhBlpwZyAVTQAAAJs"]
[Thu Jul 30 14:30:12.685211 2026] [security2:error] [pid 17707:tid 17924] [client 103.168.67.159:3558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/new/wp-login.php"] [unique_id "amumRLJM3qlhBlpwZyAVTgAAANw"], referer: http://webdisk.smoke-tfhk.com/new/
[Thu Jul 30 14:30:12.908906 2026] [security2:error] [pid 17707:tid 17897] [client 89.238.167.134:33178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amumRLJM3qlhBlpwZyAVVwAAAME"]
[Thu Jul 30 14:30:12.909026 2026] [security2:error] [pid 17707:tid 17897] [client 89.238.167.134:33178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amumRLJM3qlhBlpwZyAVVwAAAME"]
[Thu Jul 30 14:30:13.439065 2026] [security2:error] [pid 17707:tid 17945] [client 180.243.59.178:54750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumRbJM3qlhBlpwZyAVZQAAAPE"]
[Thu Jul 30 14:30:13.439234 2026] [security2:error] [pid 17707:tid 17945] [client 180.243.59.178:54750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumRbJM3qlhBlpwZyAVZQAAAPE"]
[Thu Jul 30 14:30:13.557733 2026] [security2:error] [pid 17707:tid 17892] [client 172.202.44.182:11291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amumRbJM3qlhBlpwZyAVagAAALw"]
[Thu Jul 30 14:30:13.641730 2026] [core:error] [pid 17707:tid 17915] [client 103.168.67.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:13.641752 2026] [core:error] [pid 17707:tid 17915] [client 103.168.67.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:14.792501 2026] [security2:error] [pid 17707:tid 17862] [client 52.238.199.152:37959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/NewFile.php"] [unique_id "amumRrJM3qlhBlpwZyAVjAAAAJ4"]
[Thu Jul 30 14:30:15.546378 2026] [security2:error] [pid 17707:tid 17889] [client 172.202.44.182:38953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/index/function.php"] [unique_id "amumR7JM3qlhBlpwZyAVngAAALk"]
[Thu Jul 30 14:30:16.200090 2026] [core:notice] [pid 17707:tid 17915] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:17.221895 2026] [security2:error] [pid 17707:tid 17939] [client 50.6.43.217:59334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amumOrJM3qlhBlpwZyAULgAAAOs"]
[Thu Jul 30 14:30:18.541210 2026] [security2:error] [pid 17707:tid 17962] [client 103.168.67.159:58668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/wp-login.php"] [unique_id "amumSrJM3qlhBlpwZyAV3gAAAQI"], referer: http://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:19.101325 2026] [security2:error] [pid 17707:tid 17948] [client 52.238.199.152:16405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/xx.php"] [unique_id "amumS7JM3qlhBlpwZyAV6gAAAPQ"]
[Thu Jul 30 14:30:19.340830 2026] [core:error] [pid 17707:tid 17950] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:30:19.340853 2026] [core:error] [pid 17707:tid 17950] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:30:19.520052 2026] [security2:error] [pid 17707:tid 17738] [remote 198.177.120.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.120.177.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "applinex.pro"] [uri "/xmlrpc.php"] [unique_id "amumS7JM3qlhBlpwZyAV9QAA9x4"]
[Thu Jul 30 14:30:19.520224 2026] [security2:error] [pid 17707:tid 17951] [client 198.177.120.174:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "applinex.pro"] [uri "/xmlrpc.php"] [unique_id "amumS7JM3qlhBlpwZyAV9QAA9x4"]
[Thu Jul 30 14:30:19.648087 2026] [security2:error] [pid 17707:tid 17885] [client 172.202.44.182:61534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/aaa.php"] [unique_id "amumS7JM3qlhBlpwZyAV_AAAALU"]
[Thu Jul 30 14:30:19.933085 2026] [security2:error] [pid 17707:tid 17842] [client 46.1.132.170:35898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.132.1.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adviseassociates.com"] [uri "/xmlrpc.php"] [unique_id "amumS7JM3qlhBlpwZyAV8QAAAIo"]
[Thu Jul 30 14:30:19.933214 2026] [security2:error] [pid 17707:tid 17842] [client 46.1.132.170:35898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adviseassociates.com"] [uri "/xmlrpc.php"] [unique_id "amumS7JM3qlhBlpwZyAV8QAAAIo"]
[Thu Jul 30 14:30:19.977602 2026] [security2:error] [pid 17707:tid 17935] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumS7JM3qlhBlpwZyAV7AAA5xg"]
[Thu Jul 30 14:30:20.183644 2026] [core:notice] [pid 17707:tid 17865] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:20.265367 2026] [core:notice] [pid 17707:tid 17927] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:20.531580 2026] [security2:error] [pid 17707:tid 17924] [client 172.202.44.182:38939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/getid3-core.php"] [unique_id "amumTLJM3qlhBlpwZyAWEAAAANw"]
[Thu Jul 30 14:30:20.663530 2026] [security2:error] [pid 17707:tid 17913] [client 52.238.199.152:52632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/plugins.php"] [unique_id "amumTLJM3qlhBlpwZyAWFQAAANE"]
[Thu Jul 30 14:30:20.821306 2026] [security2:error] [pid 17707:tid 17871] [client 177.6.106.101:54377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumTLJM3qlhBlpwZyAWGAAAAKc"]
[Thu Jul 30 14:30:20.821436 2026] [security2:error] [pid 17707:tid 17871] [client 177.6.106.101:54377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumTLJM3qlhBlpwZyAWGAAAAKc"]
[Thu Jul 30 14:30:21.021653 2026] [security2:error] [pid 17707:tid 17860] [client 74.7.175.167:37370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop-peace.com"] [uri "/robots.txt"] [unique_id "amumTbJM3qlhBlpwZyAWHAAAAJw"]
[Thu Jul 30 14:30:23.707652 2026] [security2:error] [pid 17707:tid 17853] [client 180.243.59.178:55276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumT7JM3qlhBlpwZyAWWAAAAJU"]
[Thu Jul 30 14:30:23.707778 2026] [security2:error] [pid 17707:tid 17853] [client 180.243.59.178:55276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumT7JM3qlhBlpwZyAWWAAAAJU"]
[Thu Jul 30 14:30:24.641687 2026] [core:notice] [pid 17707:tid 17779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:24.992208 2026] [core:notice] [pid 17707:tid 17784] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:25.235909 2026] [security2:error] [pid 17707:tid 17873] [client 103.168.67.159:46480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/index.php"] [unique_id "amumUbJM3qlhBlpwZyAWeAAAAKk"], referer: http://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:26.414246 2026] [security2:error] [pid 17707:tid 17919] [client 116.204.68.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amumUrJM3qlhBlpwZyAWlQAAANc"]
[Thu Jul 30 14:30:26.621295 2026] [security2:error] [pid 17707:tid 17907] [client 52.238.199.152:49649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/xxx.php"] [unique_id "amumUrJM3qlhBlpwZyAWoQAAAMs"]
[Thu Jul 30 14:30:26.787451 2026] [security2:error] [pid 17707:tid 17944] [client 172.202.44.182:38891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/adminer.php"] [unique_id "amumUrJM3qlhBlpwZyAWpQAAAPA"]
[Thu Jul 30 14:30:27.369558 2026] [core:notice] [pid 17707:tid 17802] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:28.590184 2026] [security2:error] [pid 17707:tid 17888] [client 172.202.44.182:11271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/alfa.php"] [unique_id "amumVLJM3qlhBlpwZyAW0QAAALg"]
[Thu Jul 30 14:30:30.834490 2026] [security2:error] [pid 17707:tid 17911] [client 52.238.199.152:16414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/css.php"] [unique_id "amumVrJM3qlhBlpwZyAXCwAAAM8"]
[Thu Jul 30 14:30:31.154413 2026] [security2:error] [pid 17707:tid 17958] [client 177.6.106.101:54860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumV7JM3qlhBlpwZyAXEQAAAP4"]
[Thu Jul 30 14:30:31.154630 2026] [security2:error] [pid 17707:tid 17958] [client 177.6.106.101:54860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumV7JM3qlhBlpwZyAXEQAAAP4"]
[Thu Jul 30 14:30:31.669873 2026] [security2:error] [pid 17707:tid 17919] [client 172.202.44.182:38900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amumV7JM3qlhBlpwZyAXIQAAANc"]
[Thu Jul 30 14:30:33.361321 2026] [core:notice] [pid 17707:tid 17732] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:33.547037 2026] [security2:error] [pid 17707:tid 17897] [client 103.231.91.59:38654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amumWbJM3qlhBlpwZyAXcQAAAME"]
[Thu Jul 30 14:30:33.547140 2026] [security2:error] [pid 17707:tid 17897] [client 103.231.91.59:38654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amumWbJM3qlhBlpwZyAXcQAAAME"]
[Thu Jul 30 14:30:33.745593 2026] [security2:error] [pid 17707:tid 17932] [client 172.202.44.182:11318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amumWbJM3qlhBlpwZyAXegAAAOQ"]
[Thu Jul 30 14:30:33.911336 2026] [security2:error] [pid 17707:tid 17928] [client 52.238.199.152:49604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amumWbJM3qlhBlpwZyAXggAAAOA"]
[Thu Jul 30 14:30:34.743532 2026] [security2:error] [pid 17707:tid 17908] [client 172.202.44.182:38886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amumWrJM3qlhBlpwZyAXmwAAAMw"]
[Thu Jul 30 14:30:35.106754 2026] [security2:error] [pid 17707:tid 17878] [client 180.243.59.178:55869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumW7JM3qlhBlpwZyAXrAAAAK4"]
[Thu Jul 30 14:30:35.106908 2026] [security2:error] [pid 17707:tid 17878] [client 180.243.59.178:55869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumW7JM3qlhBlpwZyAXrAAAAK4"]
[Thu Jul 30 14:30:35.685821 2026] [security2:error] [pid 17707:tid 17880] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumW7JM3qlhBlpwZyAXqgAAALA"]
[Thu Jul 30 14:30:35.706805 2026] [autoindex:error] [pid 17707:tid 17936] [client 141.148.153.213:0] AH01276: Cannot serve directory /home2/mbmudite/ok.otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:30:35.985661 2026] [security2:error] [pid 17707:tid 17924] [client 103.168.67.159:44208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/index.php"] [unique_id "amumW7JM3qlhBlpwZyAXxAAAANw"], referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:36.237455 2026] [security2:error] [pid 17707:tid 17913] [client 52.238.199.152:57940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amumXLJM3qlhBlpwZyAXyAAAANE"]
[Thu Jul 30 14:30:36.920947 2026] [security2:error] [pid 17707:tid 17921] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumXLJM3qlhBlpwZyAXyQAA2Uc"]
[Thu Jul 30 14:30:36.936891 2026] [security2:error] [pid 17707:tid 17930] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amumXLJM3qlhBlpwZyAX0gAAAOI"]
[Thu Jul 30 14:30:37.018732 2026] [core:error] [pid 17707:tid 17881] [client 103.168.67.159:44214] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:37.018757 2026] [core:error] [pid 17707:tid 17881] [client 103.168.67.159:44214] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:37.473459 2026] [security2:error] [pid 17707:tid 17798] [remote 40.77.167.77:51786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/680/429"] [unique_id "amumXbJM3qlhBlpwZyAX8AAAlFo"]
[Thu Jul 30 14:30:38.013970 2026] [core:error] [pid 17707:tid 17922] [client 103.168.67.159:44226] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:38.014003 2026] [core:error] [pid 17707:tid 17922] [client 103.168.67.159:44226] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:38.140883 2026] [security2:error] [pid 17707:tid 17862] [client 172.202.44.182:12202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/edit.php"] [unique_id "amumXrJM3qlhBlpwZyAYDgAAAJ4"]
[Thu Jul 30 14:30:38.290688 2026] [security2:error] [pid 17707:tid 17940] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amumXbJM3qlhBlpwZyAYBAAAAOw"]
[Thu Jul 30 14:30:38.466908 2026] [security2:error] [pid 17707:tid 17865] [client 189.156.226.90:26721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumXrJM3qlhBlpwZyAYDwAAAKE"]
[Thu Jul 30 14:30:38.467046 2026] [security2:error] [pid 17707:tid 17865] [client 189.156.226.90:26721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumXrJM3qlhBlpwZyAYDwAAAKE"]
[Thu Jul 30 14:30:39.075490 2026] [security2:error] [pid 17707:tid 17887] [client 52.238.199.152:52621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/images/index.php"] [unique_id "amumX7JM3qlhBlpwZyAYKwAAALc"]
[Thu Jul 30 14:30:39.372621 2026] [security2:error] [pid 17707:tid 17925] [client 74.7.228.18:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amumX7JM3qlhBlpwZyAYNAAAAN0"]
[Thu Jul 30 14:30:39.373363 2026] [security2:error] [pid 17707:tid 17942] [client 74.7.228.18:44358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amumX7JM3qlhBlpwZyAYMAAA7nM"]
[Thu Jul 30 14:30:40.039058 2026] [core:error] [pid 17707:tid 17912] [client 103.168.67.159:44238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:40.039091 2026] [core:error] [pid 17707:tid 17912] [client 103.168.67.159:44238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:40.128422 2026] [security2:error] [pid 17707:tid 17874] [client 52.238.199.152:52631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/network/about.php"] [unique_id "amumYLJM3qlhBlpwZyAYWQAAAKo"]
[Thu Jul 30 14:30:41.029308 2026] [core:error] [pid 17707:tid 17849] [client 103.168.67.159:44246] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:41.029327 2026] [core:error] [pid 17707:tid 17849] [client 103.168.67.159:44246] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:41.689483 2026] [security2:error] [pid 17707:tid 17900] [client 177.6.106.101:55413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumYbJM3qlhBlpwZyAYjAAAAMQ"]
[Thu Jul 30 14:30:41.700201 2026] [security2:error] [pid 17707:tid 17900] [client 177.6.106.101:55413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumYbJM3qlhBlpwZyAYjAAAAMQ"]
[Thu Jul 30 14:30:42.437635 2026] [security2:error] [pid 17707:tid 17937] [client 52.238.199.152:50174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/xpw.php"] [unique_id "amumYrJM3qlhBlpwZyAYnwAAAOk"]
[Thu Jul 30 14:30:43.351381 2026] [core:error] [pid 17707:tid 17960] [client 103.168.67.159:44250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:43.351405 2026] [core:error] [pid 17707:tid 17960] [client 103.168.67.159:44250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:44.277679 2026] [security2:error] [pid 17707:tid 17779] [remote 57.141.0.6:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amumZLJM3qlhBlpwZyAY2AAApEc"]
[Thu Jul 30 14:30:44.709780 2026] [security2:error] [pid 17707:tid 17949] [client 180.243.59.178:56515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumZLJM3qlhBlpwZyAY4QAAAPU"]
[Thu Jul 30 14:30:44.709889 2026] [security2:error] [pid 17707:tid 17949] [client 180.243.59.178:56515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumZLJM3qlhBlpwZyAY4QAAAPU"]
[Thu Jul 30 14:30:45.248643 2026] [core:error] [pid 17707:tid 17964] [client 103.168.67.159:51878] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:45.248677 2026] [core:error] [pid 17707:tid 17964] [client 103.168.67.159:51878] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:45.326312 2026] [security2:error] [pid 17707:tid 17875] [client 172.202.44.182:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/sf.php"] [unique_id "amumZbJM3qlhBlpwZyAY9QAAAKs"]
[Thu Jul 30 14:30:45.642606 2026] [security2:error] [pid 17707:tid 17910] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumZbJM3qlhBlpwZyAY7wAAAM4"]
[Thu Jul 30 14:30:45.662758 2026] [security2:error] [pid 17707:tid 17867] [client 52.238.199.152:50137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-cron.php"] [unique_id "amumZbJM3qlhBlpwZyAZAAAAAKM"]
[Thu Jul 30 14:30:45.924647 2026] [security2:error] [pid 17707:tid 17807] [remote 57.141.0.35:26028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amumZbJM3qlhBlpwZyAZBwABAGM"]
[Thu Jul 30 14:30:46.075767 2026] [security2:error] [pid 17707:tid 17893] [client 68.183.5.181:64130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "guethleentertainment.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amumZrJM3qlhBlpwZyAZDAAAAL0"]
[Thu Jul 30 14:30:46.241180 2026] [core:error] [pid 17707:tid 17911] [client 103.168.67.159:51894] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:46.241209 2026] [core:error] [pid 17707:tid 17911] [client 103.168.67.159:51894] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:46.955736 2026] [security2:error] [pid 17707:tid 17815] [remote 57.141.0.11:34058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amumZrJM3qlhBlpwZyAZKwAAsGs"]
[Thu Jul 30 14:30:47.018574 2026] [security2:error] [pid 17707:tid 17899] [client 85.208.96.199:32100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/federer-supera-sul-africano-de-virada-na-estreia-em-wimbledon/"] [unique_id "amumZ7JM3qlhBlpwZyAZLAAAAMM"]
[Thu Jul 30 14:30:47.018700 2026] [security2:error] [pid 17707:tid 17899] [client 85.208.96.199:32100] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/federer-supera-sul-africano-de-virada-na-estreia-em-wimbledon/"] [unique_id "amumZ7JM3qlhBlpwZyAZLAAAAMM"]
[Thu Jul 30 14:30:47.066988 2026] [security2:error] [pid 17707:tid 17918] [client 52.238.199.152:50175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/cah.php"] [unique_id "amumZ7JM3qlhBlpwZyAZMAAAANY"]
[Thu Jul 30 14:30:47.355477 2026] [core:error] [pid 17707:tid 17894] [client 103.168.67.159:51910] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:47.355499 2026] [core:error] [pid 17707:tid 17894] [client 103.168.67.159:51910] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:47.509106 2026] [proxy:error] [pid 17707:tid 17828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:30:47.509159 2026] [proxy_http:error] [pid 17707:tid 17828] [remote 91.92.241.196:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:30:47.509816 2026] [proxy:error] [pid 17707:tid 17828] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:30:47.509858 2026] [proxy_http:error] [pid 17707:tid 17828] [remote 91.92.241.196:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:30:47.716891 2026] [security2:error] [pid 17707:tid 17944] [client 172.202.44.182:38911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wso.php"] [unique_id "amumZ7JM3qlhBlpwZyAZQgAAAPA"]
[Thu Jul 30 14:30:48.031125 2026] [security2:error] [pid 17707:tid 17934] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.massageandspaislamabad.rest"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amumaLJM3qlhBlpwZyAZTwAAAOY"]
[Thu Jul 30 14:30:48.182809 2026] [security2:error] [pid 17707:tid 17962] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumZ7JM3qlhBlpwZyAZOwABAg4"]
[Thu Jul 30 14:30:48.378215 2026] [core:error] [pid 17707:tid 17847] [client 103.168.67.159:51918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:48.378239 2026] [core:error] [pid 17707:tid 17847] [client 103.168.67.159:51918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:48.705906 2026] [security2:error] [pid 17707:tid 17904] [client 189.156.226.90:27162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumaLJM3qlhBlpwZyAZYwAAAMg"]
[Thu Jul 30 14:30:48.706052 2026] [security2:error] [pid 17707:tid 17904] [client 189.156.226.90:27162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumaLJM3qlhBlpwZyAZYwAAAMg"]
[Thu Jul 30 14:30:48.780176 2026] [security2:error] [pid 17707:tid 17962] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumaLJM3qlhBlpwZyAZVAABAn0"]
[Thu Jul 30 14:30:49.831578 2026] [security2:error] [pid 17707:tid 17873] [client 172.202.44.182:12176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/ioxi-o.php"] [unique_id "amumabJM3qlhBlpwZyAZiAAAAKk"]
[Thu Jul 30 14:30:50.262619 2026] [security2:error] [pid 17707:tid 17902] [client 74.7.230.15:46542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-292cfc4e.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amumarJM3qlhBlpwZyAZmQAAxgs"]
[Thu Jul 30 14:30:51.108718 2026] [security2:error] [pid 17707:tid 17860] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumarJM3qlhBlpwZyAZnQAAAJw"]
[Thu Jul 30 14:30:52.296375 2026] [security2:error] [pid 17707:tid 17940] [client 177.6.106.101:56068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumbLJM3qlhBlpwZyAZ3AAAAOw"]
[Thu Jul 30 14:30:52.296609 2026] [security2:error] [pid 17707:tid 17940] [client 177.6.106.101:56068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumbLJM3qlhBlpwZyAZ3AAAAOw"]
[Thu Jul 30 14:30:52.923753 2026] [security2:error] [pid 17707:tid 17883] [client 52.238.199.152:17163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/cong.php"] [unique_id "amumbLJM3qlhBlpwZyAZ7gAAALM"]
[Thu Jul 30 14:30:53.356686 2026] [security2:error] [pid 17707:tid 17921] [client 172.202.44.182:12163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/file56.php"] [unique_id "amumbbJM3qlhBlpwZyAZ_QAAANk"]
[Thu Jul 30 14:30:53.535608 2026] [security2:error] [pid 17707:tid 17840] [client 103.168.67.159:46946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.smoke-tfhk.com"] [uri "/index.php"] [unique_id "amumbbJM3qlhBlpwZyAZ_gAAAIg"], referer: http://webdisk.smoke-tfhk.com/
[Thu Jul 30 14:30:53.985370 2026] [core:notice] [pid 17707:tid 17812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:30:54.136006 2026] [security2:error] [pid 17707:tid 17920] [client 127.0.0.1:60126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amumbrJM3qlhBlpwZyAaCgAAANg"]
[Thu Jul 30 14:30:54.136021 2026] [security2:error] [pid 17707:tid 17918] [client 74.7.228.30:58188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bah.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amumbrJM3qlhBlpwZyAaCQAAANY"]
[Thu Jul 30 14:30:54.243080 2026] [security2:error] [pid 17707:tid 17846] [client 172.202.44.182:38964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amumbrJM3qlhBlpwZyAaDwAAAI4"]
[Thu Jul 30 14:30:54.608395 2026] [security2:error] [pid 17707:tid 17841] [client 52.238.199.152:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/Sanskrit.php"] [unique_id "amumbrJM3qlhBlpwZyAaGgAAAIk"]
[Thu Jul 30 14:30:55.146910 2026] [security2:error] [pid 17707:tid 17820] [remote 116.179.37.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flixon.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amumbrJM3qlhBlpwZyAaJgAAq3A"], referer: https://flixon.net/video/the-rite-vj-junior/
[Thu Jul 30 14:30:55.770654 2026] [security2:error] [pid 17707:tid 17921] [client 107.189.2.5:48920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amumb7JM3qlhBlpwZyAaMwAAANk"]
[Thu Jul 30 14:30:55.970253 2026] [security2:error] [pid 17707:tid 17931] [client 180.243.59.178:57293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumb7JM3qlhBlpwZyAaPQAAAOM"]
[Thu Jul 30 14:30:55.970427 2026] [security2:error] [pid 17707:tid 17931] [client 180.243.59.178:57293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumb7JM3qlhBlpwZyAaPQAAAOM"]
[Thu Jul 30 14:30:56.074710 2026] [security2:error] [pid 17707:tid 17866] [client 107.189.2.5:49034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "amumcLJM3qlhBlpwZyAaQQAAAKI"]
[Thu Jul 30 14:30:56.077958 2026] [security2:error] [pid 17707:tid 17953] [client 107.189.2.5:48954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "amumcLJM3qlhBlpwZyAaQwAAAPk"]
[Thu Jul 30 14:30:56.084324 2026] [security2:error] [pid 17707:tid 17900] [client 107.189.2.5:48924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "amumcLJM3qlhBlpwZyAaRwAAAMQ"]
[Thu Jul 30 14:30:56.084399 2026] [security2:error] [pid 17707:tid 17916] [client 107.189.2.5:49020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "amumcLJM3qlhBlpwZyAaRgAAANQ"]
[Thu Jul 30 14:30:56.114186 2026] [security2:error] [pid 17707:tid 17928] [client 52.238.199.152:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ms-edit.php"] [unique_id "amumcLJM3qlhBlpwZyAaSQAAAOA"]
[Thu Jul 30 14:30:56.351877 2026] [security2:error] [pid 17707:tid 17893] [client 107.189.2.5:48968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "amumcLJM3qlhBlpwZyAaTQAAAL0"]
[Thu Jul 30 14:30:56.359098 2026] [security2:error] [pid 17707:tid 17826] [remote 57.141.0.26:34828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/5157"] [unique_id "amumcLJM3qlhBlpwZyAaTwAAsHY"]
[Thu Jul 30 14:30:56.375432 2026] [security2:error] [pid 17707:tid 17938] [client 107.189.2.5:48958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "amumcLJM3qlhBlpwZyAaVQAAAOo"]
[Thu Jul 30 14:30:56.375438 2026] [security2:error] [pid 17707:tid 17955] [client 107.189.2.5:48962] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "amumcLJM3qlhBlpwZyAaUQAAAPs"]
[Thu Jul 30 14:30:56.473488 2026] [security2:error] [pid 17707:tid 17845] [client 107.189.2.5:48954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "amumcLJM3qlhBlpwZyAaWgAAAI0"]
[Thu Jul 30 14:30:56.529691 2026] [security2:error] [pid 17707:tid 17886] [client 107.189.2.5:49034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "amumcLJM3qlhBlpwZyAaXwAAALY"]
[Thu Jul 30 14:30:56.557566 2026] [security2:error] [pid 17707:tid 17889] [client 107.189.2.5:49020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "amumcLJM3qlhBlpwZyAaYgAAALk"]
[Thu Jul 30 14:30:56.580259 2026] [security2:error] [pid 17707:tid 17912] [client 107.189.2.5:48924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "amumcLJM3qlhBlpwZyAaYwAAANA"]
[Thu Jul 30 14:30:56.743845 2026] [security2:error] [pid 17707:tid 17937] [client 107.189.2.5:48968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.openspacelab.tech"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "amumcLJM3qlhBlpwZyAaZAAAAOk"]
[Thu Jul 30 14:30:57.458052 2026] [security2:error] [pid 17707:tid 17817] [remote 74.7.243.224:40334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/img/stafff.php"] [unique_id "amumcbJM3qlhBlpwZyAafAAA220"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/img/main_image_6a2032acb13c3.jpg
[Thu Jul 30 14:30:57.812113 2026] [security2:error] [pid 17707:tid 17943] [client 172.202.44.182:38851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-admin/css/index.php"] [unique_id "amumcbJM3qlhBlpwZyAahAAAAO8"]
[Thu Jul 30 14:30:59.174436 2026] [security2:error] [pid 17707:tid 17865] [client 189.156.226.90:27707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumc7JM3qlhBlpwZyAaqwAAAKE"]
[Thu Jul 30 14:30:59.174543 2026] [security2:error] [pid 17707:tid 17865] [client 189.156.226.90:27707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumc7JM3qlhBlpwZyAaqwAAAKE"]
[Thu Jul 30 14:30:59.274871 2026] [security2:error] [pid 17707:tid 17846] [client 172.202.44.182:38919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/edit.php"] [unique_id "amumc7JM3qlhBlpwZyAarAAAAI4"]
[Thu Jul 30 14:30:59.505538 2026] [security2:error] [pid 17707:tid 17906] [client 43.157.53.115:36398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.53.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/"] [unique_id "amumc7JM3qlhBlpwZyAasAAAAMo"]
[Thu Jul 30 14:30:59.691246 2026] [security2:error] [pid 17707:tid 17933] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumc7JM3qlhBlpwZyAapwAA5Sk"]
[Thu Jul 30 14:31:00.118205 2026] [core:error] [pid 17707:tid 17942] [client 66.249.79.65:43110] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:31:00.118227 2026] [core:error] [pid 17707:tid 17942] [client 66.249.79.65:43110] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:31:00.961705 2026] [security2:error] [pid 17707:tid 17940] [client 172.202.44.182:12207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2.php"] [unique_id "amumdLJM3qlhBlpwZyAa0wAAAOw"]
[Thu Jul 30 14:31:01.090444 2026] [security2:error] [pid 17707:tid 17730] [remote 194.116.184.179:25466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amumdbJM3qlhBlpwZyAa2wAAlBY"]
[Thu Jul 30 14:31:01.565490 2026] [security2:error] [pid 17707:tid 17949] [client 57.141.0.29:51558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amumdbJM3qlhBlpwZyAa3wAA9SU"], referer: https://igetvape-australia.com/product/iget-moon-watermelon-ice/?add-to-cart=169
[Thu Jul 30 14:31:01.665850 2026] [security2:error] [pid 17707:tid 17738] [remote 57.141.0.62:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amumdbJM3qlhBlpwZyAa6AAA-R4"]
[Thu Jul 30 14:31:02.102235 2026] [security2:error] [pid 17707:tid 17889] [client 52.238.199.152:45591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/function.php"] [unique_id "amumdrJM3qlhBlpwZyAa8wAAALk"]
[Thu Jul 30 14:31:02.211576 2026] [security2:error] [pid 17707:tid 17963] [client 34.195.16.23:40639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amumdbJM3qlhBlpwZyAa7wAAAQM"]
[Thu Jul 30 14:31:02.368332 2026] [security2:error] [pid 17707:tid 17732] [remote 151.158.48.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.48.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannyplatoncuevas.com"] [uri "/wp-login.php"] [unique_id "amumdrJM3qlhBlpwZyAa-gAAzxg"]
[Thu Jul 30 14:31:02.821252 2026] [security2:error] [pid 17707:tid 17933] [client 177.6.106.101:56524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumdrJM3qlhBlpwZyAbBQAAAOU"]
[Thu Jul 30 14:31:02.821369 2026] [security2:error] [pid 17707:tid 17933] [client 177.6.106.101:56524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumdrJM3qlhBlpwZyAbBQAAAOU"]
[Thu Jul 30 14:31:03.209663 2026] [security2:error] [pid 17707:tid 17931] [client 185.191.171.10:47924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/11/20/paraiba-distribui-169-856-doses-de-vacina-contra-covid-19-e-garante-imunizantes-para-o-dia-d-de-vacinacao-neste-sabado/"] [unique_id "amumd7JM3qlhBlpwZyAbCQAAAOM"]
[Thu Jul 30 14:31:03.209763 2026] [security2:error] [pid 17707:tid 17931] [client 185.191.171.10:47924] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/11/20/paraiba-distribui-169-856-doses-de-vacina-contra-covid-19-e-garante-imunizantes-para-o-dia-d-de-vacinacao-neste-sabado/"] [unique_id "amumd7JM3qlhBlpwZyAbCQAAAOM"]
[Thu Jul 30 14:31:03.412760 2026] [security2:error] [pid 17707:tid 17938] [client 68.67.112.134:13622] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amumd7JM3qlhBlpwZyAbEAAAAOo"]
[Thu Jul 30 14:31:03.741895 2026] [security2:error] [pid 17707:tid 17879] [client 52.238.199.152:17167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ee.php"] [unique_id "amumd7JM3qlhBlpwZyAbFQAAAK8"]
[Thu Jul 30 14:31:04.155894 2026] [security2:error] [pid 17707:tid 17853] [client 172.202.44.182:11950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/wp-content/uploads/admin.php"] [unique_id "amumeLJM3qlhBlpwZyAbHwAAAJU"]
[Thu Jul 30 14:31:04.678814 2026] [core:notice] [pid 17707:tid 17774] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:04.999716 2026] [core:notice] [pid 17707:tid 17765] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:05.483855 2026] [security2:error] [pid 17707:tid 17754] [remote 57.141.0.34:42112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amumebJM3qlhBlpwZyAbQwAAiC4"]
[Thu Jul 30 14:31:06.348006 2026] [security2:error] [pid 17707:tid 17837] [client 180.243.59.178:57832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumerJM3qlhBlpwZyAbTwAAAIU"]
[Thu Jul 30 14:31:06.348118 2026] [security2:error] [pid 17707:tid 17837] [client 180.243.59.178:57832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumerJM3qlhBlpwZyAbTwAAAIU"]
[Thu Jul 30 14:31:06.563871 2026] [security2:error] [pid 17707:tid 17850] [client 172.202.44.182:38883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/mah.php"] [unique_id "amumerJM3qlhBlpwZyAbWAAAAJI"]
[Thu Jul 30 14:31:06.869879 2026] [core:error] [pid 17707:tid 17787] [remote 74.7.175.153:51204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:31:06.869903 2026] [core:error] [pid 17707:tid 17787] [remote 74.7.175.153:51204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:31:06.870093 2026] [security2:error] [pid 17707:tid 17886] [client 74.7.175.153:51204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-1774b2ed.lld.nyx.temporary.site"] [uri "/website_1774b2ed/index.php"] [unique_id "amumerJM3qlhBlpwZyAbWwAAtk8"]
[Thu Jul 30 14:31:07.188580 2026] [security2:error] [pid 17707:tid 17947] [client 116.68.203.120:56218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.203.68.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adbacklink.com"] [uri "/xmlrpc.php"] [unique_id "amume7JM3qlhBlpwZyAbZAAAAPM"]
[Thu Jul 30 14:31:07.188781 2026] [security2:error] [pid 17707:tid 17947] [client 116.68.203.120:56218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adbacklink.com"] [uri "/xmlrpc.php"] [unique_id "amume7JM3qlhBlpwZyAbZAAAAPM"]
[Thu Jul 30 14:31:07.551382 2026] [security2:error] [pid 17707:tid 17902] [client 172.202.44.182:11942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/send.php"] [unique_id "amume7JM3qlhBlpwZyAbawAAAMY"]
[Thu Jul 30 14:31:07.923328 2026] [security2:error] [pid 17707:tid 17950] [client 43.173.176.168:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/11/les-pochettes-de-latelier-st-loup-pour-les-ultrabook-toshiba/"] [unique_id "amume7JM3qlhBlpwZyAbcwAAAPY"]
[Thu Jul 30 14:31:08.079287 2026] [security2:error] [pid 17707:tid 17958] [client 43.172.195.81:40662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/02/22/cosmoparis-collection-chaussures-printemps-ete-2012/"] [unique_id "amume7JM3qlhBlpwZyAbcgAAAP4"]
[Thu Jul 30 14:31:08.316169 2026] [security2:error] [pid 17707:tid 17871] [client 54.219.192.251:12279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amumebJM3qlhBlpwZyAbRwAAAKc"]
[Thu Jul 30 14:31:08.369119 2026] [core:notice] [pid 17707:tid 17904] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:08.374708 2026] [security2:error] [pid 17707:tid 17904] [client 43.173.175.60:57128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/05/11/les-pochettes-de-latelier-st-loup-pour-les-ultrabook-toshiba/"] [unique_id "amumfLJM3qlhBlpwZyAbfwAAAMg"], referer: https://carnetdeshopping.com/index.php/2013/05/11/les-pochettes-de-latelier-st-loup-pour-les-ultrabook-toshiba/
[Thu Jul 30 14:31:08.672889 2026] [security2:error] [pid 17707:tid 17901] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumfLJM3qlhBlpwZyAbfAAAxVM"]
[Thu Jul 30 14:31:08.732190 2026] [core:notice] [pid 17707:tid 17943] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:08.812950 2026] [core:notice] [pid 17707:tid 17892] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:08.817591 2026] [security2:error] [pid 17707:tid 17892] [client 43.172.198.125:38742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/02/22/cosmoparis-collection-chaussures-printemps-ete-2012/"] [unique_id "amumfLJM3qlhBlpwZyAbiwAAALw"], referer: https://carnetdeshopping.com/index.php/2012/02/22/cosmoparis-collection-chaussures-printemps-ete-2012/
[Thu Jul 30 14:31:09.123932 2026] [core:notice] [pid 17707:tid 17801] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:09.234163 2026] [security2:error] [pid 17707:tid 17881] [client 74.7.228.38:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fyi.nyx.temporary.site"] [uri "/index.php"] [unique_id "amume7JM3qlhBlpwZyAbcQAAALE"]
[Thu Jul 30 14:31:09.235185 2026] [security2:error] [pid 17707:tid 17963] [client 74.7.228.38:55970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fyi.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amume7JM3qlhBlpwZyAbbwABA0A"]
[Thu Jul 30 14:31:09.499014 2026] [security2:error] [pid 17707:tid 17932] [client 52.238.199.152:45597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/new.php"] [unique_id "amumfbJM3qlhBlpwZyAbnAAAAOQ"]
[Thu Jul 30 14:31:09.742806 2026] [security2:error] [pid 17707:tid 17850] [client 189.156.226.90:27516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumfbJM3qlhBlpwZyAbpgAAAJI"]
[Thu Jul 30 14:31:09.742947 2026] [security2:error] [pid 17707:tid 17850] [client 189.156.226.90:27516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumfbJM3qlhBlpwZyAbpgAAAJI"]
[Thu Jul 30 14:31:10.480344 2026] [security2:error] [pid 17707:tid 17961] [client 52.238.199.152:16336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-config.php"] [unique_id "amumfrJM3qlhBlpwZyAb0QAAAQE"]
[Thu Jul 30 14:31:11.188761 2026] [security2:error] [pid 17707:tid 17901] [client 198.235.24.255:50154] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "sh00085.hostgator.com"] [uri "/"] [unique_id "amumf7JM3qlhBlpwZyAb5AAAAMU"]
[Thu Jul 30 14:31:11.388105 2026] [security2:error] [pid 17707:tid 17955] [client 52.238.199.152:16898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-conflg.php"] [unique_id "amumf7JM3qlhBlpwZyAb5QAAAPs"]
[Thu Jul 30 14:31:11.766891 2026] [security2:error] [pid 17707:tid 17911] [client 166.205.97.96:32287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumfrJM3qlhBlpwZyAbwQAAz2c"], referer: https://jwcpartners.org/contact/
[Thu Jul 30 14:31:11.767328 2026] [security2:error] [pid 17707:tid 17911] [client 166.205.97.96:32287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumfrJM3qlhBlpwZyAbvgAAz3E"], referer: https://jwcpartners.org/contact/
[Thu Jul 30 14:31:11.768271 2026] [security2:error] [pid 17707:tid 17911] [client 166.205.97.96:32287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumfrJM3qlhBlpwZyAbyQAAz3M"], referer: https://jwcpartners.org/contact/
[Thu Jul 30 14:31:12.723347 2026] [core:notice] [pid 17707:tid 17908] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:13.190826 2026] [security2:error] [pid 17707:tid 17950] [client 52.238.199.152:16365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amumgbJM3qlhBlpwZyAcDQAAAPY"]
[Thu Jul 30 14:31:13.304208 2026] [security2:error] [pid 17707:tid 17960] [client 116.179.32.72:54327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9388"] [unique_id "amumgbJM3qlhBlpwZyAcCQAAAQA"]
[Thu Jul 30 14:31:13.645851 2026] [core:notice] [pid 17707:tid 17868] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:13.646360 2026] [security2:error] [pid 17707:tid 17753] [remote 47.128.27.88:33156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/"] [unique_id "amumgbJM3qlhBlpwZyAcFQAAlC0"]
[Thu Jul 30 14:31:13.726241 2026] [security2:error] [pid 17707:tid 17927] [client 74.7.244.20:35522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "essenceeast.com"] [uri "/cgi-sys/404.html"] [unique_id "amumgbJM3qlhBlpwZyAcGQAA3xo"]
[Thu Jul 30 14:31:13.994622 2026] [security2:error] [pid 17707:tid 17857] [client 119.249.100.109:54134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9388"] [unique_id "amumgbJM3qlhBlpwZyAcIQAAAJk"]
[Thu Jul 30 14:31:14.352138 2026] [core:notice] [pid 17707:tid 17861] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:14.454021 2026] [autoindex:error] [pid 17707:tid 17906] [client 66.249.64.110:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:31:14.714969 2026] [security2:error] [pid 17707:tid 17929] [client 119.249.100.174:42786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9388"] [unique_id "amumgrJM3qlhBlpwZyAcOwAAAOE"]
[Thu Jul 30 14:31:14.770135 2026] [security2:error] [pid 17707:tid 17886] [client 52.238.199.152:16771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amumgrJM3qlhBlpwZyAcPwAAALY"]
[Thu Jul 30 14:31:14.966259 2026] [core:notice] [pid 17707:tid 17951] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:16.265962 2026] [security2:error] [pid 17707:tid 17893] [client 180.243.59.178:58326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumhLJM3qlhBlpwZyAcXgAAAL0"]
[Thu Jul 30 14:31:16.266124 2026] [security2:error] [pid 17707:tid 17893] [client 180.243.59.178:58326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumhLJM3qlhBlpwZyAcXgAAAL0"]
[Thu Jul 30 14:31:16.325526 2026] [security2:error] [pid 17707:tid 17859] [client 74.7.241.147:53556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "03.adtop.net"] [uri "/robots.txt"] [unique_id "amumhLJM3qlhBlpwZyAcXwAAmxA"]
[Thu Jul 30 14:31:16.490989 2026] [core:notice] [pid 17707:tid 17845] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:17.070971 2026] [security2:error] [pid 17707:tid 17901] [client 116.179.33.75:62221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.33.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9388"] [unique_id "amumhLJM3qlhBlpwZyAcbQAAAMU"]
[Thu Jul 30 14:31:17.173878 2026] [security2:error] [pid 17707:tid 17938] [client 166.205.97.96:32287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumhLJM3qlhBlpwZyAcdAAA6jo"], referer: https://jwcpartners.org/events/
[Thu Jul 30 14:31:17.174065 2026] [security2:error] [pid 17707:tid 17938] [client 166.205.97.96:32287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumhLJM3qlhBlpwZyAccwAA6ic"], referer: https://jwcpartners.org/events/
[Thu Jul 30 14:31:17.177710 2026] [security2:error] [pid 17707:tid 17938] [client 166.205.97.96:32287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumhLJM3qlhBlpwZyAcdQAA6kI"], referer: https://jwcpartners.org/events/
[Thu Jul 30 14:31:17.412807 2026] [core:notice] [pid 17707:tid 17952] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:17.753810 2026] [core:notice] [pid 17707:tid 17912] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:17.775649 2026] [core:notice] [pid 17707:tid 17850] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:18.880626 2026] [security2:error] [pid 17707:tid 17915] [client 166.205.97.96:32287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumhrJM3qlhBlpwZyAcoAAA008"]
[Thu Jul 30 14:31:19.018798 2026] [security2:error] [pid 17707:tid 17915] [client 166.205.97.96:32287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumhrJM3qlhBlpwZyAcnwAA00U"]
[Thu Jul 30 14:31:19.019007 2026] [security2:error] [pid 17707:tid 17915] [client 166.205.97.96:32287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumhrJM3qlhBlpwZyAcogAA00Y"]
[Thu Jul 30 14:31:20.261780 2026] [security2:error] [pid 17707:tid 17929] [client 189.156.226.90:26955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumiLJM3qlhBlpwZyAc0QAAAOE"]
[Thu Jul 30 14:31:20.261880 2026] [security2:error] [pid 17707:tid 17929] [client 189.156.226.90:26955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumiLJM3qlhBlpwZyAc0QAAAOE"]
[Thu Jul 30 14:31:21.039631 2026] [core:notice] [pid 17707:tid 17923] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:21.513596 2026] [security2:error] [pid 17707:tid 17874] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumiLJM3qlhBlpwZyAc3AAAql8"]
[Thu Jul 30 14:31:22.421578 2026] [security2:error] [pid 17707:tid 17955] [client 20.104.18.253:7286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dirs.php"] [unique_id "amumirJM3qlhBlpwZyAc_QAAAPs"]
[Thu Jul 30 14:31:22.433405 2026] [core:notice] [pid 17707:tid 17848] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:23.068332 2026] [security2:error] [pid 17707:tid 17938] [client 20.226.5.174:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pki-validationalfa.php"] [unique_id "amumi7JM3qlhBlpwZyAdDgAAAOo"]
[Thu Jul 30 14:31:23.077709 2026] [security2:error] [pid 17707:tid 17937] [client 20.104.18.253:7236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/disagimons.php"] [unique_id "amumi7JM3qlhBlpwZyAdEAAAAOk"]
[Thu Jul 30 14:31:23.316032 2026] [security2:error] [pid 17707:tid 17907] [client 52.238.199.152:17219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amumi7JM3qlhBlpwZyAdEQAAAMs"]
[Thu Jul 30 14:31:23.680272 2026] [security2:error] [pid 17707:tid 17844] [client 20.104.18.253:7266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/disagraeosc.php"] [unique_id "amumi7JM3qlhBlpwZyAdHQAAAIw"]
[Thu Jul 30 14:31:23.760231 2026] [core:notice] [pid 17707:tid 17902] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:23.970374 2026] [security2:error] [pid 17707:tid 17882] [client 37.236.10.221:33472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumi7JM3qlhBlpwZyAdHAAAALI"], referer: http://pkf.jo
[Thu Jul 30 14:31:23.971369 2026] [security2:error] [pid 17707:tid 17929] [client 177.6.106.101:54002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumi7JM3qlhBlpwZyAdJgAAAOE"]
[Thu Jul 30 14:31:23.971469 2026] [security2:error] [pid 17707:tid 17929] [client 177.6.106.101:54002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumi7JM3qlhBlpwZyAdJgAAAOE"]
[Thu Jul 30 14:31:24.296123 2026] [security2:error] [pid 17707:tid 17883] [client 20.104.18.253:7261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/disagreop.php"] [unique_id "amumjLJM3qlhBlpwZyAdKgAAALM"]
[Thu Jul 30 14:31:24.529354 2026] [security2:error] [pid 17707:tid 17950] [client 20.226.5.174:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pki-validationbypass.php"] [unique_id "amumjLJM3qlhBlpwZyAdMQAAAPY"]
[Thu Jul 30 14:31:24.851564 2026] [security2:error] [pid 17707:tid 17880] [client 90.51.217.64:37648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumjLJM3qlhBlpwZyAdMgAAALA"], referer: http://pkf.jo
[Thu Jul 30 14:31:24.901999 2026] [security2:error] [pid 17707:tid 17845] [client 20.104.18.253:7762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/about.php"] [unique_id "amumjLJM3qlhBlpwZyAdPAAAAI0"]
[Thu Jul 30 14:31:25.339557 2026] [security2:error] [pid 17707:tid 17837] [client 119.2.125.197:28011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumjbJM3qlhBlpwZyAdRAAAAIU"], referer: http://pkf.jo
[Thu Jul 30 14:31:25.485767 2026] [core:notice] [pid 17707:tid 17932] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:25.502874 2026] [security2:error] [pid 17707:tid 17841] [client 20.104.18.253:7806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/alfa-rex.php"] [unique_id "amumjbJM3qlhBlpwZyAdTAAAAIk"]
[Thu Jul 30 14:31:25.589220 2026] [security2:error] [pid 17707:tid 17954] [client 52.238.199.152:17265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amumjbJM3qlhBlpwZyAdUAAAAPo"]
[Thu Jul 30 14:31:25.674119 2026] [security2:error] [pid 17707:tid 17930] [client 20.226.5.174:51028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pki-validationk.php"] [unique_id "amumjbJM3qlhBlpwZyAdVAAAAOI"]
[Thu Jul 30 14:31:26.102194 2026] [security2:error] [pid 17707:tid 17909] [client 20.104.18.253:7254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/autoload_classmap.php"] [unique_id "amumjrJM3qlhBlpwZyAdXQAAAM0"]
[Thu Jul 30 14:31:26.114447 2026] [security2:error] [pid 17707:tid 17947] [client 50.65.222.58:57432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumjbJM3qlhBlpwZyAdVQAAAPM"], referer: http://pkf.jo
[Thu Jul 30 14:31:26.178460 2026] [security2:error] [pid 17707:tid 17896] [client 103.100.7.248:4816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumjbJM3qlhBlpwZyAdVgAAAMA"], referer: http://pkf.jo
[Thu Jul 30 14:31:26.567380 2026] [security2:error] [pid 17707:tid 17925] [client 179.25.114.249:56876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumjrJM3qlhBlpwZyAdYQAAAN0"], referer: http://pkf.jo
[Thu Jul 30 14:31:26.567414 2026] [security2:error] [pid 17707:tid 17898] [client 144.172.138.151:51390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumjrJM3qlhBlpwZyAdYgAAAMI"], referer: http://pkf.jo
[Thu Jul 30 14:31:26.722319 2026] [security2:error] [pid 17707:tid 17842] [client 20.104.18.253:7260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/block-library/admin.php"] [unique_id "amumjrJM3qlhBlpwZyAdbAAAAIo"]
[Thu Jul 30 14:31:26.801300 2026] [security2:error] [pid 17707:tid 17915] [client 180.243.59.178:58888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumjrJM3qlhBlpwZyAdbQAAANM"]
[Thu Jul 30 14:31:26.801417 2026] [security2:error] [pid 17707:tid 17915] [client 180.243.59.178:58888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumjrJM3qlhBlpwZyAdbQAAANM"]
[Thu Jul 30 14:31:26.820393 2026] [security2:error] [pid 17707:tid 17882] [client 20.226.5.174:51021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pki-validationwp.php"] [unique_id "amumjrJM3qlhBlpwZyAdbgAAALI"]
[Thu Jul 30 14:31:27.347148 2026] [security2:error] [pid 17707:tid 17857] [client 20.104.18.253:7256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/components/about.php"] [unique_id "amumj7JM3qlhBlpwZyAdewAAAJk"]
[Thu Jul 30 14:31:27.618220 2026] [core:error] [pid 17707:tid 17716] [remote 157.143.3.35:37876] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:31:27.618245 2026] [core:error] [pid 17707:tid 17716] [remote 157.143.3.35:37876] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:31:27.904766 2026] [security2:error] [pid 17707:tid 17919] [client 20.226.5.174:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pler.php"] [unique_id "amumj7JM3qlhBlpwZyAdiwAAANc"]
[Thu Jul 30 14:31:27.944302 2026] [security2:error] [pid 17707:tid 17861] [client 20.104.18.253:7243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/default.php"] [unique_id "amumj7JM3qlhBlpwZyAdjAAAAJ0"]
[Thu Jul 30 14:31:28.236203 2026] [security2:error] [pid 17707:tid 17893] [client 52.238.199.152:50453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/manager.php"] [unique_id "amumkLJM3qlhBlpwZyAdmgAAAL0"]
[Thu Jul 30 14:31:28.588764 2026] [security2:error] [pid 17707:tid 17914] [client 20.104.18.253:7249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/edit-site/about.php"] [unique_id "amumkLJM3qlhBlpwZyAdpgAAANI"]
[Thu Jul 30 14:31:28.951905 2026] [security2:error] [pid 17707:tid 17960] [client 20.226.5.174:51020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pluggable.php"] [unique_id "amumkLJM3qlhBlpwZyAdsQAAAQA"]
[Thu Jul 30 14:31:29.210046 2026] [security2:error] [pid 17707:tid 17874] [client 20.104.18.253:7271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/edit-widgets/about.php"] [unique_id "amumkbJM3qlhBlpwZyAduwAAAKo"]
[Thu Jul 30 14:31:29.491390 2026] [security2:error] [pid 17707:tid 17904] [client 45.243.192.84:55467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumkbJM3qlhBlpwZyAduQAAAMg"], referer: http://pkf.jo
[Thu Jul 30 14:31:29.619416 2026] [security2:error] [pid 17707:tid 17838] [client 196.119.119.132:44082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumkbJM3qlhBlpwZyAdvAAAAIY"], referer: http://pkf.jo
[Thu Jul 30 14:31:29.788571 2026] [security2:error] [pid 17707:tid 17941] [client 185.213.229.44:64585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumkbJM3qlhBlpwZyAdwAAAAO0"], referer: http://pkf.jo
[Thu Jul 30 14:31:29.834367 2026] [security2:error] [pid 17707:tid 17953] [client 20.104.18.253:7281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/edit-widgets/index.php"] [unique_id "amumkbJM3qlhBlpwZyAd0AAAAPk"]
[Thu Jul 30 14:31:30.080379 2026] [security2:error] [pid 17707:tid 17873] [client 20.226.5.174:51024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/plugin-install.php.INFECTED.php"] [unique_id "amumkrJM3qlhBlpwZyAd3wAAAKk"]
[Thu Jul 30 14:31:30.260578 2026] [security2:error] [pid 17707:tid 17910] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumkbJM3qlhBlpwZyAdsgAAzhA"]
[Thu Jul 30 14:31:30.335689 2026] [security2:error] [pid 17707:tid 17956] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumkbJM3qlhBlpwZyAdzAAAAPw"]
[Thu Jul 30 14:31:30.449468 2026] [security2:error] [pid 17707:tid 17875] [client 20.104.18.253:7749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/list-reusable-blocks/themes.php"] [unique_id "amumkrJM3qlhBlpwZyAeAgAAAKs"]
[Thu Jul 30 14:31:30.733602 2026] [security2:error] [pid 17707:tid 17855] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amumkrJM3qlhBlpwZyAeBwAAAJc"]
[Thu Jul 30 14:31:30.735251 2026] [security2:error] [pid 17707:tid 17847] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumkbJM3qlhBlpwZyAdwQAAjzw"]
[Thu Jul 30 14:31:30.788937 2026] [security2:error] [pid 17707:tid 17944] [client 52.238.199.152:17245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-links.php"] [unique_id "amumkrJM3qlhBlpwZyAeDAAAAPA"]
[Thu Jul 30 14:31:30.803999 2026] [security2:error] [pid 17707:tid 17914] [client 189.156.226.90:27182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumkrJM3qlhBlpwZyAeDQAAANI"]
[Thu Jul 30 14:31:30.804097 2026] [security2:error] [pid 17707:tid 17914] [client 189.156.226.90:27182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumkrJM3qlhBlpwZyAeDQAAANI"]
[Thu Jul 30 14:31:31.052413 2026] [security2:error] [pid 17707:tid 17959] [client 20.104.18.253:7241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/niil.php"] [unique_id "amumk7JM3qlhBlpwZyAeFAAAAP8"]
[Thu Jul 30 14:31:31.336283 2026] [security2:error] [pid 17707:tid 17960] [client 20.226.5.174:51010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/plugin.php"] [unique_id "amumk7JM3qlhBlpwZyAeHAAAAQA"]
[Thu Jul 30 14:31:31.694110 2026] [security2:error] [pid 17707:tid 17894] [client 20.104.18.253:7689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/test.php"] [unique_id "amumk7JM3qlhBlpwZyAeLwAAAL4"]
[Thu Jul 30 14:31:31.891186 2026] [security2:error] [pid 17707:tid 17901] [client 196.170.19.124:60924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumk7JM3qlhBlpwZyAeJgAAAMU"], referer: http://pkf.jo
[Thu Jul 30 14:31:31.997926 2026] [security2:error] [pid 17707:tid 17872] [client 196.124.69.147:58530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumk7JM3qlhBlpwZyAeMAAAAKg"], referer: http://pkf.jo
[Thu Jul 30 14:31:32.099738 2026] [security2:error] [pid 17707:tid 17848] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumk7JM3qlhBlpwZyAeIwAAkF8"]
[Thu Jul 30 14:31:32.675410 2026] [security2:error] [pid 17707:tid 17903] [client 20.226.5.174:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/plugins.php"] [unique_id "amumlLJM3qlhBlpwZyAeZgAAAMc"]
[Thu Jul 30 14:31:32.804664 2026] [security2:error] [pid 17707:tid 17962] [client 20.104.18.253:7726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/vendor/vcard.php"] [unique_id "amumlLJM3qlhBlpwZyAekAAAAQI"]
[Thu Jul 30 14:31:32.941307 2026] [security2:error] [pid 17707:tid 17893] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumlLJM3qlhBlpwZyAeUAAAAL0"]
[Thu Jul 30 14:31:33.174646 2026] [security2:error] [pid 17707:tid 17860] [client 153.117.34.96:57943] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumlLJM3qlhBlpwZyAekQAAAJw"], referer: http://pkf.jo
[Thu Jul 30 14:31:33.441772 2026] [security2:error] [pid 17707:tid 17888] [client 20.104.18.253:7716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/widgets/about.php"] [unique_id "amumlbJM3qlhBlpwZyAeowAAALg"]
[Thu Jul 30 14:31:34.094820 2026] [security2:error] [pid 17707:tid 17866] [client 20.226.5.174:51029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/plugins/bless.php"] [unique_id "amumlrJM3qlhBlpwZyAeuAAAAKI"]
[Thu Jul 30 14:31:34.327895 2026] [security2:error] [pid 17707:tid 17911] [client 20.104.18.253:7252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dist/wp-login.php"] [unique_id "amumlrJM3qlhBlpwZyAetwAAAM8"]
[Thu Jul 30 14:31:34.714579 2026] [security2:error] [pid 17707:tid 17857] [client 177.6.106.101:54583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumlrJM3qlhBlpwZyAeywAAAJk"]
[Thu Jul 30 14:31:34.714736 2026] [security2:error] [pid 17707:tid 17857] [client 177.6.106.101:54583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumlrJM3qlhBlpwZyAeywAAAJk"]
[Thu Jul 30 14:31:34.810854 2026] [security2:error] [pid 17707:tid 17851] [client 52.238.199.152:33508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/fi2.php"] [unique_id "amumlrJM3qlhBlpwZyAezQAAAJM"]
[Thu Jul 30 14:31:34.931095 2026] [security2:error] [pid 17707:tid 17878] [client 20.104.18.253:7686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/distadmin.php"] [unique_id "amumlrJM3qlhBlpwZyAezgAAAK4"]
[Thu Jul 30 14:31:35.221773 2026] [security2:error] [pid 17707:tid 17908] [client 20.226.5.174:51032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/plugins/filemanager/dialog.php"] [unique_id "amuml7JM3qlhBlpwZyAe1QAAAMw"]
[Thu Jul 30 14:31:35.568326 2026] [security2:error] [pid 17707:tid 17880] [client 20.104.18.253:7722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/distalfa.php"] [unique_id "amuml7JM3qlhBlpwZyAfAgAAALA"]
[Thu Jul 30 14:31:36.188228 2026] [security2:error] [pid 17707:tid 17895] [client 20.104.18.253:7764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/distbypass.php"] [unique_id "amummLJM3qlhBlpwZyAfFwAAAL8"]
[Thu Jul 30 14:31:36.483282 2026] [security2:error] [pid 17707:tid 17922] [client 20.226.5.174:51009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/plugins/zvwbset/shell.php"] [unique_id "amummLJM3qlhBlpwZyAfRgAAANo"]
[Thu Jul 30 14:31:36.501930 2026] [security2:error] [pid 17707:tid 17838] [client 64.43.142.2:49672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amummLJM3qlhBlpwZyAfGAAAAIY"], referer: http://pkf.jo
[Thu Jul 30 14:31:36.803288 2026] [security2:error] [pid 17707:tid 17964] [client 20.104.18.253:7684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/distk.php"] [unique_id "amummLJM3qlhBlpwZyAfUgAAAQQ"]
[Thu Jul 30 14:31:37.318959 2026] [security2:error] [pid 17707:tid 17892] [client 180.243.59.178:59448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amummbJM3qlhBlpwZyAfYgAAALw"]
[Thu Jul 30 14:31:37.319086 2026] [security2:error] [pid 17707:tid 17892] [client 180.243.59.178:59448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amummbJM3qlhBlpwZyAfYgAAALw"]
[Thu Jul 30 14:31:37.329388 2026] [security2:error] [pid 17707:tid 17869] [client 81.30.97.68:52470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amummbJM3qlhBlpwZyAfWAAAAKU"], referer: http://pkf.jo
[Thu Jul 30 14:31:37.353553 2026] [core:notice] [pid 17707:tid 17710] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:37.490427 2026] [security2:error] [pid 17707:tid 17946] [client 20.104.18.253:7730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/distwp.php"] [unique_id "amummbJM3qlhBlpwZyAfaAAAAPI"]
[Thu Jul 30 14:31:37.600464 2026] [core:notice] [pid 17707:tid 17785] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:38.107801 2026] [security2:error] [pid 17707:tid 17907] [client 20.104.18.253:7737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/doc.php"] [unique_id "amummrJM3qlhBlpwZyAffAAAAMs"]
[Thu Jul 30 14:31:38.131248 2026] [security2:error] [pid 17707:tid 17937] [client 20.226.5.174:51030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pluginsadmin.php"] [unique_id "amummrJM3qlhBlpwZyAfgAAAAOk"]
[Thu Jul 30 14:31:38.270693 2026] [security2:error] [pid 17707:tid 17860] [client 8.242.151.240:36768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amummbJM3qlhBlpwZyAfegAAAJw"], referer: http://pkf.jo
[Thu Jul 30 14:31:38.748530 2026] [security2:error] [pid 17707:tid 17920] [client 20.104.18.253:7727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/docadmin.php"] [unique_id "amummrJM3qlhBlpwZyAfkgAAANg"]
[Thu Jul 30 14:31:39.020772 2026] [security2:error] [pid 17707:tid 17861] [client 44.194.139.149:11490] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/03/bebeanuciado2-4998626-400x300.jpg"] [unique_id "amumm7JM3qlhBlpwZyAflwAAAJ0"]
[Thu Jul 30 14:31:39.422542 2026] [security2:error] [pid 17707:tid 17964] [client 20.226.5.174:51025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pluginsalfa.php"] [unique_id "amumm7JM3qlhBlpwZyAfogAAAQQ"]
[Thu Jul 30 14:31:39.440776 2026] [security2:error] [pid 17707:tid 17853] [client 20.104.18.253:7527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/docalfa.php"] [unique_id "amumm7JM3qlhBlpwZyAfowAAAJU"]
[Thu Jul 30 14:31:39.649914 2026] [security2:error] [pid 17707:tid 17887] [client 81.163.126.220:37432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumm7JM3qlhBlpwZyAfoQAAALc"], referer: http://pkf.jo
[Thu Jul 30 14:31:39.738922 2026] [core:notice] [pid 17707:tid 17921] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:40.093663 2026] [security2:error] [pid 17707:tid 17957] [client 20.104.18.253:7539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/docbypass.php"] [unique_id "amumnLJM3qlhBlpwZyAftgAAAP0"]
[Thu Jul 30 14:31:40.529225 2026] [security2:error] [pid 17707:tid 17923] [client 20.226.5.174:51036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pluginsbypass.php"] [unique_id "amumnLJM3qlhBlpwZyAfvwAAANs"]
[Thu Jul 30 14:31:40.759015 2026] [security2:error] [pid 17707:tid 17958] [client 20.104.18.253:7881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/docindex.php"] [unique_id "amumnLJM3qlhBlpwZyAfxgAAAP4"]
[Thu Jul 30 14:31:41.319032 2026] [security2:error] [pid 17707:tid 17840] [client 189.156.226.90:27487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumnbJM3qlhBlpwZyAf0QAAAIg"]
[Thu Jul 30 14:31:41.319162 2026] [security2:error] [pid 17707:tid 17840] [client 189.156.226.90:27487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumnbJM3qlhBlpwZyAf0QAAAIg"]
[Thu Jul 30 14:31:41.377926 2026] [security2:error] [pid 17707:tid 17893] [client 20.104.18.253:7883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dock.php"] [unique_id "amumnbJM3qlhBlpwZyAf1AAAAL0"]
[Thu Jul 30 14:31:41.701415 2026] [security2:error] [pid 17707:tid 17883] [client 20.226.5.174:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pluginsk.php"] [unique_id "amumnbJM3qlhBlpwZyAf4QAAALM"]
[Thu Jul 30 14:31:41.774673 2026] [security2:error] [pid 17707:tid 17845] [client 54.166.104.83:46760] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/1337/03b582de739016fb16a1762ce47ce55b.jpg"] [unique_id "amumnbJM3qlhBlpwZyAf5AAAAI0"]
[Thu Jul 30 14:31:41.980721 2026] [security2:error] [pid 17707:tid 17849] [client 20.104.18.253:7878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/docsadmin.php"] [unique_id "amumnbJM3qlhBlpwZyAf5wAAAJE"]
[Thu Jul 30 14:31:42.333153 2026] [security2:error] [pid 17707:tid 17898] [client 49.36.239.24:53040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumnbJM3qlhBlpwZyAf0wAAAMI"], referer: http://pkf.jo
[Thu Jul 30 14:31:42.423788 2026] [security2:error] [pid 17707:tid 17947] [client 114.119.130.221:34125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/product-tag/plush"] [unique_id "amumnrJM3qlhBlpwZyAf8gAAAPM"], referer: https://happyspree.app/product/happy-fit-plush-monster-toy
[Thu Jul 30 14:31:42.571613 2026] [security2:error] [pid 17707:tid 17867] [client 72.136.109.97:48356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumnrJM3qlhBlpwZyAf8AAAAKM"], referer: http://pkf.jo
[Thu Jul 30 14:31:42.588669 2026] [security2:error] [pid 17707:tid 17956] [client 20.104.18.253:7899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/docsalfa.php"] [unique_id "amumnrJM3qlhBlpwZyAf9gAAAPw"]
[Thu Jul 30 14:31:42.863312 2026] [security2:error] [pid 17707:tid 17905] [client 20.226.5.174:51041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/plupload/priv.php"] [unique_id "amumnrJM3qlhBlpwZyAgAwAAAMk"]
[Thu Jul 30 14:31:43.507249 2026] [security2:error] [pid 17707:tid 17876] [client 105.156.105.42:41920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumn7JM3qlhBlpwZyAgEgAAAKw"], referer: http://pkf.jo
[Thu Jul 30 14:31:44.028331 2026] [security2:error] [pid 17707:tid 17949] [client 99.231.177.180:37698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumn7JM3qlhBlpwZyAgIgAAAPU"], referer: http://pkf.jo
[Thu Jul 30 14:31:44.125880 2026] [security2:error] [pid 17707:tid 17872] [client 103.231.91.59:58502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amumoLJM3qlhBlpwZyAgKwAAAKg"]
[Thu Jul 30 14:31:44.126018 2026] [security2:error] [pid 17707:tid 17872] [client 103.231.91.59:58502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amumoLJM3qlhBlpwZyAgKwAAAKg"]
[Thu Jul 30 14:31:44.374166 2026] [security2:error] [pid 17707:tid 17866] [client 52.238.199.152:33503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/0x.php"] [unique_id "amumoLJM3qlhBlpwZyAgMwAAAKI"]
[Thu Jul 30 14:31:44.444934 2026] [security2:error] [pid 17707:tid 17880] [client 181.122.69.183:49462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumoLJM3qlhBlpwZyAgLAAAALA"], referer: http://pkf.jo
[Thu Jul 30 14:31:44.955292 2026] [security2:error] [pid 17707:tid 17857] [client 20.226.5.174:51027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/plupload/wp-login.php"] [unique_id "amumoLJM3qlhBlpwZyAgRgAAAJk"]
[Thu Jul 30 14:31:45.211115 2026] [security2:error] [pid 17707:tid 17874] [client 177.6.106.101:55112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumobJM3qlhBlpwZyAgTAAAAKo"]
[Thu Jul 30 14:31:45.216808 2026] [security2:error] [pid 17707:tid 17874] [client 177.6.106.101:55112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumobJM3qlhBlpwZyAgTAAAAKo"]
[Thu Jul 30 14:31:45.653314 2026] [security2:error] [pid 17707:tid 17935] [client 52.238.199.152:33519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/k.php"] [unique_id "amumobJM3qlhBlpwZyAgVQAAAOc"]
[Thu Jul 30 14:31:45.937363 2026] [security2:error] [pid 17707:tid 17960] [client 20.226.5.174:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pm.php"] [unique_id "amumobJM3qlhBlpwZyAgXwAAAQA"]
[Thu Jul 30 14:31:46.429124 2026] [security2:error] [pid 17707:tid 17727] [remote 40.77.167.23:7124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/2024/07/05/misionf.php"] [unique_id "amumorJM3qlhBlpwZyAgbgAAkhM"]
[Thu Jul 30 14:31:46.711174 2026] [security2:error] [pid 17707:tid 17898] [client 66.249.74.162:48046] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "tereasshop.com"] [uri "/robots.txt"] [unique_id "amumorJM3qlhBlpwZyAgdQAAAMI"]
[Thu Jul 30 14:31:46.968791 2026] [security2:error] [pid 17707:tid 17866] [client 52.238.199.152:33473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/gecko-new.php"] [unique_id "amumorJM3qlhBlpwZyAgegAAAKI"]
[Thu Jul 30 14:31:47.020955 2026] [core:notice] [pid 17707:tid 17858] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:47.104203 2026] [security2:error] [pid 17707:tid 17932] [client 20.226.5.174:51011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pmaxwhng.php"] [unique_id "amumo7JM3qlhBlpwZyAgfwAAAOQ"]
[Thu Jul 30 14:31:47.345517 2026] [security2:error] [pid 17707:tid 17733] [remote 57.141.18.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amumo7JM3qlhBlpwZyAgiAAA6xk"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,lycra,nylon,plastic,polyester,steel&filter_size=large,medium,small&min_price=75&max_price=125&unfilter=1
[Thu Jul 30 14:31:47.585147 2026] [security2:error] [pid 17707:tid 17732] [remote 57.141.18.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amumo7JM3qlhBlpwZyAghgAAuRg"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,cotton,lycra,nylon,plastic,polyester,steel&filter_size=large,medium,small&min_price=75&max_price=125&unfilter=1
[Thu Jul 30 14:31:47.631556 2026] [security2:error] [pid 17707:tid 17840] [client 196.191.112.241:20840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumo7JM3qlhBlpwZyAghwAAAIg"], referer: http://pkf.jo
[Thu Jul 30 14:31:47.678632 2026] [core:notice] [pid 17707:tid 17723] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:47.881218 2026] [security2:error] [pid 17707:tid 17924] [client 180.243.59.178:59990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumo7JM3qlhBlpwZyAgkwAAANw"]
[Thu Jul 30 14:31:47.881409 2026] [security2:error] [pid 17707:tid 17924] [client 180.243.59.178:59990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumo7JM3qlhBlpwZyAgkwAAANw"]
[Thu Jul 30 14:31:48.156551 2026] [core:notice] [pid 17707:tid 17945] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:31:48.686827 2026] [security2:error] [pid 17707:tid 17929] [client 20.226.5.174:51033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pn.php"] [unique_id "amumpLJM3qlhBlpwZyAgpgAAAOE"]
[Thu Jul 30 14:31:48.761371 2026] [security2:error] [pid 17707:tid 17874] [client 52.238.199.152:52533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/alfanew.php"] [unique_id "amumpLJM3qlhBlpwZyAgpwAAAKo"]
[Thu Jul 30 14:31:50.149718 2026] [security2:error] [pid 17707:tid 17860] [client 20.226.5.174:51031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/png.php"] [unique_id "amumprJM3qlhBlpwZyAgygAAAJw"]
[Thu Jul 30 14:31:50.579500 2026] [security2:error] [pid 17707:tid 17919] [client 172.237.109.114:34566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amumpbJM3qlhBlpwZyAgyQAAANc"], referer: http://alseermarine.com:80/index.html
[Thu Jul 30 14:31:50.976159 2026] [security2:error] [pid 17707:tid 17875] [client 196.189.157.101:20860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumprJM3qlhBlpwZyAg2wAAAKs"], referer: http://pkf.jo
[Thu Jul 30 14:31:51.173960 2026] [security2:error] [pid 17707:tid 17913] [client 20.226.5.174:51050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/poj.php"] [unique_id "amump7JM3qlhBlpwZyAg6gAAANE"]
[Thu Jul 30 14:31:51.840002 2026] [security2:error] [pid 17707:tid 17840] [client 138.186.250.32:38060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amump7JM3qlhBlpwZyAg9AAAAIg"], referer: http://pkf.jo
[Thu Jul 30 14:31:51.843267 2026] [security2:error] [pid 17707:tid 17841] [client 189.156.226.90:26788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amump7JM3qlhBlpwZyAg-QAAAIk"]
[Thu Jul 30 14:31:51.843364 2026] [security2:error] [pid 17707:tid 17841] [client 189.156.226.90:26788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amump7JM3qlhBlpwZyAg-QAAAIk"]
[Thu Jul 30 14:31:52.032074 2026] [core:error] [pid 17707:tid 17869] [client 74.7.241.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:31:52.032099 2026] [core:error] [pid 17707:tid 17869] [client 74.7.241.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:31:52.032237 2026] [security2:error] [pid 17707:tid 17869] [client 74.7.241.152:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.ojq.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amumqLJM3qlhBlpwZyAhBgAAAKU"]
[Thu Jul 30 14:31:52.033276 2026] [security2:error] [pid 17707:tid 17859] [client 74.7.241.152:54564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.ojq.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amumqLJM3qlhBlpwZyAhBAAAm0o"]
[Thu Jul 30 14:31:52.146407 2026] [proxy:error] [pid 17707:tid 17784] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:31:52.146466 2026] [proxy_http:error] [pid 17707:tid 17784] [remote 74.7.241.176:52584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:31:52.147057 2026] [proxy:error] [pid 17707:tid 17784] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:31:52.147102 2026] [proxy_http:error] [pid 17707:tid 17784] [remote 74.7.241.176:52584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:31:52.577066 2026] [security2:error] [pid 17707:tid 17960] [client 20.226.5.174:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pomo.php"] [unique_id "amumqLJM3qlhBlpwZyAhEgAAAQA"]
[Thu Jul 30 14:31:52.620278 2026] [security2:error] [pid 17707:tid 17951] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumqLJM3qlhBlpwZyAhAAAAAPc"]
[Thu Jul 30 14:31:52.917341 2026] [security2:error] [pid 17707:tid 17874] [client 103.231.91.59:50732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amumqLJM3qlhBlpwZyAhFwAAAKo"]
[Thu Jul 30 14:31:52.917443 2026] [security2:error] [pid 17707:tid 17874] [client 103.231.91.59:50732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amumqLJM3qlhBlpwZyAhFwAAAKo"]
[Thu Jul 30 14:31:52.997888 2026] [security2:error] [pid 17707:tid 17780] [remote 165.101.254.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.254.101.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aashlawfirm.com"] [uri "/xmlrpc.php"] [unique_id "amumqLJM3qlhBlpwZyAhEwAAy0g"]
[Thu Jul 30 14:31:52.998096 2026] [security2:error] [pid 17707:tid 17907] [client 165.101.254.178:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aashlawfirm.com"] [uri "/xmlrpc.php"] [unique_id "amumqLJM3qlhBlpwZyAhEwAAy0g"]
[Thu Jul 30 14:31:53.241566 2026] [security2:error] [pid 17707:tid 17839] [client 52.238.199.152:16269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/text.php"] [unique_id "amumqbJM3qlhBlpwZyAhHgAAAIc"]
[Thu Jul 30 14:31:53.708696 2026] [security2:error] [pid 17707:tid 17858] [client 198.12.60.40:12428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumqbJM3qlhBlpwZyAhIgAAAJo"], referer: http://pkf.jo
[Thu Jul 30 14:31:54.635196 2026] [ssl:error] [pid 17707:tid 17844] [client 185.226.197.48:51380] AH02032: Hostname w-sal.com provided via SNI and hostname www.kendarikomputer.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://w-sal.com/
[Thu Jul 30 14:31:55.078839 2026] [security2:error] [pid 17707:tid 17860] [client 70.54.72.238:59090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumqrJM3qlhBlpwZyAhQQAAAJw"], referer: http://pkf.jo
[Thu Jul 30 14:31:55.205051 2026] [security2:error] [pid 17707:tid 17861] [client 98.97.76.182:17576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumqrJM3qlhBlpwZyAhRgAAAJ0"], referer: http://pkf.jo
[Thu Jul 30 14:31:55.276052 2026] [security2:error] [pid 17707:tid 17865] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumqrJM3qlhBlpwZyAhQAAAoXY"]
[Thu Jul 30 14:31:55.590674 2026] [security2:error] [pid 17707:tid 17857] [client 20.226.5.174:51035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pongs.php"] [unique_id "amumq7JM3qlhBlpwZyAhVgAAAJk"]
[Thu Jul 30 14:31:55.922171 2026] [security2:error] [pid 17707:tid 17849] [client 52.238.199.152:52481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/f.php"] [unique_id "amumq7JM3qlhBlpwZyAhWgAAAJE"]
[Thu Jul 30 14:31:55.938277 2026] [security2:error] [pid 17707:tid 17963] [client 177.6.106.101:55639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumq7JM3qlhBlpwZyAhWwAAAQM"]
[Thu Jul 30 14:31:55.938394 2026] [security2:error] [pid 17707:tid 17963] [client 177.6.106.101:55639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumq7JM3qlhBlpwZyAhWwAAAQM"]
[Thu Jul 30 14:31:55.981537 2026] [security2:error] [pid 17707:tid 17814] [remote 216.73.217.142:21684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amumq7JM3qlhBlpwZyAhXwAArWo"]
[Thu Jul 30 14:31:56.276551 2026] [security2:error] [pid 17707:tid 17932] [client 170.83.79.22:34330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumq7JM3qlhBlpwZyAhYAAAAOQ"], referer: http://pkf.jo
[Thu Jul 30 14:31:57.034819 2026] [security2:error] [pid 17707:tid 17844] [client 52.238.199.152:3944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amumrbJM3qlhBlpwZyAhdwAAAIw"]
[Thu Jul 30 14:31:57.341927 2026] [security2:error] [pid 17707:tid 17855] [client 20.226.5.174:51047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pop.php"] [unique_id "amumrbJM3qlhBlpwZyAhgAAAAJc"]
[Thu Jul 30 14:31:57.845433 2026] [security2:error] [pid 17707:tid 17951] [client 177.47.127.129:49178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumrbJM3qlhBlpwZyAhhAAAAPc"], referer: http://pkf.jo
[Thu Jul 30 14:31:58.052753 2026] [security2:error] [pid 17707:tid 17711] [remote 74.7.243.224:48666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/img/stafff.php"] [unique_id "amumrrJM3qlhBlpwZyAhjgAAlQM"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/img/main_image_6a2032acb13c3.jpg
[Thu Jul 30 14:31:58.099326 2026] [security2:error] [pid 17707:tid 17878] [client 201.77.97.241:45608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumrbJM3qlhBlpwZyAhiwAAAK4"], referer: http://pkf.jo
[Thu Jul 30 14:31:58.341843 2026] [security2:error] [pid 17707:tid 17867] [client 180.243.59.178:60530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumrrJM3qlhBlpwZyAhmwAAAKM"]
[Thu Jul 30 14:31:58.342003 2026] [security2:error] [pid 17707:tid 17867] [client 180.243.59.178:60530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumrrJM3qlhBlpwZyAhmwAAAKM"]
[Thu Jul 30 14:31:58.586169 2026] [security2:error] [pid 17707:tid 17840] [client 52.238.199.152:33481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/hehe.php"] [unique_id "amumrrJM3qlhBlpwZyAhnwAAAIg"]
[Thu Jul 30 14:31:59.580836 2026] [security2:error] [pid 17707:tid 17961] [client 20.226.5.174:51049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/porthall.php"] [unique_id "amumr7JM3qlhBlpwZyAhsQAAAQE"]
[Thu Jul 30 14:32:00.079326 2026] [security2:error] [pid 17707:tid 17915] [client 52.238.199.152:33521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/options.php"] [unique_id "amumsLJM3qlhBlpwZyAhtQAAANM"]
[Thu Jul 30 14:32:00.714291 2026] [security2:error] [pid 17707:tid 17868] [client 20.226.5.174:51045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/post.php"] [unique_id "amumsLJM3qlhBlpwZyAhxgAAAKQ"]
[Thu Jul 30 14:32:01.141865 2026] [security2:error] [pid 17707:tid 17848] [client 52.238.199.152:16279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amumsbJM3qlhBlpwZyAhzQAAAJA"]
[Thu Jul 30 14:32:01.422959 2026] [security2:error] [pid 17707:tid 17902] [client 127.0.0.1:30506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amumsbJM3qlhBlpwZyAh2AAAAMY"]
[Thu Jul 30 14:32:01.422998 2026] [security2:error] [pid 17707:tid 17929] [client 74.7.244.32:50174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.zbj.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amumsbJM3qlhBlpwZyAh1wAAAOE"]
[Thu Jul 30 14:32:02.019391 2026] [security2:error] [pid 17707:tid 17905] [client 20.226.5.174:51037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/postfs.php"] [unique_id "amumsrJM3qlhBlpwZyAh4wAAAMk"]
[Thu Jul 30 14:32:02.426238 2026] [security2:error] [pid 17707:tid 17956] [client 189.156.226.90:26989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumsrJM3qlhBlpwZyAh7QAAAPw"]
[Thu Jul 30 14:32:02.426347 2026] [security2:error] [pid 17707:tid 17956] [client 189.156.226.90:26989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumsrJM3qlhBlpwZyAh7QAAAPw"]
[Thu Jul 30 14:32:03.466598 2026] [core:notice] [pid 17707:tid 17746] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:03.696327 2026] [security2:error] [pid 17707:tid 17734] [remote 57.141.0.7:24354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amums7JM3qlhBlpwZyAiBQAAlxo"]
[Thu Jul 30 14:32:04.224547 2026] [security2:error] [pid 17707:tid 17907] [client 136.239.213.130:54094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.213.239.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/xmlrpc.php"] [unique_id "amumtLJM3qlhBlpwZyAiEwAAAMs"]
[Thu Jul 30 14:32:04.224717 2026] [security2:error] [pid 17707:tid 17907] [client 136.239.213.130:54094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abs-sa.net"] [uri "/xmlrpc.php"] [unique_id "amumtLJM3qlhBlpwZyAiEwAAAMs"]
[Thu Jul 30 14:32:04.949322 2026] [security2:error] [pid 17707:tid 17838] [client 20.226.5.174:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/postnews.php"] [unique_id "amumtLJM3qlhBlpwZyAiJAAAAIY"]
[Thu Jul 30 14:32:06.209457 2026] [security2:error] [pid 17707:tid 17846] [client 20.226.5.174:51015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pow.php"] [unique_id "amumtrJM3qlhBlpwZyAiQAAAAI4"]
[Thu Jul 30 14:32:06.292016 2026] [security2:error] [pid 17707:tid 17869] [client 177.6.106.101:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumtrJM3qlhBlpwZyAiQQAAAKU"]
[Thu Jul 30 14:32:06.293146 2026] [security2:error] [pid 17707:tid 17869] [client 177.6.106.101:56196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumtrJM3qlhBlpwZyAiQQAAAKU"]
[Thu Jul 30 14:32:06.811668 2026] [security2:error] [pid 17707:tid 17853] [client 217.64.127.195:37270] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amumtrJM3qlhBlpwZyAiUAAAAJU"]
[Thu Jul 30 14:32:06.811791 2026] [security2:error] [pid 17707:tid 17853] [client 217.64.127.195:37270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amumtrJM3qlhBlpwZyAiUAAAAJU"]
[Thu Jul 30 14:32:06.911861 2026] [core:notice] [pid 17707:tid 17899] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:06.916945 2026] [security2:error] [pid 17707:tid 17899] [client 66.249.79.2:38664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/citationstylelanguage/get/turabian-fullnote-bibliography"] [unique_id "amumtrJM3qlhBlpwZyAiSQAAAMM"]
[Thu Jul 30 14:32:07.346054 2026] [security2:error] [pid 17707:tid 17958] [client 93.70.169.241:15872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amumt7JM3qlhBlpwZyAiUQAAAP4"], referer: http://pkf.jo
[Thu Jul 30 14:32:07.516767 2026] [security2:error] [pid 17707:tid 17851] [client 20.226.5.174:51053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/pow12.php"] [unique_id "amumt7JM3qlhBlpwZyAiWwAAAJM"]
[Thu Jul 30 14:32:08.311492 2026] [security2:error] [pid 17707:tid 17896] [client 52.238.199.152:16287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/images/index.php"] [unique_id "amumuLJM3qlhBlpwZyAicgAAAMA"]
[Thu Jul 30 14:32:08.934284 2026] [security2:error] [pid 17707:tid 17789] [remote 216.24.210.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.210.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalrelaxspa.sbs"] [uri "/wp-login.php"] [unique_id "amumuLJM3qlhBlpwZyAiegAAlFE"]
[Thu Jul 30 14:32:09.048437 2026] [core:notice] [pid 17707:tid 17864] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:09.331632 2026] [security2:error] [pid 17707:tid 17901] [client 34.90.199.112:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/assets/upload/img/icon.webp"] [unique_id "amumubJM3qlhBlpwZyAijAAAAMU"]
[Thu Jul 30 14:32:09.331743 2026] [security2:error] [pid 17707:tid 17901] [client 34.90.199.112:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/assets/upload/img/icon.webp"] [unique_id "amumubJM3qlhBlpwZyAijAAAAMU"]
[Thu Jul 30 14:32:09.724607 2026] [security2:error] [pid 17707:tid 17952] [client 180.243.59.178:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumubJM3qlhBlpwZyAimwAAAPg"]
[Thu Jul 30 14:32:09.724731 2026] [security2:error] [pid 17707:tid 17952] [client 180.243.59.178:61123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumubJM3qlhBlpwZyAimwAAAPg"]
[Thu Jul 30 14:32:09.882414 2026] [security2:error] [pid 17707:tid 17798] [remote 103.28.36.168:49518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-aa23bb9f.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amumubJM3qlhBlpwZyAikwAA21o"]
[Thu Jul 30 14:32:10.541658 2026] [security2:error] [pid 17707:tid 17867] [client 166.205.97.96:43532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumurJM3qlhBlpwZyAiqgAAozc"], referer: https://jwcpartners.org/events/
[Thu Jul 30 14:32:10.542078 2026] [security2:error] [pid 17707:tid 17867] [client 166.205.97.96:43532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumurJM3qlhBlpwZyAiqwAAo1I"], referer: https://jwcpartners.org/events/
[Thu Jul 30 14:32:10.577787 2026] [security2:error] [pid 17707:tid 17903] [client 172.237.109.114:7394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amumubJM3qlhBlpwZyAioQAAAMc"]
[Thu Jul 30 14:32:10.740729 2026] [security2:error] [pid 17707:tid 17867] [client 166.205.97.96:43532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jwcpartners.org"] [uri "/index.php"] [unique_id "amumurJM3qlhBlpwZyAisgAAo3M"], referer: https://jwcpartners.org/events/
[Thu Jul 30 14:32:11.442670 2026] [security2:error] [pid 17707:tid 17949] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumurJM3qlhBlpwZyAixAAA9Wg"]
[Thu Jul 30 14:32:11.846349 2026] [security2:error] [pid 17707:tid 17945] [client 52.238.199.152:33505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amumu7JM3qlhBlpwZyAi2gAAAPE"]
[Thu Jul 30 14:32:12.539774 2026] [security2:error] [pid 17707:tid 17839] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumu7JM3qlhBlpwZyAi4AAAAIc"]
[Thu Jul 30 14:32:12.716180 2026] [security2:error] [pid 17707:tid 17895] [client 20.52.125.110:4290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/geju.php"] [unique_id "amumvLJM3qlhBlpwZyAi7QAAAL8"]
[Thu Jul 30 14:32:12.935371 2026] [security2:error] [pid 17707:tid 17858] [client 189.156.226.90:27290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumvLJM3qlhBlpwZyAi9wAAAJo"]
[Thu Jul 30 14:32:12.935483 2026] [security2:error] [pid 17707:tid 17858] [client 189.156.226.90:27290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumvLJM3qlhBlpwZyAi9wAAAJo"]
[Thu Jul 30 14:32:13.075178 2026] [security2:error] [pid 17707:tid 17940] [client 52.238.199.152:33534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/13.php"] [unique_id "amumvbJM3qlhBlpwZyAi-AAAAOw"]
[Thu Jul 30 14:32:13.445089 2026] [security2:error] [pid 17707:tid 17924] [client 20.52.125.110:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amumvbJM3qlhBlpwZyAi_wAAANw"]
[Thu Jul 30 14:32:13.990475 2026] [security2:error] [pid 17707:tid 17964] [client 20.52.125.110:4303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp.php"] [unique_id "amumvbJM3qlhBlpwZyAjDQAAAQQ"]
[Thu Jul 30 14:32:14.421514 2026] [security2:error] [pid 17707:tid 17927] [client 52.238.199.152:16268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/inputs.php"] [unique_id "amumvrJM3qlhBlpwZyAjFwAAAN8"]
[Thu Jul 30 14:32:14.880225 2026] [security2:error] [pid 17707:tid 17917] [client 253.150.151.192:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "embassyofitalyislamabad.vip"] [uri "/wp-login.php"] [unique_id "amumvrJM3qlhBlpwZyAjHwAA1Qk"], referer: https://embassyofitalyislamabad.vip/wp-login.php
[Thu Jul 30 14:32:14.897551 2026] [security2:error] [pid 17707:tid 17910] [client 20.52.125.110:2271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/aaa.php"] [unique_id "amumvrJM3qlhBlpwZyAjIAAAAM4"]
[Thu Jul 30 14:32:15.728439 2026] [security2:error] [pid 17707:tid 17958] [client 127.0.0.1:54312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amumv7JM3qlhBlpwZyAjOAAAAP4"]
[Thu Jul 30 14:32:15.728458 2026] [security2:error] [pid 17707:tid 17911] [client 127.0.0.1:54296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.nsp.djb.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amumv7JM3qlhBlpwZyAjNwAAAM8"]
[Thu Jul 30 14:32:15.728715 2026] [security2:error] [pid 17707:tid 17950] [client 74.7.241.160:40562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.nsp.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amumv7JM3qlhBlpwZyAjNgAA9nQ"]
[Thu Jul 30 14:32:15.933295 2026] [security2:error] [pid 17707:tid 17919] [client 20.52.125.110:2250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/hoot.php"] [unique_id "amumv7JM3qlhBlpwZyAjOQAAANc"]
[Thu Jul 30 14:32:15.953420 2026] [security2:error] [pid 17707:tid 17912] [client 52.238.199.152:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/jquery.php"] [unique_id "amumv7JM3qlhBlpwZyAjOgAAANA"]
[Thu Jul 30 14:32:16.178409 2026] [security2:error] [pid 17707:tid 17730] [remote 216.73.217.142:12591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amumwLJM3qlhBlpwZyAjRAAAjRY"]
[Thu Jul 30 14:32:16.836315 2026] [security2:error] [pid 17707:tid 17918] [client 20.52.125.110:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/about.php"] [unique_id "amumwLJM3qlhBlpwZyAjUQAAANY"]
[Thu Jul 30 14:32:17.098502 2026] [security2:error] [pid 17707:tid 17865] [client 177.6.106.101:56855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumwbJM3qlhBlpwZyAjWAAAAKE"]
[Thu Jul 30 14:32:17.098618 2026] [security2:error] [pid 17707:tid 17865] [client 177.6.106.101:56855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumwbJM3qlhBlpwZyAjWAAAAKE"]
[Thu Jul 30 14:32:17.364025 2026] [security2:error] [pid 17707:tid 17842] [client 52.238.199.152:16260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/doc.php"] [unique_id "amumwbJM3qlhBlpwZyAjXwAAAIo"]
[Thu Jul 30 14:32:17.746325 2026] [security2:error] [pid 17707:tid 17925] [client 217.64.127.195:37266] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amumwbJM3qlhBlpwZyAjaQAAAN0"]
[Thu Jul 30 14:32:17.746424 2026] [security2:error] [pid 17707:tid 17925] [client 217.64.127.195:37266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amumwbJM3qlhBlpwZyAjaQAAAN0"]
[Thu Jul 30 14:32:17.983051 2026] [security2:error] [pid 17707:tid 17931] [client 20.52.125.110:2253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/admin.php"] [unique_id "amumwbJM3qlhBlpwZyAjagAAAOM"]
[Thu Jul 30 14:32:18.305253 2026] [security2:error] [pid 17707:tid 17864] [client 52.238.199.152:16294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/02.php"] [unique_id "amumwrJM3qlhBlpwZyAjdAAAAKA"]
[Thu Jul 30 14:32:19.750332 2026] [security2:error] [pid 17707:tid 17946] [client 52.238.199.152:42003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/well-known/admin.php"] [unique_id "amumw7JM3qlhBlpwZyAjkgAAAPI"]
[Thu Jul 30 14:32:20.071431 2026] [security2:error] [pid 17707:tid 17910] [client 180.243.59.178:61652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumxLJM3qlhBlpwZyAjlgAAAM4"]
[Thu Jul 30 14:32:20.071607 2026] [security2:error] [pid 17707:tid 17910] [client 180.243.59.178:61652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumxLJM3qlhBlpwZyAjlgAAAM4"]
[Thu Jul 30 14:32:20.683399 2026] [security2:error] [pid 17707:tid 17723] [remote 216.73.217.142:12591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amumxLJM3qlhBlpwZyAjowAA4A8"]
[Thu Jul 30 14:32:20.873301 2026] [security2:error] [pid 17707:tid 17885] [client 20.52.125.110:4293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amumxLJM3qlhBlpwZyAjrQAAALU"]
[Thu Jul 30 14:32:21.008566 2026] [security2:error] [pid 17707:tid 17844] [client 52.238.199.152:52516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/v.php"] [unique_id "amumxbJM3qlhBlpwZyAjsQAAAIw"]
[Thu Jul 30 14:32:21.698798 2026] [security2:error] [pid 17707:tid 17941] [client 20.52.125.110:2246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/db-cache.php"] [unique_id "amumxbJM3qlhBlpwZyAjvQAAAO0"]
[Thu Jul 30 14:32:22.208039 2026] [security2:error] [pid 17707:tid 17899] [client 20.52.125.110:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amumxrJM3qlhBlpwZyAjywAAAMM"]
[Thu Jul 30 14:32:22.983837 2026] [security2:error] [pid 17707:tid 17851] [client 20.52.125.110:4314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amumxrJM3qlhBlpwZyAj4gAAAJM"]
[Thu Jul 30 14:32:23.457638 2026] [core:notice] [pid 17707:tid 17843] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:23.541309 2026] [security2:error] [pid 17707:tid 17928] [client 189.156.226.90:27579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumx7JM3qlhBlpwZyAj8gAAAOA"]
[Thu Jul 30 14:32:23.541432 2026] [security2:error] [pid 17707:tid 17928] [client 189.156.226.90:27579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amumx7JM3qlhBlpwZyAj8gAAAOA"]
[Thu Jul 30 14:32:23.782559 2026] [security2:error] [pid 17707:tid 17787] [remote 94.23.188.205:56814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.urwru.club"] [uri "/sitemap.xml"] [unique_id "amumx7JM3qlhBlpwZyAj9wAAkU8"]
[Thu Jul 30 14:32:23.782771 2026] [security2:error] [pid 17707:tid 17849] [client 94.23.188.205:56814] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/sitemap.xml"] [unique_id "amumx7JM3qlhBlpwZyAj9wAAkU8"]
[Thu Jul 30 14:32:23.924397 2026] [core:notice] [pid 17707:tid 17926] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:23.979718 2026] [core:notice] [pid 17707:tid 17954] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:24.022499 2026] [core:notice] [pid 17707:tid 17859] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:24.484611 2026] [core:notice] [pid 17707:tid 17923] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:24.547509 2026] [core:notice] [pid 17707:tid 17949] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:24.551872 2026] [security2:error] [pid 17707:tid 17904] [client 20.52.125.110:4304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amumyLJM3qlhBlpwZyAkEAAAAMg"]
[Thu Jul 30 14:32:24.817616 2026] [security2:error] [pid 17707:tid 17910] [client 52.238.199.152:16300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/main.php"] [unique_id "amumyLJM3qlhBlpwZyAkEgAAAM4"]
[Thu Jul 30 14:32:25.706180 2026] [security2:error] [pid 17707:tid 17839] [client 20.52.125.110:2254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amumybJM3qlhBlpwZyAkKAAAAIc"]
[Thu Jul 30 14:32:26.024841 2026] [core:notice] [pid 17707:tid 17888] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:26.458374 2026] [security2:error] [pid 17707:tid 17890] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amumybJM3qlhBlpwZyAkKwAAALo"]
[Thu Jul 30 14:32:26.472220 2026] [security2:error] [pid 17707:tid 17956] [client 37.140.254.6:40001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.254.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/archivarix.cms.php"] [unique_id "amumyrJM3qlhBlpwZyAkPgAAAPw"]
[Thu Jul 30 14:32:26.554339 2026] [security2:error] [pid 17707:tid 17852] [client 20.52.125.110:2268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amumyrJM3qlhBlpwZyAkQgAAAJQ"]
[Thu Jul 30 14:32:27.368827 2026] [security2:error] [pid 17707:tid 17840] [client 54.84.147.79:20781] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/solenidade-com-entrega-de-medalhas-marca-58o-aniversario-da-camara-de-alagoinha/"] [unique_id "amumy7JM3qlhBlpwZyAkUgAAAIg"]
[Thu Jul 30 14:32:27.381101 2026] [security2:error] [pid 17707:tid 17946] [client 20.52.125.110:4330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/content.php"] [unique_id "amumy7JM3qlhBlpwZyAkUwAAAPI"]
[Thu Jul 30 14:32:27.398316 2026] [security2:error] [pid 17707:tid 17859] [client 177.6.106.101:53451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumy7JM3qlhBlpwZyAkVAAAAJs"]
[Thu Jul 30 14:32:27.398412 2026] [security2:error] [pid 17707:tid 17859] [client 177.6.106.101:53451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumy7JM3qlhBlpwZyAkVAAAAJs"]
[Thu Jul 30 14:32:27.940626 2026] [security2:error] [pid 17707:tid 17845] [client 20.52.125.110:4334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amumy7JM3qlhBlpwZyAkYwAAAI0"]
[Thu Jul 30 14:32:28.015347 2026] [security2:error] [pid 17707:tid 17939] [client 52.238.199.152:52542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/file.php"] [unique_id "amumzLJM3qlhBlpwZyAkagAAAOs"]
[Thu Jul 30 14:32:28.474745 2026] [security2:error] [pid 17707:tid 17891] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amumy7JM3qlhBlpwZyAkWAAAu1A"]
[Thu Jul 30 14:32:28.551155 2026] [security2:error] [pid 17707:tid 17961] [client 20.52.125.110:4351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amumzLJM3qlhBlpwZyAkeQAAAQE"]
[Thu Jul 30 14:32:28.816534 2026] [security2:error] [pid 17707:tid 17825] [remote 57.141.0.36:36318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55089810635/feed/rss2/"] [unique_id "amumzLJM3qlhBlpwZyAkggAAwHU"]
[Thu Jul 30 14:32:29.133493 2026] [security2:error] [pid 17707:tid 17954] [client 20.52.125.110:2265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amumzbJM3qlhBlpwZyAkiQAAAPo"]
[Thu Jul 30 14:32:29.492371 2026] [security2:error] [pid 17707:tid 17933] [client 52.238.199.152:16291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amumzbJM3qlhBlpwZyAkjgAAAOU"]
[Thu Jul 30 14:32:29.801238 2026] [security2:error] [pid 17707:tid 17883] [client 180.243.59.178:62136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumzbJM3qlhBlpwZyAkmAAAALM"]
[Thu Jul 30 14:32:29.801403 2026] [security2:error] [pid 17707:tid 17883] [client 180.243.59.178:62136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amumzbJM3qlhBlpwZyAkmAAAALM"]
[Thu Jul 30 14:32:29.974079 2026] [core:error] [pid 17707:tid 17942] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:29.974101 2026] [core:error] [pid 17707:tid 17942] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:30.007769 2026] [security2:error] [pid 17707:tid 17872] [client 20.52.125.110:4309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amumzrJM3qlhBlpwZyAkmwAAAKg"]
[Thu Jul 30 14:32:30.927559 2026] [security2:error] [pid 17707:tid 17931] [client 20.52.125.110:2099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amumzrJM3qlhBlpwZyAktAAAAOM"]
[Thu Jul 30 14:32:31.236106 2026] [security2:error] [pid 17707:tid 17738] [remote 57.141.0.22:33700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/404010317/feed/rss2/"] [unique_id "amumz7JM3qlhBlpwZyAktwAA9B4"]
[Thu Jul 30 14:32:31.572878 2026] [security2:error] [pid 17707:tid 17860] [client 20.52.125.110:2091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amumz7JM3qlhBlpwZyAkwQAAAJw"]
[Thu Jul 30 14:32:32.488034 2026] [security2:error] [pid 17707:tid 17933] [client 20.52.125.110:2243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amum0LJM3qlhBlpwZyAk1QAAAOU"]
[Thu Jul 30 14:32:33.031075 2026] [security2:error] [pid 17707:tid 17851] [client 20.52.125.110:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amum0bJM3qlhBlpwZyAk3wAAAJM"]
[Thu Jul 30 14:32:33.556471 2026] [security2:error] [pid 17707:tid 17937] [client 85.208.96.203:12258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "k2k.tech"] [uri "/robots.txt"] [unique_id "amum0bJM3qlhBlpwZyAk6QAAAOk"]
[Thu Jul 30 14:32:33.556611 2026] [security2:error] [pid 17707:tid 17937] [client 85.208.96.203:12258] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "k2k.tech"] [uri "/robots.txt"] [unique_id "amum0bJM3qlhBlpwZyAk6QAAAOk"]
[Thu Jul 30 14:32:33.995533 2026] [core:error] [pid 17707:tid 17882] [client 169.197.113.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:33.995568 2026] [core:error] [pid 17707:tid 17882] [client 169.197.113.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:34.091762 2026] [security2:error] [pid 17707:tid 17924] [client 189.156.226.90:26826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum0rJM3qlhBlpwZyAk9wAAANw"]
[Thu Jul 30 14:32:34.091876 2026] [security2:error] [pid 17707:tid 17924] [client 189.156.226.90:26826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum0rJM3qlhBlpwZyAk9wAAANw"]
[Thu Jul 30 14:32:34.206823 2026] [security2:error] [pid 17707:tid 17844] [client 52.238.199.152:52537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amum0rJM3qlhBlpwZyAk-AAAAIw"]
[Thu Jul 30 14:32:34.274561 2026] [security2:error] [pid 17707:tid 17868] [client 185.191.171.3:52794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "k2k.tech"] [uri "/"] [unique_id "amum0rJM3qlhBlpwZyAk-wAAAKQ"]
[Thu Jul 30 14:32:34.274681 2026] [security2:error] [pid 17707:tid 17868] [client 185.191.171.3:52794] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "k2k.tech"] [uri "/"] [unique_id "amum0rJM3qlhBlpwZyAk-wAAAKQ"]
[Thu Jul 30 14:32:35.485460 2026] [security2:error] [pid 17707:tid 17930] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amum0rJM3qlhBlpwZyAlDQAAAOI"]
[Thu Jul 30 14:32:36.229610 2026] [security2:error] [pid 17707:tid 17886] [client 20.52.125.110:2059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amum1LJM3qlhBlpwZyAlKAAAALY"]
[Thu Jul 30 14:32:36.721763 2026] [security2:error] [pid 17707:tid 17919] [client 18.192.166.72:48896] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amum1LJM3qlhBlpwZyAlMgAAANc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:32:36.771758 2026] [security2:error] [pid 17707:tid 17943] [client 85.208.96.212:21014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "k2k.tech"] [uri "/sitemap.xml"] [unique_id "amum1LJM3qlhBlpwZyAlMwAAAO8"]
[Thu Jul 30 14:32:36.771925 2026] [security2:error] [pid 17707:tid 17943] [client 85.208.96.212:21014] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "k2k.tech"] [uri "/sitemap.xml"] [unique_id "amum1LJM3qlhBlpwZyAlMwAAAO8"]
[Thu Jul 30 14:32:37.111211 2026] [core:notice] [pid 17707:tid 17871] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:37.116255 2026] [security2:error] [pid 17707:tid 17871] [client 18.192.166.72:48908] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amum1bJM3qlhBlpwZyAlPQAAAKc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:32:37.206155 2026] [security2:error] [pid 17707:tid 17758] [remote 192.250.227.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.227.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kbtfinancezambia.com"] [uri "/wp-login.php"] [unique_id "amum1bJM3qlhBlpwZyAlPgAAzzI"]
[Thu Jul 30 14:32:37.214098 2026] [security2:error] [pid 17707:tid 17949] [client 52.238.199.152:16318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/file.php"] [unique_id "amum1bJM3qlhBlpwZyAlPwAAAPU"]
[Thu Jul 30 14:32:37.495906 2026] [security2:error] [pid 17707:tid 17873] [client 18.192.166.72:48922] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amum1bJM3qlhBlpwZyAlQwAAAKk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:32:37.945418 2026] [security2:error] [pid 17707:tid 17935] [client 177.6.106.101:53980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum1bJM3qlhBlpwZyAlSwAAAOc"]
[Thu Jul 30 14:32:37.946043 2026] [security2:error] [pid 17707:tid 17935] [client 177.6.106.101:53980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum1bJM3qlhBlpwZyAlSwAAAOc"]
[Thu Jul 30 14:32:38.162530 2026] [security2:error] [pid 17707:tid 17878] [client 20.52.125.110:2262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amum1rJM3qlhBlpwZyAlVAAAAK4"]
[Thu Jul 30 14:32:39.412610 2026] [security2:error] [pid 17707:tid 17921] [client 20.52.125.110:4328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/banners/about.php"] [unique_id "amum17JM3qlhBlpwZyAlbwAAANk"]
[Thu Jul 30 14:32:39.675860 2026] [security2:error] [pid 17707:tid 17862] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amum17JM3qlhBlpwZyAlagAAAJ4"]
[Thu Jul 30 14:32:39.734253 2026] [core:error] [pid 17707:tid 17864] [client 169.197.113.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:39.734273 2026] [core:error] [pid 17707:tid 17864] [client 169.197.113.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:39.840009 2026] [security2:error] [pid 17707:tid 17902] [client 52.238.199.152:52529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-signup.php"] [unique_id "amum17JM3qlhBlpwZyAlfAAAAMY"]
[Thu Jul 30 14:32:40.247647 2026] [security2:error] [pid 17707:tid 17924] [client 20.52.125.110:2247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/about.php"] [unique_id "amum2LJM3qlhBlpwZyAlhAAAANw"]
[Thu Jul 30 14:32:40.799161 2026] [security2:error] [pid 17707:tid 17852] [client 180.243.59.178:62690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum2LJM3qlhBlpwZyAllAAAAJQ"]
[Thu Jul 30 14:32:40.799287 2026] [security2:error] [pid 17707:tid 17852] [client 180.243.59.178:62690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum2LJM3qlhBlpwZyAllAAAAJQ"]
[Thu Jul 30 14:32:40.936510 2026] [security2:error] [pid 17707:tid 17856] [client 52.238.199.152:42011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/css/index.php"] [unique_id "amum2LJM3qlhBlpwZyAlmAAAAJg"]
[Thu Jul 30 14:32:41.041873 2026] [security2:error] [pid 17707:tid 17884] [client 20.52.125.110:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/about.php"] [unique_id "amum2bJM3qlhBlpwZyAlmQAAALQ"]
[Thu Jul 30 14:32:41.370472 2026] [security2:error] [pid 17707:tid 17793] [remote 57.141.0.19:50494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amum2bJM3qlhBlpwZyAlowAAj1U"]
[Thu Jul 30 14:32:41.576220 2026] [security2:error] [pid 17707:tid 17865] [client 20.52.125.110:2266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amum2bJM3qlhBlpwZyAlpQAAAKE"]
[Thu Jul 30 14:32:42.369129 2026] [security2:error] [pid 17707:tid 17890] [client 20.52.125.110:2242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amum2rJM3qlhBlpwZyAlugAAALo"]
[Thu Jul 30 14:32:42.388025 2026] [core:error] [pid 17707:tid 17863] [client 169.197.113.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:42.388044 2026] [core:error] [pid 17707:tid 17863] [client 169.197.113.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:43.091813 2026] [security2:error] [pid 17707:tid 17896] [client 20.52.125.110:2269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/img/about.php"] [unique_id "amum27JM3qlhBlpwZyAlygAAAMA"]
[Thu Jul 30 14:32:43.245557 2026] [core:notice] [pid 17707:tid 17940] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:43.960557 2026] [security2:error] [pid 17707:tid 17915] [client 20.52.125.110:2056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/languages/about.php"] [unique_id "amum27JM3qlhBlpwZyAl5QAAANM"]
[Thu Jul 30 14:32:44.686842 2026] [security2:error] [pid 17707:tid 17838] [client 189.156.226.90:27099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum3LJM3qlhBlpwZyAl8gAAAIY"]
[Thu Jul 30 14:32:44.686952 2026] [security2:error] [pid 17707:tid 17838] [client 189.156.226.90:27099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum3LJM3qlhBlpwZyAl8gAAAIY"]
[Thu Jul 30 14:32:44.844289 2026] [core:error] [pid 17707:tid 17964] [client 169.197.113.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:44.844311 2026] [core:error] [pid 17707:tid 17964] [client 169.197.113.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:45.107499 2026] [security2:error] [pid 17707:tid 17865] [client 20.52.125.110:2261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amum3bJM3qlhBlpwZyAl_wAAAKE"]
[Thu Jul 30 14:32:45.892538 2026] [security2:error] [pid 17707:tid 17844] [client 20.52.125.110:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amum3bJM3qlhBlpwZyAmDwAAAIw"]
[Thu Jul 30 14:32:46.329463 2026] [security2:error] [pid 17707:tid 17923] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amum3bJM3qlhBlpwZyAmAAAA214"]
[Thu Jul 30 14:32:46.464288 2026] [security2:error] [pid 17707:tid 17960] [client 52.238.199.152:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ge.php"] [unique_id "amum3rJM3qlhBlpwZyAmHAAAAQA"]
[Thu Jul 30 14:32:46.577865 2026] [security2:error] [pid 17707:tid 17860] [client 47.128.29.185:29818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "skcarrental.ae"] [uri "/robots.txt"] [unique_id "amum3rJM3qlhBlpwZyAmIwAAAJw"]
[Thu Jul 30 14:32:47.084665 2026] [security2:error] [pid 17707:tid 17866] [client 20.52.125.110:2273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amum37JM3qlhBlpwZyAmLQAAAKI"]
[Thu Jul 30 14:32:47.516412 2026] [core:notice] [pid 17707:tid 17819] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:47.983984 2026] [security2:error] [pid 17707:tid 17932] [client 20.52.125.110:2291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amum37JM3qlhBlpwZyAmWgAAAOQ"]
[Thu Jul 30 14:32:48.150090 2026] [security2:error] [pid 17707:tid 17961] [client 52.176.39.128:3074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.39.176.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amum4LJM3qlhBlpwZyAmXgAAAQE"]
[Thu Jul 30 14:32:48.676547 2026] [security2:error] [pid 17707:tid 17919] [client 177.6.106.101:54521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum4LJM3qlhBlpwZyAmcgAAANc"]
[Thu Jul 30 14:32:48.676676 2026] [security2:error] [pid 17707:tid 17919] [client 177.6.106.101:54521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum4LJM3qlhBlpwZyAmcgAAANc"]
[Thu Jul 30 14:32:49.083701 2026] [fcgid:warn] [pid 17707:tid 17936] (70014)End of file found: [client 169.197.113.175:39084] mod_fcgid: can't get data from http client
[Thu Jul 30 14:32:49.164543 2026] [security2:error] [pid 17707:tid 17905] [client 103.231.91.59:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amum4bJM3qlhBlpwZyAmgAAAAMk"]
[Thu Jul 30 14:32:49.164654 2026] [security2:error] [pid 17707:tid 17905] [client 103.231.91.59:60164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amum4bJM3qlhBlpwZyAmgAAAAMk"]
[Thu Jul 30 14:32:49.366666 2026] [core:notice] [pid 17707:tid 17874] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:49.379145 2026] [security2:error] [pid 17707:tid 17920] [client 52.238.199.152:16284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/goods.php"] [unique_id "amum4bJM3qlhBlpwZyAmhQAAANg"]
[Thu Jul 30 14:32:49.531414 2026] [security2:error] [pid 17707:tid 17924] [client 20.52.125.110:2249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/js/about.php"] [unique_id "amum4bJM3qlhBlpwZyAmhgAAANw"]
[Thu Jul 30 14:32:50.188123 2026] [security2:error] [pid 17707:tid 17953] [client 20.52.125.110:4335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amum4rJM3qlhBlpwZyAmlAAAAPk"]
[Thu Jul 30 14:32:50.569872 2026] [autoindex:error] [pid 17707:tid 17865] [client 159.65.24.22:40402] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:32:50.790968 2026] [security2:error] [pid 17707:tid 17867] [client 20.52.125.110:2303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amum4rJM3qlhBlpwZyAmogAAAKM"]
[Thu Jul 30 14:32:51.267721 2026] [security2:error] [pid 17707:tid 17899] [client 180.243.59.178:63242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum47JM3qlhBlpwZyAmrAAAAMM"]
[Thu Jul 30 14:32:51.267884 2026] [security2:error] [pid 17707:tid 17899] [client 180.243.59.178:63242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum47JM3qlhBlpwZyAmrAAAAMM"]
[Thu Jul 30 14:32:51.450780 2026] [security2:error] [pid 17707:tid 17927] [client 20.52.125.110:4297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amum47JM3qlhBlpwZyAmswAAAN8"]
[Thu Jul 30 14:32:52.043717 2026] [security2:error] [pid 17707:tid 17857] [client 20.52.125.110:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amum5LJM3qlhBlpwZyAmxwAAAJk"]
[Thu Jul 30 14:32:52.099014 2026] [security2:error] [pid 17707:tid 17914] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amum47JM3qlhBlpwZyAmvQAAANI"]
[Thu Jul 30 14:32:52.660755 2026] [security2:error] [pid 17707:tid 17931] [client 52.238.199.152:42000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/403.php"] [unique_id "amum5LJM3qlhBlpwZyAm0gAAAOM"]
[Thu Jul 30 14:32:52.752724 2026] [security2:error] [pid 17707:tid 17849] [client 20.52.125.110:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amum5LJM3qlhBlpwZyAm1QAAAJE"]
[Thu Jul 30 14:32:53.388470 2026] [security2:error] [pid 17707:tid 17962] [client 20.52.125.110:4345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/themes/about.php"] [unique_id "amum5bJM3qlhBlpwZyAm4gAAAQI"]
[Thu Jul 30 14:32:54.059493 2026] [security2:error] [pid 17707:tid 17927] [client 20.52.125.110:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amum5rJM3qlhBlpwZyAm8gAAAN8"]
[Thu Jul 30 14:32:54.433847 2026] [core:notice] [pid 17707:tid 17793] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:32:54.470683 2026] [security2:error] [pid 17707:tid 17901] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amum5bJM3qlhBlpwZyAm4wAAxU0"]
[Thu Jul 30 14:32:54.575907 2026] [security2:error] [pid 17707:tid 17889] [client 34.196.6.199:24130] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/arquivos/noticias/1652/xd746f2a6fb373d6b702ca629b52cbf6b.jpg.pagespeed.ic.Zxf5j7ZgOB.webp"] [unique_id "amum5rJM3qlhBlpwZyAm_gAAALk"]
[Thu Jul 30 14:32:55.211683 2026] [security2:error] [pid 17707:tid 17897] [client 189.156.226.90:27498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum57JM3qlhBlpwZyAnCAAAAME"]
[Thu Jul 30 14:32:55.211810 2026] [security2:error] [pid 17707:tid 17897] [client 189.156.226.90:27498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum57JM3qlhBlpwZyAnCAAAAME"]
[Thu Jul 30 14:32:55.224369 2026] [security2:error] [pid 17707:tid 17920] [client 20.52.125.110:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/images/about.php"] [unique_id "amum57JM3qlhBlpwZyAnCQAAANg"]
[Thu Jul 30 14:32:55.767917 2026] [security2:error] [pid 17707:tid 17863] [client 20.52.125.110:4343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amum57JM3qlhBlpwZyAnFAAAAJ8"]
[Thu Jul 30 14:32:55.857149 2026] [core:error] [pid 17707:tid 17961] [client 195.96.139.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:55.857172 2026] [core:error] [pid 17707:tid 17961] [client 195.96.139.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:32:56.468216 2026] [security2:error] [pid 17707:tid 17873] [client 20.52.125.110:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/images/about.php"] [unique_id "amum6LJM3qlhBlpwZyAnKAAAAKk"]
[Thu Jul 30 14:32:57.357676 2026] [security2:error] [pid 17707:tid 17917] [client 20.52.125.110:2080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/about.php"] [unique_id "amum6bJM3qlhBlpwZyAnNQAAANU"]
[Thu Jul 30 14:32:57.898839 2026] [security2:error] [pid 17707:tid 17852] [client 20.52.125.110:2252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/cgi-bin/about.php"] [unique_id "amum6bJM3qlhBlpwZyAnQAAAAJQ"]
[Thu Jul 30 14:32:57.931145 2026] [security2:error] [pid 17707:tid 17950] [client 52.238.199.152:41996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/public/makeasmtp.php"] [unique_id "amum6bJM3qlhBlpwZyAnQQAAAPY"]
[Thu Jul 30 14:32:58.364321 2026] [autoindex:error] [pid 17707:tid 17843] [client 91.192.10.101:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:32:58.660542 2026] [autoindex:error] [pid 17707:tid 17961] [client 91.192.10.101:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://koidomino.click
[Thu Jul 30 14:32:58.735759 2026] [security2:error] [pid 17707:tid 17921] [client 20.52.125.110:4333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amum6rJM3qlhBlpwZyAnWQAAANk"]
[Thu Jul 30 14:32:58.965290 2026] [security2:error] [pid 17707:tid 17869] [client 52.238.199.152:52490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/mar.php"] [unique_id "amum6rJM3qlhBlpwZyAnXAAAAKU"]
[Thu Jul 30 14:32:59.135213 2026] [autoindex:error] [pid 17707:tid 17937] [client 91.192.10.101:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:32:59.177750 2026] [security2:error] [pid 17707:tid 17912] [client 177.6.106.101:55057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum67JM3qlhBlpwZyAnZAAAANA"]
[Thu Jul 30 14:32:59.177866 2026] [security2:error] [pid 17707:tid 17912] [client 177.6.106.101:55057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum67JM3qlhBlpwZyAnZAAAANA"]
[Thu Jul 30 14:32:59.466898 2026] [security2:error] [pid 17707:tid 17880] [client 20.52.125.110:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amum67JM3qlhBlpwZyAnawAAALA"]
[Thu Jul 30 14:32:59.663341 2026] [security2:error] [pid 17707:tid 17884] [client 91.192.10.101:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koidomino.click"] [uri "/.env"] [unique_id "amum67JM3qlhBlpwZyAneAAAALQ"]
[Thu Jul 30 14:32:59.890252 2026] [security2:error] [pid 17707:tid 17878] [client 91.192.10.101:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koidomino.click"] [uri "/api/.env"] [unique_id "amum67JM3qlhBlpwZyAngQAAAK4"]
[Thu Jul 30 14:32:59.902088 2026] [security2:error] [pid 17707:tid 17901] [client 91.192.10.101:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koidomino.click"] [uri "/backend/.env"] [unique_id "amum67JM3qlhBlpwZyAnhAAAAMU"]
[Thu Jul 30 14:33:00.102433 2026] [security2:error] [pid 17707:tid 17963] [client 20.52.125.110:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/css/about.php"] [unique_id "amum7LJM3qlhBlpwZyAniQAAAQM"]
[Thu Jul 30 14:33:00.157945 2026] [security2:error] [pid 17707:tid 17817] [remote 74.7.243.224:36152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/login.php"] [unique_id "amum7LJM3qlhBlpwZyAnjAAA0m0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 14:33:00.296891 2026] [security2:error] [pid 17707:tid 17857] [client 52.238.199.152:3910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/system.php"] [unique_id "amum7LJM3qlhBlpwZyAnkQAAAJk"]
[Thu Jul 30 14:33:00.436846 2026] [security2:error] [pid 17707:tid 17931] [client 103.231.91.59:40132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amum7LJM3qlhBlpwZyAnkwAAAOM"]
[Thu Jul 30 14:33:00.436944 2026] [security2:error] [pid 17707:tid 17931] [client 103.231.91.59:40132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amum7LJM3qlhBlpwZyAnkwAAAOM"]
[Thu Jul 30 14:33:00.683238 2026] [security2:error] [pid 17707:tid 17944] [client 20.52.125.110:2506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/images/about.php"] [unique_id "amum7LJM3qlhBlpwZyAnmAAAAPA"]
[Thu Jul 30 14:33:00.757140 2026] [core:error] [pid 17707:tid 17832] [remote 216.73.217.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:33:00.757164 2026] [core:error] [pid 17707:tid 17832] [remote 216.73.217.1:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:33:01.011560 2026] [security2:error] [pid 17707:tid 17949] [client 103.231.91.59:40136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amum7bJM3qlhBlpwZyAnoAAAAPU"]
[Thu Jul 30 14:33:01.011668 2026] [security2:error] [pid 17707:tid 17949] [client 103.231.91.59:40136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amum7bJM3qlhBlpwZyAnoAAAAPU"]
[Thu Jul 30 14:33:01.280237 2026] [security2:error] [pid 17707:tid 17867] [client 180.243.59.178:63761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum7bJM3qlhBlpwZyAnqAAAAKM"]
[Thu Jul 30 14:33:01.280380 2026] [security2:error] [pid 17707:tid 17867] [client 180.243.59.178:63761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum7bJM3qlhBlpwZyAnqAAAAKM"]
[Thu Jul 30 14:33:01.323034 2026] [security2:error] [pid 17707:tid 17959] [client 20.52.125.110:2547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amum7bJM3qlhBlpwZyAnqQAAAP8"]
[Thu Jul 30 14:33:01.928804 2026] [security2:error] [pid 17707:tid 17926] [client 20.52.125.110:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amum7bJM3qlhBlpwZyAnvQAAAN4"]
[Thu Jul 30 14:33:02.275329 2026] [security2:error] [pid 17707:tid 17871] [client 52.238.199.152:3923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/lock360.php"] [unique_id "amum7rJM3qlhBlpwZyAnxQAAAKc"]
[Thu Jul 30 14:33:03.277516 2026] [security2:error] [pid 17707:tid 17898] [client 20.52.125.110:2539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amum77JM3qlhBlpwZyAn0wAAAMI"]
[Thu Jul 30 14:33:03.785518 2026] [security2:error] [pid 17707:tid 17961] [client 20.52.125.110:2501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/cloud.php"] [unique_id "amum77JM3qlhBlpwZyAn4wAAAQE"]
[Thu Jul 30 14:33:04.522779 2026] [security2:error] [pid 17707:tid 17857] [client 52.238.199.152:3936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amum8LJM3qlhBlpwZyAn9gAAAJk"]
[Thu Jul 30 14:33:04.757340 2026] [security2:error] [pid 17707:tid 17867] [client 20.52.125.110:2554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amum8LJM3qlhBlpwZyAn-AAAAKM"]
[Thu Jul 30 14:33:05.484779 2026] [security2:error] [pid 17707:tid 17852] [client 20.52.125.110:2496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/updates.php"] [unique_id "amum8bJM3qlhBlpwZyAoCAAAAJQ"]
[Thu Jul 30 14:33:05.764401 2026] [security2:error] [pid 17707:tid 17922] [client 189.156.226.90:27646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum8bJM3qlhBlpwZyAoDAAAANo"]
[Thu Jul 30 14:33:05.764520 2026] [security2:error] [pid 17707:tid 17922] [client 189.156.226.90:27646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum8bJM3qlhBlpwZyAoDAAAANo"]
[Thu Jul 30 14:33:06.145720 2026] [security2:error] [pid 17707:tid 17897] [client 52.238.199.152:42043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/mah.php"] [unique_id "amum8rJM3qlhBlpwZyAoFwAAAME"]
[Thu Jul 30 14:33:06.276805 2026] [security2:error] [pid 17707:tid 17943] [client 20.52.125.110:2272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/css/cloud.php"] [unique_id "amum8rJM3qlhBlpwZyAoGAAAAO8"]
[Thu Jul 30 14:33:06.629037 2026] [security2:error] [pid 17707:tid 17921] [client 185.191.171.1:11742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/03/economia-brasileira-cresce-1-no-1o-trimestre-de-2022-aponta-ibge/"] [unique_id "amum8rJM3qlhBlpwZyAoJQAAANk"]
[Thu Jul 30 14:33:06.629161 2026] [security2:error] [pid 17707:tid 17921] [client 185.191.171.1:11742] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/03/economia-brasileira-cresce-1-no-1o-trimestre-de-2022-aponta-ibge/"] [unique_id "amum8rJM3qlhBlpwZyAoJQAAANk"]
[Thu Jul 30 14:33:06.992887 2026] [security2:error] [pid 17707:tid 17857] [client 20.52.125.110:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amum8rJM3qlhBlpwZyAoKgAAAJk"]
[Thu Jul 30 14:33:07.333756 2026] [security2:error] [pid 17707:tid 17905] [client 52.238.199.152:3906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-class.php"] [unique_id "amum87JM3qlhBlpwZyAoMgAAAMk"]
[Thu Jul 30 14:33:07.775996 2026] [security2:error] [pid 17707:tid 17933] [client 20.52.125.110:2538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/img/cloud.php"] [unique_id "amum87JM3qlhBlpwZyAoPwAAAOU"]
[Thu Jul 30 14:33:07.861331 2026] [core:error] [pid 17707:tid 17950] [client 74.7.230.16:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:33:07.861354 2026] [core:error] [pid 17707:tid 17950] [client 74.7.230.16:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:33:07.861496 2026] [security2:error] [pid 17707:tid 17950] [client 74.7.230.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.iop.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amum87JM3qlhBlpwZyAoQgAAAPY"]
[Thu Jul 30 14:33:07.862129 2026] [security2:error] [pid 17707:tid 17837] [client 74.7.230.16:56300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.iop.udi.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amum87JM3qlhBlpwZyAoQAAAhSQ"]
[Thu Jul 30 14:33:08.800385 2026] [security2:error] [pid 17707:tid 17909] [client 20.52.125.110:2276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amum9LJM3qlhBlpwZyAoZAAAAM0"]
[Thu Jul 30 14:33:10.040048 2026] [security2:error] [pid 17707:tid 17940] [client 177.6.106.101:55670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum9rJM3qlhBlpwZyAoiQAAAOw"]
[Thu Jul 30 14:33:10.040699 2026] [security2:error] [pid 17707:tid 17940] [client 177.6.106.101:55670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum9rJM3qlhBlpwZyAoiQAAAOw"]
[Thu Jul 30 14:33:10.690601 2026] [security2:error] [pid 17707:tid 17874] [client 20.52.125.110:2177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amum9rJM3qlhBlpwZyAonwAAAKo"]
[Thu Jul 30 14:33:10.758447 2026] [security2:error] [pid 17707:tid 17849] [client 172.237.109.114:52917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amum9rJM3qlhBlpwZyAokAAAAJE"]
[Thu Jul 30 14:33:10.973283 2026] [security2:error] [pid 17707:tid 17913] [client 216.244.66.236:51890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amum9rJM3qlhBlpwZyAopAAAANE"]
[Thu Jul 30 14:33:10.973417 2026] [security2:error] [pid 17707:tid 17913] [client 216.244.66.236:51890] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amum9rJM3qlhBlpwZyAopAAAANE"]
[Thu Jul 30 14:33:11.277235 2026] [security2:error] [pid 17707:tid 17861] [client 20.52.125.110:2503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/avaa.php"] [unique_id "amum97JM3qlhBlpwZyAorwAAAJ0"]
[Thu Jul 30 14:33:11.761880 2026] [security2:error] [pid 17707:tid 17930] [client 180.243.59.178:64297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum97JM3qlhBlpwZyAotgAAAOI"]
[Thu Jul 30 14:33:11.762062 2026] [security2:error] [pid 17707:tid 17930] [client 180.243.59.178:64297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amum97JM3qlhBlpwZyAotgAAAOI"]
[Thu Jul 30 14:33:11.994433 2026] [security2:error] [pid 17707:tid 17934] [client 20.52.125.110:2516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/images/cloud.php"] [unique_id "amum97JM3qlhBlpwZyAougAAAOY"]
[Thu Jul 30 14:33:12.654073 2026] [security2:error] [pid 17707:tid 17931] [client 52.238.199.152:47110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/backup.php"] [unique_id "amum-LJM3qlhBlpwZyAoyAAAAOM"]
[Thu Jul 30 14:33:12.802849 2026] [security2:error] [pid 17707:tid 17964] [client 43.173.175.159:51510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.175.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2018/07/20/petit-sac-mariage-2018/"] [unique_id "amum-LJM3qlhBlpwZyAoxQAAAQQ"]
[Thu Jul 30 14:33:13.288417 2026] [security2:error] [pid 17707:tid 17946] [client 20.52.125.110:2211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amum-bJM3qlhBlpwZyAo1gAAAPI"]
[Thu Jul 30 14:33:13.430752 2026] [core:notice] [pid 17707:tid 17865] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:13.436353 2026] [security2:error] [pid 17707:tid 17865] [client 43.172.197.92:41868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2018/07/20/petit-sac-mariage-2018/"] [unique_id "amum-bJM3qlhBlpwZyAo2wAAAKE"], referer: https://carnetdeshopping.com/index.php/2018/07/20/petit-sac-mariage-2018/
[Thu Jul 30 14:33:14.068252 2026] [security2:error] [pid 17707:tid 17873] [client 20.52.125.110:2212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amum-rJM3qlhBlpwZyAo6AAAAKk"]
[Thu Jul 30 14:33:15.421429 2026] [core:error] [pid 17707:tid 17817] [remote 74.7.244.27:41850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:33:15.421457 2026] [core:error] [pid 17707:tid 17817] [remote 74.7.244.27:41850] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:33:15.421634 2026] [security2:error] [pid 17707:tid 17940] [client 74.7.244.27:41850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-e571b8b9.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amum-7JM3qlhBlpwZyAo_gAA7G0"]
[Thu Jul 30 14:33:15.570652 2026] [security2:error] [pid 17707:tid 17878] [client 20.52.125.110:2232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amum-7JM3qlhBlpwZyApAwAAAK4"]
[Thu Jul 30 14:33:15.835852 2026] [security2:error] [pid 17707:tid 17868] [client 204.12.208.18:61565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/x1823cc/index.php"] [unique_id "amum-7JM3qlhBlpwZyApCgAAAKQ"], referer: https://saifalkhaleejest.com/wp-includes/x1823cc/index.php
[Thu Jul 30 14:33:16.330542 2026] [security2:error] [pid 17707:tid 17912] [client 189.156.226.90:27104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum_LJM3qlhBlpwZyApFQAAANA"]
[Thu Jul 30 14:33:16.330692 2026] [security2:error] [pid 17707:tid 17912] [client 189.156.226.90:27104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amum_LJM3qlhBlpwZyApFQAAANA"]
[Thu Jul 30 14:33:16.785387 2026] [security2:error] [pid 17707:tid 17859] [client 52.238.199.152:50265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/default.php"] [unique_id "amum_LJM3qlhBlpwZyApHwAAAJs"]
[Thu Jul 30 14:33:17.694044 2026] [proxy:error] [pid 17707:tid 17875] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:17.694114 2026] [proxy_http:error] [pid 17707:tid 17875] [client 193.47.62.167:40626] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:17.694744 2026] [proxy:error] [pid 17707:tid 17875] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:17.694789 2026] [proxy_http:error] [pid 17707:tid 17875] [client 193.47.62.167:40626] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:17.999803 2026] [security2:error] [pid 17707:tid 17852] [client 20.52.125.110:2513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amum_bJM3qlhBlpwZyApNQAAAJQ"]
[Thu Jul 30 14:33:18.223016 2026] [security2:error] [pid 17707:tid 17862] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amum_bJM3qlhBlpwZyApNAAAAJ4"]
[Thu Jul 30 14:33:18.223125 2026] [security2:error] [pid 17707:tid 17862] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amum_bJM3qlhBlpwZyApNAAAAJ4"]
[Thu Jul 30 14:33:18.474610 2026] [security2:error] [pid 17707:tid 17938] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amum_rJM3qlhBlpwZyApQwAAAOo"]
[Thu Jul 30 14:33:18.474698 2026] [security2:error] [pid 17707:tid 17938] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amum_rJM3qlhBlpwZyApQwAAAOo"]
[Thu Jul 30 14:33:18.561355 2026] [security2:error] [pid 17707:tid 17847] [client 20.52.125.110:2198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amum_rJM3qlhBlpwZyApRQAAAI8"]
[Thu Jul 30 14:33:18.718198 2026] [security2:error] [pid 17707:tid 17841] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/xstelth.php"] [unique_id "amum_rJM3qlhBlpwZyApTAAAAIk"]
[Thu Jul 30 14:33:18.718333 2026] [security2:error] [pid 17707:tid 17841] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/xstelth.php"] [unique_id "amum_rJM3qlhBlpwZyApTAAAAIk"]
[Thu Jul 30 14:33:18.972411 2026] [security2:error] [pid 17707:tid 17858] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/584062352875874akp.php"] [unique_id "amum_rJM3qlhBlpwZyApVAAAAJo"]
[Thu Jul 30 14:33:18.972500 2026] [security2:error] [pid 17707:tid 17858] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/584062352875874akp.php"] [unique_id "amum_rJM3qlhBlpwZyApVAAAAJo"]
[Thu Jul 30 14:33:19.211075 2026] [security2:error] [pid 17707:tid 17879] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/newfile.php"] [unique_id "amum_7JM3qlhBlpwZyApWwAAAK8"]
[Thu Jul 30 14:33:19.211207 2026] [security2:error] [pid 17707:tid 17879] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/newfile.php"] [unique_id "amum_7JM3qlhBlpwZyApWwAAAK8"]
[Thu Jul 30 14:33:19.366736 2026] [security2:error] [pid 17707:tid 17899] [client 20.52.125.110:2197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/cloud.php"] [unique_id "amum_7JM3qlhBlpwZyApYwAAAMM"]
[Thu Jul 30 14:33:19.369489 2026] [security2:error] [pid 17707:tid 17855] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amum_rJM3qlhBlpwZyApTwAAAJc"]
[Thu Jul 30 14:33:19.427308 2026] [core:notice] [pid 17707:tid 17728] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:19.428892 2026] [core:notice] [pid 17707:tid 17821] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:19.457242 2026] [security2:error] [pid 17707:tid 17917] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/tBEZGQz.php"] [unique_id "amum_7JM3qlhBlpwZyApZgAAANU"]
[Thu Jul 30 14:33:19.457399 2026] [security2:error] [pid 17707:tid 17917] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/tBEZGQz.php"] [unique_id "amum_7JM3qlhBlpwZyApZgAAANU"]
[Thu Jul 30 14:33:19.460305 2026] [core:notice] [pid 17707:tid 17753] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:19.579668 2026] [security2:error] [pid 17707:tid 17937] [client 172.237.109.114:49180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amum_7JM3qlhBlpwZyApVgAAAOk"]
[Thu Jul 30 14:33:19.725588 2026] [security2:error] [pid 17707:tid 17929] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpanel/phpinfo"] [unique_id "amum_7JM3qlhBlpwZyApawAAAOE"]
[Thu Jul 30 14:33:19.735212 2026] [core:notice] [pid 17707:tid 17716] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:19.737148 2026] [core:notice] [pid 17707:tid 17712] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:19.758287 2026] [core:notice] [pid 17707:tid 17737] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:19.974395 2026] [security2:error] [pid 17707:tid 17883] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/drykl.php"] [unique_id "amum_7JM3qlhBlpwZyApdAAAALM"]
[Thu Jul 30 14:33:19.974476 2026] [security2:error] [pid 17707:tid 17883] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/drykl.php"] [unique_id "amum_7JM3qlhBlpwZyApdAAAALM"]
[Thu Jul 30 14:33:20.132264 2026] [security2:error] [pid 17707:tid 17920] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/blue/"] [unique_id "amunALJM3qlhBlpwZyApdgAAANg"]
[Thu Jul 30 14:33:20.391893 2026] [security2:error] [pid 17707:tid 17854] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ls.php"] [unique_id "amunALJM3qlhBlpwZyApfwAAAJY"]
[Thu Jul 30 14:33:20.392021 2026] [security2:error] [pid 17707:tid 17854] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ls.php"] [unique_id "amunALJM3qlhBlpwZyApfwAAAJY"]
[Thu Jul 30 14:33:20.468547 2026] [security2:error] [pid 17707:tid 17837] [client 20.52.125.110:2504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/updates.php"] [unique_id "amunALJM3qlhBlpwZyApgwAAAIU"]
[Thu Jul 30 14:33:20.513774 2026] [security2:error] [pid 17707:tid 17909] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/dx.php"] [unique_id "amunALJM3qlhBlpwZyAphQAAAM0"]
[Thu Jul 30 14:33:20.513917 2026] [security2:error] [pid 17707:tid 17909] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/dx.php"] [unique_id "amunALJM3qlhBlpwZyAphQAAAM0"]
[Thu Jul 30 14:33:20.536754 2026] [security2:error] [pid 17707:tid 17895] [client 177.6.106.101:56539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunALJM3qlhBlpwZyAphgAAAL8"]
[Thu Jul 30 14:33:20.548487 2026] [security2:error] [pid 17707:tid 17895] [client 177.6.106.101:56539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunALJM3qlhBlpwZyAphgAAAL8"]
[Thu Jul 30 14:33:20.858919 2026] [security2:error] [pid 17707:tid 17942] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amunALJM3qlhBlpwZyApigAAAO4"]
[Thu Jul 30 14:33:20.859051 2026] [security2:error] [pid 17707:tid 17942] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amunALJM3qlhBlpwZyApigAAAO4"]
[Thu Jul 30 14:33:21.090943 2026] [security2:error] [pid 17707:tid 17884] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/485.php"] [unique_id "amunAbJM3qlhBlpwZyAplwAAALQ"]
[Thu Jul 30 14:33:21.091065 2026] [security2:error] [pid 17707:tid 17884] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/485.php"] [unique_id "amunAbJM3qlhBlpwZyAplwAAALQ"]
[Thu Jul 30 14:33:21.179200 2026] [security2:error] [pid 17707:tid 17892] [client 20.52.125.110:2238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amunAbJM3qlhBlpwZyApmwAAALw"]
[Thu Jul 30 14:33:21.323283 2026] [security2:error] [pid 17707:tid 17890] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gelio1.php"] [unique_id "amunAbJM3qlhBlpwZyApnAAAALo"]
[Thu Jul 30 14:33:21.323403 2026] [security2:error] [pid 17707:tid 17890] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gelio1.php"] [unique_id "amunAbJM3qlhBlpwZyApnAAAALo"]
[Thu Jul 30 14:33:21.558156 2026] [security2:error] [pid 17707:tid 17888] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/lp6.php"] [unique_id "amunAbJM3qlhBlpwZyAppQAAALg"]
[Thu Jul 30 14:33:21.558248 2026] [security2:error] [pid 17707:tid 17888] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/lp6.php"] [unique_id "amunAbJM3qlhBlpwZyAppQAAALg"]
[Thu Jul 30 14:33:21.789887 2026] [security2:error] [pid 17707:tid 17875] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-admin/maint/admin.php"] [unique_id "amunAbJM3qlhBlpwZyApqQAAAKs"]
[Thu Jul 30 14:33:21.790013 2026] [security2:error] [pid 17707:tid 17875] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-admin/maint/admin.php"] [unique_id "amunAbJM3qlhBlpwZyApqQAAAKs"]
[Thu Jul 30 14:33:22.103661 2026] [security2:error] [pid 17707:tid 17924] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpanel/wp-includes/sodium_compat/"] [unique_id "amunArJM3qlhBlpwZyApsAAAANw"]
[Thu Jul 30 14:33:22.276507 2026] [security2:error] [pid 17707:tid 17950] [client 20.52.125.110:2524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amunArJM3qlhBlpwZyAptAAAAPY"]
[Thu Jul 30 14:33:22.368212 2026] [security2:error] [pid 17707:tid 17946] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/w3llscc.php"] [unique_id "amunArJM3qlhBlpwZyAptQAAAPI"]
[Thu Jul 30 14:33:22.368320 2026] [security2:error] [pid 17707:tid 17946] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/w3llscc.php"] [unique_id "amunArJM3qlhBlpwZyAptQAAAPI"]
[Thu Jul 30 14:33:22.438504 2026] [security2:error] [pid 17707:tid 17920] [client 180.243.59.178:64836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunArJM3qlhBlpwZyAptgAAANg"]
[Thu Jul 30 14:33:22.438662 2026] [security2:error] [pid 17707:tid 17920] [client 180.243.59.178:64836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunArJM3qlhBlpwZyAptgAAANg"]
[Thu Jul 30 14:33:22.505229 2026] [security2:error] [pid 17707:tid 17889] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/miru3.php"] [unique_id "amunArJM3qlhBlpwZyAptwAAALk"]
[Thu Jul 30 14:33:22.505336 2026] [security2:error] [pid 17707:tid 17889] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/miru3.php"] [unique_id "amunArJM3qlhBlpwZyAptwAAALk"]
[Thu Jul 30 14:33:22.740408 2026] [security2:error] [pid 17707:tid 17853] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/autoload_classmap.php"] [unique_id "amunArJM3qlhBlpwZyApwQAAAJU"]
[Thu Jul 30 14:33:22.740509 2026] [security2:error] [pid 17707:tid 17853] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/autoload_classmap.php"] [unique_id "amunArJM3qlhBlpwZyApwQAAAJU"]
[Thu Jul 30 14:33:23.230105 2026] [security2:error] [pid 17707:tid 17874] [client 20.52.125.110:2199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amunA7JM3qlhBlpwZyApygAAAKo"]
[Thu Jul 30 14:33:23.317026 2026] [security2:error] [pid 17707:tid 17845] [client 52.238.199.152:52423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/maint/about.php"] [unique_id "amunA7JM3qlhBlpwZyApzQAAAI0"]
[Thu Jul 30 14:33:23.452251 2026] [security2:error] [pid 17707:tid 17858] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpanel/wp-content/"] [unique_id "amunA7JM3qlhBlpwZyApzgAAAJo"]
[Thu Jul 30 14:33:23.721813 2026] [security2:error] [pid 17707:tid 17953] [client 204.12.208.18:61714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/x1823cc/index.php"] [unique_id "amunA7JM3qlhBlpwZyAp1wAAAPk"], referer: https://saifalkhaleejest.com/wp-includes/x1823cc/index.php
[Thu Jul 30 14:33:23.991058 2026] [security2:error] [pid 17707:tid 17848] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-content/themes/index.php"] [unique_id "amunA7JM3qlhBlpwZyAp2wAAAJA"]
[Thu Jul 30 14:33:23.991179 2026] [security2:error] [pid 17707:tid 17848] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-content/themes/index.php"] [unique_id "amunA7JM3qlhBlpwZyAp2wAAAJA"]
[Thu Jul 30 14:33:24.229573 2026] [security2:error] [pid 17707:tid 17873] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/av.php"] [unique_id "amunBLJM3qlhBlpwZyAp5AAAAKk"]
[Thu Jul 30 14:33:24.229687 2026] [security2:error] [pid 17707:tid 17873] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/av.php"] [unique_id "amunBLJM3qlhBlpwZyAp5AAAAKk"]
[Thu Jul 30 14:33:24.429028 2026] [core:notice] [pid 17707:tid 17947] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:24.558005 2026] [security2:error] [pid 17707:tid 17855] [client 172.237.109.114:14073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunBLJM3qlhBlpwZyAp3wAAAJc"]
[Thu Jul 30 14:33:24.599054 2026] [security2:error] [pid 17707:tid 17937] [client 20.52.125.110:2180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/alfa-rex.php7"] [unique_id "amunBLJM3qlhBlpwZyAp7wAAAOk"]
[Thu Jul 30 14:33:24.771188 2026] [security2:error] [pid 17707:tid 17866] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpanel/wp-includes/l10n/"] [unique_id "amunBLJM3qlhBlpwZyAp8wAAAKI"]
[Thu Jul 30 14:33:24.904919 2026] [security2:error] [pid 17707:tid 17929] [client 52.238.199.152:50284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amunBLJM3qlhBlpwZyAp9wAAAOE"]
[Thu Jul 30 14:33:24.961911 2026] [security2:error] [pid 17707:tid 17950] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpanel/wordpress/wp-admin/maint/"] [unique_id "amunBLJM3qlhBlpwZyAp-AAAAPY"]
[Thu Jul 30 14:33:25.287324 2026] [security2:error] [pid 17707:tid 17907] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/tiny.php"] [unique_id "amunBbJM3qlhBlpwZyAqAQAAAMs"]
[Thu Jul 30 14:33:25.287624 2026] [security2:error] [pid 17707:tid 17907] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/tiny.php"] [unique_id "amunBbJM3qlhBlpwZyAqAQAAAMs"]
[Thu Jul 30 14:33:25.540889 2026] [security2:error] [pid 17707:tid 17841] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amunBbJM3qlhBlpwZyAqAwAAAIk"]
[Thu Jul 30 14:33:25.541037 2026] [security2:error] [pid 17707:tid 17841] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amunBbJM3qlhBlpwZyAqAwAAAIk"]
[Thu Jul 30 14:33:25.572474 2026] [security2:error] [pid 17707:tid 17854] [client 20.52.125.110:2635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/alfanew.php"] [unique_id "amunBbJM3qlhBlpwZyAqBAAAAJY"]
[Thu Jul 30 14:33:25.920725 2026] [security2:error] [pid 17707:tid 17895] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/zrrhj.php"] [unique_id "amunBbJM3qlhBlpwZyAqDgAAAL8"]
[Thu Jul 30 14:33:25.920820 2026] [security2:error] [pid 17707:tid 17895] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/zrrhj.php"] [unique_id "amunBbJM3qlhBlpwZyAqDgAAAL8"]
[Thu Jul 30 14:33:26.155803 2026] [security2:error] [pid 17707:tid 17879] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amunBrJM3qlhBlpwZyAqGAAAAK8"]
[Thu Jul 30 14:33:26.156006 2026] [security2:error] [pid 17707:tid 17879] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amunBrJM3qlhBlpwZyAqGAAAAK8"]
[Thu Jul 30 14:33:26.392103 2026] [security2:error] [pid 17707:tid 17899] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wpgum.php"] [unique_id "amunBrJM3qlhBlpwZyAqHAAAAMM"]
[Thu Jul 30 14:33:26.392222 2026] [security2:error] [pid 17707:tid 17899] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wpgum.php"] [unique_id "amunBrJM3qlhBlpwZyAqHAAAAMM"]
[Thu Jul 30 14:33:26.557997 2026] [security2:error] [pid 17707:tid 17795] [remote 57.141.0.49:31000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amunBrJM3qlhBlpwZyAqIAAAzlc"]
[Thu Jul 30 14:33:26.628258 2026] [security2:error] [pid 17707:tid 17880] [client 20.52.125.110:2069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amunBrJM3qlhBlpwZyAqJAAAALA"]
[Thu Jul 30 14:33:26.640150 2026] [security2:error] [pid 17707:tid 17945] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ywwbf.php"] [unique_id "amunBrJM3qlhBlpwZyAqJQAAAPE"]
[Thu Jul 30 14:33:26.640281 2026] [security2:error] [pid 17707:tid 17945] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ywwbf.php"] [unique_id "amunBrJM3qlhBlpwZyAqJQAAAPE"]
[Thu Jul 30 14:33:26.845787 2026] [core:notice] [pid 17707:tid 17777] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:26.849870 2026] [security2:error] [pid 17707:tid 17890] [client 189.156.226.90:27272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunBrJM3qlhBlpwZyAqKgAAALo"]
[Thu Jul 30 14:33:26.849991 2026] [security2:error] [pid 17707:tid 17890] [client 189.156.226.90:27272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunBrJM3qlhBlpwZyAqKgAAALo"]
[Thu Jul 30 14:33:26.879777 2026] [security2:error] [pid 17707:tid 17947] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/xoldj.php"] [unique_id "amunBrJM3qlhBlpwZyAqKwAAAPM"]
[Thu Jul 30 14:33:26.879859 2026] [security2:error] [pid 17707:tid 17947] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/xoldj.php"] [unique_id "amunBrJM3qlhBlpwZyAqKwAAAPM"]
[Thu Jul 30 14:33:27.112063 2026] [security2:error] [pid 17707:tid 17964] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/f35.php"] [unique_id "amunB7JM3qlhBlpwZyAqMAAAAQQ"]
[Thu Jul 30 14:33:27.112173 2026] [security2:error] [pid 17707:tid 17964] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/f35.php"] [unique_id "amunB7JM3qlhBlpwZyAqMAAAAQQ"]
[Thu Jul 30 14:33:27.231819 2026] [security2:error] [pid 17707:tid 17885] [client 20.52.125.110:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amunB7JM3qlhBlpwZyAqNwAAALU"]
[Thu Jul 30 14:33:27.312491 2026] [security2:error] [pid 17707:tid 17892] [client 52.238.199.152:52459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ty.php"] [unique_id "amunB7JM3qlhBlpwZyAqOAAAALw"]
[Thu Jul 30 14:33:27.644918 2026] [security2:error] [pid 17707:tid 17926] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gk.php"] [unique_id "amunB7JM3qlhBlpwZyAqPQAAAN4"]
[Thu Jul 30 14:33:27.645037 2026] [security2:error] [pid 17707:tid 17926] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gk.php"] [unique_id "amunB7JM3qlhBlpwZyAqPQAAAN4"]
[Thu Jul 30 14:33:27.891114 2026] [security2:error] [pid 17707:tid 17865] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/584062352875874akp.php"] [unique_id "amunB7JM3qlhBlpwZyAqRQAAAKE"]
[Thu Jul 30 14:33:27.891229 2026] [security2:error] [pid 17707:tid 17865] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/584062352875874akp.php"] [unique_id "amunB7JM3qlhBlpwZyAqRQAAAKE"]
[Thu Jul 30 14:33:28.143096 2026] [security2:error] [pid 17707:tid 17949] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wper3.php"] [unique_id "amunCLJM3qlhBlpwZyAqSQAAAPU"]
[Thu Jul 30 14:33:28.143219 2026] [security2:error] [pid 17707:tid 17949] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wper3.php"] [unique_id "amunCLJM3qlhBlpwZyAqSQAAAPU"]
[Thu Jul 30 14:33:28.428286 2026] [security2:error] [pid 17707:tid 17845] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/bthil.php"] [unique_id "amunCLJM3qlhBlpwZyAqVAAAAI0"]
[Thu Jul 30 14:33:28.428435 2026] [security2:error] [pid 17707:tid 17845] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/bthil.php"] [unique_id "amunCLJM3qlhBlpwZyAqVAAAAI0"]
[Thu Jul 30 14:33:28.658773 2026] [security2:error] [pid 17707:tid 17840] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wyzer1.php"] [unique_id "amunCLJM3qlhBlpwZyAqXAAAAIg"]
[Thu Jul 30 14:33:28.658886 2026] [security2:error] [pid 17707:tid 17840] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wyzer1.php"] [unique_id "amunCLJM3qlhBlpwZyAqXAAAAIg"]
[Thu Jul 30 14:33:28.708063 2026] [security2:error] [pid 17707:tid 17923] [client 20.104.18.253:48766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/_Podt.php"] [unique_id "amunCLJM3qlhBlpwZyAqXgAAANs"]
[Thu Jul 30 14:33:28.891756 2026] [security2:error] [pid 17707:tid 17943] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/mh.php"] [unique_id "amunCLJM3qlhBlpwZyAqZQAAAO8"]
[Thu Jul 30 14:33:28.891915 2026] [security2:error] [pid 17707:tid 17943] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/mh.php"] [unique_id "amunCLJM3qlhBlpwZyAqZQAAAO8"]
[Thu Jul 30 14:33:29.302927 2026] [security2:error] [pid 17707:tid 17870] [client 20.104.18.253:48730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/_adminer.php"] [unique_id "amunCbJM3qlhBlpwZyAqbwAAAKY"]
[Thu Jul 30 14:33:29.459353 2026] [security2:error] [pid 17707:tid 17964] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amunCbJM3qlhBlpwZyAqdQAAAQQ"]
[Thu Jul 30 14:33:29.459497 2026] [security2:error] [pid 17707:tid 17964] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amunCbJM3qlhBlpwZyAqdQAAAQQ"]
[Thu Jul 30 14:33:29.633843 2026] [security2:error] [pid 17707:tid 17900] [client 52.238.199.152:3887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/readme.php"] [unique_id "amunCbJM3qlhBlpwZyAqeQAAAMQ"]
[Thu Jul 30 14:33:29.699879 2026] [security2:error] [pid 17707:tid 17873] [client 193.47.62.167:53562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ryg.owl.temporary.site"] [uri "/public/index.php"] [unique_id "amunCLJM3qlhBlpwZyAqZAAAAKk"]
[Thu Jul 30 14:33:29.710423 2026] [security2:error] [pid 17707:tid 17892] [client 158.158.45.59:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amunCbJM3qlhBlpwZyAqegAAALw"]
[Thu Jul 30 14:33:29.710528 2026] [security2:error] [pid 17707:tid 17892] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amunCbJM3qlhBlpwZyAqegAAALw"]
[Thu Jul 30 14:33:29.710625 2026] [security2:error] [pid 17707:tid 17892] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amunCbJM3qlhBlpwZyAqegAAALw"]
[Thu Jul 30 14:33:29.896135 2026] [security2:error] [pid 17707:tid 17863] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunCbJM3qlhBlpwZyAqbQAAnzc"]
[Thu Jul 30 14:33:29.897276 2026] [security2:error] [pid 17707:tid 17886] [client 20.52.125.110:2186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-p.php7"] [unique_id "amunCbJM3qlhBlpwZyAqgQAAALY"]
[Thu Jul 30 14:33:29.909275 2026] [security2:error] [pid 17707:tid 17931] [client 20.104.18.253:48712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/a.php"] [unique_id "amunCbJM3qlhBlpwZyAqggAAAOM"]
[Thu Jul 30 14:33:29.955507 2026] [security2:error] [pid 17707:tid 17853] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/chosen.php"] [unique_id "amunCbJM3qlhBlpwZyAqgwAAAJU"]
[Thu Jul 30 14:33:29.955618 2026] [security2:error] [pid 17707:tid 17853] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/chosen.php"] [unique_id "amunCbJM3qlhBlpwZyAqgwAAAJU"]
[Thu Jul 30 14:33:30.192713 2026] [security2:error] [pid 17707:tid 17906] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/sd.php"] [unique_id "amunCrJM3qlhBlpwZyAqhwAAAMo"]
[Thu Jul 30 14:33:30.192837 2026] [security2:error] [pid 17707:tid 17906] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/sd.php"] [unique_id "amunCrJM3qlhBlpwZyAqhwAAAMo"]
[Thu Jul 30 14:33:30.502562 2026] [security2:error] [pid 17707:tid 17838] [client 20.104.18.253:2649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/a1.php"] [unique_id "amunCrJM3qlhBlpwZyAqjgAAAIY"]
[Thu Jul 30 14:33:30.575046 2026] [security2:error] [pid 17707:tid 17858] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/z60.php"] [unique_id "amunCrJM3qlhBlpwZyAqjwAAAJo"]
[Thu Jul 30 14:33:30.575166 2026] [security2:error] [pid 17707:tid 17858] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/z60.php"] [unique_id "amunCrJM3qlhBlpwZyAqjwAAAJo"]
[Thu Jul 30 14:33:30.754364 2026] [security2:error] [pid 17707:tid 17912] [client 20.52.125.110:2671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-admin/repeater.php"] [unique_id "amunCrJM3qlhBlpwZyAqlwAAANA"]
[Thu Jul 30 14:33:30.847958 2026] [security2:error] [pid 17707:tid 17848] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/home.php"] [unique_id "amunCrJM3qlhBlpwZyAqmwAAAJA"]
[Thu Jul 30 14:33:30.848080 2026] [security2:error] [pid 17707:tid 17848] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/home.php"] [unique_id "amunCrJM3qlhBlpwZyAqmwAAAJA"]
[Thu Jul 30 14:33:30.915801 2026] [security2:error] [pid 17707:tid 17916] [client 177.6.106.101:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunCrJM3qlhBlpwZyAqnwAAANQ"]
[Thu Jul 30 14:33:30.915900 2026] [security2:error] [pid 17707:tid 17916] [client 177.6.106.101:57054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunCrJM3qlhBlpwZyAqnwAAANQ"]
[Thu Jul 30 14:33:31.099193 2026] [security2:error] [pid 17707:tid 17945] [client 20.104.18.253:2643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/a2.php"] [unique_id "amunC7JM3qlhBlpwZyAqpAAAAPE"]
[Thu Jul 30 14:33:31.215738 2026] [security2:error] [pid 17707:tid 17890] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ws58.php"] [unique_id "amunC7JM3qlhBlpwZyAqpQAAALo"]
[Thu Jul 30 14:33:31.215853 2026] [security2:error] [pid 17707:tid 17890] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ws58.php"] [unique_id "amunC7JM3qlhBlpwZyAqpQAAALo"]
[Thu Jul 30 14:33:31.265855 2026] [security2:error] [pid 17707:tid 17877] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunCrJM3qlhBlpwZyAqkgAArW4"]
[Thu Jul 30 14:33:31.274602 2026] [security2:error] [pid 17707:tid 17861] [client 20.52.125.110:2181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-includes/repeater.php"] [unique_id "amunC7JM3qlhBlpwZyAqqwAAAJ0"]
[Thu Jul 30 14:33:31.462490 2026] [security2:error] [pid 17707:tid 17875] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gulu.php"] [unique_id "amunC7JM3qlhBlpwZyAqsAAAAKs"]
[Thu Jul 30 14:33:31.462608 2026] [security2:error] [pid 17707:tid 17875] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/gulu.php"] [unique_id "amunC7JM3qlhBlpwZyAqsAAAAKs"]
[Thu Jul 30 14:33:31.613655 2026] [security2:error] [pid 17707:tid 17963] [client 66.249.90.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunC7JM3qlhBlpwZyAqowAAAQM"]
[Thu Jul 30 14:33:31.711080 2026] [security2:error] [pid 17707:tid 17866] [client 20.104.18.253:2628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/a3.php"] [unique_id "amunC7JM3qlhBlpwZyAqtAAAAKI"]
[Thu Jul 30 14:33:31.714607 2026] [security2:error] [pid 17707:tid 17914] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amunC7JM3qlhBlpwZyAqtQAAANI"]
[Thu Jul 30 14:33:31.714681 2026] [security2:error] [pid 17707:tid 17914] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amunC7JM3qlhBlpwZyAqtQAAANI"]
[Thu Jul 30 14:33:31.878170 2026] [security2:error] [pid 17707:tid 17722] [remote 57.141.0.12:54608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amunC7JM3qlhBlpwZyAqwAAAtw4"]
[Thu Jul 30 14:33:31.947243 2026] [security2:error] [pid 17707:tid 17853] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wpls.php"] [unique_id "amunC7JM3qlhBlpwZyAqwwAAAJU"]
[Thu Jul 30 14:33:31.947336 2026] [security2:error] [pid 17707:tid 17853] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wpls.php"] [unique_id "amunC7JM3qlhBlpwZyAqwwAAAJU"]
[Thu Jul 30 14:33:32.109272 2026] [core:notice] [pid 17707:tid 17924] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:32.181441 2026] [security2:error] [pid 17707:tid 17907] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/php.php"] [unique_id "amunDLJM3qlhBlpwZyAqxgAAAMs"]
[Thu Jul 30 14:33:32.181562 2026] [security2:error] [pid 17707:tid 17907] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/php.php"] [unique_id "amunDLJM3qlhBlpwZyAqxgAAAMs"]
[Thu Jul 30 14:33:32.311963 2026] [security2:error] [pid 17707:tid 17955] [client 20.104.18.253:2647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/aa.php"] [unique_id "amunDLJM3qlhBlpwZyAqygAAAPs"]
[Thu Jul 30 14:33:32.417608 2026] [security2:error] [pid 17707:tid 17953] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/100.php"] [unique_id "amunDLJM3qlhBlpwZyAq0QAAAPk"]
[Thu Jul 30 14:33:32.417697 2026] [security2:error] [pid 17707:tid 17953] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/100.php"] [unique_id "amunDLJM3qlhBlpwZyAq0QAAAPk"]
[Thu Jul 30 14:33:32.603309 2026] [security2:error] [pid 17707:tid 17895] [client 20.52.125.110:2645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/wp-content/repeater.php"] [unique_id "amunDLJM3qlhBlpwZyAq0wAAAL8"]
[Thu Jul 30 14:33:32.650532 2026] [security2:error] [pid 17707:tid 17884] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/BDKR28WP.php"] [unique_id "amunDLJM3qlhBlpwZyAq1AAAALQ"]
[Thu Jul 30 14:33:32.650645 2026] [security2:error] [pid 17707:tid 17884] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/BDKR28WP.php"] [unique_id "amunDLJM3qlhBlpwZyAq1AAAALQ"]
[Thu Jul 30 14:33:32.882620 2026] [security2:error] [pid 17707:tid 17957] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/browse.php"] [unique_id "amunDLJM3qlhBlpwZyAq2AAAAP0"]
[Thu Jul 30 14:33:32.882746 2026] [security2:error] [pid 17707:tid 17957] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/browse.php"] [unique_id "amunDLJM3qlhBlpwZyAq2AAAAP0"]
[Thu Jul 30 14:33:32.919914 2026] [security2:error] [pid 17707:tid 17859] [client 20.104.18.253:48759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/aaa.php"] [unique_id "amunDLJM3qlhBlpwZyAq3AAAAJs"]
[Thu Jul 30 14:33:33.106452 2026] [security2:error] [pid 17707:tid 17897] [client 52.238.199.152:16737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/options.php"] [unique_id "amunDbJM3qlhBlpwZyAq4AAAAME"]
[Thu Jul 30 14:33:33.126410 2026] [security2:error] [pid 17707:tid 17904] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-good.php"] [unique_id "amunDbJM3qlhBlpwZyAq4QAAAMg"]
[Thu Jul 30 14:33:33.126496 2026] [security2:error] [pid 17707:tid 17904] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-good.php"] [unique_id "amunDbJM3qlhBlpwZyAq4QAAAMg"]
[Thu Jul 30 14:33:33.430004 2026] [security2:error] [pid 17707:tid 17841] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/8573.php"] [unique_id "amunDbJM3qlhBlpwZyAq6AAAAIk"]
[Thu Jul 30 14:33:33.430109 2026] [security2:error] [pid 17707:tid 17841] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/8573.php"] [unique_id "amunDbJM3qlhBlpwZyAq6AAAAIk"]
[Thu Jul 30 14:33:33.553444 2026] [security2:error] [pid 17707:tid 17877] [client 20.104.18.253:2674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/aaaa.php"] [unique_id "amunDbJM3qlhBlpwZyAq7AAAAK0"]
[Thu Jul 30 14:33:33.684872 2026] [security2:error] [pid 17707:tid 17870] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-admin/install.php"] [unique_id "amunDbJM3qlhBlpwZyAq7QAAAKY"]
[Thu Jul 30 14:33:33.685023 2026] [security2:error] [pid 17707:tid 17870] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-admin/install.php"] [unique_id "amunDbJM3qlhBlpwZyAq7QAAAKY"]
[Thu Jul 30 14:33:33.793775 2026] [security2:error] [pid 17707:tid 17947] [client 20.226.5.174:37581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/leaf_mailer.php"] [unique_id "amunDbJM3qlhBlpwZyAq8QAAAPM"]
[Thu Jul 30 14:33:33.861350 2026] [security2:error] [pid 17707:tid 17962] [client 180.243.59.178:65419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunDbJM3qlhBlpwZyAq9QAAAQI"]
[Thu Jul 30 14:33:33.861470 2026] [security2:error] [pid 17707:tid 17962] [client 180.243.59.178:65419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunDbJM3qlhBlpwZyAq9QAAAQI"]
[Thu Jul 30 14:33:34.139769 2026] [security2:error] [pid 17707:tid 17862] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/classwithtostring.php"] [unique_id "amunDrJM3qlhBlpwZyAq-gAAAJ4"]
[Thu Jul 30 14:33:34.139880 2026] [security2:error] [pid 17707:tid 17862] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/classwithtostring.php"] [unique_id "amunDrJM3qlhBlpwZyAq-gAAAJ4"]
[Thu Jul 30 14:33:34.196176 2026] [security2:error] [pid 17707:tid 17892] [client 20.104.18.253:48728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/aahana/json.php"] [unique_id "amunDrJM3qlhBlpwZyAq-wAAALw"]
[Thu Jul 30 14:33:34.359293 2026] [security2:error] [pid 17707:tid 17914] [client 52.238.199.152:17096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/admin.php7"] [unique_id "amunDrJM3qlhBlpwZyArAwAAANI"]
[Thu Jul 30 14:33:34.388614 2026] [security2:error] [pid 17707:tid 17932] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ohct.php"] [unique_id "amunDrJM3qlhBlpwZyArBAAAAOQ"]
[Thu Jul 30 14:33:34.388721 2026] [security2:error] [pid 17707:tid 17932] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ohct.php"] [unique_id "amunDrJM3qlhBlpwZyArBAAAAOQ"]
[Thu Jul 30 14:33:34.659805 2026] [security2:error] [pid 17707:tid 17856] [client 77.83.36.161:7433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amunDrJM3qlhBlpwZyArBQAAAJg"]
[Thu Jul 30 14:33:34.686679 2026] [security2:error] [pid 17707:tid 17932] [client 20.226.5.174:37574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/leaf_php.php"] [unique_id "amunDrJM3qlhBlpwZyArCQAAAOQ"]
[Thu Jul 30 14:33:34.808223 2026] [security2:error] [pid 17707:tid 17849] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/bless.php"] [unique_id "amunDrJM3qlhBlpwZyArDQAAAJE"]
[Thu Jul 30 14:33:34.808328 2026] [security2:error] [pid 17707:tid 17849] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/bless.php"] [unique_id "amunDrJM3qlhBlpwZyArDQAAAJE"]
[Thu Jul 30 14:33:34.850488 2026] [security2:error] [pid 17707:tid 17891] [client 20.104.18.253:48714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/aahana/worksec.php"] [unique_id "amunDrJM3qlhBlpwZyArDgAAALs"]
[Thu Jul 30 14:33:35.248798 2026] [security2:error] [pid 17707:tid 17936] [client 77.83.36.161:7891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amunD7JM3qlhBlpwZyArGAAAAOg"]
[Thu Jul 30 14:33:35.473536 2026] [security2:error] [pid 17707:tid 17952] [client 20.104.18.253:48737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ab.php"] [unique_id "amunD7JM3qlhBlpwZyArIQAAAPg"]
[Thu Jul 30 14:33:35.595168 2026] [security2:error] [pid 17707:tid 17890] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amunD7JM3qlhBlpwZyArJQAAALo"]
[Thu Jul 30 14:33:35.595301 2026] [security2:error] [pid 17707:tid 17890] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amunD7JM3qlhBlpwZyArJQAAALo"]
[Thu Jul 30 14:33:35.642437 2026] [security2:error] [pid 17707:tid 17957] [client 20.226.5.174:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/leafmailer.php"] [unique_id "amunD7JM3qlhBlpwZyArJgAAAP0"]
[Thu Jul 30 14:33:35.841007 2026] [security2:error] [pid 17707:tid 17927] [client 77.83.36.161:8209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amunD7JM3qlhBlpwZyArKAAAAN8"]
[Thu Jul 30 14:33:35.851275 2026] [security2:error] [pid 17707:tid 17867] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amunD7JM3qlhBlpwZyArKQAAAKM"]
[Thu Jul 30 14:33:35.851374 2026] [security2:error] [pid 17707:tid 17867] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amunD7JM3qlhBlpwZyArKQAAAKM"]
[Thu Jul 30 14:33:36.094163 2026] [security2:error] [pid 17707:tid 17958] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ta0ol.php"] [unique_id "amunELJM3qlhBlpwZyArNQAAAP4"]
[Thu Jul 30 14:33:36.094268 2026] [security2:error] [pid 17707:tid 17958] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ta0ol.php"] [unique_id "amunELJM3qlhBlpwZyArNQAAAP4"]
[Thu Jul 30 14:33:36.146330 2026] [security2:error] [pid 17707:tid 17877] [client 20.104.18.253:48741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/abby.php"] [unique_id "amunELJM3qlhBlpwZyArNwAAAK0"]
[Thu Jul 30 14:33:36.332615 2026] [security2:error] [pid 17707:tid 17900] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/sa.php7"] [unique_id "amunELJM3qlhBlpwZyArOAAAAMQ"]
[Thu Jul 30 14:33:36.332780 2026] [security2:error] [pid 17707:tid 17900] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/sa.php7"] [unique_id "amunELJM3qlhBlpwZyArOAAAAMQ"]
[Thu Jul 30 14:33:36.537287 2026] [security2:error] [pid 17707:tid 17851] [client 20.226.5.174:37573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/leafmailer.php.php"] [unique_id "amunELJM3qlhBlpwZyArQAAAAJM"]
[Thu Jul 30 14:33:36.562251 2026] [security2:error] [pid 17707:tid 17753] [remote 57.141.0.46:54768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amunELJM3qlhBlpwZyArRAAAoi0"]
[Thu Jul 30 14:33:36.572192 2026] [security2:error] [pid 17707:tid 17853] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-class.php"] [unique_id "amunELJM3qlhBlpwZyArRQAAAJU"]
[Thu Jul 30 14:33:36.572297 2026] [security2:error] [pid 17707:tid 17853] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-class.php"] [unique_id "amunELJM3qlhBlpwZyArRQAAAJU"]
[Thu Jul 30 14:33:36.807396 2026] [security2:error] [pid 17707:tid 17865] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amunELJM3qlhBlpwZyArRgAAAKE"]
[Thu Jul 30 14:33:36.807537 2026] [security2:error] [pid 17707:tid 17865] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amunELJM3qlhBlpwZyArRgAAAKE"]
[Thu Jul 30 14:33:36.846267 2026] [security2:error] [pid 17707:tid 17931] [client 20.104.18.253:2629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/abc.php"] [unique_id "amunELJM3qlhBlpwZyArRwAAAOM"]
[Thu Jul 30 14:33:37.071663 2026] [security2:error] [pid 17707:tid 17902] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/bootstrap.php"] [unique_id "amunEbJM3qlhBlpwZyArTgAAAMY"]
[Thu Jul 30 14:33:37.071789 2026] [security2:error] [pid 17707:tid 17902] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/bootstrap.php"] [unique_id "amunEbJM3qlhBlpwZyArTgAAAMY"]
[Thu Jul 30 14:33:37.077151 2026] [security2:error] [pid 17707:tid 17886] [client 204.12.208.18:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-includes/x1823cc/index.php"] [unique_id "amunEbJM3qlhBlpwZyArTwAAALY"], referer: https://saifalkhaleejest.com/wp-includes/x1823cc/index.php
[Thu Jul 30 14:33:37.383960 2026] [security2:error] [pid 17707:tid 17858] [client 189.156.226.90:27712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunEbJM3qlhBlpwZyArUwAAAJo"]
[Thu Jul 30 14:33:37.384115 2026] [security2:error] [pid 17707:tid 17858] [client 189.156.226.90:27712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunEbJM3qlhBlpwZyArUwAAAJo"]
[Thu Jul 30 14:33:37.435904 2026] [security2:error] [pid 17707:tid 17857] [client 20.226.5.174:37596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/leafmailer2.8.php"] [unique_id "amunEbJM3qlhBlpwZyArVAAAAJk"]
[Thu Jul 30 14:33:37.470998 2026] [security2:error] [pid 17707:tid 17860] [client 20.104.18.253:48736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/abcd.php"] [unique_id "amunEbJM3qlhBlpwZyArWAAAAJw"]
[Thu Jul 30 14:33:37.522446 2026] [security2:error] [pid 17707:tid 17916] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-blog-header.php"] [unique_id "amunEbJM3qlhBlpwZyArXAAAANQ"]
[Thu Jul 30 14:33:37.522570 2026] [security2:error] [pid 17707:tid 17916] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-blog-header.php"] [unique_id "amunEbJM3qlhBlpwZyArXAAAANQ"]
[Thu Jul 30 14:33:37.778215 2026] [security2:error] [pid 17707:tid 17854] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/aa.php"] [unique_id "amunEbJM3qlhBlpwZyArYwAAAJY"]
[Thu Jul 30 14:33:37.778344 2026] [security2:error] [pid 17707:tid 17854] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/aa.php"] [unique_id "amunEbJM3qlhBlpwZyArYwAAAJY"]
[Thu Jul 30 14:33:38.069062 2026] [security2:error] [pid 17707:tid 17850] [client 20.104.18.253:2642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/abcde.php"] [unique_id "amunErJM3qlhBlpwZyAraAAAAJI"]
[Thu Jul 30 14:33:38.187049 2026] [security2:error] [pid 17707:tid 17915] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/tx79.php"] [unique_id "amunErJM3qlhBlpwZyArcgAAANM"]
[Thu Jul 30 14:33:38.187142 2026] [security2:error] [pid 17707:tid 17915] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/tx79.php"] [unique_id "amunErJM3qlhBlpwZyArcgAAANM"]
[Thu Jul 30 14:33:38.330945 2026] [security2:error] [pid 17707:tid 17929] [client 20.226.5.174:37575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/led.php"] [unique_id "amunErJM3qlhBlpwZyArcwAAAOE"]
[Thu Jul 30 14:33:38.419184 2026] [security2:error] [pid 17707:tid 17877] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/motu.php"] [unique_id "amunErJM3qlhBlpwZyArdAAAAK0"]
[Thu Jul 30 14:33:38.419303 2026] [security2:error] [pid 17707:tid 17877] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/motu.php"] [unique_id "amunErJM3qlhBlpwZyArdAAAAK0"]
[Thu Jul 30 14:33:38.686084 2026] [security2:error] [pid 17707:tid 17892] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-head.php"] [unique_id "amunErJM3qlhBlpwZyArewAAALw"]
[Thu Jul 30 14:33:38.686191 2026] [security2:error] [pid 17707:tid 17892] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-head.php"] [unique_id "amunErJM3qlhBlpwZyArewAAALw"]
[Thu Jul 30 14:33:38.698849 2026] [security2:error] [pid 17707:tid 17901] [client 20.104.18.253:2888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/about.php"] [unique_id "amunErJM3qlhBlpwZyArfAAAAMU"]
[Thu Jul 30 14:33:39.006120 2026] [security2:error] [pid 17707:tid 17889] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-admin/options-privacy.php"] [unique_id "amunE7JM3qlhBlpwZyArgAAAALk"]
[Thu Jul 30 14:33:39.006238 2026] [security2:error] [pid 17707:tid 17889] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-admin/options-privacy.php"] [unique_id "amunE7JM3qlhBlpwZyArgAAAALk"]
[Thu Jul 30 14:33:39.226461 2026] [security2:error] [pid 17707:tid 17852] [client 20.226.5.174:37572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/legal.php"] [unique_id "amunE7JM3qlhBlpwZyArjwAAAJQ"]
[Thu Jul 30 14:33:39.267967 2026] [security2:error] [pid 17707:tid 17891] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/60856e3a4findex.php"] [unique_id "amunE7JM3qlhBlpwZyArkwAAALs"]
[Thu Jul 30 14:33:39.268084 2026] [security2:error] [pid 17707:tid 17891] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/60856e3a4findex.php"] [unique_id "amunE7JM3qlhBlpwZyArkwAAALs"]
[Thu Jul 30 14:33:39.321020 2026] [security2:error] [pid 17707:tid 17856] [client 20.104.18.253:48716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/about.php/wp-content/x/index.php"] [unique_id "amunE7JM3qlhBlpwZyArlAAAAJg"]
[Thu Jul 30 14:33:39.513441 2026] [security2:error] [pid 17707:tid 17857] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-the.php"] [unique_id "amunE7JM3qlhBlpwZyArlQAAAJk"]
[Thu Jul 30 14:33:39.513558 2026] [security2:error] [pid 17707:tid 17857] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp-the.php"] [unique_id "amunE7JM3qlhBlpwZyArlQAAAJk"]
[Thu Jul 30 14:33:39.583869 2026] [security2:error] [pid 17707:tid 17845] [client 20.226.5.174:50513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/simple/simple.php"] [unique_id "amunE7JM3qlhBlpwZyArmgAAAI0"]
[Thu Jul 30 14:33:39.917596 2026] [security2:error] [pid 17707:tid 17842] [client 20.104.18.253:48758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/abuot.php"] [unique_id "amunE7JM3qlhBlpwZyArpgAAAIo"]
[Thu Jul 30 14:33:40.126665 2026] [security2:error] [pid 17707:tid 17919] [client 20.226.5.174:37569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/legion.php"] [unique_id "amunFLJM3qlhBlpwZyArqwAAANc"]
[Thu Jul 30 14:33:40.213639 2026] [security2:error] [pid 17707:tid 17958] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp.php"] [unique_id "amunFLJM3qlhBlpwZyArrwAAAP4"]
[Thu Jul 30 14:33:40.213721 2026] [security2:error] [pid 17707:tid 17958] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wp.php"] [unique_id "amunFLJM3qlhBlpwZyArrwAAAP4"]
[Thu Jul 30 14:33:40.467770 2026] [security2:error] [pid 17707:tid 17892] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/users.php"] [unique_id "amunFLJM3qlhBlpwZyArtgAAALw"]
[Thu Jul 30 14:33:40.467884 2026] [security2:error] [pid 17707:tid 17892] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/users.php"] [unique_id "amunFLJM3qlhBlpwZyArtgAAALw"]
[Thu Jul 30 14:33:40.510880 2026] [security2:error] [pid 17707:tid 17948] [client 20.226.5.174:50502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/simple_cmd.php"] [unique_id "amunFLJM3qlhBlpwZyArtwAAAPQ"]
[Thu Jul 30 14:33:40.554404 2026] [security2:error] [pid 17707:tid 17941] [client 20.104.18.253:48719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ac.php"] [unique_id "amunFLJM3qlhBlpwZyAruAAAAO0"]
[Thu Jul 30 14:33:40.730158 2026] [security2:error] [pid 17707:tid 17914] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/tinysd.php"] [unique_id "amunFLJM3qlhBlpwZyArvwAAANI"]
[Thu Jul 30 14:33:40.730308 2026] [security2:error] [pid 17707:tid 17914] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/tinysd.php"] [unique_id "amunFLJM3qlhBlpwZyArvwAAANI"]
[Thu Jul 30 14:33:40.878017 2026] [security2:error] [pid 17707:tid 17938] [client 52.238.199.152:17149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/wp-login.php"] [unique_id "amunFLJM3qlhBlpwZyArxAAAAOo"]
[Thu Jul 30 14:33:41.023827 2026] [security2:error] [pid 17707:tid 17942] [client 20.226.5.174:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/let.php"] [unique_id "amunFbJM3qlhBlpwZyArxQAAAO4"]
[Thu Jul 30 14:33:41.105141 2026] [security2:error] [pid 17707:tid 17906] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ws78.php"] [unique_id "amunFbJM3qlhBlpwZyArxgAAAMo"]
[Thu Jul 30 14:33:41.105261 2026] [security2:error] [pid 17707:tid 17906] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ws78.php"] [unique_id "amunFbJM3qlhBlpwZyArxgAAAMo"]
[Thu Jul 30 14:33:41.153566 2026] [security2:error] [pid 17707:tid 17849] [client 20.104.18.253:48763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/acces.php"] [unique_id "amunFbJM3qlhBlpwZyArygAAAJE"]
[Thu Jul 30 14:33:41.340847 2026] [security2:error] [pid 17707:tid 17916] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/elp.php"] [unique_id "amunFbJM3qlhBlpwZyAr1AAAANQ"]
[Thu Jul 30 14:33:41.340946 2026] [security2:error] [pid 17707:tid 17916] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/elp.php"] [unique_id "amunFbJM3qlhBlpwZyAr1AAAANQ"]
[Thu Jul 30 14:33:41.463041 2026] [security2:error] [pid 17707:tid 17891] [client 20.226.5.174:50509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/sindex.php"] [unique_id "amunFbJM3qlhBlpwZyAr1QAAALs"]
[Thu Jul 30 14:33:41.521037 2026] [security2:error] [pid 17707:tid 17922] [client 177.6.106.101:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunFbJM3qlhBlpwZyAr1gAAANo"]
[Thu Jul 30 14:33:41.521572 2026] [security2:error] [pid 17707:tid 17922] [client 177.6.106.101:53603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunFbJM3qlhBlpwZyAr1gAAANo"]
[Thu Jul 30 14:33:41.527732 2026] [security2:error] [pid 17707:tid 17839] [client 103.231.91.59:47640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amunFbJM3qlhBlpwZyAr1wAAAIc"]
[Thu Jul 30 14:33:41.527802 2026] [security2:error] [pid 17707:tid 17839] [client 103.231.91.59:47640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amunFbJM3qlhBlpwZyAr1wAAAIc"]
[Thu Jul 30 14:33:41.573877 2026] [security2:error] [pid 17707:tid 17859] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/atomlib.php"] [unique_id "amunFbJM3qlhBlpwZyAr2AAAAJs"]
[Thu Jul 30 14:33:41.573970 2026] [security2:error] [pid 17707:tid 17859] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/atomlib.php"] [unique_id "amunFbJM3qlhBlpwZyAr2AAAAJs"]
[Thu Jul 30 14:33:41.766712 2026] [security2:error] [pid 17707:tid 17865] [client 20.104.18.253:48720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/access.php"] [unique_id "amunFbJM3qlhBlpwZyAr3wAAAKE"]
[Thu Jul 30 14:33:41.809621 2026] [security2:error] [pid 17707:tid 17957] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wyzer3.php"] [unique_id "amunFbJM3qlhBlpwZyAr4gAAAP0"]
[Thu Jul 30 14:33:41.809703 2026] [security2:error] [pid 17707:tid 17957] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/wyzer3.php"] [unique_id "amunFbJM3qlhBlpwZyAr4gAAAP0"]
[Thu Jul 30 14:33:41.905588 2026] [security2:error] [pid 17707:tid 17934] [client 52.238.199.152:52537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amunFbJM3qlhBlpwZyAr5AAAAOY"]
[Thu Jul 30 14:33:41.917048 2026] [security2:error] [pid 17707:tid 17910] [client 20.226.5.174:37578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/lf.php"] [unique_id "amunFbJM3qlhBlpwZyAr5QAAAM4"]
[Thu Jul 30 14:33:42.042778 2026] [security2:error] [pid 17707:tid 17875] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/max.php"] [unique_id "amunFrJM3qlhBlpwZyAr5gAAAKs"]
[Thu Jul 30 14:33:42.042886 2026] [security2:error] [pid 17707:tid 17875] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/max.php"] [unique_id "amunFrJM3qlhBlpwZyAr5gAAAKs"]
[Thu Jul 30 14:33:42.281612 2026] [security2:error] [pid 17707:tid 17867] [client 85.208.96.212:16684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/25/pre-candidato-a-governador-veneziano-assume-compromisso-de-implantar-campus-da-uepb-no-vale-do-pianco/"] [unique_id "amunFrJM3qlhBlpwZyAr7gAAAKM"]
[Thu Jul 30 14:33:42.281735 2026] [security2:error] [pid 17707:tid 17867] [client 85.208.96.212:16684] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/25/pre-candidato-a-governador-veneziano-assume-compromisso-de-implantar-campus-da-uepb-no-vale-do-pianco/"] [unique_id "amunFrJM3qlhBlpwZyAr7gAAAKM"]
[Thu Jul 30 14:33:42.303891 2026] [security2:error] [pid 17707:tid 17878] [client 158.158.45.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.45.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ftde.php"] [unique_id "amunFrJM3qlhBlpwZyAr8AAAAK4"]
[Thu Jul 30 14:33:42.304025 2026] [security2:error] [pid 17707:tid 17878] [client 158.158.45.59:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.greecevisaassistanceislamabad.online"] [uri "/ftde.php"] [unique_id "amunFrJM3qlhBlpwZyAr8AAAAK4"]
[Thu Jul 30 14:33:42.390163 2026] [security2:error] [pid 17707:tid 17919] [client 20.104.18.253:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ace.php"] [unique_id "amunFrJM3qlhBlpwZyAr8wAAANc"]
[Thu Jul 30 14:33:42.448177 2026] [security2:error] [pid 17707:tid 17930] [client 20.226.5.174:50529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/sindicat.php"] [unique_id "amunFrJM3qlhBlpwZyAr9AAAAOI"]
[Thu Jul 30 14:33:42.687900 2026] [security2:error] [pid 17707:tid 17845] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunFrJM3qlhBlpwZyAr5wAAjUk"]
[Thu Jul 30 14:33:42.847682 2026] [security2:error] [pid 17707:tid 17921] [client 20.226.5.174:37571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/library.php"] [unique_id "amunFrJM3qlhBlpwZyAr_AAAANk"]
[Thu Jul 30 14:33:43.006748 2026] [security2:error] [pid 17707:tid 17889] [client 20.104.18.253:2209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/acme-challengeadmin.php"] [unique_id "amunF7JM3qlhBlpwZyAsAAAAALk"]
[Thu Jul 30 14:33:43.426480 2026] [security2:error] [pid 17707:tid 17913] [client 20.226.5.174:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/singlee.php"] [unique_id "amunF7JM3qlhBlpwZyAsDQAAANE"]
[Thu Jul 30 14:33:43.650553 2026] [security2:error] [pid 17707:tid 17884] [client 20.104.18.253:48764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/acme-challengealfa.php"] [unique_id "amunF7JM3qlhBlpwZyAsDwAAALQ"]
[Thu Jul 30 14:33:43.754014 2026] [security2:error] [pid 17707:tid 17751] [remote 20.89.80.94:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-login.php"] [unique_id "amunF7JM3qlhBlpwZyAsDgAA8Cs"]
[Thu Jul 30 14:33:43.794645 2026] [security2:error] [pid 17707:tid 17953] [client 20.226.5.174:37577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/library/about.php"] [unique_id "amunF7JM3qlhBlpwZyAsEAAAAPk"]
[Thu Jul 30 14:33:44.025348 2026] [security2:error] [pid 17707:tid 17956] [client 180.243.59.178:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunGLJM3qlhBlpwZyAsGgAAAPw"]
[Thu Jul 30 14:33:44.025497 2026] [security2:error] [pid 17707:tid 17956] [client 180.243.59.178:49553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunGLJM3qlhBlpwZyAsGgAAAPw"]
[Thu Jul 30 14:33:44.262267 2026] [security2:error] [pid 17707:tid 17839] [client 20.104.18.253:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/acme-challengebypass.php"] [unique_id "amunGLJM3qlhBlpwZyAsHQAAAIc"]
[Thu Jul 30 14:33:44.510361 2026] [security2:error] [pid 17707:tid 17936] [client 20.226.5.174:50503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/site-info.php"] [unique_id "amunGLJM3qlhBlpwZyAsKQAAAOg"]
[Thu Jul 30 14:33:44.657774 2026] [security2:error] [pid 17707:tid 17782] [remote 97.74.93.24:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koriusa.info"] [uri "/wp-login.php"] [unique_id "amunGLJM3qlhBlpwZyAsKwAAwUo"]
[Thu Jul 30 14:33:44.790209 2026] [security2:error] [pid 17707:tid 17943] [client 20.226.5.174:37594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/library/index.php"] [unique_id "amunGLJM3qlhBlpwZyAsLAAAAO8"]
[Thu Jul 30 14:33:44.864834 2026] [security2:error] [pid 17707:tid 17876] [client 20.104.18.253:48721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/acme-challengek.php"] [unique_id "amunGLJM3qlhBlpwZyAsLgAAAKw"]
[Thu Jul 30 14:33:45.322891 2026] [security2:error] [pid 17707:tid 17912] [client 52.238.199.152:16730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/file.php"] [unique_id "amunGbJM3qlhBlpwZyAsOgAAANA"]
[Thu Jul 30 14:33:45.468815 2026] [security2:error] [pid 17707:tid 17948] [client 20.104.18.253:2235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/acme-challengewp.php"] [unique_id "amunGbJM3qlhBlpwZyAsQQAAAPQ"]
[Thu Jul 30 14:33:45.569273 2026] [security2:error] [pid 17707:tid 17851] [client 20.226.5.174:50501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/site-title/index.php"] [unique_id "amunGbJM3qlhBlpwZyAsRQAAAJM"]
[Thu Jul 30 14:33:45.776255 2026] [security2:error] [pid 17707:tid 17931] [client 20.226.5.174:37591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/libs.php"] [unique_id "amunGbJM3qlhBlpwZyAsRwAAAOM"]
[Thu Jul 30 14:33:45.794944 2026] [security2:error] [pid 17707:tid 17853] [client 216.244.66.236:37132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amunGbJM3qlhBlpwZyAsSAAAAJU"]
[Thu Jul 30 14:33:45.795070 2026] [security2:error] [pid 17707:tid 17853] [client 216.244.66.236:37132] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amunGbJM3qlhBlpwZyAsSAAAAJU"]
[Thu Jul 30 14:33:46.101413 2026] [security2:error] [pid 17707:tid 17937] [client 20.104.18.253:2223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ad.php"] [unique_id "amunGrJM3qlhBlpwZyAsVQAAAOk"]
[Thu Jul 30 14:33:46.544428 2026] [security2:error] [pid 17707:tid 17896] [client 20.226.5.174:50497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/sitemap.php"] [unique_id "amunGrJM3qlhBlpwZyAsYQAAAMA"]
[Thu Jul 30 14:33:46.600802 2026] [security2:error] [pid 17707:tid 17955] [client 52.238.199.152:52477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/bak.php"] [unique_id "amunGrJM3qlhBlpwZyAsZQAAAPs"]
[Thu Jul 30 14:33:46.718166 2026] [security2:error] [pid 17707:tid 17888] [client 20.104.18.253:2221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/ad24f.php"] [unique_id "amunGrJM3qlhBlpwZyAsZgAAALg"]
[Thu Jul 30 14:33:46.747638 2026] [security2:error] [pid 17707:tid 17935] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunGrJM3qlhBlpwZyAsVwAA50M"]
[Thu Jul 30 14:33:46.759903 2026] [security2:error] [pid 17707:tid 17928] [client 20.226.5.174:37584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/license.php"] [unique_id "amunGrJM3qlhBlpwZyAsZwAAAOA"]
[Thu Jul 30 14:33:46.877127 2026] [security2:error] [pid 17707:tid 17846] [client 74.7.230.14:41058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pkfkurdistan.com"] [uri "/cgi-sys/404.html"] [unique_id "amunGrJM3qlhBlpwZyAsaAAAjlQ"]
[Thu Jul 30 14:33:47.334033 2026] [security2:error] [pid 17707:tid 17877] [client 20.104.18.253:2199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/add-venue-ru.php"] [unique_id "amunG7JM3qlhBlpwZyAsdgAAAK0"]
[Thu Jul 30 14:33:47.522099 2026] [security2:error] [pid 17707:tid 17926] [client 20.226.5.174:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/sitemaps.php"] [unique_id "amunG7JM3qlhBlpwZyAsegAAAN4"]
[Thu Jul 30 14:33:47.936668 2026] [security2:error] [pid 17707:tid 17862] [client 189.156.226.90:26716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunG7JM3qlhBlpwZyAshQAAAJ4"]
[Thu Jul 30 14:33:47.936790 2026] [security2:error] [pid 17707:tid 17862] [client 189.156.226.90:26716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunG7JM3qlhBlpwZyAshQAAAJ4"]
[Thu Jul 30 14:33:47.978611 2026] [security2:error] [pid 17707:tid 17851] [client 20.104.18.253:2200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.qpsuae.com"] [uri "/adm.php"] [unique_id "amunG7JM3qlhBlpwZyAsiAAAAJM"]
[Thu Jul 30 14:33:47.980993 2026] [security2:error] [pid 17707:tid 17885] [client 20.226.5.174:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/license.txt/xmlrpc.php"] [unique_id "amunG7JM3qlhBlpwZyAshAAAALU"]
[Thu Jul 30 14:33:48.047865 2026] [core:notice] [pid 17707:tid 17889] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:48.185151 2026] [core:notice] [pid 17707:tid 17852] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:48.521238 2026] [security2:error] [pid 17707:tid 17874] [client 20.226.5.174:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/siteone.php"] [unique_id "amunHLJM3qlhBlpwZyAslgAAAKo"]
[Thu Jul 30 14:33:48.522807 2026] [core:notice] [pid 17707:tid 17959] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:48.922628 2026] [core:notice] [pid 17707:tid 17839] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:33:48.935203 2026] [security2:error] [pid 17707:tid 17923] [client 20.226.5.174:37606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/licenses.php"] [unique_id "amunHLJM3qlhBlpwZyAsnwAAANs"]
[Thu Jul 30 14:33:49.204388 2026] [security2:error] [pid 17707:tid 17845] [client 52.238.199.152:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/config.php"] [unique_id "amunHbJM3qlhBlpwZyAspwAAAI0"]
[Thu Jul 30 14:33:49.498787 2026] [security2:error] [pid 17707:tid 17888] [client 20.226.5.174:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/sites/default/wp-login.php"] [unique_id "amunHbJM3qlhBlpwZyAsqwAAALg"]
[Thu Jul 30 14:33:49.844468 2026] [security2:error] [pid 17707:tid 17875] [client 20.226.5.174:37579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/lightspped.php"] [unique_id "amunHbJM3qlhBlpwZyAstgAAAKs"]
[Thu Jul 30 14:33:50.034277 2026] [security2:error] [pid 17707:tid 17897] [client 40.77.167.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amunHbJM3qlhBlpwZyAsuQAAAME"]
[Thu Jul 30 14:33:50.230370 2026] [security2:error] [pid 17707:tid 17908] [client 20.40.58.237:64768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amunHrJM3qlhBlpwZyAswQAAAMw"]
[Thu Jul 30 14:33:50.493952 2026] [security2:error] [pid 17707:tid 17930] [client 20.226.5.174:50496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/sitesadmin.php"] [unique_id "amunHrJM3qlhBlpwZyAsxQAAAOI"]
[Thu Jul 30 14:33:50.725367 2026] [security2:error] [pid 17707:tid 17907] [client 85.208.96.205:41306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/11/mega-sena-deste-sabado-11-sorteia-premio-de-r-40-milhoes/"] [unique_id "amunHrJM3qlhBlpwZyAszAAAAMs"]
[Thu Jul 30 14:33:50.725540 2026] [security2:error] [pid 17707:tid 17907] [client 85.208.96.205:41306] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/11/mega-sena-deste-sabado-11-sorteia-premio-de-r-40-milhoes/"] [unique_id "amunHrJM3qlhBlpwZyAszAAAAMs"]
[Thu Jul 30 14:33:50.745694 2026] [security2:error] [pid 17707:tid 17837] [client 20.226.5.174:37589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/link.php"] [unique_id "amunHrJM3qlhBlpwZyAszQAAAIU"]
[Thu Jul 30 14:33:51.020913 2026] [security2:error] [pid 17707:tid 17889] [client 57.141.0.69:30112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koriusa.info"] [uri "/index.php"] [unique_id "amunHrJM3qlhBlpwZyAs0QAAuWs"]
[Thu Jul 30 14:33:51.177904 2026] [security2:error] [pid 17707:tid 17954] [client 152.32.142.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gas.djb.temporary.site"] [uri "/index.php"] [unique_id "amunH7JM3qlhBlpwZyAs2QAAAPo"]
[Thu Jul 30 14:33:51.260487 2026] [security2:error] [pid 17707:tid 17860] [client 52.238.199.152:3871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amunH7JM3qlhBlpwZyAs4AAAAJw"]
[Thu Jul 30 14:33:51.524970 2026] [security2:error] [pid 17707:tid 17883] [client 20.226.5.174:50511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/size.php"] [unique_id "amunH7JM3qlhBlpwZyAs5gAAALM"]
[Thu Jul 30 14:33:51.645163 2026] [security2:error] [pid 17707:tid 17910] [client 20.226.5.174:37586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreview/404.php"] [unique_id "amunH7JM3qlhBlpwZyAs5wAAAM4"]
[Thu Jul 30 14:33:52.055900 2026] [security2:error] [pid 17707:tid 17960] [client 177.6.106.101:54089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunILJM3qlhBlpwZyAs9QAAAQA"]
[Thu Jul 30 14:33:52.057970 2026] [security2:error] [pid 17707:tid 17960] [client 177.6.106.101:54089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunILJM3qlhBlpwZyAs9QAAAQA"]
[Thu Jul 30 14:33:52.213226 2026] [security2:error] [pid 17707:tid 17809] [remote 114.119.153.97:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fantasynamelist.com"] [uri "/about/"] [unique_id "amunILJM3qlhBlpwZyAtAAAA3mU"], referer: https://fantasynamelist.com/character-class/cleric-name-generator/
[Thu Jul 30 14:33:52.275083 2026] [security2:error] [pid 17707:tid 17925] [client 47.128.122.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amunILJM3qlhBlpwZyAs_AAAAN0"]
[Thu Jul 30 14:33:52.275569 2026] [security2:error] [pid 17707:tid 17876] [client 52.238.199.152:52467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-activate.php"] [unique_id "amunILJM3qlhBlpwZyAtAQAAAKw"]
[Thu Jul 30 14:33:52.573165 2026] [security2:error] [pid 17707:tid 17880] [client 172.237.109.114:13707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunILJM3qlhBlpwZyAs-AAAALA"], referer: https://alseermarine.com:443/index.html
[Thu Jul 30 14:33:52.581477 2026] [security2:error] [pid 17707:tid 17901] [client 20.226.5.174:37582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreview/admin.php"] [unique_id "amunILJM3qlhBlpwZyAtCAAAAMU"]
[Thu Jul 30 14:33:52.582821 2026] [security2:error] [pid 17707:tid 17951] [client 20.226.5.174:50515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/sk.php"] [unique_id "amunILJM3qlhBlpwZyAtCQAAAPc"]
[Thu Jul 30 14:33:53.515520 2026] [security2:error] [pid 17707:tid 17964] [client 20.226.5.174:37613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreview/alfa.php"] [unique_id "amunIbJM3qlhBlpwZyAtHwAAAQQ"]
[Thu Jul 30 14:33:54.158708 2026] [security2:error] [pid 17707:tid 17940] [client 52.238.199.152:42744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-file.php"] [unique_id "amunIrJM3qlhBlpwZyAtKwAAAOw"]
[Thu Jul 30 14:33:54.161090 2026] [security2:error] [pid 17707:tid 17923] [client 20.226.5.174:50558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/skatepark/alpha.php"] [unique_id "amunIrJM3qlhBlpwZyAtLAAAANs"]
[Thu Jul 30 14:33:54.451289 2026] [security2:error] [pid 17707:tid 17878] [client 20.226.5.174:37587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreview/bypass.php"] [unique_id "amunIrJM3qlhBlpwZyAtNAAAAK4"]
[Thu Jul 30 14:33:54.826628 2026] [proxy:error] [pid 17707:tid 17925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:54.826720 2026] [proxy_http:error] [pid 17707:tid 17925] [client 52.202.41.153:15597] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:54.827521 2026] [proxy:error] [pid 17707:tid 17925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:54.827584 2026] [proxy_http:error] [pid 17707:tid 17925] [client 52.202.41.153:15597] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:54.853132 2026] [autoindex:error] [pid 17707:tid 17939] [client 54.87.222.253:44096] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:33:54.853726 2026] [proxy:error] [pid 17707:tid 17924] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:54.853802 2026] [proxy_http:error] [pid 17707:tid 17924] [client 54.87.222.253:45302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:54.854392 2026] [proxy:error] [pid 17707:tid 17924] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:54.854442 2026] [proxy_http:error] [pid 17707:tid 17924] [client 54.87.222.253:45302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:54.885683 2026] [autoindex:error] [pid 17707:tid 17885] [client 52.202.41.153:52759] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:33:54.931755 2026] [autoindex:error] [pid 17707:tid 17853] [client 52.202.41.153:3028] AH01276: Cannot serve directory /home2/tvsnyxte/public_html/website_f8c1eb2c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:33:54.982419 2026] [security2:error] [pid 17707:tid 17914] [client 52.238.199.152:50294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/12.php"] [unique_id "amunIrJM3qlhBlpwZyAtTAAAANI"]
[Thu Jul 30 14:33:55.157120 2026] [security2:error] [pid 17707:tid 17873] [client 20.226.5.174:50499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/skatepark/db.php"] [unique_id "amunI7JM3qlhBlpwZyAtUAAAAKk"]
[Thu Jul 30 14:33:55.424868 2026] [security2:error] [pid 17707:tid 17902] [client 20.226.5.174:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreview/class.php"] [unique_id "amunI7JM3qlhBlpwZyAtVQAAAMY"]
[Thu Jul 30 14:33:55.613036 2026] [security2:error] [pid 17707:tid 17949] [client 180.243.59.178:50157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunI7JM3qlhBlpwZyAtXgAAAPU"]
[Thu Jul 30 14:33:55.613153 2026] [security2:error] [pid 17707:tid 17949] [client 180.243.59.178:50157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunI7JM3qlhBlpwZyAtXgAAAPU"]
[Thu Jul 30 14:33:55.876519 2026] [security2:error] [pid 17707:tid 17850] [client 180.243.188.193:17654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.188.243.180.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ad-company.net"] [uri "/xmlrpc.php"] [unique_id "amunI7JM3qlhBlpwZyAtVAAAAJI"]
[Thu Jul 30 14:33:55.876667 2026] [security2:error] [pid 17707:tid 17850] [client 180.243.188.193:17654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ad-company.net"] [uri "/xmlrpc.php"] [unique_id "amunI7JM3qlhBlpwZyAtVAAAAJI"]
[Thu Jul 30 14:33:56.220534 2026] [security2:error] [pid 17707:tid 17872] [client 20.226.5.174:50500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/skatepark/doc.php"] [unique_id "amunJLJM3qlhBlpwZyAtawAAAKg"]
[Thu Jul 30 14:33:56.345837 2026] [security2:error] [pid 17707:tid 17888] [client 20.226.5.174:37605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreview/db.php"] [unique_id "amunJLJM3qlhBlpwZyAtbAAAALg"]
[Thu Jul 30 14:33:56.514749 2026] [security2:error] [pid 17707:tid 17927] [client 172.237.109.114:51333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunJLJM3qlhBlpwZyAtZwAAAN8"], referer: http://alseermarine.com:80
[Thu Jul 30 14:33:56.764500 2026] [proxy:error] [pid 17707:tid 17960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:56.764615 2026] [proxy_http:error] [pid 17707:tid 17960] [client 44.216.125.112:46858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:56.765888 2026] [proxy:error] [pid 17707:tid 17960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:56.765942 2026] [proxy_http:error] [pid 17707:tid 17960] [client 44.216.125.112:46858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:56.781861 2026] [proxy:error] [pid 17707:tid 17900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:56.781924 2026] [proxy_http:error] [pid 17707:tid 17900] [client 18.211.55.47:20798] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:56.782492 2026] [proxy:error] [pid 17707:tid 17900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:56.782538 2026] [proxy_http:error] [pid 17707:tid 17900] [client 18.211.55.47:20798] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:57.009785 2026] [proxy:error] [pid 17707:tid 17951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:57.009864 2026] [proxy_http:error] [pid 17707:tid 17951] [client 44.213.206.96:20729] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:57.010506 2026] [proxy:error] [pid 17707:tid 17951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:57.010563 2026] [proxy_http:error] [pid 17707:tid 17951] [client 44.213.206.96:20729] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:57.022239 2026] [proxy:error] [pid 17707:tid 17894] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:57.022332 2026] [proxy_http:error] [pid 17707:tid 17894] [client 52.4.19.39:59141] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:57.023212 2026] [proxy:error] [pid 17707:tid 17894] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:57.023267 2026] [proxy_http:error] [pid 17707:tid 17894] [client 52.4.19.39:59141] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:57.064276 2026] [security2:error] [pid 17707:tid 17929] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunJLJM3qlhBlpwZyAtcAAA4SI"]
[Thu Jul 30 14:33:57.242449 2026] [security2:error] [pid 17707:tid 17946] [client 20.226.5.174:37601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreview/index.php"] [unique_id "amunJbJM3qlhBlpwZyAtlgAAAPI"]
[Thu Jul 30 14:33:57.314848 2026] [security2:error] [pid 17707:tid 17862] [client 20.226.5.174:49807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/skatepark/img_screen.php"] [unique_id "amunJbJM3qlhBlpwZyAtlwAAAJ4"]
[Thu Jul 30 14:33:57.609019 2026] [security2:error] [pid 17707:tid 17926] [client 52.238.199.152:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/epinyins.php"] [unique_id "amunJbJM3qlhBlpwZyAtogAAAN4"]
[Thu Jul 30 14:33:58.267646 2026] [security2:error] [pid 17707:tid 17854] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amunJrJM3qlhBlpwZyAttwAAAJY"]
[Thu Jul 30 14:33:58.298956 2026] [security2:error] [pid 17707:tid 17934] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunJbJM3qlhBlpwZyAtpgAAAOY"]
[Thu Jul 30 14:33:58.301618 2026] [security2:error] [pid 17707:tid 17923] [client 20.226.5.174:37599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreview/k.php"] [unique_id "amunJrJM3qlhBlpwZyAtuwAAANs"]
[Thu Jul 30 14:33:58.338202 2026] [security2:error] [pid 17707:tid 17950] [client 20.226.5.174:50557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/sketch/404.php"] [unique_id "amunJrJM3qlhBlpwZyAtvAAAAPY"]
[Thu Jul 30 14:33:58.462238 2026] [security2:error] [pid 17707:tid 17924] [client 189.156.226.90:27129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunJrJM3qlhBlpwZyAtvQAAANw"]
[Thu Jul 30 14:33:58.462393 2026] [security2:error] [pid 17707:tid 17924] [client 189.156.226.90:27129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunJrJM3qlhBlpwZyAtvQAAANw"]
[Thu Jul 30 14:33:58.525621 2026] [security2:error] [pid 17707:tid 17928] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunJbJM3qlhBlpwZyAtrQAA4Ck"]
[Thu Jul 30 14:33:59.041023 2026] [security2:error] [pid 17707:tid 17915] [client 52.167.144.210:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunJrJM3qlhBlpwZyAtzAAAANM"]
[Thu Jul 30 14:33:59.188606 2026] [security2:error] [pid 17707:tid 17855] [client 52.238.199.152:16725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amunJ7JM3qlhBlpwZyAt1wAAAJc"]
[Thu Jul 30 14:33:59.243621 2026] [security2:error] [pid 17707:tid 17945] [client 20.226.5.174:37626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreview/wp.php"] [unique_id "amunJ7JM3qlhBlpwZyAt2wAAAPE"]
[Thu Jul 30 14:33:59.359059 2026] [proxy:error] [pid 17707:tid 17801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:59.359119 2026] [proxy_http:error] [pid 17707:tid 17801] [remote 74.7.244.7:59612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:59.359684 2026] [proxy:error] [pid 17707:tid 17801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:33:59.359726 2026] [proxy_http:error] [pid 17707:tid 17801] [remote 74.7.244.7:59612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:33:59.378001 2026] [security2:error] [pid 17707:tid 17859] [client 20.226.5.174:50512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/skipper.php"] [unique_id "amunJ7JM3qlhBlpwZyAt3gAAAJs"]
[Thu Jul 30 14:33:59.510832 2026] [security2:error] [pid 17707:tid 17905] [client 20.63.98.115:20285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/gmo.php"] [unique_id "amunJ7JM3qlhBlpwZyAt3AAAAMk"]
[Thu Jul 30 14:34:00.160099 2026] [security2:error] [pid 17707:tid 17878] [client 20.226.5.174:37585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreviewadmin.php"] [unique_id "amunKLJM3qlhBlpwZyAt7gAAAK4"]
[Thu Jul 30 14:34:00.436897 2026] [security2:error] [pid 17707:tid 17892] [client 20.226.5.174:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/skippershell.php"] [unique_id "amunKLJM3qlhBlpwZyAt8gAAALw"]
[Thu Jul 30 14:34:00.944902 2026] [proxy:error] [pid 17707:tid 17837] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:00.944965 2026] [proxy_http:error] [pid 17707:tid 17837] [client 98.87.102.177:55212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:00.945523 2026] [proxy:error] [pid 17707:tid 17837] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:00.945569 2026] [proxy_http:error] [pid 17707:tid 17837] [client 98.87.102.177:55212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:00.976864 2026] [proxy:error] [pid 17707:tid 17903] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:00.976946 2026] [proxy_http:error] [pid 17707:tid 17903] [client 98.87.102.177:30575] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:00.977859 2026] [proxy:error] [pid 17707:tid 17903] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:00.977913 2026] [proxy_http:error] [pid 17707:tid 17903] [client 98.87.102.177:30575] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:01.058720 2026] [security2:error] [pid 17707:tid 17928] [client 20.226.5.174:37590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreviewalfa.php"] [unique_id "amunKbJM3qlhBlpwZyAuBgAAAOA"]
[Thu Jul 30 14:34:01.423795 2026] [security2:error] [pid 17707:tid 17873] [client 20.63.98.115:29318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/nakrip.php"] [unique_id "amunKbJM3qlhBlpwZyAuFQAAAKk"]
[Thu Jul 30 14:34:01.451913 2026] [security2:error] [pid 17707:tid 17784] [remote 43.134.14.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lucky-strike-shop.com"] [uri "/product/marlboro-11"] [unique_id "amunKbJM3qlhBlpwZyAuFgAA-0w"]
[Thu Jul 30 14:34:01.452116 2026] [security2:error] [pid 17707:tid 17955] [client 43.134.14.73:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lucky-strike-shop.com"] [uri "/product/marlboro-11"] [unique_id "amunKbJM3qlhBlpwZyAuFgAA-0w"]
[Thu Jul 30 14:34:01.476627 2026] [security2:error] [pid 17707:tid 17918] [client 20.226.5.174:7174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/skj.php"] [unique_id "amunKbJM3qlhBlpwZyAuFwAAANY"]
[Thu Jul 30 14:34:01.664924 2026] [security2:error] [pid 17707:tid 17931] [client 136.144.33.57:55387] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jesus.claims"] [uri "/"] [unique_id "amunKbJM3qlhBlpwZyAuGQAAAOM"]
[Thu Jul 30 14:34:01.939219 2026] [security2:error] [pid 17707:tid 17933] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunKbJM3qlhBlpwZyAuEgAAAOU"]
[Thu Jul 30 14:34:01.953950 2026] [security2:error] [pid 17707:tid 17917] [client 20.226.5.174:37611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreviewbypass.php"] [unique_id "amunKbJM3qlhBlpwZyAuIgAAANU"]
[Thu Jul 30 14:34:02.476724 2026] [security2:error] [pid 17707:tid 17872] [client 20.226.5.174:50528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/sky-pro/js.php"] [unique_id "amunKrJM3qlhBlpwZyAuMwAAAKg"]
[Thu Jul 30 14:34:02.610888 2026] [security2:error] [pid 17707:tid 17780] [remote 69.57.172.96:44342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.172.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amunKrJM3qlhBlpwZyAuNwAAvEg"]
[Thu Jul 30 14:34:02.835831 2026] [security2:error] [pid 17707:tid 17957] [client 177.6.106.101:54648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunKrJM3qlhBlpwZyAuPwAAAP0"]
[Thu Jul 30 14:34:02.835932 2026] [security2:error] [pid 17707:tid 17957] [client 177.6.106.101:54648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunKrJM3qlhBlpwZyAuPwAAAP0"]
[Thu Jul 30 14:34:02.868039 2026] [security2:error] [pid 17707:tid 17871] [client 20.226.5.174:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/linkpreviewk.php"] [unique_id "amunKrJM3qlhBlpwZyAuQAAAAKc"]
[Thu Jul 30 14:34:03.143600 2026] [security2:error] [pid 17707:tid 17930] [client 52.238.199.152:16746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/system_log.php"] [unique_id "amunK7JM3qlhBlpwZyAuRQAAAOI"]
[Thu Jul 30 14:34:03.597142 2026] [security2:error] [pid 17707:tid 17906] [client 20.226.5.174:50549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/slider.php"] [unique_id "amunK7JM3qlhBlpwZyAuTwAAAMo"]
[Thu Jul 30 14:34:03.759849 2026] [security2:error] [pid 17707:tid 17851] [client 136.144.33.89:45745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jesus.claims"] [uri "/wp-includes/css/buttons.css"] [unique_id "amunK7JM3qlhBlpwZyAuUAAAAJM"]
[Thu Jul 30 14:34:04.435632 2026] [security2:error] [pid 17707:tid 17818] [remote 74.7.243.224:32978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amunLLJM3qlhBlpwZyAuaAAAnW4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:34:04.634398 2026] [security2:error] [pid 17707:tid 17952] [client 200.2.121.43:39743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/uk/product.php"] [unique_id "amunLLJM3qlhBlpwZyAuYgAAAPg"]
[Thu Jul 30 14:34:04.679010 2026] [security2:error] [pid 17707:tid 17867] [client 20.226.5.174:50520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/small.php"] [unique_id "amunLLJM3qlhBlpwZyAuaQAAAKM"]
[Thu Jul 30 14:34:05.047247 2026] [security2:error] [pid 17707:tid 17916] [client 180.243.59.178:50610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunLbJM3qlhBlpwZyAucwAAANQ"]
[Thu Jul 30 14:34:05.047385 2026] [security2:error] [pid 17707:tid 17916] [client 180.243.59.178:50610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunLbJM3qlhBlpwZyAucwAAANQ"]
[Thu Jul 30 14:34:05.160651 2026] [security2:error] [pid 17707:tid 17940] [client 216.244.66.200:50502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mydubaidesertsafari.com"] [uri "/robots.txt"] [unique_id "amunLbJM3qlhBlpwZyAudQAAAOw"]
[Thu Jul 30 14:34:05.160774 2026] [security2:error] [pid 17707:tid 17940] [client 216.244.66.200:50502] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mydubaidesertsafari.com"] [uri "/robots.txt"] [unique_id "amunLbJM3qlhBlpwZyAudQAAAOw"]
[Thu Jul 30 14:34:05.464311 2026] [security2:error] [pid 17707:tid 17894] [client 194.102.104.29:56039] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amunLbJM3qlhBlpwZyAufAAAAL4"]
[Thu Jul 30 14:34:05.735079 2026] [security2:error] [pid 17707:tid 17802] [remote 216.38.28.47:36720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-login.php"] [unique_id "amunLbJM3qlhBlpwZyAugAAA7V4"]
[Thu Jul 30 14:34:05.760035 2026] [security2:error] [pid 17707:tid 17886] [client 20.226.5.174:49801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/smaxx.php"] [unique_id "amunLbJM3qlhBlpwZyAugQAAALY"]
[Thu Jul 30 14:34:05.783765 2026] [security2:error] [pid 17707:tid 17871] [client 194.102.104.29:57143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/conf/.env"] [unique_id "amunLbJM3qlhBlpwZyAuggAAAKc"]
[Thu Jul 30 14:34:06.331238 2026] [security2:error] [pid 17707:tid 17956] [client 136.144.33.75:39547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jesus.claims"] [uri "/media/system/js/core.js"] [unique_id "amunLrJM3qlhBlpwZyAujgAAAPw"]
[Thu Jul 30 14:34:06.811112 2026] [security2:error] [pid 17707:tid 17908] [client 20.226.5.174:49818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/smilies/about.php"] [unique_id "amunLrJM3qlhBlpwZyAunAAAAMw"]
[Thu Jul 30 14:34:06.818821 2026] [security2:error] [pid 17707:tid 17920] [client 52.238.199.152:52466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amunLrJM3qlhBlpwZyAunQAAANg"]
[Thu Jul 30 14:34:07.173901 2026] [security2:error] [pid 17707:tid 17896] [client 194.102.104.29:56351] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/wp-content/.env"] [unique_id "amunL7JM3qlhBlpwZyAuqQAAAMA"]
[Thu Jul 30 14:34:07.485696 2026] [security2:error] [pid 17707:tid 17948] [client 194.102.104.29:60245] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/wp-admin/.env"] [unique_id "amunL7JM3qlhBlpwZyAusgAAAPQ"]
[Thu Jul 30 14:34:07.535519 2026] [security2:error] [pid 17707:tid 17942] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunLrJM3qlhBlpwZyAumAAA7m8"]
[Thu Jul 30 14:34:07.584257 2026] [security2:error] [pid 17707:tid 17905] [client 74.7.244.39:45984] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amunL7JM3qlhBlpwZyAuqgAAyWs"], referer: http://www.alseermarine.ae/robots.txt
[Thu Jul 30 14:34:07.584283 2026] [security2:error] [pid 17707:tid 17905] [client 74.7.244.39:45984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amunL7JM3qlhBlpwZyAuqgAAyWs"], referer: http://www.alseermarine.ae/robots.txt
[Thu Jul 30 14:34:07.719648 2026] [security2:error] [pid 17707:tid 17889] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunLrJM3qlhBlpwZyAungAAuQA"]
[Thu Jul 30 14:34:07.785880 2026] [security2:error] [pid 17707:tid 17869] [client 194.102.104.29:60683] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/library/.env"] [unique_id "amunL7JM3qlhBlpwZyAuuQAAAKU"]
[Thu Jul 30 14:34:07.867600 2026] [security2:error] [pid 17707:tid 17866] [client 20.226.5.174:7184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/smilies/alfa-rex.php"] [unique_id "amunL7JM3qlhBlpwZyAuugAAAKI"]
[Thu Jul 30 14:34:08.085061 2026] [security2:error] [pid 17707:tid 17871] [client 194.102.104.29:62021] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "amunMLJM3qlhBlpwZyAuwQAAAKc"]
[Thu Jul 30 14:34:08.208668 2026] [security2:error] [pid 17707:tid 17809] [remote 57.141.0.45:37258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amunMLJM3qlhBlpwZyAuxgAA5mU"]
[Thu Jul 30 14:34:08.396261 2026] [security2:error] [pid 17707:tid 17899] [client 103.231.91.59:54300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amunMLJM3qlhBlpwZyAuyQAAAMM"]
[Thu Jul 30 14:34:08.396357 2026] [security2:error] [pid 17707:tid 17899] [client 103.231.91.59:54300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amunMLJM3qlhBlpwZyAuyQAAAMM"]
[Thu Jul 30 14:34:08.596403 2026] [security2:error] [pid 17707:tid 17845] [client 194.102.104.29:62545] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/vendor/.env"] [unique_id "amunMLJM3qlhBlpwZyAu0QAAAI0"]
[Thu Jul 30 14:34:08.669715 2026] [security2:error] [pid 17707:tid 17932] [client 74.7.244.39:45990] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunMLJM3qlhBlpwZyAuyAAA5DQ"], referer: https://www.alseermarine.com/robots.txt
[Thu Jul 30 14:34:08.851693 2026] [security2:error] [pid 17707:tid 17868] [client 20.226.5.174:7171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/smilies/file.php"] [unique_id "amunMLJM3qlhBlpwZyAu1QAAAKQ"]
[Thu Jul 30 14:34:09.044840 2026] [security2:error] [pid 17707:tid 17935] [client 194.102.104.29:63268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "amunMbJM3qlhBlpwZyAu3QAAAOc"]
[Thu Jul 30 14:34:09.119174 2026] [core:error] [pid 17707:tid 17840] [client 74.7.230.8:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:34:09.119193 2026] [core:error] [pid 17707:tid 17840] [client 74.7.230.8:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:34:09.119323 2026] [security2:error] [pid 17707:tid 17840] [client 74.7.230.8:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.jud.zzt.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amunMbJM3qlhBlpwZyAu4QAAAIg"]
[Thu Jul 30 14:34:09.119938 2026] [security2:error] [pid 17707:tid 17915] [client 74.7.230.8:48286] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.jud.zzt.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amunMbJM3qlhBlpwZyAu3wAA0xs"]
[Thu Jul 30 14:34:09.189954 2026] [security2:error] [pid 17707:tid 17856] [client 20.63.98.115:49147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/radio.php"] [unique_id "amunMbJM3qlhBlpwZyAu4gAAAJg"]
[Thu Jul 30 14:34:09.434538 2026] [security2:error] [pid 17707:tid 17896] [client 194.102.104.29:62754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "amunMbJM3qlhBlpwZyAu5wAAAMA"]
[Thu Jul 30 14:34:09.723793 2026] [security2:error] [pid 17707:tid 17878] [client 194.102.104.29:64679] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "amunMbJM3qlhBlpwZyAu9AAAAK4"]
[Thu Jul 30 14:34:09.961973 2026] [security2:error] [pid 17707:tid 17844] [client 20.226.5.174:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/smilies/index.php"] [unique_id "amunMbJM3qlhBlpwZyAu9QAAAIw"]
[Thu Jul 30 14:34:10.057193 2026] [security2:error] [pid 17707:tid 17918] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunMbJM3qlhBlpwZyAu6AAA1hQ"]
[Thu Jul 30 14:34:10.099542 2026] [security2:error] [pid 17707:tid 17922] [client 189.156.226.90:26840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunMrJM3qlhBlpwZyAu_AAAANo"]
[Thu Jul 30 14:34:10.099669 2026] [security2:error] [pid 17707:tid 17922] [client 189.156.226.90:26840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunMrJM3qlhBlpwZyAu_AAAANo"]
[Thu Jul 30 14:34:10.216853 2026] [security2:error] [pid 17707:tid 17957] [client 194.102.104.29:52024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/blog/.env"] [unique_id "amunMrJM3qlhBlpwZyAu_QAAAP0"]
[Thu Jul 30 14:34:10.292251 2026] [security2:error] [pid 17707:tid 17934] [client 127.0.0.1:59866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amunMrJM3qlhBlpwZyAvAgAAAOY"]
[Thu Jul 30 14:34:10.292274 2026] [security2:error] [pid 17707:tid 17958] [client 74.7.241.143:44672] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tereasshop.com"] [uri "/robots.txt"] [unique_id "amunMrJM3qlhBlpwZyAvAQAAAP4"]
[Thu Jul 30 14:34:10.397440 2026] [security2:error] [pid 17707:tid 17740] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amunMrJM3qlhBlpwZyAvAwAAtCA"]
[Thu Jul 30 14:34:10.558560 2026] [security2:error] [pid 17707:tid 17852] [client 194.102.104.29:52517] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "amunMrJM3qlhBlpwZyAvBgAAAJQ"]
[Thu Jul 30 14:34:10.885930 2026] [security2:error] [pid 17707:tid 17846] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.bensecuritylocksmith.site"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amunMrJM3qlhBlpwZyAvFAAAAI4"]
[Thu Jul 30 14:34:11.047520 2026] [security2:error] [pid 17707:tid 17964] [client 20.226.5.174:50504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/smilies/network.php"] [unique_id "amunM7JM3qlhBlpwZyAvFgAAAQQ"]
[Thu Jul 30 14:34:11.270135 2026] [security2:error] [pid 17707:tid 17908] [client 194.102.104.29:54496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "amunM7JM3qlhBlpwZyAvHQAAAMw"]
[Thu Jul 30 14:34:11.531972 2026] [security2:error] [pid 17707:tid 17953] [client 52.238.199.152:50280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ini.php"] [unique_id "amunM7JM3qlhBlpwZyAvIQAAAPk"]
[Thu Jul 30 14:34:11.770240 2026] [security2:error] [pid 17707:tid 17896] [client 194.102.104.29:55857] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "amunM7JM3qlhBlpwZyAvKQAAAMA"]
[Thu Jul 30 14:34:12.148952 2026] [security2:error] [pid 17707:tid 17864] [client 20.226.5.174:50531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/smilies/priv.php"] [unique_id "amunNLJM3qlhBlpwZyAvOQAAAKA"]
[Thu Jul 30 14:34:12.222430 2026] [security2:error] [pid 17707:tid 17882] [client 194.102.104.29:57600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/app/config/.env"] [unique_id "amunNLJM3qlhBlpwZyAvPQAAALI"]
[Thu Jul 30 14:34:12.351042 2026] [core:notice] [pid 17707:tid 17723] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:12.403031 2026] [security2:error] [pid 17707:tid 17931] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunM7JM3qlhBlpwZyAvKgAA4xM"]
[Thu Jul 30 14:34:12.517706 2026] [security2:error] [pid 17707:tid 17866] [client 194.102.104.29:57611] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "amunNLJM3qlhBlpwZyAvQgAAAKI"]
[Thu Jul 30 14:34:12.565691 2026] [security2:error] [pid 17707:tid 17942] [client 172.237.109.114:55256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunNLJM3qlhBlpwZyAvNQAAAO4"], referer: http://alseermarine.com:80
[Thu Jul 30 14:34:12.593161 2026] [security2:error] [pid 17707:tid 17721] [remote 216.73.217.142:40945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amunNLJM3qlhBlpwZyAvQwABAA0"]
[Thu Jul 30 14:34:12.779678 2026] [security2:error] [pid 17707:tid 17892] [client 20.63.98.115:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-singin.php"] [unique_id "amunNLJM3qlhBlpwZyAvTQAAALw"]
[Thu Jul 30 14:34:12.837455 2026] [security2:error] [pid 17707:tid 17944] [client 194.102.104.29:58331] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/audio/.env"] [unique_id "amunNLJM3qlhBlpwZyAvUAAAAPA"]
[Thu Jul 30 14:34:12.861621 2026] [core:notice] [pid 17707:tid 17729] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:13.343822 2026] [security2:error] [pid 17707:tid 17849] [client 194.102.104.29:54876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/cgi-bin/.env"] [unique_id "amunNbJM3qlhBlpwZyAvWwAAAJE"]
[Thu Jul 30 14:34:13.470474 2026] [security2:error] [pid 17707:tid 17919] [client 177.6.106.101:55805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunNbJM3qlhBlpwZyAvXwAAANc"]
[Thu Jul 30 14:34:13.470614 2026] [security2:error] [pid 17707:tid 17919] [client 177.6.106.101:55805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunNbJM3qlhBlpwZyAvXwAAANc"]
[Thu Jul 30 14:34:13.600061 2026] [security2:error] [pid 17707:tid 17851] [client 172.237.109.114:10798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunNbJM3qlhBlpwZyAvVAAAAJM"]
[Thu Jul 30 14:34:13.613090 2026] [security2:error] [pid 17707:tid 17964] [client 20.63.98.115:29375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/as.php"] [unique_id "amunNbJM3qlhBlpwZyAvYAAAAQQ"]
[Thu Jul 30 14:34:13.680137 2026] [security2:error] [pid 17707:tid 17951] [client 194.102.104.29:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "amunNbJM3qlhBlpwZyAvYQAAAPc"]
[Thu Jul 30 14:34:14.001683 2026] [security2:error] [pid 17707:tid 17936] [client 194.102.104.29:60984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "amunNbJM3qlhBlpwZyAvbAAAAOg"]
[Thu Jul 30 14:34:14.163635 2026] [security2:error] [pid 17707:tid 17890] [client 52.238.199.152:42726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ok.php"] [unique_id "amunNrJM3qlhBlpwZyAvbgAAALo"]
[Thu Jul 30 14:34:14.344458 2026] [security2:error] [pid 17707:tid 17864] [client 194.102.104.29:61671] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/base/.env"] [unique_id "amunNrJM3qlhBlpwZyAvdQAAAKA"]
[Thu Jul 30 14:34:14.519560 2026] [proxy:error] [pid 17707:tid 17931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:14.519630 2026] [proxy_http:error] [pid 17707:tid 17931] [client 32.194.121.99:52276] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:14.520197 2026] [proxy:error] [pid 17707:tid 17931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:14.520245 2026] [proxy_http:error] [pid 17707:tid 17931] [client 32.194.121.99:52276] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:14.520371 2026] [proxy:error] [pid 17707:tid 17918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:14.520422 2026] [proxy_http:error] [pid 17707:tid 17918] [client 34.224.175.62:47126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:14.520973 2026] [proxy:error] [pid 17707:tid 17918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:14.521046 2026] [proxy_http:error] [pid 17707:tid 17918] [client 34.224.175.62:47126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:14.565403 2026] [security2:error] [pid 17707:tid 17947] [client 20.63.98.115:44116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/x.php"] [unique_id "amunNrJM3qlhBlpwZyAvhAAAAPM"]
[Thu Jul 30 14:34:14.729360 2026] [security2:error] [pid 17707:tid 17913] [client 194.102.104.29:62155] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "amunNrJM3qlhBlpwZyAvhQAAANE"]
[Thu Jul 30 14:34:15.019486 2026] [security2:error] [pid 17707:tid 17845] [client 194.102.104.29:62655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/vendor/laravel/.env"] [unique_id "amunN7JM3qlhBlpwZyAvkwAAAI0"]
[Thu Jul 30 14:34:15.250889 2026] [core:notice] [pid 17707:tid 17838] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:15.381911 2026] [security2:error] [pid 17707:tid 17847] [client 194.102.104.29:63153] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "amunN7JM3qlhBlpwZyAvnQAAAI8"]
[Thu Jul 30 14:34:15.402929 2026] [security2:error] [pid 17707:tid 17932] [client 20.63.98.115:44096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/item.php"] [unique_id "amunN7JM3qlhBlpwZyAvoQAAAOQ"]
[Thu Jul 30 14:34:15.652832 2026] [security2:error] [pid 17707:tid 17964] [client 180.243.59.178:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunN7JM3qlhBlpwZyAvpQAAAQQ"]
[Thu Jul 30 14:34:15.652962 2026] [security2:error] [pid 17707:tid 17964] [client 180.243.59.178:51146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunN7JM3qlhBlpwZyAvpQAAAQQ"]
[Thu Jul 30 14:34:15.884777 2026] [security2:error] [pid 17707:tid 17872] [client 52.238.199.152:16715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amunN7JM3qlhBlpwZyAvqgAAAKg"]
[Thu Jul 30 14:34:16.368689 2026] [security2:error] [pid 17707:tid 17857] [client 194.102.104.29:63567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/protected/.env"] [unique_id "amunOLJM3qlhBlpwZyAvtAAAAJk"]
[Thu Jul 30 14:34:16.423326 2026] [security2:error] [pid 17707:tid 17885] [client 20.63.98.115:44608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/app.php"] [unique_id "amunOLJM3qlhBlpwZyAvtQAAALU"]
[Thu Jul 30 14:34:16.684386 2026] [security2:error] [pid 17707:tid 17950] [client 194.102.104.29:64138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/newsite/.env"] [unique_id "amunOLJM3qlhBlpwZyAvvAAAAPY"]
[Thu Jul 30 14:34:17.038928 2026] [security2:error] [pid 17707:tid 17934] [client 194.102.104.29:50036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "amunObJM3qlhBlpwZyAvxgAAAOY"]
[Thu Jul 30 14:34:17.331375 2026] [security2:error] [pid 17707:tid 17902] [client 52.238.199.152:42703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-configs.php"] [unique_id "amunObJM3qlhBlpwZyAvywAAAMY"]
[Thu Jul 30 14:34:17.465418 2026] [security2:error] [pid 17707:tid 17850] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunOLJM3qlhBlpwZyAvwAAAAJI"]
[Thu Jul 30 14:34:17.602016 2026] [security2:error] [pid 17707:tid 17881] [client 194.102.104.29:52860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/sites/all/libraries/mailchimp/.env"] [unique_id "amunObJM3qlhBlpwZyAv1QAAALE"]
[Thu Jul 30 14:34:18.180605 2026] [security2:error] [pid 17707:tid 17910] [client 194.102.104.29:56794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "amunOrJM3qlhBlpwZyAv4AAAAM4"]
[Thu Jul 30 14:34:18.209751 2026] [security2:error] [pid 17707:tid 17915] [client 109.235.50.35:41800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.50.235.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amunOrJM3qlhBlpwZyAv4QAAANM"]
[Thu Jul 30 14:34:18.209836 2026] [security2:error] [pid 17707:tid 17915] [client 109.235.50.35:41800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amunOrJM3qlhBlpwZyAv4QAAANM"]
[Thu Jul 30 14:34:18.478912 2026] [security2:error] [pid 17707:tid 17885] [client 194.102.104.29:61680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "amunOrJM3qlhBlpwZyAv8gAAALU"]
[Thu Jul 30 14:34:18.830204 2026] [security2:error] [pid 17707:tid 17871] [client 194.102.104.29:63389] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/cpanel.pkv.tqa.temporary.site/.env"] [unique_id "amunOrJM3qlhBlpwZyAwBAAAAKc"]
[Thu Jul 30 14:34:18.861357 2026] [security2:error] [pid 17707:tid 17931] [client 52.238.199.152:45068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/01.php"] [unique_id "amunOrJM3qlhBlpwZyAwBQAAAOM"]
[Thu Jul 30 14:34:18.969404 2026] [security2:error] [pid 17707:tid 17961] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunOrJM3qlhBlpwZyAv8AAAAQE"]
[Thu Jul 30 14:34:19.501603 2026] [core:notice] [pid 17707:tid 17713] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:19.707625 2026] [security2:error] [pid 17707:tid 17898] [client 189.156.226.90:27723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunO7JM3qlhBlpwZyAwNQAAAMI"]
[Thu Jul 30 14:34:19.707747 2026] [security2:error] [pid 17707:tid 17898] [client 189.156.226.90:27723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunO7JM3qlhBlpwZyAwNQAAAMI"]
[Thu Jul 30 14:34:19.859067 2026] [security2:error] [pid 17707:tid 17924] [client 194.102.104.29:55525] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "cpanel.pkv.tqa.temporary.site"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amunO7JM3qlhBlpwZyAwOgAAANw"]
[Thu Jul 30 14:34:21.396901 2026] [security2:error] [pid 17707:tid 17882] [client 20.63.98.115:44614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/k.php"] [unique_id "amunPbJM3qlhBlpwZyAwiwAAALI"]
[Thu Jul 30 14:34:21.441205 2026] [fcgid:warn] [pid 17707:tid 17849] (70014)End of file found: [client 123.58.210.106:46458] mod_fcgid: can't get data from http client
[Thu Jul 30 14:34:21.572131 2026] [security2:error] [pid 17707:tid 17885] [client 103.231.91.59:60636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.91.231.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amunPbJM3qlhBlpwZyAwlwAAALU"]
[Thu Jul 30 14:34:21.572226 2026] [security2:error] [pid 17707:tid 17885] [client 103.231.91.59:60636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amunPbJM3qlhBlpwZyAwlwAAALU"]
[Thu Jul 30 14:34:21.792264 2026] [core:notice] [pid 17707:tid 17924] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:22.150276 2026] [core:notice] [pid 17707:tid 17895] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:22.589627 2026] [security2:error] [pid 17707:tid 17945] [client 43.173.179.143:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/grageaku/about/aboutThisPublishingSystem"] [unique_id "amunPrJM3qlhBlpwZyAwtAAAAPE"]
[Thu Jul 30 14:34:23.191809 2026] [security2:error] [pid 17707:tid 17937] [client 20.63.98.115:44671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-fmfile.php"] [unique_id "amunP7JM3qlhBlpwZyAwywAAAOk"]
[Thu Jul 30 14:34:23.321393 2026] [security2:error] [pid 17707:tid 17944] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunPrJM3qlhBlpwZyAwvgAAAPA"]
[Thu Jul 30 14:34:23.429529 2026] [core:notice] [pid 17707:tid 17918] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:24.004442 2026] [security2:error] [pid 17707:tid 17876] [client 177.6.106.101:56621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunQLJM3qlhBlpwZyAw8gAAAKw"]
[Thu Jul 30 14:34:24.004568 2026] [security2:error] [pid 17707:tid 17876] [client 177.6.106.101:56621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunQLJM3qlhBlpwZyAw8gAAAKw"]
[Thu Jul 30 14:34:24.261103 2026] [security2:error] [pid 17707:tid 17946] [client 43.173.180.233:51596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/grageaku/$$$call$$$/page/page/css"] [unique_id "amunQLJM3qlhBlpwZyAw8QAAAPI"], referer: http://ejournalugj.com/
[Thu Jul 30 14:34:24.299904 2026] [security2:error] [pid 17707:tid 17850] [client 43.172.198.20:55538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/grageaku/$$$call$$$/page/page/css"] [unique_id "amunQLJM3qlhBlpwZyAw8wAAAJI"], referer: http://ejournalugj.com/
[Thu Jul 30 14:34:25.421949 2026] [security2:error] [pid 17707:tid 17841] [client 20.63.98.115:53209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wi.php"] [unique_id "amunQbJM3qlhBlpwZyAxHgAAAIk"]
[Thu Jul 30 14:34:25.605086 2026] [security2:error] [pid 17707:tid 17930] [client 172.237.109.114:34836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunQLJM3qlhBlpwZyAxFwAAAOI"], referer: http://alseermarine.com:80
[Thu Jul 30 14:34:26.036724 2026] [security2:error] [pid 17707:tid 17946] [client 180.243.59.178:51679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunQrJM3qlhBlpwZyAxMwAAAPI"]
[Thu Jul 30 14:34:26.036873 2026] [security2:error] [pid 17707:tid 17946] [client 180.243.59.178:51679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunQrJM3qlhBlpwZyAxMwAAAPI"]
[Thu Jul 30 14:34:26.383276 2026] [security2:error] [pid 17707:tid 17925] [client 20.63.98.115:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/php8.php"] [unique_id "amunQrJM3qlhBlpwZyAxOwAAAN0"]
[Thu Jul 30 14:34:26.841961 2026] [security2:error] [pid 17707:tid 17865] [client 74.7.228.36:52196] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amunQrJM3qlhBlpwZyAxQwAAoV8"], referer: https://www.bedandbreakfast-skye.com/
[Thu Jul 30 14:34:27.723631 2026] [core:notice] [pid 17707:tid 17955] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:27.929825 2026] [core:notice] [pid 17707:tid 17772] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:28.484600 2026] [security2:error] [pid 17707:tid 17943] [client 172.237.109.114:40546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunQ7JM3qlhBlpwZyAxdwAAAO8"], referer: http://alseermarine.com:80
[Thu Jul 30 14:34:28.865428 2026] [security2:error] [pid 17707:tid 17900] [client 20.63.98.115:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/tes.php"] [unique_id "amunRLJM3qlhBlpwZyAxjQAAAMQ"]
[Thu Jul 30 14:34:29.154103 2026] [security2:error] [pid 17707:tid 17894] [client 52.238.199.152:38085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amunRbJM3qlhBlpwZyAxnwAAAL4"]
[Thu Jul 30 14:34:30.096583 2026] [security2:error] [pid 17707:tid 17905] [client 20.63.98.115:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/about.php"] [unique_id "amunRrJM3qlhBlpwZyAxsQAAAMk"]
[Thu Jul 30 14:34:30.204917 2026] [security2:error] [pid 17707:tid 17923] [client 189.156.226.90:26950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunRrJM3qlhBlpwZyAxtQAAANs"]
[Thu Jul 30 14:34:30.205047 2026] [security2:error] [pid 17707:tid 17923] [client 189.156.226.90:26950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunRrJM3qlhBlpwZyAxtQAAANs"]
[Thu Jul 30 14:34:31.081041 2026] [security2:error] [pid 17707:tid 17961] [client 52.238.199.152:16710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amunR7JM3qlhBlpwZyAxxQAAAQE"]
[Thu Jul 30 14:34:31.201028 2026] [security2:error] [pid 17707:tid 17922] [client 217.64.127.195:50966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.127.64.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amunR7JM3qlhBlpwZyAxyAAAANo"]
[Thu Jul 30 14:34:31.201181 2026] [security2:error] [pid 17707:tid 17922] [client 217.64.127.195:50966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amunR7JM3qlhBlpwZyAxyAAAANo"]
[Thu Jul 30 14:34:31.267838 2026] [security2:error] [pid 17707:tid 17841] [client 20.63.98.115:44945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/headers.php"] [unique_id "amunR7JM3qlhBlpwZyAx0AAAAIk"]
[Thu Jul 30 14:34:32.160506 2026] [security2:error] [pid 17707:tid 17914] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunR7JM3qlhBlpwZyAx3QAAANI"]
[Thu Jul 30 14:34:33.608637 2026] [security2:error] [pid 17707:tid 17927] [client 152.32.142.138:44766] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gas.djb.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amunSbJM3qlhBlpwZyAyGQAAAN8"]
[Thu Jul 30 14:34:33.710281 2026] [core:notice] [pid 17707:tid 17939] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:34.297945 2026] [security2:error] [pid 17707:tid 17914] [client 177.6.106.101:57363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunSrJM3qlhBlpwZyAyLQAAANI"]
[Thu Jul 30 14:34:34.298154 2026] [security2:error] [pid 17707:tid 17914] [client 177.6.106.101:57363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunSrJM3qlhBlpwZyAyLQAAANI"]
[Thu Jul 30 14:34:34.421456 2026] [security2:error] [pid 17707:tid 17852] [client 20.63.98.115:45310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/admin.php"] [unique_id "amunSrJM3qlhBlpwZyAyMgAAAJQ"]
[Thu Jul 30 14:34:34.895114 2026] [security2:error] [pid 17707:tid 17850] [client 109.235.50.35:45488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.50.235.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amunSrJM3qlhBlpwZyAyQQAAAJI"]
[Thu Jul 30 14:34:34.895236 2026] [security2:error] [pid 17707:tid 17850] [client 109.235.50.35:45488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amunSrJM3qlhBlpwZyAyQQAAAJI"]
[Thu Jul 30 14:34:35.336515 2026] [security2:error] [pid 17707:tid 17834] [remote 47.128.96.209:19880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/393"] [unique_id "amunS7JM3qlhBlpwZyAyTAAA4H4"]
[Thu Jul 30 14:34:35.417805 2026] [core:notice] [pid 17707:tid 17717] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:35.422404 2026] [security2:error] [pid 17707:tid 17913] [client 47.128.96.209:19880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/393"] [unique_id "amunS7JM3qlhBlpwZyAyVgAA0Qk"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:34:35.666240 2026] [core:notice] [pid 17707:tid 17745] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:35.777033 2026] [core:notice] [pid 17707:tid 17747] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:35.777239 2026] [core:notice] [pid 17707:tid 17708] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:35.908042 2026] [security2:error] [pid 17707:tid 17919] [client 45.32.119.175:55869] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvape-australia.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amunS7JM3qlhBlpwZyAyZAAAANc"]
[Thu Jul 30 14:34:35.955490 2026] [security2:error] [pid 17707:tid 17948] [client 20.63.98.115:45289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/flower.php"] [unique_id "amunS7JM3qlhBlpwZyAyZwAAAPQ"]
[Thu Jul 30 14:34:36.208654 2026] [security2:error] [pid 17707:tid 17955] [client 52.238.199.152:16741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amunTLJM3qlhBlpwZyAycQAAAPs"]
[Thu Jul 30 14:34:36.219877 2026] [security2:error] [pid 17707:tid 17871] [client 176.28.137.245:20536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunP7JM3qlhBlpwZyAw5wAAAKc"], referer: http://pkf.jo
[Thu Jul 30 14:34:36.220248 2026] [security2:error] [pid 17707:tid 17873] [client 172.81.0.179:60326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunP7JM3qlhBlpwZyAw8AAAAKk"], referer: http://pkf.jo
[Thu Jul 30 14:34:36.223598 2026] [security2:error] [pid 17707:tid 17909] [client 113.190.133.192:33870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunP7JM3qlhBlpwZyAw3QAAAM0"], referer: http://pkf.jo
[Thu Jul 30 14:34:36.223854 2026] [security2:error] [pid 17707:tid 17924] [client 41.116.197.48:27859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunQLJM3qlhBlpwZyAxFgAAANw"], referer: http://pkf.jo
[Thu Jul 30 14:34:36.226817 2026] [security2:error] [pid 17707:tid 17937] [client 75.138.149.138:48051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunQLJM3qlhBlpwZyAxBQAAAOk"], referer: http://pkf.jo
[Thu Jul 30 14:34:36.226959 2026] [security2:error] [pid 17707:tid 17895] [client 89.152.61.123:57374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunP7JM3qlhBlpwZyAw5QAAAL8"], referer: http://pkf.jo
[Thu Jul 30 14:34:36.228074 2026] [security2:error] [pid 17707:tid 17962] [client 157.100.204.147:34460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunQLJM3qlhBlpwZyAw_gAAAQI"], referer: http://pkf.jo
[Thu Jul 30 14:34:36.232175 2026] [security2:error] [pid 17707:tid 17838] [client 14.191.201.209:10028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunP7JM3qlhBlpwZyAw6AAAAIY"], referer: http://pkf.jo
[Thu Jul 30 14:34:36.238315 2026] [security2:error] [pid 17707:tid 17881] [client 178.26.101.177:60569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunP7JM3qlhBlpwZyAw7QAAALE"], referer: http://pkf.jo
[Thu Jul 30 14:34:36.745697 2026] [security2:error] [pid 17707:tid 17764] [remote 80.74.156.100:20824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.156.74.80.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amunTLJM3qlhBlpwZyAygQAA1jg"]
[Thu Jul 30 14:34:37.467506 2026] [security2:error] [pid 17707:tid 17905] [client 180.243.59.178:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunTbJM3qlhBlpwZyAyjgAAAMk"]
[Thu Jul 30 14:34:37.467945 2026] [security2:error] [pid 17707:tid 17905] [client 180.243.59.178:52257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunTbJM3qlhBlpwZyAyjgAAAMk"]
[Thu Jul 30 14:34:37.497035 2026] [core:error] [pid 17707:tid 17730] [remote 52.167.144.187:27289] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:34:37.497055 2026] [core:error] [pid 17707:tid 17730] [remote 52.167.144.187:27289] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:34:37.673284 2026] [security2:error] [pid 17707:tid 17926] [client 52.238.199.152:45080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/db.php"] [unique_id "amunTbJM3qlhBlpwZyAymgAAAN4"]
[Thu Jul 30 14:34:38.055404 2026] [security2:error] [pid 17707:tid 17934] [client 20.63.98.115:10791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amunTrJM3qlhBlpwZyAypgAAAOY"]
[Thu Jul 30 14:34:38.079042 2026] [security2:error] [pid 17707:tid 17870] [client 40.77.167.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunTbJM3qlhBlpwZyAynQAAAKY"]
[Thu Jul 30 14:34:38.270338 2026] [security2:error] [pid 17707:tid 17951] [client 14.191.110.1:4045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunSrJM3qlhBlpwZyAyOgAAAPc"], referer: http://pkf.jo
[Thu Jul 30 14:34:38.275963 2026] [security2:error] [pid 17707:tid 17888] [client 86.97.94.168:40970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunSrJM3qlhBlpwZyAyRQAAALg"], referer: http://pkf.jo
[Thu Jul 30 14:34:38.282916 2026] [security2:error] [pid 17707:tid 17860] [client 137.101.188.114:33532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunSrJM3qlhBlpwZyAyQgAAAJw"], referer: http://pkf.jo
[Thu Jul 30 14:34:38.284992 2026] [security2:error] [pid 17707:tid 17844] [client 92.209.206.227:31052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunSrJM3qlhBlpwZyAyQAAAAIw"], referer: http://pkf.jo
[Thu Jul 30 14:34:38.328144 2026] [security2:error] [pid 17707:tid 17961] [client 106.192.30.239:43926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunTLJM3qlhBlpwZyAybAAAAQE"], referer: http://pkf.jo
[Thu Jul 30 14:34:38.362858 2026] [security2:error] [pid 17707:tid 17907] [client 149.232.250.9:34960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunS7JM3qlhBlpwZyAyWwAAAMs"], referer: http://pkf.jo
[Thu Jul 30 14:34:38.620281 2026] [security2:error] [pid 17707:tid 17882] [client 45.32.119.175:49529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.119.32.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amunTrJM3qlhBlpwZyAyswAAALI"]
[Thu Jul 30 14:34:38.620429 2026] [security2:error] [pid 17707:tid 17882] [client 45.32.119.175:49529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amunTrJM3qlhBlpwZyAyswAAALI"]
[Thu Jul 30 14:34:38.639314 2026] [security2:error] [pid 17707:tid 17896] [client 172.237.109.114:59383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunTrJM3qlhBlpwZyAyrwAAAMA"], referer: https://alseermarine.com:443/index.html
[Thu Jul 30 14:34:39.049962 2026] [security2:error] [pid 17707:tid 17901] [client 52.238.199.152:45064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/pages.php"] [unique_id "amunT7JM3qlhBlpwZyAyvgAAAMU"]
[Thu Jul 30 14:34:39.216589 2026] [security2:error] [pid 17707:tid 17864] [client 181.51.34.57:2220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunS7JM3qlhBlpwZyAyXAAAAKA"], referer: http://pkf.jo
[Thu Jul 30 14:34:39.226740 2026] [security2:error] [pid 17707:tid 17887] [client 102.209.221.77:26164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunTLJM3qlhBlpwZyAycwAAALc"], referer: http://pkf.jo
[Thu Jul 30 14:34:39.754150 2026] [security2:error] [pid 17707:tid 17715] [remote 57.141.0.61:60086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/485177242/feed/rss2/"] [unique_id "amunT7JM3qlhBlpwZyAy1QAAwgc"]
[Thu Jul 30 14:34:40.743720 2026] [security2:error] [pid 17707:tid 17844] [client 189.156.226.90:27164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunULJM3qlhBlpwZyAy9AAAAIw"]
[Thu Jul 30 14:34:40.743864 2026] [security2:error] [pid 17707:tid 17844] [client 189.156.226.90:27164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunULJM3qlhBlpwZyAy9AAAAIw"]
[Thu Jul 30 14:34:40.952075 2026] [security2:error] [pid 17707:tid 17873] [client 20.15.133.160:11905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amunULJM3qlhBlpwZyAy4wAAqSI"]
[Thu Jul 30 14:34:41.295356 2026] [security2:error] [pid 17707:tid 17890] [client 83.171.206.59:13828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunULJM3qlhBlpwZyAy-QAAALo"], referer: http://pkf.jo
[Thu Jul 30 14:34:42.617392 2026] [security2:error] [pid 17707:tid 17860] [client 40.77.167.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunUrJM3qlhBlpwZyAzHQAAAJw"]
[Thu Jul 30 14:34:43.178233 2026] [security2:error] [pid 17707:tid 17891] [client 52.238.199.152:16718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/admin.php"] [unique_id "amunU7JM3qlhBlpwZyAzRgAAALs"]
[Thu Jul 30 14:34:44.212994 2026] [security2:error] [pid 17707:tid 17914] [client 52.238.199.152:16751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-load.php"] [unique_id "amunVLJM3qlhBlpwZyAzXAAAANI"]
[Thu Jul 30 14:34:44.944372 2026] [security2:error] [pid 17707:tid 17951] [client 177.6.106.101:53827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunVLJM3qlhBlpwZyAzcAAAAPc"]
[Thu Jul 30 14:34:44.944471 2026] [security2:error] [pid 17707:tid 17951] [client 177.6.106.101:53827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunVLJM3qlhBlpwZyAzcAAAAPc"]
[Thu Jul 30 14:34:45.047783 2026] [proxy:error] [pid 17707:tid 17910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:45.047878 2026] [proxy_http:error] [pid 17707:tid 17910] [client 54.87.222.253:22047] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:45.048495 2026] [proxy:error] [pid 17707:tid 17910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:45.048541 2026] [proxy_http:error] [pid 17707:tid 17910] [client 54.87.222.253:22047] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:45.094104 2026] [proxy:error] [pid 17707:tid 17931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:45.094181 2026] [proxy_http:error] [pid 17707:tid 17931] [client 3.228.112.215:35844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:45.094788 2026] [proxy:error] [pid 17707:tid 17931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:34:45.094847 2026] [proxy_http:error] [pid 17707:tid 17931] [client 3.228.112.215:35844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:34:46.018484 2026] [security2:error] [pid 17707:tid 17860] [client 52.238.199.152:16720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/as/function.php"] [unique_id "amunVrJM3qlhBlpwZyAzoQAAAJw"]
[Thu Jul 30 14:34:46.067870 2026] [security2:error] [pid 17707:tid 17722] [remote 52.167.144.191:42312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/-/media/Files/OGB/Soumu/humanitariaf.php"] [unique_id "amunVrJM3qlhBlpwZyAzpQAA0g4"]
[Thu Jul 30 14:34:46.075071 2026] [security2:error] [pid 17707:tid 17845] [client 20.63.98.115:10088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "globalmarks.pk"] [uri "/wp-content.php"] [unique_id "amunVrJM3qlhBlpwZyAzpgAAAI0"]
[Thu Jul 30 14:34:46.386216 2026] [security2:error] [pid 17707:tid 17857] [client 20.104.18.253:5128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/ea3f.php"] [unique_id "amunVrJM3qlhBlpwZyAzqgAAAJk"]
[Thu Jul 30 14:34:46.481950 2026] [security2:error] [pid 17707:tid 17880] [client 52.71.216.196:28375] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/chuvas-voltar-a-causar-alagamento-no-centro-de-guarabira/jkhgsdf/"] [unique_id "amunVrJM3qlhBlpwZyAzrgAAALA"]
[Thu Jul 30 14:34:47.016201 2026] [security2:error] [pid 17707:tid 17952] [client 20.104.18.253:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/eagle.php"] [unique_id "amunV7JM3qlhBlpwZyAzuwAAAPg"]
[Thu Jul 30 14:34:47.031451 2026] [security2:error] [pid 17707:tid 17863] [client 52.238.199.152:38096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/filter.php"] [unique_id "amunV7JM3qlhBlpwZyAzvAAAAJ8"]
[Thu Jul 30 14:34:47.532405 2026] [security2:error] [pid 17707:tid 17920] [client 180.243.59.178:52784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunV7JM3qlhBlpwZyAzxQAAANg"]
[Thu Jul 30 14:34:47.532539 2026] [security2:error] [pid 17707:tid 17920] [client 180.243.59.178:52784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunV7JM3qlhBlpwZyAzxQAAANg"]
[Thu Jul 30 14:34:47.631079 2026] [security2:error] [pid 17707:tid 17904] [client 20.104.18.253:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/ed35f.php"] [unique_id "amunV7JM3qlhBlpwZyAzzAAAAMg"]
[Thu Jul 30 14:34:47.973346 2026] [core:notice] [pid 17707:tid 17717] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:48.264386 2026] [security2:error] [pid 17707:tid 17906] [client 20.104.18.253:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/edit-comments.php"] [unique_id "amunWLJM3qlhBlpwZyAz3wAAAMo"]
[Thu Jul 30 14:34:48.840144 2026] [security2:error] [pid 17707:tid 17856] [client 52.167.144.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunWLJM3qlhBlpwZyAz5AAAAJg"]
[Thu Jul 30 14:34:48.919839 2026] [security2:error] [pid 17707:tid 17959] [client 20.104.18.253:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/edit-form.php"] [unique_id "amunWLJM3qlhBlpwZyAz7wAAAP8"]
[Thu Jul 30 14:34:49.465893 2026] [security2:error] [pid 17707:tid 17900] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunWLJM3qlhBlpwZyAz7gAAxHQ"]
[Thu Jul 30 14:34:49.522154 2026] [security2:error] [pid 17707:tid 17867] [client 20.104.18.253:5174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/edit-tags.php"] [unique_id "amunWbJM3qlhBlpwZyAz-gAAAKM"]
[Thu Jul 30 14:34:50.136888 2026] [security2:error] [pid 17707:tid 17927] [client 20.104.18.253:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/edit-wolf.php"] [unique_id "amunWrJM3qlhBlpwZyA0CQAAAN8"]
[Thu Jul 30 14:34:50.349684 2026] [security2:error] [pid 17707:tid 17719] [remote 80.150.6.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.6.150.80.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oceanscout.com"] [uri "/wp-login.php"] [unique_id "amunWrJM3qlhBlpwZyA0BQAA2Qs"]
[Thu Jul 30 14:34:50.459633 2026] [security2:error] [pid 17707:tid 17937] [client 139.28.219.70:48834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amunWrJM3qlhBlpwZyA0EQAAAOk"]
[Thu Jul 30 14:34:50.738819 2026] [security2:error] [pid 17707:tid 17851] [client 20.104.18.253:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/edit.php"] [unique_id "amunWrJM3qlhBlpwZyA0GQAAAJM"]
[Thu Jul 30 14:34:50.965593 2026] [security2:error] [pid 17707:tid 17858] [client 139.28.219.70:58898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amunWrJM3qlhBlpwZyA0HQAAAJo"]
[Thu Jul 30 14:34:51.014138 2026] [security2:error] [pid 17707:tid 17906] [client 172.237.109.114:40924] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "alseermarine.com"] [uri "/webui/logoutconfirm.html"] [unique_id "amunW7JM3qlhBlpwZyA0HgAAAMo"]
[Thu Jul 30 14:34:51.236682 2026] [security2:error] [pid 17707:tid 17850] [client 139.28.219.70:58906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amunW7JM3qlhBlpwZyA0KwAAAJI"]
[Thu Jul 30 14:34:51.304413 2026] [security2:error] [pid 17707:tid 17840] [client 189.156.226.90:27606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunW7JM3qlhBlpwZyA0LwAAAIg"]
[Thu Jul 30 14:34:51.304512 2026] [security2:error] [pid 17707:tid 17840] [client 189.156.226.90:27606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunW7JM3qlhBlpwZyA0LwAAAIg"]
[Thu Jul 30 14:34:51.347793 2026] [security2:error] [pid 17707:tid 17844] [client 20.104.18.253:6132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/editor.php"] [unique_id "amunW7JM3qlhBlpwZyA0MAAAAIw"]
[Thu Jul 30 14:34:51.509518 2026] [security2:error] [pid 17707:tid 17848] [client 139.28.219.70:58918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amunW7JM3qlhBlpwZyA0NAAAAJA"]
[Thu Jul 30 14:34:51.793845 2026] [security2:error] [pid 17707:tid 17892] [client 139.28.219.70:58930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amunW7JM3qlhBlpwZyA0OwAAALw"]
[Thu Jul 30 14:34:52.001947 2026] [security2:error] [pid 17707:tid 17928] [client 20.104.18.253:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/editor/filemanager.php"] [unique_id "amunXLJM3qlhBlpwZyA0PwAAAOA"]
[Thu Jul 30 14:34:52.067925 2026] [security2:error] [pid 17707:tid 17941] [client 139.28.219.70:58934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amunXLJM3qlhBlpwZyA0QAAAAO0"]
[Thu Jul 30 14:34:52.100866 2026] [security2:error] [pid 17707:tid 17960] [client 52.238.199.152:42750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/he.php"] [unique_id "amunXLJM3qlhBlpwZyA0QQAAAQA"]
[Thu Jul 30 14:34:52.332952 2026] [security2:error] [pid 17707:tid 17874] [client 139.28.219.70:58950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amunXLJM3qlhBlpwZyA0SgAAAKo"]
[Thu Jul 30 14:34:52.603227 2026] [security2:error] [pid 17707:tid 17843] [client 139.28.219.70:58952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amunXLJM3qlhBlpwZyA0TwAAAIs"]
[Thu Jul 30 14:34:52.639281 2026] [security2:error] [pid 17707:tid 17944] [client 20.104.18.253:6142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/editor/filemanager/updates.php"] [unique_id "amunXLJM3qlhBlpwZyA0UAAAAPA"]
[Thu Jul 30 14:34:52.802266 2026] [core:notice] [pid 17707:tid 17904] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:52.854819 2026] [security2:error] [pid 17707:tid 17926] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunXLJM3qlhBlpwZyA0RQAA3nk"]
[Thu Jul 30 14:34:52.868704 2026] [security2:error] [pid 17707:tid 17845] [client 139.28.219.70:58960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amunXLJM3qlhBlpwZyA0WAAAAI0"]
[Thu Jul 30 14:34:53.137787 2026] [security2:error] [pid 17707:tid 17894] [client 139.28.219.70:58972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amunXbJM3qlhBlpwZyA0YAAAAL4"]
[Thu Jul 30 14:34:53.278072 2026] [security2:error] [pid 17707:tid 17858] [client 20.104.18.253:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/ee.php"] [unique_id "amunXbJM3qlhBlpwZyA0YgAAAJo"]
[Thu Jul 30 14:34:53.409436 2026] [security2:error] [pid 17707:tid 17898] [client 139.28.219.70:58988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amunXbJM3qlhBlpwZyA0aQAAAMI"]
[Thu Jul 30 14:34:53.666515 2026] [security2:error] [pid 17707:tid 17910] [client 139.28.219.70:58992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amunXbJM3qlhBlpwZyA0bwAAAM4"]
[Thu Jul 30 14:34:53.876125 2026] [security2:error] [pid 17707:tid 17848] [client 20.104.18.253:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/ee8.php"] [unique_id "amunXbJM3qlhBlpwZyA0cwAAAJA"]
[Thu Jul 30 14:34:53.931720 2026] [security2:error] [pid 17707:tid 17887] [client 139.28.219.70:59000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amunXbJM3qlhBlpwZyA0dwAAALc"]
[Thu Jul 30 14:34:53.965435 2026] [security2:error] [pid 17707:tid 17861] [client 52.238.199.152:16836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amunXbJM3qlhBlpwZyA0eQAAAJ0"]
[Thu Jul 30 14:34:54.198397 2026] [security2:error] [pid 17707:tid 17839] [client 139.28.219.70:59012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amunXrJM3qlhBlpwZyA0fQAAAIc"]
[Thu Jul 30 14:34:54.465567 2026] [security2:error] [pid 17707:tid 17909] [client 139.28.219.70:59016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amunXrJM3qlhBlpwZyA0hAAAAM0"]
[Thu Jul 30 14:34:54.485493 2026] [security2:error] [pid 17707:tid 17928] [client 20.104.18.253:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/eew.php"] [unique_id "amunXrJM3qlhBlpwZyA0hQAAAOA"]
[Thu Jul 30 14:34:54.555773 2026] [security2:error] [pid 17707:tid 17963] [client 172.237.109.114:46585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunXbJM3qlhBlpwZyA0eAAAAQM"], referer: http://alseermarine.com:80
[Thu Jul 30 14:34:54.736083 2026] [security2:error] [pid 17707:tid 17915] [client 139.28.219.70:59026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bisbeetour.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amunXrJM3qlhBlpwZyA0jAAAANM"]
[Thu Jul 30 14:34:55.118826 2026] [security2:error] [pid 17707:tid 17926] [client 20.104.18.253:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/el.php"] [unique_id "amunX7JM3qlhBlpwZyA0mgAAAN4"]
[Thu Jul 30 14:34:55.198934 2026] [security2:error] [pid 17707:tid 17953] [client 52.238.199.152:52417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amunXrJM3qlhBlpwZyA0kwAAAPk"]
[Thu Jul 30 14:34:55.455935 2026] [security2:error] [pid 17707:tid 17883] [client 177.6.106.101:54470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunX7JM3qlhBlpwZyA0owAAALM"]
[Thu Jul 30 14:34:55.456076 2026] [security2:error] [pid 17707:tid 17883] [client 177.6.106.101:54470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunX7JM3qlhBlpwZyA0owAAALM"]
[Thu Jul 30 14:34:55.759598 2026] [security2:error] [pid 17707:tid 17866] [client 20.104.18.253:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/elementor/wp-error_log.php"] [unique_id "amunX7JM3qlhBlpwZyA0qwAAAKI"]
[Thu Jul 30 14:34:55.886915 2026] [security2:error] [pid 17707:tid 17840] [client 47.128.45.105:38732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "journeywomenscenter.org"] [uri "/robots.txt"] [unique_id "amunX7JM3qlhBlpwZyA0rAAAAIg"]
[Thu Jul 30 14:34:56.628812 2026] [security2:error] [pid 17707:tid 17958] [client 20.104.18.253:6127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/elementor/wp-login.php"] [unique_id "amunYLJM3qlhBlpwZyA0twAAAP4"]
[Thu Jul 30 14:34:56.817761 2026] [security2:error] [pid 17707:tid 17839] [client 52.238.199.152:16847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amunYLJM3qlhBlpwZyA0wgAAAIc"]
[Thu Jul 30 14:34:57.272802 2026] [security2:error] [pid 17707:tid 17855] [client 20.104.18.253:5123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/elementor/wp-wjvngrh.php"] [unique_id "amunYbJM3qlhBlpwZyA0zQAAAJc"]
[Thu Jul 30 14:34:57.853006 2026] [security2:error] [pid 17707:tid 17937] [client 216.73.216.104:9260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amunYbJM3qlhBlpwZyA00wAA6Wk"]
[Thu Jul 30 14:34:57.869733 2026] [security2:error] [pid 17707:tid 17927] [client 20.104.18.253:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/elements/filemanager.php"] [unique_id "amunYbJM3qlhBlpwZyA02gAAAN8"]
[Thu Jul 30 14:34:57.879713 2026] [security2:error] [pid 17707:tid 17935] [client 52.238.199.152:16885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "amunYbJM3qlhBlpwZyA02wAAAOc"]
[Thu Jul 30 14:34:58.064392 2026] [core:notice] [pid 17707:tid 17782] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:58.073493 2026] [core:notice] [pid 17707:tid 17800] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:58.073736 2026] [core:notice] [pid 17707:tid 17783] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:58.073736 2026] [core:notice] [pid 17707:tid 17724] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:58.481008 2026] [core:notice] [pid 17707:tid 17799] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:34:58.550019 2026] [security2:error] [pid 17707:tid 17866] [client 20.104.18.253:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/elements/udd.php"] [unique_id "amunYrJM3qlhBlpwZyA08QAAAKI"]
[Thu Jul 30 14:34:58.589485 2026] [security2:error] [pid 17707:tid 17840] [client 180.243.59.178:53352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunYrJM3qlhBlpwZyA09QAAAIg"]
[Thu Jul 30 14:34:58.589636 2026] [security2:error] [pid 17707:tid 17840] [client 180.243.59.178:53352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunYrJM3qlhBlpwZyA09QAAAIg"]
[Thu Jul 30 14:34:59.183421 2026] [security2:error] [pid 17707:tid 17954] [client 20.104.18.253:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/elements/wp-2019.php"] [unique_id "amunY7JM3qlhBlpwZyA1AwAAAPo"]
[Thu Jul 30 14:34:59.599535 2026] [security2:error] [pid 17707:tid 17960] [client 172.237.109.114:48197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunY7JM3qlhBlpwZyA0_AAAAQA"]
[Thu Jul 30 14:34:59.784226 2026] [security2:error] [pid 17707:tid 17895] [client 20.104.18.253:5136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/elp.php"] [unique_id "amunY7JM3qlhBlpwZyA1EwAAAL8"]
[Thu Jul 30 14:35:00.185467 2026] [security2:error] [pid 17707:tid 17887] [client 52.238.199.152:32981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/atomlib.php"] [unique_id "amunZLJM3qlhBlpwZyA1FwAAALc"]
[Thu Jul 30 14:35:00.401235 2026] [security2:error] [pid 17707:tid 17962] [client 20.104.18.253:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/email.php"] [unique_id "amunZLJM3qlhBlpwZyA1IQAAAQI"]
[Thu Jul 30 14:35:00.662620 2026] [core:notice] [pid 17707:tid 17859] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:01.052379 2026] [security2:error] [pid 17707:tid 17946] [client 20.104.18.253:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/endpoints/atomlib.php"] [unique_id "amunZbJM3qlhBlpwZyA1LQAAAPI"]
[Thu Jul 30 14:35:01.247767 2026] [security2:error] [pid 17707:tid 17748] [remote 190.92.174.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "echomemoversalain.casa"] [uri "/wp-login.php"] [unique_id "amunZbJM3qlhBlpwZyA1MAAAjCg"]
[Thu Jul 30 14:35:01.292946 2026] [security2:error] [pid 17707:tid 17794] [remote 57.141.0.2:38700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amunZbJM3qlhBlpwZyA1NAAAkFY"]
[Thu Jul 30 14:35:01.340474 2026] [security2:error] [pid 17707:tid 17892] [client 139.28.219.70:50180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amunZbJM3qlhBlpwZyA1OAAAALw"]
[Thu Jul 30 14:35:01.617471 2026] [security2:error] [pid 17707:tid 17900] [client 139.28.219.70:50188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/xmlrpc.php"] [unique_id "amunZbJM3qlhBlpwZyA1PAAAAMQ"]
[Thu Jul 30 14:35:01.655850 2026] [security2:error] [pid 17707:tid 17916] [client 20.104.18.253:5159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/endpoints/class-wp-rest-attachment-controller.php"] [unique_id "amunZbJM3qlhBlpwZyA1PwAAANQ"]
[Thu Jul 30 14:35:01.908277 2026] [security2:error] [pid 17707:tid 17925] [client 189.156.226.90:27734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunZbJM3qlhBlpwZyA1SAAAAN0"]
[Thu Jul 30 14:35:01.908397 2026] [security2:error] [pid 17707:tid 17925] [client 189.156.226.90:27734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunZbJM3qlhBlpwZyA1SAAAAN0"]
[Thu Jul 30 14:35:02.261639 2026] [security2:error] [pid 17707:tid 17870] [client 139.28.219.70:50196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amunZrJM3qlhBlpwZyA1TAAAAKY"]
[Thu Jul 30 14:35:02.276847 2026] [security2:error] [pid 17707:tid 17877] [client 20.104.18.253:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/endpoints/index.php"] [unique_id "amunZrJM3qlhBlpwZyA1TwAAAK0"]
[Thu Jul 30 14:35:02.470514 2026] [security2:error] [pid 17707:tid 17932] [client 52.238.199.152:16735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amunZrJM3qlhBlpwZyA1VQAAAOQ"]
[Thu Jul 30 14:35:02.528645 2026] [security2:error] [pid 17707:tid 17964] [client 139.28.219.70:50200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amunZrJM3qlhBlpwZyA1WAAAAQQ"]
[Thu Jul 30 14:35:02.801258 2026] [security2:error] [pid 17707:tid 17872] [client 139.28.219.70:50204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amunZrJM3qlhBlpwZyA1WwAAAKg"]
[Thu Jul 30 14:35:02.883744 2026] [security2:error] [pid 17707:tid 17930] [client 20.104.18.253:5157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/env.php"] [unique_id "amunZrJM3qlhBlpwZyA1YAAAAOI"]
[Thu Jul 30 14:35:03.080582 2026] [security2:error] [pid 17707:tid 17858] [client 139.28.219.70:50210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amunZ7JM3qlhBlpwZyA1ZwAAAJo"]
[Thu Jul 30 14:35:03.348553 2026] [security2:error] [pid 17707:tid 17910] [client 139.28.219.70:50220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amunZ7JM3qlhBlpwZyA1awAAAM4"]
[Thu Jul 30 14:35:03.553279 2026] [security2:error] [pid 17707:tid 17869] [client 20.104.18.253:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/envato-css.php"] [unique_id "amunZ7JM3qlhBlpwZyA1cgAAAKU"]
[Thu Jul 30 14:35:03.610479 2026] [security2:error] [pid 17707:tid 17840] [client 139.28.219.70:50236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amunZ7JM3qlhBlpwZyA1cwAAAIg"]
[Thu Jul 30 14:35:03.879724 2026] [security2:error] [pid 17707:tid 17956] [client 139.28.219.70:50248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amunZ7JM3qlhBlpwZyA1eAAAAPw"]
[Thu Jul 30 14:35:03.907365 2026] [security2:error] [pid 17707:tid 17945] [client 52.238.199.152:52421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/gebase.php"] [unique_id "amunZ7JM3qlhBlpwZyA1fAAAAPE"]
[Thu Jul 30 14:35:04.183056 2026] [security2:error] [pid 17707:tid 17874] [client 139.28.219.70:50252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amunaLJM3qlhBlpwZyA1gAAAAKo"]
[Thu Jul 30 14:35:04.204862 2026] [security2:error] [pid 17707:tid 17878] [client 20.104.18.253:6119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/envato-market/inc/class-envato-market-github.php"] [unique_id "amunaLJM3qlhBlpwZyA1gQAAAK4"]
[Thu Jul 30 14:35:04.455905 2026] [security2:error] [pid 17707:tid 17839] [client 139.28.219.70:50266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amunaLJM3qlhBlpwZyA1iAAAAIc"]
[Thu Jul 30 14:35:04.648856 2026] [security2:error] [pid 17707:tid 17815] [remote 57.141.0.31:25096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6151894337/feed/rss2/"] [unique_id "amunaLJM3qlhBlpwZyA1jAAA5Ws"]
[Thu Jul 30 14:35:04.728346 2026] [security2:error] [pid 17707:tid 17940] [client 139.28.219.70:50268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amunaLJM3qlhBlpwZyA1jQAAAOw"]
[Thu Jul 30 14:35:04.808093 2026] [security2:error] [pid 17707:tid 17842] [client 20.104.18.253:5127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/envs.php"] [unique_id "amunaLJM3qlhBlpwZyA1jgAAAIo"]
[Thu Jul 30 14:35:04.898829 2026] [security2:error] [pid 17707:tid 17899] [client 74.7.228.36:45514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amunaLJM3qlhBlpwZyA1kgAAwwA"], referer: https://www.bedandbreakfast-skye.com/
[Thu Jul 30 14:35:04.994461 2026] [security2:error] [pid 17707:tid 17921] [client 139.28.219.70:50270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amunaLJM3qlhBlpwZyA1lAAAANk"]
[Thu Jul 30 14:35:05.264038 2026] [security2:error] [pid 17707:tid 17923] [client 139.28.219.70:50276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amunabJM3qlhBlpwZyA1nwAAANs"]
[Thu Jul 30 14:35:05.416936 2026] [security2:error] [pid 17707:tid 17872] [client 20.104.18.253:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/epinyins.php"] [unique_id "amunabJM3qlhBlpwZyA1pAAAAKg"]
[Thu Jul 30 14:35:05.519695 2026] [security2:error] [pid 17707:tid 17935] [client 139.28.219.70:50286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amunabJM3qlhBlpwZyA1pwAAAOc"]
[Thu Jul 30 14:35:05.792788 2026] [security2:error] [pid 17707:tid 17894] [client 139.28.219.70:50290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "arabiandubaisafari.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amunabJM3qlhBlpwZyA1rAAAAL4"]
[Thu Jul 30 14:35:06.057397 2026] [security2:error] [pid 17707:tid 17883] [client 20.104.18.253:6124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/erinyani/asasx.php"] [unique_id "amunarJM3qlhBlpwZyA1sQAAALM"]
[Thu Jul 30 14:35:06.527963 2026] [security2:error] [pid 17707:tid 17884] [client 178.156.185.231:31698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amunabJM3qlhBlpwZyA1mwAAALQ"], referer: https://globalmarks.pk/
[Thu Jul 30 14:35:06.562180 2026] [security2:error] [pid 17707:tid 17738] [remote 74.7.243.224:34978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amunarJM3qlhBlpwZyA1uwAAiB4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:35:06.911072 2026] [security2:error] [pid 17707:tid 17844] [client 50.6.43.217:49662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amunarJM3qlhBlpwZyA1tAAAAIw"]
[Thu Jul 30 14:35:07.272148 2026] [security2:error] [pid 17707:tid 17949] [client 177.6.106.101:54979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuna7JM3qlhBlpwZyA1zQAAAPU"]
[Thu Jul 30 14:35:07.272282 2026] [security2:error] [pid 17707:tid 17949] [client 177.6.106.101:54979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuna7JM3qlhBlpwZyA1zQAAAPU"]
[Thu Jul 30 14:35:07.641012 2026] [security2:error] [pid 17707:tid 17900] [client 50.6.43.217:49670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amunarJM3qlhBlpwZyA1wgAAAMQ"]
[Thu Jul 30 14:35:08.384885 2026] [security2:error] [pid 17707:tid 17739] [remote 57.141.0.13:57296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/27169508389/feed/rss2/"] [unique_id "amunbLJM3qlhBlpwZyA15AAAlh8"]
[Thu Jul 30 14:35:08.573804 2026] [security2:error] [pid 17707:tid 17930] [client 180.243.59.178:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunbLJM3qlhBlpwZyA16gAAAOI"]
[Thu Jul 30 14:35:08.573942 2026] [security2:error] [pid 17707:tid 17930] [client 180.243.59.178:53860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunbLJM3qlhBlpwZyA16gAAAOI"]
[Thu Jul 30 14:35:08.909292 2026] [core:notice] [pid 17707:tid 17927] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:09.561855 2026] [security2:error] [pid 17707:tid 17803] [remote 40.77.167.25:7465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/RILL/index"] [unique_id "amunbbJM3qlhBlpwZyA2AQAAul8"]
[Thu Jul 30 14:35:10.083208 2026] [security2:error] [pid 17707:tid 17903] [client 52.238.199.152:38135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/xl.php"] [unique_id "amunbrJM3qlhBlpwZyA2EgAAAMc"]
[Thu Jul 30 14:35:10.135704 2026] [security2:error] [pid 17707:tid 17853] [client 39.34.158.83:17492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunbbJM3qlhBlpwZyA2CgAAAJU"], referer: http://pkf.jo
[Thu Jul 30 14:35:10.135801 2026] [security2:error] [pid 17707:tid 17945] [client 92.209.168.36:50009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunbbJM3qlhBlpwZyA2CwAAAPE"], referer: http://pkf.jo
[Thu Jul 30 14:35:10.197022 2026] [security2:error] [pid 17707:tid 17874] [client 103.181.57.92:27228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunbbJM3qlhBlpwZyA2DQAAAKo"], referer: http://pkf.jo
[Thu Jul 30 14:35:10.516221 2026] [security2:error] [pid 17707:tid 17869] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunbbJM3qlhBlpwZyA2DAAApTU"]
[Thu Jul 30 14:35:10.664933 2026] [security2:error] [pid 17707:tid 17931] [client 181.197.174.43:41928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunbrJM3qlhBlpwZyA2GQAAAOM"], referer: http://pkf.jo
[Thu Jul 30 14:35:11.060470 2026] [security2:error] [pid 17707:tid 17932] [client 192.223.104.143:53421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunbrJM3qlhBlpwZyA2cwAAAOQ"], referer: http://pkf.jo
[Thu Jul 30 14:35:11.229884 2026] [security2:error] [pid 17707:tid 17904] [client 52.238.199.152:42709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/2.php"] [unique_id "amunb7JM3qlhBlpwZyA2fwAAAMg"]
[Thu Jul 30 14:35:11.421742 2026] [security2:error] [pid 17707:tid 17962] [client 103.121.103.79:23870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunb7JM3qlhBlpwZyA2fAAAAQI"], referer: http://pkf.jo
[Thu Jul 30 14:35:12.061831 2026] [security2:error] [pid 17707:tid 17883] [client 205.209.65.8:36552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunb7JM3qlhBlpwZyA2igAAALM"], referer: http://pkf.jo
[Thu Jul 30 14:35:12.419341 2026] [security2:error] [pid 17707:tid 17950] [client 189.156.226.90:27005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuncLJM3qlhBlpwZyA2lwAAAPY"]
[Thu Jul 30 14:35:12.419473 2026] [security2:error] [pid 17707:tid 17950] [client 189.156.226.90:27005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuncLJM3qlhBlpwZyA2lwAAAPY"]
[Thu Jul 30 14:35:12.842133 2026] [security2:error] [pid 17707:tid 17821] [remote 74.7.227.39:40296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amuncLJM3qlhBlpwZyA2nwAA8XE"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico
[Thu Jul 30 14:35:13.021314 2026] [security2:error] [pid 17707:tid 17865] [client 216.244.66.196:34860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuncbJM3qlhBlpwZyA2pgAAAKE"]
[Thu Jul 30 14:35:13.021448 2026] [security2:error] [pid 17707:tid 17865] [client 216.244.66.196:34860] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuncbJM3qlhBlpwZyA2pgAAAKE"]
[Thu Jul 30 14:35:13.924184 2026] [security2:error] [pid 17707:tid 17893] [client 43.173.173.145:50432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2020/01/11/sejour-ile-maurice-conseils-budget/"] [unique_id "amuncbJM3qlhBlpwZyA2vAAAAL0"]
[Thu Jul 30 14:35:14.195888 2026] [security2:error] [pid 17707:tid 17739] [remote 47.128.28.0:29938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/"] [unique_id "amuncrJM3qlhBlpwZyA2wwAAwR8"]
[Thu Jul 30 14:35:14.239805 2026] [security2:error] [pid 17707:tid 17926] [client 44.196.118.6:28258] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/chuvas-voltar-a-causar-alagamento-no-centro-de-guarabira/20150321053301-2/"] [unique_id "amuncrJM3qlhBlpwZyA2xAAAAN4"]
[Thu Jul 30 14:35:14.536520 2026] [core:notice] [pid 17707:tid 17879] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:14.542204 2026] [security2:error] [pid 17707:tid 17879] [client 43.173.181.100:41346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2020/01/11/sejour-ile-maurice-conseils-budget/"] [unique_id "amuncrJM3qlhBlpwZyA2zAAAAK8"], referer: https://carnetdeshopping.com/index.php/2020/01/11/sejour-ile-maurice-conseils-budget/
[Thu Jul 30 14:35:14.593358 2026] [security2:error] [pid 17707:tid 17750] [remote 57.141.0.58:41098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuncrJM3qlhBlpwZyA2zQAAmSo"]
[Thu Jul 30 14:35:15.107690 2026] [security2:error] [pid 17707:tid 17866] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuncrJM3qlhBlpwZyA2ywAAoiY"]
[Thu Jul 30 14:35:15.491386 2026] [security2:error] [pid 17707:tid 17803] [remote 54.38.147.233:34540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.rgserve.ph"] [uri "/robots.txt"] [unique_id "amunc7JM3qlhBlpwZyA24wAAuF8"]
[Thu Jul 30 14:35:15.491512 2026] [security2:error] [pid 17707:tid 17888] [client 54.38.147.233:34540] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.rgserve.ph"] [uri "/robots.txt"] [unique_id "amunc7JM3qlhBlpwZyA24wAAuF8"]
[Thu Jul 30 14:35:15.937647 2026] [core:notice] [pid 17707:tid 17864] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:16.108411 2026] [security2:error] [pid 17707:tid 17948] [client 102.178.161.110:36650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amunc7JM3qlhBlpwZyA28QAAAPQ"], referer: http://pkf.jo
[Thu Jul 30 14:35:16.598652 2026] [core:notice] [pid 17707:tid 17962] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:17.002259 2026] [security2:error] [pid 17707:tid 17722] [remote 176.31.139.29:60960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.rgserve.ph"] [uri "/apply.html"] [unique_id "amundbJM3qlhBlpwZyA3DgAAqQ4"]
[Thu Jul 30 14:35:17.002400 2026] [security2:error] [pid 17707:tid 17873] [client 176.31.139.29:60960] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.rgserve.ph"] [uri "/apply.html"] [unique_id "amundbJM3qlhBlpwZyA3DgAAqQ4"]
[Thu Jul 30 14:35:17.741468 2026] [core:notice] [pid 17707:tid 17917] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:18.080856 2026] [security2:error] [pid 17707:tid 17887] [client 177.6.106.101:55663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amundrJM3qlhBlpwZyA3LQAAALc"]
[Thu Jul 30 14:35:18.081000 2026] [security2:error] [pid 17707:tid 17887] [client 177.6.106.101:55663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amundrJM3qlhBlpwZyA3LQAAALc"]
[Thu Jul 30 14:35:18.741713 2026] [security2:error] [pid 17707:tid 17911] [client 43.128.70.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amundrJM3qlhBlpwZyA3OgAAAM8"], referer: http://cnpinyin.com/dict1?search=%e4%b8%be%e8%a1%8c
[Thu Jul 30 14:35:18.794920 2026] [security2:error] [pid 17707:tid 17920] [client 52.238.199.152:17163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/baxa1.php"] [unique_id "amundrJM3qlhBlpwZyA3RQAAANg"]
[Thu Jul 30 14:35:19.087759 2026] [security2:error] [pid 17707:tid 17951] [client 180.243.59.178:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amund7JM3qlhBlpwZyA3SQAAAPc"]
[Thu Jul 30 14:35:19.087916 2026] [security2:error] [pid 17707:tid 17951] [client 180.243.59.178:54396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amund7JM3qlhBlpwZyA3SQAAAPc"]
[Thu Jul 30 14:35:20.475123 2026] [autoindex:error] [pid 17707:tid 17924] [client 32.194.121.99:25531] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_a59f0c15/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:35:20.674819 2026] [security2:error] [pid 17707:tid 17843] [client 49.36.32.150:43156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuneLJM3qlhBlpwZyA3YwAAAIs"], referer: http://pkf.jo
[Thu Jul 30 14:35:22.757342 2026] [security2:error] [pid 17707:tid 17770] [remote 173.209.48.90:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.48.209.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amunerJM3qlhBlpwZyA3pQAA-j4"]
[Thu Jul 30 14:35:22.808254 2026] [security2:error] [pid 17707:tid 17956] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunerJM3qlhBlpwZyA3lAAA_Gw"]
[Thu Jul 30 14:35:23.057648 2026] [security2:error] [pid 17707:tid 17868] [client 189.156.226.90:27311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amune7JM3qlhBlpwZyA3swAAAKQ"]
[Thu Jul 30 14:35:23.057759 2026] [security2:error] [pid 17707:tid 17868] [client 189.156.226.90:27311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amune7JM3qlhBlpwZyA3swAAAKQ"]
[Thu Jul 30 14:35:23.065369 2026] [security2:error] [pid 17707:tid 17945] [client 52.238.199.152:17004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/settings.php"] [unique_id "amune7JM3qlhBlpwZyA3tAAAAPE"]
[Thu Jul 30 14:35:23.601862 2026] [security2:error] [pid 17707:tid 17838] [client 217.64.127.195:37520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.127.64.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amune7JM3qlhBlpwZyA3wwAAAIY"]
[Thu Jul 30 14:35:23.601970 2026] [security2:error] [pid 17707:tid 17838] [client 217.64.127.195:37520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amune7JM3qlhBlpwZyA3wwAAAIY"]
[Thu Jul 30 14:35:24.169074 2026] [autoindex:error] [pid 17707:tid 17848] [client 217.76.57.223:54309] AH01276: Cannot serve directory /var/www/html/.well-known/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:35:24.250507 2026] [core:notice] [pid 17707:tid 17861] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:24.262427 2026] [core:notice] [pid 17707:tid 17879] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:24.944120 2026] [security2:error] [pid 17707:tid 17964] [client 52.238.199.152:16968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/dropdown.php"] [unique_id "amunfLJM3qlhBlpwZyA36QAAAQQ"]
[Thu Jul 30 14:35:25.008159 2026] [security2:error] [pid 17707:tid 17709] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.jookreview.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amunfbJM3qlhBlpwZyA36wAArQE"]
[Thu Jul 30 14:35:25.371885 2026] [security2:error] [pid 17707:tid 17767] [remote 209.42.21.22:41912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amunfbJM3qlhBlpwZyA38QAAyDs"]
[Thu Jul 30 14:35:25.515037 2026] [security2:error] [pid 17707:tid 17930] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.jookreview.com"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amunfbJM3qlhBlpwZyA39QAAAOI"]
[Thu Jul 30 14:35:27.159446 2026] [security2:error] [pid 17707:tid 17855] [client 177.6.106.101:56418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunf7JM3qlhBlpwZyA4IAAAAJc"]
[Thu Jul 30 14:35:27.160537 2026] [security2:error] [pid 17707:tid 17855] [client 177.6.106.101:56418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunf7JM3qlhBlpwZyA4IAAAAJc"]
[Thu Jul 30 14:35:28.262768 2026] [security2:error] [pid 17707:tid 17923] [client 52.238.199.152:16954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin.php"] [unique_id "amungLJM3qlhBlpwZyA4OgAAANs"]
[Thu Jul 30 14:35:29.166450 2026] [security2:error] [pid 17707:tid 17883] [client 52.238.199.152:41955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/buy.php"] [unique_id "amungbJM3qlhBlpwZyA4TQAAALM"]
[Thu Jul 30 14:35:30.062311 2026] [security2:error] [pid 17707:tid 17950] [client 180.243.59.178:54954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amungrJM3qlhBlpwZyA4XwAAAPY"]
[Thu Jul 30 14:35:30.062467 2026] [security2:error] [pid 17707:tid 17950] [client 180.243.59.178:54954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amungrJM3qlhBlpwZyA4XwAAAPY"]
[Thu Jul 30 14:35:31.144207 2026] [security2:error] [pid 17707:tid 17881] [client 52.238.199.152:45097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/mini.php"] [unique_id "amung7JM3qlhBlpwZyA4dQAAALE"]
[Thu Jul 30 14:35:32.297383 2026] [autoindex:error] [pid 17707:tid 17903] [client 217.76.57.223:54309] AH01276: Cannot serve directory /var/www/html/images/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:35:32.766011 2026] [security2:error] [pid 17707:tid 17849] [client 52.238.199.152:33009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/cd.php"] [unique_id "amunhLJM3qlhBlpwZyA4mgAAAJE"]
[Thu Jul 30 14:35:33.669656 2026] [security2:error] [pid 17707:tid 17947] [client 189.156.226.90:27670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunhbJM3qlhBlpwZyA4sgAAAPM"]
[Thu Jul 30 14:35:33.669785 2026] [security2:error] [pid 17707:tid 17947] [client 189.156.226.90:27670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunhbJM3qlhBlpwZyA4sgAAAPM"]
[Thu Jul 30 14:35:34.580731 2026] [security2:error] [pid 17707:tid 17906] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunhbJM3qlhBlpwZyA4vwAAAMo"]
[Thu Jul 30 14:35:34.854473 2026] [autoindex:error] [pid 17707:tid 17848] [client 195.96.139.209:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://koidomino.click
[Thu Jul 30 14:35:34.892436 2026] [security2:error] [pid 17707:tid 17868] [client 52.238.199.152:16891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amunhrJM3qlhBlpwZyA41gAAAKQ"]
[Thu Jul 30 14:35:36.013716 2026] [security2:error] [pid 17707:tid 17861] [client 52.238.199.152:52476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/batm.php"] [unique_id "amuniLJM3qlhBlpwZyA46wAAAJ0"]
[Thu Jul 30 14:35:36.846156 2026] [core:notice] [pid 17707:tid 17875] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:37.140568 2026] [security2:error] [pid 17707:tid 17923] [client 52.238.199.152:45433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/hehehehe.php"] [unique_id "amunibJM3qlhBlpwZyA5BgAAANs"]
[Thu Jul 30 14:35:37.542646 2026] [security2:error] [pid 17707:tid 17930] [client 177.6.106.101:57206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunibJM3qlhBlpwZyA5EgAAAOI"]
[Thu Jul 30 14:35:37.542797 2026] [security2:error] [pid 17707:tid 17930] [client 177.6.106.101:57206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunibJM3qlhBlpwZyA5EgAAAOI"]
[Thu Jul 30 14:35:38.894720 2026] [security2:error] [pid 17707:tid 17860] [client 139.28.219.70:53396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amunirJM3qlhBlpwZyA5KwAAAJw"]
[Thu Jul 30 14:35:39.160721 2026] [security2:error] [pid 17707:tid 17958] [client 139.28.219.70:53410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "milfordauto.com"] [uri "/xmlrpc.php"] [unique_id "amuni7JM3qlhBlpwZyA5NQAAAP4"]
[Thu Jul 30 14:35:39.459832 2026] [security2:error] [pid 17707:tid 17779] [remote 57.141.0.15:54200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuni7JM3qlhBlpwZyA5NwAA60c"]
[Thu Jul 30 14:35:39.573243 2026] [security2:error] [pid 17707:tid 17952] [client 139.28.219.70:53414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuni7JM3qlhBlpwZyA5PgAAAPg"]
[Thu Jul 30 14:35:39.682457 2026] [core:notice] [pid 17707:tid 17961] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:39.841532 2026] [security2:error] [pid 17707:tid 17944] [client 139.28.219.70:53430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuni7JM3qlhBlpwZyA5QwAAAPA"]
[Thu Jul 30 14:35:40.115161 2026] [security2:error] [pid 17707:tid 17905] [client 139.28.219.70:53444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amunjLJM3qlhBlpwZyA5SgAAAMk"]
[Thu Jul 30 14:35:40.146653 2026] [security2:error] [pid 17707:tid 17864] [client 180.243.59.178:55456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunjLJM3qlhBlpwZyA5TQAAAKA"]
[Thu Jul 30 14:35:40.146775 2026] [security2:error] [pid 17707:tid 17864] [client 180.243.59.178:55456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunjLJM3qlhBlpwZyA5TQAAAKA"]
[Thu Jul 30 14:35:40.380392 2026] [security2:error] [pid 17707:tid 17892] [client 139.28.219.70:53450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amunjLJM3qlhBlpwZyA5TwAAALw"]
[Thu Jul 30 14:35:40.548177 2026] [core:notice] [pid 17707:tid 17906] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:40.652681 2026] [security2:error] [pid 17707:tid 17839] [client 139.28.219.70:46148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amunjLJM3qlhBlpwZyA5WgAAAIc"]
[Thu Jul 30 14:35:40.925079 2026] [security2:error] [pid 17707:tid 17888] [client 139.28.219.70:46156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amunjLJM3qlhBlpwZyA5XAAAALg"]
[Thu Jul 30 14:35:41.213742 2026] [security2:error] [pid 17707:tid 17842] [client 139.28.219.70:46170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amunjbJM3qlhBlpwZyA5ZwAAAIo"]
[Thu Jul 30 14:35:41.476239 2026] [security2:error] [pid 17707:tid 17878] [client 139.28.219.70:46176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amunjbJM3qlhBlpwZyA5aAAAAK4"]
[Thu Jul 30 14:35:41.576031 2026] [security2:error] [pid 17707:tid 17933] [client 52.238.199.152:42691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/sim.php/wp-includes/certificates/plugins.php"] [unique_id "amunjbJM3qlhBlpwZyA5bAAAAOU"]
[Thu Jul 30 14:35:41.748528 2026] [security2:error] [pid 17707:tid 17904] [client 139.28.219.70:46178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amunjbJM3qlhBlpwZyA5cwAAAMg"]
[Thu Jul 30 14:35:42.013831 2026] [security2:error] [pid 17707:tid 17896] [client 139.28.219.70:46192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amunjrJM3qlhBlpwZyA5dAAAAMA"]
[Thu Jul 30 14:35:42.281961 2026] [security2:error] [pid 17707:tid 17838] [client 139.28.219.70:46200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amunjrJM3qlhBlpwZyA5egAAAIY"]
[Thu Jul 30 14:35:42.551699 2026] [security2:error] [pid 17707:tid 17910] [client 139.28.219.70:46212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amunjrJM3qlhBlpwZyA5iAAAAM4"]
[Thu Jul 30 14:35:42.830491 2026] [security2:error] [pid 17707:tid 17837] [client 139.28.219.70:46214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amunjrJM3qlhBlpwZyA5lQAAAIU"]
[Thu Jul 30 14:35:43.106496 2026] [security2:error] [pid 17707:tid 17946] [client 139.28.219.70:46228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amunj7JM3qlhBlpwZyA5mQAAAPI"]
[Thu Jul 30 14:35:43.130643 2026] [security2:error] [pid 17707:tid 17741] [remote 95.247.153.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.153.247.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "afropakmedical.com"] [uri "/xmlrpc.php"] [unique_id "amunjrJM3qlhBlpwZyA5lgAAxyE"]
[Thu Jul 30 14:35:43.130859 2026] [security2:error] [pid 17707:tid 17903] [client 95.247.153.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "afropakmedical.com"] [uri "/xmlrpc.php"] [unique_id "amunjrJM3qlhBlpwZyA5lgAAxyE"]
[Thu Jul 30 14:35:43.370807 2026] [security2:error] [pid 17707:tid 17872] [client 52.238.199.152:17219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-seo.php"] [unique_id "amunj7JM3qlhBlpwZyA5pQAAAKg"]
[Thu Jul 30 14:35:43.388687 2026] [security2:error] [pid 17707:tid 17956] [client 139.28.219.70:46238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amunj7JM3qlhBlpwZyA5pgAAAPw"]
[Thu Jul 30 14:35:43.665742 2026] [security2:error] [pid 17707:tid 17929] [client 139.28.219.70:46240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milfordauto.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amunj7JM3qlhBlpwZyA5pwAAAOE"]
[Thu Jul 30 14:35:44.005927 2026] [security2:error] [pid 17707:tid 17914] [client 216.244.66.243:52224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/rattlesnake-roundup/high-point-obituaries"] [unique_id "amunkLJM3qlhBlpwZyA5tQAAANI"]
[Thu Jul 30 14:35:44.006064 2026] [security2:error] [pid 17707:tid 17914] [client 216.244.66.243:52224] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arabiandubaisafari.com"] [uri "/rattlesnake-roundup/high-point-obituaries"] [unique_id "amunkLJM3qlhBlpwZyA5tQAAANI"]
[Thu Jul 30 14:35:44.247539 2026] [security2:error] [pid 17707:tid 17945] [client 189.156.226.90:26796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunkLJM3qlhBlpwZyA5uQAAAPE"]
[Thu Jul 30 14:35:44.247672 2026] [security2:error] [pid 17707:tid 17945] [client 189.156.226.90:26796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunkLJM3qlhBlpwZyA5uQAAAPE"]
[Thu Jul 30 14:35:45.226553 2026] [core:notice] [pid 17707:tid 17739] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:47.464582 2026] [core:error] [pid 17707:tid 17744] [remote 74.7.241.164:42198] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:35:47.464610 2026] [core:error] [pid 17707:tid 17744] [remote 74.7.241.164:42198] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:35:47.464775 2026] [security2:error] [pid 17707:tid 17863] [client 74.7.241.164:42198] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "vertexroofsolutions.com"] [uri "/index.php"] [unique_id "amunk7JM3qlhBlpwZyA59QAAnyQ"]
[Thu Jul 30 14:35:47.557930 2026] [security2:error] [pid 17707:tid 17821] [remote 57.141.0.12:21030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amunk7JM3qlhBlpwZyA59gAA2nE"]
[Thu Jul 30 14:35:48.120014 2026] [security2:error] [pid 17707:tid 17924] [client 177.6.106.101:53646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunlLJM3qlhBlpwZyA6AwAAANw"]
[Thu Jul 30 14:35:48.120170 2026] [security2:error] [pid 17707:tid 17924] [client 177.6.106.101:53646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunlLJM3qlhBlpwZyA6AwAAANw"]
[Thu Jul 30 14:35:49.177775 2026] [core:notice] [pid 17707:tid 17839] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:49.269741 2026] [security2:error] [pid 17707:tid 17914] [client 52.238.199.152:52420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/zwso.php"] [unique_id "amunlbJM3qlhBlpwZyA6HQAAANI"]
[Thu Jul 30 14:35:49.748074 2026] [core:notice] [pid 17707:tid 17963] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:49.960552 2026] [security2:error] [pid 17707:tid 17847] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunlbJM3qlhBlpwZyA6IwAAAI8"]
[Thu Jul 30 14:35:50.081732 2026] [security2:error] [pid 17707:tid 17929] [client 47.128.58.53:59930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mydubaidesertsafari.com"] [uri "/robots.txt"] [unique_id "amunlrJM3qlhBlpwZyA6MQAAAOE"]
[Thu Jul 30 14:35:50.414250 2026] [security2:error] [pid 17707:tid 17877] [client 180.243.59.178:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunlrJM3qlhBlpwZyA6PgAAAK0"]
[Thu Jul 30 14:35:50.414410 2026] [security2:error] [pid 17707:tid 17877] [client 180.243.59.178:55978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunlrJM3qlhBlpwZyA6PgAAAK0"]
[Thu Jul 30 14:35:51.348024 2026] [security2:error] [pid 17707:tid 17958] [client 52.238.199.152:17149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/user.php"] [unique_id "amunl7JM3qlhBlpwZyA6TQAAAP4"]
[Thu Jul 30 14:35:52.376398 2026] [security2:error] [pid 17707:tid 17946] [client 52.238.199.152:42723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/assets/index.php"] [unique_id "amunmLJM3qlhBlpwZyA6YgAAAPI"]
[Thu Jul 30 14:35:52.709766 2026] [core:notice] [pid 17707:tid 17773] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:53.350867 2026] [core:notice] [pid 17707:tid 17941] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:53.541505 2026] [security2:error] [pid 17707:tid 17826] [remote 198.38.94.87:55474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amunmbJM3qlhBlpwZyA6ewAAzXY"]
[Thu Jul 30 14:35:53.583067 2026] [core:notice] [pid 17707:tid 17858] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:53.938397 2026] [security2:error] [pid 17707:tid 17896] [client 89.238.167.134:50846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amunmbJM3qlhBlpwZyA6gQAAAMA"]
[Thu Jul 30 14:35:53.938522 2026] [security2:error] [pid 17707:tid 17896] [client 89.238.167.134:50846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amunmbJM3qlhBlpwZyA6gQAAAMA"]
[Thu Jul 30 14:35:54.743174 2026] [security2:error] [pid 17707:tid 17919] [client 189.156.226.90:27120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunmrJM3qlhBlpwZyA6lgAAANc"]
[Thu Jul 30 14:35:54.743304 2026] [security2:error] [pid 17707:tid 17919] [client 189.156.226.90:27120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunmrJM3qlhBlpwZyA6lgAAANc"]
[Thu Jul 30 14:35:55.001945 2026] [security2:error] [pid 17707:tid 17866] [client 52.238.199.152:41961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/byp.php"] [unique_id "amunm7JM3qlhBlpwZyA6lwAAAKI"]
[Thu Jul 30 14:35:56.045390 2026] [security2:error] [pid 17707:tid 17917] [client 52.238.199.152:38122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/bs1.php"] [unique_id "amunnLJM3qlhBlpwZyA6tAAAANU"]
[Thu Jul 30 14:35:57.187963 2026] [security2:error] [pid 17707:tid 17961] [client 52.238.199.152:16849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/IXR/allez.php"] [unique_id "amunnbJM3qlhBlpwZyA60gAAAQE"]
[Thu Jul 30 14:35:57.460763 2026] [autoindex:error] [pid 17707:tid 17862] [client 45.61.137.20:38244] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:35:58.072616 2026] [core:notice] [pid 17707:tid 17910] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:35:58.636831 2026] [security2:error] [pid 17707:tid 17847] [client 154.57.218.68:43777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amunnrJM3qlhBlpwZyA68wAAjxA"], referer: https://trello.com/
[Thu Jul 30 14:35:58.683334 2026] [security2:error] [pid 17707:tid 17839] [client 177.6.106.101:54131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunnrJM3qlhBlpwZyA6_gAAAIc"]
[Thu Jul 30 14:35:58.684467 2026] [security2:error] [pid 17707:tid 17839] [client 177.6.106.101:54131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunnrJM3qlhBlpwZyA6_gAAAIc"]
[Thu Jul 30 14:35:59.559435 2026] [security2:error] [pid 17707:tid 17895] [client 52.238.199.152:45076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/load.php"] [unique_id "amunn7JM3qlhBlpwZyA7EgAAAL8"]
[Thu Jul 30 14:35:59.651400 2026] [security2:error] [pid 17707:tid 17904] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunn7JM3qlhBlpwZyA7CAAAAMg"]
[Thu Jul 30 14:36:00.492141 2026] [security2:error] [pid 17707:tid 17868] [client 52.238.199.152:41941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/privacy.php"] [unique_id "amunoLJM3qlhBlpwZyA7JwAAAKQ"]
[Thu Jul 30 14:36:01.288767 2026] [core:notice] [pid 17707:tid 17955] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:01.633127 2026] [security2:error] [pid 17707:tid 17945] [client 180.243.59.178:56759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunobJM3qlhBlpwZyA7QwAAAPE"]
[Thu Jul 30 14:36:01.633270 2026] [security2:error] [pid 17707:tid 17945] [client 180.243.59.178:56759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunobJM3qlhBlpwZyA7QwAAAPE"]
[Thu Jul 30 14:36:01.986752 2026] [security2:error] [pid 17707:tid 17893] [client 52.238.199.152:45118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-cli.php"] [unique_id "amunobJM3qlhBlpwZyA7TgAAAL0"]
[Thu Jul 30 14:36:02.961897 2026] [security2:error] [pid 17707:tid 17905] [client 52.238.199.152:16850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/cc.php"] [unique_id "amunorJM3qlhBlpwZyA7aQAAAMk"]
[Thu Jul 30 14:36:03.414664 2026] [security2:error] [pid 17707:tid 17913] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunorJM3qlhBlpwZyA7XwAAANE"]
[Thu Jul 30 14:36:03.750134 2026] [security2:error] [pid 17707:tid 17956] [client 47.128.47.177:31626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabian-tours.com"] [uri "/robots.txt"] [unique_id "amuno7JM3qlhBlpwZyA7egAAAPw"]
[Thu Jul 30 14:36:04.338918 2026] [security2:error] [pid 17707:tid 17861] [client 52.238.199.152:33013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/media-new.php"] [unique_id "amunpLJM3qlhBlpwZyA7kAAAAJ0"]
[Thu Jul 30 14:36:05.303489 2026] [security2:error] [pid 17707:tid 17850] [client 189.156.226.90:27592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunpbJM3qlhBlpwZyA7pQAAAJI"]
[Thu Jul 30 14:36:05.303628 2026] [security2:error] [pid 17707:tid 17850] [client 189.156.226.90:27592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunpbJM3qlhBlpwZyA7pQAAAJI"]
[Thu Jul 30 14:36:05.505499 2026] [security2:error] [pid 17707:tid 17855] [client 52.238.199.152:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-blog.php"] [unique_id "amunpbJM3qlhBlpwZyA7qQAAAJc"]
[Thu Jul 30 14:36:06.581384 2026] [security2:error] [pid 17707:tid 17784] [remote 72.167.132.114:46260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amunprJM3qlhBlpwZyA7wAAA9Ew"]
[Thu Jul 30 14:36:07.492259 2026] [security2:error] [pid 17707:tid 17927] [client 217.64.127.195:40936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.127.64.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amunp7JM3qlhBlpwZyA73AAAAN8"]
[Thu Jul 30 14:36:07.492357 2026] [security2:error] [pid 17707:tid 17927] [client 217.64.127.195:40936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amunp7JM3qlhBlpwZyA73AAAAN8"]
[Thu Jul 30 14:36:08.700541 2026] [security2:error] [pid 17707:tid 17952] [client 127.0.0.1:12534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amunqLJM3qlhBlpwZyA7-QAAAPg"]
[Thu Jul 30 14:36:08.700584 2026] [security2:error] [pid 17707:tid 17899] [client 127.0.0.1:12522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.seven-stars-shop.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amunqLJM3qlhBlpwZyA7-AAAAMM"]
[Thu Jul 30 14:36:08.700689 2026] [security2:error] [pid 17707:tid 17921] [client 74.7.228.10:49434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.seven-stars-shop.com"] [uri "/robots.txt"] [unique_id "amunqLJM3qlhBlpwZyA79wAA2SM"]
[Thu Jul 30 14:36:08.774388 2026] [core:notice] [pid 17707:tid 17885] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:09.376874 2026] [security2:error] [pid 17707:tid 17870] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunqLJM3qlhBlpwZyA8AQAApmA"]
[Thu Jul 30 14:36:09.797390 2026] [security2:error] [pid 17707:tid 17864] [client 52.238.199.152:42698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-2019.php"] [unique_id "amunqbJM3qlhBlpwZyA8GQAAAKA"]
[Thu Jul 30 14:36:09.900553 2026] [security2:error] [pid 17707:tid 17883] [client 177.6.106.101:54688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunqbJM3qlhBlpwZyA8HgAAALM"]
[Thu Jul 30 14:36:09.900688 2026] [security2:error] [pid 17707:tid 17883] [client 177.6.106.101:54688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunqbJM3qlhBlpwZyA8HgAAALM"]
[Thu Jul 30 14:36:11.634417 2026] [security2:error] [pid 17707:tid 17959] [client 180.243.59.178:57393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunq7JM3qlhBlpwZyA8XAAAAP8"]
[Thu Jul 30 14:36:11.634756 2026] [security2:error] [pid 17707:tid 17959] [client 180.243.59.178:57393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunq7JM3qlhBlpwZyA8XAAAAP8"]
[Thu Jul 30 14:36:11.960557 2026] [security2:error] [pid 17707:tid 17719] [remote 57.141.0.70:22270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3834645497/feed/rss2/"] [unique_id "amunq7JM3qlhBlpwZyA8aAAAlAs"]
[Thu Jul 30 14:36:12.501631 2026] [core:notice] [pid 17707:tid 17827] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:12.706076 2026] [security2:error] [pid 17707:tid 17846] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunrLJM3qlhBlpwZyA8awAAAI4"]
[Thu Jul 30 14:36:13.373852 2026] [core:notice] [pid 17707:tid 17952] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:13.634523 2026] [security2:error] [pid 17707:tid 17923] [client 154.57.218.68:43800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amunrbJM3qlhBlpwZyA8yQAA22A"], referer: https://www.urwru.club/
[Thu Jul 30 14:36:13.939922 2026] [core:notice] [pid 17707:tid 17887] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:14.187398 2026] [security2:error] [pid 17707:tid 17895] [client 52.238.199.152:16884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/menu.php"] [unique_id "amunrrJM3qlhBlpwZyA88QAAAL8"]
[Thu Jul 30 14:36:14.375903 2026] [core:notice] [pid 17707:tid 17905] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:14.800439 2026] [core:notice] [pid 17707:tid 17915] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:15.124861 2026] [security2:error] [pid 17707:tid 17871] [client 131.161.79.181:3563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.79.161.131.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agr8story.site"] [uri "/xmlrpc.php"] [unique_id "amunrrJM3qlhBlpwZyA8_gAAAKc"]
[Thu Jul 30 14:36:15.125060 2026] [security2:error] [pid 17707:tid 17871] [client 131.161.79.181:3563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agr8story.site"] [uri "/xmlrpc.php"] [unique_id "amunrrJM3qlhBlpwZyA8_gAAAKc"]
[Thu Jul 30 14:36:15.660674 2026] [security2:error] [pid 17707:tid 17840] [client 172.237.109.114:15939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunr7JM3qlhBlpwZyA9CwAAAIg"], referer: https://alseermarine.com:443/index.html
[Thu Jul 30 14:36:15.688049 2026] [core:notice] [pid 17707:tid 17911] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:15.891924 2026] [security2:error] [pid 17707:tid 17941] [client 189.156.226.90:27659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunr7JM3qlhBlpwZyA9HAAAAO0"]
[Thu Jul 30 14:36:15.892063 2026] [security2:error] [pid 17707:tid 17941] [client 189.156.226.90:27659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunr7JM3qlhBlpwZyA9HAAAAO0"]
[Thu Jul 30 14:36:16.676891 2026] [core:notice] [pid 17707:tid 17837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:18.329010 2026] [security2:error] [pid 17707:tid 17889] [client 57.141.0.53:63006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amunsbJM3qlhBlpwZyA9gAAAuRI"], referer: https://igetvape-australia.com/product/alibarbar-rich-8000-puffs-6/
[Thu Jul 30 14:36:18.406450 2026] [core:notice] [pid 17707:tid 17844] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:18.422684 2026] [core:notice] [pid 17707:tid 17874] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:18.872954 2026] [core:notice] [pid 17707:tid 17909] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:19.777185 2026] [core:notice] [pid 17707:tid 17937] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:19.880049 2026] [security2:error] [pid 17707:tid 17938] [client 52.238.199.152:45408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-crons.php"] [unique_id "amuns7JM3qlhBlpwZyA9zQAAAOo"]
[Thu Jul 30 14:36:20.329925 2026] [security2:error] [pid 17707:tid 17843] [client 74.7.175.191:36000] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "arabiantourz.com"] [uri "/cgi-sys/404.html"] [unique_id "amuntLJM3qlhBlpwZyA92wAAAIs"]
[Thu Jul 30 14:36:20.438321 2026] [security2:error] [pid 17707:tid 17916] [client 102.206.97.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuntLJM3qlhBlpwZyA91wAAANQ"], referer: https://cnpinyin.com
[Thu Jul 30 14:36:20.453292 2026] [core:notice] [pid 17707:tid 17915] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:20.871920 2026] [security2:error] [pid 17707:tid 17846] [client 177.6.106.101:55689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuntLJM3qlhBlpwZyA97gAAAI4"]
[Thu Jul 30 14:36:20.872040 2026] [security2:error] [pid 17707:tid 17846] [client 177.6.106.101:55689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuntLJM3qlhBlpwZyA97gAAAI4"]
[Thu Jul 30 14:36:21.267147 2026] [core:notice] [pid 17707:tid 17893] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:21.947556 2026] [security2:error] [pid 17707:tid 17854] [client 52.238.199.152:42711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/class.php"] [unique_id "amuntbJM3qlhBlpwZyA-BAAAAJY"]
[Thu Jul 30 14:36:21.981324 2026] [security2:error] [pid 17707:tid 17957] [client 127.0.0.1:58546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuntbJM3qlhBlpwZyA-BwAAAP0"]
[Thu Jul 30 14:36:21.981349 2026] [security2:error] [pid 17707:tid 17871] [client 127.0.0.1:58538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.caflchimneysweeper.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuntbJM3qlhBlpwZyA-BgAAAKc"]
[Thu Jul 30 14:36:21.981462 2026] [security2:error] [pid 17707:tid 17855] [client 74.7.230.57:56770] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.caflchimneysweeper.com"] [uri "/robots.txt"] [unique_id "amuntbJM3qlhBlpwZyA-BQAAlzg"]
[Thu Jul 30 14:36:22.065437 2026] [security2:error] [pid 17707:tid 17908] [client 43.173.174.218:49408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/07/05/a-la-decouverte-de-lege-cap-ferret/"] [unique_id "amuntbJM3qlhBlpwZyA9_QAAAMw"]
[Thu Jul 30 14:36:22.751468 2026] [core:notice] [pid 17707:tid 17881] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:22.756274 2026] [security2:error] [pid 17707:tid 17881] [client 43.173.180.90:45338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/07/05/a-la-decouverte-de-lege-cap-ferret/"] [unique_id "amuntrJM3qlhBlpwZyA-EQAAALE"], referer: https://carnetdeshopping.com/index.php/2015/07/05/a-la-decouverte-de-lege-cap-ferret/
[Thu Jul 30 14:36:22.924921 2026] [security2:error] [pid 17707:tid 17960] [client 180.243.59.178:57972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuntrJM3qlhBlpwZyA-HAAAAQA"]
[Thu Jul 30 14:36:22.925082 2026] [security2:error] [pid 17707:tid 17960] [client 180.243.59.178:57972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuntrJM3qlhBlpwZyA-HAAAAQA"]
[Thu Jul 30 14:36:22.969621 2026] [security2:error] [pid 17707:tid 17856] [client 52.238.199.152:42710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/login.php"] [unique_id "amuntrJM3qlhBlpwZyA-IAAAAJg"]
[Thu Jul 30 14:36:23.077502 2026] [security2:error] [pid 17707:tid 17820] [remote 167.71.218.184:50640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amunt7JM3qlhBlpwZyA-IQAA9XA"]
[Thu Jul 30 14:36:23.632539 2026] [core:notice] [pid 17707:tid 17882] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:24.406179 2026] [security2:error] [pid 17707:tid 17895] [client 52.238.199.152:38080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/aged.php"] [unique_id "amunuLJM3qlhBlpwZyA-QgAAAL8"]
[Thu Jul 30 14:36:24.931050 2026] [security2:error] [pid 17707:tid 17740] [remote 57.141.0.59:44486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amunuLJM3qlhBlpwZyA-TQAAtCA"]
[Thu Jul 30 14:36:25.329789 2026] [core:notice] [pid 17707:tid 17829] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:26.538808 2026] [security2:error] [pid 17707:tid 17886] [client 189.156.226.90:26971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunurJM3qlhBlpwZyA-bgAAALY"]
[Thu Jul 30 14:36:26.538928 2026] [security2:error] [pid 17707:tid 17886] [client 189.156.226.90:26971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunurJM3qlhBlpwZyA-bgAAALY"]
[Thu Jul 30 14:36:27.314249 2026] [security2:error] [pid 17707:tid 17875] [client 52.238.199.152:39042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/vv.php"] [unique_id "amunu7JM3qlhBlpwZyA-fgAAAKs"]
[Thu Jul 30 14:36:29.844677 2026] [core:notice] [pid 17707:tid 17932] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:29.848409 2026] [security2:error] [pid 17707:tid 17932] [client 216.75.132.27:21766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ejournalugj.com"] [uri "/-yanz/Content_analysis.pdf"] [unique_id "amunvbJM3qlhBlpwZyA-twAAAOQ"]
[Thu Jul 30 14:36:30.381088 2026] [security2:error] [pid 17707:tid 17886] [client 177.6.106.101:56441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunvrJM3qlhBlpwZyA-xAAAALY"]
[Thu Jul 30 14:36:30.381262 2026] [security2:error] [pid 17707:tid 17886] [client 177.6.106.101:56441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunvrJM3qlhBlpwZyA-xAAAALY"]
[Thu Jul 30 14:36:30.455358 2026] [security2:error] [pid 17707:tid 17957] [client 109.235.50.35:55500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.50.235.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amunvrJM3qlhBlpwZyA-xQAAAP0"]
[Thu Jul 30 14:36:30.455461 2026] [security2:error] [pid 17707:tid 17957] [client 109.235.50.35:55500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amunvrJM3qlhBlpwZyA-xQAAAP0"]
[Thu Jul 30 14:36:30.538453 2026] [security2:error] [pid 17707:tid 17888] [client 52.238.199.152:33524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/user-edit.php"] [unique_id "amunvrJM3qlhBlpwZyA-xwAAALg"]
[Thu Jul 30 14:36:30.782439 2026] [core:notice] [pid 17707:tid 17890] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:31.228390 2026] [security2:error] [pid 17707:tid 17931] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunvrJM3qlhBlpwZyA-wAAAAOM"]
[Thu Jul 30 14:36:31.329562 2026] [security2:error] [pid 17707:tid 17956] [client 52.238.199.152:41960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amunv7JM3qlhBlpwZyA-3QAAAPw"]
[Thu Jul 30 14:36:31.680525 2026] [security2:error] [pid 17707:tid 17925] [client 68.67.112.68:22543] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amunv7JM3qlhBlpwZyA-5AAAAN0"]
[Thu Jul 30 14:36:32.212719 2026] [core:notice] [pid 17707:tid 17837] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:32.471866 2026] [core:notice] [pid 17707:tid 17792] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:32.555477 2026] [core:notice] [pid 17707:tid 17751] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:32.706779 2026] [security2:error] [pid 17707:tid 17910] [client 180.243.59.178:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunwLJM3qlhBlpwZyA_AAAAAM4"]
[Thu Jul 30 14:36:32.706936 2026] [security2:error] [pid 17707:tid 17910] [client 180.243.59.178:58455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunwLJM3qlhBlpwZyA_AAAAAM4"]
[Thu Jul 30 14:36:32.979104 2026] [security2:error] [pid 17707:tid 17951] [client 52.238.199.152:32971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/engine.php"] [unique_id "amunwLJM3qlhBlpwZyA_CQAAAPc"]
[Thu Jul 30 14:36:33.093109 2026] [security2:error] [pid 17707:tid 17849] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amunwLJM3qlhBlpwZyA--wAAAJE"]
[Thu Jul 30 14:36:33.340872 2026] [core:error] [pid 17707:tid 17899] [client 66.249.74.105:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:36:33.340898 2026] [core:error] [pid 17707:tid 17899] [client 66.249.74.105:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:36:33.768138 2026] [security2:error] [pid 17707:tid 17956] [client 52.238.199.152:33500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/edit-comments.php"] [unique_id "amunwbJM3qlhBlpwZyA_GgAAAPw"]
[Thu Jul 30 14:36:34.376225 2026] [core:notice] [pid 17707:tid 17847] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:34.843620 2026] [security2:error] [pid 17707:tid 17801] [remote 82.130.249.15:49580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.249.130.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mshandco.org"] [uri "/wp-login.php"] [unique_id "amunwrJM3qlhBlpwZyA_MQAAnl0"]
[Thu Jul 30 14:36:34.973280 2026] [core:notice] [pid 17707:tid 17907] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:35.462185 2026] [security2:error] [pid 17707:tid 17838] [client 52.238.199.152:16872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-blog-header.php"] [unique_id "amunw7JM3qlhBlpwZyA_QgAAAIY"]
[Thu Jul 30 14:36:36.341323 2026] [security2:error] [pid 17707:tid 17872] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amunw7JM3qlhBlpwZyA_QQAAqEA"]
[Thu Jul 30 14:36:36.480243 2026] [security2:error] [pid 17707:tid 17942] [client 52.238.199.152:16868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/alfa-rex.php7"] [unique_id "amunxLJM3qlhBlpwZyA_VgAAAO4"]
[Thu Jul 30 14:36:36.736249 2026] [security2:error] [pid 17707:tid 17870] [client 172.237.109.114:58061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunxLJM3qlhBlpwZyA_TwAAAKY"]
[Thu Jul 30 14:36:37.120349 2026] [security2:error] [pid 17707:tid 17852] [client 189.156.226.90:27200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunxbJM3qlhBlpwZyA_YwAAAJQ"]
[Thu Jul 30 14:36:37.120486 2026] [security2:error] [pid 17707:tid 17852] [client 189.156.226.90:27200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunxbJM3qlhBlpwZyA_YwAAAJQ"]
[Thu Jul 30 14:36:37.141030 2026] [core:notice] [pid 17707:tid 17767] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:37.507068 2026] [security2:error] [pid 17707:tid 17952] [client 52.167.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunxbJM3qlhBlpwZyA_agAAAPg"]
[Thu Jul 30 14:36:38.432885 2026] [security2:error] [pid 17707:tid 17910] [client 52.167.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunxrJM3qlhBlpwZyA_gAAAAM4"]
[Thu Jul 30 14:36:38.632266 2026] [security2:error] [pid 17707:tid 17953] [client 52.238.199.152:16624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/pomo/fgertreyersd.php"] [unique_id "amunxrJM3qlhBlpwZyA_kAAAAPk"]
[Thu Jul 30 14:36:38.726165 2026] [security2:error] [pid 17707:tid 17850] [client 172.237.109.114:64752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amunxrJM3qlhBlpwZyA_gQAAAJI"]
[Thu Jul 30 14:36:38.839946 2026] [security2:error] [pid 17707:tid 17872] [client 40.77.167.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunxrJM3qlhBlpwZyA_jwAAAKg"]
[Thu Jul 30 14:36:39.394698 2026] [security2:error] [pid 17707:tid 17894] [client 109.235.50.35:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.50.235.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amunx7JM3qlhBlpwZyA_pwAAAL4"]
[Thu Jul 30 14:36:39.394778 2026] [security2:error] [pid 17707:tid 17894] [client 109.235.50.35:46038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amunx7JM3qlhBlpwZyA_pwAAAL4"]
[Thu Jul 30 14:36:39.528343 2026] [security2:error] [pid 17707:tid 17844] [client 52.238.199.152:38083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/css/xmrlpc.php"] [unique_id "amunx7JM3qlhBlpwZyA_rgAAAIw"]
[Thu Jul 30 14:36:39.581080 2026] [security2:error] [pid 17707:tid 17943] [client 40.77.167.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunx7JM3qlhBlpwZyA_oAAAAO8"]
[Thu Jul 30 14:36:39.611197 2026] [core:notice] [pid 17707:tid 17716] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:39.792405 2026] [core:notice] [pid 17707:tid 17739] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:40.024401 2026] [core:notice] [pid 17707:tid 17712] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:40.528516 2026] [security2:error] [pid 17707:tid 17888] [client 40.77.167.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunyLJM3qlhBlpwZyA_xAAAALg"]
[Thu Jul 30 14:36:40.605236 2026] [security2:error] [pid 17707:tid 17873] [client 217.64.127.195:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.127.64.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amunyLJM3qlhBlpwZyA_zAAAAKk"]
[Thu Jul 30 14:36:40.605348 2026] [security2:error] [pid 17707:tid 17873] [client 217.64.127.195:59714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amunyLJM3qlhBlpwZyA_zAAAAKk"]
[Thu Jul 30 14:36:41.521876 2026] [security2:error] [pid 17707:tid 17937] [client 177.6.106.101:56929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunybJM3qlhBlpwZyA_3QAAAOk"]
[Thu Jul 30 14:36:41.522024 2026] [security2:error] [pid 17707:tid 17937] [client 177.6.106.101:56929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amunybJM3qlhBlpwZyA_3QAAAOk"]
[Thu Jul 30 14:36:41.599820 2026] [security2:error] [pid 17707:tid 17946] [client 52.238.199.152:45396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/classsmtps.php"] [unique_id "amunybJM3qlhBlpwZyA_4QAAAPI"]
[Thu Jul 30 14:36:41.879367 2026] [core:notice] [pid 17707:tid 17733] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:42.199742 2026] [security2:error] [pid 17707:tid 17858] [client 40.77.167.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amunybJM3qlhBlpwZyA_6wAAAJo"]
[Thu Jul 30 14:36:42.269645 2026] [core:notice] [pid 17707:tid 17887] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:42.606898 2026] [security2:error] [pid 17707:tid 17763] [remote 122.154.0.170:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.0.154.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fantasynamelist.com"] [uri "/wp-login.php"] [unique_id "amunyrJM3qlhBlpwZyA_-AAAozc"]
[Thu Jul 30 14:36:43.013099 2026] [security2:error] [pid 17707:tid 17874] [client 180.243.59.178:58974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuny7JM3qlhBlpwZyBAAwAAAKo"]
[Thu Jul 30 14:36:43.013291 2026] [security2:error] [pid 17707:tid 17874] [client 180.243.59.178:58974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuny7JM3qlhBlpwZyBAAwAAAKo"]
[Thu Jul 30 14:36:43.062092 2026] [security2:error] [pid 17707:tid 17837] [client 50.6.43.217:32550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amunyrJM3qlhBlpwZyA_8wAAAIU"]
[Thu Jul 30 14:36:43.148360 2026] [core:notice] [pid 17707:tid 17742] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:43.785152 2026] [security2:error] [pid 17707:tid 17869] [client 50.6.43.217:32554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuny7JM3qlhBlpwZyBABAAAAKU"]
[Thu Jul 30 14:36:44.056848 2026] [core:notice] [pid 17707:tid 17956] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:44.292020 2026] [core:notice] [pid 17707:tid 17844] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:44.871075 2026] [fcgid:warn] [pid 17707:tid 17940] (70014)End of file found: [client 152.32.142.138:45390] mod_fcgid: can't get data from http client
[Thu Jul 30 14:36:44.889566 2026] [core:notice] [pid 17707:tid 17852] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:45.265959 2026] [core:notice] [pid 17707:tid 17860] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:45.873073 2026] [core:notice] [pid 17707:tid 17895] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:46.090020 2026] [security2:error] [pid 17707:tid 17871] [client 52.238.199.152:16858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/themes/zMousse/otuz1.php"] [unique_id "amunzrJM3qlhBlpwZyBAawAAAKc"]
[Thu Jul 30 14:36:46.593508 2026] [core:notice] [pid 17707:tid 17851] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:47.343912 2026] [core:notice] [pid 17707:tid 17876] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:47.737270 2026] [security2:error] [pid 17707:tid 17950] [client 189.156.226.90:27633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunz7JM3qlhBlpwZyBArAAAAPY"]
[Thu Jul 30 14:36:47.737427 2026] [security2:error] [pid 17707:tid 17950] [client 189.156.226.90:27633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amunz7JM3qlhBlpwZyBArAAAAPY"]
[Thu Jul 30 14:36:47.865161 2026] [security2:error] [pid 17707:tid 17954] [client 50.6.43.217:32560] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amunz7JM3qlhBlpwZyBArQAAAPo"]
[Thu Jul 30 14:36:47.896198 2026] [security2:error] [pid 17707:tid 17857] [client 50.6.43.217:32562] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amunz7JM3qlhBlpwZyBAsQAAAJk"]
[Thu Jul 30 14:36:47.919988 2026] [core:notice] [pid 17707:tid 17842] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:47.992772 2026] [security2:error] [pid 17707:tid 17848] [client 185.191.171.18:19260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/robots.txt"] [unique_id "amunz7JM3qlhBlpwZyBAswAAAJA"]
[Thu Jul 30 14:36:47.992951 2026] [security2:error] [pid 17707:tid 17848] [client 185.191.171.18:19260] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lark-shop.com"] [uri "/robots.txt"] [unique_id "amunz7JM3qlhBlpwZyBAswAAAJA"]
[Thu Jul 30 14:36:48.442053 2026] [core:notice] [pid 17707:tid 17920] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:48.538426 2026] [security2:error] [pid 17707:tid 17922] [client 52.167.144.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amun0LJM3qlhBlpwZyBAugAAANo"]
[Thu Jul 30 14:36:48.661837 2026] [security2:error] [pid 17707:tid 17889] [client 172.237.109.114:14107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amun0LJM3qlhBlpwZyBAtwAAALk"], referer: https://alseermarine.com:443/index.html
[Thu Jul 30 14:36:48.784616 2026] [security2:error] [pid 17707:tid 17905] [client 52.238.199.152:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/123.php"] [unique_id "amun0LJM3qlhBlpwZyBA0QAAAMk"]
[Thu Jul 30 14:36:49.116813 2026] [core:notice] [pid 17707:tid 17877] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:49.146048 2026] [security2:error] [pid 17707:tid 17915] [client 50.6.43.217:32568] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amun0bJM3qlhBlpwZyBA2gAAANM"]
[Thu Jul 30 14:36:49.186770 2026] [security2:error] [pid 17707:tid 17841] [client 185.191.171.13:57644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/product/marlboro-16/"] [unique_id "amun0bJM3qlhBlpwZyBA2wAAAIk"]
[Thu Jul 30 14:36:49.186910 2026] [security2:error] [pid 17707:tid 17841] [client 185.191.171.13:57644] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lark-shop.com"] [uri "/product/marlboro-16/"] [unique_id "amun0bJM3qlhBlpwZyBA2wAAAIk"]
[Thu Jul 30 14:36:49.336271 2026] [security2:error] [pid 17707:tid 17932] [client 50.6.43.217:32580] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amun0bJM3qlhBlpwZyBA3wAAAOQ"]
[Thu Jul 30 14:36:49.822467 2026] [core:notice] [pid 17707:tid 17910] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:50.204485 2026] [core:notice] [pid 17707:tid 17848] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:50.852051 2026] [core:notice] [pid 17707:tid 17946] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:51.442268 2026] [core:notice] [pid 17707:tid 17854] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:51.577093 2026] [security2:error] [pid 17707:tid 17919] [client 177.6.106.101:53469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun07JM3qlhBlpwZyBBLwAAANc"]
[Thu Jul 30 14:36:51.577205 2026] [security2:error] [pid 17707:tid 17919] [client 177.6.106.101:53469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun07JM3qlhBlpwZyBBLwAAANc"]
[Thu Jul 30 14:36:52.008652 2026] [core:notice] [pid 17707:tid 17869] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:52.660189 2026] [security2:error] [pid 17707:tid 17942] [client 172.237.109.114:44414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amun1LJM3qlhBlpwZyBBQwAAAO4"], referer: https://alseermarine.com:443/index.html
[Thu Jul 30 14:36:52.696379 2026] [core:notice] [pid 17707:tid 17923] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:53.428173 2026] [core:notice] [pid 17707:tid 17883] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:53.699209 2026] [security2:error] [pid 17707:tid 17886] [client 180.243.59.178:59524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun1bJM3qlhBlpwZyBBaQAAALY"]
[Thu Jul 30 14:36:53.699324 2026] [security2:error] [pid 17707:tid 17886] [client 180.243.59.178:59524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun1bJM3qlhBlpwZyBBaQAAALY"]
[Thu Jul 30 14:36:54.100061 2026] [http2:info] [pid 43637:tid 43637] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 14:36:54.526276 2026] [core:notice] [pid 43637:tid 43774] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:54.748053 2026] [security2:error] [pid 17707:tid 17884] [client 52.238.199.152:16880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amun1rJM3qlhBlpwZyBBbQAAALQ"]
[Thu Jul 30 14:36:55.316312 2026] [security2:error] [pid 43637:tid 43821] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amun1oa8U9lZpWaWlJJdLgAAAAA"]
[Thu Jul 30 14:36:55.332056 2026] [core:notice] [pid 43637:tid 43824] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:55.359377 2026] [core:notice] [pid 43637:tid 43810] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:55.938484 2026] [core:notice] [pid 43637:tid 43846] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:56.305093 2026] [security2:error] [pid 43637:tid 43857] [client 52.238.199.152:41972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/filebrowser.php"] [unique_id "amun2Ia8U9lZpWaWlJJdYwAAAFk"]
[Thu Jul 30 14:36:56.677192 2026] [core:notice] [pid 43637:tid 43880] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:57.084874 2026] [security2:error] [pid 43637:tid 43654] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amun2Ia8U9lZpWaWlJJdcgAAcRA"]
[Thu Jul 30 14:36:57.085123 2026] [security2:error] [pid 43637:tid 43881] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amun2Ia8U9lZpWaWlJJdcgAAcRA"]
[Thu Jul 30 14:36:57.168354 2026] [security2:error] [pid 43637:tid 43791] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amun2Ia8U9lZpWaWlJJdXgAAAFQ"]
[Thu Jul 30 14:36:57.244242 2026] [security2:error] [pid 43637:tid 43661] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amun2Ya8U9lZpWaWlJJdgAAAIRc"]
[Thu Jul 30 14:36:57.244493 2026] [security2:error] [pid 43637:tid 43801] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amun2Ya8U9lZpWaWlJJdgAAAIRc"]
[Thu Jul 30 14:36:57.288447 2026] [core:notice] [pid 43637:tid 43797] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:57.437591 2026] [security2:error] [pid 43637:tid 43787] [client 52.238.199.152:38087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/makeasmtp.php"] [unique_id "amun2Ya8U9lZpWaWlJJdigAAABM"]
[Thu Jul 30 14:36:57.953628 2026] [security2:error] [pid 43637:tid 43826] [client 198.23.198.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.198.23.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucky-strike-shop.com"] [uri "/phpinfo.php"] [unique_id "amun2Ya8U9lZpWaWlJJdkgAAADo"]
[Thu Jul 30 14:36:58.008019 2026] [core:notice] [pid 43637:tid 43838] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:58.203955 2026] [security2:error] [pid 43637:tid 43673] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amun2Ya8U9lZpWaWlJJdlwAAQSM"]
[Thu Jul 30 14:36:58.204224 2026] [security2:error] [pid 43637:tid 43833] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/wp-login.php"] [unique_id "amun2Ya8U9lZpWaWlJJdlwAAQSM"]
[Thu Jul 30 14:36:58.309660 2026] [security2:error] [pid 43637:tid 43841] [client 189.156.226.90:26852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amun2oa8U9lZpWaWlJJdnwAAAEk"]
[Thu Jul 30 14:36:58.309784 2026] [security2:error] [pid 43637:tid 43841] [client 189.156.226.90:26852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amun2oa8U9lZpWaWlJJdnwAAAEk"]
[Thu Jul 30 14:36:58.378500 2026] [security2:error] [pid 43637:tid 43676] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/red.php"] [unique_id "amun2oa8U9lZpWaWlJJdoAAATyY"]
[Thu Jul 30 14:36:58.378665 2026] [security2:error] [pid 43637:tid 43847] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/red.php"] [unique_id "amun2oa8U9lZpWaWlJJdoAAATyY"]
[Thu Jul 30 14:36:58.679470 2026] [core:notice] [pid 43637:tid 43877] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:59.289076 2026] [security2:error] [pid 43637:tid 43688] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/cc.php"] [unique_id "amun24a8U9lZpWaWlJJdvAAABzI"]
[Thu Jul 30 14:36:59.289261 2026] [security2:error] [pid 43637:tid 43775] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/cc.php"] [unique_id "amun24a8U9lZpWaWlJJdvAAABzI"]
[Thu Jul 30 14:36:59.289440 2026] [core:notice] [pid 43637:tid 43891] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:59.319564 2026] [security2:error] [pid 43637:tid 43867] [client 52.238.199.152:45430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/bypass.php"] [unique_id "amun24a8U9lZpWaWlJJdvQAAAGM"]
[Thu Jul 30 14:36:59.457110 2026] [security2:error] [pid 43637:tid 43690] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/log.php"] [unique_id "amun24a8U9lZpWaWlJJdwgAADjQ"]
[Thu Jul 30 14:36:59.457308 2026] [security2:error] [pid 43637:tid 43782] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/log.php"] [unique_id "amun24a8U9lZpWaWlJJdwgAADjQ"]
[Thu Jul 30 14:36:59.616703 2026] [security2:error] [pid 43637:tid 43694] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/edit.php"] [unique_id "amun24a8U9lZpWaWlJJdywAAIDg"]
[Thu Jul 30 14:36:59.616868 2026] [security2:error] [pid 43637:tid 43800] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/edit.php"] [unique_id "amun24a8U9lZpWaWlJJdywAAIDg"]
[Thu Jul 30 14:36:59.627125 2026] [security2:error] [pid 43637:tid 43799] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amun2oa8U9lZpWaWlJJdqAAAAFw"]
[Thu Jul 30 14:36:59.782044 2026] [security2:error] [pid 43637:tid 43695] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/plugins.php"] [unique_id "amun24a8U9lZpWaWlJJdzQAAHDk"]
[Thu Jul 30 14:36:59.782207 2026] [security2:error] [pid 43637:tid 43796] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/plugins.php"] [unique_id "amun24a8U9lZpWaWlJJdzQAAHDk"]
[Thu Jul 30 14:36:59.887834 2026] [core:notice] [pid 43637:tid 43804] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:36:59.948075 2026] [security2:error] [pid 43637:tid 43696] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/style.php"] [unique_id "amun24a8U9lZpWaWlJJdzwAAGjo"]
[Thu Jul 30 14:36:59.948323 2026] [security2:error] [pid 43637:tid 43794] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/style.php"] [unique_id "amun24a8U9lZpWaWlJJdzwAAGjo"]
[Thu Jul 30 14:37:00.108758 2026] [security2:error] [pid 43637:tid 43699] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/plugins.php"] [unique_id "amun3Ia8U9lZpWaWlJJd1gAAMD0"]
[Thu Jul 30 14:37:00.108891 2026] [security2:error] [pid 43637:tid 43816] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/plugins.php"] [unique_id "amun3Ia8U9lZpWaWlJJd1gAAMD0"]
[Thu Jul 30 14:37:00.179163 2026] [security2:error] [pid 43637:tid 43810] [client 198.23.198.15:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "lucky-strike-shop.com"] [uri "/.env.bak"] [unique_id "amun3Ia8U9lZpWaWlJJd2wAAACo"]
[Thu Jul 30 14:37:00.262142 2026] [security2:error] [pid 43637:tid 43701] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/file.php"] [unique_id "amun3Ia8U9lZpWaWlJJd3AAAND8"]
[Thu Jul 30 14:37:00.262377 2026] [security2:error] [pid 43637:tid 43820] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/file.php"] [unique_id "amun3Ia8U9lZpWaWlJJd3AAAND8"]
[Thu Jul 30 14:37:00.539525 2026] [core:notice] [pid 43637:tid 43829] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:00.596911 2026] [security2:error] [pid 43637:tid 43790] [client 172.237.109.114:9583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amun3Ia8U9lZpWaWlJJd1wAAABY"]
[Thu Jul 30 14:37:00.694276 2026] [security2:error] [pid 43637:tid 43705] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/uninstall.php"] [unique_id "amun3Ia8U9lZpWaWlJJd5QAATUM"]
[Thu Jul 30 14:37:00.694443 2026] [security2:error] [pid 43637:tid 43845] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/uninstall.php"] [unique_id "amun3Ia8U9lZpWaWlJJd5QAATUM"]
[Thu Jul 30 14:37:00.695663 2026] [security2:error] [pid 43637:tid 43844] [client 198.23.198.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.198.23.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucky-strike-shop.com"] [uri "/info.php"] [unique_id "amun3Ia8U9lZpWaWlJJd5gAAAEw"]
[Thu Jul 30 14:37:00.846543 2026] [security2:error] [pid 43637:tid 43706] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/la.php"] [unique_id "amun3Ia8U9lZpWaWlJJd7AAASUQ"]
[Thu Jul 30 14:37:00.846721 2026] [security2:error] [pid 43637:tid 43841] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/la.php"] [unique_id "amun3Ia8U9lZpWaWlJJd7AAASUQ"]
[Thu Jul 30 14:37:01.052148 2026] [autoindex:error] [pid 43637:tid 43835] [client 74.7.242.49:56554] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://pr-new.domaineye.com
[Thu Jul 30 14:37:01.139188 2026] [security2:error] [pid 43637:tid 43708] [remote 74.248.20.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.20.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/css.php"] [unique_id "amun3Ya8U9lZpWaWlJJd8QAAWUY"]
[Thu Jul 30 14:37:01.139342 2026] [security2:error] [pid 43637:tid 43857] [client 74.248.20.32:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "allmontecristi.com"] [uri "/css.php"] [unique_id "amun3Ya8U9lZpWaWlJJd8QAAWUY"]
[Thu Jul 30 14:37:01.211868 2026] [core:notice] [pid 43637:tid 43872] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:01.952427 2026] [core:notice] [pid 43637:tid 43895] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:02.178113 2026] [security2:error] [pid 43637:tid 43869] [client 177.6.106.101:53957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun3oa8U9lZpWaWlJJeCwAAAGU"]
[Thu Jul 30 14:37:02.178258 2026] [security2:error] [pid 43637:tid 43869] [client 177.6.106.101:53957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun3oa8U9lZpWaWlJJeCwAAAGU"]
[Thu Jul 30 14:37:02.413943 2026] [security2:error] [pid 43637:tid 43719] [remote 103.164.173.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.173.164.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "openspacelab.club"] [uri "/wordpress/xmlrpc.php"] [unique_id "amun3oa8U9lZpWaWlJJeEwAAElE"]
[Thu Jul 30 14:37:02.414187 2026] [security2:error] [pid 43637:tid 43786] [client 103.164.173.46:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "openspacelab.club"] [uri "/wordpress/xmlrpc.php"] [unique_id "amun3oa8U9lZpWaWlJJeEwAAElE"]
[Thu Jul 30 14:37:02.494526 2026] [security2:error] [pid 43637:tid 43777] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amun3Ya8U9lZpWaWlJJd-wAAAHQ"]
[Thu Jul 30 14:37:02.535798 2026] [security2:error] [pid 43637:tid 43855] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amun3Ya8U9lZpWaWlJJeAgAAV0w"]
[Thu Jul 30 14:37:02.594300 2026] [core:notice] [pid 43637:tid 43804] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:03.033763 2026] [core:notice] [pid 43637:tid 43838] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:03.961860 2026] [security2:error] [pid 43637:tid 43890] [client 172.237.109.114:39392] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amun34a8U9lZpWaWlJJeOAAAAHo"]
[Thu Jul 30 14:37:04.147073 2026] [security2:error] [pid 43637:tid 43879] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amun34a8U9lZpWaWlJJeHwAAAEg"]
[Thu Jul 30 14:37:05.330082 2026] [security2:error] [pid 43637:tid 43787] [client 180.243.59.178:60115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun4Ya8U9lZpWaWlJJeUgAAABM"]
[Thu Jul 30 14:37:05.330239 2026] [security2:error] [pid 43637:tid 43787] [client 180.243.59.178:60115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun4Ya8U9lZpWaWlJJeUgAAABM"]
[Thu Jul 30 14:37:05.768788 2026] [security2:error] [pid 43637:tid 43838] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amun4Ia8U9lZpWaWlJJeRQAAABs"]
[Thu Jul 30 14:37:06.049916 2026] [core:notice] [pid 43637:tid 43746] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:06.433872 2026] [security2:error] [pid 43637:tid 43842] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amun4Ya8U9lZpWaWlJJeXgAAAEo"]
[Thu Jul 30 14:37:06.504120 2026] [security2:error] [pid 43637:tid 43864] [client 172.237.109.114:40433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amun4oa8U9lZpWaWlJJeagAAAGA"]
[Thu Jul 30 14:37:06.566785 2026] [security2:error] [pid 43637:tid 43849] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amun4Ya8U9lZpWaWlJJeZgAAAFE"]
[Thu Jul 30 14:37:06.567181 2026] [security2:error] [pid 43637:tid 43874] [client 52.238.199.152:16425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/pi.php"] [unique_id "amun4oa8U9lZpWaWlJJedgAAAGo"]
[Thu Jul 30 14:37:06.588518 2026] [core:notice] [pid 43637:tid 43750] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:07.005807 2026] [security2:error] [pid 43637:tid 43755] [remote 68.183.22.192:59190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.22.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amun4oa8U9lZpWaWlJJegAAAQXU"]
[Thu Jul 30 14:37:07.290958 2026] [core:notice] [pid 43637:tid 43775] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:07.723764 2026] [core:error] [pid 43637:tid 43794] [client 74.7.175.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:37:07.723787 2026] [core:error] [pid 43637:tid 43794] [client 74.7.175.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:37:07.723931 2026] [security2:error] [pid 43637:tid 43794] [client 74.7.175.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.rvi.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amun44a8U9lZpWaWlJJekAAAABo"]
[Thu Jul 30 14:37:07.724555 2026] [security2:error] [pid 43637:tid 43811] [client 74.7.175.172:35676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.rvi.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amun44a8U9lZpWaWlJJejgAAK3k"]
[Thu Jul 30 14:37:08.160459 2026] [core:notice] [pid 43637:tid 43798] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:08.499031 2026] [core:notice] [pid 43637:tid 43765] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:08.561649 2026] [security2:error] [pid 43637:tid 43886] [client 201.93.23.219:55009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.23.93.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abudhabicarrecoveryllc.online"] [uri "/xmlrpc.php"] [unique_id "amun5Ia8U9lZpWaWlJJeogAAAHY"]
[Thu Jul 30 14:37:08.561844 2026] [security2:error] [pid 43637:tid 43886] [client 201.93.23.219:55009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abudhabicarrecoveryllc.online"] [uri "/xmlrpc.php"] [unique_id "amun5Ia8U9lZpWaWlJJeogAAAHY"]
[Thu Jul 30 14:37:08.776212 2026] [core:notice] [pid 43637:tid 43640] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:08.776900 2026] [security2:error] [pid 43637:tid 43639] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.allmontecristi.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amun5Ia8U9lZpWaWlJJerwAAAQE"]
[Thu Jul 30 14:37:08.912424 2026] [security2:error] [pid 43637:tid 43880] [client 189.156.226.90:27105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amun5Ia8U9lZpWaWlJJesgAAAHA"]
[Thu Jul 30 14:37:08.912554 2026] [security2:error] [pid 43637:tid 43880] [client 189.156.226.90:27105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amun5Ia8U9lZpWaWlJJesgAAAHA"]
[Thu Jul 30 14:37:10.560491 2026] [security2:error] [pid 43637:tid 43817] [client 172.237.109.114:14933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amun5oa8U9lZpWaWlJJe0QAAADE"]
[Thu Jul 30 14:37:10.878339 2026] [security2:error] [pid 43637:tid 43828] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amun5oa8U9lZpWaWlJJe2gAAADw"]
[Thu Jul 30 14:37:11.727675 2026] [security2:error] [pid 43637:tid 43863] [client 201.93.23.219:55025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.23.93.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abudhabicarrecoveryllc.site"] [uri "/xmlrpc.php"] [unique_id "amun54a8U9lZpWaWlJJe-AAAAF8"]
[Thu Jul 30 14:37:11.728026 2026] [security2:error] [pid 43637:tid 43863] [client 201.93.23.219:55025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abudhabicarrecoveryllc.site"] [uri "/xmlrpc.php"] [unique_id "amun54a8U9lZpWaWlJJe-AAAAF8"]
[Thu Jul 30 14:37:12.031341 2026] [security2:error] [pid 43637:tid 43850] [client 52.238.199.152:16293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-seo.php"] [unique_id "amun6Ia8U9lZpWaWlJJfAAAAAFI"]
[Thu Jul 30 14:37:12.061190 2026] [security2:error] [pid 43637:tid 43860] [client 152.32.142.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gas.djb.temporary.site"] [uri "/index.php"] [unique_id "amun54a8U9lZpWaWlJJe_gAAAFw"]
[Thu Jul 30 14:37:12.510286 2026] [security2:error] [pid 43637:tid 43668] [remote 57.141.0.39:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/66784244892/feed/rss2/"] [unique_id "amun6Ia8U9lZpWaWlJJfDQAAPx4"]
[Thu Jul 30 14:37:12.677429 2026] [security2:error] [pid 43637:tid 43776] [client 177.6.106.101:54453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun6Ia8U9lZpWaWlJJfEAAAAAg"]
[Thu Jul 30 14:37:12.680749 2026] [security2:error] [pid 43637:tid 43776] [client 177.6.106.101:54453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun6Ia8U9lZpWaWlJJfEAAAAAg"]
[Thu Jul 30 14:37:12.753565 2026] [security2:error] [pid 43637:tid 43790] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amun6Ia8U9lZpWaWlJJfFAAAABY"]
[Thu Jul 30 14:37:13.195429 2026] [security2:error] [pid 43637:tid 43798] [client 2.58.56.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.56.58.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tranquilrootsisb.space"] [uri "/xmlrpc.php"] [unique_id "amun6Ia8U9lZpWaWlJJfGgAAAB4"]
[Thu Jul 30 14:37:13.632786 2026] [security2:error] [pid 43637:tid 43859] [client 172.237.109.114:47734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amun6Ya8U9lZpWaWlJJfGwAAAFs"]
[Thu Jul 30 14:37:13.757505 2026] [security2:error] [pid 43637:tid 43870] [client 52.238.199.152:52484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/gebase.php69"] [unique_id "amun6Ya8U9lZpWaWlJJfKAAAAGY"]
[Thu Jul 30 14:37:13.912191 2026] [security2:error] [pid 43637:tid 43863] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amun6Ya8U9lZpWaWlJJfMAAAAF8"]
[Thu Jul 30 14:37:14.100514 2026] [security2:error] [pid 43637:tid 43895] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amun6oa8U9lZpWaWlJJfMQAAAH8"]
[Thu Jul 30 14:37:14.450202 2026] [security2:error] [pid 43637:tid 43807] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amun6oa8U9lZpWaWlJJfPAAAACc"]
[Thu Jul 30 14:37:14.517050 2026] [security2:error] [pid 43637:tid 43881] [client 43.172.195.204:58094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/29/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/"] [unique_id "amun6oa8U9lZpWaWlJJfMgAAAHE"]
[Thu Jul 30 14:37:14.832843 2026] [security2:error] [pid 43637:tid 43808] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amun6oa8U9lZpWaWlJJfQgAAACg"]
[Thu Jul 30 14:37:15.027271 2026] [security2:error] [pid 43637:tid 43802] [client 180.243.59.178:60605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun64a8U9lZpWaWlJJfSgAAACI"]
[Thu Jul 30 14:37:15.027394 2026] [security2:error] [pid 43637:tid 43802] [client 180.243.59.178:60605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun64a8U9lZpWaWlJJfSgAAACI"]
[Thu Jul 30 14:37:15.174519 2026] [security2:error] [pid 43637:tid 43795] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amun64a8U9lZpWaWlJJfTQAAABs"]
[Thu Jul 30 14:37:15.185812 2026] [core:notice] [pid 43637:tid 43823] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:15.192096 2026] [security2:error] [pid 43637:tid 43823] [client 43.172.197.58:49728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/29/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/"] [unique_id "amun64a8U9lZpWaWlJJfTgAAADc"], referer: https://carnetdeshopping.com/index.php/2012/07/29/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/?replytocom=618
[Thu Jul 30 14:37:15.517549 2026] [security2:error] [pid 43637:tid 43847] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amun64a8U9lZpWaWlJJfWgAAAE8"]
[Thu Jul 30 14:37:15.871719 2026] [security2:error] [pid 43637:tid 43858] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amun64a8U9lZpWaWlJJfZQAAAFo"]
[Thu Jul 30 14:37:16.220842 2026] [security2:error] [pid 43637:tid 43840] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amun7Ia8U9lZpWaWlJJfbAAAAEg"]
[Thu Jul 30 14:37:16.508114 2026] [core:notice] [pid 43637:tid 43895] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:16.565162 2026] [security2:error] [pid 43637:tid 43833] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amun7Ia8U9lZpWaWlJJfeAAAAEE"]
[Thu Jul 30 14:37:16.908636 2026] [security2:error] [pid 43637:tid 43800] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amun7Ia8U9lZpWaWlJJffwAAACA"]
[Thu Jul 30 14:37:17.184417 2026] [security2:error] [pid 43637:tid 43809] [client 116.179.37.224:61500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "online-hope.com"] [uri "/wp-content/plugins/litespeed-cache/guest.vary.php"] [unique_id "amun7Ya8U9lZpWaWlJJfhwAAACk"], referer: https://online-hope.com/
[Thu Jul 30 14:37:17.204116 2026] [core:notice] [pid 43637:tid 43813] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:17.219429 2026] [security2:error] [pid 43637:tid 43796] [client 52.238.199.152:41963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/config.php"] [unique_id "amun7Ya8U9lZpWaWlJJfiQAAABw"]
[Thu Jul 30 14:37:17.251068 2026] [security2:error] [pid 43637:tid 43818] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amun7Ya8U9lZpWaWlJJfigAAADI"]
[Thu Jul 30 14:37:17.625503 2026] [security2:error] [pid 43637:tid 43865] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amun7Ya8U9lZpWaWlJJfmAAAAGE"]
[Thu Jul 30 14:37:17.978493 2026] [security2:error] [pid 43637:tid 43826] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amun7Ya8U9lZpWaWlJJfoQAAADo"]
[Thu Jul 30 14:37:18.102231 2026] [security2:error] [pid 43637:tid 43872] [client 52.238.199.152:38103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ws.php"] [unique_id "amun7oa8U9lZpWaWlJJfpQAAAGg"]
[Thu Jul 30 14:37:18.371860 2026] [security2:error] [pid 43637:tid 43864] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amun7oa8U9lZpWaWlJJfpgAAAGA"]
[Thu Jul 30 14:37:18.726885 2026] [security2:error] [pid 43637:tid 43867] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amun7oa8U9lZpWaWlJJfsAAAAGM"]
[Thu Jul 30 14:37:19.053762 2026] [core:notice] [pid 43637:tid 43780] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:19.134341 2026] [security2:error] [pid 43637:tid 43808] [client 2.58.56.101:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tranquilrootsisb.space"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amun74a8U9lZpWaWlJJfvgAAACg"]
[Thu Jul 30 14:37:19.421224 2026] [security2:error] [pid 43637:tid 43806] [client 189.156.226.90:27366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amun74a8U9lZpWaWlJJfwAAAACY"]
[Thu Jul 30 14:37:19.421350 2026] [security2:error] [pid 43637:tid 43806] [client 189.156.226.90:27366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amun74a8U9lZpWaWlJJfwAAAACY"]
[Thu Jul 30 14:37:19.883078 2026] [security2:error] [pid 43637:tid 43836] [client 51.77.211.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amun74a8U9lZpWaWlJJf0AAAAEQ"]
[Thu Jul 30 14:37:20.358595 2026] [security2:error] [pid 43637:tid 43877] [client 57.129.135.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amun8Ia8U9lZpWaWlJJf5gAAAG0"]
[Thu Jul 30 14:37:20.707002 2026] [security2:error] [pid 43637:tid 43861] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amun8Ia8U9lZpWaWlJJf2gAAAF0"]
[Thu Jul 30 14:37:21.429295 2026] [security2:error] [pid 43637:tid 43874] [client 185.191.171.7:64452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/11/senado-aprova-aumento-de-gastos-com-publicidade-de-governos/"] [unique_id "amun8Ya8U9lZpWaWlJJf_gAAAGo"]
[Thu Jul 30 14:37:21.429460 2026] [security2:error] [pid 43637:tid 43874] [client 185.191.171.7:64452] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/11/senado-aprova-aumento-de-gastos-com-publicidade-de-governos/"] [unique_id "amun8Ya8U9lZpWaWlJJf_gAAAGo"]
[Thu Jul 30 14:37:21.440466 2026] [security2:error] [pid 43637:tid 43866] [client 52.238.199.152:38090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/admin/function.php"] [unique_id "amun8Ya8U9lZpWaWlJJf_wAAAGI"]
[Thu Jul 30 14:37:21.554183 2026] [security2:error] [pid 43637:tid 43892] [client 172.237.109.114:3605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amun8Ya8U9lZpWaWlJJf9gAAAHw"]
[Thu Jul 30 14:37:21.765007 2026] [security2:error] [pid 43637:tid 43792] [client 152.32.142.138:54338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gas.djb.temporary.site"] [uri "/wp-content/plugins/wp-plugin-hostgator/readme.txt"] [unique_id "amun8Ya8U9lZpWaWlJJgCQAAABg"]
[Thu Jul 30 14:37:22.603920 2026] [security2:error] [pid 43637:tid 43847] [client 184.75.221.59:45936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amun8oa8U9lZpWaWlJJgFgAAAE8"]
[Thu Jul 30 14:37:22.604050 2026] [security2:error] [pid 43637:tid 43847] [client 184.75.221.59:45936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amun8oa8U9lZpWaWlJJgFgAAAE8"]
[Thu Jul 30 14:37:23.207517 2026] [security2:error] [pid 43637:tid 43828] [client 52.238.199.152:52527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "amun84a8U9lZpWaWlJJgIwAAADw"]
[Thu Jul 30 14:37:23.269554 2026] [security2:error] [pid 43637:tid 43843] [client 177.6.106.101:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun84a8U9lZpWaWlJJgJwAAAEs"]
[Thu Jul 30 14:37:23.269695 2026] [security2:error] [pid 43637:tid 43843] [client 177.6.106.101:54916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun84a8U9lZpWaWlJJgJwAAAEs"]
[Thu Jul 30 14:37:23.640374 2026] [security2:error] [pid 43637:tid 43889] [client 141.95.54.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amun84a8U9lZpWaWlJJgMAAAAHk"]
[Thu Jul 30 14:37:23.829837 2026] [core:notice] [pid 43637:tid 43891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:23.920148 2026] [security2:error] [pid 43637:tid 43840] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amun84a8U9lZpWaWlJJgLQAAAEg"]
[Thu Jul 30 14:37:24.436207 2026] [security2:error] [pid 43637:tid 43892] [client 145.239.81.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amun9Ia8U9lZpWaWlJJgRQAAAHw"]
[Thu Jul 30 14:37:24.925442 2026] [security2:error] [pid 43637:tid 43860] [client 43.173.181.20:57016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/jibm/issue/view/405"] [unique_id "amun9Ia8U9lZpWaWlJJgSgAAAFw"]
[Thu Jul 30 14:37:25.715427 2026] [security2:error] [pid 43637:tid 43803] [client 52.238.199.152:52502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/themes/about.php"] [unique_id "amun9Ya8U9lZpWaWlJJgZgAAACM"]
[Thu Jul 30 14:37:25.762850 2026] [core:notice] [pid 43637:tid 43887] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:25.993334 2026] [security2:error] [pid 43637:tid 43810] [client 172.237.109.114:25764] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amun9Ya8U9lZpWaWlJJgcQAAACo"]
[Thu Jul 30 14:37:26.494798 2026] [core:notice] [pid 43637:tid 43875] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:26.589047 2026] [security2:error] [pid 43637:tid 43819] [client 180.243.59.178:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun9oa8U9lZpWaWlJJgfQAAADM"]
[Thu Jul 30 14:37:26.589212 2026] [security2:error] [pid 43637:tid 43819] [client 180.243.59.178:61185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun9oa8U9lZpWaWlJJgfQAAADM"]
[Thu Jul 30 14:37:26.767801 2026] [security2:error] [pid 43637:tid 43840] [client 52.238.199.152:16461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amun9oa8U9lZpWaWlJJggAAAAEg"]
[Thu Jul 30 14:37:26.927446 2026] [core:notice] [pid 43637:tid 43642] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:27.224249 2026] [core:notice] [pid 43637:tid 43652] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:27.600510 2026] [proxy:error] [pid 43637:tid 43795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:37:27.600594 2026] [proxy_http:error] [pid 43637:tid 43795] [client 143.244.57.82:34402] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:37:27.601453 2026] [proxy:error] [pid 43637:tid 43795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:37:27.601513 2026] [proxy_http:error] [pid 43637:tid 43795] [client 143.244.57.82:34402] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:37:27.889386 2026] [proxy:error] [pid 43637:tid 43824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:37:27.889483 2026] [proxy_http:error] [pid 43637:tid 43824] [client 143.244.57.82:34404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:37:27.890349 2026] [proxy:error] [pid 43637:tid 43824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:37:27.890413 2026] [proxy_http:error] [pid 43637:tid 43824] [client 143.244.57.82:34404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:37:28.154722 2026] [security2:error] [pid 43637:tid 43790] [client 52.238.199.152:45377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/uploads/2024/index.php"] [unique_id "amun-Ia8U9lZpWaWlJJguQAAABY"]
[Thu Jul 30 14:37:28.201550 2026] [security2:error] [pid 43637:tid 43887] [client 143.244.57.82:34410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amun-Ia8U9lZpWaWlJJguwAAAHc"]
[Thu Jul 30 14:37:28.475586 2026] [proxy:error] [pid 43637:tid 43841] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:37:28.475654 2026] [proxy_http:error] [pid 43637:tid 43841] [client 143.244.57.82:34414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:37:28.476233 2026] [proxy:error] [pid 43637:tid 43841] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:37:28.476290 2026] [proxy_http:error] [pid 43637:tid 43841] [client 143.244.57.82:34414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:37:28.670058 2026] [security2:error] [pid 43637:tid 43858] [client 20.40.58.237:56686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amun-Ia8U9lZpWaWlJJg8wAAAFo"]
[Thu Jul 30 14:37:28.764693 2026] [security2:error] [pid 43637:tid 43875] [client 143.244.57.82:34424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amun-Ia8U9lZpWaWlJJg9AAAAGs"]
[Thu Jul 30 14:37:29.037822 2026] [security2:error] [pid 43637:tid 43874] [client 143.244.57.82:34438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amun-Ya8U9lZpWaWlJJg-wAAAGo"]
[Thu Jul 30 14:37:29.180993 2026] [security2:error] [pid 43637:tid 43801] [client 52.238.199.152:16346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/cong.php"] [unique_id "amun-Ya8U9lZpWaWlJJg_wAAACE"]
[Thu Jul 30 14:37:29.312357 2026] [security2:error] [pid 43637:tid 43768] [client 143.244.57.82:34454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amun-Ya8U9lZpWaWlJJhAAAAAAA"]
[Thu Jul 30 14:37:29.400752 2026] [security2:error] [pid 43637:tid 43812] [client 20.40.58.237:56687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amun-Ya8U9lZpWaWlJJhAQAAACw"]
[Thu Jul 30 14:37:29.625494 2026] [security2:error] [pid 43637:tid 43786] [client 143.244.57.82:34456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amun-Ya8U9lZpWaWlJJhCQAAABI"]
[Thu Jul 30 14:37:29.900438 2026] [security2:error] [pid 43637:tid 43776] [client 143.244.57.82:34468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amun-Ya8U9lZpWaWlJJhGAAAAAg"]
[Thu Jul 30 14:37:30.040627 2026] [security2:error] [pid 43637:tid 43814] [client 189.156.226.90:27646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amun-oa8U9lZpWaWlJJhHAAAAC4"]
[Thu Jul 30 14:37:30.040761 2026] [security2:error] [pid 43637:tid 43814] [client 189.156.226.90:27646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amun-oa8U9lZpWaWlJJhHAAAAC4"]
[Thu Jul 30 14:37:30.214934 2026] [security2:error] [pid 43637:tid 43800] [client 143.244.57.82:34484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amun-oa8U9lZpWaWlJJhbQAAACA"]
[Thu Jul 30 14:37:30.496989 2026] [security2:error] [pid 43637:tid 43894] [client 143.244.57.82:34496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amun-oa8U9lZpWaWlJJhcQAAAH4"]
[Thu Jul 30 14:37:30.517186 2026] [security2:error] [pid 43637:tid 43834] [client 52.238.199.152:38115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/languages/about.php"] [unique_id "amun-oa8U9lZpWaWlJJhdAAAAEI"]
[Thu Jul 30 14:37:30.777184 2026] [security2:error] [pid 43637:tid 43810] [client 143.244.57.82:34498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amun-oa8U9lZpWaWlJJhhAAAACo"]
[Thu Jul 30 14:37:31.034322 2026] [security2:error] [pid 43637:tid 43862] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amun-oa8U9lZpWaWlJJhcAAAAF4"]
[Thu Jul 30 14:37:31.053137 2026] [security2:error] [pid 43637:tid 43888] [client 143.244.57.82:34508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amun-4a8U9lZpWaWlJJhhQAAAHg"]
[Thu Jul 30 14:37:31.338470 2026] [security2:error] [pid 43637:tid 43851] [client 143.244.57.82:34518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amun-4a8U9lZpWaWlJJhkAAAAFM"]
[Thu Jul 30 14:37:31.611842 2026] [security2:error] [pid 43637:tid 43840] [client 143.244.57.82:34520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amun-4a8U9lZpWaWlJJhlAAAAEg"]
[Thu Jul 30 14:37:31.890082 2026] [security2:error] [pid 43637:tid 43804] [client 143.244.57.82:34526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amun-4a8U9lZpWaWlJJhngAAACQ"]
[Thu Jul 30 14:37:31.910486 2026] [security2:error] [pid 43637:tid 43884] [client 52.238.199.152:3909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/edit.php"] [unique_id "amun-4a8U9lZpWaWlJJhnwAAAHQ"]
[Thu Jul 30 14:37:32.175933 2026] [security2:error] [pid 43637:tid 43796] [client 143.244.57.82:34532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amun_Ia8U9lZpWaWlJJhowAAABw"]
[Thu Jul 30 14:37:32.454637 2026] [security2:error] [pid 43637:tid 43831] [client 143.244.57.82:34536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nco.zzt.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amun_Ia8U9lZpWaWlJJhrgAAAD8"]
[Thu Jul 30 14:37:32.595144 2026] [security2:error] [pid 43637:tid 43800] [client 46.183.217.105:44586] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amun_Ia8U9lZpWaWlJJhsAAAACA"]
[Thu Jul 30 14:37:32.595268 2026] [security2:error] [pid 43637:tid 43800] [client 46.183.217.105:44586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amun_Ia8U9lZpWaWlJJhsAAAACA"]
[Thu Jul 30 14:37:33.037769 2026] [security2:error] [pid 43637:tid 43708] [remote 2a03:2880:f800:21:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amun_Ia8U9lZpWaWlJJhrQAAC0Y"]
[Thu Jul 30 14:37:33.873392 2026] [security2:error] [pid 43637:tid 43805] [client 177.6.106.101:55427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun_Ya8U9lZpWaWlJJhzgAAACU"]
[Thu Jul 30 14:37:33.873490 2026] [security2:error] [pid 43637:tid 43805] [client 177.6.106.101:55427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amun_Ya8U9lZpWaWlJJhzgAAACU"]
[Thu Jul 30 14:37:34.426101 2026] [core:notice] [pid 43637:tid 43724] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:34.696722 2026] [core:notice] [pid 43637:tid 43725] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:35.012281 2026] [security2:error] [pid 43637:tid 43884] [client 68.221.186.136:3930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/geju.php"] [unique_id "amun_4a8U9lZpWaWlJJh5QAAAHQ"]
[Thu Jul 30 14:37:36.144823 2026] [security2:error] [pid 43637:tid 43893] [client 52.238.199.152:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/about/function.php"] [unique_id "amuoAIa8U9lZpWaWlJJh_AAAAH0"]
[Thu Jul 30 14:37:36.177654 2026] [security2:error] [pid 43637:tid 43827] [client 180.243.59.178:61694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoAIa8U9lZpWaWlJJh_QAAADs"]
[Thu Jul 30 14:37:36.177845 2026] [security2:error] [pid 43637:tid 43827] [client 180.243.59.178:61694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoAIa8U9lZpWaWlJJh_QAAADs"]
[Thu Jul 30 14:37:36.950782 2026] [security2:error] [pid 43637:tid 43761] [remote 52.167.144.219:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/26"] [unique_id "amuoAIa8U9lZpWaWlJJiDQAAQHo"]
[Thu Jul 30 14:37:37.297115 2026] [security2:error] [pid 43637:tid 43849] [client 52.238.199.152:41953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/simple/function.php"] [unique_id "amuoAYa8U9lZpWaWlJJiEQAAAFE"]
[Thu Jul 30 14:37:38.361706 2026] [core:notice] [pid 43637:tid 43848] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:38.519875 2026] [security2:error] [pid 43637:tid 43804] [client 52.238.199.152:45379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/mah/function.php"] [unique_id "amuoAoa8U9lZpWaWlJJiOQAAACQ"]
[Thu Jul 30 14:37:38.595692 2026] [security2:error] [pid 43637:tid 43792] [client 193.47.62.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.embassyofitalyislamabad.vip"] [uri "/index.php"] [unique_id "amuoAYa8U9lZpWaWlJJiIwAAABg"]
[Thu Jul 30 14:37:39.261872 2026] [security2:error] [pid 43637:tid 43663] [remote 40.77.167.24:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/3635"] [unique_id "amuoA4a8U9lZpWaWlJJiSgAAShk"]
[Thu Jul 30 14:37:39.278856 2026] [security2:error] [pid 43637:tid 43845] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoAoa8U9lZpWaWlJJiPwAAAE0"]
[Thu Jul 30 14:37:39.577774 2026] [security2:error] [pid 43637:tid 43893] [client 172.237.109.114:48806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuoAoa8U9lZpWaWlJJiQwAAAH0"], referer: http://alseermarine.com:80
[Thu Jul 30 14:37:40.227190 2026] [security2:error] [pid 43637:tid 43748] [remote 57.141.0.45:34574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amuoBIa8U9lZpWaWlJJibAAAAG4"]
[Thu Jul 30 14:37:40.264033 2026] [security2:error] [pid 43637:tid 43888] [client 52.238.199.152:38093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/go.php"] [unique_id "amuoBIa8U9lZpWaWlJJibQAAAHg"]
[Thu Jul 30 14:37:40.556627 2026] [security2:error] [pid 43637:tid 43813] [client 189.156.226.90:26979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoBIa8U9lZpWaWlJJidAAAAC0"]
[Thu Jul 30 14:37:40.556742 2026] [security2:error] [pid 43637:tid 43813] [client 189.156.226.90:26979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoBIa8U9lZpWaWlJJidAAAAC0"]
[Thu Jul 30 14:37:40.636584 2026] [security2:error] [pid 43637:tid 43877] [client 184.75.221.59:45116] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuoBIa8U9lZpWaWlJJidQAAAG0"]
[Thu Jul 30 14:37:40.636719 2026] [security2:error] [pid 43637:tid 43877] [client 184.75.221.59:45116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuoBIa8U9lZpWaWlJJidQAAAG0"]
[Thu Jul 30 14:37:41.128152 2026] [security2:error] [pid 43637:tid 43762] [remote 57.141.0.46:33456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5351135361/feed/rss2/"] [unique_id "amuoBYa8U9lZpWaWlJJigAAAK3s"]
[Thu Jul 30 14:37:41.574782 2026] [security2:error] [pid 43637:tid 43801] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoBIa8U9lZpWaWlJJifQAAACE"]
[Thu Jul 30 14:37:42.107875 2026] [security2:error] [pid 43637:tid 43861] [client 52.238.199.152:3925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/buy.php"] [unique_id "amuoBoa8U9lZpWaWlJJimwAAAF0"]
[Thu Jul 30 14:37:42.820229 2026] [security2:error] [pid 43637:tid 43821] [client 78.47.173.76:64134] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuoBoa8U9lZpWaWlJJiuAAAADU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:37:42.849100 2026] [security2:error] [pid 43637:tid 43736] [remote 57.141.0.20:60514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuoBoa8U9lZpWaWlJJiuQAAf2I"]
[Thu Jul 30 14:37:43.053050 2026] [core:error] [pid 43637:tid 43686] [remote 74.7.228.5:38118] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:37:43.053070 2026] [core:error] [pid 43637:tid 43686] [remote 74.7.228.5:38118] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:37:43.053237 2026] [security2:error] [pid 43637:tid 43823] [client 74.7.228.5:38118] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.mahsudtransportandbuildingdemolition.business"] [uri "/index.php"] [unique_id "amuoB4a8U9lZpWaWlJJiugAANzA"]
[Thu Jul 30 14:37:43.298595 2026] [core:notice] [pid 43637:tid 43860] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:43.303280 2026] [security2:error] [pid 43637:tid 43860] [client 78.47.173.76:64142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuoB4a8U9lZpWaWlJJiwgAAAFw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:37:43.706755 2026] [security2:error] [pid 43637:tid 43831] [client 78.47.173.76:64148] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuoB4a8U9lZpWaWlJJiygAAAD8"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:37:44.139316 2026] [security2:error] [pid 43637:tid 43883] [client 68.221.186.136:3945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuoCIa8U9lZpWaWlJJi1wAAAHM"]
[Thu Jul 30 14:37:44.528341 2026] [security2:error] [pid 43637:tid 43856] [client 177.6.106.101:56008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoCIa8U9lZpWaWlJJi4gAAAFg"]
[Thu Jul 30 14:37:44.528485 2026] [security2:error] [pid 43637:tid 43856] [client 177.6.106.101:56008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoCIa8U9lZpWaWlJJi4gAAAFg"]
[Thu Jul 30 14:37:44.782813 2026] [core:error] [pid 43637:tid 43812] [client 167.71.12.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:37:44.782835 2026] [core:error] [pid 43637:tid 43812] [client 167.71.12.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:37:45.248099 2026] [security2:error] [pid 43637:tid 43893] [client 68.221.186.136:3963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp.php"] [unique_id "amuoCYa8U9lZpWaWlJJi9gAAAH0"]
[Thu Jul 30 14:37:45.467802 2026] [security2:error] [pid 43637:tid 43776] [client 52.238.199.152:45399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/themes/astra/inc/ki1k.php"] [unique_id "amuoCYa8U9lZpWaWlJJi_QAAAAg"]
[Thu Jul 30 14:37:45.619807 2026] [core:notice] [pid 43637:tid 43844] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:46.742992 2026] [security2:error] [pid 43637:tid 43841] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoCoa8U9lZpWaWlJJjCgAAAEk"]
[Thu Jul 30 14:37:46.782161 2026] [security2:error] [pid 43637:tid 43813] [client 180.243.59.178:62234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoCoa8U9lZpWaWlJJjFwAAAC0"]
[Thu Jul 30 14:37:46.782268 2026] [security2:error] [pid 43637:tid 43813] [client 180.243.59.178:62234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoCoa8U9lZpWaWlJJjFwAAAC0"]
[Thu Jul 30 14:37:46.792666 2026] [security2:error] [pid 43637:tid 43843] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoCoa8U9lZpWaWlJJjDQAAAEs"]
[Thu Jul 30 14:37:47.882876 2026] [core:error] [pid 43637:tid 43796] [client 167.71.12.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.club4.au/
[Thu Jul 30 14:37:47.882899 2026] [core:error] [pid 43637:tid 43796] [client 167.71.12.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.club4.au/
[Thu Jul 30 14:37:48.151940 2026] [security2:error] [pid 43637:tid 43677] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.applinex.pro"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuoDIa8U9lZpWaWlJJjOAAACSc"]
[Thu Jul 30 14:37:48.474784 2026] [security2:error] [pid 43637:tid 43838] [client 68.221.186.136:3967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/aaa.php"] [unique_id "amuoDIa8U9lZpWaWlJJjPgAAAEY"]
[Thu Jul 30 14:37:48.504875 2026] [security2:error] [pid 43637:tid 43787] [client 172.237.109.114:11760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuoDIa8U9lZpWaWlJJjNgAAABM"]
[Thu Jul 30 14:37:48.896747 2026] [security2:error] [pid 43637:tid 43882] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.applinex.pro"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuoDIa8U9lZpWaWlJJjSgAAAHI"]
[Thu Jul 30 14:37:49.477037 2026] [security2:error] [pid 43637:tid 43843] [client 68.221.186.136:3293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/hoot.php"] [unique_id "amuoDYa8U9lZpWaWlJJjVAAAAEs"]
[Thu Jul 30 14:37:49.892275 2026] [security2:error] [pid 43637:tid 43732] [remote 57.141.0.12:20530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6626375131/feed/rss2/"] [unique_id "amuoDYa8U9lZpWaWlJJjYAAAU14"]
[Thu Jul 30 14:37:50.228672 2026] [security2:error] [pid 43637:tid 43783] [client 68.221.186.136:3909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/about.php"] [unique_id "amuoDoa8U9lZpWaWlJJjbQAAAA8"]
[Thu Jul 30 14:37:50.693870 2026] [security2:error] [pid 43637:tid 43638] [remote 103.74.116.239:59202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuoDoa8U9lZpWaWlJJjdgAAfwA"]
[Thu Jul 30 14:37:50.740132 2026] [proxy:error] [pid 43637:tid 43765] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:37:50.740189 2026] [proxy_http:error] [pid 43637:tid 43765] [remote 74.7.241.159:58718] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:37:50.740860 2026] [proxy:error] [pid 43637:tid 43765] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:37:50.740904 2026] [proxy_http:error] [pid 43637:tid 43765] [remote 74.7.241.159:58718] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:37:50.798594 2026] [security2:error] [pid 43637:tid 43807] [client 52.238.199.152:41923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wq.php7"] [unique_id "amuoDoa8U9lZpWaWlJJjfgAAACc"]
[Thu Jul 30 14:37:51.125149 2026] [security2:error] [pid 43637:tid 43811] [client 189.156.226.90:27141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoD4a8U9lZpWaWlJJjggAAACs"]
[Thu Jul 30 14:37:51.125272 2026] [security2:error] [pid 43637:tid 43811] [client 189.156.226.90:27141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoD4a8U9lZpWaWlJJjggAAACs"]
[Thu Jul 30 14:37:51.864825 2026] [security2:error] [pid 43637:tid 43810] [client 52.238.199.152:38105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/forum.php"] [unique_id "amuoD4a8U9lZpWaWlJJjkwAAACo"]
[Thu Jul 30 14:37:52.358222 2026] [security2:error] [pid 43637:tid 43885] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuoD4a8U9lZpWaWlJJjjwAAdXI"]
[Thu Jul 30 14:37:53.678553 2026] [security2:error] [pid 43637:tid 43832] [client 52.238.199.152:45414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/5index.php"] [unique_id "amuoEYa8U9lZpWaWlJJjtAAAAEA"]
[Thu Jul 30 14:37:53.997219 2026] [core:notice] [pid 43637:tid 43868] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:54.193585 2026] [security2:error] [pid 43637:tid 43838] [client 114.119.154.161:29679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "asian-connect.com"] [uri "/robots.txt"] [unique_id "amuoEoa8U9lZpWaWlJJjvwAAAEY"], referer: http://asian-connect.com/robots.txt
[Thu Jul 30 14:37:54.945391 2026] [security2:error] [pid 43637:tid 43792] [client 52.238.199.152:38086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/cookie.php"] [unique_id "amuoEoa8U9lZpWaWlJJj0gAAABg"]
[Thu Jul 30 14:37:55.053025 2026] [security2:error] [pid 43637:tid 43844] [client 177.6.106.101:56637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoE4a8U9lZpWaWlJJj1gAAAEw"]
[Thu Jul 30 14:37:55.053191 2026] [security2:error] [pid 43637:tid 43844] [client 177.6.106.101:56637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoE4a8U9lZpWaWlJJj1gAAAEw"]
[Thu Jul 30 14:37:56.488516 2026] [core:notice] [pid 43637:tid 43870] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:37:56.549806 2026] [security2:error] [pid 43637:tid 43873] [client 68.221.186.136:3279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/admin.php"] [unique_id "amuoFIa8U9lZpWaWlJJj_AAAAGk"]
[Thu Jul 30 14:37:56.891553 2026] [security2:error] [pid 43637:tid 43798] [client 180.243.59.178:62749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoFIa8U9lZpWaWlJJkAAAAAB4"]
[Thu Jul 30 14:37:56.891697 2026] [security2:error] [pid 43637:tid 43798] [client 180.243.59.178:62749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoFIa8U9lZpWaWlJJkAAAAAB4"]
[Thu Jul 30 14:37:57.081377 2026] [security2:error] [pid 43637:tid 43807] [client 20.226.5.174:13441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/contents.php"] [unique_id "amuoFYa8U9lZpWaWlJJkBwAAACc"]
[Thu Jul 30 14:37:57.147313 2026] [security2:error] [pid 43637:tid 43894] [client 68.221.186.136:3956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuoFYa8U9lZpWaWlJJkCwAAAH4"]
[Thu Jul 30 14:37:57.534691 2026] [security2:error] [pid 43637:tid 43769] [client 52.238.199.152:38107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/edit-form.php"] [unique_id "amuoFYa8U9lZpWaWlJJkEAAAAAE"]
[Thu Jul 30 14:37:57.780132 2026] [security2:error] [pid 43637:tid 43844] [client 102.209.254.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuoFYa8U9lZpWaWlJJkGQAAAEw"], referer: https://cnpinyin.com
[Thu Jul 30 14:37:57.926798 2026] [security2:error] [pid 43637:tid 43859] [client 68.221.186.136:3913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuoFYa8U9lZpWaWlJJkHQAAAFs"]
[Thu Jul 30 14:37:58.085895 2026] [security2:error] [pid 43637:tid 43843] [client 20.226.5.174:13450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/contentwp.php"] [unique_id "amuoFoa8U9lZpWaWlJJkJAAAAEs"]
[Thu Jul 30 14:37:58.332752 2026] [core:error] [pid 43637:tid 43872] [client 184.154.139.59:39006] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=alfalasifurnituremoversllc.com&yahoo.com
[Thu Jul 30 14:37:58.332776 2026] [core:error] [pid 43637:tid 43872] [client 184.154.139.59:39006] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.google.com/url?url=alfalasifurnituremoversllc.com&yahoo.com
[Thu Jul 30 14:37:58.808333 2026] [core:error] [pid 43637:tid 43846] [client 74.7.228.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:37:58.808354 2026] [core:error] [pid 43637:tid 43846] [client 74.7.228.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:37:58.808478 2026] [security2:error] [pid 43637:tid 43846] [client 74.7.228.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.ltr.tqa.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuoFoa8U9lZpWaWlJJkNQAAAE4"]
[Thu Jul 30 14:37:58.809793 2026] [security2:error] [pid 43637:tid 43799] [client 74.7.228.13:40918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.ltr.tqa.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuoFoa8U9lZpWaWlJJkMwAAHzA"]
[Thu Jul 30 14:37:59.079219 2026] [security2:error] [pid 43637:tid 43780] [client 68.221.186.136:3288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuoF4a8U9lZpWaWlJJkOQAAAAw"]
[Thu Jul 30 14:37:59.154281 2026] [security2:error] [pid 43637:tid 43892] [client 52.238.199.152:45422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/aleXus.php"] [unique_id "amuoF4a8U9lZpWaWlJJkPQAAAHw"]
[Thu Jul 30 14:37:59.179166 2026] [security2:error] [pid 43637:tid 43829] [client 20.226.5.174:13464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/cookie.php"] [unique_id "amuoF4a8U9lZpWaWlJJkQQAAAD0"]
[Thu Jul 30 14:37:59.340598 2026] [security2:error] [pid 43637:tid 43855] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuoFoa8U9lZpWaWlJJkMgAAV2I"]
[Thu Jul 30 14:37:59.538677 2026] [security2:error] [pid 43637:tid 43838] [client 74.7.241.145:48588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.arabian-tours.com.khw.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuoF4a8U9lZpWaWlJJkRQAARkI"]
[Thu Jul 30 14:37:59.789151 2026] [security2:error] [pid 43637:tid 43853] [client 68.221.186.136:3294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuoF4a8U9lZpWaWlJJkTwAAAFU"]
[Thu Jul 30 14:38:00.344927 2026] [security2:error] [pid 43637:tid 43883] [client 52.238.199.152:17144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/user.php"] [unique_id "amuoGIa8U9lZpWaWlJJkXAAAAHM"]
[Thu Jul 30 14:38:00.363540 2026] [security2:error] [pid 43637:tid 43769] [client 20.226.5.174:13459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/cool.php"] [unique_id "amuoGIa8U9lZpWaWlJJkXQAAAAE"]
[Thu Jul 30 14:38:00.782233 2026] [security2:error] [pid 43637:tid 43891] [client 68.221.186.136:3958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuoGIa8U9lZpWaWlJJkZwAAAHs"]
[Thu Jul 30 14:38:01.028045 2026] [core:notice] [pid 43637:tid 43691] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:01.348794 2026] [security2:error] [pid 43637:tid 43881] [client 85.208.96.210:13508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/07/rego-barros-e-exonerado-do-cargo-de-porta-voz-da-presidencia/"] [unique_id "amuoGYa8U9lZpWaWlJJkcwAAAHE"]
[Thu Jul 30 14:38:01.348891 2026] [security2:error] [pid 43637:tid 43881] [client 85.208.96.210:13508] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/07/rego-barros-e-exonerado-do-cargo-de-porta-voz-da-presidencia/"] [unique_id "amuoGYa8U9lZpWaWlJJkcwAAAHE"]
[Thu Jul 30 14:38:01.454382 2026] [security2:error] [pid 43637:tid 43774] [client 52.238.199.152:45385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ab1ux1ft.php"] [unique_id "amuoGYa8U9lZpWaWlJJkdwAAAAY"]
[Thu Jul 30 14:38:01.458188 2026] [security2:error] [pid 43637:tid 43778] [client 20.226.5.174:13448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/core-plugin/include.php"] [unique_id "amuoGYa8U9lZpWaWlJJkeAAAAAo"]
[Thu Jul 30 14:38:01.527904 2026] [security2:error] [pid 43637:tid 43835] [client 102.78.230.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuoGYa8U9lZpWaWlJJkdgAAAEM"], referer: https://cnpinyin.com/learning-progress
[Thu Jul 30 14:38:01.664681 2026] [core:notice] [pid 43637:tid 43707] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:01.685702 2026] [security2:error] [pid 43637:tid 43780] [client 189.156.226.90:27651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoGYa8U9lZpWaWlJJkfwAAAAw"]
[Thu Jul 30 14:38:01.685844 2026] [security2:error] [pid 43637:tid 43780] [client 189.156.226.90:27651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoGYa8U9lZpWaWlJJkfwAAAAw"]
[Thu Jul 30 14:38:02.512036 2026] [security2:error] [pid 43637:tid 43854] [client 20.226.5.174:13453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/core-stab/index.php"] [unique_id "amuoGoa8U9lZpWaWlJJkkQAAAFY"]
[Thu Jul 30 14:38:02.789854 2026] [security2:error] [pid 43637:tid 43834] [client 52.238.199.152:41956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/home/function.php"] [unique_id "amuoGoa8U9lZpWaWlJJklQAAAEI"]
[Thu Jul 30 14:38:03.508128 2026] [security2:error] [pid 43637:tid 43850] [client 20.226.5.174:13457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/core.php"] [unique_id "amuoG4a8U9lZpWaWlJJkqwAAAFI"]
[Thu Jul 30 14:38:04.492390 2026] [security2:error] [pid 43637:tid 43791] [client 52.238.199.152:45378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-login.php"] [unique_id "amuoHIa8U9lZpWaWlJJkxwAAABc"]
[Thu Jul 30 14:38:04.572863 2026] [security2:error] [pid 43637:tid 43777] [client 20.226.5.174:13458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/core/include.php"] [unique_id "amuoHIa8U9lZpWaWlJJkyAAAAAk"]
[Thu Jul 30 14:38:04.631331 2026] [security2:error] [pid 43637:tid 43895] [client 68.221.186.136:3965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuoHIa8U9lZpWaWlJJkyQAAAH8"]
[Thu Jul 30 14:38:04.928481 2026] [security2:error] [pid 43637:tid 43785] [client 38.210.90.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuoHIa8U9lZpWaWlJJkzAAAABE"], referer: https://cnpinyin.com/learning-progress/
[Thu Jul 30 14:38:05.543999 2026] [security2:error] [pid 43637:tid 43850] [client 203.198.28.191:6073] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2011/11/new-york-empire-state-building_02-carnet-de-shopping.jpg"] [unique_id "amuoHYa8U9lZpWaWlJJk5wAAAFI"]
[Thu Jul 30 14:38:05.625920 2026] [security2:error] [pid 43637:tid 43873] [client 20.226.5.174:13456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/core885.php"] [unique_id "amuoHYa8U9lZpWaWlJJk6QAAAGk"]
[Thu Jul 30 14:38:05.703206 2026] [security2:error] [pid 43637:tid 43889] [client 177.6.106.101:57366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoHYa8U9lZpWaWlJJk6gAAAHk"]
[Thu Jul 30 14:38:05.703326 2026] [security2:error] [pid 43637:tid 43889] [client 177.6.106.101:57366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoHYa8U9lZpWaWlJJk6gAAAHk"]
[Thu Jul 30 14:38:05.894096 2026] [core:notice] [pid 43637:tid 43832] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:06.120418 2026] [security2:error] [pid 43637:tid 43880] [client 68.221.186.136:3937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuoHoa8U9lZpWaWlJJk9QAAAHA"]
[Thu Jul 30 14:38:06.244446 2026] [security2:error] [pid 43637:tid 43874] [client 52.238.199.152:16637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "amuoHoa8U9lZpWaWlJJk-QAAAGo"]
[Thu Jul 30 14:38:06.694437 2026] [security2:error] [pid 43637:tid 43771] [client 20.226.5.174:13470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/coreadmin.php"] [unique_id "amuoHoa8U9lZpWaWlJJlEwAAAAM"]
[Thu Jul 30 14:38:07.058167 2026] [security2:error] [pid 43637:tid 43770] [client 52.238.199.152:32985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp.php"] [unique_id "amuoH4a8U9lZpWaWlJJlHgAAAAI"]
[Thu Jul 30 14:38:07.163176 2026] [security2:error] [pid 43637:tid 43797] [client 68.221.186.136:3946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/content.php"] [unique_id "amuoH4a8U9lZpWaWlJJlIgAAAB0"]
[Thu Jul 30 14:38:07.527632 2026] [core:notice] [pid 43637:tid 43826] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:07.828503 2026] [security2:error] [pid 43637:tid 43835] [client 20.226.5.174:13442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/corealfa.php"] [unique_id "amuoH4a8U9lZpWaWlJJlNQAAAEM"]
[Thu Jul 30 14:38:08.373338 2026] [security2:error] [pid 43637:tid 43807] [client 68.221.186.136:3284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuoIIa8U9lZpWaWlJJlQAAAACc"]
[Thu Jul 30 14:38:08.587949 2026] [core:notice] [pid 43637:tid 43844] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:08.863458 2026] [security2:error] [pid 43637:tid 43805] [client 20.226.5.174:13468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/corebypass.php"] [unique_id "amuoIIa8U9lZpWaWlJJlTgAAACU"]
[Thu Jul 30 14:38:08.994428 2026] [core:notice] [pid 43637:tid 43876] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:09.122862 2026] [security2:error] [pid 43637:tid 43860] [client 52.238.199.152:38106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/Requests/library/about.php"] [unique_id "amuoIYa8U9lZpWaWlJJlUwAAAFw"]
[Thu Jul 30 14:38:09.163913 2026] [security2:error] [pid 43637:tid 43852] [client 180.243.59.178:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoIYa8U9lZpWaWlJJlWAAAAFQ"]
[Thu Jul 30 14:38:09.164054 2026] [security2:error] [pid 43637:tid 43852] [client 180.243.59.178:63397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoIYa8U9lZpWaWlJJlWAAAAFQ"]
[Thu Jul 30 14:38:09.194680 2026] [security2:error] [pid 43637:tid 43849] [client 68.221.186.136:4620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuoIYa8U9lZpWaWlJJlWQAAAFE"]
[Thu Jul 30 14:38:09.878217 2026] [security2:error] [pid 43637:tid 43823] [client 68.221.186.136:3942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuoIYa8U9lZpWaWlJJlZwAAADc"]
[Thu Jul 30 14:38:09.948418 2026] [security2:error] [pid 43637:tid 43871] [client 20.226.5.174:13467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/corek.php"] [unique_id "amuoIYa8U9lZpWaWlJJlaAAAAGc"]
[Thu Jul 30 14:38:10.084373 2026] [security2:error] [pid 43637:tid 43821] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samirkhalifa.net"] [uri "/wp-admin/install.php"] [unique_id "amuoIoa8U9lZpWaWlJJlaQAAADU"]
[Thu Jul 30 14:38:10.465107 2026] [security2:error] [pid 43637:tid 43824] [client 154.57.218.68:44043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuoH4a8U9lZpWaWlJJlNAAAOBs"], referer: https://www.urwru.club/emm-elevate/
[Thu Jul 30 14:38:10.798827 2026] [security2:error] [pid 43637:tid 43802] [client 68.221.186.136:4637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuoIoa8U9lZpWaWlJJlhAAAACI"]
[Thu Jul 30 14:38:10.956215 2026] [security2:error] [pid 43637:tid 43798] [client 20.226.5.174:13480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/corewp.php"] [unique_id "amuoIoa8U9lZpWaWlJJlhgAAAB4"]
[Thu Jul 30 14:38:11.466232 2026] [security2:error] [pid 43637:tid 43887] [client 68.221.186.136:3914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuoI4a8U9lZpWaWlJJllAAAAHc"]
[Thu Jul 30 14:38:12.019766 2026] [security2:error] [pid 43637:tid 43876] [client 20.226.5.174:13451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/cot.php"] [unique_id "amuoJIa8U9lZpWaWlJJlowAAAGw"]
[Thu Jul 30 14:38:12.142318 2026] [security2:error] [pid 43637:tid 43816] [client 68.221.186.136:4650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuoJIa8U9lZpWaWlJJlpQAAADA"]
[Thu Jul 30 14:38:12.274425 2026] [security2:error] [pid 43637:tid 43770] [client 189.156.226.90:26802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoJIa8U9lZpWaWlJJlrwAAAAI"]
[Thu Jul 30 14:38:12.274541 2026] [security2:error] [pid 43637:tid 43770] [client 189.156.226.90:26802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoJIa8U9lZpWaWlJJlrwAAAAI"]
[Thu Jul 30 14:38:12.397595 2026] [security2:error] [pid 43637:tid 43851] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuoI4a8U9lZpWaWlJJlmwAAUxI"]
[Thu Jul 30 14:38:12.712723 2026] [security2:error] [pid 43637:tid 43702] [remote 152.228.213.32:55728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-468361c2.glb.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuoJIa8U9lZpWaWlJJltgAAKkA"]
[Thu Jul 30 14:38:12.745893 2026] [security2:error] [pid 43637:tid 43695] [remote 57.141.0.69:57272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuoJIa8U9lZpWaWlJJltwAAeDk"]
[Thu Jul 30 14:38:13.019345 2026] [security2:error] [pid 43637:tid 43847] [client 20.226.5.174:13455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/cpanel.php"] [unique_id "amuoJYa8U9lZpWaWlJJlwQAAAE8"]
[Thu Jul 30 14:38:13.149302 2026] [security2:error] [pid 43637:tid 43838] [client 68.221.186.136:3934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuoJYa8U9lZpWaWlJJlwgAAAEY"]
[Thu Jul 30 14:38:13.649212 2026] [security2:error] [pid 43637:tid 43718] [remote 74.7.243.224:49732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amuoJYa8U9lZpWaWlJJlzAAAHlA"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:38:13.733481 2026] [security2:error] [pid 43637:tid 43777] [client 68.221.186.136:4613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuoJYa8U9lZpWaWlJJlzgAAAAk"]
[Thu Jul 30 14:38:13.913038 2026] [core:notice] [pid 43637:tid 43839] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:14.112216 2026] [security2:error] [pid 43637:tid 43864] [client 20.226.5.174:13452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/cpnbxgdm.php"] [unique_id "amuoJoa8U9lZpWaWlJJl8gAAAGA"]
[Thu Jul 30 14:38:14.364220 2026] [security2:error] [pid 43637:tid 43769] [client 20.104.18.253:9233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/docsbypass.php"] [unique_id "amuoJoa8U9lZpWaWlJJl-QAAAAE"]
[Thu Jul 30 14:38:14.959606 2026] [security2:error] [pid 43637:tid 43823] [client 20.104.18.253:9224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/docsk.php"] [unique_id "amuoJoa8U9lZpWaWlJJmBwAAADc"]
[Thu Jul 30 14:38:14.977004 2026] [security2:error] [pid 43637:tid 43871] [client 68.221.186.136:3904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuoJoa8U9lZpWaWlJJmCAAAAGc"]
[Thu Jul 30 14:38:15.072171 2026] [core:error] [pid 43637:tid 43735] [remote 74.7.175.179:60894] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:15.072199 2026] [core:error] [pid 43637:tid 43735] [remote 74.7.175.179:60894] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:15.072380 2026] [security2:error] [pid 43637:tid 43851] [client 74.7.175.179:60894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-7647e64c.qsq.nyx.temporary.site"] [uri "/website_7647e64c/index.php"] [unique_id "amuoJ4a8U9lZpWaWlJJmDAAAU2E"]
[Thu Jul 30 14:38:15.075166 2026] [security2:error] [pid 43637:tid 43890] [client 52.238.199.152:3873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/index.php"] [unique_id "amuoJ4a8U9lZpWaWlJJmDQAAAHo"]
[Thu Jul 30 14:38:15.234042 2026] [security2:error] [pid 43637:tid 43781] [client 20.226.5.174:13462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/creates.php"] [unique_id "amuoJ4a8U9lZpWaWlJJmFwAAAA0"]
[Thu Jul 30 14:38:15.418749 2026] [core:notice] [pid 43637:tid 43818] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:15.555540 2026] [security2:error] [pid 43637:tid 43790] [client 20.104.18.253:9264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/docswp.php"] [unique_id "amuoJ4a8U9lZpWaWlJJmIQAAABY"]
[Thu Jul 30 14:38:16.145615 2026] [security2:error] [pid 43637:tid 43783] [client 57.141.0.52:55336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuoJ4a8U9lZpWaWlJJmNgAADx0"], referer: https://igetvape-australia.com/product/alibarbar-ingot-banana-buzz-9000-puffs/?add-to-cart=925
[Thu Jul 30 14:38:16.153645 2026] [security2:error] [pid 43637:tid 43864] [client 20.104.18.253:9277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/documentsadmin.php"] [unique_id "amuoKIa8U9lZpWaWlJJmPAAAAGA"]
[Thu Jul 30 14:38:16.203622 2026] [security2:error] [pid 43637:tid 43858] [client 68.221.186.136:3910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuoKIa8U9lZpWaWlJJmPQAAAFo"]
[Thu Jul 30 14:38:16.205315 2026] [security2:error] [pid 43637:tid 43894] [client 177.6.106.101:53831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoKIa8U9lZpWaWlJJmPgAAAH4"]
[Thu Jul 30 14:38:16.205476 2026] [security2:error] [pid 43637:tid 43894] [client 177.6.106.101:53831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoKIa8U9lZpWaWlJJmPgAAAH4"]
[Thu Jul 30 14:38:16.361060 2026] [security2:error] [pid 43637:tid 43788] [client 20.226.5.174:13444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/credits.php"] [unique_id "amuoKIa8U9lZpWaWlJJmRQAAABQ"]
[Thu Jul 30 14:38:16.749818 2026] [security2:error] [pid 43637:tid 43774] [client 20.104.18.253:9266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/documentsalfa.php"] [unique_id "amuoKIa8U9lZpWaWlJJmUAAAAAY"]
[Thu Jul 30 14:38:17.322772 2026] [core:notice] [pid 43637:tid 43847] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:17.347177 2026] [security2:error] [pid 43637:tid 43806] [client 20.104.18.253:9231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/documentsbypass.php"] [unique_id "amuoKYa8U9lZpWaWlJJmXwAAACY"]
[Thu Jul 30 14:38:17.389464 2026] [security2:error] [pid 43637:tid 43814] [client 52.238.199.152:47317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/asasx.php"] [unique_id "amuoKYa8U9lZpWaWlJJmYwAAAC4"]
[Thu Jul 30 14:38:17.426511 2026] [security2:error] [pid 43637:tid 43851] [client 68.221.186.136:3911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuoKYa8U9lZpWaWlJJmZAAAAFM"]
[Thu Jul 30 14:38:17.453163 2026] [security2:error] [pid 43637:tid 43831] [client 20.226.5.174:13447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/cron.php"] [unique_id "amuoKYa8U9lZpWaWlJJmZQAAAD8"]
[Thu Jul 30 14:38:17.810951 2026] [security2:error] [pid 43637:tid 43886] [client 180.243.59.178:63836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoKYa8U9lZpWaWlJJmaQAAAHY"]
[Thu Jul 30 14:38:17.811092 2026] [security2:error] [pid 43637:tid 43886] [client 180.243.59.178:63836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoKYa8U9lZpWaWlJJmaQAAAHY"]
[Thu Jul 30 14:38:17.943340 2026] [security2:error] [pid 43637:tid 43836] [client 20.104.18.253:9232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/documentsk.php"] [unique_id "amuoKYa8U9lZpWaWlJJmcgAAAEQ"]
[Thu Jul 30 14:38:18.112547 2026] [core:notice] [pid 43637:tid 43863] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:18.488913 2026] [security2:error] [pid 43637:tid 43893] [client 20.226.5.174:13476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/cron_job.php"] [unique_id "amuoKoa8U9lZpWaWlJJmhAAAAH0"]
[Thu Jul 30 14:38:18.494316 2026] [security2:error] [pid 43637:tid 43782] [client 68.221.186.136:3906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/about.php"] [unique_id "amuoKoa8U9lZpWaWlJJmhQAAAA4"]
[Thu Jul 30 14:38:18.540378 2026] [security2:error] [pid 43637:tid 43879] [client 20.104.18.253:9271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/documentswp.php"] [unique_id "amuoKoa8U9lZpWaWlJJmiQAAAG8"]
[Thu Jul 30 14:38:19.135431 2026] [security2:error] [pid 43637:tid 43794] [client 20.104.18.253:9221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/docwp.php"] [unique_id "amuoK4a8U9lZpWaWlJJmmwAAABo"]
[Thu Jul 30 14:38:19.446045 2026] [security2:error] [pid 43637:tid 43832] [client 217.182.77.22:39096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuoK4a8U9lZpWaWlJJmlwAAAEA"]
[Thu Jul 30 14:38:19.731423 2026] [security2:error] [pid 43637:tid 43786] [client 20.104.18.253:9602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dog.php"] [unique_id "amuoK4a8U9lZpWaWlJJmpAAAABI"]
[Thu Jul 30 14:38:19.803616 2026] [security2:error] [pid 43637:tid 43810] [client 20.226.5.174:13475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/crop/admin.php"] [unique_id "amuoK4a8U9lZpWaWlJJmqAAAACo"]
[Thu Jul 30 14:38:20.327924 2026] [security2:error] [pid 43637:tid 43853] [client 20.104.18.253:9260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/doiconvs.php"] [unique_id "amuoLIa8U9lZpWaWlJJmuwAAAFU"]
[Thu Jul 30 14:38:20.435159 2026] [security2:error] [pid 43637:tid 43867] [client 68.221.186.136:3917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/.well-known/about.php"] [unique_id "amuoLIa8U9lZpWaWlJJmwAAAAGM"]
[Thu Jul 30 14:38:20.809177 2026] [security2:error] [pid 43637:tid 43774] [client 74.7.230.42:39374] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "durkhanai.ae.ahe.udi.temporary.site"] [uri "/public/robots.txt"] [unique_id "amuoLIa8U9lZpWaWlJJmxwAABnQ"]
[Thu Jul 30 14:38:20.916717 2026] [security2:error] [pid 43637:tid 43856] [client 52.238.199.152:38142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/user/wp-login.php"] [unique_id "amuoLIa8U9lZpWaWlJJm0AAAAFg"]
[Thu Jul 30 14:38:20.924657 2026] [security2:error] [pid 43637:tid 43873] [client 20.104.18.253:9237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dokumenadmin.php"] [unique_id "amuoLIa8U9lZpWaWlJJm0QAAAGk"]
[Thu Jul 30 14:38:20.947434 2026] [security2:error] [pid 43637:tid 43811] [client 114.119.151.165:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "embassyofgermanypakistanllc.de"] [uri "/robots.txt"] [unique_id "amuoLIa8U9lZpWaWlJJm1AAAACs"], referer: http://embassyofgermanypakistanllc.de/robots.txt
[Thu Jul 30 14:38:20.970770 2026] [security2:error] [pid 43637:tid 43821] [client 20.226.5.174:13460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/crop/uword.php"] [unique_id "amuoLIa8U9lZpWaWlJJm1gAAADU"]
[Thu Jul 30 14:38:21.531631 2026] [security2:error] [pid 43637:tid 43874] [client 20.104.18.253:9270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dokumenalfa.php"] [unique_id "amuoLYa8U9lZpWaWlJJm5wAAAGo"]
[Thu Jul 30 14:38:21.641047 2026] [security2:error] [pid 43637:tid 43772] [client 147.135.209.14:44414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuoLYa8U9lZpWaWlJJm2gAAAAQ"]
[Thu Jul 30 14:38:21.827210 2026] [security2:error] [pid 43637:tid 43888] [client 52.238.199.152:38095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "amuoLYa8U9lZpWaWlJJm6QAAAHg"]
[Thu Jul 30 14:38:22.127228 2026] [security2:error] [pid 43637:tid 43894] [client 20.104.18.253:9222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dokumenbypass.php"] [unique_id "amuoLoa8U9lZpWaWlJJm-AAAAH4"]
[Thu Jul 30 14:38:22.148655 2026] [security2:error] [pid 43637:tid 43860] [client 20.226.5.174:13498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/crop/zmFM.php"] [unique_id "amuoLoa8U9lZpWaWlJJm-QAAAFw"]
[Thu Jul 30 14:38:22.414445 2026] [core:notice] [pid 43637:tid 43827] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:22.471381 2026] [security2:error] [pid 43637:tid 43871] [client 66.249.73.97:38114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuoLoa8U9lZpWaWlJJm9AAAAGc"]
[Thu Jul 30 14:38:22.577028 2026] [security2:error] [pid 43637:tid 43881] [client 68.221.186.136:3925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuoLoa8U9lZpWaWlJJnBgAAAHE"]
[Thu Jul 30 14:38:22.721639 2026] [security2:error] [pid 43637:tid 43884] [client 20.104.18.253:9227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dokumenk.php"] [unique_id "amuoLoa8U9lZpWaWlJJnCwAAAHQ"]
[Thu Jul 30 14:38:22.791598 2026] [security2:error] [pid 43637:tid 43820] [client 189.156.226.90:27025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoLoa8U9lZpWaWlJJnDAAAADQ"]
[Thu Jul 30 14:38:22.791736 2026] [security2:error] [pid 43637:tid 43820] [client 189.156.226.90:27025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoLoa8U9lZpWaWlJJnDAAAADQ"]
[Thu Jul 30 14:38:23.259950 2026] [security2:error] [pid 43637:tid 43795] [client 20.226.5.174:13446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/crystal/doc.php"] [unique_id "amuoL4a8U9lZpWaWlJJnGwAAABs"]
[Thu Jul 30 14:38:23.283209 2026] [security2:error] [pid 43637:tid 43794] [client 52.238.199.152:50289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/radio.php"] [unique_id "amuoL4a8U9lZpWaWlJJnHQAAABo"]
[Thu Jul 30 14:38:23.298115 2026] [security2:error] [pid 43637:tid 43814] [client 68.221.186.136:4661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuoL4a8U9lZpWaWlJJnHgAAAC4"]
[Thu Jul 30 14:38:23.317463 2026] [security2:error] [pid 43637:tid 43892] [client 20.104.18.253:9258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dokumenwp.php"] [unique_id "amuoL4a8U9lZpWaWlJJnHwAAAHw"]
[Thu Jul 30 14:38:23.792245 2026] [proxy:error] [pid 43637:tid 43849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:38:23.792334 2026] [proxy_http:error] [pid 43637:tid 43849] [client 34.224.175.62:48984] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:38:23.792914 2026] [proxy:error] [pid 43637:tid 43849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:38:23.792956 2026] [proxy_http:error] [pid 43637:tid 43849] [client 34.224.175.62:48984] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:38:23.794769 2026] [proxy:error] [pid 43637:tid 43894] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:38:23.794852 2026] [proxy_http:error] [pid 43637:tid 43894] [client 34.233.129.35:65361] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:38:23.795427 2026] [proxy:error] [pid 43637:tid 43894] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:38:23.795473 2026] [proxy_http:error] [pid 43637:tid 43894] [client 34.233.129.35:65361] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:38:23.913710 2026] [security2:error] [pid 43637:tid 43891] [client 20.104.18.253:9278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/domain.php"] [unique_id "amuoL4a8U9lZpWaWlJJnNQAAAHs"]
[Thu Jul 30 14:38:23.917526 2026] [security2:error] [pid 43637:tid 43711] [remote 52.167.144.172:13673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/18696050/partnerf.php"] [unique_id "amuoL4a8U9lZpWaWlJJnNgAAPUk"]
[Thu Jul 30 14:38:24.416276 2026] [security2:error] [pid 43637:tid 43881] [client 20.226.5.174:13489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/crystal/option.php"] [unique_id "amuoMIa8U9lZpWaWlJJnQAAAAHE"]
[Thu Jul 30 14:38:24.513467 2026] [security2:error] [pid 43637:tid 43821] [client 20.104.18.253:9627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dop.php"] [unique_id "amuoMIa8U9lZpWaWlJJnRQAAADU"]
[Thu Jul 30 14:38:24.881899 2026] [core:error] [pid 43637:tid 43722] [remote 52.167.144.147:63444] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:24.881925 2026] [core:error] [pid 43637:tid 43722] [remote 52.167.144.147:63444] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:25.108688 2026] [security2:error] [pid 43637:tid 43794] [client 20.104.18.253:9228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dosya.php"] [unique_id "amuoMYa8U9lZpWaWlJJnXgAAABo"]
[Thu Jul 30 14:38:25.426485 2026] [security2:error] [pid 43637:tid 43837] [client 68.221.186.136:3920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/img/about.php"] [unique_id "amuoMYa8U9lZpWaWlJJnaAAAAEU"]
[Thu Jul 30 14:38:25.702723 2026] [security2:error] [pid 43637:tid 43826] [client 20.104.18.253:9653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dot.php"] [unique_id "amuoMYa8U9lZpWaWlJJnbwAAADo"]
[Thu Jul 30 14:38:25.952179 2026] [core:notice] [pid 43637:tid 43782] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:25.954031 2026] [security2:error] [pid 43637:tid 43843] [client 20.226.5.174:13471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/crystal/wp-login.php"] [unique_id "amuoMYa8U9lZpWaWlJJnbAAAAEs"]
[Thu Jul 30 14:38:26.301349 2026] [security2:error] [pid 43637:tid 43850] [client 20.104.18.253:9647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/download.php"] [unique_id "amuoMoa8U9lZpWaWlJJnigAAAFI"]
[Thu Jul 30 14:38:26.646621 2026] [security2:error] [pid 43637:tid 43784] [client 177.6.106.101:54435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoMoa8U9lZpWaWlJJnjgAAABA"]
[Thu Jul 30 14:38:26.646753 2026] [security2:error] [pid 43637:tid 43784] [client 177.6.106.101:54435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoMoa8U9lZpWaWlJJnjgAAABA"]
[Thu Jul 30 14:38:26.896097 2026] [security2:error] [pid 43637:tid 43854] [client 20.104.18.253:9245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dox.php"] [unique_id "amuoMoa8U9lZpWaWlJJnmAAAAFY"]
[Thu Jul 30 14:38:27.136950 2026] [security2:error] [pid 43637:tid 43807] [client 20.226.5.174:13466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/css-ready-sel/file.php"] [unique_id "amuoM4a8U9lZpWaWlJJnnQAAACc"]
[Thu Jul 30 14:38:27.208922 2026] [security2:error] [pid 43637:tid 43803] [client 68.221.186.136:3274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuoM4a8U9lZpWaWlJJnngAAACM"]
[Thu Jul 30 14:38:27.491313 2026] [security2:error] [pid 43637:tid 43792] [client 52.238.199.152:38118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuoM4a8U9lZpWaWlJJnpQAAABg"]
[Thu Jul 30 14:38:27.496282 2026] [security2:error] [pid 43637:tid 43810] [client 20.104.18.253:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dr.php"] [unique_id "amuoM4a8U9lZpWaWlJJnpgAAACo"]
[Thu Jul 30 14:38:27.853887 2026] [security2:error] [pid 43637:tid 43826] [client 68.221.186.136:4630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuoM4a8U9lZpWaWlJJnswAAADo"]
[Thu Jul 30 14:38:27.884372 2026] [security2:error] [pid 43637:tid 43853] [client 47.128.121.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuoM4a8U9lZpWaWlJJnrwAAAFU"]
[Thu Jul 30 14:38:28.092539 2026] [security2:error] [pid 43637:tid 43782] [client 20.104.18.253:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dragonforce.php"] [unique_id "amuoNIa8U9lZpWaWlJJntwAAAA4"]
[Thu Jul 30 14:38:28.246290 2026] [security2:error] [pid 43637:tid 43893] [client 20.226.5.174:13443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/css-ready/file.php"] [unique_id "amuoNIa8U9lZpWaWlJJnvwAAAH0"]
[Thu Jul 30 14:38:28.689129 2026] [security2:error] [pid 43637:tid 43802] [client 20.104.18.253:9253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dropdown.php"] [unique_id "amuoNIa8U9lZpWaWlJJnyAAAACI"]
[Thu Jul 30 14:38:29.010824 2026] [security2:error] [pid 43637:tid 43831] [client 180.243.59.178:64418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoNYa8U9lZpWaWlJJn0QAAAD8"]
[Thu Jul 30 14:38:29.011007 2026] [security2:error] [pid 43637:tid 43831] [client 180.243.59.178:64418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoNYa8U9lZpWaWlJJn0QAAAD8"]
[Thu Jul 30 14:38:29.285198 2026] [security2:error] [pid 43637:tid 43795] [client 20.104.18.253:9236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/ds.php"] [unique_id "amuoNYa8U9lZpWaWlJJn2QAAABs"]
[Thu Jul 30 14:38:29.321015 2026] [security2:error] [pid 43637:tid 43882] [client 20.226.5.174:13454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/css.php"] [unique_id "amuoNYa8U9lZpWaWlJJn3QAAAHI"]
[Thu Jul 30 14:38:29.536121 2026] [proxy:error] [pid 43637:tid 43820] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:38:29.536185 2026] [proxy_http:error] [pid 43637:tid 43820] [client 195.96.139.253:55929] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:38:29.536749 2026] [proxy:error] [pid 43637:tid 43820] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:38:29.536790 2026] [proxy_http:error] [pid 43637:tid 43820] [client 195.96.139.253:55929] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:38:29.830313 2026] [security2:error] [pid 43637:tid 43870] [client 52.238.199.152:17106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/st.php"] [unique_id "amuoNYa8U9lZpWaWlJJn5gAAAGY"]
[Thu Jul 30 14:38:29.881929 2026] [security2:error] [pid 43637:tid 43800] [client 20.104.18.253:9276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dummy.php"] [unique_id "amuoNYa8U9lZpWaWlJJn6gAAACA"]
[Thu Jul 30 14:38:29.947528 2026] [core:error] [pid 43637:tid 43862] [client 74.7.175.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:29.947553 2026] [core:error] [pid 43637:tid 43862] [client 74.7.175.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:29.947698 2026] [security2:error] [pid 43637:tid 43862] [client 74.7.175.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.ahm.djb.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuoNYa8U9lZpWaWlJJn8AAAAF4"]
[Thu Jul 30 14:38:29.948378 2026] [security2:error] [pid 43637:tid 43828] [client 74.7.175.178:34636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.ahm.djb.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuoNYa8U9lZpWaWlJJn7gAAPH4"]
[Thu Jul 30 14:38:30.479078 2026] [security2:error] [pid 43637:tid 43894] [client 20.104.18.253:9225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dummyyummy/wp-signup.php"] [unique_id "amuoNoa8U9lZpWaWlJJoAAAAAH4"]
[Thu Jul 30 14:38:30.560019 2026] [security2:error] [pid 43637:tid 43857] [client 20.226.5.174:13449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/csv.php"] [unique_id "amuoNoa8U9lZpWaWlJJoBAAAAFk"]
[Thu Jul 30 14:38:30.560914 2026] [security2:error] [pid 43637:tid 43840] [client 68.221.186.136:4626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuoNoa8U9lZpWaWlJJoBQAAAEg"]
[Thu Jul 30 14:38:30.896960 2026] [security2:error] [pid 43637:tid 43747] [remote 52.167.144.139:59381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/665"] [unique_id "amuoNoa8U9lZpWaWlJJoBgAAUm0"]
[Thu Jul 30 14:38:31.090204 2026] [security2:error] [pid 43637:tid 43821] [client 20.104.18.253:9217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dump.php"] [unique_id "amuoN4a8U9lZpWaWlJJoFQAAADU"]
[Thu Jul 30 14:38:31.107935 2026] [security2:error] [pid 43637:tid 43657] [remote 52.167.144.139:59381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/507"] [unique_id "amuoN4a8U9lZpWaWlJJoFgAAFhM"]
[Thu Jul 30 14:38:31.315310 2026] [security2:error] [pid 43637:tid 43776] [client 68.221.186.136:4660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuoN4a8U9lZpWaWlJJoGAAAAAg"]
[Thu Jul 30 14:38:31.552290 2026] [security2:error] [pid 43637:tid 43869] [client 52.238.199.152:50297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/about.php"] [unique_id "amuoN4a8U9lZpWaWlJJoJwAAAGU"]
[Thu Jul 30 14:38:31.685311 2026] [security2:error] [pid 43637:tid 43892] [client 20.104.18.253:9619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/dyqvcfqv.php"] [unique_id "amuoN4a8U9lZpWaWlJJoKAAAAHw"]
[Thu Jul 30 14:38:31.707199 2026] [security2:error] [pid 43637:tid 43831] [client 20.226.5.174:13469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/current.php"] [unique_id "amuoN4a8U9lZpWaWlJJoKQAAAD8"]
[Thu Jul 30 14:38:31.969289 2026] [security2:error] [pid 43637:tid 43849] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoNoa8U9lZpWaWlJJn-QAAAFE"]
[Thu Jul 30 14:38:32.079766 2026] [security2:error] [pid 43637:tid 43800] [client 68.221.186.136:4646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuoOIa8U9lZpWaWlJJoOAAAACA"]
[Thu Jul 30 14:38:32.286405 2026] [security2:error] [pid 43637:tid 43867] [client 20.104.18.253:9265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/e-preview.php"] [unique_id "amuoOIa8U9lZpWaWlJJoPAAAAGM"]
[Thu Jul 30 14:38:32.491762 2026] [security2:error] [pid 43637:tid 43878] [client 172.237.109.114:58091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuoN4a8U9lZpWaWlJJoMQAAAG4"]
[Thu Jul 30 14:38:32.884211 2026] [security2:error] [pid 43637:tid 43811] [client 20.104.18.253:9609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/e.php"] [unique_id "amuoOIa8U9lZpWaWlJJoTAAAACs"]
[Thu Jul 30 14:38:33.367117 2026] [security2:error] [pid 43637:tid 43888] [client 189.156.226.90:27586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoOYa8U9lZpWaWlJJoVAAAAHg"]
[Thu Jul 30 14:38:33.367245 2026] [security2:error] [pid 43637:tid 43888] [client 189.156.226.90:27586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoOYa8U9lZpWaWlJJoVAAAAHg"]
[Thu Jul 30 14:38:33.509150 2026] [security2:error] [pid 43637:tid 43851] [client 68.221.186.136:3283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuoOYa8U9lZpWaWlJJoWwAAAFM"]
[Thu Jul 30 14:38:33.876877 2026] [security2:error] [pid 43637:tid 43877] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuoOYa8U9lZpWaWlJJoUwAAbXU"]
[Thu Jul 30 14:38:33.999881 2026] [security2:error] [pid 43637:tid 43817] [client 52.238.199.152:38104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/admin.php"] [unique_id "amuoOYa8U9lZpWaWlJJocgAAADE"]
[Thu Jul 30 14:38:34.446673 2026] [security2:error] [pid 43637:tid 43822] [client 74.7.228.50:52436] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.abudhabifurnituremoverspackers.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuoOoa8U9lZpWaWlJJodwAAADY"]
[Thu Jul 30 14:38:34.643520 2026] [security2:error] [pid 43637:tid 43891] [client 184.75.221.59:52338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuoOoa8U9lZpWaWlJJogQAAAHs"]
[Thu Jul 30 14:38:34.643641 2026] [security2:error] [pid 43637:tid 43891] [client 184.75.221.59:52338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuoOoa8U9lZpWaWlJJogQAAAHs"]
[Thu Jul 30 14:38:34.674246 2026] [security2:error] [pid 43637:tid 43776] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuoOoa8U9lZpWaWlJJodAAACDE"]
[Thu Jul 30 14:38:34.870096 2026] [core:error] [pid 43637:tid 43750] [remote 74.7.230.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:34.870123 2026] [core:error] [pid 43637:tid 43750] [remote 74.7.230.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:34.870349 2026] [security2:error] [pid 43637:tid 43866] [client 74.7.230.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.blsspainvisacenterpakistan.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuoOoa8U9lZpWaWlJJoggAAYnA"]
[Thu Jul 30 14:38:35.162575 2026] [security2:error] [pid 43637:tid 43800] [client 68.221.186.136:4651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuoO4a8U9lZpWaWlJJokAAAACA"]
[Thu Jul 30 14:38:35.229165 2026] [security2:error] [pid 43637:tid 43826] [client 52.238.199.152:38120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/css/admin.php"] [unique_id "amuoO4a8U9lZpWaWlJJolAAAADo"]
[Thu Jul 30 14:38:35.468476 2026] [security2:error] [pid 43637:tid 43838] [client 66.249.75.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.urbanshiftmovingcompany.one"] [uri "/index.php"] [unique_id "amuoOoa8U9lZpWaWlJJogwAARj8"]
[Thu Jul 30 14:38:36.081148 2026] [security2:error] [pid 43637:tid 43805] [client 172.237.109.114:27955] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "alseermarine.com"] [uri "/webui/logoutconfirm.html"] [unique_id "amuoPIa8U9lZpWaWlJJopQAAACU"]
[Thu Jul 30 14:38:36.189368 2026] [security2:error] [pid 43637:tid 43865] [client 52.238.199.152:38100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuoPIa8U9lZpWaWlJJoqAAAAGE"]
[Thu Jul 30 14:38:36.366676 2026] [security2:error] [pid 43637:tid 43880] [client 68.221.186.136:4668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuoPIa8U9lZpWaWlJJorgAAAHA"]
[Thu Jul 30 14:38:37.410020 2026] [security2:error] [pid 43637:tid 43772] [client 177.6.106.101:55021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoPYa8U9lZpWaWlJJoygAAAAQ"]
[Thu Jul 30 14:38:37.410160 2026] [security2:error] [pid 43637:tid 43772] [client 177.6.106.101:55021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoPYa8U9lZpWaWlJJoygAAAAQ"]
[Thu Jul 30 14:38:38.284440 2026] [security2:error] [pid 43637:tid 43796] [client 68.221.186.136:4639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuoPoa8U9lZpWaWlJJo2wAAABw"]
[Thu Jul 30 14:38:38.971112 2026] [security2:error] [pid 43637:tid 43795] [client 180.243.59.178:64929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoPoa8U9lZpWaWlJJo7AAAABs"]
[Thu Jul 30 14:38:38.971255 2026] [security2:error] [pid 43637:tid 43795] [client 180.243.59.178:64929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoPoa8U9lZpWaWlJJo7AAAABs"]
[Thu Jul 30 14:38:39.249173 2026] [security2:error] [pid 43637:tid 43814] [client 68.221.186.136:3931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuoP4a8U9lZpWaWlJJo8wAAAC4"]
[Thu Jul 30 14:38:39.408837 2026] [security2:error] [pid 43637:tid 43876] [client 52.238.199.152:37959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp2.php"] [unique_id "amuoP4a8U9lZpWaWlJJo-QAAAGw"]
[Thu Jul 30 14:38:39.408900 2026] [core:notice] [pid 43637:tid 43676] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:39.413367 2026] [security2:error] [pid 43637:tid 43863] [client 213.188.72.182:33485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/393"] [unique_id "amuoP4a8U9lZpWaWlJJo7QAAXyY"]
[Thu Jul 30 14:38:41.046706 2026] [core:notice] [pid 43637:tid 43725] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:41.898664 2026] [security2:error] [pid 43637:tid 43830] [client 68.221.186.136:3314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuoQYa8U9lZpWaWlJJpLgAAAD4"]
[Thu Jul 30 14:38:42.579071 2026] [core:notice] [pid 43637:tid 43770] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.186404 2026] [core:notice] [pid 43637:tid 43653] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.190895 2026] [security2:error] [pid 43637:tid 43870] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/lib/pkp/styles/fontawesome/fontawesome_v-3.3.0.17.css"] [unique_id "amuoQoa8U9lZpWaWlJJpQwAAZg8"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.194723 2026] [core:notice] [pid 43637:tid 43647] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.200800 2026] [security2:error] [pid 43637:tid 43870] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/site/pageHeaderTitleImage_id_ID.jpg"] [unique_id "amuoQoa8U9lZpWaWlJJpRgAAZgk"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.201261 2026] [core:notice] [pid 43637:tid 43661] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.205404 2026] [security2:error] [pid 43637:tid 43870] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/index_php/index/---call---/page/page/css-name-stylesheet.css"] [unique_id "amuoQoa8U9lZpWaWlJJpRAAAZhc"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.207859 2026] [core:notice] [pid 43637:tid 43740] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.212314 2026] [security2:error] [pid 43637:tid 43870] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/index_php/index/---call---/page/page/css-name-font.css"] [unique_id "amuoQoa8U9lZpWaWlJJpRQAAZmY"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.685606 2026] [core:notice] [pid 43637:tid 43642] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.689188 2026] [security2:error] [pid 43637:tid 43894] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/17/journalThumbnail_en_US.png"] [unique_id "amuoQ4a8U9lZpWaWlJJpWgAAfgQ"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.689463 2026] [core:notice] [pid 43637:tid 43659] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.692638 2026] [security2:error] [pid 43637:tid 43894] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/11/journalThumbnail_id_ID.jpg"] [unique_id "amuoQ4a8U9lZpWaWlJJpWwAAfhU"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.692734 2026] [core:notice] [pid 43637:tid 43726] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.692766 2026] [core:notice] [pid 43637:tid 43666] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.692848 2026] [core:notice] [pid 43637:tid 43752] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.695775 2026] [security2:error] [pid 43637:tid 43894] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/site/images/apranolo/Crossref_Logo_Stacked_RGB_SMALL.png"] [unique_id "amuoQ4a8U9lZpWaWlJJpXAAAflg"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.695908 2026] [security2:error] [pid 43637:tid 43894] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/32/journalThumbnail_id_ID.jpg"] [unique_id "amuoQ4a8U9lZpWaWlJJpXQAAfhw"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.697446 2026] [security2:error] [pid 43637:tid 43894] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/44/journalThumbnail_id_ID.png"] [unique_id "amuoQ4a8U9lZpWaWlJJpXgAAfnI"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.699169 2026] [core:notice] [pid 43637:tid 43669] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.699172 2026] [core:notice] [pid 43637:tid 43747] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.700427 2026] [core:notice] [pid 43637:tid 43662] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:43.702137 2026] [security2:error] [pid 43637:tid 43879] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/22/journalThumbnail_en_US.jpg"] [unique_id "amuoQ4a8U9lZpWaWlJJpXwAAbx8"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.702304 2026] [security2:error] [pid 43637:tid 43879] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/19/journalThumbnail_id_ID.jpg"] [unique_id "amuoQ4a8U9lZpWaWlJJpYAAAb20"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.704466 2026] [security2:error] [pid 43637:tid 43879] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/33/journalThumbnail_id_ID.jpg"] [unique_id "amuoQ4a8U9lZpWaWlJJpYQAAbxg"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:43.952889 2026] [security2:error] [pid 43637:tid 43778] [client 189.156.226.90:27640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoQ4a8U9lZpWaWlJJpZgAAAAo"]
[Thu Jul 30 14:38:43.953010 2026] [security2:error] [pid 43637:tid 43778] [client 189.156.226.90:27640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoQ4a8U9lZpWaWlJJpZgAAAAo"]
[Thu Jul 30 14:38:44.139248 2026] [security2:error] [pid 43637:tid 43855] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoQ4a8U9lZpWaWlJJpVQAAAFc"]
[Thu Jul 30 14:38:44.190322 2026] [core:notice] [pid 43637:tid 43657] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.190322 2026] [core:notice] [pid 43637:tid 43746] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.190727 2026] [core:notice] [pid 43637:tid 43665] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.190732 2026] [core:notice] [pid 43637:tid 43759] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.190787 2026] [core:notice] [pid 43637:tid 43737] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.193776 2026] [security2:error] [pid 43637:tid 43804] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/8/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJpcAAAJGw"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.193949 2026] [security2:error] [pid 43637:tid 43804] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/10/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJpcQAAJBM"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.194297 2026] [security2:error] [pid 43637:tid 43804] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/39/journalThumbnail_en_US.png"] [unique_id "amuoRIa8U9lZpWaWlJJpbwAAJGM"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.196324 2026] [security2:error] [pid 43637:tid 43804] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/20/journalThumbnail_en_US.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJpcgAAJBs"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.196685 2026] [security2:error] [pid 43637:tid 43804] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/24/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJpcwAAJHg"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.198893 2026] [core:notice] [pid 43637:tid 43660] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.202334 2026] [security2:error] [pid 43637:tid 43824] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/7/journalThumbnail_id_ID.png"] [unique_id "amuoRIa8U9lZpWaWlJJpdAAAOBY"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.211919 2026] [core:notice] [pid 43637:tid 43684] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.212427 2026] [core:notice] [pid 43637:tid 43643] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.215048 2026] [security2:error] [pid 43637:tid 43885] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/14/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJpdgAAdS4"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.215931 2026] [security2:error] [pid 43637:tid 43885] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/21/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJpdQAAdQU"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.487853 2026] [security2:error] [pid 43637:tid 43862] [client 68.221.186.136:4623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuoRIa8U9lZpWaWlJJpfQAAAF4"]
[Thu Jul 30 14:38:44.684781 2026] [core:notice] [pid 43637:tid 43640] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.684791 2026] [core:notice] [pid 43637:tid 43670] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.687621 2026] [core:notice] [pid 43637:tid 43739] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.687729 2026] [core:notice] [pid 43637:tid 43658] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.688505 2026] [security2:error] [pid 43637:tid 43795] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/29/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJpgQAAGwI"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.689761 2026] [security2:error] [pid 43637:tid 43795] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/6/journalThumbnail_en_US.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJpggAAGyA"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.689971 2026] [core:notice] [pid 43637:tid 43762] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.691037 2026] [security2:error] [pid 43637:tid 43795] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/35/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJphAAAGxQ"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.691647 2026] [security2:error] [pid 43637:tid 43795] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/3/journalThumbnail_en_US.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJpgwAAG2U"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.693001 2026] [core:notice] [pid 43637:tid 43650] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.694526 2026] [security2:error] [pid 43637:tid 43795] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/4/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJphQAAG3s"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.696513 2026] [security2:error] [pid 43637:tid 43795] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/25/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJphgAAGww"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.705285 2026] [core:notice] [pid 43637:tid 43675] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.705460 2026] [core:notice] [pid 43637:tid 43649] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:44.708413 2026] [security2:error] [pid 43637:tid 43871] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/2/journalThumbnail_id_ID.png"] [unique_id "amuoRIa8U9lZpWaWlJJpiAAAZyU"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:44.710340 2026] [security2:error] [pid 43637:tid 43871] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/1/journalThumbnail_id_ID.jpg"] [unique_id "amuoRIa8U9lZpWaWlJJphwAAZws"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:45.111636 2026] [security2:error] [pid 43637:tid 43863] [client 68.221.186.136:4611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuoRYa8U9lZpWaWlJJpkwAAAF8"]
[Thu Jul 30 14:38:45.178631 2026] [core:notice] [pid 43637:tid 43744] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:45.178631 2026] [core:notice] [pid 43637:tid 43685] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:45.182283 2026] [security2:error] [pid 43637:tid 43890] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/public/journals/13/journalThumbnail_id_ID.jpg"] [unique_id "amuoRYa8U9lZpWaWlJJplAAAemo"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:45.182462 2026] [security2:error] [pid 43637:tid 43890] [client 188.119.118.32:36139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/templates/images/ojs_brand.png"] [unique_id "amuoRYa8U9lZpWaWlJJplQAAei8"], referer: https://www.ejournalugj.com/index.php/logika/article/view/393
[Thu Jul 30 14:38:46.534633 2026] [security2:error] [pid 43637:tid 43788] [client 52.238.199.152:37974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/s.php"] [unique_id "amuoRoa8U9lZpWaWlJJpugAAABQ"]
[Thu Jul 30 14:38:46.791318 2026] [security2:error] [pid 43637:tid 43802] [client 57.141.0.17:41956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuoRoa8U9lZpWaWlJJptgAAIig"], referer: https://igetvape-australia.com/product-category/iget-hot/?add-to-cart=201
[Thu Jul 30 14:38:47.142028 2026] [security2:error] [pid 43637:tid 43702] [remote 97.74.93.24:48922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daralnaseemdxb.com"] [uri "/wp-login.php"] [unique_id "amuoR4a8U9lZpWaWlJJpyQAARkA"]
[Thu Jul 30 14:38:47.755408 2026] [security2:error] [pid 43637:tid 43768] [client 185.191.171.18:28798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/21/desabamento-de-casa-deixa-tres-adultos-e-quatro-criancas-feridos-em-sape/"] [unique_id "amuoR4a8U9lZpWaWlJJp1QAAAAA"]
[Thu Jul 30 14:38:47.755520 2026] [security2:error] [pid 43637:tid 43768] [client 185.191.171.18:28798] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/21/desabamento-de-casa-deixa-tres-adultos-e-quatro-criancas-feridos-em-sape/"] [unique_id "amuoR4a8U9lZpWaWlJJp1QAAAAA"]
[Thu Jul 30 14:38:47.851313 2026] [security2:error] [pid 43637:tid 43801] [client 177.6.106.101:55714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoR4a8U9lZpWaWlJJp1gAAACE"]
[Thu Jul 30 14:38:47.851467 2026] [security2:error] [pid 43637:tid 43801] [client 177.6.106.101:55714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoR4a8U9lZpWaWlJJp1gAAACE"]
[Thu Jul 30 14:38:47.952814 2026] [security2:error] [pid 43637:tid 43877] [client 52.238.199.152:32972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/help.php"] [unique_id "amuoR4a8U9lZpWaWlJJp2gAAAG0"]
[Thu Jul 30 14:38:48.045445 2026] [security2:error] [pid 43637:tid 43883] [client 43.164.194.198:43662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aetiiph.net"] [uri "/index.php"] [unique_id "amuoRoa8U9lZpWaWlJJptQAAAHM"]
[Thu Jul 30 14:38:49.622603 2026] [security2:error] [pid 43637:tid 43851] [client 74.7.228.37:46154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chachabet.live.qsv.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuoSYa8U9lZpWaWlJJp_QAAAFM"]
[Thu Jul 30 14:38:49.870654 2026] [security2:error] [pid 43637:tid 43794] [client 52.238.199.152:37986] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuoSYa8U9lZpWaWlJJqBAAAABo"]
[Thu Jul 30 14:38:49.870791 2026] [security2:error] [pid 43637:tid 43794] [client 52.238.199.152:37986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuoSYa8U9lZpWaWlJJqBAAAABo"]
[Thu Jul 30 14:38:50.952165 2026] [security2:error] [pid 43637:tid 43783] [client 52.238.199.152:38094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/admin/upload/css.php"] [unique_id "amuoSoa8U9lZpWaWlJJqHgAAAA8"]
[Thu Jul 30 14:38:51.399210 2026] [security2:error] [pid 43637:tid 43809] [client 180.243.59.178:49198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoS4a8U9lZpWaWlJJqKwAAACk"]
[Thu Jul 30 14:38:51.399337 2026] [security2:error] [pid 43637:tid 43809] [client 180.243.59.178:49198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoS4a8U9lZpWaWlJJqKwAAACk"]
[Thu Jul 30 14:38:51.598337 2026] [security2:error] [pid 43637:tid 43832] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoS4a8U9lZpWaWlJJqIQAAAEA"]
[Thu Jul 30 14:38:52.185917 2026] [core:error] [pid 43637:tid 43811] [client 173.252.82.25:50824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:52.185943 2026] [core:error] [pid 43637:tid 43811] [client 173.252.82.25:50824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:38:52.262336 2026] [security2:error] [pid 43637:tid 43770] [client 68.221.186.136:3972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/images/about.php"] [unique_id "amuoTIa8U9lZpWaWlJJqPAAAAAI"]
[Thu Jul 30 14:38:52.858925 2026] [security2:error] [pid 43637:tid 43803] [client 68.221.186.136:4021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuoTIa8U9lZpWaWlJJqRwAAACM"]
[Thu Jul 30 14:38:52.870436 2026] [security2:error] [pid 43637:tid 43805] [client 52.238.199.152:50261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuoTIa8U9lZpWaWlJJqSQAAACU"]
[Thu Jul 30 14:38:54.099465 2026] [security2:error] [pid 43637:tid 43875] [client 52.238.199.152:38005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/autoloadclassmap.php"] [unique_id "amuoToa8U9lZpWaWlJJqYQAAAGs"]
[Thu Jul 30 14:38:54.247585 2026] [security2:error] [pid 43637:tid 43775] [client 68.221.186.136:3979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuoToa8U9lZpWaWlJJqZQAAAAc"]
[Thu Jul 30 14:38:54.496529 2026] [security2:error] [pid 43637:tid 43813] [client 189.156.226.90:26862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoToa8U9lZpWaWlJJqZgAAAC0"]
[Thu Jul 30 14:38:54.496660 2026] [security2:error] [pid 43637:tid 43813] [client 189.156.226.90:26862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoToa8U9lZpWaWlJJqZgAAAC0"]
[Thu Jul 30 14:38:55.091681 2026] [security2:error] [pid 43637:tid 43867] [client 57.141.0.22:28900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuoToa8U9lZpWaWlJJqcAAAY1k"], referer: https://igetvape-australia.com/product/iget-moon-passion-fruit-lychee/?add-to-cart=177
[Thu Jul 30 14:38:55.117702 2026] [security2:error] [pid 43637:tid 43872] [client 68.221.186.136:4621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/about.php"] [unique_id "amuoT4a8U9lZpWaWlJJqdwAAAGg"]
[Thu Jul 30 14:38:55.601524 2026] [security2:error] [pid 43637:tid 43894] [client 52.238.199.152:37966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/x.php"] [unique_id "amuoT4a8U9lZpWaWlJJqhAAAAH4"]
[Thu Jul 30 14:38:55.789169 2026] [security2:error] [pid 43637:tid 43774] [client 68.221.186.136:3272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/cgi-bin/about.php"] [unique_id "amuoT4a8U9lZpWaWlJJqiAAAAAY"]
[Thu Jul 30 14:38:57.000419 2026] [security2:error] [pid 43637:tid 43784] [client 68.221.186.136:4003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuoUIa8U9lZpWaWlJJqoAAAABA"]
[Thu Jul 30 14:38:57.233858 2026] [security2:error] [pid 43637:tid 43814] [client 64.42.179.59:43308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuoUIa8U9lZpWaWlJJqngAAAC4"]
[Thu Jul 30 14:38:57.234027 2026] [security2:error] [pid 43637:tid 43814] [client 64.42.179.59:43308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuoUIa8U9lZpWaWlJJqngAAAC4"]
[Thu Jul 30 14:38:57.830477 2026] [security2:error] [pid 43637:tid 43787] [client 52.238.199.152:38125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-class.php"] [unique_id "amuoUYa8U9lZpWaWlJJqtAAAABM"]
[Thu Jul 30 14:38:58.967786 2026] [security2:error] [pid 43637:tid 43836] [client 177.6.106.101:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoUoa8U9lZpWaWlJJqzQAAAEQ"]
[Thu Jul 30 14:38:58.967917 2026] [security2:error] [pid 43637:tid 43836] [client 177.6.106.101:56353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoUoa8U9lZpWaWlJJqzQAAAEQ"]
[Thu Jul 30 14:38:59.078852 2026] [security2:error] [pid 43637:tid 43840] [client 52.238.199.152:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/content.php"] [unique_id "amuoU4a8U9lZpWaWlJJqzgAAAEg"]
[Thu Jul 30 14:38:59.199519 2026] [core:notice] [pid 43637:tid 43657] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:38:59.614367 2026] [core:notice] [pid 43637:tid 43643] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:00.792512 2026] [security2:error] [pid 43637:tid 43862] [client 180.243.59.178:49679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoVIa8U9lZpWaWlJJrDAAAAF4"]
[Thu Jul 30 14:39:00.792617 2026] [security2:error] [pid 43637:tid 43862] [client 180.243.59.178:49679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoVIa8U9lZpWaWlJJrDAAAAF4"]
[Thu Jul 30 14:39:01.304751 2026] [security2:error] [pid 43637:tid 43828] [client 68.221.186.136:3993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuoVYa8U9lZpWaWlJJrLAAAADw"]
[Thu Jul 30 14:39:01.852160 2026] [security2:error] [pid 43637:tid 43822] [client 68.221.186.136:3275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuoVYa8U9lZpWaWlJJrSwAAADY"]
[Thu Jul 30 14:39:01.915454 2026] [security2:error] [pid 43637:tid 43811] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuoVYa8U9lZpWaWlJJrRQAAACs"]
[Thu Jul 30 14:39:02.066436 2026] [core:notice] [pid 43637:tid 43835] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:02.338112 2026] [security2:error] [pid 43637:tid 43883] [client 64.42.179.59:48500] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuoVoa8U9lZpWaWlJJrWgAAAHM"]
[Thu Jul 30 14:39:02.338219 2026] [security2:error] [pid 43637:tid 43883] [client 64.42.179.59:48500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuoVoa8U9lZpWaWlJJrWgAAAHM"]
[Thu Jul 30 14:39:02.521294 2026] [security2:error] [pid 43637:tid 43839] [client 52.238.199.152:3840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/acp.php"] [unique_id "amuoVoa8U9lZpWaWlJJrZgAAAEc"]
[Thu Jul 30 14:39:02.683418 2026] [security2:error] [pid 43637:tid 43792] [client 68.221.186.136:4610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuoVoa8U9lZpWaWlJJrbAAAABg"]
[Thu Jul 30 14:39:03.266115 2026] [security2:error] [pid 43637:tid 43672] [remote 49.51.233.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.233.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuoV4a8U9lZpWaWlJJreQAAaSI"]
[Thu Jul 30 14:39:03.406705 2026] [security2:error] [pid 43637:tid 43806] [client 52.238.199.152:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/g.php"] [unique_id "amuoV4a8U9lZpWaWlJJriwAAACY"]
[Thu Jul 30 14:39:03.411703 2026] [core:notice] [pid 43637:tid 43799] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:03.509397 2026] [security2:error] [pid 43637:tid 43865] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-6cfcc7a4.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuoVoa8U9lZpWaWlJJrdwAAAGE"]
[Thu Jul 30 14:39:03.510309 2026] [security2:error] [pid 43637:tid 43768] [client 74.7.230.63:54652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-6cfcc7a4.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuoVoa8U9lZpWaWlJJrdQAAAEA"]
[Thu Jul 30 14:39:03.716544 2026] [security2:error] [pid 43637:tid 43692] [remote 74.7.243.224:47942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amuoV4a8U9lZpWaWlJJrnQAAHjY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:39:03.737512 2026] [security2:error] [pid 43637:tid 43797] [client 127.0.0.1:52578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuoV4a8U9lZpWaWlJJrnAAAAB0"]
[Thu Jul 30 14:39:03.737537 2026] [security2:error] [pid 43637:tid 43863] [client 127.0.0.1:52574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.lxw.gpl.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuoV4a8U9lZpWaWlJJrmwAAAF8"]
[Thu Jul 30 14:39:03.737650 2026] [security2:error] [pid 43637:tid 43801] [client 74.7.230.9:53294] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.lxw.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuoV4a8U9lZpWaWlJJrmgAAIQ0"]
[Thu Jul 30 14:39:04.316742 2026] [security2:error] [pid 43637:tid 43847] [client 52.238.199.152:50263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/caches.php"] [unique_id "amuoWIa8U9lZpWaWlJJrsQAAAE8"]
[Thu Jul 30 14:39:04.988817 2026] [security2:error] [pid 43637:tid 43816] [client 189.156.226.90:27210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoWIa8U9lZpWaWlJJrygAAADA"]
[Thu Jul 30 14:39:04.988970 2026] [security2:error] [pid 43637:tid 43816] [client 189.156.226.90:27210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoWIa8U9lZpWaWlJJrygAAADA"]
[Thu Jul 30 14:39:05.614231 2026] [security2:error] [pid 43637:tid 43801] [client 52.238.199.152:49636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuoWYa8U9lZpWaWlJJr3AAAACE"]
[Thu Jul 30 14:39:05.616412 2026] [security2:error] [pid 43637:tid 43696] [remote 57.141.0.49:55442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4208817797/feed/rss2/"] [unique_id "amuoWYa8U9lZpWaWlJJr2wAAfTo"]
[Thu Jul 30 14:39:05.813481 2026] [security2:error] [pid 43637:tid 43790] [client 68.221.186.136:4614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuoWYa8U9lZpWaWlJJr4AAAABY"]
[Thu Jul 30 14:39:07.497516 2026] [security2:error] [pid 43637:tid 43883] [client 68.221.186.136:4618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuoW4a8U9lZpWaWlJJsBQAAAHM"]
[Thu Jul 30 14:39:08.023012 2026] [security2:error] [pid 43637:tid 43773] [client 52.238.199.152:16726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/css/about.php"] [unique_id "amuoXIa8U9lZpWaWlJJsDwAAAAU"]
[Thu Jul 30 14:39:08.299018 2026] [security2:error] [pid 43637:tid 43808] [client 112.198.227.30:43894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.227.198.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ai-kr.com"] [uri "/xmlrpc.php"] [unique_id "amuoXIa8U9lZpWaWlJJsEAAAACg"]
[Thu Jul 30 14:39:08.299172 2026] [security2:error] [pid 43637:tid 43808] [client 112.198.227.30:43894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ai-kr.com"] [uri "/xmlrpc.php"] [unique_id "amuoXIa8U9lZpWaWlJJsEAAAACg"]
[Thu Jul 30 14:39:08.612200 2026] [security2:error] [pid 43637:tid 43781] [client 68.221.186.136:4014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuoXIa8U9lZpWaWlJJsGwAAAA0"]
[Thu Jul 30 14:39:08.849315 2026] [security2:error] [pid 43637:tid 43770] [client 52.238.199.152:37981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/files/index.php"] [unique_id "amuoXIa8U9lZpWaWlJJsIgAAAAI"]
[Thu Jul 30 14:39:09.521146 2026] [security2:error] [pid 43637:tid 43882] [client 177.6.106.101:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoXYa8U9lZpWaWlJJsLwAAAHI"]
[Thu Jul 30 14:39:09.521292 2026] [security2:error] [pid 43637:tid 43882] [client 177.6.106.101:56982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoXYa8U9lZpWaWlJJsLwAAAHI"]
[Thu Jul 30 14:39:09.642998 2026] [security2:error] [pid 43637:tid 43817] [client 68.221.186.136:4022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/cloud.php"] [unique_id "amuoXYa8U9lZpWaWlJJsNwAAADE"]
[Thu Jul 30 14:39:09.860085 2026] [security2:error] [pid 43637:tid 43894] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuoXYa8U9lZpWaWlJJsKwAAfmE"]
[Thu Jul 30 14:39:10.433431 2026] [security2:error] [pid 43637:tid 43883] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoXYa8U9lZpWaWlJJsPQAAAHM"]
[Thu Jul 30 14:39:10.674901 2026] [autoindex:error] [pid 43637:tid 43818] [client 98.87.102.177:51059] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:39:10.927334 2026] [autoindex:error] [pid 43637:tid 43869] [client 52.202.41.153:1812] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_cfd6e8f6/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:39:11.157739 2026] [security2:error] [pid 43637:tid 43772] [client 180.243.59.178:50223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoX4a8U9lZpWaWlJJsXwAAAAQ"]
[Thu Jul 30 14:39:11.157861 2026] [security2:error] [pid 43637:tid 43772] [client 180.243.59.178:50223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoX4a8U9lZpWaWlJJsXwAAAAQ"]
[Thu Jul 30 14:39:11.847068 2026] [security2:error] [pid 43637:tid 43777] [client 68.221.186.136:4026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuoX4a8U9lZpWaWlJJsbgAAAAk"]
[Thu Jul 30 14:39:12.588300 2026] [security2:error] [pid 43637:tid 43837] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoYIa8U9lZpWaWlJJsdwAAAEU"]
[Thu Jul 30 14:39:13.196752 2026] [security2:error] [pid 43637:tid 43854] [client 68.221.186.136:3980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/updates.php"] [unique_id "amuoYYa8U9lZpWaWlJJskgAAAFY"]
[Thu Jul 30 14:39:13.905629 2026] [security2:error] [pid 43637:tid 43840] [client 194.102.104.29:58342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amuoYYa8U9lZpWaWlJJsnwAAAEg"]
[Thu Jul 30 14:39:14.191680 2026] [security2:error] [pid 43637:tid 43802] [client 185.191.171.16:57422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2023/06/cara-aman-untuk-restart-dan-reboot"] [unique_id "amuoYoa8U9lZpWaWlJJsqAAAACI"]
[Thu Jul 30 14:39:14.191821 2026] [security2:error] [pid 43637:tid 43802] [client 185.191.171.16:57422] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2023/06/cara-aman-untuk-restart-dan-reboot"] [unique_id "amuoYoa8U9lZpWaWlJJsqAAAACI"]
[Thu Jul 30 14:39:14.226320 2026] [security2:error] [pid 43637:tid 43804] [client 194.102.104.29:53831] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/conf/.env"] [unique_id "amuoYoa8U9lZpWaWlJJsqQAAACQ"]
[Thu Jul 30 14:39:14.266885 2026] [security2:error] [pid 43637:tid 43857] [client 52.238.199.152:49632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuoYoa8U9lZpWaWlJJsqgAAAFk"]
[Thu Jul 30 14:39:14.637374 2026] [security2:error] [pid 43637:tid 43894] [client 194.102.104.29:58830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/wp-content/.env"] [unique_id "amuoYoa8U9lZpWaWlJJstQAAAH4"]
[Thu Jul 30 14:39:14.647344 2026] [security2:error] [pid 43637:tid 43885] [client 74.7.175.132:41678] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.xnc.nyx.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuoYoa8U9lZpWaWlJJstgAAdXg"]
[Thu Jul 30 14:39:14.707900 2026] [security2:error] [pid 43637:tid 43771] [client 172.237.109.114:33172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuoYoa8U9lZpWaWlJJspgAAAAM"], referer: https://alseermarine.com:443/index.html
[Thu Jul 30 14:39:14.865850 2026] [security2:error] [pid 43637:tid 43643] [remote 47.128.27.8:59458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/women-pjs-jacket-olive/"] [unique_id "amuoYoa8U9lZpWaWlJJsuAAAMAU"]
[Thu Jul 30 14:39:14.980395 2026] [security2:error] [pid 43637:tid 43788] [client 194.102.104.29:58809] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/wp-admin/.env"] [unique_id "amuoYoa8U9lZpWaWlJJswwAAABQ"]
[Thu Jul 30 14:39:15.502361 2026] [autoindex:error] [pid 43637:tid 43640] [remote 74.7.243.239:51552] AH01276: Cannot serve directory /home2/xncnyxte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:39:15.521307 2026] [security2:error] [pid 43637:tid 43783] [client 189.156.226.90:27585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoY4a8U9lZpWaWlJJs0QAAAA8"]
[Thu Jul 30 14:39:15.521438 2026] [security2:error] [pid 43637:tid 43783] [client 189.156.226.90:27585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoY4a8U9lZpWaWlJJs0QAAAA8"]
[Thu Jul 30 14:39:15.545861 2026] [security2:error] [pid 43637:tid 43873] [client 68.221.186.136:3992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/css/cloud.php"] [unique_id "amuoY4a8U9lZpWaWlJJs1gAAAGk"]
[Thu Jul 30 14:39:15.547372 2026] [security2:error] [pid 43637:tid 43779] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoYoa8U9lZpWaWlJJswQAAAAs"]
[Thu Jul 30 14:39:15.653696 2026] [security2:error] [pid 43637:tid 43781] [client 194.102.104.29:60166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/library/.env"] [unique_id "amuoY4a8U9lZpWaWlJJs1wAAAA0"]
[Thu Jul 30 14:39:15.703167 2026] [security2:error] [pid 43637:tid 43796] [client 52.238.199.152:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/network/admin.php"] [unique_id "amuoY4a8U9lZpWaWlJJs2AAAABw"]
[Thu Jul 30 14:39:16.148540 2026] [security2:error] [pid 43637:tid 43823] [client 68.221.186.136:3983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amuoZIa8U9lZpWaWlJJs4wAAADc"]
[Thu Jul 30 14:39:16.223655 2026] [security2:error] [pid 43637:tid 43879] [client 20.63.98.115:38432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/gmo.php"] [unique_id "amuoZIa8U9lZpWaWlJJs5AAAAG8"]
[Thu Jul 30 14:39:16.554542 2026] [security2:error] [pid 43637:tid 43866] [client 194.102.104.29:52918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "amuoZIa8U9lZpWaWlJJs6wAAAGI"]
[Thu Jul 30 14:39:16.854831 2026] [security2:error] [pid 43637:tid 43815] [client 194.102.104.29:65361] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/vendor/.env"] [unique_id "amuoZIa8U9lZpWaWlJJs8AAAAC8"]
[Thu Jul 30 14:39:17.239263 2026] [security2:error] [pid 43637:tid 43875] [client 194.102.104.29:65256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "amuoZYa8U9lZpWaWlJJs-gAAAGs"]
[Thu Jul 30 14:39:17.345319 2026] [security2:error] [pid 43637:tid 43852] [client 20.63.98.115:49607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/nakrip.php"] [unique_id "amuoZYa8U9lZpWaWlJJs_gAAAFQ"]
[Thu Jul 30 14:39:17.493585 2026] [core:notice] [pid 43637:tid 43806] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:17.781300 2026] [security2:error] [pid 43637:tid 43829] [client 194.102.104.29:62822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "amuoZYa8U9lZpWaWlJJtDAAAAD0"]
[Thu Jul 30 14:39:18.053419 2026] [security2:error] [pid 43637:tid 43828] [client 68.221.186.136:4031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/img/cloud.php"] [unique_id "amuoZoa8U9lZpWaWlJJtEAAAADw"]
[Thu Jul 30 14:39:18.127892 2026] [security2:error] [pid 43637:tid 43779] [client 194.102.104.29:62013] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "amuoZoa8U9lZpWaWlJJtFAAAAAs"]
[Thu Jul 30 14:39:18.253715 2026] [security2:error] [pid 43637:tid 43783] [client 20.63.98.115:44042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/radio.php"] [unique_id "amuoZoa8U9lZpWaWlJJtGQAAAA8"]
[Thu Jul 30 14:39:18.627766 2026] [core:notice] [pid 43637:tid 43755] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:18.736033 2026] [security2:error] [pid 43637:tid 43844] [client 52.238.199.152:49619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuoZoa8U9lZpWaWlJJtKgAAAEw"]
[Thu Jul 30 14:39:18.776180 2026] [security2:error] [pid 43637:tid 43878] [client 194.102.104.29:61320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/blog/.env"] [unique_id "amuoZoa8U9lZpWaWlJJtKwAAAG4"]
[Thu Jul 30 14:39:18.854745 2026] [security2:error] [pid 43637:tid 43782] [client 68.221.186.136:4020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amuoZoa8U9lZpWaWlJJtLAAAAA4"]
[Thu Jul 30 14:39:19.027104 2026] [security2:error] [pid 43637:tid 43796] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoZoa8U9lZpWaWlJJtHQAAABw"]
[Thu Jul 30 14:39:19.437004 2026] [security2:error] [pid 43637:tid 43771] [client 194.102.104.29:65355] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "amuoZ4a8U9lZpWaWlJJtNgAAAAM"]
[Thu Jul 30 14:39:19.677951 2026] [security2:error] [pid 43637:tid 43875] [client 68.221.186.136:4638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuoZ4a8U9lZpWaWlJJtPQAAAGs"]
[Thu Jul 30 14:39:19.890422 2026] [security2:error] [pid 43637:tid 43876] [client 20.63.98.115:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-singin.php"] [unique_id "amuoZ4a8U9lZpWaWlJJtRwAAAGw"]
[Thu Jul 30 14:39:20.079009 2026] [security2:error] [pid 43637:tid 43885] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoZ4a8U9lZpWaWlJJtOQAAAHU"]
[Thu Jul 30 14:39:20.210274 2026] [security2:error] [pid 43637:tid 43880] [client 177.6.106.101:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoaIa8U9lZpWaWlJJtUAAAAHA"]
[Thu Jul 30 14:39:20.210383 2026] [security2:error] [pid 43637:tid 43880] [client 177.6.106.101:53860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoaIa8U9lZpWaWlJJtUAAAAHA"]
[Thu Jul 30 14:39:20.269988 2026] [security2:error] [pid 43637:tid 43806] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoZ4a8U9lZpWaWlJJtQAAAACY"]
[Thu Jul 30 14:39:20.489767 2026] [security2:error] [pid 43637:tid 43810] [client 68.221.186.136:4030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/avaa.php"] [unique_id "amuoaIa8U9lZpWaWlJJtVwAAACo"]
[Thu Jul 30 14:39:20.550064 2026] [security2:error] [pid 43637:tid 43841] [client 194.102.104.29:51421] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "amuoaIa8U9lZpWaWlJJtWAAAAEk"]
[Thu Jul 30 14:39:20.792652 2026] [security2:error] [pid 43637:tid 43821] [client 52.238.199.152:16718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuoaIa8U9lZpWaWlJJtZQAAADU"]
[Thu Jul 30 14:39:20.877515 2026] [security2:error] [pid 43637:tid 43862] [client 180.243.59.178:50719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoaIa8U9lZpWaWlJJtaQAAAF4"]
[Thu Jul 30 14:39:20.877662 2026] [security2:error] [pid 43637:tid 43862] [client 180.243.59.178:50719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoaIa8U9lZpWaWlJJtaQAAAF4"]
[Thu Jul 30 14:39:20.929483 2026] [security2:error] [pid 43637:tid 43777] [client 194.102.104.29:58428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "amuoaIa8U9lZpWaWlJJtagAAAAk"]
[Thu Jul 30 14:39:21.066945 2026] [security2:error] [pid 43637:tid 43811] [client 20.63.98.115:59558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/as.php"] [unique_id "amuoaYa8U9lZpWaWlJJtawAAACs"]
[Thu Jul 30 14:39:21.255848 2026] [security2:error] [pid 43637:tid 43812] [client 194.102.104.29:51684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/app/config/.env"] [unique_id "amuoaYa8U9lZpWaWlJJtcgAAACw"]
[Thu Jul 30 14:39:21.353526 2026] [security2:error] [pid 43637:tid 43694] [remote 57.141.0.37:60122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/Peer-Review-Process"] [unique_id "amuoaYa8U9lZpWaWlJJtcwAAejg"]
[Thu Jul 30 14:39:21.696774 2026] [security2:error] [pid 43637:tid 43876] [client 194.102.104.29:50675] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "amuoaYa8U9lZpWaWlJJtfwAAAGw"]
[Thu Jul 30 14:39:22.024731 2026] [security2:error] [pid 43637:tid 43848] [client 20.63.98.115:38608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/x.php"] [unique_id "amuoaoa8U9lZpWaWlJJthgAAAFA"]
[Thu Jul 30 14:39:22.141024 2026] [security2:error] [pid 43637:tid 43808] [client 194.102.104.29:50767] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/audio/.env"] [unique_id "amuoaoa8U9lZpWaWlJJtiAAAACg"]
[Thu Jul 30 14:39:22.302235 2026] [security2:error] [pid 43637:tid 43785] [client 52.238.199.152:49653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/fonts/wp-login.php"] [unique_id "amuoaoa8U9lZpWaWlJJthwAAABE"]
[Thu Jul 30 14:39:22.453606 2026] [security2:error] [pid 43637:tid 43801] [client 194.102.104.29:58859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/cgi-bin/.env"] [unique_id "amuoaoa8U9lZpWaWlJJtlAAAACE"]
[Thu Jul 30 14:39:22.875662 2026] [security2:error] [pid 43637:tid 43794] [client 194.102.104.29:58001] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "amuoaoa8U9lZpWaWlJJtnwAAABo"]
[Thu Jul 30 14:39:22.940268 2026] [security2:error] [pid 43637:tid 43790] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuoaoa8U9lZpWaWlJJtnQAAABY"]
[Thu Jul 30 14:39:23.033680 2026] [security2:error] [pid 43637:tid 43780] [client 20.63.98.115:34081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/item.php"] [unique_id "amuoa4a8U9lZpWaWlJJtogAAAAw"]
[Thu Jul 30 14:39:23.208784 2026] [security2:error] [pid 43637:tid 43857] [client 194.102.104.29:61932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "amuoa4a8U9lZpWaWlJJtqQAAAFk"]
[Thu Jul 30 14:39:23.332252 2026] [security2:error] [pid 43637:tid 43895] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuoaoa8U9lZpWaWlJJtjgAAfz4"]
[Thu Jul 30 14:39:23.342201 2026] [security2:error] [pid 43637:tid 43879] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuoa4a8U9lZpWaWlJJtpQAAAG8"]
[Thu Jul 30 14:39:23.430562 2026] [security2:error] [pid 43637:tid 43875] [client 68.221.186.136:4625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/images/cloud.php"] [unique_id "amuoa4a8U9lZpWaWlJJtrwAAAGs"]
[Thu Jul 30 14:39:23.547909 2026] [security2:error] [pid 43637:tid 43823] [client 52.238.199.152:49646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/themes.php"] [unique_id "amuoa4a8U9lZpWaWlJJtsQAAADc"]
[Thu Jul 30 14:39:23.577614 2026] [security2:error] [pid 43637:tid 43851] [client 194.102.104.29:59565] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/base/.env"] [unique_id "amuoa4a8U9lZpWaWlJJtsgAAAFM"]
[Thu Jul 30 14:39:23.896787 2026] [security2:error] [pid 43637:tid 43855] [client 194.102.104.29:52094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "amuoa4a8U9lZpWaWlJJtuQAAAFc"]
[Thu Jul 30 14:39:24.009412 2026] [security2:error] [pid 43637:tid 43865] [client 68.221.186.136:4027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amuobIa8U9lZpWaWlJJtvQAAAGE"]
[Thu Jul 30 14:39:24.245886 2026] [security2:error] [pid 43637:tid 43773] [client 194.102.104.29:60304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/vendor/laravel/.env"] [unique_id "amuobIa8U9lZpWaWlJJtwQAAAAU"]
[Thu Jul 30 14:39:24.598330 2026] [core:notice] [pid 43637:tid 43800] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:24.726791 2026] [security2:error] [pid 43637:tid 43880] [client 194.102.104.29:62088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "amuobIa8U9lZpWaWlJJtywAAAHA"]
[Thu Jul 30 14:39:24.829679 2026] [core:notice] [pid 43637:tid 43829] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:25.019928 2026] [security2:error] [pid 43637:tid 43806] [client 68.221.186.136:4024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amuobYa8U9lZpWaWlJJt2AAAACY"]
[Thu Jul 30 14:39:25.027851 2026] [security2:error] [pid 43637:tid 43771] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuobIa8U9lZpWaWlJJtxQAAA1E"]
[Thu Jul 30 14:39:25.055010 2026] [security2:error] [pid 43637:tid 43781] [client 194.102.104.29:61647] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/protected/.env"] [unique_id "amuobYa8U9lZpWaWlJJt2QAAAA0"]
[Thu Jul 30 14:39:25.282101 2026] [security2:error] [pid 43637:tid 43815] [client 20.63.98.115:53344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/app.php"] [unique_id "amuobYa8U9lZpWaWlJJt2wAAAC8"]
[Thu Jul 30 14:39:25.356650 2026] [security2:error] [pid 43637:tid 43790] [client 194.102.104.29:61181] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/newsite/.env"] [unique_id "amuobYa8U9lZpWaWlJJt4QAAABY"]
[Thu Jul 30 14:39:25.594325 2026] [security2:error] [pid 43637:tid 43772] [client 52.238.199.152:17155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/if.php"] [unique_id "amuobYa8U9lZpWaWlJJt7QAAAAQ"]
[Thu Jul 30 14:39:25.616895 2026] [security2:error] [pid 43637:tid 43830] [client 68.221.186.136:4019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amuobYa8U9lZpWaWlJJt7gAAAD4"]
[Thu Jul 30 14:39:25.668988 2026] [security2:error] [pid 43637:tid 43850] [client 194.102.104.29:49496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "amuobYa8U9lZpWaWlJJt7wAAAFI"]
[Thu Jul 30 14:39:25.843489 2026] [core:notice] [pid 43637:tid 43774] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:25.845178 2026] [core:notice] [pid 43637:tid 43838] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:25.868247 2026] [core:notice] [pid 43637:tid 43730] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:25.985419 2026] [security2:error] [pid 43637:tid 43882] [client 194.102.104.29:64620] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/sites/all/libraries/mailchimp/.env"] [unique_id "amuobYa8U9lZpWaWlJJt-QAAAHI"]
[Thu Jul 30 14:39:26.086781 2026] [security2:error] [pid 43637:tid 43866] [client 189.156.226.90:27677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoboa8U9lZpWaWlJJt_QAAAGI"]
[Thu Jul 30 14:39:26.086891 2026] [security2:error] [pid 43637:tid 43866] [client 189.156.226.90:27677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoboa8U9lZpWaWlJJt_QAAAGI"]
[Thu Jul 30 14:39:26.603886 2026] [security2:error] [pid 43637:tid 43880] [client 194.102.104.29:62072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "amuoboa8U9lZpWaWlJJuDQAAAHA"]
[Thu Jul 30 14:39:26.728849 2026] [core:notice] [pid 43637:tid 43661] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:26.757574 2026] [core:notice] [pid 43637:tid 43740] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:26.911741 2026] [security2:error] [pid 43637:tid 43818] [client 194.102.104.29:52683] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "amuoboa8U9lZpWaWlJJuFgAAADI"]
[Thu Jul 30 14:39:27.278268 2026] [security2:error] [pid 43637:tid 43776] [client 68.221.186.136:4004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amuob4a8U9lZpWaWlJJuIAAAAAg"]
[Thu Jul 30 14:39:27.449843 2026] [security2:error] [pid 43637:tid 43872] [client 194.102.104.29:50616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/___proxy_subdomain_cpanel/cpanel.qax.tqa.temporary.site/.env"] [unique_id "amuob4a8U9lZpWaWlJJuJAAAAGg"]
[Thu Jul 30 14:39:27.839713 2026] [security2:error] [pid 43637:tid 43777] [client 68.221.186.136:4002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amuob4a8U9lZpWaWlJJuLwAAAAk"]
[Thu Jul 30 14:39:28.340952 2026] [security2:error] [pid 43637:tid 43826] [client 194.102.104.29:65425] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "cpanel.qax.tqa.temporary.site"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuocIa8U9lZpWaWlJJuPwAAADo"]
[Thu Jul 30 14:39:28.863376 2026] [security2:error] [pid 43637:tid 43862] [client 20.63.98.115:34092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/k.php"] [unique_id "amuocIa8U9lZpWaWlJJuSgAAAF4"]
[Thu Jul 30 14:39:29.022507 2026] [security2:error] [pid 43637:tid 43874] [client 68.221.186.136:4615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/cloud.php"] [unique_id "amuocYa8U9lZpWaWlJJuTgAAAGo"]
[Thu Jul 30 14:39:29.040911 2026] [core:notice] [pid 43637:tid 43824] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:29.187887 2026] [security2:error] [pid 43637:tid 43684] [remote 57.141.0.11:26532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuocYa8U9lZpWaWlJJuUwAAEi4"]
[Thu Jul 30 14:39:30.068327 2026] [security2:error] [pid 43637:tid 43809] [client 68.221.186.136:3321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/updates.php"] [unique_id "amuocoa8U9lZpWaWlJJuXgAAACk"]
[Thu Jul 30 14:39:30.551743 2026] [security2:error] [pid 43637:tid 43869] [client 20.63.98.115:9316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-fmfile.php"] [unique_id "amuocoa8U9lZpWaWlJJubwAAAGU"]
[Thu Jul 30 14:39:30.722516 2026] [security2:error] [pid 43637:tid 43861] [client 52.238.199.152:45571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/editor.php"] [unique_id "amuocoa8U9lZpWaWlJJucwAAAF0"]
[Thu Jul 30 14:39:30.761223 2026] [security2:error] [pid 43637:tid 43650] [remote 97.74.93.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuocoa8U9lZpWaWlJJudQAAUgw"]
[Thu Jul 30 14:39:30.769496 2026] [security2:error] [pid 43637:tid 43787] [client 177.6.106.101:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuocoa8U9lZpWaWlJJudwAAABM"]
[Thu Jul 30 14:39:30.769641 2026] [security2:error] [pid 43637:tid 43787] [client 177.6.106.101:54590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuocoa8U9lZpWaWlJJudwAAABM"]
[Thu Jul 30 14:39:31.022489 2026] [core:notice] [pid 43637:tid 43772] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:31.651376 2026] [security2:error] [pid 43637:tid 43648] [remote 57.141.0.33:27910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55997217192/feed/rss2/"] [unique_id "amuoc4a8U9lZpWaWlJJuiwAAago"]
[Thu Jul 30 14:39:31.738808 2026] [security2:error] [pid 43637:tid 43801] [client 20.63.98.115:53272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wi.php"] [unique_id "amuoc4a8U9lZpWaWlJJujAAAACE"]
[Thu Jul 30 14:39:31.937280 2026] [security2:error] [pid 43637:tid 43779] [client 52.238.199.152:50124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/click.php"] [unique_id "amuoc4a8U9lZpWaWlJJulwAAAAs"]
[Thu Jul 30 14:39:32.447308 2026] [security2:error] [pid 43637:tid 43821] [client 180.243.59.178:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuodIa8U9lZpWaWlJJungAAADU"]
[Thu Jul 30 14:39:32.447426 2026] [security2:error] [pid 43637:tid 43821] [client 180.243.59.178:51312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuodIa8U9lZpWaWlJJungAAADU"]
[Thu Jul 30 14:39:32.507628 2026] [security2:error] [pid 43637:tid 43895] [client 216.244.66.242:36610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingstarenterprises.com"] [uri "/fhoxt/luxury-penthouses-for-rent-nyc-airbnb"] [unique_id "amuodIa8U9lZpWaWlJJuogAAAH8"]
[Thu Jul 30 14:39:32.507721 2026] [security2:error] [pid 43637:tid 43895] [client 216.244.66.242:36610] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kingstarenterprises.com"] [uri "/fhoxt/luxury-penthouses-for-rent-nyc-airbnb"] [unique_id "amuodIa8U9lZpWaWlJJuogAAAH8"]
[Thu Jul 30 14:39:33.103786 2026] [security2:error] [pid 43637:tid 43843] [client 20.63.98.115:9284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/php8.php"] [unique_id "amuodYa8U9lZpWaWlJJurwAAAEs"]
[Thu Jul 30 14:39:33.296561 2026] [security2:error] [pid 43637:tid 43878] [client 52.238.199.152:50116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/test.php7"] [unique_id "amuodYa8U9lZpWaWlJJusAAAAG4"]
[Thu Jul 30 14:39:34.995503 2026] [security2:error] [pid 43637:tid 43818] [client 20.63.98.115:1992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/tes.php"] [unique_id "amuodoa8U9lZpWaWlJJu0gAAADI"]
[Thu Jul 30 14:39:35.723588 2026] [security2:error] [pid 43637:tid 43770] [client 172.237.109.114:52665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuod4a8U9lZpWaWlJJu1gAAAAI"]
[Thu Jul 30 14:39:35.877169 2026] [core:notice] [pid 43637:tid 43774] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:35.899743 2026] [core:notice] [pid 43637:tid 43787] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:35.912742 2026] [security2:error] [pid 43637:tid 43796] [client 192.178.15.68:60288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuod4a8U9lZpWaWlJJu3wAAABw"]
[Thu Jul 30 14:39:36.028362 2026] [security2:error] [pid 43637:tid 43855] [client 20.63.98.115:45965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/about.php"] [unique_id "amuoeIa8U9lZpWaWlJJu8AAAAFc"]
[Thu Jul 30 14:39:36.174848 2026] [security2:error] [pid 43637:tid 43699] [remote 151.158.180.11:51396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.180.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "journeywomenscenter.org"] [uri "/wp-login.php"] [unique_id "amuoeIa8U9lZpWaWlJJu9wAAOz0"]
[Thu Jul 30 14:39:36.189144 2026] [security2:error] [pid 43637:tid 43830] [client 52.238.199.152:16991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuoeIa8U9lZpWaWlJJu-AAAAD4"]
[Thu Jul 30 14:39:36.652946 2026] [security2:error] [pid 43637:tid 43792] [client 189.156.226.90:27032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoeIa8U9lZpWaWlJJvBQAAABg"]
[Thu Jul 30 14:39:36.653082 2026] [security2:error] [pid 43637:tid 43792] [client 189.156.226.90:27032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoeIa8U9lZpWaWlJJvBQAAABg"]
[Thu Jul 30 14:39:36.732973 2026] [core:notice] [pid 43637:tid 43709] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:36.771109 2026] [core:notice] [pid 43637:tid 43708] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:36.907925 2026] [security2:error] [pid 43637:tid 43835] [client 17.241.75.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marlboro-shop.com"] [uri "/index.php"] [unique_id "amuoeIa8U9lZpWaWlJJu8wAAAEM"]
[Thu Jul 30 14:39:37.165884 2026] [security2:error] [pid 43637:tid 43771] [client 184.75.221.59:38442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuoeYa8U9lZpWaWlJJvDgAAAAM"]
[Thu Jul 30 14:39:37.166017 2026] [security2:error] [pid 43637:tid 43771] [client 184.75.221.59:38442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuoeYa8U9lZpWaWlJJvDgAAAAM"]
[Thu Jul 30 14:39:37.320723 2026] [security2:error] [pid 43637:tid 43780] [client 158.158.105.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.105.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jdasecurity.ph"] [uri "/.well-known/about.php"] [unique_id "amuoeYa8U9lZpWaWlJJvEwAAAAw"]
[Thu Jul 30 14:39:37.320829 2026] [security2:error] [pid 43637:tid 43780] [client 158.158.105.63:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jdasecurity.ph"] [uri "/.well-known/about.php"] [unique_id "amuoeYa8U9lZpWaWlJJvEwAAAAw"]
[Thu Jul 30 14:39:37.670833 2026] [security2:error] [pid 43637:tid 43781] [client 20.63.98.115:9299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/headers.php"] [unique_id "amuoeYa8U9lZpWaWlJJvHwAAAA0"]
[Thu Jul 30 14:39:38.162408 2026] [security2:error] [pid 43637:tid 43883] [client 68.221.186.136:3813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amuoeoa8U9lZpWaWlJJvKQAAAHM"]
[Thu Jul 30 14:39:38.598238 2026] [security2:error] [pid 43637:tid 43813] [client 20.63.98.115:53316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/admin.php"] [unique_id "amuoeoa8U9lZpWaWlJJvMgAAAC0"]
[Thu Jul 30 14:39:39.017235 2026] [security2:error] [pid 43637:tid 43873] [client 68.221.186.136:3790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amuoe4a8U9lZpWaWlJJvOwAAAGk"]
[Thu Jul 30 14:39:39.063754 2026] [security2:error] [pid 43637:tid 43876] [client 34.126.128.88:34444] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "arabiandubaisafari.com"] [uri "/"] [unique_id "amuoe4a8U9lZpWaWlJJvPAAAAGw"]
[Thu Jul 30 14:39:40.168720 2026] [security2:error] [pid 43637:tid 43875] [client 20.63.98.115:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/flower.php"] [unique_id "amuofIa8U9lZpWaWlJJvWAAAAGs"]
[Thu Jul 30 14:39:40.332598 2026] [security2:error] [pid 43637:tid 43810] [client 52.238.199.152:16923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/content.php"] [unique_id "amuofIa8U9lZpWaWlJJvXgAAACo"]
[Thu Jul 30 14:39:40.363206 2026] [security2:error] [pid 43637:tid 43811] [client 52.167.144.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuoe4a8U9lZpWaWlJJvVgAAACs"]
[Thu Jul 30 14:39:40.686630 2026] [security2:error] [pid 43637:tid 43807] [client 68.221.186.136:3807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amuofIa8U9lZpWaWlJJvZwAAACc"]
[Thu Jul 30 14:39:40.688933 2026] [security2:error] [pid 43637:tid 43818] [client 177.6.106.101:55480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuofIa8U9lZpWaWlJJvaAAAADI"]
[Thu Jul 30 14:39:40.689045 2026] [security2:error] [pid 43637:tid 43818] [client 177.6.106.101:55480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuofIa8U9lZpWaWlJJvaAAAADI"]
[Thu Jul 30 14:39:41.321316 2026] [security2:error] [pid 43637:tid 43829] [client 20.63.98.115:2024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuofYa8U9lZpWaWlJJvegAAAD0"]
[Thu Jul 30 14:39:41.632947 2026] [security2:error] [pid 43637:tid 43784] [client 216.73.216.110:44510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ajakholding.net"] [uri "/index.php"] [unique_id "amuofYa8U9lZpWaWlJJvfgAAECE"]
[Thu Jul 30 14:39:42.310939 2026] [security2:error] [pid 43637:tid 43847] [client 68.221.186.136:3784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/alfa-rex.php7"] [unique_id "amuofoa8U9lZpWaWlJJvjAAAAE8"]
[Thu Jul 30 14:39:42.813760 2026] [security2:error] [pid 43637:tid 43781] [client 180.243.59.178:51849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuofoa8U9lZpWaWlJJvlQAAAA0"]
[Thu Jul 30 14:39:42.813899 2026] [security2:error] [pid 43637:tid 43781] [client 180.243.59.178:51849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuofoa8U9lZpWaWlJJvlQAAAA0"]
[Thu Jul 30 14:39:43.029269 2026] [security2:error] [pid 43637:tid 43728] [remote 57.141.0.51:28108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/519416797/feed/rss2/"] [unique_id "amuof4a8U9lZpWaWlJJvnwAAZVo"]
[Thu Jul 30 14:39:43.229720 2026] [security2:error] [pid 43637:tid 43860] [client 85.208.96.210:18790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/19/homem-e-assassinado-a-tiros-enquanto-pilotava-moto-em-bayeux/"] [unique_id "amuof4a8U9lZpWaWlJJvoAAAAFw"]
[Thu Jul 30 14:39:43.229933 2026] [security2:error] [pid 43637:tid 43860] [client 85.208.96.210:18790] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/19/homem-e-assassinado-a-tiros-enquanto-pilotava-moto-em-bayeux/"] [unique_id "amuof4a8U9lZpWaWlJJvoAAAAFw"]
[Thu Jul 30 14:39:43.439389 2026] [security2:error] [pid 43637:tid 43820] [client 64.42.179.59:60118] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuof4a8U9lZpWaWlJJvqAAAADQ"]
[Thu Jul 30 14:39:43.439479 2026] [security2:error] [pid 43637:tid 43820] [client 64.42.179.59:60118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuof4a8U9lZpWaWlJJvqAAAADQ"]
[Thu Jul 30 14:39:43.468770 2026] [security2:error] [pid 43637:tid 43773] [client 68.221.186.136:3786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/alfanew.php"] [unique_id "amuof4a8U9lZpWaWlJJvqQAAAAU"]
[Thu Jul 30 14:39:43.772103 2026] [security2:error] [pid 43637:tid 43856] [client 52.238.199.152:16553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known.php"] [unique_id "amuof4a8U9lZpWaWlJJvsAAAAFg"]
[Thu Jul 30 14:39:44.162117 2026] [security2:error] [pid 43637:tid 43799] [client 68.221.186.136:3825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amuogIa8U9lZpWaWlJJvugAAAB8"]
[Thu Jul 30 14:39:44.395148 2026] [security2:error] [pid 43637:tid 43813] [client 20.63.98.115:9707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-content.php"] [unique_id "amuogIa8U9lZpWaWlJJvvgAAAC0"]
[Thu Jul 30 14:39:45.303516 2026] [security2:error] [pid 43637:tid 43667] [remote 57.141.0.7:44586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7399102667/feed/rss2/"] [unique_id "amuogYa8U9lZpWaWlJJv0QAAKR0"]
[Thu Jul 30 14:39:45.337889 2026] [security2:error] [pid 43637:tid 43826] [client 52.238.199.152:16571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "amuogYa8U9lZpWaWlJJv0gAAADo"]
[Thu Jul 30 14:39:45.984778 2026] [security2:error] [pid 43637:tid 43844] [client 68.221.186.136:3837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amuogYa8U9lZpWaWlJJv4gAAAEw"]
[Thu Jul 30 14:39:46.433008 2026] [security2:error] [pid 43637:tid 43660] [remote 97.74.93.24:55380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amuogoa8U9lZpWaWlJJv6QAAMxY"]
[Thu Jul 30 14:39:46.610038 2026] [security2:error] [pid 43637:tid 43887] [client 20.63.98.115:2040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/function.php"] [unique_id "amuogoa8U9lZpWaWlJJv8wAAAHc"]
[Thu Jul 30 14:39:46.918433 2026] [security2:error] [pid 43637:tid 43885] [client 52.238.199.152:16520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/themes/twenty/twenty.php"] [unique_id "amuogoa8U9lZpWaWlJJv9wAAAHU"]
[Thu Jul 30 14:39:47.190785 2026] [security2:error] [pid 43637:tid 43786] [client 189.156.226.90:27281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuog4a8U9lZpWaWlJJv_wAAABI"]
[Thu Jul 30 14:39:47.190919 2026] [security2:error] [pid 43637:tid 43786] [client 189.156.226.90:27281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuog4a8U9lZpWaWlJJv_wAAABI"]
[Thu Jul 30 14:39:47.336531 2026] [security2:error] [pid 43637:tid 43873] [client 20.63.98.115:40764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/chosen.php"] [unique_id "amuog4a8U9lZpWaWlJJwAwAAAGk"]
[Thu Jul 30 14:39:48.053443 2026] [security2:error] [pid 43637:tid 43780] [client 52.238.199.152:16905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amuohIa8U9lZpWaWlJJwEQAAAAw"]
[Thu Jul 30 14:39:48.681047 2026] [security2:error] [pid 43637:tid 43837] [client 68.221.186.136:3792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-p.php7"] [unique_id "amuohIa8U9lZpWaWlJJwHgAAAEU"]
[Thu Jul 30 14:39:49.041588 2026] [security2:error] [pid 43637:tid 43894] [client 52.238.199.152:16547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuohYa8U9lZpWaWlJJwKQAAAH4"]
[Thu Jul 30 14:39:49.383580 2026] [security2:error] [pid 43637:tid 43860] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuohIa8U9lZpWaWlJJwIgAAXAo"]
[Thu Jul 30 14:39:49.505707 2026] [core:notice] [pid 43637:tid 43763] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:39:49.808839 2026] [security2:error] [pid 43637:tid 43807] [client 68.221.186.136:3783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/repeater.php"] [unique_id "amuohYa8U9lZpWaWlJJwOgAAACc"]
[Thu Jul 30 14:39:49.910207 2026] [security2:error] [pid 43637:tid 43891] [client 40.77.167.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuohYa8U9lZpWaWlJJwNgAAAHs"]
[Thu Jul 30 14:39:50.198715 2026] [security2:error] [pid 43637:tid 43810] [client 20.63.98.115:40717] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lilyinspires.com"] [uri "/1.php"] [unique_id "amuohoa8U9lZpWaWlJJwSAAAACo"]
[Thu Jul 30 14:39:50.198837 2026] [security2:error] [pid 43637:tid 43810] [client 20.63.98.115:40717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/1.php"] [unique_id "amuohoa8U9lZpWaWlJJwSAAAACo"]
[Thu Jul 30 14:39:50.493292 2026] [security2:error] [pid 43637:tid 43795] [client 68.221.186.136:3811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-includes/repeater.php"] [unique_id "amuohoa8U9lZpWaWlJJwUgAAABs"]
[Thu Jul 30 14:39:50.936109 2026] [security2:error] [pid 43637:tid 43816] [client 52.238.199.152:16512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuohoa8U9lZpWaWlJJwXAAAADA"]
[Thu Jul 30 14:39:50.993907 2026] [security2:error] [pid 43637:tid 43868] [client 2a03:2880:f800:2a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuohoa8U9lZpWaWlJJwSQAAZHM"]
[Thu Jul 30 14:39:51.112529 2026] [security2:error] [pid 43637:tid 43702] [remote 52.167.144.187:27275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/formation-des-formateurs-des-caa-et-sepj/article.php"] [unique_id "amuohoa8U9lZpWaWlJJwWwAAZUA"]
[Thu Jul 30 14:39:51.657657 2026] [security2:error] [pid 43637:tid 43893] [client 177.6.106.101:56082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoh4a8U9lZpWaWlJJwawAAAH0"]
[Thu Jul 30 14:39:51.695811 2026] [security2:error] [pid 43637:tid 43893] [client 177.6.106.101:56082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoh4a8U9lZpWaWlJJwawAAAH0"]
[Thu Jul 30 14:39:52.110827 2026] [security2:error] [pid 43637:tid 43800] [client 20.63.98.115:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/lv.php"] [unique_id "amuoiIa8U9lZpWaWlJJwdgAAACA"]
[Thu Jul 30 14:39:52.428606 2026] [security2:error] [pid 43637:tid 43808] [client 180.243.59.178:52352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoiIa8U9lZpWaWlJJwfgAAACg"]
[Thu Jul 30 14:39:52.428766 2026] [security2:error] [pid 43637:tid 43808] [client 180.243.59.178:52352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoiIa8U9lZpWaWlJJwfgAAACg"]
[Thu Jul 30 14:39:53.040750 2026] [security2:error] [pid 43637:tid 43788] [client 52.238.199.152:17256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "amuoiYa8U9lZpWaWlJJwigAAABQ"]
[Thu Jul 30 14:39:53.192297 2026] [security2:error] [pid 43637:tid 43776] [client 20.63.98.115:1571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/css.php"] [unique_id "amuoiYa8U9lZpWaWlJJwjgAAAAg"]
[Thu Jul 30 14:39:53.920659 2026] [proxy:error] [pid 43637:tid 43721] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:39:53.920729 2026] [proxy_http:error] [pid 43637:tid 43721] [remote 74.7.175.192:39064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:39:53.921608 2026] [proxy:error] [pid 43637:tid 43721] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:39:53.921670 2026] [proxy_http:error] [pid 43637:tid 43721] [remote 74.7.175.192:39064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:39:54.034170 2026] [security2:error] [pid 43637:tid 43795] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuoiYa8U9lZpWaWlJJwlQAAG0k"]
[Thu Jul 30 14:39:54.049238 2026] [security2:error] [pid 43637:tid 43883] [client 193.124.67.142:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuoiYa8U9lZpWaWlJJwpAAAAHM"], referer: http://cnpinyin.com/experience/chinese-customs/chinese+horoscope+symbols/
[Thu Jul 30 14:39:54.106488 2026] [security2:error] [pid 43637:tid 43840] [client 68.221.186.136:3800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-content/repeater.php"] [unique_id "amuoioa8U9lZpWaWlJJwqQAAAEg"]
[Thu Jul 30 14:39:54.172203 2026] [security2:error] [pid 43637:tid 43713] [remote 57.141.0.11:44050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuoioa8U9lZpWaWlJJwqgAAZUs"]
[Thu Jul 30 14:39:54.206282 2026] [security2:error] [pid 43637:tid 43707] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "amuoioa8U9lZpWaWlJJwqwAAE0U"]
[Thu Jul 30 14:39:54.359525 2026] [core:error] [pid 43637:tid 43700] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:54.359548 2026] [core:error] [pid 43637:tid 43700] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:54.512590 2026] [core:error] [pid 43637:tid 43710] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:54.512622 2026] [core:error] [pid 43637:tid 43710] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:54.530687 2026] [security2:error] [pid 43637:tid 43712] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoioa8U9lZpWaWlJJwtAAAHko"]
[Thu Jul 30 14:39:54.588498 2026] [security2:error] [pid 43637:tid 43696] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoioa8U9lZpWaWlJJwtgAAPjo"]
[Thu Jul 30 14:39:54.624423 2026] [security2:error] [pid 43637:tid 43724] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoioa8U9lZpWaWlJJwuQAAcVY"]
[Thu Jul 30 14:39:54.665519 2026] [core:error] [pid 43637:tid 43644] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:54.665547 2026] [core:error] [pid 43637:tid 43644] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:54.704413 2026] [security2:error] [pid 43637:tid 43880] [client 52.238.199.152:16651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/files.php"] [unique_id "amuoioa8U9lZpWaWlJJwvAAAAHA"]
[Thu Jul 30 14:39:54.816131 2026] [security2:error] [pid 43637:tid 43681] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "amuoioa8U9lZpWaWlJJwvwAAeys"]
[Thu Jul 30 14:39:54.861408 2026] [security2:error] [pid 43637:tid 43865] [client 20.63.98.115:1552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/gecko.php"] [unique_id "amuoioa8U9lZpWaWlJJwwQAAAGE"]
[Thu Jul 30 14:39:54.968102 2026] [core:error] [pid 43637:tid 43676] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:54.968124 2026] [core:error] [pid 43637:tid 43676] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:55.107045 2026] [security2:error] [pid 43637:tid 43698] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/.env"] [unique_id "amuoi4a8U9lZpWaWlJJwzwAAFjw"]
[Thu Jul 30 14:39:55.118519 2026] [security2:error] [pid 43637:tid 43697] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "amuoi4a8U9lZpWaWlJJw0AAAajs"]
[Thu Jul 30 14:39:55.319322 2026] [security2:error] [pid 43637:tid 43719] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoi4a8U9lZpWaWlJJw2QAAaFE"]
[Thu Jul 30 14:39:55.393767 2026] [security2:error] [pid 43637:tid 43751] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuoi4a8U9lZpWaWlJJw4QAARHE"]
[Thu Jul 30 14:39:55.445639 2026] [security2:error] [pid 43637:tid 43743] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoi4a8U9lZpWaWlJJw6AAASWk"]
[Thu Jul 30 14:39:55.520472 2026] [security2:error] [pid 43637:tid 43758] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuoi4a8U9lZpWaWlJJw6QAAG3c"]
[Thu Jul 30 14:39:55.527729 2026] [security2:error] [pid 43637:tid 43671] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuoi4a8U9lZpWaWlJJw6wAARyE"]
[Thu Jul 30 14:39:55.686675 2026] [security2:error] [pid 43637:tid 43720] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuoi4a8U9lZpWaWlJJw8wAAE1I"]
[Thu Jul 30 14:39:55.803117 2026] [security2:error] [pid 43637:tid 43645] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoi4a8U9lZpWaWlJJw7QAANwc"]
[Thu Jul 30 14:39:55.829323 2026] [security2:error] [pid 43637:tid 43740] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoi4a8U9lZpWaWlJJw_AAAPmY"]
[Thu Jul 30 14:39:55.831260 2026] [security2:error] [pid 43637:tid 43654] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuoi4a8U9lZpWaWlJJw_QAAcRA"]
[Thu Jul 30 14:39:55.841313 2026] [security2:error] [pid 43637:tid 43642] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuoi4a8U9lZpWaWlJJw_wAAdwQ"]
[Thu Jul 30 14:39:55.906823 2026] [security2:error] [pid 43637:tid 43726] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoi4a8U9lZpWaWlJJxBQAAXFg"]
[Thu Jul 30 14:39:55.962891 2026] [core:error] [pid 43637:tid 43752] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:55.962913 2026] [core:error] [pid 43637:tid 43752] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:55.984085 2026] [security2:error] [pid 43637:tid 43663] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoi4a8U9lZpWaWlJJxDQAAdBk"]
[Thu Jul 30 14:39:55.989374 2026] [security2:error] [pid 43637:tid 43747] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoi4a8U9lZpWaWlJJxDgAAbG0"]
[Thu Jul 30 14:39:56.113326 2026] [security2:error] [pid 43637:tid 43746] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "amuojIa8U9lZpWaWlJJxFAAAQmw"]
[Thu Jul 30 14:39:56.120266 2026] [security2:error] [pid 43637:tid 43890] [client 20.63.98.115:1547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xmlrpc.php"] [unique_id "amuoi4a8U9lZpWaWlJJxAQAAAHo"]
[Thu Jul 30 14:39:56.127149 2026] [security2:error] [pid 43637:tid 43657] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuojIa8U9lZpWaWlJJxFgAAHxM"]
[Thu Jul 30 14:39:56.216201 2026] [security2:error] [pid 43637:tid 43660] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/api/.env"] [unique_id "amuojIa8U9lZpWaWlJJxIQAATxY"]
[Thu Jul 30 14:39:56.269022 2026] [core:error] [pid 43637:tid 43682] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:56.269056 2026] [core:error] [pid 43637:tid 43682] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:56.276668 2026] [security2:error] [pid 43637:tid 43640] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuojIa8U9lZpWaWlJJxJQAAaQI"]
[Thu Jul 30 14:39:56.289420 2026] [security2:error] [pid 43637:tid 43670] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuojIa8U9lZpWaWlJJxJgAAFCA"]
[Thu Jul 30 14:39:56.305789 2026] [security2:error] [pid 43637:tid 43748] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuojIa8U9lZpWaWlJJxJwAAUG4"]
[Thu Jul 30 14:39:56.314354 2026] [security2:error] [pid 43637:tid 43658] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuojIa8U9lZpWaWlJJxKAAACBQ"]
[Thu Jul 30 14:39:56.419737 2026] [security2:error] [pid 43637:tid 43664] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuojIa8U9lZpWaWlJJxLwAAWRo"]
[Thu Jul 30 14:39:56.420216 2026] [security2:error] [pid 43637:tid 43766] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "amuojIa8U9lZpWaWlJJxLgAAeH8"]
[Thu Jul 30 14:39:56.429186 2026] [security2:error] [pid 43637:tid 43772] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoi4a8U9lZpWaWlJJw-wAAAAQ"]
[Thu Jul 30 14:39:56.561826 2026] [security2:error] [pid 43637:tid 43757] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/dev/.env"] [unique_id "amuojIa8U9lZpWaWlJJxOgAAf3Y"]
[Thu Jul 30 14:39:56.572316 2026] [core:error] [pid 43637:tid 43648] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:56.572333 2026] [core:error] [pid 43637:tid 43648] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:56.592253 2026] [security2:error] [pid 43637:tid 43673] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuojIa8U9lZpWaWlJJxPQAAHCM"]
[Thu Jul 30 14:39:56.606533 2026] [security2:error] [pid 43637:tid 43763] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuojIa8U9lZpWaWlJJxPgAALnw"]
[Thu Jul 30 14:39:56.610361 2026] [security2:error] [pid 43637:tid 43741] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuojIa8U9lZpWaWlJJxPwAAa2c"]
[Thu Jul 30 14:39:56.626171 2026] [security2:error] [pid 43637:tid 43755] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuojIa8U9lZpWaWlJJxQAAACXU"]
[Thu Jul 30 14:39:56.719385 2026] [security2:error] [pid 43637:tid 43678] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuojIa8U9lZpWaWlJJxQwAAcyg"]
[Thu Jul 30 14:39:56.727337 2026] [core:error] [pid 43637:tid 43679] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:56.727362 2026] [core:error] [pid 43637:tid 43679] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:56.749003 2026] [security2:error] [pid 43637:tid 43754] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuojIa8U9lZpWaWlJJxRgAAYHQ"]
[Thu Jul 30 14:39:56.757806 2026] [security2:error] [pid 43637:tid 43683] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuojIa8U9lZpWaWlJJxSQAAeS0"]
[Thu Jul 30 14:39:56.779130 2026] [security2:error] [pid 43637:tid 43775] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuojIa8U9lZpWaWlJJxHQAAAAc"]
[Thu Jul 30 14:39:56.796452 2026] [security2:error] [pid 43637:tid 43687] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuojIa8U9lZpWaWlJJxTgAAUzE"]
[Thu Jul 30 14:39:56.865312 2026] [security2:error] [pid 43637:tid 43753] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuojIa8U9lZpWaWlJJxTwAAM3M"]
[Thu Jul 30 14:39:56.880229 2026] [security2:error] [pid 43637:tid 43702] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "amuojIa8U9lZpWaWlJJxUQAAKUA"]
[Thu Jul 30 14:39:57.010456 2026] [security2:error] [pid 43637:tid 43693] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuojYa8U9lZpWaWlJJxYAAAezc"]
[Thu Jul 30 14:39:57.032593 2026] [security2:error] [pid 43637:tid 43699] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "amuojYa8U9lZpWaWlJJxYQAAAT0"]
[Thu Jul 30 14:39:57.058384 2026] [security2:error] [pid 43637:tid 43718] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuojYa8U9lZpWaWlJJxYwAAF1A"]
[Thu Jul 30 14:39:57.058516 2026] [security2:error] [pid 43637:tid 43736] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuojYa8U9lZpWaWlJJxYgAAcGI"]
[Thu Jul 30 14:39:57.062456 2026] [security2:error] [pid 43637:tid 43651] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/laravel/.env"] [unique_id "amuojYa8U9lZpWaWlJJxZAAAGA0"]
[Thu Jul 30 14:39:57.077523 2026] [security2:error] [pid 43637:tid 43694] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuojYa8U9lZpWaWlJJxZQAAZzg"]
[Thu Jul 30 14:39:57.107499 2026] [security2:error] [pid 43637:tid 43691] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuojYa8U9lZpWaWlJJxZgAAITU"]
[Thu Jul 30 14:39:57.119196 2026] [security2:error] [pid 43637:tid 43705] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuojYa8U9lZpWaWlJJxZwAAYUM"]
[Thu Jul 30 14:39:57.153462 2026] [security2:error] [pid 43637:tid 43703] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuojYa8U9lZpWaWlJJxaAAAdUE"]
[Thu Jul 30 14:39:57.182957 2026] [security2:error] [pid 43637:tid 43709] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "amuojYa8U9lZpWaWlJJxaQAAdEc"]
[Thu Jul 30 14:39:57.203492 2026] [security2:error] [pid 43637:tid 43708] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuojYa8U9lZpWaWlJJxagAAEUY"]
[Thu Jul 30 14:39:57.250419 2026] [security2:error] [pid 43637:tid 43713] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuojYa8U9lZpWaWlJJxcQAAeks"]
[Thu Jul 30 14:39:57.262180 2026] [security2:error] [pid 43637:tid 43707] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuojYa8U9lZpWaWlJJxcwAALEU"]
[Thu Jul 30 14:39:57.324547 2026] [autoindex:error] [pid 43637:tid 43835] [client 85.215.116.8:57928] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:39:57.329762 2026] [core:error] [pid 43637:tid 43700] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:57.329778 2026] [core:error] [pid 43637:tid 43700] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:57.355930 2026] [security2:error] [pid 43637:tid 43680] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuojYa8U9lZpWaWlJJxdwAAUio"]
[Thu Jul 30 14:39:57.356148 2026] [security2:error] [pid 43637:tid 43710] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuojYa8U9lZpWaWlJJxeAAAT0g"]
[Thu Jul 30 14:39:57.404286 2026] [security2:error] [pid 43637:tid 43696] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuojYa8U9lZpWaWlJJxegAASjo"]
[Thu Jul 30 14:39:57.404344 2026] [security2:error] [pid 43637:tid 43724] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuojYa8U9lZpWaWlJJxewAAJVY"]
[Thu Jul 30 14:39:57.416898 2026] [security2:error] [pid 43637:tid 43714] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/backend/.env"] [unique_id "amuojYa8U9lZpWaWlJJxfAAAEEw"]
[Thu Jul 30 14:39:57.449057 2026] [security2:error] [pid 43637:tid 43681] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuojYa8U9lZpWaWlJJxgAAAaSs"]
[Thu Jul 30 14:39:57.486946 2026] [security2:error] [pid 43637:tid 43677] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "amuojYa8U9lZpWaWlJJxgQAACic"]
[Thu Jul 30 14:39:57.564341 2026] [security2:error] [pid 43637:tid 43698] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuojYa8U9lZpWaWlJJxjQAAADw"]
[Thu Jul 30 14:39:57.592626 2026] [security2:error] [pid 43637:tid 43697] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuojYa8U9lZpWaWlJJxjgAANTs"]
[Thu Jul 30 14:39:57.636380 2026] [security2:error] [pid 43637:tid 43761] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuojYa8U9lZpWaWlJJxjwAAaHo"]
[Thu Jul 30 14:39:57.661304 2026] [security2:error] [pid 43637:tid 43638] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuojYa8U9lZpWaWlJJxkAAAXQA"]
[Thu Jul 30 14:39:57.718969 2026] [security2:error] [pid 43637:tid 43735] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuojYa8U9lZpWaWlJJxkgAARGE"]
[Thu Jul 30 14:39:57.774042 2026] [security2:error] [pid 43637:tid 43843] [client 189.156.226.90:27633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuojYa8U9lZpWaWlJJxlwAAAEs"]
[Thu Jul 30 14:39:57.774144 2026] [security2:error] [pid 43637:tid 43843] [client 189.156.226.90:27633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuojYa8U9lZpWaWlJJxlwAAAEs"]
[Thu Jul 30 14:39:57.788694 2026] [core:error] [pid 43637:tid 43751] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:57.788711 2026] [core:error] [pid 43637:tid 43751] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:57.803242 2026] [security2:error] [pid 43637:tid 43730] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuojYa8U9lZpWaWlJJxnAAAf1w"]
[Thu Jul 30 14:39:57.861801 2026] [security2:error] [pid 43637:tid 43743] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuojYa8U9lZpWaWlJJxnQAALmk"]
[Thu Jul 30 14:39:57.867053 2026] [security2:error] [pid 43637:tid 43646] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuojYa8U9lZpWaWlJJxngAAawg"]
[Thu Jul 30 14:39:57.885162 2026] [security2:error] [pid 43637:tid 43758] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuojYa8U9lZpWaWlJJxnwAAY3c"]
[Thu Jul 30 14:39:57.914763 2026] [security2:error] [pid 43637:tid 43671] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuojYa8U9lZpWaWlJJxoAAACSE"]
[Thu Jul 30 14:39:57.923913 2026] [security2:error] [pid 43637:tid 43808] [client 20.63.98.115:52839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/f35.php"] [unique_id "amuojYa8U9lZpWaWlJJxoQAAACg"]
[Thu Jul 30 14:39:57.939488 2026] [security2:error] [pid 43637:tid 43729] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/images/.env"] [unique_id "amuojYa8U9lZpWaWlJJxogAADls"]
[Thu Jul 30 14:39:57.967117 2026] [security2:error] [pid 43637:tid 43639] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/web/.env"] [unique_id "amuojYa8U9lZpWaWlJJxpgAAYAE"]
[Thu Jul 30 14:39:58.065009 2026] [security2:error] [pid 43637:tid 43740] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuojoa8U9lZpWaWlJJxsAAAYmY"]
[Thu Jul 30 14:39:58.091996 2026] [core:error] [pid 43637:tid 43654] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:58.092015 2026] [core:error] [pid 43637:tid 43654] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:58.104728 2026] [security2:error] [pid 43637:tid 43642] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuojoa8U9lZpWaWlJJxsgAAMwQ"]
[Thu Jul 30 14:39:58.126583 2026] [security2:error] [pid 43637:tid 43659] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/.env.bak"] [unique_id "amuojoa8U9lZpWaWlJJxswAAVBU"]
[Thu Jul 30 14:39:58.176537 2026] [security2:error] [pid 43637:tid 43726] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuojoa8U9lZpWaWlJJxtQAAWlg"]
[Thu Jul 30 14:39:58.215450 2026] [security2:error] [pid 43637:tid 43745] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuojoa8U9lZpWaWlJJxtwAAC2s"]
[Thu Jul 30 14:39:58.244623 2026] [core:error] [pid 43637:tid 43752] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:58.244642 2026] [core:error] [pid 43637:tid 43752] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:58.271919 2026] [security2:error] [pid 43637:tid 43669] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/staging/.env"] [unique_id "amuojoa8U9lZpWaWlJJxvQAAMh8"]
[Thu Jul 30 14:39:58.331873 2026] [security2:error] [pid 43637:tid 43652] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuojoa8U9lZpWaWlJJxxQAAXg4"]
[Thu Jul 30 14:39:58.332617 2026] [security2:error] [pid 43637:tid 43746] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuojoa8U9lZpWaWlJJxxgAAFWw"]
[Thu Jul 30 14:39:58.395825 2026] [security2:error] [pid 43637:tid 43657] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/API/.env"] [unique_id "amuojoa8U9lZpWaWlJJxyQAAARM"]
[Thu Jul 30 14:39:58.477383 2026] [security2:error] [pid 43637:tid 43660] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuojoa8U9lZpWaWlJJxzwAAIRY"]
[Thu Jul 30 14:39:58.485443 2026] [security2:error] [pid 43637:tid 43684] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuojoa8U9lZpWaWlJJx0AAAYS4"]
[Thu Jul 30 14:39:58.547427 2026] [security2:error] [pid 43637:tid 43737] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "amuojoa8U9lZpWaWlJJx2AAALWM"]
[Thu Jul 30 14:39:58.550241 2026] [security2:error] [pid 43637:tid 43670] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuojoa8U9lZpWaWlJJx2QAAEiA"]
[Thu Jul 30 14:39:58.559812 2026] [security2:error] [pid 43637:tid 43748] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuojoa8U9lZpWaWlJJx2gAAGm4"]
[Thu Jul 30 14:39:58.626718 2026] [security2:error] [pid 43637:tid 43739] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/core/.env"] [unique_id "amuojoa8U9lZpWaWlJJx3AAAT2U"]
[Thu Jul 30 14:39:58.629212 2026] [security2:error] [pid 43637:tid 43664] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuojoa8U9lZpWaWlJJx3QAASho"]
[Thu Jul 30 14:39:58.661781 2026] [security2:error] [pid 43637:tid 43650] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuojoa8U9lZpWaWlJJx3wAAQQw"]
[Thu Jul 30 14:39:58.699488 2026] [security2:error] [pid 43637:tid 43668] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuojoa8U9lZpWaWlJJx4QAAKh4"]
[Thu Jul 30 14:39:58.701140 2026] [core:error] [pid 43637:tid 43728] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:58.701158 2026] [core:error] [pid 43637:tid 43728] [remote 77.90.185.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:39:58.703896 2026] [security2:error] [pid 43637:tid 43675] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuojoa8U9lZpWaWlJJx4gAAAyU"]
[Thu Jul 30 14:39:58.784061 2026] [security2:error] [pid 43637:tid 43749] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuojoa8U9lZpWaWlJJx5QAAUG8"]
[Thu Jul 30 14:39:58.805512 2026] [security2:error] [pid 43637:tid 43762] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuojoa8U9lZpWaWlJJx5gAACHs"]
[Thu Jul 30 14:39:58.806699 2026] [security2:error] [pid 43637:tid 43686] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuojoa8U9lZpWaWlJJx6AAAPDA"]
[Thu Jul 30 14:39:58.846089 2026] [security2:error] [pid 43637:tid 43823] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuojoa8U9lZpWaWlJJxvAAAADc"]
[Thu Jul 30 14:39:58.940936 2026] [security2:error] [pid 43637:tid 43744] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuojoa8U9lZpWaWlJJx9AAARGo"]
[Thu Jul 30 14:39:58.955148 2026] [security2:error] [pid 43637:tid 43655] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuojoa8U9lZpWaWlJJx-QAAVRE"]
[Thu Jul 30 14:39:59.033642 2026] [security2:error] [pid 43637:tid 43679] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuoj4a8U9lZpWaWlJJx-gAADSk"]
[Thu Jul 30 14:39:59.084770 2026] [security2:error] [pid 43637:tid 43764] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuoj4a8U9lZpWaWlJJx_gAAY30"]
[Thu Jul 30 14:39:59.101138 2026] [security2:error] [pid 43637:tid 43683] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuoj4a8U9lZpWaWlJJx_wAADi0"]
[Thu Jul 30 14:39:59.136827 2026] [security2:error] [pid 43637:tid 43662] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/images/.env"] [unique_id "amuoj4a8U9lZpWaWlJJyAAAAYBg"]
[Thu Jul 30 14:39:59.170867 2026] [security2:error] [pid 43637:tid 43840] [client 20.63.98.115:39627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/autoload_classmap.php"] [unique_id "amuoj4a8U9lZpWaWlJJyAQAAAEg"]
[Thu Jul 30 14:39:59.396706 2026] [security2:error] [pid 43637:tid 43706] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuoj4a8U9lZpWaWlJJyEQAAWkQ"]
[Thu Jul 30 14:39:59.398480 2026] [security2:error] [pid 43637:tid 43695] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuoj4a8U9lZpWaWlJJyEwAAUTk"]
[Thu Jul 30 14:39:59.473017 2026] [security2:error] [pid 43637:tid 43889] [client 52.238.199.152:52462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/Text/index.php"] [unique_id "amuoj4a8U9lZpWaWlJJyGAAAAHk"]
[Thu Jul 30 14:39:59.493426 2026] [proxy:error] [pid 43637:tid 43845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:39:59.493501 2026] [proxy_http:error] [pid 43637:tid 43845] [client 24.199.98.76:48578] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:39:59.494083 2026] [proxy:error] [pid 43637:tid 43845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:39:59.494128 2026] [proxy_http:error] [pid 43637:tid 43845] [client 24.199.98.76:48578] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:39:59.543506 2026] [security2:error] [pid 43637:tid 43693] [remote 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuoj4a8U9lZpWaWlJJyHAAAfTc"]
[Thu Jul 30 14:39:59.553143 2026] [security2:error] [pid 43637:tid 43701] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuoj4a8U9lZpWaWlJJyHQAAPT8"]
[Thu Jul 30 14:39:59.683890 2026] [security2:error] [pid 43637:tid 43699] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/API/.env"] [unique_id "amuoj4a8U9lZpWaWlJJyIQAAIT0"]
[Thu Jul 30 14:39:59.702968 2026] [security2:error] [pid 43637:tid 43736] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuoj4a8U9lZpWaWlJJyIwAAJ2I"]
[Thu Jul 30 14:39:59.837637 2026] [security2:error] [pid 43637:tid 43694] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/app/.env"] [unique_id "amuoj4a8U9lZpWaWlJJyJQAAETg"]
[Thu Jul 30 14:39:59.840531 2026] [security2:error] [pid 43637:tid 43691] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuoj4a8U9lZpWaWlJJyJgAAJjU"]
[Thu Jul 30 14:39:59.860025 2026] [security2:error] [pid 43637:tid 43703] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuoj4a8U9lZpWaWlJJyKQAAHUE"]
[Thu Jul 30 14:40:00.012019 2026] [security2:error] [pid 43637:tid 43713] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuokIa8U9lZpWaWlJJyMgAAeks"]
[Thu Jul 30 14:40:00.103214 2026] [proxy:error] [pid 43637:tid 43848] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:40:00.103291 2026] [proxy_http:error] [pid 43637:tid 43848] [client 24.199.98.76:58400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.bonafideadvisors.com/
[Thu Jul 30 14:40:00.104133 2026] [proxy:error] [pid 43637:tid 43848] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:40:00.104195 2026] [proxy_http:error] [pid 43637:tid 43848] [client 24.199.98.76:58400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.bonafideadvisors.com/
[Thu Jul 30 14:40:00.297294 2026] [security2:error] [pid 43637:tid 43700] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuokIa8U9lZpWaWlJJyPAAAPD4"]
[Thu Jul 30 14:40:00.444024 2026] [security2:error] [pid 43637:tid 43696] [remote 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuokIa8U9lZpWaWlJJyQwAACjo"]
[Thu Jul 30 14:40:00.673950 2026] [security2:error] [pid 43637:tid 43771] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuokIa8U9lZpWaWlJJyOAAAAAM"]
[Thu Jul 30 14:40:01.054988 2026] [proxy:error] [pid 43637:tid 43825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:40:01.055046 2026] [proxy_http:error] [pid 43637:tid 43825] [client 24.199.98.76:56140] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:40:01.055614 2026] [proxy:error] [pid 43637:tid 43825] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:40:01.055658 2026] [proxy_http:error] [pid 43637:tid 43825] [client 24.199.98.76:56140] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:40:01.360347 2026] [security2:error] [pid 43637:tid 43894] [client 52.238.199.152:16808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuokYa8U9lZpWaWlJJyWAAAAH4"]
[Thu Jul 30 14:40:01.438526 2026] [core:notice] [pid 43637:tid 43817] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:01.563099 2026] [core:notice] [pid 43637:tid 43892] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:01.637924 2026] [security2:error] [pid 43637:tid 43875] [client 20.63.98.115:62902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/NewFile.php"] [unique_id "amuokYa8U9lZpWaWlJJyYwAAAGs"]
[Thu Jul 30 14:40:02.064024 2026] [core:notice] [pid 43637:tid 43769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:02.273709 2026] [core:notice] [pid 43637:tid 43850] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:02.441036 2026] [security2:error] [pid 43637:tid 43785] [client 20.63.98.115:3750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xx.php"] [unique_id "amuokoa8U9lZpWaWlJJycwAAABE"]
[Thu Jul 30 14:40:02.482426 2026] [core:notice] [pid 43637:tid 43777] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:02.691146 2026] [core:notice] [pid 43637:tid 43888] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:02.896729 2026] [security2:error] [pid 43637:tid 43810] [client 20.65.193.1:59086] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.6.43.248"] [uri "/index.cgi"] [unique_id "amuokoa8U9lZpWaWlJJygwAAACo"]
[Thu Jul 30 14:40:02.900212 2026] [core:notice] [pid 43637:tid 43853] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:03.016694 2026] [security2:error] [pid 43637:tid 43838] [client 57.141.0.31:45192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuokYa8U9lZpWaWlJJyTwAARic"]
[Thu Jul 30 14:40:03.112895 2026] [core:notice] [pid 43637:tid 43792] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:03.307504 2026] [security2:error] [pid 43637:tid 43743] [remote 20.100.187.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuok4a8U9lZpWaWlJJykAAAXWk"]
[Thu Jul 30 14:40:03.321871 2026] [core:notice] [pid 43637:tid 43787] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:03.464514 2026] [core:notice] [pid 43637:tid 43844] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:03.530949 2026] [core:notice] [pid 43637:tid 43894] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:03.674513 2026] [security2:error] [pid 43637:tid 43879] [client 180.243.59.178:52921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuok4a8U9lZpWaWlJJymgAAAG8"]
[Thu Jul 30 14:40:03.674712 2026] [security2:error] [pid 43637:tid 43879] [client 180.243.59.178:52921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuok4a8U9lZpWaWlJJymgAAAG8"]
[Thu Jul 30 14:40:03.725484 2026] [security2:error] [pid 43637:tid 43839] [client 20.63.98.115:50433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/plugins.php"] [unique_id "amuok4a8U9lZpWaWlJJymwAAAEc"]
[Thu Jul 30 14:40:03.740094 2026] [core:notice] [pid 43637:tid 43863] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:03.764948 2026] [security2:error] [pid 43637:tid 43729] [remote 20.100.187.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/flower.php"] [unique_id "amuok4a8U9lZpWaWlJJynwAAGVs"]
[Thu Jul 30 14:40:04.009681 2026] [security2:error] [pid 43637:tid 43809] [client 172.237.109.114:12082] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amuolIa8U9lZpWaWlJJypwAAACk"]
[Thu Jul 30 14:40:04.210499 2026] [security2:error] [pid 43637:tid 43642] [remote 20.100.187.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/xleet.php"] [unique_id "amuolIa8U9lZpWaWlJJyrwAAOAQ"]
[Thu Jul 30 14:40:04.221004 2026] [security2:error] [pid 43637:tid 43849] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuok4a8U9lZpWaWlJJymQAAAFE"]
[Thu Jul 30 14:40:04.515893 2026] [core:notice] [pid 43637:tid 43653] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:04.570308 2026] [core:error] [pid 43637:tid 43745] (36)File name too long: [remote 142.147.200.165:53590] AH00036: access to /&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;42&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N/A&quot;,&quot;display_price&quot;:129,&quot;display_regular_price&quot;:129,&quot;image&quot;:{&quot;title&quot;:&quot;image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp&quot;,&quot;caption&quot;:&quot;&quot;,&quot;url&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/05/image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp&quot;,&quot;alt&quot;:&quot;image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp&quot;,&quot;src&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/05/image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp&quot;,&quot;srcset&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/05/image_38b8a3be-0a85-46da-bbf6-5756d1f2589c_720x480-600x400-1.webp failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;42&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N'), referer: https://kicksity.com/product/louis-vuitton-slides-white/
[Thu Jul 30 14:40:04.667482 2026] [security2:error] [pid 43637:tid 43882] [client 20.63.98.115:52817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xxx.php"] [unique_id "amuolIa8U9lZpWaWlJJyvQAAAHI"]
[Thu Jul 30 14:40:04.746291 2026] [security2:error] [pid 43637:tid 43669] [remote 20.100.187.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saptora.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuolIa8U9lZpWaWlJJyvgAAOh8"]
[Thu Jul 30 14:40:04.848764 2026] [security2:error] [pid 43637:tid 43742] [remote 185.191.171.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fantasynamelist.com"] [uri "/character-class/ranger-name-generator/"] [unique_id "amuolIa8U9lZpWaWlJJyxQAAW2g"]
[Thu Jul 30 14:40:04.848932 2026] [security2:error] [pid 43637:tid 43859] [client 185.191.171.15:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fantasynamelist.com"] [uri "/character-class/ranger-name-generator/"] [unique_id "amuolIa8U9lZpWaWlJJyxQAAW2g"]
[Thu Jul 30 14:40:05.301988 2026] [core:notice] [pid 43637:tid 43773] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:05.411263 2026] [security2:error] [pid 43637:tid 43842] [client 177.6.106.101:57103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuolYa8U9lZpWaWlJJy2AAAAEo"]
[Thu Jul 30 14:40:05.411537 2026] [security2:error] [pid 43637:tid 43842] [client 177.6.106.101:57103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuolYa8U9lZpWaWlJJy2AAAAEo"]
[Thu Jul 30 14:40:05.603526 2026] [security2:error] [pid 43637:tid 43881] [client 20.63.98.115:3721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/css.php"] [unique_id "amuolYa8U9lZpWaWlJJy2wAAAHE"]
[Thu Jul 30 14:40:06.135246 2026] [core:notice] [pid 43637:tid 43640] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:06.646312 2026] [security2:error] [pid 43637:tid 43831] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoloa8U9lZpWaWlJJy6QAAAD8"]
[Thu Jul 30 14:40:06.661196 2026] [security2:error] [pid 43637:tid 43884] [client 52.238.199.152:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuoloa8U9lZpWaWlJJy9AAAAHQ"]
[Thu Jul 30 14:40:06.841619 2026] [proxy:error] [pid 43637:tid 43882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:40:06.841707 2026] [proxy_http:error] [pid 43637:tid 43882] [client 24.199.98.76:56260] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.bonafideadvisors.com/
[Thu Jul 30 14:40:06.842411 2026] [proxy:error] [pid 43637:tid 43882] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:40:06.842461 2026] [proxy_http:error] [pid 43637:tid 43882] [client 24.199.98.76:56260] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.bonafideadvisors.com/
[Thu Jul 30 14:40:07.174605 2026] [security2:error] [pid 43637:tid 43675] [remote 74.7.243.224:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amuol4a8U9lZpWaWlJJzAwAAUCU"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:40:07.213894 2026] [security2:error] [pid 43637:tid 43808] [client 20.63.98.115:50443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuol4a8U9lZpWaWlJJzBQAAACg"]
[Thu Jul 30 14:40:07.635850 2026] [security2:error] [pid 43637:tid 43818] [client 52.238.199.152:50449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ws.php"] [unique_id "amuol4a8U9lZpWaWlJJzDgAAADI"]
[Thu Jul 30 14:40:07.736181 2026] [core:notice] [pid 43637:tid 43858] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:08.034233 2026] [security2:error] [pid 43637:tid 43860] [client 20.63.98.115:3768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuomIa8U9lZpWaWlJJzHQAAAFw"]
[Thu Jul 30 14:40:08.134995 2026] [core:notice] [pid 43637:tid 43648] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:08.274306 2026] [security2:error] [pid 43637:tid 43777] [client 189.156.226.90:26821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuomIa8U9lZpWaWlJJzIgAAAAk"]
[Thu Jul 30 14:40:08.274416 2026] [security2:error] [pid 43637:tid 43777] [client 189.156.226.90:26821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuomIa8U9lZpWaWlJJzIgAAAAk"]
[Thu Jul 30 14:40:08.590196 2026] [core:notice] [pid 43637:tid 43741] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:08.591367 2026] [security2:error] [pid 43637:tid 43800] [client 52.238.199.152:50444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-config-sample.php"] [unique_id "amuomIa8U9lZpWaWlJJzKwAAACA"]
[Thu Jul 30 14:40:09.021637 2026] [core:notice] [pid 43637:tid 43755] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:09.131495 2026] [security2:error] [pid 43637:tid 43841] [client 20.63.98.115:39624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuomYa8U9lZpWaWlJJzNwAAAEk"]
[Thu Jul 30 14:40:09.540537 2026] [security2:error] [pid 43637:tid 43829] [client 216.73.217.139:10561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tmrfsl.com"] [uri "/index.php"] [unique_id "amuomYa8U9lZpWaWlJJzPQAAPS0"]
[Thu Jul 30 14:40:09.824964 2026] [security2:error] [pid 43637:tid 43824] [client 216.73.217.139:10561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tmrfsl.com"] [uri "/index.php"] [unique_id "amuomYa8U9lZpWaWlJJzTAAAOHM"], referer: https://tmrfsl.com/sitemap.xml
[Thu Jul 30 14:40:09.931708 2026] [security2:error] [pid 43637:tid 43805] [client 20.63.98.115:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-admin/network/about.php"] [unique_id "amuomYa8U9lZpWaWlJJzUAAAACU"]
[Thu Jul 30 14:40:10.035161 2026] [security2:error] [pid 43637:tid 43692] [remote 57.141.0.58:65444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuomoa8U9lZpWaWlJJzVAAAPjY"]
[Thu Jul 30 14:40:10.299090 2026] [security2:error] [pid 43637:tid 43777] [client 52.238.199.152:52474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wso.php"] [unique_id "amuomoa8U9lZpWaWlJJzXAAAAAk"]
[Thu Jul 30 14:40:10.836992 2026] [security2:error] [pid 43637:tid 43814] [client 20.63.98.115:50454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xpw.php"] [unique_id "amuomoa8U9lZpWaWlJJzagAAAC4"]
[Thu Jul 30 14:40:11.192096 2026] [security2:error] [pid 43637:tid 43813] [client 52.238.199.152:17242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/sh.php"] [unique_id "amuom4a8U9lZpWaWlJJzhQAAAC0"]
[Thu Jul 30 14:40:11.338244 2026] [security2:error] [pid 43637:tid 43875] [client 172.237.109.114:25687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzbwAAAGs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.338368 2026] [security2:error] [pid 43637:tid 43875] [client 172.237.109.114:25687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzbwAAAGs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.347411 2026] [security2:error] [pid 43637:tid 43791] [client 172.237.109.114:39445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzeAAAABc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.347506 2026] [security2:error] [pid 43637:tid 43791] [client 172.237.109.114:39445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzeAAAABc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.379837 2026] [security2:error] [pid 43637:tid 43694] [remote 161.35.162.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.162.35.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topmoversandpackerssharjah.art"] [uri "/xmlrpc.php"] [unique_id "amuom4a8U9lZpWaWlJJzigAAQDg"]
[Thu Jul 30 14:40:11.379997 2026] [security2:error] [pid 43637:tid 43832] [client 161.35.162.136:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topmoversandpackerssharjah.art"] [uri "/xmlrpc.php"] [unique_id "amuom4a8U9lZpWaWlJJzigAAQDg"]
[Thu Jul 30 14:40:11.407709 2026] [security2:error] [pid 43637:tid 43799] [client 172.237.109.114:5071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzhAAAAB8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.407827 2026] [security2:error] [pid 43637:tid 43799] [client 172.237.109.114:5071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzhAAAAB8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.586929 2026] [security2:error] [pid 43637:tid 43787] [client 172.237.109.114:47826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzbQAAABM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.588766 2026] [security2:error] [pid 43637:tid 43845] [client 172.237.109.114:55049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzdAAAAE0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.590470 2026] [security2:error] [pid 43637:tid 43891] [client 172.237.109.114:38331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzcQAAAHs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.590470 2026] [security2:error] [pid 43637:tid 43856] [client 172.237.109.114:5358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzdQAAAFg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.595771 2026] [security2:error] [pid 43637:tid 43773] [client 172.237.109.114:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzdwAAAAU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.597362 2026] [security2:error] [pid 43637:tid 43793] [client 172.237.109.114:31721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzbgAAABk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.600975 2026] [security2:error] [pid 43637:tid 43852] [client 172.237.109.114:42099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzcgAAAFQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.602551 2026] [security2:error] [pid 43637:tid 43837] [client 172.237.109.114:29491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzdgAAAEU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.607751 2026] [security2:error] [pid 43637:tid 43770] [client 172.237.109.114:53441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzcAAAAAI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.621963 2026] [security2:error] [pid 43637:tid 43878] [client 172.237.109.114:42937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzewAAAG4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.623514 2026] [security2:error] [pid 43637:tid 43795] [client 172.237.109.114:57929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzeQAAABs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.640598 2026] [security2:error] [pid 43637:tid 43886] [client 172.237.109.114:42075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzegAAAHY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.641703 2026] [security2:error] [pid 43637:tid 43846] [client 172.237.109.114:22391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzfAAAAE4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.651956 2026] [security2:error] [pid 43637:tid 43829] [client 172.237.109.114:8921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzgwAAAD0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.657882 2026] [security2:error] [pid 43637:tid 43892] [client 172.237.109.114:5100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzgQAAAHw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.664082 2026] [security2:error] [pid 43637:tid 43789] [client 172.237.109.114:20061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzfwAAABU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.673164 2026] [security2:error] [pid 43637:tid 43880] [client 172.237.109.114:44529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuom4a8U9lZpWaWlJJzggAAAHA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:11.925492 2026] [security2:error] [pid 43637:tid 43833] [client 20.63.98.115:23616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-cron.php"] [unique_id "amuom4a8U9lZpWaWlJJzlAAAAEE"]
[Thu Jul 30 14:40:12.178804 2026] [proxy:error] [pid 43637:tid 43774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:40:12.178877 2026] [proxy_http:error] [pid 43637:tid 43774] [client 52.202.41.153:57118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:40:12.179461 2026] [proxy:error] [pid 43637:tid 43774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:40:12.179516 2026] [proxy_http:error] [pid 43637:tid 43774] [client 52.202.41.153:57118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:40:12.526260 2026] [security2:error] [pid 43637:tid 43801] [client 3.133.226.214:21290] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuom4a8U9lZpWaWlJJzhgAAACE"], referer: https://globalmarks.pk/
[Thu Jul 30 14:40:12.618081 2026] [security2:error] [pid 43637:tid 43713] [remote 40.77.167.24:53895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/citationstylelanguage/get/ieee"] [unique_id "amuonIa8U9lZpWaWlJJzoAAAR0s"]
[Thu Jul 30 14:40:13.907251 2026] [security2:error] [pid 43637:tid 43785] [client 20.63.98.115:1595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/cah.php"] [unique_id "amuonYa8U9lZpWaWlJJzvAAAABE"]
[Thu Jul 30 14:40:13.974661 2026] [security2:error] [pid 43637:tid 43795] [client 180.243.59.178:53479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuonYa8U9lZpWaWlJJzvQAAABs"]
[Thu Jul 30 14:40:13.974814 2026] [security2:error] [pid 43637:tid 43795] [client 180.243.59.178:53479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuonYa8U9lZpWaWlJJzvQAAABs"]
[Thu Jul 30 14:40:14.887905 2026] [security2:error] [pid 43637:tid 43773] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuonoa8U9lZpWaWlJJzvgAABVY"]
[Thu Jul 30 14:40:15.379262 2026] [security2:error] [pid 43637:tid 43789] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuonoa8U9lZpWaWlJJzzQAAFSY"]
[Thu Jul 30 14:40:15.927654 2026] [security2:error] [pid 43637:tid 43859] [client 20.63.98.115:3774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/cong.php"] [unique_id "amuon4a8U9lZpWaWlJJz6AAAAFs"]
[Thu Jul 30 14:40:16.606436 2026] [security2:error] [pid 43637:tid 43894] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuooIa8U9lZpWaWlJJz6QAAfnE"]
[Thu Jul 30 14:40:16.787626 2026] [security2:error] [pid 43637:tid 43730] [remote 57.141.0.47:28734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/15978321292/feed/rss2/"] [unique_id "amuooIa8U9lZpWaWlJJz9wAAGVw"]
[Thu Jul 30 14:40:17.413908 2026] [security2:error] [pid 43637:tid 43785] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuooIa8U9lZpWaWlJJz-QAAABE"]
[Thu Jul 30 14:40:18.240822 2026] [security2:error] [pid 43637:tid 43846] [client 20.63.98.115:3718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/Sanskrit.php"] [unique_id "amuoooa8U9lZpWaWlJJ0IQAAAE4"]
[Thu Jul 30 14:40:18.567999 2026] [security2:error] [pid 43637:tid 43783] [client 52.238.199.152:17247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/send.php"] [unique_id "amuoooa8U9lZpWaWlJJ0KAAAAA8"]
[Thu Jul 30 14:40:18.866573 2026] [security2:error] [pid 43637:tid 43858] [client 189.156.226.90:27093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoooa8U9lZpWaWlJJ0LQAAAFo"]
[Thu Jul 30 14:40:18.866700 2026] [security2:error] [pid 43637:tid 43858] [client 189.156.226.90:27093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuoooa8U9lZpWaWlJJ0LQAAAFo"]
[Thu Jul 30 14:40:18.965582 2026] [security2:error] [pid 43637:tid 43726] [remote 57.141.0.9:62190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4208817797/feed/rss2/"] [unique_id "amuoooa8U9lZpWaWlJJ0LAAASlg"]
[Thu Jul 30 14:40:19.120175 2026] [security2:error] [pid 43637:tid 43862] [client 20.63.98.115:9718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ms-edit.php"] [unique_id "amuoo4a8U9lZpWaWlJJ0NwAAAF4"]
[Thu Jul 30 14:40:19.650724 2026] [security2:error] [pid 43637:tid 43807] [client 52.238.199.152:50447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ds.php"] [unique_id "amuoo4a8U9lZpWaWlJJ0QQAAACc"]
[Thu Jul 30 14:40:20.507701 2026] [security2:error] [pid 43637:tid 43777] [client 184.75.221.59:47524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuopIa8U9lZpWaWlJJ0VAAAAAk"]
[Thu Jul 30 14:40:20.507832 2026] [security2:error] [pid 43637:tid 43777] [client 184.75.221.59:47524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuopIa8U9lZpWaWlJJ0VAAAAAk"]
[Thu Jul 30 14:40:21.598037 2026] [security2:error] [pid 43637:tid 43893] [client 20.63.98.115:3757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/function.php"] [unique_id "amuopYa8U9lZpWaWlJJ0cAAAAH0"]
[Thu Jul 30 14:40:22.357119 2026] [security2:error] [pid 43637:tid 43878] [client 52.238.199.152:52477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wso112233.php"] [unique_id "amuopoa8U9lZpWaWlJJ0gwAAAG4"]
[Thu Jul 30 14:40:22.817344 2026] [security2:error] [pid 43637:tid 43829] [client 20.63.98.115:11069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ee.php"] [unique_id "amuopoa8U9lZpWaWlJJ0jwAAAD0"]
[Thu Jul 30 14:40:22.975137 2026] [autoindex:error] [pid 43637:tid 43809] [client 66.132.224.83:31132] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:40:23.131330 2026] [core:error] [pid 43637:tid 43871] [client 110.35.80.116:44184] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Jul 30 14:40:23.962726 2026] [security2:error] [pid 43637:tid 43804] [client 52.238.199.152:17266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "amuop4a8U9lZpWaWlJJ0qAAAACQ"]
[Thu Jul 30 14:40:24.184184 2026] [security2:error] [pid 43637:tid 43848] [client 180.243.59.178:53999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoqIa8U9lZpWaWlJJ0qgAAAFA"]
[Thu Jul 30 14:40:24.184337 2026] [security2:error] [pid 43637:tid 43848] [client 180.243.59.178:53999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoqIa8U9lZpWaWlJJ0qgAAAFA"]
[Thu Jul 30 14:40:24.977952 2026] [security2:error] [pid 43637:tid 43853] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuoqIa8U9lZpWaWlJJ0sgAAVRw"]
[Thu Jul 30 14:40:25.494915 2026] [core:notice] [pid 43637:tid 43892] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:25.537068 2026] [security2:error] [pid 43637:tid 43830] [client 20.63.98.115:11048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/new.php"] [unique_id "amuoqYa8U9lZpWaWlJJ00gAAAD4"]
[Thu Jul 30 14:40:25.543953 2026] [security2:error] [pid 43637:tid 43878] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuoqIa8U9lZpWaWlJJ0wgAAAG4"]
[Thu Jul 30 14:40:25.582054 2026] [core:notice] [pid 43637:tid 43873] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:25.708634 2026] [security2:error] [pid 43637:tid 43838] [client 50.6.43.217:42798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuoqYa8U9lZpWaWlJJ01AAAAEY"]
[Thu Jul 30 14:40:25.839464 2026] [security2:error] [pid 43637:tid 43792] [client 50.6.43.217:42812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuoqYa8U9lZpWaWlJJ01gAAABg"]
[Thu Jul 30 14:40:26.154808 2026] [security2:error] [pid 43637:tid 43847] [client 177.6.106.101:55503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoqoa8U9lZpWaWlJJ04QAAAE8"]
[Thu Jul 30 14:40:26.155018 2026] [security2:error] [pid 43637:tid 43847] [client 177.6.106.101:55503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuoqoa8U9lZpWaWlJJ04QAAAE8"]
[Thu Jul 30 14:40:26.219290 2026] [security2:error] [pid 43637:tid 43800] [client 52.238.199.152:50481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "amuoqoa8U9lZpWaWlJJ04gAAACA"]
[Thu Jul 30 14:40:26.392470 2026] [security2:error] [pid 43637:tid 43819] [client 74.7.241.129:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.heiakujawir.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuoqoa8U9lZpWaWlJJ06AAAM3M"]
[Thu Jul 30 14:40:26.604845 2026] [security2:error] [pid 43637:tid 43817] [client 20.63.98.115:49395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-config.php"] [unique_id "amuoqoa8U9lZpWaWlJJ08gAAADE"]
[Thu Jul 30 14:40:26.617273 2026] [security2:error] [pid 43637:tid 43863] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuoqoa8U9lZpWaWlJJ07wAAAF8"]
[Thu Jul 30 14:40:26.664417 2026] [core:notice] [pid 43637:tid 43750] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:28.825263 2026] [security2:error] [pid 43637:tid 43794] [client 20.63.98.115:50438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-conflg.php"] [unique_id "amuorIa8U9lZpWaWlJJ1JwAAABo"]
[Thu Jul 30 14:40:29.417921 2026] [security2:error] [pid 43637:tid 43835] [client 189.156.226.90:27304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuorYa8U9lZpWaWlJJ1RgAAAEM"]
[Thu Jul 30 14:40:29.418065 2026] [security2:error] [pid 43637:tid 43835] [client 189.156.226.90:27304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuorYa8U9lZpWaWlJJ1RgAAAEM"]
[Thu Jul 30 14:40:29.449528 2026] [security2:error] [pid 43637:tid 43727] [remote 5.39.1.242:61528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/nouvelles-recentes/"] [unique_id "amuorYa8U9lZpWaWlJJ1RwAAG1k"]
[Thu Jul 30 14:40:29.449721 2026] [security2:error] [pid 43637:tid 43795] [client 5.39.1.242:61528] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/nouvelles-recentes/"] [unique_id "amuorYa8U9lZpWaWlJJ1RwAAG1k"]
[Thu Jul 30 14:40:29.716250 2026] [security2:error] [pid 43637:tid 43821] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuorYa8U9lZpWaWlJJ1TQAAADU"]
[Thu Jul 30 14:40:30.164292 2026] [security2:error] [pid 43637:tid 43730] [remote 208.109.9.173:51750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-fdb1204b.med.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuoroa8U9lZpWaWlJJ1WgAAMFw"]
[Thu Jul 30 14:40:30.564028 2026] [security2:error] [pid 43637:tid 43743] [remote 57.141.0.2:43022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuoroa8U9lZpWaWlJJ1XgAARmk"]
[Thu Jul 30 14:40:30.740230 2026] [security2:error] [pid 43637:tid 43830] [client 135.119.63.61:35339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/011i.php"] [unique_id "amuoroa8U9lZpWaWlJJ1aQAAAD4"]
[Thu Jul 30 14:40:30.990734 2026] [core:notice] [pid 43637:tid 43789] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:31.481463 2026] [core:notice] [pid 43637:tid 43791] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:31.606897 2026] [security2:error] [pid 43637:tid 43775] [client 20.63.98.115:9630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lilyinspires.com"] [uri "/index.php"] [unique_id "amuoroa8U9lZpWaWlJJ1YgAAAAc"]
[Thu Jul 30 14:40:31.739633 2026] [core:notice] [pid 43637:tid 43641] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:31.807348 2026] [security2:error] [pid 43637:tid 43778] [client 20.63.98.115:9630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuor4a8U9lZpWaWlJJ1iAAAAAo"]
[Thu Jul 30 14:40:32.045351 2026] [core:notice] [pid 43637:tid 43653] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.045351 2026] [core:notice] [pid 43637:tid 43758] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.045388 2026] [core:notice] [pid 43637:tid 43663] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.045445 2026] [core:notice] [pid 43637:tid 43654] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.045537 2026] [core:notice] [pid 43637:tid 43752] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.045592 2026] [core:notice] [pid 43637:tid 43765] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.045831 2026] [core:notice] [pid 43637:tid 43652] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.045864 2026] [core:notice] [pid 43637:tid 43669] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.045878 2026] [core:notice] [pid 43637:tid 43745] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.045955 2026] [core:notice] [pid 43637:tid 43726] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.047917 2026] [core:notice] [pid 43637:tid 43742] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.048105 2026] [core:notice] [pid 43637:tid 43747] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.050350 2026] [core:notice] [pid 43637:tid 43758] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.050905 2026] [core:notice] [pid 43637:tid 43657] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.050967 2026] [core:notice] [pid 43637:tid 43667] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.077501 2026] [security2:error] [pid 43637:tid 43788] [client 172.237.109.114:60965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1mwAAABQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.077835 2026] [security2:error] [pid 43637:tid 43813] [client 172.237.109.114:26181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1nAAAAC0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.077966 2026] [security2:error] [pid 43637:tid 43881] [client 172.237.109.114:5233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1nQAAAHE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.078007 2026] [security2:error] [pid 43637:tid 43776] [client 172.237.109.114:51205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1ngAAAAg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.080166 2026] [security2:error] [pid 43637:tid 43870] [client 172.237.109.114:21648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1oAAAAGY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.080252 2026] [security2:error] [pid 43637:tid 43877] [client 172.237.109.114:20038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1nwAAAG0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.087165 2026] [security2:error] [pid 43637:tid 43821] [client 172.237.109.114:53745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1oQAAADU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.087295 2026] [security2:error] [pid 43637:tid 43829] [client 172.237.109.114:54519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1ogAAAD0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.094014 2026] [security2:error] [pid 43637:tid 43849] [client 172.237.109.114:25244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1owAAAFE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.094823 2026] [security2:error] [pid 43637:tid 43895] [client 172.237.109.114:15256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1pAAAAH8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.095079 2026] [security2:error] [pid 43637:tid 43807] [client 172.237.109.114:52689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1pQAAACc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.103992 2026] [security2:error] [pid 43637:tid 43820] [client 172.237.109.114:42737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1pgAAADQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.121719 2026] [security2:error] [pid 43637:tid 43874] [client 172.237.109.114:42314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1pwAAAGo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.121801 2026] [security2:error] [pid 43637:tid 43874] [client 172.237.109.114:42314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1pwAAAGo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.122866 2026] [security2:error] [pid 43637:tid 43872] [client 172.237.109.114:36843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1qAAAAGg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.123089 2026] [security2:error] [pid 43637:tid 43827] [client 172.237.109.114:6299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1qQAAADs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.123989 2026] [security2:error] [pid 43637:tid 43793] [client 172.237.109.114:22567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1qgAAABk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.124129 2026] [security2:error] [pid 43637:tid 43798] [client 172.237.109.114:26638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1qwAAAB4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.134790 2026] [security2:error] [pid 43637:tid 43835] [client 135.119.63.61:34528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/03a005685d.php"] [unique_id "amuosIa8U9lZpWaWlJJ1rAAAAEM"]
[Thu Jul 30 14:40:32.150401 2026] [security2:error] [pid 43637:tid 43790] [client 172.237.109.114:53097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1rQAAABY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.151913 2026] [security2:error] [pid 43637:tid 43878] [client 172.237.109.114:10561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1rgAAAG4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.152582 2026] [security2:error] [pid 43637:tid 43770] [client 172.237.109.114:36875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuosIa8U9lZpWaWlJJ1rwAAAAI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:32.422473 2026] [security2:error] [pid 43637:tid 43857] [client 52.238.199.152:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/mail.php"] [unique_id "amuosIa8U9lZpWaWlJJ1twAAAFk"]
[Thu Jul 30 14:40:32.594113 2026] [core:notice] [pid 43637:tid 43684] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:32.712108 2026] [security2:error] [pid 43637:tid 43885] [client 20.63.98.115:46856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuosIa8U9lZpWaWlJJ1wAAAAHU"]
[Thu Jul 30 14:40:33.136395 2026] [security2:error] [pid 43637:tid 43876] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuosIa8U9lZpWaWlJJ1ugAAAGw"]
[Thu Jul 30 14:40:33.468638 2026] [core:notice] [pid 43637:tid 43739] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:33.486549 2026] [core:notice] [pid 43637:tid 43658] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:33.662924 2026] [security2:error] [pid 43637:tid 43870] [client 20.63.98.115:53972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuosYa8U9lZpWaWlJJ12AAAAGY"]
[Thu Jul 30 14:40:33.880858 2026] [security2:error] [pid 43637:tid 43842] [client 135.119.63.61:35366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/403.php"] [unique_id "amuosYa8U9lZpWaWlJJ14gAAAEo"]
[Thu Jul 30 14:40:33.995142 2026] [security2:error] [pid 43637:tid 43849] [client 52.238.199.152:50443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-mail.php"] [unique_id "amuosYa8U9lZpWaWlJJ14wAAAFE"]
[Thu Jul 30 14:40:34.499366 2026] [security2:error] [pid 43637:tid 43871] [client 180.243.59.178:54533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuosoa8U9lZpWaWlJJ17QAAAGc"]
[Thu Jul 30 14:40:34.499489 2026] [security2:error] [pid 43637:tid 43871] [client 180.243.59.178:54533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuosoa8U9lZpWaWlJJ17QAAAGc"]
[Thu Jul 30 14:40:34.634153 2026] [security2:error] [pid 43637:tid 43831] [client 121.229.156.96:53860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hoki188win.com"] [uri "/"] [unique_id "amuosoa8U9lZpWaWlJJ17gAAAD8"]
[Thu Jul 30 14:40:34.634334 2026] [security2:error] [pid 43637:tid 43831] [client 121.229.156.96:53860] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hoki188win.com"] [uri "/"] [unique_id "amuosoa8U9lZpWaWlJJ17gAAAD8"]
[Thu Jul 30 14:40:34.654115 2026] [security2:error] [pid 43637:tid 43847] [client 20.63.98.115:46900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuosoa8U9lZpWaWlJJ17wAAAE8"]
[Thu Jul 30 14:40:34.939139 2026] [autoindex:error] [pid 43637:tid 43892] [client 66.132.172.132:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:40:35.107723 2026] [security2:error] [pid 43637:tid 43843] [client 135.119.63.61:37509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/404.php"] [unique_id "amuos4a8U9lZpWaWlJJ1_QAAAEs"]
[Thu Jul 30 14:40:35.803912 2026] [core:notice] [pid 43637:tid 43823] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:36.224713 2026] [security2:error] [pid 43637:tid 43852] [client 106.75.66.187:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/favicon.ico"] [unique_id "amuotIa8U9lZpWaWlJJ2EQAAAFQ"]
[Thu Jul 30 14:40:36.320024 2026] [security2:error] [pid 43637:tid 43859] [client 52.238.199.152:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-trackback.php"] [unique_id "amuotIa8U9lZpWaWlJJ2FAAAAFs"]
[Thu Jul 30 14:40:36.806601 2026] [security2:error] [pid 43637:tid 43813] [client 20.63.98.115:36296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/manager.php"] [unique_id "amuotIa8U9lZpWaWlJJ2IQAAAC0"]
[Thu Jul 30 14:40:37.072695 2026] [security2:error] [pid 43637:tid 43861] [client 106.75.66.187:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/robots.txt"] [unique_id "amuotYa8U9lZpWaWlJJ2LwAAAF0"]
[Thu Jul 30 14:40:37.215026 2026] [core:notice] [pid 43637:tid 43662] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:37.244581 2026] [security2:error] [pid 43637:tid 43781] [client 177.6.106.101:56715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuotYa8U9lZpWaWlJJ2MgAAAA0"]
[Thu Jul 30 14:40:37.244688 2026] [security2:error] [pid 43637:tid 43781] [client 177.6.106.101:56715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuotYa8U9lZpWaWlJJ2MgAAAA0"]
[Thu Jul 30 14:40:37.423032 2026] [security2:error] [pid 43637:tid 43779] [client 114.119.138.220:32219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ecre.ae"] [uri "/search"] [unique_id "amuotYa8U9lZpWaWlJJ2OQAAAAs"], referer: https://ecre.ae/service-26
[Thu Jul 30 14:40:37.471169 2026] [core:notice] [pid 43637:tid 43688] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:37.643027 2026] [security2:error] [pid 43637:tid 43847] [client 20.63.98.115:53990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-links.php"] [unique_id "amuotYa8U9lZpWaWlJJ2QQAAAE8"]
[Thu Jul 30 14:40:38.197810 2026] [security2:error] [pid 43637:tid 43889] [client 106.75.66.187:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/sitemap.xml"] [unique_id "amuotoa8U9lZpWaWlJJ2SwAAAHk"]
[Thu Jul 30 14:40:38.238156 2026] [security2:error] [pid 43637:tid 43792] [client 74.7.241.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.altaazi.com"] [uri "/index.php"] [unique_id "amuotYa8U9lZpWaWlJJ2LgAAGHQ"]
[Thu Jul 30 14:40:38.238189 2026] [security2:error] [pid 43637:tid 43792] [client 74.7.241.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.altaazi.com"] [uri "/index.php"] [unique_id "amuotYa8U9lZpWaWlJJ2LgAAGHQ"]
[Thu Jul 30 14:40:38.548639 2026] [security2:error] [pid 43637:tid 43811] [client 74.7.241.152:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jgp.fxh.temporary.site"] [uri "/index.php"] [unique_id "amuotIa8U9lZpWaWlJJ2KgAAACs"]
[Thu Jul 30 14:40:38.549581 2026] [security2:error] [pid 43637:tid 43796] [client 74.7.241.152:51504] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jgp.fxh.temporary.site"] [uri "/robots.txt"] [unique_id "amuotIa8U9lZpWaWlJJ2JwAAHCg"]
[Thu Jul 30 14:40:38.733066 2026] [security2:error] [pid 43637:tid 43859] [client 20.63.98.115:1325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/fi2.php"] [unique_id "amuotoa8U9lZpWaWlJJ2VgAAAFs"]
[Thu Jul 30 14:40:38.973109 2026] [security2:error] [pid 43637:tid 43820] [client 172.237.109.114:14655] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amuotoa8U9lZpWaWlJJ2WgAAADQ"]
[Thu Jul 30 14:40:39.283970 2026] [security2:error] [pid 43637:tid 43835] [client 74.7.241.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "altaazi.com"] [uri "/index.php"] [unique_id "amuot4a8U9lZpWaWlJJ2ZAAAQz0"], referer: https://www.altaazi.com/robots.txt
[Thu Jul 30 14:40:39.299581 2026] [security2:error] [pid 43637:tid 43867] [client 135.119.63.61:23270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/aa.php"] [unique_id "amuot4a8U9lZpWaWlJJ2ZQAAAGM"]
[Thu Jul 30 14:40:39.632189 2026] [security2:error] [pid 43637:tid 43826] [client 20.63.98.115:46871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/0x.php"] [unique_id "amuot4a8U9lZpWaWlJJ2dAAAADo"]
[Thu Jul 30 14:40:39.684947 2026] [security2:error] [pid 43637:tid 43856] [client 74.7.175.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hirisaveram.com"] [uri "/index.php"] [unique_id "amuot4a8U9lZpWaWlJJ2agAAWDU"]
[Thu Jul 30 14:40:39.776289 2026] [security2:error] [pid 43637:tid 43802] [client 52.238.199.152:45108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/uploads/cong.php"] [unique_id "amuot4a8U9lZpWaWlJJ2dQAAACI"]
[Thu Jul 30 14:40:39.912318 2026] [security2:error] [pid 43637:tid 43789] [client 189.156.226.90:27604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuot4a8U9lZpWaWlJJ2dgAAABU"]
[Thu Jul 30 14:40:39.912457 2026] [security2:error] [pid 43637:tid 43789] [client 189.156.226.90:27604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuot4a8U9lZpWaWlJJ2dgAAABU"]
[Thu Jul 30 14:40:40.163844 2026] [security2:error] [pid 43637:tid 43817] [client 135.119.63.61:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/aafewc0k.php"] [unique_id "amuouIa8U9lZpWaWlJJ2gAAAADE"]
[Thu Jul 30 14:40:40.205160 2026] [security2:error] [pid 43637:tid 43812] [client 52.238.199.152:10317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuouIa8U9lZpWaWlJJ2gQAAACw"]
[Thu Jul 30 14:40:40.345149 2026] [security2:error] [pid 43637:tid 43885] [client 20.104.18.253:2377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/_Podt.php"] [unique_id "amuouIa8U9lZpWaWlJJ2ggAAAHU"]
[Thu Jul 30 14:40:40.631887 2026] [security2:error] [pid 43637:tid 43799] [client 52.238.199.152:39083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuouIa8U9lZpWaWlJJ2igAAAB8"]
[Thu Jul 30 14:40:41.035077 2026] [security2:error] [pid 43637:tid 43805] [client 20.104.18.253:31692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/_adminer.php"] [unique_id "amuouYa8U9lZpWaWlJJ2kQAAACU"]
[Thu Jul 30 14:40:41.268787 2026] [security2:error] [pid 43637:tid 43824] [client 68.67.112.134:32721] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "azureskyfilms.com"] [uri "/robots.txt"] [unique_id "amuouYa8U9lZpWaWlJJ2ngAAADg"]
[Thu Jul 30 14:40:41.688816 2026] [security2:error] [pid 43637:tid 43816] [client 20.104.18.253:31687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/a.php"] [unique_id "amuouYa8U9lZpWaWlJJ2qQAAADA"]
[Thu Jul 30 14:40:41.753763 2026] [security2:error] [pid 43637:tid 43807] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuouYa8U9lZpWaWlJJ2lwAAACc"]
[Thu Jul 30 14:40:42.161174 2026] [core:notice] [pid 43637:tid 43698] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:42.290907 2026] [security2:error] [pid 43637:tid 43801] [client 20.104.18.253:31706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/a1.php"] [unique_id "amuouoa8U9lZpWaWlJJ2vAAAACE"]
[Thu Jul 30 14:40:42.737402 2026] [security2:error] [pid 43637:tid 43875] [client 135.119.63.61:37528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/abcd.php"] [unique_id "amuouoa8U9lZpWaWlJJ20AAAAGs"]
[Thu Jul 30 14:40:42.965747 2026] [security2:error] [pid 43637:tid 43889] [client 20.104.18.253:31682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/a2.php"] [unique_id "amuouoa8U9lZpWaWlJJ21AAAAHk"]
[Thu Jul 30 14:40:43.082001 2026] [security2:error] [pid 43637:tid 43805] [client 52.238.199.152:45076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/webadmin.php"] [unique_id "amuou4a8U9lZpWaWlJJ21QAAACU"]
[Thu Jul 30 14:40:43.594146 2026] [security2:error] [pid 43637:tid 43842] [client 20.104.18.253:31722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/a3.php"] [unique_id "amuou4a8U9lZpWaWlJJ23wAAAEo"]
[Thu Jul 30 14:40:43.952541 2026] [security2:error] [pid 43637:tid 43867] [client 20.63.98.115:3800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/k.php"] [unique_id "amuou4a8U9lZpWaWlJJ26wAAAGM"]
[Thu Jul 30 14:40:44.239482 2026] [security2:error] [pid 43637:tid 43785] [client 20.104.18.253:31686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/aa.php"] [unique_id "amuovIa8U9lZpWaWlJJ28AAAABE"]
[Thu Jul 30 14:40:44.532693 2026] [security2:error] [pid 43637:tid 43732] [remote 52.167.144.219:55822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/communityf.php"] [unique_id "amuovIa8U9lZpWaWlJJ2-AAALl4"]
[Thu Jul 30 14:40:44.897641 2026] [security2:error] [pid 43637:tid 43886] [client 20.104.18.253:31705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/aaa.php"] [unique_id "amuovIa8U9lZpWaWlJJ2_wAAAHY"]
[Thu Jul 30 14:40:44.982755 2026] [security2:error] [pid 43637:tid 43840] [client 20.63.98.115:36351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/gecko-new.php"] [unique_id "amuovIa8U9lZpWaWlJJ3AAAAAEg"]
[Thu Jul 30 14:40:45.206610 2026] [core:notice] [pid 43637:tid 43893] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:45.547067 2026] [security2:error] [pid 43637:tid 43768] [client 20.104.18.253:31730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/aaaa.php"] [unique_id "amuovYa8U9lZpWaWlJJ3DgAAAAA"]
[Thu Jul 30 14:40:45.745671 2026] [core:notice] [pid 43637:tid 43796] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:45.809874 2026] [core:error] [pid 43637:tid 43842] [client 66.249.73.102:56064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:40:45.809896 2026] [core:error] [pid 43637:tid 43842] [client 66.249.73.102:56064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:40:46.093222 2026] [security2:error] [pid 43637:tid 43868] [client 180.243.59.178:55129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuovoa8U9lZpWaWlJJ3GwAAAGQ"]
[Thu Jul 30 14:40:46.093358 2026] [security2:error] [pid 43637:tid 43868] [client 180.243.59.178:55129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuovoa8U9lZpWaWlJJ3GwAAAGQ"]
[Thu Jul 30 14:40:46.159649 2026] [core:notice] [pid 43637:tid 43816] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:46.161431 2026] [security2:error] [pid 43637:tid 43835] [client 20.104.18.253:31694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/aahana/json.php"] [unique_id "amuovoa8U9lZpWaWlJJ3IQAAAEM"]
[Thu Jul 30 14:40:46.406629 2026] [security2:error] [pid 43637:tid 43769] [client 154.164.144.23:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.144.164.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fiyan.co"] [uri "/xmlrpc.php"] [unique_id "amuovoa8U9lZpWaWlJJ3HAAAAAE"]
[Thu Jul 30 14:40:46.406811 2026] [security2:error] [pid 43637:tid 43769] [client 154.164.144.23:59274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fiyan.co"] [uri "/xmlrpc.php"] [unique_id "amuovoa8U9lZpWaWlJJ3HAAAAAE"]
[Thu Jul 30 14:40:46.543382 2026] [security2:error] [pid 43637:tid 43820] [client 135.119.63.61:37522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/about.php"] [unique_id "amuovoa8U9lZpWaWlJJ3LAAAADQ"]
[Thu Jul 30 14:40:46.759951 2026] [security2:error] [pid 43637:tid 43814] [client 20.104.18.253:2381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/aahana/worksec.php"] [unique_id "amuovoa8U9lZpWaWlJJ3MwAAAC4"]
[Thu Jul 30 14:40:46.973348 2026] [security2:error] [pid 43637:tid 43800] [client 172.237.109.114:28921] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amuovoa8U9lZpWaWlJJ3OAAAACA"]
[Thu Jul 30 14:40:47.086873 2026] [security2:error] [pid 43637:tid 43888] [client 20.63.98.115:36332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/alfanew.php"] [unique_id "amuov4a8U9lZpWaWlJJ3OgAAAHg"]
[Thu Jul 30 14:40:47.383075 2026] [security2:error] [pid 43637:tid 43791] [client 20.104.18.253:2374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/ab.php"] [unique_id "amuov4a8U9lZpWaWlJJ3RAAAABc"]
[Thu Jul 30 14:40:48.082810 2026] [security2:error] [pid 43637:tid 43816] [client 20.104.18.253:31713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/abby.php"] [unique_id "amuowIa8U9lZpWaWlJJ3UwAAADA"]
[Thu Jul 30 14:40:48.299836 2026] [core:notice] [pid 43637:tid 43737] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:48.644173 2026] [security2:error] [pid 43637:tid 43826] [client 135.119.63.61:37523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/admin.php"] [unique_id "amuowIa8U9lZpWaWlJJ3nAAAADo"]
[Thu Jul 30 14:40:48.738773 2026] [security2:error] [pid 43637:tid 43772] [client 20.104.18.253:2389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/abc.php"] [unique_id "amuowIa8U9lZpWaWlJJ3nQAAAAQ"]
[Thu Jul 30 14:40:48.831915 2026] [security2:error] [pid 43637:tid 43857] [client 20.63.98.115:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/text.php"] [unique_id "amuowIa8U9lZpWaWlJJ3oQAAAFk"]
[Thu Jul 30 14:40:48.833697 2026] [security2:error] [pid 43637:tid 43804] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuowIa8U9lZpWaWlJJ3jwAAACQ"]
[Thu Jul 30 14:40:49.132972 2026] [core:notice] [pid 43637:tid 43739] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:49.151617 2026] [security2:error] [pid 43637:tid 43880] [client 172.237.109.114:39358] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amuowYa8U9lZpWaWlJJ3qQAAAHA"]
[Thu Jul 30 14:40:49.303965 2026] [security2:error] [pid 43637:tid 43859] [client 186.73.210.234:52876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuouYa8U9lZpWaWlJJ2nwAAAFs"], referer: http://pkf.jo
[Thu Jul 30 14:40:49.305129 2026] [security2:error] [pid 43637:tid 43833] [client 181.188.160.170:52601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuouYa8U9lZpWaWlJJ2pQAAAEE"], referer: http://pkf.jo
[Thu Jul 30 14:40:49.308336 2026] [security2:error] [pid 43637:tid 43864] [client 212.253.73.253:39132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuouoa8U9lZpWaWlJJ2wgAAAGA"], referer: http://pkf.jo
[Thu Jul 30 14:40:49.309682 2026] [security2:error] [pid 43637:tid 43783] [client 113.199.231.125:5585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuovoa8U9lZpWaWlJJ3NwAAAA8"], referer: http://pkf.jo
[Thu Jul 30 14:40:49.320187 2026] [security2:error] [pid 43637:tid 43875] [client 105.69.37.191:51016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuovYa8U9lZpWaWlJJ3BQAAAGs"], referer: http://pkf.jo
[Thu Jul 30 14:40:49.320475 2026] [security2:error] [pid 43637:tid 43784] [client 154.208.33.203:60286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuouoa8U9lZpWaWlJJ2uAAAABA"], referer: http://pkf.jo
[Thu Jul 30 14:40:49.320598 2026] [security2:error] [pid 43637:tid 43879] [client 186.55.68.239:55184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuouoa8U9lZpWaWlJJ2vQAAAG8"], referer: http://pkf.jo
[Thu Jul 30 14:40:49.320651 2026] [security2:error] [pid 43637:tid 43793] [client 186.22.57.12:41790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuouYa8U9lZpWaWlJJ2pAAAABk"], referer: http://pkf.jo
[Thu Jul 30 14:40:49.374706 2026] [security2:error] [pid 43637:tid 43861] [client 20.104.18.253:31681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/abcd.php"] [unique_id "amuowYa8U9lZpWaWlJJ3tAAAAF0"]
[Thu Jul 30 14:40:49.639168 2026] [security2:error] [pid 43637:tid 43815] [client 20.63.98.115:54008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/f.php"] [unique_id "amuowYa8U9lZpWaWlJJ3ugAAAC8"]
[Thu Jul 30 14:40:49.959128 2026] [core:error] [pid 43637:tid 43675] [remote 40.77.167.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:40:49.959151 2026] [core:error] [pid 43637:tid 43675] [remote 40.77.167.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:40:50.016106 2026] [security2:error] [pid 43637:tid 43749] [remote 57.141.0.50:21446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amuowoa8U9lZpWaWlJJ3xQAAfG8"]
[Thu Jul 30 14:40:50.046693 2026] [security2:error] [pid 43637:tid 43856] [client 20.104.18.253:2407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/abcde.php"] [unique_id "amuowoa8U9lZpWaWlJJ3xgAAAFg"]
[Thu Jul 30 14:40:50.385443 2026] [security2:error] [pid 43637:tid 43774] [client 52.238.199.152:39085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/link.php"] [unique_id "amuowoa8U9lZpWaWlJJ35AAAAAY"]
[Thu Jul 30 14:40:50.406733 2026] [security2:error] [pid 43637:tid 43854] [client 40.77.167.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuowoa8U9lZpWaWlJJ3yQAAAFY"]
[Thu Jul 30 14:40:50.487317 2026] [security2:error] [pid 43637:tid 43835] [client 20.63.98.115:36646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuowoa8U9lZpWaWlJJ37gAAAEM"]
[Thu Jul 30 14:40:50.515923 2026] [security2:error] [pid 43637:tid 43822] [client 189.156.226.90:26890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuowoa8U9lZpWaWlJJ37wAAADY"]
[Thu Jul 30 14:40:50.516060 2026] [security2:error] [pid 43637:tid 43822] [client 189.156.226.90:26890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuowoa8U9lZpWaWlJJ37wAAADY"]
[Thu Jul 30 14:40:50.547304 2026] [security2:error] [pid 43637:tid 43894] [client 135.119.63.61:23237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/adminfuns.php"] [unique_id "amuowoa8U9lZpWaWlJJ38AAAAH4"]
[Thu Jul 30 14:40:50.662670 2026] [security2:error] [pid 43637:tid 43824] [client 20.104.18.253:2375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/about.php"] [unique_id "amuowoa8U9lZpWaWlJJ3-gAAADg"]
[Thu Jul 30 14:40:50.910642 2026] [security2:error] [pid 43637:tid 43807] [client 40.77.167.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuowoa8U9lZpWaWlJJ39AAAACc"]
[Thu Jul 30 14:40:51.285445 2026] [security2:error] [pid 43637:tid 43799] [client 20.104.18.253:2379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/about.php/wp-content/x/index.php"] [unique_id "amuow4a8U9lZpWaWlJJ4HwAAAB8"]
[Thu Jul 30 14:40:51.552514 2026] [security2:error] [pid 43637:tid 43886] [client 57.141.0.24:43076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koriusa.info"] [uri "/index.php"] [unique_id "amuowIa8U9lZpWaWlJJ3mwAAdhY"]
[Thu Jul 30 14:40:51.691334 2026] [security2:error] [pid 43637:tid 43875] [client 172.237.109.114:4185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuow4a8U9lZpWaWlJJ4HQAAAGs"]
[Thu Jul 30 14:40:51.723438 2026] [security2:error] [pid 43637:tid 43793] [client 52.238.199.152:33494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/ova.php"] [unique_id "amuow4a8U9lZpWaWlJJ4MgAAABk"]
[Thu Jul 30 14:40:51.900356 2026] [security2:error] [pid 43637:tid 43815] [client 135.119.63.61:37508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/albin.php"] [unique_id "amuow4a8U9lZpWaWlJJ4OAAAAC8"]
[Thu Jul 30 14:40:51.968623 2026] [security2:error] [pid 43637:tid 43788] [client 20.104.18.253:31718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/abuot.php"] [unique_id "amuow4a8U9lZpWaWlJJ4PAAAABQ"]
[Thu Jul 30 14:40:52.078726 2026] [security2:error] [pid 43637:tid 43878] [client 172.237.109.114:10169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4RAAAAG4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.078752 2026] [security2:error] [pid 43637:tid 43866] [client 172.237.109.114:47219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4RQAAAGI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.087106 2026] [security2:error] [pid 43637:tid 43780] [client 185.24.60.180:52837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuow4a8U9lZpWaWlJJ4NgAAAAw"], referer: http://pkf.jo
[Thu Jul 30 14:40:52.096541 2026] [security2:error] [pid 43637:tid 43851] [client 172.237.109.114:35983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4SAAAAFM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.102664 2026] [security2:error] [pid 43637:tid 43884] [client 172.237.109.114:1952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4SQAAAHQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.120671 2026] [security2:error] [pid 43637:tid 43871] [client 172.237.109.114:28613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4SgAAAGc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.120827 2026] [security2:error] [pid 43637:tid 43804] [client 172.237.109.114:34835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4SwAAACQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.147682 2026] [security2:error] [pid 43637:tid 43818] [client 172.237.109.114:6427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4TAAAADI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.148132 2026] [security2:error] [pid 43637:tid 43855] [client 172.237.109.114:31347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4TQAAAFc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.148222 2026] [security2:error] [pid 43637:tid 43855] [client 172.237.109.114:31347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4TQAAAFc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.148806 2026] [security2:error] [pid 43637:tid 43860] [client 172.237.109.114:20591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4TgAAAFw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.149449 2026] [security2:error] [pid 43637:tid 43873] [client 172.237.109.114:31139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4TwAAAGk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.149623 2026] [security2:error] [pid 43637:tid 43894] [client 172.237.109.114:58694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4UAAAAH4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.149851 2026] [security2:error] [pid 43637:tid 43857] [client 172.237.109.114:38115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4UQAAAFk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.150379 2026] [security2:error] [pid 43637:tid 43858] [client 172.237.109.114:5419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4UgAAAFo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.150939 2026] [security2:error] [pid 43637:tid 43863] [client 172.237.109.114:53893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4UwAAAF8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.151302 2026] [security2:error] [pid 43637:tid 43786] [client 172.237.109.114:47944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4VAAAABI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.151373 2026] [security2:error] [pid 43637:tid 43769] [client 172.237.109.114:52599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4VQAAAAE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.151614 2026] [security2:error] [pid 43637:tid 43779] [client 172.237.109.114:27796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4VgAAAAs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:52.379558 2026] [security2:error] [pid 43637:tid 43846] [client 20.63.98.115:46853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/hehe.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4WgAAAE4"]
[Thu Jul 30 14:40:52.640391 2026] [security2:error] [pid 43637:tid 43893] [client 20.104.18.253:31689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/ac.php"] [unique_id "amuoxIa8U9lZpWaWlJJ4ZAAAAH0"]
[Thu Jul 30 14:40:53.103146 2026] [security2:error] [pid 43637:tid 43774] [client 172.237.109.114:48731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxYa8U9lZpWaWlJJ4bAAAAAY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:53.120170 2026] [security2:error] [pid 43637:tid 43883] [client 172.237.109.114:17379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxYa8U9lZpWaWlJJ4bwAAAHM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:53.121938 2026] [security2:error] [pid 43637:tid 43881] [client 172.237.109.114:17261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuoxYa8U9lZpWaWlJJ4cAAAAHE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:40:53.267830 2026] [security2:error] [pid 43637:tid 43821] [client 20.104.18.253:31736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/acces.php"] [unique_id "amuoxYa8U9lZpWaWlJJ4cgAAADU"]
[Thu Jul 30 14:40:53.473082 2026] [core:notice] [pid 43637:tid 43723] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:53.945297 2026] [security2:error] [pid 43637:tid 43873] [client 20.104.18.253:31719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/access.php"] [unique_id "amuoxYa8U9lZpWaWlJJ4fQAAAGk"]
[Thu Jul 30 14:40:53.989789 2026] [core:error] [pid 43637:tid 43732] [remote 207.46.13.116:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:40:53.989817 2026] [core:error] [pid 43637:tid 43732] [remote 207.46.13.116:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:40:54.234159 2026] [core:notice] [pid 43637:tid 43639] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:40:54.585664 2026] [security2:error] [pid 43637:tid 43812] [client 20.104.18.253:31721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/ace.php"] [unique_id "amuoxoa8U9lZpWaWlJJ4jQAAACw"]
[Thu Jul 30 14:40:54.651248 2026] [security2:error] [pid 43637:tid 43840] [client 135.119.63.61:23271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/amfsqvgv.php"] [unique_id "amuoxoa8U9lZpWaWlJJ4jwAAAEg"]
[Thu Jul 30 14:40:54.800417 2026] [security2:error] [pid 43637:tid 43768] [client 52.238.199.152:39043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/css/colors/coffee/about.php"] [unique_id "amuoxoa8U9lZpWaWlJJ4ngAAAAA"]
[Thu Jul 30 14:40:55.224091 2026] [security2:error] [pid 43637:tid 43811] [client 20.104.18.253:31715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/acme-challengeadmin.php"] [unique_id "amuox4a8U9lZpWaWlJJ4qAAAACs"]
[Thu Jul 30 14:40:55.570749 2026] [security2:error] [pid 43637:tid 43809] [client 180.243.59.178:55449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.59.243.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuox4a8U9lZpWaWlJJ4rQAAACk"]
[Thu Jul 30 14:40:55.570862 2026] [security2:error] [pid 43637:tid 43809] [client 180.243.59.178:55449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuox4a8U9lZpWaWlJJ4rQAAACk"]
[Thu Jul 30 14:40:55.601582 2026] [security2:error] [pid 43637:tid 43842] [client 34.74.242.206:1591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/"] [unique_id "amuox4a8U9lZpWaWlJJ4rwAAAEo"]
[Thu Jul 30 14:40:55.601699 2026] [security2:error] [pid 43637:tid 43842] [client 34.74.242.206:1591] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/"] [unique_id "amuox4a8U9lZpWaWlJJ4rwAAAEo"]
[Thu Jul 30 14:40:55.846817 2026] [security2:error] [pid 43637:tid 43788] [client 20.104.18.253:31711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/acme-challengealfa.php"] [unique_id "amuox4a8U9lZpWaWlJJ4tgAAABQ"]
[Thu Jul 30 14:40:56.297210 2026] [security2:error] [pid 43637:tid 43866] [client 31.31.107.17:47550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuox4a8U9lZpWaWlJJ4twAAAGI"], referer: http://pkf.jo
[Thu Jul 30 14:40:56.445488 2026] [security2:error] [pid 43637:tid 43804] [client 20.104.18.253:2408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/acme-challengebypass.php"] [unique_id "amuoyIa8U9lZpWaWlJJ4xwAAACQ"]
[Thu Jul 30 14:40:56.558774 2026] [security2:error] [pid 43637:tid 43783] [client 109.76.32.50:36878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuoyIa8U9lZpWaWlJJ4vgAAAA8"], referer: http://pkf.jo
[Thu Jul 30 14:40:56.665862 2026] [security2:error] [pid 43637:tid 43786] [client 181.78.74.236:38900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuoyIa8U9lZpWaWlJJ4wgAAABI"], referer: http://pkf.jo
[Thu Jul 30 14:40:56.737590 2026] [security2:error] [pid 43637:tid 43779] [client 190.56.94.190:48482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuoyIa8U9lZpWaWlJJ4xgAAAAs"], referer: http://pkf.jo
[Thu Jul 30 14:40:56.937622 2026] [security2:error] [pid 43637:tid 43793] [client 52.238.199.152:42719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuoyIa8U9lZpWaWlJJ40QAAABk"]
[Thu Jul 30 14:40:57.056403 2026] [security2:error] [pid 43637:tid 43777] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ40wAAAAk"]
[Thu Jul 30 14:40:57.070432 2026] [security2:error] [pid 43637:tid 43797] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ41AAAAB0"]
[Thu Jul 30 14:40:57.083072 2026] [security2:error] [pid 43637:tid 43837] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ41QAAAEU"]
[Thu Jul 30 14:40:57.113011 2026] [security2:error] [pid 43637:tid 43799] [client 20.104.18.253:31712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/acme-challengek.php"] [unique_id "amuoyYa8U9lZpWaWlJJ41gAAAB8"]
[Thu Jul 30 14:40:57.141327 2026] [security2:error] [pid 43637:tid 43833] [client 135.119.63.61:23239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/ant.php"] [unique_id "amuoyYa8U9lZpWaWlJJ41wAAAEE"]
[Thu Jul 30 14:40:57.155899 2026] [security2:error] [pid 43637:tid 43778] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ42AAAAAo"]
[Thu Jul 30 14:40:57.176139 2026] [security2:error] [pid 43637:tid 43889] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ43AAAAHk"]
[Thu Jul 30 14:40:57.367344 2026] [security2:error] [pid 43637:tid 43770] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ47QAAAAI"]
[Thu Jul 30 14:40:57.427272 2026] [security2:error] [pid 43637:tid 43850] [client 105.209.236.231:52570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuoyYa8U9lZpWaWlJJ40gAAAFI"], referer: http://pkf.jo
[Thu Jul 30 14:40:57.668230 2026] [security2:error] [pid 43637:tid 43771] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ4-QAAAAM"]
[Thu Jul 30 14:40:57.698186 2026] [security2:error] [pid 43637:tid 43878] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ4_AAAAG4"]
[Thu Jul 30 14:40:57.757448 2026] [security2:error] [pid 43637:tid 43772] [client 20.104.18.253:2387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/acme-challengewp.php"] [unique_id "amuoyYa8U9lZpWaWlJJ5AwAAAAQ"]
[Thu Jul 30 14:40:57.808549 2026] [security2:error] [pid 43637:tid 43789] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ5BAAAABU"]
[Thu Jul 30 14:40:57.814397 2026] [security2:error] [pid 43637:tid 43800] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ5BgAAACA"]
[Thu Jul 30 14:40:57.866743 2026] [security2:error] [pid 43637:tid 43798] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/api/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ5DAAAAB4"]
[Thu Jul 30 14:40:57.960212 2026] [security2:error] [pid 43637:tid 43787] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuoyYa8U9lZpWaWlJJ5DwAAABM"]
[Thu Jul 30 14:40:58.004046 2026] [security2:error] [pid 43637:tid 43806] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5EQAAACY"]
[Thu Jul 30 14:40:58.004624 2026] [security2:error] [pid 43637:tid 43885] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/api/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5EgAAAHU"]
[Thu Jul 30 14:40:58.102332 2026] [security2:error] [pid 43637:tid 43859] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoyoa8U9lZpWaWlJJ5FAAAAFs"]
[Thu Jul 30 14:40:58.121186 2026] [security2:error] [pid 43637:tid 43819] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5FQAAADM"]
[Thu Jul 30 14:40:58.140617 2026] [security2:error] [pid 43637:tid 43834] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5FgAAAEI"]
[Thu Jul 30 14:40:58.154644 2026] [security2:error] [pid 43637:tid 43871] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoyoa8U9lZpWaWlJJ5FwAAAGc"]
[Thu Jul 30 14:40:58.160107 2026] [security2:error] [pid 43637:tid 43783] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5GQAAAA8"]
[Thu Jul 30 14:40:58.203843 2026] [security2:error] [pid 43637:tid 43823] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/dev/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5GgAAADc"]
[Thu Jul 30 14:40:58.272881 2026] [security2:error] [pid 43637:tid 43828] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoyoa8U9lZpWaWlJJ5IAAAADw"]
[Thu Jul 30 14:40:58.305124 2026] [security2:error] [pid 43637:tid 43858] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoyoa8U9lZpWaWlJJ5IwAAAFo"]
[Thu Jul 30 14:40:58.320649 2026] [security2:error] [pid 43637:tid 43791] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/dev/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5JQAAABc"]
[Thu Jul 30 14:40:58.354356 2026] [security2:error] [pid 43637:tid 43848] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoyoa8U9lZpWaWlJJ5KAAAAFA"]
[Thu Jul 30 14:40:58.463345 2026] [security2:error] [pid 43637:tid 43812] [client 20.104.18.253:2376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/ad.php"] [unique_id "amuoyoa8U9lZpWaWlJJ5LAAAACw"]
[Thu Jul 30 14:40:58.471220 2026] [security2:error] [pid 43637:tid 43844] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoyoa8U9lZpWaWlJJ5LQAAAEw"]
[Thu Jul 30 14:40:58.486339 2026] [security2:error] [pid 43637:tid 43833] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5LgAAAEE"]
[Thu Jul 30 14:40:58.544360 2026] [security2:error] [pid 43637:tid 43889] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5LwAAAHk"]
[Thu Jul 30 14:40:58.598359 2026] [security2:error] [pid 43637:tid 43890] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5MQAAAHo"]
[Thu Jul 30 14:40:58.721807 2026] [security2:error] [pid 43637:tid 43813] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5OwAAAC0"]
[Thu Jul 30 14:40:58.737536 2026] [security2:error] [pid 43637:tid 43801] [client 20.63.98.115:36302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/options.php"] [unique_id "amuoyoa8U9lZpWaWlJJ5PAAAACE"]
[Thu Jul 30 14:40:58.805008 2026] [security2:error] [pid 43637:tid 43877] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5QgAAAG0"]
[Thu Jul 30 14:40:58.815576 2026] [security2:error] [pid 43637:tid 43770] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/laravel/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5RAAAAAI"]
[Thu Jul 30 14:40:58.848094 2026] [security2:error] [pid 43637:tid 43768] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5SAAAAAA"]
[Thu Jul 30 14:40:58.856620 2026] [autoindex:error] [pid 43637:tid 43809] [client 87.236.176.36:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://n1rmalabet88.com:8080
[Thu Jul 30 14:40:58.902854 2026] [security2:error] [pid 43637:tid 43838] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5TQAAAEY"]
[Thu Jul 30 14:40:58.919934 2026] [security2:error] [pid 43637:tid 43853] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/laravel/.env"] [unique_id "amuoyoa8U9lZpWaWlJJ5TgAAAFU"]
[Thu Jul 30 14:40:59.032537 2026] [security2:error] [pid 43637:tid 43824] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5VQAAADg"]
[Thu Jul 30 14:40:59.093370 2026] [security2:error] [pid 43637:tid 43881] [client 20.104.18.253:31717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/ad24f.php"] [unique_id "amuoy4a8U9lZpWaWlJJ5WAAAAHE"]
[Thu Jul 30 14:40:59.142209 2026] [security2:error] [pid 43637:tid 43851] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/backend/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5WQAAAFM"]
[Thu Jul 30 14:40:59.166694 2026] [security2:error] [pid 43637:tid 43884] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5WwAAAHQ"]
[Thu Jul 30 14:40:59.177366 2026] [security2:error] [pid 43637:tid 43843] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5XAAAAEs"]
[Thu Jul 30 14:40:59.186479 2026] [security2:error] [pid 43637:tid 43827] [client 5.175.146.247:13014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuoyoa8U9lZpWaWlJJ5SwAAADs"], referer: http://pkf.jo
[Thu Jul 30 14:40:59.230591 2026] [security2:error] [pid 43637:tid 43800] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/backend/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5YAAAACA"]
[Thu Jul 30 14:40:59.312580 2026] [security2:error] [pid 43637:tid 43873] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5ZgAAAGk"]
[Thu Jul 30 14:40:59.364383 2026] [security2:error] [pid 43637:tid 43819] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5bwAAADM"]
[Thu Jul 30 14:40:59.446487 2026] [security2:error] [pid 43637:tid 43807] [client 52.238.199.152:39088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/users.php"] [unique_id "amuoy4a8U9lZpWaWlJJ5dwAAACc"]
[Thu Jul 30 14:40:59.463090 2026] [security2:error] [pid 43637:tid 43858] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuoy4a8U9lZpWaWlJJ5eAAAAFo"]
[Thu Jul 30 14:40:59.505510 2026] [security2:error] [pid 43637:tid 43869] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5ewAAAGU"]
[Thu Jul 30 14:40:59.505724 2026] [security2:error] [pid 43637:tid 43867] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5egAAAGM"]
[Thu Jul 30 14:40:59.514314 2026] [security2:error] [pid 43637:tid 43835] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuoy4a8U9lZpWaWlJJ5fAAAAEM"]
[Thu Jul 30 14:40:59.611684 2026] [security2:error] [pid 43637:tid 43887] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5ggAAAHc"]
[Thu Jul 30 14:40:59.649511 2026] [security2:error] [pid 43637:tid 43795] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/web/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5gwAAABs"]
[Thu Jul 30 14:40:59.653150 2026] [security2:error] [pid 43637:tid 43836] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuoy4a8U9lZpWaWlJJ5hAAAAEQ"]
[Thu Jul 30 14:40:59.656866 2026] [security2:error] [pid 43637:tid 43793] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuoy4a8U9lZpWaWlJJ5hQAAABk"]
[Thu Jul 30 14:40:59.664367 2026] [security2:error] [pid 43637:tid 43846] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5hgAAAE4"]
[Thu Jul 30 14:40:59.699985 2026] [security2:error] [pid 43637:tid 43777] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/web/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5hwAAAAk"]
[Thu Jul 30 14:40:59.718058 2026] [security2:error] [pid 43637:tid 43840] [client 40.77.167.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuoy4a8U9lZpWaWlJJ5dgAAAEg"]
[Thu Jul 30 14:40:59.733967 2026] [security2:error] [pid 43637:tid 43820] [client 135.119.63.61:7344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/appreciators.php"] [unique_id "amuoy4a8U9lZpWaWlJJ5iAAAADQ"]
[Thu Jul 30 14:40:59.741894 2026] [security2:error] [pid 43637:tid 43829] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5iQAAAD0"]
[Thu Jul 30 14:40:59.753751 2026] [security2:error] [pid 43637:tid 43891] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/api/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5jAAAAHs"]
[Thu Jul 30 14:40:59.788411 2026] [security2:error] [pid 43637:tid 43790] [client 20.104.18.253:31739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/add-venue-ru.php"] [unique_id "amuoy4a8U9lZpWaWlJJ5jwAAABY"]
[Thu Jul 30 14:40:59.795782 2026] [security2:error] [pid 43637:tid 43805] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/.env.bak"] [unique_id "amuoy4a8U9lZpWaWlJJ5kAAAACU"]
[Thu Jul 30 14:40:59.807455 2026] [security2:error] [pid 43637:tid 43868] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5kQAAAGQ"]
[Thu Jul 30 14:40:59.850888 2026] [security2:error] [pid 43637:tid 43856] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/.env.bak"] [unique_id "amuoy4a8U9lZpWaWlJJ5lgAAAFg"]
[Thu Jul 30 14:40:59.897259 2026] [security2:error] [pid 43637:tid 43877] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuoy4a8U9lZpWaWlJJ5mgAAAG0"]
[Thu Jul 30 14:40:59.918773 2026] [security2:error] [pid 43637:tid 43870] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5nAAAAGY"]
[Thu Jul 30 14:40:59.940972 2026] [security2:error] [pid 43637:tid 43883] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/staging/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5oAAAAHM"]
[Thu Jul 30 14:40:59.941953 2026] [security2:error] [pid 43637:tid 43773] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuoy4a8U9lZpWaWlJJ5nwAAAAU"]
[Thu Jul 30 14:40:59.942043 2026] [security2:error] [pid 43637:tid 43773] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuoy4a8U9lZpWaWlJJ5nwAAAAU"]
[Thu Jul 30 14:40:59.969394 2026] [security2:error] [pid 43637:tid 43774] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5ogAAAAY"]
[Thu Jul 30 14:40:59.999179 2026] [security2:error] [pid 43637:tid 43826] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/staging/.env"] [unique_id "amuoy4a8U9lZpWaWlJJ5owAAADo"]
[Thu Jul 30 14:41:00.051092 2026] [security2:error] [pid 43637:tid 43838] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5pAAAAEY"]
[Thu Jul 30 14:41:00.053884 2026] [security2:error] [pid 43637:tid 43853] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/dev/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5pQAAAFU"]
[Thu Jul 30 14:41:00.067330 2026] [security2:error] [pid 43637:tid 43852] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuozIa8U9lZpWaWlJJ5pgAAAFQ"]
[Thu Jul 30 14:41:00.111631 2026] [security2:error] [pid 43637:tid 43808] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5qQAAACg"]
[Thu Jul 30 14:41:00.116468 2026] [security2:error] [pid 43637:tid 43821] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuozIa8U9lZpWaWlJJ5qgAAADU"]
[Thu Jul 30 14:41:00.117457 2026] [security2:error] [pid 43637:tid 43878] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5qwAAAG4"]
[Thu Jul 30 14:41:00.186788 2026] [security2:error] [pid 43637:tid 43779] [client 20.63.98.115:36665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuozIa8U9lZpWaWlJJ5rQAAAAs"]
[Thu Jul 30 14:41:00.200055 2026] [security2:error] [pid 43637:tid 43785] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.appliancerepairservice.one"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "amuozIa8U9lZpWaWlJJ5rgAAABE"]
[Thu Jul 30 14:41:00.265764 2026] [security2:error] [pid 43637:tid 43827] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/core/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5swAAADs"]
[Thu Jul 30 14:41:00.267526 2026] [security2:error] [pid 43637:tid 43865] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuozIa8U9lZpWaWlJJ5tAAAAGE"]
[Thu Jul 30 14:41:00.308865 2026] [security2:error] [pid 43637:tid 43800] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/core/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5uAAAACA"]
[Thu Jul 30 14:41:00.325504 2026] [security2:error] [pid 43637:tid 43782] [client 94.154.43.186:22874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.themushroom.online"] [uri "/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5uQAAAA4"]
[Thu Jul 30 14:41:00.410200 2026] [security2:error] [pid 43637:tid 43857] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5wQAAAFk"]
[Thu Jul 30 14:41:00.410849 2026] [security2:error] [pid 43637:tid 43859] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuozIa8U9lZpWaWlJJ5wgAAAFs"]
[Thu Jul 30 14:41:00.414625 2026] [security2:error] [pid 43637:tid 43851] [client 20.104.18.253:2537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.kingstarenterprises.com"] [uri "/adm.php"] [unique_id "amuozIa8U9lZpWaWlJJ5wwAAAFM"]
[Thu Jul 30 14:41:00.429845 2026] [security2:error] [pid 43637:tid 43819] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5xQAAADM"]
[Thu Jul 30 14:41:00.456873 2026] [security2:error] [pid 43637:tid 43783] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuozIa8U9lZpWaWlJJ5xgAAAA8"]
[Thu Jul 30 14:41:00.467757 2026] [security2:error] [pid 43637:tid 43786] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuozIa8U9lZpWaWlJJ5xwAAABI"]
[Thu Jul 30 14:41:00.467839 2026] [security2:error] [pid 43637:tid 43786] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuozIa8U9lZpWaWlJJ5xwAAABI"]
[Thu Jul 30 14:41:00.508759 2026] [security2:error] [pid 43637:tid 43879] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5ygAAAG8"]
[Thu Jul 30 14:41:00.553173 2026] [security2:error] [pid 43637:tid 43837] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuozIa8U9lZpWaWlJJ5zAAAAEU"]
[Thu Jul 30 14:41:00.564580 2026] [security2:error] [pid 43637:tid 43828] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuozIa8U9lZpWaWlJJ5zQAAADw"]
[Thu Jul 30 14:41:00.657150 2026] [security2:error] [pid 43637:tid 43867] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/laravel/.env"] [unique_id "amuozIa8U9lZpWaWlJJ50QAAAGM"]
[Thu Jul 30 14:41:00.695846 2026] [security2:error] [pid 43637:tid 43848] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuozIa8U9lZpWaWlJJ51AAAAFA"]
[Thu Jul 30 14:41:00.730030 2026] [security2:error] [pid 43637:tid 43781] [client 46.183.217.105:40606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuozIa8U9lZpWaWlJJ5yAAAAA0"]
[Thu Jul 30 14:41:00.730129 2026] [security2:error] [pid 43637:tid 43781] [client 46.183.217.105:40606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuozIa8U9lZpWaWlJJ5yAAAAA0"]
[Thu Jul 30 14:41:00.866959 2026] [security2:error] [pid 43637:tid 43890] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/images/.env"] [unique_id "amuozIa8U9lZpWaWlJJ54gAAAHo"]
[Thu Jul 30 14:41:00.897399 2026] [security2:error] [pid 43637:tid 43796] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/images/.env"] [unique_id "amuozIa8U9lZpWaWlJJ55AAAABw"]
[Thu Jul 30 14:41:00.930611 2026] [security2:error] [pid 43637:tid 43831] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuozIa8U9lZpWaWlJJ56AAAAD8"]
[Thu Jul 30 14:41:00.969737 2026] [security2:error] [pid 43637:tid 43792] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/backend/.env"] [unique_id "amuozIa8U9lZpWaWlJJ57AAAABg"]
[Thu Jul 30 14:41:00.994329 2026] [security2:error] [pid 43637:tid 43877] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/xstelth.php"] [unique_id "amuozIa8U9lZpWaWlJJ57gAAAG0"]
[Thu Jul 30 14:41:00.994422 2026] [security2:error] [pid 43637:tid 43877] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/xstelth.php"] [unique_id "amuozIa8U9lZpWaWlJJ57gAAAG0"]
[Thu Jul 30 14:41:01.008181 2026] [security2:error] [pid 43637:tid 43770] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuozYa8U9lZpWaWlJJ57wAAAAI"]
[Thu Jul 30 14:41:01.050602 2026] [security2:error] [pid 43637:tid 43870] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuozYa8U9lZpWaWlJJ58gAAAGY"]
[Thu Jul 30 14:41:01.075559 2026] [security2:error] [pid 43637:tid 43825] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuozYa8U9lZpWaWlJJ59AAAADk"]
[Thu Jul 30 14:41:01.126206 2026] [security2:error] [pid 43637:tid 43816] [client 189.156.226.90:27202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuozYa8U9lZpWaWlJJ59gAAADA"]
[Thu Jul 30 14:41:01.126335 2026] [security2:error] [pid 43637:tid 43816] [client 189.156.226.90:27202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuozYa8U9lZpWaWlJJ59gAAADA"]
[Thu Jul 30 14:41:01.140236 2026] [security2:error] [pid 43637:tid 43797] [client 20.63.98.115:9660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/images/index.php"] [unique_id "amuozYa8U9lZpWaWlJJ59wAAAB0"]
[Thu Jul 30 14:41:01.141141 2026] [security2:error] [pid 43637:tid 43883] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuozYa8U9lZpWaWlJJ5-AAAAHM"]
[Thu Jul 30 14:41:01.153847 2026] [security2:error] [pid 43637:tid 43773] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuozYa8U9lZpWaWlJJ5-QAAAAU"]
[Thu Jul 30 14:41:01.218658 2026] [security2:error] [pid 43637:tid 43875] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuozYa8U9lZpWaWlJJ5_gAAAGs"]
[Thu Jul 30 14:41:01.283914 2026] [security2:error] [pid 43637:tid 43838] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "imap.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6AAAAAEY"]
[Thu Jul 30 14:41:01.362172 2026] [security2:error] [pid 43637:tid 43808] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/API/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6AgAAACg"]
[Thu Jul 30 14:41:01.372031 2026] [security2:error] [pid 43637:tid 43822] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/API/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6BwAAADY"]
[Thu Jul 30 14:41:01.442711 2026] [security2:error] [pid 43637:tid 43849] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/web/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6EAAAAFE"]
[Thu Jul 30 14:41:01.478328 2026] [security2:error] [pid 43637:tid 43882] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/584062352875874akp.php"] [unique_id "amuozYa8U9lZpWaWlJJ6EQAAAHI"]
[Thu Jul 30 14:41:01.478427 2026] [security2:error] [pid 43637:tid 43882] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/584062352875874akp.php"] [unique_id "amuozYa8U9lZpWaWlJJ6EQAAAHI"]
[Thu Jul 30 14:41:01.515253 2026] [security2:error] [pid 43637:tid 43798] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whm.appliancerepairservice.one"] [uri "/___proxy_subdomain_whm/app/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6FQAAAB4"]
[Thu Jul 30 14:41:01.539558 2026] [security2:error] [pid 43637:tid 43860] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6FgAAAFw"]
[Thu Jul 30 14:41:01.595129 2026] [security2:error] [pid 43637:tid 43769] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/.env.bak"] [unique_id "amuozYa8U9lZpWaWlJJ6FwAAAAE"]
[Thu Jul 30 14:41:01.599774 2026] [security2:error] [pid 43637:tid 43857] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6GAAAAFk"]
[Thu Jul 30 14:41:01.642043 2026] [security2:error] [pid 43637:tid 43866] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.appliancerepairservice.one"] [uri "/___proxy_subdomain_webdisk/app/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6GQAAAGI"]
[Thu Jul 30 14:41:01.681931 2026] [security2:error] [pid 43637:tid 43863] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuozYa8U9lZpWaWlJJ6HAAAAF8"]
[Thu Jul 30 14:41:01.745372 2026] [security2:error] [pid 43637:tid 43818] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6HgAAADI"]
[Thu Jul 30 14:41:01.747738 2026] [security2:error] [pid 43637:tid 43834] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/staging/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6HwAAAEI"]
[Thu Jul 30 14:41:01.857029 2026] [security2:error] [pid 43637:tid 43873] [client 135.119.63.61:19831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.globalmarks.pk"] [uri "/archive.php"] [unique_id "amuozYa8U9lZpWaWlJJ6JQAAAGk"]
[Thu Jul 30 14:41:01.943290 2026] [security2:error] [pid 43637:tid 43817] [client 20.63.98.115:9641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amuozYa8U9lZpWaWlJJ6KwAAADE"]
[Thu Jul 30 14:41:01.968738 2026] [security2:error] [pid 43637:tid 43867] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/newfile.php"] [unique_id "amuozYa8U9lZpWaWlJJ6MAAAAGM"]
[Thu Jul 30 14:41:01.968853 2026] [security2:error] [pid 43637:tid 43867] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/newfile.php"] [unique_id "amuozYa8U9lZpWaWlJJ6MAAAAGM"]
[Thu Jul 30 14:41:01.973138 2026] [security2:error] [pid 43637:tid 43848] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuozYa8U9lZpWaWlJJ6MgAAAFA"]
[Thu Jul 30 14:41:02.059955 2026] [security2:error] [pid 43637:tid 43836] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/core/.env"] [unique_id "amuozoa8U9lZpWaWlJJ6NgAAAEQ"]
[Thu Jul 30 14:41:02.074365 2026] [security2:error] [pid 43637:tid 43847] [client 102.209.222.212:25513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuozYa8U9lZpWaWlJJ6HQAAAE8"], referer: http://pkf.jo
[Thu Jul 30 14:41:02.122846 2026] [security2:error] [pid 43637:tid 43869] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pop.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuozoa8U9lZpWaWlJJ6NwAAAGU"]
[Thu Jul 30 14:41:02.138104 2026] [security2:error] [pid 43637:tid 43840] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuozoa8U9lZpWaWlJJ6OAAAAEg"]
[Thu Jul 30 14:41:02.210367 2026] [security2:error] [pid 43637:tid 43829] [client 77.90.185.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.185.90.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.appliancerepairservice.one"] [uri "/phpinfo.php"] [unique_id "amuozoa8U9lZpWaWlJJ6PAAAAD0"]
[Thu Jul 30 14:41:02.477702 2026] [security2:error] [pid 43637:tid 43754] [remote 57.141.0.37:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuozoa8U9lZpWaWlJJ6RgAAenQ"]
[Thu Jul 30 14:41:02.482962 2026] [security2:error] [pid 43637:tid 43856] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/tBEZGQz.php"] [unique_id "amuozoa8U9lZpWaWlJJ6SAAAAFg"]
[Thu Jul 30 14:41:02.483060 2026] [security2:error] [pid 43637:tid 43856] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/tBEZGQz.php"] [unique_id "amuozoa8U9lZpWaWlJJ6SAAAAFg"]
[Thu Jul 30 14:41:02.499761 2026] [security2:error] [pid 43637:tid 43830] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuozYa8U9lZpWaWlJJ6JgAAAD4"]
[Thu Jul 30 14:41:02.641489 2026] [security2:error] [pid 43637:tid 43797] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuozoa8U9lZpWaWlJJ6TgAAAB0"]
[Thu Jul 30 14:41:02.641523 2026] [security2:error] [pid 43637:tid 43883] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/images/.env"] [unique_id "amuozoa8U9lZpWaWlJJ6TwAAAHM"]
[Thu Jul 30 14:41:02.786915 2026] [security2:error] [pid 43637:tid 43850] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuozoa8U9lZpWaWlJJ6UAAAAFI"]
[Thu Jul 30 14:41:02.883992 2026] [security2:error] [pid 43637:tid 43656] [remote 77.95.113.183:40792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.113.95.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amuozoa8U9lZpWaWlJJ6UgAALxI"]
[Thu Jul 30 14:41:03.015257 2026] [security2:error] [pid 43637:tid 43794] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.airevoduct.ltd"] [uri "/phpinfo"] [unique_id "amuoz4a8U9lZpWaWlJJ6WgAAABo"]
[Thu Jul 30 14:41:03.015372 2026] [security2:error] [pid 43637:tid 43794] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.airevoduct.ltd"] [uri "/phpinfo"] [unique_id "amuoz4a8U9lZpWaWlJJ6WgAAABo"]
[Thu Jul 30 14:41:03.092798 2026] [security2:error] [pid 43637:tid 43780] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/API/.env"] [unique_id "amuoz4a8U9lZpWaWlJJ6YAAAAAw"]
[Thu Jul 30 14:41:03.238395 2026] [security2:error] [pid 43637:tid 43827] [client 77.90.185.230:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ftp.appliancerepairservice.one"] [uri "/app/.env"] [unique_id "amuoz4a8U9lZpWaWlJJ6YQAAADs"]
[Thu Jul 30 14:41:03.548216 2026] [security2:error] [pid 43637:tid 43863] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/drykl.php"] [unique_id "amuoz4a8U9lZpWaWlJJ6agAAAF8"]
[Thu Jul 30 14:41:03.548310 2026] [security2:error] [pid 43637:tid 43863] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/drykl.php"] [unique_id "amuoz4a8U9lZpWaWlJJ6agAAAF8"]
[Thu Jul 30 14:41:03.677714 2026] [security2:error] [pid 43637:tid 43810] [client 20.63.98.115:1341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/13.php"] [unique_id "amuoz4a8U9lZpWaWlJJ6cQAAACo"]
[Thu Jul 30 14:41:04.078444 2026] [security2:error] [pid 43637:tid 43836] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amuo0Ia8U9lZpWaWlJJ6fAAAAEQ"]
[Thu Jul 30 14:41:04.078524 2026] [security2:error] [pid 43637:tid 43836] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amuo0Ia8U9lZpWaWlJJ6fAAAAEQ"]
[Thu Jul 30 14:41:04.178836 2026] [security2:error] [pid 43637:tid 43867] [client 52.167.144.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuoz4a8U9lZpWaWlJJ6dQAAAGM"]
[Thu Jul 30 14:41:04.217553 2026] [security2:error] [pid 43637:tid 43837] [client 181.46.39.15:49500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuoz4a8U9lZpWaWlJJ6dAAAAEU"], referer: http://pkf.jo
[Thu Jul 30 14:41:04.610239 2026] [security2:error] [pid 43637:tid 43792] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ls.php"] [unique_id "amuo0Ia8U9lZpWaWlJJ6hwAAABg"]
[Thu Jul 30 14:41:04.610368 2026] [security2:error] [pid 43637:tid 43792] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ls.php"] [unique_id "amuo0Ia8U9lZpWaWlJJ6hwAAABg"]
[Thu Jul 30 14:41:04.921809 2026] [security2:error] [pid 43637:tid 43812] [client 20.63.98.115:9606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lilyinspires.com"] [uri "/index.php"] [unique_id "amuo0Ia8U9lZpWaWlJJ6jgAAACw"]
[Thu Jul 30 14:41:05.087761 2026] [security2:error] [pid 43637:tid 43874] [client 52.167.144.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuo0Ia8U9lZpWaWlJJ6jQAAAGo"]
[Thu Jul 30 14:41:05.118823 2026] [security2:error] [pid 43637:tid 43768] [client 20.63.98.115:9606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/inputs.php"] [unique_id "amuo0Ya8U9lZpWaWlJJ6lgAAAAA"]
[Thu Jul 30 14:41:05.858936 2026] [security2:error] [pid 43637:tid 43821] [client 20.63.98.115:38484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/jquery.php"] [unique_id "amuo0Ya8U9lZpWaWlJJ6owAAADU"]
[Thu Jul 30 14:41:06.835011 2026] [security2:error] [pid 43637:tid 43879] [client 20.63.98.115:27146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/doc.php"] [unique_id "amuo0oa8U9lZpWaWlJJ6tgAAAG8"]
[Thu Jul 30 14:41:06.989206 2026] [core:notice] [pid 43637:tid 43887] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:41:07.070910 2026] [core:notice] [pid 43637:tid 43869] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:41:07.187768 2026] [security2:error] [pid 43637:tid 43873] [client 52.238.199.152:16849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/defaults.php"] [unique_id "amuo04a8U9lZpWaWlJJ6wwAAAGk"]
[Thu Jul 30 14:41:07.927444 2026] [security2:error] [pid 43637:tid 43825] [client 74.7.241.128:57868] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuo04a8U9lZpWaWlJJ60wAAOUM"]
[Thu Jul 30 14:41:07.946959 2026] [security2:error] [pid 43637:tid 43811] [client 20.226.5.174:14291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/custom-plugin.php"] [unique_id "amuo04a8U9lZpWaWlJJ61AAAACs"]
[Thu Jul 30 14:41:08.699220 2026] [security2:error] [pid 43637:tid 43802] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/dx.php"] [unique_id "amuo1Ia8U9lZpWaWlJJ64AAAACI"]
[Thu Jul 30 14:41:08.699337 2026] [security2:error] [pid 43637:tid 43802] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/dx.php"] [unique_id "amuo1Ia8U9lZpWaWlJJ64AAAACI"]
[Thu Jul 30 14:41:08.926011 2026] [security2:error] [pid 43637:tid 43882] [client 20.226.5.174:14273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/customize.php"] [unique_id "amuo1Ia8U9lZpWaWlJJ66wAAAHI"]
[Thu Jul 30 14:41:09.185266 2026] [security2:error] [pid 43637:tid 43885] [client 106.75.67.28:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/favicon.ico"] [unique_id "amuo1Ya8U9lZpWaWlJJ67AAAAHU"]
[Thu Jul 30 14:41:09.262522 2026] [security2:error] [pid 43637:tid 43835] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/mac.php"] [unique_id "amuo1Ya8U9lZpWaWlJJ68AAAAEM"]
[Thu Jul 30 14:41:09.262641 2026] [security2:error] [pid 43637:tid 43835] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/mac.php"] [unique_id "amuo1Ya8U9lZpWaWlJJ68AAAAEM"]
[Thu Jul 30 14:41:09.750798 2026] [security2:error] [pid 43637:tid 43646] [remote 74.7.243.224:51430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amuo1Ya8U9lZpWaWlJJ7AwAAEAg"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:41:09.813643 2026] [security2:error] [pid 43637:tid 43877] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/485.php"] [unique_id "amuo1Ya8U9lZpWaWlJJ7CQAAAG0"]
[Thu Jul 30 14:41:09.813786 2026] [security2:error] [pid 43637:tid 43877] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/485.php"] [unique_id "amuo1Ya8U9lZpWaWlJJ7CQAAAG0"]
[Thu Jul 30 14:41:09.853721 2026] [security2:error] [pid 43637:tid 43796] [client 20.226.5.174:14294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/cux.php"] [unique_id "amuo1Ya8U9lZpWaWlJJ7CwAAABw"]
[Thu Jul 30 14:41:09.995733 2026] [security2:error] [pid 43637:tid 43891] [client 37.18.63.236:22727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuo1Ya8U9lZpWaWlJJ7AQAAAHs"], referer: http://pkf.jo
[Thu Jul 30 14:41:10.020346 2026] [proxy:error] [pid 43637:tid 43812] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:10.020440 2026] [proxy_http:error] [pid 43637:tid 43812] [client 98.87.102.177:47954] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:10.021390 2026] [proxy:error] [pid 43637:tid 43812] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:10.021461 2026] [proxy_http:error] [pid 43637:tid 43812] [client 98.87.102.177:47954] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:10.026284 2026] [security2:error] [pid 43637:tid 43816] [client 106.75.67.28:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/robots.txt"] [unique_id "amuo1oa8U9lZpWaWlJJ7FQAAADA"]
[Thu Jul 30 14:41:10.042021 2026] [security2:error] [pid 43637:tid 43832] [client 106.75.67.28:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/sitemap.xml"] [unique_id "amuo1oa8U9lZpWaWlJJ7FgAAAEA"]
[Thu Jul 30 14:41:10.179525 2026] [security2:error] [pid 43637:tid 43641] [remote 103.74.116.239:45808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amuo1oa8U9lZpWaWlJJ7GAAAPQM"]
[Thu Jul 30 14:41:10.349148 2026] [security2:error] [pid 43637:tid 43878] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gelio1.php"] [unique_id "amuo1oa8U9lZpWaWlJJ7HwAAAG4"]
[Thu Jul 30 14:41:10.349239 2026] [security2:error] [pid 43637:tid 43878] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gelio1.php"] [unique_id "amuo1oa8U9lZpWaWlJJ7HwAAAG4"]
[Thu Jul 30 14:41:10.480827 2026] [security2:error] [pid 43637:tid 43883] [client 37.205.114.175:6600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuo1oa8U9lZpWaWlJJ7GQAAAHM"], referer: http://pkf.jo
[Thu Jul 30 14:41:10.832741 2026] [security2:error] [pid 43637:tid 43849] [client 90.171.79.68:59930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuo1oa8U9lZpWaWlJJ7JQAAAFE"], referer: http://pkf.jo
[Thu Jul 30 14:41:10.865956 2026] [security2:error] [pid 43637:tid 43862] [client 20.226.5.174:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/cw2013.php"] [unique_id "amuo1oa8U9lZpWaWlJJ7KQAAAF4"]
[Thu Jul 30 14:41:10.881712 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/lp6.php"] [unique_id "amuo1oa8U9lZpWaWlJJ7KgAAAGI"]
[Thu Jul 30 14:41:10.881796 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/lp6.php"] [unique_id "amuo1oa8U9lZpWaWlJJ7KgAAAGI"]
[Thu Jul 30 14:41:10.925178 2026] [security2:error] [pid 43637:tid 43852] [client 20.63.98.115:50100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/02.php"] [unique_id "amuo1oa8U9lZpWaWlJJ7LgAAAFQ"]
[Thu Jul 30 14:41:11.077969 2026] [security2:error] [pid 43637:tid 43800] [client 172.237.109.114:61575] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amuo14a8U9lZpWaWlJJ7NQAAACA"]
[Thu Jul 30 14:41:11.392400 2026] [security2:error] [pid 43637:tid 43807] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuo14a8U9lZpWaWlJJ7OAAAACc"]
[Thu Jul 30 14:41:11.392491 2026] [security2:error] [pid 43637:tid 43807] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuo14a8U9lZpWaWlJJ7OAAAACc"]
[Thu Jul 30 14:41:11.703807 2026] [security2:error] [pid 43637:tid 43781] [client 189.156.226.90:27388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuo14a8U9lZpWaWlJJ7QAAAAA0"]
[Thu Jul 30 14:41:11.703931 2026] [security2:error] [pid 43637:tid 43781] [client 189.156.226.90:27388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuo14a8U9lZpWaWlJJ7QAAAAA0"]
[Thu Jul 30 14:41:11.845088 2026] [security2:error] [pid 43637:tid 43867] [client 20.226.5.174:14287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/cwsd.php"] [unique_id "amuo14a8U9lZpWaWlJJ7QgAAAGM"]
[Thu Jul 30 14:41:11.895795 2026] [security2:error] [pid 43637:tid 43817] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-includes/sodium_compat/"] [unique_id "amuo14a8U9lZpWaWlJJ7QwAAADE"]
[Thu Jul 30 14:41:11.895906 2026] [security2:error] [pid 43637:tid 43817] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-includes/sodium_compat/"] [unique_id "amuo14a8U9lZpWaWlJJ7QwAAADE"]
[Thu Jul 30 14:41:12.050597 2026] [security2:error] [pid 43637:tid 43840] [client 45.168.200.227:33300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuo14a8U9lZpWaWlJJ7QQAAAEg"], referer: http://pkf.jo
[Thu Jul 30 14:41:12.089417 2026] [core:notice] [pid 43637:tid 43742] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:41:12.344388 2026] [security2:error] [pid 43637:tid 43892] [client 174.49.189.174:32930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7SwAAAHw"], referer: http://pkf.jo
[Thu Jul 30 14:41:12.406880 2026] [security2:error] [pid 43637:tid 43773] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/w3llscc.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7VQAAAAU"]
[Thu Jul 30 14:41:12.407001 2026] [security2:error] [pid 43637:tid 43773] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/w3llscc.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7VQAAAAU"]
[Thu Jul 30 14:41:12.430985 2026] [core:notice] [pid 43637:tid 43779] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:41:12.435246 2026] [security2:error] [pid 43637:tid 43779] [client 41.102.159.108:49094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/view/2683"] [unique_id "amuo2Ia8U9lZpWaWlJJ7UgAAAAs"]
[Thu Jul 30 14:41:12.512085 2026] [security2:error] [pid 43637:tid 43893] [client 86.193.64.121:48144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7UwAAAH0"], referer: http://pkf.jo
[Thu Jul 30 14:41:12.634295 2026] [security2:error] [pid 43637:tid 43812] [client 20.63.98.115:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/well-known/admin.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7XwAAACw"]
[Thu Jul 30 14:41:12.708266 2026] [security2:error] [pid 43637:tid 43850] [client 52.238.199.152:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7ZAAAAFI"]
[Thu Jul 30 14:41:12.825031 2026] [security2:error] [pid 43637:tid 43774] [client 20.226.5.174:14274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/cy.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7ZQAAAAY"]
[Thu Jul 30 14:41:12.931430 2026] [security2:error] [pid 43637:tid 43821] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/miru3.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7ZgAAADU"]
[Thu Jul 30 14:41:12.931601 2026] [security2:error] [pid 43637:tid 43821] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/miru3.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7ZgAAADU"]
[Thu Jul 30 14:41:12.942173 2026] [security2:error] [pid 43637:tid 43824] [client 131.222.232.212:23387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuo2Ia8U9lZpWaWlJJ7YAAAADg"], referer: http://pkf.jo
[Thu Jul 30 14:41:13.078426 2026] [security2:error] [pid 43637:tid 43782] [client 172.237.109.114:31092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7cAAAAA4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.078944 2026] [security2:error] [pid 43637:tid 43864] [client 172.237.109.114:54539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7cQAAAGA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.079514 2026] [security2:error] [pid 43637:tid 43806] [client 172.237.109.114:5663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7cgAAACY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.087387 2026] [security2:error] [pid 43637:tid 43860] [client 172.237.109.114:1025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7cwAAAFw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.089841 2026] [security2:error] [pid 43637:tid 43835] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7dAAAAEM"]
[Thu Jul 30 14:41:13.089922 2026] [security2:error] [pid 43637:tid 43835] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7dAAAAEM"]
[Thu Jul 30 14:41:13.093073 2026] [security2:error] [pid 43637:tid 43798] [client 172.237.109.114:37007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7dQAAAB4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.094280 2026] [security2:error] [pid 43637:tid 43894] [client 172.237.109.114:26843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7dgAAAH4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.094484 2026] [security2:error] [pid 43637:tid 43862] [client 172.237.109.114:1485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7dwAAAF4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.120617 2026] [security2:error] [pid 43637:tid 43834] [client 172.237.109.114:3841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7eAAAAEI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.122096 2026] [security2:error] [pid 43637:tid 43787] [client 172.237.109.114:47588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7eQAAABM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.123389 2026] [security2:error] [pid 43637:tid 43827] [client 172.237.109.114:64154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7ewAAADs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.123427 2026] [security2:error] [pid 43637:tid 43882] [client 172.237.109.114:33158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7egAAAHI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.123646 2026] [security2:error] [pid 43637:tid 43818] [client 172.237.109.114:57645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7fAAAADI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.123806 2026] [security2:error] [pid 43637:tid 43880] [client 172.237.109.114:33449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7fQAAAHA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.124528 2026] [security2:error] [pid 43637:tid 43819] [client 172.237.109.114:47668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7fgAAADM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.150821 2026] [security2:error] [pid 43637:tid 43881] [client 172.237.109.114:50155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7fwAAAHE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.151673 2026] [security2:error] [pid 43637:tid 43885] [client 172.237.109.114:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7gAAAAHU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.152133 2026] [security2:error] [pid 43637:tid 43823] [client 172.237.109.114:49851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7gQAAADc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:13.287094 2026] [core:notice] [pid 43637:tid 43717] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:41:13.405839 2026] [core:notice] [pid 43637:tid 43682] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:41:13.454824 2026] [security2:error] [pid 43637:tid 43784] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/autoload_classmap.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7hAAAABA"]
[Thu Jul 30 14:41:13.454937 2026] [security2:error] [pid 43637:tid 43784] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/autoload_classmap.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7hAAAABA"]
[Thu Jul 30 14:41:13.688166 2026] [security2:error] [pid 43637:tid 43859] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7jgAAAFs"]
[Thu Jul 30 14:41:13.688306 2026] [security2:error] [pid 43637:tid 43859] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7jgAAAFs"]
[Thu Jul 30 14:41:13.760468 2026] [autoindex:error] [pid 43637:tid 43831] [client 20.63.98.115:27169] AH01276: Cannot serve directory /home1/ocldjbte/public_html/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:13.806379 2026] [security2:error] [pid 43637:tid 43840] [client 20.226.5.174:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/cybershell.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7kAAAAEg"]
[Thu Jul 30 14:41:13.946823 2026] [security2:error] [pid 43637:tid 43779] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-content/"] [unique_id "amuo2Ya8U9lZpWaWlJJ7kQAAAAs"]
[Thu Jul 30 14:41:13.946932 2026] [security2:error] [pid 43637:tid 43779] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-content/"] [unique_id "amuo2Ya8U9lZpWaWlJJ7kQAAAAs"]
[Thu Jul 30 14:41:13.996244 2026] [security2:error] [pid 43637:tid 43838] [client 20.63.98.115:27169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/v.php"] [unique_id "amuo2Ya8U9lZpWaWlJJ7lQAAAEY"]
[Thu Jul 30 14:41:14.085276 2026] [security2:error] [pid 43637:tid 43872] [client 172.237.109.114:20602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7mQAAAGg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:14.090209 2026] [security2:error] [pid 43637:tid 43828] [client 172.237.109.114:41786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7mgAAADw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:14.123939 2026] [security2:error] [pid 43637:tid 43893] [client 172.237.109.114:34945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7ngAAAH0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:14.285171 2026] [security2:error] [pid 43637:tid 43780] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/inputs.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7nwAAAAw"]
[Thu Jul 30 14:41:14.285289 2026] [security2:error] [pid 43637:tid 43780] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/inputs.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7nwAAAAw"]
[Thu Jul 30 14:41:14.443621 2026] [security2:error] [pid 43637:tid 43824] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-content/themes/index.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7oQAAADg"]
[Thu Jul 30 14:41:14.443719 2026] [security2:error] [pid 43637:tid 43824] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-content/themes/index.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7oQAAADg"]
[Thu Jul 30 14:41:14.464447 2026] [core:notice] [pid 43637:tid 43771] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:41:14.770412 2026] [security2:error] [pid 43637:tid 43668] [remote 185.191.171.10:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "embassyofgermanypakistanllc.de"] [uri "/product/aprilaire-5000-whole-home-air-cleaner/"] [unique_id "amuo2oa8U9lZpWaWlJJ7rAAAXx4"]
[Thu Jul 30 14:41:14.770584 2026] [security2:error] [pid 43637:tid 43863] [client 185.191.171.10:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "embassyofgermanypakistanllc.de"] [uri "/product/aprilaire-5000-whole-home-air-cleaner/"] [unique_id "amuo2oa8U9lZpWaWlJJ7rAAAXx4"]
[Thu Jul 30 14:41:14.786457 2026] [security2:error] [pid 43637:tid 43849] [client 20.226.5.174:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/cylul.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7rQAAAFE"]
[Thu Jul 30 14:41:14.897606 2026] [security2:error] [pid 43637:tid 43775] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/admin.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7rwAAAAc"]
[Thu Jul 30 14:41:14.897703 2026] [security2:error] [pid 43637:tid 43775] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/admin.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7rwAAAAc"]
[Thu Jul 30 14:41:14.949175 2026] [security2:error] [pid 43637:tid 43836] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/av.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7sAAAAEQ"]
[Thu Jul 30 14:41:14.949268 2026] [security2:error] [pid 43637:tid 43836] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/av.php"] [unique_id "amuo2oa8U9lZpWaWlJJ7sAAAAEQ"]
[Thu Jul 30 14:41:15.443135 2026] [security2:error] [pid 43637:tid 43830] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-includes/l10n/"] [unique_id "amuo24a8U9lZpWaWlJJ7uwAAAD4"]
[Thu Jul 30 14:41:15.443240 2026] [security2:error] [pid 43637:tid 43830] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-includes/l10n/"] [unique_id "amuo24a8U9lZpWaWlJJ7uwAAAD4"]
[Thu Jul 30 14:41:15.522639 2026] [security2:error] [pid 43637:tid 43793] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/goods.php"] [unique_id "amuo24a8U9lZpWaWlJJ7vQAAABk"]
[Thu Jul 30 14:41:15.522744 2026] [security2:error] [pid 43637:tid 43793] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/goods.php"] [unique_id "amuo24a8U9lZpWaWlJJ7vQAAABk"]
[Thu Jul 30 14:41:15.537934 2026] [security2:error] [pid 43637:tid 43844] [client 20.63.98.115:36655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/main.php"] [unique_id "amuo24a8U9lZpWaWlJJ7vgAAAEw"]
[Thu Jul 30 14:41:15.702740 2026] [security2:error] [pid 43637:tid 43868] [client 20.226.5.174:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/d.php"] [unique_id "amuo24a8U9lZpWaWlJJ7xgAAAGQ"]
[Thu Jul 30 14:41:15.797696 2026] [security2:error] [pid 43637:tid 43895] [client 192.162.64.166:17900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuo24a8U9lZpWaWlJJ7vAAAAH8"], referer: http://pkf.jo
[Thu Jul 30 14:41:15.961618 2026] [security2:error] [pid 43637:tid 43854] [client 20.104.16.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amuo24a8U9lZpWaWlJJ7ywAAAFY"]
[Thu Jul 30 14:41:15.961736 2026] [security2:error] [pid 43637:tid 43854] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amuo24a8U9lZpWaWlJJ7ywAAAFY"]
[Thu Jul 30 14:41:16.201369 2026] [security2:error] [pid 43637:tid 43788] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/file.php"] [unique_id "amuo3Ia8U9lZpWaWlJJ70gAAABQ"]
[Thu Jul 30 14:41:16.201480 2026] [security2:error] [pid 43637:tid 43788] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/file.php"] [unique_id "amuo3Ia8U9lZpWaWlJJ70gAAABQ"]
[Thu Jul 30 14:41:16.502706 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/tiny.php"] [unique_id "amuo3Ia8U9lZpWaWlJJ71wAAAGI"]
[Thu Jul 30 14:41:16.502852 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/tiny.php"] [unique_id "amuo3Ia8U9lZpWaWlJJ71wAAAGI"]
[Thu Jul 30 14:41:16.602324 2026] [autoindex:error] [pid 43637:tid 43864] [client 13.140.136.17:0] AH01276: Cannot serve directory /home2/vvrhflte/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:16.675142 2026] [security2:error] [pid 43637:tid 43786] [client 20.226.5.174:14284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/d0main.php"] [unique_id "amuo3Ia8U9lZpWaWlJJ73QAAABI"]
[Thu Jul 30 14:41:16.854060 2026] [security2:error] [pid 43637:tid 43834] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/adminfuns.php"] [unique_id "amuo3Ia8U9lZpWaWlJJ75AAAAEI"]
[Thu Jul 30 14:41:16.854218 2026] [security2:error] [pid 43637:tid 43834] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/adminfuns.php"] [unique_id "amuo3Ia8U9lZpWaWlJJ75AAAAEI"]
[Thu Jul 30 14:41:16.911352 2026] [security2:error] [pid 43637:tid 43826] [client 20.63.98.115:38512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/.well-known/file.php"] [unique_id "amuo3Ia8U9lZpWaWlJJ75gAAADo"]
[Thu Jul 30 14:41:17.027707 2026] [security2:error] [pid 43637:tid 43882] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuo3Ya8U9lZpWaWlJJ75wAAAHI"]
[Thu Jul 30 14:41:17.027824 2026] [security2:error] [pid 43637:tid 43882] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuo3Ya8U9lZpWaWlJJ75wAAAHI"]
[Thu Jul 30 14:41:17.451076 2026] [security2:error] [pid 43637:tid 43803] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/404.php"] [unique_id "amuo3Ya8U9lZpWaWlJJ79AAAACM"]
[Thu Jul 30 14:41:17.451210 2026] [security2:error] [pid 43637:tid 43803] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/404.php"] [unique_id "amuo3Ya8U9lZpWaWlJJ79AAAACM"]
[Thu Jul 30 14:41:17.544234 2026] [security2:error] [pid 43637:tid 43871] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/zrrhj.php"] [unique_id "amuo3Ya8U9lZpWaWlJJ79QAAAGc"]
[Thu Jul 30 14:41:17.544348 2026] [security2:error] [pid 43637:tid 43871] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/zrrhj.php"] [unique_id "amuo3Ya8U9lZpWaWlJJ79QAAAGc"]
[Thu Jul 30 14:41:17.573546 2026] [security2:error] [pid 43637:tid 43837] [client 20.226.5.174:14283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/d4.php"] [unique_id "amuo3Ya8U9lZpWaWlJJ79gAAAEU"]
[Thu Jul 30 14:41:18.091342 2026] [security2:error] [pid 43637:tid 43770] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuo3oa8U9lZpWaWlJJ8AQAAAAI"]
[Thu Jul 30 14:41:18.091516 2026] [security2:error] [pid 43637:tid 43770] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuo3oa8U9lZpWaWlJJ8AQAAAAI"]
[Thu Jul 30 14:41:18.112739 2026] [security2:error] [pid 43637:tid 43859] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wk/index.php"] [unique_id "amuo3oa8U9lZpWaWlJJ8AgAAAFs"]
[Thu Jul 30 14:41:18.112888 2026] [security2:error] [pid 43637:tid 43859] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wk/index.php"] [unique_id "amuo3oa8U9lZpWaWlJJ8AgAAAFs"]
[Thu Jul 30 14:41:18.513211 2026] [security2:error] [pid 43637:tid 43815] [client 20.226.5.174:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/d65ve.php"] [unique_id "amuo3oa8U9lZpWaWlJJ8DAAAAC8"]
[Thu Jul 30 14:41:18.648229 2026] [security2:error] [pid 43637:tid 43878] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wpgum.php"] [unique_id "amuo3oa8U9lZpWaWlJJ8DQAAAG4"]
[Thu Jul 30 14:41:18.648353 2026] [security2:error] [pid 43637:tid 43878] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wpgum.php"] [unique_id "amuo3oa8U9lZpWaWlJJ8DQAAAG4"]
[Thu Jul 30 14:41:19.047847 2026] [core:notice] [pid 43637:tid 43821] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:41:19.172997 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ywwbf.php"] [unique_id "amuo34a8U9lZpWaWlJJ8GQAAAGI"]
[Thu Jul 30 14:41:19.173088 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ywwbf.php"] [unique_id "amuo34a8U9lZpWaWlJJ8GQAAAGI"]
[Thu Jul 30 14:41:19.366644 2026] [security2:error] [pid 43637:tid 43876] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/about.php"] [unique_id "amuo34a8U9lZpWaWlJJ8IAAAAGw"]
[Thu Jul 30 14:41:19.366749 2026] [security2:error] [pid 43637:tid 43876] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/about.php"] [unique_id "amuo34a8U9lZpWaWlJJ8IAAAAGw"]
[Thu Jul 30 14:41:19.397951 2026] [core:notice] [pid 43637:tid 43884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:41:19.488775 2026] [security2:error] [pid 43637:tid 43806] [client 20.226.5.174:14278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/d7.php"] [unique_id "amuo34a8U9lZpWaWlJJ8JQAAACY"]
[Thu Jul 30 14:41:19.716844 2026] [security2:error] [pid 43637:tid 43885] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/xoldj.php"] [unique_id "amuo34a8U9lZpWaWlJJ8KwAAAHU"]
[Thu Jul 30 14:41:19.716938 2026] [security2:error] [pid 43637:tid 43885] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/xoldj.php"] [unique_id "amuo34a8U9lZpWaWlJJ8KwAAAHU"]
[Thu Jul 30 14:41:20.011619 2026] [security2:error] [pid 43637:tid 43847] [client 52.238.199.152:16407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "amuo4Ia8U9lZpWaWlJJ8MgAAAE8"]
[Thu Jul 30 14:41:20.267270 2026] [security2:error] [pid 43637:tid 43817] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/f35.php"] [unique_id "amuo4Ia8U9lZpWaWlJJ8NgAAADE"]
[Thu Jul 30 14:41:20.267376 2026] [security2:error] [pid 43637:tid 43817] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/f35.php"] [unique_id "amuo4Ia8U9lZpWaWlJJ8NgAAADE"]
[Thu Jul 30 14:41:20.480968 2026] [security2:error] [pid 43637:tid 43820] [client 20.226.5.174:14303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/dashboardadmin.php"] [unique_id "amuo4Ia8U9lZpWaWlJJ8OgAAADQ"]
[Thu Jul 30 14:41:20.800685 2026] [security2:error] [pid 43637:tid 43816] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gk.php"] [unique_id "amuo4Ia8U9lZpWaWlJJ8QQAAADA"]
[Thu Jul 30 14:41:20.800777 2026] [security2:error] [pid 43637:tid 43816] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gk.php"] [unique_id "amuo4Ia8U9lZpWaWlJJ8QQAAADA"]
[Thu Jul 30 14:41:20.958452 2026] [security2:error] [pid 43637:tid 43790] [client 52.238.199.152:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/plugins.php"] [unique_id "amuo4Ia8U9lZpWaWlJJ8RwAAABY"]
[Thu Jul 30 14:41:21.285447 2026] [security2:error] [pid 43637:tid 43828] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/term.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8TAAAADw"]
[Thu Jul 30 14:41:21.285553 2026] [security2:error] [pid 43637:tid 43828] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/term.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8TAAAADw"]
[Thu Jul 30 14:41:21.306210 2026] [security2:error] [pid 43637:tid 43815] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/584062352875874akp.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8TwAAAC8"]
[Thu Jul 30 14:41:21.306305 2026] [security2:error] [pid 43637:tid 43815] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/584062352875874akp.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8TwAAAC8"]
[Thu Jul 30 14:41:21.459336 2026] [security2:error] [pid 43637:tid 43801] [client 20.226.5.174:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/dashboardalfa.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8UQAAACE"]
[Thu Jul 30 14:41:21.467956 2026] [autoindex:error] [pid 43637:tid 43812] [client 101.226.10.126:59598] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:21.468576 2026] [security2:error] [pid 43637:tid 43812] [client 101.226.10.126:59598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo4Ya8U9lZpWaWlJJ8UAAAACw"]
[Thu Jul 30 14:41:21.586110 2026] [security2:error] [pid 43637:tid 43839] [client 20.63.98.115:50055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8VwAAAEc"]
[Thu Jul 30 14:41:21.851868 2026] [security2:error] [pid 43637:tid 43852] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wper3.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8XQAAAFQ"]
[Thu Jul 30 14:41:21.852035 2026] [security2:error] [pid 43637:tid 43852] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wper3.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8XQAAAFQ"]
[Thu Jul 30 14:41:21.937082 2026] [security2:error] [pid 43637:tid 43864] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/ioxi-o.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8XgAAAGA"]
[Thu Jul 30 14:41:21.937205 2026] [security2:error] [pid 43637:tid 43864] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/ioxi-o.php"] [unique_id "amuo4Ya8U9lZpWaWlJJ8XgAAAGA"]
[Thu Jul 30 14:41:22.230236 2026] [security2:error] [pid 43637:tid 43799] [client 189.156.226.90:26689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8aQAAAB8"]
[Thu Jul 30 14:41:22.230365 2026] [security2:error] [pid 43637:tid 43799] [client 189.156.226.90:26689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8aQAAAB8"]
[Thu Jul 30 14:41:22.256025 2026] [autoindex:error] [pid 43637:tid 43807] [client 52.202.41.153:55231] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:22.284056 2026] [autoindex:error] [pid 43637:tid 43791] [client 101.226.10.126:59670] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:22.284648 2026] [security2:error] [pid 43637:tid 43791] [client 101.226.10.126:59670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo4oa8U9lZpWaWlJJ8awAAABc"]
[Thu Jul 30 14:41:22.388481 2026] [security2:error] [pid 43637:tid 43835] [client 20.226.5.174:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/dashboardbypass.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8bwAAAEM"]
[Thu Jul 30 14:41:22.403711 2026] [security2:error] [pid 43637:tid 43836] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/bthil.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8cAAAAEQ"]
[Thu Jul 30 14:41:22.403794 2026] [security2:error] [pid 43637:tid 43836] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/bthil.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8cAAAAEQ"]
[Thu Jul 30 14:41:22.552732 2026] [security2:error] [pid 43637:tid 43847] [client 20.9.4.9:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.koinjp189.com"] [uri "/1.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8cQAAAE8"]
[Thu Jul 30 14:41:22.552851 2026] [security2:error] [pid 43637:tid 43847] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/1.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8cQAAAE8"]
[Thu Jul 30 14:41:22.552951 2026] [security2:error] [pid 43637:tid 43847] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/1.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8cQAAAE8"]
[Thu Jul 30 14:41:22.632064 2026] [autoindex:error] [pid 43637:tid 43781] [client 101.226.10.126:59670] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:22.632682 2026] [security2:error] [pid 43637:tid 43781] [client 101.226.10.126:59670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo4oa8U9lZpWaWlJJ8dQAAAA0"]
[Thu Jul 30 14:41:22.734006 2026] [security2:error] [pid 43637:tid 43862] [client 100.24.149.244:25294] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/fabiano-gomes-desmoraliza-menor-e-ataca-verbalmente-o-presidente-do-sindicato-dos-jornalistas/"] [unique_id "amuo4oa8U9lZpWaWlJJ8egAAAF4"]
[Thu Jul 30 14:41:22.919175 2026] [security2:error] [pid 43637:tid 43889] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wyzer1.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8fgAAAHk"]
[Thu Jul 30 14:41:22.919292 2026] [security2:error] [pid 43637:tid 43889] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wyzer1.php"] [unique_id "amuo4oa8U9lZpWaWlJJ8fgAAAHk"]
[Thu Jul 30 14:41:22.979918 2026] [autoindex:error] [pid 43637:tid 43856] [client 101.226.10.126:59670] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:22.980559 2026] [security2:error] [pid 43637:tid 43856] [client 101.226.10.126:59670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo4oa8U9lZpWaWlJJ8fwAAAFg"]
[Thu Jul 30 14:41:23.115384 2026] [security2:error] [pid 43637:tid 43644] [remote 57.141.0.61:29886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3390535976/feed/rss2/"] [unique_id "amuo44a8U9lZpWaWlJJ8gAAAdwY"]
[Thu Jul 30 14:41:23.166533 2026] [security2:error] [pid 43637:tid 43892] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/alfa.php"] [unique_id "amuo44a8U9lZpWaWlJJ8hwAAAHw"]
[Thu Jul 30 14:41:23.166624 2026] [security2:error] [pid 43637:tid 43892] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/alfa.php"] [unique_id "amuo44a8U9lZpWaWlJJ8hwAAAHw"]
[Thu Jul 30 14:41:23.326596 2026] [security2:error] [pid 43637:tid 43832] [client 20.226.5.174:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/dashboardk.php"] [unique_id "amuo44a8U9lZpWaWlJJ8jQAAAEA"]
[Thu Jul 30 14:41:23.437319 2026] [security2:error] [pid 43637:tid 43895] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/mh.php"] [unique_id "amuo44a8U9lZpWaWlJJ8kQAAAH8"]
[Thu Jul 30 14:41:23.437413 2026] [security2:error] [pid 43637:tid 43895] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/mh.php"] [unique_id "amuo44a8U9lZpWaWlJJ8kQAAAH8"]
[Thu Jul 30 14:41:23.572931 2026] [security2:error] [pid 43637:tid 43876] [client 52.238.199.152:52617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/upgrade/wp-login.php"] [unique_id "amuo44a8U9lZpWaWlJJ8kwAAAGw"]
[Thu Jul 30 14:41:23.663777 2026] [autoindex:error] [pid 43637:tid 43840] [client 101.226.10.126:59788] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:23.664419 2026] [security2:error] [pid 43637:tid 43840] [client 101.226.10.126:59788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo44a8U9lZpWaWlJJ8lgAAAEg"]
[Thu Jul 30 14:41:23.783556 2026] [security2:error] [pid 43637:tid 43843] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/edit.php"] [unique_id "amuo44a8U9lZpWaWlJJ8ngAAAEs"]
[Thu Jul 30 14:41:23.783709 2026] [security2:error] [pid 43637:tid 43843] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/edit.php"] [unique_id "amuo44a8U9lZpWaWlJJ8ngAAAEs"]
[Thu Jul 30 14:41:23.913021 2026] [security2:error] [pid 43637:tid 43777] [client 20.63.98.115:40864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuo44a8U9lZpWaWlJJ8oQAAAAk"]
[Thu Jul 30 14:41:23.980755 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuo44a8U9lZpWaWlJJ8owAAAGI"]
[Thu Jul 30 14:41:23.980871 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuo44a8U9lZpWaWlJJ8owAAAGI"]
[Thu Jul 30 14:41:24.003043 2026] [security2:error] [pid 43637:tid 43860] [client 101.226.10.126:59788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:vars[1][]. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "phpinfo(,ARGS:vars[1][]"] [severity "CRITICAL"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo5Ia8U9lZpWaWlJJ8pAAAAFw"]
[Thu Jul 30 14:41:24.003212 2026] [security2:error] [pid 43637:tid 43860] [client 101.226.10.126:59788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo5Ia8U9lZpWaWlJJ8pAAAAFw"]
[Thu Jul 30 14:41:24.201318 2026] [security2:error] [pid 43637:tid 43894] [client 46.183.217.105:51576] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8qgAAAH4"]
[Thu Jul 30 14:41:24.201422 2026] [security2:error] [pid 43637:tid 43894] [client 46.183.217.105:51576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8qgAAAH4"]
[Thu Jul 30 14:41:24.223339 2026] [security2:error] [pid 43637:tid 43883] [client 20.226.5.174:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/dashboardwp.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8rAAAAHM"]
[Thu Jul 30 14:41:24.398234 2026] [security2:error] [pid 43637:tid 43810] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/elp.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8sQAAACo"]
[Thu Jul 30 14:41:24.398390 2026] [security2:error] [pid 43637:tid 43810] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/elp.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8sQAAACo"]
[Thu Jul 30 14:41:24.493313 2026] [security2:error] [pid 43637:tid 43818] [client 20.104.16.169:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.airevoduct.ltd"] [uri "/1.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8swAAADI"]
[Thu Jul 30 14:41:24.493425 2026] [security2:error] [pid 43637:tid 43818] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/1.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8swAAADI"]
[Thu Jul 30 14:41:24.493529 2026] [security2:error] [pid 43637:tid 43818] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/1.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8swAAADI"]
[Thu Jul 30 14:41:24.726148 2026] [autoindex:error] [pid 43637:tid 43847] [client 101.226.10.126:59868] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:24.726805 2026] [security2:error] [pid 43637:tid 43847] [client 101.226.10.126:59868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo5Ia8U9lZpWaWlJJ8uQAAAE8"]
[Thu Jul 30 14:41:24.972488 2026] [security2:error] [pid 43637:tid 43869] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/chosen.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8wAAAAGU"]
[Thu Jul 30 14:41:24.972597 2026] [security2:error] [pid 43637:tid 43869] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/chosen.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8wAAAAGU"]
[Thu Jul 30 14:41:24.985201 2026] [security2:error] [pid 43637:tid 43846] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/classwithtostring.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8wQAAAE4"]
[Thu Jul 30 14:41:24.985288 2026] [security2:error] [pid 43637:tid 43846] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/classwithtostring.php"] [unique_id "amuo5Ia8U9lZpWaWlJJ8wQAAAE4"]
[Thu Jul 30 14:41:25.099130 2026] [autoindex:error] [pid 43637:tid 43845] [client 101.226.10.126:59868] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:25.099727 2026] [security2:error] [pid 43637:tid 43845] [client 101.226.10.126:59868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo5Ya8U9lZpWaWlJJ8wwAAAE0"]
[Thu Jul 30 14:41:25.121893 2026] [security2:error] [pid 43637:tid 43871] [client 20.226.5.174:14298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/data.php"] [unique_id "amuo5Ya8U9lZpWaWlJJ8xAAAAGc"]
[Thu Jul 30 14:41:25.136842 2026] [security2:error] [pid 43637:tid 43863] [client 52.238.199.152:52615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/certificates/wp-login.php"] [unique_id "amuo5Ya8U9lZpWaWlJJ8xQAAAF8"]
[Thu Jul 30 14:41:25.323751 2026] [security2:error] [pid 43637:tid 43886] [client 191.232.199.39:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wk/index.php"] [unique_id "amuo5Ya8U9lZpWaWlJJ8zAAAAHY"]
[Thu Jul 30 14:41:25.468577 2026] [security2:error] [pid 43637:tid 43868] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/sd.php"] [unique_id "amuo5Ya8U9lZpWaWlJJ80QAAAGQ"]
[Thu Jul 30 14:41:25.468663 2026] [security2:error] [pid 43637:tid 43868] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/sd.php"] [unique_id "amuo5Ya8U9lZpWaWlJJ80QAAAGQ"]
[Thu Jul 30 14:41:25.472700 2026] [autoindex:error] [pid 43637:tid 43859] [client 101.226.10.126:59868] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:25.473358 2026] [security2:error] [pid 43637:tid 43859] [client 101.226.10.126:59868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo5Ya8U9lZpWaWlJJ80AAAAFs"]
[Thu Jul 30 14:41:25.956661 2026] [security2:error] [pid 43637:tid 43878] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/z60.php"] [unique_id "amuo5Ya8U9lZpWaWlJJ83AAAAG4"]
[Thu Jul 30 14:41:25.956744 2026] [security2:error] [pid 43637:tid 43878] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/z60.php"] [unique_id "amuo5Ya8U9lZpWaWlJJ83AAAAG4"]
[Thu Jul 30 14:41:26.124484 2026] [security2:error] [pid 43637:tid 43843] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/666.php"] [unique_id "amuo5oa8U9lZpWaWlJJ83QAAAEs"]
[Thu Jul 30 14:41:26.124595 2026] [security2:error] [pid 43637:tid 43843] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/666.php"] [unique_id "amuo5oa8U9lZpWaWlJJ83QAAAEs"]
[Thu Jul 30 14:41:26.214707 2026] [security2:error] [pid 43637:tid 43876] [client 20.226.5.174:14295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/data532.php"] [unique_id "amuo5oa8U9lZpWaWlJJ83gAAAGw"]
[Thu Jul 30 14:41:26.235466 2026] [security2:error] [pid 43637:tid 43773] [client 52.238.199.152:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/css/network.php"] [unique_id "amuo5oa8U9lZpWaWlJJ84AAAAAU"]
[Thu Jul 30 14:41:26.244431 2026] [security2:error] [pid 43637:tid 43785] [client 101.226.10.126:60006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/404.html"] [unique_id "amuo5oa8U9lZpWaWlJJ83wAAABE"]
[Thu Jul 30 14:41:26.503890 2026] [security2:error] [pid 43637:tid 43786] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/home.php"] [unique_id "amuo5oa8U9lZpWaWlJJ86gAAABI"]
[Thu Jul 30 14:41:26.503988 2026] [security2:error] [pid 43637:tid 43786] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/home.php"] [unique_id "amuo5oa8U9lZpWaWlJJ86gAAABI"]
[Thu Jul 30 14:41:26.636249 2026] [security2:error] [pid 43637:tid 43802] [client 101.226.10.126:60006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/404.html"] [unique_id "amuo5oa8U9lZpWaWlJJ87AAAACI"]
[Thu Jul 30 14:41:26.726628 2026] [proxy:error] [pid 43637:tid 43883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:26.726702 2026] [proxy_http:error] [pid 43637:tid 43883] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:26.727288 2026] [proxy:error] [pid 43637:tid 43883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:26.727333 2026] [proxy_http:error] [pid 43637:tid 43883] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:26.727428 2026] [security2:error] [pid 43637:tid 43883] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuo5oa8U9lZpWaWlJJ87QAAAHM"]
[Thu Jul 30 14:41:27.113039 2026] [security2:error] [pid 43637:tid 43873] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ws58.php"] [unique_id "amuo54a8U9lZpWaWlJJ8-AAAAGk"]
[Thu Jul 30 14:41:27.113141 2026] [security2:error] [pid 43637:tid 43873] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ws58.php"] [unique_id "amuo54a8U9lZpWaWlJJ8-AAAAGk"]
[Thu Jul 30 14:41:27.122137 2026] [security2:error] [pid 43637:tid 43810] [client 20.226.5.174:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/database.php"] [unique_id "amuo54a8U9lZpWaWlJJ8-gAAACo"]
[Thu Jul 30 14:41:27.165333 2026] [security2:error] [pid 43637:tid 43776] [client 191.232.199.39:42569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/av.php"] [unique_id "amuo54a8U9lZpWaWlJJ8_AAAAAg"]
[Thu Jul 30 14:41:27.319682 2026] [autoindex:error] [pid 43637:tid 43837] [client 101.226.10.126:60104] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:27.320317 2026] [security2:error] [pid 43637:tid 43837] [client 101.226.10.126:60104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo54a8U9lZpWaWlJJ9BAAAAEU"]
[Thu Jul 30 14:41:27.323691 2026] [security2:error] [pid 43637:tid 43811] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/ws54.php"] [unique_id "amuo54a8U9lZpWaWlJJ9BQAAACs"]
[Thu Jul 30 14:41:27.323833 2026] [security2:error] [pid 43637:tid 43811] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/ws54.php"] [unique_id "amuo54a8U9lZpWaWlJJ9BQAAACs"]
[Thu Jul 30 14:41:27.414618 2026] [security2:error] [pid 43637:tid 43881] [client 52.238.199.152:16260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-cron.php"] [unique_id "amuo54a8U9lZpWaWlJJ9CQAAAHE"]
[Thu Jul 30 14:41:27.415875 2026] [security2:error] [pid 43637:tid 43879] [client 85.208.96.201:40326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/26/em-esperanca-alunos-matriculados-na-rede-municipal-de-ensino-recebem-tablets-e-fardamento-completo/"] [unique_id "amuo54a8U9lZpWaWlJJ9CgAAAG8"]
[Thu Jul 30 14:41:27.415998 2026] [security2:error] [pid 43637:tid 43879] [client 85.208.96.201:40326] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/26/em-esperanca-alunos-matriculados-na-rede-municipal-de-ensino-recebem-tablets-e-fardamento-completo/"] [unique_id "amuo54a8U9lZpWaWlJJ9CgAAAG8"]
[Thu Jul 30 14:41:27.521441 2026] [security2:error] [pid 43637:tid 43781] [client 20.63.98.115:41823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-content/file.php"] [unique_id "amuo54a8U9lZpWaWlJJ9DgAAAA0"]
[Thu Jul 30 14:41:27.603963 2026] [security2:error] [pid 43637:tid 43833] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gulu.php"] [unique_id "amuo54a8U9lZpWaWlJJ9DwAAAEE"]
[Thu Jul 30 14:41:27.604073 2026] [security2:error] [pid 43637:tid 43833] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/gulu.php"] [unique_id "amuo54a8U9lZpWaWlJJ9DwAAAEE"]
[Thu Jul 30 14:41:27.648747 2026] [autoindex:error] [pid 43637:tid 43844] [client 101.226.10.126:60104] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:27.649355 2026] [security2:error] [pid 43637:tid 43844] [client 101.226.10.126:60104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo54a8U9lZpWaWlJJ9EAAAAEw"]
[Thu Jul 30 14:41:27.887008 2026] [security2:error] [pid 43637:tid 43842] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/deepseek_d.php"] [unique_id "amuo54a8U9lZpWaWlJJ9GAAAAEo"]
[Thu Jul 30 14:41:27.887103 2026] [security2:error] [pid 43637:tid 43842] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/deepseek_d.php"] [unique_id "amuo54a8U9lZpWaWlJJ9GAAAAEo"]
[Thu Jul 30 14:41:27.978765 2026] [autoindex:error] [pid 43637:tid 43779] [client 101.226.10.126:60104] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:27.979410 2026] [security2:error] [pid 43637:tid 43779] [client 101.226.10.126:60104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo54a8U9lZpWaWlJJ9GQAAAAs"]
[Thu Jul 30 14:41:28.080811 2026] [security2:error] [pid 43637:tid 43828] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuo6Ia8U9lZpWaWlJJ9HQAAADw"]
[Thu Jul 30 14:41:28.080900 2026] [security2:error] [pid 43637:tid 43828] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuo6Ia8U9lZpWaWlJJ9HQAAADw"]
[Thu Jul 30 14:41:28.103551 2026] [security2:error] [pid 43637:tid 43892] [client 20.226.5.174:14296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/date.php"] [unique_id "amuo6Ia8U9lZpWaWlJJ9HgAAAHw"]
[Thu Jul 30 14:41:28.470599 2026] [security2:error] [pid 43637:tid 43865] [client 191.232.199.39:42579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/mini.php"] [unique_id "amuo6Ia8U9lZpWaWlJJ9KgAAAGE"]
[Thu Jul 30 14:41:28.510764 2026] [security2:error] [pid 43637:tid 43812] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/function/function.php"] [unique_id "amuo6Ia8U9lZpWaWlJJ9KwAAACw"]
[Thu Jul 30 14:41:28.510867 2026] [security2:error] [pid 43637:tid 43812] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/function/function.php"] [unique_id "amuo6Ia8U9lZpWaWlJJ9KwAAACw"]
[Thu Jul 30 14:41:28.584931 2026] [security2:error] [pid 43637:tid 43774] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wpls.php"] [unique_id "amuo6Ia8U9lZpWaWlJJ9LwAAAAY"]
[Thu Jul 30 14:41:28.585034 2026] [security2:error] [pid 43637:tid 43774] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wpls.php"] [unique_id "amuo6Ia8U9lZpWaWlJJ9LwAAAAY"]
[Thu Jul 30 14:41:28.717911 2026] [autoindex:error] [pid 43637:tid 43864] [client 101.226.10.126:60214] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:28.718493 2026] [security2:error] [pid 43637:tid 43864] [client 101.226.10.126:60214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo6Ia8U9lZpWaWlJJ9NQAAAGA"]
[Thu Jul 30 14:41:28.882234 2026] [proxy:error] [pid 43637:tid 43883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:28.882318 2026] [proxy_http:error] [pid 43637:tid 43883] [client 185.247.137.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:2082
[Thu Jul 30 14:41:28.883198 2026] [proxy:error] [pid 43637:tid 43883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:28.883259 2026] [proxy_http:error] [pid 43637:tid 43883] [client 185.247.137.21:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.koinjp189.com:2082
[Thu Jul 30 14:41:29.102534 2026] [security2:error] [pid 43637:tid 43819] [client 101.226.10.126:60214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:vars[1][]. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "phpinfo(,ARGS:vars[1][]"] [severity "CRITICAL"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo6Ya8U9lZpWaWlJJ9QQAAADM"]
[Thu Jul 30 14:41:29.102680 2026] [security2:error] [pid 43637:tid 43819] [client 101.226.10.126:60214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo6Ya8U9lZpWaWlJJ9QQAAADM"]
[Thu Jul 30 14:41:29.116802 2026] [security2:error] [pid 43637:tid 43849] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/php.php"] [unique_id "amuo6Ya8U9lZpWaWlJJ9QwAAAFE"]
[Thu Jul 30 14:41:29.116941 2026] [security2:error] [pid 43637:tid 43849] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/php.php"] [unique_id "amuo6Ya8U9lZpWaWlJJ9QwAAAFE"]
[Thu Jul 30 14:41:29.131303 2026] [security2:error] [pid 43637:tid 43866] [client 20.226.5.174:14302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/dav.php"] [unique_id "amuo6Ya8U9lZpWaWlJJ9RAAAAGI"]
[Thu Jul 30 14:41:29.208546 2026] [security2:error] [pid 43637:tid 43778] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuo6Ia8U9lZpWaWlJJ9MQAACg4"]
[Thu Jul 30 14:41:29.484155 2026] [security2:error] [pid 43637:tid 43817] [client 101.226.10.126:60214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:chr|fwrite|fopen|system|echr|passthru|serialize|include|php_uname|popen|proc_open|shell_exec|mysql_query|eval|str_rot13|exec|proc_nice|proc_terminate|proc_get_status|proc_close|pfsockopen|leak|apache_child_terminate|posix_kill|posix_mkfifo|posix_ ..." at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "789"] [id "340128"] [rev "25"] [msg "Atomicorp.com WAF Rules: Remote PHP command exection"] [data "<?"] [severity "CRITICAL"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo6Ya8U9lZpWaWlJJ9TAAAADE"]
[Thu Jul 30 14:41:29.484261 2026] [security2:error] [pid 43637:tid 43817] [client 101.226.10.126:60214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo6Ya8U9lZpWaWlJJ9TAAAADE"]
[Thu Jul 30 14:41:29.569527 2026] [security2:error] [pid 43637:tid 43877] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/nw.php"] [unique_id "amuo6Ya8U9lZpWaWlJJ9TQAAAG0"]
[Thu Jul 30 14:41:29.569682 2026] [security2:error] [pid 43637:tid 43877] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/nw.php"] [unique_id "amuo6Ya8U9lZpWaWlJJ9TQAAAG0"]
[Thu Jul 30 14:41:29.636468 2026] [security2:error] [pid 43637:tid 43823] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/100.php"] [unique_id "amuo6Ya8U9lZpWaWlJJ9UQAAADc"]
[Thu Jul 30 14:41:29.636607 2026] [security2:error] [pid 43637:tid 43823] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/100.php"] [unique_id "amuo6Ya8U9lZpWaWlJJ9UQAAADc"]
[Thu Jul 30 14:41:29.857485 2026] [security2:error] [pid 43637:tid 43848] [client 191.232.199.39:49004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/aa.php"] [unique_id "amuo6Ya8U9lZpWaWlJJ9UgAAAFA"]
[Thu Jul 30 14:41:30.082174 2026] [security2:error] [pid 43637:tid 43810] [client 20.63.98.115:55093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-signup.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9WgAAACo"]
[Thu Jul 30 14:41:30.170585 2026] [security2:error] [pid 43637:tid 43770] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/BDKR28WP.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9XgAAAAI"]
[Thu Jul 30 14:41:30.170705 2026] [security2:error] [pid 43637:tid 43770] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/BDKR28WP.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9XgAAAAI"]
[Thu Jul 30 14:41:30.170795 2026] [security2:error] [pid 43637:tid 43787] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/xleet.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9XwAAABM"]
[Thu Jul 30 14:41:30.170916 2026] [security2:error] [pid 43637:tid 43787] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/xleet.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9XwAAABM"]
[Thu Jul 30 14:41:30.206754 2026] [security2:error] [pid 43637:tid 43842] [client 101.226.10.126:60348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/404.html"] [unique_id "amuo6oa8U9lZpWaWlJJ9YAAAAEo"]
[Thu Jul 30 14:41:30.230957 2026] [security2:error] [pid 43637:tid 43890] [client 20.226.5.174:14293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/db-cache.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9YQAAAHo"]
[Thu Jul 30 14:41:30.574365 2026] [security2:error] [pid 43637:tid 43808] [client 101.226.10.126:60348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/404.html"] [unique_id "amuo6oa8U9lZpWaWlJJ9aQAAACg"]
[Thu Jul 30 14:41:30.750804 2026] [security2:error] [pid 43637:tid 43843] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/browse.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9bQAAAEs"]
[Thu Jul 30 14:41:30.750906 2026] [security2:error] [pid 43637:tid 43843] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/browse.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9bQAAAEs"]
[Thu Jul 30 14:41:30.783443 2026] [security2:error] [pid 43637:tid 43893] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9bgAAAH0"]
[Thu Jul 30 14:41:30.783549 2026] [security2:error] [pid 43637:tid 43893] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9bgAAAH0"]
[Thu Jul 30 14:41:30.894344 2026] [security2:error] [pid 43637:tid 43768] [client 52.238.199.152:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/acp.php"] [unique_id "amuo6oa8U9lZpWaWlJJ9bwAAAAA"]
[Thu Jul 30 14:41:30.942094 2026] [security2:error] [pid 43637:tid 43794] [client 101.226.10.126:60348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/404.html"] [unique_id "amuo6oa8U9lZpWaWlJJ9cAAAABo"]
[Thu Jul 30 14:41:31.114084 2026] [security2:error] [pid 43637:tid 43880] [client 177.6.106.101:55230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuo64a8U9lZpWaWlJJ9eAAAAHA"]
[Thu Jul 30 14:41:31.114215 2026] [security2:error] [pid 43637:tid 43880] [client 177.6.106.101:55230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuo64a8U9lZpWaWlJJ9eAAAAHA"]
[Thu Jul 30 14:41:31.202443 2026] [security2:error] [pid 43637:tid 43878] [client 191.232.199.39:42586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/w.php"] [unique_id "amuo64a8U9lZpWaWlJJ9eQAAAG4"]
[Thu Jul 30 14:41:31.257896 2026] [security2:error] [pid 43637:tid 43786] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-good.php"] [unique_id "amuo64a8U9lZpWaWlJJ9fQAAABI"]
[Thu Jul 30 14:41:31.257972 2026] [security2:error] [pid 43637:tid 43786] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-good.php"] [unique_id "amuo64a8U9lZpWaWlJJ9fQAAABI"]
[Thu Jul 30 14:41:31.261895 2026] [security2:error] [pid 43637:tid 43876] [client 20.226.5.174:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/db-safe-mode.php"] [unique_id "amuo64a8U9lZpWaWlJJ9fgAAAGw"]
[Thu Jul 30 14:41:31.394437 2026] [security2:error] [pid 43637:tid 43802] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/155.php"] [unique_id "amuo64a8U9lZpWaWlJJ9fwAAACI"]
[Thu Jul 30 14:41:31.394557 2026] [security2:error] [pid 43637:tid 43802] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/155.php"] [unique_id "amuo64a8U9lZpWaWlJJ9fwAAACI"]
[Thu Jul 30 14:41:31.648174 2026] [autoindex:error] [pid 43637:tid 43778] [client 101.226.10.126:60490] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:31.648771 2026] [security2:error] [pid 43637:tid 43778] [client 101.226.10.126:60490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo64a8U9lZpWaWlJJ9jQAAAAo"]
[Thu Jul 30 14:41:31.995871 2026] [autoindex:error] [pid 43637:tid 43795] [client 101.226.10.126:60490] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:31.996528 2026] [security2:error] [pid 43637:tid 43795] [client 101.226.10.126:60490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo64a8U9lZpWaWlJJ9kQAAABs"]
[Thu Jul 30 14:41:32.023171 2026] [security2:error] [pid 43637:tid 43862] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/96i.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9kwAAAF4"]
[Thu Jul 30 14:41:32.023272 2026] [security2:error] [pid 43637:tid 43862] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/96i.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9kwAAAF4"]
[Thu Jul 30 14:41:32.247473 2026] [security2:error] [pid 43637:tid 43780] [client 20.226.5.174:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/db-update.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9nQAAAAw"]
[Thu Jul 30 14:41:32.343234 2026] [autoindex:error] [pid 43637:tid 43891] [client 101.226.10.126:60490] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:32.343844 2026] [security2:error] [pid 43637:tid 43891] [client 101.226.10.126:60490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo7Ia8U9lZpWaWlJJ9oQAAAHs"]
[Thu Jul 30 14:41:32.518651 2026] [security2:error] [pid 43637:tid 43845] [client 191.232.199.39:48026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/admin.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9owAAAE0"]
[Thu Jul 30 14:41:32.565250 2026] [security2:error] [pid 43637:tid 43800] [client 52.238.199.152:16280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/assets/bypass.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9qgAAACA"]
[Thu Jul 30 14:41:32.623075 2026] [security2:error] [pid 43637:tid 43892] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/as.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9rAAAAHw"]
[Thu Jul 30 14:41:32.623168 2026] [security2:error] [pid 43637:tid 43892] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/as.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9rAAAAHw"]
[Thu Jul 30 14:41:32.770033 2026] [security2:error] [pid 43637:tid 43868] [client 189.156.226.90:27092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9swAAAGQ"]
[Thu Jul 30 14:41:32.770140 2026] [security2:error] [pid 43637:tid 43868] [client 189.156.226.90:27092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9swAAAGQ"]
[Thu Jul 30 14:41:32.819177 2026] [security2:error] [pid 43637:tid 43815] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/8573.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9tAAAAC8"]
[Thu Jul 30 14:41:32.819271 2026] [security2:error] [pid 43637:tid 43815] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/8573.php"] [unique_id "amuo7Ia8U9lZpWaWlJJ9tAAAAC8"]
[Thu Jul 30 14:41:33.088578 2026] [autoindex:error] [pid 43637:tid 43884] [client 101.226.10.126:60614] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:33.089252 2026] [security2:error] [pid 43637:tid 43884] [client 101.226.10.126:60614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo7Ya8U9lZpWaWlJJ9twAAAHQ"]
[Thu Jul 30 14:41:33.204532 2026] [security2:error] [pid 43637:tid 43773] [client 20.226.5.174:14316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/db.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9zQAAAAU"]
[Thu Jul 30 14:41:33.219800 2026] [security2:error] [pid 43637:tid 43799] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/min.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9zgAAAB8"]
[Thu Jul 30 14:41:33.219899 2026] [security2:error] [pid 43637:tid 43799] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/min.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9zgAAAB8"]
[Thu Jul 30 14:41:33.314182 2026] [security2:error] [pid 43637:tid 43826] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-admin/install.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ90gAAADo"]
[Thu Jul 30 14:41:33.314332 2026] [security2:error] [pid 43637:tid 43826] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-admin/install.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ90gAAADo"]
[Thu Jul 30 14:41:33.319898 2026] [security2:error] [pid 43637:tid 43768] [client 172.237.109.114:22817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9uAAAAAA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.320097 2026] [security2:error] [pid 43637:tid 43768] [client 172.237.109.114:22817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9uAAAAAA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.335696 2026] [security2:error] [pid 43637:tid 43777] [client 172.237.109.114:31382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9vQAAAAk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.335803 2026] [security2:error] [pid 43637:tid 43777] [client 172.237.109.114:31382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9vQAAAAk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.336123 2026] [security2:error] [pid 43637:tid 43774] [client 172.237.109.114:6762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9xwAAAAY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.336197 2026] [security2:error] [pid 43637:tid 43839] [client 172.237.109.114:8947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9wAAAAEc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.339711 2026] [security2:error] [pid 43637:tid 43794] [client 172.237.109.114:18189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9uQAAABo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.348443 2026] [security2:error] [pid 43637:tid 43865] [client 172.237.109.114:22512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9uwAAAGE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.351693 2026] [security2:error] [pid 43637:tid 43812] [client 172.237.109.114:1342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9vgAAACw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.353281 2026] [security2:error] [pid 43637:tid 43771] [client 172.237.109.114:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9vwAAAAM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.361042 2026] [security2:error] [pid 43637:tid 43875] [client 172.237.109.114:41146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9wQAAAGs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.373124 2026] [security2:error] [pid 43637:tid 43821] [client 172.237.109.114:10959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9wwAAADU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.386753 2026] [security2:error] [pid 43637:tid 43850] [client 172.237.109.114:50621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9wgAAAFI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.391677 2026] [security2:error] [pid 43637:tid 43788] [client 172.237.109.114:49480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9xAAAABQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.404716 2026] [security2:error] [pid 43637:tid 43855] [client 172.237.109.114:64089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9xgAAAFc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.408004 2026] [security2:error] [pid 43637:tid 43874] [client 172.237.109.114:29937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9yQAAAGo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.408262 2026] [security2:error] [pid 43637:tid 43874] [client 172.237.109.114:29937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9yQAAAGo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:33.464795 2026] [security2:error] [pid 43637:tid 43778] [client 101.226.10.126:60614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "phpinfo(,ARGS:s"] [severity "CRITICAL"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo7Ya8U9lZpWaWlJJ91wAAAAo"]
[Thu Jul 30 14:41:33.464926 2026] [security2:error] [pid 43637:tid 43778] [client 101.226.10.126:60614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo7Ya8U9lZpWaWlJJ91wAAAAo"]
[Thu Jul 30 14:41:33.732702 2026] [security2:error] [pid 43637:tid 43824] [client 172.237.109.114:12939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ9ygAAADg"]
[Thu Jul 30 14:41:33.833346 2026] [security2:error] [pid 43637:tid 43831] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/classwithtostring.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ96AAAAD8"]
[Thu Jul 30 14:41:33.833452 2026] [security2:error] [pid 43637:tid 43831] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/classwithtostring.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ96AAAAD8"]
[Thu Jul 30 14:41:33.874763 2026] [security2:error] [pid 43637:tid 43862] [client 191.232.199.39:49007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ96QAAAF4"]
[Thu Jul 30 14:41:34.009898 2026] [security2:error] [pid 43637:tid 43836] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuo7Ya8U9lZpWaWlJJ91gAAAEQ"]
[Thu Jul 30 14:41:34.081299 2026] [security2:error] [pid 43637:tid 43890] [client 172.237.109.114:46191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7oa8U9lZpWaWlJJ97AAAAHo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:34.094366 2026] [security2:error] [pid 43637:tid 43797] [client 172.237.109.114:42160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7oa8U9lZpWaWlJJ97QAAAB0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:34.094834 2026] [security2:error] [pid 43637:tid 43828] [client 172.237.109.114:56024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7oa8U9lZpWaWlJJ97gAAADw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:34.101420 2026] [security2:error] [pid 43637:tid 43832] [client 172.237.109.114:1341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7oa8U9lZpWaWlJJ97wAAAEA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:34.121403 2026] [security2:error] [pid 43637:tid 43842] [client 172.237.109.114:2070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo7oa8U9lZpWaWlJJ98AAAAEo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:34.174354 2026] [autoindex:error] [pid 43637:tid 43801] [client 101.226.10.126:60724] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:34.174987 2026] [security2:error] [pid 43637:tid 43801] [client 101.226.10.126:60724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo7oa8U9lZpWaWlJJ98gAAACE"]
[Thu Jul 30 14:41:34.216964 2026] [security2:error] [pid 43637:tid 43872] [client 20.226.5.174:14323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/db/mar.php"] [unique_id "amuo7oa8U9lZpWaWlJJ9-QAAAGg"]
[Thu Jul 30 14:41:34.383844 2026] [security2:error] [pid 43637:tid 43807] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ohct.php"] [unique_id "amuo7oa8U9lZpWaWlJJ-AQAAACc"]
[Thu Jul 30 14:41:34.383963 2026] [security2:error] [pid 43637:tid 43807] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ohct.php"] [unique_id "amuo7oa8U9lZpWaWlJJ-AQAAACc"]
[Thu Jul 30 14:41:34.536267 2026] [autoindex:error] [pid 43637:tid 43794] [client 101.226.10.126:60724] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:34.536901 2026] [security2:error] [pid 43637:tid 43794] [client 101.226.10.126:60724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo7oa8U9lZpWaWlJJ-AgAAABo"]
[Thu Jul 30 14:41:34.758993 2026] [security2:error] [pid 43637:tid 43875] [client 128.2.204.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuo7oa8U9lZpWaWlJJ-BQAAAGs"]
[Thu Jul 30 14:41:34.877572 2026] [security2:error] [pid 43637:tid 43871] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/bless.php"] [unique_id "amuo7oa8U9lZpWaWlJJ-EAAAAGc"]
[Thu Jul 30 14:41:34.877700 2026] [security2:error] [pid 43637:tid 43871] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/bless.php"] [unique_id "amuo7oa8U9lZpWaWlJJ-EAAAAGc"]
[Thu Jul 30 14:41:34.896582 2026] [autoindex:error] [pid 43637:tid 43879] [client 101.226.10.126:60724] AH01276: Cannot serve directory /home2/dovdtnte/public_html/rodneyleesmith/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:34.897201 2026] [security2:error] [pid 43637:tid 43879] [client 101.226.10.126:60724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "rodneyleesmith.com"] [uri "/cgi-sys/403.html"] [unique_id "amuo7oa8U9lZpWaWlJJ-EwAAAG8"]
[Thu Jul 30 14:41:34.958587 2026] [proxy:error] [pid 43637:tid 43816] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:34.958656 2026] [proxy_http:error] [pid 43637:tid 43816] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:34.959316 2026] [proxy:error] [pid 43637:tid 43816] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:34.959362 2026] [proxy_http:error] [pid 43637:tid 43816] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:34.959449 2026] [security2:error] [pid 43637:tid 43816] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuo7oa8U9lZpWaWlJJ-FgAAADA"]
[Thu Jul 30 14:41:35.092843 2026] [security2:error] [pid 43637:tid 43889] [client 172.237.109.114:7153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuo74a8U9lZpWaWlJJ-FwAAAHk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:35.163459 2026] [security2:error] [pid 43637:tid 43837] [client 20.226.5.174:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/db/uploader.php"] [unique_id "amuo74a8U9lZpWaWlJJ-GAAAAEU"]
[Thu Jul 30 14:41:35.363539 2026] [security2:error] [pid 43637:tid 43829] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/about.php"] [unique_id "amuo74a8U9lZpWaWlJJ-JAAAAD0"]
[Thu Jul 30 14:41:35.363670 2026] [security2:error] [pid 43637:tid 43829] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/about.php"] [unique_id "amuo74a8U9lZpWaWlJJ-JAAAAD0"]
[Thu Jul 30 14:41:35.402379 2026] [security2:error] [pid 43637:tid 43830] [client 191.232.199.39:48988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/m.php"] [unique_id "amuo74a8U9lZpWaWlJJ-KgAAAD4"]
[Thu Jul 30 14:41:35.447185 2026] [security2:error] [pid 43637:tid 43818] [client 20.63.98.115:41821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuo74a8U9lZpWaWlJJ-LQAAADI"]
[Thu Jul 30 14:41:35.540764 2026] [security2:error] [pid 43637:tid 43809] [client 52.238.199.152:16257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/sx.php"] [unique_id "amuo74a8U9lZpWaWlJJ-MAAAACk"]
[Thu Jul 30 14:41:35.596148 2026] [security2:error] [pid 43637:tid 43842] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/php8.php"] [unique_id "amuo74a8U9lZpWaWlJJ-MgAAAEo"]
[Thu Jul 30 14:41:35.596245 2026] [security2:error] [pid 43637:tid 43842] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/php8.php"] [unique_id "amuo74a8U9lZpWaWlJJ-MgAAAEo"]
[Thu Jul 30 14:41:35.615025 2026] [security2:error] [pid 43637:tid 43854] [client 101.226.10.126:60846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "phpinfo(,ARGS:s"] [severity "CRITICAL"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo74a8U9lZpWaWlJJ-MwAAAFY"]
[Thu Jul 30 14:41:35.615124 2026] [security2:error] [pid 43637:tid 43854] [client 101.226.10.126:60846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "rodneyleesmith.com"] [uri "/"] [unique_id "amuo74a8U9lZpWaWlJJ-MwAAAFY"]
[Thu Jul 30 14:41:35.876121 2026] [security2:error] [pid 43637:tid 43810] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuo74a8U9lZpWaWlJJ-OwAAACo"]
[Thu Jul 30 14:41:35.876247 2026] [security2:error] [pid 43637:tid 43810] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuo74a8U9lZpWaWlJJ-OwAAACo"]
[Thu Jul 30 14:41:36.108913 2026] [security2:error] [pid 43637:tid 43861] [client 20.226.5.174:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/db_model.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-QQAAAF0"]
[Thu Jul 30 14:41:36.210747 2026] [security2:error] [pid 43637:tid 43773] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/admin.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-QwAAAAU"]
[Thu Jul 30 14:41:36.210843 2026] [security2:error] [pid 43637:tid 43773] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/admin.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-QwAAAAU"]
[Thu Jul 30 14:41:36.355554 2026] [security2:error] [pid 43637:tid 43804] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ta0ol.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-TgAAACQ"]
[Thu Jul 30 14:41:36.355654 2026] [security2:error] [pid 43637:tid 43804] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ta0ol.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-TgAAACQ"]
[Thu Jul 30 14:41:36.603004 2026] [security2:error] [pid 43637:tid 43875] [client 101.226.10.126:60914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-TQAAAGs"]
[Thu Jul 30 14:41:36.603120 2026] [security2:error] [pid 43637:tid 43875] [client 101.226.10.126:60914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-TQAAAGs"]
[Thu Jul 30 14:41:36.728621 2026] [security2:error] [pid 43637:tid 43821] [client 191.232.199.39:53475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-UgAAADU"]
[Thu Jul 30 14:41:36.802069 2026] [security2:error] [pid 43637:tid 43863] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/222.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-WAAAAF8"]
[Thu Jul 30 14:41:36.802153 2026] [security2:error] [pid 43637:tid 43863] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/222.php"] [unique_id "amuo8Ia8U9lZpWaWlJJ-WAAAAF8"]
[Thu Jul 30 14:41:36.867046 2026] [security2:error] [pid 43637:tid 43833] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/sa.php7"] [unique_id "amuo8Ia8U9lZpWaWlJJ-XAAAAEE"]
[Thu Jul 30 14:41:36.867129 2026] [security2:error] [pid 43637:tid 43833] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/sa.php7"] [unique_id "amuo8Ia8U9lZpWaWlJJ-XAAAAEE"]
[Thu Jul 30 14:41:37.072552 2026] [security2:error] [pid 43637:tid 43871] [client 20.226.5.174:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/dbx.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-YwAAAGc"]
[Thu Jul 30 14:41:37.341470 2026] [security2:error] [pid 43637:tid 43784] [client 101.226.10.126:32778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-bAAAABA"]
[Thu Jul 30 14:41:37.341592 2026] [security2:error] [pid 43637:tid 43784] [client 101.226.10.126:32778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-bAAAABA"]
[Thu Jul 30 14:41:37.384028 2026] [security2:error] [pid 43637:tid 43856] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-class.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-cgAAAFg"]
[Thu Jul 30 14:41:37.384139 2026] [security2:error] [pid 43637:tid 43856] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-class.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-cgAAAFg"]
[Thu Jul 30 14:41:37.502825 2026] [security2:error] [pid 43637:tid 43837] [client 172.237.109.114:22846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-XgAAAEU"]
[Thu Jul 30 14:41:37.899192 2026] [security2:error] [pid 43637:tid 43853] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/8.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-fgAAAFU"]
[Thu Jul 30 14:41:37.899304 2026] [security2:error] [pid 43637:tid 43853] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/8.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-fgAAAFU"]
[Thu Jul 30 14:41:37.990887 2026] [security2:error] [pid 43637:tid 43806] [client 101.226.10.126:32844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-gAAAACY"]
[Thu Jul 30 14:41:37.991048 2026] [security2:error] [pid 43637:tid 43806] [client 101.226.10.126:32844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo8Ya8U9lZpWaWlJJ-gAAAACY"]
[Thu Jul 30 14:41:38.028154 2026] [security2:error] [pid 43637:tid 43815] [client 20.226.5.174:14312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/dd.php"] [unique_id "amuo8oa8U9lZpWaWlJJ-gwAAAC8"]
[Thu Jul 30 14:41:38.214757 2026] [security2:error] [pid 43637:tid 43779] [client 52.238.199.152:52543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/adminfuns.php"] [unique_id "amuo8oa8U9lZpWaWlJJ-hQAAAAs"]
[Thu Jul 30 14:41:38.340707 2026] [security2:error] [pid 43637:tid 43826] [client 127.0.0.1:13208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuo8oa8U9lZpWaWlJJ-iAAAADo"]
[Thu Jul 30 14:41:38.340785 2026] [security2:error] [pid 43637:tid 43864] [client 74.7.228.14:33466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.rockyeahshirts.com"] [uri "/robots.txt"] [unique_id "amuo8oa8U9lZpWaWlJJ-hwAAYFw"]
[Thu Jul 30 14:41:38.404244 2026] [security2:error] [pid 43637:tid 43874] [client 191.232.199.39:3053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/classwithtostring.php"] [unique_id "amuo8oa8U9lZpWaWlJJ-jwAAAGo"]
[Thu Jul 30 14:41:38.411404 2026] [security2:error] [pid 43637:tid 43873] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/bootstrap.php"] [unique_id "amuo8oa8U9lZpWaWlJJ-kQAAAGk"]
[Thu Jul 30 14:41:38.411499 2026] [security2:error] [pid 43637:tid 43873] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/bootstrap.php"] [unique_id "amuo8oa8U9lZpWaWlJJ-kQAAAGk"]
[Thu Jul 30 14:41:38.507483 2026] [security2:error] [pid 43637:tid 43671] [remote 57.141.0.40:53786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuo8oa8U9lZpWaWlJJ-kwAAZCE"]
[Thu Jul 30 14:41:38.686075 2026] [security2:error] [pid 43637:tid 43885] [client 101.226.10.126:32906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo8oa8U9lZpWaWlJJ-mQAAAHU"]
[Thu Jul 30 14:41:38.686181 2026] [security2:error] [pid 43637:tid 43885] [client 101.226.10.126:32906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo8oa8U9lZpWaWlJJ-mQAAAHU"]
[Thu Jul 30 14:41:38.900208 2026] [security2:error] [pid 43637:tid 43847] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-blog-header.php"] [unique_id "amuo8oa8U9lZpWaWlJJ-nAAAAE8"]
[Thu Jul 30 14:41:38.900346 2026] [security2:error] [pid 43637:tid 43847] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-blog-header.php"] [unique_id "amuo8oa8U9lZpWaWlJJ-nAAAAE8"]
[Thu Jul 30 14:41:39.378536 2026] [security2:error] [pid 43637:tid 43770] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/aa.php"] [unique_id "amuo84a8U9lZpWaWlJJ-pwAAAAI"]
[Thu Jul 30 14:41:39.378689 2026] [security2:error] [pid 43637:tid 43770] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/aa.php"] [unique_id "amuo84a8U9lZpWaWlJJ-pwAAAAI"]
[Thu Jul 30 14:41:39.405998 2026] [security2:error] [pid 43637:tid 43645] [remote 57.141.18.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuo84a8U9lZpWaWlJJ-pAAATQc"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,linen,lycra,polyester,silicon&rating=5&status=instock&min_price=75&max_price=125&unfilter=1
[Thu Jul 30 14:41:39.438728 2026] [security2:error] [pid 43637:tid 43829] [client 101.226.10.126:32968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo84a8U9lZpWaWlJJ-qwAAAD0"]
[Thu Jul 30 14:41:39.438827 2026] [security2:error] [pid 43637:tid 43829] [client 101.226.10.126:32968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo84a8U9lZpWaWlJJ-qwAAAD0"]
[Thu Jul 30 14:41:39.549137 2026] [security2:error] [pid 43637:tid 43653] [remote 57.141.18.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuo84a8U9lZpWaWlJJ-rwAAEw8"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,linen,lycra,polyester,silicon&rating=5&status=instock&min_price=75&max_price=125&unfilter=1
[Thu Jul 30 14:41:39.589263 2026] [security2:error] [pid 43637:tid 43862] [client 52.238.199.152:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/about.php"] [unique_id "amuo84a8U9lZpWaWlJJ-sgAAAF4"]
[Thu Jul 30 14:41:39.610474 2026] [core:error] [pid 43637:tid 43820] [client 17.246.23.135:33526] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:41:39.610493 2026] [core:error] [pid 43637:tid 43820] [client 17.246.23.135:33526] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:41:39.762625 2026] [security2:error] [pid 43637:tid 43891] [client 191.232.199.39:3042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/gmo.php"] [unique_id "amuo84a8U9lZpWaWlJJ-uAAAAHs"]
[Thu Jul 30 14:41:39.854532 2026] [security2:error] [pid 43637:tid 43819] [client 20.63.98.115:1411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ge.php"] [unique_id "amuo84a8U9lZpWaWlJJ-uQAAADM"]
[Thu Jul 30 14:41:39.908451 2026] [security2:error] [pid 43637:tid 43854] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/tx79.php"] [unique_id "amuo84a8U9lZpWaWlJJ-ugAAAFY"]
[Thu Jul 30 14:41:39.908558 2026] [security2:error] [pid 43637:tid 43854] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/tx79.php"] [unique_id "amuo84a8U9lZpWaWlJJ-ugAAAFY"]
[Thu Jul 30 14:41:40.097992 2026] [security2:error] [pid 43637:tid 43884] [client 101.226.10.126:33024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php/module/action/param1/$%7B@print%28md5%282333%29%29%7D"] [unique_id "amuo9Ia8U9lZpWaWlJJ-wgAAAHQ"]
[Thu Jul 30 14:41:40.098101 2026] [security2:error] [pid 43637:tid 43884] [client 101.226.10.126:33024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php/module/action/param1/$%7B@print%28md5%282333%29%29%7D"] [unique_id "amuo9Ia8U9lZpWaWlJJ-wgAAAHQ"]
[Thu Jul 30 14:41:40.445716 2026] [security2:error] [pid 43637:tid 43797] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/motu.php"] [unique_id "amuo9Ia8U9lZpWaWlJJ-xgAAAB0"]
[Thu Jul 30 14:41:40.445830 2026] [security2:error] [pid 43637:tid 43797] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/motu.php"] [unique_id "amuo9Ia8U9lZpWaWlJJ-xgAAAB0"]
[Thu Jul 30 14:41:40.515836 2026] [security2:error] [pid 43637:tid 43798] [client 20.226.5.174:38023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/leaf_mailer.php"] [unique_id "amuo9Ia8U9lZpWaWlJJ-ygAAAB4"]
[Thu Jul 30 14:41:40.770714 2026] [security2:error] [pid 43637:tid 43868] [client 101.226.10.126:33072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo9Ia8U9lZpWaWlJJ-0wAAAGQ"]
[Thu Jul 30 14:41:40.770851 2026] [security2:error] [pid 43637:tid 43868] [client 101.226.10.126:33072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo9Ia8U9lZpWaWlJJ-0wAAAGQ"]
[Thu Jul 30 14:41:40.956796 2026] [security2:error] [pid 43637:tid 43792] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-head.php"] [unique_id "amuo9Ia8U9lZpWaWlJJ-1AAAABg"]
[Thu Jul 30 14:41:40.956913 2026] [security2:error] [pid 43637:tid 43792] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-head.php"] [unique_id "amuo9Ia8U9lZpWaWlJJ-1AAAABg"]
[Thu Jul 30 14:41:41.311538 2026] [security2:error] [pid 43637:tid 43827] [client 191.232.199.39:3048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuo9Ya8U9lZpWaWlJJ-4QAAADs"]
[Thu Jul 30 14:41:41.311933 2026] [security2:error] [pid 43637:tid 43799] [client 20.63.98.115:55085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/goods.php"] [unique_id "amuo9Ya8U9lZpWaWlJJ-4gAAAB8"]
[Thu Jul 30 14:41:41.436209 2026] [security2:error] [pid 43637:tid 43833] [client 20.226.5.174:38031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/leaf_php.php"] [unique_id "amuo9Ya8U9lZpWaWlJJ-5AAAAEE"]
[Thu Jul 30 14:41:41.458923 2026] [security2:error] [pid 43637:tid 43790] [client 101.226.10.126:33134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo9Ya8U9lZpWaWlJJ-5QAAABY"]
[Thu Jul 30 14:41:41.459071 2026] [security2:error] [pid 43637:tid 43790] [client 101.226.10.126:33134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo9Ya8U9lZpWaWlJJ-5QAAABY"]
[Thu Jul 30 14:41:41.462848 2026] [security2:error] [pid 43637:tid 43892] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuo9Ya8U9lZpWaWlJJ-5gAAAHw"]
[Thu Jul 30 14:41:41.462930 2026] [security2:error] [pid 43637:tid 43892] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuo9Ya8U9lZpWaWlJJ-5gAAAHw"]
[Thu Jul 30 14:41:41.831681 2026] [security2:error] [pid 43637:tid 43819] [client 206.135.24.10:51424] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuo9Ya8U9lZpWaWlJJ-8gAAADM"]
[Thu Jul 30 14:41:41.976380 2026] [security2:error] [pid 43637:tid 43878] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/60856e3a4findex.php"] [unique_id "amuo9Ya8U9lZpWaWlJJ-8wAAAG4"]
[Thu Jul 30 14:41:41.976490 2026] [security2:error] [pid 43637:tid 43878] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/60856e3a4findex.php"] [unique_id "amuo9Ya8U9lZpWaWlJJ-8wAAAG4"]
[Thu Jul 30 14:41:42.072189 2026] [security2:error] [pid 43637:tid 43884] [client 52.238.199.152:52536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/images/chosen.php"] [unique_id "amuo9oa8U9lZpWaWlJJ-9wAAAHQ"]
[Thu Jul 30 14:41:42.094297 2026] [security2:error] [pid 43637:tid 43828] [client 206.135.24.10:46604] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuo9oa8U9lZpWaWlJJ--AAAADw"]
[Thu Jul 30 14:41:42.145929 2026] [security2:error] [pid 43637:tid 43797] [client 101.226.10.126:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo9oa8U9lZpWaWlJJ-_wAAAB0"]
[Thu Jul 30 14:41:42.146040 2026] [security2:error] [pid 43637:tid 43797] [client 101.226.10.126:33188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo9oa8U9lZpWaWlJJ-_wAAAB0"]
[Thu Jul 30 14:41:42.303283 2026] [security2:error] [pid 43637:tid 43883] [client 20.63.98.115:1699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/403.php"] [unique_id "amuo9oa8U9lZpWaWlJJ_BgAAAHM"]
[Thu Jul 30 14:41:42.332308 2026] [security2:error] [pid 43637:tid 43882] [client 20.226.5.174:38027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/leafmailer.php"] [unique_id "amuo9oa8U9lZpWaWlJJ_BwAAAHI"]
[Thu Jul 30 14:41:42.493345 2026] [security2:error] [pid 43637:tid 43794] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-the.php"] [unique_id "amuo9oa8U9lZpWaWlJJ_CAAAABo"]
[Thu Jul 30 14:41:42.493461 2026] [security2:error] [pid 43637:tid 43794] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp-the.php"] [unique_id "amuo9oa8U9lZpWaWlJJ_CAAAABo"]
[Thu Jul 30 14:41:42.587382 2026] [security2:error] [pid 43637:tid 43889] [client 177.6.106.101:53461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuo9oa8U9lZpWaWlJJ_DAAAAHk"]
[Thu Jul 30 14:41:42.587486 2026] [security2:error] [pid 43637:tid 43889] [client 177.6.106.101:53461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuo9oa8U9lZpWaWlJJ_DAAAAHk"]
[Thu Jul 30 14:41:42.775493 2026] [security2:error] [pid 43637:tid 43817] [client 101.226.10.126:33246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo9oa8U9lZpWaWlJJ_EAAAADE"]
[Thu Jul 30 14:41:42.775636 2026] [security2:error] [pid 43637:tid 43817] [client 101.226.10.126:33246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo9oa8U9lZpWaWlJJ_EAAAADE"]
[Thu Jul 30 14:41:43.031952 2026] [security2:error] [pid 43637:tid 43816] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp.php"] [unique_id "amuo94a8U9lZpWaWlJJ_FQAAADA"]
[Thu Jul 30 14:41:43.032085 2026] [security2:error] [pid 43637:tid 43816] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wp.php"] [unique_id "amuo94a8U9lZpWaWlJJ_FQAAADA"]
[Thu Jul 30 14:41:43.272579 2026] [security2:error] [pid 43637:tid 43785] [client 20.226.5.174:38019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/leafmailer.php.php"] [unique_id "amuo94a8U9lZpWaWlJJ_HQAAABE"]
[Thu Jul 30 14:41:43.371357 2026] [security2:error] [pid 43637:tid 43835] [client 52.238.199.152:52484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuo94a8U9lZpWaWlJJ_IQAAAEM"]
[Thu Jul 30 14:41:43.378422 2026] [security2:error] [pid 43637:tid 43793] [client 189.156.226.90:27256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuo94a8U9lZpWaWlJJ_IgAAABk"]
[Thu Jul 30 14:41:43.378541 2026] [security2:error] [pid 43637:tid 43793] [client 189.156.226.90:27256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuo94a8U9lZpWaWlJJ_IgAAABk"]
[Thu Jul 30 14:41:43.406188 2026] [security2:error] [pid 43637:tid 43859] [client 101.226.10.126:33304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo94a8U9lZpWaWlJJ_IwAAAFs"]
[Thu Jul 30 14:41:43.406287 2026] [security2:error] [pid 43637:tid 43859] [client 101.226.10.126:33304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo94a8U9lZpWaWlJJ_IwAAAFs"]
[Thu Jul 30 14:41:43.440638 2026] [security2:error] [pid 43637:tid 43880] [client 191.232.199.39:3057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-the.php"] [unique_id "amuo94a8U9lZpWaWlJJ_JAAAAHA"]
[Thu Jul 30 14:41:43.567694 2026] [security2:error] [pid 43637:tid 43813] [client 216.73.216.176:17139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mediaspawn.com"] [uri "/index.php"] [unique_id "amuo94a8U9lZpWaWlJJ_JQAALQw"]
[Thu Jul 30 14:41:43.570057 2026] [security2:error] [pid 43637:tid 43862] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/users.php"] [unique_id "amuo94a8U9lZpWaWlJJ_JwAAAF4"]
[Thu Jul 30 14:41:43.570149 2026] [security2:error] [pid 43637:tid 43862] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/users.php"] [unique_id "amuo94a8U9lZpWaWlJJ_JwAAAF4"]
[Thu Jul 30 14:41:44.065830 2026] [security2:error] [pid 43637:tid 43779] [client 101.226.10.126:33366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_NQAAAAs"]
[Thu Jul 30 14:41:44.065944 2026] [security2:error] [pid 43637:tid 43779] [client 101.226.10.126:33366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_NQAAAAs"]
[Thu Jul 30 14:41:44.091597 2026] [security2:error] [pid 43637:tid 43852] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/tinysd.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_NgAAAFQ"]
[Thu Jul 30 14:41:44.091679 2026] [security2:error] [pid 43637:tid 43852] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/tinysd.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_NgAAAFQ"]
[Thu Jul 30 14:41:44.207905 2026] [security2:error] [pid 43637:tid 43806] [client 20.226.5.174:38035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/leafmailer2.8.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_PQAAACY"]
[Thu Jul 30 14:41:44.280931 2026] [security2:error] [pid 43637:tid 43824] [client 20.63.98.115:30577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/public/makeasmtp.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_QgAAADg"]
[Thu Jul 30 14:41:44.707844 2026] [security2:error] [pid 43637:tid 43860] [client 52.238.199.152:16282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/install.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_SwAAAFw"]
[Thu Jul 30 14:41:44.713184 2026] [security2:error] [pid 43637:tid 43811] [client 101.226.10.126:33418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_TAAAACs"]
[Thu Jul 30 14:41:44.713261 2026] [security2:error] [pid 43637:tid 43811] [client 101.226.10.126:33418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_TAAAACs"]
[Thu Jul 30 14:41:44.732106 2026] [security2:error] [pid 43637:tid 43879] [client 158.158.76.106:1971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_TgAAAG8"]
[Thu Jul 30 14:41:44.732275 2026] [security2:error] [pid 43637:tid 43879] [client 158.158.76.106:1971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuo-Ia8U9lZpWaWlJJ_TgAAAG8"]
[Thu Jul 30 14:41:45.022267 2026] [security2:error] [pid 43637:tid 43769] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_VQAAAAE"]
[Thu Jul 30 14:41:45.022381 2026] [security2:error] [pid 43637:tid 43769] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_VQAAAAE"]
[Thu Jul 30 14:41:45.115614 2026] [security2:error] [pid 43637:tid 43781] [client 20.226.5.174:38028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/led.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_VgAAAA0"]
[Thu Jul 30 14:41:45.172238 2026] [security2:error] [pid 43637:tid 43868] [client 191.232.199.39:3026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/404.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_VwAAAGQ"]
[Thu Jul 30 14:41:45.202738 2026] [security2:error] [pid 43637:tid 43845] [client 127.0.0.1:49188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuo-Ya8U9lZpWaWlJJ_WQAAAE0"]
[Thu Jul 30 14:41:45.202784 2026] [security2:error] [pid 43637:tid 43863] [client 74.7.244.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.okcasino-1.com"] [uri "/robots.txt"] [unique_id "amuo-Ya8U9lZpWaWlJJ_WAAAXxg"]
[Thu Jul 30 14:41:45.357959 2026] [security2:error] [pid 43637:tid 43813] [client 101.226.10.126:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_ZAAAAC0"]
[Thu Jul 30 14:41:45.358086 2026] [security2:error] [pid 43637:tid 43813] [client 101.226.10.126:33482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_ZAAAAC0"]
[Thu Jul 30 14:41:45.449088 2026] [security2:error] [pid 43637:tid 43887] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ws78.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_ZQAAAHc"]
[Thu Jul 30 14:41:45.449197 2026] [security2:error] [pid 43637:tid 43887] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ws78.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_ZQAAAHc"]
[Thu Jul 30 14:41:45.657615 2026] [security2:error] [pid 43637:tid 43842] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/info.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_aAAAAEo"]
[Thu Jul 30 14:41:45.657727 2026] [security2:error] [pid 43637:tid 43842] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/info.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_aAAAAEo"]
[Thu Jul 30 14:41:45.970261 2026] [security2:error] [pid 43637:tid 43852] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/elp.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_dQAAAFQ"]
[Thu Jul 30 14:41:45.970376 2026] [security2:error] [pid 43637:tid 43852] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/elp.php"] [unique_id "amuo-Ya8U9lZpWaWlJJ_dQAAAFQ"]
[Thu Jul 30 14:41:46.036393 2026] [security2:error] [pid 43637:tid 43832] [client 20.226.5.174:38017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/legal.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_dgAAAEA"]
[Thu Jul 30 14:41:46.039877 2026] [security2:error] [pid 43637:tid 43841] [client 101.226.10.126:33546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_dwAAAEk"]
[Thu Jul 30 14:41:46.039966 2026] [security2:error] [pid 43637:tid 43841] [client 101.226.10.126:33546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_dwAAAEk"]
[Thu Jul 30 14:41:46.156834 2026] [security2:error] [pid 43637:tid 43864] [client 216.244.66.236:41000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dhowcruisedinner.com"] [uri "/hjM/sun%2C-sea-and-selling-houses-rodriguez-sisters"] [unique_id "amuo-oa8U9lZpWaWlJJ_ewAAAGA"]
[Thu Jul 30 14:41:46.156949 2026] [security2:error] [pid 43637:tid 43864] [client 216.244.66.236:41000] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dhowcruisedinner.com"] [uri "/hjM/sun%2C-sea-and-selling-houses-rodriguez-sisters"] [unique_id "amuo-oa8U9lZpWaWlJJ_ewAAAGA"]
[Thu Jul 30 14:41:46.304107 2026] [security2:error] [pid 43637:tid 43840] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/a.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_fwAAAEg"]
[Thu Jul 30 14:41:46.304199 2026] [security2:error] [pid 43637:tid 43840] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/a.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_fwAAAEg"]
[Thu Jul 30 14:41:46.369806 2026] [security2:error] [pid 43637:tid 43873] [client 20.118.34.237:10242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_gwAAAGk"]
[Thu Jul 30 14:41:46.501211 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/atomlib.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_hwAAAGI"]
[Thu Jul 30 14:41:46.501323 2026] [security2:error] [pid 43637:tid 43866] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/atomlib.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_hwAAAGI"]
[Thu Jul 30 14:41:46.664269 2026] [security2:error] [pid 43637:tid 43792] [client 158.158.76.106:1222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_iQAAABg"]
[Thu Jul 30 14:41:46.664362 2026] [security2:error] [pid 43637:tid 43792] [client 158.158.76.106:1222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_iQAAABg"]
[Thu Jul 30 14:41:46.717531 2026] [security2:error] [pid 43637:tid 43867] [client 101.226.10.126:33608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_igAAAGM"]
[Thu Jul 30 14:41:46.717698 2026] [security2:error] [pid 43637:tid 43867] [client 101.226.10.126:33608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_igAAAGM"]
[Thu Jul 30 14:41:46.754344 2026] [security2:error] [pid 43637:tid 43830] [client 52.238.199.152:42047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/cgi-bin/about.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_iwAAAD4"]
[Thu Jul 30 14:41:46.919603 2026] [security2:error] [pid 43637:tid 43816] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/chosen.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_lAAAADA"]
[Thu Jul 30 14:41:46.919701 2026] [security2:error] [pid 43637:tid 43816] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/chosen.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_lAAAADA"]
[Thu Jul 30 14:41:46.928393 2026] [security2:error] [pid 43637:tid 43791] [client 20.63.98.115:1434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/mar.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_lgAAABc"]
[Thu Jul 30 14:41:46.957232 2026] [security2:error] [pid 43637:tid 43858] [client 20.226.5.174:38032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/legion.php"] [unique_id "amuo-oa8U9lZpWaWlJJ_lwAAAFo"]
[Thu Jul 30 14:41:47.025536 2026] [security2:error] [pid 43637:tid 43803] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wyzer3.php"] [unique_id "amuo-4a8U9lZpWaWlJJ_mAAAACM"]
[Thu Jul 30 14:41:47.025683 2026] [security2:error] [pid 43637:tid 43803] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/wyzer3.php"] [unique_id "amuo-4a8U9lZpWaWlJJ_mAAAACM"]
[Thu Jul 30 14:41:47.427728 2026] [security2:error] [pid 43637:tid 43891] [client 101.226.10.126:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-4a8U9lZpWaWlJJ_qQAAAHs"]
[Thu Jul 30 14:41:47.427832 2026] [security2:error] [pid 43637:tid 43891] [client 101.226.10.126:33670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo-4a8U9lZpWaWlJJ_qQAAAHs"]
[Thu Jul 30 14:41:47.524194 2026] [security2:error] [pid 43637:tid 43809] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/index.php"] [unique_id "amuo-4a8U9lZpWaWlJJ_rwAAACk"]
[Thu Jul 30 14:41:47.524289 2026] [security2:error] [pid 43637:tid 43809] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/index.php"] [unique_id "amuo-4a8U9lZpWaWlJJ_rwAAACk"]
[Thu Jul 30 14:41:47.534860 2026] [security2:error] [pid 43637:tid 43853] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/max.php"] [unique_id "amuo-4a8U9lZpWaWlJJ_sAAAAFU"]
[Thu Jul 30 14:41:47.534937 2026] [security2:error] [pid 43637:tid 43853] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/max.php"] [unique_id "amuo-4a8U9lZpWaWlJJ_sAAAAFU"]
[Thu Jul 30 14:41:47.874571 2026] [security2:error] [pid 43637:tid 43789] [client 20.226.5.174:38021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/let.php"] [unique_id "amuo-4a8U9lZpWaWlJJ_twAAABU"]
[Thu Jul 30 14:41:48.062194 2026] [security2:error] [pid 43637:tid 43840] [client 20.104.16.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.16.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ftde.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_vgAAAEg"]
[Thu Jul 30 14:41:48.062288 2026] [security2:error] [pid 43637:tid 43840] [client 20.104.16.169:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.airevoduct.ltd"] [uri "/ftde.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_vgAAAEg"]
[Thu Jul 30 14:41:48.118109 2026] [security2:error] [pid 43637:tid 43824] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/vx.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_vwAAADg"]
[Thu Jul 30 14:41:48.118207 2026] [security2:error] [pid 43637:tid 43824] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/vx.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_vwAAADg"]
[Thu Jul 30 14:41:48.157353 2026] [security2:error] [pid 43637:tid 43872] [client 101.226.10.126:33748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_wAAAAGg"]
[Thu Jul 30 14:41:48.157515 2026] [security2:error] [pid 43637:tid 43872] [client 101.226.10.126:33748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_wAAAAGg"]
[Thu Jul 30 14:41:48.430994 2026] [security2:error] [pid 43637:tid 43777] [client 52.238.199.152:52534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/css/colors/about.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_yAAAAAk"]
[Thu Jul 30 14:41:48.544363 2026] [security2:error] [pid 43637:tid 43882] [client 135.119.63.61:37897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/011i.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_zAAAAHI"]
[Thu Jul 30 14:41:48.707342 2026] [proxy:error] [pid 43637:tid 43773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:48.707415 2026] [proxy_http:error] [pid 43637:tid 43773] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:48.708082 2026] [proxy:error] [pid 43637:tid 43773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:48.708129 2026] [proxy_http:error] [pid 43637:tid 43773] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:48.708225 2026] [security2:error] [pid 43637:tid 43773] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuo_Ia8U9lZpWaWlJJ_zwAAAAU"]
[Thu Jul 30 14:41:48.807357 2026] [security2:error] [pid 43637:tid 43867] [client 20.226.5.174:38030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/lf.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_0AAAAGM"]
[Thu Jul 30 14:41:48.810610 2026] [security2:error] [pid 43637:tid 43875] [client 101.226.10.126:33818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_0QAAAGs"]
[Thu Jul 30 14:41:48.810727 2026] [security2:error] [pid 43637:tid 43875] [client 101.226.10.126:33818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_0QAAAGs"]
[Thu Jul 30 14:41:48.885310 2026] [security2:error] [pid 43637:tid 43855] [client 213.180.203.126:55554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuo_Ia8U9lZpWaWlJJ_zQAAAFc"]
[Thu Jul 30 14:41:49.043752 2026] [security2:error] [pid 43637:tid 43833] [client 158.158.76.106:1924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/images/pearl/index.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_2AAAAEE"]
[Thu Jul 30 14:41:49.043864 2026] [security2:error] [pid 43637:tid 43833] [client 158.158.76.106:1924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/images/pearl/index.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_2AAAAEE"]
[Thu Jul 30 14:41:49.323287 2026] [security2:error] [pid 43637:tid 43800] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wap.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_3AAAACA"]
[Thu Jul 30 14:41:49.323405 2026] [security2:error] [pid 43637:tid 43800] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wap.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_3AAAACA"]
[Thu Jul 30 14:41:49.449027 2026] [security2:error] [pid 43637:tid 43862] [client 101.226.10.126:33870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_4wAAAF4"]
[Thu Jul 30 14:41:49.449128 2026] [security2:error] [pid 43637:tid 43862] [client 101.226.10.126:33870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_4wAAAF4"]
[Thu Jul 30 14:41:49.565184 2026] [security2:error] [pid 43637:tid 43851] [client 191.232.199.39:53447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/init.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_5wAAAFM"]
[Thu Jul 30 14:41:49.649158 2026] [security2:error] [pid 43637:tid 43873] [client 20.63.98.115:37571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/system.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_6AAAAGk"]
[Thu Jul 30 14:41:49.734412 2026] [security2:error] [pid 43637:tid 43870] [client 20.226.5.174:38036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/library.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_7AAAAGY"]
[Thu Jul 30 14:41:49.949606 2026] [security2:error] [pid 43637:tid 43884] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-admin/wp.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_8wAAAHQ"]
[Thu Jul 30 14:41:49.949714 2026] [security2:error] [pid 43637:tid 43884] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-admin/wp.php"] [unique_id "amuo_Ya8U9lZpWaWlJJ_8wAAAHQ"]
[Thu Jul 30 14:41:50.129321 2026] [security2:error] [pid 43637:tid 43841] [client 101.226.10.126:33938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/public/index.php"] [unique_id "amuo_oa8U9lZpWaWlJJ_-AAAAEk"]
[Thu Jul 30 14:41:50.129412 2026] [security2:error] [pid 43637:tid 43841] [client 101.226.10.126:33938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/public/index.php"] [unique_id "amuo_oa8U9lZpWaWlJJ_-AAAAEk"]
[Thu Jul 30 14:41:50.555591 2026] [security2:error] [pid 43637:tid 43872] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/bgymj.php"] [unique_id "amuo_oa8U9lZpWaWlJKAAAAAAGg"]
[Thu Jul 30 14:41:50.555731 2026] [security2:error] [pid 43637:tid 43872] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/bgymj.php"] [unique_id "amuo_oa8U9lZpWaWlJKAAAAAAGg"]
[Thu Jul 30 14:41:50.630188 2026] [security2:error] [pid 43637:tid 43807] [client 20.226.5.174:38033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/library/about.php"] [unique_id "amuo_oa8U9lZpWaWlJKABAAAACc"]
[Thu Jul 30 14:41:50.640851 2026] [security2:error] [pid 43637:tid 43893] [client 135.119.63.61:37927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/03a005685d.php"] [unique_id "amuo_oa8U9lZpWaWlJKABQAAAH0"]
[Thu Jul 30 14:41:50.739895 2026] [security2:error] [pid 43637:tid 43850] [client 64.42.179.59:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuo_oa8U9lZpWaWlJKABgAAAFI"]
[Thu Jul 30 14:41:50.740020 2026] [security2:error] [pid 43637:tid 43850] [client 64.42.179.59:60980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuo_oa8U9lZpWaWlJKABgAAAFI"]
[Thu Jul 30 14:41:50.800415 2026] [security2:error] [pid 43637:tid 43824] [client 20.63.98.115:1715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/lock360.php"] [unique_id "amuo_oa8U9lZpWaWlJKABwAAADg"]
[Thu Jul 30 14:41:50.882735 2026] [security2:error] [pid 43637:tid 43794] [client 158.158.76.106:1239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/bypass.php"] [unique_id "amuo_oa8U9lZpWaWlJKACAAAABo"]
[Thu Jul 30 14:41:50.882851 2026] [security2:error] [pid 43637:tid 43794] [client 158.158.76.106:1239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/bypass.php"] [unique_id "amuo_oa8U9lZpWaWlJKACAAAABo"]
[Thu Jul 30 14:41:50.918218 2026] [security2:error] [pid 43637:tid 43812] [client 101.226.10.126:34018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_oa8U9lZpWaWlJKADAAAACw"]
[Thu Jul 30 14:41:50.918312 2026] [security2:error] [pid 43637:tid 43812] [client 101.226.10.126:34018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_oa8U9lZpWaWlJKADAAAACw"]
[Thu Jul 30 14:41:51.173135 2026] [security2:error] [pid 43637:tid 43875] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/aa.php"] [unique_id "amuo_4a8U9lZpWaWlJKAEwAAAGs"]
[Thu Jul 30 14:41:51.173238 2026] [security2:error] [pid 43637:tid 43875] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/aa.php"] [unique_id "amuo_4a8U9lZpWaWlJKAEwAAAGs"]
[Thu Jul 30 14:41:51.526830 2026] [security2:error] [pid 43637:tid 43871] [client 20.226.5.174:38016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/library/index.php"] [unique_id "amuo_4a8U9lZpWaWlJKAGgAAAGc"]
[Thu Jul 30 14:41:51.585376 2026] [security2:error] [pid 43637:tid 43770] [client 101.226.10.126:34090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_4a8U9lZpWaWlJKAHAAAAAI"]
[Thu Jul 30 14:41:51.585466 2026] [security2:error] [pid 43637:tid 43770] [client 101.226.10.126:34090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amuo_4a8U9lZpWaWlJKAHAAAAAI"]
[Thu Jul 30 14:41:51.760752 2026] [security2:error] [pid 43637:tid 43788] [client 20.63.98.115:30555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amuo_4a8U9lZpWaWlJKAIAAAABQ"]
[Thu Jul 30 14:41:51.789246 2026] [security2:error] [pid 43637:tid 43780] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-mail.php"] [unique_id "amuo_4a8U9lZpWaWlJKAIQAAAAw"]
[Thu Jul 30 14:41:51.789342 2026] [security2:error] [pid 43637:tid 43780] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-mail.php"] [unique_id "amuo_4a8U9lZpWaWlJKAIQAAAAw"]
[Thu Jul 30 14:41:52.245707 2026] [security2:error] [pid 43637:tid 43801] [client 101.226.10.126:34138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php/index"] [unique_id "amupAIa8U9lZpWaWlJKALgAAACE"]
[Thu Jul 30 14:41:52.245797 2026] [security2:error] [pid 43637:tid 43801] [client 101.226.10.126:34138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php/index"] [unique_id "amupAIa8U9lZpWaWlJKALgAAACE"]
[Thu Jul 30 14:41:52.389883 2026] [security2:error] [pid 43637:tid 43884] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/bolt.php"] [unique_id "amupAIa8U9lZpWaWlJKALwAAAHQ"]
[Thu Jul 30 14:41:52.390004 2026] [security2:error] [pid 43637:tid 43884] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/bolt.php"] [unique_id "amupAIa8U9lZpWaWlJKALwAAAHQ"]
[Thu Jul 30 14:41:52.423807 2026] [security2:error] [pid 43637:tid 43876] [client 20.226.5.174:38029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/libs.php"] [unique_id "amupAIa8U9lZpWaWlJKAMAAAAGw"]
[Thu Jul 30 14:41:52.464326 2026] [security2:error] [pid 43637:tid 43880] [client 191.232.199.39:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/file5.php"] [unique_id "amupAIa8U9lZpWaWlJKAMQAAAHA"]
[Thu Jul 30 14:41:52.520418 2026] [security2:error] [pid 43637:tid 43853] [client 20.63.98.115:37809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/mah.php"] [unique_id "amupAIa8U9lZpWaWlJKANQAAAFU"]
[Thu Jul 30 14:41:52.881439 2026] [security2:error] [pid 43637:tid 43893] [client 101.226.10.126:34190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php/index"] [unique_id "amupAIa8U9lZpWaWlJKAPAAAAH0"]
[Thu Jul 30 14:41:52.881556 2026] [security2:error] [pid 43637:tid 43893] [client 101.226.10.126:34190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php/index"] [unique_id "amupAIa8U9lZpWaWlJKAPAAAAH0"]
[Thu Jul 30 14:41:52.999644 2026] [security2:error] [pid 43637:tid 43779] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/bthil.php"] [unique_id "amupAIa8U9lZpWaWlJKAPQAAAAs"]
[Thu Jul 30 14:41:52.999750 2026] [security2:error] [pid 43637:tid 43779] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/bthil.php"] [unique_id "amupAIa8U9lZpWaWlJKAPQAAAAs"]
[Thu Jul 30 14:41:53.080046 2026] [security2:error] [pid 43637:tid 43824] [client 172.237.109.114:49842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKAQgAAADg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.093029 2026] [security2:error] [pid 43637:tid 43771] [client 172.237.109.114:61815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKARAAAAAM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.093139 2026] [security2:error] [pid 43637:tid 43865] [client 172.237.109.114:2016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKAQwAAAGE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.093505 2026] [security2:error] [pid 43637:tid 43794] [client 172.237.109.114:17869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKARQAAABo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.094063 2026] [security2:error] [pid 43637:tid 43812] [client 172.237.109.114:32590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKARwAAACw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.094225 2026] [security2:error] [pid 43637:tid 43804] [client 172.237.109.114:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKASAAAACQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.094243 2026] [security2:error] [pid 43637:tid 43890] [client 172.237.109.114:14885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKASgAAAHo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.094306 2026] [security2:error] [pid 43637:tid 43890] [client 172.237.109.114:14885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKASgAAAHo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.094373 2026] [security2:error] [pid 43637:tid 43830] [client 172.237.109.114:14267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKASQAAAD4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.095753 2026] [security2:error] [pid 43637:tid 43883] [client 172.237.109.114:61083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKASwAAAHM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.101659 2026] [security2:error] [pid 43637:tid 43774] [client 172.237.109.114:12974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKATQAAAAY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.123435 2026] [security2:error] [pid 43637:tid 43866] [client 172.237.109.114:44993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKATwAAAGI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.149090 2026] [security2:error] [pid 43637:tid 43775] [client 172.237.109.114:64340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKAUAAAAAc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.150262 2026] [security2:error] [pid 43637:tid 43861] [client 172.237.109.114:32917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKAUQAAAF0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.151652 2026] [security2:error] [pid 43637:tid 43860] [client 172.237.109.114:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAYa8U9lZpWaWlJKAUgAAAFw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:53.239386 2026] [security2:error] [pid 43637:tid 43850] [client 135.119.63.61:21376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/403.php"] [unique_id "amupAYa8U9lZpWaWlJKAVwAAAFI"]
[Thu Jul 30 14:41:53.318187 2026] [security2:error] [pid 43637:tid 43773] [client 20.226.5.174:38034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/license.php"] [unique_id "amupAYa8U9lZpWaWlJKAWAAAAAU"]
[Thu Jul 30 14:41:53.406502 2026] [security2:error] [pid 43637:tid 43881] [client 52.238.199.152:52493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/classwithtostring.php"] [unique_id "amupAYa8U9lZpWaWlJKAWQAAAHE"]
[Thu Jul 30 14:41:53.558297 2026] [security2:error] [pid 43637:tid 43842] [client 101.226.10.126:34252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amupAYa8U9lZpWaWlJKAWwAAAEo"]
[Thu Jul 30 14:41:53.558395 2026] [security2:error] [pid 43637:tid 43842] [client 101.226.10.126:34252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/index.php"] [unique_id "amupAYa8U9lZpWaWlJKAWwAAAEo"]
[Thu Jul 30 14:41:53.644202 2026] [proxy:error] [pid 43637:tid 43815] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:53.644268 2026] [proxy_http:error] [pid 43637:tid 43815] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:53.644857 2026] [proxy:error] [pid 43637:tid 43815] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:41:53.644902 2026] [proxy_http:error] [pid 43637:tid 43815] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:41:53.645020 2026] [security2:error] [pid 43637:tid 43815] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amupAYa8U9lZpWaWlJKAYwAAAC8"]
[Thu Jul 30 14:41:53.692410 2026] [security2:error] [pid 43637:tid 43838] [client 184.75.221.59:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amupAYa8U9lZpWaWlJKAZAAAAEY"]
[Thu Jul 30 14:41:53.692500 2026] [security2:error] [pid 43637:tid 43838] [client 184.75.221.59:44224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amupAYa8U9lZpWaWlJKAZAAAAEY"]
[Thu Jul 30 14:41:53.810004 2026] [security2:error] [pid 43637:tid 43895] [client 191.232.199.39:3011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amupAYa8U9lZpWaWlJKAaAAAAH8"]
[Thu Jul 30 14:41:53.879870 2026] [autoindex:error] [pid 43637:tid 43837] [client 20.63.98.115:41852] AH01276: Cannot serve directory /home1/ocldjbte/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:53.891522 2026] [security2:error] [pid 43637:tid 43853] [client 189.156.226.90:27444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupAYa8U9lZpWaWlJKAawAAAFU"]
[Thu Jul 30 14:41:53.891642 2026] [security2:error] [pid 43637:tid 43853] [client 189.156.226.90:27444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupAYa8U9lZpWaWlJKAawAAAFU"]
[Thu Jul 30 14:41:54.087331 2026] [security2:error] [pid 43637:tid 43822] [client 172.237.109.114:45065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAoa8U9lZpWaWlJKAbwAAADY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:54.088569 2026] [security2:error] [pid 43637:tid 43857] [client 172.237.109.114:28782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAoa8U9lZpWaWlJKAcAAAAFk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:54.091784 2026] [security2:error] [pid 43637:tid 43888] [client 20.63.98.115:41852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-class.php"] [unique_id "amupAoa8U9lZpWaWlJKAcQAAAHg"]
[Thu Jul 30 14:41:54.122931 2026] [security2:error] [pid 43637:tid 43840] [client 172.237.109.114:56548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAoa8U9lZpWaWlJKAcgAAAEg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:54.148632 2026] [security2:error] [pid 43637:tid 43798] [client 172.237.109.114:40072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAoa8U9lZpWaWlJKAcwAAAB4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:54.150654 2026] [security2:error] [pid 43637:tid 43768] [client 172.237.109.114:37275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupAoa8U9lZpWaWlJKAdAAAAAA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:54.249323 2026] [security2:error] [pid 43637:tid 43771] [client 101.226.10.126:34322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.10.226.101.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodneyleesmith.com"] [uri "/jnuqrys.php"] [unique_id "amupAoa8U9lZpWaWlJKAeAAAAAM"]
[Thu Jul 30 14:41:54.249463 2026] [security2:error] [pid 43637:tid 43771] [client 101.226.10.126:34322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rodneyleesmith.com"] [uri "/jnuqrys.php"] [unique_id "amupAoa8U9lZpWaWlJKAeAAAAAM"]
[Thu Jul 30 14:41:54.270568 2026] [security2:error] [pid 43637:tid 43812] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/x.php"] [unique_id "amupAoa8U9lZpWaWlJKAegAAACw"]
[Thu Jul 30 14:41:54.270674 2026] [security2:error] [pid 43637:tid 43812] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/x.php"] [unique_id "amupAoa8U9lZpWaWlJKAegAAACw"]
[Thu Jul 30 14:41:54.515598 2026] [security2:error] [pid 43637:tid 43806] [client 20.226.5.174:38043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/license.txt/xmlrpc.php"] [unique_id "amupAoa8U9lZpWaWlJKAeQAAACY"]
[Thu Jul 30 14:41:54.891844 2026] [security2:error] [pid 43637:tid 43818] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/index/function.php"] [unique_id "amupAoa8U9lZpWaWlJKAlQAAADI"]
[Thu Jul 30 14:41:54.891990 2026] [security2:error] [pid 43637:tid 43818] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/index/function.php"] [unique_id "amupAoa8U9lZpWaWlJKAlQAAADI"]
[Thu Jul 30 14:41:55.151932 2026] [security2:error] [pid 43637:tid 43809] [client 172.237.109.114:40836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupA4a8U9lZpWaWlJKAmQAAACk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:41:55.160317 2026] [security2:error] [pid 43637:tid 43816] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupAoa8U9lZpWaWlJKAgwAAADA"]
[Thu Jul 30 14:41:55.198041 2026] [security2:error] [pid 43637:tid 43845] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupAoa8U9lZpWaWlJKAiAAAAE0"]
[Thu Jul 30 14:41:55.443900 2026] [security2:error] [pid 43637:tid 43801] [client 20.226.5.174:38041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/licenses.php"] [unique_id "amupA4a8U9lZpWaWlJKAoAAAACE"]
[Thu Jul 30 14:41:55.529647 2026] [security2:error] [pid 43637:tid 43854] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/aaa.php"] [unique_id "amupA4a8U9lZpWaWlJKAoQAAAFY"]
[Thu Jul 30 14:41:55.529761 2026] [security2:error] [pid 43637:tid 43854] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/aaa.php"] [unique_id "amupA4a8U9lZpWaWlJKAoQAAAFY"]
[Thu Jul 30 14:41:55.859463 2026] [security2:error] [pid 43637:tid 43858] [client 135.119.63.61:21422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/404.php"] [unique_id "amupA4a8U9lZpWaWlJKAqQAAAFo"]
[Thu Jul 30 14:41:55.908576 2026] [security2:error] [pid 43637:tid 43849] [client 191.232.199.39:53480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/shell.php"] [unique_id "amupA4a8U9lZpWaWlJKAqwAAAFE"]
[Thu Jul 30 14:41:55.965163 2026] [security2:error] [pid 43637:tid 43872] [client 158.158.76.106:1974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/wp-admin/about.php"] [unique_id "amupA4a8U9lZpWaWlJKArwAAAGg"]
[Thu Jul 30 14:41:55.965285 2026] [security2:error] [pid 43637:tid 43872] [client 158.158.76.106:1974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/wp-admin/about.php"] [unique_id "amupA4a8U9lZpWaWlJKArwAAAGg"]
[Thu Jul 30 14:41:56.343890 2026] [security2:error] [pid 43637:tid 43805] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amupA4a8U9lZpWaWlJKAqAAAJR0"]
[Thu Jul 30 14:41:56.366826 2026] [security2:error] [pid 43637:tid 43889] [client 20.226.5.174:38024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/lightspped.php"] [unique_id "amupBIa8U9lZpWaWlJKAtgAAAHk"]
[Thu Jul 30 14:41:56.426289 2026] [security2:error] [pid 43637:tid 43864] [client 20.63.98.115:1709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/backup.php"] [unique_id "amupBIa8U9lZpWaWlJKAtwAAAGA"]
[Thu Jul 30 14:41:56.655059 2026] [security2:error] [pid 43637:tid 43792] [client 52.238.199.152:52539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/js/about.php"] [unique_id "amupBIa8U9lZpWaWlJKAuwAAABg"]
[Thu Jul 30 14:41:57.262310 2026] [security2:error] [pid 43637:tid 43781] [client 20.226.5.174:38053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/link.php"] [unique_id "amupBYa8U9lZpWaWlJKAywAAAA0"]
[Thu Jul 30 14:41:57.414728 2026] [security2:error] [pid 43637:tid 43860] [client 191.232.199.39:53465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/f35.php"] [unique_id "amupBYa8U9lZpWaWlJKA0AAAAFw"]
[Thu Jul 30 14:41:57.950400 2026] [security2:error] [pid 43637:tid 43865] [client 135.119.63.61:37939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/aa.php"] [unique_id "amupBYa8U9lZpWaWlJKA2gAAAGE"]
[Thu Jul 30 14:41:58.130194 2026] [security2:error] [pid 43637:tid 43847] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/abcd.php"] [unique_id "amupBoa8U9lZpWaWlJKA3gAAAE8"]
[Thu Jul 30 14:41:58.130309 2026] [security2:error] [pid 43637:tid 43847] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/abcd.php"] [unique_id "amupBoa8U9lZpWaWlJKA3gAAAE8"]
[Thu Jul 30 14:41:58.180857 2026] [security2:error] [pid 43637:tid 43842] [client 20.226.5.174:38038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreview/404.php"] [unique_id "amupBoa8U9lZpWaWlJKA3wAAAEo"]
[Thu Jul 30 14:41:58.215383 2026] [security2:error] [pid 43637:tid 43829] [client 20.63.98.115:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/default.php"] [unique_id "amupBoa8U9lZpWaWlJKA4AAAAD0"]
[Thu Jul 30 14:41:58.673316 2026] [security2:error] [pid 43637:tid 43843] [client 191.232.199.39:48986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/new.php"] [unique_id "amupBoa8U9lZpWaWlJKA8AAAAEs"]
[Thu Jul 30 14:41:58.750168 2026] [security2:error] [pid 43637:tid 43840] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-good.php"] [unique_id "amupBoa8U9lZpWaWlJKA8QAAAEg"]
[Thu Jul 30 14:41:58.750286 2026] [security2:error] [pid 43637:tid 43840] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-good.php"] [unique_id "amupBoa8U9lZpWaWlJKA8QAAAEg"]
[Thu Jul 30 14:41:59.002259 2026] [security2:error] [pid 43637:tid 43851] [client 52.238.199.152:47151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/comfunctions.php"] [unique_id "amupB4a8U9lZpWaWlJKA_wAAAFM"]
[Thu Jul 30 14:41:59.095324 2026] [security2:error] [pid 43637:tid 43796] [client 20.226.5.174:38040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreview/admin.php"] [unique_id "amupB4a8U9lZpWaWlJKBBAAAABw"]
[Thu Jul 30 14:41:59.335555 2026] [autoindex:error] [pid 43637:tid 43790] [client 18.211.55.47:14248] AH01276: Cannot serve directory /home1/eardjbte/public_html/website_b1080a24/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:41:59.400252 2026] [security2:error] [pid 43637:tid 43781] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/simple.php"] [unique_id "amupB4a8U9lZpWaWlJKBCwAAAA0"]
[Thu Jul 30 14:41:59.400385 2026] [security2:error] [pid 43637:tid 43781] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/simple.php"] [unique_id "amupB4a8U9lZpWaWlJKBCwAAAA0"]
[Thu Jul 30 14:41:59.977041 2026] [security2:error] [pid 43637:tid 43787] [client 52.238.199.152:16381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/images/class-config.php"] [unique_id "amupB4a8U9lZpWaWlJKBEAAAABM"]
[Thu Jul 30 14:41:59.995870 2026] [security2:error] [pid 43637:tid 43835] [client 20.226.5.174:38047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreview/alfa.php"] [unique_id "amupB4a8U9lZpWaWlJKBEQAAAEM"]
[Thu Jul 30 14:42:00.048187 2026] [security2:error] [pid 43637:tid 43782] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/edit-tags.php"] [unique_id "amupCIa8U9lZpWaWlJKBFQAAAA4"]
[Thu Jul 30 14:42:00.048275 2026] [security2:error] [pid 43637:tid 43782] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/edit-tags.php"] [unique_id "amupCIa8U9lZpWaWlJKBFQAAAA4"]
[Thu Jul 30 14:42:00.632287 2026] [security2:error] [pid 43637:tid 43895] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/u.php"] [unique_id "amupCIa8U9lZpWaWlJKBIQAAAH8"]
[Thu Jul 30 14:42:00.632368 2026] [security2:error] [pid 43637:tid 43895] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/u.php"] [unique_id "amupCIa8U9lZpWaWlJKBIQAAAH8"]
[Thu Jul 30 14:42:00.706099 2026] [security2:error] [pid 43637:tid 43850] [client 191.232.199.39:43039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/adminfuns.php"] [unique_id "amupCIa8U9lZpWaWlJKBJQAAAFI"]
[Thu Jul 30 14:42:00.960879 2026] [security2:error] [pid 43637:tid 43776] [client 20.226.5.174:7301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreview/bypass.php"] [unique_id "amupCIa8U9lZpWaWlJKBKQAAAAg"]
[Thu Jul 30 14:42:01.311051 2026] [security2:error] [pid 43637:tid 43881] [client 66.249.66.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.plumbingplumb.com"] [uri "/index.php"] [unique_id "amupCIa8U9lZpWaWlJKBFgAAcRw"]
[Thu Jul 30 14:42:01.327845 2026] [security2:error] [pid 43637:tid 43889] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amupCYa8U9lZpWaWlJKBNAAAAHk"]
[Thu Jul 30 14:42:01.328029 2026] [security2:error] [pid 43637:tid 43889] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amupCYa8U9lZpWaWlJKBNAAAAHk"]
[Thu Jul 30 14:42:01.708412 2026] [security2:error] [pid 43637:tid 43826] [client 52.238.199.152:52501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/widgets/include.php"] [unique_id "amupCYa8U9lZpWaWlJKBPAAAADo"]
[Thu Jul 30 14:42:01.903917 2026] [security2:error] [pid 43637:tid 43804] [client 20.226.5.174:38049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreview/class.php"] [unique_id "amupCYa8U9lZpWaWlJKBQwAAACQ"]
[Thu Jul 30 14:42:01.936888 2026] [security2:error] [pid 43637:tid 43868] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/h.php"] [unique_id "amupCYa8U9lZpWaWlJKBRAAAAGQ"]
[Thu Jul 30 14:42:01.937012 2026] [security2:error] [pid 43637:tid 43868] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/h.php"] [unique_id "amupCYa8U9lZpWaWlJKBRAAAAGQ"]
[Thu Jul 30 14:42:02.503798 2026] [security2:error] [pid 43637:tid 43848] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/ms-edit.php"] [unique_id "amupCoa8U9lZpWaWlJKBUwAAAFA"]
[Thu Jul 30 14:42:02.503895 2026] [security2:error] [pid 43637:tid 43848] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/ms-edit.php"] [unique_id "amupCoa8U9lZpWaWlJKBUwAAAFA"]
[Thu Jul 30 14:42:02.838068 2026] [security2:error] [pid 43637:tid 43870] [client 20.226.5.174:38055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreview/db.php"] [unique_id "amupCoa8U9lZpWaWlJKBXgAAAGY"]
[Thu Jul 30 14:42:02.856867 2026] [security2:error] [pid 43637:tid 43874] [client 135.119.63.61:37929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/aafewc0k.php"] [unique_id "amupCoa8U9lZpWaWlJKBXwAAAGo"]
[Thu Jul 30 14:42:03.085706 2026] [security2:error] [pid 43637:tid 43825] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/a7.php"] [unique_id "amupC4a8U9lZpWaWlJKBZAAAADk"]
[Thu Jul 30 14:42:03.085794 2026] [security2:error] [pid 43637:tid 43825] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/a7.php"] [unique_id "amupC4a8U9lZpWaWlJKBZAAAADk"]
[Thu Jul 30 14:42:03.219651 2026] [security2:error] [pid 43637:tid 43810] [client 191.232.199.39:48979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/fm.php"] [unique_id "amupC4a8U9lZpWaWlJKBZgAAACo"]
[Thu Jul 30 14:42:03.346827 2026] [security2:error] [pid 43637:tid 43877] [client 177.6.106.101:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupC4a8U9lZpWaWlJKBbwAAAG0"]
[Thu Jul 30 14:42:03.347010 2026] [security2:error] [pid 43637:tid 43877] [client 177.6.106.101:56223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupC4a8U9lZpWaWlJKBbwAAAG0"]
[Thu Jul 30 14:42:03.482011 2026] [security2:error] [pid 43637:tid 43702] [remote 66.70.255.14:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.255.70.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mediaspawn.com"] [uri "/wp-login.php"] [unique_id "amupC4a8U9lZpWaWlJKBaQAAT0A"]
[Thu Jul 30 14:42:03.683198 2026] [security2:error] [pid 43637:tid 43881] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/manager.php"] [unique_id "amupC4a8U9lZpWaWlJKBdAAAAHE"]
[Thu Jul 30 14:42:03.683308 2026] [security2:error] [pid 43637:tid 43881] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/manager.php"] [unique_id "amupC4a8U9lZpWaWlJKBdAAAAHE"]
[Thu Jul 30 14:42:03.734483 2026] [security2:error] [pid 43637:tid 43802] [client 135.119.63.61:37919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/abcd.php"] [unique_id "amupC4a8U9lZpWaWlJKBeAAAACI"]
[Thu Jul 30 14:42:03.734506 2026] [security2:error] [pid 43637:tid 43828] [client 20.226.5.174:38026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreview/index.php"] [unique_id "amupC4a8U9lZpWaWlJKBeQAAADw"]
[Thu Jul 30 14:42:04.250156 2026] [security2:error] [pid 43637:tid 43830] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/w1.php"] [unique_id "amupDIa8U9lZpWaWlJKBhQAAAD4"]
[Thu Jul 30 14:42:04.250264 2026] [security2:error] [pid 43637:tid 43830] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/w1.php"] [unique_id "amupDIa8U9lZpWaWlJKBhQAAAD4"]
[Thu Jul 30 14:42:04.573161 2026] [security2:error] [pid 43637:tid 43846] [client 189.156.226.90:26744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupDIa8U9lZpWaWlJKBjQAAAE4"]
[Thu Jul 30 14:42:04.573288 2026] [security2:error] [pid 43637:tid 43846] [client 189.156.226.90:26744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupDIa8U9lZpWaWlJKBjQAAAE4"]
[Thu Jul 30 14:42:04.612715 2026] [security2:error] [pid 43637:tid 43794] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupDIa8U9lZpWaWlJKBggAAABo"]
[Thu Jul 30 14:42:04.668026 2026] [security2:error] [pid 43637:tid 43804] [client 20.226.5.174:38037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreview/k.php"] [unique_id "amupDIa8U9lZpWaWlJKBjwAAACQ"]
[Thu Jul 30 14:42:05.239700 2026] [security2:error] [pid 43637:tid 43793] [client 135.119.63.61:38622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/about.php"] [unique_id "amupDYa8U9lZpWaWlJKBnQAAABk"]
[Thu Jul 30 14:42:05.491632 2026] [security2:error] [pid 43637:tid 43825] [client 191.232.199.39:43025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/file.php"] [unique_id "amupDYa8U9lZpWaWlJKBpwAAADk"]
[Thu Jul 30 14:42:05.600659 2026] [security2:error] [pid 43637:tid 43778] [client 20.226.5.174:38063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreview/wp.php"] [unique_id "amupDYa8U9lZpWaWlJKBqAAAAAo"]
[Thu Jul 30 14:42:05.752740 2026] [proxy:error] [pid 43637:tid 43841] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:05.752817 2026] [proxy_http:error] [pid 43637:tid 43841] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:05.753391 2026] [proxy:error] [pid 43637:tid 43841] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:05.753436 2026] [proxy_http:error] [pid 43637:tid 43841] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:05.753536 2026] [security2:error] [pid 43637:tid 43841] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amupDYa8U9lZpWaWlJKBqQAAAEk"]
[Thu Jul 30 14:42:05.830961 2026] [security2:error] [pid 43637:tid 43845] [client 52.238.199.152:3579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/gmo.php"] [unique_id "amupDYa8U9lZpWaWlJKBrAAAAE0"]
[Thu Jul 30 14:42:06.093967 2026] [security2:error] [pid 43637:tid 43797] [client 135.119.63.61:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/admin.php"] [unique_id "amupDoa8U9lZpWaWlJKBuAAAAB0"]
[Thu Jul 30 14:42:06.230302 2026] [security2:error] [pid 43637:tid 43769] [client 52.238.199.152:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/install.php"] [unique_id "amupDoa8U9lZpWaWlJKBuQAAAAE"]
[Thu Jul 30 14:42:06.386771 2026] [security2:error] [pid 43637:tid 43859] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-login.php"] [unique_id "amupDoa8U9lZpWaWlJKBvgAAAFs"]
[Thu Jul 30 14:42:06.386928 2026] [security2:error] [pid 43637:tid 43859] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-login.php"] [unique_id "amupDoa8U9lZpWaWlJKBvgAAAFs"]
[Thu Jul 30 14:42:06.494203 2026] [security2:error] [pid 43637:tid 43840] [client 20.226.5.174:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreviewadmin.php"] [unique_id "amupDoa8U9lZpWaWlJKBxQAAAEg"]
[Thu Jul 30 14:42:06.876399 2026] [core:notice] [pid 43637:tid 43830] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:06.905322 2026] [security2:error] [pid 43637:tid 43796] [client 158.158.76.106:1540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/12.php"] [unique_id "amupDoa8U9lZpWaWlJKBygAAABw"]
[Thu Jul 30 14:42:06.905408 2026] [security2:error] [pid 43637:tid 43796] [client 158.158.76.106:1540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/12.php"] [unique_id "amupDoa8U9lZpWaWlJKBygAAABw"]
[Thu Jul 30 14:42:06.957303 2026] [core:error] [pid 43637:tid 43868] [client 74.7.175.135:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:06.957328 2026] [core:error] [pid 43637:tid 43868] [client 74.7.175.135:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:06.957455 2026] [security2:error] [pid 43637:tid 43868] [client 74.7.175.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.akth.com.pk"] [uri "/index.php"] [unique_id "amupDoa8U9lZpWaWlJKB0AAAAGQ"]
[Thu Jul 30 14:42:06.958050 2026] [security2:error] [pid 43637:tid 43871] [client 74.7.175.135:49688] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.akth.com.pk"] [uri "/robots.txt"] [unique_id "amupDoa8U9lZpWaWlJKBzgAAZ3o"]
[Thu Jul 30 14:42:07.020954 2026] [security2:error] [pid 43637:tid 43804] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/default.php"] [unique_id "amupD4a8U9lZpWaWlJKB1AAAACQ"]
[Thu Jul 30 14:42:07.021121 2026] [security2:error] [pid 43637:tid 43804] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/default.php"] [unique_id "amupD4a8U9lZpWaWlJKB1AAAACQ"]
[Thu Jul 30 14:42:07.372471 2026] [security2:error] [pid 43637:tid 43862] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupD4a8U9lZpWaWlJKB2AAAAF4"]
[Thu Jul 30 14:42:07.410284 2026] [security2:error] [pid 43637:tid 43870] [client 191.232.199.39:43048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/bolt.php"] [unique_id "amupD4a8U9lZpWaWlJKB4AAAAGY"]
[Thu Jul 30 14:42:07.446549 2026] [security2:error] [pid 43637:tid 43823] [client 20.226.5.174:36357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreviewalfa.php"] [unique_id "amupD4a8U9lZpWaWlJKB4QAAADc"]
[Thu Jul 30 14:42:07.730285 2026] [core:notice] [pid 43637:tid 43841] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:07.998573 2026] [security2:error] [pid 43637:tid 43888] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/i.php"] [unique_id "amupD4a8U9lZpWaWlJKB8gAAAHg"]
[Thu Jul 30 14:42:07.998664 2026] [security2:error] [pid 43637:tid 43888] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/i.php"] [unique_id "amupD4a8U9lZpWaWlJKB8gAAAHg"]
[Thu Jul 30 14:42:08.121869 2026] [security2:error] [pid 43637:tid 43821] [client 135.119.63.61:37944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/adminfuns.php"] [unique_id "amupEIa8U9lZpWaWlJKB9gAAADU"]
[Thu Jul 30 14:42:08.382069 2026] [security2:error] [pid 43637:tid 43876] [client 20.226.5.174:40071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreviewbypass.php"] [unique_id "amupEIa8U9lZpWaWlJKB9wAAAGw"]
[Thu Jul 30 14:42:08.530801 2026] [security2:error] [pid 43637:tid 43828] [client 191.232.199.39:14336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "kingstarenterprises.com"] [uri "/"] [unique_id "amupEIa8U9lZpWaWlJKB-wAAADw"]
[Thu Jul 30 14:42:08.537679 2026] [security2:error] [pid 43637:tid 43771] [client 52.238.199.152:3546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/nakrip.php"] [unique_id "amupEIa8U9lZpWaWlJKB_AAAAAM"]
[Thu Jul 30 14:42:08.621684 2026] [proxy:error] [pid 43637:tid 43833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:08.621749 2026] [proxy_http:error] [pid 43637:tid 43833] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:08.622321 2026] [proxy:error] [pid 43637:tid 43833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:08.622366 2026] [proxy_http:error] [pid 43637:tid 43833] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:08.622451 2026] [security2:error] [pid 43637:tid 43833] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amupEIa8U9lZpWaWlJKCBAAAAEE"]
[Thu Jul 30 14:42:08.782378 2026] [security2:error] [pid 43637:tid 43893] [client 191.232.199.39:3058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/3.php"] [unique_id "amupEIa8U9lZpWaWlJKCBQAAAH0"]
[Thu Jul 30 14:42:09.118008 2026] [security2:error] [pid 43637:tid 43770] [client 20.63.98.115:37225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-admin/maint/about.php"] [unique_id "amupEYa8U9lZpWaWlJKCEQAAAAI"]
[Thu Jul 30 14:42:09.275907 2026] [security2:error] [pid 43637:tid 43790] [client 20.226.5.174:7300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jesus.claims"] [uri "/linkpreviewk.php"] [unique_id "amupEYa8U9lZpWaWlJKCFQAAABY"]
[Thu Jul 30 14:42:09.389266 2026] [security2:error] [pid 43637:tid 43872] [client 191.232.199.39:14346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "kingstarenterprises.com"] [uri "/"] [unique_id "amupEYa8U9lZpWaWlJKCFgAAAGg"]
[Thu Jul 30 14:42:09.428163 2026] [security2:error] [pid 43637:tid 43799] [client 135.119.63.61:38620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/albin.php"] [unique_id "amupEYa8U9lZpWaWlJKCGAAAAB8"]
[Thu Jul 30 14:42:09.727595 2026] [security2:error] [pid 43637:tid 43884] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amupEYa8U9lZpWaWlJKCIgAAAHQ"]
[Thu Jul 30 14:42:09.727693 2026] [security2:error] [pid 43637:tid 43884] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amupEYa8U9lZpWaWlJKCIgAAAHQ"]
[Thu Jul 30 14:42:10.165322 2026] [security2:error] [pid 43637:tid 43795] [client 20.63.98.115:30492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amupEoa8U9lZpWaWlJKCLgAAABs"]
[Thu Jul 30 14:42:10.325352 2026] [security2:error] [pid 43637:tid 43853] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/themes/index.php"] [unique_id "amupEoa8U9lZpWaWlJKCMgAAAFU"]
[Thu Jul 30 14:42:10.325471 2026] [security2:error] [pid 43637:tid 43853] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/themes/index.php"] [unique_id "amupEoa8U9lZpWaWlJKCMgAAAFU"]
[Thu Jul 30 14:42:10.695771 2026] [security2:error] [pid 43637:tid 43747] [remote 74.7.243.224:42842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amupEoa8U9lZpWaWlJKCPgAARW0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:42:10.804966 2026] [security2:error] [pid 43637:tid 43877] [client 191.232.199.39:3056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/222.php"] [unique_id "amupEoa8U9lZpWaWlJKCRAAAAG0"]
[Thu Jul 30 14:42:10.827183 2026] [security2:error] [pid 43637:tid 43810] [client 135.119.63.61:35750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/amfsqvgv.php"] [unique_id "amupEoa8U9lZpWaWlJKCRQAAACo"]
[Thu Jul 30 14:42:11.087307 2026] [security2:error] [pid 43637:tid 43875] [client 20.63.98.115:1946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ty.php"] [unique_id "amupE4a8U9lZpWaWlJKCTgAAAGs"]
[Thu Jul 30 14:42:11.187096 2026] [security2:error] [pid 43637:tid 43794] [client 167.71.215.169:51228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "pkf.jo"] [uri "/wp-json/batch/v1"] [unique_id "amupE4a8U9lZpWaWlJKCUQAAABo"]
[Thu Jul 30 14:42:11.200579 2026] [security2:error] [pid 43637:tid 43881] [client 52.238.199.152:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "amupE4a8U9lZpWaWlJKCVAAAAHE"]
[Thu Jul 30 14:42:11.475718 2026] [security2:error] [pid 43637:tid 43883] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupEoa8U9lZpWaWlJKCSQAAAHM"]
[Thu Jul 30 14:42:11.858956 2026] [security2:error] [pid 43637:tid 43838] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/gecko-new.php"] [unique_id "amupE4a8U9lZpWaWlJKCYwAAAEY"]
[Thu Jul 30 14:42:11.859097 2026] [security2:error] [pid 43637:tid 43838] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/gecko-new.php"] [unique_id "amupE4a8U9lZpWaWlJKCYwAAAEY"]
[Thu Jul 30 14:42:12.145991 2026] [security2:error] [pid 43637:tid 43842] [client 135.119.63.61:35749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/ant.php"] [unique_id "amupFIa8U9lZpWaWlJKCaQAAAEo"]
[Thu Jul 30 14:42:12.156133 2026] [security2:error] [pid 43637:tid 43823] [client 191.232.199.39:3062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amupFIa8U9lZpWaWlJKCawAAADc"]
[Thu Jul 30 14:42:12.174165 2026] [core:notice] [pid 43637:tid 43776] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:12.428244 2026] [security2:error] [pid 43637:tid 43852] [client 52.238.199.152:47117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/SimplePie/gzdecodes.php"] [unique_id "amupFIa8U9lZpWaWlJKCdgAAAFQ"]
[Thu Jul 30 14:42:12.485389 2026] [security2:error] [pid 43637:tid 43867] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/NewFile.php"] [unique_id "amupFIa8U9lZpWaWlJKCdwAAAGM"]
[Thu Jul 30 14:42:12.485538 2026] [security2:error] [pid 43637:tid 43867] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/NewFile.php"] [unique_id "amupFIa8U9lZpWaWlJKCdwAAAGM"]
[Thu Jul 30 14:42:12.847743 2026] [security2:error] [pid 43637:tid 43875] [client 158.158.76.106:1949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/nothing2.php"] [unique_id "amupFIa8U9lZpWaWlJKCiAAAAGs"]
[Thu Jul 30 14:42:12.847875 2026] [security2:error] [pid 43637:tid 43875] [client 158.158.76.106:1949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/nothing2.php"] [unique_id "amupFIa8U9lZpWaWlJKCiAAAAGs"]
[Thu Jul 30 14:42:13.077838 2026] [security2:error] [pid 43637:tid 43868] [client 172.237.109.114:46833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKCiwAAAGQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.078771 2026] [security2:error] [pid 43637:tid 43866] [client 172.237.109.114:48359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKCjAAAAGI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.079007 2026] [security2:error] [pid 43637:tid 43846] [client 172.237.109.114:53283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKCjgAAAE4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.079706 2026] [security2:error] [pid 43637:tid 43817] [client 172.237.109.114:38567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKCjQAAADE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.093808 2026] [security2:error] [pid 43637:tid 43871] [client 172.237.109.114:12562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKCjwAAAGc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.093843 2026] [security2:error] [pid 43637:tid 43824] [client 172.237.109.114:13530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKCkAAAADg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.094958 2026] [security2:error] [pid 43637:tid 43781] [client 172.237.109.114:10730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKCkQAAAA0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.095064 2026] [security2:error] [pid 43637:tid 43813] [client 172.237.109.114:49853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKCkgAAAC0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.123793 2026] [security2:error] [pid 43637:tid 43881] [client 172.237.109.114:45155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKClAAAAHE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.148120 2026] [security2:error] [pid 43637:tid 43820] [client 172.237.109.114:57539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKClwAAADQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.150095 2026] [security2:error] [pid 43637:tid 43863] [client 172.237.109.114:18202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFYa8U9lZpWaWlJKCmAAAAF8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:13.366616 2026] [security2:error] [pid 43637:tid 43874] [client 52.238.199.152:37146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/radio.php"] [unique_id "amupFYa8U9lZpWaWlJKCngAAAGo"]
[Thu Jul 30 14:42:13.548465 2026] [security2:error] [pid 43637:tid 43772] [client 191.232.199.39:48991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amupFYa8U9lZpWaWlJKCpAAAAAQ"]
[Thu Jul 30 14:42:13.620882 2026] [security2:error] [pid 43637:tid 43823] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-Blogs.php"] [unique_id "amupFYa8U9lZpWaWlJKCpQAAADc"]
[Thu Jul 30 14:42:13.621050 2026] [security2:error] [pid 43637:tid 43823] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-Blogs.php"] [unique_id "amupFYa8U9lZpWaWlJKCpQAAADc"]
[Thu Jul 30 14:42:13.663712 2026] [security2:error] [pid 43637:tid 43770] [client 135.119.63.61:38631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/appreciators.php"] [unique_id "amupFYa8U9lZpWaWlJKCpgAAAAI"]
[Thu Jul 30 14:42:13.699247 2026] [security2:error] [pid 43637:tid 43841] [client 52.238.199.152:3905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-back.php"] [unique_id "amupFYa8U9lZpWaWlJKCqAAAAEk"]
[Thu Jul 30 14:42:14.079921 2026] [security2:error] [pid 43637:tid 43843] [client 172.237.109.114:17491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFoa8U9lZpWaWlJKCswAAAEs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:14.081039 2026] [security2:error] [pid 43637:tid 43849] [client 172.237.109.114:1601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFoa8U9lZpWaWlJKCtAAAAFE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:14.123369 2026] [security2:error] [pid 43637:tid 43852] [client 172.237.109.114:30318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFoa8U9lZpWaWlJKCtQAAAFQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:14.125299 2026] [security2:error] [pid 43637:tid 43837] [client 172.237.109.114:16561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFoa8U9lZpWaWlJKCtwAAAEU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:14.125356 2026] [security2:error] [pid 43637:tid 43867] [client 172.237.109.114:52629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFoa8U9lZpWaWlJKCtgAAAGM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:14.125427 2026] [security2:error] [pid 43637:tid 43797] [client 172.237.109.114:23852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFoa8U9lZpWaWlJKCuAAAAB0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:14.125451 2026] [security2:error] [pid 43637:tid 43853] [client 172.237.109.114:22522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFoa8U9lZpWaWlJKCuQAAAFU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:14.151799 2026] [security2:error] [pid 43637:tid 43771] [client 172.237.109.114:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupFoa8U9lZpWaWlJKCugAAAAM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:14.205146 2026] [security2:error] [pid 43637:tid 43801] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "amupFoa8U9lZpWaWlJKCvgAAACE"]
[Thu Jul 30 14:42:14.205289 2026] [security2:error] [pid 43637:tid 43801] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "amupFoa8U9lZpWaWlJKCvgAAACE"]
[Thu Jul 30 14:42:14.682830 2026] [security2:error] [pid 43637:tid 43817] [client 135.119.63.61:38627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/archive.php"] [unique_id "amupFoa8U9lZpWaWlJKCzgAAADE"]
[Thu Jul 30 14:42:14.772921 2026] [security2:error] [pid 43637:tid 43686] [remote 106.75.98.244:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/favicon.ico"] [unique_id "amupFoa8U9lZpWaWlJKC0gAAPzA"]
[Thu Jul 30 14:42:14.809804 2026] [security2:error] [pid 43637:tid 43870] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/themes.php"] [unique_id "amupFoa8U9lZpWaWlJKC1AAAAGY"]
[Thu Jul 30 14:42:14.809901 2026] [security2:error] [pid 43637:tid 43870] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/themes.php"] [unique_id "amupFoa8U9lZpWaWlJKC1AAAAGY"]
[Thu Jul 30 14:42:14.814926 2026] [security2:error] [pid 43637:tid 43892] [client 20.63.98.115:41768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/readme.php"] [unique_id "amupFoa8U9lZpWaWlJKC1QAAAHw"]
[Thu Jul 30 14:42:14.837207 2026] [security2:error] [pid 43637:tid 43763] [remote 154.38.175.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.175.38.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skilledfurnituremoversuae.com"] [uri "/xmlrpc.php"] [unique_id "amupFoa8U9lZpWaWlJKCzAAAK3w"]
[Thu Jul 30 14:42:14.837413 2026] [security2:error] [pid 43637:tid 43811] [client 154.38.175.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skilledfurnituremoversuae.com"] [uri "/xmlrpc.php"] [unique_id "amupFoa8U9lZpWaWlJKCzAAAK3w"]
[Thu Jul 30 14:42:15.016059 2026] [security2:error] [pid 43637:tid 43780] [client 189.156.226.90:27061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupF4a8U9lZpWaWlJKC3QAAAAw"]
[Thu Jul 30 14:42:15.016144 2026] [security2:error] [pid 43637:tid 43780] [client 189.156.226.90:27061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupF4a8U9lZpWaWlJKC3QAAAAw"]
[Thu Jul 30 14:42:15.072113 2026] [security2:error] [pid 43637:tid 43880] [client 111.225.149.45:63414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amupF4a8U9lZpWaWlJKC3gAAAHA"]
[Thu Jul 30 14:42:15.094139 2026] [security2:error] [pid 43637:tid 43874] [client 172.237.109.114:59774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupF4a8U9lZpWaWlJKC3wAAAGo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:15.094243 2026] [security2:error] [pid 43637:tid 43874] [client 172.237.109.114:59774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupF4a8U9lZpWaWlJKC3wAAAGo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:15.355275 2026] [security2:error] [pid 43637:tid 43834] [client 191.232.199.39:3071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/admin.php"] [unique_id "amupF4a8U9lZpWaWlJKC4wAAAEI"]
[Thu Jul 30 14:42:15.407263 2026] [security2:error] [pid 43637:tid 43839] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/cv.php"] [unique_id "amupF4a8U9lZpWaWlJKC5wAAAEc"]
[Thu Jul 30 14:42:15.407363 2026] [security2:error] [pid 43637:tid 43839] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/cv.php"] [unique_id "amupF4a8U9lZpWaWlJKC5wAAAEc"]
[Thu Jul 30 14:42:15.436427 2026] [core:error] [pid 43637:tid 43858] [client 45.92.84.170:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:15.436450 2026] [core:error] [pid 43637:tid 43858] [client 45.92.84.170:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:15.466105 2026] [security2:error] [pid 43637:tid 43776] [client 52.238.199.152:16340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "amupF4a8U9lZpWaWlJKC7gAAAAg"]
[Thu Jul 30 14:42:15.568214 2026] [security2:error] [pid 43637:tid 43750] [remote 106.75.98.244:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/404.html/sitemap.xml"] [unique_id "amupF4a8U9lZpWaWlJKC7wAAA3A"]
[Thu Jul 30 14:42:15.700274 2026] [security2:error] [pid 43637:tid 43832] [client 52.238.199.152:56310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-singin.php"] [unique_id "amupF4a8U9lZpWaWlJKC9gAAAEA"]
[Thu Jul 30 14:42:15.995520 2026] [proxy:error] [pid 43637:tid 43873] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:15.995594 2026] [proxy_http:error] [pid 43637:tid 43873] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:15.996231 2026] [proxy:error] [pid 43637:tid 43873] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:15.996275 2026] [proxy_http:error] [pid 43637:tid 43873] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:15.996354 2026] [security2:error] [pid 43637:tid 43873] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amupF4a8U9lZpWaWlJKDAAAAAGk"]
[Thu Jul 30 14:42:16.028520 2026] [security2:error] [pid 43637:tid 43754] [remote 106.75.98.244:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/404.html/robots.txt"] [unique_id "amupGIa8U9lZpWaWlJKDAQAAX3Q"]
[Thu Jul 30 14:42:16.203881 2026] [security2:error] [pid 43637:tid 43859] [client 135.119.63.61:35759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/as.php"] [unique_id "amupGIa8U9lZpWaWlJKDAgAAAFs"]
[Thu Jul 30 14:42:16.520389 2026] [security2:error] [pid 43637:tid 43883] [client 20.63.98.115:41758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-admin/options.php"] [unique_id "amupGIa8U9lZpWaWlJKDDAAAAHM"]
[Thu Jul 30 14:42:16.613797 2026] [security2:error] [pid 43637:tid 43886] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amupGIa8U9lZpWaWlJKDDQAAAHY"]
[Thu Jul 30 14:42:16.613904 2026] [security2:error] [pid 43637:tid 43886] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amupGIa8U9lZpWaWlJKDDQAAAHY"]
[Thu Jul 30 14:42:16.632315 2026] [core:error] [pid 43637:tid 43808] [client 45.92.84.170:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:16.632333 2026] [core:error] [pid 43637:tid 43808] [client 45.92.84.170:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:16.636417 2026] [security2:error] [pid 43637:tid 43790] [client 191.232.199.39:43042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-configs.php"] [unique_id "amupGIa8U9lZpWaWlJKDEQAAABY"]
[Thu Jul 30 14:42:16.784728 2026] [security2:error] [pid 43637:tid 43782] [client 52.238.199.152:16355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/themes/index.php"] [unique_id "amupGIa8U9lZpWaWlJKDEgAAAA4"]
[Thu Jul 30 14:42:16.915877 2026] [security2:error] [pid 43637:tid 43772] [client 64.42.179.59:36672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amupGIa8U9lZpWaWlJKDFwAAAAQ"]
[Thu Jul 30 14:42:16.916003 2026] [security2:error] [pid 43637:tid 43772] [client 64.42.179.59:36672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amupGIa8U9lZpWaWlJKDFwAAAAQ"]
[Thu Jul 30 14:42:17.197994 2026] [security2:error] [pid 43637:tid 43784] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/ws83.php"] [unique_id "amupGYa8U9lZpWaWlJKDIgAAABA"]
[Thu Jul 30 14:42:17.198081 2026] [security2:error] [pid 43637:tid 43784] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/ws83.php"] [unique_id "amupGYa8U9lZpWaWlJKDIgAAABA"]
[Thu Jul 30 14:42:17.344626 2026] [security2:error] [pid 43637:tid 43894] [client 135.119.63.61:38592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/atomlib.php"] [unique_id "amupGYa8U9lZpWaWlJKDJAAAAH4"]
[Thu Jul 30 14:42:17.393610 2026] [core:error] [pid 43637:tid 43847] [client 31.56.58.134:46406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:17.393638 2026] [core:error] [pid 43637:tid 43847] [client 31.56.58.134:46406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:17.625798 2026] [security2:error] [pid 43637:tid 43836] [client 172.237.109.114:54427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amupGYa8U9lZpWaWlJKDHgAAAEQ"]
[Thu Jul 30 14:42:17.660829 2026] [security2:error] [pid 43637:tid 43771] [client 31.56.58.134:46408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-8880a99c.lld.nyx.temporary.site"] [uri "/.env"] [unique_id "amupGYa8U9lZpWaWlJKDNgAAAAM"]
[Thu Jul 30 14:42:17.786493 2026] [security2:error] [pid 43637:tid 43889] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/atex1.php"] [unique_id "amupGYa8U9lZpWaWlJKDOQAAAHk"]
[Thu Jul 30 14:42:17.786599 2026] [security2:error] [pid 43637:tid 43889] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/atex1.php"] [unique_id "amupGYa8U9lZpWaWlJKDOQAAAHk"]
[Thu Jul 30 14:42:17.852882 2026] [security2:error] [pid 43637:tid 43868] [client 158.158.76.106:1983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/media.php"] [unique_id "amupGYa8U9lZpWaWlJKDOgAAAGQ"]
[Thu Jul 30 14:42:17.853006 2026] [security2:error] [pid 43637:tid 43868] [client 158.158.76.106:1983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/media.php"] [unique_id "amupGYa8U9lZpWaWlJKDOgAAAGQ"]
[Thu Jul 30 14:42:18.162782 2026] [security2:error] [pid 43637:tid 43813] [client 52.238.199.152:56297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/as.php"] [unique_id "amupGoa8U9lZpWaWlJKDSQAAAC0"]
[Thu Jul 30 14:42:18.194312 2026] [security2:error] [pid 43637:tid 43803] [client 191.232.199.39:48961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/php.php"] [unique_id "amupGoa8U9lZpWaWlJKDSgAAACM"]
[Thu Jul 30 14:42:18.302353 2026] [security2:error] [pid 43637:tid 43802] [client 52.238.199.152:3928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/user.php"] [unique_id "amupGoa8U9lZpWaWlJKDTAAAACI"]
[Thu Jul 30 14:42:18.382088 2026] [security2:error] [pid 43637:tid 43793] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/class-t.api.php"] [unique_id "amupGoa8U9lZpWaWlJKDTQAAABk"]
[Thu Jul 30 14:42:18.382232 2026] [security2:error] [pid 43637:tid 43793] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/class-t.api.php"] [unique_id "amupGoa8U9lZpWaWlJKDTQAAABk"]
[Thu Jul 30 14:42:18.480864 2026] [security2:error] [pid 43637:tid 43812] [client 177.6.106.101:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupGoa8U9lZpWaWlJKDVAAAACw"]
[Thu Jul 30 14:42:18.480967 2026] [security2:error] [pid 43637:tid 43812] [client 177.6.106.101:53587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupGoa8U9lZpWaWlJKDVAAAACw"]
[Thu Jul 30 14:42:18.693048 2026] [core:notice] [pid 43637:tid 43865] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:18.964192 2026] [security2:error] [pid 43637:tid 43769] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/w.php"] [unique_id "amupGoa8U9lZpWaWlJKDYwAAAAE"]
[Thu Jul 30 14:42:18.964308 2026] [security2:error] [pid 43637:tid 43769] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/w.php"] [unique_id "amupGoa8U9lZpWaWlJKDYwAAAAE"]
[Thu Jul 30 14:42:19.033344 2026] [security2:error] [pid 43637:tid 43819] [client 52.238.199.152:47293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/x.php"] [unique_id "amupG4a8U9lZpWaWlJKDZwAAADM"]
[Thu Jul 30 14:42:19.068244 2026] [security2:error] [pid 43637:tid 43725] [remote 106.75.98.244:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/favicon.ico"] [unique_id "amupG4a8U9lZpWaWlJKDbAAAQlc"]
[Thu Jul 30 14:42:19.470665 2026] [security2:error] [pid 43637:tid 43895] [client 191.232.199.39:53441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/index.php"] [unique_id "amupG4a8U9lZpWaWlJKDdgAAAH8"]
[Thu Jul 30 14:42:19.525696 2026] [core:notice] [pid 43637:tid 43850] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:19.536919 2026] [security2:error] [pid 43637:tid 43788] [client 135.119.63.61:38639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/autoload_classmap.php"] [unique_id "amupG4a8U9lZpWaWlJKDewAAABQ"]
[Thu Jul 30 14:42:19.848887 2026] [security2:error] [pid 43637:tid 43653] [remote 106.75.98.244:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/404.html/sitemap.xml"] [unique_id "amupG4a8U9lZpWaWlJKDjgAAfQ8"]
[Thu Jul 30 14:42:20.028391 2026] [security2:error] [pid 43637:tid 43781] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/archive.php"] [unique_id "amupHIa8U9lZpWaWlJKDkgAAAA0"]
[Thu Jul 30 14:42:20.028479 2026] [security2:error] [pid 43637:tid 43781] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/archive.php"] [unique_id "amupHIa8U9lZpWaWlJKDkgAAAA0"]
[Thu Jul 30 14:42:20.167667 2026] [security2:error] [pid 43637:tid 43815] [client 52.238.199.152:47121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "amupHIa8U9lZpWaWlJKDngAAAC8"]
[Thu Jul 30 14:42:20.301877 2026] [security2:error] [pid 43637:tid 43732] [remote 106.75.98.244:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/404.html/robots.txt"] [unique_id "amupHIa8U9lZpWaWlJKDoAAAcV4"]
[Thu Jul 30 14:42:20.343966 2026] [security2:error] [pid 43637:tid 43821] [client 158.158.76.106:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/file2.php"] [unique_id "amupHIa8U9lZpWaWlJKDoQAAADU"]
[Thu Jul 30 14:42:20.344084 2026] [security2:error] [pid 43637:tid 43821] [client 158.158.76.106:1928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/file2.php"] [unique_id "amupHIa8U9lZpWaWlJKDoQAAADU"]
[Thu Jul 30 14:42:20.439323 2026] [core:notice] [pid 43637:tid 43643] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:20.637598 2026] [security2:error] [pid 43637:tid 43892] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/bless.php"] [unique_id "amupHIa8U9lZpWaWlJKDrQAAAHw"]
[Thu Jul 30 14:42:20.637722 2026] [security2:error] [pid 43637:tid 43892] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/bless.php"] [unique_id "amupHIa8U9lZpWaWlJKDrQAAAHw"]
[Thu Jul 30 14:42:20.807728 2026] [security2:error] [pid 43637:tid 43776] [client 52.238.199.152:3702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/item.php"] [unique_id "amupHIa8U9lZpWaWlJKDsQAAAAg"]
[Thu Jul 30 14:42:20.960515 2026] [security2:error] [pid 43637:tid 43835] [client 191.232.199.39:48997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/a.php"] [unique_id "amupHIa8U9lZpWaWlJKDsgAAAEM"]
[Thu Jul 30 14:42:21.145032 2026] [security2:error] [pid 43637:tid 43772] [client 31.56.58.134:43384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-8880a99c.lld.nyx.temporary.site"] [uri "/.env"] [unique_id "amupHYa8U9lZpWaWlJKDuQAAAAQ"]
[Thu Jul 30 14:42:21.386743 2026] [security2:error] [pid 43637:tid 43886] [client 135.119.63.61:38621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/bb.php"] [unique_id "amupHYa8U9lZpWaWlJKDvQAAAHY"]
[Thu Jul 30 14:42:21.476035 2026] [core:error] [pid 43637:tid 43843] [client 31.56.58.134:43388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:21.476059 2026] [core:error] [pid 43637:tid 43843] [client 31.56.58.134:43388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:42:22.061546 2026] [security2:error] [pid 43637:tid 43805] [client 52.238.199.152:3934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amupHoa8U9lZpWaWlJKDyAAAACU"]
[Thu Jul 30 14:42:22.085413 2026] [security2:error] [pid 43637:tid 43845] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/sagax1.php"] [unique_id "amupHoa8U9lZpWaWlJKDywAAAE0"]
[Thu Jul 30 14:42:22.085501 2026] [security2:error] [pid 43637:tid 43845] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/sagax1.php"] [unique_id "amupHoa8U9lZpWaWlJKDywAAAE0"]
[Thu Jul 30 14:42:22.249550 2026] [security2:error] [pid 43637:tid 43775] [client 20.63.98.115:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/admin.php7"] [unique_id "amupHoa8U9lZpWaWlJKD1AAAAAc"]
[Thu Jul 30 14:42:22.665853 2026] [core:notice] [pid 43637:tid 43738] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:22.732513 2026] [security2:error] [pid 43637:tid 43803] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wpc.php"] [unique_id "amupHoa8U9lZpWaWlJKD5QAAACM"]
[Thu Jul 30 14:42:22.732680 2026] [security2:error] [pid 43637:tid 43803] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wpc.php"] [unique_id "amupHoa8U9lZpWaWlJKD5QAAACM"]
[Thu Jul 30 14:42:22.824886 2026] [security2:error] [pid 43637:tid 43796] [client 135.119.63.61:38606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/bnm.php"] [unique_id "amupHoa8U9lZpWaWlJKD5gAAABw"]
[Thu Jul 30 14:42:23.113044 2026] [security2:error] [pid 43637:tid 43774] [client 191.232.199.39:53469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amupH4a8U9lZpWaWlJKD8QAAAAY"]
[Thu Jul 30 14:42:23.117942 2026] [security2:error] [pid 43637:tid 43848] [client 52.238.199.152:33731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/app.php"] [unique_id "amupH4a8U9lZpWaWlJKD8gAAAFA"]
[Thu Jul 30 14:42:23.277146 2026] [security2:error] [pid 43637:tid 43811] [client 158.158.76.106:1933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/simple.php"] [unique_id "amupH4a8U9lZpWaWlJKD9wAAACs"]
[Thu Jul 30 14:42:23.277299 2026] [security2:error] [pid 43637:tid 43811] [client 158.158.76.106:1933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/simple.php"] [unique_id "amupH4a8U9lZpWaWlJKD9wAAACs"]
[Thu Jul 30 14:42:23.338742 2026] [security2:error] [pid 43637:tid 43776] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/fone1.php"] [unique_id "amupH4a8U9lZpWaWlJKD-wAAAAg"]
[Thu Jul 30 14:42:23.338898 2026] [security2:error] [pid 43637:tid 43776] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/fone1.php"] [unique_id "amupH4a8U9lZpWaWlJKD-wAAAAg"]
[Thu Jul 30 14:42:23.427096 2026] [security2:error] [pid 43637:tid 43793] [client 52.238.199.152:47116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/hehe.php"] [unique_id "amupH4a8U9lZpWaWlJKD_AAAABk"]
[Thu Jul 30 14:42:23.483209 2026] [security2:error] [pid 43637:tid 43838] [client 20.63.98.115:27262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/.well-known/wp-login.php"] [unique_id "amupH4a8U9lZpWaWlJKD_QAAAEY"]
[Thu Jul 30 14:42:24.253016 2026] [core:notice] [pid 43637:tid 43788] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:24.343960 2026] [security2:error] [pid 43637:tid 43791] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/ncx.php"] [unique_id "amupIIa8U9lZpWaWlJKEGAAAABc"]
[Thu Jul 30 14:42:24.344071 2026] [security2:error] [pid 43637:tid 43791] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/ncx.php"] [unique_id "amupIIa8U9lZpWaWlJKEGAAAABc"]
[Thu Jul 30 14:42:24.517956 2026] [security2:error] [pid 43637:tid 43787] [client 20.63.98.115:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amupIIa8U9lZpWaWlJKEGQAAABM"]
[Thu Jul 30 14:42:24.915831 2026] [security2:error] [pid 43637:tid 43794] [client 135.119.63.61:34779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/bootstrap.php"] [unique_id "amupIIa8U9lZpWaWlJKEJgAAABo"]
[Thu Jul 30 14:42:24.923016 2026] [core:notice] [pid 43637:tid 43803] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:25.074286 2026] [security2:error] [pid 43637:tid 43872] [client 43.172.198.224:42490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/02/20/collection-printemps-ete-2013-accessorize/"] [unique_id "amupIIa8U9lZpWaWlJKEJQAAAGg"]
[Thu Jul 30 14:42:25.088458 2026] [security2:error] [pid 43637:tid 43836] [client 191.232.199.39:43014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin.php"] [unique_id "amupIYa8U9lZpWaWlJKEKAAAAEQ"]
[Thu Jul 30 14:42:25.099047 2026] [security2:error] [pid 43637:tid 43837] [client 52.238.199.152:3705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/k.php"] [unique_id "amupIYa8U9lZpWaWlJKEKQAAAEU"]
[Thu Jul 30 14:42:25.157167 2026] [security2:error] [pid 43637:tid 43796] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-admin/js/index.php"] [unique_id "amupIYa8U9lZpWaWlJKEKgAAABw"]
[Thu Jul 30 14:42:25.157325 2026] [security2:error] [pid 43637:tid 43796] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-admin/js/index.php"] [unique_id "amupIYa8U9lZpWaWlJKEKgAAABw"]
[Thu Jul 30 14:42:25.376793 2026] [security2:error] [pid 43637:tid 43816] [client 158.158.76.106:1929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amupIYa8U9lZpWaWlJKENAAAADA"]
[Thu Jul 30 14:42:25.376895 2026] [security2:error] [pid 43637:tid 43816] [client 158.158.76.106:1929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/mac.php"] [unique_id "amupIYa8U9lZpWaWlJKENAAAADA"]
[Thu Jul 30 14:42:25.419661 2026] [security2:error] [pid 43637:tid 43802] [client 20.63.98.115:27214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-admin/file.php"] [unique_id "amupIYa8U9lZpWaWlJKENQAAACI"]
[Thu Jul 30 14:42:25.484593 2026] [core:notice] [pid 43637:tid 43795] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:25.490178 2026] [security2:error] [pid 43637:tid 43795] [client 43.173.181.164:54794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/02/20/collection-printemps-ete-2013-accessorize/"] [unique_id "amupIYa8U9lZpWaWlJKENgAAABs"], referer: https://carnetdeshopping.com/index.php/2013/02/20/collection-printemps-ete-2013-accessorize/
[Thu Jul 30 14:42:25.594967 2026] [security2:error] [pid 43637:tid 43814] [client 189.156.226.90:27334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupIYa8U9lZpWaWlJKENwAAAC4"]
[Thu Jul 30 14:42:25.595134 2026] [security2:error] [pid 43637:tid 43814] [client 189.156.226.90:27334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupIYa8U9lZpWaWlJKENwAAAC4"]
[Thu Jul 30 14:42:25.797844 2026] [security2:error] [pid 43637:tid 43823] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wso.php"] [unique_id "amupIYa8U9lZpWaWlJKEPAAAADc"]
[Thu Jul 30 14:42:25.797996 2026] [security2:error] [pid 43637:tid 43823] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wso.php"] [unique_id "amupIYa8U9lZpWaWlJKEPAAAADc"]
[Thu Jul 30 14:42:26.387290 2026] [security2:error] [pid 43637:tid 43850] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/zup.php73"] [unique_id "amupIoa8U9lZpWaWlJKETgAAAFI"]
[Thu Jul 30 14:42:26.387387 2026] [security2:error] [pid 43637:tid 43850] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/zup.php73"] [unique_id "amupIoa8U9lZpWaWlJKETgAAAFI"]
[Thu Jul 30 14:42:26.687094 2026] [security2:error] [pid 43637:tid 43895] [client 135.119.63.61:34788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/buy.php"] [unique_id "amupIoa8U9lZpWaWlJKEUgAAAH8"]
[Thu Jul 30 14:42:26.750034 2026] [security2:error] [pid 43637:tid 43810] [client 191.232.199.39:47905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/size.php"] [unique_id "amupIoa8U9lZpWaWlJKEUwAAACo"]
[Thu Jul 30 14:42:26.989549 2026] [security2:error] [pid 43637:tid 43801] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/k.php"] [unique_id "amupIoa8U9lZpWaWlJKEWgAAACE"]
[Thu Jul 30 14:42:26.989711 2026] [security2:error] [pid 43637:tid 43801] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/k.php"] [unique_id "amupIoa8U9lZpWaWlJKEWgAAACE"]
[Thu Jul 30 14:42:27.524647 2026] [security2:error] [pid 43637:tid 43886] [client 20.63.98.115:49308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/bak.php"] [unique_id "amupI4a8U9lZpWaWlJKEaAAAAHY"]
[Thu Jul 30 14:42:27.611356 2026] [security2:error] [pid 43637:tid 43785] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-blink.php"] [unique_id "amupI4a8U9lZpWaWlJKEbAAAABE"]
[Thu Jul 30 14:42:27.611456 2026] [security2:error] [pid 43637:tid 43785] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-blink.php"] [unique_id "amupI4a8U9lZpWaWlJKEbAAAABE"]
[Thu Jul 30 14:42:27.686696 2026] [security2:error] [pid 43637:tid 43851] [client 135.119.63.61:35732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/chosen.php"] [unique_id "amupI4a8U9lZpWaWlJKEcAAAAFM"]
[Thu Jul 30 14:42:27.921602 2026] [security2:error] [pid 43637:tid 43866] [client 47.128.121.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amupI4a8U9lZpWaWlJKEcwAAAGI"]
[Thu Jul 30 14:42:28.241788 2026] [proxy:error] [pid 43637:tid 43786] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:28.241870 2026] [proxy_http:error] [pid 43637:tid 43786] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:28.242453 2026] [proxy:error] [pid 43637:tid 43786] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:28.242500 2026] [proxy_http:error] [pid 43637:tid 43786] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:28.242611 2026] [security2:error] [pid 43637:tid 43786] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amupJIa8U9lZpWaWlJKEhAAAABI"]
[Thu Jul 30 14:42:28.327946 2026] [security2:error] [pid 43637:tid 43819] [client 20.63.98.115:1933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/config.php"] [unique_id "amupJIa8U9lZpWaWlJKEhQAAADM"]
[Thu Jul 30 14:42:28.658128 2026] [security2:error] [pid 43637:tid 43856] [client 135.119.63.61:35766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/class-wp-image.php"] [unique_id "amupJIa8U9lZpWaWlJKEkAAAAFg"]
[Thu Jul 30 14:42:28.757443 2026] [security2:error] [pid 43637:tid 43715] [remote 57.141.0.33:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amupJIa8U9lZpWaWlJKEkQAAaU0"]
[Thu Jul 30 14:42:28.853766 2026] [security2:error] [pid 43637:tid 43798] [client 52.238.199.152:3689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-fmfile.php"] [unique_id "amupJIa8U9lZpWaWlJKEkwAAAB4"]
[Thu Jul 30 14:42:28.854693 2026] [proxy:error] [pid 43637:tid 43833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:28.854753 2026] [proxy_http:error] [pid 43637:tid 43833] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:28.855594 2026] [proxy:error] [pid 43637:tid 43833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:28.855644 2026] [proxy_http:error] [pid 43637:tid 43833] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:28.855725 2026] [security2:error] [pid 43637:tid 43833] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amupJIa8U9lZpWaWlJKEkgAAAEE"]
[Thu Jul 30 14:42:28.956586 2026] [security2:error] [pid 43637:tid 43869] [client 52.238.199.152:47133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/webadmin.php"] [unique_id "amupJIa8U9lZpWaWlJKElwAAAGU"]
[Thu Jul 30 14:42:29.436090 2026] [proxy:error] [pid 43637:tid 43847] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:29.436164 2026] [proxy_http:error] [pid 43637:tid 43847] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:29.436734 2026] [proxy:error] [pid 43637:tid 43847] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:29.436775 2026] [proxy_http:error] [pid 43637:tid 43847] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:29.436871 2026] [security2:error] [pid 43637:tid 43847] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.koinjp189.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amupJYa8U9lZpWaWlJKEoQAAAE8"]
[Thu Jul 30 14:42:29.461043 2026] [security2:error] [pid 43637:tid 43846] [client 135.119.63.61:34800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/classsmtps.php"] [unique_id "amupJYa8U9lZpWaWlJKEogAAAE4"]
[Thu Jul 30 14:42:29.609675 2026] [security2:error] [pid 43637:tid 43879] [client 135.119.63.61:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cakiltheme/idx.php"] [unique_id "amupJYa8U9lZpWaWlJKErAAAAG8"]
[Thu Jul 30 14:42:30.080578 2026] [security2:error] [pid 43637:tid 43866] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/ww5.php"] [unique_id "amupJoa8U9lZpWaWlJKEtgAAAGI"]
[Thu Jul 30 14:42:30.080680 2026] [security2:error] [pid 43637:tid 43866] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/ww5.php"] [unique_id "amupJoa8U9lZpWaWlJKEtgAAAGI"]
[Thu Jul 30 14:42:30.145787 2026] [security2:error] [pid 43637:tid 43776] [client 216.73.216.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "themushroom.online"] [uri "/index.php"] [unique_id "amupJYa8U9lZpWaWlJKEsAAAAAg"]
[Thu Jul 30 14:42:30.293258 2026] [security2:error] [pid 43637:tid 43813] [client 135.119.63.61:34802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/classwithtostring.php"] [unique_id "amupJoa8U9lZpWaWlJKEvAAAAC0"]
[Thu Jul 30 14:42:30.319152 2026] [security2:error] [pid 43637:tid 43883] [client 135.119.63.61:17544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cakiltheme/up.php"] [unique_id "amupJoa8U9lZpWaWlJKEvQAAAHM"]
[Thu Jul 30 14:42:30.355909 2026] [security2:error] [pid 43637:tid 43774] [client 191.232.199.39:2892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amupJoa8U9lZpWaWlJKEvwAAAAY"]
[Thu Jul 30 14:42:30.384595 2026] [security2:error] [pid 43637:tid 43770] [client 52.238.199.152:47153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/backup.php"] [unique_id "amupJoa8U9lZpWaWlJKEwQAAAAI"]
[Thu Jul 30 14:42:30.466736 2026] [security2:error] [pid 43637:tid 43804] [client 52.238.199.152:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wi.php"] [unique_id "amupJoa8U9lZpWaWlJKEwgAAACQ"]
[Thu Jul 30 14:42:30.724202 2026] [security2:error] [pid 43637:tid 43768] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/2.php"] [unique_id "amupJoa8U9lZpWaWlJKEzAAAAAA"]
[Thu Jul 30 14:42:30.724309 2026] [security2:error] [pid 43637:tid 43768] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/2.php"] [unique_id "amupJoa8U9lZpWaWlJKEzAAAAAA"]
[Thu Jul 30 14:42:31.052114 2026] [security2:error] [pid 43637:tid 43806] [client 135.119.63.61:5439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/calendar/index.php"] [unique_id "amupJ4a8U9lZpWaWlJKEzgAAACY"]
[Thu Jul 30 14:42:31.159693 2026] [security2:error] [pid 43637:tid 43882] [client 135.119.63.61:35721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/config.php"] [unique_id "amupJ4a8U9lZpWaWlJKE0AAAAHI"]
[Thu Jul 30 14:42:31.317733 2026] [security2:error] [pid 43637:tid 43826] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amupJ4a8U9lZpWaWlJKE2wAAADo"]
[Thu Jul 30 14:42:31.317838 2026] [security2:error] [pid 43637:tid 43826] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amupJ4a8U9lZpWaWlJKE2wAAADo"]
[Thu Jul 30 14:42:31.753123 2026] [security2:error] [pid 43637:tid 43861] [client 135.119.63.61:5402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/canonical.php"] [unique_id "amupJ4a8U9lZpWaWlJKE6wAAAF0"]
[Thu Jul 30 14:42:31.815948 2026] [security2:error] [pid 43637:tid 43885] [client 52.238.199.152:39085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/atomlib.php"] [unique_id "amupJ4a8U9lZpWaWlJKE7gAAAHU"]
[Thu Jul 30 14:42:31.897316 2026] [security2:error] [pid 43637:tid 43863] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/atomlib.php"] [unique_id "amupJ4a8U9lZpWaWlJKE7wAAAF8"]
[Thu Jul 30 14:42:31.897435 2026] [security2:error] [pid 43637:tid 43863] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/atomlib.php"] [unique_id "amupJ4a8U9lZpWaWlJKE7wAAAF8"]
[Thu Jul 30 14:42:32.061283 2026] [security2:error] [pid 43637:tid 43777] [client 191.232.199.39:43016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/403.php"] [unique_id "amupKIa8U9lZpWaWlJKE8AAAAAk"]
[Thu Jul 30 14:42:32.069966 2026] [security2:error] [pid 43637:tid 43827] [client 20.63.98.115:1263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amupKIa8U9lZpWaWlJKE8QAAADs"]
[Thu Jul 30 14:42:32.464750 2026] [security2:error] [pid 43637:tid 43780] [client 135.119.63.61:31923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/catalogadmin.php"] [unique_id "amupKIa8U9lZpWaWlJKE_AAAAAw"]
[Thu Jul 30 14:42:32.534700 2026] [security2:error] [pid 43637:tid 43835] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/rip.php"] [unique_id "amupKIa8U9lZpWaWlJKE_QAAAEM"]
[Thu Jul 30 14:42:32.534814 2026] [security2:error] [pid 43637:tid 43835] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/rip.php"] [unique_id "amupKIa8U9lZpWaWlJKE_QAAAEM"]
[Thu Jul 30 14:42:32.567478 2026] [security2:error] [pid 43637:tid 43776] [client 158.158.76.106:1964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/install.php"] [unique_id "amupKIa8U9lZpWaWlJKE_gAAAAg"]
[Thu Jul 30 14:42:32.567582 2026] [security2:error] [pid 43637:tid 43776] [client 158.158.76.106:1964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/install.php"] [unique_id "amupKIa8U9lZpWaWlJKE_gAAAAg"]
[Thu Jul 30 14:42:33.079537 2026] [security2:error] [pid 43637:tid 43841] [client 172.237.109.114:64804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFCwAAAEk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.079571 2026] [security2:error] [pid 43637:tid 43876] [client 172.237.109.114:38234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFCgAAAGw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.080209 2026] [security2:error] [pid 43637:tid 43784] [client 172.237.109.114:7578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFDAAAABA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.081843 2026] [security2:error] [pid 43637:tid 43829] [client 172.237.109.114:31413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFDQAAAD0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.089398 2026] [security2:error] [pid 43637:tid 43854] [client 172.237.109.114:1553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFDgAAAFY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.092844 2026] [security2:error] [pid 43637:tid 43781] [client 172.237.109.114:25582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFEAAAAA0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.092874 2026] [security2:error] [pid 43637:tid 43789] [client 172.237.109.114:57529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFDwAAABU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.093916 2026] [security2:error] [pid 43637:tid 43828] [client 172.237.109.114:17970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFEQAAADw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.094613 2026] [security2:error] [pid 43637:tid 43832] [client 172.237.109.114:1614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFEgAAAEA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.114273 2026] [security2:error] [pid 43637:tid 43852] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/p.php"] [unique_id "amupKYa8U9lZpWaWlJKFEwAAAFQ"]
[Thu Jul 30 14:42:33.114355 2026] [security2:error] [pid 43637:tid 43852] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/p.php"] [unique_id "amupKYa8U9lZpWaWlJKFEwAAAFQ"]
[Thu Jul 30 14:42:33.149218 2026] [security2:error] [pid 43637:tid 43768] [client 172.237.109.114:19517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFFQAAAAA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.149246 2026] [security2:error] [pid 43637:tid 43797] [client 172.237.109.114:2804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFFAAAAB0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:33.166474 2026] [security2:error] [pid 43637:tid 43786] [client 135.119.63.61:17585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/catalogalfa.php"] [unique_id "amupKYa8U9lZpWaWlJKFFgAAABI"]
[Thu Jul 30 14:42:33.643788 2026] [security2:error] [pid 43637:tid 43785] [client 135.119.63.61:34752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/core.php"] [unique_id "amupKYa8U9lZpWaWlJKFIwAAABE"]
[Thu Jul 30 14:42:33.766156 2026] [security2:error] [pid 43637:tid 43794] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.koinjp189.com"] [uri "/php.php"] [unique_id "amupKYa8U9lZpWaWlJKFKAAAABo"]
[Thu Jul 30 14:42:33.766244 2026] [security2:error] [pid 43637:tid 43794] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.koinjp189.com"] [uri "/php.php"] [unique_id "amupKYa8U9lZpWaWlJKFKAAAABo"]
[Thu Jul 30 14:42:33.768767 2026] [security2:error] [pid 43637:tid 43788] [client 191.232.199.39:2922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amupKYa8U9lZpWaWlJKFKQAAABQ"]
[Thu Jul 30 14:42:33.868011 2026] [security2:error] [pid 43637:tid 43824] [client 135.119.63.61:5398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/catalogbypass.php"] [unique_id "amupKYa8U9lZpWaWlJKFMAAAADg"]
[Thu Jul 30 14:42:34.038408 2026] [core:notice] [pid 43637:tid 43812] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:34.078343 2026] [security2:error] [pid 43637:tid 43893] [client 172.237.109.114:33831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKoa8U9lZpWaWlJKFMgAAAH0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:34.078490 2026] [security2:error] [pid 43637:tid 43811] [client 172.237.109.114:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKoa8U9lZpWaWlJKFMwAAACs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:34.089183 2026] [security2:error] [pid 43637:tid 43795] [client 172.237.109.114:47651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKoa8U9lZpWaWlJKFNAAAABs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:34.092636 2026] [security2:error] [pid 43637:tid 43870] [client 172.237.109.114:65419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKoa8U9lZpWaWlJKFNQAAAGY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:34.093461 2026] [security2:error] [pid 43637:tid 43865] [client 172.237.109.114:54310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKoa8U9lZpWaWlJKFNgAAAGE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:34.094184 2026] [security2:error] [pid 43637:tid 43878] [client 172.237.109.114:12560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKoa8U9lZpWaWlJKFNwAAAG4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:34.122841 2026] [security2:error] [pid 43637:tid 43802] [client 172.237.109.114:39324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKoa8U9lZpWaWlJKFOAAAACI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:34.123661 2026] [security2:error] [pid 43637:tid 43884] [client 172.237.109.114:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupKoa8U9lZpWaWlJKFOQAAAHQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:34.144817 2026] [security2:error] [pid 43637:tid 43848] [client 52.238.199.152:56303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/php8.php"] [unique_id "amupKoa8U9lZpWaWlJKFOgAAAFA"]
[Thu Jul 30 14:42:34.221612 2026] [core:notice] [pid 43637:tid 43752] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:34.367205 2026] [security2:error] [pid 43637:tid 43834] [client 158.158.76.106:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/wsx.php"] [unique_id "amupKoa8U9lZpWaWlJKFQgAAAEI"]
[Thu Jul 30 14:42:34.367327 2026] [security2:error] [pid 43637:tid 43834] [client 158.158.76.106:1922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/wsx.php"] [unique_id "amupKoa8U9lZpWaWlJKFQgAAAEI"]
[Thu Jul 30 14:42:34.511168 2026] [core:notice] [pid 43637:tid 43778] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:34.561710 2026] [security2:error] [pid 43637:tid 43774] [client 135.119.63.61:5312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/catalogk.php"] [unique_id "amupKoa8U9lZpWaWlJKFRwAAAAY"]
[Thu Jul 30 14:42:34.699377 2026] [security2:error] [pid 43637:tid 43807] [client 20.63.98.115:1640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-activate.php"] [unique_id "amupKoa8U9lZpWaWlJKFSAAAACc"]
[Thu Jul 30 14:42:34.772350 2026] [security2:error] [pid 43637:tid 43840] [client 177.6.106.101:56358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupKoa8U9lZpWaWlJKFTwAAAEg"]
[Thu Jul 30 14:42:34.772454 2026] [security2:error] [pid 43637:tid 43840] [client 177.6.106.101:56358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupKoa8U9lZpWaWlJKFTwAAAEg"]
[Thu Jul 30 14:42:34.998894 2026] [security2:error] [pid 43637:tid 43828] [client 191.232.199.39:47921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/as.php"] [unique_id "amupKoa8U9lZpWaWlJKFVgAAADw"]
[Thu Jul 30 14:42:35.091043 2026] [proxy:error] [pid 43637:tid 43805] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:35.091125 2026] [proxy_http:error] [pid 43637:tid 43805] [client 18.211.55.47:19072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:35.091761 2026] [proxy:error] [pid 43637:tid 43805] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:35.091808 2026] [proxy_http:error] [pid 43637:tid 43805] [client 18.211.55.47:19072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:35.151413 2026] [security2:error] [pid 43637:tid 43810] [client 172.237.109.114:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupK4a8U9lZpWaWlJKFWQAAACo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:35.330219 2026] [security2:error] [pid 43637:tid 43787] [client 135.119.63.61:31905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/catalogwp.php"] [unique_id "amupK4a8U9lZpWaWlJKFXgAAABM"]
[Thu Jul 30 14:42:35.482279 2026] [security2:error] [pid 43637:tid 43895] [client 52.238.199.152:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/tes.php"] [unique_id "amupK4a8U9lZpWaWlJKFZgAAAH8"]
[Thu Jul 30 14:42:35.617014 2026] [core:notice] [pid 43637:tid 43665] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:35.928020 2026] [security2:error] [pid 43637:tid 43825] [client 135.119.63.61:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/css.php"] [unique_id "amupK4a8U9lZpWaWlJKFdgAAADk"]
[Thu Jul 30 14:42:36.041331 2026] [security2:error] [pid 43637:tid 43808] [client 135.119.63.61:31918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/categories/about.php"] [unique_id "amupLIa8U9lZpWaWlJKFdwAAACg"]
[Thu Jul 30 14:42:36.077111 2026] [core:notice] [pid 43637:tid 43788] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:36.147504 2026] [security2:error] [pid 43637:tid 43640] [remote 47.128.96.191:61722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/issue/view/577"] [unique_id "amupK4a8U9lZpWaWlJKFcgAAYQI"]
[Thu Jul 30 14:42:36.208372 2026] [security2:error] [pid 43637:tid 43848] [client 189.156.226.90:27666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupLIa8U9lZpWaWlJKFeQAAAFA"]
[Thu Jul 30 14:42:36.208492 2026] [security2:error] [pid 43637:tid 43848] [client 189.156.226.90:27666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupLIa8U9lZpWaWlJKFeQAAAFA"]
[Thu Jul 30 14:42:36.222517 2026] [core:notice] [pid 43637:tid 43658] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:36.226449 2026] [security2:error] [pid 43637:tid 43823] [client 47.128.96.191:61722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/issue/view/577"] [unique_id "amupLIa8U9lZpWaWlJKFegAANxQ"], referer: https://www.ejournalugj.com/index.php/tumed/issue/view/577
[Thu Jul 30 14:42:36.430730 2026] [core:notice] [pid 43637:tid 43786] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:36.474621 2026] [core:notice] [pid 43637:tid 43650] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:36.585320 2026] [core:notice] [pid 43637:tid 43668] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:36.585662 2026] [core:notice] [pid 43637:tid 43757] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:36.716603 2026] [security2:error] [pid 43637:tid 43887] [client 191.232.199.39:2904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amupLIa8U9lZpWaWlJKFiwAAAHc"]
[Thu Jul 30 14:42:36.804820 2026] [security2:error] [pid 43637:tid 43852] [client 135.119.63.61:31900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/category.php"] [unique_id "amupLIa8U9lZpWaWlJKFkQAAAFQ"]
[Thu Jul 30 14:42:36.949148 2026] [security2:error] [pid 43637:tid 43835] [client 52.238.199.152:3967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/epinyins.php"] [unique_id "amupLIa8U9lZpWaWlJKFkgAAAEM"]
[Thu Jul 30 14:42:37.010696 2026] [core:notice] [pid 43637:tid 43793] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:37.065996 2026] [security2:error] [pid 43637:tid 43862] [client 52.238.199.152:3695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/about.php"] [unique_id "amupLYa8U9lZpWaWlJKFmgAAAF4"]
[Thu Jul 30 14:42:37.467477 2026] [security2:error] [pid 43637:tid 43779] [client 158.158.76.106:1951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/alfa.php"] [unique_id "amupLYa8U9lZpWaWlJKFqgAAAAs"]
[Thu Jul 30 14:42:37.467575 2026] [security2:error] [pid 43637:tid 43779] [client 158.158.76.106:1951] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/alfa.php"] [unique_id "amupLYa8U9lZpWaWlJKFqgAAAAs"]
[Thu Jul 30 14:42:37.632280 2026] [security2:error] [pid 43637:tid 43836] [client 135.119.63.61:5923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cay-van-phong/filemanager.php"] [unique_id "amupLYa8U9lZpWaWlJKFqwAAAEQ"]
[Thu Jul 30 14:42:37.907747 2026] [proxy:error] [pid 43637:tid 43755] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:37.907801 2026] [proxy_http:error] [pid 43637:tid 43755] [remote 74.7.175.183:58336] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:37.908411 2026] [proxy:error] [pid 43637:tid 43755] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:37.908459 2026] [proxy_http:error] [pid 43637:tid 43755] [remote 74.7.175.183:58336] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:38.069828 2026] [security2:error] [pid 43637:tid 43817] [client 52.238.199.152:3935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.bonafideadvisors.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amupLoa8U9lZpWaWlJKFuwAAADE"]
[Thu Jul 30 14:42:38.405122 2026] [security2:error] [pid 43637:tid 43866] [client 135.119.63.61:5935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cay-van-phong/hehe.php"] [unique_id "amupLoa8U9lZpWaWlJKFwAAAAGI"]
[Thu Jul 30 14:42:38.411893 2026] [security2:error] [pid 43637:tid 43851] [client 191.232.199.39:2386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amupLoa8U9lZpWaWlJKFwQAAAFM"]
[Thu Jul 30 14:42:38.801186 2026] [security2:error] [pid 43637:tid 43883] [client 52.238.199.152:47269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/headers.php"] [unique_id "amupLoa8U9lZpWaWlJKFygAAAHM"]
[Thu Jul 30 14:42:39.158360 2026] [security2:error] [pid 43637:tid 43781] [client 135.119.63.61:5898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cay-van-phong/skibidi.php"] [unique_id "amupL4a8U9lZpWaWlJKF1QAAAA0"]
[Thu Jul 30 14:42:39.696318 2026] [security2:error] [pid 43637:tid 43783] [client 158.158.76.106:1970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/dlu.php"] [unique_id "amupL4a8U9lZpWaWlJKF4gAAAA8"]
[Thu Jul 30 14:42:39.696439 2026] [security2:error] [pid 43637:tid 43783] [client 158.158.76.106:1970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/dlu.php"] [unique_id "amupL4a8U9lZpWaWlJKF4gAAAA8"]
[Thu Jul 30 14:42:39.900436 2026] [security2:error] [pid 43637:tid 43799] [client 135.119.63.61:5940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cbgd.php"] [unique_id "amupL4a8U9lZpWaWlJKF5AAAAB8"]
[Thu Jul 30 14:42:40.503015 2026] [security2:error] [pid 43637:tid 43892] [client 191.232.199.39:2417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/plugins.php"] [unique_id "amupMIa8U9lZpWaWlJKF8wAAAHw"]
[Thu Jul 30 14:42:40.664576 2026] [security2:error] [pid 43637:tid 43891] [client 135.119.63.61:31883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cbrfo.php"] [unique_id "amupMIa8U9lZpWaWlJKF-gAAAHs"]
[Thu Jul 30 14:42:40.734904 2026] [security2:error] [pid 43637:tid 43814] [client 68.67.112.242:52499] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amupMIa8U9lZpWaWlJKF-wAAAC4"]
[Thu Jul 30 14:42:41.388689 2026] [security2:error] [pid 43637:tid 43784] [client 135.119.63.61:51563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cc.php"] [unique_id "amupMYa8U9lZpWaWlJKGDQAAABA"]
[Thu Jul 30 14:42:41.838363 2026] [security2:error] [pid 43637:tid 43856] [client 191.232.199.39:2425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/js/index.php"] [unique_id "amupMYa8U9lZpWaWlJKGGQAAAFg"]
[Thu Jul 30 14:42:42.066195 2026] [security2:error] [pid 43637:tid 43871] [client 64.42.179.59:34278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amupMoa8U9lZpWaWlJKGHQAAAGc"]
[Thu Jul 30 14:42:42.066292 2026] [security2:error] [pid 43637:tid 43871] [client 64.42.179.59:34278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amupMoa8U9lZpWaWlJKGHQAAAGc"]
[Thu Jul 30 14:42:42.138815 2026] [security2:error] [pid 43637:tid 43809] [client 135.119.63.61:31385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ccaef.php"] [unique_id "amupMoa8U9lZpWaWlJKGIQAAACk"]
[Thu Jul 30 14:42:42.377164 2026] [security2:error] [pid 43637:tid 43776] [client 20.63.98.115:54209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-file.php"] [unique_id "amupMoa8U9lZpWaWlJKGJgAAAAg"]
[Thu Jul 30 14:42:42.564099 2026] [security2:error] [pid 43637:tid 43862] [client 52.238.199.152:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/admin.php"] [unique_id "amupMoa8U9lZpWaWlJKGJwAAAF4"]
[Thu Jul 30 14:42:42.627626 2026] [security2:error] [pid 43637:tid 43818] [client 135.119.63.61:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/database.php"] [unique_id "amupMoa8U9lZpWaWlJKGKwAAADI"]
[Thu Jul 30 14:42:42.978659 2026] [security2:error] [pid 43637:tid 43824] [client 135.119.63.61:31402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ccx/index.php"] [unique_id "amupMoa8U9lZpWaWlJKGMwAAADg"]
[Thu Jul 30 14:42:43.125130 2026] [security2:error] [pid 43637:tid 43802] [client 158.158.76.106:1244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/f6.php"] [unique_id "amupM4a8U9lZpWaWlJKGNwAAACI"]
[Thu Jul 30 14:42:43.125229 2026] [security2:error] [pid 43637:tid 43802] [client 158.158.76.106:1244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/f6.php"] [unique_id "amupM4a8U9lZpWaWlJKGNwAAACI"]
[Thu Jul 30 14:42:43.436313 2026] [security2:error] [pid 43637:tid 43788] [client 191.232.199.39:2483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/go.php"] [unique_id "amupM4a8U9lZpWaWlJKGQAAAABQ"]
[Thu Jul 30 14:42:43.521067 2026] [security2:error] [pid 43637:tid 43786] [client 20.63.98.115:49833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/12.php"] [unique_id "amupM4a8U9lZpWaWlJKGQQAAABI"]
[Thu Jul 30 14:42:43.688778 2026] [security2:error] [pid 43637:tid 43848] [client 135.119.63.61:5936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cd.php"] [unique_id "amupM4a8U9lZpWaWlJKGRQAAAFA"]
[Thu Jul 30 14:42:44.516195 2026] [security2:error] [pid 43637:tid 43822] [client 135.119.63.61:31408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cdxadmin.php"] [unique_id "amupNIa8U9lZpWaWlJKGWwAAADY"]
[Thu Jul 30 14:42:44.650993 2026] [security2:error] [pid 43637:tid 43846] [client 191.232.199.39:2404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/test1.php"] [unique_id "amupNIa8U9lZpWaWlJKGXQAAAE4"]
[Thu Jul 30 14:42:44.852516 2026] [security2:error] [pid 43637:tid 43847] [client 135.119.63.61:34813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/db.php"] [unique_id "amupNIa8U9lZpWaWlJKGagAAAE8"]
[Thu Jul 30 14:42:44.910469 2026] [security2:error] [pid 43637:tid 43889] [client 20.63.98.115:54268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/epinyins.php"] [unique_id "amupNIa8U9lZpWaWlJKGawAAAHk"]
[Thu Jul 30 14:42:45.265302 2026] [security2:error] [pid 43637:tid 43877] [client 135.119.63.61:5387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cekidot/alf.php"] [unique_id "amupNYa8U9lZpWaWlJKGdQAAAG0"]
[Thu Jul 30 14:42:46.053837 2026] [security2:error] [pid 43637:tid 43829] [client 135.119.63.61:5906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cekidot/mar.php"] [unique_id "amupNoa8U9lZpWaWlJKGhQAAAD0"]
[Thu Jul 30 14:42:46.184816 2026] [security2:error] [pid 43637:tid 43799] [client 52.238.199.152:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/flower.php"] [unique_id "amupNoa8U9lZpWaWlJKGhgAAAB8"]
[Thu Jul 30 14:42:46.378990 2026] [security2:error] [pid 43637:tid 43826] [client 191.232.199.39:2478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/images/index.php"] [unique_id "amupNoa8U9lZpWaWlJKGkQAAADo"]
[Thu Jul 30 14:42:46.629174 2026] [security2:error] [pid 43637:tid 43822] [client 158.158.76.106:1966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/0x.php"] [unique_id "amupNoa8U9lZpWaWlJKGkgAAADY"]
[Thu Jul 30 14:42:46.629290 2026] [security2:error] [pid 43637:tid 43822] [client 158.158.76.106:1966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/0x.php"] [unique_id "amupNoa8U9lZpWaWlJKGkgAAADY"]
[Thu Jul 30 14:42:46.786010 2026] [security2:error] [pid 43637:tid 43804] [client 189.156.226.90:26953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupNoa8U9lZpWaWlJKGlgAAACQ"]
[Thu Jul 30 14:42:46.786128 2026] [security2:error] [pid 43637:tid 43804] [client 189.156.226.90:26953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupNoa8U9lZpWaWlJKGlgAAACQ"]
[Thu Jul 30 14:42:46.813957 2026] [security2:error] [pid 43637:tid 43810] [client 135.119.63.61:5911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cekidot/mr.php"] [unique_id "amupNoa8U9lZpWaWlJKGlwAAACo"]
[Thu Jul 30 14:42:47.003212 2026] [security2:error] [pid 43637:tid 43745] [remote 57.141.0.37:65220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amupN4a8U9lZpWaWlJKGngAAQWs"]
[Thu Jul 30 14:42:47.164344 2026] [security2:error] [pid 43637:tid 43796] [client 52.238.199.152:3676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amupN4a8U9lZpWaWlJKGoAAAABw"]
[Thu Jul 30 14:42:47.631173 2026] [security2:error] [pid 43637:tid 43808] [client 135.119.63.61:5312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cepair/doc.php"] [unique_id "amupN4a8U9lZpWaWlJKGsAAAACg"]
[Thu Jul 30 14:42:48.084111 2026] [security2:error] [pid 43637:tid 43853] [client 191.232.199.39:2399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/asd.php"] [unique_id "amupOIa8U9lZpWaWlJKGvAAAAFU"]
[Thu Jul 30 14:42:48.138471 2026] [security2:error] [pid 43637:tid 43842] [client 88.99.80.227:43804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amupOIa8U9lZpWaWlJKGvQAAAEo"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:42:48.165869 2026] [security2:error] [pid 43637:tid 43889] [client 135.119.63.61:34808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/default.php"] [unique_id "amupOIa8U9lZpWaWlJKGvgAAAHk"]
[Thu Jul 30 14:42:48.303032 2026] [security2:error] [pid 43637:tid 43851] [client 52.238.199.152:47278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content.php"] [unique_id "amupOIa8U9lZpWaWlJKGwAAAAFM"]
[Thu Jul 30 14:42:48.485738 2026] [security2:error] [pid 43637:tid 43799] [client 135.119.63.61:31363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/certificates/plugins.php"] [unique_id "amupOIa8U9lZpWaWlJKGyAAAAB8"]
[Thu Jul 30 14:42:48.501292 2026] [core:notice] [pid 43637:tid 43850] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:48.505508 2026] [security2:error] [pid 43637:tid 43850] [client 88.99.80.227:43806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amupOIa8U9lZpWaWlJKGywAAAFI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:42:48.901727 2026] [security2:error] [pid 43637:tid 43822] [client 88.99.80.227:43812] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amupOIa8U9lZpWaWlJKG1QAAADY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:42:49.106358 2026] [security2:error] [pid 43637:tid 43811] [client 158.158.76.106:1555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/geck.php"] [unique_id "amupOYa8U9lZpWaWlJKG3wAAACs"]
[Thu Jul 30 14:42:49.106505 2026] [security2:error] [pid 43637:tid 43811] [client 158.158.76.106:1555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/geck.php"] [unique_id "amupOYa8U9lZpWaWlJKG3wAAACs"]
[Thu Jul 30 14:42:49.361100 2026] [security2:error] [pid 43637:tid 43796] [client 135.119.63.61:5948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cf.php"] [unique_id "amupOYa8U9lZpWaWlJKG4gAAABw"]
[Thu Jul 30 14:42:49.553738 2026] [security2:error] [pid 43637:tid 43771] [client 52.238.199.152:53232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/function.php"] [unique_id "amupOYa8U9lZpWaWlJKG7QAAAAM"]
[Thu Jul 30 14:42:49.668134 2026] [security2:error] [pid 43637:tid 43795] [client 191.232.199.39:2447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amupOYa8U9lZpWaWlJKG7wAAABs"]
[Thu Jul 30 14:42:49.754399 2026] [security2:error] [pid 43637:tid 43868] [client 135.119.63.61:35714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/dropdown.php"] [unique_id "amupOYa8U9lZpWaWlJKG8AAAAGQ"]
[Thu Jul 30 14:42:50.190308 2026] [security2:error] [pid 43637:tid 43879] [client 20.63.98.115:1139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amupOoa8U9lZpWaWlJKHAgAAAG8"]
[Thu Jul 30 14:42:50.207343 2026] [security2:error] [pid 43637:tid 43841] [client 135.119.63.61:31384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cfile.php"] [unique_id "amupOoa8U9lZpWaWlJKHAwAAAEk"]
[Thu Jul 30 14:42:50.564851 2026] [core:notice] [pid 43637:tid 43865] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:50.833223 2026] [core:notice] [pid 43637:tid 43744] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:50.907135 2026] [security2:error] [pid 43637:tid 43793] [client 135.119.63.61:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/edit.php"] [unique_id "amupOoa8U9lZpWaWlJKHHgAAABk"]
[Thu Jul 30 14:42:51.076851 2026] [security2:error] [pid 43637:tid 43857] [client 135.119.63.61:17536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cgi-binadmin.php"] [unique_id "amupO4a8U9lZpWaWlJKHKAAAAFk"]
[Thu Jul 30 14:42:51.281930 2026] [security2:error] [pid 43637:tid 43824] [client 20.63.98.115:1148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/system_log.php"] [unique_id "amupO4a8U9lZpWaWlJKHLQAAADg"]
[Thu Jul 30 14:42:51.324455 2026] [security2:error] [pid 43637:tid 43755] [remote 192.250.227.149:35734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.227.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-eea484b2.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amupO4a8U9lZpWaWlJKHLgAAMXU"]
[Thu Jul 30 14:42:51.341115 2026] [core:notice] [pid 43637:tid 43874] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:51.460577 2026] [security2:error] [pid 43637:tid 43863] [client 74.7.230.37:43958] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.abudhabifurnituremoverspackers.com"] [uri "/robots.txt"] [unique_id "amupO4a8U9lZpWaWlJKHMwAAAF8"]
[Thu Jul 30 14:42:51.829493 2026] [security2:error] [pid 43637:tid 43805] [client 158.158.76.106:1961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amupO4a8U9lZpWaWlJKHQAAAACU"]
[Thu Jul 30 14:42:51.829595 2026] [security2:error] [pid 43637:tid 43805] [client 158.158.76.106:1961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/8.php"] [unique_id "amupO4a8U9lZpWaWlJKHQAAAACU"]
[Thu Jul 30 14:42:51.852289 2026] [security2:error] [pid 43637:tid 43687] [remote 97.74.93.24:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/wp-login.php"] [unique_id "amupO4a8U9lZpWaWlJKHQgAAWzE"]
[Thu Jul 30 14:42:51.896618 2026] [security2:error] [pid 43637:tid 43875] [client 135.119.63.61:5912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cgi-binalfa.php"] [unique_id "amupO4a8U9lZpWaWlJKHSQAAAGs"]
[Thu Jul 30 14:42:51.934686 2026] [security2:error] [pid 43637:tid 43816] [client 191.232.199.39:2414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amupO4a8U9lZpWaWlJKHSgAAADA"]
[Thu Jul 30 14:42:52.252096 2026] [security2:error] [pid 43637:tid 43881] [client 20.63.98.115:11070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amupPIa8U9lZpWaWlJKHWAAAAHE"]
[Thu Jul 30 14:42:52.322231 2026] [security2:error] [pid 43637:tid 43835] [client 52.238.199.152:3686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/chosen.php"] [unique_id "amupPIa8U9lZpWaWlJKHWQAAAEM"]
[Thu Jul 30 14:42:52.331036 2026] [security2:error] [pid 43637:tid 43888] [client 135.119.63.61:34811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/f35.php"] [unique_id "amupPIa8U9lZpWaWlJKHWgAAAHg"]
[Thu Jul 30 14:42:52.373500 2026] [core:notice] [pid 43637:tid 43793] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:52.729253 2026] [security2:error] [pid 43637:tid 43834] [client 135.119.63.61:31386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cgi-binbypass.php"] [unique_id "amupPIa8U9lZpWaWlJKHZgAAAEI"]
[Thu Jul 30 14:42:53.228877 2026] [security2:error] [pid 43637:tid 43868] [client 52.238.199.152:37170] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "arabian-tours.com"] [uri "/1.php"] [unique_id "amupPYa8U9lZpWaWlJKHcgAAAGQ"]
[Thu Jul 30 14:42:53.229012 2026] [security2:error] [pid 43637:tid 43868] [client 52.238.199.152:37170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/1.php"] [unique_id "amupPYa8U9lZpWaWlJKHcgAAAGQ"]
[Thu Jul 30 14:42:53.368210 2026] [security2:error] [pid 43637:tid 43788] [client 191.232.199.39:48988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/atomlib.php"] [unique_id "amupPYa8U9lZpWaWlJKHdwAAABQ"]
[Thu Jul 30 14:42:53.442547 2026] [security2:error] [pid 43637:tid 43782] [client 135.119.63.61:35735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themushroom.online"] [uri "/f7.php"] [unique_id "amupPYa8U9lZpWaWlJKHeAAAAA4"]
[Thu Jul 30 14:42:53.443867 2026] [security2:error] [pid 43637:tid 43693] [remote 57.141.0.26:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amupPYa8U9lZpWaWlJKHeQAARTc"]
[Thu Jul 30 14:42:53.501232 2026] [security2:error] [pid 43637:tid 43842] [client 135.119.63.61:17590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cgi-bink.php"] [unique_id "amupPYa8U9lZpWaWlJKHfAAAAEo"]
[Thu Jul 30 14:42:53.524849 2026] [security2:error] [pid 43637:tid 43848] [client 20.63.98.115:11099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ini.php"] [unique_id "amupPYa8U9lZpWaWlJKHfgAAAFA"]
[Thu Jul 30 14:42:53.563999 2026] [security2:error] [pid 43637:tid 43873] [client 57.141.0.48:53158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amupPYa8U9lZpWaWlJKHcwAAaXQ"], referer: https://igetvape-australia.com/product-tag/alibarbar-ingot-wtf-grapefruit-9000-puffs/
[Thu Jul 30 14:42:54.334789 2026] [security2:error] [pid 43637:tid 43780] [client 172.237.109.114:56246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHjAAAAAw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.348241 2026] [security2:error] [pid 43637:tid 43871] [client 172.237.109.114:43041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHjgAAAGc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.348430 2026] [security2:error] [pid 43637:tid 43799] [client 172.237.109.114:28477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHjwAAAB8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.351676 2026] [security2:error] [pid 43637:tid 43773] [client 172.237.109.114:64776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHjQAAAAU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.360787 2026] [security2:error] [pid 43637:tid 43792] [client 172.237.109.114:43103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHkQAAABg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.362212 2026] [security2:error] [pid 43637:tid 43860] [client 172.237.109.114:63052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHkAAAAFw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.366177 2026] [security2:error] [pid 43637:tid 43787] [client 172.237.109.114:28692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHkgAAABM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.396942 2026] [security2:error] [pid 43637:tid 43887] [client 172.237.109.114:31988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHlQAAAHc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.407893 2026] [security2:error] [pid 43637:tid 43821] [client 172.237.109.114:6404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHlAAAADU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.408780 2026] [security2:error] [pid 43637:tid 43777] [client 172.237.109.114:31912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHlgAAAAk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.409269 2026] [security2:error] [pid 43637:tid 43840] [client 172.237.109.114:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupPoa8U9lZpWaWlJKHkwAAAEg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:54.516886 2026] [security2:error] [pid 43637:tid 43895] [client 52.238.199.152:36695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/lv.php"] [unique_id "amupPoa8U9lZpWaWlJKHnAAAAH8"]
[Thu Jul 30 14:42:54.954724 2026] [core:notice] [pid 43637:tid 43708] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:54.958279 2026] [security2:error] [pid 43637:tid 43893] [client 170.83.178.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/view/244/index.php/JIPKL/guide"] [unique_id "amupPoa8U9lZpWaWlJKHowAAfUY"]
[Thu Jul 30 14:42:55.079364 2026] [security2:error] [pid 43637:tid 43855] [client 172.237.109.114:61926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupP4a8U9lZpWaWlJKHqQAAAFc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:55.080614 2026] [security2:error] [pid 43637:tid 43863] [client 172.237.109.114:33500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupP4a8U9lZpWaWlJKHqgAAAF8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:55.088298 2026] [security2:error] [pid 43637:tid 43858] [client 172.237.109.114:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupP4a8U9lZpWaWlJKHqwAAAFo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:55.103254 2026] [security2:error] [pid 43637:tid 43876] [client 172.237.109.114:11459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupP4a8U9lZpWaWlJKHrgAAAGw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:55.125182 2026] [security2:error] [pid 43637:tid 43866] [client 172.237.109.114:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupP4a8U9lZpWaWlJKHsAAAAGI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:55.125293 2026] [security2:error] [pid 43637:tid 43862] [client 172.237.109.114:48161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupP4a8U9lZpWaWlJKHsQAAAF4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:55.149741 2026] [security2:error] [pid 43637:tid 43806] [client 172.237.109.114:7539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupP4a8U9lZpWaWlJKHsgAAACY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:55.151522 2026] [security2:error] [pid 43637:tid 43882] [client 172.237.109.114:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupP4a8U9lZpWaWlJKHswAAAHI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:55.442756 2026] [security2:error] [pid 43637:tid 43853] [client 52.238.199.152:59964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/css.php"] [unique_id "amupP4a8U9lZpWaWlJKHvgAAAFU"]
[Thu Jul 30 14:42:55.604276 2026] [security2:error] [pid 43637:tid 43885] [client 191.232.199.39:2918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amupP4a8U9lZpWaWlJKHwAAAAHU"]
[Thu Jul 30 14:42:55.916191 2026] [security2:error] [pid 43637:tid 43846] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupP4a8U9lZpWaWlJKHvQAAAE4"]
[Thu Jul 30 14:42:56.075251 2026] [security2:error] [pid 43637:tid 43814] [client 158.158.76.106:1960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/133.php"] [unique_id "amupQIa8U9lZpWaWlJKHzAAAAC4"]
[Thu Jul 30 14:42:56.075401 2026] [security2:error] [pid 43637:tid 43814] [client 158.158.76.106:1960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/133.php"] [unique_id "amupQIa8U9lZpWaWlJKHzAAAAC4"]
[Thu Jul 30 14:42:56.147147 2026] [security2:error] [pid 43637:tid 43822] [client 172.237.109.114:57163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupQIa8U9lZpWaWlJKHzgAAADY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:42:56.419543 2026] [core:notice] [pid 43637:tid 43715] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:42:56.609288 2026] [security2:error] [pid 43637:tid 43774] [client 52.238.199.152:59919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/gecko.php"] [unique_id "amupQIa8U9lZpWaWlJKH3wAAAAY"]
[Thu Jul 30 14:42:57.004246 2026] [security2:error] [pid 43637:tid 43809] [client 177.6.106.101:54906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupQIa8U9lZpWaWlJKH7AAAACk"]
[Thu Jul 30 14:42:57.004402 2026] [security2:error] [pid 43637:tid 43809] [client 177.6.106.101:54906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupQIa8U9lZpWaWlJKH7AAAACk"]
[Thu Jul 30 14:42:57.015672 2026] [security2:error] [pid 43637:tid 43868] [client 57.141.0.32:59770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amupQIa8U9lZpWaWlJKH4wAAZAY"], referer: https://igetvape-australia.com/product/alibarbar-rich-8000-puffs/
[Thu Jul 30 14:42:57.121252 2026] [security2:error] [pid 43637:tid 43870] [client 20.63.98.115:48522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ok.php"] [unique_id "amupQYa8U9lZpWaWlJKH7QAAAGY"]
[Thu Jul 30 14:42:57.320174 2026] [security2:error] [pid 43637:tid 43812] [client 189.156.226.90:27243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupQYa8U9lZpWaWlJKH-AAAACw"]
[Thu Jul 30 14:42:57.320332 2026] [security2:error] [pid 43637:tid 43812] [client 189.156.226.90:27243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupQYa8U9lZpWaWlJKH-AAAACw"]
[Thu Jul 30 14:42:57.466671 2026] [autoindex:error] [pid 43637:tid 43833] [client 62.141.44.236:36112] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:42:58.208646 2026] [security2:error] [pid 43637:tid 43818] [client 52.238.199.152:53216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/xmlrpc.php"] [unique_id "amupQYa8U9lZpWaWlJKIFAAAADI"]
[Thu Jul 30 14:42:58.248879 2026] [security2:error] [pid 43637:tid 43875] [client 191.232.199.39:47877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/inputs.php"] [unique_id "amupQoa8U9lZpWaWlJKIKAAAAGs"]
[Thu Jul 30 14:42:59.289158 2026] [proxy:error] [pid 43637:tid 43813] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:59.289239 2026] [proxy_http:error] [pid 43637:tid 43813] [client 54.87.222.253:10494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:59.289821 2026] [proxy:error] [pid 43637:tid 43813] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:42:59.289862 2026] [proxy_http:error] [pid 43637:tid 43813] [client 54.87.222.253:10494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:42:59.480406 2026] [security2:error] [pid 43637:tid 43814] [client 52.238.199.152:33766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/f35.php"] [unique_id "amupQ4a8U9lZpWaWlJKITAAAAC4"]
[Thu Jul 30 14:42:59.721509 2026] [security2:error] [pid 43637:tid 43855] [client 191.232.199.39:2405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/index.php"] [unique_id "amupQ4a8U9lZpWaWlJKITQAAAFc"]
[Thu Jul 30 14:43:00.526163 2026] [security2:error] [pid 43637:tid 43807] [client 52.238.199.152:3604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/autoload_classmap.php"] [unique_id "amupRIa8U9lZpWaWlJKIYAAAACc"]
[Thu Jul 30 14:43:00.673812 2026] [security2:error] [pid 43637:tid 43789] [client 216.73.216.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.investigations.worldofwhiskers.com"] [uri "/index.php"] [unique_id "amupQ4a8U9lZpWaWlJKISAAAFVI"]
[Thu Jul 30 14:43:00.988184 2026] [security2:error] [pid 43637:tid 43853] [client 191.232.199.39:2381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/network/index.php"] [unique_id "amupRIa8U9lZpWaWlJKIaQAAAFU"]
[Thu Jul 30 14:43:01.091897 2026] [autoindex:error] [pid 43637:tid 43780] [client 52.202.41.153:39259] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:43:02.390606 2026] [security2:error] [pid 43637:tid 43845] [client 191.232.199.39:2491] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kendarikomputer.com"] [uri "/wp-content/1.php"] [unique_id "amupRoa8U9lZpWaWlJKIgQAAAE0"]
[Thu Jul 30 14:43:02.390740 2026] [security2:error] [pid 43637:tid 43845] [client 191.232.199.39:2491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/1.php"] [unique_id "amupRoa8U9lZpWaWlJKIgQAAAE0"]
[Thu Jul 30 14:43:02.408810 2026] [security2:error] [pid 43637:tid 43833] [client 52.238.199.152:3666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/NewFile.php"] [unique_id "amupRoa8U9lZpWaWlJKIggAAAEE"]
[Thu Jul 30 14:43:02.439959 2026] [security2:error] [pid 43637:tid 43732] [remote 173.231.241.109:38212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.241.231.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-aa23bb9f.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amupRoa8U9lZpWaWlJKIgwAAFF4"]
[Thu Jul 30 14:43:02.727599 2026] [security2:error] [pid 43637:tid 43802] [client 144.76.19.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amupRoa8U9lZpWaWlJKIjAAAACI"]
[Thu Jul 30 14:43:03.210072 2026] [security2:error] [pid 43637:tid 43726] [remote 152.53.37.129:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.37.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amupR4a8U9lZpWaWlJKIlgAAOlg"]
[Thu Jul 30 14:43:03.210266 2026] [security2:error] [pid 43637:tid 43826] [client 152.53.37.129:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "madeninsabah.com"] [uri "/xmlrpc.php"] [unique_id "amupR4a8U9lZpWaWlJKIlgAAOlg"]
[Thu Jul 30 14:43:03.379873 2026] [security2:error] [pid 43637:tid 43818] [client 52.238.199.152:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/xx.php"] [unique_id "amupR4a8U9lZpWaWlJKInQAAADI"]
[Thu Jul 30 14:43:04.377906 2026] [security2:error] [pid 43637:tid 43871] [client 158.158.76.106:1246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/11.php"] [unique_id "amupSIa8U9lZpWaWlJKIsAAAAGc"]
[Thu Jul 30 14:43:04.378035 2026] [security2:error] [pid 43637:tid 43871] [client 158.158.76.106:1246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/11.php"] [unique_id "amupSIa8U9lZpWaWlJKIsAAAAGc"]
[Thu Jul 30 14:43:04.775818 2026] [security2:error] [pid 43637:tid 43873] [client 191.232.199.39:2477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/plugin.php"] [unique_id "amupSIa8U9lZpWaWlJKIugAAAGk"]
[Thu Jul 30 14:43:05.133003 2026] [security2:error] [pid 43637:tid 43856] [client 185.191.171.11:18236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/05/messi-perdera-viagem-do-psg-a-lorient-com-lesao-no-tendao-de-aquiles/"] [unique_id "amupSYa8U9lZpWaWlJKIwwAAAFg"]
[Thu Jul 30 14:43:05.133118 2026] [security2:error] [pid 43637:tid 43856] [client 185.191.171.11:18236] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/05/messi-perdera-viagem-do-psg-a-lorient-com-lesao-no-tendao-de-aquiles/"] [unique_id "amupSYa8U9lZpWaWlJKIwwAAAFg"]
[Thu Jul 30 14:43:05.363097 2026] [core:notice] [pid 43637:tid 43668] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:05.846961 2026] [security2:error] [pid 43637:tid 43762] [remote 57.141.0.61:41670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amupSYa8U9lZpWaWlJKI1AAAWns"]
[Thu Jul 30 14:43:06.082597 2026] [security2:error] [pid 43637:tid 43749] [remote 57.141.0.19:47080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amupSoa8U9lZpWaWlJKI2QAAJG8"]
[Thu Jul 30 14:43:06.231687 2026] [security2:error] [pid 43637:tid 43867] [client 191.232.199.39:45993] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "kendarikomputer.com"] [uri "/1.php"] [unique_id "amupSoa8U9lZpWaWlJKI4AAAAGM"]
[Thu Jul 30 14:43:06.231809 2026] [security2:error] [pid 43637:tid 43867] [client 191.232.199.39:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/1.php"] [unique_id "amupSoa8U9lZpWaWlJKI4AAAAGM"]
[Thu Jul 30 14:43:06.337676 2026] [security2:error] [pid 43637:tid 43753] [remote 57.141.0.28:35248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amupSoa8U9lZpWaWlJKI1wAADXM"], referer: https://igetvape-australia.com/product-category/iget-hot/?add-to-cart=197
[Thu Jul 30 14:43:06.626769 2026] [security2:error] [pid 43637:tid 43797] [client 52.238.199.152:58869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/plugins.php"] [unique_id "amupSoa8U9lZpWaWlJKI8gAAAB0"]
[Thu Jul 30 14:43:06.674442 2026] [security2:error] [pid 43637:tid 43810] [client 216.73.216.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.investigations.worldofwhiskers.com"] [uri "/index.php"] [unique_id "amupSoa8U9lZpWaWlJKI7AAAKn0"]
[Thu Jul 30 14:43:07.213369 2026] [core:notice] [pid 43637:tid 43689] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:07.411406 2026] [security2:error] [pid 43637:tid 43892] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupSoa8U9lZpWaWlJKI-AAAAHw"]
[Thu Jul 30 14:43:07.844930 2026] [security2:error] [pid 43637:tid 43771] [client 189.156.226.90:27549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupS4a8U9lZpWaWlJKJFAAAAAM"]
[Thu Jul 30 14:43:07.845061 2026] [security2:error] [pid 43637:tid 43771] [client 189.156.226.90:27549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupS4a8U9lZpWaWlJKJFAAAAAM"]
[Thu Jul 30 14:43:08.005337 2026] [security2:error] [pid 43637:tid 43880] [client 191.232.199.39:2371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/gg.php"] [unique_id "amupTIa8U9lZpWaWlJKJGgAAAHA"]
[Thu Jul 30 14:43:09.454652 2026] [security2:error] [pid 43637:tid 43854] [client 172.237.109.114:56901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amupTIa8U9lZpWaWlJKJNgAAAFY"]
[Thu Jul 30 14:43:09.775143 2026] [security2:error] [pid 43637:tid 43845] [client 191.232.199.39:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp.php"] [unique_id "amupTYa8U9lZpWaWlJKJTwAAAE0"]
[Thu Jul 30 14:43:09.996836 2026] [security2:error] [pid 43637:tid 43793] [client 52.238.199.152:33738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/xxx.php"] [unique_id "amupTYa8U9lZpWaWlJKJVwAAABk"]
[Thu Jul 30 14:43:10.645610 2026] [security2:error] [pid 43637:tid 43806] [client 158.158.76.106:1225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/3.php"] [unique_id "amupToa8U9lZpWaWlJKJaAAAACY"]
[Thu Jul 30 14:43:10.645764 2026] [security2:error] [pid 43637:tid 43806] [client 158.158.76.106:1225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "_dc-mx.26905cb6b084.prestigemassagestudio.cfd"] [uri "/3.php"] [unique_id "amupToa8U9lZpWaWlJKJaAAAACY"]
[Thu Jul 30 14:43:11.187444 2026] [core:notice] [pid 43637:tid 43719] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:11.241398 2026] [security2:error] [pid 43637:tid 43811] [client 191.232.199.39:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amupT4a8U9lZpWaWlJKJdwAAACs"]
[Thu Jul 30 14:43:11.581666 2026] [security2:error] [pid 43637:tid 43671] [remote 74.7.243.224:52014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amupT4a8U9lZpWaWlJKJfgAAViE"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:43:11.686055 2026] [core:notice] [pid 43637:tid 43770] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:12.676363 2026] [security2:error] [pid 43637:tid 43772] [client 52.238.199.152:53219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/css.php"] [unique_id "amupUIa8U9lZpWaWlJKJlAAAAAQ"]
[Thu Jul 30 14:43:12.779587 2026] [core:notice] [pid 43637:tid 43745] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:12.808753 2026] [security2:error] [pid 43637:tid 43843] [client 191.232.199.39:2488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/file.php"] [unique_id "amupUIa8U9lZpWaWlJKJmgAAAEs"]
[Thu Jul 30 14:43:12.931025 2026] [core:notice] [pid 43637:tid 43734] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:13.068049 2026] [core:error] [pid 43637:tid 43659] [remote 216.73.216.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:43:13.068070 2026] [core:error] [pid 43637:tid 43659] [remote 216.73.216.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:43:13.224770 2026] [core:notice] [pid 43637:tid 43653] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:13.344549 2026] [core:notice] [pid 43637:tid 43747] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:13.690228 2026] [core:error] [pid 43637:tid 43742] [remote 216.73.216.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:43:13.690251 2026] [core:error] [pid 43637:tid 43742] [remote 216.73.216.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:43:14.018714 2026] [security2:error] [pid 43637:tid 43797] [client 52.238.199.152:33739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amupUoa8U9lZpWaWlJKJxwAAAB0"]
[Thu Jul 30 14:43:14.079505 2026] [security2:error] [pid 43637:tid 43796] [client 172.237.109.114:11283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJywAAABw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.089484 2026] [security2:error] [pid 43637:tid 43888] [client 172.237.109.114:47969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJzAAAAHg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.091582 2026] [security2:error] [pid 43637:tid 43881] [client 172.237.109.114:45126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJzQAAAHE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.102281 2026] [security2:error] [pid 43637:tid 43877] [client 172.237.109.114:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJzgAAAG0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.103238 2026] [security2:error] [pid 43637:tid 43846] [client 172.237.109.114:1440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJzwAAAE4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.120302 2026] [security2:error] [pid 43637:tid 43860] [client 172.237.109.114:20162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJ0AAAAFw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.121603 2026] [security2:error] [pid 43637:tid 43889] [client 172.237.109.114:12532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJ0QAAAHk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.123518 2026] [security2:error] [pid 43637:tid 43847] [client 172.237.109.114:60263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJ0gAAAE8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.124492 2026] [security2:error] [pid 43637:tid 43778] [client 172.237.109.114:23885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJ0wAAAAo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.148649 2026] [security2:error] [pid 43637:tid 43776] [client 172.237.109.114:43428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupUoa8U9lZpWaWlJKJ1AAAAAg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:14.175514 2026] [security2:error] [pid 43637:tid 43779] [client 82.102.18.188:35864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.iop.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amupUoa8U9lZpWaWlJKJ1QAAAAs"]
[Thu Jul 30 14:43:14.175623 2026] [security2:error] [pid 43637:tid 43779] [client 82.102.18.188:35864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.iop.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amupUoa8U9lZpWaWlJKJ1QAAAAs"]
[Thu Jul 30 14:43:14.231929 2026] [security2:error] [pid 43637:tid 43857] [client 177.6.106.101:57207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupUoa8U9lZpWaWlJKJ1gAAAFk"]
[Thu Jul 30 14:43:14.232049 2026] [security2:error] [pid 43637:tid 43857] [client 177.6.106.101:57207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupUoa8U9lZpWaWlJKJ1gAAAFk"]
[Thu Jul 30 14:43:14.597175 2026] [security2:error] [pid 43637:tid 43824] [client 191.232.199.39:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/user/index.php"] [unique_id "amupUoa8U9lZpWaWlJKJ4wAAADg"]
[Thu Jul 30 14:43:15.075331 2026] [security2:error] [pid 43637:tid 43657] [remote 47.128.27.82:13642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/fendi-jacket-tan/"] [unique_id "amupU4a8U9lZpWaWlJKJ7QAAGhM"]
[Thu Jul 30 14:43:15.078201 2026] [security2:error] [pid 43637:tid 43852] [client 172.237.109.114:46508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupU4a8U9lZpWaWlJKJ7gAAAFQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:15.079472 2026] [security2:error] [pid 43637:tid 43807] [client 172.237.109.114:4665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupU4a8U9lZpWaWlJKJ7wAAACc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:15.090814 2026] [security2:error] [pid 43637:tid 43789] [client 172.237.109.114:51722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupU4a8U9lZpWaWlJKJ8AAAABU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:15.092056 2026] [security2:error] [pid 43637:tid 43783] [client 172.237.109.114:2210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupU4a8U9lZpWaWlJKJ8QAAAA8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:15.093608 2026] [security2:error] [pid 43637:tid 43886] [client 172.237.109.114:25085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupU4a8U9lZpWaWlJKJ8gAAAHY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:15.093854 2026] [security2:error] [pid 43637:tid 43836] [client 172.237.109.114:29357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupU4a8U9lZpWaWlJKJ8wAAAEQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:15.101924 2026] [security2:error] [pid 43637:tid 43841] [client 172.237.109.114:56418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupU4a8U9lZpWaWlJKJ9AAAAEk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:15.121403 2026] [security2:error] [pid 43637:tid 43867] [client 172.237.109.114:33256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupU4a8U9lZpWaWlJKJ9QAAAGM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:15.123837 2026] [security2:error] [pid 43637:tid 43880] [client 172.237.109.114:24999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupU4a8U9lZpWaWlJKJ9gAAAHA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:15.304676 2026] [security2:error] [pid 43637:tid 43885] [client 127.0.0.1:27790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amupU4a8U9lZpWaWlJKJ-AAAAHU"]
[Thu Jul 30 14:43:15.304699 2026] [security2:error] [pid 43637:tid 43868] [client 74.7.230.25:43862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ais.njr.temporary.site"] [uri "/robots.txt"] [unique_id "amupU4a8U9lZpWaWlJKJ9wAAAGQ"]
[Thu Jul 30 14:43:16.283572 2026] [security2:error] [pid 43637:tid 43772] [client 20.226.5.174:31949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/yanznopat.php"] [unique_id "amupVIa8U9lZpWaWlJKKDgAAAAQ"]
[Thu Jul 30 14:43:16.310021 2026] [security2:error] [pid 43637:tid 43808] [client 191.232.199.39:2402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amupVIa8U9lZpWaWlJKKDwAAACg"]
[Thu Jul 30 14:43:17.079126 2026] [security2:error] [pid 43637:tid 43853] [client 172.237.109.114:44679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupVYa8U9lZpWaWlJKKGgAAAFU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:17.980811 2026] [security2:error] [pid 43637:tid 43792] [client 191.232.199.39:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/index/function.php"] [unique_id "amupVYa8U9lZpWaWlJKKMgAAABg"]
[Thu Jul 30 14:43:18.397686 2026] [security2:error] [pid 43637:tid 43847] [client 189.156.226.90:26772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupVoa8U9lZpWaWlJKKQAAAAE8"]
[Thu Jul 30 14:43:18.397832 2026] [security2:error] [pid 43637:tid 43847] [client 189.156.226.90:26772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupVoa8U9lZpWaWlJKKQAAAAE8"]
[Thu Jul 30 14:43:19.051327 2026] [security2:error] [pid 43637:tid 43775] [client 185.191.171.10:37292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/16/pf-realiza-2a-fase-de-operacao-contra-grupo-suspeito-de-contrabando-de-cigarros-e-lavagem-de-dinheiro-na-pb/"] [unique_id "amupV4a8U9lZpWaWlJKKTQAAAAc"]
[Thu Jul 30 14:43:19.051501 2026] [security2:error] [pid 43637:tid 43775] [client 185.191.171.10:37292] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/16/pf-realiza-2a-fase-de-operacao-contra-grupo-suspeito-de-contrabando-de-cigarros-e-lavagem-de-dinheiro-na-pb/"] [unique_id "amupV4a8U9lZpWaWlJKKTQAAAAc"]
[Thu Jul 30 14:43:19.558264 2026] [security2:error] [pid 43637:tid 43655] [remote 57.141.0.39:56900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amupV4a8U9lZpWaWlJKKXQAADxE"]
[Thu Jul 30 14:43:19.617672 2026] [security2:error] [pid 43637:tid 43810] [client 20.226.5.174:31942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/yee.php"] [unique_id "amupV4a8U9lZpWaWlJKKXgAAACo"]
[Thu Jul 30 14:43:20.162644 2026] [security2:error] [pid 43637:tid 43796] [client 191.232.199.39:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/aaa.php"] [unique_id "amupWIa8U9lZpWaWlJKKawAAABw"]
[Thu Jul 30 14:43:20.969692 2026] [security2:error] [pid 43637:tid 43846] [client 20.226.5.174:31939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/yellow.php"] [unique_id "amupWIa8U9lZpWaWlJKKfgAAAE4"]
[Thu Jul 30 14:43:21.406208 2026] [security2:error] [pid 43637:tid 43791] [client 52.238.199.152:36694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amupWYa8U9lZpWaWlJKKjgAAABc"]
[Thu Jul 30 14:43:21.557947 2026] [security2:error] [pid 43637:tid 43780] [client 191.232.199.39:46006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/getid3-core.php"] [unique_id "amupWYa8U9lZpWaWlJKKjwAAAAw"]
[Thu Jul 30 14:43:21.775324 2026] [security2:error] [pid 43637:tid 43851] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amupWYa8U9lZpWaWlJKKgQAAU0Q"]
[Thu Jul 30 14:43:22.020473 2026] [security2:error] [pid 43637:tid 43879] [client 20.226.5.174:31938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/yes.php"] [unique_id "amupWoa8U9lZpWaWlJKKmQAAAG8"]
[Thu Jul 30 14:43:22.622061 2026] [security2:error] [pid 43637:tid 43783] [client 43.173.182.11:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/05/25/experience-centre-commercial-rosny-2/"] [unique_id "amupWoa8U9lZpWaWlJKKoQAAAA8"]
[Thu Jul 30 14:43:23.076489 2026] [security2:error] [pid 43637:tid 43807] [client 52.238.199.152:33733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/images/index.php"] [unique_id "amupW4a8U9lZpWaWlJKKsgAAACc"]
[Thu Jul 30 14:43:23.147145 2026] [security2:error] [pid 43637:tid 43782] [client 20.226.5.174:31937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/yindu.php"] [unique_id "amupW4a8U9lZpWaWlJKKswAAAA4"]
[Thu Jul 30 14:43:23.450658 2026] [core:notice] [pid 43637:tid 43887] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:23.455446 2026] [security2:error] [pid 43637:tid 43887] [client 43.172.195.149:33162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/05/25/experience-centre-commercial-rosny-2/"] [unique_id "amupW4a8U9lZpWaWlJKKvQAAAHc"], referer: https://carnetdeshopping.com/index.php/2016/05/25/experience-centre-commercial-rosny-2/
[Thu Jul 30 14:43:23.901542 2026] [security2:error] [pid 43637:tid 43869] [client 52.238.199.152:58855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/network/about.php"] [unique_id "amupW4a8U9lZpWaWlJKKyAAAAGU"]
[Thu Jul 30 14:43:24.316252 2026] [security2:error] [pid 43637:tid 43888] [client 191.232.199.39:2375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/adminer.php"] [unique_id "amupXIa8U9lZpWaWlJKK0gAAAHg"]
[Thu Jul 30 14:43:24.415505 2026] [security2:error] [pid 43637:tid 43772] [client 20.226.5.174:58190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/yox.php"] [unique_id "amupXIa8U9lZpWaWlJKK1gAAAAQ"]
[Thu Jul 30 14:43:25.534023 2026] [security2:error] [pid 43637:tid 43821] [client 20.226.5.174:31893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/yy.php"] [unique_id "amupXYa8U9lZpWaWlJKK7wAAADU"]
[Thu Jul 30 14:43:25.840244 2026] [security2:error] [pid 43637:tid 43783] [client 52.238.199.152:33752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/xpw.php"] [unique_id "amupXYa8U9lZpWaWlJKK-wAAAA8"]
[Thu Jul 30 14:43:25.977881 2026] [security2:error] [pid 43637:tid 43807] [client 191.232.199.39:2401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/alfa.php"] [unique_id "amupXYa8U9lZpWaWlJKK_AAAACc"]
[Thu Jul 30 14:43:26.633516 2026] [security2:error] [pid 43637:tid 43833] [client 52.238.199.152:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-cron.php"] [unique_id "amupXoa8U9lZpWaWlJKLEQAAAEE"]
[Thu Jul 30 14:43:26.694031 2026] [security2:error] [pid 43637:tid 43770] [client 20.226.5.174:31360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/yyobang/mar.php"] [unique_id "amupXoa8U9lZpWaWlJKLFwAAAAI"]
[Thu Jul 30 14:43:27.755117 2026] [security2:error] [pid 43637:tid 43839] [client 191.232.199.39:46004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amupX4a8U9lZpWaWlJKLMQAAAEc"]
[Thu Jul 30 14:43:27.894886 2026] [security2:error] [pid 43637:tid 43836] [client 20.226.5.174:31680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/z.php"] [unique_id "amupX4a8U9lZpWaWlJKLMgAAAEQ"]
[Thu Jul 30 14:43:28.363108 2026] [security2:error] [pid 43637:tid 43829] [client 177.6.106.101:53741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupYIa8U9lZpWaWlJKLRQAAAD0"]
[Thu Jul 30 14:43:28.363216 2026] [security2:error] [pid 43637:tid 43829] [client 177.6.106.101:53741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupYIa8U9lZpWaWlJKLRQAAAD0"]
[Thu Jul 30 14:43:28.913808 2026] [security2:error] [pid 43637:tid 43875] [client 52.238.199.152:57733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/cah.php"] [unique_id "amupYIa8U9lZpWaWlJKLUQAAAGs"]
[Thu Jul 30 14:43:28.978766 2026] [security2:error] [pid 43637:tid 43787] [client 189.156.226.90:27091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupYIa8U9lZpWaWlJKLUwAAABM"]
[Thu Jul 30 14:43:28.978916 2026] [security2:error] [pid 43637:tid 43787] [client 189.156.226.90:27091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupYIa8U9lZpWaWlJKLUwAAABM"]
[Thu Jul 30 14:43:28.996951 2026] [security2:error] [pid 43637:tid 43776] [client 20.226.5.174:31682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zaco.php"] [unique_id "amupYIa8U9lZpWaWlJKLVAAAAAg"]
[Thu Jul 30 14:43:29.180806 2026] [security2:error] [pid 43637:tid 43790] [client 191.232.199.39:30606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amupYYa8U9lZpWaWlJKLXgAAABY"]
[Thu Jul 30 14:43:29.963195 2026] [security2:error] [pid 43637:tid 43862] [client 20.226.5.174:60258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zacosmall.php"] [unique_id "amupYYa8U9lZpWaWlJKLbAAAAF4"]
[Thu Jul 30 14:43:30.639852 2026] [security2:error] [pid 43637:tid 43824] [client 191.232.199.39:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amupYoa8U9lZpWaWlJKLdwAAADg"]
[Thu Jul 30 14:43:30.902132 2026] [security2:error] [pid 43637:tid 43867] [client 216.73.217.60:55396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ecre.ae"] [uri "/index.php"] [unique_id "amupYoa8U9lZpWaWlJKLcwAAYwc"]
[Thu Jul 30 14:43:30.996606 2026] [security2:error] [pid 43637:tid 43878] [client 20.226.5.174:31941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zadad4dadad1.php"] [unique_id "amupYoa8U9lZpWaWlJKLhgAAAG4"]
[Thu Jul 30 14:43:32.035382 2026] [security2:error] [pid 43637:tid 43792] [client 191.232.199.39:30624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/edit.php"] [unique_id "amupZIa8U9lZpWaWlJKLnQAAABg"]
[Thu Jul 30 14:43:32.067784 2026] [security2:error] [pid 43637:tid 43640] [remote 106.75.64.28:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/favicon.ico"] [unique_id "amupZIa8U9lZpWaWlJKLngAAZQI"]
[Thu Jul 30 14:43:32.069694 2026] [security2:error] [pid 43637:tid 43826] [client 20.226.5.174:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zc-639.php"] [unique_id "amupZIa8U9lZpWaWlJKLnwAAADo"]
[Thu Jul 30 14:43:32.252285 2026] [security2:error] [pid 43637:tid 43858] [client 43.172.198.49:39766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/issue/archive"] [unique_id "amupZIa8U9lZpWaWlJKLnAAAAFo"]
[Thu Jul 30 14:43:32.367415 2026] [security2:error] [pid 43637:tid 43650] [remote 104.43.50.80:18439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.50.43.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-fdb1204b.med.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amupZIa8U9lZpWaWlJKLpgAAagw"]
[Thu Jul 30 14:43:32.842925 2026] [security2:error] [pid 43637:tid 43757] [remote 106.75.64.28:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/404.html/sitemap.xml"] [unique_id "amupZIa8U9lZpWaWlJKLrQAAVXY"]
[Thu Jul 30 14:43:32.858798 2026] [core:notice] [pid 43637:tid 43864] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:33.028169 2026] [security2:error] [pid 43637:tid 43814] [client 20.226.5.174:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zec.php"] [unique_id "amupZYa8U9lZpWaWlJKLuAAAAC4"]
[Thu Jul 30 14:43:33.312911 2026] [security2:error] [pid 43637:tid 43744] [remote 106.75.64.28:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/404.html/robots.txt"] [unique_id "amupZYa8U9lZpWaWlJKLuQAAP2o"]
[Thu Jul 30 14:43:33.374565 2026] [core:notice] [pid 43637:tid 43848] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:33.424624 2026] [core:notice] [pid 43637:tid 43774] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:33.721202 2026] [proxy:error] [pid 43637:tid 43822] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:43:33.721283 2026] [proxy_http:error] [pid 43637:tid 43822] [client 44.213.206.96:30316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:43:33.721850 2026] [proxy:error] [pid 43637:tid 43822] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:43:33.721894 2026] [proxy_http:error] [pid 43637:tid 43822] [client 44.213.206.96:30316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:43:33.977735 2026] [security2:error] [pid 43637:tid 43881] [client 52.1.106.130:53733] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2020/08/61be2012-32e4-426c-a424-cc0c89661720-e1597505274950.jpg"] [unique_id "amupZYa8U9lZpWaWlJKL0gAAAHE"]
[Thu Jul 30 14:43:34.077463 2026] [security2:error] [pid 43637:tid 43893] [client 172.237.109.114:18083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL1gAAAH0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.078019 2026] [security2:error] [pid 43637:tid 43787] [client 191.232.199.39:30600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/sf.php"] [unique_id "amupZoa8U9lZpWaWlJKL1wAAABM"]
[Thu Jul 30 14:43:34.078680 2026] [security2:error] [pid 43637:tid 43857] [client 172.237.109.114:9138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL2AAAAFk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.078798 2026] [security2:error] [pid 43637:tid 43799] [client 172.237.109.114:14246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL2QAAAB8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.079437 2026] [security2:error] [pid 43637:tid 43825] [client 172.237.109.114:46591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL2gAAADk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.089224 2026] [security2:error] [pid 43637:tid 43875] [client 172.237.109.114:47357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL2wAAAGs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.093508 2026] [security2:error] [pid 43637:tid 43846] [client 172.237.109.114:27272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL3AAAAE4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.112489 2026] [security2:error] [pid 43637:tid 43863] [client 20.226.5.174:32281] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zedd/1.php"] [unique_id "amupZoa8U9lZpWaWlJKL3QAAAF8"]
[Thu Jul 30 14:43:34.112602 2026] [security2:error] [pid 43637:tid 43863] [client 20.226.5.174:32281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zedd/1.php"] [unique_id "amupZoa8U9lZpWaWlJKL3QAAAF8"]
[Thu Jul 30 14:43:34.149675 2026] [security2:error] [pid 43637:tid 43800] [client 172.237.109.114:64606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL3gAAACA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.150204 2026] [security2:error] [pid 43637:tid 43886] [client 172.237.109.114:22233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL3wAAAHY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.150516 2026] [security2:error] [pid 43637:tid 43838] [client 172.237.109.114:16787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL4AAAAEY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.150902 2026] [security2:error] [pid 43637:tid 43795] [client 172.237.109.114:5173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZoa8U9lZpWaWlJKL4QAAABs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:34.181449 2026] [security2:error] [pid 43637:tid 43851] [client 52.238.199.152:33740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/cong.php"] [unique_id "amupZoa8U9lZpWaWlJKL4wAAAFM"]
[Thu Jul 30 14:43:35.103709 2026] [security2:error] [pid 43637:tid 43789] [client 172.237.109.114:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZ4a8U9lZpWaWlJKL9AAAABU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:35.123513 2026] [security2:error] [pid 43637:tid 43836] [client 172.237.109.114:37609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupZ4a8U9lZpWaWlJKL9wAAAEQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:35.195528 2026] [security2:error] [pid 43637:tid 43879] [client 20.226.5.174:31689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zero.php"] [unique_id "amupZ4a8U9lZpWaWlJKL-QAAAG8"]
[Thu Jul 30 14:43:35.298802 2026] [security2:error] [pid 43637:tid 43874] [client 177.6.106.101:54623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupZ4a8U9lZpWaWlJKL-wAAAGo"]
[Thu Jul 30 14:43:35.298971 2026] [security2:error] [pid 43637:tid 43874] [client 177.6.106.101:54623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupZ4a8U9lZpWaWlJKL-wAAAGo"]
[Thu Jul 30 14:43:35.406896 2026] [security2:error] [pid 43637:tid 43666] [remote 106.75.64.28:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/favicon.ico"] [unique_id "amupZ4a8U9lZpWaWlJKL_gAAJxw"]
[Thu Jul 30 14:43:35.679442 2026] [core:notice] [pid 43637:tid 43841] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:35.700939 2026] [security2:error] [pid 43637:tid 43779] [client 191.232.199.39:30617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wso.php"] [unique_id "amupZ4a8U9lZpWaWlJKMCwAAAAs"]
[Thu Jul 30 14:43:36.069554 2026] [proxy:error] [pid 43637:tid 43799] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:43:36.069634 2026] [proxy_http:error] [pid 43637:tid 43799] [client 52.4.19.39:3032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:43:36.070291 2026] [proxy:error] [pid 43637:tid 43799] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:43:36.070339 2026] [proxy_http:error] [pid 43637:tid 43799] [client 52.4.19.39:3032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:43:36.079552 2026] [security2:error] [pid 43637:tid 43837] [client 172.237.109.114:54904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupaIa8U9lZpWaWlJKMEwAAAEU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:36.092489 2026] [security2:error] [pid 43637:tid 43788] [client 172.237.109.114:54129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupaIa8U9lZpWaWlJKMFQAAABQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:36.092513 2026] [security2:error] [pid 43637:tid 43894] [client 172.237.109.114:59759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupaIa8U9lZpWaWlJKMFAAAAH4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:36.123783 2026] [security2:error] [pid 43637:tid 43868] [client 172.237.109.114:4498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupaIa8U9lZpWaWlJKMFgAAAGQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:36.147482 2026] [security2:error] [pid 43637:tid 43850] [client 172.237.109.114:3090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupaIa8U9lZpWaWlJKMGgAAAFI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:36.150628 2026] [security2:error] [pid 43637:tid 43881] [client 172.237.109.114:12775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupaIa8U9lZpWaWlJKMGwAAAHE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:36.151518 2026] [security2:error] [pid 43637:tid 43884] [client 172.237.109.114:4861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupaIa8U9lZpWaWlJKMHAAAAHQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:36.162783 2026] [security2:error] [pid 43637:tid 43648] [remote 106.75.64.28:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/404.html/sitemap.xml"] [unique_id "amupaIa8U9lZpWaWlJKMHQAAQQo"]
[Thu Jul 30 14:43:36.252479 2026] [security2:error] [pid 43637:tid 43827] [client 20.226.5.174:59894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zeroday.php"] [unique_id "amupaIa8U9lZpWaWlJKMHgAAADs"]
[Thu Jul 30 14:43:36.647018 2026] [security2:error] [pid 43637:tid 43689] [remote 106.75.64.28:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.bestdogproductguide.com"] [uri "/404.html/robots.txt"] [unique_id "amupaIa8U9lZpWaWlJKMKAAAPjM"]
[Thu Jul 30 14:43:36.952085 2026] [security2:error] [pid 43637:tid 43810] [client 52.238.199.152:59913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/Sanskrit.php"] [unique_id "amupaIa8U9lZpWaWlJKMKgAAACo"]
[Thu Jul 30 14:43:36.991820 2026] [security2:error] [pid 43637:tid 43791] [client 191.232.199.39:30595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/ioxi-o.php"] [unique_id "amupaIa8U9lZpWaWlJKMKwAAABc"]
[Thu Jul 30 14:43:37.078348 2026] [security2:error] [pid 43637:tid 43832] [client 172.237.109.114:6860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupaYa8U9lZpWaWlJKMMQAAAEA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:37.349997 2026] [security2:error] [pid 43637:tid 43839] [client 20.226.5.174:31685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zf.php"] [unique_id "amupaYa8U9lZpWaWlJKMNgAAAEc"]
[Thu Jul 30 14:43:38.339995 2026] [security2:error] [pid 43637:tid 43801] [client 191.232.199.39:2470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/file56.php"] [unique_id "amupaoa8U9lZpWaWlJKMSwAAACE"]
[Thu Jul 30 14:43:38.400456 2026] [security2:error] [pid 43637:tid 43845] [client 52.238.199.152:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ms-edit.php"] [unique_id "amupaoa8U9lZpWaWlJKMTwAAAE0"]
[Thu Jul 30 14:43:38.479658 2026] [security2:error] [pid 43637:tid 43786] [client 20.226.5.174:31945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zfox.php"] [unique_id "amupaoa8U9lZpWaWlJKMUQAAABI"]
[Thu Jul 30 14:43:39.442710 2026] [security2:error] [pid 43637:tid 43770] [client 20.226.5.174:31943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zgdsfadsk/rk3.php"] [unique_id "amupa4a8U9lZpWaWlJKMZwAAAAI"]
[Thu Jul 30 14:43:39.477997 2026] [security2:error] [pid 43637:tid 43847] [client 189.156.226.90:27230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupa4a8U9lZpWaWlJKMaAAAAE8"]
[Thu Jul 30 14:43:39.478120 2026] [security2:error] [pid 43637:tid 43847] [client 189.156.226.90:27230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupa4a8U9lZpWaWlJKMaAAAAE8"]
[Thu Jul 30 14:43:39.608873 2026] [security2:error] [pid 43637:tid 43866] [client 191.232.199.39:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amupa4a8U9lZpWaWlJKMbQAAAGI"]
[Thu Jul 30 14:43:39.936742 2026] [security2:error] [pid 43637:tid 43872] [client 52.238.199.152:53194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/function.php"] [unique_id "amupa4a8U9lZpWaWlJKMeAAAAGg"]
[Thu Jul 30 14:43:39.974513 2026] [security2:error] [pid 43637:tid 43774] [client 172.237.109.114:31849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/l.fcgi"] [unique_id "amupa4a8U9lZpWaWlJKMeQAAAAY"]
[Thu Jul 30 14:43:40.477344 2026] [security2:error] [pid 43637:tid 43877] [client 20.226.5.174:31947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zgdsfage/rk3.php"] [unique_id "amupbIa8U9lZpWaWlJKMgwAAAG0"]
[Thu Jul 30 14:43:40.808029 2026] [security2:error] [pid 43637:tid 43779] [client 191.232.199.39:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-admin/css/index.php"] [unique_id "amupbIa8U9lZpWaWlJKMigAAAAs"]
[Thu Jul 30 14:43:41.465310 2026] [security2:error] [pid 43637:tid 43820] [client 20.226.5.174:31936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zgdsfags/rk3.php"] [unique_id "amupbYa8U9lZpWaWlJKMrwAAADQ"]
[Thu Jul 30 14:43:41.750097 2026] [security2:error] [pid 43637:tid 43876] [client 64.42.179.59:42060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amupbYa8U9lZpWaWlJKMswAAAGw"]
[Thu Jul 30 14:43:41.750205 2026] [security2:error] [pid 43637:tid 43876] [client 64.42.179.59:42060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amupbYa8U9lZpWaWlJKMswAAAGw"]
[Thu Jul 30 14:43:41.992510 2026] [core:notice] [pid 43637:tid 43785] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:42.214114 2026] [security2:error] [pid 43637:tid 43852] [client 191.232.199.39:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/edit.php"] [unique_id "amupboa8U9lZpWaWlJKMvgAAAFQ"]
[Thu Jul 30 14:43:42.292357 2026] [security2:error] [pid 43637:tid 43806] [client 185.191.171.10:53346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jcsgoeastwood.org"] [uri "/robots.txt"] [unique_id "amupboa8U9lZpWaWlJKMvwAAACY"]
[Thu Jul 30 14:43:42.292483 2026] [security2:error] [pid 43637:tid 43806] [client 185.191.171.10:53346] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jcsgoeastwood.org"] [uri "/robots.txt"] [unique_id "amupboa8U9lZpWaWlJKMvwAAACY"]
[Thu Jul 30 14:43:42.481682 2026] [security2:error] [pid 43637:tid 43879] [client 20.226.5.174:60279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zk.php"] [unique_id "amupboa8U9lZpWaWlJKMxwAAAG8"]
[Thu Jul 30 14:43:43.241111 2026] [security2:error] [pid 43637:tid 43868] [client 52.238.199.152:59914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ee.php"] [unique_id "amupb4a8U9lZpWaWlJKM1QAAAGQ"]
[Thu Jul 30 14:43:43.275570 2026] [security2:error] [pid 43637:tid 43813] [client 85.208.96.209:13002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jcsgoeastwood.org"] [uri "/my-dashboard/cb-profile/460-ellie"] [unique_id "amupb4a8U9lZpWaWlJKM1gAAAC0"]
[Thu Jul 30 14:43:43.275668 2026] [security2:error] [pid 43637:tid 43813] [client 85.208.96.209:13002] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jcsgoeastwood.org"] [uri "/my-dashboard/cb-profile/460-ellie"] [unique_id "amupb4a8U9lZpWaWlJKM1gAAAC0"]
[Thu Jul 30 14:43:43.593943 2026] [core:error] [pid 43637:tid 43851] [client 74.7.228.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:43:43.593999 2026] [core:error] [pid 43637:tid 43851] [client 74.7.228.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:43:43.594139 2026] [security2:error] [pid 43637:tid 43851] [client 74.7.228.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.embassyofspaininpakistan.info"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amupb4a8U9lZpWaWlJKM4AAAAFM"]
[Thu Jul 30 14:43:43.594805 2026] [security2:error] [pid 43637:tid 43786] [client 74.7.228.47:40364] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.embassyofspaininpakistan.info"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amupb4a8U9lZpWaWlJKM3gAAEl4"]
[Thu Jul 30 14:43:43.651901 2026] [security2:error] [pid 43637:tid 43787] [client 20.226.5.174:31684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zmFM.php"] [unique_id "amupb4a8U9lZpWaWlJKM4QAAABM"]
[Thu Jul 30 14:43:43.683972 2026] [security2:error] [pid 43637:tid 43846] [client 191.232.199.39:47912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/2.php"] [unique_id "amupb4a8U9lZpWaWlJKM4gAAAE4"]
[Thu Jul 30 14:43:43.707475 2026] [security2:error] [pid 43637:tid 43838] [client 66.249.66.192:60161] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "newwcoupons.net"] [uri "/robots.txt"] [unique_id "amupb4a8U9lZpWaWlJKM4wAAAEY"]
[Thu Jul 30 14:43:43.987250 2026] [security2:error] [pid 43637:tid 43837] [client 52.238.199.152:33729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/new.php"] [unique_id "amupb4a8U9lZpWaWlJKM8gAAAEU"]
[Thu Jul 30 14:43:44.360884 2026] [core:notice] [pid 43637:tid 43670] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:44.661654 2026] [security2:error] [pid 43637:tid 43777] [client 20.226.5.174:31954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zone.php"] [unique_id "amupcIa8U9lZpWaWlJKNAAAAAAk"]
[Thu Jul 30 14:43:44.916163 2026] [security2:error] [pid 43637:tid 43785] [client 191.232.199.39:30610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amupcIa8U9lZpWaWlJKNBAAAABE"]
[Thu Jul 30 14:43:45.079019 2026] [security2:error] [pid 43637:tid 43879] [client 128.2.204.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amupcIa8U9lZpWaWlJKNBwAAAG8"]
[Thu Jul 30 14:43:45.114415 2026] [security2:error] [pid 43637:tid 43835] [client 177.6.106.101:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupcYa8U9lZpWaWlJKNEAAAAEM"]
[Thu Jul 30 14:43:45.114537 2026] [security2:error] [pid 43637:tid 43835] [client 177.6.106.101:55248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupcYa8U9lZpWaWlJKNEAAAAEM"]
[Thu Jul 30 14:43:45.124529 2026] [security2:error] [pid 43637:tid 43794] [client 116.204.105.189:52392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amupcIa8U9lZpWaWlJKM9gAAGiw"]
[Thu Jul 30 14:43:45.611908 2026] [security2:error] [pid 43637:tid 43887] [client 103.59.160.186:49800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "abs-sa.net"] [uri "/index.php"] [unique_id "amupcYa8U9lZpWaWlJKNHAAAAHc"]
[Thu Jul 30 14:43:45.797440 2026] [security2:error] [pid 43637:tid 43813] [client 20.226.5.174:31953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zsec.php"] [unique_id "amupcYa8U9lZpWaWlJKNJwAAAC0"]
[Thu Jul 30 14:43:46.135742 2026] [security2:error] [pid 43637:tid 43851] [client 191.232.199.39:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/mah.php"] [unique_id "amupcoa8U9lZpWaWlJKNMgAAAFM"]
[Thu Jul 30 14:43:46.741171 2026] [security2:error] [pid 43637:tid 43772] [client 20.226.5.174:31956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zuk.php"] [unique_id "amupcoa8U9lZpWaWlJKNPwAAAAQ"]
[Thu Jul 30 14:43:47.462405 2026] [security2:error] [pid 43637:tid 43852] [client 191.232.199.39:30603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/send.php"] [unique_id "amupc4a8U9lZpWaWlJKNTAAAAFQ"]
[Thu Jul 30 14:43:47.853228 2026] [core:notice] [pid 43637:tid 43856] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:47.963814 2026] [security2:error] [pid 43637:tid 43821] [client 20.226.5.174:60258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zwso.php"] [unique_id "amupc4a8U9lZpWaWlJKNVgAAADU"]
[Thu Jul 30 14:43:48.551022 2026] [security2:error] [pid 43637:tid 43833] [client 172.237.109.114:64926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amupc4a8U9lZpWaWlJKNWAAAAEE"], referer: http://alseermarine.com:80/flashdisk/WWW/index.htm
[Thu Jul 30 14:43:48.729947 2026] [security2:error] [pid 43637:tid 43888] [client 184.75.221.59:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amupdIa8U9lZpWaWlJKNbQAAAHg"]
[Thu Jul 30 14:43:48.730067 2026] [security2:error] [pid 43637:tid 43888] [client 184.75.221.59:53466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amupdIa8U9lZpWaWlJKNbQAAAHg"]
[Thu Jul 30 14:43:48.739868 2026] [security2:error] [pid 43637:tid 43782] [client 191.232.199.39:2468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amupdIa8U9lZpWaWlJKNbgAAAA4"]
[Thu Jul 30 14:43:49.078084 2026] [security2:error] [pid 43637:tid 43792] [client 20.226.5.174:31950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zx.php"] [unique_id "amupdYa8U9lZpWaWlJKNdQAAABg"]
[Thu Jul 30 14:43:49.154154 2026] [core:notice] [pid 43637:tid 43825] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:49.582044 2026] [security2:error] [pid 43637:tid 43879] [client 46.183.217.105:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.217.183.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amupdYa8U9lZpWaWlJKNgQAAAG8"]
[Thu Jul 30 14:43:49.582131 2026] [security2:error] [pid 43637:tid 43879] [client 46.183.217.105:43880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amupdYa8U9lZpWaWlJKNgQAAAG8"]
[Thu Jul 30 14:43:49.625171 2026] [security2:error] [pid 43637:tid 43701] [remote 75.119.132.40:53832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.132.119.75.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-login.php"] [unique_id "amupdYa8U9lZpWaWlJKNggAAZj8"]
[Thu Jul 30 14:43:50.050276 2026] [security2:error] [pid 43637:tid 43817] [client 189.156.226.90:27611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupdoa8U9lZpWaWlJKNjQAAADE"]
[Thu Jul 30 14:43:50.050393 2026] [security2:error] [pid 43637:tid 43817] [client 189.156.226.90:27611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupdoa8U9lZpWaWlJKNjQAAADE"]
[Thu Jul 30 14:43:50.095884 2026] [security2:error] [pid 43637:tid 43863] [client 172.237.109.114:23910] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amupdoa8U9lZpWaWlJKNjgAAAF8"]
[Thu Jul 30 14:43:50.108759 2026] [security2:error] [pid 43637:tid 43819] [client 20.226.5.174:31957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zxcv.php"] [unique_id "amupdoa8U9lZpWaWlJKNjwAAADM"]
[Thu Jul 30 14:43:50.290849 2026] [security2:error] [pid 43637:tid 43774] [client 191.232.199.39:2398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/about.php"] [unique_id "amupdoa8U9lZpWaWlJKNlAAAAAY"]
[Thu Jul 30 14:43:50.722874 2026] [autoindex:error] [pid 43637:tid 43808] [client 52.4.19.39:11145] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:43:50.758573 2026] [security2:error] [pid 43637:tid 43721] [remote 74.7.175.187:60830] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dov.dtn.temporary.site"] [uri "/index.php"] [unique_id "amupaoa8U9lZpWaWlJKMUgAAa1M"]
[Thu Jul 30 14:43:50.862459 2026] [core:notice] [pid 43637:tid 43696] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:51.101172 2026] [security2:error] [pid 43637:tid 43876] [client 20.226.5.174:31683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zze.php"] [unique_id "amupd4a8U9lZpWaWlJKNpgAAAGw"]
[Thu Jul 30 14:43:51.515203 2026] [security2:error] [pid 43637:tid 43825] [client 191.232.199.39:2897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/options.php"] [unique_id "amupd4a8U9lZpWaWlJKNsQAAADk"]
[Thu Jul 30 14:43:51.568392 2026] [security2:error] [pid 43637:tid 43806] [client 143.244.57.86:58390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lilyinspires.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amupd4a8U9lZpWaWlJKNtAAAACY"]
[Thu Jul 30 14:43:52.422619 2026] [security2:error] [pid 43637:tid 43885] [client 20.226.5.174:31946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lilyinspires.com"] [uri "/zzz.php"] [unique_id "amupeIa8U9lZpWaWlJKNxgAAAHU"]
[Thu Jul 30 14:43:52.464888 2026] [security2:error] [pid 43637:tid 43830] [client 52.238.199.152:33728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-config.php"] [unique_id "amupeIa8U9lZpWaWlJKNygAAAD4"]
[Thu Jul 30 14:43:52.465617 2026] [security2:error] [pid 43637:tid 43811] [client 143.244.57.86:58392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xmlrpc.php"] [unique_id "amupeIa8U9lZpWaWlJKNwgAAACs"]
[Thu Jul 30 14:43:52.838189 2026] [core:notice] [pid 43637:tid 43711] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:52.883537 2026] [security2:error] [pid 43637:tid 43881] [client 191.232.199.39:2459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-content/themes/index.php"] [unique_id "amupeIa8U9lZpWaWlJKNzwAAAHE"]
[Thu Jul 30 14:43:53.936888 2026] [security2:error] [pid 43637:tid 43844] [client 57.141.0.49:50156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amupeYa8U9lZpWaWlJKN4wAATFw"], referer: https://igetvape-australia.com/product/alibarbar-ice-adjust-12000-puffs-skittles/
[Thu Jul 30 14:43:54.084363 2026] [security2:error] [pid 43637:tid 43861] [client 143.244.57.86:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xmlrpc.php"] [unique_id "amupeoa8U9lZpWaWlJKN8AAAAF0"]
[Thu Jul 30 14:43:54.084462 2026] [security2:error] [pid 43637:tid 43861] [client 143.244.57.86:58396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lilyinspires.com"] [uri "/xmlrpc.php"] [unique_id "amupeoa8U9lZpWaWlJKN8AAAAF0"]
[Thu Jul 30 14:43:54.091779 2026] [security2:error] [pid 43637:tid 43876] [client 191.232.199.39:30622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/wp-file.php"] [unique_id "amupeoa8U9lZpWaWlJKN8QAAAGw"]
[Thu Jul 30 14:43:54.437285 2026] [security2:error] [pid 43637:tid 43843] [client 52.238.199.152:59915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-conflg.php"] [unique_id "amupeoa8U9lZpWaWlJKN9QAAAEs"]
[Thu Jul 30 14:43:54.741712 2026] [core:error] [pid 43637:tid 43776] [client 138.246.253.24:52130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:43:54.741732 2026] [core:error] [pid 43637:tid 43776] [client 138.246.253.24:52130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:43:55.076505 2026] [security2:error] [pid 43637:tid 43835] [client 172.237.109.114:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKOAwAAAEM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.077546 2026] [security2:error] [pid 43637:tid 43877] [client 172.237.109.114:11794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKOBAAAAG0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.079331 2026] [security2:error] [pid 43637:tid 43885] [client 172.237.109.114:8366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKOBQAAAHU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.094801 2026] [security2:error] [pid 43637:tid 43794] [client 172.237.109.114:11033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKOCAAAABo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.096275 2026] [security2:error] [pid 43637:tid 43805] [client 172.237.109.114:6803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKOCgAAACU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.121151 2026] [security2:error] [pid 43637:tid 43814] [client 172.237.109.114:41212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKOCwAAAC4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.147849 2026] [security2:error] [pid 43637:tid 43850] [client 172.237.109.114:36340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKODAAAAFI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.148576 2026] [security2:error] [pid 43637:tid 43883] [client 172.237.109.114:45185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKODQAAAHM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.149236 2026] [security2:error] [pid 43637:tid 43845] [client 172.237.109.114:43529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKODgAAAE0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.150833 2026] [security2:error] [pid 43637:tid 43895] [client 172.237.109.114:26078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupe4a8U9lZpWaWlJKODwAAAH8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:55.508869 2026] [security2:error] [pid 43637:tid 43821] [client 191.232.199.39:47886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kendarikomputer.com"] [uri "/sid3.php"] [unique_id "amupe4a8U9lZpWaWlJKOFwAAADU"]
[Thu Jul 30 14:43:55.868505 2026] [core:notice] [pid 43637:tid 43888] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:55.947066 2026] [security2:error] [pid 43637:tid 43875] [client 154.164.144.23:41471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.144.164.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fiyan.co"] [uri "/xmlrpc.php"] [unique_id "amupe4a8U9lZpWaWlJKOIgAAAGs"]
[Thu Jul 30 14:43:55.947205 2026] [security2:error] [pid 43637:tid 43875] [client 154.164.144.23:41471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fiyan.co"] [uri "/xmlrpc.php"] [unique_id "amupe4a8U9lZpWaWlJKOIgAAAGs"]
[Thu Jul 30 14:43:56.077449 2026] [security2:error] [pid 43637:tid 43891] [client 172.237.109.114:34837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfIa8U9lZpWaWlJKOJgAAAHs"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:56.087158 2026] [security2:error] [pid 43637:tid 43844] [client 172.237.109.114:50156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfIa8U9lZpWaWlJKOJwAAAEw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:56.362966 2026] [security2:error] [pid 43637:tid 43841] [client 52.238.199.152:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amupfIa8U9lZpWaWlJKOLQAAAEk"]
[Thu Jul 30 14:43:56.400863 2026] [security2:error] [pid 43637:tid 43676] [remote 216.73.216.51:11477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amupfIa8U9lZpWaWlJKOLAAABSY"]
[Thu Jul 30 14:43:56.478846 2026] [core:notice] [pid 43637:tid 43828] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:43:57.086305 2026] [security2:error] [pid 43637:tid 43787] [client 172.237.109.114:26885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfYa8U9lZpWaWlJKOQQAAABM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:57.086614 2026] [security2:error] [pid 43637:tid 43771] [client 172.237.109.114:42243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfYa8U9lZpWaWlJKOQgAAAAM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:57.091635 2026] [security2:error] [pid 43637:tid 43838] [client 172.237.109.114:41623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfYa8U9lZpWaWlJKORAAAAEY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:57.094176 2026] [security2:error] [pid 43637:tid 43833] [client 172.237.109.114:9592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfYa8U9lZpWaWlJKORQAAAEE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:57.121509 2026] [security2:error] [pid 43637:tid 43840] [client 172.237.109.114:27072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfYa8U9lZpWaWlJKORgAAAEg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:57.123509 2026] [security2:error] [pid 43637:tid 43858] [client 172.237.109.114:19470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfYa8U9lZpWaWlJKORwAAAFo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:57.151556 2026] [security2:error] [pid 43637:tid 43815] [client 172.237.109.114:30796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfYa8U9lZpWaWlJKOSgAAAC8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:57.433148 2026] [security2:error] [pid 43637:tid 43817] [client 52.238.199.152:53235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amupfYa8U9lZpWaWlJKOTQAAADE"]
[Thu Jul 30 14:43:58.102640 2026] [security2:error] [pid 43637:tid 43790] [client 172.237.109.114:33135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupfoa8U9lZpWaWlJKOWgAAABY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:43:58.350998 2026] [security2:error] [pid 43637:tid 43841] [client 52.238.199.152:36800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amupfoa8U9lZpWaWlJKOYgAAAEk"]
[Thu Jul 30 14:43:59.542019 2026] [security2:error] [pid 43637:tid 43823] [client 177.6.106.101:55750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupf4a8U9lZpWaWlJKOeQAAADc"]
[Thu Jul 30 14:43:59.542127 2026] [security2:error] [pid 43637:tid 43823] [client 177.6.106.101:55750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupf4a8U9lZpWaWlJKOeQAAADc"]
[Thu Jul 30 14:44:00.040643 2026] [security2:error] [pid 43637:tid 43866] [client 52.238.199.152:36675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amupgIa8U9lZpWaWlJKOhAAAAGI"]
[Thu Jul 30 14:44:00.708818 2026] [security2:error] [pid 43637:tid 43854] [client 189.156.226.90:26842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupgIa8U9lZpWaWlJKOkQAAAFY"]
[Thu Jul 30 14:44:00.708966 2026] [security2:error] [pid 43637:tid 43854] [client 189.156.226.90:26842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupgIa8U9lZpWaWlJKOkQAAAFY"]
[Thu Jul 30 14:44:01.941215 2026] [security2:error] [pid 43637:tid 43803] [client 52.238.199.152:58873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/manager.php"] [unique_id "amupgYa8U9lZpWaWlJKOtQAAACM"]
[Thu Jul 30 14:44:01.971574 2026] [security2:error] [pid 43637:tid 43793] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amupgYa8U9lZpWaWlJKOpAAAGW4"]
[Thu Jul 30 14:44:02.977509 2026] [security2:error] [pid 43637:tid 43848] [client 172.237.109.114:7788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/l.fcgi"] [unique_id "amupgoa8U9lZpWaWlJKOzgAAAFA"]
[Thu Jul 30 14:44:03.179995 2026] [security2:error] [pid 43637:tid 43895] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amupg4a8U9lZpWaWlJKO0gAAAH8"]
[Thu Jul 30 14:44:03.272565 2026] [security2:error] [pid 43637:tid 43864] [client 14.191.214.201:2602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupgoa8U9lZpWaWlJKOygAAAGA"], referer: http://pkf.jo
[Thu Jul 30 14:44:03.339763 2026] [security2:error] [pid 43637:tid 43891] [client 195.20.125.17:30701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupg4a8U9lZpWaWlJKOzwAAAHs"], referer: http://pkf.jo
[Thu Jul 30 14:44:03.634440 2026] [security2:error] [pid 43637:tid 43788] [client 171.227.183.253:36966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupg4a8U9lZpWaWlJKO1gAAABQ"], referer: http://pkf.jo
[Thu Jul 30 14:44:03.635288 2026] [security2:error] [pid 43637:tid 43847] [client 176.88.136.50:46279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupgoa8U9lZpWaWlJKOxgAAAE8"], referer: http://pkf.jo
[Thu Jul 30 14:44:03.826385 2026] [security2:error] [pid 43637:tid 43878] [client 78.22.123.31:51710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupg4a8U9lZpWaWlJKO3QAAAG4"], referer: http://pkf.jo
[Thu Jul 30 14:44:04.495456 2026] [security2:error] [pid 43637:tid 43830] [client 190.104.176.153:30765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuphIa8U9lZpWaWlJKO6gAAAD4"], referer: http://pkf.jo
[Thu Jul 30 14:44:04.495538 2026] [security2:error] [pid 43637:tid 43811] [client 138.59.196.87:44414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuphIa8U9lZpWaWlJKO6AAAACs"], referer: http://pkf.jo
[Thu Jul 30 14:44:04.558322 2026] [core:notice] [pid 43637:tid 43838] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:04.806852 2026] [security2:error] [pid 43637:tid 43687] [remote 136.65.23.210:52140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.23.65.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/modules/gsnippetsreviews/ws-gsnippetsreviews.php"] [unique_id "amuphIa8U9lZpWaWlJKO-gAAUjE"]
[Thu Jul 30 14:44:05.649634 2026] [security2:error] [pid 43637:tid 43685] [remote 57.141.0.43:36502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuphYa8U9lZpWaWlJKPBwAAOi8"]
[Thu Jul 30 14:44:06.416827 2026] [security2:error] [pid 43637:tid 43877] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuphoa8U9lZpWaWlJKPIwAAAG0"]
[Thu Jul 30 14:44:06.426513 2026] [security2:error] [pid 43637:tid 43785] [client 74.7.228.6:59340] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pwy.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuphoa8U9lZpWaWlJKPJwAAABE"]
[Thu Jul 30 14:44:07.473512 2026] [security2:error] [pid 43637:tid 43814] [client 52.238.199.152:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-links.php"] [unique_id "amuph4a8U9lZpWaWlJKPQgAAAC4"]
[Thu Jul 30 14:44:08.445408 2026] [security2:error] [pid 43637:tid 43893] [client 177.6.106.101:56559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupiIa8U9lZpWaWlJKPUwAAAH0"]
[Thu Jul 30 14:44:08.445600 2026] [security2:error] [pid 43637:tid 43893] [client 177.6.106.101:56559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupiIa8U9lZpWaWlJKPUwAAAH0"]
[Thu Jul 30 14:44:08.511406 2026] [security2:error] [pid 43637:tid 43779] [client 193.47.62.167:52570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rry.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuphoa8U9lZpWaWlJKPMQAAAAs"]
[Thu Jul 30 14:44:08.727518 2026] [security2:error] [pid 43637:tid 43864] [client 52.238.199.152:36698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/fi2.php"] [unique_id "amupiIa8U9lZpWaWlJKPXgAAAGA"]
[Thu Jul 30 14:44:10.132696 2026] [core:notice] [pid 43637:tid 43772] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:10.376773 2026] [core:notice] [pid 43637:tid 43888] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:10.557620 2026] [core:notice] [pid 43637:tid 43858] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:10.598004 2026] [core:notice] [pid 43637:tid 43876] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:10.819276 2026] [core:notice] [pid 43637:tid 43879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:11.011908 2026] [core:notice] [pid 43637:tid 43812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:11.241397 2026] [core:notice] [pid 43637:tid 43841] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:11.365536 2026] [security2:error] [pid 43637:tid 43730] [remote 216.73.216.51:43753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amupi4a8U9lZpWaWlJKPnAAAYFw"]
[Thu Jul 30 14:44:11.392495 2026] [security2:error] [pid 43637:tid 43816] [client 189.156.226.90:27216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupi4a8U9lZpWaWlJKPnQAAADA"]
[Thu Jul 30 14:44:11.392597 2026] [security2:error] [pid 43637:tid 43816] [client 189.156.226.90:27216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupi4a8U9lZpWaWlJKPnQAAADA"]
[Thu Jul 30 14:44:11.479652 2026] [core:notice] [pid 43637:tid 43883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:11.485898 2026] [core:error] [pid 43637:tid 43856] [client 74.7.228.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:44:11.485915 2026] [core:error] [pid 43637:tid 43856] [client 74.7.228.47:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:44:11.486037 2026] [security2:error] [pid 43637:tid 43856] [client 74.7.228.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.portugalvisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amupi4a8U9lZpWaWlJKPogAAAFg"]
[Thu Jul 30 14:44:11.486929 2026] [security2:error] [pid 43637:tid 43827] [client 74.7.228.47:52398] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.portugalvisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amupi4a8U9lZpWaWlJKPnwAAOyc"]
[Thu Jul 30 14:44:11.589467 2026] [security2:error] [pid 43637:tid 43865] [client 74.7.175.140:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "1persent.teknomalay.com"] [uri "/cgi-sys/404.html"] [unique_id "amupi4a8U9lZpWaWlJKPpAAAYUM"]
[Thu Jul 30 14:44:11.759319 2026] [core:notice] [pid 43637:tid 43855] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:11.898495 2026] [security2:error] [pid 43637:tid 43774] [client 52.238.199.152:36679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/0x.php"] [unique_id "amupi4a8U9lZpWaWlJKPsAAAAAY"]
[Thu Jul 30 14:44:12.046824 2026] [core:notice] [pid 43637:tid 43770] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:12.105696 2026] [core:notice] [pid 43637:tid 43839] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:12.280598 2026] [core:notice] [pid 43637:tid 43796] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:12.532767 2026] [core:notice] [pid 43637:tid 43879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:12.827818 2026] [core:notice] [pid 43637:tid 43812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:12.871129 2026] [security2:error] [pid 43637:tid 43773] [client 52.238.199.152:3624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/k.php"] [unique_id "amupjIa8U9lZpWaWlJKPygAAAAU"]
[Thu Jul 30 14:44:13.112629 2026] [core:notice] [pid 43637:tid 43886] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:13.262126 2026] [security2:error] [pid 43637:tid 43725] [remote 190.92.174.81:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amupjYa8U9lZpWaWlJKP0AAAYFc"]
[Thu Jul 30 14:44:13.262258 2026] [security2:error] [pid 43637:tid 43864] [client 190.92.174.81:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "santaclaraimports.com"] [uri "/xmlrpc.php"] [unique_id "amupjYa8U9lZpWaWlJKP0AAAYFc"]
[Thu Jul 30 14:44:13.353451 2026] [core:notice] [pid 43637:tid 43887] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:13.430428 2026] [core:notice] [pid 43637:tid 43660] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:13.661802 2026] [core:notice] [pid 43637:tid 43724] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:15.270907 2026] [security2:error] [pid 43637:tid 43795] [client 20.226.5.174:45445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/providers/index.php"] [unique_id "amupj4a8U9lZpWaWlJKP_gAAABs"]
[Thu Jul 30 14:44:16.081902 2026] [security2:error] [pid 43637:tid 43808] [client 172.237.109.114:14085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQGAAAACg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.086237 2026] [security2:error] [pid 43637:tid 43821] [client 172.237.109.114:34378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQGgAAADU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.086403 2026] [security2:error] [pid 43637:tid 43792] [client 172.237.109.114:26886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQGQAAABg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.092137 2026] [security2:error] [pid 43637:tid 43809] [client 172.237.109.114:42672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQGwAAACk"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.094455 2026] [security2:error] [pid 43637:tid 43789] [client 172.237.109.114:39206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQHAAAABU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.125736 2026] [security2:error] [pid 43637:tid 43784] [client 172.237.109.114:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQHQAAABA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.147568 2026] [security2:error] [pid 43637:tid 43804] [client 172.237.109.114:3202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQHgAAACQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.148861 2026] [security2:error] [pid 43637:tid 43862] [client 172.237.109.114:17004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQHwAAAF4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.149827 2026] [security2:error] [pid 43637:tid 43855] [client 172.237.109.114:9740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQIAAAAFc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.151225 2026] [security2:error] [pid 43637:tid 43791] [client 172.237.109.114:46741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkIa8U9lZpWaWlJKQIQAAABc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:16.258526 2026] [security2:error] [pid 43637:tid 43726] [remote 74.7.243.224:48322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amupkIa8U9lZpWaWlJKQIgAALlg"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:44:16.275733 2026] [security2:error] [pid 43637:tid 43873] [client 20.226.5.174:45462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/providers/ultra.php"] [unique_id "amupkIa8U9lZpWaWlJKQIwAAAGk"]
[Thu Jul 30 14:44:16.774405 2026] [security2:error] [pid 43637:tid 43885] [client 177.6.106.101:57081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupkIa8U9lZpWaWlJKQLgAAAHU"]
[Thu Jul 30 14:44:16.774549 2026] [security2:error] [pid 43637:tid 43885] [client 177.6.106.101:57081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupkIa8U9lZpWaWlJKQLgAAAHU"]
[Thu Jul 30 14:44:17.077059 2026] [security2:error] [pid 43637:tid 43797] [client 172.237.109.114:32445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkYa8U9lZpWaWlJKQNQAAAB0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:17.087628 2026] [security2:error] [pid 43637:tid 43878] [client 172.237.109.114:44344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkYa8U9lZpWaWlJKQNgAAAG4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:17.386259 2026] [security2:error] [pid 43637:tid 43867] [client 20.226.5.174:45443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/providers/wp-conflg.php"] [unique_id "amupkYa8U9lZpWaWlJKQOwAAAGM"]
[Thu Jul 30 14:44:18.079223 2026] [security2:error] [pid 43637:tid 43804] [client 172.237.109.114:50822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkoa8U9lZpWaWlJKQUgAAACQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:18.079248 2026] [security2:error] [pid 43637:tid 43862] [client 172.237.109.114:59262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkoa8U9lZpWaWlJKQUwAAAF4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:18.095078 2026] [security2:error] [pid 43637:tid 43865] [client 172.237.109.114:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkoa8U9lZpWaWlJKQVAAAAGE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:18.096078 2026] [security2:error] [pid 43637:tid 43820] [client 172.237.109.114:44089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkoa8U9lZpWaWlJKQVQAAADQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:18.102109 2026] [security2:error] [pid 43637:tid 43845] [client 172.237.109.114:36927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkoa8U9lZpWaWlJKQVwAAAE0"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:18.106766 2026] [security2:error] [pid 43637:tid 43783] [client 216.73.216.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thesounddepot.com"] [uri "/index.php"] [unique_id "amupj4a8U9lZpWaWlJKP_QAAAA8"]
[Thu Jul 30 14:44:18.124047 2026] [security2:error] [pid 43637:tid 43888] [client 172.237.109.114:20893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkoa8U9lZpWaWlJKQWAAAAHg"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:18.149432 2026] [security2:error] [pid 43637:tid 43839] [client 172.237.109.114:10033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupkoa8U9lZpWaWlJKQWgAAAEc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:18.373389 2026] [security2:error] [pid 43637:tid 43873] [client 20.226.5.174:45463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/providers/yes.php"] [unique_id "amupkoa8U9lZpWaWlJKQYgAAAGk"]
[Thu Jul 30 14:44:19.103370 2026] [security2:error] [pid 43637:tid 43864] [client 172.237.109.114:6172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupk4a8U9lZpWaWlJKQcgAAAGA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:19.342380 2026] [autoindex:error] [pid 43637:tid 43859] [client 43.134.56.214:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.melatipkr.xyz
[Thu Jul 30 14:44:19.391860 2026] [security2:error] [pid 43637:tid 43887] [client 20.226.5.174:45487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/providers/zmFM.php"] [unique_id "amupk4a8U9lZpWaWlJKQeAAAAHc"]
[Thu Jul 30 14:44:20.578088 2026] [security2:error] [pid 43637:tid 43860] [client 20.226.5.174:45465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/ptk.php"] [unique_id "amuplIa8U9lZpWaWlJKQjgAAAFw"]
[Thu Jul 30 14:44:20.801140 2026] [core:notice] [pid 43637:tid 43764] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:20.883469 2026] [security2:error] [pid 43637:tid 43750] [remote 57.141.0.35:41146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuplIa8U9lZpWaWlJKQmQAAAXA"]
[Thu Jul 30 14:44:21.120457 2026] [core:notice] [pid 43637:tid 43706] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:21.636203 2026] [security2:error] [pid 43637:tid 43799] [client 20.226.5.174:45456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pu1.php"] [unique_id "amuplYa8U9lZpWaWlJKQpwAAAB8"]
[Thu Jul 30 14:44:21.865663 2026] [security2:error] [pid 43637:tid 43781] [client 189.156.226.90:27550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuplYa8U9lZpWaWlJKQtAAAAA0"]
[Thu Jul 30 14:44:21.865804 2026] [security2:error] [pid 43637:tid 43781] [client 189.156.226.90:27550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuplYa8U9lZpWaWlJKQtAAAAA0"]
[Thu Jul 30 14:44:22.721079 2026] [security2:error] [pid 43637:tid 43860] [client 20.226.5.174:6788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/publicadmin.php"] [unique_id "amuploa8U9lZpWaWlJKQwAAAAFw"]
[Thu Jul 30 14:44:23.462230 2026] [security2:error] [pid 43637:tid 43840] [client 52.238.199.152:53204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/gecko-new.php"] [unique_id "amupl4a8U9lZpWaWlJKQ0wAAAEg"]
[Thu Jul 30 14:44:23.725333 2026] [security2:error] [pid 43637:tid 43859] [client 20.226.5.174:6804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/publicalfa.php"] [unique_id "amupl4a8U9lZpWaWlJKQ1wAAAFs"]
[Thu Jul 30 14:44:24.163067 2026] [security2:error] [pid 43637:tid 43789] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupl4a8U9lZpWaWlJKQ1gAAABU"]
[Thu Jul 30 14:44:24.255922 2026] [security2:error] [pid 43637:tid 43674] [remote 57.141.0.28:55588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amupmIa8U9lZpWaWlJKQ4gAAJyQ"]
[Thu Jul 30 14:44:24.533275 2026] [security2:error] [pid 43637:tid 43817] [client 172.237.109.114:7875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amupl4a8U9lZpWaWlJKQ4QAAADE"]
[Thu Jul 30 14:44:24.771799 2026] [security2:error] [pid 43637:tid 43852] [client 20.226.5.174:6795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/publicbypass.php"] [unique_id "amupmIa8U9lZpWaWlJKQ8gAAAFQ"]
[Thu Jul 30 14:44:24.814654 2026] [security2:error] [pid 43637:tid 43879] [client 52.238.199.152:36710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/alfanew.php"] [unique_id "amupmIa8U9lZpWaWlJKQ9AAAAG8"]
[Thu Jul 30 14:44:25.103835 2026] [security2:error] [pid 43637:tid 43851] [client 172.237.109.114:61301] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amupmYa8U9lZpWaWlJKQ_QAAAFM"]
[Thu Jul 30 14:44:25.276247 2026] [security2:error] [pid 43637:tid 43773] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupmIa8U9lZpWaWlJKQ8QAAAAU"]
[Thu Jul 30 14:44:25.857128 2026] [security2:error] [pid 43637:tid 43887] [client 20.226.5.174:6798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/publick.php"] [unique_id "amupmYa8U9lZpWaWlJKRBwAAAHc"]
[Thu Jul 30 14:44:26.037335 2026] [security2:error] [pid 43637:tid 43781] [client 74.7.230.37:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcalendars.meg.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/404.html"] [unique_id "amupmoa8U9lZpWaWlJKRFAAAAA0"]
[Thu Jul 30 14:44:26.037951 2026] [security2:error] [pid 43637:tid 43826] [client 74.7.230.37:57264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcalendars.meg.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amupmoa8U9lZpWaWlJKREgAAOkw"]
[Thu Jul 30 14:44:26.608042 2026] [security2:error] [pid 43637:tid 43789] [client 74.7.230.19:55416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "billsnap-fiyan-co.nxt.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amupmoa8U9lZpWaWlJKRHgAAFWE"]
[Thu Jul 30 14:44:26.869833 2026] [security2:error] [pid 43637:tid 43824] [client 20.226.5.174:6791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/publicwp.php"] [unique_id "amupmoa8U9lZpWaWlJKRKQAAADg"]
[Thu Jul 30 14:44:26.923450 2026] [security2:error] [pid 43637:tid 43774] [client 52.238.199.152:58837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/text.php"] [unique_id "amupmoa8U9lZpWaWlJKRLQAAAAY"]
[Thu Jul 30 14:44:27.315488 2026] [core:notice] [pid 43637:tid 43852] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:27.474506 2026] [security2:error] [pid 43637:tid 43825] [client 52.167.144.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itrnetwork.org"] [uri "/index.php"] [unique_id "amupm4a8U9lZpWaWlJKRNAAAOQg"], referer: https://itrnetwork.org/sponsors/
[Thu Jul 30 14:44:27.915455 2026] [security2:error] [pid 43637:tid 43877] [client 20.226.5.174:6796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/purna.php"] [unique_id "amupm4a8U9lZpWaWlJKRRgAAAG0"]
[Thu Jul 30 14:44:28.265204 2026] [security2:error] [pid 43637:tid 43799] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amupm4a8U9lZpWaWlJKRQgAAHyE"]
[Thu Jul 30 14:44:28.267889 2026] [security2:error] [pid 43637:tid 43782] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupm4a8U9lZpWaWlJKRRQAAAA4"]
[Thu Jul 30 14:44:28.529274 2026] [security2:error] [pid 43637:tid 43804] [client 123.16.194.21:33569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnIa8U9lZpWaWlJKRUAAAACQ"], referer: http://pkf.jo
[Thu Jul 30 14:44:28.542043 2026] [security2:error] [pid 43637:tid 43830] [client 52.238.199.152:36687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/f.php"] [unique_id "amupnIa8U9lZpWaWlJKRWQAAAD4"]
[Thu Jul 30 14:44:28.608224 2026] [security2:error] [pid 43637:tid 43826] [client 113.174.18.148:39667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnIa8U9lZpWaWlJKRVQAAADo"], referer: http://pkf.jo
[Thu Jul 30 14:44:29.051131 2026] [security2:error] [pid 43637:tid 43807] [client 20.226.5.174:6786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pv.php"] [unique_id "amupnYa8U9lZpWaWlJKRZAAAACc"]
[Thu Jul 30 14:44:29.108140 2026] [security2:error] [pid 43637:tid 43792] [client 177.6.106.101:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupnYa8U9lZpWaWlJKRawAAABg"]
[Thu Jul 30 14:44:29.108255 2026] [security2:error] [pid 43637:tid 43792] [client 177.6.106.101:53484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupnYa8U9lZpWaWlJKRawAAABg"]
[Thu Jul 30 14:44:29.247997 2026] [security2:error] [pid 43637:tid 43893] [client 45.181.120.114:49926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnIa8U9lZpWaWlJKRYgAAAH0"], referer: http://pkf.jo
[Thu Jul 30 14:44:29.329837 2026] [security2:error] [pid 43637:tid 43873] [client 93.182.108.169:28068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnIa8U9lZpWaWlJKRYwAAAGk"], referer: http://pkf.jo
[Thu Jul 30 14:44:29.512904 2026] [security2:error] [pid 43637:tid 43824] [client 24.129.84.37:43862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnYa8U9lZpWaWlJKRbAAAADg"], referer: http://pkf.jo
[Thu Jul 30 14:44:29.574166 2026] [security2:error] [pid 43637:tid 43886] [client 186.237.160.60:60059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnYa8U9lZpWaWlJKRcAAAAHY"], referer: http://pkf.jo
[Thu Jul 30 14:44:29.665412 2026] [security2:error] [pid 43637:tid 43869] [client 64.42.179.59:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amupnYa8U9lZpWaWlJKReAAAAGU"]
[Thu Jul 30 14:44:29.665523 2026] [security2:error] [pid 43637:tid 43869] [client 64.42.179.59:36832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amupnYa8U9lZpWaWlJKReAAAAGU"]
[Thu Jul 30 14:44:29.976357 2026] [security2:error] [pid 43637:tid 43835] [client 152.156.110.1:38337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnYa8U9lZpWaWlJKReQAAAEM"], referer: http://pkf.jo
[Thu Jul 30 14:44:30.185276 2026] [security2:error] [pid 43637:tid 43771] [client 20.226.5.174:6806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pwnd-1/admin.php"] [unique_id "amupnoa8U9lZpWaWlJKRggAAAAM"]
[Thu Jul 30 14:44:30.361093 2026] [security2:error] [pid 43637:tid 43647] [remote 57.141.0.1:45146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amupnoa8U9lZpWaWlJKRhwAAIQk"]
[Thu Jul 30 14:44:30.435743 2026] [security2:error] [pid 43637:tid 43822] [client 2.90.126.57:1037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnoa8U9lZpWaWlJKRfgAAADY"], referer: http://pkf.jo
[Thu Jul 30 14:44:30.622156 2026] [security2:error] [pid 43637:tid 43836] [client 177.93.200.35:43218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnoa8U9lZpWaWlJKRhgAAAEQ"], referer: http://pkf.jo
[Thu Jul 30 14:44:31.172754 2026] [security2:error] [pid 43637:tid 43866] [client 116.110.43.245:15895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupnoa8U9lZpWaWlJKRmgAAAGI"], referer: http://pkf.jo
[Thu Jul 30 14:44:31.257180 2026] [security2:error] [pid 43637:tid 43876] [client 20.226.5.174:6803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pwnd-1/pwnd.php"] [unique_id "amupn4a8U9lZpWaWlJKRogAAAGw"]
[Thu Jul 30 14:44:31.922243 2026] [security2:error] [pid 43637:tid 43894] [client 52.238.199.152:36817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amupn4a8U9lZpWaWlJKRsgAAAH4"]
[Thu Jul 30 14:44:32.262783 2026] [security2:error] [pid 43637:tid 43816] [client 20.226.5.174:6797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pwnd.php"] [unique_id "amupoIa8U9lZpWaWlJKRvgAAADA"]
[Thu Jul 30 14:44:32.405763 2026] [security2:error] [pid 43637:tid 43878] [client 189.156.226.90:26659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupoIa8U9lZpWaWlJKRwgAAAG4"]
[Thu Jul 30 14:44:32.405873 2026] [security2:error] [pid 43637:tid 43878] [client 189.156.226.90:26659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupoIa8U9lZpWaWlJKRwgAAAG4"]
[Thu Jul 30 14:44:33.379224 2026] [security2:error] [pid 43637:tid 43799] [client 20.226.5.174:6805] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "chicago-mfg.com"] [uri "/pwnd/1.php"] [unique_id "amupoYa8U9lZpWaWlJKR0wAAAB8"]
[Thu Jul 30 14:44:33.379332 2026] [security2:error] [pid 43637:tid 43799] [client 20.226.5.174:6805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pwnd/1.php"] [unique_id "amupoYa8U9lZpWaWlJKR0wAAAB8"]
[Thu Jul 30 14:44:33.454583 2026] [security2:error] [pid 43637:tid 43849] [client 52.238.199.152:36721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/hehe.php"] [unique_id "amupoYa8U9lZpWaWlJKR1gAAAFE"]
[Thu Jul 30 14:44:34.123862 2026] [security2:error] [pid 43637:tid 43818] [client 172.237.109.114:43094] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amupooa8U9lZpWaWlJKR4wAAADI"]
[Thu Jul 30 14:44:34.321297 2026] [security2:error] [pid 43637:tid 43789] [client 66.249.65.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupoYa8U9lZpWaWlJKR2gAAABU"]
[Thu Jul 30 14:44:34.400398 2026] [security2:error] [pid 43637:tid 43786] [client 20.226.5.174:6807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pwnd/11.php"] [unique_id "amupooa8U9lZpWaWlJKR6wAAABI"]
[Thu Jul 30 14:44:34.404355 2026] [security2:error] [pid 43637:tid 43762] [remote 57.141.0.53:43468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amupooa8U9lZpWaWlJKR7AAAZXs"]
[Thu Jul 30 14:44:34.663378 2026] [security2:error] [pid 43637:tid 43797] [client 51.68.107.154:33987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/robots.txt"] [unique_id "amupooa8U9lZpWaWlJKR8AAAAB0"]
[Thu Jul 30 14:44:34.663506 2026] [security2:error] [pid 43637:tid 43797] [client 51.68.107.154:33987] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jesus.claims"] [uri "/robots.txt"] [unique_id "amupooa8U9lZpWaWlJKR8AAAAB0"]
[Thu Jul 30 14:44:34.827351 2026] [security2:error] [pid 43637:tid 43826] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amupooa8U9lZpWaWlJKR5AAAOho"]
[Thu Jul 30 14:44:35.373915 2026] [security2:error] [pid 43637:tid 43772] [client 20.226.5.174:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pwnd/admin-footer.php"] [unique_id "amupo4a8U9lZpWaWlJKSAwAAAAQ"]
[Thu Jul 30 14:44:35.376998 2026] [security2:error] [pid 43637:tid 43890] [client 79.116.169.149:57154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupo4a8U9lZpWaWlJKR-QAAAHo"], referer: http://pkf.jo
[Thu Jul 30 14:44:35.537531 2026] [core:error] [pid 43637:tid 43662] [remote 52.167.144.193:40974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:44:35.537567 2026] [core:error] [pid 43637:tid 43662] [remote 52.167.144.193:40974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:44:35.897452 2026] [security2:error] [pid 43637:tid 43811] [client 177.54.75.208:8973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupo4a8U9lZpWaWlJKSBQAAACs"], referer: http://pkf.jo
[Thu Jul 30 14:44:36.024687 2026] [security2:error] [pid 43637:tid 43836] [client 157.48.144.123:56498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupo4a8U9lZpWaWlJKSCgAAAEQ"], referer: http://pkf.jo
[Thu Jul 30 14:44:36.498409 2026] [security2:error] [pid 43637:tid 43799] [client 188.119.52.254:31193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuppIa8U9lZpWaWlJKSFAAAAB8"], referer: http://pkf.jo
[Thu Jul 30 14:44:36.719264 2026] [security2:error] [pid 43637:tid 43872] [client 20.226.5.174:6821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pwnd/as.php"] [unique_id "amuppIa8U9lZpWaWlJKSIwAAAGg"]
[Thu Jul 30 14:44:37.663023 2026] [security2:error] [pid 43637:tid 43886] [client 170.233.210.12:47018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuppYa8U9lZpWaWlJKSMQAAAHY"], referer: http://pkf.jo
[Thu Jul 30 14:44:37.727363 2026] [security2:error] [pid 43637:tid 43868] [client 20.226.5.174:6819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pwnd/pwnd.php"] [unique_id "amuppYa8U9lZpWaWlJKSNQAAAGQ"]
[Thu Jul 30 14:44:38.077131 2026] [security2:error] [pid 43637:tid 43838] [client 172.237.109.114:32354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSQAAAAEY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.078615 2026] [security2:error] [pid 43637:tid 43832] [client 172.237.109.114:8305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSQQAAAEA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.086472 2026] [security2:error] [pid 43637:tid 43892] [client 172.237.109.114:26089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSQgAAAHw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.090845 2026] [security2:error] [pid 43637:tid 43772] [client 172.237.109.114:28707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSQwAAAAQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.091508 2026] [security2:error] [pid 43637:tid 43883] [client 172.237.109.114:27901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSRAAAAHM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.091617 2026] [security2:error] [pid 43637:tid 43890] [client 172.237.109.114:18094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSRQAAAHo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.091951 2026] [security2:error] [pid 43637:tid 43878] [client 172.237.109.114:1614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSRgAAAG4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.120101 2026] [security2:error] [pid 43637:tid 43790] [client 172.237.109.114:34509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSRwAAABY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.149406 2026] [security2:error] [pid 43637:tid 43822] [client 172.237.109.114:6134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSSAAAADY"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.150352 2026] [security2:error] [pid 43637:tid 43855] [client 172.237.109.114:9062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSSgAAAFc"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.150381 2026] [security2:error] [pid 43637:tid 43858] [client 172.237.109.114:41009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSSQAAAFo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.150709 2026] [security2:error] [pid 43637:tid 43852] [client 172.237.109.114:18778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amuppoa8U9lZpWaWlJKSSwAAAFQ"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:38.319943 2026] [security2:error] [pid 43637:tid 43847] [client 177.6.106.101:53970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuppoa8U9lZpWaWlJKSTwAAAE8"]
[Thu Jul 30 14:44:38.320068 2026] [security2:error] [pid 43637:tid 43847] [client 177.6.106.101:53970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuppoa8U9lZpWaWlJKSTwAAAE8"]
[Thu Jul 30 14:44:38.556317 2026] [security2:error] [pid 43637:tid 43834] [client 52.238.199.152:36714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/options.php"] [unique_id "amuppoa8U9lZpWaWlJKSWAAAAEI"]
[Thu Jul 30 14:44:38.689918 2026] [security2:error] [pid 43637:tid 43837] [client 20.226.5.174:6810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/qfunctions.php"] [unique_id "amuppoa8U9lZpWaWlJKSXQAAAEU"]
[Thu Jul 30 14:44:39.076675 2026] [security2:error] [pid 43637:tid 43869] [client 172.237.109.114:8494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupp4a8U9lZpWaWlJKSawAAAGU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:39.603187 2026] [security2:error] [pid 43637:tid 43785] [client 85.208.96.196:24702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/06/psg-anuncia-contratacao-de-brasileiro-ex-barca-para-a-temporada/"] [unique_id "amupp4a8U9lZpWaWlJKSdwAAABE"]
[Thu Jul 30 14:44:39.603307 2026] [security2:error] [pid 43637:tid 43785] [client 85.208.96.196:24702] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/06/psg-anuncia-contratacao-de-brasileiro-ex-barca-para-a-temporada/"] [unique_id "amupp4a8U9lZpWaWlJKSdwAAABE"]
[Thu Jul 30 14:44:39.745279 2026] [security2:error] [pid 43637:tid 43889] [client 20.226.5.174:6816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/qinfofuns.php"] [unique_id "amupp4a8U9lZpWaWlJKSeAAAAHk"]
[Thu Jul 30 14:44:39.745701 2026] [security2:error] [pid 43637:tid 43803] [client 92.25.42.229:34086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupp4a8U9lZpWaWlJKScwAAACM"], referer: http://pkf.jo
[Thu Jul 30 14:44:40.047078 2026] [security2:error] [pid 43637:tid 43890] [client 17.241.219.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amupp4a8U9lZpWaWlJKSfgAAAHo"]
[Thu Jul 30 14:44:40.092190 2026] [security2:error] [pid 43637:tid 43821] [client 172.237.109.114:18172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupqIa8U9lZpWaWlJKShgAAADU"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:40.092629 2026] [security2:error] [pid 43637:tid 43770] [client 172.237.109.114:46736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupqIa8U9lZpWaWlJKShwAAAAI"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:40.122344 2026] [security2:error] [pid 43637:tid 43783] [client 172.237.109.114:36443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/wp-login.php"] [unique_id "amupqIa8U9lZpWaWlJKSiAAAAA8"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:40.145589 2026] [security2:error] [pid 43637:tid 43797] [client 52.238.199.152:36705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amupqIa8U9lZpWaWlJKSiQAAAB0"]
[Thu Jul 30 14:44:40.874372 2026] [security2:error] [pid 43637:tid 43861] [client 20.226.5.174:6794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/qwturjyu.php"] [unique_id "amupqIa8U9lZpWaWlJKSmgAAAF0"]
[Thu Jul 30 14:44:41.234252 2026] [security2:error] [pid 43637:tid 43837] [client 52.238.199.152:36689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/images/index.php"] [unique_id "amupqYa8U9lZpWaWlJKSpAAAAEU"]
[Thu Jul 30 14:44:41.980487 2026] [security2:error] [pid 43637:tid 43778] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amupqYa8U9lZpWaWlJKSqAAACl8"]
[Thu Jul 30 14:44:42.011601 2026] [security2:error] [pid 43637:tid 43877] [client 20.226.5.174:6793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/r.php"] [unique_id "amupqoa8U9lZpWaWlJKStwAAAG0"]
[Thu Jul 30 14:44:43.020171 2026] [security2:error] [pid 43637:tid 43828] [client 189.156.226.90:27062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupq4a8U9lZpWaWlJKS1wAAADw"]
[Thu Jul 30 14:44:43.020299 2026] [security2:error] [pid 43637:tid 43828] [client 189.156.226.90:27062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupq4a8U9lZpWaWlJKS1wAAADw"]
[Thu Jul 30 14:44:43.042329 2026] [security2:error] [pid 43637:tid 43779] [client 20.226.5.174:6789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/r3x.php"] [unique_id "amupq4a8U9lZpWaWlJKS2AAAAAs"]
[Thu Jul 30 14:44:44.152280 2026] [security2:error] [pid 43637:tid 43860] [client 20.226.5.174:6785] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "chicago-mfg.com"] [uri "/r57.php"] [unique_id "amuprIa8U9lZpWaWlJKS7QAAAFw"]
[Thu Jul 30 14:44:44.636748 2026] [security2:error] [pid 43637:tid 43878] [client 88.160.215.29:56162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuprIa8U9lZpWaWlJKS9QAAAG4"], referer: http://pkf.jo
[Thu Jul 30 14:44:45.173659 2026] [security2:error] [pid 43637:tid 43849] [client 20.226.5.174:6820] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "chicago-mfg.com"] [uri "/r57.php"] [unique_id "amuprYa8U9lZpWaWlJKTDgAAAFE"]
[Thu Jul 30 14:44:45.940478 2026] [security2:error] [pid 43637:tid 43672] [remote 57.141.0.44:23784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuprYa8U9lZpWaWlJKTTQAAOiI"]
[Thu Jul 30 14:44:46.040772 2026] [security2:error] [pid 43637:tid 43868] [client 52.238.199.152:53197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/uploads/index.php"] [unique_id "amuproa8U9lZpWaWlJKTYgAAAGQ"]
[Thu Jul 30 14:44:46.330047 2026] [security2:error] [pid 43637:tid 43696] [remote 97.74.93.24:41512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuproa8U9lZpWaWlJKTcwAABTo"]
[Thu Jul 30 14:44:46.409893 2026] [security2:error] [pid 43637:tid 43825] [client 20.226.5.174:6808] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "chicago-mfg.com"] [uri "/r57.php"] [unique_id "amuproa8U9lZpWaWlJKTdwAAADk"]
[Thu Jul 30 14:44:46.471866 2026] [security2:error] [pid 43637:tid 43793] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuprYa8U9lZpWaWlJKTSgAAGXM"]
[Thu Jul 30 14:44:46.865763 2026] [security2:error] [pid 43637:tid 43783] [client 52.238.199.152:36735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/13.php"] [unique_id "amuproa8U9lZpWaWlJKThgAAAA8"]
[Thu Jul 30 14:44:46.932045 2026] [security2:error] [pid 43637:tid 43853] [client 177.136.182.6:24898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuproa8U9lZpWaWlJKTegAAAFU"], referer: http://pkf.jo
[Thu Jul 30 14:44:47.453866 2026] [security2:error] [pid 43637:tid 43871] [client 20.226.5.174:6809] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "chicago-mfg.com"] [uri "/r57.php"] [unique_id "amupr4a8U9lZpWaWlJKTogAAAGc"]
[Thu Jul 30 14:44:48.133505 2026] [security2:error] [pid 43637:tid 43869] [client 52.238.199.152:3585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/inputs.php"] [unique_id "amupsIa8U9lZpWaWlJKTsgAAAGU"]
[Thu Jul 30 14:44:48.252779 2026] [security2:error] [pid 43637:tid 43877] [client 85.204.70.116:33241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amupsIa8U9lZpWaWlJKTuQAAAG0"]
[Thu Jul 30 14:44:48.361707 2026] [security2:error] [pid 43637:tid 43847] [client 177.6.106.101:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupsIa8U9lZpWaWlJKTugAAAE8"]
[Thu Jul 30 14:44:48.361837 2026] [security2:error] [pid 43637:tid 43847] [client 177.6.106.101:54384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupsIa8U9lZpWaWlJKTugAAAE8"]
[Thu Jul 30 14:44:48.810197 2026] [security2:error] [pid 43637:tid 43793] [client 85.204.70.116:58297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amupsIa8U9lZpWaWlJKTygAAABk"]
[Thu Jul 30 14:44:49.093605 2026] [security2:error] [pid 43637:tid 43854] [client 85.204.70.116:6771] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amupsYa8U9lZpWaWlJKT2QAAAFY"]
[Thu Jul 30 14:44:49.372946 2026] [security2:error] [pid 43637:tid 43788] [client 85.204.70.116:46654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amupsYa8U9lZpWaWlJKT4AAAABQ"]
[Thu Jul 30 14:44:49.642924 2026] [security2:error] [pid 43637:tid 43791] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupsYa8U9lZpWaWlJKT0gAAABc"]
[Thu Jul 30 14:44:49.674137 2026] [security2:error] [pid 43637:tid 43864] [client 85.204.70.116:46656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amupsYa8U9lZpWaWlJKT5wAAAGA"]
[Thu Jul 30 14:44:49.929690 2026] [security2:error] [pid 43637:tid 43776] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupsYa8U9lZpWaWlJKT3wAAAAg"]
[Thu Jul 30 14:44:49.960295 2026] [security2:error] [pid 43637:tid 43785] [client 85.204.70.116:46668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amupsYa8U9lZpWaWlJKT7gAAABE"]
[Thu Jul 30 14:44:50.231947 2026] [security2:error] [pid 43637:tid 43858] [client 85.204.70.116:46680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amupsoa8U9lZpWaWlJKT-AAAAFo"]
[Thu Jul 30 14:44:50.560319 2026] [http2:info] [pid 62112:tid 62112] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 14:44:50.575948 2026] [security2:error] [pid 62112:tid 62243] [client 85.204.70.116:46686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amupssJgo6iBrIY9VJK34AAAAIY"]
[Thu Jul 30 14:44:50.839139 2026] [security2:error] [pid 62112:tid 62247] [client 85.204.70.116:46694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amupssJgo6iBrIY9VJK34QAAAIo"]
[Thu Jul 30 14:44:50.945892 2026] [core:notice] [pid 62112:tid 62250] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:51.095312 2026] [security2:error] [pid 62112:tid 62260] [client 85.204.70.116:46696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amups8Jgo6iBrIY9VJK37AAAAJc"]
[Thu Jul 30 14:44:51.146117 2026] [security2:error] [pid 43637:tid 43787] [client 52.238.199.152:3642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/jquery.php"] [unique_id "amups4a8U9lZpWaWlJKT-gAAABM"]
[Thu Jul 30 14:44:51.392834 2026] [security2:error] [pid 62112:tid 62276] [client 85.204.70.116:46702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amups8Jgo6iBrIY9VJK38wAAAKc"]
[Thu Jul 30 14:44:51.550724 2026] [security2:error] [pid 62112:tid 62118] [remote 74.7.227.39:60034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amups8Jgo6iBrIY9VJK39wAAowU"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates/loop
[Thu Jul 30 14:44:51.672578 2026] [security2:error] [pid 62112:tid 62283] [client 85.204.70.116:46718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amups8Jgo6iBrIY9VJK3-AAAAK4"]
[Thu Jul 30 14:44:51.961100 2026] [security2:error] [pid 62112:tid 62301] [client 85.204.70.116:46732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amups8Jgo6iBrIY9VJK4AgAAAMA"]
[Thu Jul 30 14:44:52.259154 2026] [security2:error] [pid 62112:tid 62312] [client 85.204.70.116:46734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuptMJgo6iBrIY9VJK4CgAAAMs"]
[Thu Jul 30 14:44:52.270827 2026] [security2:error] [pid 62112:tid 62317] [client 74.7.175.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "parkingandtransport.com"] [uri "/robots.txt"] [unique_id "amuptMJgo6iBrIY9VJK4DQAAANA"]
[Thu Jul 30 14:44:52.271420 2026] [security2:error] [pid 62112:tid 62313] [client 74.7.175.148:49708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "parkingandtransport.com"] [uri "/robots.txt"] [unique_id "amuptMJgo6iBrIY9VJK4CwAAAMw"]
[Thu Jul 30 14:44:52.507486 2026] [security2:error] [pid 62112:tid 62332] [client 85.204.70.116:57176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuptMJgo6iBrIY9VJK4FQAAAN8"]
[Thu Jul 30 14:44:52.719119 2026] [security2:error] [pid 62112:tid 62309] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuptMJgo6iBrIY9VJK4CAAAAMg"]
[Thu Jul 30 14:44:52.796621 2026] [security2:error] [pid 62112:tid 62343] [client 85.204.70.116:57184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuptMJgo6iBrIY9VJK4GQAAAOo"]
[Thu Jul 30 14:44:52.843898 2026] [security2:error] [pid 62112:tid 62128] [remote 57.141.0.69:22046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuptMJgo6iBrIY9VJK4GgAA5A8"]
[Thu Jul 30 14:44:52.923010 2026] [security2:error] [pid 62112:tid 62347] [client 74.7.175.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "parkingandtransport.com"] [uri "/404.html"] [unique_id "amuptMJgo6iBrIY9VJK4HwAAAO4"], referer: http://parkingandtransport.com/robots.txt
[Thu Jul 30 14:44:52.923629 2026] [security2:error] [pid 62112:tid 62340] [client 74.7.175.148:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "parkingandtransport.com"] [uri "/robots.txt"] [unique_id "amuptMJgo6iBrIY9VJK4HAAA5xE"], referer: http://parkingandtransport.com/robots.txt
[Thu Jul 30 14:44:53.062964 2026] [security2:error] [pid 62112:tid 62362] [client 85.204.70.116:57192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.xsx.acn.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuptcJgo6iBrIY9VJK4JwAAAP0"]
[Thu Jul 30 14:44:53.200326 2026] [security2:error] [pid 62112:tid 62256] [client 43.130.26.3:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.26.130.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/index"] [unique_id "amuptcJgo6iBrIY9VJK4LwAAAJM"]
[Thu Jul 30 14:44:53.530955 2026] [security2:error] [pid 62112:tid 62258] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuptcJgo6iBrIY9VJK4MgAAAJU"]
[Thu Jul 30 14:44:53.605403 2026] [security2:error] [pid 62112:tid 62251] [client 189.156.226.90:27258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuptcJgo6iBrIY9VJK4OQAAAI4"]
[Thu Jul 30 14:44:53.605572 2026] [security2:error] [pid 62112:tid 62251] [client 189.156.226.90:27258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuptcJgo6iBrIY9VJK4OQAAAI4"]
[Thu Jul 30 14:44:53.630421 2026] [security2:error] [pid 62112:tid 62361] [client 172.237.109.114:35214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuptcJgo6iBrIY9VJK4KgAAAPw"], referer: https://alseermarine.com:443
[Thu Jul 30 14:44:54.466157 2026] [security2:error] [pid 62112:tid 62300] [client 52.238.199.152:36691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/doc.php"] [unique_id "amuptsJgo6iBrIY9VJK4SQAAAL8"]
[Thu Jul 30 14:44:54.986239 2026] [security2:error] [pid 62112:tid 62316] [client 188.47.116.233:22099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuptsJgo6iBrIY9VJK4TgAAAM8"], referer: http://pkf.jo
[Thu Jul 30 14:44:55.871895 2026] [security2:error] [pid 62112:tid 62358] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amupt8Jgo6iBrIY9VJK4ZwAAAPk"]
[Thu Jul 30 14:44:55.916959 2026] [security2:error] [pid 62112:tid 62355] [client 172.202.44.182:34629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "autodiscover.arabian-tours.com"] [uri "/"] [unique_id "amupt8Jgo6iBrIY9VJK4aAAAAPY"]
[Thu Jul 30 14:44:56.544004 2026] [security2:error] [pid 62112:tid 62363] [client 52.238.199.152:58854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/02.php"] [unique_id "amupuMJgo6iBrIY9VJK4cgAAAP4"]
[Thu Jul 30 14:44:57.537003 2026] [security2:error] [pid 62112:tid 62288] [client 72.27.107.5:32838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupucJgo6iBrIY9VJK4hQAAALM"], referer: http://pkf.jo
[Thu Jul 30 14:44:57.637971 2026] [security2:error] [pid 62112:tid 62295] [client 88.244.88.50:40600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupucJgo6iBrIY9VJK4iQAAALo"], referer: http://pkf.jo
[Thu Jul 30 14:44:58.022180 2026] [security2:error] [pid 62112:tid 62283] [client 177.6.106.101:54807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupusJgo6iBrIY9VJK4lwAAAK4"]
[Thu Jul 30 14:44:58.022339 2026] [security2:error] [pid 62112:tid 62283] [client 177.6.106.101:54807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupusJgo6iBrIY9VJK4lwAAAK4"]
[Thu Jul 30 14:44:58.085042 2026] [security2:error] [pid 62112:tid 62320] [client 185.191.171.12:58996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/23/botafogo-pb-anuncia-a-contratacao-do-meia-anderson-rosa-que-estava-no-futebol-paulista/"] [unique_id "amupusJgo6iBrIY9VJK4mAAAANM"]
[Thu Jul 30 14:44:58.085213 2026] [security2:error] [pid 62112:tid 62320] [client 185.191.171.12:58996] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/23/botafogo-pb-anuncia-a-contratacao-do-meia-anderson-rosa-que-estava-no-futebol-paulista/"] [unique_id "amupusJgo6iBrIY9VJK4mAAAANM"]
[Thu Jul 30 14:44:58.241697 2026] [security2:error] [pid 62112:tid 62277] [client 52.238.199.152:58841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/well-known/admin.php"] [unique_id "amupusJgo6iBrIY9VJK4nQAAAKg"]
[Thu Jul 30 14:44:58.281836 2026] [security2:error] [pid 62112:tid 62316] [client 186.68.148.134:35226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupucJgo6iBrIY9VJK4lAAAAM8"], referer: http://pkf.jo
[Thu Jul 30 14:44:58.306852 2026] [security2:error] [pid 62112:tid 62325] [client 190.140.112.16:57953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupucJgo6iBrIY9VJK4lQAAANg"], referer: http://pkf.jo
[Thu Jul 30 14:44:59.075615 2026] [security2:error] [pid 62112:tid 62174] [remote 110.249.201.96:14968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/product/kent-3/"] [unique_id "amupu8Jgo6iBrIY9VJK4rgAAkT0"]
[Thu Jul 30 14:44:59.082968 2026] [core:notice] [pid 62112:tid 62175] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:44:59.859257 2026] [security2:error] [pid 62112:tid 62369] [client 110.159.42.230:44474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupu8Jgo6iBrIY9VJK4uwAAAQQ"], referer: http://pkf.jo
[Thu Jul 30 14:45:00.040907 2026] [security2:error] [pid 62112:tid 62184] [remote 74.7.227.39:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amupvMJgo6iBrIY9VJK4yAAAp0c"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/premium-addons-for-elementor/modules/woocommerce/templates/loop
[Thu Jul 30 14:45:00.101375 2026] [security2:error] [pid 62112:tid 62296] [client 52.238.199.152:36682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/v.php"] [unique_id "amupvMJgo6iBrIY9VJK4yQAAALs"]
[Thu Jul 30 14:45:00.177844 2026] [core:notice] [pid 62112:tid 62185] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:00.220613 2026] [core:error] [pid 62112:tid 62187] [remote 175.157.8.120:12770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:00.220644 2026] [core:error] [pid 62112:tid 62187] [remote 175.157.8.120:12770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:00.220644 2026] [core:error] [pid 62112:tid 62186] [remote 175.157.8.120:12770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:00.220658 2026] [core:error] [pid 62112:tid 62186] [remote 175.157.8.120:12770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:00.256172 2026] [security2:error] [pid 62112:tid 62188] [remote 57.141.0.7:36628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amupvMJgo6iBrIY9VJK4zgAAvEs"]
[Thu Jul 30 14:45:01.911875 2026] [security2:error] [pid 62112:tid 62318] [client 52.238.199.152:58835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/main.php"] [unique_id "amupvcJgo6iBrIY9VJK48gAAANE"]
[Thu Jul 30 14:45:02.206284 2026] [security2:error] [pid 62112:tid 62368] [client 41.143.130.50:34746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupvcJgo6iBrIY9VJK48AABA1c"], referer: https://pkf.jo
[Thu Jul 30 14:45:02.585758 2026] [security2:error] [pid 62112:tid 62250] [client 85.153.226.231:33728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupvsJgo6iBrIY9VJK4_QAAAI0"], referer: http://pkf.jo
[Thu Jul 30 14:45:02.895432 2026] [security2:error] [pid 62112:tid 62285] [client 37.205.113.172:32572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupvsJgo6iBrIY9VJK5DAAAALA"], referer: http://pkf.jo
[Thu Jul 30 14:45:03.136740 2026] [security2:error] [pid 62112:tid 62274] [client 52.238.199.152:36700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known/file.php"] [unique_id "amupv8Jgo6iBrIY9VJK5FwAAAKU"]
[Thu Jul 30 14:45:03.219788 2026] [security2:error] [pid 62112:tid 62271] [client 91.73.4.252:3590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amupvsJgo6iBrIY9VJK5EQAAomM"], referer: https://skcarrental.ae/car-type/budget-car/?gad_source=1&gad_campaignid=23407362233&gbraid=0AAAABCcUrdkyLCPjbn7cORnSSF-gAXts2&gclid=CjwKCAjw7KvTBhA6EiwAWnutYWyQWSRyI6G4pfrJKAiY5dg9NHCTF832XuBZoiSbXqBwBGW1PtxpkxoCrGUQAvD_BwE
[Thu Jul 30 14:45:04.203114 2026] [security2:error] [pid 62112:tid 62336] [client 189.156.226.90:27609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupwMJgo6iBrIY9VJK5MgAAAOM"]
[Thu Jul 30 14:45:04.203233 2026] [security2:error] [pid 62112:tid 62336] [client 189.156.226.90:27609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupwMJgo6iBrIY9VJK5MgAAAOM"]
[Thu Jul 30 14:45:04.751579 2026] [security2:error] [pid 62112:tid 62223] [remote 57.141.0.6:38008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amupwMJgo6iBrIY9VJK5MwAA-W4"]
[Thu Jul 30 14:45:05.067480 2026] [security2:error] [pid 62112:tid 62342] [client 64.42.179.59:55662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amupwcJgo6iBrIY9VJK5QAAAAOk"]
[Thu Jul 30 14:45:05.067624 2026] [security2:error] [pid 62112:tid 62342] [client 64.42.179.59:55662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amupwcJgo6iBrIY9VJK5QAAAAOk"]
[Thu Jul 30 14:45:05.253166 2026] [core:notice] [pid 62112:tid 62275] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:05.978508 2026] [security2:error] [pid 62112:tid 62335] [client 52.238.199.152:3622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amupwcJgo6iBrIY9VJK5UwAAAOI"]
[Thu Jul 30 14:45:06.137541 2026] [security2:error] [pid 62112:tid 62288] [client 85.106.144.174:61526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupwcJgo6iBrIY9VJK5UgAAALM"], referer: http://pkf.jo
[Thu Jul 30 14:45:06.145939 2026] [core:notice] [pid 62112:tid 62234] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:06.421346 2026] [security2:error] [pid 62112:tid 62293] [client 60.95.11.236:50080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5VAAAALg"], referer: http://pkf.jo
[Thu Jul 30 14:45:06.437962 2026] [security2:error] [pid 62112:tid 62304] [client 103.134.1.115:51461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5WQAAAMM"], referer: http://pkf.jo
[Thu Jul 30 14:45:06.481282 2026] [security2:error] [pid 62112:tid 62295] [client 45.6.0.66:49093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5WgAAALo"], referer: http://pkf.jo
[Thu Jul 30 14:45:06.660936 2026] [security2:error] [pid 62112:tid 62328] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5ZwAAANs"]
[Thu Jul 30 14:45:06.676189 2026] [security2:error] [pid 62112:tid 62329] [client 88.185.21.61:2942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5ZAAAANw"], referer: http://pkf.jo
[Thu Jul 30 14:45:06.918618 2026] [security2:error] [pid 62112:tid 62313] [client 52.238.199.152:3565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amupwsJgo6iBrIY9VJK5fAAAAMw"]
[Thu Jul 30 14:45:07.310929 2026] [security2:error] [pid 62112:tid 62345] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5bQAAAOw"]
[Thu Jul 30 14:45:07.430157 2026] [core:notice] [pid 62112:tid 62266] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:07.754433 2026] [core:notice] [pid 62112:tid 62259] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:08.022820 2026] [security2:error] [pid 62112:tid 62287] [client 52.238.199.152:3595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/file.php"] [unique_id "amupxMJgo6iBrIY9VJK5mgAAALI"]
[Thu Jul 30 14:45:08.830581 2026] [security2:error] [pid 62112:tid 62270] [client 177.6.106.101:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupxMJgo6iBrIY9VJK5qQAAAKE"]
[Thu Jul 30 14:45:08.830702 2026] [security2:error] [pid 62112:tid 62270] [client 177.6.106.101:55248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupxMJgo6iBrIY9VJK5qQAAAKE"]
[Thu Jul 30 14:45:09.230763 2026] [security2:error] [pid 62112:tid 62312] [client 5.25.166.77:14568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5aAAAAMs"], referer: http://pkf.jo
[Thu Jul 30 14:45:09.292070 2026] [security2:error] [pid 62112:tid 62261] [client 176.29.19.112:9663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5fQAAAJg"], referer: http://pkf.jo
[Thu Jul 30 14:45:09.296250 2026] [security2:error] [pid 62112:tid 62355] [client 60.54.215.9:43710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5dAAAAPY"], referer: http://pkf.jo
[Thu Jul 30 14:45:09.296293 2026] [security2:error] [pid 62112:tid 62247] [client 136.34.64.10:44650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupwsJgo6iBrIY9VJK5eQAAAIo"], referer: http://pkf.jo
[Thu Jul 30 14:45:09.297077 2026] [security2:error] [pid 62112:tid 62330] [client 200.92.172.163:42276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupw8Jgo6iBrIY9VJK5gAAAAN0"], referer: http://pkf.jo
[Thu Jul 30 14:45:09.318181 2026] [security2:error] [pid 62112:tid 62358] [client 171.225.9.113:46872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupw8Jgo6iBrIY9VJK5gQAAAPk"], referer: http://pkf.jo
[Thu Jul 30 14:45:09.623335 2026] [security2:error] [pid 62112:tid 62336] [client 172.237.109.114:38797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amupxcJgo6iBrIY9VJK5sQAAAOM"], referer: https://alseermarine.com:443
[Thu Jul 30 14:45:10.224816 2026] [security2:error] [pid 62112:tid 62361] [client 103.191.131.187:6828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupw8Jgo6iBrIY9VJK5iQAAAPw"], referer: http://pkf.jo
[Thu Jul 30 14:45:10.310625 2026] [security2:error] [pid 62112:tid 62272] [client 210.213.112.103:34911] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupw8Jgo6iBrIY9VJK5jwAAAKM"], referer: http://pkf.jo
[Thu Jul 30 14:45:10.401120 2026] [security2:error] [pid 62112:tid 62348] [client 178.216.13.232:52032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupxcJgo6iBrIY9VJK5sAAAAO8"], referer: http://pkf.jo
[Thu Jul 30 14:45:10.496465 2026] [security2:error] [pid 62112:tid 62366] [client 49.34.182.71:55914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupxcJgo6iBrIY9VJK5vQAAAQE"], referer: http://pkf.jo
[Thu Jul 30 14:45:10.891152 2026] [core:notice] [pid 62112:tid 62146] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:11.382380 2026] [core:notice] [pid 62112:tid 62149] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:12.473569 2026] [core:notice] [pid 62112:tid 62317] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:12.528125 2026] [security2:error] [pid 62112:tid 62254] [client 185.244.168.184:49020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupyMJgo6iBrIY9VJK59AAAAJE"], referer: http://pkf.jo
[Thu Jul 30 14:45:12.803828 2026] [core:notice] [pid 62112:tid 62246] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:12.817678 2026] [security2:error] [pid 62112:tid 62359] [client 37.237.164.30:3985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupyMJgo6iBrIY9VJK5-QAAAPo"], referer: http://pkf.jo
[Thu Jul 30 14:45:13.175068 2026] [security2:error] [pid 62112:tid 62269] [client 185.191.171.6:64530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/27/stj-mantem-por-unanimidade-prisao-da-ex-deputada-flordelis/"] [unique_id "amupycJgo6iBrIY9VJK6DwAAAKA"]
[Thu Jul 30 14:45:13.175202 2026] [security2:error] [pid 62112:tid 62269] [client 185.191.171.6:64530] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/27/stj-mantem-por-unanimidade-prisao-da-ex-deputada-flordelis/"] [unique_id "amupycJgo6iBrIY9VJK6DwAAAKA"]
[Thu Jul 30 14:45:13.226441 2026] [security2:error] [pid 62112:tid 62266] [client 91.73.4.252:3590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amupycJgo6iBrIY9VJK6BgAAnTI"], referer: https://skcarrental.ae/car-type/budget-car,suv-car/?post_types=cars
[Thu Jul 30 14:45:13.265623 2026] [security2:error] [pid 62112:tid 62297] [client 174.57.105.70:54548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupyMJgo6iBrIY9VJK6BAAAALw"], referer: http://pkf.jo
[Thu Jul 30 14:45:13.847658 2026] [security2:error] [pid 62112:tid 62316] [client 52.238.199.152:3563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-signup.php"] [unique_id "amupycJgo6iBrIY9VJK6HAAAAM8"]
[Thu Jul 30 14:45:14.748485 2026] [security2:error] [pid 62112:tid 62350] [client 189.156.226.90:26919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupysJgo6iBrIY9VJK6NAAAAPE"]
[Thu Jul 30 14:45:14.748603 2026] [security2:error] [pid 62112:tid 62350] [client 189.156.226.90:26919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amupysJgo6iBrIY9VJK6NAAAAPE"]
[Thu Jul 30 14:45:14.916942 2026] [security2:error] [pid 62112:tid 62312] [client 52.238.199.152:3557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/css/index.php"] [unique_id "amupysJgo6iBrIY9VJK6NQAAAMs"]
[Thu Jul 30 14:45:15.041438 2026] [security2:error] [pid 62112:tid 62291] [client 45.156.129.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amupycJgo6iBrIY9VJK6DgAAALY"]
[Thu Jul 30 14:45:16.244063 2026] [security2:error] [pid 62112:tid 62297] [client 103.134.1.42:42239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupy8Jgo6iBrIY9VJK6TgAAALw"], referer: http://pkf.jo
[Thu Jul 30 14:45:16.296774 2026] [security2:error] [pid 62112:tid 62366] [client 177.197.234.215:15804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupy8Jgo6iBrIY9VJK6TwAAAQE"], referer: http://pkf.jo
[Thu Jul 30 14:45:16.732427 2026] [security2:error] [pid 62112:tid 62288] [client 73.109.63.81:56210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupzMJgo6iBrIY9VJK6WgAAALM"], referer: http://pkf.jo
[Thu Jul 30 14:45:17.033500 2026] [security2:error] [pid 62112:tid 62340] [client 45.156.129.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amupzMJgo6iBrIY9VJK6agAAAOc"]
[Thu Jul 30 14:45:18.692472 2026] [security2:error] [pid 62112:tid 62338] [client 117.110.190.209:55234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amupzsJgo6iBrIY9VJK6hQAAAOU"], referer: http://pkf.jo
[Thu Jul 30 14:45:18.791205 2026] [security2:error] [pid 62112:tid 62245] [client 52.238.199.152:36699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ge.php"] [unique_id "amupzsJgo6iBrIY9VJK6jAAAAIg"]
[Thu Jul 30 14:45:19.520960 2026] [security2:error] [pid 62112:tid 62285] [client 177.6.106.101:55684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupz8Jgo6iBrIY9VJK6oAAAALA"]
[Thu Jul 30 14:45:19.521104 2026] [security2:error] [pid 62112:tid 62285] [client 177.6.106.101:55684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amupz8Jgo6iBrIY9VJK6oAAAALA"]
[Thu Jul 30 14:45:19.759028 2026] [security2:error] [pid 62112:tid 62292] [client 52.238.199.152:3626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/goods.php"] [unique_id "amupz8Jgo6iBrIY9VJK6oQAAALc"]
[Thu Jul 30 14:45:19.804852 2026] [security2:error] [pid 62112:tid 62212] [remote 74.7.243.224:57018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amupz8Jgo6iBrIY9VJK6ogAAyWM"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:45:19.919005 2026] [security2:error] [pid 62112:tid 62361] [client 178.156.185.231:55640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amupzsJgo6iBrIY9VJK6iwAAAPw"], referer: https://globalmarks.pk/
[Thu Jul 30 14:45:20.875655 2026] [security2:error] [pid 62112:tid 62330] [client 52.238.199.152:3520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/403.php"] [unique_id "amup0MJgo6iBrIY9VJK6uAAAAN0"]
[Thu Jul 30 14:45:21.509888 2026] [security2:error] [pid 62112:tid 62250] [client 46.183.217.105:55334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.217.183.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amup0cJgo6iBrIY9VJK6zgAAAI0"]
[Thu Jul 30 14:45:21.509969 2026] [security2:error] [pid 62112:tid 62250] [client 46.183.217.105:55334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amup0cJgo6iBrIY9VJK6zgAAAI0"]
[Thu Jul 30 14:45:21.719336 2026] [security2:error] [pid 62112:tid 62313] [client 45.156.129.167:54800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup0cJgo6iBrIY9VJK60QAAAMw"]
[Thu Jul 30 14:45:21.741250 2026] [security2:error] [pid 62112:tid 62267] [client 190.212.205.212:22580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup0cJgo6iBrIY9VJK6xwAAAJ4"], referer: http://pkf.jo
[Thu Jul 30 14:45:22.028821 2026] [security2:error] [pid 62112:tid 62299] [client 172.58.210.82:28245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup0cJgo6iBrIY9VJK61QAAAL4"], referer: http://pkf.jo
[Thu Jul 30 14:45:22.053741 2026] [security2:error] [pid 62112:tid 62266] [client 52.238.199.152:3628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/public/makeasmtp.php"] [unique_id "amup0sJgo6iBrIY9VJK63gAAAJ0"]
[Thu Jul 30 14:45:22.153744 2026] [core:notice] [pid 62112:tid 62367] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:22.683084 2026] [security2:error] [pid 62112:tid 62269] [client 172.237.109.114:49290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amup0sJgo6iBrIY9VJK64gAAAKA"], referer: https://alseermarine.com:443
[Thu Jul 30 14:45:23.489303 2026] [security2:error] [pid 62112:tid 62304] [client 172.237.109.114:22131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amup08Jgo6iBrIY9VJK68wAAAMM"]
[Thu Jul 30 14:45:23.692917 2026] [security2:error] [pid 62112:tid 62309] [client 45.156.129.164:29954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup08Jgo6iBrIY9VJK6_gAAAMg"]
[Thu Jul 30 14:45:23.936418 2026] [security2:error] [pid 62112:tid 62360] [client 52.238.199.152:47187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/mar.php"] [unique_id "amup08Jgo6iBrIY9VJK7CQAAAPs"]
[Thu Jul 30 14:45:24.563455 2026] [security2:error] [pid 62112:tid 62268] [client 172.237.109.114:26361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amup1MJgo6iBrIY9VJK7DgAAAJ8"]
[Thu Jul 30 14:45:24.709103 2026] [security2:error] [pid 62112:tid 62357] [client 43.173.178.248:39756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/"] [unique_id "amup1MJgo6iBrIY9VJK7FgAAAPg"]
[Thu Jul 30 14:45:24.709924 2026] [security2:error] [pid 62112:tid 62346] [client 43.173.181.248:48460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/12/16/noel-2013-40-idees-de-cadeaux-pour-lui-mode-beaute-techno-voyage/"] [unique_id "amup1MJgo6iBrIY9VJK7FQAAAO0"]
[Thu Jul 30 14:45:24.854912 2026] [security2:error] [pid 62112:tid 62255] [client 43.172.197.92:53912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/06/21/cabas-de-plage-ete-2016/"] [unique_id "amup1MJgo6iBrIY9VJK7GgAAAJI"]
[Thu Jul 30 14:45:24.873336 2026] [security2:error] [pid 62112:tid 62280] [client 43.173.180.218:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/09/27/rituel-nettoyant-visage-bio-phyts/"] [unique_id "amup1MJgo6iBrIY9VJK7GwAAAKs"]
[Thu Jul 30 14:45:24.909346 2026] [security2:error] [pid 62112:tid 62127] [remote 74.7.227.39:43572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amup1MJgo6iBrIY9VJK7KwAAvw4"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/tlp-team/app
[Thu Jul 30 14:45:24.957130 2026] [security2:error] [pid 62112:tid 62348] [client 43.172.198.78:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/04/28/les-10-indispensables-de-la-semaine-7/"] [unique_id "amup1MJgo6iBrIY9VJK7IAAAAO8"]
[Thu Jul 30 14:45:24.991418 2026] [security2:error] [pid 62112:tid 62248] [client 86.220.181.187:52910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup1MJgo6iBrIY9VJK7HwAAAIs"], referer: http://pkf.jo
[Thu Jul 30 14:45:25.133523 2026] [core:notice] [pid 62112:tid 62288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:25.139327 2026] [security2:error] [pid 62112:tid 62288] [client 43.173.181.48:54938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/06/21/cabas-de-plage-ete-2016/"] [unique_id "amup1cJgo6iBrIY9VJK7LwAAALM"], referer: https://carnetdeshopping.com/index.php/2016/06/21/cabas-de-plage-ete-2016/
[Thu Jul 30 14:45:25.139522 2026] [security2:error] [pid 62112:tid 62285] [client 43.173.178.67:59402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/13/apercu-de-la-collection-pain-de-sucre-ete-2014/"] [unique_id "amup1MJgo6iBrIY9VJK7KgAAALA"]
[Thu Jul 30 14:45:25.167027 2026] [autoindex:error] [pid 62112:tid 62327] [client 157.245.56.50:65049] AH01276: Cannot serve directory /home1/fnmgzjte/public_html/website_ab07ce6a/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 14:45:25.189044 2026] [security2:error] [pid 62112:tid 62265] [client 43.173.181.58:48296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/01/31/quelques-jours-shopping-a-barcelone/"] [unique_id "amup1MJgo6iBrIY9VJK7LAAAAJw"]
[Thu Jul 30 14:45:25.289838 2026] [core:notice] [pid 62112:tid 62298] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:25.292448 2026] [security2:error] [pid 62112:tid 62282] [client 189.156.226.90:27157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup1cJgo6iBrIY9VJK7QAAAAK0"]
[Thu Jul 30 14:45:25.292755 2026] [security2:error] [pid 62112:tid 62282] [client 189.156.226.90:27157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup1cJgo6iBrIY9VJK7QAAAAK0"]
[Thu Jul 30 14:45:25.294700 2026] [security2:error] [pid 62112:tid 62298] [client 43.172.196.191:39440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/"] [unique_id "amup1cJgo6iBrIY9VJK7PwAAAL0"], referer: https://carnetdeshopping.com/index.php/tag/shopping-a-londres-le-centre-commercial-westfield-stratford-city-avec-victorias-secret/
[Thu Jul 30 14:45:25.297213 2026] [core:notice] [pid 62112:tid 62291] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:25.302826 2026] [security2:error] [pid 62112:tid 62291] [client 43.173.180.250:56222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/12/16/noel-2013-40-idees-de-cadeaux-pour-lui-mode-beaute-techno-voyage/"] [unique_id "amup1cJgo6iBrIY9VJK7QQAAALY"], referer: https://carnetdeshopping.com/index.php/2013/12/16/noel-2013-40-idees-de-cadeaux-pour-lui-mode-beaute-techno-voyage/?replytocom=969
[Thu Jul 30 14:45:25.385687 2026] [core:notice] [pid 62112:tid 62249] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:25.391839 2026] [core:notice] [pid 62112:tid 62318] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:25.391891 2026] [security2:error] [pid 62112:tid 62249] [client 43.173.179.44:52674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/13/apercu-de-la-collection-pain-de-sucre-ete-2014/"] [unique_id "amup1cJgo6iBrIY9VJK7QgAAAIw"], referer: https://carnetdeshopping.com/index.php/2014/03/13/apercu-de-la-collection-pain-de-sucre-ete-2014/?replytocom=1177
[Thu Jul 30 14:45:25.394476 2026] [core:notice] [pid 62112:tid 62353] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:25.397258 2026] [security2:error] [pid 62112:tid 62318] [client 43.172.195.152:60382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/09/27/rituel-nettoyant-visage-bio-phyts/"] [unique_id "amup1cJgo6iBrIY9VJK7QwAAANE"], referer: https://carnetdeshopping.com/index.php/2015/09/27/rituel-nettoyant-visage-bio-phyts/
[Thu Jul 30 14:45:25.400045 2026] [security2:error] [pid 62112:tid 62353] [client 43.173.176.59:41892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/04/28/les-10-indispensables-de-la-semaine-7/"] [unique_id "amup1cJgo6iBrIY9VJK7RAAAAPQ"], referer: https://carnetdeshopping.com/index.php/2013/04/28/les-10-indispensables-de-la-semaine-7/
[Thu Jul 30 14:45:25.571667 2026] [core:notice] [pid 62112:tid 62317] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:25.577635 2026] [security2:error] [pid 62112:tid 62317] [client 43.173.178.57:47772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/01/31/quelques-jours-shopping-a-barcelone/"] [unique_id "amup1cJgo6iBrIY9VJK7RgAAANA"], referer: https://carnetdeshopping.com/index.php/2012/01/31/quelques-jours-shopping-a-barcelone/?replytocom=305
[Thu Jul 30 14:45:25.907722 2026] [security2:error] [pid 62112:tid 62330] [client 52.238.199.152:58878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/system.php"] [unique_id "amup1cJgo6iBrIY9VJK7XwAAAN0"]
[Thu Jul 30 14:45:26.101066 2026] [security2:error] [pid 62112:tid 62268] [client 95.136.40.174:41720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup1cJgo6iBrIY9VJK7VgAAAJ8"], referer: http://pkf.jo
[Thu Jul 30 14:45:26.194807 2026] [security2:error] [pid 62112:tid 62266] [client 45.156.129.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup1cJgo6iBrIY9VJK7YwAAAJ0"]
[Thu Jul 30 14:45:26.689090 2026] [security2:error] [pid 62112:tid 62299] [client 172.237.109.114:9439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amup1sJgo6iBrIY9VJK7ZQAAAL4"], referer: https://alseermarine.com:443
[Thu Jul 30 14:45:27.233150 2026] [security2:error] [pid 62112:tid 62331] [client 185.191.171.6:17094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/07/19/paraiba-tem-138-secoes-disponiveis-para-voto-em-transito-eleitores-ja-podem-solicitar/"] [unique_id "amup18Jgo6iBrIY9VJK7kgAAAN4"]
[Thu Jul 30 14:45:27.233296 2026] [security2:error] [pid 62112:tid 62331] [client 185.191.171.6:17094] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/07/19/paraiba-tem-138-secoes-disponiveis-para-voto-em-transito-eleitores-ja-podem-solicitar/"] [unique_id "amup18Jgo6iBrIY9VJK7kgAAAN4"]
[Thu Jul 30 14:45:27.614440 2026] [security2:error] [pid 62112:tid 62363] [client 45.156.129.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup18Jgo6iBrIY9VJK7oAAAAP4"]
[Thu Jul 30 14:45:27.763459 2026] [security2:error] [pid 62112:tid 62342] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amup18Jgo6iBrIY9VJK7kAAAAOk"]
[Thu Jul 30 14:45:27.956386 2026] [security2:error] [pid 62112:tid 62312] [client 35.88.176.53:63108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amup18Jgo6iBrIY9VJK7pAAAyyo"]
[Thu Jul 30 14:45:28.764356 2026] [security2:error] [pid 62112:tid 62368] [client 142.93.64.107:49456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "878"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.kfo.lku.temporary.site"] [uri "/"] [unique_id "amup2MJgo6iBrIY9VJK7vwAAAQM"]
[Thu Jul 30 14:45:28.945591 2026] [security2:error] [pid 62112:tid 62294] [client 52.238.199.152:51015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/lock360.php"] [unique_id "amup2MJgo6iBrIY9VJK7xAAAALk"]
[Thu Jul 30 14:45:29.400366 2026] [security2:error] [pid 62112:tid 62268] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup2cJgo6iBrIY9VJK70AAAAJ8"]
[Thu Jul 30 14:45:30.390138 2026] [security2:error] [pid 62112:tid 62252] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amup2cJgo6iBrIY9VJK72gAAjzY"]
[Thu Jul 30 14:45:30.524955 2026] [security2:error] [pid 62112:tid 62303] [client 85.107.92.92:26782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup2sJgo6iBrIY9VJK75gAAAMI"], referer: http://pkf.jo
[Thu Jul 30 14:45:30.684208 2026] [autoindex:error] [pid 62112:tid 62320] [client 54.87.187.46:53032] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:45:30.687830 2026] [autoindex:error] [pid 62112:tid 62350] [client 54.87.187.46:53020] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:45:30.757167 2026] [security2:error] [pid 62112:tid 62259] [client 177.6.106.101:56123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amup2sJgo6iBrIY9VJK78wAAAJY"]
[Thu Jul 30 14:45:30.757309 2026] [security2:error] [pid 62112:tid 62259] [client 177.6.106.101:56123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amup2sJgo6iBrIY9VJK78wAAAJY"]
[Thu Jul 30 14:45:31.741956 2026] [security2:error] [pid 62112:tid 62351] [client 72.193.125.232:41436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup28Jgo6iBrIY9VJK8BwAAAPI"], referer: http://pkf.jo
[Thu Jul 30 14:45:32.237893 2026] [security2:error] [pid 62112:tid 62345] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amup28Jgo6iBrIY9VJK8EgAA7E8"]
[Thu Jul 30 14:45:32.572405 2026] [security2:error] [pid 62112:tid 62324] [client 45.156.129.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup3MJgo6iBrIY9VJK8LQAAANc"]
[Thu Jul 30 14:45:32.581995 2026] [security2:error] [pid 62112:tid 62247] [client 52.238.199.152:36824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amup3MJgo6iBrIY9VJK8MQAAAIo"]
[Thu Jul 30 14:45:33.178989 2026] [security2:error] [pid 62112:tid 62276] [client 105.115.11.118:7318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup3MJgo6iBrIY9VJK8OQAAAKc"], referer: http://pkf.jo
[Thu Jul 30 14:45:34.452475 2026] [security2:error] [pid 62112:tid 62222] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/images/images/cache.php"] [unique_id "amup3sJgo6iBrIY9VJK8VAAA1G0"], referer: www.google.com
[Thu Jul 30 14:45:35.393177 2026] [security2:error] [pid 62112:tid 62273] [client 46.183.217.105:36176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.217.183.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amup38Jgo6iBrIY9VJK8dgAAAKQ"]
[Thu Jul 30 14:45:35.393283 2026] [security2:error] [pid 62112:tid 62273] [client 46.183.217.105:36176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amup38Jgo6iBrIY9VJK8dgAAAKQ"]
[Thu Jul 30 14:45:35.565848 2026] [security2:error] [pid 62112:tid 62234] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/storage/media/media/cache.php"] [unique_id "amup38Jgo6iBrIY9VJK8dwAA5Xk"], referer: www.google.com
[Thu Jul 30 14:45:35.810507 2026] [security2:error] [pid 62112:tid 62238] [remote 185.181.252.107:51052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.252.181.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amup38Jgo6iBrIY9VJK8fAAAjH0"]
[Thu Jul 30 14:45:35.890525 2026] [security2:error] [pid 62112:tid 62331] [client 189.156.226.90:27555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup38Jgo6iBrIY9VJK8gAAAAN4"]
[Thu Jul 30 14:45:35.890655 2026] [security2:error] [pid 62112:tid 62331] [client 189.156.226.90:27555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup38Jgo6iBrIY9VJK8gAAAAN4"]
[Thu Jul 30 14:45:36.273949 2026] [security2:error] [pid 62112:tid 62342] [client 45.156.129.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup4MJgo6iBrIY9VJK8hgAAAOk"]
[Thu Jul 30 14:45:36.632131 2026] [core:notice] [pid 62112:tid 62239] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:36.872148 2026] [core:notice] [pid 62112:tid 62119] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:37.152901 2026] [security2:error] [pid 62112:tid 62265] [client 73.68.113.82:38910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup4MJgo6iBrIY9VJK8nAAAAJw"], referer: http://pkf.jo
[Thu Jul 30 14:45:37.228429 2026] [security2:error] [pid 62112:tid 62126] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/storage/storage/cache.php"] [unique_id "amup4cJgo6iBrIY9VJK8pgAA4A0"], referer: www.google.com
[Thu Jul 30 14:45:37.516999 2026] [security2:error] [pid 62112:tid 62358] [client 52.238.199.152:36801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/mah.php"] [unique_id "amup4cJgo6iBrIY9VJK8sQAAAPk"]
[Thu Jul 30 14:45:38.068684 2026] [security2:error] [pid 62112:tid 62325] [client 45.156.129.166:19104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup4cJgo6iBrIY9VJK8uAAAANg"]
[Thu Jul 30 14:45:38.330891 2026] [security2:error] [pid 62112:tid 62246] [client 149.2.83.28:43514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup4sJgo6iBrIY9VJK8vwAAAIk"], referer: http://pkf.jo
[Thu Jul 30 14:45:38.639229 2026] [security2:error] [pid 62112:tid 62134] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cache.php"] [unique_id "amup4sJgo6iBrIY9VJK8zAAApRU"], referer: www.google.com
[Thu Jul 30 14:45:39.563749 2026] [security2:error] [pid 62112:tid 62295] [client 52.238.199.152:59783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-class.php"] [unique_id "amup48Jgo6iBrIY9VJK84gAAALo"]
[Thu Jul 30 14:45:39.586088 2026] [security2:error] [pid 62112:tid 62306] [client 45.156.129.164:55896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup48Jgo6iBrIY9VJK82wAAAMU"]
[Thu Jul 30 14:45:40.220221 2026] [security2:error] [pid 62112:tid 62153] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/images/images/images/images/images/images/images/images/cache.php"] [unique_id "amup5MJgo6iBrIY9VJK87gAA7ig"], referer: www.google.com
[Thu Jul 30 14:45:40.532184 2026] [security2:error] [pid 62112:tid 62283] [client 177.6.106.101:56713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amup5MJgo6iBrIY9VJK89AAAAK4"]
[Thu Jul 30 14:45:40.532371 2026] [security2:error] [pid 62112:tid 62283] [client 177.6.106.101:56713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amup5MJgo6iBrIY9VJK89AAAAK4"]
[Thu Jul 30 14:45:40.785158 2026] [security2:error] [pid 62112:tid 62334] [client 20.104.18.253:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/workart/db.php"] [unique_id "amup5MJgo6iBrIY9VJK8_wAAAOE"]
[Thu Jul 30 14:45:40.926667 2026] [security2:error] [pid 62112:tid 62251] [client 45.156.129.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup5MJgo6iBrIY9VJK8_gAAAI4"]
[Thu Jul 30 14:45:41.388128 2026] [core:notice] [pid 62112:tid 62271] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:41.415841 2026] [security2:error] [pid 62112:tid 62314] [client 52.238.199.152:3647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/backup.php"] [unique_id "amup5cJgo6iBrIY9VJK9CwAAAM0"]
[Thu Jul 30 14:45:41.453677 2026] [security2:error] [pid 62112:tid 62355] [client 20.104.18.253:17252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/workart/doc.php"] [unique_id "amup5cJgo6iBrIY9VJK9DQAAAPY"]
[Thu Jul 30 14:45:41.659937 2026] [security2:error] [pid 62112:tid 62161] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/images/images/images/images/images/images/images/cache.php"] [unique_id "amup5cJgo6iBrIY9VJK9GQAAzjA"], referer: www.google.com
[Thu Jul 30 14:45:42.076963 2026] [security2:error] [pid 62112:tid 62292] [client 20.104.18.253:17953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/worksec.php"] [unique_id "amup5sJgo6iBrIY9VJK9IAAAALc"]
[Thu Jul 30 14:45:42.506445 2026] [security2:error] [pid 62112:tid 62310] [client 154.208.50.151:43478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup5sJgo6iBrIY9VJK9JAAAAMk"], referer: http://pkf.jo
[Thu Jul 30 14:45:42.747296 2026] [security2:error] [pid 62112:tid 62278] [client 20.104.18.253:17943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-.myluv.php"] [unique_id "amup5sJgo6iBrIY9VJK9NwAAAKk"]
[Thu Jul 30 14:45:42.998055 2026] [security2:error] [pid 62112:tid 62263] [client 78.173.20.81:51360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup5sJgo6iBrIY9VJK9MwAAAJo"], referer: http://pkf.jo
[Thu Jul 30 14:45:43.019044 2026] [security2:error] [pid 62112:tid 62173] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/images/images/images/images/images/images/cache.php"] [unique_id "amup58Jgo6iBrIY9VJK9OQAA8Dw"], referer: www.google.com
[Thu Jul 30 14:45:43.335248 2026] [security2:error] [pid 62112:tid 62359] [client 94.253.124.203:35134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup5sJgo6iBrIY9VJK9OAAAAPo"], referer: http://pkf.jo
[Thu Jul 30 14:45:43.461062 2026] [security2:error] [pid 62112:tid 62316] [client 20.104.18.253:17250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-2019.php"] [unique_id "amup58Jgo6iBrIY9VJK9RgAAAM8"]
[Thu Jul 30 14:45:43.486480 2026] [security2:error] [pid 62112:tid 62296] [client 103.87.194.44:43270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup58Jgo6iBrIY9VJK9RAAAALs"], referer: http://pkf.jo
[Thu Jul 30 14:45:43.611363 2026] [security2:error] [pid 62112:tid 62279] [client 173.176.165.189:48566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup58Jgo6iBrIY9VJK9RQAAAKo"], referer: http://pkf.jo
[Thu Jul 30 14:45:44.138398 2026] [security2:error] [pid 62112:tid 62281] [client 20.104.18.253:17248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-22.php"] [unique_id "amup6MJgo6iBrIY9VJK9XwAAAKw"]
[Thu Jul 30 14:45:44.279080 2026] [security2:error] [pid 62112:tid 62305] [client 41.193.224.166:43066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup58Jgo6iBrIY9VJK9UQAAAMQ"], referer: http://pkf.jo
[Thu Jul 30 14:45:44.374681 2026] [security2:error] [pid 62112:tid 62248] [client 102.17.118.238:29124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amup58Jgo6iBrIY9VJK9UwAAAIs"], referer: http://pkf.jo
[Thu Jul 30 14:45:44.413667 2026] [security2:error] [pid 62112:tid 62190] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/images/images/images/images/images/cache.php"] [unique_id "amup6MJgo6iBrIY9VJK9ZgAA5E0"], referer: www.google.com
[Thu Jul 30 14:45:44.725942 2026] [security2:error] [pid 62112:tid 62285] [client 114.10.84.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amup6MJgo6iBrIY9VJK9ZAAAsEk"], referer: https://flixon.net/?tab=post&search&search_filter=post_types&cpage&post_type=any&s=Jalinan%20terlarang%20&_wpnonce=ab8659ecbd
[Thu Jul 30 14:45:44.803165 2026] [security2:error] [pid 62112:tid 62345] [client 20.104.18.253:17271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-SEo.php"] [unique_id "amup6MJgo6iBrIY9VJK9cAAAAOw"]
[Thu Jul 30 14:45:45.383370 2026] [security2:error] [pid 62112:tid 62339] [client 45.156.129.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup6cJgo6iBrIY9VJK9ewAAAOY"]
[Thu Jul 30 14:45:45.405505 2026] [security2:error] [pid 62112:tid 62356] [client 114.10.84.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amup6MJgo6iBrIY9VJK9dAAA91Q"], referer: https://flixon.net/?tab=post&search&search_filter=post_types&cpage&post_type=any&s=Jalinan%20terlarang%20&_wpnonce=ab8659ecbd
[Thu Jul 30 14:45:45.440614 2026] [security2:error] [pid 62112:tid 62249] [client 20.104.18.253:17231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-aa.php"] [unique_id "amup6cJgo6iBrIY9VJK9gwAAAIw"]
[Thu Jul 30 14:45:45.732842 2026] [security2:error] [pid 62112:tid 62354] [client 52.238.199.152:37016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/default.php"] [unique_id "amup6cJgo6iBrIY9VJK9jAAAAPU"]
[Thu Jul 30 14:45:45.964843 2026] [security2:error] [pid 62112:tid 62199] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/images/images/images/images/cache.php"] [unique_id "amup6cJgo6iBrIY9VJK9lQAAolY"], referer: www.google.com
[Thu Jul 30 14:45:46.057781 2026] [security2:error] [pid 62112:tid 62342] [client 20.104.18.253:17934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-act.php"] [unique_id "amup6sJgo6iBrIY9VJK9lgAAAOk"]
[Thu Jul 30 14:45:46.280090 2026] [security2:error] [pid 62112:tid 62289] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amup6cJgo6iBrIY9VJK9iQAAALQ"]
[Thu Jul 30 14:45:46.359233 2026] [security2:error] [pid 62112:tid 62269] [client 189.156.226.90:26630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup6sJgo6iBrIY9VJK9nwAAAKA"]
[Thu Jul 30 14:45:46.359340 2026] [security2:error] [pid 62112:tid 62269] [client 189.156.226.90:26630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup6sJgo6iBrIY9VJK9nwAAAKA"]
[Thu Jul 30 14:45:46.496811 2026] [security2:error] [pid 62112:tid 62200] [remote 5.161.62.209:49408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-4b30cf0f.lld.nyx.temporary.site"] [uri "/.env"] [unique_id "amup6sJgo6iBrIY9VJK9pAAAzlc"]
[Thu Jul 30 14:45:46.723863 2026] [security2:error] [pid 62112:tid 62285] [client 20.104.18.253:17945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-activat.php"] [unique_id "amup6sJgo6iBrIY9VJK9rgAAALA"]
[Thu Jul 30 14:45:46.848505 2026] [security2:error] [pid 62112:tid 62310] [client 45.156.129.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup6sJgo6iBrIY9VJK9qgAAAMk"]
[Thu Jul 30 14:45:47.028236 2026] [security2:error] [pid 62112:tid 62258] [client 52.238.199.152:36995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/maint/about.php"] [unique_id "amup68Jgo6iBrIY9VJK9tgAAAJU"]
[Thu Jul 30 14:45:47.349356 2026] [core:notice] [pid 62112:tid 62272] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:47.426440 2026] [security2:error] [pid 62112:tid 62263] [client 20.104.18.253:17922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-activate.php"] [unique_id "amup68Jgo6iBrIY9VJK9vgAAAJo"]
[Thu Jul 30 14:45:47.877061 2026] [security2:error] [pid 62112:tid 62212] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/images/images/images/cache.php"] [unique_id "amup68Jgo6iBrIY9VJK9ygAA9WM"], referer: www.google.com
[Thu Jul 30 14:45:47.990929 2026] [proxy:error] [pid 62112:tid 62361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:45:47.990995 2026] [proxy_http:error] [pid 62112:tid 62361] [client 87.99.136.174:33880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:45:47.991576 2026] [proxy:error] [pid 62112:tid 62361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:45:47.991617 2026] [proxy_http:error] [pid 62112:tid 62361] [client 87.99.136.174:33880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:45:48.050534 2026] [security2:error] [pid 62112:tid 62317] [client 20.104.18.253:17976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-add-admin.php"] [unique_id "amup7MJgo6iBrIY9VJK93AAAANA"]
[Thu Jul 30 14:45:48.200843 2026] [core:error] [pid 62112:tid 62265] [client 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:48.200865 2026] [core:error] [pid 62112:tid 62265] [client 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:48.205743 2026] [core:error] [pid 62112:tid 62328] [client 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:48.205784 2026] [core:error] [pid 62112:tid 62328] [client 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:48.206571 2026] [core:error] [pid 62112:tid 62248] [client 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:48.206590 2026] [core:error] [pid 62112:tid 62248] [client 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:45:48.642129 2026] [security2:error] [pid 62112:tid 62298] [client 52.238.199.152:58879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amup7MJgo6iBrIY9VJK9_QAAAL0"]
[Thu Jul 30 14:45:48.658332 2026] [security2:error] [pid 62112:tid 62223] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/wp-content/plugins/plugins/cache.php"] [unique_id "amup7MJgo6iBrIY9VJK9_gAAwm4"], referer: www.google.com
[Thu Jul 30 14:45:48.732611 2026] [security2:error] [pid 62112:tid 62260] [client 20.104.18.253:17230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-admin.php"] [unique_id "amup7MJgo6iBrIY9VJK9_wAAAJc"]
[Thu Jul 30 14:45:48.932781 2026] [security2:error] [pid 62112:tid 62246] [client 74.7.175.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "parkingandtransport.com"] [uri "/404.html"] [unique_id "amup7MJgo6iBrIY9VJK-CAAAAIk"]
[Thu Jul 30 14:45:48.933909 2026] [security2:error] [pid 62112:tid 62369] [client 74.7.175.148:33782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "parkingandtransport.com"] [uri "/robots.txt"] [unique_id "amup7MJgo6iBrIY9VJK-BAABBHI"]
[Thu Jul 30 14:45:49.231803 2026] [security2:error] [pid 62112:tid 62290] [client 45.156.129.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup7cJgo6iBrIY9VJK-DwAAALU"]
[Thu Jul 30 14:45:49.406190 2026] [security2:error] [pid 62112:tid 62307] [client 20.104.18.253:17256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "amup7cJgo6iBrIY9VJK-GQAAAMY"]
[Thu Jul 30 14:45:49.499602 2026] [security2:error] [pid 62112:tid 62238] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/assets/images/images/cache.php"] [unique_id "amup7cJgo6iBrIY9VJK-GwAA730"], referer: www.google.com
[Thu Jul 30 14:45:49.613309 2026] [security2:error] [pid 62112:tid 62258] [client 114.10.84.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/wp-login.php"] [unique_id "amup7MJgo6iBrIY9VJK-AwAAlXM"], referer: https://flixon.net/?tab=post&search&search_filter=post_types&cpage&post_type=any&s=Jalinan%20terlarang%20&_wpnonce=ab8659ecbd
[Thu Jul 30 14:45:50.163078 2026] [security2:error] [pid 62112:tid 62316] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amup7cJgo6iBrIY9VJK-HwAAz38"]
[Thu Jul 30 14:45:50.221841 2026] [security2:error] [pid 62112:tid 62252] [client 20.104.18.253:17247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amup7sJgo6iBrIY9VJK-LgAAAI8"]
[Thu Jul 30 14:45:50.491438 2026] [security2:error] [pid 62112:tid 62121] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/blogs/media/media/cache.php"] [unique_id "amup7sJgo6iBrIY9VJK-MgAAsQg"], referer: www.google.com
[Thu Jul 30 14:45:50.974181 2026] [security2:error] [pid 62112:tid 62332] [client 20.104.18.253:17939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-admins.php"] [unique_id "amup7sJgo6iBrIY9VJK-QwAAAN8"]
[Thu Jul 30 14:45:50.982257 2026] [security2:error] [pid 62112:tid 62339] [client 17.241.75.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amup7sJgo6iBrIY9VJK-PgAAAOY"]
[Thu Jul 30 14:45:51.028121 2026] [security2:error] [pid 62112:tid 62330] [client 177.6.106.101:57144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amup78Jgo6iBrIY9VJK-RAAAAN0"]
[Thu Jul 30 14:45:51.028253 2026] [security2:error] [pid 62112:tid 62330] [client 177.6.106.101:57144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amup78Jgo6iBrIY9VJK-RAAAAN0"]
[Thu Jul 30 14:45:51.154149 2026] [proxy:error] [pid 62112:tid 62287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:45:51.154211 2026] [proxy_http:error] [pid 62112:tid 62287] [client 34.233.129.35:57007] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:45:51.154795 2026] [proxy:error] [pid 62112:tid 62287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:45:51.154839 2026] [proxy_http:error] [pid 62112:tid 62287] [client 34.233.129.35:57007] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:45:51.177709 2026] [core:notice] [pid 62112:tid 62306] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:51.218879 2026] [security2:error] [pid 62112:tid 62134] [remote 62.60.130.210:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allmontecristi.com"] [uri "/cache/cache/cache.php"] [unique_id "amup78Jgo6iBrIY9VJK-VwAAlRU"], referer: www.google.com
[Thu Jul 30 14:45:51.440460 2026] [security2:error] [pid 62112:tid 62318] [client 52.238.199.152:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ty.php"] [unique_id "amup78Jgo6iBrIY9VJK-XQAAANE"]
[Thu Jul 30 14:45:51.647937 2026] [core:notice] [pid 62112:tid 62143] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:51.664185 2026] [security2:error] [pid 62112:tid 62340] [client 20.104.18.253:17262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-aespa.php"] [unique_id "amup78Jgo6iBrIY9VJK-agAAAOc"]
[Thu Jul 30 14:45:51.693105 2026] [security2:error] [pid 62112:tid 62267] [client 45.156.129.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup78Jgo6iBrIY9VJK-YAAAAJ4"]
[Thu Jul 30 14:45:51.926339 2026] [core:notice] [pid 62112:tid 62154] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:52.312191 2026] [security2:error] [pid 62112:tid 62302] [client 110.249.202.155:18206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/robots.txt"] [unique_id "amup8MJgo6iBrIY9VJK-fQAAAME"]
[Thu Jul 30 14:45:52.358741 2026] [security2:error] [pid 62112:tid 62268] [client 20.104.18.253:17261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-akuma.php"] [unique_id "amup8MJgo6iBrIY9VJK-gQAAAJ8"]
[Thu Jul 30 14:45:52.360733 2026] [security2:error] [pid 62112:tid 62273] [client 87.99.136.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qax.tqa.temporary.site"] [uri "/index.php"] [unique_id "amup7MJgo6iBrIY9VJK97QAAAKQ"]
[Thu Jul 30 14:45:52.371538 2026] [security2:error] [pid 62112:tid 62313] [client 87.99.136.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qax.tqa.temporary.site"] [uri "/index.php"] [unique_id "amup68Jgo6iBrIY9VJK91AAAAMw"]
[Thu Jul 30 14:45:52.423533 2026] [security2:error] [pid 62112:tid 62342] [client 87.99.136.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qax.tqa.temporary.site"] [uri "/index.php"] [unique_id "amup7MJgo6iBrIY9VJK92wAAAOk"]
[Thu Jul 30 14:45:52.471364 2026] [security2:error] [pid 62112:tid 62352] [client 87.99.136.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.qax.tqa.temporary.site"] [uri "/index.php"] [unique_id "amup7MJgo6iBrIY9VJK95gAAAPM"]
[Thu Jul 30 14:45:53.024069 2026] [security2:error] [pid 62112:tid 62277] [client 20.104.18.253:17278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-api.php"] [unique_id "amup8cJgo6iBrIY9VJK-lQAAAKg"]
[Thu Jul 30 14:45:53.683791 2026] [security2:error] [pid 62112:tid 62326] [client 20.104.18.253:17257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-apxupx.php"] [unique_id "amup8cJgo6iBrIY9VJK-ogAAANk"]
[Thu Jul 30 14:45:53.748947 2026] [security2:error] [pid 62112:tid 62318] [client 172.237.109.114:49673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amup8cJgo6iBrIY9VJK-lgAAANE"], referer: https://alseermarine.com:443
[Thu Jul 30 14:45:53.939353 2026] [security2:error] [pid 62112:tid 62169] [remote 57.141.0.59:52902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amup8cJgo6iBrIY9VJK-qgAAxzg"]
[Thu Jul 30 14:45:54.437398 2026] [security2:error] [pid 62112:tid 62366] [client 20.104.18.253:17941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-atom.php"] [unique_id "amup8sJgo6iBrIY9VJK-twAAAQE"]
[Thu Jul 30 14:45:55.183952 2026] [security2:error] [pid 62112:tid 62243] [client 20.104.18.253:27117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-atomx.php"] [unique_id "amup88Jgo6iBrIY9VJK-xgAAAIY"]
[Thu Jul 30 14:45:55.529467 2026] [security2:error] [pid 62112:tid 62174] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/wp-login.php"] [unique_id "amup88Jgo6iBrIY9VJK-xQAAnT0"], referer: https://www.spececigarette.com/
[Thu Jul 30 14:45:55.673479 2026] [security2:error] [pid 62112:tid 62325] [client 52.238.199.152:58923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/readme.php"] [unique_id "amup88Jgo6iBrIY9VJK-0AAAANg"]
[Thu Jul 30 14:45:55.881425 2026] [security2:error] [pid 62112:tid 62292] [client 20.104.18.253:17937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-backup-sql-302.php"] [unique_id "amup88Jgo6iBrIY9VJK-1wAAALc"]
[Thu Jul 30 14:45:55.907659 2026] [security2:error] [pid 62112:tid 62187] [remote 5.161.62.209:30108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-723a6906.glb.nyx.temporary.site"] [uri "/.env"] [unique_id "amup88Jgo6iBrIY9VJK-2wAA50o"]
[Thu Jul 30 14:45:56.025586 2026] [security2:error] [pid 62112:tid 62270] [client 94.154.43.229:39558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ecre.ae"] [uri "/.env"] [unique_id "amup9MJgo6iBrIY9VJK-3wAAAKE"]
[Thu Jul 30 14:45:56.074972 2026] [security2:error] [pid 62112:tid 62247] [client 45.156.129.166:14066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup88Jgo6iBrIY9VJK-2QAAAIo"]
[Thu Jul 30 14:45:56.103697 2026] [security2:error] [pid 62112:tid 62186] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/blog/wp-login.php"] [unique_id "amup9MJgo6iBrIY9VJK-4gAA8kk"], referer: https://www.spececigarette.com/blog/
[Thu Jul 30 14:45:56.622891 2026] [security2:error] [pid 62112:tid 62354] [client 20.104.18.253:17277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-beckup.php"] [unique_id "amup9MJgo6iBrIY9VJK-8AAAAPU"]
[Thu Jul 30 14:45:56.969823 2026] [security2:error] [pid 62112:tid 62275] [client 189.156.226.90:27038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup9MJgo6iBrIY9VJK--gAAAKY"]
[Thu Jul 30 14:45:56.969971 2026] [security2:error] [pid 62112:tid 62275] [client 189.156.226.90:27038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup9MJgo6iBrIY9VJK--gAAAKY"]
[Thu Jul 30 14:45:56.979055 2026] [security2:error] [pid 62112:tid 62364] [client 52.238.199.152:33954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/options.php"] [unique_id "amup9MJgo6iBrIY9VJK--wAAAP8"]
[Thu Jul 30 14:45:57.321374 2026] [security2:error] [pid 62112:tid 62263] [client 20.104.18.253:17234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-blockdown.php"] [unique_id "amup9cJgo6iBrIY9VJK_BAAAAJo"]
[Thu Jul 30 14:45:57.675038 2026] [security2:error] [pid 62112:tid 62204] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/wordpress/wp-login.php"] [unique_id "amup9cJgo6iBrIY9VJK_DgAA91s"], referer: https://www.spececigarette.com/wordpress/
[Thu Jul 30 14:45:57.719703 2026] [security2:error] [pid 62112:tid 62247] [client 45.156.129.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup9cJgo6iBrIY9VJK_CgAAAIo"]
[Thu Jul 30 14:45:58.088769 2026] [security2:error] [pid 62112:tid 62350] [client 20.104.18.253:17224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-blog-header.php"] [unique_id "amup9sJgo6iBrIY9VJK_FQAAAPE"]
[Thu Jul 30 14:45:58.239289 2026] [security2:error] [pid 62112:tid 62208] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/wp/wp-login.php"] [unique_id "amup9sJgo6iBrIY9VJK_HQAAol8"], referer: https://www.spececigarette.com/wp/
[Thu Jul 30 14:45:58.457470 2026] [security2:error] [pid 62112:tid 62209] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/cms/wp-login.php"] [unique_id "amup9sJgo6iBrIY9VJK_JQAA-GA"], referer: https://www.spececigarette.com/cms/
[Thu Jul 30 14:45:58.564693 2026] [core:notice] [pid 62112:tid 62290] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:45:58.710990 2026] [security2:error] [pid 62112:tid 62210] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/site/wp-login.php"] [unique_id "amup9sJgo6iBrIY9VJK_KgAA0GE"], referer: https://www.spececigarette.com/site/
[Thu Jul 30 14:45:58.794583 2026] [security2:error] [pid 62112:tid 62304] [client 20.104.18.253:17951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-blog-post.php"] [unique_id "amup9sJgo6iBrIY9VJK_KwAAAMM"]
[Thu Jul 30 14:45:59.564026 2026] [security2:error] [pid 62112:tid 62285] [client 20.104.18.253:17935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-blog.php"] [unique_id "amup98Jgo6iBrIY9VJK_PAAAALA"]
[Thu Jul 30 14:45:59.840522 2026] [security2:error] [pid 62112:tid 62214] [remote 54.37.118.93:60566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aded-rdc.org"] [uri "/developpement-des-capacite-s-organisationnelles/"] [unique_id "amup98Jgo6iBrIY9VJK_QwAA0WU"]
[Thu Jul 30 14:45:59.840694 2026] [security2:error] [pid 62112:tid 62318] [client 54.37.118.93:60566] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aded-rdc.org"] [uri "/developpement-des-capacite-s-organisationnelles/"] [unique_id "amup98Jgo6iBrIY9VJK_QwAA0WU"]
[Thu Jul 30 14:46:00.115582 2026] [security2:error] [pid 62112:tid 62329] [client 52.238.199.152:33929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/admin.php7"] [unique_id "amup-MJgo6iBrIY9VJK_SwAAANw"]
[Thu Jul 30 14:46:00.256820 2026] [security2:error] [pid 62112:tid 62226] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/main/wp-login.php"] [unique_id "amup-MJgo6iBrIY9VJK_VAAAwnE"], referer: https://www.spececigarette.com/main/
[Thu Jul 30 14:46:00.309442 2026] [security2:error] [pid 62112:tid 62339] [client 20.104.18.253:17928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-booking.php"] [unique_id "amup-MJgo6iBrIY9VJK_VQAAAOY"]
[Thu Jul 30 14:46:00.377169 2026] [security2:error] [pid 62112:tid 62368] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amup98Jgo6iBrIY9VJK_QgABA2c"]
[Thu Jul 30 14:46:00.404011 2026] [security2:error] [pid 62112:tid 62282] [client 45.156.129.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oceanscout.com"] [uri "/index.php"] [unique_id "amup-MJgo6iBrIY9VJK_UwAAAK0"]
[Thu Jul 30 14:46:00.842705 2026] [security2:error] [pid 62112:tid 62229] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/new/wp-login.php"] [unique_id "amup-MJgo6iBrIY9VJK_YgAApHQ"], referer: https://www.spececigarette.com/new/
[Thu Jul 30 14:46:00.942505 2026] [core:notice] [pid 62112:tid 62353] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:00.960725 2026] [core:notice] [pid 62112:tid 62254] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:01.091315 2026] [security2:error] [pid 62112:tid 62269] [client 20.104.18.253:17957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-cache.php"] [unique_id "amup-cJgo6iBrIY9VJK_bQAAAKA"]
[Thu Jul 30 14:46:01.395247 2026] [core:notice] [pid 62112:tid 62300] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:01.445325 2026] [security2:error] [pid 62112:tid 62117] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/wp-login.php"] [unique_id "amup-cJgo6iBrIY9VJK_dQAA2gQ"], referer: http://www.spececigarette.com/
[Thu Jul 30 14:46:01.705459 2026] [security2:error] [pid 62112:tid 62118] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/blog/wp-login.php"] [unique_id "amup-cJgo6iBrIY9VJK_fwAA5QU"], referer: http://www.spececigarette.com/blog/
[Thu Jul 30 14:46:01.778339 2026] [core:notice] [pid 62112:tid 62239] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:01.784761 2026] [core:notice] [pid 62112:tid 62291] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:01.785763 2026] [core:notice] [pid 62112:tid 62122] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:01.792021 2026] [security2:error] [pid 62112:tid 62116] [remote 216.73.216.51:34986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amup-cJgo6iBrIY9VJK_hwAAnAM"]
[Thu Jul 30 14:46:01.882413 2026] [security2:error] [pid 62112:tid 62316] [client 20.104.18.253:17959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-casper.php"] [unique_id "amup-cJgo6iBrIY9VJK_iAAAAM8"]
[Thu Jul 30 14:46:01.887881 2026] [security2:error] [pid 62112:tid 62290] [client 177.6.106.101:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amup-cJgo6iBrIY9VJK_iQAAALU"]
[Thu Jul 30 14:46:01.888063 2026] [security2:error] [pid 62112:tid 62290] [client 177.6.106.101:53536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amup-cJgo6iBrIY9VJK_iQAAALU"]
[Thu Jul 30 14:46:01.893404 2026] [security2:error] [pid 62112:tid 62245] [client 52.238.199.152:36900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known/wp-login.php"] [unique_id "amup-cJgo6iBrIY9VJK_fAAAAIg"]
[Thu Jul 30 14:46:01.947537 2026] [security2:error] [pid 62112:tid 62125] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/wordpress/wp-login.php"] [unique_id "amup-cJgo6iBrIY9VJK_igAAmgw"], referer: http://www.spececigarette.com/wordpress/
[Thu Jul 30 14:46:02.562713 2026] [security2:error] [pid 62112:tid 62130] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/wp/wp-login.php"] [unique_id "amup-sJgo6iBrIY9VJK_mAAA7RE"], referer: http://www.spececigarette.com/wp/
[Thu Jul 30 14:46:02.613796 2026] [security2:error] [pid 62112:tid 62341] [client 20.104.18.253:17926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.worldofwhiskers.com"] [uri "/wp-checkbex.php"] [unique_id "amup-sJgo6iBrIY9VJK_nAAAAOg"]
[Thu Jul 30 14:46:02.684110 2026] [security2:error] [pid 62112:tid 62131] [remote 57.141.0.65:50386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amup-sJgo6iBrIY9VJK_ngAArRI"]
[Thu Jul 30 14:46:02.814353 2026] [security2:error] [pid 62112:tid 62135] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/cms/wp-login.php"] [unique_id "amup-sJgo6iBrIY9VJK_owAAkxY"], referer: http://www.spececigarette.com/cms/
[Thu Jul 30 14:46:02.948374 2026] [security2:error] [pid 62112:tid 62336] [client 52.238.199.152:37069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amup-sJgo6iBrIY9VJK_pQAAAOM"]
[Thu Jul 30 14:46:03.404494 2026] [security2:error] [pid 62112:tid 62143] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/site/wp-login.php"] [unique_id "amup-8Jgo6iBrIY9VJK_twAAhR4"], referer: http://www.spececigarette.com/site/
[Thu Jul 30 14:46:03.653246 2026] [security2:error] [pid 62112:tid 62154] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/main/wp-login.php"] [unique_id "amup-8Jgo6iBrIY9VJK_vwAAlik"], referer: http://www.spececigarette.com/main/
[Thu Jul 30 14:46:03.921416 2026] [security2:error] [pid 62112:tid 62324] [client 2a03:2880:f800:11:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amup-8Jgo6iBrIY9VJK_tgAA1yI"]
[Thu Jul 30 14:46:04.141844 2026] [security2:error] [pid 62112:tid 62170] [remote 57.141.0.69:31712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amup_MJgo6iBrIY9VJK_2AAAjTk"]
[Thu Jul 30 14:46:04.263355 2026] [security2:error] [pid 62112:tid 62318] [client 52.238.199.152:36898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/file.php"] [unique_id "amup_MJgo6iBrIY9VJK_3AAAANE"]
[Thu Jul 30 14:46:04.957267 2026] [security2:error] [pid 62112:tid 62187] [remote 93.123.109.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.spececigarette.com"] [uri "/new/wp-login.php"] [unique_id "amup_MJgo6iBrIY9VJK_8wAAkEo"], referer: http://www.spececigarette.com/new/
[Thu Jul 30 14:46:05.552284 2026] [security2:error] [pid 62112:tid 62352] [client 52.238.199.152:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/bak.php"] [unique_id "amup_cJgo6iBrIY9VJLABwAAAPM"]
[Thu Jul 30 14:46:06.281179 2026] [security2:error] [pid 62112:tid 62319] [client 184.75.221.59:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amup_sJgo6iBrIY9VJLAGgAAANI"]
[Thu Jul 30 14:46:06.281279 2026] [security2:error] [pid 62112:tid 62319] [client 184.75.221.59:56658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amup_sJgo6iBrIY9VJLAGgAAANI"]
[Thu Jul 30 14:46:07.547813 2026] [security2:error] [pid 62112:tid 62305] [client 189.156.226.90:27251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup_8Jgo6iBrIY9VJLAYAAAAMQ"]
[Thu Jul 30 14:46:07.547942 2026] [security2:error] [pid 62112:tid 62305] [client 189.156.226.90:27251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amup_8Jgo6iBrIY9VJLAYAAAAMQ"]
[Thu Jul 30 14:46:08.260857 2026] [security2:error] [pid 62112:tid 62277] [client 52.238.199.152:51038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/config.php"] [unique_id "amuqAMJgo6iBrIY9VJLAdQAAAKg"]
[Thu Jul 30 14:46:08.306880 2026] [security2:error] [pid 62112:tid 62324] [client 172.202.44.182:8139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.mukasarati.com"] [uri "/"] [unique_id "amuqAMJgo6iBrIY9VJLAeAAAANc"]
[Thu Jul 30 14:46:08.949852 2026] [security2:error] [pid 62112:tid 62368] [client 172.202.44.182:8132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.mukasarati.com"] [uri "/"] [unique_id "amuqAMJgo6iBrIY9VJLAhgAAAQM"]
[Thu Jul 30 14:46:10.910892 2026] [fcgid:warn] [pid 62112:tid 62302] (70014)End of file found: [client 143.198.88.13:56257] mod_fcgid: can't get data from http client
[Thu Jul 30 14:46:12.026182 2026] [security2:error] [pid 62112:tid 62350] [client 177.6.106.101:53977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqBMJgo6iBrIY9VJLA5AAAAPE"]
[Thu Jul 30 14:46:12.026865 2026] [security2:error] [pid 62112:tid 62350] [client 177.6.106.101:53977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqBMJgo6iBrIY9VJLA5AAAAPE"]
[Thu Jul 30 14:46:12.535639 2026] [security2:error] [pid 62112:tid 62267] [client 143.198.88.13:57513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.worldofwhiskers.com.bkv.gpl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuqBMJgo6iBrIY9VJLA-AAAAJ4"], referer: https://woo.comport.com.tr//wp-login.php
[Thu Jul 30 14:46:12.798362 2026] [security2:error] [pid 62112:tid 62283] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.worldofwhiskers.com.bkv.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuqBMJgo6iBrIY9VJLA_wAAAK4"], referer: https://woo.comport.com.tr//wp-login.php
[Thu Jul 30 14:46:13.114466 2026] [security2:error] [pid 62112:tid 62289] [client 143.198.88.13:57499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.worldofwhiskers.com.bkv.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuqBcJgo6iBrIY9VJLBCAAAALQ"], referer: https://woo.comport.com.tr//wp-login.php
[Thu Jul 30 14:46:13.163729 2026] [security2:error] [pid 62112:tid 62295] [client 65.109.163.125:44916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuqBMJgo6iBrIY9VJLBAgAAALo"]
[Thu Jul 30 14:46:13.300600 2026] [security2:error] [pid 62112:tid 62253] [client 143.198.88.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.worldofwhiskers.com.bkv.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuqBcJgo6iBrIY9VJLBEQAAAJA"], referer: https://woo.comport.com.tr//wp-login.php
[Thu Jul 30 14:46:13.505570 2026] [security2:error] [pid 62112:tid 62299] [client 143.198.88.13:57499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.worldofwhiskers.com.bkv.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuqBcJgo6iBrIY9VJLBFwAAAL4"], referer: https://woo.comport.com.tr//wp-login.php
[Thu Jul 30 14:46:13.559023 2026] [security2:error] [pid 62112:tid 62354] [client 143.198.88.13:57499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.worldofwhiskers.com.bkv.gpl.temporary.site"] [uri "/blog//xmlrpc.php"] [unique_id "amuqBcJgo6iBrIY9VJLBHAAAAPU"]
[Thu Jul 30 14:46:13.559123 2026] [security2:error] [pid 62112:tid 62354] [client 143.198.88.13:57499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.worldofwhiskers.com.bkv.gpl.temporary.site"] [uri "/blog//xmlrpc.php"] [unique_id "amuqBcJgo6iBrIY9VJLBHAAAAPU"]
[Thu Jul 30 14:46:13.617004 2026] [security2:error] [pid 62112:tid 62280] [client 52.238.199.152:55561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amuqBcJgo6iBrIY9VJLBIAAAAKs"]
[Thu Jul 30 14:46:13.682965 2026] [security2:error] [pid 62112:tid 62243] [client 143.198.88.13:64239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.88.198.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.worldofwhiskers.com.bkv.gpl.temporary.site"] [uri "/blog//wp-login.php"] [unique_id "amuqBcJgo6iBrIY9VJLBIQAAAIY"], referer: www.worldofwhiskers.com.bkv.gpl.temporary.site/blog//wp-login.php
[Thu Jul 30 14:46:14.692823 2026] [security2:error] [pid 62112:tid 62284] [client 52.238.199.152:57911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-activate.php"] [unique_id "amuqBsJgo6iBrIY9VJLBNwAAAK8"]
[Thu Jul 30 14:46:15.639219 2026] [security2:error] [pid 62112:tid 62293] [client 93.123.109.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuqB8Jgo6iBrIY9VJLBRQAAuG0"], referer: https://www.spececigarette.com/
[Thu Jul 30 14:46:16.042442 2026] [security2:error] [pid 62112:tid 62356] [client 52.238.199.152:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-file.php"] [unique_id "amuqCMJgo6iBrIY9VJLBTwAAAPc"]
[Thu Jul 30 14:46:16.552313 2026] [security2:error] [pid 62112:tid 62228] [remote 5.161.62.209:51988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d0175726.glb.nyx.temporary.site"] [uri "/.env"] [unique_id "amuqCMJgo6iBrIY9VJLBWwAA4HM"]
[Thu Jul 30 14:46:16.621526 2026] [security2:error] [pid 62112:tid 62117] [remote 52.167.144.162:41481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/pbb/article/download/7395/2951"] [unique_id "amuqCMJgo6iBrIY9VJLBXAAAywQ"]
[Thu Jul 30 14:46:16.659474 2026] [security2:error] [pid 62112:tid 62314] [client 93.123.109.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuqCMJgo6iBrIY9VJLBUwAAzXA"], referer: https://www.spececigarette.com/
[Thu Jul 30 14:46:16.804263 2026] [security2:error] [pid 62112:tid 62238] [remote 216.73.216.51:56979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuqCMJgo6iBrIY9VJLBYwABAn0"]
[Thu Jul 30 14:46:18.013251 2026] [autoindex:error] [pid 62112:tid 62255] [client 170.106.161.78:56038] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:46:18.109433 2026] [security2:error] [pid 62112:tid 62353] [client 189.156.226.90:27619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqCsJgo6iBrIY9VJLBjQAAAPQ"]
[Thu Jul 30 14:46:18.109573 2026] [security2:error] [pid 62112:tid 62353] [client 189.156.226.90:27619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqCsJgo6iBrIY9VJLBjQAAAPQ"]
[Thu Jul 30 14:46:18.447785 2026] [security2:error] [pid 62112:tid 62281] [client 52.238.199.152:36892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/12.php"] [unique_id "amuqCsJgo6iBrIY9VJLBlgAAAKw"]
[Thu Jul 30 14:46:18.926523 2026] [security2:error] [pid 62112:tid 62132] [remote 57.141.18.122:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuqCsJgo6iBrIY9VJLBqAAAqhM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,silicon,titanium,wood,steel,nylon,denim&orderby=price-desc&tax_product_cat=sweatshirts&filter_size=small&unfilter=1
[Thu Jul 30 14:46:19.280734 2026] [security2:error] [pid 62112:tid 62152] [remote 57.141.18.65:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuqC8Jgo6iBrIY9VJLBrAAAxic"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,silicon,titanium,wood,steel,nylon,denim&orderby=price-desc&tax_product_cat=sweatshirts&filter_size=small&unfilter=1
[Thu Jul 30 14:46:19.847710 2026] [security2:error] [pid 62112:tid 62302] [client 52.238.199.152:51037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/epinyins.php"] [unique_id "amuqC8Jgo6iBrIY9VJLBwwAAAME"]
[Thu Jul 30 14:46:19.872599 2026] [security2:error] [pid 62112:tid 62174] [remote 5.161.62.209:32036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-dc09cfb9.jud.zzt.temporary.site"] [uri "/.env"] [unique_id "amuqC8Jgo6iBrIY9VJLBxgAA6j0"]
[Thu Jul 30 14:46:19.991931 2026] [security2:error] [pid 62112:tid 62292] [client 93.123.109.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.spececigarette.com"] [uri "/index.php"] [unique_id "amuqC8Jgo6iBrIY9VJLBvAAAtzE"], referer: https://www.spececigarette.com/
[Thu Jul 30 14:46:22.360674 2026] [security2:error] [pid 62112:tid 62367] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqDcJgo6iBrIY9VJLB7gABAjI"]
[Thu Jul 30 14:46:22.979999 2026] [security2:error] [pid 62112:tid 62182] [remote 74.7.243.224:46368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/article.php"] [unique_id "amuqDsJgo6iBrIY9VJLCBAAAlUU"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/img/main_image_691eb235e69fc.jpg
[Thu Jul 30 14:46:23.252784 2026] [security2:error] [pid 62112:tid 62329] [client 177.6.106.101:54391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqD8Jgo6iBrIY9VJLCCwAAANw"]
[Thu Jul 30 14:46:23.252908 2026] [security2:error] [pid 62112:tid 62329] [client 177.6.106.101:54391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqD8Jgo6iBrIY9VJLCCwAAANw"]
[Thu Jul 30 14:46:23.767416 2026] [security2:error] [pid 62112:tid 62290] [client 91.73.4.252:3598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amuqD8Jgo6iBrIY9VJLCEgAAtVQ"], referer: https://skcarrental.ae/car-type/suv-car/page/3/?post_types=cars
[Thu Jul 30 14:46:25.150392 2026] [security2:error] [pid 62112:tid 62315] [client 52.238.199.152:37470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amuqEcJgo6iBrIY9VJLCNwAAAM4"]
[Thu Jul 30 14:46:26.107541 2026] [security2:error] [pid 62112:tid 62335] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqEcJgo6iBrIY9VJLCPgAA4mA"]
[Thu Jul 30 14:46:26.626571 2026] [security2:error] [pid 62112:tid 62358] [client 52.238.199.152:55571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/system_log.php"] [unique_id "amuqEsJgo6iBrIY9VJLCWAAAAPk"]
[Thu Jul 30 14:46:27.139028 2026] [security2:error] [pid 62112:tid 62215] [remote 85.208.96.207:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jookreview.com"] [uri "/robots.txt"] [unique_id "amuqE8Jgo6iBrIY9VJLCYgAAzWY"]
[Thu Jul 30 14:46:27.139173 2026] [security2:error] [pid 62112:tid 62314] [client 85.208.96.207:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jookreview.com"] [uri "/robots.txt"] [unique_id "amuqE8Jgo6iBrIY9VJLCYgAAzWY"]
[Thu Jul 30 14:46:27.935278 2026] [security2:error] [pid 62112:tid 62324] [client 52.238.199.152:36882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuqE8Jgo6iBrIY9VJLCeAAAANc"]
[Thu Jul 30 14:46:28.639117 2026] [security2:error] [pid 62112:tid 62247] [client 189.156.226.90:26781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqFMJgo6iBrIY9VJLCiQAAAIo"]
[Thu Jul 30 14:46:28.639242 2026] [security2:error] [pid 62112:tid 62247] [client 189.156.226.90:26781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqFMJgo6iBrIY9VJLCiQAAAIo"]
[Thu Jul 30 14:46:29.050475 2026] [security2:error] [pid 62112:tid 62228] [remote 85.208.96.198:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jookreview.com"] [uri "/hydraulic-jack-oil-plugs-24pcs-oil-filler-plug/"] [unique_id "amuqFcJgo6iBrIY9VJLClAAA6HM"]
[Thu Jul 30 14:46:29.050651 2026] [security2:error] [pid 62112:tid 62341] [client 85.208.96.198:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jookreview.com"] [uri "/hydraulic-jack-oil-plugs-24pcs-oil-filler-plug/"] [unique_id "amuqFcJgo6iBrIY9VJLClAAA6HM"]
[Thu Jul 30 14:46:29.271618 2026] [security2:error] [pid 62112:tid 62290] [client 52.238.199.152:51024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ini.php"] [unique_id "amuqFcJgo6iBrIY9VJLCmQAAALU"]
[Thu Jul 30 14:46:31.977780 2026] [core:notice] [pid 62112:tid 62114] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:33.145437 2026] [security2:error] [pid 62112:tid 62249] [client 177.6.106.101:54811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqGcJgo6iBrIY9VJLC5wAAAIw"]
[Thu Jul 30 14:46:33.145582 2026] [security2:error] [pid 62112:tid 62249] [client 177.6.106.101:54811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqGcJgo6iBrIY9VJLC5wAAAIw"]
[Thu Jul 30 14:46:33.409905 2026] [security2:error] [pid 62112:tid 62275] [client 52.238.199.152:37089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ok.php"] [unique_id "amuqGcJgo6iBrIY9VJLC6AAAAKY"]
[Thu Jul 30 14:46:33.584207 2026] [security2:error] [pid 62112:tid 62243] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqGMJgo6iBrIY9VJLC3QAAhho"]
[Thu Jul 30 14:46:34.324314 2026] [core:notice] [pid 62112:tid 62148] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:34.913468 2026] [security2:error] [pid 62112:tid 62359] [client 52.238.199.152:36903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuqGsJgo6iBrIY9VJLDCgAAAPo"]
[Thu Jul 30 14:46:35.179424 2026] [security2:error] [pid 62112:tid 62306] [client 74.7.228.9:34680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.arabian-tours.com"] [uri "/cgi-sys/404.html"] [unique_id "amuqG8Jgo6iBrIY9VJLDEQAAxSY"]
[Thu Jul 30 14:46:36.221659 2026] [security2:error] [pid 62112:tid 62166] [remote 47.128.96.150:65350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/jka/article/view/4380"] [unique_id "amuqG8Jgo6iBrIY9VJLDJwAAiDU"]
[Thu Jul 30 14:46:36.289085 2026] [core:notice] [pid 62112:tid 62172] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:36.293721 2026] [security2:error] [pid 62112:tid 62298] [client 47.128.96.150:65350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jka/article/view/4380"] [unique_id "amuqHMJgo6iBrIY9VJLDMAAAvTs"], referer: https://www.ejournalugj.com/index.php/jka/article/view/4380
[Thu Jul 30 14:46:36.545498 2026] [core:notice] [pid 62112:tid 62155] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:36.625576 2026] [security2:error] [pid 62112:tid 62252] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqHMJgo6iBrIY9VJLDOAAAAI8"]
[Thu Jul 30 14:46:36.658035 2026] [core:notice] [pid 62112:tid 62171] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:36.658186 2026] [core:notice] [pid 62112:tid 62170] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:37.620899 2026] [security2:error] [pid 62112:tid 62359] [client 52.238.199.152:36663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-configs.php"] [unique_id "amuqHcJgo6iBrIY9VJLDUQAAAPo"]
[Thu Jul 30 14:46:38.977300 2026] [security2:error] [pid 62112:tid 62365] [client 172.0.22.9:63448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.22.0.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/xmlrpc.php"] [unique_id "amuqHsJgo6iBrIY9VJLDawAAAQA"]
[Thu Jul 30 14:46:38.977420 2026] [security2:error] [pid 62112:tid 62365] [client 172.0.22.9:63448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alanturner.com.au"] [uri "/xmlrpc.php"] [unique_id "amuqHsJgo6iBrIY9VJLDawAAAQA"]
[Thu Jul 30 14:46:39.240781 2026] [security2:error] [pid 62112:tid 62279] [client 189.156.226.90:27181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqH8Jgo6iBrIY9VJLDdgAAAKo"]
[Thu Jul 30 14:46:39.240910 2026] [security2:error] [pid 62112:tid 62279] [client 189.156.226.90:27181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqH8Jgo6iBrIY9VJLDdgAAAKo"]
[Thu Jul 30 14:46:39.376215 2026] [security2:error] [pid 62112:tid 62325] [client 74.7.241.147:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.urbanshiftmovingcompany.one"] [uri "/index.php"] [unique_id "amuqHsJgo6iBrIY9VJLDbwAA2DI"]
[Thu Jul 30 14:46:40.903024 2026] [security2:error] [pid 62112:tid 62199] [remote 216.73.216.51:36515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqIMJgo6iBrIY9VJLDnQAA71Y"]
[Thu Jul 30 14:46:41.125909 2026] [security2:error] [pid 62112:tid 62358] [client 185.177.72.67:2158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqIcJgo6iBrIY9VJLDpgAAAPk"]
[Thu Jul 30 14:46:41.428809 2026] [security2:error] [pid 62112:tid 62295] [client 52.238.199.152:36659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/01.php"] [unique_id "amuqIcJgo6iBrIY9VJLDrAAAALo"]
[Thu Jul 30 14:46:41.893530 2026] [security2:error] [pid 62112:tid 62303] [client 185.177.72.67:2158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/api.swp"] [unique_id "amuqIcJgo6iBrIY9VJLDtQAAAMI"]
[Thu Jul 30 14:46:41.896028 2026] [core:notice] [pid 62112:tid 62210] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:42.346710 2026] [security2:error] [pid 62112:tid 62343] [client 185.177.72.67:2158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqIsJgo6iBrIY9VJLDwwAAAOo"]
[Thu Jul 30 14:46:42.533169 2026] [security2:error] [pid 62112:tid 62336] [client 74.7.241.132:44810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuqIsJgo6iBrIY9VJLDywAA42A"]
[Thu Jul 30 14:46:43.157237 2026] [security2:error] [pid 62112:tid 62366] [client 185.177.72.67:2158] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.git%00"] [unique_id "amuqI8Jgo6iBrIY9VJLD2wAAAQE"]
[Thu Jul 30 14:46:43.754894 2026] [security2:error] [pid 62112:tid 62310] [client 177.6.106.101:55229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqI8Jgo6iBrIY9VJLD7gAAAMk"]
[Thu Jul 30 14:46:43.755043 2026] [security2:error] [pid 62112:tid 62310] [client 177.6.106.101:55229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqI8Jgo6iBrIY9VJLD7gAAAMk"]
[Thu Jul 30 14:46:44.901793 2026] [security2:error] [pid 62112:tid 62302] [client 185.177.72.67:2158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqJMJgo6iBrIY9VJLECAAAAME"]
[Thu Jul 30 14:46:45.057940 2026] [security2:error] [pid 62112:tid 62311] [client 185.177.72.67:2158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqJcJgo6iBrIY9VJLECQAAAMo"]
[Thu Jul 30 14:46:45.194329 2026] [security2:error] [pid 62112:tid 62357] [client 185.177.72.67:2158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqJcJgo6iBrIY9VJLEEAAAAPg"]
[Thu Jul 30 14:46:45.346020 2026] [security2:error] [pid 62112:tid 62272] [client 185.177.72.67:2158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqJcJgo6iBrIY9VJLEFAAAAKM"]
[Thu Jul 30 14:46:45.967613 2026] [security2:error] [pid 62112:tid 62230] [remote 57.141.0.48:61730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuqJcJgo6iBrIY9VJLEIgAAoXU"]
[Thu Jul 30 14:46:46.422350 2026] [security2:error] [pid 62112:tid 62288] [client 20.104.18.253:42302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/vv.php"] [unique_id "amuqJsJgo6iBrIY9VJLEMAAAALM"]
[Thu Jul 30 14:46:47.151476 2026] [security2:error] [pid 62112:tid 62334] [client 20.104.18.253:42245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/vwcleanerplugin/bump.php"] [unique_id "amuqJ8Jgo6iBrIY9VJLERAAAAOE"]
[Thu Jul 30 14:46:47.440378 2026] [security2:error] [pid 62112:tid 62262] [client 52.238.199.152:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amuqJ8Jgo6iBrIY9VJLEVgAAAJk"]
[Thu Jul 30 14:46:47.556375 2026] [security2:error] [pid 62112:tid 62319] [client 172.237.109.114:2006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuqJsJgo6iBrIY9VJLEPQAAANI"]
[Thu Jul 30 14:46:47.908814 2026] [security2:error] [pid 62112:tid 62278] [client 20.104.18.253:42263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/vwx.php"] [unique_id "amuqJ8Jgo6iBrIY9VJLEZAAAAKk"]
[Thu Jul 30 14:46:47.913897 2026] [security2:error] [pid 62112:tid 62367] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqJ8Jgo6iBrIY9VJLETgAAAQI"]
[Thu Jul 30 14:46:48.640396 2026] [security2:error] [pid 62112:tid 62290] [client 20.104.18.253:42295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/vxrl.php"] [unique_id "amuqKMJgo6iBrIY9VJLEdwAAALU"]
[Thu Jul 30 14:46:49.436194 2026] [security2:error] [pid 62112:tid 62307] [client 20.104.18.253:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/vy2m7.php"] [unique_id "amuqKcJgo6iBrIY9VJLEkAAAAMY"]
[Thu Jul 30 14:46:49.871153 2026] [security2:error] [pid 62112:tid 62325] [client 189.156.226.90:27557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqKcJgo6iBrIY9VJLEnwAAANg"]
[Thu Jul 30 14:46:49.871279 2026] [security2:error] [pid 62112:tid 62325] [client 189.156.226.90:27557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqKcJgo6iBrIY9VJLEnwAAANg"]
[Thu Jul 30 14:46:49.916632 2026] [security2:error] [pid 62112:tid 62249] [client 52.238.199.152:51071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amuqKcJgo6iBrIY9VJLEowAAAIw"]
[Thu Jul 30 14:46:50.081776 2026] [security2:error] [pid 62112:tid 62256] [client 20.104.18.253:42281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/w.php"] [unique_id "amuqKsJgo6iBrIY9VJLEqAAAAJM"]
[Thu Jul 30 14:46:50.795913 2026] [security2:error] [pid 62112:tid 62290] [client 20.104.18.253:24472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/w3llstore.php"] [unique_id "amuqKsJgo6iBrIY9VJLEuQAAALU"]
[Thu Jul 30 14:46:51.620440 2026] [security2:error] [pid 62112:tid 62330] [client 20.104.18.253:24479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/waf_defender.php"] [unique_id "amuqK8Jgo6iBrIY9VJLE1AAAAN0"]
[Thu Jul 30 14:46:51.738870 2026] [security2:error] [pid 62112:tid 62334] [client 185.177.72.67:2158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/info.php"] [unique_id "amuqK8Jgo6iBrIY9VJLEzgAAAOE"]
[Thu Jul 30 14:46:51.893528 2026] [security2:error] [pid 62112:tid 62298] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pna.djb.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuqK8Jgo6iBrIY9VJLE1wAAAL0"]
[Thu Jul 30 14:46:51.894109 2026] [security2:error] [pid 62112:tid 62314] [client 74.7.175.191:56180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.pna.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuqK8Jgo6iBrIY9VJLE1QAAzRw"]
[Thu Jul 30 14:46:51.978345 2026] [core:notice] [pid 62112:tid 62145] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:52.032666 2026] [security2:error] [pid 62112:tid 62319] [client 185.177.72.67:7336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/info.php%257e"] [unique_id "amuqLMJgo6iBrIY9VJLE3wAAANI"]
[Thu Jul 30 14:46:52.293144 2026] [security2:error] [pid 62112:tid 62325] [client 185.177.72.67:7352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/info.php%28%28"] [unique_id "amuqLMJgo6iBrIY9VJLE5AAAANg"]
[Thu Jul 30 14:46:52.416784 2026] [security2:error] [pid 62112:tid 62361] [client 20.104.18.253:24458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wander.php"] [unique_id "amuqLMJgo6iBrIY9VJLE5QAAAPw"]
[Thu Jul 30 14:46:52.548130 2026] [security2:error] [pid 62112:tid 62254] [client 185.177.72.67:7368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/info.php/"] [unique_id "amuqLMJgo6iBrIY9VJLE7wAAAJE"]
[Thu Jul 30 14:46:52.722721 2026] [autoindex:error] [pid 62112:tid 62359] [client 74.7.227.54:0] AH01276: Cannot serve directory /home1/pnadjbte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:46:52.820438 2026] [security2:error] [pid 62112:tid 62322] [client 52.238.199.152:51027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuqLMJgo6iBrIY9VJLE9wAAANU"]
[Thu Jul 30 14:46:53.221883 2026] [security2:error] [pid 62112:tid 62292] [client 20.104.18.253:42266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wawe.php"] [unique_id "amuqLcJgo6iBrIY9VJLFAwAAALc"]
[Thu Jul 30 14:46:54.058175 2026] [security2:error] [pid 62112:tid 62286] [client 114.119.128.132:29399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/investment-calculator"] [unique_id "amuqLsJgo6iBrIY9VJLFGgAAALE"], referer: https://alseermarine.com/investor-relations/fact-sheet
[Thu Jul 30 14:46:54.105468 2026] [security2:error] [pid 62112:tid 62308] [client 20.104.18.253:42283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wb.php"] [unique_id "amuqLsJgo6iBrIY9VJLFHQAAAMc"]
[Thu Jul 30 14:46:54.575037 2026] [security2:error] [pid 62112:tid 62287] [client 177.6.106.101:55669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqLsJgo6iBrIY9VJLFLAAAALI"]
[Thu Jul 30 14:46:54.575144 2026] [security2:error] [pid 62112:tid 62287] [client 177.6.106.101:55669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqLsJgo6iBrIY9VJLFLAAAALI"]
[Thu Jul 30 14:46:54.813483 2026] [security2:error] [pid 62112:tid 62273] [client 20.104.18.253:42257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/we.php"] [unique_id "amuqLsJgo6iBrIY9VJLFNAAAAKQ"]
[Thu Jul 30 14:46:55.520240 2026] [security2:error] [pid 62112:tid 62341] [client 20.104.18.253:42278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/web.php"] [unique_id "amuqL8Jgo6iBrIY9VJLFSwAAAOg"]
[Thu Jul 30 14:46:55.988922 2026] [security2:error] [pid 62112:tid 62267] [client 114.119.136.3:22465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2022/01/034-800x445.jpg"] [unique_id "amuqL8Jgo6iBrIY9VJLFWAAAAJ4"], referer: https://www.nordeste1.com/2022/01/26/tragedia-homem-morre-esmagado-em-colisao-entre-caminhoes-na-br-101-na-grande-joao-pessoa/
[Thu Jul 30 14:46:56.200117 2026] [security2:error] [pid 62112:tid 62283] [client 20.104.18.253:42291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/webadmin.php"] [unique_id "amuqMMJgo6iBrIY9VJLFYwAAAK4"]
[Thu Jul 30 14:46:56.297165 2026] [security2:error] [pid 62112:tid 62324] [client 52.238.199.152:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/db.php"] [unique_id "amuqMMJgo6iBrIY9VJLFaQAAANc"]
[Thu Jul 30 14:46:56.602454 2026] [core:notice] [pid 62112:tid 62277] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:56.969260 2026] [security2:error] [pid 62112:tid 62336] [client 20.104.18.253:24492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/webalfa.php"] [unique_id "amuqMMJgo6iBrIY9VJLFfQAAAOM"]
[Thu Jul 30 14:46:57.700597 2026] [security2:error] [pid 62112:tid 62297] [client 20.104.18.253:42247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/webdb.php"] [unique_id "amuqMcJgo6iBrIY9VJLFlwAAALw"]
[Thu Jul 30 14:46:57.801711 2026] [security2:error] [pid 62112:tid 62253] [client 52.238.199.152:37142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/pages.php"] [unique_id "amuqMcJgo6iBrIY9VJLFmgAAAJA"]
[Thu Jul 30 14:46:58.084334 2026] [core:notice] [pid 62112:tid 62194] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:46:58.412311 2026] [security2:error] [pid 62112:tid 62303] [client 20.104.18.253:42241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/webk.php"] [unique_id "amuqMsJgo6iBrIY9VJLFsAAAAMI"]
[Thu Jul 30 14:46:59.194523 2026] [security2:error] [pid 62112:tid 62336] [client 185.177.72.67:7376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/phpinfo.php"] [unique_id "amuqM8Jgo6iBrIY9VJLFwwAAAOM"]
[Thu Jul 30 14:46:59.263436 2026] [security2:error] [pid 62112:tid 62369] [client 20.104.18.253:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/webshell.php"] [unique_id "amuqM8Jgo6iBrIY9VJLFzwAAAQQ"]
[Thu Jul 30 14:46:59.455114 2026] [security2:error] [pid 62112:tid 62318] [client 185.177.72.67:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/phpinfo.php%255f"] [unique_id "amuqM8Jgo6iBrIY9VJLF0wAAANE"]
[Thu Jul 30 14:46:59.638339 2026] [security2:error] [pid 62112:tid 62302] [client 172.237.109.114:53836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuqM8Jgo6iBrIY9VJLFvwAAAME"]
[Thu Jul 30 14:46:59.708854 2026] [security2:error] [pid 62112:tid 62256] [client 185.177.72.67:51192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/phpinfo.php%253c"] [unique_id "amuqM8Jgo6iBrIY9VJLF1QAAAJM"]
[Thu Jul 30 14:46:59.963594 2026] [security2:error] [pid 62112:tid 62304] [client 185.177.72.67:51200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/phpinfo.php%255d"] [unique_id "amuqM8Jgo6iBrIY9VJLF3AAAAMM"]
[Thu Jul 30 14:47:00.034953 2026] [security2:error] [pid 62112:tid 62348] [client 20.104.18.253:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/webwp.php"] [unique_id "amuqNMJgo6iBrIY9VJLF3QAAAO8"]
[Thu Jul 30 14:47:00.310569 2026] [security2:error] [pid 62112:tid 62356] [client 216.73.216.90:9614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amuqM8Jgo6iBrIY9VJLF1AAA92E"]
[Thu Jul 30 14:47:00.493082 2026] [security2:error] [pid 62112:tid 62306] [client 189.156.226.90:26704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqNMJgo6iBrIY9VJLF4QAAAMU"]
[Thu Jul 30 14:47:00.493211 2026] [security2:error] [pid 62112:tid 62306] [client 189.156.226.90:26704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqNMJgo6iBrIY9VJLF4QAAAMU"]
[Thu Jul 30 14:47:00.754326 2026] [core:notice] [pid 62112:tid 62346] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:00.811866 2026] [security2:error] [pid 62112:tid 62322] [client 52.238.199.152:55580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/admin.php"] [unique_id "amuqNMJgo6iBrIY9VJLF7wAAANU"]
[Thu Jul 30 14:47:00.827184 2026] [security2:error] [pid 62112:tid 62327] [client 20.104.18.253:24477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/weo.php"] [unique_id "amuqNMJgo6iBrIY9VJLF8QAAANo"]
[Thu Jul 30 14:47:01.519055 2026] [security2:error] [pid 62112:tid 62264] [client 20.104.18.253:42242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wg.php"] [unique_id "amuqNcJgo6iBrIY9VJLF_wAAAJs"]
[Thu Jul 30 14:47:01.707131 2026] [security2:error] [pid 62112:tid 62319] [client 185.177.72.67:51208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/core%7e"] [unique_id "amuqNcJgo6iBrIY9VJLGBAAAANI"]
[Thu Jul 30 14:47:02.229322 2026] [security2:error] [pid 62112:tid 62293] [client 20.104.18.253:24485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/whmcs.php"] [unique_id "amuqNsJgo6iBrIY9VJLGEgAAALg"]
[Thu Jul 30 14:47:02.336941 2026] [security2:error] [pid 62112:tid 62300] [client 114.119.150.64:51257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/soldes-d-hiver-2016-minelli/bottes-cavalieres-cuir_minelli/"] [unique_id "amuqNsJgo6iBrIY9VJLGGgAAAL8"], referer: https://www.carnetdeshopping.com/soldes-d-hiver-2016-minelli/bottes-cavalieres-cuir_minelli/
[Thu Jul 30 14:47:02.341628 2026] [proxy:error] [pid 62112:tid 62256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:47:02.341691 2026] [proxy_http:error] [pid 62112:tid 62256] [client 34.224.175.62:11532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:47:02.342293 2026] [proxy:error] [pid 62112:tid 62256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:47:02.342340 2026] [proxy_http:error] [pid 62112:tid 62256] [client 34.224.175.62:11532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:47:02.862655 2026] [security2:error] [pid 62112:tid 62231] [remote 57.141.0.21:27178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuqNsJgo6iBrIY9VJLGLQAAlHY"]
[Thu Jul 30 14:47:02.962960 2026] [security2:error] [pid 62112:tid 62265] [client 20.104.18.253:24463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wi.php"] [unique_id "amuqNsJgo6iBrIY9VJLGLwAAAJw"]
[Thu Jul 30 14:47:03.186483 2026] [security2:error] [pid 62112:tid 62227] [remote 198.38.94.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sama-architect.com"] [uri "/wp-login.php"] [unique_id "amuqN8Jgo6iBrIY9VJLGMgAAunI"]
[Thu Jul 30 14:47:03.716966 2026] [security2:error] [pid 62112:tid 62303] [client 20.104.18.253:25034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/widget-logic/mini.php"] [unique_id "amuqN8Jgo6iBrIY9VJLGPwAAAMI"]
[Thu Jul 30 14:47:04.005135 2026] [security2:error] [pid 62112:tid 62230] [remote 57.141.0.27:28340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuqOMJgo6iBrIY9VJLGSwAA5HU"]
[Thu Jul 30 14:47:04.472878 2026] [security2:error] [pid 62112:tid 62321] [client 20.104.18.253:24454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/widgets.php"] [unique_id "amuqOMJgo6iBrIY9VJLGYAAAANQ"]
[Thu Jul 30 14:47:04.801036 2026] [security2:error] [pid 62112:tid 62345] [client 177.6.106.101:56108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqOMJgo6iBrIY9VJLGZAAAAOw"]
[Thu Jul 30 14:47:04.801164 2026] [security2:error] [pid 62112:tid 62345] [client 177.6.106.101:56108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqOMJgo6iBrIY9VJLGZAAAAOw"]
[Thu Jul 30 14:47:05.284661 2026] [security2:error] [pid 62112:tid 62335] [client 20.104.18.253:24468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/widgets/about.php"] [unique_id "amuqOcJgo6iBrIY9VJLGdAAAAOI"]
[Thu Jul 30 14:47:06.042117 2026] [security2:error] [pid 62112:tid 62308] [client 50.6.43.217:11742] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuqOsJgo6iBrIY9VJLGjgAAAMc"]
[Thu Jul 30 14:47:06.065158 2026] [security2:error] [pid 62112:tid 62343] [client 50.6.43.217:11750] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuqOsJgo6iBrIY9VJLGkAAAAOo"]
[Thu Jul 30 14:47:06.082918 2026] [security2:error] [pid 62112:tid 62337] [client 185.177.72.67:51208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/test.php"] [unique_id "amuqOsJgo6iBrIY9VJLGkQAAAOQ"]
[Thu Jul 30 14:47:06.085660 2026] [security2:error] [pid 62112:tid 62322] [client 20.104.18.253:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/widgets/admin.php"] [unique_id "amuqOsJgo6iBrIY9VJLGkgAAANU"]
[Thu Jul 30 14:47:06.342132 2026] [security2:error] [pid 62112:tid 62250] [client 185.177.72.67:51210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/test.php..."] [unique_id "amuqOsJgo6iBrIY9VJLGlAAAAI0"]
[Thu Jul 30 14:47:06.590419 2026] [security2:error] [pid 62112:tid 62280] [client 185.177.72.67:51224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/test.php%09%09"] [unique_id "amuqOsJgo6iBrIY9VJLGngAAAKs"]
[Thu Jul 30 14:47:06.789399 2026] [security2:error] [pid 62112:tid 62359] [client 20.104.18.253:24482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/widgets/alfa-rex.php"] [unique_id "amuqOsJgo6iBrIY9VJLGogAAAPo"]
[Thu Jul 30 14:47:06.799261 2026] [security2:error] [pid 62112:tid 62332] [client 52.238.199.152:55591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-load.php"] [unique_id "amuqOsJgo6iBrIY9VJLGowAAAN8"]
[Thu Jul 30 14:47:06.849106 2026] [security2:error] [pid 62112:tid 62242] [client 185.177.72.67:51226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/test.php...."] [unique_id "amuqOsJgo6iBrIY9VJLGpAAAAIU"]
[Thu Jul 30 14:47:07.111285 2026] [security2:error] [pid 62112:tid 62188] [remote 64.225.121.94:33550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuqO8Jgo6iBrIY9VJLGrgAA0ks"]
[Thu Jul 30 14:47:07.386637 2026] [security2:error] [pid 62112:tid 62350] [client 50.6.43.217:17814] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuqO8Jgo6iBrIY9VJLGsQAAAPE"]
[Thu Jul 30 14:47:07.552050 2026] [security2:error] [pid 62112:tid 62368] [client 20.104.18.253:24487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/widgets/autoload_classmap.php"] [unique_id "amuqO8Jgo6iBrIY9VJLGugAAAQM"]
[Thu Jul 30 14:47:08.266590 2026] [security2:error] [pid 62112:tid 62286] [client 20.104.18.253:42260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/widgets/browser.php"] [unique_id "amuqPMJgo6iBrIY9VJLGzQAAALE"]
[Thu Jul 30 14:47:08.540737 2026] [security2:error] [pid 62112:tid 62347] [client 50.6.43.217:17818] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuqPMJgo6iBrIY9VJLG1AAAAO4"]
[Thu Jul 30 14:47:08.981829 2026] [security2:error] [pid 62112:tid 62261] [client 185.177.72.67:51234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/localhost.sql"] [unique_id "amuqPMJgo6iBrIY9VJLG3gAAAJg"]
[Thu Jul 30 14:47:09.031758 2026] [security2:error] [pid 62112:tid 62353] [client 20.104.18.253:42273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/widgets/bypass.php"] [unique_id "amuqPcJgo6iBrIY9VJLG4gAAAPQ"]
[Thu Jul 30 14:47:09.560735 2026] [security2:error] [pid 62112:tid 62319] [client 185.177.72.67:51234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/db.sql"] [unique_id "amuqPcJgo6iBrIY9VJLG8gAAANI"]
[Thu Jul 30 14:47:09.656037 2026] [security2:error] [pid 62112:tid 62244] [client 74.7.241.141:46834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "tgr.fiyan.co"] [uri "/cgi-sys/404.html"] [unique_id "amuqPcJgo6iBrIY9VJLG8wAAhyk"]
[Thu Jul 30 14:47:09.792318 2026] [security2:error] [pid 62112:tid 62341] [client 20.104.18.253:25065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/widgets/click.php"] [unique_id "amuqPcJgo6iBrIY9VJLG_wAAAOg"]
[Thu Jul 30 14:47:11.088766 2026] [security2:error] [pid 62112:tid 62340] [client 189.156.226.90:27085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqP8Jgo6iBrIY9VJLHLwAAAOc"]
[Thu Jul 30 14:47:11.088936 2026] [security2:error] [pid 62112:tid 62340] [client 189.156.226.90:27085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqP8Jgo6iBrIY9VJLHLwAAAOc"]
[Thu Jul 30 14:47:11.479946 2026] [security2:error] [pid 62112:tid 62258] [client 74.7.228.26:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ncg.udi.temporary.site"] [uri "/index.php"] [unique_id "amuqPsJgo6iBrIY9VJLHJwAAAJU"]
[Thu Jul 30 14:47:11.480728 2026] [security2:error] [pid 62112:tid 62312] [client 74.7.228.26:46146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ncg.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuqPsJgo6iBrIY9VJLHJQAAyy0"]
[Thu Jul 30 14:47:12.042951 2026] [security2:error] [pid 62112:tid 62338] [client 52.238.199.152:56257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/as/function.php"] [unique_id "amuqQMJgo6iBrIY9VJLHTAAAAOU"]
[Thu Jul 30 14:47:12.112214 2026] [security2:error] [pid 62112:tid 62294] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqP8Jgo6iBrIY9VJLHOgAAuSo"]
[Thu Jul 30 14:47:13.127069 2026] [security2:error] [pid 62112:tid 62362] [client 52.238.199.152:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/filter.php"] [unique_id "amuqQcJgo6iBrIY9VJLHbwAAAP0"]
[Thu Jul 30 14:47:13.298947 2026] [core:notice] [pid 62112:tid 62337] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:13.448163 2026] [security2:error] [pid 62112:tid 62242] [client 185.177.72.67:51234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/backup.sql"] [unique_id "amuqQcJgo6iBrIY9VJLHfwAAAIU"]
[Thu Jul 30 14:47:13.581655 2026] [security2:error] [pid 62112:tid 62256] [client 185.177.72.67:51234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/backup.sql.php"] [unique_id "amuqQcJgo6iBrIY9VJLHgAAAAJM"]
[Thu Jul 30 14:47:13.894132 2026] [security2:error] [pid 62112:tid 62250] [client 200.222.240.248:8532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.240.222.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albashayerfurnituremovers.xyz"] [uri "/xmlrpc.php"] [unique_id "amuqQcJgo6iBrIY9VJLHgQAAAI0"]
[Thu Jul 30 14:47:13.894259 2026] [security2:error] [pid 62112:tid 62250] [client 200.222.240.248:8532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albashayerfurnituremovers.xyz"] [uri "/xmlrpc.php"] [unique_id "amuqQcJgo6iBrIY9VJLHgQAAAI0"]
[Thu Jul 30 14:47:13.963849 2026] [security2:error] [pid 62112:tid 62281] [client 52.238.199.152:56306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/he.php"] [unique_id "amuqQcJgo6iBrIY9VJLHjQAAAKw"]
[Thu Jul 30 14:47:14.196846 2026] [security2:error] [pid 62112:tid 62246] [client 114.119.132.52:50749] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/2025/12/"] [unique_id "amuqQsJgo6iBrIY9VJLHlwAAAIk"], referer: https://saifalkhaleejest.com/when-to-use-rotation-chain-hoists-over-standard-chain-hoists/
[Thu Jul 30 14:47:14.453080 2026] [security2:error] [pid 62112:tid 62201] [remote 114.119.142.7:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/index_php/JIPKL/openaccess"] [unique_id "amuqQsJgo6iBrIY9VJLHoQAAvFg"], referer: https://www.jipkl.com/index.php/JIPKL/issue/view/16
[Thu Jul 30 14:47:14.747357 2026] [security2:error] [pid 62112:tid 62347] [client 185.177.72.67:7730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/index.php"] [unique_id "amuqQsJgo6iBrIY9VJLHqgAAAO4"]
[Thu Jul 30 14:47:14.999537 2026] [security2:error] [pid 62112:tid 62362] [client 185.177.72.67:7736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/index.php%255f"] [unique_id "amuqQsJgo6iBrIY9VJLHtAAAAP0"]
[Thu Jul 30 14:47:15.270045 2026] [security2:error] [pid 62112:tid 62366] [client 185.177.72.67:7752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/index.php%255d"] [unique_id "amuqQ8Jgo6iBrIY9VJLHuwAAAQE"]
[Thu Jul 30 14:47:15.472224 2026] [security2:error] [pid 62112:tid 62138] [remote 47.128.27.31:29594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-dunk-high-crimson-tint/"] [unique_id "amuqQ8Jgo6iBrIY9VJLHwQAAhRk"]
[Thu Jul 30 14:47:15.520075 2026] [security2:error] [pid 62112:tid 62302] [client 185.177.72.67:7764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/index.php.aws"] [unique_id "amuqQ8Jgo6iBrIY9VJLHwgAAAME"]
[Thu Jul 30 14:47:15.537321 2026] [security2:error] [pid 62112:tid 62305] [client 177.6.106.101:56713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqQ8Jgo6iBrIY9VJLHxgAAAMQ"]
[Thu Jul 30 14:47:15.537438 2026] [security2:error] [pid 62112:tid 62305] [client 177.6.106.101:56713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqQ8Jgo6iBrIY9VJLHxgAAAMQ"]
[Thu Jul 30 14:47:15.724159 2026] [security2:error] [pid 62112:tid 62208] [remote 103.253.21.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.21.253.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ciunews.com"] [uri "/xmlrpc.php"] [unique_id "amuqQ8Jgo6iBrIY9VJLHwAAA3F8"]
[Thu Jul 30 14:47:15.724391 2026] [security2:error] [pid 62112:tid 62329] [client 103.253.21.184:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ciunews.com"] [uri "/xmlrpc.php"] [unique_id "amuqQ8Jgo6iBrIY9VJLHwAAA3F8"]
[Thu Jul 30 14:47:16.258424 2026] [security2:error] [pid 62112:tid 62321] [client 52.238.199.152:55594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/setup-config.php"] [unique_id "amuqRMJgo6iBrIY9VJLH2QAAANQ"]
[Thu Jul 30 14:47:17.145172 2026] [security2:error] [pid 62112:tid 62362] [client 52.238.199.152:56280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amuqRcJgo6iBrIY9VJLH_AAAAP0"]
[Thu Jul 30 14:47:18.416216 2026] [security2:error] [pid 62112:tid 62330] [client 52.238.199.152:55555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuqRsJgo6iBrIY9VJLILQAAAN0"]
[Thu Jul 30 14:47:18.527496 2026] [security2:error] [pid 62112:tid 62257] [client 85.208.96.208:24592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuqRsJgo6iBrIY9VJLILwAAAJQ"]
[Thu Jul 30 14:47:18.527663 2026] [security2:error] [pid 62112:tid 62257] [client 85.208.96.208:24592] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuqRsJgo6iBrIY9VJLILwAAAJQ"]
[Thu Jul 30 14:47:19.004239 2026] [security2:error] [pid 62112:tid 62234] [remote 57.141.0.2:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuqR8Jgo6iBrIY9VJLIQQAAm3k"]
[Thu Jul 30 14:47:19.147148 2026] [core:notice] [pid 62112:tid 62356] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:19.337392 2026] [security2:error] [pid 62112:tid 62337] [client 85.208.96.204:10860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/26/mulher-desaparecida-e-encontrada-morta-dentro-de-cobra-de-quase-7-metros/"] [unique_id "amuqR8Jgo6iBrIY9VJLITAAAAOQ"]
[Thu Jul 30 14:47:19.337530 2026] [security2:error] [pid 62112:tid 62337] [client 85.208.96.204:10860] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/26/mulher-desaparecida-e-encontrada-morta-dentro-de-cobra-de-quase-7-metros/"] [unique_id "amuqR8Jgo6iBrIY9VJLITAAAAOQ"]
[Thu Jul 30 14:47:19.531528 2026] [security2:error] [pid 62112:tid 62369] [client 52.238.199.152:37168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "amuqR8Jgo6iBrIY9VJLIVwAAAQQ"]
[Thu Jul 30 14:47:19.868332 2026] [security2:error] [pid 62112:tid 62281] [client 74.7.241.163:34454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.tereasshop.com"] [uri "/robots.txt"] [unique_id "amuqR8Jgo6iBrIY9VJLIYgAAAKw"]
[Thu Jul 30 14:47:20.767477 2026] [security2:error] [pid 62112:tid 62322] [client 185.177.72.67:7768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/settings.php.save"] [unique_id "amuqSMJgo6iBrIY9VJLIggAAANU"]
[Thu Jul 30 14:47:20.857587 2026] [security2:error] [pid 62112:tid 62267] [client 52.238.199.152:37156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/atomlib.php"] [unique_id "amuqSMJgo6iBrIY9VJLIhgAAAJ4"]
[Thu Jul 30 14:47:21.030348 2026] [security2:error] [pid 62112:tid 62316] [client 185.177.72.67:63790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/settings.php.save%5f%5f"] [unique_id "amuqScJgo6iBrIY9VJLIjQAAAM8"]
[Thu Jul 30 14:47:21.287700 2026] [security2:error] [pid 62112:tid 62317] [client 185.177.72.67:63806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/settings.php.save%29"] [unique_id "amuqScJgo6iBrIY9VJLIkQAAANA"]
[Thu Jul 30 14:47:21.293156 2026] [security2:error] [pid 62112:tid 62119] [remote 57.141.0.55:47286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuqScJgo6iBrIY9VJLIkgABAQY"]
[Thu Jul 30 14:47:21.544401 2026] [security2:error] [pid 62112:tid 62369] [client 185.177.72.67:63822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/settings.php.save.aws"] [unique_id "amuqScJgo6iBrIY9VJLInAAAAQQ"]
[Thu Jul 30 14:47:21.610613 2026] [security2:error] [pid 62112:tid 62326] [client 189.156.226.90:27350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqScJgo6iBrIY9VJLInQAAANk"]
[Thu Jul 30 14:47:21.610732 2026] [security2:error] [pid 62112:tid 62326] [client 189.156.226.90:27350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqScJgo6iBrIY9VJLInQAAANk"]
[Thu Jul 30 14:47:22.092941 2026] [security2:error] [pid 62112:tid 62255] [client 114.119.148.108:55193] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kingstarenterprises.com"] [uri "/product-category/gym-club-accessories/knee-wraps/"] [unique_id "amuqSsJgo6iBrIY9VJLIsAAAAJI"], referer: https://www.kingstarenterprises.com/product-category/gym-club-accessories/knee-wraps/?wc_view_mode=masonry_grid
[Thu Jul 30 14:47:22.367465 2026] [security2:error] [pid 62112:tid 62312] [client 52.238.199.152:56270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuqSsJgo6iBrIY9VJLItwAAAMs"]
[Thu Jul 30 14:47:22.643045 2026] [security2:error] [pid 62112:tid 62311] [client 185.177.72.67:63828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqSsJgo6iBrIY9VJLIvwAAAMo"]
[Thu Jul 30 14:47:22.733449 2026] [security2:error] [pid 62112:tid 62295] [client 114.119.131.200:51091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/docs/5cfb7b-portsmouth-kit-20/5cfb7b-webex-teams"] [unique_id "amuqSsJgo6iBrIY9VJLIwAAAALo"], referer: https://arabiandubaisafari.com/docs/5cfb7b-portsmouth-kit-20/5cfb7b-webex-teams
[Thu Jul 30 14:47:22.911142 2026] [security2:error] [pid 62112:tid 62351] [client 185.177.72.67:63828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqSsJgo6iBrIY9VJLIzAAAAPI"]
[Thu Jul 30 14:47:23.025433 2026] [security2:error] [pid 62112:tid 62264] [client 114.119.143.11:38695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiantourz.com"] [uri "/etiquette-produit/cb/"] [unique_id "amuqS8Jgo6iBrIY9VJLI0gAAAJs"], referer: https://www.arabiantourz.com/soldes/homme-fred-perry-twin-tipped-fred-perry-shirt-blacksircb-t-shirts-polos/
[Thu Jul 30 14:47:23.307771 2026] [security2:error] [pid 62112:tid 62359] [client 52.238.199.152:56263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/gebase.php"] [unique_id "amuqS8Jgo6iBrIY9VJLI1gAAAPo"]
[Thu Jul 30 14:47:23.382928 2026] [security2:error] [pid 62112:tid 62291] [client 114.119.158.112:27415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabian-tours.com"] [uri "/site/lego-batwing-instructions-76120-56216b"] [unique_id "amuqS8Jgo6iBrIY9VJLI3gAAALY"], referer: https://arabian-tours.com/site/loto-6-live-56216b
[Thu Jul 30 14:47:24.276791 2026] [security2:error] [pid 62112:tid 62255] [client 185.177.72.67:63828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/database.sql"] [unique_id "amuqTMJgo6iBrIY9VJLI9wAAAJI"]
[Thu Jul 30 14:47:24.714103 2026] [security2:error] [pid 62112:tid 62161] [remote 57.141.0.24:24288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/589953950/feed/rss2/"] [unique_id "amuqTMJgo6iBrIY9VJLJBgAAiDA"]
[Thu Jul 30 14:47:24.784277 2026] [security2:error] [pid 62112:tid 62341] [client 52.238.199.152:55598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/xl.php"] [unique_id "amuqTMJgo6iBrIY9VJLJBwAAAOg"]
[Thu Jul 30 14:47:25.607280 2026] [security2:error] [pid 62112:tid 62335] [client 87.250.224.123:45512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuqTMJgo6iBrIY9VJLJAAAAAOI"]
[Thu Jul 30 14:47:25.804628 2026] [security2:error] [pid 62112:tid 62363] [client 177.6.106.101:57276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqTcJgo6iBrIY9VJLJKwAAAP4"]
[Thu Jul 30 14:47:25.806775 2026] [security2:error] [pid 62112:tid 62363] [client 177.6.106.101:57276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqTcJgo6iBrIY9VJLJKwAAAP4"]
[Thu Jul 30 14:47:25.875486 2026] [security2:error] [pid 62112:tid 62359] [client 43.173.179.159:36426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/11/30/cristina-cordula-pour-tati/"] [unique_id "amuqTcJgo6iBrIY9VJLJJQAAAPo"]
[Thu Jul 30 14:47:26.054558 2026] [core:notice] [pid 62112:tid 62317] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:26.059947 2026] [security2:error] [pid 62112:tid 62249] [client 52.238.199.152:55577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/2.php"] [unique_id "amuqTsJgo6iBrIY9VJLJNQAAAIw"]
[Thu Jul 30 14:47:26.103608 2026] [autoindex:error] [pid 62112:tid 62338] [client 119.12.199.187:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:47:26.623602 2026] [core:notice] [pid 62112:tid 62365] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:26.628400 2026] [security2:error] [pid 62112:tid 62365] [client 43.173.178.215:45620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/11/30/cristina-cordula-pour-tati/"] [unique_id "amuqTsJgo6iBrIY9VJLJRwAAAQA"], referer: https://carnetdeshopping.com/index.php/2015/11/30/cristina-cordula-pour-tati/
[Thu Jul 30 14:47:27.253841 2026] [security2:error] [pid 62112:tid 62259] [client 52.238.199.152:37151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/baxa1.php"] [unique_id "amuqT8Jgo6iBrIY9VJLJXwAAAJY"]
[Thu Jul 30 14:47:27.859784 2026] [security2:error] [pid 62112:tid 62271] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqT8Jgo6iBrIY9VJLJXgAAAKI"]
[Thu Jul 30 14:47:28.336802 2026] [security2:error] [pid 62112:tid 62249] [client 74.7.230.25:40550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aded-rdc.org"] [uri "/index.php"] [unique_id "amuqUMJgo6iBrIY9VJLJjAAAjFY"]
[Thu Jul 30 14:47:29.180774 2026] [security2:error] [pid 62112:tid 62242] [client 52.238.199.152:37183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/settings.php"] [unique_id "amuqUcJgo6iBrIY9VJLJrAAAAIU"]
[Thu Jul 30 14:47:29.963721 2026] [security2:error] [pid 62112:tid 62368] [client 172.237.109.114:24826] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amuqUcJgo6iBrIY9VJLJ1gAAAQM"]
[Thu Jul 30 14:47:30.009716 2026] [security2:error] [pid 62112:tid 62354] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqUcJgo6iBrIY9VJLJwgAAAPU"]
[Thu Jul 30 14:47:30.269412 2026] [security2:error] [pid 62112:tid 62296] [client 185.177.72.67:63828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqUsJgo6iBrIY9VJLJ3AAAALs"]
[Thu Jul 30 14:47:30.396712 2026] [security2:error] [pid 62112:tid 62285] [client 185.177.72.67:63828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env%5e"] [unique_id "amuqUsJgo6iBrIY9VJLJ4gAAALA"]
[Thu Jul 30 14:47:30.847292 2026] [security2:error] [pid 62112:tid 62326] [client 114.119.150.168:26367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/4/"] [unique_id "amuqUsJgo6iBrIY9VJLJ9QAAANk"], referer: https://kicksity.com/shop/?filtering=1&filter_product_cat=240%2C231%2C200%2C169%2C135%2C250
[Thu Jul 30 14:47:31.389238 2026] [security2:error] [pid 62112:tid 62284] [client 52.238.199.152:37120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/dropdown.php"] [unique_id "amuqU8Jgo6iBrIY9VJLKCQAAAK8"]
[Thu Jul 30 14:47:32.062403 2026] [security2:error] [pid 62112:tid 62369] [client 185.177.72.67:63828] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/_profiler%00"] [unique_id "amuqVMJgo6iBrIY9VJLKJgAAAQQ"]
[Thu Jul 30 14:47:32.123755 2026] [security2:error] [pid 62112:tid 62297] [client 189.156.226.90:27599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqVMJgo6iBrIY9VJLKJwAAALw"]
[Thu Jul 30 14:47:32.123898 2026] [security2:error] [pid 62112:tid 62297] [client 189.156.226.90:27599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqVMJgo6iBrIY9VJLKJwAAALw"]
[Thu Jul 30 14:47:32.151320 2026] [security2:error] [pid 62112:tid 62283] [client 172.237.109.114:42121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/l.fcgi"] [unique_id "amuqVMJgo6iBrIY9VJLKKQAAAK4"]
[Thu Jul 30 14:47:32.166151 2026] [security2:error] [pid 62112:tid 62364] [client 94.176.22.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuqVMJgo6iBrIY9VJLKJQAAAP8"], referer: https://cnpinyin.com
[Thu Jul 30 14:47:32.544367 2026] [security2:error] [pid 62112:tid 62274] [client 172.237.109.114:6921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuqU8Jgo6iBrIY9VJLKHwAAAKU"]
[Thu Jul 30 14:47:32.600823 2026] [security2:error] [pid 62112:tid 62357] [client 52.238.199.152:37154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin.php"] [unique_id "amuqVMJgo6iBrIY9VJLKQwAAAPg"]
[Thu Jul 30 14:47:33.643254 2026] [security2:error] [pid 62112:tid 62246] [client 52.238.199.152:37177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/buy.php"] [unique_id "amuqVcJgo6iBrIY9VJLKZAAAAIk"]
[Thu Jul 30 14:47:33.827535 2026] [security2:error] [pid 62112:tid 62361] [client 104.210.140.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iwic.tw"] [uri "/index.php"] [unique_id "amuqVMJgo6iBrIY9VJLKMgAA_A4"]
[Thu Jul 30 14:47:35.003241 2026] [security2:error] [pid 62112:tid 62276] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqVsJgo6iBrIY9VJLKfgAAAKc"]
[Thu Jul 30 14:47:35.489904 2026] [security2:error] [pid 62112:tid 62245] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuqV8Jgo6iBrIY9VJLKoAAAAIg"]
[Thu Jul 30 14:47:35.490020 2026] [security2:error] [pid 62112:tid 62245] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuqV8Jgo6iBrIY9VJLKoAAAAIg"]
[Thu Jul 30 14:47:35.732944 2026] [security2:error] [pid 62112:tid 62336] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuqV8Jgo6iBrIY9VJLKrgAAAOM"]
[Thu Jul 30 14:47:35.733088 2026] [security2:error] [pid 62112:tid 62336] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuqV8Jgo6iBrIY9VJLKrgAAAOM"]
[Thu Jul 30 14:47:35.807622 2026] [security2:error] [pid 62112:tid 62244] [client 52.238.199.152:37171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/mini.php"] [unique_id "amuqV8Jgo6iBrIY9VJLKswAAAIc"]
[Thu Jul 30 14:47:35.966768 2026] [security2:error] [pid 62112:tid 62285] [client 114.10.84.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuqV8Jgo6iBrIY9VJLKpQAAsDQ"], referer: https://flixon.net/
[Thu Jul 30 14:47:35.975625 2026] [security2:error] [pid 62112:tid 62315] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/images/pearl/index.php"] [unique_id "amuqV8Jgo6iBrIY9VJLKuwAAAM4"]
[Thu Jul 30 14:47:35.975724 2026] [security2:error] [pid 62112:tid 62315] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/images/pearl/index.php"] [unique_id "amuqV8Jgo6iBrIY9VJLKuwAAAM4"]
[Thu Jul 30 14:47:36.011739 2026] [core:notice] [pid 62112:tid 62350] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:36.348703 2026] [security2:error] [pid 62112:tid 62311] [client 185.177.72.67:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/erp~"] [unique_id "amuqWMJgo6iBrIY9VJLKyQAAAMo"]
[Thu Jul 30 14:47:36.416946 2026] [security2:error] [pid 62112:tid 62355] [client 177.6.106.101:53952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqWMJgo6iBrIY9VJLKzQAAAPY"]
[Thu Jul 30 14:47:36.417146 2026] [security2:error] [pid 62112:tid 62355] [client 177.6.106.101:53952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqWMJgo6iBrIY9VJLKzQAAAPY"]
[Thu Jul 30 14:47:36.521122 2026] [security2:error] [pid 62112:tid 62367] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/bypass.php"] [unique_id "amuqWMJgo6iBrIY9VJLKzwAAAQI"]
[Thu Jul 30 14:47:36.521233 2026] [security2:error] [pid 62112:tid 62367] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/bypass.php"] [unique_id "amuqWMJgo6iBrIY9VJLKzwAAAQI"]
[Thu Jul 30 14:47:36.782242 2026] [security2:error] [pid 62112:tid 62360] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wp-admin/about.php"] [unique_id "amuqWMJgo6iBrIY9VJLK3QAAAPs"]
[Thu Jul 30 14:47:36.782342 2026] [security2:error] [pid 62112:tid 62360] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wp-admin/about.php"] [unique_id "amuqWMJgo6iBrIY9VJLK3QAAAPs"]
[Thu Jul 30 14:47:36.785736 2026] [security2:error] [pid 62112:tid 62317] [client 114.119.147.205:31809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amuqWMJgo6iBrIY9VJLK3gAAANA"], referer: https://www.toscanamall.com/fr?remove_item=f45fa6602838b826f62e4e8552bda5c0
[Thu Jul 30 14:47:37.019488 2026] [security2:error] [pid 62112:tid 62245] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/12.php"] [unique_id "amuqWcJgo6iBrIY9VJLK5AAAAIg"]
[Thu Jul 30 14:47:37.019587 2026] [security2:error] [pid 62112:tid 62245] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/12.php"] [unique_id "amuqWcJgo6iBrIY9VJLK5AAAAIg"]
[Thu Jul 30 14:47:37.034431 2026] [security2:error] [pid 62112:tid 62368] [client 114.119.147.205:57541] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pkf.jo"] [uri "/our-people/mohammed-khattab/"] [unique_id "amuqWcJgo6iBrIY9VJLK5QAAAQM"], referer: https://pkf.jo/our-people/mohammed-khattab/
[Thu Jul 30 14:47:37.268534 2026] [security2:error] [pid 62112:tid 62265] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/nothing2.php"] [unique_id "amuqWcJgo6iBrIY9VJLK8wAAAJw"]
[Thu Jul 30 14:47:37.268687 2026] [security2:error] [pid 62112:tid 62265] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/nothing2.php"] [unique_id "amuqWcJgo6iBrIY9VJLK8wAAAJw"]
[Thu Jul 30 14:47:37.507631 2026] [security2:error] [pid 62112:tid 62333] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/media.php"] [unique_id "amuqWcJgo6iBrIY9VJLK-wAAAOA"]
[Thu Jul 30 14:47:37.507748 2026] [security2:error] [pid 62112:tid 62333] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/media.php"] [unique_id "amuqWcJgo6iBrIY9VJLK-wAAAOA"]
[Thu Jul 30 14:47:37.758140 2026] [security2:error] [pid 62112:tid 62305] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/file2.php"] [unique_id "amuqWcJgo6iBrIY9VJLLCQAAAMQ"]
[Thu Jul 30 14:47:37.758280 2026] [security2:error] [pid 62112:tid 62305] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/file2.php"] [unique_id "amuqWcJgo6iBrIY9VJLLCQAAAMQ"]
[Thu Jul 30 14:47:37.779889 2026] [security2:error] [pid 62112:tid 62193] [remote 168.119.5.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.5.119.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-login.php"] [unique_id "amuqWcJgo6iBrIY9VJLK_AAAqFA"]
[Thu Jul 30 14:47:37.908025 2026] [security2:error] [pid 62112:tid 62327] [client 52.238.199.152:56275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/cd.php"] [unique_id "amuqWcJgo6iBrIY9VJLLEQAAANo"]
[Thu Jul 30 14:47:37.986674 2026] [security2:error] [pid 62112:tid 62199] [remote 57.141.0.37:59728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuqWcJgo6iBrIY9VJLLFAAAj1Y"]
[Thu Jul 30 14:47:38.071655 2026] [security2:error] [pid 62112:tid 62357] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/simple.php"] [unique_id "amuqWsJgo6iBrIY9VJLLFwAAAPg"]
[Thu Jul 30 14:47:38.071745 2026] [security2:error] [pid 62112:tid 62357] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/simple.php"] [unique_id "amuqWsJgo6iBrIY9VJLLFwAAAPg"]
[Thu Jul 30 14:47:38.144274 2026] [security2:error] [pid 62112:tid 62171] [remote 57.141.0.8:21016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/56555984686/feed/rss2/"] [unique_id "amuqWcJgo6iBrIY9VJLLDgAA9zo"]
[Thu Jul 30 14:47:38.310437 2026] [security2:error] [pid 62112:tid 62256] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/mac.php"] [unique_id "amuqWsJgo6iBrIY9VJLLIQAAAJM"]
[Thu Jul 30 14:47:38.310564 2026] [security2:error] [pid 62112:tid 62256] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/mac.php"] [unique_id "amuqWsJgo6iBrIY9VJLLIQAAAJM"]
[Thu Jul 30 14:47:38.341215 2026] [security2:error] [pid 62112:tid 62326] [client 185.177.72.67:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/prod.htaccess"] [unique_id "amuqWsJgo6iBrIY9VJLLIgAAANk"]
[Thu Jul 30 14:47:38.401410 2026] [security2:error] [pid 62112:tid 62200] [remote 216.73.216.51:51955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqWsJgo6iBrIY9VJLLJgAA-1c"]
[Thu Jul 30 14:47:38.569030 2026] [security2:error] [pid 62112:tid 62279] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/install.php"] [unique_id "amuqWsJgo6iBrIY9VJLLLAAAAKo"]
[Thu Jul 30 14:47:38.569167 2026] [security2:error] [pid 62112:tid 62279] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/install.php"] [unique_id "amuqWsJgo6iBrIY9VJLLLAAAAKo"]
[Thu Jul 30 14:47:38.824182 2026] [security2:error] [pid 62112:tid 62361] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wsx.php"] [unique_id "amuqWsJgo6iBrIY9VJLLNgAAAPw"]
[Thu Jul 30 14:47:38.824273 2026] [security2:error] [pid 62112:tid 62361] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wsx.php"] [unique_id "amuqWsJgo6iBrIY9VJLLNgAAAPw"]
[Thu Jul 30 14:47:39.062646 2026] [security2:error] [pid 62112:tid 62286] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/alfa.php"] [unique_id "amuqW8Jgo6iBrIY9VJLLQAAAALE"]
[Thu Jul 30 14:47:39.062754 2026] [security2:error] [pid 62112:tid 62286] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/alfa.php"] [unique_id "amuqW8Jgo6iBrIY9VJLLQAAAALE"]
[Thu Jul 30 14:47:39.071391 2026] [security2:error] [pid 62112:tid 62346] [client 52.238.199.152:56271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuqW8Jgo6iBrIY9VJLLQQAAAO0"]
[Thu Jul 30 14:47:39.310857 2026] [security2:error] [pid 62112:tid 62335] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/dlu.php"] [unique_id "amuqW8Jgo6iBrIY9VJLLSwAAAOI"]
[Thu Jul 30 14:47:39.310999 2026] [security2:error] [pid 62112:tid 62335] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/dlu.php"] [unique_id "amuqW8Jgo6iBrIY9VJLLSwAAAOI"]
[Thu Jul 30 14:47:39.391473 2026] [security2:error] [pid 62112:tid 62366] [client 216.244.66.200:50168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mydubaidesertsafari.com"] [uri "/gas-line/how-to-remove-torsion-axle-spindle"] [unique_id "amuqW8Jgo6iBrIY9VJLLUAAAAQE"]
[Thu Jul 30 14:47:39.391599 2026] [security2:error] [pid 62112:tid 62366] [client 216.244.66.200:50168] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mydubaidesertsafari.com"] [uri "/gas-line/how-to-remove-torsion-axle-spindle"] [unique_id "amuqW8Jgo6iBrIY9VJLLUAAAAQE"]
[Thu Jul 30 14:47:39.461853 2026] [security2:error] [pid 62112:tid 62260] [client 114.119.132.101:60521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "online-hope.com"] [uri "/product-tag/peace%E5%92%8C%E5%B9%B3%E9%A6%99%E7%85%9921mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8"] [unique_id "amuqW8Jgo6iBrIY9VJLLUwAAAJc"], referer: https://online-hope.com/product-tag/peace%E5%92%8C%E5%B9%B3%E9%A6%99%E7%85%9921mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8
[Thu Jul 30 14:47:39.667085 2026] [security2:error] [pid 62112:tid 62255] [client 172.237.109.114:30444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuqW8Jgo6iBrIY9VJLLQgAAAJI"], referer: https://alseermarine.com:443/flashdisk/WWW/index.htm
[Thu Jul 30 14:47:39.881485 2026] [autoindex:error] [pid 62112:tid 62348] [client 185.177.72.67:60972] AH01276: Cannot serve directory /home2/dtxgzjte/public_html/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:47:40.229789 2026] [security2:error] [pid 62112:tid 62259] [client 74.7.230.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ladiessecretdepartment.com"] [uri "/index.php"] [unique_id "amuqWcJgo6iBrIY9VJLLAgAAAJY"]
[Thu Jul 30 14:47:40.230763 2026] [security2:error] [pid 62112:tid 62282] [client 74.7.230.57:41986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ladiessecretdepartment.com"] [uri "/robots.txt"] [unique_id "amuqWcJgo6iBrIY9VJLK_wAArTw"]
[Thu Jul 30 14:47:40.420512 2026] [security2:error] [pid 62112:tid 62304] [client 185.177.72.67:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env.old"] [unique_id "amuqXMJgo6iBrIY9VJLLcwAAAMM"]
[Thu Jul 30 14:47:40.557700 2026] [security2:error] [pid 62112:tid 62219] [remote 216.73.216.51:37038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqXMJgo6iBrIY9VJLLdgAA5mo"]
[Thu Jul 30 14:47:40.831085 2026] [security2:error] [pid 62112:tid 62351] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/f6.php"] [unique_id "amuqXMJgo6iBrIY9VJLLfQAAAPI"]
[Thu Jul 30 14:47:40.831171 2026] [security2:error] [pid 62112:tid 62351] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/f6.php"] [unique_id "amuqXMJgo6iBrIY9VJLLfQAAAPI"]
[Thu Jul 30 14:47:41.072234 2026] [security2:error] [pid 62112:tid 62301] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/0x.php"] [unique_id "amuqXcJgo6iBrIY9VJLLhAAAAMA"]
[Thu Jul 30 14:47:41.072339 2026] [security2:error] [pid 62112:tid 62301] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/0x.php"] [unique_id "amuqXcJgo6iBrIY9VJLLhAAAAMA"]
[Thu Jul 30 14:47:41.312689 2026] [security2:error] [pid 62112:tid 62353] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/geck.php"] [unique_id "amuqXcJgo6iBrIY9VJLLjgAAAPQ"]
[Thu Jul 30 14:47:41.312797 2026] [security2:error] [pid 62112:tid 62353] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/geck.php"] [unique_id "amuqXcJgo6iBrIY9VJLLjgAAAPQ"]
[Thu Jul 30 14:47:41.566025 2026] [security2:error] [pid 62112:tid 62252] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/8.php"] [unique_id "amuqXcJgo6iBrIY9VJLLlwAAAI8"]
[Thu Jul 30 14:47:41.566130 2026] [security2:error] [pid 62112:tid 62252] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/8.php"] [unique_id "amuqXcJgo6iBrIY9VJLLlwAAAI8"]
[Thu Jul 30 14:47:41.815100 2026] [security2:error] [pid 62112:tid 62356] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/133.php"] [unique_id "amuqXcJgo6iBrIY9VJLLmgAAAPc"]
[Thu Jul 30 14:47:41.815228 2026] [security2:error] [pid 62112:tid 62356] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/133.php"] [unique_id "amuqXcJgo6iBrIY9VJLLmgAAAPc"]
[Thu Jul 30 14:47:41.889619 2026] [security2:error] [pid 62112:tid 62280] [client 185.191.171.8:44710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuqXcJgo6iBrIY9VJLLngAAAKs"]
[Thu Jul 30 14:47:41.889717 2026] [security2:error] [pid 62112:tid 62280] [client 185.191.171.8:44710] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuqXcJgo6iBrIY9VJLLngAAAKs"]
[Thu Jul 30 14:47:42.052886 2026] [security2:error] [pid 62112:tid 62365] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/11.php"] [unique_id "amuqXsJgo6iBrIY9VJLLpgAAAQA"]
[Thu Jul 30 14:47:42.053050 2026] [security2:error] [pid 62112:tid 62365] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/11.php"] [unique_id "amuqXsJgo6iBrIY9VJLLpgAAAQA"]
[Thu Jul 30 14:47:42.260309 2026] [security2:error] [pid 62112:tid 62272] [client 52.238.199.152:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/batm.php"] [unique_id "amuqXsJgo6iBrIY9VJLLqQAAAKM"]
[Thu Jul 30 14:47:42.305991 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/3.php"] [unique_id "amuqXsJgo6iBrIY9VJLLqgAAAIs"]
[Thu Jul 30 14:47:42.306099 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/3.php"] [unique_id "amuqXsJgo6iBrIY9VJLLqgAAAIs"]
[Thu Jul 30 14:47:42.366405 2026] [security2:error] [pid 62112:tid 62307] [client 185.177.72.67:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/settings.swp"] [unique_id "amuqXsJgo6iBrIY9VJLLrgAAAMY"]
[Thu Jul 30 14:47:42.533567 2026] [security2:error] [pid 62112:tid 62291] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuqXsJgo6iBrIY9VJLLsQAAALY"]
[Thu Jul 30 14:47:42.567703 2026] [security2:error] [pid 62112:tid 62243] [client 172.213.216.126:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.lucky-strike-shop.com"] [uri "/1.php"] [unique_id "amuqXsJgo6iBrIY9VJLLugAAAIY"]
[Thu Jul 30 14:47:42.567797 2026] [security2:error] [pid 62112:tid 62243] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/1.php"] [unique_id "amuqXsJgo6iBrIY9VJLLugAAAIY"]
[Thu Jul 30 14:47:42.567876 2026] [security2:error] [pid 62112:tid 62243] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/1.php"] [unique_id "amuqXsJgo6iBrIY9VJLLugAAAIY"]
[Thu Jul 30 14:47:42.634541 2026] [security2:error] [pid 62112:tid 62283] [client 185.177.72.67:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env.swp"] [unique_id "amuqXsJgo6iBrIY9VJLLuwAAAK4"]
[Thu Jul 30 14:47:42.754817 2026] [security2:error] [pid 62112:tid 62339] [client 189.156.226.90:26807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqXsJgo6iBrIY9VJLLvAAAAOY"]
[Thu Jul 30 14:47:42.754924 2026] [security2:error] [pid 62112:tid 62339] [client 189.156.226.90:26807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqXsJgo6iBrIY9VJLLvAAAAOY"]
[Thu Jul 30 14:47:42.801523 2026] [security2:error] [pid 62112:tid 62298] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ouh.php"] [unique_id "amuqXsJgo6iBrIY9VJLLvgAAAL0"]
[Thu Jul 30 14:47:42.801635 2026] [security2:error] [pid 62112:tid 62298] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ouh.php"] [unique_id "amuqXsJgo6iBrIY9VJLLvgAAAL0"]
[Thu Jul 30 14:47:43.049842 2026] [security2:error] [pid 62112:tid 62366] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ioxi-o.php"] [unique_id "amuqX8Jgo6iBrIY9VJLLygAAAQE"]
[Thu Jul 30 14:47:43.049969 2026] [security2:error] [pid 62112:tid 62366] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ioxi-o.php"] [unique_id "amuqX8Jgo6iBrIY9VJLLygAAAQE"]
[Thu Jul 30 14:47:43.185685 2026] [security2:error] [pid 62112:tid 62261] [client 185.177.72.67:60972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.EnV"] [unique_id "amuqX8Jgo6iBrIY9VJLLzAAAAJg"]
[Thu Jul 30 14:47:43.297032 2026] [security2:error] [pid 62112:tid 62303] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ar.php"] [unique_id "amuqX8Jgo6iBrIY9VJLLzQAAAMI"]
[Thu Jul 30 14:47:43.297152 2026] [security2:error] [pid 62112:tid 62303] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ar.php"] [unique_id "amuqX8Jgo6iBrIY9VJLLzQAAAMI"]
[Thu Jul 30 14:47:43.465787 2026] [security2:error] [pid 62112:tid 62295] [client 175.110.237.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuqX8Jgo6iBrIY9VJLL0QAAALo"], referer: https://cnpinyin.com
[Thu Jul 30 14:47:43.597631 2026] [security2:error] [pid 62112:tid 62277] [client 52.238.199.152:55567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/hehehehe.php"] [unique_id "amuqX8Jgo6iBrIY9VJLL2gAAAKg"]
[Thu Jul 30 14:47:43.720201 2026] [security2:error] [pid 62112:tid 62299] [client 185.177.72.67:38822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.EnV^"] [unique_id "amuqX8Jgo6iBrIY9VJLL4QAAAL4"]
[Thu Jul 30 14:47:43.740571 2026] [security2:error] [pid 62112:tid 62348] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/info.php"] [unique_id "amuqX8Jgo6iBrIY9VJLL4gAAAO8"]
[Thu Jul 30 14:47:43.740677 2026] [security2:error] [pid 62112:tid 62348] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/info.php"] [unique_id "amuqX8Jgo6iBrIY9VJLL4gAAAO8"]
[Thu Jul 30 14:47:43.987317 2026] [security2:error] [pid 62112:tid 62354] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/123.php"] [unique_id "amuqX8Jgo6iBrIY9VJLL6gAAAPU"]
[Thu Jul 30 14:47:43.987428 2026] [security2:error] [pid 62112:tid 62354] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/123.php"] [unique_id "amuqX8Jgo6iBrIY9VJLL6gAAAPU"]
[Thu Jul 30 14:47:44.232002 2026] [security2:error] [pid 62112:tid 62257] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/33.php"] [unique_id "amuqYMJgo6iBrIY9VJLL8QAAAJQ"]
[Thu Jul 30 14:47:44.232149 2026] [security2:error] [pid 62112:tid 62257] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/33.php"] [unique_id "amuqYMJgo6iBrIY9VJLL8QAAAJQ"]
[Thu Jul 30 14:47:44.245290 2026] [security2:error] [pid 62112:tid 62369] [client 185.177.72.67:38822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/authui.htaccess"] [unique_id "amuqYMJgo6iBrIY9VJLL8gAAAQQ"]
[Thu Jul 30 14:47:44.426629 2026] [security2:error] [pid 62112:tid 62279] [client 144.124.192.245:34234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqYMJgo6iBrIY9VJLL6wAAAKo"], referer: http://pkf.jo
[Thu Jul 30 14:47:44.472680 2026] [security2:error] [pid 62112:tid 62340] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/bak.php"] [unique_id "amuqYMJgo6iBrIY9VJLL-AAAAOc"]
[Thu Jul 30 14:47:44.472778 2026] [security2:error] [pid 62112:tid 62340] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/bak.php"] [unique_id "amuqYMJgo6iBrIY9VJLL-AAAAOc"]
[Thu Jul 30 14:47:44.483104 2026] [security2:error] [pid 62112:tid 62358] [client 52.238.199.152:56293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/sim.php/wp-includes/certificates/plugins.php"] [unique_id "amuqYMJgo6iBrIY9VJLL-QAAAPk"]
[Thu Jul 30 14:47:44.512453 2026] [security2:error] [pid 62112:tid 62298] [client 185.177.72.67:38822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/test2.php"] [unique_id "amuqYMJgo6iBrIY9VJLL_QAAAL0"]
[Thu Jul 30 14:47:44.710319 2026] [security2:error] [pid 62112:tid 62285] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/term.php"] [unique_id "amuqYMJgo6iBrIY9VJLMAwAAALA"]
[Thu Jul 30 14:47:44.710472 2026] [security2:error] [pid 62112:tid 62285] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/term.php"] [unique_id "amuqYMJgo6iBrIY9VJLMAwAAALA"]
[Thu Jul 30 14:47:44.764391 2026] [security2:error] [pid 62112:tid 62256] [client 185.177.72.67:38836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/test2.php%2e%2e%2f%2e%2e%2f"] [unique_id "amuqYMJgo6iBrIY9VJLMBQAAAJM"]
[Thu Jul 30 14:47:44.784303 2026] [security2:error] [pid 62112:tid 62265] [client 62.201.248.104:51668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqYMJgo6iBrIY9VJLL-gAAAJw"], referer: http://pkf.jo
[Thu Jul 30 14:47:44.966048 2026] [security2:error] [pid 62112:tid 62327] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/opts.php"] [unique_id "amuqYMJgo6iBrIY9VJLMDAAAANo"]
[Thu Jul 30 14:47:44.966166 2026] [security2:error] [pid 62112:tid 62327] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/opts.php"] [unique_id "amuqYMJgo6iBrIY9VJLMDAAAANo"]
[Thu Jul 30 14:47:45.002848 2026] [core:notice] [pid 62112:tid 62319] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:45.018568 2026] [security2:error] [pid 62112:tid 62267] [client 185.177.72.67:38838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/test2.php.well-known"] [unique_id "amuqYcJgo6iBrIY9VJLMDwAAAJ4"]
[Thu Jul 30 14:47:45.219692 2026] [security2:error] [pid 62112:tid 62325] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wkl.php"] [unique_id "amuqYcJgo6iBrIY9VJLMGAAAANg"]
[Thu Jul 30 14:47:45.219833 2026] [security2:error] [pid 62112:tid 62325] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wkl.php"] [unique_id "amuqYcJgo6iBrIY9VJLMGAAAANg"]
[Thu Jul 30 14:47:45.262282 2026] [security2:error] [pid 62112:tid 62284] [client 177.23.210.151:1717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqYMJgo6iBrIY9VJLMAgAAAK8"], referer: http://pkf.jo
[Thu Jul 30 14:47:45.279506 2026] [security2:error] [pid 62112:tid 62250] [client 185.177.72.67:38848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/test2.php//"] [unique_id "amuqYcJgo6iBrIY9VJLMGQAAAI0"]
[Thu Jul 30 14:47:45.458051 2026] [security2:error] [pid 62112:tid 62338] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/we.php"] [unique_id "amuqYcJgo6iBrIY9VJLMGgAAAOU"]
[Thu Jul 30 14:47:45.458201 2026] [security2:error] [pid 62112:tid 62338] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/we.php"] [unique_id "amuqYcJgo6iBrIY9VJLMGgAAAOU"]
[Thu Jul 30 14:47:45.497673 2026] [security2:error] [pid 62112:tid 62328] [client 46.173.96.24:33353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqYcJgo6iBrIY9VJLMEwAAANs"], referer: http://pkf.jo
[Thu Jul 30 14:47:45.498514 2026] [security2:error] [pid 62112:tid 62315] [client 177.86.69.51:18302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqYMJgo6iBrIY9VJLMCQAAAM4"], referer: http://pkf.jo
[Thu Jul 30 14:47:45.530945 2026] [security2:error] [pid 62112:tid 62348] [client 185.177.72.67:38862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/config.php.bak"] [unique_id "amuqYcJgo6iBrIY9VJLMHgAAAO8"]
[Thu Jul 30 14:47:45.629219 2026] [security2:error] [pid 62112:tid 62282] [client 85.208.96.194:36794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2023/03/microsoft-365-solusi-produktivitas-yang"] [unique_id "amuqYcJgo6iBrIY9VJLMIgAAAK0"]
[Thu Jul 30 14:47:45.629388 2026] [security2:error] [pid 62112:tid 62282] [client 85.208.96.194:36794] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2023/03/microsoft-365-solusi-produktivitas-yang"] [unique_id "amuqYcJgo6iBrIY9VJLMIgAAAK0"]
[Thu Jul 30 14:47:45.703244 2026] [security2:error] [pid 62112:tid 62354] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/7.php"] [unique_id "amuqYcJgo6iBrIY9VJLMJgAAAPU"]
[Thu Jul 30 14:47:45.703378 2026] [security2:error] [pid 62112:tid 62354] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/7.php"] [unique_id "amuqYcJgo6iBrIY9VJLMJgAAAPU"]
[Thu Jul 30 14:47:45.784025 2026] [security2:error] [pid 62112:tid 62307] [client 185.177.72.67:38870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/config.php.bak%257d"] [unique_id "amuqYcJgo6iBrIY9VJLMKAAAAMY"]
[Thu Jul 30 14:47:45.954296 2026] [security2:error] [pid 62112:tid 62302] [client 52.238.199.152:37128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-seo.php"] [unique_id "amuqYcJgo6iBrIY9VJLMKQAAAME"]
[Thu Jul 30 14:47:45.964093 2026] [security2:error] [pid 62112:tid 62310] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ls.php"] [unique_id "amuqYcJgo6iBrIY9VJLMKgAAAMk"]
[Thu Jul 30 14:47:45.964184 2026] [security2:error] [pid 62112:tid 62310] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ls.php"] [unique_id "amuqYcJgo6iBrIY9VJLMKgAAAMk"]
[Thu Jul 30 14:47:46.041150 2026] [security2:error] [pid 62112:tid 62345] [client 185.177.72.67:38876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/ConFig.Php.bak"] [unique_id "amuqYsJgo6iBrIY9VJLMLgAAAOw"]
[Thu Jul 30 14:47:46.171071 2026] [security2:error] [pid 62112:tid 62351] [client 185.177.72.67:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/config.php.bak%0d"] [unique_id "amuqYsJgo6iBrIY9VJLMNQAAAPI"]
[Thu Jul 30 14:47:46.446063 2026] [security2:error] [pid 62112:tid 62245] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ant.php"] [unique_id "amuqYsJgo6iBrIY9VJLMOAAAAIg"]
[Thu Jul 30 14:47:46.446192 2026] [security2:error] [pid 62112:tid 62245] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ant.php"] [unique_id "amuqYsJgo6iBrIY9VJLMOAAAAIg"]
[Thu Jul 30 14:47:46.702903 2026] [security2:error] [pid 62112:tid 62292] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/155.php"] [unique_id "amuqYsJgo6iBrIY9VJLMPwAAALc"]
[Thu Jul 30 14:47:46.703020 2026] [security2:error] [pid 62112:tid 62292] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/155.php"] [unique_id "amuqYsJgo6iBrIY9VJLMPwAAALc"]
[Thu Jul 30 14:47:47.058398 2026] [security2:error] [pid 62112:tid 62271] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/file9.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMSAAAAKI"]
[Thu Jul 30 14:47:47.058529 2026] [security2:error] [pid 62112:tid 62271] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/file9.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMSAAAAKI"]
[Thu Jul 30 14:47:47.151875 2026] [security2:error] [pid 62112:tid 62346] [client 185.177.72.67:38882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/app_dev.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMTgAAAO0"]
[Thu Jul 30 14:47:47.303818 2026] [security2:error] [pid 62112:tid 62276] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/css.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMWAAAAKc"]
[Thu Jul 30 14:47:47.303921 2026] [security2:error] [pid 62112:tid 62276] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/css.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMWAAAAKc"]
[Thu Jul 30 14:47:47.336327 2026] [security2:error] [pid 62112:tid 62270] [client 52.238.199.152:36908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/zwso.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMWgAAAKE"]
[Thu Jul 30 14:47:47.404053 2026] [security2:error] [pid 62112:tid 62315] [client 185.177.72.67:38894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/app_dev.php%2520"] [unique_id "amuqY8Jgo6iBrIY9VJLMXAAAAM4"]
[Thu Jul 30 14:47:47.548506 2026] [security2:error] [pid 62112:tid 62269] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/js.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMXQAAAKA"]
[Thu Jul 30 14:47:47.548634 2026] [security2:error] [pid 62112:tid 62269] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/js.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMXQAAAKA"]
[Thu Jul 30 14:47:47.660658 2026] [security2:error] [pid 62112:tid 62317] [client 185.177.72.67:38908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/app_dev.php%253f"] [unique_id "amuqY8Jgo6iBrIY9VJLMYwAAANA"]
[Thu Jul 30 14:47:47.786132 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/lock360.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMagAAAIs"]
[Thu Jul 30 14:47:47.786240 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/lock360.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMagAAAIs"]
[Thu Jul 30 14:47:47.929686 2026] [security2:error] [pid 62112:tid 62310] [client 185.177.72.67:38914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/app_dev.php%2524"] [unique_id "amuqY8Jgo6iBrIY9VJLMbAAAAMk"]
[Thu Jul 30 14:47:48.037080 2026] [security2:error] [pid 62112:tid 62253] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/v.php"] [unique_id "amuqZMJgo6iBrIY9VJLMbwAAAJA"]
[Thu Jul 30 14:47:48.037224 2026] [security2:error] [pid 62112:tid 62253] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/v.php"] [unique_id "amuqZMJgo6iBrIY9VJLMbwAAAJA"]
[Thu Jul 30 14:47:48.234011 2026] [security2:error] [pid 62112:tid 62347] [client 52.238.199.152:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/user.php"] [unique_id "amuqZMJgo6iBrIY9VJLMegAAAO4"]
[Thu Jul 30 14:47:48.237026 2026] [security2:error] [pid 62112:tid 62263] [client 82.205.88.191:36514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqY8Jgo6iBrIY9VJLMawAAAJo"], referer: http://pkf.jo
[Thu Jul 30 14:47:48.287580 2026] [security2:error] [pid 62112:tid 62339] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/pucci.php"] [unique_id "amuqZMJgo6iBrIY9VJLMfQAAAOY"]
[Thu Jul 30 14:47:48.287707 2026] [security2:error] [pid 62112:tid 62339] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/pucci.php"] [unique_id "amuqZMJgo6iBrIY9VJLMfQAAAOY"]
[Thu Jul 30 14:47:48.435198 2026] [security2:error] [pid 62112:tid 62334] [client 190.94.212.241:55214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqZMJgo6iBrIY9VJLMcAAA4Rw"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxvideos.cc%2Fhot-shy-redhead-that-turns-out-to-be-freak-during-sex.html
[Thu Jul 30 14:47:48.527011 2026] [security2:error] [pid 62112:tid 62309] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/file4.php"] [unique_id "amuqZMJgo6iBrIY9VJLMhQAAAMg"]
[Thu Jul 30 14:47:48.527152 2026] [security2:error] [pid 62112:tid 62309] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/file4.php"] [unique_id "amuqZMJgo6iBrIY9VJLMhQAAAMg"]
[Thu Jul 30 14:47:48.768285 2026] [security2:error] [pid 62112:tid 62250] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/222.php"] [unique_id "amuqZMJgo6iBrIY9VJLMkgAAAI0"]
[Thu Jul 30 14:47:48.768364 2026] [security2:error] [pid 62112:tid 62250] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/222.php"] [unique_id "amuqZMJgo6iBrIY9VJLMkgAAAI0"]
[Thu Jul 30 14:47:48.924681 2026] [security2:error] [pid 62112:tid 62304] [client 177.6.106.101:54408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqZMJgo6iBrIY9VJLMlgAAAMM"]
[Thu Jul 30 14:47:48.924796 2026] [security2:error] [pid 62112:tid 62304] [client 177.6.106.101:54408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqZMJgo6iBrIY9VJLMlgAAAMM"]
[Thu Jul 30 14:47:49.077581 2026] [security2:error] [pid 62112:tid 62350] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/shellalfa.php"] [unique_id "amuqZcJgo6iBrIY9VJLMpAAAAPE"]
[Thu Jul 30 14:47:49.077664 2026] [security2:error] [pid 62112:tid 62350] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/shellalfa.php"] [unique_id "amuqZcJgo6iBrIY9VJLMpAAAAPE"]
[Thu Jul 30 14:47:49.311888 2026] [security2:error] [pid 62112:tid 62320] [client 114.119.135.245:60191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fireworkskenya.co.ke"] [uri "/our-products/consumer-fireworks/big-display-cakes/vamos-pa-la-danza"] [unique_id "amuqZcJgo6iBrIY9VJLMsQAAANM"], referer: https://fireworkskenya.co.ke/our-products/consumer-fireworks/big-display-cakes/vamos-pa-la-danza
[Thu Jul 30 14:47:49.352785 2026] [security2:error] [pid 62112:tid 62269] [client 52.238.199.152:37079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/assets/index.php"] [unique_id "amuqZcJgo6iBrIY9VJLMsgAAAKA"]
[Thu Jul 30 14:47:49.400029 2026] [security2:error] [pid 62112:tid 62283] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/aaa.php"] [unique_id "amuqZcJgo6iBrIY9VJLMtAAAAK4"]
[Thu Jul 30 14:47:49.400133 2026] [security2:error] [pid 62112:tid 62283] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/aaa.php"] [unique_id "amuqZcJgo6iBrIY9VJLMtAAAAK4"]
[Thu Jul 30 14:47:49.482767 2026] [security2:error] [pid 62112:tid 62185] [remote 57.141.0.35:42358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuqZcJgo6iBrIY9VJLMtQAAxkg"]
[Thu Jul 30 14:47:49.658021 2026] [security2:error] [pid 62112:tid 62306] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/abcd.php"] [unique_id "amuqZcJgo6iBrIY9VJLMuQAAAMU"]
[Thu Jul 30 14:47:49.658126 2026] [security2:error] [pid 62112:tid 62306] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/abcd.php"] [unique_id "amuqZcJgo6iBrIY9VJLMuQAAAMU"]
[Thu Jul 30 14:47:49.872443 2026] [security2:error] [pid 62112:tid 62200] [remote 216.73.216.51:37038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqZcJgo6iBrIY9VJLMxAAAnFc"]
[Thu Jul 30 14:47:49.895713 2026] [security2:error] [pid 62112:tid 62274] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/about.php"] [unique_id "amuqZcJgo6iBrIY9VJLMxgAAAKU"]
[Thu Jul 30 14:47:49.895843 2026] [security2:error] [pid 62112:tid 62274] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/about.php"] [unique_id "amuqZcJgo6iBrIY9VJLMxgAAAKU"]
[Thu Jul 30 14:47:50.147071 2026] [security2:error] [pid 62112:tid 62305] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wsd.php"] [unique_id "amuqZsJgo6iBrIY9VJLMywAAAMQ"]
[Thu Jul 30 14:47:50.147174 2026] [security2:error] [pid 62112:tid 62305] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wsd.php"] [unique_id "amuqZsJgo6iBrIY9VJLMywAAAMQ"]
[Thu Jul 30 14:47:50.396301 2026] [security2:error] [pid 62112:tid 62315] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ab.php"] [unique_id "amuqZsJgo6iBrIY9VJLM1AAAAM4"]
[Thu Jul 30 14:47:50.396418 2026] [security2:error] [pid 62112:tid 62315] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ab.php"] [unique_id "amuqZsJgo6iBrIY9VJLM1AAAAM4"]
[Thu Jul 30 14:47:50.407283 2026] [security2:error] [pid 62112:tid 62197] [remote 194.116.184.179:10853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuqZsJgo6iBrIY9VJLM1QAA0lQ"]
[Thu Jul 30 14:47:50.647373 2026] [security2:error] [pid 62112:tid 62314] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/gt.php"] [unique_id "amuqZsJgo6iBrIY9VJLM2gAAAM0"]
[Thu Jul 30 14:47:50.647538 2026] [security2:error] [pid 62112:tid 62314] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/gt.php"] [unique_id "amuqZsJgo6iBrIY9VJLM2gAAAM0"]
[Thu Jul 30 14:47:50.882622 2026] [security2:error] [pid 62112:tid 62359] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/taff.php"] [unique_id "amuqZsJgo6iBrIY9VJLM4wAAAPo"]
[Thu Jul 30 14:47:50.882734 2026] [security2:error] [pid 62112:tid 62359] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/taff.php"] [unique_id "amuqZsJgo6iBrIY9VJLM4wAAAPo"]
[Thu Jul 30 14:47:51.139492 2026] [security2:error] [pid 62112:tid 62249] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ee.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLM6QAAAIw"]
[Thu Jul 30 14:47:51.139655 2026] [security2:error] [pid 62112:tid 62249] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/ee.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLM6QAAAIw"]
[Thu Jul 30 14:47:51.356152 2026] [security2:error] [pid 62112:tid 62341] [client 52.238.199.152:55559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/byp.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLM8QAAAOg"]
[Thu Jul 30 14:47:51.407695 2026] [security2:error] [pid 62112:tid 62363] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/max.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLM8wAAAP4"]
[Thu Jul 30 14:47:51.407808 2026] [security2:error] [pid 62112:tid 62363] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/max.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLM8wAAAP4"]
[Thu Jul 30 14:47:51.490440 2026] [core:notice] [pid 62112:tid 62321] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:51.659820 2026] [security2:error] [pid 62112:tid 62307] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/aa.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLM_gAAAMY"]
[Thu Jul 30 14:47:51.659933 2026] [security2:error] [pid 62112:tid 62307] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/aa.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLM_gAAAMY"]
[Thu Jul 30 14:47:51.895283 2026] [security2:error] [pid 62112:tid 62334] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/system_log.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLNCQAAAOE"]
[Thu Jul 30 14:47:51.895367 2026] [security2:error] [pid 62112:tid 62334] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/system_log.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLNCQAAAOE"]
[Thu Jul 30 14:47:51.917159 2026] [security2:error] [pid 62112:tid 62360] [client 57.141.0.28:55918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuqZ8Jgo6iBrIY9VJLM-QAA-2U"], referer: https://igetvape-australia.com/store/?product-page=3&add-to-cart=130
[Thu Jul 30 14:47:52.127702 2026] [core:notice] [pid 62112:tid 62364] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:52.145516 2026] [security2:error] [pid 62112:tid 62352] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/201.php"] [unique_id "amuqaMJgo6iBrIY9VJLNEAAAAPM"]
[Thu Jul 30 14:47:52.145615 2026] [security2:error] [pid 62112:tid 62352] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/201.php"] [unique_id "amuqaMJgo6iBrIY9VJLNEAAAAPM"]
[Thu Jul 30 14:47:52.246782 2026] [security2:error] [pid 62112:tid 62218] [remote 51.75.236.129:40352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuqaMJgo6iBrIY9VJLNEgAAjmk"]
[Thu Jul 30 14:47:52.247006 2026] [security2:error] [pid 62112:tid 62251] [client 51.75.236.129:40352] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuqaMJgo6iBrIY9VJLNEgAAjmk"]
[Thu Jul 30 14:47:52.389750 2026] [security2:error] [pid 62112:tid 62343] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/100.php"] [unique_id "amuqaMJgo6iBrIY9VJLNFwAAAOo"]
[Thu Jul 30 14:47:52.389835 2026] [security2:error] [pid 62112:tid 62343] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/100.php"] [unique_id "amuqaMJgo6iBrIY9VJLNFwAAAOo"]
[Thu Jul 30 14:47:52.509437 2026] [security2:error] [pid 62112:tid 62256] [client 52.238.199.152:37162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/bs1.php"] [unique_id "amuqaMJgo6iBrIY9VJLNIAAAAJM"]
[Thu Jul 30 14:47:52.655168 2026] [security2:error] [pid 62112:tid 62348] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wp-blink.php"] [unique_id "amuqaMJgo6iBrIY9VJLNIgAAAO8"]
[Thu Jul 30 14:47:52.655261 2026] [security2:error] [pid 62112:tid 62348] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/wp-blink.php"] [unique_id "amuqaMJgo6iBrIY9VJLNIgAAAO8"]
[Thu Jul 30 14:47:52.806243 2026] [security2:error] [pid 62112:tid 62297] [client 5.129.177.71:13110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqaMJgo6iBrIY9VJLNGgAAvGo"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxvideos.cc%2Fhot-tamil-wife1.html
[Thu Jul 30 14:47:52.922725 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/images.php"] [unique_id "amuqaMJgo6iBrIY9VJLNKgAAAIs"]
[Thu Jul 30 14:47:52.922829 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/images.php"] [unique_id "amuqaMJgo6iBrIY9VJLNKgAAAIs"]
[Thu Jul 30 14:47:53.169865 2026] [security2:error] [pid 62112:tid 62361] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/fm.php"] [unique_id "amuqacJgo6iBrIY9VJLNNQAAAPw"]
[Thu Jul 30 14:47:53.169950 2026] [security2:error] [pid 62112:tid 62361] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/fm.php"] [unique_id "amuqacJgo6iBrIY9VJLNNQAAAPw"]
[Thu Jul 30 14:47:53.175671 2026] [security2:error] [pid 62112:tid 62345] [client 82.225.160.93:13118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqaMJgo6iBrIY9VJLNKAAAAOw"], referer: http://pkf.jo
[Thu Jul 30 14:47:53.274242 2026] [security2:error] [pid 62112:tid 62281] [client 189.156.226.90:27151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqacJgo6iBrIY9VJLNOAAAAKw"]
[Thu Jul 30 14:47:53.274364 2026] [security2:error] [pid 62112:tid 62281] [client 189.156.226.90:27151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqacJgo6iBrIY9VJLNOAAAAKw"]
[Thu Jul 30 14:47:53.411284 2026] [security2:error] [pid 62112:tid 62333] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/rrr.php"] [unique_id "amuqacJgo6iBrIY9VJLNPQAAAOA"]
[Thu Jul 30 14:47:53.411379 2026] [security2:error] [pid 62112:tid 62333] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/rrr.php"] [unique_id "amuqacJgo6iBrIY9VJLNPQAAAOA"]
[Thu Jul 30 14:47:53.643887 2026] [security2:error] [pid 62112:tid 62235] [remote 92.222.104.194:46426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.nordeste1.com"] [uri "/category/cidades/"] [unique_id "amuqacJgo6iBrIY9VJLNRwAA23o"]
[Thu Jul 30 14:47:53.644064 2026] [security2:error] [pid 62112:tid 62328] [client 92.222.104.194:46426] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/category/cidades/"] [unique_id "amuqacJgo6iBrIY9VJLNRwAA23o"]
[Thu Jul 30 14:47:53.664109 2026] [security2:error] [pid 62112:tid 62364] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/mail.php"] [unique_id "amuqacJgo6iBrIY9VJLNSAAAAP8"]
[Thu Jul 30 14:47:53.664250 2026] [security2:error] [pid 62112:tid 62364] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/mail.php"] [unique_id "amuqacJgo6iBrIY9VJLNSAAAAP8"]
[Thu Jul 30 14:47:53.916494 2026] [security2:error] [pid 62112:tid 62308] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/chosen.php"] [unique_id "amuqacJgo6iBrIY9VJLNTAAAAMc"]
[Thu Jul 30 14:47:53.916605 2026] [security2:error] [pid 62112:tid 62308] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/chosen.php"] [unique_id "amuqacJgo6iBrIY9VJLNTAAAAMc"]
[Thu Jul 30 14:47:54.153575 2026] [security2:error] [pid 62112:tid 62295] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/doti.php"] [unique_id "amuqasJgo6iBrIY9VJLNWgAAALo"]
[Thu Jul 30 14:47:54.153692 2026] [security2:error] [pid 62112:tid 62295] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/doti.php"] [unique_id "amuqasJgo6iBrIY9VJLNWgAAALo"]
[Thu Jul 30 14:47:54.186295 2026] [fcgid:warn] [pid 62112:tid 62356] (70014)End of file found: [client 185.177.72.67:38924] mod_fcgid: can't get data from http client
[Thu Jul 30 14:47:54.302578 2026] [security2:error] [pid 62112:tid 62304] [client 49.13.167.123:61660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuqasJgo6iBrIY9VJLNXAAAAMM"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:47:54.391661 2026] [security2:error] [pid 62112:tid 62354] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/x0.php"] [unique_id "amuqasJgo6iBrIY9VJLNXQAAAPU"]
[Thu Jul 30 14:47:54.391779 2026] [security2:error] [pid 62112:tid 62354] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/x0.php"] [unique_id "amuqasJgo6iBrIY9VJLNXQAAAPU"]
[Thu Jul 30 14:47:54.434322 2026] [fcgid:warn] [pid 62112:tid 62349] (70014)End of file found: [client 185.177.72.67:58538] mod_fcgid: can't get data from http client
[Thu Jul 30 14:47:54.592026 2026] [security2:error] [pid 62112:tid 62236] [remote 57.141.0.28:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/27169508389/feed/rss2/"] [unique_id "amuqasJgo6iBrIY9VJLNaQAA0Hs"]
[Thu Jul 30 14:47:54.687210 2026] [fcgid:warn] [pid 62112:tid 62279] (70014)End of file found: [client 185.177.72.67:58552] mod_fcgid: can't get data from http client
[Thu Jul 30 14:47:54.693470 2026] [security2:error] [pid 62112:tid 62338] [client 172.237.109.114:12252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuqasJgo6iBrIY9VJLNWAAAAOU"]
[Thu Jul 30 14:47:54.779285 2026] [core:notice] [pid 62112:tid 62294] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:54.784897 2026] [security2:error] [pid 62112:tid 62294] [client 49.13.167.123:61666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuqasJgo6iBrIY9VJLNbQAAALk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:47:54.801095 2026] [security2:error] [pid 62112:tid 62360] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/bless.php"] [unique_id "amuqasJgo6iBrIY9VJLNbgAAAPs"]
[Thu Jul 30 14:47:54.801204 2026] [security2:error] [pid 62112:tid 62360] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/bless.php"] [unique_id "amuqasJgo6iBrIY9VJLNbgAAAPs"]
[Thu Jul 30 14:47:54.939602 2026] [fcgid:warn] [pid 62112:tid 62331] (70014)End of file found: [client 185.177.72.67:58566] mod_fcgid: can't get data from http client
[Thu Jul 30 14:47:54.975066 2026] [security2:error] [pid 62112:tid 62268] [client 112.202.39.157:36084] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqasJgo6iBrIY9VJLNXwAAAJ8"]
[Thu Jul 30 14:47:55.002993 2026] [security2:error] [pid 62112:tid 62242] [client 216.73.216.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.designmenow.net"] [uri "/public/index.php"] [unique_id "amuqasJgo6iBrIY9VJLNWQAAhQU"]
[Thu Jul 30 14:47:55.030505 2026] [security2:error] [pid 62112:tid 62268] [client 112.202.39.157:36084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqasJgo6iBrIY9VJLNXwAAAJ8"]
[Thu Jul 30 14:47:55.030592 2026] [security2:error] [pid 62112:tid 62268] [client 112.202.39.157:36084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqasJgo6iBrIY9VJLNXwAAAJ8"]
[Thu Jul 30 14:47:55.051679 2026] [security2:error] [pid 62112:tid 62251] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/cgi-bin/index.php"] [unique_id "amuqa8Jgo6iBrIY9VJLNdgAAAI4"]
[Thu Jul 30 14:47:55.051774 2026] [security2:error] [pid 62112:tid 62251] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/cgi-bin/index.php"] [unique_id "amuqa8Jgo6iBrIY9VJLNdgAAAI4"]
[Thu Jul 30 14:47:55.155832 2026] [security2:error] [pid 62112:tid 62337] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqasJgo6iBrIY9VJLNZgAA5AM"]
[Thu Jul 30 14:47:55.229290 2026] [security2:error] [pid 62112:tid 62125] [remote 57.141.0.34:30728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuqa8Jgo6iBrIY9VJLNewAAsAw"]
[Thu Jul 30 14:47:55.257284 2026] [security2:error] [pid 62112:tid 62122] [remote 35.204.109.104:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.bestdogproductguide.com"] [uri "/"] [unique_id "amuqa8Jgo6iBrIY9VJLNfAAAwgk"]
[Thu Jul 30 14:47:55.257427 2026] [security2:error] [pid 62112:tid 62303] [client 35.204.109.104:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bestdogproductguide.com"] [uri "/"] [unique_id "amuqa8Jgo6iBrIY9VJLNfAAAwgk"]
[Thu Jul 30 14:47:55.314762 2026] [security2:error] [pid 62112:tid 62322] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/size.php"] [unique_id "amuqa8Jgo6iBrIY9VJLNfQAAANU"]
[Thu Jul 30 14:47:55.314882 2026] [security2:error] [pid 62112:tid 62322] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/size.php"] [unique_id "amuqa8Jgo6iBrIY9VJLNfQAAANU"]
[Thu Jul 30 14:47:55.384058 2026] [security2:error] [pid 62112:tid 62315] [client 49.13.167.123:61674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuqa8Jgo6iBrIY9VJLNfgAAAM4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:47:55.545264 2026] [security2:error] [pid 62112:tid 62188] [remote 216.73.216.51:37444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqa8Jgo6iBrIY9VJLNgwAA6ks"]
[Thu Jul 30 14:47:55.556770 2026] [security2:error] [pid 62112:tid 62284] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/lala.php"] [unique_id "amuqa8Jgo6iBrIY9VJLNhAAAAK8"]
[Thu Jul 30 14:47:55.556847 2026] [security2:error] [pid 62112:tid 62284] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/lala.php"] [unique_id "amuqa8Jgo6iBrIY9VJLNhAAAAK8"]
[Thu Jul 30 14:47:55.804923 2026] [security2:error] [pid 62112:tid 62264] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lucky-strike-shop.com"] [uri "/file1.php"] [unique_id "amuqa8Jgo6iBrIY9VJLNjQAAAJs"]
[Thu Jul 30 14:47:55.805042 2026] [security2:error] [pid 62112:tid 62264] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.lucky-strike-shop.com"] [uri "/file1.php"] [unique_id "amuqa8Jgo6iBrIY9VJLNjQAAAJs"]
[Thu Jul 30 14:47:55.887564 2026] [security2:error] [pid 62112:tid 62325] [client 185.177.72.67:58572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/_phpinfo.php"] [unique_id "amuqa8Jgo6iBrIY9VJLNjwAAANg"]
[Thu Jul 30 14:47:56.058740 2026] [security2:error] [pid 62112:tid 62354] [client 112.202.39.157:36124] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqbMJgo6iBrIY9VJLNlgAAAPU"]
[Thu Jul 30 14:47:56.115257 2026] [security2:error] [pid 62112:tid 62354] [client 112.202.39.157:36124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqbMJgo6iBrIY9VJLNlgAAAPU"]
[Thu Jul 30 14:47:56.138347 2026] [security2:error] [pid 62112:tid 62291] [client 185.177.72.67:58582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/_phpinfo.php.dockerignore"] [unique_id "amuqbMJgo6iBrIY9VJLNmwAAALY"]
[Thu Jul 30 14:47:56.387402 2026] [security2:error] [pid 62112:tid 62243] [client 185.177.72.67:58584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/_phpinfo.php%3f"] [unique_id "amuqbMJgo6iBrIY9VJLNnwAAAIY"]
[Thu Jul 30 14:47:56.388920 2026] [security2:error] [pid 62112:tid 62320] [client 62.122.105.149:46792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqbMJgo6iBrIY9VJLNlwAAANM"], referer: http://pkf.jo
[Thu Jul 30 14:47:56.650807 2026] [security2:error] [pid 62112:tid 62288] [client 185.177.72.67:58592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/_phpinfo.php%2e%2e%2f%2e%2e%2f"] [unique_id "amuqbMJgo6iBrIY9VJLNqQAAALM"]
[Thu Jul 30 14:47:56.901052 2026] [security2:error] [pid 62112:tid 62308] [client 185.177.72.67:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-config.php"] [unique_id "amuqbMJgo6iBrIY9VJLNrgAAAMc"]
[Thu Jul 30 14:47:57.150014 2026] [security2:error] [pid 62112:tid 62303] [client 185.177.72.67:58608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aded-rdc.org"] [uri "/wp-config.php%7c%7c"] [unique_id "amuqbcJgo6iBrIY9VJLNtgAAAMI"]
[Thu Jul 30 14:47:57.331373 2026] [security2:error] [pid 62112:tid 62324] [client 112.202.39.157:36160] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqbcJgo6iBrIY9VJLNugAAANc"]
[Thu Jul 30 14:47:57.382336 2026] [security2:error] [pid 62112:tid 62324] [client 112.202.39.157:36160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqbcJgo6iBrIY9VJLNugAAANc"]
[Thu Jul 30 14:47:57.408216 2026] [security2:error] [pid 62112:tid 62293] [client 185.177.72.67:58614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aded-rdc.org"] [uri "/wp-config.php%257e"] [unique_id "amuqbcJgo6iBrIY9VJLNuwAAALg"]
[Thu Jul 30 14:47:57.548570 2026] [security2:error] [pid 62112:tid 62343] [client 114.119.145.102:46907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shorewooddaycare.com"] [uri "/julidan/beltine2181376.html"] [unique_id "amuqbcJgo6iBrIY9VJLNvwAAAOo"], referer: https://www.shorewooddaycare.com/julidan/beltine2181376.html
[Thu Jul 30 14:47:57.618078 2026] [security2:error] [pid 62112:tid 62256] [client 43.128.112.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuqbcJgo6iBrIY9VJLNvgAAAJM"], referer: http://cnpinyin.com/dict1?search=%e6%89%a7%e6%b3%95
[Thu Jul 30 14:47:57.659389 2026] [security2:error] [pid 62112:tid 62249] [client 185.177.72.67:58626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aded-rdc.org"] [uri "/wp-config.php//"] [unique_id "amuqbcJgo6iBrIY9VJLNxAAAAIw"]
[Thu Jul 30 14:47:57.661489 2026] [security2:error] [pid 62112:tid 62358] [client 177.6.106.101:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqbcJgo6iBrIY9VJLNxgAAAPk"]
[Thu Jul 30 14:47:57.661748 2026] [security2:error] [pid 62112:tid 62358] [client 177.6.106.101:55170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqbcJgo6iBrIY9VJLNxgAAAPk"]
[Thu Jul 30 14:47:58.700022 2026] [security2:error] [pid 62112:tid 62327] [client 112.202.39.157:36192] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqbsJgo6iBrIY9VJLN4wAAANo"]
[Thu Jul 30 14:47:58.758858 2026] [security2:error] [pid 62112:tid 62327] [client 112.202.39.157:36192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqbsJgo6iBrIY9VJLN4wAAANo"]
[Thu Jul 30 14:47:58.826833 2026] [security2:error] [pid 62112:tid 62287] [client 114.119.132.68:31793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cnpinyin.com"] [uri "/feed"] [unique_id "amuqbsJgo6iBrIY9VJLN6QAAALI"], referer: https://cnpinyin.com/feed
[Thu Jul 30 14:47:59.001914 2026] [security2:error] [pid 62112:tid 62296] [client 114.119.140.4:50567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lark-shop.com"] [uri "/shop/page/7/privacy-policy"] [unique_id "amuqb8Jgo6iBrIY9VJLN6wAAALs"], referer: https://lark-shop.com/shop/page/7/
[Thu Jul 30 14:47:59.010273 2026] [security2:error] [pid 62112:tid 62339] [client 196.176.4.13:52960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqbsJgo6iBrIY9VJLN4AAAAOY"], referer: http://pkf.jo
[Thu Jul 30 14:47:59.772601 2026] [core:notice] [pid 62112:tid 62250] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:47:59.977564 2026] [security2:error] [pid 62112:tid 62366] [client 112.202.39.157:36224] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqb8Jgo6iBrIY9VJLOCQAAAQE"]
[Thu Jul 30 14:48:00.029404 2026] [security2:error] [pid 62112:tid 62366] [client 112.202.39.157:36224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqb8Jgo6iBrIY9VJLOCQAAAQE"]
[Thu Jul 30 14:48:00.311055 2026] [core:notice] [pid 62112:tid 62358] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:00.605084 2026] [security2:error] [pid 62112:tid 62323] [client 52.238.199.152:37130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/IXR/allez.php"] [unique_id "amuqcMJgo6iBrIY9VJLOHAAAANY"]
[Thu Jul 30 14:48:00.637277 2026] [security2:error] [pid 62112:tid 62321] [client 185.177.72.67:58634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/server.php"] [unique_id "amuqcMJgo6iBrIY9VJLOHQAAANQ"]
[Thu Jul 30 14:48:00.906863 2026] [security2:error] [pid 62112:tid 62242] [client 185.177.72.67:37822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/server.php.%252e"] [unique_id "amuqcMJgo6iBrIY9VJLOJwAAAIU"]
[Thu Jul 30 14:48:01.163781 2026] [security2:error] [pid 62112:tid 62364] [client 185.177.72.67:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/server.php%0a"] [unique_id "amuqccJgo6iBrIY9VJLOLQAAAP8"]
[Thu Jul 30 14:48:01.260570 2026] [security2:error] [pid 62112:tid 62313] [client 112.202.39.157:36272] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqccJgo6iBrIY9VJLOLwAAAMw"]
[Thu Jul 30 14:48:01.312025 2026] [security2:error] [pid 62112:tid 62313] [client 112.202.39.157:36272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuqccJgo6iBrIY9VJLOLwAAAMw"]
[Thu Jul 30 14:48:01.378173 2026] [security2:error] [pid 62112:tid 62271] [client 82.38.180.121:55424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.180.38.82.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/CARUBAN/index_php/Konstruksi/issue/current"] [unique_id "amuqccJgo6iBrIY9VJLOLAAAAKI"]
[Thu Jul 30 14:48:01.430481 2026] [security2:error] [pid 62112:tid 62285] [client 185.177.72.67:37838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/server.php%5e"] [unique_id "amuqccJgo6iBrIY9VJLOOAAAALA"]
[Thu Jul 30 14:48:01.964320 2026] [security2:error] [pid 62112:tid 62280] [client 114.119.136.185:59035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/events/retreat-dates/eventsbyday/2026/4/8/-"] [unique_id "amuqccJgo6iBrIY9VJLOTAAAAKs"], referer: https://www.hmhs.ph/events/retreat-dates/monthcalendar/2026/4/-
[Thu Jul 30 14:48:02.333200 2026] [core:notice] [pid 62112:tid 62257] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:02.537110 2026] [security2:error] [pid 62112:tid 62249] [client 85.208.96.193:60800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/07/o-que-explica-a-lenta-vacinacao-contra-covid-19-na-uniao-europeia/"] [unique_id "amuqcsJgo6iBrIY9VJLOZgAAAIw"]
[Thu Jul 30 14:48:02.537310 2026] [security2:error] [pid 62112:tid 62249] [client 85.208.96.193:60800] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/07/o-que-explica-a-lenta-vacinacao-contra-covid-19-na-uniao-europeia/"] [unique_id "amuqcsJgo6iBrIY9VJLOZgAAAIw"]
[Thu Jul 30 14:48:02.827198 2026] [security2:error] [pid 62112:tid 62194] [remote 184.168.126.180:42824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/wp-login.php"] [unique_id "amuqcsJgo6iBrIY9VJLOagAAhlE"]
[Thu Jul 30 14:48:02.922678 2026] [core:notice] [pid 62112:tid 62181] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:03.161362 2026] [security2:error] [pid 62112:tid 62331] [client 102.141.44.136:32023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqcsJgo6iBrIY9VJLOaQAAAN4"], referer: http://pkf.jo
[Thu Jul 30 14:48:03.224270 2026] [security2:error] [pid 62112:tid 62361] [client 52.238.199.152:47295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/load.php"] [unique_id "amuqc8Jgo6iBrIY9VJLOegAAAPw"]
[Thu Jul 30 14:48:04.012567 2026] [security2:error] [pid 62112:tid 62266] [client 189.156.226.90:27373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqdMJgo6iBrIY9VJLOmAAAAJ0"]
[Thu Jul 30 14:48:04.012704 2026] [security2:error] [pid 62112:tid 62266] [client 189.156.226.90:27373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqdMJgo6iBrIY9VJLOmAAAAJ0"]
[Thu Jul 30 14:48:04.037988 2026] [security2:error] [pid 62112:tid 62280] [client 200.35.154.3:38560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqc8Jgo6iBrIY9VJLOiwAAq0M"], referer: http://pkf.jo/home/changeculture?langcode=en&returnurl=https%3A%2F%2Fcomprar-capoten.es.tl%2F
[Thu Jul 30 14:48:04.300822 2026] [security2:error] [pid 62112:tid 62358] [client 52.238.199.152:47276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/privacy.php"] [unique_id "amuqdMJgo6iBrIY9VJLOnQAAAPk"]
[Thu Jul 30 14:48:04.576129 2026] [security2:error] [pid 62112:tid 62213] [remote 57.141.0.54:47196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuqdMJgo6iBrIY9VJLOqwABA2Q"]
[Thu Jul 30 14:48:05.053922 2026] [security2:error] [pid 62112:tid 62339] [client 172.213.244.85:12551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuqdcJgo6iBrIY9VJLOtQAAAOY"]
[Thu Jul 30 14:48:05.054040 2026] [security2:error] [pid 62112:tid 62339] [client 172.213.244.85:12551] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuqdcJgo6iBrIY9VJLOtQAAAOY"]
[Thu Jul 30 14:48:05.205881 2026] [fcgid:warn] [pid 62112:tid 62331] (70014)End of file found: [client 185.177.72.67:37844] mod_fcgid: can't get data from http client
[Thu Jul 30 14:48:05.320578 2026] [security2:error] [pid 62112:tid 62315] [client 104.210.56.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fantasynamelist.com"] [uri "/index.php"] [unique_id "amuqc8Jgo6iBrIY9VJLOiQAAzls"]
[Thu Jul 30 14:48:05.457775 2026] [security2:error] [pid 62112:tid 62316] [client 172.213.244.85:56463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuqdcJgo6iBrIY9VJLOvwAAAM8"]
[Thu Jul 30 14:48:05.457884 2026] [security2:error] [pid 62112:tid 62316] [client 172.213.244.85:56463] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuqdcJgo6iBrIY9VJLOvwAAAM8"]
[Thu Jul 30 14:48:05.458128 2026] [fcgid:warn] [pid 62112:tid 62303] (70014)End of file found: [client 185.177.72.67:37850] mod_fcgid: can't get data from http client
[Thu Jul 30 14:48:05.722690 2026] [fcgid:warn] [pid 62112:tid 62347] (70014)End of file found: [client 185.177.72.67:37864] mod_fcgid: can't get data from http client
[Thu Jul 30 14:48:05.907516 2026] [security2:error] [pid 62112:tid 62356] [client 172.213.244.85:19259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/xstelth.php"] [unique_id "amuqdcJgo6iBrIY9VJLOzAAAAPc"]
[Thu Jul 30 14:48:05.907642 2026] [security2:error] [pid 62112:tid 62356] [client 172.213.244.85:19259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/xstelth.php"] [unique_id "amuqdcJgo6iBrIY9VJLOzAAAAPc"]
[Thu Jul 30 14:48:05.926798 2026] [security2:error] [pid 62112:tid 62359] [client 52.238.199.152:56267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-cli.php"] [unique_id "amuqdcJgo6iBrIY9VJLOzQAAAPo"]
[Thu Jul 30 14:48:05.992855 2026] [fcgid:warn] [pid 62112:tid 62367] (70014)End of file found: [client 185.177.72.67:37866] mod_fcgid: can't get data from http client
[Thu Jul 30 14:48:06.036035 2026] [security2:error] [pid 62112:tid 62255] [client 191.8.88.5:57048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqdcJgo6iBrIY9VJLOygAAAJI"], referer: http://pkf.jo
[Thu Jul 30 14:48:06.337460 2026] [security2:error] [pid 62112:tid 62307] [client 172.213.244.85:20541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/584062352875874akp.php"] [unique_id "amuqdsJgo6iBrIY9VJLO4QAAAMY"]
[Thu Jul 30 14:48:06.337564 2026] [security2:error] [pid 62112:tid 62307] [client 172.213.244.85:20541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/584062352875874akp.php"] [unique_id "amuqdsJgo6iBrIY9VJLO4QAAAMY"]
[Thu Jul 30 14:48:06.570502 2026] [security2:error] [pid 62112:tid 62358] [client 169.224.3.59:47292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqdsJgo6iBrIY9VJLO2gAA-XY"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Ffpoxxx.click
[Thu Jul 30 14:48:06.823196 2026] [security2:error] [pid 62112:tid 62317] [client 172.213.244.85:43043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/newfile.php"] [unique_id "amuqdsJgo6iBrIY9VJLO-AAAANA"]
[Thu Jul 30 14:48:06.823284 2026] [security2:error] [pid 62112:tid 62317] [client 172.213.244.85:43043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/newfile.php"] [unique_id "amuqdsJgo6iBrIY9VJLO-AAAANA"]
[Thu Jul 30 14:48:06.927232 2026] [security2:error] [pid 62112:tid 62275] [client 52.238.199.152:37155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/cc.php"] [unique_id "amuqdsJgo6iBrIY9VJLO-gAAAKY"]
[Thu Jul 30 14:48:07.190819 2026] [security2:error] [pid 62112:tid 62282] [client 172.213.244.85:58633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/tBEZGQz.php"] [unique_id "amuqd8Jgo6iBrIY9VJLPDAAAAK0"]
[Thu Jul 30 14:48:07.190951 2026] [security2:error] [pid 62112:tid 62282] [client 172.213.244.85:58633] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/tBEZGQz.php"] [unique_id "amuqd8Jgo6iBrIY9VJLPDAAAAK0"]
[Thu Jul 30 14:48:07.472798 2026] [security2:error] [pid 62112:tid 62293] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqdsJgo6iBrIY9VJLO-QAAuGs"]
[Thu Jul 30 14:48:07.614686 2026] [security2:error] [pid 62112:tid 62332] [client 172.213.244.85:53411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.instomail.com"] [uri "/___proxy_subdomain_webdisk/phpinfo"] [unique_id "amuqd8Jgo6iBrIY9VJLPGQAAAN8"]
[Thu Jul 30 14:48:07.764841 2026] [security2:error] [pid 62112:tid 62247] [client 172.213.244.85:53411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/drykl.php"] [unique_id "amuqd8Jgo6iBrIY9VJLPIAAAAIo"]
[Thu Jul 30 14:48:07.765010 2026] [security2:error] [pid 62112:tid 62247] [client 172.213.244.85:53411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/drykl.php"] [unique_id "amuqd8Jgo6iBrIY9VJLPIAAAAIo"]
[Thu Jul 30 14:48:08.006480 2026] [security2:error] [pid 62112:tid 62313] [client 185.177.72.67:37880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env.backup"] [unique_id "amuqeMJgo6iBrIY9VJLPIgAAAMw"]
[Thu Jul 30 14:48:08.150424 2026] [security2:error] [pid 62112:tid 62333] [client 172.213.244.85:56458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.instomail.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuqeMJgo6iBrIY9VJLPKwAAAOA"]
[Thu Jul 30 14:48:08.178198 2026] [security2:error] [pid 62112:tid 62249] [client 52.238.199.152:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/media-new.php"] [unique_id "amuqeMJgo6iBrIY9VJLPLgAAAIw"]
[Thu Jul 30 14:48:08.278145 2026] [security2:error] [pid 62112:tid 62292] [client 172.213.244.85:56458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/ls.php"] [unique_id "amuqeMJgo6iBrIY9VJLPMgAAALc"]
[Thu Jul 30 14:48:08.278250 2026] [security2:error] [pid 62112:tid 62292] [client 172.213.244.85:56458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/ls.php"] [unique_id "amuqeMJgo6iBrIY9VJLPMgAAALc"]
[Thu Jul 30 14:48:08.489543 2026] [security2:error] [pid 62112:tid 62354] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqd8Jgo6iBrIY9VJLPFgAA9Xw"]
[Thu Jul 30 14:48:08.493057 2026] [security2:error] [pid 62112:tid 62299] [client 177.6.106.101:55914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqeMJgo6iBrIY9VJLPNAAAAL4"]
[Thu Jul 30 14:48:08.493280 2026] [security2:error] [pid 62112:tid 62299] [client 177.6.106.101:55914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqeMJgo6iBrIY9VJLPNAAAAL4"]
[Thu Jul 30 14:48:08.654912 2026] [security2:error] [pid 62112:tid 62243] [client 172.213.244.85:53398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/dx.php"] [unique_id "amuqeMJgo6iBrIY9VJLPOgAAAIY"]
[Thu Jul 30 14:48:08.655028 2026] [security2:error] [pid 62112:tid 62243] [client 172.213.244.85:53398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/dx.php"] [unique_id "amuqeMJgo6iBrIY9VJLPOgAAAIY"]
[Thu Jul 30 14:48:08.688933 2026] [autoindex:error] [pid 62112:tid 62283] [client 185.177.72.67:37880] AH01276: Cannot serve directory /home2/dtxgzjte/public_html/includes/: No matching DirectoryIndex (index.php,index.html,/errors/403.php) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:48:08.848447 2026] [security2:error] [pid 62112:tid 62345] [client 91.73.4.252:3638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "skcarrental.ae"] [uri "/index.php"] [unique_id "amuqeMJgo6iBrIY9VJLPOQAA7Aw"], referer: https://skcarrental.ae/car-type/suv-car/?post_types=cars
[Thu Jul 30 14:48:09.011620 2026] [security2:error] [pid 62112:tid 62285] [client 172.213.244.85:17772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/mac.php"] [unique_id "amuqecJgo6iBrIY9VJLPRgAAALA"]
[Thu Jul 30 14:48:09.011725 2026] [security2:error] [pid 62112:tid 62285] [client 172.213.244.85:17772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/mac.php"] [unique_id "amuqecJgo6iBrIY9VJLPRgAAALA"]
[Thu Jul 30 14:48:09.463260 2026] [security2:error] [pid 62112:tid 62262] [client 172.213.244.85:19250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/485.php"] [unique_id "amuqecJgo6iBrIY9VJLPWAAAAJk"]
[Thu Jul 30 14:48:09.463363 2026] [security2:error] [pid 62112:tid 62262] [client 172.213.244.85:19250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/485.php"] [unique_id "amuqecJgo6iBrIY9VJLPWAAAAJk"]
[Thu Jul 30 14:48:09.583056 2026] [security2:error] [pid 62112:tid 62268] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqeMJgo6iBrIY9VJLPRQAAnwg"]
[Thu Jul 30 14:48:09.661989 2026] [security2:error] [pid 62112:tid 62254] [client 185.177.72.67:37880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/api.orig"] [unique_id "amuqecJgo6iBrIY9VJLPXgAAAJE"]
[Thu Jul 30 14:48:09.667050 2026] [core:notice] [pid 62112:tid 62316] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:10.035759 2026] [security2:error] [pid 62112:tid 62247] [client 172.213.244.85:17741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/gelio1.php"] [unique_id "amuqesJgo6iBrIY9VJLPaAAAAIo"]
[Thu Jul 30 14:48:10.035874 2026] [security2:error] [pid 62112:tid 62247] [client 172.213.244.85:17741] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/gelio1.php"] [unique_id "amuqesJgo6iBrIY9VJLPaAAAAIo"]
[Thu Jul 30 14:48:10.202611 2026] [security2:error] [pid 62112:tid 62307] [client 185.177.72.67:37880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/src.orig"] [unique_id "amuqesJgo6iBrIY9VJLPbQAAAMY"]
[Thu Jul 30 14:48:10.481144 2026] [security2:error] [pid 62112:tid 62329] [client 52.238.199.152:37165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-blog.php"] [unique_id "amuqesJgo6iBrIY9VJLPeQAAANw"]
[Thu Jul 30 14:48:10.502330 2026] [security2:error] [pid 62112:tid 62365] [client 172.213.244.85:53429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/lp6.php"] [unique_id "amuqesJgo6iBrIY9VJLPegAAAQA"]
[Thu Jul 30 14:48:10.502418 2026] [security2:error] [pid 62112:tid 62365] [client 172.213.244.85:53429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/lp6.php"] [unique_id "amuqesJgo6iBrIY9VJLPegAAAQA"]
[Thu Jul 30 14:48:10.608846 2026] [security2:error] [pid 62112:tid 62311] [client 20.226.5.174:17670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/dds.php"] [unique_id "amuqesJgo6iBrIY9VJLPfQAAAMo"]
[Thu Jul 30 14:48:10.901578 2026] [security2:error] [pid 62112:tid 62251] [client 172.213.244.85:58641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuqesJgo6iBrIY9VJLPiQAAAI4"]
[Thu Jul 30 14:48:10.901667 2026] [security2:error] [pid 62112:tid 62251] [client 172.213.244.85:58641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuqesJgo6iBrIY9VJLPiQAAAI4"]
[Thu Jul 30 14:48:11.258041 2026] [security2:error] [pid 62112:tid 62308] [client 80.240.7.196:60246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqesJgo6iBrIY9VJLPigAAAMc"], referer: http://pkf.jo
[Thu Jul 30 14:48:11.333227 2026] [security2:error] [pid 62112:tid 62282] [client 172.213.244.85:19208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.instomail.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/sodium_compat/"] [unique_id "amuqe8Jgo6iBrIY9VJLPlwAAAK0"]
[Thu Jul 30 14:48:11.361108 2026] [security2:error] [pid 62112:tid 62315] [client 41.182.112.47:35894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqe8Jgo6iBrIY9VJLPjQAAAM4"], referer: http://pkf.jo
[Thu Jul 30 14:48:11.461537 2026] [security2:error] [pid 62112:tid 62262] [client 172.213.244.85:19208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/w3llscc.php"] [unique_id "amuqe8Jgo6iBrIY9VJLPnAAAAJk"]
[Thu Jul 30 14:48:11.461654 2026] [security2:error] [pid 62112:tid 62262] [client 172.213.244.85:19208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/w3llscc.php"] [unique_id "amuqe8Jgo6iBrIY9VJLPnAAAAJk"]
[Thu Jul 30 14:48:11.584324 2026] [security2:error] [pid 62112:tid 62340] [client 20.226.5.174:17685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/de25bcd3c6.php"] [unique_id "amuqe8Jgo6iBrIY9VJLPngAAAOc"]
[Thu Jul 30 14:48:11.807411 2026] [security2:error] [pid 62112:tid 62244] [client 172.213.244.85:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/miru3.php"] [unique_id "amuqe8Jgo6iBrIY9VJLPpgAAAIc"]
[Thu Jul 30 14:48:11.807511 2026] [security2:error] [pid 62112:tid 62244] [client 172.213.244.85:26574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/miru3.php"] [unique_id "amuqe8Jgo6iBrIY9VJLPpgAAAIc"]
[Thu Jul 30 14:48:12.145194 2026] [core:notice] [pid 62112:tid 62363] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:12.180098 2026] [security2:error] [pid 62112:tid 62313] [client 172.213.244.85:58627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/autoload_classmap.php"] [unique_id "amuqfMJgo6iBrIY9VJLPsAAAAMw"]
[Thu Jul 30 14:48:12.180192 2026] [security2:error] [pid 62112:tid 62313] [client 172.213.244.85:58627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/autoload_classmap.php"] [unique_id "amuqfMJgo6iBrIY9VJLPsAAAAMw"]
[Thu Jul 30 14:48:12.444034 2026] [core:notice] [pid 62112:tid 62294] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:12.554541 2026] [security2:error] [pid 62112:tid 62272] [client 20.226.5.174:17666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/de_fb_uploads/b.php"] [unique_id "amuqfMJgo6iBrIY9VJLPvwAAAKM"]
[Thu Jul 30 14:48:12.637075 2026] [security2:error] [pid 62112:tid 62248] [client 52.238.199.152:47235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-2019.php"] [unique_id "amuqfMJgo6iBrIY9VJLPxAAAAIs"]
[Thu Jul 30 14:48:12.843645 2026] [security2:error] [pid 62112:tid 62334] [client 172.213.244.85:19230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.instomail.com"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuqfMJgo6iBrIY9VJLPyQAAAOE"]
[Thu Jul 30 14:48:12.971609 2026] [security2:error] [pid 62112:tid 62271] [client 172.213.244.85:19230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuqfMJgo6iBrIY9VJLP1AAAAKI"]
[Thu Jul 30 14:48:12.971715 2026] [security2:error] [pid 62112:tid 62271] [client 172.213.244.85:19230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuqfMJgo6iBrIY9VJLP1AAAAKI"]
[Thu Jul 30 14:48:13.165158 2026] [security2:error] [pid 62112:tid 62252] [client 82.167.32.7:62932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqfMJgo6iBrIY9VJLPzAAAAI8"], referer: http://pkf.jo
[Thu Jul 30 14:48:13.349094 2026] [security2:error] [pid 62112:tid 62324] [client 172.213.244.85:19263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/av.php"] [unique_id "amuqfcJgo6iBrIY9VJLP3QAAANc"]
[Thu Jul 30 14:48:13.349212 2026] [security2:error] [pid 62112:tid 62324] [client 172.213.244.85:19263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/av.php"] [unique_id "amuqfcJgo6iBrIY9VJLP3QAAANc"]
[Thu Jul 30 14:48:13.556430 2026] [security2:error] [pid 62112:tid 62259] [client 114.119.151.174:49533] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ejournalugj.com"] [uri "/index_php/grageaku/index"] [unique_id "amuqfcJgo6iBrIY9VJLP6gAAAJY"], referer: https://www.ejournalugj.com/index.php/grageaku/issue/current
[Thu Jul 30 14:48:13.560643 2026] [security2:error] [pid 62112:tid 62342] [client 20.226.5.174:17664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/de_fb_uploads/bypass.php"] [unique_id "amuqfcJgo6iBrIY9VJLP6wAAAOk"]
[Thu Jul 30 14:48:13.700309 2026] [security2:error] [pid 62112:tid 62244] [client 172.213.244.85:17759] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.instomail.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuqfcJgo6iBrIY9VJLP7gAAAIc"]
[Thu Jul 30 14:48:13.748330 2026] [security2:error] [pid 62112:tid 62260] [client 172.237.109.114:61331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuqfcJgo6iBrIY9VJLP2gAAAJc"]
[Thu Jul 30 14:48:13.849962 2026] [security2:error] [pid 62112:tid 62276] [client 172.213.244.85:17759] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.instomail.com"] [uri "/___proxy_subdomain_webdisk/wordpress/wp-admin/maint/"] [unique_id "amuqfcJgo6iBrIY9VJLP8QAAAKc"]
[Thu Jul 30 14:48:13.978932 2026] [security2:error] [pid 62112:tid 62363] [client 172.213.244.85:17759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/tiny.php"] [unique_id "amuqfcJgo6iBrIY9VJLP-QAAAP4"]
[Thu Jul 30 14:48:13.979036 2026] [security2:error] [pid 62112:tid 62363] [client 172.213.244.85:17759] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/tiny.php"] [unique_id "amuqfcJgo6iBrIY9VJLP-QAAAP4"]
[Thu Jul 30 14:48:14.331619 2026] [security2:error] [pid 62112:tid 62292] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuqfsJgo6iBrIY9VJLQAwAAALc"]
[Thu Jul 30 14:48:14.502834 2026] [security2:error] [pid 62112:tid 62272] [client 189.156.226.90:26681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqfsJgo6iBrIY9VJLQDgAAAKM"]
[Thu Jul 30 14:48:14.502969 2026] [security2:error] [pid 62112:tid 62272] [client 189.156.226.90:26681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqfsJgo6iBrIY9VJLQDgAAAKM"]
[Thu Jul 30 14:48:14.504331 2026] [security2:error] [pid 62112:tid 62168] [remote 57.141.0.55:56566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuqfsJgo6iBrIY9VJLQDwABADc"]
[Thu Jul 30 14:48:14.504585 2026] [security2:error] [pid 62112:tid 62287] [client 20.226.5.174:17675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/debug.php"] [unique_id "amuqfsJgo6iBrIY9VJLQEAAAALI"]
[Thu Jul 30 14:48:14.578283 2026] [security2:error] [pid 62112:tid 62277] [client 172.213.244.85:57154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuqfsJgo6iBrIY9VJLQFgAAAKg"]
[Thu Jul 30 14:48:14.578382 2026] [security2:error] [pid 62112:tid 62277] [client 172.213.244.85:57154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amuqfsJgo6iBrIY9VJLQFgAAAKg"]
[Thu Jul 30 14:48:14.586323 2026] [autoindex:error] [pid 62112:tid 62265] [client 185.177.72.67:37880] AH01276: Cannot serve directory /home2/dtxgzjte/public_html/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:48:14.927917 2026] [security2:error] [pid 62112:tid 62345] [client 172.213.244.85:43012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/zrrhj.php"] [unique_id "amuqfsJgo6iBrIY9VJLQGQAAAOw"]
[Thu Jul 30 14:48:14.928068 2026] [security2:error] [pid 62112:tid 62345] [client 172.213.244.85:43012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/zrrhj.php"] [unique_id "amuqfsJgo6iBrIY9VJLQGQAAAOw"]
[Thu Jul 30 14:48:15.033244 2026] [security2:error] [pid 62112:tid 62356] [client 52.238.199.152:55583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/menu.php"] [unique_id "amuqf8Jgo6iBrIY9VJLQGwAAAPc"]
[Thu Jul 30 14:48:15.365047 2026] [security2:error] [pid 62112:tid 62318] [client 172.213.244.85:12591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuqf8Jgo6iBrIY9VJLQHwAAANE"]
[Thu Jul 30 14:48:15.365146 2026] [security2:error] [pid 62112:tid 62318] [client 172.213.244.85:12591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuqf8Jgo6iBrIY9VJLQHwAAANE"]
[Thu Jul 30 14:48:15.497794 2026] [security2:error] [pid 62112:tid 62252] [client 20.226.5.174:17669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/dedi1.php"] [unique_id "amuqf8Jgo6iBrIY9VJLQIQAAAI8"]
[Thu Jul 30 14:48:15.877715 2026] [security2:error] [pid 62112:tid 62244] [client 172.213.244.85:12559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wpgum.php"] [unique_id "amuqf8Jgo6iBrIY9VJLQLQAAAIc"]
[Thu Jul 30 14:48:15.877813 2026] [security2:error] [pid 62112:tid 62244] [client 172.213.244.85:12559] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wpgum.php"] [unique_id "amuqf8Jgo6iBrIY9VJLQLQAAAIc"]
[Thu Jul 30 14:48:16.301331 2026] [security2:error] [pid 62112:tid 62247] [client 172.213.244.85:58681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/ywwbf.php"] [unique_id "amuqgMJgo6iBrIY9VJLQOgAAAIo"]
[Thu Jul 30 14:48:16.301438 2026] [security2:error] [pid 62112:tid 62247] [client 172.213.244.85:58681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/ywwbf.php"] [unique_id "amuqgMJgo6iBrIY9VJLQOgAAAIo"]
[Thu Jul 30 14:48:16.400171 2026] [security2:error] [pid 62112:tid 62307] [client 185.177.72.67:37880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/libs~"] [unique_id "amuqgMJgo6iBrIY9VJLQPgAAAMY"]
[Thu Jul 30 14:48:16.506369 2026] [security2:error] [pid 62112:tid 62280] [client 20.226.5.174:17679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/deeto/login.php"] [unique_id "amuqgMJgo6iBrIY9VJLQPwAAAKs"]
[Thu Jul 30 14:48:16.727732 2026] [security2:error] [pid 62112:tid 62330] [client 172.213.244.85:56452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/xoldj.php"] [unique_id "amuqgMJgo6iBrIY9VJLQSQAAAN0"]
[Thu Jul 30 14:48:16.727825 2026] [security2:error] [pid 62112:tid 62330] [client 172.213.244.85:56452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/xoldj.php"] [unique_id "amuqgMJgo6iBrIY9VJLQSQAAAN0"]
[Thu Jul 30 14:48:17.096057 2026] [security2:error] [pid 62112:tid 62366] [client 52.238.199.152:56308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-crons.php"] [unique_id "amuqgcJgo6iBrIY9VJLQUgAAAQE"]
[Thu Jul 30 14:48:17.109120 2026] [security2:error] [pid 62112:tid 62287] [client 172.213.244.85:26617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/f35.php"] [unique_id "amuqgcJgo6iBrIY9VJLQUwAAALI"]
[Thu Jul 30 14:48:17.109238 2026] [security2:error] [pid 62112:tid 62287] [client 172.213.244.85:26617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/f35.php"] [unique_id "amuqgcJgo6iBrIY9VJLQUwAAALI"]
[Thu Jul 30 14:48:17.330743 2026] [security2:error] [pid 62112:tid 62360] [client 66.249.73.96:35448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqgMJgo6iBrIY9VJLQTwAAAPs"]
[Thu Jul 30 14:48:17.447019 2026] [security2:error] [pid 62112:tid 62364] [client 172.213.244.85:53409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/gk.php"] [unique_id "amuqgcJgo6iBrIY9VJLQXAAAAP8"]
[Thu Jul 30 14:48:17.447160 2026] [security2:error] [pid 62112:tid 62364] [client 172.213.244.85:53409] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/gk.php"] [unique_id "amuqgcJgo6iBrIY9VJLQXAAAAP8"]
[Thu Jul 30 14:48:17.610821 2026] [security2:error] [pid 62112:tid 62270] [client 20.226.5.174:17688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/defau1t.php"] [unique_id "amuqgcJgo6iBrIY9VJLQYwAAAKE"]
[Thu Jul 30 14:48:17.779274 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.244.85:17779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/584062352875874akp.php"] [unique_id "amuqgcJgo6iBrIY9VJLQawAAAIs"]
[Thu Jul 30 14:48:17.779400 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.244.85:17779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/584062352875874akp.php"] [unique_id "amuqgcJgo6iBrIY9VJLQawAAAIs"]
[Thu Jul 30 14:48:18.185046 2026] [security2:error] [pid 62112:tid 62293] [client 172.213.244.85:17791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wper3.php"] [unique_id "amuqgsJgo6iBrIY9VJLQdAAAALg"]
[Thu Jul 30 14:48:18.185141 2026] [security2:error] [pid 62112:tid 62293] [client 172.213.244.85:17791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wper3.php"] [unique_id "amuqgsJgo6iBrIY9VJLQdAAAALg"]
[Thu Jul 30 14:48:18.430333 2026] [core:notice] [pid 62112:tid 62357] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:18.597204 2026] [security2:error] [pid 62112:tid 62349] [client 20.226.5.174:17692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/defaul.php"] [unique_id "amuqgsJgo6iBrIY9VJLQgwAAAPA"]
[Thu Jul 30 14:48:18.665681 2026] [security2:error] [pid 62112:tid 62310] [client 172.213.244.85:17787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/bthil.php"] [unique_id "amuqgsJgo6iBrIY9VJLQiAAAAMk"]
[Thu Jul 30 14:48:18.665797 2026] [security2:error] [pid 62112:tid 62310] [client 172.213.244.85:17787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/bthil.php"] [unique_id "amuqgsJgo6iBrIY9VJLQiAAAAMk"]
[Thu Jul 30 14:48:18.719428 2026] [security2:error] [pid 62112:tid 62264] [client 177.6.106.101:56486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqgsJgo6iBrIY9VJLQigAAAJs"]
[Thu Jul 30 14:48:18.719583 2026] [security2:error] [pid 62112:tid 62264] [client 177.6.106.101:56486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqgsJgo6iBrIY9VJLQigAAAJs"]
[Thu Jul 30 14:48:18.977400 2026] [security2:error] [pid 62112:tid 62292] [client 172.213.244.85:19201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wyzer1.php"] [unique_id "amuqgsJgo6iBrIY9VJLQlgAAALc"]
[Thu Jul 30 14:48:18.977517 2026] [security2:error] [pid 62112:tid 62292] [client 172.213.244.85:19201] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wyzer1.php"] [unique_id "amuqgsJgo6iBrIY9VJLQlgAAALc"]
[Thu Jul 30 14:48:19.189616 2026] [security2:error] [pid 62112:tid 62348] [client 91.170.2.145:37550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqgsJgo6iBrIY9VJLQkQAA72g"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fporntube.skin
[Thu Jul 30 14:48:19.282575 2026] [security2:error] [pid 62112:tid 62352] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqgsJgo6iBrIY9VJLQhwAAAPM"]
[Thu Jul 30 14:48:19.355141 2026] [security2:error] [pid 62112:tid 62356] [client 172.213.244.85:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/mh.php"] [unique_id "amuqg8Jgo6iBrIY9VJLQpQAAAPc"]
[Thu Jul 30 14:48:19.355251 2026] [security2:error] [pid 62112:tid 62356] [client 172.213.244.85:26596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/mh.php"] [unique_id "amuqg8Jgo6iBrIY9VJLQpQAAAPc"]
[Thu Jul 30 14:48:19.374338 2026] [security2:error] [pid 62112:tid 62258] [client 52.238.199.152:56281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/class.php"] [unique_id "amuqg8Jgo6iBrIY9VJLQpgAAAJU"]
[Thu Jul 30 14:48:19.642901 2026] [security2:error] [pid 62112:tid 62288] [client 20.226.5.174:17667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/defaul1.php"] [unique_id "amuqg8Jgo6iBrIY9VJLQrQAAALM"]
[Thu Jul 30 14:48:19.675502 2026] [security2:error] [pid 62112:tid 62324] [client 172.213.244.85:17732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuqg8Jgo6iBrIY9VJLQrgAAANc"]
[Thu Jul 30 14:48:19.675607 2026] [security2:error] [pid 62112:tid 62324] [client 172.213.244.85:17732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amuqg8Jgo6iBrIY9VJLQrgAAANc"]
[Thu Jul 30 14:48:20.020775 2026] [security2:error] [pid 62112:tid 62259] [client 172.213.244.85:14632] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.instomail.com"] [uri "/1.php"] [unique_id "amuqhMJgo6iBrIY9VJLQvQAAAJY"]
[Thu Jul 30 14:48:20.020890 2026] [security2:error] [pid 62112:tid 62259] [client 172.213.244.85:14632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/1.php"] [unique_id "amuqhMJgo6iBrIY9VJLQvQAAAJY"]
[Thu Jul 30 14:48:20.020996 2026] [security2:error] [pid 62112:tid 62259] [client 172.213.244.85:14632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/1.php"] [unique_id "amuqhMJgo6iBrIY9VJLQvQAAAJY"]
[Thu Jul 30 14:48:20.320949 2026] [security2:error] [pid 62112:tid 62314] [client 172.213.244.85:45061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/chosen.php"] [unique_id "amuqhMJgo6iBrIY9VJLQxgAAAM0"]
[Thu Jul 30 14:48:20.321058 2026] [security2:error] [pid 62112:tid 62314] [client 172.213.244.85:45061] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/chosen.php"] [unique_id "amuqhMJgo6iBrIY9VJLQxgAAAM0"]
[Thu Jul 30 14:48:20.551662 2026] [security2:error] [pid 62112:tid 62279] [client 185.177.72.67:41742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/wordpress.sql"] [unique_id "amuqhMJgo6iBrIY9VJLQzgAAAKo"]
[Thu Jul 30 14:48:20.650176 2026] [security2:error] [pid 62112:tid 62332] [client 172.213.244.85:19220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/sd.php"] [unique_id "amuqhMJgo6iBrIY9VJLQ0wAAAN8"]
[Thu Jul 30 14:48:20.650282 2026] [security2:error] [pid 62112:tid 62332] [client 172.213.244.85:19220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/sd.php"] [unique_id "amuqhMJgo6iBrIY9VJLQ0wAAAN8"]
[Thu Jul 30 14:48:20.657004 2026] [security2:error] [pid 62112:tid 62276] [client 20.226.5.174:17677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/default.php"] [unique_id "amuqhMJgo6iBrIY9VJLQ1AAAAKc"]
[Thu Jul 30 14:48:21.044753 2026] [security2:error] [pid 62112:tid 62334] [client 172.213.244.85:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/z60.php"] [unique_id "amuqhcJgo6iBrIY9VJLQ7QAAAOE"]
[Thu Jul 30 14:48:21.044856 2026] [security2:error] [pid 62112:tid 62334] [client 172.213.244.85:53418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/z60.php"] [unique_id "amuqhcJgo6iBrIY9VJLQ7QAAAOE"]
[Thu Jul 30 14:48:21.204631 2026] [core:notice] [pid 62112:tid 62355] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:21.372280 2026] [security2:error] [pid 62112:tid 62295] [client 172.213.244.85:14623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/home.php"] [unique_id "amuqhcJgo6iBrIY9VJLQ-QAAALo"]
[Thu Jul 30 14:48:21.372382 2026] [security2:error] [pid 62112:tid 62295] [client 172.213.244.85:14623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/home.php"] [unique_id "amuqhcJgo6iBrIY9VJLQ-QAAALo"]
[Thu Jul 30 14:48:21.587472 2026] [security2:error] [pid 62112:tid 62314] [client 185.177.72.67:41742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env~"] [unique_id "amuqhcJgo6iBrIY9VJLRBgAAAM0"]
[Thu Jul 30 14:48:21.657919 2026] [security2:error] [pid 62112:tid 62328] [client 20.226.5.174:17671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/default_folders.php"] [unique_id "amuqhcJgo6iBrIY9VJLRBwAAANs"]
[Thu Jul 30 14:48:21.673070 2026] [security2:error] [pid 62112:tid 62335] [client 172.213.244.85:57202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/ws58.php"] [unique_id "amuqhcJgo6iBrIY9VJLRCQAAAOI"]
[Thu Jul 30 14:48:21.673170 2026] [security2:error] [pid 62112:tid 62335] [client 172.213.244.85:57202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/ws58.php"] [unique_id "amuqhcJgo6iBrIY9VJLRCQAAAOI"]
[Thu Jul 30 14:48:22.038273 2026] [security2:error] [pid 62112:tid 62362] [client 74.7.175.134:48416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.womenclothingbox.com"] [uri "/cgi-sys/404.html"] [unique_id "amuqhsJgo6iBrIY9VJLRFwAA_RI"]
[Thu Jul 30 14:48:22.044438 2026] [security2:error] [pid 62112:tid 62317] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqhcJgo6iBrIY9VJLQ_QAA0BE"]
[Thu Jul 30 14:48:22.152581 2026] [security2:error] [pid 62112:tid 62321] [client 172.213.244.85:40746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/gulu.php"] [unique_id "amuqhsJgo6iBrIY9VJLRGwAAANQ"]
[Thu Jul 30 14:48:22.152671 2026] [security2:error] [pid 62112:tid 62321] [client 172.213.244.85:40746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/gulu.php"] [unique_id "amuqhsJgo6iBrIY9VJLRGwAAANQ"]
[Thu Jul 30 14:48:22.497069 2026] [security2:error] [pid 62112:tid 62274] [client 172.213.244.85:49910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuqhsJgo6iBrIY9VJLRKwAAAKU"]
[Thu Jul 30 14:48:22.497180 2026] [security2:error] [pid 62112:tid 62274] [client 172.213.244.85:49910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amuqhsJgo6iBrIY9VJLRKwAAAKU"]
[Thu Jul 30 14:48:22.691157 2026] [core:notice] [pid 62112:tid 62290] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:22.748858 2026] [security2:error] [pid 62112:tid 62291] [client 20.226.5.174:17680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/defaults.php"] [unique_id "amuqhsJgo6iBrIY9VJLRNAAAALY"]
[Thu Jul 30 14:48:22.944521 2026] [security2:error] [pid 62112:tid 62316] [client 172.213.244.85:17735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wpls.php"] [unique_id "amuqhsJgo6iBrIY9VJLROwAAAM8"]
[Thu Jul 30 14:48:22.944645 2026] [security2:error] [pid 62112:tid 62316] [client 172.213.244.85:17735] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wpls.php"] [unique_id "amuqhsJgo6iBrIY9VJLROwAAAM8"]
[Thu Jul 30 14:48:23.014315 2026] [security2:error] [pid 62112:tid 62366] [client 52.238.199.152:47251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/login.php"] [unique_id "amuqh8Jgo6iBrIY9VJLRPgAAAQE"]
[Thu Jul 30 14:48:23.184234 2026] [core:notice] [pid 62112:tid 62246] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:23.354728 2026] [security2:error] [pid 62112:tid 62287] [client 172.213.244.85:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/php.php"] [unique_id "amuqh8Jgo6iBrIY9VJLRTwAAALI"]
[Thu Jul 30 14:48:23.354841 2026] [security2:error] [pid 62112:tid 62287] [client 172.213.244.85:14620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/php.php"] [unique_id "amuqh8Jgo6iBrIY9VJLRTwAAALI"]
[Thu Jul 30 14:48:23.736188 2026] [security2:error] [pid 62112:tid 62314] [client 20.226.5.174:17682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/degesaciihaxor.php"] [unique_id "amuqh8Jgo6iBrIY9VJLRXAAAAM0"]
[Thu Jul 30 14:48:23.743135 2026] [security2:error] [pid 62112:tid 62306] [client 172.213.244.85:40724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/100.php"] [unique_id "amuqh8Jgo6iBrIY9VJLRXQAAAMU"]
[Thu Jul 30 14:48:23.743209 2026] [security2:error] [pid 62112:tid 62306] [client 172.213.244.85:40724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/100.php"] [unique_id "amuqh8Jgo6iBrIY9VJLRXQAAAMU"]
[Thu Jul 30 14:48:24.176413 2026] [security2:error] [pid 62112:tid 62250] [client 172.213.244.85:14617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/BDKR28WP.php"] [unique_id "amuqiMJgo6iBrIY9VJLRbQAAAI0"]
[Thu Jul 30 14:48:24.176531 2026] [security2:error] [pid 62112:tid 62250] [client 172.213.244.85:14617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/BDKR28WP.php"] [unique_id "amuqiMJgo6iBrIY9VJLRbQAAAI0"]
[Thu Jul 30 14:48:24.353216 2026] [security2:error] [pid 62112:tid 62251] [client 52.238.199.152:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/aged.php"] [unique_id "amuqiMJgo6iBrIY9VJLRdAAAAI4"]
[Thu Jul 30 14:48:24.513862 2026] [security2:error] [pid 62112:tid 62356] [client 172.213.244.85:53436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/browse.php"] [unique_id "amuqiMJgo6iBrIY9VJLRfQAAAPc"]
[Thu Jul 30 14:48:24.513955 2026] [security2:error] [pid 62112:tid 62356] [client 172.213.244.85:53436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/browse.php"] [unique_id "amuqiMJgo6iBrIY9VJLRfQAAAPc"]
[Thu Jul 30 14:48:24.775828 2026] [security2:error] [pid 62112:tid 62289] [client 20.226.5.174:17693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/degeselih.php"] [unique_id "amuqiMJgo6iBrIY9VJLRgQAAALQ"]
[Thu Jul 30 14:48:24.889778 2026] [security2:error] [pid 62112:tid 62266] [client 172.213.244.85:26592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-good.php"] [unique_id "amuqiMJgo6iBrIY9VJLRhQAAAJ0"]
[Thu Jul 30 14:48:24.889864 2026] [security2:error] [pid 62112:tid 62266] [client 172.213.244.85:26592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-good.php"] [unique_id "amuqiMJgo6iBrIY9VJLRhQAAAJ0"]
[Thu Jul 30 14:48:25.114962 2026] [security2:error] [pid 62112:tid 62283] [client 189.156.226.90:27013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqicJgo6iBrIY9VJLRjwAAAK4"]
[Thu Jul 30 14:48:25.115109 2026] [security2:error] [pid 62112:tid 62283] [client 189.156.226.90:27013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqicJgo6iBrIY9VJLRjwAAAK4"]
[Thu Jul 30 14:48:25.407020 2026] [security2:error] [pid 62112:tid 62304] [client 172.213.244.85:12583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/8573.php"] [unique_id "amuqicJgo6iBrIY9VJLRkgAAAMM"]
[Thu Jul 30 14:48:25.407140 2026] [security2:error] [pid 62112:tid 62304] [client 172.213.244.85:12583] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/8573.php"] [unique_id "amuqicJgo6iBrIY9VJLRkgAAAMM"]
[Thu Jul 30 14:48:25.472265 2026] [security2:error] [pid 62112:tid 62316] [client 52.238.199.152:51029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/vv.php"] [unique_id "amuqicJgo6iBrIY9VJLRnAAAAM8"]
[Thu Jul 30 14:48:25.789640 2026] [security2:error] [pid 62112:tid 62347] [client 20.226.5.174:17673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/dejavu.php"] [unique_id "amuqicJgo6iBrIY9VJLRpgAAAO4"]
[Thu Jul 30 14:48:25.927262 2026] [security2:error] [pid 62112:tid 62293] [client 172.213.244.85:53424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-admin/install.php"] [unique_id "amuqicJgo6iBrIY9VJLRqQAAALg"]
[Thu Jul 30 14:48:25.927352 2026] [security2:error] [pid 62112:tid 62293] [client 172.213.244.85:53424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-admin/install.php"] [unique_id "amuqicJgo6iBrIY9VJLRqQAAALg"]
[Thu Jul 30 14:48:26.428508 2026] [security2:error] [pid 62112:tid 62366] [client 172.213.244.85:17476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/classwithtostring.php"] [unique_id "amuqisJgo6iBrIY9VJLRvAAAAQE"]
[Thu Jul 30 14:48:26.428606 2026] [security2:error] [pid 62112:tid 62366] [client 172.213.244.85:17476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/classwithtostring.php"] [unique_id "amuqisJgo6iBrIY9VJLRvAAAAQE"]
[Thu Jul 30 14:48:26.822971 2026] [security2:error] [pid 62112:tid 62363] [client 172.213.244.85:57153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/ohct.php"] [unique_id "amuqisJgo6iBrIY9VJLR2gAAAP4"]
[Thu Jul 30 14:48:26.823108 2026] [security2:error] [pid 62112:tid 62363] [client 172.213.244.85:57153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/ohct.php"] [unique_id "amuqisJgo6iBrIY9VJLR2gAAAP4"]
[Thu Jul 30 14:48:26.900990 2026] [security2:error] [pid 62112:tid 62339] [client 20.226.5.174:17681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/delpaths.php"] [unique_id "amuqisJgo6iBrIY9VJLR3AAAAOY"]
[Thu Jul 30 14:48:27.286252 2026] [security2:error] [pid 62112:tid 62308] [client 172.213.244.85:40766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/bless.php"] [unique_id "amuqi8Jgo6iBrIY9VJLR6wAAAMc"]
[Thu Jul 30 14:48:27.286353 2026] [security2:error] [pid 62112:tid 62308] [client 172.213.244.85:40766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/bless.php"] [unique_id "amuqi8Jgo6iBrIY9VJLR6wAAAMc"]
[Thu Jul 30 14:48:27.736124 2026] [security2:error] [pid 62112:tid 62273] [client 172.213.244.85:17784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/about.php"] [unique_id "amuqi8Jgo6iBrIY9VJLR_QAAAKQ"]
[Thu Jul 30 14:48:27.736273 2026] [security2:error] [pid 62112:tid 62273] [client 172.213.244.85:17784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/about.php"] [unique_id "amuqi8Jgo6iBrIY9VJLR_QAAAKQ"]
[Thu Jul 30 14:48:27.998749 2026] [security2:error] [pid 62112:tid 62325] [client 20.226.5.174:17668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/demo.php"] [unique_id "amuqi8Jgo6iBrIY9VJLSAQAAANg"]
[Thu Jul 30 14:48:28.214200 2026] [security2:error] [pid 62112:tid 62302] [client 172.213.244.85:53401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuqjMJgo6iBrIY9VJLSEQAAAME"]
[Thu Jul 30 14:48:28.214303 2026] [security2:error] [pid 62112:tid 62302] [client 172.213.244.85:53401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuqjMJgo6iBrIY9VJLSEQAAAME"]
[Thu Jul 30 14:48:28.396427 2026] [fcgid:warn] [pid 62112:tid 62276] (70014)End of file found: [client 185.177.72.67:30948] mod_fcgid: can't get data from http client
[Thu Jul 30 14:48:28.618276 2026] [security2:error] [pid 62112:tid 62348] [client 172.213.244.85:20504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/ta0ol.php"] [unique_id "amuqjMJgo6iBrIY9VJLSGwAAAO8"]
[Thu Jul 30 14:48:28.618370 2026] [security2:error] [pid 62112:tid 62348] [client 172.213.244.85:20504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/ta0ol.php"] [unique_id "amuqjMJgo6iBrIY9VJLSGwAAAO8"]
[Thu Jul 30 14:48:28.648821 2026] [fcgid:warn] [pid 62112:tid 62329] (70014)End of file found: [client 185.177.72.67:30960] mod_fcgid: can't get data from http client
[Thu Jul 30 14:48:28.905407 2026] [fcgid:warn] [pid 62112:tid 62265] (70014)End of file found: [client 185.177.72.67:22692] mod_fcgid: can't get data from http client
[Thu Jul 30 14:48:28.994368 2026] [security2:error] [pid 62112:tid 62292] [client 20.226.5.174:17672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/demos.php"] [unique_id "amuqjMJgo6iBrIY9VJLSJgAAALc"]
[Thu Jul 30 14:48:29.054171 2026] [security2:error] [pid 62112:tid 62353] [client 172.213.244.85:14613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/sa.php7"] [unique_id "amuqjcJgo6iBrIY9VJLSJwAAAPQ"]
[Thu Jul 30 14:48:29.054271 2026] [security2:error] [pid 62112:tid 62353] [client 172.213.244.85:14613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/sa.php7"] [unique_id "amuqjcJgo6iBrIY9VJLSJwAAAPQ"]
[Thu Jul 30 14:48:29.152602 2026] [fcgid:warn] [pid 62112:tid 62337] (70014)End of file found: [client 185.177.72.67:22704] mod_fcgid: can't get data from http client
[Thu Jul 30 14:48:29.414346 2026] [security2:error] [pid 62112:tid 62284] [client 172.213.244.85:14611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-class.php"] [unique_id "amuqjcJgo6iBrIY9VJLSNAAAAK8"]
[Thu Jul 30 14:48:29.414429 2026] [security2:error] [pid 62112:tid 62284] [client 172.213.244.85:14611] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-class.php"] [unique_id "amuqjcJgo6iBrIY9VJLSNAAAAK8"]
[Thu Jul 30 14:48:29.874029 2026] [security2:error] [pid 62112:tid 62323] [client 172.213.244.85:43050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/8.php"] [unique_id "amuqjcJgo6iBrIY9VJLSQQAAANY"]
[Thu Jul 30 14:48:29.874123 2026] [security2:error] [pid 62112:tid 62323] [client 172.213.244.85:43050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/8.php"] [unique_id "amuqjcJgo6iBrIY9VJLSQQAAANY"]
[Thu Jul 30 14:48:30.059265 2026] [core:notice] [pid 62112:tid 62322] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:30.203201 2026] [security2:error] [pid 62112:tid 62267] [client 185.177.72.67:22714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/en.orig"] [unique_id "amuqjsJgo6iBrIY9VJLSSAAAAJ4"]
[Thu Jul 30 14:48:30.241168 2026] [security2:error] [pid 62112:tid 62282] [client 172.213.244.85:17483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/bootstrap.php"] [unique_id "amuqjsJgo6iBrIY9VJLSTQAAAK0"]
[Thu Jul 30 14:48:30.241281 2026] [security2:error] [pid 62112:tid 62282] [client 172.213.244.85:17483] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/bootstrap.php"] [unique_id "amuqjsJgo6iBrIY9VJLSTQAAAK0"]
[Thu Jul 30 14:48:30.411443 2026] [security2:error] [pid 62112:tid 62320] [client 20.226.5.174:17686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/dep.php"] [unique_id "amuqjsJgo6iBrIY9VJLSUQAAANM"]
[Thu Jul 30 14:48:30.542839 2026] [security2:error] [pid 62112:tid 62354] [client 172.213.244.85:26579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-blog-header.php"] [unique_id "amuqjsJgo6iBrIY9VJLSVAAAAPU"]
[Thu Jul 30 14:48:30.542942 2026] [security2:error] [pid 62112:tid 62354] [client 172.213.244.85:26579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-blog-header.php"] [unique_id "amuqjsJgo6iBrIY9VJLSVAAAAPU"]
[Thu Jul 30 14:48:30.941485 2026] [security2:error] [pid 62112:tid 62245] [client 172.213.244.85:49877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/aa.php"] [unique_id "amuqjsJgo6iBrIY9VJLSagAAAIg"]
[Thu Jul 30 14:48:30.941645 2026] [security2:error] [pid 62112:tid 62245] [client 172.213.244.85:49877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/aa.php"] [unique_id "amuqjsJgo6iBrIY9VJLSagAAAIg"]
[Thu Jul 30 14:48:31.029248 2026] [security2:error] [pid 62112:tid 62285] [client 52.238.199.152:37124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/user-edit.php"] [unique_id "amuqj8Jgo6iBrIY9VJLSbAAAALA"]
[Thu Jul 30 14:48:31.143455 2026] [security2:error] [pid 62112:tid 62369] [client 185.177.72.67:22714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/o.php"] [unique_id "amuqj8Jgo6iBrIY9VJLSdwAAAQQ"]
[Thu Jul 30 14:48:31.410015 2026] [security2:error] [pid 62112:tid 62319] [client 185.177.72.67:22728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/o.php%2f"] [unique_id "amuqj8Jgo6iBrIY9VJLSfgAAANI"]
[Thu Jul 30 14:48:31.454900 2026] [security2:error] [pid 62112:tid 62366] [client 172.213.244.85:53434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/tx79.php"] [unique_id "amuqj8Jgo6iBrIY9VJLSfwAAAQE"]
[Thu Jul 30 14:48:31.455039 2026] [security2:error] [pid 62112:tid 62366] [client 172.213.244.85:53434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/tx79.php"] [unique_id "amuqj8Jgo6iBrIY9VJLSfwAAAQE"]
[Thu Jul 30 14:48:31.489892 2026] [security2:error] [pid 62112:tid 62345] [client 20.226.5.174:17709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/deploy.php"] [unique_id "amuqj8Jgo6iBrIY9VJLSgAAAAOw"]
[Thu Jul 30 14:48:31.665589 2026] [security2:error] [pid 62112:tid 62315] [client 185.177.72.67:22744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/o.php..."] [unique_id "amuqj8Jgo6iBrIY9VJLShAAAAM4"]
[Thu Jul 30 14:48:31.699028 2026] [security2:error] [pid 62112:tid 62159] [remote 216.73.216.51:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqj8Jgo6iBrIY9VJLShQAAmS4"]
[Thu Jul 30 14:48:31.802857 2026] [security2:error] [pid 62112:tid 62255] [client 172.213.244.85:53394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/motu.php"] [unique_id "amuqj8Jgo6iBrIY9VJLShgAAAJI"]
[Thu Jul 30 14:48:31.802966 2026] [security2:error] [pid 62112:tid 62255] [client 172.213.244.85:53394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/motu.php"] [unique_id "amuqj8Jgo6iBrIY9VJLShgAAAJI"]
[Thu Jul 30 14:48:31.934851 2026] [security2:error] [pid 62112:tid 62307] [client 185.177.72.67:22748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/o.php.swp"] [unique_id "amuqj8Jgo6iBrIY9VJLSjgAAAMY"]
[Thu Jul 30 14:48:32.165022 2026] [security2:error] [pid 62112:tid 62348] [client 172.213.244.85:43070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-head.php"] [unique_id "amuqkMJgo6iBrIY9VJLSkgAAAO8"]
[Thu Jul 30 14:48:32.165149 2026] [security2:error] [pid 62112:tid 62348] [client 172.213.244.85:43070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-head.php"] [unique_id "amuqkMJgo6iBrIY9VJLSkgAAAO8"]
[Thu Jul 30 14:48:32.194148 2026] [security2:error] [pid 62112:tid 62161] [remote 57.141.0.19:49704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuqkMJgo6iBrIY9VJLSlQAAqTA"]
[Thu Jul 30 14:48:32.371420 2026] [security2:error] [pid 62112:tid 62302] [client 52.238.199.152:37152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuqkMJgo6iBrIY9VJLSoAAAAME"]
[Thu Jul 30 14:48:32.526758 2026] [security2:error] [pid 62112:tid 62309] [client 20.226.5.174:17676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/deprecated.php"] [unique_id "amuqkMJgo6iBrIY9VJLSqAAAAMg"]
[Thu Jul 30 14:48:32.950450 2026] [security2:error] [pid 62112:tid 62351] [client 172.213.244.85:12571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuqkMJgo6iBrIY9VJLSuQAAAPI"]
[Thu Jul 30 14:48:32.950537 2026] [security2:error] [pid 62112:tid 62351] [client 172.213.244.85:12571] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amuqkMJgo6iBrIY9VJLSuQAAAPI"]
[Thu Jul 30 14:48:33.217847 2026] [security2:error] [pid 62112:tid 62148] [remote 216.73.216.51:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqkcJgo6iBrIY9VJLSwQAAuCM"]
[Thu Jul 30 14:48:33.316211 2026] [security2:error] [pid 62112:tid 62299] [client 172.213.244.85:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/60856e3a4findex.php"] [unique_id "amuqkcJgo6iBrIY9VJLSwwAAAL4"]
[Thu Jul 30 14:48:33.316392 2026] [security2:error] [pid 62112:tid 62299] [client 172.213.244.85:26590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/60856e3a4findex.php"] [unique_id "amuqkcJgo6iBrIY9VJLSwwAAAL4"]
[Thu Jul 30 14:48:33.528367 2026] [security2:error] [pid 62112:tid 62243] [client 20.226.5.174:17674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/descargas.php"] [unique_id "amuqkcJgo6iBrIY9VJLS0AAAAIY"]
[Thu Jul 30 14:48:33.645512 2026] [security2:error] [pid 62112:tid 62338] [client 35.204.197.107:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "website-7c59acf7.vdb.nyx.temporary.site"] [uri "/"] [unique_id "amuqkcJgo6iBrIY9VJLS1QAAAOU"]
[Thu Jul 30 14:48:33.645625 2026] [security2:error] [pid 62112:tid 62338] [client 35.204.197.107:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "website-7c59acf7.vdb.nyx.temporary.site"] [uri "/"] [unique_id "amuqkcJgo6iBrIY9VJLS1QAAAOU"]
[Thu Jul 30 14:48:33.702091 2026] [security2:error] [pid 62112:tid 62369] [client 172.213.244.85:43032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp-the.php"] [unique_id "amuqkcJgo6iBrIY9VJLS1wAAAQQ"]
[Thu Jul 30 14:48:33.702186 2026] [security2:error] [pid 62112:tid 62369] [client 172.213.244.85:43032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp-the.php"] [unique_id "amuqkcJgo6iBrIY9VJLS1wAAAQQ"]
[Thu Jul 30 14:48:33.993241 2026] [security2:error] [pid 62112:tid 62284] [client 172.213.244.85:53388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wp.php"] [unique_id "amuqkcJgo6iBrIY9VJLS5AAAAK8"]
[Thu Jul 30 14:48:33.993347 2026] [security2:error] [pid 62112:tid 62284] [client 172.213.244.85:53388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wp.php"] [unique_id "amuqkcJgo6iBrIY9VJLS5AAAAK8"]
[Thu Jul 30 14:48:34.084463 2026] [security2:error] [pid 62112:tid 62334] [client 103.82.26.211:58225] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.qpsuae.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuqksJgo6iBrIY9VJLS6QAAAOE"]
[Thu Jul 30 14:48:34.202290 2026] [security2:error] [pid 62112:tid 62309] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/app.swp"] [unique_id "amuqksJgo6iBrIY9VJLS6wAAAMg"]
[Thu Jul 30 14:48:34.403544 2026] [security2:error] [pid 62112:tid 62315] [client 172.213.244.85:40715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/users.php"] [unique_id "amuqksJgo6iBrIY9VJLS8wAAAM4"]
[Thu Jul 30 14:48:34.403699 2026] [security2:error] [pid 62112:tid 62315] [client 172.213.244.85:40715] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/users.php"] [unique_id "amuqksJgo6iBrIY9VJLS8wAAAM4"]
[Thu Jul 30 14:48:34.444326 2026] [security2:error] [pid 62112:tid 62283] [client 103.82.26.211:58256] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.qpsuae.com"] [uri "/___proxy_subdomain_cpanel/wp-json/batch/v1"] [unique_id "amuqksJgo6iBrIY9VJLS9AAAAK4"]
[Thu Jul 30 14:48:34.613500 2026] [security2:error] [pid 62112:tid 62312] [client 20.226.5.174:17690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/details.php"] [unique_id "amuqksJgo6iBrIY9VJLS_gAAAMs"]
[Thu Jul 30 14:48:34.692666 2026] [security2:error] [pid 62112:tid 62263] [client 172.237.109.114:57902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuqksJgo6iBrIY9VJLS6gAAAJo"], referer: https://alseermarine.com:443
[Thu Jul 30 14:48:34.722508 2026] [security2:error] [pid 62112:tid 62150] [remote 216.73.216.51:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuqksJgo6iBrIY9VJLTAwAA6iU"]
[Thu Jul 30 14:48:34.760088 2026] [security2:error] [pid 62112:tid 62320] [client 172.213.244.85:43060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/tinysd.php"] [unique_id "amuqksJgo6iBrIY9VJLTBAAAANM"]
[Thu Jul 30 14:48:34.760222 2026] [security2:error] [pid 62112:tid 62320] [client 172.213.244.85:43060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/tinysd.php"] [unique_id "amuqksJgo6iBrIY9VJLTBAAAANM"]
[Thu Jul 30 14:48:34.921918 2026] [security2:error] [pid 62112:tid 62293] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htpasswd"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.terraform.htpasswd"] [unique_id "amuqksJgo6iBrIY9VJLTCAAAALg"]
[Thu Jul 30 14:48:35.095381 2026] [security2:error] [pid 62112:tid 62297] [client 172.213.244.85:40765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/ws78.php"] [unique_id "amuqk8Jgo6iBrIY9VJLTEAAAALw"]
[Thu Jul 30 14:48:35.095474 2026] [security2:error] [pid 62112:tid 62297] [client 172.213.244.85:40765] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/ws78.php"] [unique_id "amuqk8Jgo6iBrIY9VJLTEAAAALw"]
[Thu Jul 30 14:48:35.228277 2026] [security2:error] [pid 62112:tid 62199] [remote 216.73.216.51:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqk8Jgo6iBrIY9VJLTEwAAzFY"]
[Thu Jul 30 14:48:35.350586 2026] [security2:error] [pid 62112:tid 62349] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/log.txt~"] [unique_id "amuqk8Jgo6iBrIY9VJLTFwAAAPA"]
[Thu Jul 30 14:48:35.486427 2026] [security2:error] [pid 62112:tid 62314] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/log.txt.bak"] [unique_id "amuqk8Jgo6iBrIY9VJLTGAAAAM0"]
[Thu Jul 30 14:48:35.538813 2026] [security2:error] [pid 62112:tid 62298] [client 172.213.244.85:57206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/elp.php"] [unique_id "amuqk8Jgo6iBrIY9VJLTHgAAAL0"]
[Thu Jul 30 14:48:35.538937 2026] [security2:error] [pid 62112:tid 62298] [client 172.213.244.85:57206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/elp.php"] [unique_id "amuqk8Jgo6iBrIY9VJLTHgAAAL0"]
[Thu Jul 30 14:48:35.639412 2026] [security2:error] [pid 62112:tid 62346] [client 20.226.5.174:17698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/dev.php"] [unique_id "amuqk8Jgo6iBrIY9VJLTIwAAAO0"]
[Thu Jul 30 14:48:35.667101 2026] [security2:error] [pid 62112:tid 62278] [client 189.156.226.90:27377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqk8Jgo6iBrIY9VJLTJAAAAKk"]
[Thu Jul 30 14:48:35.667204 2026] [security2:error] [pid 62112:tid 62278] [client 189.156.226.90:27377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqk8Jgo6iBrIY9VJLTJAAAAKk"]
[Thu Jul 30 14:48:35.948620 2026] [security2:error] [pid 62112:tid 62289] [client 172.213.244.85:57214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/atomlib.php"] [unique_id "amuqk8Jgo6iBrIY9VJLTLQAAALQ"]
[Thu Jul 30 14:48:35.948725 2026] [security2:error] [pid 62112:tid 62289] [client 172.213.244.85:57214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/atomlib.php"] [unique_id "amuqk8Jgo6iBrIY9VJLTLQAAALQ"]
[Thu Jul 30 14:48:36.407564 2026] [security2:error] [pid 62112:tid 62315] [client 172.213.244.85:58626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/wyzer3.php"] [unique_id "amuqlMJgo6iBrIY9VJLTQAAAAM4"]
[Thu Jul 30 14:48:36.407705 2026] [security2:error] [pid 62112:tid 62315] [client 172.213.244.85:58626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/wyzer3.php"] [unique_id "amuqlMJgo6iBrIY9VJLTQAAAAM4"]
[Thu Jul 30 14:48:36.717140 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.244.85:57170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/max.php"] [unique_id "amuqlMJgo6iBrIY9VJLTTQAAAIs"]
[Thu Jul 30 14:48:36.717236 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.244.85:57170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/max.php"] [unique_id "amuqlMJgo6iBrIY9VJLTTQAAAIs"]
[Thu Jul 30 14:48:36.736855 2026] [security2:error] [pid 62112:tid 62224] [remote 216.73.216.51:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuqlMJgo6iBrIY9VJLTTgAAmm8"]
[Thu Jul 30 14:48:36.758215 2026] [security2:error] [pid 62112:tid 62357] [client 20.226.5.174:17694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/devil.php"] [unique_id "amuqlMJgo6iBrIY9VJLTTwAAAPg"]
[Thu Jul 30 14:48:37.194108 2026] [security2:error] [pid 62112:tid 62317] [client 172.213.244.85:14615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.244.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.instomail.com"] [uri "/ftde.php"] [unique_id "amuqlcJgo6iBrIY9VJLTWgAAANA"]
[Thu Jul 30 14:48:37.194208 2026] [security2:error] [pid 62112:tid 62317] [client 172.213.244.85:14615] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.instomail.com"] [uri "/ftde.php"] [unique_id "amuqlcJgo6iBrIY9VJLTWgAAANA"]
[Thu Jul 30 14:48:37.734793 2026] [security2:error] [pid 62112:tid 62364] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/nodeapi%00"] [unique_id "amuqlcJgo6iBrIY9VJLTawAAAP8"]
[Thu Jul 30 14:48:37.763570 2026] [security2:error] [pid 62112:tid 62313] [client 20.226.5.174:17684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/dex.php"] [unique_id "amuqlcJgo6iBrIY9VJLTbwAAAMw"]
[Thu Jul 30 14:48:37.869699 2026] [security2:error] [pid 62112:tid 62356] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqlcJgo6iBrIY9VJLTcAAAAPc"]
[Thu Jul 30 14:48:38.005498 2026] [security2:error] [pid 62112:tid 62247] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqlsJgo6iBrIY9VJLTdAAAAIo"]
[Thu Jul 30 14:48:38.144005 2026] [security2:error] [pid 62112:tid 62363] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqlsJgo6iBrIY9VJLTdQAAAP4"]
[Thu Jul 30 14:48:38.281112 2026] [security2:error] [pid 62112:tid 62327] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/.env"] [unique_id "amuqlsJgo6iBrIY9VJLTgQAAANo"]
[Thu Jul 30 14:48:39.049505 2026] [security2:error] [pid 62112:tid 62309] [client 20.226.5.174:17697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/dfre.php"] [unique_id "amuql8Jgo6iBrIY9VJLTmQAAAMg"]
[Thu Jul 30 14:48:39.245711 2026] [security2:error] [pid 62112:tid 62236] [remote 216.73.216.51:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuql8Jgo6iBrIY9VJLTnwAA2Hs"]
[Thu Jul 30 14:48:40.060764 2026] [security2:error] [pid 62112:tid 62272] [client 20.226.5.174:17687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/dialog.php"] [unique_id "amuqmMJgo6iBrIY9VJLTtQAAAKM"]
[Thu Jul 30 14:48:40.426601 2026] [security2:error] [pid 62112:tid 62279] [client 177.6.106.101:55598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqmMJgo6iBrIY9VJLTwQAAAKo"]
[Thu Jul 30 14:48:40.426712 2026] [security2:error] [pid 62112:tid 62279] [client 177.6.106.101:55598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqmMJgo6iBrIY9VJLTwQAAAKo"]
[Thu Jul 30 14:48:40.775452 2026] [security2:error] [pid 62112:tid 62347] [client 52.238.199.152:3670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/engine.php"] [unique_id "amuqmMJgo6iBrIY9VJLTzwAAAO4"]
[Thu Jul 30 14:48:41.202602 2026] [security2:error] [pid 62112:tid 62310] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "aded-rdc.org"] [uri "/projects.bak"] [unique_id "amuqmcJgo6iBrIY9VJLT2wAAAMk"]
[Thu Jul 30 14:48:41.219901 2026] [security2:error] [pid 62112:tid 62368] [client 20.226.5.174:17720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/digital-download/new.php"] [unique_id "amuqmcJgo6iBrIY9VJLT3AAAAQM"]
[Thu Jul 30 14:48:41.339547 2026] [security2:error] [pid 62112:tid 62367] [client 185.177.72.67:22758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aded-rdc.org"] [uri "/wp-config.php.backup"] [unique_id "amuqmcJgo6iBrIY9VJLT3wAAAQI"]
[Thu Jul 30 14:48:41.525417 2026] [security2:error] [pid 62112:tid 62259] [client 74.7.228.4:47062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-c2c617cc.pwy.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuqmcJgo6iBrIY9VJLT5QAAAJY"]
[Thu Jul 30 14:48:41.597547 2026] [security2:error] [pid 62112:tid 62282] [client 185.177.72.67:32480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aded-rdc.org"] [uri "/wp-config.php.backup%253e"] [unique_id "amuqmcJgo6iBrIY9VJLT6QAAAK0"]
[Thu Jul 30 14:48:41.863869 2026] [security2:error] [pid 62112:tid 62320] [client 185.177.72.67:32488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aded-rdc.org"] [uri "/wp-config.php.backup%7c"] [unique_id "amuqmcJgo6iBrIY9VJLT6gAAANM"]
[Thu Jul 30 14:48:41.961843 2026] [security2:error] [pid 62112:tid 62270] [client 127.0.0.1:37112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuqmcJgo6iBrIY9VJLT8AAAAKE"]
[Thu Jul 30 14:48:41.961933 2026] [security2:error] [pid 62112:tid 62263] [client 74.7.230.4:56362] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wdr.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuqmcJgo6iBrIY9VJLT7wAAmgg"]
[Thu Jul 30 14:48:42.093119 2026] [security2:error] [pid 62112:tid 62309] [client 52.238.199.152:37264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/edit-comments.php"] [unique_id "amuqmsJgo6iBrIY9VJLT_gAAAMg"]
[Thu Jul 30 14:48:42.119449 2026] [security2:error] [pid 62112:tid 62358] [client 185.177.72.67:32504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aded-rdc.org"] [uri "/wp-config.php.backup.zshrc"] [unique_id "amuqmsJgo6iBrIY9VJLT_wAAAPk"]
[Thu Jul 30 14:48:42.323844 2026] [security2:error] [pid 62112:tid 62318] [client 20.226.5.174:17705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/digital-download/up.php"] [unique_id "amuqmsJgo6iBrIY9VJLUAwAAANE"]
[Thu Jul 30 14:48:42.708656 2026] [security2:error] [pid 62112:tid 62248] [client 74.7.241.177:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.portugalvisaapplicationcenterinislamabad.site"] [uri "/index.php"] [unique_id "amuqmcJgo6iBrIY9VJLT9wAAAIs"]
[Thu Jul 30 14:48:42.709361 2026] [security2:error] [pid 62112:tid 62354] [client 74.7.241.177:42274] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.portugalvisaapplicationcenterinislamabad.site"] [uri "/robots.txt"] [unique_id "amuqmcJgo6iBrIY9VJLT9AAA9QY"]
[Thu Jul 30 14:48:43.016305 2026] [security2:error] [pid 62112:tid 62340] [client 52.238.199.152:33765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-blog-header.php"] [unique_id "amuqm8Jgo6iBrIY9VJLUGgAAAOc"]
[Thu Jul 30 14:48:43.483940 2026] [security2:error] [pid 62112:tid 62254] [client 20.226.5.174:17683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/dir.php"] [unique_id "amuqm8Jgo6iBrIY9VJLUJAAAAJE"]
[Thu Jul 30 14:48:43.842957 2026] [security2:error] [pid 62112:tid 62283] [client 43.173.178.203:47922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuqm8Jgo6iBrIY9VJLUKgAAAK4"]
[Thu Jul 30 14:48:44.246479 2026] [security2:error] [pid 62112:tid 62177] [remote 216.73.216.51:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuqnMJgo6iBrIY9VJLUQAAA-UA"]
[Thu Jul 30 14:48:44.688221 2026] [security2:error] [pid 62112:tid 62152] [remote 17.246.19.187:45298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.19.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/8959"] [unique_id "amuqnMJgo6iBrIY9VJLURwAAsCc"]
[Thu Jul 30 14:48:44.909940 2026] [security2:error] [pid 62112:tid 62339] [client 86.216.231.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuqnMJgo6iBrIY9VJLUVgAAAOY"], referer: https://cnpinyin.com
[Thu Jul 30 14:48:45.913114 2026] [security2:error] [pid 62112:tid 62264] [client 185.177.72.67:32510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/index.php"] [unique_id "amuqncJgo6iBrIY9VJLUdQAAAJs"]
[Thu Jul 30 14:48:46.042772 2026] [core:notice] [pid 62112:tid 62322] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:46.166108 2026] [security2:error] [pid 62112:tid 62328] [client 185.177.72.67:32522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/indexf.php"] [unique_id "amuqnsJgo6iBrIY9VJLUfQAAANs"]
[Thu Jul 30 14:48:46.192872 2026] [security2:error] [pid 62112:tid 62361] [client 189.156.226.90:27643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqnsJgo6iBrIY9VJLUfwAAAPw"]
[Thu Jul 30 14:48:46.193002 2026] [security2:error] [pid 62112:tid 62361] [client 189.156.226.90:27643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqnsJgo6iBrIY9VJLUfwAAAPw"]
[Thu Jul 30 14:48:46.428667 2026] [security2:error] [pid 62112:tid 62294] [client 185.177.72.67:32532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/aboutf.php"] [unique_id "amuqnsJgo6iBrIY9VJLUgwAAALk"]
[Thu Jul 30 14:48:46.694788 2026] [security2:error] [pid 62112:tid 62314] [client 185.177.72.67:32544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/misionf.php"] [unique_id "amuqnsJgo6iBrIY9VJLUiAAAAM0"]
[Thu Jul 30 14:48:46.956178 2026] [security2:error] [pid 62112:tid 62243] [client 185.177.72.67:32554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/valuef.php"] [unique_id "amuqnsJgo6iBrIY9VJLUjwAAAIY"]
[Thu Jul 30 14:48:47.233427 2026] [security2:error] [pid 62112:tid 62339] [client 185.177.72.67:32570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/aprochef.php"] [unique_id "amuqn8Jgo6iBrIY9VJLUlgAAAOY"]
[Thu Jul 30 14:48:47.492042 2026] [security2:error] [pid 62112:tid 62344] [client 185.177.72.67:32574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/stafff.php"] [unique_id "amuqn8Jgo6iBrIY9VJLUmwAAAOs"]
[Thu Jul 30 14:48:47.764093 2026] [security2:error] [pid 62112:tid 62287] [client 185.177.72.67:32580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/humanitariaf.php"] [unique_id "amuqn8Jgo6iBrIY9VJLUogAAALI"]
[Thu Jul 30 14:48:47.847176 2026] [core:notice] [pid 62112:tid 62345] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:48.035243 2026] [security2:error] [pid 62112:tid 62350] [client 185.177.72.67:32586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/youthf.php"] [unique_id "amuqoMJgo6iBrIY9VJLUpwAAAPE"]
[Thu Jul 30 14:48:48.286433 2026] [security2:error] [pid 62112:tid 62300] [client 185.177.72.67:32592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/communityf.php"] [unique_id "amuqoMJgo6iBrIY9VJLUsQAAAL8"]
[Thu Jul 30 14:48:48.542401 2026] [security2:error] [pid 62112:tid 62361] [client 185.177.72.67:32600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/rreportf.php"] [unique_id "amuqoMJgo6iBrIY9VJLUtQAAAPw"]
[Thu Jul 30 14:48:48.793259 2026] [security2:error] [pid 62112:tid 62309] [client 52.238.199.152:61752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/alfa-rex.php7"] [unique_id "amuqoMJgo6iBrIY9VJLUvgAAAMg"]
[Thu Jul 30 14:48:48.810607 2026] [security2:error] [pid 62112:tid 62249] [client 185.177.72.67:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/Policyf.php"] [unique_id "amuqoMJgo6iBrIY9VJLUwAAAAIw"]
[Thu Jul 30 14:48:49.063507 2026] [security2:error] [pid 62112:tid 62356] [client 185.177.72.67:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/reportf.php"] [unique_id "amuqocJgo6iBrIY9VJLUxQAAAPc"]
[Thu Jul 30 14:48:49.311572 2026] [security2:error] [pid 62112:tid 62289] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqoMJgo6iBrIY9VJLUrQAAtDk"]
[Thu Jul 30 14:48:49.315116 2026] [security2:error] [pid 62112:tid 62301] [client 185.177.72.67:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/teamf.php"] [unique_id "amuqocJgo6iBrIY9VJLUywAAAMA"]
[Thu Jul 30 14:48:49.572041 2026] [security2:error] [pid 62112:tid 62306] [client 185.177.72.67:6148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/mediaf.php"] [unique_id "amuqocJgo6iBrIY9VJLU0gAAAMU"]
[Thu Jul 30 14:48:49.823020 2026] [security2:error] [pid 62112:tid 62364] [client 185.177.72.67:6156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/storyf.php"] [unique_id "amuqocJgo6iBrIY9VJLU1AAAAP8"]
[Thu Jul 30 14:48:50.089735 2026] [security2:error] [pid 62112:tid 62254] [client 185.177.72.67:6164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/donatef.php"] [unique_id "amuqosJgo6iBrIY9VJLU3wAAAJE"]
[Thu Jul 30 14:48:50.342099 2026] [security2:error] [pid 62112:tid 62310] [client 185.177.72.67:6166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/vloloteerf.php"] [unique_id "amuqosJgo6iBrIY9VJLU4QAAAMk"]
[Thu Jul 30 14:48:50.393543 2026] [security2:error] [pid 62112:tid 62308] [client 177.6.106.101:56161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqosJgo6iBrIY9VJLU5gAAAMc"]
[Thu Jul 30 14:48:50.393634 2026] [security2:error] [pid 62112:tid 62308] [client 177.6.106.101:56161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqosJgo6iBrIY9VJLU5gAAAMc"]
[Thu Jul 30 14:48:50.594153 2026] [security2:error] [pid 62112:tid 62323] [client 185.177.72.67:6174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/partnerf.php"] [unique_id "amuqosJgo6iBrIY9VJLU7AAAANY"]
[Thu Jul 30 14:48:50.848237 2026] [security2:error] [pid 62112:tid 62280] [client 185.177.72.67:6182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/job.php"] [unique_id "amuqosJgo6iBrIY9VJLU8QAAAKs"]
[Thu Jul 30 14:48:50.984317 2026] [core:notice] [pid 62112:tid 62276] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:51.104311 2026] [security2:error] [pid 62112:tid 62360] [client 185.177.72.67:6196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/login.php"] [unique_id "amuqo8Jgo6iBrIY9VJLU-wAAAPs"]
[Thu Jul 30 14:48:51.180878 2026] [security2:error] [pid 62112:tid 62314] [client 52.238.199.152:61700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/pomo/fgertreyersd.php"] [unique_id "amuqo8Jgo6iBrIY9VJLU_QAAAM0"]
[Thu Jul 30 14:48:51.221379 2026] [security2:error] [pid 62112:tid 62317] [client 79.43.250.114:37196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqosJgo6iBrIY9VJLU8gAAANA"], referer: http://pkf.jo
[Thu Jul 30 14:48:51.362476 2026] [security2:error] [pid 62112:tid 62335] [client 185.177.72.67:6200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/contactff.php"] [unique_id "amuqo8Jgo6iBrIY9VJLVBAAAAOI"]
[Thu Jul 30 14:48:51.474632 2026] [security2:error] [pid 62112:tid 62359] [client 190.97.102.237:35856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqo8Jgo6iBrIY9VJLU_AAAAPo"], referer: http://pkf.jo
[Thu Jul 30 14:48:51.620020 2026] [security2:error] [pid 62112:tid 62348] [client 185.177.72.67:6204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-json/gravitysmtp/v1/tests/article.php"] [unique_id "amuqo8Jgo6iBrIY9VJLVDAAAAO8"]
[Thu Jul 30 14:48:51.638324 2026] [security2:error] [pid 62112:tid 62265] [client 45.6.35.73:21986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqo8Jgo6iBrIY9VJLVAQAAAJw"], referer: http://pkf.jo
[Thu Jul 30 14:48:51.992116 2026] [security2:error] [pid 62112:tid 62364] [client 184.75.223.203:39962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuqo8Jgo6iBrIY9VJLVFAAAAP8"]
[Thu Jul 30 14:48:51.992221 2026] [security2:error] [pid 62112:tid 62364] [client 184.75.223.203:39962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuqo8Jgo6iBrIY9VJLVFAAAAP8"]
[Thu Jul 30 14:48:52.340361 2026] [security2:error] [pid 62112:tid 62247] [client 65.93.23.55:43608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqo8Jgo6iBrIY9VJLVDQAAAIo"], referer: http://pkf.jo
[Thu Jul 30 14:48:52.451396 2026] [security2:error] [pid 62112:tid 62278] [client 43.250.80.92:47960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqo8Jgo6iBrIY9VJLVDgAAAKk"], referer: http://pkf.jo
[Thu Jul 30 14:48:52.488093 2026] [security2:error] [pid 62112:tid 62306] [client 185.244.154.185:32956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqo8Jgo6iBrIY9VJLVDwAAAMU"], referer: http://pkf.jo
[Thu Jul 30 14:48:52.971571 2026] [security2:error] [pid 62112:tid 62308] [client 31.3.152.100:45252] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuqpMJgo6iBrIY9VJLVKwAAAMc"]
[Thu Jul 30 14:48:52.971659 2026] [security2:error] [pid 62112:tid 62308] [client 31.3.152.100:45252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuqpMJgo6iBrIY9VJLVKwAAAMc"]
[Thu Jul 30 14:48:53.131311 2026] [security2:error] [pid 62112:tid 62350] [client 52.238.199.152:33776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/css/xmrlpc.php"] [unique_id "amuqpcJgo6iBrIY9VJLVOwAAAPE"]
[Thu Jul 30 14:48:53.256208 2026] [security2:error] [pid 62112:tid 62267] [client 148.230.15.97:53539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqpMJgo6iBrIY9VJLVMAAAAJ4"], referer: http://pkf.jo
[Thu Jul 30 14:48:53.496600 2026] [security2:error] [pid 62112:tid 62361] [client 172.213.232.128:65170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.tmb/LA.php"] [unique_id "amuqpcJgo6iBrIY9VJLVPgAAAPw"]
[Thu Jul 30 14:48:53.568014 2026] [security2:error] [pid 62112:tid 62343] [client 185.99.6.148:26533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqpcJgo6iBrIY9VJLVPAAAAOo"], referer: http://pkf.jo
[Thu Jul 30 14:48:53.596635 2026] [security2:error] [pid 62112:tid 62256] [client 59.103.216.71:37274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqpcJgo6iBrIY9VJLVPQAAAJM"], referer: http://pkf.jo
[Thu Jul 30 14:48:54.256822 2026] [security2:error] [pid 62112:tid 62317] [client 38.9.184.157:37570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqpcJgo6iBrIY9VJLVSgAAANA"], referer: http://pkf.jo
[Thu Jul 30 14:48:54.287121 2026] [security2:error] [pid 62112:tid 62277] [client 45.138.221.39:61053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqpcJgo6iBrIY9VJLVSwAAAKg"], referer: http://pkf.jo
[Thu Jul 30 14:48:54.384507 2026] [security2:error] [pid 62112:tid 62243] [client 172.213.232.128:44833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.tmb/admin.php"] [unique_id "amuqpsJgo6iBrIY9VJLVWwAAAIY"]
[Thu Jul 30 14:48:54.660861 2026] [core:notice] [pid 62112:tid 62237] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:55.207803 2026] [core:notice] [pid 62112:tid 62114] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:55.535040 2026] [security2:error] [pid 62112:tid 62308] [client 110.249.202.224:59450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuqp8Jgo6iBrIY9VJLVeQAAAMc"]
[Thu Jul 30 14:48:55.542222 2026] [security2:error] [pid 62112:tid 62295] [client 172.213.232.128:24588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.tmb/class_api.php"] [unique_id "amuqp8Jgo6iBrIY9VJLVegAAALo"]
[Thu Jul 30 14:48:55.785475 2026] [security2:error] [pid 62112:tid 62288] [client 72.27.198.118:43936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqp8Jgo6iBrIY9VJLVdwAAALM"], referer: http://pkf.jo
[Thu Jul 30 14:48:55.992187 2026] [security2:error] [pid 62112:tid 62335] [client 52.238.199.152:33781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/classsmtps.php"] [unique_id "amuqp8Jgo6iBrIY9VJLViQAAAOI"]
[Thu Jul 30 14:48:56.274382 2026] [security2:error] [pid 62112:tid 62309] [client 172.213.232.128:44569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuqqMJgo6iBrIY9VJLVlQAAAMg"]
[Thu Jul 30 14:48:56.565865 2026] [security2:error] [pid 62112:tid 62130] [remote 103.75.185.95:39056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuqqMJgo6iBrIY9VJLVmQAAhRE"]
[Thu Jul 30 14:48:56.709735 2026] [security2:error] [pid 62112:tid 62302] [client 189.156.226.90:26743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqqMJgo6iBrIY9VJLVnwAAAME"]
[Thu Jul 30 14:48:56.709824 2026] [security2:error] [pid 62112:tid 62302] [client 189.156.226.90:26743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqqMJgo6iBrIY9VJLVnwAAAME"]
[Thu Jul 30 14:48:57.273751 2026] [security2:error] [pid 62112:tid 62347] [client 172.213.232.128:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuqqcJgo6iBrIY9VJLVpgAAAO4"]
[Thu Jul 30 14:48:58.007383 2026] [security2:error] [pid 62112:tid 62266] [client 52.238.199.152:37269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/themes/zMousse/otuz1.php"] [unique_id "amuqqsJgo6iBrIY9VJLVwQAAAJ0"]
[Thu Jul 30 14:48:58.399497 2026] [core:notice] [pid 62112:tid 62332] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:58.443089 2026] [security2:error] [pid 62112:tid 62317] [client 57.141.0.61:44934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koriusa.info"] [uri "/index.php"] [unique_id "amuqqMJgo6iBrIY9VJLVmAAA0CY"]
[Thu Jul 30 14:48:58.820851 2026] [security2:error] [pid 62112:tid 62285] [client 213.152.161.249:33884] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuqqsJgo6iBrIY9VJLV0gAAALA"]
[Thu Jul 30 14:48:58.821013 2026] [security2:error] [pid 62112:tid 62285] [client 213.152.161.249:33884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuqqsJgo6iBrIY9VJLV0gAAALA"]
[Thu Jul 30 14:48:58.862416 2026] [security2:error] [pid 62112:tid 62359] [client 143.105.135.175:6076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqqsJgo6iBrIY9VJLV0QAAAPo"], referer: http://pkf.jo
[Thu Jul 30 14:48:58.863738 2026] [core:notice] [pid 62112:tid 62307] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:48:58.901186 2026] [security2:error] [pid 62112:tid 62292] [client 95.153.90.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuqqsJgo6iBrIY9VJLV1wAAALc"], referer: https://cnpinyin.com
[Thu Jul 30 14:48:59.015283 2026] [security2:error] [pid 62112:tid 62245] [client 172.213.232.128:44589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuqq8Jgo6iBrIY9VJLV5AAAAIg"]
[Thu Jul 30 14:48:59.107082 2026] [security2:error] [pid 62112:tid 62311] [client 185.177.72.67:62762] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "aded-rdc.org"] [uri "/"] [unique_id "amuqq8Jgo6iBrIY9VJLV5QAAAMo"]
[Thu Jul 30 14:48:59.550782 2026] [security2:error] [pid 62112:tid 62297] [client 52.238.199.152:61756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/123.php"] [unique_id "amuqq8Jgo6iBrIY9VJLV9QAAALw"]
[Thu Jul 30 14:49:00.752478 2026] [security2:error] [pid 62112:tid 62325] [client 52.238.199.152:64779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuqrMJgo6iBrIY9VJLWCgAAANg"]
[Thu Jul 30 14:49:01.293838 2026] [security2:error] [pid 62112:tid 62288] [client 177.6.106.101:56857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqrcJgo6iBrIY9VJLWHQAAALM"]
[Thu Jul 30 14:49:01.293959 2026] [security2:error] [pid 62112:tid 62288] [client 177.6.106.101:56857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqrcJgo6iBrIY9VJLWHQAAALM"]
[Thu Jul 30 14:49:01.403719 2026] [security2:error] [pid 62112:tid 62363] [client 102.212.68.82:51452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqrcJgo6iBrIY9VJLWGwAAAP4"], referer: http://pkf.jo
[Thu Jul 30 14:49:02.040350 2026] [security2:error] [pid 62112:tid 62252] [client 52.238.199.152:37255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/filebrowser.php"] [unique_id "amuqrsJgo6iBrIY9VJLWMgAAAI8"]
[Thu Jul 30 14:49:02.164344 2026] [security2:error] [pid 62112:tid 62244] [client 172.213.232.128:44586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/991176.php"] [unique_id "amuqrsJgo6iBrIY9VJLWNgAAAIc"]
[Thu Jul 30 14:49:02.270857 2026] [core:notice] [pid 62112:tid 62190] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:02.537579 2026] [core:notice] [pid 62112:tid 62189] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:03.093282 2026] [security2:error] [pid 62112:tid 62328] [client 200.87.91.82:62982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqrsJgo6iBrIY9VJLWQgAAANs"], referer: http://pkf.jo
[Thu Jul 30 14:49:03.180847 2026] [security2:error] [pid 62112:tid 62330] [client 114.119.147.137:40569] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amuqr8Jgo6iBrIY9VJLWTQAAAN0"], referer: http://dhowcruisedinner.com/robots.txt
[Thu Jul 30 14:49:03.386841 2026] [security2:error] [pid 62112:tid 62261] [client 52.238.199.152:37262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/makeasmtp.php"] [unique_id "amuqr8Jgo6iBrIY9VJLWTwAAAJg"]
[Thu Jul 30 14:49:03.429334 2026] [security2:error] [pid 62112:tid 62272] [client 172.213.232.128:65171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuqr8Jgo6iBrIY9VJLWUwAAAKM"]
[Thu Jul 30 14:49:04.157096 2026] [security2:error] [pid 62112:tid 62369] [client 172.213.232.128:44841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuqsMJgo6iBrIY9VJLWbQAAAQQ"]
[Thu Jul 30 14:49:04.257761 2026] [security2:error] [pid 62112:tid 62365] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqsMJgo6iBrIY9VJLWYwABAFM"]
[Thu Jul 30 14:49:04.358057 2026] [security2:error] [pid 62112:tid 62279] [client 45.225.206.50:45360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqsMJgo6iBrIY9VJLWZAAAAKo"], referer: http://pkf.jo
[Thu Jul 30 14:49:04.446809 2026] [security2:error] [pid 62112:tid 62278] [client 52.238.199.152:37168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/bypass.php"] [unique_id "amuqsMJgo6iBrIY9VJLWcwAAAKk"]
[Thu Jul 30 14:49:04.792414 2026] [security2:error] [pid 62112:tid 62315] [client 172.213.232.128:44599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuqsMJgo6iBrIY9VJLWgAAAAM4"]
[Thu Jul 30 14:49:05.607849 2026] [security2:error] [pid 62112:tid 62266] [client 81.91.183.252:42808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqscJgo6iBrIY9VJLWjgAAAJ0"], referer: http://pkf.jo
[Thu Jul 30 14:49:05.929637 2026] [security2:error] [pid 62112:tid 62215] [remote 216.73.216.51:33573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqscJgo6iBrIY9VJLWmgAA6mY"]
[Thu Jul 30 14:49:06.129754 2026] [security2:error] [pid 62112:tid 62299] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqscJgo6iBrIY9VJLWmwAAvk4"]
[Thu Jul 30 14:49:06.166574 2026] [security2:error] [pid 62112:tid 62271] [client 181.199.60.87:25800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqscJgo6iBrIY9VJLWmQAAAKI"], referer: http://pkf.jo
[Thu Jul 30 14:49:06.308177 2026] [security2:error] [pid 62112:tid 62298] [client 52.238.199.152:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/pi.php"] [unique_id "amuqssJgo6iBrIY9VJLWpgAAAL0"]
[Thu Jul 30 14:49:06.544273 2026] [security2:error] [pid 62112:tid 62353] [client 196.238.136.234:55472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqssJgo6iBrIY9VJLWpQAAAPQ"], referer: http://pkf.jo
[Thu Jul 30 14:49:06.609564 2026] [security2:error] [pid 62112:tid 62286] [client 74.118.61.85:44364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqssJgo6iBrIY9VJLWpwAAALE"], referer: http://pkf.jo
[Thu Jul 30 14:49:06.903007 2026] [security2:error] [pid 62112:tid 62311] [client 34.91.100.6:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.website-7c59acf7.vdb.nyx.temporary.site"] [uri "/"] [unique_id "amuqssJgo6iBrIY9VJLWtQAAAMo"]
[Thu Jul 30 14:49:06.903114 2026] [security2:error] [pid 62112:tid 62311] [client 34.91.100.6:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.website-7c59acf7.vdb.nyx.temporary.site"] [uri "/"] [unique_id "amuqssJgo6iBrIY9VJLWtQAAAMo"]
[Thu Jul 30 14:49:07.063856 2026] [access_compat:error] [pid 62112:tid 62207] [remote 142.93.0.66:0] AH01797: client denied by server configuration: /home1/glbnyxte/public_html/website_9c517624/server-status
[Thu Jul 30 14:49:07.256823 2026] [security2:error] [pid 62112:tid 62251] [client 200.15.16.235:32338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqssJgo6iBrIY9VJLWrwAAAI4"], referer: http://pkf.jo
[Thu Jul 30 14:49:07.287555 2026] [security2:error] [pid 62112:tid 62348] [client 118.179.26.111:46632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqssJgo6iBrIY9VJLWsAAAAO8"], referer: http://pkf.jo
[Thu Jul 30 14:49:07.334002 2026] [security2:error] [pid 62112:tid 62252] [client 189.156.226.90:27168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqs8Jgo6iBrIY9VJLWxgAAAI8"]
[Thu Jul 30 14:49:07.334107 2026] [security2:error] [pid 62112:tid 62252] [client 189.156.226.90:27168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqs8Jgo6iBrIY9VJLWxgAAAI8"]
[Thu Jul 30 14:49:07.427741 2026] [security2:error] [pid 62112:tid 62261] [client 172.213.232.128:24624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuqs8Jgo6iBrIY9VJLWyAAAAJg"]
[Thu Jul 30 14:49:07.554291 2026] [security2:error] [pid 62112:tid 62352] [client 99.232.75.81:45699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqs8Jgo6iBrIY9VJLWwQAAAPM"], referer: http://pkf.jo
[Thu Jul 30 14:49:07.680261 2026] [core:notice] [pid 62112:tid 62232] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:07.682729 2026] [security2:error] [pid 62112:tid 62290] [client 41.220.201.103:61025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqs8Jgo6iBrIY9VJLWxwAAALU"], referer: http://pkf.jo
[Thu Jul 30 14:49:07.686823 2026] [security2:error] [pid 62112:tid 62355] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqs8Jgo6iBrIY9VJLWvAAAAPY"]
[Thu Jul 30 14:49:07.762154 2026] [security2:error] [pid 62112:tid 62291] [client 52.238.199.152:33735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-seo.php"] [unique_id "amuqs8Jgo6iBrIY9VJLW0wAAALY"]
[Thu Jul 30 14:49:08.355910 2026] [security2:error] [pid 62112:tid 62256] [client 172.213.232.128:24841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuqtMJgo6iBrIY9VJLW4AAAAJM"]
[Thu Jul 30 14:49:08.589432 2026] [security2:error] [pid 62112:tid 62301] [client 91.225.37.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuqtMJgo6iBrIY9VJLW6gAAAMA"], referer: https://cnpinyin.com
[Thu Jul 30 14:49:08.911770 2026] [security2:error] [pid 62112:tid 62258] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqtMJgo6iBrIY9VJLW8QAAlX4"]
[Thu Jul 30 14:49:08.932920 2026] [core:notice] [pid 62112:tid 62358] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:09.093656 2026] [security2:error] [pid 62112:tid 62287] [client 172.213.232.128:42478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuqtcJgo6iBrIY9VJLW_gAAALI"]
[Thu Jul 30 14:49:09.100155 2026] [security2:error] [pid 62112:tid 62363] [client 153.67.137.225:54692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqtMJgo6iBrIY9VJLW9QAAAP4"], referer: http://pkf.jo
[Thu Jul 30 14:49:09.116256 2026] [security2:error] [pid 62112:tid 62250] [client 52.238.199.152:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/gebase.php69"] [unique_id "amuqtcJgo6iBrIY9VJLXAgAAAI0"]
[Thu Jul 30 14:49:09.198016 2026] [security2:error] [pid 62112:tid 62119] [remote 57.141.0.58:33382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuqtcJgo6iBrIY9VJLXCAAAnAY"]
[Thu Jul 30 14:49:09.271307 2026] [security2:error] [pid 62112:tid 62288] [client 181.63.25.58:40866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqtMJgo6iBrIY9VJLW-wAAALM"], referer: http://pkf.jo
[Thu Jul 30 14:49:09.379732 2026] [security2:error] [pid 62112:tid 62303] [client 110.227.42.246:32954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqtcJgo6iBrIY9VJLW_AAAAMI"], referer: http://pkf.jo
[Thu Jul 30 14:49:09.530282 2026] [security2:error] [pid 62112:tid 62134] [remote 57.141.0.46:40572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuqtcJgo6iBrIY9VJLXCQAA6RU"]
[Thu Jul 30 14:49:09.640874 2026] [security2:error] [pid 62112:tid 62296] [client 172.237.109.114:25364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuqtcJgo6iBrIY9VJLXBAAAALs"]
[Thu Jul 30 14:49:09.906081 2026] [security2:error] [pid 62112:tid 62357] [client 172.213.232.128:44550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuqtcJgo6iBrIY9VJLXFwAAAPg"]
[Thu Jul 30 14:49:10.141581 2026] [security2:error] [pid 62112:tid 62291] [client 102.204.4.0:54118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqtcJgo6iBrIY9VJLXFgAAALY"], referer: http://pkf.jo
[Thu Jul 30 14:49:10.451184 2026] [security2:error] [pid 62112:tid 62143] [remote 216.73.216.51:33573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuqtsJgo6iBrIY9VJLXJAAA2B4"]
[Thu Jul 30 14:49:10.463320 2026] [security2:error] [pid 62112:tid 62336] [client 20.52.125.110:5372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/--wp-lgj.php"] [unique_id "amuqtsJgo6iBrIY9VJLXJQAAAOM"]
[Thu Jul 30 14:49:10.851502 2026] [security2:error] [pid 62112:tid 62360] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqtsJgo6iBrIY9VJLXJwAA-yk"]
[Thu Jul 30 14:49:10.892500 2026] [security2:error] [pid 62112:tid 62339] [client 127.0.0.1:57990] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuqtsJgo6iBrIY9VJLXMgAAAOY"]
[Thu Jul 30 14:49:10.892602 2026] [security2:error] [pid 62112:tid 62354] [client 74.7.230.46:33550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ahk.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amuqtsJgo6iBrIY9VJLXMQAA9Sg"]
[Thu Jul 30 14:49:11.014971 2026] [security2:error] [pid 62112:tid 62356] [client 172.213.232.128:44588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuqt8Jgo6iBrIY9VJLXNgAAAPc"]
[Thu Jul 30 14:49:11.145740 2026] [security2:error] [pid 62112:tid 62266] [client 52.238.199.152:33748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/config.php"] [unique_id "amuqt8Jgo6iBrIY9VJLXNwAAAJ0"]
[Thu Jul 30 14:49:11.363903 2026] [proxy:error] [pid 62112:tid 62365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:49:11.363956 2026] [proxy_http:error] [pid 62112:tid 62365] [client 20.52.125.110:5359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:49:11.365000 2026] [proxy:error] [pid 62112:tid 62365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:49:11.365061 2026] [proxy_http:error] [pid 62112:tid 62365] [client 20.52.125.110:5359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:49:11.397580 2026] [security2:error] [pid 62112:tid 62351] [client 31.3.152.100:32780] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuqt8Jgo6iBrIY9VJLXQgAAAPI"]
[Thu Jul 30 14:49:11.397692 2026] [security2:error] [pid 62112:tid 62351] [client 31.3.152.100:32780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuqt8Jgo6iBrIY9VJLXQgAAAPI"]
[Thu Jul 30 14:49:11.597479 2026] [security2:error] [pid 62112:tid 62250] [client 103.181.163.108:60030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqt8Jgo6iBrIY9VJLXOQAAAI0"], referer: http://pkf.jo
[Thu Jul 30 14:49:11.688697 2026] [security2:error] [pid 62112:tid 62300] [client 172.213.232.128:42455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuqt8Jgo6iBrIY9VJLXRgAAAL8"]
[Thu Jul 30 14:49:11.855840 2026] [security2:error] [pid 62112:tid 62287] [client 177.6.106.101:57346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqt8Jgo6iBrIY9VJLXSgAAALI"]
[Thu Jul 30 14:49:11.855944 2026] [security2:error] [pid 62112:tid 62287] [client 177.6.106.101:57346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqt8Jgo6iBrIY9VJLXSgAAALI"]
[Thu Jul 30 14:49:12.000349 2026] [core:notice] [pid 62112:tid 62244] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:12.049153 2026] [security2:error] [pid 62112:tid 62293] [client 20.52.125.110:5315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuquMJgo6iBrIY9VJLXUgAAALg"]
[Thu Jul 30 14:49:12.205674 2026] [security2:error] [pid 62112:tid 62320] [client 172.213.232.128:65325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuquMJgo6iBrIY9VJLXVAAAANM"]
[Thu Jul 30 14:49:12.515048 2026] [security2:error] [pid 62112:tid 62333] [client 52.238.199.152:33736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ws.php"] [unique_id "amuquMJgo6iBrIY9VJLXXQAAAOA"]
[Thu Jul 30 14:49:12.656872 2026] [security2:error] [pid 62112:tid 62323] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuquMJgo6iBrIY9VJLXYQAAANY"]
[Thu Jul 30 14:49:12.656999 2026] [security2:error] [pid 62112:tid 62323] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuquMJgo6iBrIY9VJLXYQAAANY"]
[Thu Jul 30 14:49:12.740508 2026] [security2:error] [pid 62112:tid 62275] [client 20.52.125.110:4566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.well-known/flower.php"] [unique_id "amuquMJgo6iBrIY9VJLXYwAAAKY"]
[Thu Jul 30 14:49:12.909542 2026] [security2:error] [pid 62112:tid 62256] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuquMJgo6iBrIY9VJLXZQAAAJM"]
[Thu Jul 30 14:49:12.909663 2026] [security2:error] [pid 62112:tid 62256] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuquMJgo6iBrIY9VJLXZQAAAJM"]
[Thu Jul 30 14:49:13.166479 2026] [security2:error] [pid 62112:tid 62286] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuqucJgo6iBrIY9VJLXcAAAALE"]
[Thu Jul 30 14:49:13.166635 2026] [security2:error] [pid 62112:tid 62286] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuqucJgo6iBrIY9VJLXcAAAALE"]
[Thu Jul 30 14:49:13.412346 2026] [security2:error] [pid 62112:tid 62339] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/err.php"] [unique_id "amuqucJgo6iBrIY9VJLXdAAAAOY"]
[Thu Jul 30 14:49:13.412449 2026] [security2:error] [pid 62112:tid 62339] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/err.php"] [unique_id "amuqucJgo6iBrIY9VJLXdAAAAOY"]
[Thu Jul 30 14:49:13.509150 2026] [security2:error] [pid 62112:tid 62359] [client 172.213.232.128:44604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuqucJgo6iBrIY9VJLXeAAAAPo"]
[Thu Jul 30 14:49:13.646647 2026] [security2:error] [pid 62112:tid 62271] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/img.php"] [unique_id "amuqucJgo6iBrIY9VJLXfgAAAKI"]
[Thu Jul 30 14:49:13.646748 2026] [security2:error] [pid 62112:tid 62271] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/img.php"] [unique_id "amuqucJgo6iBrIY9VJLXfgAAAKI"]
[Thu Jul 30 14:49:13.675632 2026] [security2:error] [pid 62112:tid 62304] [client 20.52.125.110:5375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.well-known/xleet.php"] [unique_id "amuqucJgo6iBrIY9VJLXgQAAAMM"]
[Thu Jul 30 14:49:13.878213 2026] [security2:error] [pid 62112:tid 62313] [client 107.174.94.29:60592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuqucJgo6iBrIY9VJLXeQAAzBw"], referer: https://alseermarine.com/
[Thu Jul 30 14:49:13.894581 2026] [security2:error] [pid 62112:tid 62352] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/aa.php"] [unique_id "amuqucJgo6iBrIY9VJLXiQAAAPM"]
[Thu Jul 30 14:49:13.894697 2026] [security2:error] [pid 62112:tid 62352] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/aa.php"] [unique_id "amuqucJgo6iBrIY9VJLXiQAAAPM"]
[Thu Jul 30 14:49:13.973614 2026] [security2:error] [pid 62112:tid 62338] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqucJgo6iBrIY9VJLXhQAA5Tg"]
[Thu Jul 30 14:49:14.147813 2026] [security2:error] [pid 62112:tid 62366] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/av.php"] [unique_id "amuqusJgo6iBrIY9VJLXlAAAAQE"]
[Thu Jul 30 14:49:14.147892 2026] [security2:error] [pid 62112:tid 62366] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/av.php"] [unique_id "amuqusJgo6iBrIY9VJLXlAAAAQE"]
[Thu Jul 30 14:49:14.382309 2026] [security2:error] [pid 62112:tid 62308] [client 20.52.125.110:5342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuqusJgo6iBrIY9VJLXlgAAAMc"]
[Thu Jul 30 14:49:14.405756 2026] [security2:error] [pid 62112:tid 62322] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/xa.php"] [unique_id "amuqusJgo6iBrIY9VJLXlwAAANU"]
[Thu Jul 30 14:49:14.405842 2026] [security2:error] [pid 62112:tid 62322] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/xa.php"] [unique_id "amuqusJgo6iBrIY9VJLXlwAAANU"]
[Thu Jul 30 14:49:14.639243 2026] [security2:error] [pid 62112:tid 62263] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/media.php"] [unique_id "amuqusJgo6iBrIY9VJLXogAAAJo"]
[Thu Jul 30 14:49:14.639389 2026] [security2:error] [pid 62112:tid 62263] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/media.php"] [unique_id "amuqusJgo6iBrIY9VJLXogAAAJo"]
[Thu Jul 30 14:49:14.793323 2026] [security2:error] [pid 62112:tid 62332] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqusJgo6iBrIY9VJLXnwAA30w"]
[Thu Jul 30 14:49:14.883280 2026] [security2:error] [pid 62112:tid 62317] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/images.php"] [unique_id "amuqusJgo6iBrIY9VJLXowAAANA"]
[Thu Jul 30 14:49:14.883392 2026] [security2:error] [pid 62112:tid 62317] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/images.php"] [unique_id "amuqusJgo6iBrIY9VJLXowAAANA"]
[Thu Jul 30 14:49:15.138287 2026] [security2:error] [pid 62112:tid 62298] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/gecko.php"] [unique_id "amuqu8Jgo6iBrIY9VJLXrwAAAL0"]
[Thu Jul 30 14:49:15.138407 2026] [security2:error] [pid 62112:tid 62298] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/gecko.php"] [unique_id "amuqu8Jgo6iBrIY9VJLXrwAAAL0"]
[Thu Jul 30 14:49:15.385971 2026] [security2:error] [pid 62112:tid 62292] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/82.php"] [unique_id "amuqu8Jgo6iBrIY9VJLXsAAAALc"]
[Thu Jul 30 14:49:15.386102 2026] [security2:error] [pid 62112:tid 62292] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/82.php"] [unique_id "amuqu8Jgo6iBrIY9VJLXsAAAALc"]
[Thu Jul 30 14:49:15.412916 2026] [security2:error] [pid 62112:tid 62277] [client 20.52.125.110:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuqu8Jgo6iBrIY9VJLXsQAAAKg"]
[Thu Jul 30 14:49:15.637500 2026] [security2:error] [pid 62112:tid 62279] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/xstelth.php"] [unique_id "amuqu8Jgo6iBrIY9VJLXugAAAKo"]
[Thu Jul 30 14:49:15.637593 2026] [security2:error] [pid 62112:tid 62279] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/xstelth.php"] [unique_id "amuqu8Jgo6iBrIY9VJLXugAAAKo"]
[Thu Jul 30 14:49:15.688195 2026] [core:notice] [pid 62112:tid 62182] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:15.893910 2026] [security2:error] [pid 62112:tid 62358] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/xp.php"] [unique_id "amuqu8Jgo6iBrIY9VJLXwwAAAPk"]
[Thu Jul 30 14:49:15.894032 2026] [security2:error] [pid 62112:tid 62358] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/xp.php"] [unique_id "amuqu8Jgo6iBrIY9VJLXwwAAAPk"]
[Thu Jul 30 14:49:16.134390 2026] [security2:error] [pid 62112:tid 62244] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuqvMJgo6iBrIY9VJLXzQAAAIc"]
[Thu Jul 30 14:49:16.134532 2026] [security2:error] [pid 62112:tid 62244] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuqvMJgo6iBrIY9VJLXzQAAAIc"]
[Thu Jul 30 14:49:16.345312 2026] [security2:error] [pid 62112:tid 62257] [client 52.238.199.152:64787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/admin/function.php"] [unique_id "amuqvMJgo6iBrIY9VJLX0wAAAJQ"]
[Thu Jul 30 14:49:16.467229 2026] [security2:error] [pid 62112:tid 62251] [client 172.213.232.128:48567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuqvMJgo6iBrIY9VJLX1AAAAI4"]
[Thu Jul 30 14:49:16.490169 2026] [security2:error] [pid 62112:tid 62315] [client 102.209.137.222:7024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqvMJgo6iBrIY9VJLX0AAAAM4"], referer: http://pkf.jo
[Thu Jul 30 14:49:16.510117 2026] [security2:error] [pid 62112:tid 62313] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqvMJgo6iBrIY9VJLX0gAAzDo"]
[Thu Jul 30 14:49:16.603178 2026] [security2:error] [pid 62112:tid 62300] [client 20.52.125.110:5447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuqvMJgo6iBrIY9VJLX2AAAAL8"]
[Thu Jul 30 14:49:16.864599 2026] [security2:error] [pid 62112:tid 62367] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/adminner.php"] [unique_id "amuqvMJgo6iBrIY9VJLX3wAAAQI"]
[Thu Jul 30 14:49:16.864710 2026] [security2:error] [pid 62112:tid 62367] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/adminner.php"] [unique_id "amuqvMJgo6iBrIY9VJLX3wAAAQI"]
[Thu Jul 30 14:49:17.127370 2026] [security2:error] [pid 62112:tid 62307] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/a.php"] [unique_id "amuqvcJgo6iBrIY9VJLX5AAAAMY"]
[Thu Jul 30 14:49:17.127495 2026] [security2:error] [pid 62112:tid 62307] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/a.php"] [unique_id "amuqvcJgo6iBrIY9VJLX5AAAAMY"]
[Thu Jul 30 14:49:17.310221 2026] [security2:error] [pid 62112:tid 62245] [client 20.52.125.110:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuqvcJgo6iBrIY9VJLX7AAAAIg"]
[Thu Jul 30 14:49:17.376132 2026] [security2:error] [pid 62112:tid 62298] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/k.php"] [unique_id "amuqvcJgo6iBrIY9VJLX7gAAAL0"]
[Thu Jul 30 14:49:17.376235 2026] [security2:error] [pid 62112:tid 62298] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/k.php"] [unique_id "amuqvcJgo6iBrIY9VJLX7gAAAL0"]
[Thu Jul 30 14:49:17.393770 2026] [core:notice] [pid 62112:tid 62208] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:17.577640 2026] [security2:error] [pid 62112:tid 62285] [client 84.54.71.189:57847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqvcJgo6iBrIY9VJLX6wAAALA"], referer: http://pkf.jo
[Thu Jul 30 14:49:17.624455 2026] [security2:error] [pid 62112:tid 62247] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/222.php"] [unique_id "amuqvcJgo6iBrIY9VJLX9AAAAIo"]
[Thu Jul 30 14:49:17.624585 2026] [security2:error] [pid 62112:tid 62247] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/222.php"] [unique_id "amuqvcJgo6iBrIY9VJLX9AAAAIo"]
[Thu Jul 30 14:49:17.898252 2026] [security2:error] [pid 62112:tid 62368] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/mac.php"] [unique_id "amuqvcJgo6iBrIY9VJLX-wAAAQM"]
[Thu Jul 30 14:49:17.898362 2026] [security2:error] [pid 62112:tid 62368] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/mac.php"] [unique_id "amuqvcJgo6iBrIY9VJLX-wAAAQM"]
[Thu Jul 30 14:49:17.911936 2026] [security2:error] [pid 62112:tid 62316] [client 172.213.232.128:24892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuqvcJgo6iBrIY9VJLX_AAAAM8"]
[Thu Jul 30 14:49:17.953264 2026] [security2:error] [pid 62112:tid 62294] [client 189.156.226.90:27593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqvcJgo6iBrIY9VJLX_QAAALk"]
[Thu Jul 30 14:49:17.953414 2026] [security2:error] [pid 62112:tid 62294] [client 189.156.226.90:27593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqvcJgo6iBrIY9VJLX_QAAALk"]
[Thu Jul 30 14:49:18.141161 2026] [security2:error] [pid 62112:tid 62344] [client 4.232.188.49:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-content/uploads/"] [unique_id "amuqvsJgo6iBrIY9VJLYAQAAAOs"]
[Thu Jul 30 14:49:18.141269 2026] [security2:error] [pid 62112:tid 62344] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-content/uploads/"] [unique_id "amuqvsJgo6iBrIY9VJLYAQAAAOs"]
[Thu Jul 30 14:49:18.343280 2026] [proxy:error] [pid 62112:tid 62279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:49:18.343361 2026] [proxy_http:error] [pid 62112:tid 62279] [client 20.52.125.110:5370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:49:18.344219 2026] [proxy:error] [pid 62112:tid 62279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:49:18.344285 2026] [proxy_http:error] [pid 62112:tid 62279] [client 20.52.125.110:5370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:49:18.389009 2026] [security2:error] [pid 62112:tid 62252] [client 4.232.188.49:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-includes/Text/"] [unique_id "amuqvsJgo6iBrIY9VJLYDwAAAI8"]
[Thu Jul 30 14:49:18.389119 2026] [security2:error] [pid 62112:tid 62252] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-includes/Text/"] [unique_id "amuqvsJgo6iBrIY9VJLYDwAAAI8"]
[Thu Jul 30 14:49:18.401605 2026] [security2:error] [pid 62112:tid 62365] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqvsJgo6iBrIY9VJLYBQABAG8"]
[Thu Jul 30 14:49:18.620266 2026] [security2:error] [pid 62112:tid 62342] [client 210.87.89.242:47464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqvsJgo6iBrIY9VJLYDQAAAOk"], referer: http://pkf.jo
[Thu Jul 30 14:49:18.623220 2026] [security2:error] [pid 62112:tid 62297] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/ops.php"] [unique_id "amuqvsJgo6iBrIY9VJLYEwAAALw"]
[Thu Jul 30 14:49:18.623286 2026] [security2:error] [pid 62112:tid 62297] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/ops.php"] [unique_id "amuqvsJgo6iBrIY9VJLYEwAAALw"]
[Thu Jul 30 14:49:18.868682 2026] [security2:error] [pid 62112:tid 62308] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/8.php"] [unique_id "amuqvsJgo6iBrIY9VJLYHAAAAMc"]
[Thu Jul 30 14:49:18.868781 2026] [security2:error] [pid 62112:tid 62308] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/8.php"] [unique_id "amuqvsJgo6iBrIY9VJLYHAAAAMc"]
[Thu Jul 30 14:49:19.032424 2026] [security2:error] [pid 62112:tid 62334] [client 20.52.125.110:4560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYIgAAAOE"]
[Thu Jul 30 14:49:19.117904 2026] [security2:error] [pid 62112:tid 62330] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/FWAZ.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYIwAAAN0"]
[Thu Jul 30 14:49:19.118048 2026] [security2:error] [pid 62112:tid 62330] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/FWAZ.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYIwAAAN0"]
[Thu Jul 30 14:49:19.367994 2026] [security2:error] [pid 62112:tid 62242] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/biufile.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYKgAAAIU"]
[Thu Jul 30 14:49:19.368098 2026] [security2:error] [pid 62112:tid 62242] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/biufile.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYKgAAAIU"]
[Thu Jul 30 14:49:19.373443 2026] [security2:error] [pid 62112:tid 62304] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqvsJgo6iBrIY9VJLYFQAAw24"]
[Thu Jul 30 14:49:19.588492 2026] [security2:error] [pid 62112:tid 62269] [client 20.52.125.110:5357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYLgAAAKA"]
[Thu Jul 30 14:49:19.603972 2026] [security2:error] [pid 62112:tid 62327] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/coffexium.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYLwAAANo"]
[Thu Jul 30 14:49:19.604105 2026] [security2:error] [pid 62112:tid 62327] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/coffexium.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYLwAAANo"]
[Thu Jul 30 14:49:19.836900 2026] [security2:error] [pid 62112:tid 62251] [client 172.213.232.128:24881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYOQAAAI4"]
[Thu Jul 30 14:49:19.843138 2026] [security2:error] [pid 62112:tid 62345] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/simple.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYOgAAAOw"]
[Thu Jul 30 14:49:19.843235 2026] [security2:error] [pid 62112:tid 62345] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/simple.php"] [unique_id "amuqv8Jgo6iBrIY9VJLYOgAAAOw"]
[Thu Jul 30 14:49:20.061286 2026] [security2:error] [pid 62112:tid 62222] [remote 142.93.0.66:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.rooferio.enterprises"] [uri "/.env"] [unique_id "amuqwMJgo6iBrIY9VJLYOwAA_20"]
[Thu Jul 30 14:49:20.095485 2026] [security2:error] [pid 62112:tid 62294] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/fpwch.php"] [unique_id "amuqwMJgo6iBrIY9VJLYPAAAALk"]
[Thu Jul 30 14:49:20.095630 2026] [security2:error] [pid 62112:tid 62294] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/fpwch.php"] [unique_id "amuqwMJgo6iBrIY9VJLYPAAAALk"]
[Thu Jul 30 14:49:20.325078 2026] [security2:error] [pid 62112:tid 62248] [client 20.52.125.110:5324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuqwMJgo6iBrIY9VJLYRwAAAIs"]
[Thu Jul 30 14:49:20.329505 2026] [security2:error] [pid 62112:tid 62264] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/dex.php"] [unique_id "amuqwMJgo6iBrIY9VJLYSAAAAJs"]
[Thu Jul 30 14:49:20.329595 2026] [security2:error] [pid 62112:tid 62264] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/dex.php"] [unique_id "amuqwMJgo6iBrIY9VJLYSAAAAJs"]
[Thu Jul 30 14:49:20.522359 2026] [security2:error] [pid 62112:tid 62246] [client 45.235.218.27:6191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqwMJgo6iBrIY9VJLYPgAAAIk"], referer: http://pkf.jo
[Thu Jul 30 14:49:20.566587 2026] [security2:error] [pid 62112:tid 62297] [client 4.232.188.49:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amuqwMJgo6iBrIY9VJLYUAAAALw"]
[Thu Jul 30 14:49:20.566709 2026] [security2:error] [pid 62112:tid 62297] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amuqwMJgo6iBrIY9VJLYUAAAALw"]
[Thu Jul 30 14:49:20.566801 2026] [security2:error] [pid 62112:tid 62297] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/1.php"] [unique_id "amuqwMJgo6iBrIY9VJLYUAAAALw"]
[Thu Jul 30 14:49:20.804401 2026] [security2:error] [pid 62112:tid 62290] [client 4.232.188.49:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amuqwMJgo6iBrIY9VJLYVwAAALU"]
[Thu Jul 30 14:49:20.804556 2026] [security2:error] [pid 62112:tid 62290] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-admin/css/colors/modern/"] [unique_id "amuqwMJgo6iBrIY9VJLYVwAAALU"]
[Thu Jul 30 14:49:20.890723 2026] [security2:error] [pid 62112:tid 62353] [client 20.52.125.110:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuqwMJgo6iBrIY9VJLYWwAAAPQ"]
[Thu Jul 30 14:49:20.961414 2026] [security2:error] [pid 62112:tid 62282] [client 176.222.61.222:35358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqwMJgo6iBrIY9VJLYUQAAAK0"], referer: http://pkf.jo
[Thu Jul 30 14:49:21.427884 2026] [security2:error] [pid 62112:tid 62358] [client 52.167.144.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuqwMJgo6iBrIY9VJLYQwAAAPk"]
[Thu Jul 30 14:49:21.468694 2026] [security2:error] [pid 62112:tid 62293] [client 172.213.232.128:41970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/bek.php"] [unique_id "amuqwcJgo6iBrIY9VJLYaQAAALg"]
[Thu Jul 30 14:49:21.527973 2026] [security2:error] [pid 62112:tid 62340] [client 50.6.43.217:24542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuqwMJgo6iBrIY9VJLYUwAAAOc"]
[Thu Jul 30 14:49:21.638702 2026] [core:notice] [pid 62112:tid 62227] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:21.688172 2026] [security2:error] [pid 62112:tid 62343] [client 20.52.125.110:4591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuqwcJgo6iBrIY9VJLYbQAAAOo"]
[Thu Jul 30 14:49:21.712818 2026] [security2:error] [pid 62112:tid 62235] [remote 20.54.134.42:2239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ldk.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuqwcJgo6iBrIY9VJLYbgAAxno"]
[Thu Jul 30 14:49:21.899287 2026] [security2:error] [pid 62112:tid 62350] [client 40.77.167.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuqvsJgo6iBrIY9VJLYGwAAAPE"]
[Thu Jul 30 14:49:22.064261 2026] [security2:error] [pid 62112:tid 62336] [client 190.220.147.190:52040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqwcJgo6iBrIY9VJLYcgAAAOM"], referer: http://pkf.jo
[Thu Jul 30 14:49:22.095022 2026] [core:notice] [pid 62112:tid 62121] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:22.261473 2026] [security2:error] [pid 62112:tid 62243] [client 50.6.43.217:41604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuqwcJgo6iBrIY9VJLYawAAAIY"]
[Thu Jul 30 14:49:22.331818 2026] [security2:error] [pid 62112:tid 62334] [client 177.6.106.101:53921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqwsJgo6iBrIY9VJLYfwAAAOE"]
[Thu Jul 30 14:49:22.331917 2026] [security2:error] [pid 62112:tid 62334] [client 177.6.106.101:53921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqwsJgo6iBrIY9VJLYfwAAAOE"]
[Thu Jul 30 14:49:22.525479 2026] [security2:error] [pid 62112:tid 62258] [client 20.52.125.110:5349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuqwsJgo6iBrIY9VJLYhAAAAJU"]
[Thu Jul 30 14:49:22.642561 2026] [security2:error] [pid 62112:tid 62279] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/config.json.php"] [unique_id "amuqwsJgo6iBrIY9VJLYiAAAAKo"]
[Thu Jul 30 14:49:22.642670 2026] [security2:error] [pid 62112:tid 62279] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/config.json.php"] [unique_id "amuqwsJgo6iBrIY9VJLYiAAAAKo"]
[Thu Jul 30 14:49:22.643870 2026] [security2:error] [pid 62112:tid 62130] [remote 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqwsJgo6iBrIY9VJLYgAAA7xE"]
[Thu Jul 30 14:49:22.879830 2026] [security2:error] [pid 62112:tid 62297] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/k2.php"] [unique_id "amuqwsJgo6iBrIY9VJLYjQAAALw"]
[Thu Jul 30 14:49:22.880009 2026] [security2:error] [pid 62112:tid 62297] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/k2.php"] [unique_id "amuqwsJgo6iBrIY9VJLYjQAAALw"]
[Thu Jul 30 14:49:23.000439 2026] [security2:error] [pid 62112:tid 62303] [client 5.15.115.126:47060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqwsJgo6iBrIY9VJLYiQAAAMI"], referer: http://pkf.jo
[Thu Jul 30 14:49:23.060355 2026] [core:notice] [pid 62112:tid 62127] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:23.067238 2026] [security2:error] [pid 62112:tid 62257] [client 20.52.125.110:5313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYkwAAAJQ"]
[Thu Jul 30 14:49:23.120960 2026] [security2:error] [pid 62112:tid 62305] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/raw.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYmAAAAMQ"]
[Thu Jul 30 14:49:23.121074 2026] [security2:error] [pid 62112:tid 62305] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/raw.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYmAAAAMQ"]
[Thu Jul 30 14:49:23.336814 2026] [security2:error] [pid 62112:tid 62313] [client 151.244.155.49:16113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYkQAAAMw"], referer: http://pkf.jo
[Thu Jul 30 14:49:23.357716 2026] [security2:error] [pid 62112:tid 62317] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYnQAAANA"]
[Thu Jul 30 14:49:23.357827 2026] [security2:error] [pid 62112:tid 62317] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYnQAAANA"]
[Thu Jul 30 14:49:23.394726 2026] [security2:error] [pid 62112:tid 62308] [client 88.238.189.177:57412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYlAAAAMc"], referer: http://pkf.jo
[Thu Jul 30 14:49:23.486562 2026] [security2:error] [pid 62112:tid 62361] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYmwAAAPw"]
[Thu Jul 30 14:49:23.498522 2026] [security2:error] [pid 62112:tid 62299] [client 20.91.199.21:3118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/geju.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYpQAAAL4"]
[Thu Jul 30 14:49:23.564821 2026] [security2:error] [pid 62112:tid 62133] [remote 74.7.243.224:50776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/uploads/content/login.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYqQAApxQ"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/content/uploads/content/1781252056_BAGIRA.jpg
[Thu Jul 30 14:49:23.639056 2026] [security2:error] [pid 62112:tid 62327] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/fffm.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYqwAAANo"]
[Thu Jul 30 14:49:23.639173 2026] [security2:error] [pid 62112:tid 62327] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/fffm.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYqwAAANo"]
[Thu Jul 30 14:49:23.702585 2026] [security2:error] [pid 62112:tid 62256] [client 88.168.34.23:40698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYoAAAAJM"], referer: http://pkf.jo
[Thu Jul 30 14:49:23.853082 2026] [security2:error] [pid 62112:tid 62269] [client 190.141.49.25:59776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYqgAAAKA"], referer: http://pkf.jo
[Thu Jul 30 14:49:23.891502 2026] [security2:error] [pid 62112:tid 62286] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/111.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYrAAAALE"]
[Thu Jul 30 14:49:23.891665 2026] [security2:error] [pid 62112:tid 62286] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/111.php"] [unique_id "amuqw8Jgo6iBrIY9VJLYrAAAALE"]
[Thu Jul 30 14:49:24.074486 2026] [security2:error] [pid 62112:tid 62307] [client 20.52.125.110:4550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuqxMJgo6iBrIY9VJLYtAAAAMY"]
[Thu Jul 30 14:49:24.145156 2026] [security2:error] [pid 62112:tid 62265] [client 4.232.188.49:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-includes/Requests/"] [unique_id "amuqxMJgo6iBrIY9VJLYuwAAAJw"]
[Thu Jul 30 14:49:24.145286 2026] [security2:error] [pid 62112:tid 62265] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-includes/Requests/"] [unique_id "amuqxMJgo6iBrIY9VJLYuwAAAJw"]
[Thu Jul 30 14:49:24.161776 2026] [security2:error] [pid 62112:tid 62243] [client 185.177.72.67:7392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuqxMJgo6iBrIY9VJLYvAAAAIY"]
[Thu Jul 30 14:49:24.257154 2026] [lsapi:error] [pid 62112:tid 62363] [client 185.177.72.67:62768] [host aded-rdc.org] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown
[Thu Jul 30 14:49:24.257200 2026] [lsapi:error] [pid 62112:tid 62363] [client 185.177.72.67:62768] [host aded-rdc.org] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache
[Thu Jul 30 14:49:24.257210 2026] [lsapi:error] [pid 62112:tid 62363] [client 185.177.72.67:62768] [host aded-rdc.org] Client error on sending request(POST / HTTP/1.1); uri(/) content-length(131395): user_get_body(tmpstackbuf, 16384): read from client failed
[Thu Jul 30 14:49:24.417655 2026] [security2:error] [pid 62112:tid 62261] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/ws.php"] [unique_id "amuqxMJgo6iBrIY9VJLYwAAAAJg"]
[Thu Jul 30 14:49:24.417781 2026] [security2:error] [pid 62112:tid 62261] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/ws.php"] [unique_id "amuqxMJgo6iBrIY9VJLYwAAAAJg"]
[Thu Jul 30 14:49:24.421100 2026] [security2:error] [pid 62112:tid 62338] [client 185.177.72.67:7396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amuqxMJgo6iBrIY9VJLYwgAAAOU"]
[Thu Jul 30 14:49:24.429572 2026] [security2:error] [pid 62112:tid 62263] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuqxMJgo6iBrIY9VJLYtwAAAJo"]
[Thu Jul 30 14:49:24.537258 2026] [security2:error] [pid 62112:tid 62248] [client 163.53.25.168:32079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqxMJgo6iBrIY9VJLYvQAAAIs"], referer: http://pkf.jo
[Thu Jul 30 14:49:24.696652 2026] [security2:error] [pid 62112:tid 62303] [client 185.177.72.67:7402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuqxMJgo6iBrIY9VJLYyQAAAMI"]
[Thu Jul 30 14:49:24.780128 2026] [security2:error] [pid 62112:tid 62283] [client 20.52.125.110:4558] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.lilyinspires.com"] [uri "/1.php"] [unique_id "amuqxMJgo6iBrIY9VJLYygAAAK4"]
[Thu Jul 30 14:49:24.780254 2026] [security2:error] [pid 62112:tid 62283] [client 20.52.125.110:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/1.php"] [unique_id "amuqxMJgo6iBrIY9VJLYygAAAK4"]
[Thu Jul 30 14:49:24.962589 2026] [security2:error] [pid 62112:tid 62257] [client 185.177.72.67:7416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuqxMJgo6iBrIY9VJLYzwAAAJQ"]
[Thu Jul 30 14:49:25.107097 2026] [security2:error] [pid 62112:tid 62297] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqxMJgo6iBrIY9VJLYywAAvAU"]
[Thu Jul 30 14:49:25.212091 2026] [security2:error] [pid 62112:tid 62295] [client 185.177.72.67:7432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuqxcJgo6iBrIY9VJLY3AAAALo"]
[Thu Jul 30 14:49:25.395405 2026] [security2:error] [pid 62112:tid 62275] [client 20.52.125.110:4561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/admin.php"] [unique_id "amuqxcJgo6iBrIY9VJLY3gAAAKY"]
[Thu Jul 30 14:49:25.435072 2026] [security2:error] [pid 62112:tid 62172] [remote 57.141.0.64:33712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/6307"] [unique_id "amuqxcJgo6iBrIY9VJLY2wAAzjs"]
[Thu Jul 30 14:49:25.468331 2026] [security2:error] [pid 62112:tid 62305] [client 185.191.171.14:14744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/16/detran-pb-instala-junta-psicologica-para-revisao-de-resultado-do-exame-psicotecnico/"] [unique_id "amuqxcJgo6iBrIY9VJLY4AAAAMQ"]
[Thu Jul 30 14:49:25.468442 2026] [security2:error] [pid 62112:tid 62305] [client 185.191.171.14:14744] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/16/detran-pb-instala-junta-psicologica-para-revisao-de-resultado-do-exame-psicotecnico/"] [unique_id "amuqxcJgo6iBrIY9VJLY4AAAAMQ"]
[Thu Jul 30 14:49:25.479250 2026] [security2:error] [pid 62112:tid 62333] [client 185.177.72.67:7448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuqxcJgo6iBrIY9VJLY4wAAAOA"]
[Thu Jul 30 14:49:25.532424 2026] [security2:error] [pid 62112:tid 62349] [client 213.204.127.6:17452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqxcJgo6iBrIY9VJLY3QAAAPA"], referer: http://pkf.jo
[Thu Jul 30 14:49:25.719798 2026] [security2:error] [pid 62112:tid 62311] [client 172.213.232.128:40719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuqxcJgo6iBrIY9VJLY7gAAAMo"]
[Thu Jul 30 14:49:25.753757 2026] [security2:error] [pid 62112:tid 62313] [client 57.141.0.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqxcJgo6iBrIY9VJLY2QAAAMw"]
[Thu Jul 30 14:49:26.084003 2026] [security2:error] [pid 62112:tid 62277] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuqxcJgo6iBrIY9VJLY8AAAAKg"]
[Thu Jul 30 14:49:26.350609 2026] [security2:error] [pid 62112:tid 62351] [client 20.91.199.21:41294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuqxsJgo6iBrIY9VJLZAAAAAPI"]
[Thu Jul 30 14:49:26.364772 2026] [security2:error] [pid 62112:tid 62247] [client 20.52.125.110:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/as.php"] [unique_id "amuqxsJgo6iBrIY9VJLZAQAAAIo"]
[Thu Jul 30 14:49:26.696219 2026] [security2:error] [pid 62112:tid 62326] [client 52.238.199.152:33791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "amuqxsJgo6iBrIY9VJLZCgAAANk"]
[Thu Jul 30 14:49:26.732180 2026] [security2:error] [pid 62112:tid 62250] [client 45.157.52.13:59808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqxsJgo6iBrIY9VJLZAgAAAI0"], referer: http://pkf.jo
[Thu Jul 30 14:49:26.982831 2026] [security2:error] [pid 62112:tid 62324] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqxsJgo6iBrIY9VJLZEQAA1zc"]
[Thu Jul 30 14:49:26.996543 2026] [security2:error] [pid 62112:tid 62303] [client 20.52.125.110:10637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/autoload_classmap.php"] [unique_id "amuqxsJgo6iBrIY9VJLZFAAAAMI"]
[Thu Jul 30 14:49:27.084642 2026] [security2:error] [pid 62112:tid 62348] [client 57.141.0.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqxsJgo6iBrIY9VJLZBgAAAO8"]
[Thu Jul 30 14:49:27.440116 2026] [security2:error] [pid 62112:tid 62278] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqxsJgo6iBrIY9VJLZEgAAqSE"]
[Thu Jul 30 14:49:27.501537 2026] [security2:error] [pid 62112:tid 62361] [client 20.52.125.110:5325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/back.php"] [unique_id "amuqx8Jgo6iBrIY9VJLZHwAAAPw"]
[Thu Jul 30 14:49:27.972483 2026] [security2:error] [pid 62112:tid 62284] [client 43.173.176.100:41774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/02/24/le-pain-quotidien-saint-lazare/"] [unique_id "amuqx8Jgo6iBrIY9VJLZIwAAAK8"]
[Thu Jul 30 14:49:28.090085 2026] [security2:error] [pid 62112:tid 62323] [client 52.238.199.152:53194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuqyMJgo6iBrIY9VJLZLAAAANY"]
[Thu Jul 30 14:49:28.125454 2026] [security2:error] [pid 62112:tid 62292] [client 20.52.125.110:5329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuqyMJgo6iBrIY9VJLZLQAAALc"]
[Thu Jul 30 14:49:28.527444 2026] [security2:error] [pid 62112:tid 62269] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqyMJgo6iBrIY9VJLZOQAAoCU"]
[Thu Jul 30 14:49:28.539752 2026] [security2:error] [pid 62112:tid 62273] [client 189.156.226.90:26638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqyMJgo6iBrIY9VJLZPQAAAKQ"]
[Thu Jul 30 14:49:28.539869 2026] [security2:error] [pid 62112:tid 62273] [client 189.156.226.90:26638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuqyMJgo6iBrIY9VJLZPQAAAKQ"]
[Thu Jul 30 14:49:28.619901 2026] [core:notice] [pid 62112:tid 62274] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:28.625535 2026] [security2:error] [pid 62112:tid 62274] [client 43.173.174.199:55394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/02/24/le-pain-quotidien-saint-lazare/"] [unique_id "amuqyMJgo6iBrIY9VJLZPwAAAKU"], referer: https://carnetdeshopping.com/index.php/2016/02/24/le-pain-quotidien-saint-lazare/
[Thu Jul 30 14:49:28.777103 2026] [core:notice] [pid 62112:tid 62138] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:28.966478 2026] [security2:error] [pid 62112:tid 62277] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqyMJgo6iBrIY9VJLZOAAAqFA"]
[Thu Jul 30 14:49:29.208490 2026] [security2:error] [pid 62112:tid 62296] [client 20.52.125.110:10639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/c/flower.php"] [unique_id "amuqycJgo6iBrIY9VJLZVgAAALs"]
[Thu Jul 30 14:49:29.246147 2026] [security2:error] [pid 62112:tid 62266] [client 20.91.199.21:35830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/011i.php"] [unique_id "amuqycJgo6iBrIY9VJLZWwAAAJ0"]
[Thu Jul 30 14:49:29.490556 2026] [security2:error] [pid 62112:tid 62297] [client 52.167.144.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuqycJgo6iBrIY9VJLZVQAAALw"]
[Thu Jul 30 14:49:29.573851 2026] [security2:error] [pid 62112:tid 62330] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqycJgo6iBrIY9VJLZXQAA3VQ"]
[Thu Jul 30 14:49:29.948707 2026] [security2:error] [pid 62112:tid 62331] [client 20.52.125.110:5336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/c/xleet.php"] [unique_id "amuqycJgo6iBrIY9VJLZbAAAAN4"]
[Thu Jul 30 14:49:30.080667 2026] [security2:error] [pid 62112:tid 62306] [client 52.238.199.152:36696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuqysJgo6iBrIY9VJLZbQAAAMU"]
[Thu Jul 30 14:49:30.141643 2026] [security2:error] [pid 62112:tid 62337] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuqycJgo6iBrIY9VJLZZgAAAOQ"]
[Thu Jul 30 14:49:30.227608 2026] [security2:error] [pid 62112:tid 62263] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqycJgo6iBrIY9VJLZWgAAmlI"]
[Thu Jul 30 14:49:30.446561 2026] [security2:error] [pid 62112:tid 62344] [client 20.91.199.21:17475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp.php"] [unique_id "amuqysJgo6iBrIY9VJLZeQAAAOs"]
[Thu Jul 30 14:49:30.747558 2026] [security2:error] [pid 62112:tid 62273] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqysJgo6iBrIY9VJLZfQAApGA"]
[Thu Jul 30 14:49:30.879032 2026] [security2:error] [pid 62112:tid 62363] [client 20.52.125.110:5363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/classwithtostring.php"] [unique_id "amuqysJgo6iBrIY9VJLZiAAAAP4"]
[Thu Jul 30 14:49:30.911100 2026] [security2:error] [pid 62112:tid 62264] [client 52.167.144.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuqysJgo6iBrIY9VJLZgAAAAJs"]
[Thu Jul 30 14:49:31.096916 2026] [security2:error] [pid 62112:tid 62299] [client 103.190.45.60:40458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuqysJgo6iBrIY9VJLZgQAAvl8"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Ftiava.pro
[Thu Jul 30 14:49:31.429782 2026] [security2:error] [pid 62112:tid 62280] [client 172.213.232.128:41922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/class.api.php"] [unique_id "amuqy8Jgo6iBrIY9VJLZkgAAAKs"]
[Thu Jul 30 14:49:31.440285 2026] [security2:error] [pid 62112:tid 62295] [client 114.119.150.9:32659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shop-kent.com"] [uri "/product/hope/"] [unique_id "amuqy8Jgo6iBrIY9VJLZkwAAALo"], referer: https://shop-kent.com/product/hope/
[Thu Jul 30 14:49:31.645113 2026] [security2:error] [pid 62112:tid 62317] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqy8Jgo6iBrIY9VJLZlAAA0GY"]
[Thu Jul 30 14:49:31.851969 2026] [security2:error] [pid 62112:tid 62288] [client 52.167.144.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuqy8Jgo6iBrIY9VJLZmgAAALM"]
[Thu Jul 30 14:49:31.890080 2026] [security2:error] [pid 62112:tid 62242] [client 20.91.199.21:6957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/aaa.php"] [unique_id "amuqy8Jgo6iBrIY9VJLZoQAAAIU"]
[Thu Jul 30 14:49:31.891623 2026] [security2:error] [pid 62112:tid 62258] [client 20.52.125.110:5312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/content.php"] [unique_id "amuqy8Jgo6iBrIY9VJLZogAAAJU"]
[Thu Jul 30 14:49:32.052627 2026] [security2:error] [pid 62112:tid 62343] [client 172.213.232.128:40716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/cong.php"] [unique_id "amuqzMJgo6iBrIY9VJLZpgAAAOo"]
[Thu Jul 30 14:49:32.357738 2026] [security2:error] [pid 62112:tid 62256] [client 20.91.199.21:53977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/03a005685d.php"] [unique_id "amuqzMJgo6iBrIY9VJLZrgAAAJM"]
[Thu Jul 30 14:49:32.449312 2026] [security2:error] [pid 62112:tid 62301] [client 52.238.199.152:36675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/uploads/2024/index.php"] [unique_id "amuqzMJgo6iBrIY9VJLZrwAAAMA"]
[Thu Jul 30 14:49:32.488870 2026] [security2:error] [pid 62112:tid 62311] [client 20.52.125.110:10631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/doc.php"] [unique_id "amuqzMJgo6iBrIY9VJLZsAAAAMo"]
[Thu Jul 30 14:49:32.683773 2026] [security2:error] [pid 62112:tid 62360] [client 177.6.106.101:54560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqzMJgo6iBrIY9VJLZtwAAAPs"]
[Thu Jul 30 14:49:32.683884 2026] [security2:error] [pid 62112:tid 62360] [client 177.6.106.101:54560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuqzMJgo6iBrIY9VJLZtwAAAPs"]
[Thu Jul 30 14:49:32.832456 2026] [security2:error] [pid 62112:tid 62369] [client 20.91.199.21:14086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/hoot.php"] [unique_id "amuqzMJgo6iBrIY9VJLZuwAAAQQ"]
[Thu Jul 30 14:49:32.842765 2026] [security2:error] [pid 62112:tid 62342] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqzMJgo6iBrIY9VJLZpwAA6XY"]
[Thu Jul 30 14:49:32.857610 2026] [security2:error] [pid 62112:tid 62338] [client 172.213.232.128:44587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/content.php"] [unique_id "amuqzMJgo6iBrIY9VJLZvAAAAOU"]
[Thu Jul 30 14:49:33.162386 2026] [security2:error] [pid 62112:tid 62264] [client 110.249.201.66:55794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuqzcJgo6iBrIY9VJLZwwAAAJs"]
[Thu Jul 30 14:49:33.331708 2026] [security2:error] [pid 62112:tid 62253] [client 20.91.199.21:50405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/403.php"] [unique_id "amuqzcJgo6iBrIY9VJLZxwAAAJA"]
[Thu Jul 30 14:49:33.335596 2026] [security2:error] [pid 62112:tid 62284] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuqzMJgo6iBrIY9VJLZswAAr2M"]
[Thu Jul 30 14:49:33.362313 2026] [security2:error] [pid 62112:tid 62270] [client 20.52.125.110:5341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/dropdown.php"] [unique_id "amuqzcJgo6iBrIY9VJLZyQAAAKE"]
[Thu Jul 30 14:49:33.572309 2026] [security2:error] [pid 62112:tid 62320] [client 172.213.232.128:41635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuqzcJgo6iBrIY9VJLZzQAAANM"]
[Thu Jul 30 14:49:33.688112 2026] [security2:error] [pid 62112:tid 62262] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqzcJgo6iBrIY9VJLZzAAAmWs"]
[Thu Jul 30 14:49:33.851081 2026] [security2:error] [pid 62112:tid 62324] [client 20.52.125.110:10670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/ee.php"] [unique_id "amuqzcJgo6iBrIY9VJLZ0gAAANc"]
[Thu Jul 30 14:49:33.911467 2026] [security2:error] [pid 62112:tid 62356] [client 20.91.199.21:50410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/404.php"] [unique_id "amuqzcJgo6iBrIY9VJLZ1gAAAPc"]
[Thu Jul 30 14:49:34.138162 2026] [security2:error] [pid 62112:tid 62288] [client 172.213.232.128:45508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/elp.php"] [unique_id "amuqzsJgo6iBrIY9VJLZ2gAAALM"]
[Thu Jul 30 14:49:34.243911 2026] [security2:error] [pid 62112:tid 62347] [client 20.91.199.21:17862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/about.php"] [unique_id "amuqzsJgo6iBrIY9VJLZ3gAAAO4"]
[Thu Jul 30 14:49:34.617508 2026] [security2:error] [pid 62112:tid 62358] [client 20.52.125.110:10647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/flower.php"] [unique_id "amuqzsJgo6iBrIY9VJLZ5gAAAPk"]
[Thu Jul 30 14:49:34.722776 2026] [security2:error] [pid 62112:tid 62292] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuqzsJgo6iBrIY9VJLZ5QAAtwE"]
[Thu Jul 30 14:49:34.872364 2026] [security2:error] [pid 62112:tid 62261] [client 20.91.199.21:53454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/aa.php"] [unique_id "amuqzsJgo6iBrIY9VJLZ7QAAAJg"]
[Thu Jul 30 14:49:35.341378 2026] [security2:error] [pid 62112:tid 62313] [client 20.91.199.21:40922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/admin.php"] [unique_id "amuqz8Jgo6iBrIY9VJLZ9wAAAMw"]
[Thu Jul 30 14:49:35.556647 2026] [security2:error] [pid 62112:tid 62351] [client 20.52.125.110:10624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/gecko-new.php"] [unique_id "amuqz8Jgo6iBrIY9VJLZ_wAAAPI"]
[Thu Jul 30 14:49:35.569036 2026] [security2:error] [pid 62112:tid 62278] [client 172.213.232.128:45545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuqz8Jgo6iBrIY9VJLaAAAAAKk"]
[Thu Jul 30 14:49:36.206319 2026] [security2:error] [pid 62112:tid 62355] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuq0MJgo6iBrIY9VJLaCgAA9n0"]
[Thu Jul 30 14:49:36.214355 2026] [security2:error] [pid 62112:tid 62360] [client 20.91.199.21:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/aafewc0k.php"] [unique_id "amuq0MJgo6iBrIY9VJLaCwAAAPs"]
[Thu Jul 30 14:49:36.408768 2026] [security2:error] [pid 62112:tid 62248] [client 52.238.199.152:36729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known/cong.php"] [unique_id "amuq0MJgo6iBrIY9VJLaEgAAAIs"]
[Thu Jul 30 14:49:36.592648 2026] [security2:error] [pid 62112:tid 62270] [client 20.52.125.110:5328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/m.php"] [unique_id "amuq0MJgo6iBrIY9VJLaFgAAAKE"]
[Thu Jul 30 14:49:37.043303 2026] [security2:error] [pid 62112:tid 62317] [client 172.213.232.128:24610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuq0cJgo6iBrIY9VJLaIAAAANA"]
[Thu Jul 30 14:49:37.154604 2026] [security2:error] [pid 62112:tid 62288] [client 20.91.199.21:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/abcd.php"] [unique_id "amuq0cJgo6iBrIY9VJLaJAAAALM"]
[Thu Jul 30 14:49:37.417114 2026] [security2:error] [pid 62112:tid 62258] [client 20.52.125.110:10679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuq0cJgo6iBrIY9VJLaKAAAAJU"]
[Thu Jul 30 14:49:37.665155 2026] [security2:error] [pid 62112:tid 62256] [client 172.213.232.128:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuq0cJgo6iBrIY9VJLaMAAAAJM"]
[Thu Jul 30 14:49:37.848085 2026] [security2:error] [pid 62112:tid 62127] [remote 142.93.0.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rooferio.enterprises"] [uri "/info.php"] [unique_id "amuq0cJgo6iBrIY9VJLaLwAAxQ4"]
[Thu Jul 30 14:49:37.930438 2026] [core:error] [pid 62112:tid 62291] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:49:37.930467 2026] [core:error] [pid 62112:tid 62291] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:49:38.296433 2026] [security2:error] [pid 62112:tid 62345] [client 20.52.125.110:5364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/mah/flower.php"] [unique_id "amuq0sJgo6iBrIY9VJLaPwAAAOw"]
[Thu Jul 30 14:49:38.535579 2026] [security2:error] [pid 62112:tid 62264] [client 172.213.232.128:41940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuq0sJgo6iBrIY9VJLaRwAAAJs"]
[Thu Jul 30 14:49:38.572298 2026] [security2:error] [pid 62112:tid 62278] [client 20.91.199.21:49405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/about.php"] [unique_id "amuq0sJgo6iBrIY9VJLaSAAAAKk"]
[Thu Jul 30 14:49:38.697264 2026] [security2:error] [pid 62112:tid 62260] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuq0sJgo6iBrIY9VJLaOQAAlxU"]
[Thu Jul 30 14:49:38.756213 2026] [security2:error] [pid 62112:tid 62329] [client 20.52.125.110:10685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/mah/xleet.php"] [unique_id "amuq0sJgo6iBrIY9VJLaUQAAANw"]
[Thu Jul 30 14:49:39.077620 2026] [security2:error] [pid 62112:tid 62297] [client 189.156.226.90:27055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq08Jgo6iBrIY9VJLaWAAAALw"]
[Thu Jul 30 14:49:39.077723 2026] [security2:error] [pid 62112:tid 62297] [client 189.156.226.90:27055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq08Jgo6iBrIY9VJLaWAAAALw"]
[Thu Jul 30 14:49:39.188177 2026] [security2:error] [pid 62112:tid 62144] [remote 57.141.0.47:64216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuq08Jgo6iBrIY9VJLaWgAA2B8"]
[Thu Jul 30 14:49:39.196842 2026] [security2:error] [pid 62112:tid 62249] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuq0sJgo6iBrIY9VJLaTgAAAIw"]
[Thu Jul 30 14:49:39.354292 2026] [security2:error] [pid 62112:tid 62331] [client 20.52.125.110:10633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/mini.php"] [unique_id "amuq08Jgo6iBrIY9VJLaXQAAAN4"]
[Thu Jul 30 14:49:39.383399 2026] [security2:error] [pid 62112:tid 62340] [client 114.119.134.182:44293] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mydubaidesertsafari.com"] [uri "/q7m1iw/andrew-goodman-death"] [unique_id "amuq08Jgo6iBrIY9VJLaXgAAAOc"], referer: https://rutadeloro.com/SjAKB/royal-mail-new-stamps-2022
[Thu Jul 30 14:49:39.469420 2026] [security2:error] [pid 62112:tid 62333] [client 20.91.199.21:54484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/admin.php"] [unique_id "amuq08Jgo6iBrIY9VJLaXwAAAOA"]
[Thu Jul 30 14:49:39.687959 2026] [autoindex:error] [pid 62112:tid 62336] [client 2605:6400:10:2e1:b22c:4cad:703a:ea85:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://melatipkr.xyz
[Thu Jul 30 14:49:39.824435 2026] [security2:error] [pid 62112:tid 62306] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/coffee.php"] [unique_id "amuq08Jgo6iBrIY9VJLaawAAAMU"]
[Thu Jul 30 14:49:39.824543 2026] [security2:error] [pid 62112:tid 62306] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/coffee.php"] [unique_id "amuq08Jgo6iBrIY9VJLaawAAAMU"]
[Thu Jul 30 14:49:39.876026 2026] [security2:error] [pid 62112:tid 62265] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuq08Jgo6iBrIY9VJLaaAAAnAU"]
[Thu Jul 30 14:49:39.883006 2026] [security2:error] [pid 62112:tid 62324] [client 172.213.232.128:41947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuq08Jgo6iBrIY9VJLabAAAANc"]
[Thu Jul 30 14:49:39.914588 2026] [security2:error] [pid 62112:tid 62308] [client 20.52.125.110:10669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/moon.php"] [unique_id "amuq08Jgo6iBrIY9VJLacQAAAMc"]
[Thu Jul 30 14:49:40.068848 2026] [security2:error] [pid 62112:tid 62251] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/goods.php"] [unique_id "amuq1MJgo6iBrIY9VJLadQAAAI4"]
[Thu Jul 30 14:49:40.068951 2026] [security2:error] [pid 62112:tid 62251] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/goods.php"] [unique_id "amuq1MJgo6iBrIY9VJLadQAAAI4"]
[Thu Jul 30 14:49:40.099486 2026] [security2:error] [pid 62112:tid 62275] [client 52.238.199.152:36719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuq1MJgo6iBrIY9VJLadwAAAKY"]
[Thu Jul 30 14:49:40.328704 2026] [security2:error] [pid 62112:tid 62279] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amuq1MJgo6iBrIY9VJLafgAAAKo"]
[Thu Jul 30 14:49:40.328820 2026] [security2:error] [pid 62112:tid 62279] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amuq1MJgo6iBrIY9VJLafgAAAKo"]
[Thu Jul 30 14:49:40.401190 2026] [security2:error] [pid 62112:tid 62272] [client 27.125.240.208:9040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq1MJgo6iBrIY9VJLadgAAAKM"], referer: http://pkf.jo
[Thu Jul 30 14:49:40.499407 2026] [security2:error] [pid 62112:tid 62361] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuq08Jgo6iBrIY9VJLabgAA_BM"]
[Thu Jul 30 14:49:40.518001 2026] [security2:error] [pid 62112:tid 62345] [client 20.52.125.110:10644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/new.php"] [unique_id "amuq1MJgo6iBrIY9VJLaggAAAOw"]
[Thu Jul 30 14:49:40.584031 2026] [security2:error] [pid 62112:tid 62321] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amuq1MJgo6iBrIY9VJLahgAAANQ"]
[Thu Jul 30 14:49:40.584147 2026] [security2:error] [pid 62112:tid 62321] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/about.php"] [unique_id "amuq1MJgo6iBrIY9VJLahgAAANQ"]
[Thu Jul 30 14:49:40.676715 2026] [security2:error] [pid 62112:tid 62312] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuq1MJgo6iBrIY9VJLagQAAyyc"]
[Thu Jul 30 14:49:40.697517 2026] [security2:error] [pid 62112:tid 62352] [client 172.213.232.128:45515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuq1MJgo6iBrIY9VJLaigAAAPM"]
[Thu Jul 30 14:49:40.723006 2026] [security2:error] [pid 62112:tid 62250] [client 90.129.227.229:34850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq1MJgo6iBrIY9VJLafwAAAI0"], referer: http://pkf.jo
[Thu Jul 30 14:49:40.780496 2026] [security2:error] [pid 62112:tid 62359] [client 39.34.171.187:35789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq1MJgo6iBrIY9VJLagAAAAPo"], referer: http://pkf.jo
[Thu Jul 30 14:49:40.834461 2026] [security2:error] [pid 62112:tid 62262] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuq1MJgo6iBrIY9VJLajgAAAJk"]
[Thu Jul 30 14:49:40.834545 2026] [security2:error] [pid 62112:tid 62262] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/admin.php"] [unique_id "amuq1MJgo6iBrIY9VJLajgAAAJk"]
[Thu Jul 30 14:49:41.147895 2026] [security2:error] [pid 62112:tid 62276] [client 20.52.125.110:5344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/radio.php"] [unique_id "amuq1cJgo6iBrIY9VJLamwAAAKc"]
[Thu Jul 30 14:49:41.275990 2026] [security2:error] [pid 62112:tid 62248] [client 52.238.199.152:47209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/edit.php"] [unique_id "amuq1cJgo6iBrIY9VJLanwAAAIs"]
[Thu Jul 30 14:49:41.386350 2026] [security2:error] [pid 62112:tid 62356] [client 106.215.154.59:8711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq1cJgo6iBrIY9VJLakwAAAPc"], referer: http://pkf.jo
[Thu Jul 30 14:49:41.467958 2026] [security2:error] [pid 62112:tid 62310] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amuq1cJgo6iBrIY9VJLaoQAAAMk"]
[Thu Jul 30 14:49:41.468106 2026] [security2:error] [pid 62112:tid 62310] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amuq1cJgo6iBrIY9VJLaoQAAAMk"]
[Thu Jul 30 14:49:41.529662 2026] [security2:error] [pid 62112:tid 62327] [client 187.234.241.51:46342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq1cJgo6iBrIY9VJLalwAAANo"], referer: http://pkf.jo
[Thu Jul 30 14:49:41.568573 2026] [security2:error] [pid 62112:tid 62266] [client 99.250.30.18:59276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq1MJgo6iBrIY9VJLakQAAAJ0"], referer: http://pkf.jo
[Thu Jul 30 14:49:41.677256 2026] [security2:error] [pid 62112:tid 62350] [client 213.172.155.75:55908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq1cJgo6iBrIY9VJLaoAAAAPE"], referer: http://pkf.jo
[Thu Jul 30 14:49:41.721246 2026] [security2:error] [pid 62112:tid 62332] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amuq1cJgo6iBrIY9VJLaqQAAAN8"]
[Thu Jul 30 14:49:41.721336 2026] [security2:error] [pid 62112:tid 62332] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/inputs.php"] [unique_id "amuq1cJgo6iBrIY9VJLaqQAAAN8"]
[Thu Jul 30 14:49:41.813083 2026] [security2:error] [pid 62112:tid 62331] [client 20.52.125.110:10672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/s.php"] [unique_id "amuq1cJgo6iBrIY9VJLarQAAAN4"]
[Thu Jul 30 14:49:41.954957 2026] [security2:error] [pid 62112:tid 62291] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/adminfuns.php"] [unique_id "amuq1cJgo6iBrIY9VJLarwAAALY"]
[Thu Jul 30 14:49:41.955111 2026] [security2:error] [pid 62112:tid 62291] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/adminfuns.php"] [unique_id "amuq1cJgo6iBrIY9VJLarwAAALY"]
[Thu Jul 30 14:49:41.986039 2026] [security2:error] [pid 62112:tid 62354] [client 20.91.199.21:53451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/adminfuns.php"] [unique_id "amuq1cJgo6iBrIY9VJLasAAAAPU"]
[Thu Jul 30 14:49:42.206392 2026] [security2:error] [pid 62112:tid 62254] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/404.php"] [unique_id "amuq1sJgo6iBrIY9VJLatAAAAJE"]
[Thu Jul 30 14:49:42.206483 2026] [security2:error] [pid 62112:tid 62254] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/404.php"] [unique_id "amuq1sJgo6iBrIY9VJLatAAAAJE"]
[Thu Jul 30 14:49:42.264195 2026] [security2:error] [pid 62112:tid 62187] [remote 209.42.27.148:60488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.27.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuq1sJgo6iBrIY9VJLauAAAyko"]
[Thu Jul 30 14:49:42.452490 2026] [security2:error] [pid 62112:tid 62286] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/xxx.php"] [unique_id "amuq1sJgo6iBrIY9VJLavQAAALE"]
[Thu Jul 30 14:49:42.452619 2026] [security2:error] [pid 62112:tid 62286] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/xxx.php"] [unique_id "amuq1sJgo6iBrIY9VJLavQAAALE"]
[Thu Jul 30 14:49:42.469426 2026] [security2:error] [pid 62112:tid 62252] [client 20.52.125.110:5474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/sim.php"] [unique_id "amuq1sJgo6iBrIY9VJLavgAAAI8"]
[Thu Jul 30 14:49:42.612292 2026] [security2:error] [pid 62112:tid 62271] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuq1sJgo6iBrIY9VJLavAAAoiw"]
[Thu Jul 30 14:49:42.699394 2026] [security2:error] [pid 62112:tid 62264] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/classwithtostring.php"] [unique_id "amuq1sJgo6iBrIY9VJLawgAAAJs"]
[Thu Jul 30 14:49:42.699482 2026] [security2:error] [pid 62112:tid 62264] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/classwithtostring.php"] [unique_id "amuq1sJgo6iBrIY9VJLawgAAAJs"]
[Thu Jul 30 14:49:42.770876 2026] [security2:error] [pid 62112:tid 62364] [client 172.213.232.128:40724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuq1sJgo6iBrIY9VJLaxwAAAP8"]
[Thu Jul 30 14:49:42.874338 2026] [security2:error] [pid 62112:tid 62351] [client 20.91.199.21:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/albin.php"] [unique_id "amuq1sJgo6iBrIY9VJLaywAAAPI"]
[Thu Jul 30 14:49:42.948738 2026] [security2:error] [pid 62112:tid 62250] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/234ff.php"] [unique_id "amuq1sJgo6iBrIY9VJLazQAAAI0"]
[Thu Jul 30 14:49:42.948848 2026] [security2:error] [pid 62112:tid 62250] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/234ff.php"] [unique_id "amuq1sJgo6iBrIY9VJLazQAAAI0"]
[Thu Jul 30 14:49:43.208007 2026] [security2:error] [pid 62112:tid 62296] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/133.php"] [unique_id "amuq18Jgo6iBrIY9VJLa0AAAALs"]
[Thu Jul 30 14:49:43.208108 2026] [security2:error] [pid 62112:tid 62296] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/133.php"] [unique_id "amuq18Jgo6iBrIY9VJLa0AAAALs"]
[Thu Jul 30 14:49:43.218084 2026] [security2:error] [pid 62112:tid 62277] [client 31.215.86.2:52138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq1sJgo6iBrIY9VJLazAAAAKg"], referer: http://pkf.jo
[Thu Jul 30 14:49:43.345678 2026] [security2:error] [pid 62112:tid 62369] [client 177.6.106.101:55156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuq18Jgo6iBrIY9VJLa1wAAAQQ"]
[Thu Jul 30 14:49:43.346516 2026] [security2:error] [pid 62112:tid 62369] [client 177.6.106.101:55156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuq18Jgo6iBrIY9VJLa1wAAAQQ"]
[Thu Jul 30 14:49:43.460651 2026] [security2:error] [pid 62112:tid 62293] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-ws68.php"] [unique_id "amuq18Jgo6iBrIY9VJLa2QAAALg"]
[Thu Jul 30 14:49:43.460771 2026] [security2:error] [pid 62112:tid 62293] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/wp-ws68.php"] [unique_id "amuq18Jgo6iBrIY9VJLa2QAAALg"]
[Thu Jul 30 14:49:43.563879 2026] [security2:error] [pid 62112:tid 62366] [client 20.52.125.110:5369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/text.php"] [unique_id "amuq18Jgo6iBrIY9VJLa2wAAAQE"]
[Thu Jul 30 14:49:43.618391 2026] [security2:error] [pid 62112:tid 62325] [client 20.91.199.21:54535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/amfsqvgv.php"] [unique_id "amuq18Jgo6iBrIY9VJLa3AAAANg"]
[Thu Jul 30 14:49:43.709274 2026] [security2:error] [pid 62112:tid 62297] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/mgrr.php"] [unique_id "amuq18Jgo6iBrIY9VJLa3QAAALw"]
[Thu Jul 30 14:49:43.709391 2026] [security2:error] [pid 62112:tid 62297] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/mgrr.php"] [unique_id "amuq18Jgo6iBrIY9VJLa3QAAALw"]
[Thu Jul 30 14:49:43.734156 2026] [security2:error] [pid 62112:tid 62285] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuq18Jgo6iBrIY9VJLa2gAAsD4"]
[Thu Jul 30 14:49:43.943531 2026] [security2:error] [pid 62112:tid 62358] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/55.php"] [unique_id "amuq18Jgo6iBrIY9VJLa5wAAAPk"]
[Thu Jul 30 14:49:43.943643 2026] [security2:error] [pid 62112:tid 62358] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.tranquilrootsisb.space"] [uri "/55.php"] [unique_id "amuq18Jgo6iBrIY9VJLa5wAAAPk"]
[Thu Jul 30 14:49:43.980722 2026] [core:notice] [pid 62112:tid 62248] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:44.267164 2026] [security2:error] [pid 62112:tid 62258] [client 20.52.125.110:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/user.php"] [unique_id "amuq2MJgo6iBrIY9VJLa6gAAAJU"]
[Thu Jul 30 14:49:44.549234 2026] [security2:error] [pid 62112:tid 62255] [client 172.213.232.128:44556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuq2MJgo6iBrIY9VJLa8wAAAJI"]
[Thu Jul 30 14:49:45.029586 2026] [security2:error] [pid 62112:tid 62249] [client 52.238.199.152:59809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/about/function.php"] [unique_id "amuq2cJgo6iBrIY9VJLa_gAAAIw"]
[Thu Jul 30 14:49:46.356133 2026] [security2:error] [pid 62112:tid 62325] [client 172.213.232.128:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuq2sJgo6iBrIY9VJLbIgAAANg"]
[Thu Jul 30 14:49:46.448615 2026] [security2:error] [pid 62112:tid 62281] [client 20.52.125.110:5319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/webadmin.php"] [unique_id "amuq2sJgo6iBrIY9VJLbJwAAAKw"]
[Thu Jul 30 14:49:46.710734 2026] [security2:error] [pid 62112:tid 62343] [client 20.91.199.21:14121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuq2sJgo6iBrIY9VJLbKwAAAOo"]
[Thu Jul 30 14:49:46.716210 2026] [security2:error] [pid 62112:tid 62250] [client 52.238.199.152:36713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/simple/function.php"] [unique_id "amuq2sJgo6iBrIY9VJLbLAAAAI0"]
[Thu Jul 30 14:49:46.914791 2026] [core:notice] [pid 62112:tid 62344] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:47.085088 2026] [security2:error] [pid 62112:tid 62301] [client 20.52.125.110:5322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amuq28Jgo6iBrIY9VJLbUgAAAMA"]
[Thu Jul 30 14:49:47.187940 2026] [security2:error] [pid 62112:tid 62263] [client 20.91.199.21:51472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/ant.php"] [unique_id "amuq28Jgo6iBrIY9VJLbWQAAAJo"]
[Thu Jul 30 14:49:47.732869 2026] [security2:error] [pid 62112:tid 62268] [client 20.91.199.21:17860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuq28Jgo6iBrIY9VJLbZwAAAJ8"]
[Thu Jul 30 14:49:47.760860 2026] [security2:error] [pid 62112:tid 62305] [client 20.52.125.110:5335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amuq28Jgo6iBrIY9VJLbaAAAAMQ"]
[Thu Jul 30 14:49:47.812227 2026] [security2:error] [pid 62112:tid 62338] [client 52.238.199.152:36716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/mah/function.php"] [unique_id "amuq28Jgo6iBrIY9VJLbaQAAAOU"]
[Thu Jul 30 14:49:48.189758 2026] [security2:error] [pid 62112:tid 62296] [client 20.91.199.21:50379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/appreciators.php"] [unique_id "amuq3MJgo6iBrIY9VJLbggAAALs"]
[Thu Jul 30 14:49:48.396300 2026] [security2:error] [pid 62112:tid 62330] [client 20.52.125.110:5454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amuq3MJgo6iBrIY9VJLbgwAAAN0"]
[Thu Jul 30 14:49:48.908522 2026] [security2:error] [pid 62112:tid 62300] [client 20.52.125.110:5318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amuq3MJgo6iBrIY9VJLbkwAAAL8"]
[Thu Jul 30 14:49:49.045621 2026] [security2:error] [pid 62112:tid 62350] [client 52.238.199.152:47175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/go.php"] [unique_id "amuq3cJgo6iBrIY9VJLblwAAAPE"]
[Thu Jul 30 14:49:49.434608 2026] [security2:error] [pid 62112:tid 62294] [client 20.91.199.21:41284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuq3cJgo6iBrIY9VJLbngAAALk"]
[Thu Jul 30 14:49:49.668784 2026] [security2:error] [pid 62112:tid 62362] [client 189.156.226.90:27608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq3cJgo6iBrIY9VJLbpQAAAP0"]
[Thu Jul 30 14:49:49.668883 2026] [security2:error] [pid 62112:tid 62362] [client 189.156.226.90:27608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq3cJgo6iBrIY9VJLbpQAAAP0"]
[Thu Jul 30 14:49:49.911469 2026] [security2:error] [pid 62112:tid 62269] [client 20.52.125.110:10674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amuq3cJgo6iBrIY9VJLbrAAAAKA"]
[Thu Jul 30 14:49:50.568672 2026] [security2:error] [pid 62112:tid 62359] [client 20.52.125.110:10671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amuq3sJgo6iBrIY9VJLbuwAAAPo"]
[Thu Jul 30 14:49:50.931259 2026] [core:error] [pid 62112:tid 62303] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:49:50.931281 2026] [core:error] [pid 62112:tid 62303] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:49:51.415377 2026] [security2:error] [pid 62112:tid 62333] [client 20.52.125.110:5316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuq38Jgo6iBrIY9VJLb0QAAAOA"]
[Thu Jul 30 14:49:51.515688 2026] [security2:error] [pid 62112:tid 62323] [client 5.161.255.152:51330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuq38Jgo6iBrIY9VJLbzgAAANY"]
[Thu Jul 30 14:49:51.682276 2026] [security2:error] [pid 62112:tid 62312] [client 5.161.255.152:51634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuq38Jgo6iBrIY9VJLb0AAAAMs"]
[Thu Jul 30 14:49:51.709618 2026] [security2:error] [pid 62112:tid 62314] [client 172.213.232.128:44598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuq38Jgo6iBrIY9VJLb3AAAAM0"]
[Thu Jul 30 14:49:51.727196 2026] [security2:error] [pid 62112:tid 62293] [client 52.238.199.152:47181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/buy.php"] [unique_id "amuq38Jgo6iBrIY9VJLb3QAAALg"]
[Thu Jul 30 14:49:51.793409 2026] [core:notice] [pid 62112:tid 62339] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:52.051017 2026] [security2:error] [pid 62112:tid 62282] [client 5.161.255.152:51334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.raad.pk"] [uri "/index.php"] [unique_id "amuq38Jgo6iBrIY9VJLbzwAAAK0"]
[Thu Jul 30 14:49:52.121609 2026] [core:notice] [pid 62112:tid 62178] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:52.190601 2026] [security2:error] [pid 62112:tid 62253] [client 20.91.199.21:53068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/archive.php"] [unique_id "amuq4MJgo6iBrIY9VJLb6wAAAJA"]
[Thu Jul 30 14:49:52.311111 2026] [core:notice] [pid 62112:tid 62162] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:52.508802 2026] [core:notice] [pid 62112:tid 62168] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:52.649056 2026] [security2:error] [pid 62112:tid 62246] [client 52.238.199.152:37338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/themes/astra/inc/ki1k.php"] [unique_id "amuq4MJgo6iBrIY9VJLb9gAAAIk"]
[Thu Jul 30 14:49:52.884375 2026] [security2:error] [pid 62112:tid 62262] [client 20.91.199.21:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuq4MJgo6iBrIY9VJLb_QAAAJk"]
[Thu Jul 30 14:49:52.975310 2026] [security2:error] [pid 62112:tid 62338] [client 20.91.199.21:51468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/as.php"] [unique_id "amuq4MJgo6iBrIY9VJLb_wAAAOU"]
[Thu Jul 30 14:49:53.630902 2026] [security2:error] [pid 62112:tid 62258] [client 20.91.199.21:51489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/atomlib.php"] [unique_id "amuq4cJgo6iBrIY9VJLcFgAAAJU"]
[Thu Jul 30 14:49:54.074596 2026] [security2:error] [pid 62112:tid 62263] [client 52.238.199.152:3592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wq.php7"] [unique_id "amuq4sJgo6iBrIY9VJLcIgAAAJo"]
[Thu Jul 30 14:49:54.094063 2026] [security2:error] [pid 62112:tid 62312] [client 142.93.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rooferio.enterprises"] [uri "/index.php"] [unique_id "amuq4cJgo6iBrIY9VJLcHgAAy0k"]
[Thu Jul 30 14:49:54.379108 2026] [security2:error] [pid 62112:tid 62319] [client 20.52.125.110:10646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amuq4sJgo6iBrIY9VJLcLAAAANI"]
[Thu Jul 30 14:49:54.480128 2026] [security2:error] [pid 62112:tid 62314] [client 177.6.106.101:55999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuq4sJgo6iBrIY9VJLcLQAAAM0"]
[Thu Jul 30 14:49:54.480250 2026] [security2:error] [pid 62112:tid 62314] [client 177.6.106.101:55999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuq4sJgo6iBrIY9VJLcLQAAAM0"]
[Thu Jul 30 14:49:54.544308 2026] [security2:error] [pid 62112:tid 62254] [client 172.213.232.128:40641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuq4sJgo6iBrIY9VJLcLgAAAJE"]
[Thu Jul 30 14:49:54.909896 2026] [security2:error] [pid 62112:tid 62246] [client 52.238.199.152:37022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/forum.php"] [unique_id "amuq4sJgo6iBrIY9VJLcOQAAAIk"]
[Thu Jul 30 14:49:55.078055 2026] [security2:error] [pid 62112:tid 62283] [client 20.52.125.110:4578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amuq48Jgo6iBrIY9VJLcOgAAAK4"]
[Thu Jul 30 14:49:55.682898 2026] [security2:error] [pid 62112:tid 62340] [client 20.52.125.110:10680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amuq48Jgo6iBrIY9VJLcSwAAAOc"]
[Thu Jul 30 14:49:55.704485 2026] [core:notice] [pid 62112:tid 62322] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:55.717758 2026] [security2:error] [pid 62112:tid 62252] [client 20.91.199.21:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/autoload_classmap.php"] [unique_id "amuq48Jgo6iBrIY9VJLcTQAAAI8"]
[Thu Jul 30 14:49:56.010770 2026] [security2:error] [pid 62112:tid 62262] [client 172.213.232.128:40895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuq5MJgo6iBrIY9VJLcVQAAAJk"]
[Thu Jul 30 14:49:56.011877 2026] [security2:error] [pid 62112:tid 62248] [client 52.238.199.152:37033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/5index.php"] [unique_id "amuq5MJgo6iBrIY9VJLcVgAAAIs"]
[Thu Jul 30 14:49:56.550138 2026] [core:notice] [pid 62112:tid 62208] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:56.567827 2026] [core:notice] [pid 62112:tid 62265] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:49:56.679703 2026] [security2:error] [pid 62112:tid 62274] [client 172.213.232.128:40873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuq5MJgo6iBrIY9VJLcYwAAAKU"]
[Thu Jul 30 14:49:56.897935 2026] [security2:error] [pid 62112:tid 62286] [client 20.91.199.21:49391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/bb.php"] [unique_id "amuq5MJgo6iBrIY9VJLcbQAAALE"]
[Thu Jul 30 14:49:57.050082 2026] [security2:error] [pid 62112:tid 62292] [client 20.52.125.110:4545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/flower.php"] [unique_id "amuq5cJgo6iBrIY9VJLcbgAAALc"]
[Thu Jul 30 14:49:57.232394 2026] [security2:error] [pid 62112:tid 62349] [client 20.91.199.21:13649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuq5cJgo6iBrIY9VJLcbwAAAPA"]
[Thu Jul 30 14:49:57.250935 2026] [autoindex:error] [pid 62112:tid 62257] [client 134.209.47.102:51954] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:49:57.548858 2026] [security2:error] [pid 62112:tid 62305] [client 172.213.232.128:40892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuq5cJgo6iBrIY9VJLcewAAAMQ"]
[Thu Jul 30 14:49:57.623181 2026] [security2:error] [pid 62112:tid 62173] [remote 97.74.93.24:43678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuq5cJgo6iBrIY9VJLcfAAArzw"]
[Thu Jul 30 14:49:57.695018 2026] [security2:error] [pid 62112:tid 62364] [client 20.52.125.110:5360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amuq5cJgo6iBrIY9VJLcgQAAAP8"]
[Thu Jul 30 14:49:57.966946 2026] [security2:error] [pid 62112:tid 62366] [client 20.91.199.21:3260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuq5cJgo6iBrIY9VJLcjAAAAQE"]
[Thu Jul 30 14:49:58.025059 2026] [security2:error] [pid 62112:tid 62245] [client 20.91.199.21:50380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/bnm.php"] [unique_id "amuq5sJgo6iBrIY9VJLcjQAAAIg"]
[Thu Jul 30 14:49:58.104554 2026] [security2:error] [pid 62112:tid 62251] [client 52.238.199.152:37337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/cookie.php"] [unique_id "amuq5sJgo6iBrIY9VJLcjgAAAI4"]
[Thu Jul 30 14:49:58.216832 2026] [security2:error] [pid 62112:tid 62343] [client 20.52.125.110:4565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amuq5sJgo6iBrIY9VJLcjwAAAOo"]
[Thu Jul 30 14:49:58.402325 2026] [autoindex:error] [pid 62112:tid 62304] [client 134.209.47.102:60836] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:49:58.840885 2026] [security2:error] [pid 62112:tid 62244] [client 172.213.232.128:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuq5sJgo6iBrIY9VJLcnQAAAIc"]
[Thu Jul 30 14:49:59.107839 2026] [security2:error] [pid 62112:tid 62287] [client 40.77.167.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuq5sJgo6iBrIY9VJLcnAAAALI"]
[Thu Jul 30 14:49:59.190746 2026] [security2:error] [pid 62112:tid 62300] [client 20.91.199.21:56560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/bootstrap.php"] [unique_id "amuq58Jgo6iBrIY9VJLcpwAAAL8"]
[Thu Jul 30 14:49:59.346629 2026] [security2:error] [pid 62112:tid 62353] [client 52.238.199.152:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/edit-form.php"] [unique_id "amuq58Jgo6iBrIY9VJLcqAAAAPQ"]
[Thu Jul 30 14:49:59.395812 2026] [security2:error] [pid 62112:tid 62282] [client 20.91.199.21:17866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuq58Jgo6iBrIY9VJLcrAAAAK0"]
[Thu Jul 30 14:49:59.407224 2026] [security2:error] [pid 62112:tid 62299] [client 20.52.125.110:10686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amuq58Jgo6iBrIY9VJLcrQAAAL4"]
[Thu Jul 30 14:49:59.754189 2026] [security2:error] [pid 62112:tid 62283] [client 172.213.232.128:45541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuq58Jgo6iBrIY9VJLctAAAAK4"]
[Thu Jul 30 14:49:59.997199 2026] [security2:error] [pid 62112:tid 62318] [client 20.52.125.110:10625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuq58Jgo6iBrIY9VJLcuwAAANE"]
[Thu Jul 30 14:50:00.262399 2026] [core:notice] [pid 62112:tid 62117] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:00.307932 2026] [security2:error] [pid 62112:tid 62336] [client 189.156.226.90:27665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq6MJgo6iBrIY9VJLcwAAAAOM"]
[Thu Jul 30 14:50:00.308084 2026] [security2:error] [pid 62112:tid 62336] [client 189.156.226.90:27665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq6MJgo6iBrIY9VJLcwAAAAOM"]
[Thu Jul 30 14:50:00.486069 2026] [security2:error] [pid 62112:tid 62248] [client 172.213.232.128:41934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuq6MJgo6iBrIY9VJLcxAAAAIs"]
[Thu Jul 30 14:50:00.569276 2026] [security2:error] [pid 62112:tid 62267] [client 20.52.125.110:10654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuq6MJgo6iBrIY9VJLcywAAAJ4"]
[Thu Jul 30 14:50:00.626298 2026] [security2:error] [pid 62112:tid 62339] [client 52.238.199.152:36486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/aleXus.php"] [unique_id "amuq6MJgo6iBrIY9VJLczwAAAOY"]
[Thu Jul 30 14:50:00.872886 2026] [security2:error] [pid 62112:tid 62290] [client 20.91.199.21:56538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/buy.php"] [unique_id "amuq6MJgo6iBrIY9VJLc0AAAALU"]
[Thu Jul 30 14:50:01.444325 2026] [security2:error] [pid 62112:tid 62349] [client 85.208.96.204:24706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/01/29/theatro-santa-roza-inscreve-para-turmas-on-line-de-bale-classico-e-danca-flamenca/"] [unique_id "amuq6cJgo6iBrIY9VJLc3wAAAPA"]
[Thu Jul 30 14:50:01.444447 2026] [security2:error] [pid 62112:tid 62349] [client 85.208.96.204:24706] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/01/29/theatro-santa-roza-inscreve-para-turmas-on-line-de-bale-classico-e-danca-flamenca/"] [unique_id "amuq6cJgo6iBrIY9VJLc3wAAAPA"]
[Thu Jul 30 14:50:01.449408 2026] [security2:error] [pid 62112:tid 62314] [client 20.52.125.110:4554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amuq6cJgo6iBrIY9VJLc4AAAAM0"]
[Thu Jul 30 14:50:01.496040 2026] [security2:error] [pid 62112:tid 62286] [client 172.213.232.128:40749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuq6cJgo6iBrIY9VJLc4wAAALE"]
[Thu Jul 30 14:50:01.554216 2026] [security2:error] [pid 62112:tid 62309] [client 20.91.199.21:53064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/chosen.php"] [unique_id "amuq6cJgo6iBrIY9VJLc5QAAAMg"]
[Thu Jul 30 14:50:01.673120 2026] [security2:error] [pid 62112:tid 62260] [client 52.238.199.152:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/user.php"] [unique_id "amuq6cJgo6iBrIY9VJLc7AAAAJc"]
[Thu Jul 30 14:50:01.715805 2026] [security2:error] [pid 62112:tid 62124] [remote 185.95.156.16:44062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.156.95.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amuq6cJgo6iBrIY9VJLc7QAA5Qs"]
[Thu Jul 30 14:50:02.352604 2026] [security2:error] [pid 62112:tid 62298] [client 20.91.199.21:52463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/class-wp-image.php"] [unique_id "amuq6sJgo6iBrIY9VJLc-AAAAL0"]
[Thu Jul 30 14:50:02.568178 2026] [security2:error] [pid 62112:tid 62340] [client 172.213.232.128:45521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuq6sJgo6iBrIY9VJLc-gAAAOc"]
[Thu Jul 30 14:50:02.576931 2026] [security2:error] [pid 62112:tid 62258] [client 20.52.125.110:5331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuq6sJgo6iBrIY9VJLc-wAAAJU"]
[Thu Jul 30 14:50:02.841756 2026] [security2:error] [pid 62112:tid 62324] [client 110.249.202.9:23504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amuq6sJgo6iBrIY9VJLdBQAAANc"]
[Thu Jul 30 14:50:03.134681 2026] [security2:error] [pid 62112:tid 62251] [client 52.238.199.152:58892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ab1ux1ft.php"] [unique_id "amuq68Jgo6iBrIY9VJLdCQAAAI4"]
[Thu Jul 30 14:50:03.325681 2026] [security2:error] [pid 62112:tid 62317] [client 20.91.199.21:49387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/classsmtps.php"] [unique_id "amuq68Jgo6iBrIY9VJLdEQAAANA"]
[Thu Jul 30 14:50:03.553185 2026] [security2:error] [pid 62112:tid 62268] [client 20.52.125.110:5343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amuq68Jgo6iBrIY9VJLdEgAAAJ8"]
[Thu Jul 30 14:50:03.628713 2026] [security2:error] [pid 62112:tid 62290] [client 172.213.232.128:24579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuq68Jgo6iBrIY9VJLdEwAAALU"]
[Thu Jul 30 14:50:03.967970 2026] [security2:error] [pid 62112:tid 62359] [client 68.67.112.88:30444] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuq68Jgo6iBrIY9VJLdHgAAAPo"]
[Thu Jul 30 14:50:04.158229 2026] [security2:error] [pid 62112:tid 62246] [client 20.91.199.21:36117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/classwithtostring.php"] [unique_id "amuq7MJgo6iBrIY9VJLdHwAAAIk"]
[Thu Jul 30 14:50:04.345355 2026] [security2:error] [pid 62112:tid 62353] [client 20.52.125.110:4563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amuq7MJgo6iBrIY9VJLdKAAAAPQ"]
[Thu Jul 30 14:50:04.423416 2026] [security2:error] [pid 62112:tid 62270] [client 177.6.106.101:56577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuq7MJgo6iBrIY9VJLdKgAAAKE"]
[Thu Jul 30 14:50:04.423584 2026] [security2:error] [pid 62112:tid 62270] [client 177.6.106.101:56577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuq7MJgo6iBrIY9VJLdKgAAAKE"]
[Thu Jul 30 14:50:04.621584 2026] [security2:error] [pid 62112:tid 62356] [client 20.91.199.21:4937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/content.php"] [unique_id "amuq7MJgo6iBrIY9VJLdKwAAAPc"]
[Thu Jul 30 14:50:04.780232 2026] [security2:error] [pid 62112:tid 62284] [client 172.213.232.128:41931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuq7MJgo6iBrIY9VJLdLwAAAK8"]
[Thu Jul 30 14:50:05.125763 2026] [security2:error] [pid 62112:tid 62323] [client 20.52.125.110:10662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuq7cJgo6iBrIY9VJLdNgAAANY"]
[Thu Jul 30 14:50:05.307299 2026] [core:notice] [pid 62112:tid 62143] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:05.498815 2026] [security2:error] [pid 62112:tid 62273] [client 20.91.199.21:19813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuq7cJgo6iBrIY9VJLdQgAAAKQ"]
[Thu Jul 30 14:50:05.650255 2026] [security2:error] [pid 62112:tid 62352] [client 20.91.199.21:49836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/config.php"] [unique_id "amuq7cJgo6iBrIY9VJLdRwAAAPM"]
[Thu Jul 30 14:50:05.712099 2026] [security2:error] [pid 62112:tid 62249] [client 172.213.232.128:44564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuq7cJgo6iBrIY9VJLdSAAAAIw"]
[Thu Jul 30 14:50:05.734804 2026] [security2:error] [pid 62112:tid 62333] [client 20.52.125.110:10650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lilyinspires.com"] [uri "/wp-config-sample.php"] [unique_id "amuq7cJgo6iBrIY9VJLdSQAAAOA"]
[Thu Jul 30 14:50:06.363115 2026] [security2:error] [pid 62112:tid 62361] [client 20.91.199.21:53071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/core.php"] [unique_id "amuq7sJgo6iBrIY9VJLdXAAAAPw"]
[Thu Jul 30 14:50:06.511474 2026] [security2:error] [pid 62112:tid 62243] [client 172.213.232.128:44590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuq7sJgo6iBrIY9VJLdYQAAAIY"]
[Thu Jul 30 14:50:06.939078 2026] [core:notice] [pid 62112:tid 62152] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:06.975312 2026] [security2:error] [pid 62112:tid 62329] [client 20.91.199.21:36113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/css.php"] [unique_id "amuq7sJgo6iBrIY9VJLdaQAAANw"]
[Thu Jul 30 14:50:07.193378 2026] [core:notice] [pid 62112:tid 62139] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:07.516687 2026] [security2:error] [pid 62112:tid 62178] [remote 57.141.0.66:56684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/PBB/article/view/7407/2963"] [unique_id "amuq78Jgo6iBrIY9VJLdbwAAs0E"]
[Thu Jul 30 14:50:07.519569 2026] [security2:error] [pid 62112:tid 62310] [client 20.91.199.21:4947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuq78Jgo6iBrIY9VJLdeQAAAMk"]
[Thu Jul 30 14:50:07.906939 2026] [security2:error] [pid 62112:tid 62313] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuq78Jgo6iBrIY9VJLdfQAAAMw"]
[Thu Jul 30 14:50:07.907055 2026] [security2:error] [pid 62112:tid 62313] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuq78Jgo6iBrIY9VJLdfQAAAMw"]
[Thu Jul 30 14:50:08.314085 2026] [security2:error] [pid 62112:tid 62250] [client 20.91.199.21:22621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuq8MJgo6iBrIY9VJLdiAAAAI0"]
[Thu Jul 30 14:50:08.418496 2026] [security2:error] [pid 62112:tid 62265] [client 20.91.199.21:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/database.php"] [unique_id "amuq8MJgo6iBrIY9VJLdjAAAAJw"]
[Thu Jul 30 14:50:08.505955 2026] [security2:error] [pid 62112:tid 62365] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuq8MJgo6iBrIY9VJLdjQAAAQA"]
[Thu Jul 30 14:50:08.506086 2026] [security2:error] [pid 62112:tid 62365] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuq8MJgo6iBrIY9VJLdjQAAAQA"]
[Thu Jul 30 14:50:08.555576 2026] [security2:error] [pid 62112:tid 62304] [client 172.213.232.128:40739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuq8MJgo6iBrIY9VJLdkQAAAMM"]
[Thu Jul 30 14:50:08.656900 2026] [security2:error] [pid 62112:tid 62326] [client 52.238.199.152:36539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/home/function.php"] [unique_id "amuq8MJgo6iBrIY9VJLdlQAAANk"]
[Thu Jul 30 14:50:09.128661 2026] [security2:error] [pid 62112:tid 62296] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/xstelth.php"] [unique_id "amuq8cJgo6iBrIY9VJLdnwAAALs"]
[Thu Jul 30 14:50:09.128833 2026] [security2:error] [pid 62112:tid 62296] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/xstelth.php"] [unique_id "amuq8cJgo6iBrIY9VJLdnwAAALs"]
[Thu Jul 30 14:50:09.285907 2026] [security2:error] [pid 62112:tid 62349] [client 20.91.199.21:3097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuq8cJgo6iBrIY9VJLdoQAAAPA"]
[Thu Jul 30 14:50:09.622388 2026] [security2:error] [pid 62112:tid 62286] [client 20.91.199.21:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/db.php"] [unique_id "amuq8cJgo6iBrIY9VJLdqgAAALE"]
[Thu Jul 30 14:50:09.724075 2026] [security2:error] [pid 62112:tid 62357] [client 172.213.232.128:40728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuq8cJgo6iBrIY9VJLdrgAAAPg"]
[Thu Jul 30 14:50:09.730991 2026] [security2:error] [pid 62112:tid 62281] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/584062352875874akp.php"] [unique_id "amuq8cJgo6iBrIY9VJLdrwAAAKw"]
[Thu Jul 30 14:50:09.731075 2026] [security2:error] [pid 62112:tid 62281] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/584062352875874akp.php"] [unique_id "amuq8cJgo6iBrIY9VJLdrwAAAKw"]
[Thu Jul 30 14:50:10.008938 2026] [security2:error] [pid 62112:tid 62260] [client 52.238.199.152:37018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-login.php"] [unique_id "amuq8cJgo6iBrIY9VJLdsAAAAJc"]
[Thu Jul 30 14:50:10.318597 2026] [security2:error] [pid 62112:tid 62253] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/newfile.php"] [unique_id "amuq8sJgo6iBrIY9VJLduwAAAJA"]
[Thu Jul 30 14:50:10.318690 2026] [security2:error] [pid 62112:tid 62253] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/newfile.php"] [unique_id "amuq8sJgo6iBrIY9VJLduwAAAJA"]
[Thu Jul 30 14:50:10.497040 2026] [security2:error] [pid 62112:tid 62368] [client 172.213.232.128:44554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuq8sJgo6iBrIY9VJLdwAAAAQM"]
[Thu Jul 30 14:50:10.849405 2026] [security2:error] [pid 62112:tid 62292] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/tBEZGQz.php"] [unique_id "amuq8sJgo6iBrIY9VJLdywAAALc"]
[Thu Jul 30 14:50:10.849564 2026] [security2:error] [pid 62112:tid 62292] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/tBEZGQz.php"] [unique_id "amuq8sJgo6iBrIY9VJLdywAAALc"]
[Thu Jul 30 14:50:10.899410 2026] [security2:error] [pid 62112:tid 62244] [client 189.156.226.90:26952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq8sJgo6iBrIY9VJLdzAAAAIc"]
[Thu Jul 30 14:50:10.899581 2026] [security2:error] [pid 62112:tid 62244] [client 189.156.226.90:26952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq8sJgo6iBrIY9VJLdzAAAAIc"]
[Thu Jul 30 14:50:11.356405 2026] [security2:error] [pid 62112:tid 62247] [client 20.91.199.21:36148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/default.php"] [unique_id "amuq88Jgo6iBrIY9VJLd1gAAAIo"]
[Thu Jul 30 14:50:11.402322 2026] [security2:error] [pid 62112:tid 62314] [client 172.202.95.21:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.koinjp189.com"] [uri "/phpinfo"] [unique_id "amuq88Jgo6iBrIY9VJLd1wAAAM0"]
[Thu Jul 30 14:50:11.402425 2026] [security2:error] [pid 62112:tid 62314] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.koinjp189.com"] [uri "/phpinfo"] [unique_id "amuq88Jgo6iBrIY9VJLd1wAAAM0"]
[Thu Jul 30 14:50:11.601364 2026] [security2:error] [pid 62112:tid 62304] [client 52.238.199.152:37027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "amuq88Jgo6iBrIY9VJLd3wAAAMM"]
[Thu Jul 30 14:50:11.747096 2026] [security2:error] [pid 62112:tid 62282] [client 14.182.157.11:38695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq88Jgo6iBrIY9VJLd2AAAAK0"], referer: http://pkf.jo
[Thu Jul 30 14:50:11.899993 2026] [security2:error] [pid 62112:tid 62359] [client 20.91.199.21:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/dropdown.php"] [unique_id "amuq88Jgo6iBrIY9VJLd4wAAAPo"]
[Thu Jul 30 14:50:11.971265 2026] [security2:error] [pid 62112:tid 62303] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/drykl.php"] [unique_id "amuq88Jgo6iBrIY9VJLd5QAAAMI"]
[Thu Jul 30 14:50:11.971396 2026] [security2:error] [pid 62112:tid 62303] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/drykl.php"] [unique_id "amuq88Jgo6iBrIY9VJLd5QAAAMI"]
[Thu Jul 30 14:50:11.985173 2026] [security2:error] [pid 62112:tid 62353] [client 172.213.232.128:42792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuq88Jgo6iBrIY9VJLd5gAAAPQ"]
[Thu Jul 30 14:50:12.220913 2026] [security2:error] [pid 62112:tid 62193] [remote 52.167.144.237:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jpa/article/download/1493/index_php/caiic"] [unique_id "amuq88Jgo6iBrIY9VJLd5AAAvFA"]
[Thu Jul 30 14:50:12.540362 2026] [security2:error] [pid 62112:tid 62354] [client 172.213.232.128:45506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuq9MJgo6iBrIY9VJLd8AAAAPU"]
[Thu Jul 30 14:50:12.562320 2026] [security2:error] [pid 62112:tid 62301] [client 172.202.95.21:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amuq9MJgo6iBrIY9VJLd8wAAAMA"]
[Thu Jul 30 14:50:12.562418 2026] [security2:error] [pid 62112:tid 62301] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amuq9MJgo6iBrIY9VJLd8wAAAMA"]
[Thu Jul 30 14:50:12.747957 2026] [security2:error] [pid 62112:tid 62350] [client 20.91.199.21:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/edit.php"] [unique_id "amuq9MJgo6iBrIY9VJLd-gAAAPE"]
[Thu Jul 30 14:50:12.859720 2026] [security2:error] [pid 62112:tid 62344] [client 14.234.131.56:53870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq9MJgo6iBrIY9VJLd9QAAAOs"], referer: http://pkf.jo
[Thu Jul 30 14:50:12.946346 2026] [security2:error] [pid 62112:tid 62258] [client 88.238.12.58:20354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq9MJgo6iBrIY9VJLd9gAAAJU"], referer: http://pkf.jo
[Thu Jul 30 14:50:13.019180 2026] [security2:error] [pid 62112:tid 62325] [client 52.238.199.152:36525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp.php"] [unique_id "amuq9cJgo6iBrIY9VJLd_gAAANg"]
[Thu Jul 30 14:50:13.383998 2026] [security2:error] [pid 62112:tid 62368] [client 172.213.232.128:24257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuq9cJgo6iBrIY9VJLeCAAAAQM"]
[Thu Jul 30 14:50:13.675089 2026] [security2:error] [pid 62112:tid 62264] [client 201.227.36.16:49008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq9cJgo6iBrIY9VJLeCQAAAJs"], referer: http://pkf.jo
[Thu Jul 30 14:50:13.697266 2026] [security2:error] [pid 62112:tid 62345] [client 73.167.3.156:45804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq9cJgo6iBrIY9VJLeCgAAAOw"], referer: http://pkf.jo
[Thu Jul 30 14:50:13.732514 2026] [security2:error] [pid 62112:tid 62263] [client 184.75.223.203:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuq9cJgo6iBrIY9VJLeEAAAAJo"]
[Thu Jul 30 14:50:13.732619 2026] [security2:error] [pid 62112:tid 62263] [client 184.75.223.203:47148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuq9cJgo6iBrIY9VJLeEAAAAJo"]
[Thu Jul 30 14:50:14.250733 2026] [security2:error] [pid 62112:tid 62277] [client 197.221.251.106:21248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq9cJgo6iBrIY9VJLeFgAAAKg"], referer: http://pkf.jo
[Thu Jul 30 14:50:14.310640 2026] [security2:error] [pid 62112:tid 62290] [client 52.238.199.152:37014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/Requests/library/about.php"] [unique_id "amuq9sJgo6iBrIY9VJLeIAAAALU"]
[Thu Jul 30 14:50:14.468728 2026] [security2:error] [pid 62112:tid 62302] [client 20.91.199.21:13648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuq9sJgo6iBrIY9VJLeIQAAAME"]
[Thu Jul 30 14:50:14.659425 2026] [security2:error] [pid 62112:tid 62351] [client 172.213.232.128:45563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuq9sJgo6iBrIY9VJLeJQAAAPI"]
[Thu Jul 30 14:50:14.946603 2026] [security2:error] [pid 62112:tid 62282] [client 169.224.68.131:57433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq9sJgo6iBrIY9VJLeJAAAAK0"], referer: http://pkf.jo
[Thu Jul 30 14:50:15.140050 2026] [security2:error] [pid 62112:tid 62358] [client 177.154.168.152:13340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq9sJgo6iBrIY9VJLeLQAAAPk"], referer: http://pkf.jo
[Thu Jul 30 14:50:15.215766 2026] [security2:error] [pid 62112:tid 62283] [client 20.91.199.21:3079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuq98Jgo6iBrIY9VJLeLwAAAK4"]
[Thu Jul 30 14:50:15.390743 2026] [security2:error] [pid 62112:tid 62366] [client 172.213.232.128:57212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuq98Jgo6iBrIY9VJLeOQAAAQE"]
[Thu Jul 30 14:50:15.448923 2026] [security2:error] [pid 62112:tid 62337] [client 52.238.199.152:58920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known/index.php"] [unique_id "amuq98Jgo6iBrIY9VJLeOgAAAOQ"]
[Thu Jul 30 14:50:15.702608 2026] [security2:error] [pid 62112:tid 62256] [client 177.6.106.101:57186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.106.6.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuq98Jgo6iBrIY9VJLeOwAAAJM"]
[Thu Jul 30 14:50:15.720859 2026] [security2:error] [pid 62112:tid 62256] [client 177.6.106.101:57186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.co.ke"] [uri "/xmlrpc.php"] [unique_id "amuq98Jgo6iBrIY9VJLeOwAAAJM"]
[Thu Jul 30 14:50:16.276145 2026] [security2:error] [pid 62112:tid 62321] [client 47.128.121.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuq-MJgo6iBrIY9VJLeSgAAANQ"]
[Thu Jul 30 14:50:16.300560 2026] [security2:error] [pid 62112:tid 62250] [client 52.238.199.152:37013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/asasx.php"] [unique_id "amuq-MJgo6iBrIY9VJLeUgAAAI0"]
[Thu Jul 30 14:50:16.327055 2026] [security2:error] [pid 62112:tid 62206] [remote 74.7.243.224:50322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/js/stafff.php"] [unique_id "amuq-MJgo6iBrIY9VJLeVQAApl0"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/js/bootstrap.bundle.min.js
[Thu Jul 30 14:50:16.357605 2026] [security2:error] [pid 62112:tid 62244] [client 20.91.199.21:54053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/f35.php"] [unique_id "amuq-MJgo6iBrIY9VJLeVgAAAIc"]
[Thu Jul 30 14:50:16.382038 2026] [security2:error] [pid 62112:tid 62368] [client 190.140.54.69:51590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq-MJgo6iBrIY9VJLeSwAAAQM"], referer: http://pkf.jo
[Thu Jul 30 14:50:16.472361 2026] [security2:error] [pid 62112:tid 62312] [client 20.91.199.21:15487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuq-MJgo6iBrIY9VJLeWwAAAMs"]
[Thu Jul 30 14:50:16.507448 2026] [security2:error] [pid 62112:tid 62271] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuq98Jgo6iBrIY9VJLeRwAAAKI"]
[Thu Jul 30 14:50:16.510890 2026] [security2:error] [pid 62112:tid 62229] [remote 216.73.216.51:55666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuq-MJgo6iBrIY9VJLeXQAAtnQ"]
[Thu Jul 30 14:50:16.542453 2026] [security2:error] [pid 62112:tid 62264] [client 190.189.165.247:59690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq-MJgo6iBrIY9VJLeTQAAAJs"], referer: http://pkf.jo
[Thu Jul 30 14:50:17.111440 2026] [security2:error] [pid 62112:tid 62364] [client 169.224.2.189:18133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq-MJgo6iBrIY9VJLeZAAAAP8"], referer: http://pkf.jo
[Thu Jul 30 14:50:17.321098 2026] [security2:error] [pid 62112:tid 62120] [remote 57.141.0.18:42174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuq-cJgo6iBrIY9VJLebgAAsQc"]
[Thu Jul 30 14:50:17.425896 2026] [security2:error] [pid 62112:tid 62329] [client 20.91.199.21:54043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.deltaedu.net"] [uri "/f7.php"] [unique_id "amuq-cJgo6iBrIY9VJLecgAAANw"]
[Thu Jul 30 14:50:17.938602 2026] [security2:error] [pid 62112:tid 62115] [remote 157.55.39.201:59914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/hc/en-us/articles/stafff.php"] [unique_id "amuq-cJgo6iBrIY9VJLefQAA2AI"]
[Thu Jul 30 14:50:18.274803 2026] [security2:error] [pid 62112:tid 62269] [client 82.102.23.139:40436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuq-sJgo6iBrIY9VJLegwAAAKA"]
[Thu Jul 30 14:50:18.274957 2026] [security2:error] [pid 62112:tid 62269] [client 82.102.23.139:40436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuq-sJgo6iBrIY9VJLegwAAAKA"]
[Thu Jul 30 14:50:18.278934 2026] [security2:error] [pid 62112:tid 62273] [client 41.92.109.63:36571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq-cJgo6iBrIY9VJLegQAAAKQ"], referer: http://pkf.jo
[Thu Jul 30 14:50:18.323510 2026] [security2:error] [pid 62112:tid 62363] [client 20.91.199.21:19794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuq-sJgo6iBrIY9VJLehwAAAP4"]
[Thu Jul 30 14:50:18.457603 2026] [security2:error] [pid 62112:tid 62318] [client 177.234.244.251:36347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq-sJgo6iBrIY9VJLehQAAANE"], referer: http://pkf.jo
[Thu Jul 30 14:50:18.479144 2026] [security2:error] [pid 62112:tid 62319] [client 45.183.187.226:10926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq-sJgo6iBrIY9VJLehgAAANI"], referer: http://pkf.jo
[Thu Jul 30 14:50:18.569844 2026] [security2:error] [pid 62112:tid 62315] [client 52.238.199.152:58942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/user/wp-login.php"] [unique_id "amuq-sJgo6iBrIY9VJLelAAAAM4"]
[Thu Jul 30 14:50:18.769061 2026] [security2:error] [pid 62112:tid 62300] [client 186.189.90.130:29256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq-sJgo6iBrIY9VJLekQAAAL8"], referer: http://pkf.jo
[Thu Jul 30 14:50:19.297515 2026] [security2:error] [pid 62112:tid 62259] [client 166.114.138.26:58302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq-sJgo6iBrIY9VJLelQAAAJY"], referer: http://pkf.jo
[Thu Jul 30 14:50:19.358360 2026] [security2:error] [pid 62112:tid 62252] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuq-sJgo6iBrIY9VJLejgAAjw0"]
[Thu Jul 30 14:50:19.506913 2026] [core:notice] [pid 62112:tid 62114] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:20.099868 2026] [core:notice] [pid 62112:tid 62285] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:21.067269 2026] [security2:error] [pid 62112:tid 62135] [remote 216.73.216.51:55666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuq_cJgo6iBrIY9VJLe0AAA2RY"]
[Thu Jul 30 14:50:21.443545 2026] [security2:error] [pid 62112:tid 62278] [client 189.156.226.90:27474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq_cJgo6iBrIY9VJLe1QAAAKk"]
[Thu Jul 30 14:50:21.443700 2026] [security2:error] [pid 62112:tid 62278] [client 189.156.226.90:27474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuq_cJgo6iBrIY9VJLe1QAAAKk"]
[Thu Jul 30 14:50:21.640937 2026] [core:notice] [pid 62112:tid 62296] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:21.727027 2026] [security2:error] [pid 62112:tid 62361] [client 78.190.98.147:45326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq_cJgo6iBrIY9VJLe1AAAAPw"], referer: http://pkf.jo
[Thu Jul 30 14:50:22.791604 2026] [security2:error] [pid 62112:tid 62306] [client 66.9.161.61:4654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuq_sJgo6iBrIY9VJLe7gAAxSQ"], referer: https://pkf.jo
[Thu Jul 30 14:50:23.240733 2026] [security2:error] [pid 62112:tid 62263] [client 185.177.72.69:38990] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "aded-rdc.org"] [uri "/"] [unique_id "amuq_8Jgo6iBrIY9VJLfBAAAAJo"]
[Thu Jul 30 14:50:23.533969 2026] [security2:error] [pid 62112:tid 62310] [client 172.237.109.114:38865] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuq_sJgo6iBrIY9VJLe-QAAAMk"]
[Thu Jul 30 14:50:23.843351 2026] [security2:error] [pid 62112:tid 62319] [client 109.105.209.12:50888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lilyinspires.com"] [uri "/index.php"] [unique_id "amuq_8Jgo6iBrIY9VJLfDwAA0gU"]
[Thu Jul 30 14:50:24.149601 2026] [security2:error] [pid 62112:tid 62312] [client 109.105.209.12:50888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lilyinspires.com"] [uri "/index.php"] [unique_id "amurAMJgo6iBrIY9VJLfEQAAyzs"]
[Thu Jul 30 14:50:24.963703 2026] [security2:error] [pid 62112:tid 62266] [client 43.161.234.148:58844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.234.161.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amurAMJgo6iBrIY9VJLfJwAAAJ0"]
[Thu Jul 30 14:50:25.082458 2026] [security2:error] [pid 62112:tid 62355] [client 185.177.72.69:39144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurAcJgo6iBrIY9VJLfKQAAAPY"]
[Thu Jul 30 14:50:25.338098 2026] [security2:error] [pid 62112:tid 62354] [client 52.238.199.152:36505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "amurAcJgo6iBrIY9VJLfNQAAAPU"]
[Thu Jul 30 14:50:25.338140 2026] [security2:error] [pid 62112:tid 62298] [client 185.177.72.69:39170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amurAcJgo6iBrIY9VJLfNgAAAL0"]
[Thu Jul 30 14:50:25.352064 2026] [security2:error] [pid 62112:tid 62283] [client 20.91.199.21:19799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amurAcJgo6iBrIY9VJLfNwAAAK4"]
[Thu Jul 30 14:50:25.603816 2026] [security2:error] [pid 62112:tid 62362] [client 185.177.72.69:39192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurAcJgo6iBrIY9VJLfOQAAAP0"]
[Thu Jul 30 14:50:25.858877 2026] [security2:error] [pid 62112:tid 62263] [client 185.177.72.69:39228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurAcJgo6iBrIY9VJLfQwAAAJo"]
[Thu Jul 30 14:50:26.107381 2026] [security2:error] [pid 62112:tid 62341] [client 185.177.72.69:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurAsJgo6iBrIY9VJLfRAAAAOg"]
[Thu Jul 30 14:50:26.154871 2026] [security2:error] [pid 62112:tid 62248] [client 20.91.199.21:15456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amurAsJgo6iBrIY9VJLfSAAAAIs"]
[Thu Jul 30 14:50:26.344669 2026] [security2:error] [pid 62112:tid 62363] [client 52.238.199.152:36521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/radio.php"] [unique_id "amurAsJgo6iBrIY9VJLfTwAAAP4"]
[Thu Jul 30 14:50:26.359864 2026] [security2:error] [pid 62112:tid 62324] [client 185.177.72.69:39284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurAsJgo6iBrIY9VJLfUAAAANc"]
[Thu Jul 30 14:50:26.612268 2026] [security2:error] [pid 62112:tid 62279] [client 172.213.232.128:45269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amurAsJgo6iBrIY9VJLfUgAAAKo"]
[Thu Jul 30 14:50:26.728437 2026] [security2:error] [pid 62112:tid 62157] [remote 216.73.216.51:35692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amurAsJgo6iBrIY9VJLfWQAAqCw"]
[Thu Jul 30 14:50:27.035634 2026] [security2:error] [pid 62112:tid 62342] [client 91.218.183.52:59792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurAsJgo6iBrIY9VJLfVQAAAOk"]
[Thu Jul 30 14:50:27.658206 2026] [security2:error] [pid 62112:tid 62338] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/ls.php"] [unique_id "amurA8Jgo6iBrIY9VJLfbQAAAOU"]
[Thu Jul 30 14:50:27.658355 2026] [security2:error] [pid 62112:tid 62338] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/ls.php"] [unique_id "amurA8Jgo6iBrIY9VJLfbQAAAOU"]
[Thu Jul 30 14:50:27.805691 2026] [security2:error] [pid 62112:tid 62351] [client 172.213.232.128:42185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nordeste1.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amurA8Jgo6iBrIY9VJLfbAAAAPI"]
[Thu Jul 30 14:50:27.851222 2026] [security2:error] [pid 62112:tid 62259] [client 52.238.199.152:58884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amurA8Jgo6iBrIY9VJLfdQAAAJY"]
[Thu Jul 30 14:50:28.037860 2026] [core:notice] [pid 62112:tid 62358] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:28.053039 2026] [security2:error] [pid 62112:tid 62357] [client 94.47.157.212:15796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurA8Jgo6iBrIY9VJLfbgAAAPg"], referer: http://pkf.jo
[Thu Jul 30 14:50:28.190742 2026] [security2:error] [pid 62112:tid 62285] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/dx.php"] [unique_id "amurBMJgo6iBrIY9VJLfewAAALA"]
[Thu Jul 30 14:50:28.190886 2026] [security2:error] [pid 62112:tid 62285] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/dx.php"] [unique_id "amurBMJgo6iBrIY9VJLfewAAALA"]
[Thu Jul 30 14:50:28.454963 2026] [security2:error] [pid 62112:tid 62343] [client 172.237.109.114:1510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurA8Jgo6iBrIY9VJLfeQAAAOo"]
[Thu Jul 30 14:50:29.207397 2026] [security2:error] [pid 62112:tid 62247] [client 178.130.145.210:45674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurBMJgo6iBrIY9VJLfkAAAAIo"], referer: http://pkf.jo
[Thu Jul 30 14:50:29.211777 2026] [security2:error] [pid 62112:tid 62269] [client 52.238.199.152:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/st.php"] [unique_id "amurBcJgo6iBrIY9VJLflwAAAKA"]
[Thu Jul 30 14:50:29.518677 2026] [security2:error] [pid 62112:tid 62270] [client 45.70.144.152:23502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurBcJgo6iBrIY9VJLfmAAAAKE"], referer: http://pkf.jo
[Thu Jul 30 14:50:29.573873 2026] [security2:error] [pid 62112:tid 62272] [client 169.224.17.122:53612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurBcJgo6iBrIY9VJLfmQAAAKM"], referer: http://pkf.jo
[Thu Jul 30 14:50:29.983196 2026] [security2:error] [pid 62112:tid 62361] [client 154.72.118.28:40394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurBcJgo6iBrIY9VJLfowAAAPw"], referer: http://pkf.jo
[Thu Jul 30 14:50:30.379512 2026] [security2:error] [pid 62112:tid 62266] [client 52.238.199.152:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/about.php"] [unique_id "amurBsJgo6iBrIY9VJLftwAAAJ0"]
[Thu Jul 30 14:50:30.406729 2026] [security2:error] [pid 62112:tid 62356] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/mac.php"] [unique_id "amurBsJgo6iBrIY9VJLfuAAAAPc"]
[Thu Jul 30 14:50:30.406827 2026] [security2:error] [pid 62112:tid 62356] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/mac.php"] [unique_id "amurBsJgo6iBrIY9VJLfuAAAAPc"]
[Thu Jul 30 14:50:30.437372 2026] [security2:error] [pid 62112:tid 62310] [client 212.154.72.111:8250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurBsJgo6iBrIY9VJLfsAAAAMk"], referer: http://pkf.jo
[Thu Jul 30 14:50:30.643029 2026] [security2:error] [pid 62112:tid 62289] [client 102.66.147.47:36520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurBsJgo6iBrIY9VJLftAAAtFM"], referer: https://pkf.jo
[Thu Jul 30 14:50:30.685407 2026] [security2:error] [pid 62112:tid 62245] [client 141.94.94.103:36964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurBsJgo6iBrIY9VJLftgAAAIg"]
[Thu Jul 30 14:50:30.762064 2026] [security2:error] [pid 62112:tid 62264] [client 20.91.199.21:16281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/banners/about.php"] [unique_id "amurBsJgo6iBrIY9VJLfwAAAAJs"]
[Thu Jul 30 14:50:30.958539 2026] [core:error] [pid 62112:tid 62208] [remote 74.7.244.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:50:30.958571 2026] [core:error] [pid 62112:tid 62208] [remote 74.7.244.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:50:30.958750 2026] [security2:error] [pid 62112:tid 62267] [client 74.7.244.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.massageandspaislamabad.rest"] [uri "/index.php"] [unique_id "amurBsJgo6iBrIY9VJLfxwAAnl8"]
[Thu Jul 30 14:50:30.987423 2026] [security2:error] [pid 62112:tid 62346] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/485.php"] [unique_id "amurBsJgo6iBrIY9VJLfyQAAAO0"]
[Thu Jul 30 14:50:30.987577 2026] [security2:error] [pid 62112:tid 62346] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/485.php"] [unique_id "amurBsJgo6iBrIY9VJLfyQAAAO0"]
[Thu Jul 30 14:50:31.350693 2026] [security2:error] [pid 62112:tid 62347] [client 194.59.29.219:7640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurB8Jgo6iBrIY9VJLfygAAAO4"], referer: http://pkf.jo
[Thu Jul 30 14:50:31.499856 2026] [security2:error] [pid 62112:tid 62306] [client 52.238.199.152:37427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/admin.php"] [unique_id "amurB8Jgo6iBrIY9VJLf1gAAAMU"]
[Thu Jul 30 14:50:31.521115 2026] [security2:error] [pid 62112:tid 62268] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/gelio1.php"] [unique_id "amurB8Jgo6iBrIY9VJLf2AAAAJ8"]
[Thu Jul 30 14:50:31.521250 2026] [security2:error] [pid 62112:tid 62268] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/gelio1.php"] [unique_id "amurB8Jgo6iBrIY9VJLf2AAAAJ8"]
[Thu Jul 30 14:50:31.624821 2026] [security2:error] [pid 62112:tid 62368] [client 20.91.199.21:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/about.php"] [unique_id "amurB8Jgo6iBrIY9VJLf2wAAAQM"]
[Thu Jul 30 14:50:31.873120 2026] [security2:error] [pid 62112:tid 62279] [client 195.155.169.224:8000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurB8Jgo6iBrIY9VJLf2QAAAKo"], referer: http://pkf.jo
[Thu Jul 30 14:50:31.983797 2026] [security2:error] [pid 62112:tid 62320] [client 189.156.226.90:27667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurB8Jgo6iBrIY9VJLf5AAAANM"]
[Thu Jul 30 14:50:31.983943 2026] [security2:error] [pid 62112:tid 62320] [client 189.156.226.90:27667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurB8Jgo6iBrIY9VJLf5AAAANM"]
[Thu Jul 30 14:50:32.051019 2026] [security2:error] [pid 62112:tid 62299] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/lp6.php"] [unique_id "amurCMJgo6iBrIY9VJLf6AAAAL4"]
[Thu Jul 30 14:50:32.051152 2026] [security2:error] [pid 62112:tid 62299] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/lp6.php"] [unique_id "amurCMJgo6iBrIY9VJLf6AAAAL4"]
[Thu Jul 30 14:50:32.444455 2026] [security2:error] [pid 62112:tid 62330] [client 172.237.109.114:52140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurB8Jgo6iBrIY9VJLf4QAAAN0"]
[Thu Jul 30 14:50:32.452431 2026] [core:notice] [pid 62112:tid 62191] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:32.564231 2026] [security2:error] [pid 62112:tid 62334] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amurCMJgo6iBrIY9VJLf9AAAAOE"]
[Thu Jul 30 14:50:32.564351 2026] [security2:error] [pid 62112:tid 62334] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "amurCMJgo6iBrIY9VJLf9AAAAOE"]
[Thu Jul 30 14:50:32.682593 2026] [security2:error] [pid 62112:tid 62278] [client 172.237.109.114:63032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurCMJgo6iBrIY9VJLf6gAAAKk"]
[Thu Jul 30 14:50:32.721609 2026] [security2:error] [pid 62112:tid 62206] [remote 57.141.0.51:36698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3293993679/feed/rss2/"] [unique_id "amurCMJgo6iBrIY9VJLf-QAAk10"]
[Thu Jul 30 14:50:32.838815 2026] [core:notice] [pid 62112:tid 62348] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:33.132670 2026] [security2:error] [pid 62112:tid 62309] [client 20.91.199.21:4990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/about.php"] [unique_id "amurCcJgo6iBrIY9VJLgAwAAAMg"]
[Thu Jul 30 14:50:33.137499 2026] [security2:error] [pid 62112:tid 62302] [client 172.202.95.21:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amurCcJgo6iBrIY9VJLgBAAAAME"]
[Thu Jul 30 14:50:33.137579 2026] [security2:error] [pid 62112:tid 62302] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "amurCcJgo6iBrIY9VJLgBAAAAME"]
[Thu Jul 30 14:50:33.148586 2026] [core:notice] [pid 62112:tid 62229] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:33.237497 2026] [security2:error] [pid 62112:tid 62289] [client 213.152.161.249:37172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amurCMJgo6iBrIY9VJLf_AAAALQ"]
[Thu Jul 30 14:50:33.237620 2026] [security2:error] [pid 62112:tid 62289] [client 213.152.161.249:37172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amurCMJgo6iBrIY9VJLf_AAAALQ"]
[Thu Jul 30 14:50:33.742690 2026] [security2:error] [pid 62112:tid 62333] [client 52.238.199.152:37424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/css/admin.php"] [unique_id "amurCcJgo6iBrIY9VJLgEQAAAOA"]
[Thu Jul 30 14:50:33.763078 2026] [security2:error] [pid 62112:tid 62319] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/w3llscc.php"] [unique_id "amurCcJgo6iBrIY9VJLgFAAAANI"]
[Thu Jul 30 14:50:33.763161 2026] [security2:error] [pid 62112:tid 62319] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/w3llscc.php"] [unique_id "amurCcJgo6iBrIY9VJLgFAAAANI"]
[Thu Jul 30 14:50:33.925821 2026] [core:notice] [pid 62112:tid 62222] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:33.926195 2026] [security2:error] [pid 62112:tid 62341] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurCcJgo6iBrIY9VJLgCgAA6Gg"]
[Thu Jul 30 14:50:34.016507 2026] [security2:error] [pid 62112:tid 62326] [client 20.91.199.21:59960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amurCsJgo6iBrIY9VJLgGAAAANk"]
[Thu Jul 30 14:50:34.313855 2026] [security2:error] [pid 62112:tid 62360] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/miru3.php"] [unique_id "amurCsJgo6iBrIY9VJLgIwAAAPs"]
[Thu Jul 30 14:50:34.313958 2026] [security2:error] [pid 62112:tid 62360] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/miru3.php"] [unique_id "amurCsJgo6iBrIY9VJLgIwAAAPs"]
[Thu Jul 30 14:50:34.871775 2026] [security2:error] [pid 62112:tid 62353] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/autoload_classmap.php"] [unique_id "amurCsJgo6iBrIY9VJLgLQAAAPQ"]
[Thu Jul 30 14:50:34.871853 2026] [security2:error] [pid 62112:tid 62353] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/autoload_classmap.php"] [unique_id "amurCsJgo6iBrIY9VJLgLQAAAPQ"]
[Thu Jul 30 14:50:35.442092 2026] [security2:error] [pid 62112:tid 62256] [client 172.202.95.21:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-content/"] [unique_id "amurC8Jgo6iBrIY9VJLgOAAAAJM"]
[Thu Jul 30 14:50:35.442236 2026] [security2:error] [pid 62112:tid 62256] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-content/"] [unique_id "amurC8Jgo6iBrIY9VJLgOAAAAJM"]
[Thu Jul 30 14:50:35.820238 2026] [security2:error] [pid 62112:tid 62350] [client 52.238.199.152:37407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amurC8Jgo6iBrIY9VJLgRAAAAPE"]
[Thu Jul 30 14:50:35.945100 2026] [security2:error] [pid 62112:tid 62311] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-content/themes/index.php"] [unique_id "amurC8Jgo6iBrIY9VJLgSQAAAMo"]
[Thu Jul 30 14:50:35.945188 2026] [security2:error] [pid 62112:tid 62311] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-content/themes/index.php"] [unique_id "amurC8Jgo6iBrIY9VJLgSQAAAMo"]
[Thu Jul 30 14:50:36.009038 2026] [security2:error] [pid 62112:tid 62343] [client 82.102.23.139:55184] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amurDMJgo6iBrIY9VJLgSgAAAOo"]
[Thu Jul 30 14:50:36.009155 2026] [security2:error] [pid 62112:tid 62343] [client 82.102.23.139:55184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amurDMJgo6iBrIY9VJLgSgAAAOo"]
[Thu Jul 30 14:50:36.477829 2026] [security2:error] [pid 62112:tid 62277] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/av.php"] [unique_id "amurDMJgo6iBrIY9VJLgWwAAAKg"]
[Thu Jul 30 14:50:36.477929 2026] [security2:error] [pid 62112:tid 62277] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/av.php"] [unique_id "amurDMJgo6iBrIY9VJLgWwAAAKg"]
[Thu Jul 30 14:50:36.646611 2026] [security2:error] [pid 62112:tid 62314] [client 49.228.48.152:59462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurDMJgo6iBrIY9VJLgVAAAAM0"], referer: http://pkf.jo
[Thu Jul 30 14:50:36.800818 2026] [security2:error] [pid 62112:tid 62325] [client 52.238.199.152:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp2.php"] [unique_id "amurDMJgo6iBrIY9VJLgYAAAANg"]
[Thu Jul 30 14:50:36.811792 2026] [security2:error] [pid 62112:tid 62294] [client 2a03:2880:f800:a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurDMJgo6iBrIY9VJLgUwAAuU8"]
[Thu Jul 30 14:50:37.067000 2026] [security2:error] [pid 62112:tid 62327] [client 172.202.95.21:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-includes/l10n/"] [unique_id "amurDcJgo6iBrIY9VJLgaQAAANo"]
[Thu Jul 30 14:50:37.067118 2026] [security2:error] [pid 62112:tid 62327] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-includes/l10n/"] [unique_id "amurDcJgo6iBrIY9VJLgaQAAANo"]
[Thu Jul 30 14:50:37.117131 2026] [security2:error] [pid 62112:tid 62270] [client 148.222.205.234:30437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurDMJgo6iBrIY9VJLgYQAAAKE"], referer: http://pkf.jo
[Thu Jul 30 14:50:37.496987 2026] [security2:error] [pid 62112:tid 62308] [client 172.237.109.114:64922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurDcJgo6iBrIY9VJLgaAAAAMc"]
[Thu Jul 30 14:50:37.618431 2026] [security2:error] [pid 62112:tid 62310] [client 172.202.95.21:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.koinjp189.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amurDcJgo6iBrIY9VJLgdgAAAMk"]
[Thu Jul 30 14:50:37.618539 2026] [security2:error] [pid 62112:tid 62310] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.koinjp189.com"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amurDcJgo6iBrIY9VJLgdgAAAMk"]
[Thu Jul 30 14:50:38.167945 2026] [security2:error] [pid 62112:tid 62302] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/tiny.php"] [unique_id "amurDsJgo6iBrIY9VJLggQAAAME"]
[Thu Jul 30 14:50:38.168069 2026] [security2:error] [pid 62112:tid 62302] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/tiny.php"] [unique_id "amurDsJgo6iBrIY9VJLggQAAAME"]
[Thu Jul 30 14:50:38.762280 2026] [security2:error] [pid 62112:tid 62319] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amurDsJgo6iBrIY9VJLgkwAAANI"]
[Thu Jul 30 14:50:38.762382 2026] [security2:error] [pid 62112:tid 62319] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amurDsJgo6iBrIY9VJLgkwAAANI"]
[Thu Jul 30 14:50:39.143503 2026] [security2:error] [pid 62112:tid 62342] [client 20.91.199.21:59935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amurD8Jgo6iBrIY9VJLgowAAAOk"]
[Thu Jul 30 14:50:39.171266 2026] [core:notice] [pid 62112:tid 62152] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:39.179660 2026] [security2:error] [pid 62112:tid 62268] [client 142.147.193.84:26106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/ikea/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/09/ikea_collection_sittning_set-de-table_3.jpg"] [unique_id "amurDsJgo6iBrIY9VJLgmgAAnyc"], referer: https://carnetdeshopping.com/index.php/tag/ikea/
[Thu Jul 30 14:50:39.377048 2026] [security2:error] [pid 62112:tid 62322] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/zrrhj.php"] [unique_id "amurD8Jgo6iBrIY9VJLgqAAAANU"]
[Thu Jul 30 14:50:39.377174 2026] [security2:error] [pid 62112:tid 62322] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/zrrhj.php"] [unique_id "amurD8Jgo6iBrIY9VJLgqAAAANU"]
[Thu Jul 30 14:50:39.570862 2026] [security2:error] [pid 62112:tid 62345] [client 51.120.83.160:17431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amurD8Jgo6iBrIY9VJLgpAAAAOw"]
[Thu Jul 30 14:50:39.570969 2026] [security2:error] [pid 62112:tid 62345] [client 51.120.83.160:17431] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amurD8Jgo6iBrIY9VJLgpAAAAOw"]
[Thu Jul 30 14:50:39.822770 2026] [security2:error] [pid 62112:tid 62359] [client 20.91.199.21:18134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/img/about.php"] [unique_id "amurD8Jgo6iBrIY9VJLgsgAAAPo"]
[Thu Jul 30 14:50:39.993374 2026] [security2:error] [pid 62112:tid 62283] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amurD8Jgo6iBrIY9VJLgtwAAAK4"]
[Thu Jul 30 14:50:39.993477 2026] [security2:error] [pid 62112:tid 62283] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amurD8Jgo6iBrIY9VJLgtwAAAK4"]
[Thu Jul 30 14:50:40.553742 2026] [security2:error] [pid 62112:tid 62347] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wpgum.php"] [unique_id "amurEMJgo6iBrIY9VJLgyQAAAO4"]
[Thu Jul 30 14:50:40.553840 2026] [security2:error] [pid 62112:tid 62347] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wpgum.php"] [unique_id "amurEMJgo6iBrIY9VJLgyQAAAO4"]
[Thu Jul 30 14:50:40.599061 2026] [security2:error] [pid 62112:tid 62311] [client 51.120.83.160:43482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amurEMJgo6iBrIY9VJLgywAAAMo"]
[Thu Jul 30 14:50:40.599175 2026] [security2:error] [pid 62112:tid 62311] [client 51.120.83.160:43482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amurEMJgo6iBrIY9VJLgywAAAMo"]
[Thu Jul 30 14:50:40.879072 2026] [security2:error] [pid 62112:tid 62316] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amurEMJgo6iBrIY9VJLgzgAAAM8"]
[Thu Jul 30 14:50:40.936780 2026] [security2:error] [pid 62112:tid 62297] [client 20.91.199.21:45686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/languages/about.php"] [unique_id "amurEMJgo6iBrIY9VJLg1QAAALw"]
[Thu Jul 30 14:50:41.078023 2026] [security2:error] [pid 62112:tid 62148] [remote 216.73.216.51:35692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amurEcJgo6iBrIY9VJLg2QAAqiM"]
[Thu Jul 30 14:50:41.150310 2026] [security2:error] [pid 62112:tid 62360] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/ywwbf.php"] [unique_id "amurEcJgo6iBrIY9VJLg3wAAAPs"]
[Thu Jul 30 14:50:41.150416 2026] [security2:error] [pid 62112:tid 62360] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/ywwbf.php"] [unique_id "amurEcJgo6iBrIY9VJLg3wAAAPs"]
[Thu Jul 30 14:50:41.256444 2026] [security2:error] [pid 62112:tid 62300] [client 51.120.83.160:14038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/images/pearl/index.php"] [unique_id "amurEcJgo6iBrIY9VJLg4QAAAL8"]
[Thu Jul 30 14:50:41.256565 2026] [security2:error] [pid 62112:tid 62300] [client 51.120.83.160:14038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/images/pearl/index.php"] [unique_id "amurEcJgo6iBrIY9VJLg4QAAAL8"]
[Thu Jul 30 14:50:41.736780 2026] [security2:error] [pid 62112:tid 62256] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/xoldj.php"] [unique_id "amurEcJgo6iBrIY9VJLg7gAAAJM"]
[Thu Jul 30 14:50:41.736918 2026] [security2:error] [pid 62112:tid 62256] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/xoldj.php"] [unique_id "amurEcJgo6iBrIY9VJLg7gAAAJM"]
[Thu Jul 30 14:50:41.786447 2026] [security2:error] [pid 62112:tid 62345] [client 20.91.199.21:45693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amurEcJgo6iBrIY9VJLg7wAAAOw"]
[Thu Jul 30 14:50:41.898632 2026] [core:notice] [pid 62112:tid 62350] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:41.911711 2026] [core:notice] [pid 62112:tid 62249] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:42.276017 2026] [core:notice] [pid 62112:tid 62266] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:42.365371 2026] [core:notice] [pid 62112:tid 62155] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:42.370302 2026] [security2:error] [pid 62112:tid 62283] [client 103.108.97.219:57438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/ikea/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/09/ikea_collection_sittning_plateaux.jpg"] [unique_id "amurEsJgo6iBrIY9VJLg9gAArio"], referer: https://carnetdeshopping.com/index.php/tag/ikea/
[Thu Jul 30 14:50:42.387072 2026] [security2:error] [pid 62112:tid 62347] [client 51.120.83.160:14051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/bypass.php"] [unique_id "amurEsJgo6iBrIY9VJLg_wAAAO4"]
[Thu Jul 30 14:50:42.387168 2026] [security2:error] [pid 62112:tid 62347] [client 51.120.83.160:14051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/bypass.php"] [unique_id "amurEsJgo6iBrIY9VJLg_wAAAO4"]
[Thu Jul 30 14:50:42.438334 2026] [security2:error] [pid 62112:tid 62251] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/f35.php"] [unique_id "amurEsJgo6iBrIY9VJLhAAAAAI4"]
[Thu Jul 30 14:50:42.438476 2026] [security2:error] [pid 62112:tid 62251] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/f35.php"] [unique_id "amurEsJgo6iBrIY9VJLhAAAAAI4"]
[Thu Jul 30 14:50:42.582037 2026] [security2:error] [pid 62112:tid 62244] [client 189.156.226.90:26753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurEsJgo6iBrIY9VJLhBAAAAIc"]
[Thu Jul 30 14:50:42.582170 2026] [security2:error] [pid 62112:tid 62244] [client 189.156.226.90:26753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurEsJgo6iBrIY9VJLhBAAAAIc"]
[Thu Jul 30 14:50:42.656896 2026] [security2:error] [pid 62112:tid 62267] [client 185.187.207.71:6682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurEsJgo6iBrIY9VJLg_gAAAJ4"], referer: http://pkf.jo
[Thu Jul 30 14:50:42.754762 2026] [security2:error] [pid 62112:tid 62357] [client 112.86.225.252:57264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/canada-goose-down-jacket-2/"] [unique_id "amurEsJgo6iBrIY9VJLhCwAAAPg"]
[Thu Jul 30 14:50:42.754933 2026] [security2:error] [pid 62112:tid 62357] [client 112.86.225.252:57264] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/canada-goose-down-jacket-2/"] [unique_id "amurEsJgo6iBrIY9VJLhCwAAAPg"]
[Thu Jul 30 14:50:42.877852 2026] [security2:error] [pid 62112:tid 62273] [client 20.91.199.21:45663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amurEsJgo6iBrIY9VJLhFAAAAKQ"]
[Thu Jul 30 14:50:42.953447 2026] [core:notice] [pid 62112:tid 62213] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:42.985912 2026] [core:notice] [pid 62112:tid 62203] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:43.030343 2026] [security2:error] [pid 62112:tid 62287] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/gk.php"] [unique_id "amurE8Jgo6iBrIY9VJLhGwAAALI"]
[Thu Jul 30 14:50:43.030427 2026] [security2:error] [pid 62112:tid 62287] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/gk.php"] [unique_id "amurE8Jgo6iBrIY9VJLhGwAAALI"]
[Thu Jul 30 14:50:43.293101 2026] [security2:error] [pid 62112:tid 62254] [client 14.191.32.162:11764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurEsJgo6iBrIY9VJLhGgAAAJE"], referer: http://pkf.jo
[Thu Jul 30 14:50:43.384844 2026] [core:notice] [pid 62112:tid 62204] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:43.565816 2026] [core:notice] [pid 62112:tid 62234] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:43.568664 2026] [security2:error] [pid 62112:tid 62288] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/584062352875874akp.php"] [unique_id "amurE8Jgo6iBrIY9VJLhKQAAALM"]
[Thu Jul 30 14:50:43.568758 2026] [security2:error] [pid 62112:tid 62288] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/584062352875874akp.php"] [unique_id "amurE8Jgo6iBrIY9VJLhKQAAALM"]
[Thu Jul 30 14:50:43.661950 2026] [security2:error] [pid 62112:tid 62226] [remote 57.141.0.63:46274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amurE8Jgo6iBrIY9VJLhLQAAzXE"]
[Thu Jul 30 14:50:43.878672 2026] [security2:error] [pid 62112:tid 62257] [client 5.44.168.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uat.alseermarine.com"] [uri "/index.php"] [unique_id "amurE8Jgo6iBrIY9VJLhJgAAAJQ"]
[Thu Jul 30 14:50:44.188765 2026] [security2:error] [pid 62112:tid 62365] [client 39.194.5.97:23032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurE8Jgo6iBrIY9VJLhNQAAAQA"], referer: http://pkf.jo
[Thu Jul 30 14:50:44.194270 2026] [security2:error] [pid 62112:tid 62328] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wper3.php"] [unique_id "amurFMJgo6iBrIY9VJLhQAAAANs"]
[Thu Jul 30 14:50:44.194394 2026] [security2:error] [pid 62112:tid 62328] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wper3.php"] [unique_id "amurFMJgo6iBrIY9VJLhQAAAANs"]
[Thu Jul 30 14:50:44.669560 2026] [security2:error] [pid 62112:tid 62268] [client 136.53.40.28:42431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurFMJgo6iBrIY9VJLhRAAAAJ8"], referer: http://pkf.jo
[Thu Jul 30 14:50:44.731739 2026] [security2:error] [pid 62112:tid 62334] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/bthil.php"] [unique_id "amurFMJgo6iBrIY9VJLhVAAAAOE"]
[Thu Jul 30 14:50:44.731858 2026] [security2:error] [pid 62112:tid 62334] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/bthil.php"] [unique_id "amurFMJgo6iBrIY9VJLhVAAAAOE"]
[Thu Jul 30 14:50:44.822252 2026] [security2:error] [pid 62112:tid 62359] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurFMJgo6iBrIY9VJLhPAAA-lk"]
[Thu Jul 30 14:50:45.023622 2026] [security2:error] [pid 62112:tid 62243] [client 51.120.83.160:14068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/wp-admin/about.php"] [unique_id "amurFcJgo6iBrIY9VJLhXAAAAIY"]
[Thu Jul 30 14:50:45.023735 2026] [security2:error] [pid 62112:tid 62243] [client 51.120.83.160:14068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/wp-admin/about.php"] [unique_id "amurFcJgo6iBrIY9VJLhXAAAAIY"]
[Thu Jul 30 14:50:45.141777 2026] [security2:error] [pid 62112:tid 62345] [client 181.42.131.157:25156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurFMJgo6iBrIY9VJLhWQAAAOw"], referer: http://pkf.jo
[Thu Jul 30 14:50:45.151415 2026] [security2:error] [pid 62112:tid 62260] [client 37.61.126.7:2595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurFMJgo6iBrIY9VJLhWgAAAJc"], referer: http://pkf.jo
[Thu Jul 30 14:50:45.276197 2026] [security2:error] [pid 62112:tid 62257] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wyzer1.php"] [unique_id "amurFcJgo6iBrIY9VJLhXQAAAJQ"]
[Thu Jul 30 14:50:45.276296 2026] [security2:error] [pid 62112:tid 62257] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wyzer1.php"] [unique_id "amurFcJgo6iBrIY9VJLhXQAAAJQ"]
[Thu Jul 30 14:50:45.662221 2026] [security2:error] [pid 62112:tid 62350] [client 51.120.83.160:17451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/12.php"] [unique_id "amurFcJgo6iBrIY9VJLhZAAAAPE"]
[Thu Jul 30 14:50:45.662332 2026] [security2:error] [pid 62112:tid 62350] [client 51.120.83.160:17451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/12.php"] [unique_id "amurFcJgo6iBrIY9VJLhZAAAAPE"]
[Thu Jul 30 14:50:45.790571 2026] [security2:error] [pid 62112:tid 62351] [client 52.238.199.152:37415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/s.php"] [unique_id "amurFcJgo6iBrIY9VJLhZQAAAPI"]
[Thu Jul 30 14:50:45.895066 2026] [security2:error] [pid 62112:tid 62362] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/mh.php"] [unique_id "amurFcJgo6iBrIY9VJLhaQAAAP0"]
[Thu Jul 30 14:50:45.895176 2026] [security2:error] [pid 62112:tid 62362] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/mh.php"] [unique_id "amurFcJgo6iBrIY9VJLhaQAAAP0"]
[Thu Jul 30 14:50:46.198761 2026] [security2:error] [pid 62112:tid 62310] [client 20.91.199.21:9055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amurFsJgo6iBrIY9VJLhcgAAAMk"]
[Thu Jul 30 14:50:46.395321 2026] [security2:error] [pid 62112:tid 62276] [client 75.118.71.92:54794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurFsJgo6iBrIY9VJLhbgAAAKc"], referer: http://pkf.jo
[Thu Jul 30 14:50:46.494530 2026] [security2:error] [pid 62112:tid 62342] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amurFsJgo6iBrIY9VJLhdgAAAOk"]
[Thu Jul 30 14:50:46.494649 2026] [security2:error] [pid 62112:tid 62342] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amurFsJgo6iBrIY9VJLhdgAAAOk"]
[Thu Jul 30 14:50:46.838805 2026] [security2:error] [pid 62112:tid 62364] [client 45.14.31.18:36432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurFsJgo6iBrIY9VJLhdwAAAP8"], referer: http://pkf.jo
[Thu Jul 30 14:50:47.088740 2026] [core:notice] [pid 62112:tid 62131] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:47.089841 2026] [security2:error] [pid 62112:tid 62336] [client 172.202.95.21:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.koinjp189.com"] [uri "/1.php"] [unique_id "amurF8Jgo6iBrIY9VJLhiAAAAOM"]
[Thu Jul 30 14:50:47.089991 2026] [security2:error] [pid 62112:tid 62336] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/1.php"] [unique_id "amurF8Jgo6iBrIY9VJLhiAAAAOM"]
[Thu Jul 30 14:50:47.090102 2026] [security2:error] [pid 62112:tid 62336] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/1.php"] [unique_id "amurF8Jgo6iBrIY9VJLhiAAAAOM"]
[Thu Jul 30 14:50:47.253232 2026] [security2:error] [pid 62112:tid 62302] [client 51.120.83.160:43489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/nothing2.php"] [unique_id "amurF8Jgo6iBrIY9VJLhkQAAAME"]
[Thu Jul 30 14:50:47.253341 2026] [security2:error] [pid 62112:tid 62302] [client 51.120.83.160:43489] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/nothing2.php"] [unique_id "amurF8Jgo6iBrIY9VJLhkQAAAME"]
[Thu Jul 30 14:50:47.310024 2026] [security2:error] [pid 62112:tid 62272] [client 52.238.199.152:37498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/help.php"] [unique_id "amurF8Jgo6iBrIY9VJLhkgAAAKM"]
[Thu Jul 30 14:50:47.612353 2026] [security2:error] [pid 62112:tid 62284] [client 45.174.149.87:55537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurF8Jgo6iBrIY9VJLhkwAAAK8"], referer: http://pkf.jo
[Thu Jul 30 14:50:47.695495 2026] [security2:error] [pid 62112:tid 62351] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/chosen.php"] [unique_id "amurF8Jgo6iBrIY9VJLhnQAAAPI"]
[Thu Jul 30 14:50:47.695589 2026] [security2:error] [pid 62112:tid 62351] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/chosen.php"] [unique_id "amurF8Jgo6iBrIY9VJLhnQAAAPI"]
[Thu Jul 30 14:50:47.787058 2026] [security2:error] [pid 62112:tid 62346] [client 51.120.83.160:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/media.php"] [unique_id "amurF8Jgo6iBrIY9VJLhoQAAAO0"]
[Thu Jul 30 14:50:47.787216 2026] [security2:error] [pid 62112:tid 62346] [client 51.120.83.160:14024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/media.php"] [unique_id "amurF8Jgo6iBrIY9VJLhoQAAAO0"]
[Thu Jul 30 14:50:48.235806 2026] [core:notice] [pid 62112:tid 62319] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:48.264696 2026] [security2:error] [pid 62112:tid 62299] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/sd.php"] [unique_id "amurGMJgo6iBrIY9VJLhsgAAAL4"]
[Thu Jul 30 14:50:48.264824 2026] [security2:error] [pid 62112:tid 62299] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/sd.php"] [unique_id "amurGMJgo6iBrIY9VJLhsgAAAL4"]
[Thu Jul 30 14:50:48.557010 2026] [security2:error] [pid 62112:tid 62276] [client 52.238.199.152:37480] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "arabian-tours.com"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amurGMJgo6iBrIY9VJLhtwAAAKc"]
[Thu Jul 30 14:50:48.557125 2026] [security2:error] [pid 62112:tid 62276] [client 52.238.199.152:37480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amurGMJgo6iBrIY9VJLhtwAAAKc"]
[Thu Jul 30 14:50:48.648449 2026] [security2:error] [pid 62112:tid 62303] [client 20.91.199.21:9045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amurGMJgo6iBrIY9VJLhuAAAAMI"]
[Thu Jul 30 14:50:48.827807 2026] [security2:error] [pid 62112:tid 62336] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/z60.php"] [unique_id "amurGMJgo6iBrIY9VJLhvwAAAOM"]
[Thu Jul 30 14:50:48.827903 2026] [security2:error] [pid 62112:tid 62336] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/z60.php"] [unique_id "amurGMJgo6iBrIY9VJLhvwAAAOM"]
[Thu Jul 30 14:50:49.079427 2026] [security2:error] [pid 62112:tid 62243] [client 51.120.83.160:27832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/file2.php"] [unique_id "amurGcJgo6iBrIY9VJLhxwAAAIY"]
[Thu Jul 30 14:50:49.079508 2026] [security2:error] [pid 62112:tid 62243] [client 51.120.83.160:27832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/file2.php"] [unique_id "amurGcJgo6iBrIY9VJLhxwAAAIY"]
[Thu Jul 30 14:50:49.476938 2026] [security2:error] [pid 62112:tid 62339] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/home.php"] [unique_id "amurGcJgo6iBrIY9VJLh1AAAAOY"]
[Thu Jul 30 14:50:49.477068 2026] [security2:error] [pid 62112:tid 62339] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/home.php"] [unique_id "amurGcJgo6iBrIY9VJLh1AAAAOY"]
[Thu Jul 30 14:50:49.560991 2026] [security2:error] [pid 62112:tid 62354] [client 52.238.199.152:37486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/admin/upload/css.php"] [unique_id "amurGcJgo6iBrIY9VJLh2AAAAPU"]
[Thu Jul 30 14:50:49.587934 2026] [security2:error] [pid 62112:tid 62348] [client 141.94.78.40:48210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurGcJgo6iBrIY9VJLhzwAAAO8"]
[Thu Jul 30 14:50:49.652286 2026] [security2:error] [pid 62112:tid 62350] [client 111.119.48.3:13333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurGcJgo6iBrIY9VJLh0QAAAPE"], referer: http://pkf.jo
[Thu Jul 30 14:50:50.046057 2026] [security2:error] [pid 62112:tid 62297] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/ws58.php"] [unique_id "amurGsJgo6iBrIY9VJLh5AAAALw"]
[Thu Jul 30 14:50:50.046185 2026] [security2:error] [pid 62112:tid 62297] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/ws58.php"] [unique_id "amurGsJgo6iBrIY9VJLh5AAAALw"]
[Thu Jul 30 14:50:50.104473 2026] [security2:error] [pid 62112:tid 62292] [client 51.120.83.160:18852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/simple.php"] [unique_id "amurGsJgo6iBrIY9VJLh6AAAALc"]
[Thu Jul 30 14:50:50.104594 2026] [security2:error] [pid 62112:tid 62292] [client 51.120.83.160:18852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/simple.php"] [unique_id "amurGsJgo6iBrIY9VJLh6AAAALc"]
[Thu Jul 30 14:50:50.144197 2026] [core:notice] [pid 62112:tid 62325] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:50.297992 2026] [security2:error] [pid 62112:tid 62293] [client 213.180.203.124:60340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amurGMJgo6iBrIY9VJLhqQAAALg"]
[Thu Jul 30 14:50:50.462220 2026] [core:notice] [pid 62112:tid 62158] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:50.594149 2026] [security2:error] [pid 62112:tid 62256] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/gulu.php"] [unique_id "amurGsJgo6iBrIY9VJLh-AAAAJM"]
[Thu Jul 30 14:50:50.594286 2026] [security2:error] [pid 62112:tid 62256] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/gulu.php"] [unique_id "amurGsJgo6iBrIY9VJLh-AAAAJM"]
[Thu Jul 30 14:50:50.690404 2026] [core:notice] [pid 62112:tid 62166] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:50.696614 2026] [security2:error] [pid 62112:tid 62262] [client 142.111.200.217:64350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/tag/ikea/\\xc2\\xbbhttp:/www.carnetdeshopping.com/wp-content/uploads/2015/09/ikea_collection_sittning_couverts.jpg"] [unique_id "amurGsJgo6iBrIY9VJLh9gAAmTU"], referer: https://carnetdeshopping.com/index.php/tag/ikea/
[Thu Jul 30 14:50:51.003515 2026] [security2:error] [pid 62112:tid 62355] [client 52.238.199.152:37408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/images/about.php"] [unique_id "amurG8Jgo6iBrIY9VJLiAwAAAPY"]
[Thu Jul 30 14:50:51.016641 2026] [core:notice] [pid 62112:tid 62145] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:51.168666 2026] [security2:error] [pid 62112:tid 62290] [client 20.91.199.21:9345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/js/about.php"] [unique_id "amurG8Jgo6iBrIY9VJLiDQAAALU"]
[Thu Jul 30 14:50:51.171433 2026] [security2:error] [pid 62112:tid 62356] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amurG8Jgo6iBrIY9VJLiDgAAAPc"]
[Thu Jul 30 14:50:51.171564 2026] [security2:error] [pid 62112:tid 62356] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amurG8Jgo6iBrIY9VJLiDgAAAPc"]
[Thu Jul 30 14:50:51.319484 2026] [core:notice] [pid 62112:tid 62167] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:51.376062 2026] [security2:error] [pid 62112:tid 62351] [client 51.120.83.160:37359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/mac.php"] [unique_id "amurG8Jgo6iBrIY9VJLiEwAAAPI"]
[Thu Jul 30 14:50:51.376144 2026] [security2:error] [pid 62112:tid 62351] [client 51.120.83.160:37359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/mac.php"] [unique_id "amurG8Jgo6iBrIY9VJLiEwAAAPI"]
[Thu Jul 30 14:50:51.380835 2026] [security2:error] [pid 62112:tid 62264] [client 147.78.160.138:55910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurG8Jgo6iBrIY9VJLiBQAAAJs"], referer: http://pkf.jo
[Thu Jul 30 14:50:51.759617 2026] [security2:error] [pid 62112:tid 62368] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wpls.php"] [unique_id "amurG8Jgo6iBrIY9VJLiHAAAAQM"]
[Thu Jul 30 14:50:51.759735 2026] [security2:error] [pid 62112:tid 62368] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wpls.php"] [unique_id "amurG8Jgo6iBrIY9VJLiHAAAAQM"]
[Thu Jul 30 14:50:52.378521 2026] [security2:error] [pid 62112:tid 62338] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/php.php"] [unique_id "amurHMJgo6iBrIY9VJLiLAAAAOU"]
[Thu Jul 30 14:50:52.378675 2026] [security2:error] [pid 62112:tid 62338] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/php.php"] [unique_id "amurHMJgo6iBrIY9VJLiLAAAAOU"]
[Thu Jul 30 14:50:52.642784 2026] [security2:error] [pid 62112:tid 62298] [client 51.120.83.160:57325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/install.php"] [unique_id "amurHMJgo6iBrIY9VJLiMQAAAL0"]
[Thu Jul 30 14:50:52.642905 2026] [security2:error] [pid 62112:tid 62298] [client 51.120.83.160:57325] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/install.php"] [unique_id "amurHMJgo6iBrIY9VJLiMQAAAL0"]
[Thu Jul 30 14:50:52.666092 2026] [security2:error] [pid 62112:tid 62273] [client 20.91.199.21:59953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amurHMJgo6iBrIY9VJLiMgAAAKQ"]
[Thu Jul 30 14:50:52.776005 2026] [security2:error] [pid 62112:tid 62280] [client 31.3.152.100:52910] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amurHMJgo6iBrIY9VJLiMAAAAKs"]
[Thu Jul 30 14:50:52.776163 2026] [security2:error] [pid 62112:tid 62280] [client 31.3.152.100:52910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amurHMJgo6iBrIY9VJLiMAAAAKs"]
[Thu Jul 30 14:50:53.003954 2026] [security2:error] [pid 62112:tid 62367] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/100.php"] [unique_id "amurHcJgo6iBrIY9VJLiPQAAAQI"]
[Thu Jul 30 14:50:53.004071 2026] [security2:error] [pid 62112:tid 62367] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/100.php"] [unique_id "amurHcJgo6iBrIY9VJLiPQAAAQI"]
[Thu Jul 30 14:50:53.167875 2026] [security2:error] [pid 62112:tid 62337] [client 189.156.226.90:27017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurHcJgo6iBrIY9VJLiPgAAAOQ"]
[Thu Jul 30 14:50:53.168028 2026] [security2:error] [pid 62112:tid 62337] [client 189.156.226.90:27017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurHcJgo6iBrIY9VJLiPgAAAOQ"]
[Thu Jul 30 14:50:53.581901 2026] [security2:error] [pid 62112:tid 62306] [client 51.120.83.160:43469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/wsx.php"] [unique_id "amurHcJgo6iBrIY9VJLiSgAAAMU"]
[Thu Jul 30 14:50:53.582010 2026] [security2:error] [pid 62112:tid 62306] [client 51.120.83.160:43469] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/wsx.php"] [unique_id "amurHcJgo6iBrIY9VJLiSgAAAMU"]
[Thu Jul 30 14:50:53.616511 2026] [security2:error] [pid 62112:tid 62244] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/BDKR28WP.php"] [unique_id "amurHcJgo6iBrIY9VJLiSwAAAIc"]
[Thu Jul 30 14:50:53.616623 2026] [security2:error] [pid 62112:tid 62244] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/BDKR28WP.php"] [unique_id "amurHcJgo6iBrIY9VJLiSwAAAIc"]
[Thu Jul 30 14:50:54.243183 2026] [security2:error] [pid 62112:tid 62293] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/browse.php"] [unique_id "amurHsJgo6iBrIY9VJLiWQAAALg"]
[Thu Jul 30 14:50:54.243281 2026] [security2:error] [pid 62112:tid 62293] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/browse.php"] [unique_id "amurHsJgo6iBrIY9VJLiWQAAALg"]
[Thu Jul 30 14:50:54.298501 2026] [security2:error] [pid 62112:tid 62287] [client 125.162.246.14:59177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amurHcJgo6iBrIY9VJLiUgAAALI"], referer: http://pkf.jo
[Thu Jul 30 14:50:54.659883 2026] [security2:error] [pid 62112:tid 62323] [client 51.120.83.160:43476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/alfa.php"] [unique_id "amurHsJgo6iBrIY9VJLiaAAAANY"]
[Thu Jul 30 14:50:54.660006 2026] [security2:error] [pid 62112:tid 62323] [client 51.120.83.160:43476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/alfa.php"] [unique_id "amurHsJgo6iBrIY9VJLiaAAAANY"]
[Thu Jul 30 14:50:54.788394 2026] [security2:error] [pid 62112:tid 62301] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-good.php"] [unique_id "amurHsJgo6iBrIY9VJLibAAAAMA"]
[Thu Jul 30 14:50:54.788510 2026] [security2:error] [pid 62112:tid 62301] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-good.php"] [unique_id "amurHsJgo6iBrIY9VJLibAAAAMA"]
[Thu Jul 30 14:50:55.192696 2026] [security2:error] [pid 62112:tid 62245] [client 66.249.66.204:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "bestdogproductguide.com"] [uri "/robots.txt"] [unique_id "amurH8Jgo6iBrIY9VJLidQAAAIg"]
[Thu Jul 30 14:50:55.367338 2026] [security2:error] [pid 62112:tid 62321] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/8573.php"] [unique_id "amurH8Jgo6iBrIY9VJLieQAAANQ"]
[Thu Jul 30 14:50:55.367469 2026] [security2:error] [pid 62112:tid 62321] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/8573.php"] [unique_id "amurH8Jgo6iBrIY9VJLieQAAANQ"]
[Thu Jul 30 14:50:55.909367 2026] [security2:error] [pid 62112:tid 62352] [client 51.120.83.160:43471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/dlu.php"] [unique_id "amurH8Jgo6iBrIY9VJLigwAAAPM"]
[Thu Jul 30 14:50:55.909466 2026] [security2:error] [pid 62112:tid 62352] [client 51.120.83.160:43471] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/dlu.php"] [unique_id "amurH8Jgo6iBrIY9VJLigwAAAPM"]
[Thu Jul 30 14:50:55.940775 2026] [security2:error] [pid 62112:tid 62306] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-admin/install.php"] [unique_id "amurH8Jgo6iBrIY9VJLihAAAAMU"]
[Thu Jul 30 14:50:55.940871 2026] [security2:error] [pid 62112:tid 62306] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-admin/install.php"] [unique_id "amurH8Jgo6iBrIY9VJLihAAAAMU"]
[Thu Jul 30 14:50:56.552561 2026] [security2:error] [pid 62112:tid 62294] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/classwithtostring.php"] [unique_id "amurIMJgo6iBrIY9VJLilQAAALk"]
[Thu Jul 30 14:50:56.552671 2026] [security2:error] [pid 62112:tid 62294] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/classwithtostring.php"] [unique_id "amurIMJgo6iBrIY9VJLilQAAALk"]
[Thu Jul 30 14:50:56.746577 2026] [security2:error] [pid 62112:tid 62276] [client 20.91.199.21:59923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amurIMJgo6iBrIY9VJLinAAAAKc"]
[Thu Jul 30 14:50:57.095474 2026] [security2:error] [pid 62112:tid 62296] [client 45.117.62.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amurIMJgo6iBrIY9VJLiogAAALs"], referer: https://cnpinyin.com
[Thu Jul 30 14:50:57.172746 2026] [security2:error] [pid 62112:tid 62345] [client 127.0.0.1:28014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amurIcJgo6iBrIY9VJLiqQAAAOw"]
[Thu Jul 30 14:50:57.172882 2026] [security2:error] [pid 62112:tid 62288] [client 74.7.175.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.choiceroofingservices.click"] [uri "/robots.txt"] [unique_id "amurIcJgo6iBrIY9VJLiqAAAs2Y"]
[Thu Jul 30 14:50:57.206820 2026] [security2:error] [pid 62112:tid 62300] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/ohct.php"] [unique_id "amurIcJgo6iBrIY9VJLirQAAAL8"]
[Thu Jul 30 14:50:57.206933 2026] [security2:error] [pid 62112:tid 62300] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/ohct.php"] [unique_id "amurIcJgo6iBrIY9VJLirQAAAL8"]
[Thu Jul 30 14:50:57.795891 2026] [core:notice] [pid 62112:tid 62191] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:50:57.845702 2026] [security2:error] [pid 62112:tid 62347] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/bless.php"] [unique_id "amurIcJgo6iBrIY9VJLiuQAAAO4"]
[Thu Jul 30 14:50:57.845808 2026] [security2:error] [pid 62112:tid 62347] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/bless.php"] [unique_id "amurIcJgo6iBrIY9VJLiuQAAAO4"]
[Thu Jul 30 14:50:57.958199 2026] [security2:error] [pid 62112:tid 62269] [client 51.120.83.160:17419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/f6.php"] [unique_id "amurIcJgo6iBrIY9VJLiugAAAKA"]
[Thu Jul 30 14:50:57.958313 2026] [security2:error] [pid 62112:tid 62269] [client 51.120.83.160:17419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/f6.php"] [unique_id "amurIcJgo6iBrIY9VJLiugAAAKA"]
[Thu Jul 30 14:50:58.375639 2026] [security2:error] [pid 62112:tid 62295] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/about.php"] [unique_id "amurIsJgo6iBrIY9VJLixAAAALo"]
[Thu Jul 30 14:50:58.375788 2026] [security2:error] [pid 62112:tid 62295] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/about.php"] [unique_id "amurIsJgo6iBrIY9VJLixAAAALo"]
[Thu Jul 30 14:50:58.481969 2026] [security2:error] [pid 62112:tid 62173] [remote 114.119.134.64:64307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dhowcruisedinner.com"] [uri "/JbcYdA/hartford-golf-club-members"] [unique_id "amurIsJgo6iBrIY9VJLiyAAAyTw"]
[Thu Jul 30 14:50:58.874495 2026] [security2:error] [pid 62112:tid 62265] [client 3.133.226.214:55074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amurIcJgo6iBrIY9VJLisQAAAJw"], referer: https://globalmarks.pk/
[Thu Jul 30 14:50:58.976727 2026] [security2:error] [pid 62112:tid 62361] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amurIsJgo6iBrIY9VJLi1gAAAPw"]
[Thu Jul 30 14:50:58.976814 2026] [security2:error] [pid 62112:tid 62361] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amurIsJgo6iBrIY9VJLi1gAAAPw"]
[Thu Jul 30 14:50:59.056735 2026] [security2:error] [pid 62112:tid 62267] [client 20.91.199.21:45684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amurI8Jgo6iBrIY9VJLi2AAAAJ4"]
[Thu Jul 30 14:50:59.064533 2026] [security2:error] [pid 62112:tid 62328] [client 52.167.144.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurIsJgo6iBrIY9VJLizgAAANs"]
[Thu Jul 30 14:50:59.558133 2026] [security2:error] [pid 62112:tid 62286] [client 52.167.144.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurI8Jgo6iBrIY9VJLi3wAAALE"]
[Thu Jul 30 14:50:59.631031 2026] [security2:error] [pid 62112:tid 62345] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/ta0ol.php"] [unique_id "amurI8Jgo6iBrIY9VJLi6AAAAOw"]
[Thu Jul 30 14:50:59.631166 2026] [security2:error] [pid 62112:tid 62345] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/ta0ol.php"] [unique_id "amurI8Jgo6iBrIY9VJLi6AAAAOw"]
[Thu Jul 30 14:50:59.883057 2026] [security2:error] [pid 62112:tid 62275] [client 51.120.83.160:17454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/0x.php"] [unique_id "amurI8Jgo6iBrIY9VJLi7wAAAKY"]
[Thu Jul 30 14:50:59.883146 2026] [security2:error] [pid 62112:tid 62275] [client 51.120.83.160:17454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/0x.php"] [unique_id "amurI8Jgo6iBrIY9VJLi7wAAAKY"]
[Thu Jul 30 14:51:00.092888 2026] [security2:error] [pid 62112:tid 62271] [client 20.91.199.21:3267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amurJMJgo6iBrIY9VJLi8wAAAKI"]
[Thu Jul 30 14:51:00.253057 2026] [security2:error] [pid 62112:tid 62350] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/sa.php7"] [unique_id "amurJMJgo6iBrIY9VJLi9AAAAPE"]
[Thu Jul 30 14:51:00.253174 2026] [security2:error] [pid 62112:tid 62350] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/sa.php7"] [unique_id "amurJMJgo6iBrIY9VJLi9AAAAPE"]
[Thu Jul 30 14:51:00.843964 2026] [security2:error] [pid 62112:tid 62293] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-class.php"] [unique_id "amurJMJgo6iBrIY9VJLjBAAAALg"]
[Thu Jul 30 14:51:00.844064 2026] [security2:error] [pid 62112:tid 62293] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-class.php"] [unique_id "amurJMJgo6iBrIY9VJLjBAAAALg"]
[Thu Jul 30 14:51:01.194095 2026] [security2:error] [pid 62112:tid 62363] [client 216.73.217.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.collectgabon.com"] [uri "/index.php"] [unique_id "amurJcJgo6iBrIY9VJLjDgAAAP4"]
[Thu Jul 30 14:51:01.259953 2026] [security2:error] [pid 62112:tid 62359] [client 51.120.83.160:43460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/geck.php"] [unique_id "amurJcJgo6iBrIY9VJLjFwAAAPo"]
[Thu Jul 30 14:51:01.260071 2026] [security2:error] [pid 62112:tid 62359] [client 51.120.83.160:43460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/geck.php"] [unique_id "amurJcJgo6iBrIY9VJLjFwAAAPo"]
[Thu Jul 30 14:51:01.402299 2026] [security2:error] [pid 62112:tid 62312] [client 52.238.199.152:36639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/autoloadclassmap.php"] [unique_id "amurJcJgo6iBrIY9VJLjHgAAAMs"]
[Thu Jul 30 14:51:01.425132 2026] [security2:error] [pid 62112:tid 62283] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/8.php"] [unique_id "amurJcJgo6iBrIY9VJLjIgAAAK4"]
[Thu Jul 30 14:51:01.425222 2026] [security2:error] [pid 62112:tid 62283] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/8.php"] [unique_id "amurJcJgo6iBrIY9VJLjIgAAAK4"]
[Thu Jul 30 14:51:01.425635 2026] [security2:error] [pid 62112:tid 62244] [client 20.91.199.21:39336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amurJcJgo6iBrIY9VJLjIwAAAIc"]
[Thu Jul 30 14:51:01.979491 2026] [security2:error] [pid 62112:tid 62340] [client 51.120.83.160:43516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.online-hope.com"] [uri "/8.php"] [unique_id "amurJcJgo6iBrIY9VJLjLwAAAOc"]
[Thu Jul 30 14:51:01.979641 2026] [security2:error] [pid 62112:tid 62340] [client 51.120.83.160:43516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.online-hope.com"] [uri "/8.php"] [unique_id "amurJcJgo6iBrIY9VJLjLwAAAOc"]
[Thu Jul 30 14:51:02.001210 2026] [security2:error] [pid 62112:tid 62255] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/bootstrap.php"] [unique_id "amurJsJgo6iBrIY9VJLjMAAAAJI"]
[Thu Jul 30 14:51:02.001329 2026] [security2:error] [pid 62112:tid 62255] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/bootstrap.php"] [unique_id "amurJsJgo6iBrIY9VJLjMAAAAJI"]
[Thu Jul 30 14:51:02.302865 2026] [security2:error] [pid 62112:tid 62264] [client 52.238.199.152:37453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/x.php"] [unique_id "amurJsJgo6iBrIY9VJLjNwAAAJs"]
[Thu Jul 30 14:51:02.603307 2026] [core:notice] [pid 62112:tid 62243] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:02.629532 2026] [security2:error] [pid 62112:tid 62281] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-blog-header.php"] [unique_id "amurJsJgo6iBrIY9VJLjQgAAAKw"]
[Thu Jul 30 14:51:02.629629 2026] [security2:error] [pid 62112:tid 62281] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-blog-header.php"] [unique_id "amurJsJgo6iBrIY9VJLjQgAAAKw"]
[Thu Jul 30 14:51:02.793578 2026] [security2:error] [pid 62112:tid 62354] [client 20.91.199.21:15074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/themes/about.php"] [unique_id "amurJsJgo6iBrIY9VJLjRgAAAPU"]
[Thu Jul 30 14:51:03.225919 2026] [security2:error] [pid 62112:tid 62325] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/aa.php"] [unique_id "amurJ8Jgo6iBrIY9VJLjUgAAANg"]
[Thu Jul 30 14:51:03.226086 2026] [security2:error] [pid 62112:tid 62325] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/aa.php"] [unique_id "amurJ8Jgo6iBrIY9VJLjUgAAANg"]
[Thu Jul 30 14:51:03.663990 2026] [security2:error] [pid 62112:tid 62342] [client 52.238.199.152:37405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-class.php"] [unique_id "amurJ8Jgo6iBrIY9VJLjWgAAAOk"]
[Thu Jul 30 14:51:03.789459 2026] [security2:error] [pid 62112:tid 62332] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/tx79.php"] [unique_id "amurJ8Jgo6iBrIY9VJLjXwAAAN8"]
[Thu Jul 30 14:51:03.789590 2026] [security2:error] [pid 62112:tid 62332] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/tx79.php"] [unique_id "amurJ8Jgo6iBrIY9VJLjXwAAAN8"]
[Thu Jul 30 14:51:03.792694 2026] [security2:error] [pid 62112:tid 62312] [client 189.156.226.90:27607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurJ8Jgo6iBrIY9VJLjYAAAAMs"]
[Thu Jul 30 14:51:03.792796 2026] [security2:error] [pid 62112:tid 62312] [client 189.156.226.90:27607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurJ8Jgo6iBrIY9VJLjYAAAAMs"]
[Thu Jul 30 14:51:04.138991 2026] [security2:error] [pid 62112:tid 62295] [client 57.141.0.3:39778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amurJ8Jgo6iBrIY9VJLjXgAAuh8"], referer: https://igetvape-australia.com/product-tag/iget-bar-plus-s3-kit-blackberry/
[Thu Jul 30 14:51:04.302652 2026] [security2:error] [pid 62112:tid 62321] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/motu.php"] [unique_id "amurKMJgo6iBrIY9VJLjbAAAANQ"]
[Thu Jul 30 14:51:04.302751 2026] [security2:error] [pid 62112:tid 62321] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/motu.php"] [unique_id "amurKMJgo6iBrIY9VJLjbAAAANQ"]
[Thu Jul 30 14:51:04.360526 2026] [security2:error] [pid 62112:tid 62339] [client 20.91.199.21:15079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amurKMJgo6iBrIY9VJLjbwAAAOY"]
[Thu Jul 30 14:51:04.842203 2026] [security2:error] [pid 62112:tid 62347] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-head.php"] [unique_id "amurKMJgo6iBrIY9VJLjegAAAO4"]
[Thu Jul 30 14:51:04.842282 2026] [security2:error] [pid 62112:tid 62347] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-head.php"] [unique_id "amurKMJgo6iBrIY9VJLjegAAAO4"]
[Thu Jul 30 14:51:05.291810 2026] [security2:error] [pid 62112:tid 62251] [client 52.238.199.152:37463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/content.php"] [unique_id "amurKcJgo6iBrIY9VJLjgQAAAI4"]
[Thu Jul 30 14:51:05.480399 2026] [security2:error] [pid 62112:tid 62263] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amurKcJgo6iBrIY9VJLjhgAAAJo"]
[Thu Jul 30 14:51:05.480511 2026] [security2:error] [pid 62112:tid 62263] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "amurKcJgo6iBrIY9VJLjhgAAAJo"]
[Thu Jul 30 14:51:05.771204 2026] [security2:error] [pid 62112:tid 62167] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Avada/licensing/style.php"] [unique_id "amurKcJgo6iBrIY9VJLjjgAAwjY"]
[Thu Jul 30 14:51:06.011330 2026] [security2:error] [pid 62112:tid 62162] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/BDKR28_nfbxj7ov.php"] [unique_id "amurKsJgo6iBrIY9VJLjkgAAoTE"]
[Thu Jul 30 14:51:06.094007 2026] [security2:error] [pid 62112:tid 62258] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/60856e3a4findex.php"] [unique_id "amurKsJgo6iBrIY9VJLjmAAAAJU"]
[Thu Jul 30 14:51:06.094108 2026] [security2:error] [pid 62112:tid 62258] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/60856e3a4findex.php"] [unique_id "amurKsJgo6iBrIY9VJLjmAAAAJU"]
[Thu Jul 30 14:51:06.338592 2026] [security2:error] [pid 62112:tid 62176] [remote 57.141.0.68:52436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/24984966950/feed/rss2/"] [unique_id "amurKsJgo6iBrIY9VJLjnQAArj8"]
[Thu Jul 30 14:51:06.607595 2026] [security2:error] [pid 62112:tid 62260] [client 52.238.199.152:37473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/acp.php"] [unique_id "amurKsJgo6iBrIY9VJLjpQAAAJc"]
[Thu Jul 30 14:51:06.675511 2026] [security2:error] [pid 62112:tid 62340] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-the.php"] [unique_id "amurKsJgo6iBrIY9VJLjpgAAAOc"]
[Thu Jul 30 14:51:06.675665 2026] [security2:error] [pid 62112:tid 62340] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp-the.php"] [unique_id "amurKsJgo6iBrIY9VJLjpgAAAOc"]
[Thu Jul 30 14:51:06.717178 2026] [security2:error] [pid 62112:tid 62146] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/BIBIL.php"] [unique_id "amurKsJgo6iBrIY9VJLjpwAAlCE"]
[Thu Jul 30 14:51:06.959850 2026] [security2:error] [pid 62112:tid 62141] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Cache.php"] [unique_id "amurKsJgo6iBrIY9VJLjrgAA-Bw"]
[Thu Jul 30 14:51:07.199730 2026] [security2:error] [pid 62112:tid 62169] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Cache/Cache.php"] [unique_id "amurK8Jgo6iBrIY9VJLjtAAA7jg"]
[Thu Jul 30 14:51:07.286385 2026] [security2:error] [pid 62112:tid 62243] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wp.php"] [unique_id "amurK8Jgo6iBrIY9VJLjuAAAAIY"]
[Thu Jul 30 14:51:07.286473 2026] [security2:error] [pid 62112:tid 62243] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wp.php"] [unique_id "amurK8Jgo6iBrIY9VJLjuAAAAIY"]
[Thu Jul 30 14:51:07.465270 2026] [security2:error] [pid 62112:tid 62175] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Cache/about.php"] [unique_id "amurK8Jgo6iBrIY9VJLjuwAApT4"]
[Thu Jul 30 14:51:07.556755 2026] [security2:error] [pid 62112:tid 62352] [client 172.237.109.114:43117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurKsJgo6iBrIY9VJLjsAAAAPM"]
[Thu Jul 30 14:51:07.705824 2026] [security2:error] [pid 62112:tid 62183] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Cache/dropdown.php"] [unique_id "amurK8Jgo6iBrIY9VJLjwQAA10Y"]
[Thu Jul 30 14:51:07.817214 2026] [security2:error] [pid 62112:tid 62337] [client 20.91.199.21:45433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/images/about.php"] [unique_id "amurK8Jgo6iBrIY9VJLjxQAAAOQ"]
[Thu Jul 30 14:51:07.847768 2026] [security2:error] [pid 62112:tid 62362] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/users.php"] [unique_id "amurK8Jgo6iBrIY9VJLjxgAAAP0"]
[Thu Jul 30 14:51:07.847885 2026] [security2:error] [pid 62112:tid 62362] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/users.php"] [unique_id "amurK8Jgo6iBrIY9VJLjxgAAAP0"]
[Thu Jul 30 14:51:08.008038 2026] [security2:error] [pid 62112:tid 62199] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Cache/index.php"] [unique_id "amurLMJgo6iBrIY9VJLjygAA-lY"]
[Thu Jul 30 14:51:08.251605 2026] [security2:error] [pid 62112:tid 62189] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Cache/upfile.php"] [unique_id "amurLMJgo6iBrIY9VJLjzgAAvEw"]
[Thu Jul 30 14:51:08.412803 2026] [security2:error] [pid 62112:tid 62366] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/tinysd.php"] [unique_id "amurLMJgo6iBrIY9VJLj0gAAAQE"]
[Thu Jul 30 14:51:08.412934 2026] [security2:error] [pid 62112:tid 62366] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/tinysd.php"] [unique_id "amurLMJgo6iBrIY9VJLj0gAAAQE"]
[Thu Jul 30 14:51:08.502039 2026] [security2:error] [pid 62112:tid 62150] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Canonical.php"] [unique_id "amurLMJgo6iBrIY9VJLj1gAApyU"]
[Thu Jul 30 14:51:08.623308 2026] [security2:error] [pid 62112:tid 62345] [client 31.3.152.100:58092] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amurLMJgo6iBrIY9VJLj2AAAAOw"]
[Thu Jul 30 14:51:08.623442 2026] [security2:error] [pid 62112:tid 62345] [client 31.3.152.100:58092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amurLMJgo6iBrIY9VJLj2AAAAOw"]
[Thu Jul 30 14:51:08.712865 2026] [core:notice] [pid 62112:tid 62138] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:08.716457 2026] [security2:error] [pid 62112:tid 62336] [client 98.95.120.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/32."] [unique_id "amurLMJgo6iBrIY9VJLj0wAA4xk"]
[Thu Jul 30 14:51:08.742318 2026] [security2:error] [pid 62112:tid 62170] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Capi.php"] [unique_id "amurLMJgo6iBrIY9VJLj3QAAjDk"]
[Thu Jul 30 14:51:08.980596 2026] [security2:error] [pid 62112:tid 62266] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/ws78.php"] [unique_id "amurLMJgo6iBrIY9VJLj4AAAAJ0"]
[Thu Jul 30 14:51:08.980716 2026] [security2:error] [pid 62112:tid 62266] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/ws78.php"] [unique_id "amurLMJgo6iBrIY9VJLj4AAAAJ0"]
[Thu Jul 30 14:51:09.024156 2026] [security2:error] [pid 62112:tid 62155] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Content/Type/index.php"] [unique_id "amurLcJgo6iBrIY9VJLj4gAA1Co"]
[Thu Jul 30 14:51:09.427509 2026] [security2:error] [pid 62112:tid 62195] [remote 47.128.27.91:13270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-5-retro-racer-blue/"] [unique_id "amurLcJgo6iBrIY9VJLj7gAAm1I"]
[Thu Jul 30 14:51:09.513494 2026] [core:notice] [pid 62112:tid 62245] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:09.527831 2026] [security2:error] [pid 62112:tid 62253] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/elp.php"] [unique_id "amurLcJgo6iBrIY9VJLj8AAAAJA"]
[Thu Jul 30 14:51:09.527914 2026] [security2:error] [pid 62112:tid 62253] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/elp.php"] [unique_id "amurLcJgo6iBrIY9VJLj8AAAAJA"]
[Thu Jul 30 14:51:09.561619 2026] [security2:error] [pid 62112:tid 62171] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Content/Type/wp-login.php"] [unique_id "amurLcJgo6iBrIY9VJLj7AAAyjo"]
[Thu Jul 30 14:51:09.837992 2026] [security2:error] [pid 62112:tid 62216] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Content/index.php"] [unique_id "amurLcJgo6iBrIY9VJLj-wAA_2c"]
[Thu Jul 30 14:51:09.973796 2026] [core:notice] [pid 62112:tid 62352] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:10.080539 2026] [security2:error] [pid 62112:tid 62208] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Cookie/wp-login.php"] [unique_id "amurLsJgo6iBrIY9VJLj_gAAuV8"]
[Thu Jul 30 14:51:10.349295 2026] [security2:error] [pid 62112:tid 62209] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Core-Econ/index.php"] [unique_id "amurLsJgo6iBrIY9VJLkCQAA-mA"]
[Thu Jul 30 14:51:10.375285 2026] [security2:error] [pid 62112:tid 62263] [client 178.20.47.39:51240] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.47.39" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amurLsJgo6iBrIY9VJLkCgAAAJo"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 14:51:10.593211 2026] [security2:error] [pid 62112:tid 62262] [client 201.145.72.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amurLsJgo6iBrIY9VJLkDQAAAJk"], referer: https://cnpinyin.com
[Thu Jul 30 14:51:10.593286 2026] [security2:error] [pid 62112:tid 62221] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Core-Econ/upH.php"] [unique_id "amurLsJgo6iBrIY9VJLkDgAA6Ww"]
[Thu Jul 30 14:51:10.867244 2026] [security2:error] [pid 62112:tid 62200] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Core-EconX/up.php"] [unique_id "amurLsJgo6iBrIY9VJLkFQAAzFc"]
[Thu Jul 30 14:51:11.087374 2026] [security2:error] [pid 62112:tid 62310] [client 52.238.199.152:36654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/g.php"] [unique_id "amurL8Jgo6iBrIY9VJLkGQAAAMk"]
[Thu Jul 30 14:51:11.109218 2026] [security2:error] [pid 62112:tid 62173] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/DJP9.php"] [unique_id "amurL8Jgo6iBrIY9VJLkHQABAjw"]
[Thu Jul 30 14:51:11.342633 2026] [security2:error] [pid 62112:tid 62229] [remote 40.77.167.30:21179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/jpita.or.jp/Policyf.php"] [unique_id "amurL8Jgo6iBrIY9VJLkKAAAjXQ"]
[Thu Jul 30 14:51:11.349517 2026] [security2:error] [pid 62112:tid 62219] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff.php"] [unique_id "amurL8Jgo6iBrIY9VJLkKQAA8Wo"]
[Thu Jul 30 14:51:11.635996 2026] [security2:error] [pid 62112:tid 62120] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Engine.php"] [unique_id "amurL8Jgo6iBrIY9VJLkLQAA7gc"]
[Thu Jul 30 14:51:11.777937 2026] [security2:error] [pid 62112:tid 62351] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurL8Jgo6iBrIY9VJLkIwAA8m8"]
[Thu Jul 30 14:51:11.924779 2026] [security2:error] [pid 62112:tid 62231] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Engine/about.php"] [unique_id "amurL8Jgo6iBrIY9VJLkNAAApXY"]
[Thu Jul 30 14:51:12.082478 2026] [autoindex:error] [pid 62112:tid 62320] [client 2605:6400:20:3da:d5c5:4b68:fbc:5c55:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:51:12.166001 2026] [security2:error] [pid 62112:tid 62117] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Engine/admin-ajax.php"] [unique_id "amurMMJgo6iBrIY9VJLkPQAAngQ"]
[Thu Jul 30 14:51:12.397775 2026] [security2:error] [pid 62112:tid 62265] [client 213.152.161.249:58444] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amurMMJgo6iBrIY9VJLkRAAAAJw"]
[Thu Jul 30 14:51:12.397886 2026] [security2:error] [pid 62112:tid 62265] [client 213.152.161.249:58444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amurMMJgo6iBrIY9VJLkRAAAAJw"]
[Thu Jul 30 14:51:12.452076 2026] [security2:error] [pid 62112:tid 62237] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Engine/com_search.php"] [unique_id "amurMMJgo6iBrIY9VJLkRwAA-nw"]
[Thu Jul 30 14:51:12.553596 2026] [security2:error] [pid 62112:tid 62270] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/atomlib.php"] [unique_id "amurMMJgo6iBrIY9VJLkTAAAAKE"]
[Thu Jul 30 14:51:12.553692 2026] [security2:error] [pid 62112:tid 62270] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/atomlib.php"] [unique_id "amurMMJgo6iBrIY9VJLkTAAAAKE"]
[Thu Jul 30 14:51:12.717635 2026] [security2:error] [pid 62112:tid 62122] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Engine/doc.php"] [unique_id "amurMMJgo6iBrIY9VJLkTwAAiQk"]
[Thu Jul 30 14:51:12.956400 2026] [security2:error] [pid 62112:tid 62188] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Engine/index.php"] [unique_id "amurMMJgo6iBrIY9VJLkVwABAUs"]
[Thu Jul 30 14:51:13.090200 2026] [security2:error] [pid 62112:tid 62114] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-class-db.php"] [unique_id "amurMcJgo6iBrIY9VJLkWwAA6QE"]
[Thu Jul 30 14:51:13.130612 2026] [security2:error] [pid 62112:tid 62283] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/wyzer3.php"] [unique_id "amurMcJgo6iBrIY9VJLkXAAAAK4"]
[Thu Jul 30 14:51:13.130712 2026] [security2:error] [pid 62112:tid 62283] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/wyzer3.php"] [unique_id "amurMcJgo6iBrIY9VJLkXAAAAK4"]
[Thu Jul 30 14:51:13.202114 2026] [security2:error] [pid 62112:tid 62228] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Engine/priv.php"] [unique_id "amurMcJgo6iBrIY9VJLkXQAAjHM"]
[Thu Jul 30 14:51:13.396379 2026] [security2:error] [pid 62112:tid 62121] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-class.php"] [unique_id "amurMcJgo6iBrIY9VJLkZQAAlgg"]
[Thu Jul 30 14:51:13.442284 2026] [security2:error] [pid 62112:tid 62113] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Engine/wp-login.php"] [unique_id "amurMcJgo6iBrIY9VJLkZgAAqwA"]
[Thu Jul 30 14:51:13.685837 2026] [security2:error] [pid 62112:tid 62135] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Renderer/about.php"] [unique_id "amurMcJgo6iBrIY9VJLkagAArxY"]
[Thu Jul 30 14:51:13.692314 2026] [security2:error] [pid 62112:tid 62315] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/max.php"] [unique_id "amurMcJgo6iBrIY9VJLkawAAAM4"]
[Thu Jul 30 14:51:13.692388 2026] [security2:error] [pid 62112:tid 62315] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/max.php"] [unique_id "amurMcJgo6iBrIY9VJLkawAAAM4"]
[Thu Jul 30 14:51:13.927921 2026] [security2:error] [pid 62112:tid 62119] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Renderer/alfa-rex.php"] [unique_id "amurMcJgo6iBrIY9VJLkcwAAtgY"]
[Thu Jul 30 14:51:14.167202 2026] [security2:error] [pid 62112:tid 62133] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-classic/inc/index.php"] [unique_id "amurMsJgo6iBrIY9VJLkdwAAjRQ"]
[Thu Jul 30 14:51:14.168907 2026] [security2:error] [pid 62112:tid 62134] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Renderer/index.php"] [unique_id "amurMsJgo6iBrIY9VJLkeAAA7hU"]
[Thu Jul 30 14:51:14.306305 2026] [security2:error] [pid 62112:tid 62289] [client 172.202.95.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koinjp189.com"] [uri "/ftde.php"] [unique_id "amurMsJgo6iBrIY9VJLkegAAALQ"]
[Thu Jul 30 14:51:14.306427 2026] [security2:error] [pid 62112:tid 62289] [client 172.202.95.21:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.koinjp189.com"] [uri "/ftde.php"] [unique_id "amurMsJgo6iBrIY9VJLkegAAALQ"]
[Thu Jul 30 14:51:14.339276 2026] [security2:error] [pid 62112:tid 62253] [client 189.156.226.90:27704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurMsJgo6iBrIY9VJLkewAAAJA"]
[Thu Jul 30 14:51:14.339384 2026] [security2:error] [pid 62112:tid 62253] [client 189.156.226.90:27704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurMsJgo6iBrIY9VJLkewAAAJA"]
[Thu Jul 30 14:51:14.405889 2026] [security2:error] [pid 62112:tid 62159] [remote 65.181.116.95:37154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wce.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amurMsJgo6iBrIY9VJLkdAAA5i4"]
[Thu Jul 30 14:51:14.408601 2026] [security2:error] [pid 62112:tid 62232] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/Renderer/wp-login.php"] [unique_id "amurMsJgo6iBrIY9VJLkfwAA6nc"]
[Thu Jul 30 14:51:14.420875 2026] [security2:error] [pid 62112:tid 62161] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-commentin.php"] [unique_id "amurMsJgo6iBrIY9VJLkgAAAxzA"]
[Thu Jul 30 14:51:14.480437 2026] [core:error] [pid 62112:tid 62320] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:14.480463 2026] [core:error] [pid 62112:tid 62320] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:14.569508 2026] [security2:error] [pid 62112:tid 62242] [client 20.91.199.21:45583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amurMsJgo6iBrIY9VJLkhwAAAIU"]
[Thu Jul 30 14:51:14.674569 2026] [security2:error] [pid 62112:tid 62233] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/Diff/about.php"] [unique_id "amurMsJgo6iBrIY9VJLkiwAArXg"]
[Thu Jul 30 14:51:14.708068 2026] [security2:error] [pid 62112:tid 62147] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-comments-pos.php"] [unique_id "amurMsJgo6iBrIY9VJLkjAAAkyI"]
[Thu Jul 30 14:51:14.987951 2026] [security2:error] [pid 62112:tid 62136] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-comments-post.php"] [unique_id "amurMsJgo6iBrIY9VJLkkQAA8xc"]
[Thu Jul 30 14:51:15.506885 2026] [security2:error] [pid 62112:tid 62177] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-comments.php"] [unique_id "amurM8Jgo6iBrIY9VJLklwAAi0A"]
[Thu Jul 30 14:51:15.784435 2026] [security2:error] [pid 62112:tid 62166] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-conctent.php"] [unique_id "amurM8Jgo6iBrIY9VJLkpQAApDU"]
[Thu Jul 30 14:51:15.843263 2026] [security2:error] [pid 62112:tid 62123] [remote 47.128.27.5:55586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-barb-north-kalan/"] [unique_id "amurM8Jgo6iBrIY9VJLkpgAA3wo"]
[Thu Jul 30 14:51:16.031954 2026] [security2:error] [pid 62112:tid 62164] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-configer.php"] [unique_id "amurNMJgo6iBrIY9VJLkrgAAsDM"]
[Thu Jul 30 14:51:16.038031 2026] [security2:error] [pid 62112:tid 62328] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurM8Jgo6iBrIY9VJLknAAA2yg"]
[Thu Jul 30 14:51:16.122689 2026] [security2:error] [pid 62112:tid 62259] [client 172.237.109.114:57391] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "alseermarine.com"] [uri "/api/"] [unique_id "amurNMJgo6iBrIY9VJLksgAAAJY"]
[Thu Jul 30 14:51:16.282749 2026] [security2:error] [pid 62112:tid 62178] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-configs.php"] [unique_id "amurNMJgo6iBrIY9VJLktgAA3EE"]
[Thu Jul 30 14:51:16.569227 2026] [security2:error] [pid 62112:tid 62143] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-confiq.php"] [unique_id "amurNMJgo6iBrIY9VJLkvQAAxR4"]
[Thu Jul 30 14:51:16.822133 2026] [security2:error] [pid 62112:tid 62176] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-confirm.php"] [unique_id "amurNMJgo6iBrIY9VJLkwQAAhj8"]
[Thu Jul 30 14:51:16.855007 2026] [security2:error] [pid 62112:tid 62296] [client 20.91.199.21:13504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/images/about.php"] [unique_id "amurNMJgo6iBrIY9VJLkwgAAALs"]
[Thu Jul 30 14:51:17.103147 2026] [security2:error] [pid 62112:tid 62168] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-conflg.php"] [unique_id "amurNcJgo6iBrIY9VJLkyQAA_zc"]
[Thu Jul 30 14:51:17.172028 2026] [security2:error] [pid 62112:tid 62254] [client 52.238.199.152:56308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known/caches.php"] [unique_id "amurNcJgo6iBrIY9VJLkygAAAJE"]
[Thu Jul 30 14:51:17.357374 2026] [security2:error] [pid 62112:tid 62156] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-conflg.php/wp-content/plugins/google-seo-rank/wp-configs.php"] [unique_id "amurNcJgo6iBrIY9VJLkzgAAxCs"]
[Thu Jul 30 14:51:17.631410 2026] [security2:error] [pid 62112:tid 62179] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-consar.php"] [unique_id "amurNcJgo6iBrIY9VJLk1QAAwkI"]
[Thu Jul 30 14:51:17.883617 2026] [security2:error] [pid 62112:tid 62175] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content.php"] [unique_id "amurNcJgo6iBrIY9VJLk2gAAhz4"]
[Thu Jul 30 14:51:18.158490 2026] [security2:error] [pid 62112:tid 62183] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content.php.php"] [unique_id "amurNsJgo6iBrIY9VJLk3wAAsUY"]
[Thu Jul 30 14:51:18.192079 2026] [security2:error] [pid 62112:tid 62325] [client 20.91.199.21:17098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/about.php"] [unique_id "amurNsJgo6iBrIY9VJLk4gAAANg"]
[Thu Jul 30 14:51:18.397865 2026] [core:notice] [pid 62112:tid 62190] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:18.409869 2026] [security2:error] [pid 62112:tid 62199] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/plugins/watch/bop.php"] [unique_id "amurNsJgo6iBrIY9VJLk5wAA41Y"]
[Thu Jul 30 14:51:18.526877 2026] [security2:error] [pid 62112:tid 62189] [remote 43.228.157.75:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amurNsJgo6iBrIY9VJLk6QAA70w"]
[Thu Jul 30 14:51:18.535218 2026] [core:notice] [pid 62112:tid 62185] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:18.558560 2026] [core:notice] [pid 62112:tid 62148] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:18.602646 2026] [security2:error] [pid 62112:tid 62150] [remote 43.228.157.75:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "amurNsJgo6iBrIY9VJLk7gAA2yU"], referer: www.google.com
[Thu Jul 30 14:51:18.759010 2026] [security2:error] [pid 62112:tid 62170] [remote 43.228.157.75:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "amurNsJgo6iBrIY9VJLk9AAA3Dk"], referer: www.google.com
[Thu Jul 30 14:51:18.805040 2026] [security2:error] [pid 62112:tid 62193] [remote 43.228.157.75:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-plain.php"] [unique_id "amurNsJgo6iBrIY9VJLk9gAAulA"], referer: www.google.com
[Thu Jul 30 14:51:18.967762 2026] [security2:error] [pid 62112:tid 62155] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-content/uploads/json.php"] [unique_id "amurNsJgo6iBrIY9VJLk-QAAxSo"]
[Thu Jul 30 14:51:19.146054 2026] [security2:error] [pid 62112:tid 62246] [client 52.238.199.152:57902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amurN8Jgo6iBrIY9VJLlAAAAAIk"]
[Thu Jul 30 14:51:19.216878 2026] [security2:error] [pid 62112:tid 62195] [remote 43.228.157.75:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/jbzesptw.php"] [unique_id "amurN8Jgo6iBrIY9VJLlAgAAmFI"], referer: www.google.com
[Thu Jul 30 14:51:19.241560 2026] [security2:error] [pid 62112:tid 62171] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-corn-sample.php"] [unique_id "amurN8Jgo6iBrIY9VJLlAwAA3jo"]
[Thu Jul 30 14:51:19.296691 2026] [security2:error] [pid 62112:tid 62365] [client 20.91.199.21:45220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/cgi-bin/about.php"] [unique_id "amurN8Jgo6iBrIY9VJLlBwAAAQA"]
[Thu Jul 30 14:51:19.335658 2026] [core:notice] [pid 62112:tid 62197] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:19.502997 2026] [security2:error] [pid 62112:tid 62216] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-crom.php"] [unique_id "amurN8Jgo6iBrIY9VJLlCQAA_2c"]
[Thu Jul 30 14:51:19.655464 2026] [core:notice] [pid 62112:tid 62234] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:19.779380 2026] [security2:error] [pid 62112:tid 62210] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-cron.php"] [unique_id "amurN8Jgo6iBrIY9VJLlFAAA0mE"]
[Thu Jul 30 14:51:20.078808 2026] [security2:error] [pid 62112:tid 62359] [client 52.167.144.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurN8Jgo6iBrIY9VJLlEwAAAPo"]
[Thu Jul 30 14:51:20.206756 2026] [security2:error] [pid 62112:tid 62215] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-css.php"] [unique_id "amurOMJgo6iBrIY9VJLlHQAAwGY"]
[Thu Jul 30 14:51:20.349676 2026] [security2:error] [pid 62112:tid 62354] [client 121.229.156.49:39650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/off-white-c-o-virgil-abloh-out-of-office-low-top-leather-sneakersooo-14/"] [unique_id "amurOMJgo6iBrIY9VJLlJAAAAPU"]
[Thu Jul 30 14:51:20.349798 2026] [security2:error] [pid 62112:tid 62354] [client 121.229.156.49:39650] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/off-white-c-o-virgil-abloh-out-of-office-low-top-leather-sneakersooo-14/"] [unique_id "amurOMJgo6iBrIY9VJLlJAAAAPU"]
[Thu Jul 30 14:51:20.481514 2026] [security2:error] [pid 62112:tid 62265] [client 20.91.199.21:41053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amurOMJgo6iBrIY9VJLlJQAAAJw"]
[Thu Jul 30 14:51:20.560820 2026] [security2:error] [pid 62112:tid 62338] [client 172.237.109.114:14917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurN8Jgo6iBrIY9VJLlGAAAAOU"]
[Thu Jul 30 14:51:20.568958 2026] [security2:error] [pid 62112:tid 62191] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-daft/miin.php"] [unique_id "amurOMJgo6iBrIY9VJLlJwAA6U4"]
[Thu Jul 30 14:51:20.897270 2026] [security2:error] [pid 62112:tid 62206] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-damin.php"] [unique_id "amurOMJgo6iBrIY9VJLlMQAA210"]
[Thu Jul 30 14:51:21.180711 2026] [security2:error] [pid 62112:tid 62229] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-db-ajax-made/wp-ajax.php"] [unique_id "amurOcJgo6iBrIY9VJLlOAAAm3Q"]
[Thu Jul 30 14:51:21.348372 2026] [core:notice] [pid 62112:tid 62211] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:21.353239 2026] [security2:error] [pid 62112:tid 62368] [client 17.246.23.25:52760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/8959"] [unique_id "amurOcJgo6iBrIY9VJLlPAABA2I"], referer: https://www.ejournalugj.com/index.php/Euclid/article/view/8959
[Thu Jul 30 14:51:21.471028 2026] [security2:error] [pid 62112:tid 62224] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-defaul.php"] [unique_id "amurOcJgo6iBrIY9VJLlQAAAym8"]
[Thu Jul 30 14:51:21.753514 2026] [security2:error] [pid 62112:tid 62202] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-del.php"] [unique_id "amurOcJgo6iBrIY9VJLlRAAA3lk"]
[Thu Jul 30 14:51:22.036418 2026] [security2:error] [pid 62112:tid 62220] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-diambar/includes/loadme.php"] [unique_id "amurOsJgo6iBrIY9VJLlTgAArWs"]
[Thu Jul 30 14:51:22.067329 2026] [core:notice] [pid 62112:tid 62369] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:22.319670 2026] [security2:error] [pid 62112:tid 62140] [remote 20.104.18.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.markmocek.com"] [uri "/wp-dnd.php"] [unique_id "amurOsJgo6iBrIY9VJLlWAAAuRs"]
[Thu Jul 30 14:51:22.886553 2026] [core:notice] [pid 62112:tid 62198] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:22.951451 2026] [security2:error] [pid 62112:tid 62318] [client 20.91.199.21:9000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amurOsJgo6iBrIY9VJLlYwAAANE"]
[Thu Jul 30 14:51:23.744857 2026] [security2:error] [pid 62112:tid 62272] [client 52.238.199.152:37454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/css/about.php"] [unique_id "amurO8Jgo6iBrIY9VJLlcQAAAKM"]
[Thu Jul 30 14:51:23.998145 2026] [security2:error] [pid 62112:tid 62240] [remote 82.130.249.15:59258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.249.130.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/wp-login.php"] [unique_id "amurO8Jgo6iBrIY9VJLleAAAk38"]
[Thu Jul 30 14:51:24.112137 2026] [core:error] [pid 62112:tid 62245] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:24.112156 2026] [core:error] [pid 62112:tid 62245] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:24.266882 2026] [core:notice] [pid 62112:tid 62228] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:24.773557 2026] [core:notice] [pid 62112:tid 62129] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:24.844172 2026] [security2:error] [pid 62112:tid 62254] [client 40.77.167.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurPMJgo6iBrIY9VJLljAAAAJE"]
[Thu Jul 30 14:51:24.872709 2026] [security2:error] [pid 62112:tid 62369] [client 189.156.226.90:26790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurPMJgo6iBrIY9VJLlkAAAAQQ"]
[Thu Jul 30 14:51:24.872812 2026] [security2:error] [pid 62112:tid 62369] [client 189.156.226.90:26790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurPMJgo6iBrIY9VJLlkAAAAQQ"]
[Thu Jul 30 14:51:25.396943 2026] [security2:error] [pid 62112:tid 62134] [remote 52.167.144.199:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/rehabilitation-a-base-communautaire-2/mediaf.php"] [unique_id "amurPcJgo6iBrIY9VJLlmwAA2RU"]
[Thu Jul 30 14:51:25.711396 2026] [core:notice] [pid 62112:tid 62232] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:25.925455 2026] [security2:error] [pid 62112:tid 62288] [client 179.43.134.114:44324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happyspree.app"] [uri "/wp-login.php"] [unique_id "amurPcJgo6iBrIY9VJLlpgAAALM"]
[Thu Jul 30 14:51:26.393017 2026] [core:notice] [pid 62112:tid 62136] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:26.393062 2026] [security2:error] [pid 62112:tid 62278] [client 52.238.199.152:37496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/files/index.php"] [unique_id "amurPsJgo6iBrIY9VJLluQAAAKk"]
[Thu Jul 30 14:51:27.159237 2026] [core:notice] [pid 62112:tid 62158] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:27.437414 2026] [security2:error] [pid 62112:tid 62314] [client 52.238.199.152:37474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amurP8Jgo6iBrIY9VJLlywAAAM0"]
[Thu Jul 30 14:51:27.465673 2026] [security2:error] [pid 62112:tid 62362] [client 184.75.223.203:53884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amurP8Jgo6iBrIY9VJLlzwAAAP0"]
[Thu Jul 30 14:51:27.465789 2026] [security2:error] [pid 62112:tid 62362] [client 184.75.223.203:53884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amurP8Jgo6iBrIY9VJLlzwAAAP0"]
[Thu Jul 30 14:51:28.434138 2026] [core:notice] [pid 62112:tid 62366] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:28.568972 2026] [security2:error] [pid 62112:tid 62263] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amurQMJgo6iBrIY9VJLl6QAAAJo"]
[Thu Jul 30 14:51:28.569098 2026] [security2:error] [pid 62112:tid 62263] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amurQMJgo6iBrIY9VJLl6QAAAJo"]
[Thu Jul 30 14:51:28.914120 2026] [security2:error] [pid 62112:tid 62245] [client 179.43.134.114:44340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happyspree.app"] [uri "/wp-login.php"] [unique_id "amurQMJgo6iBrIY9VJLl8wAAAIg"], referer: https://happyspree.app/wp-admin/
[Thu Jul 30 14:51:29.092956 2026] [security2:error] [pid 62112:tid 62325] [client 52.238.199.152:37389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/network/admin.php"] [unique_id "amurQcJgo6iBrIY9VJLl-gAAANg"]
[Thu Jul 30 14:51:29.205439 2026] [security2:error] [pid 62112:tid 62253] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amurQcJgo6iBrIY9VJLl_QAAAJA"]
[Thu Jul 30 14:51:29.205567 2026] [security2:error] [pid 62112:tid 62253] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amurQcJgo6iBrIY9VJLl_QAAAJA"]
[Thu Jul 30 14:51:29.825689 2026] [security2:error] [pid 62112:tid 62279] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wicked.php"] [unique_id "amurQcJgo6iBrIY9VJLmCgAAAKo"]
[Thu Jul 30 14:51:29.825805 2026] [security2:error] [pid 62112:tid 62279] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wicked.php"] [unique_id "amurQcJgo6iBrIY9VJLmCgAAAKo"]
[Thu Jul 30 14:51:29.983686 2026] [security2:error] [pid 62112:tid 62244] [client 45.148.10.120:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.koidomino.click"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "amurQcJgo6iBrIY9VJLmEAAAAIc"]
[Thu Jul 30 14:51:30.134333 2026] [security2:error] [pid 62112:tid 62369] [client 20.91.199.21:3876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/css/about.php"] [unique_id "amurQsJgo6iBrIY9VJLmFQAAAQQ"]
[Thu Jul 30 14:51:30.217760 2026] [security2:error] [pid 62112:tid 62362] [client 52.167.144.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurQcJgo6iBrIY9VJLmDQAAAP0"]
[Thu Jul 30 14:51:30.368391 2026] [security2:error] [pid 62112:tid 62273] [client 31.3.152.100:52058] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amurQsJgo6iBrIY9VJLmHQAAAKQ"]
[Thu Jul 30 14:51:30.368542 2026] [security2:error] [pid 62112:tid 62273] [client 31.3.152.100:52058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amurQsJgo6iBrIY9VJLmHQAAAKQ"]
[Thu Jul 30 14:51:30.401395 2026] [security2:error] [pid 62112:tid 62343] [client 52.238.199.152:58890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amurQsJgo6iBrIY9VJLmHgAAAOo"]
[Thu Jul 30 14:51:30.446581 2026] [security2:error] [pid 62112:tid 62338] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wpx.php"] [unique_id "amurQsJgo6iBrIY9VJLmHwAAAOU"]
[Thu Jul 30 14:51:30.446698 2026] [security2:error] [pid 62112:tid 62338] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wpx.php"] [unique_id "amurQsJgo6iBrIY9VJLmHwAAAOU"]
[Thu Jul 30 14:51:30.471431 2026] [security2:error] [pid 62112:tid 62319] [client 172.237.109.114:38675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurQcJgo6iBrIY9VJLmDgAAANI"]
[Thu Jul 30 14:51:31.059785 2026] [security2:error] [pid 62112:tid 62272] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/images.php"] [unique_id "amurQ8Jgo6iBrIY9VJLmKgAAAKM"]
[Thu Jul 30 14:51:31.059902 2026] [security2:error] [pid 62112:tid 62272] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/images.php"] [unique_id "amurQ8Jgo6iBrIY9VJLmKgAAAKM"]
[Thu Jul 30 14:51:31.594560 2026] [security2:error] [pid 62112:tid 62260] [client 20.91.199.21:3830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/images/about.php"] [unique_id "amurQ8Jgo6iBrIY9VJLmOAAAAJc"]
[Thu Jul 30 14:51:31.678015 2026] [security2:error] [pid 62112:tid 62307] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/1xmomo.php"] [unique_id "amurQ8Jgo6iBrIY9VJLmOQAAAMY"]
[Thu Jul 30 14:51:31.678120 2026] [security2:error] [pid 62112:tid 62307] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/1xmomo.php"] [unique_id "amurQ8Jgo6iBrIY9VJLmOQAAAMY"]
[Thu Jul 30 14:51:31.777228 2026] [security2:error] [pid 62112:tid 62309] [client 52.238.199.152:37476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amurQ8Jgo6iBrIY9VJLmPQAAAMg"]
[Thu Jul 30 14:51:31.785450 2026] [security2:error] [pid 62112:tid 62312] [client 180.102.110.166:52278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-white-blue/"] [unique_id "amurQ8Jgo6iBrIY9VJLmPwAAAMs"]
[Thu Jul 30 14:51:31.785637 2026] [security2:error] [pid 62112:tid 62312] [client 180.102.110.166:52278] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-white-blue/"] [unique_id "amurQ8Jgo6iBrIY9VJLmPwAAAMs"]
[Thu Jul 30 14:51:32.142485 2026] [security2:error] [pid 62112:tid 62320] [client 20.91.199.21:3973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amurRMJgo6iBrIY9VJLmSAAAANM"]
[Thu Jul 30 14:51:32.305090 2026] [security2:error] [pid 62112:tid 62352] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/1revo.php"] [unique_id "amurRMJgo6iBrIY9VJLmTgAAAPM"]
[Thu Jul 30 14:51:32.305186 2026] [security2:error] [pid 62112:tid 62352] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/1revo.php"] [unique_id "amurRMJgo6iBrIY9VJLmTgAAAPM"]
[Thu Jul 30 14:51:32.801450 2026] [security2:error] [pid 62112:tid 62301] [client 52.238.199.152:37449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/fonts/wp-login.php"] [unique_id "amurRMJgo6iBrIY9VJLmVgAAAMA"]
[Thu Jul 30 14:51:32.927734 2026] [security2:error] [pid 62112:tid 62298] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/cong.php"] [unique_id "amurRMJgo6iBrIY9VJLmXQAAAL0"]
[Thu Jul 30 14:51:32.927826 2026] [security2:error] [pid 62112:tid 62298] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/cong.php"] [unique_id "amurRMJgo6iBrIY9VJLmXQAAAL0"]
[Thu Jul 30 14:51:33.558358 2026] [security2:error] [pid 62112:tid 62275] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/a.php"] [unique_id "amurRcJgo6iBrIY9VJLmbAAAAKY"]
[Thu Jul 30 14:51:33.558520 2026] [security2:error] [pid 62112:tid 62275] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/a.php"] [unique_id "amurRcJgo6iBrIY9VJLmbAAAAKY"]
[Thu Jul 30 14:51:33.558887 2026] [security2:error] [pid 62112:tid 62323] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amurRMJgo6iBrIY9VJLmXAAAANY"]
[Thu Jul 30 14:51:33.797777 2026] [security2:error] [pid 62112:tid 62276] [client 20.91.199.21:3832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amurRcJgo6iBrIY9VJLmbgAAAKc"]
[Thu Jul 30 14:51:34.189876 2026] [security2:error] [pid 62112:tid 62266] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/srontol.php"] [unique_id "amurRsJgo6iBrIY9VJLmeAAAAJ0"]
[Thu Jul 30 14:51:34.190005 2026] [security2:error] [pid 62112:tid 62266] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/srontol.php"] [unique_id "amurRsJgo6iBrIY9VJLmeAAAAJ0"]
[Thu Jul 30 14:51:34.468864 2026] [core:error] [pid 62112:tid 62312] [client 87.99.130.230:44640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:34.468890 2026] [core:error] [pid 62112:tid 62312] [client 87.99.130.230:44640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:34.644006 2026] [security2:error] [pid 62112:tid 62365] [client 173.239.211.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyfluoxetine.store"] [uri "/wp-login.php"] [unique_id "amurRsJgo6iBrIY9VJLmgAAAAQA"]
[Thu Jul 30 14:51:34.667575 2026] [core:error] [pid 62112:tid 62311] [client 87.99.130.230:22214] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:34.667595 2026] [core:error] [pid 62112:tid 62311] [client 87.99.130.230:22214] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:34.813191 2026] [security2:error] [pid 62112:tid 62360] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/reop3.php"] [unique_id "amurRsJgo6iBrIY9VJLmjAAAAPs"]
[Thu Jul 30 14:51:34.813303 2026] [security2:error] [pid 62112:tid 62360] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/reop3.php"] [unique_id "amurRsJgo6iBrIY9VJLmjAAAAPs"]
[Thu Jul 30 14:51:35.383505 2026] [security2:error] [pid 62112:tid 62270] [client 189.156.226.90:27260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurR8Jgo6iBrIY9VJLmmAAAAKE"]
[Thu Jul 30 14:51:35.383610 2026] [security2:error] [pid 62112:tid 62270] [client 189.156.226.90:27260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurR8Jgo6iBrIY9VJLmmAAAAKE"]
[Thu Jul 30 14:51:35.452680 2026] [security2:error] [pid 62112:tid 62318] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/file5.php"] [unique_id "amurR8Jgo6iBrIY9VJLmnAAAANE"]
[Thu Jul 30 14:51:35.452828 2026] [security2:error] [pid 62112:tid 62318] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/file5.php"] [unique_id "amurR8Jgo6iBrIY9VJLmnAAAANE"]
[Thu Jul 30 14:51:36.006806 2026] [core:notice] [pid 62112:tid 62315] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:36.081366 2026] [security2:error] [pid 62112:tid 62323] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/domvf.php"] [unique_id "amurSMJgo6iBrIY9VJLmqQAAANY"]
[Thu Jul 30 14:51:36.081495 2026] [security2:error] [pid 62112:tid 62323] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/domvf.php"] [unique_id "amurSMJgo6iBrIY9VJLmqQAAANY"]
[Thu Jul 30 14:51:36.695026 2026] [security2:error] [pid 62112:tid 62255] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/zero.php"] [unique_id "amurSMJgo6iBrIY9VJLmuQAAAJI"]
[Thu Jul 30 14:51:36.695125 2026] [security2:error] [pid 62112:tid 62255] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/zero.php"] [unique_id "amurSMJgo6iBrIY9VJLmuQAAAJI"]
[Thu Jul 30 14:51:36.835142 2026] [security2:error] [pid 62112:tid 62260] [client 20.91.199.21:4016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amurSMJgo6iBrIY9VJLmvgAAAJc"]
[Thu Jul 30 14:51:36.986855 2026] [security2:error] [pid 62112:tid 62344] [client 43.173.179.92:43614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JSTE/about/privacy"] [unique_id "amurSMJgo6iBrIY9VJLmvQAAAOs"]
[Thu Jul 30 14:51:37.323342 2026] [security2:error] [pid 62112:tid 62320] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/002.php"] [unique_id "amurScJgo6iBrIY9VJLmyAAAANM"]
[Thu Jul 30 14:51:37.323487 2026] [security2:error] [pid 62112:tid 62320] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/002.php"] [unique_id "amurScJgo6iBrIY9VJLmyAAAANM"]
[Thu Jul 30 14:51:37.554246 2026] [core:notice] [pid 62112:tid 62349] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:37.800102 2026] [security2:error] [pid 62112:tid 62324] [client 52.238.199.152:57876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/themes.php"] [unique_id "amurScJgo6iBrIY9VJLm1gAAANc"]
[Thu Jul 30 14:51:37.943753 2026] [security2:error] [pid 62112:tid 62314] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/thoms.php"] [unique_id "amurScJgo6iBrIY9VJLm5gAAAM0"]
[Thu Jul 30 14:51:37.943882 2026] [security2:error] [pid 62112:tid 62314] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/thoms.php"] [unique_id "amurScJgo6iBrIY9VJLm5gAAAM0"]
[Thu Jul 30 14:51:37.947319 2026] [core:notice] [pid 62112:tid 62317] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:38.156000 2026] [core:notice] [pid 62112:tid 62319] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:38.563948 2026] [security2:error] [pid 62112:tid 62284] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fi22.php"] [unique_id "amurSsJgo6iBrIY9VJLnBAAAAK8"]
[Thu Jul 30 14:51:38.564077 2026] [security2:error] [pid 62112:tid 62284] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fi22.php"] [unique_id "amurSsJgo6iBrIY9VJLnBAAAAK8"]
[Thu Jul 30 14:51:39.155944 2026] [core:notice] [pid 62112:tid 62178] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:39.222348 2026] [security2:error] [pid 62112:tid 62338] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/wp-content/"] [unique_id "amurS8Jgo6iBrIY9VJLnJQAAAOU"]
[Thu Jul 30 14:51:39.612698 2026] [security2:error] [pid 62112:tid 62272] [client 52.238.199.152:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/if.php"] [unique_id "amurS8Jgo6iBrIY9VJLnLQAAAKM"]
[Thu Jul 30 14:51:39.643014 2026] [security2:error] [pid 62112:tid 62282] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/82.php"] [unique_id "amurS8Jgo6iBrIY9VJLnLgAAAK0"]
[Thu Jul 30 14:51:39.643111 2026] [security2:error] [pid 62112:tid 62282] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/82.php"] [unique_id "amurS8Jgo6iBrIY9VJLnLgAAAK0"]
[Thu Jul 30 14:51:39.889778 2026] [core:notice] [pid 62112:tid 62176] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:40.192859 2026] [security2:error] [pid 62112:tid 62262] [client 20.91.199.21:3586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/cloud.php"] [unique_id "amurTMJgo6iBrIY9VJLnPAAAAJk"]
[Thu Jul 30 14:51:40.296056 2026] [security2:error] [pid 62112:tid 62303] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sx.php"] [unique_id "amurTMJgo6iBrIY9VJLnQQAAAMI"]
[Thu Jul 30 14:51:40.296172 2026] [security2:error] [pid 62112:tid 62303] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sx.php"] [unique_id "amurTMJgo6iBrIY9VJLnQQAAAMI"]
[Thu Jul 30 14:51:40.336130 2026] [core:notice] [pid 62112:tid 62146] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:40.397900 2026] [core:notice] [pid 62112:tid 62142] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:40.560169 2026] [security2:error] [pid 62112:tid 62314] [client 94.154.43.184:50990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jesus.claims"] [uri "/.env"] [unique_id "amurTMJgo6iBrIY9VJLnRAAAAM0"]
[Thu Jul 30 14:51:40.795899 2026] [core:notice] [pid 62112:tid 62141] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:40.918825 2026] [security2:error] [pid 62112:tid 62361] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/dex.php"] [unique_id "amurTMJgo6iBrIY9VJLnUQAAAPw"]
[Thu Jul 30 14:51:40.918939 2026] [security2:error] [pid 62112:tid 62361] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/dex.php"] [unique_id "amurTMJgo6iBrIY9VJLnUQAAAPw"]
[Thu Jul 30 14:51:41.487140 2026] [core:notice] [pid 62112:tid 62174] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:41.487880 2026] [security2:error] [pid 62112:tid 62284] [client 172.237.109.114:30350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurTMJgo6iBrIY9VJLnUgAAAK8"]
[Thu Jul 30 14:51:41.561928 2026] [security2:error] [pid 62112:tid 62368] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fpwch.php"] [unique_id "amurTcJgo6iBrIY9VJLnYAAAAQM"]
[Thu Jul 30 14:51:41.562058 2026] [security2:error] [pid 62112:tid 62368] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fpwch.php"] [unique_id "amurTcJgo6iBrIY9VJLnYAAAAQM"]
[Thu Jul 30 14:51:41.879321 2026] [security2:error] [pid 62112:tid 62338] [client 94.154.43.186:38680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "clubnails.bonafideadvisors.com"] [uri "/.env"] [unique_id "amurTcJgo6iBrIY9VJLnawAAAOU"]
[Thu Jul 30 14:51:41.943313 2026] [core:notice] [pid 62112:tid 62185] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:41.972816 2026] [security2:error] [pid 62112:tid 62280] [client 20.91.199.21:3397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amurTcJgo6iBrIY9VJLnbQAAAKs"]
[Thu Jul 30 14:51:42.189331 2026] [security2:error] [pid 62112:tid 62309] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/black.php"] [unique_id "amurTsJgo6iBrIY9VJLnbgAAAMg"]
[Thu Jul 30 14:51:42.189443 2026] [security2:error] [pid 62112:tid 62309] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/black.php"] [unique_id "amurTsJgo6iBrIY9VJLnbgAAAMg"]
[Thu Jul 30 14:51:42.831833 2026] [security2:error] [pid 62112:tid 62297] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/loader.php"] [unique_id "amurTsJgo6iBrIY9VJLnfgAAALw"]
[Thu Jul 30 14:51:42.831925 2026] [security2:error] [pid 62112:tid 62297] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/loader.php"] [unique_id "amurTsJgo6iBrIY9VJLnfgAAALw"]
[Thu Jul 30 14:51:42.843030 2026] [security2:error] [pid 62112:tid 62364] [client 20.91.199.21:22668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/updates.php"] [unique_id "amurTsJgo6iBrIY9VJLngQAAAP8"]
[Thu Jul 30 14:51:43.017328 2026] [security2:error] [pid 62112:tid 62333] [client 52.238.199.152:37429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/editor.php"] [unique_id "amurT8Jgo6iBrIY9VJLnhgAAAOA"]
[Thu Jul 30 14:51:43.410790 2026] [core:notice] [pid 62112:tid 62182] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:43.502232 2026] [security2:error] [pid 62112:tid 62265] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/file61.php"] [unique_id "amurT8Jgo6iBrIY9VJLnkQAAAJw"]
[Thu Jul 30 14:51:43.502329 2026] [security2:error] [pid 62112:tid 62265] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/file61.php"] [unique_id "amurT8Jgo6iBrIY9VJLnkQAAAJw"]
[Thu Jul 30 14:51:44.157605 2026] [security2:error] [pid 62112:tid 62276] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-css.php"] [unique_id "amurUMJgo6iBrIY9VJLnnQAAAKc"]
[Thu Jul 30 14:51:44.157716 2026] [security2:error] [pid 62112:tid 62276] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-css.php"] [unique_id "amurUMJgo6iBrIY9VJLnnQAAAKc"]
[Thu Jul 30 14:51:44.290562 2026] [core:notice] [pid 62112:tid 62204] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:44.313100 2026] [security2:error] [pid 62112:tid 62290] [client 20.91.199.21:6172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/css/cloud.php"] [unique_id "amurUMJgo6iBrIY9VJLnogAAALU"]
[Thu Jul 30 14:51:44.772039 2026] [security2:error] [pid 62112:tid 62289] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-blink.php"] [unique_id "amurUMJgo6iBrIY9VJLnqQAAALQ"]
[Thu Jul 30 14:51:44.772156 2026] [security2:error] [pid 62112:tid 62289] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-blink.php"] [unique_id "amurUMJgo6iBrIY9VJLnqQAAALQ"]
[Thu Jul 30 14:51:45.389693 2026] [security2:error] [pid 62112:tid 62304] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/txets.php"] [unique_id "amurUcJgo6iBrIY9VJLntwAAAMM"]
[Thu Jul 30 14:51:45.389838 2026] [security2:error] [pid 62112:tid 62304] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/txets.php"] [unique_id "amurUcJgo6iBrIY9VJLntwAAAMM"]
[Thu Jul 30 14:51:45.996002 2026] [security2:error] [pid 62112:tid 62364] [client 189.156.226.90:27664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurUcJgo6iBrIY9VJLnwwAAAP8"]
[Thu Jul 30 14:51:45.996142 2026] [security2:error] [pid 62112:tid 62364] [client 189.156.226.90:27664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurUcJgo6iBrIY9VJLnwwAAAP8"]
[Thu Jul 30 14:51:46.008829 2026] [security2:error] [pid 62112:tid 62333] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/pucci.php"] [unique_id "amurUsJgo6iBrIY9VJLnxwAAAOA"]
[Thu Jul 30 14:51:46.008918 2026] [security2:error] [pid 62112:tid 62333] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/pucci.php"] [unique_id "amurUsJgo6iBrIY9VJLnxwAAAOA"]
[Thu Jul 30 14:51:46.127004 2026] [security2:error] [pid 62112:tid 62200] [remote 216.73.216.51:20325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amurUsJgo6iBrIY9VJLnywAAoVc"]
[Thu Jul 30 14:51:46.642324 2026] [security2:error] [pid 62112:tid 62339] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xwpg.php"] [unique_id "amurUsJgo6iBrIY9VJLn2gAAAOY"]
[Thu Jul 30 14:51:46.642429 2026] [security2:error] [pid 62112:tid 62339] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xwpg.php"] [unique_id "amurUsJgo6iBrIY9VJLn2gAAAOY"]
[Thu Jul 30 14:51:47.086836 2026] [core:notice] [pid 62112:tid 62214] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:47.205427 2026] [core:notice] [pid 62112:tid 62211] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:47.262136 2026] [security2:error] [pid 62112:tid 62274] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ops.php"] [unique_id "amurU8Jgo6iBrIY9VJLn5gAAAKU"]
[Thu Jul 30 14:51:47.262245 2026] [security2:error] [pid 62112:tid 62274] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ops.php"] [unique_id "amurU8Jgo6iBrIY9VJLn5gAAAKU"]
[Thu Jul 30 14:51:47.313825 2026] [core:notice] [pid 62112:tid 62120] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:47.329389 2026] [core:notice] [pid 62112:tid 62202] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:47.384755 2026] [core:notice] [pid 62112:tid 62223] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:47.409026 2026] [security2:error] [pid 62112:tid 62272] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amurU8Jgo6iBrIY9VJLn7gAAAKM"]
[Thu Jul 30 14:51:47.409123 2026] [security2:error] [pid 62112:tid 62272] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amurU8Jgo6iBrIY9VJLn7gAAAKM"]
[Thu Jul 30 14:51:47.414012 2026] [security2:error] [pid 62112:tid 62326] [client 20.91.199.21:6735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amurU8Jgo6iBrIY9VJLn7wAAANk"]
[Thu Jul 30 14:51:47.715819 2026] [security2:error] [pid 62112:tid 62365] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amurU8Jgo6iBrIY9VJLn9gAAAQA"]
[Thu Jul 30 14:51:47.715912 2026] [security2:error] [pid 62112:tid 62365] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amurU8Jgo6iBrIY9VJLn9gAAAQA"]
[Thu Jul 30 14:51:47.895291 2026] [security2:error] [pid 62112:tid 62242] [client 52.165.196.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/1.php"] [unique_id "amurU8Jgo6iBrIY9VJLn-AAAAIU"]
[Thu Jul 30 14:51:47.895401 2026] [security2:error] [pid 62112:tid 62242] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/1.php"] [unique_id "amurU8Jgo6iBrIY9VJLn-AAAAIU"]
[Thu Jul 30 14:51:47.895501 2026] [security2:error] [pid 62112:tid 62242] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/1.php"] [unique_id "amurU8Jgo6iBrIY9VJLn-AAAAIU"]
[Thu Jul 30 14:51:48.011266 2026] [security2:error] [pid 62112:tid 62262] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/xstelth.php"] [unique_id "amurVMJgo6iBrIY9VJLn_AAAAJk"]
[Thu Jul 30 14:51:48.011367 2026] [security2:error] [pid 62112:tid 62262] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/xstelth.php"] [unique_id "amurVMJgo6iBrIY9VJLn_AAAAJk"]
[Thu Jul 30 14:51:48.295856 2026] [security2:error] [pid 62112:tid 62364] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/584062352875874akp.php"] [unique_id "amurVMJgo6iBrIY9VJLoBAAAAP8"]
[Thu Jul 30 14:51:48.295956 2026] [security2:error] [pid 62112:tid 62364] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/584062352875874akp.php"] [unique_id "amurVMJgo6iBrIY9VJLoBAAAAP8"]
[Thu Jul 30 14:51:48.387006 2026] [security2:error] [pid 62112:tid 62334] [client 52.238.199.152:37390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/click.php"] [unique_id "amurVMJgo6iBrIY9VJLoBQAAAOE"]
[Thu Jul 30 14:51:48.478040 2026] [core:error] [pid 62112:tid 62236] [remote 74.7.244.9:51096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:48.478059 2026] [core:error] [pid 62112:tid 62236] [remote 74.7.244.9:51096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:48.478284 2026] [security2:error] [pid 62112:tid 62244] [client 74.7.244.9:51096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.carrescia.com"] [uri "/index.php"] [unique_id "amurVMJgo6iBrIY9VJLoBgAAh3s"]
[Thu Jul 30 14:51:48.510009 2026] [security2:error] [pid 62112:tid 62311] [client 20.91.199.21:5668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/img/cloud.php"] [unique_id "amurVMJgo6iBrIY9VJLoCgAAAMo"]
[Thu Jul 30 14:51:48.526667 2026] [security2:error] [pid 62112:tid 62314] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/mac.php"] [unique_id "amurVMJgo6iBrIY9VJLoCwAAAM0"]
[Thu Jul 30 14:51:48.526758 2026] [security2:error] [pid 62112:tid 62314] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/mac.php"] [unique_id "amurVMJgo6iBrIY9VJLoCwAAAM0"]
[Thu Jul 30 14:51:48.590417 2026] [security2:error] [pid 62112:tid 62270] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/newfile.php"] [unique_id "amurVMJgo6iBrIY9VJLoDAAAAKE"]
[Thu Jul 30 14:51:48.590511 2026] [security2:error] [pid 62112:tid 62270] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/newfile.php"] [unique_id "amurVMJgo6iBrIY9VJLoDAAAAKE"]
[Thu Jul 30 14:51:48.862061 2026] [security2:error] [pid 62112:tid 62301] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/tBEZGQz.php"] [unique_id "amurVMJgo6iBrIY9VJLoFAAAAMA"]
[Thu Jul 30 14:51:48.862191 2026] [security2:error] [pid 62112:tid 62301] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/tBEZGQz.php"] [unique_id "amurVMJgo6iBrIY9VJLoFAAAAMA"]
[Thu Jul 30 14:51:49.146943 2026] [security2:error] [pid 62112:tid 62339] [client 20.215.211.95:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/phpinfo"] [unique_id "amurVcJgo6iBrIY9VJLoGQAAAOY"]
[Thu Jul 30 14:51:49.147062 2026] [security2:error] [pid 62112:tid 62339] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/phpinfo"] [unique_id "amurVcJgo6iBrIY9VJLoGQAAAOY"]
[Thu Jul 30 14:51:49.164889 2026] [security2:error] [pid 62112:tid 62321] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-admin/js/index.php"] [unique_id "amurVcJgo6iBrIY9VJLoGgAAANQ"]
[Thu Jul 30 14:51:49.164968 2026] [security2:error] [pid 62112:tid 62321] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-admin/js/index.php"] [unique_id "amurVcJgo6iBrIY9VJLoGgAAANQ"]
[Thu Jul 30 14:51:49.348797 2026] [core:error] [pid 62112:tid 62188] [remote 40.77.167.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:49.348820 2026] [core:error] [pid 62112:tid 62188] [remote 40.77.167.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:49.658026 2026] [security2:error] [pid 62112:tid 62257] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/drykl.php"] [unique_id "amurVcJgo6iBrIY9VJLoJgAAAJQ"]
[Thu Jul 30 14:51:49.658136 2026] [security2:error] [pid 62112:tid 62257] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/drykl.php"] [unique_id "amurVcJgo6iBrIY9VJLoJgAAAJQ"]
[Thu Jul 30 14:51:49.806354 2026] [security2:error] [pid 62112:tid 62272] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/aa.php"] [unique_id "amurVcJgo6iBrIY9VJLoLgAAAKM"]
[Thu Jul 30 14:51:49.806436 2026] [security2:error] [pid 62112:tid 62272] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/aa.php"] [unique_id "amurVcJgo6iBrIY9VJLoLgAAAKM"]
[Thu Jul 30 14:51:49.961203 2026] [security2:error] [pid 62112:tid 62326] [client 20.215.211.95:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amurVcJgo6iBrIY9VJLoLwAAANk"]
[Thu Jul 30 14:51:49.961342 2026] [security2:error] [pid 62112:tid 62326] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amurVcJgo6iBrIY9VJLoLwAAANk"]
[Thu Jul 30 14:51:50.423567 2026] [security2:error] [pid 62112:tid 62277] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xyn.php"] [unique_id "amurVsJgo6iBrIY9VJLoOQAAAKg"]
[Thu Jul 30 14:51:50.423686 2026] [security2:error] [pid 62112:tid 62277] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xyn.php"] [unique_id "amurVsJgo6iBrIY9VJLoOQAAAKg"]
[Thu Jul 30 14:51:50.452020 2026] [security2:error] [pid 62112:tid 62365] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ls.php"] [unique_id "amurVsJgo6iBrIY9VJLoOgAAAQA"]
[Thu Jul 30 14:51:50.452111 2026] [security2:error] [pid 62112:tid 62365] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ls.php"] [unique_id "amurVsJgo6iBrIY9VJLoOgAAAQA"]
[Thu Jul 30 14:51:50.498759 2026] [security2:error] [pid 62112:tid 62323] [client 20.91.199.21:6768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amurVsJgo6iBrIY9VJLoOwAAANY"]
[Thu Jul 30 14:51:50.604178 2026] [security2:error] [pid 62112:tid 62247] [client 52.238.199.152:37411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/test.php7"] [unique_id "amurVsJgo6iBrIY9VJLoPAAAAIo"]
[Thu Jul 30 14:51:50.761826 2026] [security2:error] [pid 62112:tid 62320] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/dx.php"] [unique_id "amurVsJgo6iBrIY9VJLoRQAAANM"]
[Thu Jul 30 14:51:50.761992 2026] [security2:error] [pid 62112:tid 62320] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/dx.php"] [unique_id "amurVsJgo6iBrIY9VJLoRQAAANM"]
[Thu Jul 30 14:51:51.038316 2026] [security2:error] [pid 62112:tid 62261] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-wp.php"] [unique_id "amurV8Jgo6iBrIY9VJLoSQAAAJg"]
[Thu Jul 30 14:51:51.038419 2026] [security2:error] [pid 62112:tid 62261] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-wp.php"] [unique_id "amurV8Jgo6iBrIY9VJLoSQAAAJg"]
[Thu Jul 30 14:51:51.166735 2026] [security2:error] [pid 62112:tid 62286] [client 20.91.199.21:5641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amurV8Jgo6iBrIY9VJLoTQAAALE"]
[Thu Jul 30 14:51:51.277508 2026] [security2:error] [pid 62112:tid 62287] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/mac.php"] [unique_id "amurV8Jgo6iBrIY9VJLoUQAAALI"]
[Thu Jul 30 14:51:51.277666 2026] [security2:error] [pid 62112:tid 62287] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/mac.php"] [unique_id "amurV8Jgo6iBrIY9VJLoUQAAALI"]
[Thu Jul 30 14:51:51.518117 2026] [security2:error] [pid 62112:tid 62302] [client 172.237.109.114:52717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurV8Jgo6iBrIY9VJLoSAAAAME"]
[Thu Jul 30 14:51:51.555532 2026] [security2:error] [pid 62112:tid 62336] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/485.php"] [unique_id "amurV8Jgo6iBrIY9VJLoVwAAAOM"]
[Thu Jul 30 14:51:51.555647 2026] [security2:error] [pid 62112:tid 62336] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/485.php"] [unique_id "amurV8Jgo6iBrIY9VJLoVwAAAOM"]
[Thu Jul 30 14:51:51.681571 2026] [security2:error] [pid 62112:tid 62283] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/aw.php"] [unique_id "amurV8Jgo6iBrIY9VJLoWgAAAK4"]
[Thu Jul 30 14:51:51.681694 2026] [security2:error] [pid 62112:tid 62283] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/aw.php"] [unique_id "amurV8Jgo6iBrIY9VJLoWgAAAK4"]
[Thu Jul 30 14:51:51.891197 2026] [security2:error] [pid 62112:tid 62354] [client 49.51.196.42:34104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amurV8Jgo6iBrIY9VJLoVgAAAPU"]
[Thu Jul 30 14:51:51.972299 2026] [core:error] [pid 62112:tid 62161] [remote 216.73.216.175:39093] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:51.972323 2026] [core:error] [pid 62112:tid 62161] [remote 216.73.216.175:39093] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:52.007489 2026] [security2:error] [pid 62112:tid 62257] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gelio1.php"] [unique_id "amurWMJgo6iBrIY9VJLoZgAAAJQ"]
[Thu Jul 30 14:51:52.007591 2026] [security2:error] [pid 62112:tid 62257] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gelio1.php"] [unique_id "amurWMJgo6iBrIY9VJLoZgAAAJQ"]
[Thu Jul 30 14:51:52.125274 2026] [security2:error] [pid 62112:tid 62291] [client 52.238.199.152:57883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amurWMJgo6iBrIY9VJLoZwAAALY"]
[Thu Jul 30 14:51:52.228966 2026] [core:notice] [pid 62112:tid 62253] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:51:52.302321 2026] [security2:error] [pid 62112:tid 62326] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/lp6.php"] [unique_id "amurWMJgo6iBrIY9VJLobwAAANk"]
[Thu Jul 30 14:51:52.302444 2026] [security2:error] [pid 62112:tid 62326] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/lp6.php"] [unique_id "amurWMJgo6iBrIY9VJLobwAAANk"]
[Thu Jul 30 14:51:52.368443 2026] [security2:error] [pid 62112:tid 62281] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/classwithtostring.php"] [unique_id "amurWMJgo6iBrIY9VJLocAAAAKw"]
[Thu Jul 30 14:51:52.368549 2026] [security2:error] [pid 62112:tid 62281] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/classwithtostring.php"] [unique_id "amurWMJgo6iBrIY9VJLocAAAAKw"]
[Thu Jul 30 14:51:52.578253 2026] [security2:error] [pid 62112:tid 62344] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-admin/maint/admin.php"] [unique_id "amurWMJgo6iBrIY9VJLodAAAAOs"]
[Thu Jul 30 14:51:52.578369 2026] [security2:error] [pid 62112:tid 62344] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-admin/maint/admin.php"] [unique_id "amurWMJgo6iBrIY9VJLodAAAAOs"]
[Thu Jul 30 14:51:52.844376 2026] [security2:error] [pid 62112:tid 62293] [client 20.215.211.95:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-includes/sodium_compat/"] [unique_id "amurWMJgo6iBrIY9VJLoeAAAALg"]
[Thu Jul 30 14:51:52.844483 2026] [security2:error] [pid 62112:tid 62293] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-includes/sodium_compat/"] [unique_id "amurWMJgo6iBrIY9VJLoeAAAALg"]
[Thu Jul 30 14:51:52.924807 2026] [security2:error] [pid 62112:tid 62137] [remote 212.80.9.235:50328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amurWMJgo6iBrIY9VJLofAAAxhg"]
[Thu Jul 30 14:51:52.942070 2026] [security2:error] [pid 62112:tid 62264] [client 20.91.199.21:15982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/avaa.php"] [unique_id "amurWMJgo6iBrIY9VJLofwAAAJs"]
[Thu Jul 30 14:51:52.988918 2026] [security2:error] [pid 62112:tid 62294] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/yawa.php"] [unique_id "amurWMJgo6iBrIY9VJLogQAAALk"]
[Thu Jul 30 14:51:52.989031 2026] [security2:error] [pid 62112:tid 62294] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/yawa.php"] [unique_id "amurWMJgo6iBrIY9VJLogQAAALk"]
[Thu Jul 30 14:51:53.116170 2026] [security2:error] [pid 62112:tid 62286] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/w3llscc.php"] [unique_id "amurWcJgo6iBrIY9VJLohwAAALE"]
[Thu Jul 30 14:51:53.116267 2026] [security2:error] [pid 62112:tid 62286] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/w3llscc.php"] [unique_id "amurWcJgo6iBrIY9VJLohwAAALE"]
[Thu Jul 30 14:51:53.291964 2026] [security2:error] [pid 62112:tid 62355] [client 52.238.199.152:37416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/content.php"] [unique_id "amurWcJgo6iBrIY9VJLoiwAAAPY"]
[Thu Jul 30 14:51:53.399857 2026] [security2:error] [pid 62112:tid 62298] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/miru3.php"] [unique_id "amurWcJgo6iBrIY9VJLojgAAAL0"]
[Thu Jul 30 14:51:53.399995 2026] [security2:error] [pid 62112:tid 62298] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/miru3.php"] [unique_id "amurWcJgo6iBrIY9VJLojgAAAL0"]
[Thu Jul 30 14:51:53.559331 2026] [security2:error] [pid 62112:tid 62297] [client 172.237.109.114:24723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurWcJgo6iBrIY9VJLogwAAALw"]
[Thu Jul 30 14:51:53.668511 2026] [security2:error] [pid 62112:tid 62342] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sym403.php"] [unique_id "amurWcJgo6iBrIY9VJLolAAAAOk"]
[Thu Jul 30 14:51:53.668624 2026] [security2:error] [pid 62112:tid 62342] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sym403.php"] [unique_id "amurWcJgo6iBrIY9VJLolAAAAOk"]
[Thu Jul 30 14:51:53.668961 2026] [security2:error] [pid 62112:tid 62315] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/autoload_classmap.php"] [unique_id "amurWcJgo6iBrIY9VJLolQAAAM4"]
[Thu Jul 30 14:51:53.669100 2026] [security2:error] [pid 62112:tid 62315] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/autoload_classmap.php"] [unique_id "amurWcJgo6iBrIY9VJLolQAAAM4"]
[Thu Jul 30 14:51:53.889110 2026] [security2:error] [pid 62112:tid 62318] [client 20.91.199.21:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/images/cloud.php"] [unique_id "amurWcJgo6iBrIY9VJLomQAAANE"]
[Thu Jul 30 14:51:53.939571 2026] [security2:error] [pid 62112:tid 62278] [client 20.215.211.95:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-content/"] [unique_id "amurWcJgo6iBrIY9VJLomgAAAKk"]
[Thu Jul 30 14:51:53.939681 2026] [security2:error] [pid 62112:tid 62278] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-content/"] [unique_id "amurWcJgo6iBrIY9VJLomgAAAKk"]
[Thu Jul 30 14:51:54.224780 2026] [security2:error] [pid 62112:tid 62250] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-content/themes/index.php"] [unique_id "amurWsJgo6iBrIY9VJLopAAAAI0"]
[Thu Jul 30 14:51:54.224890 2026] [security2:error] [pid 62112:tid 62250] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-content/themes/index.php"] [unique_id "amurWsJgo6iBrIY9VJLopAAAAI0"]
[Thu Jul 30 14:51:54.362366 2026] [security2:error] [pid 62112:tid 62274] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/colors/blue/"] [unique_id "amurWsJgo6iBrIY9VJLoqAAAAKU"]
[Thu Jul 30 14:51:54.500474 2026] [security2:error] [pid 62112:tid 62346] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/av.php"] [unique_id "amurWsJgo6iBrIY9VJLorQAAAO0"]
[Thu Jul 30 14:51:54.500626 2026] [security2:error] [pid 62112:tid 62346] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/av.php"] [unique_id "amurWsJgo6iBrIY9VJLorQAAAO0"]
[Thu Jul 30 14:51:54.778416 2026] [security2:error] [pid 62112:tid 62323] [client 20.215.211.95:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-includes/l10n/"] [unique_id "amurWsJgo6iBrIY9VJLosgAAANY"]
[Thu Jul 30 14:51:54.778526 2026] [security2:error] [pid 62112:tid 62323] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-includes/l10n/"] [unique_id "amurWsJgo6iBrIY9VJLosgAAANY"]
[Thu Jul 30 14:51:54.840507 2026] [security2:error] [pid 62112:tid 62320] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/adminner.php"] [unique_id "amurWsJgo6iBrIY9VJLotQAAANM"]
[Thu Jul 30 14:51:54.840691 2026] [security2:error] [pid 62112:tid 62320] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/adminner.php"] [unique_id "amurWsJgo6iBrIY9VJLotQAAANM"]
[Thu Jul 30 14:51:55.077082 2026] [security2:error] [pid 62112:tid 62364] [client 20.215.211.95:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amurW8Jgo6iBrIY9VJLovQAAAP8"]
[Thu Jul 30 14:51:55.077167 2026] [security2:error] [pid 62112:tid 62364] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wordpress/wp-admin/maint/"] [unique_id "amurW8Jgo6iBrIY9VJLovQAAAP8"]
[Thu Jul 30 14:51:55.122242 2026] [security2:error] [pid 62112:tid 62281] [client 20.91.199.21:6771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amurW8Jgo6iBrIY9VJLovwAAAKw"]
[Thu Jul 30 14:51:55.348424 2026] [security2:error] [pid 62112:tid 62270] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/tiny.php"] [unique_id "amurW8Jgo6iBrIY9VJLowwAAAKE"]
[Thu Jul 30 14:51:55.348535 2026] [security2:error] [pid 62112:tid 62270] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/tiny.php"] [unique_id "amurW8Jgo6iBrIY9VJLowwAAAKE"]
[Thu Jul 30 14:51:55.470795 2026] [security2:error] [pid 62112:tid 62273] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/yup.php"] [unique_id "amurW8Jgo6iBrIY9VJLoxwAAAKQ"]
[Thu Jul 30 14:51:55.470900 2026] [security2:error] [pid 62112:tid 62273] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/yup.php"] [unique_id "amurW8Jgo6iBrIY9VJLoxwAAAKQ"]
[Thu Jul 30 14:51:55.633199 2026] [security2:error] [pid 62112:tid 62258] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amurW8Jgo6iBrIY9VJLoywAAAJU"]
[Thu Jul 30 14:51:55.633350 2026] [security2:error] [pid 62112:tid 62258] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/BsMPQ6Wavdefault.php"] [unique_id "amurW8Jgo6iBrIY9VJLoywAAAJU"]
[Thu Jul 30 14:51:55.916087 2026] [security2:error] [pid 62112:tid 62295] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/zrrhj.php"] [unique_id "amurW8Jgo6iBrIY9VJLo0AAAALo"]
[Thu Jul 30 14:51:55.916189 2026] [security2:error] [pid 62112:tid 62295] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/zrrhj.php"] [unique_id "amurW8Jgo6iBrIY9VJLo0AAAALo"]
[Thu Jul 30 14:51:56.117965 2026] [security2:error] [pid 62112:tid 62339] [client 202.76.184.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amurW8Jgo6iBrIY9VJLo0wAAAOY"]
[Thu Jul 30 14:51:56.133914 2026] [security2:error] [pid 62112:tid 62156] [remote 216.73.216.51:10038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amurXMJgo6iBrIY9VJLo2gAA6is"]
[Thu Jul 30 14:51:56.139537 2026] [security2:error] [pid 62112:tid 62276] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/config.json.php"] [unique_id "amurXMJgo6iBrIY9VJLo2wAAAKc"]
[Thu Jul 30 14:51:56.139621 2026] [security2:error] [pid 62112:tid 62276] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/config.json.php"] [unique_id "amurXMJgo6iBrIY9VJLo2wAAAKc"]
[Thu Jul 30 14:51:56.199861 2026] [security2:error] [pid 62112:tid 62354] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amurXMJgo6iBrIY9VJLo3QAAAPU"]
[Thu Jul 30 14:51:56.199961 2026] [security2:error] [pid 62112:tid 62354] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amurXMJgo6iBrIY9VJLo3QAAAPU"]
[Thu Jul 30 14:51:56.266221 2026] [security2:error] [pid 62112:tid 62366] [client 52.238.199.152:57872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/.well-known.php"] [unique_id "amurXMJgo6iBrIY9VJLo3gAAAQE"]
[Thu Jul 30 14:51:56.478148 2026] [security2:error] [pid 62112:tid 62289] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wpgum.php"] [unique_id "amurXMJgo6iBrIY9VJLo4gAAALQ"]
[Thu Jul 30 14:51:56.478261 2026] [security2:error] [pid 62112:tid 62289] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wpgum.php"] [unique_id "amurXMJgo6iBrIY9VJLo4gAAALQ"]
[Thu Jul 30 14:51:56.528012 2026] [security2:error] [pid 62112:tid 62321] [client 189.156.226.90:27707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurXMJgo6iBrIY9VJLo4wAAANQ"]
[Thu Jul 30 14:51:56.528113 2026] [security2:error] [pid 62112:tid 62321] [client 189.156.226.90:27707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurXMJgo6iBrIY9VJLo4wAAANQ"]
[Thu Jul 30 14:51:56.750354 2026] [security2:error] [pid 62112:tid 62346] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ywwbf.php"] [unique_id "amurXMJgo6iBrIY9VJLo6wAAAO0"]
[Thu Jul 30 14:51:56.750471 2026] [security2:error] [pid 62112:tid 62346] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ywwbf.php"] [unique_id "amurXMJgo6iBrIY9VJLo6wAAAO0"]
[Thu Jul 30 14:51:56.799642 2026] [security2:error] [pid 62112:tid 62309] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/wp-includes/block-bindings/"] [unique_id "amurXMJgo6iBrIY9VJLo7AAAAMg"]
[Thu Jul 30 14:51:57.001144 2026] [core:error] [pid 62112:tid 62133] [remote 52.167.144.141:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:57.001169 2026] [core:error] [pid 62112:tid 62133] [remote 52.167.144.141:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:51:57.042075 2026] [security2:error] [pid 62112:tid 62352] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/xoldj.php"] [unique_id "amurXcJgo6iBrIY9VJLo8gAAAPM"]
[Thu Jul 30 14:51:57.042174 2026] [security2:error] [pid 62112:tid 62352] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/xoldj.php"] [unique_id "amurXcJgo6iBrIY9VJLo8gAAAPM"]
[Thu Jul 30 14:51:57.216273 2026] [security2:error] [pid 62112:tid 62262] [client 138.199.60.23:35220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dhowcruisedinner.com"] [uri "/wp-json/batch/v1"] [unique_id "amurXcJgo6iBrIY9VJLo-QAAAJk"]
[Thu Jul 30 14:51:57.231264 2026] [security2:error] [pid 62112:tid 62369] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/2.php"] [unique_id "amurXcJgo6iBrIY9VJLo-gAAAQQ"]
[Thu Jul 30 14:51:57.231347 2026] [security2:error] [pid 62112:tid 62369] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/2.php"] [unique_id "amurXcJgo6iBrIY9VJLo-gAAAQQ"]
[Thu Jul 30 14:51:57.316252 2026] [security2:error] [pid 62112:tid 62364] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/f35.php"] [unique_id "amurXcJgo6iBrIY9VJLo_AAAAP8"]
[Thu Jul 30 14:51:57.316358 2026] [security2:error] [pid 62112:tid 62364] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/f35.php"] [unique_id "amurXcJgo6iBrIY9VJLo_AAAAP8"]
[Thu Jul 30 14:51:57.557123 2026] [security2:error] [pid 62112:tid 62304] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurXMJgo6iBrIY9VJLo7QAAwzI"]
[Thu Jul 30 14:51:57.809685 2026] [security2:error] [pid 62112:tid 62313] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gk.php"] [unique_id "amurXcJgo6iBrIY9VJLpCAAAAMw"]
[Thu Jul 30 14:51:57.809798 2026] [security2:error] [pid 62112:tid 62313] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gk.php"] [unique_id "amurXcJgo6iBrIY9VJLpCAAAAMw"]
[Thu Jul 30 14:51:57.865147 2026] [security2:error] [pid 62112:tid 62363] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/f35.update.php"] [unique_id "amurXcJgo6iBrIY9VJLpCQAAAP4"]
[Thu Jul 30 14:51:57.865259 2026] [security2:error] [pid 62112:tid 62363] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/f35.update.php"] [unique_id "amurXcJgo6iBrIY9VJLpCQAAAP4"]
[Thu Jul 30 14:51:58.018558 2026] [security2:error] [pid 62112:tid 62312] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurXcJgo6iBrIY9VJLo_QAAy1Y"]
[Thu Jul 30 14:51:58.115373 2026] [security2:error] [pid 62112:tid 62258] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/584062352875874akp.php"] [unique_id "amurXsJgo6iBrIY9VJLpDQAAAJU"]
[Thu Jul 30 14:51:58.115524 2026] [security2:error] [pid 62112:tid 62258] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/584062352875874akp.php"] [unique_id "amurXsJgo6iBrIY9VJLpDQAAAJU"]
[Thu Jul 30 14:51:58.411508 2026] [security2:error] [pid 62112:tid 62279] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wper3.php"] [unique_id "amurXsJgo6iBrIY9VJLpGAAAAKo"]
[Thu Jul 30 14:51:58.411617 2026] [security2:error] [pid 62112:tid 62279] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wper3.php"] [unique_id "amurXsJgo6iBrIY9VJLpGAAAAKo"]
[Thu Jul 30 14:51:58.483490 2026] [security2:error] [pid 62112:tid 62318] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/k.php"] [unique_id "amurXsJgo6iBrIY9VJLpHAAAANE"]
[Thu Jul 30 14:51:58.483641 2026] [security2:error] [pid 62112:tid 62318] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/k.php"] [unique_id "amurXsJgo6iBrIY9VJLpHAAAANE"]
[Thu Jul 30 14:51:58.654856 2026] [security2:error] [pid 62112:tid 62278] [client 138.199.60.23:35226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dhowcruisedinner.com"] [uri "/"] [unique_id "amurXsJgo6iBrIY9VJLpHQAAAKk"]
[Thu Jul 30 14:51:58.706902 2026] [security2:error] [pid 62112:tid 62296] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/bthil.php"] [unique_id "amurXsJgo6iBrIY9VJLpIQAAALs"]
[Thu Jul 30 14:51:58.707016 2026] [security2:error] [pid 62112:tid 62296] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/bthil.php"] [unique_id "amurXsJgo6iBrIY9VJLpIQAAALs"]
[Thu Jul 30 14:51:58.984643 2026] [security2:error] [pid 62112:tid 62274] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wyzer1.php"] [unique_id "amurXsJgo6iBrIY9VJLpKQAAAKU"]
[Thu Jul 30 14:51:58.984774 2026] [security2:error] [pid 62112:tid 62274] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wyzer1.php"] [unique_id "amurXsJgo6iBrIY9VJLpKQAAAKU"]
[Thu Jul 30 14:51:59.148756 2026] [security2:error] [pid 62112:tid 62246] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/wp-admin/css/"] [unique_id "amurX8Jgo6iBrIY9VJLpKgAAAIk"]
[Thu Jul 30 14:51:59.267416 2026] [security2:error] [pid 62112:tid 62250] [client 20.91.199.21:15956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amurX8Jgo6iBrIY9VJLpLwAAAI0"]
[Thu Jul 30 14:51:59.282842 2026] [security2:error] [pid 62112:tid 62330] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/mh.php"] [unique_id "amurX8Jgo6iBrIY9VJLpMwAAAN0"]
[Thu Jul 30 14:51:59.282919 2026] [security2:error] [pid 62112:tid 62330] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/mh.php"] [unique_id "amurX8Jgo6iBrIY9VJLpMwAAAN0"]
[Thu Jul 30 14:51:59.573025 2026] [security2:error] [pid 62112:tid 62292] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/spadex.php"] [unique_id "amurX8Jgo6iBrIY9VJLpPwAAALc"]
[Thu Jul 30 14:51:59.573119 2026] [security2:error] [pid 62112:tid 62292] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/spadex.php"] [unique_id "amurX8Jgo6iBrIY9VJLpPwAAALc"]
[Thu Jul 30 14:51:59.574520 2026] [security2:error] [pid 62112:tid 62323] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amurX8Jgo6iBrIY9VJLpQAAAANY"]
[Thu Jul 30 14:51:59.574632 2026] [security2:error] [pid 62112:tid 62323] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gvg1bvpsgtot1rpklCdefault.php"] [unique_id "amurX8Jgo6iBrIY9VJLpQAAAANY"]
[Thu Jul 30 14:51:59.857925 2026] [security2:error] [pid 62112:tid 62324] [client 20.215.211.95:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/1.php"] [unique_id "amurX8Jgo6iBrIY9VJLpSQAAANc"]
[Thu Jul 30 14:51:59.858062 2026] [security2:error] [pid 62112:tid 62324] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/1.php"] [unique_id "amurX8Jgo6iBrIY9VJLpSQAAANc"]
[Thu Jul 30 14:51:59.858196 2026] [security2:error] [pid 62112:tid 62324] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/1.php"] [unique_id "amurX8Jgo6iBrIY9VJLpSQAAANc"]
[Thu Jul 30 14:52:00.075121 2026] [security2:error] [pid 62112:tid 62317] [client 20.91.199.21:12189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amurYMJgo6iBrIY9VJLpSwAAANA"]
[Thu Jul 30 14:52:00.192344 2026] [security2:error] [pid 62112:tid 62351] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/mg.php"] [unique_id "amurYMJgo6iBrIY9VJLpTAAAAPI"]
[Thu Jul 30 14:52:00.192470 2026] [security2:error] [pid 62112:tid 62351] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/mg.php"] [unique_id "amurYMJgo6iBrIY9VJLpTAAAAPI"]
[Thu Jul 30 14:52:00.498610 2026] [security2:error] [pid 62112:tid 62367] [client 172.237.109.114:50128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurYMJgo6iBrIY9VJLpSgAAAQI"]
[Thu Jul 30 14:52:00.756458 2026] [security2:error] [pid 62112:tid 62322] [client 52.238.199.152:37418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "amurYMJgo6iBrIY9VJLpYAAAANU"]
[Thu Jul 30 14:52:00.817842 2026] [security2:error] [pid 62112:tid 62338] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fnstall.php"] [unique_id "amurYMJgo6iBrIY9VJLpZAAAAOU"]
[Thu Jul 30 14:52:00.817931 2026] [security2:error] [pid 62112:tid 62338] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fnstall.php"] [unique_id "amurYMJgo6iBrIY9VJLpZAAAAOU"]
[Thu Jul 30 14:52:01.025882 2026] [security2:error] [pid 62112:tid 62278] [client 20.91.199.21:6782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amurYcJgo6iBrIY9VJLpbAAAAKk"]
[Thu Jul 30 14:52:01.432230 2026] [security2:error] [pid 62112:tid 62287] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ortasekerli1.php"] [unique_id "amurYcJgo6iBrIY9VJLpdQAAALI"]
[Thu Jul 30 14:52:01.432385 2026] [security2:error] [pid 62112:tid 62287] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ortasekerli1.php"] [unique_id "amurYcJgo6iBrIY9VJLpdQAAALI"]
[Thu Jul 30 14:52:01.733636 2026] [security2:error] [pid 62112:tid 62244] [client 52.238.199.152:58907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/themes/twenty/twenty.php"] [unique_id "amurYcJgo6iBrIY9VJLpfQAAAIc"]
[Thu Jul 30 14:52:02.067884 2026] [security2:error] [pid 62112:tid 62336] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sump1.php"] [unique_id "amurYsJgo6iBrIY9VJLpjAAAAOM"]
[Thu Jul 30 14:52:02.068009 2026] [security2:error] [pid 62112:tid 62336] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sump1.php"] [unique_id "amurYsJgo6iBrIY9VJLpjAAAAOM"]
[Thu Jul 30 14:52:02.325829 2026] [core:notice] [pid 62112:tid 62358] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:02.543398 2026] [security2:error] [pid 62112:tid 62317] [client 20.91.199.21:13851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amurYsJgo6iBrIY9VJLplAAAANA"]
[Thu Jul 30 14:52:02.690828 2026] [security2:error] [pid 62112:tid 62260] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ops.php"] [unique_id "amurYsJgo6iBrIY9VJLpnQAAAJc"]
[Thu Jul 30 14:52:02.690915 2026] [security2:error] [pid 62112:tid 62260] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ops.php"] [unique_id "amurYsJgo6iBrIY9VJLpnQAAAJc"]
[Thu Jul 30 14:52:02.916151 2026] [security2:error] [pid 62112:tid 62275] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/chosen.php"] [unique_id "amurYsJgo6iBrIY9VJLpngAAAKY"]
[Thu Jul 30 14:52:02.916278 2026] [security2:error] [pid 62112:tid 62275] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/chosen.php"] [unique_id "amurYsJgo6iBrIY9VJLpngAAAKY"]
[Thu Jul 30 14:52:02.976110 2026] [security2:error] [pid 62112:tid 62340] [client 52.238.199.152:58901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amurYsJgo6iBrIY9VJLpnwAAAOc"]
[Thu Jul 30 14:52:03.192086 2026] [security2:error] [pid 62112:tid 62344] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/sd.php"] [unique_id "amurY8Jgo6iBrIY9VJLpqQAAAOs"]
[Thu Jul 30 14:52:03.192178 2026] [security2:error] [pid 62112:tid 62344] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/sd.php"] [unique_id "amurY8Jgo6iBrIY9VJLpqQAAAOs"]
[Thu Jul 30 14:52:03.310060 2026] [security2:error] [pid 62112:tid 62292] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-post-data.php"] [unique_id "amurY8Jgo6iBrIY9VJLpqgAAALc"]
[Thu Jul 30 14:52:03.310171 2026] [security2:error] [pid 62112:tid 62292] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-post-data.php"] [unique_id "amurY8Jgo6iBrIY9VJLpqgAAALc"]
[Thu Jul 30 14:52:03.481900 2026] [security2:error] [pid 62112:tid 62286] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/z60.php"] [unique_id "amurY8Jgo6iBrIY9VJLpqwAAALE"]
[Thu Jul 30 14:52:03.482030 2026] [security2:error] [pid 62112:tid 62286] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/z60.php"] [unique_id "amurY8Jgo6iBrIY9VJLpqwAAALE"]
[Thu Jul 30 14:52:03.755602 2026] [security2:error] [pid 62112:tid 62299] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/home.php"] [unique_id "amurY8Jgo6iBrIY9VJLpuAAAAL4"]
[Thu Jul 30 14:52:03.755698 2026] [security2:error] [pid 62112:tid 62299] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/home.php"] [unique_id "amurY8Jgo6iBrIY9VJLpuAAAAL4"]
[Thu Jul 30 14:52:03.952263 2026] [security2:error] [pid 62112:tid 62259] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/root.php"] [unique_id "amurY8Jgo6iBrIY9VJLpuQAAAJY"]
[Thu Jul 30 14:52:03.952376 2026] [security2:error] [pid 62112:tid 62259] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/root.php"] [unique_id "amurY8Jgo6iBrIY9VJLpuQAAAJY"]
[Thu Jul 30 14:52:04.034378 2026] [security2:error] [pid 62112:tid 62312] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ws58.php"] [unique_id "amurZMJgo6iBrIY9VJLpugAAAMs"]
[Thu Jul 30 14:52:04.034496 2026] [security2:error] [pid 62112:tid 62312] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ws58.php"] [unique_id "amurZMJgo6iBrIY9VJLpugAAAMs"]
[Thu Jul 30 14:52:04.311253 2026] [security2:error] [pid 62112:tid 62301] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gulu.php"] [unique_id "amurZMJgo6iBrIY9VJLpxAAAAMA"]
[Thu Jul 30 14:52:04.311344 2026] [security2:error] [pid 62112:tid 62301] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/gulu.php"] [unique_id "amurZMJgo6iBrIY9VJLpxAAAAMA"]
[Thu Jul 30 14:52:04.318890 2026] [security2:error] [pid 62112:tid 62244] [client 20.91.199.21:12210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/cloud.php"] [unique_id "amurZMJgo6iBrIY9VJLpxQAAAIc"]
[Thu Jul 30 14:52:04.522524 2026] [security2:error] [pid 62112:tid 62302] [client 52.238.199.152:58911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/css/about.php"] [unique_id "amurZMJgo6iBrIY9VJLpyQAAAME"]
[Thu Jul 30 14:52:04.566162 2026] [security2:error] [pid 62112:tid 62276] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/v543.php"] [unique_id "amurZMJgo6iBrIY9VJLpygAAAKc"]
[Thu Jul 30 14:52:04.566267 2026] [security2:error] [pid 62112:tid 62276] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/v543.php"] [unique_id "amurZMJgo6iBrIY9VJLpygAAAKc"]
[Thu Jul 30 14:52:04.596382 2026] [security2:error] [pid 62112:tid 62353] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amurZMJgo6iBrIY9VJLpywAAAPQ"]
[Thu Jul 30 14:52:04.596472 2026] [security2:error] [pid 62112:tid 62353] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/6xBAm3vODE05BSzkJZRAws.php"] [unique_id "amurZMJgo6iBrIY9VJLpywAAAPQ"]
[Thu Jul 30 14:52:04.876170 2026] [security2:error] [pid 62112:tid 62272] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wpls.php"] [unique_id "amurZMJgo6iBrIY9VJLp1QAAAKM"]
[Thu Jul 30 14:52:04.876283 2026] [security2:error] [pid 62112:tid 62272] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wpls.php"] [unique_id "amurZMJgo6iBrIY9VJLp1QAAAKM"]
[Thu Jul 30 14:52:05.136208 2026] [security2:error] [pid 62112:tid 62121] [remote 65.181.116.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frontierphoenix.site"] [uri "/wp-login.php"] [unique_id "amurZcJgo6iBrIY9VJLp2QAArwg"]
[Thu Jul 30 14:52:05.156054 2026] [security2:error] [pid 62112:tid 62305] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/php.php"] [unique_id "amurZcJgo6iBrIY9VJLp2gAAAMQ"]
[Thu Jul 30 14:52:05.156151 2026] [security2:error] [pid 62112:tid 62305] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/php.php"] [unique_id "amurZcJgo6iBrIY9VJLp2gAAAMQ"]
[Thu Jul 30 14:52:05.179399 2026] [security2:error] [pid 62112:tid 62349] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sixxis.php"] [unique_id "amurZcJgo6iBrIY9VJLp2wAAAPA"]
[Thu Jul 30 14:52:05.179481 2026] [security2:error] [pid 62112:tid 62349] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sixxis.php"] [unique_id "amurZcJgo6iBrIY9VJLp2wAAAPA"]
[Thu Jul 30 14:52:05.434845 2026] [security2:error] [pid 62112:tid 62307] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/100.php"] [unique_id "amurZcJgo6iBrIY9VJLp4wAAAMY"]
[Thu Jul 30 14:52:05.434947 2026] [security2:error] [pid 62112:tid 62307] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/100.php"] [unique_id "amurZcJgo6iBrIY9VJLp4wAAAMY"]
[Thu Jul 30 14:52:05.448743 2026] [security2:error] [pid 62112:tid 62246] [client 52.238.199.152:36535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amurZcJgo6iBrIY9VJLp5AAAAIk"]
[Thu Jul 30 14:52:05.552086 2026] [security2:error] [pid 62112:tid 62249] [client 20.91.199.21:13869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/updates.php"] [unique_id "amurZcJgo6iBrIY9VJLp5gAAAIw"]
[Thu Jul 30 14:52:05.709600 2026] [security2:error] [pid 62112:tid 62294] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/BDKR28WP.php"] [unique_id "amurZcJgo6iBrIY9VJLp7gAAALk"]
[Thu Jul 30 14:52:05.709696 2026] [security2:error] [pid 62112:tid 62294] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/BDKR28WP.php"] [unique_id "amurZcJgo6iBrIY9VJLp7gAAALk"]
[Thu Jul 30 14:52:05.789553 2026] [security2:error] [pid 62112:tid 62352] [client 141.94.94.46:56376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurZcJgo6iBrIY9VJLp4gAAAPM"]
[Thu Jul 30 14:52:05.804200 2026] [security2:error] [pid 62112:tid 62311] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ip.php"] [unique_id "amurZcJgo6iBrIY9VJLp9QAAAMo"]
[Thu Jul 30 14:52:05.804300 2026] [security2:error] [pid 62112:tid 62311] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ip.php"] [unique_id "amurZcJgo6iBrIY9VJLp9QAAAMo"]
[Thu Jul 30 14:52:06.002067 2026] [security2:error] [pid 62112:tid 62268] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/browse.php"] [unique_id "amurZsJgo6iBrIY9VJLp9gAAAJ8"]
[Thu Jul 30 14:52:06.002184 2026] [security2:error] [pid 62112:tid 62268] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/browse.php"] [unique_id "amurZsJgo6iBrIY9VJLp9gAAAJ8"]
[Thu Jul 30 14:52:06.295891 2026] [security2:error] [pid 62112:tid 62312] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-good.php"] [unique_id "amurZsJgo6iBrIY9VJLp_QAAAMs"]
[Thu Jul 30 14:52:06.296273 2026] [security2:error] [pid 62112:tid 62312] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-good.php"] [unique_id "amurZsJgo6iBrIY9VJLp_QAAAMs"]
[Thu Jul 30 14:52:06.525140 2026] [security2:error] [pid 62112:tid 62364] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/kq1.php"] [unique_id "amurZsJgo6iBrIY9VJLqAgAAAP8"]
[Thu Jul 30 14:52:06.525248 2026] [security2:error] [pid 62112:tid 62364] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/kq1.php"] [unique_id "amurZsJgo6iBrIY9VJLqAgAAAP8"]
[Thu Jul 30 14:52:06.609160 2026] [security2:error] [pid 62112:tid 62310] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/8573.php"] [unique_id "amurZsJgo6iBrIY9VJLqAwAAAMk"]
[Thu Jul 30 14:52:06.609271 2026] [security2:error] [pid 62112:tid 62310] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/8573.php"] [unique_id "amurZsJgo6iBrIY9VJLqAwAAAMk"]
[Thu Jul 30 14:52:06.671025 2026] [security2:error] [pid 62112:tid 62265] [client 185.191.171.18:62520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/10/19/piloes-em-luto-candidato-a-vereador-pitu-morre-apos-sofre-infarto/"] [unique_id "amurZsJgo6iBrIY9VJLqBwAAAJw"]
[Thu Jul 30 14:52:06.671153 2026] [security2:error] [pid 62112:tid 62265] [client 185.191.171.18:62520] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/10/19/piloes-em-luto-candidato-a-vereador-pitu-morre-apos-sofre-infarto/"] [unique_id "amurZsJgo6iBrIY9VJLqBwAAAJw"]
[Thu Jul 30 14:52:06.912606 2026] [security2:error] [pid 62112:tid 62339] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-admin/install.php"] [unique_id "amurZsJgo6iBrIY9VJLqDwAAAOY"]
[Thu Jul 30 14:52:06.912713 2026] [security2:error] [pid 62112:tid 62339] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-admin/install.php"] [unique_id "amurZsJgo6iBrIY9VJLqDwAAAOY"]
[Thu Jul 30 14:52:07.063361 2026] [security2:error] [pid 62112:tid 62263] [client 189.156.226.90:27008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqFAAAAJo"]
[Thu Jul 30 14:52:07.063465 2026] [security2:error] [pid 62112:tid 62263] [client 189.156.226.90:27008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqFAAAAJo"]
[Thu Jul 30 14:52:07.150073 2026] [security2:error] [pid 62112:tid 62358] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fw/faiyy.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqFQAAAPk"]
[Thu Jul 30 14:52:07.150194 2026] [security2:error] [pid 62112:tid 62358] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fw/faiyy.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqFQAAAPk"]
[Thu Jul 30 14:52:07.180520 2026] [security2:error] [pid 62112:tid 62345] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/classwithtostring.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqFgAAAOw"]
[Thu Jul 30 14:52:07.180650 2026] [security2:error] [pid 62112:tid 62345] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/classwithtostring.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqFgAAAOw"]
[Thu Jul 30 14:52:07.451675 2026] [security2:error] [pid 62112:tid 62340] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ohct.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqIwAAAOc"]
[Thu Jul 30 14:52:07.451795 2026] [security2:error] [pid 62112:tid 62340] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ohct.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqIwAAAOc"]
[Thu Jul 30 14:52:07.720162 2026] [security2:error] [pid 62112:tid 62256] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/bless.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqJQAAAJM"]
[Thu Jul 30 14:52:07.720302 2026] [security2:error] [pid 62112:tid 62256] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/bless.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqJQAAAJM"]
[Thu Jul 30 14:52:07.841662 2026] [security2:error] [pid 62112:tid 62360] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/h02ugyh.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqKgAAAPs"]
[Thu Jul 30 14:52:07.841773 2026] [security2:error] [pid 62112:tid 62360] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/h02ugyh.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqKgAAAPs"]
[Thu Jul 30 14:52:07.986832 2026] [security2:error] [pid 62112:tid 62352] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/about.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqNAAAAPM"]
[Thu Jul 30 14:52:07.986918 2026] [security2:error] [pid 62112:tid 62352] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/about.php"] [unique_id "amurZ8Jgo6iBrIY9VJLqNAAAAPM"]
[Thu Jul 30 14:52:08.253772 2026] [security2:error] [pid 62112:tid 62288] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuraMJgo6iBrIY9VJLqPgAAALM"]
[Thu Jul 30 14:52:08.253908 2026] [security2:error] [pid 62112:tid 62288] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/public/mI35rZhMg1zJ1vuXdefault.php"] [unique_id "amuraMJgo6iBrIY9VJLqPgAAALM"]
[Thu Jul 30 14:52:08.458577 2026] [security2:error] [pid 62112:tid 62351] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-temp.php"] [unique_id "amuraMJgo6iBrIY9VJLqQwAAAPI"]
[Thu Jul 30 14:52:08.458711 2026] [security2:error] [pid 62112:tid 62351] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-temp.php"] [unique_id "amuraMJgo6iBrIY9VJLqQwAAAPI"]
[Thu Jul 30 14:52:09.102608 2026] [security2:error] [pid 62112:tid 62319] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-content/cong.php"] [unique_id "amuracJgo6iBrIY9VJLqUQAAANI"]
[Thu Jul 30 14:52:09.102718 2026] [security2:error] [pid 62112:tid 62319] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-content/cong.php"] [unique_id "amuracJgo6iBrIY9VJLqUQAAANI"]
[Thu Jul 30 14:52:09.437272 2026] [security2:error] [pid 62112:tid 62356] [client 91.225.162.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuracJgo6iBrIY9VJLqVwAAAPc"], referer: https://cnpinyin.com
[Thu Jul 30 14:52:09.757335 2026] [security2:error] [pid 62112:tid 62272] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/wp-admin/js/widget/"] [unique_id "amuracJgo6iBrIY9VJLqXwAAAKM"]
[Thu Jul 30 14:52:09.762563 2026] [security2:error] [pid 62112:tid 62269] [client 185.191.171.16:56266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/05/08/preco-do-diesel-dispara-apos-fim-de-isencao-de-impostos-federais/"] [unique_id "amuracJgo6iBrIY9VJLqYgAAAKA"]
[Thu Jul 30 14:52:09.762661 2026] [security2:error] [pid 62112:tid 62269] [client 185.191.171.16:56266] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/05/08/preco-do-diesel-dispara-apos-fim-de-isencao-de-impostos-federais/"] [unique_id "amuracJgo6iBrIY9VJLqYgAAAKA"]
[Thu Jul 30 14:52:09.915182 2026] [security2:error] [pid 62112:tid 62340] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ta0ol.php"] [unique_id "amuracJgo6iBrIY9VJLqZwAAAOc"]
[Thu Jul 30 14:52:09.915341 2026] [security2:error] [pid 62112:tid 62340] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ta0ol.php"] [unique_id "amuracJgo6iBrIY9VJLqZwAAAOc"]
[Thu Jul 30 14:52:10.169822 2026] [security2:error] [pid 62112:tid 62360] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-includes/css/index.php"] [unique_id "amurasJgo6iBrIY9VJLqbwAAAPs"]
[Thu Jul 30 14:52:10.169940 2026] [security2:error] [pid 62112:tid 62360] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-includes/css/index.php"] [unique_id "amurasJgo6iBrIY9VJLqbwAAAPs"]
[Thu Jul 30 14:52:10.202518 2026] [security2:error] [pid 62112:tid 62293] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/sa.php7"] [unique_id "amurasJgo6iBrIY9VJLqcQAAALg"]
[Thu Jul 30 14:52:10.202684 2026] [security2:error] [pid 62112:tid 62293] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/sa.php7"] [unique_id "amurasJgo6iBrIY9VJLqcQAAALg"]
[Thu Jul 30 14:52:10.517581 2026] [security2:error] [pid 62112:tid 62320] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-class.php"] [unique_id "amurasJgo6iBrIY9VJLqdwAAANM"]
[Thu Jul 30 14:52:10.517714 2026] [security2:error] [pid 62112:tid 62320] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-class.php"] [unique_id "amurasJgo6iBrIY9VJLqdwAAANM"]
[Thu Jul 30 14:52:10.593337 2026] [core:notice] [pid 62112:tid 62294] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:10.827390 2026] [security2:error] [pid 62112:tid 62323] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/jj.php"] [unique_id "amurasJgo6iBrIY9VJLqfwAAANY"]
[Thu Jul 30 14:52:10.827498 2026] [security2:error] [pid 62112:tid 62323] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/jj.php"] [unique_id "amurasJgo6iBrIY9VJLqfwAAANY"]
[Thu Jul 30 14:52:10.837492 2026] [security2:error] [pid 62112:tid 62351] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/8.php"] [unique_id "amurasJgo6iBrIY9VJLqgAAAAPI"]
[Thu Jul 30 14:52:10.837591 2026] [security2:error] [pid 62112:tid 62351] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/8.php"] [unique_id "amurasJgo6iBrIY9VJLqgAAAAPI"]
[Thu Jul 30 14:52:11.129051 2026] [security2:error] [pid 62112:tid 62279] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/bootstrap.php"] [unique_id "amura8Jgo6iBrIY9VJLqhwAAAKo"]
[Thu Jul 30 14:52:11.129149 2026] [security2:error] [pid 62112:tid 62279] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/bootstrap.php"] [unique_id "amura8Jgo6iBrIY9VJLqhwAAAKo"]
[Thu Jul 30 14:52:11.228431 2026] [core:notice] [pid 62112:tid 62337] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:11.266869 2026] [security2:error] [pid 62112:tid 62369] [client 20.91.199.21:12661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amura8Jgo6iBrIY9VJLqiQAAAQQ"]
[Thu Jul 30 14:52:11.400594 2026] [core:notice] [pid 62112:tid 62253] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:11.403177 2026] [security2:error] [pid 62112:tid 62367] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-blog-header.php"] [unique_id "amura8Jgo6iBrIY9VJLqkAAAAQI"]
[Thu Jul 30 14:52:11.403285 2026] [security2:error] [pid 62112:tid 62367] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-blog-header.php"] [unique_id "amura8Jgo6iBrIY9VJLqkAAAAQI"]
[Thu Jul 30 14:52:11.450807 2026] [security2:error] [pid 62112:tid 62339] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/class-walker-footer-dev.php"] [unique_id "amura8Jgo6iBrIY9VJLqkgAAAOY"]
[Thu Jul 30 14:52:11.450928 2026] [security2:error] [pid 62112:tid 62339] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/class-walker-footer-dev.php"] [unique_id "amura8Jgo6iBrIY9VJLqkgAAAOY"]
[Thu Jul 30 14:52:11.686508 2026] [security2:error] [pid 62112:tid 62271] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/aa.php"] [unique_id "amura8Jgo6iBrIY9VJLqmgAAAKI"]
[Thu Jul 30 14:52:11.686610 2026] [security2:error] [pid 62112:tid 62271] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/aa.php"] [unique_id "amura8Jgo6iBrIY9VJLqmgAAAKI"]
[Thu Jul 30 14:52:11.749529 2026] [security2:error] [pid 62112:tid 62292] [client 52.238.199.152:37394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "amura8Jgo6iBrIY9VJLqmwAAALc"]
[Thu Jul 30 14:52:11.962520 2026] [security2:error] [pid 62112:tid 62277] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/tx79.php"] [unique_id "amura8Jgo6iBrIY9VJLqnwAAAKg"]
[Thu Jul 30 14:52:11.962637 2026] [security2:error] [pid 62112:tid 62277] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/tx79.php"] [unique_id "amura8Jgo6iBrIY9VJLqnwAAAKg"]
[Thu Jul 30 14:52:12.019097 2026] [security2:error] [pid 62112:tid 62302] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amura8Jgo6iBrIY9VJLqkQAAAME"]
[Thu Jul 30 14:52:12.031695 2026] [core:notice] [pid 62112:tid 62321] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:12.080700 2026] [security2:error] [pid 62112:tid 62289] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xpwer1.php"] [unique_id "amurbMJgo6iBrIY9VJLqpAAAALQ"]
[Thu Jul 30 14:52:12.080783 2026] [security2:error] [pid 62112:tid 62289] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xpwer1.php"] [unique_id "amurbMJgo6iBrIY9VJLqpAAAALQ"]
[Thu Jul 30 14:52:12.099986 2026] [security2:error] [pid 62112:tid 62185] [remote 161.18.228.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.228.18.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oceanscout.com"] [uri "/wp-login.php"] [unique_id "amurbMJgo6iBrIY9VJLqpQAA7Ug"]
[Thu Jul 30 14:52:12.241153 2026] [security2:error] [pid 62112:tid 62330] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/motu.php"] [unique_id "amurbMJgo6iBrIY9VJLqqQAAAN0"]
[Thu Jul 30 14:52:12.241255 2026] [security2:error] [pid 62112:tid 62330] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/motu.php"] [unique_id "amurbMJgo6iBrIY9VJLqqQAAAN0"]
[Thu Jul 30 14:52:12.649973 2026] [security2:error] [pid 62112:tid 62262] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-head.php"] [unique_id "amurbMJgo6iBrIY9VJLqswAAAJk"]
[Thu Jul 30 14:52:12.650081 2026] [security2:error] [pid 62112:tid 62262] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-head.php"] [unique_id "amurbMJgo6iBrIY9VJLqswAAAJk"]
[Thu Jul 30 14:52:12.719880 2026] [security2:error] [pid 62112:tid 62344] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/flox.php"] [unique_id "amurbMJgo6iBrIY9VJLqtAAAAOs"]
[Thu Jul 30 14:52:12.719971 2026] [security2:error] [pid 62112:tid 62344] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/flox.php"] [unique_id "amurbMJgo6iBrIY9VJLqtAAAAOs"]
[Thu Jul 30 14:52:12.943742 2026] [security2:error] [pid 62112:tid 62329] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-admin/options-privacy.php"] [unique_id "amurbMJgo6iBrIY9VJLquQAAANw"]
[Thu Jul 30 14:52:12.943873 2026] [security2:error] [pid 62112:tid 62329] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-admin/options-privacy.php"] [unique_id "amurbMJgo6iBrIY9VJLquQAAANw"]
[Thu Jul 30 14:52:13.224356 2026] [security2:error] [pid 62112:tid 62328] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/60856e3a4findex.php"] [unique_id "amurbcJgo6iBrIY9VJLqwwAAANs"]
[Thu Jul 30 14:52:13.224462 2026] [security2:error] [pid 62112:tid 62328] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/60856e3a4findex.php"] [unique_id "amurbcJgo6iBrIY9VJLqwwAAANs"]
[Thu Jul 30 14:52:13.335799 2026] [security2:error] [pid 62112:tid 62327] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/popo.php"] [unique_id "amurbcJgo6iBrIY9VJLqxAAAANo"]
[Thu Jul 30 14:52:13.335939 2026] [security2:error] [pid 62112:tid 62327] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/popo.php"] [unique_id "amurbcJgo6iBrIY9VJLqxAAAANo"]
[Thu Jul 30 14:52:13.500901 2026] [security2:error] [pid 62112:tid 62362] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-the.php"] [unique_id "amurbcJgo6iBrIY9VJLqyAAAAP0"]
[Thu Jul 30 14:52:13.501014 2026] [security2:error] [pid 62112:tid 62362] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp-the.php"] [unique_id "amurbcJgo6iBrIY9VJLqyAAAAP0"]
[Thu Jul 30 14:52:13.785989 2026] [security2:error] [pid 62112:tid 62345] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp.php"] [unique_id "amurbcJgo6iBrIY9VJLq1AAAAOw"]
[Thu Jul 30 14:52:13.786092 2026] [security2:error] [pid 62112:tid 62345] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wp.php"] [unique_id "amurbcJgo6iBrIY9VJLq1AAAAOw"]
[Thu Jul 30 14:52:13.960925 2026] [security2:error] [pid 62112:tid 62277] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/yas.php"] [unique_id "amurbcJgo6iBrIY9VJLq2AAAAKg"]
[Thu Jul 30 14:52:13.961050 2026] [security2:error] [pid 62112:tid 62277] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/yas.php"] [unique_id "amurbcJgo6iBrIY9VJLq2AAAAKg"]
[Thu Jul 30 14:52:14.066470 2026] [security2:error] [pid 62112:tid 62274] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/users.php"] [unique_id "amurbsJgo6iBrIY9VJLq2wAAAKU"]
[Thu Jul 30 14:52:14.066589 2026] [security2:error] [pid 62112:tid 62274] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/users.php"] [unique_id "amurbsJgo6iBrIY9VJLq2wAAAKU"]
[Thu Jul 30 14:52:14.125364 2026] [security2:error] [pid 62112:tid 62282] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurbcJgo6iBrIY9VJLqyQAArUM"]
[Thu Jul 30 14:52:14.232664 2026] [security2:error] [pid 62112:tid 62339] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amurbcJgo6iBrIY9VJLqzgAAAOY"]
[Thu Jul 30 14:52:14.353520 2026] [security2:error] [pid 62112:tid 62344] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/tinysd.php"] [unique_id "amurbsJgo6iBrIY9VJLq8QAAAOs"]
[Thu Jul 30 14:52:14.353640 2026] [security2:error] [pid 62112:tid 62344] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/tinysd.php"] [unique_id "amurbsJgo6iBrIY9VJLq8QAAAOs"]
[Thu Jul 30 14:52:14.419229 2026] [security2:error] [pid 62112:tid 62357] [client 20.91.199.21:18103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amurbsJgo6iBrIY9VJLq8gAAAPg"]
[Thu Jul 30 14:52:14.623398 2026] [security2:error] [pid 62112:tid 62352] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ws78.php"] [unique_id "amurbsJgo6iBrIY9VJLq8wAAAPM"]
[Thu Jul 30 14:52:14.623511 2026] [security2:error] [pid 62112:tid 62352] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ws78.php"] [unique_id "amurbsJgo6iBrIY9VJLq8wAAAPM"]
[Thu Jul 30 14:52:14.646335 2026] [security2:error] [pid 62112:tid 62284] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/water.php"] [unique_id "amurbsJgo6iBrIY9VJLq9AAAAK8"]
[Thu Jul 30 14:52:14.646441 2026] [security2:error] [pid 62112:tid 62284] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/water.php"] [unique_id "amurbsJgo6iBrIY9VJLq9AAAAK8"]
[Thu Jul 30 14:52:14.933932 2026] [security2:error] [pid 62112:tid 62258] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/elp.php"] [unique_id "amurbsJgo6iBrIY9VJLq_AAAAJU"]
[Thu Jul 30 14:52:14.934068 2026] [security2:error] [pid 62112:tid 62258] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/elp.php"] [unique_id "amurbsJgo6iBrIY9VJLq_AAAAJU"]
[Thu Jul 30 14:52:15.033040 2026] [security2:error] [pid 62112:tid 62294] [client 52.238.199.152:57856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/files.php"] [unique_id "amurb8Jgo6iBrIY9VJLrAAAAALk"]
[Thu Jul 30 14:52:15.201864 2026] [security2:error] [pid 62112:tid 62343] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/atomlib.php"] [unique_id "amurb8Jgo6iBrIY9VJLrAwAAAOo"]
[Thu Jul 30 14:52:15.201962 2026] [security2:error] [pid 62112:tid 62343] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/atomlib.php"] [unique_id "amurb8Jgo6iBrIY9VJLrAwAAAOo"]
[Thu Jul 30 14:52:15.286586 2026] [security2:error] [pid 62112:tid 62325] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/nano.php"] [unique_id "amurb8Jgo6iBrIY9VJLrCgAAANg"]
[Thu Jul 30 14:52:15.286673 2026] [security2:error] [pid 62112:tid 62325] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/nano.php"] [unique_id "amurb8Jgo6iBrIY9VJLrCgAAANg"]
[Thu Jul 30 14:52:15.413779 2026] [core:error] [pid 62112:tid 62205] [remote 157.55.39.223:31589] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:52:15.413804 2026] [core:error] [pid 62112:tid 62205] [remote 157.55.39.223:31589] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:52:15.469531 2026] [security2:error] [pid 62112:tid 62317] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wyzer3.php"] [unique_id "amurb8Jgo6iBrIY9VJLrDwAAANA"]
[Thu Jul 30 14:52:15.469629 2026] [security2:error] [pid 62112:tid 62317] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/wyzer3.php"] [unique_id "amurb8Jgo6iBrIY9VJLrDwAAANA"]
[Thu Jul 30 14:52:15.643236 2026] [security2:error] [pid 62112:tid 62335] [client 20.91.199.21:19895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amurb8Jgo6iBrIY9VJLrEgAAAOI"]
[Thu Jul 30 14:52:15.736814 2026] [security2:error] [pid 62112:tid 62346] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/max.php"] [unique_id "amurb8Jgo6iBrIY9VJLrFgAAAO0"]
[Thu Jul 30 14:52:15.736956 2026] [security2:error] [pid 62112:tid 62346] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/max.php"] [unique_id "amurb8Jgo6iBrIY9VJLrFgAAAO0"]
[Thu Jul 30 14:52:15.911166 2026] [security2:error] [pid 62112:tid 62248] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/moon.php"] [unique_id "amurb8Jgo6iBrIY9VJLrGwAAAIs"]
[Thu Jul 30 14:52:15.911277 2026] [security2:error] [pid 62112:tid 62248] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/moon.php"] [unique_id "amurb8Jgo6iBrIY9VJLrGwAAAIs"]
[Thu Jul 30 14:52:16.038405 2026] [security2:error] [pid 62112:tid 62330] [client 20.215.211.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.211.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ftde.php"] [unique_id "amurcMJgo6iBrIY9VJLrHwAAAN0"]
[Thu Jul 30 14:52:16.038499 2026] [security2:error] [pid 62112:tid 62330] [client 20.215.211.95:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.dubaiappliance.repair"] [uri "/ftde.php"] [unique_id "amurcMJgo6iBrIY9VJLrHwAAAN0"]
[Thu Jul 30 14:52:16.260408 2026] [security2:error] [pid 62112:tid 62260] [client 20.91.199.21:12660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/alfa-rex.php7"] [unique_id "amurcMJgo6iBrIY9VJLrJAAAAJc"]
[Thu Jul 30 14:52:16.541670 2026] [security2:error] [pid 62112:tid 62331] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-info.php"] [unique_id "amurcMJgo6iBrIY9VJLrKgAAAN4"]
[Thu Jul 30 14:52:16.541773 2026] [security2:error] [pid 62112:tid 62331] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-info.php"] [unique_id "amurcMJgo6iBrIY9VJLrKgAAAN4"]
[Thu Jul 30 14:52:17.189471 2026] [security2:error] [pid 62112:tid 62313] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/file5.php"] [unique_id "amurccJgo6iBrIY9VJLrPgAAAMw"]
[Thu Jul 30 14:52:17.189586 2026] [security2:error] [pid 62112:tid 62313] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/file5.php"] [unique_id "amurccJgo6iBrIY9VJLrPgAAAMw"]
[Thu Jul 30 14:52:17.663389 2026] [security2:error] [pid 62112:tid 62367] [client 189.156.226.90:27297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurccJgo6iBrIY9VJLrSwAAAQI"]
[Thu Jul 30 14:52:17.663506 2026] [security2:error] [pid 62112:tid 62367] [client 189.156.226.90:27297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurccJgo6iBrIY9VJLrSwAAAQI"]
[Thu Jul 30 14:52:17.835086 2026] [security2:error] [pid 62112:tid 62350] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amurccJgo6iBrIY9VJLrTAAAAPE"], referer: https://cnpinyin.com/category/experience/chinese-culture-history/
[Thu Jul 30 14:52:17.902841 2026] [security2:error] [pid 62112:tid 62326] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/2000.php"] [unique_id "amurccJgo6iBrIY9VJLrVwAAANk"]
[Thu Jul 30 14:52:17.902972 2026] [security2:error] [pid 62112:tid 62326] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/2000.php"] [unique_id "amurccJgo6iBrIY9VJLrVwAAANk"]
[Thu Jul 30 14:52:17.966810 2026] [core:notice] [pid 62112:tid 62252] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:18.477763 2026] [security2:error] [pid 62112:tid 62330] [client 20.91.199.21:6673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/alfanew.php"] [unique_id "amurcsJgo6iBrIY9VJLrZQAAAN0"]
[Thu Jul 30 14:52:18.526577 2026] [security2:error] [pid 62112:tid 62300] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/122.php"] [unique_id "amurcsJgo6iBrIY9VJLrZgAAAL8"]
[Thu Jul 30 14:52:18.526729 2026] [security2:error] [pid 62112:tid 62300] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/122.php"] [unique_id "amurcsJgo6iBrIY9VJLrZgAAAL8"]
[Thu Jul 30 14:52:18.696583 2026] [core:notice] [pid 62112:tid 62131] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:19.150403 2026] [security2:error] [pid 62112:tid 62332] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/mds.php"] [unique_id "amurc8Jgo6iBrIY9VJLrcwAAAN8"]
[Thu Jul 30 14:52:19.150515 2026] [security2:error] [pid 62112:tid 62332] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/mds.php"] [unique_id "amurc8Jgo6iBrIY9VJLrcwAAAN8"]
[Thu Jul 30 14:52:19.407329 2026] [core:error] [pid 62112:tid 62140] [remote 157.55.39.10:60731] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:52:19.407364 2026] [core:error] [pid 62112:tid 62140] [remote 157.55.39.10:60731] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:52:19.644344 2026] [security2:error] [pid 62112:tid 62119] [remote 40.77.167.159:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/index.php/jipkl/guide"] [unique_id "amurc8Jgo6iBrIY9VJLrhgAA7gY"]
[Thu Jul 30 14:52:19.755588 2026] [security2:error] [pid 62112:tid 62239] [remote 207.46.13.111:32469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/1221242946/article.php"] [unique_id "amurc8Jgo6iBrIY9VJLrhQAAm34"]
[Thu Jul 30 14:52:19.784204 2026] [security2:error] [pid 62112:tid 62306] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/zc-208.php"] [unique_id "amurc8Jgo6iBrIY9VJLrjAAAAMU"]
[Thu Jul 30 14:52:19.784300 2026] [security2:error] [pid 62112:tid 62306] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/zc-208.php"] [unique_id "amurc8Jgo6iBrIY9VJLrjAAAAMU"]
[Thu Jul 30 14:52:20.273015 2026] [security2:error] [pid 62112:tid 62249] [client 185.177.72.5:1864] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "aded-rdc.org"] [uri "/"] [unique_id "amurdMJgo6iBrIY9VJLrlgAAAIw"]
[Thu Jul 30 14:52:20.313280 2026] [security2:error] [pid 62112:tid 62228] [remote 65.181.111.156:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.111.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "embassyinislamabadad.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amurdMJgo6iBrIY9VJLrlwAA2HM"]
[Thu Jul 30 14:52:20.313457 2026] [security2:error] [pid 62112:tid 62325] [client 65.181.111.156:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "embassyinislamabadad.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amurdMJgo6iBrIY9VJLrlwAA2HM"]
[Thu Jul 30 14:52:20.417706 2026] [security2:error] [pid 62112:tid 62331] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sid4.php"] [unique_id "amurdMJgo6iBrIY9VJLrowAAAN4"]
[Thu Jul 30 14:52:20.417827 2026] [security2:error] [pid 62112:tid 62331] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sid4.php"] [unique_id "amurdMJgo6iBrIY9VJLrowAAAN4"]
[Thu Jul 30 14:52:20.564887 2026] [security2:error] [pid 62112:tid 62346] [client 172.237.109.114:6687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amurdMJgo6iBrIY9VJLrkwAAAO0"]
[Thu Jul 30 14:52:20.779424 2026] [security2:error] [pid 62112:tid 62270] [client 20.91.199.21:11501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amurdMJgo6iBrIY9VJLrqwAAAKE"]
[Thu Jul 30 14:52:20.886685 2026] [security2:error] [pid 62112:tid 62298] [client 52.238.199.152:57879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/Text/index.php"] [unique_id "amurdMJgo6iBrIY9VJLrrwAAAL0"]
[Thu Jul 30 14:52:20.932934 2026] [core:notice] [pid 62112:tid 62149] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:21.088321 2026] [security2:error] [pid 62112:tid 62318] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/wp-includes/l10n/"] [unique_id "amurdcJgo6iBrIY9VJLrtwAAANE"]
[Thu Jul 30 14:52:21.525911 2026] [security2:error] [pid 62112:tid 62348] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wmore1.php"] [unique_id "amurdcJgo6iBrIY9VJLrwgAAAO8"]
[Thu Jul 30 14:52:21.526057 2026] [security2:error] [pid 62112:tid 62348] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wmore1.php"] [unique_id "amurdcJgo6iBrIY9VJLrwgAAAO8"]
[Thu Jul 30 14:52:21.650666 2026] [security2:error] [pid 62112:tid 62345] [client 20.91.199.21:6710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amurdcJgo6iBrIY9VJLrygAAAOw"]
[Thu Jul 30 14:52:22.144556 2026] [security2:error] [pid 62112:tid 62280] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/solo1.php"] [unique_id "amurdsJgo6iBrIY9VJLr1wAAAKs"]
[Thu Jul 30 14:52:22.144666 2026] [security2:error] [pid 62112:tid 62280] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/solo1.php"] [unique_id "amurdsJgo6iBrIY9VJLr1wAAAKs"]
[Thu Jul 30 14:52:22.152043 2026] [security2:error] [pid 62112:tid 62307] [client 185.177.72.5:1894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurdsJgo6iBrIY9VJLr2QAAAMY"]
[Thu Jul 30 14:52:22.255865 2026] [security2:error] [pid 62112:tid 62310] [client 52.238.199.152:57895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amurdsJgo6iBrIY9VJLr2gAAAMk"]
[Thu Jul 30 14:52:22.419435 2026] [security2:error] [pid 62112:tid 62251] [client 185.177.72.5:1902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amurdsJgo6iBrIY9VJLr6AAAAI4"]
[Thu Jul 30 14:52:22.671530 2026] [security2:error] [pid 62112:tid 62262] [client 185.177.72.5:1910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurdsJgo6iBrIY9VJLr8AAAAJk"]
[Thu Jul 30 14:52:22.745457 2026] [security2:error] [pid 62112:tid 62165] [remote 80.74.156.100:30350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.156.74.80.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amurdsJgo6iBrIY9VJLr9AAAsTQ"]
[Thu Jul 30 14:52:22.810990 2026] [security2:error] [pid 62112:tid 62311] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/wp-includes/assets/"] [unique_id "amurdsJgo6iBrIY9VJLr9QAAAMo"]
[Thu Jul 30 14:52:22.930893 2026] [security2:error] [pid 62112:tid 62303] [client 185.177.72.5:1912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurdsJgo6iBrIY9VJLr9wAAAMI"]
[Thu Jul 30 14:52:23.063230 2026] [core:notice] [pid 62112:tid 62317] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:23.182680 2026] [security2:error] [pid 62112:tid 62283] [client 185.177.72.5:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurd8Jgo6iBrIY9VJLsAQAAAK4"]
[Thu Jul 30 14:52:23.278349 2026] [security2:error] [pid 62112:tid 62367] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/wp-includes/css/"] [unique_id "amurd8Jgo6iBrIY9VJLsAgAAAQI"]
[Thu Jul 30 14:52:23.433711 2026] [security2:error] [pid 62112:tid 62347] [client 185.177.72.5:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amurd8Jgo6iBrIY9VJLsBAAAAO4"]
[Thu Jul 30 14:52:23.536752 2026] [security2:error] [pid 62112:tid 62174] [remote 57.141.18.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amurd8Jgo6iBrIY9VJLsCAAAmz0"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,linen,nylon,polyester&filter_size=medium,extra-extra-large&orderby=price&rating=5&status=instock&unfilter=1
[Thu Jul 30 14:52:23.696342 2026] [security2:error] [pid 62112:tid 62349] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/public/css.php"] [unique_id "amurd8Jgo6iBrIY9VJLsDwAAAPA"]
[Thu Jul 30 14:52:23.696431 2026] [security2:error] [pid 62112:tid 62349] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/public/css.php"] [unique_id "amurd8Jgo6iBrIY9VJLsDwAAAPA"]
[Thu Jul 30 14:52:23.785859 2026] [security2:error] [pid 62112:tid 62190] [remote 57.141.18.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amurd8Jgo6iBrIY9VJLsCQAA700"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,denim,linen,nylon,polyester&filter_size=medium,extra-extra-large&orderby=price&rating=5&status=instock&unfilter=1
[Thu Jul 30 14:52:24.042085 2026] [security2:error] [pid 62112:tid 62252] [client 52.238.199.152:36495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amureMJgo6iBrIY9VJLsFQAAAI8"]
[Thu Jul 30 14:52:24.333432 2026] [security2:error] [pid 62112:tid 62290] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/output.php"] [unique_id "amureMJgo6iBrIY9VJLsHAAAALU"]
[Thu Jul 30 14:52:24.333551 2026] [security2:error] [pid 62112:tid 62290] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/output.php"] [unique_id "amureMJgo6iBrIY9VJLsHAAAALU"]
[Thu Jul 30 14:52:24.436469 2026] [security2:error] [pid 62112:tid 62292] [client 20.91.199.21:12162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-p.php7"] [unique_id "amureMJgo6iBrIY9VJLsHQAAALc"]
[Thu Jul 30 14:52:24.891699 2026] [security2:error] [pid 62112:tid 62182] [remote 57.141.0.40:27486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amureMJgo6iBrIY9VJLsLAAAxEU"]
[Thu Jul 30 14:52:24.970306 2026] [security2:error] [pid 62112:tid 62337] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-file-120.php"] [unique_id "amureMJgo6iBrIY9VJLsLQAAAOQ"]
[Thu Jul 30 14:52:24.970414 2026] [security2:error] [pid 62112:tid 62337] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-file-120.php"] [unique_id "amureMJgo6iBrIY9VJLsLQAAAOQ"]
[Thu Jul 30 14:52:25.619216 2026] [security2:error] [pid 62112:tid 62276] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/special.php"] [unique_id "amurecJgo6iBrIY9VJLsOwAAAKc"]
[Thu Jul 30 14:52:25.619317 2026] [security2:error] [pid 62112:tid 62276] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/special.php"] [unique_id "amurecJgo6iBrIY9VJLsOwAAAKc"]
[Thu Jul 30 14:52:25.739144 2026] [security2:error] [pid 62112:tid 62243] [client 52.238.199.152:36511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ws.php"] [unique_id "amurecJgo6iBrIY9VJLsPAAAAIY"]
[Thu Jul 30 14:52:26.250071 2026] [security2:error] [pid 62112:tid 62242] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/as.php"] [unique_id "amuresJgo6iBrIY9VJLsRwAAAIU"]
[Thu Jul 30 14:52:26.250184 2026] [security2:error] [pid 62112:tid 62242] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/as.php"] [unique_id "amuresJgo6iBrIY9VJLsRwAAAIU"]
[Thu Jul 30 14:52:26.657322 2026] [security2:error] [pid 62112:tid 62272] [client 185.191.171.18:34824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/08/jogos-paralimpicos-da-paraiba-2022-comecam-sexta-feira/"] [unique_id "amuresJgo6iBrIY9VJLsVAAAAKM"]
[Thu Jul 30 14:52:26.657485 2026] [security2:error] [pid 62112:tid 62272] [client 185.191.171.18:34824] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/08/jogos-paralimpicos-da-paraiba-2022-comecam-sexta-feira/"] [unique_id "amuresJgo6iBrIY9VJLsVAAAAKM"]
[Thu Jul 30 14:52:26.718020 2026] [core:notice] [pid 62112:tid 62321] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:26.864677 2026] [security2:error] [pid 62112:tid 62287] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/cgi-bin/index.php"] [unique_id "amuresJgo6iBrIY9VJLsWQAAALI"]
[Thu Jul 30 14:52:26.864761 2026] [security2:error] [pid 62112:tid 62287] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/cgi-bin/index.php"] [unique_id "amuresJgo6iBrIY9VJLsWQAAALI"]
[Thu Jul 30 14:52:27.489743 2026] [security2:error] [pid 62112:tid 62296] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/w1px.php"] [unique_id "amure8Jgo6iBrIY9VJLsagAAALs"]
[Thu Jul 30 14:52:27.489859 2026] [security2:error] [pid 62112:tid 62296] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/w1px.php"] [unique_id "amure8Jgo6iBrIY9VJLsagAAALs"]
[Thu Jul 30 14:52:27.543062 2026] [security2:error] [pid 62112:tid 62330] [client 52.238.199.152:37007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-config-sample.php"] [unique_id "amure8Jgo6iBrIY9VJLsawAAAN0"]
[Thu Jul 30 14:52:28.122603 2026] [security2:error] [pid 62112:tid 62368] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/js.php"] [unique_id "amurfMJgo6iBrIY9VJLsdwAAAQM"]
[Thu Jul 30 14:52:28.122707 2026] [security2:error] [pid 62112:tid 62368] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/js.php"] [unique_id "amurfMJgo6iBrIY9VJLsdwAAAQM"]
[Thu Jul 30 14:52:28.241011 2026] [security2:error] [pid 62112:tid 62243] [client 189.156.226.90:27668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurfMJgo6iBrIY9VJLsfgAAAIY"]
[Thu Jul 30 14:52:28.241140 2026] [security2:error] [pid 62112:tid 62243] [client 189.156.226.90:27668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurfMJgo6iBrIY9VJLsfgAAAIY"]
[Thu Jul 30 14:52:28.460521 2026] [security2:error] [pid 62112:tid 62304] [client 20.91.199.21:45375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-admin/repeater.php"] [unique_id "amurfMJgo6iBrIY9VJLshQAAAMM"]
[Thu Jul 30 14:52:28.741078 2026] [security2:error] [pid 62112:tid 62250] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/core.php"] [unique_id "amurfMJgo6iBrIY9VJLsigAAAI0"]
[Thu Jul 30 14:52:28.741223 2026] [security2:error] [pid 62112:tid 62250] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/core.php"] [unique_id "amurfMJgo6iBrIY9VJLsigAAAI0"]
[Thu Jul 30 14:52:29.085969 2026] [security2:error] [pid 62112:tid 62117] [remote 65.181.116.95:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.116.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxt.udi.temporary.site"] [uri "/wp-login.php"] [unique_id "amurfcJgo6iBrIY9VJLskgAAlAQ"]
[Thu Jul 30 14:52:29.161563 2026] [security2:error] [pid 62112:tid 62290] [client 20.91.199.21:18485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-includes/repeater.php"] [unique_id "amurfcJgo6iBrIY9VJLskwAAALU"]
[Thu Jul 30 14:52:29.318374 2026] [security2:error] [pid 62112:tid 62249] [client 52.238.199.152:36496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wso.php"] [unique_id "amurfcJgo6iBrIY9VJLsogAAAIw"]
[Thu Jul 30 14:52:29.357315 2026] [security2:error] [pid 62112:tid 62322] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fffm.php"] [unique_id "amurfcJgo6iBrIY9VJLsqAAAANU"]
[Thu Jul 30 14:52:29.357410 2026] [security2:error] [pid 62112:tid 62322] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fffm.php"] [unique_id "amurfcJgo6iBrIY9VJLsqAAAANU"]
[Thu Jul 30 14:52:30.006736 2026] [security2:error] [pid 62112:tid 62313] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ww.php"] [unique_id "amurfsJgo6iBrIY9VJLstgAAAMw"]
[Thu Jul 30 14:52:30.006835 2026] [security2:error] [pid 62112:tid 62313] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ww.php"] [unique_id "amurfsJgo6iBrIY9VJLstgAAAMw"]
[Thu Jul 30 14:52:30.271536 2026] [security2:error] [pid 62112:tid 62330] [client 20.91.199.21:6665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carrescia.com"] [uri "/wp-content/repeater.php"] [unique_id "amurfsJgo6iBrIY9VJLsuwAAAN0"]
[Thu Jul 30 14:52:30.388721 2026] [security2:error] [pid 62112:tid 62298] [client 52.238.199.152:37009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/sh.php"] [unique_id "amurfsJgo6iBrIY9VJLsvwAAAL0"]
[Thu Jul 30 14:52:30.655442 2026] [security2:error] [pid 62112:tid 62350] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/domvf.php"] [unique_id "amurfsJgo6iBrIY9VJLsxgAAAPE"]
[Thu Jul 30 14:52:30.655560 2026] [security2:error] [pid 62112:tid 62350] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/domvf.php"] [unique_id "amurfsJgo6iBrIY9VJLsxgAAAPE"]
[Thu Jul 30 14:52:30.972834 2026] [security2:error] [pid 62112:tid 62324] [client 20.91.199.21:49014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/011i.php"] [unique_id "amurfsJgo6iBrIY9VJLsywAAANc"]
[Thu Jul 30 14:52:31.265332 2026] [security2:error] [pid 62112:tid 62356] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/echkm.php"] [unique_id "amurf8Jgo6iBrIY9VJLs1gAAAPc"]
[Thu Jul 30 14:52:31.265434 2026] [security2:error] [pid 62112:tid 62356] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/echkm.php"] [unique_id "amurf8Jgo6iBrIY9VJLs1gAAAPc"]
[Thu Jul 30 14:52:31.495525 2026] [security2:error] [pid 62112:tid 62252] [client 52.238.199.152:36534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/send.php"] [unique_id "amurf8Jgo6iBrIY9VJLs2QAAAI8"]
[Thu Jul 30 14:52:31.584659 2026] [security2:error] [pid 62112:tid 62277] [client 154.72.161.116:4007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.161.72.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alfalasifurnituremoversllc.com"] [uri "/xmlrpc.php"] [unique_id "amurf8Jgo6iBrIY9VJLs1wAAAKg"]
[Thu Jul 30 14:52:31.584895 2026] [security2:error] [pid 62112:tid 62277] [client 154.72.161.116:4007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alfalasifurnituremoversllc.com"] [uri "/xmlrpc.php"] [unique_id "amurf8Jgo6iBrIY9VJLs1wAAAKg"]
[Thu Jul 30 14:52:31.897411 2026] [security2:error] [pid 62112:tid 62293] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ano.php"] [unique_id "amurf8Jgo6iBrIY9VJLs5gAAALg"]
[Thu Jul 30 14:52:31.897556 2026] [security2:error] [pid 62112:tid 62293] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ano.php"] [unique_id "amurf8Jgo6iBrIY9VJLs5gAAALg"]
[Thu Jul 30 14:52:32.380460 2026] [security2:error] [pid 62112:tid 62267] [client 2a03:2880:f800:a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurf8Jgo6iBrIY9VJLs2AAAni8"]
[Thu Jul 30 14:52:32.542414 2026] [security2:error] [pid 62112:tid 62344] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ah25.php"] [unique_id "amurgMJgo6iBrIY9VJLs8QAAAOs"]
[Thu Jul 30 14:52:32.542529 2026] [security2:error] [pid 62112:tid 62344] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ah25.php"] [unique_id "amurgMJgo6iBrIY9VJLs8QAAAOs"]
[Thu Jul 30 14:52:32.868660 2026] [security2:error] [pid 62112:tid 62147] [remote 57.141.0.69:56026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amurgMJgo6iBrIY9VJLs-wAAqiI"]
[Thu Jul 30 14:52:33.160880 2026] [security2:error] [pid 62112:tid 62254] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/term.php"] [unique_id "amurgcJgo6iBrIY9VJLs_wAAAJE"]
[Thu Jul 30 14:52:33.161032 2026] [security2:error] [pid 62112:tid 62254] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/term.php"] [unique_id "amurgcJgo6iBrIY9VJLs_wAAAJE"]
[Thu Jul 30 14:52:33.442937 2026] [security2:error] [pid 62112:tid 62287] [client 52.238.199.152:37029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ds.php"] [unique_id "amurgcJgo6iBrIY9VJLtCQAAALI"]
[Thu Jul 30 14:52:33.580117 2026] [security2:error] [pid 62112:tid 62330] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amurgMJgo6iBrIY9VJLs_gAAAN0"]
[Thu Jul 30 14:52:33.802716 2026] [security2:error] [pid 62112:tid 62248] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/we.php"] [unique_id "amurgcJgo6iBrIY9VJLtEAAAAIs"]
[Thu Jul 30 14:52:33.802812 2026] [security2:error] [pid 62112:tid 62248] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/we.php"] [unique_id "amurgcJgo6iBrIY9VJLtEAAAAIs"]
[Thu Jul 30 14:52:34.181432 2026] [security2:error] [pid 62112:tid 62356] [client 47.128.17.85:43910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lms.aetiiph.net"] [uri "/robots.txt"] [unique_id "amurgsJgo6iBrIY9VJLtFQAAAPc"]
[Thu Jul 30 14:52:34.449265 2026] [security2:error] [pid 62112:tid 62256] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/zip-onee.php"] [unique_id "amurgsJgo6iBrIY9VJLtGwAAAJM"]
[Thu Jul 30 14:52:34.449413 2026] [security2:error] [pid 62112:tid 62256] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/zip-onee.php"] [unique_id "amurgsJgo6iBrIY9VJLtGwAAAJM"]
[Thu Jul 30 14:52:35.067060 2026] [security2:error] [pid 62112:tid 62268] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/il.php"] [unique_id "amurg8Jgo6iBrIY9VJLtLAAAAJ8"]
[Thu Jul 30 14:52:35.067172 2026] [security2:error] [pid 62112:tid 62268] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/il.php"] [unique_id "amurg8Jgo6iBrIY9VJLtLAAAAJ8"]
[Thu Jul 30 14:52:35.391608 2026] [security2:error] [pid 62112:tid 62284] [client 52.238.199.152:36518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wso112233.php"] [unique_id "amurg8Jgo6iBrIY9VJLtNQAAAK8"]
[Thu Jul 30 14:52:35.691131 2026] [security2:error] [pid 62112:tid 62315] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/one.php"] [unique_id "amurg8Jgo6iBrIY9VJLtQQAAAM4"]
[Thu Jul 30 14:52:35.691272 2026] [security2:error] [pid 62112:tid 62315] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/one.php"] [unique_id "amurg8Jgo6iBrIY9VJLtQQAAAM4"]
[Thu Jul 30 14:52:36.244805 2026] [security2:error] [pid 62112:tid 62316] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amurg8Jgo6iBrIY9VJLtPAAAAM8"]
[Thu Jul 30 14:52:36.292014 2026] [security2:error] [pid 62112:tid 62347] [client 20.91.199.21:51862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/03a005685d.php"] [unique_id "amurhMJgo6iBrIY9VJLtTQAAAO4"]
[Thu Jul 30 14:52:36.388059 2026] [security2:error] [pid 62112:tid 62338] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/002.php"] [unique_id "amurhMJgo6iBrIY9VJLtUQAAAOU"]
[Thu Jul 30 14:52:36.388175 2026] [security2:error] [pid 62112:tid 62338] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/002.php"] [unique_id "amurhMJgo6iBrIY9VJLtUQAAAOU"]
[Thu Jul 30 14:52:37.019332 2026] [security2:error] [pid 62112:tid 62339] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/file1.php"] [unique_id "amurhcJgo6iBrIY9VJLtkgAAAOY"]
[Thu Jul 30 14:52:37.019423 2026] [security2:error] [pid 62112:tid 62339] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/file1.php"] [unique_id "amurhcJgo6iBrIY9VJLtkgAAAOY"]
[Thu Jul 30 14:52:37.095665 2026] [security2:error] [pid 62112:tid 62292] [client 20.91.199.21:50256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/403.php"] [unique_id "amurhcJgo6iBrIY9VJLtkwAAALc"]
[Thu Jul 30 14:52:37.644762 2026] [security2:error] [pid 62112:tid 62284] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/akimet.php"] [unique_id "amurhcJgo6iBrIY9VJLtoAAAAK8"]
[Thu Jul 30 14:52:37.644877 2026] [security2:error] [pid 62112:tid 62284] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/akimet.php"] [unique_id "amurhcJgo6iBrIY9VJLtoAAAAK8"]
[Thu Jul 30 14:52:38.269715 2026] [security2:error] [pid 62112:tid 62336] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/reop3.php"] [unique_id "amurhsJgo6iBrIY9VJLtrQAAAOM"]
[Thu Jul 30 14:52:38.269812 2026] [security2:error] [pid 62112:tid 62336] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/reop3.php"] [unique_id "amurhsJgo6iBrIY9VJLtrQAAAOM"]
[Thu Jul 30 14:52:38.552758 2026] [security2:error] [pid 62112:tid 62362] [client 20.91.199.21:49195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/404.php"] [unique_id "amurhsJgo6iBrIY9VJLttAAAAP0"]
[Thu Jul 30 14:52:38.824415 2026] [security2:error] [pid 62112:tid 62269] [client 189.156.226.90:26792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurhsJgo6iBrIY9VJLtuQAAAKA"]
[Thu Jul 30 14:52:38.824519 2026] [security2:error] [pid 62112:tid 62269] [client 189.156.226.90:26792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurhsJgo6iBrIY9VJLtuQAAAKA"]
[Thu Jul 30 14:52:38.912663 2026] [security2:error] [pid 62112:tid 62255] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/h.php"] [unique_id "amurhsJgo6iBrIY9VJLtwQAAAJI"]
[Thu Jul 30 14:52:38.912766 2026] [security2:error] [pid 62112:tid 62255] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/h.php"] [unique_id "amurhsJgo6iBrIY9VJLtwQAAAJI"]
[Thu Jul 30 14:52:39.181450 2026] [security2:error] [pid 62112:tid 62253] [client 20.199.183.73:18545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wk/index.php"] [unique_id "amurh8Jgo6iBrIY9VJLtwgAAAJA"]
[Thu Jul 30 14:52:39.550322 2026] [security2:error] [pid 62112:tid 62357] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/2x.php"] [unique_id "amurh8Jgo6iBrIY9VJLtzAAAAPg"]
[Thu Jul 30 14:52:39.550409 2026] [security2:error] [pid 62112:tid 62357] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/2x.php"] [unique_id "amurh8Jgo6iBrIY9VJLtzAAAAPg"]
[Thu Jul 30 14:52:40.192026 2026] [security2:error] [pid 62112:tid 62354] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/petx.php"] [unique_id "amuriMJgo6iBrIY9VJLt1wAAAPU"]
[Thu Jul 30 14:52:40.192152 2026] [security2:error] [pid 62112:tid 62354] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/petx.php"] [unique_id "amuriMJgo6iBrIY9VJLt1wAAAPU"]
[Thu Jul 30 14:52:40.311146 2026] [security2:error] [pid 62112:tid 62356] [client 20.91.199.21:48794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/aa.php"] [unique_id "amuriMJgo6iBrIY9VJLt2wAAAPc"]
[Thu Jul 30 14:52:40.672600 2026] [security2:error] [pid 62112:tid 62251] [client 52.238.199.152:36537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "amuriMJgo6iBrIY9VJLt4gAAAI4"]
[Thu Jul 30 14:52:40.814020 2026] [security2:error] [pid 62112:tid 62352] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/zxz.php"] [unique_id "amuriMJgo6iBrIY9VJLt5AAAAPM"]
[Thu Jul 30 14:52:40.814133 2026] [security2:error] [pid 62112:tid 62352] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/zxz.php"] [unique_id "amuriMJgo6iBrIY9VJLt5AAAAPM"]
[Thu Jul 30 14:52:40.989889 2026] [security2:error] [pid 62112:tid 62312] [client 20.91.199.21:55416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/aafewc0k.php"] [unique_id "amuriMJgo6iBrIY9VJLt5wAAAMs"]
[Thu Jul 30 14:52:41.451628 2026] [core:error] [pid 62112:tid 62368] [client 193.47.62.167:50872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:52:41.451650 2026] [core:error] [pid 62112:tid 62368] [client 193.47.62.167:50872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:52:41.496121 2026] [security2:error] [pid 62112:tid 62342] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/2.php"] [unique_id "amuricJgo6iBrIY9VJLt8gAAAOk"]
[Thu Jul 30 14:52:41.496241 2026] [security2:error] [pid 62112:tid 62342] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/2.php"] [unique_id "amuricJgo6iBrIY9VJLt8gAAAOk"]
[Thu Jul 30 14:52:41.620186 2026] [core:notice] [pid 62112:tid 62361] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:41.770010 2026] [security2:error] [pid 62112:tid 62161] [remote 57.141.0.14:51554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5351135361/feed/rss2/"] [unique_id "amuricJgo6iBrIY9VJLt8wAA9jA"]
[Thu Jul 30 14:52:41.873067 2026] [security2:error] [pid 62112:tid 62295] [client 20.199.183.73:12271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/av.php"] [unique_id "amuricJgo6iBrIY9VJLt_QAAALo"]
[Thu Jul 30 14:52:42.089614 2026] [security2:error] [pid 62112:tid 62254] [client 52.238.199.152:37001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "amurisJgo6iBrIY9VJLuAwAAAJE"]
[Thu Jul 30 14:52:42.122922 2026] [security2:error] [pid 62112:tid 62349] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/op.php"] [unique_id "amurisJgo6iBrIY9VJLuBAAAAPA"]
[Thu Jul 30 14:52:42.123043 2026] [security2:error] [pid 62112:tid 62349] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/op.php"] [unique_id "amurisJgo6iBrIY9VJLuBAAAAPA"]
[Thu Jul 30 14:52:42.758275 2026] [security2:error] [pid 62112:tid 62357] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/a5.php"] [unique_id "amurisJgo6iBrIY9VJLuDwAAAPg"]
[Thu Jul 30 14:52:42.758373 2026] [security2:error] [pid 62112:tid 62357] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/a5.php"] [unique_id "amurisJgo6iBrIY9VJLuDwAAAPg"]
[Thu Jul 30 14:52:42.949871 2026] [security2:error] [pid 62112:tid 62362] [client 20.91.199.21:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/abcd.php"] [unique_id "amurisJgo6iBrIY9VJLuFAAAAP0"]
[Thu Jul 30 14:52:43.370523 2026] [security2:error] [pid 62112:tid 62268] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ws80.php"] [unique_id "amuri8Jgo6iBrIY9VJLuHgAAAJ8"]
[Thu Jul 30 14:52:43.370687 2026] [security2:error] [pid 62112:tid 62268] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ws80.php"] [unique_id "amuri8Jgo6iBrIY9VJLuHgAAAJ8"]
[Thu Jul 30 14:52:43.517955 2026] [security2:error] [pid 62112:tid 62255] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurisJgo6iBrIY9VJLuEAAAki8"]
[Thu Jul 30 14:52:43.840894 2026] [security2:error] [pid 62112:tid 62333] [client 20.91.199.21:51419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/about.php"] [unique_id "amuri8Jgo6iBrIY9VJLuLAAAAOA"]
[Thu Jul 30 14:52:43.986472 2026] [security2:error] [pid 62112:tid 62299] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xa.php"] [unique_id "amuri8Jgo6iBrIY9VJLuMAAAAL4"]
[Thu Jul 30 14:52:43.986594 2026] [security2:error] [pid 62112:tid 62299] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xa.php"] [unique_id "amuri8Jgo6iBrIY9VJLuMAAAAL4"]
[Thu Jul 30 14:52:44.169120 2026] [security2:error] [pid 62112:tid 62366] [client 20.199.183.73:12250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/mini.php"] [unique_id "amurjMJgo6iBrIY9VJLuQwAAAQE"]
[Thu Jul 30 14:52:44.264926 2026] [security2:error] [pid 62112:tid 62278] [client 74.7.230.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-6113a6a7.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amurisJgo6iBrIY9VJLuFwAAAKk"]
[Thu Jul 30 14:52:44.265775 2026] [security2:error] [pid 62112:tid 62277] [client 74.7.230.34:37620] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-6113a6a7.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amurisJgo6iBrIY9VJLuFQAAqBg"]
[Thu Jul 30 14:52:44.595900 2026] [security2:error] [pid 62112:tid 62252] [client 52.238.199.152:3587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/mail.php"] [unique_id "amurjMJgo6iBrIY9VJLuSQAAAI8"]
[Thu Jul 30 14:52:44.663016 2026] [security2:error] [pid 62112:tid 62302] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/asd67.php"] [unique_id "amurjMJgo6iBrIY9VJLuTQAAAME"]
[Thu Jul 30 14:52:44.663117 2026] [security2:error] [pid 62112:tid 62302] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/asd67.php"] [unique_id "amurjMJgo6iBrIY9VJLuTQAAAME"]
[Thu Jul 30 14:52:44.865323 2026] [security2:error] [pid 62112:tid 62330] [client 20.91.199.21:51432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/admin.php"] [unique_id "amurjMJgo6iBrIY9VJLuUwAAAN0"]
[Thu Jul 30 14:52:45.284410 2026] [security2:error] [pid 62112:tid 62260] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/bk.php"] [unique_id "amurjcJgo6iBrIY9VJLuZQAAAJc"]
[Thu Jul 30 14:52:45.284553 2026] [security2:error] [pid 62112:tid 62260] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/bk.php"] [unique_id "amurjcJgo6iBrIY9VJLuZQAAAJc"]
[Thu Jul 30 14:52:45.912769 2026] [security2:error] [pid 62112:tid 62306] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-links.php"] [unique_id "amurjcJgo6iBrIY9VJLuegAAAMU"]
[Thu Jul 30 14:52:45.912888 2026] [security2:error] [pid 62112:tid 62306] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-links.php"] [unique_id "amurjcJgo6iBrIY9VJLuegAAAMU"]
[Thu Jul 30 14:52:45.936781 2026] [security2:error] [pid 62112:tid 62320] [client 20.199.183.73:11578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/aa.php"] [unique_id "amurjcJgo6iBrIY9VJLuewAAANM"]
[Thu Jul 30 14:52:46.057936 2026] [security2:error] [pid 62112:tid 62256] [client 20.91.199.21:49159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/adminfuns.php"] [unique_id "amurjsJgo6iBrIY9VJLufgAAAJM"]
[Thu Jul 30 14:52:46.214883 2026] [autoindex:error] [pid 62112:tid 62251] [client 2605:6400:10:2e1:b22c:4cad:703a:ea85:0] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.melatipkr.xyz
[Thu Jul 30 14:52:46.542870 2026] [security2:error] [pid 62112:tid 62351] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/mosty.php"] [unique_id "amurjsJgo6iBrIY9VJLujQAAAPI"]
[Thu Jul 30 14:52:46.543033 2026] [security2:error] [pid 62112:tid 62351] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/mosty.php"] [unique_id "amurjsJgo6iBrIY9VJLujQAAAPI"]
[Thu Jul 30 14:52:46.554925 2026] [security2:error] [pid 62112:tid 62336] [client 74.7.244.36:41378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.emmanueljrodriguez.com"] [uri "/index.php"] [unique_id "amurjMJgo6iBrIY9VJLuTgAA40c"]
[Thu Jul 30 14:52:46.728461 2026] [security2:error] [pid 62112:tid 62245] [client 52.238.199.152:3611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-mail.php"] [unique_id "amurjsJgo6iBrIY9VJLulwAAAIg"]
[Thu Jul 30 14:52:47.095687 2026] [security2:error] [pid 62112:tid 62368] [client 20.91.199.21:49503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/albin.php"] [unique_id "amurj8Jgo6iBrIY9VJLupAAAAQM"]
[Thu Jul 30 14:52:47.198575 2026] [security2:error] [pid 62112:tid 62248] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sump3.php"] [unique_id "amurj8Jgo6iBrIY9VJLuqQAAAIs"]
[Thu Jul 30 14:52:47.198679 2026] [security2:error] [pid 62112:tid 62248] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/sump3.php"] [unique_id "amurj8Jgo6iBrIY9VJLuqQAAAIs"]
[Thu Jul 30 14:52:47.302191 2026] [security2:error] [pid 62112:tid 62324] [client 35.204.197.107:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.themushroom.online"] [uri "/"] [unique_id "amurj8Jgo6iBrIY9VJLuqgAAANc"]
[Thu Jul 30 14:52:47.302296 2026] [security2:error] [pid 62112:tid 62324] [client 35.204.197.107:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.themushroom.online"] [uri "/"] [unique_id "amurj8Jgo6iBrIY9VJLuqgAAANc"]
[Thu Jul 30 14:52:47.445774 2026] [security2:error] [pid 62112:tid 62328] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amurjsJgo6iBrIY9VJLungAA22A"]
[Thu Jul 30 14:52:47.848321 2026] [security2:error] [pid 62112:tid 62307] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/first.php"] [unique_id "amurj8Jgo6iBrIY9VJLuwgAAAMY"]
[Thu Jul 30 14:52:47.848426 2026] [security2:error] [pid 62112:tid 62307] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/first.php"] [unique_id "amurj8Jgo6iBrIY9VJLuwgAAAMY"]
[Thu Jul 30 14:52:47.904649 2026] [security2:error] [pid 62112:tid 62349] [client 74.7.241.138:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "emmanueljrodriguez.com"] [uri "/index.php"] [unique_id "amurj8Jgo6iBrIY9VJLuwwAA8A0"]
[Thu Jul 30 14:52:47.980068 2026] [security2:error] [pid 62112:tid 62220] [remote 20.54.134.42:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amurj8Jgo6iBrIY9VJLuxwAA-Ws"]
[Thu Jul 30 14:52:48.093103 2026] [security2:error] [pid 62112:tid 62310] [client 179.43.134.114:39992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amurj8Jgo6iBrIY9VJLuwQAAAMk"]
[Thu Jul 30 14:52:48.478088 2026] [security2:error] [pid 62112:tid 62265] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/acp.php"] [unique_id "amurkMJgo6iBrIY9VJLu2AAAAJw"]
[Thu Jul 30 14:52:48.478205 2026] [security2:error] [pid 62112:tid 62265] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/acp.php"] [unique_id "amurkMJgo6iBrIY9VJLu2AAAAJw"]
[Thu Jul 30 14:52:48.841319 2026] [security2:error] [pid 62112:tid 62289] [client 20.91.199.21:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/amfsqvgv.php"] [unique_id "amurkMJgo6iBrIY9VJLu5gAAALQ"]
[Thu Jul 30 14:52:48.841643 2026] [security2:error] [pid 62112:tid 62343] [client 68.221.69.72:35942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amurkMJgo6iBrIY9VJLu5QAAAOo"]
[Thu Jul 30 14:52:48.841725 2026] [security2:error] [pid 62112:tid 62343] [client 68.221.69.72:35942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amurkMJgo6iBrIY9VJLu5QAAAOo"]
[Thu Jul 30 14:52:49.100415 2026] [security2:error] [pid 62112:tid 62277] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-good.php"] [unique_id "amurkcJgo6iBrIY9VJLu9QAAAKg"]
[Thu Jul 30 14:52:49.100509 2026] [security2:error] [pid 62112:tid 62277] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-good.php"] [unique_id "amurkcJgo6iBrIY9VJLu9QAAAKg"]
[Thu Jul 30 14:52:49.388195 2026] [security2:error] [pid 62112:tid 62232] [remote 57.141.0.7:44616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amurkcJgo6iBrIY9VJLu_gAAunc"]
[Thu Jul 30 14:52:49.412413 2026] [security2:error] [pid 62112:tid 62297] [client 189.156.226.90:27062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurkcJgo6iBrIY9VJLu_wAAALw"]
[Thu Jul 30 14:52:49.412517 2026] [security2:error] [pid 62112:tid 62297] [client 189.156.226.90:27062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurkcJgo6iBrIY9VJLu_wAAALw"]
[Thu Jul 30 14:52:49.428822 2026] [security2:error] [pid 62112:tid 62285] [client 52.238.199.152:59780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-trackback.php"] [unique_id "amurkcJgo6iBrIY9VJLvAAAAALA"]
[Thu Jul 30 14:52:49.442389 2026] [security2:error] [pid 62112:tid 62318] [client 20.91.199.21:52876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/ant.php"] [unique_id "amurkcJgo6iBrIY9VJLvAQAAANE"]
[Thu Jul 30 14:52:49.725908 2026] [security2:error] [pid 62112:tid 62263] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/daerl3.php"] [unique_id "amurkcJgo6iBrIY9VJLvDQAAAJo"]
[Thu Jul 30 14:52:49.726029 2026] [security2:error] [pid 62112:tid 62263] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/daerl3.php"] [unique_id "amurkcJgo6iBrIY9VJLvDQAAAJo"]
[Thu Jul 30 14:52:50.249829 2026] [security2:error] [pid 62112:tid 62294] [client 20.199.183.73:16654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/w.php"] [unique_id "amurksJgo6iBrIY9VJLvHgAAALk"]
[Thu Jul 30 14:52:50.360681 2026] [security2:error] [pid 62112:tid 62256] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/php5.php"] [unique_id "amurksJgo6iBrIY9VJLvJgAAAJM"]
[Thu Jul 30 14:52:50.360783 2026] [security2:error] [pid 62112:tid 62256] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/php5.php"] [unique_id "amurksJgo6iBrIY9VJLvJgAAAJM"]
[Thu Jul 30 14:52:50.980508 2026] [security2:error] [pid 62112:tid 62343] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xoot.php"] [unique_id "amurksJgo6iBrIY9VJLvNAAAAOo"]
[Thu Jul 30 14:52:50.980604 2026] [security2:error] [pid 62112:tid 62343] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/xoot.php"] [unique_id "amurksJgo6iBrIY9VJLvNAAAAOo"]
[Thu Jul 30 14:52:51.269728 2026] [security2:error] [pid 62112:tid 62286] [client 20.199.183.73:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/admin.php"] [unique_id "amurk8Jgo6iBrIY9VJLvPgAAALE"]
[Thu Jul 30 14:52:51.629362 2026] [security2:error] [pid 62112:tid 62365] [client 179.43.134.114:39998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amurk8Jgo6iBrIY9VJLvUgAAAQA"], referer: https://jwcpartners.org/wp-admin/
[Thu Jul 30 14:52:51.683335 2026] [security2:error] [pid 62112:tid 62307] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/clxcc.php"] [unique_id "amurk8Jgo6iBrIY9VJLvWAAAAMY"]
[Thu Jul 30 14:52:51.683457 2026] [security2:error] [pid 62112:tid 62307] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/clxcc.php"] [unique_id "amurk8Jgo6iBrIY9VJLvWAAAAMY"]
[Thu Jul 30 14:52:51.820855 2026] [security2:error] [pid 62112:tid 62291] [client 52.238.199.152:59793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/uploads/cong.php"] [unique_id "amurk8Jgo6iBrIY9VJLvXQAAALY"]
[Thu Jul 30 14:52:51.935051 2026] [security2:error] [pid 62112:tid 62263] [client 110.249.202.237:57468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amurk8Jgo6iBrIY9VJLvZAAAAJo"]
[Thu Jul 30 14:52:51.993032 2026] [security2:error] [pid 62112:tid 62363] [client 20.91.199.21:52889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/appreciators.php"] [unique_id "amurk8Jgo6iBrIY9VJLvaAAAAP4"]
[Thu Jul 30 14:52:52.045324 2026] [security2:error] [pid 62112:tid 62246] [client 34.91.100.6:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.website-01997096.srs.nyx.temporary.site"] [uri "/"] [unique_id "amurlMJgo6iBrIY9VJLvaQAAAIk"]
[Thu Jul 30 14:52:52.045416 2026] [security2:error] [pid 62112:tid 62246] [client 34.91.100.6:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.website-01997096.srs.nyx.temporary.site"] [uri "/"] [unique_id "amurlMJgo6iBrIY9VJLvaQAAAIk"]
[Thu Jul 30 14:52:52.138091 2026] [security2:error] [pid 62112:tid 62262] [client 68.221.69.72:53794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amurlMJgo6iBrIY9VJLvagAAAJk"]
[Thu Jul 30 14:52:52.138200 2026] [security2:error] [pid 62112:tid 62262] [client 68.221.69.72:53794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amurlMJgo6iBrIY9VJLvagAAAJk"]
[Thu Jul 30 14:52:52.304568 2026] [security2:error] [pid 62112:tid 62351] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ai.php"] [unique_id "amurlMJgo6iBrIY9VJLvbwAAAPI"]
[Thu Jul 30 14:52:52.304680 2026] [security2:error] [pid 62112:tid 62351] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ai.php"] [unique_id "amurlMJgo6iBrIY9VJLvbwAAAPI"]
[Thu Jul 30 14:52:52.328095 2026] [core:notice] [pid 62112:tid 62315] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:52.448336 2026] [security2:error] [pid 62112:tid 62250] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amurk8Jgo6iBrIY9VJLvXwAAAI0"]
[Thu Jul 30 14:52:52.928584 2026] [security2:error] [pid 62112:tid 62295] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/nwflm.php"] [unique_id "amurlMJgo6iBrIY9VJLvgwAAALo"]
[Thu Jul 30 14:52:52.928731 2026] [security2:error] [pid 62112:tid 62295] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/nwflm.php"] [unique_id "amurlMJgo6iBrIY9VJLvgwAAALo"]
[Thu Jul 30 14:52:53.000439 2026] [security2:error] [pid 62112:tid 62324] [client 20.199.183.73:11573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amurlMJgo6iBrIY9VJLvhwAAANc"]
[Thu Jul 30 14:52:53.199712 2026] [security2:error] [pid 62112:tid 62278] [client 52.238.199.152:37358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amurlcJgo6iBrIY9VJLvjgAAAKk"]
[Thu Jul 30 14:52:53.514432 2026] [security2:error] [pid 62112:tid 62204] [remote 57.141.18.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amurlcJgo6iBrIY9VJLvkgAA21s"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,nylon,plastic,polyester,steel&filter_size=extra-extra-large,extra-small,large,medium,small&max_price=125&min_price=75&orderby=price-desc&status=sale&tax_product_cat=suit&unfilter=1
[Thu Jul 30 14:52:53.556267 2026] [security2:error] [pid 62112:tid 62340] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/hypo.php"] [unique_id "amurlcJgo6iBrIY9VJLvmQAAAOc"]
[Thu Jul 30 14:52:53.556379 2026] [security2:error] [pid 62112:tid 62340] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/hypo.php"] [unique_id "amurlcJgo6iBrIY9VJLvmQAAAOc"]
[Thu Jul 30 14:52:54.016769 2026] [security2:error] [pid 62112:tid 62203] [remote 57.141.18.101:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amurlcJgo6iBrIY9VJLvngAAklo"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,nylon,plastic,polyester,steel&filter_size=extra-extra-large,extra-small,large,medium,small&max_price=125&min_price=75&orderby=price-desc&status=sale&tax_product_cat=suit&unfilter=1
[Thu Jul 30 14:52:54.171699 2026] [security2:error] [pid 62112:tid 62298] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/w3llscc.php"] [unique_id "amurlsJgo6iBrIY9VJLvqgAAAL0"]
[Thu Jul 30 14:52:54.171814 2026] [security2:error] [pid 62112:tid 62298] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/w3llscc.php"] [unique_id "amurlsJgo6iBrIY9VJLvqgAAAL0"]
[Thu Jul 30 14:52:54.916881 2026] [security2:error] [pid 62112:tid 62345] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/11PJcpMFsD8B.php"] [unique_id "amurlsJgo6iBrIY9VJLvuwAAAOw"]
[Thu Jul 30 14:52:54.917012 2026] [security2:error] [pid 62112:tid 62345] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/11PJcpMFsD8B.php"] [unique_id "amurlsJgo6iBrIY9VJLvuwAAAOw"]
[Thu Jul 30 14:52:54.956381 2026] [security2:error] [pid 62112:tid 62351] [client 52.238.199.152:47179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/webadmin.php"] [unique_id "amurlsJgo6iBrIY9VJLvvAAAAPI"]
[Thu Jul 30 14:52:55.350695 2026] [security2:error] [pid 62112:tid 62296] [client 68.221.69.72:30664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amurl8Jgo6iBrIY9VJLvxQAAALs"]
[Thu Jul 30 14:52:55.350803 2026] [security2:error] [pid 62112:tid 62296] [client 68.221.69.72:30664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amurl8Jgo6iBrIY9VJLvxQAAALs"]
[Thu Jul 30 14:52:55.528122 2026] [security2:error] [pid 62112:tid 62328] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/8.php"] [unique_id "amurl8Jgo6iBrIY9VJLvyAAAANs"]
[Thu Jul 30 14:52:55.528236 2026] [security2:error] [pid 62112:tid 62328] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/8.php"] [unique_id "amurl8Jgo6iBrIY9VJLvyAAAANs"]
[Thu Jul 30 14:52:56.159164 2026] [security2:error] [pid 62112:tid 62300] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fnstall.php"] [unique_id "amurmMJgo6iBrIY9VJLv3AAAAL8"]
[Thu Jul 30 14:52:56.159307 2026] [security2:error] [pid 62112:tid 62300] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fnstall.php"] [unique_id "amurmMJgo6iBrIY9VJLv3AAAAL8"]
[Thu Jul 30 14:52:56.348535 2026] [security2:error] [pid 62112:tid 62305] [client 20.91.199.21:52551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/archive.php"] [unique_id "amurmMJgo6iBrIY9VJLv4gAAAMQ"]
[Thu Jul 30 14:52:56.805558 2026] [security2:error] [pid 62112:tid 62364] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/edorxrr.php"] [unique_id "amurmMJgo6iBrIY9VJLv7wAAAP8"]
[Thu Jul 30 14:52:56.805710 2026] [security2:error] [pid 62112:tid 62364] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/edorxrr.php"] [unique_id "amurmMJgo6iBrIY9VJLv7wAAAP8"]
[Thu Jul 30 14:52:56.819765 2026] [core:notice] [pid 62112:tid 62327] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:57.376116 2026] [security2:error] [pid 62112:tid 62358] [client 52.238.199.152:53200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/link.php"] [unique_id "amurmcJgo6iBrIY9VJLv-wAAAPk"]
[Thu Jul 30 14:52:57.438548 2026] [security2:error] [pid 62112:tid 62310] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/setup.php"] [unique_id "amurmcJgo6iBrIY9VJLv_AAAAMk"]
[Thu Jul 30 14:52:57.438668 2026] [security2:error] [pid 62112:tid 62310] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/setup.php"] [unique_id "amurmcJgo6iBrIY9VJLv_AAAAMk"]
[Thu Jul 30 14:52:57.635641 2026] [security2:error] [pid 62112:tid 62347] [client 20.91.199.21:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/as.php"] [unique_id "amurmcJgo6iBrIY9VJLwAAAAAO4"]
[Thu Jul 30 14:52:59.032959 2026] [http2:info] [pid 87988:tid 87988] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 14:52:59.048731 2026] [security2:error] [pid 87988:tid 88119] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/6.php"] [unique_id "amurmzipAwzptuCxBrg_NgAAAQs"]
[Thu Jul 30 14:52:59.048968 2026] [security2:error] [pid 87988:tid 88119] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/6.php"] [unique_id "amurmzipAwzptuCxBrg_NgAAAQs"]
[Thu Jul 30 14:52:59.050455 2026] [core:notice] [pid 87988:tid 88121] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:59.057532 2026] [security2:error] [pid 87988:tid 88126] [client 68.221.69.72:44494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/err.php"] [unique_id "amurmzipAwzptuCxBrg_OAAAARI"]
[Thu Jul 30 14:52:59.057648 2026] [security2:error] [pid 87988:tid 88126] [client 68.221.69.72:44494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/err.php"] [unique_id "amurmzipAwzptuCxBrg_OAAAARI"]
[Thu Jul 30 14:52:59.309631 2026] [core:notice] [pid 87988:tid 88118] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:52:59.314187 2026] [security2:error] [pid 87988:tid 88118] [client 66.249.79.224:40329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jka/article/view/3972"] [unique_id "amurmzipAwzptuCxBrg_NQAAAQo"]
[Thu Jul 30 14:52:59.339453 2026] [security2:error] [pid 62112:tid 62258] [client 52.238.199.152:47213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/ova.php"] [unique_id "amurm8Jgo6iBrIY9VJLwCgAAAJU"]
[Thu Jul 30 14:52:59.540883 2026] [security2:error] [pid 87988:tid 88125] [client 20.199.183.73:16135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/m.php"] [unique_id "amurmzipAwzptuCxBrg_QgAAARE"]
[Thu Jul 30 14:52:59.634201 2026] [security2:error] [pid 87988:tid 88120] [client 20.91.199.21:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/atomlib.php"] [unique_id "amurmzipAwzptuCxBrg_RgAAAQw"]
[Thu Jul 30 14:52:59.665266 2026] [security2:error] [pid 87988:tid 88149] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/w3lls.php"] [unique_id "amurmzipAwzptuCxBrg_RwAAASk"]
[Thu Jul 30 14:52:59.665357 2026] [security2:error] [pid 87988:tid 88149] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/w3lls.php"] [unique_id "amurmzipAwzptuCxBrg_RwAAASk"]
[Thu Jul 30 14:52:59.923650 2026] [security2:error] [pid 87988:tid 88147] [client 189.156.226.90:27320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurmzipAwzptuCxBrg_UAAAASc"]
[Thu Jul 30 14:52:59.923813 2026] [security2:error] [pid 87988:tid 88147] [client 189.156.226.90:27320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurmzipAwzptuCxBrg_UAAAASc"]
[Thu Jul 30 14:52:59.997589 2026] [core:notice] [pid 87988:tid 88155] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:00.126886 2026] [core:notice] [pid 87988:tid 87994] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:00.130832 2026] [security2:error] [pid 87988:tid 88162] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/2/2"] [unique_id "amurmzipAwzptuCxBrg_TwABNgU"]
[Thu Jul 30 14:53:00.288344 2026] [security2:error] [pid 87988:tid 88178] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/99.php"] [unique_id "amurnDipAwzptuCxBrg_VwAAAUY"]
[Thu Jul 30 14:53:00.288573 2026] [security2:error] [pid 87988:tid 88178] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/99.php"] [unique_id "amurnDipAwzptuCxBrg_VwAAAUY"]
[Thu Jul 30 14:53:00.307163 2026] [security2:error] [pid 87988:tid 88164] [client 52.238.199.152:47204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/css/colors/coffee/about.php"] [unique_id "amurnDipAwzptuCxBrg_WwAAATg"]
[Thu Jul 30 14:53:00.402242 2026] [security2:error] [pid 87988:tid 88177] [client 78.46.190.63:27292] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amurnDipAwzptuCxBrg_XAAAAUU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:53:00.853023 2026] [security2:error] [pid 87988:tid 88193] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amurnDipAwzptuCxBrg_YgAAAVU"]
[Thu Jul 30 14:53:00.907901 2026] [security2:error] [pid 87988:tid 88212] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-content/admin.php"] [unique_id "amurnDipAwzptuCxBrg_aQAAAWg"]
[Thu Jul 30 14:53:00.908042 2026] [security2:error] [pid 87988:tid 88212] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-content/admin.php"] [unique_id "amurnDipAwzptuCxBrg_aQAAAWg"]
[Thu Jul 30 14:53:01.020338 2026] [core:notice] [pid 87988:tid 88211] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:01.025755 2026] [security2:error] [pid 87988:tid 88211] [client 78.46.190.63:27304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amurnTipAwzptuCxBrg_awAAAWc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:53:01.167551 2026] [core:notice] [pid 87988:tid 88213] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:01.172173 2026] [security2:error] [pid 87988:tid 88213] [client 66.249.79.237:47990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3825"] [unique_id "amurnDipAwzptuCxBrg_agAAAWk"]
[Thu Jul 30 14:53:01.547057 2026] [security2:error] [pid 87988:tid 88244] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/media.php"] [unique_id "amurnTipAwzptuCxBrg_fAAAAYg"]
[Thu Jul 30 14:53:01.547189 2026] [security2:error] [pid 87988:tid 88244] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/media.php"] [unique_id "amurnTipAwzptuCxBrg_fAAAAYg"]
[Thu Jul 30 14:53:01.590631 2026] [security2:error] [pid 87988:tid 88243] [client 78.46.190.63:27312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amurnTipAwzptuCxBrg_fQAAAYc"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:53:01.672129 2026] [security2:error] [pid 87988:tid 88217] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amurnTipAwzptuCxBrg_bgAAAW0"]
[Thu Jul 30 14:53:01.767019 2026] [security2:error] [pid 87988:tid 88215] [client 20.199.183.73:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amurnTipAwzptuCxBrg_ewAAAWs"]
[Thu Jul 30 14:53:01.879588 2026] [core:notice] [pid 87988:tid 88245] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:01.909793 2026] [security2:error] [pid 87988:tid 88242] [client 52.238.199.152:47217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amurnTipAwzptuCxBrg_iQAAAYY"]
[Thu Jul 30 14:53:02.168746 2026] [security2:error] [pid 87988:tid 88125] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amurnjipAwzptuCxBrg_iwAAARE"]
[Thu Jul 30 14:53:02.168899 2026] [security2:error] [pid 87988:tid 88125] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amurnjipAwzptuCxBrg_iwAAARE"]
[Thu Jul 30 14:53:02.411203 2026] [security2:error] [pid 87988:tid 88135] [client 20.91.199.21:51353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/autoload_classmap.php"] [unique_id "amurnjipAwzptuCxBrg_lQAAARs"]
[Thu Jul 30 14:53:02.880345 2026] [security2:error] [pid 87988:tid 88175] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/222.php"] [unique_id "amurnjipAwzptuCxBrg_nQAAAUM"]
[Thu Jul 30 14:53:02.880457 2026] [security2:error] [pid 87988:tid 88175] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/222.php"] [unique_id "amurnjipAwzptuCxBrg_nQAAAUM"]
[Thu Jul 30 14:53:02.947530 2026] [security2:error] [pid 87988:tid 88178] [client 20.199.183.73:16148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/classwithtostring.php"] [unique_id "amurnjipAwzptuCxBrg_oQAAAUY"]
[Thu Jul 30 14:53:03.429500 2026] [security2:error] [pid 87988:tid 88180] [client 47.128.36.223:41826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jesus.claims"] [uri "/robots.txt"] [unique_id "amurnzipAwzptuCxBrg_qwAAAUg"]
[Thu Jul 30 14:53:03.500666 2026] [security2:error] [pid 87988:tid 88190] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-load.php"] [unique_id "amurnzipAwzptuCxBrg_rQAAAVI"]
[Thu Jul 30 14:53:03.500778 2026] [security2:error] [pid 87988:tid 88190] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-load.php"] [unique_id "amurnzipAwzptuCxBrg_rQAAAVI"]
[Thu Jul 30 14:53:03.506219 2026] [security2:error] [pid 87988:tid 88205] [client 68.221.69.72:60097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/img.php"] [unique_id "amurnzipAwzptuCxBrg_rgAAAWE"]
[Thu Jul 30 14:53:03.506287 2026] [security2:error] [pid 87988:tid 88205] [client 68.221.69.72:60097] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/img.php"] [unique_id "amurnzipAwzptuCxBrg_rgAAAWE"]
[Thu Jul 30 14:53:04.114857 2026] [security2:error] [pid 87988:tid 88234] [client 82.102.23.139:35434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.23.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuroDipAwzptuCxBrg_uwAAAX4"]
[Thu Jul 30 14:53:04.115028 2026] [security2:error] [pid 87988:tid 88234] [client 82.102.23.139:35434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuroDipAwzptuCxBrg_uwAAAX4"]
[Thu Jul 30 14:53:04.140948 2026] [security2:error] [pid 87988:tid 88237] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-content/themes/index.php"] [unique_id "amuroDipAwzptuCxBrg_vAAAAYE"]
[Thu Jul 30 14:53:04.141072 2026] [security2:error] [pid 87988:tid 88237] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-content/themes/index.php"] [unique_id "amuroDipAwzptuCxBrg_vAAAAYE"]
[Thu Jul 30 14:53:04.153967 2026] [security2:error] [pid 87988:tid 88184] [client 52.238.199.152:36718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/users.php"] [unique_id "amuroDipAwzptuCxBrg_vQAAAUw"]
[Thu Jul 30 14:53:04.648912 2026] [core:notice] [pid 87988:tid 88236] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:04.653632 2026] [security2:error] [pid 87988:tid 88236] [client 66.249.79.229:57345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Responsif/article/view/9572/4319"] [unique_id "amuroDipAwzptuCxBrg_wQAAAYA"]
[Thu Jul 30 14:53:04.673809 2026] [security2:error] [pid 87988:tid 88209] [client 20.91.199.21:51380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/bb.php"] [unique_id "amuroDipAwzptuCxBrg_yAAAAWU"]
[Thu Jul 30 14:53:04.723514 2026] [security2:error] [pid 87988:tid 88208] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuroDipAwzptuCxBrg_ugABZCU"]
[Thu Jul 30 14:53:04.783091 2026] [security2:error] [pid 87988:tid 88138] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-admin/js/index.php"] [unique_id "amuroDipAwzptuCxBrg_yQAAAR4"]
[Thu Jul 30 14:53:04.783244 2026] [security2:error] [pid 87988:tid 88138] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-admin/js/index.php"] [unique_id "amuroDipAwzptuCxBrg_yQAAAR4"]
[Thu Jul 30 14:53:05.401030 2026] [security2:error] [pid 87988:tid 88168] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/memberfuns.php"] [unique_id "amuroTipAwzptuCxBrg_2gAAATw"]
[Thu Jul 30 14:53:05.401157 2026] [security2:error] [pid 87988:tid 88168] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/memberfuns.php"] [unique_id "amuroTipAwzptuCxBrg_2gAAATw"]
[Thu Jul 30 14:53:05.763009 2026] [core:notice] [pid 87988:tid 88156] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:05.767441 2026] [security2:error] [pid 87988:tid 88156] [client 66.249.79.1:48711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/1635/1011"] [unique_id "amuroTipAwzptuCxBrg_4QAAATA"]
[Thu Jul 30 14:53:06.010137 2026] [security2:error] [pid 87988:tid 88186] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/orange3.php"] [unique_id "amurojipAwzptuCxBrg_6gAAAU4"]
[Thu Jul 30 14:53:06.010247 2026] [security2:error] [pid 87988:tid 88186] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/orange3.php"] [unique_id "amurojipAwzptuCxBrg_6gAAAU4"]
[Thu Jul 30 14:53:06.209141 2026] [security2:error] [pid 87988:tid 88198] [client 68.221.69.72:44569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/aa.php"] [unique_id "amurojipAwzptuCxBrg_8QAAAVo"]
[Thu Jul 30 14:53:06.209259 2026] [security2:error] [pid 87988:tid 88198] [client 68.221.69.72:44569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/aa.php"] [unique_id "amurojipAwzptuCxBrg_8QAAAVo"]
[Thu Jul 30 14:53:06.642813 2026] [security2:error] [pid 87988:tid 88229] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amurojipAwzptuCxBrg__wAAAXk"]
[Thu Jul 30 14:53:06.642902 2026] [security2:error] [pid 87988:tid 88229] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amurojipAwzptuCxBrg__wAAAXk"]
[Thu Jul 30 14:53:06.728168 2026] [security2:error] [pid 87988:tid 88199] [client 20.199.183.73:19765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/gmo.php"] [unique_id "amurojipAwzptuCxBrhAAQAAAVs"]
[Thu Jul 30 14:53:06.729606 2026] [core:notice] [pid 87988:tid 88203] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:06.857322 2026] [security2:error] [pid 87988:tid 88158] [client 20.91.199.21:53558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/bnm.php"] [unique_id "amurojipAwzptuCxBrhAAgAAATI"]
[Thu Jul 30 14:53:07.100149 2026] [security2:error] [pid 87988:tid 88234] [client 52.238.199.152:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/defaults.php"] [unique_id "amurozipAwzptuCxBrhACQAAAX4"]
[Thu Jul 30 14:53:07.386130 2026] [security2:error] [pid 87988:tid 88131] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-the.php"] [unique_id "amurozipAwzptuCxBrhADgAAARc"]
[Thu Jul 30 14:53:07.386276 2026] [security2:error] [pid 87988:tid 88131] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/wp-the.php"] [unique_id "amurozipAwzptuCxBrhADgAAARc"]
[Thu Jul 30 14:53:07.400722 2026] [security2:error] [pid 87988:tid 88055] [remote 216.73.216.51:12595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amurozipAwzptuCxBrhADwABa0I"]
[Thu Jul 30 14:53:07.756697 2026] [security2:error] [pid 87988:tid 88123] [client 20.199.183.73:28058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/languages/index.php"] [unique_id "amurozipAwzptuCxBrhAGQAAAQ8"]
[Thu Jul 30 14:53:07.877012 2026] [security2:error] [pid 87988:tid 88127] [client 20.91.199.21:51057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/bootstrap.php"] [unique_id "amurozipAwzptuCxBrhAGgAAARM"]
[Thu Jul 30 14:53:08.009660 2026] [security2:error] [pid 87988:tid 88152] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/crgio.php"] [unique_id "amurpDipAwzptuCxBrhAGwAAASw"]
[Thu Jul 30 14:53:08.009829 2026] [security2:error] [pid 87988:tid 88152] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/crgio.php"] [unique_id "amurpDipAwzptuCxBrhAGwAAASw"]
[Thu Jul 30 14:53:08.034280 2026] [security2:error] [pid 87988:tid 88149] [client 52.238.199.152:53201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amurpDipAwzptuCxBrhAHwAAASk"]
[Thu Jul 30 14:53:08.649907 2026] [security2:error] [pid 87988:tid 88186] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ws13.php"] [unique_id "amurpDipAwzptuCxBrhAKgAAAU4"]
[Thu Jul 30 14:53:08.650036 2026] [security2:error] [pid 87988:tid 88186] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ws13.php"] [unique_id "amurpDipAwzptuCxBrhAKgAAAU4"]
[Thu Jul 30 14:53:08.678472 2026] [security2:error] [pid 87988:tid 88170] [client 34.81.220.187:30108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/.env"] [unique_id "amurpDipAwzptuCxBrhALgAAAT4"]
[Thu Jul 30 14:53:08.688291 2026] [security2:error] [pid 87988:tid 88164] [client 34.81.220.187:30182] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/.env.bak"] [unique_id "amurpDipAwzptuCxBrhAMgAAATg"]
[Thu Jul 30 14:53:08.696798 2026] [security2:error] [pid 87988:tid 88172] [client 34.81.220.187:30190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/.env.backup"] [unique_id "amurpDipAwzptuCxBrhANgAAAUA"]
[Thu Jul 30 14:53:08.718823 2026] [security2:error] [pid 87988:tid 88156] [client 34.81.220.187:30206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/.env.old"] [unique_id "amurpDipAwzptuCxBrhAOQAAATA"]
[Thu Jul 30 14:53:08.719032 2026] [security2:error] [pid 87988:tid 88156] [client 34.81.220.187:30206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.mskabir.com"] [uri "/.env.old"] [unique_id "amurpDipAwzptuCxBrhAOQAAATA"]
[Thu Jul 30 14:53:08.733827 2026] [security2:error] [pid 87988:tid 88194] [client 34.81.220.187:30238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/app/.env"] [unique_id "amurpDipAwzptuCxBrhAOgAAAVY"]
[Thu Jul 30 14:53:08.736767 2026] [security2:error] [pid 87988:tid 88183] [client 34.81.220.187:30226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/env.json"] [unique_id "amurpDipAwzptuCxBrhAPAAAAUs"]
[Thu Jul 30 14:53:08.736897 2026] [security2:error] [pid 87988:tid 88183] [client 34.81.220.187:30226] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.mskabir.com"] [uri "/env.json"] [unique_id "amurpDipAwzptuCxBrhAPAAAAUs"]
[Thu Jul 30 14:53:08.850087 2026] [security2:error] [pid 87988:tid 88181] [client 34.81.220.187:30150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurpDipAwzptuCxBrhAMwAAAUk"]
[Thu Jul 30 14:53:08.850486 2026] [security2:error] [pid 87988:tid 88176] [client 34.81.220.187:30134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurpDipAwzptuCxBrhAMQAAAUQ"]
[Thu Jul 30 14:53:08.856408 2026] [security2:error] [pid 87988:tid 88174] [client 34.81.220.187:30120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurpDipAwzptuCxBrhAMAAAAUI"]
[Thu Jul 30 14:53:08.860775 2026] [security2:error] [pid 87988:tid 88179] [client 34.81.220.187:30168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurpDipAwzptuCxBrhANwAAAUc"]
[Thu Jul 30 14:53:08.869643 2026] [security2:error] [pid 87988:tid 88173] [client 34.81.220.187:30164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurpDipAwzptuCxBrhANQAAAUE"]
[Thu Jul 30 14:53:09.061630 2026] [security2:error] [pid 87988:tid 88210] [client 20.199.183.73:16167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-the.php"] [unique_id "amurpTipAwzptuCxBrhAQAAAAWY"]
[Thu Jul 30 14:53:09.461760 2026] [security2:error] [pid 87988:tid 88240] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/srontol.php"] [unique_id "amurpTipAwzptuCxBrhATAAAAYQ"]
[Thu Jul 30 14:53:09.461895 2026] [security2:error] [pid 87988:tid 88240] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/srontol.php"] [unique_id "amurpTipAwzptuCxBrhATAAAAYQ"]
[Thu Jul 30 14:53:09.611066 2026] [security2:error] [pid 87988:tid 88136] [client 20.91.199.21:53630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/buy.php"] [unique_id "amurpTipAwzptuCxBrhATgAAARw"]
[Thu Jul 30 14:53:10.012767 2026] [security2:error] [pid 87988:tid 88119] [client 40.77.167.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurpTipAwzptuCxBrhAUAAAAQs"]
[Thu Jul 30 14:53:10.112278 2026] [security2:error] [pid 87988:tid 88143] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/miru3.php"] [unique_id "amurpjipAwzptuCxBrhAXAAAASM"]
[Thu Jul 30 14:53:10.112393 2026] [security2:error] [pid 87988:tid 88143] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/miru3.php"] [unique_id "amurpjipAwzptuCxBrhAXAAAASM"]
[Thu Jul 30 14:53:10.257214 2026] [security2:error] [pid 87988:tid 88134] [client 20.199.183.73:11639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/404.php"] [unique_id "amurpjipAwzptuCxBrhAZAAAARo"]
[Thu Jul 30 14:53:10.506513 2026] [security2:error] [pid 87988:tid 88135] [client 189.156.226.90:27681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurpjipAwzptuCxBrhAaAAAARs"]
[Thu Jul 30 14:53:10.506656 2026] [security2:error] [pid 87988:tid 88135] [client 189.156.226.90:27681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurpjipAwzptuCxBrhAaAAAARs"]
[Thu Jul 30 14:53:10.758692 2026] [security2:error] [pid 87988:tid 88183] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ingfo.php"] [unique_id "amurpjipAwzptuCxBrhAbwAAAUs"]
[Thu Jul 30 14:53:10.758796 2026] [security2:error] [pid 87988:tid 88183] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ingfo.php"] [unique_id "amurpjipAwzptuCxBrhAbwAAAUs"]
[Thu Jul 30 14:53:11.090934 2026] [security2:error] [pid 87988:tid 88084] [remote 40.77.167.159:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/145"] [unique_id "amurpzipAwzptuCxBrhAdwABTl8"]
[Thu Jul 30 14:53:11.170881 2026] [core:notice] [pid 87988:tid 88086] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:11.239205 2026] [core:notice] [pid 87988:tid 88082] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:11.242721 2026] [security2:error] [pid 87988:tid 88194] [client 66.249.74.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/79/82"] [unique_id "amurpjipAwzptuCxBrhAcwABVl0"]
[Thu Jul 30 14:53:11.396819 2026] [security2:error] [pid 87988:tid 88217] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ey5.php"] [unique_id "amurpzipAwzptuCxBrhAhgAAAW0"]
[Thu Jul 30 14:53:11.396894 2026] [security2:error] [pid 87988:tid 88217] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/ey5.php"] [unique_id "amurpzipAwzptuCxBrhAhgAAAW0"]
[Thu Jul 30 14:53:11.834227 2026] [core:notice] [pid 87988:tid 88092] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:12.076750 2026] [security2:error] [pid 87988:tid 88239] [client 85.208.96.208:19674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/29/banco-citi-traca-meta-de-crescer-50-no-brasil-mas-cobra-responsabilidade-fiscal-do-governo/"] [unique_id "amurqDipAwzptuCxBrhAlwAAAYM"]
[Thu Jul 30 14:53:12.077031 2026] [security2:error] [pid 87988:tid 88239] [client 85.208.96.208:19674] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/29/banco-citi-traca-meta-de-crescer-50-no-brasil-mas-cobra-responsabilidade-fiscal-do-governo/"] [unique_id "amurqDipAwzptuCxBrhAlwAAAYM"]
[Thu Jul 30 14:53:12.136430 2026] [core:notice] [pid 87988:tid 88134] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:12.140752 2026] [security2:error] [pid 87988:tid 88134] [client 66.249.79.229:61223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/1366"] [unique_id "amurqDipAwzptuCxBrhAmAAAARo"]
[Thu Jul 30 14:53:12.295482 2026] [security2:error] [pid 87988:tid 88166] [client 52.238.199.152:59918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "amurqDipAwzptuCxBrhAnAAAATo"]
[Thu Jul 30 14:53:12.329201 2026] [security2:error] [pid 87988:tid 88178] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fine.php"] [unique_id "amurqDipAwzptuCxBrhAnQAAAUY"]
[Thu Jul 30 14:53:12.329309 2026] [security2:error] [pid 87988:tid 88178] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/fine.php"] [unique_id "amurqDipAwzptuCxBrhAnQAAAUY"]
[Thu Jul 30 14:53:12.832169 2026] [core:notice] [pid 87988:tid 88100] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:13.546719 2026] [security2:error] [pid 87988:tid 88158] [client 68.221.69.72:39070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/av.php"] [unique_id "amurqTipAwzptuCxBrhAtwAAATI"]
[Thu Jul 30 14:53:13.546827 2026] [security2:error] [pid 87988:tid 88158] [client 68.221.69.72:39070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/av.php"] [unique_id "amurqTipAwzptuCxBrhAtwAAATI"]
[Thu Jul 30 14:53:13.585629 2026] [security2:error] [pid 87988:tid 88105] [remote 144.76.32.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/30"] [unique_id "amurqTipAwzptuCxBrhAuAABgXQ"]
[Thu Jul 30 14:53:13.644007 2026] [core:notice] [pid 87988:tid 88200] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:13.870742 2026] [security2:error] [pid 87988:tid 88224] [client 20.199.183.73:20573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/init.php"] [unique_id "amurqTipAwzptuCxBrhAwQAAAXQ"]
[Thu Jul 30 14:53:14.436463 2026] [security2:error] [pid 87988:tid 88137] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurqjipAwzptuCxBrhAygAAAR0"]
[Thu Jul 30 14:53:14.438350 2026] [core:notice] [pid 87988:tid 88148] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:14.733208 2026] [core:notice] [pid 87988:tid 88115] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:15.378787 2026] [security2:error] [pid 87988:tid 88168] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurqzipAwzptuCxBrhA4QAAATw"]
[Thu Jul 30 14:53:15.552301 2026] [security2:error] [pid 87988:tid 88185] [client 20.199.183.73:42448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/file5.php"] [unique_id "amurqzipAwzptuCxBrhA6wAAAU0"]
[Thu Jul 30 14:53:15.659986 2026] [security2:error] [pid 87988:tid 88136] [client 52.238.199.152:61748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/plugins.php"] [unique_id "amurqzipAwzptuCxBrhA7AAAARw"]
[Thu Jul 30 14:53:16.135569 2026] [security2:error] [pid 87988:tid 88182] [client 52.167.144.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurqzipAwzptuCxBrhA7wAAAUo"]
[Thu Jul 30 14:53:16.308481 2026] [security2:error] [pid 87988:tid 88194] [client 20.91.199.21:51359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/chosen.php"] [unique_id "amurrDipAwzptuCxBrhA-QAAAVY"]
[Thu Jul 30 14:53:17.445291 2026] [security2:error] [pid 87988:tid 88149] [client 20.91.199.21:53516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/class-wp-image.php"] [unique_id "amurrTipAwzptuCxBrhBEwAAASk"]
[Thu Jul 30 14:53:17.553998 2026] [security2:error] [pid 87988:tid 88199] [client 52.238.199.152:64800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-content/upgrade/wp-login.php"] [unique_id "amurrTipAwzptuCxBrhBEgAAAVs"]
[Thu Jul 30 14:53:17.893737 2026] [security2:error] [pid 87988:tid 88241] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kamiliacademy.com"] [uri "/index.php"] [unique_id "amurqTipAwzptuCxBrhAvAAAAYU"]
[Thu Jul 30 14:53:17.995661 2026] [security2:error] [pid 87988:tid 88209] [client 68.221.69.72:31144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/xa.php"] [unique_id "amurrTipAwzptuCxBrhBHgAAAWU"]
[Thu Jul 30 14:53:17.995774 2026] [security2:error] [pid 87988:tid 88209] [client 68.221.69.72:31144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/xa.php"] [unique_id "amurrTipAwzptuCxBrhBHgAAAWU"]
[Thu Jul 30 14:53:18.834759 2026] [security2:error] [pid 87988:tid 88119] [client 20.199.183.73:49059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amurrjipAwzptuCxBrhBNQAAAQs"]
[Thu Jul 30 14:53:18.873437 2026] [security2:error] [pid 87988:tid 88188] [client 20.91.199.21:51058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/classsmtps.php"] [unique_id "amurrjipAwzptuCxBrhBNgAAAVA"]
[Thu Jul 30 14:53:19.072566 2026] [security2:error] [pid 87988:tid 88232] [client 52.167.144.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurrjipAwzptuCxBrhBNAAAAXw"]
[Thu Jul 30 14:53:19.478225 2026] [security2:error] [pid 87988:tid 88205] [client 52.238.199.152:3705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/certificates/wp-login.php"] [unique_id "amurrzipAwzptuCxBrhBQwAAAWE"]
[Thu Jul 30 14:53:19.547820 2026] [security2:error] [pid 87988:tid 88125] [client 52.167.144.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amurrzipAwzptuCxBrhBQgAAARE"]
[Thu Jul 30 14:53:19.582377 2026] [security2:error] [pid 87988:tid 88126] [client 34.81.220.187:51028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/api/.env"] [unique_id "amurrzipAwzptuCxBrhBRQAAARI"]
[Thu Jul 30 14:53:19.587069 2026] [security2:error] [pid 87988:tid 88212] [client 34.81.220.187:51044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/backend/.env"] [unique_id "amurrzipAwzptuCxBrhBRgAAAWg"]
[Thu Jul 30 14:53:19.626819 2026] [security2:error] [pid 87988:tid 88137] [client 34.81.220.187:51082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/laravel/.env"] [unique_id "amurrzipAwzptuCxBrhBSAAAAR0"]
[Thu Jul 30 14:53:19.637902 2026] [security2:error] [pid 87988:tid 88245] [client 34.81.220.187:51084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/docker/.env"] [unique_id "amurrzipAwzptuCxBrhBSQAAAYk"]
[Thu Jul 30 14:53:19.638038 2026] [security2:error] [pid 87988:tid 88245] [client 34.81.220.187:51084] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.mskabir.com"] [uri "/docker/.env"] [unique_id "amurrzipAwzptuCxBrhBSQAAAYk"]
[Thu Jul 30 14:53:19.653488 2026] [security2:error] [pid 87988:tid 88143] [client 34.81.220.187:51068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/config/.env"] [unique_id "amurrzipAwzptuCxBrhBTQAAASM"]
[Thu Jul 30 14:53:19.697122 2026] [security2:error] [pid 87988:tid 88184] [client 34.81.220.187:51118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/.gcloud/credentials"] [unique_id "amurrzipAwzptuCxBrhBVgAAAUw"]
[Thu Jul 30 14:53:19.731347 2026] [security2:error] [pid 87988:tid 88189] [client 34.81.220.187:51052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurrzipAwzptuCxBrhBRwAAAVE"]
[Thu Jul 30 14:53:19.815434 2026] [security2:error] [pid 87988:tid 88208] [client 34.81.220.187:51094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurrzipAwzptuCxBrhBTAAAAWQ"]
[Thu Jul 30 14:53:19.834237 2026] [security2:error] [pid 87988:tid 88124] [client 34.81.220.187:51106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurrzipAwzptuCxBrhBTwAAARA"]
[Thu Jul 30 14:53:19.834522 2026] [security2:error] [pid 87988:tid 88120] [client 34.81.220.187:51108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurrzipAwzptuCxBrhBUgAAAQw"]
[Thu Jul 30 14:53:19.845672 2026] [security2:error] [pid 87988:tid 88149] [client 34.81.220.187:51044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurrzipAwzptuCxBrhBVQAAASk"]
[Thu Jul 30 14:53:19.845675 2026] [security2:error] [pid 87988:tid 88123] [client 34.81.220.187:51028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurrzipAwzptuCxBrhBUwAAAQ8"]
[Thu Jul 30 14:53:20.291539 2026] [security2:error] [pid 87988:tid 88154] [client 20.199.183.73:42473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/shell.php"] [unique_id "amursDipAwzptuCxBrhBZgAAAS4"]
[Thu Jul 30 14:53:20.345465 2026] [security2:error] [pid 87988:tid 88236] [client 20.91.199.21:51036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/classwithtostring.php"] [unique_id "amursDipAwzptuCxBrhBZwAAAYA"]
[Thu Jul 30 14:53:20.826012 2026] [core:notice] [pid 87988:tid 88218] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:20.879646 2026] [security2:error] [pid 87988:tid 88183] [client 20.199.183.73:40573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/f35.php"] [unique_id "amursDipAwzptuCxBrhBcgAAAUs"]
[Thu Jul 30 14:53:21.035069 2026] [security2:error] [pid 87988:tid 88186] [client 20.91.199.21:51038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/config.php"] [unique_id "amursTipAwzptuCxBrhBcwAAAU4"]
[Thu Jul 30 14:53:21.049936 2026] [security2:error] [pid 87988:tid 88214] [client 189.156.226.90:26817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amursTipAwzptuCxBrhBdAAAAWo"]
[Thu Jul 30 14:53:21.050062 2026] [security2:error] [pid 87988:tid 88214] [client 189.156.226.90:26817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amursTipAwzptuCxBrhBdAAAAWo"]
[Thu Jul 30 14:53:21.293657 2026] [security2:error] [pid 87988:tid 88167] [client 52.238.199.152:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/css/network.php"] [unique_id "amursTipAwzptuCxBrhBewAAATs"]
[Thu Jul 30 14:53:21.804104 2026] [security2:error] [pid 87988:tid 88037] [remote 74.7.243.224:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/img/Policyf.php"] [unique_id "amursTipAwzptuCxBrhBhwABVjA"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/img/main_image_6a2032acb13c3.jpg
[Thu Jul 30 14:53:21.921032 2026] [security2:error] [pid 87988:tid 88038] [remote 216.73.216.51:12595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amursTipAwzptuCxBrhBiQABITE"]
[Thu Jul 30 14:53:22.105679 2026] [security2:error] [pid 87988:tid 88182] [client 20.199.183.73:49232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/new.php"] [unique_id "amursjipAwzptuCxBrhBigAAAUo"]
[Thu Jul 30 14:53:22.405339 2026] [security2:error] [pid 87988:tid 88138] [client 20.91.199.21:52597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/core.php"] [unique_id "amursjipAwzptuCxBrhBlAAAAR4"]
[Thu Jul 30 14:53:22.719507 2026] [security2:error] [pid 87988:tid 88045] [remote 52.167.144.237:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3889"] [unique_id "amursjipAwzptuCxBrhBmAABKTg"]
[Thu Jul 30 14:53:23.138366 2026] [security2:error] [pid 87988:tid 88128] [client 20.199.183.73:40561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/adminfuns.php"] [unique_id "amurszipAwzptuCxBrhBowAAARQ"]
[Thu Jul 30 14:53:23.691034 2026] [security2:error] [pid 87988:tid 88219] [client 31.3.152.100:41636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.152.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amurszipAwzptuCxBrhBsAAAAW8"]
[Thu Jul 30 14:53:23.691137 2026] [security2:error] [pid 87988:tid 88219] [client 31.3.152.100:41636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amurszipAwzptuCxBrhBsAAAAW8"]
[Thu Jul 30 14:53:23.708782 2026] [security2:error] [pid 87988:tid 88192] [client 52.238.199.152:3687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-cron.php"] [unique_id "amurszipAwzptuCxBrhBsQAAAVQ"]
[Thu Jul 30 14:53:23.723617 2026] [core:notice] [pid 87988:tid 88170] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:23.727955 2026] [security2:error] [pid 87988:tid 88170] [client 66.249.79.8:63068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/snpm/article/view/9705"] [unique_id "amurszipAwzptuCxBrhBrwAAAT4"]
[Thu Jul 30 14:53:24.171570 2026] [security2:error] [pid 87988:tid 88177] [client 20.199.183.73:49052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/fm.php"] [unique_id "amurtDipAwzptuCxBrhBvQAAAUU"]
[Thu Jul 30 14:53:24.187361 2026] [security2:error] [pid 87988:tid 88200] [client 20.91.199.21:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/css.php"] [unique_id "amurtDipAwzptuCxBrhBvgAAAVw"]
[Thu Jul 30 14:53:25.595712 2026] [security2:error] [pid 87988:tid 88243] [client 85.208.96.204:27734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/12/31/matheus-bezerra-consegue-escola-de-35-milhoes-de-reais-para-bananeiras-pb-assista/"] [unique_id "amurtTipAwzptuCxBrhB3wAAAYc"]
[Thu Jul 30 14:53:25.595847 2026] [security2:error] [pid 87988:tid 88243] [client 85.208.96.204:27734] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/12/31/matheus-bezerra-consegue-escola-de-35-milhoes-de-reais-para-bananeiras-pb-assista/"] [unique_id "amurtTipAwzptuCxBrhB3wAAAYc"]
[Thu Jul 30 14:53:25.682597 2026] [core:notice] [pid 87988:tid 88212] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:25.862962 2026] [core:notice] [pid 87988:tid 88069] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:26.183331 2026] [security2:error] [pid 87988:tid 88172] [client 74.7.230.33:37874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "oneuro.org"] [uri "/cgi-sys/404.html"] [unique_id "amurtjipAwzptuCxBrhB7gABQFc"]
[Thu Jul 30 14:53:27.209851 2026] [security2:error] [pid 87988:tid 88201] [client 20.91.199.21:53573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/database.php"] [unique_id "amurtzipAwzptuCxBrhCPQAAAV0"]
[Thu Jul 30 14:53:27.503250 2026] [security2:error] [pid 87988:tid 88184] [client 20.199.183.73:42468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/file.php"] [unique_id "amurtzipAwzptuCxBrhCQgAAAUw"]
[Thu Jul 30 14:53:27.639624 2026] [security2:error] [pid 87988:tid 88017] [remote 216.73.216.51:27914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amurtzipAwzptuCxBrhCTAABJhw"]
[Thu Jul 30 14:53:28.147177 2026] [security2:error] [pid 87988:tid 88124] [client 20.91.199.21:47937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/db.php"] [unique_id "amuruDipAwzptuCxBrhCVwAAARA"]
[Thu Jul 30 14:53:28.637620 2026] [security2:error] [pid 87988:tid 88119] [client 20.199.183.73:11871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/bolt.php"] [unique_id "amuruDipAwzptuCxBrhCagAAAQs"]
[Thu Jul 30 14:53:28.641810 2026] [security2:error] [pid 87988:tid 88178] [client 172.237.109.114:11789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuruDipAwzptuCxBrhCUwAAAUY"]
[Thu Jul 30 14:53:28.784651 2026] [security2:error] [pid 87988:tid 88192] [client 20.91.199.21:42910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/default.php"] [unique_id "amuruDipAwzptuCxBrhCawAAAVQ"]
[Thu Jul 30 14:53:29.273618 2026] [security2:error] [pid 87988:tid 88205] [client 68.221.69.72:55282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/media.php"] [unique_id "amuruTipAwzptuCxBrhCdgAAAWE"]
[Thu Jul 30 14:53:29.273736 2026] [security2:error] [pid 87988:tid 88205] [client 68.221.69.72:55282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/media.php"] [unique_id "amuruTipAwzptuCxBrhCdgAAAWE"]
[Thu Jul 30 14:53:29.415871 2026] [security2:error] [pid 87988:tid 88130] [client 43.133.14.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.14.133.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/frekuensi"] [unique_id "amuruTipAwzptuCxBrhCdQAAARY"]
[Thu Jul 30 14:53:29.484992 2026] [security2:error] [pid 87988:tid 88129] [client 20.199.183.73:49271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/3.php"] [unique_id "amuruTipAwzptuCxBrhCdwAAARU"]
[Thu Jul 30 14:53:29.554074 2026] [security2:error] [pid 87988:tid 88125] [client 52.238.199.152:37124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/acp.php"] [unique_id "amuruTipAwzptuCxBrhCewAAARE"]
[Thu Jul 30 14:53:29.603740 2026] [security2:error] [pid 87988:tid 88158] [client 20.91.199.21:51009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/dropdown.php"] [unique_id "amuruTipAwzptuCxBrhCfwAAATI"]
[Thu Jul 30 14:53:30.165924 2026] [security2:error] [pid 87988:tid 88120] [client 34.81.220.187:44090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/.ssh/id_rsa"] [unique_id "amurujipAwzptuCxBrhCkAAAAQw"]
[Thu Jul 30 14:53:30.167164 2026] [security2:error] [pid 87988:tid 88159] [client 34.81.220.187:44100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/.ssh/id_ed25519"] [unique_id "amurujipAwzptuCxBrhCkQAAATM"]
[Thu Jul 30 14:53:30.198186 2026] [security2:error] [pid 87988:tid 88163] [client 34.81.220.187:44062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurujipAwzptuCxBrhCigAAATc"]
[Thu Jul 30 14:53:30.273211 2026] [security2:error] [pid 87988:tid 88160] [client 34.81.220.187:44082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurujipAwzptuCxBrhCjwAAATQ"]
[Thu Jul 30 14:53:30.283303 2026] [security2:error] [pid 87988:tid 88171] [client 34.81.220.187:44110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/config.js"] [unique_id "amurujipAwzptuCxBrhCmQAAAT8"]
[Thu Jul 30 14:53:30.283419 2026] [security2:error] [pid 87988:tid 88171] [client 34.81.220.187:44110] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.mskabir.com"] [uri "/config.js"] [unique_id "amurujipAwzptuCxBrhCmQAAAT8"]
[Thu Jul 30 14:53:30.327014 2026] [security2:error] [pid 87988:tid 88123] [client 34.81.220.187:44102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurujipAwzptuCxBrhCkwAAAQ8"]
[Thu Jul 30 14:53:30.329371 2026] [security2:error] [pid 87988:tid 88154] [client 34.81.220.187:44050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amurujipAwzptuCxBrhClQAAAS4"]
[Thu Jul 30 14:53:30.395632 2026] [security2:error] [pid 87988:tid 88147] [client 20.199.183.73:24314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/222.php"] [unique_id "amurujipAwzptuCxBrhCngAAASc"]
[Thu Jul 30 14:53:30.501947 2026] [security2:error] [pid 87988:tid 88199] [client 52.238.199.152:47282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/assets/bypass.php"] [unique_id "amurujipAwzptuCxBrhCnwAAAVs"]
[Thu Jul 30 14:53:30.790484 2026] [security2:error] [pid 87988:tid 88142] [client 20.91.199.21:51015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/edit.php"] [unique_id "amurujipAwzptuCxBrhCqQAAASI"]
[Thu Jul 30 14:53:30.823070 2026] [security2:error] [pid 87988:tid 88039] [remote 57.141.0.55:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amurujipAwzptuCxBrhCqgABVzI"]
[Thu Jul 30 14:53:31.520969 2026] [security2:error] [pid 87988:tid 88183] [client 20.199.183.73:23059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuruzipAwzptuCxBrhCuAAAAUs"]
[Thu Jul 30 14:53:31.560624 2026] [security2:error] [pid 87988:tid 88228] [client 20.91.199.21:42938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/f35.php"] [unique_id "amuruzipAwzptuCxBrhCuQAAAXg"]
[Thu Jul 30 14:53:31.649507 2026] [security2:error] [pid 87988:tid 88216] [client 189.156.226.90:27040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuruzipAwzptuCxBrhCugAAAWw"]
[Thu Jul 30 14:53:31.649648 2026] [security2:error] [pid 87988:tid 88216] [client 189.156.226.90:27040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amuruzipAwzptuCxBrhCugAAAWw"]
[Thu Jul 30 14:53:32.088181 2026] [security2:error] [pid 87988:tid 88153] [client 68.67.112.200:12037] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.siatfc.com"] [uri "/robots.txt"] [unique_id "amurvDipAwzptuCxBrhCxgAAAS0"]
[Thu Jul 30 14:53:32.091773 2026] [security2:error] [pid 87988:tid 88044] [remote 103.28.36.122:50744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amurvDipAwzptuCxBrhCxQABKDc"]
[Thu Jul 30 14:53:32.509215 2026] [security2:error] [pid 87988:tid 88126] [client 112.86.225.18:37574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-light-orewood-brown-2/"] [unique_id "amurvDipAwzptuCxBrhC0AAAARI"]
[Thu Jul 30 14:53:32.509344 2026] [security2:error] [pid 87988:tid 88126] [client 112.86.225.18:37574] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-light-orewood-brown-2/"] [unique_id "amurvDipAwzptuCxBrhC0AAAARI"]
[Thu Jul 30 14:53:32.858175 2026] [security2:error] [pid 87988:tid 88150] [client 20.91.199.21:48376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/f7.php"] [unique_id "amurvDipAwzptuCxBrhC1wAAASo"]
[Thu Jul 30 14:53:33.197476 2026] [security2:error] [pid 87988:tid 88146] [client 20.199.183.73:18915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amurvTipAwzptuCxBrhC3QAAASY"]
[Thu Jul 30 14:53:33.701116 2026] [security2:error] [pid 87988:tid 88136] [client 52.238.199.152:47237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/sx.php"] [unique_id "amurvTipAwzptuCxBrhC5wAAARw"]
[Thu Jul 30 14:53:34.551213 2026] [core:notice] [pid 87988:tid 88142] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:34.913473 2026] [security2:error] [pid 87988:tid 88241] [client 54.241.134.202:11070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amurvTipAwzptuCxBrhC2wAAAYU"]
[Thu Jul 30 14:53:35.035586 2026] [security2:error] [pid 87988:tid 88130] [client 52.238.199.152:37149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/adminfuns.php"] [unique_id "amurvzipAwzptuCxBrhDCAAAARY"]
[Thu Jul 30 14:53:35.042369 2026] [security2:error] [pid 87988:tid 88137] [client 157.55.39.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amurvjipAwzptuCxBrhC8QABHUg"]
[Thu Jul 30 14:53:35.176585 2026] [security2:error] [pid 87988:tid 88181] [client 20.199.183.73:40531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/admin.php"] [unique_id "amurvzipAwzptuCxBrhDCgAAAUk"]
[Thu Jul 30 14:53:35.789597 2026] [security2:error] [pid 87988:tid 88160] [client 68.221.69.72:31139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/images.php"] [unique_id "amurvzipAwzptuCxBrhDGgAAATQ"]
[Thu Jul 30 14:53:35.789712 2026] [security2:error] [pid 87988:tid 88160] [client 68.221.69.72:31139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/images.php"] [unique_id "amurvzipAwzptuCxBrhDGgAAATQ"]
[Thu Jul 30 14:53:35.965568 2026] [security2:error] [pid 87988:tid 88240] [client 54.241.134.202:26226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amurvzipAwzptuCxBrhDGQAAAYQ"]
[Thu Jul 30 14:53:36.511813 2026] [security2:error] [pid 87988:tid 88243] [client 52.238.199.152:3684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/about.php"] [unique_id "amurwDipAwzptuCxBrhDKwAAAYc"]
[Thu Jul 30 14:53:36.558433 2026] [security2:error] [pid 87988:tid 88128] [client 20.199.183.73:24285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-configs.php"] [unique_id "amurwDipAwzptuCxBrhDLwAAARQ"]
[Thu Jul 30 14:53:36.720339 2026] [security2:error] [pid 87988:tid 88081] [remote 209.222.97.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.97.222.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "higherdimensionsii.com"] [uri "/xmlrpc.php"] [unique_id "amurwDipAwzptuCxBrhDMAABcVw"]
[Thu Jul 30 14:53:36.720557 2026] [security2:error] [pid 87988:tid 88221] [client 209.222.97.66:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "higherdimensionsii.com"] [uri "/xmlrpc.php"] [unique_id "amurwDipAwzptuCxBrhDMAABcVw"]
[Thu Jul 30 14:53:36.808610 2026] [core:notice] [pid 87988:tid 88086] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:36.825919 2026] [security2:error] [pid 87988:tid 88199] [client 66.249.66.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.glowspakarachi.site"] [uri "/index.php"] [unique_id "amurwDipAwzptuCxBrhDJAAAAVs"]
[Thu Jul 30 14:53:38.602518 2026] [core:notice] [pid 87988:tid 88098] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:38.841610 2026] [security2:error] [pid 87988:tid 88132] [client 20.199.183.73:11888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/php.php"] [unique_id "amurwjipAwzptuCxBrhDcgAAARg"]
[Thu Jul 30 14:53:38.999580 2026] [security2:error] [pid 87988:tid 88157] [client 57.129.139.88:49020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.139.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/tr/index.php"] [unique_id "amurwjipAwzptuCxBrhDbAAAATE"]
[Thu Jul 30 14:53:39.087342 2026] [http2:info] [pid 89520:tid 89520] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 14:53:39.217131 2026] [security2:error] [pid 87988:tid 88185] [client 87.99.139.140:48550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amurwjipAwzptuCxBrhDZwAAAU0"]
[Thu Jul 30 14:53:39.245363 2026] [security2:error] [pid 89520:tid 89665] [client 68.221.69.72:60211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/gecko.php"] [unique_id "amurwy0W4wRrtnDoPajlVAAAAZE"]
[Thu Jul 30 14:53:39.245476 2026] [security2:error] [pid 89520:tid 89665] [client 68.221.69.72:60211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/gecko.php"] [unique_id "amurwy0W4wRrtnDoPajlVAAAAZE"]
[Thu Jul 30 14:53:39.413753 2026] [security2:error] [pid 87988:tid 88182] [client 87.99.139.140:48534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amurwjipAwzptuCxBrhDYgAAASo"]
[Thu Jul 30 14:53:39.417166 2026] [security2:error] [pid 87988:tid 88155] [client 87.99.139.140:48518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amurwjipAwzptuCxBrhDYwAAAWA"]
[Thu Jul 30 14:53:39.519074 2026] [security2:error] [pid 87988:tid 88180] [client 52.238.199.152:37128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/images/chosen.php"] [unique_id "amurwzipAwzptuCxBrhD4wAAAUg"]
[Thu Jul 30 14:53:39.596787 2026] [security2:error] [pid 87988:tid 88196] [client 87.99.139.140:55598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amurwjipAwzptuCxBrhDcAAAAT8"]
[Thu Jul 30 14:53:39.646325 2026] [proxy:error] [pid 87988:tid 88243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:53:39.646374 2026] [proxy_http:error] [pid 87988:tid 88243] [client 87.99.139.140:48552] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:53:39.646937 2026] [proxy:error] [pid 87988:tid 88243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:53:39.646994 2026] [proxy_http:error] [pid 87988:tid 88243] [client 87.99.139.140:48552] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:53:39.679157 2026] [security2:error] [pid 87988:tid 88202] [client 213.32.68.76:56944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.68.32.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/tr/index.php"] [unique_id "amurwzipAwzptuCxBrhD4QAAAV4"]
[Thu Jul 30 14:53:40.435250 2026] [security2:error] [pid 87988:tid 88239] [client 87.99.139.140:55666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.igetvape-australia.com"] [uri "/index.php"] [unique_id "amurwzipAwzptuCxBrhEOwAAAYM"]
[Thu Jul 30 14:53:40.436774 2026] [security2:error] [pid 87988:tid 88200] [client 87.99.139.140:48570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.igetvape-australia.com"] [uri "/index.php"] [unique_id "amurwzipAwzptuCxBrhEIQAAAWI"]
[Thu Jul 30 14:53:40.543432 2026] [security2:error] [pid 89520:tid 89681] [client 87.99.139.140:55642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amurwy0W4wRrtnDoPajlVgAAAZY"]
[Thu Jul 30 14:53:40.546740 2026] [security2:error] [pid 87988:tid 88216] [client 87.99.139.140:55612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amurwzipAwzptuCxBrhEJwAAAUA"]
[Thu Jul 30 14:53:40.695691 2026] [security2:error] [pid 89520:tid 89661] [remote 52.167.144.169:2684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/hermeneutika/article/view/6772"] [unique_id "amurxC0W4wRrtnDoPajlXgABqX8"]
[Thu Jul 30 14:53:41.881233 2026] [security2:error] [pid 89520:tid 89698] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amurxS0W4wRrtnDoPajlZAAAAbI"]
[Thu Jul 30 14:53:42.107795 2026] [security2:error] [pid 89520:tid 89666] [client 20.199.183.73:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/index.php"] [unique_id "amurxi0W4wRrtnDoPajlagAAAZI"]
[Thu Jul 30 14:53:42.180373 2026] [security2:error] [pid 89520:tid 89713] [client 189.156.226.90:27417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurxi0W4wRrtnDoPajlbAAAAcE"]
[Thu Jul 30 14:53:42.180520 2026] [security2:error] [pid 89520:tid 89713] [client 189.156.226.90:27417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amurxi0W4wRrtnDoPajlbAAAAcE"]
[Thu Jul 30 14:53:42.364386 2026] [core:notice] [pid 89520:tid 89722] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:43.099353 2026] [security2:error] [pid 87988:tid 88233] [client 20.199.183.73:49078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/a.php"] [unique_id "amurxzipAwzptuCxBrhEdAAAAX0"]
[Thu Jul 30 14:53:43.518862 2026] [security2:error] [pid 89520:tid 89746] [client 68.221.69.72:55267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/82.php"] [unique_id "amurxy0W4wRrtnDoPajlegAAAeI"]
[Thu Jul 30 14:53:43.519014 2026] [security2:error] [pid 89520:tid 89746] [client 68.221.69.72:55267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/82.php"] [unique_id "amurxy0W4wRrtnDoPajlegAAAeI"]
[Thu Jul 30 14:53:44.043560 2026] [security2:error] [pid 89520:tid 89761] [client 20.199.183.73:24256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuryC0W4wRrtnDoPajlggAAAfE"]
[Thu Jul 30 14:53:45.718408 2026] [security2:error] [pid 89520:tid 89760] [client 52.238.199.152:47243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuryS0W4wRrtnDoPajljAAAAfA"]
[Thu Jul 30 14:53:45.930687 2026] [security2:error] [pid 89520:tid 89785] [client 34.81.220.187:51970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.mskabir.com"] [uri "/wp-config.php.bak"] [unique_id "amuryS0W4wRrtnDoPajlkgAAAgk"]
[Thu Jul 30 14:53:45.935871 2026] [security2:error] [pid 87988:tid 88142] [client 34.81.220.187:52012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/application.properties"] [unique_id "amuryTipAwzptuCxBrhEoAAAASI"]
[Thu Jul 30 14:53:45.936000 2026] [security2:error] [pid 87988:tid 88142] [client 34.81.220.187:52012] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.mskabir.com"] [uri "/application.properties"] [unique_id "amuryTipAwzptuCxBrhEoAAAASI"]
[Thu Jul 30 14:53:46.084654 2026] [security2:error] [pid 87988:tid 88198] [client 34.81.220.187:52010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amuryTipAwzptuCxBrhEngAAAVo"]
[Thu Jul 30 14:53:46.084660 2026] [security2:error] [pid 89520:tid 89783] [client 34.81.220.187:52004] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amuryS0W4wRrtnDoPajljwAAAgc"]
[Thu Jul 30 14:53:46.084687 2026] [security2:error] [pid 89520:tid 89783] [client 34.81.220.187:52004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amuryS0W4wRrtnDoPajljwAAAgc"]
[Thu Jul 30 14:53:46.086599 2026] [security2:error] [pid 87988:tid 88217] [client 34.81.220.187:52030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amuryTipAwzptuCxBrhEnQAAAW0"]
[Thu Jul 30 14:53:46.087523 2026] [security2:error] [pid 89520:tid 89786] [client 34.81.220.187:52018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amuryS0W4wRrtnDoPajlkAAAAgo"]
[Thu Jul 30 14:53:46.088882 2026] [security2:error] [pid 89520:tid 89787] [client 34.81.220.187:51982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amuryS0W4wRrtnDoPajlkwAAAgs"]
[Thu Jul 30 14:53:46.109343 2026] [security2:error] [pid 87988:tid 88222] [client 34.81.220.187:52014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amuryTipAwzptuCxBrhEoQAAAXI"]
[Thu Jul 30 14:53:46.165703 2026] [security2:error] [pid 87988:tid 88225] [client 34.81.220.187:51966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/wp-config.php"] [unique_id "amuryTipAwzptuCxBrhEnAAAAXU"]
[Thu Jul 30 14:53:46.187427 2026] [security2:error] [pid 87988:tid 88232] [client 34.81.220.187:51980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/config.php"] [unique_id "amuryTipAwzptuCxBrhEnwAAAXw"]
[Thu Jul 30 14:53:46.195843 2026] [security2:error] [pid 89520:tid 89788] [client 34.81.220.187:51998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/config.inc.php"] [unique_id "amuryS0W4wRrtnDoPajllAAAAgw"]
[Thu Jul 30 14:53:46.427388 2026] [security2:error] [pid 89520:tid 89773] [client 20.199.183.73:11902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin.php"] [unique_id "amuryi0W4wRrtnDoPajlmAAAAf0"]
[Thu Jul 30 14:53:47.011623 2026] [core:notice] [pid 87988:tid 88213] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:47.111445 2026] [security2:error] [pid 89520:tid 89687] [client 52.238.199.152:3683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/install.php"] [unique_id "amuryy0W4wRrtnDoPajlngAAAac"]
[Thu Jul 30 14:53:47.186368 2026] [proxy:error] [pid 87988:tid 88210] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:53:47.186458 2026] [proxy_http:error] [pid 87988:tid 88210] [client 185.247.137.17:55157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:53:47.187044 2026] [proxy:error] [pid 87988:tid 88210] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:53:47.187089 2026] [proxy_http:error] [pid 87988:tid 88210] [client 185.247.137.17:55157] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:53:47.350449 2026] [security2:error] [pid 89520:tid 89680] [client 20.199.183.73:49074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/size.php"] [unique_id "amuryy0W4wRrtnDoPajloAAAAaA"]
[Thu Jul 30 14:53:47.351335 2026] [security2:error] [pid 89520:tid 89668] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuryi0W4wRrtnDoPajlmgABlAU"]
[Thu Jul 30 14:53:47.500487 2026] [security2:error] [pid 89520:tid 89701] [client 127.0.0.1:38398] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuryy0W4wRrtnDoPajlpAAAAbU"]
[Thu Jul 30 14:53:47.500519 2026] [security2:error] [pid 89520:tid 89690] [client 74.7.241.190:50002] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.tif.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuryy0W4wRrtnDoPajlowAAAao"]
[Thu Jul 30 14:53:48.600483 2026] [core:notice] [pid 89520:tid 89538] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:48.815739 2026] [core:notice] [pid 89520:tid 89541] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:49.088200 2026] [security2:error] [pid 89520:tid 89544] [remote 57.141.0.23:52862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amurzS0W4wRrtnDoPajlvwAB6g4"]
[Thu Jul 30 14:53:49.417837 2026] [security2:error] [pid 89520:tid 89760] [client 68.221.69.72:39044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/xstelth.php"] [unique_id "amurzS0W4wRrtnDoPajlwgAAAfA"]
[Thu Jul 30 14:53:49.417967 2026] [security2:error] [pid 89520:tid 89760] [client 68.221.69.72:39044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/xstelth.php"] [unique_id "amurzS0W4wRrtnDoPajlwgAAAfA"]
[Thu Jul 30 14:53:49.629028 2026] [core:notice] [pid 87988:tid 88185] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:49.744261 2026] [security2:error] [pid 87988:tid 88191] [client 77.75.77.109:1942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/"] [unique_id "amurzTipAwzptuCxBrhE2QAAAVM"]
[Thu Jul 30 14:53:49.744374 2026] [security2:error] [pid 87988:tid 88191] [client 77.75.77.109:1942] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alseermarine.com"] [uri "/"] [unique_id "amurzTipAwzptuCxBrhE2QAAAVM"]
[Thu Jul 30 14:53:49.855500 2026] [security2:error] [pid 89520:tid 89719] [client 20.199.183.73:22536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amurzS0W4wRrtnDoPajlxwAAAcc"]
[Thu Jul 30 14:53:50.293644 2026] [security2:error] [pid 89520:tid 89663] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amurzS0W4wRrtnDoPajlxQAAAY8"]
[Thu Jul 30 14:53:50.349967 2026] [security2:error] [pid 89520:tid 89669] [client 52.238.199.152:3566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/cgi-bin/about.php"] [unique_id "amurzi0W4wRrtnDoPajlyQAAAZU"]
[Thu Jul 30 14:53:51.244467 2026] [security2:error] [pid 89520:tid 89686] [client 52.238.199.152:47268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-admin/css/colors/about.php"] [unique_id "amurzy0W4wRrtnDoPajl1AAAAaY"]
[Thu Jul 30 14:53:51.970552 2026] [security2:error] [pid 89520:tid 89696] [client 68.221.69.72:53199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/xp.php"] [unique_id "amurzy0W4wRrtnDoPajl2gAAAbA"]
[Thu Jul 30 14:53:51.970677 2026] [security2:error] [pid 89520:tid 89696] [client 68.221.69.72:53199] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/xp.php"] [unique_id "amurzy0W4wRrtnDoPajl2gAAAbA"]
[Thu Jul 30 14:53:52.009230 2026] [security2:error] [pid 89520:tid 89674] [client 20.199.183.73:49263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/403.php"] [unique_id "amur0C0W4wRrtnDoPajl2wAAAZo"]
[Thu Jul 30 14:53:52.513882 2026] [core:notice] [pid 87988:tid 88188] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:52.517937 2026] [security2:error] [pid 87988:tid 88188] [client 66.249.79.237:35048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jka/article/view/1299"] [unique_id "amur0DipAwzptuCxBrhE-gAAAVA"]
[Thu Jul 30 14:53:52.740810 2026] [security2:error] [pid 87988:tid 88240] [client 20.199.183.73:22550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amur0DipAwzptuCxBrhE_wAAAYQ"]
[Thu Jul 30 14:53:52.785506 2026] [security2:error] [pid 89520:tid 89729] [client 189.156.226.90:26649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur0C0W4wRrtnDoPajl5QAAAdE"]
[Thu Jul 30 14:53:52.785670 2026] [security2:error] [pid 89520:tid 89729] [client 189.156.226.90:26649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur0C0W4wRrtnDoPajl5QAAAdE"]
[Thu Jul 30 14:53:52.797454 2026] [security2:error] [pid 89520:tid 89737] [client 68.221.69.72:32412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/admin.php"] [unique_id "amur0C0W4wRrtnDoPajl5gAAAdk"]
[Thu Jul 30 14:53:52.797565 2026] [security2:error] [pid 89520:tid 89737] [client 68.221.69.72:32412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/admin.php"] [unique_id "amur0C0W4wRrtnDoPajl5gAAAdk"]
[Thu Jul 30 14:53:53.014842 2026] [core:notice] [pid 89520:tid 89734] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:53.552822 2026] [core:notice] [pid 87988:tid 88148] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:53.851718 2026] [security2:error] [pid 89520:tid 89744] [client 68.221.69.72:39042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/adminner.php"] [unique_id "amur0S0W4wRrtnDoPajl7gAAAeA"]
[Thu Jul 30 14:53:53.851840 2026] [security2:error] [pid 89520:tid 89744] [client 68.221.69.72:39042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/adminner.php"] [unique_id "amur0S0W4wRrtnDoPajl7gAAAeA"]
[Thu Jul 30 14:53:54.016807 2026] [core:notice] [pid 89520:tid 89758] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:54.821322 2026] [core:notice] [pid 89520:tid 89772] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:54.997325 2026] [security2:error] [pid 89520:tid 89755] [client 68.221.69.72:45900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/a.php"] [unique_id "amur0i0W4wRrtnDoPajl-AAAAes"]
[Thu Jul 30 14:53:54.997469 2026] [security2:error] [pid 89520:tid 89755] [client 68.221.69.72:45900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/a.php"] [unique_id "amur0i0W4wRrtnDoPajl-AAAAes"]
[Thu Jul 30 14:53:55.014450 2026] [security2:error] [pid 87988:tid 88241] [client 74.7.244.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcalendars.owz.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/404.html"] [unique_id "amur0zipAwzptuCxBrhFGwAAAYU"]
[Thu Jul 30 14:53:55.015942 2026] [security2:error] [pid 89520:tid 89779] [client 74.7.244.54:41100] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcalendars.owz.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amur0i0W4wRrtnDoPajl-QACAxU"]
[Thu Jul 30 14:53:55.192677 2026] [security2:error] [pid 89520:tid 89781] [client 135.119.63.61:34051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upfile.php"] [unique_id "amur0y0W4wRrtnDoPajl_QAAAgU"]
[Thu Jul 30 14:53:55.368767 2026] [security2:error] [pid 89520:tid 89787] [client 34.81.220.187:37114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0y0W4wRrtnDoPajl_wAAAgs"]
[Thu Jul 30 14:53:55.368805 2026] [security2:error] [pid 89520:tid 89787] [client 34.81.220.187:37114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0y0W4wRrtnDoPajl_wAAAgs"]
[Thu Jul 30 14:53:55.417583 2026] [core:notice] [pid 89520:tid 89773] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:55.488060 2026] [security2:error] [pid 87988:tid 88191] [client 34.81.220.187:37124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0zipAwzptuCxBrhFJQAAAVM"]
[Thu Jul 30 14:53:55.519384 2026] [security2:error] [pid 87988:tid 88185] [client 34.81.220.187:37122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0zipAwzptuCxBrhFJAAAAU0"]
[Thu Jul 30 14:53:55.543144 2026] [security2:error] [pid 87988:tid 88134] [client 34.81.220.187:37154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/.env.sample"] [unique_id "amur0zipAwzptuCxBrhFJgAAARo"]
[Thu Jul 30 14:53:55.636515 2026] [security2:error] [pid 89520:tid 89783] [client 34.81.220.187:37114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0y0W4wRrtnDoPajmBAAAAgc"]
[Thu Jul 30 14:53:55.764721 2026] [security2:error] [pid 89520:tid 89697] [client 68.221.69.72:32774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/k.php"] [unique_id "amur0y0W4wRrtnDoPajmDQAAAbE"]
[Thu Jul 30 14:53:55.764856 2026] [security2:error] [pid 89520:tid 89697] [client 68.221.69.72:32774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/k.php"] [unique_id "amur0y0W4wRrtnDoPajmDQAAAbE"]
[Thu Jul 30 14:53:56.116233 2026] [security2:error] [pid 89520:tid 89790] [client 20.199.183.73:42461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/as.php"] [unique_id "amur1C0W4wRrtnDoPajmEwAAAg4"]
[Thu Jul 30 14:53:56.217094 2026] [security2:error] [pid 89520:tid 89683] [client 34.81.220.187:37140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0y0W4wRrtnDoPajmBQAAAaM"]
[Thu Jul 30 14:53:56.217094 2026] [security2:error] [pid 89520:tid 89684] [client 34.81.220.187:37182] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0y0W4wRrtnDoPajmBgAAAaQ"]
[Thu Jul 30 14:53:56.217129 2026] [security2:error] [pid 89520:tid 89684] [client 34.81.220.187:37182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0y0W4wRrtnDoPajmBgAAAaQ"]
[Thu Jul 30 14:53:56.265037 2026] [security2:error] [pid 89520:tid 89673] [client 34.81.220.187:37166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0y0W4wRrtnDoPajmBwAAAZk"]
[Thu Jul 30 14:53:56.274028 2026] [security2:error] [pid 89520:tid 89685] [client 34.81.220.187:37186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0y0W4wRrtnDoPajmCAAAAaU"]
[Thu Jul 30 14:53:56.295258 2026] [security2:error] [pid 89520:tid 89678] [client 34.81.220.187:37200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur0y0W4wRrtnDoPajmCQAAAZ4"]
[Thu Jul 30 14:53:56.303616 2026] [security2:error] [pid 89520:tid 89704] [client 135.119.63.61:21045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upgrade.php"] [unique_id "amur1C0W4wRrtnDoPajmFgAAAbg"]
[Thu Jul 30 14:53:56.436120 2026] [security2:error] [pid 87988:tid 88139] [client 68.221.69.72:32818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/222.php"] [unique_id "amur1DipAwzptuCxBrhFNgAAAR8"]
[Thu Jul 30 14:53:56.436333 2026] [security2:error] [pid 87988:tid 88139] [client 68.221.69.72:32818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/222.php"] [unique_id "amur1DipAwzptuCxBrhFNgAAAR8"]
[Thu Jul 30 14:53:56.765056 2026] [security2:error] [pid 87988:tid 88196] [client 74.7.244.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.kax.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amur1DipAwzptuCxBrhFOwAAAVg"]
[Thu Jul 30 14:53:56.765700 2026] [security2:error] [pid 87988:tid 88214] [client 74.7.244.62:34044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.kax.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amur1DipAwzptuCxBrhFOgABamQ"]
[Thu Jul 30 14:53:56.893657 2026] [security2:error] [pid 89520:tid 89718] [client 127.0.0.1:15742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amur1C0W4wRrtnDoPajmGwAAAcY"]
[Thu Jul 30 14:53:56.893740 2026] [security2:error] [pid 89520:tid 89716] [client 74.7.230.31:51636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.nka.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amur1C0W4wRrtnDoPajmGgABxBg"]
[Thu Jul 30 14:53:57.068844 2026] [security2:error] [pid 87988:tid 88225] [client 40.77.179.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amur1DipAwzptuCxBrhFQAABdWU"], referer: https://mannyplatoncuevas.com/wp-content/fonts/9fce748c1df0d68d5551526ee784f158.css
[Thu Jul 30 14:53:57.139507 2026] [security2:error] [pid 89520:tid 89722] [client 40.77.179.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mannyplatoncuevas.com"] [uri "/index.php"] [unique_id "amur1S0W4wRrtnDoPajmHQAByhk"], referer: https://mannyplatoncuevas.com/wp-content/fonts/9fce748c1df0d68d5551526ee784f158.css
[Thu Jul 30 14:53:57.177301 2026] [security2:error] [pid 87988:tid 88230] [client 68.221.69.72:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/mac.php"] [unique_id "amur1TipAwzptuCxBrhFRQAAAXo"]
[Thu Jul 30 14:53:57.177406 2026] [security2:error] [pid 87988:tid 88230] [client 68.221.69.72:4234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/mac.php"] [unique_id "amur1TipAwzptuCxBrhFRQAAAXo"]
[Thu Jul 30 14:53:57.316910 2026] [security2:error] [pid 89520:tid 89748] [client 74.7.244.16:33636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.xdi.djb.temporary.site"] [uri "/index.php"] [unique_id "amurzC0W4wRrtnDoPajlvAAB5A0"]
[Thu Jul 30 14:53:57.328057 2026] [security2:error] [pid 89520:tid 89728] [client 135.119.63.61:21042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upl.php"] [unique_id "amur1S0W4wRrtnDoPajmIQAAAdA"]
[Thu Jul 30 14:53:57.861537 2026] [security2:error] [pid 89520:tid 89559] [remote 57.141.0.54:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/485177242/feed/rss2/"] [unique_id "amur1S0W4wRrtnDoPajmJwAB3R0"]
[Thu Jul 30 14:53:58.053942 2026] [security2:error] [pid 89520:tid 89756] [client 68.221.69.72:30689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_webmail/wp-content/uploads/"] [unique_id "amur1i0W4wRrtnDoPajmKQAAAew"]
[Thu Jul 30 14:53:58.059730 2026] [security2:error] [pid 89520:tid 89740] [client 20.199.183.73:40451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amur1i0W4wRrtnDoPajmKgAAAdw"]
[Thu Jul 30 14:53:58.287571 2026] [security2:error] [pid 87988:tid 88131] [client 135.119.63.61:46280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upload-size.php"] [unique_id "amur1jipAwzptuCxBrhFWQAAARc"]
[Thu Jul 30 14:53:58.369357 2026] [security2:error] [pid 89520:tid 89735] [client 68.221.69.72:30689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_webmail/wp-includes/Text/"] [unique_id "amur1i0W4wRrtnDoPajmKwAAAdc"]
[Thu Jul 30 14:53:58.373340 2026] [security2:error] [pid 89520:tid 89726] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amur1S0W4wRrtnDoPajmIgABzhs"]
[Thu Jul 30 14:53:58.503758 2026] [security2:error] [pid 89520:tid 89776] [client 68.221.69.72:30689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/ops.php"] [unique_id "amur1i0W4wRrtnDoPajmMQAAAgA"]
[Thu Jul 30 14:53:58.503906 2026] [security2:error] [pid 89520:tid 89776] [client 68.221.69.72:30689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/ops.php"] [unique_id "amur1i0W4wRrtnDoPajmMQAAAgA"]
[Thu Jul 30 14:53:58.900405 2026] [core:notice] [pid 89520:tid 89672] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:59.090238 2026] [security2:error] [pid 89520:tid 89681] [client 35.204.109.104:4096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.optilexai.com"] [uri "/"] [unique_id "amur1y0W4wRrtnDoPajmOAAAAaE"]
[Thu Jul 30 14:53:59.090327 2026] [security2:error] [pid 89520:tid 89681] [client 35.204.109.104:4096] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.optilexai.com"] [uri "/"] [unique_id "amur1y0W4wRrtnDoPajmOAAAAaE"]
[Thu Jul 30 14:53:59.187051 2026] [security2:error] [pid 89520:tid 89676] [client 135.119.63.61:21023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upload.php"] [unique_id "amur1y0W4wRrtnDoPajmOQAAAZw"]
[Thu Jul 30 14:53:59.218490 2026] [security2:error] [pid 89520:tid 89773] [client 68.221.69.72:59629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/8.php"] [unique_id "amur1y0W4wRrtnDoPajmOwAAAf0"]
[Thu Jul 30 14:53:59.218616 2026] [security2:error] [pid 89520:tid 89773] [client 68.221.69.72:59629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/8.php"] [unique_id "amur1y0W4wRrtnDoPajmOwAAAf0"]
[Thu Jul 30 14:53:59.474484 2026] [core:notice] [pid 89520:tid 89695] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:53:59.792272 2026] [security2:error] [pid 89520:tid 89686] [client 43.173.174.130:50388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/view/9377"] [unique_id "amur1y0W4wRrtnDoPajmQAAAAaY"]
[Thu Jul 30 14:53:59.795551 2026] [security2:error] [pid 87988:tid 88156] [client 68.221.69.72:32797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/FWAZ.php"] [unique_id "amur1zipAwzptuCxBrhFbQAAATA"]
[Thu Jul 30 14:53:59.795626 2026] [security2:error] [pid 87988:tid 88156] [client 68.221.69.72:32797] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/FWAZ.php"] [unique_id "amur1zipAwzptuCxBrhFbQAAATA"]
[Thu Jul 30 14:54:00.096030 2026] [security2:error] [pid 89520:tid 89706] [client 135.119.63.61:21049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upload_crop_v1.2.php"] [unique_id "amur2C0W4wRrtnDoPajmRQAAAbo"]
[Thu Jul 30 14:54:00.450825 2026] [security2:error] [pid 89520:tid 89560] [remote 57.141.0.2:57918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amur2C0W4wRrtnDoPajmSAABox4"]
[Thu Jul 30 14:54:00.479066 2026] [core:notice] [pid 89520:tid 89704] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:00.711089 2026] [core:notice] [pid 89520:tid 89718] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:00.720935 2026] [security2:error] [pid 89520:tid 89666] [client 37.127.175.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amur2C0W4wRrtnDoPajmTgAAAZI"], referer: https://cnpinyin.com
[Thu Jul 30 14:54:00.749175 2026] [security2:error] [pid 89520:tid 89722] [client 68.221.69.72:39100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/biufile.php"] [unique_id "amur2C0W4wRrtnDoPajmUQAAAco"]
[Thu Jul 30 14:54:00.749277 2026] [security2:error] [pid 89520:tid 89722] [client 68.221.69.72:39100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/biufile.php"] [unique_id "amur2C0W4wRrtnDoPajmUQAAAco"]
[Thu Jul 30 14:54:00.920236 2026] [core:notice] [pid 89520:tid 89737] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:01.226347 2026] [security2:error] [pid 89520:tid 89747] [client 20.199.183.73:40499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amur2S0W4wRrtnDoPajmXQAAAeM"]
[Thu Jul 30 14:54:01.276583 2026] [security2:error] [pid 87988:tid 88146] [client 135.119.63.61:20999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upload_handler.php"] [unique_id "amur2TipAwzptuCxBrhFgAAAASY"]
[Thu Jul 30 14:54:01.785175 2026] [security2:error] [pid 87988:tid 88239] [client 20.199.183.73:20570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/plugins.php"] [unique_id "amur2TipAwzptuCxBrhFiwAAAYM"]
[Thu Jul 30 14:54:01.806988 2026] [security2:error] [pid 89520:tid 89751] [client 172.237.109.114:9591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amur2S0W4wRrtnDoPajmWgAAAec"]
[Thu Jul 30 14:54:01.895326 2026] [security2:error] [pid 87988:tid 88008] [remote 74.7.227.39:37120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amur2TipAwzptuCxBrhFjgABcBM"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/woocommerce-amazon-affiliates-light-version/modules/modules_manager
[Thu Jul 30 14:54:02.148710 2026] [security2:error] [pid 87988:tid 88165] [client 68.221.69.72:4385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/coffexium.php"] [unique_id "amur2jipAwzptuCxBrhFlAAAATk"]
[Thu Jul 30 14:54:02.148859 2026] [security2:error] [pid 87988:tid 88165] [client 68.221.69.72:4385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/coffexium.php"] [unique_id "amur2jipAwzptuCxBrhFlAAAATk"]
[Thu Jul 30 14:54:02.247584 2026] [security2:error] [pid 87988:tid 88238] [client 135.119.63.61:20995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploader.php"] [unique_id "amur2jipAwzptuCxBrhFlQAAAYI"]
[Thu Jul 30 14:54:02.477131 2026] [security2:error] [pid 89520:tid 89758] [client 20.199.183.73:40484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/js/index.php"] [unique_id "amur2i0W4wRrtnDoPajmZwAAAe4"]
[Thu Jul 30 14:54:02.632596 2026] [security2:error] [pid 89520:tid 89740] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amur2i0W4wRrtnDoPajmXwAB3B8"]
[Thu Jul 30 14:54:02.800704 2026] [security2:error] [pid 89520:tid 89564] [remote 57.141.0.20:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amur2i0W4wRrtnDoPajmagACBCI"]
[Thu Jul 30 14:54:03.009579 2026] [security2:error] [pid 89520:tid 89681] [client 68.221.69.72:32793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/simple.php"] [unique_id "amur2y0W4wRrtnDoPajmbQAAAaE"]
[Thu Jul 30 14:54:03.009684 2026] [security2:error] [pid 89520:tid 89681] [client 68.221.69.72:32793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/simple.php"] [unique_id "amur2y0W4wRrtnDoPajmbQAAAaE"]
[Thu Jul 30 14:54:03.084128 2026] [security2:error] [pid 89520:tid 89787] [client 185.177.72.70:33004] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "aded-rdc.org"] [uri "/"] [unique_id "amur2y0W4wRrtnDoPajmbgAAAgs"]
[Thu Jul 30 14:54:03.326203 2026] [security2:error] [pid 89520:tid 89689] [client 189.156.226.90:27057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur2y0W4wRrtnDoPajmcQAAAak"]
[Thu Jul 30 14:54:03.326336 2026] [security2:error] [pid 89520:tid 89689] [client 189.156.226.90:27057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur2y0W4wRrtnDoPajmcQAAAak"]
[Thu Jul 30 14:54:03.532439 2026] [security2:error] [pid 89520:tid 89699] [client 68.221.69.72:4958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/fpwch.php"] [unique_id "amur2y0W4wRrtnDoPajmcwAAAbM"]
[Thu Jul 30 14:54:03.532552 2026] [security2:error] [pid 89520:tid 89699] [client 68.221.69.72:4958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/fpwch.php"] [unique_id "amur2y0W4wRrtnDoPajmcwAAAbM"]
[Thu Jul 30 14:54:03.766612 2026] [security2:error] [pid 89520:tid 89784] [client 20.199.183.73:23100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/go.php"] [unique_id "amur2y0W4wRrtnDoPajmdwAAAgg"]
[Thu Jul 30 14:54:04.010160 2026] [security2:error] [pid 89520:tid 89698] [client 31.3.152.100:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.152.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amur3C0W4wRrtnDoPajmeQAAAbI"]
[Thu Jul 30 14:54:04.010268 2026] [security2:error] [pid 89520:tid 89698] [client 31.3.152.100:55512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amur3C0W4wRrtnDoPajmeQAAAbI"]
[Thu Jul 30 14:54:04.015835 2026] [security2:error] [pid 89520:tid 89673] [client 68.221.69.72:59589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/dex.php"] [unique_id "amur3C0W4wRrtnDoPajmegAAAZk"]
[Thu Jul 30 14:54:04.015999 2026] [security2:error] [pid 89520:tid 89673] [client 68.221.69.72:59589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/dex.php"] [unique_id "amur3C0W4wRrtnDoPajmegAAAZk"]
[Thu Jul 30 14:54:04.081831 2026] [security2:error] [pid 87988:tid 88120] [client 135.119.63.61:21018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploadfilewp.php"] [unique_id "amur3DipAwzptuCxBrhFqgAAAQw"]
[Thu Jul 30 14:54:04.270141 2026] [security2:error] [pid 89520:tid 89709] [client 34.81.220.187:23214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur3C0W4wRrtnDoPajmfAAAAb0"]
[Thu Jul 30 14:54:04.339506 2026] [security2:error] [pid 89520:tid 89674] [client 34.81.220.187:23218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur3C0W4wRrtnDoPajmfQAAAZo"]
[Thu Jul 30 14:54:04.370881 2026] [security2:error] [pid 89520:tid 89715] [client 34.81.220.187:23214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/.env.orig"] [unique_id "amur3C0W4wRrtnDoPajmgAAAAcM"]
[Thu Jul 30 14:54:04.384814 2026] [security2:error] [pid 89520:tid 89692] [client 34.81.220.187:23234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/.env.swp"] [unique_id "amur3C0W4wRrtnDoPajmgQAAAaw"]
[Thu Jul 30 14:54:04.399367 2026] [security2:error] [pid 87988:tid 88244] [client 34.81.220.187:23250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/.env~"] [unique_id "amur3DipAwzptuCxBrhFtgAAAYg"]
[Thu Jul 30 14:54:04.403668 2026] [security2:error] [pid 87988:tid 88126] [client 34.81.220.187:23228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur3DipAwzptuCxBrhFsgAAARI"]
[Thu Jul 30 14:54:04.508406 2026] [security2:error] [pid 89520:tid 89710] [client 35.204.157.49:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.supreme-hydraulics.com"] [uri "/"] [unique_id "amur3C0W4wRrtnDoPajmggAAAb4"]
[Thu Jul 30 14:54:04.508559 2026] [security2:error] [pid 89520:tid 89710] [client 35.204.157.49:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.supreme-hydraulics.com"] [uri "/"] [unique_id "amur3C0W4wRrtnDoPajmggAAAb4"]
[Thu Jul 30 14:54:04.767002 2026] [security2:error] [pid 89520:tid 89683] [client 57.141.0.52:58614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amur3C0W4wRrtnDoPajmfwABoyQ"], referer: https://igetvape-australia.com/product/iget-one-chupa-chups-strawberry/
[Thu Jul 30 14:54:04.870096 2026] [security2:error] [pid 87988:tid 88136] [client 34.81.220.187:23228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur3DipAwzptuCxBrhFugAAARw"]
[Thu Jul 30 14:54:04.876756 2026] [security2:error] [pid 87988:tid 88161] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amur3DipAwzptuCxBrhFsQABNQU"]
[Thu Jul 30 14:54:04.902871 2026] [security2:error] [pid 89520:tid 89685] [client 2001:861:6591:a00:6dd7:49bf:3b40:d20c:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amur3C0W4wRrtnDoPajmewABpSM"], referer: https://allmontecristi.com
[Thu Jul 30 14:54:04.916911 2026] [security2:error] [pid 89520:tid 89748] [client 68.221.69.72:59591] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/1.php"] [unique_id "amur3C0W4wRrtnDoPajmiwAAAeQ"]
[Thu Jul 30 14:54:04.917078 2026] [security2:error] [pid 89520:tid 89748] [client 68.221.69.72:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/1.php"] [unique_id "amur3C0W4wRrtnDoPajmiwAAAeQ"]
[Thu Jul 30 14:54:04.917230 2026] [security2:error] [pid 89520:tid 89748] [client 68.221.69.72:59591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/1.php"] [unique_id "amur3C0W4wRrtnDoPajmiwAAAeQ"]
[Thu Jul 30 14:54:04.925126 2026] [security2:error] [pid 87988:tid 88211] [client 34.81.220.187:23250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur3DipAwzptuCxBrhFvwAAAWc"]
[Thu Jul 30 14:54:04.931049 2026] [proxy:error] [pid 87988:tid 88167] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:54:04.931105 2026] [proxy_http:error] [pid 87988:tid 88167] [client 5.161.255.152:49700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:54:04.931841 2026] [proxy:error] [pid 87988:tid 88167] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:54:04.931888 2026] [proxy_http:error] [pid 87988:tid 88167] [client 5.161.255.152:49700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:54:04.951837 2026] [security2:error] [pid 89520:tid 89738] [client 20.199.183.73:16748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/test1.php"] [unique_id "amur3C0W4wRrtnDoPajmjQAAAdo"]
[Thu Jul 30 14:54:04.966329 2026] [security2:error] [pid 89520:tid 89734] [client 34.81.220.187:23214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur3C0W4wRrtnDoPajmigAAAdY"]
[Thu Jul 30 14:54:04.967093 2026] [security2:error] [pid 89520:tid 89729] [client 34.81.220.187:23234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur3C0W4wRrtnDoPajmiQAAAdE"]
[Thu Jul 30 14:54:04.968892 2026] [security2:error] [pid 89520:tid 89732] [client 135.119.63.61:20992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploadk.php"] [unique_id "amur3C0W4wRrtnDoPajmjwAAAdQ"]
[Thu Jul 30 14:54:05.098239 2026] [security2:error] [pid 89520:tid 89741] [client 185.177.72.70:33040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amur3S0W4wRrtnDoPajmkwAAAd0"]
[Thu Jul 30 14:54:05.167759 2026] [core:error] [pid 89520:tid 89750] [client 5.161.255.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:05.167779 2026] [core:error] [pid 89520:tid 89750] [client 5.161.255.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:05.170075 2026] [core:error] [pid 89520:tid 89747] [client 5.161.255.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:05.170099 2026] [core:error] [pid 89520:tid 89747] [client 5.161.255.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:05.425741 2026] [security2:error] [pid 87988:tid 88188] [client 185.177.72.70:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amur3TipAwzptuCxBrhF1AAAAVA"]
[Thu Jul 30 14:54:05.690946 2026] [security2:error] [pid 89520:tid 89665] [client 185.177.72.70:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amur3S0W4wRrtnDoPajmogAAAZE"]
[Thu Jul 30 14:54:05.954879 2026] [security2:error] [pid 89520:tid 89788] [client 185.177.72.70:33060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amur3S0W4wRrtnDoPajmpgAAAgw"]
[Thu Jul 30 14:54:06.097376 2026] [security2:error] [pid 89520:tid 89664] [client 135.119.63.61:46287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploads.php"] [unique_id "amur3i0W4wRrtnDoPajmqgAAAZA"]
[Thu Jul 30 14:54:06.097954 2026] [security2:error] [pid 89520:tid 89680] [client 68.221.69.72:54352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/modern/"] [unique_id "amur3i0W4wRrtnDoPajmqQAAAaA"]
[Thu Jul 30 14:54:06.158548 2026] [security2:error] [pid 87988:tid 88180] [client 20.199.183.73:42487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/images/index.php"] [unique_id "amur3jipAwzptuCxBrhF3QAAAUg"]
[Thu Jul 30 14:54:06.166708 2026] [core:error] [pid 89520:tid 89695] [client 5.161.255.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:06.166725 2026] [core:error] [pid 89520:tid 89695] [client 5.161.255.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:06.212259 2026] [security2:error] [pid 87988:tid 88238] [client 185.177.72.70:33064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amur3jipAwzptuCxBrhF3gAAAYI"]
[Thu Jul 30 14:54:06.349245 2026] [security2:error] [pid 89520:tid 89782] [client 14.29.109.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amur3S0W4wRrtnDoPajmoAAAAgY"]
[Thu Jul 30 14:54:06.356857 2026] [security2:error] [pid 89520:tid 89705] [client 68.221.69.72:54352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/config.json.php"] [unique_id "amur3i0W4wRrtnDoPajmsgAAAbk"]
[Thu Jul 30 14:54:06.356957 2026] [security2:error] [pid 89520:tid 89705] [client 68.221.69.72:54352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/config.json.php"] [unique_id "amur3i0W4wRrtnDoPajmsgAAAbk"]
[Thu Jul 30 14:54:06.493425 2026] [security2:error] [pid 89520:tid 89703] [client 185.177.72.70:33068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amur3i0W4wRrtnDoPajmtQAAAbc"]
[Thu Jul 30 14:54:07.119725 2026] [core:notice] [pid 87988:tid 88227] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:07.394059 2026] [security2:error] [pid 89520:tid 89733] [client 20.199.183.73:16737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/asd.php"] [unique_id "amur3y0W4wRrtnDoPajmwQAAAdU"]
[Thu Jul 30 14:54:07.740821 2026] [security2:error] [pid 87988:tid 88162] [client 135.119.63.61:21028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploads/anceaecs.php"] [unique_id "amur3zipAwzptuCxBrhF-AAAATY"]
[Thu Jul 30 14:54:08.195720 2026] [security2:error] [pid 89520:tid 89731] [client 20.199.183.73:31239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amur4C0W4wRrtnDoPajmxQAAAdM"]
[Thu Jul 30 14:54:08.715647 2026] [security2:error] [pid 89520:tid 89762] [client 68.221.69.72:38716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/k2.php"] [unique_id "amur4C0W4wRrtnDoPajmygAAAfI"]
[Thu Jul 30 14:54:08.715797 2026] [security2:error] [pid 89520:tid 89762] [client 68.221.69.72:38716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/k2.php"] [unique_id "amur4C0W4wRrtnDoPajmygAAAfI"]
[Thu Jul 30 14:54:08.806144 2026] [security2:error] [pid 87988:tid 88170] [client 135.119.63.61:21019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploads/wp-mailcek.php"] [unique_id "amur4DipAwzptuCxBrhGCAAAAT4"]
[Thu Jul 30 14:54:09.105440 2026] [security2:error] [pid 89520:tid 89571] [remote 40.77.167.159:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/issue/view/10"] [unique_id "amur4S0W4wRrtnDoPajmzQABvyk"]
[Thu Jul 30 14:54:09.389941 2026] [core:notice] [pid 89520:tid 89572] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:09.879093 2026] [security2:error] [pid 87988:tid 88216] [client 135.119.63.61:21026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploadsadmin.php"] [unique_id "amur4TipAwzptuCxBrhGFQAAAWw"]
[Thu Jul 30 14:54:10.321715 2026] [security2:error] [pid 87988:tid 88221] [client 68.221.69.72:4515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/raw.php"] [unique_id "amur4jipAwzptuCxBrhGHAAAAXE"]
[Thu Jul 30 14:54:10.321838 2026] [security2:error] [pid 87988:tid 88221] [client 68.221.69.72:4515] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/raw.php"] [unique_id "amur4jipAwzptuCxBrhGHAAAAXE"]
[Thu Jul 30 14:54:10.921095 2026] [security2:error] [pid 89520:tid 89670] [client 184.75.223.203:37450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amur4i0W4wRrtnDoPajm3QAAAZY"]
[Thu Jul 30 14:54:10.921225 2026] [security2:error] [pid 89520:tid 89670] [client 184.75.223.203:37450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amur4i0W4wRrtnDoPajm3QAAAZY"]
[Thu Jul 30 14:54:11.246453 2026] [security2:error] [pid 89520:tid 89750] [client 20.199.183.73:12130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amur4y0W4wRrtnDoPajm4QAAAeY"]
[Thu Jul 30 14:54:12.574993 2026] [security2:error] [pid 89520:tid 89700] [client 172.237.109.114:4501] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amur5C0W4wRrtnDoPajm5wAAAbQ"]
[Thu Jul 30 14:54:12.599751 2026] [security2:error] [pid 87988:tid 88163] [client 135.119.63.61:22794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploadsalfa.php"] [unique_id "amur5DipAwzptuCxBrhGQAAAATc"]
[Thu Jul 30 14:54:12.984239 2026] [security2:error] [pid 89520:tid 89766] [client 68.221.69.72:59593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.69.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/wp.php"] [unique_id "amur5C0W4wRrtnDoPajm7gAAAfY"]
[Thu Jul 30 14:54:12.984370 2026] [security2:error] [pid 89520:tid 89766] [client 68.221.69.72:59593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.ghggeneralcontracting.com"] [uri "/wp.php"] [unique_id "amur5C0W4wRrtnDoPajm7gAAAfY"]
[Thu Jul 30 14:54:13.203131 2026] [security2:error] [pid 89520:tid 89575] [remote 74.7.243.224:41692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/img/Policyf.php"] [unique_id "amur5S0W4wRrtnDoPajm8gABty0"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/img/main_image_6a2032acb13c3.jpg
[Thu Jul 30 14:54:13.699914 2026] [security2:error] [pid 89520:tid 89672] [client 20.199.183.73:12013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/atomlib.php"] [unique_id "amur5S0W4wRrtnDoPajm9gAAAZg"]
[Thu Jul 30 14:54:13.912604 2026] [security2:error] [pid 89520:tid 89709] [client 189.156.226.90:27286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur5S0W4wRrtnDoPajm-AAAAb0"]
[Thu Jul 30 14:54:13.912709 2026] [security2:error] [pid 89520:tid 89709] [client 189.156.226.90:27286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur5S0W4wRrtnDoPajm-AAAAb0"]
[Thu Jul 30 14:54:14.302363 2026] [security2:error] [pid 89520:tid 89717] [client 34.81.220.187:17984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/.env.php"] [unique_id "amur5i0W4wRrtnDoPajm-gAAAcU"]
[Thu Jul 30 14:54:14.317946 2026] [security2:error] [pid 89520:tid 89727] [client 34.81.220.187:17998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/.env.php.bak"] [unique_id "amur5i0W4wRrtnDoPajm-wAAAc8"]
[Thu Jul 30 14:54:14.321085 2026] [security2:error] [pid 87988:tid 88217] [client 34.81.220.187:18000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/.env.php.backup"] [unique_id "amur5jipAwzptuCxBrhGWQAAAW0"]
[Thu Jul 30 14:54:14.359625 2026] [security2:error] [pid 87988:tid 88149] [client 34.81.220.187:18012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/.env.php-bak"] [unique_id "amur5jipAwzptuCxBrhGWgAAASk"]
[Thu Jul 30 14:54:15.023701 2026] [security2:error] [pid 87988:tid 88172] [client 135.119.63.61:22802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploadsbypass.php"] [unique_id "amur5zipAwzptuCxBrhGZgAAAUA"]
[Thu Jul 30 14:54:15.805823 2026] [security2:error] [pid 89520:tid 89744] [client 135.119.63.61:22845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploadsk.php"] [unique_id "amur5y0W4wRrtnDoPajnAgAAAeA"]
[Thu Jul 30 14:54:15.895397 2026] [security2:error] [pid 89520:tid 89576] [remote 160.191.139.115:58732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.139.191.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/wp-login.php"] [unique_id "amur5y0W4wRrtnDoPajnBAAB9S4"]
[Thu Jul 30 14:54:16.431169 2026] [security2:error] [pid 89520:tid 89753] [client 47.128.121.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amur6C0W4wRrtnDoPajnCAAAAek"]
[Thu Jul 30 14:54:16.702528 2026] [security2:error] [pid 89520:tid 89763] [client 172.237.109.114:35867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amur6C0W4wRrtnDoPajnBgAAAfM"]
[Thu Jul 30 14:54:17.352790 2026] [security2:error] [pid 87988:tid 88179] [client 135.119.63.61:21013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploadswp.php"] [unique_id "amur6TipAwzptuCxBrhGhQAAAUc"]
[Thu Jul 30 14:54:18.335023 2026] [security2:error] [pid 89520:tid 89773] [client 135.119.63.61:22834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploadwp.php"] [unique_id "amur6i0W4wRrtnDoPajnGAAAAf0"]
[Thu Jul 30 14:54:18.697780 2026] [security2:error] [pid 87988:tid 88206] [client 20.199.183.73:47878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amur6jipAwzptuCxBrhGogAAAWI"]
[Thu Jul 30 14:54:19.754962 2026] [security2:error] [pid 87988:tid 88220] [client 135.119.63.61:46273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/uploan.php"] [unique_id "amur6zipAwzptuCxBrhGtQAAAXA"]
[Thu Jul 30 14:54:20.151064 2026] [security2:error] [pid 87988:tid 88002] [remote 109.70.100.5:46178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.100.70.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amur7DipAwzptuCxBrhGvwABPA0"], referer: https://deltaedu.net/
[Thu Jul 30 14:54:20.679079 2026] [security2:error] [pid 87988:tid 88148] [client 172.237.109.114:23069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amur7DipAwzptuCxBrhGwgAAASg"]
[Thu Jul 30 14:54:20.723581 2026] [security2:error] [pid 89520:tid 89694] [client 135.119.63.61:22844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/ups.php"] [unique_id "amur7C0W4wRrtnDoPajnKQAAAa4"]
[Thu Jul 30 14:54:21.006654 2026] [security2:error] [pid 89520:tid 89683] [client 20.199.183.73:11719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/inputs.php"] [unique_id "amur7S0W4wRrtnDoPajnNQAAAaM"]
[Thu Jul 30 14:54:21.835959 2026] [security2:error] [pid 87988:tid 88134] [client 135.119.63.61:21003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upspy/con.php"] [unique_id "amur7TipAwzptuCxBrhG3AAAARo"]
[Thu Jul 30 14:54:21.883440 2026] [security2:error] [pid 87988:tid 88244] [client 109.70.100.5:46178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amur7TipAwzptuCxBrhG2wABiHU"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 14:54:21.891295 2026] [security2:error] [pid 89520:tid 89751] [client 45.230.65.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amur7S0W4wRrtnDoPajnPgAAAec"], referer: https://cnpinyin.com
[Thu Jul 30 14:54:22.107063 2026] [security2:error] [pid 87988:tid 87995] [remote 57.141.0.65:41204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amur7jipAwzptuCxBrhG4AABNwY"]
[Thu Jul 30 14:54:22.575538 2026] [security2:error] [pid 89520:tid 89778] [client 20.226.5.174:41347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/leaf_mailer.php"] [unique_id "amur7i0W4wRrtnDoPajnRQAAAgI"]
[Thu Jul 30 14:54:22.953452 2026] [security2:error] [pid 89520:tid 89749] [client 20.199.183.73:35384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/index.php"] [unique_id "amur7i0W4wRrtnDoPajnSAAAAeU"]
[Thu Jul 30 14:54:23.271191 2026] [security2:error] [pid 87988:tid 88025] [remote 57.141.0.37:25140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amur7zipAwzptuCxBrhG-AABWCQ"]
[Thu Jul 30 14:54:23.344642 2026] [security2:error] [pid 89520:tid 89719] [client 34.81.220.187:44890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/.env.php-backup"] [unique_id "amur7y0W4wRrtnDoPajnTAAAAcc"]
[Thu Jul 30 14:54:23.345286 2026] [security2:error] [pid 89520:tid 89740] [client 34.81.220.187:44904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/.env.production.php"] [unique_id "amur7y0W4wRrtnDoPajnTQAAAdw"]
[Thu Jul 30 14:54:23.350424 2026] [security2:error] [pid 87988:tid 88122] [client 34.81.220.187:44930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/.env.sample.php"] [unique_id "amur7zipAwzptuCxBrhG-QAAAQ4"]
[Thu Jul 30 14:54:23.357673 2026] [security2:error] [pid 89520:tid 89789] [client 34.81.220.187:44916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/.env.example.php"] [unique_id "amur7y0W4wRrtnDoPajnUAAAAg0"]
[Thu Jul 30 14:54:23.365052 2026] [security2:error] [pid 89520:tid 89781] [client 34.81.220.187:44928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/.env.local.php"] [unique_id "amur7y0W4wRrtnDoPajnUQAAAgU"]
[Thu Jul 30 14:54:23.428336 2026] [security2:error] [pid 89520:tid 89663] [client 34.81.220.187:45004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/API/.env"] [unique_id "amur7y0W4wRrtnDoPajnVAAAAY8"]
[Thu Jul 30 14:54:23.504433 2026] [security2:error] [pid 87988:tid 88173] [client 20.226.5.174:41360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/leaf_php.php"] [unique_id "amur7zipAwzptuCxBrhG-wAAAUE"]
[Thu Jul 30 14:54:23.511682 2026] [security2:error] [pid 89520:tid 89780] [client 34.81.220.187:44932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur7y0W4wRrtnDoPajnTgAAAgQ"]
[Thu Jul 30 14:54:23.516055 2026] [security2:error] [pid 89520:tid 89667] [client 34.81.220.187:44946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur7y0W4wRrtnDoPajnTwAAAZM"]
[Thu Jul 30 14:54:23.552632 2026] [security2:error] [pid 87988:tid 88165] [client 34.81.220.187:44960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur7zipAwzptuCxBrhG-gAAATk"]
[Thu Jul 30 14:54:23.569680 2026] [security2:error] [pid 89520:tid 89788] [client 34.81.220.187:44968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur7y0W4wRrtnDoPajnUgAAAgw"]
[Thu Jul 30 14:54:23.586051 2026] [security2:error] [pid 89520:tid 89670] [client 34.81.220.187:44992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur7y0W4wRrtnDoPajnUwAAAZY"]
[Thu Jul 30 14:54:23.601896 2026] [security2:error] [pid 89520:tid 89681] [client 34.81.220.187:44978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amur7y0W4wRrtnDoPajnVQAAAaE"]
[Thu Jul 30 14:54:23.655994 2026] [security2:error] [pid 89520:tid 89665] [client 172.237.109.114:41376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amur7y0W4wRrtnDoPajnSQAAAZE"]
[Thu Jul 30 14:54:24.066392 2026] [security2:error] [pid 87988:tid 88210] [client 135.119.63.61:22823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upspy/index.php"] [unique_id "amur8DipAwzptuCxBrhHAgAAAWY"]
[Thu Jul 30 14:54:24.483674 2026] [security2:error] [pid 89520:tid 89764] [client 20.226.5.174:41355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/leafmailer.php"] [unique_id "amur8C0W4wRrtnDoPajnXAAAAfQ"]
[Thu Jul 30 14:54:24.527294 2026] [security2:error] [pid 89520:tid 89689] [client 189.156.226.90:27655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur8C0W4wRrtnDoPajnXQAAAak"]
[Thu Jul 30 14:54:24.527429 2026] [security2:error] [pid 89520:tid 89689] [client 189.156.226.90:27655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur8C0W4wRrtnDoPajnXQAAAak"]
[Thu Jul 30 14:54:25.126376 2026] [security2:error] [pid 87988:tid 88233] [client 135.119.63.61:22824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upspy/sllolx.php"] [unique_id "amur8TipAwzptuCxBrhHEwAAAX0"]
[Thu Jul 30 14:54:25.375098 2026] [security2:error] [pid 89520:tid 89688] [client 20.226.5.174:41358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/leafmailer.php.php"] [unique_id "amur8S0W4wRrtnDoPajnYgAAAag"]
[Thu Jul 30 14:54:25.895025 2026] [security2:error] [pid 89520:tid 89710] [client 135.119.63.61:22790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/upspy/up.php"] [unique_id "amur8S0W4wRrtnDoPajnZwAAAb4"]
[Thu Jul 30 14:54:26.280183 2026] [security2:error] [pid 89520:tid 89673] [client 20.226.5.174:41344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/leafmailer2.8.php"] [unique_id "amur8i0W4wRrtnDoPajnaAAAAZk"]
[Thu Jul 30 14:54:26.537030 2026] [security2:error] [pid 87988:tid 88126] [client 172.237.109.114:52929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amur8jipAwzptuCxBrhHIQAAARI"]
[Thu Jul 30 14:54:27.212868 2026] [security2:error] [pid 89520:tid 89733] [client 20.226.5.174:41364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/led.php"] [unique_id "amur8y0W4wRrtnDoPajncgAAAdU"]
[Thu Jul 30 14:54:27.502513 2026] [security2:error] [pid 89520:tid 89675] [client 203.198.28.191:22129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2012/07/miami-beach-carnet-de-shopping_34.jpg"] [unique_id "amur8y0W4wRrtnDoPajnfgAAAZs"]
[Thu Jul 30 14:54:27.677841 2026] [security2:error] [pid 89520:tid 89720] [client 135.119.63.61:35034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/usb.php"] [unique_id "amur8y0W4wRrtnDoPajnfwAAAcg"]
[Thu Jul 30 14:54:28.148324 2026] [security2:error] [pid 89520:tid 89758] [client 20.226.5.174:7305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/legal.php"] [unique_id "amur9C0W4wRrtnDoPajnhgAAAe4"]
[Thu Jul 30 14:54:28.538957 2026] [security2:error] [pid 87988:tid 88067] [remote 57.141.0.31:22818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/404010317/feed/rss2/"] [unique_id "amur9DipAwzptuCxBrhHYQABIE4"]
[Thu Jul 30 14:54:29.043382 2026] [security2:error] [pid 89520:tid 89682] [client 20.226.5.174:7307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/legion.php"] [unique_id "amur9S0W4wRrtnDoPajnlAAAAaI"]
[Thu Jul 30 14:54:29.302240 2026] [security2:error] [pid 87988:tid 88155] [client 20.199.183.73:39797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/network/index.php"] [unique_id "amur9TipAwzptuCxBrhHbwAAAS8"]
[Thu Jul 30 14:54:29.524280 2026] [core:error] [pid 87988:tid 88223] [client 74.7.244.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:29.524305 2026] [core:error] [pid 87988:tid 88223] [client 74.7.244.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:29.524438 2026] [security2:error] [pid 87988:tid 88223] [client 74.7.244.38:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.reliablehomeappliancerepair.store"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amur9TipAwzptuCxBrhHcwAAAXM"]
[Thu Jul 30 14:54:29.525096 2026] [security2:error] [pid 89520:tid 89684] [client 74.7.244.38:38718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.reliablehomeappliancerepair.store"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amur9S0W4wRrtnDoPajnnAABpD4"]
[Thu Jul 30 14:54:29.935279 2026] [security2:error] [pid 87988:tid 88192] [client 34.86.166.207:51402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amur9TipAwzptuCxBrhHgwAAAVQ"]
[Thu Jul 30 14:54:29.979063 2026] [security2:error] [pid 87988:tid 88196] [client 20.226.5.174:7304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/let.php"] [unique_id "amur9TipAwzptuCxBrhHhAAAAVg"]
[Thu Jul 30 14:54:30.475143 2026] [security2:error] [pid 87988:tid 88138] [client 34.86.166.207:53616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.166.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvapesonline.com"] [uri "/xmlrpc.php"] [unique_id "amur9jipAwzptuCxBrhHrgAAAR4"]
[Thu Jul 30 14:54:30.883596 2026] [security2:error] [pid 89520:tid 89709] [client 20.199.183.73:21870] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "shop-peace.com"] [uri "/wp-content/1.php"] [unique_id "amur9i0W4wRrtnDoPajnowAAAb0"]
[Thu Jul 30 14:54:30.883709 2026] [security2:error] [pid 89520:tid 89709] [client 20.199.183.73:21870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/1.php"] [unique_id "amur9i0W4wRrtnDoPajnowAAAb0"]
[Thu Jul 30 14:54:30.937593 2026] [security2:error] [pid 87988:tid 88175] [client 20.226.5.174:7311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/lf.php"] [unique_id "amur9jipAwzptuCxBrhHugAAAUM"]
[Thu Jul 30 14:54:30.971596 2026] [security2:error] [pid 89520:tid 89674] [client 34.86.166.207:52006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amur9i0W4wRrtnDoPajnpAAAAZo"]
[Thu Jul 30 14:54:31.302693 2026] [security2:error] [pid 87988:tid 88224] [client 135.119.63.61:35052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/use.php"] [unique_id "amur9zipAwzptuCxBrhHxgAAAXQ"]
[Thu Jul 30 14:54:31.453289 2026] [security2:error] [pid 87988:tid 88136] [client 34.81.220.187:45008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/frontend/.env"] [unique_id "amur9zipAwzptuCxBrhHyAAAARw"]
[Thu Jul 30 14:54:31.454091 2026] [security2:error] [pid 87988:tid 88181] [client 34.81.220.187:45034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/public/.env"] [unique_id "amur9zipAwzptuCxBrhHyQAAAUk"]
[Thu Jul 30 14:54:31.454194 2026] [security2:error] [pid 87988:tid 88181] [client 34.81.220.187:45034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.mskabir.com"] [uri "/public/.env"] [unique_id "amur9zipAwzptuCxBrhHyQAAAUk"]
[Thu Jul 30 14:54:31.457397 2026] [security2:error] [pid 87988:tid 88204] [client 34.81.220.187:45012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/web/.env"] [unique_id "amur9zipAwzptuCxBrhHygAAAWA"]
[Thu Jul 30 14:54:31.460113 2026] [security2:error] [pid 89520:tid 89731] [client 34.81.220.187:45018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/www/.env"] [unique_id "amur9y0W4wRrtnDoPajnqAAAAdM"]
[Thu Jul 30 14:54:31.465619 2026] [security2:error] [pid 89520:tid 89757] [client 34.81.220.187:45046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/html/.env"] [unique_id "amur9y0W4wRrtnDoPajnqQAAAe0"]
[Thu Jul 30 14:54:31.465803 2026] [security2:error] [pid 89520:tid 89784] [client 34.86.166.207:57672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amur9y0W4wRrtnDoPajnqgAAAgg"]
[Thu Jul 30 14:54:31.490453 2026] [security2:error] [pid 89520:tid 89747] [client 34.81.220.187:45058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/src/.env"] [unique_id "amur9y0W4wRrtnDoPajnqwAAAeM"]
[Thu Jul 30 14:54:31.549598 2026] [security2:error] [pid 89520:tid 89729] [client 172.237.109.114:39970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amur9y0W4wRrtnDoPajnpQAAAdE"]
[Thu Jul 30 14:54:31.556384 2026] [security2:error] [pid 87988:tid 88219] [client 34.81.220.187:45008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/server/.env"] [unique_id "amur9zipAwzptuCxBrhHywAAAW8"]
[Thu Jul 30 14:54:31.556389 2026] [security2:error] [pid 87988:tid 88245] [client 34.81.220.187:45034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/client/.env"] [unique_id "amur9zipAwzptuCxBrhHzAAAAYk"]
[Thu Jul 30 14:54:31.560830 2026] [security2:error] [pid 87988:tid 88126] [client 34.81.220.187:45012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/core/.env"] [unique_id "amur9zipAwzptuCxBrhHzQAAARI"]
[Thu Jul 30 14:54:31.564694 2026] [security2:error] [pid 89520:tid 89744] [client 34.81.220.187:45018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/apps/.env"] [unique_id "amur9y0W4wRrtnDoPajnrAAAAeA"]
[Thu Jul 30 14:54:31.570444 2026] [security2:error] [pid 89520:tid 89761] [client 34.81.220.187:45046] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/.docker/.env"] [unique_id "amur9y0W4wRrtnDoPajnrQAAAfE"]
[Thu Jul 30 14:54:31.576680 2026] [security2:error] [pid 89520:tid 89765] [client 34.81.220.187:45066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/conf/.env"] [unique_id "amur9y0W4wRrtnDoPajnrgAAAfU"]
[Thu Jul 30 14:54:31.706037 2026] [security2:error] [pid 87988:tid 88162] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amur9zipAwzptuCxBrhHvwAAATY"]
[Thu Jul 30 14:54:31.837553 2026] [security2:error] [pid 89520:tid 89746] [client 20.226.5.174:7327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/library.php"] [unique_id "amur9y0W4wRrtnDoPajnsAAAAeI"]
[Thu Jul 30 14:54:32.008597 2026] [security2:error] [pid 89520:tid 89753] [client 34.86.166.207:62168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amur-C0W4wRrtnDoPajnsgAAAek"]
[Thu Jul 30 14:54:32.118202 2026] [core:notice] [pid 87988:tid 88217] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:32.504628 2026] [security2:error] [pid 89520:tid 89777] [client 34.86.166.207:51842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amur-C0W4wRrtnDoPajntwAAAgE"]
[Thu Jul 30 14:54:32.777968 2026] [security2:error] [pid 89520:tid 89769] [client 20.226.5.174:7309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/library/about.php"] [unique_id "amur-C0W4wRrtnDoPajnugAAAfk"]
[Thu Jul 30 14:54:32.994729 2026] [security2:error] [pid 87988:tid 88130] [client 34.86.166.207:56974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amur-DipAwzptuCxBrhH9gAAARY"]
[Thu Jul 30 14:54:33.364234 2026] [security2:error] [pid 89520:tid 89754] [client 20.199.183.73:16674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/plugin.php"] [unique_id "amur-S0W4wRrtnDoPajnvAAAAeo"]
[Thu Jul 30 14:54:33.487599 2026] [security2:error] [pid 87988:tid 88153] [client 34.86.166.207:56039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amur-TipAwzptuCxBrhIRAAAAS0"]
[Thu Jul 30 14:54:33.639866 2026] [security2:error] [pid 89520:tid 89719] [client 43.172.195.70:50506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/21/etes-vous-plutot-ballerine-ou-spartiate-concours-inside/"] [unique_id "amur-S0W4wRrtnDoPajnvQAAAcc"]
[Thu Jul 30 14:54:33.686804 2026] [security2:error] [pid 89520:tid 89740] [client 20.226.5.174:7312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/library/index.php"] [unique_id "amur-S0W4wRrtnDoPajnvwAAAdw"]
[Thu Jul 30 14:54:33.703715 2026] [security2:error] [pid 87988:tid 88156] [client 185.24.61.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amur-TipAwzptuCxBrhIRwAAATA"], referer: https://cnpinyin.com
[Thu Jul 30 14:54:33.977058 2026] [security2:error] [pid 89520:tid 89676] [client 34.86.166.207:50231] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amur-S0W4wRrtnDoPajnwQAAAZw"]
[Thu Jul 30 14:54:34.149950 2026] [core:notice] [pid 89520:tid 89681] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:34.156556 2026] [security2:error] [pid 89520:tid 89681] [client 43.173.179.71:37862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/03/21/etes-vous-plutot-ballerine-ou-spartiate-concours-inside/"] [unique_id "amur-i0W4wRrtnDoPajnwgAAAaE"], referer: https://carnetdeshopping.com/index.php/2012/03/21/etes-vous-plutot-ballerine-ou-spartiate-concours-inside/?replytocom=448
[Thu Jul 30 14:54:34.488463 2026] [security2:error] [pid 89520:tid 89689] [client 34.86.166.207:56841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amur-i0W4wRrtnDoPajnxQAAAak"]
[Thu Jul 30 14:54:34.626343 2026] [security2:error] [pid 89520:tid 89750] [client 20.226.5.174:7303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/libs.php"] [unique_id "amur-i0W4wRrtnDoPajnxgAAAeY"]
[Thu Jul 30 14:54:34.779495 2026] [security2:error] [pid 87988:tid 88185] [client 20.199.183.73:16670] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "shop-peace.com"] [uri "/1.php"] [unique_id "amur-jipAwzptuCxBrhIWgAAAU0"]
[Thu Jul 30 14:54:34.779643 2026] [security2:error] [pid 87988:tid 88185] [client 20.199.183.73:16670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/1.php"] [unique_id "amur-jipAwzptuCxBrhIWgAAAU0"]
[Thu Jul 30 14:54:34.993301 2026] [security2:error] [pid 87988:tid 88212] [client 34.86.166.207:62222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amur-jipAwzptuCxBrhIYAAAAWg"]
[Thu Jul 30 14:54:35.086038 2026] [security2:error] [pid 89520:tid 89780] [client 189.156.226.90:26901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur-y0W4wRrtnDoPajnzAAAAgQ"]
[Thu Jul 30 14:54:35.086146 2026] [security2:error] [pid 89520:tid 89780] [client 189.156.226.90:26901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amur-y0W4wRrtnDoPajnzAAAAgQ"]
[Thu Jul 30 14:54:35.515095 2026] [security2:error] [pid 87988:tid 88192] [client 34.86.166.207:62168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvapesonline.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amur-zipAwzptuCxBrhIawAAAVQ"]
[Thu Jul 30 14:54:35.521536 2026] [security2:error] [pid 87988:tid 88234] [client 20.226.5.174:7317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/license.php"] [unique_id "amur-zipAwzptuCxBrhIbAAAAX4"]
[Thu Jul 30 14:54:35.779302 2026] [security2:error] [pid 87988:tid 88239] [client 20.199.183.73:37282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/gg.php"] [unique_id "amur-zipAwzptuCxBrhIcQAAAYM"]
[Thu Jul 30 14:54:36.259884 2026] [security2:error] [pid 87988:tid 88187] [client 135.119.63.61:35060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/user-edit.php"] [unique_id "amur_DipAwzptuCxBrhIegAAAU8"]
[Thu Jul 30 14:54:36.686161 2026] [security2:error] [pid 89520:tid 89716] [client 20.226.5.174:7298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/license.txt/xmlrpc.php"] [unique_id "amur_C0W4wRrtnDoPajn0AAAAcQ"]
[Thu Jul 30 14:54:36.692302 2026] [core:error] [pid 87988:tid 87998] [remote 52.167.144.217:16954] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:36.692336 2026] [core:error] [pid 87988:tid 87998] [remote 52.167.144.217:16954] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:37.204064 2026] [security2:error] [pid 89520:tid 89667] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amur_C0W4wRrtnDoPajn1QABk0A"]
[Thu Jul 30 14:54:37.581963 2026] [security2:error] [pid 87988:tid 88120] [client 20.226.5.174:7313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/licenses.php"] [unique_id "amur_TipAwzptuCxBrhIlQAAAQw"]
[Thu Jul 30 14:54:37.588337 2026] [security2:error] [pid 87988:tid 88176] [client 135.119.63.61:35037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/user-new.php"] [unique_id "amur_TipAwzptuCxBrhIlgAAAUQ"]
[Thu Jul 30 14:54:37.590123 2026] [security2:error] [pid 89520:tid 89739] [client 20.199.183.73:16023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp.php"] [unique_id "amur_S0W4wRrtnDoPajn3AAAAds"]
[Thu Jul 30 14:54:37.861262 2026] [security2:error] [pid 87988:tid 87991] [remote 109.70.100.5:46178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.100.70.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amur_TipAwzptuCxBrhIlwABKwI"], referer: https://deltaedu.net/2016/11/06/frequently-asked-questions/
[Thu Jul 30 14:54:37.861580 2026] [security2:error] [pid 87988:tid 88151] [client 109.70.100.5:46178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amur_TipAwzptuCxBrhIlwABKwI"], referer: https://deltaedu.net/2016/11/06/frequently-asked-questions/
[Thu Jul 30 14:54:38.156070 2026] [security2:error] [pid 87988:tid 88107] [remote 109.70.100.5:46178] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amur_jipAwzptuCxBrhInQABSnY"], referer: https://deltaedu.net/wp-comments-post.php
[Thu Jul 30 14:54:38.208685 2026] [security2:error] [pid 87988:tid 88182] [client 109.70.100.5:46178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amur_jipAwzptuCxBrhInQABSnY"], referer: https://deltaedu.net/wp-comments-post.php
[Thu Jul 30 14:54:38.208759 2026] [security2:error] [pid 87988:tid 88182] [client 109.70.100.5:46178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amur_jipAwzptuCxBrhInQABSnY"], referer: https://deltaedu.net/wp-comments-post.php
[Thu Jul 30 14:54:38.320953 2026] [security2:error] [pid 89520:tid 89784] [client 20.199.183.73:37275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amur_i0W4wRrtnDoPajn4QAAAgg"]
[Thu Jul 30 14:54:38.429084 2026] [security2:error] [pid 87988:tid 88245] [client 135.119.63.61:22797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/user.php"] [unique_id "amur_jipAwzptuCxBrhIpgAAAYk"]
[Thu Jul 30 14:54:38.478921 2026] [security2:error] [pid 89520:tid 89747] [client 20.226.5.174:7322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/lightspped.php"] [unique_id "amur_i0W4wRrtnDoPajn4gAAAeM"]
[Thu Jul 30 14:54:39.322004 2026] [security2:error] [pid 87988:tid 88183] [client 20.199.183.73:11707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/file.php"] [unique_id "amur_zipAwzptuCxBrhItQAAAUs"]
[Thu Jul 30 14:54:39.392427 2026] [security2:error] [pid 87988:tid 88146] [client 20.226.5.174:7306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/link.php"] [unique_id "amur_zipAwzptuCxBrhItgAAASY"]
[Thu Jul 30 14:54:39.509392 2026] [security2:error] [pid 87988:tid 88195] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amur_jipAwzptuCxBrhIrQABVwY"]
[Thu Jul 30 14:54:39.741153 2026] [security2:error] [pid 89520:tid 89769] [client 135.119.63.61:46329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/user_guideadmin.php"] [unique_id "amur_y0W4wRrtnDoPajn8AAAAfk"]
[Thu Jul 30 14:54:40.119327 2026] [security2:error] [pid 87988:tid 88186] [client 20.199.183.73:21325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/user/index.php"] [unique_id "amusADipAwzptuCxBrhIwQAAAU4"]
[Thu Jul 30 14:54:40.317182 2026] [security2:error] [pid 89520:tid 89781] [client 20.226.5.174:7316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreview/404.php"] [unique_id "amusAC0W4wRrtnDoPajn9gAAAgU"]
[Thu Jul 30 14:54:41.145595 2026] [security2:error] [pid 89520:tid 89750] [client 20.199.183.73:11710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amusAS0W4wRrtnDoPajn_QAAAeY"]
[Thu Jul 30 14:54:41.249082 2026] [security2:error] [pid 89520:tid 89664] [client 135.119.63.61:35030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/user_guidealfa.php"] [unique_id "amusAS0W4wRrtnDoPajn_gAAAZA"]
[Thu Jul 30 14:54:41.255121 2026] [security2:error] [pid 87988:tid 88121] [client 20.226.5.174:7301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreview/admin.php"] [unique_id "amusATipAwzptuCxBrhI1wAAAQ0"]
[Thu Jul 30 14:54:41.352932 2026] [security2:error] [pid 89520:tid 89705] [client 34.81.220.187:44348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/prod/.env"] [unique_id "amusAS0W4wRrtnDoPajn_wAAAbk"]
[Thu Jul 30 14:54:41.363499 2026] [security2:error] [pid 87988:tid 88150] [client 34.81.220.187:44366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/production/.env"] [unique_id "amusATipAwzptuCxBrhI2wAAASo"]
[Thu Jul 30 14:54:41.363516 2026] [security2:error] [pid 87988:tid 88167] [client 34.81.220.187:44332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/dev/.env"] [unique_id "amusATipAwzptuCxBrhI2gAAATs"]
[Thu Jul 30 14:54:41.372120 2026] [security2:error] [pid 87988:tid 88236] [client 34.81.220.187:44346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/development/.env"] [unique_id "amusATipAwzptuCxBrhI3QAAAYA"]
[Thu Jul 30 14:54:41.377975 2026] [security2:error] [pid 89520:tid 89760] [client 34.81.220.187:44386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/test/.env"] [unique_id "amusAS0W4wRrtnDoPajoAAAAAfA"]
[Thu Jul 30 14:54:41.378174 2026] [security2:error] [pid 87988:tid 88241] [client 34.81.220.187:44376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/staging/.env"] [unique_id "amusATipAwzptuCxBrhI3gAAAYU"]
[Thu Jul 30 14:54:41.452336 2026] [security2:error] [pid 89520:tid 89706] [client 34.81.220.187:44348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/local/.env"] [unique_id "amusAS0W4wRrtnDoPajoAgAAAbo"]
[Thu Jul 30 14:54:41.452446 2026] [security2:error] [pid 89520:tid 89706] [client 34.81.220.187:44348] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.mskabir.com"] [uri "/local/.env"] [unique_id "amusAS0W4wRrtnDoPajoAgAAAbo"]
[Thu Jul 30 14:54:41.467476 2026] [security2:error] [pid 87988:tid 88127] [client 34.81.220.187:44332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/old/.env"] [unique_id "amusATipAwzptuCxBrhI4gAAARM"]
[Thu Jul 30 14:54:41.467475 2026] [security2:error] [pid 87988:tid 88164] [client 34.81.220.187:44366] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/backup/.env"] [unique_id "amusATipAwzptuCxBrhI4QAAATg"]
[Thu Jul 30 14:54:41.477768 2026] [security2:error] [pid 89520:tid 89700] [client 34.81.220.187:44386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/portal/.env"] [unique_id "amusAS0W4wRrtnDoPajoBAAAAbQ"]
[Thu Jul 30 14:54:41.480836 2026] [security2:error] [pid 87988:tid 88120] [client 34.81.220.187:44346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/new/.env"] [unique_id "amusATipAwzptuCxBrhI4wAAAQw"]
[Thu Jul 30 14:54:41.486611 2026] [security2:error] [pid 87988:tid 88176] [client 34.81.220.187:44376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/site/.env"] [unique_id "amusATipAwzptuCxBrhI5AAAAUQ"]
[Thu Jul 30 14:54:41.843602 2026] [security2:error] [pid 89520:tid 89703] [client 20.199.183.73:12203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/index/function.php"] [unique_id "amusAS0W4wRrtnDoPajoBwAAAbc"]
[Thu Jul 30 14:54:42.156267 2026] [security2:error] [pid 89520:tid 89672] [client 20.226.5.174:7323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreview/alfa.php"] [unique_id "amusAi0W4wRrtnDoPajoCAAAAZg"]
[Thu Jul 30 14:54:42.850275 2026] [core:notice] [pid 89520:tid 89604] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:43.049212 2026] [security2:error] [pid 89520:tid 89722] [client 20.226.5.174:7308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreview/bypass.php"] [unique_id "amusAy0W4wRrtnDoPajoEwAAAco"]
[Thu Jul 30 14:54:43.650144 2026] [core:notice] [pid 89520:tid 89710] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:43.654563 2026] [security2:error] [pid 89520:tid 89710] [client 66.249.79.2:41831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/881/566"] [unique_id "amusAy0W4wRrtnDoPajoFQAAAb4"]
[Thu Jul 30 14:54:43.917834 2026] [core:notice] [pid 87988:tid 88086] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:43.944584 2026] [security2:error] [pid 87988:tid 88193] [client 20.226.5.174:7315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreview/class.php"] [unique_id "amusAzipAwzptuCxBrhJEAAAAVU"]
[Thu Jul 30 14:54:44.095779 2026] [security2:error] [pid 89520:tid 89747] [client 20.199.183.73:37269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/aaa.php"] [unique_id "amusBC0W4wRrtnDoPajoHAAAAeM"]
[Thu Jul 30 14:54:44.295460 2026] [fcgid:warn] [pid 89520:tid 89675] (70014)End of file found: [client 199.45.154.123:48888] mod_fcgid: can't get data from http client
[Thu Jul 30 14:54:44.881462 2026] [security2:error] [pid 89520:tid 89711] [client 20.226.5.174:7296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreview/db.php"] [unique_id "amusBC0W4wRrtnDoPajoHwAAAb8"]
[Thu Jul 30 14:54:45.082586 2026] [security2:error] [pid 87988:tid 88137] [client 20.199.183.73:37272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/getid3-core.php"] [unique_id "amusBTipAwzptuCxBrhJIwAAAR0"]
[Thu Jul 30 14:54:45.722281 2026] [security2:error] [pid 89520:tid 89777] [client 189.156.226.90:27179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusBS0W4wRrtnDoPajoKAAAAgE"]
[Thu Jul 30 14:54:45.722394 2026] [security2:error] [pid 89520:tid 89777] [client 189.156.226.90:27179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusBS0W4wRrtnDoPajoKAAAAgE"]
[Thu Jul 30 14:54:45.764302 2026] [security2:error] [pid 87988:tid 88169] [client 20.199.183.73:16662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/adminer.php"] [unique_id "amusBTipAwzptuCxBrhJMAAAAT0"]
[Thu Jul 30 14:54:45.779868 2026] [security2:error] [pid 89520:tid 89778] [client 20.226.5.174:7310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreview/index.php"] [unique_id "amusBS0W4wRrtnDoPajoKQAAAgI"]
[Thu Jul 30 14:54:46.688083 2026] [security2:error] [pid 87988:tid 88135] [client 20.226.5.174:7299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreview/k.php"] [unique_id "amusBjipAwzptuCxBrhJTQAAARs"]
[Thu Jul 30 14:54:47.605771 2026] [security2:error] [pid 89520:tid 89663] [client 20.226.5.174:7329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreview/wp.php"] [unique_id "amusBy0W4wRrtnDoPajoNAAAAY8"]
[Thu Jul 30 14:54:48.521457 2026] [security2:error] [pid 87988:tid 88186] [client 20.226.5.174:7325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreviewadmin.php"] [unique_id "amusCDipAwzptuCxBrhJfgAAAU4"]
[Thu Jul 30 14:54:49.249363 2026] [security2:error] [pid 87988:tid 88235] [client 20.199.183.73:16026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/alfa.php"] [unique_id "amusCTipAwzptuCxBrhJiwAAAX8"]
[Thu Jul 30 14:54:49.417425 2026] [security2:error] [pid 89520:tid 89698] [client 20.226.5.174:7297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreviewalfa.php"] [unique_id "amusCS0W4wRrtnDoPajoRwAAAbI"]
[Thu Jul 30 14:54:49.501785 2026] [core:error] [pid 89520:tid 89699] [client 87.99.137.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:49.501808 2026] [core:error] [pid 89520:tid 89699] [client 87.99.137.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:49.504704 2026] [core:error] [pid 89520:tid 89683] [client 87.99.137.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:49.504725 2026] [core:error] [pid 89520:tid 89683] [client 87.99.137.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:49.535361 2026] [core:error] [pid 87988:tid 88167] [client 87.99.137.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:49.535387 2026] [core:error] [pid 87988:tid 88167] [client 87.99.137.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:49.582273 2026] [core:notice] [pid 89520:tid 89608] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:49.791933 2026] [security2:error] [pid 89520:tid 89704] [client 87.99.137.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amusCS0W4wRrtnDoPajoQQAAAbg"]
[Thu Jul 30 14:54:49.791936 2026] [security2:error] [pid 89520:tid 89714] [client 87.99.137.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amusCS0W4wRrtnDoPajoRgAAAcI"]
[Thu Jul 30 14:54:49.800291 2026] [security2:error] [pid 89520:tid 89722] [client 87.99.137.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amusCS0W4wRrtnDoPajoUQAAAco"]
[Thu Jul 30 14:54:49.804964 2026] [security2:error] [pid 87988:tid 88121] [client 87.99.137.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ear.djb.temporary.site"] [uri "/index.php"] [unique_id "amusCTipAwzptuCxBrhJkAAAAQ0"]
[Thu Jul 30 14:54:49.826137 2026] [security2:error] [pid 89520:tid 89760] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusCS0W4wRrtnDoPajoPQAB8E0"]
[Thu Jul 30 14:54:49.854697 2026] [core:notice] [pid 89520:tid 89609] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:50.145962 2026] [security2:error] [pid 89520:tid 89723] [client 87.99.137.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.totalwebsite.biz"] [uri "/index.php"] [unique_id "amusCi0W4wRrtnDoPajoWAAAAcs"]
[Thu Jul 30 14:54:50.314590 2026] [security2:error] [pid 89520:tid 89708] [client 79.97.112.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amusCi0W4wRrtnDoPajoWwAAAbw"], referer: https://cnpinyin.com
[Thu Jul 30 14:54:50.334845 2026] [security2:error] [pid 87988:tid 88120] [client 20.226.5.174:7320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreviewbypass.php"] [unique_id "amusCjipAwzptuCxBrhJpgAAAQw"]
[Thu Jul 30 14:54:50.344200 2026] [security2:error] [pid 87988:tid 88135] [client 87.99.137.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.totalwebsite.biz"] [uri "/index.php"] [unique_id "amusCjipAwzptuCxBrhJpQAAARs"]
[Thu Jul 30 14:54:50.480280 2026] [security2:error] [pid 89520:tid 89770] [client 65.55.210.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amusCi0W4wRrtnDoPajoWQAB-lA"]
[Thu Jul 30 14:54:50.588451 2026] [core:error] [pid 89520:tid 89772] [client 87.99.137.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:50.588479 2026] [core:error] [pid 89520:tid 89772] [client 87.99.137.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:54:50.644312 2026] [security2:error] [pid 89520:tid 89746] [client 109.93.214.228:6399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.214.93.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amusCi0W4wRrtnDoPajoXwAAAeI"]
[Thu Jul 30 14:54:50.644501 2026] [security2:error] [pid 89520:tid 89746] [client 109.93.214.228:6399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amusCi0W4wRrtnDoPajoXwAAAeI"]
[Thu Jul 30 14:54:50.780673 2026] [core:notice] [pid 89520:tid 89613] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:50.790689 2026] [core:notice] [pid 87988:tid 88084] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:51.133837 2026] [core:notice] [pid 89520:tid 89614] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:51.150894 2026] [core:notice] [pid 87988:tid 88025] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:51.269969 2026] [security2:error] [pid 89520:tid 89789] [client 20.226.5.174:7336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/linkpreviewk.php"] [unique_id "amusCy0W4wRrtnDoPajobQAAAg0"]
[Thu Jul 30 14:54:51.325095 2026] [proxy:error] [pid 89520:tid 89691] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:54:51.325147 2026] [proxy_http:error] [pid 89520:tid 89691] [client 87.99.137.223:50742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:54:51.325887 2026] [proxy:error] [pid 89520:tid 89691] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:54:51.325932 2026] [proxy_http:error] [pid 89520:tid 89691] [client 87.99.137.223:50742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:54:51.634177 2026] [security2:error] [pid 89520:tid 89737] [client 212.70.106.89:64208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.106.70.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alqimmafurnituremovers.xyz"] [uri "/xmlrpc.php"] [unique_id "amusCy0W4wRrtnDoPajobwAAAdk"]
[Thu Jul 30 14:54:51.634298 2026] [security2:error] [pid 89520:tid 89737] [client 212.70.106.89:64208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alqimmafurnituremovers.xyz"] [uri "/xmlrpc.php"] [unique_id "amusCy0W4wRrtnDoPajobwAAAdk"]
[Thu Jul 30 14:54:52.201150 2026] [core:notice] [pid 89520:tid 89667] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:54:53.002590 2026] [security2:error] [pid 89520:tid 89672] [client 57.141.0.16:47214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amusDC0W4wRrtnDoPajogQABmFc"], referer: https://igetvape-australia.com/cart/
[Thu Jul 30 14:54:54.766328 2026] [security2:error] [pid 89520:tid 89747] [client 20.199.183.73:18648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amusDi0W4wRrtnDoPajojgAAAeM"]
[Thu Jul 30 14:54:56.306530 2026] [security2:error] [pid 87988:tid 88183] [client 189.156.226.90:27567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusEDipAwzptuCxBrhJ9AAAAUs"]
[Thu Jul 30 14:54:56.306651 2026] [security2:error] [pid 87988:tid 88183] [client 189.156.226.90:27567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusEDipAwzptuCxBrhJ9AAAAUs"]
[Thu Jul 30 14:54:57.017333 2026] [security2:error] [pid 89520:tid 89706] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusEC0W4wRrtnDoPajorAAAAbo"]
[Thu Jul 30 14:54:57.711103 2026] [security2:error] [pid 87988:tid 88208] [client 34.81.220.187:56932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/crm/.env"] [unique_id "amusETipAwzptuCxBrhKCAAAAWQ"]
[Thu Jul 30 14:54:57.721528 2026] [security2:error] [pid 89520:tid 89680] [client 34.81.220.187:56934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/application/.env"] [unique_id "amusES0W4wRrtnDoPajougAAAaA"]
[Thu Jul 30 14:54:57.729868 2026] [security2:error] [pid 89520:tid 89722] [client 34.81.220.187:56948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/project/.env"] [unique_id "amusES0W4wRrtnDoPajouwAAAco"]
[Thu Jul 30 14:54:57.729991 2026] [security2:error] [pid 89520:tid 89722] [client 34.81.220.187:56948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.mskabir.com"] [uri "/project/.env"] [unique_id "amusES0W4wRrtnDoPajouwAAAco"]
[Thu Jul 30 14:54:57.742299 2026] [security2:error] [pid 87988:tid 88211] [client 20.199.183.73:18682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amusETipAwzptuCxBrhKCgAAAWc"]
[Thu Jul 30 14:54:57.742450 2026] [security2:error] [pid 87988:tid 88174] [client 34.81.220.187:56960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/v1/.env"] [unique_id "amusETipAwzptuCxBrhKCQAAAUI"]
[Thu Jul 30 14:54:57.789305 2026] [security2:error] [pid 89520:tid 89633] [remote 216.73.216.51:26446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amusES0W4wRrtnDoPajovAAB8mY"]
[Thu Jul 30 14:54:58.245058 2026] [security2:error] [pid 89520:tid 89684] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amusEi0W4wRrtnDoPajowQAAAaQ"]
[Thu Jul 30 14:54:58.605608 2026] [security2:error] [pid 89520:tid 89756] [client 20.199.183.73:38499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amusEi0W4wRrtnDoPajoxQAAAew"]
[Thu Jul 30 14:54:59.320771 2026] [security2:error] [pid 87988:tid 88100] [remote 57.141.18.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amusEzipAwzptuCxBrhKIwABP28"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,lycra,nylon,plastic,polyester,steel,wood&filter_size=extra-extra-large,large,small&min_price=75&max_price=125&unfilter=1
[Thu Jul 30 14:54:59.429632 2026] [security2:error] [pid 89520:tid 89758] [client 20.199.183.73:21536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/edit.php"] [unique_id "amusEy0W4wRrtnDoPajo1QAAAe4"]
[Thu Jul 30 14:54:59.532609 2026] [security2:error] [pid 89520:tid 89771] [client 172.237.109.114:44495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amusEy0W4wRrtnDoPajozQAAAfs"]
[Thu Jul 30 14:54:59.533015 2026] [security2:error] [pid 89520:tid 89643] [remote 57.141.18.109:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amusEy0W4wRrtnDoPajo0wABzm4"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,lycra,nylon,plastic,polyester,steel,wood&filter_size=extra-extra-large,large,small&min_price=75&max_price=125&unfilter=1
[Thu Jul 30 14:55:00.348050 2026] [security2:error] [pid 89520:tid 89691] [client 20.199.183.73:21361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/sf.php"] [unique_id "amusFC0W4wRrtnDoPajo3wAAAas"]
[Thu Jul 30 14:55:01.476001 2026] [security2:error] [pid 89520:tid 89699] [client 52.167.144.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amusFS0W4wRrtnDoPajo6AAAAbM"]
[Thu Jul 30 14:55:01.476865 2026] [security2:error] [pid 89520:tid 89764] [client 157.148.43.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amusFC0W4wRrtnDoPajo5AAAAfQ"]
[Thu Jul 30 14:55:01.605247 2026] [security2:error] [pid 87988:tid 88243] [client 20.199.183.73:38494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wso.php"] [unique_id "amusFTipAwzptuCxBrhKRwAAAYc"]
[Thu Jul 30 14:55:02.768773 2026] [security2:error] [pid 89520:tid 89684] [client 20.199.183.73:34460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/ioxi-o.php"] [unique_id "amusFi0W4wRrtnDoPajo_wAAAaQ"]
[Thu Jul 30 14:55:03.979500 2026] [security2:error] [pid 89520:tid 89737] [client 20.199.183.73:16010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/file56.php"] [unique_id "amusFy0W4wRrtnDoPajpEgAAAdk"]
[Thu Jul 30 14:55:04.199125 2026] [core:notice] [pid 89520:tid 89727] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:04.406998 2026] [core:notice] [pid 89520:tid 89698] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:06.142779 2026] [security2:error] [pid 87988:tid 88119] [client 127.0.0.1:45310] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amusGjipAwzptuCxBrhKcgAAAQs"]
[Thu Jul 30 14:55:06.142893 2026] [security2:error] [pid 89520:tid 89756] [client 74.7.241.169:53124] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amusGi0W4wRrtnDoPajpJAAB7HQ"]
[Thu Jul 30 14:55:06.746772 2026] [security2:error] [pid 89520:tid 89733] [client 20.199.183.73:38519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amusGi0W4wRrtnDoPajpKAAAAdU"]
[Thu Jul 30 14:55:06.819257 2026] [security2:error] [pid 87988:tid 88192] [client 189.156.226.90:26658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusGjipAwzptuCxBrhKfgAAAVQ"]
[Thu Jul 30 14:55:06.819361 2026] [security2:error] [pid 87988:tid 88192] [client 189.156.226.90:26658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusGjipAwzptuCxBrhKfgAAAVQ"]
[Thu Jul 30 14:55:07.467592 2026] [security2:error] [pid 89520:tid 89708] [client 2a00:1d34:d8eb:ab00::2:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "allmontecristi.com"] [uri "/xmlrpc.php"] [unique_id "amusGi0W4wRrtnDoPajpJQABvHU"]
[Thu Jul 30 14:55:07.993160 2026] [core:notice] [pid 87988:tid 87995] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:08.201607 2026] [core:notice] [pid 89520:tid 89753] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:08.798524 2026] [security2:error] [pid 89520:tid 89750] [client 116.179.32.236:9263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/issue/view/555"] [unique_id "amusHC0W4wRrtnDoPajpPAAAAeY"]
[Thu Jul 30 14:55:09.084435 2026] [core:notice] [pid 87988:tid 88027] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:09.086207 2026] [core:notice] [pid 89520:tid 89654] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:09.353445 2026] [core:notice] [pid 87988:tid 88024] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:09.357116 2026] [core:notice] [pid 89520:tid 89655] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:09.453074 2026] [core:notice] [pid 89520:tid 89693] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:09.808480 2026] [core:notice] [pid 87988:tid 88141] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:10.084246 2026] [security2:error] [pid 87988:tid 88175] [client 34.81.220.187:45922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.mskabir.com"] [uri "/v2/.env"] [unique_id "amusHjipAwzptuCxBrhKqgAAAUM"]
[Thu Jul 30 14:55:10.086591 2026] [security2:error] [pid 89520:tid 89764] [client 34.81.220.187:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/twilio/.env.php"] [unique_id "amusHi0W4wRrtnDoPajpTwAAAfQ"]
[Thu Jul 30 14:55:10.089015 2026] [security2:error] [pid 89520:tid 89707] [client 34.81.220.187:45942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/sendgrid/.env.php"] [unique_id "amusHi0W4wRrtnDoPajpUAAAAbs"]
[Thu Jul 30 14:55:10.091814 2026] [security2:error] [pid 89520:tid 89657] [remote 47.128.28.117:51020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/3/"] [unique_id "amusHi0W4wRrtnDoPajpUQABwns"]
[Thu Jul 30 14:55:10.092670 2026] [security2:error] [pid 87988:tid 88216] [client 34.81.220.187:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.220.81.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mskabir.com"] [uri "/config/.env.php"] [unique_id "amusHjipAwzptuCxBrhKrQAAAWw"]
[Thu Jul 30 14:55:10.284137 2026] [security2:error] [pid 87988:tid 88169] [client 34.81.220.187:45996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusHjipAwzptuCxBrhKrAAAAT0"]
[Thu Jul 30 14:55:10.289030 2026] [security2:error] [pid 87988:tid 88134] [client 34.81.220.187:45982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusHjipAwzptuCxBrhKrgAAARo"]
[Thu Jul 30 14:55:10.289286 2026] [security2:error] [pid 87988:tid 88181] [client 34.81.220.187:45988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusHjipAwzptuCxBrhKsAAAAUk"]
[Thu Jul 30 14:55:10.289458 2026] [security2:error] [pid 89520:tid 89752] [client 34.81.220.187:46010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusHi0W4wRrtnDoPajpUgAAAeg"]
[Thu Jul 30 14:55:10.298339 2026] [security2:error] [pid 87988:tid 88153] [client 34.81.220.187:45976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusHjipAwzptuCxBrhKqwAAAS0"]
[Thu Jul 30 14:55:10.300066 2026] [security2:error] [pid 87988:tid 88178] [client 34.81.220.187:45958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusHjipAwzptuCxBrhKrwAAAUY"]
[Thu Jul 30 14:55:10.305761 2026] [security2:error] [pid 89520:tid 89739] [client 34.81.220.187:46002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusHi0W4wRrtnDoPajpUwAAAds"]
[Thu Jul 30 14:55:10.309795 2026] [security2:error] [pid 87988:tid 88241] [client 34.81.220.187:46022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusHjipAwzptuCxBrhKsQAAAYU"]
[Thu Jul 30 14:55:10.443020 2026] [core:notice] [pid 89520:tid 89724] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:11.612407 2026] [core:error] [pid 87988:tid 88225] [client 40.77.167.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:55:11.612429 2026] [core:error] [pid 87988:tid 88225] [client 40.77.167.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:55:12.102972 2026] [core:notice] [pid 89520:tid 89658] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:12.435428 2026] [core:notice] [pid 89520:tid 89660] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:12.445818 2026] [security2:error] [pid 87988:tid 88234] [client 172.237.109.114:64276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amusHzipAwzptuCxBrhKzgAAAX4"]
[Thu Jul 30 14:55:12.481064 2026] [security2:error] [pid 87988:tid 88076] [remote 97.74.93.24:46160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amusIDipAwzptuCxBrhK1QABfFc"]
[Thu Jul 30 14:55:13.207424 2026] [security2:error] [pid 89520:tid 89661] [remote 74.7.243.224:37356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/js/Policyf.php"] [unique_id "amusIS0W4wRrtnDoPajpbgABnH8"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/js/bootstrap.bundle.min.js
[Thu Jul 30 14:55:14.452343 2026] [proxy:error] [pid 87988:tid 88226] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:14.452401 2026] [proxy_http:error] [pid 87988:tid 88226] [client 94.154.43.229:32596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:14.453012 2026] [proxy:error] [pid 87988:tid 88226] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:14.453058 2026] [proxy_http:error] [pid 87988:tid 88226] [client 94.154.43.229:32596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:14.607365 2026] [proxy:error] [pid 87988:tid 88244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:14.607419 2026] [proxy_http:error] [pid 87988:tid 88244] [client 94.154.43.187:60674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:14.608189 2026] [proxy:error] [pid 87988:tid 88244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:14.608237 2026] [proxy_http:error] [pid 87988:tid 88244] [client 94.154.43.187:60674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:15.804299 2026] [security2:error] [pid 87988:tid 88140] [client 20.199.183.73:29381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-admin/css/index.php"] [unique_id "amusIzipAwzptuCxBrhLDQAAASA"]
[Thu Jul 30 14:55:16.325049 2026] [security2:error] [pid 87988:tid 88049] [remote 47.128.28.100:28994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/off-white-nike-dunk/"] [unique_id "amusJDipAwzptuCxBrhLFQABDjw"]
[Thu Jul 30 14:55:16.557003 2026] [security2:error] [pid 87988:tid 88201] [client 20.199.183.73:42396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/edit.php"] [unique_id "amusJDipAwzptuCxBrhLHAAAAV0"]
[Thu Jul 30 14:55:16.747270 2026] [core:notice] [pid 87988:tid 88081] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:16.832928 2026] [core:notice] [pid 87988:tid 88089] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:17.001850 2026] [core:notice] [pid 87988:tid 88073] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:17.094012 2026] [core:notice] [pid 87988:tid 88031] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:17.187235 2026] [security2:error] [pid 89520:tid 89731] [client 20.199.183.73:18643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/2.php"] [unique_id "amusJS0W4wRrtnDoPajpgwAAAdM"]
[Thu Jul 30 14:55:17.385111 2026] [security2:error] [pid 89520:tid 89722] [client 189.156.226.90:26992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusJS0W4wRrtnDoPajphAAAAco"]
[Thu Jul 30 14:55:17.385235 2026] [security2:error] [pid 89520:tid 89722] [client 189.156.226.90:26992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusJS0W4wRrtnDoPajphAAAAco"]
[Thu Jul 30 14:55:17.520761 2026] [security2:error] [pid 87988:tid 88189] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusJDipAwzptuCxBrhLJgABUU0"]
[Thu Jul 30 14:55:17.828491 2026] [security2:error] [pid 87988:tid 88210] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusJTipAwzptuCxBrhLLQABZmY"]
[Thu Jul 30 14:55:18.031732 2026] [security2:error] [pid 87988:tid 88204] [client 20.199.183.73:16048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amusJjipAwzptuCxBrhLPgAAAWA"]
[Thu Jul 30 14:55:18.115337 2026] [security2:error] [pid 89520:tid 89664] [client 66.249.79.2:44249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amusIy0W4wRrtnDoPajpeQAAAZA"], referer: https://stunningtouchcleaning.com/
[Thu Jul 30 14:55:18.203276 2026] [core:notice] [pid 87988:tid 88185] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:18.205564 2026] [autoindex:error] [pid 89520:tid 89760] [client 94.154.43.188:37930] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_72d2afbe/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:55:18.481580 2026] [security2:error] [pid 87988:tid 88173] [client 173.252.82.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.myintentionalreset.com"] [uri "/index.php"] [unique_id "amusJDipAwzptuCxBrhLGwAAAUE"]
[Thu Jul 30 14:55:19.222135 2026] [core:error] [pid 89520:tid 89532] [remote 74.7.175.153:43826] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:55:19.222166 2026] [core:error] [pid 89520:tid 89532] [remote 74.7.175.153:43826] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:55:19.222399 2026] [security2:error] [pid 89520:tid 89718] [client 74.7.175.153:43826] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-b63f1d3b.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amusJy0W4wRrtnDoPajpkQABxgI"]
[Thu Jul 30 14:55:20.876940 2026] [security2:error] [pid 89520:tid 89723] [client 20.199.183.73:18651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/mah.php"] [unique_id "amusKC0W4wRrtnDoPajpnwAAAcs"]
[Thu Jul 30 14:55:21.267720 2026] [security2:error] [pid 89520:tid 89771] [client 66.249.79.1:50621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amusKC0W4wRrtnDoPajpngAAAfs"], referer: https://stunningtouchcleaning.com/
[Thu Jul 30 14:55:21.657693 2026] [security2:error] [pid 87988:tid 87998] [remote 57.141.0.61:53298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amusKTipAwzptuCxBrhLcAABKAk"]
[Thu Jul 30 14:55:21.946798 2026] [proxy:error] [pid 87988:tid 88096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:21.946850 2026] [proxy_http:error] [pid 87988:tid 88096] [remote 216.73.216.143:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:21.947434 2026] [proxy:error] [pid 87988:tid 88096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:21.947479 2026] [proxy_http:error] [pid 87988:tid 88096] [remote 216.73.216.143:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:22.014960 2026] [security2:error] [pid 89520:tid 89763] [client 20.199.183.73:37263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/send.php"] [unique_id "amusKi0W4wRrtnDoPajprQAAAfM"]
[Thu Jul 30 14:55:22.120765 2026] [security2:error] [pid 89520:tid 89728] [client 66.249.79.1:50621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amusKS0W4wRrtnDoPajpqAAAAdA"], referer: https://stunningtouchcleaning.com/
[Thu Jul 30 14:55:22.175770 2026] [security2:error] [pid 87988:tid 88126] [client 34.81.220.187:46056] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/cgi-sys/404.html"] [unique_id "amusKjipAwzptuCxBrhLeQAAARI"]
[Thu Jul 30 14:55:22.304920 2026] [security2:error] [pid 87988:tid 88216] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusKTipAwzptuCxBrhLcQAAAWw"]
[Thu Jul 30 14:55:22.373460 2026] [security2:error] [pid 89520:tid 89701] [client 34.81.220.187:46078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusKi0W4wRrtnDoPajpswAAAbU"]
[Thu Jul 30 14:55:22.406055 2026] [authz_core:error] [pid 87988:tid 88227] [client 34.81.220.187:46092] AH01630: client denied by server configuration: /home1/uqrdjbte/public_html/.htpasswd
[Thu Jul 30 14:55:22.452235 2026] [security2:error] [pid 89520:tid 89693] [client 34.81.220.187:46054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusKi0W4wRrtnDoPajptQAAAa0"]
[Thu Jul 30 14:55:22.455058 2026] [security2:error] [pid 89520:tid 89673] [client 34.81.220.187:46068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusKi0W4wRrtnDoPajptAAAAZk"]
[Thu Jul 30 14:55:22.498653 2026] [security2:error] [pid 87988:tid 88204] [client 34.81.220.187:46056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/index.php"] [unique_id "amusKjipAwzptuCxBrhLfAAAAWA"]
[Thu Jul 30 14:55:22.560546 2026] [proxy:error] [pid 87988:tid 88109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:22.560623 2026] [proxy_http:error] [pid 87988:tid 88109] [remote 216.73.216.143:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:22.561370 2026] [proxy:error] [pid 87988:tid 88109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:22.561421 2026] [proxy_http:error] [pid 87988:tid 88109] [remote 216.73.216.143:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:22.572648 2026] [security2:error] [pid 89520:tid 89768] [client 2a03:2880:f800:c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusKS0W4wRrtnDoPajpqgAB-AU"]
[Thu Jul 30 14:55:22.952346 2026] [security2:error] [pid 87988:tid 88112] [remote 72.167.132.114:41168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jgp.fxh.temporary.site"] [uri "/wp-login.php"] [unique_id "amusKjipAwzptuCxBrhLhgABPns"]
[Thu Jul 30 14:55:24.629380 2026] [security2:error] [pid 89520:tid 89727] [client 20.199.183.73:42425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amusLC0W4wRrtnDoPajpzgAAAc8"]
[Thu Jul 30 14:55:25.356931 2026] [security2:error] [pid 89520:tid 89778] [client 31.3.152.100:41338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.152.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amusLS0W4wRrtnDoPajp1gAAAgI"]
[Thu Jul 30 14:55:25.357046 2026] [security2:error] [pid 89520:tid 89778] [client 31.3.152.100:41338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amusLS0W4wRrtnDoPajp1gAAAgI"]
[Thu Jul 30 14:55:25.534498 2026] [security2:error] [pid 87988:tid 88157] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusLDipAwzptuCxBrhLpwAAATE"]
[Thu Jul 30 14:55:26.188002 2026] [security2:error] [pid 89520:tid 89777] [client 20.199.183.73:37308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/about.php"] [unique_id "amusLi0W4wRrtnDoPajp3QAAAgE"]
[Thu Jul 30 14:55:26.695026 2026] [security2:error] [pid 87988:tid 88023] [remote 57.141.0.70:24226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amusLjipAwzptuCxBrhLuAABgCI"]
[Thu Jul 30 14:55:26.931943 2026] [security2:error] [pid 87988:tid 88181] [client 52.238.199.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amusLjipAwzptuCxBrhLwAAAAUk"]
[Thu Jul 30 14:55:27.925224 2026] [security2:error] [pid 89520:tid 89699] [client 189.156.226.90:27232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusLy0W4wRrtnDoPajp7wAAAbM"]
[Thu Jul 30 14:55:27.925351 2026] [security2:error] [pid 89520:tid 89699] [client 189.156.226.90:27232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusLy0W4wRrtnDoPajp7wAAAbM"]
[Thu Jul 30 14:55:28.301901 2026] [security2:error] [pid 89520:tid 89736] [client 20.226.5.174:6800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/providers/index.php"] [unique_id "amusMC0W4wRrtnDoPajp9QAAAdg"]
[Thu Jul 30 14:55:29.270458 2026] [security2:error] [pid 87988:tid 88140] [client 20.226.5.174:6794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/providers/ultra.php"] [unique_id "amusMTipAwzptuCxBrhL3wAAASA"]
[Thu Jul 30 14:55:29.480294 2026] [security2:error] [pid 89520:tid 89679] [client 20.199.183.73:29428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/options.php"] [unique_id "amusMS0W4wRrtnDoPajqAAAAAZ8"]
[Thu Jul 30 14:55:30.072202 2026] [security2:error] [pid 89520:tid 89688] [client 44.208.193.63:5561] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2014/07/DSC00917-300x225.jpg"] [unique_id "amusMi0W4wRrtnDoPajqBQAAAag"]
[Thu Jul 30 14:55:30.234811 2026] [security2:error] [pid 87988:tid 88187] [client 20.226.5.174:6809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/providers/wp-conflg.php"] [unique_id "amusMjipAwzptuCxBrhL7wAAAU8"]
[Thu Jul 30 14:55:30.460266 2026] [security2:error] [pid 89520:tid 89780] [client 37.236.203.5:43264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusMS0W4wRrtnDoPajqAQAAAgQ"], referer: http://pkf.jo
[Thu Jul 30 14:55:30.595598 2026] [security2:error] [pid 87988:tid 88241] [client 71.12.253.156:43620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusLjipAwzptuCxBrhLwQAAAYU"], referer: http://pkf.jo
[Thu Jul 30 14:55:30.676947 2026] [security2:error] [pid 89520:tid 89741] [client 131.222.211.13:44598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusMi0W4wRrtnDoPajqCAAAAd0"], referer: http://pkf.jo
[Thu Jul 30 14:55:30.894279 2026] [security2:error] [pid 89520:tid 89730] [client 20.199.183.73:22498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-content/themes/index.php"] [unique_id "amusMi0W4wRrtnDoPajqEgAAAdI"]
[Thu Jul 30 14:55:31.188327 2026] [security2:error] [pid 87988:tid 88203] [client 20.226.5.174:6795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/providers/yes.php"] [unique_id "amusMzipAwzptuCxBrhL_AAAAV8"]
[Thu Jul 30 14:55:31.224713 2026] [security2:error] [pid 89520:tid 89691] [client 84.44.28.99:19868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusLy0W4wRrtnDoPajp7AAAAas"], referer: http://pkf.jo
[Thu Jul 30 14:55:31.558104 2026] [security2:error] [pid 89520:tid 89708] [client 40.77.167.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amusMy0W4wRrtnDoPajqGAAAAbw"]
[Thu Jul 30 14:55:31.608661 2026] [security2:error] [pid 89520:tid 89677] [client 66.249.73.97:50337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusMi0W4wRrtnDoPajqEwAAAZ0"]
[Thu Jul 30 14:55:32.087597 2026] [security2:error] [pid 87988:tid 88050] [remote 216.73.216.51:24888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amusNDipAwzptuCxBrhMDgABDD0"]
[Thu Jul 30 14:55:32.141251 2026] [security2:error] [pid 87988:tid 88072] [remote 40.77.167.47:43043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/responsif/article/view/9551/4316"] [unique_id "amusNDipAwzptuCxBrhMEAABYFM"]
[Thu Jul 30 14:55:32.189258 2026] [security2:error] [pid 87988:tid 88178] [client 20.226.5.174:6805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/providers/zmFM.php"] [unique_id "amusNDipAwzptuCxBrhMEQAAAUY"]
[Thu Jul 30 14:55:32.494566 2026] [security2:error] [pid 87988:tid 88137] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusMzipAwzptuCxBrhMBwABHUg"]
[Thu Jul 30 14:55:32.796216 2026] [core:notice] [pid 89520:tid 89763] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:33.160859 2026] [security2:error] [pid 89520:tid 89725] [client 20.226.5.174:6806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/ptk.php"] [unique_id "amusNS0W4wRrtnDoPajqMgAAAc0"]
[Thu Jul 30 14:55:34.095398 2026] [security2:error] [pid 87988:tid 88198] [client 20.226.5.174:6834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pu1.php"] [unique_id "amusNjipAwzptuCxBrhMJwAAAVo"]
[Thu Jul 30 14:55:34.929179 2026] [autoindex:error] [pid 89520:tid 89720] [client 94.154.43.185:33906] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_eeee7ca1/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:55:35.006670 2026] [security2:error] [pid 87988:tid 88186] [client 20.226.5.174:6798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/publicadmin.php"] [unique_id "amusNzipAwzptuCxBrhMMQAAAU4"]
[Thu Jul 30 14:55:35.804853 2026] [security2:error] [pid 89520:tid 89543] [remote 97.74.93.24:35984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/wp-login.php"] [unique_id "amusNy0W4wRrtnDoPajqVAAB_g0"]
[Thu Jul 30 14:55:35.812796 2026] [security2:error] [pid 87988:tid 88171] [client 34.81.220.187:37992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/appsettings.Development.json"] [unique_id "amusNzipAwzptuCxBrhMRgAAAT8"]
[Thu Jul 30 14:55:35.839118 2026] [security2:error] [pid 87988:tid 88148] [client 34.81.220.187:37998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.mskabir.com"] [uri "/service-account-key.json"] [unique_id "amusNzipAwzptuCxBrhMSgAAASg"]
[Thu Jul 30 14:55:35.839258 2026] [security2:error] [pid 87988:tid 88148] [client 34.81.220.187:37998] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.mskabir.com"] [uri "/service-account-key.json"] [unique_id "amusNzipAwzptuCxBrhMSgAAASg"]
[Thu Jul 30 14:55:36.006621 2026] [security2:error] [pid 89520:tid 89713] [client 20.226.5.174:6793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/publicalfa.php"] [unique_id "amusOC0W4wRrtnDoPajqWAAAAcE"]
[Thu Jul 30 14:55:36.329177 2026] [security2:error] [pid 87988:tid 88234] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusNzipAwzptuCxBrhMMwABfmA"]
[Thu Jul 30 14:55:36.457329 2026] [proxy:error] [pid 87988:tid 88136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:36.457429 2026] [proxy_http:error] [pid 87988:tid 88136] [client 94.154.43.188:29956] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:36.458594 2026] [proxy:error] [pid 87988:tid 88136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:36.458660 2026] [proxy_http:error] [pid 87988:tid 88136] [client 94.154.43.188:29956] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:36.543376 2026] [proxy:error] [pid 89520:tid 89682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:36.543435 2026] [proxy_http:error] [pid 89520:tid 89682] [client 94.154.43.178:19518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:36.544011 2026] [proxy:error] [pid 89520:tid 89682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:55:36.544055 2026] [proxy_http:error] [pid 89520:tid 89682] [client 94.154.43.178:19518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:55:36.941639 2026] [security2:error] [pid 87988:tid 88142] [client 84.75.220.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "aakmiddleast.com"] [uri "/wp-login.php"] [unique_id "amusNzipAwzptuCxBrhMOwAAASI"]
[Thu Jul 30 14:55:36.993367 2026] [security2:error] [pid 87988:tid 88176] [client 20.226.5.174:6826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/publicbypass.php"] [unique_id "amusODipAwzptuCxBrhMYQAAAUQ"]
[Thu Jul 30 14:55:37.448877 2026] [security2:error] [pid 89520:tid 89693] [client 20.199.183.73:22470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/wp-file.php"] [unique_id "amusOS0W4wRrtnDoPajqYwAAAa0"]
[Thu Jul 30 14:55:37.709776 2026] [security2:error] [pid 89520:tid 89557] [remote 216.73.216.51:23720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amusOS0W4wRrtnDoPajqZQABmRs"]
[Thu Jul 30 14:55:37.735570 2026] [security2:error] [pid 89520:tid 89687] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusOS0W4wRrtnDoPajqYQABpxw"]
[Thu Jul 30 14:55:37.928214 2026] [security2:error] [pid 87988:tid 88139] [client 20.226.5.174:6822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/publick.php"] [unique_id "amusOTipAwzptuCxBrhMdAAAAR8"]
[Thu Jul 30 14:55:38.018641 2026] [security2:error] [pid 89520:tid 89676] [client 103.229.84.35:45804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusOS0W4wRrtnDoPajqZAABnB0"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fgoodporn.click
[Thu Jul 30 14:55:38.501206 2026] [security2:error] [pid 89520:tid 89731] [client 20.199.183.73:32546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-peace.com"] [uri "/sid3.php"] [unique_id "amusOi0W4wRrtnDoPajqawAAAdM"]
[Thu Jul 30 14:55:38.533087 2026] [security2:error] [pid 89520:tid 89560] [remote 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusOS0W4wRrtnDoPajqZwABsh4"]
[Thu Jul 30 14:55:38.544947 2026] [security2:error] [pid 89520:tid 89714] [client 189.156.226.90:27670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusOi0W4wRrtnDoPajqbAAAAcI"]
[Thu Jul 30 14:55:38.545076 2026] [security2:error] [pid 89520:tid 89714] [client 189.156.226.90:27670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusOi0W4wRrtnDoPajqbAAAAcI"]
[Thu Jul 30 14:55:38.862153 2026] [security2:error] [pid 87988:tid 88233] [client 20.226.5.174:6810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/publicwp.php"] [unique_id "amusOjipAwzptuCxBrhMfQAAAX0"]
[Thu Jul 30 14:55:39.865921 2026] [security2:error] [pid 89520:tid 89790] [client 20.226.5.174:6827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/purna.php"] [unique_id "amusOy0W4wRrtnDoPajqdQAAAg4"]
[Thu Jul 30 14:55:40.821439 2026] [security2:error] [pid 87988:tid 88237] [client 20.226.5.174:6821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pv.php"] [unique_id "amusPDipAwzptuCxBrhMnQAAAYE"]
[Thu Jul 30 14:55:41.732527 2026] [security2:error] [pid 89520:tid 89733] [client 20.226.5.174:6791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pwnd-1/admin.php"] [unique_id "amusPS0W4wRrtnDoPajqgAAAAdU"]
[Thu Jul 30 14:55:42.264790 2026] [security2:error] [pid 87988:tid 88163] [client 151.250.73.198:12666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusPTipAwzptuCxBrhMrgAAATc"], referer: http://pkf.jo
[Thu Jul 30 14:55:42.652460 2026] [security2:error] [pid 87988:tid 88180] [client 20.226.5.174:6812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pwnd-1/pwnd.php"] [unique_id "amusPjipAwzptuCxBrhMuQAAAUg"]
[Thu Jul 30 14:55:43.586350 2026] [security2:error] [pid 89520:tid 89684] [client 20.226.5.174:6808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pwnd.php"] [unique_id "amusPy0W4wRrtnDoPajqkwAAAaQ"]
[Thu Jul 30 14:55:43.915530 2026] [security2:error] [pid 89520:tid 89737] [client 43.172.197.101:53344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/24/choli-habille-vos-chaussures-de-jolis-bijoux-concours-inside/"] [unique_id "amusPy0W4wRrtnDoPajqlgAAAdk"]
[Thu Jul 30 14:55:44.504400 2026] [security2:error] [pid 89520:tid 89672] [client 20.226.5.174:6847] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pwnd/1.php"] [unique_id "amusQC0W4wRrtnDoPajqoAAAAZg"]
[Thu Jul 30 14:55:44.504535 2026] [security2:error] [pid 89520:tid 89672] [client 20.226.5.174:6847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pwnd/1.php"] [unique_id "amusQC0W4wRrtnDoPajqoAAAAZg"]
[Thu Jul 30 14:55:44.611508 2026] [core:notice] [pid 89520:tid 89686] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:44.617532 2026] [security2:error] [pid 89520:tid 89686] [client 43.173.174.9:35894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/07/24/choli-habille-vos-chaussures-de-jolis-bijoux-concours-inside/"] [unique_id "amusQC0W4wRrtnDoPajqowAAAaY"], referer: https://carnetdeshopping.com/index.php/2012/07/24/choli-habille-vos-chaussures-de-jolis-bijoux-concours-inside/?replytocom=599
[Thu Jul 30 14:55:44.930238 2026] [security2:error] [pid 87988:tid 88226] [client 109.175.30.38:46642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusQDipAwzptuCxBrhM0QAAAXY"], referer: http://pkf.jo
[Thu Jul 30 14:55:45.424780 2026] [security2:error] [pid 87988:tid 88209] [client 20.226.5.174:6801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pwnd/11.php"] [unique_id "amusQTipAwzptuCxBrhM2wAAAWU"]
[Thu Jul 30 14:55:45.972579 2026] [autoindex:error] [pid 89520:tid 89718] [client 135.136.12.73:43226] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:55:46.348000 2026] [security2:error] [pid 89520:tid 89708] [client 20.226.5.174:6803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pwnd/admin-footer.php"] [unique_id "amusQi0W4wRrtnDoPajqtgAAAbw"]
[Thu Jul 30 14:55:47.097995 2026] [security2:error] [pid 89520:tid 89781] [client 201.168.111.34:35220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusQi0W4wRrtnDoPajqvQAAAgU"], referer: http://pkf.jo
[Thu Jul 30 14:55:47.308399 2026] [security2:error] [pid 89520:tid 89769] [client 20.226.5.174:6785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pwnd/as.php"] [unique_id "amusQy0W4wRrtnDoPajqxQAAAfk"]
[Thu Jul 30 14:55:47.363857 2026] [core:notice] [pid 87988:tid 88205] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:47.388873 2026] [security2:error] [pid 89520:tid 89677] [client 31.3.152.100:50824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.152.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amusQy0W4wRrtnDoPajqxwAAAZ0"]
[Thu Jul 30 14:55:47.388967 2026] [security2:error] [pid 89520:tid 89677] [client 31.3.152.100:50824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amusQy0W4wRrtnDoPajqxwAAAZ0"]
[Thu Jul 30 14:55:47.651276 2026] [core:notice] [pid 87988:tid 88123] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:48.177060 2026] [core:notice] [pid 87988:tid 88172] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:48.213178 2026] [security2:error] [pid 87988:tid 88118] [client 20.226.5.174:6824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/pwnd/pwnd.php"] [unique_id "amusRDipAwzptuCxBrhNAQAAAQo"]
[Thu Jul 30 14:55:49.069521 2026] [security2:error] [pid 87988:tid 88124] [client 189.156.226.90:26830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusRTipAwzptuCxBrhNDwAAARA"]
[Thu Jul 30 14:55:49.069647 2026] [security2:error] [pid 87988:tid 88124] [client 189.156.226.90:26830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusRTipAwzptuCxBrhNDwAAARA"]
[Thu Jul 30 14:55:49.144995 2026] [security2:error] [pid 87988:tid 88157] [client 20.226.5.174:6813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/qfunctions.php"] [unique_id "amusRTipAwzptuCxBrhNEAAAATE"]
[Thu Jul 30 14:55:50.048843 2026] [security2:error] [pid 87988:tid 88226] [client 20.226.5.174:6807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/qinfofuns.php"] [unique_id "amusRjipAwzptuCxBrhNGwAAAXY"]
[Thu Jul 30 14:55:50.414618 2026] [core:notice] [pid 89520:tid 89577] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:50.474180 2026] [core:notice] [pid 89520:tid 89790] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:50.556489 2026] [core:notice] [pid 87988:tid 88047] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:50.894113 2026] [security2:error] [pid 89520:tid 89721] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusRi0W4wRrtnDoPajq4gAAAck"]
[Thu Jul 30 14:55:51.059597 2026] [security2:error] [pid 87988:tid 88137] [client 20.226.5.174:6789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/qwturjyu.php"] [unique_id "amusRzipAwzptuCxBrhNMQAAAR0"]
[Thu Jul 30 14:55:52.032284 2026] [security2:error] [pid 89520:tid 89787] [client 20.226.5.174:6819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/r.php"] [unique_id "amusSC0W4wRrtnDoPajq7wAAAgs"]
[Thu Jul 30 14:55:52.709669 2026] [security2:error] [pid 89520:tid 89760] [client 2a03:2880:f800:11:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusSC0W4wRrtnDoPajq8AAB8DE"]
[Thu Jul 30 14:55:52.816655 2026] [security2:error] [pid 89520:tid 89583] [remote 57.141.0.17:49604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap.xml"] [unique_id "amusSC0W4wRrtnDoPajq_AABkTU"]
[Thu Jul 30 14:55:52.937821 2026] [security2:error] [pid 87988:tid 88200] [client 20.226.5.174:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/r3x.php"] [unique_id "amusSDipAwzptuCxBrhNRgAAAVw"]
[Thu Jul 30 14:55:53.226807 2026] [security2:error] [pid 89520:tid 89584] [remote 57.141.0.37:64370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amusSS0W4wRrtnDoPajrAQAB7jY"]
[Thu Jul 30 14:55:53.919687 2026] [security2:error] [pid 89520:tid 89701] [client 20.226.5.174:6833] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/r57.php"] [unique_id "amusSS0W4wRrtnDoPajrCAAAAbU"]
[Thu Jul 30 14:55:53.931516 2026] [security2:error] [pid 89520:tid 89683] [client 88.168.34.23:42616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusSS0W4wRrtnDoPajrBgAAAaM"], referer: http://pkf.jo
[Thu Jul 30 14:55:54.055274 2026] [security2:error] [pid 87988:tid 88194] [client 88.241.36.71:47742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusSTipAwzptuCxBrhNUgAAAVY"], referer: http://pkf.jo
[Thu Jul 30 14:55:54.079629 2026] [core:notice] [pid 89520:tid 89673] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:54.731730 2026] [core:notice] [pid 87988:tid 88150] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:55:54.887208 2026] [security2:error] [pid 89520:tid 89765] [client 20.226.5.174:6788] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/r57.php"] [unique_id "amusSi0W4wRrtnDoPajrGQAAAfU"]
[Thu Jul 30 14:55:55.840279 2026] [security2:error] [pid 87988:tid 88209] [client 20.226.5.174:6816] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/r57.php"] [unique_id "amusSzipAwzptuCxBrhNagAAAWU"]
[Thu Jul 30 14:55:56.747799 2026] [security2:error] [pid 89520:tid 89754] [client 20.226.5.174:6831] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/r57.php"] [unique_id "amusTC0W4wRrtnDoPajrKAAAAeo"]
[Thu Jul 30 14:55:57.769616 2026] [security2:error] [pid 89520:tid 89666] [client 123.253.51.68:59576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusTS0W4wRrtnDoPajrNAAAAZI"], referer: http://pkf.jo
[Thu Jul 30 14:55:57.857241 2026] [security2:error] [pid 89520:tid 89668] [client 74.7.228.48:53254] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "smo.zzt.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amusTS0W4wRrtnDoPajrOAABlD8"]
[Thu Jul 30 14:55:58.476371 2026] [security2:error] [pid 89520:tid 89670] [client 185.191.171.18:59746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/22/mais-de-um-milhao-de-residencias-ficam-sem-energia-eletrica-na-ucrania-apos-ataques-russos/"] [unique_id "amusTi0W4wRrtnDoPajrQgAAAZY"]
[Thu Jul 30 14:55:58.476492 2026] [security2:error] [pid 89520:tid 89670] [client 185.191.171.18:59746] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/22/mais-de-um-milhao-de-residencias-ficam-sem-energia-eletrica-na-ucrania-apos-ataques-russos/"] [unique_id "amusTi0W4wRrtnDoPajrQgAAAZY"]
[Thu Jul 30 14:55:58.786394 2026] [security2:error] [pid 89520:tid 89730] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusTi0W4wRrtnDoPajrOwAB0kE"]
[Thu Jul 30 14:55:59.724381 2026] [security2:error] [pid 89520:tid 89725] [client 189.156.226.90:27089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusTy0W4wRrtnDoPajrTwAAAc0"]
[Thu Jul 30 14:55:59.724499 2026] [security2:error] [pid 89520:tid 89725] [client 189.156.226.90:27089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusTy0W4wRrtnDoPajrTwAAAc0"]
[Thu Jul 30 14:55:59.920404 2026] [core:notice] [pid 87988:tid 88229] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:00.355073 2026] [security2:error] [pid 87988:tid 88167] [client 102.135.168.149:51802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amusUDipAwzptuCxBrhNnwAAATs"], referer: http://pkf.jo
[Thu Jul 30 14:56:00.718379 2026] [security2:error] [pid 87988:tid 88164] [client 40.77.167.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amusUDipAwzptuCxBrhNoQAAATg"]
[Thu Jul 30 14:56:01.224769 2026] [security2:error] [pid 89520:tid 89608] [remote 178.143.40.183:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.40.143.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altaazi.com"] [uri "/xmlrpc.php"] [unique_id "amusUC0W4wRrtnDoPajrXAAB3E4"]
[Thu Jul 30 14:56:01.225042 2026] [security2:error] [pid 89520:tid 89740] [client 178.143.40.183:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "altaazi.com"] [uri "/xmlrpc.php"] [unique_id "amusUC0W4wRrtnDoPajrXAAB3E4"]
[Thu Jul 30 14:56:01.601279 2026] [core:notice] [pid 89520:tid 89785] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:02.110621 2026] [security2:error] [pid 87988:tid 88234] [client 31.3.152.100:38218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.152.3.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amusUjipAwzptuCxBrhNtwAAAX4"]
[Thu Jul 30 14:56:02.110709 2026] [security2:error] [pid 87988:tid 88234] [client 31.3.152.100:38218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amusUjipAwzptuCxBrhNtwAAAX4"]
[Thu Jul 30 14:56:02.895271 2026] [security2:error] [pid 87988:tid 88112] [remote 216.73.216.51:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amusUjipAwzptuCxBrhNwgABgHs"]
[Thu Jul 30 14:56:03.273048 2026] [core:notice] [pid 87988:tid 88204] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:03.701047 2026] [security2:error] [pid 89520:tid 89736] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusUy0W4wRrtnDoPajrdQAAAdg"]
[Thu Jul 30 14:56:03.883906 2026] [security2:error] [pid 87988:tid 88128] [client 34.81.220.187:39450] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.mskabir.com"] [uri "/cgi-sys/404.html"] [unique_id "amusUzipAwzptuCxBrhN3QAAARQ"]
[Thu Jul 30 14:56:03.912688 2026] [core:notice] [pid 89520:tid 89731] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:04.486586 2026] [security2:error] [pid 87988:tid 88243] [client 178.156.187.238:4244] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amusVDipAwzptuCxBrhN5AAAAYc"], referer: https://globalmarks.pk/
[Thu Jul 30 14:56:04.745694 2026] [security2:error] [pid 89520:tid 89702] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusVC0W4wRrtnDoPajrgAABtlM"]
[Thu Jul 30 14:56:04.876969 2026] [core:notice] [pid 89520:tid 89690] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:05.009494 2026] [core:error] [pid 89520:tid 89733] [client 195.96.139.114:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:56:05.009520 2026] [core:error] [pid 89520:tid 89733] [client 195.96.139.114:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:56:05.459251 2026] [core:error] [pid 87988:tid 88223] [client 66.249.68.164:62853] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:56:05.459283 2026] [core:error] [pid 87988:tid 88223] [client 66.249.68.164:62853] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:56:05.553048 2026] [core:notice] [pid 87988:tid 88010] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:06.371234 2026] [security2:error] [pid 87988:tid 88151] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amusVTipAwzptuCxBrhN6gAAAUI"]
[Thu Jul 30 14:56:06.566951 2026] [core:notice] [pid 87988:tid 88134] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:07.242477 2026] [security2:error] [pid 89520:tid 89773] [client 52.238.199.152:9350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kicksity.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amusVy0W4wRrtnDoPajrnQAAAf0"]
[Thu Jul 30 14:56:07.374513 2026] [security2:error] [pid 87988:tid 88242] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amusVzipAwzptuCxBrhOCwAAAYY"]
[Thu Jul 30 14:56:07.972439 2026] [core:notice] [pid 87988:tid 88026] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:08.019198 2026] [security2:error] [pid 87988:tid 88125] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amusVjipAwzptuCxBrhOCgAAAQ0"]
[Thu Jul 30 14:56:08.203058 2026] [core:notice] [pid 87988:tid 88205] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:08.297862 2026] [core:notice] [pid 87988:tid 88019] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:08.329131 2026] [security2:error] [pid 89520:tid 89716] [client 52.176.39.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.39.176.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amusWC0W4wRrtnDoPajrrgAAAcQ"]
[Thu Jul 30 14:56:08.704460 2026] [security2:error] [pid 89520:tid 89734] [client 198.23.198.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.198.23.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucky-strike-shop.com"] [uri "/phpinfo.php"] [unique_id "amusWC0W4wRrtnDoPajrsQAAAdY"]
[Thu Jul 30 14:56:09.915486 2026] [security2:error] [pid 89520:tid 89625] [remote 52.176.39.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.39.176.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amusWS0W4wRrtnDoPajrvAAB114"]
[Thu Jul 30 14:56:09.939433 2026] [core:notice] [pid 89520:tid 89718] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:10.243074 2026] [security2:error] [pid 89520:tid 89688] [client 189.156.226.90:27579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusWi0W4wRrtnDoPajrwwAAAag"]
[Thu Jul 30 14:56:10.243189 2026] [security2:error] [pid 89520:tid 89688] [client 189.156.226.90:27579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusWi0W4wRrtnDoPajrwwAAAag"]
[Thu Jul 30 14:56:10.335680 2026] [security2:error] [pid 89520:tid 89702] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amusWS0W4wRrtnDoPajrtQAAAdE"]
[Thu Jul 30 14:56:10.734500 2026] [security2:error] [pid 89520:tid 89746] [client 52.167.144.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amusWi0W4wRrtnDoPajrxgAAAeI"]
[Thu Jul 30 14:56:10.889741 2026] [security2:error] [pid 87988:tid 88175] [client 198.23.198.15:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "lucky-strike-shop.com"] [uri "/.env.bak"] [unique_id "amusWjipAwzptuCxBrhORAAAAUM"]
[Thu Jul 30 14:56:11.431685 2026] [security2:error] [pid 87988:tid 88234] [client 198.23.198.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.198.23.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucky-strike-shop.com"] [uri "/info.php"] [unique_id "amusWzipAwzptuCxBrhOSwAAAX4"]
[Thu Jul 30 14:56:11.569248 2026] [core:notice] [pid 89520:tid 89742] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:12.594526 2026] [security2:error] [pid 89520:tid 89719] [client 190.68.30.189:44902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amusXC0W4wRrtnDoPajr0QAAAcc"]
[Thu Jul 30 14:56:13.237607 2026] [core:notice] [pid 89520:tid 89703] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:13.773708 2026] [security2:error] [pid 89520:tid 89619] [remote 57.141.0.3:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/27169508389/feed/rss2/"] [unique_id "amusXS0W4wRrtnDoPajr3QAB21k"]
[Thu Jul 30 14:56:14.081824 2026] [security2:error] [pid 87988:tid 88056] [remote 74.7.243.224:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/Policyf.php"] [unique_id "amusXjipAwzptuCxBrhOdwABCkM"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 14:56:14.368171 2026] [security2:error] [pid 89520:tid 89747] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusXS0W4wRrtnDoPajr3AAAAeM"]
[Thu Jul 30 14:56:14.995298 2026] [security2:error] [pid 87988:tid 88164] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amusXTipAwzptuCxBrhOcAAAAUA"]
[Thu Jul 30 14:56:15.316772 2026] [security2:error] [pid 87988:tid 88232] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusXjipAwzptuCxBrhOgQAAAXw"]
[Thu Jul 30 14:56:16.672636 2026] [security2:error] [pid 89520:tid 89683] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amusXy0W4wRrtnDoPajr-AAAAf0"]
[Thu Jul 30 14:56:18.212832 2026] [core:notice] [pid 89520:tid 89761] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:18.217926 2026] [security2:error] [pid 89520:tid 89761] [client 66.249.79.231:62535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/view/9138/3959"] [unique_id "amusYS0W4wRrtnDoPajsDAAAAfE"]
[Thu Jul 30 14:56:18.469625 2026] [security2:error] [pid 87988:tid 88160] [client 198.23.198.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amusYTipAwzptuCxBrhOnwAAAWA"]
[Thu Jul 30 14:56:20.911889 2026] [security2:error] [pid 89520:tid 89726] [client 189.156.226.90:26638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusZC0W4wRrtnDoPajsIwAAAc4"]
[Thu Jul 30 14:56:20.912021 2026] [security2:error] [pid 89520:tid 89726] [client 189.156.226.90:26638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusZC0W4wRrtnDoPajsIwAAAc4"]
[Thu Jul 30 14:56:23.764236 2026] [security2:error] [pid 89520:tid 89670] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusZy0W4wRrtnDoPajsNQABlmQ"]
[Thu Jul 30 14:56:26.807762 2026] [security2:error] [pid 89520:tid 89718] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusai0W4wRrtnDoPajsTwAAAcY"]
[Thu Jul 30 14:56:30.722381 2026] [security2:error] [pid 89520:tid 89644] [remote 97.74.87.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesounddepot.com"] [uri "/wp-login.php"] [unique_id "amusbi0W4wRrtnDoPajsewABzG8"]
[Thu Jul 30 14:56:31.465700 2026] [security2:error] [pid 89520:tid 89759] [client 189.156.226.90:27024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusby0W4wRrtnDoPajsgwAAAe8"]
[Thu Jul 30 14:56:31.465828 2026] [security2:error] [pid 89520:tid 89759] [client 189.156.226.90:27024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusby0W4wRrtnDoPajsgwAAAe8"]
[Thu Jul 30 14:56:32.156210 2026] [security2:error] [pid 89520:tid 89790] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusby0W4wRrtnDoPajshgACDnI"]
[Thu Jul 30 14:56:32.239035 2026] [core:notice] [pid 87988:tid 88143] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:34.165582 2026] [security2:error] [pid 87988:tid 88044] [remote 57.141.0.65:35654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuscjipAwzptuCxBrhPdQABDDc"]
[Thu Jul 30 14:56:34.749020 2026] [core:notice] [pid 89520:tid 89650] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:35.499311 2026] [core:notice] [pid 87988:tid 88074] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:35.503143 2026] [security2:error] [pid 87988:tid 88142] [client 66.249.65.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/72/75"] [unique_id "amusczipAwzptuCxBrhPhQABIlU"]
[Thu Jul 30 14:56:36.323967 2026] [security2:error] [pid 89520:tid 89783] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuscy0W4wRrtnDoPajspAACB3U"]
[Thu Jul 30 14:56:36.411409 2026] [core:error] [pid 87988:tid 88196] [client 74.7.175.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:56:36.411432 2026] [core:error] [pid 87988:tid 88196] [client 74.7.175.147:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:56:36.411565 2026] [security2:error] [pid 87988:tid 88196] [client 74.7.175.147:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.wyt.gpl.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amusdDipAwzptuCxBrhPmQAAAVg"]
[Thu Jul 30 14:56:36.412205 2026] [security2:error] [pid 89520:tid 89748] [client 74.7.175.147:49328] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.wyt.gpl.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amusdC0W4wRrtnDoPajsqgAB5Hc"]
[Thu Jul 30 14:56:38.551437 2026] [core:notice] [pid 89520:tid 89721] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:38.685275 2026] [core:notice] [pid 89520:tid 89687] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:39.954410 2026] [security2:error] [pid 87988:tid 88121] [client 190.2.142.78:52414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabian-tours.com"] [uri "/wp-login.php"] [unique_id "amusdzipAwzptuCxBrhPyQAAAQ0"]
[Thu Jul 30 14:56:40.170972 2026] [security2:error] [pid 89520:tid 89780] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusdy0W4wRrtnDoPajsyAACBHs"]
[Thu Jul 30 14:56:40.481344 2026] [security2:error] [pid 89520:tid 89789] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusdy0W4wRrtnDoPajsywACDXw"]
[Thu Jul 30 14:56:40.770014 2026] [security2:error] [pid 89520:tid 89720] [client 172.237.109.114:43142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuseC0W4wRrtnDoPajs0gAAAcg"]
[Thu Jul 30 14:56:40.782198 2026] [security2:error] [pid 87988:tid 88195] [client 193.47.62.167:37944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.xyt.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuseDipAwzptuCxBrhP1AAAAVc"]
[Thu Jul 30 14:56:40.901748 2026] [security2:error] [pid 87988:tid 88212] [client 190.231.239.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amusdzipAwzptuCxBrhPygAAAWg"], referer: https://shop-mevius.com/product-tag/mevius%E4%B8%83%E6%98%9F%E8%90%AC%E4%BA%8B%E7%99%BC%E9%A6%99%E7%85%991mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/
[Thu Jul 30 14:56:41.556429 2026] [core:notice] [pid 89520:tid 89774] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:41.658566 2026] [security2:error] [pid 87988:tid 88118] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuseTipAwzptuCxBrhP4QAAAQo"]
[Thu Jul 30 14:56:42.009742 2026] [security2:error] [pid 87988:tid 88227] [client 74.7.244.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.waxandgoldbooks.com"] [uri "/index.php"] [unique_id "amusdzipAwzptuCxBrhPxgAAAXc"]
[Thu Jul 30 14:56:42.010573 2026] [security2:error] [pid 87988:tid 88162] [client 74.7.244.42:56564] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.waxandgoldbooks.com"] [uri "/robots.txt"] [unique_id "amusdzipAwzptuCxBrhPxQABNmw"]
[Thu Jul 30 14:56:42.019481 2026] [core:notice] [pid 89520:tid 89719] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:42.121297 2026] [security2:error] [pid 89520:tid 89786] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuseS0W4wRrtnDoPajs3QACCgA"]
[Thu Jul 30 14:56:42.144620 2026] [security2:error] [pid 89520:tid 89714] [client 189.156.226.90:27256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusei0W4wRrtnDoPajs7gAAAcI"]
[Thu Jul 30 14:56:42.144729 2026] [security2:error] [pid 89520:tid 89714] [client 189.156.226.90:27256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amusei0W4wRrtnDoPajs7gAAAcI"]
[Thu Jul 30 14:56:43.645669 2026] [security2:error] [pid 87988:tid 88175] [client 172.237.109.114:51955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amusezipAwzptuCxBrhP-QAAAUM"]
[Thu Jul 30 14:56:44.817245 2026] [security2:error] [pid 87988:tid 88015] [remote 57.141.0.27:22788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amusfDipAwzptuCxBrhQEgABcho"]
[Thu Jul 30 14:56:44.940403 2026] [security2:error] [pid 89520:tid 89680] [client 185.89.43.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusfC0W4wRrtnDoPajtBwABoA4"]
[Thu Jul 30 14:56:48.091193 2026] [security2:error] [pid 87988:tid 88191] [client 190.2.142.78:55292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/wp-login.php"] [unique_id "amusgDipAwzptuCxBrhQQgAAAVM"]
[Thu Jul 30 14:56:48.129605 2026] [proxy:error] [pid 89520:tid 89550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:56:48.129660 2026] [proxy_http:error] [pid 89520:tid 89550] [remote 74.7.230.29:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:56:48.130227 2026] [proxy:error] [pid 89520:tid 89550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:56:48.130271 2026] [proxy_http:error] [pid 89520:tid 89550] [remote 74.7.230.29:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:56:49.837155 2026] [core:notice] [pid 87988:tid 88140] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:50.868942 2026] [core:notice] [pid 87988:tid 88062] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:56:50.872351 2026] [security2:error] [pid 87988:tid 88144] [client 66.249.65.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/280/280"] [unique_id "amusgjipAwzptuCxBrhQYgABJEk"]
[Thu Jul 30 14:56:51.416314 2026] [security2:error] [pid 89520:tid 89773] [client 190.2.142.78:55320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.142.2.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/wp-login.php"] [unique_id "amusgy0W4wRrtnDoPajtUgAAAf0"]
[Thu Jul 30 14:56:51.655146 2026] [security2:error] [pid 87988:tid 88213] [client 172.237.109.114:17093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amusgzipAwzptuCxBrhQbQAAAWk"]
[Thu Jul 30 14:56:52.025139 2026] [autoindex:error] [pid 87988:tid 88118] [client 190.2.142.78:55332] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:56:52.553320 2026] [security2:error] [pid 89520:tid 89699] [client 189.156.226.90:27476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.226.156.189.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amushC0W4wRrtnDoPajtWAAAAbM"]
[Thu Jul 30 14:56:52.553447 2026] [security2:error] [pid 89520:tid 89699] [client 189.156.226.90:27476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giftedbloomsja.com"] [uri "/xmlrpc.php"] [unique_id "amushC0W4wRrtnDoPajtWAAAAbM"]
[Thu Jul 30 14:56:52.587630 2026] [security2:error] [pid 89520:tid 89715] [client 3.253.88.183:46650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/04/favicon-300x300.jpg"] [unique_id "amushC0W4wRrtnDoPajtWgABwxs"]
[Thu Jul 30 14:56:52.617753 2026] [security2:error] [pid 89520:tid 89559] [remote 57.141.0.32:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap45.xml"] [unique_id "amushC0W4wRrtnDoPajtXAACBh0"]
[Thu Jul 30 14:56:53.104876 2026] [security2:error] [pid 89520:tid 89696] [client 18.203.178.50:22280] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/05/parlx-services-commercial-5.jpg"] [unique_id "amushC0W4wRrtnDoPajtWwABsBw"]
[Thu Jul 30 14:56:53.397847 2026] [security2:error] [pid 87988:tid 88053] [remote 57.141.0.22:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap45.xml"] [unique_id "amushTipAwzptuCxBrhQkQABSkA"]
[Thu Jul 30 14:56:54.678392 2026] [security2:error] [pid 87988:tid 88189] [client 172.237.109.114:15270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amushjipAwzptuCxBrhQmQAAAVE"]
[Thu Jul 30 14:56:55.269703 2026] [security2:error] [pid 87988:tid 88176] [client 223.109.252.145:57978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/"] [unique_id "amushzipAwzptuCxBrhQpwAAAUQ"]
[Thu Jul 30 14:56:55.269831 2026] [security2:error] [pid 87988:tid 88176] [client 223.109.252.145:57978] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "happyspree.app"] [uri "/"] [unique_id "amushzipAwzptuCxBrhQpwAAAUQ"]
[Thu Jul 30 14:56:55.522393 2026] [security2:error] [pid 89520:tid 89666] [client 13.223.3.216:61591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amushy0W4wRrtnDoPajtcQAAAZI"]
[Thu Jul 30 14:56:56.750163 2026] [security2:error] [pid 89520:tid 89564] [remote 116.179.37.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flixon.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amusiC0W4wRrtnDoPajtfwABuSI"], referer: https://flixon.net/video/over-dead-body-vj-emmy/
[Thu Jul 30 14:56:57.586763 2026] [security2:error] [pid 87988:tid 88123] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusiDipAwzptuCxBrhQvAABD2k"]
[Thu Jul 30 14:56:57.645524 2026] [security2:error] [pid 89520:tid 89707] [client 2a03:2880:f800:11:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusiS0W4wRrtnDoPajtggABuyA"]
[Thu Jul 30 14:56:58.594667 2026] [security2:error] [pid 87988:tid 88185] [client 110.249.202.167:59702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amusijipAwzptuCxBrhQ1AAAAU0"]
[Thu Jul 30 14:56:59.422423 2026] [security2:error] [pid 89520:tid 89757] [client 20.171.55.167:4837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/.tmbalfa.php"] [unique_id "amusiy0W4wRrtnDoPajtoQAAAe0"]
[Thu Jul 30 14:57:00.240990 2026] [security2:error] [pid 87988:tid 88226] [client 20.171.55.167:4816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/0x0.php"] [unique_id "amusjDipAwzptuCxBrhQ4AAAAXY"]
[Thu Jul 30 14:57:00.362161 2026] [security2:error] [pid 89520:tid 89743] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusiy0W4wRrtnDoPajtpwAB3yw"]
[Thu Jul 30 14:57:00.459092 2026] [security2:error] [pid 89520:tid 89712] [client 173.249.217.23:48266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.217.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amusjC0W4wRrtnDoPajtqgAAAcA"]
[Thu Jul 30 14:57:00.459204 2026] [security2:error] [pid 89520:tid 89712] [client 173.249.217.23:48266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amusjC0W4wRrtnDoPajtqgAAAcA"]
[Thu Jul 30 14:57:00.715037 2026] [security2:error] [pid 87988:tid 88209] [client 172.237.109.114:35564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amusjDipAwzptuCxBrhQ3gAAAWU"]
[Thu Jul 30 14:57:00.720153 2026] [security2:error] [pid 89520:tid 89760] [client 40.77.167.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amusjC0W4wRrtnDoPajtrwAAAfA"]
[Thu Jul 30 14:57:00.970435 2026] [security2:error] [pid 87988:tid 88236] [client 20.226.5.174:3413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/aman.php"] [unique_id "amusjDipAwzptuCxBrhQ5wAAAYA"]
[Thu Jul 30 14:57:01.011473 2026] [security2:error] [pid 89520:tid 89754] [client 20.171.55.167:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/1aa.php"] [unique_id "amusjS0W4wRrtnDoPajttgAAAeo"]
[Thu Jul 30 14:57:01.724375 2026] [security2:error] [pid 89520:tid 89738] [client 20.171.55.167:4993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/2023/08/admin.php"] [unique_id "amusjS0W4wRrtnDoPajtyAAAAdo"]
[Thu Jul 30 14:57:01.993602 2026] [security2:error] [pid 89520:tid 89748] [client 20.226.5.174:3399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/amaxx.php"] [unique_id "amusjS0W4wRrtnDoPajtyQAAAeQ"]
[Thu Jul 30 14:57:02.442623 2026] [security2:error] [pid 89520:tid 89725] [client 20.171.55.167:4997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/406.php"] [unique_id "amusji0W4wRrtnDoPajtzgAAAc0"]
[Thu Jul 30 14:57:02.940597 2026] [security2:error] [pid 89520:tid 89734] [client 20.226.5.174:3398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/ammika.php"] [unique_id "amusji0W4wRrtnDoPajt1AAAAdY"]
[Thu Jul 30 14:57:03.245716 2026] [security2:error] [pid 89520:tid 89783] [client 20.171.55.167:5052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/73.php"] [unique_id "amusjy0W4wRrtnDoPajt2AAAAgc"]
[Thu Jul 30 14:57:03.905923 2026] [security2:error] [pid 89520:tid 89721] [client 20.226.5.174:3404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/amp.php"] [unique_id "amusjy0W4wRrtnDoPajt2QAAAck"]
[Thu Jul 30 14:57:03.994105 2026] [security2:error] [pid 89520:tid 89765] [client 20.171.55.167:5009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/Alex-Cross.php"] [unique_id "amusjy0W4wRrtnDoPajt2wAAAfU"]
[Thu Jul 30 14:57:04.549506 2026] [core:notice] [pid 89520:tid 89576] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:04.763196 2026] [security2:error] [pid 89520:tid 89712] [client 20.171.55.167:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/Core-Econ/upH.php"] [unique_id "amuskC0W4wRrtnDoPajt4wAAAcA"]
[Thu Jul 30 14:57:04.900849 2026] [security2:error] [pid 89520:tid 89766] [client 20.226.5.174:3397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/amphicyon.php"] [unique_id "amuskC0W4wRrtnDoPajt5gAAAfY"]
[Thu Jul 30 14:57:05.246459 2026] [security2:error] [pid 89520:tid 89578] [remote 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuskC0W4wRrtnDoPajt4QABqzA"]
[Thu Jul 30 14:57:05.500727 2026] [security2:error] [pid 89520:tid 89754] [client 20.171.55.167:4850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/Diff/index.php"] [unique_id "amuskS0W4wRrtnDoPajt7QAAAeo"]
[Thu Jul 30 14:57:05.865952 2026] [security2:error] [pid 89520:tid 89700] [client 20.226.5.174:3396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/anjay.php"] [unique_id "amuskS0W4wRrtnDoPajt8QAAAbQ"]
[Thu Jul 30 14:57:06.235168 2026] [security2:error] [pid 89520:tid 89706] [client 20.171.55.167:4820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/ID3/rk2.php"] [unique_id "amuski0W4wRrtnDoPajt-AAAAbo"]
[Thu Jul 30 14:57:06.813155 2026] [security2:error] [pid 89520:tid 89678] [client 20.226.5.174:3401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/anon.php"] [unique_id "amuski0W4wRrtnDoPajt-gAAAZ4"]
[Thu Jul 30 14:57:06.988558 2026] [security2:error] [pid 87988:tid 88140] [client 20.171.55.167:4833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/OK.php"] [unique_id "amuskjipAwzptuCxBrhRMwAAASA"]
[Thu Jul 30 14:57:07.747910 2026] [security2:error] [pid 87988:tid 88146] [client 20.226.5.174:3419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/anone.php"] [unique_id "amuskzipAwzptuCxBrhRPQAAASY"]
[Thu Jul 30 14:57:07.778995 2026] [security2:error] [pid 89520:tid 89719] [client 20.171.55.167:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/RxR_uvhya.php"] [unique_id "amusky0W4wRrtnDoPajuAwAAAcc"]
[Thu Jul 30 14:57:08.087004 2026] [security2:error] [pid 87988:tid 88237] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuskzipAwzptuCxBrhROAABgSM"]
[Thu Jul 30 14:57:08.521470 2026] [security2:error] [pid 89520:tid 89783] [client 20.171.55.167:5000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/V2.php"] [unique_id "amuslC0W4wRrtnDoPajuDAAAAgc"]
[Thu Jul 30 14:57:08.567386 2026] [core:notice] [pid 89520:tid 89708] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:08.569956 2026] [core:notice] [pid 87988:tid 88153] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:08.580821 2026] [core:notice] [pid 89520:tid 89724] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:08.666880 2026] [security2:error] [pid 89520:tid 89676] [client 169.224.121.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusky0W4wRrtnDoPajuBAABnDc"], referer: https://allmontecristi.com
[Thu Jul 30 14:57:08.699359 2026] [core:notice] [pid 87988:tid 88233] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:08.701351 2026] [security2:error] [pid 89520:tid 89711] [client 20.226.5.174:3418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/anons79.php"] [unique_id "amuslC0W4wRrtnDoPajuEwAAAb8"]
[Thu Jul 30 14:57:08.712721 2026] [core:notice] [pid 89520:tid 89688] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:08.963130 2026] [core:notice] [pid 89520:tid 89743] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:08.964694 2026] [core:notice] [pid 87988:tid 88157] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:08.971573 2026] [core:notice] [pid 89520:tid 89701] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:09.080621 2026] [core:notice] [pid 89520:tid 89753] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:09.088589 2026] [core:notice] [pid 87988:tid 88188] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:09.252047 2026] [security2:error] [pid 87988:tid 88184] [client 20.171.55.167:5012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/aa.php"] [unique_id "amuslTipAwzptuCxBrhRWAAAAUw"]
[Thu Jul 30 14:57:09.432874 2026] [core:notice] [pid 87988:tid 88141] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:09.434637 2026] [security2:error] [pid 87988:tid 88141] [client 103.131.71.137:19227] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "nordeste1.com"] [uri "/robots.txt"] [unique_id "amuslTipAwzptuCxBrhRWwAAASE"]
[Thu Jul 30 14:57:09.604344 2026] [security2:error] [pid 89520:tid 89772] [client 20.226.5.174:3406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/anonsec.php"] [unique_id "amuslS0W4wRrtnDoPajuHgAAAfw"]
[Thu Jul 30 14:57:10.003659 2026] [security2:error] [pid 89520:tid 89691] [client 20.171.55.167:4827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/acme-challengek.php"] [unique_id "amusli0W4wRrtnDoPajuIgAAAas"]
[Thu Jul 30 14:57:10.065105 2026] [core:notice] [pid 87988:tid 88076] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:10.526269 2026] [security2:error] [pid 87988:tid 88245] [client 20.226.5.174:3137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/ans.php"] [unique_id "amusljipAwzptuCxBrhRcAAAAYk"]
[Thu Jul 30 14:57:10.747839 2026] [security2:error] [pid 87988:tid 88134] [client 20.171.55.167:5037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/admin403.php"] [unique_id "amusljipAwzptuCxBrhRdgAAARo"]
[Thu Jul 30 14:57:11.470721 2026] [security2:error] [pid 89520:tid 89736] [client 20.226.5.174:3146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/ant.php"] [unique_id "amusly0W4wRrtnDoPajuKwAAAdg"]
[Thu Jul 30 14:57:11.554478 2026] [security2:error] [pid 89520:tid 89683] [client 20.171.55.167:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/adminwp.php"] [unique_id "amusly0W4wRrtnDoPajuLwAAAaM"]
[Thu Jul 30 14:57:11.584163 2026] [security2:error] [pid 89520:tid 89685] [client 172.237.109.114:16081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amusly0W4wRrtnDoPajuKAAAAaU"]
[Thu Jul 30 14:57:11.598767 2026] [core:notice] [pid 89520:tid 89714] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:11.600634 2026] [security2:error] [pid 89520:tid 89714] [client 103.131.71.137:32801] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amusly0W4wRrtnDoPajuMAAAAcI"]
[Thu Jul 30 14:57:12.363926 2026] [security2:error] [pid 89520:tid 89670] [client 20.171.55.167:5046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/alexuse.php"] [unique_id "amusmC0W4wRrtnDoPajuNwAAAZY"]
[Thu Jul 30 14:57:12.385550 2026] [security2:error] [pid 87988:tid 88219] [client 20.226.5.174:3139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/antek.php"] [unique_id "amusmDipAwzptuCxBrhRhwAAAW8"]
[Thu Jul 30 14:57:13.106768 2026] [security2:error] [pid 87988:tid 88130] [client 20.171.55.167:4860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/alfacgiapiwp.php"] [unique_id "amusmTipAwzptuCxBrhRkQAAARY"]
[Thu Jul 30 14:57:13.373936 2026] [security2:error] [pid 87988:tid 88241] [client 20.226.5.174:3145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/antiheker.php"] [unique_id "amusmTipAwzptuCxBrhRlwAAAYU"]
[Thu Jul 30 14:57:13.936776 2026] [security2:error] [pid 89520:tid 89718] [client 20.171.55.167:4826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/am.php"] [unique_id "amusmS0W4wRrtnDoPajuRgAAAcY"]
[Thu Jul 30 14:57:14.426125 2026] [security2:error] [pid 89520:tid 89741] [client 20.226.5.174:3149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/ap.php"] [unique_id "amusmi0W4wRrtnDoPajuTQAAAd0"]
[Thu Jul 30 14:57:14.671994 2026] [security2:error] [pid 89520:tid 89754] [client 20.171.55.167:5043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/apikey/natural.php"] [unique_id "amusmi0W4wRrtnDoPajuTgAAAeo"]
[Thu Jul 30 14:57:15.431725 2026] [security2:error] [pid 89520:tid 89758] [client 20.226.5.174:3153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/api.php"] [unique_id "amusmy0W4wRrtnDoPajuUwAAAe4"]
[Thu Jul 30 14:57:15.511001 2026] [security2:error] [pid 87988:tid 88171] [client 20.171.55.167:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/article.php"] [unique_id "amusmzipAwzptuCxBrhRsAAAAT8"]
[Thu Jul 30 14:57:16.311601 2026] [security2:error] [pid 89520:tid 89732] [client 167.88.167.87:57690] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "svcambodia.com"] [uri "/"] [unique_id "amusnC0W4wRrtnDoPajuXwAAAdQ"]
[Thu Jul 30 14:57:16.327612 2026] [security2:error] [pid 87988:tid 88210] [client 20.171.55.167:4828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/assetsadmin.php"] [unique_id "amusnDipAwzptuCxBrhRuAAAAWY"]
[Thu Jul 30 14:57:16.413364 2026] [security2:error] [pid 89520:tid 89707] [client 20.226.5.174:3150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/api_download.php"] [unique_id "amusnC0W4wRrtnDoPajuYAAAAbs"]
[Thu Jul 30 14:57:16.582874 2026] [fcgid:warn] [pid 89520:tid 89681] (70014)End of file found: [client 66.132.186.183:30018] mod_fcgid: can't get data from http client
[Thu Jul 30 14:57:16.723097 2026] [core:notice] [pid 89520:tid 89762] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:16.726481 2026] [security2:error] [pid 89520:tid 89762] [client 66.249.79.231:44008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/5326"] [unique_id "amusnC0W4wRrtnDoPajuZQAAAfI"]
[Thu Jul 30 14:57:17.056108 2026] [security2:error] [pid 89520:tid 89767] [client 104.28.214.113:48880] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bonafideadvisors.com"] [uri "/000.php"] [unique_id "amusnS0W4wRrtnDoPajubAAAAfc"]
[Thu Jul 30 14:57:17.117027 2026] [security2:error] [pid 89520:tid 89761] [client 20.171.55.167:5011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/ava.php"] [unique_id "amusnS0W4wRrtnDoPajubwAAAfE"]
[Thu Jul 30 14:57:17.370263 2026] [security2:error] [pid 89520:tid 89790] [client 20.226.5.174:3151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/apikey/mar.php"] [unique_id "amusnS0W4wRrtnDoPajucgAAAg4"]
[Thu Jul 30 14:57:17.907812 2026] [security2:error] [pid 89520:tid 89688] [client 20.171.55.167:4832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/backup.php"] [unique_id "amusnS0W4wRrtnDoPajudwAAAag"]
[Thu Jul 30 14:57:18.328997 2026] [security2:error] [pid 87988:tid 88128] [client 20.226.5.174:3160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/apikey/natural.php"] [unique_id "amusnjipAwzptuCxBrhR0gAAARQ"]
[Thu Jul 30 14:57:18.658662 2026] [security2:error] [pid 89520:tid 89746] [client 20.171.55.167:5008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/binalfa.php"] [unique_id "amusni0W4wRrtnDoPajufwAAAeI"]
[Thu Jul 30 14:57:19.201582 2026] [security2:error] [pid 89520:tid 89756] [client 74.7.175.136:34956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.xff.nyx.temporary.site"] [uri "/index.php"] [unique_id "amusnS0W4wRrtnDoPajudgAB7D4"]
[Thu Jul 30 14:57:19.242106 2026] [security2:error] [pid 89520:tid 89789] [client 20.226.5.174:3158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/apismtp/apismtp.php"] [unique_id "amusny0W4wRrtnDoPajuhgAAAg0"]
[Thu Jul 30 14:57:19.440813 2026] [security2:error] [pid 87988:tid 88229] [client 20.171.55.167:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/blogai/issue.php"] [unique_id "amusnzipAwzptuCxBrhR5AAAAXk"]
[Thu Jul 30 14:57:19.718630 2026] [security2:error] [pid 89520:tid 89773] [client 51.68.236.93:24357] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amusny0W4wRrtnDoPajuigAAAf0"]
[Thu Jul 30 14:57:19.718734 2026] [security2:error] [pid 89520:tid 89773] [client 51.68.236.93:24357] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amusny0W4wRrtnDoPajuigAAAf0"]
[Thu Jul 30 14:57:20.208404 2026] [security2:error] [pid 89520:tid 89683] [client 20.226.5.174:3156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/app.php"] [unique_id "amusoC0W4wRrtnDoPajujAAAAaM"]
[Thu Jul 30 14:57:20.260409 2026] [security2:error] [pid 89520:tid 89697] [client 20.171.55.167:5053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/browse.php"] [unique_id "amusoC0W4wRrtnDoPajujQAAAbE"]
[Thu Jul 30 14:57:20.711920 2026] [security2:error] [pid 89520:tid 89725] [client 74.7.241.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "guardian-heir.com"] [uri "/index.php"] [unique_id "amusnC0W4wRrtnDoPajuagABzT0"], referer: https://www.guardian-heir.com/robots.txt
[Thu Jul 30 14:57:21.004798 2026] [security2:error] [pid 89520:tid 89667] [client 20.171.55.167:5030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/c451f.php"] [unique_id "amusoS0W4wRrtnDoPajulAAAAZM"]
[Thu Jul 30 14:57:21.141198 2026] [security2:error] [pid 89520:tid 89715] [client 20.226.5.174:3144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/app_dev.php"] [unique_id "amusoS0W4wRrtnDoPajulwAAAcM"]
[Thu Jul 30 14:57:21.796424 2026] [security2:error] [pid 87988:tid 88171] [client 20.171.55.167:4859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/catalogbypass.php"] [unique_id "amusoTipAwzptuCxBrhR_wAAAT8"]
[Thu Jul 30 14:57:21.872112 2026] [security2:error] [pid 89520:tid 89598] [remote 110.249.202.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "heatstickhk.com"] [uri "/robots.txt"] [unique_id "amusoS0W4wRrtnDoPajuqQAB9UQ"]
[Thu Jul 30 14:57:22.087166 2026] [security2:error] [pid 89520:tid 89776] [client 20.226.5.174:3148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/appadmin.php"] [unique_id "amusoi0W4wRrtnDoPajurQAAAgA"]
[Thu Jul 30 14:57:22.550545 2026] [security2:error] [pid 89520:tid 89787] [client 20.171.55.167:4810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/cf.php"] [unique_id "amusoi0W4wRrtnDoPajurwAAAgs"]
[Thu Jul 30 14:57:22.712547 2026] [security2:error] [pid 89520:tid 89698] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusoi0W4wRrtnDoPajurAABskk"]
[Thu Jul 30 14:57:23.013071 2026] [security2:error] [pid 87988:tid 88136] [client 20.226.5.174:3159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/appalfa.php"] [unique_id "amusozipAwzptuCxBrhSDgAAARw"]
[Thu Jul 30 14:57:23.097118 2026] [security2:error] [pid 89520:tid 89595] [remote 97.74.93.24:54302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amusoy0W4wRrtnDoPajutAAB5UE"]
[Thu Jul 30 14:57:23.126078 2026] [core:notice] [pid 89520:tid 89709] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:23.288395 2026] [security2:error] [pid 89520:tid 89673] [client 20.171.55.167:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/cjfuns.php"] [unique_id "amusoy0W4wRrtnDoPajuvAAAAZk"]
[Thu Jul 30 14:57:23.590587 2026] [core:notice] [pid 89520:tid 89744] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:23.979126 2026] [security2:error] [pid 89520:tid 89664] [client 20.226.5.174:3395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/appbypass.php"] [unique_id "amusoy0W4wRrtnDoPajuxAAAAZA"]
[Thu Jul 30 14:57:24.063502 2026] [security2:error] [pid 89520:tid 89782] [client 20.171.55.167:4854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/class-wp-block-type.php"] [unique_id "amuspC0W4wRrtnDoPajuxQAAAgY"]
[Thu Jul 30 14:57:24.684633 2026] [autoindex:error] [pid 89520:tid 89770] [client 167.172.47.19:55870] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:57:24.888700 2026] [security2:error] [pid 89520:tid 89717] [client 20.171.55.167:4803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/class-wp-lock.php"] [unique_id "amuspC0W4wRrtnDoPaju0QAAAcU"]
[Thu Jul 30 14:57:24.888792 2026] [security2:error] [pid 89520:tid 89722] [client 20.226.5.174:3172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/appk.php"] [unique_id "amuspC0W4wRrtnDoPaju0AAAAco"]
[Thu Jul 30 14:57:25.076159 2026] [security2:error] [pid 89520:tid 89752] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuspC0W4wRrtnDoPajuygAB6Eo"]
[Thu Jul 30 14:57:25.450466 2026] [autoindex:error] [pid 89520:tid 89726] [client 167.172.47.19:43626] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:57:25.634561 2026] [security2:error] [pid 89520:tid 89718] [client 20.171.55.167:4857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/class-wp-widget-tag.php"] [unique_id "amuspS0W4wRrtnDoPaju3QAAAcY"]
[Thu Jul 30 14:57:25.750257 2026] [security2:error] [pid 87988:tid 88012] [remote 57.141.0.46:48894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuspTipAwzptuCxBrhSKwABhRc"]
[Thu Jul 30 14:57:25.779505 2026] [security2:error] [pid 87988:tid 88237] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuspTipAwzptuCxBrhSIgAAAYE"]
[Thu Jul 30 14:57:25.889247 2026] [security2:error] [pid 87988:tid 88233] [client 20.226.5.174:3155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/applicationadmin.php"] [unique_id "amuspTipAwzptuCxBrhSLwAAAX0"]
[Thu Jul 30 14:57:26.367523 2026] [security2:error] [pid 89520:tid 89754] [client 20.171.55.167:5021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/cocot.php"] [unique_id "amuspi0W4wRrtnDoPaju5QAAAeo"]
[Thu Jul 30 14:57:26.908834 2026] [security2:error] [pid 87988:tid 88231] [client 20.226.5.174:3405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/applicationalfa.php"] [unique_id "amuspjipAwzptuCxBrhSOwAAAXs"]
[Thu Jul 30 14:57:27.142121 2026] [security2:error] [pid 89520:tid 89773] [client 20.171.55.167:4847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/colors/blue/ahax.php"] [unique_id "amuspy0W4wRrtnDoPaju6gAAAf0"]
[Thu Jul 30 14:57:27.533425 2026] [security2:error] [pid 87988:tid 88150] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuspjipAwzptuCxBrhSPAABKiQ"]
[Thu Jul 30 14:57:27.637224 2026] [security2:error] [pid 89520:tid 89700] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuspy0W4wRrtnDoPaju6QABtE4"]
[Thu Jul 30 14:57:27.840407 2026] [security2:error] [pid 89520:tid 89664] [client 20.226.5.174:3393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/applicationbypass.php"] [unique_id "amuspy0W4wRrtnDoPaju7wAAAZA"]
[Thu Jul 30 14:57:27.884972 2026] [security2:error] [pid 89520:tid 89681] [client 20.171.55.167:4851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/colors/blue/wp-trackback.php"] [unique_id "amuspy0W4wRrtnDoPaju8AAAAaE"]
[Thu Jul 30 14:57:28.185628 2026] [core:notice] [pid 87988:tid 88035] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:28.737646 2026] [security2:error] [pid 89520:tid 89687] [client 20.171.55.167:4861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/colors/coffee/mailer.php"] [unique_id "amusqC0W4wRrtnDoPaju-gAAAac"]
[Thu Jul 30 14:57:28.811739 2026] [security2:error] [pid 89520:tid 89757] [client 20.226.5.174:3157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/applicationd.php"] [unique_id "amusqC0W4wRrtnDoPaju-wAAAe0"]
[Thu Jul 30 14:57:29.722640 2026] [security2:error] [pid 89520:tid 89765] [client 20.171.55.167:5006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/colors/ectoplasm/wp-login.php"] [unique_id "amusqS0W4wRrtnDoPajvAwAAAfU"]
[Thu Jul 30 14:57:29.762006 2026] [security2:error] [pid 87988:tid 88205] [client 20.226.5.174:3162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/applicationk.php"] [unique_id "amusqTipAwzptuCxBrhSawAAAWE"]
[Thu Jul 30 14:57:29.915605 2026] [security2:error] [pid 89520:tid 89708] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusqS0W4wRrtnDoPajvAQABvFE"]
[Thu Jul 30 14:57:30.261622 2026] [core:notice] [pid 87988:tid 88130] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:30.290392 2026] [security2:error] [pid 89520:tid 89726] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusqS0W4wRrtnDoPajvCAAAAc4"]
[Thu Jul 30 14:57:30.486526 2026] [security2:error] [pid 87988:tid 88157] [client 20.171.55.167:4846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/colors/modern/3eTB38lCsA.php"] [unique_id "amusqjipAwzptuCxBrhSdwAAATE"]
[Thu Jul 30 14:57:30.701783 2026] [security2:error] [pid 89520:tid 89769] [client 20.226.5.174:3402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/applicationwp.php"] [unique_id "amusqi0W4wRrtnDoPajvDQAAAfk"]
[Thu Jul 30 14:57:30.825458 2026] [core:notice] [pid 87988:tid 88188] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:31.199939 2026] [security2:error] [pid 87988:tid 88152] [client 20.171.55.167:4999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/colour.php"] [unique_id "amusqzipAwzptuCxBrhSgAAAASw"]
[Thu Jul 30 14:57:31.948678 2026] [security2:error] [pid 87988:tid 88135] [client 20.171.55.167:4829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/con7ext.php"] [unique_id "amusqzipAwzptuCxBrhSjQAAARs"]
[Thu Jul 30 14:57:32.708930 2026] [core:notice] [pid 89520:tid 89710] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:32.717729 2026] [security2:error] [pid 89520:tid 89699] [client 20.171.55.167:4830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/contentbypass.php"] [unique_id "amusrC0W4wRrtnDoPajvIgAAAbM"]
[Thu Jul 30 14:57:33.457826 2026] [security2:error] [pid 87988:tid 88183] [client 20.171.55.167:5007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/credits.php"] [unique_id "amusrTipAwzptuCxBrhSqQAAAUs"]
[Thu Jul 30 14:57:33.757618 2026] [security2:error] [pid 87988:tid 88080] [remote 40.77.167.47:42018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/1247/index_php/Grageman"] [unique_id "amusrTipAwzptuCxBrhSsAABF1s"]
[Thu Jul 30 14:57:34.212377 2026] [security2:error] [pid 89520:tid 89760] [client 20.171.55.167:4908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/cybershell.php"] [unique_id "amusri0W4wRrtnDoPajvMgAAAfA"]
[Thu Jul 30 14:57:34.221964 2026] [core:notice] [pid 87988:tid 88157] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:34.437401 2026] [security2:error] [pid 87988:tid 88169] [client 216.73.216.53:32134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jesus.claims"] [uri "/index.php"] [unique_id "amusrTipAwzptuCxBrhSoAABPUY"]
[Thu Jul 30 14:57:34.466331 2026] [core:notice] [pid 89520:tid 89729] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:34.672721 2026] [security2:error] [pid 89520:tid 89753] [client 50.6.43.217:12054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amusri0W4wRrtnDoPajvOAAAAek"]
[Thu Jul 30 14:57:34.795696 2026] [security2:error] [pid 89520:tid 89689] [client 50.6.43.217:12070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amusri0W4wRrtnDoPajvPgAAAak"]
[Thu Jul 30 14:57:34.951793 2026] [security2:error] [pid 87988:tid 88233] [client 20.171.55.167:4866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/db.php"] [unique_id "amusrjipAwzptuCxBrhSwQAAAX0"]
[Thu Jul 30 14:57:35.679953 2026] [security2:error] [pid 87988:tid 88191] [client 20.171.55.167:4897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/degeselih.php"] [unique_id "amusrzipAwzptuCxBrhSzwAAAVM"]
[Thu Jul 30 14:57:36.436459 2026] [security2:error] [pid 89520:tid 89710] [client 20.171.55.167:4924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/disagraeosc.php"] [unique_id "amussC0W4wRrtnDoPajvTgAAAb4"]
[Thu Jul 30 14:57:37.181245 2026] [security2:error] [pid 87988:tid 88189] [client 20.171.55.167:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/distk.php"] [unique_id "amussTipAwzptuCxBrhS5wAAAVE"]
[Thu Jul 30 14:57:37.948228 2026] [core:error] [pid 89520:tid 89770] [client 199.45.154.155:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:57:37.948260 2026] [core:error] [pid 89520:tid 89770] [client 199.45.154.155:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:57:37.949968 2026] [security2:error] [pid 89520:tid 89696] [client 20.171.55.167:4916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/doiconvs.php"] [unique_id "amussS0W4wRrtnDoPajvVwAAAbA"]
[Thu Jul 30 14:57:38.735457 2026] [security2:error] [pid 89520:tid 89727] [client 20.171.55.167:4901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/e-preview.php"] [unique_id "amussi0W4wRrtnDoPajvYAAAAc8"]
[Thu Jul 30 14:57:38.771122 2026] [security2:error] [pid 89520:tid 89620] [remote 57.141.0.27:26864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amussi0W4wRrtnDoPajvYgACBVo"]
[Thu Jul 30 14:57:38.858721 2026] [security2:error] [pid 87988:tid 88104] [remote 57.141.0.69:22570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amussjipAwzptuCxBrhTAgABYnM"]
[Thu Jul 30 14:57:39.469449 2026] [security2:error] [pid 89520:tid 89718] [client 20.171.55.167:4904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/elements/filemanager.php"] [unique_id "amussy0W4wRrtnDoPajvawAAAcY"]
[Thu Jul 30 14:57:39.733056 2026] [security2:error] [pid 89520:tid 89708] [client 172.237.109.114:17893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amussy0W4wRrtnDoPajvaQAAAbw"]
[Thu Jul 30 14:57:40.258005 2026] [security2:error] [pid 87988:tid 88155] [client 20.171.55.167:4865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/ertg.php"] [unique_id "amustDipAwzptuCxBrhTFQAAAS8"]
[Thu Jul 30 14:57:40.559182 2026] [core:notice] [pid 89520:tid 89625] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:41.000688 2026] [security2:error] [pid 87988:tid 88162] [client 20.171.55.167:4894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/f2.php"] [unique_id "amustDipAwzptuCxBrhTIwAAATY"]
[Thu Jul 30 14:57:41.744773 2026] [security2:error] [pid 89520:tid 89726] [client 20.171.55.167:4896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/fierza.php"] [unique_id "amustS0W4wRrtnDoPajvegAAAc4"]
[Thu Jul 30 14:57:42.497421 2026] [security2:error] [pid 89520:tid 89725] [client 20.171.55.167:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/file_uploadsbypass.php"] [unique_id "amusti0W4wRrtnDoPajvfgAAAc0"]
[Thu Jul 30 14:57:42.667755 2026] [core:notice] [pid 89520:tid 89619] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:42.896789 2026] [core:notice] [pid 89520:tid 89627] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:43.189071 2026] [core:notice] [pid 89520:tid 89626] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:43.268096 2026] [security2:error] [pid 89520:tid 89699] [client 20.171.55.167:4909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/files.php"] [unique_id "amusty0W4wRrtnDoPajvhwAAAbM"]
[Thu Jul 30 14:57:44.054711 2026] [security2:error] [pid 87988:tid 88236] [client 20.171.55.167:4830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/fonts/iqb.php"] [unique_id "amusuDipAwzptuCxBrhTUQAAAYA"]
[Thu Jul 30 14:57:44.809900 2026] [security2:error] [pid 87988:tid 88138] [client 20.171.55.167:4888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/g.php"] [unique_id "amusuDipAwzptuCxBrhTWwAAAR4"]
[Thu Jul 30 14:57:45.586068 2026] [security2:error] [pid 89520:tid 89760] [client 20.171.55.167:4872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/gfile.php"] [unique_id "amusuS0W4wRrtnDoPajvpAAAAfA"]
[Thu Jul 30 14:57:45.750369 2026] [core:notice] [pid 89520:tid 89629] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:46.322037 2026] [security2:error] [pid 87988:tid 88134] [client 20.171.55.167:4913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/google-seo-rank/module.php"] [unique_id "amusujipAwzptuCxBrhTcQAAARo"]
[Thu Jul 30 14:57:47.075253 2026] [security2:error] [pid 87988:tid 88198] [client 20.171.55.167:4878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/hehe.php"] [unique_id "amusuzipAwzptuCxBrhTfgAAAVo"]
[Thu Jul 30 14:57:47.151141 2026] [security2:error] [pid 89520:tid 89729] [client 83.225.54.26:54534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.54.225.83.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aetiiph.net"] [uri "/xmlrpc.php"] [unique_id "amusui0W4wRrtnDoPajvtgAAAdE"]
[Thu Jul 30 14:57:47.151333 2026] [security2:error] [pid 89520:tid 89729] [client 83.225.54.26:54534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aetiiph.net"] [uri "/xmlrpc.php"] [unique_id "amusui0W4wRrtnDoPajvtgAAAdE"]
[Thu Jul 30 14:57:47.827265 2026] [security2:error] [pid 87988:tid 88205] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aqcent.global"] [uri "/.well-known/about.php"] [unique_id "amusuzipAwzptuCxBrhTiAAAAWE"]
[Thu Jul 30 14:57:47.827356 2026] [security2:error] [pid 87988:tid 88205] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "aqcent.global"] [uri "/.well-known/about.php"] [unique_id "amusuzipAwzptuCxBrhTiAAAAWE"]
[Thu Jul 30 14:57:47.836804 2026] [security2:error] [pid 87988:tid 88160] [client 20.171.55.167:5027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/hoot.php"] [unique_id "amusuzipAwzptuCxBrhTiQAAATQ"]
[Thu Jul 30 14:57:48.597870 2026] [security2:error] [pid 89520:tid 89696] [client 20.171.55.167:4891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/id.php"] [unique_id "amusvC0W4wRrtnDoPajvywAAAbA"]
[Thu Jul 30 14:57:48.659842 2026] [security2:error] [pid 87988:tid 88019] [remote 47.128.121.71:11186] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "radiojelli.com"] [uri "/robots.txt"] [unique_id "amusvDipAwzptuCxBrhTkQABZB4"]
[Thu Jul 30 14:57:49.318689 2026] [security2:error] [pid 89520:tid 89727] [client 20.171.55.167:4870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/impressum.php"] [unique_id "amusvS0W4wRrtnDoPajv0QAAAc8"]
[Thu Jul 30 14:57:49.469092 2026] [core:notice] [pid 89520:tid 89632] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:49.835386 2026] [core:error] [pid 87988:tid 88038] [remote 54.211.108.114:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:57:49.835411 2026] [core:error] [pid 87988:tid 88038] [remote 54.211.108.114:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:57:50.057010 2026] [security2:error] [pid 89520:tid 89765] [client 20.171.55.167:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/index404.php"] [unique_id "amusvi0W4wRrtnDoPajv1QAAAfU"]
[Thu Jul 30 14:57:50.800901 2026] [security2:error] [pid 87988:tid 88226] [client 20.171.55.167:4900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/ioxi-o.php"] [unique_id "amusvjipAwzptuCxBrhTrwAAAXY"]
[Thu Jul 30 14:57:51.509095 2026] [security2:error] [pid 87988:tid 88173] [client 20.171.55.167:4879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/jlc14ng3.php"] [unique_id "amusvzipAwzptuCxBrhTwAAAAUE"]
[Thu Jul 30 14:57:52.264749 2026] [security2:error] [pid 89520:tid 89737] [client 20.171.55.167:4925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/js.php"] [unique_id "amuswC0W4wRrtnDoPajv4wAAAdk"]
[Thu Jul 30 14:57:52.273060 2026] [core:error] [pid 89520:tid 89778] [client 87.236.176.52:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:57:52.273076 2026] [core:error] [pid 89520:tid 89778] [client 87.236.176.52:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:57:53.002764 2026] [security2:error] [pid 87988:tid 88221] [client 20.171.55.167:4889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/l.php"] [unique_id "amuswTipAwzptuCxBrhT1gAAAXE"]
[Thu Jul 30 14:57:53.166493 2026] [core:notice] [pid 87988:tid 88044] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:53.296691 2026] [security2:error] [pid 87988:tid 88196] [client 18.133.139.103:18542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/04/favicon-300x300.jpg"] [unique_id "amuswTipAwzptuCxBrhT2wABWFs"]
[Thu Jul 30 14:57:53.633624 2026] [security2:error] [pid 87988:tid 88147] [client 35.176.86.118:29284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/05/parlx-services-commercial-5.jpg"] [unique_id "amuswTipAwzptuCxBrhT2gABJzk"]
[Thu Jul 30 14:57:53.732563 2026] [security2:error] [pid 89520:tid 89744] [client 20.171.55.167:4899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/library/about.php"] [unique_id "amuswS0W4wRrtnDoPajv7wAAAeA"]
[Thu Jul 30 14:57:54.496140 2026] [security2:error] [pid 87988:tid 88127] [client 20.171.55.167:4815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/linkpreviewk.php"] [unique_id "amuswjipAwzptuCxBrhT_AAAARM"]
[Thu Jul 30 14:57:54.616071 2026] [security2:error] [pid 89520:tid 89782] [client 157.55.39.204:59493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hmhs.ph"] [uri "/index.php"] [unique_id "amuswS0W4wRrtnDoPajv8AACBms"]
[Thu Jul 30 14:57:55.226836 2026] [security2:error] [pid 87988:tid 88176] [client 20.171.55.167:4875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/log.php"] [unique_id "amuswzipAwzptuCxBrhUCwAAAUQ"]
[Thu Jul 30 14:57:55.967459 2026] [security2:error] [pid 89520:tid 89773] [client 20.171.55.167:4812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/mail.php"] [unique_id "amuswy0W4wRrtnDoPajv_AAAAf0"]
[Thu Jul 30 14:57:56.050863 2026] [security2:error] [pid 87988:tid 88153] [client 77.83.36.161:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amuswzipAwzptuCxBrhUFQAAAS0"]
[Thu Jul 30 14:57:56.429086 2026] [core:notice] [pid 89520:tid 89717] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:56.624278 2026] [core:notice] [pid 89520:tid 89790] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:57:56.699254 2026] [security2:error] [pid 89520:tid 89752] [client 20.171.55.167:4892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/man.php"] [unique_id "amusxC0W4wRrtnDoPajwCwAAAeg"]
[Thu Jul 30 14:57:57.036109 2026] [security2:error] [pid 87988:tid 88230] [client 77.83.36.161:39639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amusxTipAwzptuCxBrhUIgAAAXo"]
[Thu Jul 30 14:57:57.294879 2026] [security2:error] [pid 89520:tid 89676] [client 57.141.0.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amusxC0W4wRrtnDoPajwCAAAAZw"]
[Thu Jul 30 14:57:57.440320 2026] [security2:error] [pid 87988:tid 88135] [client 20.171.55.167:4912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/media-admin.php"] [unique_id "amusxTipAwzptuCxBrhUJgAAARs"]
[Thu Jul 30 14:57:57.588256 2026] [security2:error] [pid 89520:tid 89746] [client 77.83.36.161:39951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcsgoeastwood.org"] [uri "/administrator/index.php"] [unique_id "amusxS0W4wRrtnDoPajwDwAAAeI"]
[Thu Jul 30 14:57:58.159269 2026] [security2:error] [pid 89520:tid 89713] [client 20.171.55.167:4895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/meta.php"] [unique_id "amusxi0W4wRrtnDoPajwEwAAAcE"]
[Thu Jul 30 14:57:58.918608 2026] [security2:error] [pid 87988:tid 88121] [client 20.171.55.167:4840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/modules/elfinder/connectors/php/connector.php"] [unique_id "amusxjipAwzptuCxBrhUQAAAAQ0"]
[Thu Jul 30 14:57:59.004670 2026] [security2:error] [pid 87988:tid 88093] [remote 57.141.0.25:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/44562851719/feed/rss2/"] [unique_id "amusxzipAwzptuCxBrhURAABhmg"]
[Thu Jul 30 14:57:59.211355 2026] [proxy:error] [pid 87988:tid 88096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:57:59.211408 2026] [proxy_http:error] [pid 87988:tid 88096] [remote 74.7.175.184:50694] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:57:59.212038 2026] [proxy:error] [pid 87988:tid 88096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:57:59.212088 2026] [proxy_http:error] [pid 87988:tid 88096] [remote 74.7.175.184:50694] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:57:59.627719 2026] [security2:error] [pid 87988:tid 88180] [client 20.171.55.167:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/mysql.php"] [unique_id "amusxzipAwzptuCxBrhUTwAAAUg"]
[Thu Jul 30 14:57:59.975429 2026] [security2:error] [pid 89520:tid 89698] [client 20.100.187.246:11014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.tmb/LA.php"] [unique_id "amusxy0W4wRrtnDoPajwHAAAAbI"]
[Thu Jul 30 14:58:00.420090 2026] [security2:error] [pid 89520:tid 89740] [client 20.171.55.167:4919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/news.php"] [unique_id "amusyC0W4wRrtnDoPajwIAAAAdw"]
[Thu Jul 30 14:58:00.434853 2026] [security2:error] [pid 87988:tid 88151] [client 2a03:2880:f800:45:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amusxzipAwzptuCxBrhUSAABKw0"]
[Thu Jul 30 14:58:00.774832 2026] [security2:error] [pid 89520:tid 89774] [client 20.100.187.246:25204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.tmb/admin.php"] [unique_id "amusyC0W4wRrtnDoPajwVAAAAf4"]
[Thu Jul 30 14:58:01.033771 2026] [security2:error] [pid 87988:tid 88194] [client 74.7.230.51:36042] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.eaw.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amusyTipAwzptuCxBrhUaAAAAVY"]
[Thu Jul 30 14:58:01.153244 2026] [security2:error] [pid 87988:tid 88179] [client 220.181.108.102:8747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/1811"] [unique_id "amusyTipAwzptuCxBrhUbAAAAUc"]
[Thu Jul 30 14:58:01.184366 2026] [security2:error] [pid 89520:tid 89738] [client 20.171.55.167:4813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/nx.php"] [unique_id "amusyS0W4wRrtnDoPajwZwAAAdo"]
[Thu Jul 30 14:58:01.812662 2026] [security2:error] [pid 89520:tid 89667] [client 119.249.100.181:45557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/1811"] [unique_id "amusyS0W4wRrtnDoPajwaQAAAZM"]
[Thu Jul 30 14:58:01.910881 2026] [security2:error] [pid 89520:tid 89664] [client 20.171.55.167:4911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/options.php"] [unique_id "amusyS0W4wRrtnDoPajwbgAAAZA"]
[Thu Jul 30 14:58:02.173171 2026] [security2:error] [pid 89520:tid 89585] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amusyi0W4wRrtnDoPajwdAABtzc"]
[Thu Jul 30 14:58:02.173324 2026] [security2:error] [pid 89520:tid 89703] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amusyi0W4wRrtnDoPajwdAABtzc"]
[Thu Jul 30 14:58:02.532023 2026] [core:notice] [pid 89520:tid 89695] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:02.645473 2026] [security2:error] [pid 89520:tid 89747] [client 20.100.187.246:24984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.tmb/class_api.php"] [unique_id "amusyi0W4wRrtnDoPajweQAAAeM"]
[Thu Jul 30 14:58:02.646595 2026] [security2:error] [pid 89520:tid 89714] [client 20.171.55.167:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/pagesk.php"] [unique_id "amusyi0W4wRrtnDoPajwegAAAcI"]
[Thu Jul 30 14:58:02.708800 2026] [core:notice] [pid 89520:tid 89773] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:02.881532 2026] [core:notice] [pid 87988:tid 88131] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:03.386987 2026] [security2:error] [pid 89520:tid 89766] [client 20.171.55.167:4805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/phpimage.php"] [unique_id "amusyy0W4wRrtnDoPajwjQAAAfY"]
[Thu Jul 30 14:58:03.513404 2026] [security2:error] [pid 89520:tid 89718] [client 20.100.187.246:50900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amusyy0W4wRrtnDoPajwkAAAAcY"]
[Thu Jul 30 14:58:03.654300 2026] [core:notice] [pid 87988:tid 88029] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:03.875479 2026] [security2:error] [pid 89520:tid 89709] [client 193.47.62.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amusyS0W4wRrtnDoPajwaAABvTU"], referer: http://spececigarette.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Thu Jul 30 14:58:04.113139 2026] [security2:error] [pid 89520:tid 89736] [client 20.171.55.167:5002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/pki-validationwp.php"] [unique_id "amuszC0W4wRrtnDoPajwnAAAAdg"]
[Thu Jul 30 14:58:04.453033 2026] [security2:error] [pid 89520:tid 89733] [client 20.100.187.246:25206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuszC0W4wRrtnDoPajwnQAAAdU"]
[Thu Jul 30 14:58:04.626211 2026] [core:notice] [pid 89520:tid 89601] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:04.820731 2026] [security2:error] [pid 87988:tid 88154] [client 20.171.55.167:4873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/pomo.php"] [unique_id "amuszDipAwzptuCxBrhUowAAAS4"]
[Thu Jul 30 14:58:05.065329 2026] [security2:error] [pid 89520:tid 89786] [client 20.100.187.246:25158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuszS0W4wRrtnDoPajwqAAAAgo"]
[Thu Jul 30 14:58:05.419832 2026] [security2:error] [pid 89520:tid 89738] [client 135.119.63.61:7397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/011i.php"] [unique_id "amuszS0W4wRrtnDoPajwqQAAAdo"]
[Thu Jul 30 14:58:05.620421 2026] [security2:error] [pid 89520:tid 89704] [client 20.171.55.167:4801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/pridmag/db.php"] [unique_id "amuszS0W4wRrtnDoPajwrAAAAbg"]
[Thu Jul 30 14:58:06.361506 2026] [security2:error] [pid 87988:tid 88192] [client 20.171.55.167:4906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/providers/as.php"] [unique_id "amuszjipAwzptuCxBrhUugAAAVQ"]
[Thu Jul 30 14:58:06.544729 2026] [core:notice] [pid 87988:tid 88178] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:06.545878 2026] [core:notice] [pid 89520:tid 89696] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:06.556823 2026] [core:notice] [pid 89520:tid 89687] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:06.560479 2026] [core:notice] [pid 87988:tid 88136] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:06.563286 2026] [core:notice] [pid 89520:tid 89784] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:06.648234 2026] [security2:error] [pid 87988:tid 88159] [client 20.100.187.246:30055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/991176.php"] [unique_id "amuszjipAwzptuCxBrhUvwAAATM"]
[Thu Jul 30 14:58:06.755130 2026] [security2:error] [pid 87988:tid 88179] [client 135.119.63.61:7393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/03a005685d.php"] [unique_id "amuszjipAwzptuCxBrhUwwAAAUc"]
[Thu Jul 30 14:58:06.935475 2026] [core:notice] [pid 87988:tid 88198] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:06.940136 2026] [core:notice] [pid 89520:tid 89780] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:06.940161 2026] [core:notice] [pid 89520:tid 89727] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:06.944096 2026] [core:notice] [pid 87988:tid 88128] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:06.957111 2026] [core:notice] [pid 89520:tid 89752] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:07.099970 2026] [security2:error] [pid 87988:tid 88235] [client 20.171.55.167:5041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/pwnd/admin-footer.php"] [unique_id "amuszzipAwzptuCxBrhUyAAAAX8"]
[Thu Jul 30 14:58:07.147611 2026] [security2:error] [pid 87988:tid 88197] [client 49.13.24.81:47256] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuszzipAwzptuCxBrhUywAAAVk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:58:07.514868 2026] [core:notice] [pid 89520:tid 89680] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:07.520230 2026] [security2:error] [pid 89520:tid 89680] [client 49.13.24.81:47270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuszy0W4wRrtnDoPajwwQAAAaA"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:58:07.588882 2026] [security2:error] [pid 87988:tid 88243] [client 135.119.63.61:43343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/403.php"] [unique_id "amuszzipAwzptuCxBrhU0gAAAYc"]
[Thu Jul 30 14:58:07.654295 2026] [core:notice] [pid 87988:tid 88207] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:07.755423 2026] [core:notice] [pid 89520:tid 89712] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:07.843127 2026] [security2:error] [pid 89520:tid 89690] [client 20.171.55.167:4822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/re.php"] [unique_id "amuszy0W4wRrtnDoPajwxAAAAao"]
[Thu Jul 30 14:58:07.969387 2026] [security2:error] [pid 87988:tid 88221] [client 20.100.187.246:11011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuszzipAwzptuCxBrhU2wAAAXE"]
[Thu Jul 30 14:58:08.030792 2026] [security2:error] [pid 89520:tid 89723] [client 49.13.24.81:47276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amus0C0W4wRrtnDoPajwxwAAAcs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 14:58:08.118877 2026] [security2:error] [pid 89520:tid 89768] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuszy0W4wRrtnDoPajwwgAAAfg"]
[Thu Jul 30 14:58:08.155866 2026] [security2:error] [pid 89520:tid 89684] [client 66.249.65.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.supreme-hydraulics.com"] [uri "/index.php"] [unique_id "amuszi0W4wRrtnDoPajwtwAAAaQ"]
[Thu Jul 30 14:58:08.543387 2026] [core:notice] [pid 89520:tid 89673] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:08.566392 2026] [core:notice] [pid 89520:tid 89721] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:08.584785 2026] [security2:error] [pid 89520:tid 89671] [client 20.171.55.167:4592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/rightbar_burgundy.php"] [unique_id "amus0C0W4wRrtnDoPajwzwAAAZc"]
[Thu Jul 30 14:58:08.640352 2026] [security2:error] [pid 87988:tid 88169] [client 135.119.63.61:43371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/404.php"] [unique_id "amus0DipAwzptuCxBrhU4QAAAT0"]
[Thu Jul 30 14:58:08.666185 2026] [security2:error] [pid 89520:tid 89775] [client 20.100.187.246:11038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amus0C0W4wRrtnDoPajw0AAAAf8"]
[Thu Jul 30 14:58:08.998249 2026] [core:notice] [pid 87988:tid 88164] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:09.026628 2026] [core:notice] [pid 89520:tid 89704] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:09.322209 2026] [security2:error] [pid 89520:tid 89767] [client 20.171.55.167:4571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/sHS.php"] [unique_id "amus0S0W4wRrtnDoPajw2gAAAfc"]
[Thu Jul 30 14:58:09.485007 2026] [security2:error] [pid 89520:tid 89747] [client 135.119.63.61:7384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/aa.php"] [unique_id "amus0S0W4wRrtnDoPajw3QAAAeM"]
[Thu Jul 30 14:58:10.057336 2026] [security2:error] [pid 89520:tid 89727] [client 20.171.55.167:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/sec.php"] [unique_id "amus0i0W4wRrtnDoPajw4AAAAc8"]
[Thu Jul 30 14:58:10.915001 2026] [security2:error] [pid 87988:tid 88197] [client 20.171.55.167:4842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/settings.php"] [unique_id "amus0jipAwzptuCxBrhVCAAAAVk"]
[Thu Jul 30 14:58:10.928743 2026] [core:error] [pid 87988:tid 88183] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:58:10.928764 2026] [core:error] [pid 87988:tid 88183] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:58:10.928895 2026] [security2:error] [pid 87988:tid 88183] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.kev.udi.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amus0jipAwzptuCxBrhVCgAAAUs"]
[Thu Jul 30 14:58:10.929935 2026] [security2:error] [pid 89520:tid 89781] [client 74.7.228.63:44826] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.kev.udi.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amus0i0W4wRrtnDoPajw4wACBUw"]
[Thu Jul 30 14:58:10.996946 2026] [security2:error] [pid 89520:tid 89712] [client 23.130.104.130:33142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.104.130.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amus0i0W4wRrtnDoPajw5wAAAcA"]
[Thu Jul 30 14:58:10.997053 2026] [security2:error] [pid 89520:tid 89712] [client 23.130.104.130:33142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amus0i0W4wRrtnDoPajw5wAAAcA"]
[Thu Jul 30 14:58:11.667285 2026] [security2:error] [pid 89520:tid 89768] [client 20.171.55.167:4874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/shellbypass.php"] [unique_id "amus0y0W4wRrtnDoPajw7QAAAfg"]
[Thu Jul 30 14:58:11.788449 2026] [proxy:error] [pid 87988:tid 88196] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:58:11.788546 2026] [proxy_http:error] [pid 87988:tid 88196] [client 18.211.55.47:21624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:58:11.789138 2026] [proxy:error] [pid 87988:tid 88196] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:58:11.789185 2026] [proxy_http:error] [pid 87988:tid 88196] [client 18.211.55.47:21624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:58:12.401009 2026] [security2:error] [pid 89520:tid 89671] [client 20.171.55.167:4566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/simple-upload.php"] [unique_id "amus1C0W4wRrtnDoPajw9QAAAZc"]
[Thu Jul 30 14:58:12.465132 2026] [security2:error] [pid 89520:tid 89602] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus1C0W4wRrtnDoPajw-AABrEg"]
[Thu Jul 30 14:58:12.465271 2026] [security2:error] [pid 89520:tid 89692] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus1C0W4wRrtnDoPajw-AABrEg"]
[Thu Jul 30 14:58:13.146785 2026] [security2:error] [pid 89520:tid 89738] [client 20.171.55.167:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/sketch/404.php"] [unique_id "amus1S0W4wRrtnDoPajxBgAAAdo"]
[Thu Jul 30 14:58:13.941858 2026] [security2:error] [pid 89520:tid 89767] [client 20.171.55.167:4552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/spam.php"] [unique_id "amus1S0W4wRrtnDoPajxCQAAAfc"]
[Thu Jul 30 14:58:14.680530 2026] [security2:error] [pid 87988:tid 88156] [client 20.171.55.167:4602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/storage/download/admin.php"] [unique_id "amus1jipAwzptuCxBrhVOwAAATA"]
[Thu Jul 30 14:58:14.913786 2026] [core:notice] [pid 89520:tid 89785] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:14.917961 2026] [security2:error] [pid 89520:tid 89785] [client 66.249.65.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/91/94"] [unique_id "amus1i0W4wRrtnDoPajxEwAAAgk"]
[Thu Jul 30 14:58:15.399189 2026] [security2:error] [pid 89520:tid 89781] [client 20.171.55.167:4603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/success.php"] [unique_id "amus1y0W4wRrtnDoPajxFwAAAgU"]
[Thu Jul 30 14:58:15.844210 2026] [security2:error] [pid 89520:tid 89724] [client 20.100.187.246:11015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amus1y0W4wRrtnDoPajxHQAAAcw"]
[Thu Jul 30 14:58:16.138586 2026] [security2:error] [pid 89520:tid 89761] [client 20.171.55.167:4594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/taxonomy.php"] [unique_id "amus2C0W4wRrtnDoPajxIwAAAfE"]
[Thu Jul 30 14:58:16.167660 2026] [core:notice] [pid 89520:tid 89769] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:16.171111 2026] [security2:error] [pid 89520:tid 89769] [client 66.249.79.237:49692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/6590/2758"] [unique_id "amus1y0W4wRrtnDoPajxIAAAAfk"]
[Thu Jul 30 14:58:16.411908 2026] [security2:error] [pid 89520:tid 89739] [client 135.119.63.61:7362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/aafewc0k.php"] [unique_id "amus2C0W4wRrtnDoPajxJQAAAds"]
[Thu Jul 30 14:58:16.763149 2026] [security2:error] [pid 87988:tid 88179] [client 20.100.187.246:27074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amus2DipAwzptuCxBrhVUAAAAUc"]
[Thu Jul 30 14:58:16.866367 2026] [security2:error] [pid 87988:tid 88131] [client 20.171.55.167:5017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/tflow/goat.php"] [unique_id "amus2DipAwzptuCxBrhVUQAAARc"]
[Thu Jul 30 14:58:17.662488 2026] [security2:error] [pid 89520:tid 89697] [client 20.171.55.167:4551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/tiny.php"] [unique_id "amus2S0W4wRrtnDoPajxLgAAAbE"]
[Thu Jul 30 14:58:18.214619 2026] [security2:error] [pid 89520:tid 89786] [client 216.244.66.194:54616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amus2i0W4wRrtnDoPajxNAAAAgo"]
[Thu Jul 30 14:58:18.214735 2026] [security2:error] [pid 89520:tid 89786] [client 216.244.66.194:54616] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amus2i0W4wRrtnDoPajxNAAAAgo"]
[Thu Jul 30 14:58:18.409467 2026] [security2:error] [pid 87988:tid 88141] [client 20.171.55.167:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/tonant.php"] [unique_id "amus2jipAwzptuCxBrhVZgAAASE"]
[Thu Jul 30 14:58:18.742529 2026] [security2:error] [pid 87988:tid 88196] [client 172.237.109.114:47180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amus2jipAwzptuCxBrhVZAAAAVg"]
[Thu Jul 30 14:58:18.776834 2026] [security2:error] [pid 87988:tid 87990] [remote 47.128.119.147:33690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "radiojelli.com"] [uri "/psychology/"] [unique_id "amus2jipAwzptuCxBrhVcQABGwE"], referer: https://bootstraplily.com/robots.txt
[Thu Jul 30 14:58:18.875387 2026] [security2:error] [pid 87988:tid 88130] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amus2jipAwzptuCxBrhVZQABFn8"]
[Thu Jul 30 14:58:19.140019 2026] [security2:error] [pid 89520:tid 89664] [client 20.171.55.167:5038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/twenty/twenty.php"] [unique_id "amus2y0W4wRrtnDoPajxOQAAAZA"]
[Thu Jul 30 14:58:19.364579 2026] [security2:error] [pid 87988:tid 88188] [client 20.100.187.246:22577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/--wp-lgj.php"] [unique_id "amus2zipAwzptuCxBrhVewAAAVA"]
[Thu Jul 30 14:58:19.695077 2026] [core:notice] [pid 89520:tid 89759] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:19.880122 2026] [security2:error] [pid 87988:tid 88158] [client 20.171.55.167:4817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/twentytwentytwo/atomlib.php"] [unique_id "amus2zipAwzptuCxBrhVhAAAATI"]
[Thu Jul 30 14:58:20.084037 2026] [security2:error] [pid 87988:tid 88162] [client 135.119.63.61:7404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/abcd.php"] [unique_id "amus3DipAwzptuCxBrhVhwAAATY"]
[Thu Jul 30 14:58:20.193001 2026] [security2:error] [pid 89520:tid 89771] [client 20.100.187.246:25712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amus3C0W4wRrtnDoPajxQgAAAfs"]
[Thu Jul 30 14:58:20.284311 2026] [security2:error] [pid 89520:tid 89752] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amus2i0W4wRrtnDoPajxNwAB6FQ"]
[Thu Jul 30 14:58:20.311461 2026] [security2:error] [pid 87988:tid 88184] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amus2jipAwzptuCxBrhVbwABTAs"]
[Thu Jul 30 14:58:20.592655 2026] [security2:error] [pid 89520:tid 89757] [client 20.171.55.167:4582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/up/main.php"] [unique_id "amus3C0W4wRrtnDoPajxRgAAAe0"]
[Thu Jul 30 14:58:20.763520 2026] [security2:error] [pid 87988:tid 88010] [remote 74.7.243.224:47898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/js/humanitariaf.php"] [unique_id "amus3DipAwzptuCxBrhVjgABIBU"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/js/bootstrap.bundle.min.js
[Thu Jul 30 14:58:21.078488 2026] [security2:error] [pid 89520:tid 89717] [client 20.100.187.246:21160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amus3S0W4wRrtnDoPajxSwAAAcU"]
[Thu Jul 30 14:58:21.177714 2026] [security2:error] [pid 89520:tid 89676] [client 135.119.63.61:7411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/about.php"] [unique_id "amus3S0W4wRrtnDoPajxTQAAAZw"]
[Thu Jul 30 14:58:21.280398 2026] [security2:error] [pid 87988:tid 88201] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amus2zipAwzptuCxBrhVfAABXRo"]
[Thu Jul 30 14:58:21.420772 2026] [security2:error] [pid 89520:tid 89680] [client 20.171.55.167:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/uploadsadmin.php"] [unique_id "amus3S0W4wRrtnDoPajxTgAAAaA"]
[Thu Jul 30 14:58:21.432644 2026] [security2:error] [pid 89520:tid 89766] [client 213.152.161.20:47128] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amus3S0W4wRrtnDoPajxTAAAAfY"]
[Thu Jul 30 14:58:21.432731 2026] [security2:error] [pid 89520:tid 89766] [client 213.152.161.20:47128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amus3S0W4wRrtnDoPajxTAAAAfY"]
[Thu Jul 30 14:58:21.844493 2026] [security2:error] [pid 87988:tid 88220] [client 20.100.187.246:43633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/flower.php"] [unique_id "amus3TipAwzptuCxBrhVnwAAAXA"]
[Thu Jul 30 14:58:22.015952 2026] [security2:error] [pid 87988:tid 88213] [client 135.119.63.61:7367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/admin.php"] [unique_id "amus3jipAwzptuCxBrhVowAAAWk"]
[Thu Jul 30 14:58:22.174944 2026] [security2:error] [pid 89520:tid 89708] [client 20.171.55.167:4578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/user_guidek.php"] [unique_id "amus3i0W4wRrtnDoPajxWAAAAbw"]
[Thu Jul 30 14:58:22.561287 2026] [security2:error] [pid 89520:tid 89718] [client 241.27.169.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amus3S0W4wRrtnDoPajxVAABxlg"], referer: https://flixon.net/cold-storage-2026-vj-emmy/
[Thu Jul 30 14:58:22.674460 2026] [security2:error] [pid 87988:tid 88243] [client 172.237.109.114:49825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amus3jipAwzptuCxBrhVpwAAAYc"]
[Thu Jul 30 14:58:22.902346 2026] [security2:error] [pid 89520:tid 89729] [client 20.171.55.167:4883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/vendorswp.php"] [unique_id "amus3i0W4wRrtnDoPajxZgAAAdE"]
[Thu Jul 30 14:58:22.916485 2026] [security2:error] [pid 89520:tid 89775] [client 135.119.63.61:7402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/adminfuns.php"] [unique_id "amus3i0W4wRrtnDoPajxZwAAAf8"]
[Thu Jul 30 14:58:23.036491 2026] [security2:error] [pid 89520:tid 89623] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus3y0W4wRrtnDoPajxaAAB4F0"]
[Thu Jul 30 14:58:23.036663 2026] [security2:error] [pid 89520:tid 89744] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus3y0W4wRrtnDoPajxaAAB4F0"]
[Thu Jul 30 14:58:23.102701 2026] [core:notice] [pid 87988:tid 88193] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:23.686417 2026] [security2:error] [pid 87988:tid 88076] [remote 216.73.216.51:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amus3zipAwzptuCxBrhVvAABOlc"]
[Thu Jul 30 14:58:23.747015 2026] [security2:error] [pid 89520:tid 89728] [client 20.171.55.167:4587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wawe.php"] [unique_id "amus3y0W4wRrtnDoPajxegAAAdA"]
[Thu Jul 30 14:58:24.501261 2026] [security2:error] [pid 87988:tid 88168] [client 20.171.55.167:4586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/widgets/browser.php"] [unique_id "amus4DipAwzptuCxBrhVxQAAATw"]
[Thu Jul 30 14:58:25.056014 2026] [security2:error] [pid 89520:tid 89754] [client 20.100.187.246:22579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/xleet.php"] [unique_id "amus4S0W4wRrtnDoPajxlgAAAeo"]
[Thu Jul 30 14:58:25.227613 2026] [security2:error] [pid 89520:tid 89769] [client 20.171.55.167:4839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wikindex.php"] [unique_id "amus4S0W4wRrtnDoPajxmwAAAfk"]
[Thu Jul 30 14:58:25.817265 2026] [security2:error] [pid 89520:tid 89763] [client 57.141.0.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amus4S0W4wRrtnDoPajxmQAAAfM"]
[Thu Jul 30 14:58:25.955755 2026] [security2:error] [pid 89520:tid 89667] [client 20.171.55.167:5036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wp-22.php"] [unique_id "amus4S0W4wRrtnDoPajxpQAAAZM"]
[Thu Jul 30 14:58:26.033070 2026] [security2:error] [pid 89520:tid 89694] [client 20.100.187.246:23571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amus4i0W4wRrtnDoPajxpgAAAa4"]
[Thu Jul 30 14:58:26.327938 2026] [core:notice] [pid 89520:tid 89688] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:26.479232 2026] [security2:error] [pid 89520:tid 89695] [client 20.100.187.246:25675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amus4i0W4wRrtnDoPajxqgAAAa8"]
[Thu Jul 30 14:58:26.757006 2026] [security2:error] [pid 89520:tid 89704] [client 20.171.55.167:4591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wp-blog-header.php"] [unique_id "amus4i0W4wRrtnDoPajxqwAAAbg"]
[Thu Jul 30 14:58:27.259668 2026] [security2:error] [pid 87988:tid 88204] [client 20.100.187.246:26232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amus4zipAwzptuCxBrhV4wAAAWA"]
[Thu Jul 30 14:58:27.529599 2026] [security2:error] [pid 87988:tid 88205] [client 20.171.55.167:4605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wp-confirm.php"] [unique_id "amus4zipAwzptuCxBrhV6gAAAWE"]
[Thu Jul 30 14:58:27.716922 2026] [core:notice] [pid 87988:tid 88131] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:28.334108 2026] [security2:error] [pid 87988:tid 88153] [client 20.171.55.167:4877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wp-doft/noimg.php"] [unique_id "amus5DipAwzptuCxBrhV8wAAAS0"]
[Thu Jul 30 14:58:28.372133 2026] [security2:error] [pid 89520:tid 89741] [client 20.100.187.246:22570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amus5C0W4wRrtnDoPajxvAAAAd0"]
[Thu Jul 30 14:58:29.071136 2026] [security2:error] [pid 89520:tid 89754] [client 20.171.55.167:4581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wp-head.php"] [unique_id "amus5S0W4wRrtnDoPajxyAAAAeo"]
[Thu Jul 30 14:58:29.386285 2026] [security2:error] [pid 87988:tid 88031] [remote 216.73.216.51:39079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amus5TipAwzptuCxBrhWBAABiCo"]
[Thu Jul 30 14:58:29.476629 2026] [core:notice] [pid 89520:tid 89715] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:29.593501 2026] [security2:error] [pid 89520:tid 89769] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amus5C0W4wRrtnDoPajxxwAAAfk"]
[Thu Jul 30 14:58:29.614069 2026] [security2:error] [pid 87988:tid 88190] [client 20.100.187.246:14760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amus5TipAwzptuCxBrhWCQAAAVI"]
[Thu Jul 30 14:58:29.873508 2026] [security2:error] [pid 87988:tid 88194] [client 20.171.55.167:4604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wp-key.php"] [unique_id "amus5TipAwzptuCxBrhWCwAAAVY"]
[Thu Jul 30 14:58:29.962826 2026] [core:notice] [pid 87988:tid 88161] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:30.610276 2026] [security2:error] [pid 87988:tid 88232] [client 20.171.55.167:4853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wp-post-editor.php"] [unique_id "amus5jipAwzptuCxBrhWFgAAAXw"]
[Thu Jul 30 14:58:30.611679 2026] [security2:error] [pid 89520:tid 89780] [client 135.119.63.61:43378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/albin.php"] [unique_id "amus5i0W4wRrtnDoPajx2AAAAgQ"]
[Thu Jul 30 14:58:30.704360 2026] [security2:error] [pid 87988:tid 88222] [client 20.100.187.246:22548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amus5jipAwzptuCxBrhWFwAAAXI"]
[Thu Jul 30 14:58:30.785170 2026] [core:notice] [pid 89520:tid 89755] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:31.199550 2026] [core:notice] [pid 89520:tid 89771] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:31.353374 2026] [security2:error] [pid 89520:tid 89712] [client 20.171.55.167:4819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wp-sigunq.php"] [unique_id "amus5y0W4wRrtnDoPajx3QAAAcA"]
[Thu Jul 30 14:58:32.070548 2026] [security2:error] [pid 87988:tid 88242] [client 20.171.55.167:4607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wp-widgets.php"] [unique_id "amus6DipAwzptuCxBrhWKgAAAYY"]
[Thu Jul 30 14:58:32.119795 2026] [security2:error] [pid 89520:tid 89713] [client 135.119.63.61:43349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/amfsqvgv.php"] [unique_id "amus6C0W4wRrtnDoPajx6QAAAcE"]
[Thu Jul 30 14:58:32.664969 2026] [security2:error] [pid 89520:tid 89733] [client 127.0.0.1:40300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amus6C0W4wRrtnDoPajx8gAAAdU"]
[Thu Jul 30 14:58:32.665093 2026] [security2:error] [pid 89520:tid 89718] [client 74.7.175.186:56856] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kii.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amus6C0W4wRrtnDoPajx8QABxgg"]
[Thu Jul 30 14:58:32.746499 2026] [security2:error] [pid 87988:tid 88134] [client 20.100.187.246:11353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amus6DipAwzptuCxBrhWNQAAARo"]
[Thu Jul 30 14:58:32.899224 2026] [security2:error] [pid 87988:tid 88205] [client 20.171.55.167:4554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wpr-addons/forms/rk.php"] [unique_id "amus6DipAwzptuCxBrhWNgAAAWE"]
[Thu Jul 30 14:58:33.015067 2026] [security2:error] [pid 89520:tid 89756] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amus6C0W4wRrtnDoPajx7AAB7Ak"]
[Thu Jul 30 14:58:33.120169 2026] [security2:error] [pid 87988:tid 88126] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amus6DipAwzptuCxBrhWLQAAARI"]
[Thu Jul 30 14:58:33.300315 2026] [proxy:error] [pid 89520:tid 89541] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:58:33.300624 2026] [proxy_http:error] [pid 89520:tid 89541] [remote 74.7.230.18:34562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:58:33.301233 2026] [proxy:error] [pid 89520:tid 89541] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:58:33.301279 2026] [proxy_http:error] [pid 89520:tid 89541] [remote 74.7.230.18:34562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:58:33.601724 2026] [security2:error] [pid 87988:tid 87997] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus6TipAwzptuCxBrhWQQABggg"]
[Thu Jul 30 14:58:33.601854 2026] [security2:error] [pid 87988:tid 88238] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus6TipAwzptuCxBrhWQQABggg"]
[Thu Jul 30 14:58:33.623711 2026] [security2:error] [pid 89520:tid 89707] [client 20.171.55.167:4573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/wso403.php"] [unique_id "amus6S0W4wRrtnDoPajx-wAAAbs"]
[Thu Jul 30 14:58:33.703561 2026] [security2:error] [pid 87988:tid 87998] [remote 216.73.216.51:39079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amus6TipAwzptuCxBrhWRQABKwk"]
[Thu Jul 30 14:58:33.795009 2026] [security2:error] [pid 87988:tid 88221] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amus6TipAwzptuCxBrhWPQAAAXE"]
[Thu Jul 30 14:58:33.921052 2026] [security2:error] [pid 87988:tid 88157] [client 135.119.63.61:43341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/ant.php"] [unique_id "amus6TipAwzptuCxBrhWSQAAATE"]
[Thu Jul 30 14:58:33.969816 2026] [security2:error] [pid 87988:tid 88135] [client 20.100.187.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amus6TipAwzptuCxBrhWSAAAARs"]
[Thu Jul 30 14:58:34.240039 2026] [security2:error] [pid 89520:tid 89739] [client 20.100.187.246:22656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amus6i0W4wRrtnDoPajyAgAAAds"]
[Thu Jul 30 14:58:34.336230 2026] [security2:error] [pid 89520:tid 89735] [client 20.171.55.167:4583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/xd.php"] [unique_id "amus6i0W4wRrtnDoPajyBgAAAdc"]
[Thu Jul 30 14:58:35.048730 2026] [security2:error] [pid 87988:tid 88177] [client 20.171.55.167:4599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/xp.php"] [unique_id "amus6zipAwzptuCxBrhWVQAAAUU"]
[Thu Jul 30 14:58:35.161006 2026] [security2:error] [pid 89520:tid 89687] [client 135.119.63.61:43337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/appreciators.php"] [unique_id "amus6y0W4wRrtnDoPajyDgAAAac"]
[Thu Jul 30 14:58:35.356828 2026] [security2:error] [pid 89520:tid 89686] [client 20.100.187.246:27896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amus6y0W4wRrtnDoPajyFQAAAaY"]
[Thu Jul 30 14:58:35.387774 2026] [security2:error] [pid 87988:tid 88001] [remote 62.193.192.29:46706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.psz.dtn.temporary.site"] [uri "/wp-login.php"] [unique_id "amus6zipAwzptuCxBrhWWQABJgw"]
[Thu Jul 30 14:58:35.858259 2026] [security2:error] [pid 87988:tid 88230] [client 20.171.55.167:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/z.php"] [unique_id "amus6zipAwzptuCxBrhWYAAAAXo"]
[Thu Jul 30 14:58:36.041674 2026] [security2:error] [pid 89520:tid 89745] [client 135.119.63.61:7406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/archive.php"] [unique_id "amus7C0W4wRrtnDoPajyHgAAAeE"]
[Thu Jul 30 14:58:36.362097 2026] [security2:error] [pid 89520:tid 89790] [client 20.100.187.246:44023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amus7C0W4wRrtnDoPajyIwAAAg4"]
[Thu Jul 30 14:58:36.397348 2026] [security2:error] [pid 89520:tid 89540] [remote 51.68.247.198:53130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "carnetdeshopping.com"] [uri "/invitee-a-un-mariage-estival-20-robes-de-cocktail-chic/"] [unique_id "amus7C0W4wRrtnDoPajyJAABtgo"]
[Thu Jul 30 14:58:36.397522 2026] [security2:error] [pid 89520:tid 89702] [client 51.68.247.198:53130] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "carnetdeshopping.com"] [uri "/invitee-a-un-mariage-estival-20-robes-de-cocktail-chic/"] [unique_id "amus7C0W4wRrtnDoPajyJAABtgo"]
[Thu Jul 30 14:58:36.578834 2026] [security2:error] [pid 87988:tid 88127] [client 20.171.55.167:5013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.fireworkskenya.co.ke"] [uri "/zx.php"] [unique_id "amus7DipAwzptuCxBrhWawAAARM"]
[Thu Jul 30 14:58:37.097776 2026] [security2:error] [pid 87988:tid 88170] [client 216.73.217.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.palmtreepools.ca"] [uri "/index.php"] [unique_id "amus6zipAwzptuCxBrhWYwABPn8"]
[Thu Jul 30 14:58:37.133742 2026] [security2:error] [pid 89520:tid 89678] [client 20.100.187.246:44030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amus7S0W4wRrtnDoPajyLgAAAZ4"]
[Thu Jul 30 14:58:37.484672 2026] [security2:error] [pid 87988:tid 88201] [client 135.119.63.61:43389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/as.php"] [unique_id "amus7TipAwzptuCxBrhWewAAAV0"]
[Thu Jul 30 14:58:37.601146 2026] [security2:error] [pid 89520:tid 89708] [client 20.100.187.246:27840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amus7S0W4wRrtnDoPajyMwAAAbw"]
[Thu Jul 30 14:58:37.992346 2026] [security2:error] [pid 87988:tid 88000] [remote 47.128.96.160:38160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/search/search"] [unique_id "amus7TipAwzptuCxBrhWgAABYQs"]
[Thu Jul 30 14:58:38.011024 2026] [security2:error] [pid 89520:tid 89706] [client 20.100.187.246:12771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.wp-cli/flower.php"] [unique_id "amus7i0W4wRrtnDoPajyOAAAAbo"]
[Thu Jul 30 14:58:38.061107 2026] [core:notice] [pid 87988:tid 88027] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:38.069128 2026] [security2:error] [pid 87988:tid 88154] [client 47.128.96.160:38160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/search/search"] [unique_id "amus7jipAwzptuCxBrhWiAABLiY"], referer: https://www.ejournalugj.com/index.php/Perspective/search/search?query=vocabulary%20mastery%20notebook%20online%20learning
[Thu Jul 30 14:58:38.324846 2026] [core:notice] [pid 89520:tid 89531] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:38.442165 2026] [core:notice] [pid 89520:tid 89547] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:38.442241 2026] [core:notice] [pid 89520:tid 89544] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:38.734180 2026] [security2:error] [pid 89520:tid 89715] [client 135.119.63.61:43369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/atomlib.php"] [unique_id "amus7i0W4wRrtnDoPajyRwAAAcM"]
[Thu Jul 30 14:58:39.601498 2026] [security2:error] [pid 87988:tid 88194] [client 173.249.217.23:40166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.217.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amus7zipAwzptuCxBrhWlwAAAVY"]
[Thu Jul 30 14:58:39.601604 2026] [security2:error] [pid 87988:tid 88194] [client 173.249.217.23:40166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amus7zipAwzptuCxBrhWlwAAAVY"]
[Thu Jul 30 14:58:39.712654 2026] [security2:error] [pid 87988:tid 88168] [client 135.119.63.61:7400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/autoload_classmap.php"] [unique_id "amus7zipAwzptuCxBrhWmgAAATw"]
[Thu Jul 30 14:58:39.831003 2026] [security2:error] [pid 89520:tid 89781] [client 20.100.187.246:27140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amus7y0W4wRrtnDoPajyUQAAAgU"]
[Thu Jul 30 14:58:41.531034 2026] [security2:error] [pid 89520:tid 89696] [client 20.100.187.246:22760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amus8S0W4wRrtnDoPajyWAAAAbA"]
[Thu Jul 30 14:58:41.935623 2026] [security2:error] [pid 87988:tid 88225] [client 135.119.63.61:7373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/bb.php"] [unique_id "amus8TipAwzptuCxBrhWuQAAAXU"]
[Thu Jul 30 14:58:41.949874 2026] [core:notice] [pid 87988:tid 88199] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:41.954224 2026] [security2:error] [pid 87988:tid 88199] [client 74.0.19.9:48793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/8518"] [unique_id "amus8TipAwzptuCxBrhWtgAAAVs"]
[Thu Jul 30 14:58:42.446364 2026] [security2:error] [pid 89520:tid 89740] [client 20.100.187.246:8894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amus8i0W4wRrtnDoPajyXgAAAdw"]
[Thu Jul 30 14:58:42.498230 2026] [core:notice] [pid 87988:tid 88217] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:42.799966 2026] [core:notice] [pid 89520:tid 89674] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:42.962413 2026] [security2:error] [pid 87988:tid 88136] [client 20.100.187.246:42202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amus8jipAwzptuCxBrhWzQAAARw"]
[Thu Jul 30 14:58:43.043021 2026] [security2:error] [pid 89520:tid 89692] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amus8i0W4wRrtnDoPajyYQAAAaw"]
[Thu Jul 30 14:58:43.218305 2026] [security2:error] [pid 89520:tid 89731] [client 20.100.187.246:12742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amus8y0W4wRrtnDoPajyawAAAdM"]
[Thu Jul 30 14:58:43.625257 2026] [security2:error] [pid 89520:tid 89719] [client 82.102.18.188:33744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amus8y0W4wRrtnDoPajycAAAAcc"]
[Thu Jul 30 14:58:43.630914 2026] [security2:error] [pid 89520:tid 89689] [client 20.100.187.246:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amus8y0W4wRrtnDoPajycQAAAak"]
[Thu Jul 30 14:58:43.641823 2026] [security2:error] [pid 87988:tid 88236] [client 43.172.197.201:40230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amus8zipAwzptuCxBrhW1AAAAYA"]
[Thu Jul 30 14:58:43.655067 2026] [security2:error] [pid 89520:tid 89706] [client 135.119.63.61:43390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/bnm.php"] [unique_id "amus8y0W4wRrtnDoPajycgAAAbo"]
[Thu Jul 30 14:58:43.708435 2026] [security2:error] [pid 87988:tid 88079] [remote 216.73.216.51:43705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amus8zipAwzptuCxBrhW1wABdFo"]
[Thu Jul 30 14:58:43.821639 2026] [security2:error] [pid 89520:tid 89744] [client 172.237.109.114:20839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amus8y0W4wRrtnDoPajyagAAAeA"]
[Thu Jul 30 14:58:43.972805 2026] [security2:error] [pid 89520:tid 89679] [client 20.100.187.246:13932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amus8y0W4wRrtnDoPajyeQAAAZ8"]
[Thu Jul 30 14:58:44.025253 2026] [security2:error] [pid 89520:tid 89666] [client 82.102.18.188:33756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amus9C0W4wRrtnDoPajyegAAAZI"]
[Thu Jul 30 14:58:44.184199 2026] [security2:error] [pid 89520:tid 89545] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus9C0W4wRrtnDoPajyewACCA8"]
[Thu Jul 30 14:58:44.184358 2026] [security2:error] [pid 89520:tid 89784] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus9C0W4wRrtnDoPajyewACCA8"]
[Thu Jul 30 14:58:44.294074 2026] [security2:error] [pid 89520:tid 89677] [client 82.102.18.188:53618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amus9C0W4wRrtnDoPajyfwAAAZ0"]
[Thu Jul 30 14:58:44.313951 2026] [core:notice] [pid 89520:tid 89687] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:44.319580 2026] [security2:error] [pid 89520:tid 89687] [client 43.173.181.66:40684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/typography/"] [unique_id "amus9C0W4wRrtnDoPajygAAAAac"], referer: https://carnetdeshopping.com/index.php/typography/
[Thu Jul 30 14:58:44.572698 2026] [security2:error] [pid 87988:tid 88181] [client 82.102.18.188:53620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amus9DipAwzptuCxBrhW4gAAAUk"]
[Thu Jul 30 14:58:44.836479 2026] [security2:error] [pid 89520:tid 89760] [client 82.102.18.188:53636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amus9C0W4wRrtnDoPajyhgAAAfA"]
[Thu Jul 30 14:58:44.971532 2026] [security2:error] [pid 89520:tid 89680] [client 135.119.63.61:7390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/bootstrap.php"] [unique_id "amus9C0W4wRrtnDoPajyiQAAAaA"]
[Thu Jul 30 14:58:45.096089 2026] [security2:error] [pid 89520:tid 89743] [client 82.102.18.188:53650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amus9S0W4wRrtnDoPajyigAAAd8"]
[Thu Jul 30 14:58:45.374380 2026] [security2:error] [pid 89520:tid 89684] [client 82.102.18.188:53666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amus9S0W4wRrtnDoPajykAAAAaQ"]
[Thu Jul 30 14:58:45.645927 2026] [security2:error] [pid 87988:tid 88230] [client 82.102.18.188:53668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amus9TipAwzptuCxBrhW7QAAAXo"]
[Thu Jul 30 14:58:45.651573 2026] [security2:error] [pid 89520:tid 89724] [client 20.100.187.246:25417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/amaxx.php"] [unique_id "amus9S0W4wRrtnDoPajylAAAAcw"]
[Thu Jul 30 14:58:45.915630 2026] [security2:error] [pid 89520:tid 89756] [client 82.102.18.188:53682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amus9S0W4wRrtnDoPajymAAAAew"]
[Thu Jul 30 14:58:46.202351 2026] [security2:error] [pid 89520:tid 89748] [client 82.102.18.188:53684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amus9i0W4wRrtnDoPajymgAAAeQ"]
[Thu Jul 30 14:58:46.357844 2026] [security2:error] [pid 89520:tid 89761] [client 20.100.187.246:22741] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cnpinyin.com"] [uri "/1.php"] [unique_id "amus9i0W4wRrtnDoPajynAAAAfE"]
[Thu Jul 30 14:58:46.357951 2026] [security2:error] [pid 89520:tid 89761] [client 20.100.187.246:22741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/1.php"] [unique_id "amus9i0W4wRrtnDoPajynAAAAfE"]
[Thu Jul 30 14:58:46.474690 2026] [security2:error] [pid 89520:tid 89707] [client 82.102.18.188:53696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amus9i0W4wRrtnDoPajyoAAAAbs"]
[Thu Jul 30 14:58:46.740123 2026] [security2:error] [pid 89520:tid 89703] [client 82.102.18.188:53704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amus9i0W4wRrtnDoPajyogAAAbc"]
[Thu Jul 30 14:58:46.741189 2026] [core:notice] [pid 89520:tid 89688] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:46.835013 2026] [security2:error] [pid 89520:tid 89708] [client 135.119.63.61:43332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/buy.php"] [unique_id "amus9i0W4wRrtnDoPajyowAAAbw"]
[Thu Jul 30 14:58:47.250309 2026] [security2:error] [pid 89520:tid 89689] [client 77.83.36.161:2544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amus9y0W4wRrtnDoPajyqgAAAak"]
[Thu Jul 30 14:58:47.407656 2026] [security2:error] [pid 87988:tid 88204] [client 82.102.18.188:53710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amus9zipAwzptuCxBrhXAQAAAWA"]
[Thu Jul 30 14:58:47.697566 2026] [security2:error] [pid 89520:tid 89727] [client 82.102.18.188:10154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.mgstudiostore.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amus9y0W4wRrtnDoPajysQAAAc8"]
[Thu Jul 30 14:58:47.817351 2026] [security2:error] [pid 89520:tid 89784] [client 77.83.36.161:2851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amus9y0W4wRrtnDoPajysgAAAgg"]
[Thu Jul 30 14:58:47.909146 2026] [security2:error] [pid 87988:tid 88183] [client 135.119.63.61:7395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/chosen.php"] [unique_id "amus9zipAwzptuCxBrhXBwAAAUs"]
[Thu Jul 30 14:58:47.940080 2026] [core:notice] [pid 89520:tid 89777] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:48.099921 2026] [core:notice] [pid 89520:tid 89753] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:48.414249 2026] [security2:error] [pid 89520:tid 89771] [client 77.83.36.161:3179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administrator/index.php"] [unique_id "amus-C0W4wRrtnDoPajyuwAAAfs"]
[Thu Jul 30 14:58:48.799990 2026] [autoindex:error] [pid 87988:tid 88217] [client 40.77.167.55:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_b749bff5/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 14:58:49.102894 2026] [core:notice] [pid 89520:tid 89668] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:49.129212 2026] [security2:error] [pid 87988:tid 88100] [remote 57.141.0.10:58346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amus-TipAwzptuCxBrhXFAABIW8"]
[Thu Jul 30 14:58:49.390008 2026] [security2:error] [pid 89520:tid 89549] [remote 216.73.216.51:21568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amus-S0W4wRrtnDoPajyxwABshM"]
[Thu Jul 30 14:58:49.754647 2026] [security2:error] [pid 89520:tid 89555] [remote 57.141.0.11:25606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amus-S0W4wRrtnDoPajyywABthk"]
[Thu Jul 30 14:58:49.868521 2026] [security2:error] [pid 87988:tid 88170] [client 20.100.187.246:21837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/admin.php"] [unique_id "amus-TipAwzptuCxBrhXGgAAAT4"]
[Thu Jul 30 14:58:51.020925 2026] [security2:error] [pid 89520:tid 89710] [client 20.100.187.246:13469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/as.php"] [unique_id "amus-y0W4wRrtnDoPajy0wAAAb4"]
[Thu Jul 30 14:58:51.623527 2026] [security2:error] [pid 87988:tid 88155] [client 135.119.63.61:7386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/class-wp-image.php"] [unique_id "amus-zipAwzptuCxBrhXMQAAAS8"]
[Thu Jul 30 14:58:51.759087 2026] [security2:error] [pid 87988:tid 88191] [client 20.100.187.246:13450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/autoload_classmap.php"] [unique_id "amus-zipAwzptuCxBrhXNQAAAVM"]
[Thu Jul 30 14:58:52.324180 2026] [core:notice] [pid 89520:tid 89790] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:52.395095 2026] [security2:error] [pid 89520:tid 89719] [client 20.100.187.246:11714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/back.php"] [unique_id "amus_C0W4wRrtnDoPajy4wAAAcc"]
[Thu Jul 30 14:58:53.117487 2026] [security2:error] [pid 89520:tid 89714] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amus_C0W4wRrtnDoPajy6AAAAcI"]
[Thu Jul 30 14:58:53.508348 2026] [core:notice] [pid 89520:tid 89559] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:53.513850 2026] [security2:error] [pid 89520:tid 89771] [client 66.249.65.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/231/225"] [unique_id "amus_S0W4wRrtnDoPajy9QAB-x0"]
[Thu Jul 30 14:58:53.555147 2026] [security2:error] [pid 89520:tid 89689] [client 135.119.63.61:43344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/classsmtps.php"] [unique_id "amus_S0W4wRrtnDoPajy-QAAAak"]
[Thu Jul 30 14:58:54.563648 2026] [security2:error] [pid 89520:tid 89744] [client 20.100.187.246:42597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/bek.php"] [unique_id "amus_i0W4wRrtnDoPajzAwAAAeA"]
[Thu Jul 30 14:58:54.737288 2026] [security2:error] [pid 89520:tid 89649] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus_i0W4wRrtnDoPajzBQAB_nM"]
[Thu Jul 30 14:58:54.737433 2026] [security2:error] [pid 89520:tid 89774] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amus_i0W4wRrtnDoPajzBQAB_nM"]
[Thu Jul 30 14:58:55.116907 2026] [security2:error] [pid 89520:tid 89763] [client 135.119.63.61:57105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/classwithtostring.php"] [unique_id "amus_y0W4wRrtnDoPajzDQAAAfM"]
[Thu Jul 30 14:58:55.783989 2026] [security2:error] [pid 89520:tid 89786] [client 172.237.109.114:52619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amus_y0W4wRrtnDoPajzEAAAAgo"]
[Thu Jul 30 14:58:55.862439 2026] [security2:error] [pid 87988:tid 88205] [client 20.100.187.246:27346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amus_zipAwzptuCxBrhXYwAAAWE"]
[Thu Jul 30 14:58:56.575110 2026] [security2:error] [pid 89520:tid 89759] [client 135.119.63.61:43387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/config.php"] [unique_id "amutAC0W4wRrtnDoPajzHAAAAe8"]
[Thu Jul 30 14:58:57.200021 2026] [security2:error] [pid 89520:tid 89717] [client 20.100.187.246:13565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/c/autoload_classmap.php"] [unique_id "amutAS0W4wRrtnDoPajzJQAAAcU"]
[Thu Jul 30 14:58:57.296904 2026] [security2:error] [pid 89520:tid 89735] [client 20.100.187.246:42567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/class.api.php"] [unique_id "amutAS0W4wRrtnDoPajzJgAAAdc"]
[Thu Jul 30 14:58:57.802599 2026] [security2:error] [pid 89520:tid 89720] [client 135.119.63.61:7364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/core.php"] [unique_id "amutAS0W4wRrtnDoPajzKgAAAcg"]
[Thu Jul 30 14:58:58.377295 2026] [security2:error] [pid 87988:tid 88030] [remote 57.141.18.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amutAjipAwzptuCxBrhXhQABCyk"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon%2Clinen%2Cpolyester%2Ccotton%2Caluminum%2Cnylon%2Clycra&max_price=125&min_price=75&orderby=rating&rating=5&status=instock&filter_size=small&unfilter=1
[Thu Jul 30 14:58:58.595784 2026] [security2:error] [pid 89520:tid 89690] [client 20.100.187.246:10642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/cong.php"] [unique_id "amutAi0W4wRrtnDoPajzMgAAAao"]
[Thu Jul 30 14:58:58.751214 2026] [security2:error] [pid 89520:tid 89568] [remote 57.141.18.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amutAi0W4wRrtnDoPajzMAABsiY"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon%2Clinen%2Cpolyester%2Ccotton%2Caluminum%2Cnylon%2Clycra&max_price=125&min_price=75&orderby=rating&rating=5&status=instock&filter_size=small&unfilter=1
[Thu Jul 30 14:58:58.864502 2026] [security2:error] [pid 87988:tid 88124] [client 135.119.63.61:7365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/css.php"] [unique_id "amutAjipAwzptuCxBrhXjwAAARA"]
[Thu Jul 30 14:58:59.089598 2026] [security2:error] [pid 87988:tid 88182] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutAjipAwzptuCxBrhXhgABShU"]
[Thu Jul 30 14:58:59.377526 2026] [core:notice] [pid 87988:tid 88212] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:58:59.401772 2026] [security2:error] [pid 87988:tid 88235] [client 20.100.187.246:10763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/content.php"] [unique_id "amutAzipAwzptuCxBrhXlwAAAX8"]
[Thu Jul 30 14:59:00.433940 2026] [security2:error] [pid 89520:tid 89775] [client 20.100.187.246:10645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amutBC0W4wRrtnDoPajzQQAAAf8"]
[Thu Jul 30 14:59:00.542613 2026] [security2:error] [pid 89520:tid 89694] [client 2.136.236.152:61006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.236.136.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alqahtanifurnituremoversllc.site"] [uri "/xmlrpc.php"] [unique_id "amutBC0W4wRrtnDoPajzQAAAAa4"]
[Thu Jul 30 14:59:00.542811 2026] [security2:error] [pid 89520:tid 89694] [client 2.136.236.152:61006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alqahtanifurnituremoversllc.site"] [uri "/xmlrpc.php"] [unique_id "amutBC0W4wRrtnDoPajzQAAAAa4"]
[Thu Jul 30 14:59:01.698969 2026] [security2:error] [pid 89520:tid 89682] [client 20.100.187.246:15107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/c/flower.php"] [unique_id "amutBS0W4wRrtnDoPajzSQAAAaI"]
[Thu Jul 30 14:59:02.526067 2026] [core:notice] [pid 87988:tid 88148] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:02.877235 2026] [core:notice] [pid 87988:tid 88062] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:02.880561 2026] [security2:error] [pid 87988:tid 88228] [client 161.0.71.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/258/257"] [unique_id "amutBjipAwzptuCxBrhXxgABeEk"]
[Thu Jul 30 14:59:03.143555 2026] [core:notice] [pid 87988:tid 88226] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:03.720954 2026] [security2:error] [pid 89520:tid 89572] [remote 216.73.216.51:21568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amutBy0W4wRrtnDoPajzUgAB6So"]
[Thu Jul 30 14:59:04.040046 2026] [core:notice] [pid 87988:tid 88047] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:04.091662 2026] [security2:error] [pid 87988:tid 88140] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutBzipAwzptuCxBrhX2QAAASA"]
[Thu Jul 30 14:59:05.285737 2026] [security2:error] [pid 89520:tid 89576] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutCS0W4wRrtnDoPajzXQABqi4"]
[Thu Jul 30 14:59:05.285905 2026] [security2:error] [pid 89520:tid 89690] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutCS0W4wRrtnDoPajzXQABqi4"]
[Thu Jul 30 14:59:05.696101 2026] [core:notice] [pid 87988:tid 88172] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:05.878132 2026] [security2:error] [pid 87988:tid 88239] [client 45.148.10.120:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.koidomino.click"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "amutCTipAwzptuCxBrhYAwAAAYM"]
[Thu Jul 30 14:59:06.364295 2026] [security2:error] [pid 87988:tid 88197] [client 20.100.187.246:10814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/elp.php"] [unique_id "amutCjipAwzptuCxBrhYBwAAAVk"]
[Thu Jul 30 14:59:07.082202 2026] [security2:error] [pid 89520:tid 89697] [client 20.100.187.246:27348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amutCy0W4wRrtnDoPajzaQAAAbE"]
[Thu Jul 30 14:59:07.814557 2026] [security2:error] [pid 89520:tid 89675] [client 20.100.187.246:51265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amutCy0W4wRrtnDoPajzbQAAAZs"]
[Thu Jul 30 14:59:07.887728 2026] [security2:error] [pid 87988:tid 88183] [client 135.119.63.61:43382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/database.php"] [unique_id "amutCzipAwzptuCxBrhYJQAAAUs"]
[Thu Jul 30 14:59:09.151618 2026] [security2:error] [pid 87988:tid 88160] [client 20.100.187.246:9321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/c/xleet.php"] [unique_id "amutDTipAwzptuCxBrhYOQAAATQ"]
[Thu Jul 30 14:59:09.816413 2026] [security2:error] [pid 87988:tid 88199] [client 20.100.187.246:27343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amutDTipAwzptuCxBrhYRgAAAVs"]
[Thu Jul 30 14:59:10.139709 2026] [core:notice] [pid 89520:tid 89676] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:10.146034 2026] [security2:error] [pid 89520:tid 89580] [remote 47.128.28.117:29340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/ugg-w-classic-ultra-mini-all-black-and-velvet/"] [unique_id "amutDi0W4wRrtnDoPajzggAB7TI"]
[Thu Jul 30 14:59:10.148655 2026] [core:notice] [pid 89520:tid 89780] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:10.157879 2026] [core:notice] [pid 89520:tid 89695] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:10.160381 2026] [core:notice] [pid 87988:tid 88143] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:10.178959 2026] [core:notice] [pid 87988:tid 88164] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:10.307822 2026] [security2:error] [pid 87988:tid 88213] [client 135.119.63.61:7369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/db.php"] [unique_id "amutDjipAwzptuCxBrhYTwAAAWk"]
[Thu Jul 30 14:59:10.963941 2026] [core:notice] [pid 87988:tid 87997] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:10.964865 2026] [security2:error] [pid 87988:tid 88234] [client 175.145.217.191:41226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutDjipAwzptuCxBrhYVwAAAX4"], referer: http://pkf.jo
[Thu Jul 30 14:59:10.965482 2026] [core:notice] [pid 89520:tid 89574] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:11.019482 2026] [core:notice] [pid 89520:tid 89579] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:11.071543 2026] [core:notice] [pid 89520:tid 89771] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:11.087743 2026] [security2:error] [pid 89520:tid 89665] [client 136.53.13.145:51998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutDi0W4wRrtnDoPajziQAAAZE"], referer: http://pkf.jo
[Thu Jul 30 14:59:11.115329 2026] [core:notice] [pid 89520:tid 89584] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:11.124142 2026] [core:notice] [pid 89520:tid 89585] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:11.431961 2026] [security2:error] [pid 89520:tid 89743] [client 111.94.0.87:36051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutDy0W4wRrtnDoPajzkgAAAd8"], referer: http://pkf.jo
[Thu Jul 30 14:59:11.603417 2026] [security2:error] [pid 89520:tid 89727] [client 20.100.187.246:21201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/classwithtostring.php"] [unique_id "amutDy0W4wRrtnDoPajzkwAAAc8"]
[Thu Jul 30 14:59:11.957278 2026] [core:notice] [pid 89520:tid 89582] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:12.076652 2026] [security2:error] [pid 87988:tid 88180] [client 20.100.187.246:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amutEDipAwzptuCxBrhYcAAAAUg"]
[Thu Jul 30 14:59:12.154319 2026] [core:notice] [pid 87988:tid 88241] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:12.167711 2026] [security2:error] [pid 89520:tid 89789] [client 187.180.167.170:12463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutDy0W4wRrtnDoPajzlQAAAg0"], referer: http://pkf.jo
[Thu Jul 30 14:59:12.176450 2026] [security2:error] [pid 89520:tid 89723] [client 135.119.63.61:57140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/default.php"] [unique_id "amutEC0W4wRrtnDoPajzmgAAAcs"]
[Thu Jul 30 14:59:12.224736 2026] [security2:error] [pid 89520:tid 89754] [client 20.100.187.246:15125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/content.php"] [unique_id "amutEC0W4wRrtnDoPajzmwAAAeo"]
[Thu Jul 30 14:59:12.307135 2026] [core:notice] [pid 87988:tid 88167] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:12.321601 2026] [proxy:error] [pid 89520:tid 89586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:59:12.321649 2026] [proxy_http:error] [pid 89520:tid 89586] [remote 74.7.241.163:58968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:59:12.322260 2026] [proxy:error] [pid 89520:tid 89586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:59:12.322305 2026] [proxy_http:error] [pid 89520:tid 89586] [remote 74.7.241.163:58968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:59:12.833359 2026] [core:notice] [pid 89520:tid 89691] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:13.041591 2026] [core:notice] [pid 87988:tid 88110] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:13.163789 2026] [core:notice] [pid 87988:tid 87990] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:13.651493 2026] [security2:error] [pid 87988:tid 88147] [client 190.98.110.81:18357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutETipAwzptuCxBrhYigAAASc"], referer: http://pkf.jo
[Thu Jul 30 14:59:13.875192 2026] [security2:error] [pid 89520:tid 89587] [remote 57.141.0.18:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amutES0W4wRrtnDoPajzqQABqDk"]
[Thu Jul 30 14:59:14.021855 2026] [security2:error] [pid 89520:tid 89740] [client 135.119.63.61:7368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/dropdown.php"] [unique_id "amutEi0W4wRrtnDoPajzrAAAAdw"]
[Thu Jul 30 14:59:14.644461 2026] [security2:error] [pid 89520:tid 89707] [client 20.100.187.246:13106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/doc.php"] [unique_id "amutEi0W4wRrtnDoPajztQAAAbs"]
[Thu Jul 30 14:59:15.251196 2026] [core:notice] [pid 89520:tid 89590] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:15.331718 2026] [security2:error] [pid 89520:tid 89712] [client 135.119.63.61:7371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/edit.php"] [unique_id "amutEy0W4wRrtnDoPajzwQAAAcA"]
[Thu Jul 30 14:59:15.891891 2026] [security2:error] [pid 89520:tid 89596] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutEy0W4wRrtnDoPajzxQABw0I"]
[Thu Jul 30 14:59:15.892082 2026] [security2:error] [pid 89520:tid 89715] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutEy0W4wRrtnDoPajzxQABw0I"]
[Thu Jul 30 14:59:15.994018 2026] [core:notice] [pid 89520:tid 89593] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:16.349926 2026] [security2:error] [pid 89520:tid 89751] [client 20.100.187.246:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amutFC0W4wRrtnDoPajzygAAAec"]
[Thu Jul 30 14:59:16.695017 2026] [security2:error] [pid 89520:tid 89761] [client 135.119.63.61:43333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/f35.php"] [unique_id "amutFC0W4wRrtnDoPajzzQAAAfE"]
[Thu Jul 30 14:59:17.068692 2026] [security2:error] [pid 87988:tid 88150] [client 20.100.187.246:27342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amutFTipAwzptuCxBrhYwQAAASo"]
[Thu Jul 30 14:59:17.900549 2026] [security2:error] [pid 87988:tid 88162] [client 20.100.187.246:51284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amutFTipAwzptuCxBrhYzQAAATY"]
[Thu Jul 30 14:59:18.271140 2026] [security2:error] [pid 87988:tid 88210] [client 135.119.63.61:7360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/f7.php"] [unique_id "amutFjipAwzptuCxBrhY0AAAAWY"]
[Thu Jul 30 14:59:19.187338 2026] [core:notice] [pid 89520:tid 89769] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:19.699234 2026] [core:notice] [pid 89520:tid 89597] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:19.704374 2026] [security2:error] [pid 89520:tid 89705] [client 180.249.185.23:18877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/2708"] [unique_id "amutFy0W4wRrtnDoPajz5AABuUM"]
[Thu Jul 30 14:59:19.800236 2026] [core:notice] [pid 89520:tid 89599] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:19.956470 2026] [core:notice] [pid 89520:tid 89598] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:19.956947 2026] [core:notice] [pid 89520:tid 89603] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:19.957044 2026] [core:notice] [pid 89520:tid 89583] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:19.957197 2026] [core:notice] [pid 89520:tid 89600] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:19.958934 2026] [core:notice] [pid 89520:tid 89601] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.137352 2026] [core:notice] [pid 89520:tid 89595] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.426477 2026] [core:notice] [pid 89520:tid 89594] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.426667 2026] [core:notice] [pid 89520:tid 89605] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.426667 2026] [core:notice] [pid 89520:tid 89606] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.543316 2026] [core:notice] [pid 89520:tid 89608] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.543357 2026] [core:notice] [pid 89520:tid 89609] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.543477 2026] [core:notice] [pid 89520:tid 89607] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.649999 2026] [core:notice] [pid 89520:tid 89613] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.663763 2026] [core:notice] [pid 89520:tid 89610] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.671383 2026] [core:notice] [pid 89520:tid 89611] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.754408 2026] [core:notice] [pid 89520:tid 89612] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.760317 2026] [core:notice] [pid 89520:tid 89614] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.763299 2026] [core:notice] [pid 89520:tid 89615] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:20.848441 2026] [security2:error] [pid 89520:tid 89736] [client 20.100.187.246:20189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/dropdown.php"] [unique_id "amutGC0W4wRrtnDoPaj0CwAAAdg"]
[Thu Jul 30 14:59:20.909312 2026] [core:notice] [pid 89520:tid 89616] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.049926 2026] [core:notice] [pid 89520:tid 89617] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.088157 2026] [core:notice] [pid 89520:tid 89621] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.089396 2026] [core:notice] [pid 89520:tid 89622] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.143052 2026] [core:notice] [pid 89520:tid 89620] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.195593 2026] [core:notice] [pid 89520:tid 89625] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.202098 2026] [core:notice] [pid 89520:tid 89619] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.248214 2026] [core:notice] [pid 89520:tid 89627] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.305320 2026] [core:notice] [pid 89520:tid 89618] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.306992 2026] [core:notice] [pid 89520:tid 89623] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.741273 2026] [core:notice] [pid 89520:tid 89633] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.904222 2026] [core:notice] [pid 89520:tid 89631] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:21.913852 2026] [core:notice] [pid 89520:tid 89632] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:22.001900 2026] [core:notice] [pid 89520:tid 89636] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:22.034346 2026] [security2:error] [pid 89520:tid 89702] [client 20.100.187.246:13081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/ee.php"] [unique_id "amutGi0W4wRrtnDoPaj0LAAAAbY"]
[Thu Jul 30 14:59:22.119617 2026] [core:notice] [pid 89520:tid 89639] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:22.123691 2026] [core:notice] [pid 89520:tid 89637] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:22.124869 2026] [core:notice] [pid 89520:tid 89640] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:22.240366 2026] [core:notice] [pid 89520:tid 89643] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:22.245010 2026] [core:notice] [pid 89520:tid 89638] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:22.852760 2026] [core:notice] [pid 89520:tid 89652] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:22.983102 2026] [security2:error] [pid 87988:tid 88190] [client 20.100.187.246:9405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/flower.php"] [unique_id "amutGjipAwzptuCxBrhZFQAAAVI"]
[Thu Jul 30 14:59:23.676762 2026] [core:error] [pid 87988:tid 88081] [remote 216.73.216.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:59:23.676785 2026] [core:error] [pid 87988:tid 88081] [remote 216.73.216.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:59:23.970261 2026] [proxy:error] [pid 89520:tid 89654] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:59:23.970312 2026] [proxy_http:error] [pid 89520:tid 89654] [remote 74.7.241.137:50922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:59:23.970882 2026] [proxy:error] [pid 89520:tid 89654] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:59:23.970924 2026] [proxy_http:error] [pid 89520:tid 89654] [remote 74.7.241.137:50922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:59:24.129770 2026] [security2:error] [pid 89520:tid 89773] [client 20.100.187.246:27379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amutHC0W4wRrtnDoPaj0RwAAAf0"]
[Thu Jul 30 14:59:24.797497 2026] [security2:error] [pid 89520:tid 89659] [remote 52.167.144.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/issue/view/17"] [unique_id "amutHC0W4wRrtnDoPaj0TQABtX0"]
[Thu Jul 30 14:59:25.471383 2026] [security2:error] [pid 87988:tid 88219] [client 20.100.187.246:27287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amutHTipAwzptuCxBrhZOQAAAW8"]
[Thu Jul 30 14:59:26.463313 2026] [security2:error] [pid 87988:tid 88085] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutHjipAwzptuCxBrhZRAABNGA"]
[Thu Jul 30 14:59:26.463438 2026] [security2:error] [pid 87988:tid 88160] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutHjipAwzptuCxBrhZRAABNGA"]
[Thu Jul 30 14:59:26.758029 2026] [security2:error] [pid 89520:tid 89779] [client 20.100.187.246:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amutHi0W4wRrtnDoPaj0YwAAAgM"]
[Thu Jul 30 14:59:27.935735 2026] [security2:error] [pid 89520:tid 89533] [remote 57.141.18.2:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amutHy0W4wRrtnDoPaj0bwABuAM"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=wood,aluminum,steel,plastic,cotton&filter_size=large,extra-extra-large,extra-large&orderby=price&rating=5&tax_product_cat=suit&unfilter=1
[Thu Jul 30 14:59:28.164609 2026] [security2:error] [pid 89520:tid 89703] [client 20.100.187.246:24405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amutIC0W4wRrtnDoPaj0cgAAAbc"]
[Thu Jul 30 14:59:28.179724 2026] [security2:error] [pid 89520:tid 89532] [remote 57.141.18.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amutHy0W4wRrtnDoPaj0bgACCgI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=wood,aluminum,steel,plastic,cotton&filter_size=large,extra-extra-large,extra-large&orderby=price&rating=5&tax_product_cat=suit&unfilter=1
[Thu Jul 30 14:59:29.023091 2026] [security2:error] [pid 89520:tid 89695] [client 20.100.187.246:11085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amutIS0W4wRrtnDoPaj0fQAAAa8"]
[Thu Jul 30 14:59:29.299170 2026] [core:notice] [pid 89520:tid 89755] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:29.757611 2026] [core:error] [pid 87988:tid 88006] [remote 216.73.217.84:57184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:59:29.757634 2026] [core:error] [pid 87988:tid 88006] [remote 216.73.217.84:57184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:59:30.022244 2026] [security2:error] [pid 89520:tid 89665] [client 20.100.187.246:24382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amutIi0W4wRrtnDoPaj0hgAAAZE"]
[Thu Jul 30 14:59:30.158174 2026] [security2:error] [pid 89520:tid 89772] [client 20.203.221.142:6391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amutIi0W4wRrtnDoPaj0hwAAAfw"]
[Thu Jul 30 14:59:30.158278 2026] [security2:error] [pid 89520:tid 89772] [client 20.203.221.142:6391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amutIi0W4wRrtnDoPaj0hwAAAfw"]
[Thu Jul 30 14:59:30.249725 2026] [security2:error] [pid 87988:tid 88192] [client 185.191.171.17:57702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/04/08/brasil-bate-recorde-de-mortes-e-se-aproxima-de-marca-mundial/"] [unique_id "amutIjipAwzptuCxBrhZggAAAVQ"]
[Thu Jul 30 14:59:30.249894 2026] [security2:error] [pid 87988:tid 88192] [client 185.191.171.17:57702] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/04/08/brasil-bate-recorde-de-mortes-e-se-aproxima-de-marca-mundial/"] [unique_id "amutIjipAwzptuCxBrhZggAAAVQ"]
[Thu Jul 30 14:59:31.778674 2026] [security2:error] [pid 89520:tid 89758] [client 20.100.187.246:17527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/gecko-new.php"] [unique_id "amutIy0W4wRrtnDoPaj0lQAAAe4"]
[Thu Jul 30 14:59:31.846952 2026] [security2:error] [pid 89520:tid 89779] [client 20.203.221.142:19468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amutIy0W4wRrtnDoPaj0lgAAAgM"]
[Thu Jul 30 14:59:31.847073 2026] [security2:error] [pid 89520:tid 89779] [client 20.203.221.142:19468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amutIy0W4wRrtnDoPaj0lgAAAgM"]
[Thu Jul 30 14:59:33.017568 2026] [security2:error] [pid 89520:tid 89706] [client 20.203.221.142:5890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/images/pearl/index.php"] [unique_id "amutJS0W4wRrtnDoPaj0pAAAAbo"]
[Thu Jul 30 14:59:33.017653 2026] [security2:error] [pid 89520:tid 89706] [client 20.203.221.142:5890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/images/pearl/index.php"] [unique_id "amutJS0W4wRrtnDoPaj0pAAAAbo"]
[Thu Jul 30 14:59:33.328461 2026] [security2:error] [pid 87988:tid 88236] [client 20.100.187.246:14569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/m.php"] [unique_id "amutJTipAwzptuCxBrhZqwAAAYA"]
[Thu Jul 30 14:59:33.574514 2026] [security2:error] [pid 89520:tid 89708] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutJC0W4wRrtnDoPaj0nwABvAo"]
[Thu Jul 30 14:59:34.252398 2026] [security2:error] [pid 87988:tid 88228] [client 20.100.187.246:18684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amutJjipAwzptuCxBrhZugAAAXg"]
[Thu Jul 30 14:59:34.464194 2026] [core:notice] [pid 87988:tid 88177] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:34.657966 2026] [security2:error] [pid 89520:tid 89676] [client 20.203.221.142:22347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/bypass.php"] [unique_id "amutJi0W4wRrtnDoPaj0sAAAAZw"]
[Thu Jul 30 14:59:34.658083 2026] [security2:error] [pid 89520:tid 89676] [client 20.203.221.142:22347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/bypass.php"] [unique_id "amutJi0W4wRrtnDoPaj0sAAAAZw"]
[Thu Jul 30 14:59:34.907361 2026] [security2:error] [pid 87988:tid 88162] [client 20.100.187.246:20873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mah/flower.php"] [unique_id "amutJjipAwzptuCxBrhZxQAAATY"]
[Thu Jul 30 14:59:35.200710 2026] [security2:error] [pid 89520:tid 89531] [remote 87.250.224.102:60198] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/tag/supplychain/"] [unique_id "amutJy0W4wRrtnDoPaj0twACAAE"]
[Thu Jul 30 14:59:35.369326 2026] [security2:error] [pid 87988:tid 88182] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutJjipAwzptuCxBrhZxAAAAUo"]
[Thu Jul 30 14:59:35.505654 2026] [security2:error] [pid 87988:tid 88212] [client 20.100.187.246:14529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mah/xleet.php"] [unique_id "amutJzipAwzptuCxBrhZ0QAAAWg"]
[Thu Jul 30 14:59:35.602102 2026] [security2:error] [pid 87988:tid 88041] [remote 97.74.93.24:36800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-eea484b2.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amutJzipAwzptuCxBrhZ1gABKTQ"]
[Thu Jul 30 14:59:35.689214 2026] [core:notice] [pid 87988:tid 88055] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:36.125468 2026] [security2:error] [pid 89520:tid 89741] [client 20.203.221.142:19334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/wp-admin/about.php"] [unique_id "amutKC0W4wRrtnDoPaj0vwAAAd0"]
[Thu Jul 30 14:59:36.125577 2026] [security2:error] [pid 89520:tid 89741] [client 20.203.221.142:19334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/wp-admin/about.php"] [unique_id "amutKC0W4wRrtnDoPaj0vwAAAd0"]
[Thu Jul 30 14:59:36.724614 2026] [proxy:error] [pid 89520:tid 89683] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:59:36.724702 2026] [proxy_http:error] [pid 89520:tid 89683] [client 34.233.129.35:54113] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:59:36.725299 2026] [proxy:error] [pid 89520:tid 89683] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 14:59:36.725345 2026] [proxy_http:error] [pid 89520:tid 89683] [client 34.233.129.35:54113] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 14:59:36.928017 2026] [core:notice] [pid 87988:tid 88186] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:36.980174 2026] [security2:error] [pid 87988:tid 88079] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutKDipAwzptuCxBrhZ6AABN1o"]
[Thu Jul 30 14:59:36.980333 2026] [security2:error] [pid 87988:tid 88163] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutKDipAwzptuCxBrhZ6AABN1o"]
[Thu Jul 30 14:59:37.201265 2026] [core:notice] [pid 89520:tid 89753] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:37.245545 2026] [security2:error] [pid 89520:tid 89786] [client 20.100.187.246:10622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amutKS0W4wRrtnDoPaj0ygAAAgo"]
[Thu Jul 30 14:59:37.334402 2026] [core:error] [pid 87988:tid 88170] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:59:37.334431 2026] [core:error] [pid 87988:tid 88170] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 14:59:37.334604 2026] [security2:error] [pid 87988:tid 88170] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.baytalhuboob.com"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amutKTipAwzptuCxBrhZ7wAAAT4"]
[Thu Jul 30 14:59:37.336018 2026] [security2:error] [pid 89520:tid 89782] [client 74.7.228.63:36120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.baytalhuboob.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amutKS0W4wRrtnDoPaj0ywACBhE"]
[Thu Jul 30 14:59:37.866121 2026] [security2:error] [pid 87988:tid 88188] [client 20.203.221.142:1733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/12.php"] [unique_id "amutKTipAwzptuCxBrhZ9gAAAVA"]
[Thu Jul 30 14:59:37.866240 2026] [security2:error] [pid 87988:tid 88188] [client 20.203.221.142:1733] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/12.php"] [unique_id "amutKTipAwzptuCxBrhZ9gAAAVA"]
[Thu Jul 30 14:59:38.166544 2026] [security2:error] [pid 89520:tid 89698] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutKS0W4wRrtnDoPaj00gABsm8"]
[Thu Jul 30 14:59:38.626079 2026] [core:notice] [pid 89520:tid 89545] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:38.961713 2026] [security2:error] [pid 89520:tid 89731] [client 20.100.187.246:11092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amutKi0W4wRrtnDoPaj03AAAAdM"]
[Thu Jul 30 14:59:39.054830 2026] [security2:error] [pid 87988:tid 88216] [client 20.100.187.246:14555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/mini.php"] [unique_id "amutKzipAwzptuCxBrhaBQAAAWw"]
[Thu Jul 30 14:59:40.243436 2026] [security2:error] [pid 87988:tid 88161] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amutLDipAwzptuCxBrhaDwAAATU"]
[Thu Jul 30 14:59:40.795557 2026] [security2:error] [pid 89520:tid 89788] [client 43.173.178.203:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/02/02/h-and-m-printemps-2015/"] [unique_id "amutLC0W4wRrtnDoPaj09QAAAgw"]
[Thu Jul 30 14:59:40.955168 2026] [security2:error] [pid 89520:tid 89680] [client 20.226.5.174:13899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/custom-plugin.php"] [unique_id "amutLC0W4wRrtnDoPaj0_wAAAaA"]
[Thu Jul 30 14:59:41.470795 2026] [security2:error] [pid 87988:tid 88215] [client 20.203.221.142:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/nothing2.php"] [unique_id "amutLTipAwzptuCxBrhaJAAAAWs"]
[Thu Jul 30 14:59:41.470947 2026] [security2:error] [pid 87988:tid 88215] [client 20.203.221.142:15696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/nothing2.php"] [unique_id "amutLTipAwzptuCxBrhaJAAAAWs"]
[Thu Jul 30 14:59:41.580834 2026] [core:notice] [pid 87988:tid 88238] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:41.586817 2026] [security2:error] [pid 87988:tid 88238] [client 43.173.178.14:37678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/02/02/h-and-m-printemps-2015/"] [unique_id "amutLTipAwzptuCxBrhaJQAAAYI"], referer: https://carnetdeshopping.com/index.php/2015/02/02/h-and-m-printemps-2015/?replytocom=1430
[Thu Jul 30 14:59:41.974844 2026] [security2:error] [pid 87988:tid 88242] [client 20.226.5.174:13890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/customize.php"] [unique_id "amutLTipAwzptuCxBrhaMQAAAYY"]
[Thu Jul 30 14:59:42.063132 2026] [security2:error] [pid 89520:tid 89762] [client 136.70.80.216:51395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvape-australia.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amutLi0W4wRrtnDoPaj1DQAAAfI"]
[Thu Jul 30 14:59:42.402663 2026] [security2:error] [pid 89520:tid 89706] [client 20.203.221.142:6700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/media.php"] [unique_id "amutLi0W4wRrtnDoPaj1EgAAAbo"]
[Thu Jul 30 14:59:42.402750 2026] [security2:error] [pid 89520:tid 89706] [client 20.203.221.142:6700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/media.php"] [unique_id "amutLi0W4wRrtnDoPaj1EgAAAbo"]
[Thu Jul 30 14:59:43.029844 2026] [security2:error] [pid 89520:tid 89661] [remote 51.195.215.240:59978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "koriusa.info"] [uri "/usb-type-c-charging-fast-charging-for-on-the-go-vapers/"] [unique_id "amutLy0W4wRrtnDoPaj1GgABtH8"]
[Thu Jul 30 14:59:43.030019 2026] [security2:error] [pid 89520:tid 89700] [client 51.195.215.240:59978] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "koriusa.info"] [uri "/usb-type-c-charging-fast-charging-for-on-the-go-vapers/"] [unique_id "amutLy0W4wRrtnDoPaj1GgABtH8"]
[Thu Jul 30 14:59:43.059731 2026] [security2:error] [pid 89520:tid 89731] [client 20.226.5.174:13897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/cux.php"] [unique_id "amutLy0W4wRrtnDoPaj1GwAAAdM"]
[Thu Jul 30 14:59:43.211668 2026] [security2:error] [pid 89520:tid 89732] [client 136.70.80.216:62041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.80.70.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amutLy0W4wRrtnDoPaj1HAAAAdQ"]
[Thu Jul 30 14:59:43.368260 2026] [security2:error] [pid 89520:tid 89656] [remote 57.141.0.33:27626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5035568461/feed/rss2/"] [unique_id "amutLy0W4wRrtnDoPaj1IQAB9Xo"]
[Thu Jul 30 14:59:43.422436 2026] [security2:error] [pid 87988:tid 88244] [client 20.100.187.246:21813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/moon.php"] [unique_id "amutLzipAwzptuCxBrhaQwAAAYg"]
[Thu Jul 30 14:59:43.610624 2026] [security2:error] [pid 89520:tid 89777] [client 20.203.221.142:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/file2.php"] [unique_id "amutLy0W4wRrtnDoPaj1KAAAAgE"]
[Thu Jul 30 14:59:43.610734 2026] [security2:error] [pid 89520:tid 89777] [client 20.203.221.142:59920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/file2.php"] [unique_id "amutLy0W4wRrtnDoPaj1KAAAAgE"]
[Thu Jul 30 14:59:44.041518 2026] [security2:error] [pid 87988:tid 88125] [client 20.226.5.174:13889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/cw2013.php"] [unique_id "amutMDipAwzptuCxBrhaUQAAARE"]
[Thu Jul 30 14:59:44.089175 2026] [security2:error] [pid 87988:tid 88173] [client 110.224.124.71:58788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutLzipAwzptuCxBrhaSgAAAUE"], referer: http://pkf.jo
[Thu Jul 30 14:59:44.114117 2026] [security2:error] [pid 89520:tid 89727] [client 20.100.187.246:26474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amutMC0W4wRrtnDoPaj1LgAAAc8"]
[Thu Jul 30 14:59:44.576527 2026] [security2:error] [pid 87988:tid 88184] [client 20.100.187.246:22107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/new.php"] [unique_id "amutMDipAwzptuCxBrhaXwAAAUw"]
[Thu Jul 30 14:59:44.599578 2026] [security2:error] [pid 89520:tid 89687] [client 68.109.19.196:42400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutMC0W4wRrtnDoPaj1MAAAAac"], referer: http://pkf.jo
[Thu Jul 30 14:59:44.733167 2026] [security2:error] [pid 87988:tid 88168] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutMDipAwzptuCxBrhaVQAAATw"]
[Thu Jul 30 14:59:45.069785 2026] [security2:error] [pid 87988:tid 88235] [client 92.97.209.158:43354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutMDipAwzptuCxBrhaYAAAAX8"], referer: http://pkf.jo
[Thu Jul 30 14:59:45.071329 2026] [security2:error] [pid 87988:tid 88214] [client 20.226.5.174:13909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/cwsd.php"] [unique_id "amutMTipAwzptuCxBrhaaAAAAWo"]
[Thu Jul 30 14:59:45.577018 2026] [security2:error] [pid 89520:tid 89650] [remote 57.141.0.52:49162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amutMS0W4wRrtnDoPaj1PgAB53Q"]
[Thu Jul 30 14:59:45.653366 2026] [security2:error] [pid 87988:tid 88229] [client 20.100.187.246:28401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amutMTipAwzptuCxBrhadAAAAXk"]
[Thu Jul 30 14:59:45.893802 2026] [security2:error] [pid 89520:tid 89784] [client 20.100.187.246:19350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/radio.php"] [unique_id "amutMS0W4wRrtnDoPaj1QQAAAgg"]
[Thu Jul 30 14:59:46.079293 2026] [security2:error] [pid 89520:tid 89684] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutMS0W4wRrtnDoPaj1OwAAAaQ"]
[Thu Jul 30 14:59:46.081370 2026] [security2:error] [pid 89520:tid 89673] [client 20.226.5.174:13904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/cy.php"] [unique_id "amutMi0W4wRrtnDoPaj1RQAAAZk"]
[Thu Jul 30 14:59:46.172704 2026] [security2:error] [pid 87988:tid 88206] [client 102.39.83.17:33244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutMTipAwzptuCxBrhadwAAAWI"], referer: http://pkf.jo
[Thu Jul 30 14:59:46.659319 2026] [security2:error] [pid 89520:tid 89706] [client 143.44.144.167:17944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutMi0W4wRrtnDoPaj1SwAAAbo"], referer: http://pkf.jo
[Thu Jul 30 14:59:47.069508 2026] [security2:error] [pid 87988:tid 88147] [client 20.226.5.174:13900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/cybershell.php"] [unique_id "amutMzipAwzptuCxBrhaiQAAASc"]
[Thu Jul 30 14:59:47.434146 2026] [security2:error] [pid 89520:tid 89716] [client 20.203.221.142:19380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/simple.php"] [unique_id "amutMy0W4wRrtnDoPaj1XAAAAcQ"]
[Thu Jul 30 14:59:47.434233 2026] [security2:error] [pid 89520:tid 89716] [client 20.203.221.142:19380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/simple.php"] [unique_id "amutMy0W4wRrtnDoPaj1XAAAAcQ"]
[Thu Jul 30 14:59:47.700959 2026] [security2:error] [pid 89520:tid 89567] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutMy0W4wRrtnDoPaj1YAABnCU"]
[Thu Jul 30 14:59:47.701109 2026] [security2:error] [pid 89520:tid 89676] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutMy0W4wRrtnDoPaj1YAABnCU"]
[Thu Jul 30 14:59:47.969442 2026] [security2:error] [pid 89520:tid 89694] [client 20.100.187.246:22996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/s.php"] [unique_id "amutMy0W4wRrtnDoPaj1YgAAAa4"]
[Thu Jul 30 14:59:48.148547 2026] [security2:error] [pid 89520:tid 89780] [client 20.226.5.174:13903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/cylul.php"] [unique_id "amutNC0W4wRrtnDoPaj1ZQAAAgQ"]
[Thu Jul 30 14:59:48.165775 2026] [security2:error] [pid 87988:tid 88210] [client 20.100.187.246:27595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amutNDipAwzptuCxBrhanQAAAWY"]
[Thu Jul 30 14:59:49.064900 2026] [security2:error] [pid 89520:tid 89683] [client 136.70.80.216:56808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.80.70.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amutNS0W4wRrtnDoPaj1awAAAaM"]
[Thu Jul 30 14:59:49.065072 2026] [security2:error] [pid 89520:tid 89683] [client 136.70.80.216:56808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amutNS0W4wRrtnDoPaj1awAAAaM"]
[Thu Jul 30 14:59:49.091932 2026] [security2:error] [pid 87988:tid 88000] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prestigemassagestudio.cfd"] [uri "/app/config/local.php"] [unique_id "amutNDipAwzptuCxBrhaqQABSAs"]
[Thu Jul 30 14:59:49.128829 2026] [security2:error] [pid 89520:tid 89668] [client 20.226.5.174:13915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/d.php"] [unique_id "amutNS0W4wRrtnDoPaj1bgAAAZQ"]
[Thu Jul 30 14:59:49.387911 2026] [security2:error] [pid 87988:tid 88235] [client 20.100.187.246:19759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/sim.php"] [unique_id "amutNTipAwzptuCxBrharwAAAX8"]
[Thu Jul 30 14:59:49.467148 2026] [security2:error] [pid 87988:tid 88015] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prestigemassagestudio.cfd"] [uri "/app/config/local.php.bak"] [unique_id "amutNTipAwzptuCxBrhasAABOxo"]
[Thu Jul 30 14:59:49.826298 2026] [security2:error] [pid 87988:tid 88201] [client 20.100.187.246:42277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amutNTipAwzptuCxBrhatwAAAV0"]
[Thu Jul 30 14:59:49.930769 2026] [security2:error] [pid 87988:tid 88013] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prestigemassagestudio.cfd"] [uri "/mautic/app/config/local.php"] [unique_id "amutNTipAwzptuCxBrhauAABThg"]
[Thu Jul 30 14:59:50.112123 2026] [security2:error] [pid 89520:tid 89784] [client 20.226.5.174:13893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/d0main.php"] [unique_id "amutNi0W4wRrtnDoPaj1dwAAAgg"]
[Thu Jul 30 14:59:50.254744 2026] [security2:error] [pid 87988:tid 88202] [client 20.100.187.246:19768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/text.php"] [unique_id "amutNjipAwzptuCxBrhavgAAAV4"]
[Thu Jul 30 14:59:50.315720 2026] [security2:error] [pid 87988:tid 88025] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prestigemassagestudio.cfd"] [uri "/config/mail.php"] [unique_id "amutNjipAwzptuCxBrhavwABPiQ"]
[Thu Jul 30 14:59:50.540615 2026] [security2:error] [pid 89520:tid 89697] [client 20.203.221.142:44539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/mac.php"] [unique_id "amutNi0W4wRrtnDoPaj1fAAAAbE"]
[Thu Jul 30 14:59:50.540729 2026] [security2:error] [pid 89520:tid 89697] [client 20.203.221.142:44539] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/mac.php"] [unique_id "amutNi0W4wRrtnDoPaj1fAAAAbE"]
[Thu Jul 30 14:59:50.666080 2026] [security2:error] [pid 87988:tid 88035] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prestigemassagestudio.cfd"] [uri "/config/services.php"] [unique_id "amutNjipAwzptuCxBrhawQABZS4"]
[Thu Jul 30 14:59:51.144307 2026] [security2:error] [pid 89520:tid 89695] [client 20.226.5.174:13911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/d4.php"] [unique_id "amutNy0W4wRrtnDoPaj1ggAAAa8"]
[Thu Jul 30 14:59:51.520420 2026] [security2:error] [pid 89520:tid 89688] [client 20.100.187.246:21608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/user.php"] [unique_id "amutNy0W4wRrtnDoPaj1hgAAAag"]
[Thu Jul 30 14:59:51.768697 2026] [security2:error] [pid 89520:tid 89769] [client 20.100.187.246:26439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amutNy0W4wRrtnDoPaj1iAAAAfk"]
[Thu Jul 30 14:59:51.963497 2026] [security2:error] [pid 89520:tid 89752] [client 20.203.148.31:18877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/--wp-lgj.php"] [unique_id "amutNy0W4wRrtnDoPaj1jQAAAeg"]
[Thu Jul 30 14:59:52.097480 2026] [security2:error] [pid 87988:tid 88171] [client 20.226.5.174:13916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/d65ve.php"] [unique_id "amutODipAwzptuCxBrha1wAAAT8"]
[Thu Jul 30 14:59:52.585805 2026] [security2:error] [pid 87988:tid 88139] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutNzipAwzptuCxBrha1gABHzU"]
[Thu Jul 30 14:59:52.605088 2026] [security2:error] [pid 87988:tid 88055] [remote 57.141.0.54:57940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amutODipAwzptuCxBrha4AABdkI"]
[Thu Jul 30 14:59:52.968016 2026] [security2:error] [pid 87988:tid 88162] [client 20.100.187.246:24756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amutODipAwzptuCxBrha6AAAATY"]
[Thu Jul 30 14:59:53.036179 2026] [security2:error] [pid 89520:tid 89708] [client 20.226.5.174:13902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/d7.php"] [unique_id "amutOS0W4wRrtnDoPaj1kwAAAbw"]
[Thu Jul 30 14:59:53.341738 2026] [core:notice] [pid 89520:tid 89734] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:53.345671 2026] [security2:error] [pid 89520:tid 89734] [client 66.249.79.230:41216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3828/1869"] [unique_id "amutOS0W4wRrtnDoPaj1lAAAAdY"]
[Thu Jul 30 14:59:53.386238 2026] [security2:error] [pid 89520:tid 89701] [client 20.203.221.142:9296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/install.php"] [unique_id "amutOS0W4wRrtnDoPaj1lwAAAbU"]
[Thu Jul 30 14:59:53.386324 2026] [security2:error] [pid 89520:tid 89701] [client 20.203.221.142:9296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/install.php"] [unique_id "amutOS0W4wRrtnDoPaj1lwAAAbU"]
[Thu Jul 30 14:59:53.790502 2026] [core:notice] [pid 89520:tid 89778] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 14:59:54.088352 2026] [security2:error] [pid 89520:tid 89665] [client 20.226.5.174:13924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/dashboardadmin.php"] [unique_id "amutOi0W4wRrtnDoPaj1ngAAAZE"]
[Thu Jul 30 14:59:54.408047 2026] [security2:error] [pid 89520:tid 89790] [client 20.203.221.142:36523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/wsx.php"] [unique_id "amutOi0W4wRrtnDoPaj1oAAAAg4"]
[Thu Jul 30 14:59:54.408154 2026] [security2:error] [pid 89520:tid 89790] [client 20.203.221.142:36523] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/wsx.php"] [unique_id "amutOi0W4wRrtnDoPaj1oAAAAg4"]
[Thu Jul 30 14:59:54.975923 2026] [security2:error] [pid 89520:tid 89733] [client 20.100.187.246:27232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amutOi0W4wRrtnDoPaj1pQAAAdU"]
[Thu Jul 30 14:59:55.055654 2026] [security2:error] [pid 89520:tid 89723] [client 20.226.5.174:13920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/dashboardalfa.php"] [unique_id "amutOy0W4wRrtnDoPaj1qQAAAcs"]
[Thu Jul 30 14:59:55.419329 2026] [security2:error] [pid 89520:tid 89565] [remote 104.210.56.224:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.56.210.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/7"] [unique_id "amutOy0W4wRrtnDoPaj1rAABrSM"]
[Thu Jul 30 14:59:55.722252 2026] [security2:error] [pid 87988:tid 88243] [client 43.173.176.228:54230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amutOzipAwzptuCxBrhbBAAAAYc"]
[Thu Jul 30 14:59:55.786479 2026] [security2:error] [pid 89520:tid 89568] [remote 57.141.0.22:33828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amutOy0W4wRrtnDoPaj1sAABwSY"]
[Thu Jul 30 14:59:55.887023 2026] [security2:error] [pid 87988:tid 88163] [client 20.203.221.142:29653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/alfa.php"] [unique_id "amutOzipAwzptuCxBrhbCgAAATc"]
[Thu Jul 30 14:59:55.887142 2026] [security2:error] [pid 87988:tid 88163] [client 20.203.221.142:29653] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/alfa.php"] [unique_id "amutOzipAwzptuCxBrhbCgAAATc"]
[Thu Jul 30 14:59:55.895040 2026] [security2:error] [pid 89520:tid 89692] [client 20.100.187.246:27587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amutOy0W4wRrtnDoPaj1sQAAAaw"]
[Thu Jul 30 14:59:56.107966 2026] [security2:error] [pid 89520:tid 89763] [client 20.226.5.174:13888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/dashboardbypass.php"] [unique_id "amutPC0W4wRrtnDoPaj1tQAAAfM"]
[Thu Jul 30 14:59:56.394266 2026] [security2:error] [pid 87988:tid 88186] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutOzipAwzptuCxBrhbCQABTls"]
[Thu Jul 30 14:59:56.660228 2026] [security2:error] [pid 87988:tid 88175] [client 20.100.187.246:27206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amutPDipAwzptuCxBrhbGgAAAUM"]
[Thu Jul 30 14:59:56.802380 2026] [security2:error] [pid 89520:tid 89789] [client 20.100.187.246:19021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/webadmin.php"] [unique_id "amutPC0W4wRrtnDoPaj1vAAAAg0"]
[Thu Jul 30 14:59:56.876746 2026] [security2:error] [pid 89520:tid 89764] [client 20.203.221.142:55574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/dlu.php"] [unique_id "amutPC0W4wRrtnDoPaj1vQAAAfQ"]
[Thu Jul 30 14:59:56.876874 2026] [security2:error] [pid 89520:tid 89764] [client 20.203.221.142:55574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/dlu.php"] [unique_id "amutPC0W4wRrtnDoPaj1vQAAAfQ"]
[Thu Jul 30 14:59:56.925053 2026] [security2:error] [pid 89520:tid 89695] [client 20.203.148.31:21121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amutPC0W4wRrtnDoPaj1vgAAAa8"]
[Thu Jul 30 14:59:57.170053 2026] [security2:error] [pid 89520:tid 89775] [client 20.226.5.174:13922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/dashboardk.php"] [unique_id "amutPS0W4wRrtnDoPaj1wQAAAf8"]
[Thu Jul 30 14:59:57.848296 2026] [security2:error] [pid 89520:tid 89666] [client 20.203.221.142:44509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/f6.php"] [unique_id "amutPS0W4wRrtnDoPaj1xgAAAZI"]
[Thu Jul 30 14:59:57.848447 2026] [security2:error] [pid 89520:tid 89666] [client 20.203.221.142:44509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/f6.php"] [unique_id "amutPS0W4wRrtnDoPaj1xgAAAZI"]
[Thu Jul 30 14:59:58.176830 2026] [security2:error] [pid 87988:tid 88226] [client 20.226.5.174:13908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/dashboardwp.php"] [unique_id "amutPjipAwzptuCxBrhbLgAAAXY"]
[Thu Jul 30 14:59:58.197886 2026] [security2:error] [pid 89520:tid 89573] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutPi0W4wRrtnDoPaj1ywAB3Cs"]
[Thu Jul 30 14:59:58.198048 2026] [security2:error] [pid 89520:tid 89740] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutPi0W4wRrtnDoPaj1ywAB3Cs"]
[Thu Jul 30 14:59:58.226792 2026] [security2:error] [pid 87988:tid 88234] [client 20.100.187.246:24717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amutPjipAwzptuCxBrhbLwAAAX4"]
[Thu Jul 30 14:59:59.006585 2026] [security2:error] [pid 89520:tid 89772] [client 20.203.221.142:55589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/0x.php"] [unique_id "amutPy0W4wRrtnDoPaj11gAAAfw"]
[Thu Jul 30 14:59:59.006702 2026] [security2:error] [pid 89520:tid 89772] [client 20.203.221.142:55589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/0x.php"] [unique_id "amutPy0W4wRrtnDoPaj11gAAAfw"]
[Thu Jul 30 14:59:59.240357 2026] [security2:error] [pid 87988:tid 88179] [client 20.226.5.174:13894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/data.php"] [unique_id "amutPzipAwzptuCxBrhbOwAAAUc"]
[Thu Jul 30 14:59:59.681637 2026] [security2:error] [pid 89520:tid 89677] [client 20.100.187.246:18208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amutPy0W4wRrtnDoPaj12wAAAZ0"]
[Thu Jul 30 15:00:00.042313 2026] [security2:error] [pid 89520:tid 89571] [remote 57.141.0.27:64588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amutQC0W4wRrtnDoPaj13QAB9ik"]
[Thu Jul 30 15:00:00.269820 2026] [security2:error] [pid 89520:tid 89668] [client 20.226.5.174:13910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/data532.php"] [unique_id "amutQC0W4wRrtnDoPaj14gAAAZQ"]
[Thu Jul 30 15:00:00.526384 2026] [security2:error] [pid 89520:tid 89688] [client 20.203.148.31:26137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/flower.php"] [unique_id "amutQC0W4wRrtnDoPaj15AAAAag"]
[Thu Jul 30 15:00:00.667272 2026] [security2:error] [pid 87988:tid 88163] [client 20.203.221.142:29687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/geck.php"] [unique_id "amutQDipAwzptuCxBrhbTQAAATc"]
[Thu Jul 30 15:00:00.667380 2026] [security2:error] [pid 87988:tid 88163] [client 20.203.221.142:29687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/geck.php"] [unique_id "amutQDipAwzptuCxBrhbTQAAATc"]
[Thu Jul 30 15:00:00.905310 2026] [core:notice] [pid 89520:tid 89577] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:01.115622 2026] [security2:error] [pid 89520:tid 89784] [client 20.100.187.246:22112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amutQS0W4wRrtnDoPaj16wAAAgg"]
[Thu Jul 30 15:00:01.324608 2026] [security2:error] [pid 89520:tid 89713] [client 20.226.5.174:13925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/database.php"] [unique_id "amutQS0W4wRrtnDoPaj18QAAAcE"]
[Thu Jul 30 15:00:01.656460 2026] [security2:error] [pid 89520:tid 89692] [client 20.203.148.31:36247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/xleet.php"] [unique_id "amutQS0W4wRrtnDoPaj19wAAAaw"]
[Thu Jul 30 15:00:01.675701 2026] [security2:error] [pid 89520:tid 89690] [client 74.7.244.3:47708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lvp.hfl.temporary.site"] [uri "/index.php"] [unique_id "amutQC0W4wRrtnDoPaj14QABqio"]
[Thu Jul 30 15:00:02.025454 2026] [security2:error] [pid 89520:tid 89700] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amutQi0W4wRrtnDoPaj1_QAAAbQ"]
[Thu Jul 30 15:00:02.025602 2026] [security2:error] [pid 89520:tid 89700] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amutQi0W4wRrtnDoPaj1_QAAAbQ"]
[Thu Jul 30 15:00:02.335725 2026] [security2:error] [pid 89520:tid 89705] [client 20.226.5.174:13892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/date.php"] [unique_id "amutQi0W4wRrtnDoPaj2AQAAAbk"]
[Thu Jul 30 15:00:02.352401 2026] [security2:error] [pid 89520:tid 89759] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amutQi0W4wRrtnDoPaj2AgAAAe8"]
[Thu Jul 30 15:00:02.352551 2026] [security2:error] [pid 89520:tid 89759] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amutQi0W4wRrtnDoPaj2AgAAAe8"]
[Thu Jul 30 15:00:02.665939 2026] [security2:error] [pid 89520:tid 89716] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/x.php"] [unique_id "amutQi0W4wRrtnDoPaj2BQAAAcQ"]
[Thu Jul 30 15:00:02.666150 2026] [security2:error] [pid 89520:tid 89716] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/x.php"] [unique_id "amutQi0W4wRrtnDoPaj2BQAAAcQ"]
[Thu Jul 30 15:00:02.964667 2026] [security2:error] [pid 89520:tid 89760] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/mgrr.php"] [unique_id "amutQi0W4wRrtnDoPaj2DAAAAfA"]
[Thu Jul 30 15:00:02.964752 2026] [security2:error] [pid 89520:tid 89760] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/mgrr.php"] [unique_id "amutQi0W4wRrtnDoPaj2DAAAAfA"]
[Thu Jul 30 15:00:03.072637 2026] [security2:error] [pid 89520:tid 89707] [client 20.100.187.246:43509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amutQy0W4wRrtnDoPaj2DQAAAbs"]
[Thu Jul 30 15:00:03.269125 2026] [security2:error] [pid 89520:tid 89689] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/domvf.php"] [unique_id "amutQy0W4wRrtnDoPaj2DgAAAak"]
[Thu Jul 30 15:00:03.269238 2026] [security2:error] [pid 89520:tid 89689] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/domvf.php"] [unique_id "amutQy0W4wRrtnDoPaj2DgAAAak"]
[Thu Jul 30 15:00:03.337240 2026] [security2:error] [pid 89520:tid 89727] [client 20.203.221.142:6773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/8.php"] [unique_id "amutQy0W4wRrtnDoPaj2EAAAAc8"]
[Thu Jul 30 15:00:03.337367 2026] [security2:error] [pid 89520:tid 89727] [client 20.203.221.142:6773] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/8.php"] [unique_id "amutQy0W4wRrtnDoPaj2EAAAAc8"]
[Thu Jul 30 15:00:03.408262 2026] [security2:error] [pid 89520:tid 89581] [remote 216.73.216.51:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amutQy0W4wRrtnDoPaj2EQAB2DM"]
[Thu Jul 30 15:00:03.411345 2026] [security2:error] [pid 87988:tid 88164] [client 20.226.5.174:13926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/dav.php"] [unique_id "amutQzipAwzptuCxBrhbbQAAATg"]
[Thu Jul 30 15:00:03.586921 2026] [security2:error] [pid 87988:tid 88221] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/yup.php"] [unique_id "amutQzipAwzptuCxBrhbcQAAAXE"]
[Thu Jul 30 15:00:03.587037 2026] [security2:error] [pid 87988:tid 88221] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/yup.php"] [unique_id "amutQzipAwzptuCxBrhbcQAAAXE"]
[Thu Jul 30 15:00:03.870287 2026] [security2:error] [pid 87988:tid 88112] [remote 57.141.0.37:36622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amutQzipAwzptuCxBrhbcgABQXs"]
[Thu Jul 30 15:00:03.891523 2026] [security2:error] [pid 87988:tid 88144] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/X.php"] [unique_id "amutQzipAwzptuCxBrhbcwAAASQ"]
[Thu Jul 30 15:00:03.891619 2026] [security2:error] [pid 87988:tid 88144] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/X.php"] [unique_id "amutQzipAwzptuCxBrhbcwAAASQ"]
[Thu Jul 30 15:00:04.064474 2026] [security2:error] [pid 87988:tid 88127] [client 20.100.187.246:12307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amutRDipAwzptuCxBrhbegAAARM"]
[Thu Jul 30 15:00:04.078843 2026] [core:notice] [pid 87988:tid 88108] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:04.206659 2026] [security2:error] [pid 87988:tid 88159] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amutRDipAwzptuCxBrhbfAAAATM"]
[Thu Jul 30 15:00:04.206753 2026] [security2:error] [pid 87988:tid 88159] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amutRDipAwzptuCxBrhbfAAAATM"]
[Thu Jul 30 15:00:04.422767 2026] [security2:error] [pid 87988:tid 88168] [client 20.226.5.174:13937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/db-cache.php"] [unique_id "amutRDipAwzptuCxBrhbgAAAATw"]
[Thu Jul 30 15:00:04.534435 2026] [security2:error] [pid 89520:tid 89782] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/gec.php"] [unique_id "amutRC0W4wRrtnDoPaj2IQAAAgY"]
[Thu Jul 30 15:00:04.534544 2026] [security2:error] [pid 89520:tid 89782] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/gec.php"] [unique_id "amutRC0W4wRrtnDoPaj2IQAAAgY"]
[Thu Jul 30 15:00:04.864127 2026] [security2:error] [pid 89520:tid 89726] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/sky.php"] [unique_id "amutRC0W4wRrtnDoPaj2IgAAAc4"]
[Thu Jul 30 15:00:04.864246 2026] [security2:error] [pid 89520:tid 89726] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/sky.php"] [unique_id "amutRC0W4wRrtnDoPaj2IgAAAc4"]
[Thu Jul 30 15:00:04.886212 2026] [security2:error] [pid 89520:tid 89674] [client 20.100.187.246:11468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amutRC0W4wRrtnDoPaj2IwAAAZo"]
[Thu Jul 30 15:00:05.021771 2026] [security2:error] [pid 89520:tid 89668] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutRC0W4wRrtnDoPaj2HAAAAZQ"]
[Thu Jul 30 15:00:05.176998 2026] [security2:error] [pid 87988:tid 88169] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/fffm.php"] [unique_id "amutRTipAwzptuCxBrhbiwAAAT0"]
[Thu Jul 30 15:00:05.177102 2026] [security2:error] [pid 87988:tid 88169] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/fffm.php"] [unique_id "amutRTipAwzptuCxBrhbiwAAAT0"]
[Thu Jul 30 15:00:05.277067 2026] [core:error] [pid 89520:tid 89730] [client 74.7.241.151:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:05.277091 2026] [core:error] [pid 89520:tid 89730] [client 74.7.241.151:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:05.277233 2026] [security2:error] [pid 89520:tid 89730] [client 74.7.241.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.portugalvisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amutRS0W4wRrtnDoPaj2KgAAAdI"]
[Thu Jul 30 15:00:05.277854 2026] [security2:error] [pid 89520:tid 89718] [client 74.7.241.151:40542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.portugalvisaapplicationcenterinislamabad.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amutRS0W4wRrtnDoPaj2KAABxjc"]
[Thu Jul 30 15:00:05.481671 2026] [security2:error] [pid 87988:tid 88121] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/sixxis.php"] [unique_id "amutRTipAwzptuCxBrhbjgAAAQ0"]
[Thu Jul 30 15:00:05.481769 2026] [security2:error] [pid 87988:tid 88121] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/sixxis.php"] [unique_id "amutRTipAwzptuCxBrhbjgAAAQ0"]
[Thu Jul 30 15:00:05.497931 2026] [security2:error] [pid 87988:tid 88126] [client 20.226.5.174:13907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/db-safe-mode.php"] [unique_id "amutRTipAwzptuCxBrhbjwAAARI"]
[Thu Jul 30 15:00:05.784746 2026] [security2:error] [pid 87988:tid 88145] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/yj09.php"] [unique_id "amutRTipAwzptuCxBrhblQAAASU"]
[Thu Jul 30 15:00:05.784852 2026] [security2:error] [pid 87988:tid 88145] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/yj09.php"] [unique_id "amutRTipAwzptuCxBrhblQAAASU"]
[Thu Jul 30 15:00:06.076672 2026] [security2:error] [pid 89520:tid 89747] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/k.php"] [unique_id "amutRi0W4wRrtnDoPaj2LgAAAeM"]
[Thu Jul 30 15:00:06.076809 2026] [security2:error] [pid 89520:tid 89747] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/k.php"] [unique_id "amutRi0W4wRrtnDoPaj2LgAAAeM"]
[Thu Jul 30 15:00:06.148690 2026] [security2:error] [pid 87988:tid 88199] [client 20.100.187.246:22106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amutRjipAwzptuCxBrhbnQAAAVs"]
[Thu Jul 30 15:00:06.375139 2026] [security2:error] [pid 89520:tid 89690] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/k2.php"] [unique_id "amutRi0W4wRrtnDoPaj2MAAAAao"]
[Thu Jul 30 15:00:06.375261 2026] [security2:error] [pid 89520:tid 89690] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/k2.php"] [unique_id "amutRi0W4wRrtnDoPaj2MAAAAao"]
[Thu Jul 30 15:00:06.571888 2026] [security2:error] [pid 89520:tid 89692] [client 20.226.5.174:13932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/db-update.php"] [unique_id "amutRi0W4wRrtnDoPaj2MwAAAaw"]
[Thu Jul 30 15:00:06.666493 2026] [security2:error] [pid 87988:tid 88138] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/w.php"] [unique_id "amutRjipAwzptuCxBrhbpwAAAR4"]
[Thu Jul 30 15:00:06.666603 2026] [security2:error] [pid 87988:tid 88138] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/w.php"] [unique_id "amutRjipAwzptuCxBrhbpwAAAR4"]
[Thu Jul 30 15:00:06.826091 2026] [security2:error] [pid 87988:tid 88176] [client 20.203.148.31:18839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amutRjipAwzptuCxBrhbqAAAAUQ"]
[Thu Jul 30 15:00:06.992177 2026] [security2:error] [pid 87988:tid 88239] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/fpwch.php"] [unique_id "amutRjipAwzptuCxBrhbqQAAAYM"]
[Thu Jul 30 15:00:06.992296 2026] [security2:error] [pid 87988:tid 88239] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/fpwch.php"] [unique_id "amutRjipAwzptuCxBrhbqQAAAYM"]
[Thu Jul 30 15:00:06.997586 2026] [core:notice] [pid 87988:tid 88181] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:07.000993 2026] [security2:error] [pid 87988:tid 88181] [client 66.249.79.230:52901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/view/656"] [unique_id "amutRjipAwzptuCxBrhbqgAAAUk"]
[Thu Jul 30 15:00:07.318617 2026] [security2:error] [pid 89520:tid 89679] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/w2025.php"] [unique_id "amutRy0W4wRrtnDoPaj2NwAAAZ8"]
[Thu Jul 30 15:00:07.318740 2026] [security2:error] [pid 89520:tid 89679] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/w2025.php"] [unique_id "amutRy0W4wRrtnDoPaj2NwAAAZ8"]
[Thu Jul 30 15:00:07.608648 2026] [security2:error] [pid 87988:tid 88139] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/FWAZ.php"] [unique_id "amutRzipAwzptuCxBrhbtAAAAR8"]
[Thu Jul 30 15:00:07.608767 2026] [security2:error] [pid 87988:tid 88139] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/FWAZ.php"] [unique_id "amutRzipAwzptuCxBrhbtAAAAR8"]
[Thu Jul 30 15:00:07.615825 2026] [security2:error] [pid 87988:tid 88216] [client 20.226.5.174:13946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/db.php"] [unique_id "amutRzipAwzptuCxBrhbtQAAAWw"]
[Thu Jul 30 15:00:07.810331 2026] [security2:error] [pid 89520:tid 89676] [client 20.100.187.246:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amutRy0W4wRrtnDoPaj2OwAAAZw"]
[Thu Jul 30 15:00:07.885844 2026] [security2:error] [pid 87988:tid 88133] [client 185.191.171.1:22978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/13/prefeitos-de-junco-do-serido-nazarezinho-vista-serrana-e-passagem-declaram-apoio-a-joao-no-2o-turno/"] [unique_id "amutRzipAwzptuCxBrhbuwAAARk"]
[Thu Jul 30 15:00:07.885997 2026] [security2:error] [pid 87988:tid 88133] [client 185.191.171.1:22978] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/13/prefeitos-de-junco-do-serido-nazarezinho-vista-serrana-e-passagem-declaram-apoio-a-joao-no-2o-turno/"] [unique_id "amutRzipAwzptuCxBrhbuwAAARk"]
[Thu Jul 30 15:00:07.906146 2026] [security2:error] [pid 89520:tid 89719] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/qterm.php"] [unique_id "amutRy0W4wRrtnDoPaj2PAAAAcc"]
[Thu Jul 30 15:00:07.906233 2026] [security2:error] [pid 89520:tid 89719] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/qterm.php"] [unique_id "amutRy0W4wRrtnDoPaj2PAAAAcc"]
[Thu Jul 30 15:00:08.199410 2026] [security2:error] [pid 89520:tid 89734] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/blurbs.php"] [unique_id "amutSC0W4wRrtnDoPaj2QAAAAdY"]
[Thu Jul 30 15:00:08.199539 2026] [security2:error] [pid 89520:tid 89734] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/blurbs.php"] [unique_id "amutSC0W4wRrtnDoPaj2QAAAAdY"]
[Thu Jul 30 15:00:08.347017 2026] [security2:error] [pid 89520:tid 89732] [client 20.100.187.246:19369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amutSC0W4wRrtnDoPaj2QwAAAdQ"]
[Thu Jul 30 15:00:08.504185 2026] [security2:error] [pid 89520:tid 89760] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-ws68.php"] [unique_id "amutSC0W4wRrtnDoPaj2RAAAAfA"]
[Thu Jul 30 15:00:08.504327 2026] [security2:error] [pid 89520:tid 89760] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-ws68.php"] [unique_id "amutSC0W4wRrtnDoPaj2RAAAAfA"]
[Thu Jul 30 15:00:08.634156 2026] [security2:error] [pid 89520:tid 89669] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutSC0W4wRrtnDoPaj2PgAAAZU"]
[Thu Jul 30 15:00:08.744462 2026] [security2:error] [pid 89520:tid 89686] [client 20.100.187.246:26501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amutSC0W4wRrtnDoPaj2RwAAAaY"]
[Thu Jul 30 15:00:08.789094 2026] [security2:error] [pid 87988:tid 88025] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutSDipAwzptuCxBrhbzAABMiQ"]
[Thu Jul 30 15:00:08.789240 2026] [security2:error] [pid 87988:tid 88158] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutSDipAwzptuCxBrhbzAABMiQ"]
[Thu Jul 30 15:00:08.793392 2026] [security2:error] [pid 89520:tid 89715] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/xyn.php"] [unique_id "amutSC0W4wRrtnDoPaj2SQAAAcM"]
[Thu Jul 30 15:00:08.793492 2026] [security2:error] [pid 89520:tid 89715] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/xyn.php"] [unique_id "amutSC0W4wRrtnDoPaj2SQAAAcM"]
[Thu Jul 30 15:00:08.829754 2026] [security2:error] [pid 89520:tid 89783] [client 20.226.5.174:13905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/db/mar.php"] [unique_id "amutSC0W4wRrtnDoPaj2SgAAAgc"]
[Thu Jul 30 15:00:09.095611 2026] [security2:error] [pid 89520:tid 89738] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/ccc.php"] [unique_id "amutSS0W4wRrtnDoPaj2TgAAAdo"]
[Thu Jul 30 15:00:09.095728 2026] [security2:error] [pid 89520:tid 89738] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/ccc.php"] [unique_id "amutSS0W4wRrtnDoPaj2TgAAAdo"]
[Thu Jul 30 15:00:09.131733 2026] [security2:error] [pid 89520:tid 89788] [client 47.128.121.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amutSC0W4wRrtnDoPaj2TQAAAgw"]
[Thu Jul 30 15:00:09.385315 2026] [security2:error] [pid 89520:tid 89782] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/get.php"] [unique_id "amutSS0W4wRrtnDoPaj2UwAAAgY"]
[Thu Jul 30 15:00:09.385418 2026] [security2:error] [pid 89520:tid 89782] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/get.php"] [unique_id "amutSS0W4wRrtnDoPaj2UwAAAgY"]
[Thu Jul 30 15:00:09.520459 2026] [core:notice] [pid 89520:tid 89586] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:09.719705 2026] [security2:error] [pid 87988:tid 88201] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/images.php"] [unique_id "amutSTipAwzptuCxBrhb1wAAAV0"]
[Thu Jul 30 15:00:09.719854 2026] [security2:error] [pid 87988:tid 88201] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/images.php"] [unique_id "amutSTipAwzptuCxBrhb1wAAAV0"]
[Thu Jul 30 15:00:09.819520 2026] [security2:error] [pid 89520:tid 89766] [client 20.100.187.246:24706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amutSS0W4wRrtnDoPaj2XgAAAfY"]
[Thu Jul 30 15:00:09.999688 2026] [security2:error] [pid 89520:tid 89684] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutSS0W4wRrtnDoPaj2WwAAAaQ"]
[Thu Jul 30 15:00:10.022622 2026] [security2:error] [pid 87988:tid 88202] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/alls.php"] [unique_id "amutSjipAwzptuCxBrhb3QAAAV4"]
[Thu Jul 30 15:00:10.022721 2026] [security2:error] [pid 87988:tid 88202] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/alls.php"] [unique_id "amutSjipAwzptuCxBrhb3QAAAV4"]
[Thu Jul 30 15:00:10.062760 2026] [security2:error] [pid 89520:tid 89589] [remote 57.141.0.46:62678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amutSi0W4wRrtnDoPaj2XwABxjs"]
[Thu Jul 30 15:00:10.153447 2026] [security2:error] [pid 89520:tid 89668] [client 20.226.5.174:13934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/db/uploader.php"] [unique_id "amutSi0W4wRrtnDoPaj2YAAAAZQ"]
[Thu Jul 30 15:00:10.319210 2026] [security2:error] [pid 87988:tid 88224] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/coffexium.php"] [unique_id "amutSjipAwzptuCxBrhb4wAAAXQ"]
[Thu Jul 30 15:00:10.319303 2026] [security2:error] [pid 87988:tid 88224] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/coffexium.php"] [unique_id "amutSjipAwzptuCxBrhb4wAAAXQ"]
[Thu Jul 30 15:00:10.630291 2026] [security2:error] [pid 87988:tid 88231] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/red.php"] [unique_id "amutSjipAwzptuCxBrhb5gAAAXs"]
[Thu Jul 30 15:00:10.630431 2026] [security2:error] [pid 87988:tid 88231] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/red.php"] [unique_id "amutSjipAwzptuCxBrhb5gAAAXs"]
[Thu Jul 30 15:00:10.969358 2026] [security2:error] [pid 87988:tid 88188] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/sodium_compat/"] [unique_id "amutSjipAwzptuCxBrhb7QAAAVA"]
[Thu Jul 30 15:00:11.045287 2026] [core:notice] [pid 89520:tid 89590] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:11.096329 2026] [security2:error] [pid 89520:tid 89711] [client 20.100.187.246:25749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amutSy0W4wRrtnDoPaj2bQAAAb8"]
[Thu Jul 30 15:00:11.163688 2026] [security2:error] [pid 87988:tid 88147] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amutSzipAwzptuCxBrhb7gAAASc"]
[Thu Jul 30 15:00:11.163820 2026] [security2:error] [pid 87988:tid 88147] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amutSzipAwzptuCxBrhb7gAAASc"]
[Thu Jul 30 15:00:11.252522 2026] [security2:error] [pid 89520:tid 89729] [client 20.226.5.174:13901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/db_model.php"] [unique_id "amutSy0W4wRrtnDoPaj2cAAAAdE"]
[Thu Jul 30 15:00:11.466266 2026] [security2:error] [pid 87988:tid 88146] [client 20.203.221.142:5923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/133.php"] [unique_id "amutSzipAwzptuCxBrhb8wAAASY"]
[Thu Jul 30 15:00:11.466362 2026] [security2:error] [pid 87988:tid 88146] [client 20.203.221.142:5923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/133.php"] [unique_id "amutSzipAwzptuCxBrhb8wAAASY"]
[Thu Jul 30 15:00:11.490363 2026] [security2:error] [pid 89520:tid 89740] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/Text/"] [unique_id "amutSy0W4wRrtnDoPaj2dAAAAdw"]
[Thu Jul 30 15:00:11.674180 2026] [security2:error] [pid 89520:tid 89765] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-content/uploads/"] [unique_id "amutSy0W4wRrtnDoPaj2dQAAAfU"]
[Thu Jul 30 15:00:11.872717 2026] [security2:error] [pid 89520:tid 89712] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/index.php"] [unique_id "amutSy0W4wRrtnDoPaj2egAAAcA"]
[Thu Jul 30 15:00:11.872824 2026] [security2:error] [pid 89520:tid 89712] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/index.php"] [unique_id "amutSy0W4wRrtnDoPaj2egAAAcA"]
[Thu Jul 30 15:00:12.160392 2026] [security2:error] [pid 89520:tid 89689] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/admin.php"] [unique_id "amutTC0W4wRrtnDoPaj2fwAAAak"]
[Thu Jul 30 15:00:12.160490 2026] [security2:error] [pid 89520:tid 89689] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/admin.php"] [unique_id "amutTC0W4wRrtnDoPaj2fwAAAak"]
[Thu Jul 30 15:00:12.451052 2026] [security2:error] [pid 87988:tid 88125] [client 20.226.5.174:13918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/dbx.php"] [unique_id "amutTDipAwzptuCxBrhcBgAAARE"]
[Thu Jul 30 15:00:12.463564 2026] [security2:error] [pid 89520:tid 89736] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/177.php"] [unique_id "amutTC0W4wRrtnDoPaj2gQAAAdg"]
[Thu Jul 30 15:00:12.463667 2026] [security2:error] [pid 89520:tid 89736] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/177.php"] [unique_id "amutTC0W4wRrtnDoPaj2gQAAAdg"]
[Thu Jul 30 15:00:12.491318 2026] [security2:error] [pid 87988:tid 88174] [client 20.100.187.246:24710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amutTDipAwzptuCxBrhcBwAAAUI"]
[Thu Jul 30 15:00:12.615671 2026] [security2:error] [pid 87988:tid 88064] [remote 57.141.0.16:44496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amutTDipAwzptuCxBrhcCAABXEs"]
[Thu Jul 30 15:00:12.978016 2026] [security2:error] [pid 89520:tid 89749] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/199.php"] [unique_id "amutTC0W4wRrtnDoPaj2hQAAAeU"]
[Thu Jul 30 15:00:12.978016 2026] [security2:error] [pid 87988:tid 88212] [client 20.203.221.142:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/11.php"] [unique_id "amutTDipAwzptuCxBrhcEQAAAWg"]
[Thu Jul 30 15:00:12.978140 2026] [security2:error] [pid 89520:tid 89749] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/199.php"] [unique_id "amutTC0W4wRrtnDoPaj2hQAAAeU"]
[Thu Jul 30 15:00:12.978145 2026] [security2:error] [pid 87988:tid 88212] [client 20.203.221.142:50288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/11.php"] [unique_id "amutTDipAwzptuCxBrhcEQAAAWg"]
[Thu Jul 30 15:00:13.275466 2026] [security2:error] [pid 87988:tid 88204] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/file52.php"] [unique_id "amutTTipAwzptuCxBrhcEgAAAWA"]
[Thu Jul 30 15:00:13.275598 2026] [security2:error] [pid 87988:tid 88204] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/file52.php"] [unique_id "amutTTipAwzptuCxBrhcEgAAAWA"]
[Thu Jul 30 15:00:13.525906 2026] [security2:error] [pid 89520:tid 89677] [client 20.226.5.174:13898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/dd.php"] [unique_id "amutTS0W4wRrtnDoPaj2iAAAAZ0"]
[Thu Jul 30 15:00:13.596791 2026] [security2:error] [pid 87988:tid 88130] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/geck.php"] [unique_id "amutTTipAwzptuCxBrhcHgAAARY"]
[Thu Jul 30 15:00:13.596899 2026] [security2:error] [pid 87988:tid 88130] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/geck.php"] [unique_id "amutTTipAwzptuCxBrhcHgAAARY"]
[Thu Jul 30 15:00:13.859878 2026] [core:notice] [pid 89520:tid 89599] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:13.910758 2026] [core:notice] [pid 89520:tid 89790] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:13.961727 2026] [security2:error] [pid 89520:tid 89665] [client 57.141.0.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amutTS0W4wRrtnDoPaj2igAAAZE"]
[Thu Jul 30 15:00:14.123320 2026] [security2:error] [pid 89520:tid 89760] [client 20.203.148.31:18883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amutTi0W4wRrtnDoPaj2kAAAAfA"]
[Thu Jul 30 15:00:14.758124 2026] [security2:error] [pid 89520:tid 89770] [client 20.100.187.246:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amutTi0W4wRrtnDoPaj2mgAAAfo"]
[Thu Jul 30 15:00:14.773132 2026] [security2:error] [pid 89520:tid 89675] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/biufile.php"] [unique_id "amutTi0W4wRrtnDoPaj2mwAAAZs"]
[Thu Jul 30 15:00:14.773284 2026] [security2:error] [pid 89520:tid 89675] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/biufile.php"] [unique_id "amutTi0W4wRrtnDoPaj2mwAAAZs"]
[Thu Jul 30 15:00:15.116110 2026] [security2:error] [pid 89520:tid 89692] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/dejavu.php"] [unique_id "amutTy0W4wRrtnDoPaj2nwAAAaw"]
[Thu Jul 30 15:00:15.116215 2026] [security2:error] [pid 89520:tid 89692] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/dejavu.php"] [unique_id "amutTy0W4wRrtnDoPaj2nwAAAaw"]
[Thu Jul 30 15:00:15.289699 2026] [core:error] [pid 87988:tid 88146] [client 74.7.244.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:15.289718 2026] [core:error] [pid 87988:tid 88146] [client 74.7.244.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:15.289882 2026] [security2:error] [pid 87988:tid 88146] [client 74.7.244.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amutTzipAwzptuCxBrhcNgAAASY"]
[Thu Jul 30 15:00:15.290517 2026] [security2:error] [pid 89520:tid 89670] [client 74.7.244.25:43106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.gkc.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amutTy0W4wRrtnDoPaj2oAABljU"]
[Thu Jul 30 15:00:15.360762 2026] [security2:error] [pid 87988:tid 88166] [client 20.203.148.31:17865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amutTzipAwzptuCxBrhcNwAAATo"]
[Thu Jul 30 15:00:15.420348 2026] [security2:error] [pid 89520:tid 89728] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/aaf.php"] [unique_id "amutTy0W4wRrtnDoPaj2oQAAAdA"]
[Thu Jul 30 15:00:15.420441 2026] [security2:error] [pid 89520:tid 89728] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/aaf.php"] [unique_id "amutTy0W4wRrtnDoPaj2oQAAAdA"]
[Thu Jul 30 15:00:15.722387 2026] [security2:error] [pid 89520:tid 89757] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/ha.php"] [unique_id "amutTy0W4wRrtnDoPaj2pwAAAe0"]
[Thu Jul 30 15:00:15.722478 2026] [security2:error] [pid 89520:tid 89757] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/ha.php"] [unique_id "amutTy0W4wRrtnDoPaj2pwAAAe0"]
[Thu Jul 30 15:00:15.876236 2026] [security2:error] [pid 89520:tid 89706] [client 20.100.187.246:24750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amutTy0W4wRrtnDoPaj2qQAAAbo"]
[Thu Jul 30 15:00:16.028624 2026] [security2:error] [pid 89520:tid 89705] [client 20.203.148.31:17919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amutUC0W4wRrtnDoPaj2qgAAAbk"]
[Thu Jul 30 15:00:16.030500 2026] [security2:error] [pid 89520:tid 89759] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/hur.php"] [unique_id "amutUC0W4wRrtnDoPaj2qwAAAe8"]
[Thu Jul 30 15:00:16.030594 2026] [security2:error] [pid 89520:tid 89759] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/hur.php"] [unique_id "amutUC0W4wRrtnDoPaj2qwAAAe8"]
[Thu Jul 30 15:00:16.081261 2026] [security2:error] [pid 89520:tid 89785] [client 20.203.221.142:11466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.221.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shop-peace.com"] [uri "/3.php"] [unique_id "amutUC0W4wRrtnDoPaj2rQAAAgk"]
[Thu Jul 30 15:00:16.081416 2026] [security2:error] [pid 89520:tid 89785] [client 20.203.221.142:11466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.shop-peace.com"] [uri "/3.php"] [unique_id "amutUC0W4wRrtnDoPaj2rQAAAgk"]
[Thu Jul 30 15:00:16.148213 2026] [security2:error] [pid 89520:tid 89773] [client 197.87.186.73:48734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutTy0W4wRrtnDoPaj2qAAAAf0"], referer: http://pkf.jo
[Thu Jul 30 15:00:16.333492 2026] [security2:error] [pid 87988:tid 88194] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/h02ugyh.php"] [unique_id "amutUDipAwzptuCxBrhcRgAAAVY"]
[Thu Jul 30 15:00:16.333619 2026] [security2:error] [pid 87988:tid 88194] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/h02ugyh.php"] [unique_id "amutUDipAwzptuCxBrhcRgAAAVY"]
[Thu Jul 30 15:00:16.412968 2026] [security2:error] [pid 87988:tid 88142] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amutUDipAwzptuCxBrhcRQAAASI"]
[Thu Jul 30 15:00:16.568948 2026] [security2:error] [pid 89520:tid 89664] [client 50.6.43.217:14372] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amutQS0W4wRrtnDoPaj19QAAAZA"]
[Thu Jul 30 15:00:16.618587 2026] [security2:error] [pid 89520:tid 89686] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/155.php"] [unique_id "amutUC0W4wRrtnDoPaj2uAAAAaY"]
[Thu Jul 30 15:00:16.618688 2026] [security2:error] [pid 89520:tid 89686] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/155.php"] [unique_id "amutUC0W4wRrtnDoPaj2uAAAAaY"]
[Thu Jul 30 15:00:16.685278 2026] [core:notice] [pid 89520:tid 89768] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:16.862611 2026] [security2:error] [pid 89520:tid 89778] [client 121.58.234.254:35200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutUC0W4wRrtnDoPaj2twAAAgI"], referer: http://pkf.jo
[Thu Jul 30 15:00:16.914085 2026] [security2:error] [pid 89520:tid 89693] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/ops.php"] [unique_id "amutUC0W4wRrtnDoPaj2vAAAAa0"]
[Thu Jul 30 15:00:16.914187 2026] [security2:error] [pid 89520:tid 89693] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/ops.php"] [unique_id "amutUC0W4wRrtnDoPaj2vAAAAa0"]
[Thu Jul 30 15:00:16.934580 2026] [core:notice] [pid 87988:tid 88207] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:17.204808 2026] [security2:error] [pid 89520:tid 89720] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/ingfo.php"] [unique_id "amutUS0W4wRrtnDoPaj2xQAAAcg"]
[Thu Jul 30 15:00:17.204902 2026] [security2:error] [pid 89520:tid 89720] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/ingfo.php"] [unique_id "amutUS0W4wRrtnDoPaj2xQAAAcg"]
[Thu Jul 30 15:00:17.502175 2026] [security2:error] [pid 89520:tid 89744] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/error_log.php"] [unique_id "amutUS0W4wRrtnDoPaj2yQAAAeA"]
[Thu Jul 30 15:00:17.502282 2026] [security2:error] [pid 89520:tid 89744] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/error_log.php"] [unique_id "amutUS0W4wRrtnDoPaj2yQAAAeA"]
[Thu Jul 30 15:00:17.630928 2026] [core:notice] [pid 89520:tid 89731] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:17.793958 2026] [security2:error] [pid 89520:tid 89668] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/koala.php"] [unique_id "amutUS0W4wRrtnDoPaj20gAAAZQ"]
[Thu Jul 30 15:00:17.794116 2026] [security2:error] [pid 89520:tid 89668] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/koala.php"] [unique_id "amutUS0W4wRrtnDoPaj20gAAAZQ"]
[Thu Jul 30 15:00:18.031820 2026] [security2:error] [pid 89520:tid 89665] [client 20.100.187.246:42250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nordeste1.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amutUS0W4wRrtnDoPaj20QAAAZE"]
[Thu Jul 30 15:00:18.084742 2026] [security2:error] [pid 89520:tid 89698] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/mac.php"] [unique_id "amutUi0W4wRrtnDoPaj23gAAAbI"]
[Thu Jul 30 15:00:18.084871 2026] [security2:error] [pid 89520:tid 89698] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/mac.php"] [unique_id "amutUi0W4wRrtnDoPaj23gAAAbI"]
[Thu Jul 30 15:00:18.262025 2026] [security2:error] [pid 89520:tid 89675] [client 168.226.70.178:50948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutUS0W4wRrtnDoPaj22AAAAZs"], referer: http://pkf.jo
[Thu Jul 30 15:00:18.377414 2026] [security2:error] [pid 89520:tid 89700] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wefile.php"] [unique_id "amutUi0W4wRrtnDoPaj25wAAAbQ"]
[Thu Jul 30 15:00:18.377500 2026] [security2:error] [pid 89520:tid 89700] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wefile.php"] [unique_id "amutUi0W4wRrtnDoPaj25wAAAbQ"]
[Thu Jul 30 15:00:18.390594 2026] [security2:error] [pid 89520:tid 89690] [client 113.172.208.38:57676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutUi0W4wRrtnDoPaj23QAAAao"], referer: http://pkf.jo
[Thu Jul 30 15:00:18.599349 2026] [security2:error] [pid 89520:tid 89696] [client 20.100.187.246:19770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amutUi0W4wRrtnDoPaj26gAAAbA"]
[Thu Jul 30 15:00:18.631287 2026] [security2:error] [pid 89520:tid 89735] [client 52.200.58.199:39870] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/20150321053301.jpg"] [unique_id "amutUi0W4wRrtnDoPaj27AAAAdc"]
[Thu Jul 30 15:00:18.726444 2026] [security2:error] [pid 89520:tid 89777] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/post-comments-form/"] [unique_id "amutUi0W4wRrtnDoPaj27gAAAgE"]
[Thu Jul 30 15:00:18.921934 2026] [security2:error] [pid 89520:tid 89708] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-admin/js/"] [unique_id "amutUi0W4wRrtnDoPaj28QAAAbw"]
[Thu Jul 30 15:00:19.017718 2026] [security2:error] [pid 89520:tid 89664] [client 20.203.148.31:19267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amutUy0W4wRrtnDoPaj28wAAAZA"]
[Thu Jul 30 15:00:19.210096 2026] [security2:error] [pid 89520:tid 89738] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/makeasmtp.php"] [unique_id "amutUy0W4wRrtnDoPaj2-AAAAdo"]
[Thu Jul 30 15:00:19.210191 2026] [security2:error] [pid 89520:tid 89738] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/makeasmtp.php"] [unique_id "amutUy0W4wRrtnDoPaj2-AAAAdo"]
[Thu Jul 30 15:00:19.510076 2026] [security2:error] [pid 89520:tid 89606] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutUy0W4wRrtnDoPaj2_AABrkw"]
[Thu Jul 30 15:00:19.510267 2026] [security2:error] [pid 89520:tid 89694] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutUy0W4wRrtnDoPaj2_AABrkw"]
[Thu Jul 30 15:00:19.519276 2026] [security2:error] [pid 89520:tid 89781] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/2P.php"] [unique_id "amutUy0W4wRrtnDoPaj2_QAAAgU"]
[Thu Jul 30 15:00:19.519371 2026] [security2:error] [pid 89520:tid 89781] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/2P.php"] [unique_id "amutUy0W4wRrtnDoPaj2_QAAAgU"]
[Thu Jul 30 15:00:19.548997 2026] [security2:error] [pid 87988:tid 88129] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amutUzipAwzptuCxBrhcdQAAARU"]
[Thu Jul 30 15:00:19.549113 2026] [security2:error] [pid 87988:tid 88129] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amutUzipAwzptuCxBrhcdQAAARU"]
[Thu Jul 30 15:00:19.552669 2026] [security2:error] [pid 89520:tid 89743] [client 20.100.187.246:20118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amutUy0W4wRrtnDoPaj2_wAAAd8"]
[Thu Jul 30 15:00:19.563482 2026] [autoindex:error] [pid 89520:tid 89761] [client 43.166.130.123:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:00:19.646665 2026] [security2:error] [pid 87988:tid 88098] [remote 216.73.216.51:3392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amutUzipAwzptuCxBrhcegABW20"]
[Thu Jul 30 15:00:19.785938 2026] [security2:error] [pid 89520:tid 89753] [client 223.176.3.205:49124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amutUy0W4wRrtnDoPaj2-wAAAek"], referer: http://pkf.jo
[Thu Jul 30 15:00:19.825636 2026] [security2:error] [pid 89520:tid 89702] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/.well-known/about.php"] [unique_id "amutUy0W4wRrtnDoPaj3CQAAAbY"]
[Thu Jul 30 15:00:19.825731 2026] [security2:error] [pid 89520:tid 89702] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/.well-known/about.php"] [unique_id "amutUy0W4wRrtnDoPaj3CQAAAbY"]
[Thu Jul 30 15:00:20.125424 2026] [security2:error] [pid 89520:tid 89725] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amutVC0W4wRrtnDoPaj3DAAAAc0"]
[Thu Jul 30 15:00:20.125546 2026] [security2:error] [pid 89520:tid 89725] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amutVC0W4wRrtnDoPaj3DAAAAc0"]
[Thu Jul 30 15:00:20.128594 2026] [core:notice] [pid 89520:tid 89788] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:20.137799 2026] [security2:error] [pid 89520:tid 89605] [remote 74.7.243.224:46456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/js/Policyf.php"] [unique_id "amutVC0W4wRrtnDoPaj3DgABsUs"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/js/bootstrap.bundle.min.js
[Thu Jul 30 15:00:20.145991 2026] [security2:error] [pid 87988:tid 88181] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-includes/ID3/about.php"] [unique_id "amutVDipAwzptuCxBrhcgQAAAUk"]
[Thu Jul 30 15:00:20.146078 2026] [security2:error] [pid 87988:tid 88181] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-includes/ID3/about.php"] [unique_id "amutVDipAwzptuCxBrhcgQAAAUk"]
[Thu Jul 30 15:00:20.445750 2026] [security2:error] [pid 89520:tid 89718] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/system_log.php"] [unique_id "amutVC0W4wRrtnDoPaj3FAAAAcY"]
[Thu Jul 30 15:00:20.445861 2026] [security2:error] [pid 89520:tid 89718] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/system_log.php"] [unique_id "amutVC0W4wRrtnDoPaj3FAAAAcY"]
[Thu Jul 30 15:00:20.483662 2026] [security2:error] [pid 87988:tid 88146] [client 20.203.148.31:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amutVDipAwzptuCxBrhchwAAASY"]
[Thu Jul 30 15:00:20.732223 2026] [security2:error] [pid 87988:tid 88173] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wicked.php"] [unique_id "amutVDipAwzptuCxBrhciwAAAUE"]
[Thu Jul 30 15:00:20.732327 2026] [security2:error] [pid 87988:tid 88173] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wicked.php"] [unique_id "amutVDipAwzptuCxBrhciwAAAUE"]
[Thu Jul 30 15:00:20.787694 2026] [security2:error] [pid 89520:tid 89769] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-admin/css/"] [unique_id "amutVC0W4wRrtnDoPaj3FwAAAfk"]
[Thu Jul 30 15:00:20.985896 2026] [security2:error] [pid 89520:tid 89700] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/modern/"] [unique_id "amutVC0W4wRrtnDoPaj3HAAAAbQ"]
[Thu Jul 30 15:00:21.147568 2026] [security2:error] [pid 89520:tid 89678] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/crgio.php"] [unique_id "amutVS0W4wRrtnDoPaj3IgAAAZ4"]
[Thu Jul 30 15:00:21.147716 2026] [security2:error] [pid 89520:tid 89678] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/crgio.php"] [unique_id "amutVS0W4wRrtnDoPaj3IgAAAZ4"]
[Thu Jul 30 15:00:21.318511 2026] [security2:error] [pid 89520:tid 89759] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wpx.php"] [unique_id "amutVS0W4wRrtnDoPaj3JAAAAe8"]
[Thu Jul 30 15:00:21.318662 2026] [security2:error] [pid 89520:tid 89759] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wpx.php"] [unique_id "amutVS0W4wRrtnDoPaj3JAAAAe8"]
[Thu Jul 30 15:00:21.443512 2026] [security2:error] [pid 89520:tid 89775] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/pucci.php"] [unique_id "amutVS0W4wRrtnDoPaj3JgAAAf8"]
[Thu Jul 30 15:00:21.443631 2026] [security2:error] [pid 89520:tid 89775] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/pucci.php"] [unique_id "amutVS0W4wRrtnDoPaj3JgAAAf8"]
[Thu Jul 30 15:00:21.710718 2026] [security2:error] [pid 87988:tid 88207] [client 20.203.148.31:6168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amutVTipAwzptuCxBrhcoAAAAWM"]
[Thu Jul 30 15:00:21.781343 2026] [security2:error] [pid 87988:tid 88219] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/details/"] [unique_id "amutVTipAwzptuCxBrhcogAAAW8"]
[Thu Jul 30 15:00:21.949235 2026] [security2:error] [pid 87988:tid 88245] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/images.php"] [unique_id "amutVTipAwzptuCxBrhcqQAAAYk"]
[Thu Jul 30 15:00:21.949334 2026] [security2:error] [pid 87988:tid 88245] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/images.php"] [unique_id "amutVTipAwzptuCxBrhcqQAAAYk"]
[Thu Jul 30 15:00:21.985967 2026] [security2:error] [pid 87988:tid 88229] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/blocks/audio/"] [unique_id "amutVTipAwzptuCxBrhcqAAAAXk"]
[Thu Jul 30 15:00:22.157067 2026] [security2:error] [pid 87988:tid 88151] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-temp.php"] [unique_id "amutVjipAwzptuCxBrhcqgAAASs"]
[Thu Jul 30 15:00:22.157233 2026] [security2:error] [pid 87988:tid 88151] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-temp.php"] [unique_id "amutVjipAwzptuCxBrhcqgAAASs"]
[Thu Jul 30 15:00:22.213065 2026] [security2:error] [pid 89520:tid 89721] [client 98.83.177.42:20442] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/saudebucalgenetica.jpg"] [unique_id "amutVi0W4wRrtnDoPaj3LwAAAck"]
[Thu Jul 30 15:00:22.463144 2026] [security2:error] [pid 87988:tid 88170] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-admin/js/index.php"] [unique_id "amutVjipAwzptuCxBrhctQAAAT4"]
[Thu Jul 30 15:00:22.463249 2026] [security2:error] [pid 87988:tid 88170] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-admin/js/index.php"] [unique_id "amutVjipAwzptuCxBrhctQAAAT4"]
[Thu Jul 30 15:00:22.537938 2026] [security2:error] [pid 89520:tid 89783] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/1xmomo.php"] [unique_id "amutVi0W4wRrtnDoPaj3NgAAAgc"]
[Thu Jul 30 15:00:22.538038 2026] [security2:error] [pid 89520:tid 89783] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/1xmomo.php"] [unique_id "amutVi0W4wRrtnDoPaj3NgAAAgc"]
[Thu Jul 30 15:00:22.713111 2026] [security2:error] [pid 87988:tid 88240] [client 85.204.70.116:49418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "skcarrental.ae"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amutVjipAwzptuCxBrhcuQAAAYQ"]
[Thu Jul 30 15:00:22.716761 2026] [security2:error] [pid 89520:tid 89738] [client 20.203.148.31:6493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.wp-cli/flower.php"] [unique_id "amutVi0W4wRrtnDoPaj3OgAAAdo"]
[Thu Jul 30 15:00:22.769324 2026] [security2:error] [pid 87988:tid 88202] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/puc.php"] [unique_id "amutVjipAwzptuCxBrhcuwAAAV4"]
[Thu Jul 30 15:00:22.769427 2026] [security2:error] [pid 87988:tid 88202] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/puc.php"] [unique_id "amutVjipAwzptuCxBrhcuwAAAV4"]
[Thu Jul 30 15:00:23.067391 2026] [security2:error] [pid 89520:tid 89723] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/dx.php"] [unique_id "amutVy0W4wRrtnDoPaj3QgAAAcs"]
[Thu Jul 30 15:00:23.067502 2026] [security2:error] [pid 89520:tid 89723] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/dx.php"] [unique_id "amutVy0W4wRrtnDoPaj3QgAAAcs"]
[Thu Jul 30 15:00:23.090831 2026] [security2:error] [pid 89520:tid 89774] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/1revo.php"] [unique_id "amutVy0W4wRrtnDoPaj3QwAAAf4"]
[Thu Jul 30 15:00:23.090955 2026] [security2:error] [pid 89520:tid 89774] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/1revo.php"] [unique_id "amutVy0W4wRrtnDoPaj3QwAAAf4"]
[Thu Jul 30 15:00:23.256563 2026] [security2:error] [pid 89520:tid 89754] [client 85.204.70.116:6416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amutVy0W4wRrtnDoPaj3RQAAAeo"]
[Thu Jul 30 15:00:23.321599 2026] [security2:error] [pid 89520:tid 89744] [client 20.203.148.31:6197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/.wp-cli/xleet.php"] [unique_id "amutVy0W4wRrtnDoPaj3SAAAAeA"]
[Thu Jul 30 15:00:23.391032 2026] [security2:error] [pid 89520:tid 89742] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/Requests/"] [unique_id "amutVy0W4wRrtnDoPaj3SQAAAd4"]
[Thu Jul 30 15:00:23.622710 2026] [security2:error] [pid 87988:tid 88175] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/cong.php"] [unique_id "amutVzipAwzptuCxBrhczAAAAUM"]
[Thu Jul 30 15:00:23.622803 2026] [security2:error] [pid 87988:tid 88175] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/cong.php"] [unique_id "amutVzipAwzptuCxBrhczAAAAUM"]
[Thu Jul 30 15:00:23.635902 2026] [security2:error] [pid 89520:tid 89667] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/7.php"] [unique_id "amutVy0W4wRrtnDoPaj3TgAAAZM"]
[Thu Jul 30 15:00:23.635994 2026] [security2:error] [pid 89520:tid 89667] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/7.php"] [unique_id "amutVy0W4wRrtnDoPaj3TgAAAZM"]
[Thu Jul 30 15:00:23.680020 2026] [core:notice] [pid 87988:tid 88150] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:23.905252 2026] [security2:error] [pid 87988:tid 88166] [client 20.203.148.31:12511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amutVzipAwzptuCxBrhc0gAAATo"]
[Thu Jul 30 15:00:23.965795 2026] [security2:error] [pid 89520:tid 89682] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/8.php"] [unique_id "amutVy0W4wRrtnDoPaj3VQAAAaI"]
[Thu Jul 30 15:00:23.965889 2026] [security2:error] [pid 89520:tid 89682] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/8.php"] [unique_id "amutVy0W4wRrtnDoPaj3VQAAAaI"]
[Thu Jul 30 15:00:24.123189 2026] [security2:error] [pid 89520:tid 89711] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/a.php"] [unique_id "amutWC0W4wRrtnDoPaj3WQAAAb8"]
[Thu Jul 30 15:00:24.123339 2026] [security2:error] [pid 89520:tid 89711] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/a.php"] [unique_id "amutWC0W4wRrtnDoPaj3WQAAAb8"]
[Thu Jul 30 15:00:24.272476 2026] [security2:error] [pid 89520:tid 89666] [client 20.91.208.34:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.dubaiappliance.repair"] [uri "/1.php"] [unique_id "amutWC0W4wRrtnDoPaj3XAAAAZI"]
[Thu Jul 30 15:00:24.272584 2026] [security2:error] [pid 89520:tid 89666] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/1.php"] [unique_id "amutWC0W4wRrtnDoPaj3XAAAAZI"]
[Thu Jul 30 15:00:24.272663 2026] [security2:error] [pid 89520:tid 89666] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/1.php"] [unique_id "amutWC0W4wRrtnDoPaj3XAAAAZI"]
[Thu Jul 30 15:00:24.515411 2026] [security2:error] [pid 89520:tid 89785] [client 20.100.187.246:19349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amutWC0W4wRrtnDoPaj3YwAAAgk"]
[Thu Jul 30 15:00:24.562778 2026] [security2:error] [pid 87988:tid 88125] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/about.php"] [unique_id "amutWDipAwzptuCxBrhc3QAAARE"]
[Thu Jul 30 15:00:24.562882 2026] [security2:error] [pid 87988:tid 88125] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/about.php"] [unique_id "amutWDipAwzptuCxBrhc3QAAARE"]
[Thu Jul 30 15:00:24.685120 2026] [security2:error] [pid 89520:tid 89676] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/srontol.php"] [unique_id "amutWC0W4wRrtnDoPaj3aAAAAZw"]
[Thu Jul 30 15:00:24.685224 2026] [security2:error] [pid 89520:tid 89676] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/srontol.php"] [unique_id "amutWC0W4wRrtnDoPaj3aAAAAZw"]
[Thu Jul 30 15:00:24.852618 2026] [security2:error] [pid 87988:tid 88162] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/admin.php"] [unique_id "amutWDipAwzptuCxBrhc4AAAATY"]
[Thu Jul 30 15:00:24.852736 2026] [security2:error] [pid 87988:tid 88162] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/admin.php"] [unique_id "amutWDipAwzptuCxBrhc4AAAATY"]
[Thu Jul 30 15:00:24.962011 2026] [security2:error] [pid 87988:tid 88124] [client 20.203.148.31:36044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/flower.php"] [unique_id "amutWDipAwzptuCxBrhc5gAAARA"]
[Thu Jul 30 15:00:25.162705 2026] [security2:error] [pid 89520:tid 89715] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/edit.php"] [unique_id "amutWS0W4wRrtnDoPaj3cAAAAcM"]
[Thu Jul 30 15:00:25.162796 2026] [security2:error] [pid 89520:tid 89715] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/edit.php"] [unique_id "amutWS0W4wRrtnDoPaj3cAAAAcM"]
[Thu Jul 30 15:00:25.235286 2026] [security2:error] [pid 89520:tid 89716] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/reop3.php"] [unique_id "amutWS0W4wRrtnDoPaj3cgAAAcQ"]
[Thu Jul 30 15:00:25.235389 2026] [security2:error] [pid 89520:tid 89716] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/reop3.php"] [unique_id "amutWS0W4wRrtnDoPaj3cgAAAcQ"]
[Thu Jul 30 15:00:25.276370 2026] [security2:error] [pid 89520:tid 89664] [client 20.100.187.246:20933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/flower.php"] [unique_id "amutWS0W4wRrtnDoPaj3dQAAAZA"]
[Thu Jul 30 15:00:25.492182 2026] [security2:error] [pid 87988:tid 88245] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/admin.php"] [unique_id "amutWTipAwzptuCxBrhc8QAAAYk"]
[Thu Jul 30 15:00:25.492299 2026] [security2:error] [pid 87988:tid 88245] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/admin.php"] [unique_id "amutWTipAwzptuCxBrhc8QAAAYk"]
[Thu Jul 30 15:00:25.536829 2026] [security2:error] [pid 89520:tid 89737] [client 20.203.148.31:12505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amutWS0W4wRrtnDoPaj3ewAAAdk"]
[Thu Jul 30 15:00:25.759264 2026] [security2:error] [pid 89520:tid 89680] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/file5.php"] [unique_id "amutWS0W4wRrtnDoPaj3fwAAAaA"]
[Thu Jul 30 15:00:25.759389 2026] [security2:error] [pid 89520:tid 89680] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/file5.php"] [unique_id "amutWS0W4wRrtnDoPaj3fwAAAaA"]
[Thu Jul 30 15:00:25.792211 2026] [security2:error] [pid 89520:tid 89782] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/inputs.php"] [unique_id "amutWS0W4wRrtnDoPaj3gAAAAgY"]
[Thu Jul 30 15:00:25.792311 2026] [security2:error] [pid 89520:tid 89782] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/inputs.php"] [unique_id "amutWS0W4wRrtnDoPaj3gAAAAgY"]
[Thu Jul 30 15:00:25.879921 2026] [security2:error] [pid 89520:tid 89674] [client 85.204.70.116:37268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amutWS0W4wRrtnDoPaj3gQAAAZo"]
[Thu Jul 30 15:00:25.880045 2026] [security2:error] [pid 89520:tid 89674] [client 85.204.70.116:37268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skcarrental.ae"] [uri "/xmlrpc.php"] [unique_id "amutWS0W4wRrtnDoPaj3gQAAAZo"]
[Thu Jul 30 15:00:26.033442 2026] [security2:error] [pid 87988:tid 88179] [client 20.100.187.246:43491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amutWjipAwzptuCxBrhc-AAAAUc"]
[Thu Jul 30 15:00:26.115054 2026] [security2:error] [pid 89520:tid 89691] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/av.php"] [unique_id "amutWi0W4wRrtnDoPaj3hQAAAas"]
[Thu Jul 30 15:00:26.115161 2026] [security2:error] [pid 89520:tid 89691] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/av.php"] [unique_id "amutWi0W4wRrtnDoPaj3hQAAAas"]
[Thu Jul 30 15:00:26.297762 2026] [security2:error] [pid 89520:tid 89725] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/domvf.php"] [unique_id "amutWi0W4wRrtnDoPaj3hwAAAc0"]
[Thu Jul 30 15:00:26.297859 2026] [security2:error] [pid 89520:tid 89725] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/domvf.php"] [unique_id "amutWi0W4wRrtnDoPaj3hwAAAc0"]
[Thu Jul 30 15:00:26.346440 2026] [security2:error] [pid 89520:tid 89758] [client 23.21.148.226:11847] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/1478115326023-vivianny-90x60@2x.jpg"] [unique_id "amutWi0W4wRrtnDoPaj3iAAAAe4"]
[Thu Jul 30 15:00:26.431466 2026] [security2:error] [pid 89520:tid 89685] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/classwithtostring.php"] [unique_id "amutWi0W4wRrtnDoPaj3igAAAaU"]
[Thu Jul 30 15:00:26.431568 2026] [security2:error] [pid 89520:tid 89685] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/classwithtostring.php"] [unique_id "amutWi0W4wRrtnDoPaj3igAAAaU"]
[Thu Jul 30 15:00:26.718341 2026] [security2:error] [pid 89520:tid 89762] [client 20.203.148.31:12523] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.raad.pk"] [uri "/1.php"] [unique_id "amutWi0W4wRrtnDoPaj3kAAAAfI"]
[Thu Jul 30 15:00:26.718477 2026] [security2:error] [pid 89520:tid 89762] [client 20.203.148.31:12523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/1.php"] [unique_id "amutWi0W4wRrtnDoPaj3kAAAAfI"]
[Thu Jul 30 15:00:26.728330 2026] [security2:error] [pid 89520:tid 89682] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/themes/index.php"] [unique_id "amutWi0W4wRrtnDoPaj3kQAAAaI"]
[Thu Jul 30 15:00:26.728410 2026] [security2:error] [pid 89520:tid 89682] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/themes/index.php"] [unique_id "amutWi0W4wRrtnDoPaj3kQAAAaI"]
[Thu Jul 30 15:00:26.860550 2026] [security2:error] [pid 89520:tid 89724] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/zero.php"] [unique_id "amutWi0W4wRrtnDoPaj3kgAAAcw"]
[Thu Jul 30 15:00:26.860655 2026] [security2:error] [pid 89520:tid 89724] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/zero.php"] [unique_id "amutWi0W4wRrtnDoPaj3kgAAAcw"]
[Thu Jul 30 15:00:27.027435 2026] [security2:error] [pid 89520:tid 89678] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-blog.php"] [unique_id "amutWy0W4wRrtnDoPaj3lQAAAZ4"]
[Thu Jul 30 15:00:27.027528 2026] [security2:error] [pid 89520:tid 89678] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-blog.php"] [unique_id "amutWy0W4wRrtnDoPaj3lQAAAZ4"]
[Thu Jul 30 15:00:27.443578 2026] [security2:error] [pid 89520:tid 89704] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/002.php"] [unique_id "amutWy0W4wRrtnDoPaj3nAAAAbg"]
[Thu Jul 30 15:00:27.443686 2026] [security2:error] [pid 89520:tid 89704] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/002.php"] [unique_id "amutWy0W4wRrtnDoPaj3nAAAAbg"]
[Thu Jul 30 15:00:27.445921 2026] [security2:error] [pid 89520:tid 89775] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/js/jquery/"] [unique_id "amutWy0W4wRrtnDoPaj3mwAAAf8"]
[Thu Jul 30 15:00:27.616420 2026] [security2:error] [pid 89520:tid 89717] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/admin.php"] [unique_id "amutWy0W4wRrtnDoPaj3ogAAAcU"]
[Thu Jul 30 15:00:27.616580 2026] [security2:error] [pid 89520:tid 89717] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-content/admin.php"] [unique_id "amutWy0W4wRrtnDoPaj3ogAAAcU"]
[Thu Jul 30 15:00:27.915888 2026] [security2:error] [pid 87988:tid 88231] [client 18.216.20.192:65244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amutWzipAwzptuCxBrhdEQABeyw"]
[Thu Jul 30 15:00:27.938621 2026] [security2:error] [pid 89520:tid 89721] [client 20.203.148.31:6468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/admin.php"] [unique_id "amutWy0W4wRrtnDoPaj3pAAAAck"]
[Thu Jul 30 15:00:27.995988 2026] [security2:error] [pid 89520:tid 89716] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/adminfuns.php"] [unique_id "amutWy0W4wRrtnDoPaj3pwAAAcQ"]
[Thu Jul 30 15:00:27.996084 2026] [security2:error] [pid 89520:tid 89716] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/adminfuns.php"] [unique_id "amutWy0W4wRrtnDoPaj3pwAAAcQ"]
[Thu Jul 30 15:00:28.031476 2026] [security2:error] [pid 89520:tid 89664] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/thoms.php"] [unique_id "amutXC0W4wRrtnDoPaj3qAAAAZA"]
[Thu Jul 30 15:00:28.031575 2026] [security2:error] [pid 89520:tid 89664] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/thoms.php"] [unique_id "amutXC0W4wRrtnDoPaj3qAAAAZA"]
[Thu Jul 30 15:00:28.196875 2026] [core:notice] [pid 89520:tid 89776] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:28.309198 2026] [security2:error] [pid 89520:tid 89720] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/goods.php"] [unique_id "amutXC0W4wRrtnDoPaj3swAAAcg"]
[Thu Jul 30 15:00:28.309362 2026] [security2:error] [pid 89520:tid 89720] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/goods.php"] [unique_id "amutXC0W4wRrtnDoPaj3swAAAcg"]
[Thu Jul 30 15:00:28.538683 2026] [core:notice] [pid 89520:tid 89674] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:28.548074 2026] [security2:error] [pid 89520:tid 89723] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fi22.php"] [unique_id "amutXC0W4wRrtnDoPaj3tgAAAcs"]
[Thu Jul 30 15:00:28.548174 2026] [security2:error] [pid 89520:tid 89723] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fi22.php"] [unique_id "amutXC0W4wRrtnDoPaj3tgAAAcs"]
[Thu Jul 30 15:00:28.714754 2026] [security2:error] [pid 87988:tid 88142] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/ms-edit.php"] [unique_id "amutXDipAwzptuCxBrhdIQAAASI"]
[Thu Jul 30 15:00:28.714844 2026] [security2:error] [pid 87988:tid 88142] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/ms-edit.php"] [unique_id "amutXDipAwzptuCxBrhdIQAAASI"]
[Thu Jul 30 15:00:29.112001 2026] [security2:error] [pid 89520:tid 89747] [client 52.165.196.84:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/"] [unique_id "amutXS0W4wRrtnDoPaj3wgAAAeM"]
[Thu Jul 30 15:00:29.112122 2026] [security2:error] [pid 89520:tid 89747] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/"] [unique_id "amutXS0W4wRrtnDoPaj3wgAAAeM"]
[Thu Jul 30 15:00:29.179056 2026] [security2:error] [pid 89520:tid 89698] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/222.php"] [unique_id "amutXS0W4wRrtnDoPaj3xQAAAbI"]
[Thu Jul 30 15:00:29.179158 2026] [security2:error] [pid 89520:tid 89698] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/222.php"] [unique_id "amutXS0W4wRrtnDoPaj3xQAAAbI"]
[Thu Jul 30 15:00:29.486447 2026] [security2:error] [pid 89520:tid 89752] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/cgi-bin/index.php"] [unique_id "amutXS0W4wRrtnDoPaj3ywAAAeg"]
[Thu Jul 30 15:00:29.486568 2026] [security2:error] [pid 89520:tid 89752] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/cgi-bin/index.php"] [unique_id "amutXS0W4wRrtnDoPaj3ywAAAeg"]
[Thu Jul 30 15:00:29.685436 2026] [security2:error] [pid 89520:tid 89775] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/82.php"] [unique_id "amutXS0W4wRrtnDoPaj3zwAAAf8"]
[Thu Jul 30 15:00:29.685521 2026] [security2:error] [pid 89520:tid 89775] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/82.php"] [unique_id "amutXS0W4wRrtnDoPaj3zwAAAf8"]
[Thu Jul 30 15:00:29.820413 2026] [security2:error] [pid 89520:tid 89719] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/css/dist/"] [unique_id "amutXS0W4wRrtnDoPaj30QAAAcc"]
[Thu Jul 30 15:00:29.986211 2026] [security2:error] [pid 89520:tid 89771] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/BDKR28WP.php"] [unique_id "amutXS0W4wRrtnDoPaj31AAAAfs"]
[Thu Jul 30 15:00:29.986331 2026] [security2:error] [pid 89520:tid 89771] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/BDKR28WP.php"] [unique_id "amutXS0W4wRrtnDoPaj31AAAAfs"]
[Thu Jul 30 15:00:30.053937 2026] [core:notice] [pid 89520:tid 89789] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:30.104130 2026] [security2:error] [pid 89520:tid 89699] [client 20.100.187.246:20928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amutXi0W4wRrtnDoPaj32AAAAbM"]
[Thu Jul 30 15:00:30.181258 2026] [security2:error] [pid 87988:tid 88124] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sx.php"] [unique_id "amutXjipAwzptuCxBrhdMAAAARA"]
[Thu Jul 30 15:00:30.181353 2026] [security2:error] [pid 87988:tid 88124] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sx.php"] [unique_id "amutXjipAwzptuCxBrhdMAAAARA"]
[Thu Jul 30 15:00:30.291823 2026] [core:notice] [pid 89520:tid 89745] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:30.348060 2026] [security2:error] [pid 89520:tid 89664] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/l10n/"] [unique_id "amutXi0W4wRrtnDoPaj33QAAAZA"]
[Thu Jul 30 15:00:30.389196 2026] [security2:error] [pid 89520:tid 89616] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutXi0W4wRrtnDoPaj33gABz1Y"]
[Thu Jul 30 15:00:30.389394 2026] [security2:error] [pid 89520:tid 89727] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutXi0W4wRrtnDoPaj33gABz1Y"]
[Thu Jul 30 15:00:30.407610 2026] [security2:error] [pid 89520:tid 89766] [client 23.23.214.190:30070] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/03/1wrocpep1bfkk0vg736eczcu4-555x350.jpg"] [unique_id "amutXi0W4wRrtnDoPaj33wAAAfY"]
[Thu Jul 30 15:00:30.539044 2026] [security2:error] [pid 89520:tid 89683] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-content/uploads/"] [unique_id "amutXi0W4wRrtnDoPaj34QAAAaM"]
[Thu Jul 30 15:00:30.727833 2026] [security2:error] [pid 89520:tid 89756] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/dex.php"] [unique_id "amutXi0W4wRrtnDoPaj35AAAAew"]
[Thu Jul 30 15:00:30.727924 2026] [security2:error] [pid 89520:tid 89756] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/dex.php"] [unique_id "amutXi0W4wRrtnDoPaj35AAAAew"]
[Thu Jul 30 15:00:30.733599 2026] [security2:error] [pid 89520:tid 89776] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp.php"] [unique_id "amutXi0W4wRrtnDoPaj35QAAAgA"]
[Thu Jul 30 15:00:30.733692 2026] [security2:error] [pid 89520:tid 89776] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp.php"] [unique_id "amutXi0W4wRrtnDoPaj35QAAAgA"]
[Thu Jul 30 15:00:30.961646 2026] [security2:error] [pid 89520:tid 89617] [remote 57.141.0.11:50172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amutXi0W4wRrtnDoPaj35gACBVc"]
[Thu Jul 30 15:00:31.029877 2026] [security2:error] [pid 89520:tid 89737] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/abcd.php"] [unique_id "amutXy0W4wRrtnDoPaj35wAAAdk"]
[Thu Jul 30 15:00:31.029999 2026] [security2:error] [pid 89520:tid 89737] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/abcd.php"] [unique_id "amutXy0W4wRrtnDoPaj35wAAAdk"]
[Thu Jul 30 15:00:31.322423 2026] [security2:error] [pid 87988:tid 88206] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fpwch.php"] [unique_id "amutXzipAwzptuCxBrhdRAAAAWI"]
[Thu Jul 30 15:00:31.322513 2026] [security2:error] [pid 87988:tid 88206] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fpwch.php"] [unique_id "amutXzipAwzptuCxBrhdRAAAAWI"]
[Thu Jul 30 15:00:31.339920 2026] [security2:error] [pid 87988:tid 88145] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/a1.php"] [unique_id "amutXzipAwzptuCxBrhdRQAAASU"]
[Thu Jul 30 15:00:31.340014 2026] [security2:error] [pid 87988:tid 88145] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/a1.php"] [unique_id "amutXzipAwzptuCxBrhdRQAAASU"]
[Thu Jul 30 15:00:31.588562 2026] [security2:error] [pid 89520:tid 89720] [client 185.191.171.2:61260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.urwru.club"] [uri "/dubai-personal-trainer"] [unique_id "amutXy0W4wRrtnDoPaj36wAAAcg"]
[Thu Jul 30 15:00:31.588754 2026] [security2:error] [pid 89520:tid 89720] [client 185.191.171.2:61260] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.urwru.club"] [uri "/dubai-personal-trainer"] [unique_id "amutXy0W4wRrtnDoPaj36wAAAcg"]
[Thu Jul 30 15:00:31.670684 2026] [security2:error] [pid 89520:tid 89784] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amutXy0W4wRrtnDoPaj37AAAAgg"]
[Thu Jul 30 15:00:31.670798 2026] [security2:error] [pid 89520:tid 89784] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amutXy0W4wRrtnDoPaj37AAAAgg"]
[Thu Jul 30 15:00:31.960577 2026] [security2:error] [pid 87988:tid 88243] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/cgi-bin/admin.php"] [unique_id "amutXzipAwzptuCxBrhdTgAAAYc"]
[Thu Jul 30 15:00:31.960696 2026] [security2:error] [pid 87988:tid 88243] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/cgi-bin/admin.php"] [unique_id "amutXzipAwzptuCxBrhdTgAAAYc"]
[Thu Jul 30 15:00:32.017296 2026] [security2:error] [pid 87988:tid 88185] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/black.php"] [unique_id "amutYDipAwzptuCxBrhdTwAAAU0"]
[Thu Jul 30 15:00:32.017403 2026] [security2:error] [pid 87988:tid 88185] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/black.php"] [unique_id "amutYDipAwzptuCxBrhdTwAAAU0"]
[Thu Jul 30 15:00:32.322856 2026] [security2:error] [pid 87988:tid 88176] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-content/"] [unique_id "amutYDipAwzptuCxBrhdVQAAAUQ"]
[Thu Jul 30 15:00:32.482029 2026] [security2:error] [pid 87988:tid 88228] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/simple.php"] [unique_id "amutYDipAwzptuCxBrhdWwAAAXg"]
[Thu Jul 30 15:00:32.482169 2026] [security2:error] [pid 87988:tid 88228] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/simple.php"] [unique_id "amutYDipAwzptuCxBrhdWwAAAXg"]
[Thu Jul 30 15:00:32.525731 2026] [security2:error] [pid 89520:tid 89725] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/loader.php"] [unique_id "amutYC0W4wRrtnDoPaj38gAAAc0"]
[Thu Jul 30 15:00:32.525836 2026] [security2:error] [pid 89520:tid 89725] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/loader.php"] [unique_id "amutYC0W4wRrtnDoPaj38gAAAc0"]
[Thu Jul 30 15:00:32.819918 2026] [security2:error] [pid 89520:tid 89665] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/xxx.php"] [unique_id "amutYC0W4wRrtnDoPaj38wAAAZE"]
[Thu Jul 30 15:00:32.820085 2026] [security2:error] [pid 89520:tid 89665] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/xxx.php"] [unique_id "amutYC0W4wRrtnDoPaj38wAAAZE"]
[Thu Jul 30 15:00:33.116943 2026] [security2:error] [pid 89520:tid 89770] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/file61.php"] [unique_id "amutYS0W4wRrtnDoPaj39gAAAfo"]
[Thu Jul 30 15:00:33.117077 2026] [security2:error] [pid 89520:tid 89770] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/file61.php"] [unique_id "amutYS0W4wRrtnDoPaj39gAAAfo"]
[Thu Jul 30 15:00:33.153239 2026] [security2:error] [pid 89520:tid 89667] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/hypo.php"] [unique_id "amutYS0W4wRrtnDoPaj39wAAAZM"]
[Thu Jul 30 15:00:33.153333 2026] [security2:error] [pid 89520:tid 89667] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/hypo.php"] [unique_id "amutYS0W4wRrtnDoPaj39wAAAZM"]
[Thu Jul 30 15:00:33.165331 2026] [core:notice] [pid 89520:tid 89621] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:33.168954 2026] [security2:error] [pid 89520:tid 89681] [client 66.249.65.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/161/188"] [unique_id "amutYC0W4wRrtnDoPaj39AABoVs"]
[Thu Jul 30 15:00:33.348445 2026] [core:notice] [pid 89520:tid 89682] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:33.499456 2026] [security2:error] [pid 89520:tid 89767] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/blue/"] [unique_id "amutYS0W4wRrtnDoPaj3_AAAAfc"]
[Thu Jul 30 15:00:33.570358 2026] [core:notice] [pid 87988:tid 88133] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:33.574130 2026] [security2:error] [pid 87988:tid 88133] [client 66.249.79.8:61998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JPA/article/download/3942/2092"] [unique_id "amutYTipAwzptuCxBrhdZgAAARk"]
[Thu Jul 30 15:00:33.711897 2026] [security2:error] [pid 89520:tid 89711] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-css.php"] [unique_id "amutYS0W4wRrtnDoPaj3_QAAAb8"]
[Thu Jul 30 15:00:33.712060 2026] [security2:error] [pid 89520:tid 89711] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-css.php"] [unique_id "amutYS0W4wRrtnDoPaj3_QAAAb8"]
[Thu Jul 30 15:00:33.793049 2026] [security2:error] [pid 87988:tid 88151] [client 20.100.187.246:21631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amutYTipAwzptuCxBrhdbQAAASs"]
[Thu Jul 30 15:00:34.009984 2026] [security2:error] [pid 89520:tid 89678] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/chosen.php"] [unique_id "amutYi0W4wRrtnDoPaj4AgAAAZ4"]
[Thu Jul 30 15:00:34.010088 2026] [security2:error] [pid 89520:tid 89678] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/chosen.php"] [unique_id "amutYi0W4wRrtnDoPaj4AgAAAZ4"]
[Thu Jul 30 15:00:34.353026 2026] [security2:error] [pid 87988:tid 88184] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/block-bindings/"] [unique_id "amutYjipAwzptuCxBrhdcwAAAUw"]
[Thu Jul 30 15:00:34.404744 2026] [security2:error] [pid 89520:tid 89679] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-blink.php"] [unique_id "amutYi0W4wRrtnDoPaj4CAAAAZ8"]
[Thu Jul 30 15:00:34.404875 2026] [security2:error] [pid 89520:tid 89679] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-blink.php"] [unique_id "amutYi0W4wRrtnDoPaj4CAAAAZ8"]
[Thu Jul 30 15:00:34.600193 2026] [core:notice] [pid 89520:tid 89717] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:34.709102 2026] [security2:error] [pid 89520:tid 89734] [client 52.5.242.243:7008] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2018/06/WhatsApp-Image-2018-06-30-at-21.42.37-2.jpeg"] [unique_id "amutYi0W4wRrtnDoPaj4DQAAAdY"]
[Thu Jul 30 15:00:34.723302 2026] [core:notice] [pid 89520:tid 89780] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:34.735061 2026] [security2:error] [pid 87988:tid 88214] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/als.php"] [unique_id "amutYjipAwzptuCxBrhdeQAAAWo"]
[Thu Jul 30 15:00:34.735152 2026] [security2:error] [pid 87988:tid 88214] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/als.php"] [unique_id "amutYjipAwzptuCxBrhdeQAAAWo"]
[Thu Jul 30 15:00:34.962305 2026] [security2:error] [pid 89520:tid 89772] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/txets.php"] [unique_id "amutYi0W4wRrtnDoPaj4EQAAAfw"]
[Thu Jul 30 15:00:34.962397 2026] [security2:error] [pid 89520:tid 89772] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/txets.php"] [unique_id "amutYi0W4wRrtnDoPaj4EQAAAfw"]
[Thu Jul 30 15:00:35.234707 2026] [security2:error] [pid 89520:tid 89768] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/pol.php"] [unique_id "amutYy0W4wRrtnDoPaj4EwAAAfg"]
[Thu Jul 30 15:00:35.234825 2026] [security2:error] [pid 89520:tid 89768] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/pol.php"] [unique_id "amutYy0W4wRrtnDoPaj4EwAAAfg"]
[Thu Jul 30 15:00:35.520007 2026] [security2:error] [pid 89520:tid 89664] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/file5.php"] [unique_id "amutYy0W4wRrtnDoPaj4FwAAAZA"]
[Thu Jul 30 15:00:35.520102 2026] [security2:error] [pid 89520:tid 89664] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/file5.php"] [unique_id "amutYy0W4wRrtnDoPaj4FwAAAZA"]
[Thu Jul 30 15:00:35.581960 2026] [security2:error] [pid 89520:tid 89727] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/pucci.php"] [unique_id "amutYy0W4wRrtnDoPaj4GQAAAc8"]
[Thu Jul 30 15:00:35.582074 2026] [security2:error] [pid 89520:tid 89727] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/pucci.php"] [unique_id "amutYy0W4wRrtnDoPaj4GQAAAc8"]
[Thu Jul 30 15:00:35.840899 2026] [security2:error] [pid 87988:tid 88229] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/file.php"] [unique_id "amutYzipAwzptuCxBrhdiAAAAXk"]
[Thu Jul 30 15:00:35.841030 2026] [security2:error] [pid 87988:tid 88229] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/file.php"] [unique_id "amutYzipAwzptuCxBrhdiAAAAXk"]
[Thu Jul 30 15:00:35.972512 2026] [security2:error] [pid 89520:tid 89619] [remote 216.73.216.51:30695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amutYy0W4wRrtnDoPaj4HgABo1k"]
[Thu Jul 30 15:00:36.127961 2026] [security2:error] [pid 89520:tid 89737] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/admin.php"] [unique_id "amutZC0W4wRrtnDoPaj4IAAAAdk"]
[Thu Jul 30 15:00:36.128137 2026] [security2:error] [pid 89520:tid 89737] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/admin.php"] [unique_id "amutZC0W4wRrtnDoPaj4IAAAAdk"]
[Thu Jul 30 15:00:36.227490 2026] [security2:error] [pid 89520:tid 89733] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xwpg.php"] [unique_id "amutZC0W4wRrtnDoPaj4IgAAAdU"]
[Thu Jul 30 15:00:36.227660 2026] [security2:error] [pid 89520:tid 89733] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xwpg.php"] [unique_id "amutZC0W4wRrtnDoPaj4IgAAAdU"]
[Thu Jul 30 15:00:36.344343 2026] [security2:error] [pid 89520:tid 89708] [client 20.100.187.246:12288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amutZC0W4wRrtnDoPaj4IwAAAbw"]
[Thu Jul 30 15:00:36.415293 2026] [security2:error] [pid 89520:tid 89674] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/aa2.php"] [unique_id "amutZC0W4wRrtnDoPaj4JAAAAZo"]
[Thu Jul 30 15:00:36.415405 2026] [security2:error] [pid 89520:tid 89674] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/aa2.php"] [unique_id "amutZC0W4wRrtnDoPaj4JAAAAZo"]
[Thu Jul 30 15:00:36.431565 2026] [security2:error] [pid 89520:tid 89627] [remote 57.141.0.68:49956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com"] [uri "/search/3293993679/feed/rss2/"] [unique_id "amutZC0W4wRrtnDoPaj4JQABqGA"]
[Thu Jul 30 15:00:36.462436 2026] [security2:error] [pid 87988:tid 88208] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutYzipAwzptuCxBrhdhwABZGY"]
[Thu Jul 30 15:00:36.527525 2026] [core:notice] [pid 87988:tid 88167] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:36.703115 2026] [security2:error] [pid 87988:tid 88238] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/ccou.php"] [unique_id "amutZDipAwzptuCxBrhdmQAAAYI"]
[Thu Jul 30 15:00:36.703205 2026] [security2:error] [pid 87988:tid 88238] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/ccou.php"] [unique_id "amutZDipAwzptuCxBrhdmQAAAYI"]
[Thu Jul 30 15:00:36.845516 2026] [security2:error] [pid 87988:tid 88203] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ops.php"] [unique_id "amutZDipAwzptuCxBrhdmgAAAV8"]
[Thu Jul 30 15:00:36.845658 2026] [security2:error] [pid 87988:tid 88203] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ops.php"] [unique_id "amutZDipAwzptuCxBrhdmgAAAV8"]
[Thu Jul 30 15:00:36.846491 2026] [core:notice] [pid 89520:tid 89763] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:36.969104 2026] [core:notice] [pid 89520:tid 89750] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:37.006770 2026] [security2:error] [pid 87988:tid 88236] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/dr.php"] [unique_id "amutZTipAwzptuCxBrhdngAAAYA"]
[Thu Jul 30 15:00:37.006884 2026] [security2:error] [pid 87988:tid 88236] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/dr.php"] [unique_id "amutZTipAwzptuCxBrhdngAAAYA"]
[Thu Jul 30 15:00:37.008206 2026] [security2:error] [pid 87988:tid 88136] [client 216.73.216.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.embassyofbelgiumislamabad.cc"] [uri "/index.php"] [unique_id "amutYzipAwzptuCxBrhdhAABHFk"]
[Thu Jul 30 15:00:37.259872 2026] [core:notice] [pid 89520:tid 89747] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:37.320761 2026] [security2:error] [pid 89520:tid 89692] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/xamp.php"] [unique_id "amutZS0W4wRrtnDoPaj4MgAAAaw"]
[Thu Jul 30 15:00:37.320919 2026] [security2:error] [pid 89520:tid 89692] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/xamp.php"] [unique_id "amutZS0W4wRrtnDoPaj4MgAAAaw"]
[Thu Jul 30 15:00:37.471287 2026] [security2:error] [pid 89520:tid 89698] [client 52.165.196.84:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/1.php"] [unique_id "amutZS0W4wRrtnDoPaj4MwAAAbI"]
[Thu Jul 30 15:00:37.471429 2026] [security2:error] [pid 89520:tid 89698] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/1.php"] [unique_id "amutZS0W4wRrtnDoPaj4MwAAAbI"]
[Thu Jul 30 15:00:37.471568 2026] [security2:error] [pid 89520:tid 89698] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/1.php"] [unique_id "amutZS0W4wRrtnDoPaj4MwAAAbI"]
[Thu Jul 30 15:00:37.528368 2026] [core:notice] [pid 87988:tid 88209] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:37.578715 2026] [security2:error] [pid 87988:tid 88241] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutZDipAwzptuCxBrhdkgABhV0"]
[Thu Jul 30 15:00:37.713745 2026] [security2:error] [pid 89520:tid 89667] [client 216.73.216.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.embassyofbelgiumislamabad.cc"] [uri "/index.php"] [unique_id "amutZS0W4wRrtnDoPaj4NgABk18"]
[Thu Jul 30 15:00:37.762570 2026] [security2:error] [pid 87988:tid 88138] [client 45.91.22.87:37555] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "website-13cabd13.fso.nyx.temporary.site"] [uri "/"] [unique_id "amutZTipAwzptuCxBrhdrAAAAR4"]
[Thu Jul 30 15:00:37.826223 2026] [core:notice] [pid 87988:tid 88155] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:37.982178 2026] [security2:error] [pid 89520:tid 89711] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/mac.php"] [unique_id "amutZS0W4wRrtnDoPaj4OgAAAb8"]
[Thu Jul 30 15:00:37.982323 2026] [security2:error] [pid 89520:tid 89711] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/mac.php"] [unique_id "amutZS0W4wRrtnDoPaj4OgAAAb8"]
[Thu Jul 30 15:00:38.101314 2026] [core:notice] [pid 89520:tid 89757] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:38.306931 2026] [security2:error] [pid 87988:tid 87998] [remote 57.141.0.8:59252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amutZjipAwzptuCxBrhdtgABUAk"]
[Thu Jul 30 15:00:38.355709 2026] [security2:error] [pid 87988:tid 88148] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/bless.php"] [unique_id "amutZjipAwzptuCxBrhdtwAAASg"]
[Thu Jul 30 15:00:38.355804 2026] [security2:error] [pid 87988:tid 88148] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/bless.php"] [unique_id "amutZjipAwzptuCxBrhdtwAAASg"]
[Thu Jul 30 15:00:38.486430 2026] [security2:error] [pid 89520:tid 89709] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/js/index.php"] [unique_id "amutZi0W4wRrtnDoPaj4QQAAAb0"]
[Thu Jul 30 15:00:38.486529 2026] [security2:error] [pid 89520:tid 89709] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/js/index.php"] [unique_id "amutZi0W4wRrtnDoPaj4QQAAAb0"]
[Thu Jul 30 15:00:38.537597 2026] [core:notice] [pid 89520:tid 89704] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:38.674607 2026] [security2:error] [pid 89520:tid 89712] [client 34.233.114.237:56708] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2017/02/vagas-na-caixa-economica-federal_578921-360x195.jpg"] [unique_id "amutZi0W4wRrtnDoPaj4RgAAAcA"]
[Thu Jul 30 15:00:38.739178 2026] [core:notice] [pid 89520:tid 89676] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:38.772046 2026] [core:notice] [pid 87988:tid 88226] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:38.792685 2026] [core:notice] [pid 89520:tid 89765] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:38.928178 2026] [security2:error] [pid 89520:tid 89719] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/file25.php"] [unique_id "amutZi0W4wRrtnDoPaj4SQAAAcc"]
[Thu Jul 30 15:00:38.928286 2026] [security2:error] [pid 89520:tid 89719] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/file25.php"] [unique_id "amutZi0W4wRrtnDoPaj4SQAAAcc"]
[Thu Jul 30 15:00:38.983270 2026] [security2:error] [pid 89520:tid 89734] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/aa.php"] [unique_id "amutZi0W4wRrtnDoPaj4SgAAAdY"]
[Thu Jul 30 15:00:38.983369 2026] [security2:error] [pid 89520:tid 89734] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/aa.php"] [unique_id "amutZi0W4wRrtnDoPaj4SgAAAdY"]
[Thu Jul 30 15:00:39.088712 2026] [security2:error] [pid 89520:tid 89681] [client 20.100.187.246:18182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amutZy0W4wRrtnDoPaj4TAAAAaE"]
[Thu Jul 30 15:00:39.107349 2026] [core:notice] [pid 89520:tid 89689] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:39.220590 2026] [security2:error] [pid 89520:tid 89669] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/file6.php"] [unique_id "amutZy0W4wRrtnDoPaj4UQAAAZU"]
[Thu Jul 30 15:00:39.220692 2026] [security2:error] [pid 89520:tid 89669] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/file6.php"] [unique_id "amutZy0W4wRrtnDoPaj4UQAAAZU"]
[Thu Jul 30 15:00:39.331567 2026] [security2:error] [pid 87988:tid 88191] [client 20.203.148.31:22750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/as.php"] [unique_id "amutZzipAwzptuCxBrhdxQAAAVM"]
[Thu Jul 30 15:00:39.452690 2026] [core:notice] [pid 89520:tid 89693] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:39.511243 2026] [security2:error] [pid 89520:tid 89736] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/a2.php"] [unique_id "amutZy0W4wRrtnDoPaj4VAAAAdg"]
[Thu Jul 30 15:00:39.511357 2026] [security2:error] [pid 89520:tid 89736] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/a2.php"] [unique_id "amutZy0W4wRrtnDoPaj4VAAAAdg"]
[Thu Jul 30 15:00:39.537478 2026] [security2:error] [pid 89520:tid 89745] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xyn.php"] [unique_id "amutZy0W4wRrtnDoPaj4VQAAAeE"]
[Thu Jul 30 15:00:39.537567 2026] [security2:error] [pid 89520:tid 89745] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xyn.php"] [unique_id "amutZy0W4wRrtnDoPaj4VQAAAeE"]
[Thu Jul 30 15:00:39.565075 2026] [core:notice] [pid 87988:tid 88168] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:39.715315 2026] [core:notice] [pid 87988:tid 88180] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:39.800240 2026] [security2:error] [pid 87988:tid 88222] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/file15.php"] [unique_id "amutZzipAwzptuCxBrhd0wAAAXI"]
[Thu Jul 30 15:00:39.800332 2026] [security2:error] [pid 87988:tid 88222] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/file15.php"] [unique_id "amutZzipAwzptuCxBrhd0wAAAXI"]
[Thu Jul 30 15:00:39.986075 2026] [core:notice] [pid 89520:tid 89738] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:40.004745 2026] [security2:error] [pid 89520:tid 89722] [client 20.203.148.31:17370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/autoload_classmap.php"] [unique_id "amutaC0W4wRrtnDoPaj4WgAAAco"]
[Thu Jul 30 15:00:40.085849 2026] [security2:error] [pid 89520:tid 89776] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/f35.php"] [unique_id "amutaC0W4wRrtnDoPaj4WwAAAgA"]
[Thu Jul 30 15:00:40.085954 2026] [security2:error] [pid 89520:tid 89776] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/f35.php"] [unique_id "amutaC0W4wRrtnDoPaj4WwAAAgA"]
[Thu Jul 30 15:00:40.106079 2026] [security2:error] [pid 87988:tid 88229] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-wp.php"] [unique_id "amutaDipAwzptuCxBrhd1QAAAXk"]
[Thu Jul 30 15:00:40.106162 2026] [security2:error] [pid 87988:tid 88229] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-wp.php"] [unique_id "amutaDipAwzptuCxBrhd1QAAAXk"]
[Thu Jul 30 15:00:40.400489 2026] [security2:error] [pid 89520:tid 89726] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-load.php"] [unique_id "amutaC0W4wRrtnDoPaj4XwAAAc4"]
[Thu Jul 30 15:00:40.400613 2026] [security2:error] [pid 89520:tid 89726] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-load.php"] [unique_id "amutaC0W4wRrtnDoPaj4XwAAAc4"]
[Thu Jul 30 15:00:40.670696 2026] [security2:error] [pid 87988:tid 88208] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/aw.php"] [unique_id "amutaDipAwzptuCxBrhd3QAAAWQ"]
[Thu Jul 30 15:00:40.670853 2026] [security2:error] [pid 87988:tid 88208] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/aw.php"] [unique_id "amutaDipAwzptuCxBrhd3QAAAWQ"]
[Thu Jul 30 15:00:40.697732 2026] [security2:error] [pid 89520:tid 89688] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/xwpg.php"] [unique_id "amutaC0W4wRrtnDoPaj4ZAAAAag"]
[Thu Jul 30 15:00:40.697835 2026] [security2:error] [pid 89520:tid 89688] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/xwpg.php"] [unique_id "amutaC0W4wRrtnDoPaj4ZAAAAag"]
[Thu Jul 30 15:00:40.867528 2026] [core:notice] [pid 89520:tid 89730] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:40.968572 2026] [security2:error] [pid 89520:tid 89629] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutaC0W4wRrtnDoPaj4aQABmmI"]
[Thu Jul 30 15:00:40.968749 2026] [security2:error] [pid 89520:tid 89674] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutaC0W4wRrtnDoPaj4aQABmmI"]
[Thu Jul 30 15:00:41.050424 2026] [security2:error] [pid 89520:tid 89691] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-includes/assets/"] [unique_id "amutaS0W4wRrtnDoPaj4agAAAas"]
[Thu Jul 30 15:00:41.133972 2026] [core:notice] [pid 89520:tid 89763] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:41.181474 2026] [security2:error] [pid 87988:tid 88238] [client 20.203.148.31:20727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/back.php"] [unique_id "amutaTipAwzptuCxBrhd4gAAAYI"]
[Thu Jul 30 15:00:41.240596 2026] [security2:error] [pid 87988:tid 88225] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/classwithtostring.php"] [unique_id "amutaTipAwzptuCxBrhd5wAAAXU"]
[Thu Jul 30 15:00:41.240742 2026] [security2:error] [pid 87988:tid 88225] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/classwithtostring.php"] [unique_id "amutaTipAwzptuCxBrhd5wAAAXU"]
[Thu Jul 30 15:00:41.248277 2026] [security2:error] [pid 89520:tid 89684] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/wp-admin/css/colors/sunrise/"] [unique_id "amutaS0W4wRrtnDoPaj4bgAAAaQ"]
[Thu Jul 30 15:00:41.250517 2026] [security2:error] [pid 89520:tid 89761] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutaC0W4wRrtnDoPaj4YQAB8WM"]
[Thu Jul 30 15:00:41.403198 2026] [security2:error] [pid 89520:tid 89692] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/xstelth.php"] [unique_id "amutaS0W4wRrtnDoPaj4cAAAAaw"]
[Thu Jul 30 15:00:41.403325 2026] [security2:error] [pid 89520:tid 89692] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/xstelth.php"] [unique_id "amutaS0W4wRrtnDoPaj4cAAAAaw"]
[Thu Jul 30 15:00:41.429025 2026] [security2:error] [pid 87988:tid 88207] [client 20.100.187.246:18238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amutaTipAwzptuCxBrhd6gAAAWM"]
[Thu Jul 30 15:00:41.450385 2026] [core:notice] [pid 89520:tid 89779] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:41.695539 2026] [core:notice] [pid 89520:tid 89718] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:41.710529 2026] [security2:error] [pid 89520:tid 89760] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-admin/network/plugins.php"] [unique_id "amutaS0W4wRrtnDoPaj4dAAAAfA"]
[Thu Jul 30 15:00:41.710632 2026] [security2:error] [pid 89520:tid 89760] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/wp-admin/network/plugins.php"] [unique_id "amutaS0W4wRrtnDoPaj4dAAAAfA"]
[Thu Jul 30 15:00:41.812208 2026] [security2:error] [pid 87988:tid 88153] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/yawa.php"] [unique_id "amutaTipAwzptuCxBrhd7wAAAS0"]
[Thu Jul 30 15:00:41.812344 2026] [security2:error] [pid 87988:tid 88153] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/yawa.php"] [unique_id "amutaTipAwzptuCxBrhd7wAAAS0"]
[Thu Jul 30 15:00:41.898878 2026] [core:notice] [pid 89520:tid 89633] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:42.138023 2026] [security2:error] [pid 89520:tid 89711] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/aaa.php"] [unique_id "amutai0W4wRrtnDoPaj4eAAAAb8"]
[Thu Jul 30 15:00:42.138168 2026] [security2:error] [pid 89520:tid 89711] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/aaa.php"] [unique_id "amutai0W4wRrtnDoPaj4eAAAAb8"]
[Thu Jul 30 15:00:42.255903 2026] [security2:error] [pid 89520:tid 89671] [client 20.100.187.246:43495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amutai0W4wRrtnDoPaj4egAAAZc"]
[Thu Jul 30 15:00:42.410228 2026] [core:notice] [pid 89520:tid 89631] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:42.424454 2026] [security2:error] [pid 87988:tid 88164] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/gecko.php"] [unique_id "amutajipAwzptuCxBrhd-AAAATg"]
[Thu Jul 30 15:00:42.424557 2026] [security2:error] [pid 87988:tid 88164] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/gecko.php"] [unique_id "amutajipAwzptuCxBrhd-AAAATg"]
[Thu Jul 30 15:00:42.448344 2026] [security2:error] [pid 89520:tid 89690] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sym403.php"] [unique_id "amutai0W4wRrtnDoPaj4fgAAAao"]
[Thu Jul 30 15:00:42.448432 2026] [security2:error] [pid 89520:tid 89690] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sym403.php"] [unique_id "amutai0W4wRrtnDoPaj4fgAAAao"]
[Thu Jul 30 15:00:42.732388 2026] [security2:error] [pid 87988:tid 88189] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/pbck.php"] [unique_id "amutajipAwzptuCxBrhd-wAAAVE"]
[Thu Jul 30 15:00:42.732494 2026] [security2:error] [pid 87988:tid 88189] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/pbck.php"] [unique_id "amutajipAwzptuCxBrhd-wAAAVE"]
[Thu Jul 30 15:00:43.028671 2026] [security2:error] [pid 89520:tid 89775] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/xiugai.php"] [unique_id "amutay0W4wRrtnDoPaj4ggAAAf8"]
[Thu Jul 30 15:00:43.028775 2026] [security2:error] [pid 89520:tid 89775] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/xiugai.php"] [unique_id "amutay0W4wRrtnDoPaj4ggAAAf8"]
[Thu Jul 30 15:00:43.040843 2026] [security2:error] [pid 89520:tid 89712] [client 52.165.196.84:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amutay0W4wRrtnDoPaj4gwAAAcA"]
[Thu Jul 30 15:00:43.040926 2026] [security2:error] [pid 89520:tid 89712] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/css/colors/blue/"] [unique_id "amutay0W4wRrtnDoPaj4gwAAAcA"]
[Thu Jul 30 15:00:43.368438 2026] [security2:error] [pid 87988:tid 88166] [client 20.203.148.31:17376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/c/autoload_classmap.php"] [unique_id "amutazipAwzptuCxBrheAwAAATo"]
[Thu Jul 30 15:00:43.380798 2026] [security2:error] [pid 89520:tid 89741] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/e.php"] [unique_id "amutay0W4wRrtnDoPaj4iQAAAd0"]
[Thu Jul 30 15:00:43.380875 2026] [security2:error] [pid 89520:tid 89741] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/e.php"] [unique_id "amutay0W4wRrtnDoPaj4iQAAAd0"]
[Thu Jul 30 15:00:43.631891 2026] [security2:error] [pid 89520:tid 89772] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/adminner.php"] [unique_id "amutay0W4wRrtnDoPaj4jAAAAfw"]
[Thu Jul 30 15:00:43.632016 2026] [security2:error] [pid 89520:tid 89772] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/adminner.php"] [unique_id "amutay0W4wRrtnDoPaj4jAAAAfw"]
[Thu Jul 30 15:00:43.773383 2026] [security2:error] [pid 89520:tid 89783] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/adminner.php"] [unique_id "amutay0W4wRrtnDoPaj4jQAAAgc"]
[Thu Jul 30 15:00:43.773492 2026] [security2:error] [pid 89520:tid 89783] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/adminner.php"] [unique_id "amutay0W4wRrtnDoPaj4jQAAAgc"]
[Thu Jul 30 15:00:43.889594 2026] [security2:error] [pid 89520:tid 89780] [client 173.249.217.23:35812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.217.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amutay0W4wRrtnDoPaj4kQAAAgQ"]
[Thu Jul 30 15:00:43.889696 2026] [security2:error] [pid 89520:tid 89780] [client 173.249.217.23:35812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amutay0W4wRrtnDoPaj4kQAAAgQ"]
[Thu Jul 30 15:00:43.990180 2026] [security2:error] [pid 87988:tid 88156] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutazipAwzptuCxBrheBAAAATA"]
[Thu Jul 30 15:00:44.075973 2026] [security2:error] [pid 87988:tid 88158] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/file1221.php"] [unique_id "amutbDipAwzptuCxBrheDgAAATI"]
[Thu Jul 30 15:00:44.076144 2026] [security2:error] [pid 87988:tid 88158] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/file1221.php"] [unique_id "amutbDipAwzptuCxBrheDgAAATI"]
[Thu Jul 30 15:00:44.081480 2026] [core:notice] [pid 89520:tid 89687] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:44.195799 2026] [security2:error] [pid 87988:tid 88149] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/yup.php"] [unique_id "amutbDipAwzptuCxBrheDwAAASk"]
[Thu Jul 30 15:00:44.195924 2026] [security2:error] [pid 87988:tid 88149] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/yup.php"] [unique_id "amutbDipAwzptuCxBrheDwAAASk"]
[Thu Jul 30 15:00:44.335310 2026] [security2:error] [pid 89520:tid 89776] [client 135.119.63.61:49674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-user.php"] [unique_id "amutbC0W4wRrtnDoPaj4mgAAAgA"]
[Thu Jul 30 15:00:44.368580 2026] [core:notice] [pid 89520:tid 89733] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:44.407507 2026] [security2:error] [pid 87988:tid 88219] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/inx.php"] [unique_id "amutbDipAwzptuCxBrheEgAAAW8"]
[Thu Jul 30 15:00:44.407665 2026] [security2:error] [pid 87988:tid 88219] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/inx.php"] [unique_id "amutbDipAwzptuCxBrheEgAAAW8"]
[Thu Jul 30 15:00:44.449491 2026] [security2:error] [pid 87988:tid 88118] [client 20.203.148.31:20731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/c/flower.php"] [unique_id "amutbDipAwzptuCxBrheFQAAAQo"]
[Thu Jul 30 15:00:44.589555 2026] [security2:error] [pid 87988:tid 88191] [client 172.237.109.114:59151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amutbDipAwzptuCxBrheDQAAAVM"]
[Thu Jul 30 15:00:44.626617 2026] [core:notice] [pid 87988:tid 88214] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:44.708963 2026] [security2:error] [pid 89520:tid 89720] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/config.json.php"] [unique_id "amutbC0W4wRrtnDoPaj4ngAAAcg"]
[Thu Jul 30 15:00:44.709119 2026] [security2:error] [pid 89520:tid 89720] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/config.json.php"] [unique_id "amutbC0W4wRrtnDoPaj4ngAAAcg"]
[Thu Jul 30 15:00:44.774380 2026] [security2:error] [pid 87988:tid 88245] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/qqqa.php"] [unique_id "amutbDipAwzptuCxBrheGgAAAYk"]
[Thu Jul 30 15:00:44.774513 2026] [security2:error] [pid 87988:tid 88245] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/qqqa.php"] [unique_id "amutbDipAwzptuCxBrheGgAAAYk"]
[Thu Jul 30 15:00:44.875770 2026] [core:notice] [pid 87988:tid 88229] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:45.086236 2026] [security2:error] [pid 87988:tid 88206] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/reviall.php"] [unique_id "amutbTipAwzptuCxBrheIQAAAWI"]
[Thu Jul 30 15:00:45.086351 2026] [security2:error] [pid 87988:tid 88206] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/reviall.php"] [unique_id "amutbTipAwzptuCxBrheIQAAAWI"]
[Thu Jul 30 15:00:45.233446 2026] [core:notice] [pid 87988:tid 88170] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:45.252123 2026] [security2:error] [pid 87988:tid 88167] [client 52.165.196.84:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/block-bindings/"] [unique_id "amutbTipAwzptuCxBrheJQAAATs"]
[Thu Jul 30 15:00:45.252224 2026] [security2:error] [pid 87988:tid 88167] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/block-bindings/"] [unique_id "amutbTipAwzptuCxBrheJQAAATs"]
[Thu Jul 30 15:00:45.379243 2026] [security2:error] [pid 87988:tid 88143] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/404.php"] [unique_id "amutbTipAwzptuCxBrheKQAAASM"]
[Thu Jul 30 15:00:45.379358 2026] [security2:error] [pid 87988:tid 88143] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/404.php"] [unique_id "amutbTipAwzptuCxBrheKQAAASM"]
[Thu Jul 30 15:00:45.409022 2026] [security2:error] [pid 87988:tid 88132] [client 43.135.107.95:58173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amutbTipAwzptuCxBrheIgABGCI"]
[Thu Jul 30 15:00:45.500292 2026] [core:notice] [pid 87988:tid 88236] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:45.664193 2026] [security2:error] [pid 87988:tid 88233] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/bolt.php"] [unique_id "amutbTipAwzptuCxBrheMAAAAX0"]
[Thu Jul 30 15:00:45.664310 2026] [security2:error] [pid 87988:tid 88233] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/bolt.php"] [unique_id "amutbTipAwzptuCxBrheMAAAAX0"]
[Thu Jul 30 15:00:45.785274 2026] [security2:error] [pid 87988:tid 88181] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/2.php"] [unique_id "amutbTipAwzptuCxBrheNAAAAUk"]
[Thu Jul 30 15:00:45.785362 2026] [security2:error] [pid 87988:tid 88181] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/2.php"] [unique_id "amutbTipAwzptuCxBrheNAAAAUk"]
[Thu Jul 30 15:00:45.967247 2026] [security2:error] [pid 87988:tid 88171] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/File.php"] [unique_id "amutbTipAwzptuCxBrheNwAAAT8"]
[Thu Jul 30 15:00:45.967347 2026] [security2:error] [pid 87988:tid 88171] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/File.php"] [unique_id "amutbTipAwzptuCxBrheNwAAAT8"]
[Thu Jul 30 15:00:46.269312 2026] [security2:error] [pid 89520:tid 89747] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/fi22.php"] [unique_id "amutbi0W4wRrtnDoPaj4pQAAAeM"]
[Thu Jul 30 15:00:46.269431 2026] [security2:error] [pid 89520:tid 89747] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/fi22.php"] [unique_id "amutbi0W4wRrtnDoPaj4pQAAAeM"]
[Thu Jul 30 15:00:46.283196 2026] [security2:error] [pid 87988:tid 88228] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/f35.update.php"] [unique_id "amutbjipAwzptuCxBrhePAAAAXg"]
[Thu Jul 30 15:00:46.283291 2026] [security2:error] [pid 87988:tid 88228] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/f35.update.php"] [unique_id "amutbjipAwzptuCxBrhePAAAAXg"]
[Thu Jul 30 15:00:46.515685 2026] [core:notice] [pid 87988:tid 88150] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:46.589586 2026] [security2:error] [pid 87988:tid 88196] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/zero.php"] [unique_id "amutbjipAwzptuCxBrheQgAAAVg"]
[Thu Jul 30 15:00:46.589675 2026] [security2:error] [pid 87988:tid 88196] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/zero.php"] [unique_id "amutbjipAwzptuCxBrheQgAAAVg"]
[Thu Jul 30 15:00:46.727395 2026] [core:notice] [pid 87988:tid 88189] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:46.783490 2026] [security2:error] [pid 87988:tid 88148] [client 47.128.18.121:53886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lms.aetiiph.net"] [uri "/robots.txt"] [unique_id "amutbjipAwzptuCxBrheRgAAASg"]
[Thu Jul 30 15:00:46.814547 2026] [security2:error] [pid 89520:tid 89729] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/k.php"] [unique_id "amutbi0W4wRrtnDoPaj4rQAAAdE"]
[Thu Jul 30 15:00:46.814637 2026] [security2:error] [pid 89520:tid 89729] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/k.php"] [unique_id "amutbi0W4wRrtnDoPaj4rQAAAdE"]
[Thu Jul 30 15:00:46.842323 2026] [core:notice] [pid 89520:tid 89636] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:46.844083 2026] [core:notice] [pid 89520:tid 89639] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:46.914144 2026] [security2:error] [pid 87988:tid 88165] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/1xmomo.php"] [unique_id "amutbjipAwzptuCxBrheSAAAATk"]
[Thu Jul 30 15:00:46.914247 2026] [security2:error] [pid 87988:tid 88165] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/1xmomo.php"] [unique_id "amutbjipAwzptuCxBrheSAAAATk"]
[Thu Jul 30 15:00:46.976953 2026] [core:notice] [pid 87988:tid 88133] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:46.993242 2026] [security2:error] [pid 87988:tid 88194] [client 20.100.187.246:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amutbjipAwzptuCxBrheSgAAAVY"]
[Thu Jul 30 15:00:47.218068 2026] [security2:error] [pid 87988:tid 88174] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/fmws.php"] [unique_id "amutbzipAwzptuCxBrheTgAAAUI"]
[Thu Jul 30 15:00:47.218180 2026] [security2:error] [pid 87988:tid 88174] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/fmws.php"] [unique_id "amutbzipAwzptuCxBrheTgAAAUI"]
[Thu Jul 30 15:00:47.309414 2026] [security2:error] [pid 87988:tid 88205] [client 20.203.148.31:6259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/c/xleet.php"] [unique_id "amutbzipAwzptuCxBrheUQAAAWE"]
[Thu Jul 30 15:00:47.357280 2026] [security2:error] [pid 87988:tid 88192] [client 52.165.196.84:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/css/"] [unique_id "amutbzipAwzptuCxBrheUgAAAVQ"]
[Thu Jul 30 15:00:47.357363 2026] [security2:error] [pid 87988:tid 88192] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/css/"] [unique_id "amutbzipAwzptuCxBrheUgAAAVQ"]
[Thu Jul 30 15:00:47.523945 2026] [security2:error] [pid 87988:tid 88232] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/3PJcpMFsD8B.php"] [unique_id "amutbzipAwzptuCxBrheVQAAAXw"]
[Thu Jul 30 15:00:47.524084 2026] [security2:error] [pid 87988:tid 88232] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/3PJcpMFsD8B.php"] [unique_id "amutbzipAwzptuCxBrheVQAAAXw"]
[Thu Jul 30 15:00:47.822588 2026] [security2:error] [pid 87988:tid 88222] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/hp2.php"] [unique_id "amutbzipAwzptuCxBrheWAAAAXI"]
[Thu Jul 30 15:00:47.822716 2026] [security2:error] [pid 87988:tid 88222] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/hp2.php"] [unique_id "amutbzipAwzptuCxBrheWAAAAXI"]
[Thu Jul 30 15:00:47.907124 2026] [security2:error] [pid 87988:tid 88230] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/spadex.php"] [unique_id "amutbzipAwzptuCxBrheXQAAAXo"]
[Thu Jul 30 15:00:47.907204 2026] [security2:error] [pid 87988:tid 88230] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/spadex.php"] [unique_id "amutbzipAwzptuCxBrheXQAAAXo"]
[Thu Jul 30 15:00:48.139627 2026] [security2:error] [pid 89520:tid 89712] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/aabb.php"] [unique_id "amutcC0W4wRrtnDoPaj4twAAAcA"]
[Thu Jul 30 15:00:48.139752 2026] [security2:error] [pid 89520:tid 89712] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/aabb.php"] [unique_id "amutcC0W4wRrtnDoPaj4twAAAcA"]
[Thu Jul 30 15:00:48.436286 2026] [security2:error] [pid 87988:tid 88169] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/1254xx.php"] [unique_id "amutcDipAwzptuCxBrheZQAAAT0"]
[Thu Jul 30 15:00:48.436385 2026] [security2:error] [pid 87988:tid 88169] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/1254xx.php"] [unique_id "amutcDipAwzptuCxBrheZQAAAT0"]
[Thu Jul 30 15:00:48.449796 2026] [security2:error] [pid 87988:tid 88206] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/mg.php"] [unique_id "amutcDipAwzptuCxBrheZgAAAWI"]
[Thu Jul 30 15:00:48.449876 2026] [security2:error] [pid 87988:tid 88206] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/mg.php"] [unique_id "amutcDipAwzptuCxBrheZgAAAWI"]
[Thu Jul 30 15:00:48.547862 2026] [security2:error] [pid 87988:tid 88191] [client 20.100.187.246:19737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amutcDipAwzptuCxBrheaAAAAVM"]
[Thu Jul 30 15:00:48.747922 2026] [security2:error] [pid 87988:tid 88172] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amutcDipAwzptuCxBrheawAAAUA"]
[Thu Jul 30 15:00:48.748033 2026] [security2:error] [pid 87988:tid 88172] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amutcDipAwzptuCxBrheawAAAUA"]
[Thu Jul 30 15:00:48.931278 2026] [core:error] [pid 89520:tid 89783] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:48.931299 2026] [core:error] [pid 89520:tid 89783] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:49.011993 2026] [security2:error] [pid 89520:tid 89693] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fnstall.php"] [unique_id "amutcS0W4wRrtnDoPaj4wAAAAa0"]
[Thu Jul 30 15:00:49.012095 2026] [security2:error] [pid 89520:tid 89693] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fnstall.php"] [unique_id "amutcS0W4wRrtnDoPaj4wAAAAa0"]
[Thu Jul 30 15:00:49.041752 2026] [security2:error] [pid 89520:tid 89703] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/pms297.php"] [unique_id "amutcS0W4wRrtnDoPaj4wQAAAbc"]
[Thu Jul 30 15:00:49.041830 2026] [security2:error] [pid 89520:tid 89703] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/pms297.php"] [unique_id "amutcS0W4wRrtnDoPaj4wQAAAbc"]
[Thu Jul 30 15:00:49.101235 2026] [core:notice] [pid 87988:tid 88153] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:49.345048 2026] [core:notice] [pid 87988:tid 88171] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:49.354629 2026] [security2:error] [pid 87988:tid 88224] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/1PJcpMFsD8B.php"] [unique_id "amutcTipAwzptuCxBrhefAAAAXQ"]
[Thu Jul 30 15:00:49.354714 2026] [security2:error] [pid 87988:tid 88224] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/1PJcpMFsD8B.php"] [unique_id "amutcTipAwzptuCxBrhefAAAAXQ"]
[Thu Jul 30 15:00:49.524502 2026] [security2:error] [pid 89520:tid 89756] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ortasekerli1.php"] [unique_id "amutcS0W4wRrtnDoPaj4xgAAAew"]
[Thu Jul 30 15:00:49.524611 2026] [security2:error] [pid 89520:tid 89756] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ortasekerli1.php"] [unique_id "amutcS0W4wRrtnDoPaj4xgAAAew"]
[Thu Jul 30 15:00:49.580786 2026] [security2:error] [pid 87988:tid 88087] [remote 57.141.0.70:26720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amutcTipAwzptuCxBrhegQABe2I"]
[Thu Jul 30 15:00:49.645736 2026] [security2:error] [pid 89520:tid 89766] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/4PJcpMFsD8B.php"] [unique_id "amutcS0W4wRrtnDoPaj4xwAAAfY"]
[Thu Jul 30 15:00:49.645846 2026] [security2:error] [pid 89520:tid 89766] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/4PJcpMFsD8B.php"] [unique_id "amutcS0W4wRrtnDoPaj4xwAAAfY"]
[Thu Jul 30 15:00:49.918278 2026] [security2:error] [pid 89520:tid 89677] [client 20.100.187.246:43459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-admin/xleet.php"] [unique_id "amutcS0W4wRrtnDoPaj4zgAAAZ0"]
[Thu Jul 30 15:00:49.935464 2026] [core:notice] [pid 89520:tid 89749] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:49.989926 2026] [core:notice] [pid 87988:tid 88221] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:50.012270 2026] [security2:error] [pid 89520:tid 89726] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amutci0W4wRrtnDoPaj40gAAAc4"]
[Thu Jul 30 15:00:50.012426 2026] [security2:error] [pid 89520:tid 89726] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amutci0W4wRrtnDoPaj40gAAAc4"]
[Thu Jul 30 15:00:50.064675 2026] [security2:error] [pid 89520:tid 89688] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sump1.php"] [unique_id "amutci0W4wRrtnDoPaj40wAAAag"]
[Thu Jul 30 15:00:50.064797 2026] [security2:error] [pid 89520:tid 89688] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sump1.php"] [unique_id "amutci0W4wRrtnDoPaj40wAAAag"]
[Thu Jul 30 15:00:50.306716 2026] [security2:error] [pid 87988:tid 88216] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amutcjipAwzptuCxBrhehwAAAWw"]
[Thu Jul 30 15:00:50.306829 2026] [security2:error] [pid 87988:tid 88216] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amutcjipAwzptuCxBrhehwAAAWw"]
[Thu Jul 30 15:00:50.538899 2026] [security2:error] [pid 87988:tid 88237] [client 20.203.148.31:27387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/classwithtostring.php"] [unique_id "amutcjipAwzptuCxBrheiwAAAYE"]
[Thu Jul 30 15:00:50.571097 2026] [security2:error] [pid 89520:tid 89736] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutcS0W4wRrtnDoPaj4yAAB2Gk"]
[Thu Jul 30 15:00:50.588647 2026] [security2:error] [pid 89520:tid 89774] [client 135.119.63.61:49624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-users.php"] [unique_id "amutci0W4wRrtnDoPaj42QAAAf4"]
[Thu Jul 30 15:00:50.600792 2026] [security2:error] [pid 89520:tid 89730] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/dyui.php"] [unique_id "amutci0W4wRrtnDoPaj42gAAAdI"]
[Thu Jul 30 15:00:50.600908 2026] [security2:error] [pid 89520:tid 89730] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/dyui.php"] [unique_id "amutci0W4wRrtnDoPaj42gAAAdI"]
[Thu Jul 30 15:00:50.663122 2026] [security2:error] [pid 89520:tid 89763] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ops.php"] [unique_id "amutci0W4wRrtnDoPaj42wAAAfM"]
[Thu Jul 30 15:00:50.663234 2026] [security2:error] [pid 89520:tid 89763] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ops.php"] [unique_id "amutci0W4wRrtnDoPaj42wAAAfM"]
[Thu Jul 30 15:00:50.775938 2026] [core:notice] [pid 89520:tid 89668] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:50.957448 2026] [security2:error] [pid 89520:tid 89747] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/ho.php"] [unique_id "amutci0W4wRrtnDoPaj43wAAAeM"]
[Thu Jul 30 15:00:50.957575 2026] [security2:error] [pid 89520:tid 89747] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/ho.php"] [unique_id "amutci0W4wRrtnDoPaj43wAAAeM"]
[Thu Jul 30 15:00:51.229289 2026] [security2:error] [pid 87988:tid 88124] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-post-data.php"] [unique_id "amutczipAwzptuCxBrhemAAAARA"]
[Thu Jul 30 15:00:51.229405 2026] [security2:error] [pid 87988:tid 88124] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-post-data.php"] [unique_id "amutczipAwzptuCxBrhemAAAARA"]
[Thu Jul 30 15:00:51.250187 2026] [security2:error] [pid 89520:tid 89746] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/66b867516c8f01.php"] [unique_id "amutcy0W4wRrtnDoPaj44wAAAeI"]
[Thu Jul 30 15:00:51.250290 2026] [security2:error] [pid 89520:tid 89746] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/66b867516c8f01.php"] [unique_id "amutcy0W4wRrtnDoPaj44wAAAeI"]
[Thu Jul 30 15:00:51.431831 2026] [security2:error] [pid 87988:tid 88050] [remote 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutcjipAwzptuCxBrhekQABYT0"]
[Thu Jul 30 15:00:51.607122 2026] [security2:error] [pid 89520:tid 89762] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/ext.php"] [unique_id "amutcy0W4wRrtnDoPaj45AAAAfI"]
[Thu Jul 30 15:00:51.607235 2026] [security2:error] [pid 89520:tid 89762] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/ext.php"] [unique_id "amutcy0W4wRrtnDoPaj45AAAAfI"]
[Thu Jul 30 15:00:51.668747 2026] [security2:error] [pid 89520:tid 89697] [client 20.100.187.246:19379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-config-sample.php"] [unique_id "amutcy0W4wRrtnDoPaj45gAAAbE"]
[Thu Jul 30 15:00:51.709082 2026] [security2:error] [pid 89520:tid 89638] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutcy0W4wRrtnDoPaj46AAB-mo"]
[Thu Jul 30 15:00:51.709205 2026] [security2:error] [pid 89520:tid 89770] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutcy0W4wRrtnDoPaj46AAB-mo"]
[Thu Jul 30 15:00:51.717122 2026] [security2:error] [pid 87988:tid 88168] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutczipAwzptuCxBrhelQAAATw"]
[Thu Jul 30 15:00:51.764500 2026] [security2:error] [pid 89520:tid 89671] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/root.php"] [unique_id "amutcy0W4wRrtnDoPaj46QAAAZc"]
[Thu Jul 30 15:00:51.764616 2026] [security2:error] [pid 89520:tid 89671] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/root.php"] [unique_id "amutcy0W4wRrtnDoPaj46QAAAZc"]
[Thu Jul 30 15:00:51.789377 2026] [security2:error] [pid 89520:tid 89667] [client 20.203.148.31:19296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/content.php"] [unique_id "amutcy0W4wRrtnDoPaj46gAAAZM"]
[Thu Jul 30 15:00:51.851139 2026] [core:notice] [pid 87988:tid 88053] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:51.875043 2026] [core:notice] [pid 89520:tid 89642] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:51.881597 2026] [core:notice] [pid 87988:tid 88051] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:51.910095 2026] [security2:error] [pid 89520:tid 89757] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amutcy0W4wRrtnDoPaj47QAAAe0"]
[Thu Jul 30 15:00:51.910175 2026] [security2:error] [pid 89520:tid 89757] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amutcy0W4wRrtnDoPaj47QAAAe0"]
[Thu Jul 30 15:00:51.952291 2026] [core:notice] [pid 87988:tid 88080] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:51.956439 2026] [core:notice] [pid 89520:tid 89652] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:52.143953 2026] [core:notice] [pid 87988:tid 88081] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:52.295797 2026] [security2:error] [pid 89520:tid 89696] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/v543.php"] [unique_id "amutdC0W4wRrtnDoPaj48QAAAbA"]
[Thu Jul 30 15:00:52.295906 2026] [security2:error] [pid 89520:tid 89696] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/v543.php"] [unique_id "amutdC0W4wRrtnDoPaj48QAAAbA"]
[Thu Jul 30 15:00:52.389056 2026] [security2:error] [pid 89520:tid 89758] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amutdC0W4wRrtnDoPaj48wAAAe4"]
[Thu Jul 30 15:00:52.389165 2026] [security2:error] [pid 89520:tid 89758] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amutdC0W4wRrtnDoPaj48wAAAe4"]
[Thu Jul 30 15:00:52.434199 2026] [core:error] [pid 89520:tid 89651] [remote 104.210.140.138:28786] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:52.434236 2026] [core:error] [pid 89520:tid 89651] [remote 104.210.140.138:28786] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:52.694065 2026] [security2:error] [pid 89520:tid 89717] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/584062352875874akp.php"] [unique_id "amutdC0W4wRrtnDoPaj4-AAAAcU"]
[Thu Jul 30 15:00:52.694194 2026] [security2:error] [pid 89520:tid 89717] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/584062352875874akp.php"] [unique_id "amutdC0W4wRrtnDoPaj4-AAAAcU"]
[Thu Jul 30 15:00:52.870859 2026] [security2:error] [pid 87988:tid 88172] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sixxis.php"] [unique_id "amutdDipAwzptuCxBrhesAAAAUA"]
[Thu Jul 30 15:00:52.870971 2026] [security2:error] [pid 87988:tid 88172] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sixxis.php"] [unique_id "amutdDipAwzptuCxBrhesAAAAUA"]
[Thu Jul 30 15:00:52.988794 2026] [security2:error] [pid 89520:tid 89689] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/diidi.php"] [unique_id "amutdC0W4wRrtnDoPaj4-gAAAak"]
[Thu Jul 30 15:00:52.988891 2026] [security2:error] [pid 89520:tid 89689] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/diidi.php"] [unique_id "amutdC0W4wRrtnDoPaj4-gAAAak"]
[Thu Jul 30 15:00:53.090300 2026] [core:notice] [pid 89520:tid 89654] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:53.156385 2026] [core:notice] [pid 89520:tid 89655] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:53.312186 2026] [security2:error] [pid 89520:tid 89693] [client 20.91.208.34:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.208.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dubaiappliance.repair"] [uri "/clarebypas.php"] [unique_id "amutdS0W4wRrtnDoPaj4_wAAAa0"]
[Thu Jul 30 15:00:53.312296 2026] [security2:error] [pid 89520:tid 89693] [client 20.91.208.34:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.dubaiappliance.repair"] [uri "/clarebypas.php"] [unique_id "amutdS0W4wRrtnDoPaj4_wAAAa0"]
[Thu Jul 30 15:00:53.359456 2026] [core:notice] [pid 89520:tid 89780] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:53.448914 2026] [security2:error] [pid 89520:tid 89686] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ip.php"] [unique_id "amutdS0W4wRrtnDoPaj5AgAAAaY"]
[Thu Jul 30 15:00:53.449039 2026] [security2:error] [pid 89520:tid 89686] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ip.php"] [unique_id "amutdS0W4wRrtnDoPaj5AgAAAaY"]
[Thu Jul 30 15:00:53.595846 2026] [security2:error] [pid 87988:tid 88233] [client 135.119.63.61:27714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-ver.php"] [unique_id "amutdTipAwzptuCxBrhevwAAAX0"]
[Thu Jul 30 15:00:53.810442 2026] [security2:error] [pid 87988:tid 88171] [client 20.203.148.31:20624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/doc.php"] [unique_id "amutdTipAwzptuCxBrhewgAAAT8"]
[Thu Jul 30 15:00:54.027102 2026] [security2:error] [pid 89520:tid 89683] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/kq1.php"] [unique_id "amutdi0W4wRrtnDoPaj5BQAAAaM"]
[Thu Jul 30 15:00:54.027192 2026] [security2:error] [pid 89520:tid 89683] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/kq1.php"] [unique_id "amutdi0W4wRrtnDoPaj5BQAAAaM"]
[Thu Jul 30 15:00:54.525116 2026] [core:notice] [pid 89520:tid 89687] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:54.538185 2026] [security2:error] [pid 89520:tid 89777] [client 135.119.63.61:53837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-we.php"] [unique_id "amutdi0W4wRrtnDoPaj5CQAAAgE"]
[Thu Jul 30 15:00:54.601108 2026] [security2:error] [pid 89520:tid 89672] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fw/faiyy.php"] [unique_id "amutdi0W4wRrtnDoPaj5DQAAAZg"]
[Thu Jul 30 15:00:54.601220 2026] [security2:error] [pid 89520:tid 89672] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fw/faiyy.php"] [unique_id "amutdi0W4wRrtnDoPaj5DQAAAZg"]
[Thu Jul 30 15:00:54.604760 2026] [security2:error] [pid 87988:tid 88164] [client 20.203.148.31:20668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/dropdown.php"] [unique_id "amutdjipAwzptuCxBrhezQAAATg"]
[Thu Jul 30 15:00:54.650597 2026] [core:notice] [pid 89520:tid 89660] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:54.706063 2026] [autoindex:error] [pid 87988:tid 88120] [client 192.36.109.99:40387] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:00:55.153785 2026] [security2:error] [pid 87988:tid 88174] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/h02ugyh.php"] [unique_id "amutdzipAwzptuCxBrhe2QAAAUI"]
[Thu Jul 30 15:00:55.153876 2026] [security2:error] [pid 87988:tid 88174] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/h02ugyh.php"] [unique_id "amutdzipAwzptuCxBrhe2QAAAUI"]
[Thu Jul 30 15:00:55.324252 2026] [core:notice] [pid 87988:tid 88078] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:55.337217 2026] [security2:error] [pid 89520:tid 89680] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutdi0W4wRrtnDoPaj5EgAAAaA"]
[Thu Jul 30 15:00:55.462350 2026] [security2:error] [pid 89520:tid 89710] [client 135.119.63.61:49628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-widgets.php"] [unique_id "amutdy0W4wRrtnDoPaj5FgAAAb4"]
[Thu Jul 30 15:00:55.699551 2026] [security2:error] [pid 89520:tid 89786] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-temp.php"] [unique_id "amutdy0W4wRrtnDoPaj5GwAAAgo"]
[Thu Jul 30 15:00:55.699646 2026] [security2:error] [pid 89520:tid 89786] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-temp.php"] [unique_id "amutdy0W4wRrtnDoPaj5GwAAAgo"]
[Thu Jul 30 15:00:56.236252 2026] [security2:error] [pid 87988:tid 88201] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/cong.php"] [unique_id "amuteDipAwzptuCxBrhe6gAAAV0"]
[Thu Jul 30 15:00:56.236347 2026] [security2:error] [pid 87988:tid 88201] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/cong.php"] [unique_id "amuteDipAwzptuCxBrhe6gAAAV0"]
[Thu Jul 30 15:00:56.362245 2026] [core:error] [pid 87988:tid 88198] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:56.362269 2026] [core:error] [pid 87988:tid 88198] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:00:56.537415 2026] [security2:error] [pid 89520:tid 89762] [client 135.119.63.61:49657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-work.php"] [unique_id "amuteC0W4wRrtnDoPaj5IQAAAfI"]
[Thu Jul 30 15:00:56.734146 2026] [core:notice] [pid 89520:tid 89779] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:56.773783 2026] [security2:error] [pid 87988:tid 88195] [client 52.165.196.84:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/js/widget/"] [unique_id "amuteDipAwzptuCxBrhe9AAAAVc"]
[Thu Jul 30 15:00:56.773885 2026] [security2:error] [pid 87988:tid 88195] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/js/widget/"] [unique_id "amuteDipAwzptuCxBrhe9AAAAVc"]
[Thu Jul 30 15:00:56.876741 2026] [security2:error] [pid 89520:tid 89747] [client 20.203.148.31:27353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/ee.php"] [unique_id "amuteC0W4wRrtnDoPaj5IwAAAeM"]
[Thu Jul 30 15:00:57.366529 2026] [security2:error] [pid 87988:tid 88121] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/css/index.php"] [unique_id "amuteTipAwzptuCxBrhe_wAAAQ0"]
[Thu Jul 30 15:00:57.366731 2026] [security2:error] [pid 87988:tid 88121] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/css/index.php"] [unique_id "amuteTipAwzptuCxBrhe_wAAAQ0"]
[Thu Jul 30 15:00:57.454206 2026] [security2:error] [pid 87988:tid 88240] [client 172.237.109.114:17493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuteDipAwzptuCxBrhe-AAAAYQ"]
[Thu Jul 30 15:00:57.457120 2026] [core:notice] [pid 89520:tid 89755] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:00:57.687694 2026] [security2:error] [pid 89520:tid 89759] [client 20.203.148.31:14577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/flower.php"] [unique_id "amuteS0W4wRrtnDoPaj5KQAAAe8"]
[Thu Jul 30 15:00:57.871524 2026] [security2:error] [pid 89520:tid 89712] [client 78.47.42.23:39294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/sitemap_index.xml"] [unique_id "amuteS0W4wRrtnDoPaj5KwAAAcA"]
[Thu Jul 30 15:00:57.986718 2026] [security2:error] [pid 87988:tid 88239] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/jj.php"] [unique_id "amuteTipAwzptuCxBrhfBQAAAYM"]
[Thu Jul 30 15:00:57.986818 2026] [security2:error] [pid 87988:tid 88239] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/jj.php"] [unique_id "amuteTipAwzptuCxBrhfBQAAAYM"]
[Thu Jul 30 15:00:58.147240 2026] [security2:error] [pid 89520:tid 89689] [client 78.47.42.23:39306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/sitemap_index.xml"] [unique_id "amutei0W4wRrtnDoPaj5LgAAAak"]
[Thu Jul 30 15:00:58.339718 2026] [security2:error] [pid 87988:tid 87992] [remote 216.73.216.51:22857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amutejipAwzptuCxBrhfDAABWAM"]
[Thu Jul 30 15:00:58.618355 2026] [security2:error] [pid 89520:tid 89780] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/class-walker-footer-dev.php"] [unique_id "amutei0W4wRrtnDoPaj5MgAAAgQ"]
[Thu Jul 30 15:00:58.618467 2026] [security2:error] [pid 89520:tid 89780] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/class-walker-footer-dev.php"] [unique_id "amutei0W4wRrtnDoPaj5MgAAAgQ"]
[Thu Jul 30 15:00:58.957419 2026] [security2:error] [pid 87988:tid 88188] [client 135.119.63.61:49637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-wso.php"] [unique_id "amutejipAwzptuCxBrhfFwAAAVA"]
[Thu Jul 30 15:00:59.222272 2026] [security2:error] [pid 87988:tid 88200] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xpwer1.php"] [unique_id "amutezipAwzptuCxBrhfGwAAAVw"]
[Thu Jul 30 15:00:59.222402 2026] [security2:error] [pid 87988:tid 88200] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xpwer1.php"] [unique_id "amutezipAwzptuCxBrhfGwAAAVw"]
[Thu Jul 30 15:00:59.285648 2026] [security2:error] [pid 89520:tid 89694] [client 43.173.71.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amutey0W4wRrtnDoPaj5OAAAAa4"]
[Thu Jul 30 15:00:59.368994 2026] [security2:error] [pid 87988:tid 88150] [client 20.203.148.31:19310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/gecko-new.php"] [unique_id "amutezipAwzptuCxBrhfIQAAASo"]
[Thu Jul 30 15:00:59.759201 2026] [security2:error] [pid 89520:tid 89733] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/flox.php"] [unique_id "amutey0W4wRrtnDoPaj5PgAAAdU"]
[Thu Jul 30 15:00:59.759318 2026] [security2:error] [pid 89520:tid 89733] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/flox.php"] [unique_id "amutey0W4wRrtnDoPaj5PgAAAdU"]
[Thu Jul 30 15:00:59.865629 2026] [security2:error] [pid 89520:tid 89672] [client 135.119.63.61:27753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp-xml.php"] [unique_id "amutey0W4wRrtnDoPaj5QAAAAZg"]
[Thu Jul 30 15:00:59.928496 2026] [security2:error] [pid 89520:tid 89790] [client 78.47.42.23:39314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/sitemap_index.xml"] [unique_id "amutey0W4wRrtnDoPaj5QwAAAg4"]
[Thu Jul 30 15:00:59.930447 2026] [security2:error] [pid 87988:tid 88182] [client 20.203.148.31:27197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/m.php"] [unique_id "amutezipAwzptuCxBrhfKgAAAUo"]
[Thu Jul 30 15:01:00.330991 2026] [security2:error] [pid 87988:tid 88218] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/popo.php"] [unique_id "amutfDipAwzptuCxBrhfLwAAAW4"]
[Thu Jul 30 15:01:00.331135 2026] [security2:error] [pid 87988:tid 88218] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/popo.php"] [unique_id "amutfDipAwzptuCxBrhfLwAAAW4"]
[Thu Jul 30 15:01:00.394158 2026] [security2:error] [pid 87988:tid 88198] [client 50.6.43.217:32382] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amutfDipAwzptuCxBrhfMgAAAVo"]
[Thu Jul 30 15:01:00.545297 2026] [security2:error] [pid 89520:tid 89750] [client 50.6.43.217:32386] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amutfC0W4wRrtnDoPaj5SwAAAeY"]
[Thu Jul 30 15:01:00.902346 2026] [security2:error] [pid 87988:tid 88123] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/yas.php"] [unique_id "amutfDipAwzptuCxBrhfPwAAAQ8"]
[Thu Jul 30 15:01:00.902443 2026] [security2:error] [pid 87988:tid 88123] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/yas.php"] [unique_id "amutfDipAwzptuCxBrhfPwAAAQ8"]
[Thu Jul 30 15:01:01.262710 2026] [security2:error] [pid 87988:tid 88206] [client 135.119.63.61:27755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp.php"] [unique_id "amutfTipAwzptuCxBrhfSwAAAWI"]
[Thu Jul 30 15:01:01.367132 2026] [security2:error] [pid 89520:tid 89725] [client 20.203.148.31:27376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/mah/autoload_classmap.php"] [unique_id "amutfS0W4wRrtnDoPaj5VAAAAc0"]
[Thu Jul 30 15:01:01.452658 2026] [security2:error] [pid 89520:tid 89670] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/water.php"] [unique_id "amutfS0W4wRrtnDoPaj5VQAAAZY"]
[Thu Jul 30 15:01:01.452746 2026] [security2:error] [pid 89520:tid 89670] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/water.php"] [unique_id "amutfS0W4wRrtnDoPaj5VQAAAZY"]
[Thu Jul 30 15:01:01.988806 2026] [security2:error] [pid 89520:tid 89748] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/nano.php"] [unique_id "amutfS0W4wRrtnDoPaj5YAAAAeQ"]
[Thu Jul 30 15:01:01.988899 2026] [security2:error] [pid 89520:tid 89748] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/nano.php"] [unique_id "amutfS0W4wRrtnDoPaj5YAAAAeQ"]
[Thu Jul 30 15:01:02.069744 2026] [security2:error] [pid 89520:tid 89728] [client 20.203.148.31:19311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/mah/flower.php"] [unique_id "amutfi0W4wRrtnDoPaj5YgAAAdA"]
[Thu Jul 30 15:01:02.317454 2026] [security2:error] [pid 89520:tid 89542] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutfi0W4wRrtnDoPaj5aQABmgw"]
[Thu Jul 30 15:01:02.317636 2026] [security2:error] [pid 89520:tid 89674] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutfi0W4wRrtnDoPaj5aQABmgw"]
[Thu Jul 30 15:01:02.496381 2026] [security2:error] [pid 89520:tid 89788] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/moon.php"] [unique_id "amutfi0W4wRrtnDoPaj5bAAAAgw"]
[Thu Jul 30 15:01:02.496476 2026] [security2:error] [pid 89520:tid 89788] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/moon.php"] [unique_id "amutfi0W4wRrtnDoPaj5bAAAAgw"]
[Thu Jul 30 15:01:02.695654 2026] [security2:error] [pid 89520:tid 89706] [client 135.119.63.61:27768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp2.php"] [unique_id "amutfi0W4wRrtnDoPaj5cQAAAbo"]
[Thu Jul 30 15:01:02.849081 2026] [security2:error] [pid 87988:tid 88144] [client 20.203.148.31:12728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/mah/xleet.php"] [unique_id "amutfjipAwzptuCxBrhfYgAAASQ"]
[Thu Jul 30 15:01:03.061313 2026] [security2:error] [pid 87988:tid 88192] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-info.php"] [unique_id "amutfzipAwzptuCxBrhfaAAAAVQ"]
[Thu Jul 30 15:01:03.061418 2026] [security2:error] [pid 87988:tid 88192] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-info.php"] [unique_id "amutfzipAwzptuCxBrhfaAAAAVQ"]
[Thu Jul 30 15:01:03.653486 2026] [security2:error] [pid 87988:tid 88204] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/file5.php"] [unique_id "amutfzipAwzptuCxBrhfcgAAAWA"]
[Thu Jul 30 15:01:03.653588 2026] [security2:error] [pid 87988:tid 88204] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/file5.php"] [unique_id "amutfzipAwzptuCxBrhfcgAAAWA"]
[Thu Jul 30 15:01:04.187364 2026] [security2:error] [pid 87988:tid 88184] [client 20.203.148.31:20663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/mini.php"] [unique_id "amutgDipAwzptuCxBrhfeAAAAUw"]
[Thu Jul 30 15:01:04.197349 2026] [security2:error] [pid 89520:tid 89737] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/2000.php"] [unique_id "amutgC0W4wRrtnDoPaj5hAAAAdk"]
[Thu Jul 30 15:01:04.197458 2026] [security2:error] [pid 89520:tid 89737] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/2000.php"] [unique_id "amutgC0W4wRrtnDoPaj5hAAAAdk"]
[Thu Jul 30 15:01:04.215965 2026] [security2:error] [pid 87988:tid 88205] [client 47.128.126.186:64796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "greensparkle.net"] [uri "/robots.txt"] [unique_id "amutgDipAwzptuCxBrhfeQAAAWE"]
[Thu Jul 30 15:01:04.651298 2026] [security2:error] [pid 87988:tid 88150] [client 135.119.63.61:53844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp_class_datalib.php"] [unique_id "amutgDipAwzptuCxBrhffgAAASo"]
[Thu Jul 30 15:01:04.729760 2026] [security2:error] [pid 89520:tid 89751] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/122.php"] [unique_id "amutgC0W4wRrtnDoPaj5igAAAec"]
[Thu Jul 30 15:01:04.729857 2026] [security2:error] [pid 89520:tid 89751] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/122.php"] [unique_id "amutgC0W4wRrtnDoPaj5igAAAec"]
[Thu Jul 30 15:01:05.246782 2026] [security2:error] [pid 89520:tid 89761] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/mds.php"] [unique_id "amutgS0W4wRrtnDoPaj5kgAAAfE"]
[Thu Jul 30 15:01:05.246863 2026] [security2:error] [pid 89520:tid 89761] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/mds.php"] [unique_id "amutgS0W4wRrtnDoPaj5kgAAAfE"]
[Thu Jul 30 15:01:05.532681 2026] [security2:error] [pid 89520:tid 89555] [remote 57.141.0.22:36590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amutgS0W4wRrtnDoPaj5lgAB3hk"]
[Thu Jul 30 15:01:05.823109 2026] [security2:error] [pid 89520:tid 89787] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/zc-208.php"] [unique_id "amutgS0W4wRrtnDoPaj5mwAAAgs"]
[Thu Jul 30 15:01:05.823210 2026] [security2:error] [pid 89520:tid 89787] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/zc-208.php"] [unique_id "amutgS0W4wRrtnDoPaj5mwAAAgs"]
[Thu Jul 30 15:01:05.959232 2026] [core:notice] [pid 89520:tid 89670] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:06.048645 2026] [security2:error] [pid 89520:tid 89767] [client 20.203.148.31:23207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/moon.php"] [unique_id "amutgi0W4wRrtnDoPaj5nwAAAfc"]
[Thu Jul 30 15:01:06.236449 2026] [security2:error] [pid 89520:tid 89557] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/app/config/local.php"] [unique_id "amutgi0W4wRrtnDoPaj5ogABwRs"]
[Thu Jul 30 15:01:06.285274 2026] [security2:error] [pid 87988:tid 88245] [client 213.152.161.20:37990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amutgjipAwzptuCxBrhfjgAAAYk"]
[Thu Jul 30 15:01:06.285385 2026] [security2:error] [pid 87988:tid 88245] [client 213.152.161.20:37990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amutgjipAwzptuCxBrhfjgAAAYk"]
[Thu Jul 30 15:01:06.397379 2026] [core:notice] [pid 89520:tid 89729] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:06.400698 2026] [security2:error] [pid 87988:tid 88235] [client 135.119.63.61:27746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp_class_datlib.php"] [unique_id "amutgjipAwzptuCxBrhfmAAAAX8"]
[Thu Jul 30 15:01:06.403550 2026] [security2:error] [pid 89520:tid 89752] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sid4.php"] [unique_id "amutgi0W4wRrtnDoPaj5pAAAAeg"]
[Thu Jul 30 15:01:06.403628 2026] [security2:error] [pid 89520:tid 89752] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sid4.php"] [unique_id "amutgi0W4wRrtnDoPaj5pAAAAeg"]
[Thu Jul 30 15:01:06.428909 2026] [security2:error] [pid 89520:tid 89561] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/app/config/local.php.bak"] [unique_id "amutgi0W4wRrtnDoPaj5pgAB5B8"]
[Thu Jul 30 15:01:06.624519 2026] [security2:error] [pid 89520:tid 89661] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/mautic/app/config/local.php"] [unique_id "amutgi0W4wRrtnDoPaj5pwAB0H8"]
[Thu Jul 30 15:01:06.981900 2026] [security2:error] [pid 87988:tid 88146] [client 52.165.196.84:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/l10n/"] [unique_id "amutgjipAwzptuCxBrhfowAAASY"]
[Thu Jul 30 15:01:06.982024 2026] [security2:error] [pid 87988:tid 88146] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/l10n/"] [unique_id "amutgjipAwzptuCxBrhfowAAASY"]
[Thu Jul 30 15:01:07.148835 2026] [security2:error] [pid 89520:tid 89649] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/config/mail.php"] [unique_id "amutgy0W4wRrtnDoPaj5sQAB13M"]
[Thu Jul 30 15:01:07.244493 2026] [core:notice] [pid 87988:tid 88165] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:07.324005 2026] [security2:error] [pid 89520:tid 89658] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.prolineroofingservices.homes"] [uri "/config/services.php"] [unique_id "amutgy0W4wRrtnDoPaj5swAB3Xw"]
[Thu Jul 30 15:01:07.502515 2026] [core:notice] [pid 87988:tid 88188] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:07.541439 2026] [security2:error] [pid 89520:tid 89771] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wmore1.php"] [unique_id "amutgy0W4wRrtnDoPaj5tQAAAfs"]
[Thu Jul 30 15:01:07.541547 2026] [security2:error] [pid 89520:tid 89771] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wmore1.php"] [unique_id "amutgy0W4wRrtnDoPaj5tQAAAfs"]
[Thu Jul 30 15:01:07.584676 2026] [security2:error] [pid 87988:tid 88119] [client 20.203.148.31:23182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/new.php"] [unique_id "amutgzipAwzptuCxBrhfrQAAAQs"]
[Thu Jul 30 15:01:07.797919 2026] [security2:error] [pid 87988:tid 88166] [client 135.119.63.61:49610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp_fma.php"] [unique_id "amutgzipAwzptuCxBrhfsAAAATo"]
[Thu Jul 30 15:01:07.812401 2026] [core:notice] [pid 87988:tid 88128] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:07.938191 2026] [core:notice] [pid 87988:tid 88142] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:08.089388 2026] [security2:error] [pid 89520:tid 89694] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/solo1.php"] [unique_id "amuthC0W4wRrtnDoPaj5vgAAAa4"]
[Thu Jul 30 15:01:08.089499 2026] [security2:error] [pid 89520:tid 89694] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/solo1.php"] [unique_id "amuthC0W4wRrtnDoPaj5vgAAAa4"]
[Thu Jul 30 15:01:08.497362 2026] [security2:error] [pid 89520:tid 89676] [client 172.237.109.114:42745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuthC0W4wRrtnDoPaj5vQAAAZw"]
[Thu Jul 30 15:01:08.622114 2026] [security2:error] [pid 89520:tid 89715] [client 135.119.63.61:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp_wlx.php"] [unique_id "amuthC0W4wRrtnDoPaj5wgAAAcM"]
[Thu Jul 30 15:01:08.670672 2026] [security2:error] [pid 89520:tid 89749] [client 52.165.196.84:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/assets/"] [unique_id "amuthC0W4wRrtnDoPaj5wwAAAeU"]
[Thu Jul 30 15:01:08.670807 2026] [security2:error] [pid 89520:tid 89749] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/assets/"] [unique_id "amuthC0W4wRrtnDoPaj5wwAAAeU"]
[Thu Jul 30 15:01:08.688726 2026] [core:notice] [pid 89520:tid 89777] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:08.831424 2026] [security2:error] [pid 89520:tid 89663] [client 20.203.148.31:19273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/radio.php"] [unique_id "amuthC0W4wRrtnDoPaj5yQAAAY8"]
[Thu Jul 30 15:01:08.948015 2026] [core:notice] [pid 87988:tid 88150] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:09.267575 2026] [security2:error] [pid 87988:tid 88170] [client 52.165.196.84:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/css/"] [unique_id "amuthTipAwzptuCxBrhf3AAAAT4"]
[Thu Jul 30 15:01:09.267682 2026] [security2:error] [pid 87988:tid 88170] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/css/"] [unique_id "amuthTipAwzptuCxBrhf3AAAAT4"]
[Thu Jul 30 15:01:09.481141 2026] [security2:error] [pid 87988:tid 88169] [client 135.119.63.61:53828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp_wol.php"] [unique_id "amuthTipAwzptuCxBrhf4gAAAT0"]
[Thu Jul 30 15:01:09.499578 2026] [security2:error] [pid 89520:tid 89731] [client 20.203.148.31:17846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/s.php"] [unique_id "amuthS0W4wRrtnDoPaj50QAAAdM"]
[Thu Jul 30 15:01:09.838198 2026] [security2:error] [pid 87988:tid 88132] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/public/css.php"] [unique_id "amuthTipAwzptuCxBrhf7AAAARg"]
[Thu Jul 30 15:01:09.838288 2026] [security2:error] [pid 87988:tid 88132] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/public/css.php"] [unique_id "amuthTipAwzptuCxBrhf7AAAARg"]
[Thu Jul 30 15:01:10.185028 2026] [security2:error] [pid 87988:tid 88244] [client 135.119.63.61:55938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/file_uploadsadmin.php"] [unique_id "amuthjipAwzptuCxBrhf8gAAAYg"]
[Thu Jul 30 15:01:10.278606 2026] [core:notice] [pid 87988:tid 88171] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:10.326883 2026] [security2:error] [pid 87988:tid 88227] [client 135.119.63.61:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wp_wrong_datlib.php"] [unique_id "amuthjipAwzptuCxBrhf9QAAAXc"]
[Thu Jul 30 15:01:10.416733 2026] [security2:error] [pid 89520:tid 89770] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/output.php"] [unique_id "amuthi0W4wRrtnDoPaj52gAAAfo"]
[Thu Jul 30 15:01:10.416858 2026] [security2:error] [pid 89520:tid 89770] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/output.php"] [unique_id "amuthi0W4wRrtnDoPaj52gAAAfo"]
[Thu Jul 30 15:01:10.468764 2026] [core:notice] [pid 87988:tid 88181] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:10.940277 2026] [security2:error] [pid 87988:tid 88149] [client 5.161.73.160:15540] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuthTipAwzptuCxBrhf6AAAASk"], referer: https://globalmarks.pk/
[Thu Jul 30 15:01:10.979016 2026] [security2:error] [pid 89520:tid 89700] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-file-120.php"] [unique_id "amuthi0W4wRrtnDoPaj55gAAAbQ"]
[Thu Jul 30 15:01:10.979127 2026] [security2:error] [pid 89520:tid 89700] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-file-120.php"] [unique_id "amuthi0W4wRrtnDoPaj55gAAAbQ"]
[Thu Jul 30 15:01:11.055567 2026] [core:notice] [pid 89520:tid 89564] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:11.364072 2026] [security2:error] [pid 89520:tid 89758] [client 57.141.0.56:26276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuthi0W4wRrtnDoPaj55wAB7iQ"], referer: https://igetvape-australia.com/product/iget-bar-strawberry-lemon-ice-3500-puffs/?add-to-cart=131
[Thu Jul 30 15:01:11.427429 2026] [security2:error] [pid 87988:tid 88155] [client 135.119.63.61:53872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpcall-button/button-image.php"] [unique_id "amuthzipAwzptuCxBrhf_wAAAS8"]
[Thu Jul 30 15:01:11.463759 2026] [security2:error] [pid 89520:tid 89724] [client 20.203.148.31:27183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/sim.php"] [unique_id "amuthy0W4wRrtnDoPaj56gAAAcw"]
[Thu Jul 30 15:01:11.560184 2026] [security2:error] [pid 89520:tid 89757] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/special.php"] [unique_id "amuthy0W4wRrtnDoPaj57AAAAe0"]
[Thu Jul 30 15:01:11.560289 2026] [security2:error] [pid 89520:tid 89757] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/special.php"] [unique_id "amuthy0W4wRrtnDoPaj57AAAAe0"]
[Thu Jul 30 15:01:11.725960 2026] [core:notice] [pid 89520:tid 89681] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:11.984349 2026] [core:notice] [pid 87988:tid 88226] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:12.142959 2026] [security2:error] [pid 89520:tid 89701] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/as.php"] [unique_id "amutiC0W4wRrtnDoPaj58wAAAbU"]
[Thu Jul 30 15:01:12.143065 2026] [security2:error] [pid 89520:tid 89701] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/as.php"] [unique_id "amutiC0W4wRrtnDoPaj58wAAAbU"]
[Thu Jul 30 15:01:12.587670 2026] [security2:error] [pid 89520:tid 89778] [client 135.119.63.61:27725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpcall-button/dropdown.php"] [unique_id "amutiC0W4wRrtnDoPaj59wAAAgI"]
[Thu Jul 30 15:01:12.644597 2026] [core:notice] [pid 89520:tid 89726] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:12.658772 2026] [security2:error] [pid 89520:tid 89715] [client 20.203.148.31:25753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/text.php"] [unique_id "amutiC0W4wRrtnDoPaj5-gAAAcM"]
[Thu Jul 30 15:01:12.730912 2026] [security2:error] [pid 89520:tid 89720] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/cgi-bin/index.php"] [unique_id "amutiC0W4wRrtnDoPaj5-wAAAcg"]
[Thu Jul 30 15:01:12.731070 2026] [security2:error] [pid 89520:tid 89720] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/cgi-bin/index.php"] [unique_id "amutiC0W4wRrtnDoPaj5-wAAAcg"]
[Thu Jul 30 15:01:12.775639 2026] [core:notice] [pid 87988:tid 88124] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:12.849643 2026] [core:notice] [pid 87988:tid 88166] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:12.853896 2026] [security2:error] [pid 87988:tid 88166] [client 66.249.79.1:46897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/view/1660"] [unique_id "amutiDipAwzptuCxBrhgDQAAATo"]
[Thu Jul 30 15:01:12.863487 2026] [security2:error] [pid 89520:tid 89567] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutiC0W4wRrtnDoPaj5_AAB2SU"]
[Thu Jul 30 15:01:12.863631 2026] [security2:error] [pid 89520:tid 89737] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutiC0W4wRrtnDoPaj5_AAB2SU"]
[Thu Jul 30 15:01:13.259713 2026] [security2:error] [pid 89520:tid 89750] [client 173.249.217.23:55484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.217.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amutiS0W4wRrtnDoPaj6AQAAAeY"]
[Thu Jul 30 15:01:13.259827 2026] [security2:error] [pid 89520:tid 89750] [client 173.249.217.23:55484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amutiS0W4wRrtnDoPaj6AQAAAeY"]
[Thu Jul 30 15:01:13.295241 2026] [security2:error] [pid 89520:tid 89722] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/w1px.php"] [unique_id "amutiS0W4wRrtnDoPaj6AgAAAco"]
[Thu Jul 30 15:01:13.295355 2026] [security2:error] [pid 89520:tid 89722] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/w1px.php"] [unique_id "amutiS0W4wRrtnDoPaj6AgAAAco"]
[Thu Jul 30 15:01:13.389008 2026] [security2:error] [pid 87988:tid 88222] [client 135.119.63.61:55965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/file_uploadsalfa.php"] [unique_id "amutiTipAwzptuCxBrhgGQAAAXI"]
[Thu Jul 30 15:01:13.418226 2026] [core:notice] [pid 87988:tid 88093] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:13.429284 2026] [security2:error] [pid 89520:tid 89668] [client 20.203.148.31:23752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/user.php"] [unique_id "amutiS0W4wRrtnDoPaj6BAAAAZQ"]
[Thu Jul 30 15:01:13.524000 2026] [security2:error] [pid 89520:tid 89774] [client 135.119.63.61:27771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpkey.php"] [unique_id "amutiS0W4wRrtnDoPaj6BQAAAf4"]
[Thu Jul 30 15:01:13.835433 2026] [security2:error] [pid 89520:tid 89746] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/js.php"] [unique_id "amutiS0W4wRrtnDoPaj6BwAAAeI"]
[Thu Jul 30 15:01:13.835494 2026] [security2:error] [pid 89520:tid 89682] [client 213.152.161.20:47018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amutiS0W4wRrtnDoPaj6CAAAAaI"]
[Thu Jul 30 15:01:13.835569 2026] [security2:error] [pid 89520:tid 89746] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/js.php"] [unique_id "amutiS0W4wRrtnDoPaj6BwAAAeI"]
[Thu Jul 30 15:01:13.835576 2026] [security2:error] [pid 89520:tid 89682] [client 213.152.161.20:47018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amutiS0W4wRrtnDoPaj6CAAAAaI"]
[Thu Jul 30 15:01:13.958872 2026] [security2:error] [pid 89520:tid 89698] [client 20.203.148.31:17807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/webadmin.php"] [unique_id "amutiS0W4wRrtnDoPaj6CgAAAbI"]
[Thu Jul 30 15:01:14.353179 2026] [security2:error] [pid 89520:tid 89671] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/core.php"] [unique_id "amutii0W4wRrtnDoPaj6DwAAAZc"]
[Thu Jul 30 15:01:14.353329 2026] [security2:error] [pid 89520:tid 89671] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/core.php"] [unique_id "amutii0W4wRrtnDoPaj6DwAAAZc"]
[Thu Jul 30 15:01:14.444172 2026] [security2:error] [pid 87988:tid 88130] [client 135.119.63.61:57929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/file_uploadsbypass.php"] [unique_id "amutijipAwzptuCxBrhgKgAAARY"]
[Thu Jul 30 15:01:14.657419 2026] [security2:error] [pid 87988:tid 88220] [client 135.119.63.61:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpn.php"] [unique_id "amutijipAwzptuCxBrhgLgAAAXA"]
[Thu Jul 30 15:01:14.820827 2026] [core:notice] [pid 89520:tid 89678] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:14.841103 2026] [security2:error] [pid 89520:tid 89697] [client 190.97.242.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutii0W4wRrtnDoPaj6DQABsSg"], referer: https://allmontecristi.com
[Thu Jul 30 15:01:14.887037 2026] [security2:error] [pid 87988:tid 88129] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fffm.php"] [unique_id "amutijipAwzptuCxBrhgMAAAARU"]
[Thu Jul 30 15:01:14.887149 2026] [security2:error] [pid 87988:tid 88129] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fffm.php"] [unique_id "amutijipAwzptuCxBrhgMAAAARU"]
[Thu Jul 30 15:01:14.953250 2026] [core:notice] [pid 87988:tid 88153] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:15.030725 2026] [security2:error] [pid 87988:tid 88172] [client 74.7.241.131:38910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.sameercom.store"] [uri "/robots.txt"] [unique_id "amutizipAwzptuCxBrhgNAABQHs"]
[Thu Jul 30 15:01:15.242505 2026] [core:notice] [pid 87988:tid 88245] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:15.444633 2026] [security2:error] [pid 89520:tid 89765] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ww.php"] [unique_id "amutiy0W4wRrtnDoPaj6GwAAAfU"]
[Thu Jul 30 15:01:15.444743 2026] [security2:error] [pid 89520:tid 89765] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ww.php"] [unique_id "amutiy0W4wRrtnDoPaj6GwAAAfU"]
[Thu Jul 30 15:01:15.489255 2026] [core:notice] [pid 87988:tid 88171] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:15.525247 2026] [core:notice] [pid 89520:tid 89573] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:15.846221 2026] [core:notice] [pid 89520:tid 89780] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:15.915838 2026] [security2:error] [pid 89520:tid 89717] [client 135.119.63.61:27749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpr-addons/forms/CasperSecurity.php"] [unique_id "amutiy0W4wRrtnDoPaj6KAAAAcU"]
[Thu Jul 30 15:01:15.983806 2026] [security2:error] [pid 89520:tid 89719] [client 20.203.148.31:14588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amutiy0W4wRrtnDoPaj6KQAAAcc"]
[Thu Jul 30 15:01:16.002506 2026] [security2:error] [pid 89520:tid 89727] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/domvf.php"] [unique_id "amutjC0W4wRrtnDoPaj6KgAAAc8"]
[Thu Jul 30 15:01:16.002650 2026] [security2:error] [pid 89520:tid 89727] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/domvf.php"] [unique_id "amutjC0W4wRrtnDoPaj6KgAAAc8"]
[Thu Jul 30 15:01:16.530289 2026] [security2:error] [pid 89520:tid 89720] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/echkm.php"] [unique_id "amutjC0W4wRrtnDoPaj6MQAAAcg"]
[Thu Jul 30 15:01:16.530443 2026] [security2:error] [pid 89520:tid 89720] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/echkm.php"] [unique_id "amutjC0W4wRrtnDoPaj6MQAAAcg"]
[Thu Jul 30 15:01:16.543964 2026] [core:notice] [pid 89520:tid 89663] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:16.568719 2026] [security2:error] [pid 89520:tid 89699] [client 135.119.63.61:9049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/file_uploadsk.php"] [unique_id "amutjC0W4wRrtnDoPaj6MwAAAbM"]
[Thu Jul 30 15:01:17.034755 2026] [security2:error] [pid 87988:tid 88237] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ano.php"] [unique_id "amutjTipAwzptuCxBrhgSgAAAYE"]
[Thu Jul 30 15:01:17.034879 2026] [security2:error] [pid 87988:tid 88237] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ano.php"] [unique_id "amutjTipAwzptuCxBrhgSgAAAYE"]
[Thu Jul 30 15:01:17.251987 2026] [security2:error] [pid 89520:tid 89723] [client 20.203.148.31:19713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amutjS0W4wRrtnDoPaj6NwAAAcs"]
[Thu Jul 30 15:01:17.277915 2026] [core:notice] [pid 87988:tid 88188] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:17.396127 2026] [security2:error] [pid 89520:tid 89575] [remote 57.141.0.12:26712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amutjS0W4wRrtnDoPaj6OAABmS0"]
[Thu Jul 30 15:01:17.576733 2026] [security2:error] [pid 87988:tid 88174] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ah25.php"] [unique_id "amutjTipAwzptuCxBrhgVAAAAUI"]
[Thu Jul 30 15:01:17.576863 2026] [security2:error] [pid 87988:tid 88174] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ah25.php"] [unique_id "amutjTipAwzptuCxBrhgVAAAAUI"]
[Thu Jul 30 15:01:17.676472 2026] [core:notice] [pid 89520:tid 89668] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:17.695259 2026] [security2:error] [pid 87988:tid 88151] [client 103.82.26.211:65137] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.alshateeintl.com"] [uri "/"] [unique_id "amutjTipAwzptuCxBrhgVwAAASs"]
[Thu Jul 30 15:01:17.912456 2026] [security2:error] [pid 89520:tid 89665] [client 20.203.148.31:12683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amutjS0W4wRrtnDoPaj6QAAAAZE"]
[Thu Jul 30 15:01:18.028249 2026] [security2:error] [pid 89520:tid 89760] [client 103.82.26.211:65164] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.alshateeintl.com"] [uri "/wp-json/batch/v1"] [unique_id "amutji0W4wRrtnDoPaj6QQAAAfA"]
[Thu Jul 30 15:01:18.071752 2026] [core:notice] [pid 89520:tid 89702] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:18.172094 2026] [security2:error] [pid 89520:tid 89725] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/term.php"] [unique_id "amutji0W4wRrtnDoPaj6RAAAAc0"]
[Thu Jul 30 15:01:18.172195 2026] [security2:error] [pid 89520:tid 89725] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/term.php"] [unique_id "amutji0W4wRrtnDoPaj6RAAAAc0"]
[Thu Jul 30 15:01:18.355689 2026] [core:notice] [pid 87988:tid 88217] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:18.684964 2026] [core:notice] [pid 87988:tid 88184] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:18.750057 2026] [security2:error] [pid 89520:tid 89728] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/we.php"] [unique_id "amutji0W4wRrtnDoPaj6SgAAAdA"]
[Thu Jul 30 15:01:18.750149 2026] [security2:error] [pid 89520:tid 89728] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/we.php"] [unique_id "amutji0W4wRrtnDoPaj6SgAAAdA"]
[Thu Jul 30 15:01:18.944928 2026] [core:notice] [pid 89520:tid 89759] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:19.109224 2026] [security2:error] [pid 89520:tid 89667] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutji0W4wRrtnDoPaj6RwAAAZM"]
[Thu Jul 30 15:01:19.343654 2026] [security2:error] [pid 89520:tid 89729] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/zip-onee.php"] [unique_id "amutjy0W4wRrtnDoPaj6UQAAAdE"]
[Thu Jul 30 15:01:19.343787 2026] [security2:error] [pid 89520:tid 89729] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/zip-onee.php"] [unique_id "amutjy0W4wRrtnDoPaj6UQAAAdE"]
[Thu Jul 30 15:01:19.365911 2026] [security2:error] [pid 89520:tid 89572] [remote 57.141.0.5:59414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amutjy0W4wRrtnDoPaj6UgAB9So"]
[Thu Jul 30 15:01:19.525211 2026] [security2:error] [pid 87988:tid 88149] [client 135.119.63.61:49616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpr-addons/forms/RxRzhwix.php"] [unique_id "amutjzipAwzptuCxBrhgcgAAASk"]
[Thu Jul 30 15:01:19.909520 2026] [security2:error] [pid 87988:tid 88242] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/il.php"] [unique_id "amutjzipAwzptuCxBrhgewAAAYY"]
[Thu Jul 30 15:01:19.909611 2026] [security2:error] [pid 87988:tid 88242] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/il.php"] [unique_id "amutjzipAwzptuCxBrhgewAAAYY"]
[Thu Jul 30 15:01:20.080529 2026] [core:notice] [pid 87988:tid 88243] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:20.338515 2026] [core:notice] [pid 89520:tid 89701] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:20.442515 2026] [security2:error] [pid 89520:tid 89743] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/one.php"] [unique_id "amutkC0W4wRrtnDoPaj6YQAAAd8"]
[Thu Jul 30 15:01:20.442612 2026] [security2:error] [pid 89520:tid 89743] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/one.php"] [unique_id "amutkC0W4wRrtnDoPaj6YQAAAd8"]
[Thu Jul 30 15:01:20.543019 2026] [security2:error] [pid 87988:tid 88131] [client 135.119.63.61:49617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpr-addons/forms/b1ack.php"] [unique_id "amutkDipAwzptuCxBrhggwAAARc"]
[Thu Jul 30 15:01:20.627526 2026] [core:notice] [pid 87988:tid 88244] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:20.880698 2026] [core:notice] [pid 89520:tid 89676] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:21.006311 2026] [security2:error] [pid 87988:tid 88239] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/002.php"] [unique_id "amutkTipAwzptuCxBrhgigAAAYM"]
[Thu Jul 30 15:01:21.006421 2026] [security2:error] [pid 87988:tid 88239] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/002.php"] [unique_id "amutkTipAwzptuCxBrhgigAAAYM"]
[Thu Jul 30 15:01:21.543589 2026] [security2:error] [pid 89520:tid 89738] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/file1.php"] [unique_id "amutkS0W4wRrtnDoPaj6bQAAAdo"]
[Thu Jul 30 15:01:21.543701 2026] [security2:error] [pid 89520:tid 89738] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/file1.php"] [unique_id "amutkS0W4wRrtnDoPaj6bQAAAdo"]
[Thu Jul 30 15:01:21.562388 2026] [security2:error] [pid 89520:tid 89753] [client 135.119.63.61:55944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/file_uploadswp.php"] [unique_id "amutkS0W4wRrtnDoPaj6bgAAAek"]
[Thu Jul 30 15:01:22.088938 2026] [security2:error] [pid 89520:tid 89764] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/akimet.php"] [unique_id "amutki0W4wRrtnDoPaj6cgAAAfQ"]
[Thu Jul 30 15:01:22.089049 2026] [security2:error] [pid 89520:tid 89764] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/akimet.php"] [unique_id "amutki0W4wRrtnDoPaj6cgAAAfQ"]
[Thu Jul 30 15:01:22.174897 2026] [security2:error] [pid 87988:tid 88163] [client 20.203.148.31:6746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amutkjipAwzptuCxBrhgmAAAATc"]
[Thu Jul 30 15:01:22.544595 2026] [security2:error] [pid 89520:tid 89684] [client 135.119.63.61:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/file_uploadwp.php"] [unique_id "amutki0W4wRrtnDoPaj6eQAAAaQ"]
[Thu Jul 30 15:01:22.602906 2026] [core:notice] [pid 89520:tid 89574] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:22.655612 2026] [core:notice] [pid 89520:tid 89685] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:22.673813 2026] [security2:error] [pid 87988:tid 88128] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/reop3.php"] [unique_id "amutkjipAwzptuCxBrhgoAAAARQ"]
[Thu Jul 30 15:01:22.673939 2026] [security2:error] [pid 87988:tid 88128] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/reop3.php"] [unique_id "amutkjipAwzptuCxBrhgoAAAARQ"]
[Thu Jul 30 15:01:22.922714 2026] [core:notice] [pid 89520:tid 89770] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:22.953248 2026] [security2:error] [pid 89520:tid 89718] [client 135.119.63.61:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpr-addons/forms/e.php"] [unique_id "amutki0W4wRrtnDoPaj6fQAAAcY"]
[Thu Jul 30 15:01:23.192172 2026] [core:notice] [pid 89520:tid 89700] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:23.221487 2026] [security2:error] [pid 89520:tid 89724] [client 20.203.148.31:15034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amutky0W4wRrtnDoPaj6hQAAAcw"]
[Thu Jul 30 15:01:23.293151 2026] [security2:error] [pid 87988:tid 88161] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/h.php"] [unique_id "amutkzipAwzptuCxBrhgpAAAATU"]
[Thu Jul 30 15:01:23.293257 2026] [security2:error] [pid 87988:tid 88161] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/h.php"] [unique_id "amutkzipAwzptuCxBrhgpAAAATU"]
[Thu Jul 30 15:01:23.466112 2026] [core:notice] [pid 89520:tid 89704] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:23.552231 2026] [security2:error] [pid 89520:tid 89586] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutky0W4wRrtnDoPaj6igABmzg"]
[Thu Jul 30 15:01:23.552400 2026] [security2:error] [pid 89520:tid 89675] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutky0W4wRrtnDoPaj6igABmzg"]
[Thu Jul 30 15:01:23.733740 2026] [security2:error] [pid 89520:tid 89767] [client 135.119.63.61:9025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/fileadmin.php"] [unique_id "amutky0W4wRrtnDoPaj6jgAAAfc"]
[Thu Jul 30 15:01:23.855149 2026] [security2:error] [pid 87988:tid 88180] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/2x.php"] [unique_id "amutkzipAwzptuCxBrhgqgAAAUg"]
[Thu Jul 30 15:01:23.855271 2026] [security2:error] [pid 87988:tid 88180] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/2x.php"] [unique_id "amutkzipAwzptuCxBrhgqgAAAUg"]
[Thu Jul 30 15:01:23.877633 2026] [core:notice] [pid 89520:tid 89695] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:24.039171 2026] [security2:error] [pid 89520:tid 89779] [client 20.203.148.31:24146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amutlC0W4wRrtnDoPaj6kgAAAgM"]
[Thu Jul 30 15:01:24.160118 2026] [core:notice] [pid 89520:tid 89674] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:24.421115 2026] [security2:error] [pid 89520:tid 89694] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/petx.php"] [unique_id "amutlC0W4wRrtnDoPaj6mQAAAa4"]
[Thu Jul 30 15:01:24.421212 2026] [security2:error] [pid 89520:tid 89694] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/petx.php"] [unique_id "amutlC0W4wRrtnDoPaj6mQAAAa4"]
[Thu Jul 30 15:01:24.527650 2026] [security2:error] [pid 89520:tid 89789] [client 135.119.63.61:27737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpr-addons/forms/rk.php"] [unique_id "amutlC0W4wRrtnDoPaj6nAAAAg0"]
[Thu Jul 30 15:01:24.810712 2026] [security2:error] [pid 89520:tid 89664] [client 135.119.63.61:9048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filealfa.php"] [unique_id "amutlC0W4wRrtnDoPaj6oAAAAZA"]
[Thu Jul 30 15:01:24.987508 2026] [security2:error] [pid 89520:tid 89776] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/zxz.php"] [unique_id "amutlC0W4wRrtnDoPaj6ogAAAgA"]
[Thu Jul 30 15:01:24.987630 2026] [security2:error] [pid 89520:tid 89776] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/zxz.php"] [unique_id "amutlC0W4wRrtnDoPaj6ogAAAgA"]
[Thu Jul 30 15:01:25.152203 2026] [core:notice] [pid 89520:tid 89738] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:25.170709 2026] [core:notice] [pid 89520:tid 89588] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:25.450335 2026] [core:notice] [pid 89520:tid 89722] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:25.537844 2026] [security2:error] [pid 89520:tid 89774] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/2.php"] [unique_id "amutlS0W4wRrtnDoPaj6sgAAAf4"]
[Thu Jul 30 15:01:25.537943 2026] [security2:error] [pid 89520:tid 89774] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/2.php"] [unique_id "amutlS0W4wRrtnDoPaj6sgAAAf4"]
[Thu Jul 30 15:01:25.812748 2026] [security2:error] [pid 87988:tid 88127] [client 135.119.63.61:27713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpr-addons/forms/wp-login.php"] [unique_id "amutlTipAwzptuCxBrhgxAAAARM"]
[Thu Jul 30 15:01:26.107083 2026] [core:notice] [pid 87988:tid 88242] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:26.135561 2026] [security2:error] [pid 87988:tid 88187] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/op.php"] [unique_id "amutljipAwzptuCxBrhgyAAAAU8"]
[Thu Jul 30 15:01:26.135725 2026] [security2:error] [pid 87988:tid 88187] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/op.php"] [unique_id "amutljipAwzptuCxBrhgyAAAAU8"]
[Thu Jul 30 15:01:26.391939 2026] [core:notice] [pid 89520:tid 89741] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:26.433153 2026] [security2:error] [pid 89520:tid 89743] [client 20.203.148.31:6729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amutli0W4wRrtnDoPaj6vgAAAd8"]
[Thu Jul 30 15:01:26.698871 2026] [security2:error] [pid 89520:tid 89674] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/a5.php"] [unique_id "amutli0W4wRrtnDoPaj6wgAAAZo"]
[Thu Jul 30 15:01:26.699032 2026] [security2:error] [pid 89520:tid 89674] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/a5.php"] [unique_id "amutli0W4wRrtnDoPaj6wgAAAZo"]
[Thu Jul 30 15:01:26.949002 2026] [security2:error] [pid 89520:tid 89752] [client 135.119.63.61:57941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filebypass.php"] [unique_id "amutli0W4wRrtnDoPaj6xAAAAeg"]
[Thu Jul 30 15:01:27.098935 2026] [security2:error] [pid 87988:tid 88132] [client 154.208.43.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutljipAwzptuCxBrhgzAABGGQ"], referer: https://allmontecristi.com
[Thu Jul 30 15:01:27.252064 2026] [security2:error] [pid 89520:tid 89721] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ws80.php"] [unique_id "amutly0W4wRrtnDoPaj6yAAAAck"]
[Thu Jul 30 15:01:27.252145 2026] [security2:error] [pid 89520:tid 89721] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ws80.php"] [unique_id "amutly0W4wRrtnDoPaj6yAAAAck"]
[Thu Jul 30 15:01:27.260879 2026] [core:notice] [pid 87988:tid 88135] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:27.384685 2026] [security2:error] [pid 89520:tid 89772] [client 135.119.63.61:27752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpupex.php"] [unique_id "amutly0W4wRrtnDoPaj6ygAAAfw"]
[Thu Jul 30 15:01:27.829300 2026] [security2:error] [pid 87988:tid 88133] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xa.php"] [unique_id "amutlzipAwzptuCxBrhg4wAAARk"]
[Thu Jul 30 15:01:27.829384 2026] [security2:error] [pid 87988:tid 88133] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xa.php"] [unique_id "amutlzipAwzptuCxBrhg4wAAARk"]
[Thu Jul 30 15:01:27.920587 2026] [core:notice] [pid 87988:tid 88237] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:27.946255 2026] [security2:error] [pid 89520:tid 89781] [client 135.119.63.61:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filedokumenadmin.php"] [unique_id "amutly0W4wRrtnDoPaj6zwAAAgU"]
[Thu Jul 30 15:01:28.159079 2026] [security2:error] [pid 89520:tid 89766] [client 20.203.148.31:12972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amutmC0W4wRrtnDoPaj60AAAAfY"]
[Thu Jul 30 15:01:28.357995 2026] [security2:error] [pid 89520:tid 89723] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/asd67.php"] [unique_id "amutmC0W4wRrtnDoPaj62AAAAcs"]
[Thu Jul 30 15:01:28.358118 2026] [security2:error] [pid 89520:tid 89723] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/asd67.php"] [unique_id "amutmC0W4wRrtnDoPaj62AAAAcs"]
[Thu Jul 30 15:01:28.409235 2026] [core:notice] [pid 89520:tid 89757] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:28.913503 2026] [security2:error] [pid 87988:tid 88161] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/bk.php"] [unique_id "amutmDipAwzptuCxBrhg7wAAATU"]
[Thu Jul 30 15:01:28.913603 2026] [security2:error] [pid 87988:tid 88161] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/bk.php"] [unique_id "amutmDipAwzptuCxBrhg7wAAATU"]
[Thu Jul 30 15:01:29.051321 2026] [security2:error] [pid 89520:tid 89600] [remote 40.77.167.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/jipkl/article/download/128/121/247"] [unique_id "amutmS0W4wRrtnDoPaj66AABoEY"]
[Thu Jul 30 15:01:29.122522 2026] [security2:error] [pid 89520:tid 89763] [client 135.119.63.61:55293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filedokumenalfa.php"] [unique_id "amutmS0W4wRrtnDoPaj66QAAAfM"]
[Thu Jul 30 15:01:29.166517 2026] [security2:error] [pid 89520:tid 89764] [client 20.203.148.31:27247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amutmS0W4wRrtnDoPaj66gAAAfQ"]
[Thu Jul 30 15:01:29.447894 2026] [security2:error] [pid 87988:tid 88219] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-links.php"] [unique_id "amutmTipAwzptuCxBrhg9AAAAW8"]
[Thu Jul 30 15:01:29.448032 2026] [security2:error] [pid 87988:tid 88219] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-links.php"] [unique_id "amutmTipAwzptuCxBrhg9AAAAW8"]
[Thu Jul 30 15:01:29.644698 2026] [core:notice] [pid 89520:tid 89735] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:29.966553 2026] [security2:error] [pid 89520:tid 89745] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/mosty.php"] [unique_id "amutmS0W4wRrtnDoPaj6_QAAAeE"]
[Thu Jul 30 15:01:29.966654 2026] [security2:error] [pid 89520:tid 89745] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/mosty.php"] [unique_id "amutmS0W4wRrtnDoPaj6_QAAAeE"]
[Thu Jul 30 15:01:29.991364 2026] [security2:error] [pid 89520:tid 89689] [client 135.119.63.61:53855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpx.php"] [unique_id "amutmS0W4wRrtnDoPaj6_gAAAak"]
[Thu Jul 30 15:01:30.114865 2026] [security2:error] [pid 89520:tid 89767] [client 20.203.148.31:27200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amutmi0W4wRrtnDoPaj6_wAAAfc"]
[Thu Jul 30 15:01:30.254325 2026] [core:notice] [pid 89520:tid 89727] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:30.533928 2026] [security2:error] [pid 87988:tid 88167] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sump3.php"] [unique_id "amutmjipAwzptuCxBrhhAQAAATs"]
[Thu Jul 30 15:01:30.534050 2026] [security2:error] [pid 87988:tid 88167] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/sump3.php"] [unique_id "amutmjipAwzptuCxBrhhAQAAATs"]
[Thu Jul 30 15:01:30.796938 2026] [core:notice] [pid 87988:tid 88218] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:30.953185 2026] [security2:error] [pid 87988:tid 88214] [client 135.119.63.61:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filedokumenbypass.php"] [unique_id "amutmjipAwzptuCxBrhhCQAAAWo"]
[Thu Jul 30 15:01:31.136094 2026] [security2:error] [pid 89520:tid 89766] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/first.php"] [unique_id "amutmy0W4wRrtnDoPaj7CQAAAfY"]
[Thu Jul 30 15:01:31.136208 2026] [security2:error] [pid 89520:tid 89766] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/first.php"] [unique_id "amutmy0W4wRrtnDoPaj7CQAAAfY"]
[Thu Jul 30 15:01:31.225699 2026] [security2:error] [pid 89520:tid 89789] [client 135.119.63.61:27730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wpyii2/wpyii2.php"] [unique_id "amutmy0W4wRrtnDoPaj7CgAAAg0"]
[Thu Jul 30 15:01:31.744833 2026] [security2:error] [pid 89520:tid 89757] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/acp.php"] [unique_id "amutmy0W4wRrtnDoPaj7EAAAAe0"]
[Thu Jul 30 15:01:31.744946 2026] [security2:error] [pid 89520:tid 89757] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/acp.php"] [unique_id "amutmy0W4wRrtnDoPaj7EAAAAe0"]
[Thu Jul 30 15:01:31.868723 2026] [security2:error] [pid 89520:tid 89778] [client 20.203.148.31:6685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/flower.php"] [unique_id "amutmy0W4wRrtnDoPaj7EwAAAgI"]
[Thu Jul 30 15:01:32.135144 2026] [core:notice] [pid 89520:tid 89744] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:32.184299 2026] [security2:error] [pid 89520:tid 89754] [client 135.119.63.61:55253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filedokumenk.php"] [unique_id "amutnC0W4wRrtnDoPaj7GQAAAeo"]
[Thu Jul 30 15:01:32.212266 2026] [core:notice] [pid 87988:tid 88136] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:32.294350 2026] [security2:error] [pid 89520:tid 89682] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-good.php"] [unique_id "amutnC0W4wRrtnDoPaj7GgAAAaI"]
[Thu Jul 30 15:01:32.294465 2026] [security2:error] [pid 89520:tid 89682] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-good.php"] [unique_id "amutnC0W4wRrtnDoPaj7GgAAAaI"]
[Thu Jul 30 15:01:32.536956 2026] [security2:error] [pid 87988:tid 88172] [client 135.119.63.61:27736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/wrapper.php"] [unique_id "amutnDipAwzptuCxBrhhHwAAAUA"]
[Thu Jul 30 15:01:32.820490 2026] [security2:error] [pid 89520:tid 89762] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/daerl3.php"] [unique_id "amutnC0W4wRrtnDoPaj7GwAAAfI"]
[Thu Jul 30 15:01:32.820623 2026] [security2:error] [pid 89520:tid 89762] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/daerl3.php"] [unique_id "amutnC0W4wRrtnDoPaj7GwAAAfI"]
[Thu Jul 30 15:01:32.903351 2026] [core:notice] [pid 89520:tid 89770] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:33.153781 2026] [security2:error] [pid 87988:tid 88181] [client 135.119.63.61:55259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filedokumenwp.php"] [unique_id "amutnTipAwzptuCxBrhhJgAAAUk"]
[Thu Jul 30 15:01:33.261920 2026] [core:notice] [pid 87988:tid 88190] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:33.353273 2026] [security2:error] [pid 89520:tid 89700] [client 78.47.42.23:52742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/sitemap_index.xml"] [unique_id "amutnS0W4wRrtnDoPaj7JAAAAbQ"]
[Thu Jul 30 15:01:33.394665 2026] [security2:error] [pid 89520:tid 89724] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/php5.php"] [unique_id "amutnS0W4wRrtnDoPaj7JQAAAcw"]
[Thu Jul 30 15:01:33.394766 2026] [security2:error] [pid 89520:tid 89724] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/php5.php"] [unique_id "amutnS0W4wRrtnDoPaj7JQAAAcw"]
[Thu Jul 30 15:01:33.974262 2026] [security2:error] [pid 87988:tid 88165] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xoot.php"] [unique_id "amutnTipAwzptuCxBrhhMAAAATk"]
[Thu Jul 30 15:01:33.974362 2026] [security2:error] [pid 87988:tid 88165] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/xoot.php"] [unique_id "amutnTipAwzptuCxBrhhMAAAATk"]
[Thu Jul 30 15:01:34.063361 2026] [security2:error] [pid 87988:tid 88114] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutnjipAwzptuCxBrhhMgABOH0"]
[Thu Jul 30 15:01:34.063482 2026] [security2:error] [pid 87988:tid 88164] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutnjipAwzptuCxBrhhMgABOH0"]
[Thu Jul 30 15:01:34.371478 2026] [security2:error] [pid 87988:tid 88119] [client 78.47.42.23:52746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/sitemap_index.xml"] [unique_id "amutnjipAwzptuCxBrhhNgAAAQs"]
[Thu Jul 30 15:01:34.381229 2026] [security2:error] [pid 89520:tid 89747] [client 135.119.63.61:53882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/ws.php"] [unique_id "amutni0W4wRrtnDoPaj7LwAAAeM"]
[Thu Jul 30 15:01:34.494362 2026] [security2:error] [pid 89520:tid 89693] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/clxcc.php"] [unique_id "amutni0W4wRrtnDoPaj7MQAAAa0"]
[Thu Jul 30 15:01:34.494472 2026] [security2:error] [pid 89520:tid 89693] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/clxcc.php"] [unique_id "amutni0W4wRrtnDoPaj7MQAAAa0"]
[Thu Jul 30 15:01:35.052378 2026] [core:notice] [pid 89520:tid 89679] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:35.065457 2026] [security2:error] [pid 89520:tid 89765] [client 135.119.63.61:55939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filefuns.php"] [unique_id "amutny0W4wRrtnDoPaj7OAAAAfU"]
[Thu Jul 30 15:01:35.082369 2026] [security2:error] [pid 89520:tid 89688] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ai.php"] [unique_id "amutny0W4wRrtnDoPaj7OQAAAag"]
[Thu Jul 30 15:01:35.082446 2026] [security2:error] [pid 89520:tid 89688] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ai.php"] [unique_id "amutny0W4wRrtnDoPaj7OQAAAag"]
[Thu Jul 30 15:01:35.427564 2026] [security2:error] [pid 89520:tid 89664] [client 78.47.42.23:52760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/sitemap_index.xml"] [unique_id "amutny0W4wRrtnDoPaj7PAAAAZA"]
[Thu Jul 30 15:01:35.546950 2026] [security2:error] [pid 89520:tid 89746] [client 20.203.148.31:24129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amutny0W4wRrtnDoPaj7QQAAAeI"]
[Thu Jul 30 15:01:35.637099 2026] [security2:error] [pid 89520:tid 89782] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/nwflm.php"] [unique_id "amutny0W4wRrtnDoPaj7RAAAAgY"]
[Thu Jul 30 15:01:35.637201 2026] [security2:error] [pid 89520:tid 89782] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/nwflm.php"] [unique_id "amutny0W4wRrtnDoPaj7RAAAAgY"]
[Thu Jul 30 15:01:35.670811 2026] [core:notice] [pid 89520:tid 89751] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:35.769201 2026] [core:notice] [pid 87988:tid 88112] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:35.931364 2026] [core:notice] [pid 89520:tid 89691] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:36.176907 2026] [security2:error] [pid 89520:tid 89668] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/hypo.php"] [unique_id "amutoC0W4wRrtnDoPaj7SwAAAZQ"]
[Thu Jul 30 15:01:36.177062 2026] [security2:error] [pid 89520:tid 89668] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/hypo.php"] [unique_id "amutoC0W4wRrtnDoPaj7SwAAAZQ"]
[Thu Jul 30 15:01:36.232065 2026] [security2:error] [pid 89520:tid 89723] [client 135.119.63.61:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filek.php"] [unique_id "amutoC0W4wRrtnDoPaj7TQAAAcs"]
[Thu Jul 30 15:01:36.323966 2026] [core:notice] [pid 89520:tid 89665] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:36.367442 2026] [security2:error] [pid 89520:tid 89774] [client 20.203.148.31:19735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/maint/flower.php"] [unique_id "amutoC0W4wRrtnDoPaj7TwAAAf4"]
[Thu Jul 30 15:01:36.576055 2026] [core:notice] [pid 89520:tid 89682] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:36.701902 2026] [core:notice] [pid 89520:tid 89754] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:36.757403 2026] [core:notice] [pid 89520:tid 89680] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:36.766652 2026] [security2:error] [pid 89520:tid 89761] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/w3llscc.php"] [unique_id "amutoC0W4wRrtnDoPaj7VwAAAfE"]
[Thu Jul 30 15:01:36.766746 2026] [security2:error] [pid 89520:tid 89761] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/w3llscc.php"] [unique_id "amutoC0W4wRrtnDoPaj7VwAAAfE"]
[Thu Jul 30 15:01:36.890718 2026] [core:notice] [pid 89520:tid 89769] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:37.345734 2026] [security2:error] [pid 89520:tid 89667] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/11PJcpMFsD8B.php"] [unique_id "amutoS0W4wRrtnDoPaj7XQAAAZM"]
[Thu Jul 30 15:01:37.345842 2026] [security2:error] [pid 89520:tid 89667] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/11PJcpMFsD8B.php"] [unique_id "amutoS0W4wRrtnDoPaj7XQAAAZM"]
[Thu Jul 30 15:01:37.526572 2026] [security2:error] [pid 89520:tid 89715] [client 135.119.63.61:49648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mydubaidesertsafari.com"] [uri "/ws.php.php"] [unique_id "amutoS0W4wRrtnDoPaj7XwAAAcM"]
[Thu Jul 30 15:01:37.625332 2026] [security2:error] [pid 87988:tid 88123] [client 135.119.63.61:55267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filemanager/connectors/php/upload.php"] [unique_id "amutoTipAwzptuCxBrhhYAAAAQ8"]
[Thu Jul 30 15:01:37.888161 2026] [security2:error] [pid 87988:tid 88235] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/8.php"] [unique_id "amutoTipAwzptuCxBrhhZQAAAX8"]
[Thu Jul 30 15:01:37.888266 2026] [security2:error] [pid 87988:tid 88235] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/8.php"] [unique_id "amutoTipAwzptuCxBrhhZQAAAX8"]
[Thu Jul 30 15:01:38.173630 2026] [core:notice] [pid 89520:tid 89695] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:38.267129 2026] [security2:error] [pid 89520:tid 89763] [client 20.203.148.31:36241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amutoi0W4wRrtnDoPaj7aQAAAfM"]
[Thu Jul 30 15:01:38.464401 2026] [core:notice] [pid 89520:tid 89716] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:38.491162 2026] [security2:error] [pid 89520:tid 89745] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fnstall.php"] [unique_id "amutoi0W4wRrtnDoPaj7bAAAAeE"]
[Thu Jul 30 15:01:38.491277 2026] [security2:error] [pid 89520:tid 89745] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fnstall.php"] [unique_id "amutoi0W4wRrtnDoPaj7bAAAAeE"]
[Thu Jul 30 15:01:38.555518 2026] [security2:error] [pid 89520:tid 89607] [remote 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutoS0W4wRrtnDoPaj7ZAABsE0"]
[Thu Jul 30 15:01:38.778932 2026] [core:notice] [pid 89520:tid 89690] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:38.904323 2026] [core:notice] [pid 89520:tid 89765] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:38.948994 2026] [security2:error] [pid 87988:tid 88239] [client 20.226.5.174:16072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/linkpreviewwp.php"] [unique_id "amutojipAwzptuCxBrhhbwAAAYM"]
[Thu Jul 30 15:01:39.021130 2026] [security2:error] [pid 89520:tid 89752] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/edorxrr.php"] [unique_id "amutoy0W4wRrtnDoPaj7dAAAAeg"]
[Thu Jul 30 15:01:39.021252 2026] [security2:error] [pid 89520:tid 89752] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/edorxrr.php"] [unique_id "amutoy0W4wRrtnDoPaj7dAAAAeg"]
[Thu Jul 30 15:01:39.470845 2026] [security2:error] [pid 89520:tid 89703] [client 135.119.63.61:9073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filemanageradmin.php"] [unique_id "amutoy0W4wRrtnDoPaj7ewAAAbc"]
[Thu Jul 30 15:01:39.584868 2026] [security2:error] [pid 87988:tid 88209] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/setup.php"] [unique_id "amutozipAwzptuCxBrhhdQAAAWU"]
[Thu Jul 30 15:01:39.585001 2026] [security2:error] [pid 87988:tid 88209] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/setup.php"] [unique_id "amutozipAwzptuCxBrhhdQAAAWU"]
[Thu Jul 30 15:01:39.898015 2026] [security2:error] [pid 89520:tid 89720] [client 20.226.5.174:16065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/links.php"] [unique_id "amutoy0W4wRrtnDoPaj7ggAAAcg"]
[Thu Jul 30 15:01:39.943915 2026] [core:notice] [pid 89520:tid 89672] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:40.135714 2026] [security2:error] [pid 87988:tid 88194] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/6.php"] [unique_id "amutpDipAwzptuCxBrhhfAAAAVY"]
[Thu Jul 30 15:01:40.135827 2026] [security2:error] [pid 87988:tid 88194] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/6.php"] [unique_id "amutpDipAwzptuCxBrhhfAAAAVY"]
[Thu Jul 30 15:01:40.139346 2026] [security2:error] [pid 89520:tid 89790] [client 20.203.148.31:14478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amutpC0W4wRrtnDoPaj7hAAAAg4"]
[Thu Jul 30 15:01:40.456810 2026] [security2:error] [pid 87988:tid 88226] [client 135.119.63.61:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filemanagerbypass.php"] [unique_id "amutpDipAwzptuCxBrhhggAAAXY"]
[Thu Jul 30 15:01:40.644171 2026] [core:notice] [pid 89520:tid 89673] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:40.713937 2026] [security2:error] [pid 87988:tid 88158] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/w3lls.php"] [unique_id "amutpDipAwzptuCxBrhhgwAAATI"]
[Thu Jul 30 15:01:40.714142 2026] [security2:error] [pid 87988:tid 88158] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/w3lls.php"] [unique_id "amutpDipAwzptuCxBrhhgwAAATI"]
[Thu Jul 30 15:01:40.770423 2026] [core:notice] [pid 89520:tid 89742] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:40.792754 2026] [security2:error] [pid 87988:tid 88128] [client 20.226.5.174:16074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/litanies.php"] [unique_id "amutpDipAwzptuCxBrhhhAAAARQ"]
[Thu Jul 30 15:01:40.847102 2026] [security2:error] [pid 87988:tid 88142] [client 213.152.161.20:42492] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amutpDipAwzptuCxBrhhhwAAASI"]
[Thu Jul 30 15:01:40.847195 2026] [security2:error] [pid 87988:tid 88142] [client 213.152.161.20:42492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amutpDipAwzptuCxBrhhhwAAASI"]
[Thu Jul 30 15:01:41.041525 2026] [core:notice] [pid 89520:tid 89685] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:41.281237 2026] [security2:error] [pid 89520:tid 89761] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/99.php"] [unique_id "amutpS0W4wRrtnDoPaj7kgAAAfE"]
[Thu Jul 30 15:01:41.281356 2026] [security2:error] [pid 89520:tid 89761] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/99.php"] [unique_id "amutpS0W4wRrtnDoPaj7kgAAAfE"]
[Thu Jul 30 15:01:41.301659 2026] [core:notice] [pid 87988:tid 88137] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:41.304694 2026] [core:notice] [pid 89520:tid 89711] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:41.685769 2026] [security2:error] [pid 89520:tid 89764] [client 20.226.5.174:16076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lite.php"] [unique_id "amutpS0W4wRrtnDoPaj7mQAAAfQ"]
[Thu Jul 30 15:01:41.844155 2026] [security2:error] [pid 89520:tid 89773] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/admin.php"] [unique_id "amutpS0W4wRrtnDoPaj7mwAAAf0"]
[Thu Jul 30 15:01:41.844273 2026] [security2:error] [pid 89520:tid 89773] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/admin.php"] [unique_id "amutpS0W4wRrtnDoPaj7mwAAAf0"]
[Thu Jul 30 15:01:41.941546 2026] [security2:error] [pid 89520:tid 89748] [client 57.141.0.54:65356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amutpS0W4wRrtnDoPaj7mAAB5FQ"], referer: https://igetvape-australia.com/store/?product-page=10&add-to-cart=110
[Thu Jul 30 15:01:42.400114 2026] [security2:error] [pid 89520:tid 89767] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/media.php"] [unique_id "amutpi0W4wRrtnDoPaj7ogAAAfc"]
[Thu Jul 30 15:01:42.400221 2026] [security2:error] [pid 89520:tid 89767] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/media.php"] [unique_id "amutpi0W4wRrtnDoPaj7ogAAAfc"]
[Thu Jul 30 15:01:42.507604 2026] [core:notice] [pid 89520:tid 89788] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:42.604712 2026] [security2:error] [pid 87988:tid 88167] [client 20.226.5.174:16064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/litespeed.php"] [unique_id "amutpjipAwzptuCxBrhhnAAAATs"]
[Thu Jul 30 15:01:42.763178 2026] [core:notice] [pid 89520:tid 89781] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:42.922559 2026] [security2:error] [pid 89520:tid 89718] [client 20.203.148.31:26144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/flower.php"] [unique_id "amutpi0W4wRrtnDoPaj7qgAAAcY"]
[Thu Jul 30 15:01:42.965024 2026] [security2:error] [pid 89520:tid 89782] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amutpi0W4wRrtnDoPaj7rAAAAgY"]
[Thu Jul 30 15:01:42.965121 2026] [security2:error] [pid 89520:tid 89782] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amutpi0W4wRrtnDoPaj7rAAAAgY"]
[Thu Jul 30 15:01:42.995538 2026] [core:notice] [pid 89520:tid 89615] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:42.999481 2026] [security2:error] [pid 89520:tid 89664] [client 74.7.228.50:43320] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amutpi0W4wRrtnDoPaj7rQABkFU"]
[Thu Jul 30 15:01:43.496241 2026] [security2:error] [pid 87988:tid 88203] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/222.php"] [unique_id "amutpzipAwzptuCxBrhhpgAAAV8"]
[Thu Jul 30 15:01:43.496342 2026] [security2:error] [pid 87988:tid 88203] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/222.php"] [unique_id "amutpzipAwzptuCxBrhhpgAAAV8"]
[Thu Jul 30 15:01:43.533203 2026] [security2:error] [pid 89520:tid 89692] [client 20.226.5.174:16081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/live.php"] [unique_id "amutpy0W4wRrtnDoPaj7tAAAAaw"]
[Thu Jul 30 15:01:43.735639 2026] [security2:error] [pid 87988:tid 88157] [client 135.119.63.61:55289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filemanagerk.php"] [unique_id "amutpzipAwzptuCxBrhhqwAAATE"]
[Thu Jul 30 15:01:43.996637 2026] [security2:error] [pid 89520:tid 89685] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-load.php"] [unique_id "amutpy0W4wRrtnDoPaj7twAAAaU"]
[Thu Jul 30 15:01:43.996793 2026] [security2:error] [pid 89520:tid 89685] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-load.php"] [unique_id "amutpy0W4wRrtnDoPaj7twAAAaU"]
[Thu Jul 30 15:01:44.142914 2026] [security2:error] [pid 89520:tid 89751] [client 17.241.219.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amutpi0W4wRrtnDoPaj7rwAAAec"]
[Thu Jul 30 15:01:44.449187 2026] [security2:error] [pid 89520:tid 89740] [client 20.226.5.174:16077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/ll.php"] [unique_id "amutqC0W4wRrtnDoPaj7xAAAAdw"]
[Thu Jul 30 15:01:44.509700 2026] [security2:error] [pid 87988:tid 88206] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/themes/index.php"] [unique_id "amutqDipAwzptuCxBrhhsgAAAWI"]
[Thu Jul 30 15:01:44.509813 2026] [security2:error] [pid 87988:tid 88206] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-content/themes/index.php"] [unique_id "amutqDipAwzptuCxBrhhsgAAAWI"]
[Thu Jul 30 15:01:44.604688 2026] [security2:error] [pid 87988:tid 88042] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutqDipAwzptuCxBrhhtwABDTU"]
[Thu Jul 30 15:01:44.604848 2026] [security2:error] [pid 87988:tid 88121] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutqDipAwzptuCxBrhhtwABDTU"]
[Thu Jul 30 15:01:45.004700 2026] [core:notice] [pid 89520:tid 89752] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:45.065993 2026] [core:notice] [pid 89520:tid 89706] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:45.070240 2026] [security2:error] [pid 89520:tid 89706] [client 66.249.79.230:53029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/4480/3768"] [unique_id "amutqC0W4wRrtnDoPaj7yAAAAbo"]
[Thu Jul 30 15:01:45.091015 2026] [security2:error] [pid 89520:tid 89719] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/js/index.php"] [unique_id "amutqS0W4wRrtnDoPaj7zAAAAcc"]
[Thu Jul 30 15:01:45.091098 2026] [security2:error] [pid 89520:tid 89719] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-admin/js/index.php"] [unique_id "amutqS0W4wRrtnDoPaj7zAAAAcc"]
[Thu Jul 30 15:01:45.277091 2026] [core:notice] [pid 87988:tid 88190] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:45.342720 2026] [security2:error] [pid 89520:tid 89713] [client 20.226.5.174:16071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lmfi.php"] [unique_id "amutqS0W4wRrtnDoPaj70AAAAcE"]
[Thu Jul 30 15:01:45.650024 2026] [security2:error] [pid 89520:tid 89672] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/memberfuns.php"] [unique_id "amutqS0W4wRrtnDoPaj71AAAAZg"]
[Thu Jul 30 15:01:45.650125 2026] [security2:error] [pid 89520:tid 89672] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/memberfuns.php"] [unique_id "amutqS0W4wRrtnDoPaj71AAAAZg"]
[Thu Jul 30 15:01:46.163951 2026] [security2:error] [pid 87988:tid 88147] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/orange3.php"] [unique_id "amutqjipAwzptuCxBrhhywAAASc"]
[Thu Jul 30 15:01:46.164051 2026] [security2:error] [pid 87988:tid 88147] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/orange3.php"] [unique_id "amutqjipAwzptuCxBrhhywAAASc"]
[Thu Jul 30 15:01:46.256940 2026] [security2:error] [pid 89520:tid 89787] [client 20.226.5.174:16068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lndex.php"] [unique_id "amutqi0W4wRrtnDoPaj74gAAAgs"]
[Thu Jul 30 15:01:46.606093 2026] [security2:error] [pid 89520:tid 89717] [client 135.119.63.61:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filemanagerwp.php"] [unique_id "amutqi0W4wRrtnDoPaj76AAAAcU"]
[Thu Jul 30 15:01:46.748588 2026] [security2:error] [pid 89520:tid 89727] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amutqi0W4wRrtnDoPaj77QAAAc8"]
[Thu Jul 30 15:01:46.748719 2026] [security2:error] [pid 89520:tid 89727] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amutqi0W4wRrtnDoPaj77QAAAc8"]
[Thu Jul 30 15:01:46.823379 2026] [core:notice] [pid 87988:tid 88188] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:47.069140 2026] [core:notice] [pid 89520:tid 89719] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:47.193882 2026] [security2:error] [pid 89520:tid 89721] [client 20.226.5.174:16070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lnedx.php"] [unique_id "amutqy0W4wRrtnDoPaj78QAAAck"]
[Thu Jul 30 15:01:47.327499 2026] [security2:error] [pid 89520:tid 89713] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-the.php"] [unique_id "amutqy0W4wRrtnDoPaj79QAAAcE"]
[Thu Jul 30 15:01:47.327606 2026] [security2:error] [pid 89520:tid 89713] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/wp-the.php"] [unique_id "amutqy0W4wRrtnDoPaj79QAAAcE"]
[Thu Jul 30 15:01:47.336143 2026] [core:notice] [pid 89520:tid 89737] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:47.372325 2026] [security2:error] [pid 89520:tid 89777] [client 85.208.96.193:62204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/23/justica-eleitoral-nega-liminar-de-raniery-paulino-contra-falas-de-gervasio-maia-apos-confusao-em-guarabira/"] [unique_id "amutqy0W4wRrtnDoPaj79wAAAgE"]
[Thu Jul 30 15:01:47.372442 2026] [security2:error] [pid 89520:tid 89777] [client 85.208.96.193:62204] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/23/justica-eleitoral-nega-liminar-de-raniery-paulino-contra-falas-de-gervasio-maia-apos-confusao-em-guarabira/"] [unique_id "amutqy0W4wRrtnDoPaj79wAAAgE"]
[Thu Jul 30 15:01:47.586526 2026] [core:notice] [pid 89520:tid 89753] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:47.889706 2026] [security2:error] [pid 89520:tid 89699] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/crgio.php"] [unique_id "amutqy0W4wRrtnDoPaj7_wAAAbM"]
[Thu Jul 30 15:01:47.889811 2026] [security2:error] [pid 89520:tid 89699] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/crgio.php"] [unique_id "amutqy0W4wRrtnDoPaj7_wAAAbM"]
[Thu Jul 30 15:01:48.092725 2026] [security2:error] [pid 89520:tid 89692] [client 20.226.5.174:16083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lo.php"] [unique_id "amutrC0W4wRrtnDoPaj8AAAAAaw"]
[Thu Jul 30 15:01:48.104774 2026] [security2:error] [pid 89520:tid 89706] [client 20.91.199.21:38530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/json.php"] [unique_id "amutrC0W4wRrtnDoPaj8AQAAAbo"]
[Thu Jul 30 15:01:48.475032 2026] [security2:error] [pid 89520:tid 89704] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ws13.php"] [unique_id "amutrC0W4wRrtnDoPaj8CwAAAbg"]
[Thu Jul 30 15:01:48.475145 2026] [security2:error] [pid 89520:tid 89704] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ws13.php"] [unique_id "amutrC0W4wRrtnDoPaj8CwAAAbg"]
[Thu Jul 30 15:01:48.623547 2026] [security2:error] [pid 89520:tid 89671] [client 135.119.63.61:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/files.php"] [unique_id "amutrC0W4wRrtnDoPaj8DAAAAZc"]
[Thu Jul 30 15:01:49.012329 2026] [core:notice] [pid 89520:tid 89628] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:49.026674 2026] [security2:error] [pid 89520:tid 89773] [client 20.226.5.174:16073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/load.php"] [unique_id "amutrS0W4wRrtnDoPaj8FwAAAf0"]
[Thu Jul 30 15:01:49.064972 2026] [security2:error] [pid 89520:tid 89727] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/srontol.php"] [unique_id "amutrS0W4wRrtnDoPaj8GAAAAc8"]
[Thu Jul 30 15:01:49.065095 2026] [security2:error] [pid 89520:tid 89727] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/srontol.php"] [unique_id "amutrS0W4wRrtnDoPaj8GAAAAc8"]
[Thu Jul 30 15:01:49.255163 2026] [core:notice] [pid 89520:tid 89629] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:49.405672 2026] [core:notice] [pid 89520:tid 89631] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:49.477898 2026] [core:notice] [pid 87988:tid 88218] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:49.560707 2026] [security2:error] [pid 89520:tid 89688] [client 135.119.63.61:55977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filled.php"] [unique_id "amutrS0W4wRrtnDoPaj8IwAAAag"]
[Thu Jul 30 15:01:49.593425 2026] [security2:error] [pid 89520:tid 89766] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/miru3.php"] [unique_id "amutrS0W4wRrtnDoPaj8JAAAAfY"]
[Thu Jul 30 15:01:49.593515 2026] [security2:error] [pid 89520:tid 89766] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/miru3.php"] [unique_id "amutrS0W4wRrtnDoPaj8JAAAAfY"]
[Thu Jul 30 15:01:49.749366 2026] [core:notice] [pid 89520:tid 89726] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:49.921080 2026] [security2:error] [pid 89520:tid 89777] [client 20.226.5.174:16084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/loader.php"] [unique_id "amutrS0W4wRrtnDoPaj8KgAAAgE"]
[Thu Jul 30 15:01:50.139221 2026] [security2:error] [pid 87988:tid 88234] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ingfo.php"] [unique_id "amutrjipAwzptuCxBrhh9QAAAX4"]
[Thu Jul 30 15:01:50.139336 2026] [security2:error] [pid 87988:tid 88234] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ingfo.php"] [unique_id "amutrjipAwzptuCxBrhh9QAAAX4"]
[Thu Jul 30 15:01:50.176087 2026] [security2:error] [pid 87988:tid 88125] [client 47.128.112.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "club4.au"] [uri "/index.php"] [unique_id "amutqjipAwzptuCxBrhhzgAAARE"]
[Thu Jul 30 15:01:50.660678 2026] [core:notice] [pid 89520:tid 89666] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:50.739657 2026] [security2:error] [pid 89520:tid 89785] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ey5.php"] [unique_id "amutri0W4wRrtnDoPaj8NQAAAgk"]
[Thu Jul 30 15:01:50.739762 2026] [security2:error] [pid 89520:tid 89785] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/ey5.php"] [unique_id "amutri0W4wRrtnDoPaj8NQAAAgk"]
[Thu Jul 30 15:01:50.816477 2026] [security2:error] [pid 89520:tid 89706] [client 20.226.5.174:16082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/local.php"] [unique_id "amutri0W4wRrtnDoPaj8OQAAAbo"]
[Thu Jul 30 15:01:50.906625 2026] [core:notice] [pid 89520:tid 89702] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:51.186836 2026] [security2:error] [pid 87988:tid 88238] [client 135.119.63.61:9030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/filter.php"] [unique_id "amutrzipAwzptuCxBrhiAgAAAYI"]
[Thu Jul 30 15:01:51.339771 2026] [security2:error] [pid 89520:tid 89698] [client 52.165.196.84:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.196.165.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fine.php"] [unique_id "amutry0W4wRrtnDoPaj8QgAAAbI"]
[Thu Jul 30 15:01:51.339899 2026] [security2:error] [pid 89520:tid 89698] [client 52.165.196.84:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.buyfluoxetine.store"] [uri "/fine.php"] [unique_id "amutry0W4wRrtnDoPaj8QgAAAbI"]
[Thu Jul 30 15:01:51.629087 2026] [security2:error] [pid 89520:tid 89740] [client 20.104.18.253:10553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/erinyani/baxa1.php"] [unique_id "amutry0W4wRrtnDoPaj8RwAAAdw"]
[Thu Jul 30 15:01:51.712620 2026] [security2:error] [pid 89520:tid 89763] [client 20.226.5.174:16069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/locale.php"] [unique_id "amutry0W4wRrtnDoPaj8SAAAAfM"]
[Thu Jul 30 15:01:52.087701 2026] [security2:error] [pid 89520:tid 89788] [client 135.119.63.61:9076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/finley/min.php"] [unique_id "amutsC0W4wRrtnDoPaj8UAAAAgw"]
[Thu Jul 30 15:01:52.180878 2026] [core:notice] [pid 89520:tid 89724] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:52.222881 2026] [core:notice] [pid 89520:tid 89718] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:52.243868 2026] [security2:error] [pid 89520:tid 89719] [client 20.104.18.253:10538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/erinyani/gebase.php"] [unique_id "amutsC0W4wRrtnDoPaj8VAAAAcc"]
[Thu Jul 30 15:01:52.467343 2026] [core:notice] [pid 89520:tid 89737] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:52.607417 2026] [security2:error] [pid 89520:tid 89746] [client 20.226.5.174:16079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lock.php"] [unique_id "amutsC0W4wRrtnDoPaj8WgAAAeI"]
[Thu Jul 30 15:01:52.906797 2026] [security2:error] [pid 89520:tid 89735] [client 20.104.18.253:10509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/ern1.php"] [unique_id "amutsC0W4wRrtnDoPaj8XgAAAdc"]
[Thu Jul 30 15:01:53.319581 2026] [security2:error] [pid 89520:tid 89673] [client 135.119.63.61:55975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/fitnessbase/404.php"] [unique_id "amutsS0W4wRrtnDoPaj8YwAAAZk"]
[Thu Jul 30 15:01:53.517592 2026] [security2:error] [pid 89520:tid 89768] [client 20.91.199.21:47225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/mini.php"] [unique_id "amutsS0W4wRrtnDoPaj8ZwAAAfg"]
[Thu Jul 30 15:01:53.553012 2026] [security2:error] [pid 89520:tid 89670] [client 20.226.5.174:16080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lock1.php"] [unique_id "amutsS0W4wRrtnDoPaj8aQAAAZY"]
[Thu Jul 30 15:01:53.555251 2026] [security2:error] [pid 89520:tid 89652] [remote 154.26.129.62:50874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.129.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-login.php"] [unique_id "amutsS0W4wRrtnDoPaj8aAABrXY"]
[Thu Jul 30 15:01:53.555427 2026] [security2:error] [pid 89520:tid 89769] [client 20.104.18.253:10552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/eror.php"] [unique_id "amutsS0W4wRrtnDoPaj8agAAAfk"]
[Thu Jul 30 15:01:53.759063 2026] [core:notice] [pid 87988:tid 88165] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:54.013257 2026] [core:notice] [pid 89520:tid 89761] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:54.214740 2026] [security2:error] [pid 89520:tid 89678] [client 20.104.18.253:10529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/error-protection.php"] [unique_id "amutsi0W4wRrtnDoPaj8cwAAAZ4"]
[Thu Jul 30 15:01:54.279966 2026] [security2:error] [pid 89520:tid 89705] [client 20.203.148.31:6671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/network/xleet.php"] [unique_id "amutsi0W4wRrtnDoPaj8dAAAAbk"]
[Thu Jul 30 15:01:54.322652 2026] [security2:error] [pid 87988:tid 88200] [client 135.119.63.61:55981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/fitnessbase/crp.php"] [unique_id "amutsjipAwzptuCxBrhiIwAAAVw"]
[Thu Jul 30 15:01:54.490232 2026] [security2:error] [pid 87988:tid 88119] [client 20.226.5.174:16086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lock360.php"] [unique_id "amutsjipAwzptuCxBrhiJwAAAQs"]
[Thu Jul 30 15:01:54.509902 2026] [core:notice] [pid 87988:tid 88178] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:54.751087 2026] [core:notice] [pid 87988:tid 88222] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:54.872095 2026] [security2:error] [pid 87988:tid 88159] [client 20.104.18.253:10963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/error.php"] [unique_id "amutsjipAwzptuCxBrhiLwAAATM"]
[Thu Jul 30 15:01:55.202331 2026] [security2:error] [pid 89520:tid 89655] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutsy0W4wRrtnDoPaj8fgAB3Hk"]
[Thu Jul 30 15:01:55.202512 2026] [security2:error] [pid 89520:tid 89740] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutsy0W4wRrtnDoPaj8fgAB3Hk"]
[Thu Jul 30 15:01:55.285248 2026] [security2:error] [pid 89520:tid 89749] [client 20.91.199.21:32837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/chosen.php"] [unique_id "amutsy0W4wRrtnDoPaj8gAAAAeU"]
[Thu Jul 30 15:01:55.320214 2026] [core:notice] [pid 89520:tid 89659] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:55.420877 2026] [security2:error] [pid 89520:tid 89752] [client 20.226.5.174:16066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lofter.php"] [unique_id "amutsy0W4wRrtnDoPaj8ggAAAeg"]
[Thu Jul 30 15:01:55.483619 2026] [security2:error] [pid 89520:tid 89721] [client 20.104.18.253:10947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/ertg.php"] [unique_id "amutsy0W4wRrtnDoPaj8gwAAAck"]
[Thu Jul 30 15:01:55.653022 2026] [core:notice] [pid 89520:tid 89675] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:55.956454 2026] [core:notice] [pid 89520:tid 89784] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:56.067708 2026] [security2:error] [pid 89520:tid 89669] [client 20.91.199.21:32833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/kj.php"] [unique_id "amuttC0W4wRrtnDoPaj8jQAAAZU"]
[Thu Jul 30 15:01:56.154436 2026] [security2:error] [pid 87988:tid 88145] [client 20.104.18.253:10958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/evil.php"] [unique_id "amuttDipAwzptuCxBrhiPwAAASU"]
[Thu Jul 30 15:01:56.161991 2026] [security2:error] [pid 89520:tid 89763] [client 135.119.63.61:55966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/fitnessbase/dev.php"] [unique_id "amuttC0W4wRrtnDoPaj8kwAAAfM"]
[Thu Jul 30 15:01:56.222393 2026] [core:notice] [pid 89520:tid 89665] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:56.316039 2026] [security2:error] [pid 87988:tid 88169] [client 20.226.5.174:16089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/log.php"] [unique_id "amuttDipAwzptuCxBrhiQAAAAT0"]
[Thu Jul 30 15:01:56.402880 2026] [core:notice] [pid 89520:tid 89720] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:56.406752 2026] [security2:error] [pid 89520:tid 89720] [client 66.249.79.229:57409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/view/390/247"] [unique_id "amuttC0W4wRrtnDoPaj8kgAAAcg"]
[Thu Jul 30 15:01:56.573574 2026] [core:notice] [pid 89520:tid 89699] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:56.623249 2026] [security2:error] [pid 89520:tid 89744] [client 20.91.199.21:40396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/wp-files.php"] [unique_id "amuttC0W4wRrtnDoPaj8mAAAAeA"]
[Thu Jul 30 15:01:56.628133 2026] [core:notice] [pid 89520:tid 89536] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:56.628990 2026] [security2:error] [pid 87988:tid 88168] [client 20.203.148.31:14488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuttDipAwzptuCxBrhiQwAAATw"]
[Thu Jul 30 15:01:56.631109 2026] [security2:error] [pid 89520:tid 89778] [client 66.249.65.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/297/297"] [unique_id "amuttC0W4wRrtnDoPaj8lQACAgY"]
[Thu Jul 30 15:01:56.880274 2026] [security2:error] [pid 87988:tid 88129] [client 20.104.18.253:10517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/eviltwin.php"] [unique_id "amuttDipAwzptuCxBrhiSAAAARU"]
[Thu Jul 30 15:01:57.218038 2026] [security2:error] [pid 89520:tid 89760] [client 20.226.5.174:16085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/log404.php"] [unique_id "amuttS0W4wRrtnDoPaj8oQAAAfA"]
[Thu Jul 30 15:01:57.364908 2026] [security2:error] [pid 87988:tid 88186] [client 20.91.199.21:38564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/wp-setup.php"] [unique_id "amuttTipAwzptuCxBrhiUAAAAU4"]
[Thu Jul 30 15:01:57.368002 2026] [core:notice] [pid 89520:tid 89751] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:57.372098 2026] [security2:error] [pid 89520:tid 89751] [client 66.249.79.8:59281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/download/8379/3238"] [unique_id "amuttS0W4wRrtnDoPaj8ngAAAec"]
[Thu Jul 30 15:01:57.604357 2026] [security2:error] [pid 89520:tid 89667] [client 20.104.18.253:10545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/ex.php"] [unique_id "amuttS0W4wRrtnDoPaj8pwAAAZM"]
[Thu Jul 30 15:01:57.749944 2026] [core:notice] [pid 89520:tid 89534] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:57.994643 2026] [security2:error] [pid 89520:tid 89717] [client 20.91.199.21:47203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/defaults.php"] [unique_id "amuttS0W4wRrtnDoPaj8rgAAAcU"]
[Thu Jul 30 15:01:58.015057 2026] [security2:error] [pid 89520:tid 89696] [client 20.203.148.31:36198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/user/flower.php"] [unique_id "amutti0W4wRrtnDoPaj8rwAAAbA"]
[Thu Jul 30 15:01:58.027631 2026] [security2:error] [pid 89520:tid 89673] [client 135.119.63.61:55985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/fix.php"] [unique_id "amutti0W4wRrtnDoPaj8sAAAAZk"]
[Thu Jul 30 15:01:58.133959 2026] [security2:error] [pid 89520:tid 89716] [client 20.226.5.174:16094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/login.php"] [unique_id "amutti0W4wRrtnDoPaj8sgAAAcQ"]
[Thu Jul 30 15:01:58.302935 2026] [security2:error] [pid 87988:tid 88176] [client 20.104.18.253:10547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/ex0shell.php"] [unique_id "amuttjipAwzptuCxBrhiWQAAAUQ"]
[Thu Jul 30 15:01:58.343424 2026] [security2:error] [pid 89520:tid 89733] [client 198.199.85.181:54298] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.6.43.248"] [uri "/index.cgi"] [unique_id "amutti0W4wRrtnDoPaj8tgAAAdU"]
[Thu Jul 30 15:01:58.486309 2026] [core:notice] [pid 89520:tid 89765] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:58.733686 2026] [security2:error] [pid 89520:tid 89538] [remote 74.7.227.39:45518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amutti0W4wRrtnDoPaj8uQABrgg"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin/network
[Thu Jul 30 15:01:58.741292 2026] [core:notice] [pid 87988:tid 88146] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:58.861461 2026] [security2:error] [pid 89520:tid 89719] [client 194.102.104.29:52738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "amutti0W4wRrtnDoPaj8uwAAAcc"]
[Thu Jul 30 15:01:58.874792 2026] [security2:error] [pid 89520:tid 89788] [client 20.203.148.31:12951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/user/xleet.php"] [unique_id "amutti0W4wRrtnDoPaj8vAAAAgw"]
[Thu Jul 30 15:01:58.925468 2026] [security2:error] [pid 89520:tid 89758] [client 20.104.18.253:10535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/excel.php"] [unique_id "amutti0W4wRrtnDoPaj8vQAAAe4"]
[Thu Jul 30 15:01:58.965739 2026] [security2:error] [pid 87988:tid 88171] [client 20.91.199.21:32844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/gtc.php"] [unique_id "amuttjipAwzptuCxBrhiYwAAAT8"]
[Thu Jul 30 15:01:59.080911 2026] [security2:error] [pid 89520:tid 89721] [client 20.226.5.174:16105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/logs.php"] [unique_id "amutty0W4wRrtnDoPaj8vgAAAck"]
[Thu Jul 30 15:01:59.249966 2026] [security2:error] [pid 89520:tid 89690] [client 194.102.104.29:53207] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/conf/.env"] [unique_id "amutty0W4wRrtnDoPaj8wwAAAao"]
[Thu Jul 30 15:01:59.523425 2026] [security2:error] [pid 89520:tid 89772] [client 20.91.199.21:37742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/import.php"] [unique_id "amutty0W4wRrtnDoPaj8yAAAAfw"]
[Thu Jul 30 15:01:59.556564 2026] [security2:error] [pid 89520:tid 89672] [client 194.102.104.29:53481] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/wp-content/.env"] [unique_id "amutty0W4wRrtnDoPaj8yQAAAZg"]
[Thu Jul 30 15:01:59.563346 2026] [security2:error] [pid 87988:tid 88194] [client 20.104.18.253:10559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/exit.php"] [unique_id "amuttzipAwzptuCxBrhiaQAAAVY"]
[Thu Jul 30 15:01:59.769089 2026] [core:notice] [pid 87988:tid 88139] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:01:59.854794 2026] [security2:error] [pid 89520:tid 89731] [client 194.102.104.29:53863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/wp-admin/.env"] [unique_id "amutty0W4wRrtnDoPaj8zgAAAdM"]
[Thu Jul 30 15:01:59.994008 2026] [security2:error] [pid 89520:tid 89763] [client 20.226.5.174:16099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/logs_view.php"] [unique_id "amutty0W4wRrtnDoPaj8zwAAAfM"]
[Thu Jul 30 15:02:00.154192 2026] [security2:error] [pid 87988:tid 88151] [client 194.102.104.29:54299] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/library/.env"] [unique_id "amutuDipAwzptuCxBrhicwAAASs"]
[Thu Jul 30 15:02:00.173177 2026] [security2:error] [pid 87988:tid 88119] [client 20.104.18.253:10983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/exp.php"] [unique_id "amutuDipAwzptuCxBrhidAAAAQs"]
[Thu Jul 30 15:02:00.407137 2026] [core:notice] [pid 89520:tid 89682] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:00.425134 2026] [security2:error] [pid 89520:tid 89782] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutty0W4wRrtnDoPaj8zQACBgo"]
[Thu Jul 30 15:02:00.485471 2026] [security2:error] [pid 89520:tid 89770] [client 194.102.104.29:54467] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/new/.env"] [unique_id "amutuC0W4wRrtnDoPaj80gAAAfo"]
[Thu Jul 30 15:02:00.820954 2026] [security2:error] [pid 89520:tid 89693] [client 20.104.18.253:10501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/export.php"] [unique_id "amutuC0W4wRrtnDoPaj81gAAAa0"]
[Thu Jul 30 15:02:00.845153 2026] [security2:error] [pid 89520:tid 89704] [client 194.102.104.29:54733] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/vendor/.env"] [unique_id "amutuC0W4wRrtnDoPaj81wAAAbg"]
[Thu Jul 30 15:02:00.932663 2026] [security2:error] [pid 89520:tid 89769] [client 20.226.5.174:16067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lok.php"] [unique_id "amutuC0W4wRrtnDoPaj82gAAAfk"]
[Thu Jul 30 15:02:01.103121 2026] [security2:error] [pid 89520:tid 89734] [client 20.91.199.21:35217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/lufix.php"] [unique_id "amutuS0W4wRrtnDoPaj83gAAAdY"]
[Thu Jul 30 15:02:01.437956 2026] [security2:error] [pid 89520:tid 89678] [client 20.104.18.253:10546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/ext.php"] [unique_id "amutuS0W4wRrtnDoPaj84AAAAZ4"]
[Thu Jul 30 15:02:01.469504 2026] [security2:error] [pid 89520:tid 89676] [client 194.102.104.29:55308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "amutuS0W4wRrtnDoPaj84gAAAZw"]
[Thu Jul 30 15:02:01.681989 2026] [security2:error] [pid 89520:tid 89790] [client 20.203.148.31:12973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-admin/xleet.php"] [unique_id "amutuS0W4wRrtnDoPaj85AAAAg4"]
[Thu Jul 30 15:02:01.722113 2026] [security2:error] [pid 87988:tid 88118] [client 135.119.63.61:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/fix/as.php"] [unique_id "amutuTipAwzptuCxBrhihgAAAQo"]
[Thu Jul 30 15:02:01.802590 2026] [security2:error] [pid 89520:tid 89701] [client 194.102.104.29:55714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/local/.env"] [unique_id "amutuS0W4wRrtnDoPaj85QAAAbU"]
[Thu Jul 30 15:02:01.829505 2026] [security2:error] [pid 89520:tid 89681] [client 20.226.5.174:16107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lol.php"] [unique_id "amutuS0W4wRrtnDoPaj85gAAAaE"]
[Thu Jul 30 15:02:01.964513 2026] [core:notice] [pid 87988:tid 88208] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:02.067609 2026] [security2:error] [pid 87988:tid 88229] [client 20.104.18.253:10528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/extension/extension/Not_Found.php"] [unique_id "amutujipAwzptuCxBrhijwAAAXk"]
[Thu Jul 30 15:02:02.377342 2026] [security2:error] [pid 89520:tid 89687] [client 194.102.104.29:55832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "amutui0W4wRrtnDoPaj87AAAAac"]
[Thu Jul 30 15:02:02.674570 2026] [security2:error] [pid 89520:tid 89694] [client 20.104.18.253:10505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/extension/extension/admin.php"] [unique_id "amutui0W4wRrtnDoPaj87gAAAa4"]
[Thu Jul 30 15:02:02.676912 2026] [security2:error] [pid 89520:tid 89758] [client 194.102.104.29:55998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/blog/.env"] [unique_id "amutui0W4wRrtnDoPaj87wAAAe4"]
[Thu Jul 30 15:02:02.744250 2026] [security2:error] [pid 89520:tid 89752] [client 20.226.5.174:16101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lolzk.php"] [unique_id "amutui0W4wRrtnDoPaj88AAAAeg"]
[Thu Jul 30 15:02:02.792155 2026] [security2:error] [pid 89520:tid 89767] [client 20.91.199.21:38546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/Geforce.php"] [unique_id "amutui0W4wRrtnDoPaj88QAAAfc"]
[Thu Jul 30 15:02:02.854060 2026] [core:notice] [pid 89520:tid 89677] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:02.989357 2026] [security2:error] [pid 89520:tid 89766] [client 194.102.104.29:56263] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/crm/.env"] [unique_id "amutui0W4wRrtnDoPaj88wAAAfY"]
[Thu Jul 30 15:02:03.102864 2026] [security2:error] [pid 89520:tid 89718] [client 135.119.63.61:57965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/fix/up-constructor.php"] [unique_id "amutuy0W4wRrtnDoPaj89wAAAcY"]
[Thu Jul 30 15:02:03.322913 2026] [security2:error] [pid 87988:tid 88241] [client 20.104.18.253:10558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/extension/extension/cloud.php"] [unique_id "amutuzipAwzptuCxBrhioQAAAYU"]
[Thu Jul 30 15:02:03.625826 2026] [security2:error] [pid 89520:tid 89723] [client 194.102.104.29:56784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "amutuy0W4wRrtnDoPaj8_AAAAcs"]
[Thu Jul 30 15:02:03.683023 2026] [security2:error] [pid 89520:tid 89772] [client 20.226.5.174:16122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lufix.php"] [unique_id "amutuy0W4wRrtnDoPaj8_wAAAfw"]
[Thu Jul 30 15:02:03.942069 2026] [security2:error] [pid 87988:tid 88135] [client 20.104.18.253:10548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/extension/extension/ultra.php"] [unique_id "amutuzipAwzptuCxBrhipgAAARs"]
[Thu Jul 30 15:02:03.962251 2026] [security2:error] [pid 89520:tid 89699] [client 194.102.104.29:56910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "amutuy0W4wRrtnDoPaj9AQAAAbM"]
[Thu Jul 30 15:02:04.404556 2026] [security2:error] [pid 89520:tid 89685] [client 194.102.104.29:57086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/app/config/.env"] [unique_id "amutvC0W4wRrtnDoPaj9BAAAAaU"]
[Thu Jul 30 15:02:04.577805 2026] [security2:error] [pid 89520:tid 89692] [client 20.226.5.174:16096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lupo.php"] [unique_id "amutvC0W4wRrtnDoPaj9BgAAAaw"]
[Thu Jul 30 15:02:04.627634 2026] [security2:error] [pid 87988:tid 88120] [client 20.104.18.253:10507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/extension/wpm.php"] [unique_id "amutvDipAwzptuCxBrhisAAAAQw"]
[Thu Jul 30 15:02:04.724123 2026] [security2:error] [pid 87988:tid 88038] [remote 156.59.198.135:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nafmedical.com"] [uri "/wp-content/uploads/2025/11/3.svg"] [unique_id "amutvDipAwzptuCxBrhitAABPzE"], referer: https://nafmedical.com/
[Thu Jul 30 15:02:04.724162 2026] [security2:error] [pid 87988:tid 88133] [client 194.102.104.29:57456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "amutvDipAwzptuCxBrhiswAAARk"]
[Thu Jul 30 15:02:05.010475 2026] [security2:error] [pid 89520:tid 89783] [client 223.109.255.156:54546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-48/"] [unique_id "amutvS0W4wRrtnDoPaj9CgAAAgc"]
[Thu Jul 30 15:02:05.010617 2026] [security2:error] [pid 89520:tid 89783] [client 223.109.255.156:54546] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-low-48/"] [unique_id "amutvS0W4wRrtnDoPaj9CgAAAgc"]
[Thu Jul 30 15:02:05.103442 2026] [security2:error] [pid 89520:tid 89735] [client 20.203.148.31:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.raad.pk"] [uri "/wp-config-sample.php"] [unique_id "amutvS0W4wRrtnDoPaj9DQAAAdc"]
[Thu Jul 30 15:02:05.205394 2026] [security2:error] [pid 87988:tid 88224] [client 20.91.199.21:36780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/a4.php"] [unique_id "amutvTipAwzptuCxBrhiuQAAAXQ"]
[Thu Jul 30 15:02:05.218596 2026] [security2:error] [pid 89520:tid 89684] [client 194.102.104.29:57789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/audio/.env"] [unique_id "amutvS0W4wRrtnDoPaj9EQAAAaQ"]
[Thu Jul 30 15:02:05.379953 2026] [security2:error] [pid 89520:tid 89693] [client 20.104.18.253:10690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/ez.php"] [unique_id "amutvS0W4wRrtnDoPaj9FAAAAa0"]
[Thu Jul 30 15:02:05.478994 2026] [security2:error] [pid 89520:tid 89667] [client 20.226.5.174:16106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/luxx.php"] [unique_id "amutvS0W4wRrtnDoPaj9FQAAAZM"]
[Thu Jul 30 15:02:05.560055 2026] [security2:error] [pid 89520:tid 89680] [client 194.102.104.29:57942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/cgi-bin/.env"] [unique_id "amutvS0W4wRrtnDoPaj9FgAAAaA"]
[Thu Jul 30 15:02:05.688336 2026] [security2:error] [pid 87988:tid 88175] [client 135.119.63.61:57927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediaspawn.com"] [uri "/fix/up.php"] [unique_id "amutvTipAwzptuCxBrhiwAAAAUM"]
[Thu Jul 30 15:02:05.759674 2026] [security2:error] [pid 89520:tid 89544] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutvS0W4wRrtnDoPaj9GgABwg4"]
[Thu Jul 30 15:02:05.759842 2026] [security2:error] [pid 89520:tid 89714] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutvS0W4wRrtnDoPaj9GgABwg4"]
[Thu Jul 30 15:02:05.846550 2026] [security2:error] [pid 89520:tid 89709] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutvS0W4wRrtnDoPaj9EgAAAb0"]
[Thu Jul 30 15:02:05.857005 2026] [security2:error] [pid 89520:tid 89745] [client 194.102.104.29:58118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "amutvS0W4wRrtnDoPaj9GwAAAeE"]
[Thu Jul 30 15:02:06.069066 2026] [security2:error] [pid 87988:tid 88142] [client 20.104.18.253:11091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/f.php"] [unique_id "amutvjipAwzptuCxBrhixAAAASI"]
[Thu Jul 30 15:02:06.196414 2026] [security2:error] [pid 89520:tid 89547] [remote 74.7.227.39:51360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amutvi0W4wRrtnDoPaj9HwABxBE"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin/network
[Thu Jul 30 15:02:06.379514 2026] [security2:error] [pid 89520:tid 89681] [client 20.226.5.174:16075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lv.php"] [unique_id "amutvi0W4wRrtnDoPaj9IgAAAaE"]
[Thu Jul 30 15:02:06.474045 2026] [security2:error] [pid 89520:tid 89687] [client 194.102.104.29:58521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "amutvi0W4wRrtnDoPaj9IwAAAac"]
[Thu Jul 30 15:02:06.546184 2026] [core:notice] [pid 89520:tid 89689] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:06.715232 2026] [security2:error] [pid 87988:tid 88217] [client 20.104.18.253:10714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/f0x.php"] [unique_id "amutvjipAwzptuCxBrhizQAAAW0"]
[Thu Jul 30 15:02:06.816167 2026] [core:notice] [pid 87988:tid 88212] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:06.819681 2026] [security2:error] [pid 87988:tid 88212] [client 66.249.79.229:60159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/3879/1920"] [unique_id "amutvjipAwzptuCxBrhi0AAAAWg"]
[Thu Jul 30 15:02:06.847551 2026] [core:notice] [pid 89520:tid 89766] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:06.960919 2026] [security2:error] [pid 87988:tid 88198] [client 194.102.104.29:58824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/base/.env"] [unique_id "amutvjipAwzptuCxBrhi0QAAAVo"]
[Thu Jul 30 15:02:07.271680 2026] [security2:error] [pid 87988:tid 88150] [client 20.226.5.174:16087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pop.hmhs.ph"] [uri "/lwbdene/index.php"] [unique_id "amutvzipAwzptuCxBrhi1gAAASo"]
[Thu Jul 30 15:02:07.302196 2026] [security2:error] [pid 89520:tid 89729] [client 194.102.104.29:60800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "amutvy0W4wRrtnDoPaj9MQAAAdE"]
[Thu Jul 30 15:02:07.392164 2026] [security2:error] [pid 87988:tid 88118] [client 20.104.18.253:11097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/f1.php"] [unique_id "amutvzipAwzptuCxBrhi2QAAAQo"]
[Thu Jul 30 15:02:07.466671 2026] [core:notice] [pid 89520:tid 89732] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:07.587698 2026] [security2:error] [pid 89520:tid 89711] [client 173.249.217.23:39890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.217.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amutvy0W4wRrtnDoPaj9OAAAAb8"]
[Thu Jul 30 15:02:07.587806 2026] [security2:error] [pid 89520:tid 89711] [client 173.249.217.23:39890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amutvy0W4wRrtnDoPaj9OAAAAb8"]
[Thu Jul 30 15:02:07.684466 2026] [core:notice] [pid 89520:tid 89772] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:07.869680 2026] [security2:error] [pid 89520:tid 89720] [client 194.102.104.29:63117] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/vendor/laravel/.env"] [unique_id "amutvy0W4wRrtnDoPaj9PgAAAcg"]
[Thu Jul 30 15:02:08.038120 2026] [security2:error] [pid 89520:tid 89685] [client 20.104.18.253:11074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/f1zr.php"] [unique_id "amutwC0W4wRrtnDoPaj9QQAAAaU"]
[Thu Jul 30 15:02:08.429735 2026] [security2:error] [pid 89520:tid 89751] [client 194.102.104.29:50061] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "amutwC0W4wRrtnDoPaj9RwAAAec"]
[Thu Jul 30 15:02:08.744890 2026] [security2:error] [pid 89520:tid 89684] [client 20.104.18.253:11073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/f2.php"] [unique_id "amutwC0W4wRrtnDoPaj9SAAAAaQ"]
[Thu Jul 30 15:02:08.782544 2026] [security2:error] [pid 89520:tid 89748] [client 78.47.42.23:45574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/sitemap_index.xml"] [unique_id "amutwC0W4wRrtnDoPaj9SQAAAeQ"]
[Thu Jul 30 15:02:08.898965 2026] [security2:error] [pid 87988:tid 88235] [client 194.102.104.29:52377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/protected/.env"] [unique_id "amutwDipAwzptuCxBrhi7wAAAX8"]
[Thu Jul 30 15:02:09.478600 2026] [security2:error] [pid 89520:tid 89680] [client 20.104.18.253:11082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/f3.php"] [unique_id "amutwS0W4wRrtnDoPaj9UAAAAaA"]
[Thu Jul 30 15:02:09.560127 2026] [core:notice] [pid 87988:tid 88239] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:09.750832 2026] [security2:error] [pid 89520:tid 89674] [client 194.102.104.29:54487] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/newsite/.env"] [unique_id "amutwS0W4wRrtnDoPaj9VgAAAZo"]
[Thu Jul 30 15:02:09.882032 2026] [core:notice] [pid 87988:tid 88223] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:10.007517 2026] [security2:error] [pid 89520:tid 89715] [client 78.47.42.23:45588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/sitemap_index.xml"] [unique_id "amutwi0W4wRrtnDoPaj9WwAAAcM"]
[Thu Jul 30 15:02:10.085663 2026] [security2:error] [pid 89520:tid 89679] [client 194.102.104.29:55954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "amutwi0W4wRrtnDoPaj9XAAAAZ8"]
[Thu Jul 30 15:02:10.161219 2026] [security2:error] [pid 89520:tid 89787] [client 20.91.199.21:47192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/accueil.php"] [unique_id "amutwi0W4wRrtnDoPaj9XQAAAgs"]
[Thu Jul 30 15:02:10.239318 2026] [security2:error] [pid 89520:tid 89747] [client 20.104.18.253:10729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/f35.php"] [unique_id "amutwi0W4wRrtnDoPaj9XgAAAeM"]
[Thu Jul 30 15:02:10.393687 2026] [security2:error] [pid 89520:tid 89765] [client 194.102.104.29:58389] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/sites/all/libraries/mailchimp/.env"] [unique_id "amutwi0W4wRrtnDoPaj9YAAAAfU"]
[Thu Jul 30 15:02:10.701689 2026] [security2:error] [pid 87988:tid 88151] [client 194.102.104.29:59226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "amutwjipAwzptuCxBrhjCQAAASs"]
[Thu Jul 30 15:02:10.806869 2026] [security2:error] [pid 89520:tid 89788] [client 52.4.238.8:25870] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guethleentertainment.com"] [uri "/robots.txt"] [unique_id "amutwi0W4wRrtnDoPaj9YgAAAgw"]
[Thu Jul 30 15:02:10.916518 2026] [security2:error] [pid 89520:tid 89719] [client 20.104.18.253:10751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/f4.php"] [unique_id "amutwi0W4wRrtnDoPaj9ZAAAAcc"]
[Thu Jul 30 15:02:10.999506 2026] [security2:error] [pid 89520:tid 89767] [client 194.102.104.29:59526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "amutwi0W4wRrtnDoPaj9ZQAAAfc"]
[Thu Jul 30 15:02:11.565009 2026] [security2:error] [pid 89520:tid 89739] [client 20.104.18.253:10695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/f5.php"] [unique_id "amutwy0W4wRrtnDoPaj9bQAAAds"]
[Thu Jul 30 15:02:11.571176 2026] [security2:error] [pid 89520:tid 89664] [client 20.91.199.21:40423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/dashboard.php"] [unique_id "amutwy0W4wRrtnDoPaj9bgAAAZA"]
[Thu Jul 30 15:02:12.132250 2026] [security2:error] [pid 87988:tid 88150] [client 78.47.42.23:45594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nordeste1.com"] [uri "/sitemap_index.xml"] [unique_id "amutxDipAwzptuCxBrhjIAAAASo"]
[Thu Jul 30 15:02:12.343771 2026] [security2:error] [pid 87988:tid 88208] [client 20.104.18.253:10746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lilyinspires.com"] [uri "/fai.php"] [unique_id "amutxDipAwzptuCxBrhjIgAAAWQ"]
[Thu Jul 30 15:02:12.358249 2026] [core:notice] [pid 89520:tid 89789] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:12.402565 2026] [security2:error] [pid 87988:tid 88145] [client 194.102.104.29:60084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.spadealist.com"] [uri "/___proxy_subdomain_cpanel/cpanel.spadealist.com/.env"] [unique_id "amutxDipAwzptuCxBrhjIwAAASU"]
[Thu Jul 30 15:02:12.459784 2026] [core:notice] [pid 87988:tid 88149] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:12.468925 2026] [security2:error] [pid 89520:tid 89672] [client 20.91.199.21:36762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/radio.php"] [unique_id "amutxC0W4wRrtnDoPaj9dAAAAZg"]
[Thu Jul 30 15:02:12.578610 2026] [security2:error] [pid 87988:tid 88234] [client 74.7.241.138:41062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.newwcoupons.net"] [uri "/robots.txt"] [unique_id "amutxDipAwzptuCxBrhjKwAAAX4"]
[Thu Jul 30 15:02:12.672451 2026] [core:notice] [pid 89520:tid 89769] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:13.051298 2026] [core:notice] [pid 89520:tid 89667] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:13.408628 2026] [security2:error] [pid 89520:tid 89712] [client 213.152.161.240:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amutxS0W4wRrtnDoPaj9hAAAAcA"]
[Thu Jul 30 15:02:13.408742 2026] [security2:error] [pid 89520:tid 89712] [client 213.152.161.240:49164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amutxS0W4wRrtnDoPaj9hAAAAcA"]
[Thu Jul 30 15:02:13.590470 2026] [security2:error] [pid 89520:tid 89786] [client 20.91.199.21:38581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/wpsml-sys.php"] [unique_id "amutxS0W4wRrtnDoPaj9hwAAAgo"]
[Thu Jul 30 15:02:14.134946 2026] [core:notice] [pid 89520:tid 89745] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:14.139190 2026] [security2:error] [pid 89520:tid 89745] [client 87.199.209.34:48970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/view/1714"] [unique_id "amutxS0W4wRrtnDoPaj9jwAAAeE"], referer: https://ejournalugj.com/index.php/tumed/article/view/1714
[Thu Jul 30 15:02:14.301300 2026] [security2:error] [pid 89520:tid 89687] [client 194.102.104.29:61150] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "cpanel.spadealist.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amutxi0W4wRrtnDoPaj9lQAAAac"]
[Thu Jul 30 15:02:14.349413 2026] [security2:error] [pid 89520:tid 89701] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amutxS0W4wRrtnDoPaj9jAAAAbU"]
[Thu Jul 30 15:02:14.378506 2026] [core:notice] [pid 87988:tid 88176] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:14.507797 2026] [security2:error] [pid 89520:tid 89684] [client 172.213.232.128:57506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/011i.php"] [unique_id "amutxi0W4wRrtnDoPaj9lgAAAaQ"]
[Thu Jul 30 15:02:14.627873 2026] [core:notice] [pid 87988:tid 88233] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:14.631360 2026] [core:notice] [pid 87988:tid 88231] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:14.638566 2026] [security2:error] [pid 87988:tid 87998] [remote 216.73.216.51:15228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amutxjipAwzptuCxBrhjSAABbAk"]
[Thu Jul 30 15:02:15.002624 2026] [core:notice] [pid 89520:tid 89733] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:15.176947 2026] [core:notice] [pid 89520:tid 89688] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:15.250271 2026] [security2:error] [pid 87988:tid 88210] [client 23.130.104.130:53004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.104.130.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amutxzipAwzptuCxBrhjUQAAAWY"]
[Thu Jul 30 15:02:15.250366 2026] [security2:error] [pid 87988:tid 88210] [client 23.130.104.130:53004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amutxzipAwzptuCxBrhjUQAAAWY"]
[Thu Jul 30 15:02:15.368542 2026] [core:notice] [pid 89520:tid 89713] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:15.371784 2026] [security2:error] [pid 89520:tid 89713] [client 87.199.209.34:49033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php"] [unique_id "amutxy0W4wRrtnDoPaj9ogAAAcE"], referer: https://ejournalugj.com/index.php
[Thu Jul 30 15:02:15.545011 2026] [security2:error] [pid 89520:tid 89683] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amutxi0W4wRrtnDoPaj9mQABox0"]
[Thu Jul 30 15:02:15.875447 2026] [core:notice] [pid 89520:tid 89732] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:15.879067 2026] [security2:error] [pid 89520:tid 89732] [client 87.199.209.34:49062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php"] [unique_id "amutxy0W4wRrtnDoPaj9qgAAAdQ"], referer: https://ejournalugj.com/index.php
[Thu Jul 30 15:02:16.364954 2026] [security2:error] [pid 89520:tid 89564] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutyC0W4wRrtnDoPaj9sgABqyI"]
[Thu Jul 30 15:02:16.365101 2026] [security2:error] [pid 89520:tid 89691] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amutyC0W4wRrtnDoPaj9sgABqyI"]
[Thu Jul 30 15:02:16.369570 2026] [core:notice] [pid 89520:tid 89770] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:16.373409 2026] [security2:error] [pid 89520:tid 89770] [client 87.199.209.34:49092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php"] [unique_id "amutyC0W4wRrtnDoPaj9swAAAfo"], referer: https://ejournalugj.com/index.php
[Thu Jul 30 15:02:16.566671 2026] [security2:error] [pid 89520:tid 89742] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amutyC0W4wRrtnDoPaj9rwAAAd4"], referer: https://smoke-tfhk.com/camel-original-recommend/
[Thu Jul 30 15:02:16.871960 2026] [core:notice] [pid 89520:tid 89722] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:16.875524 2026] [security2:error] [pid 89520:tid 89722] [client 87.199.209.34:49115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ejournalugj.com"] [uri "/index.php"] [unique_id "amutyC0W4wRrtnDoPaj9uQAAAco"], referer: https://ejournalugj.com/index.php
[Thu Jul 30 15:02:16.941900 2026] [security2:error] [pid 89520:tid 89668] [client 20.91.199.21:38532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/02.php"] [unique_id "amutyC0W4wRrtnDoPaj9uwAAAZQ"]
[Thu Jul 30 15:02:17.032512 2026] [core:notice] [pid 89520:tid 89751] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:17.036335 2026] [security2:error] [pid 89520:tid 89751] [client 182.10.130.87:31739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/3122"] [unique_id "amutyC0W4wRrtnDoPaj9uAAAAec"]
[Thu Jul 30 15:02:17.145114 2026] [core:notice] [pid 89520:tid 89748] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:17.147906 2026] [security2:error] [pid 89520:tid 89748] [client 66.249.74.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/52/54"] [unique_id "amutyC0W4wRrtnDoPaj9ugAAAeQ"]
[Thu Jul 30 15:02:17.211241 2026] [security2:error] [pid 89520:tid 89677] [client 172.213.232.128:57481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/03a005685d.php"] [unique_id "amutyS0W4wRrtnDoPaj9wAAAAZ0"]
[Thu Jul 30 15:02:17.293526 2026] [core:notice] [pid 89520:tid 89774] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:17.545238 2026] [security2:error] [pid 89520:tid 89693] [client 172.237.109.114:35699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amutyC0W4wRrtnDoPaj9vAAAAa0"]
[Thu Jul 30 15:02:17.547492 2026] [core:notice] [pid 89520:tid 89782] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:18.389302 2026] [core:notice] [pid 89520:tid 89701] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:18.472646 2026] [security2:error] [pid 89520:tid 89735] [client 172.213.232.128:49506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/403.php"] [unique_id "amutyi0W4wRrtnDoPaj91wAAAdc"]
[Thu Jul 30 15:02:19.367954 2026] [security2:error] [pid 89520:tid 89690] [client 172.213.232.128:57794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/404.php"] [unique_id "amutyy0W4wRrtnDoPaj93gAAAao"]
[Thu Jul 30 15:02:19.380473 2026] [core:notice] [pid 89520:tid 89713] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:19.686762 2026] [security2:error] [pid 89520:tid 89578] [remote 74.7.243.224:48408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/img/Policyf.php"] [unique_id "amutyy0W4wRrtnDoPaj94QABlTA"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:02:20.985268 2026] [security2:error] [pid 89520:tid 89682] [client 240.95.140.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amutzC0W4wRrtnDoPaj96QABoi4"], referer: https://flixon.net/?post_type=any&s=Bokep+viral&search=&search_filter=post_types&_wpnonce=ab8659ecbd
[Thu Jul 30 15:02:21.159967 2026] [security2:error] [pid 89520:tid 89784] [client 172.213.232.128:59103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/aa.php"] [unique_id "amutzS0W4wRrtnDoPaj99wAAAgg"]
[Thu Jul 30 15:02:22.050310 2026] [security2:error] [pid 89520:tid 89584] [remote 20.89.80.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skilledfurnituremoversuae.com"] [uri "/xmlrpc.php"] [unique_id "amutzS0W4wRrtnDoPaj-AQABoTY"]
[Thu Jul 30 15:02:22.050504 2026] [security2:error] [pid 89520:tid 89681] [client 20.89.80.94:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skilledfurnituremoversuae.com"] [uri "/xmlrpc.php"] [unique_id "amutzS0W4wRrtnDoPaj-AQABoTY"]
[Thu Jul 30 15:02:23.219232 2026] [security2:error] [pid 89520:tid 89669] [client 20.91.199.21:36782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/infos.php"] [unique_id "amutzy0W4wRrtnDoPaj-HgAAAZU"]
[Thu Jul 30 15:02:23.840133 2026] [security2:error] [pid 89520:tid 89703] [client 172.213.232.128:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/aafewc0k.php"] [unique_id "amutzy0W4wRrtnDoPaj-KAAAAbc"]
[Thu Jul 30 15:02:24.344223 2026] [core:notice] [pid 89520:tid 89727] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:24.356485 2026] [core:error] [pid 89520:tid 89727] [client 66.249.79.1:37813] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:02:24.356684 2026] [security2:error] [pid 89520:tid 89727] [client 66.249.79.1:37813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/6089/2678.html.html.html.html.html.html.html.html.html.html"] [unique_id "amut0C0W4wRrtnDoPaj-LQAAAc8"]
[Thu Jul 30 15:02:24.398385 2026] [security2:error] [pid 87988:tid 88201] [client 20.91.199.21:38476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/updates.php"] [unique_id "amut0DipAwzptuCxBrhjvwAAAV0"]
[Thu Jul 30 15:02:25.208706 2026] [security2:error] [pid 89520:tid 89766] [client 20.91.199.21:38522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/user.php"] [unique_id "amut0S0W4wRrtnDoPaj-OAAAAfY"]
[Thu Jul 30 15:02:25.507457 2026] [security2:error] [pid 87988:tid 88202] [client 172.237.109.114:50785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amut0TipAwzptuCxBrhjyQAAAV4"]
[Thu Jul 30 15:02:25.870312 2026] [core:notice] [pid 89520:tid 89672] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:25.990936 2026] [core:notice] [pid 89520:tid 89691] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:26.014453 2026] [security2:error] [pid 89520:tid 89759] [client 127.0.0.1:48784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amut0S0W4wRrtnDoPaj-TAAAAe8"]
[Thu Jul 30 15:02:26.014486 2026] [security2:error] [pid 89520:tid 89744] [client 74.7.175.135:60064] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.vpv.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amut0S0W4wRrtnDoPaj-SwAAAeA"]
[Thu Jul 30 15:02:26.062998 2026] [security2:error] [pid 89520:tid 89776] [client 20.91.199.21:44161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/admin-ajax.php"] [unique_id "amut0i0W4wRrtnDoPaj-TQAAAgA"]
[Thu Jul 30 15:02:26.941809 2026] [security2:error] [pid 89520:tid 89588] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut0i0W4wRrtnDoPaj-VgACBjo"]
[Thu Jul 30 15:02:26.942023 2026] [security2:error] [pid 89520:tid 89782] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut0i0W4wRrtnDoPaj-VgACBjo"]
[Thu Jul 30 15:02:27.551718 2026] [security2:error] [pid 89520:tid 89593] [remote 57.141.0.71:48228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amut0y0W4wRrtnDoPaj-XwAB6j8"]
[Thu Jul 30 15:02:28.013782 2026] [security2:error] [pid 89520:tid 89592] [remote 74.7.227.39:35310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amut1C0W4wRrtnDoPaj-ZQABwj4"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin/network
[Thu Jul 30 15:02:28.015388 2026] [security2:error] [pid 87988:tid 88129] [client 172.213.232.128:57064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/abcd.php"] [unique_id "amut1DipAwzptuCxBrhj7gAAARU"]
[Thu Jul 30 15:02:28.578083 2026] [security2:error] [pid 87988:tid 88133] [client 20.91.199.21:10284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/alfa.php"] [unique_id "amut1DipAwzptuCxBrhj9QAAARk"]
[Thu Jul 30 15:02:29.461170 2026] [core:notice] [pid 89520:tid 89672] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:29.464447 2026] [security2:error] [pid 89520:tid 89672] [client 66.249.65.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/110/107"] [unique_id "amut1S0W4wRrtnDoPaj-dwAAAZg"]
[Thu Jul 30 15:02:29.504061 2026] [security2:error] [pid 87988:tid 88218] [client 172.237.109.114:32567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amut1TipAwzptuCxBrhj_gAAAW4"]
[Thu Jul 30 15:02:29.714199 2026] [core:notice] [pid 89520:tid 89717] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:29.987968 2026] [core:notice] [pid 89520:tid 89728] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:31.026083 2026] [security2:error] [pid 89520:tid 89698] [client 172.213.232.128:49478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/about.php"] [unique_id "amut1y0W4wRrtnDoPaj-mQAAAbI"]
[Thu Jul 30 15:02:33.253684 2026] [security2:error] [pid 87988:tid 88218] [client 20.199.183.73:43222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/themes/admin.php"] [unique_id "amut2TipAwzptuCxBrhkSQAAAW4"]
[Thu Jul 30 15:02:33.307588 2026] [security2:error] [pid 89520:tid 89666] [client 20.91.199.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.azureskyfilms.com"] [uri "/index.php"] [unique_id "amut1y0W4wRrtnDoPaj-qgAAAZI"]
[Thu Jul 30 15:02:33.506718 2026] [security2:error] [pid 87988:tid 88199] [client 20.91.199.21:10258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/hehe.php"] [unique_id "amut2TipAwzptuCxBrhkWAAAAVs"]
[Thu Jul 30 15:02:33.673345 2026] [security2:error] [pid 89520:tid 89752] [client 172.213.232.128:48713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/admin.php"] [unique_id "amut2S0W4wRrtnDoPaj-xQAAAeg"]
[Thu Jul 30 15:02:35.118288 2026] [core:notice] [pid 89520:tid 89695] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:35.385554 2026] [core:notice] [pid 89520:tid 89746] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:36.056476 2026] [security2:error] [pid 89520:tid 89713] [client 172.213.232.128:49065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/adminfuns.php"] [unique_id "amut3C0W4wRrtnDoPaj-3QAAAcE"]
[Thu Jul 30 15:02:36.633401 2026] [security2:error] [pid 89520:tid 89776] [client 172.213.232.128:59131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/albin.php"] [unique_id "amut3C0W4wRrtnDoPaj-5AAAAgA"]
[Thu Jul 30 15:02:36.686740 2026] [security2:error] [pid 87988:tid 88172] [client 20.199.183.73:36135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/m.php"] [unique_id "amut3DipAwzptuCxBrhkgAAAAUA"]
[Thu Jul 30 15:02:37.039902 2026] [core:notice] [pid 87988:tid 88189] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:37.296823 2026] [security2:error] [pid 89520:tid 89783] [client 172.213.232.128:57029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/amfsqvgv.php"] [unique_id "amut3S0W4wRrtnDoPaj-6wAAAgc"]
[Thu Jul 30 15:02:37.483515 2026] [security2:error] [pid 89520:tid 89753] [client 172.237.109.114:46040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amut3S0W4wRrtnDoPaj-6gAAAek"]
[Thu Jul 30 15:02:37.488753 2026] [security2:error] [pid 89520:tid 89722] [client 20.91.199.21:43769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/rk2.php"] [unique_id "amut3S0W4wRrtnDoPaj-7gAAAco"]
[Thu Jul 30 15:02:37.547105 2026] [security2:error] [pid 89520:tid 89606] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut3S0W4wRrtnDoPaj-7wABlEw"]
[Thu Jul 30 15:02:37.547274 2026] [security2:error] [pid 89520:tid 89668] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut3S0W4wRrtnDoPaj-7wABlEw"]
[Thu Jul 30 15:02:37.906350 2026] [security2:error] [pid 89520:tid 89782] [client 172.213.232.128:59082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/ant.php"] [unique_id "amut3S0W4wRrtnDoPaj-9QAAAgY"]
[Thu Jul 30 15:02:38.059209 2026] [core:notice] [pid 89520:tid 89594] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:38.064481 2026] [security2:error] [pid 89520:tid 89715] [client 47.128.96.129:33628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/camic/search/search"] [unique_id "amut3S0W4wRrtnDoPaj-8gABw0A"]
[Thu Jul 30 15:02:38.233325 2026] [security2:error] [pid 87988:tid 88151] [client 20.199.183.73:13982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amut3TipAwzptuCxBrhklAAAASs"]
[Thu Jul 30 15:02:38.311314 2026] [core:notice] [pid 87988:tid 88024] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:38.424383 2026] [core:notice] [pid 87988:tid 88020] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:38.424406 2026] [core:notice] [pid 87988:tid 88010] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:38.833090 2026] [security2:error] [pid 89520:tid 89747] [client 20.91.199.21:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/setup-config.php"] [unique_id "amut3i0W4wRrtnDoPaj--wAAAeM"]
[Thu Jul 30 15:02:39.192458 2026] [security2:error] [pid 87988:tid 88169] [client 172.213.232.128:48754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/appreciators.php"] [unique_id "amut3zipAwzptuCxBrhkqAAAAT0"]
[Thu Jul 30 15:02:39.399492 2026] [security2:error] [pid 89520:tid 89719] [client 4.184.60.71:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.60.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.appliancerepairservice.one"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amut3y0W4wRrtnDoPaj-_wAAAcc"]
[Thu Jul 30 15:02:39.399662 2026] [security2:error] [pid 89520:tid 89719] [client 4.184.60.71:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.appliancerepairservice.one"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amut3y0W4wRrtnDoPaj-_wAAAcc"]
[Thu Jul 30 15:02:39.790459 2026] [core:notice] [pid 89520:tid 89758] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:39.844165 2026] [security2:error] [pid 89520:tid 89788] [client 20.199.183.73:33025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wk/index.php"] [unique_id "amut3y0W4wRrtnDoPaj_CAAAAgw"]
[Thu Jul 30 15:02:40.136587 2026] [security2:error] [pid 87988:tid 88213] [client 172.213.232.128:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/archive.php"] [unique_id "amut4DipAwzptuCxBrhkuQAAAWk"]
[Thu Jul 30 15:02:40.416328 2026] [security2:error] [pid 87988:tid 88181] [client 20.199.183.73:43307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/mini.php"] [unique_id "amut4DipAwzptuCxBrhkugAAAUk"]
[Thu Jul 30 15:02:40.526585 2026] [security2:error] [pid 87988:tid 88127] [client 20.91.199.21:36681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/a7.php"] [unique_id "amut4DipAwzptuCxBrhkvwAAARM"]
[Thu Jul 30 15:02:40.735420 2026] [security2:error] [pid 87988:tid 88221] [client 172.213.232.128:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/as.php"] [unique_id "amut4DipAwzptuCxBrhkwgAAAXE"]
[Thu Jul 30 15:02:41.052391 2026] [security2:error] [pid 87988:tid 88216] [client 20.199.183.73:48321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/aa.php"] [unique_id "amut4TipAwzptuCxBrhkxwAAAWw"]
[Thu Jul 30 15:02:41.652436 2026] [security2:error] [pid 89520:tid 89695] [client 172.213.232.128:49475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/atomlib.php"] [unique_id "amut4S0W4wRrtnDoPaj_FgAAAa8"]
[Thu Jul 30 15:02:41.979226 2026] [security2:error] [pid 89520:tid 89750] [client 20.199.183.73:41235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/w.php"] [unique_id "amut4S0W4wRrtnDoPaj_FwAAAeY"]
[Thu Jul 30 15:02:42.354170 2026] [security2:error] [pid 87988:tid 88148] [client 20.91.199.21:38494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/f7.php"] [unique_id "amut4jipAwzptuCxBrhk1gAAASg"]
[Thu Jul 30 15:02:42.899632 2026] [security2:error] [pid 87988:tid 88124] [client 172.213.232.128:59092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/autoload_classmap.php"] [unique_id "amut4jipAwzptuCxBrhk3gAAARA"]
[Thu Jul 30 15:02:43.137681 2026] [security2:error] [pid 89520:tid 89671] [client 20.91.199.21:10243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/nw.php"] [unique_id "amut4y0W4wRrtnDoPaj_IgAAAZc"]
[Thu Jul 30 15:02:43.302175 2026] [security2:error] [pid 87988:tid 88184] [client 20.199.183.73:48352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/admin.php"] [unique_id "amut4zipAwzptuCxBrhk5wAAAUw"]
[Thu Jul 30 15:02:44.294406 2026] [security2:error] [pid 89520:tid 89734] [client 172.213.232.128:57063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/bb.php"] [unique_id "amut5C0W4wRrtnDoPaj_LQAAAdY"]
[Thu Jul 30 15:02:44.364522 2026] [security2:error] [pid 87988:tid 88234] [client 20.199.183.73:48595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/404.php"] [unique_id "amut5DipAwzptuCxBrhk9wAAAX4"]
[Thu Jul 30 15:02:44.844492 2026] [security2:error] [pid 89520:tid 89783] [client 20.91.199.21:36693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/ova.php"] [unique_id "amut5C0W4wRrtnDoPaj_NQAAAgc"]
[Thu Jul 30 15:02:44.866664 2026] [security2:error] [pid 87988:tid 88187] [client 45.91.22.105:50373] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "jnn.djb.temporary.site"] [uri "/"] [unique_id "amut5DipAwzptuCxBrhk-gAAAU8"]
[Thu Jul 30 15:02:44.876288 2026] [proxy:error] [pid 89520:tid 89616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:02:44.876337 2026] [proxy_http:error] [pid 89520:tid 89616] [remote 74.7.175.136:49950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:02:44.876903 2026] [proxy:error] [pid 89520:tid 89616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:02:44.876945 2026] [proxy_http:error] [pid 89520:tid 89616] [remote 74.7.175.136:49950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:02:44.960318 2026] [security2:error] [pid 89520:tid 89756] [client 45.91.22.107:61807] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.jnn.djb.temporary.site"] [uri "/"] [unique_id "amut5C0W4wRrtnDoPaj_OAAAAew"]
[Thu Jul 30 15:02:44.966012 2026] [proxy:error] [pid 89520:tid 89689] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:02:44.966062 2026] [proxy_http:error] [pid 89520:tid 89689] [client 45.91.22.79:20621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:02:44.966743 2026] [proxy:error] [pid 89520:tid 89689] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:02:44.966787 2026] [proxy_http:error] [pid 89520:tid 89689] [client 45.91.22.79:20621] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:02:44.996500 2026] [security2:error] [pid 89520:tid 89728] [client 45.91.22.90:62641] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "autodiscover.jnn.djb.temporary.site"] [uri "/"] [unique_id "amut5C0W4wRrtnDoPaj_OgAAAdA"]
[Thu Jul 30 15:02:45.019284 2026] [proxy:error] [pid 89520:tid 89684] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:02:45.019362 2026] [proxy_http:error] [pid 89520:tid 89684] [client 45.91.22.79:60081] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:02:45.020023 2026] [proxy:error] [pid 89520:tid 89684] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:02:45.020072 2026] [proxy_http:error] [pid 89520:tid 89684] [client 45.91.22.79:60081] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:02:45.026068 2026] [core:error] [pid 87988:tid 88186] [client 23.94.133.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:02:45.026090 2026] [core:error] [pid 87988:tid 88186] [client 23.94.133.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:02:45.374416 2026] [security2:error] [pid 89520:tid 89749] [client 20.199.183.73:24878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/init.php"] [unique_id "amut5S0W4wRrtnDoPaj_RwAAAeU"]
[Thu Jul 30 15:02:45.555919 2026] [core:notice] [pid 89520:tid 89763] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:45.636961 2026] [security2:error] [pid 89520:tid 89787] [client 20.91.199.21:36699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/robots.php"] [unique_id "amut5S0W4wRrtnDoPaj_SQAAAgs"]
[Thu Jul 30 15:02:45.882220 2026] [core:notice] [pid 89520:tid 89766] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:45.891603 2026] [security2:error] [pid 87988:tid 88181] [client 172.213.232.128:57084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/bnm.php"] [unique_id "amut5TipAwzptuCxBrhlDgAAAUk"]
[Thu Jul 30 15:02:46.201450 2026] [security2:error] [pid 89520:tid 89771] [client 20.203.148.31:43179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/geju.php"] [unique_id "amut5i0W4wRrtnDoPaj_UAAAAfs"]
[Thu Jul 30 15:02:46.404972 2026] [security2:error] [pid 89520:tid 89778] [client 20.199.183.73:48360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/adminfuns.php"] [unique_id "amut5i0W4wRrtnDoPaj_VAAAAgI"]
[Thu Jul 30 15:02:46.488741 2026] [security2:error] [pid 89520:tid 89789] [client 172.213.232.128:49613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/bootstrap.php"] [unique_id "amut5i0W4wRrtnDoPaj_VwAAAg0"]
[Thu Jul 30 15:02:46.574689 2026] [security2:error] [pid 89520:tid 89711] [client 20.91.199.21:38501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/alf.php"] [unique_id "amut5i0W4wRrtnDoPaj_WAAAAb8"]
[Thu Jul 30 15:02:46.955948 2026] [security2:error] [pid 89520:tid 89713] [client 20.203.148.31:4577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amut5i0W4wRrtnDoPaj_WwAAAcE"]
[Thu Jul 30 15:02:47.244893 2026] [security2:error] [pid 89520:tid 89669] [client 172.213.232.128:57087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/buy.php"] [unique_id "amut5y0W4wRrtnDoPaj_XgAAAZU"]
[Thu Jul 30 15:02:47.879673 2026] [security2:error] [pid 87988:tid 88161] [client 20.199.183.73:14147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/file.php"] [unique_id "amut5zipAwzptuCxBrhlJQAAATU"]
[Thu Jul 30 15:02:48.075263 2026] [security2:error] [pid 89520:tid 89625] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut6C0W4wRrtnDoPaj_ZQABq14"]
[Thu Jul 30 15:02:48.075388 2026] [security2:error] [pid 89520:tid 89691] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut6C0W4wRrtnDoPaj_ZQABq14"]
[Thu Jul 30 15:02:48.599574 2026] [security2:error] [pid 89520:tid 89741] [client 20.203.148.31:4553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp.php"] [unique_id "amut6C0W4wRrtnDoPaj_bAAAAd0"]
[Thu Jul 30 15:02:48.603169 2026] [security2:error] [pid 89520:tid 89790] [client 20.91.199.21:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/feedback.php"] [unique_id "amut6C0W4wRrtnDoPaj_bQAAAg4"]
[Thu Jul 30 15:02:49.285142 2026] [security2:error] [pid 87988:tid 88118] [client 172.213.232.128:57058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/chosen.php"] [unique_id "amut6TipAwzptuCxBrhlOQAAAQo"]
[Thu Jul 30 15:02:49.354097 2026] [core:notice] [pid 87988:tid 88191] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:49.621693 2026] [security2:error] [pid 87988:tid 88195] [client 43.153.73.200:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.73.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/notice"] [unique_id "amut6TipAwzptuCxBrhlQQAAAVc"]
[Thu Jul 30 15:02:49.692202 2026] [security2:error] [pid 87988:tid 88199] [client 20.203.148.31:8733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/aaa.php"] [unique_id "amut6TipAwzptuCxBrhlQwAAAVs"]
[Thu Jul 30 15:02:50.206199 2026] [security2:error] [pid 89520:tid 89620] [remote 57.141.0.24:20424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amut6i0W4wRrtnDoPaj_egAB0Fo"]
[Thu Jul 30 15:02:50.394435 2026] [security2:error] [pid 87988:tid 88138] [client 20.203.148.31:4568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/hoot.php"] [unique_id "amut6jipAwzptuCxBrhlTgAAAR4"]
[Thu Jul 30 15:02:50.670014 2026] [security2:error] [pid 89520:tid 89664] [client 173.249.217.23:40444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.217.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amut6i0W4wRrtnDoPaj_fgAAAZA"]
[Thu Jul 30 15:02:50.670129 2026] [security2:error] [pid 89520:tid 89664] [client 173.249.217.23:40444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amut6i0W4wRrtnDoPaj_fgAAAZA"]
[Thu Jul 30 15:02:50.937497 2026] [security2:error] [pid 87988:tid 88181] [client 49.47.133.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amut6jipAwzptuCxBrhlWAAAAUk"], referer: https://cnpinyin.com
[Thu Jul 30 15:02:51.069004 2026] [security2:error] [pid 87988:tid 88111] [remote 157.66.47.83:59846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.47.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amut6zipAwzptuCxBrhlWwABaXo"]
[Thu Jul 30 15:02:51.302568 2026] [security2:error] [pid 87988:tid 88147] [client 20.203.148.31:4579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/about.php"] [unique_id "amut6zipAwzptuCxBrhlYAAAASc"]
[Thu Jul 30 15:02:51.602364 2026] [security2:error] [pid 87988:tid 88149] [client 20.199.183.73:43261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/222.php"] [unique_id "amut6zipAwzptuCxBrhlaAAAASk"]
[Thu Jul 30 15:02:51.817269 2026] [security2:error] [pid 87988:tid 88188] [client 172.237.109.114:38652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amut6zipAwzptuCxBrhlXwAAAVA"]
[Thu Jul 30 15:02:52.097909 2026] [security2:error] [pid 89520:tid 89769] [client 20.91.199.21:38326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/gettest.php"] [unique_id "amut7C0W4wRrtnDoPaj_jwAAAfk"]
[Thu Jul 30 15:02:52.149669 2026] [security2:error] [pid 89520:tid 89714] [client 20.203.148.31:1303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/admin.php"] [unique_id "amut7C0W4wRrtnDoPaj_kgAAAcI"]
[Thu Jul 30 15:02:54.204934 2026] [security2:error] [pid 89520:tid 89733] [client 20.91.199.21:44105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/maint.php"] [unique_id "amut7i0W4wRrtnDoPaj_pgAAAdU"]
[Thu Jul 30 15:02:54.315548 2026] [security2:error] [pid 89520:tid 89744] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amut7S0W4wRrtnDoPaj_oQAB4Gg"]
[Thu Jul 30 15:02:54.671692 2026] [security2:error] [pid 87988:tid 88163] [client 172.213.232.128:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/class-wp-image.php"] [unique_id "amut7jipAwzptuCxBrhliwAAATc"]
[Thu Jul 30 15:02:55.080729 2026] [security2:error] [pid 89520:tid 89706] [client 20.91.199.21:36731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/files.php"] [unique_id "amut7y0W4wRrtnDoPaj_sQAAAbo"]
[Thu Jul 30 15:02:55.205483 2026] [core:notice] [pid 89520:tid 89747] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:55.656485 2026] [core:notice] [pid 89520:tid 89721] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:02:56.017303 2026] [security2:error] [pid 89520:tid 89684] [client 20.203.148.31:4578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amut8C0W4wRrtnDoPaj_vAAAAaQ"]
[Thu Jul 30 15:02:56.119427 2026] [security2:error] [pid 89520:tid 89767] [client 20.91.199.21:44097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/gecko.php"] [unique_id "amut8C0W4wRrtnDoPaj_vQAAAfc"]
[Thu Jul 30 15:02:56.581794 2026] [security2:error] [pid 89520:tid 89675] [client 172.213.232.128:48740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/classsmtps.php"] [unique_id "amut8C0W4wRrtnDoPaj_wgAAAZs"]
[Thu Jul 30 15:02:57.193537 2026] [security2:error] [pid 87988:tid 88172] [client 20.203.148.31:4957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/db-cache.php"] [unique_id "amut8TipAwzptuCxBrhlrQAAAUA"]
[Thu Jul 30 15:02:57.448752 2026] [security2:error] [pid 89520:tid 89665] [client 20.91.199.21:38335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/zwso.php"] [unique_id "amut8S0W4wRrtnDoPaj_yQAAAZE"]
[Thu Jul 30 15:02:58.468654 2026] [security2:error] [pid 89520:tid 89751] [client 172.213.232.128:49047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/classwithtostring.php"] [unique_id "amut8i0W4wRrtnDoPaj_0gAAAec"]
[Thu Jul 30 15:02:58.641565 2026] [security2:error] [pid 87988:tid 88020] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut8jipAwzptuCxBrhlvgABbR8"]
[Thu Jul 30 15:02:58.641703 2026] [security2:error] [pid 87988:tid 88217] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut8jipAwzptuCxBrhlvgABbR8"]
[Thu Jul 30 15:02:58.890916 2026] [security2:error] [pid 87988:tid 88145] [client 74.7.241.189:33208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.apw.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amut8jipAwzptuCxBrhlwQABJWM"]
[Thu Jul 30 15:02:59.043678 2026] [security2:error] [pid 87988:tid 88028] [remote 57.141.0.38:48538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amut8zipAwzptuCxBrhlwwABPic"]
[Thu Jul 30 15:02:59.430770 2026] [security2:error] [pid 89520:tid 89764] [client 20.203.148.31:8842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amut8y0W4wRrtnDoPaj_2QAAAfQ"]
[Thu Jul 30 15:02:59.553153 2026] [security2:error] [pid 89520:tid 89685] [client 20.91.199.21:38640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/13.php"] [unique_id "amut8y0W4wRrtnDoPaj_3QAAAaU"]
[Thu Jul 30 15:02:59.691588 2026] [security2:error] [pid 89520:tid 89655] [remote 57.141.0.58:22682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amut8y0W4wRrtnDoPaj_4QAB_3k"]
[Thu Jul 30 15:03:00.026878 2026] [security2:error] [pid 89520:tid 89784] [client 20.199.183.73:14157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amut9C0W4wRrtnDoPaj_4gAAAgg"]
[Thu Jul 30 15:03:00.139167 2026] [security2:error] [pid 89520:tid 89679] [client 20.203.148.31:55716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amut9C0W4wRrtnDoPaj_5AAAAZ8"]
[Thu Jul 30 15:03:00.711384 2026] [security2:error] [pid 89520:tid 89725] [client 20.91.199.21:38506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/ava.php"] [unique_id "amut9C0W4wRrtnDoPaj_5wAAAc0"]
[Thu Jul 30 15:03:00.822244 2026] [security2:error] [pid 89520:tid 89735] [client 20.203.148.31:43139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amut9C0W4wRrtnDoPaj_6QAAAdc"]
[Thu Jul 30 15:03:01.066048 2026] [security2:error] [pid 89520:tid 89728] [client 173.249.217.23:37788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.217.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amut9S0W4wRrtnDoPaj_7QAAAdA"]
[Thu Jul 30 15:03:01.066173 2026] [security2:error] [pid 89520:tid 89728] [client 173.249.217.23:37788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amut9S0W4wRrtnDoPaj_7QAAAdA"]
[Thu Jul 30 15:03:01.379932 2026] [security2:error] [pid 87988:tid 88209] [client 20.199.183.73:47841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/admin.php"] [unique_id "amut9TipAwzptuCxBrhl5QAAAWU"]
[Thu Jul 30 15:03:02.400358 2026] [security2:error] [pid 89520:tid 89683] [client 20.199.183.73:37968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-configs.php"] [unique_id "amut9i0W4wRrtnDoPaj_-AAAAaM"]
[Thu Jul 30 15:03:02.628148 2026] [security2:error] [pid 89520:tid 89787] [client 172.213.232.128:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/config.php"] [unique_id "amut9i0W4wRrtnDoPaj_-gAAAgs"]
[Thu Jul 30 15:03:02.675718 2026] [security2:error] [pid 89520:tid 89736] [client 172.237.109.114:9024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amut9i0W4wRrtnDoPaj_9QAAAdg"]
[Thu Jul 30 15:03:03.573722 2026] [security2:error] [pid 87988:tid 88081] [remote 57.141.0.17:26422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amut9zipAwzptuCxBrhmAwABGlw"]
[Thu Jul 30 15:03:03.607031 2026] [security2:error] [pid 87988:tid 88148] [client 20.91.199.21:36716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/main.php"] [unique_id "amut9zipAwzptuCxBrhmBAAAASg"]
[Thu Jul 30 15:03:03.625136 2026] [security2:error] [pid 89520:tid 89758] [client 20.203.148.31:4929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amut9y0W4wRrtnDoPagABgAAAe4"]
[Thu Jul 30 15:03:03.769580 2026] [security2:error] [pid 89520:tid 89789] [client 172.213.232.128:56518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/core.php"] [unique_id "amut9y0W4wRrtnDoPagACAAAAg0"]
[Thu Jul 30 15:03:03.781297 2026] [security2:error] [pid 89520:tid 89778] [client 20.199.183.73:16406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/php.php"] [unique_id "amut9y0W4wRrtnDoPagACgAAAgI"]
[Thu Jul 30 15:03:04.542202 2026] [security2:error] [pid 89520:tid 89682] [client 20.199.183.73:37741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/index.php"] [unique_id "amut-C0W4wRrtnDoPagAFAAAAaI"]
[Thu Jul 30 15:03:04.603447 2026] [security2:error] [pid 89520:tid 89539] [remote 111.229.10.83:43266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.229.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-login.php"] [unique_id "amut-C0W4wRrtnDoPagAEQABwAk"]
[Thu Jul 30 15:03:04.694727 2026] [security2:error] [pid 89520:tid 89774] [client 172.213.232.128:48758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/css.php"] [unique_id "amut-C0W4wRrtnDoPagAGQAAAf4"]
[Thu Jul 30 15:03:04.790617 2026] [security2:error] [pid 87988:tid 88145] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amut-DipAwzptuCxBrhmCgAAASU"]
[Thu Jul 30 15:03:05.302510 2026] [security2:error] [pid 87988:tid 88197] [client 20.199.183.73:24330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/a.php"] [unique_id "amut-TipAwzptuCxBrhmHAAAAVk"]
[Thu Jul 30 15:03:05.375383 2026] [security2:error] [pid 87988:tid 88186] [client 74.7.175.136:42808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.dqy.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amut-TipAwzptuCxBrhmHwAAAU4"]
[Thu Jul 30 15:03:05.604274 2026] [core:notice] [pid 87988:tid 88158] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:05.842444 2026] [security2:error] [pid 87988:tid 88241] [client 20.203.148.31:4948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amut-TipAwzptuCxBrhmJQAAAYU"]
[Thu Jul 30 15:03:05.922911 2026] [core:notice] [pid 89520:tid 89563] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:05.965601 2026] [security2:error] [pid 87988:tid 88236] [client 127.0.0.1:51584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amut-TipAwzptuCxBrhmKwAAAYA"]
[Thu Jul 30 15:03:05.965693 2026] [security2:error] [pid 87988:tid 88168] [client 74.7.244.43:46078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.dlm.rty.temporary.site"] [uri "/robots.txt"] [unique_id "amut-TipAwzptuCxBrhmKgABPG8"]
[Thu Jul 30 15:03:06.564854 2026] [core:notice] [pid 89520:tid 89707] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:06.667321 2026] [security2:error] [pid 89520:tid 89675] [client 20.203.148.31:4389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/content.php"] [unique_id "amut-i0W4wRrtnDoPagANQAAAZs"]
[Thu Jul 30 15:03:07.505756 2026] [security2:error] [pid 89520:tid 89780] [client 172.213.232.128:56520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/database.php"] [unique_id "amut-y0W4wRrtnDoPagAQwAAAgQ"]
[Thu Jul 30 15:03:07.855652 2026] [security2:error] [pid 87988:tid 88141] [client 20.199.183.73:47809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/Text/about.php"] [unique_id "amut-zipAwzptuCxBrhmRQAAASE"]
[Thu Jul 30 15:03:08.670315 2026] [security2:error] [pid 87988:tid 88161] [client 172.213.232.128:49142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/db.php"] [unique_id "amut_DipAwzptuCxBrhmWgAAATU"]
[Thu Jul 30 15:03:08.831709 2026] [security2:error] [pid 87988:tid 88204] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amut_DipAwzptuCxBrhmTgABYGU"]
[Thu Jul 30 15:03:08.914286 2026] [security2:error] [pid 87988:tid 88215] [client 20.91.199.21:10771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/wp-file.php"] [unique_id "amut_DipAwzptuCxBrhmWwAAAWs"]
[Thu Jul 30 15:03:09.216540 2026] [security2:error] [pid 89520:tid 89743] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amut_C0W4wRrtnDoPagATAAAAd8"]
[Thu Jul 30 15:03:09.239395 2026] [security2:error] [pid 89520:tid 89656] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut_S0W4wRrtnDoPagAUAABlXo"]
[Thu Jul 30 15:03:09.239533 2026] [security2:error] [pid 89520:tid 89669] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amut_S0W4wRrtnDoPagAUAABlXo"]
[Thu Jul 30 15:03:09.704440 2026] [security2:error] [pid 87988:tid 88207] [client 20.199.183.73:42763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin.php"] [unique_id "amut_TipAwzptuCxBrhmawAAAWM"]
[Thu Jul 30 15:03:09.888058 2026] [security2:error] [pid 87988:tid 88245] [client 172.213.232.128:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/default.php"] [unique_id "amut_TipAwzptuCxBrhmbQAAAYk"]
[Thu Jul 30 15:03:10.215593 2026] [security2:error] [pid 89520:tid 89758] [client 20.203.148.31:1324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amut_i0W4wRrtnDoPagAWgAAAe4"]
[Thu Jul 30 15:03:10.402326 2026] [security2:error] [pid 87988:tid 88221] [client 20.199.183.73:24870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/size.php"] [unique_id "amut_jipAwzptuCxBrhmdAAAAXE"]
[Thu Jul 30 15:03:10.511789 2026] [security2:error] [pid 89520:tid 89680] [client 20.91.199.21:43966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/wp-signin.php"] [unique_id "amut_i0W4wRrtnDoPagAXgAAAaA"]
[Thu Jul 30 15:03:10.587015 2026] [security2:error] [pid 87988:tid 88216] [client 172.213.232.128:48717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/dropdown.php"] [unique_id "amut_jipAwzptuCxBrhmdwAAAWw"]
[Thu Jul 30 15:03:11.276435 2026] [security2:error] [pid 89520:tid 89763] [client 172.213.232.128:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/edit.php"] [unique_id "amut_y0W4wRrtnDoPagAaQAAAfM"]
[Thu Jul 30 15:03:11.361122 2026] [core:notice] [pid 89520:tid 89736] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:11.666955 2026] [core:notice] [pid 89520:tid 89732] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:11.696026 2026] [security2:error] [pid 89520:tid 89684] [client 172.237.109.114:58581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amut_y0W4wRrtnDoPagAaAAAAaQ"]
[Thu Jul 30 15:03:11.864527 2026] [core:notice] [pid 87988:tid 88014] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:12.128629 2026] [security2:error] [pid 89520:tid 89737] [client 20.203.148.31:7450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuuAC0W4wRrtnDoPagAcwAAAdk"]
[Thu Jul 30 15:03:12.607496 2026] [security2:error] [pid 89520:tid 89537] [remote 57.141.0.68:53030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuuAC0W4wRrtnDoPagAeAACAgc"]
[Thu Jul 30 15:03:13.070913 2026] [security2:error] [pid 89520:tid 89672] [client 20.203.148.31:43223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amuuAS0W4wRrtnDoPagAgAAAAZg"]
[Thu Jul 30 15:03:13.375962 2026] [security2:error] [pid 89520:tid 89690] [client 172.213.232.128:58581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/f35.php"] [unique_id "amuuAS0W4wRrtnDoPagAhQAAAao"]
[Thu Jul 30 15:03:13.939396 2026] [security2:error] [pid 89520:tid 89725] [client 68.67.112.221:46373] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuuAS0W4wRrtnDoPagAjAAAAc0"]
[Thu Jul 30 15:03:14.351204 2026] [security2:error] [pid 89520:tid 89754] [client 20.203.148.31:7462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amuuAi0W4wRrtnDoPagAjwAAAeo"]
[Thu Jul 30 15:03:14.482718 2026] [security2:error] [pid 89520:tid 89706] [client 18.192.166.72:3830] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuuAi0W4wRrtnDoPagAlAAAAbo"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:03:14.851137 2026] [core:notice] [pid 89520:tid 89676] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:14.855378 2026] [security2:error] [pid 89520:tid 89676] [client 18.192.166.72:3840] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuuAi0W4wRrtnDoPagAmgAAAZw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:03:14.887906 2026] [security2:error] [pid 89520:tid 89663] [client 20.91.199.21:33721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/simi.php"] [unique_id "amuuAi0W4wRrtnDoPagAmwAAAY8"]
[Thu Jul 30 15:03:15.238900 2026] [security2:error] [pid 87988:tid 88235] [client 18.192.166.72:3854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuuAzipAwzptuCxBrhmoQAAAX8"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:03:15.675843 2026] [security2:error] [pid 89520:tid 89736] [client 20.91.199.21:10783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/wp-conf.php"] [unique_id "amuuAy0W4wRrtnDoPagAqgAAAdg"]
[Thu Jul 30 15:03:15.903610 2026] [security2:error] [pid 89520:tid 89756] [client 172.213.232.128:49697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/f7.php"] [unique_id "amuuAy0W4wRrtnDoPagArQAAAew"]
[Thu Jul 30 15:03:16.015875 2026] [security2:error] [pid 89520:tid 89737] [client 20.203.148.31:55737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amuuBC0W4wRrtnDoPagAsAAAAdk"]
[Thu Jul 30 15:03:16.385198 2026] [security2:error] [pid 89520:tid 89671] [client 78.190.221.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuuBC0W4wRrtnDoPagAtwAAAZc"], referer: https://cnpinyin.com
[Thu Jul 30 15:03:17.069600 2026] [security2:error] [pid 89520:tid 89685] [client 20.91.199.21:35619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/WZGHHra0r3.php"] [unique_id "amuuBS0W4wRrtnDoPagAwwAAAaU"]
[Thu Jul 30 15:03:18.021540 2026] [security2:error] [pid 87988:tid 88036] [remote 74.7.243.224:40098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuuBjipAwzptuCxBrhmuwABgC8"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:03:18.367036 2026] [security2:error] [pid 87988:tid 88200] [client 20.199.183.73:16397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/wp-class.php"] [unique_id "amuuBjipAwzptuCxBrhmwAAAAVw"]
[Thu Jul 30 15:03:19.055646 2026] [security2:error] [pid 87988:tid 88156] [client 20.91.199.21:43952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/bala.php"] [unique_id "amuuBzipAwzptuCxBrhmywAAATA"]
[Thu Jul 30 15:03:19.913802 2026] [security2:error] [pid 89520:tid 89576] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuBy0W4wRrtnDoPagA3gABsi4"]
[Thu Jul 30 15:03:19.913948 2026] [security2:error] [pid 89520:tid 89698] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuBy0W4wRrtnDoPagA3gABsi4"]
[Thu Jul 30 15:03:20.117969 2026] [security2:error] [pid 89520:tid 89683] [client 20.203.148.31:7216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amuuCC0W4wRrtnDoPagA4gAAAaM"]
[Thu Jul 30 15:03:20.869775 2026] [security2:error] [pid 89520:tid 89693] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuCC0W4wRrtnDoPagA5gABrTE"]
[Thu Jul 30 15:03:20.988540 2026] [security2:error] [pid 89520:tid 89789] [client 20.203.148.31:2396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amuuCC0W4wRrtnDoPagA7wAAAg0"]
[Thu Jul 30 15:03:21.089724 2026] [security2:error] [pid 89520:tid 89755] [client 20.199.183.73:13799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/403.php"] [unique_id "amuuCS0W4wRrtnDoPagA8QAAAes"]
[Thu Jul 30 15:03:22.039086 2026] [security2:error] [pid 89520:tid 89709] [client 20.203.148.31:32708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amuuCi0W4wRrtnDoPagA_QAAAb0"]
[Thu Jul 30 15:03:22.728266 2026] [security2:error] [pid 89520:tid 89712] [client 20.203.148.31:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amuuCi0W4wRrtnDoPagBBQAAAcA"]
[Thu Jul 30 15:03:22.829449 2026] [security2:error] [pid 89520:tid 89788] [client 20.91.199.21:55054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/bk.php"] [unique_id "amuuCi0W4wRrtnDoPagBCwAAAgw"]
[Thu Jul 30 15:03:22.949851 2026] [security2:error] [pid 87988:tid 88242] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuCjipAwzptuCxBrhnBgABhjA"]
[Thu Jul 30 15:03:23.573185 2026] [security2:error] [pid 89520:tid 89740] [client 74.7.175.191:41438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ampersandenergy.us.cc"] [uri "/robots.txt"] [unique_id "amuuCy0W4wRrtnDoPagBGQAAAdw"]
[Thu Jul 30 15:03:23.662579 2026] [security2:error] [pid 89520:tid 89767] [client 20.203.148.31:7209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuuCy0W4wRrtnDoPagBGgAAAfc"]
[Thu Jul 30 15:03:24.282826 2026] [security2:error] [pid 87988:tid 88216] [client 20.203.148.31:4570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/banners/about.php"] [unique_id "amuuDDipAwzptuCxBrhnIQAAAWw"]
[Thu Jul 30 15:03:24.356378 2026] [security2:error] [pid 87988:tid 88157] [client 20.199.183.73:43760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuuDDipAwzptuCxBrhnIwAAATE"]
[Thu Jul 30 15:03:25.096223 2026] [security2:error] [pid 89520:tid 89737] [client 99.252.106.221:46510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuuDS0W4wRrtnDoPagBLQAB2Uc"], referer: https://www.northyorksheridanmall.com/
[Thu Jul 30 15:03:25.122035 2026] [security2:error] [pid 89520:tid 89738] [client 20.203.148.31:4930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/about.php"] [unique_id "amuuDS0W4wRrtnDoPagBLgAAAdo"]
[Thu Jul 30 15:03:25.306785 2026] [security2:error] [pid 87988:tid 88239] [client 20.91.199.21:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.azureskyfilms.com"] [uri "/ahax.php"] [unique_id "amuuDTipAwzptuCxBrhnNgAAAYM"]
[Thu Jul 30 15:03:25.713541 2026] [security2:error] [pid 89520:tid 89705] [client 20.203.148.31:4605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/about.php"] [unique_id "amuuDS0W4wRrtnDoPagBNwAAAbk"]
[Thu Jul 30 15:03:26.219498 2026] [security2:error] [pid 89520:tid 89779] [client 20.199.183.73:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/as.php"] [unique_id "amuuDi0W4wRrtnDoPagBPwAAAgM"]
[Thu Jul 30 15:03:26.694330 2026] [core:notice] [pid 89520:tid 89761] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:26.782656 2026] [security2:error] [pid 89520:tid 89668] [client 20.203.148.31:32712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuuDi0W4wRrtnDoPagBSgAAAZQ"]
[Thu Jul 30 15:03:27.300644 2026] [security2:error] [pid 87988:tid 88151] [client 20.199.183.73:33076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/includes/index.php"] [unique_id "amuuDzipAwzptuCxBrhnaQAAASs"]
[Thu Jul 30 15:03:27.352485 2026] [security2:error] [pid 89520:tid 89710] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuDi0W4wRrtnDoPagBSQAAAb4"]
[Thu Jul 30 15:03:28.515110 2026] [security2:error] [pid 89520:tid 89771] [client 20.199.183.73:47702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuuEC0W4wRrtnDoPagBZAAAAfs"]
[Thu Jul 30 15:03:28.974024 2026] [security2:error] [pid 89520:tid 89602] [remote 74.7.227.39:41324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amuuEC0W4wRrtnDoPagBaQAB-kg"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin/network
[Thu Jul 30 15:03:29.451407 2026] [security2:error] [pid 89520:tid 89613] [remote 88.230.134.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.134.230.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alpha518.com"] [uri "/xmlrpc.php"] [unique_id "amuuES0W4wRrtnDoPagBcgABwlM"]
[Thu Jul 30 15:03:29.451598 2026] [security2:error] [pid 89520:tid 89714] [client 88.230.134.165:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alpha518.com"] [uri "/xmlrpc.php"] [unique_id "amuuES0W4wRrtnDoPagBcgABwlM"]
[Thu Jul 30 15:03:29.965851 2026] [security2:error] [pid 87988:tid 88076] [remote 94.154.43.187:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "spececigarette.com"] [uri "/.env"] [unique_id "amuuETipAwzptuCxBrhnoAABfFc"]
[Thu Jul 30 15:03:30.533629 2026] [security2:error] [pid 89520:tid 89611] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuEi0W4wRrtnDoPagBfgACCFE"]
[Thu Jul 30 15:03:30.533760 2026] [security2:error] [pid 89520:tid 89784] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuEi0W4wRrtnDoPagBfgACCFE"]
[Thu Jul 30 15:03:31.178367 2026] [security2:error] [pid 89520:tid 89759] [client 20.199.183.73:24341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/plugins.php"] [unique_id "amuuEy0W4wRrtnDoPagBgwAAAe8"]
[Thu Jul 30 15:03:31.520825 2026] [core:notice] [pid 89520:tid 89612] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:32.575581 2026] [security2:error] [pid 87988:tid 88121] [client 20.199.183.73:43719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/js/index.php"] [unique_id "amuuFDipAwzptuCxBrhn0AAAAQ0"]
[Thu Jul 30 15:03:33.157547 2026] [security2:error] [pid 89520:tid 89767] [client 20.52.54.143:9161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuuFS0W4wRrtnDoPagBmwAAAfc"]
[Thu Jul 30 15:03:33.593680 2026] [security2:error] [pid 89520:tid 89754] [client 20.199.183.73:14056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/go.php"] [unique_id "amuuFS0W4wRrtnDoPagBnQAAAeo"]
[Thu Jul 30 15:03:33.855424 2026] [security2:error] [pid 87988:tid 88129] [client 99.252.106.221:46514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuuFTipAwzptuCxBrhn5AABFUc"], referer: https://www.northyorksheridanmall.com/
[Thu Jul 30 15:03:33.947986 2026] [security2:error] [pid 87988:tid 88144] [client 20.52.54.143:9077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/m.php"] [unique_id "amuuFTipAwzptuCxBrhn5wAAASQ"]
[Thu Jul 30 15:03:33.985736 2026] [security2:error] [pid 89520:tid 89757] [client 213.152.161.240:47656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuuFS0W4wRrtnDoPagBogAAAe0"]
[Thu Jul 30 15:03:33.985848 2026] [security2:error] [pid 89520:tid 89757] [client 213.152.161.240:47656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuuFS0W4wRrtnDoPagBogAAAe0"]
[Thu Jul 30 15:03:34.373067 2026] [security2:error] [pid 87988:tid 88142] [client 20.203.148.31:4606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuuFjipAwzptuCxBrhn8wAAASI"]
[Thu Jul 30 15:03:34.676620 2026] [security2:error] [pid 87988:tid 88063] [remote 103.75.185.95:40950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/wp-login.php"] [unique_id "amuuFjipAwzptuCxBrhn-AABOEo"]
[Thu Jul 30 15:03:34.914006 2026] [security2:error] [pid 87988:tid 88100] [remote 212.80.9.235:43568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "exploringchanges.com"] [uri "/wp-login.php"] [unique_id "amuuFjipAwzptuCxBrhoAAABDG8"]
[Thu Jul 30 15:03:34.948963 2026] [security2:error] [pid 89520:tid 89692] [client 20.199.183.73:31226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/aaa.php"] [unique_id "amuuFi0W4wRrtnDoPagBqgAAAaw"]
[Thu Jul 30 15:03:35.035585 2026] [security2:error] [pid 87988:tid 88167] [client 20.52.54.143:9030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuuFjipAwzptuCxBrhn_QAAATs"]
[Thu Jul 30 15:03:35.845439 2026] [security2:error] [pid 89520:tid 89720] [client 20.52.54.143:9035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wk/index.php"] [unique_id "amuuFy0W4wRrtnDoPagBswAAAcg"]
[Thu Jul 30 15:03:36.076222 2026] [security2:error] [pid 87988:tid 88153] [client 20.199.183.73:37601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/getid3-core.php"] [unique_id "amuuGDipAwzptuCxBrhoDQAAAS0"]
[Thu Jul 30 15:03:36.516116 2026] [security2:error] [pid 89520:tid 89748] [client 20.52.54.143:9079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/mini.php"] [unique_id "amuuGC0W4wRrtnDoPagBugAAAeQ"]
[Thu Jul 30 15:03:36.772279 2026] [security2:error] [pid 89520:tid 89790] [client 20.199.183.73:36503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/adminer.php"] [unique_id "amuuGC0W4wRrtnDoPagBvAAAAg4"]
[Thu Jul 30 15:03:37.185620 2026] [security2:error] [pid 87988:tid 88231] [client 20.52.54.143:9160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/aa.php"] [unique_id "amuuGTipAwzptuCxBrhoHQAAAXs"]
[Thu Jul 30 15:03:37.267808 2026] [security2:error] [pid 87988:tid 88230] [client 20.203.148.31:43239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/img/about.php"] [unique_id "amuuGTipAwzptuCxBrhoHgAAAXo"]
[Thu Jul 30 15:03:37.538145 2026] [core:notice] [pid 89520:tid 89625] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:37.730136 2026] [security2:error] [pid 87988:tid 88155] [client 212.98.233.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuuGTipAwzptuCxBrhoJQAAAS8"], referer: https://cnpinyin.com
[Thu Jul 30 15:03:38.300896 2026] [security2:error] [pid 89520:tid 89675] [client 20.52.54.143:9032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/w.php"] [unique_id "amuuGi0W4wRrtnDoPagBzgAAAZs"]
[Thu Jul 30 15:03:38.376955 2026] [security2:error] [pid 89520:tid 89707] [client 20.199.183.73:19889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/maint/index.php"] [unique_id "amuuGi0W4wRrtnDoPagB0AAAAbs"]
[Thu Jul 30 15:03:38.589141 2026] [security2:error] [pid 89520:tid 89723] [client 20.203.148.31:7195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/languages/about.php"] [unique_id "amuuGi0W4wRrtnDoPagB0gAAAcs"]
[Thu Jul 30 15:03:39.355937 2026] [security2:error] [pid 89520:tid 89729] [client 20.203.148.31:43218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amuuGy0W4wRrtnDoPagB2AAAAdE"]
[Thu Jul 30 15:03:39.455205 2026] [security2:error] [pid 87988:tid 88195] [client 20.199.183.73:33051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/alfa.php"] [unique_id "amuuGzipAwzptuCxBrhoRAAAAVc"]
[Thu Jul 30 15:03:39.513309 2026] [security2:error] [pid 89520:tid 89695] [client 20.52.54.143:9065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/admin.php"] [unique_id "amuuGy0W4wRrtnDoPagB3gAAAa8"]
[Thu Jul 30 15:03:40.110490 2026] [security2:error] [pid 89520:tid 89665] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuGy0W4wRrtnDoPagB3QAAAZE"]
[Thu Jul 30 15:03:40.175925 2026] [security2:error] [pid 89520:tid 89760] [client 20.52.54.143:9043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/gmo.php"] [unique_id "amuuHC0W4wRrtnDoPagB6gAAAfA"]
[Thu Jul 30 15:03:40.599793 2026] [security2:error] [pid 89520:tid 89678] [client 20.199.183.73:13664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuuHC0W4wRrtnDoPagB8QAAAZ4"]
[Thu Jul 30 15:03:40.933781 2026] [security2:error] [pid 89520:tid 89670] [client 20.203.148.31:8895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amuuHC0W4wRrtnDoPagB9QAAAZY"]
[Thu Jul 30 15:03:40.940888 2026] [autoindex:error] [pid 89520:tid 89716] [client 82.156.116.86:42406] AH01276: Cannot serve directory /home1/uixgzjte/public_html/chicago-mfg.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:03:41.074716 2026] [security2:error] [pid 89520:tid 89631] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuHS0W4wRrtnDoPagB-QABqmQ"]
[Thu Jul 30 15:03:41.074892 2026] [security2:error] [pid 89520:tid 89690] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuHS0W4wRrtnDoPagB-QABqmQ"]
[Thu Jul 30 15:03:41.811733 2026] [security2:error] [pid 89520:tid 89672] [client 20.52.54.143:9040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/404.php"] [unique_id "amuuHS0W4wRrtnDoPagB_QAAAZg"]
[Thu Jul 30 15:03:41.909102 2026] [security2:error] [pid 89520:tid 89663] [client 20.203.148.31:3904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amuuHS0W4wRrtnDoPagB_wAAAY8"]
[Thu Jul 30 15:03:42.035289 2026] [security2:error] [pid 87988:tid 88207] [client 74.7.244.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.homemoversandpackersabudhabi.fit"] [uri "/index.php"] [unique_id "amuuHDipAwzptuCxBrhoVQABY10"]
[Thu Jul 30 15:03:42.187642 2026] [security2:error] [pid 89520:tid 89783] [client 20.199.183.73:36153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuuHi0W4wRrtnDoPagCAwAAAgc"]
[Thu Jul 30 15:03:42.366316 2026] [security2:error] [pid 87988:tid 88152] [client 20.203.148.31:3934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amuuHjipAwzptuCxBrhoZwAAASw"]
[Thu Jul 30 15:03:42.502219 2026] [security2:error] [pid 89520:tid 89709] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuHS0W4wRrtnDoPagB_gABvWc"]
[Thu Jul 30 15:03:42.514248 2026] [core:notice] [pid 89520:tid 89632] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:42.619271 2026] [core:notice] [pid 89520:tid 89639] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:42.659644 2026] [security2:error] [pid 89520:tid 89633] [remote 52.167.144.158:6558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/view/4417"] [unique_id "amuuHi0W4wRrtnDoPagCCAAB42Y"]
[Thu Jul 30 15:03:42.784130 2026] [security2:error] [pid 87988:tid 88221] [client 20.199.183.73:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuuHjipAwzptuCxBrhocgAAAXE"]
[Thu Jul 30 15:03:42.816299 2026] [proxy:error] [pid 89520:tid 89679] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:03:42.816378 2026] [proxy_http:error] [pid 89520:tid 89679] [client 52.4.19.39:27965] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:03:42.817166 2026] [proxy:error] [pid 89520:tid 89679] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:03:42.817217 2026] [proxy_http:error] [pid 89520:tid 89679] [client 52.4.19.39:27965] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:03:42.848282 2026] [proxy:error] [pid 87988:tid 88189] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:03:42.848383 2026] [proxy_http:error] [pid 87988:tid 88189] [client 44.213.206.96:54242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:03:42.849443 2026] [proxy:error] [pid 87988:tid 88189] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:03:42.849507 2026] [proxy_http:error] [pid 87988:tid 88189] [client 44.213.206.96:54242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:03:43.550908 2026] [core:notice] [pid 87988:tid 88011] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:43.639872 2026] [security2:error] [pid 87988:tid 88211] [client 20.52.54.143:9057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/init.php"] [unique_id "amuuHzipAwzptuCxBrhogAAAAWc"]
[Thu Jul 30 15:03:44.353344 2026] [security2:error] [pid 87988:tid 88182] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuHzipAwzptuCxBrhodwABShA"]
[Thu Jul 30 15:03:45.292558 2026] [security2:error] [pid 89520:tid 89674] [client 20.199.183.73:36457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/edit.php"] [unique_id "amuuIS0W4wRrtnDoPagCJQAAAZo"]
[Thu Jul 30 15:03:45.348467 2026] [security2:error] [pid 87988:tid 88134] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuHzipAwzptuCxBrhofgABGhs"]
[Thu Jul 30 15:03:45.349664 2026] [security2:error] [pid 87988:tid 88166] [client 20.203.148.31:8415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-admin/js/about.php"] [unique_id "amuuITipAwzptuCxBrhoogAAATo"]
[Thu Jul 30 15:03:46.494611 2026] [security2:error] [pid 89520:tid 89701] [client 20.199.183.73:13781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/file5.php"] [unique_id "amuuIi0W4wRrtnDoPagCOQAAAbU"]
[Thu Jul 30 15:03:47.066274 2026] [security2:error] [pid 89520:tid 89706] [client 20.199.183.73:41220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/sf.php"] [unique_id "amuuIy0W4wRrtnDoPagCPgAAAbo"]
[Thu Jul 30 15:03:47.537504 2026] [security2:error] [pid 89520:tid 89712] [client 20.203.148.31:7189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuuIy0W4wRrtnDoPagCRAAAAcA"]
[Thu Jul 30 15:03:47.569620 2026] [security2:error] [pid 87988:tid 88179] [client 110.249.202.140:55426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiandubaisafari.com"] [uri "/robots.txt"] [unique_id "amuuIzipAwzptuCxBrhowAAAAUc"]
[Thu Jul 30 15:03:47.668573 2026] [security2:error] [pid 87988:tid 88129] [client 20.52.54.143:9055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/adminfuns.php"] [unique_id "amuuIzipAwzptuCxBrhowQAAARU"]
[Thu Jul 30 15:03:48.293322 2026] [security2:error] [pid 89520:tid 89723] [client 20.199.183.73:13921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wso.php"] [unique_id "amuuJC0W4wRrtnDoPagCSwAAAcs"]
[Thu Jul 30 15:03:48.507622 2026] [security2:error] [pid 89520:tid 89726] [client 20.203.148.31:8431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuuJC0W4wRrtnDoPagCUQAAAc4"]
[Thu Jul 30 15:03:48.541616 2026] [core:notice] [pid 89520:tid 89739] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:48.825124 2026] [security2:error] [pid 89520:tid 89754] [client 20.52.54.143:9191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/file.php"] [unique_id "amuuJC0W4wRrtnDoPagCVQAAAeo"]
[Thu Jul 30 15:03:49.071918 2026] [security2:error] [pid 87988:tid 88068] [remote 57.141.0.1:51940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amuuJTipAwzptuCxBrho0AABEU8"]
[Thu Jul 30 15:03:49.108901 2026] [security2:error] [pid 89520:tid 89692] [client 20.199.183.73:48266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/ioxi-o.php"] [unique_id "amuuJS0W4wRrtnDoPagCWAAAAaw"]
[Thu Jul 30 15:03:49.307260 2026] [security2:error] [pid 89520:tid 89676] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuJC0W4wRrtnDoPagCVAABnHU"]
[Thu Jul 30 15:03:49.452764 2026] [core:notice] [pid 87988:tid 88217] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:49.532971 2026] [security2:error] [pid 89520:tid 89750] [client 20.52.54.143:9042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/222.php"] [unique_id "amuuJS0W4wRrtnDoPagCXAAAAeY"]
[Thu Jul 30 15:03:49.673029 2026] [security2:error] [pid 89520:tid 89704] [client 185.191.171.14:48860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/28/paraiba-registra-373-casos-e-uma-morte-por-covid-19-nesta-segunda-feira/"] [unique_id "amuuJS0W4wRrtnDoPagCXgAAAbg"]
[Thu Jul 30 15:03:49.673134 2026] [security2:error] [pid 89520:tid 89704] [client 185.191.171.14:48860] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/28/paraiba-registra-373-casos-e-uma-morte-por-covid-19-nesta-segunda-feira/"] [unique_id "amuuJS0W4wRrtnDoPagCXgAAAbg"]
[Thu Jul 30 15:03:50.005476 2026] [security2:error] [pid 89520:tid 89778] [client 20.199.183.73:47798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/file56.php"] [unique_id "amuuJi0W4wRrtnDoPagCYgAAAgI"]
[Thu Jul 30 15:03:50.054121 2026] [security2:error] [pid 87988:tid 88186] [client 173.249.217.23:46694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.217.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuuJjipAwzptuCxBrho4AAAAU4"]
[Thu Jul 30 15:03:50.054259 2026] [security2:error] [pid 87988:tid 88186] [client 173.249.217.23:46694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuuJjipAwzptuCxBrho4AAAAU4"]
[Thu Jul 30 15:03:50.473290 2026] [security2:error] [pid 87988:tid 88138] [client 20.52.54.143:9067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuuJjipAwzptuCxBrho5gAAAR4"]
[Thu Jul 30 15:03:50.830020 2026] [security2:error] [pid 87988:tid 88181] [client 20.199.183.73:41267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuuJjipAwzptuCxBrho7QAAAUk"]
[Thu Jul 30 15:03:51.397238 2026] [security2:error] [pid 89520:tid 89690] [client 20.199.183.73:47755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/css/index.php"] [unique_id "amuuJy0W4wRrtnDoPagCbwAAAao"]
[Thu Jul 30 15:03:51.516679 2026] [core:notice] [pid 89520:tid 89667] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:03:51.926969 2026] [security2:error] [pid 89520:tid 89654] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuJy0W4wRrtnDoPagCcwAB8Xg"]
[Thu Jul 30 15:03:51.927132 2026] [security2:error] [pid 89520:tid 89761] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuJy0W4wRrtnDoPagCcwAB8Xg"]
[Thu Jul 30 15:03:52.093897 2026] [security2:error] [pid 87988:tid 88239] [client 20.52.54.143:9073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/admin.php"] [unique_id "amuuKDipAwzptuCxBrhpAwAAAYM"]
[Thu Jul 30 15:03:52.245461 2026] [security2:error] [pid 87988:tid 88198] [client 20.199.183.73:13624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/edit.php"] [unique_id "amuuKDipAwzptuCxBrhpBgAAAVo"]
[Thu Jul 30 15:03:52.658166 2026] [security2:error] [pid 87988:tid 88119] [client 20.52.54.143:9159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-configs.php"] [unique_id "amuuKDipAwzptuCxBrhpDAAAAQs"]
[Thu Jul 30 15:03:53.455852 2026] [security2:error] [pid 87988:tid 88176] [client 20.199.183.73:54037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/2.php"] [unique_id "amuuKTipAwzptuCxBrhpGQAAAUQ"]
[Thu Jul 30 15:03:54.374551 2026] [security2:error] [pid 89520:tid 89767] [client 173.249.217.23:42002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.217.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuuKi0W4wRrtnDoPagChQAAAfc"]
[Thu Jul 30 15:03:54.374645 2026] [security2:error] [pid 89520:tid 89767] [client 173.249.217.23:42002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuuKi0W4wRrtnDoPagChQAAAfc"]
[Thu Jul 30 15:03:54.711672 2026] [security2:error] [pid 89520:tid 89745] [client 20.52.54.143:9155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/php.php"] [unique_id "amuuKi0W4wRrtnDoPagCjQAAAeE"]
[Thu Jul 30 15:03:54.846947 2026] [fcgid:warn] [pid 89520:tid 89715] (70014)End of file found: [client 78.113.135.188:17994] mod_fcgid: can't get data from http client
[Thu Jul 30 15:03:55.779380 2026] [fcgid:warn] [pid 87988:tid 88138] (70014)End of file found: [client 194.213.121.3:46932] mod_fcgid: can't get data from http client
[Thu Jul 30 15:03:55.900538 2026] [security2:error] [pid 89520:tid 89769] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuKy0W4wRrtnDoPagClwAAAfk"]
[Thu Jul 30 15:03:56.007093 2026] [security2:error] [pid 89520:tid 89755] [client 20.203.148.31:3905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amuuLC0W4wRrtnDoPagCnwAAAes"]
[Thu Jul 30 15:03:56.489046 2026] [fcgid:warn] [pid 89520:tid 89693] (70014)End of file found: [client 102.129.81.41:49164] mod_fcgid: can't get data from http client
[Thu Jul 30 15:03:56.632921 2026] [security2:error] [pid 89520:tid 89790] [client 20.203.148.31:7196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amuuLC0W4wRrtnDoPagCpgAAAg4"]
[Thu Jul 30 15:03:56.645422 2026] [security2:error] [pid 87988:tid 88180] [client 20.52.54.143:9038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/index.php"] [unique_id "amuuLDipAwzptuCxBrhpQQAAAUg"]
[Thu Jul 30 15:03:56.972160 2026] [fcgid:warn] [pid 89520:tid 89677] (70014)End of file found: [client 85.99.179.58:2330] mod_fcgid: can't get data from http client
[Thu Jul 30 15:03:57.480954 2026] [security2:error] [pid 87988:tid 88155] [client 20.52.54.143:9053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/a.php"] [unique_id "amuuLTipAwzptuCxBrhpUAAAAS8"]
[Thu Jul 30 15:03:59.541569 2026] [security2:error] [pid 89520:tid 89753] [client 20.52.54.143:9165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuuLy0W4wRrtnDoPagCyAAAAek"]
[Thu Jul 30 15:03:59.732340 2026] [security2:error] [pid 89520:tid 89782] [client 20.199.183.73:13795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuuLy0W4wRrtnDoPagCygAAAgY"]
[Thu Jul 30 15:03:59.837185 2026] [security2:error] [pid 89520:tid 89709] [client 160.238.25.181:41659] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/css_root/flaticon.css"] [unique_id "amuuLy0W4wRrtnDoPagCywAAAb0"]
[Thu Jul 30 15:04:00.291534 2026] [security2:error] [pid 89520:tid 89700] [client 20.199.183.73:32351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/mah.php"] [unique_id "amuuMC0W4wRrtnDoPagC0QAAAbQ"]
[Thu Jul 30 15:04:00.709196 2026] [security2:error] [pid 87988:tid 88191] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuMDipAwzptuCxBrhpeQABUwU"]
[Thu Jul 30 15:04:00.797222 2026] [security2:error] [pid 89520:tid 89756] [client 20.52.54.143:9068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin.php"] [unique_id "amuuMC0W4wRrtnDoPagC1wAAAew"]
[Thu Jul 30 15:04:01.533288 2026] [security2:error] [pid 87988:tid 88151] [client 20.199.183.73:45463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/send.php"] [unique_id "amuuMTipAwzptuCxBrhphwAAASs"]
[Thu Jul 30 15:04:01.590345 2026] [security2:error] [pid 89520:tid 89563] [remote 57.141.0.27:37738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuuMS0W4wRrtnDoPagC4QAB9CE"]
[Thu Jul 30 15:04:01.825493 2026] [security2:error] [pid 87988:tid 88170] [client 135.119.63.61:7968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/faq.php"] [unique_id "amuuMTipAwzptuCxBrhpiwAAAT4"]
[Thu Jul 30 15:04:02.013718 2026] [security2:error] [pid 89520:tid 89682] [client 187.189.49.123:16448] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/css/Flaticon.eot"] [unique_id "amuuMi0W4wRrtnDoPagC5wAAAaI"]
[Thu Jul 30 15:04:02.048689 2026] [security2:error] [pid 87988:tid 88128] [client 20.52.54.143:9080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/size.php"] [unique_id "amuuMjipAwzptuCxBrhpjgAAARQ"]
[Thu Jul 30 15:04:02.370154 2026] [security2:error] [pid 87988:tid 88180] [client 20.203.148.31:4574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amuuMjipAwzptuCxBrhplAAAAUg"]
[Thu Jul 30 15:04:02.410859 2026] [security2:error] [pid 89520:tid 89717] [client 89.149.88.60:1394] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/css/Flaticon.woff"] [unique_id "amuuMi0W4wRrtnDoPagC7AAAAcU"]
[Thu Jul 30 15:04:02.640087 2026] [security2:error] [pid 87988:tid 88001] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuMjipAwzptuCxBrhplgABEAw"]
[Thu Jul 30 15:04:02.640333 2026] [security2:error] [pid 87988:tid 88124] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuMjipAwzptuCxBrhplgABEAw"]
[Thu Jul 30 15:04:02.695778 2026] [security2:error] [pid 87988:tid 88211] [client 51.120.83.160:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santaclaraimports.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuuMjipAwzptuCxBrhpmgAAAWc"]
[Thu Jul 30 15:04:02.695899 2026] [security2:error] [pid 87988:tid 88211] [client 51.120.83.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "santaclaraimports.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuuMjipAwzptuCxBrhpmgAAAWc"]
[Thu Jul 30 15:04:02.750293 2026] [security2:error] [pid 87988:tid 88196] [client 20.52.54.143:9070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuuMjipAwzptuCxBrhpmwAAAVg"]
[Thu Jul 30 15:04:03.080549 2026] [security2:error] [pid 87988:tid 88225] [client 20.199.183.73:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuuMzipAwzptuCxBrhpnwAAAXU"]
[Thu Jul 30 15:04:03.126859 2026] [security2:error] [pid 87988:tid 88239] [client 135.119.63.61:7937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/fatal.php"] [unique_id "amuuMzipAwzptuCxBrhpowAAAYM"]
[Thu Jul 30 15:04:03.281025 2026] [security2:error] [pid 89520:tid 89645] [remote 57.141.18.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuuMy0W4wRrtnDoPagC9wAB8nA"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,linen,polyester,denim,aluminum,plastic,nylon,steel&orderby=popularity&rating=5&status=instock&filter_brand=rayban&unfilter=1
[Thu Jul 30 15:04:03.296617 2026] [security2:error] [pid 87988:tid 88167] [client 20.52.54.143:9050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/403.php"] [unique_id "amuuMzipAwzptuCxBrhppwAAATs"]
[Thu Jul 30 15:04:04.010959 2026] [security2:error] [pid 89520:tid 89710] [client 102.97.26.70:35448] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/css/Flaticon.eot"] [unique_id "amuuNC0W4wRrtnDoPagC_gAAAb4"]
[Thu Jul 30 15:04:04.017386 2026] [security2:error] [pid 89520:tid 89703] [client 20.52.54.143:9048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuuNC0W4wRrtnDoPagC_wAAAbc"]
[Thu Jul 30 15:04:04.165542 2026] [security2:error] [pid 89520:tid 89726] [client 20.199.183.73:39925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/about.php"] [unique_id "amuuNC0W4wRrtnDoPagDAwAAAc4"]
[Thu Jul 30 15:04:04.295422 2026] [security2:error] [pid 89520:tid 89702] [client 135.119.63.61:59364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/favicon.php"] [unique_id "amuuNC0W4wRrtnDoPagDBgAAAbY"]
[Thu Jul 30 15:04:04.296765 2026] [security2:error] [pid 89520:tid 89783] [client 191.184.166.47:43728] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/font-awesome/fonts/fontawesome-webfont.woff"] [unique_id "amuuNC0W4wRrtnDoPagDBQAAAgc"]
[Thu Jul 30 15:04:04.400389 2026] [security2:error] [pid 87988:tid 88184] [client 84.54.72.38:6767] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/font-awesome/fonts/fontawesome-webfont.eot"] [unique_id "amuuNDipAwzptuCxBrhptwAAAUw"]
[Thu Jul 30 15:04:04.467396 2026] [core:notice] [pid 89520:tid 89772] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:04.825752 2026] [security2:error] [pid 87988:tid 88126] [client 37.239.28.19:5952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/font-awesome/fonts/fontawesome-webfont.eot"] [unique_id "amuuNDipAwzptuCxBrhpwAAAARI"]
[Thu Jul 30 15:04:04.925875 2026] [security2:error] [pid 89520:tid 89757] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuNC0W4wRrtnDoPagDBwAB7Rs"]
[Thu Jul 30 15:04:05.076406 2026] [security2:error] [pid 87988:tid 88166] [client 20.52.54.143:9058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/as.php"] [unique_id "amuuNTipAwzptuCxBrhpwgAAATo"]
[Thu Jul 30 15:04:05.079554 2026] [core:notice] [pid 87988:tid 88152] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:05.246498 2026] [security2:error] [pid 87988:tid 88153] [client 27.124.95.34:54966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuuNTipAwzptuCxBrhpxwAAAS0"]
[Thu Jul 30 15:04:05.314563 2026] [security2:error] [pid 87988:tid 88200] [client 20.199.183.73:39886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/options.php"] [unique_id "amuuNTipAwzptuCxBrhpzAAAAVw"]
[Thu Jul 30 15:04:05.695759 2026] [core:notice] [pid 87988:tid 88151] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:05.699369 2026] [security2:error] [pid 87988:tid 88151] [client 66.249.79.231:62623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3834"] [unique_id "amuuNTipAwzptuCxBrhpzQAAASs"]
[Thu Jul 30 15:04:05.791909 2026] [security2:error] [pid 89520:tid 89737] [client 20.52.54.143:9076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuuNS0W4wRrtnDoPagDEwAAAdk"]
[Thu Jul 30 15:04:05.807710 2026] [security2:error] [pid 87988:tid 88203] [client 177.124.154.222:33199] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/font-awesome/fonts/fontawesome-webfont.ttf"] [unique_id "amuuNTipAwzptuCxBrhp1AAAAV8"]
[Thu Jul 30 15:04:06.023151 2026] [security2:error] [pid 89520:tid 89730] [client 135.119.63.61:8817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/fck.php"] [unique_id "amuuNi0W4wRrtnDoPagDFgAAAdI"]
[Thu Jul 30 15:04:06.072321 2026] [security2:error] [pid 89520:tid 89718] [client 20.199.183.73:39932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/themes/index.php"] [unique_id "amuuNi0W4wRrtnDoPagDFwAAAcY"]
[Thu Jul 30 15:04:06.280317 2026] [security2:error] [pid 89520:tid 89713] [client 51.120.83.160:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.83.120.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santaclaraimports.com"] [uri "/.well-known/admin.php"] [unique_id "amuuNi0W4wRrtnDoPagDGwAAAcE"]
[Thu Jul 30 15:04:06.280414 2026] [security2:error] [pid 89520:tid 89713] [client 51.120.83.160:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "santaclaraimports.com"] [uri "/.well-known/admin.php"] [unique_id "amuuNi0W4wRrtnDoPagDGwAAAcE"]
[Thu Jul 30 15:04:06.393339 2026] [security2:error] [pid 89520:tid 89738] [client 94.200.248.84:51561] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/fonts/glyphicons-halflings-regular.woff"] [unique_id "amuuNi0W4wRrtnDoPagDHAAAAdo"]
[Thu Jul 30 15:04:06.519766 2026] [security2:error] [pid 89520:tid 89656] [remote 113.68.10.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.10.68.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alshateealazraqtours.com"] [uri "/xmlrpc.php"] [unique_id "amuuNi0W4wRrtnDoPagDGgABl3o"]
[Thu Jul 30 15:04:06.520007 2026] [security2:error] [pid 89520:tid 89671] [client 113.68.10.165:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alshateealazraqtours.com"] [uri "/xmlrpc.php"] [unique_id "amuuNi0W4wRrtnDoPagDGgABl3o"]
[Thu Jul 30 15:04:06.651169 2026] [security2:error] [pid 87988:tid 88164] [client 20.203.148.31:4590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/themes/about.php"] [unique_id "amuuNjipAwzptuCxBrhp3QAAATg"]
[Thu Jul 30 15:04:06.667083 2026] [security2:error] [pid 87988:tid 88205] [client 20.199.183.73:24871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-file.php"] [unique_id "amuuNjipAwzptuCxBrhp3gAAAWE"]
[Thu Jul 30 15:04:06.692652 2026] [security2:error] [pid 87988:tid 88156] [client 212.47.138.214:4623] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/fonts/glyphicons-halflings-regular.eot"] [unique_id "amuuNjipAwzptuCxBrhp3wAAATA"]
[Thu Jul 30 15:04:06.758668 2026] [security2:error] [pid 89520:tid 89665] [client 20.52.54.143:9202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuuNi0W4wRrtnDoPagDHwAAAZE"]
[Thu Jul 30 15:04:07.250634 2026] [security2:error] [pid 89520:tid 89708] [client 200.2.163.16:21627] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/css/Flaticon.ttf"] [unique_id "amuuNy0W4wRrtnDoPagDJgAAAbw"]
[Thu Jul 30 15:04:08.035639 2026] [security2:error] [pid 89520:tid 89701] [client 186.80.54.238:10685] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arabiandubaisafari.com"] [uri "/assets/fonts/glyphicons-halflings-regular.ttf"] [unique_id "amuuOC0W4wRrtnDoPagDLwAAAbU"]
[Thu Jul 30 15:04:08.390416 2026] [security2:error] [pid 89520:tid 89689] [client 23.130.104.130:35146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.104.130.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuuOC0W4wRrtnDoPagDMgAAAak"]
[Thu Jul 30 15:04:08.390529 2026] [security2:error] [pid 89520:tid 89689] [client 23.130.104.130:35146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuuOC0W4wRrtnDoPagDMgAAAak"]
[Thu Jul 30 15:04:08.723005 2026] [security2:error] [pid 89520:tid 89744] [client 113.68.10.165:12142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.10.68.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alshateeintl.com"] [uri "/xmlrpc.php"] [unique_id "amuuOC0W4wRrtnDoPagDNgAAAeA"]
[Thu Jul 30 15:04:08.723129 2026] [security2:error] [pid 89520:tid 89744] [client 113.68.10.165:12142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alshateeintl.com"] [uri "/xmlrpc.php"] [unique_id "amuuOC0W4wRrtnDoPagDNgAAAeA"]
[Thu Jul 30 15:04:08.901144 2026] [security2:error] [pid 87988:tid 88206] [client 20.52.54.143:9083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/plugins.php"] [unique_id "amuuODipAwzptuCxBrhqAAAAAWI"]
[Thu Jul 30 15:04:09.049588 2026] [security2:error] [pid 87988:tid 88161] [client 20.199.183.73:47355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/sid3.php"] [unique_id "amuuOTipAwzptuCxBrhqBwAAATU"]
[Thu Jul 30 15:04:09.070708 2026] [security2:error] [pid 89520:tid 89742] [client 20.203.148.31:1741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amuuOS0W4wRrtnDoPagDPAAAAd4"]
[Thu Jul 30 15:04:09.379269 2026] [core:error] [pid 89520:tid 89787] [client 3.135.225.93:52914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:09.379292 2026] [core:error] [pid 89520:tid 89787] [client 3.135.225.93:52914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:09.649361 2026] [security2:error] [pid 87988:tid 88183] [client 20.52.54.143:9087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuuOTipAwzptuCxBrhqDAAAAUs"]
[Thu Jul 30 15:04:09.764166 2026] [security2:error] [pid 89520:tid 89698] [client 20.199.183.73:39010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/themes.php"] [unique_id "amuuOS0W4wRrtnDoPagDSQAAAbI"]
[Thu Jul 30 15:04:09.834203 2026] [core:error] [pid 89520:tid 89746] [client 3.135.225.93:50230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:09.834222 2026] [core:error] [pid 89520:tid 89746] [client 3.135.225.93:50230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:10.484001 2026] [security2:error] [pid 87988:tid 88136] [client 20.52.54.143:9026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/go.php"] [unique_id "amuuOjipAwzptuCxBrhqEwAAARw"]
[Thu Jul 30 15:04:10.549411 2026] [security2:error] [pid 89520:tid 89720] [client 20.199.183.73:39002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/plugins/index.php"] [unique_id "amuuOi0W4wRrtnDoPagDUgAAAcg"]
[Thu Jul 30 15:04:10.758762 2026] [security2:error] [pid 89520:tid 89713] [client 135.119.63.61:59359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/fdgfdgdsfd.php"] [unique_id "amuuOi0W4wRrtnDoPagDVgAAAcE"]
[Thu Jul 30 15:04:12.030826 2026] [security2:error] [pid 89520:tid 89717] [client 20.52.54.143:9054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/test1.php"] [unique_id "amuuPC0W4wRrtnDoPagDXgAAAcU"]
[Thu Jul 30 15:04:12.224675 2026] [security2:error] [pid 89520:tid 89677] [client 185.191.171.18:42074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/12/casal-de-influenciadores-que-vendia-rifas-e-morto-a-tiros-em-praia-da-bahia/"] [unique_id "amuuPC0W4wRrtnDoPagDZAAAAZ0"]
[Thu Jul 30 15:04:12.224782 2026] [security2:error] [pid 89520:tid 89677] [client 185.191.171.18:42074] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/12/casal-de-influenciadores-que-vendia-rifas-e-morto-a-tiros-em-praia-da-bahia/"] [unique_id "amuuPC0W4wRrtnDoPagDZAAAAZ0"]
[Thu Jul 30 15:04:12.255271 2026] [security2:error] [pid 87988:tid 88239] [client 135.119.63.61:8781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/fe5.php"] [unique_id "amuuPDipAwzptuCxBrhqRQAAAYM"]
[Thu Jul 30 15:04:12.643010 2026] [security2:error] [pid 89520:tid 89686] [client 172.237.109.114:21960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuPC0W4wRrtnDoPagDYQAAAaY"]
[Thu Jul 30 15:04:12.741102 2026] [security2:error] [pid 89520:tid 89685] [client 172.237.109.114:47223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuPC0W4wRrtnDoPagDYgAAAaU"]
[Thu Jul 30 15:04:13.187797 2026] [security2:error] [pid 89520:tid 89664] [client 135.119.63.61:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/fedora.php"] [unique_id "amuuPS0W4wRrtnDoPagDcAAAAZA"]
[Thu Jul 30 15:04:13.286930 2026] [security2:error] [pid 89520:tid 89537] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuPS0W4wRrtnDoPagDcwABrgc"]
[Thu Jul 30 15:04:13.287087 2026] [security2:error] [pid 89520:tid 89694] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuPS0W4wRrtnDoPagDcwABrgc"]
[Thu Jul 30 15:04:13.325121 2026] [security2:error] [pid 87988:tid 88187] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuPDipAwzptuCxBrhqUAAAAU8"]
[Thu Jul 30 15:04:13.778560 2026] [security2:error] [pid 89520:tid 89742] [client 20.52.54.143:9174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/images/index.php"] [unique_id "amuuPS0W4wRrtnDoPagDeAAAAd4"]
[Thu Jul 30 15:04:13.952695 2026] [security2:error] [pid 87988:tid 88028] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/.env"] [unique_id "amuuPTipAwzptuCxBrhqjgABeic"]
[Thu Jul 30 15:04:14.369768 2026] [security2:error] [pid 87988:tid 88087] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/.env.bak"] [unique_id "amuuPjipAwzptuCxBrhqmwABdGI"]
[Thu Jul 30 15:04:14.372905 2026] [security2:error] [pid 87988:tid 88068] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/.env.backup"] [unique_id "amuuPjipAwzptuCxBrhqnAABdE8"]
[Thu Jul 30 15:04:14.642134 2026] [security2:error] [pid 89520:tid 89746] [client 20.199.183.73:33981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/images/index.php"] [unique_id "amuuPi0W4wRrtnDoPagDiAAAAeI"]
[Thu Jul 30 15:04:14.680137 2026] [security2:error] [pid 89520:tid 89774] [client 74.7.244.27:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.qhp.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuuPC0W4wRrtnDoPagDZwAAAf4"]
[Thu Jul 30 15:04:14.680160 2026] [security2:error] [pid 89520:tid 89774] [client 74.7.244.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.qhp.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuuPC0W4wRrtnDoPagDZwAAAf4"]
[Thu Jul 30 15:04:14.681216 2026] [security2:error] [pid 87988:tid 88182] [client 74.7.244.27:53656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.qhp.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuuPDipAwzptuCxBrhqTAABSgQ"]
[Thu Jul 30 15:04:14.830666 2026] [security2:error] [pid 87988:tid 88047] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/.env.old"] [unique_id "amuuPjipAwzptuCxBrhqqAABFTo"]
[Thu Jul 30 15:04:14.850027 2026] [security2:error] [pid 87988:tid 88050] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/api/.env"] [unique_id "amuuPjipAwzptuCxBrhqrAABZz0"]
[Thu Jul 30 15:04:14.943524 2026] [security2:error] [pid 89520:tid 89729] [client 20.203.148.31:8434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/images/about.php"] [unique_id "amuuPi0W4wRrtnDoPagDkQAAAdE"]
[Thu Jul 30 15:04:14.978291 2026] [security2:error] [pid 89520:tid 89736] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuPi0W4wRrtnDoPagDggAAAdg"]
[Thu Jul 30 15:04:15.054060 2026] [security2:error] [pid 89520:tid 89665] [client 20.52.54.143:9064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/asd.php"] [unique_id "amuuPy0W4wRrtnDoPagDkwAAAZE"]
[Thu Jul 30 15:04:15.104429 2026] [security2:error] [pid 87988:tid 88046] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/backend/.env"] [unique_id "amuuPzipAwzptuCxBrhqrgABUDk"]
[Thu Jul 30 15:04:15.165602 2026] [security2:error] [pid 87988:tid 88077] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/config/.env"] [unique_id "amuuPzipAwzptuCxBrhqsgABPVg"]
[Thu Jul 30 15:04:15.545859 2026] [security2:error] [pid 89520:tid 89752] [client 74.7.244.27:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qhp.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuuPy0W4wRrtnDoPagDmwAAAeg"], referer: https://www.qhp.nyx.temporary.site/robots.txt
[Thu Jul 30 15:04:15.546763 2026] [security2:error] [pid 89520:tid 89748] [client 74.7.244.27:53666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qhp.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuuPy0W4wRrtnDoPagDmQAB5Cs"], referer: https://www.qhp.nyx.temporary.site/robots.txt
[Thu Jul 30 15:04:15.547327 2026] [security2:error] [pid 87988:tid 88160] [client 135.119.63.61:54911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/feed-rsss.php"] [unique_id "amuuPzipAwzptuCxBrhqwQAAATQ"]
[Thu Jul 30 15:04:16.103361 2026] [authz_core:error] [pid 87988:tid 88114] [remote 34.125.84.50:48438] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Thu Jul 30 15:04:16.227992 2026] [security2:error] [pid 89520:tid 89779] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuPy0W4wRrtnDoPagDlAACAw0"]
[Thu Jul 30 15:04:16.426477 2026] [security2:error] [pid 89520:tid 89690] [client 20.199.183.73:44317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/num.php"] [unique_id "amuuQC0W4wRrtnDoPagDpAAAAao"]
[Thu Jul 30 15:04:16.526638 2026] [security2:error] [pid 89520:tid 89686] [client 20.52.54.143:9184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuuQC0W4wRrtnDoPagDpQAAAaY"]
[Thu Jul 30 15:04:16.721418 2026] [security2:error] [pid 87988:tid 87992] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/.ssh/id_rsa"] [unique_id "amuuQDipAwzptuCxBrhq6gABYgM"]
[Thu Jul 30 15:04:16.750258 2026] [security2:error] [pid 87988:tid 88099] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/.ssh/id_dsa"] [unique_id "amuuQDipAwzptuCxBrhq6wABiW4"]
[Thu Jul 30 15:04:17.101232 2026] [security2:error] [pid 87988:tid 87990] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/id_rsa"] [unique_id "amuuQTipAwzptuCxBrhq-gABOgE"]
[Thu Jul 30 15:04:17.210452 2026] [security2:error] [pid 87988:tid 88082] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/id_dsa"] [unique_id "amuuQTipAwzptuCxBrhq-wABel0"]
[Thu Jul 30 15:04:17.281610 2026] [security2:error] [pid 87988:tid 88116] [remote 57.141.0.27:60836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55089810635/feed/rss2/"] [unique_id "amuuQTipAwzptuCxBrhrAAABeH8"]
[Thu Jul 30 15:04:17.472728 2026] [security2:error] [pid 87988:tid 88011] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/key.pem"] [unique_id "amuuQTipAwzptuCxBrhrBwABZhY"]
[Thu Jul 30 15:04:17.516731 2026] [security2:error] [pid 89520:tid 89672] [client 20.52.54.143:9169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuuQS0W4wRrtnDoPagDrAAAAZg"]
[Thu Jul 30 15:04:17.517818 2026] [security2:error] [pid 87988:tid 88113] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/privatekey.key"] [unique_id "amuuQTipAwzptuCxBrhrCwABIHw"]
[Thu Jul 30 15:04:18.128162 2026] [security2:error] [pid 87988:tid 88174] [client 20.52.54.143:9034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/atomlib.php"] [unique_id "amuuQjipAwzptuCxBrhrIQAAAUI"]
[Thu Jul 30 15:04:18.197863 2026] [security2:error] [pid 87988:tid 88034] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/.openclaw/.env"] [unique_id "amuuQjipAwzptuCxBrhrIwABai0"]
[Thu Jul 30 15:04:18.332345 2026] [security2:error] [pid 89520:tid 89783] [client 20.203.148.31:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amuuQi0W4wRrtnDoPagDsQAAAgc"]
[Thu Jul 30 15:04:18.548702 2026] [security2:error] [pid 87988:tid 88019] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/.hermes/.env"] [unique_id "amuuQjipAwzptuCxBrhrMgABVx4"]
[Thu Jul 30 15:04:18.736150 2026] [security2:error] [pid 87988:tid 88200] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuQjipAwzptuCxBrhrIAABXC4"]
[Thu Jul 30 15:04:19.074837 2026] [core:notice] [pid 87988:tid 88167] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:19.266971 2026] [security2:error] [pid 87988:tid 88131] [client 20.52.54.143:9052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuuQzipAwzptuCxBrhrTgAAARc"]
[Thu Jul 30 15:04:19.425404 2026] [security2:error] [pid 87988:tid 88204] [client 20.203.148.31:4455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/images/about.php"] [unique_id "amuuQzipAwzptuCxBrhrUgAAAWA"]
[Thu Jul 30 15:04:19.605095 2026] [security2:error] [pid 89520:tid 89712] [client 135.119.63.61:8768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/ff.php"] [unique_id "amuuQy0W4wRrtnDoPagDuwAAAcA"]
[Thu Jul 30 15:04:19.658167 2026] [security2:error] [pid 87988:tid 88077] [remote 57.141.0.7:31140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/44562851719/feed/rss2/"] [unique_id "amuuQzipAwzptuCxBrhrXQABglg"]
[Thu Jul 30 15:04:19.787917 2026] [security2:error] [pid 87988:tid 88069] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "console.ghggeneralcontracting.com"] [uri "/wp-config.php.bak"] [unique_id "amuuQzipAwzptuCxBrhrXgABhVA"]
[Thu Jul 30 15:04:19.968316 2026] [security2:error] [pid 87988:tid 88066] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "console.ghggeneralcontracting.com"] [uri "/wp-config.php.old"] [unique_id "amuuQzipAwzptuCxBrhrZwABIU0"]
[Thu Jul 30 15:04:20.165061 2026] [security2:error] [pid 89520:tid 89676] [client 20.203.148.31:4103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/about.php"] [unique_id "amuuRC0W4wRrtnDoPagDxwAAAZw"]
[Thu Jul 30 15:04:20.253675 2026] [security2:error] [pid 87988:tid 88058] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/laravel/.env"] [unique_id "amuuRDipAwzptuCxBrhrbQABbEU"]
[Thu Jul 30 15:04:20.268253 2026] [security2:error] [pid 89520:tid 89786] [client 20.199.183.73:31177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/images/admin.php"] [unique_id "amuuRC0W4wRrtnDoPagDyAAAAgo"]
[Thu Jul 30 15:04:20.288543 2026] [security2:error] [pid 87988:tid 88043] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/core/.env"] [unique_id "amuuRDipAwzptuCxBrhrbwABHDY"]
[Thu Jul 30 15:04:20.380133 2026] [security2:error] [pid 87988:tid 88220] [client 74.7.228.35:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aaapropertiesph.com"] [uri "/index.php"] [unique_id "amuuQzipAwzptuCxBrhrRwABcDQ"]
[Thu Jul 30 15:04:20.530896 2026] [security2:error] [pid 87988:tid 88031] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.84.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.ghggeneralcontracting.com"] [uri "/config/.env.php"] [unique_id "amuuRDipAwzptuCxBrhrcAABVCo"]
[Thu Jul 30 15:04:20.559084 2026] [security2:error] [pid 87988:tid 88057] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.84.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.ghggeneralcontracting.com"] [uri "/.env.php.bak"] [unique_id "amuuRDipAwzptuCxBrhrcgABVEQ"]
[Thu Jul 30 15:04:20.724088 2026] [security2:error] [pid 87988:tid 88114] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.84.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.ghggeneralcontracting.com"] [uri "/configuration.php.bak"] [unique_id "amuuRDipAwzptuCxBrhrfwABZ30"]
[Thu Jul 30 15:04:20.854782 2026] [security2:error] [pid 87988:tid 87998] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.84.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.ghggeneralcontracting.com"] [uri "/config.php.bak"] [unique_id "amuuRDipAwzptuCxBrhrgQABKQk"]
[Thu Jul 30 15:04:20.903128 2026] [security2:error] [pid 87988:tid 88179] [client 20.52.54.143:9045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/inputs.php"] [unique_id "amuuRDipAwzptuCxBrhrggAAAUc"]
[Thu Jul 30 15:04:20.948879 2026] [security2:error] [pid 87988:tid 87989] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/.env.swp"] [unique_id "amuuRDipAwzptuCxBrhrhAABPQA"]
[Thu Jul 30 15:04:20.992559 2026] [security2:error] [pid 87988:tid 88115] [remote 74.7.243.224:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuuRDipAwzptuCxBrhriQABdX4"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:04:21.009004 2026] [security2:error] [pid 87988:tid 88003] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/public/.env"] [unique_id "amuuRTipAwzptuCxBrhrigABHQ4"]
[Thu Jul 30 15:04:21.010786 2026] [security2:error] [pid 87988:tid 88111] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/web/.env"] [unique_id "amuuRTipAwzptuCxBrhriwABHXo"]
[Thu Jul 30 15:04:21.061492 2026] [security2:error] [pid 87988:tid 88140] [client 135.119.63.61:8773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/ff2.php"] [unique_id "amuuRTipAwzptuCxBrhrjgAAASA"]
[Thu Jul 30 15:04:21.154021 2026] [security2:error] [pid 89520:tid 89665] [client 20.203.148.31:8641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/cgi-bin/about.php"] [unique_id "amuuRS0W4wRrtnDoPagD0QAAAZE"]
[Thu Jul 30 15:04:21.520377 2026] [security2:error] [pid 89520:tid 89769] [client 114.132.135.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuRC0W4wRrtnDoPagDyQAB-SY"]
[Thu Jul 30 15:04:21.600893 2026] [proxy:error] [pid 87988:tid 88110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:04:21.600947 2026] [proxy_http:error] [pid 87988:tid 88110] [remote 185.247.137.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.teknomalay.com:2086
[Thu Jul 30 15:04:21.601800 2026] [proxy:error] [pid 87988:tid 88110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:04:21.601851 2026] [proxy_http:error] [pid 87988:tid 88110] [remote 185.247.137.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.teknomalay.com:2086
[Thu Jul 30 15:04:21.783528 2026] [security2:error] [pid 89520:tid 89743] [client 20.52.54.143:9170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/index.php"] [unique_id "amuuRS0W4wRrtnDoPagD3AAAAd8"]
[Thu Jul 30 15:04:21.878054 2026] [security2:error] [pid 87988:tid 88219] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuRDipAwzptuCxBrhrhgABb2s"]
[Thu Jul 30 15:04:22.427604 2026] [security2:error] [pid 89520:tid 89758] [client 135.119.63.61:59347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/ffAA531.php"] [unique_id "amuuRi0W4wRrtnDoPagD5wAAAe4"]
[Thu Jul 30 15:04:22.498251 2026] [security2:error] [pid 87988:tid 88113] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/web.config"] [unique_id "amuuRjipAwzptuCxBrhruQABYHw"]
[Thu Jul 30 15:04:22.648088 2026] [security2:error] [pid 87988:tid 88160] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuRjipAwzptuCxBrhrqQABNAE"]
[Thu Jul 30 15:04:22.848405 2026] [core:notice] [pid 87988:tid 88001] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:23.123596 2026] [core:notice] [pid 87988:tid 88010] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:23.273186 2026] [security2:error] [pid 89520:tid 89710] [client 147.90.227.68:65089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp/xmlrpc.php"] [unique_id "amuuRy0W4wRrtnDoPagD7gAAAb4"]
[Thu Jul 30 15:04:23.496190 2026] [security2:error] [pid 87988:tid 88076] [remote 34.125.84.50:48438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.ghggeneralcontracting.com"] [uri "/@fs/root/.env"] [unique_id "amuuRzipAwzptuCxBrhr3wABY1c"]
[Thu Jul 30 15:04:23.514273 2026] [security2:error] [pid 87988:tid 88165] [client 135.119.63.61:54878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/ffile.php"] [unique_id "amuuRzipAwzptuCxBrhr4QAAATk"]
[Thu Jul 30 15:04:23.968166 2026] [security2:error] [pid 87988:tid 88018] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuRzipAwzptuCxBrhr6QABQh0"]
[Thu Jul 30 15:04:23.968321 2026] [security2:error] [pid 87988:tid 88174] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuRzipAwzptuCxBrhr6QABQh0"]
[Thu Jul 30 15:04:24.439005 2026] [security2:error] [pid 87988:tid 88212] [client 135.119.63.61:7889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/fhhgjg.php"] [unique_id "amuuSDipAwzptuCxBrhr8gAAAWg"]
[Thu Jul 30 15:04:24.615004 2026] [security2:error] [pid 89520:tid 89701] [client 20.203.148.31:32146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amuuSC0W4wRrtnDoPagD_AAAAbU"]
[Thu Jul 30 15:04:24.995575 2026] [security2:error] [pid 89520:tid 89684] [client 20.52.54.143:9158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuuSC0W4wRrtnDoPagEAwAAAaQ"]
[Thu Jul 30 15:04:25.270931 2026] [security2:error] [pid 89520:tid 89786] [client 20.203.148.31:32134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuuSS0W4wRrtnDoPagEBgAAAgo"]
[Thu Jul 30 15:04:25.396258 2026] [security2:error] [pid 87988:tid 88186] [client 135.119.63.61:8815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/fi2.php"] [unique_id "amuuSTipAwzptuCxBrhsAQAAAU4"]
[Thu Jul 30 15:04:26.046837 2026] [security2:error] [pid 89520:tid 89713] [client 20.203.148.31:7344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-admin/css/about.php"] [unique_id "amuuSi0W4wRrtnDoPagEEAAAAcE"]
[Thu Jul 30 15:04:26.102919 2026] [security2:error] [pid 89520:tid 89681] [client 20.52.54.143:9074] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/1.php"] [unique_id "amuuSi0W4wRrtnDoPagEEQAAAaE"]
[Thu Jul 30 15:04:26.103059 2026] [security2:error] [pid 89520:tid 89681] [client 20.52.54.143:9074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/1.php"] [unique_id "amuuSi0W4wRrtnDoPagEEQAAAaE"]
[Thu Jul 30 15:04:26.333368 2026] [security2:error] [pid 89520:tid 89677] [client 147.90.227.68:48823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/new/xmlrpc.php"] [unique_id "amuuSi0W4wRrtnDoPagEFwAAAZ0"]
[Thu Jul 30 15:04:26.333405 2026] [security2:error] [pid 87988:tid 88152] [client 147.90.227.68:45553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/sandbox/xmlrpc.php"] [unique_id "amuuSjipAwzptuCxBrhsCwAAASw"]
[Thu Jul 30 15:04:26.334924 2026] [security2:error] [pid 89520:tid 89748] [client 147.90.227.68:54125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/staging/xmlrpc.php"] [unique_id "amuuSi0W4wRrtnDoPagEGAAAAeQ"]
[Thu Jul 30 15:04:26.338243 2026] [security2:error] [pid 89520:tid 89706] [client 147.90.227.68:62565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/home/xmlrpc.php"] [unique_id "amuuSi0W4wRrtnDoPagEGQAAAbo"]
[Thu Jul 30 15:04:26.338338 2026] [security2:error] [pid 89520:tid 89743] [client 147.90.227.68:60833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-content/xmlrpc.php"] [unique_id "amuuSi0W4wRrtnDoPagEGgAAAd8"]
[Thu Jul 30 15:04:26.338513 2026] [security2:error] [pid 89520:tid 89671] [client 147.90.227.68:50057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/web/xmlrpc.php"] [unique_id "amuuSi0W4wRrtnDoPagEGwAAAZc"]
[Thu Jul 30 15:04:26.370227 2026] [security2:error] [pid 89520:tid 89670] [client 147.90.227.68:51283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/backup/xmlrpc.php"] [unique_id "amuuSi0W4wRrtnDoPagEHAAAAZY"]
[Thu Jul 30 15:04:26.373633 2026] [security2:error] [pid 89520:tid 89728] [client 147.90.227.68:39747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp1/xmlrpc.php"] [unique_id "amuuSi0W4wRrtnDoPagEHgAAAdA"]
[Thu Jul 30 15:04:26.373750 2026] [security2:error] [pid 87988:tid 88230] [client 147.90.227.68:34263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/app/xmlrpc.php"] [unique_id "amuuSjipAwzptuCxBrhsDgAAAXo"]
[Thu Jul 30 15:04:26.373791 2026] [security2:error] [pid 87988:tid 88161] [client 147.90.227.68:29581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/prod/xmlrpc.php"] [unique_id "amuuSjipAwzptuCxBrhsDQAAATU"]
[Thu Jul 30 15:04:26.373914 2026] [security2:error] [pid 89520:tid 89733] [client 147.90.227.68:58703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/main/xmlrpc.php"] [unique_id "amuuSi0W4wRrtnDoPagEHwAAAdU"]
[Thu Jul 30 15:04:26.373934 2026] [security2:error] [pid 87988:tid 88153] [client 147.90.227.68:61149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/site/xmlrpc.php"] [unique_id "amuuSjipAwzptuCxBrhsDwAAAS0"]
[Thu Jul 30 15:04:26.374040 2026] [security2:error] [pid 87988:tid 88241] [client 147.90.227.68:59577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/testing/xmlrpc.php"] [unique_id "amuuSjipAwzptuCxBrhsEAAAAYU"]
[Thu Jul 30 15:04:26.374317 2026] [security2:error] [pid 87988:tid 88221] [client 147.90.227.68:58637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/core/xmlrpc.php"] [unique_id "amuuSjipAwzptuCxBrhsEQAAAXE"]
[Thu Jul 30 15:04:26.374581 2026] [security2:error] [pid 87988:tid 88228] [client 147.90.227.68:50219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-old//xmlrpc.php"] [unique_id "amuuSjipAwzptuCxBrhsEgAAAXg"]
[Thu Jul 30 15:04:26.375432 2026] [security2:error] [pid 87988:tid 88138] [client 147.90.227.68:63739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old/xmlrpc.php"] [unique_id "amuuSjipAwzptuCxBrhsEwAAAR4"]
[Thu Jul 30 15:04:26.714671 2026] [security2:error] [pid 89520:tid 89666] [client 135.119.63.61:59361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/fierza.php"] [unique_id "amuuSi0W4wRrtnDoPagEIgAAAZI"]
[Thu Jul 30 15:04:26.728260 2026] [security2:error] [pid 89520:tid 89762] [client 20.199.183.73:36130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuuSi0W4wRrtnDoPagEIwAAAfI"]
[Thu Jul 30 15:04:27.473167 2026] [security2:error] [pid 89520:tid 89726] [client 20.203.148.31:1770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-admin/images/about.php"] [unique_id "amuuSy0W4wRrtnDoPagELAAAAc4"]
[Thu Jul 30 15:04:27.735268 2026] [security2:error] [pid 89520:tid 89742] [client 135.119.63.61:59360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file-manager.php"] [unique_id "amuuSy0W4wRrtnDoPagELgAAAd4"]
[Thu Jul 30 15:04:27.926780 2026] [security2:error] [pid 89520:tid 89739] [client 147.90.227.68:21702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wordpress/xmlrpc.php"] [unique_id "amuuSy0W4wRrtnDoPagEMQAAAds"]
[Thu Jul 30 15:04:27.941556 2026] [security2:error] [pid 89520:tid 89709] [client 66.249.66.76:64399] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.mogomogolessons4.com"] [uri "/robots.txt"] [unique_id "amuuSy0W4wRrtnDoPagEMgAAAb0"]
[Thu Jul 30 15:04:28.135296 2026] [security2:error] [pid 89520:tid 89698] [client 147.90.227.68:35297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/newsite/xmlrpc.php"] [unique_id "amuuTC0W4wRrtnDoPagENAAAAbI"]
[Thu Jul 30 15:04:28.139054 2026] [security2:error] [pid 87988:tid 88149] [client 20.199.183.73:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "amuuTDipAwzptuCxBrhsJAAAASk"]
[Thu Jul 30 15:04:28.140723 2026] [security2:error] [pid 87988:tid 88225] [client 147.90.227.68:53932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/news/xmlrpc.php"] [unique_id "amuuTDipAwzptuCxBrhsJQAAAXU"]
[Thu Jul 30 15:04:28.140972 2026] [security2:error] [pid 89520:tid 89746] [client 147.90.227.68:40487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/dev/xmlrpc.php"] [unique_id "amuuTC0W4wRrtnDoPagENQAAAeI"]
[Thu Jul 30 15:04:28.143534 2026] [security2:error] [pid 89520:tid 89766] [client 147.90.227.68:26358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp/xmlrpc.php"] [unique_id "amuuTC0W4wRrtnDoPagENgAAAfY"]
[Thu Jul 30 15:04:28.156608 2026] [security2:error] [pid 89520:tid 89732] [client 147.90.227.68:61620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/OLD//xmlrpc.php"] [unique_id "amuuTC0W4wRrtnDoPagENwAAAdQ"]
[Thu Jul 30 15:04:28.249827 2026] [security2:error] [pid 89520:tid 89777] [client 20.203.148.31:3762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amuuTC0W4wRrtnDoPagEPAAAAgE"]
[Thu Jul 30 15:04:28.328855 2026] [security2:error] [pid 89520:tid 89770] [client 147.90.227.68:47531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/cms/xmlrpc.php"] [unique_id "amuuTC0W4wRrtnDoPagEQgAAAfo"]
[Thu Jul 30 15:04:28.329110 2026] [security2:error] [pid 87988:tid 88140] [client 147.90.227.68:30273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amuuTDipAwzptuCxBrhsKgAAASA"]
[Thu Jul 30 15:04:28.508236 2026] [security2:error] [pid 89520:tid 89720] [client 147.90.227.68:24545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/blog/xmlrpc.php"] [unique_id "amuuTC0W4wRrtnDoPagEQwAAAcg"]
[Thu Jul 30 15:04:28.682993 2026] [core:notice] [pid 87988:tid 88229] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:28.683531 2026] [security2:error] [pid 89520:tid 89679] [client 20.52.54.143:9086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/plugin.php"] [unique_id "amuuTC0W4wRrtnDoPagERAAAAZ8"]
[Thu Jul 30 15:04:28.911745 2026] [security2:error] [pid 87988:tid 88173] [client 20.203.148.31:7304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amuuTDipAwzptuCxBrhsNQAAAUE"]
[Thu Jul 30 15:04:29.020816 2026] [security2:error] [pid 87988:tid 88227] [client 20.199.183.73:38746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/gifclass.php"] [unique_id "amuuTTipAwzptuCxBrhsPAAAAXc"]
[Thu Jul 30 15:04:29.240829 2026] [security2:error] [pid 87988:tid 88239] [client 135.119.63.61:59357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file.php"] [unique_id "amuuTTipAwzptuCxBrhsPQAAAYM"]
[Thu Jul 30 15:04:29.687998 2026] [security2:error] [pid 87988:tid 88187] [client 20.203.148.31:7869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amuuTTipAwzptuCxBrhsRQAAAU8"]
[Thu Jul 30 15:04:29.966693 2026] [security2:error] [pid 89520:tid 89774] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuTS0W4wRrtnDoPagESQAB_jo"]
[Thu Jul 30 15:04:30.086169 2026] [security2:error] [pid 87988:tid 88161] [client 20.199.183.73:24862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuuTjipAwzptuCxBrhsTwAAATU"]
[Thu Jul 30 15:04:30.257677 2026] [security2:error] [pid 89520:tid 89784] [client 20.203.148.31:3761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/cloud.php"] [unique_id "amuuTi0W4wRrtnDoPagEUgAAAgg"]
[Thu Jul 30 15:04:30.459601 2026] [security2:error] [pid 89520:tid 89716] [client 20.52.54.143:9167] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.laduchessecollections.com"] [uri "/1.php"] [unique_id "amuuTi0W4wRrtnDoPagEUwAAAcQ"]
[Thu Jul 30 15:04:30.459720 2026] [security2:error] [pid 89520:tid 89716] [client 20.52.54.143:9167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/1.php"] [unique_id "amuuTi0W4wRrtnDoPagEUwAAAcQ"]
[Thu Jul 30 15:04:30.988034 2026] [security2:error] [pid 89520:tid 89671] [client 88.218.45.218:36061] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "themushroom.online"] [uri "/"] [unique_id "amuuTi0W4wRrtnDoPagEVgAAAZc"]
[Thu Jul 30 15:04:31.092834 2026] [security2:error] [pid 89520:tid 89779] [client 20.203.148.31:7825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amuuTy0W4wRrtnDoPagEWQAAAgM"]
[Thu Jul 30 15:04:31.340089 2026] [security2:error] [pid 87988:tid 88138] [client 135.119.63.61:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file15.php"] [unique_id "amuuTzipAwzptuCxBrhsZQAAAR4"]
[Thu Jul 30 15:04:31.485771 2026] [security2:error] [pid 87988:tid 88126] [client 20.199.183.73:46969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/css/index.php"] [unique_id "amuuTzipAwzptuCxBrhsaAAAARI"]
[Thu Jul 30 15:04:31.533428 2026] [security2:error] [pid 87988:tid 88129] [client 147.90.227.68:31141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/news/xmlrpc.php"] [unique_id "amuuTzipAwzptuCxBrhsaQAAARU"]
[Thu Jul 30 15:04:31.533445 2026] [security2:error] [pid 87988:tid 88151] [client 147.90.227.68:42773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/newsite/xmlrpc.php"] [unique_id "amuuTzipAwzptuCxBrhsagAAASs"]
[Thu Jul 30 15:04:31.579334 2026] [security2:error] [pid 89520:tid 89678] [client 20.52.54.143:9190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/gg.php"] [unique_id "amuuTy0W4wRrtnDoPagEXgAAAZ4"]
[Thu Jul 30 15:04:31.626011 2026] [security2:error] [pid 87988:tid 88169] [client 147.90.227.68:39374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old-site/xmlrpc.php"] [unique_id "amuuTzipAwzptuCxBrhsawAAAT0"]
[Thu Jul 30 15:04:31.627219 2026] [security2:error] [pid 89520:tid 89719] [client 147.90.227.68:60046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/temp/xmlrpc.php"] [unique_id "amuuTy0W4wRrtnDoPagEXwAAAcc"]
[Thu Jul 30 15:04:31.672430 2026] [security2:error] [pid 89520:tid 89727] [client 147.90.227.68:24083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/blog/xmlrpc.php"] [unique_id "amuuTy0W4wRrtnDoPagEYAAAAc8"]
[Thu Jul 30 15:04:31.983090 2026] [security2:error] [pid 89520:tid 89783] [client 20.199.183.73:38766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-cron.php"] [unique_id "amuuTy0W4wRrtnDoPagEZQAAAgc"]
[Thu Jul 30 15:04:32.069860 2026] [core:notice] [pid 89520:tid 89663] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:32.195604 2026] [security2:error] [pid 87988:tid 88198] [client 147.90.227.68:60227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/staging/xmlrpc.php"] [unique_id "amuuUDipAwzptuCxBrhscAAAAVo"]
[Thu Jul 30 15:04:32.195604 2026] [security2:error] [pid 89520:tid 89688] [client 147.90.227.68:37169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/sandbox/xmlrpc.php"] [unique_id "amuuUC0W4wRrtnDoPagEaQAAAag"]
[Thu Jul 30 15:04:32.196258 2026] [security2:error] [pid 89520:tid 89765] [client 147.90.227.68:33353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old-site/xmlrpc.php"] [unique_id "amuuUC0W4wRrtnDoPagEagAAAfU"]
[Thu Jul 30 15:04:32.213449 2026] [security2:error] [pid 87988:tid 88157] [client 147.90.227.68:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/new/xmlrpc.php"] [unique_id "amuuUDipAwzptuCxBrhscQAAATE"]
[Thu Jul 30 15:04:32.213630 2026] [security2:error] [pid 89520:tid 89772] [client 147.90.227.68:63188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/temp/xmlrpc.php"] [unique_id "amuuUC0W4wRrtnDoPagEawAAAfw"]
[Thu Jul 30 15:04:32.266582 2026] [security2:error] [pid 87988:tid 88137] [client 20.203.148.31:7346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.worldofwhiskers.com"] [uri "/wp-content/updates.php"] [unique_id "amuuUDipAwzptuCxBrhscgAAAR0"]
[Thu Jul 30 15:04:32.397393 2026] [security2:error] [pid 89520:tid 89701] [client 20.52.54.143:8726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuuUC0W4wRrtnDoPagEbwAAAbU"]
[Thu Jul 30 15:04:32.556424 2026] [security2:error] [pid 87988:tid 88229] [client 147.90.227.68:25103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp/xmlrpc.php"] [unique_id "amuuUDipAwzptuCxBrhseQAAAXk"]
[Thu Jul 30 15:04:33.205546 2026] [security2:error] [pid 89520:tid 89732] [client 147.90.227.68:28869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/core/xmlrpc.php"] [unique_id "amuuUS0W4wRrtnDoPagEcwAAAdQ"]
[Thu Jul 30 15:04:33.206801 2026] [security2:error] [pid 89520:tid 89749] [client 147.90.227.68:48489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/prod/xmlrpc.php"] [unique_id "amuuUS0W4wRrtnDoPagEdAAAAeU"]
[Thu Jul 30 15:04:33.206897 2026] [security2:error] [pid 89520:tid 89777] [client 147.90.227.68:52819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp1/xmlrpc.php"] [unique_id "amuuUS0W4wRrtnDoPagEdQAAAgE"]
[Thu Jul 30 15:04:33.268739 2026] [security2:error] [pid 89520:tid 89735] [client 147.90.227.68:59085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old/xmlrpc.php"] [unique_id "amuuUS0W4wRrtnDoPagEdgAAAdc"]
[Thu Jul 30 15:04:33.284235 2026] [security2:error] [pid 89520:tid 89695] [client 147.90.227.68:23191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/testing/xmlrpc.php"] [unique_id "amuuUS0W4wRrtnDoPagEdwAAAa8"]
[Thu Jul 30 15:04:33.299041 2026] [security2:error] [pid 87988:tid 88235] [client 147.90.227.68:42641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/app/xmlrpc.php"] [unique_id "amuuUTipAwzptuCxBrhshAAAAX8"]
[Thu Jul 30 15:04:33.299340 2026] [security2:error] [pid 87988:tid 88130] [client 147.90.227.68:35519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/backup/xmlrpc.php"] [unique_id "amuuUTipAwzptuCxBrhshQAAARY"]
[Thu Jul 30 15:04:33.471223 2026] [security2:error] [pid 89520:tid 89776] [client 20.52.54.143:8718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp.php"] [unique_id "amuuUS0W4wRrtnDoPagEegAAAgA"]
[Thu Jul 30 15:04:33.569251 2026] [security2:error] [pid 87988:tid 88193] [client 135.119.63.61:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file17.php"] [unique_id "amuuUTipAwzptuCxBrhsiwAAAVU"]
[Thu Jul 30 15:04:33.590385 2026] [security2:error] [pid 87988:tid 88159] [client 147.90.227.68:51666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amuuUTipAwzptuCxBrhsjAAAATM"]
[Thu Jul 30 15:04:33.767732 2026] [security2:error] [pid 87988:tid 88186] [client 147.90.227.68:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/site/xmlrpc.php"] [unique_id "amuuUTipAwzptuCxBrhsjQAAAU4"]
[Thu Jul 30 15:04:33.859210 2026] [security2:error] [pid 89520:tid 89684] [client 20.199.183.73:36125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-block.php"] [unique_id "amuuUS0W4wRrtnDoPagEfAAAAaQ"]
[Thu Jul 30 15:04:33.861565 2026] [security2:error] [pid 89520:tid 89750] [client 147.90.227.68:48843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/main/xmlrpc.php"] [unique_id "amuuUS0W4wRrtnDoPagEfQAAAeY"]
[Thu Jul 30 15:04:33.918591 2026] [security2:error] [pid 87988:tid 88238] [client 147.90.227.68:63970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/news/xmlrpc.php"] [unique_id "amuuUTipAwzptuCxBrhskQAAAYI"]
[Thu Jul 30 15:04:33.954510 2026] [security2:error] [pid 89520:tid 89717] [client 147.90.227.68:45011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/blog/xmlrpc.php"] [unique_id "amuuUS0W4wRrtnDoPagEgQAAAcU"]
[Thu Jul 30 15:04:34.346341 2026] [security2:error] [pid 89520:tid 89665] [client 147.90.227.68:61714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/home/xmlrpc.php"] [unique_id "amuuUi0W4wRrtnDoPagEhAAAAZE"]
[Thu Jul 30 15:04:34.373209 2026] [security2:error] [pid 89520:tid 89668] [client 20.52.54.143:9154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuuUi0W4wRrtnDoPagEhgAAAZQ"]
[Thu Jul 30 15:04:34.433721 2026] [security2:error] [pid 87988:tid 88093] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuUjipAwzptuCxBrhsmQABaWg"]
[Thu Jul 30 15:04:34.433887 2026] [security2:error] [pid 87988:tid 88213] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuUjipAwzptuCxBrhsmQABaWg"]
[Thu Jul 30 15:04:34.508162 2026] [security2:error] [pid 87988:tid 88152] [client 135.119.63.61:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file2.php"] [unique_id "amuuUjipAwzptuCxBrhsmgAAASw"]
[Thu Jul 30 15:04:34.633181 2026] [security2:error] [pid 87988:tid 88209] [client 147.90.227.68:32504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wordpress/xmlrpc.php"] [unique_id "amuuUjipAwzptuCxBrhsnQAAAWU"]
[Thu Jul 30 15:04:34.633327 2026] [security2:error] [pid 89520:tid 89760] [client 147.90.227.68:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-content/xmlrpc.php"] [unique_id "amuuUi0W4wRrtnDoPagEiQAAAfA"]
[Thu Jul 30 15:04:34.653367 2026] [security2:error] [pid 87988:tid 88160] [client 147.90.227.68:37213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-old//xmlrpc.php"] [unique_id "amuuUjipAwzptuCxBrhsngAAATQ"]
[Thu Jul 30 15:04:34.654582 2026] [security2:error] [pid 89520:tid 89790] [client 147.90.227.68:34807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/dev/xmlrpc.php"] [unique_id "amuuUi0W4wRrtnDoPagEigAAAg4"]
[Thu Jul 30 15:04:34.955553 2026] [core:notice] [pid 89520:tid 89728] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:34.958309 2026] [security2:error] [pid 89520:tid 89728] [client 66.249.65.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/41/43"] [unique_id "amuuUi0W4wRrtnDoPagEjAAAAdA"]
[Thu Jul 30 15:04:35.059814 2026] [security2:error] [pid 89520:tid 89718] [client 147.90.227.68:31069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/OLD//xmlrpc.php"] [unique_id "amuuUy0W4wRrtnDoPagEkQAAAcY"]
[Thu Jul 30 15:04:35.092256 2026] [security2:error] [pid 89520:tid 89730] [client 147.90.227.68:35183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/cms/xmlrpc.php"] [unique_id "amuuUy0W4wRrtnDoPagEkgAAAdI"]
[Thu Jul 30 15:04:35.250133 2026] [security2:error] [pid 89520:tid 89779] [client 20.52.54.143:9178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/file.php"] [unique_id "amuuUy0W4wRrtnDoPagEkwAAAgM"]
[Thu Jul 30 15:04:35.532361 2026] [core:error] [pid 89520:tid 89616] [remote 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:35.532383 2026] [core:error] [pid 89520:tid 89616] [remote 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:35.735807 2026] [core:notice] [pid 89520:tid 89669] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:36.004911 2026] [security2:error] [pid 89520:tid 89700] [client 147.90.227.68:48246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagEtgAAAbQ"]
[Thu Jul 30 15:04:36.053417 2026] [security2:error] [pid 89520:tid 89680] [client 135.119.63.61:59388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file3.php"] [unique_id "amuuVC0W4wRrtnDoPagEtwAAAaA"]
[Thu Jul 30 15:04:36.057735 2026] [security2:error] [pid 89520:tid 89740] [client 20.52.54.143:8704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuuVC0W4wRrtnDoPagEuAAAAdw"]
[Thu Jul 30 15:04:36.143337 2026] [security2:error] [pid 89520:tid 89688] [client 147.90.227.68:42807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/core/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagEugAAAag"]
[Thu Jul 30 15:04:36.458445 2026] [security2:error] [pid 87988:tid 88188] [client 147.90.227.68:33267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amuuVDipAwzptuCxBrhssQAAAVA"]
[Thu Jul 30 15:04:36.571061 2026] [security2:error] [pid 89520:tid 89719] [client 147.90.227.68:57173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/web/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagEvwAAAcc"]
[Thu Jul 30 15:04:36.599719 2026] [security2:error] [pid 89520:tid 89723] [client 147.90.227.68:22923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/blog/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagEwAAAAcs"]
[Thu Jul 30 15:04:36.636509 2026] [security2:error] [pid 87988:tid 88225] [client 147.90.227.68:34665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/cms/xmlrpc.php"] [unique_id "amuuVDipAwzptuCxBrhstQAAAXU"]
[Thu Jul 30 15:04:36.791944 2026] [security2:error] [pid 89520:tid 89712] [client 147.90.227.68:22459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/main/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagEyQAAAcA"]
[Thu Jul 30 15:04:36.792327 2026] [security2:error] [pid 89520:tid 89770] [client 147.90.227.68:57095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/prod/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagEygAAAfo"]
[Thu Jul 30 15:04:36.802661 2026] [security2:error] [pid 89520:tid 89681] [client 147.90.227.68:48821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/news/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagEzAAAAaE"]
[Thu Jul 30 15:04:36.824670 2026] [security2:error] [pid 89520:tid 89768] [client 147.90.227.68:39287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/site/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagEzQAAAfg"]
[Thu Jul 30 15:04:36.970702 2026] [security2:error] [pid 89520:tid 89735] [client 147.90.227.68:57853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp1/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagEzwAAAdc"]
[Thu Jul 30 15:04:36.970865 2026] [security2:error] [pid 89520:tid 89763] [client 147.90.227.68:53911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/app/xmlrpc.php"] [unique_id "amuuVC0W4wRrtnDoPagE0AAAAfM"]
[Thu Jul 30 15:04:36.970898 2026] [security2:error] [pid 87988:tid 88140] [client 147.90.227.68:33347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/testing/xmlrpc.php"] [unique_id "amuuVDipAwzptuCxBrhsuAAAASA"]
[Thu Jul 30 15:04:36.971062 2026] [security2:error] [pid 89520:tid 89695] [client 20.52.54.143:9041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuuVC0W4wRrtnDoPagEzgAAAa8"]
[Thu Jul 30 15:04:37.171284 2026] [security2:error] [pid 87988:tid 88190] [client 147.90.227.68:36193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/cms/xmlrpc.php"] [unique_id "amuuVTipAwzptuCxBrhsvwAAAVI"]
[Thu Jul 30 15:04:37.181365 2026] [security2:error] [pid 89520:tid 89776] [client 147.90.227.68:54577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/sandbox/xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE1AAAAgA"]
[Thu Jul 30 15:04:37.252712 2026] [security2:error] [pid 89520:tid 89674] [client 147.90.227.68:32489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE1gAAAZo"]
[Thu Jul 30 15:04:37.368224 2026] [security2:error] [pid 89520:tid 89737] [client 135.119.63.61:7876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file32.php"] [unique_id "amuuVS0W4wRrtnDoPagE1wAAAdk"]
[Thu Jul 30 15:04:37.597114 2026] [security2:error] [pid 89520:tid 89788] [client 20.199.183.73:48047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/fonts/admin.php"] [unique_id "amuuVS0W4wRrtnDoPagE3wAAAgw"]
[Thu Jul 30 15:04:37.612168 2026] [security2:error] [pid 89520:tid 89708] [client 147.90.227.68:55438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/temp/xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE4AAAAbw"]
[Thu Jul 30 15:04:37.622906 2026] [core:notice] [pid 89520:tid 89684] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:37.637908 2026] [security2:error] [pid 89520:tid 89774] [client 147.90.227.68:43342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/new/xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE4gAAAf4"]
[Thu Jul 30 15:04:37.638028 2026] [security2:error] [pid 89520:tid 89769] [client 147.90.227.68:51117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/dev/xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE4wAAAfk"]
[Thu Jul 30 15:04:37.643837 2026] [security2:error] [pid 89520:tid 89759] [client 147.90.227.68:54583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-content/xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE5AAAAe8"]
[Thu Jul 30 15:04:37.643966 2026] [security2:error] [pid 87988:tid 88199] [client 147.90.227.68:54101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wordpress/xmlrpc.php"] [unique_id "amuuVTipAwzptuCxBrhsxQAAAVs"]
[Thu Jul 30 15:04:37.695238 2026] [security2:error] [pid 89520:tid 89668] [client 147.90.227.68:59953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/OLD//xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE6AAAAZQ"]
[Thu Jul 30 15:04:37.738090 2026] [security2:error] [pid 87988:tid 88125] [client 147.90.227.68:31319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/site/xmlrpc.php"] [unique_id "amuuVTipAwzptuCxBrhsxwAAARE"]
[Thu Jul 30 15:04:37.819451 2026] [security2:error] [pid 89520:tid 89672] [client 147.90.227.68:59021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/new/xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE6QAAAZg"]
[Thu Jul 30 15:04:37.819678 2026] [security2:error] [pid 89520:tid 89729] [client 147.90.227.68:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/dev/xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE6gAAAdE"]
[Thu Jul 30 15:04:37.825543 2026] [security2:error] [pid 87988:tid 88204] [client 147.90.227.68:57763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wordpress/xmlrpc.php"] [unique_id "amuuVTipAwzptuCxBrhsyAAAAWA"]
[Thu Jul 30 15:04:37.834486 2026] [security2:error] [pid 87988:tid 88180] [client 147.90.227.68:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-content/xmlrpc.php"] [unique_id "amuuVTipAwzptuCxBrhsyQAAAUg"]
[Thu Jul 30 15:04:37.949925 2026] [security2:error] [pid 89520:tid 89755] [client 147.90.227.68:22282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old-site/xmlrpc.php"] [unique_id "amuuVS0W4wRrtnDoPagE6wAAAes"]
[Thu Jul 30 15:04:37.974163 2026] [security2:error] [pid 87988:tid 88185] [client 147.90.227.68:28052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp/xmlrpc.php"] [unique_id "amuuVTipAwzptuCxBrhsygAAAU0"]
[Thu Jul 30 15:04:38.016267 2026] [security2:error] [pid 89520:tid 89733] [client 147.90.227.68:22840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-old//xmlrpc.php"] [unique_id "amuuVi0W4wRrtnDoPagE7AAAAdU"]
[Thu Jul 30 15:04:38.016693 2026] [security2:error] [pid 89520:tid 89725] [client 147.90.227.68:20352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/blog/xmlrpc.php"] [unique_id "amuuVi0W4wRrtnDoPagE7QAAAc0"]
[Thu Jul 30 15:04:38.018421 2026] [security2:error] [pid 89520:tid 89748] [client 147.90.227.68:38992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/newsite/xmlrpc.php"] [unique_id "amuuVi0W4wRrtnDoPagE7gAAAeQ"]
[Thu Jul 30 15:04:38.480387 2026] [security2:error] [pid 89520:tid 89773] [client 147.90.227.68:46849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old/xmlrpc.php"] [unique_id "amuuVi0W4wRrtnDoPagE-gAAAf0"]
[Thu Jul 30 15:04:38.594152 2026] [security2:error] [pid 87988:tid 88236] [client 147.90.227.68:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/web/xmlrpc.php"] [unique_id "amuuVjipAwzptuCxBrhs0wAAAYA"]
[Thu Jul 30 15:04:38.728007 2026] [security2:error] [pid 89520:tid 89767] [client 147.90.227.68:37945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/testing/xmlrpc.php"] [unique_id "amuuVi0W4wRrtnDoPagE_gAAAfc"]
[Thu Jul 30 15:04:38.791823 2026] [security2:error] [pid 87988:tid 88167] [client 147.90.227.68:48758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp1/xmlrpc.php"] [unique_id "amuuVjipAwzptuCxBrhs2AAAATs"]
[Thu Jul 30 15:04:38.855119 2026] [security2:error] [pid 89520:tid 89775] [client 147.90.227.68:49003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/cms/xmlrpc.php"] [unique_id "amuuVi0W4wRrtnDoPagFAwAAAf8"]
[Thu Jul 30 15:04:38.986465 2026] [security2:error] [pid 89520:tid 89783] [client 147.90.227.68:31979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/backup/xmlrpc.php"] [unique_id "amuuVi0W4wRrtnDoPagFBAAAAgc"]
[Thu Jul 30 15:04:39.205431 2026] [security2:error] [pid 87988:tid 88194] [client 147.90.227.68:47927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/home/xmlrpc.php"] [unique_id "amuuVzipAwzptuCxBrhs3QAAAVY"]
[Thu Jul 30 15:04:39.241708 2026] [security2:error] [pid 89520:tid 89701] [client 147.90.227.68:37945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/staging/xmlrpc.php"] [unique_id "amuuVy0W4wRrtnDoPagFDAAAAbU"]
[Thu Jul 30 15:04:39.334150 2026] [security2:error] [pid 89520:tid 89683] [client 147.90.227.68:47739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/app/xmlrpc.php"] [unique_id "amuuVy0W4wRrtnDoPagFEAAAAaM"]
[Thu Jul 30 15:04:39.464473 2026] [core:notice] [pid 87988:tid 88015] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:39.653007 2026] [security2:error] [pid 89520:tid 89709] [client 147.90.227.68:26324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/site/xmlrpc.php"] [unique_id "amuuVy0W4wRrtnDoPagFGAAAAb0"]
[Thu Jul 30 15:04:40.094956 2026] [security2:error] [pid 89520:tid 89679] [client 147.90.227.68:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/newsite/xmlrpc.php"] [unique_id "amuuWC0W4wRrtnDoPagFLwAAAZ8"]
[Thu Jul 30 15:04:40.095554 2026] [security2:error] [pid 89520:tid 89757] [client 147.90.227.68:27927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/sandbox/xmlrpc.php"] [unique_id "amuuWC0W4wRrtnDoPagFMAAAAe0"]
[Thu Jul 30 15:04:40.121432 2026] [security2:error] [pid 87988:tid 88191] [client 20.52.54.143:9192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/index/function.php"] [unique_id "amuuWDipAwzptuCxBrhs8QAAAVM"]
[Thu Jul 30 15:04:40.179233 2026] [security2:error] [pid 87988:tid 88161] [client 147.90.227.68:48399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-old//xmlrpc.php"] [unique_id "amuuWDipAwzptuCxBrhs8wAAATU"]
[Thu Jul 30 15:04:40.181836 2026] [security2:error] [pid 89520:tid 89786] [client 147.90.227.68:28339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/blog/xmlrpc.php"] [unique_id "amuuWC0W4wRrtnDoPagFMgAAAgo"]
[Thu Jul 30 15:04:40.186612 2026] [security2:error] [pid 89520:tid 89747] [client 147.90.227.68:63679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/temp/xmlrpc.php"] [unique_id "amuuWC0W4wRrtnDoPagFMwAAAeM"]
[Thu Jul 30 15:04:40.302400 2026] [security2:error] [pid 89520:tid 89750] [client 135.119.63.61:7928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file4.php"] [unique_id "amuuWC0W4wRrtnDoPagFOQAAAeY"]
[Thu Jul 30 15:04:40.554172 2026] [security2:error] [pid 89520:tid 89762] [client 20.199.183.73:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/classwithtostring.php"] [unique_id "amuuWC0W4wRrtnDoPagFPwAAAfI"]
[Thu Jul 30 15:04:40.786248 2026] [security2:error] [pid 89520:tid 89555] [remote 103.75.185.95:58134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emj.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuuWC0W4wRrtnDoPagFQQAB9Bk"]
[Thu Jul 30 15:04:40.992523 2026] [security2:error] [pid 89520:tid 89753] [client 147.90.227.68:32493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/news/xmlrpc.php"] [unique_id "amuuWC0W4wRrtnDoPagFSgAAAek"]
[Thu Jul 30 15:04:41.043091 2026] [security2:error] [pid 87988:tid 88140] [client 20.199.183.73:13322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/test1.php"] [unique_id "amuuWTipAwzptuCxBrhtBAAAASA"]
[Thu Jul 30 15:04:41.231190 2026] [security2:error] [pid 87988:tid 88133] [client 135.119.63.61:8690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file5.php"] [unique_id "amuuWTipAwzptuCxBrhtBwAAARk"]
[Thu Jul 30 15:04:41.249167 2026] [security2:error] [pid 87988:tid 88149] [client 147.90.227.68:20813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/main/xmlrpc.php"] [unique_id "amuuWTipAwzptuCxBrhtCAAAASk"]
[Thu Jul 30 15:04:41.271715 2026] [security2:error] [pid 89520:tid 89768] [client 20.52.54.143:9157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/aaa.php"] [unique_id "amuuWS0W4wRrtnDoPagFUgAAAfg"]
[Thu Jul 30 15:04:41.309123 2026] [security2:error] [pid 89520:tid 89720] [client 147.90.227.68:42672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wordpress/xmlrpc.php"] [unique_id "amuuWS0W4wRrtnDoPagFUwAAAcg"]
[Thu Jul 30 15:04:41.309597 2026] [security2:error] [pid 87988:tid 88217] [client 147.90.227.68:44392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-content/xmlrpc.php"] [unique_id "amuuWTipAwzptuCxBrhtCQAAAW0"]
[Thu Jul 30 15:04:41.739586 2026] [security2:error] [pid 89520:tid 89780] [client 147.90.227.68:22670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/prod/xmlrpc.php"] [unique_id "amuuWS0W4wRrtnDoPagFWAAAAgQ"]
[Thu Jul 30 15:04:41.739596 2026] [security2:error] [pid 89520:tid 89675] [client 147.90.227.68:28506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/OLD//xmlrpc.php"] [unique_id "amuuWS0W4wRrtnDoPagFVwAAAZs"]
[Thu Jul 30 15:04:41.851540 2026] [security2:error] [pid 89520:tid 89695] [client 147.90.227.68:46871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amuuWS0W4wRrtnDoPagFWwAAAa8"]
[Thu Jul 30 15:04:41.866827 2026] [security2:error] [pid 89520:tid 89739] [client 147.90.227.68:42689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/staging/xmlrpc.php"] [unique_id "amuuWS0W4wRrtnDoPagFXgAAAds"]
[Thu Jul 30 15:04:41.887088 2026] [security2:error] [pid 89520:tid 89737] [client 147.90.227.68:27209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/new/xmlrpc.php"] [unique_id "amuuWS0W4wRrtnDoPagFXwAAAdk"]
[Thu Jul 30 15:04:42.110483 2026] [security2:error] [pid 89520:tid 89696] [client 147.90.227.68:25745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/core/xmlrpc.php"] [unique_id "amuuWi0W4wRrtnDoPagFYgAAAbA"]
[Thu Jul 30 15:04:42.113195 2026] [security2:error] [pid 87988:tid 88180] [client 135.119.63.61:7880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file6.php"] [unique_id "amuuWjipAwzptuCxBrhtEwAAAUg"]
[Thu Jul 30 15:04:42.306759 2026] [security2:error] [pid 87988:tid 88185] [client 147.90.227.68:57544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/testing/xmlrpc.php"] [unique_id "amuuWjipAwzptuCxBrhtFgAAAU0"]
[Thu Jul 30 15:04:42.307872 2026] [security2:error] [pid 87988:tid 88132] [client 147.90.227.68:50292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/cms/xmlrpc.php"] [unique_id "amuuWjipAwzptuCxBrhtFwAAARg"]
[Thu Jul 30 15:04:42.458070 2026] [security2:error] [pid 89520:tid 89732] [client 147.90.227.68:42588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/backup/xmlrpc.php"] [unique_id "amuuWi0W4wRrtnDoPagFawAAAdQ"]
[Thu Jul 30 15:04:42.501485 2026] [security2:error] [pid 89520:tid 89778] [client 147.90.227.68:60149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp/xmlrpc.php"] [unique_id "amuuWi0W4wRrtnDoPagFbAAAAgI"]
[Thu Jul 30 15:04:42.575799 2026] [security2:error] [pid 89520:tid 89685] [client 147.90.227.68:59251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/dev/xmlrpc.php"] [unique_id "amuuWi0W4wRrtnDoPagFbQAAAaU"]
[Thu Jul 30 15:04:42.611229 2026] [security2:error] [pid 89520:tid 89769] [client 147.90.227.68:21781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/newsite/xmlrpc.php"] [unique_id "amuuWi0W4wRrtnDoPagFbgAAAfk"]
[Thu Jul 30 15:04:42.611363 2026] [security2:error] [pid 87988:tid 88201] [client 147.90.227.68:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-old//xmlrpc.php"] [unique_id "amuuWjipAwzptuCxBrhtHQAAAV0"]
[Thu Jul 30 15:04:42.612293 2026] [security2:error] [pid 87988:tid 88231] [client 147.90.227.68:28325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/sandbox/xmlrpc.php"] [unique_id "amuuWjipAwzptuCxBrhtHgAAAXs"]
[Thu Jul 30 15:04:42.626648 2026] [security2:error] [pid 87988:tid 88177] [client 147.90.227.68:37027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/temp/xmlrpc.php"] [unique_id "amuuWjipAwzptuCxBrhtHwAAAUU"]
[Thu Jul 30 15:04:42.646782 2026] [security2:error] [pid 89520:tid 89786] [client 172.237.109.114:11885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuWi0W4wRrtnDoPagFYwAAAgo"]
[Thu Jul 30 15:04:42.896437 2026] [security2:error] [pid 89520:tid 89682] [client 20.199.183.73:46201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/images/index.php"] [unique_id "amuuWi0W4wRrtnDoPagFdgAAAaI"]
[Thu Jul 30 15:04:42.986774 2026] [security2:error] [pid 89520:tid 89672] [client 147.90.227.68:65031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old-site/xmlrpc.php"] [unique_id "amuuWi0W4wRrtnDoPagFeQAAAZg"]
[Thu Jul 30 15:04:43.207050 2026] [security2:error] [pid 87988:tid 88153] [client 147.90.227.68:42303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp1/xmlrpc.php"] [unique_id "amuuWzipAwzptuCxBrhtKwAAAS0"]
[Thu Jul 30 15:04:43.345058 2026] [security2:error] [pid 87988:tid 88127] [client 147.90.227.68:36370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/app/xmlrpc.php"] [unique_id "amuuWzipAwzptuCxBrhtLgAAARM"]
[Thu Jul 30 15:04:43.453547 2026] [security2:error] [pid 87988:tid 88241] [client 147.90.227.68:45791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/staging/xmlrpc.php"] [unique_id "amuuWzipAwzptuCxBrhtMQAAAYU"]
[Thu Jul 30 15:04:43.487615 2026] [security2:error] [pid 89520:tid 89742] [client 147.90.227.68:41241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/dev/xmlrpc.php"] [unique_id "amuuWy0W4wRrtnDoPagFiQAAAd4"]
[Thu Jul 30 15:04:43.556749 2026] [security2:error] [pid 87988:tid 88216] [client 147.90.227.68:26572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/OLD//xmlrpc.php"] [unique_id "amuuWzipAwzptuCxBrhtNAAAAWw"]
[Thu Jul 30 15:04:43.598349 2026] [security2:error] [pid 89520:tid 89740] [client 147.90.227.68:55149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/site/xmlrpc.php"] [unique_id "amuuWy0W4wRrtnDoPagFjAAAAdw"]
[Thu Jul 30 15:04:43.699916 2026] [security2:error] [pid 87988:tid 88194] [client 147.90.227.68:58121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp1/xmlrpc.php"] [unique_id "amuuWzipAwzptuCxBrhtNQAAAVY"]
[Thu Jul 30 15:04:43.700163 2026] [security2:error] [pid 87988:tid 88239] [client 147.90.227.68:45397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/news/xmlrpc.php"] [unique_id "amuuWzipAwzptuCxBrhtNgAAAYM"]
[Thu Jul 30 15:04:43.705611 2026] [core:notice] [pid 87988:tid 88044] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:43.709292 2026] [security2:error] [pid 87988:tid 88228] [client 66.249.74.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/22/24"] [unique_id "amuuWzipAwzptuCxBrhtMAABeDc"]
[Thu Jul 30 15:04:43.974480 2026] [security2:error] [pid 89520:tid 89735] [client 147.90.227.68:38364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/new/xmlrpc.php"] [unique_id "amuuWy0W4wRrtnDoPagFjwAAAdc"]
[Thu Jul 30 15:04:44.018456 2026] [security2:error] [pid 87988:tid 88210] [client 147.90.227.68:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/prod/xmlrpc.php"] [unique_id "amuuXDipAwzptuCxBrhtOwAAAWY"]
[Thu Jul 30 15:04:44.052794 2026] [security2:error] [pid 87988:tid 88189] [client 147.90.227.68:47083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old/xmlrpc.php"] [unique_id "amuuXDipAwzptuCxBrhtPAAAAVE"]
[Thu Jul 30 15:04:44.205425 2026] [security2:error] [pid 87988:tid 88171] [client 20.199.183.73:44975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/asd.php"] [unique_id "amuuXDipAwzptuCxBrhtQAAAAT8"]
[Thu Jul 30 15:04:44.211294 2026] [security2:error] [pid 87988:tid 88160] [client 147.90.227.68:44717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/newsite/xmlrpc.php"] [unique_id "amuuXDipAwzptuCxBrhtQQAAATQ"]
[Thu Jul 30 15:04:44.252080 2026] [security2:error] [pid 87988:tid 88183] [client 147.90.227.68:32975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/core/xmlrpc.php"] [unique_id "amuuXDipAwzptuCxBrhtQwAAAUs"]
[Thu Jul 30 15:04:44.334198 2026] [security2:error] [pid 89520:tid 89696] [client 147.90.227.68:61013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/backup/xmlrpc.php"] [unique_id "amuuXC0W4wRrtnDoPagFlAAAAbA"]
[Thu Jul 30 15:04:44.481236 2026] [security2:error] [pid 89520:tid 89695] [client 147.90.227.68:35358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wordpress/xmlrpc.php"] [unique_id "amuuXC0W4wRrtnDoPagFmQAAAa8"]
[Thu Jul 30 15:04:44.585852 2026] [security2:error] [pid 87988:tid 88086] [remote 5.161.62.209:17526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dhowcruisedinner.com.khw.nyx.temporary.site"] [uri "/.env"] [unique_id "amuuXDipAwzptuCxBrhtSgABPWE"]
[Thu Jul 30 15:04:44.604509 2026] [security2:error] [pid 89520:tid 89567] [remote 5.161.62.209:17516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dhowcruisedinner.com"] [uri "/.env"] [unique_id "amuuXC0W4wRrtnDoPagFnAAB1SU"]
[Thu Jul 30 15:04:44.762047 2026] [security2:error] [pid 89520:tid 89674] [client 147.90.227.68:20315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amuuXC0W4wRrtnDoPagFoQAAAZo"]
[Thu Jul 30 15:04:44.762318 2026] [security2:error] [pid 89520:tid 89737] [client 147.90.227.68:64923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-content/xmlrpc.php"] [unique_id "amuuXC0W4wRrtnDoPagFogAAAdk"]
[Thu Jul 30 15:04:44.800547 2026] [security2:error] [pid 89520:tid 89667] [client 135.119.63.61:8687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file7.php"] [unique_id "amuuXC0W4wRrtnDoPagFowAAAZM"]
[Thu Jul 30 15:04:44.911995 2026] [core:notice] [pid 89520:tid 89761] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:44.952280 2026] [security2:error] [pid 89520:tid 89790] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuXC0W4wRrtnDoPagFmAAAAg4"]
[Thu Jul 30 15:04:44.972225 2026] [security2:error] [pid 89520:tid 89729] [client 147.90.227.68:56137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/temp/xmlrpc.php"] [unique_id "amuuXC0W4wRrtnDoPagFpQAAAdE"]
[Thu Jul 30 15:04:45.019714 2026] [security2:error] [pid 89520:tid 89571] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuXS0W4wRrtnDoPagFpwABxik"]
[Thu Jul 30 15:04:45.019848 2026] [security2:error] [pid 89520:tid 89718] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuXS0W4wRrtnDoPagFpwABxik"]
[Thu Jul 30 15:04:45.083079 2026] [core:error] [pid 89520:tid 89569] [remote 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:45.083100 2026] [core:error] [pid 89520:tid 89569] [remote 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:45.283128 2026] [security2:error] [pid 89520:tid 89721] [client 147.90.227.68:54569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-old//xmlrpc.php"] [unique_id "amuuXS0W4wRrtnDoPagFqwAAAck"]
[Thu Jul 30 15:04:45.703878 2026] [security2:error] [pid 89520:tid 89772] [client 147.90.227.68:22006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old/xmlrpc.php"] [unique_id "amuuXS0W4wRrtnDoPagFswAAAfw"]
[Thu Jul 30 15:04:45.807905 2026] [security2:error] [pid 89520:tid 89726] [client 147.90.227.68:39086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/web/xmlrpc.php"] [unique_id "amuuXS0W4wRrtnDoPagFtgAAAc4"]
[Thu Jul 30 15:04:46.153464 2026] [security2:error] [pid 89520:tid 89701] [client 20.52.54.143:9049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/getid3-core.php"] [unique_id "amuuXi0W4wRrtnDoPagFugAAAbU"]
[Thu Jul 30 15:04:46.335070 2026] [security2:error] [pid 87988:tid 88157] [client 20.199.183.73:33070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/customize/index.php"] [unique_id "amuuXjipAwzptuCxBrhtYAAAATE"]
[Thu Jul 30 15:04:46.515526 2026] [security2:error] [pid 89520:tid 89709] [client 147.90.227.68:28780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/staging/xmlrpc.php"] [unique_id "amuuXi0W4wRrtnDoPagFuwAAAb0"]
[Thu Jul 30 15:04:46.515567 2026] [security2:error] [pid 89520:tid 89720] [client 147.90.227.68:62120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/home/xmlrpc.php"] [unique_id "amuuXi0W4wRrtnDoPagFvAAAAcg"]
[Thu Jul 30 15:04:46.849911 2026] [security2:error] [pid 89520:tid 89753] [client 135.119.63.61:8658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file8.php"] [unique_id "amuuXi0W4wRrtnDoPagFvQAAAek"]
[Thu Jul 30 15:04:47.130001 2026] [security2:error] [pid 87988:tid 88147] [client 20.52.54.143:8736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/adminer.php"] [unique_id "amuuXzipAwzptuCxBrhtbgAAASc"]
[Thu Jul 30 15:04:47.790831 2026] [security2:error] [pid 89520:tid 89745] [client 147.90.227.68:50851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/OLD//xmlrpc.php"] [unique_id "amuuXy0W4wRrtnDoPagFwwAAAeE"]
[Thu Jul 30 15:04:47.791845 2026] [security2:error] [pid 87988:tid 88203] [client 147.90.227.68:20528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/sandbox/xmlrpc.php"] [unique_id "amuuXzipAwzptuCxBrhteQAAAV8"]
[Thu Jul 30 15:04:47.856189 2026] [security2:error] [pid 89520:tid 89694] [client 147.90.227.68:20450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/prod/xmlrpc.php"] [unique_id "amuuXy0W4wRrtnDoPagFxAAAAa4"]
[Thu Jul 30 15:04:47.868949 2026] [security2:error] [pid 89520:tid 89680] [client 147.90.227.68:56503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/app/xmlrpc.php"] [unique_id "amuuXy0W4wRrtnDoPagFxQAAAaA"]
[Thu Jul 30 15:04:47.921226 2026] [security2:error] [pid 89520:tid 89729] [client 147.90.227.68:42353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/main/xmlrpc.php"] [unique_id "amuuXy0W4wRrtnDoPagFxgAAAdE"]
[Thu Jul 30 15:04:47.986591 2026] [core:notice] [pid 87988:tid 87997] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:48.101951 2026] [security2:error] [pid 87988:tid 88185] [client 147.90.227.68:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old/xmlrpc.php"] [unique_id "amuuYDipAwzptuCxBrhtfQAAAU0"]
[Thu Jul 30 15:04:48.213338 2026] [security2:error] [pid 89520:tid 89704] [client 147.90.227.68:44876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/core/xmlrpc.php"] [unique_id "amuuYC0W4wRrtnDoPagFywAAAbg"]
[Thu Jul 30 15:04:48.261260 2026] [security2:error] [pid 87988:tid 88180] [client 147.90.227.68:46662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/testing/xmlrpc.php"] [unique_id "amuuYDipAwzptuCxBrhtgQAAAUg"]
[Thu Jul 30 15:04:48.348295 2026] [security2:error] [pid 89520:tid 89667] [client 147.90.227.68:38055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/backup/xmlrpc.php"] [unique_id "amuuYC0W4wRrtnDoPagFzgAAAZM"]
[Thu Jul 30 15:04:48.389080 2026] [security2:error] [pid 87988:tid 88190] [client 147.90.227.68:58465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old-site/xmlrpc.php"] [unique_id "amuuYDipAwzptuCxBrhtggAAAVI"]
[Thu Jul 30 15:04:48.511336 2026] [security2:error] [pid 89520:tid 89773] [client 172.237.109.114:35433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuYC0W4wRrtnDoPagFxwAAAf0"]
[Thu Jul 30 15:04:48.632759 2026] [security2:error] [pid 89520:tid 89666] [client 20.199.183.73:36506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuuYC0W4wRrtnDoPagF0QAAAZI"]
[Thu Jul 30 15:04:48.751939 2026] [security2:error] [pid 87988:tid 88171] [client 135.119.63.61:57411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file9.php"] [unique_id "amuuYDipAwzptuCxBrhthwAAAT8"]
[Thu Jul 30 15:04:48.977771 2026] [security2:error] [pid 89520:tid 89780] [client 85.204.70.116:50756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "siatfc.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuuYC0W4wRrtnDoPagF1QAAAgQ"]
[Thu Jul 30 15:04:49.494031 2026] [security2:error] [pid 89520:tid 89768] [client 85.204.70.116:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siatfc.com"] [uri "/xmlrpc.php"] [unique_id "amuuYS0W4wRrtnDoPagF2QAAAfg"]
[Thu Jul 30 15:04:49.503510 2026] [security2:error] [pid 89520:tid 89783] [client 20.52.54.143:9182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuuYS0W4wRrtnDoPagF2gAAAgc"]
[Thu Jul 30 15:04:49.635384 2026] [security2:error] [pid 89520:tid 89776] [client 147.90.227.68:42734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/old-site/xmlrpc.php"] [unique_id "amuuYS0W4wRrtnDoPagF3AAAAgA"]
[Thu Jul 30 15:04:49.635513 2026] [security2:error] [pid 89520:tid 89691] [client 147.90.227.68:45423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/main/xmlrpc.php"] [unique_id "amuuYS0W4wRrtnDoPagF3QAAAas"]
[Thu Jul 30 15:04:50.045008 2026] [security2:error] [pid 89520:tid 89670] [client 147.90.227.68:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/web/xmlrpc.php"] [unique_id "amuuYi0W4wRrtnDoPagF6wAAAZY"]
[Thu Jul 30 15:04:50.227427 2026] [security2:error] [pid 87988:tid 88195] [client 147.90.227.68:33554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/web/xmlrpc.php"] [unique_id "amuuYjipAwzptuCxBrhtngAAAVc"]
[Thu Jul 30 15:04:50.408053 2026] [security2:error] [pid 89520:tid 89729] [client 147.90.227.68:26021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/home/xmlrpc.php"] [unique_id "amuuYi0W4wRrtnDoPagF8QAAAdE"]
[Thu Jul 30 15:04:50.440371 2026] [security2:error] [pid 89520:tid 89722] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuYS0W4wRrtnDoPagF5wAAAco"]
[Thu Jul 30 15:04:50.458682 2026] [core:notice] [pid 87988:tid 88112] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:50.476947 2026] [security2:error] [pid 89520:tid 89685] [client 172.237.109.114:65199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuYS0W4wRrtnDoPagF6gAAAaU"]
[Thu Jul 30 15:04:50.527255 2026] [security2:error] [pid 87988:tid 88238] [client 135.119.63.61:8668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file_uploadadmin.php"] [unique_id "amuuYjipAwzptuCxBrhtogAAAYI"]
[Thu Jul 30 15:04:50.539216 2026] [security2:error] [pid 89520:tid 89781] [client 20.199.183.73:33071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/atomlib.php"] [unique_id "amuuYi0W4wRrtnDoPagF9AAAAgU"]
[Thu Jul 30 15:04:50.731471 2026] [security2:error] [pid 89520:tid 89764] [client 74.7.241.134:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.mza.djb.temporary.site"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "amuuYi0W4wRrtnDoPagF9wAAAfQ"]
[Thu Jul 30 15:04:50.732131 2026] [security2:error] [pid 87988:tid 88236] [client 74.7.241.134:36300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.mza.djb.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuuYjipAwzptuCxBrhtpAABgFk"]
[Thu Jul 30 15:04:50.993323 2026] [security2:error] [pid 89520:tid 89743] [client 147.90.227.68:65147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.227.90.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pkf.jo"] [uri "/home/xmlrpc.php"] [unique_id "amuuYi0W4wRrtnDoPagF-wAAAd8"]
[Thu Jul 30 15:04:51.559568 2026] [security2:error] [pid 89520:tid 89788] [client 20.199.183.73:47233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuuYy0W4wRrtnDoPagGBwAAAgw"]
[Thu Jul 30 15:04:51.586380 2026] [security2:error] [pid 89520:tid 89675] [client 185.191.171.2:11138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/09/anitta-deixa-conselho-de-administracao-do-nubank/"] [unique_id "amuuYy0W4wRrtnDoPagGCgAAAZs"]
[Thu Jul 30 15:04:51.586506 2026] [security2:error] [pid 89520:tid 89675] [client 185.191.171.2:11138] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/09/anitta-deixa-conselho-de-administracao-do-nubank/"] [unique_id "amuuYy0W4wRrtnDoPagGCgAAAZs"]
[Thu Jul 30 15:04:51.690585 2026] [security2:error] [pid 89520:tid 89775] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuYy0W4wRrtnDoPagF_AAB_zc"]
[Thu Jul 30 15:04:51.958337 2026] [security2:error] [pid 89520:tid 89691] [client 20.52.54.143:8719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/alfa.php"] [unique_id "amuuYy0W4wRrtnDoPagGFAAAAas"]
[Thu Jul 30 15:04:52.146405 2026] [security2:error] [pid 89520:tid 89719] [client 135.119.63.61:8502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file_uploadalfa.php"] [unique_id "amuuZC0W4wRrtnDoPagGFgAAAcc"]
[Thu Jul 30 15:04:52.700062 2026] [security2:error] [pid 89520:tid 89696] [client 85.204.70.116:50786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siatfc.com"] [uri "/xmlrpc.php"] [unique_id "amuuZC0W4wRrtnDoPagGGwAAAbA"]
[Thu Jul 30 15:04:52.700173 2026] [security2:error] [pid 89520:tid 89696] [client 85.204.70.116:50786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siatfc.com"] [uri "/xmlrpc.php"] [unique_id "amuuZC0W4wRrtnDoPagGGwAAAbA"]
[Thu Jul 30 15:04:52.968912 2026] [security2:error] [pid 89520:tid 89720] [client 135.119.63.61:8494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file_uploadbypass.php"] [unique_id "amuuZC0W4wRrtnDoPagGIAAAAcg"]
[Thu Jul 30 15:04:53.049751 2026] [security2:error] [pid 89520:tid 89753] [client 20.52.54.143:9082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuuZS0W4wRrtnDoPagGIQAAAek"]
[Thu Jul 30 15:04:53.438966 2026] [security2:error] [pid 89520:tid 89670] [client 74.7.230.19:56212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bitcoinfungibletoken.com"] [uri "/robots.txt"] [unique_id "amuuZS0W4wRrtnDoPagGJQABljo"]
[Thu Jul 30 15:04:54.025036 2026] [security2:error] [pid 89520:tid 89737] [client 20.52.54.143:9181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuuZi0W4wRrtnDoPagGMAAAAdk"]
[Thu Jul 30 15:04:54.167628 2026] [security2:error] [pid 89520:tid 89663] [client 20.199.183.73:37969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/inputs.php"] [unique_id "amuuZi0W4wRrtnDoPagGNAAAAY8"]
[Thu Jul 30 15:04:54.301830 2026] [core:notice] [pid 87988:tid 88000] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:54.312929 2026] [core:error] [pid 87988:tid 88000] [remote 66.249.65.201:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:54.313267 2026] [security2:error] [pid 87988:tid 88240] [client 66.249.65.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/36/38.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuuZjipAwzptuCxBrht0QABhAs"]
[Thu Jul 30 15:04:54.576755 2026] [core:notice] [pid 89520:tid 89764] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:54.588849 2026] [core:error] [pid 89520:tid 89764] [client 66.249.79.229:49906] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:04:54.589075 2026] [security2:error] [pid 89520:tid 89764] [client 66.249.79.229:49906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/8961/4184.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuuZi0W4wRrtnDoPagGNgAAAfQ"]
[Thu Jul 30 15:04:55.119772 2026] [security2:error] [pid 87988:tid 88234] [client 20.52.54.143:8708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuuZzipAwzptuCxBrht4gAAAX4"]
[Thu Jul 30 15:04:55.553914 2026] [core:notice] [pid 89520:tid 89710] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:55.594538 2026] [security2:error] [pid 87988:tid 88023] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuZzipAwzptuCxBrht6QABFyI"]
[Thu Jul 30 15:04:55.594704 2026] [security2:error] [pid 87988:tid 88131] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuZzipAwzptuCxBrht6QABFyI"]
[Thu Jul 30 15:04:55.983394 2026] [security2:error] [pid 89520:tid 89728] [client 135.119.63.61:56001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/file_uploadk.php"] [unique_id "amuuZy0W4wRrtnDoPagGRQAAAdA"]
[Thu Jul 30 15:04:55.989817 2026] [security2:error] [pid 89520:tid 89699] [client 20.199.183.73:20945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/index.php"] [unique_id "amuuZy0W4wRrtnDoPagGRgAAAbM"]
[Thu Jul 30 15:04:56.006948 2026] [core:notice] [pid 89520:tid 89591] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:56.050645 2026] [autoindex:error] [pid 89520:tid 89780] [client 139.28.219.70:36740] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:04:56.119701 2026] [security2:error] [pid 89520:tid 89717] [client 20.52.54.143:9028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/edit.php"] [unique_id "amuuaC0W4wRrtnDoPagGSwAAAcU"]
[Thu Jul 30 15:04:56.208921 2026] [autoindex:error] [pid 89520:tid 89774] [client 139.28.219.70:36740] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:04:56.338615 2026] [security2:error] [pid 89520:tid 89701] [client 139.28.219.70:36740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuuaC0W4wRrtnDoPagGTwAAAbU"]
[Thu Jul 30 15:04:56.635994 2026] [security2:error] [pid 89520:tid 89709] [client 139.28.219.70:36742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ampcloudku.com"] [uri "/xmlrpc.php"] [unique_id "amuuaC0W4wRrtnDoPagGWgAAAb0"]
[Thu Jul 30 15:04:56.896299 2026] [core:notice] [pid 89520:tid 89696] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:04:56.905505 2026] [autoindex:error] [pid 89520:tid 89720] [client 139.28.219.70:36752] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:04:57.034630 2026] [security2:error] [pid 89520:tid 89674] [client 139.28.219.70:36752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuuaS0W4wRrtnDoPagGYwAAAZo"]
[Thu Jul 30 15:04:57.141593 2026] [security2:error] [pid 89520:tid 89694] [client 20.52.54.143:9183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/file5.php"] [unique_id "amuuaS0W4wRrtnDoPagGZgAAAa4"]
[Thu Jul 30 15:04:57.145658 2026] [security2:error] [pid 89520:tid 89752] [client 20.199.183.73:14305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/network/index.php"] [unique_id "amuuaS0W4wRrtnDoPagGZwAAAeg"]
[Thu Jul 30 15:04:57.297455 2026] [security2:error] [pid 89520:tid 89781] [client 139.28.219.70:36756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuuaS0W4wRrtnDoPagGaQAAAgU"]
[Thu Jul 30 15:04:57.435726 2026] [security2:error] [pid 89520:tid 89732] [client 4.225.203.146:6705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wk/index.php"] [unique_id "amuuaS0W4wRrtnDoPagGaAAAAdQ"]
[Thu Jul 30 15:04:57.560011 2026] [security2:error] [pid 89520:tid 89727] [client 139.28.219.70:36762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuuaS0W4wRrtnDoPagGbAAAAc8"]
[Thu Jul 30 15:04:57.816559 2026] [security2:error] [pid 87988:tid 88232] [client 139.28.219.70:36768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuuaTipAwzptuCxBrhuAgAAAXw"]
[Thu Jul 30 15:04:58.091805 2026] [security2:error] [pid 87988:tid 88218] [client 139.28.219.70:36776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuuajipAwzptuCxBrhuBQAAAW4"]
[Thu Jul 30 15:04:58.189920 2026] [security2:error] [pid 89520:tid 89790] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuaS0W4wRrtnDoPagGbQACDkw"]
[Thu Jul 30 15:04:58.284571 2026] [security2:error] [pid 89520:tid 89667] [client 172.237.109.114:33315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuaS0W4wRrtnDoPagGcAAAAZM"]
[Thu Jul 30 15:04:58.366093 2026] [security2:error] [pid 89520:tid 89676] [client 139.28.219.70:36792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuuai0W4wRrtnDoPagGdQAAAZw"]
[Thu Jul 30 15:04:58.446661 2026] [security2:error] [pid 89520:tid 89762] [client 20.52.54.143:9046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/sf.php"] [unique_id "amuuai0W4wRrtnDoPagGdgAAAfI"]
[Thu Jul 30 15:04:58.641639 2026] [security2:error] [pid 89520:tid 89666] [client 139.28.219.70:36808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuuai0W4wRrtnDoPagGegAAAZI"]
[Thu Jul 30 15:04:58.687931 2026] [security2:error] [pid 89520:tid 89603] [remote 57.141.0.22:24324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/openaccesspolicy"] [unique_id "amuuai0W4wRrtnDoPagGfAABvkk"]
[Thu Jul 30 15:04:58.771764 2026] [security2:error] [pid 89520:tid 89765] [client 4.225.203.146:55503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/av.php"] [unique_id "amuuai0W4wRrtnDoPagGfQAAAfU"]
[Thu Jul 30 15:04:58.913821 2026] [security2:error] [pid 89520:tid 89693] [client 139.28.219.70:36810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuuai0W4wRrtnDoPagGfgAAAa0"]
[Thu Jul 30 15:04:59.169441 2026] [security2:error] [pid 87988:tid 88217] [client 139.28.219.70:36820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuuazipAwzptuCxBrhuFQAAAW0"]
[Thu Jul 30 15:04:59.437501 2026] [security2:error] [pid 87988:tid 88118] [client 139.28.219.70:36830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuuazipAwzptuCxBrhuGQAAAQo"]
[Thu Jul 30 15:04:59.442572 2026] [security2:error] [pid 89520:tid 89774] [client 4.225.203.146:6684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/mini.php"] [unique_id "amuuay0W4wRrtnDoPagGgQAAAf4"]
[Thu Jul 30 15:04:59.701346 2026] [security2:error] [pid 89520:tid 89701] [client 139.28.219.70:36834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuuay0W4wRrtnDoPagGhAAAAbU"]
[Thu Jul 30 15:04:59.801536 2026] [core:notice] [pid 89520:tid 89583] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:00.027930 2026] [security2:error] [pid 87988:tid 88154] [client 139.28.219.70:36840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuubDipAwzptuCxBrhuIgAAAS4"]
[Thu Jul 30 15:05:00.287687 2026] [security2:error] [pid 89520:tid 89763] [client 20.52.54.143:8762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wso.php"] [unique_id "amuubC0W4wRrtnDoPagGjAAAAfM"]
[Thu Jul 30 15:05:00.307634 2026] [security2:error] [pid 87988:tid 88193] [client 139.28.219.70:36848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ampcloudku.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuubDipAwzptuCxBrhuKAAAAVU"]
[Thu Jul 30 15:05:01.814521 2026] [security2:error] [pid 89520:tid 89743] [client 20.199.183.73:33062] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "progroup.jo"] [uri "/wp-content/1.php"] [unique_id "amuubS0W4wRrtnDoPagGngAAAd8"]
[Thu Jul 30 15:05:01.814647 2026] [security2:error] [pid 89520:tid 89743] [client 20.199.183.73:33062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/1.php"] [unique_id "amuubS0W4wRrtnDoPagGngAAAd8"]
[Thu Jul 30 15:05:01.979898 2026] [security2:error] [pid 89520:tid 89747] [client 4.225.203.146:29302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/aa.php"] [unique_id "amuubS0W4wRrtnDoPagGogAAAeM"]
[Thu Jul 30 15:05:02.551655 2026] [security2:error] [pid 87988:tid 88235] [client 176.88.166.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amuubTipAwzptuCxBrhuNgAAAX8"], referer: https://shop-mevius.com/product/peace/
[Thu Jul 30 15:05:03.131918 2026] [security2:error] [pid 87988:tid 88179] [client 20.52.54.143:9075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/ioxi-o.php"] [unique_id "amuubzipAwzptuCxBrhuTwAAAUc"]
[Thu Jul 30 15:05:04.009949 2026] [security2:error] [pid 89520:tid 89782] [client 4.225.203.146:38540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/w.php"] [unique_id "amuucC0W4wRrtnDoPagGrQAAAgY"]
[Thu Jul 30 15:05:04.650342 2026] [security2:error] [pid 87988:tid 88118] [client 20.52.54.143:9153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/file56.php"] [unique_id "amuucDipAwzptuCxBrhuZAAAAQo"]
[Thu Jul 30 15:05:05.175800 2026] [security2:error] [pid 87988:tid 88219] [client 20.52.54.143:9061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuucTipAwzptuCxBrhubAAAAW8"]
[Thu Jul 30 15:05:05.834326 2026] [security2:error] [pid 89520:tid 89675] [client 20.199.183.73:36436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/plugin.php"] [unique_id "amuucS0W4wRrtnDoPagGuwAAAZs"]
[Thu Jul 30 15:05:05.955705 2026] [security2:error] [pid 89520:tid 89738] [client 20.52.54.143:9056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuucS0W4wRrtnDoPagGvAAAAdo"]
[Thu Jul 30 15:05:06.217808 2026] [security2:error] [pid 87988:tid 88003] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuucjipAwzptuCxBrhudwABYQ4"]
[Thu Jul 30 15:05:06.217951 2026] [security2:error] [pid 87988:tid 88205] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuucjipAwzptuCxBrhudwABYQ4"]
[Thu Jul 30 15:05:06.676185 2026] [security2:error] [pid 87988:tid 88157] [client 20.52.54.143:9175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/edit.php"] [unique_id "amuucjipAwzptuCxBrhufgAAATE"]
[Thu Jul 30 15:05:07.251378 2026] [core:notice] [pid 89520:tid 89607] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:08.403269 2026] [security2:error] [pid 89520:tid 89725] [client 20.52.54.143:9047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/2.php"] [unique_id "amuudC0W4wRrtnDoPagG1wAAAc0"]
[Thu Jul 30 15:05:08.439545 2026] [security2:error] [pid 87988:tid 88159] [client 20.199.183.73:36421] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "progroup.jo"] [uri "/1.php"] [unique_id "amuudDipAwzptuCxBrhukgAAATM"]
[Thu Jul 30 15:05:08.439662 2026] [security2:error] [pid 87988:tid 88159] [client 20.199.183.73:36421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/1.php"] [unique_id "amuudDipAwzptuCxBrhukgAAATM"]
[Thu Jul 30 15:05:09.153547 2026] [security2:error] [pid 89520:tid 89704] [client 20.52.54.143:9171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuudS0W4wRrtnDoPagG3wAAAbg"]
[Thu Jul 30 15:05:09.329806 2026] [security2:error] [pid 87988:tid 88138] [client 20.199.183.73:36443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/gg.php"] [unique_id "amuudTipAwzptuCxBrhunwAAAR4"]
[Thu Jul 30 15:05:11.115989 2026] [security2:error] [pid 89520:tid 89699] [client 4.225.203.146:55956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/admin.php"] [unique_id "amuudy0W4wRrtnDoPagG8AAAAbM"]
[Thu Jul 30 15:05:11.441628 2026] [security2:error] [pid 89520:tid 89717] [client 20.199.183.73:13463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-content/languages/index.php"] [unique_id "amuudy0W4wRrtnDoPagG9wAAAcU"]
[Thu Jul 30 15:05:11.799444 2026] [core:notice] [pid 87988:tid 88231] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:11.801011 2026] [security2:error] [pid 87988:tid 88231] [client 5.102.173.71:44652] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/robots.txt"] [unique_id "amuudzipAwzptuCxBrhuvwAAAXs"]
[Thu Jul 30 15:05:12.154344 2026] [security2:error] [pid 89520:tid 89735] [client 20.199.183.73:35142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp.php"] [unique_id "amuueC0W4wRrtnDoPagG-wAAAdc"]
[Thu Jul 30 15:05:12.383914 2026] [core:notice] [pid 89520:tid 89776] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:12.608725 2026] [core:notice] [pid 87988:tid 88184] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:12.610884 2026] [security2:error] [pid 87988:tid 88184] [client 5.102.173.71:44652] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/2023/09/19/lula-discursa-na-assembleia-geral-da-onu-nesta-terca-feira-com-foco-em-amazonia-e-vaga-no-conselho-de-seguranca/"] [unique_id "amuueDipAwzptuCxBrhuxwAAAUw"]
[Thu Jul 30 15:05:13.098450 2026] [security2:error] [pid 89520:tid 89679] [client 20.199.183.73:41322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuueS0W4wRrtnDoPagHBwAAAZ8"]
[Thu Jul 30 15:05:13.299704 2026] [core:notice] [pid 87988:tid 88127] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:13.771570 2026] [security2:error] [pid 89520:tid 89738] [client 4.225.203.146:28614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-content/themes/admin.php"] [unique_id "amuueS0W4wRrtnDoPagHCgAAAdo"]
[Thu Jul 30 15:05:13.970546 2026] [security2:error] [pid 89520:tid 89767] [client 20.52.54.143:9187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/mah.php"] [unique_id "amuueS0W4wRrtnDoPagHEQAAAfc"]
[Thu Jul 30 15:05:14.497596 2026] [core:notice] [pid 87988:tid 88209] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:14.739478 2026] [security2:error] [pid 89520:tid 89781] [client 172.237.109.114:3280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuei0W4wRrtnDoPagHEgAAAgU"]
[Thu Jul 30 15:05:14.758211 2026] [core:notice] [pid 89520:tid 89621] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:14.809149 2026] [core:notice] [pid 89520:tid 89778] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:15.104812 2026] [security2:error] [pid 87988:tid 88128] [client 20.199.183.73:35269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/file.php"] [unique_id "amuuezipAwzptuCxBrhu4QAAARQ"]
[Thu Jul 30 15:05:15.149772 2026] [security2:error] [pid 87988:tid 88232] [client 213.152.161.20:36728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuuezipAwzptuCxBrhu4gAAAXw"]
[Thu Jul 30 15:05:15.149886 2026] [security2:error] [pid 87988:tid 88232] [client 213.152.161.20:36728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuuezipAwzptuCxBrhu4gAAAXw"]
[Thu Jul 30 15:05:15.558679 2026] [security2:error] [pid 89520:tid 89727] [client 4.225.203.146:34650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/m.php"] [unique_id "amuuey0W4wRrtnDoPagHIgAAAc8"]
[Thu Jul 30 15:05:15.865070 2026] [security2:error] [pid 87988:tid 88021] [remote 185.191.171.5:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "teknomalay.com"] [uri "/robots.txt"] [unique_id "amuuezipAwzptuCxBrhu7AABMyA"]
[Thu Jul 30 15:05:15.865234 2026] [security2:error] [pid 87988:tid 88159] [client 185.191.171.5:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teknomalay.com"] [uri "/robots.txt"] [unique_id "amuuezipAwzptuCxBrhu7AABMyA"]
[Thu Jul 30 15:05:16.386327 2026] [security2:error] [pid 89520:tid 89754] [client 20.199.183.73:39013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/user/index.php"] [unique_id "amuufC0W4wRrtnDoPagHJgAAAeo"]
[Thu Jul 30 15:05:16.640377 2026] [security2:error] [pid 87988:tid 88149] [client 4.225.203.146:36295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuufDipAwzptuCxBrhu9QAAASk"]
[Thu Jul 30 15:05:17.030714 2026] [security2:error] [pid 89520:tid 89775] [client 195.2.79.165:55630] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.79.165" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuufS0W4wRrtnDoPagHKAAAAf8"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 15:05:17.183452 2026] [security2:error] [pid 89520:tid 89622] [remote 57.141.0.49:38692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuufS0W4wRrtnDoPagHKQAB3lw"]
[Thu Jul 30 15:05:17.515369 2026] [core:notice] [pid 87988:tid 88052] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:17.867904 2026] [security2:error] [pid 89520:tid 89735] [client 20.118.34.237:17749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuufS0W4wRrtnDoPagHMAAAAdc"]
[Thu Jul 30 15:05:17.869472 2026] [autoindex:error] [pid 89520:tid 89701] [client 4.225.203.146:31562] AH01276: Cannot serve directory /home1/mthgzjte/public_html/website_07446164/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:05:18.022550 2026] [security2:error] [pid 89520:tid 89708] [client 4.225.203.146:31562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/classwithtostring.php"] [unique_id "amuufi0W4wRrtnDoPagHMQAAAbw"]
[Thu Jul 30 15:05:18.986001 2026] [security2:error] [pid 89520:tid 89706] [client 4.225.203.146:36349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/gmo.php"] [unique_id "amuufi0W4wRrtnDoPagHNwAAAbo"]
[Thu Jul 30 15:05:19.053084 2026] [security2:error] [pid 87988:tid 88210] [client 20.199.183.73:35199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuufzipAwzptuCxBrhvIQAAAWY"]
[Thu Jul 30 15:05:19.231091 2026] [security2:error] [pid 89520:tid 89623] [remote 185.191.171.3:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "teknomalay.com"] [uri "/resetter-epson-l210/"] [unique_id "amuufy0W4wRrtnDoPagHOwABwl0"]
[Thu Jul 30 15:05:19.231332 2026] [security2:error] [pid 89520:tid 89714] [client 185.191.171.3:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teknomalay.com"] [uri "/resetter-epson-l210/"] [unique_id "amuufy0W4wRrtnDoPagHOwABwl0"]
[Thu Jul 30 15:05:19.236895 2026] [core:notice] [pid 89520:tid 89695] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:19.419490 2026] [security2:error] [pid 89520:tid 89626] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuufy0W4wRrtnDoPagHPQABnV8"]
[Thu Jul 30 15:05:19.419680 2026] [security2:error] [pid 89520:tid 89677] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuufy0W4wRrtnDoPagHPQABnV8"]
[Thu Jul 30 15:05:19.496312 2026] [security2:error] [pid 89520:tid 89620] [remote 20.118.34.237:17746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuufy0W4wRrtnDoPagHPgAB6Vo"]
[Thu Jul 30 15:05:19.553861 2026] [security2:error] [pid 87988:tid 88182] [client 20.52.54.143:9152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/send.php"] [unique_id "amuufzipAwzptuCxBrhvKAAAAUo"]
[Thu Jul 30 15:05:19.682422 2026] [core:notice] [pid 89520:tid 89696] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:19.934218 2026] [security2:error] [pid 89520:tid 89687] [client 20.199.183.73:35273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.183.199.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "progroup.jo"] [uri "/index/function.php"] [unique_id "amuufy0W4wRrtnDoPagHRQAAAac"]
[Thu Jul 30 15:05:20.530329 2026] [security2:error] [pid 89520:tid 89732] [client 20.52.54.143:9173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuugC0W4wRrtnDoPagHSQAAAdQ"]
[Thu Jul 30 15:05:20.681868 2026] [core:notice] [pid 89520:tid 89630] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:21.190087 2026] [security2:error] [pid 89520:tid 89720] [client 4.225.203.146:36292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-content/languages/index.php"] [unique_id "amuugS0W4wRrtnDoPagHVQAAAcg"]
[Thu Jul 30 15:05:21.670762 2026] [security2:error] [pid 87988:tid 88174] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuugTipAwzptuCxBrhvQgABQjk"]
[Thu Jul 30 15:05:22.488098 2026] [security2:error] [pid 87988:tid 88053] [remote 74.7.243.224:39480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuugjipAwzptuCxBrhvWQABe0A"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:05:22.678211 2026] [security2:error] [pid 89520:tid 89742] [client 20.52.54.143:9059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/about.php"] [unique_id "amuugi0W4wRrtnDoPagHYwAAAd4"]
[Thu Jul 30 15:05:22.868854 2026] [core:notice] [pid 89520:tid 89774] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:22.871544 2026] [security2:error] [pid 89520:tid 89774] [client 66.249.74.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/74/77"] [unique_id "amuugi0W4wRrtnDoPagHZgAAAf4"]
[Thu Jul 30 15:05:23.572627 2026] [security2:error] [pid 87988:tid 88239] [client 20.52.54.143:9071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/options.php"] [unique_id "amuugzipAwzptuCxBrhvZgAAAYM"]
[Thu Jul 30 15:05:23.895832 2026] [security2:error] [pid 87988:tid 88227] [client 4.225.203.146:31606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-the.php"] [unique_id "amuugzipAwzptuCxBrhvawAAAXc"]
[Thu Jul 30 15:05:24.339269 2026] [security2:error] [pid 89520:tid 89705] [client 20.52.54.143:8741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuuhC0W4wRrtnDoPagHcAAAAbk"]
[Thu Jul 30 15:05:24.476097 2026] [security2:error] [pid 89520:tid 89702] [client 4.225.203.146:31563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/404.php"] [unique_id "amuuhC0W4wRrtnDoPagHdQAAAbY"]
[Thu Jul 30 15:05:26.808648 2026] [security2:error] [pid 89520:tid 89790] [client 162.141.167.36:36850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amuuhC0W4wRrtnDoPagHdAAAAg4"]
[Thu Jul 30 15:05:26.877432 2026] [security2:error] [pid 89520:tid 89669] [client 4.225.203.146:36335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/init.php"] [unique_id "amuuhi0W4wRrtnDoPagHhwAAAZU"]
[Thu Jul 30 15:05:27.850361 2026] [security2:error] [pid 89520:tid 89764] [client 20.52.54.143:9039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-file.php"] [unique_id "amuuhy0W4wRrtnDoPagHkQAAAfQ"]
[Thu Jul 30 15:05:28.568811 2026] [security2:error] [pid 87988:tid 88245] [client 193.47.62.167:52324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.journeywomenscenter.org"] [uri "/index.php"] [unique_id "amuuiDipAwzptuCxBrhvnwAAAYk"]
[Thu Jul 30 15:05:29.321011 2026] [security2:error] [pid 89520:tid 89777] [client 20.52.54.143:8714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/sid3.php"] [unique_id "amuuiS0W4wRrtnDoPagHqAAAAgE"]
[Thu Jul 30 15:05:29.572024 2026] [security2:error] [pid 89520:tid 89766] [client 193.47.62.167:53740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.journeywomenscenter.org"] [uri "/index.php"] [unique_id "amuuiS0W4wRrtnDoPagHpwAAAfY"], referer: http://www.journeywomenscenter.org/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Thu Jul 30 15:05:30.057556 2026] [security2:error] [pid 87988:tid 88019] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuijipAwzptuCxBrhv4AABfx4"]
[Thu Jul 30 15:05:30.057759 2026] [security2:error] [pid 87988:tid 88235] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuijipAwzptuCxBrhv4AABfx4"]
[Thu Jul 30 15:05:30.292757 2026] [security2:error] [pid 87988:tid 88227] [client 20.52.54.143:9195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/themes.php"] [unique_id "amuuijipAwzptuCxBrhv5gAAAXc"]
[Thu Jul 30 15:05:30.929375 2026] [core:notice] [pid 87988:tid 88210] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:31.131875 2026] [security2:error] [pid 87988:tid 88159] [client 20.52.54.143:9060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/plugins/index.php"] [unique_id "amuuizipAwzptuCxBrhv-gAAATM"]
[Thu Jul 30 15:05:31.490882 2026] [security2:error] [pid 89520:tid 89687] [client 45.91.22.78:45561] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.samirkhalifa.net"] [uri "/"] [unique_id "amuuiy0W4wRrtnDoPagHuAAAAac"]
[Thu Jul 30 15:05:31.494751 2026] [core:notice] [pid 89520:tid 89767] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:31.497628 2026] [security2:error] [pid 89520:tid 89767] [client 66.249.74.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/47/49"] [unique_id "amuuiy0W4wRrtnDoPagHuQAAAfc"]
[Thu Jul 30 15:05:31.508144 2026] [proxy:error] [pid 87988:tid 88212] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:05:31.508208 2026] [proxy_http:error] [pid 87988:tid 88212] [client 45.91.22.73:26783] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:05:31.508944 2026] [proxy:error] [pid 87988:tid 88212] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:05:31.508998 2026] [proxy_http:error] [pid 87988:tid 88212] [client 45.91.22.73:26783] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:05:31.513957 2026] [security2:error] [pid 89520:tid 89670] [client 45.91.22.77:44111] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "samirkhalifa.net"] [uri "/"] [unique_id "amuuiy0W4wRrtnDoPagHugAAAZY"]
[Thu Jul 30 15:05:31.515682 2026] [security2:error] [pid 89520:tid 89686] [client 172.237.109.114:3419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuiy0W4wRrtnDoPagHsQAAAaY"]
[Thu Jul 30 15:05:31.529175 2026] [proxy:error] [pid 87988:tid 88137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:05:31.529243 2026] [proxy_http:error] [pid 87988:tid 88137] [client 45.91.22.104:33263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:05:31.529797 2026] [proxy:error] [pid 87988:tid 88137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:05:31.529839 2026] [proxy_http:error] [pid 87988:tid 88137] [client 45.91.22.104:33263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:05:31.552323 2026] [security2:error] [pid 87988:tid 88142] [client 45.91.22.58:43571] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "autodiscover.samirkhalifa.net"] [uri "/"] [unique_id "amuuizipAwzptuCxBrhwAgAAASI"]
[Thu Jul 30 15:05:31.661585 2026] [security2:error] [pid 89520:tid 89756] [client 45.91.22.59:50581] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "website-2098ead5.qzb.nyx.temporary.site"] [uri "/"] [unique_id "amuuiy0W4wRrtnDoPagHvQAAAew"]
[Thu Jul 30 15:05:32.377919 2026] [security2:error] [pid 89520:tid 89669] [client 20.52.54.143:9069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/images/index.php"] [unique_id "amuujC0W4wRrtnDoPagHxwAAAZU"]
[Thu Jul 30 15:05:33.041728 2026] [security2:error] [pid 87988:tid 88135] [client 20.52.54.143:9215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/num.php"] [unique_id "amuujTipAwzptuCxBrhwGAAAARs"]
[Thu Jul 30 15:05:33.075683 2026] [security2:error] [pid 87988:tid 88081] [remote 74.7.227.39:45126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuujTipAwzptuCxBrhwGQABO1w"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/wpforms-lite/includes
[Thu Jul 30 15:05:34.843003 2026] [security2:error] [pid 89520:tid 89717] [client 20.52.54.143:9037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuuji0W4wRrtnDoPagH2gAAAcU"]
[Thu Jul 30 15:05:35.182641 2026] [core:notice] [pid 89520:tid 89776] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:35.760202 2026] [security2:error] [pid 87988:tid 88218] [client 20.52.54.143:8737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuujzipAwzptuCxBrhwPQAAAW4"]
[Thu Jul 30 15:05:35.771495 2026] [security2:error] [pid 87988:tid 88210] [client 213.152.161.240:57856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuujzipAwzptuCxBrhwPgAAAWY"]
[Thu Jul 30 15:05:35.771572 2026] [security2:error] [pid 87988:tid 88210] [client 213.152.161.240:57856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuujzipAwzptuCxBrhwPgAAAWY"]
[Thu Jul 30 15:05:36.396360 2026] [core:notice] [pid 89520:tid 89679] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:36.399962 2026] [security2:error] [pid 89520:tid 89679] [client 66.249.79.1:49088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/download/2935/1564"] [unique_id "amuukC0W4wRrtnDoPagH7AAAAZ8"]
[Thu Jul 30 15:05:37.173544 2026] [security2:error] [pid 89520:tid 89670] [client 20.52.54.143:8747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "amuukS0W4wRrtnDoPagH9AAAAZY"]
[Thu Jul 30 15:05:37.462426 2026] [security2:error] [pid 87988:tid 88174] [client 172.237.109.114:22143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuukDipAwzptuCxBrhwUQAAAUI"]
[Thu Jul 30 15:05:37.863209 2026] [core:notice] [pid 87988:tid 88145] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:39.488774 2026] [security2:error] [pid 87988:tid 88136] [client 172.237.109.114:56675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuukzipAwzptuCxBrhwbwAAARw"]
[Thu Jul 30 15:05:39.706613 2026] [security2:error] [pid 89520:tid 89655] [remote 216.73.216.51:7535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuuky0W4wRrtnDoPagIAQAByHk"]
[Thu Jul 30 15:05:40.989381 2026] [security2:error] [pid 87988:tid 88107] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuulDipAwzptuCxBrhwjAABTXY"]
[Thu Jul 30 15:05:40.989535 2026] [security2:error] [pid 87988:tid 88185] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuulDipAwzptuCxBrhwjAABTXY"]
[Thu Jul 30 15:05:41.655902 2026] [security2:error] [pid 87988:tid 87991] [remote 72.167.132.114:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuulTipAwzptuCxBrhwlAABFQI"]
[Thu Jul 30 15:05:43.113039 2026] [security2:error] [pid 89520:tid 89734] [client 74.7.230.41:46606] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "website-08e91e41.vdb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuuly0W4wRrtnDoPagIHQAB1gI"]
[Thu Jul 30 15:05:43.376123 2026] [security2:error] [pid 89520:tid 89689] [client 20.52.54.143:9205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/gifclass.php"] [unique_id "amuuly0W4wRrtnDoPagIIgAAAak"]
[Thu Jul 30 15:05:43.795711 2026] [security2:error] [pid 89520:tid 89755] [client 74.7.230.41:46616] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.toscanamall.com"] [uri "/robots.txt"] [unique_id "amuuly0W4wRrtnDoPagIJwAB6wg"], referer: https://website-08e91e41.vdb.nyx.temporary.site/robots.txt
[Thu Jul 30 15:05:43.916536 2026] [security2:error] [pid 89520:tid 89696] [client 74.7.241.190:32880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.mayanahsafaris.com"] [uri "/robots.txt"] [unique_id "amuuly0W4wRrtnDoPagIKQAAAbA"]
[Thu Jul 30 15:05:44.961957 2026] [core:notice] [pid 89520:tid 89541] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:45.022001 2026] [security2:error] [pid 89520:tid 89781] [client 20.52.54.143:9194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuumS0W4wRrtnDoPagINgAAAgU"]
[Thu Jul 30 15:05:45.090157 2026] [proxy:error] [pid 89520:tid 89548] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:05:45.090212 2026] [proxy_http:error] [pid 89520:tid 89548] [remote 195.96.139.180:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.teknomalay.com:2082
[Thu Jul 30 15:05:45.091045 2026] [proxy:error] [pid 89520:tid 89548] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:05:45.091094 2026] [proxy_http:error] [pid 89520:tid 89548] [remote 195.96.139.180:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.teknomalay.com:2082
[Thu Jul 30 15:05:45.559820 2026] [security2:error] [pid 89520:tid 89542] [remote 216.73.216.51:20102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuumS0W4wRrtnDoPagIPAABlQw"]
[Thu Jul 30 15:05:46.228237 2026] [security2:error] [pid 89520:tid 89682] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuumS0W4wRrtnDoPagIOwAAAaI"]
[Thu Jul 30 15:05:46.256396 2026] [security2:error] [pid 89520:tid 89680] [client 20.52.54.143:9186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/css/index.php"] [unique_id "amuumi0W4wRrtnDoPagISwAAAaA"]
[Thu Jul 30 15:05:46.462195 2026] [core:notice] [pid 89520:tid 89544] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:46.465383 2026] [security2:error] [pid 89520:tid 89724] [client 66.249.65.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/79/82"] [unique_id "amuumi0W4wRrtnDoPagITAABzA4"]
[Thu Jul 30 15:05:46.930339 2026] [security2:error] [pid 89520:tid 89547] [remote 57.141.0.68:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/agro_sintesa/article/view/8467"] [unique_id "amuumi0W4wRrtnDoPagIUAACARE"]
[Thu Jul 30 15:05:47.415475 2026] [security2:error] [pid 87988:tid 88232] [client 20.52.54.143:8715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-cron.php"] [unique_id "amuumzipAwzptuCxBrhw0AAAAXw"]
[Thu Jul 30 15:05:48.292572 2026] [security2:error] [pid 89520:tid 89749] [client 103.108.231.231:41975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "emmelevate.club"] [uri "/index.php"] [unique_id "amuunC0W4wRrtnDoPagIXQAAAeU"]
[Thu Jul 30 15:05:48.351793 2026] [core:notice] [pid 89520:tid 89684] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:48.357503 2026] [security2:error] [pid 89520:tid 89684] [client 66.249.79.230:48042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/3770/1813"] [unique_id "amuunC0W4wRrtnDoPagIXgAAAaQ"]
[Thu Jul 30 15:05:48.983346 2026] [security2:error] [pid 89520:tid 89677] [client 103.108.231.231:41975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.231.108.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/xmlrpc.php"] [unique_id "amuunC0W4wRrtnDoPagIZwAAAZ0"]
[Thu Jul 30 15:05:49.648771 2026] [autoindex:error] [pid 89520:tid 89729] [client 43.159.36.180:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://otbola.click
[Thu Jul 30 15:05:50.250007 2026] [security2:error] [pid 89520:tid 89644] [remote 57.141.0.25:42510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuunS0W4wRrtnDoPagIdwAB9G8"]
[Thu Jul 30 15:05:50.582740 2026] [security2:error] [pid 87988:tid 88075] [remote 57.141.0.22:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amuunjipAwzptuCxBrhw8AABb1Y"]
[Thu Jul 30 15:05:50.779555 2026] [security2:error] [pid 89520:tid 89698] [client 43.173.179.41:48442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/02/14/centre-commercial-rosny-2/"] [unique_id "amuuni0W4wRrtnDoPagIewAAAbI"]
[Thu Jul 30 15:05:50.932857 2026] [security2:error] [pid 89520:tid 89707] [client 103.108.231.231:62372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuuni0W4wRrtnDoPagIfwAAAbs"]
[Thu Jul 30 15:05:51.360553 2026] [security2:error] [pid 87988:tid 88221] [client 20.226.5.174:33760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/011i.php"] [unique_id "amuunzipAwzptuCxBrhw-wAAAXE"]
[Thu Jul 30 15:05:51.367694 2026] [core:notice] [pid 89520:tid 89675] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:51.372241 2026] [security2:error] [pid 89520:tid 89675] [client 43.173.182.35:46284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/02/14/centre-commercial-rosny-2/"] [unique_id "amuuny0W4wRrtnDoPagIgQAAAZs"], referer: https://carnetdeshopping.com/index.php/2016/02/14/centre-commercial-rosny-2/
[Thu Jul 30 15:05:51.923780 2026] [security2:error] [pid 89520:tid 89560] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuny0W4wRrtnDoPagIhAABrR4"]
[Thu Jul 30 15:05:51.923954 2026] [security2:error] [pid 89520:tid 89693] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuny0W4wRrtnDoPagIhAABrR4"]
[Thu Jul 30 15:05:52.077904 2026] [security2:error] [pid 89520:tid 89552] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/011i.php"] [unique_id "amuuoC0W4wRrtnDoPagIiAABxxY"]
[Thu Jul 30 15:05:52.438709 2026] [security2:error] [pid 87988:tid 87993] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/03a005685d.php"] [unique_id "amuuoDipAwzptuCxBrhxDQABgAQ"]
[Thu Jul 30 15:05:52.453502 2026] [autoindex:error] [pid 89520:tid 89679] [client 216.73.216.85:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:05:52.561537 2026] [security2:error] [pid 89520:tid 89557] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/403.php"] [unique_id "amuuoC0W4wRrtnDoPagIlwABsBs"]
[Thu Jul 30 15:05:52.683452 2026] [security2:error] [pid 87988:tid 88072] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/404.php"] [unique_id "amuuoDipAwzptuCxBrhxEgABHlM"]
[Thu Jul 30 15:05:52.767270 2026] [security2:error] [pid 89520:tid 89688] [client 20.226.5.174:33753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/03a005685d.php"] [unique_id "amuuoC0W4wRrtnDoPagImQAAAag"]
[Thu Jul 30 15:05:52.804925 2026] [security2:error] [pid 89520:tid 89550] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/aa.php"] [unique_id "amuuoC0W4wRrtnDoPagImgAB8RQ"]
[Thu Jul 30 15:05:52.844455 2026] [core:notice] [pid 89520:tid 89767] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:52.868915 2026] [security2:error] [pid 87988:tid 88166] [client 103.108.231.231:6430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuuoDipAwzptuCxBrhxFAAAATo"]
[Thu Jul 30 15:05:52.927109 2026] [security2:error] [pid 87988:tid 88047] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/aafewc0k.php"] [unique_id "amuuoDipAwzptuCxBrhxGAABDTo"]
[Thu Jul 30 15:05:53.048804 2026] [security2:error] [pid 89520:tid 89561] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/abcd.php"] [unique_id "amuuoS0W4wRrtnDoPagIoQABrB8"]
[Thu Jul 30 15:05:53.172804 2026] [security2:error] [pid 87988:tid 88050] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/about.php"] [unique_id "amuuoTipAwzptuCxBrhxHgABhD0"]
[Thu Jul 30 15:05:53.190078 2026] [security2:error] [pid 87988:tid 88165] [client 172.237.109.114:19865] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuoDipAwzptuCxBrhxCAAAATk"]
[Thu Jul 30 15:05:53.294192 2026] [security2:error] [pid 89520:tid 89656] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/admin.php"] [unique_id "amuuoS0W4wRrtnDoPagIogAB1Xo"]
[Thu Jul 30 15:05:53.421095 2026] [security2:error] [pid 87988:tid 88089] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuuoTipAwzptuCxBrhxIgABKGQ"]
[Thu Jul 30 15:05:53.542355 2026] [security2:error] [pid 89520:tid 89649] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/albin.php"] [unique_id "amuuoS0W4wRrtnDoPagIqAABsXM"]
[Thu Jul 30 15:05:53.667968 2026] [security2:error] [pid 87988:tid 88044] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/amfsqvgv.php"] [unique_id "amuuoTipAwzptuCxBrhxKQABGTc"]
[Thu Jul 30 15:05:53.788823 2026] [security2:error] [pid 89520:tid 89556] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/ant.php"] [unique_id "amuuoS0W4wRrtnDoPagIqgABvxo"]
[Thu Jul 30 15:05:53.911622 2026] [security2:error] [pid 87988:tid 88046] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/appreciators.php"] [unique_id "amuuoTipAwzptuCxBrhxKgABQzk"]
[Thu Jul 30 15:05:54.032814 2026] [security2:error] [pid 89520:tid 89559] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/archive.php"] [unique_id "amuuoi0W4wRrtnDoPagIsQAByx0"]
[Thu Jul 30 15:05:54.155631 2026] [security2:error] [pid 87988:tid 88045] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/as.php"] [unique_id "amuuojipAwzptuCxBrhxMgABQjg"]
[Thu Jul 30 15:05:54.277546 2026] [security2:error] [pid 89520:tid 89658] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/atomlib.php"] [unique_id "amuuoi0W4wRrtnDoPagIswAB4nw"]
[Thu Jul 30 15:05:54.400512 2026] [security2:error] [pid 87988:tid 88060] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuuojipAwzptuCxBrhxNAABiEc"]
[Thu Jul 30 15:05:54.500573 2026] [security2:error] [pid 89520:tid 89729] [client 172.237.109.114:54936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuoi0W4wRrtnDoPagIrwAAAdE"]
[Thu Jul 30 15:05:54.521736 2026] [security2:error] [pid 89520:tid 89564] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/bb.php"] [unique_id "amuuoi0W4wRrtnDoPagIuAAB8CI"]
[Thu Jul 30 15:05:54.650921 2026] [security2:error] [pid 87988:tid 88063] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/bnm.php"] [unique_id "amuuojipAwzptuCxBrhxOQABXEo"]
[Thu Jul 30 15:05:54.714170 2026] [security2:error] [pid 89520:tid 89562] [remote 216.73.216.51:20102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuuoi0W4wRrtnDoPagIvAABoCA"]
[Thu Jul 30 15:05:54.788005 2026] [security2:error] [pid 89520:tid 89565] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/bootstrap.php"] [unique_id "amuuoi0W4wRrtnDoPagIvQAB3CM"]
[Thu Jul 30 15:05:54.882112 2026] [security2:error] [pid 87988:tid 88171] [client 103.108.231.231:23226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuuojipAwzptuCxBrhxOwAAAT8"]
[Thu Jul 30 15:05:54.911045 2026] [security2:error] [pid 87988:tid 88037] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/buy.php"] [unique_id "amuuojipAwzptuCxBrhxPAABiTA"]
[Thu Jul 30 15:05:54.915862 2026] [security2:error] [pid 87988:tid 88176] [client 20.226.5.174:33738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/403.php"] [unique_id "amuuojipAwzptuCxBrhxPQAAAUQ"]
[Thu Jul 30 15:05:55.032612 2026] [security2:error] [pid 89520:tid 89543] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/chosen.php"] [unique_id "amuuoy0W4wRrtnDoPagIwQAB1w0"]
[Thu Jul 30 15:05:55.154852 2026] [security2:error] [pid 87988:tid 88041] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/class-wp-image.php"] [unique_id "amuuozipAwzptuCxBrhxRAABGzQ"]
[Thu Jul 30 15:05:55.276552 2026] [security2:error] [pid 89520:tid 89567] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/classsmtps.php"] [unique_id "amuuoy0W4wRrtnDoPagIxgABwiU"]
[Thu Jul 30 15:05:55.399768 2026] [security2:error] [pid 87988:tid 88094] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuuozipAwzptuCxBrhxRQABNmk"]
[Thu Jul 30 15:05:55.510122 2026] [security2:error] [pid 87988:tid 88147] [client 20.52.54.143:9036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-block.php"] [unique_id "amuuozipAwzptuCxBrhxSAAAASc"]
[Thu Jul 30 15:05:55.524357 2026] [security2:error] [pid 89520:tid 89571] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/config.php"] [unique_id "amuuoy0W4wRrtnDoPagIzAAB7Sk"]
[Thu Jul 30 15:05:55.637313 2026] [security2:error] [pid 89520:tid 89715] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuoy0W4wRrtnDoPagIwAABwys"]
[Thu Jul 30 15:05:55.647397 2026] [security2:error] [pid 87988:tid 88105] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/core.php"] [unique_id "amuuozipAwzptuCxBrhxSwABMXQ"]
[Thu Jul 30 15:05:55.782124 2026] [security2:error] [pid 89520:tid 89569] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/css.php"] [unique_id "amuuoy0W4wRrtnDoPagI0AAB9ic"]
[Thu Jul 30 15:05:55.905109 2026] [security2:error] [pid 87988:tid 88095] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/database.php"] [unique_id "amuuozipAwzptuCxBrhxTgABXWo"]
[Thu Jul 30 15:05:56.026592 2026] [security2:error] [pid 89520:tid 89581] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/db.php"] [unique_id "amuupC0W4wRrtnDoPagI1AAB2DM"]
[Thu Jul 30 15:05:56.149067 2026] [security2:error] [pid 87988:tid 88103] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/default.php"] [unique_id "amuupDipAwzptuCxBrhxVQABHHI"]
[Thu Jul 30 15:05:56.269826 2026] [security2:error] [pid 89520:tid 89575] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/dropdown.php"] [unique_id "amuupC0W4wRrtnDoPagI2AAB8S0"]
[Thu Jul 30 15:05:56.311661 2026] [security2:error] [pid 87988:tid 88150] [client 20.226.5.174:33766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/404.php"] [unique_id "amuupDipAwzptuCxBrhxWAAAASo"]
[Thu Jul 30 15:05:56.394034 2026] [security2:error] [pid 87988:tid 88032] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/edit.php"] [unique_id "amuupDipAwzptuCxBrhxWQABFCs"]
[Thu Jul 30 15:05:56.514916 2026] [security2:error] [pid 89520:tid 89584] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/f35.php"] [unique_id "amuupC0W4wRrtnDoPagI2gAByjY"]
[Thu Jul 30 15:05:56.639163 2026] [security2:error] [pid 87988:tid 87989] [remote 68.221.186.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.markmocek.com"] [uri "/f7.php"] [unique_id "amuupDipAwzptuCxBrhxWwABdwA"]
[Thu Jul 30 15:05:56.691113 2026] [security2:error] [pid 89520:tid 89579] [remote 57.141.0.36:50416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5035568461/feed/rss2/"] [unique_id "amuupC0W4wRrtnDoPagI3gABpDE"]
[Thu Jul 30 15:05:56.954517 2026] [security2:error] [pid 89520:tid 89725] [client 20.52.54.143:9208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "amuupC0W4wRrtnDoPagI4QAAAc0"]
[Thu Jul 30 15:05:57.064873 2026] [security2:error] [pid 89520:tid 89789] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuupC0W4wRrtnDoPagI2QACDSo"]
[Thu Jul 30 15:05:57.118283 2026] [security2:error] [pid 89520:tid 89716] [client 103.108.231.231:45551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "amuupS0W4wRrtnDoPagI4gAAAcQ"]
[Thu Jul 30 15:05:57.801937 2026] [security2:error] [pid 89520:tid 89720] [client 20.226.5.174:33732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/aa.php"] [unique_id "amuupS0W4wRrtnDoPagI7AAAAcg"]
[Thu Jul 30 15:05:57.983797 2026] [security2:error] [pid 87988:tid 88185] [client 20.52.54.143:9156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.laduchessecollections.com"] [uri "/classwithtostring.php"] [unique_id "amuupTipAwzptuCxBrhxbAAAAU0"]
[Thu Jul 30 15:05:58.668239 2026] [core:notice] [pid 87988:tid 88107] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:58.673118 2026] [security2:error] [pid 87988:tid 88198] [client 129.226.118.178:49354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/3565"] [unique_id "amuupjipAwzptuCxBrhxdgABWnY"]
[Thu Jul 30 15:05:58.819650 2026] [core:notice] [pid 87988:tid 87991] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.026513 2026] [core:notice] [pid 87988:tid 88112] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.026526 2026] [core:notice] [pid 87988:tid 87996] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.026613 2026] [core:notice] [pid 87988:tid 88099] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.057217 2026] [core:notice] [pid 87988:tid 88104] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.059818 2026] [core:notice] [pid 87988:tid 88096] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.060419 2026] [core:notice] [pid 87988:tid 88082] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.064427 2026] [core:notice] [pid 87988:tid 88090] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.064593 2026] [core:notice] [pid 87988:tid 88078] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.070217 2026] [core:notice] [pid 87988:tid 88108] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:05:59.093773 2026] [security2:error] [pid 89520:tid 89710] [client 103.108.231.231:51129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuupy0W4wRrtnDoPagI9gAAAb4"]
[Thu Jul 30 15:05:59.440950 2026] [security2:error] [pid 89520:tid 89740] [client 172.237.109.114:51586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuupi0W4wRrtnDoPagI9QAAAdw"]
[Thu Jul 30 15:05:59.534612 2026] [security2:error] [pid 89520:tid 89668] [client 20.226.5.174:33741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/aafewc0k.php"] [unique_id "amuupy0W4wRrtnDoPagI_gAAAZQ"]
[Thu Jul 30 15:05:59.979418 2026] [autoindex:error] [pid 89520:tid 89719] [client 193.149.176.200:39302] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:06:00.589918 2026] [security2:error] [pid 89520:tid 89664] [client 20.226.5.174:33775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/abcd.php"] [unique_id "amuuqC0W4wRrtnDoPagJDAAAAZA"]
[Thu Jul 30 15:06:01.429917 2026] [security2:error] [pid 87988:tid 88195] [client 103.108.231.231:7227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuuqTipAwzptuCxBrhxnwAAAVc"]
[Thu Jul 30 15:06:01.773443 2026] [security2:error] [pid 87988:tid 88220] [client 20.226.5.174:33764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/about.php"] [unique_id "amuuqTipAwzptuCxBrhxowAAAXA"]
[Thu Jul 30 15:06:02.207922 2026] [core:notice] [pid 89520:tid 89721] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:02.591554 2026] [security2:error] [pid 89520:tid 89590] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuqi0W4wRrtnDoPagJJAAB9Dw"]
[Thu Jul 30 15:06:02.591697 2026] [security2:error] [pid 89520:tid 89764] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuqi0W4wRrtnDoPagJJAAB9Dw"]
[Thu Jul 30 15:06:03.294097 2026] [security2:error] [pid 89520:tid 89739] [client 20.226.5.174:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/admin.php"] [unique_id "amuuqy0W4wRrtnDoPagJMAAAAds"]
[Thu Jul 30 15:06:03.459473 2026] [security2:error] [pid 89520:tid 89700] [client 103.108.231.231:20741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuuqy0W4wRrtnDoPagJNAAAAbQ"]
[Thu Jul 30 15:06:05.352510 2026] [core:notice] [pid 89520:tid 89596] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:05.618804 2026] [security2:error] [pid 89520:tid 89664] [client 103.108.231.231:35972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuurS0W4wRrtnDoPagJSgAAAZA"]
[Thu Jul 30 15:06:05.728758 2026] [core:notice] [pid 89520:tid 89593] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:05.885949 2026] [security2:error] [pid 89520:tid 89722] [client 20.226.5.174:33742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/adminfuns.php"] [unique_id "amuurS0W4wRrtnDoPagJTQAAAco"]
[Thu Jul 30 15:06:06.149722 2026] [security2:error] [pid 89520:tid 89690] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuurS0W4wRrtnDoPagJSAAAAao"]
[Thu Jul 30 15:06:06.618660 2026] [security2:error] [pid 89520:tid 89582] [remote 167.71.218.184:55912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wce.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuuri0W4wRrtnDoPagJUgABzzQ"]
[Thu Jul 30 15:06:07.160540 2026] [security2:error] [pid 87988:tid 88143] [client 20.226.5.174:33769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/albin.php"] [unique_id "amuurzipAwzptuCxBrhx4wAAASM"]
[Thu Jul 30 15:06:07.420954 2026] [security2:error] [pid 87988:tid 87993] [remote 167.71.218.184:45374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nxt.udi.temporary.site"] [uri "/wp-login.php"] [unique_id "amuurzipAwzptuCxBrhx5wABFQQ"]
[Thu Jul 30 15:06:07.640876 2026] [security2:error] [pid 89520:tid 89737] [client 103.108.231.231:29858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuury0W4wRrtnDoPagJWAAAAdk"]
[Thu Jul 30 15:06:07.688134 2026] [security2:error] [pid 87988:tid 88054] [remote 57.141.0.61:51342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/about/contact"] [unique_id "amuurzipAwzptuCxBrhx6wABRkE"]
[Thu Jul 30 15:06:08.567247 2026] [security2:error] [pid 87988:tid 88124] [client 20.226.5.174:33739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/amfsqvgv.php"] [unique_id "amuusDipAwzptuCxBrhx9gAAARA"]
[Thu Jul 30 15:06:10.357513 2026] [security2:error] [pid 89520:tid 89686] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuusS0W4wRrtnDoPagJawAAAaY"]
[Thu Jul 30 15:06:10.782676 2026] [security2:error] [pid 89520:tid 89606] [remote 57.141.0.31:60920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuusi0W4wRrtnDoPagJcAAB2kw"]
[Thu Jul 30 15:06:10.908414 2026] [security2:error] [pid 87988:tid 88118] [client 20.226.5.174:33765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/ant.php"] [unique_id "amuusjipAwzptuCxBrhyGAAAAQo"]
[Thu Jul 30 15:06:11.521368 2026] [core:notice] [pid 89520:tid 89669] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:11.986186 2026] [core:notice] [pid 89520:tid 89683] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:12.081127 2026] [core:notice] [pid 87988:tid 88167] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:12.085031 2026] [security2:error] [pid 87988:tid 88167] [client 66.249.79.231:50872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/859"] [unique_id "amuuszipAwzptuCxBrhyIQAAATs"]
[Thu Jul 30 15:06:12.161204 2026] [security2:error] [pid 87988:tid 88173] [client 20.226.5.174:33772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/appreciators.php"] [unique_id "amuutDipAwzptuCxBrhyKAAAAUE"]
[Thu Jul 30 15:06:12.745726 2026] [core:notice] [pid 87988:tid 88195] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:13.246609 2026] [security2:error] [pid 89520:tid 89600] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuutS0W4wRrtnDoPagJhwABzkY"]
[Thu Jul 30 15:06:13.246760 2026] [security2:error] [pid 89520:tid 89726] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuutS0W4wRrtnDoPagJhwABzkY"]
[Thu Jul 30 15:06:13.492894 2026] [security2:error] [pid 87988:tid 88216] [client 172.237.109.114:42076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuutDipAwzptuCxBrhyOwAAAWw"]
[Thu Jul 30 15:06:13.533314 2026] [security2:error] [pid 89520:tid 89667] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuutC0W4wRrtnDoPagJhAABk1Q"]
[Thu Jul 30 15:06:13.576559 2026] [security2:error] [pid 87988:tid 88192] [client 172.237.109.114:40764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuutDipAwzptuCxBrhyOgAAAVQ"]
[Thu Jul 30 15:06:13.627394 2026] [security2:error] [pid 89520:tid 89746] [client 66.249.73.70:41977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.tmrfsl.com"] [uri "/index.php"] [unique_id "amuutC0W4wRrtnDoPagJgwAAAeI"]
[Thu Jul 30 15:06:13.897883 2026] [security2:error] [pid 87988:tid 88236] [client 192.178.6.10:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.reviewbyjook.com"] [uri "/robots.txt"] [unique_id "amuutTipAwzptuCxBrhyRAAAAYA"]
[Thu Jul 30 15:06:14.834418 2026] [security2:error] [pid 89520:tid 89735] [client 2a03:2880:f800:4:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuti0W4wRrtnDoPagJkQAB1zU"]
[Thu Jul 30 15:06:15.001838 2026] [security2:error] [pid 89520:tid 89665] [client 20.226.5.174:33750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/archive.php"] [unique_id "amuuty0W4wRrtnDoPagJlwAAAZE"]
[Thu Jul 30 15:06:15.566971 2026] [autoindex:error] [pid 87988:tid 88132] [client 43.159.36.180:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://koidomino.click
[Thu Jul 30 15:06:16.181225 2026] [security2:error] [pid 87988:tid 88200] [client 34.198.201.66:12608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuuuDipAwzptuCxBrhyZQAAAVw"], referer: https://globalmarks.pk/
[Thu Jul 30 15:06:16.505535 2026] [security2:error] [pid 87988:tid 88130] [client 20.226.5.174:33774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/as.php"] [unique_id "amuuuDipAwzptuCxBrhybAAAARY"]
[Thu Jul 30 15:06:16.733125 2026] [security2:error] [pid 89520:tid 89708] [client 110.164.193.195:48582] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuuuC0W4wRrtnDoPagJnwAAAbw"]
[Thu Jul 30 15:06:16.777792 2026] [security2:error] [pid 87988:tid 88162] [client 110.164.193.195:56150] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuuuDipAwzptuCxBrhydAAAATY"]
[Thu Jul 30 15:06:17.542656 2026] [security2:error] [pid 89520:tid 89783] [client 20.226.5.174:33755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/atomlib.php"] [unique_id "amuuuS0W4wRrtnDoPagJpAAAAgc"]
[Thu Jul 30 15:06:17.751894 2026] [core:notice] [pid 87988:tid 88213] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:18.424708 2026] [security2:error] [pid 89520:tid 89784] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuuS0W4wRrtnDoPagJqgAAAgg"]
[Thu Jul 30 15:06:18.432807 2026] [core:notice] [pid 89520:tid 89695] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:18.537822 2026] [security2:error] [pid 87988:tid 88141] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuuTipAwzptuCxBrhyhgAAASE"]
[Thu Jul 30 15:06:19.147666 2026] [security2:error] [pid 89520:tid 89770] [client 20.226.5.174:33754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/autoload_classmap.php"] [unique_id "amuuuy0W4wRrtnDoPagJtgAAAfo"]
[Thu Jul 30 15:06:19.739965 2026] [core:error] [pid 89520:tid 89611] [remote 74.7.241.159:34046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:06:19.739998 2026] [core:error] [pid 89520:tid 89611] [remote 74.7.241.159:34046] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:06:19.740154 2026] [security2:error] [pid 89520:tid 89741] [client 74.7.241.159:34046] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-d0fe016a.wvq.nyx.temporary.site"] [uri "/website_d0fe016a/index.php"] [unique_id "amuuuy0W4wRrtnDoPagJvAAB3VE"]
[Thu Jul 30 15:06:20.357558 2026] [core:notice] [pid 87988:tid 88149] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:21.355718 2026] [security2:error] [pid 89520:tid 89729] [client 20.226.5.174:33745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/bb.php"] [unique_id "amuuvS0W4wRrtnDoPagJygAAAdE"]
[Thu Jul 30 15:06:22.205091 2026] [core:notice] [pid 89520:tid 89768] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:22.224014 2026] [core:notice] [pid 89520:tid 89787] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:22.230579 2026] [core:notice] [pid 87988:tid 88221] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:22.799837 2026] [security2:error] [pid 87988:tid 88122] [client 20.226.5.174:33736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/bnm.php"] [unique_id "amuuvjipAwzptuCxBrhyxwAAAQ4"]
[Thu Jul 30 15:06:22.831316 2026] [core:notice] [pid 87988:tid 88220] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:22.839066 2026] [core:notice] [pid 87988:tid 88213] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:22.844477 2026] [core:notice] [pid 87988:tid 88230] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:23.053767 2026] [core:error] [pid 87988:tid 88237] [client 2602:80d:1004::26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:06:23.053787 2026] [core:error] [pid 87988:tid 88237] [client 2602:80d:1004::26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:06:23.833662 2026] [security2:error] [pid 87988:tid 88008] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuvzipAwzptuCxBrhy1QABHhM"]
[Thu Jul 30 15:06:23.833812 2026] [security2:error] [pid 87988:tid 88138] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuvzipAwzptuCxBrhy1QABHhM"]
[Thu Jul 30 15:06:24.416392 2026] [security2:error] [pid 87988:tid 88208] [client 20.226.5.174:33746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/bootstrap.php"] [unique_id "amuuwDipAwzptuCxBrhy3QAAAWQ"]
[Thu Jul 30 15:06:24.924787 2026] [core:notice] [pid 89520:tid 89684] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:24.938290 2026] [core:error] [pid 89520:tid 89684] [client 66.249.79.229:65510] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:06:24.938536 2026] [security2:error] [pid 89520:tid 89684] [client 66.249.79.229:65510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/6597/2849.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuuwC0W4wRrtnDoPagKBQAAAaQ"]
[Thu Jul 30 15:06:25.006231 2026] [security2:error] [pid 89520:tid 89671] [client 213.152.161.240:47266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuuwS0W4wRrtnDoPagKCQAAAZc"]
[Thu Jul 30 15:06:25.006340 2026] [security2:error] [pid 89520:tid 89671] [client 213.152.161.240:47266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuuwS0W4wRrtnDoPagKCQAAAZc"]
[Thu Jul 30 15:06:25.595180 2026] [core:notice] [pid 89520:tid 89778] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:25.782430 2026] [security2:error] [pid 87988:tid 88163] [client 20.226.5.174:33773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/buy.php"] [unique_id "amuuwTipAwzptuCxBrhy9gAAATc"]
[Thu Jul 30 15:06:26.914363 2026] [security2:error] [pid 87988:tid 88197] [client 20.226.5.174:34310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/chosen.php"] [unique_id "amuuwjipAwzptuCxBrhzCQAAAVk"]
[Thu Jul 30 15:06:27.094506 2026] [security2:error] [pid 87988:tid 88181] [client 116.179.37.3:15346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "online-hope.com"] [uri "/wp-content/plugins/litespeed-cache/guest.vary.php"] [unique_id "amuuwjipAwzptuCxBrhzCAAAAUk"], referer: https://online-hope.com/
[Thu Jul 30 15:06:27.781102 2026] [security2:error] [pid 89520:tid 89728] [client 127.0.0.1:36398] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuuwy0W4wRrtnDoPagKLwAAAdA"]
[Thu Jul 30 15:06:27.781125 2026] [security2:error] [pid 87988:tid 88126] [client 127.0.0.1:36382] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.espairsa.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuuwzipAwzptuCxBrhzFgAAARI"]
[Thu Jul 30 15:06:27.781265 2026] [security2:error] [pid 87988:tid 88235] [client 74.7.241.167:60548] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.espairsa.com"] [uri "/robots.txt"] [unique_id "amuuwzipAwzptuCxBrhzFQABf0k"]
[Thu Jul 30 15:06:27.935573 2026] [security2:error] [pid 87988:tid 88072] [remote 74.7.227.39:49522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuuwzipAwzptuCxBrhzHAABEFM"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/woozone/aa-framework
[Thu Jul 30 15:06:28.056778 2026] [security2:error] [pid 89520:tid 89544] [remote 103.74.116.239:35274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahm.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuuxC0W4wRrtnDoPagKNAABtw4"]
[Thu Jul 30 15:06:28.447148 2026] [security2:error] [pid 87988:tid 88138] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuuwzipAwzptuCxBrhzGwAAAR4"]
[Thu Jul 30 15:06:28.489295 2026] [security2:error] [pid 89520:tid 89547] [remote 74.7.243.224:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuuxC0W4wRrtnDoPagKNgAB0RE"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:06:28.504107 2026] [security2:error] [pid 87988:tid 88160] [client 20.226.5.174:33737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/class-wp-image.php"] [unique_id "amuuxDipAwzptuCxBrhzMAAAATQ"]
[Thu Jul 30 15:06:28.581422 2026] [security2:error] [pid 87988:tid 88152] [client 172.237.109.114:42940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuuxDipAwzptuCxBrhzHQAAASw"]
[Thu Jul 30 15:06:28.871741 2026] [security2:error] [pid 87988:tid 88121] [client 74.7.175.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-bec9ef14.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuuxDipAwzptuCxBrhzKAAAAQ0"]
[Thu Jul 30 15:06:28.872589 2026] [security2:error] [pid 87988:tid 88161] [client 74.7.175.184:32998] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-bec9ef14.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuuxDipAwzptuCxBrhzJAABNV4"]
[Thu Jul 30 15:06:29.917590 2026] [security2:error] [pid 89520:tid 89715] [client 20.226.5.174:33729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/classsmtps.php"] [unique_id "amuuxS0W4wRrtnDoPagKQQAAAcM"]
[Thu Jul 30 15:06:30.825198 2026] [core:notice] [pid 89520:tid 89734] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:31.178957 2026] [security2:error] [pid 89520:tid 89698] [client 20.226.5.174:33780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/classwithtostring.php"] [unique_id "amuuxy0W4wRrtnDoPagKSwAAAbI"]
[Thu Jul 30 15:06:31.729674 2026] [security2:error] [pid 89520:tid 89733] [client 85.208.96.208:48594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuuxy0W4wRrtnDoPagKUgAAAdU"]
[Thu Jul 30 15:06:31.729880 2026] [security2:error] [pid 89520:tid 89733] [client 85.208.96.208:48594] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuuxy0W4wRrtnDoPagKUgAAAdU"]
[Thu Jul 30 15:06:32.728166 2026] [security2:error] [pid 87988:tid 88227] [client 20.226.5.174:33789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/config.php"] [unique_id "amuuyDipAwzptuCxBrhzYwAAAXc"]
[Thu Jul 30 15:06:32.817840 2026] [security2:error] [pid 89520:tid 89786] [client 85.208.96.193:48718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product-category/jackets/dior-jacket/page/3/"] [unique_id "amuuyC0W4wRrtnDoPagKXQAAAgo"]
[Thu Jul 30 15:06:32.817996 2026] [security2:error] [pid 89520:tid 89786] [client 85.208.96.193:48718] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product-category/jackets/dior-jacket/page/3/"] [unique_id "amuuyC0W4wRrtnDoPagKXQAAAgo"]
[Thu Jul 30 15:06:34.364837 2026] [security2:error] [pid 87988:tid 88118] [client 20.226.5.174:33770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/core.php"] [unique_id "amuuyjipAwzptuCxBrhzdgAAAQo"]
[Thu Jul 30 15:06:34.402693 2026] [security2:error] [pid 87988:tid 88115] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuyjipAwzptuCxBrhzeAABQn4"]
[Thu Jul 30 15:06:34.402869 2026] [security2:error] [pid 87988:tid 88174] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuuyjipAwzptuCxBrhzeAABQn4"]
[Thu Jul 30 15:06:35.095795 2026] [security2:error] [pid 87988:tid 88073] [remote 190.92.174.190:50110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuuyzipAwzptuCxBrhzhgABYlQ"]
[Thu Jul 30 15:06:35.499865 2026] [security2:error] [pid 87988:tid 88123] [client 20.226.5.174:33781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/css.php"] [unique_id "amuuyzipAwzptuCxBrhziQAAAQ8"]
[Thu Jul 30 15:06:35.941338 2026] [security2:error] [pid 89520:tid 89686] [client 45.91.22.96:47305] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "azureskyfilms.com"] [uri "/"] [unique_id "amuuyy0W4wRrtnDoPagKfwAAAaY"]
[Thu Jul 30 15:06:35.964345 2026] [security2:error] [pid 89520:tid 89698] [client 45.91.22.90:27191] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.azureskyfilms.com"] [uri "/"] [unique_id "amuuyy0W4wRrtnDoPagKgAAAAbI"]
[Thu Jul 30 15:06:36.045306 2026] [security2:error] [pid 87988:tid 88241] [client 45.91.22.82:26739] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "rry.nyx.temporary.site"] [uri "/"] [unique_id "amuuzDipAwzptuCxBrhzkQAAAYU"]
[Thu Jul 30 15:06:36.113784 2026] [security2:error] [pid 89520:tid 89738] [client 45.91.22.105:52933] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "webdisk.rry.nyx.temporary.site"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "amuuzC0W4wRrtnDoPagKgwAAAdo"]
[Thu Jul 30 15:06:36.125401 2026] [security2:error] [pid 87988:tid 88144] [client 45.91.22.73:58433] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "cpanel.rry.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "amuuzDipAwzptuCxBrhzkgAAASQ"]
[Thu Jul 30 15:06:36.137828 2026] [security2:error] [pid 89520:tid 89788] [client 45.91.22.88:27521] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "cpcalendars.rry.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "amuuzC0W4wRrtnDoPagKhAAAAgw"]
[Thu Jul 30 15:06:36.138212 2026] [security2:error] [pid 89520:tid 89712] [client 45.91.22.63:34365] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.rry.nyx.temporary.site"] [uri "/"] [unique_id "amuuzC0W4wRrtnDoPagKhQAAAcA"]
[Thu Jul 30 15:06:36.148011 2026] [security2:error] [pid 89520:tid 89763] [client 45.91.22.98:52111] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "autodiscover.rry.nyx.temporary.site"] [uri "/"] [unique_id "amuuzC0W4wRrtnDoPagKhgAAAfM"]
[Thu Jul 30 15:06:36.156728 2026] [security2:error] [pid 87988:tid 88195] [client 45.91.22.65:50489] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "webmail.rry.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/"] [unique_id "amuuzDipAwzptuCxBrhzlAAAAVc"]
[Thu Jul 30 15:06:36.156900 2026] [security2:error] [pid 89520:tid 89665] [client 45.91.22.104:40631] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "cpcontacts.rry.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "amuuzC0W4wRrtnDoPagKiAAAAZE"]
[Thu Jul 30 15:06:36.724428 2026] [security2:error] [pid 87988:tid 88233] [client 20.226.5.174:34305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/database.php"] [unique_id "amuuzDipAwzptuCxBrhznQAAAX0"]
[Thu Jul 30 15:06:36.745657 2026] [security2:error] [pid 89520:tid 89688] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuzC0W4wRrtnDoPagKhwABqBM"]
[Thu Jul 30 15:06:38.056501 2026] [security2:error] [pid 87988:tid 88227] [client 20.226.5.174:33744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/db.php"] [unique_id "amuuzjipAwzptuCxBrhzsAAAAXc"]
[Thu Jul 30 15:06:38.151873 2026] [core:notice] [pid 87988:tid 88078] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:38.155718 2026] [security2:error] [pid 87988:tid 88214] [client 47.128.96.152:32718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/article/view/9533"] [unique_id "amuuzTipAwzptuCxBrhzrwABalk"]
[Thu Jul 30 15:06:38.278849 2026] [core:notice] [pid 87988:tid 88027] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:38.366202 2026] [core:notice] [pid 87988:tid 88023] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:38.430875 2026] [core:notice] [pid 87988:tid 88021] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:38.732059 2026] [core:notice] [pid 87988:tid 88163] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:39.375524 2026] [core:notice] [pid 89520:tid 89680] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:39.414861 2026] [security2:error] [pid 87988:tid 88245] [client 20.226.5.174:33752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/default.php"] [unique_id "amuuzzipAwzptuCxBrhzzAAAAYk"]
[Thu Jul 30 15:06:39.906173 2026] [security2:error] [pid 87988:tid 88168] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuuzzipAwzptuCxBrhzyQABPC0"]
[Thu Jul 30 15:06:40.715603 2026] [security2:error] [pid 89520:tid 89693] [client 20.226.5.174:33778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/dropdown.php"] [unique_id "amuu0C0W4wRrtnDoPagKrAAAAa0"]
[Thu Jul 30 15:06:41.507948 2026] [core:notice] [pid 89520:tid 89674] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:41.511341 2026] [security2:error] [pid 89520:tid 89674] [client 66.249.79.237:53331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/561/3604"] [unique_id "amuu0S0W4wRrtnDoPagKswAAAZo"]
[Thu Jul 30 15:06:41.793744 2026] [core:notice] [pid 89520:tid 89705] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:41.805584 2026] [security2:error] [pid 89520:tid 89774] [client 20.226.5.174:33735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/edit.php"] [unique_id "amuu0S0W4wRrtnDoPagKuAAAAf4"]
[Thu Jul 30 15:06:42.128390 2026] [core:notice] [pid 87988:tid 88142] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:42.602094 2026] [core:notice] [pid 89520:tid 89751] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:42.991297 2026] [core:notice] [pid 87988:tid 88152] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:42.994399 2026] [security2:error] [pid 87988:tid 88152] [client 66.249.65.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/83"] [unique_id "amuu0jipAwzptuCxBrhz-AAAASw"]
[Thu Jul 30 15:06:43.067079 2026] [security2:error] [pid 87988:tid 88160] [client 20.226.5.174:33767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/f35.php"] [unique_id "amuu0zipAwzptuCxBrh0AAAAATQ"]
[Thu Jul 30 15:06:43.310668 2026] [core:notice] [pid 89520:tid 89716] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:44.188621 2026] [security2:error] [pid 87988:tid 88202] [client 20.226.5.174:33758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.azureskyfilms.com"] [uri "/f7.php"] [unique_id "amuu1DipAwzptuCxBrh0DAAAAV4"]
[Thu Jul 30 15:06:44.935722 2026] [security2:error] [pid 89520:tid 89554] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu1C0W4wRrtnDoPagK1AAByBg"]
[Thu Jul 30 15:06:44.935916 2026] [security2:error] [pid 89520:tid 89720] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu1C0W4wRrtnDoPagK1AAByBg"]
[Thu Jul 30 15:06:45.099035 2026] [security2:error] [pid 89520:tid 89676] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuu1C0W4wRrtnDoPagK0gAAAZw"]
[Thu Jul 30 15:06:46.478313 2026] [core:notice] [pid 89520:tid 89557] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:46.482544 2026] [security2:error] [pid 89520:tid 89672] [client 66.249.65.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/289"] [unique_id "amuu1i0W4wRrtnDoPagK4QABmBs"]
[Thu Jul 30 15:06:47.406355 2026] [core:notice] [pid 87988:tid 88150] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:47.409780 2026] [security2:error] [pid 87988:tid 88150] [client 66.249.79.8:39749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3800/1840"] [unique_id "amuu1zipAwzptuCxBrh0MAAAASo"]
[Thu Jul 30 15:06:47.416745 2026] [security2:error] [pid 87988:tid 88174] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuu1jipAwzptuCxBrh0JgABQgQ"]
[Thu Jul 30 15:06:48.035772 2026] [security2:error] [pid 87988:tid 88187] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuu1zipAwzptuCxBrh0NAAAAU8"]
[Thu Jul 30 15:06:48.403488 2026] [core:notice] [pid 87988:tid 88189] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:49.723468 2026] [proxy:error] [pid 89520:tid 89704] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:06:49.723535 2026] [proxy_http:error] [pid 89520:tid 89704] [client 34.224.175.62:11704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:06:49.724111 2026] [proxy:error] [pid 89520:tid 89704] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:06:49.724158 2026] [proxy_http:error] [pid 89520:tid 89704] [client 34.224.175.62:11704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:06:49.856929 2026] [proxy:error] [pid 87988:tid 88154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:06:49.857011 2026] [proxy_http:error] [pid 87988:tid 88154] [client 32.194.121.99:63534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:06:49.857585 2026] [proxy:error] [pid 87988:tid 88154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:06:49.857631 2026] [proxy_http:error] [pid 87988:tid 88154] [client 32.194.121.99:63534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:06:51.193913 2026] [security2:error] [pid 87988:tid 88041] [remote 103.124.95.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saiqon.net"] [uri "/xmlrpc.php"] [unique_id "amuu2jipAwzptuCxBrh0YwABVTQ"]
[Thu Jul 30 15:06:51.194191 2026] [security2:error] [pid 87988:tid 88193] [client 103.124.95.161:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "saiqon.net"] [uri "/xmlrpc.php"] [unique_id "amuu2jipAwzptuCxBrh0YwABVTQ"]
[Thu Jul 30 15:06:51.560394 2026] [security2:error] [pid 89520:tid 89789] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuu2i0W4wRrtnDoPagLDAACDR8"]
[Thu Jul 30 15:06:52.139705 2026] [security2:error] [pid 87988:tid 88219] [client 74.7.244.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.qpsuae.com"] [uri "/index.php"] [unique_id "amuu2zipAwzptuCxBrh0ZgABb2k"]
[Thu Jul 30 15:06:52.139733 2026] [security2:error] [pid 87988:tid 88219] [client 74.7.244.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.qpsuae.com"] [uri "/index.php"] [unique_id "amuu2zipAwzptuCxBrh0ZgABb2k"]
[Thu Jul 30 15:06:53.709295 2026] [security2:error] [pid 87988:tid 88208] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuu3TipAwzptuCxBrh0iQAAAWQ"]
[Thu Jul 30 15:06:54.285672 2026] [core:notice] [pid 87988:tid 88128] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:06:55.225508 2026] [security2:error] [pid 89520:tid 89700] [client 127.0.0.1:16446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuu3y0W4wRrtnDoPagLKAAAAbQ"]
[Thu Jul 30 15:06:55.225603 2026] [security2:error] [pid 89520:tid 89679] [client 74.7.244.35:51278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.mahsudtransportandbuildingdemolition.business"] [uri "/robots.txt"] [unique_id "amuu3y0W4wRrtnDoPagLJwABn3M"]
[Thu Jul 30 15:06:55.469011 2026] [security2:error] [pid 89520:tid 89556] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu3y0W4wRrtnDoPagLKwAB3Bo"]
[Thu Jul 30 15:06:55.469158 2026] [security2:error] [pid 89520:tid 89740] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu3y0W4wRrtnDoPagLKwAB3Bo"]
[Thu Jul 30 15:06:55.528512 2026] [security2:error] [pid 89520:tid 89781] [client 37.140.254.18:23203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.254.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/archivarix.cms.php"] [unique_id "amuu3y0W4wRrtnDoPagLKQAAAgU"]
[Thu Jul 30 15:06:56.227440 2026] [security2:error] [pid 89520:tid 89761] [client 74.7.230.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-82d9fe69.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuu3y0W4wRrtnDoPagLMQAAAfE"]
[Thu Jul 30 15:06:56.228131 2026] [security2:error] [pid 89520:tid 89705] [client 74.7.230.7:39026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-82d9fe69.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuu3y0W4wRrtnDoPagLLwABuRU"]
[Thu Jul 30 15:06:57.830117 2026] [security2:error] [pid 89520:tid 89773] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuu4S0W4wRrtnDoPagLUQAAAf0"]
[Thu Jul 30 15:06:58.603458 2026] [fcgid:warn] [pid 89520:tid 89703] (70014)End of file found: [client 66.132.172.131:4922] mod_fcgid: can't get data from http client
[Thu Jul 30 15:07:00.381561 2026] [security2:error] [pid 87988:tid 88000] [remote 154.26.129.62:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.129.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/wp-login.php"] [unique_id "amuu5DipAwzptuCxBrh03gABHQs"]
[Thu Jul 30 15:07:00.773839 2026] [core:notice] [pid 89520:tid 89581] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:00.881766 2026] [security2:error] [pid 89520:tid 89578] [remote 57.141.18.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuu5C0W4wRrtnDoPagLdAAB0zA"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=supreme&filter_materials=aluminum%2Ccarbon%2Cdenim%2Clinen%2Cnylon%2Cpolyester%2Csteel&rating=5&status=instock&unfilter=1&orderby=popularity
[Thu Jul 30 15:07:00.932902 2026] [core:notice] [pid 89520:tid 89647] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:01.098172 2026] [core:notice] [pid 89520:tid 89584] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:01.340349 2026] [core:notice] [pid 89520:tid 89575] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:01.345327 2026] [security2:error] [pid 89520:tid 89725] [client 150.109.120.65:48526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/agrijati/issue/view/291"] [unique_id "amuu5S0W4wRrtnDoPagLeAABzS0"]
[Thu Jul 30 15:07:01.643396 2026] [security2:error] [pid 89520:tid 89579] [remote 57.141.18.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuu5S0W4wRrtnDoPagLfwAByjE"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_brand=supreme&filter_materials=aluminum%2Ccarbon%2Cdenim%2Clinen%2Cnylon%2Cpolyester%2Csteel&rating=5&status=instock&unfilter=1&orderby=popularity
[Thu Jul 30 15:07:02.326400 2026] [security2:error] [pid 89520:tid 89726] [client 20.91.199.21:33406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/json.php"] [unique_id "amuu5i0W4wRrtnDoPagLhwAAAc4"]
[Thu Jul 30 15:07:02.367737 2026] [core:notice] [pid 87988:tid 88008] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.683309 2026] [core:notice] [pid 87988:tid 88009] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.683331 2026] [core:notice] [pid 87988:tid 88010] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.683364 2026] [core:notice] [pid 87988:tid 88101] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.683392 2026] [core:notice] [pid 87988:tid 87990] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.683414 2026] [core:notice] [pid 87988:tid 88030] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.683532 2026] [core:notice] [pid 87988:tid 88038] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.684071 2026] [core:notice] [pid 87988:tid 88024] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.684071 2026] [core:notice] [pid 87988:tid 87999] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.684113 2026] [core:notice] [pid 87988:tid 88019] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:02.843368 2026] [security2:error] [pid 87988:tid 88173] [client 20.91.199.21:11097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/mini.php"] [unique_id "amuu5jipAwzptuCxBrh1AgAAAUE"]
[Thu Jul 30 15:07:03.596021 2026] [core:notice] [pid 89520:tid 89753] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:05.102598 2026] [security2:error] [pid 89520:tid 89733] [client 37.77.56.246:38978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuu6C0W4wRrtnDoPagL1AAAAdU"]
[Thu Jul 30 15:07:05.102726 2026] [security2:error] [pid 89520:tid 89733] [client 37.77.56.246:38978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuu6C0W4wRrtnDoPagL1AAAAdU"]
[Thu Jul 30 15:07:05.272883 2026] [core:notice] [pid 89520:tid 89630] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:05.276715 2026] [security2:error] [pid 89520:tid 89670] [client 66.249.74.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/100/101"] [unique_id "amuu6S0W4wRrtnDoPagL1gABlmM"]
[Thu Jul 30 15:07:06.026901 2026] [security2:error] [pid 87988:tid 88059] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu6jipAwzptuCxBrh1JgABUEY"]
[Thu Jul 30 15:07:06.027100 2026] [security2:error] [pid 87988:tid 88188] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu6jipAwzptuCxBrh1JgABUEY"]
[Thu Jul 30 15:07:06.856000 2026] [security2:error] [pid 89520:tid 89775] [client 20.91.199.21:46474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/chosen.php"] [unique_id "amuu6i0W4wRrtnDoPagL7wAAAf8"]
[Thu Jul 30 15:07:08.866727 2026] [security2:error] [pid 89520:tid 89777] [client 20.91.199.21:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/kj.php"] [unique_id "amuu7C0W4wRrtnDoPagMCwAAAgE"]
[Thu Jul 30 15:07:09.018296 2026] [core:notice] [pid 89520:tid 89761] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:09.021723 2026] [security2:error] [pid 89520:tid 89761] [client 66.249.79.230:37647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/download/7448/3013"] [unique_id "amuu7C0W4wRrtnDoPagMCgAAAfE"]
[Thu Jul 30 15:07:09.143508 2026] [security2:error] [pid 89520:tid 89723] [client 20.226.5.174:2118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Avada/licensing/style.php"] [unique_id "amuu7S0W4wRrtnDoPagMEAAAAcs"]
[Thu Jul 30 15:07:09.699706 2026] [security2:error] [pid 89520:tid 89756] [client 20.91.199.21:37049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/wp-files.php"] [unique_id "amuu7S0W4wRrtnDoPagMFwAAAew"]
[Thu Jul 30 15:07:10.166650 2026] [security2:error] [pid 89520:tid 89728] [client 20.226.5.174:2129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/BDKR28_nfbxj7ov.php"] [unique_id "amuu7i0W4wRrtnDoPagMHAAAAdA"]
[Thu Jul 30 15:07:10.174803 2026] [security2:error] [pid 89520:tid 89745] [client 213.152.161.170:44936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuu7i0W4wRrtnDoPagMHQAAAeE"]
[Thu Jul 30 15:07:10.174913 2026] [security2:error] [pid 89520:tid 89745] [client 213.152.161.170:44936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuu7i0W4wRrtnDoPagMHQAAAeE"]
[Thu Jul 30 15:07:10.903790 2026] [security2:error] [pid 89520:tid 89666] [client 20.91.199.21:46486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/wp-setup.php"] [unique_id "amuu7i0W4wRrtnDoPagMIAAAAZI"]
[Thu Jul 30 15:07:11.009787 2026] [security2:error] [pid 87988:tid 88178] [client 172.237.109.114:35098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/maintenance.php"] [unique_id "amuu7zipAwzptuCxBrh1YgAAAUY"]
[Thu Jul 30 15:07:11.138383 2026] [security2:error] [pid 87988:tid 88213] [client 20.226.5.174:2115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/BIBIL.php"] [unique_id "amuu7zipAwzptuCxBrh1ZQAAAWk"]
[Thu Jul 30 15:07:12.111660 2026] [security2:error] [pid 87988:tid 88182] [client 20.226.5.174:2126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Cache.php"] [unique_id "amuu8DipAwzptuCxBrh1bAAAAUo"]
[Thu Jul 30 15:07:13.141831 2026] [security2:error] [pid 89520:tid 89678] [client 20.226.5.174:2114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Cache/Cache.php"] [unique_id "amuu8S0W4wRrtnDoPagMPAAAAZ4"]
[Thu Jul 30 15:07:14.088818 2026] [security2:error] [pid 87988:tid 88190] [client 20.226.5.174:2127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Cache/about.php"] [unique_id "amuu8jipAwzptuCxBrh1gAAAAVI"]
[Thu Jul 30 15:07:15.063704 2026] [security2:error] [pid 89520:tid 89690] [client 20.226.5.174:2131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Cache/dropdown.php"] [unique_id "amuu8y0W4wRrtnDoPagMUQAAAao"]
[Thu Jul 30 15:07:15.639912 2026] [security2:error] [pid 89520:tid 89532] [remote 47.86.33.52:25806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.eow.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuu8y0W4wRrtnDoPagMVgABjwI"]
[Thu Jul 30 15:07:15.730466 2026] [security2:error] [pid 87988:tid 88163] [client 20.91.199.21:37240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/defaults.php"] [unique_id "amuu8zipAwzptuCxBrh1jwAAATc"]
[Thu Jul 30 15:07:15.793014 2026] [core:notice] [pid 89520:tid 89682] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:16.031238 2026] [security2:error] [pid 87988:tid 88175] [client 20.226.5.174:2119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Cache/index.php"] [unique_id "amuu9DipAwzptuCxBrh1lwAAAUM"]
[Thu Jul 30 15:07:16.412553 2026] [core:notice] [pid 87988:tid 88108] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:16.713306 2026] [security2:error] [pid 89520:tid 89535] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu9C0W4wRrtnDoPagMXgABmAU"]
[Thu Jul 30 15:07:16.713456 2026] [security2:error] [pid 89520:tid 89672] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu9C0W4wRrtnDoPagMXgABmAU"]
[Thu Jul 30 15:07:17.058358 2026] [security2:error] [pid 87988:tid 88145] [client 20.226.5.174:2130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Cache/upfile.php"] [unique_id "amuu9TipAwzptuCxBrh1pAAAASU"]
[Thu Jul 30 15:07:18.020635 2026] [security2:error] [pid 89520:tid 89677] [client 20.226.5.174:2124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Canonical.php"] [unique_id "amuu9i0W4wRrtnDoPagMcQAAAZ0"]
[Thu Jul 30 15:07:18.360352 2026] [security2:error] [pid 87988:tid 88006] [remote 57.141.0.34:28524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/information/readers"] [unique_id "amuu9jipAwzptuCxBrh1tAABaRE"]
[Thu Jul 30 15:07:18.578019 2026] [security2:error] [pid 87988:tid 88132] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuu9TipAwzptuCxBrh1sAAAARg"]
[Thu Jul 30 15:07:18.916473 2026] [security2:error] [pid 87988:tid 88141] [client 20.226.5.174:2116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Capi.php"] [unique_id "amuu9jipAwzptuCxBrh1vQAAASE"]
[Thu Jul 30 15:07:19.911997 2026] [security2:error] [pid 87988:tid 88148] [client 20.226.5.174:2135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Content/Type/index.php"] [unique_id "amuu9zipAwzptuCxBrh1xwAAASg"]
[Thu Jul 30 15:07:20.313200 2026] [security2:error] [pid 89520:tid 89785] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuu9y0W4wRrtnDoPagMhQAAAgk"]
[Thu Jul 30 15:07:20.731493 2026] [security2:error] [pid 89520:tid 89769] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuu-C0W4wRrtnDoPagMigAAAfk"]
[Thu Jul 30 15:07:21.045048 2026] [core:notice] [pid 89520:tid 89548] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:21.209840 2026] [security2:error] [pid 87988:tid 88204] [client 20.226.5.174:2113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Content/Type/wp-login.php"] [unique_id "amuu-DipAwzptuCxBrh11QAAAWA"]
[Thu Jul 30 15:07:21.356218 2026] [core:notice] [pid 89520:tid 89544] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:21.383347 2026] [security2:error] [pid 87988:tid 88171] [client 20.91.199.21:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/gtc.php"] [unique_id "amuu-TipAwzptuCxBrh18QAAAT8"]
[Thu Jul 30 15:07:22.039637 2026] [security2:error] [pid 89520:tid 89743] [client 20.91.199.21:35597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/import.php"] [unique_id "amuu-i0W4wRrtnDoPagMogAAAd8"]
[Thu Jul 30 15:07:22.144144 2026] [core:notice] [pid 87988:tid 88245] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:22.188447 2026] [security2:error] [pid 89520:tid 89712] [client 20.226.5.174:2149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Content/index.php"] [unique_id "amuu-i0W4wRrtnDoPagMqAAAAcA"]
[Thu Jul 30 15:07:23.130280 2026] [security2:error] [pid 87988:tid 88231] [client 20.226.5.174:2117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Cookie/wp-login.php"] [unique_id "amuu-zipAwzptuCxBrh2DgAAAXs"]
[Thu Jul 30 15:07:23.543397 2026] [security2:error] [pid 89520:tid 89716] [client 20.91.199.21:10782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/lufix.php"] [unique_id "amuu-y0W4wRrtnDoPagMtQAAAcQ"]
[Thu Jul 30 15:07:24.110517 2026] [security2:error] [pid 87988:tid 88207] [client 20.226.5.174:2137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Core-Econ/index.php"] [unique_id "amuu_DipAwzptuCxBrh2FgAAAWM"]
[Thu Jul 30 15:07:24.197910 2026] [security2:error] [pid 87988:tid 88174] [client 20.91.199.21:10761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.northyorksheridanmall.com"] [uri "/Geforce.php"] [unique_id "amuu_DipAwzptuCxBrh2GAAAAUI"]
[Thu Jul 30 15:07:25.085414 2026] [security2:error] [pid 89520:tid 89760] [client 20.226.5.174:2128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Core-Econ/upH.php"] [unique_id "amuu_S0W4wRrtnDoPagMwQAAAfA"]
[Thu Jul 30 15:07:25.106213 2026] [core:notice] [pid 87988:tid 88232] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:25.109397 2026] [security2:error] [pid 87988:tid 88232] [client 66.249.79.1:36905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/3311"] [unique_id "amuu_DipAwzptuCxBrh2JQAAAXw"]
[Thu Jul 30 15:07:25.534132 2026] [core:notice] [pid 89520:tid 89667] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:25.623836 2026] [security2:error] [pid 89520:tid 89769] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuu_S0W4wRrtnDoPagMwAAB-QE"]
[Thu Jul 30 15:07:26.179694 2026] [security2:error] [pid 89520:tid 89755] [client 20.226.5.174:2122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Core-EconX/up.php"] [unique_id "amuu_i0W4wRrtnDoPagMygAAAes"]
[Thu Jul 30 15:07:26.672122 2026] [security2:error] [pid 89520:tid 89747] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuu_i0W4wRrtnDoPagMzwAAAeM"]
[Thu Jul 30 15:07:26.672234 2026] [security2:error] [pid 89520:tid 89747] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuu_i0W4wRrtnDoPagMzwAAAeM"]
[Thu Jul 30 15:07:27.088337 2026] [security2:error] [pid 87988:tid 88176] [client 87.99.135.61:49066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "emmelevate.club"] [uri "/index.php"] [unique_id "amuu_jipAwzptuCxBrh2RgAAAQ0"]
[Thu Jul 30 15:07:27.136171 2026] [security2:error] [pid 87988:tid 88175] [client 87.99.135.61:53550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "emmelevate.club"] [uri "/index.php"] [unique_id "amuu_jipAwzptuCxBrh2RwAAAWA"]
[Thu Jul 30 15:07:27.176638 2026] [security2:error] [pid 89520:tid 89700] [client 20.226.5.174:2161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/DJP9.php"] [unique_id "amuu_y0W4wRrtnDoPagM2AAAAbQ"]
[Thu Jul 30 15:07:27.492149 2026] [security2:error] [pid 87988:tid 88004] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu_zipAwzptuCxBrh2WQABeQ8"]
[Thu Jul 30 15:07:27.492294 2026] [security2:error] [pid 87988:tid 88229] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuu_zipAwzptuCxBrh2WQABeQ8"]
[Thu Jul 30 15:07:27.531460 2026] [security2:error] [pid 89520:tid 89774] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuu_i0W4wRrtnDoPagM0QAB_hA"]
[Thu Jul 30 15:07:27.972018 2026] [security2:error] [pid 89520:tid 89704] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuu_y0W4wRrtnDoPagM3QAAAbg"]
[Thu Jul 30 15:07:27.972104 2026] [security2:error] [pid 89520:tid 89704] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuu_y0W4wRrtnDoPagM3QAAAbg"]
[Thu Jul 30 15:07:28.135228 2026] [security2:error] [pid 89520:tid 89719] [client 20.226.5.174:2143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff.php"] [unique_id "amuvAC0W4wRrtnDoPagM4AAAAcc"]
[Thu Jul 30 15:07:28.255761 2026] [security2:error] [pid 89520:tid 89768] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuu_y0W4wRrtnDoPagM2QAB-CE"]
[Thu Jul 30 15:07:28.337295 2026] [security2:error] [pid 87988:tid 88233] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/x.php"] [unique_id "amuvADipAwzptuCxBrh2ZgAAAX0"]
[Thu Jul 30 15:07:28.337454 2026] [security2:error] [pid 87988:tid 88233] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/x.php"] [unique_id "amuvADipAwzptuCxBrh2ZgAAAX0"]
[Thu Jul 30 15:07:28.598088 2026] [security2:error] [pid 87988:tid 88165] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/mgrr.php"] [unique_id "amuvADipAwzptuCxBrh2bwAAATk"]
[Thu Jul 30 15:07:28.598190 2026] [security2:error] [pid 87988:tid 88165] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/mgrr.php"] [unique_id "amuvADipAwzptuCxBrh2bwAAATk"]
[Thu Jul 30 15:07:28.886205 2026] [security2:error] [pid 87988:tid 88188] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/domvf.php"] [unique_id "amuvADipAwzptuCxBrh2cwAAAVA"]
[Thu Jul 30 15:07:28.886289 2026] [security2:error] [pid 87988:tid 88188] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/domvf.php"] [unique_id "amuvADipAwzptuCxBrh2cwAAAVA"]
[Thu Jul 30 15:07:29.105857 2026] [security2:error] [pid 87988:tid 88203] [client 20.226.5.174:2146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Engine.php"] [unique_id "amuvATipAwzptuCxBrh2egAAAV8"]
[Thu Jul 30 15:07:29.162764 2026] [security2:error] [pid 87988:tid 88217] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/yup.php"] [unique_id "amuvATipAwzptuCxBrh2ewAAAW0"]
[Thu Jul 30 15:07:29.162886 2026] [security2:error] [pid 87988:tid 88217] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/yup.php"] [unique_id "amuvATipAwzptuCxBrh2ewAAAW0"]
[Thu Jul 30 15:07:29.406941 2026] [security2:error] [pid 87988:tid 88208] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/X.php"] [unique_id "amuvATipAwzptuCxBrh2fwAAAWQ"]
[Thu Jul 30 15:07:29.407106 2026] [security2:error] [pid 87988:tid 88208] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/X.php"] [unique_id "amuvATipAwzptuCxBrh2fwAAAWQ"]
[Thu Jul 30 15:07:29.777649 2026] [security2:error] [pid 89520:tid 89762] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuvAS0W4wRrtnDoPagM5QAAAfI"]
[Thu Jul 30 15:07:29.777765 2026] [security2:error] [pid 89520:tid 89762] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amuvAS0W4wRrtnDoPagM5QAAAfI"]
[Thu Jul 30 15:07:30.008785 2026] [security2:error] [pid 87988:tid 88184] [client 173.252.70.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ciunews.com"] [uri "/index.php"] [unique_id "amuvADipAwzptuCxBrh2YwAAAUw"]
[Thu Jul 30 15:07:30.032390 2026] [security2:error] [pid 89520:tid 89727] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/gec.php"] [unique_id "amuvAi0W4wRrtnDoPagM5wAAAc8"]
[Thu Jul 30 15:07:30.032483 2026] [security2:error] [pid 89520:tid 89727] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/gec.php"] [unique_id "amuvAi0W4wRrtnDoPagM5wAAAc8"]
[Thu Jul 30 15:07:30.120404 2026] [security2:error] [pid 87988:tid 88128] [client 173.252.70.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ciunews.com"] [uri "/index.php"] [unique_id "amuvATipAwzptuCxBrh2hwAAARQ"]
[Thu Jul 30 15:07:30.150007 2026] [security2:error] [pid 87988:tid 88199] [client 20.226.5.174:2138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Engine/about.php"] [unique_id "amuvAjipAwzptuCxBrh2jwAAAVs"]
[Thu Jul 30 15:07:30.614902 2026] [security2:error] [pid 87988:tid 88221] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/sky.php"] [unique_id "amuvAjipAwzptuCxBrh2mQAAAXE"]
[Thu Jul 30 15:07:30.615021 2026] [security2:error] [pid 87988:tid 88221] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/sky.php"] [unique_id "amuvAjipAwzptuCxBrh2mQAAAXE"]
[Thu Jul 30 15:07:30.866683 2026] [security2:error] [pid 87988:tid 88123] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/fffm.php"] [unique_id "amuvAjipAwzptuCxBrh2mwAAAQ8"]
[Thu Jul 30 15:07:30.867026 2026] [security2:error] [pid 87988:tid 88123] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/fffm.php"] [unique_id "amuvAjipAwzptuCxBrh2mwAAAQ8"]
[Thu Jul 30 15:07:31.066255 2026] [security2:error] [pid 89520:tid 89670] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvAi0W4wRrtnDoPagM6gABlhY"]
[Thu Jul 30 15:07:31.066701 2026] [security2:error] [pid 89520:tid 89773] [client 74.7.228.14:60852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "frg.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuvAy0W4wRrtnDoPagM7gAAAf0"]
[Thu Jul 30 15:07:31.121389 2026] [security2:error] [pid 87988:tid 88153] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/sixxis.php"] [unique_id "amuvAzipAwzptuCxBrh2ogAAAS0"]
[Thu Jul 30 15:07:31.121493 2026] [security2:error] [pid 87988:tid 88153] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/sixxis.php"] [unique_id "amuvAzipAwzptuCxBrh2ogAAAS0"]
[Thu Jul 30 15:07:31.129613 2026] [security2:error] [pid 87988:tid 88005] [remote 74.7.227.39:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuvAzipAwzptuCxBrh2owABJxA"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/woozone/aa-framework
[Thu Jul 30 15:07:31.158499 2026] [security2:error] [pid 89520:tid 89707] [client 20.226.5.174:2132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Engine/admin-ajax.php"] [unique_id "amuvAy0W4wRrtnDoPagM7wAAAbs"]
[Thu Jul 30 15:07:31.364152 2026] [security2:error] [pid 89520:tid 89720] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/yj09.php"] [unique_id "amuvAy0W4wRrtnDoPagM8QAAAcg"]
[Thu Jul 30 15:07:31.364313 2026] [security2:error] [pid 89520:tid 89720] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/yj09.php"] [unique_id "amuvAy0W4wRrtnDoPagM8QAAAcg"]
[Thu Jul 30 15:07:31.668004 2026] [security2:error] [pid 87988:tid 88220] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/k.php"] [unique_id "amuvAzipAwzptuCxBrh2qwAAAXA"]
[Thu Jul 30 15:07:31.668141 2026] [security2:error] [pid 87988:tid 88220] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/k.php"] [unique_id "amuvAzipAwzptuCxBrh2qwAAAXA"]
[Thu Jul 30 15:07:31.937445 2026] [security2:error] [pid 87988:tid 88216] [client 173.252.70.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ciunews.com"] [uri "/index.php"] [unique_id "amuvAzipAwzptuCxBrh2rAAAAWw"]
[Thu Jul 30 15:07:31.980860 2026] [security2:error] [pid 89520:tid 89780] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/k2.php"] [unique_id "amuvAy0W4wRrtnDoPagM9gAAAgQ"]
[Thu Jul 30 15:07:31.981015 2026] [security2:error] [pid 89520:tid 89780] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/k2.php"] [unique_id "amuvAy0W4wRrtnDoPagM9gAAAgQ"]
[Thu Jul 30 15:07:32.135449 2026] [security2:error] [pid 87988:tid 88223] [client 20.226.5.174:2121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Engine/com_search.php"] [unique_id "amuvBDipAwzptuCxBrh2tAAAAXM"]
[Thu Jul 30 15:07:32.217871 2026] [security2:error] [pid 87988:tid 88141] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/w.php"] [unique_id "amuvBDipAwzptuCxBrh2tgAAASE"]
[Thu Jul 30 15:07:32.218029 2026] [security2:error] [pid 87988:tid 88141] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/w.php"] [unique_id "amuvBDipAwzptuCxBrh2tgAAASE"]
[Thu Jul 30 15:07:32.466969 2026] [security2:error] [pid 87988:tid 88218] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/fpwch.php"] [unique_id "amuvBDipAwzptuCxBrh2uAAAAW4"]
[Thu Jul 30 15:07:32.467100 2026] [security2:error] [pid 87988:tid 88218] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/fpwch.php"] [unique_id "amuvBDipAwzptuCxBrh2uAAAAW4"]
[Thu Jul 30 15:07:33.169777 2026] [security2:error] [pid 89520:tid 89708] [client 20.226.5.174:2112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Engine/doc.php"] [unique_id "amuvBS0W4wRrtnDoPagNBQAAAbw"]
[Thu Jul 30 15:07:33.174098 2026] [security2:error] [pid 89520:tid 89673] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/w2025.php"] [unique_id "amuvBS0W4wRrtnDoPagNBgAAAZk"]
[Thu Jul 30 15:07:33.174176 2026] [security2:error] [pid 89520:tid 89673] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/w2025.php"] [unique_id "amuvBS0W4wRrtnDoPagNBgAAAZk"]
[Thu Jul 30 15:07:33.345700 2026] [security2:error] [pid 89520:tid 89555] [remote 74.7.243.224:59092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuvBS0W4wRrtnDoPagNCQAB0hk"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:07:33.420746 2026] [security2:error] [pid 87988:tid 88120] [client 173.252.70.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ciunews.com"] [uri "/index.php"] [unique_id "amuvBTipAwzptuCxBrh2xAAAAQw"]
[Thu Jul 30 15:07:33.436700 2026] [security2:error] [pid 87988:tid 88137] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/FWAZ.php"] [unique_id "amuvBTipAwzptuCxBrh2xQAAAR0"]
[Thu Jul 30 15:07:33.436800 2026] [security2:error] [pid 87988:tid 88137] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/FWAZ.php"] [unique_id "amuvBTipAwzptuCxBrh2xQAAAR0"]
[Thu Jul 30 15:07:33.675308 2026] [security2:error] [pid 89520:tid 89758] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/qterm.php"] [unique_id "amuvBS0W4wRrtnDoPagNDgAAAe4"]
[Thu Jul 30 15:07:33.675416 2026] [security2:error] [pid 89520:tid 89758] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/qterm.php"] [unique_id "amuvBS0W4wRrtnDoPagNDgAAAe4"]
[Thu Jul 30 15:07:33.833545 2026] [security2:error] [pid 89520:tid 89702] [client 4.225.203.146:48104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wk/index.php"] [unique_id "amuvBS0W4wRrtnDoPagNEAAAAbY"]
[Thu Jul 30 15:07:33.929142 2026] [security2:error] [pid 89520:tid 89677] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/blurbs.php"] [unique_id "amuvBS0W4wRrtnDoPagNEgAAAZ0"]
[Thu Jul 30 15:07:33.929257 2026] [security2:error] [pid 89520:tid 89677] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/blurbs.php"] [unique_id "amuvBS0W4wRrtnDoPagNEgAAAZ0"]
[Thu Jul 30 15:07:33.944950 2026] [security2:error] [pid 87988:tid 88172] [client 173.252.70.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ciunews.com"] [uri "/index.php"] [unique_id "amuvBTipAwzptuCxBrh20AAAAUA"]
[Thu Jul 30 15:07:34.075099 2026] [security2:error] [pid 87988:tid 88244] [client 172.237.109.114:14324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "alseermarine.com"] [uri "/l.fcgi"] [unique_id "amuvBjipAwzptuCxBrh20QAAAYg"]
[Thu Jul 30 15:07:34.154070 2026] [core:notice] [pid 89520:tid 89761] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:34.210631 2026] [security2:error] [pid 87988:tid 88161] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-ws68.php"] [unique_id "amuvBjipAwzptuCxBrh21wAAATU"]
[Thu Jul 30 15:07:34.210728 2026] [security2:error] [pid 87988:tid 88161] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-ws68.php"] [unique_id "amuvBjipAwzptuCxBrh21wAAATU"]
[Thu Jul 30 15:07:34.263858 2026] [security2:error] [pid 87988:tid 88169] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvBTipAwzptuCxBrh2zQAAAT0"]
[Thu Jul 30 15:07:34.265170 2026] [security2:error] [pid 89520:tid 89696] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvBS0W4wRrtnDoPagNDQAAAbA"]
[Thu Jul 30 15:07:34.304001 2026] [security2:error] [pid 89520:tid 89705] [client 20.226.5.174:2156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Engine/index.php"] [unique_id "amuvBi0W4wRrtnDoPagNFQAAAbk"]
[Thu Jul 30 15:07:34.466195 2026] [security2:error] [pid 87988:tid 88130] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xyn.php"] [unique_id "amuvBjipAwzptuCxBrh22gAAARY"]
[Thu Jul 30 15:07:34.466346 2026] [security2:error] [pid 87988:tid 88130] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xyn.php"] [unique_id "amuvBjipAwzptuCxBrh22gAAARY"]
[Thu Jul 30 15:07:34.715458 2026] [security2:error] [pid 89520:tid 89782] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ccc.php"] [unique_id "amuvBi0W4wRrtnDoPagNFgAAAgY"]
[Thu Jul 30 15:07:34.715562 2026] [security2:error] [pid 89520:tid 89782] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ccc.php"] [unique_id "amuvBi0W4wRrtnDoPagNFgAAAgY"]
[Thu Jul 30 15:07:35.117495 2026] [security2:error] [pid 87988:tid 88128] [client 4.225.203.146:48123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/av.php"] [unique_id "amuvBzipAwzptuCxBrh24wAAARQ"]
[Thu Jul 30 15:07:35.377749 2026] [security2:error] [pid 87988:tid 88123] [client 20.226.5.174:2159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Engine/priv.php"] [unique_id "amuvBzipAwzptuCxBrh26AAAAQ8"]
[Thu Jul 30 15:07:36.736645 2026] [security2:error] [pid 89520:tid 89703] [client 20.226.5.174:2125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Engine/wp-login.php"] [unique_id "amuvCC0W4wRrtnDoPagNNwAAAbc"]
[Thu Jul 30 15:07:37.319325 2026] [security2:error] [pid 87988:tid 88150] [client 85.208.96.204:36888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/14/em-meio-a-protestos-peru-declara-estado-de-emergencia-por-30-dias/"] [unique_id "amuvCTipAwzptuCxBrh3AgAAASo"]
[Thu Jul 30 15:07:37.319455 2026] [security2:error] [pid 87988:tid 88150] [client 85.208.96.204:36888] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/14/em-meio-a-protestos-peru-declara-estado-de-emergencia-por-30-dias/"] [unique_id "amuvCTipAwzptuCxBrh3AgAAASo"]
[Thu Jul 30 15:07:37.756293 2026] [security2:error] [pid 89520:tid 89667] [client 20.226.5.174:2136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Renderer/about.php"] [unique_id "amuvCS0W4wRrtnDoPagNVQAAAZM"]
[Thu Jul 30 15:07:37.952523 2026] [security2:error] [pid 89520:tid 89672] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/get.php"] [unique_id "amuvCS0W4wRrtnDoPagNXwAAAZg"]
[Thu Jul 30 15:07:37.952616 2026] [security2:error] [pid 89520:tid 89672] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/get.php"] [unique_id "amuvCS0W4wRrtnDoPagNXwAAAZg"]
[Thu Jul 30 15:07:38.287784 2026] [security2:error] [pid 87988:tid 88133] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/images.php"] [unique_id "amuvCjipAwzptuCxBrh3EQAAARk"]
[Thu Jul 30 15:07:38.287901 2026] [security2:error] [pid 87988:tid 88133] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/images.php"] [unique_id "amuvCjipAwzptuCxBrh3EQAAARk"]
[Thu Jul 30 15:07:38.304777 2026] [security2:error] [pid 89520:tid 89591] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvCi0W4wRrtnDoPagNZgAB3D0"]
[Thu Jul 30 15:07:38.304957 2026] [security2:error] [pid 89520:tid 89740] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvCi0W4wRrtnDoPagNZgAB3D0"]
[Thu Jul 30 15:07:38.629373 2026] [security2:error] [pid 89520:tid 89677] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/alls.php"] [unique_id "amuvCi0W4wRrtnDoPagNaQAAAZ0"]
[Thu Jul 30 15:07:38.629481 2026] [security2:error] [pid 89520:tid 89677] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/alls.php"] [unique_id "amuvCi0W4wRrtnDoPagNaQAAAZ0"]
[Thu Jul 30 15:07:38.839038 2026] [security2:error] [pid 89520:tid 89757] [client 20.226.5.174:2120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Renderer/alfa-rex.php"] [unique_id "amuvCi0W4wRrtnDoPagNbQAAAe0"]
[Thu Jul 30 15:07:38.885415 2026] [security2:error] [pid 87988:tid 88198] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/coffexium.php"] [unique_id "amuvCjipAwzptuCxBrh3GgAAAVo"]
[Thu Jul 30 15:07:38.885547 2026] [security2:error] [pid 87988:tid 88198] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/coffexium.php"] [unique_id "amuvCjipAwzptuCxBrh3GgAAAVo"]
[Thu Jul 30 15:07:39.138339 2026] [security2:error] [pid 87988:tid 88146] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/red.php"] [unique_id "amuvCzipAwzptuCxBrh3IwAAASY"]
[Thu Jul 30 15:07:39.138481 2026] [security2:error] [pid 87988:tid 88146] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/red.php"] [unique_id "amuvCzipAwzptuCxBrh3IwAAASY"]
[Thu Jul 30 15:07:39.391447 2026] [proxy:error] [pid 87988:tid 88175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:39.391523 2026] [proxy_http:error] [pid 87988:tid 88175] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:39.392346 2026] [proxy:error] [pid 87988:tid 88175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:39.392396 2026] [proxy_http:error] [pid 87988:tid 88175] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:39.392507 2026] [security2:error] [pid 87988:tid 88175] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvCzipAwzptuCxBrh3JAAAAUM"]
[Thu Jul 30 15:07:39.519133 2026] [security2:error] [pid 89520:tid 89698] [client 74.7.230.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.jgp.fxh.temporary.site"] [uri "/index.php"] [unique_id "amuvCS0W4wRrtnDoPagNXgAAAbI"]
[Thu Jul 30 15:07:39.519816 2026] [security2:error] [pid 89520:tid 89693] [client 74.7.230.3:48766] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.jgp.fxh.temporary.site"] [uri "/robots.txt"] [unique_id "amuvCS0W4wRrtnDoPagNXAABrUI"]
[Thu Jul 30 15:07:39.636567 2026] [security2:error] [pid 89520:tid 89719] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuvCy0W4wRrtnDoPagNdAAAAcc"]
[Thu Jul 30 15:07:39.636690 2026] [security2:error] [pid 89520:tid 89719] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amuvCy0W4wRrtnDoPagNdAAAAcc"]
[Thu Jul 30 15:07:39.699871 2026] [security2:error] [pid 89520:tid 89772] [client 4.225.203.146:35978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/mini.php"] [unique_id "amuvCy0W4wRrtnDoPagNdQAAAfw"]
[Thu Jul 30 15:07:39.852827 2026] [security2:error] [pid 89520:tid 89777] [client 20.226.5.174:2152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Renderer/index.php"] [unique_id "amuvCy0W4wRrtnDoPagNeQAAAgE"]
[Thu Jul 30 15:07:39.881102 2026] [proxy:error] [pid 87988:tid 88229] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:39.881170 2026] [proxy_http:error] [pid 87988:tid 88229] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:39.881741 2026] [proxy:error] [pid 87988:tid 88229] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:39.881783 2026] [proxy_http:error] [pid 87988:tid 88229] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:39.881872 2026] [security2:error] [pid 87988:tid 88229] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvCzipAwzptuCxBrh3KwAAAXk"]
[Thu Jul 30 15:07:40.127873 2026] [proxy:error] [pid 89520:tid 89699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:40.127964 2026] [proxy_http:error] [pid 89520:tid 89699] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:40.128864 2026] [proxy:error] [pid 89520:tid 89699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:40.128931 2026] [proxy_http:error] [pid 89520:tid 89699] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:40.129074 2026] [security2:error] [pid 89520:tid 89699] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvDC0W4wRrtnDoPagNfgAAAbM"]
[Thu Jul 30 15:07:40.388777 2026] [security2:error] [pid 89520:tid 89741] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/index.php"] [unique_id "amuvDC0W4wRrtnDoPagNgwAAAd0"]
[Thu Jul 30 15:07:40.388928 2026] [security2:error] [pid 89520:tid 89741] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/index.php"] [unique_id "amuvDC0W4wRrtnDoPagNgwAAAd0"]
[Thu Jul 30 15:07:40.633117 2026] [security2:error] [pid 87988:tid 88237] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/admin.php"] [unique_id "amuvDDipAwzptuCxBrh3OAAAAYE"]
[Thu Jul 30 15:07:40.633285 2026] [security2:error] [pid 87988:tid 88237] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/admin.php"] [unique_id "amuvDDipAwzptuCxBrh3OAAAAYE"]
[Thu Jul 30 15:07:40.856239 2026] [security2:error] [pid 87988:tid 88195] [client 20.226.5.174:2142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/Renderer/wp-login.php"] [unique_id "amuvDDipAwzptuCxBrh3OgAAAVc"]
[Thu Jul 30 15:07:40.888154 2026] [security2:error] [pid 89520:tid 89746] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/177.php"] [unique_id "amuvDC0W4wRrtnDoPagNiQAAAeI"]
[Thu Jul 30 15:07:40.888246 2026] [security2:error] [pid 89520:tid 89746] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/177.php"] [unique_id "amuvDC0W4wRrtnDoPagNiQAAAeI"]
[Thu Jul 30 15:07:41.056209 2026] [core:notice] [pid 89520:tid 89614] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:41.059812 2026] [security2:error] [pid 89520:tid 89682] [client 66.249.65.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/273"] [unique_id "amuvDS0W4wRrtnDoPagNjQABolQ"]
[Thu Jul 30 15:07:41.126457 2026] [security2:error] [pid 87988:tid 88178] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/199.php"] [unique_id "amuvDTipAwzptuCxBrh3PwAAAUY"]
[Thu Jul 30 15:07:41.126568 2026] [security2:error] [pid 87988:tid 88178] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/199.php"] [unique_id "amuvDTipAwzptuCxBrh3PwAAAUY"]
[Thu Jul 30 15:07:41.257102 2026] [core:notice] [pid 89520:tid 89583] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:41.372174 2026] [security2:error] [pid 87988:tid 88218] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file52.php"] [unique_id "amuvDTipAwzptuCxBrh3QgAAAW4"]
[Thu Jul 30 15:07:41.372301 2026] [security2:error] [pid 87988:tid 88218] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file52.php"] [unique_id "amuvDTipAwzptuCxBrh3QgAAAW4"]
[Thu Jul 30 15:07:41.624213 2026] [security2:error] [pid 87988:tid 88150] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/geck.php"] [unique_id "amuvDTipAwzptuCxBrh3SAAAASo"]
[Thu Jul 30 15:07:41.624322 2026] [security2:error] [pid 87988:tid 88150] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/geck.php"] [unique_id "amuvDTipAwzptuCxBrh3SAAAASo"]
[Thu Jul 30 15:07:41.702402 2026] [security2:error] [pid 89520:tid 89703] [client 4.225.203.146:16079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/aa.php"] [unique_id "amuvDS0W4wRrtnDoPagNmAAAAbc"]
[Thu Jul 30 15:07:41.723948 2026] [security2:error] [pid 87988:tid 88031] [remote 220.181.108.84:31116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/offres-demploi-2/stafff.php"] [unique_id "amuvDTipAwzptuCxBrh3RAABYyo"]
[Thu Jul 30 15:07:41.873893 2026] [security2:error] [pid 89520:tid 89714] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/biufile.php"] [unique_id "amuvDS0W4wRrtnDoPagNmQAAAcI"]
[Thu Jul 30 15:07:41.874031 2026] [security2:error] [pid 89520:tid 89714] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/biufile.php"] [unique_id "amuvDS0W4wRrtnDoPagNmQAAAcI"]
[Thu Jul 30 15:07:41.902412 2026] [security2:error] [pid 87988:tid 88223] [client 20.226.5.174:2133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/Diff/about.php"] [unique_id "amuvDTipAwzptuCxBrh3SQAAAXM"]
[Thu Jul 30 15:07:41.930740 2026] [core:notice] [pid 87988:tid 88094] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:42.119610 2026] [security2:error] [pid 87988:tid 88124] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dejavu.php"] [unique_id "amuvDjipAwzptuCxBrh3TgAAARA"]
[Thu Jul 30 15:07:42.119735 2026] [security2:error] [pid 87988:tid 88124] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dejavu.php"] [unique_id "amuvDjipAwzptuCxBrh3TgAAARA"]
[Thu Jul 30 15:07:42.360393 2026] [security2:error] [pid 89520:tid 89735] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/aaf.php"] [unique_id "amuvDi0W4wRrtnDoPagNngAAAdc"]
[Thu Jul 30 15:07:42.360752 2026] [security2:error] [pid 89520:tid 89735] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/aaf.php"] [unique_id "amuvDi0W4wRrtnDoPagNngAAAdc"]
[Thu Jul 30 15:07:42.594398 2026] [security2:error] [pid 89520:tid 89758] [client 4.225.203.146:33849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/w.php"] [unique_id "amuvDi0W4wRrtnDoPagNogAAAe4"]
[Thu Jul 30 15:07:42.604859 2026] [security2:error] [pid 89520:tid 89761] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ha.php"] [unique_id "amuvDi0W4wRrtnDoPagNowAAAfE"]
[Thu Jul 30 15:07:42.604964 2026] [security2:error] [pid 89520:tid 89761] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ha.php"] [unique_id "amuvDi0W4wRrtnDoPagNowAAAfE"]
[Thu Jul 30 15:07:42.844671 2026] [security2:error] [pid 89520:tid 89711] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/hur.php"] [unique_id "amuvDi0W4wRrtnDoPagNqwAAAb8"]
[Thu Jul 30 15:07:42.844779 2026] [security2:error] [pid 89520:tid 89711] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/hur.php"] [unique_id "amuvDi0W4wRrtnDoPagNqwAAAb8"]
[Thu Jul 30 15:07:43.088084 2026] [security2:error] [pid 87988:tid 88177] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/h02ugyh.php"] [unique_id "amuvDzipAwzptuCxBrh3XgAAAUU"]
[Thu Jul 30 15:07:43.088219 2026] [security2:error] [pid 87988:tid 88177] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/h02ugyh.php"] [unique_id "amuvDzipAwzptuCxBrh3XgAAAUU"]
[Thu Jul 30 15:07:43.088949 2026] [security2:error] [pid 89520:tid 89616] [remote 57.141.0.2:20356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/93381591101/feed/rss2/"] [unique_id "amuvDy0W4wRrtnDoPagNsQABnlY"]
[Thu Jul 30 15:07:43.331506 2026] [security2:error] [pid 89520:tid 89733] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/155.php"] [unique_id "amuvDy0W4wRrtnDoPagNtQAAAdU"]
[Thu Jul 30 15:07:43.331616 2026] [security2:error] [pid 89520:tid 89733] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/155.php"] [unique_id "amuvDy0W4wRrtnDoPagNtQAAAdU"]
[Thu Jul 30 15:07:43.587240 2026] [security2:error] [pid 87988:tid 88173] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ops.php"] [unique_id "amuvDzipAwzptuCxBrh3ZgAAAUE"]
[Thu Jul 30 15:07:43.587350 2026] [security2:error] [pid 87988:tid 88173] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ops.php"] [unique_id "amuvDzipAwzptuCxBrh3ZgAAAUE"]
[Thu Jul 30 15:07:43.825503 2026] [security2:error] [pid 89520:tid 89789] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ingfo.php"] [unique_id "amuvDy0W4wRrtnDoPagNvAAAAg0"]
[Thu Jul 30 15:07:43.825617 2026] [security2:error] [pid 89520:tid 89789] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ingfo.php"] [unique_id "amuvDy0W4wRrtnDoPagNvAAAAg0"]
[Thu Jul 30 15:07:44.080244 2026] [security2:error] [pid 89520:tid 89746] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/error_log.php"] [unique_id "amuvEC0W4wRrtnDoPagNvgAAAeI"]
[Thu Jul 30 15:07:44.080363 2026] [security2:error] [pid 89520:tid 89746] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/error_log.php"] [unique_id "amuvEC0W4wRrtnDoPagNvgAAAeI"]
[Thu Jul 30 15:07:44.218829 2026] [security2:error] [pid 87988:tid 88138] [client 74.7.230.24:37498] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.montageluxuryhotel-com.evm.udi.temporary.site"] [uri "/index.php"] [unique_id "amuvDjipAwzptuCxBrh3VQABHn0"]
[Thu Jul 30 15:07:44.342920 2026] [security2:error] [pid 89520:tid 89739] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/koala.php"] [unique_id "amuvEC0W4wRrtnDoPagNxQAAAds"]
[Thu Jul 30 15:07:44.343049 2026] [security2:error] [pid 89520:tid 89739] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/koala.php"] [unique_id "amuvEC0W4wRrtnDoPagNxQAAAds"]
[Thu Jul 30 15:07:44.568916 2026] [security2:error] [pid 89520:tid 89775] [client 4.225.203.146:62882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/admin.php"] [unique_id "amuvEC0W4wRrtnDoPagNyAAAAf8"]
[Thu Jul 30 15:07:44.617140 2026] [security2:error] [pid 89520:tid 89715] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/mac.php"] [unique_id "amuvEC0W4wRrtnDoPagNygAAAcM"]
[Thu Jul 30 15:07:44.617237 2026] [security2:error] [pid 89520:tid 89715] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/mac.php"] [unique_id "amuvEC0W4wRrtnDoPagNygAAAcM"]
[Thu Jul 30 15:07:44.859264 2026] [security2:error] [pid 89520:tid 89694] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wefile.php"] [unique_id "amuvEC0W4wRrtnDoPagNzgAAAa4"]
[Thu Jul 30 15:07:44.859356 2026] [security2:error] [pid 89520:tid 89694] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wefile.php"] [unique_id "amuvEC0W4wRrtnDoPagNzgAAAa4"]
[Thu Jul 30 15:07:45.109346 2026] [proxy:error] [pid 87988:tid 88201] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:45.109448 2026] [proxy_http:error] [pid 87988:tid 88201] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:45.110020 2026] [proxy:error] [pid 87988:tid 88201] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:45.110065 2026] [proxy_http:error] [pid 87988:tid 88201] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:45.110164 2026] [security2:error] [pid 87988:tid 88201] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvETipAwzptuCxBrh3dAAAAV0"]
[Thu Jul 30 15:07:45.369339 2026] [proxy:error] [pid 87988:tid 88144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:45.369420 2026] [proxy_http:error] [pid 87988:tid 88144] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:45.370259 2026] [proxy:error] [pid 87988:tid 88144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:45.370315 2026] [proxy_http:error] [pid 87988:tid 88144] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:45.370441 2026] [security2:error] [pid 87988:tid 88144] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvETipAwzptuCxBrh3ewAAASQ"]
[Thu Jul 30 15:07:45.576820 2026] [security2:error] [pid 89520:tid 89730] [client 4.225.203.146:51093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuvES0W4wRrtnDoPagN1gAAAdI"]
[Thu Jul 30 15:07:45.627166 2026] [security2:error] [pid 87988:tid 88143] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/makeasmtp.php"] [unique_id "amuvETipAwzptuCxBrh3fAAAASM"]
[Thu Jul 30 15:07:45.627273 2026] [security2:error] [pid 87988:tid 88143] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/makeasmtp.php"] [unique_id "amuvETipAwzptuCxBrh3fAAAASM"]
[Thu Jul 30 15:07:45.871532 2026] [security2:error] [pid 87988:tid 88150] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/2P.php"] [unique_id "amuvETipAwzptuCxBrh3iAAAASo"]
[Thu Jul 30 15:07:45.871673 2026] [security2:error] [pid 87988:tid 88150] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/2P.php"] [unique_id "amuvETipAwzptuCxBrh3iAAAASo"]
[Thu Jul 30 15:07:46.063993 2026] [core:notice] [pid 89520:tid 89635] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:46.193441 2026] [security2:error] [pid 89520:tid 89705] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/.well-known/about.php"] [unique_id "amuvEi0W4wRrtnDoPagN4AAAAbk"]
[Thu Jul 30 15:07:46.193553 2026] [security2:error] [pid 89520:tid 89705] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/.well-known/about.php"] [unique_id "amuvEi0W4wRrtnDoPagN4AAAAbk"]
[Thu Jul 30 15:07:46.434335 2026] [security2:error] [pid 89520:tid 89779] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuvEi0W4wRrtnDoPagN5AAAAgM"]
[Thu Jul 30 15:07:46.434455 2026] [security2:error] [pid 89520:tid 89779] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuvEi0W4wRrtnDoPagN5AAAAgM"]
[Thu Jul 30 15:07:46.673736 2026] [security2:error] [pid 89520:tid 89790] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/system_log.php"] [unique_id "amuvEi0W4wRrtnDoPagN6AAAAg4"]
[Thu Jul 30 15:07:46.673838 2026] [security2:error] [pid 89520:tid 89790] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/system_log.php"] [unique_id "amuvEi0W4wRrtnDoPagN6AAAAg4"]
[Thu Jul 30 15:07:46.812389 2026] [security2:error] [pid 87988:tid 88137] [client 37.77.56.246:57198] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuvEjipAwzptuCxBrh3lAAAAR0"]
[Thu Jul 30 15:07:46.812501 2026] [security2:error] [pid 87988:tid 88137] [client 37.77.56.246:57198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuvEjipAwzptuCxBrh3lAAAAR0"]
[Thu Jul 30 15:07:46.917791 2026] [proxy:error] [pid 89520:tid 89699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:46.917876 2026] [proxy_http:error] [pid 89520:tid 89699] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:46.918733 2026] [proxy:error] [pid 89520:tid 89699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:46.918809 2026] [proxy_http:error] [pid 89520:tid 89699] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:46.918934 2026] [security2:error] [pid 89520:tid 89699] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvEi0W4wRrtnDoPagN7AAAAbM"]
[Thu Jul 30 15:07:46.940850 2026] [security2:error] [pid 87988:tid 88180] [client 4.225.203.146:33812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/m.php"] [unique_id "amuvEjipAwzptuCxBrh3mAAAAUg"]
[Thu Jul 30 15:07:47.204827 2026] [proxy:error] [pid 89520:tid 89722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:47.204900 2026] [proxy_http:error] [pid 89520:tid 89722] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:47.205486 2026] [proxy:error] [pid 89520:tid 89722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:47.205530 2026] [proxy_http:error] [pid 89520:tid 89722] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:47.205619 2026] [security2:error] [pid 89520:tid 89722] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvEy0W4wRrtnDoPagN7QAAAco"]
[Thu Jul 30 15:07:47.427196 2026] [security2:error] [pid 89520:tid 89670] [client 37.77.56.246:57210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuvEy0W4wRrtnDoPagN8wAAAZY"]
[Thu Jul 30 15:07:47.427280 2026] [security2:error] [pid 89520:tid 89670] [client 37.77.56.246:57210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuvEy0W4wRrtnDoPagN8wAAAZY"]
[Thu Jul 30 15:07:47.540157 2026] [security2:error] [pid 89520:tid 89736] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/crgio.php"] [unique_id "amuvEy0W4wRrtnDoPagN9QAAAdg"]
[Thu Jul 30 15:07:47.540263 2026] [security2:error] [pid 89520:tid 89736] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/crgio.php"] [unique_id "amuvEy0W4wRrtnDoPagN9QAAAdg"]
[Thu Jul 30 15:07:47.811293 2026] [security2:error] [pid 87988:tid 88171] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/pucci.php"] [unique_id "amuvEzipAwzptuCxBrh3pQAAAT8"]
[Thu Jul 30 15:07:47.811436 2026] [security2:error] [pid 87988:tid 88171] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/pucci.php"] [unique_id "amuvEzipAwzptuCxBrh3pQAAAT8"]
[Thu Jul 30 15:07:48.051495 2026] [proxy:error] [pid 89520:tid 89682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:48.051568 2026] [proxy_http:error] [pid 89520:tid 89682] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:48.052143 2026] [proxy:error] [pid 89520:tid 89682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:48.052188 2026] [proxy_http:error] [pid 89520:tid 89682] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:48.052270 2026] [security2:error] [pid 89520:tid 89682] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvFC0W4wRrtnDoPagN_AAAAaI"]
[Thu Jul 30 15:07:48.101363 2026] [autoindex:error] [pid 89520:tid 89737] [client 199.45.155.78:0] AH01276: Cannot serve directory /home2/mbmudite/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:07:48.152671 2026] [security2:error] [pid 87988:tid 88234] [client 4.225.203.146:11573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuvEzipAwzptuCxBrh3qAAAAX4"]
[Thu Jul 30 15:07:48.318103 2026] [proxy:error] [pid 89520:tid 89715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:48.318173 2026] [proxy_http:error] [pid 89520:tid 89715] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:48.318806 2026] [proxy:error] [pid 89520:tid 89715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:48.318852 2026] [proxy_http:error] [pid 89520:tid 89715] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:48.318949 2026] [security2:error] [pid 89520:tid 89715] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvFC0W4wRrtnDoPagN_wAAAcM"]
[Thu Jul 30 15:07:48.559251 2026] [security2:error] [pid 89520:tid 89695] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-temp.php"] [unique_id "amuvFC0W4wRrtnDoPagOBwAAAa8"]
[Thu Jul 30 15:07:48.559346 2026] [security2:error] [pid 89520:tid 89695] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-temp.php"] [unique_id "amuvFC0W4wRrtnDoPagOBwAAAa8"]
[Thu Jul 30 15:07:48.812748 2026] [security2:error] [pid 89520:tid 89714] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuvFC0W4wRrtnDoPagODAAAAcI"]
[Thu Jul 30 15:07:48.812851 2026] [security2:error] [pid 89520:tid 89714] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuvFC0W4wRrtnDoPagODAAAAcI"]
[Thu Jul 30 15:07:48.849781 2026] [security2:error] [pid 89520:tid 89633] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvFC0W4wRrtnDoPagODwABvGY"]
[Thu Jul 30 15:07:48.849956 2026] [security2:error] [pid 89520:tid 89708] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvFC0W4wRrtnDoPagODwABvGY"]
[Thu Jul 30 15:07:49.110442 2026] [security2:error] [pid 89520:tid 89758] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/puc.php"] [unique_id "amuvFS0W4wRrtnDoPagOEwAAAe4"]
[Thu Jul 30 15:07:49.110552 2026] [security2:error] [pid 89520:tid 89758] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/puc.php"] [unique_id "amuvFS0W4wRrtnDoPagOEwAAAe4"]
[Thu Jul 30 15:07:49.370653 2026] [security2:error] [pid 89520:tid 89689] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dx.php"] [unique_id "amuvFS0W4wRrtnDoPagOFAAAAak"]
[Thu Jul 30 15:07:49.370773 2026] [security2:error] [pid 89520:tid 89689] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dx.php"] [unique_id "amuvFS0W4wRrtnDoPagOFAAAAak"]
[Thu Jul 30 15:07:49.643655 2026] [proxy:error] [pid 89520:tid 89693] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:49.643723 2026] [proxy_http:error] [pid 89520:tid 89693] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:49.644303 2026] [proxy:error] [pid 89520:tid 89693] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:49.644347 2026] [proxy_http:error] [pid 89520:tid 89693] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:49.644439 2026] [security2:error] [pid 89520:tid 89693] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvFS0W4wRrtnDoPagOHQAAAa0"]
[Thu Jul 30 15:07:49.650948 2026] [autoindex:error] [pid 89520:tid 89712] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:07:49.846367 2026] [security2:error] [pid 89520:tid 89779] [client 4.225.203.146:11570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/classwithtostring.php"] [unique_id "amuvFS0W4wRrtnDoPagOHgAAAgM"]
[Thu Jul 30 15:07:49.904929 2026] [security2:error] [pid 87988:tid 88170] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/7.php"] [unique_id "amuvFTipAwzptuCxBrh3vgAAAT4"]
[Thu Jul 30 15:07:49.905037 2026] [security2:error] [pid 87988:tid 88170] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/7.php"] [unique_id "amuvFTipAwzptuCxBrh3vgAAAT4"]
[Thu Jul 30 15:07:50.030071 2026] [core:notice] [pid 89520:tid 89631] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:50.155867 2026] [security2:error] [pid 89520:tid 89723] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/8.php"] [unique_id "amuvFi0W4wRrtnDoPagOJAAAAcs"]
[Thu Jul 30 15:07:50.155955 2026] [security2:error] [pid 89520:tid 89723] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/8.php"] [unique_id "amuvFi0W4wRrtnDoPagOJAAAAcs"]
[Thu Jul 30 15:07:50.407875 2026] [security2:error] [pid 89520:tid 89677] [client 4.232.188.49:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1.php"] [unique_id "amuvFi0W4wRrtnDoPagOJQAAAZ0"]
[Thu Jul 30 15:07:50.408033 2026] [security2:error] [pid 89520:tid 89677] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1.php"] [unique_id "amuvFi0W4wRrtnDoPagOJQAAAZ0"]
[Thu Jul 30 15:07:50.408171 2026] [security2:error] [pid 89520:tid 89677] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1.php"] [unique_id "amuvFi0W4wRrtnDoPagOJQAAAZ0"]
[Thu Jul 30 15:07:50.669722 2026] [security2:error] [pid 89520:tid 89756] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/about.php"] [unique_id "amuvFi0W4wRrtnDoPagOLgAAAew"]
[Thu Jul 30 15:07:50.669836 2026] [security2:error] [pid 89520:tid 89756] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/about.php"] [unique_id "amuvFi0W4wRrtnDoPagOLgAAAew"]
[Thu Jul 30 15:07:50.876388 2026] [security2:error] [pid 89520:tid 89685] [client 204.12.208.18:54959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuvFi0W4wRrtnDoPagOKwAAAaU"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 15:07:50.908297 2026] [security2:error] [pid 87988:tid 88224] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/admin.php"] [unique_id "amuvFjipAwzptuCxBrh3yQAAAXQ"]
[Thu Jul 30 15:07:50.908389 2026] [security2:error] [pid 87988:tid 88224] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/admin.php"] [unique_id "amuvFjipAwzptuCxBrh3yQAAAXQ"]
[Thu Jul 30 15:07:51.089728 2026] [core:notice] [pid 89520:tid 89676] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:51.162711 2026] [security2:error] [pid 89520:tid 89665] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/edit.php"] [unique_id "amuvFy0W4wRrtnDoPagOMgAAAZE"]
[Thu Jul 30 15:07:51.162818 2026] [security2:error] [pid 89520:tid 89665] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/edit.php"] [unique_id "amuvFy0W4wRrtnDoPagOMgAAAZE"]
[Thu Jul 30 15:07:51.485533 2026] [security2:error] [pid 87988:tid 88142] [client 204.12.208.18:54966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuvFzipAwzptuCxBrh3zwAAASI"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 15:07:51.522080 2026] [security2:error] [pid 89520:tid 89726] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/admin.php"] [unique_id "amuvFy0W4wRrtnDoPagONQAAAc4"]
[Thu Jul 30 15:07:51.522180 2026] [security2:error] [pid 89520:tid 89726] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/admin.php"] [unique_id "amuvFy0W4wRrtnDoPagONQAAAc4"]
[Thu Jul 30 15:07:51.761040 2026] [security2:error] [pid 89520:tid 89668] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/inputs.php"] [unique_id "amuvFy0W4wRrtnDoPagOOQAAAZQ"]
[Thu Jul 30 15:07:51.761151 2026] [security2:error] [pid 89520:tid 89668] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/inputs.php"] [unique_id "amuvFy0W4wRrtnDoPagOOQAAAZQ"]
[Thu Jul 30 15:07:51.820963 2026] [core:notice] [pid 87988:tid 88211] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:52.000835 2026] [security2:error] [pid 89520:tid 89766] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/av.php"] [unique_id "amuvGC0W4wRrtnDoPagOOgAAAfY"]
[Thu Jul 30 15:07:52.000938 2026] [security2:error] [pid 89520:tid 89766] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/av.php"] [unique_id "amuvGC0W4wRrtnDoPagOOgAAAfY"]
[Thu Jul 30 15:07:52.087329 2026] [security2:error] [pid 89520:tid 89718] [client 204.12.208.18:54977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-content/brb1944e/index.php"] [unique_id "amuvGC0W4wRrtnDoPagOOwAAAcY"], referer: http://thdinfinity.com/wp-content/brb1944e/index.php
[Thu Jul 30 15:07:52.253371 2026] [security2:error] [pid 89520:tid 89694] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/classwithtostring.php"] [unique_id "amuvGC0W4wRrtnDoPagOPgAAAa4"]
[Thu Jul 30 15:07:52.253493 2026] [security2:error] [pid 89520:tid 89694] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/classwithtostring.php"] [unique_id "amuvGC0W4wRrtnDoPagOPgAAAa4"]
[Thu Jul 30 15:07:52.493349 2026] [security2:error] [pid 89520:tid 89714] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuvGC0W4wRrtnDoPagOQQAAAcI"]
[Thu Jul 30 15:07:52.493467 2026] [security2:error] [pid 89520:tid 89714] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuvGC0W4wRrtnDoPagOQQAAAcI"]
[Thu Jul 30 15:07:52.651849 2026] [security2:error] [pid 87988:tid 88149] [client 4.225.203.146:22346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/gmo.php"] [unique_id "amuvGDipAwzptuCxBrh34AAAASk"]
[Thu Jul 30 15:07:52.731121 2026] [security2:error] [pid 87988:tid 88169] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-blog.php"] [unique_id "amuvGDipAwzptuCxBrh34wAAAT0"]
[Thu Jul 30 15:07:52.731207 2026] [security2:error] [pid 87988:tid 88169] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-blog.php"] [unique_id "amuvGDipAwzptuCxBrh34wAAAT0"]
[Thu Jul 30 15:07:52.968000 2026] [proxy:error] [pid 89520:tid 89761] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:52.968073 2026] [proxy_http:error] [pid 89520:tid 89761] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:52.968632 2026] [proxy:error] [pid 89520:tid 89761] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:52.968674 2026] [proxy_http:error] [pid 89520:tid 89761] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:52.968773 2026] [security2:error] [pid 89520:tid 89761] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvGC0W4wRrtnDoPagORwAAAfE"]
[Thu Jul 30 15:07:53.240556 2026] [security2:error] [pid 89520:tid 89787] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/admin.php"] [unique_id "amuvGS0W4wRrtnDoPagOSQAAAgs"]
[Thu Jul 30 15:07:53.240674 2026] [security2:error] [pid 89520:tid 89787] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-content/admin.php"] [unique_id "amuvGS0W4wRrtnDoPagOSQAAAgs"]
[Thu Jul 30 15:07:53.482006 2026] [security2:error] [pid 89520:tid 89779] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/adminfuns.php"] [unique_id "amuvGS0W4wRrtnDoPagOTgAAAgM"]
[Thu Jul 30 15:07:53.482118 2026] [security2:error] [pid 89520:tid 89779] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/adminfuns.php"] [unique_id "amuvGS0W4wRrtnDoPagOTgAAAgM"]
[Thu Jul 30 15:07:53.723252 2026] [security2:error] [pid 87988:tid 88158] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/goods.php"] [unique_id "amuvGTipAwzptuCxBrh37wAAATI"]
[Thu Jul 30 15:07:53.723391 2026] [security2:error] [pid 87988:tid 88158] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/goods.php"] [unique_id "amuvGTipAwzptuCxBrh37wAAATI"]
[Thu Jul 30 15:07:53.811441 2026] [core:notice] [pid 87988:tid 88175] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:53.818487 2026] [security2:error] [pid 89520:tid 89700] [client 4.225.203.146:32588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuvGS0W4wRrtnDoPagOUwAAAbQ"]
[Thu Jul 30 15:07:53.921137 2026] [core:notice] [pid 87988:tid 88106] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:53.975194 2026] [security2:error] [pid 89520:tid 89762] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ms-edit.php"] [unique_id "amuvGS0W4wRrtnDoPagOWAAAAfI"]
[Thu Jul 30 15:07:53.975287 2026] [security2:error] [pid 89520:tid 89762] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ms-edit.php"] [unique_id "amuvGS0W4wRrtnDoPagOWAAAAfI"]
[Thu Jul 30 15:07:54.214111 2026] [security2:error] [pid 89520:tid 89733] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/222.php"] [unique_id "amuvGi0W4wRrtnDoPagOXgAAAdU"]
[Thu Jul 30 15:07:54.214238 2026] [security2:error] [pid 89520:tid 89733] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/222.php"] [unique_id "amuvGi0W4wRrtnDoPagOXgAAAdU"]
[Thu Jul 30 15:07:54.513293 2026] [security2:error] [pid 87988:tid 88147] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/cgi-bin/index.php"] [unique_id "amuvGjipAwzptuCxBrh3-gAAASc"]
[Thu Jul 30 15:07:54.513398 2026] [security2:error] [pid 87988:tid 88147] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/cgi-bin/index.php"] [unique_id "amuvGjipAwzptuCxBrh3-gAAASc"]
[Thu Jul 30 15:07:54.754484 2026] [proxy:error] [pid 89520:tid 89707] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:54.754569 2026] [proxy_http:error] [pid 89520:tid 89707] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:54.755342 2026] [proxy:error] [pid 89520:tid 89707] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:54.755394 2026] [proxy_http:error] [pid 89520:tid 89707] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:54.755516 2026] [security2:error] [pid 89520:tid 89707] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvGi0W4wRrtnDoPagOaQAAAbs"]
[Thu Jul 30 15:07:54.971216 2026] [core:notice] [pid 87988:tid 88170] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:55.022951 2026] [security2:error] [pid 89520:tid 89706] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/BDKR28WP.php"] [unique_id "amuvGy0W4wRrtnDoPagObgAAAbo"]
[Thu Jul 30 15:07:55.023065 2026] [security2:error] [pid 89520:tid 89706] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/BDKR28WP.php"] [unique_id "amuvGy0W4wRrtnDoPagObgAAAbo"]
[Thu Jul 30 15:07:55.292756 2026] [proxy:error] [pid 87988:tid 88225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:55.292826 2026] [proxy_http:error] [pid 87988:tid 88225] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:55.293428 2026] [proxy:error] [pid 87988:tid 88225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:55.293483 2026] [proxy_http:error] [pid 87988:tid 88225] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:55.293568 2026] [security2:error] [pid 87988:tid 88225] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvGzipAwzptuCxBrh4BQAAAXU"]
[Thu Jul 30 15:07:55.531913 2026] [proxy:error] [pid 89520:tid 89714] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:55.531971 2026] [proxy_http:error] [pid 89520:tid 89714] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:55.532542 2026] [proxy:error] [pid 89520:tid 89714] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:55.532585 2026] [proxy_http:error] [pid 89520:tid 89714] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:55.532669 2026] [security2:error] [pid 89520:tid 89714] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvGy0W4wRrtnDoPagOcwAAAcI"]
[Thu Jul 30 15:07:55.772080 2026] [security2:error] [pid 89520:tid 89784] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp.php"] [unique_id "amuvGy0W4wRrtnDoPagOdwAAAgg"]
[Thu Jul 30 15:07:55.772216 2026] [security2:error] [pid 89520:tid 89784] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp.php"] [unique_id "amuvGy0W4wRrtnDoPagOdwAAAgg"]
[Thu Jul 30 15:07:56.018689 2026] [security2:error] [pid 87988:tid 88188] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/abcd.php"] [unique_id "amuvHDipAwzptuCxBrh4EgAAAVA"]
[Thu Jul 30 15:07:56.018845 2026] [security2:error] [pid 87988:tid 88188] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/abcd.php"] [unique_id "amuvHDipAwzptuCxBrh4EgAAAVA"]
[Thu Jul 30 15:07:56.283935 2026] [security2:error] [pid 89520:tid 89692] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvGy0W4wRrtnDoPagOdgAAAaw"]
[Thu Jul 30 15:07:56.284025 2026] [security2:error] [pid 89520:tid 89763] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/a1.php"] [unique_id "amuvHC0W4wRrtnDoPagOewAAAfM"]
[Thu Jul 30 15:07:56.284128 2026] [security2:error] [pid 89520:tid 89763] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/a1.php"] [unique_id "amuvHC0W4wRrtnDoPagOewAAAfM"]
[Thu Jul 30 15:07:56.529209 2026] [security2:error] [pid 87988:tid 88179] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuvHDipAwzptuCxBrh4GQAAAUc"]
[Thu Jul 30 15:07:56.529316 2026] [security2:error] [pid 87988:tid 88179] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuvHDipAwzptuCxBrh4GQAAAUc"]
[Thu Jul 30 15:07:56.647779 2026] [core:notice] [pid 89520:tid 89696] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:56.767637 2026] [security2:error] [pid 89520:tid 89779] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuvHC0W4wRrtnDoPagOiAAAAgM"]
[Thu Jul 30 15:07:56.767738 2026] [security2:error] [pid 89520:tid 89779] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/cgi-bin/admin.php"] [unique_id "amuvHC0W4wRrtnDoPagOiAAAAgM"]
[Thu Jul 30 15:07:57.010101 2026] [proxy:error] [pid 89520:tid 89700] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:57.010174 2026] [proxy_http:error] [pid 89520:tid 89700] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:57.010746 2026] [proxy:error] [pid 89520:tid 89700] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:57.010787 2026] [proxy_http:error] [pid 89520:tid 89700] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:57.010879 2026] [security2:error] [pid 89520:tid 89700] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvHS0W4wRrtnDoPagOiwAAAbQ"]
[Thu Jul 30 15:07:57.034268 2026] [security2:error] [pid 89520:tid 89693] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvHC0W4wRrtnDoPagOggAAAa0"]
[Thu Jul 30 15:07:57.252176 2026] [core:notice] [pid 87988:tid 88045] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:57.262535 2026] [security2:error] [pid 89520:tid 89741] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/simple.php"] [unique_id "amuvHS0W4wRrtnDoPagOlQAAAd0"]
[Thu Jul 30 15:07:57.262635 2026] [security2:error] [pid 89520:tid 89741] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/simple.php"] [unique_id "amuvHS0W4wRrtnDoPagOlQAAAd0"]
[Thu Jul 30 15:07:57.312155 2026] [core:notice] [pid 87988:tid 88069] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:07:57.482204 2026] [security2:error] [pid 87988:tid 88189] [client 115.76.51.134:1847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.51.76.115.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/errores-criticos-de-los-algoritmos-de-apuestas-en-tenis-sobre-cesped/"] [unique_id "amuvHTipAwzptuCxBrh4JAAAAVE"], referer: https://thdinfinity.com/errores-criticos-de-los-algoritmos-de-apuestas-en-tenis-sobre-cesped/
[Thu Jul 30 15:07:57.501963 2026] [security2:error] [pid 89520:tid 89765] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xxx.php"] [unique_id "amuvHS0W4wRrtnDoPagOmwAAAfU"]
[Thu Jul 30 15:07:57.502088 2026] [security2:error] [pid 89520:tid 89765] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xxx.php"] [unique_id "amuvHS0W4wRrtnDoPagOmwAAAfU"]
[Thu Jul 30 15:07:57.571441 2026] [security2:error] [pid 87988:tid 88187] [client 2a03:2880:f800:32:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvHDipAwzptuCxBrh4HwABTyc"]
[Thu Jul 30 15:07:57.620631 2026] [security2:error] [pid 89520:tid 89777] [client 4.225.203.146:18465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-the.php"] [unique_id "amuvHS0W4wRrtnDoPagOnwAAAgE"]
[Thu Jul 30 15:07:57.751528 2026] [security2:error] [pid 89520:tid 89724] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/hypo.php"] [unique_id "amuvHS0W4wRrtnDoPagOpQAAAcw"]
[Thu Jul 30 15:07:57.751633 2026] [security2:error] [pid 89520:tid 89724] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/hypo.php"] [unique_id "amuvHS0W4wRrtnDoPagOpQAAAcw"]
[Thu Jul 30 15:07:57.836654 2026] [security2:error] [pid 89520:tid 89722] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvHS0W4wRrtnDoPagOlAAAAco"]
[Thu Jul 30 15:07:58.043314 2026] [proxy:error] [pid 87988:tid 88173] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:58.043385 2026] [proxy_http:error] [pid 87988:tid 88173] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:58.043955 2026] [proxy:error] [pid 87988:tid 88173] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:58.044010 2026] [proxy_http:error] [pid 87988:tid 88173] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:58.044089 2026] [security2:error] [pid 87988:tid 88173] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvHjipAwzptuCxBrh4MwAAAUE"]
[Thu Jul 30 15:07:58.281224 2026] [security2:error] [pid 89520:tid 89740] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/chosen.php"] [unique_id "amuvHi0W4wRrtnDoPagOuAAAAdw"]
[Thu Jul 30 15:07:58.281352 2026] [security2:error] [pid 89520:tid 89740] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/chosen.php"] [unique_id "amuvHi0W4wRrtnDoPagOuAAAAdw"]
[Thu Jul 30 15:07:58.344779 2026] [security2:error] [pid 89520:tid 89715] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvHS0W4wRrtnDoPagOpAAAAcM"]
[Thu Jul 30 15:07:58.390898 2026] [security2:error] [pid 87988:tid 88162] [client 185.191.171.5:64444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/nl/1-home"] [unique_id "amuvHjipAwzptuCxBrh4OQAAATY"]
[Thu Jul 30 15:07:58.391027 2026] [security2:error] [pid 87988:tid 88162] [client 185.191.171.5:64444] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/nl/1-home"] [unique_id "amuvHjipAwzptuCxBrh4OQAAATY"]
[Thu Jul 30 15:07:58.588553 2026] [proxy:error] [pid 89520:tid 89712] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:58.588630 2026] [proxy_http:error] [pid 89520:tid 89712] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:58.589365 2026] [proxy:error] [pid 89520:tid 89712] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:07:58.589426 2026] [proxy_http:error] [pid 89520:tid 89712] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:07:58.589520 2026] [security2:error] [pid 89520:tid 89712] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvHi0W4wRrtnDoPagOxwAAAcA"]
[Thu Jul 30 15:07:58.691563 2026] [security2:error] [pid 89520:tid 89733] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvHi0W4wRrtnDoPagOtAAB1Qg"]
[Thu Jul 30 15:07:58.848608 2026] [security2:error] [pid 89520:tid 89688] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/als.php"] [unique_id "amuvHi0W4wRrtnDoPagOygAAAag"]
[Thu Jul 30 15:07:58.848719 2026] [security2:error] [pid 89520:tid 89688] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/als.php"] [unique_id "amuvHi0W4wRrtnDoPagOygAAAag"]
[Thu Jul 30 15:07:59.091129 2026] [security2:error] [pid 89520:tid 89736] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/pol.php"] [unique_id "amuvHy0W4wRrtnDoPagO0QAAAdg"]
[Thu Jul 30 15:07:59.091229 2026] [security2:error] [pid 89520:tid 89736] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/pol.php"] [unique_id "amuvHy0W4wRrtnDoPagO0QAAAdg"]
[Thu Jul 30 15:07:59.265487 2026] [security2:error] [pid 87988:tid 88153] [client 4.225.203.146:19410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/404.php"] [unique_id "amuvHzipAwzptuCxBrh4SAAAAS0"]
[Thu Jul 30 15:07:59.361427 2026] [security2:error] [pid 89520:tid 89710] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file5.php"] [unique_id "amuvHy0W4wRrtnDoPagO1gAAAb4"]
[Thu Jul 30 15:07:59.361545 2026] [security2:error] [pid 89520:tid 89710] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file5.php"] [unique_id "amuvHy0W4wRrtnDoPagO1gAAAb4"]
[Thu Jul 30 15:07:59.411715 2026] [security2:error] [pid 89520:tid 89654] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvHy0W4wRrtnDoPagO1wABong"]
[Thu Jul 30 15:07:59.411875 2026] [security2:error] [pid 89520:tid 89682] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvHy0W4wRrtnDoPagO1wABong"]
[Thu Jul 30 15:07:59.526553 2026] [core:error] [pid 87988:tid 88230] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:07:59.526581 2026] [core:error] [pid 87988:tid 88230] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:07:59.586447 2026] [security2:error] [pid 89520:tid 89672] [client 185.191.171.17:26128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/27/operacao-paradigma-reforca-policiamento-nas-ruas-do-litoral-ao-sertao-da-paraiba/"] [unique_id "amuvHy0W4wRrtnDoPagO3gAAAZg"]
[Thu Jul 30 15:07:59.586584 2026] [security2:error] [pid 89520:tid 89672] [client 185.191.171.17:26128] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/27/operacao-paradigma-reforca-policiamento-nas-ruas-do-litoral-ao-sertao-da-paraiba/"] [unique_id "amuvHy0W4wRrtnDoPagO3gAAAZg"]
[Thu Jul 30 15:07:59.705564 2026] [security2:error] [pid 89520:tid 89781] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file.php"] [unique_id "amuvHy0W4wRrtnDoPagO4wAAAgU"]
[Thu Jul 30 15:07:59.705657 2026] [security2:error] [pid 89520:tid 89781] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file.php"] [unique_id "amuvHy0W4wRrtnDoPagO4wAAAgU"]
[Thu Jul 30 15:07:59.954799 2026] [security2:error] [pid 89520:tid 89743] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/admin.php"] [unique_id "amuvHy0W4wRrtnDoPagO6QAAAd8"]
[Thu Jul 30 15:07:59.954898 2026] [security2:error] [pid 89520:tid 89743] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/admin.php"] [unique_id "amuvHy0W4wRrtnDoPagO6QAAAd8"]
[Thu Jul 30 15:08:00.195093 2026] [security2:error] [pid 87988:tid 88142] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/aa2.php"] [unique_id "amuvIDipAwzptuCxBrh4WAAAASI"]
[Thu Jul 30 15:08:00.195196 2026] [security2:error] [pid 87988:tid 88142] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/aa2.php"] [unique_id "amuvIDipAwzptuCxBrh4WAAAASI"]
[Thu Jul 30 15:08:00.437253 2026] [security2:error] [pid 87988:tid 88203] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ccou.php"] [unique_id "amuvIDipAwzptuCxBrh4WQAAAV8"]
[Thu Jul 30 15:08:00.437393 2026] [security2:error] [pid 87988:tid 88203] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ccou.php"] [unique_id "amuvIDipAwzptuCxBrh4WQAAAV8"]
[Thu Jul 30 15:08:00.498157 2026] [security2:error] [pid 89520:tid 89692] [client 4.225.203.146:51098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/init.php"] [unique_id "amuvIC0W4wRrtnDoPagO7wAAAaw"]
[Thu Jul 30 15:08:00.682583 2026] [security2:error] [pid 87988:tid 88151] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dr.php"] [unique_id "amuvIDipAwzptuCxBrh4XgAAASs"]
[Thu Jul 30 15:08:00.682682 2026] [security2:error] [pid 87988:tid 88151] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dr.php"] [unique_id "amuvIDipAwzptuCxBrh4XgAAASs"]
[Thu Jul 30 15:08:00.855158 2026] [core:notice] [pid 89520:tid 89767] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:00.923547 2026] [security2:error] [pid 89520:tid 89712] [client 64.31.3.126:25016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvHy0W4wRrtnDoPagO1QAAAgQ"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2268
[Thu Jul 30 15:08:00.924077 2026] [security2:error] [pid 89520:tid 89754] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xamp.php"] [unique_id "amuvIC0W4wRrtnDoPagO-AAAAeo"]
[Thu Jul 30 15:08:00.924158 2026] [security2:error] [pid 89520:tid 89754] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xamp.php"] [unique_id "amuvIC0W4wRrtnDoPagO-AAAAeo"]
[Thu Jul 30 15:08:01.162134 2026] [security2:error] [pid 87988:tid 88119] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/bless.php"] [unique_id "amuvITipAwzptuCxBrh4YwAAAQs"]
[Thu Jul 30 15:08:01.162237 2026] [security2:error] [pid 87988:tid 88119] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/bless.php"] [unique_id "amuvITipAwzptuCxBrh4YwAAAQs"]
[Thu Jul 30 15:08:01.363199 2026] [security2:error] [pid 89520:tid 89664] [client 4.225.203.146:32595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/file5.php"] [unique_id "amuvIS0W4wRrtnDoPagPAQAAAZA"]
[Thu Jul 30 15:08:01.416663 2026] [security2:error] [pid 87988:tid 88149] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file25.php"] [unique_id "amuvITipAwzptuCxBrh4ZQAAASk"]
[Thu Jul 30 15:08:01.416841 2026] [security2:error] [pid 87988:tid 88149] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file25.php"] [unique_id "amuvITipAwzptuCxBrh4ZQAAASk"]
[Thu Jul 30 15:08:01.652468 2026] [security2:error] [pid 87988:tid 88199] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file6.php"] [unique_id "amuvITipAwzptuCxBrh4bgAAAVs"]
[Thu Jul 30 15:08:01.652568 2026] [security2:error] [pid 87988:tid 88199] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file6.php"] [unique_id "amuvITipAwzptuCxBrh4bgAAAVs"]
[Thu Jul 30 15:08:01.950127 2026] [security2:error] [pid 87988:tid 88161] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/a2.php"] [unique_id "amuvITipAwzptuCxBrh4cQAAATU"]
[Thu Jul 30 15:08:01.950243 2026] [security2:error] [pid 87988:tid 88161] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/a2.php"] [unique_id "amuvITipAwzptuCxBrh4cQAAATU"]
[Thu Jul 30 15:08:02.169098 2026] [security2:error] [pid 89520:tid 89663] [client 4.225.203.146:51088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuvIi0W4wRrtnDoPagPCQAAAY8"]
[Thu Jul 30 15:08:02.279437 2026] [security2:error] [pid 89520:tid 89722] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file15.php"] [unique_id "amuvIi0W4wRrtnDoPagPCwAAAco"]
[Thu Jul 30 15:08:02.279524 2026] [security2:error] [pid 89520:tid 89722] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file15.php"] [unique_id "amuvIi0W4wRrtnDoPagPCwAAAco"]
[Thu Jul 30 15:08:02.498096 2026] [security2:error] [pid 87988:tid 88146] [client 172.237.109.114:26935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvITipAwzptuCxBrh4cgAAASY"]
[Thu Jul 30 15:08:02.531665 2026] [security2:error] [pid 89520:tid 89766] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/f35.php"] [unique_id "amuvIi0W4wRrtnDoPagPDAAAAfY"]
[Thu Jul 30 15:08:02.531777 2026] [security2:error] [pid 89520:tid 89766] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/f35.php"] [unique_id "amuvIi0W4wRrtnDoPagPDAAAAfY"]
[Thu Jul 30 15:08:02.652087 2026] [security2:error] [pid 89520:tid 89716] [client 172.237.109.114:19480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvIi0W4wRrtnDoPagPBwAAAcQ"]
[Thu Jul 30 15:08:02.767920 2026] [security2:error] [pid 87988:tid 88128] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-load.php"] [unique_id "amuvIjipAwzptuCxBrh4gAAAARQ"]
[Thu Jul 30 15:08:02.768031 2026] [security2:error] [pid 87988:tid 88128] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-load.php"] [unique_id "amuvIjipAwzptuCxBrh4gAAAARQ"]
[Thu Jul 30 15:08:03.017313 2026] [security2:error] [pid 89520:tid 89718] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xwpg.php"] [unique_id "amuvIy0W4wRrtnDoPagPEgAAAcY"]
[Thu Jul 30 15:08:03.017456 2026] [security2:error] [pid 89520:tid 89718] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xwpg.php"] [unique_id "amuvIy0W4wRrtnDoPagPEgAAAcY"]
[Thu Jul 30 15:08:03.250289 2026] [security2:error] [pid 89520:tid 89776] [client 57.141.0.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvIi0W4wRrtnDoPagPEAAAAgA"]
[Thu Jul 30 15:08:03.266809 2026] [proxy:error] [pid 87988:tid 88233] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:08:03.266879 2026] [proxy_http:error] [pid 87988:tid 88233] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:08:03.267637 2026] [proxy:error] [pid 87988:tid 88233] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:08:03.267684 2026] [proxy_http:error] [pid 87988:tid 88233] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:08:03.267758 2026] [security2:error] [pid 87988:tid 88233] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvIzipAwzptuCxBrh4iQAAAX0"]
[Thu Jul 30 15:08:03.512085 2026] [proxy:error] [pid 89520:tid 89743] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:08:03.512157 2026] [proxy_http:error] [pid 89520:tid 89743] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:08:03.512728 2026] [proxy:error] [pid 89520:tid 89743] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:08:03.512770 2026] [proxy_http:error] [pid 89520:tid 89743] [client 4.232.188.49:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:08:03.512862 2026] [security2:error] [pid 89520:tid 89743] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.okcasino-1.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuvIy0W4wRrtnDoPagPEwAAAd8"]
[Thu Jul 30 15:08:03.528373 2026] [core:notice] [pid 87988:tid 88104] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:03.749549 2026] [security2:error] [pid 89520:tid 89758] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xstelth.php"] [unique_id "amuvIy0W4wRrtnDoPagPFQAAAe4"]
[Thu Jul 30 15:08:03.749667 2026] [security2:error] [pid 89520:tid 89758] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xstelth.php"] [unique_id "amuvIy0W4wRrtnDoPagPFQAAAe4"]
[Thu Jul 30 15:08:03.974175 2026] [core:notice] [pid 89520:tid 89730] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:04.002158 2026] [security2:error] [pid 87988:tid 88235] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuvJDipAwzptuCxBrh4lwAAAX8"]
[Thu Jul 30 15:08:04.002256 2026] [security2:error] [pid 87988:tid 88235] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "amuvJDipAwzptuCxBrh4lwAAAX8"]
[Thu Jul 30 15:08:04.239658 2026] [security2:error] [pid 89520:tid 89708] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/aaa.php"] [unique_id "amuvJC0W4wRrtnDoPagPGAAAAbw"]
[Thu Jul 30 15:08:04.239758 2026] [security2:error] [pid 89520:tid 89708] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/aaa.php"] [unique_id "amuvJC0W4wRrtnDoPagPGAAAAbw"]
[Thu Jul 30 15:08:04.478533 2026] [security2:error] [pid 89520:tid 89684] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/gecko.php"] [unique_id "amuvJC0W4wRrtnDoPagPGgAAAaQ"]
[Thu Jul 30 15:08:04.478659 2026] [security2:error] [pid 89520:tid 89684] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/gecko.php"] [unique_id "amuvJC0W4wRrtnDoPagPGgAAAaQ"]
[Thu Jul 30 15:08:04.588229 2026] [security2:error] [pid 87988:tid 88188] [client 172.237.109.114:12462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvJDipAwzptuCxBrh4mAAAAVA"]
[Thu Jul 30 15:08:04.719008 2026] [security2:error] [pid 89520:tid 89705] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/pbck.php"] [unique_id "amuvJC0W4wRrtnDoPagPHAAAAbk"]
[Thu Jul 30 15:08:04.719112 2026] [security2:error] [pid 89520:tid 89705] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/pbck.php"] [unique_id "amuvJC0W4wRrtnDoPagPHAAAAbk"]
[Thu Jul 30 15:08:04.870992 2026] [security2:error] [pid 89520:tid 89780] [client 4.225.203.146:19402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/shell.php"] [unique_id "amuvJC0W4wRrtnDoPagPHQAAAgQ"]
[Thu Jul 30 15:08:04.957399 2026] [security2:error] [pid 89520:tid 89767] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xiugai.php"] [unique_id "amuvJC0W4wRrtnDoPagPHwAAAfc"]
[Thu Jul 30 15:08:04.957534 2026] [security2:error] [pid 89520:tid 89767] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xiugai.php"] [unique_id "amuvJC0W4wRrtnDoPagPHwAAAfc"]
[Thu Jul 30 15:08:05.197585 2026] [security2:error] [pid 87988:tid 88130] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/e.php"] [unique_id "amuvJTipAwzptuCxBrh4qwAAARY"]
[Thu Jul 30 15:08:05.197672 2026] [security2:error] [pid 87988:tid 88130] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/e.php"] [unique_id "amuvJTipAwzptuCxBrh4qwAAARY"]
[Thu Jul 30 15:08:05.448303 2026] [security2:error] [pid 87988:tid 88208] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/adminner.php"] [unique_id "amuvJTipAwzptuCxBrh4sQAAAWQ"]
[Thu Jul 30 15:08:05.448396 2026] [security2:error] [pid 87988:tid 88208] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/adminner.php"] [unique_id "amuvJTipAwzptuCxBrh4sQAAAWQ"]
[Thu Jul 30 15:08:05.604298 2026] [proxy:error] [pid 87988:tid 88033] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:08:05.604361 2026] [proxy_http:error] [pid 87988:tid 88033] [remote 74.7.175.158:56730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:08:05.605234 2026] [proxy:error] [pid 87988:tid 88033] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:08:05.605291 2026] [proxy_http:error] [pid 87988:tid 88033] [remote 74.7.175.158:56730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:08:05.685935 2026] [security2:error] [pid 87988:tid 88204] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file1221.php"] [unique_id "amuvJTipAwzptuCxBrh4swAAAWA"]
[Thu Jul 30 15:08:05.686108 2026] [security2:error] [pid 87988:tid 88204] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/file1221.php"] [unique_id "amuvJTipAwzptuCxBrh4swAAAWA"]
[Thu Jul 30 15:08:05.939794 2026] [security2:error] [pid 87988:tid 88123] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/inx.php"] [unique_id "amuvJTipAwzptuCxBrh4uwAAAQ8"]
[Thu Jul 30 15:08:05.939895 2026] [security2:error] [pid 87988:tid 88123] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/inx.php"] [unique_id "amuvJTipAwzptuCxBrh4uwAAAQ8"]
[Thu Jul 30 15:08:06.176684 2026] [security2:error] [pid 89520:tid 89666] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/qqqa.php"] [unique_id "amuvJi0W4wRrtnDoPagPJwAAAZI"]
[Thu Jul 30 15:08:06.176842 2026] [security2:error] [pid 89520:tid 89666] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/qqqa.php"] [unique_id "amuvJi0W4wRrtnDoPagPJwAAAZI"]
[Thu Jul 30 15:08:06.292409 2026] [core:notice] [pid 87988:tid 88184] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:06.423392 2026] [security2:error] [pid 87988:tid 88153] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/reviall.php"] [unique_id "amuvJjipAwzptuCxBrh4xgAAAS0"]
[Thu Jul 30 15:08:06.423498 2026] [security2:error] [pid 87988:tid 88153] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/reviall.php"] [unique_id "amuvJjipAwzptuCxBrh4xgAAAS0"]
[Thu Jul 30 15:08:06.574873 2026] [security2:error] [pid 87988:tid 88128] [client 172.237.109.114:25104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvJjipAwzptuCxBrh4vgAAARQ"]
[Thu Jul 30 15:08:06.681393 2026] [security2:error] [pid 87988:tid 88143] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/404.php"] [unique_id "amuvJjipAwzptuCxBrh4yAAAASM"]
[Thu Jul 30 15:08:06.681506 2026] [security2:error] [pid 87988:tid 88143] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/404.php"] [unique_id "amuvJjipAwzptuCxBrh4yAAAASM"]
[Thu Jul 30 15:08:06.919824 2026] [security2:error] [pid 89520:tid 89706] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/bolt.php"] [unique_id "amuvJi0W4wRrtnDoPagPLAAAAbo"]
[Thu Jul 30 15:08:06.919946 2026] [security2:error] [pid 89520:tid 89706] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/bolt.php"] [unique_id "amuvJi0W4wRrtnDoPagPLAAAAbo"]
[Thu Jul 30 15:08:07.158877 2026] [security2:error] [pid 89520:tid 89766] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/File.php"] [unique_id "amuvJy0W4wRrtnDoPagPLwAAAfY"]
[Thu Jul 30 15:08:07.158994 2026] [security2:error] [pid 89520:tid 89766] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/File.php"] [unique_id "amuvJy0W4wRrtnDoPagPLwAAAfY"]
[Thu Jul 30 15:08:07.423920 2026] [security2:error] [pid 87988:tid 88126] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/fi22.php"] [unique_id "amuvJzipAwzptuCxBrh40AAAARI"]
[Thu Jul 30 15:08:07.424055 2026] [security2:error] [pid 87988:tid 88126] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/fi22.php"] [unique_id "amuvJzipAwzptuCxBrh40AAAARI"]
[Thu Jul 30 15:08:07.567877 2026] [security2:error] [pid 89520:tid 89685] [client 4.225.203.146:60954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/f35.php"] [unique_id "amuvJy0W4wRrtnDoPagPMwAAAaU"]
[Thu Jul 30 15:08:07.671326 2026] [security2:error] [pid 87988:tid 88218] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/zero.php"] [unique_id "amuvJzipAwzptuCxBrh41QAAAW4"]
[Thu Jul 30 15:08:07.671425 2026] [security2:error] [pid 87988:tid 88218] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/zero.php"] [unique_id "amuvJzipAwzptuCxBrh41QAAAW4"]
[Thu Jul 30 15:08:07.938638 2026] [security2:error] [pid 87988:tid 88142] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1xmomo.php"] [unique_id "amuvJzipAwzptuCxBrh45wAAASI"]
[Thu Jul 30 15:08:07.938757 2026] [security2:error] [pid 87988:tid 88142] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1xmomo.php"] [unique_id "amuvJzipAwzptuCxBrh45wAAASI"]
[Thu Jul 30 15:08:08.051168 2026] [security2:error] [pid 87988:tid 88207] [client 18.141.164.201:36042] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "www.deltaedu.net"] [uri "/"] [unique_id "amuvKDipAwzptuCxBrh46QAAAWM"]
[Thu Jul 30 15:08:08.176579 2026] [security2:error] [pid 89520:tid 89675] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/fmws.php"] [unique_id "amuvKC0W4wRrtnDoPagPPAAAAZs"]
[Thu Jul 30 15:08:08.176681 2026] [security2:error] [pid 89520:tid 89675] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/fmws.php"] [unique_id "amuvKC0W4wRrtnDoPagPPAAAAZs"]
[Thu Jul 30 15:08:08.265936 2026] [security2:error] [pid 89520:tid 89759] [client 172.237.109.114:1205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvJy0W4wRrtnDoPagPOAAAAe8"]
[Thu Jul 30 15:08:08.419473 2026] [security2:error] [pid 89520:tid 89740] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuvKC0W4wRrtnDoPagPPgAAAdw"]
[Thu Jul 30 15:08:08.419584 2026] [security2:error] [pid 89520:tid 89740] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuvKC0W4wRrtnDoPagPPgAAAdw"]
[Thu Jul 30 15:08:08.788800 2026] [security2:error] [pid 89520:tid 89782] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/hp2.php"] [unique_id "amuvKC0W4wRrtnDoPagPRQAAAgY"]
[Thu Jul 30 15:08:08.788944 2026] [security2:error] [pid 89520:tid 89782] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/hp2.php"] [unique_id "amuvKC0W4wRrtnDoPagPRQAAAgY"]
[Thu Jul 30 15:08:08.899031 2026] [security2:error] [pid 87988:tid 88177] [client 37.77.56.246:40974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuvKDipAwzptuCxBrh5AQAAAUU"]
[Thu Jul 30 15:08:08.899131 2026] [security2:error] [pid 87988:tid 88177] [client 37.77.56.246:40974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuvKDipAwzptuCxBrh5AQAAAUU"]
[Thu Jul 30 15:08:09.167376 2026] [security2:error] [pid 89520:tid 89770] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/aabb.php"] [unique_id "amuvKS0W4wRrtnDoPagPSAAAAfo"]
[Thu Jul 30 15:08:09.167495 2026] [security2:error] [pid 89520:tid 89770] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/aabb.php"] [unique_id "amuvKS0W4wRrtnDoPagPSAAAAfo"]
[Thu Jul 30 15:08:09.487208 2026] [security2:error] [pid 87988:tid 88133] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1254xx.php"] [unique_id "amuvKTipAwzptuCxBrh5DAAAARk"]
[Thu Jul 30 15:08:09.487315 2026] [security2:error] [pid 87988:tid 88133] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1254xx.php"] [unique_id "amuvKTipAwzptuCxBrh5DAAAARk"]
[Thu Jul 30 15:08:09.738075 2026] [security2:error] [pid 87988:tid 88208] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuvKTipAwzptuCxBrh5EQAAAWQ"]
[Thu Jul 30 15:08:09.738193 2026] [security2:error] [pid 87988:tid 88208] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "amuvKTipAwzptuCxBrh5EQAAAWQ"]
[Thu Jul 30 15:08:09.827788 2026] [security2:error] [pid 89520:tid 89717] [client 4.225.203.146:16537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/new.php"] [unique_id "amuvKS0W4wRrtnDoPagPUgAAAcU"]
[Thu Jul 30 15:08:09.976371 2026] [security2:error] [pid 89520:tid 89671] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/pms297.php"] [unique_id "amuvKS0W4wRrtnDoPagPVAAAAZc"]
[Thu Jul 30 15:08:09.976469 2026] [security2:error] [pid 89520:tid 89671] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/pms297.php"] [unique_id "amuvKS0W4wRrtnDoPagPVAAAAZc"]
[Thu Jul 30 15:08:09.999913 2026] [security2:error] [pid 87988:tid 88089] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvKTipAwzptuCxBrh5FgABNWQ"]
[Thu Jul 30 15:08:10.000119 2026] [security2:error] [pid 87988:tid 88161] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvKTipAwzptuCxBrh5FgABNWQ"]
[Thu Jul 30 15:08:10.218003 2026] [security2:error] [pid 89520:tid 89733] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuvKi0W4wRrtnDoPagPVQAAAdU"]
[Thu Jul 30 15:08:10.218122 2026] [security2:error] [pid 89520:tid 89733] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1PJcpMFsD8B.php"] [unique_id "amuvKi0W4wRrtnDoPagPVQAAAdU"]
[Thu Jul 30 15:08:10.619408 2026] [security2:error] [pid 89520:tid 89677] [client 4.225.203.146:50651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/adminfuns.php"] [unique_id "amuvKi0W4wRrtnDoPagPXgAAAZ0"]
[Thu Jul 30 15:08:11.281374 2026] [security2:error] [pid 87988:tid 88138] [client 103.225.244.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvKjipAwzptuCxBrh5HQABHlI"], referer: https://allmontecristi.com
[Thu Jul 30 15:08:11.786771 2026] [security2:error] [pid 89520:tid 89707] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuvKy0W4wRrtnDoPagPZAAAAbs"]
[Thu Jul 30 15:08:11.786892 2026] [security2:error] [pid 89520:tid 89707] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "amuvKy0W4wRrtnDoPagPZAAAAbs"]
[Thu Jul 30 15:08:12.043347 2026] [security2:error] [pid 89520:tid 89665] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuvLC0W4wRrtnDoPagPZwAAAZE"]
[Thu Jul 30 15:08:12.043462 2026] [security2:error] [pid 89520:tid 89665] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "amuvLC0W4wRrtnDoPagPZwAAAZE"]
[Thu Jul 30 15:08:12.299557 2026] [security2:error] [pid 89520:tid 89726] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuvLC0W4wRrtnDoPagPagAAAc4"]
[Thu Jul 30 15:08:12.299668 2026] [security2:error] [pid 89520:tid 89726] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "amuvLC0W4wRrtnDoPagPagAAAc4"]
[Thu Jul 30 15:08:12.633674 2026] [security2:error] [pid 89520:tid 89683] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dyui.php"] [unique_id "amuvLC0W4wRrtnDoPagPbgAAAaM"]
[Thu Jul 30 15:08:12.633793 2026] [security2:error] [pid 89520:tid 89683] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/dyui.php"] [unique_id "amuvLC0W4wRrtnDoPagPbgAAAaM"]
[Thu Jul 30 15:08:12.714942 2026] [security2:error] [pid 87988:tid 88236] [client 102.212.190.233:59126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.190.212.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amuvLDipAwzptuCxBrh5NQAAAYA"]
[Thu Jul 30 15:08:12.871436 2026] [security2:error] [pid 89520:tid 89697] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ho.php"] [unique_id "amuvLC0W4wRrtnDoPagPcAAAAbE"]
[Thu Jul 30 15:08:12.871550 2026] [security2:error] [pid 89520:tid 89697] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ho.php"] [unique_id "amuvLC0W4wRrtnDoPagPcAAAAbE"]
[Thu Jul 30 15:08:13.122838 2026] [security2:error] [pid 87988:tid 88240] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/66b867516c8f01.php"] [unique_id "amuvLTipAwzptuCxBrh5PQAAAYQ"]
[Thu Jul 30 15:08:13.122969 2026] [security2:error] [pid 87988:tid 88240] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/66b867516c8f01.php"] [unique_id "amuvLTipAwzptuCxBrh5PQAAAYQ"]
[Thu Jul 30 15:08:13.250484 2026] [security2:error] [pid 89520:tid 89556] [remote 57.141.0.49:20972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuvLS0W4wRrtnDoPagPeAAB6Ro"]
[Thu Jul 30 15:08:13.455898 2026] [security2:error] [pid 89520:tid 89735] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ext.php"] [unique_id "amuvLS0W4wRrtnDoPagPegAAAdc"]
[Thu Jul 30 15:08:13.456061 2026] [security2:error] [pid 89520:tid 89735] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/ext.php"] [unique_id "amuvLS0W4wRrtnDoPagPegAAAdc"]
[Thu Jul 30 15:08:13.680457 2026] [security2:error] [pid 87988:tid 88182] [client 102.212.190.233:58333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.190.212.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amuvLTipAwzptuCxBrh5RgAAAUo"]
[Thu Jul 30 15:08:13.680564 2026] [security2:error] [pid 87988:tid 88182] [client 102.212.190.233:58333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amuvLTipAwzptuCxBrh5RgAAAUo"]
[Thu Jul 30 15:08:13.696650 2026] [security2:error] [pid 89520:tid 89747] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuvLS0W4wRrtnDoPagPfQAAAeM"]
[Thu Jul 30 15:08:13.696738 2026] [security2:error] [pid 89520:tid 89747] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "amuvLS0W4wRrtnDoPagPfQAAAeM"]
[Thu Jul 30 15:08:13.948742 2026] [security2:error] [pid 89520:tid 89783] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuvLS0W4wRrtnDoPagPggAAAgc"]
[Thu Jul 30 15:08:13.948895 2026] [security2:error] [pid 89520:tid 89783] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/xy9brdftkyivz9ij6rusmsCdefault.php"] [unique_id "amuvLS0W4wRrtnDoPagPggAAAgc"]
[Thu Jul 30 15:08:14.197574 2026] [security2:error] [pid 89520:tid 89681] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/584062352875874akp.php"] [unique_id "amuvLi0W4wRrtnDoPagPhQAAAaE"]
[Thu Jul 30 15:08:14.197719 2026] [security2:error] [pid 89520:tid 89681] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/584062352875874akp.php"] [unique_id "amuvLi0W4wRrtnDoPagPhQAAAaE"]
[Thu Jul 30 15:08:14.442835 2026] [autoindex:error] [pid 87988:tid 88158] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:08:14.453751 2026] [security2:error] [pid 87988:tid 88221] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/diidi.php"] [unique_id "amuvLjipAwzptuCxBrh5XgAAAXE"]
[Thu Jul 30 15:08:14.453840 2026] [security2:error] [pid 87988:tid 88221] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/diidi.php"] [unique_id "amuvLjipAwzptuCxBrh5XgAAAXE"]
[Thu Jul 30 15:08:14.595779 2026] [security2:error] [pid 87988:tid 88131] [client 4.225.203.146:38974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/fm.php"] [unique_id "amuvLjipAwzptuCxBrh5YQAAARc"]
[Thu Jul 30 15:08:14.647794 2026] [security2:error] [pid 89520:tid 89696] [client 172.237.109.114:61406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvLi0W4wRrtnDoPagPhAAAAbA"]
[Thu Jul 30 15:08:14.691907 2026] [security2:error] [pid 89520:tid 89717] [client 4.232.188.49:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.188.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.okcasino-1.com"] [uri "/clarebypas.php"] [unique_id "amuvLi0W4wRrtnDoPagPiwAAAcU"]
[Thu Jul 30 15:08:14.692023 2026] [security2:error] [pid 89520:tid 89717] [client 4.232.188.49:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.okcasino-1.com"] [uri "/clarebypas.php"] [unique_id "amuvLi0W4wRrtnDoPagPiwAAAcU"]
[Thu Jul 30 15:08:14.816054 2026] [core:notice] [pid 87988:tid 88157] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:16.943178 2026] [core:notice] [pid 89520:tid 89581] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:17.023790 2026] [security2:error] [pid 87988:tid 88236] [client 4.225.203.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amuvMDipAwzptuCxBrh5ewAAAYA"]
[Thu Jul 30 15:08:17.451962 2026] [security2:error] [pid 87988:tid 88198] [client 4.225.203.146:60986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/file.php"] [unique_id "amuvMTipAwzptuCxBrh5jgAAAVo"]
[Thu Jul 30 15:08:17.503519 2026] [security2:error] [pid 89520:tid 89699] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "theregentsbarber.com.au"] [uri "/index.php"] [unique_id "amuvLy0W4wRrtnDoPagPjQAAAbM"]
[Thu Jul 30 15:08:17.682629 2026] [security2:error] [pid 87988:tid 88182] [client 172.237.109.114:30417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvMTipAwzptuCxBrh5jQAAAUo"]
[Thu Jul 30 15:08:18.500525 2026] [autoindex:error] [pid 87988:tid 88129] [client 4.225.203.146:62669] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:08:18.653225 2026] [security2:error] [pid 87988:tid 88139] [client 4.225.203.146:62669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/bolt.php"] [unique_id "amuvMjipAwzptuCxBrh5ogAAAR8"]
[Thu Jul 30 15:08:18.671349 2026] [core:notice] [pid 89520:tid 89665] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:18.674491 2026] [security2:error] [pid 89520:tid 89665] [client 66.249.79.8:37156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/download/9501/4233"] [unique_id "amuvMi0W4wRrtnDoPagPnwAAAZE"]
[Thu Jul 30 15:08:19.695733 2026] [security2:error] [pid 89520:tid 89703] [client 4.225.203.146:11856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/3.php"] [unique_id "amuvMy0W4wRrtnDoPagPqgAAAbc"]
[Thu Jul 30 15:08:20.560871 2026] [security2:error] [pid 89520:tid 89567] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvNC0W4wRrtnDoPagPswAB2yU"]
[Thu Jul 30 15:08:20.561053 2026] [security2:error] [pid 89520:tid 89739] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvNC0W4wRrtnDoPagPswAB2yU"]
[Thu Jul 30 15:08:20.760449 2026] [security2:error] [pid 87988:tid 88191] [client 4.225.203.146:50889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/222.php"] [unique_id "amuvNDipAwzptuCxBrh5vwAAAVM"]
[Thu Jul 30 15:08:21.112313 2026] [security2:error] [pid 87988:tid 88137] [client 78.47.98.55:63490] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuvNTipAwzptuCxBrh5xAAAAR0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:08:21.521835 2026] [security2:error] [pid 87988:tid 88198] [client 4.225.203.146:36559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuvNTipAwzptuCxBrh52AAAAVo"]
[Thu Jul 30 15:08:21.554889 2026] [security2:error] [pid 87988:tid 88211] [client 172.237.109.114:62864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvNTipAwzptuCxBrh5wwAAAWc"]
[Thu Jul 30 15:08:21.713895 2026] [core:notice] [pid 87988:tid 88119] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:21.718391 2026] [security2:error] [pid 87988:tid 88119] [client 78.47.98.55:63506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuvNTipAwzptuCxBrh53wAAAQs"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:08:22.098009 2026] [security2:error] [pid 87988:tid 88130] [client 78.47.98.55:63518] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuvNjipAwzptuCxBrh55gAAARY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:08:22.572452 2026] [core:notice] [pid 87988:tid 88009] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:23.923254 2026] [security2:error] [pid 87988:tid 88236] [client 185.200.117.131:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuvNzipAwzptuCxBrh6CQAAAYA"]
[Thu Jul 30 15:08:23.923348 2026] [security2:error] [pid 87988:tid 88236] [client 185.200.117.131:50368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuvNzipAwzptuCxBrh6CQAAAYA"]
[Thu Jul 30 15:08:24.547234 2026] [security2:error] [pid 87988:tid 88154] [client 172.237.109.114:30826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvODipAwzptuCxBrh6EAAAAS4"]
[Thu Jul 30 15:08:25.082468 2026] [security2:error] [pid 87988:tid 88149] [client 216.73.216.174:41084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.pkf.jo"] [uri "/index.php"] [unique_id "amuvODipAwzptuCxBrh6GwABKSM"]
[Thu Jul 30 15:08:26.085412 2026] [security2:error] [pid 87988:tid 88232] [client 4.225.203.146:50628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuvOjipAwzptuCxBrh6NwAAAXw"]
[Thu Jul 30 15:08:27.779726 2026] [autoindex:error] [pid 87988:tid 88149] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:08:27.933613 2026] [security2:error] [pid 87988:tid 88157] [client 4.225.203.146:50679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/admin.php"] [unique_id "amuvOzipAwzptuCxBrh6YwAAATE"]
[Thu Jul 30 15:08:29.004461 2026] [security2:error] [pid 87988:tid 88148] [client 4.225.203.146:11901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-configs.php"] [unique_id "amuvPTipAwzptuCxBrh6gAAAASg"]
[Thu Jul 30 15:08:29.638708 2026] [security2:error] [pid 87988:tid 88060] [remote 57.141.0.49:64830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuvPTipAwzptuCxBrh6jQABgEc"]
[Thu Jul 30 15:08:30.355371 2026] [security2:error] [pid 87988:tid 88215] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvPTipAwzptuCxBrh6kwAAAWs"]
[Thu Jul 30 15:08:30.458125 2026] [security2:error] [pid 87988:tid 88209] [client 172.237.109.114:39359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvPjipAwzptuCxBrh6mwAAAWU"]
[Thu Jul 30 15:08:31.144081 2026] [security2:error] [pid 87988:tid 88058] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvPzipAwzptuCxBrh6sAABhUU"]
[Thu Jul 30 15:08:31.144261 2026] [security2:error] [pid 87988:tid 88241] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvPzipAwzptuCxBrh6sAABhUU"]
[Thu Jul 30 15:08:31.593323 2026] [security2:error] [pid 87988:tid 88201] [client 172.237.109.114:60101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvPzipAwzptuCxBrh6rwAAAV0"]
[Thu Jul 30 15:08:32.144297 2026] [security2:error] [pid 87988:tid 88124] [client 20.171.55.167:3410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/.__info.php"] [unique_id "amuvQDipAwzptuCxBrh6xQAAARA"]
[Thu Jul 30 15:08:32.441625 2026] [security2:error] [pid 87988:tid 88240] [client 4.225.203.146:16515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/php.php"] [unique_id "amuvQDipAwzptuCxBrh60gAAAYQ"]
[Thu Jul 30 15:08:32.897433 2026] [security2:error] [pid 87988:tid 88145] [client 20.171.55.167:3446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/00.php"] [unique_id "amuvQDipAwzptuCxBrh62QAAASU"]
[Thu Jul 30 15:08:33.126270 2026] [security2:error] [pid 87988:tid 88235] [client 74.7.228.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.austriavisaapplicationcenterinislamabad.site"] [uri "/index.php"] [unique_id "amuvPzipAwzptuCxBrh6xAABfwk"]
[Thu Jul 30 15:08:33.126303 2026] [security2:error] [pid 87988:tid 88235] [client 74.7.228.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.austriavisaapplicationcenterinislamabad.site"] [uri "/index.php"] [unique_id "amuvPzipAwzptuCxBrh6xAABfwk"]
[Thu Jul 30 15:08:33.322612 2026] [security2:error] [pid 87988:tid 88205] [client 4.225.203.146:62303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wk/index.php"] [unique_id "amuvQTipAwzptuCxBrh65AAAAWE"]
[Thu Jul 30 15:08:33.400088 2026] [core:error] [pid 87988:tid 88168] [client 66.249.79.74:42379] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:08:33.400110 2026] [core:error] [pid 87988:tid 88168] [client 66.249.79.74:42379] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:08:33.743517 2026] [security2:error] [pid 87988:tid 88197] [client 20.171.55.167:3436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/13.php"] [unique_id "amuvQTipAwzptuCxBrh67AAAAVk"]
[Thu Jul 30 15:08:34.550169 2026] [security2:error] [pid 87988:tid 88143] [client 4.225.203.146:34260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/index.php"] [unique_id "amuvQjipAwzptuCxBrh7BwAAASM"]
[Thu Jul 30 15:08:34.553168 2026] [security2:error] [pid 87988:tid 88213] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvQTipAwzptuCxBrh6-QAAAWk"]
[Thu Jul 30 15:08:34.600724 2026] [security2:error] [pid 87988:tid 88099] [remote 74.7.227.39:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuvQjipAwzptuCxBrh7CAABMG4"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/woozone/aa-framework
[Thu Jul 30 15:08:34.970435 2026] [security2:error] [pid 87988:tid 88210] [client 47.128.122.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuvQjipAwzptuCxBrh7DAAAAWY"]
[Thu Jul 30 15:08:35.056972 2026] [core:error] [pid 87988:tid 88189] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:08:35.057005 2026] [core:error] [pid 87988:tid 88189] [client 185.148.0.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:08:35.104591 2026] [security2:error] [pid 87988:tid 88165] [client 20.171.55.167:3330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/2018/03/class-wp-type-registroy.php"] [unique_id "amuvQzipAwzptuCxBrh7GgAAATk"]
[Thu Jul 30 15:08:35.132553 2026] [fcgid:warn] [pid 87988:tid 88154] (70014)End of file found: [client 178.128.51.160:51119] mod_fcgid: can't get data from http client
[Thu Jul 30 15:08:35.848342 2026] [security2:error] [pid 87988:tid 88185] [client 20.171.55.167:3405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/32.php"] [unique_id "amuvQzipAwzptuCxBrh7JgAAAU0"]
[Thu Jul 30 15:08:36.260662 2026] [core:notice] [pid 87988:tid 88231] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:36.481332 2026] [security2:error] [pid 87988:tid 88243] [client 4.225.203.146:60133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/av.php"] [unique_id "amuvRDipAwzptuCxBrh7NQAAAYc"]
[Thu Jul 30 15:08:36.612170 2026] [security2:error] [pid 87988:tid 88225] [client 20.171.55.167:3420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/520.php"] [unique_id "amuvRDipAwzptuCxBrh7PAAAAXU"]
[Thu Jul 30 15:08:36.674051 2026] [security2:error] [pid 87988:tid 88166] [client 20.118.34.237:9224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guethleentertainment.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuvRDipAwzptuCxBrh7PQAAATo"]
[Thu Jul 30 15:08:36.720061 2026] [core:notice] [pid 87988:tid 88220] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:36.729302 2026] [security2:error] [pid 87988:tid 88227] [client 4.225.203.146:33816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/a.php"] [unique_id "amuvRDipAwzptuCxBrh7QgAAAXc"]
[Thu Jul 30 15:08:36.796869 2026] [security2:error] [pid 87988:tid 88136] [client 197.14.87.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvRDipAwzptuCxBrh7LQABHCI"], referer: https://allmontecristi.com
[Thu Jul 30 15:08:37.257767 2026] [security2:error] [pid 87988:tid 88011] [remote 74.7.243.224:42186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuvRTipAwzptuCxBrh7TAABMBY"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:08:37.294276 2026] [security2:error] [pid 87988:tid 88179] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvRDipAwzptuCxBrh7QQAAAUc"]
[Thu Jul 30 15:08:37.455207 2026] [security2:error] [pid 87988:tid 88171] [client 20.171.55.167:3421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/991176.php"] [unique_id "amuvRTipAwzptuCxBrh7UAAAAT8"]
[Thu Jul 30 15:08:37.474516 2026] [security2:error] [pid 87988:tid 88143] [client 4.225.203.146:33335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mini.php"] [unique_id "amuvRTipAwzptuCxBrh7UQAAASM"]
[Thu Jul 30 15:08:37.633965 2026] [autoindex:error] [pid 87988:tid 88180] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:08:37.813406 2026] [autoindex:error] [pid 87988:tid 88123] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:08:38.054878 2026] [security2:error] [pid 87988:tid 88185] [client 4.225.203.146:11537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuvRjipAwzptuCxBrh7ZAAAAU0"]
[Thu Jul 30 15:08:38.372672 2026] [security2:error] [pid 87988:tid 88157] [client 20.171.55.167:3449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/Cache/upfile.php"] [unique_id "amuvRjipAwzptuCxBrh7bwAAATE"]
[Thu Jul 30 15:08:38.962889 2026] [core:notice] [pid 87988:tid 88191] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:39.153767 2026] [security2:error] [pid 87988:tid 88188] [client 20.171.55.167:3429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/Diff/Renderer/about.php"] [unique_id "amuvRzipAwzptuCxBrh7lwAAAVA"]
[Thu Jul 30 15:08:39.293281 2026] [security2:error] [pid 87988:tid 88245] [client 185.177.72.68:52410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvRzipAwzptuCxBrh7pAAAAYk"]
[Thu Jul 30 15:08:39.456409 2026] [security2:error] [pid 87988:tid 88207] [client 4.225.203.146:45895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/aa.php"] [unique_id "amuvRzipAwzptuCxBrh7qQAAAWM"]
[Thu Jul 30 15:08:39.682764 2026] [security2:error] [pid 87988:tid 88123] [client 4.225.203.146:33829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin.php"] [unique_id "amuvRzipAwzptuCxBrh7tgAAAQ8"]
[Thu Jul 30 15:08:39.935105 2026] [security2:error] [pid 87988:tid 88183] [client 20.171.55.167:3335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/FoxWSOv1.php"] [unique_id "amuvRzipAwzptuCxBrh7wwAAAUs"]
[Thu Jul 30 15:08:39.978993 2026] [security2:error] [pid 87988:tid 88236] [client 185.177.72.68:52410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/api.swp"] [unique_id "amuvRzipAwzptuCxBrh7xQAAAYA"]
[Thu Jul 30 15:08:40.069813 2026] [security2:error] [pid 87988:tid 88124] [client 4.225.203.146:60115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/w.php"] [unique_id "amuvSDipAwzptuCxBrh7xgAAARA"]
[Thu Jul 30 15:08:40.379659 2026] [security2:error] [pid 87988:tid 88235] [client 185.177.72.68:52410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvSDipAwzptuCxBrh71gAAAX8"]
[Thu Jul 30 15:08:40.666530 2026] [security2:error] [pid 87988:tid 88133] [client 20.171.55.167:3404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/Mhbgf.php"] [unique_id "amuvSDipAwzptuCxBrh74QAAARk"]
[Thu Jul 30 15:08:40.934149 2026] [core:notice] [pid 87988:tid 88120] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:41.068465 2026] [security2:error] [pid 87988:tid 88121] [client 185.177.72.68:52410] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.git%00"] [unique_id "amuvSTipAwzptuCxBrh79wAAAQ0"]
[Thu Jul 30 15:08:41.370264 2026] [security2:error] [pid 87988:tid 88168] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvSDipAwzptuCxBrh76AABPFc"]
[Thu Jul 30 15:08:41.524291 2026] [security2:error] [pid 87988:tid 88146] [client 20.171.55.167:3336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/RxR_ghail.php"] [unique_id "amuvSTipAwzptuCxBrh8CgAAASY"]
[Thu Jul 30 15:08:41.546891 2026] [security2:error] [pid 87988:tid 88179] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvSDipAwzptuCxBrh79gABR1w"]
[Thu Jul 30 15:08:41.710757 2026] [security2:error] [pid 87988:tid 88089] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvSTipAwzptuCxBrh8FAABS2Q"]
[Thu Jul 30 15:08:41.710887 2026] [security2:error] [pid 87988:tid 88183] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvSTipAwzptuCxBrh8FAABS2Q"]
[Thu Jul 30 15:08:42.187381 2026] [security2:error] [pid 87988:tid 88125] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvSTipAwzptuCxBrh8DQAAARE"]
[Thu Jul 30 15:08:42.396664 2026] [security2:error] [pid 87988:tid 88205] [client 20.171.55.167:3342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/Text/admin.php"] [unique_id "amuvSjipAwzptuCxBrh8NQAAAWE"]
[Thu Jul 30 15:08:42.521719 2026] [security2:error] [pid 87988:tid 88071] [remote 57.141.18.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuvSjipAwzptuCxBrh8OQABhVI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,lycra,polyester,silicon,steel,titanium,plastic,cotton,nylon&min_price=300&orderby=popularity&rating=5&status=sale&filter_brand=vitra&unfilter=1
[Thu Jul 30 15:08:42.600795 2026] [security2:error] [pid 87988:tid 88120] [client 185.177.72.68:52410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvSjipAwzptuCxBrh8OgAAAQw"]
[Thu Jul 30 15:08:42.708605 2026] [security2:error] [pid 87988:tid 88191] [client 4.225.203.146:32579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/size.php"] [unique_id "amuvSjipAwzptuCxBrh8OwAAAVM"]
[Thu Jul 30 15:08:42.735185 2026] [security2:error] [pid 87988:tid 88153] [client 185.177.72.68:52410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvSjipAwzptuCxBrh8PQAAAS0"]
[Thu Jul 30 15:08:42.866647 2026] [security2:error] [pid 87988:tid 88147] [client 185.177.72.68:52410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvSjipAwzptuCxBrh8QgAAASc"]
[Thu Jul 30 15:08:42.872830 2026] [security2:error] [pid 87988:tid 88181] [client 4.225.203.146:9292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/admin.php"] [unique_id "amuvSjipAwzptuCxBrh8RAAAAUk"]
[Thu Jul 30 15:08:42.994584 2026] [security2:error] [pid 87988:tid 88148] [client 185.177.72.68:52410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvSjipAwzptuCxBrh8SQAAASg"]
[Thu Jul 30 15:08:43.173101 2026] [security2:error] [pid 87988:tid 88170] [client 20.171.55.167:3398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/Yetix.php"] [unique_id "amuvSzipAwzptuCxBrh8TwAAAT4"]
[Thu Jul 30 15:08:43.278466 2026] [security2:error] [pid 87988:tid 88053] [remote 57.141.18.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuvSzipAwzptuCxBrh8SgABE0A"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum,carbon,lycra,polyester,silicon,steel,titanium,plastic,cotton,nylon&min_price=300&orderby=popularity&rating=5&status=sale&filter_brand=vitra&unfilter=1
[Thu Jul 30 15:08:43.555187 2026] [security2:error] [pid 87988:tid 88168] [client 4.225.203.146:51100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuvSzipAwzptuCxBrh8ZQAAATw"]
[Thu Jul 30 15:08:43.959446 2026] [security2:error] [pid 87988:tid 88133] [client 20.171.55.167:3332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/abuot.php"] [unique_id "amuvSzipAwzptuCxBrh8dgAAARk"]
[Thu Jul 30 15:08:44.268285 2026] [security2:error] [pid 87988:tid 88235] [client 4.225.203.146:48359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuvTDipAwzptuCxBrh8fQAAAX8"]
[Thu Jul 30 15:08:44.578233 2026] [security2:error] [pid 87988:tid 88149] [client 74.7.241.140:53300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kicksity.com"] [uri "/index.html"] [unique_id "amuvTDipAwzptuCxBrh8eQABKVs"], referer: http://langit69.net/robots.txt
[Thu Jul 30 15:08:44.696683 2026] [security2:error] [pid 87988:tid 88218] [client 20.171.55.167:3413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/admin-footer.php"] [unique_id "amuvTDipAwzptuCxBrh8jQAAAW4"]
[Thu Jul 30 15:08:45.084033 2026] [security2:error] [pid 87988:tid 88211] [client 4.225.203.146:33360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/m.php"] [unique_id "amuvTTipAwzptuCxBrh8nwAAAWc"]
[Thu Jul 30 15:08:45.461180 2026] [core:notice] [pid 87988:tid 88067] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:45.947625 2026] [security2:error] [pid 87988:tid 88138] [client 20.171.55.167:3338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/administratork.php"] [unique_id "amuvTTipAwzptuCxBrh8vwAAAR4"]
[Thu Jul 30 15:08:45.994357 2026] [security2:error] [pid 87988:tid 88125] [client 4.225.203.146:11671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/403.php"] [unique_id "amuvTTipAwzptuCxBrh8wwAAARE"]
[Thu Jul 30 15:08:46.586954 2026] [security2:error] [pid 87988:tid 88135] [client 172.237.109.114:29678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvTjipAwzptuCxBrh8yAAAARs"]
[Thu Jul 30 15:08:46.779506 2026] [security2:error] [pid 87988:tid 88165] [client 20.171.55.167:3387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/akc.php"] [unique_id "amuvTjipAwzptuCxBrh85AAAATk"]
[Thu Jul 30 15:08:46.901139 2026] [core:notice] [pid 87988:tid 88194] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:47.191119 2026] [security2:error] [pid 87988:tid 88221] [client 4.225.203.146:23362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuvTzipAwzptuCxBrh8_QAAAXE"]
[Thu Jul 30 15:08:47.381960 2026] [core:notice] [pid 87988:tid 88199] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:47.567266 2026] [security2:error] [pid 87988:tid 88138] [client 20.171.55.167:3426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/alfaaneh.php"] [unique_id "amuvTzipAwzptuCxBrh9FAAAAR4"]
[Thu Jul 30 15:08:48.292426 2026] [security2:error] [pid 87988:tid 88206] [client 20.171.55.167:3445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/alfav4.1.php"] [unique_id "amuvUDipAwzptuCxBrh9MQAAAWI"]
[Thu Jul 30 15:08:48.351577 2026] [security2:error] [pid 87988:tid 88228] [client 37.77.56.246:56520] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuvUDipAwzptuCxBrh9NQAAAXg"]
[Thu Jul 30 15:08:48.351661 2026] [security2:error] [pid 87988:tid 88228] [client 37.77.56.246:56520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuvUDipAwzptuCxBrh9NQAAAXg"]
[Thu Jul 30 15:08:48.379893 2026] [security2:error] [pid 87988:tid 88215] [client 4.225.203.146:11697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuvUDipAwzptuCxBrh9NgAAAWs"]
[Thu Jul 30 15:08:48.448080 2026] [core:error] [pid 87988:tid 88194] [client 4.225.203.146:44519] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:08:48.448103 2026] [core:error] [pid 87988:tid 88194] [client 4.225.203.146:44519] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:08:48.623607 2026] [security2:error] [pid 87988:tid 88150] [client 185.177.72.68:52410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/info.php"] [unique_id "amuvUDipAwzptuCxBrh9RAAAASo"]
[Thu Jul 30 15:08:48.878748 2026] [security2:error] [pid 87988:tid 88148] [client 185.177.72.68:18504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/info.php%257e"] [unique_id "amuvUDipAwzptuCxBrh9SQAAASg"]
[Thu Jul 30 15:08:49.129615 2026] [security2:error] [pid 87988:tid 88222] [client 185.177.72.68:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/info.php%28%28"] [unique_id "amuvUTipAwzptuCxBrh9UgAAAXI"]
[Thu Jul 30 15:08:49.169440 2026] [security2:error] [pid 87988:tid 88137] [client 20.171.55.167:3347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/ans.php"] [unique_id "amuvUTipAwzptuCxBrh9UwAAAR0"]
[Thu Jul 30 15:08:49.384969 2026] [security2:error] [pid 87988:tid 88152] [client 185.177.72.68:18520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/info.php/"] [unique_id "amuvUTipAwzptuCxBrh9VwAAASw"]
[Thu Jul 30 15:08:49.560278 2026] [security2:error] [pid 87988:tid 88223] [client 172.237.109.114:21538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvUTipAwzptuCxBrh9TgAAAXM"]
[Thu Jul 30 15:08:49.583634 2026] [core:notice] [pid 87988:tid 88219] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:49.608818 2026] [security2:error] [pid 87988:tid 88232] [client 4.225.203.146:10197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/classwithtostring.php"] [unique_id "amuvUTipAwzptuCxBrh9XAAAAXw"]
[Thu Jul 30 15:08:49.898784 2026] [security2:error] [pid 87988:tid 88193] [client 185.200.117.131:37354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuvUTipAwzptuCxBrh9awAAAVU"]
[Thu Jul 30 15:08:49.898883 2026] [security2:error] [pid 87988:tid 88193] [client 185.200.117.131:37354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuvUTipAwzptuCxBrh9awAAAVU"]
[Thu Jul 30 15:08:50.066393 2026] [security2:error] [pid 87988:tid 88142] [client 20.171.55.167:3443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/applicationk.php"] [unique_id "amuvUjipAwzptuCxBrh9dQAAASI"]
[Thu Jul 30 15:08:50.191848 2026] [security2:error] [pid 87988:tid 88203] [client 4.225.203.146:32598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/as.php"] [unique_id "amuvUjipAwzptuCxBrh9fAAAAV8"]
[Thu Jul 30 15:08:50.510946 2026] [security2:error] [pid 87988:tid 88121] [client 4.225.203.146:10235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gmo.php"] [unique_id "amuvUjipAwzptuCxBrh9hgAAAQ0"]
[Thu Jul 30 15:08:50.627504 2026] [security2:error] [pid 87988:tid 88205] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvUjipAwzptuCxBrh9cQAAAWE"]
[Thu Jul 30 15:08:50.798009 2026] [security2:error] [pid 87988:tid 88227] [client 20.171.55.167:3411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/asetk.php"] [unique_id "amuvUjipAwzptuCxBrh9lgAAAXc"]
[Thu Jul 30 15:08:51.529703 2026] [security2:error] [pid 87988:tid 88185] [client 20.171.55.167:3450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/audio.php"] [unique_id "amuvUzipAwzptuCxBrh9sgAAAU0"]
[Thu Jul 30 15:08:52.260142 2026] [security2:error] [pid 87988:tid 88019] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvVDipAwzptuCxBrh9zwABWR4"]
[Thu Jul 30 15:08:52.260297 2026] [security2:error] [pid 87988:tid 88197] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvVDipAwzptuCxBrh9zwABWR4"]
[Thu Jul 30 15:08:52.313858 2026] [security2:error] [pid 87988:tid 88126] [client 4.225.203.146:37230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuvVDipAwzptuCxBrh90AAAARI"]
[Thu Jul 30 15:08:52.370732 2026] [security2:error] [pid 87988:tid 88242] [client 20.171.55.167:3584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/azdare.php"] [unique_id "amuvVDipAwzptuCxBrh91gAAAYY"]
[Thu Jul 30 15:08:53.449790 2026] [security2:error] [pid 87988:tid 88219] [client 20.171.55.167:3441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/beence.php"] [unique_id "amuvVTipAwzptuCxBrh-AQAAAW8"]
[Thu Jul 30 15:08:53.567240 2026] [security2:error] [pid 87988:tid 88240] [client 4.225.203.146:44537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-the.php"] [unique_id "amuvVTipAwzptuCxBrh-CwAAAYQ"]
[Thu Jul 30 15:08:54.001909 2026] [security2:error] [pid 87988:tid 88018] [remote 57.141.0.31:41654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuvVjipAwzptuCxBrh-IQABFx0"]
[Thu Jul 30 15:08:54.010955 2026] [core:error] [pid 87988:tid 88228] [client 66.249.73.100:36423] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:08:54.010989 2026] [core:error] [pid 87988:tid 88228] [client 66.249.73.100:36423] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:08:54.297753 2026] [security2:error] [pid 87988:tid 88227] [client 185.200.117.131:37370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuvVjipAwzptuCxBrh-LwAAAXc"]
[Thu Jul 30 15:08:54.297898 2026] [security2:error] [pid 87988:tid 88227] [client 185.200.117.131:37370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuvVjipAwzptuCxBrh-LwAAAXc"]
[Thu Jul 30 15:08:54.313341 2026] [security2:error] [pid 87988:tid 88160] [client 20.171.55.167:3345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/block-editor.php"] [unique_id "amuvVjipAwzptuCxBrh-MQAAATQ"]
[Thu Jul 30 15:08:54.504167 2026] [security2:error] [pid 87988:tid 88189] [client 4.225.203.146:51077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuvVjipAwzptuCxBrh-OwAAAVE"]
[Thu Jul 30 15:08:54.647831 2026] [security2:error] [pid 87988:tid 88196] [client 4.225.203.146:37241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/404.php"] [unique_id "amuvVjipAwzptuCxBrh-QgAAAVg"]
[Thu Jul 30 15:08:54.981960 2026] [security2:error] [pid 87988:tid 88195] [client 74.7.228.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.evermed-med-sa.com"] [uri "/cgi-sys/404.html"] [unique_id "amuvVjipAwzptuCxBrh-UAABVyQ"]
[Thu Jul 30 15:08:55.179057 2026] [security2:error] [pid 87988:tid 88154] [client 20.171.55.167:3408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/bootstrapwp.php"] [unique_id "amuvVzipAwzptuCxBrh-WgAAAS4"]
[Thu Jul 30 15:08:55.330399 2026] [security2:error] [pid 87988:tid 88201] [client 4.225.203.146:46452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/init.php"] [unique_id "amuvVzipAwzptuCxBrh-ZAAAAV0"]
[Thu Jul 30 15:08:55.687706 2026] [core:notice] [pid 87988:tid 88062] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:55.689927 2026] [security2:error] [pid 87988:tid 88244] [client 74.7.241.155:58646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuvVzipAwzptuCxBrh-dAABiEk"], referer: https://insurancecouncilinc.com/
[Thu Jul 30 15:08:55.691157 2026] [security2:error] [pid 87988:tid 88178] [client 185.177.72.68:18528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/phpinfo.php"] [unique_id "amuvVzipAwzptuCxBrh-dQAAAUY"]
[Thu Jul 30 15:08:55.774854 2026] [security2:error] [pid 87988:tid 88153] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvVzipAwzptuCxBrh-XQAAAS0"]
[Thu Jul 30 15:08:55.904795 2026] [core:notice] [pid 87988:tid 88050] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:08:55.907085 2026] [security2:error] [pid 87988:tid 88188] [client 74.7.241.155:58646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.nordeste1.com"] [uri "/category/politica/"] [unique_id "amuvVzipAwzptuCxBrh-fAABUD0"], referer: https://www.nordeste1.com/category/policiais/
[Thu Jul 30 15:08:55.961175 2026] [security2:error] [pid 87988:tid 88198] [client 185.177.72.68:19642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/phpinfo.php%255f"] [unique_id "amuvVzipAwzptuCxBrh-fQAAAVo"]
[Thu Jul 30 15:08:55.971547 2026] [security2:error] [pid 87988:tid 88222] [client 20.171.55.167:3334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/by.php"] [unique_id "amuvVzipAwzptuCxBrh-fgAAAXI"]
[Thu Jul 30 15:08:56.228462 2026] [security2:error] [pid 87988:tid 88211] [client 185.177.72.68:19650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/phpinfo.php%253c"] [unique_id "amuvWDipAwzptuCxBrh-hgAAAWc"]
[Thu Jul 30 15:08:56.481879 2026] [security2:error] [pid 87988:tid 88219] [client 185.177.72.68:19654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/phpinfo.php%255d"] [unique_id "amuvWDipAwzptuCxBrh-igAAAW8"]
[Thu Jul 30 15:08:56.524435 2026] [security2:error] [pid 87988:tid 88221] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvVzipAwzptuCxBrh-ewABcTo"]
[Thu Jul 30 15:08:56.579380 2026] [security2:error] [pid 87988:tid 88224] [client 185.200.117.131:37374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuvWDipAwzptuCxBrh-jgAAAXQ"]
[Thu Jul 30 15:08:56.579487 2026] [security2:error] [pid 87988:tid 88224] [client 185.200.117.131:37374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuvWDipAwzptuCxBrh-jgAAAXQ"]
[Thu Jul 30 15:08:56.871720 2026] [security2:error] [pid 87988:tid 88215] [client 20.104.18.253:24477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/vv.php"] [unique_id "amuvWDipAwzptuCxBrh-lQAAAWs"]
[Thu Jul 30 15:08:57.268145 2026] [security2:error] [pid 87988:tid 88136] [client 4.225.203.146:18011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/file5.php"] [unique_id "amuvWTipAwzptuCxBrh-rAAAARw"]
[Thu Jul 30 15:08:57.477654 2026] [security2:error] [pid 87988:tid 88213] [client 20.104.18.253:24488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/vwcleanerplugin/bump.php"] [unique_id "amuvWTipAwzptuCxBrh-tgAAAWk"]
[Thu Jul 30 15:08:57.517910 2026] [security2:error] [pid 87988:tid 88237] [client 20.171.55.167:3428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/cachewp.php"] [unique_id "amuvWTipAwzptuCxBrh-twAAAYE"]
[Thu Jul 30 15:08:57.944471 2026] [security2:error] [pid 87988:tid 88159] [client 185.177.72.68:19656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/core%7e"] [unique_id "amuvWTipAwzptuCxBrh-xwAAATM"]
[Thu Jul 30 15:08:57.991339 2026] [security2:error] [pid 87988:tid 88056] [remote 57.141.0.35:63590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuvWTipAwzptuCxBrh-yAABbUM"]
[Thu Jul 30 15:08:58.101679 2026] [security2:error] [pid 87988:tid 88190] [client 20.104.18.253:24481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/vwx.php"] [unique_id "amuvWjipAwzptuCxBrh-1QAAAVI"]
[Thu Jul 30 15:08:58.384292 2026] [security2:error] [pid 87988:tid 88218] [client 20.171.55.167:3386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/ccx/index.php"] [unique_id "amuvWjipAwzptuCxBrh-3AAAAW4"]
[Thu Jul 30 15:08:58.708161 2026] [security2:error] [pid 87988:tid 88126] [client 20.104.18.253:25143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/vxrl.php"] [unique_id "amuvWjipAwzptuCxBrh-7wAAARI"]
[Thu Jul 30 15:08:58.927491 2026] [security2:error] [pid 87988:tid 88208] [client 4.225.203.146:48103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuvWjipAwzptuCxBrh-9gAAAWQ"]
[Thu Jul 30 15:08:59.145102 2026] [security2:error] [pid 87988:tid 88149] [client 20.171.55.167:3331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/checkbex.php"] [unique_id "amuvWzipAwzptuCxBrh_BAAAASk"]
[Thu Jul 30 15:08:59.348710 2026] [security2:error] [pid 87988:tid 88162] [client 20.104.18.253:25130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/vy2m7.php"] [unique_id "amuvWzipAwzptuCxBrh_CwAAATY"]
[Thu Jul 30 15:08:59.900017 2026] [security2:error] [pid 87988:tid 88172] [client 4.225.203.146:15825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/plugins.php"] [unique_id "amuvWzipAwzptuCxBrh_IwAAAUA"]
[Thu Jul 30 15:08:59.907820 2026] [security2:error] [pid 87988:tid 88196] [client 20.171.55.167:3423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/class-phpmailer-http.php"] [unique_id "amuvWzipAwzptuCxBrh_JAAAAVg"]
[Thu Jul 30 15:08:59.967056 2026] [security2:error] [pid 87988:tid 88192] [client 20.104.18.253:24474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/w.php"] [unique_id "amuvWzipAwzptuCxBrh_KAAAAVQ"]
[Thu Jul 30 15:09:00.023044 2026] [security2:error] [pid 87988:tid 88220] [client 4.225.203.146:38227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuvXDipAwzptuCxBrh_KQAAAXA"]
[Thu Jul 30 15:09:00.160367 2026] [security2:error] [pid 87988:tid 88130] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvWzipAwzptuCxBrh_FAABFko"]
[Thu Jul 30 15:09:00.327295 2026] [security2:error] [pid 87988:tid 88140] [client 20.226.5.174:34754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/011i.php"] [unique_id "amuvXDipAwzptuCxBrh_PAAAASA"]
[Thu Jul 30 15:09:00.583797 2026] [security2:error] [pid 87988:tid 88181] [client 20.104.18.253:24457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/w3llstore.php"] [unique_id "amuvXDipAwzptuCxBrh_RQAAAUk"]
[Thu Jul 30 15:09:00.713538 2026] [security2:error] [pid 87988:tid 88141] [client 4.225.203.146:19426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuvXDipAwzptuCxBrh_UwAAASE"]
[Thu Jul 30 15:09:00.777740 2026] [security2:error] [pid 87988:tid 88167] [client 20.171.55.167:3364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/class-wp-font-utils.php"] [unique_id "amuvXDipAwzptuCxBrh_WQAAATs"]
[Thu Jul 30 15:09:00.920377 2026] [security2:error] [pid 87988:tid 88237] [client 47.79.13.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "exploringchanges.com"] [uri "/index.php"] [unique_id "amuvXDipAwzptuCxBrh_TgAAAYE"]
[Thu Jul 30 15:09:00.954965 2026] [security2:error] [pid 87988:tid 88174] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvXDipAwzptuCxBrh_QAAAAUI"]
[Thu Jul 30 15:09:01.260971 2026] [security2:error] [pid 87988:tid 88182] [client 20.104.18.253:24468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/waf_defender.php"] [unique_id "amuvXTipAwzptuCxBrh_awAAAUo"]
[Thu Jul 30 15:09:01.685119 2026] [security2:error] [pid 87988:tid 88220] [client 20.171.55.167:3424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/class-wp-simple-js.php"] [unique_id "amuvXTipAwzptuCxBrh_gAAAAXA"]
[Thu Jul 30 15:09:01.698266 2026] [security2:error] [pid 87988:tid 88157] [client 20.226.5.174:34773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/03a005685d.php"] [unique_id "amuvXTipAwzptuCxBrh_gQAAATE"]
[Thu Jul 30 15:09:01.698815 2026] [security2:error] [pid 87988:tid 88139] [client 4.225.203.146:19425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/go.php"] [unique_id "amuvXTipAwzptuCxBrh_ggAAAR8"]
[Thu Jul 30 15:09:01.858341 2026] [security2:error] [pid 87988:tid 88239] [client 20.104.18.253:25111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/wander.php"] [unique_id "amuvXTipAwzptuCxBrh_iQAAAYM"]
[Thu Jul 30 15:09:01.910738 2026] [security2:error] [pid 87988:tid 88213] [client 185.177.72.68:19656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/test.php"] [unique_id "amuvXTipAwzptuCxBrh_igAAAWk"]
[Thu Jul 30 15:09:02.173525 2026] [security2:error] [pid 87988:tid 88169] [client 185.177.72.68:19670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/test.php..."] [unique_id "amuvXjipAwzptuCxBrh_kQAAAT0"]
[Thu Jul 30 15:09:02.340270 2026] [security2:error] [pid 87988:tid 88158] [client 241.143.35.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuvXTipAwzptuCxBrh_bgABMn4"], referer: https://flixon.net/video/fire-starter-vj-junior/
[Thu Jul 30 15:09:02.424911 2026] [security2:error] [pid 87988:tid 88199] [client 185.177.72.68:19678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/test.php%09%09"] [unique_id "amuvXjipAwzptuCxBrh_mAAAAVs"]
[Thu Jul 30 15:09:02.430822 2026] [security2:error] [pid 87988:tid 88141] [client 20.171.55.167:3343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/clay.php"] [unique_id "amuvXjipAwzptuCxBrh_mQAAASE"]
[Thu Jul 30 15:09:02.464638 2026] [security2:error] [pid 87988:tid 88202] [client 20.104.18.253:25132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/wawe.php"] [unique_id "amuvXjipAwzptuCxBrh_mgAAAV4"]
[Thu Jul 30 15:09:02.504930 2026] [core:error] [pid 87988:tid 88183] [client 74.7.244.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:02.504955 2026] [core:error] [pid 87988:tid 88183] [client 74.7.244.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:02.505109 2026] [security2:error] [pid 87988:tid 88183] [client 74.7.244.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.ymk.udi.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuvXjipAwzptuCxBrh_nQAAAUs"]
[Thu Jul 30 15:09:02.505655 2026] [security2:error] [pid 87988:tid 88152] [client 74.7.244.9:38078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.ymk.udi.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuvXjipAwzptuCxBrh_mwABLFU"]
[Thu Jul 30 15:09:02.675398 2026] [security2:error] [pid 87988:tid 88178] [client 185.177.72.68:19684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/test.php...."] [unique_id "amuvXjipAwzptuCxBrh_oQAAAUY"]
[Thu Jul 30 15:09:02.777869 2026] [security2:error] [pid 87988:tid 88004] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvXjipAwzptuCxBrh_pgABZg8"]
[Thu Jul 30 15:09:02.778022 2026] [security2:error] [pid 87988:tid 88210] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvXjipAwzptuCxBrh_pgABZg8"]
[Thu Jul 30 15:09:02.807771 2026] [security2:error] [pid 87988:tid 88167] [client 20.226.5.174:34755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/403.php"] [unique_id "amuvXjipAwzptuCxBrh_pwAAATs"]
[Thu Jul 30 15:09:03.130859 2026] [security2:error] [pid 87988:tid 88227] [client 20.104.18.253:25122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/wb.php"] [unique_id "amuvXzipAwzptuCxBrh_rwAAAXc"]
[Thu Jul 30 15:09:03.240272 2026] [security2:error] [pid 87988:tid 88211] [client 20.171.55.167:3329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/colors/about.php"] [unique_id "amuvXzipAwzptuCxBrh_tQAAAWc"]
[Thu Jul 30 15:09:03.639881 2026] [core:notice] [pid 87988:tid 88070] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:03.700487 2026] [security2:error] [pid 87988:tid 88153] [client 4.225.203.146:19230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/test1.php"] [unique_id "amuvXzipAwzptuCxBrh_ywAAAS0"]
[Thu Jul 30 15:09:03.742068 2026] [security2:error] [pid 87988:tid 88147] [client 20.104.18.253:25145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/we.php"] [unique_id "amuvXzipAwzptuCxBrh_zwAAASc"]
[Thu Jul 30 15:09:03.878534 2026] [security2:error] [pid 87988:tid 88196] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvXzipAwzptuCxBrh_uwAAAVg"]
[Thu Jul 30 15:09:03.916686 2026] [core:error] [pid 87988:tid 88099] [remote 74.7.228.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:03.916707 2026] [core:error] [pid 87988:tid 88099] [remote 74.7.228.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:03.916904 2026] [security2:error] [pid 87988:tid 88140] [client 74.7.228.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "prestigemassagestudio.cfd"] [uri "/index.php"] [unique_id "amuvXzipAwzptuCxBrh_3AABIG4"]
[Thu Jul 30 15:09:04.074747 2026] [security2:error] [pid 87988:tid 88214] [client 20.171.55.167:3351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/colors/blue/gold.php"] [unique_id "amuvYDipAwzptuCxBrh_4AAAAWo"]
[Thu Jul 30 15:09:04.090743 2026] [security2:error] [pid 87988:tid 88202] [client 74.7.230.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.jto.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/cgi-sys/404.html"] [unique_id "amuvYDipAwzptuCxBrh_4wAAAV4"]
[Thu Jul 30 15:09:04.091341 2026] [security2:error] [pid 87988:tid 88244] [client 74.7.230.33:51410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.jto.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuvYDipAwzptuCxBrh_4QABiAc"]
[Thu Jul 30 15:09:04.215482 2026] [security2:error] [pid 87988:tid 88148] [client 20.226.5.174:34763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/404.php"] [unique_id "amuvYDipAwzptuCxBrh_6AAAASg"]
[Thu Jul 30 15:09:04.338973 2026] [security2:error] [pid 87988:tid 88162] [client 20.104.18.253:24459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/web.php"] [unique_id "amuvYDipAwzptuCxBrh_7wAAATY"]
[Thu Jul 30 15:09:04.349536 2026] [core:notice] [pid 87988:tid 88096] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:04.607259 2026] [security2:error] [pid 87988:tid 88163] [client 185.177.72.68:19700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/localhost.sql"] [unique_id "amuvYDipAwzptuCxBrh_-wAAATc"]
[Thu Jul 30 15:09:04.719531 2026] [autoindex:error] [pid 87988:tid 88186] [client 4.225.203.146:32586] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:04.816093 2026] [security2:error] [pid 87988:tid 88170] [client 4.225.203.146:44483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/shell.php"] [unique_id "amuvYDipAwzptuCxBriAAwAAAT4"]
[Thu Jul 30 15:09:04.913451 2026] [security2:error] [pid 87988:tid 88241] [client 4.225.203.146:32586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/images/index.php"] [unique_id "amuvYDipAwzptuCxBriABwAAAYU"]
[Thu Jul 30 15:09:04.942949 2026] [security2:error] [pid 87988:tid 88165] [client 20.104.18.253:25125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/webadmin.php"] [unique_id "amuvYDipAwzptuCxBriADwAAATk"]
[Thu Jul 30 15:09:04.942995 2026] [security2:error] [pid 87988:tid 88182] [client 20.171.55.167:3396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/colors/coffee/alfa.php"] [unique_id "amuvYDipAwzptuCxBriAEAAAAUo"]
[Thu Jul 30 15:09:05.168547 2026] [security2:error] [pid 87988:tid 88123] [client 185.177.72.68:19700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/db.sql"] [unique_id "amuvYTipAwzptuCxBriAGAAAAQ8"]
[Thu Jul 30 15:09:05.217202 2026] [core:notice] [pid 87988:tid 88131] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:05.404216 2026] [security2:error] [pid 87988:tid 88192] [client 84.17.60.251:44848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuvYTipAwzptuCxBriAIAAAAVQ"]
[Thu Jul 30 15:09:05.546597 2026] [security2:error] [pid 87988:tid 88208] [client 20.104.18.253:25120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/webalfa.php"] [unique_id "amuvYTipAwzptuCxBriAKgAAAWQ"]
[Thu Jul 30 15:09:05.692513 2026] [security2:error] [pid 87988:tid 88244] [client 84.17.60.251:44850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.60.17.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nka.hfl.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuvYTipAwzptuCxBriALwAAAYg"]
[Thu Jul 30 15:09:05.707524 2026] [security2:error] [pid 87988:tid 88137] [client 20.171.55.167:3440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/colors/content.php"] [unique_id "amuvYTipAwzptuCxBriAMAAAAR0"]
[Thu Jul 30 15:09:06.092098 2026] [security2:error] [pid 87988:tid 88152] [client 82.102.27.163:47548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuvYjipAwzptuCxBriARAAAASw"]
[Thu Jul 30 15:09:06.092201 2026] [security2:error] [pid 87988:tid 88152] [client 82.102.27.163:47548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuvYjipAwzptuCxBriARAAAASw"]
[Thu Jul 30 15:09:06.152265 2026] [security2:error] [pid 87988:tid 88209] [client 20.104.18.253:25110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/webdb.php"] [unique_id "amuvYjipAwzptuCxBriASAAAAWU"]
[Thu Jul 30 15:09:06.276638 2026] [security2:error] [pid 87988:tid 88119] [client 84.17.60.251:44562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuvYjipAwzptuCxBriASgAAAQs"]
[Thu Jul 30 15:09:06.490091 2026] [security2:error] [pid 87988:tid 88128] [client 20.226.5.174:34767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/aa.php"] [unique_id "amuvYjipAwzptuCxBriATwAAARQ"]
[Thu Jul 30 15:09:06.518808 2026] [security2:error] [pid 87988:tid 88170] [client 20.171.55.167:3432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/colors/midnight/about.php"] [unique_id "amuvYjipAwzptuCxBriAUAAAAT4"]
[Thu Jul 30 15:09:06.556226 2026] [security2:error] [pid 87988:tid 88157] [client 84.17.60.251:44566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuvYjipAwzptuCxBriAVgAAATE"]
[Thu Jul 30 15:09:06.600226 2026] [security2:error] [pid 87988:tid 88206] [client 4.225.203.146:18661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/f35.php"] [unique_id "amuvYjipAwzptuCxBriAWgAAAWI"]
[Thu Jul 30 15:09:06.653260 2026] [core:notice] [pid 87988:tid 88193] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:06.717175 2026] [security2:error] [pid 87988:tid 88211] [client 27.74.18.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvYjipAwzptuCxBriARQABZyw"], referer: https://allmontecristi.com
[Thu Jul 30 15:09:06.794311 2026] [security2:error] [pid 87988:tid 88150] [client 20.104.18.253:24475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/webk.php"] [unique_id "amuvYjipAwzptuCxBriAYAAAASo"]
[Thu Jul 30 15:09:06.868076 2026] [security2:error] [pid 87988:tid 88213] [client 84.17.60.251:44578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuvYjipAwzptuCxBriAZAAAAWk"]
[Thu Jul 30 15:09:07.149947 2026] [security2:error] [pid 87988:tid 88129] [client 84.17.60.251:44590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuvYzipAwzptuCxBriAdQAAARU"]
[Thu Jul 30 15:09:07.303050 2026] [security2:error] [pid 87988:tid 88126] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvYjipAwzptuCxBriAXAABEiE"]
[Thu Jul 30 15:09:07.432997 2026] [security2:error] [pid 87988:tid 88174] [client 84.17.60.251:44596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuvYzipAwzptuCxBriAfQAAAUI"]
[Thu Jul 30 15:09:07.456900 2026] [security2:error] [pid 87988:tid 88137] [client 20.104.18.253:24449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/webshell.php"] [unique_id "amuvYzipAwzptuCxBriAgAAAAR0"]
[Thu Jul 30 15:09:07.490494 2026] [security2:error] [pid 87988:tid 88194] [client 172.237.109.114:43358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvYzipAwzptuCxBriAawAAAVY"]
[Thu Jul 30 15:09:07.536589 2026] [security2:error] [pid 87988:tid 88235] [client 4.225.203.146:9850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/new.php"] [unique_id "amuvYzipAwzptuCxBriAgQAAAX8"]
[Thu Jul 30 15:09:07.567525 2026] [security2:error] [pid 87988:tid 88244] [client 20.226.5.174:34757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/aafewc0k.php"] [unique_id "amuvYzipAwzptuCxBriAhQAAAYg"]
[Thu Jul 30 15:09:07.652631 2026] [security2:error] [pid 87988:tid 88161] [client 20.171.55.167:3356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/colors/tfileman.php"] [unique_id "amuvYzipAwzptuCxBriAjAAAATU"]
[Thu Jul 30 15:09:07.706235 2026] [security2:error] [pid 87988:tid 88191] [client 84.17.60.251:44598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuvYzipAwzptuCxBriAkAAAAVM"]
[Thu Jul 30 15:09:07.736800 2026] [autoindex:error] [pid 87988:tid 88218] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:07.893646 2026] [security2:error] [pid 87988:tid 88180] [client 85.208.96.207:20988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/06/07/putin-indenizara-familia-de-soldados-mortos-em-guerras/"] [unique_id "amuvYzipAwzptuCxBriAlwAAAUg"]
[Thu Jul 30 15:09:07.893780 2026] [security2:error] [pid 87988:tid 88180] [client 85.208.96.207:20988] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/06/07/putin-indenizara-familia-de-soldados-mortos-em-guerras/"] [unique_id "amuvYzipAwzptuCxBriAlwAAAUg"]
[Thu Jul 30 15:09:07.921704 2026] [security2:error] [pid 87988:tid 88170] [client 4.225.203.146:18459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/asd.php"] [unique_id "amuvYzipAwzptuCxBriAmAAAAT4"]
[Thu Jul 30 15:09:07.994705 2026] [security2:error] [pid 87988:tid 88175] [client 84.17.60.251:44600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuvYzipAwzptuCxBriAnwAAAUM"]
[Thu Jul 30 15:09:08.103713 2026] [security2:error] [pid 87988:tid 88123] [client 52.176.39.128:9282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.39.176.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuvZDipAwzptuCxBriAqQAAAQ8"]
[Thu Jul 30 15:09:08.182557 2026] [security2:error] [pid 87988:tid 88228] [client 20.104.18.253:25138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/webwp.php"] [unique_id "amuvZDipAwzptuCxBriAqgAAAXg"]
[Thu Jul 30 15:09:08.238933 2026] [security2:error] [pid 87988:tid 88166] [client 185.177.72.68:19700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/backup.sql"] [unique_id "amuvZDipAwzptuCxBriArQAAATo"]
[Thu Jul 30 15:09:08.283272 2026] [security2:error] [pid 87988:tid 88144] [client 84.17.60.251:44616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuvZDipAwzptuCxBriArwAAASQ"]
[Thu Jul 30 15:09:08.370648 2026] [security2:error] [pid 87988:tid 88213] [client 17.246.15.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuvZDipAwzptuCxBriArgAAAWk"]
[Thu Jul 30 15:09:08.371709 2026] [security2:error] [pid 87988:tid 88138] [client 185.177.72.68:19700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/backup.sql.php"] [unique_id "amuvZDipAwzptuCxBriAsAAAAR4"]
[Thu Jul 30 15:09:08.501748 2026] [security2:error] [pid 87988:tid 88181] [client 20.171.55.167:3378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/componentsadmin.php"] [unique_id "amuvZDipAwzptuCxBriAtAAAAUk"]
[Thu Jul 30 15:09:08.565302 2026] [security2:error] [pid 87988:tid 88129] [client 84.17.60.251:44626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuvZDipAwzptuCxBriAuAAAARU"]
[Thu Jul 30 15:09:08.686037 2026] [security2:error] [pid 87988:tid 88214] [client 4.225.203.146:18446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuvZDipAwzptuCxBriAvwAAAWo"]
[Thu Jul 30 15:09:08.784242 2026] [security2:error] [pid 87988:tid 88223] [client 20.104.18.253:25088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/weo.php"] [unique_id "amuvZDipAwzptuCxBriAwwAAAXM"]
[Thu Jul 30 15:09:08.848391 2026] [security2:error] [pid 87988:tid 88232] [client 84.17.60.251:44636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuvZDipAwzptuCxBriAxAAAAXw"]
[Thu Jul 30 15:09:08.977718 2026] [security2:error] [pid 87988:tid 88122] [client 20.226.5.174:34774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/abcd.php"] [unique_id "amuvZDipAwzptuCxBriAygAAAQ4"]
[Thu Jul 30 15:09:09.132619 2026] [security2:error] [pid 87988:tid 88207] [client 84.17.60.251:44646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuvZTipAwzptuCxBriA0wAAAWM"]
[Thu Jul 30 15:09:09.348321 2026] [security2:error] [pid 87988:tid 88156] [client 20.171.55.167:3349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/connector.php"] [unique_id "amuvZTipAwzptuCxBriA3AAAATA"]
[Thu Jul 30 15:09:09.413903 2026] [security2:error] [pid 87988:tid 88218] [client 20.104.18.253:25116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/wg.php"] [unique_id "amuvZTipAwzptuCxBriA3gAAAW4"]
[Thu Jul 30 15:09:09.413959 2026] [security2:error] [pid 87988:tid 88120] [client 185.177.72.68:41228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/index.php"] [unique_id "amuvZTipAwzptuCxBriA3wAAAQw"]
[Thu Jul 30 15:09:09.415605 2026] [security2:error] [pid 87988:tid 88180] [client 84.17.60.251:44648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuvZTipAwzptuCxBriA4AAAAUg"]
[Thu Jul 30 15:09:09.670454 2026] [security2:error] [pid 87988:tid 88150] [client 185.177.72.68:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/index.php%255f"] [unique_id "amuvZTipAwzptuCxBriA7QAAASo"]
[Thu Jul 30 15:09:09.696612 2026] [security2:error] [pid 87988:tid 88220] [client 84.17.60.251:44658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuvZTipAwzptuCxBriA7gAAAXA"]
[Thu Jul 30 15:09:09.921306 2026] [security2:error] [pid 87988:tid 88188] [client 185.177.72.68:41254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/index.php%255d"] [unique_id "amuvZTipAwzptuCxBriA8AAAAVA"]
[Thu Jul 30 15:09:09.978203 2026] [security2:error] [pid 87988:tid 88177] [client 84.17.60.251:44660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuvZTipAwzptuCxBriA8QAAAUU"]
[Thu Jul 30 15:09:10.085503 2026] [security2:error] [pid 87988:tid 88146] [client 20.104.18.253:25099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/whmcs.php"] [unique_id "amuvZjipAwzptuCxBriA9QAAASY"]
[Thu Jul 30 15:09:10.099035 2026] [security2:error] [pid 87988:tid 88127] [client 20.171.55.167:3355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/corealfa.php"] [unique_id "amuvZjipAwzptuCxBriA9gAAARM"]
[Thu Jul 30 15:09:10.192685 2026] [security2:error] [pid 87988:tid 88151] [client 185.177.72.68:41268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/index.php.aws"] [unique_id "amuvZjipAwzptuCxBriA-gAAASs"]
[Thu Jul 30 15:09:10.243309 2026] [security2:error] [pid 87988:tid 88204] [client 20.226.5.174:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/about.php"] [unique_id "amuvZjipAwzptuCxBriA_gAAAWA"]
[Thu Jul 30 15:09:10.266574 2026] [security2:error] [pid 87988:tid 88118] [client 84.17.60.251:44664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nka.hfl.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuvZjipAwzptuCxBriA_wAAAQo"]
[Thu Jul 30 15:09:10.683566 2026] [security2:error] [pid 87988:tid 88234] [client 20.104.18.253:25112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/wi.php"] [unique_id "amuvZjipAwzptuCxBriBDwAAAX4"]
[Thu Jul 30 15:09:10.686054 2026] [security2:error] [pid 87988:tid 88225] [client 51.253.231.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvZTipAwzptuCxBriA7wABdSk"], referer: https://allmontecristi.com
[Thu Jul 30 15:09:10.790092 2026] [security2:error] [pid 87988:tid 88055] [remote 52.176.39.128:9321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.39.176.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuvZjipAwzptuCxBriBFgABc0I"]
[Thu Jul 30 15:09:10.833479 2026] [security2:error] [pid 87988:tid 88233] [client 4.225.203.146:18668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/adminfuns.php"] [unique_id "amuvZjipAwzptuCxBriBFwAAAX0"]
[Thu Jul 30 15:09:10.867383 2026] [security2:error] [pid 87988:tid 88226] [client 20.171.55.167:3362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/csv.php"] [unique_id "amuvZjipAwzptuCxBriBGwAAAXY"]
[Thu Jul 30 15:09:11.195147 2026] [core:notice] [pid 87988:tid 88218] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:11.284010 2026] [security2:error] [pid 87988:tid 88180] [client 20.104.18.253:24504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/widget-logic/mini.php"] [unique_id "amuvZzipAwzptuCxBriBLAAAAUg"]
[Thu Jul 30 15:09:12.011098 2026] [http2:info] [pid 133043:tid 133043] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 15:09:12.166235 2026] [security2:error] [pid 133043:tid 133187] [client 17.241.227.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuvaLdt6aqtVvMundNoAQAAAJM"]
[Thu Jul 30 15:09:12.223762 2026] [core:error] [pid 133043:tid 133178] [client 4.225.203.146:25957] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:12.223887 2026] [core:error] [pid 133043:tid 133178] [client 4.225.203.146:25957] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:12.227256 2026] [security2:error] [pid 133043:tid 133177] [client 20.104.18.253:24509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/widgets.php"] [unique_id "amuvaLdt6aqtVvMundNoBgAAAIk"]
[Thu Jul 30 15:09:12.302078 2026] [security2:error] [pid 133043:tid 133174] [client 20.171.55.167:3393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/data.php"] [unique_id "amuvaLdt6aqtVvMundNoEAAAAIY"]
[Thu Jul 30 15:09:12.534297 2026] [security2:error] [pid 133043:tid 133188] [client 20.226.5.174:34759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amuvaLdt6aqtVvMundNoGgAAAJQ"]
[Thu Jul 30 15:09:12.612012 2026] [security2:error] [pid 133043:tid 133186] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvaLdt6aqtVvMundNoAAAAAJI"]
[Thu Jul 30 15:09:12.848442 2026] [security2:error] [pid 133043:tid 133236] [client 20.104.18.253:24485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/widgets/about.php"] [unique_id "amuvaLdt6aqtVvMundNoKwAAAMQ"]
[Thu Jul 30 15:09:13.081852 2026] [security2:error] [pid 133043:tid 133258] [client 20.171.55.167:3414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/deeto/login.php"] [unique_id "amuvabdt6aqtVvMundNoMwAAANo"]
[Thu Jul 30 15:09:13.378898 2026] [security2:error] [pid 133043:tid 133055] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvabdt6aqtVvMundNoRAAA6As"]
[Thu Jul 30 15:09:13.379075 2026] [security2:error] [pid 133043:tid 133272] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvabdt6aqtVvMundNoRAAA6As"]
[Thu Jul 30 15:09:13.502711 2026] [security2:error] [pid 133043:tid 133286] [client 20.104.18.253:25113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/widgets/admin.php"] [unique_id "amuvabdt6aqtVvMundNoRwAAAPY"]
[Thu Jul 30 15:09:13.838701 2026] [security2:error] [pid 133043:tid 133183] [client 20.226.5.174:34783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/adminfuns.php"] [unique_id "amuvabdt6aqtVvMundNoWgAAAI8"]
[Thu Jul 30 15:09:13.941727 2026] [security2:error] [pid 133043:tid 133195] [client 20.171.55.167:3391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/dex.php"] [unique_id "amuvabdt6aqtVvMundNoXgAAAJs"]
[Thu Jul 30 15:09:14.004556 2026] [security2:error] [pid 87988:tid 88166] [client 4.225.203.146:36001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuvajipAwzptuCxBriBMQAAATo"]
[Thu Jul 30 15:09:14.146391 2026] [security2:error] [pid 133043:tid 133181] [client 20.104.18.253:24456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/widgets/alfa-rex.php"] [unique_id "amuvardt6aqtVvMundNoZgAAAI0"]
[Thu Jul 30 15:09:14.697901 2026] [security2:error] [pid 133043:tid 133256] [client 20.171.55.167:3442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/dist/niil.php"] [unique_id "amuvardt6aqtVvMundNofQAAANg"]
[Thu Jul 30 15:09:14.762461 2026] [security2:error] [pid 133043:tid 133250] [client 20.104.18.253:25127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/widgets/autoload_classmap.php"] [unique_id "amuvardt6aqtVvMundNogQAAANI"]
[Thu Jul 30 15:09:14.765668 2026] [security2:error] [pid 133043:tid 133176] [client 185.191.171.14:39488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2021/01/19/alemanha-deve-ampliar-lockdown-ate-meados-de-fevereiro/"] [unique_id "amuvardt6aqtVvMundNoggAAAIg"]
[Thu Jul 30 15:09:14.765852 2026] [security2:error] [pid 133043:tid 133176] [client 185.191.171.14:39488] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2021/01/19/alemanha-deve-ampliar-lockdown-ate-meados-de-fevereiro/"] [unique_id "amuvardt6aqtVvMundNoggAAAIg"]
[Thu Jul 30 15:09:15.029834 2026] [security2:error] [pid 133043:tid 133215] [client 2a03:2880:f800:3c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvardt6aqtVvMundNodwAArxY"]
[Thu Jul 30 15:09:15.359831 2026] [security2:error] [pid 133043:tid 133299] [client 20.104.18.253:24838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/widgets/browser.php"] [unique_id "amuva7dt6aqtVvMundNooQAAAQM"]
[Thu Jul 30 15:09:15.405367 2026] [security2:error] [pid 133043:tid 133274] [client 20.226.5.174:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/albin.php"] [unique_id "amuva7dt6aqtVvMundNopAAAAOo"]
[Thu Jul 30 15:09:15.496562 2026] [security2:error] [pid 133043:tid 133193] [client 20.171.55.167:3595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/docswp.php"] [unique_id "amuva7dt6aqtVvMundNoqQAAAJk"]
[Thu Jul 30 15:09:15.793170 2026] [security2:error] [pid 133043:tid 133209] [client 4.225.203.146:36008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/atomlib.php"] [unique_id "amuva7dt6aqtVvMundNosAAAAKk"]
[Thu Jul 30 15:09:15.816971 2026] [security2:error] [pid 133043:tid 133286] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuva7dt6aqtVvMundNolAAAAPY"]
[Thu Jul 30 15:09:15.884517 2026] [security2:error] [pid 133043:tid 133186] [client 185.177.72.68:41290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/settings.php.save"] [unique_id "amuva7dt6aqtVvMundNouAAAAJI"]
[Thu Jul 30 15:09:15.985225 2026] [security2:error] [pid 133043:tid 133221] [client 20.104.18.253:25203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/widgets/bypass.php"] [unique_id "amuva7dt6aqtVvMundNovAAAALU"]
[Thu Jul 30 15:09:16.149949 2026] [security2:error] [pid 133043:tid 133239] [client 185.177.72.68:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/settings.php.save%5f%5f"] [unique_id "amuvbLdt6aqtVvMundNovgAAAMc"]
[Thu Jul 30 15:09:16.237883 2026] [core:notice] [pid 133043:tid 133242] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:16.262606 2026] [security2:error] [pid 133043:tid 133237] [client 20.171.55.167:3402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/dr.php"] [unique_id "amuvbLdt6aqtVvMundNowAAAAMU"]
[Thu Jul 30 15:09:16.411001 2026] [security2:error] [pid 133043:tid 133236] [client 185.177.72.68:49212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/settings.php.save%29"] [unique_id "amuvbLdt6aqtVvMundNoxwAAAMQ"]
[Thu Jul 30 15:09:16.446509 2026] [security2:error] [pid 133043:tid 133227] [client 95.135.230.123:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lucky-strike-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuvardt6aqtVvMundNobQAAuxM"], referer: https://lucky-strike-shop.com/xmlrpc.php
[Thu Jul 30 15:09:16.553400 2026] [security2:error] [pid 133043:tid 133270] [client 37.77.56.246:55328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuvbLdt6aqtVvMundNozAAAAOY"]
[Thu Jul 30 15:09:16.553555 2026] [security2:error] [pid 133043:tid 133270] [client 37.77.56.246:55328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuvbLdt6aqtVvMundNozAAAAOY"]
[Thu Jul 30 15:09:16.591128 2026] [security2:error] [pid 133043:tid 133263] [client 20.104.18.253:25164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/widgets/click.php"] [unique_id "amuvbLdt6aqtVvMundNozQAAAN8"]
[Thu Jul 30 15:09:16.677863 2026] [security2:error] [pid 133043:tid 133257] [client 185.177.72.68:49228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/settings.php.save.aws"] [unique_id "amuvbLdt6aqtVvMundNozgAAANk"]
[Thu Jul 30 15:09:16.907229 2026] [security2:error] [pid 133043:tid 133252] [client 20.226.5.174:34756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/amfsqvgv.php"] [unique_id "amuvbLdt6aqtVvMundNo0wAAANQ"]
[Thu Jul 30 15:09:17.057435 2026] [security2:error] [pid 133043:tid 133258] [client 20.171.55.167:3339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/editor/filemanager/updates.php"] [unique_id "amuvbbdt6aqtVvMundNo3QAAANo"]
[Thu Jul 30 15:09:17.447232 2026] [security2:error] [pid 133043:tid 133290] [client 172.237.109.114:14659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvbLdt6aqtVvMundNo2QAAAPo"]
[Thu Jul 30 15:09:17.467266 2026] [security2:error] [pid 133043:tid 133195] [client 185.177.72.68:49234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvbbdt6aqtVvMundNo7QAAAJs"]
[Thu Jul 30 15:09:17.729013 2026] [security2:error] [pid 133043:tid 133224] [client 185.177.72.68:49234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvbbdt6aqtVvMundNo9gAAALg"]
[Thu Jul 30 15:09:18.232970 2026] [security2:error] [pid 133043:tid 133286] [client 20.171.55.167:3384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/epinyins.php"] [unique_id "amuvbrdt6aqtVvMundNpDQAAAPY"]
[Thu Jul 30 15:09:18.243777 2026] [security2:error] [pid 133043:tid 133259] [client 37.77.56.246:50864] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuvbrdt6aqtVvMundNpDgAAANs"]
[Thu Jul 30 15:09:18.243873 2026] [security2:error] [pid 133043:tid 133259] [client 37.77.56.246:50864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuvbrdt6aqtVvMundNpDgAAANs"]
[Thu Jul 30 15:09:18.293503 2026] [autoindex:error] [pid 133043:tid 133267] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:18.510778 2026] [autoindex:error] [pid 133043:tid 133252] [client 4.225.203.146:48109] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:18.664135 2026] [security2:error] [pid 133043:tid 133177] [client 4.225.203.146:48109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuvbrdt6aqtVvMundNpLAAAAIk"]
[Thu Jul 30 15:09:19.031527 2026] [security2:error] [pid 133043:tid 133205] [client 20.171.55.167:3422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/extension/extension/cloud.php"] [unique_id "amuvb7dt6aqtVvMundNpPgAAAKU"]
[Thu Jul 30 15:09:19.077847 2026] [security2:error] [pid 133043:tid 133213] [client 185.177.72.68:49234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/database.sql"] [unique_id "amuvb7dt6aqtVvMundNpPwAAAK0"]
[Thu Jul 30 15:09:19.329516 2026] [core:notice] [pid 133043:tid 133226] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:19.570823 2026] [core:error] [pid 133043:tid 133275] [client 4.225.203.146:26273] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:19.570848 2026] [core:error] [pid 133043:tid 133275] [client 4.225.203.146:26273] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:19.910762 2026] [security2:error] [pid 133043:tid 133227] [client 20.171.55.167:3439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/fedora.php"] [unique_id "amuvb7dt6aqtVvMundNpagAAALs"]
[Thu Jul 30 15:09:20.291499 2026] [autoindex:error] [pid 133043:tid 133242] [client 4.225.203.146:33814] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:20.378426 2026] [security2:error] [pid 133043:tid 133132] [remote 154.26.129.62:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.129.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/wp-login.php"] [unique_id "amuvcLdt6aqtVvMundNpggAAjVg"]
[Thu Jul 30 15:09:20.516585 2026] [autoindex:error] [pid 133043:tid 133292] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/blocks/block/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:20.694401 2026] [autoindex:error] [pid 133043:tid 133249] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:20.777323 2026] [security2:error] [pid 133043:tid 133213] [client 20.171.55.167:3597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/file8.php"] [unique_id "amuvcLdt6aqtVvMundNpnQAAAK0"]
[Thu Jul 30 15:09:20.847276 2026] [security2:error] [pid 133043:tid 133247] [client 4.225.203.146:33814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/inputs.php"] [unique_id "amuvcLdt6aqtVvMundNpoQAAAM8"]
[Thu Jul 30 15:09:21.329488 2026] [core:notice] [pid 133043:tid 133218] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:21.333473 2026] [security2:error] [pid 133043:tid 133218] [client 66.249.79.1:48319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/download/8072/3170"] [unique_id "amuvcbdt6aqtVvMundNprAAAALI"]
[Thu Jul 30 15:09:21.544179 2026] [security2:error] [pid 133043:tid 133189] [client 20.171.55.167:3454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/filefuns.php"] [unique_id "amuvcbdt6aqtVvMundNpwwAAAJU"]
[Thu Jul 30 15:09:21.651039 2026] [security2:error] [pid 133043:tid 133284] [client 178.20.45.182:55080] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.45.182" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuvcbdt6aqtVvMundNpygAAAPQ"], referer: https://deltaedu.net/2016/11/04/university-scholarship-2017/#comment-25
[Thu Jul 30 15:09:21.651143 2026] [security2:error] [pid 133043:tid 133284] [client 178.20.45.182:55080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "deltaedu.net"] [uri "/wp-comments-post.php"] [unique_id "amuvcbdt6aqtVvMundNpygAAAPQ"], referer: https://deltaedu.net/2016/11/04/university-scholarship-2017/#comment-25
[Thu Jul 30 15:09:21.713270 2026] [security2:error] [pid 133043:tid 133291] [client 4.225.203.146:33825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/index.php"] [unique_id "amuvcbdt6aqtVvMundNpzgAAAPs"]
[Thu Jul 30 15:09:21.833105 2026] [security2:error] [pid 133043:tid 133200] [client 4.225.203.146:40962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/fm.php"] [unique_id "amuvcbdt6aqtVvMundNp1AAAAKA"]
[Thu Jul 30 15:09:22.349138 2026] [core:error] [pid 133043:tid 133154] [remote 157.55.39.222:13269] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:22.349166 2026] [core:error] [pid 133043:tid 133154] [remote 157.55.39.222:13269] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:22.372730 2026] [security2:error] [pid 133043:tid 133235] [client 20.171.55.167:3388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/flame.php"] [unique_id "amuvcrdt6aqtVvMundNp6wAAAMM"]
[Thu Jul 30 15:09:22.939475 2026] [security2:error] [pid 133043:tid 133191] [client 74.7.244.43:58432] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.shop-peace.com"] [uri "/robots.txt"] [unique_id "amuvcrdt6aqtVvMundNqBQAAAJc"]
[Thu Jul 30 15:09:23.169284 2026] [security2:error] [pid 133043:tid 133211] [client 20.171.55.167:3602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/fucku.php"] [unique_id "amuvc7dt6aqtVvMundNqDgAAAKs"]
[Thu Jul 30 15:09:23.427759 2026] [security2:error] [pid 133043:tid 133229] [client 4.225.203.146:34285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuvc7dt6aqtVvMundNqHAAAAL0"]
[Thu Jul 30 15:09:23.632899 2026] [security2:error] [pid 133043:tid 133183] [client 172.237.109.114:28040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvc7dt6aqtVvMundNqDAAAAI8"]
[Thu Jul 30 15:09:23.722800 2026] [security2:error] [pid 133043:tid 133168] [remote 57.141.18.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuvc7dt6aqtVvMundNqKwAA4nw"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Ccarbon%2Clycra%2Cpolyester%2Csilicon%2Csteel%2Ctitanium%2Cplastic%2Ccotton%2Clinen&min_price=300&orderby=popularity&status=sale&tax_product_cat=furniture&filter_brand=vitra&unfilter=1
[Thu Jul 30 15:09:23.969558 2026] [security2:error] [pid 133043:tid 133166] [remote 57.141.18.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuvc7dt6aqtVvMundNqKAAAw3o"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Ccarbon%2Clycra%2Cpolyester%2Csilicon%2Csteel%2Ctitanium%2Cplastic%2Ccotton%2Clinen&min_price=300&orderby=popularity&status=sale&tax_product_cat=furniture&filter_brand=vitra&unfilter=1
[Thu Jul 30 15:09:23.984046 2026] [security2:error] [pid 133043:tid 133045] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvc7dt6aqtVvMundNqOgAA4AE"]
[Thu Jul 30 15:09:23.984186 2026] [security2:error] [pid 133043:tid 133264] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvc7dt6aqtVvMundNqOgAA4AE"]
[Thu Jul 30 15:09:24.000644 2026] [security2:error] [pid 133043:tid 133267] [client 20.171.55.167:3360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/gecko-new.php"] [unique_id "amuvc7dt6aqtVvMundNqOwAAAOM"]
[Thu Jul 30 15:09:24.572899 2026] [core:error] [pid 133043:tid 133216] [client 4.225.203.146:61380] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:24.572920 2026] [core:error] [pid 133043:tid 133216] [client 4.225.203.146:61380] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:24.863390 2026] [security2:error] [pid 133043:tid 133249] [client 185.177.72.68:49234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvdLdt6aqtVvMundNqYAAAANE"]
[Thu Jul 30 15:09:24.912682 2026] [security2:error] [pid 133043:tid 133185] [client 20.171.55.167:3368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/goat.php"] [unique_id "amuvdLdt6aqtVvMundNqYQAAAJE"]
[Thu Jul 30 15:09:24.989471 2026] [security2:error] [pid 133043:tid 133213] [client 185.177.72.68:49234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env%5e"] [unique_id "amuvdLdt6aqtVvMundNqYwAAAK0"]
[Thu Jul 30 15:09:25.577050 2026] [security2:error] [pid 133043:tid 133214] [client 85.208.96.212:27666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/22/frei-anastacio-elogia-governador-do-estado-pela-destinacao-de-r5-milhoes-para-obras-em-picui/"] [unique_id "amuvdbdt6aqtVvMundNqeQAAAK4"]
[Thu Jul 30 15:09:25.577182 2026] [security2:error] [pid 133043:tid 133214] [client 85.208.96.212:27666] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/22/frei-anastacio-elogia-governador-do-estado-pela-destinacao-de-r5-milhoes-para-obras-em-picui/"] [unique_id "amuvdbdt6aqtVvMundNqeQAAAK4"]
[Thu Jul 30 15:09:25.775783 2026] [security2:error] [pid 133043:tid 133251] [client 20.171.55.167:3425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/haf.php"] [unique_id "amuvdbdt6aqtVvMundNqfgAAANM"]
[Thu Jul 30 15:09:26.056302 2026] [security2:error] [pid 133043:tid 133191] [client 4.225.203.146:9743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/file.php"] [unique_id "amuvdrdt6aqtVvMundNqkgAAAJc"]
[Thu Jul 30 15:09:26.125085 2026] [core:notice] [pid 133043:tid 133061] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:26.580082 2026] [security2:error] [pid 133043:tid 133266] [client 185.177.72.68:49234] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/_profiler%00"] [unique_id "amuvdrdt6aqtVvMundNqqAAAAOI"]
[Thu Jul 30 15:09:26.702147 2026] [security2:error] [pid 133043:tid 133286] [client 20.171.55.167:3333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/hinfofuns.php"] [unique_id "amuvdrdt6aqtVvMundNqqgAAAPY"]
[Thu Jul 30 15:09:27.173905 2026] [security2:error] [pid 133043:tid 133282] [client 74.7.230.55:35422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "hzh.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amuvd7dt6aqtVvMundNqvgAAAPI"]
[Thu Jul 30 15:09:27.214294 2026] [security2:error] [pid 133043:tid 133245] [client 20.226.5.174:27354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/ant.php"] [unique_id "amuvd7dt6aqtVvMundNqvwAAAM0"]
[Thu Jul 30 15:09:27.409498 2026] [security2:error] [pid 133043:tid 133201] [client 74.7.230.55:35422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hzh.tqa.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuvd7dt6aqtVvMundNqxgAAAKE"], referer: https://hzh.tqa.temporary.site/robots.txt
[Thu Jul 30 15:09:28.010859 2026] [security2:error] [pid 133043:tid 133283] [client 172.237.109.114:62593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/maintenance.php"] [unique_id "amuveLdt6aqtVvMundNq5wAAAPM"]
[Thu Jul 30 15:09:28.209302 2026] [security2:error] [pid 133043:tid 133281] [client 20.171.55.167:3447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/i0004en.php//wp-content/bk/index.php"] [unique_id "amuveLdt6aqtVvMundNq8AAAAPE"]
[Thu Jul 30 15:09:28.454082 2026] [security2:error] [pid 133043:tid 133175] [client 4.225.203.146:32617] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "seven-stars-shop.com"] [uri "/wp-content/1.php"] [unique_id "amuveLdt6aqtVvMundNq_wAAAIc"]
[Thu Jul 30 15:09:28.454214 2026] [security2:error] [pid 133043:tid 133175] [client 4.225.203.146:32617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/1.php"] [unique_id "amuveLdt6aqtVvMundNq_wAAAIc"]
[Thu Jul 30 15:09:29.054586 2026] [security2:error] [pid 133043:tid 133284] [client 20.171.55.167:3607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/imagek.php"] [unique_id "amuvebdt6aqtVvMundNrGwAAAPQ"]
[Thu Jul 30 15:09:29.100837 2026] [core:notice] [pid 133043:tid 133216] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:29.103758 2026] [autoindex:error] [pid 133043:tid 133216] [client 66.249.74.7:0] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_e4dc3cbf/index.php/JIPKL/article/download/118/115: No matching DirectoryIndex (none) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:29.103880 2026] [security2:error] [pid 133043:tid 133216] [client 66.249.74.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/118/115"] [unique_id "amuveLdt6aqtVvMundNrEQAAALA"]
[Thu Jul 30 15:09:29.813332 2026] [security2:error] [pid 133043:tid 133197] [client 20.226.5.174:27332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/appreciators.php"] [unique_id "amuvebdt6aqtVvMundNrOwAAAJ0"]
[Thu Jul 30 15:09:29.838197 2026] [security2:error] [pid 133043:tid 133276] [client 20.171.55.167:3418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/indec.php"] [unique_id "amuvebdt6aqtVvMundNrPAAAAOw"]
[Thu Jul 30 15:09:29.947354 2026] [security2:error] [pid 133043:tid 133202] [client 4.225.203.146:32576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/plugin.php"] [unique_id "amuvebdt6aqtVvMundNrQAAAAKI"]
[Thu Jul 30 15:09:30.150996 2026] [core:error] [pid 133043:tid 133260] [client 4.225.203.146:49467] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:30.151021 2026] [core:error] [pid 133043:tid 133260] [client 4.225.203.146:49467] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:30.373558 2026] [security2:error] [pid 133043:tid 133095] [remote 57.141.0.70:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuverdt6aqtVvMundNrTwAA2TM"]
[Thu Jul 30 15:09:30.649540 2026] [security2:error] [pid 133043:tid 133288] [client 20.171.55.167:3407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/instabuilder2/cache/up.php"] [unique_id "amuverdt6aqtVvMundNrYwAAAPg"]
[Thu Jul 30 15:09:30.761051 2026] [security2:error] [pid 133043:tid 133217] [client 185.177.72.68:1902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/erp~"] [unique_id "amuverdt6aqtVvMundNrZAAAALE"]
[Thu Jul 30 15:09:30.836710 2026] [security2:error] [pid 133043:tid 133224] [client 4.225.203.146:9738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/bolt.php"] [unique_id "amuverdt6aqtVvMundNrZgAAALg"]
[Thu Jul 30 15:09:31.192874 2026] [security2:error] [pid 133043:tid 133115] [remote 57.141.0.67:30772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuve7dt6aqtVvMundNrgAAAwUc"]
[Thu Jul 30 15:09:31.560731 2026] [security2:error] [pid 133043:tid 133279] [client 20.171.55.167:3346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/item.php"] [unique_id "amuve7dt6aqtVvMundNrlAAAAO8"]
[Thu Jul 30 15:09:31.587126 2026] [core:notice] [pid 133043:tid 133235] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:31.693149 2026] [security2:error] [pid 133043:tid 133287] [client 20.226.5.174:27368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/archive.php"] [unique_id "amuve7dt6aqtVvMundNrlwAAAPc"]
[Thu Jul 30 15:09:31.872594 2026] [security2:error] [pid 133043:tid 133124] [remote 185.115.217.185:40720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.217.115.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-login.php"] [unique_id "amuve7dt6aqtVvMundNroAAAt1A"]
[Thu Jul 30 15:09:31.916135 2026] [security2:error] [pid 133043:tid 133271] [client 4.225.203.146:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/3.php"] [unique_id "amuve7dt6aqtVvMundNrpAAAAOc"]
[Thu Jul 30 15:09:31.990220 2026] [security2:error] [pid 133043:tid 133127] [remote 57.141.0.15:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuve7dt6aqtVvMundNrpgAAnlM"]
[Thu Jul 30 15:09:32.407145 2026] [security2:error] [pid 133043:tid 133258] [client 185.177.72.68:1902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/prod.htaccess"] [unique_id "amuvfLdt6aqtVvMundNruwAAANo"]
[Thu Jul 30 15:09:32.519780 2026] [security2:error] [pid 133043:tid 133289] [client 20.171.55.167:3427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/joomlawp.php"] [unique_id "amuvfLdt6aqtVvMundNrwQAAAPk"]
[Thu Jul 30 15:09:33.184782 2026] [security2:error] [pid 133043:tid 133193] [client 4.225.203.146:35237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/222.php"] [unique_id "amuvfbdt6aqtVvMundNr3gAAAJk"]
[Thu Jul 30 15:09:33.466954 2026] [security2:error] [pid 133043:tid 133228] [client 20.171.55.167:3435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/kk.php"] [unique_id "amuvfbdt6aqtVvMundNr7AAAALw"]
[Thu Jul 30 15:09:33.523282 2026] [security2:error] [pid 133043:tid 133178] [client 20.226.5.174:27333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/as.php"] [unique_id "amuvfbdt6aqtVvMundNr8AAAAIo"]
[Thu Jul 30 15:09:33.613107 2026] [security2:error] [pid 133043:tid 133255] [client 4.225.203.146:18471] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "seven-stars-shop.com"] [uri "/1.php"] [unique_id "amuvfbdt6aqtVvMundNr-gAAANc"]
[Thu Jul 30 15:09:33.613202 2026] [security2:error] [pid 133043:tid 133255] [client 4.225.203.146:18471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/1.php"] [unique_id "amuvfbdt6aqtVvMundNr-gAAANc"]
[Thu Jul 30 15:09:34.239622 2026] [security2:error] [pid 133043:tid 133262] [client 20.171.55.167:3370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/leafmailer.php.php"] [unique_id "amuvfrdt6aqtVvMundNsFwAAAN4"]
[Thu Jul 30 15:09:34.310808 2026] [security2:error] [pid 133043:tid 133208] [client 127.0.0.1:46714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuvfrdt6aqtVvMundNsGgAAAKg"]
[Thu Jul 30 15:09:34.310839 2026] [security2:error] [pid 133043:tid 133295] [client 74.7.230.45:42660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.cmv.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuvfrdt6aqtVvMundNsGQAAAP8"]
[Thu Jul 30 15:09:34.365840 2026] [security2:error] [pid 133043:tid 133257] [client 185.177.72.68:1902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env.old"] [unique_id "amuvfrdt6aqtVvMundNsGwAAANk"]
[Thu Jul 30 15:09:34.480063 2026] [security2:error] [pid 133043:tid 133234] [client 172.237.109.114:46178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvfbdt6aqtVvMundNsCAAAAMI"]
[Thu Jul 30 15:09:34.691794 2026] [security2:error] [pid 133043:tid 133156] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvfrdt6aqtVvMundNsKAABA3A"]
[Thu Jul 30 15:09:34.691929 2026] [security2:error] [pid 133043:tid 133299] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvfrdt6aqtVvMundNsKAABA3A"]
[Thu Jul 30 15:09:34.755040 2026] [security2:error] [pid 133043:tid 133266] [client 4.225.203.146:35262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuvfrdt6aqtVvMundNsLAAAAOI"]
[Thu Jul 30 15:09:35.138209 2026] [security2:error] [pid 133043:tid 133176] [client 20.171.55.167:3401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/linkpreview/class.php"] [unique_id "amuvf7dt6aqtVvMundNsPQAAAIg"]
[Thu Jul 30 15:09:35.774575 2026] [security2:error] [pid 133043:tid 133281] [client 4.225.203.146:9979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuvf7dt6aqtVvMundNsWwAAAPE"]
[Thu Jul 30 15:09:36.032064 2026] [security2:error] [pid 133043:tid 133260] [client 74.7.175.135:46392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "womenclothingbox.com"] [uri "/cgi-sys/404.html"] [unique_id "amuvgLdt6aqtVvMundNsXwAA3Hw"]
[Thu Jul 30 15:09:36.096791 2026] [security2:error] [pid 133043:tid 133179] [client 20.171.55.167:3596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/load.php"] [unique_id "amuvgLdt6aqtVvMundNsZgAAAIs"]
[Thu Jul 30 15:09:36.334566 2026] [security2:error] [pid 133043:tid 133265] [client 185.177.72.68:1902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/settings.swp"] [unique_id "amuvgLdt6aqtVvMundNscAAAAOE"]
[Thu Jul 30 15:09:36.573814 2026] [security2:error] [pid 133043:tid 133296] [client 4.225.203.146:50461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/gg.php"] [unique_id "amuvgLdt6aqtVvMundNsdAAAAQA"]
[Thu Jul 30 15:09:36.626216 2026] [security2:error] [pid 133043:tid 133176] [client 185.177.72.68:1902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env.swp"] [unique_id "amuvgLdt6aqtVvMundNsdgAAAIg"]
[Thu Jul 30 15:09:36.796735 2026] [core:error] [pid 133043:tid 133300] [client 4.225.203.146:21967] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:36.796755 2026] [core:error] [pid 133043:tid 133300] [client 4.225.203.146:21967] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:36.944377 2026] [security2:error] [pid 133043:tid 133238] [client 20.171.55.167:3341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/lwbdene/index.php"] [unique_id "amuvgLdt6aqtVvMundNshwAAAMY"]
[Thu Jul 30 15:09:37.180400 2026] [security2:error] [pid 133043:tid 133280] [client 185.177.72.68:1902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.EnV"] [unique_id "amuvgbdt6aqtVvMundNsjgAAAPA"]
[Thu Jul 30 15:09:37.483833 2026] [security2:error] [pid 133043:tid 133207] [client 4.225.203.146:35202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/admin.php"] [unique_id "amuvgbdt6aqtVvMundNsmwAAAKc"]
[Thu Jul 30 15:09:37.592013 2026] [security2:error] [pid 133043:tid 133282] [client 185.177.72.68:1902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.EnV^"] [unique_id "amuvgbdt6aqtVvMundNsnAAAAPI"]
[Thu Jul 30 15:09:37.663617 2026] [security2:error] [pid 133043:tid 133191] [client 20.226.5.174:27346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/atomlib.php"] [unique_id "amuvgbdt6aqtVvMundNsnQAAAJc"]
[Thu Jul 30 15:09:37.863949 2026] [security2:error] [pid 133043:tid 133279] [client 20.171.55.167:3452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/majalahpro-core/img/index.php"] [unique_id "amuvgbdt6aqtVvMundNspwAAAO8"]
[Thu Jul 30 15:09:37.932681 2026] [autoindex:error] [pid 133043:tid 133198] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/images/crystal/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:38.120598 2026] [security2:error] [pid 133043:tid 133246] [client 185.177.72.68:26236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htaccess"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/authui.htaccess"] [unique_id "amuvgrdt6aqtVvMundNssgAAAM4"]
[Thu Jul 30 15:09:38.124841 2026] [security2:error] [pid 133043:tid 133230] [client 4.225.203.146:22867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp.php"] [unique_id "amuvgrdt6aqtVvMundNsswAAAL4"]
[Thu Jul 30 15:09:38.213136 2026] [security2:error] [pid 133043:tid 133057] [remote 74.7.227.39:42664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuvgrdt6aqtVvMundNstwAAiA0"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/woozone/aa-framework
[Thu Jul 30 15:09:38.233762 2026] [security2:error] [pid 133043:tid 133188] [client 4.225.203.146:15496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-configs.php"] [unique_id "amuvgrdt6aqtVvMundNsuQAAAJQ"]
[Thu Jul 30 15:09:38.379549 2026] [security2:error] [pid 133043:tid 133214] [client 185.177.72.68:26236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/test2.php"] [unique_id "amuvgrdt6aqtVvMundNsvQAAAK4"]
[Thu Jul 30 15:09:38.471499 2026] [security2:error] [pid 133043:tid 133193] [client 74.7.244.3:47330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.qzb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuvgbdt6aqtVvMundNsrgAAmQg"]
[Thu Jul 30 15:09:38.631917 2026] [security2:error] [pid 133043:tid 133293] [client 185.177.72.68:26244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/test2.php%2e%2e%2f%2e%2e%2f"] [unique_id "amuvgrdt6aqtVvMundNsxQAAAP0"]
[Thu Jul 30 15:09:38.790656 2026] [core:notice] [pid 133043:tid 133194] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:38.876802 2026] [security2:error] [pid 133043:tid 133238] [client 20.171.55.167:3381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/masterx/wpx.php"] [unique_id "amuvgrdt6aqtVvMundNs0QAAAMY"]
[Thu Jul 30 15:09:38.883765 2026] [security2:error] [pid 133043:tid 133199] [client 185.177.72.68:26250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/test2.php.well-known"] [unique_id "amuvgrdt6aqtVvMundNs0gAAAJ8"]
[Thu Jul 30 15:09:38.942184 2026] [security2:error] [pid 133043:tid 133247] [client 4.225.203.146:22909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuvgrdt6aqtVvMundNs1gAAAM8"]
[Thu Jul 30 15:09:38.983388 2026] [security2:error] [pid 133043:tid 133180] [client 4.225.203.146:28765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/php.php"] [unique_id "amuvgrdt6aqtVvMundNs1wAAAIw"]
[Thu Jul 30 15:09:39.114518 2026] [security2:error] [pid 133043:tid 133184] [client 20.226.5.174:27331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/autoload_classmap.php"] [unique_id "amuvg7dt6aqtVvMundNs2wAAAJA"]
[Thu Jul 30 15:09:39.150650 2026] [security2:error] [pid 133043:tid 133177] [client 185.177.72.68:26254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/test2.php//"] [unique_id "amuvg7dt6aqtVvMundNs3AAAAIk"]
[Thu Jul 30 15:09:39.408818 2026] [security2:error] [pid 133043:tid 133272] [client 185.177.72.68:26264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/config.php.bak"] [unique_id "amuvg7dt6aqtVvMundNs4wAAAOg"]
[Thu Jul 30 15:09:39.678309 2026] [security2:error] [pid 133043:tid 133200] [client 185.177.72.68:26266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/config.php.bak%257d"] [unique_id "amuvg7dt6aqtVvMundNs6QAAAKA"]
[Thu Jul 30 15:09:39.783927 2026] [security2:error] [pid 133043:tid 133259] [client 20.171.55.167:3453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/mediabypass.php"] [unique_id "amuvg7dt6aqtVvMundNs6gAAANs"]
[Thu Jul 30 15:09:39.933878 2026] [security2:error] [pid 133043:tid 133230] [client 185.177.72.68:26276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/ConFig.Php.bak"] [unique_id "amuvg7dt6aqtVvMundNs8wAAAL4"]
[Thu Jul 30 15:09:40.063926 2026] [security2:error] [pid 133043:tid 133255] [client 185.177.72.68:26276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/config.php.bak%0d"] [unique_id "amuvhLdt6aqtVvMundNs-QAAANc"]
[Thu Jul 30 15:09:40.380443 2026] [security2:error] [pid 133043:tid 133192] [client 20.226.5.174:27342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/bb.php"] [unique_id "amuvhLdt6aqtVvMundNtAAAAAJg"]
[Thu Jul 30 15:09:40.621561 2026] [security2:error] [pid 133043:tid 133082] [remote 57.141.0.54:22094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuvhLdt6aqtVvMundNtDQAAmSY"]
[Thu Jul 30 15:09:40.725843 2026] [security2:error] [pid 133043:tid 133196] [client 20.171.55.167:3415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/models/indexx.php"] [unique_id "amuvhLdt6aqtVvMundNtDgAAAJw"]
[Thu Jul 30 15:09:40.866818 2026] [security2:error] [pid 133043:tid 133260] [client 185.177.72.68:26280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/app_dev.php"] [unique_id "amuvhLdt6aqtVvMundNtGAAAANw"]
[Thu Jul 30 15:09:41.129239 2026] [security2:error] [pid 133043:tid 133205] [client 185.177.72.68:26284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/app_dev.php%2520"] [unique_id "amuvhbdt6aqtVvMundNtIAAAAKU"]
[Thu Jul 30 15:09:41.317657 2026] [core:notice] [pid 133043:tid 133287] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:41.385942 2026] [security2:error] [pid 133043:tid 133242] [client 185.177.72.68:26286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/app_dev.php%253f"] [unique_id "amuvhbdt6aqtVvMundNtJAAAAMo"]
[Thu Jul 30 15:09:41.473852 2026] [security2:error] [pid 133043:tid 133256] [client 20.171.55.167:3344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/ms-functions.php"] [unique_id "amuvhbdt6aqtVvMundNtJgAAANg"]
[Thu Jul 30 15:09:41.474268 2026] [security2:error] [pid 133043:tid 133191] [client 20.226.5.174:27328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/bnm.php"] [unique_id "amuvhbdt6aqtVvMundNtJwAAAJc"]
[Thu Jul 30 15:09:41.637989 2026] [security2:error] [pid 133043:tid 133237] [client 185.177.72.68:26288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/app_dev.php%2524"] [unique_id "amuvhbdt6aqtVvMundNtMAAAAMU"]
[Thu Jul 30 15:09:41.775111 2026] [core:notice] [pid 133043:tid 133200] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:41.907800 2026] [security2:error] [pid 133043:tid 133089] [remote 74.7.243.224:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuvhbdt6aqtVvMundNtOQAAti0"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:09:42.287258 2026] [security2:error] [pid 133043:tid 133232] [client 20.171.55.167:3615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/neko.php"] [unique_id "amuvhrdt6aqtVvMundNtRwAAAMA"]
[Thu Jul 30 15:09:42.518093 2026] [security2:error] [pid 133043:tid 133268] [client 20.226.5.174:27355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/bootstrap.php"] [unique_id "amuvhrdt6aqtVvMundNtVwAAAOQ"]
[Thu Jul 30 15:09:43.057701 2026] [autoindex:error] [pid 133043:tid 133097] [remote 74.207.245.209:53006] AH01276: Cannot serve directory /home1/khwnyxte/arabiantourz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:43.134439 2026] [security2:error] [pid 133043:tid 133186] [client 20.171.55.167:3389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/noriumportfolio/doc.php"] [unique_id "amuvh7dt6aqtVvMundNtfAAAAJI"]
[Thu Jul 30 15:09:43.533288 2026] [core:error] [pid 133043:tid 133110] [remote 74.7.241.134:44160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:43.533313 2026] [core:error] [pid 133043:tid 133110] [remote 74.7.241.134:44160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:43.533577 2026] [security2:error] [pid 133043:tid 133228] [client 74.7.241.134:44160] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "guethleentertainment.com"] [uri "/index.php"] [unique_id "amuvh7dt6aqtVvMundNtjAAAvEI"]
[Thu Jul 30 15:09:43.661084 2026] [security2:error] [pid 133043:tid 133195] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvh7dt6aqtVvMundNtdAAAAJs"]
[Thu Jul 30 15:09:43.689224 2026] [security2:error] [pid 133043:tid 133294] [client 20.226.5.174:27362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/buy.php"] [unique_id "amuvh7dt6aqtVvMundNtmQAAAP4"]
[Thu Jul 30 15:09:44.085296 2026] [security2:error] [pid 133043:tid 133238] [client 20.171.55.167:3612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/omest403.php"] [unique_id "amuviLdt6aqtVvMundNtrQAAAMY"]
[Thu Jul 30 15:09:44.635928 2026] [core:notice] [pid 133043:tid 133256] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:44.722499 2026] [security2:error] [pid 133043:tid 133183] [client 4.225.203.146:16404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/file.php"] [unique_id "amuviLdt6aqtVvMundNtzgAAAI8"]
[Thu Jul 30 15:09:44.847627 2026] [security2:error] [pid 133043:tid 133178] [client 20.171.55.167:3399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/packed.php"] [unique_id "amuviLdt6aqtVvMundNt0AAAAIo"]
[Thu Jul 30 15:09:45.000363 2026] [security2:error] [pid 133043:tid 133202] [client 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuviLdt6aqtVvMundNtuQAAok0"]
[Thu Jul 30 15:09:45.131298 2026] [core:notice] [pid 133043:tid 133127] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:45.169376 2026] [security2:error] [pid 133043:tid 133126] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvibdt6aqtVvMundNt4QAAqlI"]
[Thu Jul 30 15:09:45.169535 2026] [security2:error] [pid 133043:tid 133210] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvibdt6aqtVvMundNt4QAAqlI"]
[Thu Jul 30 15:09:45.370144 2026] [security2:error] [pid 133043:tid 133216] [client 20.226.5.174:27373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amuvibdt6aqtVvMundNt6AAAALA"]
[Thu Jul 30 15:09:45.606627 2026] [security2:error] [pid 133043:tid 133276] [client 20.171.55.167:3357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/php_configuration.php"] [unique_id "amuvibdt6aqtVvMundNt9AAAAOw"]
[Thu Jul 30 15:09:46.239069 2026] [security2:error] [pid 133043:tid 133221] [client 4.225.203.146:11292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuvirdt6aqtVvMundNuEwAAALU"]
[Thu Jul 30 15:09:46.508841 2026] [security2:error] [pid 133043:tid 133186] [client 20.171.55.167:3373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/phpunit/src/Util/PHP/uss.php"] [unique_id "amuvirdt6aqtVvMundNuGgAAAJI"]
[Thu Jul 30 15:09:46.680507 2026] [security2:error] [pid 133043:tid 133279] [client 172.237.109.114:64842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvirdt6aqtVvMundNuCgAAAO8"]
[Thu Jul 30 15:09:47.243558 2026] [security2:error] [pid 133043:tid 133231] [client 20.226.5.174:28033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/class-wp-image.php"] [unique_id "amuvi7dt6aqtVvMundNuPgAAAL8"]
[Thu Jul 30 15:09:47.349577 2026] [fcgid:warn] [pid 133043:tid 133201] (70014)End of file found: [client 185.177.72.68:26292] mod_fcgid: can't get data from http client
[Thu Jul 30 15:09:47.386609 2026] [security2:error] [pid 133043:tid 133286] [client 20.171.55.167:3340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/pluginsk.php"] [unique_id "amuvi7dt6aqtVvMundNuRAAAAPY"]
[Thu Jul 30 15:09:47.617517 2026] [fcgid:warn] [pid 133043:tid 133219] (70014)End of file found: [client 185.177.72.68:36530] mod_fcgid: can't get data from http client
[Thu Jul 30 15:09:47.851043 2026] [security2:error] [pid 133043:tid 133299] [client 4.225.203.146:15491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/index.php"] [unique_id "amuvi7dt6aqtVvMundNuUAAAAQM"]
[Thu Jul 30 15:09:47.865882 2026] [fcgid:warn] [pid 133043:tid 133173] (70014)End of file found: [client 185.177.72.68:36532] mod_fcgid: can't get data from http client
[Thu Jul 30 15:09:48.120970 2026] [fcgid:warn] [pid 133043:tid 133237] (70014)End of file found: [client 185.177.72.68:36548] mod_fcgid: can't get data from http client
[Thu Jul 30 15:09:48.124213 2026] [security2:error] [pid 133043:tid 133288] [client 20.171.55.167:3395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/pref.php"] [unique_id "amuvjLdt6aqtVvMundNuVQAAAPg"]
[Thu Jul 30 15:09:48.892287 2026] [security2:error] [pid 133043:tid 133281] [client 185.177.72.68:36552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/_phpinfo.php"] [unique_id "amuvjLdt6aqtVvMundNueQAAAPE"]
[Thu Jul 30 15:09:48.965472 2026] [security2:error] [pid 133043:tid 133161] [remote 57.141.0.14:24104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuvjLdt6aqtVvMundNuegAA-XU"]
[Thu Jul 30 15:09:49.144382 2026] [security2:error] [pid 133043:tid 133291] [client 185.177.72.68:36554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/_phpinfo.php.dockerignore"] [unique_id "amuvjbdt6aqtVvMundNufQAAAPs"]
[Thu Jul 30 15:09:49.290678 2026] [security2:error] [pid 133043:tid 133251] [client 20.171.55.167:3403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/prodi.php"] [unique_id "amuvjbdt6aqtVvMundNuhAAAANM"]
[Thu Jul 30 15:09:49.414622 2026] [security2:error] [pid 133043:tid 133219] [client 185.177.72.68:36562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/_phpinfo.php%3f"] [unique_id "amuvjbdt6aqtVvMundNuiwAAALM"]
[Thu Jul 30 15:09:49.421654 2026] [security2:error] [pid 133043:tid 133275] [client 4.225.203.146:28764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/a.php"] [unique_id "amuvjbdt6aqtVvMundNujAAAAOs"]
[Thu Jul 30 15:09:49.545239 2026] [security2:error] [pid 133043:tid 133176] [client 20.226.5.174:27361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/classsmtps.php"] [unique_id "amuvjbdt6aqtVvMundNujQAAAIg"]
[Thu Jul 30 15:09:49.669662 2026] [security2:error] [pid 133043:tid 133209] [client 185.177.72.68:36568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/_phpinfo.php%2e%2e%2f%2e%2e%2f"] [unique_id "amuvjbdt6aqtVvMundNujgAAAKk"]
[Thu Jul 30 15:09:49.736864 2026] [security2:error] [pid 133043:tid 133274] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvjbdt6aqtVvMundNugAAAAOo"]
[Thu Jul 30 15:09:49.934098 2026] [security2:error] [pid 133043:tid 133221] [client 185.177.72.68:36572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/wp-config.php"] [unique_id "amuvjbdt6aqtVvMundNumgAAALU"]
[Thu Jul 30 15:09:50.128378 2026] [security2:error] [pid 133043:tid 133233] [client 20.171.55.167:3367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/publicwp.php"] [unique_id "amuvjrdt6aqtVvMundNunAAAAME"]
[Thu Jul 30 15:09:50.188199 2026] [security2:error] [pid 133043:tid 133203] [client 185.177.72.68:36582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "abs-sa.net"] [uri "/wp-config.php%7c%7c"] [unique_id "amuvjrdt6aqtVvMundNunQAAAKM"]
[Thu Jul 30 15:09:50.450668 2026] [security2:error] [pid 133043:tid 133269] [client 185.177.72.68:36592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "abs-sa.net"] [uri "/wp-config.php%257e"] [unique_id "amuvjrdt6aqtVvMundNupAAAAOU"]
[Thu Jul 30 15:09:50.508658 2026] [security2:error] [pid 133043:tid 133180] [client 172.237.109.114:63522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvjrdt6aqtVvMundNumwAAAIw"]
[Thu Jul 30 15:09:50.706332 2026] [core:notice] [pid 133043:tid 133285] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:50.717375 2026] [security2:error] [pid 133043:tid 133279] [client 185.177.72.68:36602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "abs-sa.net"] [uri "/wp-config.php//"] [unique_id "amuvjrdt6aqtVvMundNuqgAAAO8"]
[Thu Jul 30 15:09:50.890073 2026] [security2:error] [pid 133043:tid 133276] [client 95.135.230.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lucky-strike-shop.com"] [uri "/wp-admin/post-new.php"] [unique_id "amuvjbdt6aqtVvMundNuewAA7Hc"], referer: https://lucky-strike-shop.com/my-account/?action=register&xoo_el_reg_email=info239%40noreply0.com&xoo_el_reg_fname=Lukas&xoo_el_reg_lname=Baumgartner&xoo_el_reg_pass=Qz1SxPkSbG*U8z1&xoo_el_reg_pass_again=Qz1SxPkSbG*U8z1&xoo_el_reg_terms=yes&_xoo_el_form=register&xoo_el_redirect=%2Fmy-account%2F%3Faction%3Dregister
[Thu Jul 30 15:09:51.029070 2026] [security2:error] [pid 133043:tid 133195] [client 20.171.55.167:3585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/radio.php"] [unique_id "amuvj7dt6aqtVvMundNuugAAAJs"]
[Thu Jul 30 15:09:51.045521 2026] [security2:error] [pid 133043:tid 133204] [client 20.226.5.174:27363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/classwithtostring.php"] [unique_id "amuvj7dt6aqtVvMundNuvAAAAKQ"]
[Thu Jul 30 15:09:51.300533 2026] [security2:error] [pid 133043:tid 133262] [client 116.179.32.206:56479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/about"] [unique_id "amuvj7dt6aqtVvMundNuuwAAAN4"]
[Thu Jul 30 15:09:51.599569 2026] [core:error] [pid 133043:tid 133174] [client 4.225.203.146:33183] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:51.599602 2026] [core:error] [pid 133043:tid 133174] [client 4.225.203.146:33183] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:51.647280 2026] [core:error] [pid 133043:tid 133299] [client 74.7.230.10:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:51.647303 2026] [core:error] [pid 133043:tid 133299] [client 74.7.230.10:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:51.647463 2026] [security2:error] [pid 133043:tid 133299] [client 74.7.230.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.emj.gpl.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuvj7dt6aqtVvMundNu1wAAAQM"]
[Thu Jul 30 15:09:51.648268 2026] [security2:error] [pid 133043:tid 133179] [client 74.7.230.10:55422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.emj.gpl.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuvj7dt6aqtVvMundNu1QAAiww"]
[Thu Jul 30 15:09:51.656916 2026] [core:notice] [pid 133043:tid 133198] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:51.836581 2026] [security2:error] [pid 133043:tid 133175] [client 4.225.203.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amuvj7dt6aqtVvMundNutgAAAIc"]
[Thu Jul 30 15:09:51.964720 2026] [security2:error] [pid 133043:tid 133252] [client 20.171.55.167:3372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/retu.php"] [unique_id "amuvj7dt6aqtVvMundNu4gAAANQ"]
[Thu Jul 30 15:09:52.265434 2026] [security2:error] [pid 133043:tid 133180] [client 4.225.203.146:11321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuvkLdt6aqtVvMundNu8AAAAIw"]
[Thu Jul 30 15:09:52.288730 2026] [security2:error] [pid 133043:tid 133186] [client 119.249.100.45:65422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/about"] [unique_id "amuvkLdt6aqtVvMundNu6AAAAJI"]
[Thu Jul 30 15:09:52.496681 2026] [security2:error] [pid 133043:tid 133273] [client 20.226.5.174:27340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/config.php"] [unique_id "amuvkLdt6aqtVvMundNu9gAAAOk"]
[Thu Jul 30 15:09:52.779633 2026] [security2:error] [pid 133043:tid 133218] [client 20.171.55.167:3613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/rt.php"] [unique_id "amuvkLdt6aqtVvMundNvBAAAALI"]
[Thu Jul 30 15:09:52.935769 2026] [core:notice] [pid 133043:tid 133254] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:53.146167 2026] [core:error] [pid 133043:tid 133197] [client 4.225.203.146:40841] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:53.146188 2026] [core:error] [pid 133043:tid 133197] [client 4.225.203.146:40841] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:53.576733 2026] [security2:error] [pid 133043:tid 133268] [client 185.177.72.68:36604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/server.php"] [unique_id "amuvkbdt6aqtVvMundNvJwAAAOQ"]
[Thu Jul 30 15:09:53.587336 2026] [security2:error] [pid 133043:tid 133223] [client 20.171.55.167:3606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/script-loader-react-refresh-runtime.min-soap.php"] [unique_id "amuvkbdt6aqtVvMundNvKgAAALc"]
[Thu Jul 30 15:09:53.590910 2026] [security2:error] [pid 133043:tid 133247] [client 4.225.203.146:22868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/index/function.php"] [unique_id "amuvkbdt6aqtVvMundNvKwAAAM8"]
[Thu Jul 30 15:09:53.773038 2026] [security2:error] [pid 133043:tid 133179] [client 20.226.5.174:27347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/core.php"] [unique_id "amuvkbdt6aqtVvMundNvNAAAAIs"]
[Thu Jul 30 15:09:53.817300 2026] [core:notice] [pid 133043:tid 133226] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:53.831288 2026] [security2:error] [pid 133043:tid 133243] [client 185.177.72.68:36620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/server.php.%252e"] [unique_id "amuvkbdt6aqtVvMundNvNgAAAMs"]
[Thu Jul 30 15:09:53.989141 2026] [core:notice] [pid 133043:tid 133233] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:54.079654 2026] [security2:error] [pid 133043:tid 133300] [client 185.177.72.68:4738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/server.php%0a"] [unique_id "amuvkrdt6aqtVvMundNvPAAAAQQ"]
[Thu Jul 30 15:09:54.333244 2026] [security2:error] [pid 133043:tid 133193] [client 185.177.72.68:4754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/server.php%5e"] [unique_id "amuvkrdt6aqtVvMundNvRQAAAJk"]
[Thu Jul 30 15:09:54.359942 2026] [security2:error] [pid 133043:tid 133265] [client 20.171.55.167:3448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/seotheme/db.php"] [unique_id "amuvkrdt6aqtVvMundNvRgAAAOE"]
[Thu Jul 30 15:09:54.481479 2026] [security2:error] [pid 133043:tid 133255] [client 172.237.109.114:17912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvkbdt6aqtVvMundNvNwAAANc"]
[Thu Jul 30 15:09:54.642458 2026] [security2:error] [pid 133043:tid 133240] [client 172.237.109.114:46404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvkrdt6aqtVvMundNvQAAAAMg"]
[Thu Jul 30 15:09:54.660302 2026] [core:notice] [pid 133043:tid 133054] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:54.933677 2026] [security2:error] [pid 133043:tid 133191] [client 20.226.5.174:27357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/css.php"] [unique_id "amuvkrdt6aqtVvMundNvXQAAAJc"]
[Thu Jul 30 15:09:55.081055 2026] [security2:error] [pid 133043:tid 133248] [client 4.225.203.146:42893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuvk7dt6aqtVvMundNvYQAAANA"]
[Thu Jul 30 15:09:55.186288 2026] [core:error] [pid 133043:tid 133088] [remote 159.195.202.171:49828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:55.186314 2026] [core:error] [pid 133043:tid 133088] [remote 159.195.202.171:49828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:09:55.200044 2026] [security2:error] [pid 133043:tid 133197] [client 20.171.55.167:3359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/shapes.php"] [unique_id "amuvk7dt6aqtVvMundNvbgAAAJ0"]
[Thu Jul 30 15:09:55.398256 2026] [autoindex:error] [pid 133043:tid 133178] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:55.497527 2026] [security2:error] [pid 133043:tid 133253] [client 172.237.109.114:22963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvk7dt6aqtVvMundNvYAAAANU"]
[Thu Jul 30 15:09:55.580695 2026] [autoindex:error] [pid 133043:tid 133290] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:55.701125 2026] [security2:error] [pid 133043:tid 133100] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvk7dt6aqtVvMundNvjQAAnDg"]
[Thu Jul 30 15:09:55.701254 2026] [security2:error] [pid 133043:tid 133196] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvk7dt6aqtVvMundNvjQAAnDg"]
[Thu Jul 30 15:09:55.734160 2026] [security2:error] [pid 133043:tid 133255] [client 4.225.203.146:25891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/aaa.php"] [unique_id "amuvk7dt6aqtVvMundNvjwAAANc"]
[Thu Jul 30 15:09:56.007300 2026] [security2:error] [pid 133043:tid 133208] [client 20.171.55.167:3431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/sidebarh.php"] [unique_id "amuvlLdt6aqtVvMundNvmAAAAKg"]
[Thu Jul 30 15:09:56.169252 2026] [security2:error] [pid 133043:tid 133276] [client 20.226.5.174:27360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/database.php"] [unique_id "amuvlLdt6aqtVvMundNvogAAAOw"]
[Thu Jul 30 15:09:56.856317 2026] [security2:error] [pid 133043:tid 133253] [client 20.171.55.167:3383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/sites/default/wp-login.php"] [unique_id "amuvlLdt6aqtVvMundNv2gAAANU"]
[Thu Jul 30 15:09:56.911042 2026] [security2:error] [pid 133043:tid 133226] [client 4.225.203.146:17287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/getid3-core.php"] [unique_id "amuvlLdt6aqtVvMundNv3gAAALo"]
[Thu Jul 30 15:09:57.631956 2026] [security2:error] [pid 133043:tid 133300] [client 20.171.55.167:3600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/smilies/network.php"] [unique_id "amuvlbdt6aqtVvMundNwAgAAAQQ"]
[Thu Jul 30 15:09:57.703741 2026] [fcgid:warn] [pid 133043:tid 133193] (70014)End of file found: [client 185.177.72.68:4764] mod_fcgid: can't get data from http client
[Thu Jul 30 15:09:57.953932 2026] [fcgid:warn] [pid 133043:tid 133289] (70014)End of file found: [client 185.177.72.68:4774] mod_fcgid: can't get data from http client
[Thu Jul 30 15:09:58.001058 2026] [security2:error] [pid 133043:tid 133267] [client 4.225.203.146:21901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/adminer.php"] [unique_id "amuvlrdt6aqtVvMundNwDwAAAOM"]
[Thu Jul 30 15:09:58.125671 2026] [security2:error] [pid 133043:tid 133233] [client 4.225.203.146:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin.php"] [unique_id "amuvlrdt6aqtVvMundNwEQAAAME"]
[Thu Jul 30 15:09:58.173998 2026] [security2:error] [pid 133043:tid 133270] [client 20.226.5.174:28056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/db.php"] [unique_id "amuvlrdt6aqtVvMundNwFQAAAOY"]
[Thu Jul 30 15:09:58.226344 2026] [fcgid:warn] [pid 133043:tid 133266] (70014)End of file found: [client 185.177.72.68:4788] mod_fcgid: can't get data from http client
[Thu Jul 30 15:09:58.484588 2026] [fcgid:warn] [pid 133043:tid 133176] (70014)End of file found: [client 185.177.72.68:4802] mod_fcgid: can't get data from http client
[Thu Jul 30 15:09:58.609343 2026] [security2:error] [pid 133043:tid 133157] [remote 216.73.216.51:41320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuvlrdt6aqtVvMundNwJwAAoXE"]
[Thu Jul 30 15:09:58.734558 2026] [security2:error] [pid 133043:tid 133253] [client 20.171.55.167:3392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/ss.php"] [unique_id "amuvlrdt6aqtVvMundNwKgAAANU"]
[Thu Jul 30 15:09:59.225666 2026] [core:notice] [pid 133043:tid 133202] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:59.227269 2026] [core:notice] [pid 133043:tid 133249] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:09:59.231880 2026] [autoindex:error] [pid 133043:tid 133244] [client 2606:2040:1800:9f::2:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:09:59.851013 2026] [security2:error] [pid 133043:tid 133257] [client 20.171.55.167:3636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/streams.php"] [unique_id "amuvl7dt6aqtVvMundNwaAAAANk"]
[Thu Jul 30 15:09:59.899509 2026] [security2:error] [pid 133043:tid 133280] [client 4.225.203.146:38254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/size.php"] [unique_id "amuvl7dt6aqtVvMundNwbAAAAPA"]
[Thu Jul 30 15:10:00.078996 2026] [security2:error] [pid 133043:tid 133179] [client 172.237.109.114:27609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/maintenance.php"] [unique_id "amuvmLdt6aqtVvMundNwdAAAAIs"]
[Thu Jul 30 15:10:00.270150 2026] [security2:error] [pid 133043:tid 133215] [client 4.225.203.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "seven-stars-shop.com"] [uri "/index.php"] [unique_id "amuvl7dt6aqtVvMundNwVgAAAK8"]
[Thu Jul 30 15:10:00.359346 2026] [security2:error] [pid 133043:tid 133298] [client 185.177.72.68:4812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env.backup"] [unique_id "amuvmLdt6aqtVvMundNwfwAAAQI"]
[Thu Jul 30 15:10:00.463078 2026] [security2:error] [pid 133043:tid 133252] [client 20.226.5.174:27341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/default.php"] [unique_id "amuvmLdt6aqtVvMundNwhgAAANQ"]
[Thu Jul 30 15:10:00.476839 2026] [security2:error] [pid 133043:tid 133239] [client 172.237.109.114:37556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvl7dt6aqtVvMundNwcwAAAMc"]
[Thu Jul 30 15:10:00.599349 2026] [security2:error] [pid 133043:tid 133230] [client 20.171.55.167:3380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/symlink.php"] [unique_id "amuvmLdt6aqtVvMundNwjAAAAL4"]
[Thu Jul 30 15:10:00.707246 2026] [security2:error] [pid 133043:tid 133267] [client 4.225.203.146:25909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/alfa.php"] [unique_id "amuvmLdt6aqtVvMundNwkAAAAOM"]
[Thu Jul 30 15:10:01.048390 2026] [autoindex:error] [pid 133043:tid 133229] [client 185.177.72.68:0] AH01276: Cannot serve directory /home2/xyugplte/public_html/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:10:01.383422 2026] [security2:error] [pid 133043:tid 133300] [client 20.171.55.167:3438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/tes.php"] [unique_id "amuvmbdt6aqtVvMundNwsgAAAQQ"]
[Thu Jul 30 15:10:01.398508 2026] [security2:error] [pid 133043:tid 133271] [client 4.225.203.146:30512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuvmbdt6aqtVvMundNwswAAAOc"]
[Thu Jul 30 15:10:01.469972 2026] [autoindex:error] [pid 133043:tid 133242] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:10:01.625534 2026] [security2:error] [pid 133043:tid 133252] [client 4.225.203.146:25903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuvmbdt6aqtVvMundNwxgAAANQ"]
[Thu Jul 30 15:10:02.001012 2026] [security2:error] [pid 133043:tid 133291] [client 185.177.72.68:4812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/api.orig"] [unique_id "amuvmbdt6aqtVvMundNw0QAAAPs"]
[Thu Jul 30 15:10:02.157346 2026] [security2:error] [pid 133043:tid 133233] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvmbdt6aqtVvMundNwvQAAwQk"]
[Thu Jul 30 15:10:02.215166 2026] [security2:error] [pid 133043:tid 133266] [client 20.171.55.167:3433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/themes/index.php"] [unique_id "amuvmrdt6aqtVvMundNw3QAAAOI"]
[Thu Jul 30 15:10:02.541054 2026] [security2:error] [pid 133043:tid 133221] [client 185.177.72.68:4812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/src.orig"] [unique_id "amuvmrdt6aqtVvMundNw5wAAALU"]
[Thu Jul 30 15:10:02.562704 2026] [security2:error] [pid 133043:tid 133282] [client 4.225.203.146:49780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/403.php"] [unique_id "amuvmrdt6aqtVvMundNw6gAAAPI"]
[Thu Jul 30 15:10:02.803740 2026] [security2:error] [pid 133043:tid 133200] [client 20.226.5.174:27366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/dropdown.php"] [unique_id "amuvmrdt6aqtVvMundNw8wAAAKA"]
[Thu Jul 30 15:10:03.004112 2026] [security2:error] [pid 133043:tid 133212] [client 20.171.55.167:3328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/tinymce/utils/license.php"] [unique_id "amuvm7dt6aqtVvMundNw9gAAAKw"]
[Thu Jul 30 15:10:03.754326 2026] [security2:error] [pid 133043:tid 133244] [client 4.225.203.146:25872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuvm7dt6aqtVvMundNxGwAAAMw"]
[Thu Jul 30 15:10:03.791698 2026] [security2:error] [pid 133043:tid 133229] [client 20.171.55.167:3591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/trd.php"] [unique_id "amuvm7dt6aqtVvMundNxHAAAAL0"]
[Thu Jul 30 15:10:03.837813 2026] [core:notice] [pid 133043:tid 133226] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:04.384919 2026] [security2:error] [pid 133043:tid 133188] [client 20.226.5.174:27349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/edit.php"] [unique_id "amuvnLdt6aqtVvMundNxNAAAAJQ"]
[Thu Jul 30 15:10:04.486280 2026] [security2:error] [pid 133043:tid 133207] [client 172.237.109.114:47789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxJgAAAKc"]
[Thu Jul 30 15:10:04.511611 2026] [security2:error] [pid 133043:tid 133243] [client 20.171.55.167:3417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/twentytwentyfour/functions.php"] [unique_id "amuvnLdt6aqtVvMundNxOAAAAMs"]
[Thu Jul 30 15:10:04.779746 2026] [security2:error] [pid 133043:tid 133213] [client 35.82.30.189:46952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxQQAArSY"]
[Thu Jul 30 15:10:04.800317 2026] [security2:error] [pid 133043:tid 133262] [client 35.82.30.189:46974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxRwAA3iE"]
[Thu Jul 30 15:10:04.834040 2026] [proxy:error] [pid 133043:tid 133241] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:04.834096 2026] [proxy_http:error] [pid 133043:tid 133241] [client 193.47.62.167:49328] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:04.834675 2026] [proxy:error] [pid 133043:tid 133241] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:04.834719 2026] [proxy_http:error] [pid 133043:tid 133241] [client 193.47.62.167:49328] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:04.870439 2026] [security2:error] [pid 133043:tid 133211] [client 35.82.30.189:46972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxQwAAqyc"]
[Thu Jul 30 15:10:04.870439 2026] [security2:error] [pid 133043:tid 133232] [client 35.82.30.189:46956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxRAAAwCg"]
[Thu Jul 30 15:10:04.884540 2026] [security2:error] [pid 133043:tid 133224] [client 35.82.30.189:47030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxUQAAuCs"]
[Thu Jul 30 15:10:04.892331 2026] [security2:error] [pid 133043:tid 133238] [client 35.82.30.189:46994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxSAAAxh4"]
[Thu Jul 30 15:10:05.219751 2026] [security2:error] [pid 133043:tid 133257] [client 35.82.30.189:46968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxRgAA2RM"]
[Thu Jul 30 15:10:05.254500 2026] [security2:error] [pid 133043:tid 133286] [client 35.82.30.189:47000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxSQAA9ik"]
[Thu Jul 30 15:10:05.262938 2026] [security2:error] [pid 133043:tid 133264] [client 35.82.30.189:46986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxTAAA4Co"]
[Thu Jul 30 15:10:05.291030 2026] [security2:error] [pid 133043:tid 133179] [client 35.82.30.189:47016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvnLdt6aqtVvMundNxUgAAizA"]
[Thu Jul 30 15:10:05.323127 2026] [security2:error] [pid 133043:tid 133192] [client 20.171.55.167:3614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/ucp.php"] [unique_id "amuvnbdt6aqtVvMundNxfwAAAJg"]
[Thu Jul 30 15:10:05.601662 2026] [security2:error] [pid 133043:tid 133210] [client 4.225.203.146:46245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuvnbdt6aqtVvMundNxiAAAAKo"]
[Thu Jul 30 15:10:05.906111 2026] [security2:error] [pid 133043:tid 133276] [client 4.225.203.146:40927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuvnbdt6aqtVvMundNxmwAAAOw"]
[Thu Jul 30 15:10:06.150131 2026] [security2:error] [pid 133043:tid 133291] [client 20.171.55.167:3348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/upload_crop_v1.2.php"] [unique_id "amuvnrdt6aqtVvMundNxowAAAPs"]
[Thu Jul 30 15:10:06.227679 2026] [security2:error] [pid 133043:tid 133112] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvnrdt6aqtVvMundNxqgAA2kQ"]
[Thu Jul 30 15:10:06.227809 2026] [security2:error] [pid 133043:tid 133258] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvnrdt6aqtVvMundNxqgAA2kQ"]
[Thu Jul 30 15:10:06.582847 2026] [security2:error] [pid 133043:tid 133231] [client 4.225.203.146:61252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/as.php"] [unique_id "amuvnrdt6aqtVvMundNxtwAAAL8"]
[Thu Jul 30 15:10:06.590869 2026] [autoindex:error] [pid 133043:tid 133263] [client 185.177.72.68:0] AH01276: Cannot serve directory /home2/xyugplte/public_html/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:10:06.899767 2026] [security2:error] [pid 133043:tid 133234] [client 4.225.203.146:12062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/edit.php"] [unique_id "amuvnrdt6aqtVvMundNxyAAAAMI"]
[Thu Jul 30 15:10:06.984749 2026] [security2:error] [pid 133043:tid 133245] [client 20.171.55.167:3385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/usb.php"] [unique_id "amuvnrdt6aqtVvMundNxyQAAAM0"]
[Thu Jul 30 15:10:07.384838 2026] [security2:error] [pid 133043:tid 133184] [client 20.226.5.174:27352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/f35.php"] [unique_id "amuvn7dt6aqtVvMundNx4AAAAJA"]
[Thu Jul 30 15:10:07.418640 2026] [security2:error] [pid 133043:tid 133287] [client 20.215.191.139:18284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.tmb/LA.php"] [unique_id "amuvn7dt6aqtVvMundNx4wAAAPc"]
[Thu Jul 30 15:10:07.462372 2026] [security2:error] [pid 133043:tid 133121] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cgi-binwp.php"] [unique_id "amuvn7dt6aqtVvMundNx5gAA4U0"]
[Thu Jul 30 15:10:07.490818 2026] [security2:error] [pid 133043:tid 133198] [client 4.225.203.146:46302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuvn7dt6aqtVvMundNx5wAAAJ4"]
[Thu Jul 30 15:10:07.535671 2026] [security2:error] [pid 133043:tid 133248] [client 35.82.30.189:47034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuvn7dt6aqtVvMundNx5AAA0E8"]
[Thu Jul 30 15:10:07.714894 2026] [security2:error] [pid 133043:tid 133186] [client 20.171.55.167:3361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/vendoradmin.php"] [unique_id "amuvn7dt6aqtVvMundNx7gAAAJI"]
[Thu Jul 30 15:10:07.754621 2026] [security2:error] [pid 133043:tid 133212] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvn7dt6aqtVvMundNx0gAAAKw"]
[Thu Jul 30 15:10:08.041118 2026] [security2:error] [pid 133043:tid 133278] [client 20.215.191.139:18178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.tmb/admin.php"] [unique_id "amuvoLdt6aqtVvMundNx_gAAAO4"]
[Thu Jul 30 15:10:08.051171 2026] [security2:error] [pid 133043:tid 133226] [client 185.177.72.68:4812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/libs~"] [unique_id "amuvoLdt6aqtVvMundNx_wAAALo"]
[Thu Jul 30 15:10:08.161988 2026] [security2:error] [pid 133043:tid 133108] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cgialfaadmin.php"] [unique_id "amuvoLdt6aqtVvMundNyAAAA80A"]
[Thu Jul 30 15:10:08.280631 2026] [core:notice] [pid 133043:tid 133131] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:08.297651 2026] [security2:error] [pid 133043:tid 133218] [client 185.191.171.16:40410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nobleinternationals.com"] [uri "/robots.txt"] [unique_id "amuvoLdt6aqtVvMundNyCAAAALI"]
[Thu Jul 30 15:10:08.297779 2026] [security2:error] [pid 133043:tid 133218] [client 185.191.171.16:40410] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nobleinternationals.com"] [uri "/robots.txt"] [unique_id "amuvoLdt6aqtVvMundNyCAAAALI"]
[Thu Jul 30 15:10:08.400376 2026] [security2:error] [pid 133043:tid 133132] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cgialfaalfa.php"] [unique_id "amuvoLdt6aqtVvMundNyDgAA71g"]
[Thu Jul 30 15:10:08.448884 2026] [security2:error] [pid 133043:tid 133175] [client 172.237.109.114:20478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvn7dt6aqtVvMundNx_QAAAIc"]
[Thu Jul 30 15:10:08.455575 2026] [autoindex:error] [pid 133043:tid 133210] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:10:08.499761 2026] [security2:error] [pid 133043:tid 133237] [client 20.171.55.167:3365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/vwcleanerplugin/bump.php"] [unique_id "amuvoLdt6aqtVvMundNyGQAAAMU"]
[Thu Jul 30 15:10:08.637621 2026] [security2:error] [pid 133043:tid 133135] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cgialfabypass.php"] [unique_id "amuvoLdt6aqtVvMundNyHQAA6Vs"]
[Thu Jul 30 15:10:08.806713 2026] [security2:error] [pid 133043:tid 133197] [client 20.226.5.174:27365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/f7.php"] [unique_id "amuvoLdt6aqtVvMundNyJwAAAJ0"]
[Thu Jul 30 15:10:08.875322 2026] [security2:error] [pid 133043:tid 133139] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cgialfak.php"] [unique_id "amuvoLdt6aqtVvMundNyLQAAw18"]
[Thu Jul 30 15:10:08.923668 2026] [security2:error] [pid 133043:tid 133181] [client 4.225.203.146:45699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/sf.php"] [unique_id "amuvoLdt6aqtVvMundNyMQAAAI0"]
[Thu Jul 30 15:10:09.112727 2026] [security2:error] [pid 133043:tid 133141] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cgialfawp.php"] [unique_id "amuvobdt6aqtVvMundNyNQAAuGE"]
[Thu Jul 30 15:10:09.348534 2026] [security2:error] [pid 133043:tid 133144] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/checkbex.php"] [unique_id "amuvobdt6aqtVvMundNyQAAA4mQ"]
[Thu Jul 30 15:10:09.363139 2026] [security2:error] [pid 133043:tid 133258] [client 20.171.55.167:3366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/whmcs.php"] [unique_id "amuvobdt6aqtVvMundNyQQAAANo"]
[Thu Jul 30 15:10:09.586888 2026] [security2:error] [pid 133043:tid 133146] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/checkbox.php"] [unique_id "amuvobdt6aqtVvMundNyUQAAmmY"]
[Thu Jul 30 15:10:09.693485 2026] [security2:error] [pid 133043:tid 133262] [client 74.7.175.138:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.tlt.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuvn7dt6aqtVvMundNx-QAA3lI"]
[Thu Jul 30 15:10:09.693514 2026] [security2:error] [pid 133043:tid 133262] [client 74.7.175.138:45420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.tlt.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuvn7dt6aqtVvMundNx-QAA3lI"]
[Thu Jul 30 15:10:09.823237 2026] [security2:error] [pid 133043:tid 133152] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/checker.php"] [unique_id "amuvobdt6aqtVvMundNyWwAAwmw"]
[Thu Jul 30 15:10:09.912041 2026] [security2:error] [pid 133043:tid 133275] [client 4.225.203.146:46335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuvobdt6aqtVvMundNyYAAAAOs"]
[Thu Jul 30 15:10:10.059925 2026] [security2:error] [pid 133043:tid 133153] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/chitoge.php"] [unique_id "amuvordt6aqtVvMundNyaAAAy20"]
[Thu Jul 30 15:10:10.060234 2026] [core:notice] [pid 133043:tid 133147] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:10.296749 2026] [security2:error] [pid 133043:tid 133157] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/chosen-667.php"] [unique_id "amuvordt6aqtVvMundNybQAAsHE"]
[Thu Jul 30 15:10:10.341455 2026] [security2:error] [pid 133043:tid 133298] [client 85.208.96.205:21184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nobleinternationals.com"] [uri "/"] [unique_id "amuvordt6aqtVvMundNycwAAAQI"]
[Thu Jul 30 15:10:10.341595 2026] [security2:error] [pid 133043:tid 133298] [client 85.208.96.205:21184] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nobleinternationals.com"] [uri "/"] [unique_id "amuvordt6aqtVvMundNycwAAAQI"]
[Thu Jul 30 15:10:10.444681 2026] [security2:error] [pid 133043:tid 133293] [client 74.7.175.138:45434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tlt.zzt.temporary.site"] [uri "/index.php"] [unique_id "amuvordt6aqtVvMundNycgAA_W8"], referer: https://www.tlt.zzt.temporary.site/robots.txt
[Thu Jul 30 15:10:10.473677 2026] [security2:error] [pid 133043:tid 133227] [client 20.171.55.167:3434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/widgets/moon.php"] [unique_id "amuvordt6aqtVvMundNyfAAAALs"]
[Thu Jul 30 15:10:10.534060 2026] [security2:error] [pid 133043:tid 133162] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/chosen.php"] [unique_id "amuvordt6aqtVvMundNygAAAuHY"]
[Thu Jul 30 15:10:10.668015 2026] [autoindex:error] [pid 133043:tid 133230] [client 4.225.203.146:60823] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:10:10.718885 2026] [security2:error] [pid 133043:tid 133203] [client 4.225.203.146:49764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/plugins.php"] [unique_id "amuvordt6aqtVvMundNyhQAAAKM"]
[Thu Jul 30 15:10:10.769961 2026] [security2:error] [pid 133043:tid 133164] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/chris.php"] [unique_id "amuvordt6aqtVvMundNyhgAAiHg"]
[Thu Jul 30 15:10:10.824716 2026] [security2:error] [pid 133043:tid 133266] [client 4.225.203.146:60823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wso.php"] [unique_id "amuvordt6aqtVvMundNyiwAAAOI"]
[Thu Jul 30 15:10:11.007672 2026] [security2:error] [pid 133043:tid 133165] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/ciis.php"] [unique_id "amuvo7dt6aqtVvMundNylgAAznk"]
[Thu Jul 30 15:10:11.051262 2026] [core:notice] [pid 133043:tid 133168] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:11.055998 2026] [security2:error] [pid 133043:tid 133272] [client 43.154.113.165:58474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/download/4599/2251"] [unique_id "amuvordt6aqtVvMundNyigAA6Hw"]
[Thu Jul 30 15:10:11.185064 2026] [security2:error] [pid 133043:tid 133189] [client 185.200.117.131:35932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuvo7dt6aqtVvMundNynAAAAJU"]
[Thu Jul 30 15:10:11.185170 2026] [security2:error] [pid 133043:tid 133189] [client 185.200.117.131:35932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuvo7dt6aqtVvMundNynAAAAJU"]
[Thu Jul 30 15:10:11.245319 2026] [security2:error] [pid 133043:tid 133170] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cjfuns.php"] [unique_id "amuvo7dt6aqtVvMundNynwAArn4"]
[Thu Jul 30 15:10:11.330783 2026] [security2:error] [pid 133043:tid 133251] [client 20.215.191.139:42958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.tmb/class_api.php"] [unique_id "amuvo7dt6aqtVvMundNyoQAAANM"]
[Thu Jul 30 15:10:11.439193 2026] [core:notice] [pid 133043:tid 133269] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:11.470335 2026] [security2:error] [pid 133043:tid 133215] [client 20.171.55.167:3977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/woocommerce/templates/wp-login.php"] [unique_id "amuvo7dt6aqtVvMundNytAAAAK8"]
[Thu Jul 30 15:10:11.479504 2026] [security2:error] [pid 133043:tid 133221] [client 37.77.56.246:42108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuvo7dt6aqtVvMundNyngAAALU"]
[Thu Jul 30 15:10:11.479607 2026] [security2:error] [pid 133043:tid 133221] [client 37.77.56.246:42108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuvo7dt6aqtVvMundNyngAAALU"]
[Thu Jul 30 15:10:11.481285 2026] [security2:error] [pid 133043:tid 133047] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/cla.php"] [unique_id "amuvo7dt6aqtVvMundNyuAAAtAM"]
[Thu Jul 30 15:10:11.719011 2026] [security2:error] [pid 133043:tid 133058] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/clara/clara.php"] [unique_id "amuvo7dt6aqtVvMundNyvQAA0A4"]
[Thu Jul 30 15:10:11.787274 2026] [core:notice] [pid 133043:tid 133052] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:11.955110 2026] [security2:error] [pid 133043:tid 133056] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-IXR-base64-view.php"] [unique_id "amuvo7dt6aqtVvMundNyywAAkgw"]
[Thu Jul 30 15:10:11.977845 2026] [core:notice] [pid 133043:tid 133065] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:11.979784 2026] [core:notice] [pid 133043:tid 133053] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:12.175630 2026] [security2:error] [pid 133043:tid 133299] [client 185.177.72.68:26966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/wordpress.sql"] [unique_id "amuvpLdt6aqtVvMundNy1AAAAQM"]
[Thu Jul 30 15:10:12.192299 2026] [security2:error] [pid 133043:tid 133067] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-IXR-date.php"] [unique_id "amuvpLdt6aqtVvMundNy1QAA6hc"]
[Thu Jul 30 15:10:12.305574 2026] [security2:error] [pid 133043:tid 133253] [client 4.225.203.146:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuvpLdt6aqtVvMundNy1gAAANU"]
[Thu Jul 30 15:10:12.332888 2026] [security2:error] [pid 133043:tid 133177] [client 20.171.55.167:3593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-akuma.php"] [unique_id "amuvpLdt6aqtVvMundNy2gAAAIk"]
[Thu Jul 30 15:10:12.430151 2026] [security2:error] [pid 133043:tid 133068] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-IXR.php"] [unique_id "amuvpLdt6aqtVvMundNy3gAAmxg"]
[Thu Jul 30 15:10:12.477735 2026] [security2:error] [pid 133043:tid 133278] [client 196.75.110.110:47552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvpLdt6aqtVvMundNy5QAAAO4"]
[Thu Jul 30 15:10:12.527529 2026] [security2:error] [pid 133043:tid 133258] [client 196.75.110.110:47556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvpLdt6aqtVvMundNy6QAAANo"]
[Thu Jul 30 15:10:12.530703 2026] [security2:error] [pid 133043:tid 133198] [client 20.215.191.139:42959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuvpLdt6aqtVvMundNy6gAAAJ4"]
[Thu Jul 30 15:10:12.666363 2026] [security2:error] [pid 133043:tid 133059] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-config.php"] [unique_id "amuvpLdt6aqtVvMundNy7gAAjA8"]
[Thu Jul 30 15:10:12.776039 2026] [security2:error] [pid 133043:tid 133245] [client 196.75.110.110:35746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvpLdt6aqtVvMundNy8QAAAM0"]
[Thu Jul 30 15:10:12.902483 2026] [security2:error] [pid 133043:tid 133062] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-core-upgrader-first.php"] [unique_id "amuvpLdt6aqtVvMundNy-AAAuRI"]
[Thu Jul 30 15:10:13.091792 2026] [security2:error] [pid 133043:tid 133192] [client 196.75.110.110:47572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvpbdt6aqtVvMundNzAQAAAJg"]
[Thu Jul 30 15:10:13.109775 2026] [security2:error] [pid 133043:tid 133176] [client 4.225.203.146:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/ioxi-o.php"] [unique_id "amuvpbdt6aqtVvMundNzAgAAAIg"]
[Thu Jul 30 15:10:13.119623 2026] [security2:error] [pid 133043:tid 133207] [client 196.75.110.110:47566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvpbdt6aqtVvMundNzAwAAAKc"]
[Thu Jul 30 15:10:13.129633 2026] [security2:error] [pid 133043:tid 133277] [client 4.225.203.146:46296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/go.php"] [unique_id "amuvpbdt6aqtVvMundNzBAAAAO0"]
[Thu Jul 30 15:10:13.141943 2026] [security2:error] [pid 133043:tid 133076] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-feed-index.php"] [unique_id "amuvpbdt6aqtVvMundNzBwAA4SA"]
[Thu Jul 30 15:10:13.147906 2026] [security2:error] [pid 133043:tid 133249] [client 20.171.55.167:3989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-comments-post.php"] [unique_id "amuvpbdt6aqtVvMundNzCAAAANE"]
[Thu Jul 30 15:10:13.162382 2026] [security2:error] [pid 133043:tid 133183] [client 196.75.110.110:35762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvpbdt6aqtVvMundNzCQAAAI8"]
[Thu Jul 30 15:10:13.378877 2026] [security2:error] [pid 133043:tid 133054] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-flitert.php"] [unique_id "amuvpbdt6aqtVvMundNzDwAA9Qo"]
[Thu Jul 30 15:10:13.598801 2026] [security2:error] [pid 133043:tid 133205] [client 196.75.110.110:34964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvpbdt6aqtVvMundNzGAAAAKU"]
[Thu Jul 30 15:10:13.617205 2026] [security2:error] [pid 133043:tid 133090] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-ftp-pures.php"] [unique_id "amuvpbdt6aqtVvMundNzGgAAoy4"]
[Thu Jul 30 15:10:13.622039 2026] [security2:error] [pid 133043:tid 133247] [client 185.177.72.68:26966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env~"] [unique_id "amuvpbdt6aqtVvMundNzHAAAAM8"]
[Thu Jul 30 15:10:13.624477 2026] [security2:error] [pid 133043:tid 133212] [client 196.75.110.110:47576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvpbdt6aqtVvMundNzHQAAAKw"]
[Thu Jul 30 15:10:13.668894 2026] [security2:error] [pid 133043:tid 133292] [client 196.75.110.110:47580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvpbdt6aqtVvMundNzHwAAAPw"]
[Thu Jul 30 15:10:13.679390 2026] [security2:error] [pid 133043:tid 133267] [client 4.225.203.146:62818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/file56.php"] [unique_id "amuvpbdt6aqtVvMundNzIAAAAOM"]
[Thu Jul 30 15:10:13.852794 2026] [security2:error] [pid 133043:tid 133089] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-oembed.php"] [unique_id "amuvpbdt6aqtVvMundNzJQAAiy0"]
[Thu Jul 30 15:10:14.002919 2026] [security2:error] [pid 133043:tid 133266] [client 20.171.55.167:3353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-css.php"] [unique_id "amuvprdt6aqtVvMundNzMQAAAOI"]
[Thu Jul 30 15:10:14.042596 2026] [security2:error] [pid 133043:tid 133180] [client 196.75.110.110:34966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvprdt6aqtVvMundNzNgAAAIw"]
[Thu Jul 30 15:10:14.089730 2026] [security2:error] [pid 133043:tid 133074] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-phpmailer-http.php"] [unique_id "amuvprdt6aqtVvMundNzOQAAxR4"]
[Thu Jul 30 15:10:14.134992 2026] [security2:error] [pid 133043:tid 133296] [client 196.75.110.110:47270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvprdt6aqtVvMundNzOgAAAQA"]
[Thu Jul 30 15:10:14.199037 2026] [security2:error] [pid 133043:tid 133260] [client 20.215.191.139:35408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuvpbdt6aqtVvMundNzKQAAANw"]
[Thu Jul 30 15:10:14.210697 2026] [security2:error] [pid 133043:tid 133174] [client 4.225.203.146:61282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/test1.php"] [unique_id "amuvprdt6aqtVvMundNzQgAAAIY"]
[Thu Jul 30 15:10:14.306579 2026] [security2:error] [pid 133043:tid 133099] [remote 57.141.0.29:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5351135361/feed/rss2/"] [unique_id "amuvprdt6aqtVvMundNzQwAAzTc"]
[Thu Jul 30 15:10:14.326741 2026] [security2:error] [pid 133043:tid 133075] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-phpmailer.php"] [unique_id "amuvprdt6aqtVvMundNzSAAAiB8"]
[Thu Jul 30 15:10:14.392521 2026] [security2:error] [pid 133043:tid 133210] [client 196.75.110.110:34970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvprdt6aqtVvMundNzSQAAAKo"]
[Thu Jul 30 15:10:14.393186 2026] [security2:error] [pid 133043:tid 133290] [client 196.75.110.110:47274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvprdt6aqtVvMundNzSgAAAPo"]
[Thu Jul 30 15:10:14.567751 2026] [security2:error] [pid 133043:tid 133091] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-simplepie.php"] [unique_id "amuvprdt6aqtVvMundNzVAAAoy8"]
[Thu Jul 30 15:10:14.683303 2026] [security2:error] [pid 133043:tid 133284] [client 196.75.110.110:47286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvprdt6aqtVvMundNzXAAAAPQ"]
[Thu Jul 30 15:10:14.712378 2026] [security2:error] [pid 133043:tid 133215] [client 4.225.203.146:50827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuvprdt6aqtVvMundNzXgAAAK8"]
[Thu Jul 30 15:10:14.723804 2026] [security2:error] [pid 133043:tid 133292] [client 196.75.110.110:34980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvprdt6aqtVvMundNzXwAAAPw"]
[Thu Jul 30 15:10:14.750922 2026] [security2:error] [pid 133043:tid 133181] [client 20.171.55.167:3592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-foter.php"] [unique_id "amuvprdt6aqtVvMundNzYgAAAI0"]
[Thu Jul 30 15:10:14.809239 2026] [security2:error] [pid 133043:tid 133104] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-snoopye_wso.php"] [unique_id "amuvprdt6aqtVvMundNzZAABAzw"]
[Thu Jul 30 15:10:14.885073 2026] [security2:error] [pid 133043:tid 133230] [client 20.215.191.139:42988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuvprdt6aqtVvMundNzZQAAAL4"]
[Thu Jul 30 15:10:14.891837 2026] [security2:error] [pid 133043:tid 133206] [client 196.75.110.110:47290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvprdt6aqtVvMundNzaAAAAKY"]
[Thu Jul 30 15:10:15.046565 2026] [security2:error] [pid 133043:tid 133063] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-t.api.php"] [unique_id "amuvp7dt6aqtVvMundNzcQAAvRM"]
[Thu Jul 30 15:10:15.093468 2026] [security2:error] [pid 133043:tid 133195] [client 196.75.110.110:34990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvp7dt6aqtVvMundNzdQAAAJs"]
[Thu Jul 30 15:10:15.221336 2026] [core:error] [pid 133043:tid 133231] [client 4.225.203.146:35427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:15.221357 2026] [core:error] [pid 133043:tid 133231] [client 4.225.203.146:35427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:15.287387 2026] [security2:error] [pid 133043:tid 133086] [remote 20.226.5.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/class-wp-admin-bar.php"] [unique_id "amuvp7dt6aqtVvMundNzgAABACo"]
[Thu Jul 30 15:10:15.333876 2026] [security2:error] [pid 133043:tid 133278] [client 196.75.110.110:47298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvp7dt6aqtVvMundNzhAAAAO4"]
[Thu Jul 30 15:10:15.433337 2026] [security2:error] [pid 133043:tid 133220] [client 196.75.110.110:34998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvp7dt6aqtVvMundNzhgAAALQ"]
[Thu Jul 30 15:10:15.478079 2026] [security2:error] [pid 133043:tid 133178] [client 172.237.109.114:57643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvprdt6aqtVvMundNzagAAAIo"]
[Thu Jul 30 15:10:15.512019 2026] [security2:error] [pid 133043:tid 133259] [client 196.75.110.110:47312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvp7dt6aqtVvMundNzjQAAANs"]
[Thu Jul 30 15:10:15.586761 2026] [security2:error] [pid 133043:tid 133182] [client 20.171.55.167:3986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-includes/Text/network.php"] [unique_id "amuvp7dt6aqtVvMundNzkQAAAI4"]
[Thu Jul 30 15:10:15.842812 2026] [security2:error] [pid 133043:tid 133284] [client 196.75.110.110:35010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvp7dt6aqtVvMundNzogAAAPQ"]
[Thu Jul 30 15:10:15.869365 2026] [core:notice] [pid 133043:tid 133249] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:15.888629 2026] [security2:error] [pid 133043:tid 133285] [client 196.75.110.110:47324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvp7dt6aqtVvMundNzqAAAAPU"]
[Thu Jul 30 15:10:15.942308 2026] [security2:error] [pid 133043:tid 133252] [client 20.215.191.139:35410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/991176.php"] [unique_id "amuvp7dt6aqtVvMundNzqQAAANQ"]
[Thu Jul 30 15:10:16.023365 2026] [security2:error] [pid 133043:tid 133224] [client 196.75.110.110:47334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqLdt6aqtVvMundNzrAAAALg"]
[Thu Jul 30 15:10:16.122713 2026] [security2:error] [pid 133043:tid 133287] [client 4.225.203.146:50868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuvqLdt6aqtVvMundNzsQAAAPc"]
[Thu Jul 30 15:10:16.141322 2026] [security2:error] [pid 133043:tid 133232] [client 4.225.203.146:47343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/images/index.php"] [unique_id "amuvqLdt6aqtVvMundNztAAAAMA"]
[Thu Jul 30 15:10:16.226858 2026] [security2:error] [pid 133043:tid 133208] [client 196.75.110.110:35016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqLdt6aqtVvMundNzvQAAAKg"]
[Thu Jul 30 15:10:16.387232 2026] [security2:error] [pid 133043:tid 133195] [client 196.75.110.110:47348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqLdt6aqtVvMundNzwQAAAJs"]
[Thu Jul 30 15:10:16.421424 2026] [security2:error] [pid 133043:tid 133223] [client 20.171.55.167:3604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-mn.php"] [unique_id "amuvqLdt6aqtVvMundNzwgAAALc"]
[Thu Jul 30 15:10:16.542369 2026] [security2:error] [pid 133043:tid 133243] [client 196.75.110.110:35032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqLdt6aqtVvMundNzxQAAAMs"]
[Thu Jul 30 15:10:16.549550 2026] [security2:error] [pid 133043:tid 133258] [client 196.75.110.110:47354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqLdt6aqtVvMundNzxgAAANo"]
[Thu Jul 30 15:10:16.609348 2026] [security2:error] [pid 133043:tid 133286] [client 20.215.191.139:35411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuvqLdt6aqtVvMundNzzQAAAPY"]
[Thu Jul 30 15:10:16.782447 2026] [security2:error] [pid 133043:tid 133118] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvqLdt6aqtVvMundNz1wAA-ko"]
[Thu Jul 30 15:10:16.782632 2026] [security2:error] [pid 133043:tid 133290] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvqLdt6aqtVvMundNz1wAA-ko"]
[Thu Jul 30 15:10:16.857174 2026] [security2:error] [pid 133043:tid 133187] [client 196.75.110.110:47368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqLdt6aqtVvMundNz2QAAAJM"]
[Thu Jul 30 15:10:17.065581 2026] [security2:error] [pid 133043:tid 133197] [client 140.245.59.145:49763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuvqLdt6aqtVvMundNz2AAAAJ0"]
[Thu Jul 30 15:10:17.103321 2026] [security2:error] [pid 133043:tid 133186] [client 196.75.110.110:47372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqbdt6aqtVvMundNz5QAAAJI"]
[Thu Jul 30 15:10:17.179117 2026] [security2:error] [pid 133043:tid 133211] [client 20.215.191.139:42977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuvqbdt6aqtVvMundNz7AAAAKs"]
[Thu Jul 30 15:10:17.247183 2026] [security2:error] [pid 133043:tid 133173] [client 20.171.55.167:3350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-scripts.php"] [unique_id "amuvqbdt6aqtVvMundNz8QAAAIU"]
[Thu Jul 30 15:10:17.256029 2026] [proxy:error] [pid 133043:tid 133253] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:17.256081 2026] [proxy_http:error] [pid 133043:tid 133253] [client 140.245.59.145:49979] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:17.256645 2026] [proxy:error] [pid 133043:tid 133253] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:17.256687 2026] [proxy_http:error] [pid 133043:tid 133253] [client 140.245.59.145:49979] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:17.259935 2026] [security2:error] [pid 133043:tid 133299] [client 213.152.161.170:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuvqbdt6aqtVvMundNz8wAAAQM"]
[Thu Jul 30 15:10:17.260058 2026] [security2:error] [pid 133043:tid 133299] [client 213.152.161.170:37568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuvqbdt6aqtVvMundNz8wAAAQM"]
[Thu Jul 30 15:10:17.284789 2026] [core:notice] [pid 133043:tid 133248] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:17.288735 2026] [security2:error] [pid 133043:tid 133248] [client 47.79.119.140:17758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/download/6433/3835"] [unique_id "amuvqbdt6aqtVvMundNz5AAAANA"]
[Thu Jul 30 15:10:17.321917 2026] [security2:error] [pid 133043:tid 133240] [client 4.225.203.146:62842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/edit.php"] [unique_id "amuvqbdt6aqtVvMundNz-QAAAMg"]
[Thu Jul 30 15:10:17.380814 2026] [security2:error] [pid 133043:tid 133256] [client 196.75.110.110:47378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqbdt6aqtVvMundNz-gAAANg"]
[Thu Jul 30 15:10:17.449855 2026] [proxy:error] [pid 133043:tid 133263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:17.449927 2026] [proxy_http:error] [pid 133043:tid 133263] [client 140.245.59.145:50054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:17.450494 2026] [proxy:error] [pid 133043:tid 133263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:17.450539 2026] [proxy_http:error] [pid 133043:tid 133263] [client 140.245.59.145:50054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:17.606134 2026] [security2:error] [pid 133043:tid 133272] [client 196.75.110.110:47386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqbdt6aqtVvMundN0BQAAAOg"]
[Thu Jul 30 15:10:17.640641 2026] [security2:error] [pid 133043:tid 133209] [client 140.245.59.145:50134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuvqbdt6aqtVvMundN0CAAAAKk"]
[Thu Jul 30 15:10:17.649396 2026] [core:error] [pid 133043:tid 133199] [client 4.225.203.146:17643] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:17.649412 2026] [core:error] [pid 133043:tid 133199] [client 4.225.203.146:17643] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:17.827693 2026] [security2:error] [pid 133043:tid 133207] [client 140.245.59.145:50221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-admin/load-scripts.php"] [unique_id "amuvqbdt6aqtVvMundN0FQAAAKc"]
[Thu Jul 30 15:10:17.871437 2026] [core:notice] [pid 133043:tid 133288] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:17.925683 2026] [security2:error] [pid 133043:tid 133220] [client 196.75.110.110:47394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqbdt6aqtVvMundN0GwAAALQ"]
[Thu Jul 30 15:10:17.941438 2026] [security2:error] [pid 133043:tid 133180] [client 20.215.191.139:38976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuvqbdt6aqtVvMundN0HAAAAIw"]
[Thu Jul 30 15:10:18.012383 2026] [security2:error] [pid 133043:tid 133185] [client 20.171.55.167:3644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wp-trackback.php"] [unique_id "amuvqrdt6aqtVvMundN0IAAAAJE"]
[Thu Jul 30 15:10:18.015791 2026] [security2:error] [pid 133043:tid 133276] [client 140.245.59.145:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-admin/load-styles.php"] [unique_id "amuvqrdt6aqtVvMundN0IQAAAOw"]
[Thu Jul 30 15:10:18.126719 2026] [core:notice] [pid 133043:tid 133203] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:18.168241 2026] [security2:error] [pid 133043:tid 133216] [client 196.75.110.110:47404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqrdt6aqtVvMundN0KQAAALA"]
[Thu Jul 30 15:10:18.209696 2026] [proxy:error] [pid 133043:tid 133212] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:18.209771 2026] [proxy_http:error] [pid 133043:tid 133212] [client 140.245.59.145:50370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:18.210348 2026] [proxy:error] [pid 133043:tid 133212] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:18.210393 2026] [proxy_http:error] [pid 133043:tid 133212] [client 140.245.59.145:50370] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:18.213475 2026] [security2:error] [pid 133043:tid 133281] [client 4.225.203.146:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/2.php"] [unique_id "amuvqrdt6aqtVvMundN0KwAAAPE"]
[Thu Jul 30 15:10:18.390661 2026] [security2:error] [pid 133043:tid 133197] [client 196.75.110.110:47414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqrdt6aqtVvMundN0NQAAAJ0"]
[Thu Jul 30 15:10:18.400260 2026] [proxy:error] [pid 133043:tid 133230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:18.400335 2026] [proxy_http:error] [pid 133043:tid 133230] [client 140.245.59.145:50462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:18.400896 2026] [proxy:error] [pid 133043:tid 133230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:18.400938 2026] [proxy_http:error] [pid 133043:tid 133230] [client 140.245.59.145:50462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:18.509081 2026] [security2:error] [pid 133043:tid 133225] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvqbdt6aqtVvMundN0GgAAuUg"]
[Thu Jul 30 15:10:18.599782 2026] [proxy:error] [pid 133043:tid 133244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:18.599874 2026] [proxy_http:error] [pid 133043:tid 133244] [client 140.245.59.145:50538] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:18.600574 2026] [proxy:error] [pid 133043:tid 133244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:18.600623 2026] [proxy_http:error] [pid 133043:tid 133244] [client 140.245.59.145:50538] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:18.628027 2026] [core:notice] [pid 133043:tid 133248] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:18.649854 2026] [security2:error] [pid 133043:tid 133287] [client 196.75.110.110:47428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nordeste1.com"] [uri "/index.php"] [unique_id "amuvqrdt6aqtVvMundN0QgAAAPc"]
[Thu Jul 30 15:10:18.702898 2026] [security2:error] [pid 133043:tid 133219] [client 4.225.203.146:62368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/asd.php"] [unique_id "amuvqrdt6aqtVvMundN0SQAAALM"]
[Thu Jul 30 15:10:18.798302 2026] [proxy:error] [pid 133043:tid 133200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:18.798390 2026] [proxy_http:error] [pid 133043:tid 133200] [client 140.245.59.145:50609] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:18.799030 2026] [proxy:error] [pid 133043:tid 133200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:18.799079 2026] [proxy_http:error] [pid 133043:tid 133200] [client 140.245.59.145:50609] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:18.807166 2026] [security2:error] [pid 133043:tid 133218] [client 20.171.55.167:3444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wpcall-button/button-image.php"] [unique_id "amuvqrdt6aqtVvMundN0TgAAALI"]
[Thu Jul 30 15:10:18.989099 2026] [security2:error] [pid 133043:tid 133174] [client 140.245.59.145:50704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-includes/version.php"] [unique_id "amuvqrdt6aqtVvMundN0VgAAAIY"]
[Thu Jul 30 15:10:19.045356 2026] [security2:error] [pid 133043:tid 133263] [client 20.215.191.139:18230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuvq7dt6aqtVvMundN0VwAAAN8"]
[Thu Jul 30 15:10:19.176121 2026] [security2:error] [pid 133043:tid 133207] [client 140.245.59.145:50768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-includes/functions.php"] [unique_id "amuvq7dt6aqtVvMundN0WgAAAKc"]
[Thu Jul 30 15:10:19.365405 2026] [security2:error] [pid 133043:tid 133220] [client 140.245.59.145:50836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-includes/class-wp.php"] [unique_id "amuvq7dt6aqtVvMundN0ZQAAALQ"]
[Thu Jul 30 15:10:19.542552 2026] [security2:error] [pid 133043:tid 133228] [client 20.171.55.167:3588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/wso-latest.php"] [unique_id "amuvq7dt6aqtVvMundN0bgAAALw"]
[Thu Jul 30 15:10:19.552570 2026] [security2:error] [pid 133043:tid 133227] [client 140.245.59.145:50897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-includes/option.php"] [unique_id "amuvq7dt6aqtVvMundN0bwAAALs"]
[Thu Jul 30 15:10:19.645262 2026] [security2:error] [pid 133043:tid 133203] [client 20.215.191.139:42997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuvq7dt6aqtVvMundN0cQAAAKM"]
[Thu Jul 30 15:10:19.747947 2026] [security2:error] [pid 133043:tid 133285] [client 140.245.59.145:50971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-includes/post.php"] [unique_id "amuvq7dt6aqtVvMundN0eQAAAPU"]
[Thu Jul 30 15:10:19.768718 2026] [security2:error] [pid 133043:tid 133238] [client 4.225.203.146:47320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuvq7dt6aqtVvMundN0ewAAAMY"]
[Thu Jul 30 15:10:19.940776 2026] [security2:error] [pid 133043:tid 133249] [client 140.245.59.145:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-includes/user.php"] [unique_id "amuvq7dt6aqtVvMundN0iQAAANE"]
[Thu Jul 30 15:10:20.129766 2026] [proxy:error] [pid 133043:tid 133208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.129853 2026] [proxy_http:error] [pid 133043:tid 133208] [client 140.245.59.145:51103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:20.130435 2026] [proxy:error] [pid 133043:tid 133208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.130480 2026] [proxy_http:error] [pid 133043:tid 133208] [client 140.245.59.145:51103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:20.313675 2026] [security2:error] [pid 133043:tid 133213] [client 20.171.55.167:3390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/x1.php"] [unique_id "amuvrLdt6aqtVvMundN0kwAAAK0"]
[Thu Jul 30 15:10:20.322172 2026] [proxy:error] [pid 133043:tid 133214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.322232 2026] [proxy_http:error] [pid 133043:tid 133214] [client 140.245.59.145:51179] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:20.322783 2026] [proxy:error] [pid 133043:tid 133214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.322826 2026] [proxy_http:error] [pid 133043:tid 133214] [client 140.245.59.145:51179] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:20.470823 2026] [security2:error] [pid 133043:tid 133175] [client 4.225.203.146:50862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuvrLdt6aqtVvMundN0oAAAAIc"]
[Thu Jul 30 15:10:20.510919 2026] [proxy:error] [pid 133043:tid 133263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.511009 2026] [proxy_http:error] [pid 133043:tid 133263] [client 140.245.59.145:51244] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:20.511664 2026] [proxy:error] [pid 133043:tid 133263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.511714 2026] [proxy_http:error] [pid 133043:tid 133263] [client 140.245.59.145:51244] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:20.554209 2026] [security2:error] [pid 133043:tid 133151] [remote 198.38.90.25:42938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.90.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/wp-login.php"] [unique_id "amuvrLdt6aqtVvMundN0owAAsms"]
[Thu Jul 30 15:10:20.574442 2026] [fcgid:warn] [pid 133043:tid 133289] (70014)End of file found: [client 185.177.72.68:65502] mod_fcgid: can't get data from http client
[Thu Jul 30 15:10:20.699523 2026] [proxy:error] [pid 133043:tid 133176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.699615 2026] [proxy_http:error] [pid 133043:tid 133176] [client 140.245.59.145:51301] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:20.700194 2026] [proxy:error] [pid 133043:tid 133176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.700251 2026] [proxy_http:error] [pid 133043:tid 133176] [client 140.245.59.145:51301] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:20.704480 2026] [core:error] [pid 133043:tid 133242] [client 20.215.191.139:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:20.704503 2026] [core:error] [pid 133043:tid 133242] [client 20.215.191.139:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:20.832184 2026] [fcgid:warn] [pid 133043:tid 133294] (70014)End of file found: [client 185.177.72.68:65510] mod_fcgid: can't get data from http client
[Thu Jul 30 15:10:20.892771 2026] [proxy:error] [pid 133043:tid 133241] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.892858 2026] [proxy_http:error] [pid 133043:tid 133241] [client 140.245.59.145:51372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:20.893854 2026] [proxy:error] [pid 133043:tid 133241] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:20.893912 2026] [proxy_http:error] [pid 133043:tid 133241] [client 140.245.59.145:51372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.081794 2026] [proxy:error] [pid 133043:tid 133224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.081876 2026] [proxy_http:error] [pid 133043:tid 133224] [client 140.245.59.145:51453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.082451 2026] [proxy:error] [pid 133043:tid 133224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.082496 2026] [proxy_http:error] [pid 133043:tid 133224] [client 140.245.59.145:51453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.086669 2026] [fcgid:warn] [pid 133043:tid 133252] (70014)End of file found: [client 185.177.72.68:65522] mod_fcgid: can't get data from http client
[Thu Jul 30 15:10:21.189649 2026] [security2:error] [pid 133043:tid 133201] [client 20.171.55.167:3616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/xlt.php"] [unique_id "amuvrbdt6aqtVvMundN0tgAAAKE"]
[Thu Jul 30 15:10:21.277843 2026] [proxy:error] [pid 133043:tid 133293] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.277924 2026] [proxy_http:error] [pid 133043:tid 133293] [client 140.245.59.145:51532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.278504 2026] [proxy:error] [pid 133043:tid 133293] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.278550 2026] [proxy_http:error] [pid 133043:tid 133293] [client 140.245.59.145:51532] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.341100 2026] [fcgid:warn] [pid 133043:tid 133268] (70014)End of file found: [client 185.177.72.68:65532] mod_fcgid: can't get data from http client
[Thu Jul 30 15:10:21.467195 2026] [proxy:error] [pid 133043:tid 133198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.467269 2026] [proxy_http:error] [pid 133043:tid 133198] [client 140.245.59.145:51612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.467931 2026] [proxy:error] [pid 133043:tid 133198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.467990 2026] [proxy_http:error] [pid 133043:tid 133198] [client 140.245.59.145:51612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.659230 2026] [proxy:error] [pid 133043:tid 133297] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.659311 2026] [proxy_http:error] [pid 133043:tid 133297] [client 140.245.59.145:51707] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.659868 2026] [proxy:error] [pid 133043:tid 133297] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.659910 2026] [proxy_http:error] [pid 133043:tid 133297] [client 140.245.59.145:51707] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.671068 2026] [security2:error] [pid 133043:tid 133226] [client 20.215.191.139:42963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuvrbdt6aqtVvMundN0yQAAALo"]
[Thu Jul 30 15:10:21.787412 2026] [security2:error] [pid 133043:tid 133281] [client 4.225.203.146:62804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/mah.php"] [unique_id "amuvrbdt6aqtVvMundN0zQAAAPE"]
[Thu Jul 30 15:10:21.848602 2026] [proxy:error] [pid 133043:tid 133261] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.848692 2026] [proxy_http:error] [pid 133043:tid 133261] [client 140.245.59.145:51799] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:21.849521 2026] [proxy:error] [pid 133043:tid 133261] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:21.849575 2026] [proxy_http:error] [pid 133043:tid 133261] [client 140.245.59.145:51799] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.040579 2026] [proxy:error] [pid 133043:tid 133286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.040664 2026] [proxy_http:error] [pid 133043:tid 133286] [client 140.245.59.145:51870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.041552 2026] [proxy:error] [pid 133043:tid 133286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.041606 2026] [proxy_http:error] [pid 133043:tid 133286] [client 140.245.59.145:51870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.068041 2026] [security2:error] [pid 133043:tid 133251] [client 20.171.55.167:3354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/yanznopat.php"] [unique_id "amuvrrdt6aqtVvMundN04QAAANM"]
[Thu Jul 30 15:10:22.257206 2026] [security2:error] [pid 133043:tid 133266] [client 185.177.72.68:1036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/en.orig"] [unique_id "amuvrrdt6aqtVvMundN05QAAAOI"]
[Thu Jul 30 15:10:22.261597 2026] [proxy:error] [pid 133043:tid 133250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.261689 2026] [proxy_http:error] [pid 133043:tid 133250] [client 140.245.59.145:51938] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.262555 2026] [proxy:error] [pid 133043:tid 133250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.262617 2026] [proxy_http:error] [pid 133043:tid 133250] [client 140.245.59.145:51938] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.379571 2026] [security2:error] [pid 133043:tid 133274] [client 4.225.203.146:46318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuvrrdt6aqtVvMundN06wAAAOo"]
[Thu Jul 30 15:10:22.453558 2026] [proxy:error] [pid 133043:tid 133254] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.453632 2026] [proxy_http:error] [pid 133043:tid 133254] [client 140.245.59.145:52025] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.454197 2026] [proxy:error] [pid 133043:tid 133254] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.454243 2026] [proxy_http:error] [pid 133043:tid 133254] [client 140.245.59.145:52025] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.642687 2026] [proxy:error] [pid 133043:tid 133268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.642773 2026] [proxy_http:error] [pid 133043:tid 133268] [client 140.245.59.145:52091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.643348 2026] [proxy:error] [pid 133043:tid 133268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.643394 2026] [proxy_http:error] [pid 133043:tid 133268] [client 140.245.59.145:52091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.833045 2026] [proxy:error] [pid 133043:tid 133177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.833116 2026] [proxy_http:error] [pid 133043:tid 133177] [client 140.245.59.145:52163] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.833675 2026] [proxy:error] [pid 133043:tid 133177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:22.833717 2026] [proxy_http:error] [pid 133043:tid 133177] [client 140.245.59.145:52163] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:22.854151 2026] [security2:error] [pid 133043:tid 133270] [client 20.171.55.167:3382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/zgdsfage/rk3.php"] [unique_id "amuvrrdt6aqtVvMundN1BQAAAOY"]
[Thu Jul 30 15:10:22.875019 2026] [security2:error] [pid 133043:tid 133257] [client 74.7.175.157:52598] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.mxv.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuvrrdt6aqtVvMundN1BgAAANk"]
[Thu Jul 30 15:10:23.027262 2026] [security2:error] [pid 133043:tid 133272] [client 140.245.59.145:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.59.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qnj.gzj.temporary.site"] [uri "/wp-content/plugins/hello.php"] [unique_id "amuvr7dt6aqtVvMundN1EAAAAOg"]
[Thu Jul 30 15:10:23.177062 2026] [security2:error] [pid 133043:tid 133193] [client 185.177.72.68:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/o.php"] [unique_id "amuvr7dt6aqtVvMundN1GwAAAJk"]
[Thu Jul 30 15:10:23.216789 2026] [proxy:error] [pid 133043:tid 133200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.216865 2026] [proxy_http:error] [pid 133043:tid 133200] [client 140.245.59.145:52319] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:23.217452 2026] [proxy:error] [pid 133043:tid 133200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.217499 2026] [proxy_http:error] [pid 133043:tid 133200] [client 140.245.59.145:52319] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:23.266868 2026] [security2:error] [pid 133043:tid 133194] [client 4.225.203.146:47337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/atomlib.php"] [unique_id "amuvr7dt6aqtVvMundN1HQAAAJo"]
[Thu Jul 30 15:10:23.406292 2026] [proxy:error] [pid 133043:tid 133258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.406356 2026] [proxy_http:error] [pid 133043:tid 133258] [client 140.245.59.145:52409] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:23.406931 2026] [proxy:error] [pid 133043:tid 133258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.406973 2026] [proxy_http:error] [pid 133043:tid 133258] [client 140.245.59.145:52409] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:23.428423 2026] [security2:error] [pid 133043:tid 133263] [client 185.177.72.68:1046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/o.php%2f"] [unique_id "amuvr7dt6aqtVvMundN1JAAAAN8"]
[Thu Jul 30 15:10:23.436663 2026] [core:notice] [pid 133043:tid 133166] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:23.438907 2026] [security2:error] [pid 133043:tid 133262] [client 74.7.175.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "teknomalay.com"] [uri "/category/tutorial/"] [unique_id "amuvr7dt6aqtVvMundN1JQAA3no"], referer: https://aleorestaurant.com/robots.txt
[Thu Jul 30 15:10:23.605275 2026] [proxy:error] [pid 133043:tid 133176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.605358 2026] [proxy_http:error] [pid 133043:tid 133176] [client 140.245.59.145:52482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:23.606154 2026] [proxy:error] [pid 133043:tid 133176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.606206 2026] [proxy_http:error] [pid 133043:tid 133176] [client 140.245.59.145:52482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:23.675742 2026] [core:notice] [pid 133043:tid 133253] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:23.679082 2026] [security2:error] [pid 133043:tid 133284] [client 185.177.72.68:1058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/o.php..."] [unique_id "amuvr7dt6aqtVvMundN1MQAAAPQ"]
[Thu Jul 30 15:10:23.801106 2026] [proxy:error] [pid 133043:tid 133216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.801204 2026] [proxy_http:error] [pid 133043:tid 133216] [client 140.245.59.145:52579] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:23.802004 2026] [proxy:error] [pid 133043:tid 133216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.802059 2026] [proxy_http:error] [pid 133043:tid 133216] [client 140.245.59.145:52579] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:23.834791 2026] [core:error] [pid 133043:tid 133046] [remote 216.73.216.186:42987] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:23.834814 2026] [core:error] [pid 133043:tid 133046] [remote 216.73.216.186:42987] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:23.930690 2026] [security2:error] [pid 133043:tid 133174] [client 185.177.72.68:1074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/o.php.swp"] [unique_id "amuvr7dt6aqtVvMundN1PAAAAIY"]
[Thu Jul 30 15:10:23.989888 2026] [proxy:error] [pid 133043:tid 133186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.989951 2026] [proxy_http:error] [pid 133043:tid 133186] [client 140.245.59.145:52654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:23.990532 2026] [proxy:error] [pid 133043:tid 133186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:23.990578 2026] [proxy_http:error] [pid 133043:tid 133186] [client 140.245.59.145:52654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.178339 2026] [proxy:error] [pid 133043:tid 133270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.178425 2026] [proxy_http:error] [pid 133043:tid 133270] [client 140.245.59.145:52734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.178973 2026] [proxy:error] [pid 133043:tid 133270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.179031 2026] [proxy_http:error] [pid 133043:tid 133270] [client 140.245.59.145:52734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.191364 2026] [core:notice] [pid 133043:tid 133065] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:24.368292 2026] [proxy:error] [pid 133043:tid 133188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.368388 2026] [proxy_http:error] [pid 133043:tid 133188] [client 140.245.59.145:52806] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.369541 2026] [proxy:error] [pid 133043:tid 133188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.369589 2026] [proxy_http:error] [pid 133043:tid 133188] [client 140.245.59.145:52806] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.468462 2026] [security2:error] [pid 133043:tid 133204] [client 4.225.203.146:15947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/send.php"] [unique_id "amuvsLdt6aqtVvMundN1UQAAAKQ"]
[Thu Jul 30 15:10:24.567048 2026] [proxy:error] [pid 133043:tid 133275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.567121 2026] [proxy_http:error] [pid 133043:tid 133275] [client 140.245.59.145:52883] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.567719 2026] [proxy:error] [pid 133043:tid 133275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.567765 2026] [proxy_http:error] [pid 133043:tid 133275] [client 140.245.59.145:52883] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.682385 2026] [security2:error] [pid 133043:tid 133232] [client 74.7.175.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "teknomalay.com"] [uri "/index.html"] [unique_id "amuvsLdt6aqtVvMundN1RwAAwBU"], referer: https://teknomalay.com/category/tutorial/
[Thu Jul 30 15:10:24.725215 2026] [core:error] [pid 133043:tid 133236] [client 4.225.203.146:49784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:24.725241 2026] [core:error] [pid 133043:tid 133236] [client 4.225.203.146:49784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:24.761319 2026] [proxy:error] [pid 133043:tid 133218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.761403 2026] [proxy_http:error] [pid 133043:tid 133218] [client 140.245.59.145:52977] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.762252 2026] [proxy:error] [pid 133043:tid 133218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.762317 2026] [proxy_http:error] [pid 133043:tid 133218] [client 140.245.59.145:52977] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.952697 2026] [proxy:error] [pid 133043:tid 133298] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.952773 2026] [proxy_http:error] [pid 133043:tid 133298] [client 140.245.59.145:53058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:24.953342 2026] [proxy:error] [pid 133043:tid 133298] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:24.953388 2026] [proxy_http:error] [pid 133043:tid 133298] [client 140.245.59.145:53058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:25.140796 2026] [proxy:error] [pid 133043:tid 133178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:25.140874 2026] [proxy_http:error] [pid 133043:tid 133178] [client 140.245.59.145:53133] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:25.141451 2026] [proxy:error] [pid 133043:tid 133178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:25.141497 2026] [proxy_http:error] [pid 133043:tid 133178] [client 140.245.59.145:53133] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:25.306526 2026] [security2:error] [pid 133043:tid 133187] [client 20.104.18.253:18954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-class-db.php"] [unique_id "amuvsbdt6aqtVvMundN1ggAAAJM"]
[Thu Jul 30 15:10:25.826314 2026] [security2:error] [pid 133043:tid 133174] [client 4.225.203.146:26805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuvsbdt6aqtVvMundN1lQAAAIY"]
[Thu Jul 30 15:10:25.978379 2026] [security2:error] [pid 133043:tid 133188] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/app.swp"] [unique_id "amuvsbdt6aqtVvMundN1nAAAAJQ"]
[Thu Jul 30 15:10:26.045987 2026] [security2:error] [pid 133043:tid 133270] [client 20.104.18.253:18806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-class.php"] [unique_id "amuvsrdt6aqtVvMundN1oQAAAOY"]
[Thu Jul 30 15:10:26.138794 2026] [security2:error] [pid 133043:tid 133197] [client 20.215.191.139:35402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuvsrdt6aqtVvMundN1qAAAAJ0"]
[Thu Jul 30 15:10:26.447951 2026] [core:error] [pid 133043:tid 133208] [client 4.225.203.146:62361] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:26.447985 2026] [core:error] [pid 133043:tid 133208] [client 4.225.203.146:62361] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:26.660788 2026] [security2:error] [pid 133043:tid 133284] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data ".htpasswd"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.terraform.htpasswd"] [unique_id "amuvsrdt6aqtVvMundN1vgAAAPQ"]
[Thu Jul 30 15:10:26.792575 2026] [security2:error] [pid 133043:tid 133235] [client 20.104.18.253:18781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-classic/inc/index.php"] [unique_id "amuvsrdt6aqtVvMundN1wQAAAMM"]
[Thu Jul 30 15:10:26.852699 2026] [security2:error] [pid 133043:tid 133176] [client 20.215.191.139:39009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuvsrdt6aqtVvMundN1ygAAAIg"]
[Thu Jul 30 15:10:27.071754 2026] [security2:error] [pid 133043:tid 133271] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/log.txt~"] [unique_id "amuvs7dt6aqtVvMundN10gAAAOc"]
[Thu Jul 30 15:10:27.203298 2026] [security2:error] [pid 133043:tid 133280] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/log.txt.bak"] [unique_id "amuvs7dt6aqtVvMundN11gAAAPA"]
[Thu Jul 30 15:10:27.390007 2026] [security2:error] [pid 133043:tid 133075] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvs7dt6aqtVvMundN13QAA5B8"]
[Thu Jul 30 15:10:27.390165 2026] [security2:error] [pid 133043:tid 133268] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvs7dt6aqtVvMundN13QAA5B8"]
[Thu Jul 30 15:10:27.457869 2026] [security2:error] [pid 133043:tid 133285] [client 20.104.18.253:18770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-commentin.php"] [unique_id "amuvs7dt6aqtVvMundN13gAAAPU"]
[Thu Jul 30 15:10:27.478192 2026] [security2:error] [pid 133043:tid 133221] [client 172.237.109.114:45770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvsrdt6aqtVvMundN1zwAAALU"]
[Thu Jul 30 15:10:28.174304 2026] [security2:error] [pid 133043:tid 133218] [client 20.104.18.253:18773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-comments-pos.php"] [unique_id "amuvtLdt6aqtVvMundN1_wAAALI"]
[Thu Jul 30 15:10:28.616734 2026] [security2:error] [pid 133043:tid 133085] [remote 216.73.216.51:53137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuvtLdt6aqtVvMundN2FwAArCk"]
[Thu Jul 30 15:10:28.617042 2026] [security2:error] [pid 133043:tid 133293] [client 20.215.191.139:39035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuvtLdt6aqtVvMundN2GAAAAP0"]
[Thu Jul 30 15:10:28.769225 2026] [core:notice] [pid 133043:tid 133201] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:28.893459 2026] [security2:error] [pid 133043:tid 133299] [client 20.104.18.253:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-comments-post.php"] [unique_id "amuvtLdt6aqtVvMundN2JwAAAQM"]
[Thu Jul 30 15:10:29.009570 2026] [security2:error] [pid 133043:tid 133269] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/nodeapi%00"] [unique_id "amuvtbdt6aqtVvMundN2KAAAAOU"]
[Thu Jul 30 15:10:29.142812 2026] [security2:error] [pid 133043:tid 133258] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvtbdt6aqtVvMundN2LAAAANo"]
[Thu Jul 30 15:10:29.276059 2026] [security2:error] [pid 133043:tid 133245] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvtbdt6aqtVvMundN2MQAAAM0"]
[Thu Jul 30 15:10:29.408959 2026] [security2:error] [pid 133043:tid 133183] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvtbdt6aqtVvMundN2NQAAAI8"]
[Thu Jul 30 15:10:29.454505 2026] [security2:error] [pid 133043:tid 133202] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvtLdt6aqtVvMundN2IwAAoiM"]
[Thu Jul 30 15:10:29.541572 2026] [security2:error] [pid 133043:tid 133218] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/.env"] [unique_id "amuvtbdt6aqtVvMundN2NgAAALI"]
[Thu Jul 30 15:10:29.848070 2026] [security2:error] [pid 133043:tid 133289] [client 20.104.18.253:18539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-comments.php"] [unique_id "amuvtbdt6aqtVvMundN2NwAAAPk"]
[Thu Jul 30 15:10:29.899710 2026] [security2:error] [pid 133043:tid 133238] [client 4.225.203.146:28986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuvtbdt6aqtVvMundN2RwAAAMY"]
[Thu Jul 30 15:10:29.922827 2026] [core:notice] [pid 133043:tid 133112] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:30.425794 2026] [security2:error] [pid 133043:tid 133298] [client 20.215.191.139:35405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuvtrdt6aqtVvMundN2XQAAAQI"]
[Thu Jul 30 15:10:30.570124 2026] [security2:error] [pid 133043:tid 133227] [client 20.104.18.253:18764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-conctent.php"] [unique_id "amuvtrdt6aqtVvMundN2YgAAALs"]
[Thu Jul 30 15:10:30.843036 2026] [autoindex:error] [pid 133043:tid 133255] [client 4.225.203.146:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_c89ec4bd/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:10:30.993662 2026] [core:error] [pid 133043:tid 133197] [client 4.225.203.146:39280] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:30.993686 2026] [core:error] [pid 133043:tid 133197] [client 4.225.203.146:39280] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:30.996490 2026] [security2:error] [pid 133043:tid 133236] [client 4.225.203.146:49696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/about.php"] [unique_id "amuvtrdt6aqtVvMundN2eAAAAMQ"]
[Thu Jul 30 15:10:31.192938 2026] [security2:error] [pid 133043:tid 133292] [client 20.104.18.253:18514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-config.php"] [unique_id "amuvt7dt6aqtVvMundN2fwAAAPw"]
[Thu Jul 30 15:10:31.813161 2026] [security2:error] [pid 133043:tid 133191] [client 20.104.18.253:18540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-configer.php"] [unique_id "amuvt7dt6aqtVvMundN2mAAAAJc"]
[Thu Jul 30 15:10:32.305817 2026] [security2:error] [pid 133043:tid 133209] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "abs-sa.net"] [uri "/projects.bak"] [unique_id "amuvuLdt6aqtVvMundN2rQAAAKk"]
[Thu Jul 30 15:10:32.348354 2026] [core:error] [pid 133043:tid 133281] [client 4.225.203.146:39260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:32.348386 2026] [core:error] [pid 133043:tid 133281] [client 4.225.203.146:39260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:32.356287 2026] [security2:error] [pid 133043:tid 133174] [client 20.215.191.139:35431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuvuLdt6aqtVvMundN2sAAAAIY"]
[Thu Jul 30 15:10:32.426406 2026] [security2:error] [pid 133043:tid 133227] [client 20.104.18.253:18758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-configs.php"] [unique_id "amuvuLdt6aqtVvMundN2sQAAALs"]
[Thu Jul 30 15:10:32.436704 2026] [security2:error] [pid 133043:tid 133199] [client 185.177.72.68:44154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "abs-sa.net"] [uri "/wp-config.php.backup"] [unique_id "amuvuLdt6aqtVvMundN2sgAAAJ8"]
[Thu Jul 30 15:10:32.705570 2026] [security2:error] [pid 133043:tid 133197] [client 185.177.72.68:44158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "abs-sa.net"] [uri "/wp-config.php.backup%253e"] [unique_id "amuvuLdt6aqtVvMundN2uQAAAJ0"]
[Thu Jul 30 15:10:32.939578 2026] [security2:error] [pid 133043:tid 133236] [client 20.215.191.139:18180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuvuLdt6aqtVvMundN2vgAAAMQ"]
[Thu Jul 30 15:10:32.962739 2026] [security2:error] [pid 133043:tid 133202] [client 185.177.72.68:44174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "abs-sa.net"] [uri "/wp-config.php.backup%7c"] [unique_id "amuvuLdt6aqtVvMundN2vwAAAKI"]
[Thu Jul 30 15:10:33.051667 2026] [security2:error] [pid 133043:tid 133179] [client 20.104.18.253:18538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-confiq.php"] [unique_id "amuvubdt6aqtVvMundN2xAAAAIs"]
[Thu Jul 30 15:10:33.218460 2026] [security2:error] [pid 133043:tid 133176] [client 185.177.72.68:44180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "abs-sa.net"] [uri "/wp-config.php.backup.zshrc"] [unique_id "amuvubdt6aqtVvMundN2yQAAAIg"]
[Thu Jul 30 15:10:33.523848 2026] [security2:error] [pid 133043:tid 133211] [client 20.215.191.139:39699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuvubdt6aqtVvMundN20QAAAKs"]
[Thu Jul 30 15:10:33.651576 2026] [security2:error] [pid 133043:tid 133224] [client 20.104.18.253:18535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-confirm.php"] [unique_id "amuvubdt6aqtVvMundN23gAAALg"]
[Thu Jul 30 15:10:34.286529 2026] [security2:error] [pid 133043:tid 133295] [client 20.104.18.253:18498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-conflg.php"] [unique_id "amuvurdt6aqtVvMundN2-AAAAP8"]
[Thu Jul 30 15:10:34.335212 2026] [security2:error] [pid 133043:tid 133200] [client 20.215.191.139:18237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuvurdt6aqtVvMundN2-QAAAKA"]
[Thu Jul 30 15:10:34.900734 2026] [security2:error] [pid 133043:tid 133207] [client 20.104.18.253:18789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-conflg.php/wp-content/plugins/google-seo-rank/wp-configs.php"] [unique_id "amuvurdt6aqtVvMundN3EQAAAKc"]
[Thu Jul 30 15:10:34.975373 2026] [security2:error] [pid 133043:tid 133294] [client 20.215.191.139:42969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/bek.php"] [unique_id "amuvurdt6aqtVvMundN3FgAAAP4"]
[Thu Jul 30 15:10:35.464999 2026] [security2:error] [pid 133043:tid 133263] [client 4.225.203.146:15936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/options.php"] [unique_id "amuvu7dt6aqtVvMundN3LQAAAN8"]
[Thu Jul 30 15:10:35.551129 2026] [security2:error] [pid 133043:tid 133191] [client 20.104.18.253:18533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-consar.php"] [unique_id "amuvu7dt6aqtVvMundN3LgAAAJc"]
[Thu Jul 30 15:10:35.697380 2026] [core:notice] [pid 133043:tid 133219] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:36.179068 2026] [security2:error] [pid 133043:tid 133190] [client 20.104.18.253:18753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-content.php"] [unique_id "amuvvLdt6aqtVvMundN3SgAAAJY"]
[Thu Jul 30 15:10:36.306108 2026] [core:notice] [pid 133043:tid 133245] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:36.795312 2026] [security2:error] [pid 133043:tid 133176] [client 20.104.18.253:18956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-content.php.php"] [unique_id "amuvvLdt6aqtVvMundN3ZwAAAIg"]
[Thu Jul 30 15:10:37.322125 2026] [core:error] [pid 133043:tid 133265] [client 4.225.203.146:47952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:37.322148 2026] [core:error] [pid 133043:tid 133265] [client 4.225.203.146:47952] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:37.405600 2026] [security2:error] [pid 133043:tid 133204] [client 20.104.18.253:18520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-content/plugins/watch/bop.php"] [unique_id "amuvvbdt6aqtVvMundN3gwAAAKQ"]
[Thu Jul 30 15:10:38.069093 2026] [security2:error] [pid 133043:tid 133268] [client 4.225.203.146:17102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuvvrdt6aqtVvMundN3mQAAAOQ"]
[Thu Jul 30 15:10:38.217886 2026] [security2:error] [pid 133043:tid 133050] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvvbdt6aqtVvMundN3kgAAqQY"]
[Thu Jul 30 15:10:38.218149 2026] [security2:error] [pid 133043:tid 133209] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvvbdt6aqtVvMundN3kgAAqQY"]
[Thu Jul 30 15:10:38.369322 2026] [security2:error] [pid 133043:tid 133255] [client 4.225.203.146:16223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/inputs.php"] [unique_id "amuvvrdt6aqtVvMundN3oQAAANc"]
[Thu Jul 30 15:10:38.499447 2026] [security2:error] [pid 133043:tid 133170] [remote 47.128.96.163:10658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/3354"] [unique_id "amuvvrdt6aqtVvMundN3mgAAw34"]
[Thu Jul 30 15:10:38.570456 2026] [core:notice] [pid 133043:tid 133046] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:38.575229 2026] [security2:error] [pid 133043:tid 133176] [client 47.128.96.163:10658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/3354"] [unique_id "amuvvrdt6aqtVvMundN3pgAAiAI"], referer: https://ejournalugj.com/index.php/jibm/article/view/3354?articlesBySimilarityPage=2
[Thu Jul 30 15:10:38.670303 2026] [security2:error] [pid 133043:tid 133178] [client 20.104.18.253:18550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-content/uploads/json.php"] [unique_id "amuvvrdt6aqtVvMundN3qAAAAIo"]
[Thu Jul 30 15:10:38.697379 2026] [security2:error] [pid 133043:tid 133189] [client 20.215.191.139:35415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuvvrdt6aqtVvMundN3qQAAAJU"]
[Thu Jul 30 15:10:38.734183 2026] [core:notice] [pid 133043:tid 133052] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:38.818667 2026] [core:notice] [pid 133043:tid 133058] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:38.830313 2026] [core:notice] [pid 133043:tid 133211] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:38.881223 2026] [core:notice] [pid 133043:tid 133057] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:39.151763 2026] [core:notice] [pid 133043:tid 133240] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:39.331462 2026] [security2:error] [pid 133043:tid 133263] [client 20.104.18.253:18542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-corn-sample.php"] [unique_id "amuvv7dt6aqtVvMundN3vQAAAN8"]
[Thu Jul 30 15:10:39.389599 2026] [core:notice] [pid 133043:tid 133237] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:39.392759 2026] [core:notice] [pid 133043:tid 133276] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:39.559704 2026] [security2:error] [pid 133043:tid 133297] [client 20.215.191.139:18195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/class.api.php"] [unique_id "amuvv7dt6aqtVvMundN3yAAAAQE"]
[Thu Jul 30 15:10:39.927143 2026] [security2:error] [pid 133043:tid 133281] [client 4.225.203.146:31768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/wp-file.php"] [unique_id "amuvv7dt6aqtVvMundN30QAAAPE"]
[Thu Jul 30 15:10:40.009255 2026] [security2:error] [pid 133043:tid 133232] [client 20.104.18.253:18501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-crom.php"] [unique_id "amuvwLdt6aqtVvMundN31QAAAMA"]
[Thu Jul 30 15:10:40.651301 2026] [security2:error] [pid 133043:tid 133210] [client 20.104.18.253:18532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-cron.php"] [unique_id "amuvwLdt6aqtVvMundN36QAAAKo"]
[Thu Jul 30 15:10:40.695471 2026] [core:notice] [pid 133043:tid 133176] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:40.725669 2026] [security2:error] [pid 133043:tid 133190] [client 172.237.109.114:52212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvwLdt6aqtVvMundN32QAAAJY"]
[Thu Jul 30 15:10:41.342038 2026] [security2:error] [pid 133043:tid 133229] [client 20.104.18.253:18782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-css.php"] [unique_id "amuvwbdt6aqtVvMundN3-gAAAL0"]
[Thu Jul 30 15:10:41.350324 2026] [security2:error] [pid 133043:tid 133201] [client 20.215.191.139:37429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/cong.php"] [unique_id "amuvwbdt6aqtVvMundN3-wAAAKE"]
[Thu Jul 30 15:10:41.414266 2026] [security2:error] [pid 133043:tid 133081] [remote 74.7.227.39:37438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuvwbdt6aqtVvMundN3_QAArCU"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/woozone/aa-framework
[Thu Jul 30 15:10:41.478331 2026] [security2:error] [pid 133043:tid 133294] [client 172.237.109.114:10798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvwLdt6aqtVvMundN38AAAAP4"]
[Thu Jul 30 15:10:41.558540 2026] [autoindex:error] [pid 133043:tid 133077] [remote 103.151.125.97:64094] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:10:41.562779 2026] [security2:error] [pid 133043:tid 133095] [remote 57.141.0.4:54160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amuvwbdt6aqtVvMundN4BgAA3zM"]
[Thu Jul 30 15:10:41.930744 2026] [security2:error] [pid 133043:tid 133083] [remote 57.141.0.59:54648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amuvwbdt6aqtVvMundN4EQAA_yc"]
[Thu Jul 30 15:10:41.953240 2026] [security2:error] [pid 133043:tid 133268] [client 185.177.72.68:65452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuvwbdt6aqtVvMundN4EgAAAOQ"]
[Thu Jul 30 15:10:41.958305 2026] [security2:error] [pid 133043:tid 133199] [client 20.215.191.139:35801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/content.php"] [unique_id "amuvwbdt6aqtVvMundN4EwAAAJ8"]
[Thu Jul 30 15:10:41.973590 2026] [security2:error] [pid 133043:tid 133193] [client 20.104.18.253:18530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-daft/miin.php"] [unique_id "amuvwbdt6aqtVvMundN4FAAAAJk"]
[Thu Jul 30 15:10:42.006081 2026] [core:notice] [pid 133043:tid 133087] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:42.142381 2026] [security2:error] [pid 133043:tid 133216] [client 37.77.56.246:40422] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuvwrdt6aqtVvMundN4HQAAALA"]
[Thu Jul 30 15:10:42.142504 2026] [security2:error] [pid 133043:tid 133216] [client 37.77.56.246:40422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuvwrdt6aqtVvMundN4HQAAALA"]
[Thu Jul 30 15:10:42.202876 2026] [security2:error] [pid 133043:tid 133206] [client 185.177.72.68:65456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amuvwrdt6aqtVvMundN4HgAAAKY"]
[Thu Jul 30 15:10:42.452733 2026] [security2:error] [pid 133043:tid 133239] [client 185.177.72.68:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuvwrdt6aqtVvMundN4IwAAAMc"]
[Thu Jul 30 15:10:42.479865 2026] [security2:error] [pid 133043:tid 133249] [client 4.225.203.146:28991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/index.php"] [unique_id "amuvwrdt6aqtVvMundN4JAAAANE"]
[Thu Jul 30 15:10:42.482342 2026] [security2:error] [pid 133043:tid 133198] [client 4.225.203.146:22698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/sid3.php"] [unique_id "amuvwrdt6aqtVvMundN4JQAAAJ4"]
[Thu Jul 30 15:10:42.619302 2026] [security2:error] [pid 133043:tid 133189] [client 20.104.18.253:18772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-damin.php"] [unique_id "amuvwrdt6aqtVvMundN4LAAAAJU"]
[Thu Jul 30 15:10:42.701769 2026] [security2:error] [pid 133043:tid 133291] [client 185.177.72.68:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuvwrdt6aqtVvMundN4LQAAAPs"]
[Thu Jul 30 15:10:42.786312 2026] [security2:error] [pid 133043:tid 133267] [client 20.215.191.139:39415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuvwrdt6aqtVvMundN4MAAAAOM"]
[Thu Jul 30 15:10:42.973202 2026] [security2:error] [pid 133043:tid 133220] [client 185.177.72.68:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuvwrdt6aqtVvMundN4MgAAALQ"]
[Thu Jul 30 15:10:43.105683 2026] [core:notice] [pid 133043:tid 133191] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:43.222796 2026] [security2:error] [pid 133043:tid 133229] [client 20.104.18.253:18521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-db-ajax-made/wp-ajax.php"] [unique_id "amuvw7dt6aqtVvMundN4OwAAAL0"]
[Thu Jul 30 15:10:43.225288 2026] [security2:error] [pid 133043:tid 133240] [client 185.177.72.68:65496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuvw7dt6aqtVvMundN4PAAAAMg"]
[Thu Jul 30 15:10:43.446383 2026] [security2:error] [pid 133043:tid 133280] [client 172.237.109.114:61420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvw7dt6aqtVvMundN4OgAAAPA"]
[Thu Jul 30 15:10:43.840706 2026] [security2:error] [pid 133043:tid 133278] [client 20.104.18.253:18513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-defaul.php"] [unique_id "amuvw7dt6aqtVvMundN4TwAAAO4"]
[Thu Jul 30 15:10:44.234519 2026] [security2:error] [pid 133043:tid 133275] [client 20.215.191.139:39365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/elp.php"] [unique_id "amuvxLdt6aqtVvMundN4XAAAAOs"]
[Thu Jul 30 15:10:44.414217 2026] [core:notice] [pid 133043:tid 133114] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:44.527215 2026] [security2:error] [pid 133043:tid 133190] [client 20.104.18.253:18776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-del.php"] [unique_id "amuvxLdt6aqtVvMundN4ZQAAAJY"]
[Thu Jul 30 15:10:44.883408 2026] [security2:error] [pid 133043:tid 133283] [client 20.215.191.139:39389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuvxLdt6aqtVvMundN4bwAAAPM"]
[Thu Jul 30 15:10:45.156219 2026] [security2:error] [pid 133043:tid 133234] [client 20.104.18.253:18756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-diambar/includes/loadme.php"] [unique_id "amuvxbdt6aqtVvMundN4cAAAAMI"]
[Thu Jul 30 15:10:45.825947 2026] [security2:error] [pid 133043:tid 133247] [client 185.191.171.2:15574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/24/bispo-de-guarabira-e-agredido-na-igreja-apos-pregacao-e-dioecese-emite-nota-de-repudio/"] [unique_id "amuvxbdt6aqtVvMundN4dAAAAM8"]
[Thu Jul 30 15:10:45.826107 2026] [security2:error] [pid 133043:tid 133247] [client 185.191.171.2:15574] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/24/bispo-de-guarabira-e-agredido-na-igreja-apos-pregacao-e-dioecese-emite-nota-de-repudio/"] [unique_id "amuvxbdt6aqtVvMundN4dAAAAM8"]
[Thu Jul 30 15:10:45.839835 2026] [security2:error] [pid 133043:tid 133300] [client 20.215.191.139:39369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuvxbdt6aqtVvMundN4dQAAAQQ"]
[Thu Jul 30 15:10:45.884896 2026] [security2:error] [pid 133043:tid 133272] [client 20.104.18.253:18466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.progroupdoha.com"] [uri "/wp-dnd.php"] [unique_id "amuvxbdt6aqtVvMundN4dwAAAOg"]
[Thu Jul 30 15:10:46.331748 2026] [autoindex:error] [pid 133043:tid 133256] [client 195.96.139.28:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://otbola.click
[Thu Jul 30 15:10:46.658370 2026] [security2:error] [pid 133043:tid 133260] [client 20.215.191.139:37397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuvxrdt6aqtVvMundN4iwAAANw"]
[Thu Jul 30 15:10:47.358342 2026] [core:notice] [pid 133043:tid 133129] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:10:47.522903 2026] [security2:error] [pid 133043:tid 133134] [remote 74.7.243.224:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuvx7dt6aqtVvMundN4ngAA0Fo"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:10:47.700364 2026] [security2:error] [pid 133043:tid 133289] [client 20.215.191.139:39390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuvx7dt6aqtVvMundN4pQAAAPk"]
[Thu Jul 30 15:10:47.943609 2026] [security2:error] [pid 133043:tid 133187] [client 2a03:2880:f800:33:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvx7dt6aqtVvMundN4mQAAk1E"]
[Thu Jul 30 15:10:48.267963 2026] [security2:error] [pid 133043:tid 133243] [client 45.91.22.56:54341] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "xwy.nyx.temporary.site"] [uri "/"] [unique_id "amuvyLdt6aqtVvMundN4sQAAAMs"]
[Thu Jul 30 15:10:48.324461 2026] [security2:error] [pid 133043:tid 133212] [client 45.91.22.60:36949] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.xwy.nyx.temporary.site"] [uri "/"] [unique_id "amuvyLdt6aqtVvMundN4tQAAAKw"]
[Thu Jul 30 15:10:48.372816 2026] [proxy:error] [pid 133043:tid 133272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:48.372870 2026] [proxy_http:error] [pid 133043:tid 133272] [client 45.91.22.93:28703] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:48.373458 2026] [proxy:error] [pid 133043:tid 133272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:48.373503 2026] [proxy_http:error] [pid 133043:tid 133272] [client 45.91.22.93:28703] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:48.377378 2026] [security2:error] [pid 133043:tid 133247] [client 45.91.22.87:62659] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "autodiscover.xwy.nyx.temporary.site"] [uri "/"] [unique_id "amuvyLdt6aqtVvMundN4uQAAAM8"]
[Thu Jul 30 15:10:48.400309 2026] [proxy:error] [pid 133043:tid 133229] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:48.400387 2026] [proxy_http:error] [pid 133043:tid 133229] [client 45.91.22.105:49293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:48.401297 2026] [proxy:error] [pid 133043:tid 133229] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:48.401357 2026] [proxy_http:error] [pid 133043:tid 133229] [client 45.91.22.105:49293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:48.409550 2026] [security2:error] [pid 133043:tid 133195] [client 4.225.203.146:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuvyLdt6aqtVvMundN4vAAAAJs"]
[Thu Jul 30 15:10:48.448999 2026] [security2:error] [pid 133043:tid 133267] [client 20.215.191.139:37407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuvyLdt6aqtVvMundN4vQAAAOM"]
[Thu Jul 30 15:10:48.522582 2026] [security2:error] [pid 133043:tid 133142] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvyLdt6aqtVvMundN4wQAAuWI"]
[Thu Jul 30 15:10:48.522766 2026] [security2:error] [pid 133043:tid 133225] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuvyLdt6aqtVvMundN4wQAAuWI"]
[Thu Jul 30 15:10:48.930784 2026] [security2:error] [pid 133043:tid 133193] [client 62.113.113.43:58412] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "urwru.club.emmelevate.club"] [uri "/"] [unique_id "amuvyLdt6aqtVvMundN4zAAAAJk"]
[Thu Jul 30 15:10:49.239203 2026] [security2:error] [pid 133043:tid 133179] [client 20.215.191.139:18307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuvybdt6aqtVvMundN41gAAAIs"]
[Thu Jul 30 15:10:49.395687 2026] [security2:error] [pid 133043:tid 133150] [remote 207.46.13.170:26184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/les-jeunes-en-action-pour-la-sauvegarde-de-lenvironnement/feed/article.php"] [unique_id "amuvybdt6aqtVvMundN42wAA0Go"]
[Thu Jul 30 15:10:49.678759 2026] [security2:error] [pid 133043:tid 133201] [client 139.28.219.70:58636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuvybdt6aqtVvMundN45gAAAKE"]
[Thu Jul 30 15:10:49.949237 2026] [security2:error] [pid 133043:tid 133243] [client 139.28.219.70:58652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "serverkr.com"] [uri "/xmlrpc.php"] [unique_id "amuvybdt6aqtVvMundN45wAAAMs"]
[Thu Jul 30 15:10:50.196057 2026] [security2:error] [pid 133043:tid 133239] [client 4.225.203.146:35386] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "svcambodia.com"] [uri "/wp-content/1.php"] [unique_id "amuvyrdt6aqtVvMundN49QAAAMc"]
[Thu Jul 30 15:10:50.196215 2026] [security2:error] [pid 133043:tid 133239] [client 4.225.203.146:35386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/1.php"] [unique_id "amuvyrdt6aqtVvMundN49QAAAMc"]
[Thu Jul 30 15:10:50.338287 2026] [security2:error] [pid 133043:tid 133267] [client 20.215.191.139:35765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuvyrdt6aqtVvMundN49wAAAOM"]
[Thu Jul 30 15:10:50.794696 2026] [security2:error] [pid 133043:tid 133245] [client 139.28.219.70:58658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuvyrdt6aqtVvMundN5CAAAAM0"]
[Thu Jul 30 15:10:50.811435 2026] [security2:error] [pid 133043:tid 133256] [client 114.122.107.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuvyrdt6aqtVvMundN4-QAA2Hs"], referer: https://flixon.net/free-movies/
[Thu Jul 30 15:10:51.065649 2026] [security2:error] [pid 133043:tid 133193] [client 139.28.219.70:33004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuvy7dt6aqtVvMundN5CwAAAJk"]
[Thu Jul 30 15:10:51.075907 2026] [security2:error] [pid 133043:tid 133199] [client 20.171.55.167:10573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/.well-knownwp.php"] [unique_id "amuvy7dt6aqtVvMundN5DQAAAJ8"]
[Thu Jul 30 15:10:51.106566 2026] [security2:error] [pid 133043:tid 133268] [client 4.225.203.146:20161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/plugin.php"] [unique_id "amuvy7dt6aqtVvMundN5DwAAAOQ"]
[Thu Jul 30 15:10:51.323370 2026] [security2:error] [pid 133043:tid 133205] [client 139.28.219.70:33018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuvy7dt6aqtVvMundN5GwAAAKU"]
[Thu Jul 30 15:10:51.588493 2026] [security2:error] [pid 133043:tid 133198] [client 139.28.219.70:33028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuvy7dt6aqtVvMundN5HQAAAJ4"]
[Thu Jul 30 15:10:51.889182 2026] [security2:error] [pid 133043:tid 133220] [client 139.28.219.70:33034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuvy7dt6aqtVvMundN5JwAAALQ"]
[Thu Jul 30 15:10:51.893326 2026] [security2:error] [pid 133043:tid 133275] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvy7dt6aqtVvMundN5GgAAAOs"]
[Thu Jul 30 15:10:51.941923 2026] [security2:error] [pid 133043:tid 133187] [client 20.171.55.167:10328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/1234.php"] [unique_id "amuvy7dt6aqtVvMundN5KAAAAJM"]
[Thu Jul 30 15:10:52.023019 2026] [security2:error] [pid 133043:tid 133277] [client 4.225.203.146:9413] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "svcambodia.com"] [uri "/1.php"] [unique_id "amuvzLdt6aqtVvMundN5KQAAAO0"]
[Thu Jul 30 15:10:52.023133 2026] [security2:error] [pid 133043:tid 133277] [client 4.225.203.146:9413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/1.php"] [unique_id "amuvzLdt6aqtVvMundN5KQAAAO0"]
[Thu Jul 30 15:10:52.147501 2026] [security2:error] [pid 133043:tid 133229] [client 139.28.219.70:33048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuvzLdt6aqtVvMundN5LwAAAL0"]
[Thu Jul 30 15:10:52.427268 2026] [security2:error] [pid 133043:tid 133224] [client 139.28.219.70:33062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuvzLdt6aqtVvMundN5NgAAALg"]
[Thu Jul 30 15:10:52.516000 2026] [security2:error] [pid 133043:tid 133212] [client 20.215.191.139:18357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuvzLdt6aqtVvMundN5OgAAAKw"]
[Thu Jul 30 15:10:52.636440 2026] [security2:error] [pid 133043:tid 133246] [client 172.237.109.114:27298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuvzLdt6aqtVvMundN5MQAAAM4"]
[Thu Jul 30 15:10:52.690927 2026] [security2:error] [pid 133043:tid 133238] [client 139.28.219.70:33072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuvzLdt6aqtVvMundN5QQAAAMY"]
[Thu Jul 30 15:10:52.831377 2026] [security2:error] [pid 133043:tid 133200] [client 20.171.55.167:10563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/2015/05/Marvins.php"] [unique_id "amuvzLdt6aqtVvMundN5RwAAAKA"]
[Thu Jul 30 15:10:52.969177 2026] [security2:error] [pid 133043:tid 133242] [client 139.28.219.70:33082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuvzLdt6aqtVvMundN5SAAAAMo"]
[Thu Jul 30 15:10:53.032488 2026] [security2:error] [pid 133043:tid 133225] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuvzLdt6aqtVvMundN5OQAAALk"]
[Thu Jul 30 15:10:53.233781 2026] [security2:error] [pid 133043:tid 133233] [client 139.28.219.70:33092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuvzbdt6aqtVvMundN5TAAAAME"]
[Thu Jul 30 15:10:53.268142 2026] [security2:error] [pid 133043:tid 133213] [client 20.215.191.139:17842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuvzbdt6aqtVvMundN5UAAAAK0"]
[Thu Jul 30 15:10:53.336773 2026] [security2:error] [pid 133043:tid 133295] [client 167.99.155.162:37922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuvy7dt6aqtVvMundN5FwAAAP8"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:10:53.496290 2026] [security2:error] [pid 133043:tid 133176] [client 139.28.219.70:33106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serverkr.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuvzbdt6aqtVvMundN5WAAAAIg"]
[Thu Jul 30 15:10:53.623316 2026] [security2:error] [pid 133043:tid 133221] [client 20.171.55.167:10337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/3.php"] [unique_id "amuvzbdt6aqtVvMundN5WQAAALU"]
[Thu Jul 30 15:10:53.963093 2026] [security2:error] [pid 133043:tid 133183] [client 20.215.191.139:35045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuvzbdt6aqtVvMundN5aAAAAI8"]
[Thu Jul 30 15:10:54.102872 2026] [security2:error] [pid 133043:tid 133193] [client 4.225.203.146:20165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/gg.php"] [unique_id "amuvzrdt6aqtVvMundN5agAAAJk"]
[Thu Jul 30 15:10:54.574107 2026] [security2:error] [pid 133043:tid 133299] [client 20.171.55.167:10571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/4x4.php"] [unique_id "amuvzrdt6aqtVvMundN5egAAAQM"]
[Thu Jul 30 15:10:54.615747 2026] [security2:error] [pid 133043:tid 133198] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuvzbdt6aqtVvMundN5aQAAniU"]
[Thu Jul 30 15:10:55.317656 2026] [security2:error] [pid 133043:tid 133241] [client 167.99.155.162:37936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuvzrdt6aqtVvMundN5gQAAAMk"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:10:55.582407 2026] [security2:error] [pid 133043:tid 133180] [client 20.171.55.167:10322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/8890.php"] [unique_id "amuvz7dt6aqtVvMundN5jgAAAIw"]
[Thu Jul 30 15:10:56.400476 2026] [security2:error] [pid 133043:tid 133192] [client 20.171.55.167:10572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/Cache/dropdown.php"] [unique_id "amuv0Ldt6aqtVvMundN5nwAAAJg"]
[Thu Jul 30 15:10:57.219247 2026] [security2:error] [pid 133043:tid 133229] [client 20.171.55.167:10345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/Diff/Engine/priv.php"] [unique_id "amuv0bdt6aqtVvMundN5rQAAAL0"]
[Thu Jul 30 15:10:57.308485 2026] [core:error] [pid 133043:tid 133195] [client 4.225.203.146:9463] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:57.308510 2026] [core:error] [pid 133043:tid 133195] [client 4.225.203.146:9463] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:10:57.406254 2026] [proxy:error] [pid 133043:tid 133100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:57.406309 2026] [proxy_http:error] [pid 133043:tid 133100] [remote 74.7.175.167:48146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:57.406879 2026] [proxy:error] [pid 133043:tid 133100] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:10:57.406922 2026] [proxy_http:error] [pid 133043:tid 133100] [remote 74.7.175.167:48146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:10:57.960740 2026] [security2:error] [pid 133043:tid 133191] [client 85.208.96.210:20912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/12/17/conta-de-luz-vai-subir-ate-36-com-heranca-e-aumento-de-custos/"] [unique_id "amuv0bdt6aqtVvMundN5wwAAAJc"]
[Thu Jul 30 15:10:57.960886 2026] [security2:error] [pid 133043:tid 133191] [client 85.208.96.210:20912] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/12/17/conta-de-luz-vai-subir-ate-36-com-heranca-e-aumento-de-custos/"] [unique_id "amuv0bdt6aqtVvMundN5wwAAAJc"]
[Thu Jul 30 15:10:58.138712 2026] [security2:error] [pid 133043:tid 133286] [client 20.171.55.167:10565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/FoxWSO-full.php"] [unique_id "amuv0rdt6aqtVvMundN5ygAAAPY"]
[Thu Jul 30 15:10:58.422643 2026] [security2:error] [pid 133043:tid 133237] [client 190.236.85.115:3246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuv0rdt6aqtVvMundN5ywAAAMU"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:10:58.581279 2026] [security2:error] [pid 133043:tid 133268] [client 4.225.203.146:46943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp.php"] [unique_id "amuv0rdt6aqtVvMundN51gAAAOQ"]
[Thu Jul 30 15:10:58.962408 2026] [security2:error] [pid 133043:tid 133252] [client 20.171.55.167:10363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/M1.php"] [unique_id "amuv0rdt6aqtVvMundN53wAAANQ"]
[Thu Jul 30 15:10:59.137596 2026] [security2:error] [pid 133043:tid 133114] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv07dt6aqtVvMundN55QAA1kY"]
[Thu Jul 30 15:10:59.137751 2026] [security2:error] [pid 133043:tid 133254] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv07dt6aqtVvMundN55QAA1kY"]
[Thu Jul 30 15:10:59.418176 2026] [security2:error] [pid 133043:tid 133227] [client 23.94.216.234:60244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "billsnap-fiyan-co.nxt.udi.temporary.site"] [uri "/"] [unique_id "amuv07dt6aqtVvMundN57gAAALs"]
[Thu Jul 30 15:10:59.775944 2026] [security2:error] [pid 133043:tid 133226] [client 20.171.55.167:10357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/RxR_euzcx.php"] [unique_id "amuv07dt6aqtVvMundN5-gAAALo"]
[Thu Jul 30 15:10:59.957250 2026] [security2:error] [pid 133043:tid 133217] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuv07dt6aqtVvMundN57AAAALE"]
[Thu Jul 30 15:11:00.687901 2026] [security2:error] [pid 133043:tid 133283] [client 172.237.109.114:45372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuv1Ldt6aqtVvMundN6BgAAAPM"]
[Thu Jul 30 15:11:00.747699 2026] [security2:error] [pid 133043:tid 133258] [client 20.171.55.167:10309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/Summer2010/-/gif.php"] [unique_id "amuv1Ldt6aqtVvMundN6EAAAANo"]
[Thu Jul 30 15:11:01.520950 2026] [security2:error] [pid 133043:tid 133287] [client 20.215.191.139:36314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuv1bdt6aqtVvMundN6GwAAAPc"]
[Thu Jul 30 15:11:01.571214 2026] [security2:error] [pid 133043:tid 133292] [client 4.225.203.146:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuv1bdt6aqtVvMundN6HwAAAPw"]
[Thu Jul 30 15:11:01.702525 2026] [security2:error] [pid 133043:tid 133215] [client 20.171.55.167:10353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/XxX.php"] [unique_id "amuv1bdt6aqtVvMundN6JAAAAK8"]
[Thu Jul 30 15:11:02.671467 2026] [security2:error] [pid 133043:tid 133196] [client 20.171.55.167:10566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/about.php"] [unique_id "amuv1rdt6aqtVvMundN6NgAAAJw"]
[Thu Jul 30 15:11:03.474967 2026] [security2:error] [pid 133043:tid 133256] [client 20.171.55.167:10336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/admin%201.php"] [unique_id "amuv17dt6aqtVvMundN6SQAAANg"]
[Thu Jul 30 15:11:04.229130 2026] [security2:error] [pid 133043:tid 133249] [client 74.7.228.50:43630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.mei.gzj.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuv2Ldt6aqtVvMundN6WwAAANE"]
[Thu Jul 30 15:11:04.372565 2026] [security2:error] [pid 133043:tid 133176] [client 20.171.55.167:10365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/administratoralfa.php"] [unique_id "amuv2Ldt6aqtVvMundN6YwAAAIg"]
[Thu Jul 30 15:11:04.863320 2026] [fcgid:warn] [pid 133043:tid 133269] (70014)End of file found: [client 143.198.88.13:54543] mod_fcgid: can't get data from http client
[Thu Jul 30 15:11:05.176104 2026] [security2:error] [pid 133043:tid 133173] [client 20.171.55.167:10313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/ajax-actions.php"] [unique_id "amuv2bdt6aqtVvMundN6cgAAAIU"]
[Thu Jul 30 15:11:05.208870 2026] [security2:error] [pid 133043:tid 133204] [client 188.217.59.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuv2bdt6aqtVvMundN6cQAAAKQ"], referer: https://cnpinyin.com
[Thu Jul 30 15:11:06.152277 2026] [security2:error] [pid 133043:tid 133191] [client 20.171.55.167:10560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/alfa1337.php"] [unique_id "amuv2rdt6aqtVvMundN6iwAAAJc"]
[Thu Jul 30 15:11:06.570964 2026] [core:notice] [pid 133043:tid 133197] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:07.124483 2026] [security2:error] [pid 133043:tid 133221] [client 20.171.55.167:10567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/alfav4-1.php"] [unique_id "amuv27dt6aqtVvMundN6tgAAALU"]
[Thu Jul 30 15:11:07.589017 2026] [security2:error] [pid 133043:tid 133176] [client 172.237.109.114:39130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuv27dt6aqtVvMundN6tQAAAIg"]
[Thu Jul 30 15:11:08.311431 2026] [security2:error] [pid 133043:tid 133247] [client 20.171.55.167:10561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/anons79.php"] [unique_id "amuv3Ldt6aqtVvMundN60QAAAM8"]
[Thu Jul 30 15:11:08.485102 2026] [core:notice] [pid 133043:tid 133095] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:08.489803 2026] [security2:error] [pid 133043:tid 133196] [client 188.239.9.183:57430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/5193/3808"] [unique_id "amuv3Ldt6aqtVvMundN60AAAnDM"]
[Thu Jul 30 15:11:08.685816 2026] [core:notice] [pid 133043:tid 133071] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:08.841309 2026] [security2:error] [pid 133043:tid 133193] [client 4.225.203.146:46934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/file.php"] [unique_id "amuv3Ldt6aqtVvMundN63gAAAJk"]
[Thu Jul 30 15:11:08.881802 2026] [security2:error] [pid 133043:tid 133259] [client 20.215.191.139:39943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuv3Ldt6aqtVvMundN63wAAANs"]
[Thu Jul 30 15:11:08.920599 2026] [core:notice] [pid 133043:tid 133083] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:08.922202 2026] [core:notice] [pid 133043:tid 133087] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:08.978629 2026] [core:notice] [pid 133043:tid 133082] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:09.111958 2026] [security2:error] [pid 133043:tid 133245] [client 20.171.55.167:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/applicationbypass.php"] [unique_id "amuv3bdt6aqtVvMundN67AAAAM0"]
[Thu Jul 30 15:11:09.470829 2026] [security2:error] [pid 133043:tid 133099] [remote 47.128.28.101:25966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/women-pjs-jacket-olive/"] [unique_id "amuv3bdt6aqtVvMundN69AAA_Dc"]
[Thu Jul 30 15:11:09.599029 2026] [security2:error] [pid 133043:tid 133206] [client 20.215.191.139:36288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuv3bdt6aqtVvMundN6-gAAAKY"]
[Thu Jul 30 15:11:09.719921 2026] [security2:error] [pid 133043:tid 133093] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv3bdt6aqtVvMundN6_AAAwjE"]
[Thu Jul 30 15:11:09.720187 2026] [security2:error] [pid 133043:tid 133234] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv3bdt6aqtVvMundN6_AAAwjE"]
[Thu Jul 30 15:11:10.071530 2026] [security2:error] [pid 133043:tid 133248] [client 20.171.55.167:10356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/asetalfa.php"] [unique_id "amuv3rdt6aqtVvMundN7AwAAANA"]
[Thu Jul 30 15:11:11.020231 2026] [security2:error] [pid 133043:tid 133184] [client 20.171.55.167:10327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/aua.php"] [unique_id "amuv37dt6aqtVvMundN7GAAAAJA"]
[Thu Jul 30 15:11:11.030311 2026] [security2:error] [pid 133043:tid 133208] [client 20.215.191.139:38414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuv37dt6aqtVvMundN7GQAAAKg"]
[Thu Jul 30 15:11:11.203668 2026] [security2:error] [pid 133043:tid 133203] [client 4.225.203.146:47956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuv37dt6aqtVvMundN7IAAAAKM"]
[Thu Jul 30 15:11:11.674384 2026] [security2:error] [pid 133043:tid 133210] [client 20.215.191.139:39938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuv37dt6aqtVvMundN7KAAAAKo"]
[Thu Jul 30 15:11:11.801609 2026] [security2:error] [pid 133043:tid 133205] [client 20.171.55.167:10623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/ayk.php"] [unique_id "amuv37dt6aqtVvMundN7LAAAAKU"]
[Thu Jul 30 15:11:12.410868 2026] [core:error] [pid 133043:tid 133218] [client 4.225.203.146:9447] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:12.410889 2026] [core:error] [pid 133043:tid 133218] [client 4.225.203.146:9447] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:12.638372 2026] [core:notice] [pid 133043:tid 133109] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:12.771558 2026] [security2:error] [pid 133043:tid 133240] [client 20.171.55.167:10343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/bb.php"] [unique_id "amuv4Ldt6aqtVvMundN7QQAAAMg"]
[Thu Jul 30 15:11:12.798703 2026] [security2:error] [pid 133043:tid 133275] [client 20.215.191.139:37487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuv4Ldt6aqtVvMundN7QgAAAOs"]
[Thu Jul 30 15:11:13.254608 2026] [security2:error] [pid 133043:tid 133212] [client 74.7.230.15:60320] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.yie.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuv4bdt6aqtVvMundN7SwAAAKw"]
[Thu Jul 30 15:11:13.625284 2026] [security2:error] [pid 133043:tid 133270] [client 20.171.55.167:10339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/bless.php"] [unique_id "amuv4bdt6aqtVvMundN7UQAAAOY"]
[Thu Jul 30 15:11:13.861689 2026] [security2:error] [pid 133043:tid 133174] [client 4.225.203.146:34166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuv4bdt6aqtVvMundN7XgAAAIY"]
[Thu Jul 30 15:11:14.044853 2026] [security2:error] [pid 133043:tid 133276] [client 20.215.191.139:39998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuv4rdt6aqtVvMundN7ZQAAAOw"]
[Thu Jul 30 15:11:14.467584 2026] [security2:error] [pid 133043:tid 133228] [client 172.237.109.114:35294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuv4bdt6aqtVvMundN7ZAAAALw"]
[Thu Jul 30 15:11:14.534834 2026] [security2:error] [pid 133043:tid 133282] [client 20.171.55.167:10350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/bootstrapbypass.php"] [unique_id "amuv4rdt6aqtVvMundN7cwAAAPI"]
[Thu Jul 30 15:11:15.225908 2026] [security2:error] [pid 133043:tid 133229] [client 185.200.117.131:53874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuv47dt6aqtVvMundN7nQAAAL0"]
[Thu Jul 30 15:11:15.226033 2026] [security2:error] [pid 133043:tid 133229] [client 185.200.117.131:53874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuv47dt6aqtVvMundN7nQAAAL0"]
[Thu Jul 30 15:11:15.362308 2026] [security2:error] [pid 133043:tid 133288] [client 20.171.55.167:10311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/bv3.php"] [unique_id "amuv47dt6aqtVvMundN7pAAAAPg"]
[Thu Jul 30 15:11:15.741775 2026] [core:error] [pid 133043:tid 133184] [client 52.167.144.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:15.741800 2026] [core:error] [pid 133043:tid 133184] [client 52.167.144.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:16.340480 2026] [security2:error] [pid 133043:tid 133258] [client 20.171.55.167:10308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/cachek.php"] [unique_id "amuv5Ldt6aqtVvMundN7xwAAANo"]
[Thu Jul 30 15:11:16.659251 2026] [core:error] [pid 133043:tid 133046] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/
[Thu Jul 30 15:11:16.659278 2026] [core:error] [pid 133043:tid 133046] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/
[Thu Jul 30 15:11:17.267244 2026] [security2:error] [pid 133043:tid 133272] [client 20.171.55.167:10575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/cc.php"] [unique_id "amuv5bdt6aqtVvMundN72gAAAOg"]
[Thu Jul 30 15:11:17.343666 2026] [security2:error] [pid 133043:tid 133181] [client 201.20.171.91:9390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.171.20.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ampcloudku.com"] [uri "/xmlrpc.php"] [unique_id "amuv5bdt6aqtVvMundN72QAAAI0"]
[Thu Jul 30 15:11:17.343902 2026] [security2:error] [pid 133043:tid 133181] [client 201.20.171.91:9390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ampcloudku.com"] [uri "/xmlrpc.php"] [unique_id "amuv5bdt6aqtVvMundN72QAAAI0"]
[Thu Jul 30 15:11:18.190433 2026] [security2:error] [pid 133043:tid 133188] [client 20.171.55.167:10352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/cgialfak.php"] [unique_id "amuv5rdt6aqtVvMundN78AAAAJQ"]
[Thu Jul 30 15:11:18.223744 2026] [core:error] [pid 133043:tid 133056] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/wp/
[Thu Jul 30 15:11:18.223764 2026] [core:error] [pid 133043:tid 133056] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/wp/
[Thu Jul 30 15:11:18.374386 2026] [security2:error] [pid 133043:tid 133288] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuv5bdt6aqtVvMundN75gAAAPg"]
[Thu Jul 30 15:11:18.608030 2026] [security2:error] [pid 133043:tid 133286] [client 4.225.203.146:23928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/index/function.php"] [unique_id "amuv5rdt6aqtVvMundN8BQAAAPY"]
[Thu Jul 30 15:11:18.819272 2026] [core:error] [pid 133043:tid 133064] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/wp/
[Thu Jul 30 15:11:18.819297 2026] [core:error] [pid 133043:tid 133064] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/wp/
[Thu Jul 30 15:11:18.950950 2026] [security2:error] [pid 133043:tid 133296] [client 20.171.55.167:10598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/class-ftp-pures.php"] [unique_id "amuv5rdt6aqtVvMundN8DAAAAQA"]
[Thu Jul 30 15:11:18.993264 2026] [security2:error] [pid 133043:tid 133287] [client 34.7.15.221:30270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.prod"] [unique_id "amuv5rdt6aqtVvMundN8EwAAAPc"]
[Thu Jul 30 15:11:18.994864 2026] [security2:error] [pid 133043:tid 133283] [client 34.7.15.221:30286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.backup"] [unique_id "amuv5rdt6aqtVvMundN8FAAAAPM"]
[Thu Jul 30 15:11:18.995099 2026] [security2:error] [pid 133043:tid 133266] [client 34.7.15.221:30282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.bak"] [unique_id "amuv5rdt6aqtVvMundN8FQAAAOI"]
[Thu Jul 30 15:11:18.998954 2026] [core:error] [pid 133043:tid 133205] [client 34.7.15.221:30314] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:18.998971 2026] [core:error] [pid 133043:tid 133205] [client 34.7.15.221:30314] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:18.999403 2026] [security2:error] [pid 133043:tid 133199] [client 34.7.15.221:30334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/app/.env"] [unique_id "amuv5rdt6aqtVvMundN8GgAAAJ8"]
[Thu Jul 30 15:11:18.999431 2026] [security2:error] [pid 133043:tid 133289] [client 34.7.15.221:30344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/api/.env"] [unique_id "amuv5rdt6aqtVvMundN8GwAAAPk"]
[Thu Jul 30 15:11:18.999613 2026] [security2:error] [pid 133043:tid 133230] [client 34.7.15.221:30514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.npmrc"] [unique_id "amuv5rdt6aqtVvMundN8HwAAAL4"]
[Thu Jul 30 15:11:19.000631 2026] [security2:error] [pid 133043:tid 133292] [client 34.7.15.221:30384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config/.env"] [unique_id "amuv5rdt6aqtVvMundN8HgAAAPw"]
[Thu Jul 30 15:11:19.001344 2026] [core:error] [pid 133043:tid 133182] [client 34.7.15.221:30458] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.001366 2026] [core:error] [pid 133043:tid 133182] [client 34.7.15.221:30458] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.006227 2026] [core:error] [pid 133043:tid 133248] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.006247 2026] [core:error] [pid 133043:tid 133248] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.008411 2026] [core:error] [pid 133043:tid 133299] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.008437 2026] [core:error] [pid 133043:tid 133299] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.009014 2026] [security2:error] [pid 133043:tid 133190] [client 34.7.15.221:30204] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env"] [unique_id "amuv57dt6aqtVvMundN8MAAAAJY"]
[Thu Jul 30 15:11:19.015766 2026] [core:error] [pid 133043:tid 133219] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.015787 2026] [core:error] [pid 133043:tid 133219] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.016294 2026] [security2:error] [pid 133043:tid 133218] [client 34.7.15.221:30352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/backend/.env"] [unique_id "amuv57dt6aqtVvMundN8OwAAALI"]
[Thu Jul 30 15:11:19.017555 2026] [security2:error] [pid 133043:tid 133271] [client 34.7.15.221:30302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.old"] [unique_id "amuv57dt6aqtVvMundN8PwAAAOc"]
[Thu Jul 30 15:11:19.017971 2026] [core:error] [pid 133043:tid 133263] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.018000 2026] [core:error] [pid 133043:tid 133263] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.018661 2026] [core:error] [pid 133043:tid 133242] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.018674 2026] [core:error] [pid 133043:tid 133242] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.018997 2026] [security2:error] [pid 133043:tid 133290] [client 34.7.15.221:30386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/laravel/.env"] [unique_id "amuv57dt6aqtVvMundN8RAAAAPo"]
[Thu Jul 30 15:11:19.019202 2026] [security2:error] [pid 133043:tid 133261] [client 34.7.15.221:30388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/docker/.env"] [unique_id "amuv57dt6aqtVvMundN8RwAAAN0"]
[Thu Jul 30 15:11:19.019294 2026] [security2:error] [pid 133043:tid 133269] [client 34.7.15.221:30498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.ssh/id_rsa"] [unique_id "amuv57dt6aqtVvMundN8RQAAAOU"]
[Thu Jul 30 15:11:19.019616 2026] [core:error] [pid 133043:tid 133244] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.019628 2026] [core:error] [pid 133043:tid 133244] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.019819 2026] [core:error] [pid 133043:tid 133298] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.019830 2026] [core:error] [pid 133043:tid 133298] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.019904 2026] [security2:error] [pid 133043:tid 133300] [client 34.7.15.221:30442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.gcloud/credentials"] [unique_id "amuv57dt6aqtVvMundN8SgAAAQQ"]
[Thu Jul 30 15:11:19.019968 2026] [security2:error] [pid 133043:tid 133300] [client 34.7.15.221:30442] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.gcloud/credentials"] [unique_id "amuv57dt6aqtVvMundN8SgAAAQQ"]
[Thu Jul 30 15:11:19.020098 2026] [core:error] [pid 133043:tid 133188] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.020112 2026] [core:error] [pid 133043:tid 133188] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.020488 2026] [core:error] [pid 133043:tid 133259] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.020506 2026] [core:error] [pid 133043:tid 133259] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.021636 2026] [core:error] [pid 133043:tid 133255] [client 34.7.15.221:30322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.021658 2026] [core:error] [pid 133043:tid 133255] [client 34.7.15.221:30322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.022170 2026] [core:error] [pid 133043:tid 133187] [client 34.7.15.221:30480] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.022187 2026] [core:error] [pid 133043:tid 133187] [client 34.7.15.221:30480] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.024488 2026] [core:error] [pid 133043:tid 133214] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.024501 2026] [core:error] [pid 133043:tid 133214] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.024879 2026] [core:error] [pid 133043:tid 133174] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.024892 2026] [core:error] [pid 133043:tid 133174] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.026099 2026] [core:error] [pid 133043:tid 133273] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.026113 2026] [core:error] [pid 133043:tid 133273] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.030352 2026] [core:error] [pid 133043:tid 133293] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.030367 2026] [core:error] [pid 133043:tid 133293] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.031477 2026] [core:error] [pid 133043:tid 133284] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.031493 2026] [core:error] [pid 133043:tid 133284] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.031618 2026] [security2:error] [pid 133043:tid 133284] [client 34.7.15.221:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/index.php"] [unique_id "amuv57dt6aqtVvMundN8UgAAAPQ"]
[Thu Jul 30 15:11:19.032094 2026] [security2:error] [pid 133043:tid 133203] [client 34.7.15.221:30430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.aws/credentials"] [unique_id "amuv57dt6aqtVvMundN8QgAAAKM"]
[Thu Jul 30 15:11:19.254607 2026] [core:error] [pid 133043:tid 133264] [client 4.225.203.146:9510] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.254632 2026] [core:error] [pid 133043:tid 133264] [client 4.225.203.146:9510] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.369371 2026] [core:error] [pid 133043:tid 133095] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/wordpress/
[Thu Jul 30 15:11:19.369395 2026] [core:error] [pid 133043:tid 133095] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/wordpress/
[Thu Jul 30 15:11:19.821539 2026] [security2:error] [pid 133043:tid 133061] [remote 72.167.132.114:34348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuv57dt6aqtVvMundN8YQAAsxE"]
[Thu Jul 30 15:11:19.821677 2026] [security2:error] [pid 133043:tid 133219] [client 72.167.132.114:34348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "themushroom.online"] [uri "/xmlrpc.php"] [unique_id "amuv57dt6aqtVvMundN8YQAAsxE"]
[Thu Jul 30 15:11:19.888767 2026] [security2:error] [pid 133043:tid 133288] [client 20.171.55.167:10325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/class-wp-filesystem-ftpsockets.php"] [unique_id "amuv57dt6aqtVvMundN8ZAAAAPg"]
[Thu Jul 30 15:11:19.911722 2026] [core:error] [pid 133043:tid 133260] [client 4.225.203.146:46953] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:19.911741 2026] [core:error] [pid 133043:tid 133260] [client 4.225.203.146:46953] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:20.196083 2026] [core:notice] [pid 133043:tid 133249] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:20.366570 2026] [security2:error] [pid 133043:tid 133088] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv6Ldt6aqtVvMundN8bAAAiyw"]
[Thu Jul 30 15:11:20.366706 2026] [security2:error] [pid 133043:tid 133179] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv6Ldt6aqtVvMundN8bAAAiyw"]
[Thu Jul 30 15:11:20.702000 2026] [core:error] [pid 133043:tid 133075] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/wordpress/
[Thu Jul 30 15:11:20.702022 2026] [core:error] [pid 133043:tid 133075] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/wordpress/
[Thu Jul 30 15:11:21.284692 2026] [security2:error] [pid 133043:tid 133224] [client 20.171.55.167:10307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/class-wp-session-href.php"] [unique_id "amuv6bdt6aqtVvMundN8gwAAALg"]
[Thu Jul 30 15:11:21.349106 2026] [core:error] [pid 133043:tid 133093] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/blog/
[Thu Jul 30 15:11:21.349135 2026] [core:error] [pid 133043:tid 133093] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/blog/
[Thu Jul 30 15:11:21.438226 2026] [security2:error] [pid 133043:tid 133208] [client 68.67.112.221:4374] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuv6bdt6aqtVvMundN8hQAAAKg"]
[Thu Jul 30 15:11:21.731133 2026] [security2:error] [pid 133043:tid 133229] [client 54.167.223.174:44574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuv6bdt6aqtVvMundN8jgAAAL0"], referer: https://globalmarks.pk/
[Thu Jul 30 15:11:21.788751 2026] [security2:error] [pid 133043:tid 133100] [remote 148.113.47.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.47.113.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medaxco.com"] [uri "/wp-login.php"] [unique_id "amuv6bdt6aqtVvMundN8jAAA-jg"]
[Thu Jul 30 15:11:21.949937 2026] [core:error] [pid 133043:tid 133184] [client 34.7.15.221:30542] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.949957 2026] [core:error] [pid 133043:tid 133184] [client 34.7.15.221:30542] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.949962 2026] [core:error] [pid 133043:tid 133298] [client 34.7.15.221:30586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.949997 2026] [core:error] [pid 133043:tid 133298] [client 34.7.15.221:30586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.950993 2026] [core:error] [pid 133043:tid 133282] [client 34.7.15.221:30532] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.951031 2026] [core:error] [pid 133043:tid 133282] [client 34.7.15.221:30532] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.952086 2026] [core:error] [pid 133043:tid 133300] [client 34.7.15.221:30606] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.952104 2026] [core:error] [pid 133043:tid 133300] [client 34.7.15.221:30606] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.956669 2026] [core:error] [pid 133043:tid 133195] [client 34.7.15.221:30596] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.956686 2026] [core:error] [pid 133043:tid 133195] [client 34.7.15.221:30596] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.967890 2026] [core:error] [pid 133043:tid 133188] [client 34.7.15.221:30564] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.967907 2026] [core:error] [pid 133043:tid 133186] [client 34.7.15.221:30558] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.967909 2026] [core:error] [pid 133043:tid 133188] [client 34.7.15.221:30564] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.967921 2026] [core:error] [pid 133043:tid 133186] [client 34.7.15.221:30558] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.968238 2026] [core:error] [pid 133043:tid 133247] [client 34.7.15.221:30570] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:21.968254 2026] [core:error] [pid 133043:tid 133247] [client 34.7.15.221:30570] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:22.026112 2026] [security2:error] [pid 133043:tid 133235] [client 20.171.55.167:10367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/classsmtps.php"] [unique_id "amuv6rdt6aqtVvMundN8nQAAAMM"]
[Thu Jul 30 15:11:22.099331 2026] [security2:error] [pid 133043:tid 133213] [client 4.225.203.146:34159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/aaa.php"] [unique_id "amuv6rdt6aqtVvMundN8oQAAAK0"]
[Thu Jul 30 15:11:22.688441 2026] [security2:error] [pid 133043:tid 133287] [client 40.77.167.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuv6Ldt6aqtVvMundN8dwAAAPc"]
[Thu Jul 30 15:11:22.724170 2026] [core:error] [pid 133043:tid 133045] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/blog/
[Thu Jul 30 15:11:22.724192 2026] [core:error] [pid 133043:tid 133045] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/blog/
[Thu Jul 30 15:11:22.802503 2026] [security2:error] [pid 133043:tid 133206] [client 20.215.191.139:37443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuv6rdt6aqtVvMundN8sQAAAKY"]
[Thu Jul 30 15:11:22.974327 2026] [security2:error] [pid 133043:tid 133197] [client 20.171.55.167:10589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/color/blue/maintenence.php"] [unique_id "amuv6rdt6aqtVvMundN8sgAAAJ0"]
[Thu Jul 30 15:11:23.081117 2026] [security2:error] [pid 133043:tid 133106] [remote 57.141.0.64:64268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuv67dt6aqtVvMundN8twAA5j4"]
[Thu Jul 30 15:11:23.325135 2026] [core:error] [pid 133043:tid 133111] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/old/
[Thu Jul 30 15:11:23.325162 2026] [core:error] [pid 133043:tid 133111] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/old/
[Thu Jul 30 15:11:23.726048 2026] [security2:error] [pid 133043:tid 133281] [client 4.225.203.146:10147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/getid3-core.php"] [unique_id "amuv67dt6aqtVvMundN8zgAAAPE"]
[Thu Jul 30 15:11:23.922012 2026] [security2:error] [pid 133043:tid 133290] [client 20.171.55.167:10316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/colors/blue/ds.php"] [unique_id "amuv67dt6aqtVvMundN80AAAAPo"]
[Thu Jul 30 15:11:24.212783 2026] [security2:error] [pid 133043:tid 133120] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.tmb/LA.php"] [unique_id "amuv7Ldt6aqtVvMundN83gAAoUw"]
[Thu Jul 30 15:11:24.213434 2026] [core:error] [pid 133043:tid 133273] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.213465 2026] [core:error] [pid 133043:tid 133273] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.642930 2026] [security2:error] [pid 133043:tid 133249] [client 74.7.230.25:40762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.serverkr.com"] [uri "/cgi-sys/404.html"] [unique_id "amuv7Ldt6aqtVvMundN84gAA0VA"]
[Thu Jul 30 15:11:24.681163 2026] [security2:error] [pid 133043:tid 133127] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.tmb/admin.php"] [unique_id "amuv7Ldt6aqtVvMundN85gAAq1M"]
[Thu Jul 30 15:11:24.837509 2026] [core:notice] [pid 133043:tid 133217] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:24.845601 2026] [security2:error] [pid 133043:tid 133116] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.tmb/class_api.php"] [unique_id "amuv7Ldt6aqtVvMundN86wAAqEg"]
[Thu Jul 30 15:11:24.850276 2026] [security2:error] [pid 133043:tid 133253] [client 20.171.55.167:10315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/colors/coffee/admin.php"] [unique_id "amuv7Ldt6aqtVvMundN87AAAANU"]
[Thu Jul 30 15:11:24.939442 2026] [security2:error] [pid 133043:tid 133203] [client 34.7.15.221:24640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/application_default_credentials.json"] [unique_id "amuv7Ldt6aqtVvMundN87QAAAKM"]
[Thu Jul 30 15:11:24.941108 2026] [security2:error] [pid 133043:tid 133296] [client 4.225.203.146:23904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/adminer.php"] [unique_id "amuv7Ldt6aqtVvMundN87gAAAQA"]
[Thu Jul 30 15:11:24.953307 2026] [security2:error] [pid 133043:tid 133179] [client 34.7.15.221:24658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config.php"] [unique_id "amuv7Ldt6aqtVvMundN88wAAAIs"]
[Thu Jul 30 15:11:24.959399 2026] [security2:error] [pid 133043:tid 133240] [client 34.7.15.221:24836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.txt"] [unique_id "amuv7Ldt6aqtVvMundN8_gAAAMg"]
[Thu Jul 30 15:11:24.959481 2026] [security2:error] [pid 133043:tid 133240] [client 34.7.15.221:24836] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.txt"] [unique_id "amuv7Ldt6aqtVvMundN8_gAAAMg"]
[Thu Jul 30 15:11:24.959625 2026] [core:error] [pid 133043:tid 133248] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.959637 2026] [core:error] [pid 133043:tid 133248] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.961678 2026] [security2:error] [pid 133043:tid 133289] [client 34.7.15.221:24824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.orig"] [unique_id "amuv7Ldt6aqtVvMundN9AwAAAPk"]
[Thu Jul 30 15:11:24.961798 2026] [security2:error] [pid 133043:tid 133289] [client 34.7.15.221:24824] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.orig"] [unique_id "amuv7Ldt6aqtVvMundN9AwAAAPk"]
[Thu Jul 30 15:11:24.962226 2026] [security2:error] [pid 133043:tid 133206] [client 34.7.15.221:24644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/wp-config.php"] [unique_id "amuv7Ldt6aqtVvMundN9BgAAAKY"]
[Thu Jul 30 15:11:24.962334 2026] [security2:error] [pid 133043:tid 133232] [client 34.7.15.221:24848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.swp"] [unique_id "amuv7Ldt6aqtVvMundN9BAAAAMA"]
[Thu Jul 30 15:11:24.962355 2026] [core:error] [pid 133043:tid 133285] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.962374 2026] [core:error] [pid 133043:tid 133285] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.962522 2026] [security2:error] [pid 133043:tid 133285] [client 34.7.15.221:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/index.php"] [unique_id "amuv7Ldt6aqtVvMundN8-wAAAPU"]
[Thu Jul 30 15:11:24.962971 2026] [security2:error] [pid 133043:tid 133227] [client 34.7.15.221:24662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "elitegaragedoorrepairservices.us"] [uri "/wp-config.php.bak"] [unique_id "amuv7Ldt6aqtVvMundN9CQAAALs"]
[Thu Jul 30 15:11:24.963078 2026] [security2:error] [pid 133043:tid 133254] [client 34.7.15.221:24686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config/secrets.yml"] [unique_id "amuv7Ldt6aqtVvMundN88QAAANY"]
[Thu Jul 30 15:11:24.969256 2026] [core:error] [pid 133043:tid 133227] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.969273 2026] [core:error] [pid 133043:tid 133227] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.969432 2026] [security2:error] [pid 133043:tid 133267] [client 34.7.15.221:24690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/application.yml"] [unique_id "amuv7Ldt6aqtVvMundN9FQAAAOM"]
[Thu Jul 30 15:11:24.969827 2026] [core:error] [pid 133043:tid 133262] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.969838 2026] [core:error] [pid 133043:tid 133262] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.970837 2026] [core:error] [pid 133043:tid 133189] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.970851 2026] [core:error] [pid 133043:tid 133189] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.971458 2026] [core:error] [pid 133043:tid 133238] [client 34.7.15.221:24872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.971471 2026] [core:error] [pid 133043:tid 133281] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.971474 2026] [core:error] [pid 133043:tid 133238] [client 34.7.15.221:24872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.971485 2026] [core:error] [pid 133043:tid 133281] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.972695 2026] [core:error] [pid 133043:tid 133282] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.972717 2026] [core:error] [pid 133043:tid 133282] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.972816 2026] [core:error] [pid 133043:tid 133298] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.972828 2026] [core:error] [pid 133043:tid 133298] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.974367 2026] [core:error] [pid 133043:tid 133272] [client 34.7.15.221:24718] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.974382 2026] [core:error] [pid 133043:tid 133272] [client 34.7.15.221:24718] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.975405 2026] [core:error] [pid 133043:tid 133235] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.975426 2026] [core:error] [pid 133043:tid 133235] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.977999 2026] [core:error] [pid 133043:tid 133213] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.978016 2026] [core:error] [pid 133043:tid 133213] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.979074 2026] [core:error] [pid 133043:tid 133209] [client 34.7.15.221:24714] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.979088 2026] [core:error] [pid 133043:tid 133209] [client 34.7.15.221:24714] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.979134 2026] [core:error] [pid 133043:tid 133260] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.979144 2026] [core:error] [pid 133043:tid 133260] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.981613 2026] [security2:error] [pid 133043:tid 133173] [client 34.7.15.221:24880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env~"] [unique_id "amuv7Ldt6aqtVvMundN9KAAAAIU"]
[Thu Jul 30 15:11:24.982785 2026] [core:error] [pid 133043:tid 133198] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.982805 2026] [core:error] [pid 133043:tid 133198] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.987308 2026] [core:error] [pid 133043:tid 133273] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.987324 2026] [core:error] [pid 133043:tid 133273] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.989425 2026] [core:error] [pid 133043:tid 133294] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.989439 2026] [core:error] [pid 133043:tid 133294] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.990638 2026] [core:error] [pid 133043:tid 133270] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.990657 2026] [core:error] [pid 133043:tid 133270] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.991569 2026] [core:error] [pid 133043:tid 133293] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.991583 2026] [core:error] [pid 133043:tid 133293] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.992082 2026] [core:error] [pid 133043:tid 133291] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.992097 2026] [core:error] [pid 133043:tid 133291] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.992722 2026] [core:error] [pid 133043:tid 133258] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.992742 2026] [core:error] [pid 133043:tid 133258] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.993517 2026] [core:error] [pid 133043:tid 133286] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:24.993531 2026] [core:error] [pid 133043:tid 133286] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:25.086490 2026] [security2:error] [pid 133043:tid 133121] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuv7bdt6aqtVvMundN9NAAA4E0"]
[Thu Jul 30 15:11:25.204610 2026] [security2:error] [pid 133043:tid 133239] [client 34.7.15.221:24676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config.inc.php"] [unique_id "amuv7Ldt6aqtVvMundN87wAAAMc"]
[Thu Jul 30 15:11:25.316158 2026] [core:notice] [pid 133043:tid 133288] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:25.512322 2026] [security2:error] [pid 133043:tid 133129] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuv7bdt6aqtVvMundN9OwAAvlU"]
[Thu Jul 30 15:11:25.664805 2026] [security2:error] [pid 133043:tid 133141] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuv7bdt6aqtVvMundN9RQABAWE"]
[Thu Jul 30 15:11:25.713660 2026] [core:error] [pid 133043:tid 133243] [client 4.225.203.146:34121] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:25.713683 2026] [core:error] [pid 133043:tid 133243] [client 4.225.203.146:34121] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:25.747703 2026] [security2:error] [pid 133043:tid 133216] [client 20.215.191.139:39955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuv7bdt6aqtVvMundN9SgAAALA"]
[Thu Jul 30 15:11:25.752650 2026] [security2:error] [pid 133043:tid 133260] [client 20.171.55.167:10347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/colors/coffee/xmrlpc.php"] [unique_id "amuv7bdt6aqtVvMundN9SwAAANw"]
[Thu Jul 30 15:11:25.820603 2026] [security2:error] [pid 133043:tid 133107] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/991176.php"] [unique_id "amuv7bdt6aqtVvMundN9TwAA6j8"]
[Thu Jul 30 15:11:25.983114 2026] [security2:error] [pid 133043:tid 133146] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuv7bdt6aqtVvMundN9VgAA2mY"]
[Thu Jul 30 15:11:26.183428 2026] [security2:error] [pid 133043:tid 133166] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuv7rdt6aqtVvMundN9cwAAqHo"]
[Thu Jul 30 15:11:26.377920 2026] [security2:error] [pid 133043:tid 133055] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuv7rdt6aqtVvMundN9kAAAxQs"]
[Thu Jul 30 15:11:26.603999 2026] [security2:error] [pid 133043:tid 133066] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuv7rdt6aqtVvMundN9kQAA3hY"]
[Thu Jul 30 15:11:26.683037 2026] [security2:error] [pid 133043:tid 133206] [client 20.171.55.167:10502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/colors/light/profile.php"] [unique_id "amuv7rdt6aqtVvMundN9mAAAAKY"]
[Thu Jul 30 15:11:26.740596 2026] [security2:error] [pid 133043:tid 133191] [client 20.215.191.139:37473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuv7rdt6aqtVvMundN9mQAAAJc"]
[Thu Jul 30 15:11:26.818124 2026] [security2:error] [pid 133043:tid 133054] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuv7rdt6aqtVvMundN9nQAAtQo"]
[Thu Jul 30 15:11:27.211999 2026] [security2:error] [pid 133043:tid 133239] [client 4.225.203.146:22498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/alfa.php"] [unique_id "amuv77dt6aqtVvMundN9qwAAAMc"]
[Thu Jul 30 15:11:27.212160 2026] [security2:error] [pid 133043:tid 133090] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuv77dt6aqtVvMundN9rAAArS4"]
[Thu Jul 30 15:11:27.381457 2026] [security2:error] [pid 133043:tid 133084] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuv77dt6aqtVvMundN9tQAAkSg"]
[Thu Jul 30 15:11:27.488738 2026] [security2:error] [pid 133043:tid 133187] [client 20.215.191.139:39996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuv77dt6aqtVvMundN9twAAAJM"]
[Thu Jul 30 15:11:27.533146 2026] [security2:error] [pid 133043:tid 133080] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuv77dt6aqtVvMundN9vAAAyyQ"]
[Thu Jul 30 15:11:27.623609 2026] [security2:error] [pid 133043:tid 133173] [client 20.171.55.167:10326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/colors/sunrise/colors_95.php"] [unique_id "amuv77dt6aqtVvMundN9vQAAAIU"]
[Thu Jul 30 15:11:27.697265 2026] [security2:error] [pid 133043:tid 133099] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuv77dt6aqtVvMundN9wAAAsDc"]
[Thu Jul 30 15:11:27.894447 2026] [security2:error] [pid 133043:tid 133270] [client 34.7.15.221:24908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.yaml"] [unique_id "amuv77dt6aqtVvMundN9zwAAAOY"]
[Thu Jul 30 15:11:27.897896 2026] [security2:error] [pid 133043:tid 133291] [client 34.7.15.221:24964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.php.backup"] [unique_id "amuv77dt6aqtVvMundN91AAAAPs"]
[Thu Jul 30 15:11:27.898810 2026] [security2:error] [pid 133043:tid 133215] [client 34.7.15.221:24956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.php.bak"] [unique_id "amuv77dt6aqtVvMundN91wAAAK8"]
[Thu Jul 30 15:11:27.900502 2026] [security2:error] [pid 133043:tid 133287] [client 34.7.15.221:24940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.php"] [unique_id "amuv77dt6aqtVvMundN92QAAAPc"]
[Thu Jul 30 15:11:27.901288 2026] [security2:error] [pid 133043:tid 133101] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuv77dt6aqtVvMundN92gAA9Tk"]
[Thu Jul 30 15:11:27.905812 2026] [security2:error] [pid 133043:tid 133277] [client 34.7.15.221:24974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.php-bak"] [unique_id "amuv77dt6aqtVvMundN92wAAAO0"]
[Thu Jul 30 15:11:27.908890 2026] [core:error] [pid 133043:tid 133278] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:27.908907 2026] [core:error] [pid 133043:tid 133278] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:27.910529 2026] [core:error] [pid 133043:tid 133269] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:27.910545 2026] [core:error] [pid 133043:tid 133269] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:27.911672 2026] [core:error] [pid 133043:tid 133231] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:27.911696 2026] [core:error] [pid 133043:tid 133231] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:28.059712 2026] [security2:error] [pid 133043:tid 133104] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuv8Ldt6aqtVvMundN94wAAtTw"]
[Thu Jul 30 15:11:28.303799 2026] [security2:error] [pid 133043:tid 133094] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuv8Ldt6aqtVvMundN98AAA-DI"]
[Thu Jul 30 15:11:28.429238 2026] [core:error] [pid 133043:tid 133188] [client 4.225.203.146:46623] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:28.429260 2026] [core:error] [pid 133043:tid 133188] [client 4.225.203.146:46623] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:28.467335 2026] [security2:error] [pid 133043:tid 133106] [remote 57.141.0.56:60478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/27169508389/feed/rss2/"] [unique_id "amuv8Ldt6aqtVvMundN97AAAmT4"]
[Thu Jul 30 15:11:28.493597 2026] [security2:error] [pid 133043:tid 133105] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuv8Ldt6aqtVvMundN9-AAAvD0"]
[Thu Jul 30 15:11:28.547340 2026] [security2:error] [pid 133043:tid 133241] [client 20.171.55.167:10577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/compat.php"] [unique_id "amuv8Ldt6aqtVvMundN9-QAAAMk"]
[Thu Jul 30 15:11:28.656577 2026] [security2:error] [pid 133043:tid 133109] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuv8Ldt6aqtVvMundN9-wAA10E"]
[Thu Jul 30 15:11:28.808540 2026] [security2:error] [pid 133043:tid 133118] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/bek.php"] [unique_id "amuv8Ldt6aqtVvMundN9_QAAlko"]
[Thu Jul 30 15:11:28.867611 2026] [security2:error] [pid 133043:tid 133249] [client 74.7.228.58:44556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.deltaedu.net.ssa.djb.temporary.site"] [uri "/index.php"] [unique_id "amuv8Ldt6aqtVvMundN9_AAA0UU"]
[Thu Jul 30 15:11:28.923958 2026] [security2:error] [pid 133043:tid 133208] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuv8Ldt6aqtVvMundN-BwAAAKg"]
[Thu Jul 30 15:11:28.924122 2026] [security2:error] [pid 133043:tid 133208] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuv8Ldt6aqtVvMundN-BwAAAKg"]
[Thu Jul 30 15:11:28.964079 2026] [security2:error] [pid 133043:tid 133122] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuv8Ldt6aqtVvMundN-DAAAik4"]
[Thu Jul 30 15:11:29.159903 2026] [security2:error] [pid 133043:tid 133115] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/class.api.php"] [unique_id "amuv8bdt6aqtVvMundN-FQAAwEc"]
[Thu Jul 30 15:11:29.192841 2026] [security2:error] [pid 133043:tid 133295] [client 4.225.203.146:10140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuv8bdt6aqtVvMundN-FgAAAP8"]
[Thu Jul 30 15:11:29.228035 2026] [security2:error] [pid 133043:tid 133222] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuv8bdt6aqtVvMundN-FwAAALY"]
[Thu Jul 30 15:11:29.228149 2026] [security2:error] [pid 133043:tid 133222] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuv8bdt6aqtVvMundN-FwAAALY"]
[Thu Jul 30 15:11:29.392836 2026] [security2:error] [pid 133043:tid 133116] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/cong.php"] [unique_id "amuv8bdt6aqtVvMundN-GwAAwUg"]
[Thu Jul 30 15:11:29.450132 2026] [security2:error] [pid 133043:tid 133237] [client 20.171.55.167:10312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/cong.php"] [unique_id "amuv8bdt6aqtVvMundN-HwAAAMU"]
[Thu Jul 30 15:11:29.498647 2026] [security2:error] [pid 133043:tid 133245] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuv8bdt6aqtVvMundN-IAAAAM0"]
[Thu Jul 30 15:11:29.498727 2026] [security2:error] [pid 133043:tid 133245] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuv8bdt6aqtVvMundN-IAAAAM0"]
[Thu Jul 30 15:11:29.540841 2026] [security2:error] [pid 133043:tid 133261] [client 20.215.191.139:36291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuv8bdt6aqtVvMundN-IQAAAN0"]
[Thu Jul 30 15:11:29.554139 2026] [security2:error] [pid 133043:tid 133131] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/content.php"] [unique_id "amuv8bdt6aqtVvMundN-IgAAwlc"]
[Thu Jul 30 15:11:29.576386 2026] [core:notice] [pid 133043:tid 133206] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:29.696385 2026] [core:notice] [pid 133043:tid 133267] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:29.777191 2026] [security2:error] [pid 133043:tid 133132] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuv8bdt6aqtVvMundN-JwAA8Vg"]
[Thu Jul 30 15:11:29.787257 2026] [security2:error] [pid 133043:tid 133298] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/err.php"] [unique_id "amuv8bdt6aqtVvMundN-KQAAAQI"]
[Thu Jul 30 15:11:29.787344 2026] [security2:error] [pid 133043:tid 133298] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/err.php"] [unique_id "amuv8bdt6aqtVvMundN-KQAAAQI"]
[Thu Jul 30 15:11:29.889907 2026] [core:notice] [pid 133043:tid 133205] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:29.937727 2026] [security2:error] [pid 133043:tid 133129] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/elp.php"] [unique_id "amuv8bdt6aqtVvMundN-MQAAqVU"]
[Thu Jul 30 15:11:30.073779 2026] [security2:error] [pid 133043:tid 133214] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/img.php"] [unique_id "amuv8rdt6aqtVvMundN-MgAAAK4"]
[Thu Jul 30 15:11:30.073881 2026] [security2:error] [pid 133043:tid 133214] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/img.php"] [unique_id "amuv8rdt6aqtVvMundN-MgAAAK4"]
[Thu Jul 30 15:11:30.113183 2026] [security2:error] [pid 133043:tid 133134] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuv8rdt6aqtVvMundN-NAAAtFo"]
[Thu Jul 30 15:11:30.274705 2026] [security2:error] [pid 133043:tid 133107] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuv8rdt6aqtVvMundN-NgAAqz8"]
[Thu Jul 30 15:11:30.356176 2026] [security2:error] [pid 133043:tid 133244] [client 34.7.15.221:25022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.sample.php"] [unique_id "amuv8rdt6aqtVvMundN-PAAAAMw"]
[Thu Jul 30 15:11:30.357758 2026] [security2:error] [pid 133043:tid 133224] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aa.php"] [unique_id "amuv8rdt6aqtVvMundN-PgAAALg"]
[Thu Jul 30 15:11:30.357849 2026] [security2:error] [pid 133043:tid 133224] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/aa.php"] [unique_id "amuv8rdt6aqtVvMundN-PgAAALg"]
[Thu Jul 30 15:11:30.358863 2026] [security2:error] [pid 133043:tid 133202] [client 34.7.15.221:24976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.php-backup"] [unique_id "amuv8rdt6aqtVvMundN-QAAAAKI"]
[Thu Jul 30 15:11:30.361671 2026] [security2:error] [pid 133043:tid 133181] [client 34.7.15.221:25090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/API/.env"] [unique_id "amuv8rdt6aqtVvMundN-RAAAAI0"]
[Thu Jul 30 15:11:30.362351 2026] [security2:error] [pid 133043:tid 133193] [client 34.7.15.221:25056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/sendgrid.env"] [unique_id "amuv8rdt6aqtVvMundN-RgAAAJk"]
[Thu Jul 30 15:11:30.362438 2026] [security2:error] [pid 133043:tid 133193] [client 34.7.15.221:25056] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/sendgrid.env"] [unique_id "amuv8rdt6aqtVvMundN-RgAAAJk"]
[Thu Jul 30 15:11:30.367250 2026] [security2:error] [pid 133043:tid 133198] [client 34.7.15.221:25114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/web/.env"] [unique_id "amuv8rdt6aqtVvMundN-SQAAAJ4"]
[Thu Jul 30 15:11:30.370268 2026] [core:error] [pid 133043:tid 133299] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.370284 2026] [core:error] [pid 133043:tid 133299] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.370318 2026] [core:error] [pid 133043:tid 133275] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.370330 2026] [core:error] [pid 133043:tid 133275] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.370465 2026] [security2:error] [pid 133043:tid 133275] [client 34.7.15.221:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/index.php"] [unique_id "amuv8rdt6aqtVvMundN-SgAAAOs"]
[Thu Jul 30 15:11:30.371731 2026] [security2:error] [pid 133043:tid 133228] [client 34.7.15.221:24996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.production.php"] [unique_id "amuv8rdt6aqtVvMundN-TgAAALw"]
[Thu Jul 30 15:11:30.371803 2026] [security2:error] [pid 133043:tid 133250] [client 34.7.15.221:25030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config.env"] [unique_id "amuv8rdt6aqtVvMundN-OwAAANI"]
[Thu Jul 30 15:11:30.371949 2026] [core:error] [pid 133043:tid 133217] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.371959 2026] [core:error] [pid 133043:tid 133217] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.373462 2026] [security2:error] [pid 133043:tid 133280] [client 34.7.15.221:24982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.local.php"] [unique_id "amuv8rdt6aqtVvMundN-UAAAAPA"]
[Thu Jul 30 15:11:30.374002 2026] [security2:error] [pid 133043:tid 133230] [client 34.7.15.221:25008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.env.example.php"] [unique_id "amuv8rdt6aqtVvMundN-UgAAAL4"]
[Thu Jul 30 15:11:30.374301 2026] [security2:error] [pid 133043:tid 133185] [client 34.7.15.221:25130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/public/.env"] [unique_id "amuv8rdt6aqtVvMundN-UQAAAJE"]
[Thu Jul 30 15:11:30.375657 2026] [core:error] [pid 133043:tid 133273] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.375675 2026] [core:error] [pid 133043:tid 133273] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.380448 2026] [core:error] [pid 133043:tid 133233] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.380473 2026] [core:error] [pid 133043:tid 133233] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:30.384147 2026] [security2:error] [pid 133043:tid 133297] [client 34.7.15.221:25106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/frontend/.env"] [unique_id "amuv8rdt6aqtVvMundN-VAAAAQE"]
[Thu Jul 30 15:11:30.385586 2026] [security2:error] [pid 133043:tid 133187] [client 34.7.15.221:25150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/server/.env"] [unique_id "amuv8rdt6aqtVvMundN-VQAAAJM"]
[Thu Jul 30 15:11:30.388758 2026] [security2:error] [pid 133043:tid 133241] [client 34.7.15.221:25120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/www/.env"] [unique_id "amuv8rdt6aqtVvMundN-VwAAAMk"]
[Thu Jul 30 15:11:30.388947 2026] [security2:error] [pid 133043:tid 133200] [client 34.7.15.221:25186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/apps/.env"] [unique_id "amuv8rdt6aqtVvMundN-WAAAAKA"]
[Thu Jul 30 15:11:30.389077 2026] [security2:error] [pid 133043:tid 133243] [client 34.7.15.221:25168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/client/.env"] [unique_id "amuv8rdt6aqtVvMundN-WQAAAMs"]
[Thu Jul 30 15:11:30.390798 2026] [security2:error] [pid 133043:tid 133182] [client 34.7.15.221:25144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/html/.env"] [unique_id "amuv8rdt6aqtVvMundN-WgAAAI4"]
[Thu Jul 30 15:11:30.393750 2026] [security2:error] [pid 133043:tid 133225] [client 34.7.15.221:25198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/conf/.env"] [unique_id "amuv8rdt6aqtVvMundN-XAAAALk"]
[Thu Jul 30 15:11:30.397864 2026] [security2:error] [pid 133043:tid 133256] [client 34.7.15.221:25214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/development/.env"] [unique_id "amuv8rdt6aqtVvMundN-XQAAANg"]
[Thu Jul 30 15:11:30.401604 2026] [security2:error] [pid 133043:tid 133173] [client 34.7.15.221:25230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/prod/.env"] [unique_id "amuv8rdt6aqtVvMundN-XwAAAIU"]
[Thu Jul 30 15:11:30.406237 2026] [security2:error] [pid 133043:tid 133255] [client 34.7.15.221:25166] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/src/.env"] [unique_id "amuv8rdt6aqtVvMundN-YAAAANc"]
[Thu Jul 30 15:11:30.406300 2026] [security2:error] [pid 133043:tid 133274] [client 34.7.15.221:25232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/production/.env"] [unique_id "amuv8rdt6aqtVvMundN-YQAAAOo"]
[Thu Jul 30 15:11:30.408474 2026] [security2:error] [pid 133043:tid 133283] [client 34.7.15.221:25170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/core/.env"] [unique_id "amuv8rdt6aqtVvMundN-YgAAAPM"]
[Thu Jul 30 15:11:30.414110 2026] [security2:error] [pid 133043:tid 133276] [client 34.7.15.221:25194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.docker/.env"] [unique_id "amuv8rdt6aqtVvMundN-ZQAAAOw"]
[Thu Jul 30 15:11:30.414497 2026] [security2:error] [pid 133043:tid 133190] [client 34.7.15.221:25210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/dev/.env"] [unique_id "amuv8rdt6aqtVvMundN-ZgAAAJY"]
[Thu Jul 30 15:11:30.417263 2026] [security2:error] [pid 133043:tid 133260] [client 34.7.15.221:25254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/local/.env"] [unique_id "amuv8rdt6aqtVvMundN-ZwAAANw"]
[Thu Jul 30 15:11:30.420545 2026] [security2:error] [pid 133043:tid 133292] [client 34.7.15.221:25264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/backup/.env"] [unique_id "amuv8rdt6aqtVvMundN-aQAAAPw"]
[Thu Jul 30 15:11:30.420617 2026] [security2:error] [pid 133043:tid 133292] [client 34.7.15.221:25264] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/backup/.env"] [unique_id "amuv8rdt6aqtVvMundN-aQAAAPw"]
[Thu Jul 30 15:11:30.430141 2026] [security2:error] [pid 133043:tid 133293] [client 34.7.15.221:25238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/staging/.env"] [unique_id "amuv8rdt6aqtVvMundN-agAAAP0"]
[Thu Jul 30 15:11:30.433123 2026] [security2:error] [pid 133043:tid 133286] [client 34.7.15.221:25242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/test/.env"] [unique_id "amuv8rdt6aqtVvMundN-awAAAPY"]
[Thu Jul 30 15:11:30.433237 2026] [security2:error] [pid 133043:tid 133286] [client 34.7.15.221:25242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/test/.env"] [unique_id "amuv8rdt6aqtVvMundN-awAAAPY"]
[Thu Jul 30 15:11:30.440928 2026] [security2:error] [pid 133043:tid 133186] [client 20.171.55.167:10330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/core885.php"] [unique_id "amuv8rdt6aqtVvMundN-bAAAAJI"]
[Thu Jul 30 15:11:30.485726 2026] [security2:error] [pid 133043:tid 133143] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuv8rdt6aqtVvMundN-bgAAlWM"]
[Thu Jul 30 15:11:30.487466 2026] [security2:error] [pid 133043:tid 133247] [client 74.7.230.18:42504] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.hello-pal.com.yqe.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuv8rdt6aqtVvMundN-bQAAz2o"]
[Thu Jul 30 15:11:30.526055 2026] [security2:error] [pid 133043:tid 133192] [client 4.225.203.146:9223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuv8rdt6aqtVvMundN-bwAAAJg"]
[Thu Jul 30 15:11:30.651965 2026] [security2:error] [pid 133043:tid 133268] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/av.php"] [unique_id "amuv8rdt6aqtVvMundN-cQAAAOQ"]
[Thu Jul 30 15:11:30.652109 2026] [security2:error] [pid 133043:tid 133268] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/av.php"] [unique_id "amuv8rdt6aqtVvMundN-cQAAAOQ"]
[Thu Jul 30 15:11:30.662872 2026] [security2:error] [pid 133043:tid 133212] [client 57.141.0.61:59716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "emmelevate.club"] [uri "/index.php"] [unique_id "amuv8Ldt6aqtVvMundN-BgAArEw"]
[Thu Jul 30 15:11:30.680671 2026] [security2:error] [pid 133043:tid 133130] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuv8rdt6aqtVvMundN-dAAA31Y"]
[Thu Jul 30 15:11:30.840823 2026] [security2:error] [pid 133043:tid 133161] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuv8rdt6aqtVvMundN-egAArnU"]
[Thu Jul 30 15:11:30.924315 2026] [security2:error] [pid 133043:tid 133249] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xa.php"] [unique_id "amuv8rdt6aqtVvMundN-fwAAANE"]
[Thu Jul 30 15:11:30.924426 2026] [security2:error] [pid 133043:tid 133249] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xa.php"] [unique_id "amuv8rdt6aqtVvMundN-fwAAANE"]
[Thu Jul 30 15:11:30.967335 2026] [security2:error] [pid 133043:tid 133135] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv8rdt6aqtVvMundN-gwAAnVs"]
[Thu Jul 30 15:11:30.967502 2026] [security2:error] [pid 133043:tid 133197] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv8rdt6aqtVvMundN-gwAAnVs"]
[Thu Jul 30 15:11:31.035123 2026] [security2:error] [pid 133043:tid 133162] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuv87dt6aqtVvMundN-hQAA63Y"]
[Thu Jul 30 15:11:31.074275 2026] [core:notice] [pid 133043:tid 133151] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:31.090301 2026] [security2:error] [pid 133043:tid 133284] [client 216.244.66.194:48408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuv87dt6aqtVvMundN-iQAAAPQ"]
[Thu Jul 30 15:11:31.090435 2026] [security2:error] [pid 133043:tid 133284] [client 216.244.66.194:48408] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuv87dt6aqtVvMundN-iQAAAPQ"]
[Thu Jul 30 15:11:31.099219 2026] [security2:error] [pid 133043:tid 133272] [client 20.215.191.139:39995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuv87dt6aqtVvMundN-igAAAOg"]
[Thu Jul 30 15:11:31.159649 2026] [security2:error] [pid 133043:tid 133211] [client 52.167.144.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuv8rdt6aqtVvMundN-fgAAAKs"]
[Thu Jul 30 15:11:31.194277 2026] [security2:error] [pid 133043:tid 133148] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuv87dt6aqtVvMundN-jAAA2Gg"]
[Thu Jul 30 15:11:31.208744 2026] [security2:error] [pid 133043:tid 133173] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/media.php"] [unique_id "amuv87dt6aqtVvMundN-jQAAAIU"]
[Thu Jul 30 15:11:31.208840 2026] [security2:error] [pid 133043:tid 133173] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/media.php"] [unique_id "amuv87dt6aqtVvMundN-jQAAAIU"]
[Thu Jul 30 15:11:31.254215 2026] [security2:error] [pid 133043:tid 133262] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuv8rdt6aqtVvMundN-NQAA3l4"]
[Thu Jul 30 15:11:31.277697 2026] [security2:error] [pid 133043:tid 133202] [client 20.171.55.167:10574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/css-ready/file.php"] [unique_id "amuv87dt6aqtVvMundN-jgAAAKI"]
[Thu Jul 30 15:11:31.308125 2026] [autoindex:error] [pid 133043:tid 133149] [remote 74.7.241.23:36204] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:11:31.355503 2026] [security2:error] [pid 133043:tid 133158] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuv87dt6aqtVvMundN-kwAA_HI"]
[Thu Jul 30 15:11:31.486700 2026] [security2:error] [pid 133043:tid 133189] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/images.php"] [unique_id "amuv87dt6aqtVvMundN-mgAAAJU"]
[Thu Jul 30 15:11:31.486786 2026] [security2:error] [pid 133043:tid 133189] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/images.php"] [unique_id "amuv87dt6aqtVvMundN-mgAAAJU"]
[Thu Jul 30 15:11:31.603785 2026] [security2:error] [pid 133043:tid 133147] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuv87dt6aqtVvMundN-mwAAiGc"]
[Thu Jul 30 15:11:31.619370 2026] [security2:error] [pid 133043:tid 133224] [client 4.225.203.146:23902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuv87dt6aqtVvMundN-nAAAALg"]
[Thu Jul 30 15:11:31.763482 2026] [security2:error] [pid 133043:tid 133168] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuv87dt6aqtVvMundN-pAAArXw"]
[Thu Jul 30 15:11:31.773183 2026] [security2:error] [pid 133043:tid 133234] [client 77.223.252.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuv87dt6aqtVvMundN-nwAAAMI"], referer: https://cnpinyin.com
[Thu Jul 30 15:11:31.778637 2026] [security2:error] [pid 133043:tid 133221] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/gecko.php"] [unique_id "amuv87dt6aqtVvMundN-pQAAALU"]
[Thu Jul 30 15:11:31.778783 2026] [security2:error] [pid 133043:tid 133221] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/gecko.php"] [unique_id "amuv87dt6aqtVvMundN-pQAAALU"]
[Thu Jul 30 15:11:31.836479 2026] [security2:error] [pid 133043:tid 133264] [client 20.215.191.139:17489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuv87dt6aqtVvMundN-qAAAAOA"]
[Thu Jul 30 15:11:31.961792 2026] [core:error] [pid 133043:tid 133159] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/old/
[Thu Jul 30 15:11:31.961817 2026] [core:error] [pid 133043:tid 133159] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/old/
[Thu Jul 30 15:11:31.985218 2026] [security2:error] [pid 133043:tid 133069] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuv87dt6aqtVvMundN-rwAA_xk"]
[Thu Jul 30 15:11:32.057268 2026] [security2:error] [pid 133043:tid 133178] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/82.php"] [unique_id "amuv9Ldt6aqtVvMundN-sgAAAIo"]
[Thu Jul 30 15:11:32.057363 2026] [security2:error] [pid 133043:tid 133178] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/82.php"] [unique_id "amuv9Ldt6aqtVvMundN-sgAAAIo"]
[Thu Jul 30 15:11:32.064260 2026] [core:notice] [pid 133043:tid 133208] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:32.079255 2026] [security2:error] [pid 133043:tid 133207] [client 20.171.55.167:10583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/dashboardk.php"] [unique_id "amuv9Ldt6aqtVvMundN-tgAAAKc"]
[Thu Jul 30 15:11:32.191882 2026] [security2:error] [pid 133043:tid 133250] [client 4.225.203.146:23907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/edit.php"] [unique_id "amuv9Ldt6aqtVvMundN-vAAAANI"]
[Thu Jul 30 15:11:32.193506 2026] [security2:error] [pid 133043:tid 133167] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuv9Ldt6aqtVvMundN-vQAA9Hs"]
[Thu Jul 30 15:11:32.329899 2026] [security2:error] [pid 133043:tid 133297] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xstelth.php"] [unique_id "amuv9Ldt6aqtVvMundN-vgAAAQE"]
[Thu Jul 30 15:11:32.330034 2026] [security2:error] [pid 133043:tid 133297] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xstelth.php"] [unique_id "amuv9Ldt6aqtVvMundN-vgAAAQE"]
[Thu Jul 30 15:11:32.394625 2026] [security2:error] [pid 133043:tid 133170] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuv9Ldt6aqtVvMundN-wwAAoH4"]
[Thu Jul 30 15:11:32.458667 2026] [security2:error] [pid 133043:tid 133193] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuv87dt6aqtVvMundN-rAAAAJk"]
[Thu Jul 30 15:11:32.614759 2026] [security2:error] [pid 133043:tid 133057] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuv9Ldt6aqtVvMundN-zQAA1Q0"]
[Thu Jul 30 15:11:32.621778 2026] [core:error] [pid 133043:tid 133049] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/test/
[Thu Jul 30 15:11:32.621800 2026] [core:error] [pid 133043:tid 133049] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/test/
[Thu Jul 30 15:11:32.697075 2026] [security2:error] [pid 133043:tid 133273] [client 57.141.0.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuv9Ldt6aqtVvMundN-uwAAAOk"]
[Thu Jul 30 15:11:32.755152 2026] [security2:error] [pid 133043:tid 133185] [client 20.215.191.139:18033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuv9Ldt6aqtVvMundN-zwAAAJE"]
[Thu Jul 30 15:11:32.796567 2026] [security2:error] [pid 133043:tid 133186] [client 34.7.15.221:25294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/new/.env"] [unique_id "amuv9Ldt6aqtVvMundN-0QAAAJI"]
[Thu Jul 30 15:11:32.801996 2026] [security2:error] [pid 133043:tid 133196] [client 34.7.15.221:25314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/crm/.env"] [unique_id "amuv9Ldt6aqtVvMundN-0wAAAJw"]
[Thu Jul 30 15:11:32.802172 2026] [security2:error] [pid 133043:tid 133270] [client 34.7.15.221:25336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/project/.env"] [unique_id "amuv9Ldt6aqtVvMundN-0gAAAOY"]
[Thu Jul 30 15:11:32.807554 2026] [security2:error] [pid 133043:tid 133242] [client 34.7.15.221:25278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/old/.env"] [unique_id "amuv9Ldt6aqtVvMundN-1AAAAMo"]
[Thu Jul 30 15:11:32.815282 2026] [security2:error] [pid 133043:tid 133287] [client 34.7.15.221:25300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/portal/.env"] [unique_id "amuv9Ldt6aqtVvMundN-1QAAAPc"]
[Thu Jul 30 15:11:32.817970 2026] [security2:error] [pid 133043:tid 133291] [client 34.7.15.221:25324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/application/.env"] [unique_id "amuv9Ldt6aqtVvMundN-1gAAAPs"]
[Thu Jul 30 15:11:32.818681 2026] [security2:error] [pid 133043:tid 133183] [client 34.7.15.221:25316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/site/.env"] [unique_id "amuv9Ldt6aqtVvMundN-1wAAAI8"]
[Thu Jul 30 15:11:32.819199 2026] [security2:error] [pid 133043:tid 133189] [client 34.7.15.221:25338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/v1/.env"] [unique_id "amuv9Ldt6aqtVvMundN-2AAAAJU"]
[Thu Jul 30 15:11:32.819648 2026] [security2:error] [pid 133043:tid 133059] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuv9Ldt6aqtVvMundN-2QAAuA8"]
[Thu Jul 30 15:11:32.878018 2026] [security2:error] [pid 133043:tid 133261] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xp.php"] [unique_id "amuv9Ldt6aqtVvMundN-2wAAAN0"]
[Thu Jul 30 15:11:32.878108 2026] [security2:error] [pid 133043:tid 133261] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xp.php"] [unique_id "amuv9Ldt6aqtVvMundN-2wAAAN0"]
[Thu Jul 30 15:11:32.980394 2026] [security2:error] [pid 133043:tid 133048] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuv9Ldt6aqtVvMundN-3wAA1gQ"]
[Thu Jul 30 15:11:33.006160 2026] [security2:error] [pid 133043:tid 133188] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuv9Ldt6aqtVvMundN-xQAAAJQ"]
[Thu Jul 30 15:11:33.141460 2026] [security2:error] [pid 133043:tid 133051] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuv9bdt6aqtVvMundN-5wAAiwc"]
[Thu Jul 30 15:11:33.149162 2026] [security2:error] [pid 133043:tid 133205] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuv9bdt6aqtVvMundN-6QAAAKU"]
[Thu Jul 30 15:11:33.149260 2026] [security2:error] [pid 133043:tid 133205] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuv9bdt6aqtVvMundN-6QAAAKU"]
[Thu Jul 30 15:11:33.342728 2026] [security2:error] [pid 133043:tid 133066] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuv9bdt6aqtVvMundN-6wAAtRY"]
[Thu Jul 30 15:11:33.430147 2026] [security2:error] [pid 133043:tid 133197] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/adminner.php"] [unique_id "amuv9bdt6aqtVvMundN-7wAAAJ0"]
[Thu Jul 30 15:11:33.430255 2026] [security2:error] [pid 133043:tid 133197] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/adminner.php"] [unique_id "amuv9bdt6aqtVvMundN-7wAAAJ0"]
[Thu Jul 30 15:11:33.465573 2026] [security2:error] [pid 133043:tid 133282] [client 20.171.55.167:10578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/debug.php"] [unique_id "amuv9bdt6aqtVvMundN-8QAAAPI"]
[Thu Jul 30 15:11:33.503357 2026] [security2:error] [pid 133043:tid 133073] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuv9bdt6aqtVvMundN-8gAA_h0"]
[Thu Jul 30 15:11:33.566013 2026] [core:error] [pid 133043:tid 133258] [client 4.225.203.146:9230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:33.566034 2026] [core:error] [pid 133043:tid 133258] [client 4.225.203.146:9230] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:33.625188 2026] [security2:error] [pid 133043:tid 133290] [client 20.215.191.139:18017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuv9bdt6aqtVvMundN--wAAAPo"]
[Thu Jul 30 15:11:33.663297 2026] [security2:error] [pid 133043:tid 133072] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuv9bdt6aqtVvMundN-_AAA5Rw"]
[Thu Jul 30 15:11:33.725381 2026] [security2:error] [pid 133043:tid 133297] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/a.php"] [unique_id "amuv9bdt6aqtVvMundN-_QAAAQE"]
[Thu Jul 30 15:11:33.725494 2026] [security2:error] [pid 133043:tid 133297] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/a.php"] [unique_id "amuv9bdt6aqtVvMundN-_QAAAQE"]
[Thu Jul 30 15:11:33.756310 2026] [core:error] [pid 133043:tid 133061] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/test/
[Thu Jul 30 15:11:33.756330 2026] [core:error] [pid 133043:tid 133061] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/test/
[Thu Jul 30 15:11:33.824483 2026] [security2:error] [pid 133043:tid 133095] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuv9bdt6aqtVvMundN-_wAAuTM"]
[Thu Jul 30 15:11:33.987710 2026] [security2:error] [pid 133043:tid 133081] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuv9bdt6aqtVvMundN_BgAA7CU"]
[Thu Jul 30 15:11:33.998879 2026] [security2:error] [pid 133043:tid 133286] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/k.php"] [unique_id "amuv9bdt6aqtVvMundN_BwAAAPY"]
[Thu Jul 30 15:11:33.998986 2026] [security2:error] [pid 133043:tid 133286] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/k.php"] [unique_id "amuv9bdt6aqtVvMundN_BwAAAPY"]
[Thu Jul 30 15:11:34.197842 2026] [security2:error] [pid 133043:tid 133071] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuv9rdt6aqtVvMundN_DgAA-xs"]
[Thu Jul 30 15:11:34.241884 2026] [core:error] [pid 133043:tid 133273] [client 4.225.203.146:10143] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:34.241908 2026] [core:error] [pid 133043:tid 133273] [client 4.225.203.146:10143] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:34.246931 2026] [security2:error] [pid 133043:tid 133260] [client 20.171.55.167:10366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/dev.php"] [unique_id "amuv9rdt6aqtVvMundN_EAAAANw"]
[Thu Jul 30 15:11:34.283268 2026] [security2:error] [pid 133043:tid 133261] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/222.php"] [unique_id "amuv9rdt6aqtVvMundN_EQAAAN0"]
[Thu Jul 30 15:11:34.283358 2026] [security2:error] [pid 133043:tid 133261] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/222.php"] [unique_id "amuv9rdt6aqtVvMundN_EQAAAN0"]
[Thu Jul 30 15:11:34.310932 2026] [core:error] [pid 133043:tid 133088] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/dev/
[Thu Jul 30 15:11:34.310952 2026] [core:error] [pid 133043:tid 133088] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/dev/
[Thu Jul 30 15:11:34.358845 2026] [security2:error] [pid 133043:tid 133083] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuv9rdt6aqtVvMundN_EwAA5yc"]
[Thu Jul 30 15:11:34.510346 2026] [core:error] [pid 133043:tid 133084] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/dev/
[Thu Jul 30 15:11:34.510366 2026] [core:error] [pid 133043:tid 133084] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/dev/
[Thu Jul 30 15:11:34.519768 2026] [security2:error] [pid 133043:tid 133082] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuv9rdt6aqtVvMundN_GAAA8SY"]
[Thu Jul 30 15:11:34.577248 2026] [security2:error] [pid 133043:tid 133279] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/mac.php"] [unique_id "amuv9rdt6aqtVvMundN_GQAAAO8"]
[Thu Jul 30 15:11:34.577401 2026] [security2:error] [pid 133043:tid 133279] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/mac.php"] [unique_id "amuv9rdt6aqtVvMundN_GQAAAO8"]
[Thu Jul 30 15:11:34.683340 2026] [security2:error] [pid 133043:tid 133080] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuv9rdt6aqtVvMundN_HQAAkCQ"]
[Thu Jul 30 15:11:34.845757 2026] [security2:error] [pid 133043:tid 133091] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuv9rdt6aqtVvMundN_JAAA-C8"]
[Thu Jul 30 15:11:34.863733 2026] [proxy:error] [pid 133043:tid 133209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:11:34.863792 2026] [proxy_http:error] [pid 133043:tid 133209] [client 20.215.216.94:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:11:34.864358 2026] [proxy:error] [pid 133043:tid 133209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:11:34.864403 2026] [proxy_http:error] [pid 133043:tid 133209] [client 20.215.216.94:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:11:34.864492 2026] [security2:error] [pid 133043:tid 133209] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuv9rdt6aqtVvMundN_JwAAAKk"]
[Thu Jul 30 15:11:34.990462 2026] [security2:error] [pid 133043:tid 133247] [client 20.215.191.139:18030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuv9rdt6aqtVvMundN_KQAAAM8"]
[Thu Jul 30 15:11:35.031392 2026] [security2:error] [pid 133043:tid 133093] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuv97dt6aqtVvMundN_KgAAnzE"]
[Thu Jul 30 15:11:35.048340 2026] [core:error] [pid 133043:tid 133076] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/backup/
[Thu Jul 30 15:11:35.048359 2026] [core:error] [pid 133043:tid 133076] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/backup/
[Thu Jul 30 15:11:35.062920 2026] [security2:error] [pid 133043:tid 133219] [client 20.171.55.167:10618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/dist/edit-widgets/index.php"] [unique_id "amuv97dt6aqtVvMundN_LAAAALM"]
[Thu Jul 30 15:11:35.143749 2026] [proxy:error] [pid 133043:tid 133299] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:11:35.143825 2026] [proxy_http:error] [pid 133043:tid 133299] [client 20.215.216.94:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:11:35.144413 2026] [proxy:error] [pid 133043:tid 133299] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:11:35.144468 2026] [proxy_http:error] [pid 133043:tid 133299] [client 20.215.216.94:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:11:35.144568 2026] [security2:error] [pid 133043:tid 133299] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuv97dt6aqtVvMundN_LQAAAQM"]
[Thu Jul 30 15:11:35.230938 2026] [security2:error] [pid 133043:tid 133101] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuv97dt6aqtVvMundN_MgAAtjk"]
[Thu Jul 30 15:11:35.391757 2026] [security2:error] [pid 133043:tid 133085] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuv97dt6aqtVvMundN_NwAA8Ck"]
[Thu Jul 30 15:11:35.418015 2026] [security2:error] [pid 133043:tid 133269] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ops.php"] [unique_id "amuv97dt6aqtVvMundN_OQAAAOU"]
[Thu Jul 30 15:11:35.418132 2026] [security2:error] [pid 133043:tid 133269] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ops.php"] [unique_id "amuv97dt6aqtVvMundN_OQAAAOU"]
[Thu Jul 30 15:11:35.589459 2026] [core:error] [pid 133043:tid 133104] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/backup/
[Thu Jul 30 15:11:35.589486 2026] [core:error] [pid 133043:tid 133104] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/backup/
[Thu Jul 30 15:11:35.608433 2026] [security2:error] [pid 133043:tid 133086] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuv97dt6aqtVvMundN_PQABASo"]
[Thu Jul 30 15:11:35.720076 2026] [security2:error] [pid 133043:tid 133248] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/8.php"] [unique_id "amuv97dt6aqtVvMundN_PgAAANA"]
[Thu Jul 30 15:11:35.720190 2026] [security2:error] [pid 133043:tid 133248] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/8.php"] [unique_id "amuv97dt6aqtVvMundN_PgAAANA"]
[Thu Jul 30 15:11:35.769375 2026] [security2:error] [pid 133043:tid 133096] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuv97dt6aqtVvMundN_QgAAnDQ"]
[Thu Jul 30 15:11:35.797368 2026] [security2:error] [pid 133043:tid 133200] [client 34.7.15.221:41864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/sendgrid/.env.php"] [unique_id "amuv97dt6aqtVvMundN_RAAAAKA"]
[Thu Jul 30 15:11:35.797714 2026] [security2:error] [pid 133043:tid 133278] [client 34.7.15.221:41846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/v2/.env"] [unique_id "amuv97dt6aqtVvMundN_QwAAAO4"]
[Thu Jul 30 15:11:35.798443 2026] [security2:error] [pid 133043:tid 133211] [client 34.7.15.221:41946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/.circleci/config.yml"] [unique_id "amuv97dt6aqtVvMundN_RgAAAKs"]
[Thu Jul 30 15:11:35.803573 2026] [core:error] [pid 133043:tid 133193] [client 34.7.15.221:42018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.803591 2026] [core:error] [pid 133043:tid 133193] [client 34.7.15.221:42018] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.804337 2026] [core:error] [pid 133043:tid 133220] [client 34.7.15.221:41992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.804354 2026] [core:error] [pid 133043:tid 133220] [client 34.7.15.221:41992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.805319 2026] [core:error] [pid 133043:tid 133225] [client 34.7.15.221:41974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.805336 2026] [core:error] [pid 133043:tid 133225] [client 34.7.15.221:41974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.806530 2026] [core:error] [pid 133043:tid 133292] [client 34.7.15.221:42052] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.806557 2026] [core:error] [pid 133043:tid 133292] [client 34.7.15.221:42052] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.808909 2026] [security2:error] [pid 133043:tid 133256] [client 34.7.15.221:42084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/appsettings.Development.json"] [unique_id "amuv97dt6aqtVvMundN_XwAAANg"]
[Thu Jul 30 15:11:35.809007 2026] [security2:error] [pid 133043:tid 133256] [client 34.7.15.221:42084] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/appsettings.Development.json"] [unique_id "amuv97dt6aqtVvMundN_XwAAANg"]
[Thu Jul 30 15:11:35.810608 2026] [core:error] [pid 133043:tid 133262] [client 34.7.15.221:42062] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.810625 2026] [core:error] [pid 133043:tid 133262] [client 34.7.15.221:42062] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.811356 2026] [core:error] [pid 133043:tid 133253] [client 34.7.15.221:42134] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.811373 2026] [core:error] [pid 133043:tid 133253] [client 34.7.15.221:42134] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.811789 2026] [core:error] [pid 133043:tid 133286] [client 34.7.15.221:42076] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.811809 2026] [core:error] [pid 133043:tid 133286] [client 34.7.15.221:42076] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.812360 2026] [core:error] [pid 133043:tid 133276] [client 34.7.15.221:42064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.812373 2026] [core:error] [pid 133043:tid 133276] [client 34.7.15.221:42064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.812590 2026] [core:error] [pid 133043:tid 133266] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.812600 2026] [core:error] [pid 133043:tid 133266] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.815796 2026] [security2:error] [pid 133043:tid 133202] [client 34.7.15.221:41880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/twilio/.env.php"] [unique_id "amuv97dt6aqtVvMundN_agAAAKI"]
[Thu Jul 30 15:11:35.815865 2026] [security2:error] [pid 133043:tid 133202] [client 34.7.15.221:41880] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/twilio/.env.php"] [unique_id "amuv97dt6aqtVvMundN_agAAAKI"]
[Thu Jul 30 15:11:35.815991 2026] [authz_core:error] [pid 133043:tid 133267] [client 34.7.15.221:0] AH01630: client denied by server configuration: /home1/glbnyxte/public_html/website_b21f2df0/.htpasswd
[Thu Jul 30 15:11:35.816058 2026] [core:error] [pid 133043:tid 133274] [client 34.7.15.221:42098] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.816070 2026] [core:error] [pid 133043:tid 133274] [client 34.7.15.221:42098] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.817763 2026] [core:error] [pid 133043:tid 133192] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.817777 2026] [core:error] [pid 133043:tid 133192] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.817889 2026] [core:error] [pid 133043:tid 133230] [client 34.7.15.221:42120] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.817895 2026] [security2:error] [pid 133043:tid 133190] [client 34.7.15.221:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config/.env.php"] [unique_id "amuv97dt6aqtVvMundN_bwAAAJY"]
[Thu Jul 30 15:11:35.817907 2026] [core:error] [pid 133043:tid 133230] [client 34.7.15.221:42120] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.818049 2026] [security2:error] [pid 133043:tid 133190] [client 34.7.15.221:41854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config/.env.php"] [unique_id "amuv97dt6aqtVvMundN_bwAAAJY"]
[Thu Jul 30 15:11:35.818626 2026] [core:error] [pid 133043:tid 133191] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.818639 2026] [core:error] [pid 133043:tid 133191] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.818744 2026] [core:error] [pid 133043:tid 133188] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.818760 2026] [core:error] [pid 133043:tid 133188] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.818802 2026] [core:error] [pid 133043:tid 133195] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.818812 2026] [core:error] [pid 133043:tid 133195] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.819672 2026] [core:error] [pid 133043:tid 133185] [client 34.7.15.221:42128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.819689 2026] [core:error] [pid 133043:tid 133185] [client 34.7.15.221:42128] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.820486 2026] [core:error] [pid 133043:tid 133279] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.820486 2026] [core:error] [pid 133043:tid 133281] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.820502 2026] [core:error] [pid 133043:tid 133279] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.820506 2026] [core:error] [pid 133043:tid 133281] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.822623 2026] [core:error] [pid 133043:tid 133285] [client 34.7.15.221:41976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.822640 2026] [core:error] [pid 133043:tid 133285] [client 34.7.15.221:41976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.829880 2026] [core:error] [pid 133043:tid 133215] [client 34.7.15.221:42112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.829902 2026] [core:error] [pid 133043:tid 133215] [client 34.7.15.221:42112] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.830723 2026] [core:error] [pid 133043:tid 133181] [client 34.7.15.221:42074] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.830751 2026] [core:error] [pid 133043:tid 133181] [client 34.7.15.221:42074] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.830884 2026] [security2:error] [pid 133043:tid 133181] [client 34.7.15.221:42074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/index.php"] [unique_id "amuv97dt6aqtVvMundN_eQAAAI0"]
[Thu Jul 30 15:11:35.831864 2026] [core:error] [pid 133043:tid 133198] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.831880 2026] [core:error] [pid 133043:tid 133198] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.832048 2026] [core:error] [pid 133043:tid 133235] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.832064 2026] [core:error] [pid 133043:tid 133235] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.832732 2026] [core:error] [pid 133043:tid 133283] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.832744 2026] [core:error] [pid 133043:tid 133283] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.836022 2026] [core:error] [pid 133043:tid 133244] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.836037 2026] [core:error] [pid 133043:tid 133244] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:35.910596 2026] [security2:error] [pid 133043:tid 133194] [client 20.171.55.167:10603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/docsbypass.php"] [unique_id "amuv97dt6aqtVvMundN_fwAAAJo"]
[Thu Jul 30 15:11:35.984808 2026] [security2:error] [pid 133043:tid 133110] [remote 20.91.199.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuv97dt6aqtVvMundN_gwAA4kI"]
[Thu Jul 30 15:11:36.161190 2026] [security2:error] [pid 133043:tid 133201] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/FWAZ.php"] [unique_id "amuv-Ldt6aqtVvMundN_hAAAAKE"]
[Thu Jul 30 15:11:36.161319 2026] [security2:error] [pid 133043:tid 133201] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/FWAZ.php"] [unique_id "amuv-Ldt6aqtVvMundN_hAAAAKE"]
[Thu Jul 30 15:11:36.431443 2026] [security2:error] [pid 133043:tid 133185] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/biufile.php"] [unique_id "amuv-Ldt6aqtVvMundN_jAAAAJE"]
[Thu Jul 30 15:11:36.431545 2026] [security2:error] [pid 133043:tid 133185] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/biufile.php"] [unique_id "amuv-Ldt6aqtVvMundN_jAAAAJE"]
[Thu Jul 30 15:11:36.718126 2026] [security2:error] [pid 133043:tid 133181] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/coffexium.php"] [unique_id "amuv-Ldt6aqtVvMundN_kQAAAI0"]
[Thu Jul 30 15:11:36.718310 2026] [security2:error] [pid 133043:tid 133181] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/coffexium.php"] [unique_id "amuv-Ldt6aqtVvMundN_kQAAAI0"]
[Thu Jul 30 15:11:36.812675 2026] [security2:error] [pid 133043:tid 133209] [client 20.171.55.167:10595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/download.php"] [unique_id "amuv-Ldt6aqtVvMundN_lQAAAKk"]
[Thu Jul 30 15:11:36.992174 2026] [security2:error] [pid 133043:tid 133299] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/simple.php"] [unique_id "amuv-Ldt6aqtVvMundN_mQAAAQM"]
[Thu Jul 30 15:11:36.992281 2026] [security2:error] [pid 133043:tid 133299] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/simple.php"] [unique_id "amuv-Ldt6aqtVvMundN_mQAAAQM"]
[Thu Jul 30 15:11:37.071010 2026] [security2:error] [pid 133043:tid 133235] [client 20.215.191.139:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuv-bdt6aqtVvMundN_nQAAAMM"]
[Thu Jul 30 15:11:37.300222 2026] [security2:error] [pid 133043:tid 133258] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fpwch.php"] [unique_id "amuv-bdt6aqtVvMundN_oQAAANo"]
[Thu Jul 30 15:11:37.300321 2026] [security2:error] [pid 133043:tid 133258] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fpwch.php"] [unique_id "amuv-bdt6aqtVvMundN_oQAAANo"]
[Thu Jul 30 15:11:37.582446 2026] [security2:error] [pid 133043:tid 133208] [client 20.171.55.167:10511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/editor.php"] [unique_id "amuv-bdt6aqtVvMundN_qQAAAKg"]
[Thu Jul 30 15:11:37.583900 2026] [security2:error] [pid 133043:tid 133252] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dex.php"] [unique_id "amuv-bdt6aqtVvMundN_qgAAANQ"]
[Thu Jul 30 15:11:37.583970 2026] [security2:error] [pid 133043:tid 133252] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/dex.php"] [unique_id "amuv-bdt6aqtVvMundN_qgAAANQ"]
[Thu Jul 30 15:11:37.678646 2026] [security2:error] [pid 133043:tid 133279] [client 43.131.253.14:55780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.253.131.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuv-bdt6aqtVvMundN_pQAAAO8"]
[Thu Jul 30 15:11:37.738497 2026] [security2:error] [pid 133043:tid 133226] [client 20.215.191.139:39986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuv-bdt6aqtVvMundN_rAAAALo"]
[Thu Jul 30 15:11:37.866331 2026] [security2:error] [pid 133043:tid 133186] [client 20.215.216.94:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amuv-bdt6aqtVvMundN_sAAAAJI"]
[Thu Jul 30 15:11:37.866465 2026] [security2:error] [pid 133043:tid 133186] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amuv-bdt6aqtVvMundN_sAAAAJI"]
[Thu Jul 30 15:11:37.866617 2026] [security2:error] [pid 133043:tid 133186] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/1.php"] [unique_id "amuv-bdt6aqtVvMundN_sAAAAJI"]
[Thu Jul 30 15:11:38.124793 2026] [security2:error] [pid 133043:tid 133225] [client 172.237.109.114:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/maintenance.php"] [unique_id "amuv-rdt6aqtVvMundN_uAAAALk"]
[Thu Jul 30 15:11:38.138350 2026] [proxy:error] [pid 133043:tid 133254] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:11:38.138436 2026] [proxy_http:error] [pid 133043:tid 133254] [client 20.215.216.94:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:11:38.139010 2026] [proxy:error] [pid 133043:tid 133254] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:11:38.139055 2026] [proxy_http:error] [pid 133043:tid 133254] [client 20.215.216.94:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:11:38.139148 2026] [security2:error] [pid 133043:tid 133254] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuv-rdt6aqtVvMundN_uQAAANY"]
[Thu Jul 30 15:11:38.173570 2026] [security2:error] [pid 133043:tid 133287] [client 20.171.55.167:3624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/.alf.php"] [unique_id "amuv-rdt6aqtVvMundN_ugAAAPc"]
[Thu Jul 30 15:11:38.301122 2026] [core:error] [pid 133043:tid 133119] [remote 74.7.228.34:44400] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.301146 2026] [core:error] [pid 133043:tid 133119] [remote 74.7.228.34:44400] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.301381 2026] [security2:error] [pid 133043:tid 133294] [client 74.7.228.34:44400] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-1e74fa67.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuv-rdt6aqtVvMundN_vAAA_ks"]
[Thu Jul 30 15:11:38.405701 2026] [security2:error] [pid 133043:tid 133192] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/config.json.php"] [unique_id "amuv-rdt6aqtVvMundN_wAAAAJg"]
[Thu Jul 30 15:11:38.405847 2026] [security2:error] [pid 133043:tid 133192] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/config.json.php"] [unique_id "amuv-rdt6aqtVvMundN_wAAAAJg"]
[Thu Jul 30 15:11:38.417890 2026] [security2:error] [pid 133043:tid 133189] [client 20.171.55.167:10579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/envato-market/inc/class-envato-market-github.php"] [unique_id "amuv-rdt6aqtVvMundN_xAAAAJU"]
[Thu Jul 30 15:11:38.691456 2026] [security2:error] [pid 133043:tid 133263] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/k2.php"] [unique_id "amuv-rdt6aqtVvMundN_yAAAAN8"]
[Thu Jul 30 15:11:38.691560 2026] [security2:error] [pid 133043:tid 133263] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/k2.php"] [unique_id "amuv-rdt6aqtVvMundN_yAAAAN8"]
[Thu Jul 30 15:11:38.754015 2026] [security2:error] [pid 133043:tid 133184] [client 4.225.203.146:9262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/sf.php"] [unique_id "amuv-rdt6aqtVvMundN_yQAAAJA"]
[Thu Jul 30 15:11:38.762356 2026] [security2:error] [pid 133043:tid 133213] [client 34.7.15.221:42172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/privatekey.json"] [unique_id "amuv-rdt6aqtVvMundN_zAAAAK0"]
[Thu Jul 30 15:11:38.762521 2026] [security2:error] [pid 133043:tid 133213] [client 34.7.15.221:42172] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/privatekey.json"] [unique_id "amuv-rdt6aqtVvMundN_zAAAAK0"]
[Thu Jul 30 15:11:38.764792 2026] [core:error] [pid 133043:tid 133173] [client 34.7.15.221:42148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.764810 2026] [core:error] [pid 133043:tid 133173] [client 34.7.15.221:42148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.765257 2026] [core:error] [pid 133043:tid 133175] [client 34.7.15.221:42154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.765282 2026] [core:error] [pid 133043:tid 133175] [client 34.7.15.221:42154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.765399 2026] [security2:error] [pid 133043:tid 133175] [client 34.7.15.221:42154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/index.php"] [unique_id "amuv-rdt6aqtVvMundN_ygAAAIc"]
[Thu Jul 30 15:11:38.765516 2026] [core:error] [pid 133043:tid 133271] [client 34.7.15.221:42190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.765528 2026] [core:error] [pid 133043:tid 133271] [client 34.7.15.221:42190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.765946 2026] [core:error] [pid 133043:tid 133174] [client 34.7.15.221:42202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.765957 2026] [core:error] [pid 133043:tid 133174] [client 34.7.15.221:42202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.766632 2026] [core:error] [pid 133043:tid 133185] [client 34.7.15.221:42178] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.766648 2026] [core:error] [pid 133043:tid 133238] [client 34.7.15.221:42166] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.766649 2026] [core:error] [pid 133043:tid 133185] [client 34.7.15.221:42178] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.766662 2026] [core:error] [pid 133043:tid 133238] [client 34.7.15.221:42166] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.782471 2026] [core:error] [pid 133043:tid 133229] [client 34.7.15.221:42204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.782489 2026] [core:error] [pid 133043:tid 133229] [client 34.7.15.221:42204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:38.928235 2026] [core:error] [pid 133043:tid 133121] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/staging/
[Thu Jul 30 15:11:38.928263 2026] [core:error] [pid 133043:tid 133121] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/staging/
[Thu Jul 30 15:11:38.975166 2026] [security2:error] [pid 133043:tid 133299] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/raw.php"] [unique_id "amuv-rdt6aqtVvMundN_2AAAAQM"]
[Thu Jul 30 15:11:38.975253 2026] [security2:error] [pid 133043:tid 133299] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/raw.php"] [unique_id "amuv-rdt6aqtVvMundN_2AAAAQM"]
[Thu Jul 30 15:11:38.985883 2026] [security2:error] [pid 133043:tid 133231] [client 20.171.55.167:3995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/01.php"] [unique_id "amuv-rdt6aqtVvMundN_3QAAAL8"]
[Thu Jul 30 15:11:39.246730 2026] [security2:error] [pid 133043:tid 133228] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp.php"] [unique_id "amuv-7dt6aqtVvMundN_4QAAALw"]
[Thu Jul 30 15:11:39.246840 2026] [security2:error] [pid 133043:tid 133228] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp.php"] [unique_id "amuv-7dt6aqtVvMundN_4QAAALw"]
[Thu Jul 30 15:11:39.360474 2026] [security2:error] [pid 133043:tid 133258] [client 20.215.191.139:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuv-7dt6aqtVvMundN_4gAAANo"]
[Thu Jul 30 15:11:39.372225 2026] [security2:error] [pid 133043:tid 133227] [client 20.171.55.167:10532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/extension/extension/Not_Found.php"] [unique_id "amuv-7dt6aqtVvMundN_4wAAALs"]
[Thu Jul 30 15:11:39.516409 2026] [security2:error] [pid 133043:tid 133242] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fffm.php"] [unique_id "amuv-7dt6aqtVvMundN_7gAAAMo"]
[Thu Jul 30 15:11:39.516512 2026] [security2:error] [pid 133043:tid 133242] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/fffm.php"] [unique_id "amuv-7dt6aqtVvMundN_7gAAAMo"]
[Thu Jul 30 15:11:39.795048 2026] [security2:error] [pid 133043:tid 133292] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/111.php"] [unique_id "amuv-7dt6aqtVvMundN_8gAAAPw"]
[Thu Jul 30 15:11:39.795162 2026] [security2:error] [pid 133043:tid 133292] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/111.php"] [unique_id "amuv-7dt6aqtVvMundN_8gAAAPw"]
[Thu Jul 30 15:11:39.799125 2026] [security2:error] [pid 133043:tid 133226] [client 20.171.55.167:3590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/1337.php"] [unique_id "amuv-7dt6aqtVvMundN_8wAAALo"]
[Thu Jul 30 15:11:40.083596 2026] [proxy:error] [pid 133043:tid 133223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:11:40.083655 2026] [proxy_http:error] [pid 133043:tid 133223] [client 20.215.216.94:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:11:40.084283 2026] [proxy:error] [pid 133043:tid 133223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:11:40.084331 2026] [proxy_http:error] [pid 133043:tid 133223] [client 20.215.216.94:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:11:40.084410 2026] [security2:error] [pid 133043:tid 133223] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuv_Ldt6aqtVvMundN_-wAAALc"]
[Thu Jul 30 15:11:40.155654 2026] [security2:error] [pid 133043:tid 133286] [client 20.171.55.167:10497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/fdgfdgdsfd.php"] [unique_id "amuv_Ldt6aqtVvMundN__gAAAPY"]
[Thu Jul 30 15:11:40.382250 2026] [security2:error] [pid 133043:tid 133195] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ws.php"] [unique_id "amuv_Ldt6aqtVvMundOAAgAAAJs"]
[Thu Jul 30 15:11:40.382407 2026] [security2:error] [pid 133043:tid 133195] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/ws.php"] [unique_id "amuv_Ldt6aqtVvMundOAAgAAAJs"]
[Thu Jul 30 15:11:40.669482 2026] [security2:error] [pid 133043:tid 133278] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/coffee.php"] [unique_id "amuv_Ldt6aqtVvMundOACgAAAO4"]
[Thu Jul 30 15:11:40.669598 2026] [security2:error] [pid 133043:tid 133278] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/coffee.php"] [unique_id "amuv_Ldt6aqtVvMundOACgAAAO4"]
[Thu Jul 30 15:11:40.701748 2026] [security2:error] [pid 133043:tid 133298] [client 20.171.55.167:3621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/2019/08/w-1.php"] [unique_id "amuv_Ldt6aqtVvMundOADgAAAQI"]
[Thu Jul 30 15:11:40.895101 2026] [core:error] [pid 133043:tid 133280] [client 4.225.203.146:46650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:40.895129 2026] [core:error] [pid 133043:tid 133280] [client 4.225.203.146:46650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:40.922242 2026] [security2:error] [pid 133043:tid 133185] [client 20.171.55.167:10329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/file6.php"] [unique_id "amuv_Ldt6aqtVvMundOAEwAAAJE"]
[Thu Jul 30 15:11:40.967803 2026] [security2:error] [pid 133043:tid 133219] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/goods.php"] [unique_id "amuv_Ldt6aqtVvMundOAFAAAALM"]
[Thu Jul 30 15:11:40.967914 2026] [security2:error] [pid 133043:tid 133219] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/goods.php"] [unique_id "amuv_Ldt6aqtVvMundOAFAAAALM"]
[Thu Jul 30 15:11:41.239041 2026] [security2:error] [pid 133043:tid 133222] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amuv_bdt6aqtVvMundOAHAAAALY"]
[Thu Jul 30 15:11:41.239160 2026] [security2:error] [pid 133043:tid 133222] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amuv_bdt6aqtVvMundOAHAAAALY"]
[Thu Jul 30 15:11:41.375625 2026] [core:notice] [pid 133043:tid 133260] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:41.477971 2026] [security2:error] [pid 133043:tid 133253] [client 20.215.191.139:17991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuv_bdt6aqtVvMundOAIQAAANU"]
[Thu Jul 30 15:11:41.529202 2026] [security2:error] [pid 133043:tid 133254] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amuv_bdt6aqtVvMundOAIgAAANY"]
[Thu Jul 30 15:11:41.529311 2026] [security2:error] [pid 133043:tid 133254] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/about.php"] [unique_id "amuv_bdt6aqtVvMundOAIgAAANY"]
[Thu Jul 30 15:11:41.564331 2026] [security2:error] [pid 133043:tid 133161] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv_bdt6aqtVvMundOAJgAAu3U"]
[Thu Jul 30 15:11:41.564485 2026] [security2:error] [pid 133043:tid 133227] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuv_bdt6aqtVvMundOAJgAAu3U"]
[Thu Jul 30 15:11:41.595679 2026] [core:error] [pid 133043:tid 133284] [client 34.7.15.221:42260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.595708 2026] [core:error] [pid 133043:tid 133284] [client 34.7.15.221:42260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.595918 2026] [core:error] [pid 133043:tid 133250] [client 34.7.15.221:42220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.595935 2026] [core:error] [pid 133043:tid 133250] [client 34.7.15.221:42220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.596099 2026] [core:error] [pid 133043:tid 133272] [client 34.7.15.221:42244] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.596118 2026] [security2:error] [pid 133043:tid 133208] [client 34.7.15.221:42392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/configuration.php"] [unique_id "amuv_bdt6aqtVvMundOAMQAAAKg"]
[Thu Jul 30 15:11:41.596128 2026] [core:error] [pid 133043:tid 133272] [client 34.7.15.221:42244] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.596193 2026] [security2:error] [pid 133043:tid 133208] [client 34.7.15.221:42392] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/configuration.php"] [unique_id "amuv_bdt6aqtVvMundOAMQAAAKg"]
[Thu Jul 30 15:11:41.596226 2026] [security2:error] [pid 133043:tid 133196] [client 34.7.15.221:42352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "elitegaragedoorrepairservices.us"] [uri "/wp-config.php.old"] [unique_id "amuv_bdt6aqtVvMundOAMgAAAJw"]
[Thu Jul 30 15:11:41.596439 2026] [core:error] [pid 133043:tid 133279] [client 34.7.15.221:42222] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.596452 2026] [core:error] [pid 133043:tid 133279] [client 34.7.15.221:42222] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.596453 2026] [core:error] [pid 133043:tid 133240] [client 34.7.15.221:42262] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.596459 2026] [core:error] [pid 133043:tid 133239] [client 34.7.15.221:42228] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.596463 2026] [core:error] [pid 133043:tid 133240] [client 34.7.15.221:42262] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.596473 2026] [core:error] [pid 133043:tid 133239] [client 34.7.15.221:42228] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.597456 2026] [core:error] [pid 133043:tid 133297] [client 34.7.15.221:42316] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.597471 2026] [core:error] [pid 133043:tid 133297] [client 34.7.15.221:42316] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.597642 2026] [security2:error] [pid 133043:tid 133218] [client 34.7.15.221:42374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "elitegaragedoorrepairservices.us"] [uri "/wp-config.php.save"] [unique_id "amuv_bdt6aqtVvMundOAMwAAALI"]
[Thu Jul 30 15:11:41.597830 2026] [security2:error] [pid 133043:tid 133183] [client 34.7.15.221:42384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "elitegaragedoorrepairservices.us"] [uri "/wp-config.php.orig"] [unique_id "amuv_bdt6aqtVvMundOANAAAAI8"]
[Thu Jul 30 15:11:41.597896 2026] [security2:error] [pid 133043:tid 133183] [client 34.7.15.221:42384] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/wp-config.php.orig"] [unique_id "amuv_bdt6aqtVvMundOANAAAAI8"]
[Thu Jul 30 15:11:41.598294 2026] [core:error] [pid 133043:tid 133217] [client 34.7.15.221:42308] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.598312 2026] [core:error] [pid 133043:tid 133217] [client 34.7.15.221:42308] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.598848 2026] [core:error] [pid 133043:tid 133252] [client 34.7.15.221:42334] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.598864 2026] [core:error] [pid 133043:tid 133252] [client 34.7.15.221:42334] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.599103 2026] [core:error] [pid 133043:tid 133203] [client 34.7.15.221:42278] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.599116 2026] [core:error] [pid 133043:tid 133203] [client 34.7.15.221:42278] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.599158 2026] [security2:error] [pid 133043:tid 133242] [client 34.7.15.221:42406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config/config.php"] [unique_id "amuv_bdt6aqtVvMundOANgAAAMo"]
[Thu Jul 30 15:11:41.600917 2026] [security2:error] [pid 133043:tid 133248] [client 34.7.15.221:42368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "elitegaragedoorrepairservices.us"] [uri "/wp-config.php~"] [unique_id "amuv_bdt6aqtVvMundOAOgAAANA"]
[Thu Jul 30 15:11:41.600949 2026] [security2:error] [pid 133043:tid 133277] [client 34.7.15.221:42410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/database.php"] [unique_id "amuv_bdt6aqtVvMundOAOQAAAO0"]
[Thu Jul 30 15:11:41.601714 2026] [core:error] [pid 133043:tid 133269] [client 34.7.15.221:42358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.601728 2026] [core:error] [pid 133043:tid 133269] [client 34.7.15.221:42358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.607345 2026] [security2:error] [pid 133043:tid 133200] [client 34.7.15.221:42414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config.php.bak"] [unique_id "amuv_bdt6aqtVvMundOAQAAAAKA"]
[Thu Jul 30 15:11:41.611161 2026] [security2:error] [pid 133043:tid 133211] [client 34.7.15.221:42246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/api/config.json"] [unique_id "amuv_bdt6aqtVvMundOAQgAAAKs"]
[Thu Jul 30 15:11:41.613898 2026] [core:error] [pid 133043:tid 133274] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.613918 2026] [core:error] [pid 133043:tid 133274] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.616180 2026] [core:error] [pid 133043:tid 133192] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.616197 2026] [core:error] [pid 133043:tid 133192] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.616518 2026] [core:error] [pid 133043:tid 133251] [client 34.7.15.221:42294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.616528 2026] [core:error] [pid 133043:tid 133251] [client 34.7.15.221:42294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.617156 2026] [core:error] [pid 133043:tid 133190] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.617172 2026] [core:error] [pid 133043:tid 133190] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.617785 2026] [core:error] [pid 133043:tid 133186] [client 34.7.15.221:42340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.617796 2026] [core:error] [pid 133043:tid 133186] [client 34.7.15.221:42340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.618136 2026] [core:error] [pid 133043:tid 133193] [client 34.7.15.221:42328] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.618152 2026] [core:error] [pid 133043:tid 133193] [client 34.7.15.221:42328] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.619207 2026] [core:error] [pid 133043:tid 133270] [client 34.7.15.221:42320] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.619221 2026] [core:error] [pid 133043:tid 133270] [client 34.7.15.221:42320] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.620275 2026] [core:error] [pid 133043:tid 133220] [client 34.7.15.221:42380] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.620291 2026] [core:error] [pid 133043:tid 133220] [client 34.7.15.221:42380] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.621112 2026] [security2:error] [pid 133043:tid 133226] [client 34.7.15.221:42458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/config.yaml"] [unique_id "amuv_bdt6aqtVvMundOATgAAALo"]
[Thu Jul 30 15:11:41.621493 2026] [security2:error] [pid 133043:tid 133292] [client 34.7.15.221:42434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/db.php"] [unique_id "amuv_bdt6aqtVvMundOATwAAAPw"]
[Thu Jul 30 15:11:41.625470 2026] [core:error] [pid 133043:tid 133265] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.625484 2026] [core:error] [pid 133043:tid 133265] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.627593 2026] [core:error] [pid 133043:tid 133195] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.627609 2026] [core:error] [pid 133043:tid 133195] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:41.708722 2026] [security2:error] [pid 133043:tid 133283] [client 172.237.109.114:25903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuv_bdt6aqtVvMundOAGwAAAPM"]
[Thu Jul 30 15:11:41.710659 2026] [security2:error] [pid 133043:tid 133276] [client 20.171.55.167:10346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/filedokumenk.php"] [unique_id "amuv_bdt6aqtVvMundOAVgAAAOw"]
[Thu Jul 30 15:11:41.735675 2026] [security2:error] [pid 133043:tid 133259] [client 20.171.55.167:3419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/32O7x8UeIG.php"] [unique_id "amuv_bdt6aqtVvMundOAVwAAANs"]
[Thu Jul 30 15:11:41.809172 2026] [security2:error] [pid 133043:tid 133287] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuv_bdt6aqtVvMundOAWwAAAPc"]
[Thu Jul 30 15:11:41.809274 2026] [security2:error] [pid 133043:tid 133287] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/admin.php"] [unique_id "amuv_bdt6aqtVvMundOAWwAAAPc"]
[Thu Jul 30 15:11:41.844346 2026] [core:notice] [pid 133043:tid 133238] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:41.975632 2026] [security2:error] [pid 133043:tid 133206] [client 4.225.203.146:46621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wso.php"] [unique_id "amuv_bdt6aqtVvMundOAYAAAAKY"]
[Thu Jul 30 15:11:42.080612 2026] [security2:error] [pid 133043:tid 133252] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amuv_rdt6aqtVvMundOAYgAAANQ"]
[Thu Jul 30 15:11:42.080712 2026] [security2:error] [pid 133043:tid 133252] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amuv_rdt6aqtVvMundOAYgAAANQ"]
[Thu Jul 30 15:11:42.408133 2026] [security2:error] [pid 133043:tid 133201] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amuv_rdt6aqtVvMundOAawAAAKE"]
[Thu Jul 30 15:11:42.408233 2026] [security2:error] [pid 133043:tid 133201] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/inputs.php"] [unique_id "amuv_rdt6aqtVvMundOAawAAAKE"]
[Thu Jul 30 15:11:42.540361 2026] [security2:error] [pid 133043:tid 133223] [client 82.102.27.163:45848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuv_rdt6aqtVvMundOAbAAAALc"]
[Thu Jul 30 15:11:42.540476 2026] [security2:error] [pid 133043:tid 133223] [client 82.102.27.163:45848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuv_rdt6aqtVvMundOAbAAAALc"]
[Thu Jul 30 15:11:42.612039 2026] [fcgid:warn] [pid 133043:tid 133270] (70014)End of file found: [client 66.132.195.57:38024] mod_fcgid: can't get data from http client
[Thu Jul 30 15:11:42.628968 2026] [security2:error] [pid 133043:tid 133210] [client 20.171.55.167:10606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/fix/up.php"] [unique_id "amuv_rdt6aqtVvMundOAcQAAAKo"]
[Thu Jul 30 15:11:42.673532 2026] [security2:error] [pid 133043:tid 133251] [client 20.171.55.167:3379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/529.php"] [unique_id "amuv_rdt6aqtVvMundOAcgAAANM"]
[Thu Jul 30 15:11:42.694867 2026] [security2:error] [pid 133043:tid 133265] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/adminfuns.php"] [unique_id "amuv_rdt6aqtVvMundOAcwAAAOE"]
[Thu Jul 30 15:11:42.694969 2026] [security2:error] [pid 133043:tid 133265] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/adminfuns.php"] [unique_id "amuv_rdt6aqtVvMundOAcwAAAOE"]
[Thu Jul 30 15:11:42.975396 2026] [security2:error] [pid 133043:tid 133298] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/404.php"] [unique_id "amuv_rdt6aqtVvMundOAewAAAQI"]
[Thu Jul 30 15:11:42.975513 2026] [security2:error] [pid 133043:tid 133298] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/404.php"] [unique_id "amuv_rdt6aqtVvMundOAewAAAQI"]
[Thu Jul 30 15:11:43.278941 2026] [security2:error] [pid 133043:tid 133280] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xxx.php"] [unique_id "amuv_7dt6aqtVvMundOAgwAAAPA"]
[Thu Jul 30 15:11:43.279096 2026] [security2:error] [pid 133043:tid 133280] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/xxx.php"] [unique_id "amuv_7dt6aqtVvMundOAgwAAAPA"]
[Thu Jul 30 15:11:43.499246 2026] [security2:error] [pid 133043:tid 133246] [client 20.171.55.167:10341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/foxx.php"] [unique_id "amuv_7dt6aqtVvMundOAhwAAAM4"]
[Thu Jul 30 15:11:43.556849 2026] [security2:error] [pid 133043:tid 133237] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/classwithtostring.php"] [unique_id "amuv_7dt6aqtVvMundOAiAAAAMU"]
[Thu Jul 30 15:11:43.556948 2026] [security2:error] [pid 133043:tid 133237] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/classwithtostring.php"] [unique_id "amuv_7dt6aqtVvMundOAiAAAAMU"]
[Thu Jul 30 15:11:43.571823 2026] [security2:error] [pid 133043:tid 133197] [client 20.171.55.167:3598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/;k.php"] [unique_id "amuv_7dt6aqtVvMundOAigAAAJ0"]
[Thu Jul 30 15:11:43.603984 2026] [security2:error] [pid 133043:tid 133269] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuv_rdt6aqtVvMundOAegAA5V4"]
[Thu Jul 30 15:11:43.793712 2026] [security2:error] [pid 133043:tid 133276] [client 20.215.191.139:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuv_7dt6aqtVvMundOAkgAAAOw"]
[Thu Jul 30 15:11:43.798378 2026] [security2:error] [pid 133043:tid 133232] [client 82.102.27.163:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuv_7dt6aqtVvMundOAkwAAAMA"]
[Thu Jul 30 15:11:43.798504 2026] [security2:error] [pid 133043:tid 133232] [client 82.102.27.163:57900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuv_7dt6aqtVvMundOAkwAAAMA"]
[Thu Jul 30 15:11:43.844154 2026] [security2:error] [pid 133043:tid 133236] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/234ff.php"] [unique_id "amuv_7dt6aqtVvMundOAlAAAAMQ"]
[Thu Jul 30 15:11:43.844259 2026] [security2:error] [pid 133043:tid 133236] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/234ff.php"] [unique_id "amuv_7dt6aqtVvMundOAlAAAAMQ"]
[Thu Jul 30 15:11:43.991086 2026] [core:notice] [pid 133043:tid 133266] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:44.130610 2026] [security2:error] [pid 133043:tid 133264] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/133.php"] [unique_id "amuwALdt6aqtVvMundOAnAAAAOA"]
[Thu Jul 30 15:11:44.130723 2026] [security2:error] [pid 133043:tid 133264] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/133.php"] [unique_id "amuwALdt6aqtVvMundOAnAAAAOA"]
[Thu Jul 30 15:11:44.310632 2026] [security2:error] [pid 133043:tid 133207] [client 20.171.55.167:10592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/geck.php"] [unique_id "amuwALdt6aqtVvMundOApgAAAKc"]
[Thu Jul 30 15:11:44.384840 2026] [security2:error] [pid 133043:tid 133239] [client 34.7.15.221:17662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/web.config"] [unique_id "amuwALdt6aqtVvMundOAqQAAAMc"]
[Thu Jul 30 15:11:44.387634 2026] [core:error] [pid 133043:tid 133224] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.387651 2026] [core:error] [pid 133043:tid 133224] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.391787 2026] [security2:error] [pid 133043:tid 133218] [client 34.7.15.221:17698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/docker-compose.yaml"] [unique_id "amuwALdt6aqtVvMundOArwAAALI"]
[Thu Jul 30 15:11:44.391858 2026] [security2:error] [pid 133043:tid 133218] [client 34.7.15.221:17698] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/docker-compose.yaml"] [unique_id "amuwALdt6aqtVvMundOArwAAALI"]
[Thu Jul 30 15:11:44.399442 2026] [core:error] [pid 133043:tid 133201] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.399459 2026] [core:error] [pid 133043:tid 133201] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.399554 2026] [core:error] [pid 133043:tid 133223] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.399565 2026] [core:error] [pid 133043:tid 133223] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.402378 2026] [security2:error] [pid 133043:tid 133291] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-ws68.php"] [unique_id "amuwALdt6aqtVvMundOAswAAAPs"]
[Thu Jul 30 15:11:44.402464 2026] [security2:error] [pid 133043:tid 133291] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/wp-ws68.php"] [unique_id "amuwALdt6aqtVvMundOAswAAAPs"]
[Thu Jul 30 15:11:44.419368 2026] [core:error] [pid 133043:tid 133263] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.419380 2026] [core:error] [pid 133043:tid 133216] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.419385 2026] [core:error] [pid 133043:tid 133263] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.419391 2026] [core:error] [pid 133043:tid 133216] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.420929 2026] [core:error] [pid 133043:tid 133286] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.420943 2026] [core:error] [pid 133043:tid 133286] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:44.421054 2026] [security2:error] [pid 133043:tid 133286] [client 34.7.15.221:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/index.php"] [unique_id "amuwALdt6aqtVvMundOAvgAAAPY"]
[Thu Jul 30 15:11:44.421547 2026] [security2:error] [pid 133043:tid 133248] [client 34.7.15.221:17678] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elitegaragedoorrepairservices.us"] [uri "/application.yaml"] [unique_id "amuwALdt6aqtVvMundOAuAAAANA"]
[Thu Jul 30 15:11:44.673403 2026] [security2:error] [pid 133043:tid 133234] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/mgrr.php"] [unique_id "amuwALdt6aqtVvMundOAwAAAAMI"]
[Thu Jul 30 15:11:44.673525 2026] [security2:error] [pid 133043:tid 133234] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/mgrr.php"] [unique_id "amuwALdt6aqtVvMundOAwAAAAMI"]
[Thu Jul 30 15:11:44.906212 2026] [security2:error] [pid 133043:tid 133211] [client 20.171.55.167:3623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/Canonical.php"] [unique_id "amuwALdt6aqtVvMundOAyAAAAKs"]
[Thu Jul 30 15:11:44.957257 2026] [security2:error] [pid 133043:tid 133180] [client 20.215.216.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.216.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/55.php"] [unique_id "amuwALdt6aqtVvMundOAzAAAAIw"]
[Thu Jul 30 15:11:44.957362 2026] [security2:error] [pid 133043:tid 133180] [client 20.215.216.94:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.bestdogproductguide.com"] [uri "/55.php"] [unique_id "amuwALdt6aqtVvMundOAzAAAAIw"]
[Thu Jul 30 15:11:45.643334 2026] [core:error] [pid 133043:tid 133049] [remote 157.55.39.58:2342] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:45.643361 2026] [core:error] [pid 133043:tid 133049] [remote 157.55.39.58:2342] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:45.880234 2026] [security2:error] [pid 133043:tid 133293] [client 20.171.55.167:10498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/gmo.php"] [unique_id "amuwAbdt6aqtVvMundOA4wAAAP0"]
[Thu Jul 30 15:11:45.945081 2026] [core:notice] [pid 133043:tid 133257] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:45.993136 2026] [security2:error] [pid 133043:tid 133272] [client 20.171.55.167:3358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/Diff/Renderer/alfa-rex.php"] [unique_id "amuwAbdt6aqtVvMundOA7AAAAOg"]
[Thu Jul 30 15:11:46.167769 2026] [security2:error] [pid 133043:tid 133238] [client 20.215.191.139:18000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.worldofwhiskers.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuwAbdt6aqtVvMundOA5QAAAMY"]
[Thu Jul 30 15:11:46.719132 2026] [security2:error] [pid 133043:tid 133279] [client 4.225.203.146:21778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/ioxi-o.php"] [unique_id "amuwArdt6aqtVvMundOA_AAAAO8"]
[Thu Jul 30 15:11:46.849687 2026] [security2:error] [pid 133043:tid 133252] [client 20.171.55.167:10362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/gzdecode.php"] [unique_id "amuwArdt6aqtVvMundOA_QAAANQ"]
[Thu Jul 30 15:11:46.931773 2026] [security2:error] [pid 133043:tid 133215] [client 20.171.55.167:3990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/FroggBaba.php"] [unique_id "amuwArdt6aqtVvMundOBAAAAAK8"]
[Thu Jul 30 15:11:47.215812 2026] [security2:error] [pid 133043:tid 133174] [client 20.215.191.139:53431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/011i.php"] [unique_id "amuwA7dt6aqtVvMundOBCQAAAIY"]
[Thu Jul 30 15:11:47.450828 2026] [security2:error] [pid 133043:tid 133249] [client 34.7.15.221:17726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/storage/logs/laravel.log"] [unique_id "amuwA7dt6aqtVvMundOBEwAAANE"]
[Thu Jul 30 15:11:47.454087 2026] [security2:error] [pid 133043:tid 133299] [client 34.7.15.221:17768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/db.sql"] [unique_id "amuwA7dt6aqtVvMundOBFAAAAQM"]
[Thu Jul 30 15:11:47.454336 2026] [security2:error] [pid 133043:tid 133275] [client 34.7.15.221:17756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/backup.sql"] [unique_id "amuwA7dt6aqtVvMundOBFQAAAOs"]
[Thu Jul 30 15:11:47.456899 2026] [security2:error] [pid 133043:tid 133288] [client 34.7.15.221:17792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/dump.sql"] [unique_id "amuwA7dt6aqtVvMundOBFgAAAPg"]
[Thu Jul 30 15:11:47.472427 2026] [core:error] [pid 133043:tid 133235] [client 34.7.15.221:17740] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:47.472447 2026] [core:error] [pid 133043:tid 133235] [client 34.7.15.221:17740] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:47.472687 2026] [core:error] [pid 133043:tid 133236] [client 34.7.15.221:17720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:47.472702 2026] [core:error] [pid 133043:tid 133236] [client 34.7.15.221:17720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:47.472966 2026] [core:error] [pid 133043:tid 133261] [client 34.7.15.221:17728] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:47.472994 2026] [core:error] [pid 133043:tid 133261] [client 34.7.15.221:17728] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:47.474413 2026] [security2:error] [pid 133043:tid 133290] [client 34.7.15.221:17780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/database.sql"] [unique_id "amuwA7dt6aqtVvMundOBHAAAAPo"]
[Thu Jul 30 15:11:47.481692 2026] [core:error] [pid 133043:tid 133287] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:47.481708 2026] [core:error] [pid 133043:tid 133287] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:47.601922 2026] [core:notice] [pid 133043:tid 133300] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:47.754899 2026] [security2:error] [pid 133043:tid 133240] [client 20.171.55.167:10342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/hi.php"] [unique_id "amuwA7dt6aqtVvMundOBIwAAAMg"]
[Thu Jul 30 15:11:47.868138 2026] [security2:error] [pid 133043:tid 133254] [client 20.171.55.167:3610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/Mhbgf.php/wp-content/themes/travelscape/json.php"] [unique_id "amuwA7dt6aqtVvMundOBJQAAANY"]
[Thu Jul 30 15:11:48.541319 2026] [security2:error] [pid 133043:tid 133263] [client 20.171.55.167:10304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/i0004en.php//bk/index.php"] [unique_id "amuwBLdt6aqtVvMundOBNQAAAN8"]
[Thu Jul 30 15:11:48.709588 2026] [security2:error] [pid 133043:tid 133242] [client 20.171.55.167:3375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/RxR_litwf.php"] [unique_id "amuwBLdt6aqtVvMundOBOQAAAMo"]
[Thu Jul 30 15:11:48.985394 2026] [security2:error] [pid 133043:tid 133219] [client 4.225.203.146:22525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/file56.php"] [unique_id "amuwBLdt6aqtVvMundOBQAAAALM"]
[Thu Jul 30 15:11:49.018648 2026] [core:notice] [pid 133043:tid 133215] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:49.346956 2026] [security2:error] [pid 133043:tid 133237] [client 20.215.191.139:21246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/03a005685d.php"] [unique_id "amuwBbdt6aqtVvMundOBSgAAAMU"]
[Thu Jul 30 15:11:49.466281 2026] [security2:error] [pid 133043:tid 133197] [client 20.171.55.167:10361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/imagealfa.php"] [unique_id "amuwBbdt6aqtVvMundOBSwAAAJ0"]
[Thu Jul 30 15:11:49.561819 2026] [security2:error] [pid 133043:tid 133084] [remote 74.7.243.224:37048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/article.php"] [unique_id "amuwBbdt6aqtVvMundOBUgAAhig"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/img/1784117897_IMG_1213.jpg
[Thu Jul 30 15:11:49.564671 2026] [security2:error] [pid 133043:tid 133211] [client 20.171.55.167:3978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/Text/index.php"] [unique_id "amuwBbdt6aqtVvMundOBUwAAAKs"]
[Thu Jul 30 15:11:49.701312 2026] [security2:error] [pid 133043:tid 133268] [client 34.74.242.206:1596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nordeste1.com"] [uri "/robots.txt"] [unique_id "amuwBbdt6aqtVvMundOBVwAAAOQ"]
[Thu Jul 30 15:11:49.701421 2026] [security2:error] [pid 133043:tid 133268] [client 34.74.242.206:1596] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nordeste1.com"] [uri "/robots.txt"] [unique_id "amuwBbdt6aqtVvMundOBVwAAAOQ"]
[Thu Jul 30 15:11:49.992940 2026] [fcgid:warn] [pid 133043:tid 133294] (70014)End of file found: [client 34.7.15.221:17808] mod_fcgid: can't get data from http client
[Thu Jul 30 15:11:50.148320 2026] [security2:error] [pid 133043:tid 133182] [client 34.74.242.206:1599] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nordeste1.com"] [uri "/"] [unique_id "amuwBrdt6aqtVvMundOBaQAAAI4"]
[Thu Jul 30 15:11:50.148427 2026] [security2:error] [pid 133043:tid 133182] [client 34.74.242.206:1599] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nordeste1.com"] [uri "/"] [unique_id "amuwBrdt6aqtVvMundOBaQAAAI4"]
[Thu Jul 30 15:11:50.395217 2026] [security2:error] [pid 133043:tid 133224] [client 20.171.55.167:3647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/Ysuyo.php"] [unique_id "amuwBrdt6aqtVvMundOBagAAALg"]
[Thu Jul 30 15:11:50.396497 2026] [security2:error] [pid 133043:tid 133217] [client 20.171.55.167:10334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/includeswp-conflg.php"] [unique_id "amuwBrdt6aqtVvMundOBawAAALE"]
[Thu Jul 30 15:11:51.097345 2026] [core:notice] [pid 133043:tid 133272] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:51.320264 2026] [security2:error] [pid 133043:tid 133230] [client 20.171.55.167:10601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/instaall.php"] [unique_id "amuwB7dt6aqtVvMundOBigAAAL4"]
[Thu Jul 30 15:11:51.484832 2026] [security2:error] [pid 133043:tid 133256] [client 4.225.203.146:21819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuwB7dt6aqtVvMundOBjQAAANg"]
[Thu Jul 30 15:11:51.512676 2026] [security2:error] [pid 133043:tid 133280] [client 223.82.228.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuwB7dt6aqtVvMundOBhQAAAPA"], referer: https://smoke-tfhk.com/wp-json/wp/v2/product/3088
[Thu Jul 30 15:11:51.560682 2026] [core:error] [pid 133043:tid 133096] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/staging/
[Thu Jul 30 15:11:51.560720 2026] [core:error] [pid 133043:tid 133096] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/staging/
[Thu Jul 30 15:11:51.561904 2026] [security2:error] [pid 133043:tid 133104] [remote 40.77.167.14:50503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JSHR/login/lostPassword"] [unique_id "amuwB7dt6aqtVvMundOBiAAAxTw"]
[Thu Jul 30 15:11:51.748523 2026] [core:notice] [pid 133043:tid 133273] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:51.853898 2026] [security2:error] [pid 133043:tid 133209] [client 146.103.113.214:64468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.113.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuwB7dt6aqtVvMundOBmwAAAKk"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 15:11:51.957253 2026] [security2:error] [pid 133043:tid 133271] [client 20.171.55.167:3619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/ac.php"] [unique_id "amuwB7dt6aqtVvMundOBnwAAAOc"]
[Thu Jul 30 15:11:52.115753 2026] [security2:error] [pid 133043:tid 133214] [client 20.171.55.167:10506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/iqb.php"] [unique_id "amuwCLdt6aqtVvMundOBowAAAK4"]
[Thu Jul 30 15:11:52.176173 2026] [security2:error] [pid 133043:tid 133079] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwCLdt6aqtVvMundOBpQAAoyM"]
[Thu Jul 30 15:11:52.176313 2026] [security2:error] [pid 133043:tid 133203] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwCLdt6aqtVvMundOBpQAAoyM"]
[Thu Jul 30 15:11:52.454325 2026] [security2:error] [pid 133043:tid 133111] [remote 57.141.0.53:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/66526086350/feed/rss2/"] [unique_id "amuwCLdt6aqtVvMundOBrAAAx0M"]
[Thu Jul 30 15:11:52.488494 2026] [security2:error] [pid 133043:tid 133274] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwB7dt6aqtVvMundOBngAAAOo"]
[Thu Jul 30 15:11:52.495844 2026] [core:notice] [pid 133043:tid 133270] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:52.499081 2026] [core:notice] [pid 133043:tid 133233] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:52.706593 2026] [core:error] [pid 133043:tid 133118] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/
[Thu Jul 30 15:11:52.706618 2026] [core:error] [pid 133043:tid 133118] [remote 195.178.110.104:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.germanyvisasupportcenterislamabad.website/
[Thu Jul 30 15:11:52.852727 2026] [security2:error] [pid 133043:tid 133212] [client 20.171.55.167:3998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/admin-functions.php"] [unique_id "amuwCLdt6aqtVvMundOBuQAAAKw"]
[Thu Jul 30 15:11:52.941736 2026] [security2:error] [pid 133043:tid 133262] [client 20.171.55.167:10348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/joomlabypass.php"] [unique_id "amuwCLdt6aqtVvMundOBugAAAN4"]
[Thu Jul 30 15:11:52.960639 2026] [core:notice] [pid 133043:tid 133242] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:52.964390 2026] [core:notice] [pid 133043:tid 133219] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:53.249736 2026] [fcgid:warn] [pid 133043:tid 133185] (70014)End of file found: [client 34.7.15.221:17818] mod_fcgid: can't get data from http client
[Thu Jul 30 15:11:53.269197 2026] [security2:error] [pid 133043:tid 133210] [client 34.7.15.221:17830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/index.php"] [unique_id "amuwCbdt6aqtVvMundOByQAAAKo"]
[Thu Jul 30 15:11:53.298833 2026] [security2:error] [pid 133043:tid 133293] [client 4.225.203.146:21762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuwCbdt6aqtVvMundOBygAAAP0"]
[Thu Jul 30 15:11:53.770603 2026] [security2:error] [pid 133043:tid 133241] [client 51.68.111.219:24549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hello-pal.com"] [uri "/robots.txt"] [unique_id "amuwCbdt6aqtVvMundOB1gAAAMk"]
[Thu Jul 30 15:11:53.770734 2026] [security2:error] [pid 133043:tid 133241] [client 51.68.111.219:24549] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.hello-pal.com"] [uri "/robots.txt"] [unique_id "amuwCbdt6aqtVvMundOB1gAAAMk"]
[Thu Jul 30 15:11:53.777495 2026] [security2:error] [pid 133043:tid 133287] [client 20.171.55.167:3987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/administratorwp.php"] [unique_id "amuwCbdt6aqtVvMundOB1wAAAPc"]
[Thu Jul 30 15:11:53.867511 2026] [security2:error] [pid 133043:tid 133288] [client 20.171.55.167:10581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/karak.php"] [unique_id "amuwCbdt6aqtVvMundOB3AAAAPg"]
[Thu Jul 30 15:11:54.166615 2026] [security2:error] [pid 133043:tid 133202] [client 4.225.203.146:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/edit.php"] [unique_id "amuwCrdt6aqtVvMundOB4wAAAKI"]
[Thu Jul 30 15:11:54.306146 2026] [security2:error] [pid 133043:tid 133251] [client 146.103.113.214:64577] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuwCrdt6aqtVvMundOB6gAAANM"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 15:11:54.340836 2026] [core:notice] [pid 133043:tid 133224] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:54.384176 2026] [security2:error] [pid 133043:tid 133220] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuwCrdt6aqtVvMundOB7AAAALQ"]
[Thu Jul 30 15:11:54.384298 2026] [security2:error] [pid 133043:tid 133220] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuwCrdt6aqtVvMundOB7AAAALQ"]
[Thu Jul 30 15:11:54.535238 2026] [security2:error] [pid 133043:tid 133269] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwCbdt6aqtVvMundOB2QAA5VM"]
[Thu Jul 30 15:11:54.699829 2026] [security2:error] [pid 133043:tid 133248] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuwCrdt6aqtVvMundOB8AAAANA"]
[Thu Jul 30 15:11:54.699943 2026] [security2:error] [pid 133043:tid 133248] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuwCrdt6aqtVvMundOB8AAAANA"]
[Thu Jul 30 15:11:54.726331 2026] [security2:error] [pid 133043:tid 133270] [client 20.171.55.167:3400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/akcc.php"] [unique_id "amuwCrdt6aqtVvMundOB8gAAAOY"]
[Thu Jul 30 15:11:54.764874 2026] [security2:error] [pid 133043:tid 133260] [client 20.171.55.167:10505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/leaf_php.php"] [unique_id "amuwCrdt6aqtVvMundOB9gAAANw"]
[Thu Jul 30 15:11:54.926028 2026] [core:notice] [pid 133043:tid 133216] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:55.039366 2026] [security2:error] [pid 133043:tid 133198] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuwC7dt6aqtVvMundOB_gAAAJ4"]
[Thu Jul 30 15:11:55.039471 2026] [security2:error] [pid 133043:tid 133198] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuwC7dt6aqtVvMundOB_gAAAJ4"]
[Thu Jul 30 15:11:55.201020 2026] [security2:error] [pid 133043:tid 133286] [client 219.92.196.15:58637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.196.92.219.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/xmlrpc.php"] [unique_id "amuwCrdt6aqtVvMundOB8QAAAPY"]
[Thu Jul 30 15:11:55.201182 2026] [security2:error] [pid 133043:tid 133286] [client 219.92.196.15:58637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arabiantourz.com"] [uri "/xmlrpc.php"] [unique_id "amuwCrdt6aqtVvMundOB8QAAAPY"]
[Thu Jul 30 15:11:55.378098 2026] [security2:error] [pid 133043:tid 133256] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/err.php"] [unique_id "amuwC7dt6aqtVvMundOCBgAAANg"]
[Thu Jul 30 15:11:55.378220 2026] [security2:error] [pid 133043:tid 133256] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/err.php"] [unique_id "amuwC7dt6aqtVvMundOCBgAAANg"]
[Thu Jul 30 15:11:55.525816 2026] [security2:error] [pid 133043:tid 133282] [client 20.171.55.167:3451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/alfacgiapi/bypass.php"] [unique_id "amuwC7dt6aqtVvMundOCCgAAAPI"]
[Thu Jul 30 15:11:55.535012 2026] [security2:error] [pid 133043:tid 133229] [client 4.225.203.146:16451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/2.php"] [unique_id "amuwC7dt6aqtVvMundOCCwAAAL0"]
[Thu Jul 30 15:11:55.536232 2026] [security2:error] [pid 133043:tid 133178] [client 20.215.191.139:64714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/403.php"] [unique_id "amuwC7dt6aqtVvMundOCDAAAAIo"]
[Thu Jul 30 15:11:55.588587 2026] [security2:error] [pid 133043:tid 133252] [client 20.171.55.167:10568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/linkpreview/alfa.php"] [unique_id "amuwC7dt6aqtVvMundOCDQAAANQ"]
[Thu Jul 30 15:11:55.634640 2026] [security2:error] [pid 133043:tid 133230] [client 172.237.109.114:41548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwC7dt6aqtVvMundOB_wAAAL4"]
[Thu Jul 30 15:11:55.718644 2026] [security2:error] [pid 133043:tid 133296] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/img.php"] [unique_id "amuwC7dt6aqtVvMundOCDwAAAQA"]
[Thu Jul 30 15:11:55.718748 2026] [security2:error] [pid 133043:tid 133296] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/img.php"] [unique_id "amuwC7dt6aqtVvMundOCDwAAAQA"]
[Thu Jul 30 15:11:55.839744 2026] [security2:error] [pid 133043:tid 133181] [client 45.227.253.15:36614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/index.php/jk"] [unique_id "amuwC7dt6aqtVvMundOCEgAAAI0"]
[Thu Jul 30 15:11:56.051743 2026] [fcgid:warn] [pid 133043:tid 133273] (70014)End of file found: [client 34.7.15.221:43300] mod_fcgid: can't get data from http client
[Thu Jul 30 15:11:56.054408 2026] [security2:error] [pid 133043:tid 133268] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/aa.php"] [unique_id "amuwDLdt6aqtVvMundOCGQAAAOQ"]
[Thu Jul 30 15:11:56.054510 2026] [security2:error] [pid 133043:tid 133268] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/aa.php"] [unique_id "amuwDLdt6aqtVvMundOCGQAAAOQ"]
[Thu Jul 30 15:11:56.066501 2026] [core:error] [pid 133043:tid 133240] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:56.066522 2026] [core:error] [pid 133043:tid 133240] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:56.219799 2026] [security2:error] [pid 133043:tid 133283] [client 20.215.191.139:23919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/404.php"] [unique_id "amuwDLdt6aqtVvMundOCIAAAAPM"]
[Thu Jul 30 15:11:56.380569 2026] [security2:error] [pid 133043:tid 133226] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/av.php"] [unique_id "amuwDLdt6aqtVvMundOCJwAAALo"]
[Thu Jul 30 15:11:56.380688 2026] [security2:error] [pid 133043:tid 133226] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/av.php"] [unique_id "amuwDLdt6aqtVvMundOCJwAAALo"]
[Thu Jul 30 15:11:56.505180 2026] [security2:error] [pid 133043:tid 133267] [client 20.171.55.167:3376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/alfax.php"] [unique_id "amuwDLdt6aqtVvMundOCKgAAAOM"]
[Thu Jul 30 15:11:56.544144 2026] [security2:error] [pid 133043:tid 133257] [client 20.171.55.167:10501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/lnedx.php"] [unique_id "amuwDLdt6aqtVvMundOCKwAAANk"]
[Thu Jul 30 15:11:56.681004 2026] [security2:error] [pid 133043:tid 133248] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xa.php"] [unique_id "amuwDLdt6aqtVvMundOCLwAAANA"]
[Thu Jul 30 15:11:56.681089 2026] [security2:error] [pid 133043:tid 133248] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xa.php"] [unique_id "amuwDLdt6aqtVvMundOCLwAAANA"]
[Thu Jul 30 15:11:57.020495 2026] [security2:error] [pid 133043:tid 133280] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/media.php"] [unique_id "amuwDbdt6aqtVvMundOCPAAAAPA"]
[Thu Jul 30 15:11:57.020658 2026] [security2:error] [pid 133043:tid 133280] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/media.php"] [unique_id "amuwDbdt6aqtVvMundOCPAAAAPA"]
[Thu Jul 30 15:11:57.143613 2026] [core:notice] [pid 133043:tid 133260] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:57.147345 2026] [security2:error] [pid 133043:tid 133260] [client 74.0.19.9:36789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/9214"] [unique_id "amuwDbdt6aqtVvMundOCQgAAANw"]
[Thu Jul 30 15:11:57.303208 2026] [security2:error] [pid 133043:tid 133229] [client 20.171.55.167:3201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/ant.php"] [unique_id "amuwDbdt6aqtVvMundOCRgAAAL0"]
[Thu Jul 30 15:11:57.354284 2026] [security2:error] [pid 133043:tid 133287] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/images.php"] [unique_id "amuwDbdt6aqtVvMundOCSAAAAPc"]
[Thu Jul 30 15:11:57.354444 2026] [security2:error] [pid 133043:tid 133287] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/images.php"] [unique_id "amuwDbdt6aqtVvMundOCSAAAAPc"]
[Thu Jul 30 15:11:57.603848 2026] [security2:error] [pid 133043:tid 133253] [client 172.237.109.114:22517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwDbdt6aqtVvMundOCQQAAANU"]
[Thu Jul 30 15:11:57.666430 2026] [security2:error] [pid 133043:tid 133182] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/gecko.php"] [unique_id "amuwDbdt6aqtVvMundOCWQAAAI4"]
[Thu Jul 30 15:11:57.666547 2026] [security2:error] [pid 133043:tid 133182] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/gecko.php"] [unique_id "amuwDbdt6aqtVvMundOCWQAAAI4"]
[Thu Jul 30 15:11:57.734038 2026] [security2:error] [pid 133043:tid 133290] [client 146.103.113.214:64913] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuwDbdt6aqtVvMundOCWgAAAPo"], referer: https://shorewooddaycare.com/contact.php?status=tour-invalid#tour-form
[Thu Jul 30 15:11:57.987483 2026] [security2:error] [pid 133043:tid 133223] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/82.php"] [unique_id "amuwDbdt6aqtVvMundOCXwAAALc"]
[Thu Jul 30 15:11:57.987576 2026] [security2:error] [pid 133043:tid 133223] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/82.php"] [unique_id "amuwDbdt6aqtVvMundOCXwAAALc"]
[Thu Jul 30 15:11:58.013457 2026] [core:notice] [pid 133043:tid 133243] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:58.261808 2026] [security2:error] [pid 133043:tid 133224] [client 20.171.55.167:3601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/applicationwp.php"] [unique_id "amuwDrdt6aqtVvMundOCaAAAALg"]
[Thu Jul 30 15:11:58.298720 2026] [security2:error] [pid 133043:tid 133234] [client 20.171.55.167:10510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/luxx.php"] [unique_id "amuwDrdt6aqtVvMundOCaQAAAMI"]
[Thu Jul 30 15:11:58.307309 2026] [security2:error] [pid 133043:tid 133270] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xstelth.php"] [unique_id "amuwDrdt6aqtVvMundOCagAAAOY"]
[Thu Jul 30 15:11:58.307457 2026] [security2:error] [pid 133043:tid 133270] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xstelth.php"] [unique_id "amuwDrdt6aqtVvMundOCagAAAOY"]
[Thu Jul 30 15:11:58.347053 2026] [security2:error] [pid 133043:tid 133158] [remote 209.42.28.28:35822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.28.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuwDrdt6aqtVvMundOCawAA4XI"]
[Thu Jul 30 15:11:58.607612 2026] [security2:error] [pid 133043:tid 133198] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xp.php"] [unique_id "amuwDrdt6aqtVvMundOCcwAAAJ4"]
[Thu Jul 30 15:11:58.607720 2026] [security2:error] [pid 133043:tid 133198] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xp.php"] [unique_id "amuwDrdt6aqtVvMundOCcwAAAJ4"]
[Thu Jul 30 15:11:58.640178 2026] [core:notice] [pid 133043:tid 133213] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:11:58.675262 2026] [security2:error] [pid 133043:tid 133138] [remote 57.141.0.6:46632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/491057609/feed/rss2/"] [unique_id "amuwDrdt6aqtVvMundOCeAAAkl4"]
[Thu Jul 30 15:11:58.932588 2026] [security2:error] [pid 133043:tid 133280] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuwDrdt6aqtVvMundOCegAAAPA"]
[Thu Jul 30 15:11:58.932739 2026] [security2:error] [pid 133043:tid 133280] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuwDrdt6aqtVvMundOCegAAAPA"]
[Thu Jul 30 15:11:59.248993 2026] [security2:error] [pid 133043:tid 133294] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/adminner.php"] [unique_id "amuwD7dt6aqtVvMundOChwAAAP4"]
[Thu Jul 30 15:11:59.249092 2026] [security2:error] [pid 133043:tid 133294] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/adminner.php"] [unique_id "amuwD7dt6aqtVvMundOChwAAAP4"]
[Thu Jul 30 15:11:59.301162 2026] [security2:error] [pid 133043:tid 133221] [client 20.171.55.167:10344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/maintenance.php"] [unique_id "amuwD7dt6aqtVvMundOCiAAAALU"]
[Thu Jul 30 15:11:59.536759 2026] [security2:error] [pid 133043:tid 133276] [client 34.7.15.221:43326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/?\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/"] [unique_id "amuwD7dt6aqtVvMundOCpQAAAOw"]
[Thu Jul 30 15:11:59.540658 2026] [security2:error] [pid 133043:tid 133254] [client 4.225.203.146:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuwD7dt6aqtVvMundOCpwAAANY"]
[Thu Jul 30 15:11:59.554611 2026] [core:error] [pid 133043:tid 133295] [client 34.7.15.221:43320] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Thu Jul 30 15:11:59.566403 2026] [core:error] [pid 133043:tid 133191] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:59.566429 2026] [core:error] [pid 133043:tid 133191] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:59.654180 2026] [security2:error] [pid 133043:tid 133210] [client 20.171.55.167:3599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/asetwp.php"] [unique_id "amuwD7dt6aqtVvMundOCrQAAAKo"]
[Thu Jul 30 15:11:59.692699 2026] [core:error] [pid 133043:tid 133053] [remote 207.46.13.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:59.692717 2026] [core:error] [pid 133043:tid 133053] [remote 207.46.13.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:11:59.715807 2026] [security2:error] [pid 133043:tid 133251] [client 20.215.191.139:61434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/aa.php"] [unique_id "amuwD7dt6aqtVvMundOCsgAAANM"]
[Thu Jul 30 15:11:59.842925 2026] [security2:error] [pid 133043:tid 133237] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/a.php"] [unique_id "amuwD7dt6aqtVvMundOCswAAAMU"]
[Thu Jul 30 15:11:59.843064 2026] [security2:error] [pid 133043:tid 133237] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/a.php"] [unique_id "amuwD7dt6aqtVvMundOCswAAAMU"]
[Thu Jul 30 15:12:00.144351 2026] [security2:error] [pid 133043:tid 133227] [client 62.113.113.43:37826] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "emmelevate.club"] [uri "/"] [unique_id "amuwELdt6aqtVvMundOCtgAAALs"]
[Thu Jul 30 15:12:00.149659 2026] [security2:error] [pid 133043:tid 133297] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/k.php"] [unique_id "amuwELdt6aqtVvMundOCtwAAAQE"]
[Thu Jul 30 15:12:00.149759 2026] [security2:error] [pid 133043:tid 133297] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/k.php"] [unique_id "amuwELdt6aqtVvMundOCtwAAAQE"]
[Thu Jul 30 15:12:00.158106 2026] [security2:error] [pid 133043:tid 133190] [client 20.171.55.167:10524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/mas.php"] [unique_id "amuwELdt6aqtVvMundOCuAAAAJY"]
[Thu Jul 30 15:12:00.373284 2026] [security2:error] [pid 133043:tid 133274] [client 20.215.191.139:61390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/aafewc0k.php"] [unique_id "amuwELdt6aqtVvMundOCugAAAOo"]
[Thu Jul 30 15:12:00.404000 2026] [core:notice] [pid 133043:tid 133281] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:00.447798 2026] [security2:error] [pid 133043:tid 133245] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/222.php"] [unique_id "amuwELdt6aqtVvMundOCvAAAAM0"]
[Thu Jul 30 15:12:00.447922 2026] [security2:error] [pid 133043:tid 133245] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/222.php"] [unique_id "amuwELdt6aqtVvMundOCvAAAAM0"]
[Thu Jul 30 15:12:00.536257 2026] [security2:error] [pid 133043:tid 133193] [client 20.171.55.167:3369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/audit.php"] [unique_id "amuwELdt6aqtVvMundOCwQAAAJk"]
[Thu Jul 30 15:12:00.607568 2026] [security2:error] [pid 133043:tid 133267] [client 172.237.109.114:61715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwELdt6aqtVvMundOCtQAAAOM"]
[Thu Jul 30 15:12:00.780210 2026] [security2:error] [pid 133043:tid 133246] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/mac.php"] [unique_id "amuwELdt6aqtVvMundOCwgAAAM4"]
[Thu Jul 30 15:12:00.780343 2026] [security2:error] [pid 133043:tid 133246] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/mac.php"] [unique_id "amuwELdt6aqtVvMundOCwgAAAM4"]
[Thu Jul 30 15:12:00.900397 2026] [core:notice] [pid 133043:tid 133231] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:00.940866 2026] [security2:error] [pid 133043:tid 133175] [client 20.171.55.167:10513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/mediaadmin.php"] [unique_id "amuwELdt6aqtVvMundOCzAAAAIc"]
[Thu Jul 30 15:12:01.099963 2026] [security2:error] [pid 133043:tid 133252] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-content/uploads/"] [unique_id "amuwEbdt6aqtVvMundOC0QAAANQ"]
[Thu Jul 30 15:12:01.343873 2026] [security2:error] [pid 133043:tid 133236] [client 20.171.55.167:3630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/azra-tn/wso.php"] [unique_id "amuwEbdt6aqtVvMundOC1gAAAMQ"]
[Thu Jul 30 15:12:01.437963 2026] [security2:error] [pid 133043:tid 133177] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/Text/"] [unique_id "amuwEbdt6aqtVvMundOC2gAAAIk"]
[Thu Jul 30 15:12:01.598712 2026] [security2:error] [pid 133043:tid 133273] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ops.php"] [unique_id "amuwEbdt6aqtVvMundOC4gAAAOk"]
[Thu Jul 30 15:12:01.598855 2026] [security2:error] [pid 133043:tid 133273] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ops.php"] [unique_id "amuwEbdt6aqtVvMundOC4gAAAOk"]
[Thu Jul 30 15:12:01.625576 2026] [security2:error] [pid 133043:tid 133293] [client 20.215.191.139:48895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/abcd.php"] [unique_id "amuwEbdt6aqtVvMundOC4wAAAP0"]
[Thu Jul 30 15:12:01.758449 2026] [security2:error] [pid 133043:tid 133188] [client 20.171.55.167:10586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/moddofuns.php"] [unique_id "amuwEbdt6aqtVvMundOC5AAAAJQ"]
[Thu Jul 30 15:12:01.762342 2026] [security2:error] [pid 133043:tid 133214] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/8.php"] [unique_id "amuwEbdt6aqtVvMundOC5QAAAK4"]
[Thu Jul 30 15:12:01.762504 2026] [security2:error] [pid 133043:tid 133214] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/8.php"] [unique_id "amuwEbdt6aqtVvMundOC5QAAAK4"]
[Thu Jul 30 15:12:01.810295 2026] [security2:error] [pid 133043:tid 133288] [client 34.7.15.221:43334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitegaragedoorrepairservices.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwEbdt6aqtVvMundOC5gAAAPg"]
[Thu Jul 30 15:12:01.810401 2026] [security2:error] [pid 133043:tid 133288] [client 34.7.15.221:43334] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elitegaragedoorrepairservices.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwEbdt6aqtVvMundOC5gAAAPg"]
[Thu Jul 30 15:12:02.071088 2026] [security2:error] [pid 133043:tid 133233] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/FWAZ.php"] [unique_id "amuwErdt6aqtVvMundOC8AAAAME"]
[Thu Jul 30 15:12:02.071202 2026] [security2:error] [pid 133043:tid 133233] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/FWAZ.php"] [unique_id "amuwErdt6aqtVvMundOC8AAAAME"]
[Thu Jul 30 15:12:02.106941 2026] [core:error] [pid 133043:tid 133226] [client 34.7.15.221:43342] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:02.106962 2026] [core:error] [pid 133043:tid 133226] [client 34.7.15.221:43342] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:02.110562 2026] [security2:error] [pid 133043:tid 133220] [client 34.7.15.221:43346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/index.php"] [unique_id "amuwErdt6aqtVvMundOC_QAAALQ"]
[Thu Jul 30 15:12:02.258617 2026] [security2:error] [pid 133043:tid 133205] [client 20.171.55.167:4006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/berax.php"] [unique_id "amuwErdt6aqtVvMundOC_gAAAKU"]
[Thu Jul 30 15:12:02.390106 2026] [security2:error] [pid 133043:tid 133234] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/biufile.php"] [unique_id "amuwErdt6aqtVvMundODAQAAAMI"]
[Thu Jul 30 15:12:02.390189 2026] [security2:error] [pid 133043:tid 133234] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/biufile.php"] [unique_id "amuwErdt6aqtVvMundODAQAAAMI"]
[Thu Jul 30 15:12:02.565277 2026] [security2:error] [pid 133043:tid 133263] [client 20.171.55.167:10320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/mrjn.php"] [unique_id "amuwErdt6aqtVvMundODFwAAAN8"]
[Thu Jul 30 15:12:02.702765 2026] [security2:error] [pid 133043:tid 133224] [client 20.215.191.139:48838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/about.php"] [unique_id "amuwErdt6aqtVvMundODGAAAALg"]
[Thu Jul 30 15:12:02.781483 2026] [security2:error] [pid 133043:tid 133111] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwErdt6aqtVvMundODGQAAr0M"]
[Thu Jul 30 15:12:02.781677 2026] [security2:error] [pid 133043:tid 133215] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwErdt6aqtVvMundODGQAAr0M"]
[Thu Jul 30 15:12:03.190848 2026] [security2:error] [pid 133043:tid 133247] [client 20.171.55.167:3430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/block-patterns.php"] [unique_id "amuwE7dt6aqtVvMundODJAAAAM8"]
[Thu Jul 30 15:12:03.262687 2026] [security2:error] [pid 133043:tid 133231] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/coffexium.php"] [unique_id "amuwE7dt6aqtVvMundODJQAAAL8"]
[Thu Jul 30 15:12:03.262791 2026] [security2:error] [pid 133043:tid 133231] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/coffexium.php"] [unique_id "amuwE7dt6aqtVvMundODJQAAAL8"]
[Thu Jul 30 15:12:03.349599 2026] [security2:error] [pid 133043:tid 133219] [client 20.171.55.167:10354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/ndak/marijuana.php"] [unique_id "amuwE7dt6aqtVvMundODJgAAALM"]
[Thu Jul 30 15:12:03.470743 2026] [security2:error] [pid 133043:tid 133276] [client 4.225.203.146:9277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/mah.php"] [unique_id "amuwE7dt6aqtVvMundODJwAAAOw"]
[Thu Jul 30 15:12:03.552967 2026] [core:notice] [pid 133043:tid 133173] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:03.564449 2026] [security2:error] [pid 133043:tid 133211] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/simple.php"] [unique_id "amuwE7dt6aqtVvMundODLwAAAKs"]
[Thu Jul 30 15:12:03.564584 2026] [security2:error] [pid 133043:tid 133211] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/simple.php"] [unique_id "amuwE7dt6aqtVvMundODLwAAAKs"]
[Thu Jul 30 15:12:03.597718 2026] [security2:error] [pid 133043:tid 133241] [client 68.183.5.181:54127] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "happyspree.app"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "amuwE7dt6aqtVvMundODMwAAAMk"]
[Thu Jul 30 15:12:03.867116 2026] [security2:error] [pid 133043:tid 133235] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fpwch.php"] [unique_id "amuwE7dt6aqtVvMundODNAAAAMM"]
[Thu Jul 30 15:12:03.867233 2026] [security2:error] [pid 133043:tid 133235] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fpwch.php"] [unique_id "amuwE7dt6aqtVvMundODNAAAAMM"]
[Thu Jul 30 15:12:03.983348 2026] [core:error] [pid 133043:tid 133288] [client 34.7.15.221:43358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:03.983375 2026] [core:error] [pid 133043:tid 133288] [client 34.7.15.221:43358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:04.161332 2026] [security2:error] [pid 133043:tid 133228] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/dex.php"] [unique_id "amuwFLdt6aqtVvMundODRAAAALw"]
[Thu Jul 30 15:12:04.161446 2026] [security2:error] [pid 133043:tid 133228] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/dex.php"] [unique_id "amuwFLdt6aqtVvMundODRAAAALw"]
[Thu Jul 30 15:12:04.243719 2026] [security2:error] [pid 133043:tid 133281] [client 34.7.15.221:43372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:handle. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "exec(,ARGS:handle"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/console/css/%2e%2e%2fconsole.portal"] [unique_id "amuwFLdt6aqtVvMundODRgAAAPE"]
[Thu Jul 30 15:12:04.260156 2026] [security2:error] [pid 133043:tid 133182] [client 20.171.55.167:10621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/noriumportfolio/alpha.php"] [unique_id "amuwFLdt6aqtVvMundODRwAAAI4"]
[Thu Jul 30 15:12:04.448715 2026] [security2:error] [pid 133043:tid 133248] [client 20.171.55.167:3609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/border.php"] [unique_id "amuwFLdt6aqtVvMundODSwAAANA"]
[Thu Jul 30 15:12:04.466037 2026] [security2:error] [pid 133043:tid 133226] [client 34.7.15.221:43368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.15.7.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitegaragedoorrepairservices.us"] [uri "/user/register"] [unique_id "amuwFLdt6aqtVvMundODRQAAALo"]
[Thu Jul 30 15:12:04.466155 2026] [security2:error] [pid 133043:tid 133226] [client 34.7.15.221:43368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "409"] [hostname "elitegaragedoorrepairservices.us"] [uri "/user/register"] [unique_id "amuwFLdt6aqtVvMundODRQAAALo"]
[Thu Jul 30 15:12:04.474988 2026] [security2:error] [pid 133043:tid 133208] [client 20.100.169.152:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.heiakujawir.com"] [uri "/1.php"] [unique_id "amuwFLdt6aqtVvMundODTgAAAKg"]
[Thu Jul 30 15:12:04.475102 2026] [security2:error] [pid 133043:tid 133208] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/1.php"] [unique_id "amuwFLdt6aqtVvMundODTgAAAKg"]
[Thu Jul 30 15:12:04.475206 2026] [security2:error] [pid 133043:tid 133208] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/1.php"] [unique_id "amuwFLdt6aqtVvMundODTgAAAKg"]
[Thu Jul 30 15:12:04.629330 2026] [security2:error] [pid 133043:tid 133223] [client 172.237.109.114:30307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwFLdt6aqtVvMundODQwAAALc"]
[Thu Jul 30 15:12:04.636994 2026] [security2:error] [pid 133043:tid 133180] [client 20.215.191.139:59010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/admin.php"] [unique_id "amuwFLdt6aqtVvMundODWQAAAIw"]
[Thu Jul 30 15:12:04.801769 2026] [security2:error] [pid 133043:tid 133212] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/modern/"] [unique_id "amuwFLdt6aqtVvMundODWwAAAKw"]
[Thu Jul 30 15:12:04.958482 2026] [security2:error] [pid 133043:tid 133298] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/config.json.php"] [unique_id "amuwFLdt6aqtVvMundODaAAAAQI"]
[Thu Jul 30 15:12:04.958589 2026] [security2:error] [pid 133043:tid 133298] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/config.json.php"] [unique_id "amuwFLdt6aqtVvMundODaAAAAQI"]
[Thu Jul 30 15:12:05.053653 2026] [security2:error] [pid 133043:tid 133280] [client 20.171.55.167:10564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/olux.php"] [unique_id "amuwFbdt6aqtVvMundODfAAAAPA"]
[Thu Jul 30 15:12:05.231504 2026] [security2:error] [pid 133043:tid 133275] [client 20.171.55.167:3603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/byp.php"] [unique_id "amuwFbdt6aqtVvMundODiAAAAOs"]
[Thu Jul 30 15:12:05.282972 2026] [security2:error] [pid 133043:tid 133214] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/k2.php"] [unique_id "amuwFbdt6aqtVvMundODigAAAK4"]
[Thu Jul 30 15:12:05.283136 2026] [security2:error] [pid 133043:tid 133214] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/k2.php"] [unique_id "amuwFbdt6aqtVvMundODigAAAK4"]
[Thu Jul 30 15:12:05.435714 2026] [security2:error] [pid 133043:tid 133177] [client 20.215.191.139:23915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/adminfuns.php"] [unique_id "amuwFbdt6aqtVvMundODjgAAAIk"]
[Thu Jul 30 15:12:05.585565 2026] [security2:error] [pid 133043:tid 133269] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/raw.php"] [unique_id "amuwFbdt6aqtVvMundODmgAAAOU"]
[Thu Jul 30 15:12:05.585675 2026] [security2:error] [pid 133043:tid 133269] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/raw.php"] [unique_id "amuwFbdt6aqtVvMundODmgAAAOU"]
[Thu Jul 30 15:12:05.735313 2026] [security2:error] [pid 133043:tid 133195] [client 57.141.0.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwFbdt6aqtVvMundODlwAAAJs"]
[Thu Jul 30 15:12:05.829401 2026] [core:error] [pid 133043:tid 133203] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:05.829437 2026] [core:error] [pid 133043:tid 133203] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:05.891851 2026] [security2:error] [pid 133043:tid 133201] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp.php"] [unique_id "amuwFbdt6aqtVvMundODpAAAAKE"]
[Thu Jul 30 15:12:05.891945 2026] [security2:error] [pid 133043:tid 133201] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp.php"] [unique_id "amuwFbdt6aqtVvMundODpAAAAKE"]
[Thu Jul 30 15:12:06.009369 2026] [security2:error] [pid 133043:tid 133209] [client 20.171.55.167:10539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/pDPTEa.php"] [unique_id "amuwFrdt6aqtVvMundODpwAAAKk"]
[Thu Jul 30 15:12:06.037542 2026] [security2:error] [pid 133043:tid 133279] [client 20.171.55.167:3984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/cakil/up.php"] [unique_id "amuwFrdt6aqtVvMundODrQAAAO8"]
[Thu Jul 30 15:12:06.136758 2026] [core:notice] [pid 133043:tid 133292] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:06.189402 2026] [security2:error] [pid 133043:tid 133222] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/fffm.php"] [unique_id "amuwFrdt6aqtVvMundODtwAAALY"]
[Thu Jul 30 15:12:06.189500 2026] [security2:error] [pid 133043:tid 133222] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/fffm.php"] [unique_id "amuwFrdt6aqtVvMundODtwAAALY"]
[Thu Jul 30 15:12:06.202586 2026] [security2:error] [pid 133043:tid 133299] [client 34.7.15.221:1710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/..%2f..%2f..%2f..%2f..%2fetc/passwd"] [unique_id "amuwFrdt6aqtVvMundODuAAAAQM"]
[Thu Jul 30 15:12:06.330476 2026] [core:notice] [pid 133043:tid 133230] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:06.489525 2026] [security2:error] [pid 133043:tid 133242] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/111.php"] [unique_id "amuwFrdt6aqtVvMundODugAAAMo"]
[Thu Jul 30 15:12:06.489644 2026] [security2:error] [pid 133043:tid 133242] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/111.php"] [unique_id "amuwFrdt6aqtVvMundODugAAAMo"]
[Thu Jul 30 15:12:06.520848 2026] [security2:error] [pid 133043:tid 133267] [client 20.215.191.139:61427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/albin.php"] [unique_id "amuwFrdt6aqtVvMundODvQAAAOM"]
[Thu Jul 30 15:12:06.802883 2026] [security2:error] [pid 133043:tid 133268] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.heiakujawir.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/Requests/"] [unique_id "amuwFrdt6aqtVvMundODxQAAAOQ"]
[Thu Jul 30 15:12:06.838234 2026] [security2:error] [pid 133043:tid 133221] [client 20.171.55.167:10562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/php.php"] [unique_id "amuwFrdt6aqtVvMundODxgAAALU"]
[Thu Jul 30 15:12:06.959718 2026] [security2:error] [pid 133043:tid 133277] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/ws.php"] [unique_id "amuwFrdt6aqtVvMundODxwAAAO0"]
[Thu Jul 30 15:12:06.959836 2026] [security2:error] [pid 133043:tid 133277] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/ws.php"] [unique_id "amuwFrdt6aqtVvMundODxwAAAO0"]
[Thu Jul 30 15:12:07.237682 2026] [security2:error] [pid 133043:tid 133261] [client 20.215.191.139:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/amfsqvgv.php"] [unique_id "amuwF7dt6aqtVvMundODzgAAAN0"]
[Thu Jul 30 15:12:07.271331 2026] [security2:error] [pid 133043:tid 133254] [client 20.171.55.167:3620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/cd.php"] [unique_id "amuwF7dt6aqtVvMundOD0gAAANY"]
[Thu Jul 30 15:12:07.281434 2026] [security2:error] [pid 133043:tid 133220] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/coffee.php"] [unique_id "amuwF7dt6aqtVvMundOD0wAAALQ"]
[Thu Jul 30 15:12:07.281513 2026] [security2:error] [pid 133043:tid 133220] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/coffee.php"] [unique_id "amuwF7dt6aqtVvMundOD0wAAALQ"]
[Thu Jul 30 15:12:07.596747 2026] [security2:error] [pid 133043:tid 133265] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/goods.php"] [unique_id "amuwF7dt6aqtVvMundOD2AAAAOE"]
[Thu Jul 30 15:12:07.596891 2026] [security2:error] [pid 133043:tid 133265] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/goods.php"] [unique_id "amuwF7dt6aqtVvMundOD2AAAAOE"]
[Thu Jul 30 15:12:07.611163 2026] [security2:error] [pid 133043:tid 133245] [client 17.241.227.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwF7dt6aqtVvMundOD1gAAAM0"]
[Thu Jul 30 15:12:07.821230 2026] [security2:error] [pid 133043:tid 133269] [client 20.171.55.167:10310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/phpunit/src/Util/PHP/peli.php"] [unique_id "amuwF7dt6aqtVvMundOD4gAAAOU"]
[Thu Jul 30 15:12:08.117972 2026] [security2:error] [pid 133043:tid 133215] [client 34.7.15.221:1736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:fileName. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "elitegaragedoorrepairservices.us"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "amuwGLdt6aqtVvMundOD7wAAAK8"]
[Thu Jul 30 15:12:08.135067 2026] [security2:error] [pid 133043:tid 133198] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/about.php"] [unique_id "amuwGLdt6aqtVvMundOD8AAAAJ4"]
[Thu Jul 30 15:12:08.135176 2026] [security2:error] [pid 133043:tid 133198] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/about.php"] [unique_id "amuwGLdt6aqtVvMundOD8AAAAJ4"]
[Thu Jul 30 15:12:08.153159 2026] [security2:error] [pid 133043:tid 133259] [client 20.171.55.167:3994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/checkbox.php"] [unique_id "amuwGLdt6aqtVvMundOD8wAAANs"]
[Thu Jul 30 15:12:08.320227 2026] [core:error] [pid 133043:tid 133236] [client 34.7.15.221:1736] AH10244: invalid URI path (/dana-na/../dana/html5acc/guacamole/../../../../../../etc/passwd?/dana/html5acc/guacamole/)
[Thu Jul 30 15:12:08.333067 2026] [core:error] [pid 133043:tid 133230] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:08.333097 2026] [core:error] [pid 133043:tid 133230] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:08.450285 2026] [security2:error] [pid 133043:tid 133197] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/about.php"] [unique_id "amuwGLdt6aqtVvMundOD_gAAAJ0"]
[Thu Jul 30 15:12:08.450388 2026] [security2:error] [pid 133043:tid 133197] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/about.php"] [unique_id "amuwGLdt6aqtVvMundOD_gAAAJ0"]
[Thu Jul 30 15:12:08.628164 2026] [security2:error] [pid 133043:tid 133173] [client 20.171.55.167:10600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/pluginsalfa.php"] [unique_id "amuwGLdt6aqtVvMundOD_wAAAIU"]
[Thu Jul 30 15:12:08.705008 2026] [core:error] [pid 133043:tid 133258] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:08.705028 2026] [core:error] [pid 133043:tid 133258] [client 34.7.15.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:08.769924 2026] [security2:error] [pid 133043:tid 133177] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuwGLdt6aqtVvMundOEDAAAAIk"]
[Thu Jul 30 15:12:08.770038 2026] [security2:error] [pid 133043:tid 133177] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/admin.php"] [unique_id "amuwGLdt6aqtVvMundOEDAAAAIk"]
[Thu Jul 30 15:12:09.068997 2026] [security2:error] [pid 133043:tid 133218] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/inputs.php"] [unique_id "amuwGbdt6aqtVvMundOEFAAAALI"]
[Thu Jul 30 15:12:09.069102 2026] [security2:error] [pid 133043:tid 133218] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/inputs.php"] [unique_id "amuwGbdt6aqtVvMundOEFAAAALI"]
[Thu Jul 30 15:12:09.098183 2026] [security2:error] [pid 133043:tid 133264] [client 20.171.55.167:3622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/class-phpmailer.php"] [unique_id "amuwGbdt6aqtVvMundOEFQAAAOA"]
[Thu Jul 30 15:12:09.117362 2026] [security2:error] [pid 133043:tid 133275] [client 85.208.96.204:50038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/09/bolsonaro-tem-13-aliados-competitivos-na-disputa-pelos-estados/"] [unique_id "amuwGbdt6aqtVvMundOEFgAAAOs"]
[Thu Jul 30 15:12:09.117478 2026] [security2:error] [pid 133043:tid 133275] [client 85.208.96.204:50038] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/09/bolsonaro-tem-13-aliados-competitivos-na-disputa-pelos-estados/"] [unique_id "amuwGbdt6aqtVvMundOEFgAAAOs"]
[Thu Jul 30 15:12:09.399726 2026] [security2:error] [pid 133043:tid 133183] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/inputs.php"] [unique_id "amuwGbdt6aqtVvMundOEIgAAAI8"]
[Thu Jul 30 15:12:09.399889 2026] [security2:error] [pid 133043:tid 133183] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/inputs.php"] [unique_id "amuwGbdt6aqtVvMundOEIgAAAI8"]
[Thu Jul 30 15:12:09.602853 2026] [security2:error] [pid 133043:tid 133202] [client 172.237.109.114:47588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwGbdt6aqtVvMundOEFwAAAKI"]
[Thu Jul 30 15:12:09.726178 2026] [security2:error] [pid 133043:tid 133199] [client 20.215.191.139:23877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/ant.php"] [unique_id "amuwGbdt6aqtVvMundOEJgAAAJ8"]
[Thu Jul 30 15:12:09.853578 2026] [security2:error] [pid 133043:tid 133227] [client 20.171.55.167:3992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/class-wp-header.php"] [unique_id "amuwGbdt6aqtVvMundOEMAAAALs"]
[Thu Jul 30 15:12:10.139997 2026] [security2:error] [pid 133043:tid 133253] [client 20.171.55.167:10599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/ppus/up.php"] [unique_id "amuwGrdt6aqtVvMundOENAAAANU"]
[Thu Jul 30 15:12:10.185456 2026] [security2:error] [pid 133043:tid 133260] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/adminfuns.php"] [unique_id "amuwGrdt6aqtVvMundOENQAAANw"]
[Thu Jul 30 15:12:10.185570 2026] [security2:error] [pid 133043:tid 133260] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/adminfuns.php"] [unique_id "amuwGrdt6aqtVvMundOENQAAANw"]
[Thu Jul 30 15:12:10.384121 2026] [security2:error] [pid 133043:tid 133250] [client 20.215.191.139:23887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/appreciators.php"] [unique_id "amuwGrdt6aqtVvMundOEPQAAANI"]
[Thu Jul 30 15:12:10.493844 2026] [security2:error] [pid 133043:tid 133201] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/404.php"] [unique_id "amuwGrdt6aqtVvMundOEQQAAAKE"]
[Thu Jul 30 15:12:10.493949 2026] [security2:error] [pid 133043:tid 133201] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/404.php"] [unique_id "amuwGrdt6aqtVvMundOEQQAAAKE"]
[Thu Jul 30 15:12:10.501782 2026] [security2:error] [pid 133043:tid 133176] [client 172.237.109.114:1699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwGrdt6aqtVvMundOEMQAAAIg"]
[Thu Jul 30 15:12:10.735616 2026] [security2:error] [pid 133043:tid 133268] [client 20.171.55.167:3337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/class-wp-site-query.php"] [unique_id "amuwGrdt6aqtVvMundOERAAAAOQ"]
[Thu Jul 30 15:12:10.800675 2026] [security2:error] [pid 133043:tid 133177] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/xxx.php"] [unique_id "amuwGrdt6aqtVvMundOERgAAAIk"]
[Thu Jul 30 15:12:10.800800 2026] [security2:error] [pid 133043:tid 133177] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/xxx.php"] [unique_id "amuwGrdt6aqtVvMundOERgAAAIk"]
[Thu Jul 30 15:12:10.936207 2026] [core:notice] [pid 133043:tid 133089] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:11.014782 2026] [security2:error] [pid 133043:tid 133277] [client 20.171.55.167:10605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/priv8.php"] [unique_id "amuwG7dt6aqtVvMundOEUQAAAO0"]
[Thu Jul 30 15:12:11.118611 2026] [security2:error] [pid 133043:tid 133275] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/classwithtostring.php"] [unique_id "amuwG7dt6aqtVvMundOEVgAAAOs"]
[Thu Jul 30 15:12:11.118718 2026] [security2:error] [pid 133043:tid 133275] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/classwithtostring.php"] [unique_id "amuwG7dt6aqtVvMundOEVgAAAOs"]
[Thu Jul 30 15:12:11.418177 2026] [security2:error] [pid 133043:tid 133271] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/234ff.php"] [unique_id "amuwG7dt6aqtVvMundOEXQAAAOc"]
[Thu Jul 30 15:12:11.418263 2026] [security2:error] [pid 133043:tid 133271] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/234ff.php"] [unique_id "amuwG7dt6aqtVvMundOEXQAAAOc"]
[Thu Jul 30 15:12:11.638515 2026] [security2:error] [pid 133043:tid 133274] [client 20.171.55.167:3997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/clen.php"] [unique_id "amuwG7dt6aqtVvMundOEYwAAAOo"]
[Thu Jul 30 15:12:11.742316 2026] [security2:error] [pid 133043:tid 133198] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/133.php"] [unique_id "amuwG7dt6aqtVvMundOEZgAAAJ4"]
[Thu Jul 30 15:12:11.742402 2026] [security2:error] [pid 133043:tid 133198] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/133.php"] [unique_id "amuwG7dt6aqtVvMundOEZgAAAJ4"]
[Thu Jul 30 15:12:11.834899 2026] [security2:error] [pid 133043:tid 133215] [client 20.171.55.167:10585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/publicbypass.php"] [unique_id "amuwG7dt6aqtVvMundOEaQAAAK8"]
[Thu Jul 30 15:12:12.075429 2026] [security2:error] [pid 133043:tid 133253] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-ws68.php"] [unique_id "amuwHLdt6aqtVvMundOEcwAAANU"]
[Thu Jul 30 15:12:12.075537 2026] [security2:error] [pid 133043:tid 133253] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/wp-ws68.php"] [unique_id "amuwHLdt6aqtVvMundOEcwAAANU"]
[Thu Jul 30 15:12:12.213089 2026] [security2:error] [pid 133043:tid 133189] [client 20.215.191.139:23914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/archive.php"] [unique_id "amuwHLdt6aqtVvMundOEdQAAAJU"]
[Thu Jul 30 15:12:12.387171 2026] [security2:error] [pid 133043:tid 133242] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/mgrr.php"] [unique_id "amuwHLdt6aqtVvMundOEegAAAMo"]
[Thu Jul 30 15:12:12.387259 2026] [security2:error] [pid 133043:tid 133242] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/mgrr.php"] [unique_id "amuwHLdt6aqtVvMundOEegAAAMo"]
[Thu Jul 30 15:12:12.431925 2026] [security2:error] [pid 133043:tid 133229] [client 20.171.55.167:3634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/colors/admin.php"] [unique_id "amuwHLdt6aqtVvMundOEgAAAAL0"]
[Thu Jul 30 15:12:12.630180 2026] [security2:error] [pid 133043:tid 133299] [client 172.237.109.114:5690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwHLdt6aqtVvMundOEdAAAAQM"]
[Thu Jul 30 15:12:12.699512 2026] [security2:error] [pid 133043:tid 133214] [client 20.100.169.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.heiakujawir.com"] [uri "/55.php"] [unique_id "amuwHLdt6aqtVvMundOEhwAAAK4"]
[Thu Jul 30 15:12:12.699619 2026] [security2:error] [pid 133043:tid 133214] [client 20.100.169.152:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.heiakujawir.com"] [uri "/55.php"] [unique_id "amuwHLdt6aqtVvMundOEhwAAAK4"]
[Thu Jul 30 15:12:12.704247 2026] [security2:error] [pid 133043:tid 133209] [client 20.171.55.167:10611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/racing.php"] [unique_id "amuwHLdt6aqtVvMundOEiAAAAKk"]
[Thu Jul 30 15:12:12.933881 2026] [security2:error] [pid 133043:tid 133188] [client 20.215.191.139:48857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/as.php"] [unique_id "amuwHLdt6aqtVvMundOEjgAAAJQ"]
[Thu Jul 30 15:12:13.324877 2026] [security2:error] [pid 133043:tid 133102] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwHbdt6aqtVvMundOEmQAAxzo"]
[Thu Jul 30 15:12:13.325091 2026] [security2:error] [pid 133043:tid 133239] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwHbdt6aqtVvMundOEmQAAxzo"]
[Thu Jul 30 15:12:13.398861 2026] [security2:error] [pid 133043:tid 133245] [client 20.171.55.167:3617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/colors/blue/index.php"] [unique_id "amuwHbdt6aqtVvMundOEmgAAAM0"]
[Thu Jul 30 15:12:13.529689 2026] [security2:error] [pid 133043:tid 133192] [client 20.171.55.167:10616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/resize.php"] [unique_id "amuwHbdt6aqtVvMundOEogAAAJg"]
[Thu Jul 30 15:12:14.211651 2026] [security2:error] [pid 133043:tid 133270] [client 20.171.55.167:3455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/colors/coffee/alfashell.php"] [unique_id "amuwHrdt6aqtVvMundOEvAAAAOY"]
[Thu Jul 30 15:12:14.292539 2026] [security2:error] [pid 133043:tid 133283] [client 4.225.203.146:21779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/send.php"] [unique_id "amuwHrdt6aqtVvMundOEvgAAAPM"]
[Thu Jul 30 15:12:14.360279 2026] [core:notice] [pid 133043:tid 133085] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:14.370502 2026] [security2:error] [pid 133043:tid 133237] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwHbdt6aqtVvMundOEqQAAxTw"]
[Thu Jul 30 15:12:14.470138 2026] [security2:error] [pid 133043:tid 133267] [client 20.171.55.167:10617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/rspp.php"] [unique_id "amuwHrdt6aqtVvMundOEwgAAAOM"]
[Thu Jul 30 15:12:14.625447 2026] [core:notice] [pid 133043:tid 133096] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:14.917798 2026] [security2:error] [pid 133043:tid 133251] [client 20.171.55.167:3633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/colors/ec%5Bredacted%5Dlasm/my1.php"] [unique_id "amuwHrdt6aqtVvMundOE0gAAANM"]
[Thu Jul 30 15:12:15.195137 2026] [security2:error] [pid 133043:tid 133233] [client 4.225.203.146:49898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuwH7dt6aqtVvMundOE3gAAAME"]
[Thu Jul 30 15:12:15.287049 2026] [security2:error] [pid 133043:tid 133238] [client 20.171.55.167:10359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/sb.php"] [unique_id "amuwH7dt6aqtVvMundOE4AAAAMY"]
[Thu Jul 30 15:12:15.632641 2026] [security2:error] [pid 133043:tid 133180] [client 20.171.55.167:3637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/colors/midnight/admin.php"] [unique_id "amuwH7dt6aqtVvMundOE7AAAAIw"]
[Thu Jul 30 15:12:16.077624 2026] [security2:error] [pid 133043:tid 133232] [client 20.171.55.167:10321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/seoplugins/mar.php"] [unique_id "amuwILdt6aqtVvMundOE9wAAAMA"]
[Thu Jul 30 15:12:16.133445 2026] [security2:error] [pid 133043:tid 133187] [client 20.215.191.139:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/atomlib.php"] [unique_id "amuwILdt6aqtVvMundOE_AAAAJM"]
[Thu Jul 30 15:12:16.174024 2026] [core:notice] [pid 133043:tid 133196] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:16.345124 2026] [security2:error] [pid 133043:tid 133236] [client 20.171.55.167:3605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/colors/wp.php"] [unique_id "amuwILdt6aqtVvMundOFAwAAAMQ"]
[Thu Jul 30 15:12:16.359664 2026] [security2:error] [pid 133043:tid 133216] [client 213.152.161.170:56088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuwILdt6aqtVvMundOFBAAAALA"]
[Thu Jul 30 15:12:16.359776 2026] [security2:error] [pid 133043:tid 133216] [client 213.152.161.170:56088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuwILdt6aqtVvMundOFBAAAALA"]
[Thu Jul 30 15:12:16.954911 2026] [security2:error] [pid 133043:tid 133272] [client 20.171.55.167:10338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/sh3ll.php"] [unique_id "amuwILdt6aqtVvMundOFFwAAAOg"]
[Thu Jul 30 15:12:17.082660 2026] [security2:error] [pid 133043:tid 133228] [client 20.171.55.167:3641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/componentsalfa.php"] [unique_id "amuwIbdt6aqtVvMundOFGwAAALw"]
[Thu Jul 30 15:12:17.805020 2026] [security2:error] [pid 133043:tid 133206] [client 20.171.55.167:3627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "amuwIbdt6aqtVvMundOFMQAAAKY"]
[Thu Jul 30 15:12:17.814516 2026] [security2:error] [pid 133043:tid 133227] [client 20.171.55.167:10588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/shxrtr.php"] [unique_id "amuwIbdt6aqtVvMundOFMgAAALs"]
[Thu Jul 30 15:12:18.269172 2026] [core:error] [pid 133043:tid 133284] [client 4.225.203.146:49584] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:18.269194 2026] [core:error] [pid 133043:tid 133284] [client 4.225.203.146:49584] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:18.282204 2026] [security2:error] [pid 133043:tid 133114] [remote 65.181.111.156:53738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.111.181.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amuwIrdt6aqtVvMundOFQwAAlUY"]
[Thu Jul 30 15:12:18.556926 2026] [security2:error] [pid 133043:tid 133224] [client 20.171.55.167:3589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/corebypass.php"] [unique_id "amuwIrdt6aqtVvMundOFRAAAALg"]
[Thu Jul 30 15:12:18.751684 2026] [security2:error] [pid 133043:tid 133214] [client 20.171.55.167:10613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/sitemaps.php"] [unique_id "amuwIrdt6aqtVvMundOFTwAAAK4"]
[Thu Jul 30 15:12:19.333601 2026] [security2:error] [pid 133043:tid 133202] [client 20.171.55.167:3971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/current.php"] [unique_id "amuwI7dt6aqtVvMundOFYwAAAKI"]
[Thu Jul 30 15:12:19.463303 2026] [security2:error] [pid 133043:tid 133246] [client 172.237.109.114:44435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwIrdt6aqtVvMundOFVQAAAM4"]
[Thu Jul 30 15:12:19.549132 2026] [security2:error] [pid 133043:tid 133286] [client 20.171.55.167:10582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/smilies/file.php"] [unique_id "amuwI7dt6aqtVvMundOFaAAAAPY"]
[Thu Jul 30 15:12:19.998360 2026] [security2:error] [pid 133043:tid 133299] [client 20.215.191.139:48707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/autoload_classmap.php"] [unique_id "amuwI7dt6aqtVvMundOFcgAAAQM"]
[Thu Jul 30 15:12:20.039414 2026] [security2:error] [pid 133043:tid 133240] [client 20.171.55.167:3219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/data532.php"] [unique_id "amuwJLdt6aqtVvMundOFdQAAAMg"]
[Thu Jul 30 15:12:20.457026 2026] [security2:error] [pid 133043:tid 133177] [client 20.171.55.167:10335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/src/index.php"] [unique_id "amuwJLdt6aqtVvMundOFfwAAAIk"]
[Thu Jul 30 15:12:20.829894 2026] [security2:error] [pid 133043:tid 133225] [client 20.215.191.139:21207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/bb.php"] [unique_id "amuwJLdt6aqtVvMundOFhAAAALk"]
[Thu Jul 30 15:12:20.846645 2026] [security2:error] [pid 133043:tid 133188] [client 20.171.55.167:4011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/defau1t.php"] [unique_id "amuwJLdt6aqtVvMundOFhQAAAJQ"]
[Thu Jul 30 15:12:21.174386 2026] [security2:error] [pid 133043:tid 133277] [client 4.225.203.146:27982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/about.php"] [unique_id "amuwJbdt6aqtVvMundOFjQAAAO0"]
[Thu Jul 30 15:12:21.409646 2026] [security2:error] [pid 133043:tid 133195] [client 20.171.55.167:10496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/storage/upload/wp.php"] [unique_id "amuwJbdt6aqtVvMundOFlAAAAJs"]
[Thu Jul 30 15:12:21.461153 2026] [security2:error] [pid 133043:tid 133209] [client 172.237.109.114:16489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwJLdt6aqtVvMundOFjAAAAKk"]
[Thu Jul 30 15:12:21.594671 2026] [security2:error] [pid 133043:tid 133194] [client 185.200.117.131:54088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuwJbdt6aqtVvMundOFmwAAAJo"]
[Thu Jul 30 15:12:21.594773 2026] [security2:error] [pid 133043:tid 133194] [client 185.200.117.131:54088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuwJbdt6aqtVvMundOFmwAAAJo"]
[Thu Jul 30 15:12:21.596327 2026] [security2:error] [pid 133043:tid 133236] [client 20.171.55.167:3406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/dfre.php"] [unique_id "amuwJbdt6aqtVvMundOFnAAAAMQ"]
[Thu Jul 30 15:12:21.685154 2026] [security2:error] [pid 133043:tid 133285] [client 20.215.191.139:61435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/bnm.php"] [unique_id "amuwJbdt6aqtVvMundOFnQAAAPU"]
[Thu Jul 30 15:12:21.868492 2026] [security2:error] [pid 133043:tid 133280] [client 4.225.203.146:17174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/options.php"] [unique_id "amuwJbdt6aqtVvMundOFogAAAPA"]
[Thu Jul 30 15:12:22.026357 2026] [core:notice] [pid 133043:tid 133281] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:22.366258 2026] [security2:error] [pid 133043:tid 133242] [client 20.171.55.167:3642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/dist/test.php"] [unique_id "amuwJrdt6aqtVvMundOFrgAAAMo"]
[Thu Jul 30 15:12:22.385032 2026] [security2:error] [pid 133043:tid 133276] [client 20.171.55.167:10522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/sym.php"] [unique_id "amuwJrdt6aqtVvMundOFsAAAAOw"]
[Thu Jul 30 15:12:22.710839 2026] [security2:error] [pid 133043:tid 133250] [client 20.215.191.139:23911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/bootstrap.php"] [unique_id "amuwJrdt6aqtVvMundOFuQAAANI"]
[Thu Jul 30 15:12:23.124898 2026] [security2:error] [pid 133043:tid 133185] [client 20.171.55.167:3973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/documentsadmin.php"] [unique_id "amuwJ7dt6aqtVvMundOFyAAAAJE"]
[Thu Jul 30 15:12:23.174175 2026] [security2:error] [pid 133043:tid 133284] [client 4.225.203.146:24026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuwJ7dt6aqtVvMundOFyQAAAPQ"]
[Thu Jul 30 15:12:23.423678 2026] [security2:error] [pid 133043:tid 133297] [client 20.171.55.167:10512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/templatesdex.php"] [unique_id "amuwJ7dt6aqtVvMundOFzQAAAQE"]
[Thu Jul 30 15:12:24.111353 2026] [security2:error] [pid 133043:tid 133239] [client 20.215.191.139:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/buy.php"] [unique_id "amuwKLdt6aqtVvMundOF5AAAAMc"]
[Thu Jul 30 15:12:24.128764 2026] [security2:error] [pid 133043:tid 133166] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwKLdt6aqtVvMundOF5QAAm3o"]
[Thu Jul 30 15:12:24.128929 2026] [security2:error] [pid 133043:tid 133195] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwKLdt6aqtVvMundOF5QAAm3o"]
[Thu Jul 30 15:12:24.179581 2026] [security2:error] [pid 133043:tid 133204] [client 20.171.55.167:3985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/dragonforce.php"] [unique_id "amuwKLdt6aqtVvMundOF5gAAAKQ"]
[Thu Jul 30 15:12:24.321320 2026] [security2:error] [pid 133043:tid 133279] [client 20.171.55.167:11099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/themes-install.php"] [unique_id "amuwKLdt6aqtVvMundOF6AAAAO8"]
[Thu Jul 30 15:12:24.425930 2026] [security2:error] [pid 133043:tid 133285] [client 4.225.203.146:24055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/wp-file.php"] [unique_id "amuwKLdt6aqtVvMundOF6gAAAPU"]
[Thu Jul 30 15:12:25.094156 2026] [security2:error] [pid 133043:tid 133237] [client 20.171.55.167:3216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/ee.php"] [unique_id "amuwKbdt6aqtVvMundOGAAAAAMU"]
[Thu Jul 30 15:12:25.207682 2026] [security2:error] [pid 133043:tid 133210] [client 20.215.191.139:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/chosen.php"] [unique_id "amuwKbdt6aqtVvMundOGBAAAAKo"]
[Thu Jul 30 15:12:25.249009 2026] [security2:error] [pid 133043:tid 133216] [client 20.171.55.167:10610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/tinymce/skins/wordpress/images/about.php"] [unique_id "amuwKbdt6aqtVvMundOGBgAAALA"]
[Thu Jul 30 15:12:25.539778 2026] [security2:error] [pid 133043:tid 133262] [client 4.225.203.146:27990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.203.225.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "svcambodia.com"] [uri "/sid3.php"] [unique_id "amuwKbdt6aqtVvMundOGDAAAAN4"]
[Thu Jul 30 15:12:25.739731 2026] [core:notice] [pid 133043:tid 133284] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:25.813067 2026] [security2:error] [pid 133043:tid 133188] [client 20.171.55.167:3626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/erinyani/asasx.php"] [unique_id "amuwKbdt6aqtVvMundOGFwAAAJQ"]
[Thu Jul 30 15:12:25.856351 2026] [core:notice] [pid 133043:tid 133065] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:26.104028 2026] [security2:error] [pid 133043:tid 133207] [client 20.171.55.167:10609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/travel/issue.php"] [unique_id "amuwKrdt6aqtVvMundOGIgAAAKc"]
[Thu Jul 30 15:12:26.137275 2026] [core:notice] [pid 133043:tid 133160] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:26.359041 2026] [security2:error] [pid 133043:tid 133245] [client 20.215.191.139:48843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/class-wp-image.php"] [unique_id "amuwKrdt6aqtVvMundOGKgAAAM0"]
[Thu Jul 30 15:12:26.581519 2026] [security2:error] [pid 133043:tid 133239] [client 20.171.55.167:3227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/extension/extension/ultra.php"] [unique_id "amuwKrdt6aqtVvMundOGMwAAAMc"]
[Thu Jul 30 15:12:26.899054 2026] [core:notice] [pid 133043:tid 133046] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:26.980283 2026] [security2:error] [pid 133043:tid 133280] [client 20.171.55.167:10333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/twentytwentyfour/about.php"] [unique_id "amuwKrdt6aqtVvMundOGQAAAAPA"]
[Thu Jul 30 15:12:27.335597 2026] [security2:error] [pid 133043:tid 133270] [client 20.171.55.167:4004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/feed-rsss.php"] [unique_id "amuwK7dt6aqtVvMundOGTAAAAOY"]
[Thu Jul 30 15:12:27.775655 2026] [security2:error] [pid 133043:tid 133254] [client 20.171.55.167:10570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/ubh/index.php"] [unique_id "amuwK7dt6aqtVvMundOGWgAAANY"]
[Thu Jul 30 15:12:28.217082 2026] [core:error] [pid 133043:tid 133288] [client 74.7.241.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:28.217102 2026] [core:error] [pid 133043:tid 133288] [client 74.7.241.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:28.217200 2026] [security2:error] [pid 133043:tid 133288] [client 74.7.241.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.pvc.hfl.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amuwLLdt6aqtVvMundOGbwAAAPg"]
[Thu Jul 30 15:12:28.218654 2026] [security2:error] [pid 133043:tid 133262] [client 74.7.241.172:50790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.pvc.hfl.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amuwLLdt6aqtVvMundOGaAAA3hE"]
[Thu Jul 30 15:12:28.243716 2026] [security2:error] [pid 133043:tid 133190] [client 20.171.55.167:3204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/file9.php"] [unique_id "amuwLLdt6aqtVvMundOGcQAAAJY"]
[Thu Jul 30 15:12:28.246684 2026] [core:notice] [pid 133043:tid 133136] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:28.456409 2026] [security2:error] [pid 133043:tid 133187] [client 20.215.191.139:48727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/classsmtps.php"] [unique_id "amuwLLdt6aqtVvMundOGcwAAAJM"]
[Thu Jul 30 15:12:28.509528 2026] [security2:error] [pid 133043:tid 133225] [client 172.237.109.114:61460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwLLdt6aqtVvMundOGXgAAALk"]
[Thu Jul 30 15:12:28.669968 2026] [security2:error] [pid 133043:tid 133213] [client 20.171.55.167:10559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/upload-size.php"] [unique_id "amuwLLdt6aqtVvMundOGegAAAK0"]
[Thu Jul 30 15:12:29.011854 2026] [security2:error] [pid 133043:tid 133234] [client 20.171.55.167:3639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/filek.php"] [unique_id "amuwLbdt6aqtVvMundOGgwAAAMI"]
[Thu Jul 30 15:12:29.452095 2026] [security2:error] [pid 133043:tid 133255] [client 20.171.55.167:10360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/upspy/sllolx.php"] [unique_id "amuwLbdt6aqtVvMundOGlAAAANc"]
[Thu Jul 30 15:12:29.873703 2026] [security2:error] [pid 133043:tid 133270] [client 20.215.191.139:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/classwithtostring.php"] [unique_id "amuwLbdt6aqtVvMundOGoAAAAOY"]
[Thu Jul 30 15:12:29.895888 2026] [security2:error] [pid 133043:tid 133295] [client 20.171.55.167:3205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/flower.php"] [unique_id "amuwLbdt6aqtVvMundOGpAAAAP8"]
[Thu Jul 30 15:12:29.967937 2026] [fcgid:warn] [pid 133043:tid 133228] (70014)End of file found: [client 66.132.186.166:44778] mod_fcgid: can't get data from http client
[Thu Jul 30 15:12:30.228333 2026] [security2:error] [pid 133043:tid 133214] [client 20.171.55.167:10500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/v4.php"] [unique_id "amuwLrdt6aqtVvMundOGqQAAAK4"]
[Thu Jul 30 15:12:30.710407 2026] [security2:error] [pid 133043:tid 133209] [client 20.215.191.139:48755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/config.php"] [unique_id "amuwLrdt6aqtVvMundOGtgAAAKk"]
[Thu Jul 30 15:12:31.049925 2026] [security2:error] [pid 133043:tid 133245] [client 20.171.55.167:3646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/function.php"] [unique_id "amuwL7dt6aqtVvMundOGwwAAAM0"]
[Thu Jul 30 15:12:31.070297 2026] [security2:error] [pid 133043:tid 133239] [client 20.171.55.167:10514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/vuln.php"] [unique_id "amuwL7dt6aqtVvMundOGxAAAAMc"]
[Thu Jul 30 15:12:31.258115 2026] [security2:error] [pid 133043:tid 133285] [client 82.102.27.163:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuwL7dt6aqtVvMundOGxQAAAPU"]
[Thu Jul 30 15:12:31.258256 2026] [security2:error] [pid 133043:tid 133285] [client 82.102.27.163:33044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuwL7dt6aqtVvMundOGxQAAAPU"]
[Thu Jul 30 15:12:31.649236 2026] [core:error] [pid 133043:tid 133255] [client 74.7.228.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:31.649262 2026] [core:error] [pid 133043:tid 133255] [client 74.7.228.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:31.649437 2026] [security2:error] [pid 133043:tid 133255] [client 74.7.228.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.shop-kent.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuwL7dt6aqtVvMundOG1wAAANc"]
[Thu Jul 30 15:12:31.650079 2026] [security2:error] [pid 133043:tid 133252] [client 74.7.228.23:59344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.shop-kent.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuwL7dt6aqtVvMundOG1QAA1Dw"]
[Thu Jul 30 15:12:31.805083 2026] [security2:error] [pid 133043:tid 133204] [client 20.215.191.139:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/core.php"] [unique_id "amuwL7dt6aqtVvMundOG2gAAAKQ"]
[Thu Jul 30 15:12:31.813199 2026] [security2:error] [pid 133043:tid 133258] [client 20.171.55.167:3377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/gecko.php"] [unique_id "amuwL7dt6aqtVvMundOG3AAAANo"]
[Thu Jul 30 15:12:31.936460 2026] [security2:error] [pid 133043:tid 133179] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwL7dt6aqtVvMundOGyAAAAIs"]
[Thu Jul 30 15:12:31.991046 2026] [security2:error] [pid 133043:tid 133232] [client 20.171.55.167:10520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/weo.php"] [unique_id "amuwL7dt6aqtVvMundOG5QAAAMA"]
[Thu Jul 30 15:12:32.551736 2026] [security2:error] [pid 133043:tid 133275] [client 20.171.55.167:3643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/goat1.php"] [unique_id "amuwMLdt6aqtVvMundOG9wAAAOs"]
[Thu Jul 30 15:12:32.557061 2026] [security2:error] [pid 133043:tid 133288] [client 20.52.54.143:10525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "amuwMLdt6aqtVvMundOG-AAAAPg"]
[Thu Jul 30 15:12:32.784211 2026] [security2:error] [pid 133043:tid 133193] [client 20.171.55.167:10622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/widgets/links.php"] [unique_id "amuwMLdt6aqtVvMundOG_wAAAJk"]
[Thu Jul 30 15:12:32.812035 2026] [security2:error] [pid 133043:tid 133202] [client 157.245.98.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.website-723a6906.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuwMLdt6aqtVvMundOG_gAAAKI"], referer: http://www.website-723a6906.glb.nyx.temporary.site/
[Thu Jul 30 15:12:33.251205 2026] [security2:error] [pid 133043:tid 133230] [client 20.52.54.143:10500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/php8.php"] [unique_id "amuwMbdt6aqtVvMundOHDgAAAL4"]
[Thu Jul 30 15:12:33.392603 2026] [security2:error] [pid 133043:tid 133173] [client 20.171.55.167:3999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/harga.php"] [unique_id "amuwMbdt6aqtVvMundOHEwAAAIU"]
[Thu Jul 30 15:12:33.491574 2026] [security2:error] [pid 133043:tid 133216] [client 157.245.98.238:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.website-723a6906.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuwMbdt6aqtVvMundOHFAAAALA"], referer: https://www.website-723a6906.glb.nyx.temporary.site/
[Thu Jul 30 15:12:33.729599 2026] [security2:error] [pid 133043:tid 133235] [client 20.171.55.167:10507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/woocommerce-square/index.php"] [unique_id "amuwMbdt6aqtVvMundOHHwAAAMM"]
[Thu Jul 30 15:12:34.084405 2026] [proxy:error] [pid 133043:tid 133205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:34.084462 2026] [proxy_http:error] [pid 133043:tid 133205] [client 74.7.241.164:47804] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:34.085151 2026] [proxy:error] [pid 133043:tid 133205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:34.085198 2026] [proxy_http:error] [pid 133043:tid 133205] [client 74.7.241.164:47804] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:34.085304 2026] [security2:error] [pid 133043:tid 133205] [client 74.7.241.164:47804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.vpv.tqa.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuwMrdt6aqtVvMundOHMwAAAKU"]
[Thu Jul 30 15:12:34.218495 2026] [security2:error] [pid 133043:tid 133233] [client 20.171.55.167:4010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/hiroshi.php"] [unique_id "amuwMrdt6aqtVvMundOHNQAAAME"]
[Thu Jul 30 15:12:34.473685 2026] [security2:error] [pid 133043:tid 133284] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwMbdt6aqtVvMundOHKAAAAPQ"]
[Thu Jul 30 15:12:34.580507 2026] [security2:error] [pid 133043:tid 133182] [client 20.171.55.167:10516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wp-admins.php"] [unique_id "amuwMrdt6aqtVvMundOHQAAAAI4"]
[Thu Jul 30 15:12:34.696917 2026] [security2:error] [pid 133043:tid 133113] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwMrdt6aqtVvMundOHQgAAukU"]
[Thu Jul 30 15:12:34.697077 2026] [security2:error] [pid 133043:tid 133226] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwMrdt6aqtVvMundOHQgAAukU"]
[Thu Jul 30 15:12:34.938739 2026] [security2:error] [pid 133043:tid 133203] [client 20.215.191.139:59024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/css.php"] [unique_id "amuwMrdt6aqtVvMundOHRQAAAKM"]
[Thu Jul 30 15:12:35.056090 2026] [security2:error] [pid 133043:tid 133206] [client 20.171.55.167:3981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/i0004en.php//wp-content/plugins/bk/index.php"] [unique_id "amuwM7dt6aqtVvMundOHTQAAAKY"]
[Thu Jul 30 15:12:35.097405 2026] [security2:error] [pid 133043:tid 133180] [client 20.52.54.143:10546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/lite.php"] [unique_id "amuwM7dt6aqtVvMundOHUQAAAIw"]
[Thu Jul 30 15:12:35.773134 2026] [security2:error] [pid 133043:tid 133218] [client 20.171.55.167:3628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/images.php"] [unique_id "amuwM7dt6aqtVvMundOHZgAAALI"]
[Thu Jul 30 15:12:35.948944 2026] [security2:error] [pid 133043:tid 133294] [client 47.128.121.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwM7dt6aqtVvMundOHZQAAAP4"]
[Thu Jul 30 15:12:35.966918 2026] [security2:error] [pid 133043:tid 133272] [client 20.171.55.167:10508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wp-commentin.php"] [unique_id "amuwM7dt6aqtVvMundOHagAAAOg"]
[Thu Jul 30 15:12:36.040538 2026] [security2:error] [pid 133043:tid 133262] [client 20.52.54.143:10545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/term.php"] [unique_id "amuwNLdt6aqtVvMundOHbwAAAN4"]
[Thu Jul 30 15:12:36.625746 2026] [security2:error] [pid 133043:tid 133260] [client 185.177.72.30:14672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwNLdt6aqtVvMundOHhQAAANw"]
[Thu Jul 30 15:12:36.643740 2026] [security2:error] [pid 133043:tid 133270] [client 20.171.55.167:4024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/indeex.php"] [unique_id "amuwNLdt6aqtVvMundOHiQAAAOY"]
[Thu Jul 30 15:12:36.715821 2026] [security2:error] [pid 133043:tid 133236] [client 20.52.54.143:10556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/config.php"] [unique_id "amuwNLdt6aqtVvMundOHiwAAAMQ"]
[Thu Jul 30 15:12:36.882716 2026] [security2:error] [pid 133043:tid 133242] [client 185.177.72.30:14682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amuwNLdt6aqtVvMundOHjwAAAMo"]
[Thu Jul 30 15:12:36.912241 2026] [security2:error] [pid 133043:tid 133227] [client 20.171.55.167:10596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wp-crom.php"] [unique_id "amuwNLdt6aqtVvMundOHkAAAALs"]
[Thu Jul 30 15:12:37.149572 2026] [security2:error] [pid 133043:tid 133240] [client 185.177.72.30:14686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwNbdt6aqtVvMundOHmQAAAMg"]
[Thu Jul 30 15:12:37.201426 2026] [security2:error] [pid 133043:tid 133278] [client 20.104.18.253:6343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/astra/inc/fm.php"] [unique_id "amuwNbdt6aqtVvMundOHnQAAAO4"]
[Thu Jul 30 15:12:37.374221 2026] [security2:error] [pid 133043:tid 133290] [client 20.171.55.167:4012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/install.php"] [unique_id "amuwNbdt6aqtVvMundOHoQAAAPo"]
[Thu Jul 30 15:12:37.413076 2026] [security2:error] [pid 133043:tid 133297] [client 185.177.72.30:14696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwNbdt6aqtVvMundOHogAAAQE"]
[Thu Jul 30 15:12:37.671325 2026] [security2:error] [pid 133043:tid 133277] [client 185.177.72.30:14700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwNbdt6aqtVvMundOHqgAAAO0"]
[Thu Jul 30 15:12:37.738339 2026] [security2:error] [pid 133043:tid 133235] [client 20.171.55.167:10602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wp-fmfile.php"] [unique_id "amuwNbdt6aqtVvMundOHrwAAAMM"]
[Thu Jul 30 15:12:37.868322 2026] [security2:error] [pid 133043:tid 133199] [client 20.104.18.253:6361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/astra/inc/ki1k.php"] [unique_id "amuwNbdt6aqtVvMundOHsQAAAJ8"]
[Thu Jul 30 15:12:37.938859 2026] [security2:error] [pid 133043:tid 133238] [client 185.177.72.30:14712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwNbdt6aqtVvMundOHswAAAMY"]
[Thu Jul 30 15:12:38.510256 2026] [security2:error] [pid 133043:tid 133284] [client 20.104.18.253:6615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/atombil.php"] [unique_id "amuwNrdt6aqtVvMundOHwQAAAPQ"]
[Thu Jul 30 15:12:38.566480 2026] [security2:error] [pid 133043:tid 133254] [client 20.52.54.143:10559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuwNrdt6aqtVvMundOHwwAAANY"]
[Thu Jul 30 15:12:38.578584 2026] [security2:error] [pid 133043:tid 133223] [client 20.171.55.167:3586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/j.php"] [unique_id "amuwNrdt6aqtVvMundOHxAAAALc"]
[Thu Jul 30 15:12:38.873051 2026] [security2:error] [pid 133043:tid 133196] [client 20.171.55.167:11080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wp-maill.php"] [unique_id "amuwNrdt6aqtVvMundOH0gAAAJw"]
[Thu Jul 30 15:12:39.033862 2026] [security2:error] [pid 133043:tid 133135] [remote 216.73.216.51:35246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuwN7dt6aqtVvMundOH1QAAvls"]
[Thu Jul 30 15:12:39.157508 2026] [security2:error] [pid 133043:tid 133211] [client 20.104.18.253:6341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/atomlib.php"] [unique_id "amuwN7dt6aqtVvMundOH2gAAAKs"]
[Thu Jul 30 15:12:39.451107 2026] [security2:error] [pid 133043:tid 133210] [client 20.171.55.167:3209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/joy.php"] [unique_id "amuwN7dt6aqtVvMundOH5QAAAKo"]
[Thu Jul 30 15:12:39.759221 2026] [security2:error] [pid 133043:tid 133263] [client 20.104.18.253:6592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/aua.php"] [unique_id "amuwN7dt6aqtVvMundOH7gAAAN8"]
[Thu Jul 30 15:12:39.785431 2026] [security2:error] [pid 133043:tid 133295] [client 20.171.55.167:10536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wp-root.php"] [unique_id "amuwN7dt6aqtVvMundOH7wAAAP8"]
[Thu Jul 30 15:12:40.217029 2026] [security2:error] [pid 133043:tid 133224] [client 20.215.191.139:45973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/database.php"] [unique_id "amuwOLdt6aqtVvMundOH-QAAALg"]
[Thu Jul 30 15:12:40.340033 2026] [security2:error] [pid 133043:tid 133265] [client 20.171.55.167:3632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/klarnaAjax.php"] [unique_id "amuwOLdt6aqtVvMundOIAAAAAOE"]
[Thu Jul 30 15:12:40.361510 2026] [security2:error] [pid 133043:tid 133272] [client 20.104.18.253:6356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/aucxzso.php"] [unique_id "amuwOLdt6aqtVvMundOIAQAAAOg"]
[Thu Jul 30 15:12:40.624608 2026] [security2:error] [pid 133043:tid 133193] [client 20.171.55.167:10615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wp-tinymce.php"] [unique_id "amuwOLdt6aqtVvMundOIBgAAAJk"]
[Thu Jul 30 15:12:40.965773 2026] [security2:error] [pid 133043:tid 133284] [client 20.215.191.139:48866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/db.php"] [unique_id "amuwOLdt6aqtVvMundOIEQAAAPQ"]
[Thu Jul 30 15:12:40.969364 2026] [security2:error] [pid 133043:tid 133198] [client 20.104.18.253:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/audio.php"] [unique_id "amuwOLdt6aqtVvMundOIEgAAAJ4"]
[Thu Jul 30 15:12:41.174159 2026] [security2:error] [pid 133043:tid 133292] [client 20.171.55.167:3203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/leafmailer2.8.php"] [unique_id "amuwObdt6aqtVvMundOIFAAAAPw"]
[Thu Jul 30 15:12:41.512789 2026] [security2:error] [pid 133043:tid 133282] [client 20.171.55.167:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wp_wol.php"] [unique_id "amuwObdt6aqtVvMundOIHwAAAPI"]
[Thu Jul 30 15:12:41.573335 2026] [security2:error] [pid 133043:tid 133174] [client 20.104.18.253:6653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/audit.php"] [unique_id "amuwObdt6aqtVvMundOIIAAAAIY"]
[Thu Jul 30 15:12:41.602557 2026] [security2:error] [pid 133043:tid 133249] [client 20.215.191.139:46001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/default.php"] [unique_id "amuwObdt6aqtVvMundOIIgAAANE"]
[Thu Jul 30 15:12:41.938401 2026] [security2:error] [pid 133043:tid 133299] [client 20.171.55.167:3352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/linkpreview/db.php"] [unique_id "amuwObdt6aqtVvMundOIMwAAAQM"]
[Thu Jul 30 15:12:42.197815 2026] [security2:error] [pid 133043:tid 133218] [client 20.104.18.253:6635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/auth.php"] [unique_id "amuwOrdt6aqtVvMundOINwAAALI"]
[Thu Jul 30 15:12:42.240751 2026] [security2:error] [pid 133043:tid 133287] [client 2a03:2880:f800:3b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwObdt6aqtVvMundOIIwAA9xc"]
[Thu Jul 30 15:12:42.273177 2026] [security2:error] [pid 133043:tid 133221] [client 20.171.55.167:10580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wsanon.php"] [unique_id "amuwOrdt6aqtVvMundOIOwAAALU"]
[Thu Jul 30 15:12:42.315172 2026] [core:notice] [pid 133043:tid 133069] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:42.629687 2026] [security2:error] [pid 133043:tid 133274] [client 20.215.191.139:46005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/dropdown.php"] [unique_id "amuwOrdt6aqtVvMundOISQAAAOo"]
[Thu Jul 30 15:12:42.830362 2026] [security2:error] [pid 133043:tid 133181] [client 20.171.55.167:3218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/loader.php"] [unique_id "amuwOrdt6aqtVvMundOIUQAAAI0"]
[Thu Jul 30 15:12:42.833943 2026] [security2:error] [pid 133043:tid 133246] [client 20.104.18.253:6647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/authorize.php"] [unique_id "amuwOrdt6aqtVvMundOIUwAAAM4"]
[Thu Jul 30 15:12:43.029796 2026] [security2:error] [pid 133043:tid 133289] [client 20.52.54.143:10498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-good.php"] [unique_id "amuwO7dt6aqtVvMundOIWAAAAPk"]
[Thu Jul 30 15:12:43.060687 2026] [security2:error] [pid 133043:tid 133257] [client 20.171.55.167:10525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/wzy.php"] [unique_id "amuwO7dt6aqtVvMundOIWQAAANk"]
[Thu Jul 30 15:12:43.447690 2026] [security2:error] [pid 133043:tid 133196] [client 20.104.18.253:6351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/autoload_classmap.php"] [unique_id "amuwO7dt6aqtVvMundOIZgAAAJw"]
[Thu Jul 30 15:12:43.710495 2026] [security2:error] [pid 133043:tid 133255] [client 20.171.55.167:3608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/lx.php"] [unique_id "amuwO7dt6aqtVvMundOIaAAAANc"]
[Thu Jul 30 15:12:43.808507 2026] [security2:error] [pid 133043:tid 133258] [client 213.152.161.170:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuwO7dt6aqtVvMundOIaQAAANo"]
[Thu Jul 30 15:12:43.808648 2026] [security2:error] [pid 133043:tid 133258] [client 213.152.161.170:59306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuwO7dt6aqtVvMundOIaQAAANo"]
[Thu Jul 30 15:12:43.857507 2026] [security2:error] [pid 133043:tid 133216] [client 20.171.55.167:10317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/xleet.php"] [unique_id "amuwO7dt6aqtVvMundOIbQAAALA"]
[Thu Jul 30 15:12:44.059827 2026] [security2:error] [pid 133043:tid 133273] [client 20.104.18.253:6389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/autoloadclassmap.php"] [unique_id "amuwPLdt6aqtVvMundOIdAAAAOk"]
[Thu Jul 30 15:12:44.617422 2026] [security2:error] [pid 133043:tid 133235] [client 20.171.55.167:3969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/majalahpro-core/index.php"] [unique_id "amuwPLdt6aqtVvMundOIfwAAAMM"]
[Thu Jul 30 15:12:44.660777 2026] [security2:error] [pid 133043:tid 133262] [client 20.104.18.253:6354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/automanipulative.php"] [unique_id "amuwPLdt6aqtVvMundOIgAAAAN4"]
[Thu Jul 30 15:12:44.961142 2026] [security2:error] [pid 133043:tid 133056] [remote 74.7.227.39:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuwPLdt6aqtVvMundOIhwAApQw"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/wpforms-lite/includes
[Thu Jul 30 15:12:44.968604 2026] [security2:error] [pid 133043:tid 133174] [client 20.215.191.139:52806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/edit.php"] [unique_id "amuwPLdt6aqtVvMundOIiAAAAIY"]
[Thu Jul 30 15:12:45.268271 2026] [security2:error] [pid 133043:tid 133279] [client 20.104.18.253:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/av.php"] [unique_id "amuwPbdt6aqtVvMundOIkAAAAO8"]
[Thu Jul 30 15:12:45.335877 2026] [security2:error] [pid 133043:tid 133171] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwPbdt6aqtVvMundOIkQAAtn8"]
[Thu Jul 30 15:12:45.336032 2026] [security2:error] [pid 133043:tid 133222] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwPbdt6aqtVvMundOIkQAAtn8"]
[Thu Jul 30 15:12:45.535103 2026] [security2:error] [pid 133043:tid 133226] [client 20.171.55.167:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/matamu.php"] [unique_id "amuwPbdt6aqtVvMundOImAAAALo"]
[Thu Jul 30 15:12:45.536700 2026] [proxy:error] [pid 133043:tid 133270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:45.536757 2026] [proxy_http:error] [pid 133043:tid 133270] [client 193.47.62.167:38064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:45.537327 2026] [proxy:error] [pid 133043:tid 133270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:45.537372 2026] [proxy_http:error] [pid 133043:tid 133270] [client 193.47.62.167:38064] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:45.617860 2026] [security2:error] [pid 133043:tid 133260] [client 20.171.55.167:10582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/yanierin/akc.php"] [unique_id "amuwPbdt6aqtVvMundOIngAAANw"]
[Thu Jul 30 15:12:45.866754 2026] [security2:error] [pid 133043:tid 133227] [client 20.104.18.253:6595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/ava.php"] [unique_id "amuwPbdt6aqtVvMundOInwAAALs"]
[Thu Jul 30 15:12:45.903575 2026] [security2:error] [pid 133043:tid 133257] [client 20.215.191.139:20181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/f35.php"] [unique_id "amuwPbdt6aqtVvMundOIoAAAANk"]
[Thu Jul 30 15:12:46.344331 2026] [security2:error] [pid 133043:tid 133216] [client 20.171.55.167:3224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/mediak.php"] [unique_id "amuwPrdt6aqtVvMundOIqgAAALA"]
[Thu Jul 30 15:12:46.467724 2026] [security2:error] [pid 133043:tid 133210] [client 20.104.18.253:6610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/avaa.php"] [unique_id "amuwPrdt6aqtVvMundOIrgAAAKo"]
[Thu Jul 30 15:12:46.481884 2026] [security2:error] [pid 133043:tid 133278] [client 20.171.55.167:10523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.arabiandubaisafari.com"] [uri "/zfox.php"] [unique_id "amuwPrdt6aqtVvMundOIsQAAAO4"]
[Thu Jul 30 15:12:46.604375 2026] [security2:error] [pid 133043:tid 133267] [client 20.215.191.139:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.progroupdoha.com"] [uri "/f7.php"] [unique_id "amuwPrdt6aqtVvMundOIwAAAAOM"]
[Thu Jul 30 15:12:47.026623 2026] [security2:error] [pid 133043:tid 133224] [client 185.200.117.131:50810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuwP7dt6aqtVvMundOIxwAAALg"]
[Thu Jul 30 15:12:47.026713 2026] [security2:error] [pid 133043:tid 133224] [client 185.200.117.131:50810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuwP7dt6aqtVvMundOIxwAAALg"]
[Thu Jul 30 15:12:47.067002 2026] [security2:error] [pid 133043:tid 133293] [client 20.104.18.253:6630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/ave.php"] [unique_id "amuwP7dt6aqtVvMundOIyAAAAP0"]
[Thu Jul 30 15:12:47.176049 2026] [security2:error] [pid 133043:tid 133275] [client 20.171.55.167:4018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/moderation.php"] [unique_id "amuwP7dt6aqtVvMundOIzAAAAOs"]
[Thu Jul 30 15:12:47.664676 2026] [security2:error] [pid 133043:tid 133187] [client 20.104.18.253:6632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/aves.php"] [unique_id "amuwP7dt6aqtVvMundOI1wAAAJM"]
[Thu Jul 30 15:12:47.726538 2026] [security2:error] [pid 133043:tid 133285] [client 20.52.54.143:10519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amuwP7dt6aqtVvMundOI2wAAAPU"]
[Thu Jul 30 15:12:47.847192 2026] [core:notice] [pid 133043:tid 133084] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:47.850825 2026] [security2:error] [pid 133043:tid 133279] [client 66.249.65.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/275/274"] [unique_id "amuwP7dt6aqtVvMundOI1QAA7yg"]
[Thu Jul 30 15:12:47.948202 2026] [security2:error] [pid 133043:tid 133213] [client 20.171.55.167:3979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/ms-site.php"] [unique_id "amuwP7dt6aqtVvMundOI3QAAAK0"]
[Thu Jul 30 15:12:48.311001 2026] [security2:error] [pid 133043:tid 133176] [client 20.104.18.253:6348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/awesome-coming-soon/come.php"] [unique_id "amuwQLdt6aqtVvMundOI6AAAAIg"]
[Thu Jul 30 15:12:48.471734 2026] [security2:error] [pid 133043:tid 133226] [client 172.237.109.114:17883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwP7dt6aqtVvMundOI3gAAALo"]
[Thu Jul 30 15:12:48.595242 2026] [security2:error] [pid 133043:tid 133271] [client 68.221.186.136:21890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/geju.php"] [unique_id "amuwQLdt6aqtVvMundOI7QAAAOc"]
[Thu Jul 30 15:12:48.683543 2026] [security2:error] [pid 133043:tid 133189] [client 20.52.54.143:10507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/abcd.php"] [unique_id "amuwQLdt6aqtVvMundOI8QAAAJU"]
[Thu Jul 30 15:12:48.864336 2026] [security2:error] [pid 133043:tid 133296] [client 20.171.55.167:3629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/network.php"] [unique_id "amuwQLdt6aqtVvMundOI9QAAAQA"]
[Thu Jul 30 15:12:48.908572 2026] [security2:error] [pid 133043:tid 133243] [client 20.104.18.253:6616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/awesome-coming-soon/flower.php"] [unique_id "amuwQLdt6aqtVvMundOI9gAAAMs"]
[Thu Jul 30 15:12:49.529670 2026] [security2:error] [pid 133043:tid 133286] [client 20.104.18.253:6338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/aws.php"] [unique_id "amuwQbdt6aqtVvMundOJBAAAAPY"]
[Thu Jul 30 15:12:49.623901 2026] [security2:error] [pid 133043:tid 133199] [client 20.52.54.143:10762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/x.php"] [unique_id "amuwQbdt6aqtVvMundOJCAAAAJ8"]
[Thu Jul 30 15:12:49.880931 2026] [security2:error] [pid 133043:tid 133190] [client 20.171.55.167:3210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/noriumportfolio/img_screen.php"] [unique_id "amuwQbdt6aqtVvMundOJDwAAAJY"]
[Thu Jul 30 15:12:49.982235 2026] [core:error] [pid 133043:tid 133063] [remote 157.55.39.222:20483] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:49.982258 2026] [core:error] [pid 133043:tid 133063] [remote 157.55.39.222:20483] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:50.131917 2026] [security2:error] [pid 133043:tid 133275] [client 20.104.18.253:6598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/ax.php"] [unique_id "amuwQrdt6aqtVvMundOJFAAAAOs"]
[Thu Jul 30 15:12:50.150632 2026] [security2:error] [pid 133043:tid 133205] [client 20.52.54.143:10511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/goods.php"] [unique_id "amuwQrdt6aqtVvMundOJFQAAAKU"]
[Thu Jul 30 15:12:50.443785 2026] [security2:error] [pid 133043:tid 133238] [client 68.221.186.136:9032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amuwQrdt6aqtVvMundOJGwAAAMY"]
[Thu Jul 30 15:12:50.527500 2026] [security2:error] [pid 133043:tid 133300] [client 185.200.117.131:59596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuwQrdt6aqtVvMundOJHwAAAQQ"]
[Thu Jul 30 15:12:50.527592 2026] [security2:error] [pid 133043:tid 133300] [client 185.200.117.131:59596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuwQrdt6aqtVvMundOJHwAAAQQ"]
[Thu Jul 30 15:12:50.712933 2026] [security2:error] [pid 133043:tid 133285] [client 20.171.55.167:3976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/on-settingssl.php"] [unique_id "amuwQrdt6aqtVvMundOJJAAAAPU"]
[Thu Jul 30 15:12:50.733718 2026] [security2:error] [pid 133043:tid 133213] [client 20.104.18.253:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/axx.php"] [unique_id "amuwQrdt6aqtVvMundOJJQAAAK0"]
[Thu Jul 30 15:12:50.941046 2026] [security2:error] [pid 133043:tid 133229] [client 102.102.249.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwQrdt6aqtVvMundOJKAAAAL0"]
[Thu Jul 30 15:12:51.338193 2026] [security2:error] [pid 133043:tid 133173] [client 20.104.18.253:6634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/ay.php"] [unique_id "amuwQ7dt6aqtVvMundOJNQAAAIU"]
[Thu Jul 30 15:12:51.474248 2026] [security2:error] [pid 133043:tid 133255] [client 172.237.109.114:56276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwQrdt6aqtVvMundOJLwAAANc"]
[Thu Jul 30 15:12:51.514222 2026] [security2:error] [pid 133043:tid 133290] [client 20.171.55.167:4050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/page.php"] [unique_id "amuwQ7dt6aqtVvMundOJPAAAAPo"]
[Thu Jul 30 15:12:51.649442 2026] [security2:error] [pid 133043:tid 133250] [client 172.237.109.114:59106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwQ7dt6aqtVvMundOJMAAAANI"]
[Thu Jul 30 15:12:51.935618 2026] [security2:error] [pid 133043:tid 133207] [client 20.104.18.253:6636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/ayk.php"] [unique_id "amuwQ7dt6aqtVvMundOJRwAAAKc"]
[Thu Jul 30 15:12:52.150472 2026] [security2:error] [pid 133043:tid 133111] [remote 74.7.243.224:60232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/partners/article.php"] [unique_id "amuwQ7dt6aqtVvMundOJQwAA8EM"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/partners/1784122808_wilde%20gazen.jpg
[Thu Jul 30 15:12:52.245491 2026] [security2:error] [pid 133043:tid 133278] [client 20.52.54.143:10534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-access.php"] [unique_id "amuwRLdt6aqtVvMundOJTAAAAO4"]
[Thu Jul 30 15:12:52.577688 2026] [security2:error] [pid 133043:tid 133235] [client 20.104.18.253:6619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/az.php"] [unique_id "amuwRLdt6aqtVvMundOJUwAAAMM"]
[Thu Jul 30 15:12:52.774370 2026] [security2:error] [pid 133043:tid 133199] [client 20.171.55.167:3635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/phpad/as.php"] [unique_id "amuwRLdt6aqtVvMundOJVwAAAJ8"]
[Thu Jul 30 15:12:53.168709 2026] [security2:error] [pid 133043:tid 133189] [client 68.221.186.136:2727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp.php"] [unique_id "amuwRbdt6aqtVvMundOJYgAAAJU"]
[Thu Jul 30 15:12:53.173318 2026] [security2:error] [pid 133043:tid 133291] [client 20.52.54.143:10550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-content/uploads/min.php"] [unique_id "amuwRbdt6aqtVvMundOJYwAAAPs"]
[Thu Jul 30 15:12:53.177215 2026] [security2:error] [pid 133043:tid 133200] [client 20.104.18.253:6621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/azdare.php"] [unique_id "amuwRbdt6aqtVvMundOJZAAAAKA"]
[Thu Jul 30 15:12:53.631406 2026] [security2:error] [pid 133043:tid 133236] [client 20.171.55.167:3972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/phpwp.php"] [unique_id "amuwRbdt6aqtVvMundOJbgAAAMQ"]
[Thu Jul 30 15:12:53.780878 2026] [security2:error] [pid 133043:tid 133276] [client 20.104.18.253:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/azra-tn/wso.php"] [unique_id "amuwRbdt6aqtVvMundOJdQAAAOw"]
[Thu Jul 30 15:12:54.157381 2026] [security2:error] [pid 133043:tid 133177] [client 213.152.161.170:55086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuwRrdt6aqtVvMundOJggAAAIk"]
[Thu Jul 30 15:12:54.157483 2026] [security2:error] [pid 133043:tid 133177] [client 213.152.161.170:55086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuwRrdt6aqtVvMundOJggAAAIk"]
[Thu Jul 30 15:12:54.365158 2026] [security2:error] [pid 133043:tid 133196] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwRbdt6aqtVvMundOJcQAAAJw"]
[Thu Jul 30 15:12:54.382652 2026] [security2:error] [pid 133043:tid 133273] [client 20.104.18.253:6364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/b.php"] [unique_id "amuwRrdt6aqtVvMundOJhgAAAOk"]
[Thu Jul 30 15:12:54.567751 2026] [security2:error] [pid 133043:tid 133287] [client 20.171.55.167:3638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/plupload/priv.php"] [unique_id "amuwRrdt6aqtVvMundOJigAAAPc"]
[Thu Jul 30 15:12:54.979674 2026] [security2:error] [pid 133043:tid 133178] [client 20.104.18.253:6603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/b374k.php"] [unique_id "amuwRrdt6aqtVvMundOJlAAAAIo"]
[Thu Jul 30 15:12:55.322914 2026] [security2:error] [pid 133043:tid 133289] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwRrdt6aqtVvMundOJjwAA-Vo"]
[Thu Jul 30 15:12:55.558849 2026] [security2:error] [pid 133043:tid 133205] [client 20.171.55.167:3625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/press/index.php"] [unique_id "amuwR7dt6aqtVvMundOJpQAAAKU"]
[Thu Jul 30 15:12:55.579586 2026] [security2:error] [pid 133043:tid 133264] [client 20.104.18.253:33867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/b8b.php"] [unique_id "amuwR7dt6aqtVvMundOJpgAAAOA"]
[Thu Jul 30 15:12:55.648028 2026] [core:error] [pid 133043:tid 133201] [client 5.161.206.147:8734] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:55.648050 2026] [core:error] [pid 133043:tid 133201] [client 5.161.206.147:8734] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:55.866325 2026] [core:error] [pid 133043:tid 133260] [client 5.161.206.147:30176] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:55.866351 2026] [core:error] [pid 133043:tid 133260] [client 5.161.206.147:30176] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:55.877436 2026] [core:error] [pid 133043:tid 133282] [client 185.148.0.208:38002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:55.877456 2026] [core:error] [pid 133043:tid 133282] [client 185.148.0.208:38002] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:55.930372 2026] [security2:error] [pid 133043:tid 133107] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwR7dt6aqtVvMundOJtgAA9T8"]
[Thu Jul 30 15:12:55.930558 2026] [security2:error] [pid 133043:tid 133285] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwR7dt6aqtVvMundOJtgAA9T8"]
[Thu Jul 30 15:12:56.132255 2026] [security2:error] [pid 133043:tid 133300] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwR7dt6aqtVvMundOJogAAAQQ"]
[Thu Jul 30 15:12:56.178396 2026] [security2:error] [pid 133043:tid 133216] [client 20.104.18.253:6614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.northyorksheridanmall.com"] [uri "/babu.php"] [unique_id "amuwSLdt6aqtVvMundOJvQAAALA"]
[Thu Jul 30 15:12:56.333970 2026] [core:notice] [pid 133043:tid 133243] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:56.404915 2026] [security2:error] [pid 133043:tid 133219] [client 20.171.55.167:3213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/product.php"] [unique_id "amuwSLdt6aqtVvMundOJxQAAALM"]
[Thu Jul 30 15:12:56.620055 2026] [proxy:error] [pid 133043:tid 133273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:56.620129 2026] [proxy_http:error] [pid 133043:tid 133273] [client 5.161.206.147:10100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:56.620708 2026] [proxy:error] [pid 133043:tid 133273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:56.620753 2026] [proxy_http:error] [pid 133043:tid 133273] [client 5.161.206.147:10100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:56.623686 2026] [core:notice] [pid 133043:tid 133212] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:12:56.640328 2026] [proxy:error] [pid 133043:tid 133280] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:56.640405 2026] [proxy_http:error] [pid 133043:tid 133280] [client 5.161.206.147:10108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:56.641002 2026] [proxy:error] [pid 133043:tid 133280] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:56.641050 2026] [proxy_http:error] [pid 133043:tid 133280] [client 5.161.206.147:10108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:56.648124 2026] [core:error] [pid 133043:tid 133262] [client 5.161.206.147:10120] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:56.648145 2026] [core:error] [pid 133043:tid 133262] [client 5.161.206.147:10120] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:56.822675 2026] [proxy:error] [pid 133043:tid 133287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:56.822736 2026] [proxy_http:error] [pid 133043:tid 133287] [client 5.161.206.147:21308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:56.823324 2026] [proxy:error] [pid 133043:tid 133287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:56.823370 2026] [proxy_http:error] [pid 133043:tid 133287] [client 5.161.206.147:21308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:56.835801 2026] [proxy:error] [pid 133043:tid 133221] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:56.835887 2026] [proxy_http:error] [pid 133043:tid 133221] [client 5.161.206.147:21312] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:56.836481 2026] [proxy:error] [pid 133043:tid 133221] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:12:56.836537 2026] [proxy_http:error] [pid 133043:tid 133221] [client 5.161.206.147:21312] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:12:56.840062 2026] [core:error] [pid 133043:tid 133218] [client 5.161.206.147:21328] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:56.840077 2026] [core:error] [pid 133043:tid 133218] [client 5.161.206.147:21328] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:57.293368 2026] [security2:error] [pid 133043:tid 133299] [client 20.171.55.167:3640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/purna.php"] [unique_id "amuwSbdt6aqtVvMundOJ4gAAAQM"]
[Thu Jul 30 15:12:57.447750 2026] [security2:error] [pid 133043:tid 133209] [client 172.237.109.114:1508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwSLdt6aqtVvMundOJ2AAAAKk"]
[Thu Jul 30 15:12:57.479354 2026] [security2:error] [pid 133043:tid 133232] [client 68.221.186.136:9508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/aaa.php"] [unique_id "amuwSbdt6aqtVvMundOJ5gAAAMA"]
[Thu Jul 30 15:12:57.605556 2026] [core:error] [pid 133043:tid 133158] [remote 157.55.39.222:20508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:57.605582 2026] [core:error] [pid 133043:tid 133158] [remote 157.55.39.222:20508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:12:57.823936 2026] [security2:error] [pid 133043:tid 133298] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwSbdt6aqtVvMundOJ4QAAAQI"]
[Thu Jul 30 15:12:58.008311 2026] [security2:error] [pid 133043:tid 133271] [client 20.171.55.167:3229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/raf.php"] [unique_id "amuwSrdt6aqtVvMundOJ9QAAAOc"]
[Thu Jul 30 15:12:58.674130 2026] [security2:error] [pid 133043:tid 133258] [client 20.52.54.143:10767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/filemanager.php"] [unique_id "amuwSrdt6aqtVvMundOKCwAAANo"]
[Thu Jul 30 15:12:58.762126 2026] [security2:error] [pid 133043:tid 133216] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwSrdt6aqtVvMundOJ-gAAALA"]
[Thu Jul 30 15:12:58.840265 2026] [security2:error] [pid 133043:tid 133267] [client 20.171.55.167:3409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/revisi.php"] [unique_id "amuwSrdt6aqtVvMundOKEAAAAOM"]
[Thu Jul 30 15:12:59.110625 2026] [security2:error] [pid 133043:tid 133240] [client 68.221.186.136:22584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/hoot.php"] [unique_id "amuwS7dt6aqtVvMundOKGAAAAMg"]
[Thu Jul 30 15:12:59.280308 2026] [security2:error] [pid 133043:tid 133177] [client 20.52.54.143:10778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-includes/ID3/index.php"] [unique_id "amuwS7dt6aqtVvMundOKHgAAAIk"]
[Thu Jul 30 15:12:59.472374 2026] [security2:error] [pid 133043:tid 133294] [client 172.237.109.114:19652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwSrdt6aqtVvMundOKEQAAAP4"]
[Thu Jul 30 15:13:00.282474 2026] [security2:error] [pid 133043:tid 133200] [client 20.171.55.167:3238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/rtheq.php"] [unique_id "amuwTLdt6aqtVvMundOKOAAAAKA"]
[Thu Jul 30 15:13:00.477078 2026] [security2:error] [pid 133043:tid 133238] [client 20.52.54.143:10768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/bthil.php"] [unique_id "amuwTLdt6aqtVvMundOKQAAAAMY"]
[Thu Jul 30 15:13:00.767610 2026] [security2:error] [pid 133043:tid 133173] [client 68.221.186.136:22575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/about.php"] [unique_id "amuwTLdt6aqtVvMundOKRgAAAIU"]
[Thu Jul 30 15:13:01.073572 2026] [security2:error] [pid 133043:tid 133216] [client 20.171.55.167:3975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/script-loader.php"] [unique_id "amuwTbdt6aqtVvMundOKUQAAALA"]
[Thu Jul 30 15:13:01.415487 2026] [security2:error] [pid 133043:tid 133183] [client 68.221.186.136:9069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/admin.php"] [unique_id "amuwTbdt6aqtVvMundOKWQAAAI8"]
[Thu Jul 30 15:13:01.444504 2026] [core:notice] [pid 133043:tid 133061] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:01.535020 2026] [security2:error] [pid 133043:tid 133274] [client 84.75.220.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.220.75.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "baytalhuboob.com"] [uri "/wp-login.php"] [unique_id "amuwTbdt6aqtVvMundOKUAAAAOo"]
[Thu Jul 30 15:13:01.837681 2026] [security2:error] [pid 133043:tid 133189] [client 20.52.54.143:10759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/xmlrpc.php"] [unique_id "amuwTbdt6aqtVvMundOKawAAAJU"]
[Thu Jul 30 15:13:02.021335 2026] [security2:error] [pid 133043:tid 133204] [client 20.171.55.167:4013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/seotheme/dropdown.php"] [unique_id "amuwTrdt6aqtVvMundOKcgAAAKQ"]
[Thu Jul 30 15:13:02.516078 2026] [security2:error] [pid 133043:tid 133300] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwTbdt6aqtVvMundOKcQAAAQQ"]
[Thu Jul 30 15:13:02.710460 2026] [security2:error] [pid 133043:tid 133212] [client 68.221.186.136:2700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuwTrdt6aqtVvMundOKgQAAAKw"]
[Thu Jul 30 15:13:02.833273 2026] [security2:error] [pid 133043:tid 133277] [client 57.141.0.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwTrdt6aqtVvMundOKdQAAAO0"]
[Thu Jul 30 15:13:02.916610 2026] [security2:error] [pid 133043:tid 133233] [client 20.171.55.167:3371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/shell.php"] [unique_id "amuwTrdt6aqtVvMundOKhQAAAME"]
[Thu Jul 30 15:13:03.470655 2026] [security2:error] [pid 133043:tid 133258] [client 46.248.208.152:11970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuwTbdt6aqtVvMundOKUgAAANo"]
[Thu Jul 30 15:13:03.970501 2026] [security2:error] [pid 133043:tid 133260] [client 20.171.55.167:3587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/sidebart.php"] [unique_id "amuwT7dt6aqtVvMundOKogAAANw"]
[Thu Jul 30 15:13:04.341699 2026] [security2:error] [pid 133043:tid 133199] [client 68.221.186.136:4986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/db-cache.php"] [unique_id "amuwULdt6aqtVvMundOKsQAAAJ8"]
[Thu Jul 30 15:13:04.401640 2026] [security2:error] [pid 133043:tid 133100] [remote 57.141.18.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuwULdt6aqtVvMundOKrAAAvzg"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Ccarbon%2Cdenim%2Cpolyester%2Cplastic%2Clinen%2Ctitanium%2Ccotton&orderby=price&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 15:13:04.461238 2026] [security2:error] [pid 133043:tid 133110] [remote 57.141.18.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuwULdt6aqtVvMundOKrQAAzkI"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=aluminum%2Ccarbon%2Cdenim%2Cpolyester%2Cplastic%2Clinen%2Ctitanium%2Ccotton&orderby=price&rating=5&tax_product_cat=furniture&unfilter=1
[Thu Jul 30 15:13:04.699612 2026] [security2:error] [pid 133043:tid 133210] [client 20.171.55.167:3257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/sitesadmin.php"] [unique_id "amuwULdt6aqtVvMundOKvQAAAKo"]
[Thu Jul 30 15:13:04.889381 2026] [autoindex:error] [pid 133043:tid 133269] [client 185.148.0.208:38002] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:13:05.038966 2026] [security2:error] [pid 133043:tid 133255] [client 20.52.54.143:10496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/cv.php"] [unique_id "amuwUbdt6aqtVvMundOKxgAAANc"]
[Thu Jul 30 15:13:05.488403 2026] [security2:error] [pid 133043:tid 133216] [client 20.171.55.167:4003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/smilies/priv.php"] [unique_id "amuwUbdt6aqtVvMundOK0QAAALA"]
[Thu Jul 30 15:13:06.348666 2026] [security2:error] [pid 133043:tid 133242] [client 20.171.55.167:3363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/ssa.php"] [unique_id "amuwUrdt6aqtVvMundOK4gAAAMo"]
[Thu Jul 30 15:13:06.504225 2026] [security2:error] [pid 133043:tid 133094] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwUrdt6aqtVvMundOK5gAAiDI"]
[Thu Jul 30 15:13:06.504463 2026] [security2:error] [pid 133043:tid 133176] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwUrdt6aqtVvMundOK5gAAiDI"]
[Thu Jul 30 15:13:07.504792 2026] [security2:error] [pid 133043:tid 133202] [client 185.200.117.131:39728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuwU7dt6aqtVvMundOK-QAAAKI"]
[Thu Jul 30 15:13:07.504873 2026] [security2:error] [pid 133043:tid 133202] [client 185.200.117.131:39728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuwU7dt6aqtVvMundOK-QAAAKI"]
[Thu Jul 30 15:13:07.694690 2026] [security2:error] [pid 133043:tid 133286] [client 20.171.55.167:3247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/sts.php"] [unique_id "amuwU7dt6aqtVvMundOK_QAAAPY"]
[Thu Jul 30 15:13:08.625076 2026] [security2:error] [pid 133043:tid 133287] [client 20.171.55.167:4019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/sys.php"] [unique_id "amuwVLdt6aqtVvMundOLEgAAAPc"]
[Thu Jul 30 15:13:08.767368 2026] [security2:error] [pid 133043:tid 133251] [client 68.221.186.136:6194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amuwVLdt6aqtVvMundOLGQAAANM"]
[Thu Jul 30 15:13:09.451172 2026] [security2:error] [pid 133043:tid 133205] [client 172.237.109.114:19321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwVLdt6aqtVvMundOLGgAAAKU"]
[Thu Jul 30 15:13:09.458688 2026] [security2:error] [pid 133043:tid 133253] [client 20.171.55.167:4014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/tesla.php"] [unique_id "amuwVbdt6aqtVvMundOLLAAAANU"]
[Thu Jul 30 15:13:09.571463 2026] [core:notice] [pid 133043:tid 133128] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:09.775771 2026] [security2:error] [pid 133043:tid 133134] [remote 57.141.0.18:53332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/66526086350/feed/rss2/"] [unique_id "amuwVbdt6aqtVvMundOLNQAAm1o"]
[Thu Jul 30 15:13:10.519030 2026] [security2:error] [pid 133043:tid 133272] [client 20.171.55.167:4017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/themes/wp-login.php"] [unique_id "amuwVrdt6aqtVvMundOLPwAAAOg"]
[Thu Jul 30 15:13:10.522765 2026] [core:notice] [pid 133043:tid 133175] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:10.858752 2026] [security2:error] [pid 133043:tid 133183] [client 68.221.186.136:22544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amuwVrdt6aqtVvMundOLTwAAAI8"]
[Thu Jul 30 15:13:11.197944 2026] [security2:error] [pid 133043:tid 133280] [client 20.52.54.143:10780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-content/packed.php"] [unique_id "amuwV7dt6aqtVvMundOLVAAAAPA"]
[Thu Jul 30 15:13:11.362916 2026] [security2:error] [pid 133043:tid 133252] [client 20.171.55.167:3244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/tinymce/wp-tinymce.php"] [unique_id "amuwV7dt6aqtVvMundOLWgAAANQ"]
[Thu Jul 30 15:13:11.578356 2026] [security2:error] [pid 133043:tid 133283] [client 172.237.109.114:50539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwV7dt6aqtVvMundOLUAAAAPM"]
[Thu Jul 30 15:13:12.289034 2026] [security2:error] [pid 133043:tid 133267] [client 20.171.55.167:4008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/tro.php"] [unique_id "amuwWLdt6aqtVvMundOLcgAAAOM"]
[Thu Jul 30 15:13:12.455747 2026] [security2:error] [pid 133043:tid 133192] [client 172.237.109.114:24598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwV7dt6aqtVvMundOLZwAAAJg"]
[Thu Jul 30 15:13:12.558039 2026] [security2:error] [pid 133043:tid 133182] [client 20.52.54.143:10522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/css.php"] [unique_id "amuwWLdt6aqtVvMundOLdgAAAI4"]
[Thu Jul 30 15:13:12.808511 2026] [autoindex:error] [pid 133043:tid 133197] [client 185.148.0.208:54724] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:13:13.149911 2026] [security2:error] [pid 133043:tid 133241] [client 20.171.55.167:3970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/twentytwentyfour/system_cache.php"] [unique_id "amuwWbdt6aqtVvMundOLgwAAAMk"]
[Thu Jul 30 15:13:13.284927 2026] [core:notice] [pid 133043:tid 133183] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:13.881116 2026] [security2:error] [pid 133043:tid 133179] [client 20.52.54.143:10539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-admin/js/index.php"] [unique_id "amuwWbdt6aqtVvMundOLkQAAAIs"]
[Thu Jul 30 15:13:14.180941 2026] [security2:error] [pid 133043:tid 133237] [client 20.171.55.167:3233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/udr73i.php"] [unique_id "amuwWrdt6aqtVvMundOLogAAAMU"]
[Thu Jul 30 15:13:14.438072 2026] [security2:error] [pid 133043:tid 133269] [client 20.52.54.143:10512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/core.php"] [unique_id "amuwWrdt6aqtVvMundOLqwAAAOU"]
[Thu Jul 30 15:13:15.238175 2026] [security2:error] [pid 133043:tid 133240] [client 66.132.186.175:10438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "sh00085.hostgator.com"] [uri "/index.cgi"] [unique_id "amuwWrdt6aqtVvMundOLtwAAAMg"]
[Thu Jul 30 15:13:15.524376 2026] [security2:error] [pid 133043:tid 133228] [client 68.221.186.136:4939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amuwW7dt6aqtVvMundOLuAAAALw"]
[Thu Jul 30 15:13:15.602752 2026] [security2:error] [pid 133043:tid 133274] [client 20.171.55.167:4020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/upload_handler.php"] [unique_id "amuwW7dt6aqtVvMundOLuQAAAOo"]
[Thu Jul 30 15:13:16.199632 2026] [security2:error] [pid 133043:tid 133282] [client 216.244.66.199:39428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuwXLdt6aqtVvMundOLwwAAAPI"]
[Thu Jul 30 15:13:16.199767 2026] [security2:error] [pid 133043:tid 133282] [client 216.244.66.199:39428] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuwXLdt6aqtVvMundOLwwAAAPI"]
[Thu Jul 30 15:13:16.424753 2026] [security2:error] [pid 133043:tid 133185] [client 20.171.55.167:3237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/use.php"] [unique_id "amuwXLdt6aqtVvMundOLygAAAJE"]
[Thu Jul 30 15:13:16.845860 2026] [security2:error] [pid 133043:tid 133244] [client 68.221.186.136:11623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amuwXLdt6aqtVvMundOL1wAAAMw"]
[Thu Jul 30 15:13:17.026594 2026] [security2:error] [pid 133043:tid 133059] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwXbdt6aqtVvMundOL2AAA_A8"]
[Thu Jul 30 15:13:17.026751 2026] [security2:error] [pid 133043:tid 133292] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwXbdt6aqtVvMundOL2AAA_A8"]
[Thu Jul 30 15:13:17.133223 2026] [core:notice] [pid 133043:tid 133056] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:17.191033 2026] [security2:error] [pid 133043:tid 133204] [client 20.171.55.167:3631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/vendoralfa.php"] [unique_id "amuwXbdt6aqtVvMundOL3AAAAKQ"]
[Thu Jul 30 15:13:17.247048 2026] [security2:error] [pid 133043:tid 133173] [client 20.52.54.143:10252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/admin/function.php"] [unique_id "amuwXbdt6aqtVvMundOL3gAAAIU"]
[Thu Jul 30 15:13:17.366944 2026] [core:error] [pid 133043:tid 133264] [client 185.148.0.208:54738] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:13:17.366985 2026] [core:error] [pid 133043:tid 133264] [client 185.148.0.208:54738] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:13:18.088051 2026] [security2:error] [pid 133043:tid 133285] [client 20.171.55.167:3594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/vwx.php"] [unique_id "amuwXrdt6aqtVvMundOL7wAAAPU"]
[Thu Jul 30 15:13:18.122800 2026] [security2:error] [pid 133043:tid 133263] [client 68.221.186.136:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amuwXrdt6aqtVvMundOL8AAAAN8"]
[Thu Jul 30 15:13:18.732997 2026] [security2:error] [pid 133043:tid 133219] [client 116.204.44.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwXrdt6aqtVvMundOL_QAAALM"], referer: http://cnpinyin.com/dict1?search=%e5%a4%a9%e7%a7%a4
[Thu Jul 30 15:13:18.802567 2026] [security2:error] [pid 133043:tid 133175] [client 68.221.186.136:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/content.php"] [unique_id "amuwXrdt6aqtVvMundOMAgAAAIc"]
[Thu Jul 30 15:13:19.176300 2026] [security2:error] [pid 133043:tid 133186] [client 20.171.55.167:3896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wi.php"] [unique_id "amuwX7dt6aqtVvMundOMDQAAAJI"]
[Thu Jul 30 15:13:19.292574 2026] [security2:error] [pid 133043:tid 133214] [client 68.221.186.136:9086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dhowcruisedinner.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amuwX7dt6aqtVvMundOMEgAAAK4"]
[Thu Jul 30 15:13:19.945585 2026] [security2:error] [pid 133043:tid 133223] [client 20.171.55.167:3901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/widgets/xmrlpc.php"] [unique_id "amuwX7dt6aqtVvMundOMJwAAALc"]
[Thu Jul 30 15:13:20.210068 2026] [core:error] [pid 133043:tid 133227] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:13:20.210091 2026] [core:error] [pid 133043:tid 133227] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:13:20.863519 2026] [security2:error] [pid 133043:tid 133175] [client 20.171.55.167:3222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wordpresss3cll/includes.php"] [unique_id "amuwYLdt6aqtVvMundOMPgAAAIc"]
[Thu Jul 30 15:13:21.578363 2026] [core:error] [pid 133043:tid 133100] [remote 74.7.244.39:44700] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:13:21.578387 2026] [core:error] [pid 133043:tid 133100] [remote 74.7.244.39:44700] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:13:21.578543 2026] [security2:error] [pid 133043:tid 133245] [client 74.7.244.39:44700] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-c84df7de.ooj.hfl.temporary.site"] [uri "/website_c84df7de/index.php"] [unique_id "amuwYbdt6aqtVvMundOMUwAAzTg"]
[Thu Jul 30 15:13:21.989110 2026] [security2:error] [pid 133043:tid 133269] [client 185.200.117.131:41650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuwYbdt6aqtVvMundOMXAAAAOU"]
[Thu Jul 30 15:13:21.989195 2026] [security2:error] [pid 133043:tid 133269] [client 185.200.117.131:41650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuwYbdt6aqtVvMundOMXAAAAOU"]
[Thu Jul 30 15:13:22.105705 2026] [security2:error] [pid 133043:tid 133205] [client 20.171.55.167:3988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wp-api.php"] [unique_id "amuwYrdt6aqtVvMundOMYgAAAKU"]
[Thu Jul 30 15:13:22.460081 2026] [security2:error] [pid 133043:tid 133225] [client 20.52.54.143:10269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/admin/index.php"] [unique_id "amuwYrdt6aqtVvMundOMawAAALk"]
[Thu Jul 30 15:13:22.948759 2026] [security2:error] [pid 133043:tid 133175] [client 20.171.55.167:3240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wp-comments.php"] [unique_id "amuwYrdt6aqtVvMundOMfgAAAIc"]
[Thu Jul 30 15:13:23.233669 2026] [security2:error] [pid 133043:tid 133211] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwYrdt6aqtVvMundOMeAAAAKs"]
[Thu Jul 30 15:13:23.630619 2026] [security2:error] [pid 133043:tid 133196] [client 185.177.72.12:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwY7dt6aqtVvMundOMlAAAAJw"]
[Thu Jul 30 15:13:23.773012 2026] [security2:error] [pid 133043:tid 133259] [client 20.52.54.143:10248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/storage/rip.php"] [unique_id "amuwY7dt6aqtVvMundOMlQAAANs"]
[Thu Jul 30 15:13:23.884269 2026] [security2:error] [pid 133043:tid 133221] [client 185.177.72.12:58194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amuwY7dt6aqtVvMundOMlgAAALU"]
[Thu Jul 30 15:13:23.896055 2026] [security2:error] [pid 133043:tid 133231] [client 20.171.55.167:3888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wp-daft/miin.php"] [unique_id "amuwY7dt6aqtVvMundOMlwAAAL8"]
[Thu Jul 30 15:13:24.134731 2026] [security2:error] [pid 133043:tid 133228] [client 185.177.72.12:58200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwZLdt6aqtVvMundOMpQAAALw"]
[Thu Jul 30 15:13:24.386467 2026] [security2:error] [pid 133043:tid 133209] [client 185.177.72.12:58214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwZLdt6aqtVvMundOMqQAAAKk"]
[Thu Jul 30 15:13:24.402393 2026] [security2:error] [pid 133043:tid 133184] [client 64.31.3.126:48653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuwYrdt6aqtVvMundOMYwAAAKg"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2268
[Thu Jul 30 15:13:24.637747 2026] [security2:error] [pid 133043:tid 133279] [client 185.177.72.12:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwZLdt6aqtVvMundOMtAAAAO8"]
[Thu Jul 30 15:13:24.849179 2026] [security2:error] [pid 133043:tid 133295] [client 20.171.55.167:3805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wp-freeform/includes/loadme.php"] [unique_id "amuwZLdt6aqtVvMundOMuAAAAP8"]
[Thu Jul 30 15:13:24.889810 2026] [security2:error] [pid 133043:tid 133201] [client 185.177.72.12:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwZLdt6aqtVvMundOMugAAAKE"]
[Thu Jul 30 15:13:25.043578 2026] [security2:error] [pid 133043:tid 133189] [client 20.52.54.143:10242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/ahax.php"] [unique_id "amuwZbdt6aqtVvMundOMvgAAAJU"]
[Thu Jul 30 15:13:25.759423 2026] [security2:error] [pid 133043:tid 133244] [client 20.52.54.143:10506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/zoom1.php"] [unique_id "amuwZbdt6aqtVvMundOM1QAAAMw"]
[Thu Jul 30 15:13:25.779796 2026] [security2:error] [pid 133043:tid 133253] [client 20.171.55.167:3807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.northyorksheridanmall.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuwZbdt6aqtVvMundOM1gAAANU"]
[Thu Jul 30 15:13:26.673636 2026] [security2:error] [pid 133043:tid 133197] [client 20.171.55.167:3848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wp-nakal.php"] [unique_id "amuwZrdt6aqtVvMundOM6gAAAJ0"]
[Thu Jul 30 15:13:27.407635 2026] [security2:error] [pid 133043:tid 133188] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwZrdt6aqtVvMundOM7wAAlGY"]
[Thu Jul 30 15:13:27.594798 2026] [security2:error] [pid 133043:tid 133107] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwZ7dt6aqtVvMundOM_wAAhz8"]
[Thu Jul 30 15:13:27.594941 2026] [security2:error] [pid 133043:tid 133175] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwZ7dt6aqtVvMundOM_wAAhz8"]
[Thu Jul 30 15:13:27.611302 2026] [security2:error] [pid 133043:tid 133220] [client 20.171.55.167:3800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wp-scriptss.php"] [unique_id "amuwZ7dt6aqtVvMundONAwAAALQ"]
[Thu Jul 30 15:13:27.626543 2026] [security2:error] [pid 133043:tid 133279] [client 20.52.54.143:10260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/txets.php"] [unique_id "amuwZ7dt6aqtVvMundONBAAAAO8"]
[Thu Jul 30 15:13:28.507090 2026] [security2:error] [pid 133043:tid 133258] [client 20.171.55.167:3845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wp-update.php"] [unique_id "amuwaLdt6aqtVvMundONIAAAANo"]
[Thu Jul 30 15:13:28.536195 2026] [security2:error] [pid 133043:tid 133225] [client 185.177.72.5:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwaLdt6aqtVvMundONIgAAALk"]
[Thu Jul 30 15:13:28.781808 2026] [core:notice] [pid 133043:tid 133148] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:28.786666 2026] [security2:error] [pid 133043:tid 133263] [client 185.177.72.5:55028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amuwaLdt6aqtVvMundONKAAAAN8"]
[Thu Jul 30 15:13:28.788413 2026] [security2:error] [pid 133043:tid 133149] [remote 57.141.0.43:63410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/432552404/feed/rss2/"] [unique_id "amuwaLdt6aqtVvMundONKQAAo2k"]
[Thu Jul 30 15:13:28.836024 2026] [security2:error] [pid 133043:tid 133281] [client 128.140.41.193:9228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuwaLdt6aqtVvMundONKwAAAPE"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:13:29.039119 2026] [security2:error] [pid 133043:tid 133251] [client 185.177.72.5:55034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwabdt6aqtVvMundONMQAAANM"]
[Thu Jul 30 15:13:29.134433 2026] [security2:error] [pid 133043:tid 133157] [remote 57.141.0.70:24102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/432552404/feed/rss2/"] [unique_id "amuwabdt6aqtVvMundONOAAAl3E"]
[Thu Jul 30 15:13:29.214004 2026] [core:notice] [pid 133043:tid 133252] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:29.219183 2026] [security2:error] [pid 133043:tid 133252] [client 128.140.41.193:9242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuwabdt6aqtVvMundONOQAAANQ"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:13:29.293957 2026] [security2:error] [pid 133043:tid 133276] [client 185.177.72.5:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwabdt6aqtVvMundONOgAAAOw"]
[Thu Jul 30 15:13:29.552195 2026] [security2:error] [pid 133043:tid 133265] [client 185.177.72.5:55054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwabdt6aqtVvMundONQQAAAOE"]
[Thu Jul 30 15:13:29.622848 2026] [security2:error] [pid 133043:tid 133188] [client 20.171.55.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wpcall-button/dropdown.php"] [unique_id "amuwabdt6aqtVvMundONQgAAAJQ"]
[Thu Jul 30 15:13:29.768330 2026] [core:notice] [pid 133043:tid 133176] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:29.801606 2026] [security2:error] [pid 133043:tid 133204] [client 185.177.72.5:55070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuwabdt6aqtVvMundONSgAAAKQ"]
[Thu Jul 30 15:13:29.833669 2026] [security2:error] [pid 133043:tid 133297] [client 128.140.41.193:9252] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuwabdt6aqtVvMundONSwAAAQE"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:13:29.955368 2026] [core:notice] [pid 133043:tid 133182] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:30.518289 2026] [security2:error] [pid 133043:tid 133255] [client 20.171.55.167:3866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/wso.php"] [unique_id "amuwardt6aqtVvMundONXgAAANc"]
[Thu Jul 30 15:13:30.732756 2026] [security2:error] [pid 133043:tid 133248] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwabdt6aqtVvMundONSQAAANA"]
[Thu Jul 30 15:13:30.750867 2026] [core:notice] [pid 133043:tid 133285] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:31.353090 2026] [security2:error] [pid 133043:tid 133262] [client 20.171.55.167:3844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/x35.php"] [unique_id "amuwa7dt6aqtVvMundONcQAAAN4"]
[Thu Jul 30 15:13:31.523095 2026] [security2:error] [pid 133043:tid 133251] [client 20.52.54.143:10499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-content/themes/about.php"] [unique_id "amuwa7dt6aqtVvMundONdwAAANM"]
[Thu Jul 30 15:13:32.144525 2026] [security2:error] [pid 133043:tid 133284] [client 20.171.55.167:3837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/xltavrat.php"] [unique_id "amuwbLdt6aqtVvMundONggAAAPQ"]
[Thu Jul 30 15:13:33.022881 2026] [security2:error] [pid 133043:tid 133253] [client 20.171.55.167:3778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/yee.php"] [unique_id "amuwbbdt6aqtVvMundONkgAAANU"]
[Thu Jul 30 15:13:33.839470 2026] [core:notice] [pid 133043:tid 133173] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:34.067931 2026] [security2:error] [pid 133043:tid 133055] [remote 216.73.216.51:28024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuwbrdt6aqtVvMundONpwAA-Qs"]
[Thu Jul 30 15:13:34.067972 2026] [security2:error] [pid 133043:tid 133299] [client 20.171.55.167:3797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.northyorksheridanmall.com"] [uri "/zgdsfags/rk3.php"] [unique_id "amuwbrdt6aqtVvMundONqAAAAQM"]
[Thu Jul 30 15:13:34.887674 2026] [security2:error] [pid 133043:tid 133266] [client 20.52.54.143:10554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-includes/assets/index.php"] [unique_id "amuwbrdt6aqtVvMundONxgAAAOI"]
[Thu Jul 30 15:13:34.914268 2026] [security2:error] [pid 133043:tid 133072] [remote 57.141.0.50:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/432552404/feed/rss2/"] [unique_id "amuwbrdt6aqtVvMundONxwAAqxw"]
[Thu Jul 30 15:13:35.142372 2026] [security2:error] [pid 133043:tid 133214] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwbrdt6aqtVvMundONtgAAAK4"]
[Thu Jul 30 15:13:35.239608 2026] [core:notice] [pid 133043:tid 133136] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:35.390606 2026] [core:notice] [pid 133043:tid 133239] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:36.358199 2026] [security2:error] [pid 133043:tid 133233] [client 2a03:2880:f800:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwb7dt6aqtVvMundON3gAAwRQ"]
[Thu Jul 30 15:13:36.653154 2026] [security2:error] [pid 133043:tid 133209] [client 20.52.54.143:10535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-admin/index.php"] [unique_id "amuwcLdt6aqtVvMundON8gAAAKk"]
[Thu Jul 30 15:13:36.850836 2026] [security2:error] [pid 133043:tid 133269] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwcLdt6aqtVvMundON6QAA5Sg"]
[Thu Jul 30 15:13:37.342521 2026] [security2:error] [pid 133043:tid 133217] [client 20.52.54.143:10283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/radio.php"] [unique_id "amuwcbdt6aqtVvMundOOAwAAALE"]
[Thu Jul 30 15:13:37.526423 2026] [security2:error] [pid 133043:tid 133103] [remote 57.141.0.11:62264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amuwcbdt6aqtVvMundOOBwAA5js"]
[Thu Jul 30 15:13:37.581847 2026] [core:notice] [pid 133043:tid 133075] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:38.116007 2026] [security2:error] [pid 133043:tid 133199] [client 20.52.54.143:10249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/item.php"] [unique_id "amuwcrdt6aqtVvMundOOFAAAAJ8"]
[Thu Jul 30 15:13:38.199650 2026] [core:notice] [pid 133043:tid 133063] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:38.295074 2026] [security2:error] [pid 133043:tid 133101] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwcrdt6aqtVvMundOOHAAA_Tk"]
[Thu Jul 30 15:13:38.295246 2026] [security2:error] [pid 133043:tid 133293] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwcrdt6aqtVvMundOOHAAA_Tk"]
[Thu Jul 30 15:13:38.651948 2026] [security2:error] [pid 133043:tid 133198] [client 172.237.109.114:49503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwcrdt6aqtVvMundOOEwAAAJ4"]
[Thu Jul 30 15:13:38.860797 2026] [core:notice] [pid 133043:tid 133240] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:38.994426 2026] [core:notice] [pid 133043:tid 133076] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:40.456921 2026] [security2:error] [pid 133043:tid 133266] [client 172.237.109.114:19921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwc7dt6aqtVvMundOOQQAAAOI"]
[Thu Jul 30 15:13:40.502656 2026] [security2:error] [pid 133043:tid 133192] [client 45.5.118.215:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwdLdt6aqtVvMundOOTAAAAJg"], referer: https://cnpinyin.com
[Thu Jul 30 15:13:40.867773 2026] [security2:error] [pid 133043:tid 133257] [client 20.52.54.143:10273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/t.php"] [unique_id "amuwdLdt6aqtVvMundOOWAAAANk"]
[Thu Jul 30 15:13:40.943346 2026] [core:notice] [pid 133043:tid 133116] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:41.098849 2026] [proxy:error] [pid 133043:tid 133187] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:13:41.098932 2026] [proxy_http:error] [pid 133043:tid 133187] [client 87.236.176.132:38475] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:13:41.099582 2026] [proxy:error] [pid 133043:tid 133187] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:13:41.099630 2026] [proxy_http:error] [pid 133043:tid 133187] [client 87.236.176.132:38475] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:13:41.147177 2026] [security2:error] [pid 133043:tid 133234] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwdLdt6aqtVvMundOOVgAAwks"]
[Thu Jul 30 15:13:41.444057 2026] [security2:error] [pid 133043:tid 133199] [client 66.249.68.66:52215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nobleinternationals.com"] [uri "/index.php/favicon.ico"] [unique_id "amuwdLdt6aqtVvMundOOWQAAAJ8"]
[Thu Jul 30 15:13:41.498961 2026] [security2:error] [pid 133043:tid 133206] [client 20.52.54.143:10920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/i.php"] [unique_id "amuwdbdt6aqtVvMundOOawAAAKY"]
[Thu Jul 30 15:13:42.027379 2026] [security2:error] [pid 133043:tid 133260] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwdbdt6aqtVvMundOOZwAAANw"]
[Thu Jul 30 15:13:42.516428 2026] [security2:error] [pid 133043:tid 133276] [client 172.237.109.114:45465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwdrdt6aqtVvMundOOewAAAOw"]
[Thu Jul 30 15:13:42.541962 2026] [security2:error] [pid 133043:tid 133217] [client 68.183.185.171:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.185.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amuwdrdt6aqtVvMundOOggAAALE"]
[Thu Jul 30 15:13:42.945267 2026] [security2:error] [pid 133043:tid 133292] [client 66.249.71.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vanguardlegalassociates.team"] [uri "/index.php"] [unique_id "amuwdrdt6aqtVvMundOOigAA_Go"]
[Thu Jul 30 15:13:43.081288 2026] [security2:error] [pid 133043:tid 133151] [remote 57.141.0.13:33994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuwd7dt6aqtVvMundOOkAAAm2s"]
[Thu Jul 30 15:13:44.462178 2026] [core:notice] [pid 133043:tid 133135] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:44.540100 2026] [security2:error] [pid 133043:tid 133256] [client 20.52.54.143:10933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/deepseek_d.php"] [unique_id "amuweLdt6aqtVvMundOOsgAAANg"]
[Thu Jul 30 15:13:45.730495 2026] [security2:error] [pid 133043:tid 133195] [client 112.207.210.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwebdt6aqtVvMundOOzgAAAJs"], referer: https://cnpinyin.com/mycertificates
[Thu Jul 30 15:13:45.976886 2026] [security2:error] [pid 133043:tid 133187] [client 127.0.0.1:28340] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuwebdt6aqtVvMundOO2QAAAJM"]
[Thu Jul 30 15:13:45.976986 2026] [security2:error] [pid 133043:tid 133273] [client 74.7.244.23:58080] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ysw.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuwebdt6aqtVvMundOO2AAAAOk"]
[Thu Jul 30 15:13:46.562639 2026] [security2:error] [pid 133043:tid 133173] [client 20.52.54.143:10889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "amuwerdt6aqtVvMundOO5QAAAIU"]
[Thu Jul 30 15:13:47.322313 2026] [security2:error] [pid 133043:tid 133248] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwerdt6aqtVvMundOO5AAA0F4"]
[Thu Jul 30 15:13:47.470487 2026] [security2:error] [pid 133043:tid 133156] [remote 57.141.0.2:54978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuwe7dt6aqtVvMundOO_gAAlHA"]
[Thu Jul 30 15:13:47.524092 2026] [core:notice] [pid 133043:tid 133259] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:48.081572 2026] [security2:error] [pid 133043:tid 133228] [client 185.200.117.131:58842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuwfLdt6aqtVvMundOPDQAAALw"]
[Thu Jul 30 15:13:48.081691 2026] [security2:error] [pid 133043:tid 133228] [client 185.200.117.131:58842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuwfLdt6aqtVvMundOPDQAAALw"]
[Thu Jul 30 15:13:48.217587 2026] [security2:error] [pid 133043:tid 133226] [client 20.52.54.143:10900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuwfLdt6aqtVvMundOPDgAAALo"]
[Thu Jul 30 15:13:48.412925 2026] [security2:error] [pid 133043:tid 133235] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwe7dt6aqtVvMundOO-gAAw3w"]
[Thu Jul 30 15:13:48.708194 2026] [security2:error] [pid 133043:tid 133062] [remote 57.141.0.69:64060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5035568461/feed/rss2/"] [unique_id "amuwfLdt6aqtVvMundOPGgAAshI"]
[Thu Jul 30 15:13:48.977921 2026] [security2:error] [pid 133043:tid 133202] [client 20.52.54.143:10885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/assets/images/doc.php"] [unique_id "amuwfLdt6aqtVvMundOPIgAAAKI"]
[Thu Jul 30 15:13:49.016287 2026] [core:notice] [pid 133043:tid 133059] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:49.050807 2026] [security2:error] [pid 133043:tid 133270] [client 2a03:2880:f800:a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwfLdt6aqtVvMundOPFgAA5g4"]
[Thu Jul 30 15:13:49.083465 2026] [core:error] [pid 133043:tid 133056] [remote 66.249.77.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:13:49.083484 2026] [core:error] [pid 133043:tid 133056] [remote 66.249.77.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:13:49.103265 2026] [core:notice] [pid 133043:tid 133066] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:49.600136 2026] [core:notice] [pid 133043:tid 133070] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:49.604039 2026] [security2:error] [pid 133043:tid 133073] [remote 57.141.0.44:63736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuwfbdt6aqtVvMundOPKwAAhR0"]
[Thu Jul 30 15:13:50.508814 2026] [security2:error] [pid 133043:tid 133213] [client 172.237.109.114:49008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwfbdt6aqtVvMundOPOwAAAK0"]
[Thu Jul 30 15:13:50.630333 2026] [security2:error] [pid 133043:tid 133254] [client 172.237.109.114:9970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwfrdt6aqtVvMundOPQwAAANY"]
[Thu Jul 30 15:13:50.761394 2026] [security2:error] [pid 133043:tid 133089] [remote 57.141.0.67:51368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuwfrdt6aqtVvMundOPTgAA3S0"]
[Thu Jul 30 15:13:52.064250 2026] [security2:error] [pid 133043:tid 133293] [client 20.52.54.143:10892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/bgymj.php"] [unique_id "amuwgLdt6aqtVvMundOPawAAAP0"]
[Thu Jul 30 15:13:52.255574 2026] [security2:error] [pid 133043:tid 133080] [remote 74.7.243.224:40026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/partners/article.php"] [unique_id "amuwgLdt6aqtVvMundOPcAAA-yQ"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/img/uploads/partners/1784122808_wilde%20gazen.jpg
[Thu Jul 30 15:13:52.862436 2026] [security2:error] [pid 133043:tid 133180] [client 194.61.17.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwgLdt6aqtVvMundOPaQAAjDc"], referer: https://allmontecristi.com
[Thu Jul 30 15:13:53.467574 2026] [security2:error] [pid 133043:tid 133228] [client 43.173.179.164:54332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/12/15/cadeaux-noel-2014-pour-elle/"] [unique_id "amuwgbdt6aqtVvMundOPjgAAALw"]
[Thu Jul 30 15:13:53.566286 2026] [security2:error] [pid 133043:tid 133276] [client 172.237.109.114:26821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwgbdt6aqtVvMundOPhgAAAOw"]
[Thu Jul 30 15:13:53.710410 2026] [core:notice] [pid 133043:tid 133193] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:53.712316 2026] [core:notice] [pid 133043:tid 133086] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:53.716251 2026] [security2:error] [pid 133043:tid 133193] [client 43.173.181.37:37512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/12/15/cadeaux-noel-2014-pour-elle/"] [unique_id "amuwgbdt6aqtVvMundOPmgAAAJk"], referer: https://carnetdeshopping.com/index.php/2014/12/15/cadeaux-noel-2014-pour-elle/
[Thu Jul 30 15:13:54.063483 2026] [security2:error] [pid 133043:tid 133230] [client 20.52.54.143:11129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "amuwgrdt6aqtVvMundOPnwAAAL4"]
[Thu Jul 30 15:13:54.308547 2026] [security2:error] [pid 133043:tid 133178] [client 181.53.13.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwgrdt6aqtVvMundOPrAAAAIo"], referer: http://cnpinyin.com
[Thu Jul 30 15:13:54.521808 2026] [security2:error] [pid 133043:tid 133112] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwgrdt6aqtVvMundOPsgAAzkQ"]
[Thu Jul 30 15:13:54.521966 2026] [security2:error] [pid 133043:tid 133246] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwgrdt6aqtVvMundOPsgAAzkQ"]
[Thu Jul 30 15:13:55.261444 2026] [security2:error] [pid 133043:tid 133132] [remote 111.225.148.109:22786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/2024/09/02/al-seer-marine-unveils-new-dynamic-brand-identity-to-underline-its-position-as-a-global-pioneer-in-maritime-excellence/"] [unique_id "amuwg7dt6aqtVvMundOPxgAAkFg"]
[Thu Jul 30 15:13:55.898325 2026] [security2:error] [pid 133043:tid 133274] [client 187.132.201.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwg7dt6aqtVvMundOP0QAAAOo"], referer: https://cnpinyin.com
[Thu Jul 30 15:13:56.424604 2026] [security2:error] [pid 133043:tid 133286] [client 37.77.56.246:56294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.56.77.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuwhLdt6aqtVvMundOP5AAAAPY"]
[Thu Jul 30 15:13:56.424701 2026] [security2:error] [pid 133043:tid 133286] [client 37.77.56.246:56294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuwhLdt6aqtVvMundOP5AAAAPY"]
[Thu Jul 30 15:13:56.872040 2026] [security2:error] [pid 133043:tid 133209] [client 20.52.54.143:10681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-load.php"] [unique_id "amuwhLdt6aqtVvMundOP7gAAAKk"]
[Thu Jul 30 15:13:58.793084 2026] [security2:error] [pid 133043:tid 133275] [client 152.42.164.200:50876] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuwhrdt6aqtVvMundOQFQAAAOs"]
[Thu Jul 30 15:13:58.866612 2026] [security2:error] [pid 133043:tid 133236] [client 152.42.164.200:59222] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.58"] [uri "/"] [unique_id "amuwhrdt6aqtVvMundOQGQAAAMQ"]
[Thu Jul 30 15:13:59.272178 2026] [core:notice] [pid 133043:tid 133202] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:13:59.273075 2026] [security2:error] [pid 133043:tid 133257] [client 68.221.186.136:31948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/011i.php"] [unique_id "amuwh7dt6aqtVvMundOQIQAAANk"]
[Thu Jul 30 15:14:00.003058 2026] [security2:error] [pid 133043:tid 133217] [client 20.52.54.143:10672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/a.php"] [unique_id "amuwiLdt6aqtVvMundOQMwAAALE"]
[Thu Jul 30 15:14:00.548247 2026] [security2:error] [pid 133043:tid 133147] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwiLdt6aqtVvMundOQPgAA3Wc"]
[Thu Jul 30 15:14:00.548376 2026] [security2:error] [pid 133043:tid 133261] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwiLdt6aqtVvMundOQPgAA3Wc"]
[Thu Jul 30 15:14:00.606065 2026] [security2:error] [pid 133043:tid 133283] [client 68.221.186.136:31232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/03a005685d.php"] [unique_id "amuwiLdt6aqtVvMundOQPwAAAPM"]
[Thu Jul 30 15:14:00.933040 2026] [security2:error] [pid 133043:tid 133235] [client 20.52.54.143:10669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/u.php"] [unique_id "amuwiLdt6aqtVvMundOQRgAAAMM"]
[Thu Jul 30 15:14:01.149538 2026] [security2:error] [pid 133043:tid 133130] [remote 57.141.0.14:40276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuwibdt6aqtVvMundOQTAAA_FY"]
[Thu Jul 30 15:14:01.190209 2026] [security2:error] [pid 133043:tid 133199] [client 68.221.186.136:33725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/403.php"] [unique_id "amuwibdt6aqtVvMundOQTgAAAJ8"]
[Thu Jul 30 15:14:02.377703 2026] [security2:error] [pid 133043:tid 133240] [client 74.7.230.19:57104] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.sayaa.ai"] [uri "/cgi-sys/404.html"] [unique_id "amuwirdt6aqtVvMundOQcAAAyAM"]
[Thu Jul 30 15:14:02.413424 2026] [security2:error] [pid 133043:tid 133220] [client 36.236.224.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwirdt6aqtVvMundOQbAAAALQ"], referer: http://cnpinyin.com
[Thu Jul 30 15:14:02.512390 2026] [security2:error] [pid 133043:tid 133264] [client 39.34.139.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwirdt6aqtVvMundOQbwAAAOA"], referer: https://cnpinyin.com/mycertificates
[Thu Jul 30 15:14:02.571278 2026] [security2:error] [pid 133043:tid 133178] [client 172.237.109.114:59965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwirdt6aqtVvMundOQYgAAAIo"]
[Thu Jul 30 15:14:02.964362 2026] [security2:error] [pid 133043:tid 133186] [client 20.52.54.143:10662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/r.php"] [unique_id "amuwirdt6aqtVvMundOQfAAAAJI"]
[Thu Jul 30 15:14:03.831572 2026] [security2:error] [pid 133043:tid 133182] [client 68.221.186.136:33341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/404.php"] [unique_id "amuwi7dt6aqtVvMundOQmwAAAI4"]
[Thu Jul 30 15:14:04.591660 2026] [security2:error] [pid 133043:tid 133242] [client 68.221.186.136:35651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/aa.php"] [unique_id "amuwjLdt6aqtVvMundOQtQAAAMo"]
[Thu Jul 30 15:14:04.617247 2026] [security2:error] [pid 133043:tid 133296] [client 20.52.54.143:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-blog.php"] [unique_id "amuwjLdt6aqtVvMundOQuAAAAQA"]
[Thu Jul 30 15:14:05.867707 2026] [security2:error] [pid 133043:tid 133298] [client 68.221.186.136:33721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/aafewc0k.php"] [unique_id "amuwjbdt6aqtVvMundORIQAAAQI"]
[Thu Jul 30 15:14:05.927094 2026] [security2:error] [pid 133043:tid 133180] [client 20.52.54.143:10686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/xxx.php"] [unique_id "amuwjbdt6aqtVvMundORJwAAAIw"]
[Thu Jul 30 15:14:07.239273 2026] [security2:error] [pid 133043:tid 133062] [remote 193.200.221.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.221.200.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vietnambitcoin.app"] [uri "/wp-login.php"] [unique_id "amuwj7dt6aqtVvMundORZgAA3xI"]
[Thu Jul 30 15:14:07.481261 2026] [security2:error] [pid 133043:tid 133212] [client 68.221.186.136:33694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/abcd.php"] [unique_id "amuwj7dt6aqtVvMundORcAAAAKw"]
[Thu Jul 30 15:14:07.702583 2026] [security2:error] [pid 133043:tid 133175] [client 38.137.176.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwjrdt6aqtVvMundORXgAAhw0"], referer: https://allmontecristi.com
[Thu Jul 30 15:14:08.275504 2026] [security2:error] [pid 133043:tid 133048] [remote 57.141.0.31:32108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amuwkLdt6aqtVvMundORgAAA0gQ"]
[Thu Jul 30 15:14:08.420016 2026] [security2:error] [pid 133043:tid 133227] [client 68.221.186.136:31949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/about.php"] [unique_id "amuwkLdt6aqtVvMundORhwAAALs"]
[Thu Jul 30 15:14:08.480485 2026] [security2:error] [pid 133043:tid 133300] [client 172.237.109.114:30821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwj7dt6aqtVvMundORewAAAQQ"]
[Thu Jul 30 15:14:08.760496 2026] [security2:error] [pid 133043:tid 133236] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwkLdt6aqtVvMundORfAAAxBY"]
[Thu Jul 30 15:14:08.964325 2026] [security2:error] [pid 133043:tid 133205] [client 66.249.66.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.baytalhuboob.com"] [uri "/index.php"] [unique_id "amuwkLdt6aqtVvMundORjAAAAKU"]
[Thu Jul 30 15:14:10.000314 2026] [security2:error] [pid 133043:tid 133274] [client 68.221.186.136:33300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/admin.php"] [unique_id "amuwkbdt6aqtVvMundORrwAAAOo"]
[Thu Jul 30 15:14:10.845317 2026] [security2:error] [pid 133043:tid 133087] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwkrdt6aqtVvMundORvAAA_Ss"]
[Thu Jul 30 15:14:10.845509 2026] [security2:error] [pid 133043:tid 133293] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwkrdt6aqtVvMundORvAAA_Ss"]
[Thu Jul 30 15:14:11.101841 2026] [core:notice] [pid 133043:tid 133190] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:11.645961 2026] [security2:error] [pid 133043:tid 133260] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwk7dt6aqtVvMundORxwAAANw"]
[Thu Jul 30 15:14:12.011636 2026] [security2:error] [pid 133043:tid 133191] [client 20.52.54.143:10654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/tool.php"] [unique_id "amuwlLdt6aqtVvMundOR2gAAAJc"]
[Thu Jul 30 15:14:12.749237 2026] [security2:error] [pid 133043:tid 133276] [client 95.136.65.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwlLdt6aqtVvMundOR6gAAAOw"], referer: http://cnpinyin.com
[Thu Jul 30 15:14:12.805195 2026] [security2:error] [pid 133043:tid 133221] [client 20.52.54.143:10685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-content.php"] [unique_id "amuwlLdt6aqtVvMundOR7wAAALU"]
[Thu Jul 30 15:14:13.248616 2026] [security2:error] [pid 133043:tid 133205] [client 172.237.109.114:46912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwlLdt6aqtVvMundOR7gAAAKU"]
[Thu Jul 30 15:14:13.465067 2026] [security2:error] [pid 133043:tid 133230] [client 20.52.54.143:10441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/k.php"] [unique_id "amuwlbdt6aqtVvMundOR-wAAAL4"]
[Thu Jul 30 15:14:14.615227 2026] [security2:error] [pid 133043:tid 133252] [client 172.237.109.114:6359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwlrdt6aqtVvMundOSDgAAANQ"]
[Thu Jul 30 15:14:14.714307 2026] [security2:error] [pid 133043:tid 133237] [client 20.52.54.143:10453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/root.php"] [unique_id "amuwlrdt6aqtVvMundOSHAAAAMU"]
[Thu Jul 30 15:14:15.350181 2026] [security2:error] [pid 133043:tid 133245] [client 20.52.54.143:10488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/ws.php"] [unique_id "amuwl7dt6aqtVvMundOSLwAAAM0"]
[Thu Jul 30 15:14:15.625929 2026] [security2:error] [pid 133043:tid 133114] [remote 103.200.22.140:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.22.200.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kbtfinancezambia.com"] [uri "/wp-login.php"] [unique_id "amuwl7dt6aqtVvMundOSMAAA4kY"]
[Thu Jul 30 15:14:16.176560 2026] [security2:error] [pid 133043:tid 133293] [client 43.156.228.27:43216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.228.156.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuwl7dt6aqtVvMundOSPAAAAP0"]
[Thu Jul 30 15:14:16.253767 2026] [core:notice] [pid 133043:tid 133176] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:16.867570 2026] [security2:error] [pid 133043:tid 133219] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwmLdt6aqtVvMundOSSQAAALM"]
[Thu Jul 30 15:14:17.529889 2026] [security2:error] [pid 133043:tid 133214] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwmLdt6aqtVvMundOSVQAAAK4"]
[Thu Jul 30 15:14:17.630430 2026] [security2:error] [pid 133043:tid 133107] [remote 57.141.0.64:48180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuwmbdt6aqtVvMundOSawAArz8"]
[Thu Jul 30 15:14:17.890507 2026] [security2:error] [pid 133043:tid 133224] [client 68.221.186.136:24048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/adminfuns.php"] [unique_id "amuwmbdt6aqtVvMundOScgAAALg"]
[Thu Jul 30 15:14:18.667754 2026] [security2:error] [pid 133043:tid 133158] [remote 57.141.0.63:22100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/610298834/feed/rss2/"] [unique_id "amuwmrdt6aqtVvMundOSfwAA_3I"]
[Thu Jul 30 15:14:18.832860 2026] [security2:error] [pid 133043:tid 133187] [client 20.52.54.143:10482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/p.php"] [unique_id "amuwmrdt6aqtVvMundOSgwAAAJM"]
[Thu Jul 30 15:14:19.401489 2026] [core:error] [pid 133043:tid 133291] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:14:19.401519 2026] [core:error] [pid 133043:tid 133291] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:14:19.449153 2026] [security2:error] [pid 133043:tid 133264] [client 20.52.54.143:10465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/elp.php"] [unique_id "amuwm7dt6aqtVvMundOSkgAAAOA"]
[Thu Jul 30 15:14:19.798959 2026] [security2:error] [pid 133043:tid 133178] [client 68.221.186.136:31629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/albin.php"] [unique_id "amuwm7dt6aqtVvMundOSmQAAAIo"]
[Thu Jul 30 15:14:20.411077 2026] [security2:error] [pid 133043:tid 133181] [client 5.254.250.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwnLdt6aqtVvMundOSpQAAAI0"], referer: http://cnpinyin.com
[Thu Jul 30 15:14:21.511198 2026] [security2:error] [pid 133043:tid 133156] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwnbdt6aqtVvMundOSwQAAoXA"]
[Thu Jul 30 15:14:21.511356 2026] [security2:error] [pid 133043:tid 133201] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwnbdt6aqtVvMundOSwQAAoXA"]
[Thu Jul 30 15:14:21.674843 2026] [security2:error] [pid 133043:tid 133175] [client 20.52.54.143:10641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/a1.php"] [unique_id "amuwnbdt6aqtVvMundOSyAAAAIc"]
[Thu Jul 30 15:14:22.219535 2026] [core:notice] [pid 133043:tid 133062] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:22.260623 2026] [security2:error] [pid 133043:tid 133286] [client 68.221.186.136:37583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/amfsqvgv.php"] [unique_id "amuwnrdt6aqtVvMundOS2wAAAPY"]
[Thu Jul 30 15:14:22.298334 2026] [security2:error] [pid 133043:tid 133227] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwnbdt6aqtVvMundOSywAAALs"]
[Thu Jul 30 15:14:23.683497 2026] [security2:error] [pid 133043:tid 133197] [client 20.52.54.143:10489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-includes/Text/index.php"] [unique_id "amuwn7dt6aqtVvMundOS_QAAAJ0"]
[Thu Jul 30 15:14:23.983327 2026] [security2:error] [pid 133043:tid 133275] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwn7dt6aqtVvMundOS9gAAAOs"]
[Thu Jul 30 15:14:24.186253 2026] [core:notice] [pid 133043:tid 133272] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:24.735150 2026] [security2:error] [pid 133043:tid 133293] [client 140.213.118.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwoLdt6aqtVvMundOTBgAA_R0"], referer: https://allmontecristi.com
[Thu Jul 30 15:14:25.276087 2026] [security2:error] [pid 133043:tid 133279] [client 68.221.186.136:31291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/ant.php"] [unique_id "amuwobdt6aqtVvMundOTKAAAAO8"]
[Thu Jul 30 15:14:25.648294 2026] [security2:error] [pid 133043:tid 133235] [client 161.35.91.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.embassyinislamabadad.com"] [uri "/index.php"] [unique_id "amuwobdt6aqtVvMundOTLQAAAMM"], referer: http://mail.embassyinislamabadad.com/
[Thu Jul 30 15:14:26.125910 2026] [security2:error] [pid 133043:tid 133228] [client 68.221.186.136:31621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/appreciators.php"] [unique_id "amuwordt6aqtVvMundOTPwAAALw"]
[Thu Jul 30 15:14:26.226249 2026] [security2:error] [pid 133043:tid 133221] [client 102.0.16.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwordt6aqtVvMundOTPQAAALU"], referer: http://cnpinyin.com
[Thu Jul 30 15:14:27.056750 2026] [security2:error] [pid 133043:tid 133203] [client 20.226.5.174:37582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/leaf_mailer.php"] [unique_id "amuwo7dt6aqtVvMundOTVwAAAKM"]
[Thu Jul 30 15:14:27.240339 2026] [security2:error] [pid 133043:tid 133190] [client 68.221.186.136:31254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/archive.php"] [unique_id "amuwo7dt6aqtVvMundOTXAAAAJY"]
[Thu Jul 30 15:14:27.242408 2026] [core:notice] [pid 133043:tid 133074] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:27.416491 2026] [security2:error] [pid 133043:tid 133213] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuwo7dt6aqtVvMundOTYAAAAK0"]
[Thu Jul 30 15:14:27.603476 2026] [security2:error] [pid 133043:tid 133241] [client 20.52.54.143:11009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/alfa-rex.php7"] [unique_id "amuwo7dt6aqtVvMundOTbAAAAMk"]
[Thu Jul 30 15:14:27.852870 2026] [core:notice] [pid 133043:tid 133096] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:27.956572 2026] [security2:error] [pid 133043:tid 133233] [client 20.226.5.174:37578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/leaf_php.php"] [unique_id "amuwo7dt6aqtVvMundOTdwAAAME"]
[Thu Jul 30 15:14:28.192023 2026] [security2:error] [pid 133043:tid 133235] [client 68.221.186.136:39631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/as.php"] [unique_id "amuwpLdt6aqtVvMundOTeQAAAMM"]
[Thu Jul 30 15:14:28.337543 2026] [security2:error] [pid 133043:tid 133295] [client 20.52.54.143:11011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-admin/css/admin.php"] [unique_id "amuwpLdt6aqtVvMundOThwAAAP8"]
[Thu Jul 30 15:14:28.867116 2026] [security2:error] [pid 133043:tid 133253] [client 20.226.5.174:37583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/leafmailer.php"] [unique_id "amuwpLdt6aqtVvMundOTkQAAANU"]
[Thu Jul 30 15:14:28.986516 2026] [core:notice] [pid 133043:tid 133105] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:28.997426 2026] [security2:error] [pid 133043:tid 133264] [client 82.102.27.163:51140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuwpLdt6aqtVvMundOTmQAAAOA"]
[Thu Jul 30 15:14:28.997512 2026] [security2:error] [pid 133043:tid 133264] [client 82.102.27.163:51140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amuwpLdt6aqtVvMundOTmQAAAOA"]
[Thu Jul 30 15:14:29.002656 2026] [security2:error] [pid 133043:tid 133256] [client 20.52.54.143:11051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/install.php"] [unique_id "amuwpbdt6aqtVvMundOTmgAAANg"]
[Thu Jul 30 15:14:29.167477 2026] [core:notice] [pid 133043:tid 133299] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:29.289298 2026] [security2:error] [pid 133043:tid 133192] [client 82.102.18.188:57728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "safaratraveltours.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuwpbdt6aqtVvMundOTsAAAAJg"]
[Thu Jul 30 15:14:29.566611 2026] [security2:error] [pid 133043:tid 133241] [client 161.35.91.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.embassyinislamabadad.com"] [uri "/index.php"] [unique_id "amuwpbdt6aqtVvMundOTuAAAAMk"], referer: https://mail.embassyinislamabadad.com/
[Thu Jul 30 15:14:29.660047 2026] [security2:error] [pid 133043:tid 133227] [client 68.221.186.136:33291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/atomlib.php"] [unique_id "amuwpbdt6aqtVvMundOTwwAAALs"]
[Thu Jul 30 15:14:29.723775 2026] [security2:error] [pid 133043:tid 133153] [remote 57.141.0.8:27502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuwpbdt6aqtVvMundOTzQAA520"]
[Thu Jul 30 15:14:29.807470 2026] [security2:error] [pid 133043:tid 133209] [client 20.226.5.174:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/leafmailer.php.php"] [unique_id "amuwpbdt6aqtVvMundOT4wAAAKk"]
[Thu Jul 30 15:14:29.828578 2026] [security2:error] [pid 133043:tid 133191] [client 82.102.18.188:57738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuwpbdt6aqtVvMundOT5gAAAJc"]
[Thu Jul 30 15:14:30.447151 2026] [security2:error] [pid 133043:tid 133224] [client 68.221.186.136:23405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/autoload_classmap.php"] [unique_id "amuwprdt6aqtVvMundOT8AAAALg"]
[Thu Jul 30 15:14:30.708829 2026] [security2:error] [pid 133043:tid 133195] [client 20.226.5.174:37575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/leafmailer2.8.php"] [unique_id "amuwprdt6aqtVvMundOT9AAAAJs"]
[Thu Jul 30 15:14:30.805333 2026] [core:notice] [pid 133043:tid 133176] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:31.083030 2026] [core:error] [pid 133043:tid 133260] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:14:31.083056 2026] [core:error] [pid 133043:tid 133260] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:14:31.210837 2026] [security2:error] [pid 133043:tid 133170] [remote 57.141.0.40:38874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/login/lostPassword"] [unique_id "amuwp7dt6aqtVvMundOUAAAA-34"]
[Thu Jul 30 15:14:31.339510 2026] [core:notice] [pid 133043:tid 133246] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:31.644172 2026] [security2:error] [pid 133043:tid 133269] [client 20.226.5.174:37572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/led.php"] [unique_id "amuwp7dt6aqtVvMundOUEgAAAOU"]
[Thu Jul 30 15:14:31.677256 2026] [security2:error] [pid 133043:tid 133268] [client 68.221.186.136:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/bb.php"] [unique_id "amuwp7dt6aqtVvMundOUEwAAAOQ"]
[Thu Jul 30 15:14:32.026580 2026] [security2:error] [pid 133043:tid 133223] [client 20.52.54.143:11064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-includes/fonts/index.php"] [unique_id "amuwqLdt6aqtVvMundOUIQAAALc"]
[Thu Jul 30 15:14:32.040378 2026] [security2:error] [pid 133043:tid 133191] [client 82.102.18.188:57750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuwqLdt6aqtVvMundOUIwAAAJc"]
[Thu Jul 30 15:14:32.040472 2026] [security2:error] [pid 133043:tid 133191] [client 82.102.18.188:57750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuwqLdt6aqtVvMundOUIwAAAJc"]
[Thu Jul 30 15:14:32.170451 2026] [security2:error] [pid 133043:tid 133046] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwqLdt6aqtVvMundOUJAABAQI"]
[Thu Jul 30 15:14:32.170627 2026] [security2:error] [pid 133043:tid 133297] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwqLdt6aqtVvMundOUJAABAQI"]
[Thu Jul 30 15:14:32.542277 2026] [security2:error] [pid 133043:tid 133280] [client 20.226.5.174:37585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/legal.php"] [unique_id "amuwqLdt6aqtVvMundOULAAAAPA"]
[Thu Jul 30 15:14:32.578371 2026] [security2:error] [pid 133043:tid 133221] [client 82.102.18.188:57762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuwqLdt6aqtVvMundOUMAAAALU"]
[Thu Jul 30 15:14:32.578485 2026] [security2:error] [pid 133043:tid 133221] [client 82.102.18.188:57762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuwqLdt6aqtVvMundOUMAAAALU"]
[Thu Jul 30 15:14:32.806365 2026] [core:notice] [pid 133043:tid 133193] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:32.810821 2026] [security2:error] [pid 133043:tid 133193] [client 66.249.79.231:48874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/download/9146/3966"] [unique_id "amuwqLdt6aqtVvMundOULQAAAJk"]
[Thu Jul 30 15:14:33.044900 2026] [security2:error] [pid 133043:tid 133281] [client 68.221.186.136:37615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/bnm.php"] [unique_id "amuwqbdt6aqtVvMundOUQAAAAPE"]
[Thu Jul 30 15:14:33.478458 2026] [security2:error] [pid 133043:tid 133225] [client 20.226.5.174:37581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/legion.php"] [unique_id "amuwqbdt6aqtVvMundOUSQAAALk"]
[Thu Jul 30 15:14:33.565799 2026] [security2:error] [pid 133043:tid 133205] [client 172.237.109.114:55894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwqLdt6aqtVvMundOUPgAAAKU"]
[Thu Jul 30 15:14:33.631508 2026] [security2:error] [pid 133043:tid 133291] [client 20.52.54.143:10447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/upload.php"] [unique_id "amuwqbdt6aqtVvMundOUTgAAAPs"]
[Thu Jul 30 15:14:33.747642 2026] [security2:error] [pid 133043:tid 133256] [client 68.221.186.136:35613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/bootstrap.php"] [unique_id "amuwqbdt6aqtVvMundOUUAAAANg"]
[Thu Jul 30 15:14:34.380231 2026] [security2:error] [pid 133043:tid 133290] [client 20.226.5.174:37577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/let.php"] [unique_id "amuwqrdt6aqtVvMundOUYQAAAPo"]
[Thu Jul 30 15:14:34.668184 2026] [security2:error] [pid 133043:tid 133227] [client 68.221.186.136:24090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/buy.php"] [unique_id "amuwqrdt6aqtVvMundOUbwAAALs"]
[Thu Jul 30 15:14:34.748372 2026] [security2:error] [pid 133043:tid 133064] [remote 110.249.201.249:13462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/ar/2025/08/22/ai-transformation-strategy-with-deployment-of-ai-observer-nova/"] [unique_id "amuwqrdt6aqtVvMundOUcAAAqxQ"]
[Thu Jul 30 15:14:35.299292 2026] [security2:error] [pid 133043:tid 133201] [client 20.226.5.174:37586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/lf.php"] [unique_id "amuwq7dt6aqtVvMundOUfgAAAKE"]
[Thu Jul 30 15:14:35.479235 2026] [security2:error] [pid 133043:tid 133198] [client 68.221.186.136:33324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/chosen.php"] [unique_id "amuwq7dt6aqtVvMundOUgQAAAJ4"]
[Thu Jul 30 15:14:35.856281 2026] [security2:error] [pid 133043:tid 133098] [remote 57.141.0.54:40266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap2.xml"] [unique_id "amuwq7dt6aqtVvMundOUkgAA_TY"]
[Thu Jul 30 15:14:36.217209 2026] [security2:error] [pid 133043:tid 133184] [client 20.226.5.174:37570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/library.php"] [unique_id "amuwrLdt6aqtVvMundOUoAAAAJA"]
[Thu Jul 30 15:14:36.342389 2026] [security2:error] [pid 133043:tid 133263] [client 68.221.186.136:24081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/class-wp-image.php"] [unique_id "amuwrLdt6aqtVvMundOUpgAAAN8"]
[Thu Jul 30 15:14:36.483549 2026] [security2:error] [pid 133043:tid 133258] [client 2a03:2880:f800:1d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwq7dt6aqtVvMundOUkwAA2jk"]
[Thu Jul 30 15:14:36.687155 2026] [security2:error] [pid 133043:tid 133227] [client 37.77.56.246:44678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.56.77.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuwrLdt6aqtVvMundOUrgAAALs"]
[Thu Jul 30 15:14:36.687268 2026] [security2:error] [pid 133043:tid 133227] [client 37.77.56.246:44678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuwrLdt6aqtVvMundOUrgAAALs"]
[Thu Jul 30 15:14:37.111553 2026] [security2:error] [pid 133043:tid 133216] [client 20.226.5.174:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/library/about.php"] [unique_id "amuwrbdt6aqtVvMundOUtQAAALA"]
[Thu Jul 30 15:14:37.133007 2026] [security2:error] [pid 133043:tid 133193] [client 20.52.54.143:11065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-content/file.php"] [unique_id "amuwrbdt6aqtVvMundOUtgAAAJk"]
[Thu Jul 30 15:14:37.709088 2026] [security2:error] [pid 133043:tid 133234] [client 20.52.54.143:11049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/files.php"] [unique_id "amuwrbdt6aqtVvMundOUxgAAAMI"]
[Thu Jul 30 15:14:38.315318 2026] [security2:error] [pid 133043:tid 133243] [client 20.226.5.174:37571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/library/index.php"] [unique_id "amuwrrdt6aqtVvMundOU1AAAAMs"]
[Thu Jul 30 15:14:38.562900 2026] [security2:error] [pid 133043:tid 133266] [client 20.52.54.143:11010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/o.php"] [unique_id "amuwrrdt6aqtVvMundOU2wAAAOI"]
[Thu Jul 30 15:14:38.651971 2026] [core:error] [pid 133043:tid 133209] [client 23.94.133.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:14:38.652012 2026] [core:error] [pid 133043:tid 133209] [client 23.94.133.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:14:39.255155 2026] [security2:error] [pid 133043:tid 133181] [client 20.226.5.174:37579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/libs.php"] [unique_id "amuwr7dt6aqtVvMundOU8AAAAI0"]
[Thu Jul 30 15:14:39.713644 2026] [security2:error] [pid 133043:tid 133297] [client 20.52.54.143:10449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/file2.php"] [unique_id "amuwr7dt6aqtVvMundOU-AAAAQE"]
[Thu Jul 30 15:14:40.148175 2026] [core:notice] [pid 133043:tid 133153] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:40.190763 2026] [security2:error] [pid 133043:tid 133203] [client 20.226.5.174:37569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/license.php"] [unique_id "amuwsLdt6aqtVvMundOVBwAAAKM"]
[Thu Jul 30 15:14:40.667068 2026] [security2:error] [pid 133043:tid 133286] [client 68.221.186.136:36041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/classsmtps.php"] [unique_id "amuwsLdt6aqtVvMundOVFAAAAPY"]
[Thu Jul 30 15:14:40.727579 2026] [core:notice] [pid 133043:tid 133142] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:41.127995 2026] [security2:error] [pid 133043:tid 133259] [client 20.226.5.174:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/license.txt/xmlrpc.php"] [unique_id "amuwsbdt6aqtVvMundOVIQAAANs"]
[Thu Jul 30 15:14:41.270857 2026] [security2:error] [pid 133043:tid 133260] [client 20.52.54.143:11048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuwsbdt6aqtVvMundOVIgAAANw"]
[Thu Jul 30 15:14:41.498837 2026] [security2:error] [pid 133043:tid 133274] [client 172.237.109.114:61476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwsLdt6aqtVvMundOVHwAAAOo"]
[Thu Jul 30 15:14:42.022527 2026] [security2:error] [pid 133043:tid 133214] [client 20.226.5.174:37574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/licenses.php"] [unique_id "amuwsrdt6aqtVvMundOVOgAAAK4"]
[Thu Jul 30 15:14:42.243956 2026] [security2:error] [pid 133043:tid 133215] [client 20.52.54.143:10494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/xda.php"] [unique_id "amuwsrdt6aqtVvMundOVPQAAAK8"]
[Thu Jul 30 15:14:42.583440 2026] [security2:error] [pid 133043:tid 133240] [client 172.237.109.114:44421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwsrdt6aqtVvMundOVPAAAAMg"]
[Thu Jul 30 15:14:42.875076 2026] [security2:error] [pid 133043:tid 133049] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwsrdt6aqtVvMundOVSwAArAU"]
[Thu Jul 30 15:14:42.875253 2026] [security2:error] [pid 133043:tid 133212] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwsrdt6aqtVvMundOVSwAArAU"]
[Thu Jul 30 15:14:42.918061 2026] [security2:error] [pid 133043:tid 133279] [client 20.226.5.174:37594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/lightspped.php"] [unique_id "amuwsrdt6aqtVvMundOVTAAAAO8"]
[Thu Jul 30 15:14:43.496163 2026] [security2:error] [pid 133043:tid 133256] [client 20.52.54.143:11066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/theme.php"] [unique_id "amuws7dt6aqtVvMundOVXwAAANg"]
[Thu Jul 30 15:14:43.840369 2026] [security2:error] [pid 133043:tid 133260] [client 20.226.5.174:37591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/link.php"] [unique_id "amuws7dt6aqtVvMundOVZwAAANw"]
[Thu Jul 30 15:14:43.945203 2026] [security2:error] [pid 133043:tid 133276] [client 74.7.244.63:58126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.bwu.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuws7dt6aqtVvMundOVaQAA7HM"]
[Thu Jul 30 15:14:44.187006 2026] [security2:error] [pid 133043:tid 133238] [client 74.7.244.63:58126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bwu.gzj.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "amuwtLdt6aqtVvMundOVdAAAxg8"], referer: https://www.bwu.gzj.temporary.site/robots.txt
[Thu Jul 30 15:14:44.404681 2026] [security2:error] [pid 133043:tid 133289] [client 50.6.43.217:38496] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuwtLdt6aqtVvMundOVdQAAAPk"]
[Thu Jul 30 15:14:44.437447 2026] [security2:error] [pid 133043:tid 133251] [client 50.6.43.217:38500] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuwtLdt6aqtVvMundOVdgAAANM"]
[Thu Jul 30 15:14:44.736650 2026] [security2:error] [pid 133043:tid 133248] [client 20.226.5.174:37593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreview/404.php"] [unique_id "amuwtLdt6aqtVvMundOVhwAAANA"]
[Thu Jul 30 15:14:44.825619 2026] [security2:error] [pid 133043:tid 133272] [client 68.221.186.136:39645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/classwithtostring.php"] [unique_id "amuwtLdt6aqtVvMundOViAAAAOg"]
[Thu Jul 30 15:14:45.216583 2026] [security2:error] [pid 133043:tid 133182] [client 20.52.54.143:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/classwithtostring.php"] [unique_id "amuwtbdt6aqtVvMundOVlQAAAI4"]
[Thu Jul 30 15:14:45.405085 2026] [security2:error] [pid 133043:tid 133204] [client 68.221.186.136:23417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/config.php"] [unique_id "amuwtbdt6aqtVvMundOVlwAAAKQ"]
[Thu Jul 30 15:14:45.483100 2026] [security2:error] [pid 133043:tid 133266] [client 50.6.43.217:38516] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuwtbdt6aqtVvMundOVmAAAAOI"]
[Thu Jul 30 15:14:45.709309 2026] [security2:error] [pid 133043:tid 133241] [client 20.226.5.174:37611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreview/admin.php"] [unique_id "amuwtbdt6aqtVvMundOVogAAAMk"]
[Thu Jul 30 15:14:46.091431 2026] [security2:error] [pid 133043:tid 133292] [client 68.221.186.136:35598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/core.php"] [unique_id "amuwtrdt6aqtVvMundOVrQAAAPw"]
[Thu Jul 30 15:14:46.415960 2026] [security2:error] [pid 133043:tid 133183] [client 20.52.54.143:11027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/news.php"] [unique_id "amuwtrdt6aqtVvMundOVtAAAAI8"]
[Thu Jul 30 15:14:46.655065 2026] [security2:error] [pid 133043:tid 133181] [client 172.237.109.114:28072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwtrdt6aqtVvMundOVsQAAAI0"]
[Thu Jul 30 15:14:46.666616 2026] [security2:error] [pid 133043:tid 133216] [client 20.226.5.174:37597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreview/alfa.php"] [unique_id "amuwtrdt6aqtVvMundOVvQAAALA"]
[Thu Jul 30 15:14:46.812064 2026] [security2:error] [pid 133043:tid 133195] [client 68.221.186.136:23360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/css.php"] [unique_id "amuwtrdt6aqtVvMundOVwgAAAJs"]
[Thu Jul 30 15:14:47.076797 2026] [core:notice] [pid 133043:tid 133278] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:47.081112 2026] [security2:error] [pid 133043:tid 133278] [client 66.249.79.1:48617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/download/1097/708"] [unique_id "amuwtrdt6aqtVvMundOVwwAAAO4"]
[Thu Jul 30 15:14:47.307798 2026] [security2:error] [pid 133043:tid 133207] [client 20.52.54.143:11008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/about/function.php"] [unique_id "amuwt7dt6aqtVvMundOV1AAAAKc"]
[Thu Jul 30 15:14:47.643954 2026] [security2:error] [pid 133043:tid 133293] [client 20.226.5.174:37595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreview/bypass.php"] [unique_id "amuwt7dt6aqtVvMundOV2gAAAP0"]
[Thu Jul 30 15:14:47.740319 2026] [security2:error] [pid 133043:tid 133249] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwt7dt6aqtVvMundOVywAAANE"]
[Thu Jul 30 15:14:48.552368 2026] [security2:error] [pid 133043:tid 133226] [client 20.226.5.174:37584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreview/class.php"] [unique_id "amuwuLdt6aqtVvMundOV9AAAALo"]
[Thu Jul 30 15:14:48.663701 2026] [core:notice] [pid 133043:tid 133239] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:48.667166 2026] [security2:error] [pid 133043:tid 133239] [client 66.249.65.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/84/87"] [unique_id "amuwuLdt6aqtVvMundOV8AAAAMc"]
[Thu Jul 30 15:14:48.793451 2026] [security2:error] [pid 133043:tid 133085] [remote 217.182.128.41:42524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuwuLdt6aqtVvMundOV_AAAqyk"]
[Thu Jul 30 15:14:49.099674 2026] [security2:error] [pid 133043:tid 133219] [client 176.97.79.119:55735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.79.97.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuwubdt6aqtVvMundOWAgAAALM"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 15:14:49.168961 2026] [security2:error] [pid 133043:tid 133186] [client 68.221.186.136:24086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/database.php"] [unique_id "amuwubdt6aqtVvMundOWAwAAAJI"]
[Thu Jul 30 15:14:49.490468 2026] [security2:error] [pid 133043:tid 133214] [client 20.226.5.174:37596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreview/db.php"] [unique_id "amuwubdt6aqtVvMundOWDQAAAK4"]
[Thu Jul 30 15:14:49.609834 2026] [security2:error] [pid 133043:tid 133296] [client 176.97.79.119:55760] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuwubdt6aqtVvMundOWEQAAAQA"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 15:14:50.057625 2026] [security2:error] [pid 133043:tid 133298] [client 68.221.186.136:33307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/db.php"] [unique_id "amuwurdt6aqtVvMundOWGwAAAQI"]
[Thu Jul 30 15:14:50.396635 2026] [security2:error] [pid 133043:tid 133290] [client 20.226.5.174:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreview/index.php"] [unique_id "amuwurdt6aqtVvMundOWIwAAAPo"]
[Thu Jul 30 15:14:50.725310 2026] [security2:error] [pid 133043:tid 133241] [client 68.221.186.136:33283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/default.php"] [unique_id "amuwurdt6aqtVvMundOWJwAAAMk"]
[Thu Jul 30 15:14:51.083623 2026] [security2:error] [pid 133043:tid 133108] [remote 212.80.9.235:40784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-login.php"] [unique_id "amuwu7dt6aqtVvMundOWMQAAvUA"]
[Thu Jul 30 15:14:51.223665 2026] [security2:error] [pid 133043:tid 133283] [client 176.97.79.119:55844] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuwu7dt6aqtVvMundOWMgAAAPM"], referer: https://shorewooddaycare.com/contact.php?status=tour-invalid#tour-form
[Thu Jul 30 15:14:51.303158 2026] [security2:error] [pid 133043:tid 133247] [client 20.226.5.174:37606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreview/k.php"] [unique_id "amuwu7dt6aqtVvMundOWNAAAAM8"]
[Thu Jul 30 15:14:51.530182 2026] [core:notice] [pid 133043:tid 133183] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:51.534280 2026] [security2:error] [pid 133043:tid 133183] [client 66.249.79.230:46095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/download/9593/4294"] [unique_id "amuwu7dt6aqtVvMundOWMwAAAI8"]
[Thu Jul 30 15:14:51.924537 2026] [security2:error] [pid 133043:tid 133193] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwu7dt6aqtVvMundOWNQAAmVg"]
[Thu Jul 30 15:14:52.125495 2026] [security2:error] [pid 133043:tid 133278] [client 20.52.54.143:11045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-includes/admin.php"] [unique_id "amuwvLdt6aqtVvMundOWSQAAAO4"]
[Thu Jul 30 15:14:52.126961 2026] [security2:error] [pid 133043:tid 133238] [client 57.141.0.8:34072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siatfc.com"] [uri "/index.php"] [unique_id "amuwu7dt6aqtVvMundOWPwAAxkg"]
[Thu Jul 30 15:14:52.202230 2026] [security2:error] [pid 133043:tid 133176] [client 20.226.5.174:37598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreview/wp.php"] [unique_id "amuwvLdt6aqtVvMundOWSgAAAIg"]
[Thu Jul 30 15:14:52.385030 2026] [security2:error] [pid 133043:tid 133257] [client 68.221.186.136:24091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/dropdown.php"] [unique_id "amuwvLdt6aqtVvMundOWTgAAANk"]
[Thu Jul 30 15:14:53.096353 2026] [security2:error] [pid 133043:tid 133298] [client 20.226.5.174:37617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreviewadmin.php"] [unique_id "amuwvbdt6aqtVvMundOWZAAAAQI"]
[Thu Jul 30 15:14:53.246679 2026] [security2:error] [pid 133043:tid 133121] [remote 74.7.243.224:43654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/teamf.php"] [unique_id "amuwvbdt6aqtVvMundOWZgAAkE0"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/article.php?id=27
[Thu Jul 30 15:14:53.319855 2026] [security2:error] [pid 133043:tid 133296] [client 68.221.186.136:23227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/edit.php"] [unique_id "amuwvbdt6aqtVvMundOWZwAAAQA"]
[Thu Jul 30 15:14:53.499767 2026] [core:notice] [pid 133043:tid 133241] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:53.564968 2026] [security2:error] [pid 133043:tid 133133] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwvbdt6aqtVvMundOWbgAAvVk"]
[Thu Jul 30 15:14:53.565139 2026] [security2:error] [pid 133043:tid 133229] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwvbdt6aqtVvMundOWbgAAvVk"]
[Thu Jul 30 15:14:53.729968 2026] [security2:error] [pid 133043:tid 133277] [client 20.52.54.143:11012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/lock360.php"] [unique_id "amuwvbdt6aqtVvMundOWcgAAAO0"]
[Thu Jul 30 15:14:54.014897 2026] [security2:error] [pid 133043:tid 133235] [client 20.226.5.174:37607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreviewalfa.php"] [unique_id "amuwvrdt6aqtVvMundOWdwAAAMM"]
[Thu Jul 30 15:14:54.061387 2026] [security2:error] [pid 133043:tid 133206] [client 68.221.186.136:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/f35.php"] [unique_id "amuwvrdt6aqtVvMundOWfgAAAKY"]
[Thu Jul 30 15:14:54.476945 2026] [core:notice] [pid 133043:tid 133253] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:54.538936 2026] [security2:error] [pid 133043:tid 133276] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuwvbdt6aqtVvMundOWdQAA7F0"]
[Thu Jul 30 15:14:54.930230 2026] [security2:error] [pid 133043:tid 133249] [client 68.221.186.136:30576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/f7.php"] [unique_id "amuwvrdt6aqtVvMundOWkgAAANE"]
[Thu Jul 30 15:14:54.939229 2026] [security2:error] [pid 133043:tid 133268] [client 20.226.5.174:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreviewbypass.php"] [unique_id "amuwvrdt6aqtVvMundOWkwAAAOQ"]
[Thu Jul 30 15:14:55.168091 2026] [security2:error] [pid 133043:tid 133279] [client 57.141.0.25:35812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "siatfc.com"] [uri "/index.php"] [unique_id "amuwvrdt6aqtVvMundOWlQAA71s"]
[Thu Jul 30 15:14:55.288493 2026] [security2:error] [pid 133043:tid 133204] [client 57.141.0.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwvrdt6aqtVvMundOWkQAAAKQ"]
[Thu Jul 30 15:14:55.386069 2026] [security2:error] [pid 133043:tid 133245] [client 43.173.177.150:46942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.177.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/04/03/nouveau-site-de-minelli/"] [unique_id "amuwv7dt6aqtVvMundOWnwAAAM0"]
[Thu Jul 30 15:14:55.871831 2026] [security2:error] [pid 133043:tid 133236] [client 20.226.5.174:37573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/linkpreviewk.php"] [unique_id "amuwv7dt6aqtVvMundOWqQAAAMQ"]
[Thu Jul 30 15:14:55.886950 2026] [core:notice] [pid 133043:tid 133267] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:55.892501 2026] [security2:error] [pid 133043:tid 133267] [client 43.172.194.223:45186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/04/03/nouveau-site-de-minelli/"] [unique_id "amuwv7dt6aqtVvMundOWqgAAAOM"], referer: https://carnetdeshopping.com/index.php/2009/04/03/nouveau-site-de-minelli/
[Thu Jul 30 15:14:56.144876 2026] [core:notice] [pid 133043:tid 133269] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:56.483430 2026] [security2:error] [pid 133043:tid 133174] [client 37.77.56.246:34858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.56.77.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuwwLdt6aqtVvMundOWtQAAAIY"]
[Thu Jul 30 15:14:56.483535 2026] [security2:error] [pid 133043:tid 133174] [client 37.77.56.246:34858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuwwLdt6aqtVvMundOWtQAAAIY"]
[Thu Jul 30 15:14:57.041019 2026] [security2:error] [pid 133043:tid 133237] [client 220.181.108.105:63449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/about/privacy"] [unique_id "amuwwLdt6aqtVvMundOWwQAAAMU"]
[Thu Jul 30 15:14:57.221797 2026] [security2:error] [pid 133043:tid 133138] [remote 103.75.185.95:43990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themushroom.online"] [uri "/wp-login.php"] [unique_id "amuwwbdt6aqtVvMundOW0AAAh14"]
[Thu Jul 30 15:14:57.407109 2026] [security2:error] [pid 133043:tid 133230] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwwLdt6aqtVvMundOWxAAAAL4"]
[Thu Jul 30 15:14:57.829302 2026] [security2:error] [pid 133043:tid 133249] [client 47.236.164.125:34690] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alseermarine.com"] [uri "/about/leadership/"] [unique_id "amuwwbdt6aqtVvMundOW5gAAANE"]
[Thu Jul 30 15:14:57.989570 2026] [security2:error] [pid 133043:tid 133259] [client 37.77.56.246:34864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.56.77.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuwwbdt6aqtVvMundOW6AAAANs"]
[Thu Jul 30 15:14:57.989658 2026] [security2:error] [pid 133043:tid 133259] [client 37.77.56.246:34864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuwwbdt6aqtVvMundOW6AAAANs"]
[Thu Jul 30 15:14:58.082851 2026] [security2:error] [pid 133043:tid 133224] [client 20.52.54.143:11025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-conflg.php"] [unique_id "amuwwrdt6aqtVvMundOW6QAAALg"]
[Thu Jul 30 15:14:58.098144 2026] [core:notice] [pid 133043:tid 133199] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:14:58.168699 2026] [security2:error] [pid 133043:tid 133207] [client 57.141.0.17:44362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alseermarine.com"] [uri "/index.php"] [unique_id "amuwwbdt6aqtVvMundOW5QAAp3Y"]
[Thu Jul 30 15:14:58.455701 2026] [security2:error] [pid 133043:tid 133179] [client 119.249.100.173:57348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/about/privacy"] [unique_id "amuwwrdt6aqtVvMundOW9gAAAIs"]
[Thu Jul 30 15:14:58.559896 2026] [security2:error] [pid 133043:tid 133266] [client 172.237.109.114:16420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwwrdt6aqtVvMundOW6gAAAOI"]
[Thu Jul 30 15:14:58.889266 2026] [security2:error] [pid 133043:tid 133062] [remote 110.249.201.155:17976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor_relations/financial-report-2024.pdf"] [unique_id "amuwwrdt6aqtVvMundOXAQAAmxI"]
[Thu Jul 30 15:14:58.993523 2026] [security2:error] [pid 133043:tid 133283] [client 20.52.54.143:10636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/123.php"] [unique_id "amuwwrdt6aqtVvMundOXBQAAAPM"]
[Thu Jul 30 15:14:59.655680 2026] [security2:error] [pid 133043:tid 133176] [client 20.52.54.143:10435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/yanz.php"] [unique_id "amuww7dt6aqtVvMundOXEgAAAIg"]
[Thu Jul 30 15:14:59.780343 2026] [core:notice] [pid 133043:tid 133268] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:00.176891 2026] [core:notice] [pid 133043:tid 133204] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:00.239458 2026] [core:notice] [pid 133043:tid 133249] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:00.475011 2026] [security2:error] [pid 133043:tid 133185] [client 213.152.161.170:58724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuwxLdt6aqtVvMundOXKQAAAJE"]
[Thu Jul 30 15:15:00.475118 2026] [security2:error] [pid 133043:tid 133185] [client 213.152.161.170:58724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuwxLdt6aqtVvMundOXKQAAAJE"]
[Thu Jul 30 15:15:01.021469 2026] [security2:error] [pid 133043:tid 133221] [client 20.52.54.143:11068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/autoload_classmap.php"] [unique_id "amuwxbdt6aqtVvMundOXNgAAALU"]
[Thu Jul 30 15:15:01.168756 2026] [core:notice] [pid 133043:tid 133190] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:01.213238 2026] [security2:error] [pid 133043:tid 133207] [client 57.141.0.58:35450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwxLdt6aqtVvMundOXKgAApww"]
[Thu Jul 30 15:15:03.113663 2026] [core:notice] [pid 133043:tid 133224] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:04.013956 2026] [core:notice] [pid 133043:tid 133235] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:04.058785 2026] [core:error] [pid 133043:tid 133183] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:04.058814 2026] [core:error] [pid 133043:tid 133183] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:04.195730 2026] [security2:error] [pid 133043:tid 133110] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwyLdt6aqtVvMundOXfwAAnUI"]
[Thu Jul 30 15:15:04.195895 2026] [security2:error] [pid 133043:tid 133197] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuwyLdt6aqtVvMundOXfwAAnUI"]
[Thu Jul 30 15:15:04.212727 2026] [security2:error] [pid 133043:tid 133207] [client 20.52.54.143:11032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/bi.php"] [unique_id "amuwyLdt6aqtVvMundOXgAAAAKc"]
[Thu Jul 30 15:15:04.776128 2026] [core:notice] [pid 133043:tid 133100] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:04.907146 2026] [core:notice] [pid 133043:tid 133262] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:04.948618 2026] [security2:error] [pid 133043:tid 133299] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuwyLdt6aqtVvMundOXkgAAAQM"]
[Thu Jul 30 15:15:05.276867 2026] [security2:error] [pid 133043:tid 133254] [client 20.52.54.143:11038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/cc.php"] [unique_id "amuwybdt6aqtVvMundOXowAAANY"]
[Thu Jul 30 15:15:05.571411 2026] [core:notice] [pid 133043:tid 133223] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:05.738247 2026] [security2:error] [pid 133043:tid 133221] [client 82.102.27.163:44776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuwybdt6aqtVvMundOXsAAAALU"]
[Thu Jul 30 15:15:05.738355 2026] [security2:error] [pid 133043:tid 133221] [client 82.102.27.163:44776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuwybdt6aqtVvMundOXsAAAALU"]
[Thu Jul 30 15:15:05.977841 2026] [security2:error] [pid 133043:tid 133277] [client 20.52.54.143:10439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/files/index.php"] [unique_id "amuwybdt6aqtVvMundOXtQAAAO0"]
[Thu Jul 30 15:15:06.173423 2026] [security2:error] [pid 133043:tid 133251] [client 116.179.33.72:11530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.33.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/$$$call$$$/page/page/css"] [unique_id "amuwybdt6aqtVvMundOXsQAAANM"], referer: http://www.ejournalugj.com/
[Thu Jul 30 15:15:06.284371 2026] [security2:error] [pid 133043:tid 133183] [client 37.77.56.246:46590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.56.77.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuwyrdt6aqtVvMundOXvgAAAI8"]
[Thu Jul 30 15:15:06.284506 2026] [security2:error] [pid 133043:tid 133183] [client 37.77.56.246:46590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuwyrdt6aqtVvMundOXvgAAAI8"]
[Thu Jul 30 15:15:06.306756 2026] [core:notice] [pid 133043:tid 133080] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:06.518909 2026] [security2:error] [pid 133043:tid 133273] [client 172.237.109.114:37202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwyrdt6aqtVvMundOXtgAAAOk"]
[Thu Jul 30 15:15:06.709906 2026] [security2:error] [pid 133043:tid 133198] [client 172.237.109.114:18148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuwyrdt6aqtVvMundOXvQAAAJ4"]
[Thu Jul 30 15:15:07.105920 2026] [security2:error] [pid 133043:tid 133200] [client 66.249.93.77:37224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuwybdt6aqtVvMundOXnQAAAKA"]
[Thu Jul 30 15:15:07.127923 2026] [security2:error] [pid 133043:tid 133210] [client 50.6.43.217:60150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuwy7dt6aqtVvMundOXzgAAAKo"]
[Thu Jul 30 15:15:07.128745 2026] [security2:error] [pid 133043:tid 133191] [client 66.249.93.77:64738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuwyLdt6aqtVvMundOXmgAAAJc"]
[Thu Jul 30 15:15:07.251752 2026] [security2:error] [pid 133043:tid 133279] [client 50.6.43.217:60164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuwy7dt6aqtVvMundOX1QAAAO8"]
[Thu Jul 30 15:15:07.536142 2026] [security2:error] [pid 133043:tid 133178] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuwyrdt6aqtVvMundOXzAAAAIo"]
[Thu Jul 30 15:15:07.725517 2026] [core:notice] [pid 133043:tid 133118] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:08.427015 2026] [security2:error] [pid 133043:tid 133094] [remote 47.128.115.37:43872] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuwzLdt6aqtVvMundOX8gAA7TI"]
[Thu Jul 30 15:15:09.651292 2026] [core:notice] [pid 133043:tid 133279] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:09.955918 2026] [security2:error] [pid 133043:tid 133120] [remote 47.128.27.4:23254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/fendi-jacket-tan/"] [unique_id "amuwzbdt6aqtVvMundOYGwAAnEw"]
[Thu Jul 30 15:15:10.127704 2026] [core:notice] [pid 133043:tid 133245] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:11.374642 2026] [security2:error] [pid 133043:tid 133251] [client 146.103.109.89:20512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.109.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuwz7dt6aqtVvMundOYRgAAANM"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 15:15:11.866501 2026] [security2:error] [pid 133043:tid 133290] [client 146.103.109.89:20573] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuwz7dt6aqtVvMundOYUQAAAPo"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 15:15:12.831036 2026] [security2:error] [pid 133043:tid 133298] [client 185.200.117.131:54638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.117.200.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuw0Ldt6aqtVvMundOYYAAAAQI"]
[Thu Jul 30 15:15:12.831139 2026] [security2:error] [pid 133043:tid 133298] [client 185.200.117.131:54638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuw0Ldt6aqtVvMundOYYAAAAQI"]
[Thu Jul 30 15:15:13.291217 2026] [autoindex:error] [pid 133043:tid 133174] [client 124.123.106.143:34236] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:15:13.652189 2026] [security2:error] [pid 133043:tid 133193] [client 20.52.54.143:10647] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.jesus.claims"] [uri "/1.php7"] [unique_id "amuw0bdt6aqtVvMundOYeAAAAJk"]
[Thu Jul 30 15:15:13.652342 2026] [security2:error] [pid 133043:tid 133193] [client 20.52.54.143:10647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/1.php7"] [unique_id "amuw0bdt6aqtVvMundOYeAAAAJk"]
[Thu Jul 30 15:15:14.592635 2026] [security2:error] [pid 133043:tid 133261] [client 172.237.109.114:58526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuw0rdt6aqtVvMundOYggAAAN0"]
[Thu Jul 30 15:15:14.877569 2026] [security2:error] [pid 133043:tid 133233] [client 20.52.54.143:10633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/disagraeosc.php"] [unique_id "amuw0rdt6aqtVvMundOYlQAAAME"]
[Thu Jul 30 15:15:14.890494 2026] [security2:error] [pid 133043:tid 133065] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw0rdt6aqtVvMundOYlgAA8BU"]
[Thu Jul 30 15:15:14.890666 2026] [security2:error] [pid 133043:tid 133280] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw0rdt6aqtVvMundOYlgAA8BU"]
[Thu Jul 30 15:15:15.091752 2026] [security2:error] [pid 133043:tid 133180] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuw0rdt6aqtVvMundOYiAAAAIw"]
[Thu Jul 30 15:15:15.559352 2026] [security2:error] [pid 133043:tid 133287] [client 172.237.109.114:34856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuw07dt6aqtVvMundOYnAAAAPc"]
[Thu Jul 30 15:15:15.935825 2026] [security2:error] [pid 133043:tid 133194] [client 20.52.54.143:10472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-logs.php"] [unique_id "amuw07dt6aqtVvMundOYsQAAAJo"]
[Thu Jul 30 15:15:16.154834 2026] [security2:error] [pid 133043:tid 133277] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuw07dt6aqtVvMundOYrQAAAO0"]
[Thu Jul 30 15:15:16.850056 2026] [security2:error] [pid 133043:tid 133273] [client 50.6.43.217:18690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuw1Ldt6aqtVvMundOYuQAAAOk"]
[Thu Jul 30 15:15:16.894624 2026] [security2:error] [pid 133043:tid 133210] [client 20.52.54.143:10445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-admin/css/about.php"] [unique_id "amuw1Ldt6aqtVvMundOYxgAAAKo"]
[Thu Jul 30 15:15:17.569647 2026] [security2:error] [pid 133043:tid 133279] [client 50.6.43.217:18704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuw1Ldt6aqtVvMundOYxQAAAO8"]
[Thu Jul 30 15:15:18.179962 2026] [security2:error] [pid 133043:tid 133257] [client 20.52.54.143:10475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/system_log.php"] [unique_id "amuw1rdt6aqtVvMundOY4QAAANk"]
[Thu Jul 30 15:15:18.499539 2026] [security2:error] [pid 133043:tid 133217] [client 139.59.25.22:35464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.clubnails.bonafideadvisors.com"] [uri "/index.php"] [unique_id "amuw1rdt6aqtVvMundOY5QAAALE"], referer: http://www.clubnails.bonafideadvisors.com/
[Thu Jul 30 15:15:18.791019 2026] [security2:error] [pid 133043:tid 133181] [client 20.52.54.143:10436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/24.php"] [unique_id "amuw1rdt6aqtVvMundOY8AAAAI0"]
[Thu Jul 30 15:15:18.968088 2026] [security2:error] [pid 133043:tid 133136] [remote 209.133.215.178:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.215.133.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "koriusa.info"] [uri "/wp-login.php"] [unique_id "amuw1rdt6aqtVvMundOY8QAA-1w"]
[Thu Jul 30 15:15:19.235728 2026] [security2:error] [pid 133043:tid 133220] [client 139.59.25.22:44130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.clubnails.bonafideadvisors.com"] [uri "/index.php"] [unique_id "amuw17dt6aqtVvMundOY8gAAALQ"], referer: https://www.clubnails.bonafideadvisors.com/
[Thu Jul 30 15:15:19.536703 2026] [autoindex:error] [pid 133043:tid 133251] [client 103.120.237.214:37195] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:15:20.959094 2026] [security2:error] [pid 133043:tid 133227] [client 85.208.96.196:38616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2020/09/23/daniella-ribeiro-e-veneziano-pedem-licenca-do-senado-suplentes-diego-tavares-e-ney-suassuna-assumem-cargos-ate-janeiro/"] [unique_id "amuw2Ldt6aqtVvMundOZKAAAALs"]
[Thu Jul 30 15:15:20.959284 2026] [security2:error] [pid 133043:tid 133227] [client 85.208.96.196:38616] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2020/09/23/daniella-ribeiro-e-veneziano-pedem-licenca-do-senado-suplentes-diego-tavares-e-ney-suassuna-assumem-cargos-ate-janeiro/"] [unique_id "amuw2Ldt6aqtVvMundOZKAAAALs"]
[Thu Jul 30 15:15:20.996737 2026] [autoindex:error] [pid 133043:tid 133087] [remote 172.237.151.13:59264] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_b63f1d3b/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:15:21.086622 2026] [core:notice] [pid 133043:tid 133053] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:21.090485 2026] [security2:error] [pid 133043:tid 133241] [client 66.249.74.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/268/267"] [unique_id "amuw2Ldt6aqtVvMundOZJwAAyQk"]
[Thu Jul 30 15:15:21.213751 2026] [core:notice] [pid 133043:tid 133200] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:21.225970 2026] [core:error] [pid 133043:tid 133200] [client 66.249.79.231:53497] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:21.226184 2026] [security2:error] [pid 133043:tid 133200] [client 66.249.79.231:53497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/1581/3639.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuw2bdt6aqtVvMundOZLgAAAKA"]
[Thu Jul 30 15:15:21.288569 2026] [security2:error] [pid 133043:tid 133211] [client 20.52.54.143:10495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-content/plugins/index.php"] [unique_id "amuw2bdt6aqtVvMundOZMgAAAKs"]
[Thu Jul 30 15:15:21.573627 2026] [core:error] [pid 133043:tid 133263] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:21.573658 2026] [core:error] [pid 133043:tid 133263] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:21.762496 2026] [security2:error] [pid 133043:tid 133092] [remote 57.141.0.61:61126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuw2bdt6aqtVvMundOZOwAAnTA"]
[Thu Jul 30 15:15:21.819736 2026] [security2:error] [pid 133043:tid 133299] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuw2bdt6aqtVvMundOZLQABAxA"]
[Thu Jul 30 15:15:21.911290 2026] [core:notice] [pid 133043:tid 133291] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:22.933665 2026] [security2:error] [pid 133043:tid 133233] [client 85.208.96.211:18722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/16/prefeitura-de-lagoa-de-dentro-entregou-600-cestas-basicas-a-populacao-carente/"] [unique_id "amuw2rdt6aqtVvMundOZWwAAAME"]
[Thu Jul 30 15:15:22.933807 2026] [security2:error] [pid 133043:tid 133233] [client 85.208.96.211:18722] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/16/prefeitura-de-lagoa-de-dentro-entregou-600-cestas-basicas-a-populacao-carente/"] [unique_id "amuw2rdt6aqtVvMundOZWwAAAME"]
[Thu Jul 30 15:15:23.331594 2026] [security2:error] [pid 133043:tid 133284] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuw2rdt6aqtVvMundOZUQAAAPQ"]
[Thu Jul 30 15:15:24.608652 2026] [security2:error] [pid 133043:tid 133216] [client 172.237.109.114:65508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuw3Ldt6aqtVvMundOZdAAAALA"]
[Thu Jul 30 15:15:24.771533 2026] [core:error] [pid 133043:tid 133129] [remote 52.167.144.169:2641] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:24.771553 2026] [core:error] [pid 133043:tid 133129] [remote 52.167.144.169:2641] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:25.054701 2026] [security2:error] [pid 133043:tid 133277] [client 20.52.54.143:11017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-admin/images/index.php"] [unique_id "amuw3bdt6aqtVvMundOZiwAAAO0"]
[Thu Jul 30 15:15:25.449466 2026] [security2:error] [pid 133043:tid 133121] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw3bdt6aqtVvMundOZjwAAkk0"]
[Thu Jul 30 15:15:25.449627 2026] [security2:error] [pid 133043:tid 133186] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw3bdt6aqtVvMundOZjwAAkk0"]
[Thu Jul 30 15:15:25.809670 2026] [security2:error] [pid 133043:tid 133214] [client 20.52.54.143:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/num.php"] [unique_id "amuw3bdt6aqtVvMundOZlwAAAK4"]
[Thu Jul 30 15:15:26.283329 2026] [security2:error] [pid 133043:tid 133143] [remote 57.141.0.37:33436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3390535976/feed/rss2/"] [unique_id "amuw3rdt6aqtVvMundOZogAAuGM"]
[Thu Jul 30 15:15:26.993731 2026] [core:notice] [pid 133043:tid 133271] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:27.040476 2026] [security2:error] [pid 133043:tid 133153] [remote 57.141.0.28:63682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55997217192/feed/rss2/"] [unique_id "amuw37dt6aqtVvMundOZtgAAz20"]
[Thu Jul 30 15:15:27.899598 2026] [security2:error] [pid 133043:tid 133201] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuw37dt6aqtVvMundOZwAAAAKE"]
[Thu Jul 30 15:15:27.923408 2026] [security2:error] [pid 133043:tid 133291] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuw37dt6aqtVvMundOZwwAAAPs"]
[Thu Jul 30 15:15:28.088281 2026] [security2:error] [pid 133043:tid 133278] [client 20.52.54.143:11021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuw4Ldt6aqtVvMundOZ1wAAAO4"]
[Thu Jul 30 15:15:29.963466 2026] [security2:error] [pid 133043:tid 133247] [client 20.52.54.143:11055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "amuw4bdt6aqtVvMundOaBAAAAM8"]
[Thu Jul 30 15:15:30.218848 2026] [security2:error] [pid 133043:tid 133062] [remote 57.141.0.14:34222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuw4rdt6aqtVvMundOaCQAAlhI"]
[Thu Jul 30 15:15:30.325715 2026] [security2:error] [pid 133043:tid 133145] [remote 207.46.13.170:30899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/1374079454/article.php"] [unique_id "amuw4rdt6aqtVvMundOaDgAA8GU"]
[Thu Jul 30 15:15:31.696810 2026] [security2:error] [pid 133043:tid 133279] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuw47dt6aqtVvMundOaKQAA738"]
[Thu Jul 30 15:15:32.646900 2026] [security2:error] [pid 133043:tid 133184] [client 20.52.54.143:11040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/gifclass.php"] [unique_id "amuw5Ldt6aqtVvMundOaVgAAAJA"]
[Thu Jul 30 15:15:33.439258 2026] [core:notice] [pid 133043:tid 133245] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:34.162085 2026] [core:notice] [pid 133043:tid 133079] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:34.608380 2026] [security2:error] [pid 133043:tid 133247] [client 20.52.54.143:11052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-content/plugins/admin.php"] [unique_id "amuw5rdt6aqtVvMundOaigAAAM8"]
[Thu Jul 30 15:15:35.570308 2026] [core:notice] [pid 133043:tid 133214] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:35.576724 2026] [security2:error] [pid 133043:tid 133214] [client 66.249.79.230:55260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA/article/view/2236/1354"] [unique_id "amuw57dt6aqtVvMundOaqAAAAK4"]
[Thu Jul 30 15:15:36.015614 2026] [security2:error] [pid 133043:tid 133249] [client 74.7.241.176:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kayomanis.com"] [uri "/index.php"] [unique_id "amuw57dt6aqtVvMundOamAAAANE"]
[Thu Jul 30 15:15:36.015648 2026] [security2:error] [pid 133043:tid 133249] [client 74.7.241.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kayomanis.com"] [uri "/index.php"] [unique_id "amuw57dt6aqtVvMundOamAAAANE"]
[Thu Jul 30 15:15:36.016465 2026] [security2:error] [pid 133043:tid 133190] [client 74.7.241.176:45008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.kayomanis.com"] [uri "/robots.txt"] [unique_id "amuw57dt6aqtVvMundOalgAAlko"]
[Thu Jul 30 15:15:36.017966 2026] [security2:error] [pid 133043:tid 133045] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw6Ldt6aqtVvMundOaswAAxAE"]
[Thu Jul 30 15:15:36.018149 2026] [security2:error] [pid 133043:tid 133236] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw6Ldt6aqtVvMundOaswAAxAE"]
[Thu Jul 30 15:15:36.656696 2026] [security2:error] [pid 133043:tid 133187] [client 20.52.54.143:10663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/css/index.php"] [unique_id "amuw6Ldt6aqtVvMundOaxAAAAJM"]
[Thu Jul 30 15:15:36.822352 2026] [security2:error] [pid 133043:tid 133247] [client 74.7.241.176:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kayomanis.com"] [uri "/index.php"] [unique_id "amuw6Ldt6aqtVvMundOaxQAAAM8"], referer: https://www.kayomanis.com/robots.txt
[Thu Jul 30 15:15:36.823355 2026] [security2:error] [pid 133043:tid 133250] [client 74.7.241.176:45024] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kayomanis.com"] [uri "/robots.txt"] [unique_id "amuw6Ldt6aqtVvMundOawQAA0kw"], referer: https://www.kayomanis.com/robots.txt
[Thu Jul 30 15:15:36.897404 2026] [core:error] [pid 133043:tid 133208] [client 5.161.225.116:33906] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:36.897429 2026] [core:error] [pid 133043:tid 133208] [client 5.161.225.116:33906] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:37.002790 2026] [security2:error] [pid 133043:tid 133139] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.royalrelaxspa.sbs"] [uri "/app/config/local.php"] [unique_id "amuw6bdt6aqtVvMundOaywAA0F8"]
[Thu Jul 30 15:15:37.098663 2026] [core:error] [pid 133043:tid 133291] [client 5.161.225.116:33014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:37.098685 2026] [core:error] [pid 133043:tid 133291] [client 5.161.225.116:33014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:37.273137 2026] [security2:error] [pid 133043:tid 133137] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.royalrelaxspa.sbs"] [uri "/app/config/local.php.bak"] [unique_id "amuw6bdt6aqtVvMundOa1AAAt10"]
[Thu Jul 30 15:15:37.454204 2026] [security2:error] [pid 133043:tid 133153] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.royalrelaxspa.sbs"] [uri "/mautic/app/config/local.php"] [unique_id "amuw6bdt6aqtVvMundOa1gAAv20"]
[Thu Jul 30 15:15:37.587771 2026] [security2:error] [pid 133043:tid 133269] [client 20.52.54.143:11067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-cron.php"] [unique_id "amuw6bdt6aqtVvMundOa2gAAAOU"]
[Thu Jul 30 15:15:37.629683 2026] [security2:error] [pid 133043:tid 133135] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.royalrelaxspa.sbs"] [uri "/config/mail.php"] [unique_id "amuw6bdt6aqtVvMundOa3gAAlVs"]
[Thu Jul 30 15:15:38.162501 2026] [security2:error] [pid 133043:tid 133154] [remote 195.178.110.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.royalrelaxspa.sbs"] [uri "/config/services.php"] [unique_id "amuw6rdt6aqtVvMundOa6gAAtm4"]
[Thu Jul 30 15:15:38.983900 2026] [security2:error] [pid 133043:tid 133148] [remote 57.141.0.17:44512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuw6rdt6aqtVvMundOa-QAA8Wg"]
[Thu Jul 30 15:15:39.850407 2026] [security2:error] [pid 133043:tid 133210] [client 20.52.54.143:10448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-block.php"] [unique_id "amuw67dt6aqtVvMundObDAAAAKo"]
[Thu Jul 30 15:15:40.532266 2026] [core:notice] [pid 133043:tid 133245] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:40.617053 2026] [security2:error] [pid 133043:tid 133275] [client 172.237.109.114:11629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuw7Ldt6aqtVvMundObDwAAAOs"]
[Thu Jul 30 15:15:40.681170 2026] [security2:error] [pid 133043:tid 133240] [client 20.52.54.143:10438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jesus.claims"] [uri "/wp-includes/fonts/admin.php"] [unique_id "amuw7Ldt6aqtVvMundObIwAAAMg"]
[Thu Jul 30 15:15:41.485908 2026] [security2:error] [pid 133043:tid 133295] [client 172.237.109.114:24717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuw7Ldt6aqtVvMundObLgAAAP8"]
[Thu Jul 30 15:15:44.100521 2026] [core:notice] [pid 133043:tid 133078] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:44.247541 2026] [security2:error] [pid 133043:tid 133082] [remote 62.210.185.4:60004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-aa23bb9f.dlr.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuw8Ldt6aqtVvMundObeAAA2CY"]
[Thu Jul 30 15:15:44.473898 2026] [security2:error] [pid 133043:tid 133292] [client 172.237.109.114:13010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuw77dt6aqtVvMundObdAAAAPw"]
[Thu Jul 30 15:15:45.483918 2026] [security2:error] [pid 133043:tid 133269] [client 172.237.109.114:59440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuw8Ldt6aqtVvMundObjQAAAOU"]
[Thu Jul 30 15:15:46.597822 2026] [security2:error] [pid 133043:tid 133105] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw8rdt6aqtVvMundObrQAA9T0"]
[Thu Jul 30 15:15:46.598001 2026] [security2:error] [pid 133043:tid 133285] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw8rdt6aqtVvMundObrQAA9T0"]
[Thu Jul 30 15:15:47.373675 2026] [core:error] [pid 133043:tid 133209] [client 87.99.130.230:42708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:47.373714 2026] [core:error] [pid 133043:tid 133209] [client 87.99.130.230:42708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:47.579609 2026] [core:error] [pid 133043:tid 133196] [client 87.99.130.230:6810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:47.579633 2026] [core:error] [pid 133043:tid 133196] [client 87.99.130.230:6810] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:48.482002 2026] [security2:error] [pid 133043:tid 133128] [remote 57.141.0.39:43050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5035568461/feed/rss2/"] [unique_id "amuw9Ldt6aqtVvMundOb2wAA_VQ"]
[Thu Jul 30 15:15:48.544685 2026] [core:notice] [pid 133043:tid 133177] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:48.951394 2026] [security2:error] [pid 133043:tid 133127] [remote 111.225.148.80:58480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/2024/07/15/al-seer-marine-expands-leadership-team-with-the-appointment-of-gunther-alvarado-as-deputy-ceo/"] [unique_id "amuw9Ldt6aqtVvMundOb4wAA9VM"]
[Thu Jul 30 15:15:49.139617 2026] [core:notice] [pid 133043:tid 133252] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:49.274955 2026] [security2:error] [pid 133043:tid 133123] [remote 97.74.87.194:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-login.php"] [unique_id "amuw9bdt6aqtVvMundOb8AAAp08"]
[Thu Jul 30 15:15:50.146440 2026] [core:notice] [pid 133043:tid 133126] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:50.238550 2026] [security2:error] [pid 133043:tid 133294] [client 20.100.187.246:13933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/--wp-lgj.php"] [unique_id "amuw9rdt6aqtVvMundOcEAAAAP4"]
[Thu Jul 30 15:15:50.262480 2026] [core:error] [pid 133043:tid 133174] [client 139.28.219.70:38702] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:50.262508 2026] [core:error] [pid 133043:tid 133174] [client 139.28.219.70:38702] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:50.529851 2026] [core:error] [pid 133043:tid 133197] [client 139.28.219.70:45004] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:50.529875 2026] [core:error] [pid 133043:tid 133197] [client 139.28.219.70:45004] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:15:50.581819 2026] [core:notice] [pid 133043:tid 133271] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:50.833290 2026] [security2:error] [pid 133043:tid 133246] [client 139.28.219.70:45014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hvacairductscleaners.us"] [uri "/xmlrpc.php"] [unique_id "amuw9rdt6aqtVvMundOcHQAAAM4"]
[Thu Jul 30 15:15:50.833394 2026] [security2:error] [pid 133043:tid 133246] [client 139.28.219.70:45014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hvacairductscleaners.us"] [uri "/xmlrpc.php"] [unique_id "amuw9rdt6aqtVvMundOcHQAAAM4"]
[Thu Jul 30 15:15:52.937395 2026] [security2:error] [pid 133043:tid 133234] [client 20.100.187.246:8839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amuw-Ldt6aqtVvMundOcSQAAAMI"]
[Thu Jul 30 15:15:53.512197 2026] [security2:error] [pid 133043:tid 133266] [client 172.237.109.114:19689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuw-bdt6aqtVvMundOcSgAAAOI"]
[Thu Jul 30 15:15:53.771870 2026] [security2:error] [pid 133043:tid 133155] [remote 74.7.243.224:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/job.php"] [unique_id "amuw-bdt6aqtVvMundOcXAAAvW8"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/article.php?id=27
[Thu Jul 30 15:15:54.742297 2026] [security2:error] [pid 133043:tid 133225] [client 47.128.38.94:41448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jwcpartners.org"] [uri "/robots.txt"] [unique_id "amuw-rdt6aqtVvMundOcbgAAALk"]
[Thu Jul 30 15:15:54.912672 2026] [security2:error] [pid 133043:tid 133273] [client 20.100.187.246:15924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/flower.php"] [unique_id "amuw-rdt6aqtVvMundOceAAAAOk"]
[Thu Jul 30 15:15:54.978925 2026] [security2:error] [pid 133043:tid 133062] [remote 97.74.93.24:53856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supreme-hydraulics.com"] [uri "/wp-login.php"] [unique_id "amuw-rdt6aqtVvMundOceQAA0hI"]
[Thu Jul 30 15:15:55.687971 2026] [security2:error] [pid 133043:tid 133216] [client 20.100.187.246:8834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/xleet.php"] [unique_id "amuw-7dt6aqtVvMundOchwAAALA"]
[Thu Jul 30 15:15:55.875765 2026] [security2:error] [pid 133043:tid 133237] [client 85.208.96.194:49996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/07/12/policia-civil-prende-chefe-de-faccao-investigado-por-matar-mulher-nos-festejos-juninos-em-solanea/"] [unique_id "amuw-7dt6aqtVvMundOckAAAAMU"]
[Thu Jul 30 15:15:55.875898 2026] [security2:error] [pid 133043:tid 133237] [client 85.208.96.194:49996] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/07/12/policia-civil-prende-chefe-de-faccao-investigado-por-matar-mulher-nos-festejos-juninos-em-solanea/"] [unique_id "amuw-7dt6aqtVvMundOckAAAAMU"]
[Thu Jul 30 15:15:56.169993 2026] [core:notice] [pid 133043:tid 133277] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:56.174204 2026] [security2:error] [pid 133043:tid 133277] [client 66.249.79.229:40105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/article/download/1951/1223"] [unique_id "amuw-7dt6aqtVvMundOckgAAAO0"]
[Thu Jul 30 15:15:57.008541 2026] [security2:error] [pid 133043:tid 133235] [client 20.100.187.246:14770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amuw_bdt6aqtVvMundOcpQAAAMM"]
[Thu Jul 30 15:15:57.122136 2026] [security2:error] [pid 133043:tid 133056] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw_bdt6aqtVvMundOcpgAA_ww"]
[Thu Jul 30 15:15:57.122329 2026] [security2:error] [pid 133043:tid 133295] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuw_bdt6aqtVvMundOcpgAA_ww"]
[Thu Jul 30 15:15:57.865530 2026] [security2:error] [pid 133043:tid 133182] [client 20.100.187.246:19716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amuw_bdt6aqtVvMundOctAAAAI4"]
[Thu Jul 30 15:15:57.865861 2026] [core:notice] [pid 133043:tid 133189] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:15:57.869724 2026] [security2:error] [pid 133043:tid 133189] [client 66.249.79.8:65496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/view/189/135"] [unique_id "amuw_bdt6aqtVvMundOcsAAAAJU"]
[Thu Jul 30 15:15:58.440845 2026] [security2:error] [pid 133043:tid 133250] [client 172.237.109.114:1812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuw_bdt6aqtVvMundOcuwAAANI"]
[Thu Jul 30 15:15:59.274304 2026] [core:notice] [pid 133043:tid 133258] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:00.018800 2026] [security2:error] [pid 133043:tid 133187] [client 20.100.187.246:43623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amuxALdt6aqtVvMundOc5QAAAJM"]
[Thu Jul 30 15:16:00.726135 2026] [security2:error] [pid 133043:tid 133213] [client 20.100.187.246:19405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amuxALdt6aqtVvMundOc9gAAAK0"]
[Thu Jul 30 15:16:01.408389 2026] [core:error] [pid 133043:tid 133287] [client 20.100.187.246:14754] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:16:01.408412 2026] [core:error] [pid 133043:tid 133287] [client 20.100.187.246:14754] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:16:02.132347 2026] [core:notice] [pid 133043:tid 133237] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:02.291489 2026] [security2:error] [pid 133043:tid 133255] [client 20.100.187.246:23587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amuxArdt6aqtVvMundOdHAAAANc"]
[Thu Jul 30 15:16:02.786008 2026] [security2:error] [pid 133043:tid 133092] [remote 57.141.0.52:33420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuxArdt6aqtVvMundOdLQAA8DA"]
[Thu Jul 30 15:16:02.805448 2026] [core:notice] [pid 133043:tid 133202] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:02.917179 2026] [core:notice] [pid 133043:tid 133077] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:04.197402 2026] [core:notice] [pid 133043:tid 133226] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:04.201506 2026] [security2:error] [pid 133043:tid 133226] [client 66.249.79.231:56148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/5716"] [unique_id "amuxA7dt6aqtVvMundOdRwAAALo"]
[Thu Jul 30 15:16:04.319429 2026] [security2:error] [pid 133043:tid 133221] [client 20.100.187.246:43632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amuxBLdt6aqtVvMundOdUQAAALU"]
[Thu Jul 30 15:16:04.347424 2026] [core:notice] [pid 133043:tid 133251] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:04.572740 2026] [core:notice] [pid 133043:tid 133262] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:04.665599 2026] [security2:error] [pid 133043:tid 133209] [client 40.77.167.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuxArdt6aqtVvMundOdIAAAAKk"]
[Thu Jul 30 15:16:04.821964 2026] [core:notice] [pid 133043:tid 133131] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:04.919761 2026] [security2:error] [pid 133043:tid 133177] [client 40.77.167.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ashbournerow.com"] [uri "/index.php"] [unique_id "amuxBLdt6aqtVvMundOdXwAAiVg"]
[Thu Jul 30 15:16:05.082671 2026] [core:notice] [pid 133043:tid 133248] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:05.198787 2026] [security2:error] [pid 133043:tid 133242] [client 2a03:2880:f800:2c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxBLdt6aqtVvMundOdVAAAyio"]
[Thu Jul 30 15:16:05.492068 2026] [core:notice] [pid 133043:tid 133116] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:05.668723 2026] [security2:error] [pid 133043:tid 133259] [client 20.100.187.246:11649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amuxBbdt6aqtVvMundOddgAAANs"]
[Thu Jul 30 15:16:06.420814 2026] [http2:info] [pid 147647:tid 147647] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 15:16:06.588134 2026] [security2:error] [pid 147647:tid 147779] [client 20.100.187.246:11710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.wp-cli/flower.php"] [unique_id "amuxBu_ioCvBERk4wq9rDgAAAQw"]
[Thu Jul 30 15:16:06.649754 2026] [core:error] [pid 147647:tid 147648] [remote 52.167.144.206:52548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:16:06.649786 2026] [core:error] [pid 147647:tid 147648] [remote 52.167.144.206:52548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:16:06.660104 2026] [security2:error] [pid 147647:tid 147777] [client 74.7.241.132:55408] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.tif.zzt.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuxBu_ioCvBERk4wq9rEAAAAQo"]
[Thu Jul 30 15:16:07.762929 2026] [security2:error] [pid 147647:tid 147659] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxB-_ioCvBERk4wq9rLgABNQs"]
[Thu Jul 30 15:16:07.763124 2026] [security2:error] [pid 147647:tid 147820] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxB-_ioCvBERk4wq9rLgABNQs"]
[Thu Jul 30 15:16:07.957066 2026] [security2:error] [pid 147647:tid 147833] [client 40.77.167.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuxB-_ioCvBERk4wq9rKgAAAUI"]
[Thu Jul 30 15:16:08.253796 2026] [core:notice] [pid 147647:tid 147664] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:08.348882 2026] [core:notice] [pid 147647:tid 147665] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:08.460598 2026] [security2:error] [pid 147647:tid 147807] [client 20.100.187.246:19400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amuxCO_ioCvBERk4wq9rPQAAASg"]
[Thu Jul 30 15:16:08.911153 2026] [core:notice] [pid 147647:tid 147671] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:09.003925 2026] [core:notice] [pid 147647:tid 147672] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:09.028564 2026] [security2:error] [pid 147647:tid 147901] [client 34.74.242.206:1768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mediaspawn.com"] [uri "/robots.txt"] [unique_id "amuxCe_ioCvBERk4wq9rTwAAAYY"]
[Thu Jul 30 15:16:09.028681 2026] [security2:error] [pid 147647:tid 147901] [client 34.74.242.206:1768] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mediaspawn.com"] [uri "/robots.txt"] [unique_id "amuxCe_ioCvBERk4wq9rTwAAAYY"]
[Thu Jul 30 15:16:09.477046 2026] [security2:error] [pid 147647:tid 147793] [client 34.74.242.206:1779] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mediaspawn.com"] [uri "/"] [unique_id "amuxCe_ioCvBERk4wq9rWwAAARo"]
[Thu Jul 30 15:16:09.477189 2026] [security2:error] [pid 147647:tid 147793] [client 34.74.242.206:1779] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mediaspawn.com"] [uri "/"] [unique_id "amuxCe_ioCvBERk4wq9rWwAAARo"]
[Thu Jul 30 15:16:09.579837 2026] [security2:error] [pid 147647:tid 147898] [client 172.237.109.114:27206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxCe_ioCvBERk4wq9rUAAAAYM"]
[Thu Jul 30 15:16:09.749184 2026] [security2:error] [pid 147647:tid 147782] [client 20.100.187.246:23560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuxCe_ioCvBERk4wq9rYgAAAQ8"]
[Thu Jul 30 15:16:10.367068 2026] [security2:error] [pid 147647:tid 147682] [remote 57.141.0.2:30388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuxCu_ioCvBERk4wq9rcQABLSI"]
[Thu Jul 30 15:16:10.835678 2026] [security2:error] [pid 147647:tid 147823] [client 20.100.187.246:14781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuxCu_ioCvBERk4wq9reQAAATg"]
[Thu Jul 30 15:16:12.165804 2026] [core:notice] [pid 147647:tid 147789] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:12.529595 2026] [core:notice] [pid 147647:tid 147699] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:12.714866 2026] [security2:error] [pid 147647:tid 147806] [client 20.100.187.246:11692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amuxDO_ioCvBERk4wq9rpgAAASc"]
[Thu Jul 30 15:16:12.792839 2026] [core:notice] [pid 147647:tid 147701] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:12.828409 2026] [security2:error] [pid 147647:tid 147703] [remote 110.249.202.44:55912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/investment-calculator/"] [unique_id "amuxDO_ioCvBERk4wq9rqwABNDc"]
[Thu Jul 30 15:16:13.693746 2026] [security2:error] [pid 147647:tid 147898] [client 2a03:2880:f800:31:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxDe_ioCvBERk4wq9rsgABgzo"]
[Thu Jul 30 15:16:14.741482 2026] [core:notice] [pid 147647:tid 147797] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:15.242252 2026] [security2:error] [pid 147647:tid 147722] [remote 216.73.216.51:25746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuxD-_ioCvBERk4wq9r5QABNko"]
[Thu Jul 30 15:16:15.331056 2026] [security2:error] [pid 147647:tid 147800] [client 112.86.225.173:42716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product-category/new-arrivals/"] [unique_id "amuxD-_ioCvBERk4wq9r5gAAASE"]
[Thu Jul 30 15:16:15.331193 2026] [security2:error] [pid 147647:tid 147800] [client 112.86.225.173:42716] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product-category/new-arrivals/"] [unique_id "amuxD-_ioCvBERk4wq9r5gAAASE"]
[Thu Jul 30 15:16:15.377224 2026] [security2:error] [pid 147647:tid 147791] [client 20.100.187.246:14483] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bisbeetour.com"] [uri "/1.php"] [unique_id "amuxD-_ioCvBERk4wq9r6AAAARg"]
[Thu Jul 30 15:16:15.377344 2026] [security2:error] [pid 147647:tid 147791] [client 20.100.187.246:14483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/1.php"] [unique_id "amuxD-_ioCvBERk4wq9r6AAAARg"]
[Thu Jul 30 15:16:16.146605 2026] [autoindex:error] [pid 147647:tid 147866] [client 43.128.149.102:34288] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_b63f1d3b/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:16:16.182211 2026] [security2:error] [pid 147647:tid 147823] [client 20.100.187.246:43543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/admin.php"] [unique_id "amuxEO_ioCvBERk4wq9sAQAAATg"]
[Thu Jul 30 15:16:16.245767 2026] [core:notice] [pid 147647:tid 147835] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:16.643840 2026] [core:notice] [pid 147647:tid 147874] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:16.647864 2026] [security2:error] [pid 147647:tid 147874] [client 66.249.79.1:47056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/5137"] [unique_id "amuxEO_ioCvBERk4wq9sBAAAAWs"]
[Thu Jul 30 15:16:17.515551 2026] [core:notice] [pid 147647:tid 147738] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:17.765331 2026] [security2:error] [pid 147647:tid 147886] [client 20.100.187.246:43537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/as.php"] [unique_id "amuxEe_ioCvBERk4wq9sJwAAAXc"]
[Thu Jul 30 15:16:17.766760 2026] [core:notice] [pid 147647:tid 147742] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:17.773560 2026] [autoindex:error] [pid 147647:tid 147828] [client 129.226.174.80:49706] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:16:18.315169 2026] [security2:error] [pid 147647:tid 147747] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxEu_ioCvBERk4wq9sMwABSWM"]
[Thu Jul 30 15:16:18.315359 2026] [security2:error] [pid 147647:tid 147840] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxEu_ioCvBERk4wq9sMwABSWM"]
[Thu Jul 30 15:16:18.820047 2026] [core:notice] [pid 147647:tid 147871] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:19.609888 2026] [security2:error] [pid 147647:tid 147858] [client 20.100.187.246:14724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/autoload_classmap.php"] [unique_id "amuxE-_ioCvBERk4wq9sTQAAAVs"]
[Thu Jul 30 15:16:19.750359 2026] [core:notice] [pid 147647:tid 147789] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:19.985041 2026] [security2:error] [pid 147647:tid 147780] [client 85.208.96.197:48164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/4210"] [unique_id "amuxE-_ioCvBERk4wq9sWQAAAQ0"]
[Thu Jul 30 15:16:19.985218 2026] [security2:error] [pid 147647:tid 147780] [client 85.208.96.197:48164] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/4210"] [unique_id "amuxE-_ioCvBERk4wq9sWQAAAQ0"]
[Thu Jul 30 15:16:21.826059 2026] [core:notice] [pid 147647:tid 147772] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:21.961667 2026] [security2:error] [pid 147647:tid 147884] [client 77.31.205.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuxFe_ioCvBERk4wq9sfQAAAXU"], referer: https://cnpinyin.com
[Thu Jul 30 15:16:22.599748 2026] [security2:error] [pid 147647:tid 147806] [client 20.100.187.246:11705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/back.php"] [unique_id "amuxFu_ioCvBERk4wq9skQAAASc"]
[Thu Jul 30 15:16:22.636815 2026] [proxy:error] [pid 147647:tid 147795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:16:22.636869 2026] [proxy_http:error] [pid 147647:tid 147795] [client 74.7.241.189:48504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:16:22.637466 2026] [proxy:error] [pid 147647:tid 147795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:16:22.637511 2026] [proxy_http:error] [pid 147647:tid 147795] [client 74.7.241.189:48504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:16:22.637632 2026] [security2:error] [pid 147647:tid 147795] [client 74.7.241.189:48504] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.ghj.djb.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuxFu_ioCvBERk4wq9skgAAARw"]
[Thu Jul 30 15:16:23.280499 2026] [autoindex:error] [pid 147647:tid 147836] [client 91.192.10.101:48286] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:16:23.348582 2026] [security2:error] [pid 147647:tid 147831] [client 4.225.203.146:3078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "arabian-tours.com"] [uri "/"] [unique_id "amuxF-_ioCvBERk4wq9spAAAAUA"]
[Thu Jul 30 15:16:23.450937 2026] [autoindex:error] [pid 147647:tid 147851] [client 91.192.10.101:39078] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:16:23.600841 2026] [autoindex:error] [pid 147647:tid 147867] [client 91.192.10.101:39078] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:16:23.674774 2026] [security2:error] [pid 147647:tid 147830] [client 20.100.187.246:9353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/c/autoload_classmap.php"] [unique_id "amuxF-_ioCvBERk4wq9srQAAAT8"]
[Thu Jul 30 15:16:23.706594 2026] [security2:error] [pid 147647:tid 147868] [client 4.225.203.146:3072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "arabian-tours.com"] [uri "/"] [unique_id "amuxF-_ioCvBERk4wq9srgAAAWU"]
[Thu Jul 30 15:16:24.118363 2026] [security2:error] [pid 147647:tid 147880] [client 91.192.10.101:39078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koidomino.click.mbm.udi.temporary.site"] [uri "/.env"] [unique_id "amuxGO_ioCvBERk4wq9suwAAAXE"]
[Thu Jul 30 15:16:24.753299 2026] [security2:error] [pid 147647:tid 147782] [client 91.192.10.101:39140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koidomino.click.mbm.udi.temporary.site"] [uri "/api/.env"] [unique_id "amuxGO_ioCvBERk4wq9szAAAAQ8"]
[Thu Jul 30 15:16:24.878143 2026] [security2:error] [pid 147647:tid 147888] [client 91.192.10.101:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "koidomino.click.mbm.udi.temporary.site"] [uri "/backend/.env"] [unique_id "amuxGO_ioCvBERk4wq9szwAAAXk"]
[Thu Jul 30 15:16:25.259323 2026] [core:notice] [pid 147647:tid 147816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:25.263572 2026] [security2:error] [pid 147647:tid 147816] [client 66.249.79.8:60190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/view/1753"] [unique_id "amuxGe_ioCvBERk4wq9s3QAAATE"]
[Thu Jul 30 15:16:26.346849 2026] [security2:error] [pid 147647:tid 147814] [client 20.100.187.246:43581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/c/flower.php"] [unique_id "amuxGu_ioCvBERk4wq9s9AAAAS8"]
[Thu Jul 30 15:16:26.680672 2026] [core:error] [pid 147647:tid 147688] [remote 74.7.230.9:40964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:16:26.680697 2026] [core:error] [pid 147647:tid 147688] [remote 74.7.230.9:40964] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:16:26.680870 2026] [security2:error] [pid 147647:tid 147872] [client 74.7.230.9:40964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "chicago-mfg.com"] [uri "/index.php"] [unique_id "amuxGu_ioCvBERk4wq9s_wABaSg"]
[Thu Jul 30 15:16:26.965042 2026] [core:notice] [pid 147647:tid 147686] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:27.471186 2026] [security2:error] [pid 147647:tid 147901] [client 172.237.109.114:39548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxGu_ioCvBERk4wq9tAgAAAYY"]
[Thu Jul 30 15:16:28.239804 2026] [security2:error] [pid 147647:tid 147896] [client 20.100.187.246:8955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/c/xleet.php"] [unique_id "amuxHO_ioCvBERk4wq9tJAAAAYE"]
[Thu Jul 30 15:16:28.881110 2026] [security2:error] [pid 147647:tid 147891] [client 178.156.185.127:25566] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuxG-_ioCvBERk4wq9tDwAAAXw"], referer: https://globalmarks.pk/
[Thu Jul 30 15:16:28.972426 2026] [security2:error] [pid 147647:tid 147709] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxHO_ioCvBERk4wq9tMwABMz0"]
[Thu Jul 30 15:16:28.972571 2026] [security2:error] [pid 147647:tid 147818] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxHO_ioCvBERk4wq9tMwABMz0"]
[Thu Jul 30 15:16:29.311595 2026] [security2:error] [pid 147647:tid 147812] [client 57.141.0.39:22662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuxHO_ioCvBERk4wq9tMgABLTw"], referer: https://igetvape-australia.com/product/iget-moon-pineapple-grape-ice/
[Thu Jul 30 15:16:29.636831 2026] [security2:error] [pid 147647:tid 147883] [client 20.100.187.246:23508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/classwithtostring.php"] [unique_id "amuxHe_ioCvBERk4wq9tQQAAAXQ"]
[Thu Jul 30 15:16:29.737259 2026] [core:notice] [pid 147647:tid 147716] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:30.245900 2026] [security2:error] [pid 147647:tid 147719] [remote 216.73.216.51:34696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuxHu_ioCvBERk4wq9tTQABTEc"]
[Thu Jul 30 15:16:30.389556 2026] [security2:error] [pid 147647:tid 147863] [client 213.152.161.170:52030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuxHu_ioCvBERk4wq9tVAAAAWA"]
[Thu Jul 30 15:16:30.389646 2026] [security2:error] [pid 147647:tid 147863] [client 213.152.161.170:52030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuxHu_ioCvBERk4wq9tVAAAAWA"]
[Thu Jul 30 15:16:30.839257 2026] [security2:error] [pid 147647:tid 147836] [client 20.100.187.246:21860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/content.php"] [unique_id "amuxHu_ioCvBERk4wq9tYAAAAUU"]
[Thu Jul 30 15:16:31.281317 2026] [security2:error] [pid 147647:tid 147872] [client 47.128.25.72:58850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kayomanis.com"] [uri "/robots.txt"] [unique_id "amuxH-_ioCvBERk4wq9tZAAAAWk"]
[Thu Jul 30 15:16:31.446685 2026] [security2:error] [pid 147647:tid 147788] [client 17.246.15.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuxH-_ioCvBERk4wq9tZwAAARU"]
[Thu Jul 30 15:16:32.630777 2026] [core:notice] [pid 147647:tid 147800] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:33.941726 2026] [security2:error] [pid 147647:tid 147891] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxIe_ioCvBERk4wq9tlwAAAXw"]
[Thu Jul 30 15:16:34.277625 2026] [security2:error] [pid 147647:tid 147875] [client 20.100.187.246:14195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/doc.php"] [unique_id "amuxIu_ioCvBERk4wq9tqwAAAWw"]
[Thu Jul 30 15:16:34.347297 2026] [core:notice] [pid 147647:tid 147792] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:34.350766 2026] [security2:error] [pid 147647:tid 147792] [client 66.249.79.8:56839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/ELTERA/article/view/3969/1977"] [unique_id "amuxIu_ioCvBERk4wq9trgAAARk"]
[Thu Jul 30 15:16:34.560425 2026] [core:notice] [pid 147647:tid 147752] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:35.795505 2026] [security2:error] [pid 147647:tid 147835] [client 74.7.244.29:55014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "388iendd.site"] [uri "/robots.txt"] [unique_id "amuxI-_ioCvBERk4wq9tygAAAUQ"]
[Thu Jul 30 15:16:36.287468 2026] [security2:error] [pid 147647:tid 147766] [remote 57.141.0.5:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuxJO_ioCvBERk4wq9t2AABUXY"]
[Thu Jul 30 15:16:36.497591 2026] [security2:error] [pid 147647:tid 147887] [client 172.237.109.114:42435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxI-_ioCvBERk4wq9t0gAAAXg"]
[Thu Jul 30 15:16:36.532303 2026] [security2:error] [pid 147647:tid 147858] [client 47.128.121.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuxJO_ioCvBERk4wq9t2wAAAVs"]
[Thu Jul 30 15:16:38.693817 2026] [security2:error] [pid 147647:tid 147845] [client 20.100.187.246:21855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/dropdown.php"] [unique_id "amuxJu_ioCvBERk4wq9uDwAAAU4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 15:16:39.277442 2026] [core:notice] [pid 147647:tid 147812] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:39.280862 2026] [security2:error] [pid 147647:tid 147812] [client 66.249.74.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/113"] [unique_id "amuxJ-_ioCvBERk4wq9uGwAAAS0"]
[Thu Jul 30 15:16:39.300125 2026] [security2:error] [pid 147647:tid 147804] [client 66.249.73.66:35974] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/robots.txt"] [unique_id "amuxJ-_ioCvBERk4wq9uJgAAASU"]
[Thu Jul 30 15:16:39.428391 2026] [security2:error] [pid 147647:tid 147797] [client 20.100.187.246:23491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/ee.php"] [unique_id "amuxJ-_ioCvBERk4wq9uKgAAAR4"]
[Thu Jul 30 15:16:39.526101 2026] [security2:error] [pid 147647:tid 147875] [client 213.152.161.170:56744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuxJ-_ioCvBERk4wq9uKwAAAWw"]
[Thu Jul 30 15:16:39.526204 2026] [security2:error] [pid 147647:tid 147875] [client 213.152.161.170:56744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuxJ-_ioCvBERk4wq9uKwAAAWw"]
[Thu Jul 30 15:16:39.543169 2026] [security2:error] [pid 147647:tid 147663] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxJ-_ioCvBERk4wq9uLgABIg8"]
[Thu Jul 30 15:16:39.543348 2026] [security2:error] [pid 147647:tid 147801] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxJ-_ioCvBERk4wq9uLgABIg8"]
[Thu Jul 30 15:16:39.778227 2026] [proxy:error] [pid 147647:tid 147902] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:16:39.778296 2026] [proxy_http:error] [pid 147647:tid 147902] [client 98.87.102.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:16:39.778954 2026] [proxy:error] [pid 147647:tid 147902] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:16:39.779015 2026] [proxy_http:error] [pid 147647:tid 147902] [client 98.87.102.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:16:39.798965 2026] [proxy:error] [pid 147647:tid 147798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:16:39.799032 2026] [proxy_http:error] [pid 147647:tid 147798] [client 18.211.55.47:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:16:39.799611 2026] [proxy:error] [pid 147647:tid 147798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:16:39.799653 2026] [proxy_http:error] [pid 147647:tid 147798] [client 18.211.55.47:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:16:39.846652 2026] [security2:error] [pid 147647:tid 147890] [client 66.249.65.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxJ-_ioCvBERk4wq9uJQAAAXs"]
[Thu Jul 30 15:16:40.092920 2026] [security2:error] [pid 147647:tid 147794] [client 66.249.73.64:65407] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "shop-peace.com"] [uri "/hello-world/"] [unique_id "amuxKO_ioCvBERk4wq9uPAAAARs"]
[Thu Jul 30 15:16:40.235341 2026] [security2:error] [pid 147647:tid 147810] [client 20.100.187.246:14199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/flower.php"] [unique_id "amuxKO_ioCvBERk4wq9uQQAAASs"]
[Thu Jul 30 15:16:40.891181 2026] [core:notice] [pid 147647:tid 147844] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:41.915947 2026] [security2:error] [pid 147647:tid 147682] [remote 57.141.0.54:32030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amuxKe_ioCvBERk4wq9uagABeiI"]
[Thu Jul 30 15:16:42.009256 2026] [security2:error] [pid 147647:tid 147681] [remote 57.141.0.54:32046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amuxKu_ioCvBERk4wq9uawABGSE"]
[Thu Jul 30 15:16:42.020907 2026] [core:notice] [pid 147647:tid 147872] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:42.025429 2026] [security2:error] [pid 147647:tid 147872] [client 66.249.79.230:61289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/download/4146/2077"] [unique_id "amuxKe_ioCvBERk4wq9uZgAAAWk"]
[Thu Jul 30 15:16:42.259883 2026] [security2:error] [pid 147647:tid 147893] [client 20.100.187.246:14179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/gecko-new.php"] [unique_id "amuxKu_ioCvBERk4wq9ucgAAAX4"]
[Thu Jul 30 15:16:42.913564 2026] [security2:error] [pid 147647:tid 147849] [client 20.100.187.246:21887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/m.php"] [unique_id "amuxKu_ioCvBERk4wq9ufwAAAVI"]
[Thu Jul 30 15:16:43.193942 2026] [security2:error] [pid 147647:tid 147851] [client 167.172.139.96:52497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "arabiandubaisafari.com"] [uri "/wp-json/batch/v1"] [unique_id "amuxK-_ioCvBERk4wq9uggAAAVQ"]
[Thu Jul 30 15:16:43.503084 2026] [security2:error] [pid 147647:tid 147813] [client 172.237.109.114:7915] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxK-_ioCvBERk4wq9ugAAAAS4"]
[Thu Jul 30 15:16:43.584181 2026] [security2:error] [pid 147647:tid 147853] [client 167.172.139.96:52508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "arabiandubaisafari.com"] [uri "/"] [unique_id "amuxK-_ioCvBERk4wq9ujAAAAVY"]
[Thu Jul 30 15:16:43.963292 2026] [security2:error] [pid 147647:tid 147861] [client 167.172.139.96:52516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "arabiandubaisafari.com"] [uri "/wp-json/batch/v1"] [unique_id "amuxK-_ioCvBERk4wq9umQAAAV4"]
[Thu Jul 30 15:16:44.134640 2026] [security2:error] [pid 147647:tid 147858] [client 82.102.27.163:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuxLO_ioCvBERk4wq9umgAAAVs"]
[Thu Jul 30 15:16:44.134754 2026] [security2:error] [pid 147647:tid 147858] [client 82.102.27.163:54382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuxLO_ioCvBERk4wq9umgAAAVs"]
[Thu Jul 30 15:16:44.657754 2026] [security2:error] [pid 147647:tid 147696] [remote 57.141.0.50:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/63798190810/feed/rss2/"] [unique_id "amuxLO_ioCvBERk4wq9upAABhjA"]
[Thu Jul 30 15:16:44.821355 2026] [security2:error] [pid 147647:tid 147801] [client 20.100.187.246:21841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amuxLO_ioCvBERk4wq9uqAAAASI"]
[Thu Jul 30 15:16:45.484062 2026] [security2:error] [pid 147647:tid 147781] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxLO_ioCvBERk4wq9urgAAAQ4"]
[Thu Jul 30 15:16:45.671103 2026] [security2:error] [pid 147647:tid 147826] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxLe_ioCvBERk4wq9utAAAATs"]
[Thu Jul 30 15:16:45.671112 2026] [core:notice] [pid 147647:tid 147854] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:46.239947 2026] [security2:error] [pid 147647:tid 147867] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxLe_ioCvBERk4wq9uxQAAAWQ"]
[Thu Jul 30 15:16:46.352724 2026] [security2:error] [pid 147647:tid 147830] [client 20.100.187.246:23542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mah/flower.php"] [unique_id "amuxLu_ioCvBERk4wq9u1AAAAT8"]
[Thu Jul 30 15:16:46.616476 2026] [core:notice] [pid 147647:tid 147777] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:47.163636 2026] [security2:error] [pid 147647:tid 147779] [client 20.100.187.246:14157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mah/xleet.php"] [unique_id "amuxL-_ioCvBERk4wq9u5QAAAQw"]
[Thu Jul 30 15:16:47.280930 2026] [core:notice] [pid 147647:tid 147715] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:47.284653 2026] [security2:error] [pid 147647:tid 147797] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/252/252"] [unique_id "amuxL-_ioCvBERk4wq9u5AABHkM"]
[Thu Jul 30 15:16:47.972912 2026] [security2:error] [pid 147647:tid 147811] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxL-_ioCvBERk4wq9u6wAAASw"]
[Thu Jul 30 15:16:48.669337 2026] [security2:error] [pid 147647:tid 147791] [client 66.249.93.2:41034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuxMO_ioCvBERk4wq9u_AAAARg"]
[Thu Jul 30 15:16:49.669592 2026] [security2:error] [pid 147647:tid 147853] [client 20.100.187.246:14169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/mini.php"] [unique_id "amuxMe_ioCvBERk4wq9vHQAAAVY"]
[Thu Jul 30 15:16:50.207672 2026] [security2:error] [pid 147647:tid 147740] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxMu_ioCvBERk4wq9vKgABelw"]
[Thu Jul 30 15:16:50.207884 2026] [security2:error] [pid 147647:tid 147889] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxMu_ioCvBERk4wq9vKgABelw"]
[Thu Jul 30 15:16:50.407130 2026] [core:notice] [pid 147647:tid 147779] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:50.857403 2026] [core:notice] [pid 147647:tid 147747] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:51.888286 2026] [security2:error] [pid 147647:tid 147871] [client 159.203.182.119:46892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuxM-_ioCvBERk4wq9vUAAAAWg"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:16:51.890234 2026] [security2:error] [pid 147647:tid 147828] [client 112.86.225.111:36898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/louis-vuitton-slippers-26/"] [unique_id "amuxM-_ioCvBERk4wq9vVAAAAT0"]
[Thu Jul 30 15:16:51.890328 2026] [security2:error] [pid 147647:tid 147828] [client 112.86.225.111:36898] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/louis-vuitton-slippers-26/"] [unique_id "amuxM-_ioCvBERk4wq9vVAAAAT0"]
[Thu Jul 30 15:16:52.884271 2026] [security2:error] [pid 147647:tid 147895] [client 158.158.41.78:9398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wk/index.php"] [unique_id "amuxNO_ioCvBERk4wq9vZwAAAYA"]
[Thu Jul 30 15:16:52.985418 2026] [security2:error] [pid 147647:tid 147762] [remote 57.141.0.47:52602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amuxNO_ioCvBERk4wq9vawABHHI"]
[Thu Jul 30 15:16:53.010355 2026] [security2:error] [pid 147647:tid 147786] [client 20.100.187.246:14520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/moon.php"] [unique_id "amuxNe_ioCvBERk4wq9vbAAAARM"]
[Thu Jul 30 15:16:53.641513 2026] [security2:error] [pid 147647:tid 147809] [client 172.237.109.114:36616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxNe_ioCvBERk4wq9vbQAAASo"]
[Thu Jul 30 15:16:53.661916 2026] [security2:error] [pid 147647:tid 147803] [client 159.203.182.119:46896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuxNe_ioCvBERk4wq9vdAAAASQ"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:16:54.525046 2026] [security2:error] [pid 147647:tid 147829] [client 20.100.187.246:14154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/new.php"] [unique_id "amuxNu_ioCvBERk4wq9vjwAAAT4"]
[Thu Jul 30 15:16:55.025865 2026] [security2:error] [pid 147647:tid 147648] [remote 212.80.9.235:57856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mshandco.org"] [uri "/wp-login.php"] [unique_id "amuxN-_ioCvBERk4wq9vmAABPwA"]
[Thu Jul 30 15:16:55.210329 2026] [security2:error] [pid 147647:tid 147815] [client 2a03:2880:f800:3:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxNu_ioCvBERk4wq9vkAABMH0"]
[Thu Jul 30 15:16:55.437550 2026] [core:notice] [pid 147647:tid 147804] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:55.652690 2026] [security2:error] [pid 147647:tid 147821] [client 158.158.41.78:16904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/av.php"] [unique_id "amuxN-_ioCvBERk4wq9vqwAAATY"]
[Thu Jul 30 15:16:55.821896 2026] [security2:error] [pid 147647:tid 147840] [client 79.116.226.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "palmtreepools.ca"] [uri "/index.php"] [unique_id "amuxNu_ioCvBERk4wq9vgQAAAUk"]
[Thu Jul 30 15:16:56.313302 2026] [core:notice] [pid 147647:tid 147657] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:56.736842 2026] [security2:error] [pid 147647:tid 147823] [client 20.100.187.246:23528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/radio.php"] [unique_id "amuxOO_ioCvBERk4wq9vxQAAATg"]
[Thu Jul 30 15:16:56.953753 2026] [core:notice] [pid 147647:tid 147877] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:56.957027 2026] [security2:error] [pid 147647:tid 147889] [client 50.61.197.56:60612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuxOO_ioCvBERk4wq9vxAAAAXo"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:16:56.957167 2026] [security2:error] [pid 147647:tid 147877] [client 66.249.79.8:58047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/1048/3620"] [unique_id "amuxOO_ioCvBERk4wq9vygAAAW4"]
[Thu Jul 30 15:16:57.772512 2026] [core:notice] [pid 147647:tid 147837] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:57.776011 2026] [security2:error] [pid 147647:tid 147837] [client 66.249.79.8:58047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Euclid/article/download/3122/2111"] [unique_id "amuxOe_ioCvBERk4wq9v3wAAAUY"]
[Thu Jul 30 15:16:58.240390 2026] [security2:error] [pid 147647:tid 147890] [client 158.158.41.78:17372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/mini.php"] [unique_id "amuxOu_ioCvBERk4wq9v8AAAAXs"]
[Thu Jul 30 15:16:58.510264 2026] [security2:error] [pid 147647:tid 147809] [client 20.100.187.246:14474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/s.php"] [unique_id "amuxOu_ioCvBERk4wq9v-AAAASo"]
[Thu Jul 30 15:16:58.575677 2026] [security2:error] [pid 147647:tid 147685] [remote 74.7.243.224:38432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/job.php"] [unique_id "amuxOu_ioCvBERk4wq9v-gABYiU"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/article.php?id=27
[Thu Jul 30 15:16:59.551073 2026] [core:notice] [pid 147647:tid 147783] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:16:59.780878 2026] [security2:error] [pid 147647:tid 147839] [client 20.100.187.246:21835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/sim.php"] [unique_id "amuxO-_ioCvBERk4wq9wJQAAAUg"]
[Thu Jul 30 15:17:00.577352 2026] [autoindex:error] [pid 147647:tid 147810] [client 43.159.136.201:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.otbola.click
[Thu Jul 30 15:17:00.912669 2026] [security2:error] [pid 147647:tid 147811] [client 20.100.187.246:23540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/text.php"] [unique_id "amuxPO_ioCvBERk4wq9wPgAAASw"]
[Thu Jul 30 15:17:00.935986 2026] [security2:error] [pid 147647:tid 147724] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxPO_ioCvBERk4wq9wPwABQUw"]
[Thu Jul 30 15:17:00.936168 2026] [security2:error] [pid 147647:tid 147832] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxPO_ioCvBERk4wq9wPwABQUw"]
[Thu Jul 30 15:17:01.526861 2026] [security2:error] [pid 147647:tid 147866] [client 158.158.41.78:16898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/aa.php"] [unique_id "amuxPe_ioCvBERk4wq9wUAAAAWM"]
[Thu Jul 30 15:17:01.566267 2026] [core:error] [pid 147647:tid 147732] [remote 216.73.217.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:01.566302 2026] [core:error] [pid 147647:tid 147732] [remote 216.73.217.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:01.922433 2026] [core:notice] [pid 147647:tid 147790] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:01.936924 2026] [security2:error] [pid 147647:tid 147813] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxPe_ioCvBERk4wq9wTAAAAS4"]
[Thu Jul 30 15:17:02.050174 2026] [security2:error] [pid 147647:tid 147899] [client 49.36.189.179:40472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuxPe_ioCvBERk4wq9wXQAAAYQ"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:17:02.153330 2026] [security2:error] [pid 147647:tid 147877] [client 20.100.187.246:8929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/user.php"] [unique_id "amuxPu_ioCvBERk4wq9wagAAAW4"]
[Thu Jul 30 15:17:02.201286 2026] [core:error] [pid 147647:tid 147726] [remote 216.73.217.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:02.201315 2026] [core:error] [pid 147647:tid 147726] [remote 216.73.217.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:02.523158 2026] [core:notice] [pid 147647:tid 147838] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:02.760896 2026] [security2:error] [pid 147647:tid 147747] [remote 111.225.148.65:36936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/ar/products-services/innovation-defense-technologies/innovation-sustainability/"] [unique_id "amuxPu_ioCvBERk4wq9wegABH2M"]
[Thu Jul 30 15:17:02.904120 2026] [security2:error] [pid 147647:tid 147893] [client 20.100.187.246:43579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/webadmin.php"] [unique_id "amuxPu_ioCvBERk4wq9wewAAAX4"]
[Thu Jul 30 15:17:03.328947 2026] [security2:error] [pid 147647:tid 147841] [client 167.99.43.221:47236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuxP-_ioCvBERk4wq9wggAAAUo"], referer: http://happyspree.app/
[Thu Jul 30 15:17:03.332899 2026] [core:notice] [pid 147647:tid 147748] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:04.043795 2026] [security2:error] [pid 147647:tid 147814] [client 20.100.187.246:43533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amuxQO_ioCvBERk4wq9wmAAAAS8"]
[Thu Jul 30 15:17:04.903909 2026] [security2:error] [pid 147647:tid 147895] [client 20.100.187.246:8906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amuxQO_ioCvBERk4wq9wtAAAAYA"]
[Thu Jul 30 15:17:04.931807 2026] [core:notice] [pid 147647:tid 147900] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:05.429198 2026] [proxy:error] [pid 147647:tid 147765] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:17:05.429257 2026] [proxy_http:error] [pid 147647:tid 147765] [remote 74.7.244.49:36822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:17:05.430194 2026] [proxy:error] [pid 147647:tid 147765] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:17:05.430248 2026] [proxy_http:error] [pid 147647:tid 147765] [remote 74.7.244.49:36822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:17:05.470586 2026] [core:notice] [pid 147647:tid 147877] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:05.604244 2026] [core:notice] [pid 147647:tid 147808] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:05.608145 2026] [security2:error] [pid 147647:tid 147808] [client 66.249.79.1:41224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/2682/1494"] [unique_id "amuxQe_ioCvBERk4wq9wzAAAASk"]
[Thu Jul 30 15:17:05.633116 2026] [security2:error] [pid 147647:tid 147843] [client 172.237.109.114:11993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxQe_ioCvBERk4wq9wvAAAAUw"]
[Thu Jul 30 15:17:05.658507 2026] [security2:error] [pid 147647:tid 147866] [client 88.163.186.252:11566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.186.163.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arabiandubaisafari.com"] [uri "/xmlrpc.php"] [unique_id "amuxQe_ioCvBERk4wq9wyAAAAWM"]
[Thu Jul 30 15:17:05.658641 2026] [security2:error] [pid 147647:tid 147866] [client 88.163.186.252:11566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arabiandubaisafari.com"] [uri "/xmlrpc.php"] [unique_id "amuxQe_ioCvBERk4wq9wyAAAAWM"]
[Thu Jul 30 15:17:06.074343 2026] [security2:error] [pid 147647:tid 147852] [client 20.100.187.246:23504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amuxQu_ioCvBERk4wq9w3AAAAVU"]
[Thu Jul 30 15:17:06.749520 2026] [security2:error] [pid 147647:tid 147803] [client 20.100.187.246:8954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amuxQu_ioCvBERk4wq9w6wAAASQ"]
[Thu Jul 30 15:17:07.346541 2026] [security2:error] [pid 147647:tid 147836] [client 20.100.187.246:14743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amuxQ-_ioCvBERk4wq9w-wAAAUU"]
[Thu Jul 30 15:17:08.031138 2026] [security2:error] [pid 147647:tid 147812] [client 20.100.187.246:14734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amuxRO_ioCvBERk4wq9xDgAAAS0"]
[Thu Jul 30 15:17:08.332248 2026] [security2:error] [pid 147647:tid 147814] [client 185.177.72.53:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuxRO_ioCvBERk4wq9xDwAAAS8"]
[Thu Jul 30 15:17:08.586735 2026] [security2:error] [pid 147647:tid 147788] [client 185.177.72.53:5088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "amuxRO_ioCvBERk4wq9xGgAAARU"]
[Thu Jul 30 15:17:08.835508 2026] [security2:error] [pid 147647:tid 147800] [client 185.177.72.53:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuxRO_ioCvBERk4wq9xHgAAASE"]
[Thu Jul 30 15:17:09.078866 2026] [core:notice] [pid 147647:tid 147792] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:09.083171 2026] [security2:error] [pid 147647:tid 147792] [client 66.249.79.231:41490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/download/5701/2541"] [unique_id "amuxRe_ioCvBERk4wq9xJQAAARk"]
[Thu Jul 30 15:17:09.091060 2026] [security2:error] [pid 147647:tid 147854] [client 185.177.72.53:5096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuxRe_ioCvBERk4wq9xJgAAAVc"]
[Thu Jul 30 15:17:09.357030 2026] [security2:error] [pid 147647:tid 147859] [client 185.177.72.53:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuxRe_ioCvBERk4wq9xKgAAAVw"]
[Thu Jul 30 15:17:09.609835 2026] [security2:error] [pid 147647:tid 147797] [client 185.177.72.53:5106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abs-sa.net"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "amuxRe_ioCvBERk4wq9xMgAAAR4"]
[Thu Jul 30 15:17:11.314425 2026] [core:notice] [pid 147647:tid 147838] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:11.413588 2026] [autoindex:error] [pid 147647:tid 147820] [client 135.181.254.169:45200] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:17:11.526431 2026] [core:notice] [pid 147647:tid 147902] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:12.019692 2026] [core:notice] [pid 147647:tid 147687] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:12.776308 2026] [autoindex:error] [pid 147647:tid 147823] [client 135.181.254.169:59938] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:17:12.891459 2026] [security2:error] [pid 147647:tid 147691] [remote 57.141.0.65:56894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/93381591101/feed/rss2/"] [unique_id "amuxSO_ioCvBERk4wq9xdwABSis"]
[Thu Jul 30 15:17:12.958069 2026] [core:notice] [pid 147647:tid 147846] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:13.383171 2026] [autoindex:error] [pid 147647:tid 147780] [client 135.181.254.169:45202] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:17:14.461799 2026] [security2:error] [pid 147647:tid 147821] [client 172.237.109.114:51327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxSe_ioCvBERk4wq9xjAAAATY"]
[Thu Jul 30 15:17:14.650186 2026] [security2:error] [pid 147647:tid 147837] [client 158.158.41.78:16927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/w.php"] [unique_id "amuxSu_ioCvBERk4wq9xngAAAUY"]
[Thu Jul 30 15:17:14.869040 2026] [security2:error] [pid 147647:tid 147855] [client 157.148.58.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuxSu_ioCvBERk4wq9xpAAAAVg"]
[Thu Jul 30 15:17:15.285814 2026] [core:notice] [pid 147647:tid 147886] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:15.289926 2026] [security2:error] [pid 147647:tid 147886] [client 66.249.79.8:35011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/view/829/1007"] [unique_id "amuxS-_ioCvBERk4wq9xsQAAAXc"]
[Thu Jul 30 15:17:15.351631 2026] [security2:error] [pid 147647:tid 147832] [client 158.158.41.78:15852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/admin.php"] [unique_id "amuxS-_ioCvBERk4wq9xtQAAAUE"]
[Thu Jul 30 15:17:15.469167 2026] [core:notice] [pid 147647:tid 147716] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:15.522794 2026] [core:notice] [pid 147647:tid 147847] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:15.666361 2026] [core:notice] [pid 147647:tid 147801] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:16.502263 2026] [security2:error] [pid 147647:tid 147880] [client 158.158.41.78:26150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/themes/admin.php"] [unique_id "amuxTO_ioCvBERk4wq9x1gAAAXE"]
[Thu Jul 30 15:17:17.508558 2026] [security2:error] [pid 147647:tid 147825] [client 82.102.18.188:52012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuxTe_ioCvBERk4wq9x7wAAATo"]
[Thu Jul 30 15:17:17.675989 2026] [autoindex:error] [pid 147647:tid 147845] [client 43.159.136.201:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.koidomino.click
[Thu Jul 30 15:17:17.903099 2026] [security2:error] [pid 147647:tid 147826] [client 82.102.18.188:52018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuxTe_ioCvBERk4wq9x-wAAATs"]
[Thu Jul 30 15:17:18.170719 2026] [security2:error] [pid 147647:tid 147815] [client 82.102.18.188:52034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuxTu_ioCvBERk4wq9x_QAAATA"]
[Thu Jul 30 15:17:18.235580 2026] [core:notice] [pid 147647:tid 147901] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:18.441426 2026] [security2:error] [pid 147647:tid 147869] [client 82.102.18.188:52038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuxTu_ioCvBERk4wq9yBwAAAWY"]
[Thu Jul 30 15:17:18.618630 2026] [core:notice] [pid 147647:tid 147864] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:18.649653 2026] [core:error] [pid 147647:tid 147731] [remote 216.73.217.106:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:18.649675 2026] [core:error] [pid 147647:tid 147731] [remote 216.73.217.106:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:18.702431 2026] [security2:error] [pid 147647:tid 147799] [client 82.102.18.188:49513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuxTu_ioCvBERk4wq9yDAAAASA"]
[Thu Jul 30 15:17:18.969107 2026] [security2:error] [pid 147647:tid 147840] [client 82.102.18.188:52052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuxTu_ioCvBERk4wq9yFgAAAUk"]
[Thu Jul 30 15:17:19.239330 2026] [security2:error] [pid 147647:tid 147902] [client 82.102.18.188:52056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuxT-_ioCvBERk4wq9yFwAAAYc"]
[Thu Jul 30 15:17:19.442121 2026] [core:notice] [pid 147647:tid 147837] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:19.445060 2026] [security2:error] [pid 147647:tid 147877] [client 20.100.187.246:14551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amuxT-_ioCvBERk4wq9yHwAAAW4"]
[Thu Jul 30 15:17:19.501612 2026] [security2:error] [pid 147647:tid 147857] [client 82.102.18.188:52064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuxT-_ioCvBERk4wq9yIAAAAVo"]
[Thu Jul 30 15:17:19.581047 2026] [security2:error] [pid 147647:tid 147810] [client 158.158.41.78:17397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/m.php"] [unique_id "amuxT-_ioCvBERk4wq9yJAAAASs"]
[Thu Jul 30 15:17:19.769637 2026] [security2:error] [pid 147647:tid 147898] [client 82.102.18.188:52074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuxT-_ioCvBERk4wq9yJgAAAYM"]
[Thu Jul 30 15:17:20.039006 2026] [security2:error] [pid 147647:tid 147845] [client 82.102.18.188:52078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuxUO_ioCvBERk4wq9yMgAAAU4"]
[Thu Jul 30 15:17:20.300870 2026] [security2:error] [pid 147647:tid 147797] [client 20.100.187.246:8914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amuxUO_ioCvBERk4wq9yOgAAAR4"]
[Thu Jul 30 15:17:20.303450 2026] [security2:error] [pid 147647:tid 147867] [client 82.102.18.188:52088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuxUO_ioCvBERk4wq9yOwAAAWQ"]
[Thu Jul 30 15:17:20.818370 2026] [security2:error] [pid 147647:tid 147903] [client 82.102.18.188:52096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuxUO_ioCvBERk4wq9yRgAAAYg"]
[Thu Jul 30 15:17:20.932107 2026] [security2:error] [pid 147647:tid 147881] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxUO_ioCvBERk4wq9yOQAAAXI"]
[Thu Jul 30 15:17:21.097602 2026] [security2:error] [pid 147647:tid 147880] [client 82.102.18.188:52108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuxUe_ioCvBERk4wq9yVQAAAXE"]
[Thu Jul 30 15:17:21.236237 2026] [core:error] [pid 147647:tid 147782] [client 74.7.241.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:21.236263 2026] [core:error] [pid 147647:tid 147782] [client 74.7.241.132:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:21.236407 2026] [security2:error] [pid 147647:tid 147782] [client 74.7.241.132:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.rru.djb.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuxUe_ioCvBERk4wq9yWAAAAQ8"]
[Thu Jul 30 15:17:21.237020 2026] [security2:error] [pid 147647:tid 147838] [client 74.7.241.132:42490] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.rru.djb.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuxUe_ioCvBERk4wq9yVgABR00"]
[Thu Jul 30 15:17:21.485994 2026] [security2:error] [pid 147647:tid 147794] [client 172.237.109.114:55547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxUe_ioCvBERk4wq9yTwAAARs"]
[Thu Jul 30 15:17:21.867486 2026] [core:notice] [pid 147647:tid 147865] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:22.182077 2026] [security2:error] [pid 147647:tid 147798] [client 20.100.187.246:14533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amuxUu_ioCvBERk4wq9ybwAAAR8"]
[Thu Jul 30 15:17:22.332779 2026] [security2:error] [pid 147647:tid 147868] [client 47.128.34.10:19772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rgserve.ph"] [uri "/robots.txt"] [unique_id "amuxUu_ioCvBERk4wq9ycAAAAWU"]
[Thu Jul 30 15:17:22.372746 2026] [security2:error] [pid 147647:tid 147834] [client 82.102.18.188:52120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuxUu_ioCvBERk4wq9ycQAAAUM"]
[Thu Jul 30 15:17:22.635017 2026] [security2:error] [pid 147647:tid 147761] [remote 74.7.227.39:44294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuxUu_ioCvBERk4wq9yfgABHnE"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/
[Thu Jul 30 15:17:22.635041 2026] [security2:error] [pid 147647:tid 147866] [client 82.102.18.188:52132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.gbq.rty.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuxUu_ioCvBERk4wq9yfQAAAWM"]
[Thu Jul 30 15:17:22.862005 2026] [security2:error] [pid 147647:tid 147901] [client 134.19.179.195:47526] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuxUu_ioCvBERk4wq9yegAAAYY"]
[Thu Jul 30 15:17:22.862105 2026] [security2:error] [pid 147647:tid 147901] [client 134.19.179.195:47526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuxUu_ioCvBERk4wq9yegAAAYY"]
[Thu Jul 30 15:17:23.144558 2026] [security2:error] [pid 147647:tid 147778] [client 40.77.167.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuxUO_ioCvBERk4wq9yNQABC2A"]
[Thu Jul 30 15:17:23.330022 2026] [security2:error] [pid 147647:tid 147784] [client 158.158.41.78:26163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuxU-_ioCvBERk4wq9yjgAAARE"]
[Thu Jul 30 15:17:24.309673 2026] [security2:error] [pid 147647:tid 147884] [client 20.100.187.246:14546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amuxVO_ioCvBERk4wq9yqgAAAXU"]
[Thu Jul 30 15:17:24.662030 2026] [security2:error] [pid 147647:tid 147886] [client 134.19.179.195:35506] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuxVO_ioCvBERk4wq9ysQAAAXc"]
[Thu Jul 30 15:17:24.662122 2026] [security2:error] [pid 147647:tid 147886] [client 134.19.179.195:35506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuxVO_ioCvBERk4wq9ysQAAAXc"]
[Thu Jul 30 15:17:24.926035 2026] [security2:error] [pid 147647:tid 147868] [client 20.100.187.246:20869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/flower.php"] [unique_id "amuxVO_ioCvBERk4wq9yuAAAAWU"]
[Thu Jul 30 15:17:25.020590 2026] [core:notice] [pid 147647:tid 147867] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:25.311731 2026] [autoindex:error] [pid 147647:tid 147863] [client 158.158.41.78:24603] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:17:25.443589 2026] [security2:error] [pid 147647:tid 147869] [client 158.158.41.78:24603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/classwithtostring.php"] [unique_id "amuxVe_ioCvBERk4wq9yxAAAAWY"]
[Thu Jul 30 15:17:25.658634 2026] [security2:error] [pid 147647:tid 147875] [client 20.100.187.246:11505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amuxVe_ioCvBERk4wq9yyAAAAWw"]
[Thu Jul 30 15:17:26.072001 2026] [security2:error] [pid 147647:tid 147806] [client 158.158.41.78:33304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/gmo.php"] [unique_id "amuxVu_ioCvBERk4wq9y2gAAASc"]
[Thu Jul 30 15:17:26.303381 2026] [security2:error] [pid 147647:tid 147670] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxVu_ioCvBERk4wq9y5QABDxY"]
[Thu Jul 30 15:17:26.303566 2026] [security2:error] [pid 147647:tid 147782] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxVu_ioCvBERk4wq9y5QABDxY"]
[Thu Jul 30 15:17:26.348897 2026] [security2:error] [pid 147647:tid 147805] [client 134.19.179.195:47534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuxVu_ioCvBERk4wq9y6QAAASY"]
[Thu Jul 30 15:17:26.349019 2026] [security2:error] [pid 147647:tid 147805] [client 134.19.179.195:47534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuxVu_ioCvBERk4wq9y6QAAASY"]
[Thu Jul 30 15:17:26.489553 2026] [core:notice] [pid 147647:tid 147792] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:26.555760 2026] [security2:error] [pid 147647:tid 147865] [client 158.158.41.78:16935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/languages/index.php"] [unique_id "amuxVu_ioCvBERk4wq9y7AAAAWI"]
[Thu Jul 30 15:17:26.651904 2026] [core:notice] [pid 147647:tid 147811] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:26.668240 2026] [security2:error] [pid 147647:tid 147810] [client 20.100.187.246:14584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amuxVu_ioCvBERk4wq9y8QAAASs"]
[Thu Jul 30 15:17:27.606502 2026] [security2:error] [pid 147647:tid 147862] [client 91.192.10.101:43462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mails.moswey.com"] [uri "/.env"] [unique_id "amuxV-_ioCvBERk4wq9zBwAAAV8"]
[Thu Jul 30 15:17:27.655879 2026] [security2:error] [pid 147647:tid 147903] [client 20.100.187.246:16743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amuxV-_ioCvBERk4wq9zCQAAAYg"]
[Thu Jul 30 15:17:27.801272 2026] [security2:error] [pid 147647:tid 147678] [remote 111.225.149.169:18764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/ar/articles/"] [unique_id "amuxV-_ioCvBERk4wq9zEQABOR4"]
[Thu Jul 30 15:17:27.860964 2026] [security2:error] [pid 147647:tid 147868] [client 158.158.41.78:26168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-the.php"] [unique_id "amuxV-_ioCvBERk4wq9zFQAAAWU"]
[Thu Jul 30 15:17:28.011262 2026] [core:notice] [pid 147647:tid 147831] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:28.015887 2026] [security2:error] [pid 147647:tid 147831] [client 66.249.79.229:38826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Caruban/article/view/5322/2507"] [unique_id "amuxV-_ioCvBERk4wq9zDwAAAUA"]
[Thu Jul 30 15:17:28.056511 2026] [core:notice] [pid 147647:tid 147888] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:28.062855 2026] [security2:error] [pid 147647:tid 147896] [client 91.192.10.101:40664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mails.moswey.com"] [uri "/backend/.env"] [unique_id "amuxWO_ioCvBERk4wq9zHwAAAYE"]
[Thu Jul 30 15:17:28.152579 2026] [security2:error] [pid 147647:tid 147894] [client 91.192.10.101:43462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mails.moswey.com"] [uri "/api/.env"] [unique_id "amuxWO_ioCvBERk4wq9zIQAAAX8"]
[Thu Jul 30 15:17:28.995059 2026] [security2:error] [pid 147647:tid 147853] [client 213.152.161.133:50248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuxWO_ioCvBERk4wq9zRAAAAVY"]
[Thu Jul 30 15:17:28.995170 2026] [security2:error] [pid 147647:tid 147853] [client 213.152.161.133:50248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuxWO_ioCvBERk4wq9zRAAAAVY"]
[Thu Jul 30 15:17:29.171252 2026] [security2:error] [pid 147647:tid 147837] [client 158.158.41.78:9672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/404.php"] [unique_id "amuxWe_ioCvBERk4wq9zRgAAAUY"]
[Thu Jul 30 15:17:29.941350 2026] [security2:error] [pid 147647:tid 147825] [client 20.100.187.246:14156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amuxWe_ioCvBERk4wq9zWAAAATo"]
[Thu Jul 30 15:17:30.555066 2026] [security2:error] [pid 147647:tid 147880] [client 158.158.41.78:16900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/init.php"] [unique_id "amuxWu_ioCvBERk4wq9zYwAAAXE"]
[Thu Jul 30 15:17:30.753403 2026] [core:error] [pid 147647:tid 147884] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:30.753438 2026] [core:error] [pid 147647:tid 147884] [client 74.7.228.63:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:30.753587 2026] [security2:error] [pid 147647:tid 147884] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.nco.zzt.temporary.site"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "amuxWu_ioCvBERk4wq9zaQAAAXU"]
[Thu Jul 30 15:17:30.754230 2026] [security2:error] [pid 147647:tid 147895] [client 74.7.228.63:44884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.nco.zzt.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuxWu_ioCvBERk4wq9zZwABgDY"]
[Thu Jul 30 15:17:30.873296 2026] [security2:error] [pid 147647:tid 147876] [client 20.100.187.246:9372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amuxWu_ioCvBERk4wq9zbQAAAW0"]
[Thu Jul 30 15:17:31.233069 2026] [security2:error] [pid 147647:tid 147864] [client 158.158.41.78:17400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/file5.php"] [unique_id "amuxW-_ioCvBERk4wq9zdQAAAWE"]
[Thu Jul 30 15:17:31.368132 2026] [core:notice] [pid 147647:tid 147867] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:31.371590 2026] [security2:error] [pid 147647:tid 147867] [client 66.249.79.229:38826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3818"] [unique_id "amuxW-_ioCvBERk4wq9zeQAAAWQ"]
[Thu Jul 30 15:17:32.358291 2026] [security2:error] [pid 147647:tid 147825] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuxXO_ioCvBERk4wq9zjgAAATo"]
[Thu Jul 30 15:17:32.433562 2026] [security2:error] [pid 147647:tid 147790] [client 158.158.41.78:9698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/maint/index.php"] [unique_id "amuxXO_ioCvBERk4wq9zjwAAARc"]
[Thu Jul 30 15:17:32.532084 2026] [security2:error] [pid 147647:tid 147882] [client 2a03:2880:f800:a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxW-_ioCvBERk4wq9zhAABcz0"]
[Thu Jul 30 15:17:32.557612 2026] [security2:error] [pid 147647:tid 147826] [client 45.94.31.73:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.31.94.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.koinjp189.com"] [uri "/xmlrpc.php"] [unique_id "amuxXO_ioCvBERk4wq9zkwAAATs"]
[Thu Jul 30 15:17:32.845902 2026] [security2:error] [pid 147647:tid 147893] [client 20.100.187.246:11458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amuxXO_ioCvBERk4wq9zmwAAAX4"]
[Thu Jul 30 15:17:33.236723 2026] [security2:error] [pid 147647:tid 147724] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxXe_ioCvBERk4wq9zpgABJEw"]
[Thu Jul 30 15:17:33.236919 2026] [security2:error] [pid 147647:tid 147803] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxXe_ioCvBERk4wq9zpgABJEw"]
[Thu Jul 30 15:17:33.717173 2026] [security2:error] [pid 147647:tid 147889] [client 158.158.41.78:24577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/shell.php"] [unique_id "amuxXe_ioCvBERk4wq9zsAAAAXo"]
[Thu Jul 30 15:17:34.187766 2026] [security2:error] [pid 147647:tid 147787] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuxXu_ioCvBERk4wq9zvAAAARQ"]
[Thu Jul 30 15:17:34.370650 2026] [security2:error] [pid 147647:tid 147796] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuxXu_ioCvBERk4wq9zvgAAAR0"]
[Thu Jul 30 15:17:34.681941 2026] [core:notice] [pid 147647:tid 147831] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:34.725121 2026] [security2:error] [pid 147647:tid 147794] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuxXu_ioCvBERk4wq9z0AAAARs"]
[Thu Jul 30 15:17:34.879291 2026] [security2:error] [pid 147647:tid 147817] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxXu_ioCvBERk4wq9zyAAAATI"]
[Thu Jul 30 15:17:35.089863 2026] [security2:error] [pid 147647:tid 147845] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuxX-_ioCvBERk4wq9z0wAAAU4"]
[Thu Jul 30 15:17:35.148820 2026] [core:notice] [pid 147647:tid 147884] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:35.249318 2026] [security2:error] [pid 147647:tid 147726] [remote 144.79.133.30:36390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuxX-_ioCvBERk4wq9z5wABak4"]
[Thu Jul 30 15:17:35.260494 2026] [core:notice] [pid 147647:tid 147843] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:35.263962 2026] [security2:error] [pid 147647:tid 147843] [client 66.249.79.229:38826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/8342"] [unique_id "amuxX-_ioCvBERk4wq9z6AAAAUw"]
[Thu Jul 30 15:17:35.476195 2026] [security2:error] [pid 147647:tid 147787] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuxX-_ioCvBERk4wq9z7QAAARQ"]
[Thu Jul 30 15:17:35.770509 2026] [security2:error] [pid 147647:tid 147742] [remote 216.73.216.51:12424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuxX-_ioCvBERk4wq9z9wABVV4"]
[Thu Jul 30 15:17:35.875231 2026] [security2:error] [pid 147647:tid 147806] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuxX-_ioCvBERk4wq9z-wAAASc"]
[Thu Jul 30 15:17:36.300845 2026] [security2:error] [pid 147647:tid 147886] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuxYO_ioCvBERk4wq90CwAAAXc"]
[Thu Jul 30 15:17:36.459342 2026] [security2:error] [pid 147647:tid 147865] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxYO_ioCvBERk4wq90BwAAAWI"]
[Thu Jul 30 15:17:36.670782 2026] [security2:error] [pid 147647:tid 147840] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuxYO_ioCvBERk4wq90GQAAAUk"]
[Thu Jul 30 15:17:36.983081 2026] [security2:error] [pid 147647:tid 147848] [client 20.100.187.246:11473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amuxYO_ioCvBERk4wq90IgAAAVE"]
[Thu Jul 30 15:17:37.049129 2026] [security2:error] [pid 147647:tid 147807] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuxYe_ioCvBERk4wq90IwAAASg"]
[Thu Jul 30 15:17:37.408522 2026] [security2:error] [pid 147647:tid 147813] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuxYe_ioCvBERk4wq90LQAAAS4"]
[Thu Jul 30 15:17:37.646162 2026] [core:notice] [pid 147647:tid 147871] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:37.798008 2026] [security2:error] [pid 147647:tid 147894] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuxYe_ioCvBERk4wq90MgAAAX8"]
[Thu Jul 30 15:17:38.035360 2026] [security2:error] [pid 147647:tid 147778] [client 20.100.187.246:11486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amuxYu_ioCvBERk4wq90PQAAAQs"]
[Thu Jul 30 15:17:38.149770 2026] [security2:error] [pid 147647:tid 147875] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuxYu_ioCvBERk4wq90PgAAAWw"]
[Thu Jul 30 15:17:38.498749 2026] [security2:error] [pid 147647:tid 147883] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuxYu_ioCvBERk4wq90SQAAAXQ"]
[Thu Jul 30 15:17:38.717326 2026] [security2:error] [pid 147647:tid 147890] [client 20.100.187.246:14565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amuxYu_ioCvBERk4wq90SgAAAXs"]
[Thu Jul 30 15:17:38.719086 2026] [security2:error] [pid 147647:tid 147768] [remote 57.141.0.3:61248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuxYu_ioCvBERk4wq90SwABang"]
[Thu Jul 30 15:17:38.882319 2026] [security2:error] [pid 147647:tid 147828] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuxYu_ioCvBERk4wq90TwAAAT0"]
[Thu Jul 30 15:17:38.983648 2026] [security2:error] [pid 147647:tid 147892] [client 82.102.18.188:58694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alseermarine.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuxYu_ioCvBERk4wq90VwAAAX0"]
[Thu Jul 30 15:17:39.282781 2026] [security2:error] [pid 147647:tid 147823] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuxY-_ioCvBERk4wq90WQAAATg"]
[Thu Jul 30 15:17:39.436500 2026] [security2:error] [pid 147647:tid 147866] [client 172.237.109.114:57335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxYu_ioCvBERk4wq90VQAAAWM"]
[Thu Jul 30 15:17:39.510174 2026] [security2:error] [pid 147647:tid 147844] [client 82.102.18.188:58704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amuxY-_ioCvBERk4wq90YAAAAU0"]
[Thu Jul 30 15:17:39.743149 2026] [security2:error] [pid 147647:tid 147814] [client 45.94.31.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.koinjp189.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuxY-_ioCvBERk4wq90ZAAAAS8"]
[Thu Jul 30 15:17:40.247240 2026] [core:error] [pid 147647:tid 147893] [client 87.99.136.66:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:40.247265 2026] [core:error] [pid 147647:tid 147893] [client 87.99.136.66:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:40.368998 2026] [core:notice] [pid 147647:tid 147898] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:40.984599 2026] [core:error] [pid 147647:tid 147654] [remote 87.99.136.66:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:40.984624 2026] [core:error] [pid 147647:tid 147654] [remote 87.99.136.66:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:41.107721 2026] [security2:error] [pid 147647:tid 147811] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxZO_ioCvBERk4wq90fgAAASw"]
[Thu Jul 30 15:17:41.268304 2026] [core:notice] [pid 147647:tid 147855] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:41.272747 2026] [security2:error] [pid 147647:tid 147855] [client 66.249.79.229:50979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/article/view/4882"] [unique_id "amuxZe_ioCvBERk4wq90kgAAAVg"]
[Thu Jul 30 15:17:41.370800 2026] [security2:error] [pid 147647:tid 147900] [client 20.100.187.246:20884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-admin/xleet.php"] [unique_id "amuxZe_ioCvBERk4wq90kwAAAYU"]
[Thu Jul 30 15:17:41.753964 2026] [security2:error] [pid 147647:tid 147841] [client 158.158.41.78:17353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/f35.php"] [unique_id "amuxZe_ioCvBERk4wq90oQAAAUo"]
[Thu Jul 30 15:17:41.876327 2026] [core:error] [pid 147647:tid 147902] [client 87.99.128.58:49250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:41.876351 2026] [core:error] [pid 147647:tid 147902] [client 87.99.128.58:49250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:42.047006 2026] [security2:error] [pid 147647:tid 147670] [remote 97.74.93.24:43858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kamiliacademy.com"] [uri "/wp-login.php"] [unique_id "amuxZu_ioCvBERk4wq90rAABJxY"]
[Thu Jul 30 15:17:42.074309 2026] [core:error] [pid 147647:tid 147795] [client 87.99.128.58:7732] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:42.074329 2026] [core:error] [pid 147647:tid 147795] [client 87.99.128.58:7732] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:17:42.400752 2026] [security2:error] [pid 147647:tid 147809] [client 82.102.18.188:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amuxZu_ioCvBERk4wq90sAAAASo"]
[Thu Jul 30 15:17:42.400887 2026] [security2:error] [pid 147647:tid 147809] [client 82.102.18.188:58712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amuxZu_ioCvBERk4wq90sAAAASo"]
[Thu Jul 30 15:17:42.490356 2026] [proxy:error] [pid 147647:tid 147803] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:17:42.490445 2026] [proxy_http:error] [pid 147647:tid 147803] [client 52.4.19.39:11287] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:17:42.491029 2026] [proxy:error] [pid 147647:tid 147803] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:17:42.491093 2026] [proxy_http:error] [pid 147647:tid 147803] [client 52.4.19.39:11287] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:17:42.528166 2026] [core:notice] [pid 147647:tid 147668] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:42.567335 2026] [proxy:error] [pid 147647:tid 147791] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:17:42.567403 2026] [proxy_http:error] [pid 147647:tid 147791] [client 52.4.19.39:25581] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:17:42.567969 2026] [proxy:error] [pid 147647:tid 147791] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:17:42.568024 2026] [proxy_http:error] [pid 147647:tid 147791] [client 52.4.19.39:25581] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:17:42.748370 2026] [security2:error] [pid 147647:tid 147778] [client 158.158.41.78:26120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/new.php"] [unique_id "amuxZu_ioCvBERk4wq90wgAAAQs"]
[Thu Jul 30 15:17:42.931360 2026] [security2:error] [pid 147647:tid 147897] [client 82.102.18.188:58722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amuxZu_ioCvBERk4wq90yAAAAYI"]
[Thu Jul 30 15:17:42.931470 2026] [security2:error] [pid 147647:tid 147897] [client 82.102.18.188:58722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alseermarine.com"] [uri "/xmlrpc.php"] [unique_id "amuxZu_ioCvBERk4wq90yAAAAYI"]
[Thu Jul 30 15:17:43.348152 2026] [security2:error] [pid 147647:tid 147894] [client 20.226.5.174:32903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/011i.php"] [unique_id "amuxZ-_ioCvBERk4wq900QAAAX8"]
[Thu Jul 30 15:17:43.568958 2026] [security2:error] [pid 147647:tid 147895] [client 172.237.109.114:11308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxZ-_ioCvBERk4wq90zwAAAYA"]
[Thu Jul 30 15:17:43.572076 2026] [security2:error] [pid 147647:tid 147885] [client 172.237.109.114:29341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxZ-_ioCvBERk4wq900AAAAXY"]
[Thu Jul 30 15:17:43.652386 2026] [security2:error] [pid 147647:tid 147805] [client 20.100.187.246:8903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bisbeetour.com"] [uri "/wp-config-sample.php"] [unique_id "amuxZ-_ioCvBERk4wq903QAAASY"]
[Thu Jul 30 15:17:43.997796 2026] [security2:error] [pid 147647:tid 147676] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxZ-_ioCvBERk4wq904gABFxw"]
[Thu Jul 30 15:17:43.998023 2026] [security2:error] [pid 147647:tid 147790] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxZ-_ioCvBERk4wq904gABFxw"]
[Thu Jul 30 15:17:44.184713 2026] [core:notice] [pid 147647:tid 147813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:44.280031 2026] [security2:error] [pid 147647:tid 147679] [remote 85.208.96.193:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "espairsa.com"] [uri "/"] [unique_id "amuxaO_ioCvBERk4wq906gABcR8"]
[Thu Jul 30 15:17:44.280267 2026] [security2:error] [pid 147647:tid 147880] [client 85.208.96.193:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "espairsa.com"] [uri "/"] [unique_id "amuxaO_ioCvBERk4wq906gABcR8"]
[Thu Jul 30 15:17:44.414605 2026] [security2:error] [pid 147647:tid 147845] [client 20.226.5.174:32910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/03a005685d.php"] [unique_id "amuxaO_ioCvBERk4wq906wAAAU4"]
[Thu Jul 30 15:17:44.750633 2026] [security2:error] [pid 147647:tid 147883] [client 85.208.96.205:30228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/robots.txt"] [unique_id "amuxaO_ioCvBERk4wq909gAAAXQ"]
[Thu Jul 30 15:17:44.750792 2026] [security2:error] [pid 147647:tid 147883] [client 85.208.96.205:30228] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/robots.txt"] [unique_id "amuxaO_ioCvBERk4wq909gAAAXQ"]
[Thu Jul 30 15:17:44.779205 2026] [security2:error] [pid 147647:tid 147868] [client 158.158.41.78:15868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/adminfuns.php"] [unique_id "amuxaO_ioCvBERk4wq909wAAAWU"]
[Thu Jul 30 15:17:44.842080 2026] [core:notice] [pid 147647:tid 147691] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:44.846432 2026] [security2:error] [pid 147647:tid 147876] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/161/188"] [unique_id "amuxaO_ioCvBERk4wq90-AABbSs"]
[Thu Jul 30 15:17:45.335821 2026] [security2:error] [pid 147647:tid 147789] [client 85.208.96.210:11218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/"] [unique_id "amuxae_ioCvBERk4wq91BwAAARY"]
[Thu Jul 30 15:17:45.335936 2026] [security2:error] [pid 147647:tid 147789] [client 85.208.96.210:11218] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "saifalkhaleejest.com"] [uri "/"] [unique_id "amuxae_ioCvBERk4wq91BwAAARY"]
[Thu Jul 30 15:17:45.410197 2026] [security2:error] [pid 147647:tid 147864] [client 20.226.5.174:32897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/403.php"] [unique_id "amuxae_ioCvBERk4wq91CQAAAWE"]
[Thu Jul 30 15:17:45.806790 2026] [core:notice] [pid 147647:tid 147702] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:45.836422 2026] [core:notice] [pid 147647:tid 147848] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:46.457660 2026] [security2:error] [pid 147647:tid 147873] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxae_ioCvBERk4wq91EgABai4"]
[Thu Jul 30 15:17:46.548294 2026] [security2:error] [pid 147647:tid 147887] [client 20.226.5.174:32915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/404.php"] [unique_id "amuxau_ioCvBERk4wq91JgAAAXg"]
[Thu Jul 30 15:17:46.600860 2026] [security2:error] [pid 147647:tid 147854] [client 74.7.244.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-229ac79d.lld.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuxYe_ioCvBERk4wq90OAAAAVc"]
[Thu Jul 30 15:17:46.601860 2026] [security2:error] [pid 147647:tid 147800] [client 74.7.244.10:42838] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-229ac79d.lld.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuxYe_ioCvBERk4wq90NgABIXI"]
[Thu Jul 30 15:17:46.831579 2026] [core:notice] [pid 147647:tid 147809] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:47.329513 2026] [core:notice] [pid 147647:tid 147705] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:47.542570 2026] [autoindex:error] [pid 147647:tid 147835] [client 158.158.41.78:33289] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:17:47.673078 2026] [security2:error] [pid 147647:tid 147787] [client 158.158.41.78:33289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/fm.php"] [unique_id "amuxa-_ioCvBERk4wq91TgAAARQ"]
[Thu Jul 30 15:17:47.721306 2026] [security2:error] [pid 147647:tid 147850] [client 213.152.186.19:39586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuxa-_ioCvBERk4wq91UgAAAVM"]
[Thu Jul 30 15:17:47.721425 2026] [security2:error] [pid 147647:tid 147850] [client 213.152.186.19:39586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuxa-_ioCvBERk4wq91UgAAAVM"]
[Thu Jul 30 15:17:47.910206 2026] [core:notice] [pid 147647:tid 147833] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:48.160604 2026] [security2:error] [pid 147647:tid 147879] [client 20.226.5.174:32928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/aa.php"] [unique_id "amuxbO_ioCvBERk4wq91XAAAAXA"]
[Thu Jul 30 15:17:49.344766 2026] [security2:error] [pid 147647:tid 147829] [client 20.226.5.174:32900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/aafewc0k.php"] [unique_id "amuxbe_ioCvBERk4wq91fQAAAT4"]
[Thu Jul 30 15:17:49.357700 2026] [security2:error] [pid 147647:tid 147838] [client 158.158.41.78:22357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amuxbO_ioCvBERk4wq91dwAAAUc"]
[Thu Jul 30 15:17:49.448887 2026] [security2:error] [pid 147647:tid 147738] [remote 57.141.0.47:57354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/PBB/article/view/7393/2949"] [unique_id "amuxbe_ioCvBERk4wq91gQABPFo"]
[Thu Jul 30 15:17:49.450036 2026] [security2:error] [pid 147647:tid 147737] [remote 103.75.185.95:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuxbe_ioCvBERk4wq91gAABclk"]
[Thu Jul 30 15:17:49.615187 2026] [security2:error] [pid 147647:tid 147819] [client 158.158.41.78:22357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/file.php"] [unique_id "amuxbe_ioCvBERk4wq91ggAAATQ"]
[Thu Jul 30 15:17:50.020658 2026] [core:notice] [pid 147647:tid 147787] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:50.024875 2026] [security2:error] [pid 147647:tid 147787] [client 66.249.79.229:59372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/view/9251"] [unique_id "amuxbu_ioCvBERk4wq91kAAAARQ"]
[Thu Jul 30 15:17:50.475815 2026] [security2:error] [pid 147647:tid 147833] [client 20.226.5.174:32901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/abcd.php"] [unique_id "amuxbu_ioCvBERk4wq91mQAAAUI"]
[Thu Jul 30 15:17:50.979959 2026] [core:notice] [pid 147647:tid 147821] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:51.060347 2026] [autoindex:error] [pid 147647:tid 147847] [client 158.158.41.78:33284] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:17:51.204446 2026] [security2:error] [pid 147647:tid 147878] [client 158.158.41.78:33284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/bolt.php"] [unique_id "amuxb-_ioCvBERk4wq91qQAAAW8"]
[Thu Jul 30 15:17:51.603730 2026] [security2:error] [pid 147647:tid 147763] [remote 110.249.202.13:29944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/ar/investor-relations/investor-contact/"] [unique_id "amuxb-_ioCvBERk4wq91uwABTHM"]
[Thu Jul 30 15:17:51.690131 2026] [security2:error] [pid 147647:tid 147842] [client 20.226.5.174:32902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/about.php"] [unique_id "amuxb-_ioCvBERk4wq91vAAAAUs"]
[Thu Jul 30 15:17:51.814636 2026] [security2:error] [pid 147647:tid 147822] [client 158.158.41.78:52267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/3.php"] [unique_id "amuxb-_ioCvBERk4wq91vgAAATc"]
[Thu Jul 30 15:17:53.087850 2026] [security2:error] [pid 147647:tid 147769] [remote 17.241.75.131:47494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.75.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuxcO_ioCvBERk4wq911AABZnk"], referer: https://lark-shop.com/product/winston-5/
[Thu Jul 30 15:17:53.274791 2026] [security2:error] [pid 147647:tid 147799] [client 20.104.137.252:58353] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "google-search.org"] [uri "/.env"] [unique_id "amuxce_ioCvBERk4wq913QAAASA"]
[Thu Jul 30 15:17:53.697119 2026] [security2:error] [pid 147647:tid 147807] [client 20.226.5.174:32919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/admin.php"] [unique_id "amuxce_ioCvBERk4wq916AAAASg"]
[Thu Jul 30 15:17:54.588679 2026] [security2:error] [pid 147647:tid 147786] [client 172.237.109.114:36642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxcu_ioCvBERk4wq919AAAARM"]
[Thu Jul 30 15:17:54.599227 2026] [security2:error] [pid 147647:tid 147656] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxcu_ioCvBERk4wq91_QABSwg"]
[Thu Jul 30 15:17:54.599463 2026] [security2:error] [pid 147647:tid 147842] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxcu_ioCvBERk4wq91_QABSwg"]
[Thu Jul 30 15:17:54.811501 2026] [security2:error] [pid 147647:tid 147860] [client 193.47.62.167:47486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-831c2970.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amuxce_ioCvBERk4wq916QAAAV0"]
[Thu Jul 30 15:17:54.869262 2026] [security2:error] [pid 147647:tid 147889] [client 20.226.5.174:32906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/adminfuns.php"] [unique_id "amuxcu_ioCvBERk4wq92BgAAAXo"]
[Thu Jul 30 15:17:56.541029 2026] [security2:error] [pid 147647:tid 147903] [client 20.226.5.174:32925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/albin.php"] [unique_id "amuxdO_ioCvBERk4wq92KgAAAYg"]
[Thu Jul 30 15:17:57.087291 2026] [core:notice] [pid 147647:tid 147779] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:57.309384 2026] [security2:error] [pid 147647:tid 147860] [client 43.173.179.115:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2018/05/16/idees-cadeaux-fete-des-meres-2018/"] [unique_id "amuxde_ioCvBERk4wq92OgAAAV0"]
[Thu Jul 30 15:17:57.717697 2026] [core:notice] [pid 147647:tid 147677] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:57.754071 2026] [core:notice] [pid 147647:tid 147897] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:57.931961 2026] [core:notice] [pid 147647:tid 147824] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:57.937682 2026] [security2:error] [pid 147647:tid 147824] [client 43.173.180.180:35934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2018/05/16/idees-cadeaux-fete-des-meres-2018/"] [unique_id "amuxde_ioCvBERk4wq92TAAAATk"], referer: https://carnetdeshopping.com/index.php/2018/05/16/idees-cadeaux-fete-des-meres-2018/
[Thu Jul 30 15:17:57.998358 2026] [core:notice] [pid 147647:tid 147901] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:58.177854 2026] [security2:error] [pid 147647:tid 147685] [remote 64.225.121.94:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lld.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuxdu_ioCvBERk4wq92UQABayU"]
[Thu Jul 30 15:17:58.575379 2026] [security2:error] [pid 147647:tid 147831] [client 20.226.5.174:32922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/amfsqvgv.php"] [unique_id "amuxdu_ioCvBERk4wq92WAAAAUA"]
[Thu Jul 30 15:17:58.746841 2026] [core:notice] [pid 147647:tid 147854] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:17:58.750883 2026] [security2:error] [pid 147647:tid 147854] [client 66.249.79.229:64679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/view/6364/2752"] [unique_id "amuxdu_ioCvBERk4wq92XgAAAVc"]
[Thu Jul 30 15:17:59.839046 2026] [security2:error] [pid 147647:tid 147876] [client 20.226.5.174:32904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/ant.php"] [unique_id "amuxd-_ioCvBERk4wq92cwAAAW0"]
[Thu Jul 30 15:18:00.032733 2026] [core:notice] [pid 147647:tid 147862] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:00.036096 2026] [security2:error] [pid 147647:tid 147862] [client 66.249.79.229:64679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/5692/2534"] [unique_id "amuxeO_ioCvBERk4wq92fAAAAV8"]
[Thu Jul 30 15:18:00.096512 2026] [core:notice] [pid 147647:tid 147857] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:00.299454 2026] [core:notice] [pid 147647:tid 147863] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:00.811556 2026] [core:notice] [pid 147647:tid 147839] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:01.280525 2026] [security2:error] [pid 147647:tid 147882] [client 20.226.5.174:32948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/appreciators.php"] [unique_id "amuxee_ioCvBERk4wq92oAAAAXM"]
[Thu Jul 30 15:18:01.383367 2026] [core:notice] [pid 147647:tid 147887] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:01.387385 2026] [security2:error] [pid 147647:tid 147887] [client 66.249.79.237:42740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Responsif/article/view/9573"] [unique_id "amuxee_ioCvBERk4wq92mQAAAXg"]
[Thu Jul 30 15:18:01.587738 2026] [security2:error] [pid 147647:tid 147681] [remote 57.141.0.67:38964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuxee_ioCvBERk4wq92qAABSiE"]
[Thu Jul 30 15:18:01.681614 2026] [core:notice] [pid 147647:tid 147694] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:02.083477 2026] [security2:error] [pid 147647:tid 147788] [client 114.119.152.139:50129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "azureskyfilms.com"] [uri "/images/IMG_0134_2-300x300.jpg"] [unique_id "amuxeu_ioCvBERk4wq92tgAAARU"], referer: https://azureskyfilms.com/images/IMG_0134_2-300x300.jpg
[Thu Jul 30 15:18:02.124725 2026] [security2:error] [pid 147647:tid 147701] [remote 74.7.227.39:56494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuxeu_ioCvBERk4wq92twABdTU"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/
[Thu Jul 30 15:18:02.161855 2026] [security2:error] [pid 147647:tid 147797] [client 5.161.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blsspainvisacenterpakistan.site"] [uri "/index.php"] [unique_id "amuxeO_ioCvBERk4wq92lQAAAR4"]
[Thu Jul 30 15:18:02.161944 2026] [security2:error] [pid 147647:tid 147792] [client 5.161.225.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blsspainvisacenterpakistan.site"] [uri "/index.php"] [unique_id "amuxee_ioCvBERk4wq92qgABGXI"]
[Thu Jul 30 15:18:02.372526 2026] [security2:error] [pid 147647:tid 147881] [client 20.226.5.174:32914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/archive.php"] [unique_id "amuxeu_ioCvBERk4wq92uwAAAXI"]
[Thu Jul 30 15:18:02.776833 2026] [core:notice] [pid 147647:tid 147798] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:02.780567 2026] [security2:error] [pid 147647:tid 147798] [client 66.249.79.2:38785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Caruban/article/view/2315/1432"] [unique_id "amuxeu_ioCvBERk4wq92wgAAAR8"]
[Thu Jul 30 15:18:02.909510 2026] [core:notice] [pid 147647:tid 147877] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:03.588690 2026] [security2:error] [pid 147647:tid 147814] [client 20.226.5.174:32924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/as.php"] [unique_id "amuxe-_ioCvBERk4wq921wAAAS8"]
[Thu Jul 30 15:18:03.669348 2026] [security2:error] [pid 147647:tid 147804] [client 103.168.67.159:52606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/wp-login.php"] [unique_id "amuxe-_ioCvBERk4wq92zQAAASU"], referer: https://cpanel.hmhs.ph/
[Thu Jul 30 15:18:04.195592 2026] [security2:error] [pid 147647:tid 147834] [client 158.158.41.78:9494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/222.php"] [unique_id "amuxfO_ioCvBERk4wq925AAAAUM"]
[Thu Jul 30 15:18:04.334291 2026] [core:notice] [pid 147647:tid 147806] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:04.338693 2026] [security2:error] [pid 147647:tid 147806] [client 66.249.79.1:35483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/3460/1753"] [unique_id "amuxfO_ioCvBERk4wq924wAAASc"]
[Thu Jul 30 15:18:04.533059 2026] [core:notice] [pid 147647:tid 147795] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:04.881544 2026] [security2:error] [pid 147647:tid 147878] [client 20.226.5.174:32920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/atomlib.php"] [unique_id "amuxfO_ioCvBERk4wq929QAAAW8"]
[Thu Jul 30 15:18:04.940465 2026] [security2:error] [pid 147647:tid 147802] [client 103.168.67.159:56060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/blog/wp-login.php"] [unique_id "amuxfO_ioCvBERk4wq929gAAASM"], referer: https://cpanel.hmhs.ph/blog/
[Thu Jul 30 15:18:04.957838 2026] [security2:error] [pid 147647:tid 147833] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxe-_ioCvBERk4wq922wABQlA"]
[Thu Jul 30 15:18:04.989179 2026] [security2:error] [pid 147647:tid 147901] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxe-_ioCvBERk4wq922AABhko"]
[Thu Jul 30 15:18:05.188560 2026] [security2:error] [pid 147647:tid 147737] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxfe_ioCvBERk4wq92_gABiVk"]
[Thu Jul 30 15:18:05.188729 2026] [security2:error] [pid 147647:tid 147904] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxfe_ioCvBERk4wq92_gABiVk"]
[Thu Jul 30 15:18:05.323690 2026] [core:notice] [pid 147647:tid 147739] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:05.721734 2026] [core:notice] [pid 147647:tid 147719] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:06.006765 2026] [security2:error] [pid 147647:tid 147873] [client 158.158.41.78:16171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/images/admin.php"] [unique_id "amuxfu_ioCvBERk4wq93GQAAAWo"]
[Thu Jul 30 15:18:06.051379 2026] [core:notice] [pid 147647:tid 147745] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:06.056791 2026] [security2:error] [pid 147647:tid 147858] [client 20.226.5.174:32907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/autoload_classmap.php"] [unique_id "amuxfu_ioCvBERk4wq93GwAAAVs"]
[Thu Jul 30 15:18:06.080753 2026] [security2:error] [pid 147647:tid 147799] [client 103.168.67.159:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/wordpress/wp-login.php"] [unique_id "amuxfu_ioCvBERk4wq93IAAAASA"], referer: https://cpanel.hmhs.ph/wordpress/
[Thu Jul 30 15:18:06.118610 2026] [core:notice] [pid 147647:tid 147847] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:06.518921 2026] [core:notice] [pid 147647:tid 147896] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:07.103526 2026] [security2:error] [pid 147647:tid 147792] [client 103.168.67.159:56078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/wp/wp-login.php"] [unique_id "amuxf-_ioCvBERk4wq93PgAAARk"], referer: https://cpanel.hmhs.ph/wp/
[Thu Jul 30 15:18:07.135543 2026] [security2:error] [pid 147647:tid 147904] [client 20.226.5.174:32911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/bb.php"] [unique_id "amuxf-_ioCvBERk4wq93QwAAAYk"]
[Thu Jul 30 15:18:07.572402 2026] [security2:error] [pid 147647:tid 147812] [client 158.158.41.78:10082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuxf-_ioCvBERk4wq93TwAAAS0"]
[Thu Jul 30 15:18:07.677608 2026] [security2:error] [pid 147647:tid 147849] [client 172.237.109.114:48930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxf-_ioCvBERk4wq93QQAAAVI"]
[Thu Jul 30 15:18:07.792457 2026] [core:notice] [pid 147647:tid 147823] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:08.017270 2026] [security2:error] [pid 147647:tid 147841] [client 62.102.148.162:45452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuxgO_ioCvBERk4wq93XQAAAUo"]
[Thu Jul 30 15:18:08.017372 2026] [security2:error] [pid 147647:tid 147841] [client 62.102.148.162:45452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuxgO_ioCvBERk4wq93XQAAAUo"]
[Thu Jul 30 15:18:08.461661 2026] [security2:error] [pid 147647:tid 147856] [client 20.226.5.174:32913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/bnm.php"] [unique_id "amuxgO_ioCvBERk4wq93ZwAAAVk"]
[Thu Jul 30 15:18:08.800644 2026] [security2:error] [pid 147647:tid 147898] [client 103.168.67.159:56082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/cms/wp-login.php"] [unique_id "amuxgO_ioCvBERk4wq93cgAAAYM"], referer: https://cpanel.hmhs.ph/cms/
[Thu Jul 30 15:18:08.880534 2026] [autoindex:error] [pid 147647:tid 147878] [client 158.158.41.78:9922] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:18:09.064130 2026] [security2:error] [pid 147647:tid 147803] [client 158.158.41.78:9922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/admin.php"] [unique_id "amuxge_ioCvBERk4wq93dQAAASQ"]
[Thu Jul 30 15:18:09.502346 2026] [security2:error] [pid 147647:tid 147867] [client 20.226.5.174:32932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/bootstrap.php"] [unique_id "amuxge_ioCvBERk4wq93mwAAAWQ"]
[Thu Jul 30 15:18:10.144517 2026] [security2:error] [pid 147647:tid 147855] [client 158.158.41.78:10066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-configs.php"] [unique_id "amuxgu_ioCvBERk4wq93xAAAAVg"]
[Thu Jul 30 15:18:10.152801 2026] [core:notice] [pid 147647:tid 147814] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:10.187366 2026] [security2:error] [pid 147647:tid 147796] [client 103.168.67.159:56096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/site/wp-login.php"] [unique_id "amuxgu_ioCvBERk4wq93xgAAAR0"], referer: https://cpanel.hmhs.ph/site/
[Thu Jul 30 15:18:10.526093 2026] [security2:error] [pid 147647:tid 147854] [client 20.226.5.174:32916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/buy.php"] [unique_id "amuxgu_ioCvBERk4wq930QAAAVc"]
[Thu Jul 30 15:18:10.826080 2026] [core:notice] [pid 147647:tid 147903] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:10.830358 2026] [security2:error] [pid 147647:tid 147903] [client 66.249.79.230:61292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/agrijati/article/view/176"] [unique_id "amuxgu_ioCvBERk4wq930gAAAYg"]
[Thu Jul 30 15:18:11.411640 2026] [security2:error] [pid 147647:tid 147866] [client 103.168.67.159:56112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/main/wp-login.php"] [unique_id "amuxg-_ioCvBERk4wq938gAAAWM"], referer: https://cpanel.hmhs.ph/main/
[Thu Jul 30 15:18:11.729297 2026] [core:notice] [pid 147647:tid 147721] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:11.901956 2026] [security2:error] [pid 147647:tid 147794] [client 20.226.5.174:32937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/chosen.php"] [unique_id "amuxg-_ioCvBERk4wq93-wAAARs"]
[Thu Jul 30 15:18:11.987044 2026] [security2:error] [pid 147647:tid 147826] [client 158.158.41.78:30602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/php.php"] [unique_id "amuxg-_ioCvBERk4wq93_wAAATs"]
[Thu Jul 30 15:18:12.893367 2026] [security2:error] [pid 147647:tid 147809] [client 103.168.67.159:56114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/new/wp-login.php"] [unique_id "amuxhO_ioCvBERk4wq94DwAAASo"], referer: https://cpanel.hmhs.ph/new/
[Thu Jul 30 15:18:13.065293 2026] [core:notice] [pid 147647:tid 147865] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:13.134049 2026] [security2:error] [pid 147647:tid 147856] [client 158.158.41.78:9835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/index.php"] [unique_id "amuxhe_ioCvBERk4wq94FQAAAVk"]
[Thu Jul 30 15:18:13.372403 2026] [security2:error] [pid 147647:tid 147795] [client 20.226.5.174:32921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/class-wp-image.php"] [unique_id "amuxhe_ioCvBERk4wq94GQAAARw"]
[Thu Jul 30 15:18:13.463167 2026] [security2:error] [pid 147647:tid 147823] [client 103.168.67.159:36272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/wp-login.php"] [unique_id "amuxhe_ioCvBERk4wq94HgAAATg"], referer: http://cpanel.hmhs.ph/
[Thu Jul 30 15:18:13.666318 2026] [core:notice] [pid 147647:tid 147881] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:13.877588 2026] [security2:error] [pid 147647:tid 147777] [client 158.158.41.78:9805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/a.php"] [unique_id "amuxhe_ioCvBERk4wq94JwAAAQo"]
[Thu Jul 30 15:18:14.113671 2026] [core:notice] [pid 147647:tid 147821] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:14.479879 2026] [security2:error] [pid 147647:tid 147852] [client 20.226.5.174:32945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/classsmtps.php"] [unique_id "amuxhu_ioCvBERk4wq94NgAAAVU"]
[Thu Jul 30 15:18:14.545013 2026] [core:notice] [pid 147647:tid 147904] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:14.800869 2026] [core:notice] [pid 147647:tid 147789] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:15.028783 2026] [core:notice] [pid 147647:tid 147882] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:15.545474 2026] [security2:error] [pid 147647:tid 147807] [client 103.168.67.159:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/blog/wp-login.php"] [unique_id "amuxh-_ioCvBERk4wq94TAAAASg"], referer: http://cpanel.hmhs.ph/blog/
[Thu Jul 30 15:18:15.760429 2026] [security2:error] [pid 147647:tid 147729] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxh-_ioCvBERk4wq94UAABW1E"]
[Thu Jul 30 15:18:15.760602 2026] [security2:error] [pid 147647:tid 147858] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxh-_ioCvBERk4wq94UAABW1E"]
[Thu Jul 30 15:18:16.224878 2026] [security2:error] [pid 147647:tid 147889] [client 103.168.67.159:50916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/wordpress/wp-login.php"] [unique_id "amuxiO_ioCvBERk4wq94XQAAAXo"], referer: http://cpanel.hmhs.ph/wordpress/
[Thu Jul 30 15:18:16.242609 2026] [core:notice] [pid 147647:tid 147890] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:16.530793 2026] [autoindex:error] [pid 147647:tid 147902] [client 158.158.41.78:17493] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:18:16.559012 2026] [security2:error] [pid 147647:tid 147834] [client 20.226.5.174:32929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/classwithtostring.php"] [unique_id "amuxiO_ioCvBERk4wq94agAAAUM"]
[Thu Jul 30 15:18:16.686624 2026] [autoindex:error] [pid 147647:tid 147818] [client 158.158.41.78:17493] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:18:16.816102 2026] [security2:error] [pid 147647:tid 147810] [client 158.158.41.78:17493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/Text/about.php"] [unique_id "amuxiO_ioCvBERk4wq94bQAAASs"]
[Thu Jul 30 15:18:17.000632 2026] [security2:error] [pid 147647:tid 147835] [client 103.168.67.159:50924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/wp/wp-login.php"] [unique_id "amuxiO_ioCvBERk4wq94dgAAAUQ"], referer: http://cpanel.hmhs.ph/wp/
[Thu Jul 30 15:18:17.068044 2026] [core:notice] [pid 147647:tid 147759] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:17.597214 2026] [security2:error] [pid 147647:tid 147839] [client 172.237.109.114:33519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxie_ioCvBERk4wq94eQAAAUg"]
[Thu Jul 30 15:18:17.745792 2026] [security2:error] [pid 147647:tid 147852] [client 20.226.5.174:32926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/config.php"] [unique_id "amuxie_ioCvBERk4wq94iQAAAVU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 15:18:18.013310 2026] [security2:error] [pid 147647:tid 147887] [client 103.168.67.159:50930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/cms/wp-login.php"] [unique_id "amuxiu_ioCvBERk4wq94lgAAAXg"], referer: http://cpanel.hmhs.ph/cms/
[Thu Jul 30 15:18:18.483024 2026] [proxy:error] [pid 147647:tid 147831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:18:18.483094 2026] [proxy_http:error] [pid 147647:tid 147831] [client 34.233.129.35:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:18:18.483842 2026] [proxy:error] [pid 147647:tid 147831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:18:18.483901 2026] [proxy_http:error] [pid 147647:tid 147831] [client 34.233.129.35:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:18:18.525942 2026] [security2:error] [pid 147647:tid 147768] [remote 97.74.87.194:36994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amuxiu_ioCvBERk4wq94pAABHng"]
[Thu Jul 30 15:18:19.080193 2026] [security2:error] [pid 147647:tid 147888] [client 20.226.5.174:32917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/core.php"] [unique_id "amuxi-_ioCvBERk4wq94tgAAAXk"]
[Thu Jul 30 15:18:19.346472 2026] [core:error] [pid 147647:tid 147775] [remote 74.7.241.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:19.346502 2026] [core:error] [pid 147647:tid 147775] [remote 74.7.241.158:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:19.346694 2026] [security2:error] [pid 147647:tid 147782] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.embassyofitalyislamabad.vip"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amuxi-_ioCvBERk4wq94uwABD38"]
[Thu Jul 30 15:18:19.542559 2026] [security2:error] [pid 147647:tid 147894] [client 103.168.67.159:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/site/wp-login.php"] [unique_id "amuxi-_ioCvBERk4wq94vwAAAX8"], referer: http://cpanel.hmhs.ph/site/
[Thu Jul 30 15:18:19.734045 2026] [proxy:error] [pid 147647:tid 147814] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:18:19.734118 2026] [proxy_http:error] [pid 147647:tid 147814] [client 34.233.129.35:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:18:19.734699 2026] [proxy:error] [pid 147647:tid 147814] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:18:19.734740 2026] [proxy_http:error] [pid 147647:tid 147814] [client 34.233.129.35:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:18:20.037966 2026] [core:notice] [pid 147647:tid 147832] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:20.180705 2026] [security2:error] [pid 147647:tid 147891] [client 158.158.41.78:32089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin.php"] [unique_id "amuxjO_ioCvBERk4wq94zwAAAXw"]
[Thu Jul 30 15:18:20.201540 2026] [core:notice] [pid 147647:tid 147820] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:20.527665 2026] [security2:error] [pid 147647:tid 147796] [client 20.226.5.174:32931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/css.php"] [unique_id "amuxjO_ioCvBERk4wq941wAAAR0"]
[Thu Jul 30 15:18:21.019311 2026] [security2:error] [pid 147647:tid 147902] [client 103.168.67.159:50936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/main/wp-login.php"] [unique_id "amuxje_ioCvBERk4wq944gAAAYc"], referer: http://cpanel.hmhs.ph/main/
[Thu Jul 30 15:18:21.240609 2026] [security2:error] [pid 147647:tid 147670] [remote 57.141.0.45:28618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/85694478356/feed/rss2/"] [unique_id "amuxje_ioCvBERk4wq947QABNxY"]
[Thu Jul 30 15:18:21.564121 2026] [security2:error] [pid 147647:tid 147834] [client 172.237.109.114:36940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxje_ioCvBERk4wq944QAAAUM"]
[Thu Jul 30 15:18:21.712809 2026] [core:notice] [pid 147647:tid 147854] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:21.713959 2026] [security2:error] [pid 147647:tid 147784] [client 103.168.67.159:50952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/new/wp-login.php"] [unique_id "amuxje_ioCvBERk4wq949QAAARE"], referer: http://cpanel.hmhs.ph/new/
[Thu Jul 30 15:18:21.716964 2026] [security2:error] [pid 147647:tid 147854] [client 66.249.79.8:49527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/download/5131/2424"] [unique_id "amuxje_ioCvBERk4wq947gAAAVc"]
[Thu Jul 30 15:18:22.005755 2026] [security2:error] [pid 147647:tid 147793] [client 20.226.5.174:32933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/database.php"] [unique_id "amuxju_ioCvBERk4wq94-QAAARo"]
[Thu Jul 30 15:18:23.420667 2026] [security2:error] [pid 147647:tid 147787] [client 20.226.5.174:32905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/db.php"] [unique_id "amuxj-_ioCvBERk4wq95FAAAARQ"]
[Thu Jul 30 15:18:23.465622 2026] [security2:error] [pid 147647:tid 147876] [client 68.67.112.235:6090] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuxj-_ioCvBERk4wq95FQAAAW0"]
[Thu Jul 30 15:18:23.823338 2026] [security2:error] [pid 147647:tid 147887] [client 158.158.41.78:9593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/size.php"] [unique_id "amuxj-_ioCvBERk4wq95HAAAAXg"]
[Thu Jul 30 15:18:24.878279 2026] [security2:error] [pid 147647:tid 147825] [client 20.226.5.174:32949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/default.php"] [unique_id "amuxkO_ioCvBERk4wq95MgAAATo"]
[Thu Jul 30 15:18:25.872044 2026] [security2:error] [pid 147647:tid 147899] [client 158.158.41.78:32107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/wp-class.php"] [unique_id "amuxke_ioCvBERk4wq95RgAAAYQ"]
[Thu Jul 30 15:18:26.363136 2026] [security2:error] [pid 147647:tid 147696] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxku_ioCvBERk4wq95UQABWzA"]
[Thu Jul 30 15:18:26.363290 2026] [security2:error] [pid 147647:tid 147858] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxku_ioCvBERk4wq95UQABWzA"]
[Thu Jul 30 15:18:26.496720 2026] [security2:error] [pid 147647:tid 147852] [client 172.237.109.114:4807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxku_ioCvBERk4wq95SgAAAVU"]
[Thu Jul 30 15:18:26.626873 2026] [security2:error] [pid 147647:tid 147871] [client 20.226.5.174:32912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/dropdown.php"] [unique_id "amuxku_ioCvBERk4wq95VQAAAWg"]
[Thu Jul 30 15:18:26.841899 2026] [core:notice] [pid 147647:tid 147795] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:27.298305 2026] [core:notice] [pid 147647:tid 147850] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:27.301468 2026] [security2:error] [pid 147647:tid 147850] [client 66.249.79.8:44638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/1035/665"] [unique_id "amuxk-_ioCvBERk4wq95ZwAAAVM"]
[Thu Jul 30 15:18:27.969328 2026] [core:notice] [pid 147647:tid 147789] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:27.974642 2026] [security2:error] [pid 147647:tid 147789] [client 66.249.79.8:44638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/view/3723"] [unique_id "amuxk-_ioCvBERk4wq95fQAAARY"]
[Thu Jul 30 15:18:27.994519 2026] [security2:error] [pid 147647:tid 147840] [client 62.238.48.211:55408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amuxke_ioCvBERk4wq95OwAAAUM"]
[Thu Jul 30 15:18:28.154877 2026] [security2:error] [pid 147647:tid 147888] [client 103.168.67.159:48714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/wp-login.php"] [unique_id "amuxlO_ioCvBERk4wq95fwAAAXk"], referer: https://cpanel.hmhs.ph/
[Thu Jul 30 15:18:28.387652 2026] [security2:error] [pid 147647:tid 147823] [client 20.226.5.174:32451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/edit.php"] [unique_id "amuxlO_ioCvBERk4wq95oAAAATg"]
[Thu Jul 30 15:18:28.851359 2026] [security2:error] [pid 147647:tid 147871] [client 158.158.41.78:26537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/403.php"] [unique_id "amuxlO_ioCvBERk4wq95vwAAAWg"]
[Thu Jul 30 15:18:29.058241 2026] [core:notice] [pid 147647:tid 147878] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:29.064067 2026] [security2:error] [pid 147647:tid 147878] [client 66.249.79.229:41498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/view/4964/3780"] [unique_id "amuxle_ioCvBERk4wq95zgAAAW8"]
[Thu Jul 30 15:18:29.078934 2026] [security2:error] [pid 147647:tid 147766] [remote 57.141.0.47:38628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuxle_ioCvBERk4wq95zwABO3Y"]
[Thu Jul 30 15:18:29.417371 2026] [security2:error] [pid 147647:tid 147797] [client 158.158.41.78:25894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuxle_ioCvBERk4wq950wAAAR4"]
[Thu Jul 30 15:18:29.671089 2026] [security2:error] [pid 147647:tid 147863] [client 20.226.5.174:32665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/f35.php"] [unique_id "amuxle_ioCvBERk4wq953gAAAWA"]
[Thu Jul 30 15:18:29.710921 2026] [security2:error] [pid 147647:tid 147767] [remote 57.141.0.36:40664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuxle_ioCvBERk4wq953wABInc"]
[Thu Jul 30 15:18:29.726649 2026] [core:error] [pid 147647:tid 147772] [remote 216.73.216.175:17568] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:29.726676 2026] [core:error] [pid 147647:tid 147772] [remote 216.73.216.175:17568] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:30.029691 2026] [core:notice] [pid 147647:tid 147841] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:30.250525 2026] [security2:error] [pid 147647:tid 147769] [remote 57.141.0.34:39742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuxlu_ioCvBERk4wq957QABLnk"]
[Thu Jul 30 15:18:31.351113 2026] [security2:error] [pid 147647:tid 147833] [client 20.226.5.174:32651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.asian-connect.com"] [uri "/f7.php"] [unique_id "amuxl-_ioCvBERk4wq96DgAAAUI"]
[Thu Jul 30 15:18:31.918949 2026] [security2:error] [pid 147647:tid 147869] [client 158.158.41.78:32133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/as.php"] [unique_id "amuxl-_ioCvBERk4wq96DwAAAWY"]
[Thu Jul 30 15:18:32.611956 2026] [security2:error] [pid 147647:tid 147851] [client 172.237.109.114:34831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxmO_ioCvBERk4wq96EgAAAVQ"]
[Thu Jul 30 15:18:32.936991 2026] [core:notice] [pid 147647:tid 147890] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:32.940938 2026] [security2:error] [pid 147647:tid 147890] [client 66.249.79.230:48137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/download/9009/4275"] [unique_id "amuxmO_ioCvBERk4wq96FAAAAXs"]
[Thu Jul 30 15:18:33.512504 2026] [security2:error] [pid 147647:tid 147872] [client 158.158.41.78:9856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/includes/index.php"] [unique_id "amuxme_ioCvBERk4wq96GQAAAWk"]
[Thu Jul 30 15:18:33.533354 2026] [core:notice] [pid 147647:tid 147862] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:34.055773 2026] [core:notice] [pid 147647:tid 147809] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:34.059238 2026] [security2:error] [pid 147647:tid 147809] [client 66.249.79.8:44638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JSTE/article/view/8479"] [unique_id "amuxmu_ioCvBERk4wq96HAAAASo"]
[Thu Jul 30 15:18:34.532471 2026] [security2:error] [pid 147647:tid 147663] [remote 57.141.0.41:27122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuxmu_ioCvBERk4wq96IQABbg8"]
[Thu Jul 30 15:18:35.474347 2026] [security2:error] [pid 147647:tid 147805] [client 34.84.221.1:28037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2016/04/ASOS-PETITE-Robe-fourreau-texturee-235x300.jpg"] [unique_id "amuxm-_ioCvBERk4wq96KgAAASY"]
[Thu Jul 30 15:18:35.572143 2026] [security2:error] [pid 147647:tid 147849] [client 43.153.10.83:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.10.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/about/privacy"] [unique_id "amuxm-_ioCvBERk4wq96KQAAAVI"]
[Thu Jul 30 15:18:35.656846 2026] [security2:error] [pid 147647:tid 147789] [client 20.104.18.253:24857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/vv.php"] [unique_id "amuxm-_ioCvBERk4wq96KwAAARY"]
[Thu Jul 30 15:18:35.695260 2026] [security2:error] [pid 147647:tid 147840] [client 128.140.106.114:19650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuxm-_ioCvBERk4wq96LAAAAUk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:18:36.066850 2026] [security2:error] [pid 147647:tid 147665] [remote 97.74.93.24:57214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amuxnO_ioCvBERk4wq96MgABRxE"]
[Thu Jul 30 15:18:36.277485 2026] [security2:error] [pid 147647:tid 147843] [client 20.104.18.253:24848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/vwcleanerplugin/bump.php"] [unique_id "amuxnO_ioCvBERk4wq96MwAAAUw"]
[Thu Jul 30 15:18:36.305236 2026] [core:notice] [pid 147647:tid 147813] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:36.309867 2026] [security2:error] [pid 147647:tid 147813] [client 128.140.106.114:19656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuxnO_ioCvBERk4wq96NAAAAS4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:18:36.453852 2026] [security2:error] [pid 147647:tid 147793] [client 158.158.41.78:25831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuxnO_ioCvBERk4wq96NQAAARo"]
[Thu Jul 30 15:18:36.703065 2026] [security2:error] [pid 147647:tid 147853] [client 128.140.106.114:19668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuxnO_ioCvBERk4wq96NgAAAVY"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:18:36.881550 2026] [security2:error] [pid 147647:tid 147659] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxnO_ioCvBERk4wq96NwABOAs"]
[Thu Jul 30 15:18:36.881802 2026] [security2:error] [pid 147647:tid 147823] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxnO_ioCvBERk4wq96NwABOAs"]
[Thu Jul 30 15:18:36.929338 2026] [security2:error] [pid 147647:tid 147839] [client 20.104.18.253:24884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/vwx.php"] [unique_id "amuxnO_ioCvBERk4wq96OAAAAUg"]
[Thu Jul 30 15:18:37.542437 2026] [security2:error] [pid 147647:tid 147883] [client 20.104.18.253:40621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/vxrl.php"] [unique_id "amuxne_ioCvBERk4wq96PwAAAXQ"]
[Thu Jul 30 15:18:38.163802 2026] [security2:error] [pid 147647:tid 147831] [client 20.104.18.253:40601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/vy2m7.php"] [unique_id "amuxnu_ioCvBERk4wq96QQAAAUA"]
[Thu Jul 30 15:18:38.823390 2026] [security2:error] [pid 147647:tid 147849] [client 20.104.18.253:24853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/w.php"] [unique_id "amuxnu_ioCvBERk4wq96TgAAAVI"]
[Thu Jul 30 15:18:38.894590 2026] [security2:error] [pid 147647:tid 147824] [client 158.158.41.78:45089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/plugins.php"] [unique_id "amuxnu_ioCvBERk4wq96UQAAATk"]
[Thu Jul 30 15:18:39.062580 2026] [security2:error] [pid 147647:tid 147809] [client 213.180.203.114:33412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.urwru.club"] [uri "/index.php"] [unique_id "amuxnu_ioCvBERk4wq96RwAAASo"]
[Thu Jul 30 15:18:39.502380 2026] [security2:error] [pid 147647:tid 147867] [client 20.104.18.253:40594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/w3llstore.php"] [unique_id "amuxn-_ioCvBERk4wq96YAAAAWQ"]
[Thu Jul 30 15:18:40.004098 2026] [core:notice] [pid 147647:tid 147827] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:40.007625 2026] [security2:error] [pid 147647:tid 147827] [client 66.249.79.8:45131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/8967"] [unique_id "amuxoO_ioCvBERk4wq96bgAAATw"]
[Thu Jul 30 15:18:40.025509 2026] [security2:error] [pid 147647:tid 147903] [client 158.158.41.78:25843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/js/index.php"] [unique_id "amuxoO_ioCvBERk4wq96cgAAAYg"]
[Thu Jul 30 15:18:40.116498 2026] [security2:error] [pid 147647:tid 147829] [client 20.104.18.253:24868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/waf_defender.php"] [unique_id "amuxoO_ioCvBERk4wq96dgAAAT4"]
[Thu Jul 30 15:18:40.727682 2026] [security2:error] [pid 147647:tid 147871] [client 20.104.18.253:24875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/wander.php"] [unique_id "amuxoO_ioCvBERk4wq96ggAAAWg"]
[Thu Jul 30 15:18:40.762537 2026] [security2:error] [pid 147647:tid 147683] [remote 110.249.202.76:31172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/ar/2025/11/12/al-seer-marine-achieves-fleet-of-18-vessels-in-just-three-years-completing-first-stage-of-rapid-expansion/"] [unique_id "amuxoO_ioCvBERk4wq96gwABTiM"]
[Thu Jul 30 15:18:41.068055 2026] [security2:error] [pid 147647:tid 147898] [client 158.158.41.78:18688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/go.php"] [unique_id "amuxoe_ioCvBERk4wq96jgAAAYM"]
[Thu Jul 30 15:18:41.372387 2026] [security2:error] [pid 147647:tid 147836] [client 20.104.18.253:24887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/wawe.php"] [unique_id "amuxoe_ioCvBERk4wq96kwAAAUU"]
[Thu Jul 30 15:18:42.003442 2026] [security2:error] [pid 147647:tid 147843] [client 20.104.18.253:24870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/wb.php"] [unique_id "amuxou_ioCvBERk4wq96ngAAAUw"]
[Thu Jul 30 15:18:42.288947 2026] [core:notice] [pid 147647:tid 147856] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:42.448716 2026] [security2:error] [pid 147647:tid 147839] [client 158.158.41.78:44459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/test1.php"] [unique_id "amuxou_ioCvBERk4wq96rAAAAUg"]
[Thu Jul 30 15:18:42.632368 2026] [security2:error] [pid 147647:tid 147804] [client 20.104.18.253:40620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/we.php"] [unique_id "amuxou_ioCvBERk4wq96swAAASU"]
[Thu Jul 30 15:18:43.244305 2026] [core:error] [pid 147647:tid 147873] [client 5.161.206.147:51954] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:43.244331 2026] [core:error] [pid 147647:tid 147873] [client 5.161.206.147:51954] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:43.258426 2026] [security2:error] [pid 147647:tid 147706] [remote 74.7.227.39:36134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amuxo-_ioCvBERk4wq96xAABHjo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/
[Thu Jul 30 15:18:43.272421 2026] [core:error] [pid 147647:tid 147711] [remote 157.55.39.222:13451] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:43.272445 2026] [core:error] [pid 147647:tid 147711] [remote 157.55.39.222:13451] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:43.295238 2026] [security2:error] [pid 147647:tid 147872] [client 20.104.18.253:24832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/web.php"] [unique_id "amuxo-_ioCvBERk4wq96xgAAAWk"]
[Thu Jul 30 15:18:43.438660 2026] [core:error] [pid 147647:tid 147831] [client 5.161.206.147:16146] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:43.438688 2026] [core:error] [pid 147647:tid 147831] [client 5.161.206.147:16146] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:18:43.480388 2026] [security2:error] [pid 147647:tid 147852] [client 172.237.109.114:8097] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxou_ioCvBERk4wq96uAAAAVU"]
[Thu Jul 30 15:18:43.485577 2026] [core:notice] [pid 147647:tid 147861] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:43.635253 2026] [security2:error] [pid 147647:tid 147777] [client 103.168.67.159:29384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hmhs.ph"] [uri "/index.php"] [unique_id "amuxo-_ioCvBERk4wq96zQAAAQo"], referer: https://cpanel.hmhs.ph/
[Thu Jul 30 15:18:43.659030 2026] [security2:error] [pid 147647:tid 147875] [client 172.237.109.114:9010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxo-_ioCvBERk4wq96vAAAAWw"]
[Thu Jul 30 15:18:43.911215 2026] [security2:error] [pid 147647:tid 147811] [client 20.104.18.253:24863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/webadmin.php"] [unique_id "amuxo-_ioCvBERk4wq961AAAASw"]
[Thu Jul 30 15:18:43.940912 2026] [core:notice] [pid 147647:tid 147840] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:44.517341 2026] [security2:error] [pid 147647:tid 147855] [client 20.104.18.253:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/webalfa.php"] [unique_id "amuxpO_ioCvBERk4wq964AAAAVg"]
[Thu Jul 30 15:18:45.144094 2026] [core:notice] [pid 147647:tid 147814] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:45.148222 2026] [security2:error] [pid 147647:tid 147814] [client 66.249.79.229:48147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JGST/article/view/3147/1621"] [unique_id "amuxpO_ioCvBERk4wq966gAAAS8"]
[Thu Jul 30 15:18:45.162571 2026] [security2:error] [pid 147647:tid 147856] [client 20.104.18.253:24861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/webdb.php"] [unique_id "amuxpe_ioCvBERk4wq967wAAAVk"]
[Thu Jul 30 15:18:45.204157 2026] [security2:error] [pid 147647:tid 147838] [client 176.235.182.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxpO_ioCvBERk4wq963wABRzI"], referer: https://allmontecristi.com
[Thu Jul 30 15:18:45.371662 2026] [core:notice] [pid 147647:tid 147896] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:45.375125 2026] [security2:error] [pid 147647:tid 147896] [client 66.249.79.8:45131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Caruban/article/view/8611/3483"] [unique_id "amuxpe_ioCvBERk4wq969wAAAYE"]
[Thu Jul 30 15:18:45.783508 2026] [security2:error] [pid 147647:tid 147806] [client 20.104.18.253:24888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/webk.php"] [unique_id "amuxpe_ioCvBERk4wq96_wAAASc"]
[Thu Jul 30 15:18:46.419339 2026] [security2:error] [pid 147647:tid 147897] [client 20.104.18.253:40599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/webshell.php"] [unique_id "amuxpu_ioCvBERk4wq97EgAAAYI"]
[Thu Jul 30 15:18:46.968022 2026] [core:notice] [pid 147647:tid 147828] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:46.971428 2026] [security2:error] [pid 147647:tid 147828] [client 66.249.79.8:45131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/snpm/article/view/9608/4372"] [unique_id "amuxpu_ioCvBERk4wq97HwAAAT0"]
[Thu Jul 30 15:18:47.072845 2026] [security2:error] [pid 147647:tid 147836] [client 20.104.18.253:40635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/webwp.php"] [unique_id "amuxp-_ioCvBERk4wq97IAAAAUU"]
[Thu Jul 30 15:18:47.402845 2026] [security2:error] [pid 147647:tid 147738] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxp-_ioCvBERk4wq97JwABdlo"]
[Thu Jul 30 15:18:47.403040 2026] [security2:error] [pid 147647:tid 147885] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxp-_ioCvBERk4wq97JwABdlo"]
[Thu Jul 30 15:18:47.466469 2026] [core:notice] [pid 147647:tid 147859] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:47.750867 2026] [security2:error] [pid 147647:tid 147860] [client 20.104.18.253:24839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/weo.php"] [unique_id "amuxp-_ioCvBERk4wq97LAAAAV0"]
[Thu Jul 30 15:18:48.178166 2026] [core:notice] [pid 147647:tid 147891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:48.181818 2026] [security2:error] [pid 147647:tid 147891] [client 66.249.79.229:48147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/view/9249"] [unique_id "amuxqO_ioCvBERk4wq97NgAAAXw"]
[Thu Jul 30 15:18:48.380564 2026] [security2:error] [pid 147647:tid 147903] [client 20.104.18.253:24833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/wg.php"] [unique_id "amuxqO_ioCvBERk4wq97PgAAAYg"]
[Thu Jul 30 15:18:48.629603 2026] [core:notice] [pid 147647:tid 147807] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:49.020743 2026] [security2:error] [pid 147647:tid 147834] [client 20.104.18.253:24850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/whmcs.php"] [unique_id "amuxqe_ioCvBERk4wq97UwAAAUM"]
[Thu Jul 30 15:18:49.130896 2026] [core:notice] [pid 147647:tid 147798] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:49.134110 2026] [security2:error] [pid 147647:tid 147798] [client 66.249.79.229:48147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/view/1136/844"] [unique_id "amuxqe_ioCvBERk4wq97VgAAAR8"]
[Thu Jul 30 15:18:49.380465 2026] [core:notice] [pid 147647:tid 147821] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:49.619375 2026] [security2:error] [pid 147647:tid 147897] [client 172.237.109.114:36935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxqe_ioCvBERk4wq97VQAAAYI"]
[Thu Jul 30 15:18:49.641211 2026] [security2:error] [pid 147647:tid 147904] [client 20.104.18.253:40603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/wi.php"] [unique_id "amuxqe_ioCvBERk4wq97YgAAAYk"]
[Thu Jul 30 15:18:49.769000 2026] [security2:error] [pid 147647:tid 147864] [client 146.103.113.214:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.113.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siatfc.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuxqe_ioCvBERk4wq97YwAAAWE"], referer: https://siatfc.com/contact-page/
[Thu Jul 30 15:18:50.117631 2026] [core:notice] [pid 147647:tid 147779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:50.236722 2026] [security2:error] [pid 147647:tid 147855] [client 20.104.18.253:24854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/widget-logic/mini.php"] [unique_id "amuxqu_ioCvBERk4wq97dgAAAVg"]
[Thu Jul 30 15:18:50.400718 2026] [autoindex:error] [pid 147647:tid 147849] [client 158.158.41.78:21150] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:18:50.459591 2026] [security2:error] [pid 147647:tid 147790] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxqe_ioCvBERk4wq97ZAABF0A"]
[Thu Jul 30 15:18:50.563217 2026] [security2:error] [pid 147647:tid 147827] [client 158.158.41.78:21150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/images/index.php"] [unique_id "amuxqu_ioCvBERk4wq97gQAAATw"]
[Thu Jul 30 15:18:50.856033 2026] [security2:error] [pid 147647:tid 147817] [client 20.104.18.253:24858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/widgets.php"] [unique_id "amuxqu_ioCvBERk4wq97iAAAATI"]
[Thu Jul 30 15:18:51.293872 2026] [security2:error] [pid 147647:tid 147875] [client 74.7.241.171:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rry.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuxq-_ioCvBERk4wq97mAAAAWw"]
[Thu Jul 30 15:18:51.295242 2026] [security2:error] [pid 147647:tid 147871] [client 74.7.241.171:43700] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rry.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuxq-_ioCvBERk4wq97lgABaAA"]
[Thu Jul 30 15:18:51.493804 2026] [security2:error] [pid 147647:tid 147800] [client 20.104.18.253:24627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/widgets/about.php"] [unique_id "amuxq-_ioCvBERk4wq97mgAAASE"]
[Thu Jul 30 15:18:51.639858 2026] [security2:error] [pid 147647:tid 147872] [client 172.237.109.114:9934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxq-_ioCvBERk4wq97kgAAAWk"]
[Thu Jul 30 15:18:52.131807 2026] [security2:error] [pid 147647:tid 147864] [client 20.104.18.253:40631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/widgets/admin.php"] [unique_id "amuxrO_ioCvBERk4wq97rwAAAWE"]
[Thu Jul 30 15:18:52.731003 2026] [security2:error] [pid 147647:tid 147883] [client 20.104.18.253:24891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/widgets/alfa-rex.php"] [unique_id "amuxrO_ioCvBERk4wq97wQAAAXQ"]
[Thu Jul 30 15:18:53.340098 2026] [security2:error] [pid 147647:tid 147817] [client 20.104.18.253:24878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/widgets/autoload_classmap.php"] [unique_id "amuxre_ioCvBERk4wq97zgAAATI"]
[Thu Jul 30 15:18:53.947173 2026] [security2:error] [pid 147647:tid 147821] [client 20.104.18.253:40625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/widgets/browser.php"] [unique_id "amuxre_ioCvBERk4wq972gAAATY"]
[Thu Jul 30 15:18:54.541601 2026] [security2:error] [pid 147647:tid 147788] [client 20.104.18.253:24619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/widgets/bypass.php"] [unique_id "amuxru_ioCvBERk4wq975QAAARU"]
[Thu Jul 30 15:18:54.881925 2026] [autoindex:error] [pid 147647:tid 147777] [client 158.158.41.78:16380] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:18:55.013076 2026] [security2:error] [pid 147647:tid 147890] [client 158.158.41.78:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/asd.php"] [unique_id "amuxr-_ioCvBERk4wq978AAAAXs"]
[Thu Jul 30 15:18:55.153229 2026] [security2:error] [pid 147647:tid 147883] [client 20.104.18.253:24869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fireworkskenya.co.ke"] [uri "/widgets/click.php"] [unique_id "amuxr-_ioCvBERk4wq978QAAAXQ"]
[Thu Jul 30 15:18:56.229143 2026] [core:notice] [pid 147647:tid 147835] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:56.240376 2026] [security2:error] [pid 147647:tid 147669] [remote 52.81.123.237:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fantasynamelist.com"] [uri "/favicon.ico"] [unique_id "amuxsO_ioCvBERk4wq98CQABaxU"], referer: https://fantasynamelist.com/medieval/
[Thu Jul 30 15:18:57.090392 2026] [security2:error] [pid 147647:tid 147846] [client 158.158.41.78:32423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/customize/index.php"] [unique_id "amuxse_ioCvBERk4wq98HQAAAU8"]
[Thu Jul 30 15:18:57.803771 2026] [core:notice] [pid 147647:tid 147856] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:57.809527 2026] [security2:error] [pid 147647:tid 147838] [client 158.158.41.78:15399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuxse_ioCvBERk4wq98LAAAAUc"]
[Thu Jul 30 15:18:57.983090 2026] [security2:error] [pid 147647:tid 147686] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxse_ioCvBERk4wq98NAABWyY"]
[Thu Jul 30 15:18:57.983226 2026] [security2:error] [pid 147647:tid 147858] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxse_ioCvBERk4wq98NAABWyY"]
[Thu Jul 30 15:18:58.256279 2026] [core:notice] [pid 147647:tid 147851] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:58.555235 2026] [security2:error] [pid 147647:tid 147794] [client 95.181.2.156:42541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amuxse_ioCvBERk4wq98KQAAARs"]
[Thu Jul 30 15:18:58.697249 2026] [security2:error] [pid 147647:tid 147859] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxsu_ioCvBERk4wq98NQABXCg"]
[Thu Jul 30 15:18:58.802800 2026] [security2:error] [pid 147647:tid 147887] [client 158.158.41.78:20683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/atomlib.php"] [unique_id "amuxsu_ioCvBERk4wq98RwAAAXg"]
[Thu Jul 30 15:18:58.958039 2026] [core:notice] [pid 147647:tid 147894] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:58.961596 2026] [security2:error] [pid 147647:tid 147894] [client 66.249.79.8:50663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/article/view/9048/3904"] [unique_id "amuxsu_ioCvBERk4wq98TwAAAX8"]
[Thu Jul 30 15:18:59.016099 2026] [security2:error] [pid 147647:tid 147893] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxsu_ioCvBERk4wq98RgAAAX4"]
[Thu Jul 30 15:18:59.147271 2026] [security2:error] [pid 147647:tid 147873] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxsu_ioCvBERk4wq98QwAAAWo"]
[Thu Jul 30 15:18:59.440922 2026] [core:notice] [pid 147647:tid 147800] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:59.443898 2026] [security2:error] [pid 147647:tid 147800] [client 66.249.79.8:50663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/view/2687/3702"] [unique_id "amuxs-_ioCvBERk4wq98VgAAASE"]
[Thu Jul 30 15:18:59.645130 2026] [autoindex:error] [pid 147647:tid 147799] [client 158.158.41.78:28108] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:18:59.838773 2026] [autoindex:error] [pid 147647:tid 147843] [client 158.158.41.78:28108] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:18:59.910586 2026] [core:notice] [pid 147647:tid 147813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:18:59.969423 2026] [security2:error] [pid 147647:tid 147885] [client 158.158.41.78:28108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuxs-_ioCvBERk4wq98ZQAAAXY"]
[Thu Jul 30 15:19:00.258858 2026] [security2:error] [pid 147647:tid 147860] [client 62.102.148.162:51210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuxtO_ioCvBERk4wq98bwAAAV0"]
[Thu Jul 30 15:19:00.259029 2026] [security2:error] [pid 147647:tid 147860] [client 62.102.148.162:51210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuxtO_ioCvBERk4wq98bwAAAV0"]
[Thu Jul 30 15:19:00.546654 2026] [security2:error] [pid 147647:tid 147809] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxs-_ioCvBERk4wq98YwABKiE"]
[Thu Jul 30 15:19:01.427936 2026] [security2:error] [pid 147647:tid 147844] [client 165.16.30.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxtO_ioCvBERk4wq98fAABTTk"], referer: https://allmontecristi.com
[Thu Jul 30 15:19:01.575441 2026] [security2:error] [pid 147647:tid 147783] [client 2a03:2880:f800:2b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxtO_ioCvBERk4wq98gAABEDw"]
[Thu Jul 30 15:19:01.726740 2026] [security2:error] [pid 147647:tid 147877] [client 85.208.96.202:21322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/21/video-solucao-sera-prender-alexandre-de-moraes-diz-desembargador-aposentado-sebastiao-coelho/"] [unique_id "amuxte_ioCvBERk4wq98nQAAAW4"]
[Thu Jul 30 15:19:01.726870 2026] [security2:error] [pid 147647:tid 147877] [client 85.208.96.202:21322] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/21/video-solucao-sera-prender-alexandre-de-moraes-diz-desembargador-aposentado-sebastiao-coelho/"] [unique_id "amuxte_ioCvBERk4wq98nQAAAW4"]
[Thu Jul 30 15:19:01.831199 2026] [security2:error] [pid 147647:tid 147817] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxte_ioCvBERk4wq98jQAAATI"]
[Thu Jul 30 15:19:02.073439 2026] [core:notice] [pid 147647:tid 147790] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:02.077724 2026] [security2:error] [pid 147647:tid 147790] [client 66.249.79.231:37720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/view/4595/2250"] [unique_id "amuxte_ioCvBERk4wq98nwAAARc"]
[Thu Jul 30 15:19:02.367349 2026] [security2:error] [pid 147647:tid 147888] [client 213.152.186.19:55232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuxtu_ioCvBERk4wq98rgAAAXk"]
[Thu Jul 30 15:19:02.367475 2026] [security2:error] [pid 147647:tid 147888] [client 213.152.186.19:55232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuxtu_ioCvBERk4wq98rgAAAXk"]
[Thu Jul 30 15:19:02.484782 2026] [core:notice] [pid 147647:tid 147900] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:02.542268 2026] [autoindex:error] [pid 147647:tid 147793] [client 158.158.41.78:33999] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:19:02.687757 2026] [autoindex:error] [pid 147647:tid 147858] [client 158.158.41.78:33999] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/blocks/block/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:19:02.833825 2026] [autoindex:error] [pid 147647:tid 147849] [client 158.158.41.78:33999] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:19:02.963739 2026] [security2:error] [pid 147647:tid 147883] [client 158.158.41.78:33999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/inputs.php"] [unique_id "amuxtu_ioCvBERk4wq98wQAAAXQ"]
[Thu Jul 30 15:19:04.214168 2026] [security2:error] [pid 147647:tid 147829] [client 66.249.66.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxt-_ioCvBERk4wq98zwABPl4"]
[Thu Jul 30 15:19:04.420821 2026] [core:notice] [pid 147647:tid 147729] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:04.476770 2026] [security2:error] [pid 147647:tid 147784] [client 172.237.109.114:6259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxt-_ioCvBERk4wq981gAAARE"]
[Thu Jul 30 15:19:04.633241 2026] [core:notice] [pid 147647:tid 147865] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:04.713304 2026] [security2:error] [pid 147647:tid 147694] [remote 74.7.243.224:40854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/img/rreportf.php"] [unique_id "amuxuO_ioCvBERk4wq988QABTC4"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/img/main_image_6a2032acb13c3.jpg
[Thu Jul 30 15:19:04.720853 2026] [core:notice] [pid 147647:tid 147755] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:04.995387 2026] [security2:error] [pid 147647:tid 147821] [client 74.208.87.83:65194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "ajakholding.net"] [uri "/"] [unique_id "amuxuO_ioCvBERk4wq989gAAATY"]
[Thu Jul 30 15:19:05.287198 2026] [security2:error] [pid 147647:tid 147879] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxuO_ioCvBERk4wq987QABcFw"]
[Thu Jul 30 15:19:05.403820 2026] [security2:error] [pid 147647:tid 147818] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxuO_ioCvBERk4wq989QAAATM"]
[Thu Jul 30 15:19:05.847389 2026] [core:notice] [pid 147647:tid 147868] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:06.337436 2026] [core:notice] [pid 147647:tid 147834] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:06.383606 2026] [security2:error] [pid 147647:tid 147862] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxue_ioCvBERk4wq99BwABX3E"]
[Thu Jul 30 15:19:06.785503 2026] [security2:error] [pid 147647:tid 147899] [client 158.158.41.78:15383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/index.php"] [unique_id "amuxuu_ioCvBERk4wq99KAAAAYQ"]
[Thu Jul 30 15:19:07.062279 2026] [security2:error] [pid 147647:tid 147880] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxuu_ioCvBERk4wq99HgAAAXE"]
[Thu Jul 30 15:19:07.558543 2026] [security2:error] [pid 147647:tid 147865] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxuu_ioCvBERk4wq99LAAAAWI"]
[Thu Jul 30 15:19:07.827775 2026] [security2:error] [pid 147647:tid 147823] [client 158.158.41.78:43152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/network/index.php"] [unique_id "amuxu-_ioCvBERk4wq99QAAAATg"]
[Thu Jul 30 15:19:08.550846 2026] [security2:error] [pid 147647:tid 147661] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxvO_ioCvBERk4wq99UQABGw0"]
[Thu Jul 30 15:19:08.551002 2026] [security2:error] [pid 147647:tid 147794] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxvO_ioCvBERk4wq99UQABGw0"]
[Thu Jul 30 15:19:08.856536 2026] [core:notice] [pid 147647:tid 147886] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:09.424142 2026] [core:notice] [pid 147647:tid 147649] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:09.616296 2026] [security2:error] [pid 147647:tid 147653] [remote 57.141.0.48:65292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuxve_ioCvBERk4wq99bgABhgU"]
[Thu Jul 30 15:19:10.105267 2026] [security2:error] [pid 147647:tid 147770] [remote 51.161.37.69:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "royalrelaxspa.sbs"] [uri "/robots.txt"] [unique_id "amuxvu_ioCvBERk4wq99eQABLXo"]
[Thu Jul 30 15:19:10.105441 2026] [security2:error] [pid 147647:tid 147812] [client 51.161.37.69:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "royalrelaxspa.sbs"] [uri "/robots.txt"] [unique_id "amuxvu_ioCvBERk4wq99eQABLXo"]
[Thu Jul 30 15:19:10.740788 2026] [security2:error] [pid 147647:tid 147677] [remote 47.128.28.102:49156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/moose-knuckles-jacket-black-10/"] [unique_id "amuxvu_ioCvBERk4wq99hAABFR0"]
[Thu Jul 30 15:19:12.167640 2026] [security2:error] [pid 147647:tid 147799] [client 20.151.221.234:12123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wk/index.php"] [unique_id "amuxwO_ioCvBERk4wq99rAAAASA"]
[Thu Jul 30 15:19:12.351465 2026] [core:notice] [pid 147647:tid 147840] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:12.460647 2026] [security2:error] [pid 147647:tid 147893] [client 172.237.109.114:12826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxv-_ioCvBERk4wq99pgAAAX4"]
[Thu Jul 30 15:19:12.709744 2026] [core:notice] [pid 147647:tid 147691] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:12.713306 2026] [security2:error] [pid 147647:tid 147786] [client 66.249.65.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/223/241"] [unique_id "amuxwO_ioCvBERk4wq99rgABEys"]
[Thu Jul 30 15:19:12.780719 2026] [security2:error] [pid 147647:tid 147887] [client 158.158.41.78:27800] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "raad.pk"] [uri "/wp-content/1.php"] [unique_id "amuxwO_ioCvBERk4wq99ugAAAXg"]
[Thu Jul 30 15:19:12.780841 2026] [security2:error] [pid 147647:tid 147887] [client 158.158.41.78:27800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/1.php"] [unique_id "amuxwO_ioCvBERk4wq99ugAAAXg"]
[Thu Jul 30 15:19:13.012761 2026] [security2:error] [pid 147647:tid 147871] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aws.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuxvO_ioCvBERk4wq99VwAAAWg"]
[Thu Jul 30 15:19:13.013790 2026] [security2:error] [pid 147647:tid 147875] [client 74.7.228.2:37758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aws.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amuxvO_ioCvBERk4wq99UwABbBY"]
[Thu Jul 30 15:19:13.413968 2026] [core:notice] [pid 147647:tid 147828] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:13.417467 2026] [security2:error] [pid 147647:tid 147828] [client 66.249.79.229:62732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/download/1613/1061"] [unique_id "amuxwe_ioCvBERk4wq99xwAAAT0"]
[Thu Jul 30 15:19:13.796314 2026] [security2:error] [pid 147647:tid 147809] [client 20.151.221.234:40905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/av.php"] [unique_id "amuxwe_ioCvBERk4wq990QAAASo"]
[Thu Jul 30 15:19:13.833606 2026] [security2:error] [pid 147647:tid 147804] [client 85.208.96.210:14190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/robots.txt"] [unique_id "amuxwe_ioCvBERk4wq990gAAASU"]
[Thu Jul 30 15:19:13.833726 2026] [security2:error] [pid 147647:tid 147804] [client 85.208.96.210:14190] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jesus.claims"] [uri "/robots.txt"] [unique_id "amuxwe_ioCvBERk4wq990gAAASU"]
[Thu Jul 30 15:19:14.101243 2026] [core:notice] [pid 147647:tid 147785] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:14.624739 2026] [security2:error] [pid 147647:tid 147811] [client 20.151.221.234:40923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/mini.php"] [unique_id "amuxwu_ioCvBERk4wq996gAAASw"]
[Thu Jul 30 15:19:14.641507 2026] [security2:error] [pid 147647:tid 147880] [client 193.233.230.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "azureskyfilms.com"] [uri "/index.php"] [unique_id "amuxwu_ioCvBERk4wq995AAAAXE"]
[Thu Jul 30 15:19:14.879691 2026] [core:notice] [pid 147647:tid 147830] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:15.739125 2026] [core:notice] [pid 147647:tid 147805] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:15.742708 2026] [security2:error] [pid 147647:tid 147805] [client 66.249.79.230:52583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/view/3555"] [unique_id "amuxw-_ioCvBERk4wq99_AAAASY"]
[Thu Jul 30 15:19:15.813877 2026] [security2:error] [pid 147647:tid 147855] [client 185.191.171.4:25298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/favicon-ipad/"] [unique_id "amuxw-_ioCvBERk4wq9-BgAAAVg"]
[Thu Jul 30 15:19:15.814034 2026] [security2:error] [pid 147647:tid 147855] [client 185.191.171.4:25298] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jesus.claims"] [uri "/favicon-ipad/"] [unique_id "amuxw-_ioCvBERk4wq9-BgAAAVg"]
[Thu Jul 30 15:19:15.967825 2026] [core:notice] [pid 147647:tid 147857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:16.446669 2026] [security2:error] [pid 147647:tid 147802] [client 20.151.221.234:40914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/aa.php"] [unique_id "amuxxO_ioCvBERk4wq9-EwAAASM"]
[Thu Jul 30 15:19:16.569714 2026] [core:notice] [pid 147647:tid 147817] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:16.573475 2026] [security2:error] [pid 147647:tid 147817] [client 66.249.79.8:54344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Grage/article/download/830/505"] [unique_id "amuxxO_ioCvBERk4wq9-FAAAATI"]
[Thu Jul 30 15:19:16.689738 2026] [security2:error] [pid 147647:tid 147854] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxxO_ioCvBERk4wq9-CAABVz4"]
[Thu Jul 30 15:19:17.135783 2026] [security2:error] [pid 147647:tid 147734] [remote 216.73.216.51:6201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuxxe_ioCvBERk4wq9-IAABFlY"]
[Thu Jul 30 15:19:17.206257 2026] [security2:error] [pid 147647:tid 147717] [remote 216.73.216.51:6201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuxxe_ioCvBERk4wq9-JAABhkU"]
[Thu Jul 30 15:19:17.372464 2026] [core:notice] [pid 147647:tid 147882] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:17.582560 2026] [security2:error] [pid 147647:tid 147834] [client 20.151.221.234:40926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/w.php"] [unique_id "amuxxe_ioCvBERk4wq9-LAAAAUM"]
[Thu Jul 30 15:19:17.589252 2026] [core:notice] [pid 147647:tid 147840] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:17.914549 2026] [security2:error] [pid 147647:tid 147860] [client 158.158.41.78:10026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/plugin.php"] [unique_id "amuxxe_ioCvBERk4wq9-PAAAAV0"]
[Thu Jul 30 15:19:18.219058 2026] [security2:error] [pid 147647:tid 147737] [remote 216.73.216.51:6201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuxxu_ioCvBERk4wq9-QQABcFk"]
[Thu Jul 30 15:19:18.648804 2026] [security2:error] [pid 147647:tid 147818] [client 20.151.221.234:55774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/admin.php"] [unique_id "amuxxu_ioCvBERk4wq9-SQAAATM"]
[Thu Jul 30 15:19:19.114861 2026] [security2:error] [pid 147647:tid 147851] [client 158.158.41.78:19369] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "raad.pk"] [uri "/1.php"] [unique_id "amuxx-_ioCvBERk4wq9-WAAAAVQ"]
[Thu Jul 30 15:19:19.115006 2026] [security2:error] [pid 147647:tid 147851] [client 158.158.41.78:19369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/1.php"] [unique_id "amuxx-_ioCvBERk4wq9-WAAAAVQ"]
[Thu Jul 30 15:19:19.157749 2026] [security2:error] [pid 147647:tid 147742] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxx-_ioCvBERk4wq9-WQABQF4"]
[Thu Jul 30 15:19:19.157949 2026] [security2:error] [pid 147647:tid 147831] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuxx-_ioCvBERk4wq9-WQABQF4"]
[Thu Jul 30 15:19:19.456714 2026] [security2:error] [pid 147647:tid 147886] [client 172.237.109.114:10428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuxxu_ioCvBERk4wq9-VwAAAXc"]
[Thu Jul 30 15:19:20.176132 2026] [core:notice] [pid 147647:tid 147821] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:20.198307 2026] [core:error] [pid 147647:tid 147821] [client 66.249.79.229:43176] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:20.198561 2026] [security2:error] [pid 147647:tid 147821] [client 66.249.79.229:43176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/3350/1771.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuxyO_ioCvBERk4wq9-eAAAATY"]
[Thu Jul 30 15:19:20.320563 2026] [security2:error] [pid 147647:tid 147850] [client 158.158.41.78:9994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/gg.php"] [unique_id "amuxyO_ioCvBERk4wq9-fAAAAVM"]
[Thu Jul 30 15:19:20.422778 2026] [core:notice] [pid 147647:tid 147891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:20.426366 2026] [security2:error] [pid 147647:tid 147891] [client 66.249.79.8:54344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/download/4892/2298"] [unique_id "amuxyO_ioCvBERk4wq9-gQAAAXw"]
[Thu Jul 30 15:19:20.760332 2026] [security2:error] [pid 147647:tid 147813] [client 2a03:2880:f800:36:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxyO_ioCvBERk4wq9-dgABLmI"]
[Thu Jul 30 15:19:21.226335 2026] [security2:error] [pid 147647:tid 147765] [remote 216.73.216.51:6201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuxye_ioCvBERk4wq9-lgABVHU"]
[Thu Jul 30 15:19:21.259483 2026] [security2:error] [pid 147647:tid 147822] [client 20.151.221.234:12143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuxye_ioCvBERk4wq9-lwAAATc"]
[Thu Jul 30 15:19:21.753893 2026] [security2:error] [pid 147647:tid 147760] [remote 216.73.216.51:6201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuxye_ioCvBERk4wq9-pwABVnA"]
[Thu Jul 30 15:19:22.065951 2026] [core:error] [pid 147647:tid 147824] [client 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:22.065984 2026] [core:error] [pid 147647:tid 147824] [client 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:22.719934 2026] [core:notice] [pid 147647:tid 147733] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:22.803898 2026] [core:error] [pid 147647:tid 147659] [remote 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:22.803923 2026] [core:error] [pid 147647:tid 147659] [remote 87.99.136.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:23.000098 2026] [core:notice] [pid 147647:tid 147656] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:23.325607 2026] [security2:error] [pid 147647:tid 147842] [client 2a03:2880:f800:15:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxyu_ioCvBERk4wq9-vgABSw8"]
[Thu Jul 30 15:19:23.674678 2026] [core:notice] [pid 147647:tid 147788] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:23.933226 2026] [core:notice] [pid 147647:tid 147827] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:23.936722 2026] [security2:error] [pid 147647:tid 147827] [client 66.249.79.229:53731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/3928/1968"] [unique_id "amuxy-_ioCvBERk4wq9-4AAAATw"]
[Thu Jul 30 15:19:24.236344 2026] [security2:error] [pid 147647:tid 147662] [remote 216.73.216.51:6201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuxzO_ioCvBERk4wq9-7AABhg4"]
[Thu Jul 30 15:19:24.367451 2026] [core:notice] [pid 147647:tid 147834] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:24.370953 2026] [security2:error] [pid 147647:tid 147834] [client 66.249.79.229:53731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jibm/article/view/690"] [unique_id "amuxzO_ioCvBERk4wq9-8QAAAUM"]
[Thu Jul 30 15:19:24.404837 2026] [autoindex:error] [pid 147647:tid 147838] [client 158.158.41.78:20690] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/images/crystal/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:19:24.534873 2026] [security2:error] [pid 147647:tid 147814] [client 158.158.41.78:20690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp.php"] [unique_id "amuxzO_ioCvBERk4wq9-9gAAAS8"]
[Thu Jul 30 15:19:24.708742 2026] [security2:error] [pid 147647:tid 147806] [client 20.151.221.234:55751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/m.php"] [unique_id "amuxzO_ioCvBERk4wq9-_QAAASc"]
[Thu Jul 30 15:19:24.825824 2026] [core:notice] [pid 147647:tid 147848] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:24.829730 2026] [security2:error] [pid 147647:tid 147848] [client 66.249.79.229:53731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3905/1944"] [unique_id "amuxzO_ioCvBERk4wq9_BwAAAVE"]
[Thu Jul 30 15:19:24.921076 2026] [security2:error] [pid 147647:tid 147843] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxzO_ioCvBERk4wq9-8AAAAUw"]
[Thu Jul 30 15:19:25.106750 2026] [security2:error] [pid 147647:tid 147685] [remote 57.141.0.69:34220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7374488921/feed/rss2/"] [unique_id "amuxze_ioCvBERk4wq9_DAABQiU"]
[Thu Jul 30 15:19:25.597267 2026] [core:notice] [pid 147647:tid 147679] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:25.634219 2026] [core:notice] [pid 147647:tid 147866] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:25.637808 2026] [security2:error] [pid 147647:tid 147866] [client 66.249.79.229:53731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/1958/1227"] [unique_id "amuxze_ioCvBERk4wq9_HAAAAWM"]
[Thu Jul 30 15:19:25.742152 2026] [security2:error] [pid 147647:tid 147686] [remote 216.73.216.51:6201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuxze_ioCvBERk4wq9_IAABVyY"]
[Thu Jul 30 15:19:25.763999 2026] [security2:error] [pid 147647:tid 147867] [client 20.151.221.234:11348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuxze_ioCvBERk4wq9_FwAAAWQ"]
[Thu Jul 30 15:19:26.680487 2026] [core:notice] [pid 147647:tid 147894] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:26.687702 2026] [core:error] [pid 147647:tid 147863] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://chimnify.services/
[Thu Jul 30 15:19:26.687724 2026] [core:error] [pid 147647:tid 147863] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://chimnify.services/
[Thu Jul 30 15:19:27.050298 2026] [security2:error] [pid 147647:tid 147846] [client 2a03:2880:f800:20:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuxzu_ioCvBERk4wq9_MgABTxo"]
[Thu Jul 30 15:19:27.207797 2026] [security2:error] [pid 147647:tid 147904] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuxzu_ioCvBERk4wq9_OgAAAYk"]
[Thu Jul 30 15:19:27.281269 2026] [security2:error] [pid 147647:tid 147899] [client 43.157.170.126:51328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.170.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuxz-_ioCvBERk4wq9_SgAAAYQ"]
[Thu Jul 30 15:19:27.478718 2026] [core:notice] [pid 147647:tid 147828] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:27.482204 2026] [security2:error] [pid 147647:tid 147828] [client 66.249.79.229:53731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JSTE/article/view/6034/2626"] [unique_id "amuxz-_ioCvBERk4wq9_TgAAAT0"]
[Thu Jul 30 15:19:27.747864 2026] [security2:error] [pid 147647:tid 147713] [remote 216.73.216.51:6201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuxz-_ioCvBERk4wq9_VgABaUE"]
[Thu Jul 30 15:19:28.241648 2026] [core:error] [pid 147647:tid 147814] [client 45.249.89.53:58089] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:28.241669 2026] [core:error] [pid 147647:tid 147814] [client 45.249.89.53:58089] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:28.399750 2026] [core:error] [pid 147647:tid 147823] [client 138.124.103.234:48752] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:28.399779 2026] [core:error] [pid 147647:tid 147823] [client 138.124.103.234:48752] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:28.544915 2026] [security2:error] [pid 147647:tid 147894] [client 20.151.221.234:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/classwithtostring.php"] [unique_id "amux0O_ioCvBERk4wq9_cQAAAX8"]
[Thu Jul 30 15:19:28.804582 2026] [core:error] [pid 147647:tid 147811] [client 64.227.104.105:37460] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:28.804624 2026] [core:error] [pid 147647:tid 147811] [client 64.227.104.105:37460] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:28.872742 2026] [core:notice] [pid 147647:tid 147715] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:28.998741 2026] [core:notice] [pid 147647:tid 147859] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:29.004634 2026] [security2:error] [pid 147647:tid 147859] [client 66.249.79.8:37519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/article/view/4885/2294"] [unique_id "amux0O_ioCvBERk4wq9_fwAAAVw"]
[Thu Jul 30 15:19:29.232130 2026] [core:notice] [pid 147647:tid 147793] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:29.341894 2026] [security2:error] [pid 147647:tid 147818] [client 20.151.221.234:11355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/gmo.php"] [unique_id "amux0e_ioCvBERk4wq9_hwAAATM"]
[Thu Jul 30 15:19:29.469005 2026] [security2:error] [pid 147647:tid 147825] [client 158.158.41.78:15600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/blocks/about.php"] [unique_id "amux0e_ioCvBERk4wq9_jAAAATo"]
[Thu Jul 30 15:19:29.644333 2026] [security2:error] [pid 147647:tid 147899] [client 45.249.89.53:59949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amux0e_ioCvBERk4wq9_kAAAAYQ"]
[Thu Jul 30 15:19:29.785563 2026] [security2:error] [pid 147647:tid 147727] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux0e_ioCvBERk4wq9_lAABPU8"]
[Thu Jul 30 15:19:29.785714 2026] [security2:error] [pid 147647:tid 147828] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux0e_ioCvBERk4wq9_lAABPU8"]
[Thu Jul 30 15:19:29.897052 2026] [security2:error] [pid 147647:tid 147820] [client 138.124.103.234:48754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amux0e_ioCvBERk4wq9_lQAAATU"]
[Thu Jul 30 15:19:29.921066 2026] [core:notice] [pid 147647:tid 147731] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:30.017826 2026] [core:error] [pid 147647:tid 147788] [client 45.249.89.53:59949] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:30.017849 2026] [core:error] [pid 147647:tid 147788] [client 45.249.89.53:59949] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:30.187921 2026] [core:error] [pid 147647:tid 147816] [client 138.124.103.234:48754] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:30.187949 2026] [core:error] [pid 147647:tid 147816] [client 138.124.103.234:48754] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:30.262744 2026] [security2:error] [pid 147647:tid 147872] [client 64.227.104.105:38734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amux0u_ioCvBERk4wq9_ngAAAWk"]
[Thu Jul 30 15:19:30.487633 2026] [security2:error] [pid 147647:tid 147829] [client 172.237.109.114:29420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amux0u_ioCvBERk4wq9_mgAAAT4"]
[Thu Jul 30 15:19:30.608556 2026] [core:error] [pid 147647:tid 147885] [client 64.227.104.105:38734] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:30.608588 2026] [core:error] [pid 147647:tid 147885] [client 64.227.104.105:38734] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:30.677650 2026] [security2:error] [pid 147647:tid 147802] [client 172.237.109.114:52308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amux0u_ioCvBERk4wq9_nAAAASM"]
[Thu Jul 30 15:19:30.778940 2026] [security2:error] [pid 147647:tid 147827] [client 20.151.221.234:11963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/languages/index.php"] [unique_id "amux0u_ioCvBERk4wq9_qAAAATw"]
[Thu Jul 30 15:19:31.411016 2026] [core:error] [pid 147647:tid 147894] [client 45.249.89.53:60644] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:31.411041 2026] [core:error] [pid 147647:tid 147894] [client 45.249.89.53:60644] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:31.429235 2026] [security2:error] [pid 147647:tid 147879] [client 172.237.109.114:22747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amux0u_ioCvBERk4wq9_rwAAAXA"]
[Thu Jul 30 15:19:31.516421 2026] [core:error] [pid 147647:tid 147900] [client 138.124.103.234:48756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:31.516451 2026] [core:error] [pid 147647:tid 147900] [client 138.124.103.234:48756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:31.807207 2026] [core:notice] [pid 147647:tid 147883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:31.811076 2026] [security2:error] [pid 147647:tid 147883] [client 66.249.79.8:37519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Deiksis/article/view/1144"] [unique_id "amux0-_ioCvBERk4wq9_uwAAAXQ"]
[Thu Jul 30 15:19:31.926095 2026] [security2:error] [pid 147647:tid 147804] [client 158.158.41.78:19383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/file.php"] [unique_id "amux0-_ioCvBERk4wq9_xAAAASU"]
[Thu Jul 30 15:19:32.052078 2026] [core:notice] [pid 147647:tid 147881] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:32.077128 2026] [core:error] [pid 147647:tid 147813] [client 64.227.104.105:38746] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:32.077152 2026] [core:error] [pid 147647:tid 147813] [client 64.227.104.105:38746] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:32.726643 2026] [core:error] [pid 147647:tid 147820] [client 138.124.103.234:48760] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:32.726673 2026] [core:error] [pid 147647:tid 147820] [client 138.124.103.234:48760] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:32.797302 2026] [core:error] [pid 147647:tid 147822] [client 45.249.89.53:61152] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:32.797324 2026] [core:error] [pid 147647:tid 147822] [client 45.249.89.53:61152] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:33.066183 2026] [security2:error] [pid 147647:tid 147821] [client 20.151.221.234:11376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-the.php"] [unique_id "amux1e_ioCvBERk4wq9_4wAAATY"]
[Thu Jul 30 15:19:33.091950 2026] [core:notice] [pid 147647:tid 147798] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:33.095669 2026] [security2:error] [pid 147647:tid 147798] [client 66.249.79.8:37519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/download/3260/1671"] [unique_id "amux1e_ioCvBERk4wq9_5AAAAR8"]
[Thu Jul 30 15:19:33.338435 2026] [security2:error] [pid 147647:tid 147849] [client 216.244.66.236:59694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amux1e_ioCvBERk4wq9_6gAAAVI"]
[Thu Jul 30 15:19:33.338534 2026] [security2:error] [pid 147647:tid 147849] [client 216.244.66.236:59694] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dhowcruisedinner.com"] [uri "/robots.txt"] [unique_id "amux1e_ioCvBERk4wq9_6gAAAVI"]
[Thu Jul 30 15:19:33.561072 2026] [security2:error] [pid 147647:tid 147752] [remote 40.77.167.243:59249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/distribution-des-kits-hygieniques-reutilisation-pour-la-gestion-du-cycle-menstruel/article.php"] [unique_id "amux1e_ioCvBERk4wq9_9QABYmg"]
[Thu Jul 30 15:19:33.672652 2026] [core:error] [pid 147647:tid 147858] [client 64.227.104.105:38756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:33.672694 2026] [core:error] [pid 147647:tid 147858] [client 64.227.104.105:38756] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:33.768537 2026] [security2:error] [pid 147647:tid 147744] [remote 40.77.167.243:59249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/%E0%B8%A7%E0%B8%B4%E0%B8%98%E0%B8%B5%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B9%80%E0%B8%82%E0%B8%B5%E0%B8%A2%E0%B8%99%E0%B8%9A%E0%B8%A3%E0%B8%A3%E0%B8%93%E0%B8%B2%E0%B8%99%E0%B8%B8%E0%B8%81%E0%B8%A3%E0%B8%A1/article.php"] [unique_id "amux1e_ioCvBERk4wq9_-AABTWA"]
[Thu Jul 30 15:19:33.868920 2026] [core:notice] [pid 147647:tid 147803] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:34.078561 2026] [security2:error] [pid 147647:tid 147856] [client 20.151.221.234:11380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/404.php"] [unique_id "amux1u_ioCvBERk4wq-ABwAAAVk"]
[Thu Jul 30 15:19:34.082237 2026] [security2:error] [pid 147647:tid 147772] [remote 40.77.167.243:59249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/19826089/article.php"] [unique_id "amux1u_ioCvBERk4wq-ACAABKnw"]
[Thu Jul 30 15:19:34.216724 2026] [core:error] [pid 147647:tid 147846] [client 45.249.89.53:61670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:34.216747 2026] [core:error] [pid 147647:tid 147846] [client 45.249.89.53:61670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:34.303477 2026] [core:error] [pid 147647:tid 147835] [client 138.124.103.234:58386] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:34.303501 2026] [core:error] [pid 147647:tid 147835] [client 138.124.103.234:58386] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:34.958947 2026] [core:notice] [pid 147647:tid 147784] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:35.202332 2026] [core:error] [pid 147647:tid 147785] [client 64.227.104.105:38766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:35.202360 2026] [core:error] [pid 147647:tid 147785] [client 64.227.104.105:38766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:35.602817 2026] [core:error] [pid 147647:tid 147882] [client 45.249.89.53:62265] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:35.602841 2026] [core:error] [pid 147647:tid 147882] [client 45.249.89.53:62265] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:35.692151 2026] [core:error] [pid 147647:tid 147887] [client 138.124.103.234:58396] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:35.692174 2026] [core:error] [pid 147647:tid 147887] [client 138.124.103.234:58396] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:36.392792 2026] [core:error] [pid 147647:tid 147841] [client 139.59.102.20:15050] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:36.392819 2026] [core:error] [pid 147647:tid 147841] [client 139.59.102.20:15050] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:36.508039 2026] [security2:error] [pid 147647:tid 147829] [client 20.151.221.234:43275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/init.php"] [unique_id "amux2O_ioCvBERk4wq-APAAAAT4"]
[Thu Jul 30 15:19:36.630647 2026] [core:error] [pid 147647:tid 147815] [client 64.227.104.105:38776] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:36.630669 2026] [core:error] [pid 147647:tid 147815] [client 64.227.104.105:38776] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:36.788625 2026] [security2:error] [pid 147647:tid 147833] [client 158.158.41.78:23823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/user/index.php"] [unique_id "amux2O_ioCvBERk4wq-ARQAAAUI"]
[Thu Jul 30 15:19:36.852572 2026] [core:notice] [pid 147647:tid 147890] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:36.917396 2026] [core:notice] [pid 147647:tid 147881] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:37.018035 2026] [core:error] [pid 147647:tid 147898] [client 45.249.89.53:62822] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:37.018071 2026] [core:error] [pid 147647:tid 147898] [client 45.249.89.53:62822] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:37.087533 2026] [core:error] [pid 147647:tid 147861] [client 138.124.103.234:58410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:37.087552 2026] [core:error] [pid 147647:tid 147861] [client 138.124.103.234:58410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:37.898267 2026] [security2:error] [pid 147647:tid 147824] [client 20.151.221.234:11956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/file5.php"] [unique_id "amux2e_ioCvBERk4wq-AYQAAATk"]
[Thu Jul 30 15:19:37.973875 2026] [core:error] [pid 147647:tid 147801] [client 64.227.104.105:38792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:37.973900 2026] [core:error] [pid 147647:tid 147801] [client 64.227.104.105:38792] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:38.172010 2026] [core:notice] [pid 147647:tid 147863] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:38.350690 2026] [core:error] [pid 147647:tid 147862] [client 138.124.103.234:58416] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:38.350912 2026] [core:error] [pid 147647:tid 147862] [client 138.124.103.234:58416] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:38.411463 2026] [core:error] [pid 147647:tid 147875] [client 45.249.89.53:63351] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:38.411493 2026] [core:error] [pid 147647:tid 147875] [client 45.249.89.53:63351] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:39.270777 2026] [security2:error] [pid 147647:tid 147890] [client 20.151.221.234:11934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amux2-_ioCvBERk4wq-AhgAAAXs"]
[Thu Jul 30 15:19:39.305796 2026] [security2:error] [pid 147647:tid 147675] [remote 57.141.0.67:34370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amux2-_ioCvBERk4wq-AiAABgxs"]
[Thu Jul 30 15:19:39.335827 2026] [core:notice] [pid 147647:tid 147884] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:39.473559 2026] [core:error] [pid 147647:tid 147788] [client 64.227.104.105:38582] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:39.473586 2026] [core:error] [pid 147647:tid 147788] [client 64.227.104.105:38582] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:39.603650 2026] [security2:error] [pid 147647:tid 147881] [client 172.237.109.114:25189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amux2-_ioCvBERk4wq-AfQAAAXI"]
[Thu Jul 30 15:19:39.683307 2026] [core:notice] [pid 147647:tid 147877] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:39.709953 2026] [core:notice] [pid 147647:tid 147888] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:39.728057 2026] [security2:error] [pid 147647:tid 147845] [client 57.141.0.38:29384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amux2-_ioCvBERk4wq-AigABThw"], referer: https://igetvape-australia.com/product/bar-plus-s3-kit-lemonade-monster/
[Thu Jul 30 15:19:39.729285 2026] [security2:error] [pid 147647:tid 147880] [client 138.124.103.234:58430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env.backup"] [unique_id "amux2-_ioCvBERk4wq-AkgAAAXE"]
[Thu Jul 30 15:19:39.812153 2026] [security2:error] [pid 147647:tid 147799] [client 45.249.89.53:63945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env.backup"] [unique_id "amux2-_ioCvBERk4wq-AlwAAASA"]
[Thu Jul 30 15:19:39.980485 2026] [security2:error] [pid 147647:tid 147843] [client 158.158.41.78:22823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "raad.pk"] [uri "/index.php"] [unique_id "amux2-_ioCvBERk4wq-AjAAAAUw"]
[Thu Jul 30 15:19:40.005608 2026] [core:error] [pid 147647:tid 147832] [client 138.124.103.234:58430] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:40.005635 2026] [core:error] [pid 147647:tid 147832] [client 138.124.103.234:58430] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:40.115110 2026] [core:notice] [pid 147647:tid 147860] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:40.131773 2026] [core:notice] [pid 147647:tid 147787] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:40.188933 2026] [core:error] [pid 147647:tid 147782] [client 45.249.89.53:63945] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:40.188952 2026] [core:error] [pid 147647:tid 147782] [client 45.249.89.53:63945] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:40.320354 2026] [security2:error] [pid 147647:tid 147896] [client 158.158.41.78:22823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amux3O_ioCvBERk4wq-ApgAAAYE"]
[Thu Jul 30 15:19:40.539374 2026] [core:notice] [pid 147647:tid 147811] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:40.546106 2026] [security2:error] [pid 147647:tid 147779] [client 20.151.221.234:11370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/shell.php"] [unique_id "amux3O_ioCvBERk4wq-AqwAAAQw"]
[Thu Jul 30 15:19:40.547593 2026] [security2:error] [pid 147647:tid 147774] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux3O_ioCvBERk4wq-ArAABhX4"]
[Thu Jul 30 15:19:40.547707 2026] [security2:error] [pid 147647:tid 147900] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux3O_ioCvBERk4wq-ArAABhX4"]
[Thu Jul 30 15:19:40.630888 2026] [core:notice] [pid 147647:tid 147838] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:40.936893 2026] [security2:error] [pid 147647:tid 147857] [client 64.227.104.105:38584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/.env.backup"] [unique_id "amux3O_ioCvBERk4wq-AugAAAVo"]
[Thu Jul 30 15:19:40.941569 2026] [core:notice] [pid 147647:tid 147841] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:41.313320 2026] [core:notice] [pid 147647:tid 147902] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:41.329706 2026] [security2:error] [pid 147647:tid 147833] [client 138.124.103.234:58432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env.old"] [unique_id "amux3e_ioCvBERk4wq-AwwAAAUI"]
[Thu Jul 30 15:19:41.473072 2026] [security2:error] [pid 147647:tid 147829] [client 158.158.41.78:24124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/index/function.php"] [unique_id "amux3e_ioCvBERk4wq-AygAAAT4"]
[Thu Jul 30 15:19:41.577225 2026] [security2:error] [pid 147647:tid 147836] [client 45.249.89.53:64666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env.old"] [unique_id "amux3e_ioCvBERk4wq-AzAAAAUU"]
[Thu Jul 30 15:19:41.577534 2026] [core:error] [pid 147647:tid 147903] [client 64.227.104.105:38584] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:41.577547 2026] [core:error] [pid 147647:tid 147903] [client 64.227.104.105:38584] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:41.581393 2026] [core:notice] [pid 147647:tid 147866] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:41.585139 2026] [security2:error] [pid 147647:tid 147866] [client 66.249.79.229:37315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/582/363"] [unique_id "amux3e_ioCvBERk4wq-AzQAAAWM"]
[Thu Jul 30 15:19:41.601286 2026] [security2:error] [pid 147647:tid 147784] [client 138.124.103.234:58432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env.bak"] [unique_id "amux3e_ioCvBERk4wq-AzwAAARE"]
[Thu Jul 30 15:19:41.674916 2026] [security2:error] [pid 147647:tid 147822] [client 20.151.221.234:11343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/f35.php"] [unique_id "amux3e_ioCvBERk4wq-A0AAAATc"]
[Thu Jul 30 15:19:41.701168 2026] [core:notice] [pid 147647:tid 147797] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:41.812755 2026] [core:notice] [pid 147647:tid 147888] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:41.834233 2026] [core:notice] [pid 147647:tid 147696] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:41.879730 2026] [core:error] [pid 147647:tid 147777] [client 138.124.103.234:58432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:41.879752 2026] [core:error] [pid 147647:tid 147777] [client 138.124.103.234:58432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:41.951485 2026] [security2:error] [pid 147647:tid 147821] [client 45.249.89.53:64666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env.bak"] [unique_id "amux3e_ioCvBERk4wq-A3QAAATY"]
[Thu Jul 30 15:19:42.100516 2026] [core:notice] [pid 147647:tid 147824] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:42.263275 2026] [core:notice] [pid 147647:tid 147840] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:42.266759 2026] [security2:error] [pid 147647:tid 147840] [client 66.249.79.229:37315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/334/217"] [unique_id "amux3u_ioCvBERk4wq-A3wAAAUk"]
[Thu Jul 30 15:19:42.321128 2026] [core:error] [pid 147647:tid 147843] [client 45.249.89.53:64666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:42.321150 2026] [core:error] [pid 147647:tid 147843] [client 45.249.89.53:64666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:42.471621 2026] [core:notice] [pid 147647:tid 147782] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:42.807593 2026] [core:notice] [pid 147647:tid 147876] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:42.918820 2026] [core:notice] [pid 147647:tid 147793] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:43.030315 2026] [security2:error] [pid 147647:tid 147875] [client 64.227.104.105:38586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/.env.old"] [unique_id "amux3-_ioCvBERk4wq-A_AAAAWw"]
[Thu Jul 30 15:19:43.170221 2026] [autoindex:error] [pid 147647:tid 147799] [client 158.158.41.78:43146] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:19:43.182739 2026] [security2:error] [pid 147647:tid 147868] [client 20.151.221.234:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/new.php"] [unique_id "amux3-_ioCvBERk4wq-A_gAAAWU"]
[Thu Jul 30 15:19:43.270272 2026] [security2:error] [pid 147647:tid 147811] [client 138.124.103.234:57672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env.swp"] [unique_id "amux3-_ioCvBERk4wq-A_wAAASw"]
[Thu Jul 30 15:19:43.308649 2026] [security2:error] [pid 147647:tid 147808] [client 110.249.201.145:47928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/robots.txt"] [unique_id "amux3-_ioCvBERk4wq-BAQAAASk"]
[Thu Jul 30 15:19:43.318456 2026] [autoindex:error] [pid 147647:tid 147809] [client 158.158.41.78:43146] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:19:43.447582 2026] [security2:error] [pid 147647:tid 147854] [client 64.227.104.105:38586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/.env.bak"] [unique_id "amux3-_ioCvBERk4wq-BCAAAAVc"]
[Thu Jul 30 15:19:43.451575 2026] [security2:error] [pid 147647:tid 147873] [client 158.158.41.78:43146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/aaa.php"] [unique_id "amux3-_ioCvBERk4wq-BCQAAAWo"]
[Thu Jul 30 15:19:43.552099 2026] [security2:error] [pid 147647:tid 147874] [client 138.124.103.234:57672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env~"] [unique_id "amux3-_ioCvBERk4wq-BDQAAAWs"]
[Thu Jul 30 15:19:43.701173 2026] [security2:error] [pid 147647:tid 147869] [client 45.249.89.53:65515] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env.swp"] [unique_id "amux3-_ioCvBERk4wq-BDgAAAWY"]
[Thu Jul 30 15:19:43.823149 2026] [core:error] [pid 147647:tid 147789] [client 138.124.103.234:57672] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:43.823176 2026] [core:error] [pid 147647:tid 147789] [client 138.124.103.234:57672] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:43.863670 2026] [security2:error] [pid 147647:tid 147867] [client 20.226.5.174:35987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/011i.php"] [unique_id "amux3-_ioCvBERk4wq-BEAAAAWQ"]
[Thu Jul 30 15:19:43.894365 2026] [core:error] [pid 147647:tid 147820] [client 64.227.104.105:38586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:43.894383 2026] [core:error] [pid 147647:tid 147820] [client 64.227.104.105:38586] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:44.070407 2026] [security2:error] [pid 147647:tid 147881] [client 45.249.89.53:65515] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env~"] [unique_id "amux4O_ioCvBERk4wq-BGwAAAXI"]
[Thu Jul 30 15:19:44.151276 2026] [security2:error] [pid 147647:tid 147842] [client 20.151.221.234:11905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/adminfuns.php"] [unique_id "amux4O_ioCvBERk4wq-BHAAAAUs"]
[Thu Jul 30 15:19:44.437441 2026] [core:error] [pid 147647:tid 147845] [client 45.249.89.53:65515] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:44.437465 2026] [core:error] [pid 147647:tid 147845] [client 45.249.89.53:65515] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:44.542611 2026] [core:notice] [pid 147647:tid 147791] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:44.993942 2026] [core:notice] [pid 147647:tid 147807] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:44.997426 2026] [security2:error] [pid 147647:tid 147807] [client 66.249.79.229:37315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/download/5835/2567"] [unique_id "amux4O_ioCvBERk4wq-BLAAAASg"]
[Thu Jul 30 15:19:45.020752 2026] [security2:error] [pid 147647:tid 147843] [client 144.31.143.114:34428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-30643359.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amux4e_ioCvBERk4wq-BLgAAAUw"]
[Thu Jul 30 15:19:45.321870 2026] [core:error] [pid 147647:tid 147787] [client 138.124.103.234:57684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:45.321893 2026] [core:error] [pid 147647:tid 147787] [client 138.124.103.234:57684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:45.333687 2026] [security2:error] [pid 147647:tid 147849] [client 64.227.104.105:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/.env.swp"] [unique_id "amux4e_ioCvBERk4wq-BNwAAAVI"]
[Thu Jul 30 15:19:45.336704 2026] [security2:error] [pid 147647:tid 147860] [client 20.226.5.174:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/03a005685d.php"] [unique_id "amux4e_ioCvBERk4wq-BOAAAAV0"]
[Thu Jul 30 15:19:45.675972 2026] [security2:error] [pid 147647:tid 147815] [client 20.151.221.234:11945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/fm.php"] [unique_id "amux4e_ioCvBERk4wq-BRAAAATA"]
[Thu Jul 30 15:19:45.740257 2026] [security2:error] [pid 147647:tid 147837] [client 64.227.104.105:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/.env~"] [unique_id "amux4e_ioCvBERk4wq-BRQAAAUY"]
[Thu Jul 30 15:19:45.790833 2026] [core:notice] [pid 147647:tid 147796] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:45.820515 2026] [core:error] [pid 147647:tid 147865] [client 45.249.89.53:50020] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:45.820535 2026] [core:error] [pid 147647:tid 147865] [client 45.249.89.53:50020] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:46.222433 2026] [core:error] [pid 147647:tid 147890] [client 64.227.104.105:38602] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:46.222456 2026] [core:error] [pid 147647:tid 147890] [client 64.227.104.105:38602] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:46.601633 2026] [core:error] [pid 147647:tid 147792] [client 138.124.103.234:57696] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:46.601659 2026] [core:error] [pid 147647:tid 147792] [client 138.124.103.234:57696] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:46.819010 2026] [security2:error] [pid 147647:tid 147866] [client 20.151.221.234:12275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/file.php"] [unique_id "amux4u_ioCvBERk4wq-BXQAAAWM"]
[Thu Jul 30 15:19:46.918814 2026] [security2:error] [pid 147647:tid 147780] [client 20.226.5.174:35979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/403.php"] [unique_id "amux4u_ioCvBERk4wq-BXgAAAQ0"]
[Thu Jul 30 15:19:47.211926 2026] [core:error] [pid 147647:tid 147878] [client 45.249.89.53:50606] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:47.211950 2026] [core:error] [pid 147647:tid 147878] [client 45.249.89.53:50606] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:47.250555 2026] [core:notice] [pid 147647:tid 147791] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:47.491634 2026] [security2:error] [pid 147647:tid 147852] [client 172.237.109.114:3748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amux4u_ioCvBERk4wq-BYgAAAVU"]
[Thu Jul 30 15:19:47.685264 2026] [security2:error] [pid 147647:tid 147842] [client 172.237.109.114:54181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amux4-_ioCvBERk4wq-BZgAAAUs"]
[Thu Jul 30 15:19:47.721860 2026] [core:error] [pid 147647:tid 147785] [client 64.227.104.105:38610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:47.721890 2026] [core:error] [pid 147647:tid 147785] [client 64.227.104.105:38610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:47.835360 2026] [security2:error] [pid 147647:tid 147844] [client 20.151.221.234:53844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/bolt.php"] [unique_id "amux4-_ioCvBERk4wq-BewAAAU0"]
[Thu Jul 30 15:19:47.853023 2026] [security2:error] [pid 147647:tid 147743] [remote 74.7.227.39:57504] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amux4-_ioCvBERk4wq-BfQABSV8"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/elementskit-lite
[Thu Jul 30 15:19:47.877128 2026] [security2:error] [pid 147647:tid 147850] [client 74.7.244.63:33620] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ooj.hfl.temporary.site"] [uri "/index.php"] [unique_id "amux4-_ioCvBERk4wq-BcwABU1Q"]
[Thu Jul 30 15:19:47.936518 2026] [core:error] [pid 147647:tid 147847] [client 138.124.103.234:57710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:47.936727 2026] [core:error] [pid 147647:tid 147847] [client 138.124.103.234:57710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:48.134841 2026] [security2:error] [pid 147647:tid 147883] [client 20.226.5.174:35975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/404.php"] [unique_id "amux5O_ioCvBERk4wq-BhgAAAXQ"]
[Thu Jul 30 15:19:48.607336 2026] [core:error] [pid 147647:tid 147868] [client 45.249.89.53:51184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:48.607357 2026] [core:error] [pid 147647:tid 147868] [client 45.249.89.53:51184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:49.207384 2026] [security2:error] [pid 147647:tid 147861] [client 20.151.221.234:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/3.php"] [unique_id "amux5e_ioCvBERk4wq-BpwAAAV4"]
[Thu Jul 30 15:19:49.214472 2026] [security2:error] [pid 147647:tid 147836] [client 20.226.5.174:35986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/aa.php"] [unique_id "amux5e_ioCvBERk4wq-BqgAAAUU"]
[Thu Jul 30 15:19:49.216172 2026] [core:error] [pid 147647:tid 147834] [client 64.227.104.105:52238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:49.216195 2026] [core:error] [pid 147647:tid 147834] [client 64.227.104.105:52238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:49.321315 2026] [core:error] [pid 147647:tid 147822] [client 138.124.103.234:57720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:49.321341 2026] [core:error] [pid 147647:tid 147822] [client 138.124.103.234:57720] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:49.867442 2026] [security2:error] [pid 147647:tid 147827] [client 158.158.41.78:43192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/getid3-core.php"] [unique_id "amux5e_ioCvBERk4wq-BtQAAATw"]
[Thu Jul 30 15:19:49.912310 2026] [core:notice] [pid 147647:tid 147782] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:49.915948 2026] [security2:error] [pid 147647:tid 147782] [client 66.249.79.229:36603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/InaBHS/article/view/7386"] [unique_id "amux5e_ioCvBERk4wq-BtgAAAQ8"]
[Thu Jul 30 15:19:49.984850 2026] [security2:error] [pid 147647:tid 147807] [client 20.151.221.234:58176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/222.php"] [unique_id "amux5e_ioCvBERk4wq-BuwAAASg"]
[Thu Jul 30 15:19:49.987355 2026] [core:error] [pid 147647:tid 147802] [client 45.249.89.53:51784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:49.987371 2026] [core:error] [pid 147647:tid 147802] [client 45.249.89.53:51784] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:50.360238 2026] [security2:error] [pid 147647:tid 147849] [client 20.226.5.174:35995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/aafewc0k.php"] [unique_id "amux5u_ioCvBERk4wq-BxwAAAVI"]
[Thu Jul 30 15:19:50.384352 2026] [core:notice] [pid 147647:tid 147812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:50.387963 2026] [security2:error] [pid 147647:tid 147812] [client 66.249.79.8:37519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/817"] [unique_id "amux5u_ioCvBERk4wq-ByAAAAS0"]
[Thu Jul 30 15:19:50.593710 2026] [core:error] [pid 147647:tid 147793] [client 138.124.103.234:57736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:50.593734 2026] [core:error] [pid 147647:tid 147793] [client 138.124.103.234:57736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:50.623433 2026] [security2:error] [pid 147647:tid 147818] [client 195.201.163.148:39660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.163.201.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.milfordauto.com"] [uri "/insurance_ralations.php"] [unique_id "amux5u_ioCvBERk4wq-BywAAATM"]
[Thu Jul 30 15:19:50.785143 2026] [core:error] [pid 147647:tid 147815] [client 64.227.104.105:52248] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:50.785169 2026] [core:error] [pid 147647:tid 147815] [client 64.227.104.105:52248] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:50.834242 2026] [core:notice] [pid 147647:tid 147789] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:51.186865 2026] [security2:error] [pid 147647:tid 147752] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux5-_ioCvBERk4wq-B3AABFWg"]
[Thu Jul 30 15:19:51.187025 2026] [security2:error] [pid 147647:tid 147788] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux5-_ioCvBERk4wq-B3AABFWg"]
[Thu Jul 30 15:19:51.382595 2026] [core:error] [pid 147647:tid 147820] [client 45.249.89.53:52355] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:51.382624 2026] [core:error] [pid 147647:tid 147820] [client 45.249.89.53:52355] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:51.904361 2026] [core:error] [pid 147647:tid 147821] [client 138.124.103.234:57752] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:51.904382 2026] [core:error] [pid 147647:tid 147821] [client 138.124.103.234:57752] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:52.166842 2026] [core:error] [pid 147647:tid 147830] [client 64.227.104.105:52258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:52.166873 2026] [core:error] [pid 147647:tid 147830] [client 64.227.104.105:52258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:52.181502 2026] [security2:error] [pid 147647:tid 147829] [client 20.151.221.234:11634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amux6O_ioCvBERk4wq-B9gAAAT4"]
[Thu Jul 30 15:19:52.201093 2026] [security2:error] [pid 147647:tid 147802] [client 74.7.228.47:38134] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.ndn.nyx.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amux6O_ioCvBERk4wq-B9wAAASM"]
[Thu Jul 30 15:19:52.676944 2026] [security2:error] [pid 147647:tid 147850] [client 20.226.5.174:35991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/abcd.php"] [unique_id "amux6O_ioCvBERk4wq-CAgAAAVM"]
[Thu Jul 30 15:19:52.787252 2026] [core:error] [pid 147647:tid 147885] [client 45.249.89.53:52938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:52.787277 2026] [core:error] [pid 147647:tid 147885] [client 45.249.89.53:52938] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:52.884126 2026] [security2:error] [pid 147647:tid 147881] [client 180.211.233.74:55850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amux6O_ioCvBERk4wq-CCgAAAXI"]
[Thu Jul 30 15:19:53.158224 2026] [core:error] [pid 147647:tid 147818] [client 138.124.103.234:58190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:53.158248 2026] [core:error] [pid 147647:tid 147818] [client 138.124.103.234:58190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:53.649346 2026] [core:error] [pid 147647:tid 147899] [client 64.227.104.105:52264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:53.649375 2026] [core:error] [pid 147647:tid 147899] [client 64.227.104.105:52264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:53.715174 2026] [core:notice] [pid 147647:tid 147836] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:53.786645 2026] [security2:error] [pid 147647:tid 147893] [client 147.182.163.41:42874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amux6e_ioCvBERk4wq-CHAAAAX4"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:19:53.786667 2026] [security2:error] [pid 147647:tid 147854] [client 142.93.127.2:52822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amux6e_ioCvBERk4wq-CHgAAAVc"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:19:53.820340 2026] [security2:error] [pid 147647:tid 147835] [client 20.151.221.234:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amux6e_ioCvBERk4wq-CIgAAAUQ"]
[Thu Jul 30 15:19:53.946915 2026] [core:notice] [pid 147647:tid 147822] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:53.950663 2026] [security2:error] [pid 147647:tid 147822] [client 66.249.79.8:37519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JPA/article/view/8348/3494"] [unique_id "amux6e_ioCvBERk4wq-CJwAAATc"]
[Thu Jul 30 15:19:54.166189 2026] [core:error] [pid 147647:tid 147834] [client 45.249.89.53:53515] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:54.166214 2026] [core:error] [pid 147647:tid 147834] [client 45.249.89.53:53515] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:54.454251 2026] [core:error] [pid 147647:tid 147887] [client 138.124.103.234:58196] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:54.454274 2026] [core:error] [pid 147647:tid 147887] [client 138.124.103.234:58196] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:54.896099 2026] [core:notice] [pid 147647:tid 147804] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:55.070025 2026] [core:error] [pid 147647:tid 147876] [client 64.227.104.105:52270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:55.070048 2026] [core:error] [pid 147647:tid 147876] [client 64.227.104.105:52270] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:55.265534 2026] [security2:error] [pid 147647:tid 147797] [client 20.226.5.174:35978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/about.php"] [unique_id "amux6-_ioCvBERk4wq-CRQAAAR4"]
[Thu Jul 30 15:19:55.561889 2026] [core:error] [pid 147647:tid 147883] [client 45.249.89.53:54068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:55.561916 2026] [core:error] [pid 147647:tid 147883] [client 45.249.89.53:54068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:55.593908 2026] [core:notice] [pid 147647:tid 147787] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:55.597343 2026] [security2:error] [pid 147647:tid 147787] [client 66.249.79.229:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/view/1262/783"] [unique_id "amux6-_ioCvBERk4wq-CUAAAARQ"]
[Thu Jul 30 15:19:55.616182 2026] [security2:error] [pid 147647:tid 147790] [client 142.93.127.2:52832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amux6-_ioCvBERk4wq-CRwAAARc"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:19:55.620613 2026] [security2:error] [pid 147647:tid 147862] [client 147.182.163.41:42876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amux6-_ioCvBERk4wq-CRgAAAV8"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:19:55.682317 2026] [core:error] [pid 147647:tid 147651] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:55.682338 2026] [core:error] [pid 147647:tid 147651] [remote 216.73.216.89:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:55.692656 2026] [security2:error] [pid 147647:tid 147867] [client 20.151.221.234:11643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/admin.php"] [unique_id "amux6-_ioCvBERk4wq-CVQAAAWQ"]
[Thu Jul 30 15:19:55.890893 2026] [core:error] [pid 147647:tid 147825] [client 138.124.103.234:58212] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:55.890925 2026] [core:error] [pid 147647:tid 147825] [client 138.124.103.234:58212] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:56.205588 2026] [security2:error] [pid 147647:tid 147798] [client 158.158.41.78:9281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/adminer.php"] [unique_id "amux7O_ioCvBERk4wq-CYgAAAR8"]
[Thu Jul 30 15:19:56.261393 2026] [security2:error] [pid 147647:tid 147895] [client 62.102.148.162:42072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amux7O_ioCvBERk4wq-CYwAAAYA"]
[Thu Jul 30 15:19:56.261514 2026] [security2:error] [pid 147647:tid 147895] [client 62.102.148.162:42072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amux7O_ioCvBERk4wq-CYwAAAYA"]
[Thu Jul 30 15:19:56.300688 2026] [core:notice] [pid 147647:tid 147877] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:56.396097 2026] [core:error] [pid 147647:tid 147903] [client 64.227.104.105:52272] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:56.396121 2026] [core:error] [pid 147647:tid 147903] [client 64.227.104.105:52272] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:56.585959 2026] [security2:error] [pid 147647:tid 147861] [client 20.226.5.174:36000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amux7O_ioCvBERk4wq-CagAAAV4"]
[Thu Jul 30 15:19:56.948857 2026] [core:error] [pid 147647:tid 147823] [client 45.249.89.53:54655] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:56.948878 2026] [core:error] [pid 147647:tid 147823] [client 45.249.89.53:54655] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:57.101912 2026] [core:notice] [pid 147647:tid 147844] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:57.195660 2026] [core:notice] [pid 147647:tid 147655] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:57.199925 2026] [security2:error] [pid 147647:tid 147821] [client 170.83.179.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/39/41/79"] [unique_id "amux7O_ioCvBERk4wq-CdAABNgc"]
[Thu Jul 30 15:19:57.207499 2026] [autoindex:error] [pid 147647:tid 147887] [client 158.158.41.78:42346] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-content/uploads/2024/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:19:57.345598 2026] [security2:error] [pid 147647:tid 147813] [client 158.158.41.78:42346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/alfa.php"] [unique_id "amux7e_ioCvBERk4wq-CggAAAS4"]
[Thu Jul 30 15:19:57.545905 2026] [core:notice] [pid 147647:tid 147811] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:57.549729 2026] [security2:error] [pid 147647:tid 147811] [client 66.249.79.229:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/2770/1515"] [unique_id "amux7e_ioCvBERk4wq-CgwAAASw"]
[Thu Jul 30 15:19:57.615563 2026] [security2:error] [pid 147647:tid 147785] [client 20.151.221.234:39877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-configs.php"] [unique_id "amux7e_ioCvBERk4wq-CiAAAARI"]
[Thu Jul 30 15:19:57.794335 2026] [core:error] [pid 147647:tid 147871] [client 64.227.104.105:52286] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:57.794356 2026] [core:error] [pid 147647:tid 147871] [client 64.227.104.105:52286] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:57.858405 2026] [security2:error] [pid 147647:tid 147829] [client 45.151.236.21:32957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amux7e_ioCvBERk4wq-ChwAAAT4"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:19:57.934652 2026] [security2:error] [pid 147647:tid 147815] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/app/.env"] [unique_id "amux7e_ioCvBERk4wq-CkwAAATA"]
[Thu Jul 30 15:19:58.043953 2026] [core:notice] [pid 147647:tid 147874] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:58.244628 2026] [security2:error] [pid 147647:tid 147810] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/src/.env"] [unique_id "amux7u_ioCvBERk4wq-CmwAAASs"]
[Thu Jul 30 15:19:58.385841 2026] [autoindex:error] [pid 147647:tid 147866] [client 158.158.41.78:24768] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:19:58.401902 2026] [security2:error] [pid 147647:tid 147787] [client 20.226.5.174:35983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/adminfuns.php"] [unique_id "amux7u_ioCvBERk4wq-CoQAAARQ"]
[Thu Jul 30 15:19:58.476576 2026] [security2:error] [pid 147647:tid 147788] [client 20.151.221.234:11646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/php.php"] [unique_id "amux7u_ioCvBERk4wq-CogAAARU"]
[Thu Jul 30 15:19:58.516109 2026] [security2:error] [pid 147647:tid 147880] [client 158.158.41.78:24768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amux7u_ioCvBERk4wq-CowAAAXE"]
[Thu Jul 30 15:19:58.550086 2026] [security2:error] [pid 147647:tid 147836] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/config/.env"] [unique_id "amux7u_ioCvBERk4wq-CpAAAAUU"]
[Thu Jul 30 15:19:58.583819 2026] [security2:error] [pid 147647:tid 147683] [remote 57.141.0.19:27992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amux7u_ioCvBERk4wq-CpQABNSM"]
[Thu Jul 30 15:19:58.638019 2026] [core:notice] [pid 147647:tid 147687] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:58.728895 2026] [core:notice] [pid 147647:tid 147819] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:58.732110 2026] [security2:error] [pid 147647:tid 147819] [client 66.249.79.8:37519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/article/view/9070/3894"] [unique_id "amux7u_ioCvBERk4wq-CrgAAATQ"]
[Thu Jul 30 15:19:58.851198 2026] [security2:error] [pid 147647:tid 147889] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/backend/.env"] [unique_id "amux7u_ioCvBERk4wq-CsgAAAXo"]
[Thu Jul 30 15:19:58.981633 2026] [core:error] [pid 147647:tid 147822] [client 64.227.104.105:43474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:58.981665 2026] [core:error] [pid 147647:tid 147822] [client 64.227.104.105:43474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:59.049090 2026] [security2:error] [pid 147647:tid 147901] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/app/.env"] [unique_id "amux7-_ioCvBERk4wq-CtQAAAYY"]
[Thu Jul 30 15:19:59.113531 2026] [security2:error] [pid 147647:tid 147851] [client 158.158.41.78:42339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amux7-_ioCvBERk4wq-CtgAAAVQ"]
[Thu Jul 30 15:19:59.164080 2026] [security2:error] [pid 147647:tid 147873] [client 179.1.122.18:18559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amux7u_ioCvBERk4wq-CswAAAWo"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:19:59.165351 2026] [security2:error] [pid 147647:tid 147782] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/frontend/.env"] [unique_id "amux7-_ioCvBERk4wq-CuQAAAQ8"]
[Thu Jul 30 15:19:59.230732 2026] [security2:error] [pid 147647:tid 147827] [client 20.151.221.234:39935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/index.php"] [unique_id "amux7-_ioCvBERk4wq-CvAAAATw"]
[Thu Jul 30 15:19:59.412194 2026] [security2:error] [pid 147647:tid 147850] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/src/.env"] [unique_id "amux7-_ioCvBERk4wq-CwwAAAVM"]
[Thu Jul 30 15:19:59.469170 2026] [security2:error] [pid 147647:tid 147821] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/api/.env"] [unique_id "amux7-_ioCvBERk4wq-CxAAAATY"]
[Thu Jul 30 15:19:59.475747 2026] [core:notice] [pid 147647:tid 147690] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:19:59.479290 2026] [security2:error] [pid 147647:tid 147802] [client 66.249.65.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/278/278"] [unique_id "amux7-_ioCvBERk4wq-CuwABIyo"]
[Thu Jul 30 15:19:59.669814 2026] [core:error] [pid 147647:tid 147814] [client 138.124.103.234:58238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:59.669839 2026] [core:error] [pid 147647:tid 147814] [client 138.124.103.234:58238] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:19:59.774464 2026] [security2:error] [pid 147647:tid 147896] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/config/.env"] [unique_id "amux7-_ioCvBERk4wq-CzQAAAYE"]
[Thu Jul 30 15:19:59.774494 2026] [security2:error] [pid 147647:tid 147881] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/server/.env"] [unique_id "amux7-_ioCvBERk4wq-CzAAAAXI"]
[Thu Jul 30 15:20:00.079087 2026] [security2:error] [pid 147647:tid 147857] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/client/.env"] [unique_id "amux8O_ioCvBERk4wq-C1AAAAVo"]
[Thu Jul 30 15:20:00.137490 2026] [security2:error] [pid 147647:tid 147879] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/backend/.env"] [unique_id "amux8O_ioCvBERk4wq-C1QAAAXA"]
[Thu Jul 30 15:20:00.384362 2026] [security2:error] [pid 147647:tid 147780] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/web/.env"] [unique_id "amux8O_ioCvBERk4wq-C4AAAAQ0"]
[Thu Jul 30 15:20:00.500642 2026] [security2:error] [pid 147647:tid 147898] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/frontend/.env"] [unique_id "amux8O_ioCvBERk4wq-C4QAAAYM"]
[Thu Jul 30 15:20:00.516108 2026] [security2:error] [pid 147647:tid 147864] [client 20.151.221.234:11615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/a.php"] [unique_id "amux8O_ioCvBERk4wq-C4gAAAWE"]
[Thu Jul 30 15:20:00.567558 2026] [security2:error] [pid 147647:tid 147900] [client 20.226.5.174:36014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/albin.php"] [unique_id "amux8O_ioCvBERk4wq-C4wAAAYU"]
[Thu Jul 30 15:20:00.693395 2026] [security2:error] [pid 147647:tid 147810] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/public/.env"] [unique_id "amux8O_ioCvBERk4wq-C5AAAASs"]
[Thu Jul 30 15:20:00.864013 2026] [security2:error] [pid 147647:tid 147820] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/api/.env"] [unique_id "amux8O_ioCvBERk4wq-C7AAAATU"]
[Thu Jul 30 15:20:01.006326 2026] [security2:error] [pid 147647:tid 147798] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/private/.env"] [unique_id "amux8e_ioCvBERk4wq-C8AAAAR8"]
[Thu Jul 30 15:20:01.126224 2026] [security2:error] [pid 147647:tid 147877] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/app/.env"] [unique_id "amux8e_ioCvBERk4wq-C8QAAAW4"]
[Thu Jul 30 15:20:01.228486 2026] [security2:error] [pid 147647:tid 147783] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/server/.env"] [unique_id "amux8e_ioCvBERk4wq-C9AAAARA"]
[Thu Jul 30 15:20:01.314275 2026] [security2:error] [pid 147647:tid 147833] [client 138.124.103.234:58226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/var/.env"] [unique_id "amux8e_ioCvBERk4wq-C-QAAAUI"]
[Thu Jul 30 15:20:01.531467 2026] [security2:error] [pid 147647:tid 147827] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/src/.env"] [unique_id "amux8e_ioCvBERk4wq-DAwAAATw"]
[Thu Jul 30 15:20:01.584677 2026] [core:error] [pid 147647:tid 147716] [remote 74.7.241.158:54666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:01.584717 2026] [core:error] [pid 147647:tid 147716] [remote 74.7.241.158:54666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:01.584894 2026] [security2:error] [pid 147647:tid 147851] [client 74.7.241.158:54666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-170cb886.ubp.hmu.temporary.site"] [uri "/index.php"] [unique_id "amux8e_ioCvBERk4wq-DBQABVEQ"]
[Thu Jul 30 15:20:01.595955 2026] [security2:error] [pid 147647:tid 147859] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/client/.env"] [unique_id "amux8e_ioCvBERk4wq-DBgAAAVw"]
[Thu Jul 30 15:20:01.623542 2026] [core:error] [pid 147647:tid 147842] [client 138.124.103.234:58226] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:01.623560 2026] [core:error] [pid 147647:tid 147842] [client 138.124.103.234:58226] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:01.811461 2026] [security2:error] [pid 147647:tid 147703] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux8e_ioCvBERk4wq-DCQABfDc"]
[Thu Jul 30 15:20:01.811623 2026] [security2:error] [pid 147647:tid 147891] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux8e_ioCvBERk4wq-DCQABfDc"]
[Thu Jul 30 15:20:01.938331 2026] [security2:error] [pid 147647:tid 147681] [remote 74.7.243.224:49180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/reportf.php"] [unique_id "amux8e_ioCvBERk4wq-DFgABCyE"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 15:20:01.958425 2026] [security2:error] [pid 147647:tid 147876] [client 20.151.221.234:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amux8e_ioCvBERk4wq-DGQAAAW0"]
[Thu Jul 30 15:20:01.958808 2026] [security2:error] [pid 147647:tid 147796] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/web/.env"] [unique_id "amux8e_ioCvBERk4wq-DGAAAAR0"]
[Thu Jul 30 15:20:01.972327 2026] [security2:error] [pid 147647:tid 147901] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amux8e_ioCvBERk4wq-C_wAAAYY"]
[Thu Jul 30 15:20:02.011487 2026] [security2:error] [pid 147647:tid 147793] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/config/.env"] [unique_id "amux8u_ioCvBERk4wq-DGgAAARo"]
[Thu Jul 30 15:20:02.144740 2026] [security2:error] [pid 147647:tid 147720] [remote 57.141.0.5:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/491057609/feed/rss2/"] [unique_id "amux8u_ioCvBERk4wq-DHAABckg"]
[Thu Jul 30 15:20:02.281735 2026] [core:notice] [pid 147647:tid 147879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:02.322245 2026] [security2:error] [pid 147647:tid 147829] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/public/.env"] [unique_id "amux8u_ioCvBERk4wq-DIgAAAT4"]
[Thu Jul 30 15:20:02.448850 2026] [core:error] [pid 147647:tid 147824] [client 168.129.177.245:52116] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:02.448871 2026] [core:error] [pid 147647:tid 147824] [client 168.129.177.245:52116] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:02.525113 2026] [security2:error] [pid 147647:tid 147799] [client 43.173.174.12:40482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/04/24/east-mamma-la-nouvelle-trattoria-italienne-a-paris/"] [unique_id "amux8u_ioCvBERk4wq-DHgAAASA"]
[Thu Jul 30 15:20:02.538099 2026] [security2:error] [pid 147647:tid 147888] [client 177.39.126.36:54894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amux8u_ioCvBERk4wq-DHQAAAXk"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:20:02.538627 2026] [security2:error] [pid 147647:tid 147870] [client 20.226.5.174:35973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/amfsqvgv.php"] [unique_id "amux8u_ioCvBERk4wq-DKwAAAWc"]
[Thu Jul 30 15:20:02.685644 2026] [security2:error] [pid 147647:tid 147890] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/private/.env"] [unique_id "amux8u_ioCvBERk4wq-DLAAAAXs"]
[Thu Jul 30 15:20:02.689145 2026] [security2:error] [pid 147647:tid 147813] [client 172.237.109.114:19530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amux8u_ioCvBERk4wq-DGwAAAS4"]
[Thu Jul 30 15:20:02.757105 2026] [security2:error] [pid 147647:tid 147866] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/backend/.env"] [unique_id "amux8u_ioCvBERk4wq-DLgAAAWM"]
[Thu Jul 30 15:20:02.869093 2026] [security2:error] [pid 147647:tid 147809] [client 20.151.221.234:11619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin.php"] [unique_id "amux8u_ioCvBERk4wq-DMgAAASo"]
[Thu Jul 30 15:20:02.884626 2026] [core:error] [pid 147647:tid 147835] [client 138.124.103.234:58246] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:02.884645 2026] [core:error] [pid 147647:tid 147835] [client 138.124.103.234:58246] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:02.968006 2026] [core:notice] [pid 147647:tid 147899] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:02.973046 2026] [security2:error] [pid 147647:tid 147899] [client 43.172.197.21:60260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/04/24/east-mamma-la-nouvelle-trattoria-italienne-a-paris/"] [unique_id "amux8u_ioCvBERk4wq-DNwAAAYQ"], referer: https://carnetdeshopping.com/index.php/2015/04/24/east-mamma-la-nouvelle-trattoria-italienne-a-paris/?replytocom=1479
[Thu Jul 30 15:20:03.048789 2026] [security2:error] [pid 147647:tid 147819] [client 45.249.89.53:55234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/var/.env"] [unique_id "amux8-_ioCvBERk4wq-DOwAAATQ"]
[Thu Jul 30 15:20:03.247314 2026] [core:notice] [pid 147647:tid 147843] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:03.412757 2026] [core:error] [pid 147647:tid 147784] [client 45.249.89.53:55234] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:03.412779 2026] [core:error] [pid 147647:tid 147784] [client 45.249.89.53:55234] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:03.421916 2026] [core:notice] [pid 147647:tid 147831] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:03.424940 2026] [security2:error] [pid 147647:tid 147831] [client 66.249.79.1:63533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/7713"] [unique_id "amux8-_ioCvBERk4wq-DPQAAAUA"]
[Thu Jul 30 15:20:03.440524 2026] [security2:error] [pid 147647:tid 147904] [client 178.121.27.249:6027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amux8-_ioCvBERk4wq-DPAAAAYk"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:20:03.474776 2026] [security2:error] [pid 147647:tid 147897] [client 216.244.66.236:58892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amux8-_ioCvBERk4wq-DRwAAAYI"]
[Thu Jul 30 15:20:03.474883 2026] [security2:error] [pid 147647:tid 147897] [client 216.244.66.236:58892] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amux8-_ioCvBERk4wq-DRwAAAYI"]
[Thu Jul 30 15:20:03.480626 2026] [security2:error] [pid 147647:tid 147878] [client 216.244.66.236:58896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amux8-_ioCvBERk4wq-DSQAAAW8"]
[Thu Jul 30 15:20:03.480715 2026] [security2:error] [pid 147647:tid 147878] [client 216.244.66.236:58896] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.toscanamall.com"] [uri "/fr"] [unique_id "amux8-_ioCvBERk4wq-DSQAAAW8"]
[Thu Jul 30 15:20:03.497235 2026] [security2:error] [pid 147647:tid 147823] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/frontend/.env"] [unique_id "amux8-_ioCvBERk4wq-DTAAAATg"]
[Thu Jul 30 15:20:03.729283 2026] [security2:error] [pid 147647:tid 147791] [client 20.226.5.174:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/ant.php"] [unique_id "amux8-_ioCvBERk4wq-DUQAAARg"]
[Thu Jul 30 15:20:03.857090 2026] [core:notice] [pid 147647:tid 147887] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:03.866559 2026] [core:error] [pid 147647:tid 147887] [client 66.249.74.8:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:03.866742 2026] [security2:error] [pid 147647:tid 147887] [client 66.249.74.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/48/50.html.html.html.html.html.html.html.html.html.html"] [unique_id "amux8-_ioCvBERk4wq-DUgAAAXg"]
[Thu Jul 30 15:20:03.928014 2026] [security2:error] [pid 147647:tid 147840] [client 20.151.221.234:11593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/size.php"] [unique_id "amux8-_ioCvBERk4wq-DVgAAAUk"]
[Thu Jul 30 15:20:03.997257 2026] [core:error] [pid 147647:tid 147806] [client 139.59.102.20:21140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:03.997286 2026] [core:error] [pid 147647:tid 147806] [client 139.59.102.20:21140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:04.066367 2026] [security2:error] [pid 147647:tid 147883] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/api/.env"] [unique_id "amux9O_ioCvBERk4wq-DXgAAAXQ"]
[Thu Jul 30 15:20:04.359236 2026] [core:notice] [pid 147647:tid 147850] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:04.359659 2026] [core:error] [pid 147647:tid 147896] [client 138.124.103.234:50306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:04.359675 2026] [core:error] [pid 147647:tid 147896] [client 138.124.103.234:50306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:04.362647 2026] [security2:error] [pid 147647:tid 147850] [client 66.249.79.2:38872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/download/2785/1547"] [unique_id "amux9O_ioCvBERk4wq-DYwAAAVM"]
[Thu Jul 30 15:20:04.641446 2026] [security2:error] [pid 147647:tid 147901] [client 172.237.109.114:13353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amux9O_ioCvBERk4wq-DYgAAAYY"]
[Thu Jul 30 15:20:04.755323 2026] [security2:error] [pid 147647:tid 147790] [client 20.226.5.174:35981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/appreciators.php"] [unique_id "amux9O_ioCvBERk4wq-DbgAAARc"]
[Thu Jul 30 15:20:04.805476 2026] [core:error] [pid 147647:tid 147872] [client 45.249.89.53:57838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:04.805499 2026] [core:error] [pid 147647:tid 147872] [client 45.249.89.53:57838] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:04.833272 2026] [security2:error] [pid 147647:tid 147854] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/server/.env"] [unique_id "amux9O_ioCvBERk4wq-DcAAAAVc"]
[Thu Jul 30 15:20:05.026142 2026] [core:notice] [pid 147647:tid 147816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:05.038363 2026] [core:error] [pid 147647:tid 147816] [client 66.249.79.231:60208] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:05.038522 2026] [security2:error] [pid 147647:tid 147816] [client 66.249.79.231:60208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/view/9524/4274.html.html.html.html.html.html.html.html.html.html"] [unique_id "amux9e_ioCvBERk4wq-DdAAAATE"]
[Thu Jul 30 15:20:05.189045 2026] [core:error] [pid 147647:tid 147877] [client 74.7.241.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:05.189065 2026] [core:error] [pid 147647:tid 147877] [client 74.7.241.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:05.189183 2026] [security2:error] [pid 147647:tid 147877] [client 74.7.241.144:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.axm.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amux9e_ioCvBERk4wq-DfgAAAW4"]
[Thu Jul 30 15:20:05.189823 2026] [security2:error] [pid 147647:tid 147866] [client 74.7.241.144:55888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.axm.gzj.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amux9e_ioCvBERk4wq-DfAABY1k"]
[Thu Jul 30 15:20:05.291355 2026] [autoindex:error] [pid 147647:tid 147722] [remote 139.144.212.130:38098] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:20:05.421039 2026] [security2:error] [pid 147647:tid 147832] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/client/.env"] [unique_id "amux9e_ioCvBERk4wq-DgAAAAUE"]
[Thu Jul 30 15:20:05.459346 2026] [security2:error] [pid 147647:tid 147888] [client 158.158.41.78:38819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amux9e_ioCvBERk4wq-DhAAAAXk"]
[Thu Jul 30 15:20:05.693641 2026] [core:error] [pid 147647:tid 147895] [client 138.124.103.234:50308] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:05.693661 2026] [core:error] [pid 147647:tid 147895] [client 138.124.103.234:50308] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:05.917784 2026] [security2:error] [pid 147647:tid 147810] [client 20.151.221.234:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amux9e_ioCvBERk4wq-DjgAAASs"]
[Thu Jul 30 15:20:05.931489 2026] [security2:error] [pid 147647:tid 147860] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/web/.env"] [unique_id "amux9e_ioCvBERk4wq-DjwAAAV0"]
[Thu Jul 30 15:20:05.961264 2026] [core:notice] [pid 147647:tid 147848] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:05.964533 2026] [security2:error] [pid 147647:tid 147848] [client 66.249.79.229:42182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/7845/3129"] [unique_id "amux9e_ioCvBERk4wq-DjAAAAVE"]
[Thu Jul 30 15:20:06.188292 2026] [core:notice] [pid 147647:tid 147876] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:06.191390 2026] [security2:error] [pid 147647:tid 147876] [client 66.249.79.229:42182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/6260"] [unique_id "amux9u_ioCvBERk4wq-DmQAAAW0"]
[Thu Jul 30 15:20:06.192277 2026] [core:error] [pid 147647:tid 147823] [client 45.249.89.53:58386] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:06.192294 2026] [core:error] [pid 147647:tid 147823] [client 45.249.89.53:58386] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:06.341210 2026] [security2:error] [pid 147647:tid 147803] [client 20.226.5.174:35974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/archive.php"] [unique_id "amux9u_ioCvBERk4wq-DnAAAASQ"]
[Thu Jul 30 15:20:06.638342 2026] [security2:error] [pid 147647:tid 147896] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/public/.env"] [unique_id "amux9u_ioCvBERk4wq-DpgAAAYE"]
[Thu Jul 30 15:20:06.723387 2026] [core:notice] [pid 147647:tid 147862] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:06.839868 2026] [security2:error] [pid 147647:tid 147883] [client 20.151.221.234:53831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/403.php"] [unique_id "amux9u_ioCvBERk4wq-DqAAAAXQ"]
[Thu Jul 30 15:20:07.017042 2026] [core:error] [pid 147647:tid 147865] [client 138.124.103.234:50312] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:07.017067 2026] [core:error] [pid 147647:tid 147865] [client 138.124.103.234:50312] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:07.188439 2026] [security2:error] [pid 147647:tid 147798] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/private/.env"] [unique_id "amux9-_ioCvBERk4wq-DvQAAAR8"]
[Thu Jul 30 15:20:07.292904 2026] [core:notice] [pid 147647:tid 147805] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:07.570378 2026] [security2:error] [pid 147647:tid 147837] [client 158.158.41.78:52464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/edit.php"] [unique_id "amux9-_ioCvBERk4wq-DxgAAAUY"]
[Thu Jul 30 15:20:07.575636 2026] [core:error] [pid 147647:tid 147828] [client 45.249.89.53:58914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:07.575663 2026] [core:error] [pid 147647:tid 147828] [client 45.249.89.53:58914] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:07.660416 2026] [security2:error] [pid 147647:tid 147894] [client 64.227.104.105:43480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/var/.env"] [unique_id "amux9-_ioCvBERk4wq-DygAAAX8"]
[Thu Jul 30 15:20:07.698571 2026] [security2:error] [pid 147647:tid 147892] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amux9-_ioCvBERk4wq-DuQAAAX0"]
[Thu Jul 30 15:20:07.809162 2026] [security2:error] [pid 147647:tid 147884] [client 20.151.221.234:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amux9-_ioCvBERk4wq-DzQAAAXU"]
[Thu Jul 30 15:20:07.918761 2026] [security2:error] [pid 147647:tid 147903] [client 20.226.5.174:35994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/as.php"] [unique_id "amux9-_ioCvBERk4wq-D0QAAAYg"]
[Thu Jul 30 15:20:08.111057 2026] [core:error] [pid 147647:tid 147849] [client 64.227.104.105:43480] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:08.111081 2026] [core:error] [pid 147647:tid 147849] [client 64.227.104.105:43480] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:08.257916 2026] [core:notice] [pid 147647:tid 147814] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:08.722889 2026] [core:notice] [pid 147647:tid 147799] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:08.726495 2026] [security2:error] [pid 147647:tid 147799] [client 66.249.79.1:63533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/1962/1231"] [unique_id "amux-O_ioCvBERk4wq-D5AAAASA"]
[Thu Jul 30 15:20:08.744793 2026] [security2:error] [pid 147647:tid 147875] [client 20.151.221.234:11588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/as.php"] [unique_id "amux-O_ioCvBERk4wq-D5wAAAWw"]
[Thu Jul 30 15:20:08.966640 2026] [core:error] [pid 147647:tid 147812] [client 45.249.89.53:59448] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:08.966662 2026] [core:error] [pid 147647:tid 147812] [client 45.249.89.53:59448] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:09.135607 2026] [autoindex:error] [pid 147647:tid 147879] [client 158.158.41.78:52468] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:20:09.215534 2026] [core:notice] [pid 147647:tid 147880] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:09.219104 2026] [security2:error] [pid 147647:tid 147880] [client 66.249.79.1:63533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JSTE/article/view/6602/2748"] [unique_id "amux-e_ioCvBERk4wq-D9QAAAXE"]
[Thu Jul 30 15:20:09.482228 2026] [security2:error] [pid 147647:tid 147777] [client 20.151.221.234:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amux-e_ioCvBERk4wq-D_QAAAQo"]
[Thu Jul 30 15:20:09.486361 2026] [security2:error] [pid 147647:tid 147866] [client 158.158.41.78:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/sf.php"] [unique_id "amux-e_ioCvBERk4wq-D_gAAAWM"]
[Thu Jul 30 15:20:09.633453 2026] [security2:error] [pid 147647:tid 147882] [client 20.226.5.174:35989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/atomlib.php"] [unique_id "amux-e_ioCvBERk4wq-EAgAAAXM"]
[Thu Jul 30 15:20:10.124671 2026] [core:error] [pid 147647:tid 147873] [client 64.227.104.105:56858] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:10.124699 2026] [core:error] [pid 147647:tid 147873] [client 64.227.104.105:56858] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:10.228317 2026] [security2:error] [pid 147647:tid 147884] [client 20.151.221.234:11614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amux-u_ioCvBERk4wq-EDwAAAXU"]
[Thu Jul 30 15:20:10.705355 2026] [security2:error] [pid 147647:tid 147868] [client 20.226.5.174:35990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/autoload_classmap.php"] [unique_id "amux-u_ioCvBERk4wq-EHQAAAWU"]
[Thu Jul 30 15:20:11.086013 2026] [core:error] [pid 147647:tid 147846] [client 168.129.177.245:30806] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:11.086041 2026] [core:error] [pid 147647:tid 147846] [client 168.129.177.245:30806] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:11.457830 2026] [security2:error] [pid 147647:tid 147789] [client 20.151.221.234:39895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/plugins.php"] [unique_id "amux--_ioCvBERk4wq-ENgAAARY"]
[Thu Jul 30 15:20:11.834177 2026] [core:notice] [pid 147647:tid 147866] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:11.837659 2026] [security2:error] [pid 147647:tid 147866] [client 66.249.79.8:41576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/download/1085/772"] [unique_id "amux--_ioCvBERk4wq-EQwAAAWM"]
[Thu Jul 30 15:20:11.853144 2026] [core:error] [pid 147647:tid 147816] [client 64.227.104.105:56862] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:11.853159 2026] [core:error] [pid 147647:tid 147816] [client 64.227.104.105:56862] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:11.916485 2026] [security2:error] [pid 147647:tid 147661] [remote 89.185.225.24:59298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amux--_ioCvBERk4wq-ESwABEw0"]
[Thu Jul 30 15:20:12.442279 2026] [security2:error] [pid 147647:tid 147827] [client 20.226.5.174:35993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/bb.php"] [unique_id "amux_O_ioCvBERk4wq-EWQAAATw"]
[Thu Jul 30 15:20:12.526028 2026] [security2:error] [pid 147647:tid 147663] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux_O_ioCvBERk4wq-EWgABfQ8"]
[Thu Jul 30 15:20:12.526174 2026] [security2:error] [pid 147647:tid 147892] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amux_O_ioCvBERk4wq-EWgABfQ8"]
[Thu Jul 30 15:20:12.999790 2026] [security2:error] [pid 147647:tid 147653] [remote 57.141.0.1:23646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amux_O_ioCvBERk4wq-EaAABgAU"]
[Thu Jul 30 15:20:13.047927 2026] [core:notice] [pid 147647:tid 147823] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:13.179087 2026] [security2:error] [pid 147647:tid 147885] [client 34.21.248.151:13683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amux_e_ioCvBERk4wq-EagAAAXY"]
[Thu Jul 30 15:20:13.190544 2026] [security2:error] [pid 147647:tid 147853] [client 20.151.221.234:37550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/js/index.php"] [unique_id "amux_e_ioCvBERk4wq-EawAAAVY"]
[Thu Jul 30 15:20:13.359892 2026] [core:error] [pid 147647:tid 147806] [client 64.227.104.105:56864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:13.359912 2026] [core:error] [pid 147647:tid 147806] [client 64.227.104.105:56864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:13.421931 2026] [core:error] [pid 147647:tid 147898] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://chimnify.services/
[Thu Jul 30 15:20:13.421954 2026] [core:error] [pid 147647:tid 147898] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://chimnify.services/
[Thu Jul 30 15:20:13.688639 2026] [security2:error] [pid 147647:tid 147820] [client 52.167.144.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amux--_ioCvBERk4wq-EPwAAATU"]
[Thu Jul 30 15:20:13.714153 2026] [core:notice] [pid 147647:tid 147872] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:13.835472 2026] [autoindex:error] [pid 147647:tid 147808] [client 158.158.41.78:32442] AH01276: Cannot serve directory /home1/jvcnyxte/public_html/website_562c2b7d/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:20:13.965621 2026] [security2:error] [pid 147647:tid 147837] [client 158.158.41.78:32442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wso.php"] [unique_id "amux_e_ioCvBERk4wq-EjQAAAUY"]
[Thu Jul 30 15:20:13.984540 2026] [security2:error] [pid 147647:tid 147789] [client 20.151.221.234:11445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/go.php"] [unique_id "amux_e_ioCvBERk4wq-EjgAAARY"]
[Thu Jul 30 15:20:14.083224 2026] [core:notice] [pid 147647:tid 147819] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:14.086463 2026] [security2:error] [pid 147647:tid 147819] [client 66.249.79.229:51155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Responsif/article/view/8903"] [unique_id "amux_u_ioCvBERk4wq-ElgAAATQ"]
[Thu Jul 30 15:20:14.164051 2026] [security2:error] [pid 147647:tid 147858] [client 52.167.144.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amux_e_ioCvBERk4wq-EjAAAAVs"]
[Thu Jul 30 15:20:14.307745 2026] [core:notice] [pid 147647:tid 147904] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:14.311049 2026] [security2:error] [pid 147647:tid 147904] [client 66.249.79.8:41576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/4146"] [unique_id "amux_u_ioCvBERk4wq-EmAAAAYk"]
[Thu Jul 30 15:20:14.580751 2026] [security2:error] [pid 147647:tid 147782] [client 114.119.159.236:24319] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/investor-relations-2/interactive-analysis/"] [unique_id "amux_u_ioCvBERk4wq-EpQAAAQ8"], referer: https://alseermarine.com/investor-relations-2/share-graph
[Thu Jul 30 15:20:14.717653 2026] [core:error] [pid 147647:tid 147873] [client 64.227.104.105:56880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:14.717686 2026] [core:error] [pid 147647:tid 147873] [client 64.227.104.105:56880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:14.866000 2026] [security2:error] [pid 147647:tid 147794] [client 20.151.221.234:37566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/test1.php"] [unique_id "amux_u_ioCvBERk4wq-ErQAAARs"]
[Thu Jul 30 15:20:14.981334 2026] [security2:error] [pid 147647:tid 147683] [remote 57.141.0.70:51884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amux_u_ioCvBERk4wq-EsQABgCM"]
[Thu Jul 30 15:20:15.097432 2026] [security2:error] [pid 147647:tid 147796] [client 20.226.5.174:35982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/bnm.php"] [unique_id "amux_-_ioCvBERk4wq-EtQAAAR0"]
[Thu Jul 30 15:20:15.141629 2026] [security2:error] [pid 147647:tid 147857] [client 158.158.41.78:31812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/ioxi-o.php"] [unique_id "amux_-_ioCvBERk4wq-EtwAAAVo"]
[Thu Jul 30 15:20:16.045295 2026] [security2:error] [pid 147647:tid 147878] [client 20.151.221.234:58210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/images/index.php"] [unique_id "amuyAO_ioCvBERk4wq-E1wAAAW8"]
[Thu Jul 30 15:20:16.146150 2026] [core:notice] [pid 147647:tid 147858] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:16.271365 2026] [security2:error] [pid 147647:tid 147863] [client 213.152.161.133:46114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuyAO_ioCvBERk4wq-E3gAAAWA"]
[Thu Jul 30 15:20:16.271480 2026] [security2:error] [pid 147647:tid 147863] [client 213.152.161.133:46114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuyAO_ioCvBERk4wq-E3gAAAWA"]
[Thu Jul 30 15:20:16.390436 2026] [security2:error] [pid 147647:tid 147789] [client 20.226.5.174:35971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/bootstrap.php"] [unique_id "amuyAO_ioCvBERk4wq-E4gAAARY"]
[Thu Jul 30 15:20:16.596481 2026] [core:notice] [pid 147647:tid 147802] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:16.599918 2026] [security2:error] [pid 147647:tid 147802] [client 66.249.79.8:41576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/6355"] [unique_id "amuyAO_ioCvBERk4wq-E6gAAASM"]
[Thu Jul 30 15:20:16.601021 2026] [core:error] [pid 147647:tid 147804] [client 138.124.103.234:50320] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:16.601038 2026] [core:error] [pid 147647:tid 147804] [client 138.124.103.234:50320] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:16.665366 2026] [security2:error] [pid 147647:tid 147801] [client 172.237.109.114:45527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyAO_ioCvBERk4wq-E2AAAASI"]
[Thu Jul 30 15:20:17.093561 2026] [core:notice] [pid 147647:tid 147846] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:17.485858 2026] [security2:error] [pid 147647:tid 147805] [client 20.151.221.234:11624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/asd.php"] [unique_id "amuyAe_ioCvBERk4wq-FBQAAASY"]
[Thu Jul 30 15:20:17.540183 2026] [security2:error] [pid 147647:tid 147876] [client 114.119.158.128:28079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2021/12/WhatsApp-Image-2021-12-14-at-12.09.27-300x169.jpeg"] [unique_id "amuyAe_ioCvBERk4wq-FCQAAAW0"], referer: https://www.nordeste1.com/2021/12/14/pedro-regis-secretaria-de-educacao-certifica-professores-do-integra-educacao-pb/
[Thu Jul 30 15:20:17.592322 2026] [core:notice] [pid 147647:tid 147893] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:17.758497 2026] [core:error] [pid 147647:tid 147811] [client 152.53.242.93:55748] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:17.758521 2026] [core:error] [pid 147647:tid 147811] [client 152.53.242.93:55748] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:17.867319 2026] [core:error] [pid 147647:tid 147880] [client 138.124.103.234:56974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:17.867344 2026] [core:error] [pid 147647:tid 147880] [client 138.124.103.234:56974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:18.090663 2026] [core:notice] [pid 147647:tid 147808] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:18.123135 2026] [security2:error] [pid 147647:tid 147872] [client 20.226.5.174:35976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/buy.php"] [unique_id "amuyAu_ioCvBERk4wq-FJAAAAWk"]
[Thu Jul 30 15:20:18.314769 2026] [security2:error] [pid 147647:tid 147900] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyAe_ioCvBERk4wq-FEAAAAYU"]
[Thu Jul 30 15:20:18.472095 2026] [security2:error] [pid 147647:tid 147863] [client 20.151.221.234:11417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuyAu_ioCvBERk4wq-FLgAAAWA"]
[Thu Jul 30 15:20:18.496565 2026] [security2:error] [pid 147647:tid 147890] [client 172.237.109.114:14376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyAu_ioCvBERk4wq-FHwAAAXs"]
[Thu Jul 30 15:20:18.588887 2026] [core:notice] [pid 147647:tid 147852] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:18.815373 2026] [security2:error] [pid 147647:tid 147793] [client 158.158.41.78:32432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/file56.php"] [unique_id "amuyAu_ioCvBERk4wq-FOwAAARo"]
[Thu Jul 30 15:20:19.072949 2026] [core:error] [pid 147647:tid 147815] [client 138.124.103.234:56988] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:19.072972 2026] [core:error] [pid 147647:tid 147815] [client 138.124.103.234:56988] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:19.087341 2026] [core:notice] [pid 147647:tid 147836] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:19.197501 2026] [core:notice] [pid 147647:tid 147717] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:19.236089 2026] [security2:error] [pid 147647:tid 147875] [client 20.151.221.234:11440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuyA-_ioCvBERk4wq-FSgAAAWw"]
[Thu Jul 30 15:20:19.300099 2026] [security2:error] [pid 147647:tid 147727] [remote 110.249.201.62:32058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alseermarine.com"] [uri "/"] [unique_id "amuyA-_ioCvBERk4wq-FTgABH08"]
[Thu Jul 30 15:20:19.472899 2026] [core:notice] [pid 147647:tid 147731] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:19.907224 2026] [core:notice] [pid 147647:tid 147722] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:19.961663 2026] [security2:error] [pid 147647:tid 147886] [client 20.226.5.174:36004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/chosen.php"] [unique_id "amuyA-_ioCvBERk4wq-FYgAAAXc"]
[Thu Jul 30 15:20:20.042501 2026] [core:notice] [pid 147647:tid 147904] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:20.055014 2026] [core:error] [pid 147647:tid 147904] [client 66.249.79.229:57250] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:20.055201 2026] [security2:error] [pid 147647:tid 147904] [client 66.249.79.229:57250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/777/474.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuyBO_ioCvBERk4wq-FZAAAAYk"]
[Thu Jul 30 15:20:20.092768 2026] [security2:error] [pid 147647:tid 147899] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyA-_ioCvBERk4wq-FVQAAAYQ"]
[Thu Jul 30 15:20:20.184181 2026] [security2:error] [pid 147647:tid 147827] [client 20.151.221.234:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/atomlib.php"] [unique_id "amuyBO_ioCvBERk4wq-FawAAATw"]
[Thu Jul 30 15:20:20.332189 2026] [core:error] [pid 147647:tid 147814] [client 138.124.103.234:56990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:20.332228 2026] [core:error] [pid 147647:tid 147814] [client 138.124.103.234:56990] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:20.399874 2026] [core:error] [pid 147647:tid 147868] [client 45.249.89.53:59989] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:20.399896 2026] [core:error] [pid 147647:tid 147868] [client 45.249.89.53:59989] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:20.714083 2026] [core:notice] [pid 147647:tid 147831] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:20.717682 2026] [security2:error] [pid 147647:tid 147831] [client 66.249.79.229:37312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA/article/download/6792/2798"] [unique_id "amuyBO_ioCvBERk4wq-FeQAAAUA"]
[Thu Jul 30 15:20:20.968710 2026] [core:notice] [pid 147647:tid 147884] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:21.055663 2026] [security2:error] [pid 147647:tid 147880] [client 158.158.41.78:23668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuyBe_ioCvBERk4wq-FgAAAAXE"]
[Thu Jul 30 15:20:21.289955 2026] [security2:error] [pid 147647:tid 147898] [client 20.226.5.174:35998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/class-wp-image.php"] [unique_id "amuyBe_ioCvBERk4wq-FiAAAAYM"]
[Thu Jul 30 15:20:21.442824 2026] [security2:error] [pid 147647:tid 147887] [client 20.151.221.234:39919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuyBe_ioCvBERk4wq-FjQAAAXg"]
[Thu Jul 30 15:20:21.653172 2026] [core:error] [pid 147647:tid 147798] [client 138.124.103.234:56994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:21.653194 2026] [core:error] [pid 147647:tid 147798] [client 138.124.103.234:56994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:21.786792 2026] [core:error] [pid 147647:tid 147810] [client 45.249.89.53:64314] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:21.786831 2026] [core:error] [pid 147647:tid 147810] [client 45.249.89.53:64314] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:22.208527 2026] [core:notice] [pid 147647:tid 147778] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:22.656051 2026] [core:notice] [pid 147647:tid 147891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:22.668203 2026] [core:error] [pid 147647:tid 147891] [client 66.249.79.229:37312] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:22.668363 2026] [security2:error] [pid 147647:tid 147891] [client 66.249.79.229:37312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/view/9378/4153.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuyBu_ioCvBERk4wq-FqwAAAXw"]
[Thu Jul 30 15:20:22.928374 2026] [security2:error] [pid 147647:tid 147863] [client 138.124.103.234:39678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/wp-config.php.bak"] [unique_id "amuyBu_ioCvBERk4wq-FuAAAAWA"]
[Thu Jul 30 15:20:22.995169 2026] [security2:error] [pid 147647:tid 147759] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyBu_ioCvBERk4wq-FuQABcm8"]
[Thu Jul 30 15:20:22.995306 2026] [security2:error] [pid 147647:tid 147881] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyBu_ioCvBERk4wq-FuQABcm8"]
[Thu Jul 30 15:20:23.173605 2026] [core:error] [pid 147647:tid 147797] [client 45.249.89.53:64821] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:23.173629 2026] [core:error] [pid 147647:tid 147797] [client 45.249.89.53:64821] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:23.204385 2026] [security2:error] [pid 147647:tid 147839] [client 20.151.221.234:37549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/inputs.php"] [unique_id "amuyB-_ioCvBERk4wq-FuwAAAUg"]
[Thu Jul 30 15:20:23.489208 2026] [security2:error] [pid 147647:tid 147898] [client 20.118.34.237:9219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuyB-_ioCvBERk4wq-FxgAAAYM"]
[Thu Jul 30 15:20:23.746822 2026] [core:notice] [pid 147647:tid 147883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:23.750186 2026] [security2:error] [pid 147647:tid 147883] [client 66.249.79.229:61841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Responsif/article/download/1183/755"] [unique_id "amuyB-_ioCvBERk4wq-FyAAAAXQ"]
[Thu Jul 30 15:20:24.029353 2026] [security2:error] [pid 147647:tid 147893] [client 20.226.5.174:36012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/classsmtps.php"] [unique_id "amuyCO_ioCvBERk4wq-F0gAAAX4"]
[Thu Jul 30 15:20:24.181358 2026] [core:error] [pid 147647:tid 147882] [client 144.31.143.114:34492] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:24.181384 2026] [core:error] [pid 147647:tid 147882] [client 144.31.143.114:34492] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:24.202236 2026] [core:notice] [pid 147647:tid 147856] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:24.205237 2026] [security2:error] [pid 147647:tid 147856] [client 66.249.79.237:35312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3769"] [unique_id "amuyCO_ioCvBERk4wq-F1QAAAVk"]
[Thu Jul 30 15:20:24.283109 2026] [security2:error] [pid 147647:tid 147798] [client 138.124.103.234:39682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/wp-config.php.old"] [unique_id "amuyCO_ioCvBERk4wq-F1gAAAR8"]
[Thu Jul 30 15:20:24.334947 2026] [proxy:error] [pid 147647:tid 147866] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:20:24.335025 2026] [proxy_http:error] [pid 147647:tid 147866] [client 98.87.102.177:17952] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:20:24.335847 2026] [proxy:error] [pid 147647:tid 147866] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:20:24.335902 2026] [proxy_http:error] [pid 147647:tid 147866] [client 98.87.102.177:17952] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:20:24.337020 2026] [core:error] [pid 147647:tid 147902] [client 45.249.89.53:65257] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:24.337046 2026] [core:error] [pid 147647:tid 147902] [client 45.249.89.53:65257] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:24.374115 2026] [proxy:error] [pid 147647:tid 147830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:20:24.374222 2026] [proxy_http:error] [pid 147647:tid 147830] [client 44.216.125.112:31142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:20:24.375302 2026] [proxy:error] [pid 147647:tid 147830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:20:24.375364 2026] [proxy_http:error] [pid 147647:tid 147830] [client 44.216.125.112:31142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:20:24.566674 2026] [core:error] [pid 147647:tid 147832] [client 45.249.89.53:65340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:24.566697 2026] [core:error] [pid 147647:tid 147832] [client 45.249.89.53:65340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:24.648277 2026] [security2:error] [pid 147647:tid 147784] [client 20.63.98.115:25666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/gmo.php"] [unique_id "amuyCO_ioCvBERk4wq-F9AAAARE"]
[Thu Jul 30 15:20:24.982922 2026] [security2:error] [pid 147647:tid 147802] [client 193.47.62.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.spececigarette.com"] [uri "/index.php"] [unique_id "amuyBu_ioCvBERk4wq-FqgABI1w"], referer: http://mail.spececigarette.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Thu Jul 30 15:20:25.103341 2026] [security2:error] [pid 147647:tid 147794] [client 20.226.5.174:36009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/classwithtostring.php"] [unique_id "amuyCe_ioCvBERk4wq-GAAAAARs"]
[Thu Jul 30 15:20:25.157868 2026] [security2:error] [pid 147647:tid 147797] [client 20.151.221.234:11435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/index.php"] [unique_id "amuyCe_ioCvBERk4wq-GAQAAAR4"]
[Thu Jul 30 15:20:25.836692 2026] [security2:error] [pid 147647:tid 147813] [client 138.124.103.234:39686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/wp-config.php.save"] [unique_id "amuyCe_ioCvBERk4wq-GEgAAAS4"]
[Thu Jul 30 15:20:25.924206 2026] [core:notice] [pid 147647:tid 147858] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:25.962396 2026] [core:error] [pid 147647:tid 147819] [client 45.249.89.53:49475] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:25.962424 2026] [core:error] [pid 147647:tid 147819] [client 45.249.89.53:49475] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:25.984020 2026] [security2:error] [pid 147647:tid 147843] [client 20.151.221.234:37513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuyCe_ioCvBERk4wq-GGwAAAUw"]
[Thu Jul 30 15:20:26.369972 2026] [security2:error] [pid 147647:tid 147811] [client 158.158.41.78:34075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-admin/css/index.php"] [unique_id "amuyCu_ioCvBERk4wq-GIQAAASw"]
[Thu Jul 30 15:20:26.418289 2026] [core:error] [pid 147647:tid 147775] [remote 157.55.39.222:19539] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:26.418316 2026] [core:error] [pid 147647:tid 147775] [remote 157.55.39.222:19539] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:26.427624 2026] [security2:error] [pid 147647:tid 147892] [client 20.226.5.174:36011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/config.php"] [unique_id "amuyCu_ioCvBERk4wq-GJgAAAX0"]
[Thu Jul 30 15:20:26.911082 2026] [security2:error] [pid 147647:tid 147659] [remote 216.73.216.51:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuyCu_ioCvBERk4wq-GMQABZQs"]
[Thu Jul 30 15:20:27.006530 2026] [security2:error] [pid 147647:tid 147789] [client 20.63.98.115:32108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/nakrip.php"] [unique_id "amuyC-_ioCvBERk4wq-GOQAAARY"]
[Thu Jul 30 15:20:27.105530 2026] [security2:error] [pid 147647:tid 147818] [client 20.151.221.234:50905] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "sv.radiojelli.com"] [uri "/wp-content/1.php"] [unique_id "amuyC-_ioCvBERk4wq-GPQAAATM"]
[Thu Jul 30 15:20:27.105668 2026] [security2:error] [pid 147647:tid 147818] [client 20.151.221.234:50905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/1.php"] [unique_id "amuyC-_ioCvBERk4wq-GPQAAATM"]
[Thu Jul 30 15:20:27.170757 2026] [security2:error] [pid 147647:tid 147847] [client 138.124.103.234:39692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/wp-config.php.txt"] [unique_id "amuyC-_ioCvBERk4wq-GPgAAAVA"]
[Thu Jul 30 15:20:27.395417 2026] [security2:error] [pid 147647:tid 147796] [client 45.249.89.53:50013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/wp-config.php.bak"] [unique_id "amuyC-_ioCvBERk4wq-GQAAAAR0"]
[Thu Jul 30 15:20:27.480424 2026] [security2:error] [pid 147647:tid 147806] [client 172.237.109.114:42496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyCu_ioCvBERk4wq-GNwAAASc"]
[Thu Jul 30 15:20:27.490314 2026] [core:notice] [pid 147647:tid 147884] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:27.591435 2026] [core:notice] [pid 147647:tid 147658] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:27.840453 2026] [security2:error] [pid 147647:tid 147820] [client 158.158.41.78:52132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/edit.php"] [unique_id "amuyC-_ioCvBERk4wq-GTQAAATU"]
[Thu Jul 30 15:20:27.913701 2026] [core:error] [pid 147647:tid 147874] [client 64.227.104.105:56886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:27.913723 2026] [core:error] [pid 147647:tid 147874] [client 64.227.104.105:56886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:28.243398 2026] [core:notice] [pid 147647:tid 147733] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:28.291672 2026] [security2:error] [pid 147647:tid 147879] [client 20.63.98.115:25690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/radio.php"] [unique_id "amuyDO_ioCvBERk4wq-GXgAAAXA"]
[Thu Jul 30 15:20:28.320623 2026] [security2:error] [pid 147647:tid 147841] [client 20.151.221.234:11413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/plugin.php"] [unique_id "amuyDO_ioCvBERk4wq-GXwAAAUo"]
[Thu Jul 30 15:20:28.386782 2026] [core:error] [pid 147647:tid 147788] [client 13.218.20.238:55496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:28.386803 2026] [core:error] [pid 147647:tid 147788] [client 13.218.20.238:55496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:28.508741 2026] [core:notice] [pid 147647:tid 147819] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:28.508929 2026] [security2:error] [pid 147647:tid 147833] [client 138.124.103.234:39702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/wp-config.php~"] [unique_id "amuyDO_ioCvBERk4wq-GZQAAAUI"]
[Thu Jul 30 15:20:28.512218 2026] [security2:error] [pid 147647:tid 147819] [client 66.249.79.229:64748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA/article/view/8396/3490"] [unique_id "amuyDO_ioCvBERk4wq-GZAAAATQ"]
[Thu Jul 30 15:20:28.590651 2026] [security2:error] [pid 147647:tid 147883] [client 172.237.109.114:61145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyDO_ioCvBERk4wq-GUgAAAXQ"]
[Thu Jul 30 15:20:28.732273 2026] [core:notice] [pid 147647:tid 147786] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:28.786926 2026] [security2:error] [pid 147647:tid 147866] [client 45.249.89.53:50559] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/wp-config.php.old"] [unique_id "amuyDO_ioCvBERk4wq-GbwAAAWM"]
[Thu Jul 30 15:20:28.923660 2026] [security2:error] [pid 147647:tid 147843] [client 20.226.5.174:36025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/core.php"] [unique_id "amuyDO_ioCvBERk4wq-GcAAAAUw"]
[Thu Jul 30 15:20:29.103650 2026] [core:error] [pid 147647:tid 147886] [client 64.227.104.105:33188] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:29.103670 2026] [core:error] [pid 147647:tid 147886] [client 64.227.104.105:33188] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:29.730684 2026] [security2:error] [pid 147647:tid 147801] [client 20.63.98.115:36080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-singin.php"] [unique_id "amuyDe_ioCvBERk4wq-GhQAAASI"]
[Thu Jul 30 15:20:29.935894 2026] [security2:error] [pid 147647:tid 147836] [client 74.7.241.149:35228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.qmv.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amuyDe_ioCvBERk4wq-GigAAAUU"]
[Thu Jul 30 15:20:30.031672 2026] [security2:error] [pid 147647:tid 147839] [client 138.124.103.234:39714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.103.124.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/config/app.php"] [unique_id "amuyDe_ioCvBERk4wq-GiQAAAUg"]
[Thu Jul 30 15:20:30.041081 2026] [core:notice] [pid 147647:tid 147687] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:30.083819 2026] [security2:error] [pid 147647:tid 147894] [client 20.151.221.234:39880] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "sv.radiojelli.com"] [uri "/1.php"] [unique_id "amuyDu_ioCvBERk4wq-GjwAAAX8"]
[Thu Jul 30 15:20:30.086257 2026] [security2:error] [pid 147647:tid 147894] [client 20.151.221.234:39880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/1.php"] [unique_id "amuyDu_ioCvBERk4wq-GjwAAAX8"]
[Thu Jul 30 15:20:30.111518 2026] [security2:error] [pid 147647:tid 147787] [client 20.226.5.174:5712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfa1337.php"] [unique_id "amuyDu_ioCvBERk4wq-GkAAAARQ"]
[Thu Jul 30 15:20:30.170623 2026] [security2:error] [pid 147647:tid 147820] [client 45.249.89.53:51129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/wp-config.php.save"] [unique_id "amuyDu_ioCvBERk4wq-GkQAAATU"]
[Thu Jul 30 15:20:30.323164 2026] [core:error] [pid 147647:tid 147887] [client 64.227.104.105:33204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:30.323183 2026] [core:error] [pid 147647:tid 147887] [client 64.227.104.105:33204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:30.558519 2026] [security2:error] [pid 147647:tid 147882] [client 20.63.98.115:32345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/as.php"] [unique_id "amuyDu_ioCvBERk4wq-GnwAAAXM"]
[Thu Jul 30 15:20:30.660694 2026] [core:notice] [pid 147647:tid 147897] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:30.661069 2026] [core:notice] [pid 147647:tid 147883] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:30.765335 2026] [security2:error] [pid 147647:tid 147899] [client 114.119.151.119:41759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/soldes-chez-andre-hiver-2016/boots-talons-vibration_andre/"] [unique_id "amuyDu_ioCvBERk4wq-GpQAAAYQ"], referer: https://www.carnetdeshopping.com/soldes-chez-andre-hiver-2016/boots-talons-vibration_andre/
[Thu Jul 30 15:20:30.869479 2026] [security2:error] [pid 147647:tid 147869] [client 20.151.221.234:11409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/gg.php"] [unique_id "amuyDu_ioCvBERk4wq-GqQAAAWY"]
[Thu Jul 30 15:20:30.985511 2026] [security2:error] [pid 147647:tid 147892] [client 50.6.43.217:31586] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuyDu_ioCvBERk4wq-GqgAAAX0"]
[Thu Jul 30 15:20:31.037339 2026] [security2:error] [pid 147647:tid 147865] [client 20.226.5.174:5701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfa3.php"] [unique_id "amuyD-_ioCvBERk4wq-GrAAAAWI"]
[Thu Jul 30 15:20:31.205148 2026] [core:notice] [pid 147647:tid 147808] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:31.235230 2026] [core:notice] [pid 147647:tid 147804] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:31.285212 2026] [core:error] [pid 147647:tid 147890] [client 138.124.103.234:39722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:31.285236 2026] [core:error] [pid 147647:tid 147890] [client 138.124.103.234:39722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:31.361188 2026] [security2:error] [pid 147647:tid 147875] [client 20.226.5.174:33357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/css.php"] [unique_id "amuyD-_ioCvBERk4wq-GuAAAAWw"]
[Thu Jul 30 15:20:31.497839 2026] [security2:error] [pid 147647:tid 147837] [client 172.237.109.114:19123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyD-_ioCvBERk4wq-GqwAAAUY"]
[Thu Jul 30 15:20:31.693623 2026] [core:notice] [pid 147647:tid 147818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:31.697344 2026] [security2:error] [pid 147647:tid 147818] [client 66.249.79.8:41576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/1510/894"] [unique_id "amuyD-_ioCvBERk4wq-GvQAAATM"]
[Thu Jul 30 15:20:31.941832 2026] [security2:error] [pid 147647:tid 147794] [client 20.151.221.234:11594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp.php"] [unique_id "amuyD-_ioCvBERk4wq-GxgAAARs"]
[Thu Jul 30 15:20:31.956191 2026] [security2:error] [pid 147647:tid 147791] [client 20.226.5.174:5700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfaaneh.php"] [unique_id "amuyD-_ioCvBERk4wq-GxwAAARg"]
[Thu Jul 30 15:20:31.980306 2026] [core:error] [pid 147647:tid 147881] [client 64.227.104.105:33208] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:31.980326 2026] [core:error] [pid 147647:tid 147881] [client 64.227.104.105:33208] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:32.179679 2026] [core:notice] [pid 147647:tid 147864] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:32.387452 2026] [security2:error] [pid 147647:tid 147877] [client 50.6.43.217:31592] ModSecurity: Warning. Matched phrase "Devil" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "black-devil-shop.com"] [uri "/wp-cron.php"] [unique_id "amuyEO_ioCvBERk4wq-G0QAAAW4"]
[Thu Jul 30 15:20:32.471209 2026] [security2:error] [pid 147647:tid 147793] [client 20.63.98.115:42398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/x.php"] [unique_id "amuyEO_ioCvBERk4wq-G1QAAARo"]
[Thu Jul 30 15:20:32.569732 2026] [core:error] [pid 147647:tid 147898] [client 138.124.103.234:39724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:32.569764 2026] [core:error] [pid 147647:tid 147898] [client 138.124.103.234:39724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:32.597804 2026] [security2:error] [pid 147647:tid 147697] [remote 216.73.216.51:52181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuyEO_ioCvBERk4wq-G1wABFDE"]
[Thu Jul 30 15:20:32.677327 2026] [core:notice] [pid 147647:tid 147819] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:32.680997 2026] [security2:error] [pid 147647:tid 147819] [client 66.249.79.8:41576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/3910/1949"] [unique_id "amuyEO_ioCvBERk4wq-G2AAAATQ"]
[Thu Jul 30 15:20:32.739718 2026] [security2:error] [pid 147647:tid 147841] [client 20.151.221.234:11407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuyEO_ioCvBERk4wq-G3AAAAUo"]
[Thu Jul 30 15:20:32.908175 2026] [security2:error] [pid 147647:tid 147888] [client 20.226.5.174:5703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfacgiapi/bypass.php"] [unique_id "amuyEO_ioCvBERk4wq-G4AAAAXk"]
[Thu Jul 30 15:20:32.910272 2026] [security2:error] [pid 147647:tid 147785] [client 20.226.5.174:35997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/database.php"] [unique_id "amuyEO_ioCvBERk4wq-G4QAAARI"]
[Thu Jul 30 15:20:33.235814 2026] [security2:error] [pid 147647:tid 147855] [client 23.94.216.234:55030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "black-devil-shop.com"] [uri "/"] [unique_id "amuyEe_ioCvBERk4wq-G6AAAAVg"]
[Thu Jul 30 15:20:33.457072 2026] [core:error] [pid 147647:tid 147869] [client 64.227.104.105:33214] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:33.457098 2026] [core:error] [pid 147647:tid 147869] [client 64.227.104.105:33214] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:33.467238 2026] [security2:error] [pid 147647:tid 147900] [client 158.158.41.78:40478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/2.php"] [unique_id "amuyEe_ioCvBERk4wq-G7wAAAYU"]
[Thu Jul 30 15:20:33.623909 2026] [core:notice] [pid 147647:tid 147890] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:33.627469 2026] [security2:error] [pid 147647:tid 147890] [client 66.249.79.229:45712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/download/1893/1413"] [unique_id "amuyEe_ioCvBERk4wq-G8gAAAXs"]
[Thu Jul 30 15:20:33.657547 2026] [security2:error] [pid 147647:tid 147703] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyEe_ioCvBERk4wq-G8wABUTc"]
[Thu Jul 30 15:20:33.657732 2026] [security2:error] [pid 147647:tid 147848] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyEe_ioCvBERk4wq-G8wABUTc"]
[Thu Jul 30 15:20:33.835680 2026] [security2:error] [pid 147647:tid 147789] [client 20.226.5.174:5707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfacgiapi/go.php"] [unique_id "amuyEe_ioCvBERk4wq-G9wAAARY"]
[Thu Jul 30 15:20:33.848858 2026] [core:notice] [pid 147647:tid 147803] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:33.993300 2026] [core:error] [pid 147647:tid 147846] [client 138.124.103.234:59802] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:33.993318 2026] [core:error] [pid 147647:tid 147846] [client 138.124.103.234:59802] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:33.996138 2026] [security2:error] [pid 147647:tid 147866] [client 20.151.221.234:11636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/file.php"] [unique_id "amuyEe_ioCvBERk4wq-G_QAAAWM"]
[Thu Jul 30 15:20:34.218234 2026] [security2:error] [pid 147647:tid 147871] [client 158.158.41.78:17054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuyEu_ioCvBERk4wq-HBAAAAWg"]
[Thu Jul 30 15:20:34.300128 2026] [core:notice] [pid 147647:tid 147816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:34.303904 2026] [security2:error] [pid 147647:tid 147816] [client 66.249.79.229:45712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/543"] [unique_id "amuyEu_ioCvBERk4wq-HDAAAATE"]
[Thu Jul 30 15:20:34.364395 2026] [security2:error] [pid 147647:tid 147791] [client 20.63.98.115:42427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/item.php"] [unique_id "amuyEu_ioCvBERk4wq-HDQAAARg"]
[Thu Jul 30 15:20:34.584033 2026] [security2:error] [pid 147647:tid 147796] [client 172.237.109.114:54162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyEu_ioCvBERk4wq-G_gAAAR0"]
[Thu Jul 30 15:20:34.736996 2026] [security2:error] [pid 147647:tid 147896] [client 64.227.104.105:33220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/wp-config.php.bak"] [unique_id "amuyEu_ioCvBERk4wq-HFAAAAYE"]
[Thu Jul 30 15:20:34.742690 2026] [security2:error] [pid 147647:tid 147839] [client 20.226.5.174:5708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfacgiapi/perl.alfa.php"] [unique_id "amuyEu_ioCvBERk4wq-HFQAAAUg"]
[Thu Jul 30 15:20:34.801665 2026] [core:notice] [pid 147647:tid 147820] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:34.805426 2026] [security2:error] [pid 147647:tid 147820] [client 66.249.79.229:45712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/download/11/11"] [unique_id "amuyEu_ioCvBERk4wq-HGQAAATU"]
[Thu Jul 30 15:20:34.888591 2026] [security2:error] [pid 147647:tid 147857] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyEu_ioCvBERk4wq-HCAAAAVo"]
[Thu Jul 30 15:20:34.888589 2026] [security2:error] [pid 147647:tid 147836] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyEu_ioCvBERk4wq-HCwAAAUU"]
[Thu Jul 30 15:20:34.890330 2026] [security2:error] [pid 147647:tid 147782] [client 20.226.5.174:36006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/db.php"] [unique_id "amuyEu_ioCvBERk4wq-HGgAAAQ8"]
[Thu Jul 30 15:20:35.367505 2026] [core:error] [pid 147647:tid 147878] [client 138.124.103.234:59814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:35.367546 2026] [core:error] [pid 147647:tid 147878] [client 138.124.103.234:59814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:35.449478 2026] [security2:error] [pid 147647:tid 147858] [client 172.237.109.114:39810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyEu_ioCvBERk4wq-HHAAAAVs"]
[Thu Jul 30 15:20:35.549102 2026] [core:notice] [pid 147647:tid 147849] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:35.687695 2026] [security2:error] [pid 147647:tid 147822] [client 20.226.5.174:5714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfacgiapiadmin.php"] [unique_id "amuyE-_ioCvBERk4wq-HMAAAATc"]
[Thu Jul 30 15:20:35.897559 2026] [core:error] [pid 147647:tid 147709] [remote 207.46.13.128:55796] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:35.897580 2026] [core:error] [pid 147647:tid 147709] [remote 207.46.13.128:55796] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:35.987859 2026] [security2:error] [pid 147647:tid 147886] [client 20.226.5.174:33364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/default.php"] [unique_id "amuyE-_ioCvBERk4wq-HNwAAAXc"]
[Thu Jul 30 15:20:36.065815 2026] [security2:error] [pid 147647:tid 147848] [client 20.151.221.234:11443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuyFO_ioCvBERk4wq-HPAAAAVE"]
[Thu Jul 30 15:20:36.087821 2026] [security2:error] [pid 147647:tid 147795] [client 158.158.41.78:15589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "raad.pk"] [uri "/mah.php"] [unique_id "amuyFO_ioCvBERk4wq-HPQAAARw"]
[Thu Jul 30 15:20:36.199037 2026] [security2:error] [pid 147647:tid 147867] [client 64.227.104.105:33232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/wp-config.php.old"] [unique_id "amuyFO_ioCvBERk4wq-HPgAAAWQ"]
[Thu Jul 30 15:20:36.259832 2026] [core:notice] [pid 147647:tid 147815] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:36.616242 2026] [security2:error] [pid 147647:tid 147801] [client 20.226.5.174:5723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfacgiapialfa.php"] [unique_id "amuyFO_ioCvBERk4wq-HSQAAASI"]
[Thu Jul 30 15:20:36.676814 2026] [core:error] [pid 147647:tid 147838] [client 138.124.103.234:59824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:36.676837 2026] [core:error] [pid 147647:tid 147838] [client 138.124.103.234:59824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:36.848390 2026] [core:notice] [pid 147647:tid 147856] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:37.297415 2026] [core:notice] [pid 147647:tid 147834] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:37.400115 2026] [security2:error] [pid 147647:tid 147904] [client 20.151.221.234:50919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuyFe_ioCvBERk4wq-HWwAAAYk"]
[Thu Jul 30 15:20:37.439457 2026] [security2:error] [pid 147647:tid 147787] [client 172.237.109.114:54037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyFO_ioCvBERk4wq-HTwAAARQ"]
[Thu Jul 30 15:20:37.483343 2026] [security2:error] [pid 147647:tid 147777] [client 20.226.5.174:36019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/dropdown.php"] [unique_id "amuyFe_ioCvBERk4wq-HYAAAAQo"]
[Thu Jul 30 15:20:37.548470 2026] [security2:error] [pid 147647:tid 147887] [client 20.226.5.174:5716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfacgiapibypass.php"] [unique_id "amuyFe_ioCvBERk4wq-HYgAAAXg"]
[Thu Jul 30 15:20:37.932417 2026] [security2:error] [pid 147647:tid 147828] [client 64.227.104.105:33244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/wp-config.php.save"] [unique_id "amuyFe_ioCvBERk4wq-HcAAAAT0"]
[Thu Jul 30 15:20:38.163963 2026] [security2:error] [pid 147647:tid 147808] [client 20.151.221.234:50902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/index/function.php"] [unique_id "amuyFu_ioCvBERk4wq-HeAAAASk"]
[Thu Jul 30 15:20:38.259849 2026] [security2:error] [pid 147647:tid 147821] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyFe_ioCvBERk4wq-HawAAATY"]
[Thu Jul 30 15:20:38.502076 2026] [security2:error] [pid 147647:tid 147844] [client 20.226.5.174:5705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfacgiapik.php"] [unique_id "amuyFu_ioCvBERk4wq-HfgAAAU0"]
[Thu Jul 30 15:20:38.736202 2026] [security2:error] [pid 147647:tid 147781] [client 47.128.121.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuyFe_ioCvBERk4wq-HXAAAAQ4"]
[Thu Jul 30 15:20:38.760091 2026] [security2:error] [pid 147647:tid 147792] [client 104.210.56.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuyFu_ioCvBERk4wq-HeQABGVs"]
[Thu Jul 30 15:20:38.920109 2026] [security2:error] [pid 147647:tid 147803] [client 20.63.98.115:36039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/app.php"] [unique_id "amuyFu_ioCvBERk4wq-HhwAAASQ"]
[Thu Jul 30 15:20:38.999361 2026] [core:error] [pid 147647:tid 147816] [client 138.124.103.234:59828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:38.999388 2026] [core:error] [pid 147647:tid 147816] [client 138.124.103.234:59828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:39.421365 2026] [security2:error] [pid 147647:tid 147823] [client 64.227.104.105:39724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/wp-config.php.txt"] [unique_id "amuyF-_ioCvBERk4wq-HlAAAATg"]
[Thu Jul 30 15:20:39.437397 2026] [security2:error] [pid 147647:tid 147853] [client 20.226.5.174:5704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfacgiapiwp.php"] [unique_id "amuyF-_ioCvBERk4wq-HlQAAAVY"]
[Thu Jul 30 15:20:39.492287 2026] [security2:error] [pid 147647:tid 147841] [client 20.151.221.234:37544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/aaa.php"] [unique_id "amuyF-_ioCvBERk4wq-HmwAAAUo"]
[Thu Jul 30 15:20:39.547540 2026] [security2:error] [pid 147647:tid 147735] [remote 91.86.16.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.16.86.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.spececigarette.com"] [uri "/wp-login.php"] [unique_id "amuyF-_ioCvBERk4wq-HnAABRVc"]
[Thu Jul 30 15:20:39.643597 2026] [security2:error] [pid 147647:tid 147810] [client 20.63.98.115:42417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/k.php"] [unique_id "amuyF-_ioCvBERk4wq-HnQAAASs"]
[Thu Jul 30 15:20:40.052380 2026] [security2:error] [pid 147647:tid 147879] [client 2a03:2880:f800:10:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyF-_ioCvBERk4wq-HmAABcGs"]
[Thu Jul 30 15:20:40.366105 2026] [security2:error] [pid 147647:tid 147855] [client 20.226.5.174:5706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfadheat.php"] [unique_id "amuyGO_ioCvBERk4wq-HrQAAAVg"]
[Thu Jul 30 15:20:40.527550 2026] [security2:error] [pid 147647:tid 147850] [client 20.226.5.174:35970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/edit.php"] [unique_id "amuyGO_ioCvBERk4wq-HrgAAAVM"]
[Thu Jul 30 15:20:40.759161 2026] [security2:error] [pid 147647:tid 147845] [client 64.227.104.105:39726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/wp-config.php~"] [unique_id "amuyGO_ioCvBERk4wq-HtQAAAU4"]
[Thu Jul 30 15:20:41.172421 2026] [security2:error] [pid 147647:tid 147878] [client 20.151.221.234:37530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/getid3-core.php"] [unique_id "amuyGe_ioCvBERk4wq-HvgAAAW8"]
[Thu Jul 30 15:20:41.335147 2026] [security2:error] [pid 147647:tid 147880] [client 20.226.5.174:5726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfaindex.php"] [unique_id "amuyGe_ioCvBERk4wq-HxQAAAXE"]
[Thu Jul 30 15:20:41.339495 2026] [security2:error] [pid 147647:tid 147897] [client 20.63.98.115:36068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-fmfile.php"] [unique_id "amuyGe_ioCvBERk4wq-HxgAAAYI"]
[Thu Jul 30 15:20:41.621920 2026] [security2:error] [pid 147647:tid 147781] [client 20.226.5.174:35977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/f35.php"] [unique_id "amuyGe_ioCvBERk4wq-HygAAAQ4"]
[Thu Jul 30 15:20:42.023712 2026] [core:notice] [pid 147647:tid 147816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:42.027114 2026] [security2:error] [pid 147647:tid 147816] [client 66.249.79.229:55527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/view/9626"] [unique_id "amuyGu_ioCvBERk4wq-H1AAAATE"]
[Thu Jul 30 15:20:42.282965 2026] [security2:error] [pid 147647:tid 147798] [client 66.249.73.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuyGu_ioCvBERk4wq-H2wAAAR8"]
[Thu Jul 30 15:20:42.366793 2026] [security2:error] [pid 147647:tid 147896] [client 20.226.5.174:5721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfakun.php"] [unique_id "amuyGu_ioCvBERk4wq-H4wAAAYE"]
[Thu Jul 30 15:20:42.463291 2026] [security2:error] [pid 147647:tid 147870] [client 20.63.98.115:36032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wi.php"] [unique_id "amuyGu_ioCvBERk4wq-H5QAAAWc"]
[Thu Jul 30 15:20:42.567447 2026] [security2:error] [pid 147647:tid 147830] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rocket-bookkeepers.com"] [uri "/wp-admin/install.php"] [unique_id "amuyGu_ioCvBERk4wq-H5gAAAT8"]
[Thu Jul 30 15:20:42.591511 2026] [security2:error] [pid 147647:tid 147790] [client 20.151.221.234:11392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/adminer.php"] [unique_id "amuyGu_ioCvBERk4wq-H6gAAARc"]
[Thu Jul 30 15:20:42.692140 2026] [security2:error] [pid 147647:tid 147791] [client 64.227.104.105:39728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.104.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/config/app.php"] [unique_id "amuyGu_ioCvBERk4wq-H5AAAARg"]
[Thu Jul 30 15:20:43.086383 2026] [security2:error] [pid 147647:tid 147843] [client 20.226.5.174:35985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bonafideadvisors.com"] [uri "/f7.php"] [unique_id "amuyG-_ioCvBERk4wq-H-AAAAUw"]
[Thu Jul 30 15:20:43.277373 2026] [security2:error] [pid 147647:tid 147873] [client 20.226.5.174:5696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfalonte.php"] [unique_id "amuyG-_ioCvBERk4wq-H_AAAAWo"]
[Thu Jul 30 15:20:43.335358 2026] [security2:error] [pid 147647:tid 147828] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyGu_ioCvBERk4wq-H8QAAAT0"]
[Thu Jul 30 15:20:43.818169 2026] [security2:error] [pid 147647:tid 147866] [client 20.151.221.234:39888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/alfa.php"] [unique_id "amuyG-_ioCvBERk4wq-ICAAAAWM"]
[Thu Jul 30 15:20:44.106808 2026] [core:error] [pid 147647:tid 147902] [client 64.227.104.105:39740] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:44.106831 2026] [core:error] [pid 147647:tid 147902] [client 64.227.104.105:39740] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:44.174009 2026] [security2:error] [pid 147647:tid 147847] [client 20.226.5.174:5708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfanew.php"] [unique_id "amuyHO_ioCvBERk4wq-IEgAAAVA"]
[Thu Jul 30 15:20:44.204591 2026] [security2:error] [pid 147647:tid 147656] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyHO_ioCvBERk4wq-IFQABHgg"]
[Thu Jul 30 15:20:44.204733 2026] [security2:error] [pid 147647:tid 147797] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyHO_ioCvBERk4wq-IFQABHgg"]
[Thu Jul 30 15:20:44.732465 2026] [core:notice] [pid 147647:tid 147798] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:44.799838 2026] [security2:error] [pid 147647:tid 147854] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyHO_ioCvBERk4wq-IGAAAAVc"]
[Thu Jul 30 15:20:44.834185 2026] [core:notice] [pid 147647:tid 147810] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:45.106674 2026] [security2:error] [pid 147647:tid 147780] [client 20.226.5.174:5739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfashell.php"] [unique_id "amuyHe_ioCvBERk4wq-ILQAAAQ0"]
[Thu Jul 30 15:20:45.117461 2026] [security2:error] [pid 147647:tid 147904] [client 187.184.234.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuyHe_ioCvBERk4wq-IKwAAAYk"], referer: https://cnpinyin.com
[Thu Jul 30 15:20:45.137561 2026] [security2:error] [pid 147647:tid 147875] [client 20.63.98.115:46684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/php8.php"] [unique_id "amuyHe_ioCvBERk4wq-ILgAAAWw"]
[Thu Jul 30 15:20:45.452531 2026] [core:error] [pid 147647:tid 147830] [client 64.227.104.105:39754] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:45.452561 2026] [core:error] [pid 147647:tid 147830] [client 64.227.104.105:39754] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:45.470090 2026] [core:notice] [pid 147647:tid 147808] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:45.487301 2026] [core:error] [pid 147647:tid 147835] [client 138.124.103.234:52722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:45.487323 2026] [core:error] [pid 147647:tid 147835] [client 138.124.103.234:52722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:45.566485 2026] [security2:error] [pid 147647:tid 147667] [remote 57.141.0.48:63876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuyHe_ioCvBERk4wq-INgABUxM"]
[Thu Jul 30 15:20:45.616716 2026] [security2:error] [pid 147647:tid 147851] [client 20.151.221.234:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuyHe_ioCvBERk4wq-INwAAAVQ"]
[Thu Jul 30 15:20:46.052908 2026] [security2:error] [pid 147647:tid 147822] [client 20.226.5.174:5715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfatesla.php"] [unique_id "amuyHu_ioCvBERk4wq-IOAAAATc"]
[Thu Jul 30 15:20:46.257957 2026] [security2:error] [pid 147647:tid 147852] [client 20.63.98.115:36693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/tes.php"] [unique_id "amuyHu_ioCvBERk4wq-IQAAAAVU"]
[Thu Jul 30 15:20:46.538047 2026] [security2:error] [pid 147647:tid 147829] [client 20.151.221.234:37534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuyHu_ioCvBERk4wq-IRAAAAT4"]
[Thu Jul 30 15:20:46.809601 2026] [core:error] [pid 147647:tid 147882] [client 138.124.103.234:52732] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:46.809622 2026] [core:error] [pid 147647:tid 147882] [client 138.124.103.234:52732] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:46.922835 2026] [core:error] [pid 147647:tid 147880] [client 64.227.104.105:39760] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:46.922858 2026] [core:error] [pid 147647:tid 147880] [client 64.227.104.105:39760] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:47.073915 2026] [security2:error] [pid 147647:tid 147867] [client 20.226.5.174:5713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfateslav4.php"] [unique_id "amuyH-_ioCvBERk4wq-IUQAAAWQ"]
[Thu Jul 30 15:20:47.205551 2026] [core:notice] [pid 147647:tid 147796] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:47.209440 2026] [security2:error] [pid 147647:tid 147796] [client 66.249.79.229:46425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/download/640/417"] [unique_id "amuyH-_ioCvBERk4wq-IVQAAAR0"]
[Thu Jul 30 15:20:47.465216 2026] [security2:error] [pid 147647:tid 147810] [client 2.88.91.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuyH-_ioCvBERk4wq-IXgAAASs"], referer: https://cnpinyin.com
[Thu Jul 30 15:20:47.510371 2026] [security2:error] [pid 147647:tid 147881] [client 20.151.221.234:50892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuyH-_ioCvBERk4wq-IYgAAAXI"]
[Thu Jul 30 15:20:47.915010 2026] [core:notice] [pid 147647:tid 147860] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:48.091352 2026] [security2:error] [pid 147647:tid 147791] [client 20.226.5.174:5736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfav4-1-0.php"] [unique_id "amuyIO_ioCvBERk4wq-IcQAAARg"]
[Thu Jul 30 15:20:48.140369 2026] [core:notice] [pid 147647:tid 147857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:48.164425 2026] [core:error] [pid 147647:tid 147827] [client 138.124.103.234:52742] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:48.164450 2026] [core:error] [pid 147647:tid 147827] [client 138.124.103.234:52742] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:48.285281 2026] [core:error] [pid 147647:tid 147900] [client 64.227.104.105:40234] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:48.285305 2026] [core:error] [pid 147647:tid 147900] [client 64.227.104.105:40234] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:48.388756 2026] [security2:error] [pid 147647:tid 147814] [client 168.110.218.47:30084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.218.110.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/config/app.php"] [unique_id "amuyIO_ioCvBERk4wq-IcwAAAS8"]
[Thu Jul 30 15:20:48.602344 2026] [security2:error] [pid 147647:tid 147841] [client 20.151.221.234:37525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/edit.php"] [unique_id "amuyIO_ioCvBERk4wq-IfwAAAUo"]
[Thu Jul 30 15:20:49.064056 2026] [security2:error] [pid 147647:tid 147863] [client 20.226.5.174:5697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfav4-1.php"] [unique_id "amuyIe_ioCvBERk4wq-IigAAAWA"]
[Thu Jul 30 15:20:49.592615 2026] [core:error] [pid 147647:tid 147781] [client 64.227.104.105:40240] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:49.592647 2026] [core:error] [pid 147647:tid 147781] [client 64.227.104.105:40240] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:49.645737 2026] [core:error] [pid 147647:tid 147813] [client 138.124.103.234:52746] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:49.645757 2026] [core:error] [pid 147647:tid 147813] [client 138.124.103.234:52746] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:49.836219 2026] [core:notice] [pid 147647:tid 147836] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:50.079705 2026] [security2:error] [pid 147647:tid 147875] [client 20.226.5.174:5733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfav4-1.tesla.php"] [unique_id "amuyIu_ioCvBERk4wq-IqgAAAWw"]
[Thu Jul 30 15:20:50.297232 2026] [core:notice] [pid 147647:tid 147850] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:50.571070 2026] [security2:error] [pid 147647:tid 147811] [client 172.237.109.114:7664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyIe_ioCvBERk4wq-IpQAAASw"]
[Thu Jul 30 15:20:51.036586 2026] [security2:error] [pid 147647:tid 147786] [client 20.226.5.174:5710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfav4.1.php"] [unique_id "amuyI-_ioCvBERk4wq-IyAAAARM"]
[Thu Jul 30 15:20:51.222961 2026] [security2:error] [pid 147647:tid 147897] [client 20.151.221.234:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/sf.php"] [unique_id "amuyI-_ioCvBERk4wq-IygAAAYI"]
[Thu Jul 30 15:20:51.729280 2026] [proxy:error] [pid 147647:tid 147790] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:20:51.729359 2026] [proxy_http:error] [pid 147647:tid 147790] [client 54.87.222.253:3675] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:20:51.729920 2026] [proxy:error] [pid 147647:tid 147790] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:20:51.729962 2026] [proxy_http:error] [pid 147647:tid 147790] [client 54.87.222.253:3675] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:20:51.850860 2026] [proxy:error] [pid 147647:tid 147813] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:20:51.850941 2026] [proxy_http:error] [pid 147647:tid 147813] [client 52.202.41.153:33908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:20:51.851538 2026] [proxy:error] [pid 147647:tid 147813] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:20:51.851582 2026] [proxy_http:error] [pid 147647:tid 147813] [client 52.202.41.153:33908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:20:51.947570 2026] [security2:error] [pid 147647:tid 147904] [client 20.226.5.174:5732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alfax.php"] [unique_id "amuyI-_ioCvBERk4wq-I4QAAAYk"]
[Thu Jul 30 15:20:52.061925 2026] [core:error] [pid 147647:tid 147849] [client 64.227.104.105:40254] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:52.061946 2026] [core:error] [pid 147647:tid 147849] [client 64.227.104.105:40254] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:52.203395 2026] [security2:error] [pid 147647:tid 147785] [client 20.151.221.234:50911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wso.php"] [unique_id "amuyJO_ioCvBERk4wq-I8QAAARI"]
[Thu Jul 30 15:20:52.562516 2026] [core:error] [pid 147647:tid 147900] [client 138.124.103.234:52750] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:52.562538 2026] [core:error] [pid 147647:tid 147900] [client 138.124.103.234:52750] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:52.601218 2026] [security2:error] [pid 147647:tid 147827] [client 114.119.143.101:46801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/search"] [unique_id "amuyJO_ioCvBERk4wq-I-gAAATw"], referer: https://www.kendarikomputer.com/search?updated-max=2023-06-13T20%3A49%3A00%2B08%3A00&max-results=14&reverse-paginate=true&m=1
[Thu Jul 30 15:20:52.853952 2026] [security2:error] [pid 147647:tid 147888] [client 20.226.5.174:5731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/align.php"] [unique_id "amuyJO_ioCvBERk4wq-JBAAAAXk"]
[Thu Jul 30 15:20:53.131361 2026] [core:notice] [pid 147647:tid 147898] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:53.177522 2026] [autoindex:error] [pid 147647:tid 147892] [client 43.167.236.228:45906] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_170cb886/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:20:53.346709 2026] [security2:error] [pid 147647:tid 147820] [client 94.154.43.185:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "melatipkr.xyz"] [uri "/.env"] [unique_id "amuyJe_ioCvBERk4wq-JEQAAATU"]
[Thu Jul 30 15:20:53.354261 2026] [security2:error] [pid 147647:tid 147793] [client 94.154.43.184:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ok.melatipkr.xyz"] [uri "/.env"] [unique_id "amuyJe_ioCvBERk4wq-JEgAAARo"]
[Thu Jul 30 15:20:53.656661 2026] [core:error] [pid 147647:tid 147899] [client 64.227.104.105:40266] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:53.656686 2026] [core:error] [pid 147647:tid 147899] [client 64.227.104.105:40266] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:53.757109 2026] [security2:error] [pid 147647:tid 147891] [client 20.226.5.174:5709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alivos.php"] [unique_id "amuyJe_ioCvBERk4wq-JIAAAAXw"]
[Thu Jul 30 15:20:53.793888 2026] [security2:error] [pid 147647:tid 147786] [client 20.151.221.234:11433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/ioxi-o.php"] [unique_id "amuyJe_ioCvBERk4wq-JIQAAARM"]
[Thu Jul 30 15:20:53.867943 2026] [security2:error] [pid 147647:tid 147802] [client 20.63.98.115:52337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/about.php"] [unique_id "amuyJe_ioCvBERk4wq-JIgAAASM"]
[Thu Jul 30 15:20:53.922288 2026] [core:error] [pid 147647:tid 147839] [client 138.124.103.234:53624] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:53.922323 2026] [core:error] [pid 147647:tid 147839] [client 138.124.103.234:53624] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:54.756669 2026] [security2:error] [pid 147647:tid 147890] [client 20.226.5.174:5729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/all.php"] [unique_id "amuyJu_ioCvBERk4wq-JPgAAAXs"]
[Thu Jul 30 15:20:54.811204 2026] [security2:error] [pid 147647:tid 147832] [client 66.249.73.97:61736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuyJO_ioCvBERk4wq-I6gAAAUE"]
[Thu Jul 30 15:20:54.829078 2026] [security2:error] [pid 147647:tid 147852] [client 20.63.98.115:36691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/headers.php"] [unique_id "amuyJu_ioCvBERk4wq-JQwAAAVU"]
[Thu Jul 30 15:20:54.965283 2026] [security2:error] [pid 147647:tid 147824] [client 20.151.221.234:11428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/file56.php"] [unique_id "amuyJu_ioCvBERk4wq-JRAAAATk"]
[Thu Jul 30 15:20:55.013808 2026] [security2:error] [pid 147647:tid 147737] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyJ-_ioCvBERk4wq-JRQABY1k"]
[Thu Jul 30 15:20:55.014007 2026] [security2:error] [pid 147647:tid 147866] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyJ-_ioCvBERk4wq-JRQABY1k"]
[Thu Jul 30 15:20:55.137612 2026] [core:error] [pid 147647:tid 147794] [client 64.227.104.105:40276] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:55.137642 2026] [core:error] [pid 147647:tid 147794] [client 64.227.104.105:40276] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:55.197910 2026] [core:error] [pid 147647:tid 147801] [client 138.124.103.234:53634] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:55.197931 2026] [core:error] [pid 147647:tid 147801] [client 138.124.103.234:53634] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:55.522827 2026] [core:error] [pid 147647:tid 147876] [client 45.249.89.53:60363] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:55.522857 2026] [core:error] [pid 147647:tid 147876] [client 45.249.89.53:60363] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:55.612738 2026] [security2:error] [pid 147647:tid 147897] [client 172.237.109.114:13396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyJ-_ioCvBERk4wq-JRgAAAYI"]
[Thu Jul 30 15:20:55.698710 2026] [security2:error] [pid 147647:tid 147781] [client 20.226.5.174:5722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alpa.php"] [unique_id "amuyJ-_ioCvBERk4wq-JVAAAAQ4"]
[Thu Jul 30 15:20:55.948293 2026] [security2:error] [pid 147647:tid 147886] [client 20.151.221.234:11394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amuyJ-_ioCvBERk4wq-JYQAAAXc"]
[Thu Jul 30 15:20:56.128659 2026] [security2:error] [pid 147647:tid 147896] [client 20.63.98.115:46663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/admin.php"] [unique_id "amuyKO_ioCvBERk4wq-JZAAAAYE"]
[Thu Jul 30 15:20:56.373305 2026] [core:error] [pid 147647:tid 147843] [client 138.124.103.234:53650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:56.373326 2026] [core:error] [pid 147647:tid 147843] [client 138.124.103.234:53650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:56.432374 2026] [core:error] [pid 147647:tid 147855] [client 64.227.104.105:40282] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:56.432397 2026] [core:error] [pid 147647:tid 147855] [client 64.227.104.105:40282] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:56.436581 2026] [security2:error] [pid 147647:tid 147868] [client 185.191.171.16:20048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/11/25/relator-vota-contra-abertura-de-inquerito-sobre-moraes/"] [unique_id "amuyKO_ioCvBERk4wq-JcAAAAWU"]
[Thu Jul 30 15:20:56.436676 2026] [security2:error] [pid 147647:tid 147868] [client 185.191.171.16:20048] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/11/25/relator-vota-contra-abertura-de-inquerito-sobre-moraes/"] [unique_id "amuyKO_ioCvBERk4wq-JcAAAAWU"]
[Thu Jul 30 15:20:56.640093 2026] [security2:error] [pid 147647:tid 147889] [client 20.226.5.174:5730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alumni_reg.php"] [unique_id "amuyKO_ioCvBERk4wq-JcQAAAXo"]
[Thu Jul 30 15:20:56.669311 2026] [core:notice] [pid 147647:tid 147856] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:56.751157 2026] [security2:error] [pid 147647:tid 147844] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-d35de2e9.ear.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuyKO_ioCvBERk4wq-JeAAAAU0"]
[Thu Jul 30 15:20:56.751836 2026] [security2:error] [pid 147647:tid 147900] [client 74.7.241.158:44822] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-d35de2e9.ear.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuyKO_ioCvBERk4wq-JdgABhW4"]
[Thu Jul 30 15:20:56.895564 2026] [security2:error] [pid 147647:tid 147830] [client 20.151.221.234:39900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-admin/css/index.php"] [unique_id "amuyKO_ioCvBERk4wq-JfwAAAT8"]
[Thu Jul 30 15:20:56.914379 2026] [core:error] [pid 147647:tid 147825] [client 45.249.89.53:60857] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:56.914400 2026] [core:error] [pid 147647:tid 147825] [client 45.249.89.53:60857] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:57.353484 2026] [core:notice] [pid 147647:tid 147818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:57.631059 2026] [security2:error] [pid 147647:tid 147847] [client 20.226.5.174:5724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/alwso.php"] [unique_id "amuyKe_ioCvBERk4wq-JjgAAAVA"]
[Thu Jul 30 15:20:57.721552 2026] [core:error] [pid 147647:tid 147824] [client 64.227.104.105:40286] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:57.721587 2026] [core:error] [pid 147647:tid 147824] [client 64.227.104.105:40286] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:57.766350 2026] [core:error] [pid 147647:tid 147871] [client 138.124.103.234:53658] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:57.766374 2026] [core:error] [pid 147647:tid 147871] [client 138.124.103.234:53658] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:57.898251 2026] [security2:error] [pid 147647:tid 147820] [client 20.63.98.115:52344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/flower.php"] [unique_id "amuyKe_ioCvBERk4wq-JmwAAATU"]
[Thu Jul 30 15:20:58.160033 2026] [security2:error] [pid 147647:tid 147810] [client 20.151.221.234:39879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/edit.php"] [unique_id "amuyKu_ioCvBERk4wq-JnwAAASs"]
[Thu Jul 30 15:20:58.248758 2026] [core:notice] [pid 147647:tid 147826] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:58.307001 2026] [core:error] [pid 147647:tid 147779] [client 45.249.89.53:61315] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:58.307049 2026] [core:error] [pid 147647:tid 147779] [client 45.249.89.53:61315] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:58.640224 2026] [security2:error] [pid 147647:tid 147819] [client 20.63.98.115:25658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "amuyKu_ioCvBERk4wq-JqwAAATQ"]
[Thu Jul 30 15:20:58.668696 2026] [security2:error] [pid 147647:tid 147861] [client 20.226.5.174:5698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/am.php"] [unique_id "amuyKu_ioCvBERk4wq-JrAAAAV4"]
[Thu Jul 30 15:20:58.888765 2026] [security2:error] [pid 147647:tid 147765] [remote 114.119.131.200:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jipkl.com"] [uri "/index_php/JIPKL/article/view/7/9"] [unique_id "amuyKu_ioCvBERk4wq-JsQABPHU"], referer: https://www.jipkl.com/index.php/JIPKL/issue/view/2
[Thu Jul 30 15:20:58.962386 2026] [core:notice] [pid 147647:tid 147900] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:58.965906 2026] [security2:error] [pid 147647:tid 147900] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/view/177"] [unique_id "amuyKu_ioCvBERk4wq-JrQAAAYU"]
[Thu Jul 30 15:20:59.119649 2026] [security2:error] [pid 147647:tid 147814] [client 138.124.103.234:53666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/backup/.env"] [unique_id "amuyK-_ioCvBERk4wq-JuQAAAS8"]
[Thu Jul 30 15:20:59.271967 2026] [core:notice] [pid 147647:tid 147799] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:59.398269 2026] [security2:error] [pid 147647:tid 147797] [client 138.124.103.234:53666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/backups/.env"] [unique_id "amuyK-_ioCvBERk4wq-JvgAAAR4"]
[Thu Jul 30 15:20:59.476186 2026] [security2:error] [pid 147647:tid 147796] [client 20.151.221.234:11426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/2.php"] [unique_id "amuyK-_ioCvBERk4wq-JxgAAAR0"]
[Thu Jul 30 15:20:59.621759 2026] [security2:error] [pid 147647:tid 147795] [client 20.226.5.174:5734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.milfordauto.com"] [uri "/am4n.php"] [unique_id "amuyK-_ioCvBERk4wq-JzAAAARw"]
[Thu Jul 30 15:20:59.678715 2026] [security2:error] [pid 147647:tid 147904] [client 138.124.103.234:53666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/old/.env"] [unique_id "amuyK-_ioCvBERk4wq-JzQAAAYk"]
[Thu Jul 30 15:20:59.691559 2026] [core:error] [pid 147647:tid 147866] [client 45.249.89.53:61791] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:59.691584 2026] [core:error] [pid 147647:tid 147866] [client 45.249.89.53:61791] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:20:59.730841 2026] [security2:error] [pid 147647:tid 147784] [client 43.173.179.48:59524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/09/17/patricia-blanchet-imagine-une-collection-exclusive-pour-la-redoute/"] [unique_id "amuyK-_ioCvBERk4wq-JxQAAARE"]
[Thu Jul 30 15:20:59.791947 2026] [security2:error] [pid 147647:tid 147877] [client 43.172.195.248:56786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/02/23/suite-blanco-printemps-ete-2015/"] [unique_id "amuyK-_ioCvBERk4wq-JyQAAAW4"]
[Thu Jul 30 15:20:59.843067 2026] [core:notice] [pid 147647:tid 147821] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:20:59.846743 2026] [security2:error] [pid 147647:tid 147821] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/8322/3233"] [unique_id "amuyK-_ioCvBERk4wq-JzwAAATY"]
[Thu Jul 30 15:20:59.972170 2026] [security2:error] [pid 147647:tid 147881] [client 138.124.103.234:53666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/temp/.env"] [unique_id "amuyK-_ioCvBERk4wq-J1AAAAXI"]
[Thu Jul 30 15:21:00.102623 2026] [security2:error] [pid 147647:tid 147896] [client 93.123.109.102:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.germanyvisasupportcenterislamabad.website"] [uri "/.svn/entries"] [unique_id "amuyLO_ioCvBERk4wq-J2AAAAYE"]
[Thu Jul 30 15:21:00.250898 2026] [security2:error] [pid 147647:tid 147835] [client 138.124.103.234:53666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/tmp/.env"] [unique_id "amuyLO_ioCvBERk4wq-J3AAAAUQ"]
[Thu Jul 30 15:21:00.295887 2026] [core:notice] [pid 147647:tid 147862] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:00.298949 2026] [security2:error] [pid 147647:tid 147862] [client 198.20.67.201:42142] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/th1s_1s_a_4o4"] [unique_id "amuyLO_ioCvBERk4wq-J3QAAAV8"]
[Thu Jul 30 15:21:00.466899 2026] [security2:error] [pid 147647:tid 147854] [client 20.151.221.234:58233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amuyLO_ioCvBERk4wq-J4QAAAVc"]
[Thu Jul 30 15:21:00.479109 2026] [core:notice] [pid 147647:tid 147810] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:00.483555 2026] [security2:error] [pid 147647:tid 147810] [client 43.172.198.65:48958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2012/09/17/patricia-blanchet-imagine-une-collection-exclusive-pour-la-redoute/"] [unique_id "amuyLO_ioCvBERk4wq-J4wAAASs"], referer: https://carnetdeshopping.com/index.php/2012/09/17/patricia-blanchet-imagine-une-collection-exclusive-pour-la-redoute/
[Thu Jul 30 15:21:00.492027 2026] [core:notice] [pid 147647:tid 147826] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:00.496282 2026] [security2:error] [pid 147647:tid 147826] [client 43.173.181.67:41226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/02/23/suite-blanco-printemps-ete-2015/"] [unique_id "amuyLO_ioCvBERk4wq-J5AAAATs"], referer: https://carnetdeshopping.com/index.php/2015/02/23/suite-blanco-printemps-ete-2015/
[Thu Jul 30 15:21:00.538330 2026] [core:error] [pid 147647:tid 147883] [client 138.124.103.234:53666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:00.538351 2026] [core:error] [pid 147647:tid 147883] [client 138.124.103.234:53666] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:00.675592 2026] [core:notice] [pid 147647:tid 147822] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:00.679023 2026] [security2:error] [pid 147647:tid 147822] [client 66.249.79.1:37103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/1659/1024"] [unique_id "amuyLO_ioCvBERk4wq-J7AAAATc"]
[Thu Jul 30 15:21:00.715102 2026] [security2:error] [pid 147647:tid 147656] [remote 93.123.109.102:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.germanyvisasupportcenterislamabad.website"] [uri "/"] [unique_id "amuyLO_ioCvBERk4wq-J7QABZQg"]
[Thu Jul 30 15:21:00.715262 2026] [security2:error] [pid 147647:tid 147868] [client 93.123.109.102:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.germanyvisasupportcenterislamabad.website"] [uri "/"] [unique_id "amuyLO_ioCvBERk4wq-J7QABZQg"]
[Thu Jul 30 15:21:00.976804 2026] [security2:error] [pid 147647:tid 147900] [client 93.123.109.102:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.germanyvisasupportcenterislamabad.website"] [uri "/"] [unique_id "amuyLO_ioCvBERk4wq-J8wAAAYU"]
[Thu Jul 30 15:21:00.976960 2026] [security2:error] [pid 147647:tid 147900] [client 93.123.109.102:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.germanyvisasupportcenterislamabad.website"] [uri "/"] [unique_id "amuyLO_ioCvBERk4wq-J8wAAAYU"]
[Thu Jul 30 15:21:01.065255 2026] [core:notice] [pid 147647:tid 147782] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:01.172959 2026] [security2:error] [pid 147647:tid 147827] [client 20.63.98.115:25603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content.php"] [unique_id "amuyLe_ioCvBERk4wq-J_gAAATw"]
[Thu Jul 30 15:21:01.175490 2026] [core:error] [pid 147647:tid 147898] [client 64.227.104.105:42594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:01.175506 2026] [core:error] [pid 147647:tid 147898] [client 64.227.104.105:42594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:01.238824 2026] [security2:error] [pid 147647:tid 147825] [client 20.151.221.234:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/mah.php"] [unique_id "amuyLe_ioCvBERk4wq-J_wAAATo"]
[Thu Jul 30 15:21:01.347485 2026] [core:notice] [pid 147647:tid 147832] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:01.348479 2026] [core:notice] [pid 147647:tid 147880] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:01.350735 2026] [security2:error] [pid 147647:tid 147832] [client 66.249.79.229:48836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/article/download/1809/1115"] [unique_id "amuyLe_ioCvBERk4wq-KAQAAAUE"]
[Thu Jul 30 15:21:01.523288 2026] [security2:error] [pid 147647:tid 147667] [remote 192.250.227.227:39968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.227.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuyLe_ioCvBERk4wq-KBwABHhM"]
[Thu Jul 30 15:21:01.570482 2026] [core:notice] [pid 147647:tid 147834] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:01.574790 2026] [security2:error] [pid 147647:tid 147834] [client 66.249.79.229:48836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/1884/3644"] [unique_id "amuyLe_ioCvBERk4wq-KCwAAAUM"]
[Thu Jul 30 15:21:01.854243 2026] [security2:error] [pid 147647:tid 147813] [client 62.102.148.162:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuyLe_ioCvBERk4wq-KEAAAAS4"]
[Thu Jul 30 15:21:01.854366 2026] [security2:error] [pid 147647:tid 147813] [client 62.102.148.162:33702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amuyLe_ioCvBERk4wq-KEAAAAS4"]
[Thu Jul 30 15:21:01.882842 2026] [security2:error] [pid 147647:tid 147866] [client 20.63.98.115:25968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/function.php"] [unique_id "amuyLe_ioCvBERk4wq-KEgAAAWM"]
[Thu Jul 30 15:21:01.923589 2026] [core:error] [pid 147647:tid 147780] [client 138.124.103.234:53674] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:01.923612 2026] [core:error] [pid 147647:tid 147780] [client 138.124.103.234:53674] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:02.230563 2026] [security2:error] [pid 147647:tid 147893] [client 20.151.221.234:11399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/send.php"] [unique_id "amuyLu_ioCvBERk4wq-KHgAAAX4"]
[Thu Jul 30 15:21:02.244687 2026] [core:notice] [pid 147647:tid 147835] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:02.264573 2026] [core:error] [pid 147647:tid 147860] [client 45.249.89.53:62267] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:02.264602 2026] [core:error] [pid 147647:tid 147860] [client 45.249.89.53:62267] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:02.516386 2026] [core:notice] [pid 147647:tid 147869] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:02.588741 2026] [core:error] [pid 147647:tid 147875] [client 64.227.104.105:42610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:02.588761 2026] [core:error] [pid 147647:tid 147875] [client 64.227.104.105:42610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:03.012971 2026] [core:notice] [pid 147647:tid 147900] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:03.016814 2026] [security2:error] [pid 147647:tid 147900] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/download/843/509"] [unique_id "amuyL-_ioCvBERk4wq-KMQAAAYU"]
[Thu Jul 30 15:21:03.188637 2026] [security2:error] [pid 147647:tid 147812] [client 114.119.130.60:37071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hmhs.ph"] [uri "/robots.txt"] [unique_id "amuyL-_ioCvBERk4wq-KPAAAAS0"], referer: https://www.hmhs.ph/robots.txt
[Thu Jul 30 15:21:03.192236 2026] [security2:error] [pid 147647:tid 147862] [client 20.63.98.115:57983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/chosen.php"] [unique_id "amuyL-_ioCvBERk4wq-KPQAAAV8"]
[Thu Jul 30 15:21:03.271598 2026] [core:error] [pid 147647:tid 147853] [client 138.124.103.234:49648] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:03.271620 2026] [core:error] [pid 147647:tid 147853] [client 138.124.103.234:49648] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:03.352138 2026] [security2:error] [pid 147647:tid 147894] [client 201.178.241.239:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuyL-_ioCvBERk4wq-KQwAAAX8"], referer: https://cnpinyin.com
[Thu Jul 30 15:21:03.640831 2026] [core:error] [pid 147647:tid 147818] [client 45.249.89.53:63098] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:03.640864 2026] [core:error] [pid 147647:tid 147818] [client 45.249.89.53:63098] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:03.682726 2026] [security2:error] [pid 147647:tid 147832] [client 20.151.221.234:11448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuyL-_ioCvBERk4wq-KSwAAAUE"]
[Thu Jul 30 15:21:03.720229 2026] [security2:error] [pid 147647:tid 147678] [remote 74.7.243.224:32926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/js/reportf.php"] [unique_id "amuyL-_ioCvBERk4wq-KUQABQx4"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/js/partner.html
[Thu Jul 30 15:21:03.756941 2026] [core:notice] [pid 147647:tid 147833] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:04.040739 2026] [security2:error] [pid 147647:tid 147866] [client 20.63.98.115:39948] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.hmhs.ph"] [uri "/1.php"] [unique_id "amuyMO_ioCvBERk4wq-KVwAAAWM"]
[Thu Jul 30 15:21:04.040875 2026] [security2:error] [pid 147647:tid 147866] [client 20.63.98.115:39948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/1.php"] [unique_id "amuyMO_ioCvBERk4wq-KVwAAAWM"]
[Thu Jul 30 15:21:04.200441 2026] [core:notice] [pid 147647:tid 147903] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:04.203463 2026] [security2:error] [pid 147647:tid 147903] [client 66.249.79.231:58407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Caruban/article/view/9228/4051"] [unique_id "amuyL-_ioCvBERk4wq-KVgAAAYg"]
[Thu Jul 30 15:21:04.330456 2026] [core:notice] [pid 147647:tid 147849] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:04.423433 2026] [core:notice] [pid 147647:tid 147793] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:04.532967 2026] [core:error] [pid 147647:tid 147873] [client 138.124.103.234:49662] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:04.533009 2026] [core:error] [pid 147647:tid 147873] [client 138.124.103.234:49662] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:04.862937 2026] [core:error] [pid 147647:tid 147808] [client 64.227.104.105:42620] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:04.862965 2026] [core:error] [pid 147647:tid 147808] [client 64.227.104.105:42620] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:04.870539 2026] [core:notice] [pid 147647:tid 147787] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:04.873913 2026] [security2:error] [pid 147647:tid 147787] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/download/9385/4159"] [unique_id "amuyMO_ioCvBERk4wq-KbwAAARQ"]
[Thu Jul 30 15:21:04.993140 2026] [security2:error] [pid 147647:tid 147868] [client 20.151.221.234:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/about.php"] [unique_id "amuyMO_ioCvBERk4wq-KcwAAAWU"]
[Thu Jul 30 15:21:05.023211 2026] [core:error] [pid 147647:tid 147863] [client 45.249.89.53:63535] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:05.023243 2026] [core:error] [pid 147647:tid 147863] [client 45.249.89.53:63535] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:05.174778 2026] [security2:error] [pid 147647:tid 147819] [client 20.63.98.115:22233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/lv.php"] [unique_id "amuyMe_ioCvBERk4wq-KeAAAATQ"]
[Thu Jul 30 15:21:05.215966 2026] [core:notice] [pid 147647:tid 147791] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:05.366096 2026] [core:notice] [pid 147647:tid 147829] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:05.605043 2026] [security2:error] [pid 147647:tid 147682] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyMe_ioCvBERk4wq-KgQABLSI"]
[Thu Jul 30 15:21:05.605228 2026] [security2:error] [pid 147647:tid 147812] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyMe_ioCvBERk4wq-KgQABLSI"]
[Thu Jul 30 15:21:05.660314 2026] [security2:error] [pid 147647:tid 147825] [client 114.119.140.175:64503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kingstarenterprises.com"] [uri "/product-category/gym-club-accessories/knee-wraps/"] [unique_id "amuyMe_ioCvBERk4wq-KggAAATo"], referer: http://www.kingstarenterprises.com/
[Thu Jul 30 15:21:05.862554 2026] [core:notice] [pid 147647:tid 147777] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:05.865913 2026] [security2:error] [pid 147647:tid 147777] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/download/7091/2893"] [unique_id "amuyMe_ioCvBERk4wq-KjAAAAQo"]
[Thu Jul 30 15:21:05.903641 2026] [core:error] [pid 147647:tid 147796] [client 138.124.103.234:49670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:05.903660 2026] [core:error] [pid 147647:tid 147796] [client 138.124.103.234:49670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:05.960647 2026] [security2:error] [pid 147647:tid 147852] [client 20.151.221.234:50893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/options.php"] [unique_id "amuyMe_ioCvBERk4wq-KjgAAAVU"]
[Thu Jul 30 15:21:06.220062 2026] [security2:error] [pid 147647:tid 147895] [client 74.7.241.192:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-b064dcf5.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuyMO_ioCvBERk4wq-KcgAAAYA"]
[Thu Jul 30 15:21:06.220775 2026] [security2:error] [pid 147647:tid 147859] [client 74.7.241.192:52890] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-b064dcf5.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuyMO_ioCvBERk4wq-KcAABXCs"]
[Thu Jul 30 15:21:06.334587 2026] [security2:error] [pid 147647:tid 147790] [client 18.214.124.6:46816] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/11/IMG_20151123_101817915_HDR.jpg"] [unique_id "amuyMu_ioCvBERk4wq-KlgAAARc"]
[Thu Jul 30 15:21:06.338586 2026] [security2:error] [pid 147647:tid 147795] [client 74.7.244.28:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wyt.gpl.temporary.site"] [uri "/index.php"] [unique_id "amuyL-_ioCvBERk4wq-KUAAAARw"]
[Thu Jul 30 15:21:06.339429 2026] [security2:error] [pid 147647:tid 147892] [client 74.7.244.28:34554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wyt.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amuyL-_ioCvBERk4wq-KTgABfSM"]
[Thu Jul 30 15:21:06.359294 2026] [core:notice] [pid 147647:tid 147879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:06.362697 2026] [security2:error] [pid 147647:tid 147879] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/article/download/9081/3913"] [unique_id "amuyMu_ioCvBERk4wq-KmgAAAXA"]
[Thu Jul 30 15:21:06.432611 2026] [security2:error] [pid 147647:tid 147804] [client 114.119.135.37:22417] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saifalkhaleejest.com"] [uri "/2025/12/"] [unique_id "amuyMu_ioCvBERk4wq-KmwAAASU"], referer: https://saifalkhaleejest.com/when-to-use-rotation-chain-hoists-over-standard-chain-hoists/
[Thu Jul 30 15:21:06.451861 2026] [core:error] [pid 147647:tid 147904] [client 45.249.89.53:63962] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:06.451878 2026] [core:error] [pid 147647:tid 147904] [client 45.249.89.53:63962] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:06.661210 2026] [core:error] [pid 147647:tid 147816] [client 64.227.104.105:42632] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:06.661232 2026] [core:error] [pid 147647:tid 147816] [client 64.227.104.105:42632] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:06.706430 2026] [core:notice] [pid 147647:tid 147674] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:06.752611 2026] [security2:error] [pid 147647:tid 147849] [client 20.151.221.234:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuyMu_ioCvBERk4wq-KogAAAVI"]
[Thu Jul 30 15:21:06.960283 2026] [security2:error] [pid 147647:tid 147787] [client 165.154.120.253:46722] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "womenclothingbox.com"] [uri "/favicon.ico"] [unique_id "amuyMu_ioCvBERk4wq-KrwAAARQ"]
[Thu Jul 30 15:21:07.144950 2026] [core:error] [pid 147647:tid 147778] [client 138.124.103.234:49684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:07.144996 2026] [core:error] [pid 147647:tid 147778] [client 138.124.103.234:49684] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:07.301313 2026] [core:notice] [pid 147647:tid 147803] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:07.304773 2026] [security2:error] [pid 147647:tid 147803] [client 66.249.79.229:59150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/snpm/article/download/9728/4383"] [unique_id "amuyM-_ioCvBERk4wq-KvQAAASQ"]
[Thu Jul 30 15:21:07.410915 2026] [security2:error] [pid 147647:tid 147792] [client 74.7.230.8:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "linasteamrunning.com"] [uri "/index.php"] [unique_id "amuyM-_ioCvBERk4wq-KsgAAARk"]
[Thu Jul 30 15:21:07.411778 2026] [security2:error] [pid 147647:tid 147851] [client 74.7.230.8:36334] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "linasteamrunning.com"] [uri "/robots.txt"] [unique_id "amuyM-_ioCvBERk4wq-KsAABVEE"]
[Thu Jul 30 15:21:07.419152 2026] [core:notice] [pid 147647:tid 147705] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:07.525116 2026] [core:notice] [pid 147647:tid 147876] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:07.527554 2026] [security2:error] [pid 147647:tid 147824] [client 165.154.120.253:46860] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "womenclothingbox.com"] [uri "/refund-policy/robots.txt"] [unique_id "amuyM-_ioCvBERk4wq-KxwAAATk"]
[Thu Jul 30 15:21:07.528526 2026] [security2:error] [pid 147647:tid 147876] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/grageaku/article/view/1017"] [unique_id "amuyM-_ioCvBERk4wq-KxgAAAW0"]
[Thu Jul 30 15:21:07.533064 2026] [security2:error] [pid 147647:tid 147847] [client 165.154.120.253:46858] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "womenclothingbox.com"] [uri "/refund-policy/sitemap.xml"] [unique_id "amuyM-_ioCvBERk4wq-KyAAAAVA"]
[Thu Jul 30 15:21:07.650168 2026] [security2:error] [pid 147647:tid 147724] [remote 216.73.216.51:26411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuyM-_ioCvBERk4wq-KywABXEw"]
[Thu Jul 30 15:21:07.665652 2026] [security2:error] [pid 147647:tid 147809] [client 20.63.98.115:26110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/css.php"] [unique_id "amuyM-_ioCvBERk4wq-KzAAAASo"]
[Thu Jul 30 15:21:07.845362 2026] [core:error] [pid 147647:tid 147899] [client 45.249.89.53:64422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:07.845384 2026] [core:error] [pid 147647:tid 147899] [client 45.249.89.53:64422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:07.973367 2026] [core:notice] [pid 147647:tid 147892] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:08.267254 2026] [security2:error] [pid 147647:tid 147896] [client 20.151.221.234:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/wp-file.php"] [unique_id "amuyNO_ioCvBERk4wq-K2QAAAYE"]
[Thu Jul 30 15:21:08.437397 2026] [core:error] [pid 147647:tid 147784] [client 64.227.104.105:60096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:08.437427 2026] [core:error] [pid 147647:tid 147784] [client 64.227.104.105:60096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:08.450589 2026] [core:error] [pid 147647:tid 147804] [client 138.124.103.234:49690] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:08.450615 2026] [core:error] [pid 147647:tid 147804] [client 138.124.103.234:49690] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:08.471283 2026] [core:notice] [pid 147647:tid 147883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:08.513827 2026] [security2:error] [pid 147647:tid 147886] [client 20.63.98.115:22267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/gecko.php"] [unique_id "amuyNO_ioCvBERk4wq-K5gAAAXc"]
[Thu Jul 30 15:21:08.777134 2026] [security2:error] [pid 147647:tid 147855] [client 198.20.67.201:36224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/JSTE"] [unique_id "amuyNO_ioCvBERk4wq-K5wAAAVg"], referer: http://www.google.com/url?url=www.ejournalugj.com&yahoo.com
[Thu Jul 30 15:21:08.834039 2026] [security2:error] [pid 147647:tid 147823] [client 165.154.120.253:47250] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "carnetdeshopping.com"] [uri "/favicon.ico"] [unique_id "amuyNO_ioCvBERk4wq-K6wAAATg"]
[Thu Jul 30 15:21:08.968316 2026] [core:notice] [pid 147647:tid 147807] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:08.971601 2026] [security2:error] [pid 147647:tid 147807] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/1627/1023"] [unique_id "amuyNO_ioCvBERk4wq-K8AAAASg"]
[Thu Jul 30 15:21:09.083743 2026] [security2:error] [pid 147647:tid 147878] [client 20.151.221.234:40217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.221.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sv.radiojelli.com"] [uri "/sid3.php"] [unique_id "amuyNe_ioCvBERk4wq-K9AAAAW8"]
[Thu Jul 30 15:21:09.393522 2026] [core:notice] [pid 147647:tid 147727] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:09.426256 2026] [security2:error] [pid 147647:tid 147828] [client 20.203.148.31:28463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/LA.php"] [unique_id "amuyNe_ioCvBERk4wq-K_wAAAT0"]
[Thu Jul 30 15:21:09.466281 2026] [core:notice] [pid 147647:tid 147897] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:09.599994 2026] [security2:error] [pid 147647:tid 147783] [client 165.154.120.253:47454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amuyNe_ioCvBERk4wq-LBwAAARA"]
[Thu Jul 30 15:21:09.611912 2026] [security2:error] [pid 147647:tid 147846] [client 20.63.98.115:57976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/xmlrpc.php"] [unique_id "amuyNe_ioCvBERk4wq-K-wAAAU8"]
[Thu Jul 30 15:21:09.617046 2026] [security2:error] [pid 147647:tid 147852] [client 165.154.120.253:47452] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "carnetdeshopping.com"] [uri "/sitemap.xml"] [unique_id "amuyNe_ioCvBERk4wq-LCAAAAVU"]
[Thu Jul 30 15:21:09.659725 2026] [core:notice] [pid 147647:tid 147868] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:09.662870 2026] [security2:error] [pid 147647:tid 147868] [client 198.20.67.201:36228] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ejournalugj.com"] [uri "/index_php/JPA"] [unique_id "amuyNe_ioCvBERk4wq-LCQAAAWU"]
[Thu Jul 30 15:21:09.782724 2026] [core:error] [pid 147647:tid 147851] [client 138.124.103.234:49704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:09.782745 2026] [core:error] [pid 147647:tid 147851] [client 138.124.103.234:49704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:09.961909 2026] [security2:error] [pid 147647:tid 147780] [client 134.19.179.195:39402] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuyNe_ioCvBERk4wq-LDwAAAQ0"]
[Thu Jul 30 15:21:09.962016 2026] [security2:error] [pid 147647:tid 147780] [client 134.19.179.195:39402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuyNe_ioCvBERk4wq-LDwAAAQ0"]
[Thu Jul 30 15:21:09.963700 2026] [core:notice] [pid 147647:tid 147881] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:09.966989 2026] [security2:error] [pid 147647:tid 147881] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/9516"] [unique_id "amuyNe_ioCvBERk4wq-LEAAAAXI"]
[Thu Jul 30 15:21:09.993767 2026] [security2:error] [pid 147647:tid 147821] [client 20.203.148.31:35475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/admin.php"] [unique_id "amuyNe_ioCvBERk4wq-LEwAAATY"]
[Thu Jul 30 15:21:10.108231 2026] [security2:error] [pid 147647:tid 147876] [client 64.227.104.105:60106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/backup/.env"] [unique_id "amuyNu_ioCvBERk4wq-LGQAAAW0"]
[Thu Jul 30 15:21:10.461335 2026] [core:notice] [pid 147647:tid 147810] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:10.494401 2026] [core:notice] [pid 147647:tid 147904] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:10.687305 2026] [security2:error] [pid 147647:tid 147790] [client 172.237.109.114:25840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyNu_ioCvBERk4wq-LGgAAARc"]
[Thu Jul 30 15:21:10.694588 2026] [security2:error] [pid 147647:tid 147887] [client 20.63.98.115:26093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/f35.php"] [unique_id "amuyNu_ioCvBERk4wq-LJwAAAXg"]
[Thu Jul 30 15:21:10.724102 2026] [security2:error] [pid 147647:tid 147856] [client 64.227.104.105:60106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/backups/.env"] [unique_id "amuyNu_ioCvBERk4wq-LKAAAAVk"]
[Thu Jul 30 15:21:10.960754 2026] [core:notice] [pid 147647:tid 147857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:10.984881 2026] [security2:error] [pid 147647:tid 147855] [client 198.20.67.201:36234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA"] [unique_id "amuyNu_ioCvBERk4wq-LLgAAAVg"]
[Thu Jul 30 15:21:10.985001 2026] [security2:error] [pid 147647:tid 147855] [client 198.20.67.201:36234] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA"] [unique_id "amuyNu_ioCvBERk4wq-LLgAAAVg"]
[Thu Jul 30 15:21:11.190193 2026] [security2:error] [pid 147647:tid 147807] [client 64.227.104.105:60106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/old/.env"] [unique_id "amuyN-_ioCvBERk4wq-LNgAAASg"]
[Thu Jul 30 15:21:11.361450 2026] [security2:error] [pid 147647:tid 147778] [client 165.154.120.253:48012] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sellvia.womenclothingbox.com"] [uri "/favicon.ico"] [unique_id "amuyN-_ioCvBERk4wq-LOAAAAQs"]
[Thu Jul 30 15:21:11.393425 2026] [core:error] [pid 147647:tid 147878] [client 138.124.103.234:49710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:11.393451 2026] [core:error] [pid 147647:tid 147878] [client 138.124.103.234:49710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:11.445011 2026] [security2:error] [pid 147647:tid 147787] [client 20.63.98.115:39946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/autoload_classmap.php"] [unique_id "amuyN-_ioCvBERk4wq-LQAAAARQ"]
[Thu Jul 30 15:21:11.461485 2026] [core:notice] [pid 147647:tid 147898] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:11.465663 2026] [security2:error] [pid 147647:tid 147898] [client 66.249.79.229:59150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/PBB/article/download/7402/2958"] [unique_id "amuyN-_ioCvBERk4wq-LQwAAAYM"]
[Thu Jul 30 15:21:11.600683 2026] [security2:error] [pid 147647:tid 147801] [client 64.227.104.105:60106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/temp/.env"] [unique_id "amuyN-_ioCvBERk4wq-LRwAAASI"]
[Thu Jul 30 15:21:11.634701 2026] [core:error] [pid 147647:tid 147805] [client 45.249.89.53:64861] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:11.634721 2026] [core:error] [pid 147647:tid 147805] [client 45.249.89.53:64861] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:11.948555 2026] [security2:error] [pid 147647:tid 147864] [client 64.227.104.105:60106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/tmp/.env"] [unique_id "amuyN-_ioCvBERk4wq-LTAAAAWE"]
[Thu Jul 30 15:21:11.957097 2026] [core:notice] [pid 147647:tid 147877] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:12.022059 2026] [security2:error] [pid 147647:tid 147867] [client 165.154.120.253:48146] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sellvia.womenclothingbox.com"] [uri "/sitemap.xml"] [unique_id "amuyOO_ioCvBERk4wq-LUQAAAWQ"]
[Thu Jul 30 15:21:12.024530 2026] [security2:error] [pid 147647:tid 147884] [client 165.154.120.253:48148] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sellvia.womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amuyOO_ioCvBERk4wq-LUgAAAXU"]
[Thu Jul 30 15:21:12.168101 2026] [core:notice] [pid 147647:tid 147812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:12.338969 2026] [core:error] [pid 147647:tid 147874] [client 64.227.104.105:60106] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:12.339008 2026] [core:error] [pid 147647:tid 147874] [client 64.227.104.105:60106] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:12.456839 2026] [core:notice] [pid 147647:tid 147802] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:12.642498 2026] [security2:error] [pid 147647:tid 147844] [client 134.19.179.195:37596] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuyOO_ioCvBERk4wq-LagAAAU0"]
[Thu Jul 30 15:21:12.642612 2026] [security2:error] [pid 147647:tid 147844] [client 134.19.179.195:37596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuyOO_ioCvBERk4wq-LagAAAU0"]
[Thu Jul 30 15:21:12.776794 2026] [core:error] [pid 147647:tid 147891] [client 138.124.103.234:49722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:12.776819 2026] [core:error] [pid 147647:tid 147891] [client 138.124.103.234:49722] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:12.841194 2026] [security2:error] [pid 147647:tid 147822] [client 20.63.98.115:39956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/NewFile.php"] [unique_id "amuyOO_ioCvBERk4wq-LcgAAATc"]
[Thu Jul 30 15:21:12.955706 2026] [core:notice] [pid 147647:tid 147888] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:13.010214 2026] [security2:error] [pid 147647:tid 147823] [client 20.203.148.31:11866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/class_api.php"] [unique_id "amuyOe_ioCvBERk4wq-LdAAAATg"]
[Thu Jul 30 15:21:13.021680 2026] [core:error] [pid 147647:tid 147831] [client 45.249.89.53:49758] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:13.021702 2026] [core:error] [pid 147647:tid 147831] [client 45.249.89.53:49758] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:13.301583 2026] [security2:error] [pid 147647:tid 147900] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyOO_ioCvBERk4wq-LbgAAAYU"]
[Thu Jul 30 15:21:13.452511 2026] [core:notice] [pid 147647:tid 147792] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:13.633702 2026] [security2:error] [pid 147647:tid 147819] [client 172.237.109.114:31943] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyOe_ioCvBERk4wq-LfQAAATQ"]
[Thu Jul 30 15:21:13.847749 2026] [core:error] [pid 147647:tid 147806] [client 64.227.104.105:60120] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:13.847774 2026] [core:error] [pid 147647:tid 147806] [client 64.227.104.105:60120] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:13.951558 2026] [core:notice] [pid 147647:tid 147881] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:14.231902 2026] [core:error] [pid 147647:tid 147836] [client 138.124.103.234:52766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:14.231931 2026] [core:error] [pid 147647:tid 147836] [client 138.124.103.234:52766] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:14.409101 2026] [core:error] [pid 147647:tid 147786] [client 45.249.89.53:50228] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:14.409130 2026] [core:error] [pid 147647:tid 147786] [client 45.249.89.53:50228] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:14.450079 2026] [core:notice] [pid 147647:tid 147802] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:14.453320 2026] [security2:error] [pid 147647:tid 147802] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/download/4576/2387"] [unique_id "amuyOu_ioCvBERk4wq-LngAAASM"]
[Thu Jul 30 15:21:14.764628 2026] [security2:error] [pid 147647:tid 147870] [client 198.20.67.201:56650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.67.20.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JPAS/issue/current"] [unique_id "amuyOu_ioCvBERk4wq-LpQAAAWc"], referer: http://www.google.com/url?url=ejournalugj.com&yahoo.com
[Thu Jul 30 15:21:14.948482 2026] [core:notice] [pid 147647:tid 147891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:15.342475 2026] [core:error] [pid 147647:tid 147811] [client 64.227.104.105:60122] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:15.342499 2026] [core:error] [pid 147647:tid 147811] [client 64.227.104.105:60122] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:15.447391 2026] [core:notice] [pid 147647:tid 147827] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:15.483563 2026] [core:notice] [pid 147647:tid 147765] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:15.575091 2026] [core:error] [pid 147647:tid 147878] [client 138.124.103.234:52770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:15.575117 2026] [core:error] [pid 147647:tid 147878] [client 138.124.103.234:52770] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:15.716581 2026] [security2:error] [pid 147647:tid 147901] [client 57.141.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyO-_ioCvBERk4wq-LrwAAAYY"]
[Thu Jul 30 15:21:15.786699 2026] [core:error] [pid 147647:tid 147882] [client 45.249.89.53:50758] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:15.786722 2026] [core:error] [pid 147647:tid 147882] [client 45.249.89.53:50758] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:15.946234 2026] [core:notice] [pid 147647:tid 147781] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:16.079523 2026] [security2:error] [pid 147647:tid 147648] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyPO_ioCvBERk4wq-LzQABUAA"]
[Thu Jul 30 15:21:16.079670 2026] [security2:error] [pid 147647:tid 147847] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyPO_ioCvBERk4wq-LzQABUAA"]
[Thu Jul 30 15:21:16.445715 2026] [core:notice] [pid 147647:tid 147848] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:16.449388 2026] [security2:error] [pid 147647:tid 147848] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/view/5899/2830"] [unique_id "amuyPO_ioCvBERk4wq-L1wAAAVE"]
[Thu Jul 30 15:21:16.675931 2026] [security2:error] [pid 147647:tid 147803] [client 165.154.120.253:49568] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sellvia.womenclothingbox.com"] [uri "/upload/images/favicon.png"] [unique_id "amuyPO_ioCvBERk4wq-L2wAAASQ"]
[Thu Jul 30 15:21:16.792682 2026] [security2:error] [pid 147647:tid 147851] [client 20.203.148.31:28427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amuyPO_ioCvBERk4wq-L4AAAAVQ"]
[Thu Jul 30 15:21:16.944343 2026] [core:notice] [pid 147647:tid 147886] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:17.003101 2026] [core:error] [pid 147647:tid 147840] [client 138.124.103.234:52776] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:17.003124 2026] [core:error] [pid 147647:tid 147840] [client 138.124.103.234:52776] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:17.021165 2026] [core:error] [pid 147647:tid 147800] [client 64.227.104.105:60138] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:17.021182 2026] [core:error] [pid 147647:tid 147800] [client 64.227.104.105:60138] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:17.157868 2026] [security2:error] [pid 147647:tid 147860] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyPO_ioCvBERk4wq-L2gAAAV0"]
[Thu Jul 30 15:21:17.165219 2026] [core:error] [pid 147647:tid 147873] [client 45.249.89.53:51232] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:17.165252 2026] [core:error] [pid 147647:tid 147873] [client 45.249.89.53:51232] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:17.443618 2026] [core:notice] [pid 147647:tid 147811] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:17.447283 2026] [security2:error] [pid 147647:tid 147811] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/ELTERA/article/download/3969/1977"] [unique_id "amuyPe_ioCvBERk4wq-L9wAAASw"]
[Thu Jul 30 15:21:17.666213 2026] [security2:error] [pid 147647:tid 147878] [client 165.154.120.253:49826] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sellvia.womenclothingbox.com"] [uri "/robots.txt"] [unique_id "amuyPe_ioCvBERk4wq-L-gAAAW8"]
[Thu Jul 30 15:21:17.693731 2026] [security2:error] [pid 147647:tid 147815] [client 165.154.120.253:49824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sellvia.womenclothingbox.com"] [uri "/sitemap.xml"] [unique_id "amuyPe_ioCvBERk4wq-L_AAAATA"]
[Thu Jul 30 15:21:17.943075 2026] [core:notice] [pid 147647:tid 147867] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:18.243961 2026] [core:error] [pid 147647:tid 147884] [client 138.124.103.234:52782] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:18.243997 2026] [core:error] [pid 147647:tid 147884] [client 138.124.103.234:52782] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:18.441581 2026] [core:notice] [pid 147647:tid 147806] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:18.493933 2026] [security2:error] [pid 147647:tid 147777] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyPe_ioCvBERk4wq-MAwABCns"]
[Thu Jul 30 15:21:18.551594 2026] [security2:error] [pid 147647:tid 147895] [client 45.249.89.53:51729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/backup/.env"] [unique_id "amuyPu_ioCvBERk4wq-MFAAAAYA"]
[Thu Jul 30 15:21:18.671547 2026] [core:error] [pid 147647:tid 147852] [client 64.227.104.105:60394] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:18.671579 2026] [core:error] [pid 147647:tid 147852] [client 64.227.104.105:60394] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:18.886684 2026] [security2:error] [pid 147647:tid 147900] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyPu_ioCvBERk4wq-MCQABhQM"]
[Thu Jul 30 15:21:18.918815 2026] [security2:error] [pid 147647:tid 147818] [client 45.249.89.53:51729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/backups/.env"] [unique_id "amuyPu_ioCvBERk4wq-MHAAAATM"]
[Thu Jul 30 15:21:18.940443 2026] [core:notice] [pid 147647:tid 147803] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:18.943569 2026] [security2:error] [pid 147647:tid 147803] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/InaBHS/article/view/7310"] [unique_id "amuyPu_ioCvBERk4wq-MHQAAASQ"]
[Thu Jul 30 15:21:19.077740 2026] [security2:error] [pid 147647:tid 147892] [client 20.63.98.115:42158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/xx.php"] [unique_id "amuyP-_ioCvBERk4wq-MIQAAAX0"]
[Thu Jul 30 15:21:19.176299 2026] [security2:error] [pid 147647:tid 147904] [client 62.102.148.162:57880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuyP-_ioCvBERk4wq-MIgAAAYk"]
[Thu Jul 30 15:21:19.176422 2026] [security2:error] [pid 147647:tid 147904] [client 62.102.148.162:57880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuyP-_ioCvBERk4wq-MIgAAAYk"]
[Thu Jul 30 15:21:19.287201 2026] [security2:error] [pid 147647:tid 147816] [client 45.249.89.53:51729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/old/.env"] [unique_id "amuyP-_ioCvBERk4wq-MIwAAATE"]
[Thu Jul 30 15:21:19.392969 2026] [security2:error] [pid 147647:tid 147887] [client 213.152.186.19:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuyP-_ioCvBERk4wq-MJwAAAXg"]
[Thu Jul 30 15:21:19.393064 2026] [security2:error] [pid 147647:tid 147887] [client 213.152.186.19:43818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuyP-_ioCvBERk4wq-MJwAAAXg"]
[Thu Jul 30 15:21:19.440428 2026] [core:notice] [pid 147647:tid 147800] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:19.654729 2026] [security2:error] [pid 147647:tid 147885] [client 45.249.89.53:51729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/temp/.env"] [unique_id "amuyP-_ioCvBERk4wq-MMgAAAXY"]
[Thu Jul 30 15:21:19.836635 2026] [security2:error] [pid 147647:tid 147779] [client 20.203.148.31:35511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.tmb/wp-login.php"] [unique_id "amuyP-_ioCvBERk4wq-MMAAAAQw"]
[Thu Jul 30 15:21:19.867546 2026] [security2:error] [pid 147647:tid 147822] [client 138.124.103.234:52788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/storage/framework/.env"] [unique_id "amuyP-_ioCvBERk4wq-MMwAAATc"]
[Thu Jul 30 15:21:19.939834 2026] [core:notice] [pid 147647:tid 147888] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:20.023431 2026] [security2:error] [pid 147647:tid 147797] [client 45.249.89.53:51729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/tmp/.env"] [unique_id "amuyQO_ioCvBERk4wq-MPgAAAR4"]
[Thu Jul 30 15:21:20.083217 2026] [security2:error] [pid 147647:tid 147891] [client 20.104.18.253:6324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/astra/inc/fm.php"] [unique_id "amuyQO_ioCvBERk4wq-MPwAAAXw"]
[Thu Jul 30 15:21:20.108460 2026] [core:error] [pid 147647:tid 147791] [client 64.227.104.105:60408] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:20.108478 2026] [core:error] [pid 147647:tid 147791] [client 64.227.104.105:60408] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:20.153436 2026] [security2:error] [pid 147647:tid 147828] [client 138.124.103.234:52788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/laravel/.env"] [unique_id "amuyQO_ioCvBERk4wq-MQQAAAT0"]
[Thu Jul 30 15:21:20.392790 2026] [core:error] [pid 147647:tid 147808] [client 45.249.89.53:51729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:20.392817 2026] [core:error] [pid 147647:tid 147808] [client 45.249.89.53:51729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:20.431789 2026] [security2:error] [pid 147647:tid 147898] [client 176.159.226.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuyQO_ioCvBERk4wq-MRAAAAYM"], referer: https://cnpinyin.com
[Thu Jul 30 15:21:20.440238 2026] [core:error] [pid 147647:tid 147834] [client 138.124.103.234:52788] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:20.440255 2026] [core:error] [pid 147647:tid 147834] [client 138.124.103.234:52788] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:20.662974 2026] [core:notice] [pid 147647:tid 147813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:20.668940 2026] [proxy:error] [pid 147647:tid 147824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:20.669019 2026] [proxy_http:error] [pid 147647:tid 147824] [client 52.202.41.153:18353] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:20.669587 2026] [proxy:error] [pid 147647:tid 147824] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:20.669628 2026] [proxy_http:error] [pid 147647:tid 147824] [client 52.202.41.153:18353] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:20.732773 2026] [security2:error] [pid 147647:tid 147903] [client 20.104.18.253:6312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/astra/inc/ki1k.php"] [unique_id "amuyQO_ioCvBERk4wq-MVwAAAYg"]
[Thu Jul 30 15:21:20.750955 2026] [security2:error] [pid 147647:tid 147859] [client 114.119.150.252:46823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabian-tours.com"] [uri "/site/kevin-anderson-linkedin-56216b"] [unique_id "amuyQO_ioCvBERk4wq-MWAAAAVw"], referer: https://arabian-tours.com/site/carlos-i-of-portugal-56216b
[Thu Jul 30 15:21:20.935576 2026] [core:notice] [pid 147647:tid 147836] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:20.939054 2026] [security2:error] [pid 147647:tid 147836] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JSTE/article/download/6131/2660"] [unique_id "amuyQO_ioCvBERk4wq-MXAAAAUU"]
[Thu Jul 30 15:21:21.166644 2026] [security2:error] [pid 147647:tid 147692] [remote 44.205.74.196:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "trustedmoversandpackersabudhabi.online"] [uri "/"] [unique_id "amuyQe_ioCvBERk4wq-MaQABPiw"]
[Thu Jul 30 15:21:21.349557 2026] [security2:error] [pid 147647:tid 147904] [client 20.104.18.253:6278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/atombil.php"] [unique_id "amuyQe_ioCvBERk4wq-MagAAAYk"]
[Thu Jul 30 15:21:21.649217 2026] [security2:error] [pid 147647:tid 147884] [client 20.203.148.31:11673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amuyQe_ioCvBERk4wq-MeAAAAXU"]
[Thu Jul 30 15:21:21.655250 2026] [core:error] [pid 147647:tid 147875] [client 64.227.104.105:60412] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:21.655268 2026] [core:error] [pid 147647:tid 147875] [client 64.227.104.105:60412] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:21.773345 2026] [core:error] [pid 147647:tid 147804] [client 45.249.89.53:52886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:21.773373 2026] [core:error] [pid 147647:tid 147804] [client 45.249.89.53:52886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:21.954782 2026] [security2:error] [pid 147647:tid 147823] [client 20.104.18.253:6315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/atomlib.php"] [unique_id "amuyQe_ioCvBERk4wq-MgwAAATg"]
[Thu Jul 30 15:21:22.136768 2026] [core:notice] [pid 147647:tid 147830] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:22.141328 2026] [security2:error] [pid 147647:tid 147830] [client 66.249.79.229:56646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/2599"] [unique_id "amuyQe_ioCvBERk4wq-MfwAAAT8"]
[Thu Jul 30 15:21:22.346617 2026] [security2:error] [pid 147647:tid 147794] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyQe_ioCvBERk4wq-MfQAAARs"]
[Thu Jul 30 15:21:22.366463 2026] [core:notice] [pid 147647:tid 147783] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:22.563194 2026] [security2:error] [pid 147647:tid 147877] [client 20.203.148.31:40732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/991176.php"] [unique_id "amuyQu_ioCvBERk4wq-MkgAAAW4"]
[Thu Jul 30 15:21:22.567001 2026] [security2:error] [pid 147647:tid 147864] [client 20.104.18.253:6489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/aua.php"] [unique_id "amuyQu_ioCvBERk4wq-MkwAAAWE"]
[Thu Jul 30 15:21:22.787156 2026] [core:notice] [pid 147647:tid 147813] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:22.815209 2026] [core:notice] [pid 147647:tid 147836] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:22.819044 2026] [security2:error] [pid 147647:tid 147836] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/download/8213/3324"] [unique_id "amuyQu_ioCvBERk4wq-MngAAAUU"]
[Thu Jul 30 15:21:23.100470 2026] [security2:error] [pid 147647:tid 147795] [client 127.0.0.1:49720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuyQ-_ioCvBERk4wq-MqAAAARw"]
[Thu Jul 30 15:21:23.100588 2026] [security2:error] [pid 147647:tid 147866] [client 74.7.230.8:44126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kendarikomputer.com"] [uri "/robots.txt"] [unique_id "amuyQ-_ioCvBERk4wq-MpwABY0w"]
[Thu Jul 30 15:21:23.112745 2026] [security2:error] [pid 147647:tid 147798] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyQu_ioCvBERk4wq-MkAABHzU"]
[Thu Jul 30 15:21:23.183537 2026] [security2:error] [pid 147647:tid 147842] [client 20.104.18.253:6286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/aucxzso.php"] [unique_id "amuyQ-_ioCvBERk4wq-MrAAAAUs"]
[Thu Jul 30 15:21:23.210567 2026] [core:error] [pid 147647:tid 147879] [client 45.249.89.53:53382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:23.210587 2026] [core:error] [pid 147647:tid 147879] [client 45.249.89.53:53382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:23.312840 2026] [core:notice] [pid 147647:tid 147846] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:23.316420 2026] [security2:error] [pid 147647:tid 147846] [client 66.249.79.229:56646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jibm/article/download/8415/3859"] [unique_id "amuyQ-_ioCvBERk4wq-MrwAAAU8"]
[Thu Jul 30 15:21:23.327126 2026] [security2:error] [pid 147647:tid 147799] [client 20.63.98.115:52643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/plugins.php"] [unique_id "amuyQ-_ioCvBERk4wq-MsAAAASA"]
[Thu Jul 30 15:21:23.391933 2026] [core:error] [pid 147647:tid 147900] [client 64.227.104.105:60418] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:23.391955 2026] [core:error] [pid 147647:tid 147900] [client 64.227.104.105:60418] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:23.719225 2026] [security2:error] [pid 147647:tid 147861] [client 20.203.200.218:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alnawadertech.com"] [uri "/.well-known/about.php"] [unique_id "amuyQ-_ioCvBERk4wq-MsgAAAV4"]
[Thu Jul 30 15:21:23.719352 2026] [security2:error] [pid 147647:tid 147861] [client 20.203.200.218:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alnawadertech.com"] [uri "/.well-known/about.php"] [unique_id "amuyQ-_ioCvBERk4wq-MsgAAAV4"]
[Thu Jul 30 15:21:23.771985 2026] [autoindex:error] [pid 147647:tid 147807] [client 195.96.139.2:0] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:21:23.808729 2026] [core:notice] [pid 147647:tid 147871] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:23.811994 2026] [security2:error] [pid 147647:tid 147871] [client 66.249.79.229:56646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3818/1860"] [unique_id "amuyQ-_ioCvBERk4wq-MwQAAAWg"]
[Thu Jul 30 15:21:23.824858 2026] [security2:error] [pid 147647:tid 147835] [client 20.104.18.253:6733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/audio.php"] [unique_id "amuyQ-_ioCvBERk4wq-MwwAAAUQ"]
[Thu Jul 30 15:21:24.307321 2026] [core:notice] [pid 147647:tid 147901] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:24.310883 2026] [security2:error] [pid 147647:tid 147901] [client 66.249.79.229:56646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/8598/3450"] [unique_id "amuyRO_ioCvBERk4wq-M0QAAAYY"]
[Thu Jul 30 15:21:24.429436 2026] [security2:error] [pid 147647:tid 147902] [client 20.104.18.253:6331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/audit.php"] [unique_id "amuyRO_ioCvBERk4wq-M0gAAAYc"]
[Thu Jul 30 15:21:24.497785 2026] [security2:error] [pid 147647:tid 147860] [client 20.203.148.31:42877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amuyRO_ioCvBERk4wq-M1QAAAV0"]
[Thu Jul 30 15:21:24.515570 2026] [security2:error] [pid 147647:tid 147843] [client 20.63.98.115:39732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/xxx.php"] [unique_id "amuyRO_ioCvBERk4wq-M1gAAAUw"]
[Thu Jul 30 15:21:24.605202 2026] [core:error] [pid 147647:tid 147870] [client 45.249.89.53:53981] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:24.605228 2026] [core:error] [pid 147647:tid 147870] [client 45.249.89.53:53981] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:24.619780 2026] [security2:error] [pid 147647:tid 147804] [client 172.237.109.114:5641] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyRO_ioCvBERk4wq-MzQAAASU"]
[Thu Jul 30 15:21:24.734259 2026] [core:error] [pid 147647:tid 147837] [client 138.124.103.234:52804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:24.734284 2026] [core:error] [pid 147647:tid 147837] [client 138.124.103.234:52804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:24.800509 2026] [core:notice] [pid 147647:tid 147777] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:25.032929 2026] [security2:error] [pid 147647:tid 147780] [client 20.104.18.253:6474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/auth.php"] [unique_id "amuyRe_ioCvBERk4wq-M5AAAAQ0"]
[Thu Jul 30 15:21:25.301098 2026] [core:notice] [pid 147647:tid 147802] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:25.304472 2026] [security2:error] [pid 147647:tid 147802] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/8254"] [unique_id "amuyRe_ioCvBERk4wq-M6wAAASM"]
[Thu Jul 30 15:21:25.376570 2026] [core:error] [pid 147647:tid 147803] [client 64.227.104.105:60424] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:25.376590 2026] [core:error] [pid 147647:tid 147803] [client 64.227.104.105:60424] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:25.433550 2026] [security2:error] [pid 147647:tid 147896] [client 20.203.148.31:11703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amuyRe_ioCvBERk4wq-M8AAAAYE"]
[Thu Jul 30 15:21:25.675724 2026] [security2:error] [pid 147647:tid 147842] [client 20.104.18.253:6276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/authorize.php"] [unique_id "amuyRe_ioCvBERk4wq-M9AAAAUs"]
[Thu Jul 30 15:21:25.801321 2026] [core:notice] [pid 147647:tid 147818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:25.804786 2026] [security2:error] [pid 147647:tid 147818] [client 66.249.79.229:56646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jka/article/view/2628"] [unique_id "amuyRe_ioCvBERk4wq-M-AAAATM"]
[Thu Jul 30 15:21:25.998822 2026] [core:error] [pid 147647:tid 147810] [client 45.249.89.53:54522] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:25.998843 2026] [core:error] [pid 147647:tid 147810] [client 45.249.89.53:54522] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:26.277549 2026] [security2:error] [pid 147647:tid 147873] [client 20.104.18.253:6302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/autoload_classmap.php"] [unique_id "amuyRu_ioCvBERk4wq-NBgAAAWo"]
[Thu Jul 30 15:21:26.640764 2026] [security2:error] [pid 147647:tid 147743] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyRu_ioCvBERk4wq-NCwABfV8"]
[Thu Jul 30 15:21:26.640907 2026] [security2:error] [pid 147647:tid 147892] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyRu_ioCvBERk4wq-NCwABfV8"]
[Thu Jul 30 15:21:26.767044 2026] [core:notice] [pid 147647:tid 147753] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:26.790860 2026] [security2:error] [pid 147647:tid 147783] [client 20.203.200.218:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alnawadertech.com"] [uri "/.well-known/index.php"] [unique_id "amuyRu_ioCvBERk4wq-NEwAAARA"]
[Thu Jul 30 15:21:26.790954 2026] [security2:error] [pid 147647:tid 147783] [client 20.203.200.218:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alnawadertech.com"] [uri "/.well-known/index.php"] [unique_id "amuyRu_ioCvBERk4wq-NEwAAARA"]
[Thu Jul 30 15:21:26.821457 2026] [core:error] [pid 147647:tid 147828] [client 64.227.104.105:60440] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:26.821475 2026] [core:error] [pid 147647:tid 147828] [client 64.227.104.105:60440] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:26.893437 2026] [security2:error] [pid 147647:tid 147853] [client 20.63.98.115:39703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/css.php"] [unique_id "amuyRu_ioCvBERk4wq-NFgAAAVY"]
[Thu Jul 30 15:21:26.895135 2026] [security2:error] [pid 147647:tid 147815] [client 20.104.18.253:6476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/autoloadclassmap.php"] [unique_id "amuyRu_ioCvBERk4wq-NFwAAATA"]
[Thu Jul 30 15:21:27.268934 2026] [proxy:error] [pid 147647:tid 147836] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:27.269027 2026] [proxy_http:error] [pid 147647:tid 147836] [client 5.161.225.116:30404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:27.269609 2026] [proxy:error] [pid 147647:tid 147836] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:27.269658 2026] [proxy_http:error] [pid 147647:tid 147836] [client 5.161.225.116:30404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:27.339140 2026] [core:error] [pid 147647:tid 147880] [client 138.124.103.234:38984] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:27.339162 2026] [core:error] [pid 147647:tid 147880] [client 138.124.103.234:38984] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:27.393654 2026] [core:error] [pid 147647:tid 147796] [client 45.249.89.53:55064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:27.393679 2026] [core:error] [pid 147647:tid 147796] [client 45.249.89.53:55064] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:27.399568 2026] [core:notice] [pid 147647:tid 147798] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:27.402569 2026] [security2:error] [pid 147647:tid 147798] [client 66.249.79.229:56646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/download/591/374"] [unique_id "amuyR-_ioCvBERk4wq-NKQAAAR8"]
[Thu Jul 30 15:21:27.431943 2026] [security2:error] [pid 147647:tid 147879] [client 20.203.200.218:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alnawadertech.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amuyR-_ioCvBERk4wq-NLQAAAXA"]
[Thu Jul 30 15:21:27.432088 2026] [security2:error] [pid 147647:tid 147879] [client 20.203.200.218:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alnawadertech.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "amuyR-_ioCvBERk4wq-NLQAAAXA"]
[Thu Jul 30 15:21:27.466119 2026] [proxy:error] [pid 147647:tid 147832] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:27.466179 2026] [proxy_http:error] [pid 147647:tid 147832] [client 5.161.225.116:60186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:27.466737 2026] [proxy:error] [pid 147647:tid 147832] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:27.466779 2026] [proxy_http:error] [pid 147647:tid 147832] [client 5.161.225.116:60186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:27.512653 2026] [security2:error] [pid 147647:tid 147851] [client 20.104.18.253:6285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/automanipulative.php"] [unique_id "amuyR-_ioCvBERk4wq-NNwAAAVQ"]
[Thu Jul 30 15:21:27.846625 2026] [core:notice] [pid 147647:tid 147884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:27.850205 2026] [security2:error] [pid 147647:tid 147884] [client 66.249.79.229:56646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA/article/view/6793/2799"] [unique_id "amuyR-_ioCvBERk4wq-NQQAAAXU"]
[Thu Jul 30 15:21:27.858027 2026] [security2:error] [pid 147647:tid 147831] [client 20.203.200.218:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alnawadertech.com"] [uri "/.well-known/admin.php"] [unique_id "amuyR-_ioCvBERk4wq-NQgAAAUA"]
[Thu Jul 30 15:21:27.858151 2026] [security2:error] [pid 147647:tid 147831] [client 20.203.200.218:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alnawadertech.com"] [uri "/.well-known/admin.php"] [unique_id "amuyR-_ioCvBERk4wq-NQgAAAUA"]
[Thu Jul 30 15:21:28.095757 2026] [security2:error] [pid 147647:tid 147855] [client 2a03:2880:f800:29:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyR-_ioCvBERk4wq-NMQABWFs"]
[Thu Jul 30 15:21:28.126341 2026] [security2:error] [pid 147647:tid 147791] [client 20.104.18.253:6501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/av.php"] [unique_id "amuySO_ioCvBERk4wq-NRgAAARg"]
[Thu Jul 30 15:21:28.264370 2026] [proxy:error] [pid 147647:tid 147833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:28.264468 2026] [proxy_http:error] [pid 147647:tid 147833] [client 5.161.225.116:21412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:28.265057 2026] [proxy:error] [pid 147647:tid 147833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:28.265104 2026] [proxy_http:error] [pid 147647:tid 147833] [client 5.161.225.116:21412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:28.287869 2026] [autoindex:error] [pid 147647:tid 147894] [client 178.128.51.160:0] AH01276: Cannot serve directory /home1/mthgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://msrmanufacturing.com//blog//wp-login.php
[Thu Jul 30 15:21:28.427272 2026] [security2:error] [pid 147647:tid 147757] [remote 45.146.192.214:61716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.192.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ylw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuySO_ioCvBERk4wq-NWgABIW0"]
[Thu Jul 30 15:21:28.427925 2026] [core:notice] [pid 147647:tid 147903] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:28.431864 2026] [security2:error] [pid 147647:tid 147903] [client 66.249.79.229:56646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/download/8026/3146"] [unique_id "amuySO_ioCvBERk4wq-NXAAAAYg"]
[Thu Jul 30 15:21:28.464487 2026] [proxy:error] [pid 147647:tid 147805] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:28.464552 2026] [proxy_http:error] [pid 147647:tid 147805] [client 5.161.225.116:11524] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:28.465113 2026] [proxy:error] [pid 147647:tid 147805] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:21:28.465160 2026] [proxy_http:error] [pid 147647:tid 147805] [client 5.161.225.116:11524] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:21:28.513020 2026] [core:error] [pid 147647:tid 147875] [client 64.227.104.105:38468] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:28.513051 2026] [core:error] [pid 147647:tid 147875] [client 64.227.104.105:38468] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:28.533378 2026] [security2:error] [pid 147647:tid 147801] [client 20.63.98.115:26484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "amuySO_ioCvBERk4wq-NZwAAASI"]
[Thu Jul 30 15:21:28.609535 2026] [core:error] [pid 147647:tid 147889] [client 138.124.103.234:38994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:28.609562 2026] [core:error] [pid 147647:tid 147889] [client 138.124.103.234:38994] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:28.747368 2026] [security2:error] [pid 147647:tid 147845] [client 5.161.225.116:30390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "clubnails.bonafideadvisors.com"] [uri "/index.php"] [unique_id "amuyR-_ioCvBERk4wq-NIAAAAU4"]
[Thu Jul 30 15:21:28.750965 2026] [security2:error] [pid 147647:tid 147785] [client 5.161.225.116:60180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "clubnails.bonafideadvisors.com"] [uri "/index.php"] [unique_id "amuyR-_ioCvBERk4wq-NNQAAARI"]
[Thu Jul 30 15:21:28.763130 2026] [security2:error] [pid 147647:tid 147809] [client 20.104.18.253:6305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/ava.php"] [unique_id "amuySO_ioCvBERk4wq-NagAAASo"]
[Thu Jul 30 15:21:28.827308 2026] [core:error] [pid 147647:tid 147839] [client 45.249.89.53:55663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:28.827330 2026] [core:error] [pid 147647:tid 147839] [client 45.249.89.53:55663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:28.873041 2026] [core:notice] [pid 147647:tid 147832] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:28.876145 2026] [security2:error] [pid 147647:tid 147832] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Deiksis/article/view/6347/2825"] [unique_id "amuySO_ioCvBERk4wq-NcAAAAUE"]
[Thu Jul 30 15:21:29.112283 2026] [security2:error] [pid 147647:tid 147789] [client 20.203.200.218:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alnawadertech.com"] [uri "/.well-known/log.php"] [unique_id "amuySe_ioCvBERk4wq-NdwAAARY"]
[Thu Jul 30 15:21:29.112412 2026] [security2:error] [pid 147647:tid 147789] [client 20.203.200.218:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "alnawadertech.com"] [uri "/.well-known/log.php"] [unique_id "amuySe_ioCvBERk4wq-NdwAAARY"]
[Thu Jul 30 15:21:29.389992 2026] [security2:error] [pid 147647:tid 147840] [client 20.104.18.253:6316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/avaa.php"] [unique_id "amuySe_ioCvBERk4wq-NewAAAUk"]
[Thu Jul 30 15:21:29.471604 2026] [security2:error] [pid 147647:tid 147849] [client 20.63.98.115:26469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/ID3/about.php"] [unique_id "amuySe_ioCvBERk4wq-NfwAAAVI"]
[Thu Jul 30 15:21:29.732173 2026] [core:error] [pid 147647:tid 147871] [client 64.227.104.105:38474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:29.732197 2026] [core:error] [pid 147647:tid 147871] [client 64.227.104.105:38474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:29.845051 2026] [core:error] [pid 147647:tid 147858] [client 138.124.103.234:39000] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:29.845071 2026] [core:error] [pid 147647:tid 147858] [client 138.124.103.234:39000] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:30.033758 2026] [security2:error] [pid 147647:tid 147791] [client 20.104.18.253:6294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/ave.php"] [unique_id "amuySu_ioCvBERk4wq-NjgAAARg"]
[Thu Jul 30 15:21:30.081100 2026] [core:notice] [pid 147647:tid 147811] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:30.085113 2026] [security2:error] [pid 147647:tid 147811] [client 66.249.79.1:47683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Euclid/article/download/212/212"] [unique_id "amuySe_ioCvBERk4wq-NhAAAASw"]
[Thu Jul 30 15:21:30.202363 2026] [core:error] [pid 147647:tid 147872] [client 45.249.89.53:56260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:30.202384 2026] [core:error] [pid 147647:tid 147872] [client 45.249.89.53:56260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:30.306776 2026] [security2:error] [pid 147647:tid 147796] [client 20.215.191.139:54498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/json.php"] [unique_id "amuySu_ioCvBERk4wq-NkgAAAR0"]
[Thu Jul 30 15:21:30.307806 2026] [core:notice] [pid 147647:tid 147882] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:30.334752 2026] [security2:error] [pid 147647:tid 147815] [client 114.119.153.169:61387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/docs/5cfb7b-portsmouth-kit-20/5cfb7b-water-spirit-yugioh"] [unique_id "amuySu_ioCvBERk4wq-NkwAAATA"], referer: https://arabiandubaisafari.com/docs/5cfb7b-portsmouth-kit-20/5cfb7b-water-spirit-yugioh
[Thu Jul 30 15:21:30.642536 2026] [security2:error] [pid 147647:tid 147800] [client 20.104.18.253:6483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/aves.php"] [unique_id "amuySu_ioCvBERk4wq-NnQAAASE"]
[Thu Jul 30 15:21:30.762089 2026] [core:notice] [pid 147647:tid 147875] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:31.246731 2026] [security2:error] [pid 147647:tid 147854] [client 20.104.18.253:6289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/awesome-coming-soon/come.php"] [unique_id "amuyS-_ioCvBERk4wq-NqQAAAVc"]
[Thu Jul 30 15:21:31.258737 2026] [core:notice] [pid 147647:tid 147879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:31.262288 2026] [security2:error] [pid 147647:tid 147879] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/3785/1827"] [unique_id "amuyS-_ioCvBERk4wq-NqgAAAXA"]
[Thu Jul 30 15:21:31.370930 2026] [core:error] [pid 147647:tid 147813] [client 64.227.104.105:38486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:31.370953 2026] [core:error] [pid 147647:tid 147813] [client 64.227.104.105:38486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:31.747674 2026] [security2:error] [pid 147647:tid 147821] [client 20.215.191.139:54824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/mini.php"] [unique_id "amuyS-_ioCvBERk4wq-NtwAAATY"]
[Thu Jul 30 15:21:31.835807 2026] [core:notice] [pid 147647:tid 147883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:31.875778 2026] [security2:error] [pid 147647:tid 147818] [client 20.104.18.253:6319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/awesome-coming-soon/flower.php"] [unique_id "amuyS-_ioCvBERk4wq-NuQAAATM"]
[Thu Jul 30 15:21:31.953413 2026] [core:error] [pid 147647:tid 147863] [client 45.249.89.53:56811] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:31.953446 2026] [core:error] [pid 147647:tid 147863] [client 45.249.89.53:56811] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:32.194134 2026] [autoindex:error] [pid 147647:tid 147778] [client 34.34.253.252:27698] AH01276: Cannot serve directory /home2/mbmudite/koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:21:32.220191 2026] [core:error] [pid 147647:tid 147812] [client 138.124.103.234:39016] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:32.220215 2026] [core:error] [pid 147647:tid 147812] [client 138.124.103.234:39016] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:32.401375 2026] [security2:error] [pid 147647:tid 147884] [client 20.215.191.139:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/chosen.php"] [unique_id "amuyTO_ioCvBERk4wq-NxgAAAXU"]
[Thu Jul 30 15:21:32.486745 2026] [security2:error] [pid 147647:tid 147808] [client 20.104.18.253:6306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/aws.php"] [unique_id "amuyTO_ioCvBERk4wq-NxwAAASk"]
[Thu Jul 30 15:21:32.835557 2026] [core:error] [pid 147647:tid 147835] [client 64.227.104.105:38490] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:32.835580 2026] [core:error] [pid 147647:tid 147835] [client 64.227.104.105:38490] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:33.055205 2026] [security2:error] [pid 147647:tid 147841] [client 20.215.191.139:42021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/kj.php"] [unique_id "amuyTe_ioCvBERk4wq-N2wAAAUo"]
[Thu Jul 30 15:21:33.087143 2026] [security2:error] [pid 147647:tid 147781] [client 20.104.18.253:6333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/ax.php"] [unique_id "amuyTe_ioCvBERk4wq-N3AAAAQ4"]
[Thu Jul 30 15:21:33.339994 2026] [core:error] [pid 147647:tid 147847] [client 45.249.89.53:57521] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:33.340034 2026] [core:error] [pid 147647:tid 147847] [client 45.249.89.53:57521] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:33.414418 2026] [core:notice] [pid 147647:tid 147874] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:33.417751 2026] [security2:error] [pid 147647:tid 147874] [client 66.249.79.229:58163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/download/8549/3342"] [unique_id "amuyTe_ioCvBERk4wq-N5AAAAWs"]
[Thu Jul 30 15:21:33.590805 2026] [core:error] [pid 147647:tid 147868] [client 138.124.103.234:45880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:33.590830 2026] [core:error] [pid 147647:tid 147868] [client 138.124.103.234:45880] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:33.650971 2026] [security2:error] [pid 147647:tid 147856] [client 114.119.149.228:57615] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiantourz.com"] [uri "/categorie-produit/homme/pulls-gilets-homme/page/5/"] [unique_id "amuyTe_ioCvBERk4wq-N6QAAAVk"], referer: https://www.arabiantourz.com/categorie-produit/homme/pulls-gilets-homme/page/6/
[Thu Jul 30 15:21:33.693775 2026] [security2:error] [pid 147647:tid 147896] [client 20.104.18.253:6475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/axx.php"] [unique_id "amuyTe_ioCvBERk4wq-N7QAAAYE"]
[Thu Jul 30 15:21:33.747394 2026] [core:notice] [pid 147647:tid 147848] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:34.095632 2026] [security2:error] [pid 147647:tid 147832] [client 54.167.223.174:10876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuyTe_ioCvBERk4wq-N8wAAAUE"], referer: https://globalmarks.pk/
[Thu Jul 30 15:21:34.125234 2026] [security2:error] [pid 147647:tid 147789] [client 20.203.148.31:11662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amuyTu_ioCvBERk4wq-N9wAAARY"]
[Thu Jul 30 15:21:34.173163 2026] [core:notice] [pid 147647:tid 147814] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:34.176575 2026] [security2:error] [pid 147647:tid 147814] [client 66.249.79.229:58163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/3805/1846"] [unique_id "amuyTu_ioCvBERk4wq-N-AAAAS8"]
[Thu Jul 30 15:21:34.322003 2026] [security2:error] [pid 147647:tid 147793] [client 20.104.18.253:6303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/ay.php"] [unique_id "amuyTu_ioCvBERk4wq-N_wAAARo"]
[Thu Jul 30 15:21:34.778635 2026] [core:error] [pid 147647:tid 147808] [client 45.249.89.53:58116] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:34.778659 2026] [core:error] [pid 147647:tid 147808] [client 45.249.89.53:58116] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:34.891384 2026] [core:notice] [pid 147647:tid 147901] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:34.894868 2026] [security2:error] [pid 147647:tid 147901] [client 66.249.79.229:58163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/download/9208/4031"] [unique_id "amuyTu_ioCvBERk4wq-ODQAAAYY"]
[Thu Jul 30 15:21:34.909439 2026] [security2:error] [pid 147647:tid 147804] [client 20.203.148.31:28433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amuyTu_ioCvBERk4wq-ODgAAASU"]
[Thu Jul 30 15:21:34.918537 2026] [core:error] [pid 147647:tid 147834] [client 138.124.103.234:45882] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:34.918556 2026] [core:error] [pid 147647:tid 147834] [client 138.124.103.234:45882] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:34.934417 2026] [security2:error] [pid 147647:tid 147853] [client 20.104.18.253:6481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/ayk.php"] [unique_id "amuyTu_ioCvBERk4wq-OEAAAAVY"]
[Thu Jul 30 15:21:35.110180 2026] [security2:error] [pid 147647:tid 147841] [client 64.227.104.105:38496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/storage/framework/.env"] [unique_id "amuyT-_ioCvBERk4wq-OFAAAAUo"]
[Thu Jul 30 15:21:35.339740 2026] [core:notice] [pid 147647:tid 147797] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:35.380487 2026] [security2:error] [pid 147647:tid 147830] [client 20.203.148.31:11414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amuyT-_ioCvBERk4wq-OHQAAAT8"]
[Thu Jul 30 15:21:35.526139 2026] [security2:error] [pid 147647:tid 147780] [client 64.227.104.105:38496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/laravel/.env"] [unique_id "amuyT-_ioCvBERk4wq-OHgAAAQ0"]
[Thu Jul 30 15:21:35.562078 2026] [core:notice] [pid 147647:tid 147669] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:35.595924 2026] [security2:error] [pid 147647:tid 147889] [client 20.104.18.253:6313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/az.php"] [unique_id "amuyT-_ioCvBERk4wq-OJwAAAXo"]
[Thu Jul 30 15:21:35.840949 2026] [core:notice] [pid 147647:tid 147866] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:35.844460 2026] [security2:error] [pid 147647:tid 147866] [client 66.249.79.229:58163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/view/9628/4301"] [unique_id "amuyT-_ioCvBERk4wq-OLQAAAWM"]
[Thu Jul 30 15:21:35.935221 2026] [core:error] [pid 147647:tid 147879] [client 64.227.104.105:38496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:35.935243 2026] [core:error] [pid 147647:tid 147879] [client 64.227.104.105:38496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:36.090940 2026] [core:notice] [pid 147647:tid 147660] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:36.100435 2026] [security2:error] [pid 147647:tid 147835] [client 20.63.98.115:26478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/images/index.php"] [unique_id "amuyUO_ioCvBERk4wq-ONAAAAUQ"]
[Thu Jul 30 15:21:36.156570 2026] [core:error] [pid 147647:tid 147829] [client 45.249.89.53:58733] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:36.156596 2026] [core:error] [pid 147647:tid 147829] [client 45.249.89.53:58733] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:36.195595 2026] [security2:error] [pid 147647:tid 147818] [client 20.104.18.253:6326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/azdare.php"] [unique_id "amuyUO_ioCvBERk4wq-OOAAAATM"]
[Thu Jul 30 15:21:36.200103 2026] [security2:error] [pid 147647:tid 147843] [client 20.215.191.139:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/wp-files.php"] [unique_id "amuyUO_ioCvBERk4wq-OOQAAAUw"]
[Thu Jul 30 15:21:36.246549 2026] [core:error] [pid 147647:tid 147883] [client 138.124.103.234:45886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:36.246575 2026] [core:error] [pid 147647:tid 147883] [client 138.124.103.234:45886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:36.336882 2026] [core:notice] [pid 147647:tid 147854] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:36.804423 2026] [security2:error] [pid 147647:tid 147793] [client 20.104.18.253:6284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/azra-tn/wso.php"] [unique_id "amuyUO_ioCvBERk4wq-OSwAAARo"]
[Thu Jul 30 15:21:36.835461 2026] [core:notice] [pid 147647:tid 147820] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:37.143053 2026] [security2:error] [pid 147647:tid 147686] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyUe_ioCvBERk4wq-OUwABeyY"]
[Thu Jul 30 15:21:37.143202 2026] [security2:error] [pid 147647:tid 147890] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyUe_ioCvBERk4wq-OUwABeyY"]
[Thu Jul 30 15:21:37.186062 2026] [security2:error] [pid 147647:tid 147850] [client 20.63.98.115:33558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/network/about.php"] [unique_id "amuyUe_ioCvBERk4wq-OVgAAAVM"]
[Thu Jul 30 15:21:37.334056 2026] [core:notice] [pid 147647:tid 147801] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:37.448118 2026] [security2:error] [pid 147647:tid 147867] [client 20.104.18.253:6330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/b.php"] [unique_id "amuyUe_ioCvBERk4wq-OXwAAAWQ"]
[Thu Jul 30 15:21:37.467430 2026] [core:error] [pid 147647:tid 147875] [client 138.124.103.234:45888] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:37.467452 2026] [core:error] [pid 147647:tid 147875] [client 138.124.103.234:45888] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:37.551185 2026] [core:error] [pid 147647:tid 147819] [client 45.249.89.53:59329] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:37.551216 2026] [core:error] [pid 147647:tid 147819] [client 45.249.89.53:59329] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:37.599045 2026] [security2:error] [pid 147647:tid 147841] [client 172.237.109.114:24056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyUe_ioCvBERk4wq-OUQAAAUo"]
[Thu Jul 30 15:21:37.834431 2026] [core:notice] [pid 147647:tid 147798] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:37.837849 2026] [security2:error] [pid 147647:tid 147798] [client 66.249.79.8:51257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/view/1744/1467"] [unique_id "amuyUe_ioCvBERk4wq-OaQAAAR8"]
[Thu Jul 30 15:21:38.082517 2026] [security2:error] [pid 147647:tid 147904] [client 20.104.18.253:6299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/b374k.php"] [unique_id "amuyUu_ioCvBERk4wq-OdAAAAYk"]
[Thu Jul 30 15:21:38.336756 2026] [core:notice] [pid 147647:tid 147826] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:38.340233 2026] [security2:error] [pid 147647:tid 147826] [client 66.249.79.229:58163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/download/8711/3464"] [unique_id "amuyUu_ioCvBERk4wq-OeAAAATs"]
[Thu Jul 30 15:21:38.514760 2026] [security2:error] [pid 147647:tid 147892] [client 20.215.191.139:42010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/wp-setup.php"] [unique_id "amuyUu_ioCvBERk4wq-OgAAAAX0"]
[Thu Jul 30 15:21:38.685844 2026] [security2:error] [pid 147647:tid 147787] [client 20.104.18.253:6470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/b8b.php"] [unique_id "amuyUu_ioCvBERk4wq-OgQAAARQ"]
[Thu Jul 30 15:21:38.694370 2026] [core:error] [pid 147647:tid 147799] [client 138.124.103.234:45902] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:38.694399 2026] [core:error] [pid 147647:tid 147799] [client 138.124.103.234:45902] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:38.953228 2026] [core:error] [pid 147647:tid 147778] [client 45.249.89.53:59967] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:38.953251 2026] [core:error] [pid 147647:tid 147778] [client 45.249.89.53:59967] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:39.148270 2026] [core:notice] [pid 147647:tid 147837] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:39.287124 2026] [security2:error] [pid 147647:tid 147870] [client 20.104.18.253:6327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alanturner.com.au"] [uri "/babu.php"] [unique_id "amuyU-_ioCvBERk4wq-OlAAAAWc"]
[Thu Jul 30 15:21:39.397642 2026] [core:notice] [pid 147647:tid 147707] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:39.536655 2026] [security2:error] [pid 147647:tid 147901] [client 20.215.191.139:52465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/defaults.php"] [unique_id "amuyU-_ioCvBERk4wq-OmAAAAYY"]
[Thu Jul 30 15:21:39.884263 2026] [core:notice] [pid 147647:tid 147890] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:39.985720 2026] [core:error] [pid 147647:tid 147862] [client 138.124.103.234:45912] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:39.985745 2026] [core:error] [pid 147647:tid 147862] [client 138.124.103.234:45912] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:40.117775 2026] [security2:error] [pid 147647:tid 147895] [client 20.215.191.139:19643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/gtc.php"] [unique_id "amuyVO_ioCvBERk4wq-OqwAAAYA"]
[Thu Jul 30 15:21:40.388195 2026] [security2:error] [pid 147647:tid 147693] [remote 52.167.144.227:62594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/value.php"] [unique_id "amuyVO_ioCvBERk4wq-OsQABdy0"]
[Thu Jul 30 15:21:40.589677 2026] [core:notice] [pid 147647:tid 147818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:40.593275 2026] [security2:error] [pid 147647:tid 147818] [client 66.249.79.229:58163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JSTE/article/download/7064/2867"] [unique_id "amuyVO_ioCvBERk4wq-OtQAAATM"]
[Thu Jul 30 15:21:40.758140 2026] [security2:error] [pid 147647:tid 147826] [client 45.249.89.53:60559] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/storage/framework/.env"] [unique_id "amuyVO_ioCvBERk4wq-OuQAAATs"]
[Thu Jul 30 15:21:41.137641 2026] [security2:error] [pid 147647:tid 147872] [client 45.249.89.53:60559] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/laravel/.env"] [unique_id "amuyVe_ioCvBERk4wq-OygAAAWk"]
[Thu Jul 30 15:21:41.480383 2026] [core:notice] [pid 147647:tid 147828] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:41.483758 2026] [security2:error] [pid 147647:tid 147828] [client 66.249.79.1:54824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/1315/808"] [unique_id "amuyVe_ioCvBERk4wq-O0gAAAT0"]
[Thu Jul 30 15:21:41.519401 2026] [core:error] [pid 147647:tid 147788] [client 45.249.89.53:60559] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:41.519435 2026] [core:error] [pid 147647:tid 147788] [client 45.249.89.53:60559] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:41.709722 2026] [core:notice] [pid 147647:tid 147813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:41.948283 2026] [security2:error] [pid 147647:tid 147847] [client 20.215.191.139:29822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/import.php"] [unique_id "amuyVe_ioCvBERk4wq-PCQAAAVA"]
[Thu Jul 30 15:21:42.048877 2026] [security2:error] [pid 147647:tid 147871] [client 20.63.98.115:42169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/xpw.php"] [unique_id "amuyVu_ioCvBERk4wq-PCgAAAWg"]
[Thu Jul 30 15:21:42.175512 2026] [core:notice] [pid 147647:tid 147784] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:42.178543 2026] [security2:error] [pid 147647:tid 147784] [client 66.249.79.229:58163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPAS/article/download/6061/2628"] [unique_id "amuyVu_ioCvBERk4wq-PEQAAARE"]
[Thu Jul 30 15:21:42.194760 2026] [core:error] [pid 147647:tid 147895] [client 64.227.104.105:38510] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:42.194777 2026] [core:error] [pid 147647:tid 147895] [client 64.227.104.105:38510] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:42.732260 2026] [security2:error] [pid 147647:tid 147768] [remote 216.73.216.51:17834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuyVu_ioCvBERk4wq-PIQABRHg"]
[Thu Jul 30 15:21:43.037827 2026] [security2:error] [pid 147647:tid 147782] [client 20.215.191.139:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/lufix.php"] [unique_id "amuyV-_ioCvBERk4wq-PMQAAAQ8"]
[Thu Jul 30 15:21:43.090942 2026] [security2:error] [pid 147647:tid 147799] [client 136.108.44.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amuyVO_ioCvBERk4wq-OwwAAASA"]
[Thu Jul 30 15:21:43.090974 2026] [security2:error] [pid 147647:tid 147799] [client 136.108.44.153:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/index.php"] [unique_id "amuyVO_ioCvBERk4wq-OwwAAASA"]
[Thu Jul 30 15:21:43.273750 2026] [security2:error] [pid 147647:tid 147836] [client 136.108.44.153:35472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "stunningtouchcleaning.com"] [uri "/.git/config"] [unique_id "amuyVO_ioCvBERk4wq-OwQAAAUU"]
[Thu Jul 30 15:21:43.464733 2026] [security2:error] [pid 147647:tid 147787] [client 20.63.98.115:39708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-cron.php"] [unique_id "amuyV-_ioCvBERk4wq-PRgAAARQ"]
[Thu Jul 30 15:21:43.552611 2026] [security2:error] [pid 147647:tid 147780] [client 20.203.148.31:42824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amuyV-_ioCvBERk4wq-PUQAAAQ0"]
[Thu Jul 30 15:21:43.557877 2026] [security2:error] [pid 147647:tid 147820] [client 52.167.144.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuyV-_ioCvBERk4wq-PPQAAATU"]
[Thu Jul 30 15:21:43.601222 2026] [security2:error] [pid 147647:tid 147897] [client 52.34.76.65:18956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyV-_ioCvBERk4wq-PNQABggA"]
[Thu Jul 30 15:21:43.897306 2026] [security2:error] [pid 147647:tid 147847] [client 20.215.191.139:54540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/Geforce.php"] [unique_id "amuyV-_ioCvBERk4wq-PXgAAAVA"]
[Thu Jul 30 15:21:44.134338 2026] [core:notice] [pid 147647:tid 147865] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:44.585399 2026] [core:notice] [pid 147647:tid 147823] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:44.695433 2026] [security2:error] [pid 147647:tid 147816] [client 95.19.86.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyV-_ioCvBERk4wq-PXwABMRQ"], referer: https://allmontecristi.com
[Thu Jul 30 15:21:44.787193 2026] [security2:error] [pid 147647:tid 147779] [client 52.34.76.65:10513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyWO_ioCvBERk4wq-PbAABDAM"]
[Thu Jul 30 15:21:44.808856 2026] [security2:error] [pid 147647:tid 147878] [client 20.215.191.139:29783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/a4.php"] [unique_id "amuyWO_ioCvBERk4wq-PkQAAAW8"]
[Thu Jul 30 15:21:45.037168 2026] [core:notice] [pid 147647:tid 147870] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:45.363635 2026] [security2:error] [pid 147647:tid 147698] [remote 154.26.129.62:48746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.129.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuyWe_ioCvBERk4wq-PswABgzI"]
[Thu Jul 30 15:21:45.503256 2026] [security2:error] [pid 147647:tid 147819] [client 20.203.148.31:11413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amuyWe_ioCvBERk4wq-PtQAAATQ"]
[Thu Jul 30 15:21:45.534357 2026] [core:notice] [pid 147647:tid 147829] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:45.792421 2026] [core:error] [pid 147647:tid 147887] [client 64.227.104.105:45166] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:45.792449 2026] [core:error] [pid 147647:tid 147887] [client 64.227.104.105:45166] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:46.037245 2026] [core:notice] [pid 147647:tid 147885] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:46.107771 2026] [security2:error] [pid 147647:tid 147798] [client 52.34.76.65:46847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyWe_ioCvBERk4wq-PyAABHzM"]
[Thu Jul 30 15:21:46.149862 2026] [core:error] [pid 147647:tid 147831] [client 52.167.144.213:53664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:46.149886 2026] [core:error] [pid 147647:tid 147831] [client 52.167.144.213:53664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:46.697655 2026] [core:error] [pid 147647:tid 147877] [client 45.249.89.53:61628] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:46.697694 2026] [core:error] [pid 147647:tid 147877] [client 45.249.89.53:61628] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:46.723226 2026] [security2:error] [pid 147647:tid 147903] [client 37.140.254.23:26211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.254.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moswey.com"] [uri "/archivarix.cms.php"] [unique_id "amuyWu_ioCvBERk4wq-QHQAAAYg"]
[Thu Jul 30 15:21:47.101226 2026] [security2:error] [pid 147647:tid 147846] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyWu_ioCvBERk4wq-P8wAAAU8"]
[Thu Jul 30 15:21:47.293706 2026] [security2:error] [pid 147647:tid 147816] [client 20.203.148.31:30060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amuyW-_ioCvBERk4wq-QUAAAATE"]
[Thu Jul 30 15:21:47.590309 2026] [security2:error] [pid 147647:tid 147898] [client 52.34.76.65:26543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyW-_ioCvBERk4wq-QQAABgyk"]
[Thu Jul 30 15:21:47.602807 2026] [core:error] [pid 147647:tid 147856] [client 64.227.104.105:45168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:47.603125 2026] [core:error] [pid 147647:tid 147856] [client 64.227.104.105:45168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:47.882585 2026] [security2:error] [pid 147647:tid 147718] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyW-_ioCvBERk4wq-QbgABQUY"]
[Thu Jul 30 15:21:47.882733 2026] [security2:error] [pid 147647:tid 147832] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyW-_ioCvBERk4wq-QbgABQUY"]
[Thu Jul 30 15:21:47.961660 2026] [security2:error] [pid 147647:tid 147879] [client 20.63.98.115:33598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cah.php"] [unique_id "amuyW-_ioCvBERk4wq-QhgAAAXA"]
[Thu Jul 30 15:21:48.068215 2026] [core:notice] [pid 147647:tid 147892] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:48.071596 2026] [security2:error] [pid 147647:tid 147892] [client 66.249.79.229:61383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/view/618/413"] [unique_id "amuyXO_ioCvBERk4wq-QhwAAAX0"]
[Thu Jul 30 15:21:48.093425 2026] [security2:error] [pid 147647:tid 147757] [remote 72.167.132.114:45010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-fdb1204b.med.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuyXO_ioCvBERk4wq-QiAABVG0"]
[Thu Jul 30 15:21:48.281502 2026] [core:error] [pid 147647:tid 147878] [client 74.7.241.189:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:48.281525 2026] [core:error] [pid 147647:tid 147878] [client 74.7.241.189:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:48.281627 2026] [security2:error] [pid 147647:tid 147878] [client 74.7.241.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuyXO_ioCvBERk4wq-QoAAAAW8"]
[Thu Jul 30 15:21:48.282221 2026] [security2:error] [pid 147647:tid 147814] [client 74.7.241.189:55522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.trustedmoversandpackersabudhabi.online"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuyXO_ioCvBERk4wq-QmwABL3Y"]
[Thu Jul 30 15:21:48.562734 2026] [security2:error] [pid 147647:tid 147841] [client 20.215.191.139:54478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/accueil.php"] [unique_id "amuyXO_ioCvBERk4wq-QuwAAAUo"]
[Thu Jul 30 15:21:48.791718 2026] [core:notice] [pid 147647:tid 147890] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:48.795121 2026] [security2:error] [pid 147647:tid 147890] [client 66.249.79.1:54824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/8201/3183"] [unique_id "amuyXO_ioCvBERk4wq-QwgAAAXs"]
[Thu Jul 30 15:21:49.094866 2026] [core:error] [pid 147647:tid 147801] [client 64.227.104.105:38008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:49.094896 2026] [core:error] [pid 147647:tid 147801] [client 64.227.104.105:38008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:49.875194 2026] [core:notice] [pid 147647:tid 147881] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:49.996959 2026] [core:error] [pid 147647:tid 147793] [client 45.249.89.53:63862] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:49.996992 2026] [core:error] [pid 147647:tid 147793] [client 45.249.89.53:63862] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:50.101440 2026] [security2:error] [pid 147647:tid 147844] [client 20.215.191.139:54804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/dashboard.php"] [unique_id "amuyXu_ioCvBERk4wq-RBQAAAU0"]
[Thu Jul 30 15:21:50.419966 2026] [security2:error] [pid 147647:tid 147865] [client 20.63.98.115:48491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cong.php"] [unique_id "amuyXu_ioCvBERk4wq-RDAAAAWI"]
[Thu Jul 30 15:21:50.531072 2026] [security2:error] [pid 147647:tid 147790] [client 74.7.230.56:58800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hello-pal.com.yqe.gzj.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amuyXu_ioCvBERk4wq-REwABFyM"]
[Thu Jul 30 15:21:50.638621 2026] [core:error] [pid 147647:tid 147796] [client 64.227.104.105:38016] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:50.638644 2026] [core:error] [pid 147647:tid 147796] [client 64.227.104.105:38016] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:50.639501 2026] [autoindex:error] [pid 147647:tid 147664] [remote 74.7.227.17:43676] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:21:51.094521 2026] [core:notice] [pid 147647:tid 147786] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:51.189816 2026] [core:notice] [pid 147647:tid 147842] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:51.381639 2026] [core:error] [pid 147647:tid 147808] [client 45.249.89.53:65281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:51.381682 2026] [core:error] [pid 147647:tid 147808] [client 45.249.89.53:65281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:51.592494 2026] [security2:error] [pid 147647:tid 147828] [client 20.215.191.139:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/radio.php"] [unique_id "amuyX-_ioCvBERk4wq-RNQAAAT0"]
[Thu Jul 30 15:21:52.037113 2026] [core:error] [pid 147647:tid 147836] [client 64.227.104.105:38024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:52.037137 2026] [core:error] [pid 147647:tid 147836] [client 64.227.104.105:38024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:52.081608 2026] [fcgid:warn] [pid 147647:tid 147896] (70014)End of file found: [client 18.218.118.203:61758] mod_fcgid: can't get data from http client
[Thu Jul 30 15:21:52.277087 2026] [security2:error] [pid 147647:tid 147788] [client 20.63.98.115:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/Sanskrit.php"] [unique_id "amuyYO_ioCvBERk4wq-RSAAAARU"]
[Thu Jul 30 15:21:52.486771 2026] [security2:error] [pid 147647:tid 147854] [client 172.237.109.114:11788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyX-_ioCvBERk4wq-RPwAAAVc"]
[Thu Jul 30 15:21:52.510770 2026] [security2:error] [pid 147647:tid 147871] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyX-_ioCvBERk4wq-ROwAAAWg"]
[Thu Jul 30 15:21:52.530663 2026] [security2:error] [pid 147647:tid 147832] [client 20.215.191.139:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/wpsml-sys.php"] [unique_id "amuyYO_ioCvBERk4wq-RUwAAAUE"]
[Thu Jul 30 15:21:52.641974 2026] [core:notice] [pid 147647:tid 147872] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:52.823962 2026] [core:error] [pid 147647:tid 147864] [client 45.249.89.53:49496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:52.824004 2026] [core:error] [pid 147647:tid 147864] [client 45.249.89.53:49496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:53.430028 2026] [core:notice] [pid 147647:tid 147699] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:53.453331 2026] [security2:error] [pid 147647:tid 147900] [client 40.77.167.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuyYe_ioCvBERk4wq-RZgAAAYU"]
[Thu Jul 30 15:21:53.509904 2026] [core:error] [pid 147647:tid 147801] [client 64.227.104.105:38028] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:53.509928 2026] [core:error] [pid 147647:tid 147801] [client 64.227.104.105:38028] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:53.541860 2026] [core:notice] [pid 147647:tid 147784] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:53.547581 2026] [security2:error] [pid 147647:tid 147784] [client 66.249.79.229:61071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/1770/1299"] [unique_id "amuyYe_ioCvBERk4wq-RgwAAARE"]
[Thu Jul 30 15:21:53.581935 2026] [security2:error] [pid 147647:tid 147834] [client 172.237.109.114:39081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyYe_ioCvBERk4wq-RaAAAAUM"]
[Thu Jul 30 15:21:53.776342 2026] [core:notice] [pid 147647:tid 147853] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:53.782013 2026] [security2:error] [pid 147647:tid 147853] [client 66.249.79.1:54824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Caruban/article/view/7271/2934"] [unique_id "amuyYe_ioCvBERk4wq-RjgAAAVY"]
[Thu Jul 30 15:21:53.823540 2026] [security2:error] [pid 147647:tid 147782] [client 20.63.98.115:48496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ms-edit.php"] [unique_id "amuyYe_ioCvBERk4wq-RjwAAAQ8"]
[Thu Jul 30 15:21:54.219087 2026] [core:error] [pid 147647:tid 147778] [client 45.249.89.53:50088] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:54.219111 2026] [core:error] [pid 147647:tid 147778] [client 45.249.89.53:50088] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:54.227282 2026] [core:notice] [pid 147647:tid 147787] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:54.353156 2026] [security2:error] [pid 147647:tid 147824] [client 20.215.191.139:52421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/02.php"] [unique_id "amuyYu_ioCvBERk4wq-RnAAAATk"]
[Thu Jul 30 15:21:54.627054 2026] [security2:error] [pid 147647:tid 147790] [client 20.63.98.115:42608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/function.php"] [unique_id "amuyYu_ioCvBERk4wq-RowAAARc"]
[Thu Jul 30 15:21:54.720919 2026] [core:notice] [pid 147647:tid 147805] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:55.006328 2026] [security2:error] [pid 147647:tid 147791] [client 20.215.191.139:19610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/infos.php"] [unique_id "amuyY-_ioCvBERk4wq-RugAAARg"]
[Thu Jul 30 15:21:55.295468 2026] [core:notice] [pid 147647:tid 147739] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:55.442367 2026] [core:notice] [pid 147647:tid 147780] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:55.582907 2026] [security2:error] [pid 147647:tid 147864] [client 91.184.126.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyYu_ioCvBERk4wq-RqwABYWg"], referer: https://allmontecristi.com
[Thu Jul 30 15:21:55.598651 2026] [core:error] [pid 147647:tid 147895] [client 64.227.104.105:38036] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:55.598677 2026] [core:error] [pid 147647:tid 147895] [client 64.227.104.105:38036] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:55.668066 2026] [core:error] [pid 147647:tid 147902] [client 45.249.89.53:50706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:55.668090 2026] [core:error] [pid 147647:tid 147902] [client 45.249.89.53:50706] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:55.801269 2026] [security2:error] [pid 147647:tid 147885] [client 20.63.98.115:48483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ee.php"] [unique_id "amuyY-_ioCvBERk4wq-R0QAAAXY"]
[Thu Jul 30 15:21:55.879463 2026] [security2:error] [pid 147647:tid 147812] [client 20.215.191.139:19614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/updates.php"] [unique_id "amuyY-_ioCvBERk4wq-R0gAAAS0"]
[Thu Jul 30 15:21:55.909162 2026] [core:notice] [pid 147647:tid 147799] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:56.831830 2026] [core:notice] [pid 147647:tid 147903] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:56.835431 2026] [security2:error] [pid 147647:tid 147903] [client 66.249.79.237:57214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/view/7530"] [unique_id "amuyZO_ioCvBERk4wq-R5wAAAYg"]
[Thu Jul 30 15:21:56.964186 2026] [core:error] [pid 147647:tid 147889] [client 64.227.104.105:38040] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:56.964212 2026] [core:error] [pid 147647:tid 147889] [client 64.227.104.105:38040] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:57.047908 2026] [core:error] [pid 147647:tid 147890] [client 45.249.89.53:51318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:57.047933 2026] [core:error] [pid 147647:tid 147890] [client 45.249.89.53:51318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:57.064594 2026] [core:notice] [pid 147647:tid 147794] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:57.068224 2026] [security2:error] [pid 147647:tid 147794] [client 66.249.79.1:54824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/logika/article/download/2075/1307"] [unique_id "amuyZe_ioCvBERk4wq-R9AAAARs"]
[Thu Jul 30 15:21:57.343626 2026] [security2:error] [pid 147647:tid 147901] [client 20.215.191.139:31562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/user.php"] [unique_id "amuyZe_ioCvBERk4wq-R_wAAAYY"]
[Thu Jul 30 15:21:57.946047 2026] [core:notice] [pid 147647:tid 147780] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:58.276709 2026] [core:error] [pid 147647:tid 147885] [client 64.227.104.105:60036] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:58.276745 2026] [core:error] [pid 147647:tid 147885] [client 64.227.104.105:60036] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:58.404048 2026] [core:notice] [pid 147647:tid 147785] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:58.407825 2026] [security2:error] [pid 147647:tid 147785] [client 66.249.79.1:54824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JSHR/article/view/7603"] [unique_id "amuyZu_ioCvBERk4wq-SHgAAARI"]
[Thu Jul 30 15:21:58.443075 2026] [core:error] [pid 147647:tid 147802] [client 45.249.89.53:51906] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:58.443103 2026] [core:error] [pid 147647:tid 147802] [client 45.249.89.53:51906] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:58.554893 2026] [security2:error] [pid 147647:tid 147652] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyZu_ioCvBERk4wq-SIAABDAQ"]
[Thu Jul 30 15:21:58.555102 2026] [security2:error] [pid 147647:tid 147779] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyZu_ioCvBERk4wq-SIAABDAQ"]
[Thu Jul 30 15:21:58.720026 2026] [security2:error] [pid 147647:tid 147888] [client 20.215.191.139:29779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/admin-ajax.php"] [unique_id "amuyZu_ioCvBERk4wq-SJAAAAXk"]
[Thu Jul 30 15:21:58.757539 2026] [security2:error] [pid 147647:tid 147809] [client 20.203.148.31:28421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amuyZu_ioCvBERk4wq-SJQAAASo"]
[Thu Jul 30 15:21:58.852174 2026] [core:notice] [pid 147647:tid 147807] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:59.470005 2026] [core:error] [pid 147647:tid 147806] [client 64.227.104.105:60044] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:59.470028 2026] [core:error] [pid 147647:tid 147806] [client 64.227.104.105:60044] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:59.503058 2026] [security2:error] [pid 147647:tid 147842] [client 172.237.109.114:30985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyZu_ioCvBERk4wq-SMQAAAUs"]
[Thu Jul 30 15:21:59.602896 2026] [security2:error] [pid 147647:tid 147848] [client 172.237.109.114:60741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyZ-_ioCvBERk4wq-SMgAAAVE"]
[Thu Jul 30 15:21:59.782458 2026] [core:notice] [pid 147647:tid 147895] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:21:59.786199 2026] [security2:error] [pid 147647:tid 147895] [client 66.249.79.229:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jka/article/download/5576/2873"] [unique_id "amuyZ-_ioCvBERk4wq-SQgAAAYA"]
[Thu Jul 30 15:21:59.838870 2026] [core:error] [pid 147647:tid 147900] [client 45.249.89.53:52492] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:21:59.838889 2026] [core:error] [pid 147647:tid 147900] [client 45.249.89.53:52492] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:22:00.008529 2026] [core:notice] [pid 147647:tid 147812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:00.012140 2026] [security2:error] [pid 147647:tid 147812] [client 66.249.79.1:54824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/878"] [unique_id "amuyaO_ioCvBERk4wq-STAAAAS0"]
[Thu Jul 30 15:22:00.451062 2026] [security2:error] [pid 147647:tid 147853] [client 172.237.109.114:39344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyZ-_ioCvBERk4wq-SSwAAAVY"]
[Thu Jul 30 15:22:00.806077 2026] [core:error] [pid 147647:tid 147682] [remote 216.73.217.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:22:00.806098 2026] [core:error] [pid 147647:tid 147682] [remote 216.73.217.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:22:00.967389 2026] [core:notice] [pid 147647:tid 147785] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:00.970966 2026] [security2:error] [pid 147647:tid 147785] [client 66.249.79.229:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jibm/article/view/3362/3725"] [unique_id "amuyaO_ioCvBERk4wq-STwAAARI"]
[Thu Jul 30 15:22:01.179785 2026] [security2:error] [pid 147647:tid 147855] [client 20.63.98.115:33636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/new.php"] [unique_id "amuyae_ioCvBERk4wq-SUAAAAVg"]
[Thu Jul 30 15:22:01.216446 2026] [core:error] [pid 147647:tid 147899] [client 45.249.89.53:53057] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:22:01.216472 2026] [core:error] [pid 147647:tid 147899] [client 45.249.89.53:53057] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:22:01.235523 2026] [core:notice] [pid 147647:tid 147850] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:01.239008 2026] [security2:error] [pid 147647:tid 147850] [client 66.249.79.1:54824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/8215"] [unique_id "amuyae_ioCvBERk4wq-SUgAAAVM"]
[Thu Jul 30 15:22:01.290589 2026] [core:error] [pid 147647:tid 147779] [client 66.249.68.37:55281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:22:01.290609 2026] [core:error] [pid 147647:tid 147779] [client 66.249.68.37:55281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:22:01.632134 2026] [security2:error] [pid 147647:tid 147814] [client 20.203.148.31:35512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amuyae_ioCvBERk4wq-SWgAAAS8"]
[Thu Jul 30 15:22:01.729585 2026] [core:notice] [pid 147647:tid 147896] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:01.733166 2026] [security2:error] [pid 147647:tid 147896] [client 66.249.79.229:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/view/2578"] [unique_id "amuyae_ioCvBERk4wq-SXgAAAYE"]
[Thu Jul 30 15:22:02.286869 2026] [core:notice] [pid 147647:tid 147884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:02.394751 2026] [security2:error] [pid 147647:tid 147862] [client 43.173.181.164:43096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2017/06/03/fontaine-a-boissons/"] [unique_id "amuyau_ioCvBERk4wq-SaQAAAV8"]
[Thu Jul 30 15:22:02.626895 2026] [core:error] [pid 147647:tid 147819] [client 45.249.89.53:53602] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:22:02.626926 2026] [core:error] [pid 147647:tid 147819] [client 45.249.89.53:53602] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:22:02.728479 2026] [core:notice] [pid 147647:tid 147868] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:02.992852 2026] [security2:error] [pid 147647:tid 147874] [client 20.215.191.139:19587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/alfa.php"] [unique_id "amuyau_ioCvBERk4wq-SewAAAWs"]
[Thu Jul 30 15:22:03.038199 2026] [core:notice] [pid 147647:tid 147894] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:03.044149 2026] [security2:error] [pid 147647:tid 147894] [client 43.172.195.68:52246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2017/06/03/fontaine-a-boissons/"] [unique_id "amuya-_ioCvBERk4wq-SfwAAAX8"], referer: https://carnetdeshopping.com/index.php/2017/06/03/fontaine-a-boissons/
[Thu Jul 30 15:22:03.226325 2026] [core:notice] [pid 147647:tid 147823] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:03.229697 2026] [security2:error] [pid 147647:tid 147823] [client 66.249.79.229:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/2868/1590"] [unique_id "amuya-_ioCvBERk4wq-ShgAAATg"]
[Thu Jul 30 15:22:03.656263 2026] [security2:error] [pid 147647:tid 147875] [client 20.63.98.115:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-config.php"] [unique_id "amuya-_ioCvBERk4wq-SlAAAAWw"]
[Thu Jul 30 15:22:04.512513 2026] [core:notice] [pid 147647:tid 147782] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:05.034697 2026] [security2:error] [pid 147647:tid 147837] [client 20.215.218.234:63525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/bn.php"] [unique_id "amuybe_ioCvBERk4wq-SrQAAAUY"]
[Thu Jul 30 15:22:05.034821 2026] [security2:error] [pid 147647:tid 147837] [client 20.215.218.234:63525] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/bn.php"] [unique_id "amuybe_ioCvBERk4wq-SrQAAAUY"]
[Thu Jul 30 15:22:05.168791 2026] [proxy:error] [pid 147647:tid 147827] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:05.168845 2026] [proxy_http:error] [pid 147647:tid 147827] [client 20.215.191.139:54541] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:05.169521 2026] [proxy:error] [pid 147647:tid 147827] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:05.169568 2026] [proxy_http:error] [pid 147647:tid 147827] [client 20.215.191.139:54541] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:05.226842 2026] [security2:error] [pid 147647:tid 147889] [client 20.63.98.115:42560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-conflg.php"] [unique_id "amuybe_ioCvBERk4wq-SuAAAAXo"]
[Thu Jul 30 15:22:05.504175 2026] [security2:error] [pid 147647:tid 147831] [client 20.215.218.234:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/dm.php"] [unique_id "amuybe_ioCvBERk4wq-SvQAAAUA"]
[Thu Jul 30 15:22:05.504330 2026] [security2:error] [pid 147647:tid 147831] [client 20.215.218.234:60236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/dm.php"] [unique_id "amuybe_ioCvBERk4wq-SvQAAAUA"]
[Thu Jul 30 15:22:05.948374 2026] [security2:error] [pid 147647:tid 147799] [client 20.215.218.234:20796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/gator.php"] [unique_id "amuybe_ioCvBERk4wq-SyAAAASA"]
[Thu Jul 30 15:22:05.948467 2026] [security2:error] [pid 147647:tid 147799] [client 20.215.218.234:20796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/gator.php"] [unique_id "amuybe_ioCvBERk4wq-SyAAAASA"]
[Thu Jul 30 15:22:06.106248 2026] [core:notice] [pid 147647:tid 147878] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:06.111295 2026] [security2:error] [pid 147647:tid 147878] [client 66.249.79.229:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/4895/2301"] [unique_id "amuybu_ioCvBERk4wq-SyQAAAW8"]
[Thu Jul 30 15:22:06.351435 2026] [security2:error] [pid 147647:tid 147841] [client 20.215.218.234:9941] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/___proxy_subdomain_webdisk/perlcgi.pl"] [unique_id "amuybu_ioCvBERk4wq-S1QAAAUo"]
[Thu Jul 30 15:22:06.530643 2026] [security2:error] [pid 147647:tid 147788] [client 20.215.218.234:9941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/mail.php"] [unique_id "amuybu_ioCvBERk4wq-S2QAAARU"]
[Thu Jul 30 15:22:06.530772 2026] [security2:error] [pid 147647:tid 147788] [client 20.215.218.234:9941] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/mail.php"] [unique_id "amuybu_ioCvBERk4wq-S2QAAARU"]
[Thu Jul 30 15:22:06.554063 2026] [core:notice] [pid 147647:tid 147820] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:06.893223 2026] [security2:error] [pid 147647:tid 147827] [client 20.215.218.234:63514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/mailer.php"] [unique_id "amuybu_ioCvBERk4wq-S9gAAATw"]
[Thu Jul 30 15:22:06.893370 2026] [security2:error] [pid 147647:tid 147827] [client 20.215.218.234:63514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/mailer.php"] [unique_id "amuybu_ioCvBERk4wq-S9gAAATw"]
[Thu Jul 30 15:22:07.167036 2026] [security2:error] [pid 147647:tid 147857] [client 20.63.98.115:42605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "amuyb-_ioCvBERk4wq-S-wAAAVo"]
[Thu Jul 30 15:22:07.383181 2026] [security2:error] [pid 147647:tid 147894] [client 20.215.218.234:60235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/___proxy_subdomain_webdisk/php.ini"] [unique_id "amuyb-_ioCvBERk4wq-TBgAAAX8"]
[Thu Jul 30 15:22:07.554310 2026] [security2:error] [pid 147647:tid 147843] [client 20.215.218.234:60235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/modul.php"] [unique_id "amuyb-_ioCvBERk4wq-TCQAAAUw"]
[Thu Jul 30 15:22:07.554451 2026] [security2:error] [pid 147647:tid 147843] [client 20.215.218.234:60235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/modul.php"] [unique_id "amuyb-_ioCvBERk4wq-TCQAAAUw"]
[Thu Jul 30 15:22:07.913014 2026] [security2:error] [pid 147647:tid 147741] [remote 216.73.216.51:50990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuyb-_ioCvBERk4wq-TJQABFV0"]
[Thu Jul 30 15:22:07.931458 2026] [security2:error] [pid 147647:tid 147820] [client 20.215.218.234:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/configuration.php"] [unique_id "amuyb-_ioCvBERk4wq-TJgAAATU"]
[Thu Jul 30 15:22:07.931564 2026] [security2:error] [pid 147647:tid 147820] [client 20.215.218.234:64078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/configuration.php"] [unique_id "amuyb-_ioCvBERk4wq-TJgAAATU"]
[Thu Jul 30 15:22:08.273205 2026] [security2:error] [pid 147647:tid 147850] [client 20.215.218.234:9983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/tai.php"] [unique_id "amuycO_ioCvBERk4wq-TLAAAAVM"]
[Thu Jul 30 15:22:08.273322 2026] [security2:error] [pid 147647:tid 147850] [client 20.215.218.234:9983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/tai.php"] [unique_id "amuycO_ioCvBERk4wq-TLAAAAVM"]
[Thu Jul 30 15:22:08.453107 2026] [core:notice] [pid 147647:tid 147822] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:08.456599 2026] [security2:error] [pid 147647:tid 147822] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/7005"] [unique_id "amuycO_ioCvBERk4wq-TKAAAATc"]
[Thu Jul 30 15:22:08.600923 2026] [security2:error] [pid 147647:tid 147849] [client 20.215.191.139:54505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.northyorksheridanmall.com"] [uri "/hehe.php"] [unique_id "amuycO_ioCvBERk4wq-TNgAAAVI"]
[Thu Jul 30 15:22:08.632653 2026] [security2:error] [pid 147647:tid 147833] [client 20.215.218.234:64089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/www.php"] [unique_id "amuycO_ioCvBERk4wq-TOAAAAUI"]
[Thu Jul 30 15:22:08.632769 2026] [security2:error] [pid 147647:tid 147833] [client 20.215.218.234:64089] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/www.php"] [unique_id "amuycO_ioCvBERk4wq-TOAAAAUI"]
[Thu Jul 30 15:22:08.678087 2026] [core:notice] [pid 147647:tid 147810] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:08.681586 2026] [security2:error] [pid 147647:tid 147810] [client 66.249.79.229:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/article/download/1804/1110"] [unique_id "amuycO_ioCvBERk4wq-TOQAAASs"]
[Thu Jul 30 15:22:08.997926 2026] [security2:error] [pid 147647:tid 147815] [client 20.215.218.234:21751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/x13.php"] [unique_id "amuycO_ioCvBERk4wq-TQwAAATA"]
[Thu Jul 30 15:22:08.998062 2026] [security2:error] [pid 147647:tid 147815] [client 20.215.218.234:21751] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/x13.php"] [unique_id "amuycO_ioCvBERk4wq-TQwAAATA"]
[Thu Jul 30 15:22:09.141335 2026] [core:notice] [pid 147647:tid 147786] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:09.144929 2026] [security2:error] [pid 147647:tid 147786] [client 66.249.79.229:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/download/3009/2110"] [unique_id "amuyce_ioCvBERk4wq-TRAAAARM"]
[Thu Jul 30 15:22:09.242444 2026] [security2:error] [pid 147647:tid 147757] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyce_ioCvBERk4wq-TRwABZW0"]
[Thu Jul 30 15:22:09.242653 2026] [security2:error] [pid 147647:tid 147868] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyce_ioCvBERk4wq-TRwABZW0"]
[Thu Jul 30 15:22:09.366044 2026] [security2:error] [pid 147647:tid 147893] [client 20.215.218.234:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ntaps.php"] [unique_id "amuyce_ioCvBERk4wq-TTAAAAX4"]
[Thu Jul 30 15:22:09.366150 2026] [security2:error] [pid 147647:tid 147893] [client 20.215.218.234:63539] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ntaps.php"] [unique_id "amuyce_ioCvBERk4wq-TTAAAAX4"]
[Thu Jul 30 15:22:09.431614 2026] [security2:error] [pid 147647:tid 147748] [remote 74.7.243.224:43832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/img/rreportf.php"] [unique_id "amuyce_ioCvBERk4wq-TUQABfGQ"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/img/donate.html
[Thu Jul 30 15:22:09.637671 2026] [security2:error] [pid 147647:tid 147856] [client 20.63.98.115:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/customize/chosen.php"] [unique_id "amuyce_ioCvBERk4wq-TVgAAAVk"]
[Thu Jul 30 15:22:09.639612 2026] [core:notice] [pid 147647:tid 147895] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:09.822635 2026] [security2:error] [pid 147647:tid 147829] [client 20.215.218.234:20760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/zip.php"] [unique_id "amuyce_ioCvBERk4wq-TXAAAAT4"]
[Thu Jul 30 15:22:09.822760 2026] [security2:error] [pid 147647:tid 147829] [client 20.215.218.234:20760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/zip.php"] [unique_id "amuyce_ioCvBERk4wq-TXAAAAT4"]
[Thu Jul 30 15:22:10.137719 2026] [core:notice] [pid 147647:tid 147804] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:10.367267 2026] [security2:error] [pid 147647:tid 147821] [client 20.215.218.234:9978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/@.php"] [unique_id "amuycu_ioCvBERk4wq-TawAAATY"]
[Thu Jul 30 15:22:10.367356 2026] [security2:error] [pid 147647:tid 147821] [client 20.215.218.234:9978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/@.php"] [unique_id "amuycu_ioCvBERk4wq-TawAAATY"]
[Thu Jul 30 15:22:10.607782 2026] [security2:error] [pid 147647:tid 147817] [client 20.203.148.31:42863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amuycu_ioCvBERk4wq-TbwAAATI"]
[Thu Jul 30 15:22:10.762164 2026] [core:notice] [pid 147647:tid 147781] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:10.765567 2026] [security2:error] [pid 147647:tid 147781] [client 66.249.79.229:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/RILL/article/view/1302"] [unique_id "amuycu_ioCvBERk4wq-TcAAAAQ4"]
[Thu Jul 30 15:22:10.770310 2026] [security2:error] [pid 147647:tid 147844] [client 20.215.218.234:20782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ea.php"] [unique_id "amuycu_ioCvBERk4wq-TcQAAAU0"]
[Thu Jul 30 15:22:10.770397 2026] [security2:error] [pid 147647:tid 147844] [client 20.215.218.234:20782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ea.php"] [unique_id "amuycu_ioCvBERk4wq-TcQAAAU0"]
[Thu Jul 30 15:22:11.103800 2026] [security2:error] [pid 147647:tid 147833] [client 20.215.218.234:9922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/aaaa.php"] [unique_id "amuyc-_ioCvBERk4wq-TewAAAUI"]
[Thu Jul 30 15:22:11.103909 2026] [security2:error] [pid 147647:tid 147833] [client 20.215.218.234:9922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/aaaa.php"] [unique_id "amuyc-_ioCvBERk4wq-TewAAAUI"]
[Thu Jul 30 15:22:11.213482 2026] [core:notice] [pid 147647:tid 147810] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:11.538907 2026] [security2:error] [pid 147647:tid 147815] [client 20.215.218.234:20776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/cinfo.php"] [unique_id "amuyc-_ioCvBERk4wq-ThgAAATA"]
[Thu Jul 30 15:22:11.539011 2026] [security2:error] [pid 147647:tid 147815] [client 20.215.218.234:20776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/cinfo.php"] [unique_id "amuyc-_ioCvBERk4wq-ThgAAATA"]
[Thu Jul 30 15:22:11.832474 2026] [security2:error] [pid 147647:tid 147788] [client 20.63.98.115:48489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "amuyc-_ioCvBERk4wq-TiAAAARU"]
[Thu Jul 30 15:22:11.864581 2026] [security2:error] [pid 147647:tid 147849] [client 20.203.148.31:35500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amuyc-_ioCvBERk4wq-TiwAAAVI"]
[Thu Jul 30 15:22:11.951435 2026] [security2:error] [pid 147647:tid 147900] [client 20.215.218.234:63533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/newfile.php"] [unique_id "amuyc-_ioCvBERk4wq-TkQAAAYU"]
[Thu Jul 30 15:22:11.951549 2026] [security2:error] [pid 147647:tid 147900] [client 20.215.218.234:63533] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/newfile.php"] [unique_id "amuyc-_ioCvBERk4wq-TkQAAAYU"]
[Thu Jul 30 15:22:12.082471 2026] [core:notice] [pid 147647:tid 147765] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:12.358830 2026] [security2:error] [pid 147647:tid 147895] [client 20.215.218.234:20749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/pro.php"] [unique_id "amuydO_ioCvBERk4wq-TmgAAAYA"]
[Thu Jul 30 15:22:12.358919 2026] [security2:error] [pid 147647:tid 147895] [client 20.215.218.234:20749] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/pro.php"] [unique_id "amuydO_ioCvBERk4wq-TmgAAAYA"]
[Thu Jul 30 15:22:12.364241 2026] [security2:error] [pid 147647:tid 147869] [client 20.203.148.31:35462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amuydO_ioCvBERk4wq-TmwAAAWY"]
[Thu Jul 30 15:22:12.416263 2026] [core:notice] [pid 147647:tid 147903] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:12.714469 2026] [security2:error] [pid 147647:tid 147858] [client 20.215.218.234:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/edit.php"] [unique_id "amuydO_ioCvBERk4wq-TqAAAAVs"]
[Thu Jul 30 15:22:12.714580 2026] [security2:error] [pid 147647:tid 147858] [client 20.215.218.234:60228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/edit.php"] [unique_id "amuydO_ioCvBERk4wq-TqAAAAVs"]
[Thu Jul 30 15:22:12.893368 2026] [core:notice] [pid 147647:tid 147839] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:12.941149 2026] [security2:error] [pid 147647:tid 147898] [client 20.203.148.31:30308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/amaxx.php"] [unique_id "amuydO_ioCvBERk4wq-TsQAAAYM"]
[Thu Jul 30 15:22:13.125781 2026] [security2:error] [pid 147647:tid 147778] [client 20.63.98.115:32108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "amuyde_ioCvBERk4wq-TuAAAAQs"]
[Thu Jul 30 15:22:13.183526 2026] [security2:error] [pid 147647:tid 147828] [client 20.215.218.234:9975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/11.php"] [unique_id "amuyde_ioCvBERk4wq-TuQAAAT0"]
[Thu Jul 30 15:22:13.183638 2026] [security2:error] [pid 147647:tid 147828] [client 20.215.218.234:9975] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/11.php"] [unique_id "amuyde_ioCvBERk4wq-TuQAAAT0"]
[Thu Jul 30 15:22:13.334794 2026] [proxy:error] [pid 147647:tid 147830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:13.334894 2026] [proxy_http:error] [pid 147647:tid 147830] [client 52.4.19.39:33661] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:13.335802 2026] [proxy:error] [pid 147647:tid 147830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:13.335877 2026] [proxy_http:error] [pid 147647:tid 147830] [client 52.4.19.39:33661] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:13.547812 2026] [security2:error] [pid 147647:tid 147846] [client 20.215.218.234:20779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/title.php"] [unique_id "amuyde_ioCvBERk4wq-TwwAAAU8"]
[Thu Jul 30 15:22:13.547913 2026] [security2:error] [pid 147647:tid 147846] [client 20.215.218.234:20779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/title.php"] [unique_id "amuyde_ioCvBERk4wq-TwwAAAU8"]
[Thu Jul 30 15:22:13.702783 2026] [security2:error] [pid 147647:tid 147837] [client 20.203.148.31:42832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/bek.php"] [unique_id "amuyde_ioCvBERk4wq-TzQAAAUY"]
[Thu Jul 30 15:22:13.889211 2026] [core:notice] [pid 147647:tid 147810] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:14.102433 2026] [core:notice] [pid 147647:tid 147825] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:14.103054 2026] [security2:error] [pid 147647:tid 147878] [client 213.152.186.19:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuydu_ioCvBERk4wq-T4AAAAW8"]
[Thu Jul 30 15:22:14.103152 2026] [security2:error] [pid 147647:tid 147878] [client 213.152.186.19:50216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuydu_ioCvBERk4wq-T4AAAAW8"]
[Thu Jul 30 15:22:14.106125 2026] [security2:error] [pid 147647:tid 147825] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/download/9132/3953"] [unique_id "amuydu_ioCvBERk4wq-T3wAAATo"]
[Thu Jul 30 15:22:14.144865 2026] [security2:error] [pid 147647:tid 147876] [client 20.215.218.234:21229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuyde_ioCvBERk4wq-TzgAAAW0"]
[Thu Jul 30 15:22:14.144960 2026] [security2:error] [pid 147647:tid 147876] [client 20.215.218.234:21229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuyde_ioCvBERk4wq-TzgAAAW0"]
[Thu Jul 30 15:22:14.552064 2026] [core:notice] [pid 147647:tid 147841] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:14.638113 2026] [security2:error] [pid 147647:tid 147901] [client 20.215.218.234:60283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/pass.php"] [unique_id "amuydu_ioCvBERk4wq-T7AAAAYY"]
[Thu Jul 30 15:22:14.638228 2026] [security2:error] [pid 147647:tid 147901] [client 20.215.218.234:60283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/pass.php"] [unique_id "amuydu_ioCvBERk4wq-T7AAAAYY"]
[Thu Jul 30 15:22:14.700001 2026] [security2:error] [pid 147647:tid 147873] [client 20.63.98.115:32727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/manager.php"] [unique_id "amuydu_ioCvBERk4wq-T8AAAAWo"]
[Thu Jul 30 15:22:15.052918 2026] [core:notice] [pid 147647:tid 147874] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:15.154410 2026] [security2:error] [pid 147647:tid 147904] [client 20.215.218.234:21713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/Cpanel.php"] [unique_id "amuyd-_ioCvBERk4wq-T_AAAAYk"]
[Thu Jul 30 15:22:15.154546 2026] [security2:error] [pid 147647:tid 147904] [client 20.215.218.234:21713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/Cpanel.php"] [unique_id "amuyd-_ioCvBERk4wq-T_AAAAYk"]
[Thu Jul 30 15:22:15.435198 2026] [security2:error] [pid 147647:tid 147785] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuydu_ioCvBERk4wq-T8QABEnw"]
[Thu Jul 30 15:22:15.496168 2026] [security2:error] [pid 147647:tid 147816] [client 20.215.218.234:21746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/unknown.php"] [unique_id "amuyd-_ioCvBERk4wq-UCwAAATE"]
[Thu Jul 30 15:22:15.496291 2026] [security2:error] [pid 147647:tid 147816] [client 20.215.218.234:21746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/unknown.php"] [unique_id "amuyd-_ioCvBERk4wq-UCwAAATE"]
[Thu Jul 30 15:22:15.550612 2026] [core:notice] [pid 147647:tid 147835] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:15.910925 2026] [security2:error] [pid 147647:tid 147878] [client 20.215.218.234:21215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/sel.php"] [unique_id "amuyd-_ioCvBERk4wq-UGAAAAW8"]
[Thu Jul 30 15:22:15.911054 2026] [security2:error] [pid 147647:tid 147878] [client 20.215.218.234:21215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/sel.php"] [unique_id "amuyd-_ioCvBERk4wq-UGAAAAW8"]
[Thu Jul 30 15:22:16.078117 2026] [security2:error] [pid 147647:tid 147842] [client 20.203.148.31:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amuyeO_ioCvBERk4wq-UHgAAAUs"]
[Thu Jul 30 15:22:16.193850 2026] [security2:error] [pid 147647:tid 147818] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyd-_ioCvBERk4wq-UDgAAATM"]
[Thu Jul 30 15:22:16.333252 2026] [security2:error] [pid 147647:tid 147673] [remote 195.178.110.223:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bestdogproductguide.com"] [uri "/.env"] [unique_id "amuyeO_ioCvBERk4wq-UJgABIhk"]
[Thu Jul 30 15:22:16.369535 2026] [security2:error] [pid 147647:tid 147881] [client 20.215.218.234:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/14.php"] [unique_id "amuyeO_ioCvBERk4wq-UJwAAAXI"]
[Thu Jul 30 15:22:16.369693 2026] [security2:error] [pid 147647:tid 147881] [client 20.215.218.234:60242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/14.php"] [unique_id "amuyeO_ioCvBERk4wq-UJwAAAXI"]
[Thu Jul 30 15:22:16.482265 2026] [core:notice] [pid 147647:tid 147793] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:16.485806 2026] [security2:error] [pid 147647:tid 147793] [client 66.249.79.229:62195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/361"] [unique_id "amuyeO_ioCvBERk4wq-UKQAAARo"]
[Thu Jul 30 15:22:16.508593 2026] [security2:error] [pid 147647:tid 147671] [remote 195.178.110.223:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bestdogproductguide.com"] [uri "/.env.bak"] [unique_id "amuyeO_ioCvBERk4wq-ULQABSBc"]
[Thu Jul 30 15:22:16.709958 2026] [core:notice] [pid 147647:tid 147844] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:16.713578 2026] [security2:error] [pid 147647:tid 147844] [client 66.249.79.229:62195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Caruban/article/view/3563/2257"] [unique_id "amuyeO_ioCvBERk4wq-UOQAAAU0"]
[Thu Jul 30 15:22:16.750844 2026] [security2:error] [pid 147647:tid 147885] [client 20.203.148.31:28431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/class.api.php"] [unique_id "amuyeO_ioCvBERk4wq-UOgAAAXY"]
[Thu Jul 30 15:22:17.045027 2026] [security2:error] [pid 147647:tid 147677] [remote 195.178.110.223:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bestdogproductguide.com"] [uri "/.env.backup"] [unique_id "amuyee_ioCvBERk4wq-UPwABiR0"]
[Thu Jul 30 15:22:17.055076 2026] [security2:error] [pid 147647:tid 147832] [client 20.215.218.234:21217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/about.php"] [unique_id "amuyee_ioCvBERk4wq-UQgAAAUE"]
[Thu Jul 30 15:22:17.055216 2026] [security2:error] [pid 147647:tid 147832] [client 20.215.218.234:21217] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/about.php"] [unique_id "amuyee_ioCvBERk4wq-UQgAAAUE"]
[Thu Jul 30 15:22:17.159031 2026] [core:notice] [pid 147647:tid 147867] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:17.219240 2026] [security2:error] [pid 147647:tid 147680] [remote 195.178.110.223:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bestdogproductguide.com"] [uri "/backend/.env"] [unique_id "amuyee_ioCvBERk4wq-USAABQiA"]
[Thu Jul 30 15:22:17.267507 2026] [security2:error] [pid 147647:tid 147827] [client 20.63.98.115:42612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-links.php"] [unique_id "amuyee_ioCvBERk4wq-USgAAATw"]
[Thu Jul 30 15:22:17.451045 2026] [security2:error] [pid 147647:tid 147837] [client 20.215.218.234:63535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/angel.php"] [unique_id "amuyee_ioCvBERk4wq-UUAAAAUY"]
[Thu Jul 30 15:22:17.451249 2026] [security2:error] [pid 147647:tid 147837] [client 20.215.218.234:63535] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/angel.php"] [unique_id "amuyee_ioCvBERk4wq-UUAAAAUY"]
[Thu Jul 30 15:22:17.477126 2026] [core:notice] [pid 147647:tid 147889] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:17.491654 2026] [security2:error] [pid 147647:tid 147866] [client 20.203.148.31:42834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/cong.php"] [unique_id "amuyee_ioCvBERk4wq-UUgAAAWM"]
[Thu Jul 30 15:22:17.661169 2026] [core:notice] [pid 147647:tid 147825] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:17.947860 2026] [security2:error] [pid 147647:tid 147818] [client 20.215.218.234:64076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/c100.php"] [unique_id "amuyee_ioCvBERk4wq-UZAAAATM"]
[Thu Jul 30 15:22:17.947995 2026] [security2:error] [pid 147647:tid 147818] [client 20.215.218.234:64076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/c100.php"] [unique_id "amuyee_ioCvBERk4wq-UZAAAATM"]
[Thu Jul 30 15:22:18.157369 2026] [core:notice] [pid 147647:tid 147798] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:18.160725 2026] [security2:error] [pid 147647:tid 147798] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/4905"] [unique_id "amuyeu_ioCvBERk4wq-UaQAAAR8"]
[Thu Jul 30 15:22:18.315709 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:20754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/simattacker.php"] [unique_id "amuyeu_ioCvBERk4wq-UbwAAAV4"]
[Thu Jul 30 15:22:18.315804 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:20754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/simattacker.php"] [unique_id "amuyeu_ioCvBERk4wq-UbwAAAV4"]
[Thu Jul 30 15:22:18.402334 2026] [security2:error] [pid 147647:tid 147814] [client 134.19.179.195:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuyeu_ioCvBERk4wq-UcwAAAS8"]
[Thu Jul 30 15:22:18.402470 2026] [security2:error] [pid 147647:tid 147814] [client 134.19.179.195:55184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuyeu_ioCvBERk4wq-UcwAAAS8"]
[Thu Jul 30 15:22:18.655243 2026] [core:notice] [pid 147647:tid 147796] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:18.760451 2026] [security2:error] [pid 147647:tid 147874] [client 20.215.218.234:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wsoshell.php"] [unique_id "amuyeu_ioCvBERk4wq-UfwAAAWs"]
[Thu Jul 30 15:22:18.760574 2026] [security2:error] [pid 147647:tid 147874] [client 20.215.218.234:63491] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wsoshell.php"] [unique_id "amuyeu_ioCvBERk4wq-UfwAAAWs"]
[Thu Jul 30 15:22:19.027141 2026] [security2:error] [pid 147647:tid 147890] [client 20.63.98.115:52099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/fi2.php"] [unique_id "amuye-_ioCvBERk4wq-UhwAAAXs"]
[Thu Jul 30 15:22:19.155268 2026] [core:notice] [pid 147647:tid 147816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:19.163053 2026] [security2:error] [pid 147647:tid 147835] [client 20.215.218.234:21206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/autoload_classmap.php"] [unique_id "amuye-_ioCvBERk4wq-UiwAAAUQ"]
[Thu Jul 30 15:22:19.163139 2026] [security2:error] [pid 147647:tid 147835] [client 20.215.218.234:21206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/autoload_classmap.php"] [unique_id "amuye-_ioCvBERk4wq-UiwAAAUQ"]
[Thu Jul 30 15:22:19.623008 2026] [security2:error] [pid 147647:tid 147848] [client 20.215.218.234:21237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/12.php"] [unique_id "amuye-_ioCvBERk4wq-UmgAAAVE"]
[Thu Jul 30 15:22:19.623159 2026] [security2:error] [pid 147647:tid 147848] [client 20.215.218.234:21237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/12.php"] [unique_id "amuye-_ioCvBERk4wq-UmgAAAVE"]
[Thu Jul 30 15:22:19.961880 2026] [security2:error] [pid 147647:tid 147728] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuye-_ioCvBERk4wq-UswABR1A"]
[Thu Jul 30 15:22:19.962051 2026] [security2:error] [pid 147647:tid 147838] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuye-_ioCvBERk4wq-UswABR1A"]
[Thu Jul 30 15:22:20.013527 2026] [security2:error] [pid 147647:tid 147898] [client 20.215.218.234:20764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wikiindex.php"] [unique_id "amuyfO_ioCvBERk4wq-UtwAAAYM"]
[Thu Jul 30 15:22:20.013617 2026] [security2:error] [pid 147647:tid 147898] [client 20.215.218.234:20764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wikiindex.php"] [unique_id "amuyfO_ioCvBERk4wq-UtwAAAYM"]
[Thu Jul 30 15:22:20.104412 2026] [core:notice] [pid 147647:tid 147884] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:20.124571 2026] [core:notice] [pid 147647:tid 147792] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:20.237569 2026] [security2:error] [pid 147647:tid 147813] [client 20.203.148.31:30051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/content.php"] [unique_id "amuyfO_ioCvBERk4wq-UvwAAAS4"]
[Thu Jul 30 15:22:20.399689 2026] [security2:error] [pid 147647:tid 147778] [client 20.215.218.234:63532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alex.php"] [unique_id "amuyfO_ioCvBERk4wq-UxAAAAQs"]
[Thu Jul 30 15:22:20.399811 2026] [security2:error] [pid 147647:tid 147778] [client 20.215.218.234:63532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alex.php"] [unique_id "amuyfO_ioCvBERk4wq-UxAAAAQs"]
[Thu Jul 30 15:22:20.688478 2026] [security2:error] [pid 147647:tid 147732] [remote 195.178.110.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdogproductguide.com"] [uri "/phpinfo.php"] [unique_id "amuyfO_ioCvBERk4wq-UxQABgVQ"]
[Thu Jul 30 15:22:20.759787 2026] [security2:error] [pid 147647:tid 147868] [client 20.215.218.234:20759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-0.php"] [unique_id "amuyfO_ioCvBERk4wq-UzQAAAWU"]
[Thu Jul 30 15:22:20.759883 2026] [security2:error] [pid 147647:tid 147868] [client 20.215.218.234:20759] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-0.php"] [unique_id "amuyfO_ioCvBERk4wq-UzQAAAWU"]
[Thu Jul 30 15:22:20.864742 2026] [security2:error] [pid 147647:tid 147735] [remote 195.178.110.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdogproductguide.com"] [uri "/info.php"] [unique_id "amuyfO_ioCvBERk4wq-U0gABGFc"]
[Thu Jul 30 15:22:21.035927 2026] [security2:error] [pid 147647:tid 147743] [remote 195.178.110.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdogproductguide.com"] [uri "/test.php"] [unique_id "amuyfe_ioCvBERk4wq-U6wABFV8"]
[Thu Jul 30 15:22:21.195794 2026] [security2:error] [pid 147647:tid 147793] [client 20.215.218.234:21758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-1.php"] [unique_id "amuyfe_ioCvBERk4wq-U7AAAARo"]
[Thu Jul 30 15:22:21.195919 2026] [security2:error] [pid 147647:tid 147793] [client 20.215.218.234:21758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-1.php"] [unique_id "amuyfe_ioCvBERk4wq-U7AAAARo"]
[Thu Jul 30 15:22:21.576184 2026] [security2:error] [pid 147647:tid 147778] [client 20.215.218.234:20781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/xindex.php"] [unique_id "amuyfe_ioCvBERk4wq-VCQAAAQs"]
[Thu Jul 30 15:22:21.576286 2026] [security2:error] [pid 147647:tid 147778] [client 20.215.218.234:20781] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/xindex.php"] [unique_id "amuyfe_ioCvBERk4wq-VCQAAAQs"]
[Thu Jul 30 15:22:21.798517 2026] [core:notice] [pid 147647:tid 147904] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:22.024302 2026] [security2:error] [pid 147647:tid 147740] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/jquery/bypass.php"] [unique_id "amuyfu_ioCvBERk4wq-VGAABI1w"]
[Thu Jul 30 15:22:22.080846 2026] [security2:error] [pid 147647:tid 147827] [client 20.215.218.234:9960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wiki-index.php"] [unique_id "amuyfu_ioCvBERk4wq-VHAAAATw"]
[Thu Jul 30 15:22:22.080945 2026] [security2:error] [pid 147647:tid 147827] [client 20.215.218.234:9960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wiki-index.php"] [unique_id "amuyfu_ioCvBERk4wq-VHAAAATw"]
[Thu Jul 30 15:22:22.288541 2026] [security2:error] [pid 147647:tid 147657] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/jquery/jquery.php"] [unique_id "amuyfu_ioCvBERk4wq-VHwABEgk"]
[Thu Jul 30 15:22:22.563586 2026] [security2:error] [pid 147647:tid 147881] [client 20.215.218.234:60257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/Bulle.php"] [unique_id "amuyfu_ioCvBERk4wq-VOAAAAXI"]
[Thu Jul 30 15:22:22.563725 2026] [security2:error] [pid 147647:tid 147881] [client 20.215.218.234:60257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/Bulle.php"] [unique_id "amuyfu_ioCvBERk4wq-VOAAAAXI"]
[Thu Jul 30 15:22:22.688373 2026] [core:notice] [pid 147647:tid 147872] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:22.691991 2026] [security2:error] [pid 147647:tid 147872] [client 66.249.79.229:60271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/article/view/1818"] [unique_id "amuyfu_ioCvBERk4wq-VOwAAAWk"]
[Thu Jul 30 15:22:22.708226 2026] [security2:error] [pid 147647:tid 147816] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyfu_ioCvBERk4wq-VGwABMXk"]
[Thu Jul 30 15:22:22.910563 2026] [security2:error] [pid 147647:tid 147836] [client 20.203.148.31:11832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amuyfu_ioCvBERk4wq-VRAAAAUU"]
[Thu Jul 30 15:22:22.915268 2026] [core:notice] [pid 147647:tid 147852] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:22.918838 2026] [security2:error] [pid 147647:tid 147852] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/8267/3214"] [unique_id "amuyfu_ioCvBERk4wq-VRQAAAVU"]
[Thu Jul 30 15:22:22.938096 2026] [security2:error] [pid 147647:tid 147792] [client 20.215.218.234:64092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/srx.php"] [unique_id "amuyfu_ioCvBERk4wq-VRgAAARk"]
[Thu Jul 30 15:22:22.938242 2026] [security2:error] [pid 147647:tid 147792] [client 20.215.218.234:64092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/srx.php"] [unique_id "amuyfu_ioCvBERk4wq-VRgAAARk"]
[Thu Jul 30 15:22:23.051654 2026] [security2:error] [pid 147647:tid 147669] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/jquery/suggest.php"] [unique_id "amuyf-_ioCvBERk4wq-VSwABXBU"]
[Thu Jul 30 15:22:23.308687 2026] [security2:error] [pid 147647:tid 147682] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/js.php"] [unique_id "amuyf-_ioCvBERk4wq-VUgABTSI"]
[Thu Jul 30 15:22:23.420012 2026] [security2:error] [pid 147647:tid 147898] [client 20.215.218.234:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/plugins/owfsmac/mar.php"] [unique_id "amuyf-_ioCvBERk4wq-VVgAAAYM"]
[Thu Jul 30 15:22:23.420156 2026] [security2:error] [pid 147647:tid 147898] [client 20.215.218.234:63516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/plugins/owfsmac/mar.php"] [unique_id "amuyf-_ioCvBERk4wq-VVgAAAYM"]
[Thu Jul 30 15:22:23.563730 2026] [core:notice] [pid 147647:tid 147787] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:23.580236 2026] [security2:error] [pid 147647:tid 147688] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/js1.php"] [unique_id "amuyf-_ioCvBERk4wq-VXQABIyg"]
[Thu Jul 30 15:22:23.835195 2026] [core:notice] [pid 147647:tid 147857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:23.843475 2026] [security2:error] [pid 147647:tid 147663] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/js_editor.php"] [unique_id "amuyf-_ioCvBERk4wq-VYgABDQ8"]
[Thu Jul 30 15:22:23.852016 2026] [security2:error] [pid 147647:tid 147834] [client 20.215.218.234:20788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/tersembunyi.php"] [unique_id "amuyf-_ioCvBERk4wq-VYwAAAUM"]
[Thu Jul 30 15:22:23.852124 2026] [security2:error] [pid 147647:tid 147834] [client 20.215.218.234:20788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/tersembunyi.php"] [unique_id "amuyf-_ioCvBERk4wq-VYwAAAUM"]
[Thu Jul 30 15:22:24.064062 2026] [core:notice] [pid 147647:tid 147800] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:24.105447 2026] [security2:error] [pid 147647:tid 147770] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/json.php"] [unique_id "amuygO_ioCvBERk4wq-VawABM3o"]
[Thu Jul 30 15:22:24.131304 2026] [security2:error] [pid 147647:tid 147785] [client 20.203.148.31:28370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/elp.php"] [unique_id "amuygO_ioCvBERk4wq-VcAAAARI"]
[Thu Jul 30 15:22:24.193483 2026] [security2:error] [pid 147647:tid 147793] [client 20.215.218.234:20799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/lab.php"] [unique_id "amuygO_ioCvBERk4wq-VdAAAARo"]
[Thu Jul 30 15:22:24.193640 2026] [security2:error] [pid 147647:tid 147793] [client 20.215.218.234:20799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/lab.php"] [unique_id "amuygO_ioCvBERk4wq-VdAAAARo"]
[Thu Jul 30 15:22:24.363938 2026] [security2:error] [pid 147647:tid 147660] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/jsstrings.php"] [unique_id "amuygO_ioCvBERk4wq-VdgABYQw"]
[Thu Jul 30 15:22:24.512034 2026] [core:notice] [pid 147647:tid 147839] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:24.586054 2026] [security2:error] [pid 147647:tid 147777] [client 20.215.218.234:60271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/___proxy_subdomain_webdisk/1.aspx"] [unique_id "amuygO_ioCvBERk4wq-VewAAAQo"]
[Thu Jul 30 15:22:24.619199 2026] [security2:error] [pid 147647:tid 147651] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/just2.php"] [unique_id "amuygO_ioCvBERk4wq-VfgABWAM"]
[Thu Jul 30 15:22:24.749840 2026] [security2:error] [pid 147647:tid 147840] [client 20.215.218.234:60271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/___proxy_subdomain_webdisk/shell.aspx"] [unique_id "amuygO_ioCvBERk4wq-VgwAAAUk"]
[Thu Jul 30 15:22:24.754998 2026] [security2:error] [pid 147647:tid 147848] [client 20.63.98.115:32250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/0x.php"] [unique_id "amuygO_ioCvBERk4wq-VhAAAAVE"]
[Thu Jul 30 15:22:24.803443 2026] [proxy:error] [pid 147647:tid 147686] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:24.803496 2026] [proxy_http:error] [pid 147647:tid 147686] [remote 74.7.230.12:47334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:24.804061 2026] [proxy:error] [pid 147647:tid 147686] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:24.804105 2026] [proxy_http:error] [pid 147647:tid 147686] [remote 74.7.230.12:47334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:24.877704 2026] [security2:error] [pid 147647:tid 147680] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/k.php"] [unique_id "amuygO_ioCvBERk4wq-VhgABHyA"]
[Thu Jul 30 15:22:24.922559 2026] [security2:error] [pid 147647:tid 147850] [client 20.215.218.234:60271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/___proxy_subdomain_webdisk/a.aspx"] [unique_id "amuygO_ioCvBERk4wq-VhwAAAVM"]
[Thu Jul 30 15:22:25.008519 2026] [core:notice] [pid 147647:tid 147870] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:25.012050 2026] [security2:error] [pid 147647:tid 147870] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/download/3723/1986"] [unique_id "amuyge_ioCvBERk4wq-VjgAAAWc"]
[Thu Jul 30 15:22:25.069600 2026] [security2:error] [pid 147647:tid 147809] [client 20.215.218.234:60271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-raze.php"] [unique_id "amuyge_ioCvBERk4wq-VjwAAASo"]
[Thu Jul 30 15:22:25.069740 2026] [security2:error] [pid 147647:tid 147809] [client 20.215.218.234:60271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-raze.php"] [unique_id "amuyge_ioCvBERk4wq-VjwAAASo"]
[Thu Jul 30 15:22:25.156538 2026] [security2:error] [pid 147647:tid 147675] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/k7.php"] [unique_id "amuyge_ioCvBERk4wq-VkwABTRs"]
[Thu Jul 30 15:22:25.325796 2026] [core:notice] [pid 147647:tid 147886] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:25.417316 2026] [security2:error] [pid 147647:tid 147668] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/kadence/functions.php"] [unique_id "amuyge_ioCvBERk4wq-VmwABRBQ"]
[Thu Jul 30 15:22:25.461748 2026] [security2:error] [pid 147647:tid 147847] [client 20.215.218.234:60239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-init.php"] [unique_id "amuyge_ioCvBERk4wq-VngAAAVA"]
[Thu Jul 30 15:22:25.461846 2026] [security2:error] [pid 147647:tid 147847] [client 20.215.218.234:60239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-init.php"] [unique_id "amuyge_ioCvBERk4wq-VngAAAVA"]
[Thu Jul 30 15:22:25.505905 2026] [core:notice] [pid 147647:tid 147887] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:25.509404 2026] [security2:error] [pid 147647:tid 147887] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/download/4846/2262"] [unique_id "amuyge_ioCvBERk4wq-VoAAAAXg"]
[Thu Jul 30 15:22:25.663467 2026] [security2:error] [pid 147647:tid 147833] [client 143.244.57.86:60102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ahk.tqa.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuyge_ioCvBERk4wq-VpAAAAUI"]
[Thu Jul 30 15:22:25.676525 2026] [security2:error] [pid 147647:tid 147733] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/kal.php"] [unique_id "amuyge_ioCvBERk4wq-VpQABMlU"]
[Thu Jul 30 15:22:25.792529 2026] [core:notice] [pid 147647:tid 147784] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:25.862618 2026] [security2:error] [pid 147647:tid 147893] [client 20.215.218.234:21696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/lyda.php"] [unique_id "amuyge_ioCvBERk4wq-VqgAAAX4"]
[Thu Jul 30 15:22:25.862707 2026] [security2:error] [pid 147647:tid 147893] [client 20.215.218.234:21696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/lyda.php"] [unique_id "amuyge_ioCvBERk4wq-VqgAAAX4"]
[Thu Jul 30 15:22:25.862900 2026] [security2:error] [pid 147647:tid 147829] [client 23.248.167.51:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "markmocek.com"] [uri "/wp-login.php"] [unique_id "amuyge_ioCvBERk4wq-VmQAAAT4"]
[Thu Jul 30 15:22:25.931178 2026] [security2:error] [pid 147647:tid 147670] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/karak.php"] [unique_id "amuyge_ioCvBERk4wq-VrAABeRY"]
[Thu Jul 30 15:22:26.004172 2026] [core:notice] [pid 147647:tid 147854] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:26.006224 2026] [security2:error] [pid 147647:tid 147831] [client 143.244.57.86:60112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahk.tqa.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuyge_ioCvBERk4wq-VsAAAAUA"]
[Thu Jul 30 15:22:26.010112 2026] [security2:error] [pid 147647:tid 147854] [client 66.249.79.229:60271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/8728"] [unique_id "amuygu_ioCvBERk4wq-VsQAAAVc"]
[Thu Jul 30 15:22:26.191812 2026] [security2:error] [pid 147647:tid 147692] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/kepo.php"] [unique_id "amuygu_ioCvBERk4wq-VtgABCiw"]
[Thu Jul 30 15:22:26.255524 2026] [security2:error] [pid 147647:tid 147900] [client 20.63.98.115:32710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/k.php"] [unique_id "amuygu_ioCvBERk4wq-VtwAAAYU"]
[Thu Jul 30 15:22:26.268015 2026] [security2:error] [pid 147647:tid 147879] [client 20.203.148.31:35467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amuygu_ioCvBERk4wq-VuAAAAXA"]
[Thu Jul 30 15:22:26.398276 2026] [security2:error] [pid 147647:tid 147807] [client 20.215.218.234:20792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfashell.php"] [unique_id "amuygu_ioCvBERk4wq-VwAAAASg"]
[Thu Jul 30 15:22:26.398411 2026] [security2:error] [pid 147647:tid 147807] [client 20.215.218.234:20792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfashell.php"] [unique_id "amuygu_ioCvBERk4wq-VwAAAASg"]
[Thu Jul 30 15:22:26.454104 2026] [security2:error] [pid 147647:tid 147672] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/kk.php"] [unique_id "amuygu_ioCvBERk4wq-VxAABXBg"]
[Thu Jul 30 15:22:26.499196 2026] [core:notice] [pid 147647:tid 147788] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:26.711338 2026] [security2:error] [pid 147647:tid 147683] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/klarnaAjax.php"] [unique_id "amuygu_ioCvBERk4wq-VzQABTSM"]
[Thu Jul 30 15:22:26.826822 2026] [security2:error] [pid 147647:tid 147799] [client 20.215.218.234:21723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/av.php"] [unique_id "amuygu_ioCvBERk4wq-V1QAAASA"]
[Thu Jul 30 15:22:26.826951 2026] [security2:error] [pid 147647:tid 147799] [client 20.215.218.234:21723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/av.php"] [unique_id "amuygu_ioCvBERk4wq-V1QAAASA"]
[Thu Jul 30 15:22:26.970850 2026] [security2:error] [pid 147647:tid 147713] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/kn18l3.php"] [unique_id "amuygu_ioCvBERk4wq-V1gABTkE"]
[Thu Jul 30 15:22:27.068049 2026] [core:notice] [pid 147647:tid 147815] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:27.232831 2026] [security2:error] [pid 147647:tid 147720] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/kndw1.php"] [unique_id "amuyg-_ioCvBERk4wq-V4AABFkg"]
[Thu Jul 30 15:22:27.299827 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:64069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/upl.php"] [unique_id "amuyg-_ioCvBERk4wq-V4gAAAV4"]
[Thu Jul 30 15:22:27.299958 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:64069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/upl.php"] [unique_id "amuyg-_ioCvBERk4wq-V4gAAAV4"]
[Thu Jul 30 15:22:27.360838 2026] [security2:error] [pid 147647:tid 147802] [client 20.63.98.115:25797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/gecko-new.php"] [unique_id "amuyg-_ioCvBERk4wq-V5wAAASM"]
[Thu Jul 30 15:22:27.491144 2026] [security2:error] [pid 147647:tid 147710] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/krypton.php"] [unique_id "amuyg-_ioCvBERk4wq-V6AABbT4"]
[Thu Jul 30 15:22:27.658866 2026] [core:notice] [pid 147647:tid 147784] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:27.750396 2026] [security2:error] [pid 147647:tid 147724] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/krysis.php"] [unique_id "amuyg-_ioCvBERk4wq-V9QABCkw"]
[Thu Jul 30 15:22:27.780280 2026] [security2:error] [pid 147647:tid 147855] [client 20.215.218.234:63521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/___proxy_subdomain_webdisk/login.phtml"] [unique_id "amuyg-_ioCvBERk4wq-V9gAAAVg"]
[Thu Jul 30 15:22:27.833458 2026] [security2:error] [pid 147647:tid 147689] [remote 103.57.220.209:46818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.57.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuyg-_ioCvBERk4wq-V-AABeyk"]
[Thu Jul 30 15:22:27.929752 2026] [security2:error] [pid 147647:tid 147846] [client 20.215.218.234:63521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/gelay.php"] [unique_id "amuyg-_ioCvBERk4wq-V_AAAAU8"]
[Thu Jul 30 15:22:27.929892 2026] [security2:error] [pid 147647:tid 147846] [client 20.215.218.234:63521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/gelay.php"] [unique_id "amuyg-_ioCvBERk4wq-V_AAAAU8"]
[Thu Jul 30 15:22:27.939837 2026] [security2:error] [pid 147647:tid 147828] [client 143.244.57.86:60120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ahk.tqa.temporary.site"] [uri "/index.php"] [unique_id "amuyg-_ioCvBERk4wq-V9wAAAT0"]
[Thu Jul 30 15:22:28.009525 2026] [security2:error] [pid 147647:tid 147753] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/kwm4.php"] [unique_id "amuyhO_ioCvBERk4wq-V_QABOWk"]
[Thu Jul 30 15:22:28.075616 2026] [security2:error] [pid 147647:tid 147869] [client 143.244.57.86:60120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahk.tqa.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuyhO_ioCvBERk4wq-WAQAAAWY"]
[Thu Jul 30 15:22:28.075725 2026] [security2:error] [pid 147647:tid 147869] [client 143.244.57.86:60120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ahk.tqa.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuyhO_ioCvBERk4wq-WAQAAAWY"]
[Thu Jul 30 15:22:28.107798 2026] [core:notice] [pid 147647:tid 147788] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:28.113549 2026] [security2:error] [pid 147647:tid 147788] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Euclid/article/view/317"] [unique_id "amuyhO_ioCvBERk4wq-WAgAAARU"]
[Thu Jul 30 15:22:28.142781 2026] [security2:error] [pid 147647:tid 147847] [client 20.203.148.31:35516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amuyhO_ioCvBERk4wq-WAwAAAVA"]
[Thu Jul 30 15:22:28.294282 2026] [security2:error] [pid 147647:tid 147728] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/kyami.php"] [unique_id "amuyhO_ioCvBERk4wq-WCwABP1A"]
[Thu Jul 30 15:22:28.321602 2026] [security2:error] [pid 147647:tid 147859] [client 20.63.98.115:32231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/alfanew.php"] [unique_id "amuyhO_ioCvBERk4wq-WDAAAAVw"]
[Thu Jul 30 15:22:28.331642 2026] [security2:error] [pid 147647:tid 147811] [client 20.215.218.234:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/darkshell.php"] [unique_id "amuyhO_ioCvBERk4wq-WDQAAASw"]
[Thu Jul 30 15:22:28.331824 2026] [security2:error] [pid 147647:tid 147811] [client 20.215.218.234:60265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/darkshell.php"] [unique_id "amuyhO_ioCvBERk4wq-WDQAAASw"]
[Thu Jul 30 15:22:28.585285 2026] [security2:error] [pid 147647:tid 147704] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/l.php"] [unique_id "amuyhO_ioCvBERk4wq-WEgABTjg"]
[Thu Jul 30 15:22:28.602134 2026] [core:notice] [pid 147647:tid 147815] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:28.605450 2026] [security2:error] [pid 147647:tid 147815] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/5078"] [unique_id "amuyhO_ioCvBERk4wq-WFgAAATA"]
[Thu Jul 30 15:22:28.705731 2026] [security2:error] [pid 147647:tid 147699] [remote 216.73.216.51:45669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuyhO_ioCvBERk4wq-WFwABGDM"]
[Thu Jul 30 15:22:28.731109 2026] [security2:error] [pid 147647:tid 147834] [client 20.215.218.234:20785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/gel4y.php"] [unique_id "amuyhO_ioCvBERk4wq-WGAAAAUM"]
[Thu Jul 30 15:22:28.731227 2026] [security2:error] [pid 147647:tid 147834] [client 20.215.218.234:20785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/gel4y.php"] [unique_id "amuyhO_ioCvBERk4wq-WGAAAAUM"]
[Thu Jul 30 15:22:28.873852 2026] [security2:error] [pid 147647:tid 147738] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/l10n.php"] [unique_id "amuyhO_ioCvBERk4wq-WHgABDlo"]
[Thu Jul 30 15:22:28.880060 2026] [core:notice] [pid 147647:tid 147837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:29.100782 2026] [core:notice] [pid 147647:tid 147802] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:29.153453 2026] [security2:error] [pid 147647:tid 147877] [client 20.203.148.31:42833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amuyhe_ioCvBERk4wq-WKAAAAW4"]
[Thu Jul 30 15:22:29.166461 2026] [security2:error] [pid 147647:tid 147757] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/la.php"] [unique_id "amuyhe_ioCvBERk4wq-WKQABbW0"]
[Thu Jul 30 15:22:29.169107 2026] [security2:error] [pid 147647:tid 147894] [client 20.215.218.234:9920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/contacts.php"] [unique_id "amuyhe_ioCvBERk4wq-WKgAAAX8"]
[Thu Jul 30 15:22:29.169206 2026] [security2:error] [pid 147647:tid 147894] [client 20.215.218.234:9920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/contacts.php"] [unique_id "amuyhe_ioCvBERk4wq-WKgAAAX8"]
[Thu Jul 30 15:22:29.429146 2026] [security2:error] [pid 147647:tid 147729] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/langar.php"] [unique_id "amuyhe_ioCvBERk4wq-WMgABclE"]
[Thu Jul 30 15:22:29.596105 2026] [core:notice] [pid 147647:tid 147821] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:29.599723 2026] [security2:error] [pid 147647:tid 147821] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/view/2549"] [unique_id "amuyhe_ioCvBERk4wq-WOQAAATY"]
[Thu Jul 30 15:22:29.688502 2026] [security2:error] [pid 147647:tid 147853] [client 20.215.218.234:20791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/yo.php"] [unique_id "amuyhe_ioCvBERk4wq-WOgAAAVY"]
[Thu Jul 30 15:22:29.688644 2026] [security2:error] [pid 147647:tid 147853] [client 20.215.218.234:20791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/yo.php"] [unique_id "amuyhe_ioCvBERk4wq-WOgAAAVY"]
[Thu Jul 30 15:22:29.691607 2026] [security2:error] [pid 147647:tid 147708] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/law.php"] [unique_id "amuyhe_ioCvBERk4wq-WOwABSjw"]
[Thu Jul 30 15:22:29.740573 2026] [security2:error] [pid 147647:tid 147833] [client 20.63.98.115:32251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/text.php"] [unique_id "amuyhe_ioCvBERk4wq-WPwAAAUI"]
[Thu Jul 30 15:22:29.964756 2026] [security2:error] [pid 147647:tid 147700] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/laymu.php"] [unique_id "amuyhe_ioCvBERk4wq-WQAABdjQ"]
[Thu Jul 30 15:22:30.111790 2026] [security2:error] [pid 147647:tid 147825] [client 20.215.218.234:21208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/fm.php"] [unique_id "amuyhu_ioCvBERk4wq-WRAAAATo"]
[Thu Jul 30 15:22:30.111893 2026] [security2:error] [pid 147647:tid 147825] [client 20.215.218.234:21208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/fm.php"] [unique_id "amuyhu_ioCvBERk4wq-WRAAAATo"]
[Thu Jul 30 15:22:30.232492 2026] [security2:error] [pid 147647:tid 147796] [client 20.203.148.31:30023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amuyhu_ioCvBERk4wq-WSQAAAR0"]
[Thu Jul 30 15:22:30.234924 2026] [security2:error] [pid 147647:tid 147755] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/layout.php"] [unique_id "amuyhu_ioCvBERk4wq-WSgABU2s"]
[Thu Jul 30 15:22:30.492743 2026] [security2:error] [pid 147647:tid 147744] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/lc.php"] [unique_id "amuyhu_ioCvBERk4wq-WUQABZGA"]
[Thu Jul 30 15:22:30.506669 2026] [security2:error] [pid 147647:tid 147803] [client 20.215.218.234:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/a.php"] [unique_id "amuyhu_ioCvBERk4wq-WVQAAASQ"]
[Thu Jul 30 15:22:30.506765 2026] [security2:error] [pid 147647:tid 147803] [client 20.215.218.234:64087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/a.php"] [unique_id "amuyhu_ioCvBERk4wq-WVQAAASQ"]
[Thu Jul 30 15:22:30.542749 2026] [security2:error] [pid 147647:tid 147752] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyhu_ioCvBERk4wq-WWAABH2g"]
[Thu Jul 30 15:22:30.543010 2026] [security2:error] [pid 147647:tid 147798] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyhu_ioCvBERk4wq-WWAABH2g"]
[Thu Jul 30 15:22:30.628520 2026] [core:notice] [pid 147647:tid 147787] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:30.755900 2026] [security2:error] [pid 147647:tid 147754] [remote 135.119.63.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.markmocek.com"] [uri "/leaf.php"] [unique_id "amuyhu_ioCvBERk4wq-WXQABG2o"]
[Thu Jul 30 15:22:30.868498 2026] [security2:error] [pid 147647:tid 147808] [client 20.215.218.234:21700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/sym.php"] [unique_id "amuyhu_ioCvBERk4wq-WcwAAASk"]
[Thu Jul 30 15:22:30.868611 2026] [security2:error] [pid 147647:tid 147808] [client 20.215.218.234:21700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/sym.php"] [unique_id "amuyhu_ioCvBERk4wq-WcwAAASk"]
[Thu Jul 30 15:22:31.173426 2026] [core:notice] [pid 147647:tid 147842] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:31.176854 2026] [security2:error] [pid 147647:tid 147842] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/4145"] [unique_id "amuyh-_ioCvBERk4wq-WegAAAUs"]
[Thu Jul 30 15:22:31.371911 2026] [security2:error] [pid 147647:tid 147801] [client 20.215.218.234:60255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/shell.php"] [unique_id "amuyh-_ioCvBERk4wq-WgQAAASI"]
[Thu Jul 30 15:22:31.372047 2026] [security2:error] [pid 147647:tid 147801] [client 20.215.218.234:60255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/shell.php"] [unique_id "amuyh-_ioCvBERk4wq-WgQAAASI"]
[Thu Jul 30 15:22:31.552862 2026] [security2:error] [pid 147647:tid 147888] [client 172.237.109.114:12868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyhu_ioCvBERk4wq-WdgAAAXk"]
[Thu Jul 30 15:22:31.711012 2026] [core:notice] [pid 147647:tid 147751] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:31.977537 2026] [security2:error] [pid 147647:tid 147899] [client 20.215.218.234:63506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/mini.php"] [unique_id "amuyh-_ioCvBERk4wq-WlQAAAYQ"]
[Thu Jul 30 15:22:31.977631 2026] [security2:error] [pid 147647:tid 147899] [client 20.215.218.234:63506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/mini.php"] [unique_id "amuyh-_ioCvBERk4wq-WlQAAAYQ"]
[Thu Jul 30 15:22:32.337187 2026] [security2:error] [pid 147647:tid 147854] [client 20.203.148.31:30075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amuyiO_ioCvBERk4wq-WnQAAAVc"]
[Thu Jul 30 15:22:32.541834 2026] [security2:error] [pid 147647:tid 147782] [client 20.215.218.234:63544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/mar.php"] [unique_id "amuyiO_ioCvBERk4wq-WpwAAAQ8"]
[Thu Jul 30 15:22:32.541995 2026] [security2:error] [pid 147647:tid 147782] [client 20.215.218.234:63544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/mar.php"] [unique_id "amuyiO_ioCvBERk4wq-WpwAAAQ8"]
[Thu Jul 30 15:22:32.587330 2026] [security2:error] [pid 147647:tid 147893] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyh-_ioCvBERk4wq-WlAABfnQ"]
[Thu Jul 30 15:22:32.737554 2026] [core:notice] [pid 147647:tid 147803] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:32.741260 2026] [security2:error] [pid 147647:tid 147803] [client 66.249.79.229:42823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/view/6547"] [unique_id "amuyiO_ioCvBERk4wq-WogAAASQ"]
[Thu Jul 30 15:22:33.171145 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:21242] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/1.php"] [unique_id "amuyie_ioCvBERk4wq-WtQAAAV4"]
[Thu Jul 30 15:22:33.171296 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:21242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/1.php"] [unique_id "amuyie_ioCvBERk4wq-WtQAAAV4"]
[Thu Jul 30 15:22:33.171445 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:21242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/1.php"] [unique_id "amuyie_ioCvBERk4wq-WtQAAAV4"]
[Thu Jul 30 15:22:33.243894 2026] [security2:error] [pid 147647:tid 147870] [client 20.203.148.31:35468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amuyie_ioCvBERk4wq-WuQAAAWc"]
[Thu Jul 30 15:22:33.406152 2026] [core:notice] [pid 147647:tid 147848] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:33.676407 2026] [security2:error] [pid 147647:tid 147816] [client 20.215.218.234:60279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/imageswp-init.php"] [unique_id "amuyie_ioCvBERk4wq-WxwAAATE"]
[Thu Jul 30 15:22:33.676518 2026] [security2:error] [pid 147647:tid 147816] [client 20.215.218.234:60279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/imageswp-init.php"] [unique_id "amuyie_ioCvBERk4wq-WxwAAATE"]
[Thu Jul 30 15:22:33.866968 2026] [core:notice] [pid 147647:tid 147809] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:33.870571 2026] [security2:error] [pid 147647:tid 147809] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/download/6103/2938"] [unique_id "amuyie_ioCvBERk4wq-W1AAAASo"]
[Thu Jul 30 15:22:34.061068 2026] [security2:error] [pid 147647:tid 147849] [client 20.215.218.234:60266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/upload.php"] [unique_id "amuyiu_ioCvBERk4wq-W1QAAAVI"]
[Thu Jul 30 15:22:34.061189 2026] [security2:error] [pid 147647:tid 147849] [client 20.215.218.234:60266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/upload.php"] [unique_id "amuyiu_ioCvBERk4wq-W1QAAAVI"]
[Thu Jul 30 15:22:34.257910 2026] [core:notice] [pid 147647:tid 147900] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:34.469973 2026] [core:notice] [pid 147647:tid 147810] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:34.473200 2026] [security2:error] [pid 147647:tid 147810] [client 103.131.71.143:44227] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ejournalugj.com"] [uri "/robots.txt"] [unique_id "amuyiu_ioCvBERk4wq-W5AAAASs"]
[Thu Jul 30 15:22:34.635315 2026] [security2:error] [pid 147647:tid 147855] [client 20.215.218.234:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/fox.php"] [unique_id "amuyiu_ioCvBERk4wq-W6AAAAVg"]
[Thu Jul 30 15:22:34.635451 2026] [security2:error] [pid 147647:tid 147855] [client 20.215.218.234:60278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/fox.php"] [unique_id "amuyiu_ioCvBERk4wq-W6AAAAVg"]
[Thu Jul 30 15:22:34.997806 2026] [core:notice] [pid 147647:tid 147831] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:35.060101 2026] [security2:error] [pid 147647:tid 147876] [client 20.215.218.234:60237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/fw.php"] [unique_id "amuyi-_ioCvBERk4wq-W8gAAAW0"]
[Thu Jul 30 15:22:35.060213 2026] [security2:error] [pid 147647:tid 147876] [client 20.215.218.234:60237] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/fw.php"] [unique_id "amuyi-_ioCvBERk4wq-W8gAAAW0"]
[Thu Jul 30 15:22:35.202274 2026] [security2:error] [pid 147647:tid 147780] [client 20.203.148.31:42776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amuyi-_ioCvBERk4wq-W9gAAAQ0"]
[Thu Jul 30 15:22:35.483539 2026] [security2:error] [pid 147647:tid 147895] [client 20.215.218.234:21207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/alfa.php"] [unique_id "amuyi-_ioCvBERk4wq-XAQAAAYA"]
[Thu Jul 30 15:22:35.483659 2026] [security2:error] [pid 147647:tid 147895] [client 20.215.218.234:21207] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/alfa.php"] [unique_id "amuyi-_ioCvBERk4wq-XAQAAAYA"]
[Thu Jul 30 15:22:35.847429 2026] [security2:error] [pid 147647:tid 147887] [client 2a03:2880:f800:7:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyi-_ioCvBERk4wq-W9wABeAw"]
[Thu Jul 30 15:22:35.914096 2026] [security2:error] [pid 147647:tid 147897] [client 20.215.218.234:21704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/alfashell.php"] [unique_id "amuyi-_ioCvBERk4wq-XCAAAAYI"]
[Thu Jul 30 15:22:35.914216 2026] [security2:error] [pid 147647:tid 147897] [client 20.215.218.234:21704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/alfashell.php"] [unique_id "amuyi-_ioCvBERk4wq-XCAAAAYI"]
[Thu Jul 30 15:22:36.085157 2026] [core:notice] [pid 147647:tid 147852] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:36.088724 2026] [security2:error] [pid 147647:tid 147852] [client 66.249.79.229:42823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/download/9501/4233"] [unique_id "amuyjO_ioCvBERk4wq-XDAAAAVU"]
[Thu Jul 30 15:22:36.375107 2026] [security2:error] [pid 147647:tid 147812] [client 20.215.218.234:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/gelay.php"] [unique_id "amuyjO_ioCvBERk4wq-XEgAAAS0"]
[Thu Jul 30 15:22:36.375228 2026] [security2:error] [pid 147647:tid 147812] [client 20.215.218.234:60280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/gelay.php"] [unique_id "amuyjO_ioCvBERk4wq-XEgAAAS0"]
[Thu Jul 30 15:22:36.599613 2026] [security2:error] [pid 147647:tid 147825] [client 172.237.109.114:29196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyjO_ioCvBERk4wq-XDQAAATo"]
[Thu Jul 30 15:22:36.603972 2026] [core:notice] [pid 147647:tid 147866] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:36.608454 2026] [security2:error] [pid 147647:tid 147866] [client 103.131.71.80:32621] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "ejournalugj.com"] [uri "/index.html"] [unique_id "amuyjO_ioCvBERk4wq-XGgAAAWM"]
[Thu Jul 30 15:22:36.715774 2026] [security2:error] [pid 147647:tid 147797] [client 20.203.148.31:32599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amuyjO_ioCvBERk4wq-XHgAAAR4"]
[Thu Jul 30 15:22:36.800187 2026] [security2:error] [pid 147647:tid 147823] [client 20.215.218.234:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/byps.php"] [unique_id "amuyjO_ioCvBERk4wq-XIgAAATg"]
[Thu Jul 30 15:22:36.800319 2026] [security2:error] [pid 147647:tid 147823] [client 20.215.218.234:63493] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/byps.php"] [unique_id "amuyjO_ioCvBERk4wq-XIgAAATg"]
[Thu Jul 30 15:22:36.853758 2026] [core:notice] [pid 147647:tid 147858] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:37.273141 2026] [security2:error] [pid 147647:tid 147813] [client 20.215.218.234:21190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/bypass.php"] [unique_id "amuyje_ioCvBERk4wq-XLwAAAS4"]
[Thu Jul 30 15:22:37.273274 2026] [security2:error] [pid 147647:tid 147813] [client 20.215.218.234:21190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/bypass.php"] [unique_id "amuyje_ioCvBERk4wq-XLwAAAS4"]
[Thu Jul 30 15:22:37.613299 2026] [security2:error] [pid 147647:tid 147886] [client 172.237.109.114:51412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyje_ioCvBERk4wq-XKwAAAXc"]
[Thu Jul 30 15:22:37.629302 2026] [security2:error] [pid 147647:tid 147786] [client 20.203.148.31:42754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amuyje_ioCvBERk4wq-XOgAAARM"]
[Thu Jul 30 15:22:37.630804 2026] [security2:error] [pid 147647:tid 147833] [client 20.215.218.234:60247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/x.php"] [unique_id "amuyje_ioCvBERk4wq-XOwAAAUI"]
[Thu Jul 30 15:22:37.630898 2026] [security2:error] [pid 147647:tid 147833] [client 20.215.218.234:60247] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/x.php"] [unique_id "amuyje_ioCvBERk4wq-XOwAAAUI"]
[Thu Jul 30 15:22:37.968415 2026] [security2:error] [pid 147647:tid 147804] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyje_ioCvBERk4wq-XMgAAASU"]
[Thu Jul 30 15:22:38.032283 2026] [core:notice] [pid 147647:tid 147840] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:38.063799 2026] [security2:error] [pid 147647:tid 147836] [client 20.215.218.234:20739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/leaf.php"] [unique_id "amuyju_ioCvBERk4wq-XSQAAAUU"]
[Thu Jul 30 15:22:38.063907 2026] [security2:error] [pid 147647:tid 147836] [client 20.215.218.234:20739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/leaf.php"] [unique_id "amuyju_ioCvBERk4wq-XSQAAAUU"]
[Thu Jul 30 15:22:38.159218 2026] [core:notice] [pid 147647:tid 147725] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:38.450492 2026] [security2:error] [pid 147647:tid 147799] [client 20.215.218.234:21213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/wso.php"] [unique_id "amuyju_ioCvBERk4wq-XUwAAASA"]
[Thu Jul 30 15:22:38.450646 2026] [security2:error] [pid 147647:tid 147799] [client 20.215.218.234:21213] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/wso.php"] [unique_id "amuyju_ioCvBERk4wq-XUwAAASA"]
[Thu Jul 30 15:22:38.860843 2026] [security2:error] [pid 147647:tid 147695] [remote 20.89.83.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.83.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesounddepot.com"] [uri "/wp-login.php"] [unique_id "amuyju_ioCvBERk4wq-XVwABZC8"]
[Thu Jul 30 15:22:38.946316 2026] [core:notice] [pid 147647:tid 147904] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:38.950636 2026] [security2:error] [pid 147647:tid 147822] [client 20.215.218.234:21736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/sym403.php"] [unique_id "amuyju_ioCvBERk4wq-XZQAAATc"]
[Thu Jul 30 15:22:38.950731 2026] [security2:error] [pid 147647:tid 147822] [client 20.215.218.234:21736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/sym403.php"] [unique_id "amuyju_ioCvBERk4wq-XZQAAATc"]
[Thu Jul 30 15:22:39.361506 2026] [security2:error] [pid 147647:tid 147829] [client 20.215.218.234:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/leafmailer2.8.php"] [unique_id "amuyj-_ioCvBERk4wq-XbQAAAT4"]
[Thu Jul 30 15:22:39.361620 2026] [security2:error] [pid 147647:tid 147829] [client 20.215.218.234:60286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/leafmailer2.8.php"] [unique_id "amuyj-_ioCvBERk4wq-XbQAAAT4"]
[Thu Jul 30 15:22:39.479073 2026] [security2:error] [pid 147647:tid 147798] [client 20.203.148.31:28450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amuyj-_ioCvBERk4wq-XbgAAAR8"]
[Thu Jul 30 15:22:39.709933 2026] [security2:error] [pid 147647:tid 147793] [client 20.215.218.234:60561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/lux.php"] [unique_id "amuyj-_ioCvBERk4wq-XcwAAARo"]
[Thu Jul 30 15:22:39.710064 2026] [security2:error] [pid 147647:tid 147793] [client 20.215.218.234:60561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/images/lux.php"] [unique_id "amuyj-_ioCvBERk4wq-XcwAAARo"]
[Thu Jul 30 15:22:39.904364 2026] [core:notice] [pid 147647:tid 147833] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:39.907973 2026] [security2:error] [pid 147647:tid 147833] [client 66.249.79.1:46460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agro_sintesa/article/view/2317"] [unique_id "amuyj-_ioCvBERk4wq-XgAAAAUI"]
[Thu Jul 30 15:22:40.091141 2026] [security2:error] [pid 147647:tid 147832] [client 20.215.218.234:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/w3llstore.php"] [unique_id "amuykO_ioCvBERk4wq-XgQAAAUE"]
[Thu Jul 30 15:22:40.091269 2026] [security2:error] [pid 147647:tid 147832] [client 20.215.218.234:63505] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/w3llstore.php"] [unique_id "amuykO_ioCvBERk4wq-XgQAAAUE"]
[Thu Jul 30 15:22:40.127102 2026] [core:notice] [pid 147647:tid 147777] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:40.337345 2026] [security2:error] [pid 147647:tid 147836] [client 114.119.156.77:38573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dhowcruisedinner.com"] [uri "/marina-dhow-cruise.html"] [unique_id "amuykO_ioCvBERk4wq-XiQAAAUU"]
[Thu Jul 30 15:22:40.468725 2026] [security2:error] [pid 147647:tid 147874] [client 20.215.218.234:21724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfi.php"] [unique_id "amuykO_ioCvBERk4wq-XjQAAAWs"]
[Thu Jul 30 15:22:40.468847 2026] [security2:error] [pid 147647:tid 147874] [client 20.215.218.234:21724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfi.php"] [unique_id "amuykO_ioCvBERk4wq-XjQAAAWs"]
[Thu Jul 30 15:22:40.581115 2026] [core:notice] [pid 147647:tid 147900] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:40.817884 2026] [security2:error] [pid 147647:tid 147867] [client 20.215.218.234:21244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/DC.php"] [unique_id "amuykO_ioCvBERk4wq-XmAAAAWQ"]
[Thu Jul 30 15:22:40.818001 2026] [security2:error] [pid 147647:tid 147867] [client 20.215.218.234:21244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/DC.php"] [unique_id "amuykO_ioCvBERk4wq-XmAAAAWQ"]
[Thu Jul 30 15:22:41.200276 2026] [security2:error] [pid 147647:tid 147810] [client 20.215.218.234:63547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/DC.php"] [unique_id "amuyke_ioCvBERk4wq-XoQAAASs"]
[Thu Jul 30 15:22:41.200414 2026] [security2:error] [pid 147647:tid 147810] [client 20.215.218.234:63547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/DC.php"] [unique_id "amuyke_ioCvBERk4wq-XoQAAASs"]
[Thu Jul 30 15:22:41.227217 2026] [security2:error] [pid 147647:tid 147753] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyke_ioCvBERk4wq-XogABGGk"]
[Thu Jul 30 15:22:41.227431 2026] [security2:error] [pid 147647:tid 147791] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyke_ioCvBERk4wq-XogABGGk"]
[Thu Jul 30 15:22:41.591263 2026] [security2:error] [pid 147647:tid 147878] [client 20.215.218.234:20784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/shell.php"] [unique_id "amuyke_ioCvBERk4wq-XrAAAAW8"]
[Thu Jul 30 15:22:41.591383 2026] [security2:error] [pid 147647:tid 147878] [client 20.215.218.234:20784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/shell.php"] [unique_id "amuyke_ioCvBERk4wq-XrAAAAW8"]
[Thu Jul 30 15:22:41.860490 2026] [core:notice] [pid 147647:tid 147895] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:41.863821 2026] [security2:error] [pid 147647:tid 147895] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/962"] [unique_id "amuyke_ioCvBERk4wq-XsgAAAYA"]
[Thu Jul 30 15:22:41.974615 2026] [core:notice] [pid 147647:tid 147722] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:42.011806 2026] [security2:error] [pid 147647:tid 147885] [client 20.215.218.234:21184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/fox.php"] [unique_id "amuyku_ioCvBERk4wq-XugAAAXY"]
[Thu Jul 30 15:22:42.011925 2026] [security2:error] [pid 147647:tid 147885] [client 20.215.218.234:21184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/fox.php"] [unique_id "amuyku_ioCvBERk4wq-XugAAAXY"]
[Thu Jul 30 15:22:42.421258 2026] [security2:error] [pid 147647:tid 147840] [client 20.215.218.234:9946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "amuyku_ioCvBERk4wq-XwQAAAUk"]
[Thu Jul 30 15:22:42.421365 2026] [security2:error] [pid 147647:tid 147840] [client 20.215.218.234:9946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "amuyku_ioCvBERk4wq-XwQAAAUk"]
[Thu Jul 30 15:22:42.761699 2026] [core:notice] [pid 147647:tid 147857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:42.861765 2026] [security2:error] [pid 147647:tid 147849] [client 20.215.218.234:64065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "amuyku_ioCvBERk4wq-XyQAAAVI"]
[Thu Jul 30 15:22:42.862143 2026] [security2:error] [pid 147647:tid 147849] [client 20.215.218.234:64065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "amuyku_ioCvBERk4wq-XyQAAAVI"]
[Thu Jul 30 15:22:43.211626 2026] [core:notice] [pid 147647:tid 147896] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:43.215021 2026] [security2:error] [pid 147647:tid 147896] [client 66.249.79.1:46460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/article/view/8382"] [unique_id "amuyk-_ioCvBERk4wq-X0AAAAYE"]
[Thu Jul 30 15:22:43.313791 2026] [security2:error] [pid 147647:tid 147845] [client 20.215.218.234:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/Ninja.php"] [unique_id "amuyk-_ioCvBERk4wq-X0QAAAU4"]
[Thu Jul 30 15:22:43.313915 2026] [security2:error] [pid 147647:tid 147845] [client 20.215.218.234:64075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/Ninja.php"] [unique_id "amuyk-_ioCvBERk4wq-X0QAAAU4"]
[Thu Jul 30 15:22:43.762277 2026] [core:notice] [pid 147647:tid 147823] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:43.779821 2026] [security2:error] [pid 147647:tid 147781] [client 20.63.98.115:33293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/f.php"] [unique_id "amuyk-_ioCvBERk4wq-X6QAAAQ4"]
[Thu Jul 30 15:22:43.786413 2026] [security2:error] [pid 147647:tid 147791] [client 20.215.218.234:63522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-incleude.php"] [unique_id "amuyk-_ioCvBERk4wq-X6gAAARg"]
[Thu Jul 30 15:22:43.786524 2026] [security2:error] [pid 147647:tid 147791] [client 20.215.218.234:63522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-incleude.php"] [unique_id "amuyk-_ioCvBERk4wq-X6gAAARg"]
[Thu Jul 30 15:22:44.249879 2026] [security2:error] [pid 147647:tid 147805] [client 20.215.218.234:54777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/fpebr.php"] [unique_id "amuylO_ioCvBERk4wq-X-wAAASY"]
[Thu Jul 30 15:22:44.250027 2026] [security2:error] [pid 147647:tid 147805] [client 20.215.218.234:54777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/fpebr.php"] [unique_id "amuylO_ioCvBERk4wq-X-wAAASY"]
[Thu Jul 30 15:22:44.665747 2026] [core:notice] [pid 147647:tid 147745] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:44.826669 2026] [security2:error] [pid 147647:tid 147840] [client 20.215.218.234:9944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/snd21.php"] [unique_id "amuylO_ioCvBERk4wq-YCAAAAUk"]
[Thu Jul 30 15:22:44.826788 2026] [security2:error] [pid 147647:tid 147840] [client 20.215.218.234:9944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/snd21.php"] [unique_id "amuylO_ioCvBERk4wq-YCAAAAUk"]
[Thu Jul 30 15:22:44.924489 2026] [core:notice] [pid 147647:tid 147836] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:44.927945 2026] [security2:error] [pid 147647:tid 147836] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/view/4836"] [unique_id "amuylO_ioCvBERk4wq-YCQAAAUU"]
[Thu Jul 30 15:22:45.328495 2026] [security2:error] [pid 147647:tid 147863] [client 20.215.218.234:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/olu.php"] [unique_id "amuyle_ioCvBERk4wq-YFQAAAWA"]
[Thu Jul 30 15:22:45.328672 2026] [security2:error] [pid 147647:tid 147863] [client 20.215.218.234:60256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/olu.php"] [unique_id "amuyle_ioCvBERk4wq-YFQAAAWA"]
[Thu Jul 30 15:22:45.373612 2026] [core:notice] [pid 147647:tid 147825] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:45.693262 2026] [security2:error] [pid 147647:tid 147883] [client 20.203.148.31:28464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amuyle_ioCvBERk4wq-YIQAAAXQ"]
[Thu Jul 30 15:22:45.706013 2026] [security2:error] [pid 147647:tid 147827] [client 50.6.43.217:18086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/1.jpg"] [unique_id "amuyle_ioCvBERk4wq-YIgAAATw"]
[Thu Jul 30 15:22:45.715827 2026] [security2:error] [pid 147647:tid 147871] [client 50.6.43.217:18088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/2.jpg"] [unique_id "amuyle_ioCvBERk4wq-YJQAAAWg"]
[Thu Jul 30 15:22:45.727071 2026] [security2:error] [pid 147647:tid 147781] [client 50.6.43.217:18090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ecvh.ae"] [uri "/modules/wktestimonialblock/views/img/hotels_testimonials_img/3.jpg"] [unique_id "amuyle_ioCvBERk4wq-YJwAAAQ4"]
[Thu Jul 30 15:22:45.753092 2026] [security2:error] [pid 147647:tid 147782] [client 20.63.98.115:33295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuyle_ioCvBERk4wq-YKAAAAQ8"]
[Thu Jul 30 15:22:45.857352 2026] [security2:error] [pid 147647:tid 147821] [client 20.215.218.234:9926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/tuco.php"] [unique_id "amuyle_ioCvBERk4wq-YKgAAATY"]
[Thu Jul 30 15:22:45.857470 2026] [security2:error] [pid 147647:tid 147821] [client 20.215.218.234:9926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/tuco.php"] [unique_id "amuyle_ioCvBERk4wq-YKgAAATY"]
[Thu Jul 30 15:22:45.868520 2026] [core:notice] [pid 147647:tid 147864] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:45.985200 2026] [core:notice] [pid 147647:tid 147750] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:46.382329 2026] [security2:error] [pid 147647:tid 147882] [client 20.215.218.234:9932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ice.php"] [unique_id "amuylu_ioCvBERk4wq-YQAAAAXM"]
[Thu Jul 30 15:22:46.382469 2026] [security2:error] [pid 147647:tid 147882] [client 20.215.218.234:9932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ice.php"] [unique_id "amuylu_ioCvBERk4wq-YQAAAAXM"]
[Thu Jul 30 15:22:46.386111 2026] [core:notice] [pid 147647:tid 147804] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:46.722049 2026] [security2:error] [pid 147647:tid 147801] [client 172.237.109.114:16765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuylu_ioCvBERk4wq-YPQAAASI"]
[Thu Jul 30 15:22:46.869849 2026] [core:notice] [pid 147647:tid 147799] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:46.873323 2026] [security2:error] [pid 147647:tid 147799] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Deiksis/article/view/2131/1525"] [unique_id "amuylu_ioCvBERk4wq-YVQAAASA"]
[Thu Jul 30 15:22:46.962077 2026] [security2:error] [pid 147647:tid 147874] [client 20.203.148.31:30047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amuylu_ioCvBERk4wq-YVwAAAWs"]
[Thu Jul 30 15:22:46.996148 2026] [security2:error] [pid 147647:tid 147884] [client 20.63.98.115:49085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/hehe.php"] [unique_id "amuylu_ioCvBERk4wq-YWwAAAXU"]
[Thu Jul 30 15:22:47.157816 2026] [security2:error] [pid 147647:tid 147789] [client 20.215.218.234:60245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/codeboy1877x.php"] [unique_id "amuyl-_ioCvBERk4wq-YYQAAARY"]
[Thu Jul 30 15:22:47.157923 2026] [security2:error] [pid 147647:tid 147789] [client 20.215.218.234:60245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/codeboy1877x.php"] [unique_id "amuyl-_ioCvBERk4wq-YYQAAARY"]
[Thu Jul 30 15:22:47.214213 2026] [proxy:error] [pid 147647:tid 147877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:47.214301 2026] [proxy_http:error] [pid 147647:tid 147877] [client 3.225.222.228:18580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:47.215134 2026] [proxy:error] [pid 147647:tid 147877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:47.215196 2026] [proxy_http:error] [pid 147647:tid 147877] [client 3.225.222.228:18580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:47.229155 2026] [proxy:error] [pid 147647:tid 147831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:47.229246 2026] [proxy_http:error] [pid 147647:tid 147831] [client 52.4.19.39:30576] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:47.229884 2026] [proxy:error] [pid 147647:tid 147831] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:47.229930 2026] [proxy_http:error] [pid 147647:tid 147831] [client 52.4.19.39:30576] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:47.367021 2026] [core:notice] [pid 147647:tid 147793] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:47.585715 2026] [security2:error] [pid 147647:tid 147778] [client 20.215.218.234:21218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wsanon.php"] [unique_id "amuyl-_ioCvBERk4wq-YegAAAQs"]
[Thu Jul 30 15:22:47.585818 2026] [security2:error] [pid 147647:tid 147778] [client 20.215.218.234:21218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wsanon.php"] [unique_id "amuyl-_ioCvBERk4wq-YegAAAQs"]
[Thu Jul 30 15:22:47.781949 2026] [security2:error] [pid 147647:tid 147804] [client 20.63.98.115:32749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/options.php"] [unique_id "amuyl-_ioCvBERk4wq-YgAAAASU"]
[Thu Jul 30 15:22:47.998044 2026] [security2:error] [pid 147647:tid 147875] [client 20.215.218.234:64068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/Alfa.php"] [unique_id "amuyl-_ioCvBERk4wq-YgQAAAWw"]
[Thu Jul 30 15:22:47.998169 2026] [security2:error] [pid 147647:tid 147875] [client 20.215.218.234:64068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/Alfa.php"] [unique_id "amuyl-_ioCvBERk4wq-YgQAAAWw"]
[Thu Jul 30 15:22:48.177788 2026] [core:notice] [pid 147647:tid 147772] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:48.179708 2026] [core:notice] [pid 147647:tid 147895] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:48.401204 2026] [core:notice] [pid 147647:tid 147659] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:48.447289 2026] [security2:error] [pid 147647:tid 147830] [client 20.215.218.234:21741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "amuymO_ioCvBERk4wq-YlwAAAT8"]
[Thu Jul 30 15:22:48.447415 2026] [security2:error] [pid 147647:tid 147830] [client 20.215.218.234:21741] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "amuymO_ioCvBERk4wq-YlwAAAT8"]
[Thu Jul 30 15:22:48.627620 2026] [core:notice] [pid 147647:tid 147883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:48.629041 2026] [security2:error] [pid 147647:tid 147869] [client 20.203.148.31:32605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amuymO_ioCvBERk4wq-YnQAAAWY"]
[Thu Jul 30 15:22:48.643095 2026] [security2:error] [pid 147647:tid 147799] [client 20.63.98.115:49068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amuymO_ioCvBERk4wq-YngAAASA"]
[Thu Jul 30 15:22:48.816773 2026] [security2:error] [pid 147647:tid 147806] [client 134.19.179.195:35562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuymO_ioCvBERk4wq-YsQAAASc"]
[Thu Jul 30 15:22:48.816868 2026] [security2:error] [pid 147647:tid 147806] [client 134.19.179.195:35562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuymO_ioCvBERk4wq-YsQAAASc"]
[Thu Jul 30 15:22:48.896098 2026] [security2:error] [pid 147647:tid 147786] [client 20.215.218.234:21739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "amuymO_ioCvBERk4wq-YsgAAARM"]
[Thu Jul 30 15:22:48.896224 2026] [security2:error] [pid 147647:tid 147786] [client 20.215.218.234:21739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "amuymO_ioCvBERk4wq-YsgAAARM"]
[Thu Jul 30 15:22:49.360667 2026] [security2:error] [pid 147647:tid 147892] [client 20.215.218.234:63489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "amuyme_ioCvBERk4wq-YvwAAAX0"]
[Thu Jul 30 15:22:49.360769 2026] [security2:error] [pid 147647:tid 147892] [client 20.215.218.234:63489] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "amuyme_ioCvBERk4wq-YvwAAAX0"]
[Thu Jul 30 15:22:49.387719 2026] [security2:error] [pid 147647:tid 147808] [client 2a03:2880:f800:1a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuymO_ioCvBERk4wq-YqgABKRk"]
[Thu Jul 30 15:22:49.426212 2026] [security2:error] [pid 147647:tid 147778] [client 20.203.148.31:40666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amuyme_ioCvBERk4wq-YwAAAAQs"]
[Thu Jul 30 15:22:49.456106 2026] [security2:error] [pid 147647:tid 147688] [remote 57.141.0.62:58602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuyme_ioCvBERk4wq-YwQABTSg"]
[Thu Jul 30 15:22:49.569841 2026] [security2:error] [pid 147647:tid 147856] [client 20.63.98.115:22155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/images/index.php"] [unique_id "amuyme_ioCvBERk4wq-YwgAAAVk"]
[Thu Jul 30 15:22:49.738562 2026] [security2:error] [pid 147647:tid 147811] [client 20.215.218.234:21226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "amuyme_ioCvBERk4wq-YxgAAASw"]
[Thu Jul 30 15:22:49.738672 2026] [security2:error] [pid 147647:tid 147811] [client 20.215.218.234:21226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "amuyme_ioCvBERk4wq-YxgAAASw"]
[Thu Jul 30 15:22:50.065791 2026] [security2:error] [pid 147647:tid 147866] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuymu_ioCvBERk4wq-Y1wAAAWM"]
[Thu Jul 30 15:22:50.065907 2026] [security2:error] [pid 147647:tid 147866] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuymu_ioCvBERk4wq-Y1wAAAWM"]
[Thu Jul 30 15:22:50.180393 2026] [proxy:error] [pid 147647:tid 147830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:50.180478 2026] [proxy_http:error] [pid 147647:tid 147830] [client 3.225.222.228:29143] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:50.181084 2026] [proxy:error] [pid 147647:tid 147830] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:22:50.181134 2026] [proxy_http:error] [pid 147647:tid 147830] [client 3.225.222.228:29143] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:22:50.208100 2026] [security2:error] [pid 147647:tid 147874] [client 20.215.218.234:20771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin/mailer.php"] [unique_id "amuymu_ioCvBERk4wq-Y4AAAAWs"]
[Thu Jul 30 15:22:50.208194 2026] [security2:error] [pid 147647:tid 147874] [client 20.215.218.234:20771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-admin/mailer.php"] [unique_id "amuymu_ioCvBERk4wq-Y4AAAAWs"]
[Thu Jul 30 15:22:50.301757 2026] [security2:error] [pid 147647:tid 147861] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuymu_ioCvBERk4wq-Y4wAAAV4"]
[Thu Jul 30 15:22:50.301872 2026] [security2:error] [pid 147647:tid 147861] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuymu_ioCvBERk4wq-Y4wAAAV4"]
[Thu Jul 30 15:22:50.339066 2026] [security2:error] [pid 147647:tid 147823] [client 20.203.148.31:11756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amuymu_ioCvBERk4wq-Y5QAAATg"]
[Thu Jul 30 15:22:50.536054 2026] [security2:error] [pid 147647:tid 147780] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/images/pearl/index.php"] [unique_id "amuymu_ioCvBERk4wq-Y7wAAAQ0"]
[Thu Jul 30 15:22:50.536147 2026] [security2:error] [pid 147647:tid 147780] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/images/pearl/index.php"] [unique_id "amuymu_ioCvBERk4wq-Y7wAAAQ0"]
[Thu Jul 30 15:22:50.595434 2026] [security2:error] [pid 147647:tid 147791] [client 20.215.218.234:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/mailer.php"] [unique_id "amuymu_ioCvBERk4wq-Y8AAAARg"]
[Thu Jul 30 15:22:50.595599 2026] [security2:error] [pid 147647:tid 147791] [client 20.215.218.234:60224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-content/mailer.php"] [unique_id "amuymu_ioCvBERk4wq-Y8AAAARg"]
[Thu Jul 30 15:22:50.624966 2026] [autoindex:error] [pid 147647:tid 147894] [client 142.93.143.123:39634] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:22:50.662922 2026] [autoindex:error] [pid 147647:tid 147781] [client 43.135.144.81:35420] AH01276: Cannot serve directory /home2/ubphmute/public_html/website_b63f1d3b/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:22:50.782511 2026] [security2:error] [pid 147647:tid 147807] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/bypass.php"] [unique_id "amuymu_ioCvBERk4wq-Y9gAAASg"]
[Thu Jul 30 15:22:50.782607 2026] [security2:error] [pid 147647:tid 147807] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/bypass.php"] [unique_id "amuymu_ioCvBERk4wq-Y9gAAASg"]
[Thu Jul 30 15:22:50.893510 2026] [security2:error] [pid 147647:tid 147877] [client 20.63.98.115:25794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/uploads/index.php"] [unique_id "amuymu_ioCvBERk4wq-Y-gAAAW4"]
[Thu Jul 30 15:22:51.001361 2026] [security2:error] [pid 147647:tid 147683] [remote 57.141.0.28:47868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuym-_ioCvBERk4wq-ZAQABbSM"]
[Thu Jul 30 15:22:51.012428 2026] [security2:error] [pid 147647:tid 147832] [client 99.225.16.200:50718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amuymu_ioCvBERk4wq-Y_AABQRw"], referer: https://www.northyorksheridanmall.com/store/
[Thu Jul 30 15:22:51.014909 2026] [security2:error] [pid 147647:tid 147819] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/wp-admin/about.php"] [unique_id "amuym-_ioCvBERk4wq-ZAgAAATQ"]
[Thu Jul 30 15:22:51.015013 2026] [security2:error] [pid 147647:tid 147819] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/wp-admin/about.php"] [unique_id "amuym-_ioCvBERk4wq-ZAgAAATQ"]
[Thu Jul 30 15:22:51.051031 2026] [security2:error] [pid 147647:tid 147873] [client 20.215.218.234:60261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-includes/mailer.php"] [unique_id "amuym-_ioCvBERk4wq-ZAwAAAWo"]
[Thu Jul 30 15:22:51.051177 2026] [security2:error] [pid 147647:tid 147873] [client 20.215.218.234:60261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/wp-includes/mailer.php"] [unique_id "amuym-_ioCvBERk4wq-ZAwAAAWo"]
[Thu Jul 30 15:22:51.403919 2026] [security2:error] [pid 147647:tid 147898] [client 20.215.218.234:47360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ym.php"] [unique_id "amuym-_ioCvBERk4wq-ZDQAAAYM"]
[Thu Jul 30 15:22:51.404072 2026] [security2:error] [pid 147647:tid 147898] [client 20.215.218.234:47360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ym.php"] [unique_id "amuym-_ioCvBERk4wq-ZDQAAAYM"]
[Thu Jul 30 15:22:51.426366 2026] [core:notice] [pid 147647:tid 147881] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:51.429800 2026] [security2:error] [pid 147647:tid 147881] [client 66.249.79.8:46936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/article/download/8722/3474"] [unique_id "amuym-_ioCvBERk4wq-ZDwAAAXI"]
[Thu Jul 30 15:22:51.444906 2026] [security2:error] [pid 147647:tid 147885] [client 172.237.109.114:55632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuymu_ioCvBERk4wq-Y_QAAAXY"]
[Thu Jul 30 15:22:51.445740 2026] [autoindex:error] [pid 147647:tid 147847] [client 142.93.143.123:38090] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:22:51.685509 2026] [security2:error] [pid 147647:tid 147814] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/12.php"] [unique_id "amuym-_ioCvBERk4wq-ZGgAAAS8"]
[Thu Jul 30 15:22:51.685622 2026] [security2:error] [pid 147647:tid 147814] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/12.php"] [unique_id "amuym-_ioCvBERk4wq-ZGgAAAS8"]
[Thu Jul 30 15:22:51.819745 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:9956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfa1.php"] [unique_id "amuym-_ioCvBERk4wq-ZHgAAAV4"]
[Thu Jul 30 15:22:51.819838 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:9956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alfa1.php"] [unique_id "amuym-_ioCvBERk4wq-ZHgAAAV4"]
[Thu Jul 30 15:22:51.863896 2026] [security2:error] [pid 147647:tid 147710] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuym-_ioCvBERk4wq-ZIQABOD4"]
[Thu Jul 30 15:22:51.864069 2026] [security2:error] [pid 147647:tid 147823] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuym-_ioCvBERk4wq-ZIQABOD4"]
[Thu Jul 30 15:22:51.921655 2026] [security2:error] [pid 147647:tid 147848] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/nothing2.php"] [unique_id "amuym-_ioCvBERk4wq-ZJgAAAVE"]
[Thu Jul 30 15:22:51.921755 2026] [security2:error] [pid 147647:tid 147848] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/nothing2.php"] [unique_id "amuym-_ioCvBERk4wq-ZJgAAAVE"]
[Thu Jul 30 15:22:51.966823 2026] [security2:error] [pid 147647:tid 147834] [client 20.203.148.31:33767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amuym-_ioCvBERk4wq-ZJwAAAUM"]
[Thu Jul 30 15:22:52.040803 2026] [security2:error] [pid 147647:tid 147860] [client 20.63.98.115:25842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/13.php"] [unique_id "amuynO_ioCvBERk4wq-ZLAAAAV0"]
[Thu Jul 30 15:22:52.169242 2026] [security2:error] [pid 147647:tid 147831] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/media.php"] [unique_id "amuynO_ioCvBERk4wq-ZLQAAAUA"]
[Thu Jul 30 15:22:52.169392 2026] [security2:error] [pid 147647:tid 147831] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/media.php"] [unique_id "amuynO_ioCvBERk4wq-ZLQAAAUA"]
[Thu Jul 30 15:22:52.218290 2026] [security2:error] [pid 147647:tid 147781] [client 20.215.218.234:21712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/159.php"] [unique_id "amuynO_ioCvBERk4wq-ZLwAAAQ4"]
[Thu Jul 30 15:22:52.218425 2026] [security2:error] [pid 147647:tid 147781] [client 20.215.218.234:21712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/159.php"] [unique_id "amuynO_ioCvBERk4wq-ZLwAAAQ4"]
[Thu Jul 30 15:22:52.422929 2026] [security2:error] [pid 147647:tid 147816] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/file2.php"] [unique_id "amuynO_ioCvBERk4wq-ZOAAAATE"]
[Thu Jul 30 15:22:52.423049 2026] [security2:error] [pid 147647:tid 147816] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/file2.php"] [unique_id "amuynO_ioCvBERk4wq-ZOAAAATE"]
[Thu Jul 30 15:22:52.463255 2026] [security2:error] [pid 147647:tid 147839] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuym-_ioCvBERk4wq-ZIgAAAUg"]
[Thu Jul 30 15:22:52.491972 2026] [security2:error] [pid 147647:tid 147891] [client 172.237.109.114:17969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuynO_ioCvBERk4wq-ZKwAAAXw"]
[Thu Jul 30 15:22:52.622136 2026] [security2:error] [pid 147647:tid 147818] [client 74.7.228.23:60666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amuynO_ioCvBERk4wq-ZPQABMyk"]
[Thu Jul 30 15:22:52.626662 2026] [security2:error] [pid 147647:tid 147832] [client 20.215.218.234:9962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/tesla1.php"] [unique_id "amuynO_ioCvBERk4wq-ZPgAAAUE"]
[Thu Jul 30 15:22:52.626760 2026] [security2:error] [pid 147647:tid 147832] [client 20.215.218.234:9962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/tesla1.php"] [unique_id "amuynO_ioCvBERk4wq-ZPgAAAUE"]
[Thu Jul 30 15:22:52.664958 2026] [security2:error] [pid 147647:tid 147819] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/simple.php"] [unique_id "amuynO_ioCvBERk4wq-ZPwAAATQ"]
[Thu Jul 30 15:22:52.665079 2026] [security2:error] [pid 147647:tid 147819] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/simple.php"] [unique_id "amuynO_ioCvBERk4wq-ZPwAAATQ"]
[Thu Jul 30 15:22:52.829510 2026] [security2:error] [pid 147647:tid 147798] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuynO_ioCvBERk4wq-ZLgABH08"]
[Thu Jul 30 15:22:52.895557 2026] [security2:error] [pid 147647:tid 147857] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/mac.php"] [unique_id "amuynO_ioCvBERk4wq-ZQwAAAVo"]
[Thu Jul 30 15:22:52.895667 2026] [security2:error] [pid 147647:tid 147857] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/mac.php"] [unique_id "amuynO_ioCvBERk4wq-ZQwAAAVo"]
[Thu Jul 30 15:22:53.013357 2026] [security2:error] [pid 147647:tid 147824] [client 20.215.218.234:60254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/shadowx.php"] [unique_id "amuyne_ioCvBERk4wq-ZSAAAATk"]
[Thu Jul 30 15:22:53.013476 2026] [security2:error] [pid 147647:tid 147824] [client 20.215.218.234:60254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/shadowx.php"] [unique_id "amuyne_ioCvBERk4wq-ZSAAAATk"]
[Thu Jul 30 15:22:53.127271 2026] [security2:error] [pid 147647:tid 147802] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/install.php"] [unique_id "amuyne_ioCvBERk4wq-ZTwAAASM"]
[Thu Jul 30 15:22:53.127420 2026] [security2:error] [pid 147647:tid 147802] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/install.php"] [unique_id "amuyne_ioCvBERk4wq-ZTwAAASM"]
[Thu Jul 30 15:22:53.150597 2026] [core:notice] [pid 147647:tid 147897] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:53.359374 2026] [security2:error] [pid 147647:tid 147801] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/wsx.php"] [unique_id "amuyne_ioCvBERk4wq-ZWgAAASI"]
[Thu Jul 30 15:22:53.359490 2026] [security2:error] [pid 147647:tid 147801] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/wsx.php"] [unique_id "amuyne_ioCvBERk4wq-ZWgAAASI"]
[Thu Jul 30 15:22:53.380643 2026] [security2:error] [pid 147647:tid 147837] [client 20.215.218.234:20795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/hexor.php"] [unique_id "amuyne_ioCvBERk4wq-ZWwAAAUY"]
[Thu Jul 30 15:22:53.380761 2026] [security2:error] [pid 147647:tid 147837] [client 20.215.218.234:20795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/hexor.php"] [unique_id "amuyne_ioCvBERk4wq-ZWwAAAUY"]
[Thu Jul 30 15:22:53.445687 2026] [security2:error] [pid 147647:tid 147788] [client 20.63.98.115:25846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/inputs.php"] [unique_id "amuyne_ioCvBERk4wq-ZXAAAARU"]
[Thu Jul 30 15:22:53.595502 2026] [security2:error] [pid 147647:tid 147799] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/alfa.php"] [unique_id "amuyne_ioCvBERk4wq-ZYwAAASA"]
[Thu Jul 30 15:22:53.595634 2026] [security2:error] [pid 147647:tid 147799] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/alfa.php"] [unique_id "amuyne_ioCvBERk4wq-ZYwAAASA"]
[Thu Jul 30 15:22:53.620098 2026] [security2:error] [pid 147647:tid 147785] [client 40.77.167.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuyne_ioCvBERk4wq-ZVwAAARI"]
[Thu Jul 30 15:22:53.839733 2026] [security2:error] [pid 147647:tid 147864] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/dlu.php"] [unique_id "amuyne_ioCvBERk4wq-ZbQAAAWE"]
[Thu Jul 30 15:22:53.839878 2026] [security2:error] [pid 147647:tid 147864] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/dlu.php"] [unique_id "amuyne_ioCvBERk4wq-ZbQAAAWE"]
[Thu Jul 30 15:22:53.866812 2026] [security2:error] [pid 147647:tid 147865] [client 20.215.218.234:9973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/leaf.php"] [unique_id "amuyne_ioCvBERk4wq-ZbgAAAWI"]
[Thu Jul 30 15:22:53.866971 2026] [security2:error] [pid 147647:tid 147865] [client 20.215.218.234:9973] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/leaf.php"] [unique_id "amuyne_ioCvBERk4wq-ZbgAAAWI"]
[Thu Jul 30 15:22:53.902323 2026] [core:notice] [pid 147647:tid 147861] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:53.906131 2026] [security2:error] [pid 147647:tid 147861] [client 66.249.79.1:54751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/REFORMASI/article/view/2647"] [unique_id "amuyne_ioCvBERk4wq-ZZgAAAV4"]
[Thu Jul 30 15:22:53.966793 2026] [security2:error] [pid 147647:tid 147794] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyne_ioCvBERk4wq-ZWAABG0s"]
[Thu Jul 30 15:22:54.080716 2026] [security2:error] [pid 147647:tid 147880] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/f6.php"] [unique_id "amuynu_ioCvBERk4wq-ZegAAAXE"]
[Thu Jul 30 15:22:54.080852 2026] [security2:error] [pid 147647:tid 147880] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/f6.php"] [unique_id "amuynu_ioCvBERk4wq-ZegAAAXE"]
[Thu Jul 30 15:22:54.225219 2026] [security2:error] [pid 147647:tid 147835] [client 20.215.218.234:63509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/FoxWSOv1.php"] [unique_id "amuynu_ioCvBERk4wq-ZfgAAAUQ"]
[Thu Jul 30 15:22:54.225366 2026] [security2:error] [pid 147647:tid 147835] [client 20.215.218.234:63509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/FoxWSOv1.php"] [unique_id "amuynu_ioCvBERk4wq-ZfgAAAUQ"]
[Thu Jul 30 15:22:54.321334 2026] [security2:error] [pid 147647:tid 147899] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/0x.php"] [unique_id "amuynu_ioCvBERk4wq-ZgwAAAYQ"]
[Thu Jul 30 15:22:54.321480 2026] [security2:error] [pid 147647:tid 147899] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/0x.php"] [unique_id "amuynu_ioCvBERk4wq-ZgwAAAYQ"]
[Thu Jul 30 15:22:54.417476 2026] [core:notice] [pid 147647:tid 147728] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:54.421868 2026] [security2:error] [pid 147647:tid 147855] [client 66.249.74.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/226/220"] [unique_id "amuynu_ioCvBERk4wq-ZewABWFA"]
[Thu Jul 30 15:22:54.428463 2026] [security2:error] [pid 147647:tid 147819] [client 20.63.98.115:25845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/jquery.php"] [unique_id "amuynu_ioCvBERk4wq-ZiAAAATQ"]
[Thu Jul 30 15:22:54.527956 2026] [security2:error] [pid 147647:tid 147891] [client 172.237.109.114:63039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyne_ioCvBERk4wq-ZcAAAAXw"]
[Thu Jul 30 15:22:54.568349 2026] [security2:error] [pid 147647:tid 147825] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/geck.php"] [unique_id "amuynu_ioCvBERk4wq-ZlAAAATo"]
[Thu Jul 30 15:22:54.568457 2026] [security2:error] [pid 147647:tid 147825] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/geck.php"] [unique_id "amuynu_ioCvBERk4wq-ZlAAAATo"]
[Thu Jul 30 15:22:54.691234 2026] [security2:error] [pid 147647:tid 147853] [client 20.215.218.234:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/foxwsov1.php"] [unique_id "amuynu_ioCvBERk4wq-ZmgAAAVY"]
[Thu Jul 30 15:22:54.691341 2026] [security2:error] [pid 147647:tid 147853] [client 20.215.218.234:63546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/foxwsov1.php"] [unique_id "amuynu_ioCvBERk4wq-ZmgAAAVY"]
[Thu Jul 30 15:22:54.821607 2026] [security2:error] [pid 147647:tid 147862] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/8.php"] [unique_id "amuynu_ioCvBERk4wq-ZoQAAAV8"]
[Thu Jul 30 15:22:54.821747 2026] [security2:error] [pid 147647:tid 147862] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/8.php"] [unique_id "amuynu_ioCvBERk4wq-ZoQAAAV8"]
[Thu Jul 30 15:22:54.872489 2026] [security2:error] [pid 147647:tid 147809] [client 20.203.148.31:31761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amuynu_ioCvBERk4wq-ZogAAASo"]
[Thu Jul 30 15:22:55.066403 2026] [security2:error] [pid 147647:tid 147789] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/133.php"] [unique_id "amuyn-_ioCvBERk4wq-ZqgAAARY"]
[Thu Jul 30 15:22:55.066523 2026] [security2:error] [pid 147647:tid 147789] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/133.php"] [unique_id "amuyn-_ioCvBERk4wq-ZqgAAARY"]
[Thu Jul 30 15:22:55.158659 2026] [security2:error] [pid 147647:tid 147791] [client 20.215.218.234:9963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/FoxWSOv2.php"] [unique_id "amuyn-_ioCvBERk4wq-ZrgAAARg"]
[Thu Jul 30 15:22:55.158820 2026] [security2:error] [pid 147647:tid 147791] [client 20.215.218.234:9963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/FoxWSOv2.php"] [unique_id "amuyn-_ioCvBERk4wq-ZrgAAARg"]
[Thu Jul 30 15:22:55.301679 2026] [security2:error] [pid 147647:tid 147900] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/11.php"] [unique_id "amuyn-_ioCvBERk4wq-ZsAAAAYU"]
[Thu Jul 30 15:22:55.301798 2026] [security2:error] [pid 147647:tid 147900] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/11.php"] [unique_id "amuyn-_ioCvBERk4wq-ZsAAAAYU"]
[Thu Jul 30 15:22:55.515052 2026] [security2:error] [pid 147647:tid 147867] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuynu_ioCvBERk4wq-ZmQABZEI"]
[Thu Jul 30 15:22:55.533599 2026] [security2:error] [pid 147647:tid 147806] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/3.php"] [unique_id "amuyn-_ioCvBERk4wq-ZtAAAASc"]
[Thu Jul 30 15:22:55.533710 2026] [security2:error] [pid 147647:tid 147806] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/3.php"] [unique_id "amuyn-_ioCvBERk4wq-ZtAAAASc"]
[Thu Jul 30 15:22:55.749742 2026] [security2:error] [pid 147647:tid 147880] [client 20.215.218.234:21754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/foxwsov2.php"] [unique_id "amuyn-_ioCvBERk4wq-ZxAAAAXE"]
[Thu Jul 30 15:22:55.749835 2026] [security2:error] [pid 147647:tid 147880] [client 20.215.218.234:21754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/foxwsov2.php"] [unique_id "amuyn-_ioCvBERk4wq-ZxAAAAXE"]
[Thu Jul 30 15:22:56.201269 2026] [security2:error] [pid 147647:tid 147803] [client 20.215.218.234:60594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/shellx.php"] [unique_id "amuyoO_ioCvBERk4wq-ZzAAAASQ"]
[Thu Jul 30 15:22:56.201401 2026] [security2:error] [pid 147647:tid 147803] [client 20.215.218.234:60594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/shellx.php"] [unique_id "amuyoO_ioCvBERk4wq-ZzAAAASQ"]
[Thu Jul 30 15:22:56.226686 2026] [core:notice] [pid 147647:tid 147779] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:56.230271 2026] [security2:error] [pid 147647:tid 147779] [client 66.249.79.8:64403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/download/7527/3010"] [unique_id "amuyoO_ioCvBERk4wq-ZzwAAAQw"]
[Thu Jul 30 15:22:56.384507 2026] [security2:error] [pid 147647:tid 147885] [client 82.102.18.188:46136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuyoO_ioCvBERk4wq-Z1AAAAXY"]
[Thu Jul 30 15:22:56.572242 2026] [security2:error] [pid 147647:tid 147788] [client 20.215.218.234:60233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/1index.php"] [unique_id "amuyoO_ioCvBERk4wq-Z2AAAARU"]
[Thu Jul 30 15:22:56.572378 2026] [security2:error] [pid 147647:tid 147788] [client 20.215.218.234:60233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/1index.php"] [unique_id "amuyoO_ioCvBERk4wq-Z2AAAARU"]
[Thu Jul 30 15:22:56.602913 2026] [security2:error] [pid 147647:tid 147856] [client 158.158.76.106:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.echomemoversalain.casa"] [uri "/1.php"] [unique_id "amuyoO_ioCvBERk4wq-Z3AAAAVk"]
[Thu Jul 30 15:22:56.603040 2026] [security2:error] [pid 147647:tid 147856] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/1.php"] [unique_id "amuyoO_ioCvBERk4wq-Z3AAAAVk"]
[Thu Jul 30 15:22:56.603145 2026] [security2:error] [pid 147647:tid 147856] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/1.php"] [unique_id "amuyoO_ioCvBERk4wq-Z3AAAAVk"]
[Thu Jul 30 15:22:56.750883 2026] [security2:error] [pid 147647:tid 147894] [client 20.63.98.115:22207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/doc.php"] [unique_id "amuyoO_ioCvBERk4wq-Z5AAAAX8"]
[Thu Jul 30 15:22:56.849117 2026] [security2:error] [pid 147647:tid 147785] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/ouh.php"] [unique_id "amuyoO_ioCvBERk4wq-Z5wAAARI"]
[Thu Jul 30 15:22:56.849220 2026] [security2:error] [pid 147647:tid 147785] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/ouh.php"] [unique_id "amuyoO_ioCvBERk4wq-Z5wAAARI"]
[Thu Jul 30 15:22:56.926475 2026] [security2:error] [pid 147647:tid 147842] [client 82.102.18.188:46144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.parkingandtransport.com"] [uri "/xmlrpc.php"] [unique_id "amuyoO_ioCvBERk4wq-Z6gAAAUs"]
[Thu Jul 30 15:22:56.937860 2026] [security2:error] [pid 147647:tid 147852] [client 20.215.218.234:60285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/2index.php"] [unique_id "amuyoO_ioCvBERk4wq-Z7AAAAVU"]
[Thu Jul 30 15:22:56.938002 2026] [security2:error] [pid 147647:tid 147852] [client 20.215.218.234:60285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/2index.php"] [unique_id "amuyoO_ioCvBERk4wq-Z7AAAAVU"]
[Thu Jul 30 15:22:57.092433 2026] [security2:error] [pid 147647:tid 147904] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/ioxi-o.php"] [unique_id "amuyoe_ioCvBERk4wq-Z7QAAAYk"]
[Thu Jul 30 15:22:57.092544 2026] [security2:error] [pid 147647:tid 147904] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/ioxi-o.php"] [unique_id "amuyoe_ioCvBERk4wq-Z7QAAAYk"]
[Thu Jul 30 15:22:57.340424 2026] [security2:error] [pid 147647:tid 147794] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/ar.php"] [unique_id "amuyoe_ioCvBERk4wq-Z9AAAARs"]
[Thu Jul 30 15:22:57.340537 2026] [security2:error] [pid 147647:tid 147794] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/ar.php"] [unique_id "amuyoe_ioCvBERk4wq-Z9AAAARs"]
[Thu Jul 30 15:22:57.343785 2026] [security2:error] [pid 147647:tid 147876] [client 20.215.218.234:64081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/3index.php"] [unique_id "amuyoe_ioCvBERk4wq-Z9QAAAW0"]
[Thu Jul 30 15:22:57.343864 2026] [security2:error] [pid 147647:tid 147876] [client 20.215.218.234:64081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/3index.php"] [unique_id "amuyoe_ioCvBERk4wq-Z9QAAAW0"]
[Thu Jul 30 15:22:57.475415 2026] [security2:error] [pid 147647:tid 147780] [client 66.249.79.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.shop-kent.com"] [uri "/index.php"] [unique_id "amuyoO_ioCvBERk4wq-Z4wAAAQ0"]
[Thu Jul 30 15:22:57.566604 2026] [core:notice] [pid 147647:tid 147854] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:57.577347 2026] [security2:error] [pid 147647:tid 147778] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/info.php"] [unique_id "amuyoe_ioCvBERk4wq-aAwAAAQs"]
[Thu Jul 30 15:22:57.577435 2026] [security2:error] [pid 147647:tid 147778] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/info.php"] [unique_id "amuyoe_ioCvBERk4wq-aAwAAAQs"]
[Thu Jul 30 15:22:57.592740 2026] [security2:error] [pid 147647:tid 147868] [client 62.102.148.162:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuyoe_ioCvBERk4wq-aBAAAAWU"]
[Thu Jul 30 15:22:57.592831 2026] [security2:error] [pid 147647:tid 147868] [client 62.102.148.162:56412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuyoe_ioCvBERk4wq-aBAAAAWU"]
[Thu Jul 30 15:22:57.635332 2026] [security2:error] [pid 147647:tid 147849] [client 82.102.18.188:46158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuyoe_ioCvBERk4wq-aBwAAAVI"]
[Thu Jul 30 15:22:57.759081 2026] [security2:error] [pid 147647:tid 147814] [client 20.215.218.234:9945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/4index.php"] [unique_id "amuyoe_ioCvBERk4wq-aCQAAAS8"]
[Thu Jul 30 15:22:57.759194 2026] [security2:error] [pid 147647:tid 147814] [client 20.215.218.234:9945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/4index.php"] [unique_id "amuyoe_ioCvBERk4wq-aCQAAAS8"]
[Thu Jul 30 15:22:57.827670 2026] [security2:error] [pid 147647:tid 147779] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/123.php"] [unique_id "amuyoe_ioCvBERk4wq-aDAAAAQw"]
[Thu Jul 30 15:22:57.827814 2026] [security2:error] [pid 147647:tid 147779] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/123.php"] [unique_id "amuyoe_ioCvBERk4wq-aDAAAAQw"]
[Thu Jul 30 15:22:58.079133 2026] [security2:error] [pid 147647:tid 147846] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/33.php"] [unique_id "amuyou_ioCvBERk4wq-aEQAAAU8"]
[Thu Jul 30 15:22:58.079243 2026] [security2:error] [pid 147647:tid 147846] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/33.php"] [unique_id "amuyou_ioCvBERk4wq-aEQAAAU8"]
[Thu Jul 30 15:22:58.108202 2026] [security2:error] [pid 147647:tid 147898] [client 20.63.98.115:33296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/02.php"] [unique_id "amuyou_ioCvBERk4wq-aEgAAAYM"]
[Thu Jul 30 15:22:58.158881 2026] [security2:error] [pid 147647:tid 147788] [client 20.215.218.234:21049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/5index.php"] [unique_id "amuyou_ioCvBERk4wq-aFQAAARU"]
[Thu Jul 30 15:22:58.158967 2026] [security2:error] [pid 147647:tid 147788] [client 20.215.218.234:21049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/5index.php"] [unique_id "amuyou_ioCvBERk4wq-aFQAAARU"]
[Thu Jul 30 15:22:58.317709 2026] [security2:error] [pid 147647:tid 147829] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/bak.php"] [unique_id "amuyou_ioCvBERk4wq-aGQAAAT4"]
[Thu Jul 30 15:22:58.317814 2026] [security2:error] [pid 147647:tid 147829] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/bak.php"] [unique_id "amuyou_ioCvBERk4wq-aGQAAAT4"]
[Thu Jul 30 15:22:58.420305 2026] [security2:error] [pid 147647:tid 147897] [client 82.102.18.188:46162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuyou_ioCvBERk4wq-aHgAAAYI"]
[Thu Jul 30 15:22:58.565488 2026] [security2:error] [pid 147647:tid 147900] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/term.php"] [unique_id "amuyou_ioCvBERk4wq-aJQAAAYU"]
[Thu Jul 30 15:22:58.565591 2026] [security2:error] [pid 147647:tid 147900] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/term.php"] [unique_id "amuyou_ioCvBERk4wq-aJQAAAYU"]
[Thu Jul 30 15:22:58.567689 2026] [security2:error] [pid 147647:tid 147831] [client 20.215.218.234:21749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/6index.php"] [unique_id "amuyou_ioCvBERk4wq-aJgAAAUA"]
[Thu Jul 30 15:22:58.567806 2026] [security2:error] [pid 147647:tid 147831] [client 20.215.218.234:21749] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/6index.php"] [unique_id "amuyou_ioCvBERk4wq-aJgAAAUA"]
[Thu Jul 30 15:22:58.738332 2026] [core:notice] [pid 147647:tid 147787] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:58.799656 2026] [security2:error] [pid 147647:tid 147827] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/opts.php"] [unique_id "amuyou_ioCvBERk4wq-aLgAAATw"]
[Thu Jul 30 15:22:58.799776 2026] [security2:error] [pid 147647:tid 147827] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/opts.php"] [unique_id "amuyou_ioCvBERk4wq-aLgAAATw"]
[Thu Jul 30 15:22:58.887628 2026] [core:notice] [pid 147647:tid 147794] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:58.958768 2026] [security2:error] [pid 147647:tid 147867] [client 82.102.18.188:46168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuyou_ioCvBERk4wq-aMwAAAWQ"]
[Thu Jul 30 15:22:58.986951 2026] [security2:error] [pid 147647:tid 147873] [client 20.215.218.234:9929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/7index.php"] [unique_id "amuyou_ioCvBERk4wq-aNAAAAWo"]
[Thu Jul 30 15:22:58.987103 2026] [security2:error] [pid 147647:tid 147873] [client 20.215.218.234:9929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/7index.php"] [unique_id "amuyou_ioCvBERk4wq-aNAAAAWo"]
[Thu Jul 30 15:22:59.275916 2026] [security2:error] [pid 147647:tid 147878] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/wkl.php"] [unique_id "amuyo-_ioCvBERk4wq-aPQAAAW8"]
[Thu Jul 30 15:22:59.276024 2026] [security2:error] [pid 147647:tid 147878] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/wkl.php"] [unique_id "amuyo-_ioCvBERk4wq-aPQAAAW8"]
[Thu Jul 30 15:22:59.404479 2026] [core:notice] [pid 147647:tid 147778] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:59.438767 2026] [security2:error] [pid 147647:tid 147811] [client 20.215.218.234:9924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/8index.php"] [unique_id "amuyo-_ioCvBERk4wq-aQQAAASw"]
[Thu Jul 30 15:22:59.438924 2026] [security2:error] [pid 147647:tid 147811] [client 20.215.218.234:9924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/8index.php"] [unique_id "amuyo-_ioCvBERk4wq-aQQAAASw"]
[Thu Jul 30 15:22:59.489282 2026] [security2:error] [pid 147647:tid 147798] [client 82.102.18.188:46178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuyo-_ioCvBERk4wq-aRQAAAR8"]
[Thu Jul 30 15:22:59.496814 2026] [security2:error] [pid 147647:tid 147837] [client 20.203.148.31:28422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amuyo-_ioCvBERk4wq-aRwAAAUY"]
[Thu Jul 30 15:22:59.509476 2026] [security2:error] [pid 147647:tid 147895] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/we.php"] [unique_id "amuyo-_ioCvBERk4wq-aSQAAAYA"]
[Thu Jul 30 15:22:59.509589 2026] [security2:error] [pid 147647:tid 147895] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/we.php"] [unique_id "amuyo-_ioCvBERk4wq-aSQAAAYA"]
[Thu Jul 30 15:22:59.611871 2026] [security2:error] [pid 147647:tid 147820] [client 172.237.109.114:1254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyo-_ioCvBERk4wq-aOAAAATU"]
[Thu Jul 30 15:22:59.684839 2026] [core:notice] [pid 147647:tid 147879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:22:59.735179 2026] [security2:error] [pid 147647:tid 147859] [client 172.237.109.114:6629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyo-_ioCvBERk4wq-aOQAAAVw"]
[Thu Jul 30 15:22:59.737254 2026] [security2:error] [pid 147647:tid 147899] [client 20.63.98.115:25801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/well-known/admin.php"] [unique_id "amuyo-_ioCvBERk4wq-aUQAAAYQ"]
[Thu Jul 30 15:22:59.746791 2026] [security2:error] [pid 147647:tid 147885] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/7.php"] [unique_id "amuyo-_ioCvBERk4wq-aUgAAAXY"]
[Thu Jul 30 15:22:59.746887 2026] [security2:error] [pid 147647:tid 147885] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/7.php"] [unique_id "amuyo-_ioCvBERk4wq-aUgAAAXY"]
[Thu Jul 30 15:22:59.867508 2026] [security2:error] [pid 147647:tid 147884] [client 20.215.218.234:21188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/9index.php"] [unique_id "amuyo-_ioCvBERk4wq-aUwAAAXU"]
[Thu Jul 30 15:22:59.867619 2026] [security2:error] [pid 147647:tid 147884] [client 20.215.218.234:21188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/9index.php"] [unique_id "amuyo-_ioCvBERk4wq-aUwAAAXU"]
[Thu Jul 30 15:22:59.984198 2026] [security2:error] [pid 147647:tid 147795] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/ls.php"] [unique_id "amuyo-_ioCvBERk4wq-aVwAAARw"]
[Thu Jul 30 15:22:59.984337 2026] [security2:error] [pid 147647:tid 147795] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/ls.php"] [unique_id "amuyo-_ioCvBERk4wq-aVwAAARw"]
[Thu Jul 30 15:23:00.027427 2026] [security2:error] [pid 147647:tid 147801] [client 82.102.18.188:46194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuypO_ioCvBERk4wq-aWAAAASI"]
[Thu Jul 30 15:23:00.200762 2026] [security2:error] [pid 147647:tid 147842] [client 20.215.218.234:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index4.php"] [unique_id "amuypO_ioCvBERk4wq-aXAAAAUs"]
[Thu Jul 30 15:23:00.200872 2026] [security2:error] [pid 147647:tid 147842] [client 20.215.218.234:62993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index4.php"] [unique_id "amuypO_ioCvBERk4wq-aXAAAAUs"]
[Thu Jul 30 15:23:00.220744 2026] [security2:error] [pid 147647:tid 147852] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/ant.php"] [unique_id "amuypO_ioCvBERk4wq-aXQAAAVU"]
[Thu Jul 30 15:23:00.220887 2026] [security2:error] [pid 147647:tid 147852] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/ant.php"] [unique_id "amuypO_ioCvBERk4wq-aXQAAAVU"]
[Thu Jul 30 15:23:00.323220 2026] [security2:error] [pid 147647:tid 147894] [client 20.203.148.31:38248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amuypO_ioCvBERk4wq-aYgAAAX8"]
[Thu Jul 30 15:23:00.463111 2026] [security2:error] [pid 147647:tid 147787] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/155.php"] [unique_id "amuypO_ioCvBERk4wq-aZgAAARQ"]
[Thu Jul 30 15:23:00.463257 2026] [security2:error] [pid 147647:tid 147787] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/155.php"] [unique_id "amuypO_ioCvBERk4wq-aZgAAARQ"]
[Thu Jul 30 15:23:00.538198 2026] [security2:error] [pid 147647:tid 147810] [client 20.215.218.234:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index5.php"] [unique_id "amuypO_ioCvBERk4wq-aaAAAASs"]
[Thu Jul 30 15:23:00.538307 2026] [security2:error] [pid 147647:tid 147810] [client 20.215.218.234:60274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index5.php"] [unique_id "amuypO_ioCvBERk4wq-aaAAAASs"]
[Thu Jul 30 15:23:00.553145 2026] [security2:error] [pid 147647:tid 147791] [client 82.102.18.188:46208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuypO_ioCvBERk4wq-aaQAAARg"]
[Thu Jul 30 15:23:00.710356 2026] [security2:error] [pid 147647:tid 147796] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/file9.php"] [unique_id "amuypO_ioCvBERk4wq-adAAAAR0"]
[Thu Jul 30 15:23:00.710476 2026] [security2:error] [pid 147647:tid 147796] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/file9.php"] [unique_id "amuypO_ioCvBERk4wq-adAAAAR0"]
[Thu Jul 30 15:23:00.865847 2026] [security2:error] [pid 147647:tid 147878] [client 20.63.98.115:25848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/v.php"] [unique_id "amuypO_ioCvBERk4wq-arwAAAW8"]
[Thu Jul 30 15:23:00.876121 2026] [security2:error] [pid 147647:tid 147849] [client 20.215.218.234:21199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index6.php"] [unique_id "amuypO_ioCvBERk4wq-atAAAAVI"]
[Thu Jul 30 15:23:00.876194 2026] [security2:error] [pid 147647:tid 147849] [client 20.215.218.234:21199] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index6.php"] [unique_id "amuypO_ioCvBERk4wq-atAAAAVI"]
[Thu Jul 30 15:23:00.942569 2026] [security2:error] [pid 147647:tid 147837] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/css.php"] [unique_id "amuypO_ioCvBERk4wq-atwAAAUY"]
[Thu Jul 30 15:23:00.942670 2026] [security2:error] [pid 147647:tid 147837] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/css.php"] [unique_id "amuypO_ioCvBERk4wq-atwAAAUY"]
[Thu Jul 30 15:23:01.084763 2026] [security2:error] [pid 147647:tid 147865] [client 82.102.18.188:46212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuype_ioCvBERk4wq-auwAAAWI"]
[Thu Jul 30 15:23:01.168997 2026] [security2:error] [pid 147647:tid 147808] [client 43.173.182.79:53486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/08/07/serviettes-rondes-the-beach-people/"] [unique_id "amuypO_ioCvBERk4wq-atQAAASk"]
[Thu Jul 30 15:23:01.176664 2026] [security2:error] [pid 147647:tid 147800] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/js.php"] [unique_id "amuype_ioCvBERk4wq-avQAAASE"]
[Thu Jul 30 15:23:01.176800 2026] [security2:error] [pid 147647:tid 147800] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/js.php"] [unique_id "amuype_ioCvBERk4wq-avQAAASE"]
[Thu Jul 30 15:23:01.214063 2026] [security2:error] [pid 147647:tid 147892] [client 20.215.218.234:21720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index7.php"] [unique_id "amuype_ioCvBERk4wq-awAAAAX0"]
[Thu Jul 30 15:23:01.214192 2026] [security2:error] [pid 147647:tid 147892] [client 20.215.218.234:21720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index7.php"] [unique_id "amuype_ioCvBERk4wq-awAAAAX0"]
[Thu Jul 30 15:23:01.424783 2026] [security2:error] [pid 147647:tid 147853] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/lock360.php"] [unique_id "amuype_ioCvBERk4wq-axAAAAVY"]
[Thu Jul 30 15:23:01.424934 2026] [security2:error] [pid 147647:tid 147853] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/lock360.php"] [unique_id "amuype_ioCvBERk4wq-axAAAAVY"]
[Thu Jul 30 15:23:01.620578 2026] [security2:error] [pid 147647:tid 147845] [client 82.102.18.188:46226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuype_ioCvBERk4wq-ayQAAAU4"]
[Thu Jul 30 15:23:01.660132 2026] [security2:error] [pid 147647:tid 147851] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/v.php"] [unique_id "amuype_ioCvBERk4wq-aygAAAVQ"]
[Thu Jul 30 15:23:01.660252 2026] [security2:error] [pid 147647:tid 147851] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/v.php"] [unique_id "amuype_ioCvBERk4wq-aygAAAVQ"]
[Thu Jul 30 15:23:01.826615 2026] [core:notice] [pid 147647:tid 147883] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:01.834425 2026] [security2:error] [pid 147647:tid 147883] [client 43.172.194.134:59502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/08/07/serviettes-rondes-the-beach-people/"] [unique_id "amuype_ioCvBERk4wq-a0wAAAXQ"], referer: https://carnetdeshopping.com/index.php/2015/08/07/serviettes-rondes-the-beach-people/
[Thu Jul 30 15:23:01.893260 2026] [security2:error] [pid 147647:tid 147805] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/pucci.php"] [unique_id "amuype_ioCvBERk4wq-a1QAAASY"]
[Thu Jul 30 15:23:01.893368 2026] [security2:error] [pid 147647:tid 147805] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/pucci.php"] [unique_id "amuype_ioCvBERk4wq-a1QAAASY"]
[Thu Jul 30 15:23:01.908085 2026] [security2:error] [pid 147647:tid 147884] [client 20.203.148.31:35508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amuype_ioCvBERk4wq-a1gAAAXU"]
[Thu Jul 30 15:23:02.009689 2026] [core:notice] [pid 147647:tid 147816] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:02.013492 2026] [security2:error] [pid 147647:tid 147816] [client 66.249.79.1:54751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/camic/article/download/9059/3896"] [unique_id "amuypu_ioCvBERk4wq-a3QAAATE"]
[Thu Jul 30 15:23:02.138871 2026] [security2:error] [pid 147647:tid 147806] [client 82.102.18.188:46232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuypu_ioCvBERk4wq-a4wAAASc"]
[Thu Jul 30 15:23:02.139697 2026] [security2:error] [pid 147647:tid 147890] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/file4.php"] [unique_id "amuypu_ioCvBERk4wq-a5AAAAXs"]
[Thu Jul 30 15:23:02.139782 2026] [security2:error] [pid 147647:tid 147890] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/file4.php"] [unique_id "amuypu_ioCvBERk4wq-a5AAAAXs"]
[Thu Jul 30 15:23:02.179587 2026] [security2:error] [pid 147647:tid 147813] [client 20.215.218.234:9967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index8.php"] [unique_id "amuypu_ioCvBERk4wq-a5gAAAS4"]
[Thu Jul 30 15:23:02.179704 2026] [security2:error] [pid 147647:tid 147813] [client 20.215.218.234:9967] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index8.php"] [unique_id "amuypu_ioCvBERk4wq-a5gAAAS4"]
[Thu Jul 30 15:23:02.375490 2026] [security2:error] [pid 147647:tid 147895] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/222.php"] [unique_id "amuypu_ioCvBERk4wq-a7gAAAYA"]
[Thu Jul 30 15:23:02.375620 2026] [security2:error] [pid 147647:tid 147895] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/222.php"] [unique_id "amuypu_ioCvBERk4wq-a7gAAAYA"]
[Thu Jul 30 15:23:02.384345 2026] [security2:error] [pid 147647:tid 147830] [client 20.63.98.115:58088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/main.php"] [unique_id "amuypu_ioCvBERk4wq-a7wAAAT8"]
[Thu Jul 30 15:23:02.570026 2026] [security2:error] [pid 147647:tid 147753] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuypu_ioCvBERk4wq-a8gABYWk"]
[Thu Jul 30 15:23:02.570236 2026] [security2:error] [pid 147647:tid 147864] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuypu_ioCvBERk4wq-a8gABYWk"]
[Thu Jul 30 15:23:02.611477 2026] [security2:error] [pid 147647:tid 147836] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/shellalfa.php"] [unique_id "amuypu_ioCvBERk4wq-a9gAAAUU"]
[Thu Jul 30 15:23:02.611631 2026] [security2:error] [pid 147647:tid 147836] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/shellalfa.php"] [unique_id "amuypu_ioCvBERk4wq-a9gAAAUU"]
[Thu Jul 30 15:23:02.654461 2026] [security2:error] [pid 147647:tid 147891] [client 20.203.148.31:35487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amuypu_ioCvBERk4wq-a9wAAAXw"]
[Thu Jul 30 15:23:02.665786 2026] [security2:error] [pid 147647:tid 147868] [client 82.102.18.188:46246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuypu_ioCvBERk4wq-a-AAAAWU"]
[Thu Jul 30 15:23:02.734406 2026] [security2:error] [pid 147647:tid 147791] [client 172.237.109.114:19603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuypu_ioCvBERk4wq-a5QAAARg"]
[Thu Jul 30 15:23:02.843448 2026] [security2:error] [pid 147647:tid 147885] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/aaa.php"] [unique_id "amuypu_ioCvBERk4wq-a_AAAAXY"]
[Thu Jul 30 15:23:02.843596 2026] [security2:error] [pid 147647:tid 147885] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/aaa.php"] [unique_id "amuypu_ioCvBERk4wq-a_AAAAXY"]
[Thu Jul 30 15:23:02.906331 2026] [core:notice] [pid 147647:tid 147850] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:02.921048 2026] [security2:error] [pid 147647:tid 147803] [client 46.232.235.4:48608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuypu_ioCvBERk4wq-bAQAAASQ"]
[Thu Jul 30 15:23:02.989882 2026] [security2:error] [pid 147647:tid 147824] [client 46.232.235.4:48624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-30643359.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuypu_ioCvBERk4wq-bAwAAATk"]
[Thu Jul 30 15:23:03.060583 2026] [security2:error] [pid 147647:tid 147729] [remote 57.141.0.61:36930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/514832250/feed/rss2/"] [unique_id "amuyp-_ioCvBERk4wq-bBAABhFE"]
[Thu Jul 30 15:23:03.079143 2026] [security2:error] [pid 147647:tid 147842] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/abcd.php"] [unique_id "amuyp-_ioCvBERk4wq-bBwAAAUs"]
[Thu Jul 30 15:23:03.079268 2026] [security2:error] [pid 147647:tid 147842] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/abcd.php"] [unique_id "amuyp-_ioCvBERk4wq-bBwAAAUs"]
[Thu Jul 30 15:23:03.100900 2026] [security2:error] [pid 147647:tid 147851] [client 46.232.235.4:48636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-e5e391bf.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuyp-_ioCvBERk4wq-bCQAAAVQ"]
[Thu Jul 30 15:23:03.104894 2026] [security2:error] [pid 147647:tid 147886] [client 20.215.218.234:64100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index9.php"] [unique_id "amuyp-_ioCvBERk4wq-bCgAAAXc"]
[Thu Jul 30 15:23:03.105032 2026] [security2:error] [pid 147647:tid 147886] [client 20.215.218.234:64100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/index9.php"] [unique_id "amuyp-_ioCvBERk4wq-bCgAAAXc"]
[Thu Jul 30 15:23:03.216108 2026] [security2:error] [pid 147647:tid 147833] [client 82.102.18.188:46254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuyp-_ioCvBERk4wq-bDAAAAUI"]
[Thu Jul 30 15:23:03.278622 2026] [security2:error] [pid 147647:tid 147807] [client 20.63.98.115:58105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/.well-known/file.php"] [unique_id "amuyp-_ioCvBERk4wq-bDQAAASg"]
[Thu Jul 30 15:23:03.312031 2026] [security2:error] [pid 147647:tid 147778] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/about.php"] [unique_id "amuyp-_ioCvBERk4wq-bDgAAAQs"]
[Thu Jul 30 15:23:03.312134 2026] [security2:error] [pid 147647:tid 147778] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/about.php"] [unique_id "amuyp-_ioCvBERk4wq-bDgAAAQs"]
[Thu Jul 30 15:23:03.452606 2026] [security2:error] [pid 147647:tid 147858] [client 46.232.235.4:48650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuyp-_ioCvBERk4wq-bFQAAAVs"]
[Thu Jul 30 15:23:03.465913 2026] [security2:error] [pid 147647:tid 147800] [client 193.228.57.14:58532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuypu_ioCvBERk4wq-bAgABIVc"]
[Thu Jul 30 15:23:03.510249 2026] [security2:error] [pid 147647:tid 147904] [client 20.215.218.234:20742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/indeex.php"] [unique_id "amuyp-_ioCvBERk4wq-bFwAAAYk"]
[Thu Jul 30 15:23:03.510331 2026] [security2:error] [pid 147647:tid 147904] [client 20.215.218.234:20742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/indeex.php"] [unique_id "amuyp-_ioCvBERk4wq-bFwAAAYk"]
[Thu Jul 30 15:23:03.546506 2026] [security2:error] [pid 147647:tid 147897] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/wsd.php"] [unique_id "amuyp-_ioCvBERk4wq-bGgAAAYI"]
[Thu Jul 30 15:23:03.546600 2026] [security2:error] [pid 147647:tid 147897] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/wsd.php"] [unique_id "amuyp-_ioCvBERk4wq-bGgAAAYI"]
[Thu Jul 30 15:23:03.741117 2026] [security2:error] [pid 147647:tid 147777] [client 82.102.18.188:46268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuyp-_ioCvBERk4wq-bHwAAAQo"]
[Thu Jul 30 15:23:03.747829 2026] [security2:error] [pid 147647:tid 147793] [client 20.203.148.31:28428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amuyp-_ioCvBERk4wq-bIAAAARo"]
[Thu Jul 30 15:23:03.810732 2026] [core:notice] [pid 147647:tid 147902] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:03.814178 2026] [security2:error] [pid 147647:tid 147902] [client 66.249.79.8:54378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3789"] [unique_id "amuyp-_ioCvBERk4wq-bIQAAAYc"]
[Thu Jul 30 15:23:03.985770 2026] [security2:error] [pid 147647:tid 147798] [client 20.215.218.234:20789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/jindex.php"] [unique_id "amuyp-_ioCvBERk4wq-bLAAAAR8"]
[Thu Jul 30 15:23:03.985882 2026] [security2:error] [pid 147647:tid 147798] [client 20.215.218.234:20789] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/jindex.php"] [unique_id "amuyp-_ioCvBERk4wq-bLAAAAR8"]
[Thu Jul 30 15:23:04.269643 2026] [security2:error] [pid 147647:tid 147855] [client 82.102.18.188:53276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuyqO_ioCvBERk4wq-bMQAAAVg"]
[Thu Jul 30 15:23:04.312325 2026] [security2:error] [pid 147647:tid 147875] [client 20.63.98.115:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/.well-known/pki-validation/index.php"] [unique_id "amuyqO_ioCvBERk4wq-bMgAAAWw"]
[Thu Jul 30 15:23:04.457790 2026] [security2:error] [pid 147647:tid 147853] [client 20.215.218.234:54758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/p0wny-shell.php"] [unique_id "amuyqO_ioCvBERk4wq-bTQAAAVY"]
[Thu Jul 30 15:23:04.457880 2026] [security2:error] [pid 147647:tid 147853] [client 20.215.218.234:54758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/p0wny-shell.php"] [unique_id "amuyqO_ioCvBERk4wq-bTQAAAVY"]
[Thu Jul 30 15:23:04.516009 2026] [security2:error] [pid 147647:tid 147880] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyp-_ioCvBERk4wq-bJwAAAXE"]
[Thu Jul 30 15:23:04.608550 2026] [core:error] [pid 147647:tid 147826] [client 46.232.235.4:48670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:04.608576 2026] [core:error] [pid 147647:tid 147826] [client 46.232.235.4:48670] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:04.747599 2026] [core:notice] [pid 147647:tid 147841] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:04.751113 2026] [security2:error] [pid 147647:tid 147841] [client 66.249.79.230:44301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/view/947/628"] [unique_id "amuyqO_ioCvBERk4wq-bTgAAAUo"]
[Thu Jul 30 15:23:04.765676 2026] [core:error] [pid 147647:tid 147825] [client 46.232.235.4:48672] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:04.765694 2026] [core:error] [pid 147647:tid 147825] [client 46.232.235.4:48672] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:04.804884 2026] [security2:error] [pid 147647:tid 147870] [client 82.102.18.188:53288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.parkingandtransport.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuyqO_ioCvBERk4wq-bVwAAAWc"]
[Thu Jul 30 15:23:04.836426 2026] [security2:error] [pid 147647:tid 147836] [client 20.203.148.31:28358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amuyqO_ioCvBERk4wq-bWAAAAUU"]
[Thu Jul 30 15:23:04.846350 2026] [core:error] [pid 147647:tid 147848] [client 46.232.235.4:48664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:04.846379 2026] [core:error] [pid 147647:tid 147848] [client 46.232.235.4:48664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:04.953777 2026] [core:error] [pid 147647:tid 147824] [client 46.232.235.4:48688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:04.953803 2026] [core:error] [pid 147647:tid 147824] [client 46.232.235.4:48688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:04.973677 2026] [core:notice] [pid 147647:tid 147831] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:05.089120 2026] [security2:error] [pid 147647:tid 147812] [client 20.215.218.234:54730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ex0shell.php"] [unique_id "amuyqe_ioCvBERk4wq-bYwAAAS0"]
[Thu Jul 30 15:23:05.089220 2026] [security2:error] [pid 147647:tid 147812] [client 20.215.218.234:54730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/ex0shell.php"] [unique_id "amuyqe_ioCvBERk4wq-bYwAAAS0"]
[Thu Jul 30 15:23:05.314141 2026] [security2:error] [pid 147647:tid 147860] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyqO_ioCvBERk4wq-bVQAAAV0"]
[Thu Jul 30 15:23:05.513249 2026] [security2:error] [pid 147647:tid 147784] [client 20.171.55.167:7256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/.fk.php"] [unique_id "amuyqe_ioCvBERk4wq-bdwAAARE"]
[Thu Jul 30 15:23:05.662013 2026] [core:notice] [pid 147647:tid 147839] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:05.664948 2026] [security2:error] [pid 147647:tid 147839] [client 66.249.79.230:44301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/7891/3368"] [unique_id "amuyqe_ioCvBERk4wq-bgAAAAUg"]
[Thu Jul 30 15:23:05.688728 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:54761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/exp.php"] [unique_id "amuyqe_ioCvBERk4wq-bggAAAV4"]
[Thu Jul 30 15:23:05.688844 2026] [security2:error] [pid 147647:tid 147861] [client 20.215.218.234:54761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/exp.php"] [unique_id "amuyqe_ioCvBERk4wq-bggAAAV4"]
[Thu Jul 30 15:23:05.929734 2026] [autoindex:error] [pid 147647:tid 147895] [client 34.224.175.62:1750] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:23:05.929818 2026] [autoindex:error] [pid 147647:tid 147866] [client 34.233.129.35:39874] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:23:06.191878 2026] [security2:error] [pid 147647:tid 147818] [client 207.46.13.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.glowspakarachi.site"] [uri "/index.php"] [unique_id "amuyqe_ioCvBERk4wq-bewABMyI"]
[Thu Jul 30 15:23:06.220855 2026] [security2:error] [pid 147647:tid 147819] [client 20.171.55.167:7246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/098.php"] [unique_id "amuyqu_ioCvBERk4wq-bmwAAATQ"]
[Thu Jul 30 15:23:06.277420 2026] [security2:error] [pid 147647:tid 147896] [client 20.203.148.31:35485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amuyqu_ioCvBERk4wq-bnAAAAYE"]
[Thu Jul 30 15:23:06.373346 2026] [security2:error] [pid 147647:tid 147850] [client 20.215.218.234:60284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/pHpINJ.php"] [unique_id "amuyqu_ioCvBERk4wq-bnwAAAVM"]
[Thu Jul 30 15:23:06.373483 2026] [security2:error] [pid 147647:tid 147850] [client 20.215.218.234:60284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/pHpINJ.php"] [unique_id "amuyqu_ioCvBERk4wq-bnwAAAVM"]
[Thu Jul 30 15:23:06.395653 2026] [core:error] [pid 147647:tid 147826] [client 52.167.144.213:53668] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:06.395678 2026] [core:error] [pid 147647:tid 147826] [client 52.167.144.213:53668] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:06.407294 2026] [core:notice] [pid 147647:tid 147825] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:06.410650 2026] [security2:error] [pid 147647:tid 147825] [client 66.249.79.8:54378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/ELTERA/article/view/3180"] [unique_id "amuyqu_ioCvBERk4wq-bpAAAATo"]
[Thu Jul 30 15:23:06.577544 2026] [security2:error] [pid 147647:tid 147863] [client 172.237.109.114:65530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyqu_ioCvBERk4wq-bkwAAAWA"]
[Thu Jul 30 15:23:06.807555 2026] [core:notice] [pid 147647:tid 147831] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:06.959041 2026] [security2:error] [pid 147647:tid 147857] [client 20.203.148.31:40681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amuyqu_ioCvBERk4wq-bvAAAAVo"]
[Thu Jul 30 15:23:07.153160 2026] [security2:error] [pid 147647:tid 147781] [client 20.171.55.167:7295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/1945.php"] [unique_id "amuyq-_ioCvBERk4wq-bxwAAAQ4"]
[Thu Jul 30 15:23:07.421705 2026] [core:notice] [pid 147647:tid 147811] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:07.506119 2026] [security2:error] [pid 147647:tid 147902] [client 20.215.218.234:21745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/robot.php"] [unique_id "amuyq-_ioCvBERk4wq-b0AAAAYc"]
[Thu Jul 30 15:23:07.506218 2026] [security2:error] [pid 147647:tid 147902] [client 20.215.218.234:21745] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/robot.php"] [unique_id "amuyq-_ioCvBERk4wq-b0AAAAYc"]
[Thu Jul 30 15:23:07.726574 2026] [security2:error] [pid 147647:tid 147709] [remote 57.141.0.22:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuyq-_ioCvBERk4wq-b2QABZD0"]
[Thu Jul 30 15:23:08.086642 2026] [security2:error] [pid 147647:tid 147828] [client 20.171.55.167:7815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/2022/bidlbdgp.php"] [unique_id "amuyrO_ioCvBERk4wq-b5gAAAT0"]
[Thu Jul 30 15:23:08.087604 2026] [core:notice] [pid 147647:tid 147872] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:08.186918 2026] [security2:error] [pid 147647:tid 147896] [client 20.203.148.31:29708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amuyrO_ioCvBERk4wq-b6gAAAYE"]
[Thu Jul 30 15:23:08.469599 2026] [security2:error] [pid 147647:tid 147899] [client 20.215.218.234:21753] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "523"] [id "900207"] [msg "Sys[0-9]+ Mailer"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/sys32.php"] [unique_id "amuyrO_ioCvBERk4wq-b8wAAAYQ"]
[Thu Jul 30 15:23:08.469707 2026] [security2:error] [pid 147647:tid 147899] [client 20.215.218.234:21753] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/sys32.php"] [unique_id "amuyrO_ioCvBERk4wq-b8wAAAYQ"]
[Thu Jul 30 15:23:08.494883 2026] [security2:error] [pid 147647:tid 147820] [client 193.228.57.6:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyrO_ioCvBERk4wq-b4AABNSY"]
[Thu Jul 30 15:23:08.537574 2026] [core:notice] [pid 147647:tid 147833] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:08.789109 2026] [security2:error] [pid 147647:tid 147894] [client 20.171.55.167:7817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/400.php"] [unique_id "amuyrO_ioCvBERk4wq-cAgAAAX8"]
[Thu Jul 30 15:23:09.211889 2026] [security2:error] [pid 147647:tid 147778] [client 20.203.148.31:28438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amuyre_ioCvBERk4wq-cGQAAAQs"]
[Thu Jul 30 15:23:09.550992 2026] [security2:error] [pid 147647:tid 147902] [client 20.171.55.167:7641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/6.php"] [unique_id "amuyre_ioCvBERk4wq-cKgAAAYc"]
[Thu Jul 30 15:23:09.671234 2026] [security2:error] [pid 147647:tid 147904] [client 20.215.218.234:64084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/simple_cmd.php"] [unique_id "amuyre_ioCvBERk4wq-cMQAAAYk"]
[Thu Jul 30 15:23:09.671373 2026] [security2:error] [pid 147647:tid 147904] [client 20.215.218.234:64084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/simple_cmd.php"] [unique_id "amuyre_ioCvBERk4wq-cMQAAAYk"]
[Thu Jul 30 15:23:09.750500 2026] [security2:error] [pid 147647:tid 147793] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyre_ioCvBERk4wq-cEgAAARo"]
[Thu Jul 30 15:23:09.832027 2026] [security2:error] [pid 147647:tid 147860] [client 46.232.235.4:48702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuyre_ioCvBERk4wq-cNgAAAV0"]
[Thu Jul 30 15:23:09.841457 2026] [core:notice] [pid 147647:tid 147802] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:09.845477 2026] [security2:error] [pid 147647:tid 147802] [client 66.249.79.229:54142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/361/513"] [unique_id "amuyre_ioCvBERk4wq-cOAAAASM"]
[Thu Jul 30 15:23:09.903036 2026] [security2:error] [pid 147647:tid 147898] [client 20.63.98.115:25892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "amuyre_ioCvBERk4wq-cPQAAAYM"]
[Thu Jul 30 15:23:09.926488 2026] [security2:error] [pid 147647:tid 147859] [client 46.232.235.4:48722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuyre_ioCvBERk4wq-cPgAAAVw"]
[Thu Jul 30 15:23:10.005738 2026] [security2:error] [pid 147647:tid 147821] [client 46.232.235.4:48714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-e5e391bf.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuyru_ioCvBERk4wq-cRgAAATY"]
[Thu Jul 30 15:23:10.011338 2026] [security2:error] [pid 147647:tid 147880] [client 46.232.235.4:48730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-35ddd216.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuyru_ioCvBERk4wq-cRwAAAXE"]
[Thu Jul 30 15:23:10.026788 2026] [security2:error] [pid 147647:tid 147838] [client 20.203.148.31:35880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amuyru_ioCvBERk4wq-cSAAAAUc"]
[Thu Jul 30 15:23:10.273210 2026] [security2:error] [pid 147647:tid 147870] [client 20.171.55.167:7824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ALFA_DATAalfa.php"] [unique_id "amuyru_ioCvBERk4wq-cUwAAAWc"]
[Thu Jul 30 15:23:10.377429 2026] [security2:error] [pid 147647:tid 147799] [client 74.7.228.5:42654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.jsc.fyv.temporary.site"] [uri "/index.php"] [unique_id "amuyrO_ioCvBERk4wq-b9gABIDg"]
[Thu Jul 30 15:23:10.698141 2026] [security2:error] [pid 147647:tid 147782] [client 20.215.218.234:63004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.218.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alpa.php"] [unique_id "amuyru_ioCvBERk4wq-cYQAAAQ8"]
[Thu Jul 30 15:23:10.698264 2026] [security2:error] [pid 147647:tid 147782] [client 20.215.218.234:63004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.montageluxuryhotel.com"] [uri "/alpa.php"] [unique_id "amuyru_ioCvBERk4wq-cYQAAAQ8"]
[Thu Jul 30 15:23:10.894874 2026] [core:notice] [pid 147647:tid 147830] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:10.941042 2026] [security2:error] [pid 147647:tid 147856] [client 193.228.57.6:12170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyru_ioCvBERk4wq-cWgABWRE"]
[Thu Jul 30 15:23:11.271339 2026] [security2:error] [pid 147647:tid 147832] [client 20.171.55.167:7287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/Content/Type/wp-login.php"] [unique_id "amuyr-_ioCvBERk4wq-ccAAAAUE"]
[Thu Jul 30 15:23:11.342920 2026] [security2:error] [pid 147647:tid 147789] [client 20.63.98.115:64612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/file.php"] [unique_id "amuyr-_ioCvBERk4wq-cfwAAARY"]
[Thu Jul 30 15:23:11.404987 2026] [autoindex:error] [pid 147647:tid 147804] [client 34.224.175.62:35892] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:23:11.432095 2026] [security2:error] [pid 147647:tid 147682] [remote 47.128.28.118:11680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/ro-black-white-2/"] [unique_id "amuyr-_ioCvBERk4wq-chwABaSI"]
[Thu Jul 30 15:23:11.556089 2026] [autoindex:error] [pid 147647:tid 147841] [client 82.102.18.188:43082] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:23:11.651772 2026] [core:notice] [pid 147647:tid 147880] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:11.696811 2026] [autoindex:error] [pid 147647:tid 147825] [client 82.102.18.188:43082] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:23:11.825585 2026] [security2:error] [pid 147647:tid 147896] [client 82.102.18.188:43082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuyr-_ioCvBERk4wq-csQAAAYE"]
[Thu Jul 30 15:23:12.028038 2026] [security2:error] [pid 147647:tid 147899] [client 20.171.55.167:7243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/Diff/about.php"] [unique_id "amuysO_ioCvBERk4wq-cuAAAAYQ"]
[Thu Jul 30 15:23:12.103802 2026] [security2:error] [pid 147647:tid 147852] [client 82.102.18.188:43092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.guethleentertainment.com"] [uri "/xmlrpc.php"] [unique_id "amuysO_ioCvBERk4wq-cuwAAAVU"]
[Thu Jul 30 15:23:12.382946 2026] [autoindex:error] [pid 147647:tid 147839] [client 82.102.18.188:43094] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:23:12.438269 2026] [core:error] [pid 147647:tid 147894] [client 46.232.235.4:53070] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:12.438301 2026] [core:error] [pid 147647:tid 147894] [client 46.232.235.4:53070] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:12.460188 2026] [core:error] [pid 147647:tid 147823] [client 46.232.235.4:53082] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:12.460219 2026] [core:error] [pid 147647:tid 147823] [client 46.232.235.4:53082] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:12.460848 2026] [security2:error] [pid 147647:tid 147807] [client 20.63.98.115:25773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-signup.php"] [unique_id "amuysO_ioCvBERk4wq-cywAAASg"]
[Thu Jul 30 15:23:12.486318 2026] [security2:error] [pid 147647:tid 147837] [client 172.237.109.114:19498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyr-_ioCvBERk4wq-ctwAAAUY"]
[Thu Jul 30 15:23:12.509897 2026] [core:error] [pid 147647:tid 147882] [client 46.232.235.4:53096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:12.509922 2026] [core:error] [pid 147647:tid 147882] [client 46.232.235.4:53096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:12.514681 2026] [security2:error] [pid 147647:tid 147780] [client 82.102.18.188:43094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuysO_ioCvBERk4wq-c2QAAAQ0"]
[Thu Jul 30 15:23:12.565412 2026] [security2:error] [pid 147647:tid 147870] [client 172.237.109.114:55114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyr-_ioCvBERk4wq-ctgAAAWc"]
[Thu Jul 30 15:23:12.731016 2026] [security2:error] [pid 147647:tid 147902] [client 20.171.55.167:7238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/I3zu2h.php"] [unique_id "amuysO_ioCvBERk4wq-c4QAAAYc"]
[Thu Jul 30 15:23:12.771686 2026] [security2:error] [pid 147647:tid 147845] [client 82.102.18.188:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuysO_ioCvBERk4wq-c4gAAAU4"]
[Thu Jul 30 15:23:12.806739 2026] [core:notice] [pid 147647:tid 147885] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:12.810183 2026] [security2:error] [pid 147647:tid 147885] [client 66.249.79.229:54142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jka/article/view/6874"] [unique_id "amuysO_ioCvBERk4wq-c4wAAAXY"]
[Thu Jul 30 15:23:12.891212 2026] [core:error] [pid 147647:tid 147793] [client 46.232.235.4:53104] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:12.891232 2026] [core:error] [pid 147647:tid 147793] [client 46.232.235.4:53104] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:13.044856 2026] [security2:error] [pid 147647:tid 147838] [client 82.102.18.188:43114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuyse_ioCvBERk4wq-c8AAAAUc"]
[Thu Jul 30 15:23:13.183869 2026] [security2:error] [pid 147647:tid 147715] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyse_ioCvBERk4wq-c8QABfEM"]
[Thu Jul 30 15:23:13.184040 2026] [security2:error] [pid 147647:tid 147891] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyse_ioCvBERk4wq-c8QABfEM"]
[Thu Jul 30 15:23:13.441703 2026] [security2:error] [pid 147647:tid 147896] [client 20.171.55.167:7272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/Mo2AaAaAaPrivateShell.php"] [unique_id "amuyse_ioCvBERk4wq-c_QAAAYE"]
[Thu Jul 30 15:23:13.700658 2026] [core:notice] [pid 147647:tid 147852] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:13.704093 2026] [security2:error] [pid 147647:tid 147852] [client 66.249.79.230:54424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/5347/3344"] [unique_id "amuyse_ioCvBERk4wq-dBwAAAVU"]
[Thu Jul 30 15:23:13.927585 2026] [core:notice] [pid 147647:tid 147823] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:13.930817 2026] [security2:error] [pid 147647:tid 147823] [client 66.249.79.229:54142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/download/654/406"] [unique_id "amuyse_ioCvBERk4wq-dEQAAATg"]
[Thu Jul 30 15:23:14.152965 2026] [security2:error] [pid 147647:tid 147786] [client 20.171.55.167:7232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/RxR_qpgqc.php"] [unique_id "amuysu_ioCvBERk4wq-dGwAAARM"]
[Thu Jul 30 15:23:14.308558 2026] [security2:error] [pid 147647:tid 147889] [client 82.102.18.188:36582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuysu_ioCvBERk4wq-dIAAAAXo"]
[Thu Jul 30 15:23:14.366927 2026] [core:notice] [pid 147647:tid 147847] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:14.429382 2026] [security2:error] [pid 147647:tid 147879] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/ab.php"] [unique_id "amuysu_ioCvBERk4wq-dJwAAAXA"]
[Thu Jul 30 15:23:14.429493 2026] [security2:error] [pid 147647:tid 147879] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/ab.php"] [unique_id "amuysu_ioCvBERk4wq-dJwAAAXA"]
[Thu Jul 30 15:23:14.673926 2026] [security2:error] [pid 147647:tid 147793] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/gt.php"] [unique_id "amuysu_ioCvBERk4wq-dMgAAARo"]
[Thu Jul 30 15:23:14.674044 2026] [security2:error] [pid 147647:tid 147793] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/gt.php"] [unique_id "amuysu_ioCvBERk4wq-dMgAAARo"]
[Thu Jul 30 15:23:14.873309 2026] [security2:error] [pid 147647:tid 147860] [client 20.171.55.167:7255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/Uploading.php"] [unique_id "amuysu_ioCvBERk4wq-dMwAAAV0"]
[Thu Jul 30 15:23:14.887612 2026] [core:notice] [pid 147647:tid 147881] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:14.925437 2026] [security2:error] [pid 147647:tid 147826] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/taff.php"] [unique_id "amuysu_ioCvBERk4wq-dOAAAATs"]
[Thu Jul 30 15:23:14.925589 2026] [security2:error] [pid 147647:tid 147826] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/taff.php"] [unique_id "amuysu_ioCvBERk4wq-dOAAAATs"]
[Thu Jul 30 15:23:15.065154 2026] [security2:error] [pid 147647:tid 147707] [remote 74.7.243.224:48370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/donatef.php"] [unique_id "amuys-_ioCvBERk4wq-dPgABZjs"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 15:23:15.159702 2026] [security2:error] [pid 147647:tid 147785] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/ee.php"] [unique_id "amuys-_ioCvBERk4wq-dQQAAARI"]
[Thu Jul 30 15:23:15.159861 2026] [security2:error] [pid 147647:tid 147785] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/ee.php"] [unique_id "amuys-_ioCvBERk4wq-dQQAAARI"]
[Thu Jul 30 15:23:15.410121 2026] [security2:error] [pid 147647:tid 147877] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/max.php"] [unique_id "amuys-_ioCvBERk4wq-dQgAAAW4"]
[Thu Jul 30 15:23:15.410236 2026] [security2:error] [pid 147647:tid 147877] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/max.php"] [unique_id "amuys-_ioCvBERk4wq-dQgAAAW4"]
[Thu Jul 30 15:23:15.585451 2026] [security2:error] [pid 147647:tid 147851] [client 20.171.55.167:7270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/a.php"] [unique_id "amuys-_ioCvBERk4wq-dQwAAAVQ"]
[Thu Jul 30 15:23:15.586622 2026] [security2:error] [pid 147647:tid 147867] [client 20.203.148.31:28461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amuys-_ioCvBERk4wq-dRAAAAWQ"]
[Thu Jul 30 15:23:15.590141 2026] [security2:error] [pid 147647:tid 147800] [client 82.102.18.188:36584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuys-_ioCvBERk4wq-dRQAAASE"]
[Thu Jul 30 15:23:15.643806 2026] [security2:error] [pid 147647:tid 147835] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/aa.php"] [unique_id "amuys-_ioCvBERk4wq-dRgAAAUQ"]
[Thu Jul 30 15:23:15.643910 2026] [security2:error] [pid 147647:tid 147835] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/aa.php"] [unique_id "amuys-_ioCvBERk4wq-dRgAAAUQ"]
[Thu Jul 30 15:23:15.779478 2026] [core:notice] [pid 147647:tid 147884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:15.816231 2026] [core:notice] [pid 147647:tid 147849] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:15.854490 2026] [security2:error] [pid 147647:tid 147806] [client 82.102.18.188:36596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuys-_ioCvBERk4wq-dSgAAASc"]
[Thu Jul 30 15:23:15.877695 2026] [security2:error] [pid 147647:tid 147822] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/system_log.php"] [unique_id "amuys-_ioCvBERk4wq-dSwAAATc"]
[Thu Jul 30 15:23:15.877796 2026] [security2:error] [pid 147647:tid 147822] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/system_log.php"] [unique_id "amuys-_ioCvBERk4wq-dSwAAATc"]
[Thu Jul 30 15:23:16.111910 2026] [security2:error] [pid 147647:tid 147861] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/201.php"] [unique_id "amuytO_ioCvBERk4wq-dTQAAAV4"]
[Thu Jul 30 15:23:16.112036 2026] [security2:error] [pid 147647:tid 147861] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/201.php"] [unique_id "amuytO_ioCvBERk4wq-dTQAAAV4"]
[Thu Jul 30 15:23:16.115812 2026] [security2:error] [pid 147647:tid 147833] [client 20.203.148.31:40738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amuytO_ioCvBERk4wq-dTgAAAUI"]
[Thu Jul 30 15:23:16.129622 2026] [security2:error] [pid 147647:tid 147839] [client 82.102.18.188:36608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuytO_ioCvBERk4wq-dTwAAAUg"]
[Thu Jul 30 15:23:16.347854 2026] [security2:error] [pid 147647:tid 147830] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/100.php"] [unique_id "amuytO_ioCvBERk4wq-dVgAAAT8"]
[Thu Jul 30 15:23:16.347958 2026] [security2:error] [pid 147647:tid 147830] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/100.php"] [unique_id "amuytO_ioCvBERk4wq-dVgAAAT8"]
[Thu Jul 30 15:23:16.360853 2026] [security2:error] [pid 147647:tid 147782] [client 20.171.55.167:7822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ace.php"] [unique_id "amuytO_ioCvBERk4wq-dVwAAAQ8"]
[Thu Jul 30 15:23:16.448163 2026] [security2:error] [pid 147647:tid 147871] [client 2a03:2880:f800:1e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuys-_ioCvBERk4wq-dTAABaHQ"]
[Thu Jul 30 15:23:16.495046 2026] [core:notice] [pid 147647:tid 147808] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:16.549828 2026] [core:notice] [pid 147647:tid 147844] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:16.592819 2026] [security2:error] [pid 147647:tid 147802] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/wp-blink.php"] [unique_id "amuytO_ioCvBERk4wq-dZAAAASM"]
[Thu Jul 30 15:23:16.592972 2026] [security2:error] [pid 147647:tid 147802] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/wp-blink.php"] [unique_id "amuytO_ioCvBERk4wq-dZAAAASM"]
[Thu Jul 30 15:23:16.629146 2026] [security2:error] [pid 147647:tid 147832] [client 82.102.18.188:36612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuytO_ioCvBERk4wq-dZwAAAUE"]
[Thu Jul 30 15:23:16.634894 2026] [security2:error] [pid 147647:tid 147870] [client 20.203.148.31:32029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amuytO_ioCvBERk4wq-dagAAAWc"]
[Thu Jul 30 15:23:16.702167 2026] [core:notice] [pid 147647:tid 147840] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:16.705824 2026] [security2:error] [pid 147647:tid 147840] [client 66.249.79.8:37892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/download/1509/893"] [unique_id "amuytO_ioCvBERk4wq-dXAAAAUk"]
[Thu Jul 30 15:23:16.798868 2026] [security2:error] [pid 147647:tid 147795] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuytO_ioCvBERk4wq-daAAAARw"]
[Thu Jul 30 15:23:16.834416 2026] [security2:error] [pid 147647:tid 147814] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/images.php"] [unique_id "amuytO_ioCvBERk4wq-dbgAAAS8"]
[Thu Jul 30 15:23:16.834520 2026] [security2:error] [pid 147647:tid 147814] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/images.php"] [unique_id "amuytO_ioCvBERk4wq-dbgAAAS8"]
[Thu Jul 30 15:23:16.927516 2026] [core:notice] [pid 147647:tid 147888] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:16.930567 2026] [security2:error] [pid 147647:tid 147888] [client 66.249.79.229:54142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/8865/3532"] [unique_id "amuytO_ioCvBERk4wq-ddQAAAXk"]
[Thu Jul 30 15:23:17.070153 2026] [security2:error] [pid 147647:tid 147804] [client 20.171.55.167:7262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/admin-post.php"] [unique_id "amuyte_ioCvBERk4wq-dfAAAASU"]
[Thu Jul 30 15:23:17.079071 2026] [security2:error] [pid 147647:tid 147851] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/fm.php"] [unique_id "amuyte_ioCvBERk4wq-dfQAAAVQ"]
[Thu Jul 30 15:23:17.079221 2026] [security2:error] [pid 147647:tid 147851] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/fm.php"] [unique_id "amuyte_ioCvBERk4wq-dfQAAAVQ"]
[Thu Jul 30 15:23:17.150103 2026] [security2:error] [pid 147647:tid 147800] [client 82.102.18.188:36622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuyte_ioCvBERk4wq-dfgAAASE"]
[Thu Jul 30 15:23:17.293971 2026] [security2:error] [pid 147647:tid 147887] [client 20.203.148.31:32044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amuyte_ioCvBERk4wq-dgwAAAXg"]
[Thu Jul 30 15:23:17.312546 2026] [security2:error] [pid 147647:tid 147831] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/rrr.php"] [unique_id "amuyte_ioCvBERk4wq-dhQAAAUA"]
[Thu Jul 30 15:23:17.312673 2026] [security2:error] [pid 147647:tid 147831] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/rrr.php"] [unique_id "amuyte_ioCvBERk4wq-dhQAAAUA"]
[Thu Jul 30 15:23:17.331461 2026] [core:notice] [pid 147647:tid 147769] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:17.341307 2026] [security2:error] [pid 147647:tid 147867] [client 20.63.98.115:26022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/css/index.php"] [unique_id "amuyte_ioCvBERk4wq-dhwAAAWQ"]
[Thu Jul 30 15:23:17.382022 2026] [core:notice] [pid 147647:tid 147810] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:17.423250 2026] [security2:error] [pid 147647:tid 147852] [client 82.102.18.188:36634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuyte_ioCvBERk4wq-dkQAAAVU"]
[Thu Jul 30 15:23:17.459452 2026] [security2:error] [pid 147647:tid 147834] [client 62.102.148.162:52320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuyte_ioCvBERk4wq-dkwAAAUM"]
[Thu Jul 30 15:23:17.459550 2026] [security2:error] [pid 147647:tid 147834] [client 62.102.148.162:52320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amuyte_ioCvBERk4wq-dkwAAAUM"]
[Thu Jul 30 15:23:17.549023 2026] [security2:error] [pid 147647:tid 147820] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/mail.php"] [unique_id "amuyte_ioCvBERk4wq-dlAAAATU"]
[Thu Jul 30 15:23:17.549168 2026] [security2:error] [pid 147647:tid 147820] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/mail.php"] [unique_id "amuyte_ioCvBERk4wq-dlAAAATU"]
[Thu Jul 30 15:23:17.587654 2026] [security2:error] [pid 147647:tid 147812] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuytO_ioCvBERk4wq-dewAAAS0"]
[Thu Jul 30 15:23:17.704093 2026] [security2:error] [pid 147647:tid 147853] [client 82.102.18.188:36640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuyte_ioCvBERk4wq-dmQAAAVY"]
[Thu Jul 30 15:23:17.792223 2026] [security2:error] [pid 147647:tid 147904] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/chosen.php"] [unique_id "amuyte_ioCvBERk4wq-dmgAAAYk"]
[Thu Jul 30 15:23:17.792335 2026] [security2:error] [pid 147647:tid 147904] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/chosen.php"] [unique_id "amuyte_ioCvBERk4wq-dmgAAAYk"]
[Thu Jul 30 15:23:17.805992 2026] [security2:error] [pid 147647:tid 147830] [client 20.171.55.167:7245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/adminwebalfa.php"] [unique_id "amuyte_ioCvBERk4wq-dmwAAAT8"]
[Thu Jul 30 15:23:17.878475 2026] [core:notice] [pid 147647:tid 147843] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:17.959600 2026] [security2:error] [pid 147647:tid 147879] [client 82.102.18.188:36652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuyte_ioCvBERk4wq-dowAAAXA"]
[Thu Jul 30 15:23:18.036473 2026] [security2:error] [pid 147647:tid 147898] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/doti.php"] [unique_id "amuytu_ioCvBERk4wq-dpwAAAYM"]
[Thu Jul 30 15:23:18.036568 2026] [security2:error] [pid 147647:tid 147898] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/doti.php"] [unique_id "amuytu_ioCvBERk4wq-dpwAAAYM"]
[Thu Jul 30 15:23:18.087089 2026] [core:notice] [pid 147647:tid 147878] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:18.231848 2026] [security2:error] [pid 147647:tid 147869] [client 82.102.18.188:36658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.guethleentertainment.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuytu_ioCvBERk4wq-dqwAAAWY"]
[Thu Jul 30 15:23:18.271892 2026] [security2:error] [pid 147647:tid 147826] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/x0.php"] [unique_id "amuytu_ioCvBERk4wq-drAAAATs"]
[Thu Jul 30 15:23:18.272028 2026] [security2:error] [pid 147647:tid 147826] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/x0.php"] [unique_id "amuytu_ioCvBERk4wq-drAAAATs"]
[Thu Jul 30 15:23:18.375679 2026] [core:notice] [pid 147647:tid 147883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:18.443789 2026] [security2:error] [pid 147647:tid 147845] [client 20.203.148.31:30608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfkurdistan.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amuytu_ioCvBERk4wq-dqgAAAU4"]
[Thu Jul 30 15:23:18.508112 2026] [security2:error] [pid 147647:tid 147897] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/bless.php"] [unique_id "amuytu_ioCvBERk4wq-duAAAAYI"]
[Thu Jul 30 15:23:18.508258 2026] [security2:error] [pid 147647:tid 147897] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/bless.php"] [unique_id "amuytu_ioCvBERk4wq-duAAAAYI"]
[Thu Jul 30 15:23:18.518158 2026] [security2:error] [pid 147647:tid 147825] [client 20.171.55.167:7276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/aksinet.php"] [unique_id "amuytu_ioCvBERk4wq-duQAAATo"]
[Thu Jul 30 15:23:18.622130 2026] [security2:error] [pid 147647:tid 147814] [client 172.237.109.114:56455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuytu_ioCvBERk4wq-dqQAAAS8"]
[Thu Jul 30 15:23:18.750494 2026] [security2:error] [pid 147647:tid 147790] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/cgi-bin/index.php"] [unique_id "amuytu_ioCvBERk4wq-dvQAAARc"]
[Thu Jul 30 15:23:18.750595 2026] [security2:error] [pid 147647:tid 147790] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/cgi-bin/index.php"] [unique_id "amuytu_ioCvBERk4wq-dvQAAARc"]
[Thu Jul 30 15:23:18.994230 2026] [security2:error] [pid 147647:tid 147855] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/size.php"] [unique_id "amuytu_ioCvBERk4wq-dxQAAAVg"]
[Thu Jul 30 15:23:18.994318 2026] [security2:error] [pid 147647:tid 147855] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/size.php"] [unique_id "amuytu_ioCvBERk4wq-dxQAAAVg"]
[Thu Jul 30 15:23:19.227107 2026] [security2:error] [pid 147647:tid 147854] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/lala.php"] [unique_id "amuyt-_ioCvBERk4wq-dygAAAVc"]
[Thu Jul 30 15:23:19.227214 2026] [security2:error] [pid 147647:tid 147854] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/lala.php"] [unique_id "amuyt-_ioCvBERk4wq-dygAAAVc"]
[Thu Jul 30 15:23:19.230313 2026] [security2:error] [pid 147647:tid 147852] [client 20.171.55.167:7810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/alfacgiapiadmin.php"] [unique_id "amuyt-_ioCvBERk4wq-dywAAAVU"]
[Thu Jul 30 15:23:19.462340 2026] [security2:error] [pid 147647:tid 147873] [client 158.158.76.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.76.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.echomemoversalain.casa"] [uri "/file1.php"] [unique_id "amuyt-_ioCvBERk4wq-d0QAAAWo"]
[Thu Jul 30 15:23:19.462470 2026] [security2:error] [pid 147647:tid 147873] [client 158.158.76.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.echomemoversalain.casa"] [uri "/file1.php"] [unique_id "amuyt-_ioCvBERk4wq-d0QAAAWo"]
[Thu Jul 30 15:23:19.671890 2026] [security2:error] [pid 147647:tid 147882] [client 134.19.179.195:58578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuyt-_ioCvBERk4wq-d1wAAAXM"]
[Thu Jul 30 15:23:19.672014 2026] [security2:error] [pid 147647:tid 147882] [client 134.19.179.195:58578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amuyt-_ioCvBERk4wq-d1wAAAXM"]
[Thu Jul 30 15:23:19.934048 2026] [security2:error] [pid 147647:tid 147842] [client 20.63.98.115:42237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ge.php"] [unique_id "amuyt-_ioCvBERk4wq-d2wAAAUs"]
[Thu Jul 30 15:23:20.077210 2026] [security2:error] [pid 147647:tid 147871] [client 20.171.55.167:7260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/all.php"] [unique_id "amuyuO_ioCvBERk4wq-d4gAAAWg"]
[Thu Jul 30 15:23:20.412227 2026] [core:notice] [pid 147647:tid 147685] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:20.862012 2026] [security2:error] [pid 147647:tid 147891] [client 20.171.55.167:7240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ap.php"] [unique_id "amuyuO_ioCvBERk4wq-d8QAAAXw"]
[Thu Jul 30 15:23:21.102538 2026] [core:notice] [pid 147647:tid 147809] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:21.200220 2026] [security2:error] [pid 147647:tid 147795] [client 38.172.162.57:16383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuyuO_ioCvBERk4wq-d8gAAARw"]
[Thu Jul 30 15:23:21.200427 2026] [security2:error] [pid 147647:tid 147795] [client 38.172.162.57:16383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuyuO_ioCvBERk4wq-d8gAAARw"]
[Thu Jul 30 15:23:21.580933 2026] [security2:error] [pid 147647:tid 147872] [client 20.171.55.167:7290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/archivarix.cms.php"] [unique_id "amuyue_ioCvBERk4wq-eCQAAAWk"]
[Thu Jul 30 15:23:21.765020 2026] [core:notice] [pid 147647:tid 147895] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:21.937729 2026] [security2:error] [pid 147647:tid 147778] [client 167.88.167.87:33632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bookario.com"] [uri "/"] [unique_id "amuyue_ioCvBERk4wq-eFQAAAQs"]
[Thu Jul 30 15:23:22.340784 2026] [security2:error] [pid 147647:tid 147802] [client 20.171.55.167:7251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/assetadmin.php"] [unique_id "amuyuu_ioCvBERk4wq-eIgAAASM"]
[Thu Jul 30 15:23:22.425829 2026] [security2:error] [pid 147647:tid 147780] [client 2a03:2880:f800:13:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyue_ioCvBERk4wq-eDwABDRY"]
[Thu Jul 30 15:23:22.577106 2026] [security2:error] [pid 147647:tid 147853] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyue_ioCvBERk4wq-eGAAAAVY"]
[Thu Jul 30 15:23:22.692464 2026] [security2:error] [pid 147647:tid 147892] [client 20.63.98.115:60509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/goods.php"] [unique_id "amuyuu_ioCvBERk4wq-eMAAAAX0"]
[Thu Jul 30 15:23:22.752923 2026] [security2:error] [pid 147647:tid 147740] [remote 112.78.134.58:41024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnpinyin.com"] [uri "/wp-login.php"] [unique_id "amuyuu_ioCvBERk4wq-eMQABW1w"]
[Thu Jul 30 15:23:22.878478 2026] [core:notice] [pid 147647:tid 147809] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:22.881906 2026] [security2:error] [pid 147647:tid 147809] [client 66.249.79.8:37892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/view/690/539"] [unique_id "amuyuu_ioCvBERk4wq-eMgAAASo"]
[Thu Jul 30 15:23:23.061596 2026] [security2:error] [pid 147647:tid 147848] [client 20.171.55.167:7919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/autoload_classmap.php"] [unique_id "amuyu-_ioCvBERk4wq-eOQAAAVE"]
[Thu Jul 30 15:23:23.404511 2026] [core:notice] [pid 147647:tid 147897] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:23.406900 2026] [core:notice] [pid 147647:tid 147827] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:23.408163 2026] [security2:error] [pid 147647:tid 147897] [client 45.147.133.161:50977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/7088"] [unique_id "amuyu-_ioCvBERk4wq-ePQAAAYI"]
[Thu Jul 30 15:23:23.818363 2026] [security2:error] [pid 147647:tid 147861] [client 20.171.55.167:7852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/b8b.php"] [unique_id "amuyu-_ioCvBERk4wq-eUAAAAV4"]
[Thu Jul 30 15:23:23.851203 2026] [core:notice] [pid 147647:tid 147813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:23.854729 2026] [security2:error] [pid 147647:tid 147813] [client 66.249.79.8:37892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/view/2943"] [unique_id "amuyu-_ioCvBERk4wq-eUQAAAS4"]
[Thu Jul 30 15:23:24.347867 2026] [core:notice] [pid 147647:tid 147885] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:24.452045 2026] [core:error] [pid 147647:tid 147695] [remote 216.73.216.186:19395] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:24.452070 2026] [core:error] [pid 147647:tid 147695] [remote 216.73.216.186:19395] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:24.531941 2026] [security2:error] [pid 147647:tid 147898] [client 20.171.55.167:7236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/bi.php"] [unique_id "amuyvO_ioCvBERk4wq-eYQAAAYM"]
[Thu Jul 30 15:23:25.179701 2026] [core:notice] [pid 147647:tid 147826] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:25.180093 2026] [security2:error] [pid 147647:tid 147859] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyvO_ioCvBERk4wq-eZAAAAVw"]
[Thu Jul 30 15:23:25.244508 2026] [security2:error] [pid 147647:tid 147896] [client 20.171.55.167:7935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/block-template-utils.php"] [unique_id "amuyve_ioCvBERk4wq-ecwAAAYE"]
[Thu Jul 30 15:23:25.460561 2026] [core:notice] [pid 147647:tid 147798] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:25.625427 2026] [security2:error] [pid 147647:tid 147804] [client 43.159.132.207:37146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.132.159.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuyve_ioCvBERk4wq-ebgAAASU"]
[Thu Jul 30 15:23:25.949109 2026] [security2:error] [pid 147647:tid 147797] [client 20.171.55.167:7849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/bowotod.php"] [unique_id "amuyve_ioCvBERk4wq-ehAAAAR4"]
[Thu Jul 30 15:23:26.365313 2026] [core:notice] [pid 147647:tid 147824] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:26.368679 2026] [security2:error] [pid 147647:tid 147824] [client 66.249.79.229:61620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JSHR/article/view/9495/4357"] [unique_id "amuyvu_ioCvBERk4wq-eiwAAATk"]
[Thu Jul 30 15:23:26.552555 2026] [security2:error] [pid 147647:tid 147882] [client 20.63.98.115:26401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/403.php"] [unique_id "amuyvu_ioCvBERk4wq-ekAAAAXM"]
[Thu Jul 30 15:23:26.653430 2026] [core:notice] [pid 147647:tid 147846] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:26.754133 2026] [security2:error] [pid 147647:tid 147844] [client 20.171.55.167:7905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/bypass403.php"] [unique_id "amuyvu_ioCvBERk4wq-ekgAAAU0"]
[Thu Jul 30 15:23:27.102090 2026] [core:notice] [pid 147647:tid 147817] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:27.105584 2026] [security2:error] [pid 147647:tid 147817] [client 66.249.79.229:61620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/4220"] [unique_id "amuyv-_ioCvBERk4wq-enAAAATI"]
[Thu Jul 30 15:23:27.539859 2026] [security2:error] [pid 147647:tid 147874] [client 20.171.55.167:7910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/calendar/index.php"] [unique_id "amuyv-_ioCvBERk4wq-epwAAAWs"]
[Thu Jul 30 15:23:27.595704 2026] [core:notice] [pid 147647:tid 147859] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:27.599287 2026] [security2:error] [pid 147647:tid 147859] [client 66.249.79.229:61620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/download/3613/3729"] [unique_id "amuyv-_ioCvBERk4wq-eqAAAAVw"]
[Thu Jul 30 15:23:27.738354 2026] [security2:error] [pid 147647:tid 147891] [client 20.63.98.115:49515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/public/makeasmtp.php"] [unique_id "amuyv-_ioCvBERk4wq-eqQAAAXw"]
[Thu Jul 30 15:23:27.990960 2026] [security2:error] [pid 147647:tid 147752] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyv-_ioCvBERk4wq-etQABDWg"]
[Thu Jul 30 15:23:27.991142 2026] [security2:error] [pid 147647:tid 147780] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyv-_ioCvBERk4wq-etQABDWg"]
[Thu Jul 30 15:23:28.050662 2026] [security2:error] [pid 147647:tid 147718] [remote 57.141.0.53:42978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amuywO_ioCvBERk4wq-etgABU0Y"]
[Thu Jul 30 15:23:28.237543 2026] [security2:error] [pid 147647:tid 147865] [client 193.228.57.14:47022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyv-_ioCvBERk4wq-eqgABYm8"]
[Thu Jul 30 15:23:28.257117 2026] [security2:error] [pid 147647:tid 147848] [client 20.171.55.167:7886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/cekidot/mar.php"] [unique_id "amuywO_ioCvBERk4wq-euwAAAVE"]
[Thu Jul 30 15:23:28.683378 2026] [core:notice] [pid 147647:tid 147889] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:28.690371 2026] [security2:error] [pid 147647:tid 147781] [client 20.63.98.115:26038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/mar.php"] [unique_id "amuywO_ioCvBERk4wq-eywAAAQ4"]
[Thu Jul 30 15:23:29.021901 2026] [security2:error] [pid 147647:tid 147824] [client 20.171.55.167:7882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/chosen-667.php"] [unique_id "amuywe_ioCvBERk4wq-e4wAAATk"]
[Thu Jul 30 15:23:29.152146 2026] [security2:error] [pid 147647:tid 147894] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuywO_ioCvBERk4wq-exwAAAX8"]
[Thu Jul 30 15:23:29.738921 2026] [security2:error] [pid 147647:tid 147900] [client 20.171.55.167:7252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/class-t.api.php"] [unique_id "amuywe_ioCvBERk4wq-e-AAAAYU"]
[Thu Jul 30 15:23:29.740880 2026] [security2:error] [pid 147647:tid 147825] [client 20.63.98.115:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/system.php"] [unique_id "amuywe_ioCvBERk4wq-e-QAAATo"]
[Thu Jul 30 15:23:29.842366 2026] [core:notice] [pid 147647:tid 147862] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:30.503886 2026] [security2:error] [pid 147647:tid 147792] [client 20.171.55.167:7235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/class-wp-image-editor.php"] [unique_id "amuywu_ioCvBERk4wq-fCAAAARk"]
[Thu Jul 30 15:23:31.141353 2026] [security2:error] [pid 147647:tid 147833] [client 52.32.240.62:48132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuywu_ioCvBERk4wq-fDwABQg8"]
[Thu Jul 30 15:23:31.216904 2026] [security2:error] [pid 147647:tid 147856] [client 20.171.55.167:7902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/class-wp-themeeses-json-main.php"] [unique_id "amuyw-_ioCvBERk4wq-fIgAAAVk"]
[Thu Jul 30 15:23:31.425368 2026] [security2:error] [pid 147647:tid 147897] [client 38.172.162.57:16054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuyw-_ioCvBERk4wq-fIwAAAYI"]
[Thu Jul 30 15:23:31.425506 2026] [security2:error] [pid 147647:tid 147897] [client 38.172.162.57:16054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuyw-_ioCvBERk4wq-fIwAAAYI"]
[Thu Jul 30 15:23:31.723527 2026] [core:notice] [pid 147647:tid 147788] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:32.115709 2026] [security2:error] [pid 147647:tid 147857] [client 20.63.98.115:60490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/lock360.php"] [unique_id "amuyxO_ioCvBERk4wq-fQwAAAVo"]
[Thu Jul 30 15:23:32.298811 2026] [core:notice] [pid 147647:tid 147892] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:32.366215 2026] [security2:error] [pid 147647:tid 147816] [client 20.171.55.167:7894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/cmd.php"] [unique_id "amuyxO_ioCvBERk4wq-fUQAAATE"]
[Thu Jul 30 15:23:32.385638 2026] [security2:error] [pid 147647:tid 147781] [client 2a03:2880:f800:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyw-_ioCvBERk4wq-fNgABDi0"]
[Thu Jul 30 15:23:32.618013 2026] [core:notice] [pid 147647:tid 147825] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:32.621663 2026] [security2:error] [pid 147647:tid 147825] [client 66.249.79.229:43378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/download/3832/1874"] [unique_id "amuyxO_ioCvBERk4wq-faQAAATo"]
[Thu Jul 30 15:23:32.638251 2026] [core:notice] [pid 147647:tid 147835] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:32.762355 2026] [core:notice] [pid 147647:tid 147805] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:32.849089 2026] [core:notice] [pid 147647:tid 147820] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:32.852482 2026] [security2:error] [pid 147647:tid 147820] [client 66.249.79.229:43378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA/article/download/4831/2358"] [unique_id "amuyxO_ioCvBERk4wq-fggAAATU"]
[Thu Jul 30 15:23:33.048037 2026] [security2:error] [pid 147647:tid 147812] [client 20.63.98.115:26037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "amuyxe_ioCvBERk4wq-fhQAAAS0"]
[Thu Jul 30 15:23:33.090826 2026] [security2:error] [pid 147647:tid 147864] [client 20.171.55.167:7278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/colors/blue/RxRrRoRuqS.php"] [unique_id "amuyxe_ioCvBERk4wq-fiQAAAWE"]
[Thu Jul 30 15:23:33.289446 2026] [core:notice] [pid 147647:tid 147844] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:33.645503 2026] [security2:error] [pid 147647:tid 147831] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyxe_ioCvBERk4wq-fhAABQFc"]
[Thu Jul 30 15:23:33.786655 2026] [core:notice] [pid 147647:tid 147903] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:33.790201 2026] [security2:error] [pid 147647:tid 147903] [client 66.249.79.8:37892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/download/9422/4197"] [unique_id "amuyxe_ioCvBERk4wq-fogAAAYg"]
[Thu Jul 30 15:23:33.797278 2026] [security2:error] [pid 147647:tid 147868] [client 20.171.55.167:7239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/colors/blue/plugins.php"] [unique_id "amuyxe_ioCvBERk4wq-fowAAAWU"]
[Thu Jul 30 15:23:34.290900 2026] [core:notice] [pid 147647:tid 147867] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:34.294460 2026] [security2:error] [pid 147647:tid 147867] [client 66.249.79.229:43378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/333/218"] [unique_id "amuyxu_ioCvBERk4wq-frwAAAWQ"]
[Thu Jul 30 15:23:34.318606 2026] [security2:error] [pid 147647:tid 147718] [remote 57.141.0.53:42994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/66784244892/feed/rss2/"] [unique_id "amuyxu_ioCvBERk4wq-fpwABEUY"]
[Thu Jul 30 15:23:34.577365 2026] [security2:error] [pid 147647:tid 147825] [client 20.171.55.167:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/colors/coffee/cloud.php"] [unique_id "amuyxu_ioCvBERk4wq-ftAAAATo"]
[Thu Jul 30 15:23:34.688708 2026] [core:notice] [pid 147647:tid 147871] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:34.781688 2026] [core:notice] [pid 147647:tid 147849] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:34.785184 2026] [security2:error] [pid 147647:tid 147849] [client 66.249.79.8:37892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/8081/3173"] [unique_id "amuyxu_ioCvBERk4wq-fxwAAAVI"]
[Thu Jul 30 15:23:35.138279 2026] [security2:error] [pid 147647:tid 147801] [client 47.128.57.165:53050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cmplboard.com"] [uri "/robots.txt"] [unique_id "amuyx-_ioCvBERk4wq-f0gAAASI"]
[Thu Jul 30 15:23:35.157550 2026] [security2:error] [pid 147647:tid 147666] [remote 57.141.0.15:60600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuyx-_ioCvBERk4wq-f0wABHhI"]
[Thu Jul 30 15:23:35.285789 2026] [core:notice] [pid 147647:tid 147813] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:35.291310 2026] [security2:error] [pid 147647:tid 147813] [client 66.249.79.229:43378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/3614/2116"] [unique_id "amuyx-_ioCvBERk4wq-f3wAAAS4"]
[Thu Jul 30 15:23:35.320078 2026] [security2:error] [pid 147647:tid 147809] [client 20.171.55.167:7897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/colors/ectoplasm/links.php"] [unique_id "amuyx-_ioCvBERk4wq-f4QAAASo"]
[Thu Jul 30 15:23:35.340406 2026] [security2:error] [pid 147647:tid 147719] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyx-_ioCvBERk4wq-f4gABYUc"]
[Thu Jul 30 15:23:35.340556 2026] [security2:error] [pid 147647:tid 147864] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuyx-_ioCvBERk4wq-f4gABYUc"]
[Thu Jul 30 15:23:35.983574 2026] [security2:error] [pid 147647:tid 147876] [client 20.63.98.115:48384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/mah.php"] [unique_id "amuyx-_ioCvBERk4wq-gAAAAAW0"]
[Thu Jul 30 15:23:36.051260 2026] [security2:error] [pid 147647:tid 147831] [client 20.171.55.167:7285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/colors/midnight/gmail.php"] [unique_id "amuyyO_ioCvBERk4wq-gAgAAAUA"]
[Thu Jul 30 15:23:36.251956 2026] [core:notice] [pid 147647:tid 147878] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:36.485911 2026] [core:notice] [pid 147647:tid 147865] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:36.798166 2026] [security2:error] [pid 147647:tid 147830] [client 20.171.55.167:7920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/colorsalfa.php"] [unique_id "amuyyO_ioCvBERk4wq-gGQAAAT8"]
[Thu Jul 30 15:23:36.933761 2026] [core:notice] [pid 147647:tid 147811] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:36.946341 2026] [core:error] [pid 147647:tid 147811] [client 66.249.79.229:43378] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:36.946553 2026] [security2:error] [pid 147647:tid 147811] [client 66.249.79.229:43378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/3974/2177.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuyyO_ioCvBERk4wq-gHQAAASw"]
[Thu Jul 30 15:23:37.132642 2026] [core:notice] [pid 147647:tid 147662] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:37.589660 2026] [security2:error] [pid 147647:tid 147797] [client 20.171.55.167:7823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/componentswp.php"] [unique_id "amuyye_ioCvBERk4wq-gLwAAAR4"]
[Thu Jul 30 15:23:37.699727 2026] [security2:error] [pid 147647:tid 147812] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuyye_ioCvBERk4wq-gIwAAAS0"]
[Thu Jul 30 15:23:37.836625 2026] [security2:error] [pid 147647:tid 147697] [remote 97.74.93.24:55182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuyye_ioCvBERk4wq-gMwABTzE"]
[Thu Jul 30 15:23:38.068427 2026] [core:notice] [pid 147647:tid 147903] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:38.323659 2026] [security2:error] [pid 147647:tid 147892] [client 20.171.55.167:7925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/content-management/content.php"] [unique_id "amuyyu_ioCvBERk4wq-gQQAAAX0"]
[Thu Jul 30 15:23:39.052689 2026] [security2:error] [pid 147647:tid 147842] [client 20.171.55.167:7835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/cot.php"] [unique_id "amuyy-_ioCvBERk4wq-gVQAAAUs"]
[Thu Jul 30 15:23:39.375532 2026] [core:notice] [pid 147647:tid 147806] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:39.379226 2026] [security2:error] [pid 147647:tid 147806] [client 66.249.79.229:64332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jibm/article/download/8415/3857"] [unique_id "amuyy-_ioCvBERk4wq-gWAAAASc"]
[Thu Jul 30 15:23:39.565621 2026] [security2:error] [pid 147647:tid 147734] [remote 57.141.0.21:27502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuyy-_ioCvBERk4wq-gYwABd1Y"]
[Thu Jul 30 15:23:39.606777 2026] [core:notice] [pid 147647:tid 147833] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:39.850282 2026] [security2:error] [pid 147647:tid 147823] [client 20.171.55.167:7893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/cux.php"] [unique_id "amuyy-_ioCvBERk4wq-gaAAAATg"]
[Thu Jul 30 15:23:40.336714 2026] [core:notice] [pid 147647:tid 147885] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:40.565862 2026] [security2:error] [pid 147647:tid 147788] [client 20.171.55.167:7909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/dav.php"] [unique_id "amuyzO_ioCvBERk4wq-gggAAARU"]
[Thu Jul 30 15:23:40.876962 2026] [core:notice] [pid 147647:tid 147784] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:40.880406 2026] [security2:error] [pid 147647:tid 147784] [client 66.249.79.8:37892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Caruban/article/view/8655"] [unique_id "amuyzO_ioCvBERk4wq-ghgAAARE"]
[Thu Jul 30 15:23:41.008799 2026] [security2:error] [pid 147647:tid 147701] [remote 57.141.0.63:31102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amuyze_ioCvBERk4wq-giwABWzU"]
[Thu Jul 30 15:23:41.234760 2026] [security2:error] [pid 147647:tid 147829] [client 78.47.98.55:14456] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amuyze_ioCvBERk4wq-glgAAAT4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:23:41.275766 2026] [security2:error] [pid 147647:tid 147844] [client 2a03:2880:f800:25:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuyzO_ioCvBERk4wq-gewABTVM"]
[Thu Jul 30 15:23:41.281549 2026] [security2:error] [pid 147647:tid 147840] [client 20.171.55.167:7927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/default.php"] [unique_id "amuyze_ioCvBERk4wq-glwAAAUk"]
[Thu Jul 30 15:23:41.325871 2026] [core:notice] [pid 147647:tid 147872] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:41.329565 2026] [security2:error] [pid 147647:tid 147872] [client 66.249.79.8:37892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/view/233"] [unique_id "amuyze_ioCvBERk4wq-gmAAAAWk"]
[Thu Jul 30 15:23:41.594566 2026] [core:notice] [pid 147647:tid 147868] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:41.598800 2026] [security2:error] [pid 147647:tid 147868] [client 78.47.98.55:14464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amuyze_ioCvBERk4wq-goQAAAWU"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:23:41.624922 2026] [security2:error] [pid 147647:tid 147850] [client 172.237.109.114:40481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuyze_ioCvBERk4wq-gkQAAAVM"]
[Thu Jul 30 15:23:41.822357 2026] [core:notice] [pid 147647:tid 147889] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:41.990936 2026] [security2:error] [pid 147647:tid 147809] [client 20.171.55.167:7820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/digital-download/up.php"] [unique_id "amuyze_ioCvBERk4wq-grwAAASo"]
[Thu Jul 30 15:23:41.997453 2026] [security2:error] [pid 147647:tid 147812] [client 78.47.98.55:14480] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amuyze_ioCvBERk4wq-grgAAAS0"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:23:41.999015 2026] [security2:error] [pid 147647:tid 147782] [client 38.172.162.57:16373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuyze_ioCvBERk4wq-gsQAAAQ8"]
[Thu Jul 30 15:23:41.999102 2026] [security2:error] [pid 147647:tid 147782] [client 38.172.162.57:16373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuyze_ioCvBERk4wq-gsQAAAQ8"]
[Thu Jul 30 15:23:42.060283 2026] [security2:error] [pid 147647:tid 147877] [client 20.63.98.115:29708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-class.php"] [unique_id "amuyzu_ioCvBERk4wq-gtwAAAW4"]
[Thu Jul 30 15:23:42.319702 2026] [core:notice] [pid 147647:tid 147790] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:42.323003 2026] [security2:error] [pid 147647:tid 147790] [client 66.249.79.8:37892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/article/view/4944/2325"] [unique_id "amuyzu_ioCvBERk4wq-gvwAAARc"]
[Thu Jul 30 15:23:42.344286 2026] [core:notice] [pid 147647:tid 147891] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:42.371504 2026] [core:notice] [pid 147647:tid 147878] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:42.757927 2026] [security2:error] [pid 147647:tid 147859] [client 20.171.55.167:7234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/dist/wp-login.php"] [unique_id "amuyzu_ioCvBERk4wq-gywAAAVw"]
[Thu Jul 30 15:23:43.009943 2026] [security2:error] [pid 147647:tid 147898] [client 20.63.98.115:29753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/backup.php"] [unique_id "amuyz-_ioCvBERk4wq-g1AAAAYM"]
[Thu Jul 30 15:23:43.469164 2026] [security2:error] [pid 147647:tid 147860] [client 20.171.55.167:7898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/documentsk.php"] [unique_id "amuyz-_ioCvBERk4wq-g5gAAAV0"]
[Thu Jul 30 15:23:43.515182 2026] [security2:error] [pid 147647:tid 147785] [client 40.77.167.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuyz-_ioCvBERk4wq-g2gAAARI"]
[Thu Jul 30 15:23:43.855560 2026] [security2:error] [pid 147647:tid 147824] [client 20.63.98.115:26394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/default.php"] [unique_id "amuyz-_ioCvBERk4wq-g_QAAATk"]
[Thu Jul 30 15:23:43.948592 2026] [core:notice] [pid 147647:tid 147752] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:43.979923 2026] [core:notice] [pid 147647:tid 147759] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:44.227521 2026] [core:notice] [pid 147647:tid 147708] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:44.234497 2026] [security2:error] [pid 147647:tid 147878] [client 20.171.55.167:7875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/dummy.php"] [unique_id "amuy0O_ioCvBERk4wq-hHgAAAW8"]
[Thu Jul 30 15:23:44.251382 2026] [core:notice] [pid 147647:tid 147728] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:44.916261 2026] [security2:error] [pid 147647:tid 147825] [client 20.63.98.115:29793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/maint/about.php"] [unique_id "amuy0O_ioCvBERk4wq-hOAAAATo"]
[Thu Jul 30 15:23:44.949489 2026] [core:notice] [pid 147647:tid 147884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:44.953352 2026] [security2:error] [pid 147647:tid 147884] [client 66.249.79.229:45030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/676/422"] [unique_id "amuy0O_ioCvBERk4wq-hKwAAAXU"]
[Thu Jul 30 15:23:45.175641 2026] [security2:error] [pid 147647:tid 147809] [client 20.171.55.167:7939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/el.php"] [unique_id "amuy0e_ioCvBERk4wq-hQAAAASo"]
[Thu Jul 30 15:23:45.177412 2026] [core:notice] [pid 147647:tid 147818] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:45.180871 2026] [security2:error] [pid 147647:tid 147818] [client 66.249.79.8:37892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Euclid/article/view/3312/2640"] [unique_id "amuy0e_ioCvBERk4wq-hQQAAATM"]
[Thu Jul 30 15:23:45.240973 2026] [core:error] [pid 147647:tid 147761] [remote 157.55.39.222:13548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:45.241013 2026] [core:error] [pid 147647:tid 147761] [remote 157.55.39.222:13548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:45.254748 2026] [security2:error] [pid 147647:tid 147775] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuy0e_ioCvBERk4wq-hRQABfn8"]
[Thu Jul 30 15:23:45.254949 2026] [security2:error] [pid 147647:tid 147893] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuy0e_ioCvBERk4wq-hRQABfn8"]
[Thu Jul 30 15:23:45.313957 2026] [core:notice] [pid 147647:tid 147814] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:45.626624 2026] [core:notice] [pid 147647:tid 147780] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:45.632170 2026] [security2:error] [pid 147647:tid 147780] [client 66.249.79.229:45030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/view/4484"] [unique_id "amuy0e_ioCvBERk4wq-hUgAAAQ0"]
[Thu Jul 30 15:23:45.684006 2026] [core:notice] [pid 147647:tid 147751] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:45.878740 2026] [security2:error] [pid 147647:tid 147840] [client 20.171.55.167:7873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ern1.php"] [unique_id "amuy0e_ioCvBERk4wq-hYQAAAUk"]
[Thu Jul 30 15:23:46.124497 2026] [core:notice] [pid 147647:tid 147804] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:46.130183 2026] [security2:error] [pid 147647:tid 147804] [client 66.249.79.229:45030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jka/article/download/3581/2462"] [unique_id "amuy0u_ioCvBERk4wq-hYgAAASU"]
[Thu Jul 30 15:23:46.585041 2026] [security2:error] [pid 147647:tid 147853] [client 20.171.55.167:7892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/f.php"] [unique_id "amuy0u_ioCvBERk4wq-hbgAAAVY"]
[Thu Jul 30 15:23:46.635084 2026] [security2:error] [pid 147647:tid 147879] [client 66.249.66.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.baytalhuboob.com"] [uri "/index.php"] [unique_id "amuy0O_ioCvBERk4wq-hOQABcE4"]
[Thu Jul 30 15:23:47.289955 2026] [security2:error] [pid 147647:tid 147839] [client 20.171.55.167:7995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ffAA531.php"] [unique_id "amuy0-_ioCvBERk4wq-hfgAAAUg"]
[Thu Jul 30 15:23:47.352371 2026] [core:notice] [pid 147647:tid 147855] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:47.355947 2026] [security2:error] [pid 147647:tid 147855] [client 66.249.79.229:45030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/download/4898/2304"] [unique_id "amuy0-_ioCvBERk4wq-hfwAAAVg"]
[Thu Jul 30 15:23:47.998505 2026] [security2:error] [pid 147647:tid 147837] [client 20.171.55.167:7938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/file_uploadbypass.php"] [unique_id "amuy0-_ioCvBERk4wq-hkAAAAUY"]
[Thu Jul 30 15:23:48.258046 2026] [core:notice] [pid 147647:tid 147786] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:48.705735 2026] [security2:error] [pid 147647:tid 147872] [client 20.171.55.167:7879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/filemanageradmin.php"] [unique_id "amuy1O_ioCvBERk4wq-hoQAAAWk"]
[Thu Jul 30 15:23:48.719196 2026] [core:notice] [pid 147647:tid 147861] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:49.038772 2026] [core:notice] [pid 147647:tid 147772] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:49.289830 2026] [core:notice] [pid 147647:tid 147675] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:49.348280 2026] [core:notice] [pid 147647:tid 147891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:49.393048 2026] [security2:error] [pid 147647:tid 147816] [client 20.63.98.115:48399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/uploads/2022/10/upload.php"] [unique_id "amuy1e_ioCvBERk4wq-htwAAATE"]
[Thu Jul 30 15:23:49.478752 2026] [security2:error] [pid 147647:tid 147821] [client 172.237.109.114:18308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuy1O_ioCvBERk4wq-hqgAAATY"]
[Thu Jul 30 15:23:49.498667 2026] [security2:error] [pid 147647:tid 147808] [client 20.171.55.167:7986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/fmadmin.php"] [unique_id "amuy1e_ioCvBERk4wq-huAAAASk"]
[Thu Jul 30 15:23:49.797048 2026] [core:notice] [pid 147647:tid 147805] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:50.212842 2026] [security2:error] [pid 147647:tid 147848] [client 20.171.55.167:7880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/fungsi.php"] [unique_id "amuy1u_ioCvBERk4wq-h0AAAAVE"]
[Thu Jul 30 15:23:50.275845 2026] [security2:error] [pid 147647:tid 147837] [client 185.191.171.5:47074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2025/02/cara-mengukur-kapasitor-pada"] [unique_id "amuy1u_ioCvBERk4wq-h0QAAAUY"]
[Thu Jul 30 15:23:50.275961 2026] [security2:error] [pid 147647:tid 147837] [client 185.191.171.5:47074] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2025/02/cara-mengukur-kapasitor-pada"] [unique_id "amuy1u_ioCvBERk4wq-h0QAAAUY"]
[Thu Jul 30 15:23:50.294618 2026] [core:notice] [pid 147647:tid 147846] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:50.830492 2026] [core:error] [pid 147647:tid 147863] [client 66.249.74.106:40827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:50.830515 2026] [core:error] [pid 147647:tid 147863] [client 66.249.74.106:40827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:50.928184 2026] [security2:error] [pid 147647:tid 147873] [client 20.171.55.167:7945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/gelay.php"] [unique_id "amuy1u_ioCvBERk4wq-h5QAAAWo"]
[Thu Jul 30 15:23:51.434171 2026] [security2:error] [pid 147647:tid 147689] [remote 40.77.167.241:64947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/jpa/article/download/1493/index_php/Responsif/issue/current"] [unique_id "amuy1-_ioCvBERk4wq-h8AABZik"]
[Thu Jul 30 15:23:51.459031 2026] [security2:error] [pid 147647:tid 147825] [client 172.237.109.114:30692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuy1u_ioCvBERk4wq-h5gAAATo"]
[Thu Jul 30 15:23:51.635849 2026] [security2:error] [pid 147647:tid 147853] [client 20.171.55.167:7890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/gold.php"] [unique_id "amuy1-_ioCvBERk4wq-h9QAAAVY"]
[Thu Jul 30 15:23:51.696605 2026] [security2:error] [pid 147647:tid 147816] [client 20.118.34.237:9286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuy1-_ioCvBERk4wq-h-QAAATE"]
[Thu Jul 30 15:23:51.952368 2026] [core:notice] [pid 147647:tid 147874] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:52.367050 2026] [security2:error] [pid 147647:tid 147844] [client 20.171.55.167:7885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/hax.php"] [unique_id "amuy2O_ioCvBERk4wq-iCwAAAU0"]
[Thu Jul 30 15:23:52.541012 2026] [security2:error] [pid 147647:tid 147855] [client 38.172.162.57:15882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuy2O_ioCvBERk4wq-iFwAAAVg"]
[Thu Jul 30 15:23:52.541142 2026] [security2:error] [pid 147647:tid 147855] [client 38.172.162.57:15882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuy2O_ioCvBERk4wq-iFwAAAVg"]
[Thu Jul 30 15:23:52.817892 2026] [security2:error] [pid 147647:tid 147795] [client 20.63.98.115:48407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ty.php"] [unique_id "amuy2O_ioCvBERk4wq-iHwAAARw"]
[Thu Jul 30 15:23:52.846732 2026] [core:notice] [pid 147647:tid 147786] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:52.850080 2026] [security2:error] [pid 147647:tid 147786] [client 66.249.79.229:39252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/RILL/article/view/2138"] [unique_id "amuy2O_ioCvBERk4wq-iIAAAARM"]
[Thu Jul 30 15:23:53.070384 2026] [core:notice] [pid 147647:tid 147904] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:53.083086 2026] [security2:error] [pid 147647:tid 147789] [client 20.171.55.167:7953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/homealfa.php"] [unique_id "amuy2e_ioCvBERk4wq-iKgAAARY"]
[Thu Jul 30 15:23:53.270437 2026] [security2:error] [pid 147647:tid 147894] [client 52.167.144.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuy2O_ioCvBERk4wq-iJgAAAX8"]
[Thu Jul 30 15:23:53.789859 2026] [security2:error] [pid 147647:tid 147893] [client 20.171.55.167:7877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/i0004en.php//wp-includes/bk/index.php"] [unique_id "amuy2e_ioCvBERk4wq-iSQAAAX4"]
[Thu Jul 30 15:23:54.438816 2026] [security2:error] [pid 147647:tid 147886] [client 213.152.161.133:46382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuy2u_ioCvBERk4wq-iWwAAAXc"]
[Thu Jul 30 15:23:54.438930 2026] [security2:error] [pid 147647:tid 147886] [client 213.152.161.133:46382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amuy2u_ioCvBERk4wq-iWwAAAXc"]
[Thu Jul 30 15:23:54.559065 2026] [security2:error] [pid 147647:tid 147800] [client 20.171.55.167:7958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/imagesk.php"] [unique_id "amuy2u_ioCvBERk4wq-iYgAAASE"]
[Thu Jul 30 15:23:54.671858 2026] [security2:error] [pid 147647:tid 147833] [client 52.167.144.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amuy2u_ioCvBERk4wq-iVwAAAUI"]
[Thu Jul 30 15:23:54.924604 2026] [security2:error] [pid 147647:tid 147741] [remote 57.141.0.59:38898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuy2u_ioCvBERk4wq-ibAABLV0"]
[Thu Jul 30 15:23:55.214740 2026] [core:notice] [pid 147647:tid 147903] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:55.218871 2026] [security2:error] [pid 147647:tid 147903] [client 66.249.79.8:52485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agro_sintesa/article/download/3196/1632"] [unique_id "amuy2-_ioCvBERk4wq-icgAAAYg"]
[Thu Jul 30 15:23:55.261776 2026] [security2:error] [pid 147647:tid 147811] [client 20.63.98.115:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/readme.php"] [unique_id "amuy2-_ioCvBERk4wq-idAAAASw"]
[Thu Jul 30 15:23:55.278986 2026] [security2:error] [pid 147647:tid 147822] [client 20.171.55.167:7985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/index1.php"] [unique_id "amuy2-_ioCvBERk4wq-idwAAATc"]
[Thu Jul 30 15:23:55.442432 2026] [core:notice] [pid 147647:tid 147881] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:55.445878 2026] [security2:error] [pid 147647:tid 147881] [client 66.249.79.229:39252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JGST/article/view/6946"] [unique_id "amuy2-_ioCvBERk4wq-iewAAAXI"]
[Thu Jul 30 15:23:55.739187 2026] [security2:error] [pid 147647:tid 147904] [client 146.103.125.97:65287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "saifalkhaleejest.com"] [uri "/"] [unique_id "amuy2-_ioCvBERk4wq-igwAAAYk"]
[Thu Jul 30 15:23:55.888144 2026] [core:notice] [pid 147647:tid 147843] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:55.891995 2026] [security2:error] [pid 147647:tid 147843] [client 66.249.79.1:59515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/5997"] [unique_id "amuy2-_ioCvBERk4wq-iiwAAAUw"]
[Thu Jul 30 15:23:55.934216 2026] [security2:error] [pid 147647:tid 147901] [client 155.117.163.49:33462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/2532-medium/almond-note-e-liquido-queens-flavors.jpg"] [unique_id "amuy2-_ioCvBERk4wq-ijgAAAYY"]
[Thu Jul 30 15:23:55.987022 2026] [security2:error] [pid 147647:tid 147791] [client 162.243.64.70:37482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.xyh.udi.temporary.site"] [uri "/.env"] [unique_id "amuy2-_ioCvBERk4wq-ikAAAARg"]
[Thu Jul 30 15:23:56.002547 2026] [security2:error] [pid 147647:tid 147806] [client 20.171.55.167:7978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/interactivity-api-class.php"] [unique_id "amuy3O_ioCvBERk4wq-ikQAAASc"]
[Thu Jul 30 15:23:56.389736 2026] [core:notice] [pid 147647:tid 147875] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:56.392899 2026] [security2:error] [pid 147647:tid 147875] [client 66.249.79.229:39252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/download/9525/4272"] [unique_id "amuy3O_ioCvBERk4wq-inQAAAWw"]
[Thu Jul 30 15:23:56.511575 2026] [security2:error] [pid 147647:tid 147897] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy2-_ioCvBERk4wq-ijwAAAYI"]
[Thu Jul 30 15:23:56.571471 2026] [security2:error] [pid 147647:tid 147757] [remote 57.141.0.29:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuy3O_ioCvBERk4wq-imAABSm0"]
[Thu Jul 30 15:23:56.673743 2026] [security2:error] [pid 147647:tid 147858] [client 20.63.98.115:29802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/options.php"] [unique_id "amuy3O_ioCvBERk4wq-iogAAAVs"]
[Thu Jul 30 15:23:56.708155 2026] [security2:error] [pid 147647:tid 147759] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuy3O_ioCvBERk4wq-iowABVW8"]
[Thu Jul 30 15:23:56.708281 2026] [security2:error] [pid 147647:tid 147852] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuy3O_ioCvBERk4wq-iowABVW8"]
[Thu Jul 30 15:23:56.711227 2026] [security2:error] [pid 147647:tid 147846] [client 20.171.55.167:7965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/jdtroslp.php"] [unique_id "amuy3O_ioCvBERk4wq-ipAAAAU8"]
[Thu Jul 30 15:23:56.890440 2026] [core:notice] [pid 147647:tid 147812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:57.043038 2026] [core:error] [pid 147647:tid 147756] [remote 40.77.167.8:28161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:57.043064 2026] [core:error] [pid 147647:tid 147756] [remote 40.77.167.8:28161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:23:57.579311 2026] [security2:error] [pid 147647:tid 147826] [client 20.171.55.167:7937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/jquery.php"] [unique_id "amuy3e_ioCvBERk4wq-ivwAAATs"]
[Thu Jul 30 15:23:57.598240 2026] [core:notice] [pid 147647:tid 147821] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:57.668798 2026] [security2:error] [pid 147647:tid 147782] [client 40.77.178.218:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "online-hope.com"] [uri "/index.php"] [unique_id "amuy3O_ioCvBERk4wq-iqAAAAQ8"]
[Thu Jul 30 15:23:57.672793 2026] [security2:error] [pid 147647:tid 147833] [client 146.103.125.97:65316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "saifalkhaleejest.com"] [uri "/"] [unique_id "amuy3e_ioCvBERk4wq-iuwAAAUI"]
[Thu Jul 30 15:23:57.734369 2026] [core:notice] [pid 147647:tid 147819] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:58.199598 2026] [core:notice] [pid 147647:tid 147899] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:58.263025 2026] [security2:error] [pid 147647:tid 147822] [client 20.63.98.115:29728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/admin.php7"] [unique_id "amuy3u_ioCvBERk4wq-i2wAAATc"]
[Thu Jul 30 15:23:58.284344 2026] [security2:error] [pid 147647:tid 147863] [client 114.119.154.77:63753] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mydubaidesertsafari.com"] [uri "/bXy/what-happened-to-logan-kim-on-the-resident"] [unique_id "amuy3u_ioCvBERk4wq-i3AAAAWA"], referer: https://www.rxelromany.com/archived/
[Thu Jul 30 15:23:58.310895 2026] [security2:error] [pid 147647:tid 147801] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy3e_ioCvBERk4wq-iyAAAASI"]
[Thu Jul 30 15:23:58.502017 2026] [security2:error] [pid 147647:tid 147823] [client 20.171.55.167:7996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/krypton.php"] [unique_id "amuy3u_ioCvBERk4wq-i4wAAATg"]
[Thu Jul 30 15:23:58.666675 2026] [core:notice] [pid 147647:tid 147902] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:23:59.140451 2026] [security2:error] [pid 147647:tid 147750] [remote 97.74.87.194:45304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jwcpartners.org"] [uri "/wp-login.php"] [unique_id "amuy3-_ioCvBERk4wq-i-QABg2Y"]
[Thu Jul 30 15:23:59.232410 2026] [security2:error] [pid 147647:tid 147832] [client 20.171.55.167:7961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/legion.php"] [unique_id "amuy3-_ioCvBERk4wq-i_QAAAUE"]
[Thu Jul 30 15:23:59.913798 2026] [security2:error] [pid 147647:tid 147837] [client 20.63.98.115:48794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/.well-known/wp-login.php"] [unique_id "amuy3-_ioCvBERk4wq-jCwAAAUY"]
[Thu Jul 30 15:23:59.942249 2026] [security2:error] [pid 147647:tid 147794] [client 20.171.55.167:7981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/linkpreview/wp.php"] [unique_id "amuy3-_ioCvBERk4wq-jDgAAARs"]
[Thu Jul 30 15:23:59.953591 2026] [security2:error] [pid 147647:tid 147817] [client 146.103.125.97:65349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "saifalkhaleejest.com"] [uri "/"] [unique_id "amuy3-_ioCvBERk4wq-i-AAAATI"]
[Thu Jul 30 15:24:00.176250 2026] [security2:error] [pid 147647:tid 147848] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy3-_ioCvBERk4wq-jBgAAAVE"]
[Thu Jul 30 15:24:00.708829 2026] [security2:error] [pid 147647:tid 147893] [client 20.171.55.167:7980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/lock.php"] [unique_id "amuy4O_ioCvBERk4wq-jLgAAAX4"]
[Thu Jul 30 15:24:01.003585 2026] [autoindex:error] [pid 147647:tid 147784] [client 44.216.125.112:34412] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:24:01.415598 2026] [security2:error] [pid 147647:tid 147850] [client 20.171.55.167:7874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/m.php"] [unique_id "amuy4e_ioCvBERk4wq-jYAAAAVM"]
[Thu Jul 30 15:24:01.746117 2026] [security2:error] [pid 147647:tid 147873] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy4e_ioCvBERk4wq-jSwAAAWo"]
[Thu Jul 30 15:24:01.806094 2026] [core:notice] [pid 147647:tid 147812] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:02.184131 2026] [security2:error] [pid 147647:tid 147896] [client 20.171.55.167:7943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/majalahpro-core/lib/index.php"] [unique_id "amuy4u_ioCvBERk4wq-jjAAAAYE"]
[Thu Jul 30 15:24:02.351023 2026] [autoindex:error] [pid 147647:tid 147796] [client 98.87.102.177:34916] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:24:02.362857 2026] [autoindex:error] [pid 147647:tid 147901] [client 98.87.102.177:17567] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_19d94cc7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:24:02.622852 2026] [security2:error] [pid 147647:tid 147842] [client 172.237.109.114:47875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuy4u_ioCvBERk4wq-jigAAAUs"]
[Thu Jul 30 15:24:02.895815 2026] [security2:error] [pid 147647:tid 147800] [client 20.171.55.167:7955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/max.php"] [unique_id "amuy4u_ioCvBERk4wq-joAAAASE"]
[Thu Jul 30 15:24:03.032851 2026] [core:notice] [pid 147647:tid 147795] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:03.035756 2026] [security2:error] [pid 147647:tid 147795] [client 66.249.79.231:49266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3856"] [unique_id "amuy4u_ioCvBERk4wq-jnwAAARw"]
[Thu Jul 30 15:24:03.148280 2026] [security2:error] [pid 147647:tid 147849] [client 38.172.162.57:15979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuy4-_ioCvBERk4wq-jpgAAAVI"]
[Thu Jul 30 15:24:03.148414 2026] [security2:error] [pid 147647:tid 147849] [client 38.172.162.57:15979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuy4-_ioCvBERk4wq-jpgAAAVI"]
[Thu Jul 30 15:24:03.891497 2026] [http2:info] [pid 173718:tid 173718] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 15:24:03.908950 2026] [security2:error] [pid 173718:tid 173849] [client 62.102.148.162:38058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuy40oi7QGnEa1uk6mb6wAAAAA"]
[Thu Jul 30 15:24:03.909168 2026] [security2:error] [pid 173718:tid 173849] [client 62.102.148.162:38058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amuy40oi7QGnEa1uk6mb6wAAAAA"]
[Thu Jul 30 15:24:04.066662 2026] [security2:error] [pid 147647:tid 147846] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuy4-_ioCvBERk4wq-jpwABT1M"]
[Thu Jul 30 15:24:04.139443 2026] [core:notice] [pid 173718:tid 173857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:04.146378 2026] [security2:error] [pid 173718:tid 173857] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/download/4144/2043"] [unique_id "amuy5Eoi7QGnEa1uk6mb-AAAAAg"]
[Thu Jul 30 15:24:04.215347 2026] [security2:error] [pid 173718:tid 173855] [client 20.171.55.167:7952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/meki.php"] [unique_id "amuy5Eoi7QGnEa1uk6mb_AAAAAY"]
[Thu Jul 30 15:24:04.526669 2026] [security2:error] [pid 173718:tid 173851] [client 172.237.109.114:58734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuy5Eoi7QGnEa1uk6mb7QAAAAI"]
[Thu Jul 30 15:24:04.852782 2026] [core:notice] [pid 173718:tid 173883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:04.914542 2026] [security2:error] [pid 173718:tid 173885] [client 20.171.55.167:7971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/module.audio-video.riff-set.php"] [unique_id "amuy5Eoi7QGnEa1uk6mcCgAAACQ"]
[Thu Jul 30 15:24:05.273678 2026] [security2:error] [pid 173718:tid 173907] [client 162.243.64.70:49932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.xyt.gzj.temporary.site"] [uri "/.env"] [unique_id "amuy5Uoi7QGnEa1uk6mcFQAAADo"]
[Thu Jul 30 15:24:05.522253 2026] [core:notice] [pid 173718:tid 173933] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:05.622152 2026] [security2:error] [pid 173718:tid 173945] [client 20.171.55.167:7972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/mvzdgot/index.php"] [unique_id "amuy5Uoi7QGnEa1uk6mcKAAAAGA"]
[Thu Jul 30 15:24:05.985296 2026] [core:notice] [pid 173718:tid 173976] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:06.391261 2026] [security2:error] [pid 173718:tid 173861] [client 20.171.55.167:7968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/new.php"] [unique_id "amuy5koi7QGnEa1uk6mcRAAAAAw"]
[Thu Jul 30 15:24:06.781831 2026] [security2:error] [pid 173718:tid 173855] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy5koi7QGnEa1uk6mcOQAAAAY"]
[Thu Jul 30 15:24:06.817931 2026] [security2:error] [pid 173718:tid 173743] [remote 52.167.144.141:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/286/286"] [unique_id "amuy5koi7QGnEa1uk6mcSwAAeBc"]
[Thu Jul 30 15:24:07.049537 2026] [core:notice] [pid 173718:tid 173888] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:07.054032 2026] [security2:error] [pid 173718:tid 173888] [client 66.249.79.229:52329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/1660/1316"] [unique_id "amuy50oi7QGnEa1uk6mcWwAAACc"]
[Thu Jul 30 15:24:07.097731 2026] [security2:error] [pid 173718:tid 173906] [client 20.171.55.167:7984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/nshell.php"] [unique_id "amuy50oi7QGnEa1uk6mcXAAAADk"]
[Thu Jul 30 15:24:07.259049 2026] [security2:error] [pid 173718:tid 173870] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy5koi7QGnEa1uk6mcTgAAABU"]
[Thu Jul 30 15:24:07.292441 2026] [core:notice] [pid 173718:tid 173928] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:07.296279 2026] [security2:error] [pid 173718:tid 173928] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/view/6264/2831"] [unique_id "amuy50oi7QGnEa1uk6mcYAAAAE8"]
[Thu Jul 30 15:24:07.320162 2026] [security2:error] [pid 173718:tid 173748] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuy50oi7QGnEa1uk6mcYQAARhw"]
[Thu Jul 30 15:24:07.320304 2026] [security2:error] [pid 173718:tid 173919] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuy50oi7QGnEa1uk6mcYQAARhw"]
[Thu Jul 30 15:24:07.758913 2026] [core:notice] [pid 173718:tid 173953] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:07.808399 2026] [security2:error] [pid 173718:tid 173947] [client 20.171.55.167:7966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/option.php"] [unique_id "amuy50oi7QGnEa1uk6mccAAAAGI"]
[Thu Jul 30 15:24:08.116495 2026] [core:notice] [pid 173718:tid 173853] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:08.122736 2026] [core:notice] [pid 173718:tid 173942] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:08.551877 2026] [security2:error] [pid 173718:tid 173860] [client 20.171.55.167:7873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/pages.php"] [unique_id "amuy6Eoi7QGnEa1uk6mcigAAAAs"]
[Thu Jul 30 15:24:08.602047 2026] [core:notice] [pid 173718:tid 173878] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:08.606198 2026] [security2:error] [pid 173718:tid 173878] [client 66.249.79.1:54574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Caruban/article/view/1558/1438"] [unique_id "amuy6Eoi7QGnEa1uk6mcggAAAB0"]
[Thu Jul 30 15:24:08.783663 2026] [security2:error] [pid 173718:tid 173879] [client 57.141.0.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy6Eoi7QGnEa1uk6mcfgAAAB4"]
[Thu Jul 30 15:24:08.834856 2026] [core:notice] [pid 173718:tid 173857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:08.838285 2026] [security2:error] [pid 173718:tid 173857] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JSTE/article/view/7064/2867"] [unique_id "amuy6Eoi7QGnEa1uk6mckgAAAAg"]
[Thu Jul 30 15:24:09.089008 2026] [proxy:error] [pid 173718:tid 173912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:24:09.089068 2026] [proxy_http:error] [pid 173718:tid 173912] [client 52.4.19.39:17827] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:24:09.089641 2026] [proxy:error] [pid 173718:tid 173912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:24:09.089686 2026] [proxy_http:error] [pid 173718:tid 173912] [client 52.4.19.39:17827] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:24:09.176050 2026] [proxy:error] [pid 173718:tid 173917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:24:09.176127 2026] [proxy_http:error] [pid 173718:tid 173917] [client 3.225.222.228:17100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:24:09.176822 2026] [proxy:error] [pid 173718:tid 173917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:24:09.176867 2026] [proxy_http:error] [pid 173718:tid 173917] [client 3.225.222.228:17100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:24:09.268688 2026] [security2:error] [pid 173718:tid 173884] [client 20.171.55.167:7977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/phpadmin/as.php"] [unique_id "amuy6Uoi7QGnEa1uk6mcoAAAACM"]
[Thu Jul 30 15:24:09.440841 2026] [core:notice] [pid 173718:tid 173921] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:09.837238 2026] [core:notice] [pid 173718:tid 173767] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:09.978675 2026] [security2:error] [pid 173718:tid 173940] [client 20.171.55.167:7907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/pinfo.php"] [unique_id "amuy6Uoi7QGnEa1uk6mcsAAAAFs"]
[Thu Jul 30 15:24:10.916725 2026] [security2:error] [pid 173718:tid 173853] [client 20.171.55.167:7990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/pmaxwhng.php"] [unique_id "amuy6koi7QGnEa1uk6mcxQAAAAQ"]
[Thu Jul 30 15:24:11.394235 2026] [core:notice] [pid 173718:tid 173865] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:11.692426 2026] [security2:error] [pid 173718:tid 173959] [client 20.171.55.167:7973] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.revolutionary-technologies.com"] [uri "/pridmag/1.php"] [unique_id "amuy60oi7QGnEa1uk6mc2wAAAG4"]
[Thu Jul 30 15:24:11.692539 2026] [security2:error] [pid 173718:tid 173959] [client 20.171.55.167:7973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/pridmag/1.php"] [unique_id "amuy60oi7QGnEa1uk6mc2wAAAG4"]
[Thu Jul 30 15:24:11.914166 2026] [core:notice] [pid 173718:tid 173867] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:12.017559 2026] [security2:error] [pid 173718:tid 173782] [remote 57.141.0.46:22530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/ELPER-Tech/PeerRev"] [unique_id "amuy7Eoi7QGnEa1uk6mc4AAAAz4"]
[Thu Jul 30 15:24:12.463914 2026] [security2:error] [pid 173718:tid 173925] [client 20.171.55.167:7950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/profilesbypass.php"] [unique_id "amuy7Eoi7QGnEa1uk6mc7QAAAEw"]
[Thu Jul 30 15:24:12.835493 2026] [core:notice] [pid 173718:tid 173862] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:12.840475 2026] [security2:error] [pid 173718:tid 173862] [client 66.249.79.229:52971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/article/view/793/486"] [unique_id "amuy7Eoi7QGnEa1uk6mc9QAAAA0"]
[Thu Jul 30 15:24:12.937376 2026] [security2:error] [pid 173718:tid 173792] [remote 157.66.26.183:51904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-468361c2.glb.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amuy7Eoi7QGnEa1uk6mc-QAAUkg"]
[Thu Jul 30 15:24:13.070168 2026] [core:notice] [pid 173718:tid 173949] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:13.151846 2026] [security2:error] [pid 173718:tid 173957] [client 185.191.171.10:36510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2024/08/04/fabrica-e-destruida-por-incendio-no-sertao-da-paraiba/"] [unique_id "amuy7Uoi7QGnEa1uk6mc_AAAAGw"]
[Thu Jul 30 15:24:13.152072 2026] [security2:error] [pid 173718:tid 173957] [client 185.191.171.10:36510] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2024/08/04/fabrica-e-destruida-por-incendio-no-sertao-da-paraiba/"] [unique_id "amuy7Uoi7QGnEa1uk6mc_AAAAGw"]
[Thu Jul 30 15:24:13.216834 2026] [security2:error] [pid 173718:tid 173944] [client 20.171.55.167:7964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/pwnd-1/pwnd.php"] [unique_id "amuy7Uoi7QGnEa1uk6mdAQAAAF8"]
[Thu Jul 30 15:24:13.521631 2026] [core:notice] [pid 173718:tid 173861] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:13.628528 2026] [security2:error] [pid 173718:tid 173965] [client 20.63.98.115:53492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amuy7Uoi7QGnEa1uk6mdCQAAAHQ"]
[Thu Jul 30 15:24:13.700112 2026] [security2:error] [pid 173718:tid 173945] [client 38.172.162.57:16092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuy7Uoi7QGnEa1uk6mdDgAAAGA"]
[Thu Jul 30 15:24:13.700219 2026] [security2:error] [pid 173718:tid 173945] [client 38.172.162.57:16092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuy7Uoi7QGnEa1uk6mdDgAAAGA"]
[Thu Jul 30 15:24:13.926386 2026] [security2:error] [pid 173718:tid 173893] [client 20.171.55.167:7994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/random_bytes_mcrypt.php"] [unique_id "amuy7Uoi7QGnEa1uk6mdFQAAACw"]
[Thu Jul 30 15:24:14.023824 2026] [core:notice] [pid 173718:tid 173859] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:14.523821 2026] [core:notice] [pid 173718:tid 173884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:14.710313 2026] [security2:error] [pid 173718:tid 173917] [client 20.171.55.167:7912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/rex.php"] [unique_id "amuy7koi7QGnEa1uk6mdJAAAAEQ"]
[Thu Jul 30 15:24:15.468226 2026] [security2:error] [pid 173718:tid 173925] [client 20.171.55.167:7891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/rx.php"] [unique_id "amuy70oi7QGnEa1uk6mdOgAAAEw"]
[Thu Jul 30 15:24:15.601005 2026] [core:notice] [pid 173718:tid 173954] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:15.605075 2026] [security2:error] [pid 173718:tid 173954] [client 66.249.79.229:52971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3766"] [unique_id "amuy70oi7QGnEa1uk6mdPgAAAGk"]
[Thu Jul 30 15:24:15.622856 2026] [security2:error] [pid 173718:tid 173867] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuy70oi7QGnEa1uk6mdMAAAElc"]
[Thu Jul 30 15:24:16.058714 2026] [core:notice] [pid 173718:tid 173975] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:16.216170 2026] [security2:error] [pid 173718:tid 173971] [client 20.171.55.167:7957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/search.php"] [unique_id "amuy8Eoi7QGnEa1uk6mdTAAAAHo"]
[Thu Jul 30 15:24:16.408481 2026] [core:notice] [pid 173718:tid 173966] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:16.955789 2026] [security2:error] [pid 173718:tid 173897] [client 20.171.55.167:7616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/seox/wsoyanzf.php"] [unique_id "amuy8Eoi7QGnEa1uk6mdWgAAADA"]
[Thu Jul 30 15:24:17.281738 2026] [security2:error] [pid 173718:tid 173882] [client 75.181.97.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuy8Uoi7QGnEa1uk6mdYwAAACE"], referer: https://cnpinyin.com
[Thu Jul 30 15:24:17.707823 2026] [security2:error] [pid 173718:tid 173915] [client 20.171.55.167:7884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/shell20211028.php"] [unique_id "amuy8Uoi7QGnEa1uk6mdbwAAAEI"]
[Thu Jul 30 15:24:17.790278 2026] [core:notice] [pid 173718:tid 173884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:17.794753 2026] [security2:error] [pid 173718:tid 173884] [client 66.249.79.237:36013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/view/2419"] [unique_id "amuy8Uoi7QGnEa1uk6mdawAAACM"]
[Thu Jul 30 15:24:17.875525 2026] [security2:error] [pid 173718:tid 173825] [remote 200.119.192.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.192.119.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuy8Uoi7QGnEa1uk6mdcAAAOWk"]
[Thu Jul 30 15:24:17.875696 2026] [security2:error] [pid 173718:tid 173906] [client 200.119.192.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blsspainvisacenterpakistan.site"] [uri "/xmlrpc.php"] [unique_id "amuy8Uoi7QGnEa1uk6mdcAAAOWk"]
[Thu Jul 30 15:24:18.023874 2026] [core:notice] [pid 173718:tid 173864] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:18.027285 2026] [security2:error] [pid 173718:tid 173864] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/article/view/87"] [unique_id "amuy8koi7QGnEa1uk6mddAAAAA8"]
[Thu Jul 30 15:24:18.302191 2026] [security2:error] [pid 173718:tid 173831] [remote 74.7.243.224:42006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/js/donatef.php"] [unique_id "amuy8koi7QGnEa1uk6mdfQAADm8"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/js/partner.html
[Thu Jul 30 15:24:18.439654 2026] [security2:error] [pid 173718:tid 173923] [client 20.171.55.167:7930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/signin2.php"] [unique_id "amuy8koi7QGnEa1uk6mdfgAAAEo"]
[Thu Jul 30 15:24:18.769675 2026] [security2:error] [pid 173718:tid 173936] [client 20.63.98.115:35144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/file.php"] [unique_id "amuy8koi7QGnEa1uk6mdiAAAAFc"]
[Thu Jul 30 15:24:19.209711 2026] [security2:error] [pid 173718:tid 173962] [client 20.171.55.167:7249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/skatepark/alpha.php"] [unique_id "amuy80oi7QGnEa1uk6mdmgAAAHE"]
[Thu Jul 30 15:24:19.421350 2026] [fcgid:warn] [pid 173718:tid 173893] (70014)End of file found: [client 18.218.118.203:41374] mod_fcgid: can't get data from http client
[Thu Jul 30 15:24:19.595439 2026] [security2:error] [pid 173718:tid 173899] [client 20.63.98.115:26913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/bak.php"] [unique_id "amuy80oi7QGnEa1uk6mdogAAADI"]
[Thu Jul 30 15:24:19.688467 2026] [core:notice] [pid 173718:tid 173908] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:19.692131 2026] [security2:error] [pid 173718:tid 173908] [client 66.249.79.229:52971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/article/view/3969/1977"] [unique_id "amuy80oi7QGnEa1uk6mdpgAAADs"]
[Thu Jul 30 15:24:19.926574 2026] [security2:error] [pid 173718:tid 173903] [client 20.171.55.167:7987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sol.php"] [unique_id "amuy80oi7QGnEa1uk6mdrwAAADY"]
[Thu Jul 30 15:24:20.142832 2026] [core:notice] [pid 173718:tid 173852] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:20.442490 2026] [security2:error] [pid 173718:tid 173877] [client 20.63.98.115:26904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/config.php"] [unique_id "amuy9Eoi7QGnEa1uk6mdvQAAABw"]
[Thu Jul 30 15:24:20.501756 2026] [security2:error] [pid 173718:tid 173913] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy80oi7QGnEa1uk6mdrgAAAEA"]
[Thu Jul 30 15:24:20.639584 2026] [core:notice] [pid 173718:tid 173932] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:20.700892 2026] [security2:error] [pid 173718:tid 173926] [client 20.171.55.167:7976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/star.php"] [unique_id "amuy9Eoi7QGnEa1uk6mdygAAAE0"]
[Thu Jul 30 15:24:20.834818 2026] [security2:error] [pid 173718:tid 173858] [client 85.208.96.201:48504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/03/14/prefeito-zezinho-da-rapadura-celebra-convenio-para-construcao-de-uma-nova-creche-em-lagoa-de-dentro/"] [unique_id "amuy9Eoi7QGnEa1uk6mdzwAAAAk"]
[Thu Jul 30 15:24:20.835039 2026] [security2:error] [pid 173718:tid 173858] [client 85.208.96.201:48504] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/03/14/prefeito-zezinho-da-rapadura-celebra-convenio-para-construcao-de-uma-nova-creche-em-lagoa-de-dentro/"] [unique_id "amuy9Eoi7QGnEa1uk6mdzwAAAAk"]
[Thu Jul 30 15:24:21.007528 2026] [security2:error] [pid 173718:tid 173946] [client 78.142.18.40:61790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.142.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/wp-login.php"] [unique_id "amuy9Uoi7QGnEa1uk6md0wAAAGE"]
[Thu Jul 30 15:24:21.251299 2026] [security2:error] [pid 173718:tid 173953] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy9Eoi7QGnEa1uk6mdxQAAAGg"]
[Thu Jul 30 15:24:21.303314 2026] [security2:error] [pid 173718:tid 173968] [client 20.63.98.115:26251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/uploads/2025/03/themes.php"] [unique_id "amuy9Uoi7QGnEa1uk6md4QAAAHc"]
[Thu Jul 30 15:24:21.387782 2026] [core:error] [pid 173718:tid 173893] [client 74.7.241.192:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:21.387808 2026] [core:error] [pid 173718:tid 173893] [client 74.7.241.192:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:21.387933 2026] [security2:error] [pid 173718:tid 173893] [client 74.7.241.192:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.bkv.gpl.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "amuy9Uoi7QGnEa1uk6md5AAAACw"]
[Thu Jul 30 15:24:21.388602 2026] [security2:error] [pid 173718:tid 173964] [client 74.7.241.192:47076] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.bkv.gpl.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "amuy9Uoi7QGnEa1uk6md4gAAcw0"]
[Thu Jul 30 15:24:21.419826 2026] [security2:error] [pid 173718:tid 173851] [client 20.171.55.167:7889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/style.php"] [unique_id "amuy9Uoi7QGnEa1uk6md5QAAAAI"]
[Thu Jul 30 15:24:21.476161 2026] [security2:error] [pid 173718:tid 173936] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy9Eoi7QGnEa1uk6md0gAAAFc"]
[Thu Jul 30 15:24:21.489436 2026] [core:notice] [pid 173718:tid 173859] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:21.525451 2026] [core:notice] [pid 173718:tid 173853] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:21.934285 2026] [security2:error] [pid 173718:tid 173959] [client 43.172.196.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuy9Uoi7QGnEa1uk6md5wAAbg8"], referer: https://lucky-strike-shop.com/
[Thu Jul 30 15:24:21.947073 2026] [security2:error] [pid 173718:tid 173898] [client 43.172.198.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amuy9Uoi7QGnEa1uk6md6AAAMRA"], referer: https://lucky-strike-shop.com/
[Thu Jul 30 15:24:22.135861 2026] [security2:error] [pid 173718:tid 173914] [client 20.171.55.167:7876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/system_log.php"] [unique_id "amuy9koi7QGnEa1uk6md-gAAAEE"]
[Thu Jul 30 15:24:22.168903 2026] [security2:error] [pid 173718:tid 173872] [client 159.89.127.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nafmedical.com"] [uri "/index.php"] [unique_id "amuy9Uoi7QGnEa1uk6md-QAAABc"]
[Thu Jul 30 15:24:22.231970 2026] [security2:error] [pid 173718:tid 173899] [client 103.53.36.100:14580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuy9Uoi7QGnEa1uk6md7gAAMhU"]
[Thu Jul 30 15:24:22.383383 2026] [security2:error] [pid 173718:tid 173906] [client 20.63.98.115:35175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-activate.php"] [unique_id "amuy9koi7QGnEa1uk6meBQAAADk"]
[Thu Jul 30 15:24:22.444999 2026] [security2:error] [pid 173718:tid 173864] [client 159.89.127.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nafmedical.com"] [uri "/index.php"] [unique_id "amuy9koi7QGnEa1uk6meAQAADxg"]
[Thu Jul 30 15:24:22.859069 2026] [core:notice] [pid 173718:tid 173858] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:23.172683 2026] [security2:error] [pid 173718:tid 173862] [client 20.171.55.167:7267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/test1.php"] [unique_id "amuy90oi7QGnEa1uk6meIgAAAA0"]
[Thu Jul 30 15:24:23.187439 2026] [security2:error] [pid 173718:tid 173971] [client 64.89.163.9:54280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuy90oi7QGnEa1uk6meJQAAAHo"]
[Thu Jul 30 15:24:23.288236 2026] [security2:error] [pid 173718:tid 173965] [client 64.89.163.9:54350] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-30643359.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuy90oi7QGnEa1uk6meOgAAAHQ"]
[Thu Jul 30 15:24:23.349233 2026] [core:error] [pid 173718:tid 173901] [client 64.89.163.9:54340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.349256 2026] [core:error] [pid 173718:tid 173901] [client 64.89.163.9:54340] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.418860 2026] [core:error] [pid 173718:tid 173936] [client 64.89.163.9:54280] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.418889 2026] [core:error] [pid 173718:tid 173936] [client 64.89.163.9:54280] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.433793 2026] [security2:error] [pid 173718:tid 173889] [client 64.89.163.9:54318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-e5e391bf.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuy90oi7QGnEa1uk6meRAAAACg"]
[Thu Jul 30 15:24:23.436674 2026] [core:error] [pid 173718:tid 173945] [client 64.89.163.9:54392] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.436693 2026] [core:error] [pid 173718:tid 173945] [client 64.89.163.9:54392] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.492398 2026] [security2:error] [pid 173718:tid 173873] [client 20.63.98.115:35153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-file.php"] [unique_id "amuy90oi7QGnEa1uk6meRwAAABg"]
[Thu Jul 30 15:24:23.517442 2026] [core:error] [pid 173718:tid 173882] [client 64.89.163.9:54338] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.517464 2026] [core:error] [pid 173718:tid 173882] [client 64.89.163.9:54338] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.521208 2026] [core:error] [pid 173718:tid 173910] [client 64.89.163.9:54350] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.521224 2026] [core:error] [pid 173718:tid 173910] [client 64.89.163.9:54350] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.549466 2026] [core:error] [pid 173718:tid 173922] [client 64.89.163.9:54336] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.549483 2026] [core:error] [pid 173718:tid 173922] [client 64.89.163.9:54336] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.581876 2026] [core:error] [pid 173718:tid 173947] [client 64.89.163.9:54300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.581895 2026] [core:error] [pid 173718:tid 173947] [client 64.89.163.9:54300] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.622803 2026] [core:error] [pid 173718:tid 173851] [client 64.89.163.9:54416] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.622827 2026] [core:error] [pid 173718:tid 173851] [client 64.89.163.9:54416] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.637076 2026] [core:error] [pid 173718:tid 173852] [client 64.89.163.9:54362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.637091 2026] [core:error] [pid 173718:tid 173852] [client 64.89.163.9:54362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.637118 2026] [core:error] [pid 173718:tid 173888] [client 64.89.163.9:54290] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.637128 2026] [core:error] [pid 173718:tid 173888] [client 64.89.163.9:54290] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.640627 2026] [core:error] [pid 173718:tid 173920] [client 64.89.163.9:54318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.640644 2026] [core:error] [pid 173718:tid 173920] [client 64.89.163.9:54318] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.690268 2026] [core:error] [pid 173718:tid 173934] [client 64.89.163.9:54272] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.690285 2026] [core:error] [pid 173718:tid 173934] [client 64.89.163.9:54272] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.690552 2026] [core:error] [pid 173718:tid 173970] [client 64.89.163.9:54508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.690571 2026] [core:error] [pid 173718:tid 173970] [client 64.89.163.9:54508] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.691300 2026] [core:error] [pid 173718:tid 173890] [client 64.89.163.9:54352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.691316 2026] [core:error] [pid 173718:tid 173890] [client 64.89.163.9:54352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.706626 2026] [security2:error] [pid 173718:tid 173884] [client 64.89.163.9:54308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-30643359.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuy90oi7QGnEa1uk6meWQAAACM"]
[Thu Jul 30 15:24:23.714430 2026] [core:error] [pid 173718:tid 173918] [client 64.89.163.9:54482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.714447 2026] [core:error] [pid 173718:tid 173918] [client 64.89.163.9:54482] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.716552 2026] [core:error] [pid 173718:tid 173865] [client 64.89.163.9:54404] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.716575 2026] [core:error] [pid 173718:tid 173865] [client 64.89.163.9:54404] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.758838 2026] [core:error] [pid 173718:tid 173876] [client 64.89.163.9:54496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.758857 2026] [core:error] [pid 173718:tid 173876] [client 64.89.163.9:54496] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.792913 2026] [core:error] [pid 173718:tid 173881] [client 64.89.163.9:54522] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.792932 2026] [core:error] [pid 173718:tid 173881] [client 64.89.163.9:54522] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.827738 2026] [security2:error] [pid 173718:tid 173917] [client 64.89.163.9:54570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuy90oi7QGnEa1uk6meZQAAAEQ"]
[Thu Jul 30 15:24:23.846555 2026] [core:error] [pid 173718:tid 173944] [client 64.89.163.9:54308] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.846573 2026] [core:error] [pid 173718:tid 173944] [client 64.89.163.9:54308] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.848415 2026] [core:error] [pid 173718:tid 173858] [client 64.89.163.9:54326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.848430 2026] [core:error] [pid 173718:tid 173858] [client 64.89.163.9:54326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.854205 2026] [core:error] [pid 173718:tid 173933] [client 64.89.163.9:54438] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.854222 2026] [core:error] [pid 173718:tid 173933] [client 64.89.163.9:54438] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.883578 2026] [security2:error] [pid 173718:tid 173959] [client 20.171.55.167:7975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/three-column-screen-layout/db.php"] [unique_id "amuy90oi7QGnEa1uk6mebgAAAG4"]
[Thu Jul 30 15:24:23.926289 2026] [core:error] [pid 173718:tid 173932] [client 64.89.163.9:54602] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.926307 2026] [core:error] [pid 173718:tid 173932] [client 64.89.163.9:54602] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:23.976098 2026] [security2:error] [pid 173718:tid 173853] [client 64.89.163.9:54466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-35ddd216.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuy90oi7QGnEa1uk6meeAAAAAQ"]
[Thu Jul 30 15:24:24.009182 2026] [core:error] [pid 173718:tid 173850] [client 64.89.163.9:54528] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.009200 2026] [core:error] [pid 173718:tid 173850] [client 64.89.163.9:54528] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.062109 2026] [security2:error] [pid 173718:tid 173875] [client 64.89.163.9:54544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-40995a0e.yxe.zzt.temporary.site"] [uri "/.env"] [unique_id "amuy-Eoi7QGnEa1uk6meegAAABo"]
[Thu Jul 30 15:24:24.088456 2026] [core:error] [pid 173718:tid 173923] [client 64.89.163.9:54588] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.088481 2026] [core:error] [pid 173718:tid 173923] [client 64.89.163.9:54588] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.155737 2026] [core:error] [pid 173718:tid 173964] [client 64.89.163.9:54442] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.155756 2026] [core:error] [pid 173718:tid 173964] [client 64.89.163.9:54442] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.160567 2026] [core:error] [pid 173718:tid 173949] [client 64.89.163.9:54658] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.160582 2026] [core:error] [pid 173718:tid 173949] [client 64.89.163.9:54658] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.172429 2026] [security2:error] [pid 173718:tid 173954] [client 98.83.8.142:14924] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guethleentertainment.com"] [uri "/"] [unique_id "amuy-Eoi7QGnEa1uk6mehQAAAGk"]
[Thu Jul 30 15:24:24.188997 2026] [core:error] [pid 173718:tid 173962] [client 64.89.163.9:54696] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.189015 2026] [core:error] [pid 173718:tid 173962] [client 64.89.163.9:54696] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.196497 2026] [core:error] [pid 173718:tid 173859] [client 64.89.163.9:54560] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.196525 2026] [core:error] [pid 173718:tid 173859] [client 64.89.163.9:54560] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.236562 2026] [core:error] [pid 173718:tid 173889] [client 64.89.163.9:54466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.236585 2026] [core:error] [pid 173718:tid 173889] [client 64.89.163.9:54466] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.239570 2026] [core:error] [pid 173718:tid 173860] [client 64.89.163.9:54688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.239588 2026] [core:error] [pid 173718:tid 173860] [client 64.89.163.9:54688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.277572 2026] [security2:error] [pid 173718:tid 173924] [client 38.172.162.57:16050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuy-Eoi7QGnEa1uk6mejQAAAEs"]
[Thu Jul 30 15:24:24.277704 2026] [security2:error] [pid 173718:tid 173924] [client 38.172.162.57:16050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuy-Eoi7QGnEa1uk6mejQAAAEs"]
[Thu Jul 30 15:24:24.406456 2026] [core:error] [pid 173718:tid 173934] [client 64.89.163.9:54544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.406478 2026] [core:error] [pid 173718:tid 173934] [client 64.89.163.9:54544] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.436023 2026] [core:error] [pid 173718:tid 173904] [client 64.89.163.9:54814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.436049 2026] [core:error] [pid 173718:tid 173904] [client 64.89.163.9:54814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.527431 2026] [core:error] [pid 173718:tid 173868] [client 64.89.163.9:54824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.527461 2026] [core:error] [pid 173718:tid 173868] [client 64.89.163.9:54824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.547587 2026] [core:error] [pid 173718:tid 173920] [client 64.89.163.9:54840] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.547610 2026] [core:error] [pid 173718:tid 173920] [client 64.89.163.9:54840] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.657468 2026] [security2:error] [pid 173718:tid 173910] [client 20.171.55.167:7993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tmpk.php"] [unique_id "amuy-Eoi7QGnEa1uk6meqQAAAD0"]
[Thu Jul 30 15:24:24.719130 2026] [core:error] [pid 173718:tid 173943] [client 64.89.163.9:54376] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.719150 2026] [core:error] [pid 173718:tid 173943] [client 64.89.163.9:54376] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:24.833311 2026] [core:notice] [pid 173718:tid 173926] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:24.837635 2026] [security2:error] [pid 173718:tid 173926] [client 66.249.79.229:44093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/download/9315/4262"] [unique_id "amuy-Eoi7QGnEa1uk6mesgAAAE0"]
[Thu Jul 30 15:24:25.067692 2026] [core:notice] [pid 173718:tid 173946] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:25.371744 2026] [security2:error] [pid 173718:tid 173965] [client 20.171.55.167:7247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ttw.php"] [unique_id "amuy-Uoi7QGnEa1uk6meygAAAHQ"]
[Thu Jul 30 15:24:25.517116 2026] [core:notice] [pid 173718:tid 173889] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:25.520915 2026] [security2:error] [pid 173718:tid 173889] [client 66.249.79.229:44093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/logika/article/view/220"] [unique_id "amuy-Uoi7QGnEa1uk6me1AAAACg"]
[Thu Jul 30 15:24:25.568835 2026] [security2:error] [pid 173718:tid 173937] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuy-Eoi7QGnEa1uk6mevwAAAFg"]
[Thu Jul 30 15:24:26.015007 2026] [core:notice] [pid 173718:tid 173891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:26.117446 2026] [security2:error] [pid 173718:tid 173911] [client 20.171.55.167:7292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/twentytwentyone/template-parts/content/style.php"] [unique_id "amuy-koi7QGnEa1uk6me9AAAAD4"]
[Thu Jul 30 15:24:26.333324 2026] [security2:error] [pid 173718:tid 173928] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuy-Uoi7QGnEa1uk6mewwAAT1Y"]
[Thu Jul 30 15:24:26.510987 2026] [core:notice] [pid 173718:tid 173976] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:26.727131 2026] [security2:error] [pid 173718:tid 173972] [client 88.98.120.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuy-koi7QGnEa1uk6mfBQAAAHs"], referer: https://cnpinyin.com
[Thu Jul 30 15:24:26.836785 2026] [security2:error] [pid 173718:tid 173961] [client 20.171.55.167:7242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/un2.php"] [unique_id "amuy-koi7QGnEa1uk6mfBgAAAHA"]
[Thu Jul 30 15:24:26.846267 2026] [security2:error] [pid 173718:tid 173913] [client 2a03:2880:f800:3d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuy-koi7QGnEa1uk6me8wAAQHU"]
[Thu Jul 30 15:24:27.421658 2026] [security2:error] [pid 173718:tid 173936] [client 20.63.98.115:35170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/12.php"] [unique_id "amuy-0oi7QGnEa1uk6mfFAAAAFc"]
[Thu Jul 30 15:24:27.444916 2026] [core:notice] [pid 173718:tid 173922] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:27.537497 2026] [security2:error] [pid 173718:tid 173897] [client 20.171.55.167:7947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/uploadk.php"] [unique_id "amuy-0oi7QGnEa1uk6mfGwAAADA"]
[Thu Jul 30 15:24:28.310193 2026] [security2:error] [pid 173718:tid 173883] [client 20.171.55.167:7268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/user.php"] [unique_id "amuy_Eoi7QGnEa1uk6mfMAAAACI"]
[Thu Jul 30 15:24:28.430773 2026] [security2:error] [pid 173718:tid 173731] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/011i.php"] [unique_id "amuy_Eoi7QGnEa1uk6mfMQAAJgs"]
[Thu Jul 30 15:24:28.443316 2026] [security2:error] [pid 173718:tid 173948] [client 20.63.98.115:50241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/epinyins.php"] [unique_id "amuy_Eoi7QGnEa1uk6mfMgAAAGM"]
[Thu Jul 30 15:24:28.454239 2026] [security2:error] [pid 173718:tid 173913] [client 74.7.228.14:56236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.vpv.tqa.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuy_Eoi7QGnEa1uk6mfNAAAAEA"]
[Thu Jul 30 15:24:28.801888 2026] [security2:error] [pid 173718:tid 173738] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/03a005685d.php"] [unique_id "amuy_Eoi7QGnEa1uk6mfQQAAChI"]
[Thu Jul 30 15:24:28.927678 2026] [core:notice] [pid 173718:tid 173743] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:28.955599 2026] [security2:error] [pid 173718:tid 173745] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/403.php"] [unique_id "amuy_Eoi7QGnEa1uk6mfRAAAYBk"]
[Thu Jul 30 15:24:29.020077 2026] [security2:error] [pid 173718:tid 173907] [client 20.171.55.167:7944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/vendorsadmin.php"] [unique_id "amuy_Uoi7QGnEa1uk6mfSAAAADo"]
[Thu Jul 30 15:24:29.082276 2026] [security2:error] [pid 173718:tid 173739] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/404.php"] [unique_id "amuy_Uoi7QGnEa1uk6mfSQAACxM"]
[Thu Jul 30 15:24:29.128997 2026] [core:notice] [pid 173718:tid 173850] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:29.132644 2026] [security2:error] [pid 173718:tid 173850] [client 66.249.79.229:44093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA/article/view/3543"] [unique_id "amuy_Uoi7QGnEa1uk6mfSgAAAAE"]
[Thu Jul 30 15:24:29.300262 2026] [security2:error] [pid 173718:tid 173748] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/aa.php"] [unique_id "amuy_Uoi7QGnEa1uk6mfVwAAKRw"]
[Thu Jul 30 15:24:29.513089 2026] [security2:error] [pid 173718:tid 173750] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/aafewc0k.php"] [unique_id "amuy_Uoi7QGnEa1uk6mfXAAATh4"]
[Thu Jul 30 15:24:29.644602 2026] [security2:error] [pid 173718:tid 173754] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/abcd.php"] [unique_id "amuy_Uoi7QGnEa1uk6mfZAAAYiI"]
[Thu Jul 30 15:24:29.722847 2026] [security2:error] [pid 173718:tid 173897] [client 20.171.55.167:7254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/w.php"] [unique_id "amuy_Uoi7QGnEa1uk6mfZgAAADA"]
[Thu Jul 30 15:24:29.841656 2026] [core:notice] [pid 173718:tid 173956] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:29.843603 2026] [security2:error] [pid 173718:tid 173757] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/about.php"] [unique_id "amuy_Uoi7QGnEa1uk6mfZwAAJyU"]
[Thu Jul 30 15:24:29.845766 2026] [security2:error] [pid 173718:tid 173956] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/813/493"] [unique_id "amuy_Uoi7QGnEa1uk6mfXQAAAGs"]
[Thu Jul 30 15:24:29.976263 2026] [security2:error] [pid 173718:tid 173758] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/admin.php"] [unique_id "amuy_Uoi7QGnEa1uk6mfaAAAOCY"]
[Thu Jul 30 15:24:30.107610 2026] [security2:error] [pid 173718:tid 173756] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/adminfuns.php"] [unique_id "amuy_koi7QGnEa1uk6mfbAAACSQ"]
[Thu Jul 30 15:24:30.287492 2026] [security2:error] [pid 173718:tid 173761] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/albin.php"] [unique_id "amuy_koi7QGnEa1uk6mfcQAAfCk"]
[Thu Jul 30 15:24:30.414443 2026] [core:notice] [pid 173718:tid 173972] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:30.416269 2026] [security2:error] [pid 173718:tid 173767] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/amfsqvgv.php"] [unique_id "amuy_koi7QGnEa1uk6mfdwAAEi8"]
[Thu Jul 30 15:24:30.523218 2026] [security2:error] [pid 173718:tid 173870] [client 20.171.55.167:7940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/widgets/about.php"] [unique_id "amuy_koi7QGnEa1uk6mfewAAABU"]
[Thu Jul 30 15:24:30.548162 2026] [security2:error] [pid 173718:tid 173772] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/ant.php"] [unique_id "amuy_koi7QGnEa1uk6mffAAAIjQ"]
[Thu Jul 30 15:24:30.612134 2026] [security2:error] [pid 173718:tid 173857] [client 20.63.98.115:35154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "amuy_koi7QGnEa1uk6mffwAAAAg"]
[Thu Jul 30 15:24:30.738459 2026] [security2:error] [pid 173718:tid 173766] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/appreciators.php"] [unique_id "amuy_koi7QGnEa1uk6mfgQAAQC4"]
[Thu Jul 30 15:24:30.848866 2026] [core:notice] [pid 173718:tid 173765] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:30.903482 2026] [security2:error] [pid 173718:tid 173769] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/archive.php"] [unique_id "amuy_koi7QGnEa1uk6mfiQAAaTE"]
[Thu Jul 30 15:24:31.091156 2026] [security2:error] [pid 173718:tid 173777] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/as.php"] [unique_id "amuy_0oi7QGnEa1uk6mfjQAALDk"]
[Thu Jul 30 15:24:31.104530 2026] [core:notice] [pid 173718:tid 173752] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:31.232446 2026] [security2:error] [pid 173718:tid 173776] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/atomlib.php"] [unique_id "amuy_0oi7QGnEa1uk6mfkAAAbzg"]
[Thu Jul 30 15:24:31.254961 2026] [core:notice] [pid 173718:tid 173964] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:31.357721 2026] [security2:error] [pid 173718:tid 173942] [client 20.171.55.167:7941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/widgetsalfa.php"] [unique_id "amuy_0oi7QGnEa1uk6mflQAAAF0"]
[Thu Jul 30 15:24:31.361459 2026] [security2:error] [pid 173718:tid 173779] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/autoload_classmap.php"] [unique_id "amuy_0oi7QGnEa1uk6mflgAAWDs"]
[Thu Jul 30 15:24:31.498097 2026] [security2:error] [pid 173718:tid 173781] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/bb.php"] [unique_id "amuy_0oi7QGnEa1uk6mfnQAAJT0"]
[Thu Jul 30 15:24:31.604756 2026] [security2:error] [pid 173718:tid 173909] [client 172.237.109.114:58337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuy_0oi7QGnEa1uk6mfjwAAADw"]
[Thu Jul 30 15:24:31.623937 2026] [security2:error] [pid 173718:tid 173782] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/bnm.php"] [unique_id "amuy_0oi7QGnEa1uk6mfngAAaj4"]
[Thu Jul 30 15:24:31.855662 2026] [security2:error] [pid 173718:tid 173783] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/bootstrap.php"] [unique_id "amuy_0oi7QGnEa1uk6mfnwAAeT8"]
[Thu Jul 30 15:24:31.884366 2026] [core:notice] [pid 173718:tid 173854] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:31.887445 2026] [security2:error] [pid 173718:tid 173854] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Caruban/article/download/2315/1432"] [unique_id "amuy_0oi7QGnEa1uk6mfowAAAAU"]
[Thu Jul 30 15:24:31.936049 2026] [security2:error] [pid 173718:tid 173941] [client 20.63.98.115:32299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/system_log.php"] [unique_id "amuy_0oi7QGnEa1uk6mfqAAAAFw"]
[Thu Jul 30 15:24:32.061261 2026] [security2:error] [pid 173718:tid 173790] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/buy.php"] [unique_id "amuzAEoi7QGnEa1uk6mfrAAAOUY"]
[Thu Jul 30 15:24:32.089376 2026] [security2:error] [pid 173718:tid 173936] [client 20.171.55.167:7354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/workart/doc.php"] [unique_id "amuzAEoi7QGnEa1uk6mfrQAAAFc"]
[Thu Jul 30 15:24:32.191133 2026] [security2:error] [pid 173718:tid 173789] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/chosen.php"] [unique_id "amuzAEoi7QGnEa1uk6mfrgAAOEU"]
[Thu Jul 30 15:24:32.319165 2026] [security2:error] [pid 173718:tid 173792] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/class-wp-image.php"] [unique_id "amuzAEoi7QGnEa1uk6mfrwAAF0g"]
[Thu Jul 30 15:24:32.329315 2026] [core:notice] [pid 173718:tid 173928] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:32.332950 2026] [security2:error] [pid 173718:tid 173928] [client 66.249.79.229:44093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/download/9143/3963"] [unique_id "amuzAEoi7QGnEa1uk6mfsAAAAE8"]
[Thu Jul 30 15:24:32.445080 2026] [security2:error] [pid 173718:tid 173793] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/classsmtps.php"] [unique_id "amuzAEoi7QGnEa1uk6mftwAAdkk"]
[Thu Jul 30 15:24:32.585459 2026] [security2:error] [pid 173718:tid 173796] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/classwithtostring.php"] [unique_id "amuzAEoi7QGnEa1uk6mfuwAAVEw"]
[Thu Jul 30 15:24:32.712852 2026] [security2:error] [pid 173718:tid 173797] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/config.php"] [unique_id "amuzAEoi7QGnEa1uk6mfvAAAe00"]
[Thu Jul 30 15:24:32.829674 2026] [core:notice] [pid 173718:tid 173863] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:32.833458 2026] [security2:error] [pid 173718:tid 173863] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/article/download/790/482"] [unique_id "amuzAEoi7QGnEa1uk6mfvQAAAA4"]
[Thu Jul 30 15:24:32.847411 2026] [security2:error] [pid 173718:tid 173798] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/core.php"] [unique_id "amuzAEoi7QGnEa1uk6mfvgAATU4"]
[Thu Jul 30 15:24:32.858102 2026] [security2:error] [pid 173718:tid 173951] [client 20.171.55.167:7307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-atomx.php"] [unique_id "amuzAEoi7QGnEa1uk6mfvwAAAGY"]
[Thu Jul 30 15:24:32.974036 2026] [security2:error] [pid 173718:tid 173801] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/css.php"] [unique_id "amuzAEoi7QGnEa1uk6mfxgAAFlE"]
[Thu Jul 30 15:24:33.105935 2026] [security2:error] [pid 173718:tid 173804] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/database.php"] [unique_id "amuzAUoi7QGnEa1uk6mfygAAUVQ"]
[Thu Jul 30 15:24:33.261484 2026] [security2:error] [pid 173718:tid 173867] [client 20.63.98.115:31151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/maint/admin.php"] [unique_id "amuzAUoi7QGnEa1uk6mf0wAAABI"]
[Thu Jul 30 15:24:33.268001 2026] [core:notice] [pid 173718:tid 173893] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:33.305838 2026] [security2:error] [pid 173718:tid 173805] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/db.php"] [unique_id "amuzAUoi7QGnEa1uk6mf1QAAClU"]
[Thu Jul 30 15:24:33.416628 2026] [core:notice] [pid 173718:tid 173907] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:33.420322 2026] [security2:error] [pid 173718:tid 173907] [client 66.249.79.229:44093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/download/3614/3757"] [unique_id "amuzAUoi7QGnEa1uk6mf3AAAADo"]
[Thu Jul 30 15:24:33.486428 2026] [security2:error] [pid 173718:tid 173812] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/default.php"] [unique_id "amuzAUoi7QGnEa1uk6mf4AAAJVw"]
[Thu Jul 30 15:24:33.617952 2026] [security2:error] [pid 173718:tid 173964] [client 20.171.55.167:7356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-config.php"] [unique_id "amuzAUoi7QGnEa1uk6mf5AAAAHM"]
[Thu Jul 30 15:24:33.618403 2026] [security2:error] [pid 173718:tid 173815] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/dropdown.php"] [unique_id "amuzAUoi7QGnEa1uk6mf5QAAAl8"]
[Thu Jul 30 15:24:33.623135 2026] [security2:error] [pid 173718:tid 173975] [client 172.237.109.114:4991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzAUoi7QGnEa1uk6mf0AAAAH4"]
[Thu Jul 30 15:24:33.731133 2026] [security2:error] [pid 173718:tid 173814] [remote 5.161.62.209:14548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "moswey.com"] [uri "/.env"] [unique_id "amuzAUoi7QGnEa1uk6mf5wAAQl4"]
[Thu Jul 30 15:24:33.841936 2026] [security2:error] [pid 173718:tid 173816] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/edit.php"] [unique_id "amuzAUoi7QGnEa1uk6mf6QAAKmA"]
[Thu Jul 30 15:24:33.845119 2026] [security2:error] [pid 173718:tid 173968] [client 116.179.32.195:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/issue/view/524"] [unique_id "amuzAUoi7QGnEa1uk6mf4QAAAHc"]
[Thu Jul 30 15:24:34.069046 2026] [security2:error] [pid 173718:tid 173817] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/f35.php"] [unique_id "amuzAkoi7QGnEa1uk6mf8AAARWE"]
[Thu Jul 30 15:24:34.189240 2026] [core:notice] [pid 173718:tid 173917] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:34.216022 2026] [security2:error] [pid 173718:tid 173880] [client 20.63.98.115:31117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ini.php"] [unique_id "amuzAkoi7QGnEa1uk6mf9QAAAB8"]
[Thu Jul 30 15:24:34.268434 2026] [security2:error] [pid 173718:tid 173811] [remote 216.73.216.51:58565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuzAkoi7QGnEa1uk6mf9gAAMls"]
[Thu Jul 30 15:24:34.282847 2026] [security2:error] [pid 173718:tid 173824] [remote 20.203.148.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "markmocek.com"] [uri "/f7.php"] [unique_id "amuzAkoi7QGnEa1uk6mf9wAAX2g"]
[Thu Jul 30 15:24:34.351548 2026] [security2:error] [pid 173718:tid 173897] [client 20.171.55.167:7942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-defaul.php"] [unique_id "amuzAkoi7QGnEa1uk6mf-AAAADA"]
[Thu Jul 30 15:24:34.538878 2026] [security2:error] [pid 173718:tid 173849] [client 119.249.100.175:9707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/issue/view/524"] [unique_id "amuzAkoi7QGnEa1uk6mf_gAAAAA"]
[Thu Jul 30 15:24:34.849658 2026] [security2:error] [pid 173718:tid 173931] [client 38.172.162.57:16058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzAkoi7QGnEa1uk6mgBQAAAFI"]
[Thu Jul 30 15:24:34.849785 2026] [security2:error] [pid 173718:tid 173931] [client 38.172.162.57:16058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzAkoi7QGnEa1uk6mgBQAAAFI"]
[Thu Jul 30 15:24:35.098344 2026] [security2:error] [pid 173718:tid 173854] [client 192.178.4.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hikokigo.com"] [uri "/index.php"] [unique_id "amuzAUoi7QGnEa1uk6mf6AAABV0"]
[Thu Jul 30 15:24:35.123930 2026] [security2:error] [pid 173718:tid 173961] [client 20.171.55.167:7946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-functions.php"] [unique_id "amuzA0oi7QGnEa1uk6mgDAAAAHA"]
[Thu Jul 30 15:24:35.155334 2026] [security2:error] [pid 173718:tid 173870] [client 20.63.98.115:26323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ok.php"] [unique_id "amuzA0oi7QGnEa1uk6mgDQAAABU"]
[Thu Jul 30 15:24:35.199771 2026] [core:notice] [pid 173718:tid 173939] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:35.960951 2026] [security2:error] [pid 173718:tid 173893] [client 103.53.36.228:45142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzA0oi7QGnEa1uk6mgEgAALGo"]
[Thu Jul 30 15:24:36.161005 2026] [security2:error] [pid 173718:tid 173970] [client 20.171.55.167:7237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-info.php"] [unique_id "amuzBEoi7QGnEa1uk6mgJgAAAHk"]
[Thu Jul 30 15:24:36.195492 2026] [core:notice] [pid 173718:tid 173925] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:36.295480 2026] [security2:error] [pid 173718:tid 173908] [client 20.63.98.115:31199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/includes/about.php"] [unique_id "amuzBEoi7QGnEa1uk6mgKgAAADs"]
[Thu Jul 30 15:24:36.947007 2026] [security2:error] [pid 173718:tid 173944] [client 20.171.55.167:7316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-plain.php"] [unique_id "amuzBEoi7QGnEa1uk6mgUwAAAF8"]
[Thu Jul 30 15:24:37.018657 2026] [core:notice] [pid 173718:tid 173951] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:37.715302 2026] [security2:error] [pid 173718:tid 173870] [client 20.171.55.167:7321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-setting.php"] [unique_id "amuzBUoi7QGnEa1uk6mgdgAAABU"]
[Thu Jul 30 15:24:38.417501 2026] [security2:error] [pid 173718:tid 173914] [client 20.63.98.115:32278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-configs.php"] [unique_id "amuzBkoi7QGnEa1uk6mgowAAAEE"]
[Thu Jul 30 15:24:38.443672 2026] [security2:error] [pid 173718:tid 173963] [client 20.171.55.167:7312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wp-user.php"] [unique_id "amuzBkoi7QGnEa1uk6mgpQAAAHI"]
[Thu Jul 30 15:24:38.500897 2026] [security2:error] [pid 173718:tid 173884] [client 47.128.122.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuzBkoi7QGnEa1uk6mgoQAAACM"]
[Thu Jul 30 15:24:38.898156 2026] [core:notice] [pid 173718:tid 173876] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:38.901582 2026] [security2:error] [pid 173718:tid 173876] [client 66.249.79.229:56577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Edunomic/article/download/9140/3960"] [unique_id "amuzBkoi7QGnEa1uk6mguQAAABs"]
[Thu Jul 30 15:24:38.917138 2026] [security2:error] [pid 173718:tid 173954] [client 103.215.75.19:5192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/wp-login.php"] [unique_id "amuzBkoi7QGnEa1uk6mgrwAAAGk"], referer: https://worldofwhiskers.com/
[Thu Jul 30 15:24:39.176369 2026] [core:notice] [pid 173718:tid 173883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:39.179836 2026] [security2:error] [pid 173718:tid 173883] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/1739"] [unique_id "amuzB0oi7QGnEa1uk6mgvQAAACI"]
[Thu Jul 30 15:24:39.199640 2026] [security2:error] [pid 173718:tid 173966] [client 20.171.55.167:7323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wpr-addons/forms/CasperSecurity.php"] [unique_id "amuzB0oi7QGnEa1uk6mgvgAAAHU"]
[Thu Jul 30 15:24:39.749687 2026] [security2:error] [pid 173718:tid 173923] [client 103.215.75.19:5196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/blog/wp-login.php"] [unique_id "amuzB0oi7QGnEa1uk6mgywAAAEo"], referer: https://worldofwhiskers.com/blog/
[Thu Jul 30 15:24:39.760364 2026] [security2:error] [pid 173718:tid 173942] [client 213.152.186.19:33762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzB0oi7QGnEa1uk6mgzAAAAF0"]
[Thu Jul 30 15:24:39.760559 2026] [security2:error] [pid 173718:tid 173942] [client 213.152.186.19:33762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzB0oi7QGnEa1uk6mgzAAAAF0"]
[Thu Jul 30 15:24:39.859648 2026] [security2:error] [pid 173718:tid 173953] [client 103.53.36.100:41968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzB0oi7QGnEa1uk6mgxgAAaEQ"]
[Thu Jul 30 15:24:39.915946 2026] [security2:error] [pid 173718:tid 173940] [client 20.171.55.167:7959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/wso2.7.php"] [unique_id "amuzB0oi7QGnEa1uk6mg1AAAAFs"]
[Thu Jul 30 15:24:39.974443 2026] [security2:error] [pid 173718:tid 173869] [client 116.179.33.73:22001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.33.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/$$$call$$$/page/page/css"] [unique_id "amuzB0oi7QGnEa1uk6mgygAAABQ"], referer: http://www.ejournalugj.com/
[Thu Jul 30 15:24:40.017337 2026] [security2:error] [pid 173718:tid 173870] [client 116.179.33.147:65307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.33.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/$$$call$$$/page/page/css"] [unique_id "amuzB0oi7QGnEa1uk6mgzQAAABU"], referer: http://www.ejournalugj.com/
[Thu Jul 30 15:24:40.502475 2026] [security2:error] [pid 173718:tid 173861] [client 103.215.75.19:55230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/wordpress/wp-login.php"] [unique_id "amuzCEoi7QGnEa1uk6mg8gAAAAw"], referer: https://worldofwhiskers.com/wordpress/
[Thu Jul 30 15:24:40.662086 2026] [security2:error] [pid 173718:tid 173947] [client 20.171.55.167:7334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/xLB2NXAP.php"] [unique_id "amuzCEoi7QGnEa1uk6mg9AAAAGI"]
[Thu Jul 30 15:24:41.096891 2026] [core:notice] [pid 173718:tid 173853] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:41.291741 2026] [security2:error] [pid 173718:tid 173871] [client 103.215.75.19:55238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/wp/wp-login.php"] [unique_id "amuzCUoi7QGnEa1uk6mhEQAAABY"], referer: https://worldofwhiskers.com/wp/
[Thu Jul 30 15:24:41.416591 2026] [security2:error] [pid 173718:tid 173887] [client 216.73.217.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "riyadhprinter.com"] [uri "/index.php"] [unique_id "amuzCUoi7QGnEa1uk6mhDQAAACY"]
[Thu Jul 30 15:24:41.626010 2026] [security2:error] [pid 173718:tid 173931] [client 20.171.55.167:7305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/xmlrpc.php"] [unique_id "amuzCUoi7QGnEa1uk6mhEgAAAFI"]
[Thu Jul 30 15:24:41.911257 2026] [core:notice] [pid 173718:tid 173953] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:41.914859 2026] [security2:error] [pid 173718:tid 173953] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Caruban/article/view/5753/2692"] [unique_id "amuzCUoi7QGnEa1uk6mhJwAAAGg"]
[Thu Jul 30 15:24:42.020027 2026] [security2:error] [pid 173718:tid 173923] [client 103.215.75.19:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/cms/wp-login.php"] [unique_id "amuzCkoi7QGnEa1uk6mhKwAAAEo"], referer: https://worldofwhiskers.com/cms/
[Thu Jul 30 15:24:42.033758 2026] [security2:error] [pid 173718:tid 173968] [client 20.63.98.115:32280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/01.php"] [unique_id "amuzCkoi7QGnEa1uk6mhLgAAAHc"]
[Thu Jul 30 15:24:42.190212 2026] [core:notice] [pid 173718:tid 173842] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:42.219417 2026] [core:notice] [pid 173718:tid 173960] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:42.359549 2026] [core:notice] [pid 173718:tid 173935] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:42.386694 2026] [security2:error] [pid 173718:tid 173930] [client 20.171.55.167:7883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/yindu.php"] [unique_id "amuzCkoi7QGnEa1uk6mhQgAAAFE"]
[Thu Jul 30 15:24:42.824440 2026] [security2:error] [pid 173718:tid 173920] [client 103.215.75.19:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/site/wp-login.php"] [unique_id "amuzCkoi7QGnEa1uk6mhUQAAAEc"], referer: https://worldofwhiskers.com/site/
[Thu Jul 30 15:24:43.105763 2026] [security2:error] [pid 173718:tid 173972] [client 20.171.55.167:7345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/zone.php"] [unique_id "amuzC0oi7QGnEa1uk6mhYQAAAHs"]
[Thu Jul 30 15:24:43.533296 2026] [core:notice] [pid 173718:tid 173734] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:43.628613 2026] [security2:error] [pid 173718:tid 173912] [client 103.215.75.19:55260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/main/wp-login.php"] [unique_id "amuzC0oi7QGnEa1uk6mhfgAAAD8"], referer: https://worldofwhiskers.com/main/
[Thu Jul 30 15:24:44.066041 2026] [security2:error] [pid 173718:tid 173761] [remote 57.141.0.35:57786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5926905694/feed/rss2/"] [unique_id "amuzDEoi7QGnEa1uk6mhiwAATCk"]
[Thu Jul 30 15:24:44.240133 2026] [security2:error] [pid 173718:tid 173941] [client 20.63.98.115:31172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "amuzDEoi7QGnEa1uk6mhkgAAAFw"]
[Thu Jul 30 15:24:44.255498 2026] [security2:error] [pid 173718:tid 173769] [remote 198.38.94.87:47310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/wp-login.php"] [unique_id "amuzDEoi7QGnEa1uk6mhkwAALTE"]
[Thu Jul 30 15:24:44.300025 2026] [security2:error] [pid 173718:tid 173767] [remote 198.38.94.87:53272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-fdb1204b.med.gzj.temporary.site"] [uri "/wp-login.php"] [unique_id "amuzDEoi7QGnEa1uk6mhmAAARS8"]
[Thu Jul 30 15:24:44.352908 2026] [security2:error] [pid 173718:tid 173947] [client 103.215.75.19:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/new/wp-login.php"] [unique_id "amuzDEoi7QGnEa1uk6mhmwAAAGI"], referer: https://worldofwhiskers.com/new/
[Thu Jul 30 15:24:44.682224 2026] [core:notice] [pid 173718:tid 173897] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:44.891450 2026] [security2:error] [pid 173718:tid 173875] [client 103.215.75.19:46418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/wp-login.php"] [unique_id "amuzDEoi7QGnEa1uk6mhrQAAABo"], referer: http://worldofwhiskers.com/
[Thu Jul 30 15:24:45.110191 2026] [security2:error] [pid 173718:tid 173943] [client 74.7.228.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bestdogproductguide.com"] [uri "/robots.txt"] [unique_id "amuzDUoi7QGnEa1uk6mhsgAAXjM"]
[Thu Jul 30 15:24:45.154339 2026] [core:notice] [pid 173718:tid 173865] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:45.158075 2026] [security2:error] [pid 173718:tid 173865] [client 66.249.79.229:63802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/8072/3170"] [unique_id "amuzDUoi7QGnEa1uk6mhswAAABA"]
[Thu Jul 30 15:24:45.404945 2026] [security2:error] [pid 173718:tid 173892] [client 103.215.75.19:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/blog/wp-login.php"] [unique_id "amuzDUoi7QGnEa1uk6mhvAAAACs"], referer: http://worldofwhiskers.com/blog/
[Thu Jul 30 15:24:45.486530 2026] [security2:error] [pid 173718:tid 173879] [client 38.172.162.57:15962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzDUoi7QGnEa1uk6mhvQAAAB4"]
[Thu Jul 30 15:24:45.486669 2026] [security2:error] [pid 173718:tid 173879] [client 38.172.162.57:15962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzDUoi7QGnEa1uk6mhvQAAAB4"]
[Thu Jul 30 15:24:45.668923 2026] [security2:error] [pid 173718:tid 173883] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzDEoi7QGnEa1uk6mhrgAAIig"]
[Thu Jul 30 15:24:45.824665 2026] [core:notice] [pid 173718:tid 173867] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:45.953699 2026] [security2:error] [pid 173718:tid 173903] [client 103.215.75.19:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/wordpress/wp-login.php"] [unique_id "amuzDUoi7QGnEa1uk6mhywAAADY"], referer: http://worldofwhiskers.com/wordpress/
[Thu Jul 30 15:24:46.282804 2026] [core:notice] [pid 173718:tid 173929] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:46.288543 2026] [security2:error] [pid 173718:tid 173929] [client 66.249.79.8:59503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/article/download/1856/1140"] [unique_id "amuzDkoi7QGnEa1uk6mh1wAAAFA"]
[Thu Jul 30 15:24:46.440146 2026] [security2:error] [pid 173718:tid 173941] [client 103.215.75.19:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/wp/wp-login.php"] [unique_id "amuzDkoi7QGnEa1uk6mh2AAAAFw"], referer: http://worldofwhiskers.com/wp/
[Thu Jul 30 15:24:46.723867 2026] [core:notice] [pid 173718:tid 173938] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:46.878164 2026] [security2:error] [pid 173718:tid 173931] [client 20.63.98.115:32290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "amuzDkoi7QGnEa1uk6mh6QAAAFI"]
[Thu Jul 30 15:24:46.920145 2026] [security2:error] [pid 173718:tid 173898] [client 103.215.75.19:46442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/cms/wp-login.php"] [unique_id "amuzDkoi7QGnEa1uk6mh6gAAADE"], referer: http://worldofwhiskers.com/cms/
[Thu Jul 30 15:24:47.189603 2026] [security2:error] [pid 173718:tid 173876] [client 57.141.0.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzDkoi7QGnEa1uk6mh3gAAABs"]
[Thu Jul 30 15:24:47.406255 2026] [security2:error] [pid 173718:tid 173955] [client 103.215.75.19:46458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/site/wp-login.php"] [unique_id "amuzD0oi7QGnEa1uk6mh-gAAAGo"], referer: http://worldofwhiskers.com/site/
[Thu Jul 30 15:24:47.659646 2026] [core:notice] [pid 173718:tid 173907] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:47.663989 2026] [security2:error] [pid 173718:tid 173907] [client 66.249.79.8:55463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/8549/3342"] [unique_id "amuzD0oi7QGnEa1uk6mh_wAAADo"]
[Thu Jul 30 15:24:47.893406 2026] [core:notice] [pid 173718:tid 173963] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:47.960189 2026] [security2:error] [pid 173718:tid 173797] [remote 154.26.129.62:47936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.129.26.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuzD0oi7QGnEa1uk6miCgAAXk0"]
[Thu Jul 30 15:24:47.970570 2026] [security2:error] [pid 173718:tid 173975] [client 103.215.75.19:46464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/main/wp-login.php"] [unique_id "amuzD0oi7QGnEa1uk6miCwAAAH4"], referer: http://worldofwhiskers.com/main/
[Thu Jul 30 15:24:48.336286 2026] [core:notice] [pid 173718:tid 173935] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:48.341543 2026] [security2:error] [pid 173718:tid 173935] [client 66.249.79.1:56309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3915/1954"] [unique_id "amuzEEoi7QGnEa1uk6miEgAAAFY"]
[Thu Jul 30 15:24:48.451740 2026] [security2:error] [pid 173718:tid 173905] [client 103.215.75.19:46472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/new/wp-login.php"] [unique_id "amuzEEoi7QGnEa1uk6miFgAAADg"], referer: http://worldofwhiskers.com/new/
[Thu Jul 30 15:24:48.837882 2026] [core:notice] [pid 173718:tid 173926] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:48.841437 2026] [security2:error] [pid 173718:tid 173926] [client 66.249.79.229:63802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/download/282/174"] [unique_id "amuzEEoi7QGnEa1uk6miHQAAAE0"]
[Thu Jul 30 15:24:49.288452 2026] [security2:error] [pid 173718:tid 173825] [remote 216.73.216.51:16750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuzEUoi7QGnEa1uk6miKwAABWk"]
[Thu Jul 30 15:24:49.340920 2026] [core:notice] [pid 173718:tid 173897] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:49.656322 2026] [security2:error] [pid 173718:tid 173887] [client 172.237.109.114:1895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzEUoi7QGnEa1uk6miJQAAACY"]
[Thu Jul 30 15:24:49.830757 2026] [core:notice] [pid 173718:tid 173873] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:50.330749 2026] [core:notice] [pid 173718:tid 173970] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:51.436785 2026] [security2:error] [pid 173718:tid 173853] [client 20.63.98.115:31184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/upgrade/index.php"] [unique_id "amuzE0oi7QGnEa1uk6miYwAAAAQ"]
[Thu Jul 30 15:24:52.174250 2026] [core:notice] [pid 173718:tid 173951] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:52.216519 2026] [autoindex:error] [pid 173718:tid 173860] [client 44.213.206.96:39563] AH01276: Cannot serve directory /home2/meggzjte/01.serverkr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:24:52.559732 2026] [security2:error] [pid 173718:tid 173833] [remote 47.128.50.88:16604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2020/05/maillots-de-bain-recycles-Surprise-Paris-Delicat-2-1.jpg"] [unique_id "amuzFEoi7QGnEa1uk6migAAAW3E"], referer: https://telegra.ph/
[Thu Jul 30 15:24:52.686068 2026] [core:notice] [pid 173718:tid 173930] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:52.689265 2026] [security2:error] [pid 173718:tid 173930] [client 66.249.79.229:63802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JPA/article/view/4915/2389"] [unique_id "amuzFEoi7QGnEa1uk6mihgAAAFE"]
[Thu Jul 30 15:24:52.829927 2026] [security2:error] [pid 173718:tid 173950] [client 20.63.98.115:65137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/db.php"] [unique_id "amuzFEoi7QGnEa1uk6miiQAAAGU"]
[Thu Jul 30 15:24:53.092463 2026] [core:notice] [pid 173718:tid 173906] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:53.268348 2026] [security2:error] [pid 173718:tid 173888] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzFEoi7QGnEa1uk6mihQAAACc"]
[Thu Jul 30 15:24:53.409804 2026] [security2:error] [pid 173718:tid 173928] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzFEoi7QGnEa1uk6miigAAAE8"]
[Thu Jul 30 15:24:53.952474 2026] [security2:error] [pid 173718:tid 173852] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzFUoi7QGnEa1uk6milwAAAAM"]
[Thu Jul 30 15:24:53.981958 2026] [core:notice] [pid 173718:tid 173875] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:53.985481 2026] [security2:error] [pid 173718:tid 173875] [client 66.249.79.229:63802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jibm/article/view/3382"] [unique_id "amuzFUoi7QGnEa1uk6mipQAAABo"]
[Thu Jul 30 15:24:54.265122 2026] [security2:error] [pid 173718:tid 173976] [client 20.63.98.115:34957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/pages.php"] [unique_id "amuzFkoi7QGnEa1uk6misQAAAH8"]
[Thu Jul 30 15:24:54.559338 2026] [security2:error] [pid 173718:tid 173972] [client 159.148.216.31:37560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzFkoi7QGnEa1uk6miqgAAe3I"]
[Thu Jul 30 15:24:55.036167 2026] [security2:error] [pid 173718:tid 173720] [remote 57.141.0.50:23902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuzFkoi7QGnEa1uk6mivAAAZwA"]
[Thu Jul 30 15:24:55.101958 2026] [core:notice] [pid 173718:tid 173943] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:55.440432 2026] [security2:error] [pid 173718:tid 173924] [client 103.53.36.100:9606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzFkoi7QGnEa1uk6miwgAAS3o"]
[Thu Jul 30 15:24:55.444165 2026] [security2:error] [pid 173718:tid 173837] [remote 57.141.0.66:28440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuzF0oi7QGnEa1uk6mizQAAbXU"]
[Thu Jul 30 15:24:55.854815 2026] [security2:error] [pid 173718:tid 173915] [client 20.63.98.115:32270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/admin.php"] [unique_id "amuzF0oi7QGnEa1uk6mi2wAAAEI"]
[Thu Jul 30 15:24:55.971594 2026] [security2:error] [pid 173718:tid 173906] [client 38.172.162.57:16509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzF0oi7QGnEa1uk6mi8QAAADk"]
[Thu Jul 30 15:24:55.971730 2026] [security2:error] [pid 173718:tid 173906] [client 38.172.162.57:16509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzF0oi7QGnEa1uk6mi8QAAADk"]
[Thu Jul 30 15:24:55.998024 2026] [core:notice] [pid 173718:tid 173913] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:56.671821 2026] [security2:error] [pid 173718:tid 173874] [client 57.141.0.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzGEoi7QGnEa1uk6mi_wAAABk"]
[Thu Jul 30 15:24:56.756876 2026] [core:notice] [pid 173718:tid 173895] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:56.762514 2026] [security2:error] [pid 173718:tid 173895] [client 66.249.79.1:52356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/6507"] [unique_id "amuzGEoi7QGnEa1uk6mjHgAAAC4"]
[Thu Jul 30 15:24:56.780018 2026] [security2:error] [pid 173718:tid 173784] [remote 20.233.187.247:16936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-35ddd216.yxe.zzt.temporary.site"] [uri "/wp-login.php"] [unique_id "amuzGEoi7QGnEa1uk6mjHwAAakA"]
[Thu Jul 30 15:24:57.046667 2026] [security2:error] [pid 173718:tid 173868] [client 20.63.98.115:34951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-load.php"] [unique_id "amuzGUoi7QGnEa1uk6mjJwAAABM"]
[Thu Jul 30 15:24:57.207817 2026] [core:notice] [pid 173718:tid 173856] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:57.211344 2026] [security2:error] [pid 173718:tid 173856] [client 66.249.79.229:63802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/336/215"] [unique_id "amuzGUoi7QGnEa1uk6mjKQAAAAc"]
[Thu Jul 30 15:24:57.703131 2026] [core:notice] [pid 173718:tid 173924] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:58.094266 2026] [security2:error] [pid 173718:tid 173891] [client 134.19.179.195:40068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuzGkoi7QGnEa1uk6mjdQAAACo"]
[Thu Jul 30 15:24:58.094354 2026] [security2:error] [pid 173718:tid 173891] [client 134.19.179.195:40068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amuzGkoi7QGnEa1uk6mjdQAAACo"]
[Thu Jul 30 15:24:58.205828 2026] [core:notice] [pid 173718:tid 173863] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:58.209032 2026] [security2:error] [pid 173718:tid 173863] [client 66.249.79.229:63802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/3690/2234"] [unique_id "amuzGkoi7QGnEa1uk6mjeQAAAA4"]
[Thu Jul 30 15:24:58.229219 2026] [security2:error] [pid 173718:tid 173890] [client 20.63.98.115:31111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/as/function.php"] [unique_id "amuzGkoi7QGnEa1uk6mjegAAACk"]
[Thu Jul 30 15:24:58.704589 2026] [core:notice] [pid 173718:tid 173865] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:58.707538 2026] [security2:error] [pid 173718:tid 173865] [client 66.249.79.229:63802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Caruban/article/view/4398"] [unique_id "amuzGkoi7QGnEa1uk6mjlQAAABA"]
[Thu Jul 30 15:24:58.920434 2026] [security2:error] [pid 173718:tid 173860] [client 103.215.75.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worldofwhiskers.com"] [uri "/index.php"] [unique_id "amuzGEoi7QGnEa1uk6mjIwAAAAs"], referer: https://worldofwhiskers.com/
[Thu Jul 30 15:24:58.960724 2026] [security2:error] [pid 173718:tid 173753] [remote 57.141.0.59:43174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/491057609/feed/rss2/"] [unique_id "amuzGkoi7QGnEa1uk6mjogAAbiE"]
[Thu Jul 30 15:24:59.116871 2026] [security2:error] [pid 173718:tid 173886] [client 20.63.98.115:65128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/filter.php"] [unique_id "amuzG0oi7QGnEa1uk6mjpQAAACU"]
[Thu Jul 30 15:24:59.132881 2026] [security2:error] [pid 173718:tid 173961] [client 66.249.65.39:48797] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "igetvapesonline.com"] [uri "/robots.txt"] [unique_id "amuzG0oi7QGnEa1uk6mjpgAAAHA"]
[Thu Jul 30 15:24:59.149079 2026] [core:error] [pid 173718:tid 173765] [remote 74.7.244.52:38734] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:59.149099 2026] [core:error] [pid 173718:tid 173765] [remote 74.7.244.52:38734] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:24:59.149277 2026] [security2:error] [pid 173718:tid 173951] [client 74.7.244.52:38734] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-2534316e.uix.gzj.temporary.site"] [uri "/index.php"] [unique_id "amuzG0oi7QGnEa1uk6mjpwAAZi0"]
[Thu Jul 30 15:24:59.203151 2026] [core:notice] [pid 173718:tid 173868] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:24:59.393032 2026] [security2:error] [pid 173718:tid 173751] [remote 47.128.50.88:22912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2020/05/maillots-de-bain-recycles-Surprise-Paris-Delicat-1-768x1024.jpg"] [unique_id "amuzG0oi7QGnEa1uk6mjswAAcx8"], referer: https://telegra.ph/
[Thu Jul 30 15:24:59.619621 2026] [fcgid:warn] [pid 173718:tid 173950] (70014)End of file found: [client 18.218.118.203:51352] mod_fcgid: can't get data from http client
[Thu Jul 30 15:24:59.918299 2026] [core:notice] [pid 173718:tid 173880] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:00.392732 2026] [security2:error] [pid 173718:tid 173890] [client 52.238.199.152:10241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inmobiliariadia.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuzHEoi7QGnEa1uk6mjyQAAACk"]
[Thu Jul 30 15:25:00.470291 2026] [security2:error] [pid 173718:tid 173754] [remote 20.54.134.42:2281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuzHEoi7QGnEa1uk6mjzQAASSI"]
[Thu Jul 30 15:25:00.563343 2026] [security2:error] [pid 173718:tid 173910] [client 62.102.148.162:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuzHEoi7QGnEa1uk6mjzgAAAD0"]
[Thu Jul 30 15:25:00.563447 2026] [security2:error] [pid 173718:tid 173910] [client 62.102.148.162:35446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuzHEoi7QGnEa1uk6mjzgAAAD0"]
[Thu Jul 30 15:25:00.937547 2026] [fcgid:warn] [pid 173718:tid 173876] (70014)End of file found: [client 18.218.118.203:63544] mod_fcgid: can't get data from http client
[Thu Jul 30 15:25:01.902735 2026] [core:notice] [pid 173718:tid 173904] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:02.638259 2026] [fcgid:warn] [pid 173718:tid 173947] (70014)End of file found: [client 18.218.118.203:63548] mod_fcgid: can't get data from http client
[Thu Jul 30 15:25:03.185341 2026] [core:notice] [pid 173718:tid 173849] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:03.188971 2026] [security2:error] [pid 173718:tid 173849] [client 66.249.79.229:63802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/3621"] [unique_id "amuzHkoi7QGnEa1uk6mj_gAAAAA"]
[Thu Jul 30 15:25:03.255585 2026] [security2:error] [pid 173718:tid 173920] [client 20.63.98.115:32364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/he.php"] [unique_id "amuzH0oi7QGnEa1uk6mkCAAAAEc"]
[Thu Jul 30 15:25:03.413974 2026] [core:notice] [pid 173718:tid 173915] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:03.417509 2026] [security2:error] [pid 173718:tid 173915] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/4170/2057"] [unique_id "amuzH0oi7QGnEa1uk6mkCQAAAEI"]
[Thu Jul 30 15:25:04.561650 2026] [security2:error] [pid 173718:tid 173923] [client 172.237.109.114:60757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzIEoi7QGnEa1uk6mkHwAAAEo"]
[Thu Jul 30 15:25:04.739436 2026] [security2:error] [pid 173718:tid 173943] [client 213.152.186.19:38042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuzIEoi7QGnEa1uk6mkLAAAAF4"]
[Thu Jul 30 15:25:04.739534 2026] [security2:error] [pid 173718:tid 173943] [client 213.152.186.19:38042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amuzIEoi7QGnEa1uk6mkLAAAAF4"]
[Thu Jul 30 15:25:04.821754 2026] [security2:error] [pid 173718:tid 173964] [client 87.250.224.108:39736] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/robots.txt"] [unique_id "amuzIEoi7QGnEa1uk6mkLQAAAHM"]
[Thu Jul 30 15:25:05.428358 2026] [core:notice] [pid 173718:tid 173891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:05.431827 2026] [security2:error] [pid 173718:tid 173891] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/download/9448/4213"] [unique_id "amuzIUoi7QGnEa1uk6mkOAAAACo"]
[Thu Jul 30 15:25:05.453919 2026] [security2:error] [pid 173718:tid 173872] [client 20.63.98.115:36081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/setup-config.php"] [unique_id "amuzIUoi7QGnEa1uk6mkOQAAABc"]
[Thu Jul 30 15:25:06.527944 2026] [core:notice] [pid 173718:tid 173959] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:06.592926 2026] [security2:error] [pid 173718:tid 173895] [client 20.63.98.115:65115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/languages/wp-login.php"] [unique_id "amuzIkoi7QGnEa1uk6mkUQAAAC4"]
[Thu Jul 30 15:25:06.594089 2026] [security2:error] [pid 173718:tid 173896] [client 38.172.162.57:16261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzIkoi7QGnEa1uk6mkUgAAAC8"]
[Thu Jul 30 15:25:06.594172 2026] [security2:error] [pid 173718:tid 173896] [client 38.172.162.57:16261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzIkoi7QGnEa1uk6mkUgAAAC8"]
[Thu Jul 30 15:25:08.007435 2026] [security2:error] [pid 173718:tid 173778] [remote 74.7.227.39:38694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/favicon.ico"] [unique_id "amuzI0oi7QGnEa1uk6mkbAAAHzo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/favicon.ico?path=/home1/yqegzjte/thdinfinity.com/wp-admin/network
[Thu Jul 30 15:25:08.297533 2026] [core:notice] [pid 173718:tid 173913] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:08.302632 2026] [security2:error] [pid 173718:tid 173913] [client 66.249.79.230:62110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/view/1215"] [unique_id "amuzJEoi7QGnEa1uk6mkcAAAAEA"]
[Thu Jul 30 15:25:08.526276 2026] [core:notice] [pid 173718:tid 173976] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:08.817439 2026] [security2:error] [pid 173718:tid 173935] [client 20.118.34.237:15562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuzJEoi7QGnEa1uk6mkjAAAAFY"]
[Thu Jul 30 15:25:09.336042 2026] [core:notice] [pid 173718:tid 173888] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:09.763643 2026] [security2:error] [pid 173718:tid 173870] [client 139.170.73.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuzJEoi7QGnEa1uk6mkjwAAABU"]
[Thu Jul 30 15:25:09.807562 2026] [security2:error] [pid 173718:tid 173894] [client 66.249.73.98:36692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amuzJUoi7QGnEa1uk6mkmwAAAC0"]
[Thu Jul 30 15:25:10.347090 2026] [core:notice] [pid 173718:tid 173884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:10.570094 2026] [security2:error] [pid 173718:tid 173830] [remote 57.141.0.70:40636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/514832250/feed/rss2/"] [unique_id "amuzJkoi7QGnEa1uk6mkswAAf24"]
[Thu Jul 30 15:25:10.618353 2026] [core:notice] [pid 173718:tid 173955] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:11.066797 2026] [core:notice] [pid 173718:tid 173939] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:11.070305 2026] [security2:error] [pid 173718:tid 173939] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/download/4028/2025"] [unique_id "amuzJ0oi7QGnEa1uk6mkvgAAAFo"]
[Thu Jul 30 15:25:11.260872 2026] [security2:error] [pid 173718:tid 173723] [remote 20.118.34.237:15569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deltaedu.net"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuzJ0oi7QGnEa1uk6mkvwAATgM"]
[Thu Jul 30 15:25:11.560363 2026] [core:notice] [pid 173718:tid 173863] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:11.563757 2026] [security2:error] [pid 173718:tid 173863] [client 66.249.79.230:62110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/7088/2890"] [unique_id "amuzJ0oi7QGnEa1uk6mk0AAAAA4"]
[Thu Jul 30 15:25:12.061574 2026] [core:notice] [pid 173718:tid 173915] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:12.064795 2026] [security2:error] [pid 173718:tid 173915] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Caruban/article/view/9231/4054"] [unique_id "amuzKEoi7QGnEa1uk6mk2gAAAEI"]
[Thu Jul 30 15:25:12.485799 2026] [core:notice] [pid 173718:tid 173858] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:12.560814 2026] [core:notice] [pid 173718:tid 173914] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:12.606197 2026] [security2:error] [pid 173718:tid 173972] [client 43.173.182.80:51082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/02/09/sejourner-a-barcelone-a-lhotel-room-mate-emma/"] [unique_id "amuzKEoi7QGnEa1uk6mk7AAAAHs"]
[Thu Jul 30 15:25:12.634026 2026] [security2:error] [pid 173718:tid 173976] [client 182.54.23.114:64205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amuzJ0oi7QGnEa1uk6mkzAAAAHM"]
[Thu Jul 30 15:25:13.063106 2026] [security2:error] [pid 173718:tid 173943] [client 43.172.197.100:42864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/11/10/look-osez-limprime-python/"] [unique_id "amuzKUoi7QGnEa1uk6mk9wAAAF4"]
[Thu Jul 30 15:25:13.208108 2026] [security2:error] [pid 173718:tid 173911] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzKEoi7QGnEa1uk6mk6wAAAD4"]
[Thu Jul 30 15:25:13.222969 2026] [core:notice] [pid 173718:tid 173936] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:13.228711 2026] [security2:error] [pid 173718:tid 173936] [client 43.173.177.243:53028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2013/02/09/sejourner-a-barcelone-a-lhotel-room-mate-emma/"] [unique_id "amuzKUoi7QGnEa1uk6mk-AAAAFc"], referer: https://carnetdeshopping.com/index.php/2013/02/09/sejourner-a-barcelone-a-lhotel-room-mate-emma/
[Thu Jul 30 15:25:13.358541 2026] [security2:error] [pid 173718:tid 173898] [client 20.63.98.115:36690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/autoload_classmap.php"] [unique_id "amuzKUoi7QGnEa1uk6mk-QAAADE"]
[Thu Jul 30 15:25:13.513055 2026] [core:notice] [pid 173718:tid 173851] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:13.796736 2026] [core:notice] [pid 173718:tid 173854] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:13.802176 2026] [security2:error] [pid 173718:tid 173854] [client 43.173.177.147:56030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2011/11/10/look-osez-limprime-python/"] [unique_id "amuzKUoi7QGnEa1uk6mlBwAAAAU"], referer: https://carnetdeshopping.com/index.php/2011/11/10/look-osez-limprime-python/
[Thu Jul 30 15:25:14.104511 2026] [core:notice] [pid 173718:tid 173964] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:14.108017 2026] [security2:error] [pid 173718:tid 173964] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/logika/article/view/576/359"] [unique_id "amuzKkoi7QGnEa1uk6mlFQAAAHM"]
[Thu Jul 30 15:25:14.418641 2026] [security2:error] [pid 173718:tid 173933] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzKUoi7QGnEa1uk6mlCgAAAFQ"]
[Thu Jul 30 15:25:14.437356 2026] [security2:error] [pid 173718:tid 173885] [client 20.63.98.115:36694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "amuzKkoi7QGnEa1uk6mlJAAAACQ"]
[Thu Jul 30 15:25:14.562758 2026] [core:notice] [pid 173718:tid 173935] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:15.484402 2026] [core:notice] [pid 173718:tid 173956] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:15.488446 2026] [security2:error] [pid 173718:tid 173956] [client 66.249.79.229:54708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3914"] [unique_id "amuzK0oi7QGnEa1uk6mlPAAAAGs"]
[Thu Jul 30 15:25:15.502888 2026] [security2:error] [pid 173718:tid 173950] [client 20.63.98.115:52306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/atomlib.php"] [unique_id "amuzK0oi7QGnEa1uk6mlQAAAAGU"]
[Thu Jul 30 15:25:15.584094 2026] [security2:error] [pid 173718:tid 173934] [client 134.19.179.195:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuzK0oi7QGnEa1uk6mlQQAAAFU"]
[Thu Jul 30 15:25:15.584195 2026] [security2:error] [pid 173718:tid 173934] [client 134.19.179.195:57466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuzK0oi7QGnEa1uk6mlQQAAAFU"]
[Thu Jul 30 15:25:15.717966 2026] [core:notice] [pid 173718:tid 173913] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:16.164462 2026] [core:notice] [pid 173718:tid 173912] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:16.168161 2026] [security2:error] [pid 173718:tid 173912] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/view/30"] [unique_id "amuzLEoi7QGnEa1uk6mlVwAAAD8"]
[Thu Jul 30 15:25:16.196190 2026] [security2:error] [pid 173718:tid 173858] [client 20.63.98.115:61556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "amuzLEoi7QGnEa1uk6mlWAAAAAk"]
[Thu Jul 30 15:25:16.662407 2026] [core:notice] [pid 173718:tid 173881] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:17.013532 2026] [security2:error] [pid 173718:tid 173867] [client 20.63.98.115:42409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/gebase.php"] [unique_id "amuzLUoi7QGnEa1uk6mlaQAAABI"]
[Thu Jul 30 15:25:17.168672 2026] [security2:error] [pid 173718:tid 173930] [client 38.172.162.57:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzLUoi7QGnEa1uk6mlcQAAAFE"]
[Thu Jul 30 15:25:17.169459 2026] [security2:error] [pid 173718:tid 173930] [client 38.172.162.57:16364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzLUoi7QGnEa1uk6mlcQAAAFE"]
[Thu Jul 30 15:25:17.279796 2026] [security2:error] [pid 173718:tid 173958] [client 74.7.230.62:55404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.brianhpark.com"] [uri "/cgi-sys/404.html"] [unique_id "amuzLUoi7QGnEa1uk6mldAAAAG0"]
[Thu Jul 30 15:25:17.869199 2026] [core:notice] [pid 173718:tid 173748] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:17.997717 2026] [security2:error] [pid 173718:tid 173897] [client 20.63.98.115:42381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/xl.php"] [unique_id "amuzLUoi7QGnEa1uk6mlhQAAADA"]
[Thu Jul 30 15:25:18.174118 2026] [autoindex:error] [pid 173718:tid 173913] [client 74.7.227.166:51794] AH01276: Cannot serve directory /home2/lgggplte/brianhpark.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:25:18.316557 2026] [security2:error] [pid 173718:tid 173944] [client 185.191.171.13:38840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/20-anos-de-emancipacao-politica-de-casserengue/"] [unique_id "amuzLkoi7QGnEa1uk6mlkwAAAF8"]
[Thu Jul 30 15:25:18.316675 2026] [security2:error] [pid 173718:tid 173944] [client 185.191.171.13:38840] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/20-anos-de-emancipacao-politica-de-casserengue/"] [unique_id "amuzLkoi7QGnEa1uk6mlkwAAAF8"]
[Thu Jul 30 15:25:18.494795 2026] [core:notice] [pid 173718:tid 173912] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:18.935443 2026] [core:notice] [pid 173718:tid 173911] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:19.384714 2026] [core:notice] [pid 173718:tid 173941] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:19.388322 2026] [security2:error] [pid 173718:tid 173941] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jibm/article/download/7798/pdf/21599"] [unique_id "amuzL0oi7QGnEa1uk6mlrAAAAFw"]
[Thu Jul 30 15:25:19.415853 2026] [security2:error] [pid 173718:tid 173929] [client 20.63.98.115:36714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/2.php"] [unique_id "amuzL0oi7QGnEa1uk6mlsAAAAFA"]
[Thu Jul 30 15:25:19.968422 2026] [core:notice] [pid 173718:tid 173851] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:20.838346 2026] [security2:error] [pid 173718:tid 173967] [client 20.63.98.115:25610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/baxa1.php"] [unique_id "amuzMEoi7QGnEa1uk6mlyAAAAHY"]
[Thu Jul 30 15:25:20.996620 2026] [core:notice] [pid 173718:tid 173915] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:21.546379 2026] [security2:error] [pid 173718:tid 173796] [remote 74.7.243.224:48348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/article.php"] [unique_id "amuzMUoi7QGnEa1uk6ml2wAAC0w"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/1784122808_wilde%20gazen.jpg
[Thu Jul 30 15:25:21.991600 2026] [security2:error] [pid 173718:tid 173923] [client 134.19.179.195:43886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuzMUoi7QGnEa1uk6ml5AAAAEo"]
[Thu Jul 30 15:25:21.991700 2026] [security2:error] [pid 173718:tid 173923] [client 134.19.179.195:43886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amuzMUoi7QGnEa1uk6ml5AAAAEo"]
[Thu Jul 30 15:25:23.694708 2026] [security2:error] [pid 173718:tid 173948] [client 20.63.98.115:25654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/settings.php"] [unique_id "amuzM0oi7QGnEa1uk6mmFAAAAGM"]
[Thu Jul 30 15:25:23.883019 2026] [security2:error] [pid 173718:tid 173880] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzM0oi7QGnEa1uk6mmAAAAAB8"]
[Thu Jul 30 15:25:23.917586 2026] [core:notice] [pid 173718:tid 173909] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:23.949394 2026] [fcgid:warn] [pid 173718:tid 173885] (70014)End of file found: [client 172.237.109.114:26129] mod_fcgid: can't get data from http client
[Thu Jul 30 15:25:24.357287 2026] [core:notice] [pid 173718:tid 173927] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:24.360836 2026] [security2:error] [pid 173718:tid 173927] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/9145/3965"] [unique_id "amuzNEoi7QGnEa1uk6mmIwAAAE4"]
[Thu Jul 30 15:25:24.811795 2026] [security2:error] [pid 173718:tid 173898] [client 172.237.109.114:60878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzNEoi7QGnEa1uk6mmIgAAAHk"]
[Thu Jul 30 15:25:24.811828 2026] [security2:error] [pid 173718:tid 173898] [client 172.237.109.114:60878] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzNEoi7QGnEa1uk6mmIgAAAHk"]
[Thu Jul 30 15:25:24.869620 2026] [core:notice] [pid 173718:tid 173938] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:24.990470 2026] [core:notice] [pid 173718:tid 173832] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:25.146597 2026] [security2:error] [pid 173718:tid 173896] [client 172.120.11.254:40140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzNEoi7QGnEa1uk6mmLAAAL20"]
[Thu Jul 30 15:25:25.356288 2026] [core:notice] [pid 173718:tid 173934] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:25.359831 2026] [security2:error] [pid 173718:tid 173934] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/tumed/article/download/8022/3144"] [unique_id "amuzNUoi7QGnEa1uk6mmQQAAAFU"]
[Thu Jul 30 15:25:25.544161 2026] [security2:error] [pid 173718:tid 173876] [client 142.93.64.197:42738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuzNUoi7QGnEa1uk6mmRQAAABs"]
[Thu Jul 30 15:25:25.764098 2026] [security2:error] [pid 173718:tid 173894] [client 142.93.64.197:46692] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.6.43.248"] [uri "/"] [unique_id "amuzNUoi7QGnEa1uk6mmVgAAAC0"]
[Thu Jul 30 15:25:26.297217 2026] [core:notice] [pid 173718:tid 173859] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:26.300727 2026] [security2:error] [pid 173718:tid 173859] [client 66.249.79.229:55386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/agrijati/article/view/2943/1571"] [unique_id "amuzNkoi7QGnEa1uk6mmbgAAAAo"]
[Thu Jul 30 15:25:26.743652 2026] [core:notice] [pid 173718:tid 173923] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:26.746827 2026] [security2:error] [pid 173718:tid 173923] [client 66.249.79.237:53660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/tumed/article/view/4985"] [unique_id "amuzNkoi7QGnEa1uk6mmdgAAAEo"]
[Thu Jul 30 15:25:26.769388 2026] [security2:error] [pid 173718:tid 173915] [client 20.63.98.115:52298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/dropdown.php"] [unique_id "amuzNkoi7QGnEa1uk6mmeAAAAEI"]
[Thu Jul 30 15:25:26.805604 2026] [core:notice] [pid 173718:tid 173746] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:26.974324 2026] [core:notice] [pid 173718:tid 173955] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:27.758856 2026] [core:notice] [pid 173718:tid 173924] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:27.760828 2026] [security2:error] [pid 173718:tid 173939] [client 38.172.162.57:16180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzN0oi7QGnEa1uk6mmowAAAFo"]
[Thu Jul 30 15:25:27.761909 2026] [security2:error] [pid 173718:tid 173939] [client 38.172.162.57:16180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzN0oi7QGnEa1uk6mmowAAAFo"]
[Thu Jul 30 15:25:27.762185 2026] [security2:error] [pid 173718:tid 173924] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/1320"] [unique_id "amuzN0oi7QGnEa1uk6mmogAAAEs"]
[Thu Jul 30 15:25:28.253188 2026] [autoindex:error] [pid 173718:tid 173956] [client 157.143.3.35:0] AH01276: Cannot serve directory /home2/mbmudite/ok.otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:25:28.818334 2026] [core:error] [pid 173718:tid 173904] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:28.818359 2026] [core:error] [pid 173718:tid 173904] [client 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:28.818492 2026] [security2:error] [pid 173718:tid 173904] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.kayomanis.com"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amuzOEoi7QGnEa1uk6mm0gAAADc"]
[Thu Jul 30 15:25:28.819457 2026] [security2:error] [pid 173718:tid 173858] [client 74.7.244.51:57794] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.kayomanis.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amuzOEoi7QGnEa1uk6mm0AAACUU"]
[Thu Jul 30 15:25:28.872757 2026] [security2:error] [pid 173718:tid 173796] [remote 43.165.2.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.2.165.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/index/login/signIn"] [unique_id "amuzOEoi7QGnEa1uk6mm1gAASkw"]
[Thu Jul 30 15:25:29.011167 2026] [core:notice] [pid 173718:tid 173907] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:29.609910 2026] [core:notice] [pid 173718:tid 173949] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:31.147680 2026] [core:notice] [pid 173718:tid 173954] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:31.151133 2026] [security2:error] [pid 173718:tid 173954] [client 66.249.79.229:63019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/download/572/354"] [unique_id "amuzO0oi7QGnEa1uk6mnDgAAAGk"]
[Thu Jul 30 15:25:31.381339 2026] [core:notice] [pid 173718:tid 173871] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:31.385013 2026] [security2:error] [pid 173718:tid 173871] [client 66.249.79.229:63019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/943/682"] [unique_id "amuzO0oi7QGnEa1uk6mnFQAAABY"]
[Thu Jul 30 15:25:31.429174 2026] [autoindex:error] [pid 173718:tid 173933] [client 85.204.70.116:38210] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:25:31.540097 2026] [security2:error] [pid 173718:tid 173943] [client 20.63.98.115:26509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin.php"] [unique_id "amuzO0oi7QGnEa1uk6mnGgAAAF4"]
[Thu Jul 30 15:25:31.570217 2026] [autoindex:error] [pid 173718:tid 173960] [client 85.204.70.116:38210] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:25:31.702627 2026] [security2:error] [pid 173718:tid 173940] [client 85.204.70.116:38210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuzO0oi7QGnEa1uk6mnHwAAAFs"]
[Thu Jul 30 15:25:31.749537 2026] [core:notice] [pid 173718:tid 173803] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:31.833175 2026] [core:notice] [pid 173718:tid 173875] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:31.989917 2026] [core:notice] [pid 173718:tid 173778] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:32.003763 2026] [security2:error] [pid 173718:tid 173930] [client 85.204.70.116:27247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/xmlrpc.php"] [unique_id "amuzO0oi7QGnEa1uk6mnJgAAAFE"]
[Thu Jul 30 15:25:32.274470 2026] [autoindex:error] [pid 173718:tid 173916] [client 85.204.70.116:62301] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:25:32.343765 2026] [security2:error] [pid 173718:tid 173795] [remote 198.38.90.25:32928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.90.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-login.php"] [unique_id "amuzPEoi7QGnEa1uk6mnLwAAYks"]
[Thu Jul 30 15:25:32.402682 2026] [security2:error] [pid 173718:tid 173872] [client 85.204.70.116:62301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuzPEoi7QGnEa1uk6mnMwAAABc"]
[Thu Jul 30 15:25:32.690448 2026] [security2:error] [pid 173718:tid 173974] [client 85.204.70.116:34370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuzPEoi7QGnEa1uk6mnOgAAAH0"]
[Thu Jul 30 15:25:32.977872 2026] [security2:error] [pid 173718:tid 173910] [client 85.204.70.116:34372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuzPEoi7QGnEa1uk6mnPgAAAD0"]
[Thu Jul 30 15:25:33.081437 2026] [security2:error] [pid 173718:tid 173869] [client 127.0.0.1:53636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuzPUoi7QGnEa1uk6mnQAAAABQ"]
[Thu Jul 30 15:25:33.081515 2026] [security2:error] [pid 173718:tid 173887] [client 74.7.244.55:57746] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.xdi.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amuzPUoi7QGnEa1uk6mnPwAAJmU"]
[Thu Jul 30 15:25:33.229628 2026] [security2:error] [pid 173718:tid 173878] [client 85.204.70.116:34380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuzPUoi7QGnEa1uk6mnTAAAAB0"]
[Thu Jul 30 15:25:33.458134 2026] [core:notice] [pid 173718:tid 173884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:33.461309 2026] [security2:error] [pid 173718:tid 173884] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/8079"] [unique_id "amuzPUoi7QGnEa1uk6mnUwAAACM"]
[Thu Jul 30 15:25:33.529356 2026] [security2:error] [pid 173718:tid 173962] [client 85.204.70.116:34394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuzPUoi7QGnEa1uk6mnVAAAAHE"]
[Thu Jul 30 15:25:33.838042 2026] [security2:error] [pid 173718:tid 173953] [client 85.204.70.116:29292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuzPUoi7QGnEa1uk6mnXAAAAGg"]
[Thu Jul 30 15:25:33.903260 2026] [core:notice] [pid 173718:tid 173883] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:33.923790 2026] [core:notice] [pid 173718:tid 173877] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:34.067557 2026] [security2:error] [pid 173718:tid 173924] [client 20.63.98.115:26516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/buy.php"] [unique_id "amuzPkoi7QGnEa1uk6mnZAAAAEs"]
[Thu Jul 30 15:25:34.134021 2026] [security2:error] [pid 173718:tid 173929] [client 85.204.70.116:34408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuzPkoi7QGnEa1uk6mnZQAAAFA"]
[Thu Jul 30 15:25:34.159366 2026] [security2:error] [pid 173718:tid 173931] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzPUoi7QGnEa1uk6mnVQAAUnE"]
[Thu Jul 30 15:25:34.269378 2026] [security2:error] [pid 173718:tid 173836] [remote 198.38.94.87:58022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/wp-login.php"] [unique_id "amuzPkoi7QGnEa1uk6mnbwAAXnQ"]
[Thu Jul 30 15:25:34.400776 2026] [core:notice] [pid 173718:tid 173926] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:34.404160 2026] [security2:error] [pid 173718:tid 173926] [client 66.249.79.229:63019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/download/681/430"] [unique_id "amuzPkoi7QGnEa1uk6mncgAAAE0"]
[Thu Jul 30 15:25:34.414618 2026] [security2:error] [pid 173718:tid 173969] [client 85.204.70.116:34422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuzPkoi7QGnEa1uk6mndQAAAHg"]
[Thu Jul 30 15:25:34.549787 2026] [security2:error] [pid 173718:tid 173973] [client 103.4.249.9:43512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzPkoi7QGnEa1uk6mnYwAAfAY"]
[Thu Jul 30 15:25:34.711497 2026] [security2:error] [pid 173718:tid 173934] [client 85.204.70.116:34426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuzPkoi7QGnEa1uk6mneQAAAFU"]
[Thu Jul 30 15:25:34.957280 2026] [security2:error] [pid 173718:tid 173894] [client 85.204.70.116:34434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuzPkoi7QGnEa1uk6mnggAAAC0"]
[Thu Jul 30 15:25:35.241841 2026] [security2:error] [pid 173718:tid 173860] [client 85.204.70.116:34436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuzP0oi7QGnEa1uk6mnhwAAAAs"]
[Thu Jul 30 15:25:35.396567 2026] [security2:error] [pid 173718:tid 173834] [remote 193.200.221.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.221.200.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caflchimneysweeper.com"] [uri "/wp/wp-login.php"] [unique_id "amuzP0oi7QGnEa1uk6mnjwAAVnI"]
[Thu Jul 30 15:25:35.397189 2026] [core:notice] [pid 173718:tid 173845] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:35.412279 2026] [security2:error] [pid 173718:tid 173881] [client 172.237.109.114:14177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzPkoi7QGnEa1uk6mngAAAAHY"]
[Thu Jul 30 15:25:35.412304 2026] [security2:error] [pid 173718:tid 173881] [client 172.237.109.114:14177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzPkoi7QGnEa1uk6mngAAAAHY"]
[Thu Jul 30 15:25:35.557084 2026] [security2:error] [pid 173718:tid 173852] [client 85.204.70.116:11340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuzP0oi7QGnEa1uk6mnlQAAAAM"]
[Thu Jul 30 15:25:35.687836 2026] [security2:error] [pid 173718:tid 173915] [client 50.6.43.217:57612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuzP0oi7QGnEa1uk6mnlgAAAEI"]
[Thu Jul 30 15:25:35.802775 2026] [security2:error] [pid 173718:tid 173920] [client 85.204.70.116:34448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "melatipkr.xyz.mbm.udi.temporary.site"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuzP0oi7QGnEa1uk6mnrAAAAEc"]
[Thu Jul 30 15:25:35.836256 2026] [security2:error] [pid 173718:tid 173892] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuzP0oi7QGnEa1uk6mnugAAACs"]
[Thu Jul 30 15:25:35.836411 2026] [security2:error] [pid 173718:tid 173892] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuzP0oi7QGnEa1uk6mnugAAACs"]
[Thu Jul 30 15:25:35.845786 2026] [security2:error] [pid 173718:tid 173871] [client 50.6.43.217:57624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amuzP0oi7QGnEa1uk6mnpQAAABY"]
[Thu Jul 30 15:25:35.899775 2026] [security2:error] [pid 173718:tid 173928] [client 57.141.0.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzP0oi7QGnEa1uk6mniwAAAE8"]
[Thu Jul 30 15:25:36.169740 2026] [security2:error] [pid 173718:tid 173897] [client 20.63.98.115:22244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/mini.php"] [unique_id "amuzQEoi7QGnEa1uk6mnwAAAADA"]
[Thu Jul 30 15:25:36.314670 2026] [security2:error] [pid 173718:tid 173969] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuzQEoi7QGnEa1uk6mnxAAAAHg"]
[Thu Jul 30 15:25:36.314778 2026] [security2:error] [pid 173718:tid 173969] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuzQEoi7QGnEa1uk6mnxAAAAHg"]
[Thu Jul 30 15:25:36.522635 2026] [core:notice] [pid 173718:tid 173905] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:36.604963 2026] [security2:error] [pid 173718:tid 173940] [client 185.152.39.46:39948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzQEoi7QGnEa1uk6mnvwAAWyU"]
[Thu Jul 30 15:25:36.782603 2026] [security2:error] [pid 173718:tid 173888] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wicked.php"] [unique_id "amuzQEoi7QGnEa1uk6mnzAAAACc"]
[Thu Jul 30 15:25:36.782768 2026] [security2:error] [pid 173718:tid 173888] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wicked.php"] [unique_id "amuzQEoi7QGnEa1uk6mnzAAAACc"]
[Thu Jul 30 15:25:37.232046 2026] [core:notice] [pid 173718:tid 173874] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:37.235542 2026] [security2:error] [pid 173718:tid 173874] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/view/2957"] [unique_id "amuzQUoi7QGnEa1uk6mn2AAAABk"]
[Thu Jul 30 15:25:37.249133 2026] [security2:error] [pid 173718:tid 173862] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wpx.php"] [unique_id "amuzQUoi7QGnEa1uk6mn2gAAAA0"]
[Thu Jul 30 15:25:37.249213 2026] [security2:error] [pid 173718:tid 173862] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wpx.php"] [unique_id "amuzQUoi7QGnEa1uk6mn2gAAAA0"]
[Thu Jul 30 15:25:37.266298 2026] [core:notice] [pid 173718:tid 173872] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:37.348196 2026] [core:notice] [pid 173718:tid 173736] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:37.558330 2026] [core:notice] [pid 173718:tid 173923] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:37.699263 2026] [core:notice] [pid 173718:tid 173944] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:37.715919 2026] [security2:error] [pid 173718:tid 173933] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/images.php"] [unique_id "amuzQUoi7QGnEa1uk6mn8AAAAFQ"]
[Thu Jul 30 15:25:37.716073 2026] [security2:error] [pid 173718:tid 173933] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/images.php"] [unique_id "amuzQUoi7QGnEa1uk6mn8AAAAFQ"]
[Thu Jul 30 15:25:37.792792 2026] [security2:error] [pid 173718:tid 173922] [client 20.63.98.115:39995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cd.php"] [unique_id "amuzQUoi7QGnEa1uk6mn_QAAAEk"]
[Thu Jul 30 15:25:37.858495 2026] [core:notice] [pid 173718:tid 173871] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:38.148092 2026] [core:notice] [pid 173718:tid 173963] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:38.182713 2026] [security2:error] [pid 173718:tid 173958] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/1xmomo.php"] [unique_id "amuzQkoi7QGnEa1uk6moHgAAAG0"]
[Thu Jul 30 15:25:38.182827 2026] [security2:error] [pid 173718:tid 173958] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/1xmomo.php"] [unique_id "amuzQkoi7QGnEa1uk6moHgAAAG0"]
[Thu Jul 30 15:25:38.184021 2026] [security2:error] [pid 173718:tid 173825] [remote 57.141.0.31:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5351135361/feed/rss2/"] [unique_id "amuzQkoi7QGnEa1uk6moHwAAUGk"]
[Thu Jul 30 15:25:38.317665 2026] [core:notice] [pid 173718:tid 173947] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:38.321176 2026] [security2:error] [pid 173718:tid 173947] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/1498/886"] [unique_id "amuzQkoi7QGnEa1uk6moIAAAAGI"]
[Thu Jul 30 15:25:38.366761 2026] [security2:error] [pid 173718:tid 173907] [client 38.172.162.57:16593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzQkoi7QGnEa1uk6moJAAAADo"]
[Thu Jul 30 15:25:38.366892 2026] [security2:error] [pid 173718:tid 173907] [client 38.172.162.57:16593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzQkoi7QGnEa1uk6moJAAAADo"]
[Thu Jul 30 15:25:38.412050 2026] [security2:error] [pid 173718:tid 173918] [client 172.252.31.32:30456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzQUoi7QGnEa1uk6moDgAARUg"]
[Thu Jul 30 15:25:38.651961 2026] [security2:error] [pid 173718:tid 173853] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/1revo.php"] [unique_id "amuzQkoi7QGnEa1uk6moNgAAAAQ"]
[Thu Jul 30 15:25:38.652075 2026] [security2:error] [pid 173718:tid 173853] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/1revo.php"] [unique_id "amuzQkoi7QGnEa1uk6moNgAAAAQ"]
[Thu Jul 30 15:25:38.656486 2026] [security2:error] [pid 173718:tid 173905] [client 20.63.98.115:26502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/images/admin.php"] [unique_id "amuzQkoi7QGnEa1uk6moNwAAADg"]
[Thu Jul 30 15:25:39.117874 2026] [security2:error] [pid 173718:tid 173881] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/cong.php"] [unique_id "amuzQ0oi7QGnEa1uk6moSQAAACA"]
[Thu Jul 30 15:25:39.117995 2026] [security2:error] [pid 173718:tid 173881] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/cong.php"] [unique_id "amuzQ0oi7QGnEa1uk6moSQAAACA"]
[Thu Jul 30 15:25:39.258791 2026] [core:notice] [pid 173718:tid 173872] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:39.261906 2026] [security2:error] [pid 173718:tid 173872] [client 66.249.79.229:54975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/4480/3767"] [unique_id "amuzQ0oi7QGnEa1uk6moWAAAABc"]
[Thu Jul 30 15:25:39.587936 2026] [security2:error] [pid 173718:tid 173933] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/a.php"] [unique_id "amuzQ0oi7QGnEa1uk6modAAAAFQ"]
[Thu Jul 30 15:25:39.588094 2026] [security2:error] [pid 173718:tid 173933] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/a.php"] [unique_id "amuzQ0oi7QGnEa1uk6modAAAAFQ"]
[Thu Jul 30 15:25:40.059606 2026] [security2:error] [pid 173718:tid 173969] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/srontol.php"] [unique_id "amuzREoi7QGnEa1uk6mojgAAAHg"]
[Thu Jul 30 15:25:40.059703 2026] [security2:error] [pid 173718:tid 173969] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/srontol.php"] [unique_id "amuzREoi7QGnEa1uk6mojgAAAHg"]
[Thu Jul 30 15:25:40.312140 2026] [security2:error] [pid 173718:tid 173972] [client 135.119.63.61:7957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/faq.php"] [unique_id "amuzREoi7QGnEa1uk6monAAAAHs"]
[Thu Jul 30 15:25:40.526879 2026] [security2:error] [pid 173718:tid 173973] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/reop3.php"] [unique_id "amuzREoi7QGnEa1uk6moqgAAAHw"]
[Thu Jul 30 15:25:40.526965 2026] [security2:error] [pid 173718:tid 173973] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/reop3.php"] [unique_id "amuzREoi7QGnEa1uk6moqgAAAHw"]
[Thu Jul 30 15:25:40.771639 2026] [core:notice] [pid 173718:tid 173905] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:40.993791 2026] [security2:error] [pid 173718:tid 173882] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/file5.php"] [unique_id "amuzREoi7QGnEa1uk6movwAAACE"]
[Thu Jul 30 15:25:40.993937 2026] [security2:error] [pid 173718:tid 173882] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/file5.php"] [unique_id "amuzREoi7QGnEa1uk6movwAAACE"]
[Thu Jul 30 15:25:41.238275 2026] [core:notice] [pid 173718:tid 173889] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:41.309406 2026] [security2:error] [pid 173718:tid 173922] [client 20.63.98.115:46715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/batm.php"] [unique_id "amuzRUoi7QGnEa1uk6mozwAAAEk"]
[Thu Jul 30 15:25:41.460886 2026] [security2:error] [pid 173718:tid 173965] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/domvf.php"] [unique_id "amuzRUoi7QGnEa1uk6mo1wAAAHQ"]
[Thu Jul 30 15:25:41.461016 2026] [security2:error] [pid 173718:tid 173965] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/domvf.php"] [unique_id "amuzRUoi7QGnEa1uk6mo1wAAAHQ"]
[Thu Jul 30 15:25:41.504356 2026] [security2:error] [pid 173718:tid 173874] [client 135.119.63.61:8246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/fatal.php"] [unique_id "amuzRUoi7QGnEa1uk6mo2AAAABk"]
[Thu Jul 30 15:25:41.930285 2026] [security2:error] [pid 173718:tid 173865] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/zero.php"] [unique_id "amuzRUoi7QGnEa1uk6mo6wAAABA"]
[Thu Jul 30 15:25:41.930405 2026] [security2:error] [pid 173718:tid 173865] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/zero.php"] [unique_id "amuzRUoi7QGnEa1uk6mo6wAAABA"]
[Thu Jul 30 15:25:42.072799 2026] [core:notice] [pid 173718:tid 173878] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:42.217694 2026] [security2:error] [pid 173718:tid 173823] [remote 57.141.0.30:43146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuzRkoi7QGnEa1uk6mo9gAAMGc"]
[Thu Jul 30 15:25:42.344464 2026] [proxy:error] [pid 173718:tid 173947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:25:42.344552 2026] [proxy_http:error] [pid 173718:tid 173947] [client 44.213.206.96:63667] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:25:42.345126 2026] [proxy:error] [pid 173718:tid 173947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:25:42.345170 2026] [proxy_http:error] [pid 173718:tid 173947] [client 44.213.206.96:63667] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:25:42.376156 2026] [security2:error] [pid 173718:tid 173953] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzRUoi7QGnEa1uk6mo6gAAAGg"]
[Thu Jul 30 15:25:42.394182 2026] [security2:error] [pid 173718:tid 173955] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/002.php"] [unique_id "amuzRkoi7QGnEa1uk6mo_QAAAGo"]
[Thu Jul 30 15:25:42.394262 2026] [security2:error] [pid 173718:tid 173955] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/002.php"] [unique_id "amuzRkoi7QGnEa1uk6mo_QAAAGo"]
[Thu Jul 30 15:25:42.481065 2026] [proxy:error] [pid 173718:tid 173918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:25:42.481138 2026] [proxy_http:error] [pid 173718:tid 173918] [client 3.225.222.228:61638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:25:42.481290 2026] [core:notice] [pid 173718:tid 173903] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:42.481695 2026] [proxy:error] [pid 173718:tid 173918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:25:42.481738 2026] [proxy_http:error] [pid 173718:tid 173918] [client 3.225.222.228:61638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:25:42.529842 2026] [security2:error] [pid 173718:tid 173944] [client 20.63.98.115:22256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/hehehehe.php"] [unique_id "amuzRkoi7QGnEa1uk6mpAwAAAF8"]
[Thu Jul 30 15:25:42.683176 2026] [security2:error] [pid 173718:tid 173937] [client 135.119.63.61:7982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/favicon.php"] [unique_id "amuzRkoi7QGnEa1uk6mpCgAAAFg"]
[Thu Jul 30 15:25:42.863236 2026] [security2:error] [pid 173718:tid 173959] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/thoms.php"] [unique_id "amuzRkoi7QGnEa1uk6mpEAAAAG4"]
[Thu Jul 30 15:25:42.863341 2026] [security2:error] [pid 173718:tid 173959] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/thoms.php"] [unique_id "amuzRkoi7QGnEa1uk6mpEAAAAG4"]
[Thu Jul 30 15:25:43.238568 2026] [core:notice] [pid 173718:tid 173874] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:43.329406 2026] [security2:error] [pid 173718:tid 173927] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/fi22.php"] [unique_id "amuzR0oi7QGnEa1uk6mpIgAAAE4"]
[Thu Jul 30 15:25:43.329511 2026] [security2:error] [pid 173718:tid 173927] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/fi22.php"] [unique_id "amuzR0oi7QGnEa1uk6mpIgAAAE4"]
[Thu Jul 30 15:25:43.440053 2026] [security2:error] [pid 173718:tid 173833] [remote 57.141.0.12:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/64637765089/feed/rss2/"] [unique_id "amuzR0oi7QGnEa1uk6mpIwAAfXE"]
[Thu Jul 30 15:25:43.529001 2026] [security2:error] [pid 173718:tid 173887] [client 85.208.96.199:25268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/07/26/ministro-alexandre-de-moraes-prorroga-prisao-de-bolsonarista-que-ameacou-lula-e-ministros-do-stf/"] [unique_id "amuzR0oi7QGnEa1uk6mpJwAAACY"]
[Thu Jul 30 15:25:43.529172 2026] [security2:error] [pid 173718:tid 173887] [client 85.208.96.199:25268] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/07/26/ministro-alexandre-de-moraes-prorroga-prisao-de-bolsonarista-que-ameacou-lula-e-ministros-do-stf/"] [unique_id "amuzR0oi7QGnEa1uk6mpJwAAACY"]
[Thu Jul 30 15:25:43.590613 2026] [security2:error] [pid 173718:tid 173858] [client 135.119.63.61:8236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/fck.php"] [unique_id "amuzR0oi7QGnEa1uk6mpKwAAAAk"]
[Thu Jul 30 15:25:43.624767 2026] [core:error] [pid 173718:tid 173968] [client 158.69.117.45:51530] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.624789 2026] [core:error] [pid 173718:tid 173968] [client 158.69.117.45:51530] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.639313 2026] [core:error] [pid 173718:tid 173915] [client 158.69.117.45:30049] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.639331 2026] [core:error] [pid 173718:tid 173915] [client 158.69.117.45:30049] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.644008 2026] [core:error] [pid 173718:tid 173850] [client 158.69.117.45:19281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.644026 2026] [core:error] [pid 173718:tid 173850] [client 158.69.117.45:19281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.650859 2026] [core:error] [pid 173718:tid 173960] [client 158.69.117.45:23646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.650876 2026] [core:error] [pid 173718:tid 173960] [client 158.69.117.45:23646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.654628 2026] [core:error] [pid 173718:tid 173933] [client 158.69.117.45:25678] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.654643 2026] [core:error] [pid 173718:tid 173933] [client 158.69.117.45:25678] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.655368 2026] [core:error] [pid 173718:tid 173868] [client 158.69.117.45:60817] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.655390 2026] [core:error] [pid 173718:tid 173868] [client 158.69.117.45:60817] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.671009 2026] [core:error] [pid 173718:tid 173883] [client 158.69.117.45:10324] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.671027 2026] [core:error] [pid 173718:tid 173883] [client 158.69.117.45:10324] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:43.770683 2026] [security2:error] [pid 173718:tid 173806] [remote 57.141.0.8:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amuzR0oi7QGnEa1uk6mpPgAAK1Y"]
[Thu Jul 30 15:25:43.807408 2026] [security2:error] [pid 173718:tid 173941] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.jookreview.com"] [uri "/___proxy_subdomain_webdisk/wp-content/"] [unique_id "amuzR0oi7QGnEa1uk6mpPwAAAFw"]
[Thu Jul 30 15:25:43.889544 2026] [security2:error] [pid 173718:tid 173942] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzR0oi7QGnEa1uk6mpIQAAAF0"]
[Thu Jul 30 15:25:44.044252 2026] [security2:error] [pid 173718:tid 173939] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/82.php"] [unique_id "amuzSEoi7QGnEa1uk6mpQgAAAFo"]
[Thu Jul 30 15:25:44.044353 2026] [security2:error] [pid 173718:tid 173939] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/82.php"] [unique_id "amuzSEoi7QGnEa1uk6mpQgAAAFo"]
[Thu Jul 30 15:25:44.365101 2026] [core:notice] [pid 173718:tid 173876] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:44.368609 2026] [security2:error] [pid 173718:tid 173876] [client 66.249.79.229:60986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/download/3505/2218"] [unique_id "amuzSEoi7QGnEa1uk6mpTQAAABs"]
[Thu Jul 30 15:25:44.421085 2026] [core:error] [pid 173718:tid 173854] [client 158.69.117.45:16517] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.421107 2026] [core:error] [pid 173718:tid 173854] [client 158.69.117.45:16517] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.430519 2026] [core:error] [pid 173718:tid 173888] [client 158.69.117.45:15045] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.430538 2026] [core:error] [pid 173718:tid 173888] [client 158.69.117.45:15045] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.431201 2026] [core:error] [pid 173718:tid 173950] [client 158.69.117.45:29368] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.431218 2026] [core:error] [pid 173718:tid 173950] [client 158.69.117.45:29368] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.431370 2026] [security2:error] [pid 173718:tid 173962] [client 2a03:2880:f800:2f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzR0oi7QGnEa1uk6mpOgAAcQY"]
[Thu Jul 30 15:25:44.460491 2026] [core:error] [pid 173718:tid 173945] [client 158.69.117.45:35531] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.460507 2026] [core:error] [pid 173718:tid 173945] [client 158.69.117.45:35531] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.511398 2026] [security2:error] [pid 173718:tid 173922] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/sx.php"] [unique_id "amuzSEoi7QGnEa1uk6mpWAAAAEk"]
[Thu Jul 30 15:25:44.511508 2026] [security2:error] [pid 173718:tid 173922] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/sx.php"] [unique_id "amuzSEoi7QGnEa1uk6mpWAAAAEk"]
[Thu Jul 30 15:25:44.624316 2026] [core:error] [pid 173718:tid 173961] [client 158.69.117.45:46403] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.624341 2026] [core:error] [pid 173718:tid 173961] [client 158.69.117.45:46403] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.624662 2026] [core:error] [pid 173718:tid 173913] [client 158.69.117.45:6067] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.624675 2026] [core:error] [pid 173718:tid 173913] [client 158.69.117.45:6067] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:44.981439 2026] [security2:error] [pid 173718:tid 173911] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/dex.php"] [unique_id "amuzSEoi7QGnEa1uk6mpaQAAAD4"]
[Thu Jul 30 15:25:44.981575 2026] [security2:error] [pid 173718:tid 173911] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/dex.php"] [unique_id "amuzSEoi7QGnEa1uk6mpaQAAAD4"]
[Thu Jul 30 15:25:45.042308 2026] [security2:error] [pid 173718:tid 173967] [client 57.141.0.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzSEoi7QGnEa1uk6mpVwAAAHY"]
[Thu Jul 30 15:25:45.053517 2026] [security2:error] [pid 173718:tid 173721] [remote 104.244.79.40:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.79.244.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qpsuae.com"] [uri "/wp-includes/wp-login.php"] [unique_id "amuzSUoi7QGnEa1uk6mpagAACQE"]
[Thu Jul 30 15:25:45.363960 2026] [core:notice] [pid 173718:tid 173867] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:45.372427 2026] [core:error] [pid 173718:tid 173885] [client 158.69.117.45:12571] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:45.372447 2026] [core:error] [pid 173718:tid 173885] [client 158.69.117.45:12571] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:45.446712 2026] [security2:error] [pid 173718:tid 173969] [client 20.104.18.253:20081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/themes-install.php"] [unique_id "amuzSUoi7QGnEa1uk6mpcwAAAHg"]
[Thu Jul 30 15:25:45.451863 2026] [security2:error] [pid 173718:tid 173963] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/fpwch.php"] [unique_id "amuzSUoi7QGnEa1uk6mpdQAAAHI"]
[Thu Jul 30 15:25:45.452004 2026] [security2:error] [pid 173718:tid 173963] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/fpwch.php"] [unique_id "amuzSUoi7QGnEa1uk6mpdQAAAHI"]
[Thu Jul 30 15:25:45.577739 2026] [security2:error] [pid 173718:tid 173893] [client 20.63.98.115:39944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/sim.php/wp-includes/certificates/plugins.php"] [unique_id "amuzSUoi7QGnEa1uk6mpeQAAACw"]
[Thu Jul 30 15:25:45.769338 2026] [security2:error] [pid 173718:tid 173898] [client 135.119.63.61:8214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/fdgfdgdsfd.php"] [unique_id "amuzSUoi7QGnEa1uk6mpfQAAADE"]
[Thu Jul 30 15:25:45.917477 2026] [security2:error] [pid 173718:tid 173966] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/black.php"] [unique_id "amuzSUoi7QGnEa1uk6mpfgAAAHU"]
[Thu Jul 30 15:25:45.917592 2026] [security2:error] [pid 173718:tid 173966] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/black.php"] [unique_id "amuzSUoi7QGnEa1uk6mpfgAAAHU"]
[Thu Jul 30 15:25:46.051720 2026] [security2:error] [pid 173718:tid 173944] [client 20.104.18.253:20090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/themes/index.php"] [unique_id "amuzSkoi7QGnEa1uk6mphQAAAF8"]
[Thu Jul 30 15:25:46.085341 2026] [core:notice] [pid 173718:tid 173899] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:46.088767 2026] [security2:error] [pid 173718:tid 173899] [client 66.249.79.8:36920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/9140/3960"] [unique_id "amuzSkoi7QGnEa1uk6mphgAAADI"]
[Thu Jul 30 15:25:46.387103 2026] [security2:error] [pid 173718:tid 173862] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/loader.php"] [unique_id "amuzSkoi7QGnEa1uk6mpjQAAAA0"]
[Thu Jul 30 15:25:46.387230 2026] [security2:error] [pid 173718:tid 173862] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/loader.php"] [unique_id "amuzSkoi7QGnEa1uk6mpjQAAAA0"]
[Thu Jul 30 15:25:46.451495 2026] [core:error] [pid 173718:tid 173956] [client 158.69.117.45:42571] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:46.451515 2026] [core:error] [pid 173718:tid 173956] [client 158.69.117.45:42571] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:46.542877 2026] [security2:error] [pid 173718:tid 173910] [client 135.119.63.61:8733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/fe5.php"] [unique_id "amuzSkoi7QGnEa1uk6mpkgAAAD0"]
[Thu Jul 30 15:25:46.852487 2026] [security2:error] [pid 173718:tid 173907] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/file61.php"] [unique_id "amuzSkoi7QGnEa1uk6mpmgAAADo"]
[Thu Jul 30 15:25:46.852599 2026] [security2:error] [pid 173718:tid 173907] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/file61.php"] [unique_id "amuzSkoi7QGnEa1uk6mpmgAAADo"]
[Thu Jul 30 15:25:46.970898 2026] [security2:error] [pid 173718:tid 173900] [client 20.104.18.253:20135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/themes/wp-login.php"] [unique_id "amuzSkoi7QGnEa1uk6mpmQAAADM"]
[Thu Jul 30 15:25:47.272879 2026] [core:notice] [pid 173718:tid 173901] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:47.329059 2026] [security2:error] [pid 173718:tid 173875] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-css.php"] [unique_id "amuzS0oi7QGnEa1uk6mppQAAABo"]
[Thu Jul 30 15:25:47.329155 2026] [security2:error] [pid 173718:tid 173875] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-css.php"] [unique_id "amuzS0oi7QGnEa1uk6mppQAAABo"]
[Thu Jul 30 15:25:47.432648 2026] [security2:error] [pid 173718:tid 173931] [client 64.31.3.126:34837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuzSEoi7QGnEa1uk6mpYgAAAB4"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2268
[Thu Jul 30 15:25:47.578209 2026] [security2:error] [pid 173718:tid 173970] [client 135.119.63.61:8732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/fedora.php"] [unique_id "amuzS0oi7QGnEa1uk6mpqQAAAHk"]
[Thu Jul 30 15:25:47.579680 2026] [security2:error] [pid 173718:tid 173871] [client 20.104.18.253:20055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/think.php"] [unique_id "amuzS0oi7QGnEa1uk6mpqgAAABY"]
[Thu Jul 30 15:25:47.725539 2026] [core:error] [pid 173718:tid 173860] [client 158.69.117.45:58107] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:47.725560 2026] [core:error] [pid 173718:tid 173860] [client 158.69.117.45:58107] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:25:47.804922 2026] [security2:error] [pid 173718:tid 173893] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-blink.php"] [unique_id "amuzS0oi7QGnEa1uk6mpuQAAACw"]
[Thu Jul 30 15:25:47.805058 2026] [security2:error] [pid 173718:tid 173893] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-blink.php"] [unique_id "amuzS0oi7QGnEa1uk6mpuQAAACw"]
[Thu Jul 30 15:25:47.885216 2026] [security2:error] [pid 173718:tid 173960] [client 43.166.237.57:50342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.237.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/view/9287/4124"] [unique_id "amuzS0oi7QGnEa1uk6mpuwAAAG8"]
[Thu Jul 30 15:25:48.249248 2026] [security2:error] [pid 173718:tid 173942] [client 20.104.18.253:20076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/thoms.php"] [unique_id "amuzTEoi7QGnEa1uk6mpwwAAAF0"]
[Thu Jul 30 15:25:48.271639 2026] [security2:error] [pid 173718:tid 173936] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/txets.php"] [unique_id "amuzTEoi7QGnEa1uk6mpxgAAAFc"]
[Thu Jul 30 15:25:48.271723 2026] [security2:error] [pid 173718:tid 173936] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/txets.php"] [unique_id "amuzTEoi7QGnEa1uk6mpxgAAAFc"]
[Thu Jul 30 15:25:48.739045 2026] [security2:error] [pid 173718:tid 173876] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/pucci.php"] [unique_id "amuzTEoi7QGnEa1uk6mp0gAAABs"]
[Thu Jul 30 15:25:48.739149 2026] [security2:error] [pid 173718:tid 173876] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/pucci.php"] [unique_id "amuzTEoi7QGnEa1uk6mp0gAAABs"]
[Thu Jul 30 15:25:48.865727 2026] [security2:error] [pid 173718:tid 173859] [client 20.104.18.253:20056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/three-column-screen-layout/db.php"] [unique_id "amuzTEoi7QGnEa1uk6mp1gAAAAo"]
[Thu Jul 30 15:25:48.982811 2026] [security2:error] [pid 173718:tid 173879] [client 38.172.162.57:16598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzTEoi7QGnEa1uk6mp2AAAAB4"]
[Thu Jul 30 15:25:48.982961 2026] [security2:error] [pid 173718:tid 173879] [client 38.172.162.57:16598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzTEoi7QGnEa1uk6mp2AAAAB4"]
[Thu Jul 30 15:25:49.090664 2026] [security2:error] [pid 173718:tid 173956] [client 135.119.63.61:56067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/feed-rsss.php"] [unique_id "amuzTUoi7QGnEa1uk6mp2QAAAGs"]
[Thu Jul 30 15:25:49.206657 2026] [security2:error] [pid 173718:tid 173900] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/xwpg.php"] [unique_id "amuzTUoi7QGnEa1uk6mp3gAAADM"]
[Thu Jul 30 15:25:49.206762 2026] [security2:error] [pid 173718:tid 173900] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/xwpg.php"] [unique_id "amuzTUoi7QGnEa1uk6mp3gAAADM"]
[Thu Jul 30 15:25:49.336964 2026] [core:notice] [pid 173718:tid 173945] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:49.340404 2026] [security2:error] [pid 173718:tid 173945] [client 66.249.79.229:37061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/camic/article/download/9077/3915"] [unique_id "amuzTUoi7QGnEa1uk6mp4wAAAGA"]
[Thu Jul 30 15:25:49.463847 2026] [security2:error] [pid 173718:tid 173865] [client 20.104.18.253:20104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/thumbs.php"] [unique_id "amuzTUoi7QGnEa1uk6mp5gAAABA"]
[Thu Jul 30 15:25:49.675884 2026] [security2:error] [pid 173718:tid 173871] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ops.php"] [unique_id "amuzTUoi7QGnEa1uk6mp5wAAABY"]
[Thu Jul 30 15:25:49.676027 2026] [security2:error] [pid 173718:tid 173871] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ops.php"] [unique_id "amuzTUoi7QGnEa1uk6mp5wAAABY"]
[Thu Jul 30 15:25:49.718204 2026] [fcgid:warn] [pid 173718:tid 173968] (70014)End of file found: [client 172.237.109.114:1338] mod_fcgid: can't get data from http client
[Thu Jul 30 15:25:50.109393 2026] [security2:error] [pid 173718:tid 173897] [client 20.104.18.253:20080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/ticket.php"] [unique_id "amuzTkoi7QGnEa1uk6mp9QAAADA"]
[Thu Jul 30 15:25:50.142375 2026] [security2:error] [pid 173718:tid 173914] [client 20.197.178.120:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.jookreview.com"] [uri "/1.php"] [unique_id "amuzTkoi7QGnEa1uk6mp-wAAAEE"]
[Thu Jul 30 15:25:50.142475 2026] [security2:error] [pid 173718:tid 173914] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/1.php"] [unique_id "amuzTkoi7QGnEa1uk6mp-wAAAEE"]
[Thu Jul 30 15:25:50.142554 2026] [security2:error] [pid 173718:tid 173914] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/1.php"] [unique_id "amuzTkoi7QGnEa1uk6mp-wAAAEE"]
[Thu Jul 30 15:25:50.607560 2026] [security2:error] [pid 173718:tid 173976] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/mac.php"] [unique_id "amuzTkoi7QGnEa1uk6mqBgAAAH8"]
[Thu Jul 30 15:25:50.607686 2026] [security2:error] [pid 173718:tid 173976] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/mac.php"] [unique_id "amuzTkoi7QGnEa1uk6mqBgAAAH8"]
[Thu Jul 30 15:25:50.610513 2026] [security2:error] [pid 173718:tid 173862] [client 172.237.109.114:9900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzTUoi7QGnEa1uk6mp8gAAACs"]
[Thu Jul 30 15:25:50.610536 2026] [security2:error] [pid 173718:tid 173862] [client 172.237.109.114:9900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzTUoi7QGnEa1uk6mp8gAAACs"]
[Thu Jul 30 15:25:50.674079 2026] [security2:error] [pid 173718:tid 173893] [client 166.88.121.0:35950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzTkoi7QGnEa1uk6mp9wAALDU"]
[Thu Jul 30 15:25:50.762988 2026] [security2:error] [pid 173718:tid 173869] [client 20.104.18.253:20091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/time.php"] [unique_id "amuzTkoi7QGnEa1uk6mqCgAAABQ"]
[Thu Jul 30 15:25:51.072280 2026] [security2:error] [pid 173718:tid 173866] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuzT0oi7QGnEa1uk6mqEQAAABE"]
[Thu Jul 30 15:25:51.072399 2026] [security2:error] [pid 173718:tid 173866] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuzT0oi7QGnEa1uk6mqEQAAABE"]
[Thu Jul 30 15:25:51.290330 2026] [proxy:error] [pid 173718:tid 173911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:25:51.290399 2026] [proxy_http:error] [pid 173718:tid 173911] [client 32.194.121.99:11884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:25:51.290944 2026] [proxy:error] [pid 173718:tid 173911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:25:51.291002 2026] [proxy_http:error] [pid 173718:tid 173911] [client 32.194.121.99:11884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:25:51.317563 2026] [security2:error] [pid 173718:tid 173884] [client 20.63.98.115:39974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-seo.php"] [unique_id "amuzT0oi7QGnEa1uk6mqHQAAACM"]
[Thu Jul 30 15:25:51.407775 2026] [security2:error] [pid 173718:tid 173956] [client 20.104.18.253:20112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tiny.php"] [unique_id "amuzT0oi7QGnEa1uk6mqIgAAAGs"]
[Thu Jul 30 15:25:51.413163 2026] [proxy:error] [pid 173718:tid 173878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:25:51.413227 2026] [proxy_http:error] [pid 173718:tid 173878] [client 34.233.129.35:60528] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:25:51.413788 2026] [proxy:error] [pid 173718:tid 173878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:25:51.413832 2026] [proxy_http:error] [pid 173718:tid 173878] [client 34.233.129.35:60528] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:25:51.415108 2026] [core:notice] [pid 173718:tid 173875] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:51.538415 2026] [security2:error] [pid 173718:tid 173894] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/aa.php"] [unique_id "amuzT0oi7QGnEa1uk6mqKQAAAC0"]
[Thu Jul 30 15:25:51.538564 2026] [security2:error] [pid 173718:tid 173894] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/aa.php"] [unique_id "amuzT0oi7QGnEa1uk6mqKQAAAC0"]
[Thu Jul 30 15:25:51.600431 2026] [core:notice] [pid 173718:tid 173954] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:52.010634 2026] [security2:error] [pid 173718:tid 173914] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/xyn.php"] [unique_id "amuzUEoi7QGnEa1uk6mqSQAAAEE"]
[Thu Jul 30 15:25:52.010743 2026] [security2:error] [pid 173718:tid 173914] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/xyn.php"] [unique_id "amuzUEoi7QGnEa1uk6mqSQAAAEE"]
[Thu Jul 30 15:25:52.033479 2026] [security2:error] [pid 173718:tid 173855] [client 20.104.18.253:20034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinyfilemanager.php"] [unique_id "amuzUEoi7QGnEa1uk6mqTAAAAAY"]
[Thu Jul 30 15:25:52.237348 2026] [security2:error] [pid 173718:tid 173952] [client 213.152.161.133:44724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuzUEoi7QGnEa1uk6mqTQAAAGc"]
[Thu Jul 30 15:25:52.237489 2026] [security2:error] [pid 173718:tid 173952] [client 213.152.161.133:44724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amuzUEoi7QGnEa1uk6mqTQAAAGc"]
[Thu Jul 30 15:25:52.418873 2026] [security2:error] [pid 173718:tid 173966] [client 135.119.63.61:56069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/ff.php"] [unique_id "amuzUEoi7QGnEa1uk6mqVwAAAHU"]
[Thu Jul 30 15:25:52.427606 2026] [security2:error] [pid 173718:tid 173975] [client 20.63.98.115:26545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/zwso.php"] [unique_id "amuzUEoi7QGnEa1uk6mqWAAAAH4"]
[Thu Jul 30 15:25:52.480769 2026] [security2:error] [pid 173718:tid 173908] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-wp.php"] [unique_id "amuzUEoi7QGnEa1uk6mqWQAAADs"]
[Thu Jul 30 15:25:52.480858 2026] [security2:error] [pid 173718:tid 173908] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-wp.php"] [unique_id "amuzUEoi7QGnEa1uk6mqWQAAADs"]
[Thu Jul 30 15:25:52.645808 2026] [security2:error] [pid 173718:tid 173853] [client 20.104.18.253:20074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/langs/about.php"] [unique_id "amuzUEoi7QGnEa1uk6mqXAAAAAQ"]
[Thu Jul 30 15:25:52.714211 2026] [core:notice] [pid 173718:tid 173882] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:52.950128 2026] [security2:error] [pid 173718:tid 173957] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/aw.php"] [unique_id "amuzUEoi7QGnEa1uk6mqbwAAAGw"]
[Thu Jul 30 15:25:52.950241 2026] [security2:error] [pid 173718:tid 173957] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/aw.php"] [unique_id "amuzUEoi7QGnEa1uk6mqbwAAAGw"]
[Thu Jul 30 15:25:53.225234 2026] [security2:error] [pid 173718:tid 173892] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzUEoi7QGnEa1uk6mqXQAAACs"]
[Thu Jul 30 15:25:53.274101 2026] [security2:error] [pid 173718:tid 173852] [client 20.104.18.253:20114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/plugins/compat3x/css/index.php"] [unique_id "amuzUUoi7QGnEa1uk6mqcgAAAAM"]
[Thu Jul 30 15:25:53.305107 2026] [security2:error] [pid 173718:tid 173889] [client 135.119.63.61:8216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/ff2.php"] [unique_id "amuzUUoi7QGnEa1uk6mqfQAAACg"]
[Thu Jul 30 15:25:53.417011 2026] [security2:error] [pid 173718:tid 173923] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/classwithtostring.php"] [unique_id "amuzUUoi7QGnEa1uk6mqggAAAEo"]
[Thu Jul 30 15:25:53.417155 2026] [security2:error] [pid 173718:tid 173923] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/classwithtostring.php"] [unique_id "amuzUUoi7QGnEa1uk6mqggAAAEo"]
[Thu Jul 30 15:25:53.418906 2026] [security2:error] [pid 173718:tid 173851] [client 20.63.98.115:39957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/user.php"] [unique_id "amuzUUoi7QGnEa1uk6mqgwAAAAI"]
[Thu Jul 30 15:25:53.642718 2026] [core:notice] [pid 173718:tid 173945] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:53.881308 2026] [security2:error] [pid 173718:tid 173962] [client 20.104.18.253:20083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/plugins/fullscreen/about.php"] [unique_id "amuzUUoi7QGnEa1uk6mqmAAAAHE"]
[Thu Jul 30 15:25:53.885588 2026] [security2:error] [pid 173718:tid 173877] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/yawa.php"] [unique_id "amuzUUoi7QGnEa1uk6mqmQAAABw"]
[Thu Jul 30 15:25:53.885725 2026] [security2:error] [pid 173718:tid 173877] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/yawa.php"] [unique_id "amuzUUoi7QGnEa1uk6mqmQAAABw"]
[Thu Jul 30 15:25:54.124453 2026] [core:notice] [pid 173718:tid 173902] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:54.202287 2026] [security2:error] [pid 173718:tid 173916] [client 20.63.98.115:57921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/assets/index.php"] [unique_id "amuzUkoi7QGnEa1uk6mqoQAAAEM"]
[Thu Jul 30 15:25:54.355488 2026] [security2:error] [pid 173718:tid 173898] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/sym403.php"] [unique_id "amuzUkoi7QGnEa1uk6mqogAAADE"]
[Thu Jul 30 15:25:54.355599 2026] [security2:error] [pid 173718:tid 173898] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/sym403.php"] [unique_id "amuzUkoi7QGnEa1uk6mqogAAADE"]
[Thu Jul 30 15:25:54.472093 2026] [security2:error] [pid 173718:tid 173722] [remote 57.141.0.2:31364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuzUkoi7QGnEa1uk6mqqgAABgI"]
[Thu Jul 30 15:25:54.524834 2026] [security2:error] [pid 173718:tid 173930] [client 20.104.18.253:20044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/skins/lightgray/fonts/index.php"] [unique_id "amuzUkoi7QGnEa1uk6mqrgAAAFE"]
[Thu Jul 30 15:25:54.655838 2026] [core:notice] [pid 173718:tid 173975] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:54.837276 2026] [security2:error] [pid 173718:tid 173891] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.jookreview.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/colors/blue/"] [unique_id "amuzUkoi7QGnEa1uk6mqsAAAACo"]
[Thu Jul 30 15:25:55.074545 2026] [security2:error] [pid 173718:tid 173957] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/adminner.php"] [unique_id "amuzU0oi7QGnEa1uk6mqugAAAGw"]
[Thu Jul 30 15:25:55.074663 2026] [security2:error] [pid 173718:tid 173957] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/adminner.php"] [unique_id "amuzU0oi7QGnEa1uk6mqugAAAGw"]
[Thu Jul 30 15:25:55.144072 2026] [security2:error] [pid 173718:tid 173935] [client 20.104.18.253:20070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/skins/lightgray/fonts/sx.php"] [unique_id "amuzU0oi7QGnEa1uk6mquwAAAFY"]
[Thu Jul 30 15:25:55.268027 2026] [security2:error] [pid 173718:tid 173888] [client 20.63.98.115:40021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/byp.php"] [unique_id "amuzU0oi7QGnEa1uk6mqvAAAACc"]
[Thu Jul 30 15:25:55.390649 2026] [security2:error] [pid 173718:tid 173860] [client 83.167.187.4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "applinex.pro"] [uri "/xmlrpc.php"] [unique_id "amuzUkoi7QGnEa1uk6mqqQAACwU"]
[Thu Jul 30 15:25:55.397554 2026] [security2:error] [pid 173718:tid 173950] [client 135.119.63.61:56071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/ffAA531.php"] [unique_id "amuzU0oi7QGnEa1uk6mqvQAAAGU"]
[Thu Jul 30 15:25:55.543048 2026] [security2:error] [pid 173718:tid 173971] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/yup.php"] [unique_id "amuzU0oi7QGnEa1uk6mqxwAAAHo"]
[Thu Jul 30 15:25:55.543165 2026] [security2:error] [pid 173718:tid 173971] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/yup.php"] [unique_id "amuzU0oi7QGnEa1uk6mqxwAAAHo"]
[Thu Jul 30 15:25:55.631891 2026] [core:notice] [pid 173718:tid 173866] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:55.635371 2026] [security2:error] [pid 173718:tid 173866] [client 66.249.79.229:46661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/agrijati/article/view/2925/1561"] [unique_id "amuzU0oi7QGnEa1uk6mqyAAAABE"]
[Thu Jul 30 15:25:55.758629 2026] [security2:error] [pid 173718:tid 173883] [client 20.104.18.253:20118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/skins/lightgray/img/about.php"] [unique_id "amuzU0oi7QGnEa1uk6mqzAAAACI"]
[Thu Jul 30 15:25:55.946229 2026] [core:notice] [pid 173718:tid 173878] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:55.949272 2026] [security2:error] [pid 173718:tid 173878] [client 66.249.79.229:46661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/download/3621/2435"] [unique_id "amuzU0oi7QGnEa1uk6mqzgAAAB0"]
[Thu Jul 30 15:25:56.011872 2026] [security2:error] [pid 173718:tid 173875] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/config.json.php"] [unique_id "amuzVEoi7QGnEa1uk6mq0QAAABo"]
[Thu Jul 30 15:25:56.011968 2026] [security2:error] [pid 173718:tid 173875] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/config.json.php"] [unique_id "amuzVEoi7QGnEa1uk6mq0QAAABo"]
[Thu Jul 30 15:25:56.361160 2026] [security2:error] [pid 173718:tid 173961] [client 20.104.18.253:20095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/skins/lightgray/img/index.php"] [unique_id "amuzVEoi7QGnEa1uk6mq2AAAAHA"]
[Thu Jul 30 15:25:56.495535 2026] [security2:error] [pid 173718:tid 173962] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.jookreview.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/block-bindings/"] [unique_id "amuzVEoi7QGnEa1uk6mq3AAAAHE"]
[Thu Jul 30 15:25:56.738170 2026] [security2:error] [pid 173718:tid 173929] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/2.php"] [unique_id "amuzVEoi7QGnEa1uk6mq4wAAAFA"]
[Thu Jul 30 15:25:56.738331 2026] [security2:error] [pid 173718:tid 173929] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/2.php"] [unique_id "amuzVEoi7QGnEa1uk6mq4wAAAFA"]
[Thu Jul 30 15:25:56.940869 2026] [security2:error] [pid 173718:tid 173960] [client 20.63.98.115:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/bs1.php"] [unique_id "amuzVEoi7QGnEa1uk6mq5QAAAG8"]
[Thu Jul 30 15:25:56.970833 2026] [security2:error] [pid 173718:tid 173955] [client 20.104.18.253:20136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/skins/lightgray/img/wp-login.php"] [unique_id "amuzVEoi7QGnEa1uk6mq6AAAAGo"]
[Thu Jul 30 15:25:57.023228 2026] [security2:error] [pid 173718:tid 173915] [client 135.119.63.61:56080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/ffile.php"] [unique_id "amuzVUoi7QGnEa1uk6mq6wAAAEI"]
[Thu Jul 30 15:25:57.084750 2026] [core:notice] [pid 173718:tid 173737] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:57.206958 2026] [security2:error] [pid 173718:tid 173903] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/f35.update.php"] [unique_id "amuzVUoi7QGnEa1uk6mq8wAAADY"]
[Thu Jul 30 15:25:57.207102 2026] [security2:error] [pid 173718:tid 173903] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/f35.update.php"] [unique_id "amuzVUoi7QGnEa1uk6mq8wAAADY"]
[Thu Jul 30 15:25:57.592957 2026] [security2:error] [pid 173718:tid 173949] [client 20.104.18.253:20064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/skins/wordpress/images/about.php"] [unique_id "amuzVUoi7QGnEa1uk6mq-wAAAGQ"]
[Thu Jul 30 15:25:57.607061 2026] [core:notice] [pid 173718:tid 173951] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:57.662167 2026] [security2:error] [pid 173718:tid 173853] [client 203.198.28.191:13733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.carnetdeshopping.com"] [uri "/wp-content/uploads/2015/07/little-marcel-parfums_Purple-Love_1.jpg"] [unique_id "amuzVUoi7QGnEa1uk6mq_QAAAAQ"]
[Thu Jul 30 15:25:57.674165 2026] [security2:error] [pid 173718:tid 173946] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/k.php"] [unique_id "amuzVUoi7QGnEa1uk6mrAQAAAGE"]
[Thu Jul 30 15:25:57.674254 2026] [security2:error] [pid 173718:tid 173946] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/k.php"] [unique_id "amuzVUoi7QGnEa1uk6mrAQAAAGE"]
[Thu Jul 30 15:25:57.721701 2026] [security2:error] [pid 173718:tid 173761] [remote 57.141.0.14:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuzVUoi7QGnEa1uk6mrAwAAfyk"]
[Thu Jul 30 15:25:57.815226 2026] [security2:error] [pid 173718:tid 173893] [client 135.119.63.61:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/fhhgjg.php"] [unique_id "amuzVUoi7QGnEa1uk6mrBQAAACw"]
[Thu Jul 30 15:25:58.084737 2026] [security2:error] [pid 173718:tid 173860] [client 20.63.98.115:60548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/IXR/allez.php"] [unique_id "amuzVkoi7QGnEa1uk6mrCgAAAAs"]
[Thu Jul 30 15:25:58.156084 2026] [security2:error] [pid 173718:tid 173919] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.jookreview.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/css/"] [unique_id "amuzVkoi7QGnEa1uk6mrDgAAAEY"]
[Thu Jul 30 15:25:58.203015 2026] [security2:error] [pid 173718:tid 173852] [client 20.104.18.253:20142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/skins/wordpress/images/index.php"] [unique_id "amuzVkoi7QGnEa1uk6mrFQAAAAM"]
[Thu Jul 30 15:25:58.331919 2026] [security2:error] [pid 173718:tid 173944] [client 2a03:2880:f800:9:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzVUoi7QGnEa1uk6mq_gAAXzQ"]
[Thu Jul 30 15:25:58.394611 2026] [security2:error] [pid 173718:tid 173931] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/spadex.php"] [unique_id "amuzVkoi7QGnEa1uk6mrFgAAAFI"]
[Thu Jul 30 15:25:58.394764 2026] [security2:error] [pid 173718:tid 173931] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/spadex.php"] [unique_id "amuzVkoi7QGnEa1uk6mrFgAAAFI"]
[Thu Jul 30 15:25:58.682131 2026] [security2:error] [pid 173718:tid 173892] [client 147.185.226.14:52910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzVkoi7QGnEa1uk6mrFAAAKxQ"]
[Thu Jul 30 15:25:58.787252 2026] [core:notice] [pid 173718:tid 173871] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:25:58.790617 2026] [security2:error] [pid 173718:tid 173871] [client 66.249.79.229:46661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Deiksis/article/view/9247/4070"] [unique_id "amuzVkoi7QGnEa1uk6mrIwAAABY"]
[Thu Jul 30 15:25:58.808935 2026] [security2:error] [pid 173718:tid 173954] [client 20.104.18.253:41807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/utils/license.php"] [unique_id "amuzVkoi7QGnEa1uk6mrJAAAAGk"]
[Thu Jul 30 15:25:58.863783 2026] [security2:error] [pid 173718:tid 173887] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/mg.php"] [unique_id "amuzVkoi7QGnEa1uk6mrJQAAACY"]
[Thu Jul 30 15:25:58.863889 2026] [security2:error] [pid 173718:tid 173887] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/mg.php"] [unique_id "amuzVkoi7QGnEa1uk6mrJQAAACY"]
[Thu Jul 30 15:25:59.327335 2026] [security2:error] [pid 173718:tid 173864] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/fnstall.php"] [unique_id "amuzV0oi7QGnEa1uk6mrRAAAAA8"]
[Thu Jul 30 15:25:59.327484 2026] [security2:error] [pid 173718:tid 173864] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/fnstall.php"] [unique_id "amuzV0oi7QGnEa1uk6mrRAAAAA8"]
[Thu Jul 30 15:25:59.406291 2026] [security2:error] [pid 173718:tid 173855] [client 20.104.18.253:20079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tinymce/wp-tinymce.php"] [unique_id "amuzV0oi7QGnEa1uk6mrRQAAAAY"]
[Thu Jul 30 15:25:59.552122 2026] [security2:error] [pid 173718:tid 173897] [client 38.172.162.57:16291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzV0oi7QGnEa1uk6mrRwAAADA"]
[Thu Jul 30 15:25:59.552248 2026] [security2:error] [pid 173718:tid 173897] [client 38.172.162.57:16291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzV0oi7QGnEa1uk6mrRwAAADA"]
[Thu Jul 30 15:25:59.558564 2026] [security2:error] [pid 173718:tid 173885] [client 20.63.98.115:16140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/load.php"] [unique_id "amuzV0oi7QGnEa1uk6mrSAAAACQ"]
[Thu Jul 30 15:25:59.799224 2026] [security2:error] [pid 173718:tid 173946] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ortasekerli1.php"] [unique_id "amuzV0oi7QGnEa1uk6mrWwAAAGE"]
[Thu Jul 30 15:25:59.799306 2026] [security2:error] [pid 173718:tid 173946] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ortasekerli1.php"] [unique_id "amuzV0oi7QGnEa1uk6mrWwAAAGE"]
[Thu Jul 30 15:25:59.829900 2026] [security2:error] [pid 173718:tid 173791] [remote 57.141.0.64:22466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuzV0oi7QGnEa1uk6mrXAAAaEc"]
[Thu Jul 30 15:26:00.004192 2026] [security2:error] [pid 173718:tid 173957] [client 20.104.18.253:20040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tll.php"] [unique_id "amuzWEoi7QGnEa1uk6mrYgAAAGw"]
[Thu Jul 30 15:26:00.268932 2026] [security2:error] [pid 173718:tid 173879] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/sump1.php"] [unique_id "amuzWEoi7QGnEa1uk6mrggAAAB4"]
[Thu Jul 30 15:26:00.269033 2026] [security2:error] [pid 173718:tid 173879] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/sump1.php"] [unique_id "amuzWEoi7QGnEa1uk6mrggAAAB4"]
[Thu Jul 30 15:26:00.395605 2026] [security2:error] [pid 173718:tid 173913] [client 135.119.63.61:8224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/fi2.php"] [unique_id "amuzWEoi7QGnEa1uk6mrhgAAAEA"]
[Thu Jul 30 15:26:00.602785 2026] [security2:error] [pid 173718:tid 173911] [client 20.63.98.115:39725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/privacy.php"] [unique_id "amuzWEoi7QGnEa1uk6mrhwAAAD4"]
[Thu Jul 30 15:26:00.603636 2026] [security2:error] [pid 173718:tid 173856] [client 20.104.18.253:20094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tmp.php"] [unique_id "amuzWEoi7QGnEa1uk6mriAAAAAc"]
[Thu Jul 30 15:26:00.634426 2026] [security2:error] [pid 173718:tid 173854] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzWEoi7QGnEa1uk6mrZQAAAAU"]
[Thu Jul 30 15:26:00.735967 2026] [security2:error] [pid 173718:tid 173901] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ops.php"] [unique_id "amuzWEoi7QGnEa1uk6mrkAAAADQ"]
[Thu Jul 30 15:26:00.736155 2026] [security2:error] [pid 173718:tid 173901] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ops.php"] [unique_id "amuzWEoi7QGnEa1uk6mrkAAAADQ"]
[Thu Jul 30 15:26:00.834574 2026] [security2:error] [pid 173718:tid 173928] [client 172.237.109.114:12049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzWEoi7QGnEa1uk6mraQAAAEw"]
[Thu Jul 30 15:26:00.834618 2026] [security2:error] [pid 173718:tid 173928] [client 172.237.109.114:12049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzWEoi7QGnEa1uk6mraQAAAEw"]
[Thu Jul 30 15:26:01.210539 2026] [security2:error] [pid 173718:tid 173868] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-post-data.php"] [unique_id "amuzWUoi7QGnEa1uk6mrnQAAABM"]
[Thu Jul 30 15:26:01.210652 2026] [security2:error] [pid 173718:tid 173868] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-post-data.php"] [unique_id "amuzWUoi7QGnEa1uk6mrnQAAABM"]
[Thu Jul 30 15:26:01.214651 2026] [security2:error] [pid 173718:tid 173877] [client 20.104.18.253:20060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tmpk.php"] [unique_id "amuzWUoi7QGnEa1uk6mrngAAABw"]
[Thu Jul 30 15:26:01.351789 2026] [security2:error] [pid 173718:tid 173912] [client 135.119.63.61:56123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/fierza.php"] [unique_id "amuzWUoi7QGnEa1uk6mrpQAAAD8"]
[Thu Jul 30 15:26:01.393686 2026] [security2:error] [pid 173718:tid 173945] [client 2a03:2880:f800:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzWEoi7QGnEa1uk6mrkwAAYEs"]
[Thu Jul 30 15:26:01.684860 2026] [security2:error] [pid 173718:tid 173897] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/root.php"] [unique_id "amuzWUoi7QGnEa1uk6mrqwAAADA"]
[Thu Jul 30 15:26:01.685036 2026] [security2:error] [pid 173718:tid 173897] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/root.php"] [unique_id "amuzWUoi7QGnEa1uk6mrqwAAADA"]
[Thu Jul 30 15:26:01.833056 2026] [security2:error] [pid 173718:tid 173855] [client 20.104.18.253:20134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tmpl/index.php"] [unique_id "amuzWUoi7QGnEa1uk6mrsAAAAAY"]
[Thu Jul 30 15:26:01.922415 2026] [security2:error] [pid 173718:tid 173936] [client 74.7.241.163:48250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.dws.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuzWUoi7QGnEa1uk6mrtAAAAFc"]
[Thu Jul 30 15:26:02.151584 2026] [security2:error] [pid 173718:tid 173910] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/v543.php"] [unique_id "amuzWkoi7QGnEa1uk6mrtQAAAD0"]
[Thu Jul 30 15:26:02.151712 2026] [security2:error] [pid 173718:tid 173910] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/v543.php"] [unique_id "amuzWkoi7QGnEa1uk6mrtQAAAD0"]
[Thu Jul 30 15:26:02.215755 2026] [core:notice] [pid 173718:tid 173870] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:02.432435 2026] [security2:error] [pid 173718:tid 173976] [client 20.104.18.253:20100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tmpls.php"] [unique_id "amuzWkoi7QGnEa1uk6mrwAAAAH8"]
[Thu Jul 30 15:26:02.576651 2026] [security2:error] [pid 173718:tid 173724] [remote 40.77.167.224:60674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/1340247948/login.php"] [unique_id "amuzWkoi7QGnEa1uk6mrwQAARgQ"]
[Thu Jul 30 15:26:02.622671 2026] [security2:error] [pid 173718:tid 173851] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/sixxis.php"] [unique_id "amuzWkoi7QGnEa1uk6mrwgAAAAI"]
[Thu Jul 30 15:26:02.622809 2026] [security2:error] [pid 173718:tid 173851] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/sixxis.php"] [unique_id "amuzWkoi7QGnEa1uk6mrwgAAAAI"]
[Thu Jul 30 15:26:02.655099 2026] [security2:error] [pid 173718:tid 173896] [client 135.119.63.61:56074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file-manager.php"] [unique_id "amuzWkoi7QGnEa1uk6mrwwAAAC8"]
[Thu Jul 30 15:26:03.090057 2026] [security2:error] [pid 173718:tid 173872] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ip.php"] [unique_id "amuzW0oi7QGnEa1uk6mrzgAAABc"]
[Thu Jul 30 15:26:03.090178 2026] [security2:error] [pid 173718:tid 173872] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ip.php"] [unique_id "amuzW0oi7QGnEa1uk6mrzgAAABc"]
[Thu Jul 30 15:26:03.098531 2026] [security2:error] [pid 173718:tid 173852] [client 20.104.18.253:20137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tnt.php"] [unique_id "amuzW0oi7QGnEa1uk6mrzwAAAAM"]
[Thu Jul 30 15:26:03.223644 2026] [core:notice] [pid 173718:tid 173875] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:03.227255 2026] [security2:error] [pid 173718:tid 173875] [client 66.249.79.1:42067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/download/9299/4137"] [unique_id "amuzWkoi7QGnEa1uk6mrzQAAABo"]
[Thu Jul 30 15:26:03.240628 2026] [security2:error] [pid 173718:tid 173963] [client 20.63.98.115:60563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-cli.php"] [unique_id "amuzW0oi7QGnEa1uk6mr0wAAAHI"]
[Thu Jul 30 15:26:03.558473 2026] [security2:error] [pid 173718:tid 173916] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/kq1.php"] [unique_id "amuzW0oi7QGnEa1uk6mr5AAAAEM"]
[Thu Jul 30 15:26:03.558578 2026] [security2:error] [pid 173718:tid 173916] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/kq1.php"] [unique_id "amuzW0oi7QGnEa1uk6mr5AAAAEM"]
[Thu Jul 30 15:26:03.766528 2026] [security2:error] [pid 173718:tid 173902] [client 20.104.18.253:41847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/tonant.php"] [unique_id "amuzW0oi7QGnEa1uk6mr6QAAADU"]
[Thu Jul 30 15:26:04.034646 2026] [security2:error] [pid 173718:tid 173855] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/fw/faiyy.php"] [unique_id "amuzXEoi7QGnEa1uk6mr8wAAAAY"]
[Thu Jul 30 15:26:04.034731 2026] [security2:error] [pid 173718:tid 173855] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/fw/faiyy.php"] [unique_id "amuzXEoi7QGnEa1uk6mr8wAAAAY"]
[Thu Jul 30 15:26:04.380745 2026] [security2:error] [pid 173718:tid 173849] [client 20.104.18.253:20057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/too.php"] [unique_id "amuzXEoi7QGnEa1uk6msAAAAAAA"]
[Thu Jul 30 15:26:04.502643 2026] [security2:error] [pid 173718:tid 173879] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/h02ugyh.php"] [unique_id "amuzXEoi7QGnEa1uk6msCgAAAB4"]
[Thu Jul 30 15:26:04.502782 2026] [security2:error] [pid 173718:tid 173879] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/h02ugyh.php"] [unique_id "amuzXEoi7QGnEa1uk6msCgAAAB4"]
[Thu Jul 30 15:26:04.552812 2026] [security2:error] [pid 173718:tid 173960] [client 135.119.63.61:55333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file.php"] [unique_id "amuzXEoi7QGnEa1uk6msCwAAAG8"]
[Thu Jul 30 15:26:04.848309 2026] [security2:error] [pid 173718:tid 173889] [client 20.63.98.115:60584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cc.php"] [unique_id "amuzXEoi7QGnEa1uk6msEgAAACg"]
[Thu Jul 30 15:26:04.981565 2026] [security2:error] [pid 173718:tid 173909] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-temp.php"] [unique_id "amuzXEoi7QGnEa1uk6msFwAAADw"]
[Thu Jul 30 15:26:04.981667 2026] [security2:error] [pid 173718:tid 173909] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-temp.php"] [unique_id "amuzXEoi7QGnEa1uk6msFwAAADw"]
[Thu Jul 30 15:26:04.993123 2026] [security2:error] [pid 173718:tid 173923] [client 20.104.18.253:20037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/toolsadmin.php"] [unique_id "amuzXEoi7QGnEa1uk6msGAAAAEo"]
[Thu Jul 30 15:26:04.999220 2026] [core:notice] [pid 173718:tid 173866] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:05.002713 2026] [security2:error] [pid 173718:tid 173866] [client 66.249.79.229:42855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/1884/1320"] [unique_id "amuzXEoi7QGnEa1uk6msGQAAABE"]
[Thu Jul 30 15:26:05.296683 2026] [security2:error] [pid 173718:tid 173896] [client 57.141.0.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzXEoi7QGnEa1uk6msDgAAAC8"]
[Thu Jul 30 15:26:05.452477 2026] [security2:error] [pid 173718:tid 173880] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-content/cong.php"] [unique_id "amuzXUoi7QGnEa1uk6msJQAAAB8"]
[Thu Jul 30 15:26:05.452594 2026] [security2:error] [pid 173718:tid 173880] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-content/cong.php"] [unique_id "amuzXUoi7QGnEa1uk6msJQAAAB8"]
[Thu Jul 30 15:26:05.542727 2026] [core:notice] [pid 173718:tid 173934] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:05.553913 2026] [security2:error] [pid 173718:tid 173963] [client 135.119.63.61:8203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file15.php"] [unique_id "amuzXUoi7QGnEa1uk6msLQAAAHI"]
[Thu Jul 30 15:26:05.645408 2026] [security2:error] [pid 173718:tid 173895] [client 2a03:2880:f800:b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzXUoi7QGnEa1uk6msGgAALic"]
[Thu Jul 30 15:26:05.679373 2026] [core:notice] [pid 173718:tid 173933] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:05.908061 2026] [security2:error] [pid 173718:tid 173877] [client 20.63.98.115:39732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/media-new.php"] [unique_id "amuzXUoi7QGnEa1uk6msNgAAABw"]
[Thu Jul 30 15:26:05.936759 2026] [security2:error] [pid 173718:tid 173938] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.jookreview.com"] [uri "/___proxy_subdomain_webdisk/wp-admin/js/widget/"] [unique_id "amuzXUoi7QGnEa1uk6msNwAAAFk"]
[Thu Jul 30 15:26:06.112463 2026] [core:notice] [pid 173718:tid 173749] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:06.172809 2026] [security2:error] [pid 173718:tid 173869] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuzXkoi7QGnEa1uk6msPwAAABQ"]
[Thu Jul 30 15:26:06.173010 2026] [security2:error] [pid 173718:tid 173869] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-includes/css/index.php"] [unique_id "amuzXkoi7QGnEa1uk6msPwAAABQ"]
[Thu Jul 30 15:26:06.320599 2026] [core:notice] [pid 173718:tid 173754] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:06.336608 2026] [core:notice] [pid 173718:tid 173935] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:06.340112 2026] [security2:error] [pid 173718:tid 173935] [client 66.249.79.1:42067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/5327"] [unique_id "amuzXkoi7QGnEa1uk6msQwAAAFY"]
[Thu Jul 30 15:26:06.641464 2026] [security2:error] [pid 173718:tid 173879] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/jj.php"] [unique_id "amuzXkoi7QGnEa1uk6msTAAAAB4"]
[Thu Jul 30 15:26:06.641584 2026] [security2:error] [pid 173718:tid 173879] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/jj.php"] [unique_id "amuzXkoi7QGnEa1uk6msTAAAAB4"]
[Thu Jul 30 15:26:06.746289 2026] [security2:error] [pid 173718:tid 173917] [client 135.119.63.61:55316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file17.php"] [unique_id "amuzXkoi7QGnEa1uk6msTQAAAEQ"]
[Thu Jul 30 15:26:07.110867 2026] [security2:error] [pid 173718:tid 173956] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amuzX0oi7QGnEa1uk6msVAAAAGs"]
[Thu Jul 30 15:26:07.110958 2026] [security2:error] [pid 173718:tid 173956] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/class-walker-footer-dev.php"] [unique_id "amuzX0oi7QGnEa1uk6msVAAAAGs"]
[Thu Jul 30 15:26:07.543726 2026] [core:notice] [pid 173718:tid 173965] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:07.548364 2026] [security2:error] [pid 173718:tid 173965] [client 66.249.79.231:45114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/download/348/242"] [unique_id "amuzX0oi7QGnEa1uk6msWAAAAHQ"]
[Thu Jul 30 15:26:07.583692 2026] [security2:error] [pid 173718:tid 173943] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/xpwer1.php"] [unique_id "amuzX0oi7QGnEa1uk6msZAAAAF4"]
[Thu Jul 30 15:26:07.583803 2026] [security2:error] [pid 173718:tid 173943] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/xpwer1.php"] [unique_id "amuzX0oi7QGnEa1uk6msZAAAAF4"]
[Thu Jul 30 15:26:07.841489 2026] [security2:error] [pid 173718:tid 173893] [client 20.63.98.115:42136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-blog.php"] [unique_id "amuzX0oi7QGnEa1uk6msaQAAACw"]
[Thu Jul 30 15:26:07.862560 2026] [security2:error] [pid 173718:tid 173894] [client 135.119.63.61:56084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file2.php"] [unique_id "amuzX0oi7QGnEa1uk6msagAAAC0"]
[Thu Jul 30 15:26:08.074864 2026] [security2:error] [pid 173718:tid 173958] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/flox.php"] [unique_id "amuzYEoi7QGnEa1uk6msdwAAAG0"]
[Thu Jul 30 15:26:08.075015 2026] [security2:error] [pid 173718:tid 173958] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/flox.php"] [unique_id "amuzYEoi7QGnEa1uk6msdwAAAG0"]
[Thu Jul 30 15:26:08.127757 2026] [security2:error] [pid 173718:tid 173895] [client 116.204.42.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuzX0oi7QGnEa1uk6mscAAAAC4"]
[Thu Jul 30 15:26:08.176496 2026] [security2:error] [pid 173718:tid 173851] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzX0oi7QGnEa1uk6msYgAAAAI"]
[Thu Jul 30 15:26:08.545067 2026] [security2:error] [pid 173718:tid 173936] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/popo.php"] [unique_id "amuzYEoi7QGnEa1uk6mshAAAAFc"]
[Thu Jul 30 15:26:08.545171 2026] [security2:error] [pid 173718:tid 173936] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/popo.php"] [unique_id "amuzYEoi7QGnEa1uk6mshAAAAFc"]
[Thu Jul 30 15:26:08.556262 2026] [core:notice] [pid 173718:tid 173882] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:08.559722 2026] [security2:error] [pid 173718:tid 173882] [client 66.249.79.231:45114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/8873/3541"] [unique_id "amuzYEoi7QGnEa1uk6mshQAAACE"]
[Thu Jul 30 15:26:08.593323 2026] [security2:error] [pid 173718:tid 173975] [client 20.63.98.115:39712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-2019.php"] [unique_id "amuzYEoi7QGnEa1uk6msiQAAAH4"]
[Thu Jul 30 15:26:08.886920 2026] [security2:error] [pid 173718:tid 173881] [client 135.119.63.61:55296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file3.php"] [unique_id "amuzYEoi7QGnEa1uk6mslQAAACA"]
[Thu Jul 30 15:26:08.965416 2026] [security2:error] [pid 173718:tid 173908] [client 2a03:2880:f800:26:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzYEoi7QGnEa1uk6msfQAAOy8"]
[Thu Jul 30 15:26:09.012047 2026] [security2:error] [pid 173718:tid 173854] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/yas.php"] [unique_id "amuzYUoi7QGnEa1uk6msmgAAAAU"]
[Thu Jul 30 15:26:09.012158 2026] [security2:error] [pid 173718:tid 173854] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/yas.php"] [unique_id "amuzYUoi7QGnEa1uk6msmgAAAAU"]
[Thu Jul 30 15:26:09.491797 2026] [security2:error] [pid 173718:tid 173961] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/water.php"] [unique_id "amuzYUoi7QGnEa1uk6msrwAAAHA"]
[Thu Jul 30 15:26:09.491888 2026] [security2:error] [pid 173718:tid 173961] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/water.php"] [unique_id "amuzYUoi7QGnEa1uk6msrwAAAHA"]
[Thu Jul 30 15:26:09.824571 2026] [security2:error] [pid 173718:tid 173941] [client 20.100.187.246:64200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/011i.php"] [unique_id "amuzYUoi7QGnEa1uk6msuwAAAFw"]
[Thu Jul 30 15:26:09.957838 2026] [security2:error] [pid 173718:tid 173898] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/nano.php"] [unique_id "amuzYUoi7QGnEa1uk6mswAAAADE"]
[Thu Jul 30 15:26:09.957952 2026] [security2:error] [pid 173718:tid 173898] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/nano.php"] [unique_id "amuzYUoi7QGnEa1uk6mswAAAADE"]
[Thu Jul 30 15:26:10.112019 2026] [security2:error] [pid 173718:tid 173894] [client 38.172.162.57:16530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzYkoi7QGnEa1uk6msyAAAAC0"]
[Thu Jul 30 15:26:10.112135 2026] [security2:error] [pid 173718:tid 173894] [client 38.172.162.57:16530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzYkoi7QGnEa1uk6msyAAAAC0"]
[Thu Jul 30 15:26:10.140852 2026] [core:notice] [pid 173718:tid 173969] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:10.426348 2026] [security2:error] [pid 173718:tid 173876] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/moon.php"] [unique_id "amuzYkoi7QGnEa1uk6ms0AAAABs"]
[Thu Jul 30 15:26:10.426467 2026] [security2:error] [pid 173718:tid 173876] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/moon.php"] [unique_id "amuzYkoi7QGnEa1uk6ms0AAAABs"]
[Thu Jul 30 15:26:10.430276 2026] [security2:error] [pid 173718:tid 173913] [client 20.63.98.115:26493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/menu.php"] [unique_id "amuzYkoi7QGnEa1uk6ms0QAAAEA"]
[Thu Jul 30 15:26:10.716516 2026] [security2:error] [pid 173718:tid 173869] [client 20.100.187.246:39979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/03a005685d.php"] [unique_id "amuzYkoi7QGnEa1uk6ms2wAAABQ"]
[Thu Jul 30 15:26:10.725195 2026] [security2:error] [pid 173718:tid 173855] [client 116.179.32.226:28407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.32.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/about/contact"] [unique_id "amuzYkoi7QGnEa1uk6ms0gAAAAY"]
[Thu Jul 30 15:26:10.939509 2026] [security2:error] [pid 173718:tid 173908] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-info.php"] [unique_id "amuzYkoi7QGnEa1uk6ms3wAAADs"]
[Thu Jul 30 15:26:10.939611 2026] [security2:error] [pid 173718:tid 173908] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-info.php"] [unique_id "amuzYkoi7QGnEa1uk6ms3wAAADs"]
[Thu Jul 30 15:26:11.302417 2026] [security2:error] [pid 173718:tid 173944] [client 20.63.98.115:26205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-crons.php"] [unique_id "amuzY0oi7QGnEa1uk6ms6wAAAF8"]
[Thu Jul 30 15:26:11.327413 2026] [security2:error] [pid 173718:tid 173851] [client 135.119.63.61:56096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file32.php"] [unique_id "amuzY0oi7QGnEa1uk6ms7AAAAAI"]
[Thu Jul 30 15:26:11.399525 2026] [core:notice] [pid 173718:tid 173909] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:11.403615 2026] [core:notice] [pid 173718:tid 173961] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:11.416359 2026] [security2:error] [pid 173718:tid 173970] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/file5.php"] [unique_id "amuzY0oi7QGnEa1uk6ms8QAAAHk"]
[Thu Jul 30 15:26:11.416499 2026] [security2:error] [pid 173718:tid 173970] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/file5.php"] [unique_id "amuzY0oi7QGnEa1uk6ms8QAAAHk"]
[Thu Jul 30 15:26:11.668493 2026] [security2:error] [pid 173718:tid 173968] [client 20.100.187.246:64213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/403.php"] [unique_id "amuzY0oi7QGnEa1uk6ms-AAAAHc"]
[Thu Jul 30 15:26:11.889769 2026] [security2:error] [pid 173718:tid 173867] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/2000.php"] [unique_id "amuzY0oi7QGnEa1uk6ms_AAAABI"]
[Thu Jul 30 15:26:11.889886 2026] [security2:error] [pid 173718:tid 173867] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/2000.php"] [unique_id "amuzY0oi7QGnEa1uk6ms_AAAABI"]
[Thu Jul 30 15:26:12.296992 2026] [core:notice] [pid 173718:tid 173885] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:12.354407 2026] [security2:error] [pid 173718:tid 173966] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/122.php"] [unique_id "amuzZEoi7QGnEa1uk6mtBgAAAHU"]
[Thu Jul 30 15:26:12.354513 2026] [security2:error] [pid 173718:tid 173966] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/122.php"] [unique_id "amuzZEoi7QGnEa1uk6mtBgAAAHU"]
[Thu Jul 30 15:26:12.358561 2026] [security2:error] [pid 173718:tid 173894] [client 20.100.187.246:39951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/404.php"] [unique_id "amuzZEoi7QGnEa1uk6mtBwAAAC0"]
[Thu Jul 30 15:26:12.388017 2026] [core:notice] [pid 173718:tid 173938] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:12.582573 2026] [security2:error] [pid 173718:tid 173864] [client 135.119.63.61:8232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file4.php"] [unique_id "amuzZEoi7QGnEa1uk6mtCwAAAA8"]
[Thu Jul 30 15:26:12.757989 2026] [core:notice] [pid 173718:tid 173907] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:12.821153 2026] [security2:error] [pid 173718:tid 173882] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/mds.php"] [unique_id "amuzZEoi7QGnEa1uk6mtEwAAACE"]
[Thu Jul 30 15:26:12.821254 2026] [security2:error] [pid 173718:tid 173882] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/mds.php"] [unique_id "amuzZEoi7QGnEa1uk6mtEwAAACE"]
[Thu Jul 30 15:26:13.005203 2026] [security2:error] [pid 173718:tid 173868] [client 109.205.214.111:57374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nxt.udi.temporary.site"] [uri "/index.php"] [unique_id "amuzZEoi7QGnEa1uk6mtFAAAABM"]
[Thu Jul 30 15:26:13.038937 2026] [security2:error] [pid 173718:tid 173916] [client 109.205.214.111:57368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nxt.udi.temporary.site"] [uri "/index.php"] [unique_id "amuzZEoi7QGnEa1uk6mtFQAAAEM"]
[Thu Jul 30 15:26:13.287465 2026] [security2:error] [pid 173718:tid 173950] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/zc-208.php"] [unique_id "amuzZUoi7QGnEa1uk6mtHwAAAGU"]
[Thu Jul 30 15:26:13.287573 2026] [security2:error] [pid 173718:tid 173950] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/zc-208.php"] [unique_id "amuzZUoi7QGnEa1uk6mtHwAAAGU"]
[Thu Jul 30 15:26:13.309117 2026] [security2:error] [pid 173718:tid 173964] [client 20.100.187.246:30111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/aa.php"] [unique_id "amuzZUoi7QGnEa1uk6mtIAAAAHM"]
[Thu Jul 30 15:26:13.755806 2026] [security2:error] [pid 173718:tid 173920] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/sid4.php"] [unique_id "amuzZUoi7QGnEa1uk6mtKgAAAEc"]
[Thu Jul 30 15:26:13.755920 2026] [security2:error] [pid 173718:tid 173920] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/sid4.php"] [unique_id "amuzZUoi7QGnEa1uk6mtKgAAAEc"]
[Thu Jul 30 15:26:13.776252 2026] [core:notice] [pid 173718:tid 173872] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:13.779714 2026] [security2:error] [pid 173718:tid 173872] [client 66.249.79.230:44853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/article/view/1919/1197"] [unique_id "amuzZUoi7QGnEa1uk6mtKwAAABc"]
[Thu Jul 30 15:26:14.106014 2026] [security2:error] [pid 173718:tid 173881] [client 20.63.98.115:60568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/class.php"] [unique_id "amuzZkoi7QGnEa1uk6mtMgAAACA"]
[Thu Jul 30 15:26:14.234865 2026] [security2:error] [pid 173718:tid 173955] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.jookreview.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/l10n/"] [unique_id "amuzZkoi7QGnEa1uk6mtNgAAAGo"]
[Thu Jul 30 15:26:14.297899 2026] [core:notice] [pid 173718:tid 173886] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:14.471877 2026] [security2:error] [pid 173718:tid 173867] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wmore1.php"] [unique_id "amuzZkoi7QGnEa1uk6mtOwAAABI"]
[Thu Jul 30 15:26:14.472001 2026] [security2:error] [pid 173718:tid 173867] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wmore1.php"] [unique_id "amuzZkoi7QGnEa1uk6mtOwAAABI"]
[Thu Jul 30 15:26:14.946463 2026] [security2:error] [pid 173718:tid 173938] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/solo1.php"] [unique_id "amuzZkoi7QGnEa1uk6mtRgAAAFk"]
[Thu Jul 30 15:26:14.946568 2026] [security2:error] [pid 173718:tid 173938] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/solo1.php"] [unique_id "amuzZkoi7QGnEa1uk6mtRgAAAFk"]
[Thu Jul 30 15:26:14.999467 2026] [security2:error] [pid 173718:tid 173866] [client 135.119.63.61:55357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file5.php"] [unique_id "amuzZkoi7QGnEa1uk6mtRwAAABE"]
[Thu Jul 30 15:26:15.106698 2026] [fcgid:warn] [pid 173718:tid 173913] (70014)End of file found: [client 172.237.109.114:30097] mod_fcgid: can't get data from http client
[Thu Jul 30 15:26:15.423668 2026] [security2:error] [pid 173718:tid 173879] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.jookreview.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/assets/"] [unique_id "amuzZ0oi7QGnEa1uk6mtUwAAAB4"]
[Thu Jul 30 15:26:15.564187 2026] [security2:error] [pid 173718:tid 173948] [client 20.63.98.115:33593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/login.php"] [unique_id "amuzZ0oi7QGnEa1uk6mtVwAAAGM"]
[Thu Jul 30 15:26:15.679044 2026] [security2:error] [pid 173718:tid 173967] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "401"] [hostname "webdisk.jookreview.com"] [uri "/___proxy_subdomain_webdisk/wp-includes/css/"] [unique_id "amuzZ0oi7QGnEa1uk6mtWAAAAHY"]
[Thu Jul 30 15:26:15.681569 2026] [core:notice] [pid 173718:tid 173976] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:15.914995 2026] [security2:error] [pid 173718:tid 173904] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/public/css.php"] [unique_id "amuzZ0oi7QGnEa1uk6mtYAAAADc"]
[Thu Jul 30 15:26:15.915112 2026] [security2:error] [pid 173718:tid 173904] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/public/css.php"] [unique_id "amuzZ0oi7QGnEa1uk6mtYAAAADc"]
[Thu Jul 30 15:26:15.976557 2026] [security2:error] [pid 173718:tid 173911] [client 172.237.109.114:29000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzZ0oi7QGnEa1uk6mtTwAAACE"]
[Thu Jul 30 15:26:15.976591 2026] [security2:error] [pid 173718:tid 173911] [client 172.237.109.114:29000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzZ0oi7QGnEa1uk6mtTwAAACE"]
[Thu Jul 30 15:26:16.381962 2026] [security2:error] [pid 173718:tid 173970] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/output.php"] [unique_id "amuzaEoi7QGnEa1uk6mtbAAAAHk"]
[Thu Jul 30 15:26:16.382076 2026] [security2:error] [pid 173718:tid 173970] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/output.php"] [unique_id "amuzaEoi7QGnEa1uk6mtbAAAAHk"]
[Thu Jul 30 15:26:16.481867 2026] [security2:error] [pid 173718:tid 173906] [client 20.100.187.246:31083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/aafewc0k.php"] [unique_id "amuzaEoi7QGnEa1uk6mtbgAAADk"]
[Thu Jul 30 15:26:16.506699 2026] [security2:error] [pid 173718:tid 173865] [client 104.28.240.60:22038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shorewooddaycare.com"] [uri "/ms-themes.php"] [unique_id "amuzaEoi7QGnEa1uk6mtbwAAABA"]
[Thu Jul 30 15:26:16.598149 2026] [proxy:error] [pid 173718:tid 173926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:26:16.598204 2026] [proxy_http:error] [pid 173718:tid 173926] [client 74.7.244.2:57986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:26:16.598859 2026] [proxy:error] [pid 173718:tid 173926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:26:16.598908 2026] [proxy_http:error] [pid 173718:tid 173926] [client 74.7.244.2:57986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:26:16.599048 2026] [security2:error] [pid 173718:tid 173926] [client 74.7.244.2:57986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcalendars.klg.udi.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amuzaEoi7QGnEa1uk6mtcwAAAE0"]
[Thu Jul 30 15:26:16.847889 2026] [security2:error] [pid 173718:tid 173871] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-file-120.php"] [unique_id "amuzaEoi7QGnEa1uk6mteAAAABY"]
[Thu Jul 30 15:26:16.848020 2026] [security2:error] [pid 173718:tid 173871] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-file-120.php"] [unique_id "amuzaEoi7QGnEa1uk6mteAAAABY"]
[Thu Jul 30 15:26:17.315068 2026] [security2:error] [pid 173718:tid 173912] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/special.php"] [unique_id "amuzaUoi7QGnEa1uk6mtgAAAAD8"]
[Thu Jul 30 15:26:17.315225 2026] [security2:error] [pid 173718:tid 173912] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/special.php"] [unique_id "amuzaUoi7QGnEa1uk6mtgAAAAD8"]
[Thu Jul 30 15:26:17.370476 2026] [security2:error] [pid 173718:tid 173875] [client 20.100.187.246:37359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/abcd.php"] [unique_id "amuzaUoi7QGnEa1uk6mtggAAABo"]
[Thu Jul 30 15:26:17.466703 2026] [security2:error] [pid 173718:tid 173902] [client 172.237.109.114:7107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzaEoi7QGnEa1uk6mtfAAAADU"]
[Thu Jul 30 15:26:17.782756 2026] [security2:error] [pid 173718:tid 173913] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/as.php"] [unique_id "amuzaUoi7QGnEa1uk6mtjAAAAEA"]
[Thu Jul 30 15:26:17.782858 2026] [security2:error] [pid 173718:tid 173913] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/as.php"] [unique_id "amuzaUoi7QGnEa1uk6mtjAAAAEA"]
[Thu Jul 30 15:26:18.148255 2026] [security2:error] [pid 173718:tid 173907] [client 20.100.187.246:43033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/about.php"] [unique_id "amuzakoi7QGnEa1uk6mtlwAAADo"]
[Thu Jul 30 15:26:18.261521 2026] [security2:error] [pid 173718:tid 173976] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/cgi-bin/index.php"] [unique_id "amuzakoi7QGnEa1uk6mtmAAAAH8"]
[Thu Jul 30 15:26:18.261638 2026] [security2:error] [pid 173718:tid 173976] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/cgi-bin/index.php"] [unique_id "amuzakoi7QGnEa1uk6mtmAAAAH8"]
[Thu Jul 30 15:26:18.482780 2026] [security2:error] [pid 173718:tid 173888] [client 172.237.109.114:27760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzakoi7QGnEa1uk6mtkwAAACc"]
[Thu Jul 30 15:26:18.657076 2026] [core:notice] [pid 173718:tid 173974] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:18.660666 2026] [security2:error] [pid 173718:tid 173974] [client 66.249.79.229:61736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/jka/article/download/1240/823"] [unique_id "amuzakoi7QGnEa1uk6mtnAAAAH0"]
[Thu Jul 30 15:26:18.730832 2026] [security2:error] [pid 173718:tid 173927] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/w1px.php"] [unique_id "amuzakoi7QGnEa1uk6mtpgAAAE4"]
[Thu Jul 30 15:26:18.730942 2026] [security2:error] [pid 173718:tid 173927] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/w1px.php"] [unique_id "amuzakoi7QGnEa1uk6mtpgAAAE4"]
[Thu Jul 30 15:26:18.887401 2026] [core:notice] [pid 173718:tid 173851] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:18.890708 2026] [security2:error] [pid 173718:tid 173851] [client 66.249.79.229:61736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/agrijati/article/view/187"] [unique_id "amuzakoi7QGnEa1uk6mtqAAAAAI"]
[Thu Jul 30 15:26:19.015208 2026] [security2:error] [pid 173718:tid 173947] [client 20.63.98.115:26207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/aged.php"] [unique_id "amuza0oi7QGnEa1uk6mtrwAAAGI"]
[Thu Jul 30 15:26:19.202051 2026] [security2:error] [pid 173718:tid 173949] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/js.php"] [unique_id "amuza0oi7QGnEa1uk6mtswAAAGQ"]
[Thu Jul 30 15:26:19.202161 2026] [security2:error] [pid 173718:tid 173949] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/js.php"] [unique_id "amuza0oi7QGnEa1uk6mtswAAAGQ"]
[Thu Jul 30 15:26:19.355104 2026] [security2:error] [pid 173718:tid 173963] [client 20.100.187.246:31067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/admin.php"] [unique_id "amuza0oi7QGnEa1uk6mttAAAAHI"]
[Thu Jul 30 15:26:19.667904 2026] [security2:error] [pid 173718:tid 173896] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/core.php"] [unique_id "amuza0oi7QGnEa1uk6mtvgAAAC8"]
[Thu Jul 30 15:26:19.668004 2026] [security2:error] [pid 173718:tid 173896] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/core.php"] [unique_id "amuza0oi7QGnEa1uk6mtvgAAAC8"]
[Thu Jul 30 15:26:19.782815 2026] [security2:error] [pid 173718:tid 173973] [client 4.184.185.91:17116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuza0oi7QGnEa1uk6mtvwAAAHw"]
[Thu Jul 30 15:26:19.782942 2026] [security2:error] [pid 173718:tid 173973] [client 4.184.185.91:17116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuza0oi7QGnEa1uk6mtvwAAAHw"]
[Thu Jul 30 15:26:20.033000 2026] [security2:error] [pid 173718:tid 173929] [client 74.7.228.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.abudhabifurnituremoversandpackers.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amuzbEoi7QGnEa1uk6mtxwAAUAk"]
[Thu Jul 30 15:26:20.132691 2026] [security2:error] [pid 173718:tid 173902] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/fffm.php"] [unique_id "amuzbEoi7QGnEa1uk6mtyAAAADU"]
[Thu Jul 30 15:26:20.132808 2026] [security2:error] [pid 173718:tid 173902] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/fffm.php"] [unique_id "amuzbEoi7QGnEa1uk6mtyAAAADU"]
[Thu Jul 30 15:26:20.589291 2026] [security2:error] [pid 173718:tid 173857] [client 20.100.187.246:43065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/adminfuns.php"] [unique_id "amuzbEoi7QGnEa1uk6mt0wAAAAg"]
[Thu Jul 30 15:26:20.597874 2026] [security2:error] [pid 173718:tid 173937] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ww.php"] [unique_id "amuzbEoi7QGnEa1uk6mt1AAAAFg"]
[Thu Jul 30 15:26:20.597996 2026] [security2:error] [pid 173718:tid 173937] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ww.php"] [unique_id "amuzbEoi7QGnEa1uk6mt1AAAAFg"]
[Thu Jul 30 15:26:20.700324 2026] [security2:error] [pid 173718:tid 173918] [client 38.172.162.57:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzbEoi7QGnEa1uk6mt1gAAAEU"]
[Thu Jul 30 15:26:20.700674 2026] [security2:error] [pid 173718:tid 173918] [client 38.172.162.57:16320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzbEoi7QGnEa1uk6mt1gAAAEU"]
[Thu Jul 30 15:26:20.970310 2026] [core:notice] [pid 173718:tid 173967] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:21.066840 2026] [security2:error] [pid 173718:tid 173878] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/domvf.php"] [unique_id "amuzbUoi7QGnEa1uk6mt4gAAAB0"]
[Thu Jul 30 15:26:21.066964 2026] [security2:error] [pid 173718:tid 173878] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/domvf.php"] [unique_id "amuzbUoi7QGnEa1uk6mt4gAAAB0"]
[Thu Jul 30 15:26:21.268415 2026] [security2:error] [pid 173718:tid 173853] [client 20.100.187.246:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/albin.php"] [unique_id "amuzbUoi7QGnEa1uk6mt5AAAAAQ"]
[Thu Jul 30 15:26:21.530841 2026] [security2:error] [pid 173718:tid 173944] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/echkm.php"] [unique_id "amuzbUoi7QGnEa1uk6mt8AAAAF8"]
[Thu Jul 30 15:26:21.530943 2026] [security2:error] [pid 173718:tid 173944] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/echkm.php"] [unique_id "amuzbUoi7QGnEa1uk6mt8AAAAF8"]
[Thu Jul 30 15:26:21.585514 2026] [security2:error] [pid 173718:tid 173961] [client 4.184.185.91:17051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuzbUoi7QGnEa1uk6mt8gAAAHA"]
[Thu Jul 30 15:26:21.585615 2026] [security2:error] [pid 173718:tid 173961] [client 4.184.185.91:17051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuzbUoi7QGnEa1uk6mt8gAAAHA"]
[Thu Jul 30 15:26:21.606344 2026] [security2:error] [pid 173718:tid 173732] [remote 74.7.243.224:45246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/article.php"] [unique_id "amuzbUoi7QGnEa1uk6mt9gAATgw"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/js/uploads/partners/1784122808_wilde%20gazen.jpg
[Thu Jul 30 15:26:21.762176 2026] [security2:error] [pid 173718:tid 173957] [client 20.63.98.115:33634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/vv.php"] [unique_id "amuzbUoi7QGnEa1uk6mt_QAAAGw"]
[Thu Jul 30 15:26:22.004306 2026] [security2:error] [pid 173718:tid 173933] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ano.php"] [unique_id "amuzbkoi7QGnEa1uk6mt_gAAAFQ"]
[Thu Jul 30 15:26:22.004470 2026] [security2:error] [pid 173718:tid 173933] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ano.php"] [unique_id "amuzbkoi7QGnEa1uk6mt_gAAAFQ"]
[Thu Jul 30 15:26:22.031224 2026] [security2:error] [pid 173718:tid 173900] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzbUoi7QGnEa1uk6mt7AAAADM"]
[Thu Jul 30 15:26:22.064338 2026] [core:notice] [pid 173718:tid 173886] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:22.474255 2026] [security2:error] [pid 173718:tid 173929] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ah25.php"] [unique_id "amuzbkoi7QGnEa1uk6muCgAAAFA"]
[Thu Jul 30 15:26:22.474422 2026] [security2:error] [pid 173718:tid 173929] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ah25.php"] [unique_id "amuzbkoi7QGnEa1uk6muCgAAAFA"]
[Thu Jul 30 15:26:22.581233 2026] [core:notice] [pid 173718:tid 173866] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:22.936971 2026] [security2:error] [pid 173718:tid 173963] [client 135.119.63.61:57352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file6.php"] [unique_id "amuzbkoi7QGnEa1uk6muFQAAAHI"]
[Thu Jul 30 15:26:22.941060 2026] [security2:error] [pid 173718:tid 173937] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/term.php"] [unique_id "amuzbkoi7QGnEa1uk6muFgAAAFg"]
[Thu Jul 30 15:26:22.941130 2026] [security2:error] [pid 173718:tid 173937] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/term.php"] [unique_id "amuzbkoi7QGnEa1uk6muFgAAAFg"]
[Thu Jul 30 15:26:23.403557 2026] [security2:error] [pid 173718:tid 173914] [client 20.100.187.246:43023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/amfsqvgv.php"] [unique_id "amuzb0oi7QGnEa1uk6muIQAAAEE"]
[Thu Jul 30 15:26:23.408944 2026] [security2:error] [pid 173718:tid 173888] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/we.php"] [unique_id "amuzb0oi7QGnEa1uk6muIgAAACc"]
[Thu Jul 30 15:26:23.409089 2026] [security2:error] [pid 173718:tid 173888] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/we.php"] [unique_id "amuzb0oi7QGnEa1uk6muIgAAACc"]
[Thu Jul 30 15:26:23.876926 2026] [security2:error] [pid 173718:tid 173922] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/zip-onee.php"] [unique_id "amuzb0oi7QGnEa1uk6muMAAAAEk"]
[Thu Jul 30 15:26:23.877038 2026] [security2:error] [pid 173718:tid 173922] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/zip-onee.php"] [unique_id "amuzb0oi7QGnEa1uk6muMAAAAEk"]
[Thu Jul 30 15:26:23.877801 2026] [core:notice] [pid 173718:tid 173946] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:23.974118 2026] [security2:error] [pid 173718:tid 173928] [client 4.184.185.91:17093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuzb0oi7QGnEa1uk6muMQAAAE8"]
[Thu Jul 30 15:26:23.974234 2026] [security2:error] [pid 173718:tid 173928] [client 4.184.185.91:17093] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amuzb0oi7QGnEa1uk6muMQAAAE8"]
[Thu Jul 30 15:26:24.076091 2026] [security2:error] [pid 173718:tid 173925] [client 135.119.63.61:8069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file7.php"] [unique_id "amuzcEoi7QGnEa1uk6muMgAAAEw"]
[Thu Jul 30 15:26:24.153931 2026] [core:notice] [pid 173718:tid 173906] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:24.157245 2026] [security2:error] [pid 173718:tid 173906] [client 66.249.79.8:56591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JGST/article/view/2385/1406"] [unique_id "amuzcEoi7QGnEa1uk6muNgAAADk"]
[Thu Jul 30 15:26:24.346000 2026] [security2:error] [pid 173718:tid 173893] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/il.php"] [unique_id "amuzcEoi7QGnEa1uk6muOwAAACw"]
[Thu Jul 30 15:26:24.346101 2026] [security2:error] [pid 173718:tid 173893] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/il.php"] [unique_id "amuzcEoi7QGnEa1uk6muOwAAACw"]
[Thu Jul 30 15:26:24.810809 2026] [security2:error] [pid 173718:tid 173945] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/one.php"] [unique_id "amuzcEoi7QGnEa1uk6muQwAAAGA"]
[Thu Jul 30 15:26:24.810956 2026] [security2:error] [pid 173718:tid 173945] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/one.php"] [unique_id "amuzcEoi7QGnEa1uk6muQwAAAGA"]
[Thu Jul 30 15:26:24.980321 2026] [security2:error] [pid 173718:tid 173872] [client 20.100.187.246:36584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/ant.php"] [unique_id "amuzcEoi7QGnEa1uk6muSgAAABc"]
[Thu Jul 30 15:26:25.294958 2026] [security2:error] [pid 173718:tid 173921] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/002.php"] [unique_id "amuzcUoi7QGnEa1uk6muTgAAAEg"]
[Thu Jul 30 15:26:25.295068 2026] [security2:error] [pid 173718:tid 173921] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/002.php"] [unique_id "amuzcUoi7QGnEa1uk6muTgAAAEg"]
[Thu Jul 30 15:26:25.311479 2026] [security2:error] [pid 173718:tid 173864] [client 20.63.98.115:39693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/user-edit.php"] [unique_id "amuzcUoi7QGnEa1uk6muTwAAAA8"]
[Thu Jul 30 15:26:25.529957 2026] [security2:error] [pid 173718:tid 173958] [client 172.237.109.114:20941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzcEoi7QGnEa1uk6muSQAAAG0"]
[Thu Jul 30 15:26:25.720227 2026] [security2:error] [pid 173718:tid 173902] [client 20.100.187.246:4489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/appreciators.php"] [unique_id "amuzcUoi7QGnEa1uk6muWQAAADU"]
[Thu Jul 30 15:26:25.733549 2026] [core:notice] [pid 173718:tid 173857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:25.736799 2026] [security2:error] [pid 173718:tid 173857] [client 66.249.79.8:56591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/InaBHS/article/view/9261/4084"] [unique_id "amuzcUoi7QGnEa1uk6muWwAAAAg"]
[Thu Jul 30 15:26:25.743810 2026] [security2:error] [pid 173718:tid 173941] [client 135.119.63.61:8085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file8.php"] [unique_id "amuzcUoi7QGnEa1uk6muXAAAAFw"]
[Thu Jul 30 15:26:25.755658 2026] [security2:error] [pid 173718:tid 173849] [client 4.184.185.91:17105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/err.php"] [unique_id "amuzcUoi7QGnEa1uk6muXQAAAAA"]
[Thu Jul 30 15:26:25.755742 2026] [security2:error] [pid 173718:tid 173849] [client 4.184.185.91:17105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/err.php"] [unique_id "amuzcUoi7QGnEa1uk6muXQAAAAA"]
[Thu Jul 30 15:26:25.762607 2026] [security2:error] [pid 173718:tid 173953] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/file1.php"] [unique_id "amuzcUoi7QGnEa1uk6muXgAAAGg"]
[Thu Jul 30 15:26:25.762692 2026] [security2:error] [pid 173718:tid 173953] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/file1.php"] [unique_id "amuzcUoi7QGnEa1uk6muXgAAAGg"]
[Thu Jul 30 15:26:26.231247 2026] [security2:error] [pid 173718:tid 173878] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/akimet.php"] [unique_id "amuzckoi7QGnEa1uk6mubwAAAB0"]
[Thu Jul 30 15:26:26.231350 2026] [security2:error] [pid 173718:tid 173878] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/akimet.php"] [unique_id "amuzckoi7QGnEa1uk6mubwAAAB0"]
[Thu Jul 30 15:26:26.364319 2026] [security2:error] [pid 173718:tid 173930] [client 172.237.109.114:51664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzcUoi7QGnEa1uk6muWgAAAG4"]
[Thu Jul 30 15:26:26.364364 2026] [security2:error] [pid 173718:tid 173930] [client 172.237.109.114:51664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzcUoi7QGnEa1uk6muWgAAAG4"]
[Thu Jul 30 15:26:26.385290 2026] [core:notice] [pid 173718:tid 173956] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:26.388703 2026] [security2:error] [pid 173718:tid 173956] [client 66.249.79.8:56591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/agrijati/article/view/2946"] [unique_id "amuzckoi7QGnEa1uk6mucAAAAGs"]
[Thu Jul 30 15:26:26.642163 2026] [security2:error] [pid 173718:tid 173914] [client 20.100.187.246:29944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/archive.php"] [unique_id "amuzckoi7QGnEa1uk6mudwAAAEE"]
[Thu Jul 30 15:26:26.699440 2026] [security2:error] [pid 173718:tid 173964] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/reop3.php"] [unique_id "amuzckoi7QGnEa1uk6mueAAAAHM"]
[Thu Jul 30 15:26:26.699554 2026] [security2:error] [pid 173718:tid 173964] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/reop3.php"] [unique_id "amuzckoi7QGnEa1uk6mueAAAAHM"]
[Thu Jul 30 15:26:26.893687 2026] [security2:error] [pid 173718:tid 173876] [client 135.119.63.61:8071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file9.php"] [unique_id "amuzckoi7QGnEa1uk6mufAAAABs"]
[Thu Jul 30 15:26:26.903299 2026] [security2:error] [pid 173718:tid 173967] [client 20.63.98.115:33633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "amuzckoi7QGnEa1uk6mufQAAAHY"]
[Thu Jul 30 15:26:27.173754 2026] [security2:error] [pid 173718:tid 173893] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/h.php"] [unique_id "amuzc0oi7QGnEa1uk6muhAAAACw"]
[Thu Jul 30 15:26:27.173862 2026] [security2:error] [pid 173718:tid 173893] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/h.php"] [unique_id "amuzc0oi7QGnEa1uk6muhAAAACw"]
[Thu Jul 30 15:26:27.540160 2026] [security2:error] [pid 173718:tid 173945] [client 4.184.185.91:17040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/img.php"] [unique_id "amuzc0oi7QGnEa1uk6muiwAAAGA"]
[Thu Jul 30 15:26:27.540274 2026] [security2:error] [pid 173718:tid 173945] [client 4.184.185.91:17040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/img.php"] [unique_id "amuzc0oi7QGnEa1uk6muiwAAAGA"]
[Thu Jul 30 15:26:27.644910 2026] [security2:error] [pid 173718:tid 173895] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/2x.php"] [unique_id "amuzc0oi7QGnEa1uk6mujwAAAC4"]
[Thu Jul 30 15:26:27.645040 2026] [security2:error] [pid 173718:tid 173895] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/2x.php"] [unique_id "amuzc0oi7QGnEa1uk6mujwAAAC4"]
[Thu Jul 30 15:26:28.111742 2026] [security2:error] [pid 173718:tid 173939] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/petx.php"] [unique_id "amuzdEoi7QGnEa1uk6mumQAAAFo"]
[Thu Jul 30 15:26:28.111846 2026] [security2:error] [pid 173718:tid 173939] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/petx.php"] [unique_id "amuzdEoi7QGnEa1uk6mumQAAAFo"]
[Thu Jul 30 15:26:28.577197 2026] [security2:error] [pid 173718:tid 173873] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/zxz.php"] [unique_id "amuzdEoi7QGnEa1uk6muqQAAABg"]
[Thu Jul 30 15:26:28.577304 2026] [security2:error] [pid 173718:tid 173873] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/zxz.php"] [unique_id "amuzdEoi7QGnEa1uk6muqQAAABg"]
[Thu Jul 30 15:26:28.589124 2026] [security2:error] [pid 173718:tid 173975] [client 20.63.98.115:26623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/engine.php"] [unique_id "amuzdEoi7QGnEa1uk6muqgAAAH4"]
[Thu Jul 30 15:26:28.745256 2026] [security2:error] [pid 173718:tid 173919] [client 4.184.185.91:17123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/aa.php"] [unique_id "amuzdEoi7QGnEa1uk6musAAAAEY"]
[Thu Jul 30 15:26:28.745366 2026] [security2:error] [pid 173718:tid 173919] [client 4.184.185.91:17123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/aa.php"] [unique_id "amuzdEoi7QGnEa1uk6musAAAAEY"]
[Thu Jul 30 15:26:28.932355 2026] [security2:error] [pid 173718:tid 173849] [client 20.100.187.246:43021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/as.php"] [unique_id "amuzdEoi7QGnEa1uk6mutAAAAAA"]
[Thu Jul 30 15:26:28.958550 2026] [security2:error] [pid 173718:tid 173860] [client 213.152.161.133:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuzdEoi7QGnEa1uk6mutQAAAAs"]
[Thu Jul 30 15:26:28.958645 2026] [security2:error] [pid 173718:tid 173860] [client 213.152.161.133:43330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuzdEoi7QGnEa1uk6mutQAAAAs"]
[Thu Jul 30 15:26:29.041295 2026] [security2:error] [pid 173718:tid 173858] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/2.php"] [unique_id "amuzdUoi7QGnEa1uk6muvAAAAAk"]
[Thu Jul 30 15:26:29.041440 2026] [security2:error] [pid 173718:tid 173858] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/2.php"] [unique_id "amuzdUoi7QGnEa1uk6muvAAAAAk"]
[Thu Jul 30 15:26:29.211993 2026] [core:notice] [pid 173718:tid 173946] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:29.511028 2026] [security2:error] [pid 173718:tid 173934] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/op.php"] [unique_id "amuzdUoi7QGnEa1uk6muzAAAAFU"]
[Thu Jul 30 15:26:29.511153 2026] [security2:error] [pid 173718:tid 173934] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/op.php"] [unique_id "amuzdUoi7QGnEa1uk6muzAAAAFU"]
[Thu Jul 30 15:26:29.843924 2026] [security2:error] [pid 173718:tid 173867] [client 20.100.187.246:31787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/atomlib.php"] [unique_id "amuzdUoi7QGnEa1uk6mu3gAAABI"]
[Thu Jul 30 15:26:29.988888 2026] [security2:error] [pid 173718:tid 173902] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/a5.php"] [unique_id "amuzdUoi7QGnEa1uk6mu5AAAADU"]
[Thu Jul 30 15:26:29.989070 2026] [security2:error] [pid 173718:tid 173902] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/a5.php"] [unique_id "amuzdUoi7QGnEa1uk6mu5AAAADU"]
[Thu Jul 30 15:26:30.236665 2026] [core:notice] [pid 173718:tid 173975] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:30.255546 2026] [core:error] [pid 173718:tid 173975] [client 66.249.79.229:54351] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:26:30.255775 2026] [security2:error] [pid 173718:tid 173975] [client 66.249.79.229:54351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/8371/3295.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuzdkoi7QGnEa1uk6mu7QAAAH4"]
[Thu Jul 30 15:26:30.458092 2026] [security2:error] [pid 173718:tid 173959] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ws80.php"] [unique_id "amuzdkoi7QGnEa1uk6mu9QAAAG4"]
[Thu Jul 30 15:26:30.458194 2026] [security2:error] [pid 173718:tid 173959] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ws80.php"] [unique_id "amuzdkoi7QGnEa1uk6mu9QAAAG4"]
[Thu Jul 30 15:26:30.727406 2026] [security2:error] [pid 173718:tid 173859] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzdkoi7QGnEa1uk6mu6QAAClA"]
[Thu Jul 30 15:26:30.927837 2026] [security2:error] [pid 173718:tid 173925] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/xa.php"] [unique_id "amuzdkoi7QGnEa1uk6mvBgAAAEw"]
[Thu Jul 30 15:26:30.927927 2026] [security2:error] [pid 173718:tid 173925] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/xa.php"] [unique_id "amuzdkoi7QGnEa1uk6mvBgAAAEw"]
[Thu Jul 30 15:26:31.290973 2026] [security2:error] [pid 173718:tid 173964] [client 38.172.162.57:15882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzd0oi7QGnEa1uk6mvEgAAAHM"]
[Thu Jul 30 15:26:31.291560 2026] [security2:error] [pid 173718:tid 173964] [client 38.172.162.57:15882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzd0oi7QGnEa1uk6mvEgAAAHM"]
[Thu Jul 30 15:26:31.395656 2026] [security2:error] [pid 173718:tid 173957] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/asd67.php"] [unique_id "amuzd0oi7QGnEa1uk6mvFAAAAGw"]
[Thu Jul 30 15:26:31.395759 2026] [security2:error] [pid 173718:tid 173957] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/asd67.php"] [unique_id "amuzd0oi7QGnEa1uk6mvFAAAAGw"]
[Thu Jul 30 15:26:31.588393 2026] [security2:error] [pid 173718:tid 173912] [client 4.184.185.91:17046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/av.php"] [unique_id "amuzd0oi7QGnEa1uk6mvHgAAAD8"]
[Thu Jul 30 15:26:31.588505 2026] [security2:error] [pid 173718:tid 173912] [client 4.184.185.91:17046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/av.php"] [unique_id "amuzd0oi7QGnEa1uk6mvHgAAAD8"]
[Thu Jul 30 15:26:31.864457 2026] [security2:error] [pid 173718:tid 173941] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/bk.php"] [unique_id "amuzd0oi7QGnEa1uk6mvJgAAAFw"]
[Thu Jul 30 15:26:31.864565 2026] [security2:error] [pid 173718:tid 173941] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/bk.php"] [unique_id "amuzd0oi7QGnEa1uk6mvJgAAAFw"]
[Thu Jul 30 15:26:31.974132 2026] [security2:error] [pid 173718:tid 173806] [remote 198.38.94.87:39672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/wp-login.php"] [unique_id "amuzd0oi7QGnEa1uk6mvKwAADVY"]
[Thu Jul 30 15:26:32.329493 2026] [security2:error] [pid 173718:tid 173849] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-links.php"] [unique_id "amuzeEoi7QGnEa1uk6mvOQAAAAA"]
[Thu Jul 30 15:26:32.329574 2026] [security2:error] [pid 173718:tid 173849] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-links.php"] [unique_id "amuzeEoi7QGnEa1uk6mvOQAAAAA"]
[Thu Jul 30 15:26:32.805489 2026] [security2:error] [pid 173718:tid 173851] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/mosty.php"] [unique_id "amuzeEoi7QGnEa1uk6mvQwAAAAI"]
[Thu Jul 30 15:26:32.805601 2026] [security2:error] [pid 173718:tid 173851] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/mosty.php"] [unique_id "amuzeEoi7QGnEa1uk6mvQwAAAAI"]
[Thu Jul 30 15:26:33.270129 2026] [security2:error] [pid 173718:tid 173858] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/sump3.php"] [unique_id "amuzeUoi7QGnEa1uk6mvTQAAAAk"]
[Thu Jul 30 15:26:33.270260 2026] [security2:error] [pid 173718:tid 173858] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/sump3.php"] [unique_id "amuzeUoi7QGnEa1uk6mvTQAAAAk"]
[Thu Jul 30 15:26:33.361752 2026] [security2:error] [pid 173718:tid 173887] [client 4.184.185.91:17025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/xa.php"] [unique_id "amuzeUoi7QGnEa1uk6mvUQAAACY"]
[Thu Jul 30 15:26:33.361855 2026] [security2:error] [pid 173718:tid 173887] [client 4.184.185.91:17025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/xa.php"] [unique_id "amuzeUoi7QGnEa1uk6mvUQAAACY"]
[Thu Jul 30 15:26:33.555470 2026] [security2:error] [pid 173718:tid 173892] [client 20.100.187.246:54310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/autoload_classmap.php"] [unique_id "amuzeUoi7QGnEa1uk6mvVgAAACs"]
[Thu Jul 30 15:26:33.740478 2026] [security2:error] [pid 173718:tid 173966] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/first.php"] [unique_id "amuzeUoi7QGnEa1uk6mvXgAAAHU"]
[Thu Jul 30 15:26:33.740586 2026] [security2:error] [pid 173718:tid 173966] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/first.php"] [unique_id "amuzeUoi7QGnEa1uk6mvXgAAAHU"]
[Thu Jul 30 15:26:33.791522 2026] [security2:error] [pid 173718:tid 173907] [client 20.63.98.115:33600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/edit-comments.php"] [unique_id "amuzeUoi7QGnEa1uk6mvYgAAADo"]
[Thu Jul 30 15:26:34.208484 2026] [security2:error] [pid 173718:tid 173932] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/acp.php"] [unique_id "amuzekoi7QGnEa1uk6mvawAAAFM"]
[Thu Jul 30 15:26:34.208572 2026] [security2:error] [pid 173718:tid 173932] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/acp.php"] [unique_id "amuzekoi7QGnEa1uk6mvawAAAFM"]
[Thu Jul 30 15:26:34.305761 2026] [security2:error] [pid 173718:tid 173917] [client 20.100.187.246:31387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/bb.php"] [unique_id "amuzekoi7QGnEa1uk6mvcQAAAEQ"]
[Thu Jul 30 15:26:34.624227 2026] [security2:error] [pid 173718:tid 173897] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzekoi7QGnEa1uk6mvZwAAADA"]
[Thu Jul 30 15:26:34.676809 2026] [security2:error] [pid 173718:tid 173937] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-good.php"] [unique_id "amuzekoi7QGnEa1uk6mveQAAAFg"]
[Thu Jul 30 15:26:34.676897 2026] [security2:error] [pid 173718:tid 173937] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-good.php"] [unique_id "amuzekoi7QGnEa1uk6mveQAAAFg"]
[Thu Jul 30 15:26:34.901632 2026] [core:notice] [pid 173718:tid 173930] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:34.962049 2026] [security2:error] [pid 173718:tid 173927] [client 4.184.185.91:17096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/media.php"] [unique_id "amuzekoi7QGnEa1uk6mviAAAAE4"]
[Thu Jul 30 15:26:34.962147 2026] [security2:error] [pid 173718:tid 173927] [client 4.184.185.91:17096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/media.php"] [unique_id "amuzekoi7QGnEa1uk6mviAAAAE4"]
[Thu Jul 30 15:26:35.144854 2026] [security2:error] [pid 173718:tid 173896] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/daerl3.php"] [unique_id "amuze0oi7QGnEa1uk6mviwAAAC8"]
[Thu Jul 30 15:26:35.144967 2026] [security2:error] [pid 173718:tid 173896] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/daerl3.php"] [unique_id "amuze0oi7QGnEa1uk6mviwAAAC8"]
[Thu Jul 30 15:26:35.393104 2026] [security2:error] [pid 173718:tid 173742] [remote 103.28.36.122:44618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.xfx.hfl.temporary.site"] [uri "/wp-login.php"] [unique_id "amuze0oi7QGnEa1uk6mvkwAAcBY"]
[Thu Jul 30 15:26:35.616010 2026] [security2:error] [pid 173718:tid 173955] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/php5.php"] [unique_id "amuze0oi7QGnEa1uk6mvlwAAAGo"]
[Thu Jul 30 15:26:35.616142 2026] [security2:error] [pid 173718:tid 173955] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/php5.php"] [unique_id "amuze0oi7QGnEa1uk6mvlwAAAGo"]
[Thu Jul 30 15:26:35.627865 2026] [security2:error] [pid 173718:tid 173761] [remote 47.128.116.69:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahyarjewelry.co"] [uri "/robots.txt"] [unique_id "amuze0oi7QGnEa1uk6mvmAAAHik"]
[Thu Jul 30 15:26:35.692652 2026] [security2:error] [pid 173718:tid 173878] [client 20.63.98.115:26612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-blog-header.php"] [unique_id "amuze0oi7QGnEa1uk6mvnAAAAB0"]
[Thu Jul 30 15:26:35.873631 2026] [security2:error] [pid 173718:tid 173917] [client 4.184.185.91:17128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/images.php"] [unique_id "amuze0oi7QGnEa1uk6mvoAAAAEQ"]
[Thu Jul 30 15:26:35.873742 2026] [security2:error] [pid 173718:tid 173917] [client 4.184.185.91:17128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/images.php"] [unique_id "amuze0oi7QGnEa1uk6mvoAAAAEQ"]
[Thu Jul 30 15:26:35.966554 2026] [security2:error] [pid 173718:tid 173756] [remote 57.141.0.71:61868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuze0oi7QGnEa1uk6mvpAAAGiQ"]
[Thu Jul 30 15:26:36.083605 2026] [security2:error] [pid 173718:tid 173936] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/xoot.php"] [unique_id "amuzfEoi7QGnEa1uk6mvpQAAAFc"]
[Thu Jul 30 15:26:36.083711 2026] [security2:error] [pid 173718:tid 173936] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/xoot.php"] [unique_id "amuzfEoi7QGnEa1uk6mvpQAAAFc"]
[Thu Jul 30 15:26:36.336771 2026] [core:notice] [pid 173718:tid 173958] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:36.340270 2026] [security2:error] [pid 173718:tid 173958] [client 66.249.79.229:40251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/camic/article/view/9086/3927"] [unique_id "amuzfEoi7QGnEa1uk6mvqQAAAG0"]
[Thu Jul 30 15:26:36.459256 2026] [security2:error] [pid 173718:tid 173922] [client 74.7.175.166:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.higherdimensionsii.com"] [uri "/index.php"] [unique_id "amuzeUoi7QGnEa1uk6mvYwAASXM"]
[Thu Jul 30 15:26:36.459287 2026] [security2:error] [pid 173718:tid 173922] [client 74.7.175.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.higherdimensionsii.com"] [uri "/index.php"] [unique_id "amuzeUoi7QGnEa1uk6mvYwAASXM"]
[Thu Jul 30 15:26:36.553663 2026] [security2:error] [pid 173718:tid 173962] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/clxcc.php"] [unique_id "amuzfEoi7QGnEa1uk6mvsQAAAHE"]
[Thu Jul 30 15:26:36.553812 2026] [security2:error] [pid 173718:tid 173962] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/clxcc.php"] [unique_id "amuzfEoi7QGnEa1uk6mvsQAAAHE"]
[Thu Jul 30 15:26:36.560750 2026] [core:notice] [pid 173718:tid 173973] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:36.564130 2026] [security2:error] [pid 173718:tid 173973] [client 66.249.79.229:40251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Signal/article/view/11/11"] [unique_id "amuzfEoi7QGnEa1uk6mvsgAAAHw"]
[Thu Jul 30 15:26:36.663257 2026] [security2:error] [pid 173718:tid 173880] [client 4.184.185.91:17126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/gecko.php"] [unique_id "amuzfEoi7QGnEa1uk6mvswAAAB8"]
[Thu Jul 30 15:26:36.663369 2026] [security2:error] [pid 173718:tid 173880] [client 4.184.185.91:17126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/gecko.php"] [unique_id "amuzfEoi7QGnEa1uk6mvswAAAB8"]
[Thu Jul 30 15:26:36.765661 2026] [fcgid:warn] [pid 173718:tid 173885] (70014)End of file found: [client 66.132.172.182:30652] mod_fcgid: can't get data from http client
[Thu Jul 30 15:26:37.022213 2026] [security2:error] [pid 173718:tid 173955] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ai.php"] [unique_id "amuzfUoi7QGnEa1uk6mvxAAAAGo"]
[Thu Jul 30 15:26:37.022307 2026] [security2:error] [pid 173718:tid 173955] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ai.php"] [unique_id "amuzfUoi7QGnEa1uk6mvxAAAAGo"]
[Thu Jul 30 15:26:37.030837 2026] [core:notice] [pid 173718:tid 173869] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:37.033257 2026] [security2:error] [pid 173718:tid 173851] [client 20.63.98.115:61667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/alfa-rex.php7"] [unique_id "amuzfUoi7QGnEa1uk6mvxgAAAAI"]
[Thu Jul 30 15:26:37.034554 2026] [security2:error] [pid 173718:tid 173869] [client 66.249.79.8:45481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/article/view/798"] [unique_id "amuzfUoi7QGnEa1uk6mvxQAAABQ"]
[Thu Jul 30 15:26:37.234006 2026] [security2:error] [pid 173718:tid 173949] [client 20.100.187.246:43048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/bnm.php"] [unique_id "amuzfUoi7QGnEa1uk6mvxwAAAGQ"]
[Thu Jul 30 15:26:37.368029 2026] [security2:error] [pid 173718:tid 173749] [remote 57.141.0.30:33850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amuzfUoi7QGnEa1uk6mvzAAABh0"]
[Thu Jul 30 15:26:37.486325 2026] [security2:error] [pid 173718:tid 173854] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/nwflm.php"] [unique_id "amuzfUoi7QGnEa1uk6mv0wAAAAU"]
[Thu Jul 30 15:26:37.486414 2026] [security2:error] [pid 173718:tid 173854] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/nwflm.php"] [unique_id "amuzfUoi7QGnEa1uk6mv0wAAAAU"]
[Thu Jul 30 15:26:37.708208 2026] [core:notice] [pid 173718:tid 173750] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:37.953009 2026] [security2:error] [pid 173718:tid 173972] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/hypo.php"] [unique_id "amuzfUoi7QGnEa1uk6mv3QAAAHs"]
[Thu Jul 30 15:26:37.953125 2026] [security2:error] [pid 173718:tid 173972] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/hypo.php"] [unique_id "amuzfUoi7QGnEa1uk6mv3QAAAHs"]
[Thu Jul 30 15:26:38.032563 2026] [security2:error] [pid 173718:tid 173918] [client 135.119.63.61:8067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file_uploadadmin.php"] [unique_id "amuzfkoi7QGnEa1uk6mv5wAAAEU"]
[Thu Jul 30 15:26:38.349629 2026] [security2:error] [pid 173718:tid 173866] [client 20.63.98.115:61688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/pomo/fgertreyersd.php"] [unique_id "amuzfkoi7QGnEa1uk6mv8wAAABE"]
[Thu Jul 30 15:26:38.419110 2026] [security2:error] [pid 173718:tid 173914] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/w3llscc.php"] [unique_id "amuzfkoi7QGnEa1uk6mv9AAAAEE"]
[Thu Jul 30 15:26:38.419222 2026] [security2:error] [pid 173718:tid 173914] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/w3llscc.php"] [unique_id "amuzfkoi7QGnEa1uk6mv9AAAAEE"]
[Thu Jul 30 15:26:38.434729 2026] [autoindex:error] [pid 173718:tid 173864] [client 66.132.172.182:44638] AH01276: Cannot serve directory /home2/jjpgzjte/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:26:38.655078 2026] [security2:error] [pid 173718:tid 173893] [client 178.20.47.39:55482] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.47.39" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1096"] [id "900925"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amuzfkoi7QGnEa1uk6mwAAAAACw"], referer: https://shorewooddaycare.com/contact.php
[Thu Jul 30 15:26:38.888536 2026] [security2:error] [pid 173718:tid 173879] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuzfkoi7QGnEa1uk6mwBAAAAB4"]
[Thu Jul 30 15:26:38.888628 2026] [security2:error] [pid 173718:tid 173879] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "amuzfkoi7QGnEa1uk6mwBAAAAB4"]
[Thu Jul 30 15:26:38.920706 2026] [security2:error] [pid 173718:tid 173932] [client 4.184.185.91:17109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/82.php"] [unique_id "amuzfkoi7QGnEa1uk6mwBQAAAFM"]
[Thu Jul 30 15:26:38.920815 2026] [security2:error] [pid 173718:tid 173932] [client 4.184.185.91:17109] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/82.php"] [unique_id "amuzfkoi7QGnEa1uk6mwBQAAAFM"]
[Thu Jul 30 15:26:39.137388 2026] [security2:error] [pid 173718:tid 173924] [client 20.63.98.115:48462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/css/xmrlpc.php"] [unique_id "amuzf0oi7QGnEa1uk6mwDAAAAEs"]
[Thu Jul 30 15:26:39.352062 2026] [security2:error] [pid 173718:tid 173875] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/8.php"] [unique_id "amuzf0oi7QGnEa1uk6mwDQAAABo"]
[Thu Jul 30 15:26:39.352176 2026] [security2:error] [pid 173718:tid 173875] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/8.php"] [unique_id "amuzf0oi7QGnEa1uk6mwDQAAABo"]
[Thu Jul 30 15:26:39.514355 2026] [security2:error] [pid 173718:tid 173911] [client 5.161.73.160:22680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuzf0oi7QGnEa1uk6mwDgAAAD4"], referer: https://globalmarks.pk/
[Thu Jul 30 15:26:39.585924 2026] [security2:error] [pid 173718:tid 173889] [client 135.119.63.61:54939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file_uploadalfa.php"] [unique_id "amuzf0oi7QGnEa1uk6mwGAAAACg"]
[Thu Jul 30 15:26:39.772339 2026] [security2:error] [pid 173718:tid 173883] [client 172.213.208.20:18683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wk/index.php"] [unique_id "amuzf0oi7QGnEa1uk6mwHAAAACI"]
[Thu Jul 30 15:26:39.817598 2026] [security2:error] [pid 173718:tid 173901] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/fnstall.php"] [unique_id "amuzf0oi7QGnEa1uk6mwHQAAADQ"]
[Thu Jul 30 15:26:39.817697 2026] [security2:error] [pid 173718:tid 173901] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/fnstall.php"] [unique_id "amuzf0oi7QGnEa1uk6mwHQAAADQ"]
[Thu Jul 30 15:26:39.968848 2026] [core:notice] [pid 173718:tid 173930] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:40.007471 2026] [fcgid:warn] [pid 173718:tid 173922] (70014)End of file found: [client 172.237.109.114:9732] mod_fcgid: can't get data from http client
[Thu Jul 30 15:26:40.283633 2026] [security2:error] [pid 173718:tid 173892] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/edorxrr.php"] [unique_id "amuzgEoi7QGnEa1uk6mwKwAAACs"]
[Thu Jul 30 15:26:40.283783 2026] [security2:error] [pid 173718:tid 173892] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/edorxrr.php"] [unique_id "amuzgEoi7QGnEa1uk6mwKwAAACs"]
[Thu Jul 30 15:26:40.454188 2026] [security2:error] [pid 173718:tid 173856] [client 20.100.187.246:43041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/bootstrap.php"] [unique_id "amuzgEoi7QGnEa1uk6mwMAAAAAc"]
[Thu Jul 30 15:26:40.711218 2026] [security2:error] [pid 173718:tid 173912] [client 135.119.63.61:8096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file_uploadbypass.php"] [unique_id "amuzgEoi7QGnEa1uk6mwOAAAAD8"]
[Thu Jul 30 15:26:40.752039 2026] [security2:error] [pid 173718:tid 173933] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/setup.php"] [unique_id "amuzgEoi7QGnEa1uk6mwOgAAAFQ"]
[Thu Jul 30 15:26:40.752123 2026] [security2:error] [pid 173718:tid 173933] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/setup.php"] [unique_id "amuzgEoi7QGnEa1uk6mwOgAAAFQ"]
[Thu Jul 30 15:26:40.885317 2026] [security2:error] [pid 173718:tid 173903] [client 172.237.109.114:50068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzgEoi7QGnEa1uk6mwKgAAAHE"]
[Thu Jul 30 15:26:40.885344 2026] [security2:error] [pid 173718:tid 173903] [client 172.237.109.114:50068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzgEoi7QGnEa1uk6mwKgAAAHE"]
[Thu Jul 30 15:26:41.094607 2026] [security2:error] [pid 173718:tid 173938] [client 172.213.208.20:54647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/av.php"] [unique_id "amuzgUoi7QGnEa1uk6mwSQAAAFk"]
[Thu Jul 30 15:26:41.205404 2026] [security2:error] [pid 173718:tid 173797] [remote 57.141.0.6:61766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/PBB"] [unique_id "amuzgUoi7QGnEa1uk6mwTwAAYk0"]
[Thu Jul 30 15:26:41.222439 2026] [security2:error] [pid 173718:tid 173886] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/6.php"] [unique_id "amuzgUoi7QGnEa1uk6mwUAAAACU"]
[Thu Jul 30 15:26:41.222582 2026] [security2:error] [pid 173718:tid 173886] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/6.php"] [unique_id "amuzgUoi7QGnEa1uk6mwUAAAACU"]
[Thu Jul 30 15:26:41.547675 2026] [security2:error] [pid 173718:tid 173952] [client 20.100.187.246:37365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/buy.php"] [unique_id "amuzgUoi7QGnEa1uk6mwVQAAAGc"]
[Thu Jul 30 15:26:41.589201 2026] [security2:error] [pid 173718:tid 173951] [client 4.184.185.91:17142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/xstelth.php"] [unique_id "amuzgUoi7QGnEa1uk6mwVgAAAGY"]
[Thu Jul 30 15:26:41.589308 2026] [security2:error] [pid 173718:tid 173951] [client 4.184.185.91:17142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/xstelth.php"] [unique_id "amuzgUoi7QGnEa1uk6mwVgAAAGY"]
[Thu Jul 30 15:26:41.689166 2026] [security2:error] [pid 173718:tid 173883] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/w3lls.php"] [unique_id "amuzgUoi7QGnEa1uk6mwWgAAACI"]
[Thu Jul 30 15:26:41.689266 2026] [security2:error] [pid 173718:tid 173883] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/w3lls.php"] [unique_id "amuzgUoi7QGnEa1uk6mwWgAAACI"]
[Thu Jul 30 15:26:41.728248 2026] [security2:error] [pid 173718:tid 173931] [client 135.119.63.61:8108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.progroupdoha.com"] [uri "/file_uploadk.php"] [unique_id "amuzgUoi7QGnEa1uk6mwXAAAAFI"]
[Thu Jul 30 15:26:41.732439 2026] [core:notice] [pid 173718:tid 173958] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:41.735916 2026] [security2:error] [pid 173718:tid 173958] [client 66.249.79.8:45481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Agroswagati/article/view/837/617"] [unique_id "amuzgUoi7QGnEa1uk6mwXQAAAG0"]
[Thu Jul 30 15:26:41.868740 2026] [security2:error] [pid 173718:tid 173876] [client 74.7.175.166:44862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.durkhanai.ae.ahe.udi.temporary.site"] [uri "/public/robots.txt"] [unique_id "amuzgUoi7QGnEa1uk6mwYQAAG0M"]
[Thu Jul 30 15:26:41.949148 2026] [security2:error] [pid 173718:tid 173975] [client 38.172.162.57:16412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzgUoi7QGnEa1uk6mwYgAAAH4"]
[Thu Jul 30 15:26:41.949273 2026] [security2:error] [pid 173718:tid 173975] [client 38.172.162.57:16412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzgUoi7QGnEa1uk6mwYgAAAH4"]
[Thu Jul 30 15:26:42.012604 2026] [core:notice] [pid 173718:tid 173916] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:42.075160 2026] [proxy:error] [pid 173718:tid 173957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:26:42.075252 2026] [proxy_http:error] [pid 173718:tid 173957] [client 34.233.129.35:43237] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:26:42.076072 2026] [proxy:error] [pid 173718:tid 173957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:26:42.076130 2026] [proxy_http:error] [pid 173718:tid 173957] [client 34.233.129.35:43237] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:26:42.084010 2026] [proxy:error] [pid 173718:tid 173880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:26:42.084073 2026] [proxy_http:error] [pid 173718:tid 173880] [client 34.233.129.35:14646] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:26:42.084682 2026] [proxy:error] [pid 173718:tid 173880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:26:42.084731 2026] [proxy_http:error] [pid 173718:tid 173880] [client 34.233.129.35:14646] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:26:42.105520 2026] [security2:error] [pid 173718:tid 173940] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzgUoi7QGnEa1uk6mwUQAAW04"]
[Thu Jul 30 15:26:42.155059 2026] [security2:error] [pid 173718:tid 173967] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/99.php"] [unique_id "amuzgkoi7QGnEa1uk6mwdwAAAHY"]
[Thu Jul 30 15:26:42.155164 2026] [security2:error] [pid 173718:tid 173967] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/99.php"] [unique_id "amuzgkoi7QGnEa1uk6mwdwAAAHY"]
[Thu Jul 30 15:26:42.184119 2026] [core:notice] [pid 173718:tid 173907] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:42.196397 2026] [core:notice] [pid 173718:tid 173792] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:42.279533 2026] [security2:error] [pid 173718:tid 173969] [client 20.100.187.246:37849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/chosen.php"] [unique_id "amuzgkoi7QGnEa1uk6mwfwAAAHg"]
[Thu Jul 30 15:26:42.336016 2026] [proxy:error] [pid 173718:tid 173928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:26:42.336100 2026] [proxy_http:error] [pid 173718:tid 173928] [client 32.194.121.99:38018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:26:42.336948 2026] [proxy:error] [pid 173718:tid 173928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:26:42.337016 2026] [proxy_http:error] [pid 173718:tid 173928] [client 32.194.121.99:38018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:26:42.382124 2026] [security2:error] [pid 173718:tid 173890] [client 172.213.208.20:27140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/mini.php"] [unique_id "amuzgkoi7QGnEa1uk6mwhAAAACk"]
[Thu Jul 30 15:26:42.624475 2026] [security2:error] [pid 173718:tid 173888] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-content/admin.php"] [unique_id "amuzgkoi7QGnEa1uk6mwjwAAACc"]
[Thu Jul 30 15:26:42.624556 2026] [security2:error] [pid 173718:tid 173888] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-content/admin.php"] [unique_id "amuzgkoi7QGnEa1uk6mwjwAAACc"]
[Thu Jul 30 15:26:42.681708 2026] [core:notice] [pid 173718:tid 173875] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:43.095181 2026] [security2:error] [pid 173718:tid 173958] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/media.php"] [unique_id "amuzg0oi7QGnEa1uk6mwnwAAAG0"]
[Thu Jul 30 15:26:43.095294 2026] [security2:error] [pid 173718:tid 173958] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/media.php"] [unique_id "amuzg0oi7QGnEa1uk6mwnwAAAG0"]
[Thu Jul 30 15:26:43.147328 2026] [core:notice] [pid 173718:tid 173951] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:43.564843 2026] [security2:error] [pid 173718:tid 173887] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuzg0oi7QGnEa1uk6mwrgAAACY"]
[Thu Jul 30 15:26:43.564944 2026] [security2:error] [pid 173718:tid 173887] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amuzg0oi7QGnEa1uk6mwrgAAACY"]
[Thu Jul 30 15:26:43.898100 2026] [security2:error] [pid 173718:tid 173914] [client 74.7.241.143:36984] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "brianhpark.com"] [uri "/cgi-sys/404.html"] [unique_id "amuzg0oi7QGnEa1uk6mwvwAAAEE"]
[Thu Jul 30 15:26:44.039631 2026] [security2:error] [pid 173718:tid 173870] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/222.php"] [unique_id "amuzhEoi7QGnEa1uk6mwxQAAABU"]
[Thu Jul 30 15:26:44.039720 2026] [security2:error] [pid 173718:tid 173870] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/222.php"] [unique_id "amuzhEoi7QGnEa1uk6mwxQAAABU"]
[Thu Jul 30 15:26:44.131456 2026] [security2:error] [pid 173718:tid 173945] [client 20.63.98.115:33602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/classsmtps.php"] [unique_id "amuzhEoi7QGnEa1uk6mwxwAAAGA"]
[Thu Jul 30 15:26:44.179276 2026] [security2:error] [pid 173718:tid 173929] [client 4.184.185.91:17030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/xp.php"] [unique_id "amuzhEoi7QGnEa1uk6mwyAAAAFA"]
[Thu Jul 30 15:26:44.179422 2026] [security2:error] [pid 173718:tid 173929] [client 4.184.185.91:17030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/xp.php"] [unique_id "amuzhEoi7QGnEa1uk6mwyAAAAFA"]
[Thu Jul 30 15:26:44.506549 2026] [security2:error] [pid 173718:tid 173854] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-load.php"] [unique_id "amuzhEoi7QGnEa1uk6mw1QAAAAU"]
[Thu Jul 30 15:26:44.506671 2026] [security2:error] [pid 173718:tid 173854] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-load.php"] [unique_id "amuzhEoi7QGnEa1uk6mw1QAAAAU"]
[Thu Jul 30 15:26:44.584523 2026] [security2:error] [pid 173718:tid 173882] [client 172.213.208.20:13260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/aa.php"] [unique_id "amuzhEoi7QGnEa1uk6mw2QAAACE"]
[Thu Jul 30 15:26:44.784689 2026] [security2:error] [pid 173718:tid 173849] [client 20.100.187.246:31784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/class-wp-image.php"] [unique_id "amuzhEoi7QGnEa1uk6mw3QAAAAA"]
[Thu Jul 30 15:26:44.972047 2026] [security2:error] [pid 173718:tid 173918] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuzhEoi7QGnEa1uk6mw4wAAAEU"]
[Thu Jul 30 15:26:44.972153 2026] [security2:error] [pid 173718:tid 173918] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-content/themes/index.php"] [unique_id "amuzhEoi7QGnEa1uk6mw4wAAAEU"]
[Thu Jul 30 15:26:45.437261 2026] [security2:error] [pid 173718:tid 173968] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuzhUoi7QGnEa1uk6mw9gAAAHc"]
[Thu Jul 30 15:26:45.437384 2026] [security2:error] [pid 173718:tid 173968] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-admin/js/index.php"] [unique_id "amuzhUoi7QGnEa1uk6mw9gAAAHc"]
[Thu Jul 30 15:26:45.618088 2026] [security2:error] [pid 173718:tid 173908] [client 2a03:2880:f800:28:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzhEoi7QGnEa1uk6mw4gAAOwQ"]
[Thu Jul 30 15:26:45.632130 2026] [security2:error] [pid 173718:tid 173852] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzhUoi7QGnEa1uk6mw6wAAAAM"]
[Thu Jul 30 15:26:45.657559 2026] [security2:error] [pid 173718:tid 173928] [client 4.184.185.91:17120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/admin.php"] [unique_id "amuzhUoi7QGnEa1uk6mw_gAAAE8"]
[Thu Jul 30 15:26:45.657658 2026] [security2:error] [pid 173718:tid 173928] [client 4.184.185.91:17120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/admin.php"] [unique_id "amuzhUoi7QGnEa1uk6mw_gAAAE8"]
[Thu Jul 30 15:26:45.905786 2026] [security2:error] [pid 173718:tid 173888] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/memberfuns.php"] [unique_id "amuzhUoi7QGnEa1uk6mxBQAAACc"]
[Thu Jul 30 15:26:45.905890 2026] [security2:error] [pid 173718:tid 173888] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/memberfuns.php"] [unique_id "amuzhUoi7QGnEa1uk6mxBQAAACc"]
[Thu Jul 30 15:26:46.052951 2026] [security2:error] [pid 173718:tid 173861] [client 20.100.187.246:40386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/classsmtps.php"] [unique_id "amuzhkoi7QGnEa1uk6mxBgAAAAw"]
[Thu Jul 30 15:26:46.078169 2026] [core:notice] [pid 173718:tid 173919] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:46.293931 2026] [security2:error] [pid 173718:tid 173949] [client 172.213.208.20:47777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/w.php"] [unique_id "amuzhkoi7QGnEa1uk6mxFAAAAGQ"]
[Thu Jul 30 15:26:46.372706 2026] [security2:error] [pid 173718:tid 173957] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/orange3.php"] [unique_id "amuzhkoi7QGnEa1uk6mxGQAAAGw"]
[Thu Jul 30 15:26:46.372833 2026] [security2:error] [pid 173718:tid 173957] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/orange3.php"] [unique_id "amuzhkoi7QGnEa1uk6mxGQAAAGw"]
[Thu Jul 30 15:26:46.782089 2026] [security2:error] [pid 173718:tid 173865] [client 4.184.185.91:17041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/adminner.php"] [unique_id "amuzhkoi7QGnEa1uk6mxIgAAABA"]
[Thu Jul 30 15:26:46.782245 2026] [security2:error] [pid 173718:tid 173865] [client 4.184.185.91:17041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/adminner.php"] [unique_id "amuzhkoi7QGnEa1uk6mxIgAAABA"]
[Thu Jul 30 15:26:46.840740 2026] [security2:error] [pid 173718:tid 173857] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuzhkoi7QGnEa1uk6mxIwAAAAg"]
[Thu Jul 30 15:26:46.840885 2026] [security2:error] [pid 173718:tid 173857] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amuzhkoi7QGnEa1uk6mxIwAAAAg"]
[Thu Jul 30 15:26:46.895286 2026] [fcgid:warn] [pid 173718:tid 173899] (70014)End of file found: [client 18.218.118.203:52754] mod_fcgid: can't get data from http client
[Thu Jul 30 15:26:46.911370 2026] [security2:error] [pid 173718:tid 173902] [client 74.7.230.15:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.totalwebsite.biz"] [uri "/index.php"] [unique_id "amuzgkoi7QGnEa1uk6mwfgAANWs"]
[Thu Jul 30 15:26:46.911404 2026] [security2:error] [pid 173718:tid 173902] [client 74.7.230.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.totalwebsite.biz"] [uri "/index.php"] [unique_id "amuzgkoi7QGnEa1uk6mwfgAANWs"]
[Thu Jul 30 15:26:47.277313 2026] [security2:error] [pid 173718:tid 173951] [client 20.63.98.115:48467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/themes/zMousse/otuz1.php"] [unique_id "amuzh0oi7QGnEa1uk6mxMAAAAGY"]
[Thu Jul 30 15:26:47.307555 2026] [security2:error] [pid 173718:tid 173970] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/wp-the.php"] [unique_id "amuzh0oi7QGnEa1uk6mxMQAAAHk"]
[Thu Jul 30 15:26:47.307719 2026] [security2:error] [pid 173718:tid 173970] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/wp-the.php"] [unique_id "amuzh0oi7QGnEa1uk6mxMQAAAHk"]
[Thu Jul 30 15:26:47.590866 2026] [security2:error] [pid 173718:tid 173880] [client 172.213.208.20:27141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/admin.php"] [unique_id "amuzh0oi7QGnEa1uk6mxOQAAAB8"]
[Thu Jul 30 15:26:47.772247 2026] [security2:error] [pid 173718:tid 173855] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/crgio.php"] [unique_id "amuzh0oi7QGnEa1uk6mxQQAAAAY"]
[Thu Jul 30 15:26:47.772343 2026] [security2:error] [pid 173718:tid 173855] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/crgio.php"] [unique_id "amuzh0oi7QGnEa1uk6mxQQAAAAY"]
[Thu Jul 30 15:26:48.239183 2026] [security2:error] [pid 173718:tid 173915] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ws13.php"] [unique_id "amuziEoi7QGnEa1uk6mxSwAAAEI"]
[Thu Jul 30 15:26:48.239330 2026] [security2:error] [pid 173718:tid 173915] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ws13.php"] [unique_id "amuziEoi7QGnEa1uk6mxSwAAAEI"]
[Thu Jul 30 15:26:48.250337 2026] [security2:error] [pid 173718:tid 173913] [client 20.63.98.115:26587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/123.php"] [unique_id "amuziEoi7QGnEa1uk6mxTgAAAEA"]
[Thu Jul 30 15:26:48.259485 2026] [security2:error] [pid 173718:tid 173895] [client 57.141.0.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzh0oi7QGnEa1uk6mxPQAAAC4"]
[Thu Jul 30 15:26:48.290591 2026] [security2:error] [pid 173718:tid 173905] [client 4.184.185.91:17127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/a.php"] [unique_id "amuziEoi7QGnEa1uk6mxUAAAADg"]
[Thu Jul 30 15:26:48.290676 2026] [security2:error] [pid 173718:tid 173905] [client 4.184.185.91:17127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/a.php"] [unique_id "amuziEoi7QGnEa1uk6mxUAAAADg"]
[Thu Jul 30 15:26:48.715161 2026] [security2:error] [pid 173718:tid 173898] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/srontol.php"] [unique_id "amuziEoi7QGnEa1uk6mxVwAAADE"]
[Thu Jul 30 15:26:48.715272 2026] [security2:error] [pid 173718:tid 173898] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/srontol.php"] [unique_id "amuziEoi7QGnEa1uk6mxVwAAADE"]
[Thu Jul 30 15:26:49.179633 2026] [security2:error] [pid 173718:tid 173948] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/miru3.php"] [unique_id "amuziUoi7QGnEa1uk6mxZAAAAGM"]
[Thu Jul 30 15:26:49.179773 2026] [security2:error] [pid 173718:tid 173948] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/miru3.php"] [unique_id "amuziUoi7QGnEa1uk6mxZAAAAGM"]
[Thu Jul 30 15:26:49.225092 2026] [security2:error] [pid 173718:tid 173963] [client 4.184.185.91:17150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/k.php"] [unique_id "amuziUoi7QGnEa1uk6mxZQAAAHI"]
[Thu Jul 30 15:26:49.225218 2026] [security2:error] [pid 173718:tid 173963] [client 4.184.185.91:17150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/k.php"] [unique_id "amuziUoi7QGnEa1uk6mxZQAAAHI"]
[Thu Jul 30 15:26:49.368381 2026] [core:notice] [pid 173718:tid 173908] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:49.645404 2026] [security2:error] [pid 173718:tid 173893] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ingfo.php"] [unique_id "amuziUoi7QGnEa1uk6mxcAAAACw"]
[Thu Jul 30 15:26:49.645493 2026] [security2:error] [pid 173718:tid 173893] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ingfo.php"] [unique_id "amuziUoi7QGnEa1uk6mxcAAAACw"]
[Thu Jul 30 15:26:49.659098 2026] [security2:error] [pid 173718:tid 173851] [client 20.100.187.246:41470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/classwithtostring.php"] [unique_id "amuziUoi7QGnEa1uk6mxcQAAAAI"]
[Thu Jul 30 15:26:49.757211 2026] [security2:error] [pid 173718:tid 173944] [client 172.213.208.20:55015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amuziUoi7QGnEa1uk6mxcgAAAF8"]
[Thu Jul 30 15:26:49.910227 2026] [security2:error] [pid 173718:tid 173861] [client 4.184.185.91:17091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/222.php"] [unique_id "amuziUoi7QGnEa1uk6mxdgAAAAw"]
[Thu Jul 30 15:26:49.910330 2026] [security2:error] [pid 173718:tid 173861] [client 4.184.185.91:17091] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/222.php"] [unique_id "amuziUoi7QGnEa1uk6mxdgAAAAw"]
[Thu Jul 30 15:26:50.110846 2026] [security2:error] [pid 173718:tid 173947] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/ey5.php"] [unique_id "amuzikoi7QGnEa1uk6mxfQAAAGI"]
[Thu Jul 30 15:26:50.110993 2026] [security2:error] [pid 173718:tid 173947] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/ey5.php"] [unique_id "amuzikoi7QGnEa1uk6mxfQAAAGI"]
[Thu Jul 30 15:26:50.204998 2026] [security2:error] [pid 173718:tid 173903] [client 20.63.98.115:39492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "amuzikoi7QGnEa1uk6mxfgAAADY"]
[Thu Jul 30 15:26:50.584153 2026] [security2:error] [pid 173718:tid 173937] [client 20.197.178.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.178.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jookreview.com"] [uri "/fine.php"] [unique_id "amuzikoi7QGnEa1uk6mxhgAAAFg"]
[Thu Jul 30 15:26:50.584259 2026] [security2:error] [pid 173718:tid 173937] [client 20.197.178.120:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.jookreview.com"] [uri "/fine.php"] [unique_id "amuzikoi7QGnEa1uk6mxhgAAAFg"]
[Thu Jul 30 15:26:50.717120 2026] [security2:error] [pid 173718:tid 173905] [client 4.184.185.91:17104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/mac.php"] [unique_id "amuzikoi7QGnEa1uk6mxigAAADg"]
[Thu Jul 30 15:26:50.717222 2026] [security2:error] [pid 173718:tid 173905] [client 4.184.185.91:17104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/mac.php"] [unique_id "amuzikoi7QGnEa1uk6mxigAAADg"]
[Thu Jul 30 15:26:51.204451 2026] [security2:error] [pid 173718:tid 173877] [client 127.0.0.1:59834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuzi0oi7QGnEa1uk6mxlwAAABw"]
[Thu Jul 30 15:26:51.204518 2026] [security2:error] [pid 173718:tid 173892] [client 74.7.244.42:57878] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.nfh.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amuzi0oi7QGnEa1uk6mxlgAAKw8"]
[Thu Jul 30 15:26:51.207786 2026] [security2:error] [pid 173718:tid 173874] [client 4.184.185.91:17112] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.hello-pal.com"] [uri "/wp-content/uploads/"] [unique_id "amuzi0oi7QGnEa1uk6mxmAAAABk"]
[Thu Jul 30 15:26:51.207866 2026] [security2:error] [pid 173718:tid 173874] [client 4.184.185.91:17112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.hello-pal.com"] [uri "/wp-content/uploads/"] [unique_id "amuzi0oi7QGnEa1uk6mxmAAAABk"]
[Thu Jul 30 15:26:51.283970 2026] [security2:error] [pid 173718:tid 173920] [client 20.100.187.246:31376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/config.php"] [unique_id "amuzi0oi7QGnEa1uk6mxmQAAAEc"]
[Thu Jul 30 15:26:51.362251 2026] [security2:error] [pid 173718:tid 173975] [client 172.237.109.114:65419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzikoi7QGnEa1uk6mxiwAAAEI"]
[Thu Jul 30 15:26:51.362281 2026] [security2:error] [pid 173718:tid 173975] [client 172.237.109.114:65419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzikoi7QGnEa1uk6mxiwAAAEI"]
[Thu Jul 30 15:26:51.593412 2026] [security2:error] [pid 173718:tid 173936] [client 20.63.98.115:26589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/filebrowser.php"] [unique_id "amuzi0oi7QGnEa1uk6mxowAAAFc"]
[Thu Jul 30 15:26:51.628882 2026] [security2:error] [pid 173718:tid 173948] [client 4.184.185.91:4070] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.hello-pal.com"] [uri "/wp-includes/Text/"] [unique_id "amuzi0oi7QGnEa1uk6mxpAAAAGM"]
[Thu Jul 30 15:26:51.629018 2026] [security2:error] [pid 173718:tid 173948] [client 4.184.185.91:4070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.hello-pal.com"] [uri "/wp-includes/Text/"] [unique_id "amuzi0oi7QGnEa1uk6mxpAAAAGM"]
[Thu Jul 30 15:26:51.936564 2026] [security2:error] [pid 173718:tid 173939] [client 20.100.187.246:40423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/core.php"] [unique_id "amuzi0oi7QGnEa1uk6mxqQAAAFo"]
[Thu Jul 30 15:26:52.321232 2026] [security2:error] [pid 173718:tid 173945] [client 4.184.185.91:17140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/ops.php"] [unique_id "amuzjEoi7QGnEa1uk6mxswAAAGA"]
[Thu Jul 30 15:26:52.321354 2026] [security2:error] [pid 173718:tid 173945] [client 4.184.185.91:17140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/ops.php"] [unique_id "amuzjEoi7QGnEa1uk6mxswAAAGA"]
[Thu Jul 30 15:26:52.357830 2026] [core:notice] [pid 173718:tid 173943] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:52.457134 2026] [security2:error] [pid 173718:tid 173946] [client 74.7.244.9:40720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.tvs.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuzi0oi7QGnEa1uk6mxlQAAYXM"]
[Thu Jul 30 15:26:52.567342 2026] [security2:error] [pid 173718:tid 173852] [client 38.172.162.57:16420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzjEoi7QGnEa1uk6mxvAAAAAM"]
[Thu Jul 30 15:26:52.567484 2026] [security2:error] [pid 173718:tid 173852] [client 38.172.162.57:16420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzjEoi7QGnEa1uk6mxvAAAAAM"]
[Thu Jul 30 15:26:52.610692 2026] [security2:error] [pid 173718:tid 173934] [client 172.213.208.20:27165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/m.php"] [unique_id "amuzjEoi7QGnEa1uk6mxvQAAAFU"]
[Thu Jul 30 15:26:53.260928 2026] [core:notice] [pid 173718:tid 173911] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:53.264428 2026] [security2:error] [pid 173718:tid 173911] [client 66.249.79.229:41547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JNPM/article/view/847"] [unique_id "amuzjUoi7QGnEa1uk6mxzgAAAD4"]
[Thu Jul 30 15:26:53.489802 2026] [core:notice] [pid 173718:tid 173957] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:53.624187 2026] [security2:error] [pid 173718:tid 173923] [client 20.100.187.246:37408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/css.php"] [unique_id "amuzjUoi7QGnEa1uk6mx0wAAAEo"]
[Thu Jul 30 15:26:53.841297 2026] [security2:error] [pid 173718:tid 173906] [client 4.184.185.91:17088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/8.php"] [unique_id "amuzjUoi7QGnEa1uk6mx2gAAADk"]
[Thu Jul 30 15:26:53.841435 2026] [security2:error] [pid 173718:tid 173906] [client 4.184.185.91:17088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/8.php"] [unique_id "amuzjUoi7QGnEa1uk6mx2gAAADk"]
[Thu Jul 30 15:26:54.310659 2026] [security2:error] [pid 173718:tid 173967] [client 20.100.187.246:64217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/database.php"] [unique_id "amuzjkoi7QGnEa1uk6mx7AAAAHY"]
[Thu Jul 30 15:26:54.321381 2026] [security2:error] [pid 173718:tid 173890] [client 172.213.208.20:16374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amuzjkoi7QGnEa1uk6mx4QAAACk"]
[Thu Jul 30 15:26:54.374429 2026] [core:notice] [pid 173718:tid 173867] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:54.473095 2026] [security2:error] [pid 173718:tid 173939] [client 4.184.185.91:17049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/FWAZ.php"] [unique_id "amuzjkoi7QGnEa1uk6mx7wAAAFo"]
[Thu Jul 30 15:26:54.473216 2026] [security2:error] [pid 173718:tid 173939] [client 4.184.185.91:17049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/FWAZ.php"] [unique_id "amuzjkoi7QGnEa1uk6mx7wAAAFo"]
[Thu Jul 30 15:26:54.710512 2026] [core:notice] [pid 173718:tid 173926] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:54.713892 2026] [security2:error] [pid 173718:tid 173926] [client 66.249.79.229:41547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/download/8961/4184"] [unique_id "amuzjkoi7QGnEa1uk6mx9gAAAE0"]
[Thu Jul 30 15:26:55.194053 2026] [security2:error] [pid 173718:tid 173929] [client 4.184.185.91:17031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/biufile.php"] [unique_id "amuzj0oi7QGnEa1uk6mx_gAAAFA"]
[Thu Jul 30 15:26:55.194198 2026] [security2:error] [pid 173718:tid 173929] [client 4.184.185.91:17031] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/biufile.php"] [unique_id "amuzj0oi7QGnEa1uk6mx_gAAAFA"]
[Thu Jul 30 15:26:55.456380 2026] [security2:error] [pid 173718:tid 173880] [client 172.237.109.114:64812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzjkoi7QGnEa1uk6mx-gAAAB8"]
[Thu Jul 30 15:26:55.873401 2026] [core:notice] [pid 173718:tid 173900] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:55.877279 2026] [security2:error] [pid 173718:tid 173900] [client 66.249.79.8:48995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Euclid/article/download/8591/3419"] [unique_id "amuzj0oi7QGnEa1uk6myDgAAADM"]
[Thu Jul 30 15:26:55.897139 2026] [security2:error] [pid 173718:tid 173927] [client 4.184.185.91:17110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/coffexium.php"] [unique_id "amuzj0oi7QGnEa1uk6myDwAAAE4"]
[Thu Jul 30 15:26:55.897241 2026] [security2:error] [pid 173718:tid 173927] [client 4.184.185.91:17110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/coffexium.php"] [unique_id "amuzj0oi7QGnEa1uk6myDwAAAE4"]
[Thu Jul 30 15:26:56.017627 2026] [autoindex:error] [pid 173718:tid 173901] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:26:56.147835 2026] [security2:error] [pid 173718:tid 173957] [client 172.213.208.20:55019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/classwithtostring.php"] [unique_id "amuzkEoi7QGnEa1uk6myEwAAAGw"]
[Thu Jul 30 15:26:56.617578 2026] [security2:error] [pid 173718:tid 173920] [client 4.184.185.91:17149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/simple.php"] [unique_id "amuzkEoi7QGnEa1uk6myIAAAAEc"]
[Thu Jul 30 15:26:56.617707 2026] [security2:error] [pid 173718:tid 173920] [client 4.184.185.91:17149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/simple.php"] [unique_id "amuzkEoi7QGnEa1uk6myIAAAAEc"]
[Thu Jul 30 15:26:56.733161 2026] [security2:error] [pid 173718:tid 173922] [client 20.100.187.246:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/db.php"] [unique_id "amuzkEoi7QGnEa1uk6myJAAAAEk"]
[Thu Jul 30 15:26:56.998575 2026] [core:notice] [pid 173718:tid 173890] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:57.002335 2026] [security2:error] [pid 173718:tid 173890] [client 66.249.79.8:48995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/download/5696/2537"] [unique_id "amuzkEoi7QGnEa1uk6myKwAAACk"]
[Thu Jul 30 15:26:57.449471 2026] [core:notice] [pid 173718:tid 173945] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:57.554997 2026] [security2:error] [pid 173718:tid 173917] [client 20.100.187.246:6431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/default.php"] [unique_id "amuzkUoi7QGnEa1uk6myOQAAAEQ"]
[Thu Jul 30 15:26:57.699175 2026] [security2:error] [pid 173718:tid 173948] [client 20.63.98.115:32234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/makeasmtp.php"] [unique_id "amuzkUoi7QGnEa1uk6myPgAAAGM"]
[Thu Jul 30 15:26:58.044754 2026] [core:notice] [pid 173718:tid 173953] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:58.286929 2026] [core:notice] [pid 173718:tid 173913] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:26:58.601263 2026] [security2:error] [pid 173718:tid 173889] [client 20.63.98.115:39539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/bypass.php"] [unique_id "amuzkkoi7QGnEa1uk6myaQAAACg"]
[Thu Jul 30 15:26:58.955219 2026] [security2:error] [pid 173718:tid 173920] [client 4.184.185.91:17090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/fpwch.php"] [unique_id "amuzkkoi7QGnEa1uk6mydQAAAEc"]
[Thu Jul 30 15:26:58.955319 2026] [security2:error] [pid 173718:tid 173920] [client 4.184.185.91:17090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/fpwch.php"] [unique_id "amuzkkoi7QGnEa1uk6mydQAAAEc"]
[Thu Jul 30 15:26:58.992069 2026] [security2:error] [pid 173718:tid 173888] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzkkoi7QGnEa1uk6myXAAAJ2U"]
[Thu Jul 30 15:26:59.533651 2026] [security2:error] [pid 173718:tid 173963] [client 251.160.199.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amuzkUoi7QGnEa1uk6myLgAAclE"]
[Thu Jul 30 15:26:59.557672 2026] [core:notice] [pid 173718:tid 173721] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:00.112635 2026] [security2:error] [pid 173718:tid 173969] [client 4.184.185.91:17132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/dex.php"] [unique_id "amuzlEoi7QGnEa1uk6mymAAAAHg"]
[Thu Jul 30 15:27:00.112723 2026] [security2:error] [pid 173718:tid 173969] [client 4.184.185.91:17132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/dex.php"] [unique_id "amuzlEoi7QGnEa1uk6mymAAAAHg"]
[Thu Jul 30 15:27:00.507911 2026] [security2:error] [pid 173718:tid 173882] [client 20.100.187.246:37406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/dropdown.php"] [unique_id "amuzlEoi7QGnEa1uk6mypAAAACE"]
[Thu Jul 30 15:27:00.553131 2026] [security2:error] [pid 173718:tid 173910] [client 20.63.98.115:26582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/pi.php"] [unique_id "amuzlEoi7QGnEa1uk6mypQAAAD0"]
[Thu Jul 30 15:27:00.705056 2026] [security2:error] [pid 173718:tid 173743] [remote 57.141.0.3:33334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuzlEoi7QGnEa1uk6myqQAAFxc"]
[Thu Jul 30 15:27:01.075345 2026] [security2:error] [pid 173718:tid 173966] [client 172.213.208.20:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/gmo.php"] [unique_id "amuzlUoi7QGnEa1uk6myuQAAAHU"]
[Thu Jul 30 15:27:01.155241 2026] [core:notice] [pid 173718:tid 173876] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:01.159736 2026] [security2:error] [pid 173718:tid 173876] [client 66.249.79.229:60300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/9266"] [unique_id "amuzlUoi7QGnEa1uk6myugAAABs"]
[Thu Jul 30 15:27:01.169673 2026] [core:notice] [pid 173718:tid 173962] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:01.339469 2026] [security2:error] [pid 173718:tid 173892] [client 20.100.187.246:6450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/edit.php"] [unique_id "amuzlUoi7QGnEa1uk6myvgAAACs"]
[Thu Jul 30 15:27:01.524674 2026] [security2:error] [pid 173718:tid 173899] [client 20.63.98.115:39538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-seo.php"] [unique_id "amuzlUoi7QGnEa1uk6myxQAAADI"]
[Thu Jul 30 15:27:01.554042 2026] [security2:error] [pid 173718:tid 173972] [client 57.141.0.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzlEoi7QGnEa1uk6mysAAAAHs"]
[Thu Jul 30 15:27:01.712510 2026] [security2:error] [pid 173718:tid 173870] [client 82.223.4.24:49378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "journeywomenscenter.org"] [uri "/"] [unique_id "amuzlUoi7QGnEa1uk6myyQAAABU"]
[Thu Jul 30 15:27:01.742972 2026] [security2:error] [pid 173718:tid 173931] [client 172.213.208.20:52248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/languages/index.php"] [unique_id "amuzlUoi7QGnEa1uk6myygAAAFI"]
[Thu Jul 30 15:27:01.841784 2026] [core:notice] [pid 173718:tid 173864] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:01.958767 2026] [security2:error] [pid 173718:tid 173945] [client 20.100.187.246:38170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/f35.php"] [unique_id "amuzlUoi7QGnEa1uk6my1QAAAGA"]
[Thu Jul 30 15:27:02.067417 2026] [security2:error] [pid 173718:tid 173919] [client 217.181.86.63:46286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "deltaedu.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amuzlUoi7QGnEa1uk6my0QAARg0"], referer: https://deltaedu.net/wp-admin/admin-ajax.php?action=tnp&na=s
[Thu Jul 30 15:27:02.067519 2026] [core:notice] [pid 173718:tid 173891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:02.071120 2026] [security2:error] [pid 173718:tid 173891] [client 66.249.79.8:48995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Edunomic/article/view/5812/2751"] [unique_id "amuzlUoi7QGnEa1uk6myywAAACo"]
[Thu Jul 30 15:27:02.342665 2026] [security2:error] [pid 173718:tid 173917] [client 20.63.98.115:48794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/gebase.php69"] [unique_id "amuzlkoi7QGnEa1uk6my2QAAAEQ"]
[Thu Jul 30 15:27:02.682677 2026] [security2:error] [pid 173718:tid 173937] [client 20.100.187.246:64205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabiandubaisafari.com"] [uri "/f7.php"] [unique_id "amuzlkoi7QGnEa1uk6my6QAAAFg"]
[Thu Jul 30 15:27:03.209819 2026] [security2:error] [pid 173718:tid 173882] [client 38.172.162.57:16283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzl0oi7QGnEa1uk6my9QAAACE"]
[Thu Jul 30 15:27:03.209956 2026] [security2:error] [pid 173718:tid 173882] [client 38.172.162.57:16283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzl0oi7QGnEa1uk6my9QAAACE"]
[Thu Jul 30 15:27:03.559318 2026] [security2:error] [pid 173718:tid 173921] [client 252.33.73.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/wp-login.php"] [unique_id "amuzlkoi7QGnEa1uk6my3QAASBY"]
[Thu Jul 30 15:27:04.961540 2026] [security2:error] [pid 173718:tid 173961] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzmEoi7QGnEa1uk6mzEgAAcCw"]
[Thu Jul 30 15:27:05.054764 2026] [security2:error] [pid 173718:tid 173949] [client 4.184.185.91:17026] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.hello-pal.com"] [uri "/1.php"] [unique_id "amuzmUoi7QGnEa1uk6mzJQAAAGQ"]
[Thu Jul 30 15:27:05.054892 2026] [security2:error] [pid 173718:tid 173949] [client 4.184.185.91:17026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hello-pal.com"] [uri "/1.php"] [unique_id "amuzmUoi7QGnEa1uk6mzJQAAAGQ"]
[Thu Jul 30 15:27:05.055014 2026] [security2:error] [pid 173718:tid 173949] [client 4.184.185.91:17026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.hello-pal.com"] [uri "/1.php"] [unique_id "amuzmUoi7QGnEa1uk6mzJQAAAGQ"]
[Thu Jul 30 15:27:05.147461 2026] [security2:error] [pid 173718:tid 173973] [client 172.213.208.20:13279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-the.php"] [unique_id "amuzmUoi7QGnEa1uk6mzLAAAAHw"]
[Thu Jul 30 15:27:05.266667 2026] [security2:error] [pid 173718:tid 173875] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzmEoi7QGnEa1uk6mzIAAAABo"]
[Thu Jul 30 15:27:05.508968 2026] [security2:error] [pid 173718:tid 173793] [remote 57.141.0.1:45442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amuzmUoi7QGnEa1uk6mzMQAACUk"]
[Thu Jul 30 15:27:05.545044 2026] [fcgid:warn] [pid 173718:tid 173882] (70014)End of file found: [client 172.237.109.114:61779] mod_fcgid: can't get data from http client
[Thu Jul 30 15:27:05.747721 2026] [security2:error] [pid 173718:tid 173916] [client 34.24.89.36:55668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "smtp.hmhs.ph"] [uri "/index.cgi"] [unique_id "amuzmUoi7QGnEa1uk6mzOwAAAEM"]
[Thu Jul 30 15:27:06.392463 2026] [security2:error] [pid 173718:tid 173951] [client 43.173.180.131:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/01/29/collection-zara-printemps-2015/"] [unique_id "amuzmkoi7QGnEa1uk6mzTAAAAGY"]
[Thu Jul 30 15:27:06.402632 2026] [security2:error] [pid 173718:tid 173922] [client 172.237.109.114:35541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzmUoi7QGnEa1uk6mzPgAAABk"]
[Thu Jul 30 15:27:06.402663 2026] [security2:error] [pid 173718:tid 173922] [client 172.237.109.114:35541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzmUoi7QGnEa1uk6mzPgAAABk"]
[Thu Jul 30 15:27:06.522843 2026] [security2:error] [pid 173718:tid 173866] [client 57.141.0.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzmUoi7QGnEa1uk6mzQQAAABE"]
[Thu Jul 30 15:27:07.169596 2026] [core:notice] [pid 173718:tid 173883] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:07.175530 2026] [security2:error] [pid 173718:tid 173883] [client 43.173.175.69:34772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2015/01/29/collection-zara-printemps-2015/"] [unique_id "amuzm0oi7QGnEa1uk6mzWwAAACI"], referer: https://carnetdeshopping.com/index.php/2015/01/29/collection-zara-printemps-2015/?replytocom=1422
[Thu Jul 30 15:27:07.270383 2026] [security2:error] [pid 173718:tid 173783] [remote 209.42.28.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.28.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mskabir.com"] [uri "/wp-login.php"] [unique_id "amuzm0oi7QGnEa1uk6mzXwAAfD8"]
[Thu Jul 30 15:27:07.318540 2026] [security2:error] [pid 173718:tid 173881] [client 172.213.208.20:53552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/404.php"] [unique_id "amuzm0oi7QGnEa1uk6mzYwAAACA"]
[Thu Jul 30 15:27:07.789991 2026] [security2:error] [pid 173718:tid 173904] [client 74.7.228.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-34347cea.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amuzm0oi7QGnEa1uk6mzbAAAADc"]
[Thu Jul 30 15:27:07.790700 2026] [security2:error] [pid 173718:tid 173946] [client 74.7.228.3:38482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-34347cea.glb.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amuzm0oi7QGnEa1uk6mzaQAAYVc"]
[Thu Jul 30 15:27:08.660271 2026] [security2:error] [pid 173718:tid 173972] [client 85.208.96.206:38574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/10/22/flow-tarcisio-diz-que-esta-sentindo-virada-para-bolsonaro-nas-ruas/"] [unique_id "amuznEoi7QGnEa1uk6mzhwAAAHs"]
[Thu Jul 30 15:27:08.660438 2026] [security2:error] [pid 173718:tid 173972] [client 85.208.96.206:38574] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/10/22/flow-tarcisio-diz-que-esta-sentindo-virada-para-bolsonaro-nas-ruas/"] [unique_id "amuznEoi7QGnEa1uk6mzhwAAAHs"]
[Thu Jul 30 15:27:08.881499 2026] [security2:error] [pid 173718:tid 173976] [client 74.7.230.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "embassyofbelgiumislamabad.cc"] [uri "/index.php"] [unique_id "amuznEoi7QGnEa1uk6mziAAAfzo"]
[Thu Jul 30 15:27:09.170692 2026] [security2:error] [pid 173718:tid 173967] [client 20.63.98.115:39521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/config.php"] [unique_id "amuznUoi7QGnEa1uk6mzlgAAAHY"]
[Thu Jul 30 15:27:09.178184 2026] [core:notice] [pid 173718:tid 173938] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:09.182181 2026] [security2:error] [pid 173718:tid 173938] [client 66.249.79.8:54091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/PBB/article/download/7406/2962"] [unique_id "amuznUoi7QGnEa1uk6mzlwAAAFk"]
[Thu Jul 30 15:27:09.260601 2026] [security2:error] [pid 173718:tid 173863] [client 172.213.208.20:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/init.php"] [unique_id "amuznUoi7QGnEa1uk6mzmwAAAA4"]
[Thu Jul 30 15:27:09.376240 2026] [security2:error] [pid 173718:tid 173823] [remote 57.141.0.49:24952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/53909108632/feed/rss2/"] [unique_id "amuznUoi7QGnEa1uk6mzngAATGc"]
[Thu Jul 30 15:27:09.402868 2026] [core:notice] [pid 173718:tid 173900] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:09.433006 2026] [security2:error] [pid 173718:tid 173950] [client 57.141.0.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuznEoi7QGnEa1uk6mzjwAAAGU"]
[Thu Jul 30 15:27:09.572441 2026] [core:notice] [pid 173718:tid 173832] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:09.850963 2026] [core:notice] [pid 173718:tid 173912] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:09.854412 2026] [security2:error] [pid 173718:tid 173912] [client 66.249.79.8:54091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/2030"] [unique_id "amuznUoi7QGnEa1uk6mzswAAAD8"]
[Thu Jul 30 15:27:09.951975 2026] [security2:error] [pid 173718:tid 173849] [client 172.213.208.20:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/file5.php"] [unique_id "amuznUoi7QGnEa1uk6mztwAAAAA"]
[Thu Jul 30 15:27:10.069422 2026] [core:notice] [pid 173718:tid 173819] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:10.795863 2026] [security2:error] [pid 173718:tid 173958] [client 172.213.208.20:20944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amuznkoi7QGnEa1uk6mz0QAAAG0"]
[Thu Jul 30 15:27:10.809046 2026] [core:notice] [pid 173718:tid 173951] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:10.970603 2026] [core:notice] [pid 173718:tid 173724] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:11.132815 2026] [security2:error] [pid 173718:tid 173864] [client 20.63.98.115:39498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ws.php"] [unique_id "amuzn0oi7QGnEa1uk6mz3QAAAA8"]
[Thu Jul 30 15:27:11.350497 2026] [core:notice] [pid 173718:tid 173845] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:11.543457 2026] [core:notice] [pid 173718:tid 173965] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:11.645161 2026] [security2:error] [pid 173718:tid 173880] [client 164.90.219.219:58607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "lxw.gpl.temporary.site"] [uri "/wp-json/batch/v1"] [unique_id "amuzn0oi7QGnEa1uk6mz6QAAAB8"]
[Thu Jul 30 15:27:11.929419 2026] [security2:error] [pid 173718:tid 173896] [client 164.90.219.219:58617] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "lxw.gpl.temporary.site"] [uri "/"] [unique_id "amuzn0oi7QGnEa1uk6mz7gAAAC8"]
[Thu Jul 30 15:27:12.039166 2026] [security2:error] [pid 173718:tid 173900] [client 172.213.208.20:55021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/shell.php"] [unique_id "amuzoEoi7QGnEa1uk6mz8QAAADM"]
[Thu Jul 30 15:27:12.169190 2026] [security2:error] [pid 173718:tid 173727] [remote 47.128.27.57:64440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/gg-suit-jacket-brown/"] [unique_id "amuzoEoi7QGnEa1uk6mz9gAAEAc"]
[Thu Jul 30 15:27:12.214183 2026] [core:notice] [pid 173718:tid 173743] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:12.215901 2026] [security2:error] [pid 173718:tid 173946] [client 164.90.219.219:58623] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "lxw.gpl.temporary.site"] [uri "/wp-json/batch/v1"] [unique_id "amuzoEoi7QGnEa1uk6mz-AAAAGE"]
[Thu Jul 30 15:27:12.531179 2026] [security2:error] [pid 173718:tid 173887] [client 20.63.98.115:48477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/admin/function.php"] [unique_id "amuzoEoi7QGnEa1uk6m0AAAAACY"]
[Thu Jul 30 15:27:12.579881 2026] [core:notice] [pid 173718:tid 173739] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:12.662098 2026] [security2:error] [pid 173718:tid 173942] [client 172.213.208.20:27160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/f35.php"] [unique_id "amuzoEoi7QGnEa1uk6m0BQAAAF0"]
[Thu Jul 30 15:27:12.770368 2026] [core:notice] [pid 173718:tid 173957] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:13.154345 2026] [security2:error] [pid 173718:tid 173851] [client 172.213.208.20:52271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/new.php"] [unique_id "amuzoUoi7QGnEa1uk6m0DgAAAAI"]
[Thu Jul 30 15:27:13.378840 2026] [core:notice] [pid 173718:tid 173738] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:13.647338 2026] [security2:error] [pid 173718:tid 173733] [remote 57.141.0.5:54372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuzoUoi7QGnEa1uk6m0GgAAYw0"]
[Thu Jul 30 15:27:13.687889 2026] [proxy:error] [pid 173718:tid 173886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:13.687996 2026] [proxy_http:error] [pid 173718:tid 173886] [client 45.92.87.87:36653] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:13.688671 2026] [proxy:error] [pid 173718:tid 173886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:13.688721 2026] [proxy_http:error] [pid 173718:tid 173886] [client 45.92.87.87:36653] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:13.739505 2026] [core:notice] [pid 173718:tid 173844] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:13.756015 2026] [security2:error] [pid 173718:tid 173868] [client 172.213.208.20:13283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/adminfuns.php"] [unique_id "amuzoUoi7QGnEa1uk6m0HwAAABM"]
[Thu Jul 30 15:27:13.758697 2026] [security2:error] [pid 173718:tid 173945] [client 38.172.162.57:16460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzoUoi7QGnEa1uk6m0IQAAAGA"]
[Thu Jul 30 15:27:13.758781 2026] [security2:error] [pid 173718:tid 173945] [client 38.172.162.57:16460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzoUoi7QGnEa1uk6m0IQAAAGA"]
[Thu Jul 30 15:27:13.881734 2026] [security2:error] [pid 173718:tid 173866] [client 20.40.58.237:54438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.kendarikomputer.com"] [uri "/wp-json/wp/v2/posts"] [unique_id "amuzoUoi7QGnEa1uk6m0JgAAABE"]
[Thu Jul 30 15:27:13.924368 2026] [core:notice] [pid 173718:tid 173880] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:13.927989 2026] [security2:error] [pid 173718:tid 173880] [client 66.249.79.8:54091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/REFORMASI/article/view/1449/2977"] [unique_id "amuzoUoi7QGnEa1uk6m0JwAAAB8"]
[Thu Jul 30 15:27:14.121701 2026] [proxy:error] [pid 173718:tid 173975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:14.121779 2026] [proxy_http:error] [pid 173718:tid 173975] [client 45.92.87.87:38925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:14.122356 2026] [proxy:error] [pid 173718:tid 173975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:14.122409 2026] [proxy_http:error] [pid 173718:tid 173975] [client 45.92.87.87:38925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:14.519857 2026] [core:notice] [pid 173718:tid 173759] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:14.717731 2026] [core:notice] [pid 173718:tid 173758] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:14.988816 2026] [proxy:error] [pid 173718:tid 173936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:14.988871 2026] [proxy_http:error] [pid 173718:tid 173936] [client 45.92.85.193:42953] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:14.989447 2026] [proxy:error] [pid 173718:tid 173936] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:14.989493 2026] [proxy_http:error] [pid 173718:tid 173936] [client 45.92.85.193:42953] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:15.309056 2026] [security2:error] [pid 173718:tid 173734] [remote 57.141.0.59:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amuzo0oi7QGnEa1uk6m0TgAAbQ4"]
[Thu Jul 30 15:27:15.722434 2026] [security2:error] [pid 173718:tid 173870] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzo0oi7QGnEa1uk6m0RwAAABU"]
[Thu Jul 30 15:27:15.960143 2026] [proxy:error] [pid 173718:tid 173917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:15.960229 2026] [proxy_http:error] [pid 173718:tid 173917] [client 45.92.85.193:37095] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:15.960952 2026] [proxy:error] [pid 173718:tid 173917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:15.961033 2026] [proxy_http:error] [pid 173718:tid 173917] [client 45.92.85.193:37095] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:15.999081 2026] [security2:error] [pid 173718:tid 173852] [client 20.63.98.115:48480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "amuzo0oi7QGnEa1uk6m0XAAAAAM"]
[Thu Jul 30 15:27:16.835769 2026] [security2:error] [pid 173718:tid 173940] [client 172.237.109.114:39721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzpEoi7QGnEa1uk6m0ZAAAABE"]
[Thu Jul 30 15:27:16.835807 2026] [security2:error] [pid 173718:tid 173940] [client 172.237.109.114:39721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzpEoi7QGnEa1uk6m0ZAAAABE"]
[Thu Jul 30 15:27:16.882959 2026] [security2:error] [pid 173718:tid 173857] [client 20.63.98.115:32221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/themes/about.php"] [unique_id "amuzpEoi7QGnEa1uk6m0cQAAAAg"]
[Thu Jul 30 15:27:16.995659 2026] [core:notice] [pid 173718:tid 173873] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:17.226948 2026] [core:notice] [pid 173718:tid 173849] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:17.532962 2026] [core:notice] [pid 173718:tid 173779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:17.735569 2026] [core:notice] [pid 173718:tid 173932] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:17.750915 2026] [security2:error] [pid 173718:tid 173973] [client 20.63.98.115:42561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/pomo/about.php"] [unique_id "amuzpUoi7QGnEa1uk6m0hAAAAHw"]
[Thu Jul 30 15:27:18.180932 2026] [core:notice] [pid 173718:tid 173864] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:18.427614 2026] [security2:error] [pid 173718:tid 173861] [client 139.28.219.70:51874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuzpkoi7QGnEa1uk6m0mQAAAAw"]
[Thu Jul 30 15:27:18.713412 2026] [security2:error] [pid 173718:tid 173880] [client 139.28.219.70:51884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "9o0.me"] [uri "/xmlrpc.php"] [unique_id "amuzpkoi7QGnEa1uk6m0oAAAAB8"]
[Thu Jul 30 15:27:18.894627 2026] [core:notice] [pid 173718:tid 173881] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:18.966906 2026] [core:error] [pid 173718:tid 173791] [remote 216.73.216.207:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:27:18.966929 2026] [core:error] [pid 173718:tid 173791] [remote 216.73.216.207:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:27:18.970396 2026] [security2:error] [pid 173718:tid 173900] [client 139.28.219.70:51900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuzpkoi7QGnEa1uk6m0qwAAADM"]
[Thu Jul 30 15:27:19.114705 2026] [security2:error] [pid 173718:tid 173937] [client 77.83.36.161:20820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuzpkoi7QGnEa1uk6m0pQAAAFg"]
[Thu Jul 30 15:27:19.238008 2026] [security2:error] [pid 173718:tid 173906] [client 139.28.219.70:51914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amuzp0oi7QGnEa1uk6m0tQAAADk"]
[Thu Jul 30 15:27:19.506952 2026] [security2:error] [pid 173718:tid 173892] [client 139.28.219.70:51922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuzp0oi7QGnEa1uk6m0vQAAACs"]
[Thu Jul 30 15:27:19.520060 2026] [security2:error] [pid 173718:tid 173975] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzpkoi7QGnEa1uk6m0qQAAAH4"]
[Thu Jul 30 15:27:19.679155 2026] [security2:error] [pid 173718:tid 173903] [client 77.83.36.161:21273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuzp0oi7QGnEa1uk6m0vgAAADY"]
[Thu Jul 30 15:27:19.774485 2026] [security2:error] [pid 173718:tid 173922] [client 139.28.219.70:51932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuzp0oi7QGnEa1uk6m0xAAAAEk"]
[Thu Jul 30 15:27:19.942040 2026] [autoindex:error] [pid 173718:tid 173973] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:27:20.044596 2026] [security2:error] [pid 173718:tid 173951] [client 139.28.219.70:51946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuzqEoi7QGnEa1uk6m0ywAAAGY"]
[Thu Jul 30 15:27:20.072129 2026] [security2:error] [pid 173718:tid 173976] [client 172.213.208.20:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/fm.php"] [unique_id "amuzqEoi7QGnEa1uk6m0zAAAAH8"]
[Thu Jul 30 15:27:20.118623 2026] [security2:error] [pid 173718:tid 173920] [client 20.63.98.115:52118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/uploads/2024/index.php"] [unique_id "amuzqEoi7QGnEa1uk6m00AAAAEc"]
[Thu Jul 30 15:27:20.238971 2026] [security2:error] [pid 173718:tid 173974] [client 77.83.36.161:21553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/administrator/index.php"] [unique_id "amuzqEoi7QGnEa1uk6m01QAAAH0"]
[Thu Jul 30 15:27:20.315753 2026] [security2:error] [pid 173718:tid 173948] [client 139.28.219.70:51958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amuzqEoi7QGnEa1uk6m01gAAAGM"]
[Thu Jul 30 15:27:20.584185 2026] [security2:error] [pid 173718:tid 173901] [client 139.28.219.70:56518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuzqEoi7QGnEa1uk6m02wAAADQ"]
[Thu Jul 30 15:27:20.858123 2026] [security2:error] [pid 173718:tid 173883] [client 139.28.219.70:56534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuzqEoi7QGnEa1uk6m04QAAACI"]
[Thu Jul 30 15:27:21.122477 2026] [security2:error] [pid 173718:tid 173889] [client 139.28.219.70:56540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuzqUoi7QGnEa1uk6m06AAAACg"]
[Thu Jul 30 15:27:21.390419 2026] [security2:error] [pid 173718:tid 173896] [client 139.28.219.70:56546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuzqUoi7QGnEa1uk6m07QAAAC8"]
[Thu Jul 30 15:27:21.650048 2026] [security2:error] [pid 173718:tid 173946] [client 139.28.219.70:56552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuzqUoi7QGnEa1uk6m09QAAAGE"]
[Thu Jul 30 15:27:21.727383 2026] [core:notice] [pid 173718:tid 173786] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:21.731243 2026] [security2:error] [pid 173718:tid 173885] [client 66.249.74.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/83/86"] [unique_id "amuzqUoi7QGnEa1uk6m07gAAJEI"]
[Thu Jul 30 15:27:21.805140 2026] [security2:error] [pid 173718:tid 173928] [client 20.63.98.115:42603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/.well-known/cong.php"] [unique_id "amuzqUoi7QGnEa1uk6m09gAAAE8"]
[Thu Jul 30 15:27:21.927830 2026] [security2:error] [pid 173718:tid 173975] [client 139.28.219.70:56566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuzqUoi7QGnEa1uk6m0_wAAAH4"]
[Thu Jul 30 15:27:22.212907 2026] [security2:error] [pid 173718:tid 173867] [client 139.28.219.70:56574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuzqkoi7QGnEa1uk6m1BgAAABI"]
[Thu Jul 30 15:27:22.315643 2026] [security2:error] [pid 173718:tid 173894] [client 134.19.179.139:53252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuzqkoi7QGnEa1uk6m1BwAAAC0"]
[Thu Jul 30 15:27:22.315758 2026] [security2:error] [pid 173718:tid 173894] [client 134.19.179.139:53252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amuzqkoi7QGnEa1uk6m1BwAAAC0"]
[Thu Jul 30 15:27:22.473007 2026] [security2:error] [pid 173718:tid 173851] [client 139.28.219.70:56590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "9o0.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuzqkoi7QGnEa1uk6m1DwAAAAI"]
[Thu Jul 30 15:27:22.690539 2026] [security2:error] [pid 173718:tid 173954] [client 172.213.208.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuzqUoi7QGnEa1uk6m0_AAAAGk"]
[Thu Jul 30 15:27:23.109399 2026] [security2:error] [pid 173718:tid 173925] [client 172.213.208.20:51161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/file.php"] [unique_id "amuzq0oi7QGnEa1uk6m1IQAAAEw"]
[Thu Jul 30 15:27:23.198058 2026] [core:notice] [pid 173718:tid 173945] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:23.723297 2026] [autoindex:error] [pid 173718:tid 173924] [client 172.213.208.20:55386] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:27:23.725447 2026] [security2:error] [pid 173718:tid 173857] [client 110.249.202.91:33280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiandubaisafari.com"] [uri "/safari-city-marina-dhow.html"] [unique_id "amuzq0oi7QGnEa1uk6m1MQAAAAg"]
[Thu Jul 30 15:27:23.854933 2026] [security2:error] [pid 173718:tid 173968] [client 172.213.208.20:55386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/bolt.php"] [unique_id "amuzq0oi7QGnEa1uk6m1MwAAAHc"]
[Thu Jul 30 15:27:24.379509 2026] [security2:error] [pid 173718:tid 173888] [client 38.172.162.57:15935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzrEoi7QGnEa1uk6m1QQAAACc"]
[Thu Jul 30 15:27:24.379617 2026] [security2:error] [pid 173718:tid 173888] [client 38.172.162.57:15935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzrEoi7QGnEa1uk6m1QQAAACc"]
[Thu Jul 30 15:27:24.660600 2026] [security2:error] [pid 173718:tid 173874] [client 172.213.208.20:51148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/3.php"] [unique_id "amuzrEoi7QGnEa1uk6m1SQAAABk"]
[Thu Jul 30 15:27:24.757582 2026] [security2:error] [pid 173718:tid 173965] [client 20.63.98.115:42592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/languages/about.php"] [unique_id "amuzrEoi7QGnEa1uk6m1TwAAAHQ"]
[Thu Jul 30 15:27:24.904289 2026] [security2:error] [pid 173718:tid 173972] [client 74.7.227.19:39452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.durkhanai.ae.ahe.udi.temporary.site"] [uri "/public/index.php"] [unique_id "amuzrEoi7QGnEa1uk6m1UAAAe34"], referer: https://www.durkhanai.ae.ahe.udi.temporary.site/build/assets/app-BcoCxAYs.js
[Thu Jul 30 15:27:25.368532 2026] [security2:error] [pid 173718:tid 173954] [client 172.213.208.20:47814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/222.php"] [unique_id "amuzrUoi7QGnEa1uk6m1XAAAAGk"]
[Thu Jul 30 15:27:25.422670 2026] [security2:error] [pid 173718:tid 173949] [client 74.7.227.19:39452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.durkhanai.ae.ahe.udi.temporary.site"] [uri "/public/index.php"] [unique_id "amuzrUoi7QGnEa1uk6m1WwAAZFE"], referer: https://www.durkhanai.ae.ahe.udi.temporary.site/build/assets/app-BcoCxAYs.js
[Thu Jul 30 15:27:25.995893 2026] [core:notice] [pid 173718:tid 173930] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:26.376769 2026] [security2:error] [pid 173718:tid 173766] [remote 74.7.243.224:34176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/job.php"] [unique_id "amuzrkoi7QGnEa1uk6m1pAAAHi4"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 15:27:26.478017 2026] [security2:error] [pid 173718:tid 173956] [client 20.63.98.115:25839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/edit.php"] [unique_id "amuzrkoi7QGnEa1uk6m1pgAAAGs"]
[Thu Jul 30 15:27:26.585546 2026] [security2:error] [pid 173718:tid 173779] [remote 104.210.56.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.56.210.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/188"] [unique_id "amuzrkoi7QGnEa1uk6m1rQAAejs"]
[Thu Jul 30 15:27:26.732908 2026] [security2:error] [pid 173718:tid 173936] [client 172.213.208.20:55150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amuzrkoi7QGnEa1uk6m1rgAAAFc"]
[Thu Jul 30 15:27:27.157420 2026] [core:notice] [pid 173718:tid 173942] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:27.161899 2026] [security2:error] [pid 173718:tid 173942] [client 66.249.79.230:64091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/496/3588"] [unique_id "amuzrkoi7QGnEa1uk6m1tgAAAF0"]
[Thu Jul 30 15:27:27.382470 2026] [core:notice] [pid 173718:tid 173891] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:27.386519 2026] [security2:error] [pid 173718:tid 173891] [client 66.249.79.8:39341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jka/article/view/1747"] [unique_id "amuzr0oi7QGnEa1uk6m1wAAAACo"]
[Thu Jul 30 15:27:27.762708 2026] [security2:error] [pid 173718:tid 173871] [client 20.63.98.115:22195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/about/function.php"] [unique_id "amuzr0oi7QGnEa1uk6m1yQAAABY"]
[Thu Jul 30 15:27:28.340113 2026] [security2:error] [pid 173718:tid 173877] [client 172.213.208.20:55370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amuzsEoi7QGnEa1uk6m13QAAABw"]
[Thu Jul 30 15:27:28.358937 2026] [core:notice] [pid 173718:tid 173952] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:28.371748 2026] [core:error] [pid 173718:tid 173952] [client 66.249.79.229:38609] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:27:28.371929 2026] [security2:error] [pid 173718:tid 173952] [client 66.249.79.229:38609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/8460/3292.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuzsEoi7QGnEa1uk6m13gAAAGc"]
[Thu Jul 30 15:27:28.593458 2026] [core:notice] [pid 173718:tid 173879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:28.604182 2026] [security2:error] [pid 173718:tid 173950] [client 172.237.109.114:52008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuzsEoi7QGnEa1uk6m10AAAAGU"]
[Thu Jul 30 15:27:29.008021 2026] [security2:error] [pid 173718:tid 173797] [remote 216.73.216.51:19654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amuzsUoi7QGnEa1uk6m17gAAfk0"]
[Thu Jul 30 15:27:29.325004 2026] [security2:error] [pid 173718:tid 173957] [client 20.63.98.115:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/simple/function.php"] [unique_id "amuzsUoi7QGnEa1uk6m19QAAAGw"]
[Thu Jul 30 15:27:29.924894 2026] [security2:error] [pid 173718:tid 173932] [client 134.19.179.139:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuzsUoi7QGnEa1uk6m2AAAAAFM"]
[Thu Jul 30 15:27:29.925021 2026] [security2:error] [pid 173718:tid 173932] [client 134.19.179.139:58900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuzsUoi7QGnEa1uk6m2AAAAAFM"]
[Thu Jul 30 15:27:30.647869 2026] [core:notice] [pid 173718:tid 173959] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:30.915902 2026] [security2:error] [pid 173718:tid 173831] [remote 40.77.167.241:64920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/perspective/article/download/4210/2146"] [unique_id "amuzskoi7QGnEa1uk6m2HQAABW8"]
[Thu Jul 30 15:27:30.927389 2026] [autoindex:error] [pid 173718:tid 173881] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:27:30.932433 2026] [core:notice] [pid 173718:tid 173911] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:30.935701 2026] [security2:error] [pid 173718:tid 173911] [client 66.249.79.229:38629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/ELTERA/article/view/1984/1240"] [unique_id "amuzskoi7QGnEa1uk6m2FQAAAD4"]
[Thu Jul 30 15:27:31.057638 2026] [security2:error] [pid 173718:tid 173966] [client 172.213.208.20:47822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/admin.php"] [unique_id "amuzs0oi7QGnEa1uk6m2IQAAAHU"]
[Thu Jul 30 15:27:31.539421 2026] [security2:error] [pid 173718:tid 173872] [client 57.141.0.9:31134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amuzs0oi7QGnEa1uk6m2JgAAF2k"], referer: https://igetvape-australia.com/product/iget-bar-pro-blueberry-ice/
[Thu Jul 30 15:27:31.830803 2026] [security2:error] [pid 173718:tid 173915] [client 172.213.208.20:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-configs.php"] [unique_id "amuzs0oi7QGnEa1uk6m2NgAAAEI"]
[Thu Jul 30 15:27:31.868996 2026] [core:notice] [pid 173718:tid 173869] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:32.088030 2026] [security2:error] [pid 173718:tid 173942] [client 20.63.98.115:22172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/mah/function.php"] [unique_id "amuztEoi7QGnEa1uk6m2PwAAAF0"]
[Thu Jul 30 15:27:32.639338 2026] [security2:error] [pid 173718:tid 173961] [client 34.45.155.146:50334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "shop-peace.com"] [uri "/"] [unique_id "amuztEoi7QGnEa1uk6m2TgAAAHA"]
[Thu Jul 30 15:27:33.189623 2026] [security2:error] [pid 173718:tid 173852] [client 20.63.98.115:22178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/go.php"] [unique_id "amuztUoi7QGnEa1uk6m2WAAAAAM"]
[Thu Jul 30 15:27:33.383233 2026] [security2:error] [pid 173718:tid 173904] [client 43.157.22.109:55336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.22.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/board.php"] [unique_id "amuztUoi7QGnEa1uk6m2XAAAADc"]
[Thu Jul 30 15:27:33.974400 2026] [security2:error] [pid 173718:tid 173934] [client 172.213.208.20:55105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/php.php"] [unique_id "amuztUoi7QGnEa1uk6m2bAAAAFU"]
[Thu Jul 30 15:27:34.412935 2026] [core:notice] [pid 173718:tid 173957] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:34.416252 2026] [security2:error] [pid 173718:tid 173957] [client 66.249.79.229:38629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/HERMENEUTIKA/article/view/3271"] [unique_id "amuztkoi7QGnEa1uk6m2dAAAAGw"]
[Thu Jul 30 15:27:34.440944 2026] [security2:error] [pid 173718:tid 173892] [client 172.213.208.20:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/index.php"] [unique_id "amuztkoi7QGnEa1uk6m2dQAAACs"]
[Thu Jul 30 15:27:34.701866 2026] [security2:error] [pid 173718:tid 173933] [client 20.63.98.115:25788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/buy.php"] [unique_id "amuztkoi7QGnEa1uk6m2fAAAAFQ"]
[Thu Jul 30 15:27:34.784142 2026] [core:notice] [pid 173718:tid 173724] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:34.990641 2026] [security2:error] [pid 173718:tid 173862] [client 38.172.162.57:16161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuztkoi7QGnEa1uk6m2hQAAAA0"]
[Thu Jul 30 15:27:34.990744 2026] [security2:error] [pid 173718:tid 173862] [client 38.172.162.57:16161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuztkoi7QGnEa1uk6m2hQAAAA0"]
[Thu Jul 30 15:27:35.603894 2026] [security2:error] [pid 173718:tid 173808] [remote 57.141.0.20:37728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/7374488921/feed/rss2/"] [unique_id "amuzt0oi7QGnEa1uk6m2mAAAdlg"]
[Thu Jul 30 15:27:36.139307 2026] [security2:error] [pid 173718:tid 173919] [client 2a03:2880:f800:16:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuzt0oi7QGnEa1uk6m2lwAARgI"]
[Thu Jul 30 15:27:36.477455 2026] [security2:error] [pid 173718:tid 173956] [client 204.8.98.55:46700] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzuEoi7QGnEa1uk6m2pQAAAGs"]
[Thu Jul 30 15:27:36.477560 2026] [security2:error] [pid 173718:tid 173956] [client 204.8.98.55:46700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzuEoi7QGnEa1uk6m2pQAAAGs"]
[Thu Jul 30 15:27:36.705354 2026] [security2:error] [pid 173718:tid 173928] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amuzuEoi7QGnEa1uk6m2pAAAAE8"]
[Thu Jul 30 15:27:36.709426 2026] [security2:error] [pid 173718:tid 173891] [client 172.213.208.20:47870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/a.php"] [unique_id "amuzuEoi7QGnEa1uk6m2sAAAACo"]
[Thu Jul 30 15:27:37.240541 2026] [core:notice] [pid 173718:tid 173930] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:37.649063 2026] [security2:error] [pid 173718:tid 173916] [client 74.7.241.157:35630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.bnd.gpl.temporary.site"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amuzuUoi7QGnEa1uk6m2ywAAAEM"]
[Thu Jul 30 15:27:37.762449 2026] [autoindex:error] [pid 173718:tid 173880] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:27:37.918510 2026] [autoindex:error] [pid 173718:tid 173904] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:27:38.099967 2026] [security2:error] [pid 173718:tid 173879] [client 172.213.208.20:55114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amuzukoi7QGnEa1uk6m23gAAAB4"]
[Thu Jul 30 15:27:38.191451 2026] [security2:error] [pid 173718:tid 173859] [client 20.63.98.115:22182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/themes/astra/inc/ki1k.php"] [unique_id "amuzukoi7QGnEa1uk6m23wAAAAo"]
[Thu Jul 30 15:27:38.391050 2026] [security2:error] [pid 173718:tid 173951] [client 18.215.219.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "remoteworksit.com"] [uri "/index.php"] [unique_id "amuzuEoi7QGnEa1uk6m2uAAAAGY"]
[Thu Jul 30 15:27:38.614701 2026] [security2:error] [pid 173718:tid 173908] [client 172.213.208.20:54248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin.php"] [unique_id "amuzukoi7QGnEa1uk6m26AAAADs"]
[Thu Jul 30 15:27:39.392129 2026] [security2:error] [pid 173718:tid 173918] [client 136.144.33.49:50957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amuzu0oi7QGnEa1uk6m29gAAAEU"]
[Thu Jul 30 15:27:39.458616 2026] [security2:error] [pid 173718:tid 173948] [client 64.31.3.126:6117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amuzukoi7QGnEa1uk6m21wAAACY"], referer: https://globalmarks.pk/2023/08/28/parent-guide-babys-first-tooth-and-what-parents-must-know/#comment-2268
[Thu Jul 30 15:27:39.619888 2026] [security2:error] [pid 173718:tid 173754] [remote 75.119.132.40:58308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.132.119.75.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amuzu0oi7QGnEa1uk6m3AwAAEyI"]
[Thu Jul 30 15:27:39.649708 2026] [security2:error] [pid 173718:tid 173897] [client 20.63.98.115:32764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wq.php7"] [unique_id "amuzu0oi7QGnEa1uk6m3BwAAADA"]
[Thu Jul 30 15:27:40.227065 2026] [core:notice] [pid 173718:tid 173889] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:40.496067 2026] [security2:error] [pid 173718:tid 173895] [client 85.204.70.98:55838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emmelevate.club"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuzvEoi7QGnEa1uk6m3FQAAAC4"]
[Thu Jul 30 15:27:40.678442 2026] [security2:error] [pid 173718:tid 173883] [client 172.213.208.20:53498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/size.php"] [unique_id "amuzvEoi7QGnEa1uk6m3GgAAACI"]
[Thu Jul 30 15:27:41.123177 2026] [security2:error] [pid 173718:tid 173867] [client 85.204.70.98:38668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/xmlrpc.php"] [unique_id "amuzvUoi7QGnEa1uk6m3IgAAABI"]
[Thu Jul 30 15:27:41.678376 2026] [security2:error] [pid 173718:tid 173903] [client 172.213.208.20:47849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amuzvUoi7QGnEa1uk6m3LwAAADY"]
[Thu Jul 30 15:27:41.936477 2026] [core:notice] [pid 173718:tid 173785] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:42.247029 2026] [security2:error] [pid 173718:tid 173961] [client 20.63.98.115:25815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/forum.php"] [unique_id "amuzvkoi7QGnEa1uk6m3PwAAAHA"]
[Thu Jul 30 15:27:43.007343 2026] [security2:error] [pid 173718:tid 173881] [client 172.213.208.20:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/403.php"] [unique_id "amuzv0oi7QGnEa1uk6m3UQAAACA"]
[Thu Jul 30 15:27:43.386399 2026] [security2:error] [pid 173718:tid 173877] [client 20.63.98.115:25746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/5index.php"] [unique_id "amuzv0oi7QGnEa1uk6m3XwAAABw"]
[Thu Jul 30 15:27:43.454920 2026] [security2:error] [pid 173718:tid 173867] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuzv0oi7QGnEa1uk6m3YAAAABI"]
[Thu Jul 30 15:27:43.455039 2026] [security2:error] [pid 173718:tid 173867] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amuzv0oi7QGnEa1uk6m3YAAAABI"]
[Thu Jul 30 15:27:43.663821 2026] [security2:error] [pid 173718:tid 173898] [client 85.204.70.98:38682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emmelevate.club"] [uri "/xmlrpc.php"] [unique_id "amuzv0oi7QGnEa1uk6m3ZAAAADE"]
[Thu Jul 30 15:27:43.663947 2026] [security2:error] [pid 173718:tid 173898] [client 85.204.70.98:38682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "emmelevate.club"] [uri "/xmlrpc.php"] [unique_id "amuzv0oi7QGnEa1uk6m3ZAAAADE"]
[Thu Jul 30 15:27:43.736659 2026] [security2:error] [pid 173718:tid 173922] [client 20.171.55.167:3448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/.__info.php"] [unique_id "amuzv0oi7QGnEa1uk6m3ZgAAAEk"]
[Thu Jul 30 15:27:44.014161 2026] [security2:error] [pid 173718:tid 173862] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuzwEoi7QGnEa1uk6m3bwAAAA0"]
[Thu Jul 30 15:27:44.014278 2026] [security2:error] [pid 173718:tid 173862] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amuzwEoi7QGnEa1uk6m3bwAAAA0"]
[Thu Jul 30 15:27:44.276066 2026] [security2:error] [pid 173718:tid 173943] [client 20.63.98.115:25833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/cookie.php"] [unique_id "amuzwEoi7QGnEa1uk6m3cwAAAF4"]
[Thu Jul 30 15:27:44.436376 2026] [security2:error] [pid 173718:tid 173864] [client 20.171.55.167:3426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/00.php"] [unique_id "amuzwEoi7QGnEa1uk6m3fQAAAA8"]
[Thu Jul 30 15:27:44.519820 2026] [security2:error] [pid 173718:tid 173868] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/inputs.php"] [unique_id "amuzwEoi7QGnEa1uk6m3fgAAABM"]
[Thu Jul 30 15:27:44.519962 2026] [security2:error] [pid 173718:tid 173868] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/inputs.php"] [unique_id "amuzwEoi7QGnEa1uk6m3fgAAABM"]
[Thu Jul 30 15:27:44.663514 2026] [security2:error] [pid 173718:tid 173888] [client 172.213.208.20:13306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amuzwEoi7QGnEa1uk6m3fwAAACc"]
[Thu Jul 30 15:27:45.037154 2026] [security2:error] [pid 173718:tid 173967] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/admin.php"] [unique_id "amuzwUoi7QGnEa1uk6m3iQAAAHY"]
[Thu Jul 30 15:27:45.037265 2026] [security2:error] [pid 173718:tid 173967] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/admin.php"] [unique_id "amuzwUoi7QGnEa1uk6m3iQAAAHY"]
[Thu Jul 30 15:27:45.174005 2026] [security2:error] [pid 173718:tid 173927] [client 20.171.55.167:3790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/13.php"] [unique_id "amuzwUoi7QGnEa1uk6m3igAAAE4"]
[Thu Jul 30 15:27:45.183881 2026] [proxy:error] [pid 173718:tid 173904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:45.183940 2026] [proxy_http:error] [pid 173718:tid 173904] [client 34.233.129.35:10359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:45.184520 2026] [proxy:error] [pid 173718:tid 173904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:45.184566 2026] [proxy_http:error] [pid 173718:tid 173904] [client 34.233.129.35:10359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:45.226041 2026] [proxy:error] [pid 173718:tid 173966] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:45.226125 2026] [proxy_http:error] [pid 173718:tid 173966] [client 32.194.121.99:26066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:45.226726 2026] [proxy:error] [pid 173718:tid 173966] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:45.226775 2026] [proxy_http:error] [pid 173718:tid 173966] [client 32.194.121.99:26066] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:45.229494 2026] [security2:error] [pid 173718:tid 173850] [client 20.63.98.115:25890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/edit-form.php"] [unique_id "amuzwUoi7QGnEa1uk6m3lAAAAAE"]
[Thu Jul 30 15:27:45.563437 2026] [security2:error] [pid 173718:tid 173956] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/goods.php"] [unique_id "amuzwUoi7QGnEa1uk6m3nwAAAGs"]
[Thu Jul 30 15:27:45.563539 2026] [security2:error] [pid 173718:tid 173956] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/goods.php"] [unique_id "amuzwUoi7QGnEa1uk6m3nwAAAGs"]
[Thu Jul 30 15:27:45.607099 2026] [security2:error] [pid 173718:tid 173968] [client 38.172.162.57:16538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzwUoi7QGnEa1uk6m3oAAAAHc"]
[Thu Jul 30 15:27:45.607214 2026] [security2:error] [pid 173718:tid 173968] [client 38.172.162.57:16538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzwUoi7QGnEa1uk6m3oAAAAHc"]
[Thu Jul 30 15:27:46.074205 2026] [security2:error] [pid 173718:tid 173908] [client 20.171.55.167:3794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/2018/03/class-wp-type-registroy.php"] [unique_id "amuzwkoi7QGnEa1uk6m3sQAAADs"]
[Thu Jul 30 15:27:46.075304 2026] [security2:error] [pid 173718:tid 173932] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/file.php"] [unique_id "amuzwkoi7QGnEa1uk6m3sgAAAFM"]
[Thu Jul 30 15:27:46.075394 2026] [security2:error] [pid 173718:tid 173932] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/file.php"] [unique_id "amuzwkoi7QGnEa1uk6m3sgAAAFM"]
[Thu Jul 30 15:27:46.628610 2026] [security2:error] [pid 173718:tid 173963] [client 172.213.208.20:54254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/as.php"] [unique_id "amuzwkoi7QGnEa1uk6m3vQAAAHI"]
[Thu Jul 30 15:27:46.698014 2026] [security2:error] [pid 173718:tid 173891] [client 20.63.98.115:25871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/aleXus.php"] [unique_id "amuzwkoi7QGnEa1uk6m3vgAAACo"]
[Thu Jul 30 15:27:46.808761 2026] [security2:error] [pid 173718:tid 173893] [client 20.171.55.167:3430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/32.php"] [unique_id "amuzwkoi7QGnEa1uk6m3vwAAACw"]
[Thu Jul 30 15:27:47.425160 2026] [security2:error] [pid 173718:tid 173937] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/adminfuns.php"] [unique_id "amuzw0oi7QGnEa1uk6m3zAAAAFg"]
[Thu Jul 30 15:27:47.425271 2026] [security2:error] [pid 173718:tid 173937] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/adminfuns.php"] [unique_id "amuzw0oi7QGnEa1uk6m3zAAAAFg"]
[Thu Jul 30 15:27:47.457700 2026] [security2:error] [pid 173718:tid 173916] [client 172.213.208.20:47868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amuzw0oi7QGnEa1uk6m3zQAAAEM"]
[Thu Jul 30 15:27:47.510415 2026] [security2:error] [pid 173718:tid 173860] [client 20.171.55.167:3438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/520.php"] [unique_id "amuzw0oi7QGnEa1uk6m30QAAAAs"]
[Thu Jul 30 15:27:47.557384 2026] [security2:error] [pid 173718:tid 173850] [client 207.231.109.165:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.231.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samirkhalifa.net"] [uri "/images/images/cache.php"] [unique_id "amuzw0oi7QGnEa1uk6m30gAAAAE"], referer: www.google.com
[Thu Jul 30 15:27:47.939640 2026] [security2:error] [pid 173718:tid 173859] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/404.php"] [unique_id "amuzw0oi7QGnEa1uk6m32gAAAAo"]
[Thu Jul 30 15:27:47.939738 2026] [security2:error] [pid 173718:tid 173859] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/404.php"] [unique_id "amuzw0oi7QGnEa1uk6m32gAAAAo"]
[Thu Jul 30 15:27:48.212247 2026] [security2:error] [pid 173718:tid 173953] [client 20.63.98.115:49045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/user.php"] [unique_id "amuzxEoi7QGnEa1uk6m34QAAAGg"]
[Thu Jul 30 15:27:48.245673 2026] [security2:error] [pid 173718:tid 173872] [client 20.171.55.167:3777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/991176.php"] [unique_id "amuzxEoi7QGnEa1uk6m34gAAABc"]
[Thu Jul 30 15:27:48.382573 2026] [security2:error] [pid 173718:tid 173956] [client 127.0.0.1:37544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amuzxEoi7QGnEa1uk6m35AAAAGs"]
[Thu Jul 30 15:27:48.382647 2026] [security2:error] [pid 173718:tid 173975] [client 74.7.241.147:36986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.instomail.com"] [uri "/robots.txt"] [unique_id "amuzxEoi7QGnEa1uk6m34wAAflk"]
[Thu Jul 30 15:27:48.467125 2026] [security2:error] [pid 173718:tid 173890] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wk/index.php"] [unique_id "amuzxEoi7QGnEa1uk6m36AAAACk"]
[Thu Jul 30 15:27:48.467225 2026] [security2:error] [pid 173718:tid 173890] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wk/index.php"] [unique_id "amuzxEoi7QGnEa1uk6m36AAAACk"]
[Thu Jul 30 15:27:48.749619 2026] [core:notice] [pid 173718:tid 173876] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:48.944343 2026] [security2:error] [pid 173718:tid 173853] [client 20.171.55.167:3784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/Cache/upfile.php"] [unique_id "amuzxEoi7QGnEa1uk6m38AAAAAQ"]
[Thu Jul 30 15:27:48.977828 2026] [security2:error] [pid 173718:tid 173908] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuzxEoi7QGnEa1uk6m38wAAADs"]
[Thu Jul 30 15:27:48.977909 2026] [security2:error] [pid 173718:tid 173908] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/about.php"] [unique_id "amuzxEoi7QGnEa1uk6m38wAAADs"]
[Thu Jul 30 15:27:49.021138 2026] [security2:error] [pid 173718:tid 173870] [client 20.63.98.115:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/ab1ux1ft.php"] [unique_id "amuzxUoi7QGnEa1uk6m39gAAABU"]
[Thu Jul 30 15:27:49.026826 2026] [security2:error] [pid 173718:tid 173892] [client 207.231.109.165:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.231.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samirkhalifa.net"] [uri "/images/images/cache.php"] [unique_id "amuzxUoi7QGnEa1uk6m3-AAAACs"], referer: www.google.com
[Thu Jul 30 15:27:49.321853 2026] [security2:error] [pid 173718:tid 173910] [client 172.213.208.20:54694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amuzxUoi7QGnEa1uk6m4AgAAAD0"]
[Thu Jul 30 15:27:49.494171 2026] [security2:error] [pid 173718:tid 173868] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/term.php"] [unique_id "amuzxUoi7QGnEa1uk6m4AwAAABM"]
[Thu Jul 30 15:27:49.494282 2026] [security2:error] [pid 173718:tid 173868] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/term.php"] [unique_id "amuzxUoi7QGnEa1uk6m4AwAAABM"]
[Thu Jul 30 15:27:49.818891 2026] [security2:error] [pid 173718:tid 173901] [client 20.171.55.167:3786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/Diff/Renderer/about.php"] [unique_id "amuzxUoi7QGnEa1uk6m4DQAAADQ"]
[Thu Jul 30 15:27:49.927725 2026] [security2:error] [pid 173718:tid 173955] [client 20.63.98.115:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/home/function.php"] [unique_id "amuzxUoi7QGnEa1uk6m4DwAAAGo"]
[Thu Jul 30 15:27:50.021829 2026] [security2:error] [pid 173718:tid 173916] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ioxi-o.php"] [unique_id "amuzxkoi7QGnEa1uk6m4EAAAAEM"]
[Thu Jul 30 15:27:50.021940 2026] [security2:error] [pid 173718:tid 173916] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ioxi-o.php"] [unique_id "amuzxkoi7QGnEa1uk6m4EAAAAEM"]
[Thu Jul 30 15:27:50.472544 2026] [proxy:error] [pid 173718:tid 173883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:50.472626 2026] [proxy_http:error] [pid 173718:tid 173883] [client 44.213.206.96:22874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:50.473441 2026] [proxy:error] [pid 173718:tid 173883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:50.473491 2026] [proxy_http:error] [pid 173718:tid 173883] [client 44.213.206.96:22874] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:50.480564 2026] [proxy:error] [pid 173718:tid 173909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:50.480623 2026] [proxy_http:error] [pid 173718:tid 173909] [client 44.213.206.96:46998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:50.481204 2026] [proxy:error] [pid 173718:tid 173909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:27:50.481251 2026] [proxy_http:error] [pid 173718:tid 173909] [client 44.213.206.96:46998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:27:50.517961 2026] [security2:error] [pid 173718:tid 173879] [client 20.9.4.9:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuzxkoi7QGnEa1uk6m4IwAAAB4"]
[Thu Jul 30 15:27:50.518079 2026] [security2:error] [pid 173718:tid 173879] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuzxkoi7QGnEa1uk6m4IwAAAB4"]
[Thu Jul 30 15:27:50.518183 2026] [security2:error] [pid 173718:tid 173879] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/1.php"] [unique_id "amuzxkoi7QGnEa1uk6m4IwAAAB4"]
[Thu Jul 30 15:27:50.590491 2026] [security2:error] [pid 173718:tid 173939] [client 20.171.55.167:3439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/FoxWSOv1.php"] [unique_id "amuzxkoi7QGnEa1uk6m4KAAAAFo"]
[Thu Jul 30 15:27:50.628767 2026] [security2:error] [pid 173718:tid 173859] [client 172.213.208.20:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/plugins.php"] [unique_id "amuzxkoi7QGnEa1uk6m4KQAAAAo"]
[Thu Jul 30 15:27:50.826100 2026] [security2:error] [pid 173718:tid 173801] [remote 185.242.3.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-plain.php"] [unique_id "amuzxkoi7QGnEa1uk6m4MQAALVE"], referer: www.google.com
[Thu Jul 30 15:27:50.923170 2026] [security2:error] [pid 173718:tid 173827] [remote 185.242.3.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "amuzxkoi7QGnEa1uk6m4MgAAHWs"], referer: www.google.com
[Thu Jul 30 15:27:50.937135 2026] [security2:error] [pid 173718:tid 173834] [remote 185.242.3.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amuzxkoi7QGnEa1uk6m4MwAANnI"]
[Thu Jul 30 15:27:51.050329 2026] [security2:error] [pid 173718:tid 173933] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/alfa.php"] [unique_id "amuzx0oi7QGnEa1uk6m4NAAAAFQ"]
[Thu Jul 30 15:27:51.050474 2026] [security2:error] [pid 173718:tid 173933] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/alfa.php"] [unique_id "amuzx0oi7QGnEa1uk6m4NAAAAFQ"]
[Thu Jul 30 15:27:51.153082 2026] [security2:error] [pid 173718:tid 173841] [remote 185.242.3.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "amuzx0oi7QGnEa1uk6m4OAAABnk"], referer: www.google.com
[Thu Jul 30 15:27:51.220471 2026] [security2:error] [pid 173718:tid 173876] [client 172.213.208.20:37941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/js/index.php"] [unique_id "amuzx0oi7QGnEa1uk6m4OgAAABs"]
[Thu Jul 30 15:27:51.253995 2026] [security2:error] [pid 173718:tid 173727] [remote 185.242.3.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/jbfnsruw.php"] [unique_id "amuzx0oi7QGnEa1uk6m4PQAADQc"], referer: www.google.com
[Thu Jul 30 15:27:51.350483 2026] [security2:error] [pid 173718:tid 173908] [client 20.171.55.167:3444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/Mhbgf.php"] [unique_id "amuzx0oi7QGnEa1uk6m4QgAAADs"]
[Thu Jul 30 15:27:51.556620 2026] [security2:error] [pid 173718:tid 173918] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/edit.php"] [unique_id "amuzx0oi7QGnEa1uk6m4QwAAAEU"]
[Thu Jul 30 15:27:51.556727 2026] [security2:error] [pid 173718:tid 173918] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/edit.php"] [unique_id "amuzx0oi7QGnEa1uk6m4QwAAAEU"]
[Thu Jul 30 15:27:52.053862 2026] [security2:error] [pid 173718:tid 173907] [client 20.171.55.167:3424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/RxR_ghail.php"] [unique_id "amuzyEoi7QGnEa1uk6m4TwAAADo"]
[Thu Jul 30 15:27:52.055743 2026] [security2:error] [pid 173718:tid 173967] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/elp.php"] [unique_id "amuzyEoi7QGnEa1uk6m4UAAAAHY"]
[Thu Jul 30 15:27:52.055835 2026] [security2:error] [pid 173718:tid 173967] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/elp.php"] [unique_id "amuzyEoi7QGnEa1uk6m4UAAAAHY"]
[Thu Jul 30 15:27:52.100718 2026] [security2:error] [pid 173718:tid 173729] [remote 185.242.3.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "amuzyEoi7QGnEa1uk6m4UQAAagk"]
[Thu Jul 30 15:27:52.332119 2026] [security2:error] [pid 173718:tid 173875] [client 172.213.208.20:55271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/go.php"] [unique_id "amuzyEoi7QGnEa1uk6m4WwAAABo"]
[Thu Jul 30 15:27:52.525532 2026] [security2:error] [pid 173718:tid 173808] [remote 185.242.3.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "amuzyEoi7QGnEa1uk6m4YAAAS1g"]
[Thu Jul 30 15:27:52.569013 2026] [security2:error] [pid 173718:tid 173883] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/classwithtostring.php"] [unique_id "amuzyEoi7QGnEa1uk6m4YQAAACI"]
[Thu Jul 30 15:27:52.569117 2026] [security2:error] [pid 173718:tid 173883] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/classwithtostring.php"] [unique_id "amuzyEoi7QGnEa1uk6m4YQAAACI"]
[Thu Jul 30 15:27:52.636730 2026] [security2:error] [pid 173718:tid 173872] [client 20.63.98.115:49043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-login.php"] [unique_id "amuzyEoi7QGnEa1uk6m4XwAAABc"]
[Thu Jul 30 15:27:52.701517 2026] [security2:error] [pid 173718:tid 173847] [remote 185.242.3.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "amuzyEoi7QGnEa1uk6m4YgAAJH8"]
[Thu Jul 30 15:27:52.804398 2026] [security2:error] [pid 173718:tid 173944] [client 20.171.55.167:3785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/Text/admin.php"] [unique_id "amuzyEoi7QGnEa1uk6m4ZQAAAF8"]
[Thu Jul 30 15:27:52.993690 2026] [security2:error] [pid 173718:tid 173909] [client 172.213.208.20:24825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/test1.php"] [unique_id "amuzyEoi7QGnEa1uk6m4agAAADw"]
[Thu Jul 30 15:27:53.100749 2026] [security2:error] [pid 173718:tid 173957] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/666.php"] [unique_id "amuzyUoi7QGnEa1uk6m4awAAAGw"]
[Thu Jul 30 15:27:53.100858 2026] [security2:error] [pid 173718:tid 173957] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/666.php"] [unique_id "amuzyUoi7QGnEa1uk6m4awAAAGw"]
[Thu Jul 30 15:27:53.103561 2026] [security2:error] [pid 173718:tid 173722] [remote 185.242.3.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spececigarette.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "amuzyUoi7QGnEa1uk6m4bAAAegI"]
[Thu Jul 30 15:27:53.201077 2026] [security2:error] [pid 173718:tid 173915] [client 185.242.3.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuzxkoi7QGnEa1uk6m4MAAAQm0"], referer: www.google.com
[Thu Jul 30 15:27:53.301189 2026] [security2:error] [pid 173718:tid 173958] [client 62.4.17.61:49304] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "journeywomenscenter.org"] [uri "/"] [unique_id "amuzyUoi7QGnEa1uk6m4cQAAAG0"]
[Thu Jul 30 15:27:53.414931 2026] [core:notice] [pid 173718:tid 173892] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:53.503776 2026] [security2:error] [pid 173718:tid 173903] [client 20.171.55.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/Yetix.php"] [unique_id "amuzyUoi7QGnEa1uk6m4egAAADY"]
[Thu Jul 30 15:27:53.648745 2026] [core:error] [pid 173718:tid 173908] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:27:53.648769 2026] [core:error] [pid 173718:tid 173908] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:27:53.648868 2026] [security2:error] [pid 173718:tid 173908] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index.php"] [unique_id "amuzyUoi7QGnEa1uk6m4fwAAADs"]
[Thu Jul 30 15:27:54.043856 2026] [security2:error] [pid 173718:tid 173869] [client 185.242.3.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "spececigarette.com"] [uri "/index.php"] [unique_id "amuzyUoi7QGnEa1uk6m4fgAAFHw"], referer: www.google.com
[Thu Jul 30 15:27:54.148611 2026] [security2:error] [pid 173718:tid 173955] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ws54.php"] [unique_id "amuzykoi7QGnEa1uk6m4kQAAAGo"]
[Thu Jul 30 15:27:54.148694 2026] [security2:error] [pid 173718:tid 173955] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ws54.php"] [unique_id "amuzykoi7QGnEa1uk6m4kQAAAGo"]
[Thu Jul 30 15:27:54.256471 2026] [security2:error] [pid 173718:tid 173910] [client 20.171.55.167:3412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/abuot.php"] [unique_id "amuzykoi7QGnEa1uk6m4kwAAAD0"]
[Thu Jul 30 15:27:54.343318 2026] [security2:error] [pid 173718:tid 173920] [client 179.6.101.102:2497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.101.6.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/xmlrpc.php"] [unique_id "amuzykoi7QGnEa1uk6m4jQAAAEc"]
[Thu Jul 30 15:27:54.343511 2026] [security2:error] [pid 173718:tid 173920] [client 179.6.101.102:2497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "asian-connect.com"] [uri "/xmlrpc.php"] [unique_id "amuzykoi7QGnEa1uk6m4jQAAAEc"]
[Thu Jul 30 15:27:54.345166 2026] [security2:error] [pid 173718:tid 173936] [client 82.102.18.188:48758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amuzykoi7QGnEa1uk6m4lAAAAFc"]
[Thu Jul 30 15:27:54.615474 2026] [security2:error] [pid 173718:tid 173924] [client 82.102.18.188:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.carrescia.com"] [uri "/xmlrpc.php"] [unique_id "amuzykoi7QGnEa1uk6m4ngAAAEs"]
[Thu Jul 30 15:27:54.653059 2026] [security2:error] [pid 173718:tid 173970] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/deepseek_d.php"] [unique_id "amuzykoi7QGnEa1uk6m4oAAAAHk"]
[Thu Jul 30 15:27:54.653152 2026] [security2:error] [pid 173718:tid 173970] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/deepseek_d.php"] [unique_id "amuzykoi7QGnEa1uk6m4oAAAAHk"]
[Thu Jul 30 15:27:54.682580 2026] [autoindex:error] [pid 173718:tid 173929] [client 172.213.208.20:12414] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:27:54.874176 2026] [security2:error] [pid 173718:tid 173941] [client 172.213.208.20:12414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/images/index.php"] [unique_id "amuzykoi7QGnEa1uk6m4owAAAFw"]
[Thu Jul 30 15:27:54.971303 2026] [security2:error] [pid 173718:tid 173886] [client 20.171.55.167:3433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/admin-footer.php"] [unique_id "amuzykoi7QGnEa1uk6m4qQAAACU"]
[Thu Jul 30 15:27:55.035843 2026] [security2:error] [pid 173718:tid 173898] [client 82.102.18.188:48786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuzy0oi7QGnEa1uk6m4rgAAADE"]
[Thu Jul 30 15:27:55.048508 2026] [security2:error] [pid 173718:tid 173928] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzy0oi7QGnEa1uk6m4swAAAE8"]
[Thu Jul 30 15:27:55.058656 2026] [security2:error] [pid 173718:tid 173874] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuzy0oi7QGnEa1uk6m4tAAAABk"]
[Thu Jul 30 15:27:55.172938 2026] [security2:error] [pid 173718:tid 173926] [client 20.63.98.115:49524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/upgrade/about.php"] [unique_id "amuzy0oi7QGnEa1uk6m4uwAAAE0"]
[Thu Jul 30 15:27:55.294732 2026] [security2:error] [pid 173718:tid 173950] [client 82.102.18.188:48802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuzy0oi7QGnEa1uk6m4vAAAAGU"]
[Thu Jul 30 15:27:55.356767 2026] [security2:error] [pid 173718:tid 173964] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/function/function.php"] [unique_id "amuzy0oi7QGnEa1uk6m4vQAAAHM"]
[Thu Jul 30 15:27:55.356872 2026] [security2:error] [pid 173718:tid 173964] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/function/function.php"] [unique_id "amuzy0oi7QGnEa1uk6m4vQAAAHM"]
[Thu Jul 30 15:27:55.571100 2026] [security2:error] [pid 173718:tid 173891] [client 82.102.18.188:48812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amuzy0oi7QGnEa1uk6m4xwAAACo"]
[Thu Jul 30 15:27:55.690810 2026] [security2:error] [pid 173718:tid 173930] [client 20.171.55.167:3415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/administratork.php"] [unique_id "amuzy0oi7QGnEa1uk6m4ygAAAFE"]
[Thu Jul 30 15:27:55.759895 2026] [security2:error] [pid 173718:tid 173906] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzy0oi7QGnEa1uk6m40gAAADk"]
[Thu Jul 30 15:27:55.766101 2026] [security2:error] [pid 173718:tid 173935] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuzy0oi7QGnEa1uk6m40wAAAFY"]
[Thu Jul 30 15:27:55.844514 2026] [security2:error] [pid 173718:tid 173949] [client 82.102.18.188:48824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuzy0oi7QGnEa1uk6m41AAAAGQ"]
[Thu Jul 30 15:27:55.876186 2026] [security2:error] [pid 173718:tid 173907] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/nw.php"] [unique_id "amuzy0oi7QGnEa1uk6m41QAAADo"]
[Thu Jul 30 15:27:55.876279 2026] [security2:error] [pid 173718:tid 173907] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/nw.php"] [unique_id "amuzy0oi7QGnEa1uk6m41QAAADo"]
[Thu Jul 30 15:27:56.104511 2026] [security2:error] [pid 173718:tid 173872] [client 82.102.18.188:48834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuzzEoi7QGnEa1uk6m43wAAABc"]
[Thu Jul 30 15:27:56.185992 2026] [security2:error] [pid 173718:tid 173921] [client 38.172.162.57:16177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzzEoi7QGnEa1uk6m45AAAAEg"]
[Thu Jul 30 15:27:56.186089 2026] [security2:error] [pid 173718:tid 173921] [client 38.172.162.57:16177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuzzEoi7QGnEa1uk6m45AAAAEg"]
[Thu Jul 30 15:27:56.363601 2026] [security2:error] [pid 173718:tid 173879] [client 82.102.18.188:48848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuzzEoi7QGnEa1uk6m45gAAAB4"]
[Thu Jul 30 15:27:56.399515 2026] [security2:error] [pid 173718:tid 173902] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/xleet.php"] [unique_id "amuzzEoi7QGnEa1uk6m45wAAADU"]
[Thu Jul 30 15:27:56.399600 2026] [security2:error] [pid 173718:tid 173902] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/xleet.php"] [unique_id "amuzzEoi7QGnEa1uk6m45wAAADU"]
[Thu Jul 30 15:27:56.414322 2026] [security2:error] [pid 173718:tid 173898] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzEoi7QGnEa1uk6m46AAAADE"]
[Thu Jul 30 15:27:56.434399 2026] [security2:error] [pid 173718:tid 173957] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuzzEoi7QGnEa1uk6m46QAAAGw"]
[Thu Jul 30 15:27:56.638037 2026] [security2:error] [pid 173718:tid 173943] [client 82.102.18.188:48864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuzzEoi7QGnEa1uk6m48wAAAF4"]
[Thu Jul 30 15:27:56.675133 2026] [autoindex:error] [pid 173718:tid 173969] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:27:56.746202 2026] [security2:error] [pid 173718:tid 173858] [client 20.171.55.167:3405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/akc.php"] [unique_id "amuzzEoi7QGnEa1uk6m4-AAAAAk"]
[Thu Jul 30 15:27:56.805551 2026] [security2:error] [pid 173718:tid 173908] [client 172.213.208.20:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/asd.php"] [unique_id "amuzzEoi7QGnEa1uk6m4-QAAADs"]
[Thu Jul 30 15:27:56.888212 2026] [security2:error] [pid 173718:tid 173891] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzEoi7QGnEa1uk6m4-gAAACo"]
[Thu Jul 30 15:27:56.893211 2026] [security2:error] [pid 173718:tid 173938] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzEoi7QGnEa1uk6m4-wAAAFk"]
[Thu Jul 30 15:27:56.899132 2026] [security2:error] [pid 173718:tid 173976] [client 82.102.18.188:48872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuzzEoi7QGnEa1uk6m4_AAAAH8"]
[Thu Jul 30 15:27:56.930666 2026] [security2:error] [pid 173718:tid 173888] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp.php"] [unique_id "amuzzEoi7QGnEa1uk6m4_QAAACc"]
[Thu Jul 30 15:27:56.930767 2026] [security2:error] [pid 173718:tid 173888] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp.php"] [unique_id "amuzzEoi7QGnEa1uk6m4_QAAACc"]
[Thu Jul 30 15:27:56.960190 2026] [security2:error] [pid 173718:tid 173973] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuzzEoi7QGnEa1uk6m4_wAAAHw"]
[Thu Jul 30 15:27:57.074757 2026] [security2:error] [pid 173718:tid 173913] [client 204.8.98.55:47816] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuzzUoi7QGnEa1uk6m5BgAAAEA"]
[Thu Jul 30 15:27:57.074852 2026] [security2:error] [pid 173718:tid 173913] [client 204.8.98.55:47816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amuzzUoi7QGnEa1uk6m5BgAAAEA"]
[Thu Jul 30 15:27:57.166992 2026] [security2:error] [pid 173718:tid 173905] [client 82.102.18.188:48886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amuzzUoi7QGnEa1uk6m5CwAAADg"]
[Thu Jul 30 15:27:57.188855 2026] [core:notice] [pid 173718:tid 173920] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:57.303294 2026] [security2:error] [pid 173718:tid 173869] [client 20.63.98.115:32708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp.php"] [unique_id "amuzzUoi7QGnEa1uk6m5DgAAABQ"]
[Thu Jul 30 15:27:57.431833 2026] [security2:error] [pid 173718:tid 173865] [client 82.102.18.188:48898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amuzzUoi7QGnEa1uk6m5DwAAABA"]
[Thu Jul 30 15:27:57.436175 2026] [security2:error] [pid 173718:tid 173945] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzUoi7QGnEa1uk6m5EAAAAGA"]
[Thu Jul 30 15:27:57.437426 2026] [security2:error] [pid 173718:tid 173850] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzUoi7QGnEa1uk6m5EQAAAAE"]
[Thu Jul 30 15:27:57.483998 2026] [security2:error] [pid 173718:tid 173857] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzUoi7QGnEa1uk6m5EgAAAAg"]
[Thu Jul 30 15:27:57.508964 2026] [security2:error] [pid 173718:tid 173871] [client 20.171.55.167:3617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/alfaaneh.php"] [unique_id "amuzzUoi7QGnEa1uk6m5FQAAABY"]
[Thu Jul 30 15:27:57.542226 2026] [security2:error] [pid 173718:tid 173900] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuzzUoi7QGnEa1uk6m5FwAAADM"]
[Thu Jul 30 15:27:57.594726 2026] [fcgid:warn] [pid 173718:tid 173970] (70014)End of file found: [client 18.218.118.203:49376] mod_fcgid: can't get data from http client
[Thu Jul 30 15:27:57.691646 2026] [security2:error] [pid 173718:tid 173951] [client 82.102.18.188:26030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amuzzUoi7QGnEa1uk6m5IAAAAGY"]
[Thu Jul 30 15:27:57.899896 2026] [security2:error] [pid 173718:tid 173873] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzUoi7QGnEa1uk6m5HAAAABg"]
[Thu Jul 30 15:27:57.952359 2026] [security2:error] [pid 173718:tid 173902] [client 82.102.18.188:48910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuzzUoi7QGnEa1uk6m5IgAAADU"]
[Thu Jul 30 15:27:57.996616 2026] [core:error] [pid 173718:tid 173957] [client 40.77.167.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:27:57.996635 2026] [core:error] [pid 173718:tid 173957] [client 40.77.167.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:27:58.001962 2026] [security2:error] [pid 173718:tid 173877] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/155.php"] [unique_id "amuzzkoi7QGnEa1uk6m5JgAAABw"]
[Thu Jul 30 15:27:58.002129 2026] [security2:error] [pid 173718:tid 173877] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/155.php"] [unique_id "amuzzkoi7QGnEa1uk6m5JgAAABw"]
[Thu Jul 30 15:27:58.235583 2026] [security2:error] [pid 173718:tid 173851] [client 82.102.18.188:48914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.carrescia.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuzzkoi7QGnEa1uk6m5MAAAAAI"]
[Thu Jul 30 15:27:58.243512 2026] [security2:error] [pid 173718:tid 173971] [client 20.171.55.167:3701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/alfav4.1.php"] [unique_id "amuzzkoi7QGnEa1uk6m5MQAAAHo"]
[Thu Jul 30 15:27:58.275774 2026] [security2:error] [pid 173718:tid 173947] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzkoi7QGnEa1uk6m5MgAAAGI"]
[Thu Jul 30 15:27:58.275900 2026] [security2:error] [pid 173718:tid 173918] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzkoi7QGnEa1uk6m5MwAAAEU"]
[Thu Jul 30 15:27:58.328938 2026] [security2:error] [pid 173718:tid 173891] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuzzkoi7QGnEa1uk6m5NAAAACo"]
[Thu Jul 30 15:27:58.428534 2026] [security2:error] [pid 173718:tid 173904] [client 172.213.208.20:37937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amuzzkoi7QGnEa1uk6m5NQAAADc"]
[Thu Jul 30 15:27:58.518682 2026] [security2:error] [pid 173718:tid 173917] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/96i.php"] [unique_id "amuzzkoi7QGnEa1uk6m5OAAAAEQ"]
[Thu Jul 30 15:27:58.518782 2026] [security2:error] [pid 173718:tid 173917] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/96i.php"] [unique_id "amuzzkoi7QGnEa1uk6m5OAAAAEQ"]
[Thu Jul 30 15:27:59.007789 2026] [security2:error] [pid 173718:tid 173907] [client 20.171.55.167:3700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/ans.php"] [unique_id "amuzz0oi7QGnEa1uk6m5TQAAADo"]
[Thu Jul 30 15:27:59.068481 2026] [security2:error] [pid 173718:tid 173939] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/as.php"] [unique_id "amuzz0oi7QGnEa1uk6m5VAAAAFo"]
[Thu Jul 30 15:27:59.068566 2026] [security2:error] [pid 173718:tid 173939] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/as.php"] [unique_id "amuzz0oi7QGnEa1uk6m5VAAAAFo"]
[Thu Jul 30 15:27:59.081500 2026] [core:notice] [pid 173718:tid 173906] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:27:59.105471 2026] [security2:error] [pid 173718:tid 173941] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuzz0oi7QGnEa1uk6m5VgAAAFw"]
[Thu Jul 30 15:27:59.202199 2026] [security2:error] [pid 173718:tid 173967] [client 204.8.98.55:57976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuzz0oi7QGnEa1uk6m5WwAAAHY"]
[Thu Jul 30 15:27:59.202305 2026] [security2:error] [pid 173718:tid 173967] [client 204.8.98.55:57976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amuzz0oi7QGnEa1uk6m5WwAAAHY"]
[Thu Jul 30 15:27:59.624167 2026] [security2:error] [pid 173718:tid 173860] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/min.php"] [unique_id "amuzz0oi7QGnEa1uk6m5ZAAAAAs"]
[Thu Jul 30 15:27:59.624277 2026] [security2:error] [pid 173718:tid 173860] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/min.php"] [unique_id "amuzz0oi7QGnEa1uk6m5ZAAAAAs"]
[Thu Jul 30 15:27:59.716319 2026] [security2:error] [pid 173718:tid 173901] [client 20.171.55.167:3686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/applicationk.php"] [unique_id "amuzz0oi7QGnEa1uk6m5ZwAAADQ"]
[Thu Jul 30 15:28:00.056089 2026] [security2:error] [pid 173718:tid 173900] [client 172.213.208.20:54214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amuz0Eoi7QGnEa1uk6m5bQAAADM"]
[Thu Jul 30 15:28:00.154973 2026] [autoindex:error] [pid 173718:tid 173855] [client 20.9.4.9:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_298832dd/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:00.155742 2026] [security2:error] [pid 173718:tid 173855] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/cgi-sys/403.html"] [unique_id "amuz0Eoi7QGnEa1uk6m5cQAAAAY"]
[Thu Jul 30 15:28:00.190998 2026] [security2:error] [pid 173718:tid 173964] [client 20.203.148.31:45050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/011i.php"] [unique_id "amuz0Eoi7QGnEa1uk6m5cgAAAHM"]
[Thu Jul 30 15:28:00.457655 2026] [security2:error] [pid 173718:tid 173917] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/php8.php"] [unique_id "amuz0Eoi7QGnEa1uk6m5eQAAAEQ"]
[Thu Jul 30 15:28:00.457764 2026] [security2:error] [pid 173718:tid 173917] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/php8.php"] [unique_id "amuz0Eoi7QGnEa1uk6m5eQAAAEQ"]
[Thu Jul 30 15:28:00.464142 2026] [security2:error] [pid 173718:tid 173908] [client 20.171.55.167:3394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/asetk.php"] [unique_id "amuz0Eoi7QGnEa1uk6m5egAAADs"]
[Thu Jul 30 15:28:00.645088 2026] [security2:error] [pid 173718:tid 173946] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz0Eoi7QGnEa1uk6m5ewAAAGE"]
[Thu Jul 30 15:28:00.647411 2026] [security2:error] [pid 173718:tid 173930] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz0Eoi7QGnEa1uk6m5fAAAAFE"]
[Thu Jul 30 15:28:01.001540 2026] [security2:error] [pid 173718:tid 173868] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/admin.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5hgAAABM"]
[Thu Jul 30 15:28:01.001688 2026] [security2:error] [pid 173718:tid 173868] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/admin.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5hgAAABM"]
[Thu Jul 30 15:28:01.164567 2026] [security2:error] [pid 173718:tid 173884] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5hwAAACM"]
[Thu Jul 30 15:28:01.187744 2026] [security2:error] [pid 173718:tid 173961] [client 20.203.148.31:39712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/03a005685d.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5iAAAAHA"]
[Thu Jul 30 15:28:01.226807 2026] [security2:error] [pid 173718:tid 173865] [client 20.171.55.167:3666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/audio.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5jAAAABA"]
[Thu Jul 30 15:28:01.304809 2026] [core:notice] [pid 173718:tid 173945] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:01.537813 2026] [security2:error] [pid 173718:tid 173951] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/222.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5lQAAAGY"]
[Thu Jul 30 15:28:01.537922 2026] [security2:error] [pid 173718:tid 173951] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/222.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5lQAAAGY"]
[Thu Jul 30 15:28:01.912345 2026] [security2:error] [pid 173718:tid 173879] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5nwAAAB4"]
[Thu Jul 30 15:28:01.925998 2026] [security2:error] [pid 173718:tid 173859] [client 172.213.208.20:47815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/atomlib.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5oAAAAAo"]
[Thu Jul 30 15:28:01.928738 2026] [security2:error] [pid 173718:tid 173872] [client 20.171.55.167:3690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/azdare.php"] [unique_id "amuz0Uoi7QGnEa1uk6m5oQAAABc"]
[Thu Jul 30 15:28:02.099402 2026] [security2:error] [pid 173718:tid 173922] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuz0koi7QGnEa1uk6m5ogAAAEk"]
[Thu Jul 30 15:28:02.099525 2026] [security2:error] [pid 173718:tid 173922] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "amuz0koi7QGnEa1uk6m5ogAAAEk"]
[Thu Jul 30 15:28:02.107834 2026] [security2:error] [pid 173718:tid 173909] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz0koi7QGnEa1uk6m5owAAADw"]
[Thu Jul 30 15:28:02.224831 2026] [security2:error] [pid 173718:tid 173902] [client 20.203.148.31:39728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/403.php"] [unique_id "amuz0koi7QGnEa1uk6m5pAAAADU"]
[Thu Jul 30 15:28:02.239806 2026] [core:notice] [pid 173718:tid 173928] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:02.256616 2026] [security2:error] [pid 173718:tid 173958] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz0koi7QGnEa1uk6m5pgAAAG0"]
[Thu Jul 30 15:28:02.325825 2026] [security2:error] [pid 173718:tid 173787] [remote 57.141.0.56:58004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/519416797/feed/rss2/"] [unique_id "amuz0koi7QGnEa1uk6m5qgAAdEM"]
[Thu Jul 30 15:28:02.648198 2026] [security2:error] [pid 173718:tid 173918] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/info.php"] [unique_id "amuz0koi7QGnEa1uk6m5sgAAAEU"]
[Thu Jul 30 15:28:02.648316 2026] [security2:error] [pid 173718:tid 173918] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/info.php"] [unique_id "amuz0koi7QGnEa1uk6m5sgAAAEU"]
[Thu Jul 30 15:28:02.719481 2026] [security2:error] [pid 173718:tid 173867] [client 20.171.55.167:3393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/beence.php"] [unique_id "amuz0koi7QGnEa1uk6m5swAAABI"]
[Thu Jul 30 15:28:02.764349 2026] [security2:error] [pid 173718:tid 173852] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz0koi7QGnEa1uk6m5tQAAAAM"]
[Thu Jul 30 15:28:02.802652 2026] [security2:error] [pid 173718:tid 173864] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz0koi7QGnEa1uk6m5tgAAAA8"]
[Thu Jul 30 15:28:02.943229 2026] [security2:error] [pid 173718:tid 173938] [client 20.203.148.31:50917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/404.php"] [unique_id "amuz0koi7QGnEa1uk6m5vgAAAFk"]
[Thu Jul 30 15:28:03.133674 2026] [core:notice] [pid 173718:tid 173949] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:03.182315 2026] [security2:error] [pid 173718:tid 173925] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/a.php"] [unique_id "amuz00oi7QGnEa1uk6m5wwAAAEw"]
[Thu Jul 30 15:28:03.182424 2026] [security2:error] [pid 173718:tid 173925] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/a.php"] [unique_id "amuz00oi7QGnEa1uk6m5wwAAAEw"]
[Thu Jul 30 15:28:03.386387 2026] [security2:error] [pid 173718:tid 173961] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz00oi7QGnEa1uk6m5xwAAAHA"]
[Thu Jul 30 15:28:03.452540 2026] [security2:error] [pid 173718:tid 173963] [client 20.171.55.167:3658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/block-editor.php"] [unique_id "amuz00oi7QGnEa1uk6m5zgAAAHI"]
[Thu Jul 30 15:28:03.464006 2026] [autoindex:error] [pid 173718:tid 173929] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:03.661019 2026] [autoindex:error] [pid 173718:tid 173882] [client 172.213.208.20:47830] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:03.666812 2026] [security2:error] [pid 173718:tid 173865] [client 20.203.148.31:45040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/aa.php"] [unique_id "amuz00oi7QGnEa1uk6m51AAAABA"]
[Thu Jul 30 15:28:03.737485 2026] [security2:error] [pid 173718:tid 173861] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/chosen.php"] [unique_id "amuz00oi7QGnEa1uk6m51QAAAAw"]
[Thu Jul 30 15:28:03.737578 2026] [security2:error] [pid 173718:tid 173861] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/chosen.php"] [unique_id "amuz00oi7QGnEa1uk6m51QAAAAw"]
[Thu Jul 30 15:28:03.827730 2026] [core:notice] [pid 173718:tid 173906] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:03.831381 2026] [security2:error] [pid 173718:tid 173906] [client 66.249.79.1:54731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Deiksis/article/view/614"] [unique_id "amuz00oi7QGnEa1uk6m50gAAADk"]
[Thu Jul 30 15:28:03.860892 2026] [security2:error] [pid 173718:tid 173919] [client 172.213.208.20:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amuz00oi7QGnEa1uk6m51gAAAEY"]
[Thu Jul 30 15:28:04.069383 2026] [security2:error] [pid 173718:tid 173853] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz1Eoi7QGnEa1uk6m54wAAAAQ"]
[Thu Jul 30 15:28:04.129536 2026] [security2:error] [pid 173718:tid 173931] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1Eoi7QGnEa1uk6m55AAAAFI"]
[Thu Jul 30 15:28:04.144009 2026] [security2:error] [pid 173718:tid 173870] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1Eoi7QGnEa1uk6m55QAAABU"]
[Thu Jul 30 15:28:04.224399 2026] [security2:error] [pid 173718:tid 173849] [client 20.171.55.167:3687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/bootstrapwp.php"] [unique_id "amuz1Eoi7QGnEa1uk6m55gAAAAA"]
[Thu Jul 30 15:28:04.257194 2026] [security2:error] [pid 173718:tid 173892] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/index.php"] [unique_id "amuz1Eoi7QGnEa1uk6m55wAAACs"]
[Thu Jul 30 15:28:04.257306 2026] [security2:error] [pid 173718:tid 173892] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/index.php"] [unique_id "amuz1Eoi7QGnEa1uk6m55wAAACs"]
[Thu Jul 30 15:28:04.412701 2026] [security2:error] [pid 173718:tid 173887] [client 20.203.148.31:44999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/aafewc0k.php"] [unique_id "amuz1Eoi7QGnEa1uk6m56QAAACY"]
[Thu Jul 30 15:28:04.630442 2026] [security2:error] [pid 173718:tid 173946] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1Eoi7QGnEa1uk6m58gAAAGE"]
[Thu Jul 30 15:28:04.701175 2026] [security2:error] [pid 173718:tid 173858] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1Eoi7QGnEa1uk6m59QAAAAk"]
[Thu Jul 30 15:28:04.765454 2026] [autoindex:error] [pid 173718:tid 173851] [client 172.213.208.20:24413] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:04.769448 2026] [security2:error] [pid 173718:tid 173854] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/vx.php"] [unique_id "amuz1Eoi7QGnEa1uk6m59gAAAAU"]
[Thu Jul 30 15:28:04.769527 2026] [security2:error] [pid 173718:tid 173854] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/vx.php"] [unique_id "amuz1Eoi7QGnEa1uk6m59gAAAAU"]
[Thu Jul 30 15:28:04.920212 2026] [autoindex:error] [pid 173718:tid 173905] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/blocks/block/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:04.958846 2026] [security2:error] [pid 173718:tid 173884] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz1Eoi7QGnEa1uk6m6AAAAACM"]
[Thu Jul 30 15:28:04.986182 2026] [security2:error] [pid 173718:tid 173920] [client 20.171.55.167:3400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/by.php"] [unique_id "amuz1Eoi7QGnEa1uk6m6AwAAAEc"]
[Thu Jul 30 15:28:05.114702 2026] [autoindex:error] [pid 173718:tid 173945] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:05.181804 2026] [security2:error] [pid 173718:tid 173973] [client 20.63.98.115:42238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/Requests/library/about.php"] [unique_id "amuz1Uoi7QGnEa1uk6m6CwAAAHw"]
[Thu Jul 30 15:28:05.244682 2026] [security2:error] [pid 173718:tid 173882] [client 172.213.208.20:24413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/inputs.php"] [unique_id "amuz1Uoi7QGnEa1uk6m6DAAAACE"]
[Thu Jul 30 15:28:05.245665 2026] [security2:error] [pid 173718:tid 173865] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1Uoi7QGnEa1uk6m6DQAAABA"]
[Thu Jul 30 15:28:05.423943 2026] [security2:error] [pid 173718:tid 173906] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz1Uoi7QGnEa1uk6m6EQAAADk"]
[Thu Jul 30 15:28:05.513903 2026] [security2:error] [pid 173718:tid 173879] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1Uoi7QGnEa1uk6m6GAAAAB4"]
[Thu Jul 30 15:28:05.531318 2026] [core:notice] [pid 173718:tid 173939] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:05.536484 2026] [security2:error] [pid 173718:tid 173939] [client 66.249.79.230:56356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Publika/article/view/1497/883"] [unique_id "amuz1Uoi7QGnEa1uk6m6GQAAAFo"]
[Thu Jul 30 15:28:05.549286 2026] [security2:error] [pid 173718:tid 173889] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1Uoi7QGnEa1uk6m6GgAAACg"]
[Thu Jul 30 15:28:05.734851 2026] [security2:error] [pid 173718:tid 173873] [client 20.171.55.167:3879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/cachewp.php"] [unique_id "amuz1Uoi7QGnEa1uk6m6HwAAABg"]
[Thu Jul 30 15:28:05.899599 2026] [security2:error] [pid 173718:tid 173922] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1Uoi7QGnEa1uk6m6IAAAAEk"]
[Thu Jul 30 15:28:05.938070 2026] [security2:error] [pid 173718:tid 173965] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1Uoi7QGnEa1uk6m6IgAAAHQ"]
[Thu Jul 30 15:28:05.965481 2026] [security2:error] [pid 173718:tid 173871] [client 43.172.195.64:43366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/07/15/le-baume-integral-celine-escand/"] [unique_id "amuz1Uoi7QGnEa1uk6m6HgAAABY"]
[Thu Jul 30 15:28:06.137628 2026] [security2:error] [pid 173718:tid 173964] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz1koi7QGnEa1uk6m6KwAAAHM"]
[Thu Jul 30 15:28:06.430584 2026] [core:notice] [pid 173718:tid 173904] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:06.435278 2026] [security2:error] [pid 173718:tid 173904] [client 43.173.182.50:42198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/07/15/le-baume-integral-celine-escand/"] [unique_id "amuz1koi7QGnEa1uk6m6LQAAADc"], referer: https://carnetdeshopping.com/index.php/2016/07/15/le-baume-integral-celine-escand/
[Thu Jul 30 15:28:06.478919 2026] [security2:error] [pid 173718:tid 173867] [client 162.219.176.3:51112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuz1koi7QGnEa1uk6m6LgAAABI"]
[Thu Jul 30 15:28:06.479020 2026] [security2:error] [pid 173718:tid 173867] [client 162.219.176.3:51112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amuz1koi7QGnEa1uk6m6LgAAABI"]
[Thu Jul 30 15:28:06.498500 2026] [security2:error] [pid 173718:tid 173943] [client 20.171.55.167:3896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/ccx/index.php"] [unique_id "amuz1koi7QGnEa1uk6m6MAAAAF4"]
[Thu Jul 30 15:28:06.575774 2026] [security2:error] [pid 173718:tid 173858] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1koi7QGnEa1uk6m6NgAAAAk"]
[Thu Jul 30 15:28:06.596380 2026] [security2:error] [pid 173718:tid 173893] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz1koi7QGnEa1uk6m6NwAAACw"]
[Thu Jul 30 15:28:06.608643 2026] [core:notice] [pid 173718:tid 173971] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:06.671408 2026] [security2:error] [pid 173718:tid 173925] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1koi7QGnEa1uk6m6PwAAAEw"]
[Thu Jul 30 15:28:06.681988 2026] [security2:error] [pid 173718:tid 173928] [client 20.63.98.115:49506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/.well-known/index.php"] [unique_id "amuz1koi7QGnEa1uk6m6QAAAAE8"]
[Thu Jul 30 15:28:06.705593 2026] [core:notice] [pid 173718:tid 173932] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:06.762215 2026] [security2:error] [pid 173718:tid 173913] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1koi7QGnEa1uk6m6QwAAAEA"]
[Thu Jul 30 15:28:06.799802 2026] [security2:error] [pid 173718:tid 173888] [client 38.172.162.57:16017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz1koi7QGnEa1uk6m6RAAAACc"]
[Thu Jul 30 15:28:06.799909 2026] [security2:error] [pid 173718:tid 173888] [client 38.172.162.57:16017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz1koi7QGnEa1uk6m6RAAAACc"]
[Thu Jul 30 15:28:06.801054 2026] [security2:error] [pid 173718:tid 173920] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz1koi7QGnEa1uk6m6RQAAAEc"]
[Thu Jul 30 15:28:07.031550 2026] [security2:error] [pid 173718:tid 173948] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz10oi7QGnEa1uk6m6RgAAAGM"]
[Thu Jul 30 15:28:07.281485 2026] [security2:error] [pid 173718:tid 173908] [client 20.203.148.31:47197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/abcd.php"] [unique_id "amuz10oi7QGnEa1uk6m6UQAAADs"]
[Thu Jul 30 15:28:07.308914 2026] [security2:error] [pid 173718:tid 173861] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz10oi7QGnEa1uk6m6UgAAAAw"]
[Thu Jul 30 15:28:07.310052 2026] [security2:error] [pid 173718:tid 173895] [client 172.213.208.20:24397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/index.php"] [unique_id "amuz10oi7QGnEa1uk6m6UwAAAC4"]
[Thu Jul 30 15:28:07.423464 2026] [security2:error] [pid 173718:tid 173882] [client 20.171.55.167:3858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/checkbex.php"] [unique_id "amuz10oi7QGnEa1uk6m6VQAAACE"]
[Thu Jul 30 15:28:07.424015 2026] [core:notice] [pid 173718:tid 173951] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:07.436173 2026] [security2:error] [pid 173718:tid 173955] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz10oi7QGnEa1uk6m6VwAAAGo"]
[Thu Jul 30 15:28:07.438319 2026] [core:notice] [pid 173718:tid 173827] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:07.439668 2026] [security2:error] [pid 173718:tid 173827] [remote 20.118.34.237:6534] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.nordeste1.com"] [uri "/category/policiais/"] [unique_id "amuz10oi7QGnEa1uk6m6WAAAEGs"], referer: https://insurancecouncilinc.com/
[Thu Jul 30 15:28:07.555418 2026] [security2:error] [pid 173718:tid 173890] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz10oi7QGnEa1uk6m6XwAAACk"]
[Thu Jul 30 15:28:07.565256 2026] [security2:error] [pid 173718:tid 173906] [client 20.63.98.115:26033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/asasx.php"] [unique_id "amuz10oi7QGnEa1uk6m6YgAAADk"]
[Thu Jul 30 15:28:07.738047 2026] [core:error] [pid 173718:tid 173931] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:07.738067 2026] [core:error] [pid 173718:tid 173931] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:07.738159 2026] [security2:error] [pid 173718:tid 173931] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index.php"] [unique_id "amuz10oi7QGnEa1uk6m6awAAAFI"]
[Thu Jul 30 15:28:07.846341 2026] [core:notice] [pid 173718:tid 173903] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:08.161908 2026] [security2:error] [pid 173718:tid 173849] [client 172.213.208.20:19543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/network/index.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6dAAAAAA"]
[Thu Jul 30 15:28:08.162618 2026] [security2:error] [pid 173718:tid 173900] [client 20.171.55.167:3897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/class-phpmailer-http.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6dQAAADM"]
[Thu Jul 30 15:28:08.223705 2026] [security2:error] [pid 173718:tid 173899] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6ewAAADI"]
[Thu Jul 30 15:28:08.224747 2026] [security2:error] [pid 173718:tid 173852] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6fAAAAAM"]
[Thu Jul 30 15:28:08.261596 2026] [security2:error] [pid 173718:tid 173858] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wap.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6fQAAAAk"]
[Thu Jul 30 15:28:08.261688 2026] [security2:error] [pid 173718:tid 173858] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wap.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6fQAAAAk"]
[Thu Jul 30 15:28:08.311404 2026] [security2:error] [pid 173718:tid 173938] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6fgAAAFk"]
[Thu Jul 30 15:28:08.323510 2026] [core:notice] [pid 173718:tid 173930] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:08.406017 2026] [security2:error] [pid 173718:tid 173909] [client 20.203.148.31:39934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/about.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6gQAAADw"]
[Thu Jul 30 15:28:08.636769 2026] [security2:error] [pid 173718:tid 173880] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6hwAAAB8"]
[Thu Jul 30 15:28:08.766752 2026] [security2:error] [pid 173718:tid 173875] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/wp.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6jQAAABo"]
[Thu Jul 30 15:28:08.766835 2026] [security2:error] [pid 173718:tid 173875] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/wp.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6jQAAABo"]
[Thu Jul 30 15:28:08.878727 2026] [security2:error] [pid 173718:tid 173942] [client 20.171.55.167:3873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/class-wp-font-utils.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6jgAAAF0"]
[Thu Jul 30 15:28:08.887256 2026] [security2:error] [pid 173718:tid 173864] [client 20.63.98.115:42227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/user/wp-login.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6jwAAAA8"]
[Thu Jul 30 15:28:08.985681 2026] [security2:error] [pid 173718:tid 173885] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz2Eoi7QGnEa1uk6m6kAAAACQ"]
[Thu Jul 30 15:28:09.152070 2026] [security2:error] [pid 173718:tid 173941] [client 20.203.148.31:47956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/admin.php"] [unique_id "amuz2Uoi7QGnEa1uk6m6lwAAAFw"]
[Thu Jul 30 15:28:09.305708 2026] [security2:error] [pid 173718:tid 173872] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/bgymj.php"] [unique_id "amuz2Uoi7QGnEa1uk6m6ngAAABc"]
[Thu Jul 30 15:28:09.305809 2026] [security2:error] [pid 173718:tid 173872] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/bgymj.php"] [unique_id "amuz2Uoi7QGnEa1uk6m6ngAAABc"]
[Thu Jul 30 15:28:09.555433 2026] [security2:error] [pid 173718:tid 173926] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz2Uoi7QGnEa1uk6m6pAAAAE0"]
[Thu Jul 30 15:28:09.620549 2026] [security2:error] [pid 173718:tid 173889] [client 20.171.55.167:3881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/class-wp-simple-js.php"] [unique_id "amuz2Uoi7QGnEa1uk6m6pQAAACg"]
[Thu Jul 30 15:28:09.722214 2026] [security2:error] [pid 173718:tid 173870] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz2Uoi7QGnEa1uk6m6rAAAABU"]
[Thu Jul 30 15:28:09.836835 2026] [security2:error] [pid 173718:tid 173874] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/aa.php"] [unique_id "amuz2Uoi7QGnEa1uk6m6sAAAABk"]
[Thu Jul 30 15:28:09.836959 2026] [security2:error] [pid 173718:tid 173874] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/aa.php"] [unique_id "amuz2Uoi7QGnEa1uk6m6sAAAABk"]
[Thu Jul 30 15:28:10.059400 2026] [core:error] [pid 173718:tid 173891] [client 23.94.133.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:10.059426 2026] [core:error] [pid 173718:tid 173891] [client 23.94.133.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:10.281220 2026] [security2:error] [pid 173718:tid 173876] [client 20.63.98.115:49522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "amuz2koi7QGnEa1uk6m6vwAAABs"]
[Thu Jul 30 15:28:10.345500 2026] [security2:error] [pid 173718:tid 173916] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-mail.php"] [unique_id "amuz2koi7QGnEa1uk6m6wAAAAEM"]
[Thu Jul 30 15:28:10.345641 2026] [security2:error] [pid 173718:tid 173916] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-mail.php"] [unique_id "amuz2koi7QGnEa1uk6m6wAAAAEM"]
[Thu Jul 30 15:28:10.371550 2026] [security2:error] [pid 173718:tid 173858] [client 20.171.55.167:3844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/clay.php"] [unique_id "amuz2koi7QGnEa1uk6m6wQAAAAk"]
[Thu Jul 30 15:28:10.397173 2026] [security2:error] [pid 173718:tid 173877] [client 177.190.70.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-mevius.com"] [uri "/index.php"] [unique_id "amuz2Uoi7QGnEa1uk6m6oQAAABw"], referer: https://shop-mevius.com/product-tag/marlboro%E8%90%AC%E5%AF%B6%E8%B7%AF%E9%A6%99%E7%85%99%E9%8F%A1%E9%9D%A23mg%E6%97%A5%E6%9C%AC%E6%9C%AC%E5%9C%9F%E5%85%8D%E7%A8%85%E9%A6%99%E6%B8%AF%E7%8F%BE%E8%B2%A8/
[Thu Jul 30 15:28:10.752353 2026] [security2:error] [pid 173718:tid 173934] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz2koi7QGnEa1uk6m6yAAAAFU"]
[Thu Jul 30 15:28:10.754833 2026] [security2:error] [pid 173718:tid 173875] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz2koi7QGnEa1uk6m6yQAAABo"]
[Thu Jul 30 15:28:10.795230 2026] [security2:error] [pid 173718:tid 173973] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz2koi7QGnEa1uk6m6zQAAAHw"]
[Thu Jul 30 15:28:10.874519 2026] [security2:error] [pid 173718:tid 173951] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/bolt.php"] [unique_id "amuz2koi7QGnEa1uk6m60QAAAGY"]
[Thu Jul 30 15:28:10.874636 2026] [security2:error] [pid 173718:tid 173951] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/bolt.php"] [unique_id "amuz2koi7QGnEa1uk6m60QAAAGY"]
[Thu Jul 30 15:28:10.876660 2026] [security2:error] [pid 173718:tid 173948] [client 20.203.148.31:40463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/adminfuns.php"] [unique_id "amuz2koi7QGnEa1uk6m60wAAAGM"]
[Thu Jul 30 15:28:10.878412 2026] [security2:error] [pid 173718:tid 173850] [client 74.7.241.144:56246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "koplink.live.qsv.hfl.temporary.site"] [uri "/robots.txt"] [unique_id "amuz2koi7QGnEa1uk6m60gAAAAE"]
[Thu Jul 30 15:28:11.183237 2026] [security2:error] [pid 173718:tid 173955] [client 20.171.55.167:3852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/colors/about.php"] [unique_id "amuz20oi7QGnEa1uk6m61AAAAGo"]
[Thu Jul 30 15:28:11.424417 2026] [security2:error] [pid 173718:tid 173926] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/bthil.php"] [unique_id "amuz20oi7QGnEa1uk6m63gAAAE0"]
[Thu Jul 30 15:28:11.424532 2026] [security2:error] [pid 173718:tid 173926] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/bthil.php"] [unique_id "amuz20oi7QGnEa1uk6m63gAAAE0"]
[Thu Jul 30 15:28:11.837209 2026] [security2:error] [pid 173718:tid 173950] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz20oi7QGnEa1uk6m65QAAAGU"]
[Thu Jul 30 15:28:11.842888 2026] [security2:error] [pid 173718:tid 173870] [client 20.203.148.31:47131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/albin.php"] [unique_id "amuz20oi7QGnEa1uk6m65gAAABU"]
[Thu Jul 30 15:28:11.890953 2026] [security2:error] [pid 173718:tid 173871] [client 20.171.55.167:3849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/colors/blue/gold.php"] [unique_id "amuz20oi7QGnEa1uk6m66wAAABY"]
[Thu Jul 30 15:28:11.955504 2026] [cgid:error] [pid 173718:tid 173893] [client 20.9.4.9:0] AH01265: stderr from /home1/glbnyxte/public_html/website_298832dd/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 15:28:11.956214 2026] [security2:error] [pid 173718:tid 173893] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/cgi-sys/403.html"] [unique_id "amuz20oi7QGnEa1uk6m67gAAACw"]
[Thu Jul 30 15:28:12.026258 2026] [security2:error] [pid 173718:tid 173938] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m68AAAAFk"]
[Thu Jul 30 15:28:12.219307 2026] [security2:error] [pid 173718:tid 173946] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/x.php"] [unique_id "amuz3Eoi7QGnEa1uk6m68QAAAGE"]
[Thu Jul 30 15:28:12.219432 2026] [security2:error] [pid 173718:tid 173946] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/x.php"] [unique_id "amuz3Eoi7QGnEa1uk6m68QAAAGE"]
[Thu Jul 30 15:28:12.393270 2026] [security2:error] [pid 173718:tid 173905] [client 20.203.148.31:47157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/amfsqvgv.php"] [unique_id "amuz3Eoi7QGnEa1uk6m6-QAAADg"]
[Thu Jul 30 15:28:12.419491 2026] [security2:error] [pid 173718:tid 173968] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m6_AAAAHc"]
[Thu Jul 30 15:28:12.422514 2026] [security2:error] [pid 173718:tid 173851] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m6_QAAAAI"]
[Thu Jul 30 15:28:12.605267 2026] [security2:error] [pid 173718:tid 173963] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7AQAAAHI"]
[Thu Jul 30 15:28:12.605278 2026] [security2:error] [pid 173718:tid 173920] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7AAAAAEc"]
[Thu Jul 30 15:28:12.654217 2026] [security2:error] [pid 173718:tid 173884] [client 20.171.55.167:3880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/colors/coffee/alfa.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7AwAAACM"]
[Thu Jul 30 15:28:12.736458 2026] [security2:error] [pid 173718:tid 173934] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index/function.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7BAAAAFU"]
[Thu Jul 30 15:28:12.736577 2026] [security2:error] [pid 173718:tid 173934] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index/function.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7BAAAAFU"]
[Thu Jul 30 15:28:12.745335 2026] [security2:error] [pid 173718:tid 173875] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7BQAAABo"]
[Thu Jul 30 15:28:12.818575 2026] [security2:error] [pid 173718:tid 173973] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7BgAAAHw"]
[Thu Jul 30 15:28:12.852540 2026] [security2:error] [pid 173718:tid 173861] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7CgAAAAw"]
[Thu Jul 30 15:28:12.914779 2026] [security2:error] [pid 173718:tid 173850] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7DgAAAAE"]
[Thu Jul 30 15:28:12.914884 2026] [security2:error] [pid 173718:tid 173885] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7DwAAACQ"]
[Thu Jul 30 15:28:12.943231 2026] [security2:error] [pid 173718:tid 173940] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7EAAAAFs"]
[Thu Jul 30 15:28:12.989673 2026] [security2:error] [pid 173718:tid 173879] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Eoi7QGnEa1uk6m7FAAAAB4"]
[Thu Jul 30 15:28:13.129616 2026] [security2:error] [pid 173718:tid 173915] [client 20.63.98.115:42179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/radio.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7FwAAAEI"]
[Thu Jul 30 15:28:13.236032 2026] [security2:error] [pid 173718:tid 173958] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7GAAAAG0"]
[Thu Jul 30 15:28:13.268785 2026] [security2:error] [pid 173718:tid 173926] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/aaa.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7GQAAAE0"]
[Thu Jul 30 15:28:13.268878 2026] [security2:error] [pid 173718:tid 173926] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/aaa.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7GQAAAE0"]
[Thu Jul 30 15:28:13.276187 2026] [security2:error] [pid 173718:tid 173972] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7GgAAAHs"]
[Thu Jul 30 15:28:13.295963 2026] [security2:error] [pid 173718:tid 173873] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7GwAAABg"]
[Thu Jul 30 15:28:13.297501 2026] [security2:error] [pid 173718:tid 173901] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7HAAAADQ"]
[Thu Jul 30 15:28:13.323916 2026] [security2:error] [pid 173718:tid 173902] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7HQAAADU"]
[Thu Jul 30 15:28:13.402228 2026] [security2:error] [pid 173718:tid 173959] [client 20.171.55.167:3878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/colors/content.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7IQAAAG4"]
[Thu Jul 30 15:28:13.404737 2026] [security2:error] [pid 173718:tid 173950] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7IgAAAGU"]
[Thu Jul 30 15:28:13.464435 2026] [security2:error] [pid 173718:tid 173871] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7JwAAABY"]
[Thu Jul 30 15:28:13.594379 2026] [security2:error] [pid 173718:tid 173896] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7KwAAAC8"]
[Thu Jul 30 15:28:13.596241 2026] [security2:error] [pid 173718:tid 173917] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7LAAAAEQ"]
[Thu Jul 30 15:28:13.623286 2026] [security2:error] [pid 173718:tid 173867] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7LQAAABI"]
[Thu Jul 30 15:28:13.639732 2026] [security2:error] [pid 173718:tid 173965] [client 82.102.18.188:34674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "amuz3Uoi7QGnEa1uk6m7LwAAAHQ"]
[Thu Jul 30 15:28:13.782113 2026] [security2:error] [pid 173718:tid 173883] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/abcd.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7MAAAACI"]
[Thu Jul 30 15:28:13.782236 2026] [security2:error] [pid 173718:tid 173883] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/abcd.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7MAAAACI"]
[Thu Jul 30 15:28:13.820099 2026] [security2:error] [pid 173718:tid 173935] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7MQAAAFY"]
[Thu Jul 30 15:28:13.829836 2026] [security2:error] [pid 173718:tid 173866] [client 172.213.208.20:12910] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "shop-kent.com"] [uri "/wp-content/1.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7MgAAABE"]
[Thu Jul 30 15:28:13.829945 2026] [security2:error] [pid 173718:tid 173866] [client 172.213.208.20:12910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/1.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7MgAAABE"]
[Thu Jul 30 15:28:13.943142 2026] [security2:error] [pid 173718:tid 173851] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7OQAAAAI"]
[Thu Jul 30 15:28:13.947858 2026] [security2:error] [pid 173718:tid 173916] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7OgAAAEM"]
[Thu Jul 30 15:28:13.979699 2026] [security2:error] [pid 173718:tid 173897] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3Uoi7QGnEa1uk6m7PAAAADA"]
[Thu Jul 30 15:28:14.008343 2026] [security2:error] [pid 173718:tid 173868] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7PgAAABM"]
[Thu Jul 30 15:28:14.108061 2026] [security2:error] [pid 173718:tid 173876] [client 20.171.55.167:3846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/colors/midnight/about.php"] [unique_id "amuz3koi7QGnEa1uk6m7RAAAABs"]
[Thu Jul 30 15:28:14.119046 2026] [security2:error] [pid 173718:tid 173973] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7RQAAAHw"]
[Thu Jul 30 15:28:14.119421 2026] [security2:error] [pid 173718:tid 173942] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7RgAAAF0"]
[Thu Jul 30 15:28:14.241532 2026] [security2:error] [pid 173718:tid 173877] [client 82.102.18.188:46956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "amuz3koi7QGnEa1uk6m7SAAAABw"]
[Thu Jul 30 15:28:14.297601 2026] [security2:error] [pid 173718:tid 173951] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7SQAAAGY"]
[Thu Jul 30 15:28:14.321837 2026] [security2:error] [pid 173718:tid 173952] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-good.php"] [unique_id "amuz3koi7QGnEa1uk6m7SgAAAGc"]
[Thu Jul 30 15:28:14.321937 2026] [security2:error] [pid 173718:tid 173952] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-good.php"] [unique_id "amuz3koi7QGnEa1uk6m7SgAAAGc"]
[Thu Jul 30 15:28:14.343460 2026] [security2:error] [pid 173718:tid 173921] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7SwAAAEg"]
[Thu Jul 30 15:28:14.435821 2026] [core:notice] [pid 173718:tid 173970] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:14.439089 2026] [security2:error] [pid 173718:tid 173970] [client 66.249.79.229:49093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/JSTE/article/view/6555/2717"] [unique_id "amuz3koi7QGnEa1uk6m7UAAAAHk"]
[Thu Jul 30 15:28:14.442416 2026] [security2:error] [pid 173718:tid 173912] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7UQAAAD8"]
[Thu Jul 30 15:28:14.487830 2026] [security2:error] [pid 173718:tid 173955] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7UgAAAGo"]
[Thu Jul 30 15:28:14.516988 2026] [security2:error] [pid 173718:tid 173953] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7VgAAAGg"]
[Thu Jul 30 15:28:14.657860 2026] [core:notice] [pid 173718:tid 173781] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:14.661544 2026] [security2:error] [pid 173718:tid 173974] [client 20.63.98.115:33600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/plugins/about.php"] [unique_id "amuz3koi7QGnEa1uk6m7WgAAAH0"]
[Thu Jul 30 15:28:14.679028 2026] [security2:error] [pid 173718:tid 173901] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7WwAAADQ"]
[Thu Jul 30 15:28:14.734172 2026] [security2:error] [pid 173718:tid 173902] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7XAAAADU"]
[Thu Jul 30 15:28:14.806942 2026] [security2:error] [pid 173718:tid 173878] [client 20.171.55.167:3843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/colors/tfileman.php"] [unique_id "amuz3koi7QGnEa1uk6m7XQAAAB0"]
[Thu Jul 30 15:28:14.821772 2026] [security2:error] [pid 173718:tid 173910] [client 111.225.148.92:41934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/"] [unique_id "amuz3koi7QGnEa1uk6m7XgAAAD0"]
[Thu Jul 30 15:28:14.862281 2026] [security2:error] [pid 173718:tid 173922] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/simple.php"] [unique_id "amuz3koi7QGnEa1uk6m7YQAAAEk"]
[Thu Jul 30 15:28:14.862361 2026] [security2:error] [pid 173718:tid 173922] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/simple.php"] [unique_id "amuz3koi7QGnEa1uk6m7YQAAAEk"]
[Thu Jul 30 15:28:14.921603 2026] [security2:error] [pid 173718:tid 173950] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz3koi7QGnEa1uk6m7ZAAAAGU"]
[Thu Jul 30 15:28:15.027914 2026] [security2:error] [pid 173718:tid 173853] [client 172.213.208.20:52538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/plugin.php"] [unique_id "amuz30oi7QGnEa1uk6m7aQAAAAQ"]
[Thu Jul 30 15:28:15.086441 2026] [security2:error] [pid 173718:tid 173947] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7agAAAGI"]
[Thu Jul 30 15:28:15.087290 2026] [security2:error] [pid 173718:tid 173891] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7awAAACo"]
[Thu Jul 30 15:28:15.169914 2026] [security2:error] [pid 173718:tid 173965] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7bwAAAHQ"]
[Thu Jul 30 15:28:15.173195 2026] [security2:error] [pid 173718:tid 173937] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7cAAAAFg"]
[Thu Jul 30 15:28:15.264349 2026] [security2:error] [pid 173718:tid 173935] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7cQAAAFY"]
[Thu Jul 30 15:28:15.409192 2026] [security2:error] [pid 173718:tid 173928] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/edit-tags.php"] [unique_id "amuz30oi7QGnEa1uk6m7cgAAAE8"]
[Thu Jul 30 15:28:15.409312 2026] [security2:error] [pid 173718:tid 173928] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/edit-tags.php"] [unique_id "amuz30oi7QGnEa1uk6m7cgAAAE8"]
[Thu Jul 30 15:28:15.461685 2026] [security2:error] [pid 173718:tid 173971] [client 82.102.18.188:46978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "amuz30oi7QGnEa1uk6m7dQAAAHo"]
[Thu Jul 30 15:28:15.573155 2026] [security2:error] [pid 173718:tid 173858] [client 20.171.55.167:3875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/componentsadmin.php"] [unique_id "amuz30oi7QGnEa1uk6m7dwAAAAk"]
[Thu Jul 30 15:28:15.591293 2026] [security2:error] [pid 173718:tid 173923] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7egAAAEo"]
[Thu Jul 30 15:28:15.637621 2026] [security2:error] [pid 173718:tid 173869] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7fAAAABQ"]
[Thu Jul 30 15:28:15.675646 2026] [security2:error] [pid 173718:tid 173925] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7fwAAAEw"]
[Thu Jul 30 15:28:15.722389 2026] [security2:error] [pid 173718:tid 173857] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7gQAAAAg"]
[Thu Jul 30 15:28:15.845588 2026] [security2:error] [pid 173718:tid 173934] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7ggAAAFU"]
[Thu Jul 30 15:28:15.895254 2026] [security2:error] [pid 173718:tid 173961] [client 20.63.98.115:42209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/st.php"] [unique_id "amuz30oi7QGnEa1uk6m7gwAAAHA"]
[Thu Jul 30 15:28:15.968455 2026] [security2:error] [pid 173718:tid 173877] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/u.php"] [unique_id "amuz30oi7QGnEa1uk6m7hwAAABw"]
[Thu Jul 30 15:28:15.968550 2026] [security2:error] [pid 173718:tid 173877] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/u.php"] [unique_id "amuz30oi7QGnEa1uk6m7hwAAABw"]
[Thu Jul 30 15:28:15.986957 2026] [security2:error] [pid 173718:tid 173951] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz30oi7QGnEa1uk6m7iAAAAGY"]
[Thu Jul 30 15:28:16.059592 2026] [security2:error] [pid 173718:tid 173881] [client 82.102.18.188:24472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "amuz4Eoi7QGnEa1uk6m7jQAAACA"]
[Thu Jul 30 15:28:16.085342 2026] [security2:error] [pid 173718:tid 173882] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7jgAAACE"]
[Thu Jul 30 15:28:16.166318 2026] [security2:error] [pid 173718:tid 173890] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7jwAAACk"]
[Thu Jul 30 15:28:16.180733 2026] [security2:error] [pid 173718:tid 173953] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7kQAAAGg"]
[Thu Jul 30 15:28:16.272953 2026] [security2:error] [pid 173718:tid 173921] [client 20.171.55.167:3871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/connector.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7lAAAAEg"]
[Thu Jul 30 15:28:16.314513 2026] [core:notice] [pid 173718:tid 173944] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:16.324694 2026] [core:error] [pid 173718:tid 173944] [client 66.249.74.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:16.324849 2026] [security2:error] [pid 173718:tid 173944] [client 66.249.74.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/13/15.html.html.html.html.html.html.html.html.html.html"] [unique_id "amuz4Eoi7QGnEa1uk6m7jAAAAF8"]
[Thu Jul 30 15:28:16.475811 2026] [security2:error] [pid 173718:tid 173902] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/admin.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7lwAAADU"]
[Thu Jul 30 15:28:16.475908 2026] [security2:error] [pid 173718:tid 173902] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/admin.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7lwAAADU"]
[Thu Jul 30 15:28:16.556335 2026] [security2:error] [pid 173718:tid 173874] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7nAAAABk"]
[Thu Jul 30 15:28:16.665153 2026] [security2:error] [pid 173718:tid 173873] [client 82.102.18.188:46992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amuz4Eoi7QGnEa1uk6m7nQAAABg"]
[Thu Jul 30 15:28:16.721700 2026] [security2:error] [pid 173718:tid 173852] [client 216.244.66.236:55796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dhowcruisedinner.com"] [uri "/yzryc/british-museum-upcoming-exhibitions-2023"] [unique_id "amuz4Eoi7QGnEa1uk6m7oQAAAAM"]
[Thu Jul 30 15:28:16.721877 2026] [security2:error] [pid 173718:tid 173852] [client 216.244.66.236:55796] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dhowcruisedinner.com"] [uri "/yzryc/british-museum-upcoming-exhibitions-2023"] [unique_id "amuz4Eoi7QGnEa1uk6m7oQAAAAM"]
[Thu Jul 30 15:28:16.815088 2026] [security2:error] [pid 173718:tid 173918] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7ogAAAEU"]
[Thu Jul 30 15:28:16.998450 2026] [security2:error] [pid 173718:tid 173871] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/h.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7owAAABY"]
[Thu Jul 30 15:28:16.998563 2026] [security2:error] [pid 173718:tid 173871] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/h.php"] [unique_id "amuz4Eoi7QGnEa1uk6m7owAAABY"]
[Thu Jul 30 15:28:17.024774 2026] [security2:error] [pid 173718:tid 173974] [client 20.203.148.31:39919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/ant.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7pAAAAH0"]
[Thu Jul 30 15:28:17.160300 2026] [security2:error] [pid 173718:tid 173866] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7rgAAABE"]
[Thu Jul 30 15:28:17.257172 2026] [security2:error] [pid 173718:tid 173904] [client 82.102.18.188:47004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "amuz4Uoi7QGnEa1uk6m7sgAAADc"]
[Thu Jul 30 15:28:17.312104 2026] [security2:error] [pid 173718:tid 173891] [client 20.171.55.167:3900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/corealfa.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7tAAAACo"]
[Thu Jul 30 15:28:17.448369 2026] [security2:error] [pid 173718:tid 173899] [client 38.172.162.57:16235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7tQAAADI"]
[Thu Jul 30 15:28:17.448519 2026] [security2:error] [pid 173718:tid 173899] [client 38.172.162.57:16235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7tQAAADI"]
[Thu Jul 30 15:28:17.473755 2026] [security2:error] [pid 173718:tid 173968] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7tgAAAHc"]
[Thu Jul 30 15:28:17.520670 2026] [security2:error] [pid 173718:tid 173916] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ms-edit.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7twAAAEM"]
[Thu Jul 30 15:28:17.520765 2026] [security2:error] [pid 173718:tid 173916] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ms-edit.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7twAAAEM"]
[Thu Jul 30 15:28:17.550231 2026] [security2:error] [pid 173718:tid 173868] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7uwAAABM"]
[Thu Jul 30 15:28:17.601870 2026] [security2:error] [pid 173718:tid 173920] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7vAAAAEc"]
[Thu Jul 30 15:28:17.631561 2026] [security2:error] [pid 173718:tid 173927] [client 204.8.98.55:52350] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7wAAAAE4"]
[Thu Jul 30 15:28:17.631637 2026] [security2:error] [pid 173718:tid 173927] [client 204.8.98.55:52350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7wAAAAE4"]
[Thu Jul 30 15:28:17.704174 2026] [security2:error] [pid 173718:tid 173897] [client 20.63.98.115:48405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/about.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7wQAAADA"]
[Thu Jul 30 15:28:17.777767 2026] [security2:error] [pid 173718:tid 173855] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7xgAAAAY"]
[Thu Jul 30 15:28:17.777820 2026] [security2:error] [pid 173718:tid 173951] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7xQAAAGY"]
[Thu Jul 30 15:28:17.856151 2026] [security2:error] [pid 173718:tid 173925] [client 82.102.18.188:47014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "amuz4Uoi7QGnEa1uk6m7xwAAAEw"]
[Thu Jul 30 15:28:17.891723 2026] [security2:error] [pid 173718:tid 173940] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz4Uoi7QGnEa1uk6m7yAAAAFs"]
[Thu Jul 30 15:28:18.030134 2026] [security2:error] [pid 173718:tid 173912] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/a7.php"] [unique_id "amuz4koi7QGnEa1uk6m7ygAAAD8"]
[Thu Jul 30 15:28:18.030254 2026] [security2:error] [pid 173718:tid 173912] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/a7.php"] [unique_id "amuz4koi7QGnEa1uk6m7ygAAAD8"]
[Thu Jul 30 15:28:18.052653 2026] [security2:error] [pid 173718:tid 173890] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4koi7QGnEa1uk6m7ywAAACk"]
[Thu Jul 30 15:28:18.095059 2026] [security2:error] [pid 173718:tid 173881] [client 20.171.55.167:3853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/csv.php"] [unique_id "amuz4koi7QGnEa1uk6m7zwAAACA"]
[Thu Jul 30 15:28:18.139225 2026] [core:notice] [pid 173718:tid 173948] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:18.224685 2026] [security2:error] [pid 173718:tid 173926] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4koi7QGnEa1uk6m71AAAAE0"]
[Thu Jul 30 15:28:18.252169 2026] [security2:error] [pid 173718:tid 173894] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz4koi7QGnEa1uk6m72AAAAC0"]
[Thu Jul 30 15:28:18.384814 2026] [security2:error] [pid 173718:tid 173898] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4koi7QGnEa1uk6m72QAAADE"]
[Thu Jul 30 15:28:18.427850 2026] [security2:error] [pid 173718:tid 173903] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz4koi7QGnEa1uk6m72gAAADY"]
[Thu Jul 30 15:28:18.461489 2026] [security2:error] [pid 173718:tid 173872] [client 82.102.18.188:47020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "amuz4koi7QGnEa1uk6m72wAAABc"]
[Thu Jul 30 15:28:18.557821 2026] [security2:error] [pid 173718:tid 173958] [client 20.63.98.115:29735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/admin.php"] [unique_id "amuz4koi7QGnEa1uk6m73AAAAG0"]
[Thu Jul 30 15:28:18.566233 2026] [security2:error] [pid 173718:tid 173957] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/manager.php"] [unique_id "amuz4koi7QGnEa1uk6m73QAAAGw"]
[Thu Jul 30 15:28:18.566311 2026] [security2:error] [pid 173718:tid 173957] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/manager.php"] [unique_id "amuz4koi7QGnEa1uk6m73QAAAGw"]
[Thu Jul 30 15:28:18.685172 2026] [security2:error] [pid 173718:tid 173918] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4koi7QGnEa1uk6m74gAAAEU"]
[Thu Jul 30 15:28:18.694165 2026] [security2:error] [pid 173718:tid 173892] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4koi7QGnEa1uk6m75AAAACs"]
[Thu Jul 30 15:28:18.716503 2026] [security2:error] [pid 173718:tid 173964] [client 20.203.148.31:40481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/appreciators.php"] [unique_id "amuz4koi7QGnEa1uk6m75gAAAHM"]
[Thu Jul 30 15:28:18.793494 2026] [security2:error] [pid 173718:tid 173931] [client 20.171.55.167:3863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/data.php"] [unique_id "amuz4koi7QGnEa1uk6m75wAAAFI"]
[Thu Jul 30 15:28:18.965152 2026] [security2:error] [pid 173718:tid 173946] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz4koi7QGnEa1uk6m76wAAAGE"]
[Thu Jul 30 15:28:18.966445 2026] [core:notice] [pid 173718:tid 173949] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:18.974424 2026] [security2:error] [pid 173718:tid 173883] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz4koi7QGnEa1uk6m77QAAACI"]
[Thu Jul 30 15:28:19.064741 2026] [security2:error] [pid 173718:tid 173928] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz40oi7QGnEa1uk6m78QAAAE8"]
[Thu Jul 30 15:28:19.072789 2026] [security2:error] [pid 173718:tid 173975] [client 82.102.18.188:47026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "amuz40oi7QGnEa1uk6m78gAAAH4"]
[Thu Jul 30 15:28:19.089546 2026] [security2:error] [pid 173718:tid 173858] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/w1.php"] [unique_id "amuz40oi7QGnEa1uk6m78wAAAAk"]
[Thu Jul 30 15:28:19.089626 2026] [security2:error] [pid 173718:tid 173858] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/w1.php"] [unique_id "amuz40oi7QGnEa1uk6m78wAAAAk"]
[Thu Jul 30 15:28:19.228064 2026] [security2:error] [pid 173718:tid 173945] [client 196.75.110.110:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.nexiummedication.store"] [uri "/index.php"] [unique_id "amuz40oi7QGnEa1uk6m7-gAAAGA"]
[Thu Jul 30 15:28:19.249458 2026] [security2:error] [pid 173718:tid 173971] [client 20.63.98.115:48422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/css/admin.php"] [unique_id "amuz40oi7QGnEa1uk6m7-wAAAHo"]
[Thu Jul 30 15:28:19.294794 2026] [security2:error] [pid 173718:tid 173968] [client 20.203.148.31:50908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/archive.php"] [unique_id "amuz40oi7QGnEa1uk6m7_AAAAHc"]
[Thu Jul 30 15:28:19.372781 2026] [security2:error] [pid 173718:tid 173897] [client 196.75.110.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.110.75.196.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.buyfluoxetine.store"] [uri "/index.php"] [unique_id "amuz40oi7QGnEa1uk6m8AAAAADA"]
[Thu Jul 30 15:28:19.574273 2026] [security2:error] [pid 173718:tid 173934] [client 20.171.55.167:3672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/deeto/login.php"] [unique_id "amuz40oi7QGnEa1uk6m8AQAAAFU"]
[Thu Jul 30 15:28:19.595322 2026] [core:error] [pid 173718:tid 173861] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:19.595340 2026] [core:error] [pid 173718:tid 173861] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:19.595430 2026] [security2:error] [pid 173718:tid 173861] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index.php"] [unique_id "amuz40oi7QGnEa1uk6m8AgAAAAw"]
[Thu Jul 30 15:28:19.679212 2026] [security2:error] [pid 173718:tid 173961] [client 82.102.18.188:47028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "amuz40oi7QGnEa1uk6m8BgAAAHA"]
[Thu Jul 30 15:28:19.860341 2026] [core:notice] [pid 173718:tid 173973] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:19.864085 2026] [security2:error] [pid 173718:tid 173973] [client 66.249.79.229:35633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/8528/3863"] [unique_id "amuz40oi7QGnEa1uk6m8DQAAAHw"]
[Thu Jul 30 15:28:20.008854 2026] [security2:error] [pid 173718:tid 173915] [client 112.86.225.116:33538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product-category/sneaker/nike-sneaker/shox/"] [unique_id "amuz5Eoi7QGnEa1uk6m8DgAAAEI"]
[Thu Jul 30 15:28:20.009033 2026] [security2:error] [pid 173718:tid 173915] [client 112.86.225.116:33538] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product-category/sneaker/nike-sneaker/shox/"] [unique_id "amuz5Eoi7QGnEa1uk6m8DgAAAEI"]
[Thu Jul 30 15:28:20.154092 2026] [security2:error] [pid 173718:tid 173888] [client 172.213.208.20:37927] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "shop-kent.com"] [uri "/1.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8EQAAACc"]
[Thu Jul 30 15:28:20.154207 2026] [security2:error] [pid 173718:tid 173888] [client 172.213.208.20:37927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/1.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8EQAAACc"]
[Thu Jul 30 15:28:20.280963 2026] [security2:error] [pid 173718:tid 173921] [client 82.102.18.188:47040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "amuz5Eoi7QGnEa1uk6m8FwAAAEg"]
[Thu Jul 30 15:28:20.294100 2026] [security2:error] [pid 173718:tid 173894] [client 20.171.55.167:3858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/dex.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8GAAAAC0"]
[Thu Jul 30 15:28:20.341794 2026] [security2:error] [pid 173718:tid 173878] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-login.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8DwAAAB0"]
[Thu Jul 30 15:28:20.341919 2026] [security2:error] [pid 173718:tid 173878] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-login.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8DwAAAB0"]
[Thu Jul 30 15:28:20.484987 2026] [security2:error] [pid 173718:tid 173944] [client 20.63.98.115:42197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8HQAAAF8"]
[Thu Jul 30 15:28:20.788262 2026] [security2:error] [pid 173718:tid 173950] [client 172.213.208.20:12576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/gg.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8IQAAAGU"]
[Thu Jul 30 15:28:20.868504 2026] [security2:error] [pid 173718:tid 173947] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/default.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8JQAAAGI"]
[Thu Jul 30 15:28:20.868610 2026] [security2:error] [pid 173718:tid 173947] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/default.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8JQAAAGI"]
[Thu Jul 30 15:28:20.875964 2026] [security2:error] [pid 173718:tid 173918] [client 82.102.18.188:47044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amuz5Eoi7QGnEa1uk6m8JwAAAEU"]
[Thu Jul 30 15:28:20.998581 2026] [security2:error] [pid 173718:tid 173852] [client 20.171.55.167:3841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/dist/niil.php"] [unique_id "amuz5Eoi7QGnEa1uk6m8KwAAAAM"]
[Thu Jul 30 15:28:21.183769 2026] [core:notice] [pid 173718:tid 173905] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:21.382718 2026] [security2:error] [pid 173718:tid 173868] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/i.php"] [unique_id "amuz5Uoi7QGnEa1uk6m8MwAAABM"]
[Thu Jul 30 15:28:21.382826 2026] [security2:error] [pid 173718:tid 173868] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/i.php"] [unique_id "amuz5Uoi7QGnEa1uk6m8MwAAABM"]
[Thu Jul 30 15:28:21.467162 2026] [security2:error] [pid 173718:tid 173860] [client 82.102.18.188:47052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "amuz5Uoi7QGnEa1uk6m8OAAAAAs"]
[Thu Jul 30 15:28:21.773242 2026] [security2:error] [pid 173718:tid 173962] [client 20.171.55.167:3856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/docswp.php"] [unique_id "amuz5Uoi7QGnEa1uk6m8PAAAAHE"]
[Thu Jul 30 15:28:21.913031 2026] [core:error] [pid 173718:tid 173908] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:21.913064 2026] [core:error] [pid 173718:tid 173908] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:21.913153 2026] [security2:error] [pid 173718:tid 173908] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index.php"] [unique_id "amuz5Uoi7QGnEa1uk6m8QAAAADs"]
[Thu Jul 30 15:28:22.044989 2026] [autoindex:error] [pid 173718:tid 173940] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/images/crystal/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:22.066050 2026] [security2:error] [pid 173718:tid 173875] [client 82.102.18.188:47058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "amuz5koi7QGnEa1uk6m8RwAAABo"]
[Thu Jul 30 15:28:22.174547 2026] [security2:error] [pid 173718:tid 173865] [client 172.213.208.20:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp.php"] [unique_id "amuz5koi7QGnEa1uk6m8SAAAABA"]
[Thu Jul 30 15:28:22.446891 2026] [security2:error] [pid 173718:tid 173888] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amuz5koi7QGnEa1uk6m8UAAAACc"]
[Thu Jul 30 15:28:22.447034 2026] [security2:error] [pid 173718:tid 173888] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "amuz5koi7QGnEa1uk6m8UAAAACc"]
[Thu Jul 30 15:28:22.489563 2026] [security2:error] [pid 173718:tid 173973] [client 20.171.55.167:3860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/dr.php"] [unique_id "amuz5koi7QGnEa1uk6m8VAAAAHw"]
[Thu Jul 30 15:28:22.661433 2026] [security2:error] [pid 173718:tid 173926] [client 82.102.18.188:47066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amuz5koi7QGnEa1uk6m8VQAAAE0"]
[Thu Jul 30 15:28:22.683306 2026] [security2:error] [pid 173718:tid 173898] [client 172.213.208.20:12589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amuz5koi7QGnEa1uk6m8VgAAADE"]
[Thu Jul 30 15:28:22.967111 2026] [security2:error] [pid 173718:tid 173853] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/index.php"] [unique_id "amuz5koi7QGnEa1uk6m8YAAAAAQ"]
[Thu Jul 30 15:28:22.967210 2026] [security2:error] [pid 173718:tid 173853] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/themes/index.php"] [unique_id "amuz5koi7QGnEa1uk6m8YAAAAAQ"]
[Thu Jul 30 15:28:23.206057 2026] [security2:error] [pid 173718:tid 173965] [client 172.213.208.20:50519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/file.php"] [unique_id "amuz50oi7QGnEa1uk6m8YgAAAHQ"]
[Thu Jul 30 15:28:23.237303 2026] [security2:error] [pid 173718:tid 173947] [client 20.171.55.167:3882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/editor/filemanager/updates.php"] [unique_id "amuz50oi7QGnEa1uk6m8YwAAAGI"]
[Thu Jul 30 15:28:23.264217 2026] [security2:error] [pid 173718:tid 173892] [client 82.102.18.188:47080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "amuz50oi7QGnEa1uk6m8ZwAAACs"]
[Thu Jul 30 15:28:23.508049 2026] [security2:error] [pid 173718:tid 173917] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/gecko-new.php"] [unique_id "amuz50oi7QGnEa1uk6m8bgAAAEQ"]
[Thu Jul 30 15:28:23.508156 2026] [security2:error] [pid 173718:tid 173917] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/gecko-new.php"] [unique_id "amuz50oi7QGnEa1uk6m8bgAAAEQ"]
[Thu Jul 30 15:28:23.773361 2026] [proxy:error] [pid 173718:tid 173869] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:23.773484 2026] [proxy_http:error] [pid 173718:tid 173869] [client 45.92.85.50:34411] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:23.774654 2026] [proxy:error] [pid 173718:tid 173869] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:23.774724 2026] [proxy_http:error] [pid 173718:tid 173869] [client 45.92.85.50:34411] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:23.872379 2026] [security2:error] [pid 173718:tid 173909] [client 82.102.18.188:47084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "amuz50oi7QGnEa1uk6m8dAAAADw"]
[Thu Jul 30 15:28:23.940210 2026] [security2:error] [pid 173718:tid 173916] [client 20.171.55.167:3650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/epinyins.php"] [unique_id "amuz50oi7QGnEa1uk6m8dQAAAEM"]
[Thu Jul 30 15:28:24.028319 2026] [security2:error] [pid 173718:tid 173908] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/NewFile.php"] [unique_id "amuz6Eoi7QGnEa1uk6m8fAAAADs"]
[Thu Jul 30 15:28:24.028424 2026] [security2:error] [pid 173718:tid 173908] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/NewFile.php"] [unique_id "amuz6Eoi7QGnEa1uk6m8fAAAADs"]
[Thu Jul 30 15:28:24.261940 2026] [proxy:error] [pid 173718:tid 173970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:24.262023 2026] [proxy_http:error] [pid 173718:tid 173970] [client 45.92.85.50:45075] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:24.262599 2026] [proxy:error] [pid 173718:tid 173970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:24.262641 2026] [proxy_http:error] [pid 173718:tid 173970] [client 45.92.85.50:45075] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:24.470578 2026] [security2:error] [pid 173718:tid 173882] [client 82.102.18.188:53870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.pvl.djb.temporary.site"] [uri "/autodiscover/autodiscover.xml/sito/wp-includes/wlwmanifest.xml"] [unique_id "amuz6Eoi7QGnEa1uk6m8iAAAACE"]
[Thu Jul 30 15:28:24.532569 2026] [security2:error] [pid 173718:tid 173888] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-Blogs.php"] [unique_id "amuz6Eoi7QGnEa1uk6m8jAAAACc"]
[Thu Jul 30 15:28:24.532665 2026] [security2:error] [pid 173718:tid 173888] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-Blogs.php"] [unique_id "amuz6Eoi7QGnEa1uk6m8jAAAACc"]
[Thu Jul 30 15:28:24.709404 2026] [security2:error] [pid 173718:tid 173906] [client 20.171.55.167:3898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/extension/extension/cloud.php"] [unique_id "amuz6Eoi7QGnEa1uk6m8jQAAADk"]
[Thu Jul 30 15:28:24.751459 2026] [security2:error] [pid 173718:tid 173914] [client 20.63.98.115:49509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp2.php"] [unique_id "amuz6Eoi7QGnEa1uk6m8jgAAAEE"]
[Thu Jul 30 15:28:24.893547 2026] [security2:error] [pid 173718:tid 173806] [remote 216.73.216.51:35778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuz6Eoi7QGnEa1uk6m8kgAAPlY"]
[Thu Jul 30 15:28:25.081921 2026] [security2:error] [pid 173718:tid 173853] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-includes/fonts/index.php"] [unique_id "amuz6Uoi7QGnEa1uk6m8mgAAAAQ"]
[Thu Jul 30 15:28:25.082041 2026] [security2:error] [pid 173718:tid 173853] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-includes/fonts/index.php"] [unique_id "amuz6Uoi7QGnEa1uk6m8mgAAAAQ"]
[Thu Jul 30 15:28:25.183345 2026] [proxy:error] [pid 173718:tid 173874] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:25.183447 2026] [proxy_http:error] [pid 173718:tid 173874] [client 45.92.87.40:39705] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:25.184023 2026] [proxy:error] [pid 173718:tid 173874] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:25.184067 2026] [proxy_http:error] [pid 173718:tid 173874] [client 45.92.87.40:39705] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:25.474283 2026] [security2:error] [pid 173718:tid 173931] [client 20.171.55.167:3845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/fedora.php"] [unique_id "amuz6Uoi7QGnEa1uk6m8oQAAAFI"]
[Thu Jul 30 15:28:25.593763 2026] [security2:error] [pid 173718:tid 173905] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/themes.php"] [unique_id "amuz6Uoi7QGnEa1uk6m8pgAAADg"]
[Thu Jul 30 15:28:25.593858 2026] [security2:error] [pid 173718:tid 173905] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/themes.php"] [unique_id "amuz6Uoi7QGnEa1uk6m8pgAAADg"]
[Thu Jul 30 15:28:25.781418 2026] [fcgid:warn] [pid 173718:tid 173858] (70014)End of file found: [client 18.218.118.203:61160] mod_fcgid: can't get data from http client
[Thu Jul 30 15:28:26.093955 2026] [security2:error] [pid 173718:tid 173974] [client 20.63.98.115:36419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/s.php"] [unique_id "amuz6koi7QGnEa1uk6m8sQAAAH0"]
[Thu Jul 30 15:28:26.126915 2026] [security2:error] [pid 173718:tid 173945] [client 172.213.208.20:52505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/user/index.php"] [unique_id "amuz6koi7QGnEa1uk6m8sgAAAGA"]
[Thu Jul 30 15:28:26.135499 2026] [security2:error] [pid 173718:tid 173916] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/cv.php"] [unique_id "amuz6koi7QGnEa1uk6m8swAAAEM"]
[Thu Jul 30 15:28:26.135575 2026] [security2:error] [pid 173718:tid 173916] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/cv.php"] [unique_id "amuz6koi7QGnEa1uk6m8swAAAEM"]
[Thu Jul 30 15:28:26.192286 2026] [security2:error] [pid 173718:tid 173884] [client 20.171.55.167:3888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/file8.php"] [unique_id "amuz6koi7QGnEa1uk6m8twAAACM"]
[Thu Jul 30 15:28:26.212412 2026] [proxy:error] [pid 173718:tid 173963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:26.212484 2026] [proxy_http:error] [pid 173718:tid 173963] [client 45.92.87.40:41735] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:26.213083 2026] [proxy:error] [pid 173718:tid 173963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:26.213129 2026] [proxy_http:error] [pid 173718:tid 173963] [client 45.92.87.40:41735] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:26.652478 2026] [core:error] [pid 173718:tid 173970] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:26.652501 2026] [core:error] [pid 173718:tid 173970] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:26.652600 2026] [security2:error] [pid 173718:tid 173970] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index.php"] [unique_id "amuz6koi7QGnEa1uk6m8vwAAAHk"]
[Thu Jul 30 15:28:26.950629 2026] [security2:error] [pid 173718:tid 173881] [client 20.171.55.167:3668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/filefuns.php"] [unique_id "amuz6koi7QGnEa1uk6m8xgAAACA"]
[Thu Jul 30 15:28:27.167713 2026] [security2:error] [pid 173718:tid 173902] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/uploads/index.php"] [unique_id "amuz60oi7QGnEa1uk6m8zgAAADU"]
[Thu Jul 30 15:28:27.167857 2026] [security2:error] [pid 173718:tid 173902] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-content/uploads/index.php"] [unique_id "amuz60oi7QGnEa1uk6m8zgAAADU"]
[Thu Jul 30 15:28:27.175324 2026] [security2:error] [pid 173718:tid 173972] [client 216.244.66.199:56270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2013_11_20_archive.html"] [unique_id "amuz60oi7QGnEa1uk6m8zwAAAHs"]
[Thu Jul 30 15:28:27.175486 2026] [security2:error] [pid 173718:tid 173972] [client 216.244.66.199:56270] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2013_11_20_archive.html"] [unique_id "amuz60oi7QGnEa1uk6m8zwAAAHs"]
[Thu Jul 30 15:28:27.586505 2026] [security2:error] [pid 173718:tid 173948] [client 172.213.208.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuz6koi7QGnEa1uk6m8xQAAAGM"]
[Thu Jul 30 15:28:27.671180 2026] [security2:error] [pid 173718:tid 173915] [client 20.203.148.31:39870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/as.php"] [unique_id "amuz60oi7QGnEa1uk6m83wAAAEI"]
[Thu Jul 30 15:28:27.681626 2026] [security2:error] [pid 173718:tid 173958] [client 20.171.55.167:3693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/flame.php"] [unique_id "amuz60oi7QGnEa1uk6m84AAAAG0"]
[Thu Jul 30 15:28:27.700947 2026] [security2:error] [pid 173718:tid 173863] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ws83.php"] [unique_id "amuz60oi7QGnEa1uk6m84wAAAA4"]
[Thu Jul 30 15:28:27.701052 2026] [security2:error] [pid 173718:tid 173863] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ws83.php"] [unique_id "amuz60oi7QGnEa1uk6m84wAAAA4"]
[Thu Jul 30 15:28:27.943463 2026] [security2:error] [pid 173718:tid 173856] [client 172.213.208.20:53463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amuz60oi7QGnEa1uk6m85gAAAAc"]
[Thu Jul 30 15:28:28.052427 2026] [security2:error] [pid 173718:tid 173853] [client 38.172.162.57:16113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz7Eoi7QGnEa1uk6m87AAAAAQ"]
[Thu Jul 30 15:28:28.052521 2026] [security2:error] [pid 173718:tid 173853] [client 38.172.162.57:16113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz7Eoi7QGnEa1uk6m87AAAAAQ"]
[Thu Jul 30 15:28:28.221569 2026] [security2:error] [pid 173718:tid 173974] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/atex1.php"] [unique_id "amuz7Eoi7QGnEa1uk6m89AAAAH0"]
[Thu Jul 30 15:28:28.221709 2026] [security2:error] [pid 173718:tid 173974] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/atex1.php"] [unique_id "amuz7Eoi7QGnEa1uk6m89AAAAH0"]
[Thu Jul 30 15:28:28.647624 2026] [security2:error] [pid 173718:tid 173909] [client 20.171.55.167:3699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/fucku.php"] [unique_id "amuz7Eoi7QGnEa1uk6m8_AAAADw"]
[Thu Jul 30 15:28:28.741567 2026] [security2:error] [pid 173718:tid 173929] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/class-t.api.php"] [unique_id "amuz7Eoi7QGnEa1uk6m9AgAAAFA"]
[Thu Jul 30 15:28:28.741700 2026] [security2:error] [pid 173718:tid 173929] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/class-t.api.php"] [unique_id "amuz7Eoi7QGnEa1uk6m9AgAAAFA"]
[Thu Jul 30 15:28:29.143956 2026] [security2:error] [pid 173718:tid 173918] [client 20.63.98.115:26383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/help.php"] [unique_id "amuz7Uoi7QGnEa1uk6m9DQAAAEU"]
[Thu Jul 30 15:28:29.264755 2026] [security2:error] [pid 173718:tid 173901] [client 20.203.148.31:47821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/atomlib.php"] [unique_id "amuz7Uoi7QGnEa1uk6m9EwAAADQ"]
[Thu Jul 30 15:28:29.275059 2026] [security2:error] [pid 173718:tid 173912] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/w.php"] [unique_id "amuz7Uoi7QGnEa1uk6m9FQAAAD8"]
[Thu Jul 30 15:28:29.275154 2026] [security2:error] [pid 173718:tid 173912] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/w.php"] [unique_id "amuz7Uoi7QGnEa1uk6m9FQAAAD8"]
[Thu Jul 30 15:28:29.380255 2026] [security2:error] [pid 173718:tid 173906] [client 20.171.55.167:3855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/gecko-new.php"] [unique_id "amuz7Uoi7QGnEa1uk6m9GAAAADk"]
[Thu Jul 30 15:28:29.454001 2026] [security2:error] [pid 173718:tid 173756] [remote 216.73.216.51:35778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amuz7Uoi7QGnEa1uk6m9GQAAXyQ"]
[Thu Jul 30 15:28:29.856477 2026] [security2:error] [pid 173718:tid 173930] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/archive.php"] [unique_id "amuz7Uoi7QGnEa1uk6m9JgAAAFE"]
[Thu Jul 30 15:28:29.856621 2026] [security2:error] [pid 173718:tid 173930] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/archive.php"] [unique_id "amuz7Uoi7QGnEa1uk6m9JgAAAFE"]
[Thu Jul 30 15:28:29.912469 2026] [security2:error] [pid 173718:tid 173867] [client 135.119.63.61:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.__info.php"] [unique_id "amuz7Uoi7QGnEa1uk6m9JwAAABI"]
[Thu Jul 30 15:28:29.994278 2026] [security2:error] [pid 173718:tid 173884] [client 172.213.208.20:19532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/index/function.php"] [unique_id "amuz7Uoi7QGnEa1uk6m9KAAAACM"]
[Thu Jul 30 15:28:30.128758 2026] [security2:error] [pid 173718:tid 173905] [client 20.171.55.167:3678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/goat.php"] [unique_id "amuz7koi7QGnEa1uk6m9KQAAADg"]
[Thu Jul 30 15:28:30.393415 2026] [security2:error] [pid 173718:tid 173913] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/bless.php"] [unique_id "amuz7koi7QGnEa1uk6m9MwAAAEA"]
[Thu Jul 30 15:28:30.393518 2026] [security2:error] [pid 173718:tid 173913] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/bless.php"] [unique_id "amuz7koi7QGnEa1uk6m9MwAAAEA"]
[Thu Jul 30 15:28:30.623493 2026] [security2:error] [pid 173718:tid 173900] [client 20.63.98.115:26408] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.hmhs.ph"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuz7koi7QGnEa1uk6m9OAAAADM"]
[Thu Jul 30 15:28:30.623616 2026] [security2:error] [pid 173718:tid 173900] [client 20.63.98.115:26408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "amuz7koi7QGnEa1uk6m9OAAAADM"]
[Thu Jul 30 15:28:30.714061 2026] [security2:error] [pid 173718:tid 173927] [client 135.119.63.61:40311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.alf.php"] [unique_id "amuz7koi7QGnEa1uk6m9OwAAAE4"]
[Thu Jul 30 15:28:30.762568 2026] [security2:error] [pid 173718:tid 173937] [client 20.203.148.31:43057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/autoload_classmap.php"] [unique_id "amuz7koi7QGnEa1uk6m9PAAAAFg"]
[Thu Jul 30 15:28:30.837674 2026] [security2:error] [pid 173718:tid 173908] [client 20.171.55.167:3657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/haf.php"] [unique_id "amuz7koi7QGnEa1uk6m9QAAAADs"]
[Thu Jul 30 15:28:30.898376 2026] [security2:error] [pid 173718:tid 173890] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/sagax1.php"] [unique_id "amuz7koi7QGnEa1uk6m9RQAAACk"]
[Thu Jul 30 15:28:30.898466 2026] [security2:error] [pid 173718:tid 173890] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/sagax1.php"] [unique_id "amuz7koi7QGnEa1uk6m9RQAAACk"]
[Thu Jul 30 15:28:30.924694 2026] [autoindex:error] [pid 173718:tid 173865] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:31.078901 2026] [autoindex:error] [pid 173718:tid 173886] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:31.268806 2026] [core:notice] [pid 173718:tid 173955] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:31.272769 2026] [autoindex:error] [pid 173718:tid 173955] [client 66.249.79.229:52015] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_ab4e48f3/index.php/cicee/article/download/9466/4217: No matching DirectoryIndex (none) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:31.272924 2026] [security2:error] [pid 173718:tid 173955] [client 66.249.79.229:52015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/cicee/article/download/9466/4217"] [unique_id "amuz70oi7QGnEa1uk6m9TgAAAGo"]
[Thu Jul 30 15:28:31.275510 2026] [security2:error] [pid 173718:tid 173921] [client 172.213.208.20:19559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/aaa.php"] [unique_id "amuz70oi7QGnEa1uk6m9TwAAAEg"]
[Thu Jul 30 15:28:31.353353 2026] [security2:error] [pid 173718:tid 173759] [remote 74.7.243.224:32988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/reportf.php"] [unique_id "amuz70oi7QGnEa1uk6m9UAAADCc"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/article.php?id=27
[Thu Jul 30 15:28:31.441552 2026] [security2:error] [pid 173718:tid 173934] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wpc.php"] [unique_id "amuz70oi7QGnEa1uk6m9VAAAAFU"]
[Thu Jul 30 15:28:31.441647 2026] [security2:error] [pid 173718:tid 173934] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wpc.php"] [unique_id "amuz70oi7QGnEa1uk6m9VAAAAFU"]
[Thu Jul 30 15:28:31.507468 2026] [security2:error] [pid 173718:tid 173926] [client 135.119.63.61:28860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.env.php"] [unique_id "amuz70oi7QGnEa1uk6m9WAAAAE0"]
[Thu Jul 30 15:28:31.597608 2026] [security2:error] [pid 173718:tid 173873] [client 20.171.55.167:3697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/hinfofuns.php"] [unique_id "amuz70oi7QGnEa1uk6m9WQAAABg"]
[Thu Jul 30 15:28:31.630594 2026] [security2:error] [pid 173718:tid 173911] [client 20.203.148.31:46500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/bb.php"] [unique_id "amuz70oi7QGnEa1uk6m9WgAAAD4"]
[Thu Jul 30 15:28:31.699403 2026] [security2:error] [pid 173718:tid 173976] [client 20.63.98.115:29705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/admin/upload/css.php"] [unique_id "amuz70oi7QGnEa1uk6m9XwAAAH8"]
[Thu Jul 30 15:28:31.958446 2026] [security2:error] [pid 173718:tid 173915] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/fone1.php"] [unique_id "amuz70oi7QGnEa1uk6m9ZAAAAEI"]
[Thu Jul 30 15:28:31.958553 2026] [security2:error] [pid 173718:tid 173915] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/fone1.php"] [unique_id "amuz70oi7QGnEa1uk6m9ZAAAAEI"]
[Thu Jul 30 15:28:32.129536 2026] [security2:error] [pid 173718:tid 173969] [client 172.213.208.20:52502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/getid3-core.php"] [unique_id "amuz8Eoi7QGnEa1uk6m9aAAAAHg"]
[Thu Jul 30 15:28:32.239861 2026] [core:notice] [pid 173718:tid 173766] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:32.310314 2026] [security2:error] [pid 173718:tid 173931] [client 135.119.63.61:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.env.sample.php"] [unique_id "amuz8Eoi7QGnEa1uk6m9bQAAAFI"]
[Thu Jul 30 15:28:32.337396 2026] [security2:error] [pid 173718:tid 173930] [client 20.171.55.167:3664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/i0004en.php//wp-content/bk/index.php"] [unique_id "amuz8Eoi7QGnEa1uk6m9bgAAAFE"]
[Thu Jul 30 15:28:32.460225 2026] [security2:error] [pid 173718:tid 173928] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ncx.php"] [unique_id "amuz8Eoi7QGnEa1uk6m9bwAAAE8"]
[Thu Jul 30 15:28:32.460375 2026] [security2:error] [pid 173718:tid 173928] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ncx.php"] [unique_id "amuz8Eoi7QGnEa1uk6m9bwAAAE8"]
[Thu Jul 30 15:28:32.546014 2026] [security2:error] [pid 173718:tid 173884] [client 20.63.98.115:36479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/images/about.php"] [unique_id "amuz8Eoi7QGnEa1uk6m9dgAAACM"]
[Thu Jul 30 15:28:32.995738 2026] [security2:error] [pid 173718:tid 173909] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/js/index.php"] [unique_id "amuz8Eoi7QGnEa1uk6m9fgAAADw"]
[Thu Jul 30 15:28:32.995825 2026] [security2:error] [pid 173718:tid 173909] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/js/index.php"] [unique_id "amuz8Eoi7QGnEa1uk6m9fgAAADw"]
[Thu Jul 30 15:28:33.034535 2026] [security2:error] [pid 173718:tid 173968] [client 20.171.55.167:3655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/imagek.php"] [unique_id "amuz8Uoi7QGnEa1uk6m9ggAAAHc"]
[Thu Jul 30 15:28:33.134894 2026] [security2:error] [pid 173718:tid 173857] [client 135.119.63.61:4757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.fk.php"] [unique_id "amuz8Uoi7QGnEa1uk6m9gwAAAAg"]
[Thu Jul 30 15:28:33.511637 2026] [security2:error] [pid 173718:tid 173854] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wso.php"] [unique_id "amuz8Uoi7QGnEa1uk6m9iwAAAAU"]
[Thu Jul 30 15:28:33.511777 2026] [security2:error] [pid 173718:tid 173854] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wso.php"] [unique_id "amuz8Uoi7QGnEa1uk6m9iwAAAAU"]
[Thu Jul 30 15:28:33.805997 2026] [security2:error] [pid 173718:tid 173919] [client 20.171.55.167:3651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/indec.php"] [unique_id "amuz8Uoi7QGnEa1uk6m9lAAAAEY"]
[Thu Jul 30 15:28:33.927595 2026] [security2:error] [pid 173718:tid 173902] [client 135.119.63.61:4742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.htaccess.php"] [unique_id "amuz8Uoi7QGnEa1uk6m9mwAAADU"]
[Thu Jul 30 15:28:34.064445 2026] [security2:error] [pid 173718:tid 173941] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/zup.php73"] [unique_id "amuz8koi7QGnEa1uk6m9nwAAAFw"]
[Thu Jul 30 15:28:34.064536 2026] [security2:error] [pid 173718:tid 173941] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/zup.php73"] [unique_id "amuz8koi7QGnEa1uk6m9nwAAAFw"]
[Thu Jul 30 15:28:34.507129 2026] [security2:error] [pid 173718:tid 173883] [client 20.171.55.167:3850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/instabuilder2/cache/up.php"] [unique_id "amuz8koi7QGnEa1uk6m9pgAAACI"]
[Thu Jul 30 15:28:34.678298 2026] [security2:error] [pid 173718:tid 173856] [client 135.119.63.61:40308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.qiodetme.php"] [unique_id "amuz8koi7QGnEa1uk6m9rQAAAAc"]
[Thu Jul 30 15:28:35.059072 2026] [security2:error] [pid 173718:tid 173775] [remote 216.73.216.51:53930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amuz80oi7QGnEa1uk6m9sQAAfTc"]
[Thu Jul 30 15:28:35.107775 2026] [security2:error] [pid 173718:tid 173927] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/k.php"] [unique_id "amuz80oi7QGnEa1uk6m9tQAAAE4"]
[Thu Jul 30 15:28:35.107891 2026] [security2:error] [pid 173718:tid 173927] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/k.php"] [unique_id "amuz80oi7QGnEa1uk6m9tQAAAE4"]
[Thu Jul 30 15:28:35.221845 2026] [security2:error] [pid 173718:tid 173924] [client 20.171.55.167:3652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/item.php"] [unique_id "amuz80oi7QGnEa1uk6m9uQAAAEs"]
[Thu Jul 30 15:28:35.393648 2026] [security2:error] [pid 173718:tid 173908] [client 135.119.63.61:40304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.tmbadmin.php"] [unique_id "amuz80oi7QGnEa1uk6m9vQAAADs"]
[Thu Jul 30 15:28:35.448902 2026] [security2:error] [pid 173718:tid 173964] [client 20.63.98.115:26928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-includes/autoloadclassmap.php"] [unique_id "amuz80oi7QGnEa1uk6m9vgAAAHM"]
[Thu Jul 30 15:28:35.656153 2026] [security2:error] [pid 173718:tid 173886] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-blink.php"] [unique_id "amuz80oi7QGnEa1uk6m9wwAAACU"]
[Thu Jul 30 15:28:35.656250 2026] [security2:error] [pid 173718:tid 173886] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-blink.php"] [unique_id "amuz80oi7QGnEa1uk6m9wwAAACU"]
[Thu Jul 30 15:28:35.986939 2026] [security2:error] [pid 173718:tid 173859] [client 20.171.55.167:3665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/joomlawp.php"] [unique_id "amuz80oi7QGnEa1uk6m9yQAAAAo"]
[Thu Jul 30 15:28:36.170521 2026] [core:error] [pid 173718:tid 173919] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:36.170551 2026] [core:error] [pid 173718:tid 173919] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:36.170644 2026] [security2:error] [pid 173718:tid 173919] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index.php"] [unique_id "amuz9Eoi7QGnEa1uk6m9zQAAAEY"]
[Thu Jul 30 15:28:36.181601 2026] [core:notice] [pid 173718:tid 173894] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:36.283104 2026] [security2:error] [pid 173718:tid 173955] [client 135.119.63.61:4593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.tmbalfa.php"] [unique_id "amuz9Eoi7QGnEa1uk6m90gAAAGo"]
[Thu Jul 30 15:28:36.425085 2026] [security2:error] [pid 173718:tid 173920] [client 172.213.208.20:12551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/adminer.php"] [unique_id "amuz9Eoi7QGnEa1uk6m91gAAAEc"]
[Thu Jul 30 15:28:36.700902 2026] [security2:error] [pid 173718:tid 173918] [client 20.171.55.167:3859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/kk.php"] [unique_id "amuz9Eoi7QGnEa1uk6m92gAAAEU"]
[Thu Jul 30 15:28:36.718516 2026] [core:error] [pid 173718:tid 173947] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:36.718532 2026] [core:error] [pid 173718:tid 173947] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:36.718611 2026] [security2:error] [pid 173718:tid 173947] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index.php"] [unique_id "amuz9Eoi7QGnEa1uk6m93AAAAGI"]
[Thu Jul 30 15:28:37.095602 2026] [security2:error] [pid 173718:tid 173950] [client 135.119.63.61:4592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.tmbbypass.php"] [unique_id "amuz9Uoi7QGnEa1uk6m94gAAAGU"]
[Thu Jul 30 15:28:37.238439 2026] [security2:error] [pid 173718:tid 173880] [client 20.63.98.115:29736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-admin/x.php"] [unique_id "amuz9Uoi7QGnEa1uk6m96gAAAB8"]
[Thu Jul 30 15:28:37.248710 2026] [core:error] [pid 173718:tid 173852] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:37.248728 2026] [core:error] [pid 173718:tid 173852] [client 20.9.4.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:37.248816 2026] [security2:error] [pid 173718:tid 173852] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/index.php"] [unique_id "amuz9Uoi7QGnEa1uk6m96wAAAAM"]
[Thu Jul 30 15:28:37.456702 2026] [security2:error] [pid 173718:tid 173931] [client 20.171.55.167:3840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/leafmailer.php.php"] [unique_id "amuz9Uoi7QGnEa1uk6m97wAAAFI"]
[Thu Jul 30 15:28:37.631031 2026] [security2:error] [pid 173718:tid 173958] [client 20.203.148.31:46568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/bnm.php"] [unique_id "amuz9Uoi7QGnEa1uk6m98wAAAG0"]
[Thu Jul 30 15:28:37.776640 2026] [security2:error] [pid 173718:tid 173940] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ww5.php"] [unique_id "amuz9Uoi7QGnEa1uk6m9-gAAAFs"]
[Thu Jul 30 15:28:37.776786 2026] [security2:error] [pid 173718:tid 173940] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/ww5.php"] [unique_id "amuz9Uoi7QGnEa1uk6m9-gAAAFs"]
[Thu Jul 30 15:28:37.954786 2026] [security2:error] [pid 173718:tid 173916] [client 135.119.63.61:4766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.tmbk.php"] [unique_id "amuz9Uoi7QGnEa1uk6m9-wAAAEM"]
[Thu Jul 30 15:28:38.154654 2026] [security2:error] [pid 173718:tid 173909] [client 20.63.98.115:48773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/wp-class.php"] [unique_id "amuz9koi7QGnEa1uk6m-AgAAADw"]
[Thu Jul 30 15:28:38.191683 2026] [security2:error] [pid 173718:tid 173855] [client 20.171.55.167:3709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/linkpreview/class.php"] [unique_id "amuz9koi7QGnEa1uk6m-AwAAAAY"]
[Thu Jul 30 15:28:38.295676 2026] [security2:error] [pid 173718:tid 173882] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/2.php"] [unique_id "amuz9koi7QGnEa1uk6m-CwAAACE"]
[Thu Jul 30 15:28:38.295798 2026] [security2:error] [pid 173718:tid 173882] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/2.php"] [unique_id "amuz9koi7QGnEa1uk6m-CwAAACE"]
[Thu Jul 30 15:28:38.401904 2026] [security2:error] [pid 173718:tid 173856] [client 172.213.208.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amuz9Uoi7QGnEa1uk6m98gAAAAc"]
[Thu Jul 30 15:28:38.669248 2026] [security2:error] [pid 173718:tid 173963] [client 38.172.162.57:16139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz9koi7QGnEa1uk6m-EgAAAHI"]
[Thu Jul 30 15:28:38.669371 2026] [security2:error] [pid 173718:tid 173963] [client 38.172.162.57:16139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amuz9koi7QGnEa1uk6m-EgAAAHI"]
[Thu Jul 30 15:28:38.726546 2026] [security2:error] [pid 173718:tid 173921] [client 135.119.63.61:4549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.tmbwp.php"] [unique_id "amuz9koi7QGnEa1uk6m-EwAAAEg"]
[Thu Jul 30 15:28:38.859640 2026] [security2:error] [pid 173718:tid 173871] [client 172.213.208.20:27558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/alfa.php"] [unique_id "amuz9koi7QGnEa1uk6m-GgAAABY"]
[Thu Jul 30 15:28:39.167351 2026] [core:notice] [pid 173718:tid 173962] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:39.170738 2026] [security2:error] [pid 173718:tid 173944] [client 20.171.55.167:3893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/load.php"] [unique_id "amuz90oi7QGnEa1uk6m-IQAAAF8"]
[Thu Jul 30 15:28:39.185517 2026] [security2:error] [pid 173718:tid 173955] [client 20.63.98.115:48768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/content.php"] [unique_id "amuz90oi7QGnEa1uk6m-IgAAAGo"]
[Thu Jul 30 15:28:39.490148 2026] [security2:error] [pid 173718:tid 173969] [client 135.119.63.61:28813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.well-known/acme-challenge/zkotynva.php"] [unique_id "amuz90oi7QGnEa1uk6m-LwAAAHg"]
[Thu Jul 30 15:28:39.548559 2026] [security2:error] [pid 173718:tid 173867] [client 47.128.122.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amuz90oi7QGnEa1uk6m-KQAAABI"]
[Thu Jul 30 15:28:39.696937 2026] [security2:error] [pid 173718:tid 173898] [client 172.237.109.114:30209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuz90oi7QGnEa1uk6m-HwAAADE"]
[Thu Jul 30 15:28:39.712312 2026] [security2:error] [pid 173718:tid 173947] [client 172.237.109.114:53512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuz90oi7QGnEa1uk6m-HgAAAGI"]
[Thu Jul 30 15:28:39.911153 2026] [security2:error] [pid 173718:tid 173860] [client 20.171.55.167:3903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/lwbdene/index.php"] [unique_id "amuz90oi7QGnEa1uk6m-OwAAAAs"]
[Thu Jul 30 15:28:40.073171 2026] [security2:error] [pid 173718:tid 173916] [client 20.63.98.115:26942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/acp.php"] [unique_id "amuz-Eoi7QGnEa1uk6m-PAAAAEM"]
[Thu Jul 30 15:28:40.239229 2026] [security2:error] [pid 173718:tid 173887] [client 20.203.148.31:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/bootstrap.php"] [unique_id "amuz-Eoi7QGnEa1uk6m-QAAAACY"]
[Thu Jul 30 15:28:40.259136 2026] [security2:error] [pid 173718:tid 173964] [client 135.119.63.61:40284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "amuz-Eoi7QGnEa1uk6m-QQAAAHM"]
[Thu Jul 30 15:28:40.589489 2026] [proxy:error] [pid 173718:tid 173912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:40.589560 2026] [proxy_http:error] [pid 173718:tid 173912] [client 74.7.241.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:40.590136 2026] [proxy:error] [pid 173718:tid 173912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:28:40.590192 2026] [proxy_http:error] [pid 173718:tid 173912] [client 74.7.241.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:28:40.590306 2026] [security2:error] [pid 173718:tid 173912] [client 74.7.241.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.koinjp189.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amuz-Eoi7QGnEa1uk6m-SAAAAD8"]
[Thu Jul 30 15:28:40.609571 2026] [security2:error] [pid 173718:tid 173888] [client 20.171.55.167:3414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/majalahpro-core/img/index.php"] [unique_id "amuz-Eoi7QGnEa1uk6m-SQAAACc"]
[Thu Jul 30 15:28:40.718415 2026] [security2:error] [pid 173718:tid 173922] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuz-Eoi7QGnEa1uk6m-TQAAAEk"]
[Thu Jul 30 15:28:40.718505 2026] [security2:error] [pid 173718:tid 173922] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/wp-admin/classwithtostring.php"] [unique_id "amuz-Eoi7QGnEa1uk6m-TQAAAEk"]
[Thu Jul 30 15:28:41.009795 2026] [security2:error] [pid 173718:tid 173901] [client 135.119.63.61:4602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.well-knownadmin.php"] [unique_id "amuz-Uoi7QGnEa1uk6m-VQAAADQ"]
[Thu Jul 30 15:28:41.140027 2026] [security2:error] [pid 173718:tid 173956] [client 20.63.98.115:26119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/g.php"] [unique_id "amuz-Uoi7QGnEa1uk6m-VwAAAGs"]
[Thu Jul 30 15:28:41.217788 2026] [security2:error] [pid 173718:tid 173849] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/atomlib.php"] [unique_id "amuz-Uoi7QGnEa1uk6m-WwAAAAA"]
[Thu Jul 30 15:28:41.217932 2026] [security2:error] [pid 173718:tid 173849] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/atomlib.php"] [unique_id "amuz-Uoi7QGnEa1uk6m-WwAAAAA"]
[Thu Jul 30 15:28:41.264540 2026] [core:notice] [pid 173718:tid 173943] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:41.365671 2026] [security2:error] [pid 173718:tid 173871] [client 20.171.55.167:3874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/masterx/wpx.php"] [unique_id "amuz-Uoi7QGnEa1uk6m-XgAAABY"]
[Thu Jul 30 15:28:41.489360 2026] [security2:error] [pid 173718:tid 173870] [client 172.237.109.114:20760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amuz-Uoi7QGnEa1uk6m-VgAAABU"]
[Thu Jul 30 15:28:41.755372 2026] [security2:error] [pid 173718:tid 173880] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/rip.php"] [unique_id "amuz-Uoi7QGnEa1uk6m-aQAAAB8"]
[Thu Jul 30 15:28:41.755487 2026] [security2:error] [pid 173718:tid 173880] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/rip.php"] [unique_id "amuz-Uoi7QGnEa1uk6m-aQAAAB8"]
[Thu Jul 30 15:28:41.800223 2026] [security2:error] [pid 173718:tid 173950] [client 135.119.63.61:4547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.well-knownalfa.php"] [unique_id "amuz-Uoi7QGnEa1uk6m-agAAAGU"]
[Thu Jul 30 15:28:42.107969 2026] [security2:error] [pid 173718:tid 173969] [client 20.171.55.167:3090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/mediabypass.php"] [unique_id "amuz-koi7QGnEa1uk6m-cQAAAHg"]
[Thu Jul 30 15:28:42.218698 2026] [security2:error] [pid 173718:tid 173928] [client 20.203.148.31:48402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/buy.php"] [unique_id "amuz-koi7QGnEa1uk6m-cgAAAE8"]
[Thu Jul 30 15:28:42.266450 2026] [security2:error] [pid 173718:tid 173951] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/p.php"] [unique_id "amuz-koi7QGnEa1uk6m-dgAAAGY"]
[Thu Jul 30 15:28:42.266554 2026] [security2:error] [pid 173718:tid 173951] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/p.php"] [unique_id "amuz-koi7QGnEa1uk6m-dgAAAGY"]
[Thu Jul 30 15:28:42.271719 2026] [security2:error] [pid 173718:tid 173938] [client 20.63.98.115:48793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.98.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hmhs.ph"] [uri "/.well-known/caches.php"] [unique_id "amuz-koi7QGnEa1uk6m-dwAAAFk"]
[Thu Jul 30 15:28:42.344027 2026] [core:notice] [pid 173718:tid 173947] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:42.533519 2026] [security2:error] [pid 173718:tid 173952] [client 135.119.63.61:4772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.well-knownbypass.php"] [unique_id "amuz-koi7QGnEa1uk6m-fwAAAGc"]
[Thu Jul 30 15:28:42.805924 2026] [security2:error] [pid 173718:tid 173909] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/php.php"] [unique_id "amuz-koi7QGnEa1uk6m-gwAAADw"]
[Thu Jul 30 15:28:42.806027 2026] [security2:error] [pid 173718:tid 173909] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "germanyvisasupportcenterislamabad.website"] [uri "/php.php"] [unique_id "amuz-koi7QGnEa1uk6m-gwAAADw"]
[Thu Jul 30 15:28:42.815610 2026] [security2:error] [pid 173718:tid 173961] [client 20.171.55.167:3078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/models/indexx.php"] [unique_id "amuz-koi7QGnEa1uk6m-hAAAAHA"]
[Thu Jul 30 15:28:42.831700 2026] [security2:error] [pid 173718:tid 173925] [client 20.203.148.31:39859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/chosen.php"] [unique_id "amuz-koi7QGnEa1uk6m-hQAAAEw"]
[Thu Jul 30 15:28:43.252009 2026] [core:error] [pid 173718:tid 173861] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://chimnify.services/
[Thu Jul 30 15:28:43.252030 2026] [core:error] [pid 173718:tid 173861] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://chimnify.services/
[Thu Jul 30 15:28:43.306938 2026] [security2:error] [pid 173718:tid 173876] [client 135.119.63.61:40279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.well-knownk.php"] [unique_id "amuz-0oi7QGnEa1uk6m-kQAAABs"]
[Thu Jul 30 15:28:43.508283 2026] [security2:error] [pid 173718:tid 173922] [client 20.203.148.31:48150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/class-wp-image.php"] [unique_id "amuz-0oi7QGnEa1uk6m-mQAAAEk"]
[Thu Jul 30 15:28:43.610591 2026] [security2:error] [pid 173718:tid 173919] [client 20.171.55.167:3117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/ms-functions.php"] [unique_id "amuz-0oi7QGnEa1uk6m-nQAAAEY"]
[Thu Jul 30 15:28:43.667336 2026] [autoindex:error] [pid 173718:tid 173885] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:43.804134 2026] [security2:error] [pid 173718:tid 173949] [client 172.213.208.20:12584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amuz-0oi7QGnEa1uk6m-pAAAAGQ"]
[Thu Jul 30 15:28:44.053300 2026] [security2:error] [pid 173718:tid 173874] [client 135.119.63.61:28850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/.well-knownwp.php"] [unique_id "amuz_Eoi7QGnEa1uk6m-qAAAABk"]
[Thu Jul 30 15:28:44.347203 2026] [security2:error] [pid 173718:tid 173905] [client 20.171.55.167:3088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/neko.php"] [unique_id "amuz_Eoi7QGnEa1uk6m-rwAAADg"]
[Thu Jul 30 15:28:44.799194 2026] [security2:error] [pid 173718:tid 173960] [client 135.119.63.61:4764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/0.php"] [unique_id "amuz_Eoi7QGnEa1uk6m-uQAAAG8"]
[Thu Jul 30 15:28:44.931891 2026] [security2:error] [pid 173718:tid 173869] [client 20.203.148.31:48397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/classsmtps.php"] [unique_id "amuz_Eoi7QGnEa1uk6m-vQAAABQ"]
[Thu Jul 30 15:28:45.120501 2026] [security2:error] [pid 173718:tid 173974] [client 20.171.55.167:3095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/noriumportfolio/doc.php"] [unique_id "amuz_Uoi7QGnEa1uk6m-xAAAAH0"]
[Thu Jul 30 15:28:45.597182 2026] [security2:error] [pid 173718:tid 173936] [client 135.119.63.61:4760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/00.php"] [unique_id "amuz_Uoi7QGnEa1uk6m-zQAAAFc"]
[Thu Jul 30 15:28:45.867403 2026] [security2:error] [pid 173718:tid 173932] [client 20.171.55.167:3854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/omest403.php"] [unique_id "amuz_Uoi7QGnEa1uk6m-2QAAAFM"]
[Thu Jul 30 15:28:46.099750 2026] [security2:error] [pid 173718:tid 173897] [client 172.213.208.20:50520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amuz_koi7QGnEa1uk6m-4QAAADA"]
[Thu Jul 30 15:28:46.311850 2026] [security2:error] [pid 173718:tid 173901] [client 135.119.63.61:4768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/01.php"] [unique_id "amuz_koi7QGnEa1uk6m-6AAAADQ"]
[Thu Jul 30 15:28:46.574872 2026] [security2:error] [pid 173718:tid 173870] [client 20.171.55.167:3872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/packed.php"] [unique_id "amuz_koi7QGnEa1uk6m-7gAAABU"]
[Thu Jul 30 15:28:46.685492 2026] [security2:error] [pid 173718:tid 173910] [client 2a03:2880:f800:35:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amuz_koi7QGnEa1uk6m-4AAAPRs"]
[Thu Jul 30 15:28:47.078960 2026] [security2:error] [pid 173718:tid 173867] [client 135.119.63.61:28863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/02.php"] [unique_id "amuz_0oi7QGnEa1uk6m--gAAABI"]
[Thu Jul 30 15:28:47.340788 2026] [security2:error] [pid 173718:tid 173947] [client 20.171.55.167:3101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/php_configuration.php"] [unique_id "amuz_0oi7QGnEa1uk6m_AQAAAGI"]
[Thu Jul 30 15:28:47.358098 2026] [security2:error] [pid 173718:tid 173856] [client 20.203.148.31:43012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/classwithtostring.php"] [unique_id "amuz_0oi7QGnEa1uk6m_AgAAAAc"]
[Thu Jul 30 15:28:47.449418 2026] [core:notice] [pid 173718:tid 173968] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:47.821601 2026] [security2:error] [pid 173718:tid 173961] [client 135.119.63.61:4739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/07.php"] [unique_id "amuz_0oi7QGnEa1uk6m_EAAAAHA"]
[Thu Jul 30 15:28:48.111035 2026] [security2:error] [pid 173718:tid 173859] [client 20.171.55.167:3133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/phpunit/src/Util/PHP/uss.php"] [unique_id "amu0AEoi7QGnEa1uk6m_FQAAAAo"]
[Thu Jul 30 15:28:48.234078 2026] [security2:error] [pid 173718:tid 173954] [client 49.13.134.145:29694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amu0AEoi7QGnEa1uk6m_GAAAAGk"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:28:48.536271 2026] [security2:error] [pid 173718:tid 173956] [client 135.119.63.61:28847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/098.php"] [unique_id "amu0AEoi7QGnEa1uk6m_HAAAAGs"]
[Thu Jul 30 15:28:48.562780 2026] [core:notice] [pid 173718:tid 173849] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:48.774448 2026] [core:notice] [pid 173718:tid 173962] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:48.778805 2026] [security2:error] [pid 173718:tid 173962] [client 49.13.134.145:29708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amu0AEoi7QGnEa1uk6m_LgAAAHE"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:28:48.846613 2026] [security2:error] [pid 173718:tid 173885] [client 20.171.55.167:3115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/pluginsk.php"] [unique_id "amu0AEoi7QGnEa1uk6m_MQAAACQ"]
[Thu Jul 30 15:28:49.050345 2026] [core:notice] [pid 173718:tid 173950] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:49.202154 2026] [security2:error] [pid 173718:tid 173893] [client 172.213.208.20:37909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amu0AUoi7QGnEa1uk6m_OQAAACw"]
[Thu Jul 30 15:28:49.302590 2026] [security2:error] [pid 173718:tid 173904] [client 135.119.63.61:40281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/0byte.php"] [unique_id "amu0AUoi7QGnEa1uk6m_PQAAADc"]
[Thu Jul 30 15:28:49.382660 2026] [security2:error] [pid 173718:tid 173939] [client 57.141.0.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0AEoi7QGnEa1uk6m_LAAAAFo"]
[Thu Jul 30 15:28:49.398626 2026] [security2:error] [pid 173718:tid 173899] [client 49.13.134.145:29716] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amu0AUoi7QGnEa1uk6m_QAAAADI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:28:49.399909 2026] [security2:error] [pid 173718:tid 173870] [client 38.172.162.57:16192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0AUoi7QGnEa1uk6m_QQAAABU"]
[Thu Jul 30 15:28:49.400035 2026] [security2:error] [pid 173718:tid 173870] [client 38.172.162.57:16192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0AUoi7QGnEa1uk6m_QQAAABU"]
[Thu Jul 30 15:28:49.461573 2026] [security2:error] [pid 173718:tid 173754] [remote 216.73.216.51:53930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amu0AUoi7QGnEa1uk6m_QgAAYCI"]
[Thu Jul 30 15:28:49.642371 2026] [core:notice] [pid 173718:tid 173928] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:49.645728 2026] [security2:error] [pid 173718:tid 173928] [client 66.249.79.229:55033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Agroswagati/article/download/4182/2072"] [unique_id "amu0AUoi7QGnEa1uk6m_PwAAAE8"]
[Thu Jul 30 15:28:49.889134 2026] [security2:error] [pid 173718:tid 173946] [client 20.171.55.167:3653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/pref.php"] [unique_id "amu0AUoi7QGnEa1uk6m_TgAAAGE"]
[Thu Jul 30 15:28:50.038359 2026] [security2:error] [pid 173718:tid 173890] [client 135.119.63.61:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/0o.php"] [unique_id "amu0Akoi7QGnEa1uk6m_UAAAACk"]
[Thu Jul 30 15:28:50.675288 2026] [security2:error] [pid 173718:tid 173889] [client 20.171.55.167:3656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/prodi.php"] [unique_id "amu0Akoi7QGnEa1uk6m_YAAAACg"]
[Thu Jul 30 15:28:50.851425 2026] [security2:error] [pid 173718:tid 173850] [client 135.119.63.61:40259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/0x.php"] [unique_id "amu0Akoi7QGnEa1uk6m_agAAAAE"]
[Thu Jul 30 15:28:50.891077 2026] [core:notice] [pid 173718:tid 173748] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:50.894504 2026] [security2:error] [pid 173718:tid 173956] [client 74.7.244.8:53830] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ejournalugj.com"] [uri "/robots.txt"] [unique_id "amu0Akoi7QGnEa1uk6m_awAAaxw"]
[Thu Jul 30 15:28:51.186539 2026] [core:notice] [pid 173718:tid 173762] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:51.190296 2026] [security2:error] [pid 173718:tid 173906] [client 74.7.228.245:58310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/camic/article/download/9051/3903"] [unique_id "amu0Akoi7QGnEa1uk6m_bAAAOSo"]
[Thu Jul 30 15:28:51.203228 2026] [security2:error] [pid 173718:tid 173873] [client 57.141.0.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0Akoi7QGnEa1uk6m_XwAAABg"]
[Thu Jul 30 15:28:51.214414 2026] [core:notice] [pid 173718:tid 173879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:51.375379 2026] [security2:error] [pid 173718:tid 173878] [client 20.171.55.167:3851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/publicwp.php"] [unique_id "amu0A0oi7QGnEa1uk6m_eAAAAB0"]
[Thu Jul 30 15:28:51.569339 2026] [security2:error] [pid 173718:tid 173951] [client 135.119.63.61:4748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/0x0.php"] [unique_id "amu0A0oi7QGnEa1uk6m_fAAAAGY"]
[Thu Jul 30 15:28:52.004742 2026] [core:notice] [pid 173718:tid 173907] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:52.015651 2026] [core:error] [pid 173718:tid 173907] [client 66.249.65.192:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:52.015796 2026] [security2:error] [pid 173718:tid 173907] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/30/33.html.html.html.html.html.html.html.html.html.html"] [unique_id "amu0A0oi7QGnEa1uk6m_hgAAADo"]
[Thu Jul 30 15:28:52.108172 2026] [security2:error] [pid 173718:tid 173928] [client 20.171.55.167:3703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/radio.php"] [unique_id "amu0BEoi7QGnEa1uk6m_jgAAAE8"]
[Thu Jul 30 15:28:52.311632 2026] [security2:error] [pid 173718:tid 173922] [client 57.141.0.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0A0oi7QGnEa1uk6m_ggAAAEk"]
[Thu Jul 30 15:28:52.316215 2026] [security2:error] [pid 173718:tid 173908] [client 135.119.63.61:28814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/0x1.php"] [unique_id "amu0BEoi7QGnEa1uk6m_kgAAADs"]
[Thu Jul 30 15:28:52.803731 2026] [security2:error] [pid 173718:tid 173931] [client 20.203.148.31:48434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/config.php"] [unique_id "amu0BEoi7QGnEa1uk6m_nAAAAFI"]
[Thu Jul 30 15:28:52.825312 2026] [security2:error] [pid 173718:tid 173953] [client 20.171.55.167:3089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/retu.php"] [unique_id "amu0BEoi7QGnEa1uk6m_nQAAAGg"]
[Thu Jul 30 15:28:53.003382 2026] [security2:error] [pid 173718:tid 173894] [client 135.119.63.61:40285] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.svcambodia.com"] [uri "/1.php"] [unique_id "amu0BUoi7QGnEa1uk6m_pAAAAC0"]
[Thu Jul 30 15:28:53.003522 2026] [security2:error] [pid 173718:tid 173894] [client 135.119.63.61:40285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/1.php"] [unique_id "amu0BUoi7QGnEa1uk6m_pAAAAC0"]
[Thu Jul 30 15:28:53.526763 2026] [security2:error] [pid 173718:tid 173871] [client 172.213.208.20:52637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/edit.php"] [unique_id "amu0BUoi7QGnEa1uk6m_qwAAABY"]
[Thu Jul 30 15:28:53.536389 2026] [security2:error] [pid 173718:tid 173896] [client 20.171.55.167:3848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/rt.php"] [unique_id "amu0BUoi7QGnEa1uk6m_rAAAAC8"]
[Thu Jul 30 15:28:53.699440 2026] [security2:error] [pid 173718:tid 173906] [client 135.119.63.61:4593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/10.php"] [unique_id "amu0BUoi7QGnEa1uk6m_sQAAADk"]
[Thu Jul 30 15:28:54.023908 2026] [security2:error] [pid 173718:tid 173879] [client 213.152.162.84:37756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amu0BUoi7QGnEa1uk6m_sgAAAB4"]
[Thu Jul 30 15:28:54.024022 2026] [security2:error] [pid 173718:tid 173879] [client 213.152.162.84:37756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amu0BUoi7QGnEa1uk6m_sgAAAB4"]
[Thu Jul 30 15:28:54.247582 2026] [security2:error] [pid 173718:tid 173969] [client 20.171.55.167:3661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/script-loader-react-refresh-runtime.min-soap.php"] [unique_id "amu0Bkoi7QGnEa1uk6m_vQAAAHg"]
[Thu Jul 30 15:28:54.314871 2026] [autoindex:error] [pid 173718:tid 173960] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:54.401379 2026] [security2:error] [pid 173718:tid 173913] [client 135.119.63.61:4765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.svcambodia.com"] [uri "/100.php"] [unique_id "amu0Bkoi7QGnEa1uk6m_xQAAAEA"]
[Thu Jul 30 15:28:54.519512 2026] [security2:error] [pid 173718:tid 173971] [client 20.203.148.31:46118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/core.php"] [unique_id "amu0Bkoi7QGnEa1uk6m_zAAAAHo"]
[Thu Jul 30 15:28:54.658172 2026] [security2:error] [pid 173718:tid 173922] [client 172.213.208.20:48648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/sf.php"] [unique_id "amu0Bkoi7QGnEa1uk6m_0gAAAEk"]
[Thu Jul 30 15:28:54.998898 2026] [security2:error] [pid 173718:tid 173912] [client 20.171.55.167:3100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/seotheme/db.php"] [unique_id "amu0Bkoi7QGnEa1uk6m_2wAAAD8"]
[Thu Jul 30 15:28:55.240439 2026] [security2:error] [pid 173718:tid 173864] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0Bkoi7QGnEa1uk6m_0QAAAA8"]
[Thu Jul 30 15:28:55.292605 2026] [security2:error] [pid 173718:tid 173931] [client 20.203.148.31:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/css.php"] [unique_id "amu0B0oi7QGnEa1uk6m_4QAAAFI"]
[Thu Jul 30 15:28:55.696300 2026] [security2:error] [pid 173718:tid 173967] [client 20.171.55.167:3118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/shapes.php"] [unique_id "amu0B0oi7QGnEa1uk6m_6gAAAHY"]
[Thu Jul 30 15:28:55.886845 2026] [core:notice] [pid 173718:tid 173813] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:56.168474 2026] [security2:error] [pid 173718:tid 173943] [client 137.184.134.248:46934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amu0B0oi7QGnEa1uk6m_8wAAAF4"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:28:56.168478 2026] [security2:error] [pid 173718:tid 173948] [client 204.48.25.230:53334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amu0B0oi7QGnEa1uk6m_8QAAAGM"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:28:56.445698 2026] [security2:error] [pid 173718:tid 173960] [client 20.171.55.167:3670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/sidebarh.php"] [unique_id "amu0CEoi7QGnEa1uk6nAAgAAAG8"]
[Thu Jul 30 15:28:57.006524 2026] [autoindex:error] [pid 173718:tid 173858] [client 172.213.208.20:52669] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:28:57.137205 2026] [security2:error] [pid 173718:tid 173932] [client 172.213.208.20:52669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wso.php"] [unique_id "amu0CUoi7QGnEa1uk6nAEgAAAFM"]
[Thu Jul 30 15:28:57.149136 2026] [security2:error] [pid 173718:tid 173853] [client 20.171.55.167:3425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/sites/default/wp-login.php"] [unique_id "amu0CUoi7QGnEa1uk6nAEwAAAAQ"]
[Thu Jul 30 15:28:57.592825 2026] [security2:error] [pid 173718:tid 173915] [client 204.8.98.55:51250] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0CUoi7QGnEa1uk6nAIwAAAEI"]
[Thu Jul 30 15:28:57.592920 2026] [security2:error] [pid 173718:tid 173915] [client 204.8.98.55:51250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0CUoi7QGnEa1uk6nAIwAAAEI"]
[Thu Jul 30 15:28:57.842118 2026] [core:error] [pid 173718:tid 173884] [client 74.7.241.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:57.842146 2026] [core:error] [pid 173718:tid 173884] [client 74.7.241.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:28:57.842275 2026] [security2:error] [pid 173718:tid 173884] [client 74.7.241.153:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.enf.gpl.temporary.site"] [uri "/___proxy_subdomain_webdisk/index.php"] [unique_id "amu0CUoi7QGnEa1uk6nAOAAAACM"]
[Thu Jul 30 15:28:57.842863 2026] [security2:error] [pid 173718:tid 173850] [client 74.7.241.153:40610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webdisk.enf.gpl.temporary.site"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "amu0CUoi7QGnEa1uk6nANgAAAQQ"]
[Thu Jul 30 15:28:57.847096 2026] [security2:error] [pid 173718:tid 173972] [client 20.171.55.167:3122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/smilies/network.php"] [unique_id "amu0CUoi7QGnEa1uk6nAOQAAAHs"]
[Thu Jul 30 15:28:57.981483 2026] [security2:error] [pid 173718:tid 173934] [client 204.48.25.230:42532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amu0CUoi7QGnEa1uk6nAJQAAAFU"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:28:57.982385 2026] [security2:error] [pid 173718:tid 173865] [client 137.184.134.248:59648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amu0CUoi7QGnEa1uk6nAJAAAABA"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:28:58.007900 2026] [security2:error] [pid 173718:tid 173901] [client 172.213.208.20:48491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/ioxi-o.php"] [unique_id "amu0Ckoi7QGnEa1uk6nAQwAAADQ"]
[Thu Jul 30 15:28:58.472291 2026] [security2:error] [pid 173718:tid 173975] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0CUoi7QGnEa1uk6nAPAAAAH4"]
[Thu Jul 30 15:28:58.587524 2026] [security2:error] [pid 173718:tid 173851] [client 172.213.208.20:52610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/file56.php"] [unique_id "amu0Ckoi7QGnEa1uk6nAWwAAAAI"]
[Thu Jul 30 15:28:58.615602 2026] [security2:error] [pid 173718:tid 173860] [client 20.171.55.167:3084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/ss.php"] [unique_id "amu0Ckoi7QGnEa1uk6nAXQAAAAs"]
[Thu Jul 30 15:28:59.006731 2026] [security2:error] [pid 173718:tid 173747] [remote 57.141.0.16:26034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amu0C0oi7QGnEa1uk6nAZwAAUxs"]
[Thu Jul 30 15:28:59.324786 2026] [security2:error] [pid 173718:tid 173916] [client 20.171.55.167:3610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/streams.php"] [unique_id "amu0C0oi7QGnEa1uk6nAcAAAAEM"]
[Thu Jul 30 15:28:59.461307 2026] [security2:error] [pid 173718:tid 173941] [client 172.213.208.20:19544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amu0C0oi7QGnEa1uk6nAdAAAAFw"]
[Thu Jul 30 15:28:59.652829 2026] [security2:error] [pid 173718:tid 173911] [client 172.237.109.114:52352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0C0oi7QGnEa1uk6nAaAAAAD4"]
[Thu Jul 30 15:28:59.955152 2026] [security2:error] [pid 173718:tid 173905] [client 37.140.223.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp-login.php"] [unique_id "amu0C0oi7QGnEa1uk6nAewAAADg"]
[Thu Jul 30 15:28:59.964404 2026] [core:notice] [pid 173718:tid 173758] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:28:59.992600 2026] [security2:error] [pid 173718:tid 173852] [client 38.172.162.57:16004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0C0oi7QGnEa1uk6nAhQAAAAM"]
[Thu Jul 30 15:28:59.992714 2026] [security2:error] [pid 173718:tid 173852] [client 38.172.162.57:16004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0C0oi7QGnEa1uk6nAhQAAAAM"]
[Thu Jul 30 15:29:00.164855 2026] [security2:error] [pid 173718:tid 173865] [client 20.171.55.167:3688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/symlink.php"] [unique_id "amu0DEoi7QGnEa1uk6nAiQAAABA"]
[Thu Jul 30 15:29:00.540891 2026] [core:notice] [pid 173718:tid 173742] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:00.602094 2026] [core:notice] [pid 173718:tid 173755] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:00.873228 2026] [security2:error] [pid 173718:tid 173973] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0DEoi7QGnEa1uk6nAngAAAHw"]
[Thu Jul 30 15:29:01.053918 2026] [security2:error] [pid 173718:tid 173936] [client 20.203.148.31:46086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/database.php"] [unique_id "amu0DUoi7QGnEa1uk6nAqgAAAFc"]
[Thu Jul 30 15:29:01.137324 2026] [security2:error] [pid 173718:tid 173932] [client 20.171.55.167:3128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/tes.php"] [unique_id "amu0DUoi7QGnEa1uk6nArgAAAFM"]
[Thu Jul 30 15:29:01.163392 2026] [security2:error] [pid 173718:tid 173917] [client 151.244.146.21:9502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amu0DEoi7QGnEa1uk6nAogAAAEQ"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:29:01.721439 2026] [security2:error] [pid 173718:tid 173934] [client 159.89.207.20:56549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "igetvape-australia.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amu0DUoi7QGnEa1uk6nAvgAAAFU"]
[Thu Jul 30 15:29:01.744842 2026] [security2:error] [pid 173718:tid 173969] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0DUoi7QGnEa1uk6nAugAAAHg"]
[Thu Jul 30 15:29:01.865813 2026] [security2:error] [pid 173718:tid 173903] [client 20.171.55.167:3108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/themes/index.php"] [unique_id "amu0DUoi7QGnEa1uk6nAwwAAADY"]
[Thu Jul 30 15:29:01.951819 2026] [core:notice] [pid 173718:tid 173970] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:02.196012 2026] [security2:error] [pid 173718:tid 173951] [client 159.89.207.20:58079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.207.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amu0DUoi7QGnEa1uk6nAywAAAGY"]
[Thu Jul 30 15:29:02.349115 2026] [security2:error] [pid 173718:tid 173940] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0DUoi7QGnEa1uk6nAvQAAAFs"]
[Thu Jul 30 15:29:02.507490 2026] [security2:error] [pid 173718:tid 173899] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0Dkoi7QGnEa1uk6nA1QAAADI"]
[Thu Jul 30 15:29:02.550068 2026] [security2:error] [pid 173718:tid 173869] [client 2a03:2880:f800:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0DUoi7QGnEa1uk6nAygAAFCA"]
[Thu Jul 30 15:29:02.613026 2026] [security2:error] [pid 173718:tid 173851] [client 20.171.55.167:3891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/tinymce/utils/license.php"] [unique_id "amu0Dkoi7QGnEa1uk6nA3gAAAAI"]
[Thu Jul 30 15:29:02.801458 2026] [security2:error] [pid 173718:tid 173882] [client 14.245.89.240:38966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amu0Dkoi7QGnEa1uk6nA2gAAACE"], referer: https://dlr.djb.temporary.site/
[Thu Jul 30 15:29:02.864290 2026] [security2:error] [pid 173718:tid 173878] [client 172.213.208.20:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-admin/css/index.php"] [unique_id "amu0Dkoi7QGnEa1uk6nA5QAAAB0"]
[Thu Jul 30 15:29:02.942630 2026] [security2:error] [pid 173718:tid 173933] [client 20.203.148.31:40258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/db.php"] [unique_id "amu0Dkoi7QGnEa1uk6nA6QAAAFQ"]
[Thu Jul 30 15:29:03.188971 2026] [core:notice] [pid 173718:tid 173770] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:03.244289 2026] [security2:error] [pid 173718:tid 173941] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0D0oi7QGnEa1uk6nA8AAAAFw"]
[Thu Jul 30 15:29:03.324893 2026] [security2:error] [pid 173718:tid 173955] [client 20.171.55.167:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/trd.php"] [unique_id "amu0D0oi7QGnEa1uk6nA9QAAAGo"]
[Thu Jul 30 15:29:03.648862 2026] [core:notice] [pid 173718:tid 173784] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:03.851780 2026] [security2:error] [pid 173718:tid 173971] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0D0oi7QGnEa1uk6nBCAAAAHo"]
[Thu Jul 30 15:29:03.961223 2026] [security2:error] [pid 173718:tid 173896] [client 20.203.148.31:46116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/default.php"] [unique_id "amu0D0oi7QGnEa1uk6nBDwAAAC8"]
[Thu Jul 30 15:29:04.064937 2026] [security2:error] [pid 173718:tid 173906] [client 20.171.55.167:3680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/twentytwentyfour/functions.php"] [unique_id "amu0EEoi7QGnEa1uk6nBEwAAADk"]
[Thu Jul 30 15:29:04.473550 2026] [security2:error] [pid 173718:tid 173872] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0EEoi7QGnEa1uk6nBIwAAABc"]
[Thu Jul 30 15:29:04.486736 2026] [security2:error] [pid 173718:tid 173954] [client 159.89.207.20:58834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.207.89.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amu0EEoi7QGnEa1uk6nBJwAAAGk"]
[Thu Jul 30 15:29:04.486836 2026] [security2:error] [pid 173718:tid 173954] [client 159.89.207.20:58834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "igetvape-australia.com"] [uri "/xmlrpc.php"] [unique_id "amu0EEoi7QGnEa1uk6nBJwAAAGk"]
[Thu Jul 30 15:29:04.803388 2026] [security2:error] [pid 173718:tid 173936] [client 20.171.55.167:3110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/ucp.php"] [unique_id "amu0EEoi7QGnEa1uk6nBMQAAAFc"]
[Thu Jul 30 15:29:04.996281 2026] [security2:error] [pid 173718:tid 173949] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0EEoi7QGnEa1uk6nBQgAAAGQ"]
[Thu Jul 30 15:29:05.380959 2026] [security2:error] [pid 173718:tid 173859] [client 57.141.0.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0EEoi7QGnEa1uk6nBMAAAAAo"]
[Thu Jul 30 15:29:05.512241 2026] [security2:error] [pid 173718:tid 173885] [client 172.213.208.20:55443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/edit.php"] [unique_id "amu0EUoi7QGnEa1uk6nBaAAAACQ"]
[Thu Jul 30 15:29:05.512566 2026] [security2:error] [pid 173718:tid 173962] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0EUoi7QGnEa1uk6nBYgAAAHE"]
[Thu Jul 30 15:29:05.589527 2026] [security2:error] [pid 173718:tid 173976] [client 20.171.55.167:3082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/upload_crop_v1.2.php"] [unique_id "amu0EUoi7QGnEa1uk6nBagAAAH8"]
[Thu Jul 30 15:29:05.618826 2026] [core:notice] [pid 173718:tid 173921] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:05.998065 2026] [security2:error] [pid 173718:tid 173803] [remote 111.225.148.146:47884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/assets/images/mega-yacht-marina.jpg"] [unique_id "amu0EUoi7QGnEa1uk6nBewAAZFM"]
[Thu Jul 30 15:29:06.040882 2026] [security2:error] [pid 173718:tid 173945] [client 43.160.219.138:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.219.160.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-admin/install.php"] [unique_id "amu0EUoi7QGnEa1uk6nBdgAAAGA"]
[Thu Jul 30 15:29:06.325877 2026] [core:notice] [pid 173718:tid 173810] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:06.334549 2026] [security2:error] [pid 173718:tid 173968] [client 20.171.55.167:3870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/usb.php"] [unique_id "amu0Ekoi7QGnEa1uk6nBhgAAAHc"]
[Thu Jul 30 15:29:06.581037 2026] [security2:error] [pid 173718:tid 173861] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0Ekoi7QGnEa1uk6nBjwAAAAw"]
[Thu Jul 30 15:29:06.739777 2026] [security2:error] [pid 173718:tid 173907] [client 172.213.208.20:27557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/2.php"] [unique_id "amu0Ekoi7QGnEa1uk6nBnQAAADo"]
[Thu Jul 30 15:29:06.777064 2026] [security2:error] [pid 173718:tid 173926] [client 20.203.148.31:43918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/dropdown.php"] [unique_id "amu0Ekoi7QGnEa1uk6nBngAAAE0"]
[Thu Jul 30 15:29:06.926544 2026] [core:notice] [pid 173718:tid 173925] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:06.953444 2026] [security2:error] [pid 173718:tid 173885] [client 43.173.179.125:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/17/au-hasard-de-la-toile-19/"] [unique_id "amu0Ekoi7QGnEa1uk6nBpAAAACQ"]
[Thu Jul 30 15:29:07.042481 2026] [security2:error] [pid 173718:tid 173973] [client 20.171.55.167:3892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/vendoradmin.php"] [unique_id "amu0E0oi7QGnEa1uk6nBqAAAAHw"]
[Thu Jul 30 15:29:07.208875 2026] [security2:error] [pid 173718:tid 173915] [client 43.173.179.80:47002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/08/26/wallis-une-nouvelle-boutique-pour-un-shopping-elegant/feed/"] [unique_id "amu0Ekoi7QGnEa1uk6nBowAAAEI"]
[Thu Jul 30 15:29:07.236721 2026] [security2:error] [pid 173718:tid 173966] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0E0oi7QGnEa1uk6nBrwAAAHU"]
[Thu Jul 30 15:29:07.565106 2026] [core:notice] [pid 173718:tid 173832] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:07.597319 2026] [security2:error] [pid 173718:tid 173971] [client 20.203.148.31:39843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/edit.php"] [unique_id "amu0E0oi7QGnEa1uk6nBwQAAAHo"]
[Thu Jul 30 15:29:07.692312 2026] [core:notice] [pid 173718:tid 173860] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:07.697847 2026] [security2:error] [pid 173718:tid 173860] [client 43.173.177.252:35698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2014/03/17/au-hasard-de-la-toile-19/"] [unique_id "amu0E0oi7QGnEa1uk6nBygAAAAs"], referer: https://carnetdeshopping.com/index.php/2014/03/17/au-hasard-de-la-toile-19/
[Thu Jul 30 15:29:07.813508 2026] [core:notice] [pid 173718:tid 173890] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:07.818414 2026] [security2:error] [pid 173718:tid 173890] [client 43.173.179.181:50842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2009/08/26/wallis-une-nouvelle-boutique-pour-un-shopping-elegant/feed/"] [unique_id "amu0E0oi7QGnEa1uk6nB0QAAACk"], referer: https://carnetdeshopping.com/index.php/2009/08/26/wallis-une-nouvelle-boutique-pour-un-shopping-elegant/feed/
[Thu Jul 30 15:29:07.830696 2026] [security2:error] [pid 173718:tid 173918] [client 20.171.55.167:3648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/vwcleanerplugin/bump.php"] [unique_id "amu0E0oi7QGnEa1uk6nB0gAAAEU"]
[Thu Jul 30 15:29:07.929429 2026] [security2:error] [pid 173718:tid 173867] [client 172.213.208.20:51569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amu0E0oi7QGnEa1uk6nB1gAAABI"]
[Thu Jul 30 15:29:07.981644 2026] [core:notice] [pid 173718:tid 173974] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:08.309752 2026] [security2:error] [pid 173718:tid 173904] [client 2a03:2880:f800:3e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0E0oi7QGnEa1uk6nBswAAN2I"]
[Thu Jul 30 15:29:08.568852 2026] [security2:error] [pid 173718:tid 173859] [client 20.171.55.167:3428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/whmcs.php"] [unique_id "amu0FEoi7QGnEa1uk6nB5wAAAAo"]
[Thu Jul 30 15:29:08.809307 2026] [core:notice] [pid 173718:tid 173966] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:09.143944 2026] [security2:error] [pid 173718:tid 173910] [client 20.203.148.31:40275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/f35.php"] [unique_id "amu0FUoi7QGnEa1uk6nB8wAAAD0"]
[Thu Jul 30 15:29:09.272497 2026] [security2:error] [pid 173718:tid 173960] [client 20.171.55.167:3781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/widgets/moon.php"] [unique_id "amu0FUoi7QGnEa1uk6nB-QAAAG8"]
[Thu Jul 30 15:29:09.458822 2026] [security2:error] [pid 173718:tid 173949] [client 172.213.208.20:51528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/mah.php"] [unique_id "amu0FUoi7QGnEa1uk6nB_AAAAGQ"]
[Thu Jul 30 15:29:10.121545 2026] [core:notice] [pid 173718:tid 173861] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:10.233481 2026] [security2:error] [pid 173718:tid 173888] [client 20.171.55.167:3899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/woocommerce/templates/wp-login.php"] [unique_id "amu0FUoi7QGnEa1uk6nCDAAAACc"]
[Thu Jul 30 15:29:10.377525 2026] [security2:error] [pid 173718:tid 173936] [client 127.0.0.1:26144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu0Fkoi7QGnEa1uk6nCGQAAAFc"]
[Thu Jul 30 15:29:10.377553 2026] [security2:error] [pid 173718:tid 173894] [client 127.0.0.1:26130] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kev.udi.temporary.site"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu0Fkoi7QGnEa1uk6nCGAAAAC0"]
[Thu Jul 30 15:29:10.377670 2026] [security2:error] [pid 173718:tid 173851] [client 74.7.244.39:40190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.kev.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amu0Fkoi7QGnEa1uk6nCFwAAAn4"]
[Thu Jul 30 15:29:10.471072 2026] [security2:error] [pid 173718:tid 173929] [client 66.249.93.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amu0FUoi7QGnEa1uk6nCBgAAUG4"]
[Thu Jul 30 15:29:10.488141 2026] [security2:error] [pid 173718:tid 173930] [client 66.249.93.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amu0FUoi7QGnEa1uk6nCBwAAUXE"]
[Thu Jul 30 15:29:10.563698 2026] [security2:error] [pid 173718:tid 173954] [client 38.172.162.57:15949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0Fkoi7QGnEa1uk6nCHwAAAGk"]
[Thu Jul 30 15:29:10.563812 2026] [security2:error] [pid 173718:tid 173954] [client 38.172.162.57:15949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0Fkoi7QGnEa1uk6nCHwAAAGk"]
[Thu Jul 30 15:29:10.577514 2026] [core:notice] [pid 173718:tid 173919] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:10.665073 2026] [security2:error] [pid 173718:tid 173898] [client 20.203.148.31:39813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfprogroup.com"] [uri "/f7.php"] [unique_id "amu0Fkoi7QGnEa1uk6nCKgAAADE"]
[Thu Jul 30 15:29:10.692562 2026] [security2:error] [pid 173718:tid 173972] [client 172.213.208.20:25646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/send.php"] [unique_id "amu0Fkoi7QGnEa1uk6nCLgAAAHs"]
[Thu Jul 30 15:29:11.275787 2026] [security2:error] [pid 173718:tid 173916] [client 20.171.55.167:3676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-akuma.php"] [unique_id "amu0F0oi7QGnEa1uk6nCPQAAAEM"]
[Thu Jul 30 15:29:12.010780 2026] [security2:error] [pid 173718:tid 173861] [client 20.171.55.167:3669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-comments-post.php"] [unique_id "amu0GEoi7QGnEa1uk6nCSwAAAAw"]
[Thu Jul 30 15:29:12.426803 2026] [core:notice] [pid 173718:tid 173956] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:12.728690 2026] [security2:error] [pid 173718:tid 173897] [client 20.171.55.167:3097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-css.php"] [unique_id "amu0GEoi7QGnEa1uk6nCZAAAADA"]
[Thu Jul 30 15:29:12.874437 2026] [security2:error] [pid 173718:tid 173888] [client 172.213.208.20:55437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amu0GEoi7QGnEa1uk6nCaAAAACc"]
[Thu Jul 30 15:29:13.479596 2026] [security2:error] [pid 173718:tid 173913] [client 20.171.55.167:3116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-foter.php"] [unique_id "amu0GUoi7QGnEa1uk6nCegAAAEA"]
[Thu Jul 30 15:29:14.251631 2026] [security2:error] [pid 173718:tid 173870] [client 20.171.55.167:3109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-includes/Text/network.php"] [unique_id "amu0Gkoi7QGnEa1uk6nClAAAABU"]
[Thu Jul 30 15:29:14.987095 2026] [security2:error] [pid 173718:tid 173947] [client 20.171.55.167:3127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-mn.php"] [unique_id "amu0Gkoi7QGnEa1uk6nCsAAAAGI"]
[Thu Jul 30 15:29:15.410487 2026] [autoindex:error] [pid 173718:tid 173974] [client 172.213.208.20:0] AH01276: Cannot serve directory /home2/dlrdjbte/public_html/website_ee4ca56f/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:29:15.545003 2026] [security2:error] [pid 173718:tid 173889] [client 172.213.208.20:55473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/about.php"] [unique_id "amu0G0oi7QGnEa1uk6nCxgAAACg"]
[Thu Jul 30 15:29:15.745606 2026] [security2:error] [pid 173718:tid 173929] [client 20.171.55.167:3120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-scripts.php"] [unique_id "amu0G0oi7QGnEa1uk6nC0AAAAFA"]
[Thu Jul 30 15:29:16.484411 2026] [security2:error] [pid 173718:tid 173906] [client 20.171.55.167:3663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wp-trackback.php"] [unique_id "amu0HEoi7QGnEa1uk6nC5QAAADk"]
[Thu Jul 30 15:29:16.533720 2026] [security2:error] [pid 173718:tid 173735] [remote 97.74.87.194:50992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gkc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amu0HEoi7QGnEa1uk6nC6QAAXA8"]
[Thu Jul 30 15:29:16.797651 2026] [core:notice] [pid 173718:tid 173948] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:16.812016 2026] [security2:error] [pid 173718:tid 173964] [client 172.213.208.20:53202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/options.php"] [unique_id "amu0HEoi7QGnEa1uk6nC8wAAAHM"]
[Thu Jul 30 15:29:16.835970 2026] [core:notice] [pid 173718:tid 173927] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:17.189467 2026] [security2:error] [pid 173718:tid 173873] [client 20.171.55.167:3072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wpcall-button/button-image.php"] [unique_id "amu0HUoi7QGnEa1uk6nDAQAAABg"]
[Thu Jul 30 15:29:17.416673 2026] [security2:error] [pid 173718:tid 173958] [client 74.7.228.27:60272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.aetiiph.net"] [uri "/index.php"] [unique_id "amu0HEoi7QGnEa1uk6nC6gAAbQ4"]
[Thu Jul 30 15:29:17.416706 2026] [security2:error] [pid 173718:tid 173958] [client 74.7.228.27:60272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aetiiph.net"] [uri "/index.php"] [unique_id "amu0HEoi7QGnEa1uk6nC6gAAbQ4"]
[Thu Jul 30 15:29:17.944642 2026] [security2:error] [pid 173718:tid 173919] [client 20.171.55.167:3103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/wso-latest.php"] [unique_id "amu0HUoi7QGnEa1uk6nDJwAAAEY"]
[Thu Jul 30 15:29:18.084714 2026] [security2:error] [pid 173718:tid 173937] [client 74.7.228.27:60278] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aetiiph.net"] [uri "/index.php"] [unique_id "amu0Hkoi7QGnEa1uk6nDLQAAWDs"], referer: https://www.aetiiph.net/robots.txt
[Thu Jul 30 15:29:18.158488 2026] [security2:error] [pid 173718:tid 173882] [client 172.213.208.20:36915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-content/themes/index.php"] [unique_id "amu0Hkoi7QGnEa1uk6nDMQAAACE"]
[Thu Jul 30 15:29:18.425613 2026] [core:notice] [pid 173718:tid 173793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:18.433580 2026] [security2:error] [pid 173718:tid 173951] [client 193.106.21.186:43814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu0Hkoi7QGnEa1uk6nDMAAAAGY"], referer: http://pkf.jo
[Thu Jul 30 15:29:18.687933 2026] [security2:error] [pid 173718:tid 173930] [client 20.171.55.167:3675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/x1.php"] [unique_id "amu0Hkoi7QGnEa1uk6nDRAAAAFE"]
[Thu Jul 30 15:29:18.745001 2026] [security2:error] [pid 173718:tid 173849] [client 172.213.208.20:51623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/wp-file.php"] [unique_id "amu0Hkoi7QGnEa1uk6nDRgAAAAA"]
[Thu Jul 30 15:29:18.862240 2026] [core:notice] [pid 173718:tid 173929] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:18.866261 2026] [security2:error] [pid 173718:tid 173929] [client 66.249.79.229:58223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/Konstruksi/article/view/3815"] [unique_id "amu0Hkoi7QGnEa1uk6nDTwAAAFA"]
[Thu Jul 30 15:29:19.393783 2026] [security2:error] [pid 173718:tid 173963] [client 20.171.55.167:3396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/xlt.php"] [unique_id "amu0H0oi7QGnEa1uk6nDYgAAAHI"]
[Thu Jul 30 15:29:19.980661 2026] [security2:error] [pid 173718:tid 173974] [client 213.230.87.142:12666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu0H0oi7QGnEa1uk6nDcQAAAH0"], referer: http://pkf.jo
[Thu Jul 30 15:29:20.156404 2026] [security2:error] [pid 173718:tid 173900] [client 20.171.55.167:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/yanznopat.php"] [unique_id "amu0IEoi7QGnEa1uk6nDfwAAADM"]
[Thu Jul 30 15:29:20.904861 2026] [security2:error] [pid 173718:tid 173934] [client 20.171.55.167:3706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "toscanamall.com"] [uri "/zgdsfage/rk3.php"] [unique_id "amu0IEoi7QGnEa1uk6nDlwAAAFU"]
[Thu Jul 30 15:29:21.084421 2026] [security2:error] [pid 173718:tid 173959] [client 176.67.18.175:19184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu0IEoi7QGnEa1uk6nDjwAAbj4"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxxclips.mobi
[Thu Jul 30 15:29:21.099066 2026] [security2:error] [pid 173718:tid 173931] [client 38.172.162.57:16315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0IUoi7QGnEa1uk6nDmwAAAFI"]
[Thu Jul 30 15:29:21.099753 2026] [security2:error] [pid 173718:tid 173931] [client 38.172.162.57:16315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0IUoi7QGnEa1uk6nDmwAAAFI"]
[Thu Jul 30 15:29:21.350564 2026] [core:error] [pid 173718:tid 173919] [client 193.47.62.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:29:21.350600 2026] [core:error] [pid 173718:tid 173919] [client 193.47.62.167:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:29:22.120542 2026] [security2:error] [pid 173718:tid 173954] [client 88.168.127.16:2572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu0IUoi7QGnEa1uk6nDtQAAaVs"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fxxx18video.club
[Thu Jul 30 15:29:22.227242 2026] [security2:error] [pid 173718:tid 173865] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0IUoi7QGnEa1uk6nDrgAAABA"]
[Thu Jul 30 15:29:22.601940 2026] [security2:error] [pid 173718:tid 173884] [client 172.213.208.20:48449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shop-kent.com"] [uri "/sid3.php"] [unique_id "amu0Ikoi7QGnEa1uk6nDzgAAACM"]
[Thu Jul 30 15:29:22.688408 2026] [core:notice] [pid 173718:tid 173786] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:22.691723 2026] [security2:error] [pid 173718:tid 173889] [client 66.249.74.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/79/82"] [unique_id "amu0Ikoi7QGnEa1uk6nDzwAAKEI"]
[Thu Jul 30 15:29:22.833048 2026] [core:notice] [pid 173718:tid 173969] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:23.085370 2026] [security2:error] [pid 173718:tid 173939] [client 2a03:2880:f800:24:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0Ikoi7QGnEa1uk6nDxAAAWkg"]
[Thu Jul 30 15:29:24.043239 2026] [security2:error] [pid 173718:tid 173927] [client 57.141.0.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0I0oi7QGnEa1uk6nD6wAAAE4"]
[Thu Jul 30 15:29:24.514715 2026] [core:notice] [pid 173718:tid 173836] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:24.854114 2026] [core:error] [pid 173718:tid 173846] [remote 216.73.216.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:29:24.854138 2026] [core:error] [pid 173718:tid 173846] [remote 216.73.216.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:29:25.160058 2026] [core:notice] [pid 173718:tid 173827] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:25.988900 2026] [core:notice] [pid 173718:tid 173975] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:25.992094 2026] [security2:error] [pid 173718:tid 173975] [client 66.249.79.8:37517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/8222/3201"] [unique_id "amu0JUoi7QGnEa1uk6nENAAAAH4"]
[Thu Jul 30 15:29:26.144096 2026] [security2:error] [pid 173718:tid 173917] [client 94.154.43.229:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ok.tiger388.shop"] [uri "/.env"] [unique_id "amu0Jkoi7QGnEa1uk6nERQAAAEQ"]
[Thu Jul 30 15:29:26.186727 2026] [security2:error] [pid 173718:tid 173936] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0Jkoi7QGnEa1uk6nEQwAAAFc"]
[Thu Jul 30 15:29:30.592257 2026] [security2:error] [pid 173718:tid 173964] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0KUoi7QGnEa1uk6nEtgAAAHM"]
[Thu Jul 30 15:29:31.729759 2026] [security2:error] [pid 173718:tid 173877] [client 38.172.162.57:16593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0K0oi7QGnEa1uk6nE4QAAABw"]
[Thu Jul 30 15:29:31.729904 2026] [security2:error] [pid 173718:tid 173877] [client 38.172.162.57:16593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0K0oi7QGnEa1uk6nE4QAAABw"]
[Thu Jul 30 15:29:32.609718 2026] [core:notice] [pid 173718:tid 173940] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:32.612568 2026] [security2:error] [pid 173718:tid 173940] [client 66.249.74.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/31/34"] [unique_id "amu0LEoi7QGnEa1uk6nE7AAAAFs"]
[Thu Jul 30 15:29:32.744415 2026] [security2:error] [pid 173718:tid 173903] [client 2a03:2880:f800:e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0LEoi7QGnEa1uk6nE6wAANkQ"]
[Thu Jul 30 15:29:34.014001 2026] [security2:error] [pid 173718:tid 173799] [remote 74.7.243.224:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/misionf.php"] [unique_id "amu0Lkoi7QGnEa1uk6nFIgAAXU8"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/article.php?id=27
[Thu Jul 30 15:29:34.174312 2026] [security2:error] [pid 173718:tid 173921] [client 213.32.68.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0Lkoi7QGnEa1uk6nFJQAAAEg"]
[Thu Jul 30 15:29:35.044651 2026] [core:notice] [pid 173718:tid 173857] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:35.186004 2026] [security2:error] [pid 173718:tid 173952] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0L0oi7QGnEa1uk6nFTAAAAGc"]
[Thu Jul 30 15:29:35.437719 2026] [security2:error] [pid 173718:tid 173935] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0L0oi7QGnEa1uk6nFWQAAAFY"]
[Thu Jul 30 15:29:35.677791 2026] [security2:error] [pid 173718:tid 173943] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0L0oi7QGnEa1uk6nFXQAAAF4"]
[Thu Jul 30 15:29:35.913132 2026] [security2:error] [pid 173718:tid 173976] [client 51.77.210.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0L0oi7QGnEa1uk6nFawAAAH8"]
[Thu Jul 30 15:29:36.313784 2026] [security2:error] [pid 173718:tid 173875] [client 213.32.68.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0MEoi7QGnEa1uk6nFdgAAABo"]
[Thu Jul 30 15:29:36.715533 2026] [security2:error] [pid 173718:tid 173883] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0MEoi7QGnEa1uk6nFfwAAACI"]
[Thu Jul 30 15:29:36.973402 2026] [security2:error] [pid 173718:tid 173901] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0MEoi7QGnEa1uk6nFiAAAADQ"]
[Thu Jul 30 15:29:37.211476 2026] [security2:error] [pid 173718:tid 173937] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0MUoi7QGnEa1uk6nFkAAAAFg"]
[Thu Jul 30 15:29:38.221335 2026] [security2:error] [pid 173718:tid 173957] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0Mkoi7QGnEa1uk6nFrAAAAGw"]
[Thu Jul 30 15:29:38.466915 2026] [security2:error] [pid 173718:tid 173932] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0Mkoi7QGnEa1uk6nFsgAAAFM"]
[Thu Jul 30 15:29:38.700956 2026] [security2:error] [pid 173718:tid 173958] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0Mkoi7QGnEa1uk6nFugAAAG0"]
[Thu Jul 30 15:29:39.113645 2026] [core:notice] [pid 173718:tid 173846] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:39.562152 2026] [security2:error] [pid 173718:tid 173883] [client 172.237.109.114:24474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0M0oi7QGnEa1uk6nFxgAAACI"]
[Thu Jul 30 15:29:39.735623 2026] [security2:error] [pid 173718:tid 173907] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0M0oi7QGnEa1uk6nF1wAAADo"]
[Thu Jul 30 15:29:39.867551 2026] [security2:error] [pid 173718:tid 173960] [client 85.208.96.208:59042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/the-claims-of-jesus-2/"] [unique_id "amu0M0oi7QGnEa1uk6nF2wAAAG8"]
[Thu Jul 30 15:29:39.867758 2026] [security2:error] [pid 173718:tid 173960] [client 85.208.96.208:59042] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jesus.claims"] [uri "/the-claims-of-jesus-2/"] [unique_id "amu0M0oi7QGnEa1uk6nF2wAAAG8"]
[Thu Jul 30 15:29:40.383592 2026] [security2:error] [pid 173718:tid 173921] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0NEoi7QGnEa1uk6nF6QAAAEg"]
[Thu Jul 30 15:29:40.628732 2026] [security2:error] [pid 173718:tid 173951] [client 172.237.109.114:18136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0NEoi7QGnEa1uk6nF5gAAAGY"]
[Thu Jul 30 15:29:40.757160 2026] [core:notice] [pid 173718:tid 173940] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:41.288872 2026] [security2:error] [pid 173718:tid 173937] [client 183.207.45.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0NUoi7QGnEa1uk6nGEAAAAFg"]
[Thu Jul 30 15:29:41.302664 2026] [core:notice] [pid 173718:tid 173898] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:42.289077 2026] [security2:error] [pid 173718:tid 173869] [client 38.172.162.57:16596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0Nkoi7QGnEa1uk6nGKwAAABQ"]
[Thu Jul 30 15:29:42.289695 2026] [security2:error] [pid 173718:tid 173869] [client 38.172.162.57:16596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0Nkoi7QGnEa1uk6nGKwAAABQ"]
[Thu Jul 30 15:29:45.440167 2026] [security2:error] [pid 173718:tid 173910] [client 74.7.175.185:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ojq.udi.temporary.site"] [uri "/index.php"] [unique_id "amu0OEoi7QGnEa1uk6nGWwAAAD0"]
[Thu Jul 30 15:29:45.441042 2026] [security2:error] [pid 173718:tid 173904] [client 74.7.175.185:53556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ojq.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amu0OEoi7QGnEa1uk6nGVgAANw0"]
[Thu Jul 30 15:29:45.855254 2026] [core:notice] [pid 173718:tid 173786] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:47.065840 2026] [security2:error] [pid 173718:tid 173900] [client 45.170.58.109:13601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu0Okoi7QGnEa1uk6nG1wAAADM"], referer: http://pkf.jo
[Thu Jul 30 15:29:47.497327 2026] [security2:error] [pid 173718:tid 173953] [client 85.208.96.203:55130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/15/tse-realiza-teste-em-56-urnas-com-biometria-no-pais/"] [unique_id "amu0O0oi7QGnEa1uk6nG9wAAAGg"]
[Thu Jul 30 15:29:47.497438 2026] [security2:error] [pid 173718:tid 173953] [client 85.208.96.203:55130] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/15/tse-realiza-teste-em-56-urnas-com-biometria-no-pais/"] [unique_id "amu0O0oi7QGnEa1uk6nG9wAAAGg"]
[Thu Jul 30 15:29:49.298719 2026] [security2:error] [pid 173718:tid 173780] [remote 104.210.56.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.56.210.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/188"] [unique_id "amu0PUoi7QGnEa1uk6nHJAAAcjw"]
[Thu Jul 30 15:29:49.307016 2026] [security2:error] [pid 173718:tid 173941] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0PEoi7QGnEa1uk6nHFQAAXFI"]
[Thu Jul 30 15:29:49.808309 2026] [security2:error] [pid 173718:tid 173855] [client 193.194.126.226:59134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu0PUoi7QGnEa1uk6nHLgAABmU"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fdamplips.yachts
[Thu Jul 30 15:29:50.027109 2026] [security2:error] [pid 173718:tid 173894] [client 158.172.227.206:37460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu0PUoi7QGnEa1uk6nHMwAAAC0"], referer: http://pkf.jo
[Thu Jul 30 15:29:52.118675 2026] [security2:error] [pid 173718:tid 173946] [client 57.141.0.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0P0oi7QGnEa1uk6nHZwAAAGE"]
[Thu Jul 30 15:29:52.176909 2026] [core:notice] [pid 173718:tid 173829] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:52.317172 2026] [security2:error] [pid 173718:tid 173901] [client 91.167.244.126:39032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu0P0oi7QGnEa1uk6nHbwAANAY"], referer: http://pkf.jo/Home/ChangeCulture?langCode=en&returnUrl=http%3A%2F%2Fhqporntubes.com
[Thu Jul 30 15:29:52.412595 2026] [security2:error] [pid 173718:tid 173900] [client 216.73.216.33:21509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.jdasecurity.ph"] [uri "/index.php"] [unique_id "amu0QEoi7QGnEa1uk6nHewAAMxs"]
[Thu Jul 30 15:29:52.858560 2026] [security2:error] [pid 173718:tid 173968] [client 38.172.162.57:15997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0QEoi7QGnEa1uk6nHigAAAHc"]
[Thu Jul 30 15:29:52.858664 2026] [security2:error] [pid 173718:tid 173968] [client 38.172.162.57:15997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0QEoi7QGnEa1uk6nHigAAAHc"]
[Thu Jul 30 15:29:53.277243 2026] [core:notice] [pid 173718:tid 173735] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:53.281112 2026] [security2:error] [pid 173718:tid 173969] [client 66.249.74.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/200/198"] [unique_id "amu0QUoi7QGnEa1uk6nHjwAAeA8"]
[Thu Jul 30 15:29:56.464281 2026] [security2:error] [pid 173718:tid 173944] [client 111.225.149.154:39170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/assets/images/safari-city-creek6.jpg"] [unique_id "amu0REoi7QGnEa1uk6nH4AAAAF8"]
[Thu Jul 30 15:29:57.499296 2026] [core:notice] [pid 173718:tid 173949] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:29:57.502817 2026] [security2:error] [pid 173718:tid 173949] [client 66.249.79.8:54573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/jurnaltuturan/article/view/1583"] [unique_id "amu0RUoi7QGnEa1uk6nH9AAAAGQ"]
[Thu Jul 30 15:29:59.534851 2026] [security2:error] [pid 173718:tid 173956] [client 204.8.98.55:57646] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu0R0oi7QGnEa1uk6nIHAAAAGs"]
[Thu Jul 30 15:29:59.534943 2026] [security2:error] [pid 173718:tid 173956] [client 204.8.98.55:57646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu0R0oi7QGnEa1uk6nIHAAAAGs"]
[Thu Jul 30 15:30:00.343857 2026] [security2:error] [pid 173718:tid 173913] [client 2a03:2880:f800:22:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0R0oi7QGnEa1uk6nIHQAAQFw"]
[Thu Jul 30 15:30:00.964590 2026] [security2:error] [pid 173718:tid 173970] [client 172.237.109.114:5723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/pages/UI.php"] [unique_id "amu0SEoi7QGnEa1uk6nINwAAAHk"]
[Thu Jul 30 15:30:01.915928 2026] [core:notice] [pid 173718:tid 173950] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:02.205649 2026] [security2:error] [pid 173718:tid 173964] [client 185.191.171.13:39044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/05/06/produtores-de-leite-estao-ha-tres-meses-sem-receber-por-falta-de-contrapartida-do-estado/"] [unique_id "amu0Skoi7QGnEa1uk6nIZAAAAHM"]
[Thu Jul 30 15:30:02.205799 2026] [security2:error] [pid 173718:tid 173964] [client 185.191.171.13:39044] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/05/06/produtores-de-leite-estao-ha-tres-meses-sem-receber-por-falta-de-contrapartida-do-estado/"] [unique_id "amu0Skoi7QGnEa1uk6nIZAAAAHM"]
[Thu Jul 30 15:30:02.245266 2026] [security2:error] [pid 173718:tid 173933] [client 155.117.163.173:54496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.toscanamall.com"] [uri "/2535-medium/bananarama-e-neste-queens-flavors.jpg"] [unique_id "amu0Skoi7QGnEa1uk6nIZQAAAFQ"]
[Thu Jul 30 15:30:03.135894 2026] [autoindex:error] [pid 173718:tid 173888] [client 43.157.50.58:51604] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_08e91e41/fi/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.toscanamall.com/fi/
[Thu Jul 30 15:30:03.404523 2026] [security2:error] [pid 173718:tid 173877] [client 38.172.162.57:16277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0S0oi7QGnEa1uk6nIfwAAABw"]
[Thu Jul 30 15:30:03.404638 2026] [security2:error] [pid 173718:tid 173877] [client 38.172.162.57:16277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0S0oi7QGnEa1uk6nIfwAAABw"]
[Thu Jul 30 15:30:03.490527 2026] [security2:error] [pid 173718:tid 173819] [remote 57.141.0.39:21354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amu0S0oi7QGnEa1uk6nIgAAAKWM"]
[Thu Jul 30 15:30:03.839365 2026] [security2:error] [pid 173718:tid 173952] [client 66.249.64.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amu0Skoi7QGnEa1uk6nIcwAAZ3s"]
[Thu Jul 30 15:30:06.036434 2026] [security2:error] [pid 173718:tid 173853] [client 2803:9810:4c03:b010:e276:d0ff:fe6b:32c:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0TUoi7QGnEa1uk6nIqAAABFE"], referer: https://allmontecristi.com
[Thu Jul 30 15:30:08.929834 2026] [security2:error] [pid 173718:tid 173927] [client 216.244.66.230:33762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amu0UEoi7QGnEa1uk6nI-AAAAE4"]
[Thu Jul 30 15:30:08.929955 2026] [security2:error] [pid 173718:tid 173927] [client 216.244.66.230:33762] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amu0UEoi7QGnEa1uk6nI-AAAAE4"]
[Thu Jul 30 15:30:10.400848 2026] [core:notice] [pid 173718:tid 173884] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:10.486728 2026] [security2:error] [pid 173718:tid 173945] [client 54.164.106.236:37611] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/10500449_600496200087950_2134321597335213658_n.jpg"] [unique_id "amu0Ukoi7QGnEa1uk6nJIwAAAGA"]
[Thu Jul 30 15:30:10.577768 2026] [security2:error] [pid 173718:tid 173906] [client 172.202.44.182:39489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wk/index.php"] [unique_id "amu0Ukoi7QGnEa1uk6nJJwAAADk"]
[Thu Jul 30 15:30:11.773746 2026] [security2:error] [pid 173718:tid 173975] [client 172.202.44.182:37946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/av.php"] [unique_id "amu0U0oi7QGnEa1uk6nJQwAAAH4"]
[Thu Jul 30 15:30:11.816248 2026] [security2:error] [pid 173718:tid 173865] [client 68.221.186.136:10078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/geju.php"] [unique_id "amu0U0oi7QGnEa1uk6nJRwAAABA"]
[Thu Jul 30 15:30:11.917632 2026] [security2:error] [pid 173718:tid 173858] [client 216.73.216.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.com"] [uri "/index.php"] [unique_id "amu0U0oi7QGnEa1uk6nJRgAAAAk"]
[Thu Jul 30 15:30:12.347074 2026] [security2:error] [pid 173718:tid 173915] [client 68.221.186.136:5229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amu0VEoi7QGnEa1uk6nJUgAAAEI"]
[Thu Jul 30 15:30:13.907450 2026] [security2:error] [pid 173718:tid 173893] [client 172.202.44.182:39545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/mini.php"] [unique_id "amu0VUoi7QGnEa1uk6nJdAAAACw"]
[Thu Jul 30 15:30:13.938992 2026] [security2:error] [pid 173718:tid 173946] [client 38.172.162.57:16253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0VUoi7QGnEa1uk6nJeAAAAGE"]
[Thu Jul 30 15:30:13.939109 2026] [security2:error] [pid 173718:tid 173946] [client 38.172.162.57:16253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0VUoi7QGnEa1uk6nJeAAAAGE"]
[Thu Jul 30 15:30:14.223287 2026] [core:error] [pid 173718:tid 173796] [remote 74.7.175.142:46924] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:30:14.223315 2026] [core:error] [pid 173718:tid 173796] [remote 74.7.175.142:46924] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:30:14.223564 2026] [security2:error] [pid 173718:tid 173905] [client 74.7.175.142:46924] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.rodneyleesmith.com.dov.dtn.temporary.site"] [uri "/index.php"] [unique_id "amu0Vkoi7QGnEa1uk6nJfAAAOEw"]
[Thu Jul 30 15:30:14.346033 2026] [security2:error] [pid 173718:tid 173907] [client 54.164.106.236:47183] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2015/03/20915_600495906754646_8324340701731763019_n.jpg"] [unique_id "amu0Vkoi7QGnEa1uk6nJgQAAADo"]
[Thu Jul 30 15:30:15.131287 2026] [security2:error] [pid 173718:tid 173917] [client 172.202.44.182:39491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/aa.php"] [unique_id "amu0V0oi7QGnEa1uk6nJlAAAAEQ"]
[Thu Jul 30 15:30:15.621397 2026] [core:error] [pid 173718:tid 173852] [client 23.95.96.140:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:30:15.621420 2026] [core:error] [pid 173718:tid 173852] [client 23.95.96.140:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:30:15.726843 2026] [security2:error] [pid 173718:tid 173906] [client 213.152.162.84:45366] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu0V0oi7QGnEa1uk6nJmQAAADk"]
[Thu Jul 30 15:30:15.727037 2026] [security2:error] [pid 173718:tid 173906] [client 213.152.162.84:45366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu0V0oi7QGnEa1uk6nJmQAAADk"]
[Thu Jul 30 15:30:16.634591 2026] [security2:error] [pid 173718:tid 173856] [client 172.202.44.182:37891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/w.php"] [unique_id "amu0WEoi7QGnEa1uk6nJuAAAAAc"]
[Thu Jul 30 15:30:16.912557 2026] [security2:error] [pid 173718:tid 173927] [client 68.221.186.136:2453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp.php"] [unique_id "amu0WEoi7QGnEa1uk6nJvwAAAE4"]
[Thu Jul 30 15:30:16.977243 2026] [security2:error] [pid 173718:tid 173939] [client 172.237.109.114:9388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/simple/pages/UI.php"] [unique_id "amu0WEoi7QGnEa1uk6nJwAAAAFo"]
[Thu Jul 30 15:30:17.053222 2026] [security2:error] [pid 173718:tid 173911] [client 50.6.43.217:11184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "cmplboard.com"] [uri "/public/tools/reg_refetch.php"] [unique_id "amu0SUoi7QGnEa1uk6nITwAAAD4"]
[Thu Jul 30 15:30:17.508374 2026] [security2:error] [pid 173718:tid 173960] [client 68.221.186.136:6394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/aaa.php"] [unique_id "amu0WUoi7QGnEa1uk6nJywAAAG8"]
[Thu Jul 30 15:30:17.969061 2026] [security2:error] [pid 173718:tid 173955] [client 172.202.44.182:39527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/admin.php"] [unique_id "amu0WUoi7QGnEa1uk6nJ1gAAAGo"]
[Thu Jul 30 15:30:18.276759 2026] [security2:error] [pid 173718:tid 173962] [client 74.7.175.179:37896] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mails.moswey.com"] [uri "/cgi-sys/404.html"] [unique_id "amu0Wkoi7QGnEa1uk6nJ3gAAcWY"]
[Thu Jul 30 15:30:18.363821 2026] [core:notice] [pid 173718:tid 173936] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:18.514705 2026] [security2:error] [pid 173718:tid 173875] [client 213.152.162.84:36524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu0Wkoi7QGnEa1uk6nJ6AAAABo"]
[Thu Jul 30 15:30:18.514801 2026] [security2:error] [pid 173718:tid 173875] [client 213.152.162.84:36524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu0Wkoi7QGnEa1uk6nJ6AAAABo"]
[Thu Jul 30 15:30:18.530413 2026] [security2:error] [pid 173718:tid 173863] [client 74.7.241.167:57280] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.deltaedu.net"] [uri "/index.php"] [unique_id "amu0Wkoi7QGnEa1uk6nJ4AAADmw"]
[Thu Jul 30 15:30:18.530459 2026] [security2:error] [pid 173718:tid 173863] [client 74.7.241.167:57280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.deltaedu.net"] [uri "/index.php"] [unique_id "amu0Wkoi7QGnEa1uk6nJ4AAADmw"]
[Thu Jul 30 15:30:18.778770 2026] [security2:error] [pid 173718:tid 173953] [client 3.213.85.234:48300] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2019/07/8C845158-C398-41B5-AC62-254DF9DDC126-1024x1024-768x768.jpeg"] [unique_id "amu0Wkoi7QGnEa1uk6nJ7QAAAGg"]
[Thu Jul 30 15:30:18.900774 2026] [security2:error] [pid 173718:tid 173888] [client 172.202.44.182:39538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/themes/admin.php"] [unique_id "amu0Wkoi7QGnEa1uk6nJ8gAAACc"]
[Thu Jul 30 15:30:18.920140 2026] [security2:error] [pid 173718:tid 173964] [client 57.141.18.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.designmenow.net"] [uri "/public/index.php"] [unique_id "amu0Wkoi7QGnEa1uk6nJ1wAAc1k"]
[Thu Jul 30 15:30:18.985402 2026] [security2:error] [pid 173718:tid 173954] [client 68.221.186.136:2108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/hoot.php"] [unique_id "amu0Wkoi7QGnEa1uk6nJ9gAAAGk"]
[Thu Jul 30 15:30:19.220851 2026] [security2:error] [pid 173718:tid 173856] [client 74.7.241.167:57282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "deltaedu.net"] [uri "/index.php"] [unique_id "amu0W0oi7QGnEa1uk6nJ-wAAB2A"], referer: https://www.deltaedu.net/robots.txt
[Thu Jul 30 15:30:19.820870 2026] [security2:error] [pid 173718:tid 173900] [client 172.202.44.182:61551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/m.php"] [unique_id "amu0W0oi7QGnEa1uk6nKCAAAADM"]
[Thu Jul 30 15:30:20.302253 2026] [security2:error] [pid 173718:tid 173950] [client 68.221.186.136:2066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/about.php"] [unique_id "amu0XEoi7QGnEa1uk6nKEwAAAGU"]
[Thu Jul 30 15:30:20.304153 2026] [security2:error] [pid 173718:tid 173827] [remote 57.141.0.28:29624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/64637765089/feed/rss2/"] [unique_id "amu0XEoi7QGnEa1uk6nKFAAARGs"]
[Thu Jul 30 15:30:20.305734 2026] [security2:error] [pid 173718:tid 173894] [client 216.73.216.131:20565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.mgr3.com"] [uri "/index.php"] [unique_id "amu0XEoi7QGnEa1uk6nKDwAALXY"]
[Thu Jul 30 15:30:20.602056 2026] [security2:error] [pid 173718:tid 173839] [remote 57.141.0.52:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amu0XEoi7QGnEa1uk6nKGAAAbXc"]
[Thu Jul 30 15:30:20.832796 2026] [security2:error] [pid 173718:tid 173929] [client 172.202.44.182:12213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amu0XEoi7QGnEa1uk6nKIgAAAFA"]
[Thu Jul 30 15:30:20.842046 2026] [security2:error] [pid 173718:tid 173870] [client 37.41.123.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0XEoi7QGnEa1uk6nKHQAAABU"], referer: https://cnpinyin.com
[Thu Jul 30 15:30:22.275591 2026] [security2:error] [pid 173718:tid 173939] [client 172.202.44.182:61526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/classwithtostring.php"] [unique_id "amu0Xkoi7QGnEa1uk6nKPQAAAFo"]
[Thu Jul 30 15:30:22.545743 2026] [security2:error] [pid 173718:tid 173899] [client 34.227.156.153:40454] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/1478115326023-vivianny-90x60.jpg"] [unique_id "amu0Xkoi7QGnEa1uk6nKRwAAADI"]
[Thu Jul 30 15:30:22.759617 2026] [security2:error] [pid 173718:tid 173932] [client 195.88.139.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0Xkoi7QGnEa1uk6nKTQAAAFM"], referer: http://cnpinyin.com
[Thu Jul 30 15:30:22.862014 2026] [security2:error] [pid 173718:tid 173841] [remote 57.141.0.24:59436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/74297757886/feed/rss2/"] [unique_id "amu0Xkoi7QGnEa1uk6nKUQAAPXk"]
[Thu Jul 30 15:30:23.287333 2026] [security2:error] [pid 173718:tid 173874] [client 68.221.186.136:5208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/admin.php"] [unique_id "amu0X0oi7QGnEa1uk6nKXAAAABk"]
[Thu Jul 30 15:30:23.872036 2026] [security2:error] [pid 173718:tid 173944] [client 68.221.186.136:2068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amu0X0oi7QGnEa1uk6nKaAAAAF8"]
[Thu Jul 30 15:30:24.221901 2026] [core:notice] [pid 173718:tid 173943] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:24.237300 2026] [security2:error] [pid 173718:tid 173921] [client 204.8.98.55:53982] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amu0X0oi7QGnEa1uk6nKawAAAEg"]
[Thu Jul 30 15:30:24.237481 2026] [security2:error] [pid 173718:tid 173921] [client 204.8.98.55:53982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amu0X0oi7QGnEa1uk6nKawAAAEg"]
[Thu Jul 30 15:30:24.367874 2026] [core:notice] [pid 173718:tid 173747] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:24.508193 2026] [security2:error] [pid 173718:tid 173933] [client 172.202.44.182:12087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/gmo.php"] [unique_id "amu0YEoi7QGnEa1uk6nKfAAAAFQ"]
[Thu Jul 30 15:30:24.584244 2026] [security2:error] [pid 173718:tid 173890] [client 38.172.162.57:16472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0YEoi7QGnEa1uk6nKfgAAACk"]
[Thu Jul 30 15:30:24.584369 2026] [security2:error] [pid 173718:tid 173890] [client 38.172.162.57:16472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0YEoi7QGnEa1uk6nKfgAAACk"]
[Thu Jul 30 15:30:25.241335 2026] [core:notice] [pid 173718:tid 173947] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:25.251546 2026] [security2:error] [pid 173718:tid 173740] [remote 103.124.95.115:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frontierphoenix.site"] [uri "/wp-login.php"] [unique_id "amu0YUoi7QGnEa1uk6nKjgAAZRQ"]
[Thu Jul 30 15:30:25.361959 2026] [security2:error] [pid 173718:tid 173910] [client 172.202.44.182:12060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/languages/index.php"] [unique_id "amu0YUoi7QGnEa1uk6nKjwAAAD0"]
[Thu Jul 30 15:30:25.502263 2026] [core:notice] [pid 173718:tid 173873] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:26.069824 2026] [security2:error] [pid 173718:tid 173889] [client 68.221.186.136:12982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/db-cache.php"] [unique_id "amu0Ykoi7QGnEa1uk6nKqAAAACg"]
[Thu Jul 30 15:30:26.315908 2026] [security2:error] [pid 173718:tid 173936] [client 57.141.0.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0YUoi7QGnEa1uk6nKnwAAAFc"]
[Thu Jul 30 15:30:26.506871 2026] [security2:error] [pid 173718:tid 173972] [client 34.226.89.140:62341] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/09/mini_urna_cabine-400x299.jpg"] [unique_id "amu0Ykoi7QGnEa1uk6nKsAAAAHs"]
[Thu Jul 30 15:30:26.689962 2026] [security2:error] [pid 173718:tid 173888] [client 172.202.44.182:12101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-the.php"] [unique_id "amu0Ykoi7QGnEa1uk6nKtwAAACc"]
[Thu Jul 30 15:30:28.361252 2026] [core:notice] [pid 173718:tid 173774] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:28.369504 2026] [security2:error] [pid 173718:tid 173770] [remote 57.141.0.10:64990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu0ZEoi7QGnEa1uk6nK4wAAQzI"]
[Thu Jul 30 15:30:28.641660 2026] [security2:error] [pid 173718:tid 173935] [client 68.221.186.136:2465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amu0ZEoi7QGnEa1uk6nK5QAAAFY"]
[Thu Jul 30 15:30:29.551383 2026] [security2:error] [pid 173718:tid 173957] [client 172.202.44.182:12279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/404.php"] [unique_id "amu0ZUoi7QGnEa1uk6nK_gAAAGw"]
[Thu Jul 30 15:30:29.598637 2026] [security2:error] [pid 173718:tid 173849] [client 68.221.186.136:2452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amu0ZUoi7QGnEa1uk6nK_wAAAAA"]
[Thu Jul 30 15:30:30.558152 2026] [security2:error] [pid 173718:tid 173946] [client 3.212.205.90:8840] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2016/11/unnamed-4-90x60.jpg"] [unique_id "amu0Zkoi7QGnEa1uk6nLIQAAAGE"]
[Thu Jul 30 15:30:30.769558 2026] [core:notice] [pid 173718:tid 173924] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:30.774681 2026] [autoindex:error] [pid 173718:tid 173924] [client 66.249.79.8:62968] AH01276: Cannot serve directory /home1/vdbnyxte/public_html/website_ab4e48f3/index.php/cicee/article/view/9404: No matching DirectoryIndex (none) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:30:30.774868 2026] [security2:error] [pid 173718:tid 173924] [client 66.249.79.8:62968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/view/9404"] [unique_id "amu0Zkoi7QGnEa1uk6nLIAAAAEs"]
[Thu Jul 30 15:30:31.047045 2026] [security2:error] [pid 173718:tid 173939] [client 127.0.0.1:54996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu0Z0oi7QGnEa1uk6nLMgAAAFo"]
[Thu Jul 30 15:30:31.047087 2026] [security2:error] [pid 173718:tid 173866] [client 127.0.0.1:54992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.alanturner.com.au"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu0Z0oi7QGnEa1uk6nLMQAAABE"]
[Thu Jul 30 15:30:31.047168 2026] [security2:error] [pid 173718:tid 173912] [client 74.7.244.12:50192] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.alanturner.com.au"] [uri "/robots.txt"] [unique_id "amu0Z0oi7QGnEa1uk6nLMAAAP2Q"]
[Thu Jul 30 15:30:31.841190 2026] [security2:error] [pid 173718:tid 173953] [client 172.202.44.182:39548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/init.php"] [unique_id "amu0Z0oi7QGnEa1uk6nLRQAAAGg"]
[Thu Jul 30 15:30:31.887185 2026] [security2:error] [pid 173718:tid 173934] [client 68.221.186.136:5386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amu0Z0oi7QGnEa1uk6nLSQAAAFU"]
[Thu Jul 30 15:30:32.444917 2026] [security2:error] [pid 173718:tid 173945] [client 68.221.186.136:12980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amu0aEoi7QGnEa1uk6nLWwAAAGA"]
[Thu Jul 30 15:30:32.895675 2026] [security2:error] [pid 173718:tid 173956] [client 172.202.44.182:12116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/file5.php"] [unique_id "amu0aEoi7QGnEa1uk6nLZwAAAGs"]
[Thu Jul 30 15:30:33.789594 2026] [core:notice] [pid 173718:tid 173892] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:33.965186 2026] [security2:error] [pid 173718:tid 173809] [remote 57.141.0.26:46120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5351135361/feed/rss2/"] [unique_id "amu0aUoi7QGnEa1uk6nLhQAARFk"]
[Thu Jul 30 15:30:34.118068 2026] [security2:error] [pid 173718:tid 173934] [client 172.202.44.182:56321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/maint/index.php"] [unique_id "amu0akoi7QGnEa1uk6nLjAAAAFU"]
[Thu Jul 30 15:30:34.173108 2026] [core:error] [pid 173718:tid 173860] [client 52.167.144.25:33494] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:30:34.173127 2026] [core:error] [pid 173718:tid 173860] [client 52.167.144.25:33494] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:30:34.331068 2026] [security2:error] [pid 173718:tid 173900] [client 68.221.186.136:40810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amu0akoi7QGnEa1uk6nLkQAAADM"]
[Thu Jul 30 15:30:34.845854 2026] [security2:error] [pid 173718:tid 173924] [client 54.85.109.140:25130] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.nordeste1.com"] [uri "/wp-content/uploads/2020/11/Decis%C3%A3o-RP-06003295320206150060-JACARA%C3%9A-1.pdf"] [unique_id "amu0akoi7QGnEa1uk6nLmwAAAEs"]
[Thu Jul 30 15:30:35.203199 2026] [security2:error] [pid 173718:tid 173914] [client 38.172.162.57:16541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0a0oi7QGnEa1uk6nLpQAAAEE"]
[Thu Jul 30 15:30:35.203304 2026] [security2:error] [pid 173718:tid 173914] [client 38.172.162.57:16541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0a0oi7QGnEa1uk6nLpQAAAEE"]
[Thu Jul 30 15:30:35.545600 2026] [security2:error] [pid 173718:tid 173780] [remote 74.7.243.224:42056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/donatef.php"] [unique_id "amu0a0oi7QGnEa1uk6nLqgAAXDw"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/article.php?id=27
[Thu Jul 30 15:30:35.663917 2026] [security2:error] [pid 173718:tid 173912] [client 172.202.44.182:12219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/shell.php"] [unique_id "amu0a0oi7QGnEa1uk6nLrgAAAD8"]
[Thu Jul 30 15:30:36.530963 2026] [security2:error] [pid 173718:tid 173955] [client 68.221.186.136:5227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/content.php"] [unique_id "amu0bEoi7QGnEa1uk6nLwQAAAGo"]
[Thu Jul 30 15:30:36.832081 2026] [security2:error] [pid 173718:tid 173966] [client 172.202.44.182:43427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/f35.php"] [unique_id "amu0bEoi7QGnEa1uk6nLzQAAAHU"]
[Thu Jul 30 15:30:37.414663 2026] [security2:error] [pid 173718:tid 173946] [client 68.221.186.136:2519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amu0bUoi7QGnEa1uk6nL5wAAAGE"]
[Thu Jul 30 15:30:37.631236 2026] [security2:error] [pid 173718:tid 173888] [client 172.202.44.182:12170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/new.php"] [unique_id "amu0bUoi7QGnEa1uk6nL6gAAACc"]
[Thu Jul 30 15:30:38.001489 2026] [security2:error] [pid 173718:tid 173881] [client 57.141.0.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0bUoi7QGnEa1uk6nL5QAAACA"]
[Thu Jul 30 15:30:38.211714 2026] [security2:error] [pid 173718:tid 173960] [client 68.221.186.136:5402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amu0bkoi7QGnEa1uk6nMAAAAAG8"]
[Thu Jul 30 15:30:38.302857 2026] [security2:error] [pid 173718:tid 173863] [client 74.7.244.36:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amu0bkoi7QGnEa1uk6nMBgAAAA4"]
[Thu Jul 30 15:30:38.303637 2026] [security2:error] [pid 173718:tid 173967] [client 74.7.244.36:34510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amu0bkoi7QGnEa1uk6nMBAAAdhQ"]
[Thu Jul 30 15:30:39.053670 2026] [security2:error] [pid 173718:tid 173860] [client 68.221.186.136:18974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amu0b0oi7QGnEa1uk6nMFQAAAAs"]
[Thu Jul 30 15:30:39.246771 2026] [security2:error] [pid 173718:tid 173882] [client 172.202.44.182:39522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/adminfuns.php"] [unique_id "amu0b0oi7QGnEa1uk6nMGQAAACE"]
[Thu Jul 30 15:30:39.737019 2026] [security2:error] [pid 173718:tid 173933] [client 194.59.30.116:56031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.30.59.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinfungibletoken.com"] [uri "/index.php"] [unique_id "amu0b0oi7QGnEa1uk6nMIAAAAFQ"]
[Thu Jul 30 15:30:39.758776 2026] [security2:error] [pid 173718:tid 173927] [client 68.221.186.136:2058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amu0b0oi7QGnEa1uk6nMJAAAAE4"]
[Thu Jul 30 15:30:40.692507 2026] [security2:error] [pid 173718:tid 173888] [client 68.221.186.136:2487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amu0cEoi7QGnEa1uk6nMNwAAACc"]
[Thu Jul 30 15:30:40.779218 2026] [security2:error] [pid 173718:tid 173899] [client 172.202.44.182:12223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/fm.php"] [unique_id "amu0cEoi7QGnEa1uk6nMOwAAADI"]
[Thu Jul 30 15:30:41.038605 2026] [security2:error] [pid 173718:tid 173764] [remote 216.73.216.51:15325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu0cUoi7QGnEa1uk6nMQwAAKyw"]
[Thu Jul 30 15:30:41.962637 2026] [security2:error] [pid 173718:tid 173877] [client 68.221.186.136:5233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amu0cUoi7QGnEa1uk6nMVAAAABw"]
[Thu Jul 30 15:30:42.653316 2026] [security2:error] [pid 173718:tid 173936] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0ckoi7QGnEa1uk6nMVwAAVy4"]
[Thu Jul 30 15:30:43.550257 2026] [security2:error] [pid 173718:tid 173962] [client 172.202.44.182:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/file.php"] [unique_id "amu0c0oi7QGnEa1uk6nMcwAAAHE"]
[Thu Jul 30 15:30:43.821806 2026] [security2:error] [pid 173718:tid 173910] [client 68.221.186.136:12739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amu0c0oi7QGnEa1uk6nMfgAAAD0"]
[Thu Jul 30 15:30:43.877209 2026] [security2:error] [pid 173718:tid 173888] [client 172.202.44.182:19245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wk/index.php"] [unique_id "amu0c0oi7QGnEa1uk6nMfwAAACc"]
[Thu Jul 30 15:30:44.972847 2026] [security2:error] [pid 173718:tid 173939] [client 172.237.109.114:4594] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/m-wp-popup/readme.txt"] [unique_id "amu0dEoi7QGnEa1uk6nMlwAAAFo"]
[Thu Jul 30 15:30:45.023061 2026] [security2:error] [pid 173718:tid 173943] [client 172.202.44.182:19257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/av.php"] [unique_id "amu0dUoi7QGnEa1uk6nMmAAAAF4"]
[Thu Jul 30 15:30:45.551920 2026] [security2:error] [pid 173718:tid 173905] [client 68.221.186.136:19007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amu0dUoi7QGnEa1uk6nMngAAADg"]
[Thu Jul 30 15:30:45.636951 2026] [security2:error] [pid 173718:tid 173812] [remote 89.185.225.24:43914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-login.php"] [unique_id "amu0dUoi7QGnEa1uk6nMogAAOlw"]
[Thu Jul 30 15:30:45.749473 2026] [core:notice] [pid 173718:tid 173820] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:45.763145 2026] [security2:error] [pid 173718:tid 173909] [client 134.19.179.139:33390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amu0dUoi7QGnEa1uk6nMpwAAADw"]
[Thu Jul 30 15:30:45.763277 2026] [security2:error] [pid 173718:tid 173909] [client 134.19.179.139:33390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amu0dUoi7QGnEa1uk6nMpwAAADw"]
[Thu Jul 30 15:30:45.860262 2026] [security2:error] [pid 173718:tid 173866] [client 38.172.162.57:16076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0dUoi7QGnEa1uk6nMqAAAABE"]
[Thu Jul 30 15:30:45.860403 2026] [security2:error] [pid 173718:tid 173866] [client 38.172.162.57:16076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0dUoi7QGnEa1uk6nMqAAAABE"]
[Thu Jul 30 15:30:46.992255 2026] [security2:error] [pid 173718:tid 173880] [client 68.221.186.136:2533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amu0dkoi7QGnEa1uk6nMvwAAAB8"]
[Thu Jul 30 15:30:47.226541 2026] [security2:error] [pid 173718:tid 173850] [client 110.249.202.94:10554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiandubaisafari.com"] [uri "/ferrari-world.html"] [unique_id "amu0d0oi7QGnEa1uk6nMywAAAAE"]
[Thu Jul 30 15:30:47.431192 2026] [security2:error] [pid 173718:tid 173862] [client 172.202.44.182:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/bolt.php"] [unique_id "amu0d0oi7QGnEa1uk6nMzAAAAA0"]
[Thu Jul 30 15:30:47.748462 2026] [core:notice] [pid 173718:tid 173828] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:48.008300 2026] [security2:error] [pid 173718:tid 173776] [remote 198.38.94.87:38144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.94.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.emmanueljrodriguez.com"] [uri "/wp-login.php"] [unique_id "amu0eEoi7QGnEa1uk6nM1wAAXDg"]
[Thu Jul 30 15:30:48.588395 2026] [security2:error] [pid 173718:tid 173872] [client 172.237.109.114:55066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0eEoi7QGnEa1uk6nM2AAAABc"]
[Thu Jul 30 15:30:48.736298 2026] [security2:error] [pid 173718:tid 173927] [client 68.221.186.136:6318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amu0eEoi7QGnEa1uk6nM6QAAAE4"]
[Thu Jul 30 15:30:48.971522 2026] [security2:error] [pid 173718:tid 173917] [client 172.237.109.114:19334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/vkontakte-wall-post/readme.txt"] [unique_id "amu0eEoi7QGnEa1uk6nM8QAAAEQ"]
[Thu Jul 30 15:30:49.869258 2026] [security2:error] [pid 173718:tid 173873] [client 68.221.186.136:2523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/banners/about.php"] [unique_id "amu0eUoi7QGnEa1uk6nNBgAAABg"]
[Thu Jul 30 15:30:49.952118 2026] [core:notice] [pid 173718:tid 173966] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:49.956132 2026] [security2:error] [pid 173718:tid 173966] [client 66.249.79.8:38929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JNPM/article/view/1473/1002"] [unique_id "amu0eUoi7QGnEa1uk6nNCwAAAHU"]
[Thu Jul 30 15:30:50.384901 2026] [core:notice] [pid 173718:tid 173827] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:50.388550 2026] [security2:error] [pid 173718:tid 173900] [client 66.249.65.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/245/242"] [unique_id "amu0ekoi7QGnEa1uk6nNDAAAM2s"]
[Thu Jul 30 15:30:50.427532 2026] [security2:error] [pid 173718:tid 173959] [client 172.202.44.182:12229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/3.php"] [unique_id "amu0ekoi7QGnEa1uk6nNFwAAAG4"]
[Thu Jul 30 15:30:51.438567 2026] [security2:error] [pid 173718:tid 173899] [client 57.141.0.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0ekoi7QGnEa1uk6nNIQAAADI"]
[Thu Jul 30 15:30:51.482910 2026] [core:notice] [pid 173718:tid 173909] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:51.720804 2026] [core:notice] [pid 173718:tid 173955] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:51.991832 2026] [security2:error] [pid 173718:tid 173916] [client 172.237.109.114:16388] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "amu0e0oi7QGnEa1uk6nNPAAAAEM"]
[Thu Jul 30 15:30:52.164056 2026] [security2:error] [pid 173718:tid 173910] [client 183.227.29.166:2075] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "igetvape-australia.com"] [uri "/"] [unique_id "amu0fEoi7QGnEa1uk6nNPQAAAD0"]
[Thu Jul 30 15:30:52.231423 2026] [security2:error] [pid 173718:tid 173884] [client 172.202.44.182:12265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/222.php"] [unique_id "amu0fEoi7QGnEa1uk6nNPgAAACM"]
[Thu Jul 30 15:30:52.637309 2026] [security2:error] [pid 173718:tid 173847] [remote 165.22.214.22:33260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.214.22.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amu0fEoi7QGnEa1uk6nNSAAASH8"]
[Thu Jul 30 15:30:52.690875 2026] [core:notice] [pid 173718:tid 173875] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:53.102346 2026] [security2:error] [pid 173718:tid 173867] [client 68.221.186.136:6311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/about.php"] [unique_id "amu0fUoi7QGnEa1uk6nNWQAAABI"]
[Thu Jul 30 15:30:53.942302 2026] [security2:error] [pid 173718:tid 173737] [remote 57.141.0.38:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55997217192/feed/rss2/"] [unique_id "amu0fUoi7QGnEa1uk6nNewAAIhE"]
[Thu Jul 30 15:30:54.052363 2026] [security2:error] [pid 173718:tid 173965] [client 172.202.44.182:12055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/images/admin.php"] [unique_id "amu0fkoi7QGnEa1uk6nNhAAAAHQ"]
[Thu Jul 30 15:30:54.126840 2026] [security2:error] [pid 173718:tid 173964] [client 68.221.186.136:6605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/about.php"] [unique_id "amu0fkoi7QGnEa1uk6nNhgAAAHM"]
[Thu Jul 30 15:30:54.583711 2026] [security2:error] [pid 173718:tid 173915] [client 104.128.179.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0fUoi7QGnEa1uk6nNcQAAQhs"], referer: https://allmontecristi.com
[Thu Jul 30 15:30:54.727613 2026] [security2:error] [pid 173718:tid 173938] [client 172.202.44.182:32306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/mini.php"] [unique_id "amu0fkoi7QGnEa1uk6nNoQAAAFk"]
[Thu Jul 30 15:30:55.174309 2026] [security2:error] [pid 173718:tid 173863] [client 68.221.186.136:12791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amu0f0oi7QGnEa1uk6nNugAAAA4"]
[Thu Jul 30 15:30:55.612701 2026] [security2:error] [pid 173718:tid 173951] [client 172.202.44.182:12156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amu0f0oi7QGnEa1uk6nNxQAAAGY"]
[Thu Jul 30 15:30:55.747842 2026] [security2:error] [pid 173718:tid 173887] [client 172.202.44.182:19230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/aa.php"] [unique_id "amu0f0oi7QGnEa1uk6nNyQAAACY"]
[Thu Jul 30 15:30:56.431845 2026] [security2:error] [pid 173718:tid 173923] [client 68.221.186.136:12789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amu0gEoi7QGnEa1uk6nN1wAAAEo"]
[Thu Jul 30 15:30:56.506872 2026] [security2:error] [pid 173718:tid 173907] [client 38.172.162.57:16028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0gEoi7QGnEa1uk6nN3AAAADo"]
[Thu Jul 30 15:30:56.507728 2026] [security2:error] [pid 173718:tid 173907] [client 38.172.162.57:16028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0gEoi7QGnEa1uk6nN3AAAADo"]
[Thu Jul 30 15:30:56.704920 2026] [security2:error] [pid 173718:tid 173938] [client 172.202.44.182:19248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/w.php"] [unique_id "amu0gEoi7QGnEa1uk6nN6wAAAFk"]
[Thu Jul 30 15:30:57.436961 2026] [security2:error] [pid 173718:tid 173915] [client 223.109.252.210:58110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-mid-aj1-2/"] [unique_id "amu0gUoi7QGnEa1uk6nOAQAAAEI"]
[Thu Jul 30 15:30:57.437103 2026] [security2:error] [pid 173718:tid 173915] [client 223.109.252.210:58110] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/nike-air-jordan-1-mid-aj1-2/"] [unique_id "amu0gUoi7QGnEa1uk6nOAQAAAEI"]
[Thu Jul 30 15:30:57.476849 2026] [core:notice] [pid 173718:tid 173918] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:30:57.520761 2026] [security2:error] [pid 173718:tid 173961] [client 68.221.186.136:25286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/img/about.php"] [unique_id "amu0gUoi7QGnEa1uk6nOBQAAAHA"]
[Thu Jul 30 15:30:57.643222 2026] [security2:error] [pid 173718:tid 173891] [client 172.202.44.182:32277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/admin.php"] [unique_id "amu0gUoi7QGnEa1uk6nODgAAACo"]
[Thu Jul 30 15:30:58.057066 2026] [security2:error] [pid 173718:tid 173898] [client 172.202.44.182:13667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/admin.php"] [unique_id "amu0gkoi7QGnEa1uk6nOGQAAADE"]
[Thu Jul 30 15:30:58.481088 2026] [security2:error] [pid 173718:tid 173931] [client 66.249.65.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0gUoi7QGnEa1uk6nOFgAAAFI"]
[Thu Jul 30 15:30:58.682092 2026] [security2:error] [pid 173718:tid 173855] [client 172.202.44.182:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amu0gkoi7QGnEa1uk6nOLwAAAAY"]
[Thu Jul 30 15:30:59.041960 2026] [security2:error] [pid 173718:tid 173956] [client 2a03:2880:f800:30:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0gkoi7QGnEa1uk6nOKQAAaxw"]
[Thu Jul 30 15:30:59.209484 2026] [proxy:error] [pid 173718:tid 173879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:30:59.209557 2026] [proxy_http:error] [pid 173718:tid 173879] [client 54.87.222.253:33553] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:30:59.210154 2026] [proxy:error] [pid 173718:tid 173879] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:30:59.210201 2026] [proxy_http:error] [pid 173718:tid 173879] [client 54.87.222.253:33553] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:30:59.321342 2026] [proxy:error] [pid 173718:tid 173851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:30:59.321427 2026] [proxy_http:error] [pid 173718:tid 173851] [client 3.228.112.215:8511] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:30:59.322248 2026] [proxy:error] [pid 173718:tid 173851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:30:59.322301 2026] [proxy_http:error] [pid 173718:tid 173851] [client 3.228.112.215:8511] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:30:59.393857 2026] [security2:error] [pid 173718:tid 173925] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0gkoi7QGnEa1uk6nOOAAAAEw"]
[Thu Jul 30 15:30:59.648932 2026] [security2:error] [pid 173718:tid 173881] [client 172.202.44.182:39494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-configs.php"] [unique_id "amu0g0oi7QGnEa1uk6nOTgAAACA"]
[Thu Jul 30 15:30:59.729644 2026] [security2:error] [pid 173718:tid 173913] [client 68.221.186.136:8793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/languages/about.php"] [unique_id "amu0g0oi7QGnEa1uk6nOUgAAAEA"]
[Thu Jul 30 15:31:00.102766 2026] [core:notice] [pid 173718:tid 173869] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:00.647848 2026] [security2:error] [pid 173718:tid 173931] [client 68.221.186.136:9508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amu0hEoi7QGnEa1uk6nOagAAAFI"]
[Thu Jul 30 15:31:01.188376 2026] [security2:error] [pid 173718:tid 173960] [client 172.202.44.182:62965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/m.php"] [unique_id "amu0hUoi7QGnEa1uk6nOdwAAAG8"]
[Thu Jul 30 15:31:01.273702 2026] [security2:error] [pid 173718:tid 173861] [client 68.221.186.136:25287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amu0hUoi7QGnEa1uk6nOfwAAAAw"]
[Thu Jul 30 15:31:01.364058 2026] [security2:error] [pid 173718:tid 173944] [client 114.119.138.107:42429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltaedu.net"] [uri "/robots.txt"] [unique_id "amu0hUoi7QGnEa1uk6nOhAAAAF8"], referer: https://deltaedu.net/robots.txt
[Thu Jul 30 15:31:02.192763 2026] [security2:error] [pid 173718:tid 173952] [client 172.202.44.182:36495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amu0hkoi7QGnEa1uk6nOmAAAAGc"]
[Thu Jul 30 15:31:02.507215 2026] [core:notice] [pid 173718:tid 173888] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:02.510384 2026] [security2:error] [pid 173718:tid 173888] [client 66.249.65.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/download/4/4"] [unique_id "amu0hkoi7QGnEa1uk6nOmwAAACc"]
[Thu Jul 30 15:31:02.522388 2026] [security2:error] [pid 173718:tid 173972] [client 20.203.200.218:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ym.php"] [unique_id "amu0hkoi7QGnEa1uk6nOpAAAAHs"]
[Thu Jul 30 15:31:02.522491 2026] [security2:error] [pid 173718:tid 173972] [client 20.203.200.218:62426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/ym.php"] [unique_id "amu0hkoi7QGnEa1uk6nOpAAAAHs"]
[Thu Jul 30 15:31:02.839212 2026] [security2:error] [pid 173718:tid 173919] [client 68.221.186.136:18999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amu0hkoi7QGnEa1uk6nOqwAAAEY"]
[Thu Jul 30 15:31:03.135997 2026] [security2:error] [pid 173718:tid 173889] [client 20.203.200.218:62422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/alfa1.php"] [unique_id "amu0h0oi7QGnEa1uk6nOtQAAACg"]
[Thu Jul 30 15:31:03.136099 2026] [security2:error] [pid 173718:tid 173889] [client 20.203.200.218:62422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/alfa1.php"] [unique_id "amu0h0oi7QGnEa1uk6nOtQAAACg"]
[Thu Jul 30 15:31:03.468857 2026] [security2:error] [pid 173718:tid 173956] [client 68.221.186.136:6568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amu0h0oi7QGnEa1uk6nOvwAAAGs"]
[Thu Jul 30 15:31:03.569249 2026] [security2:error] [pid 173718:tid 173911] [client 172.202.44.182:36518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/classwithtostring.php"] [unique_id "amu0h0oi7QGnEa1uk6nOwgAAAD4"]
[Thu Jul 30 15:31:03.637925 2026] [security2:error] [pid 173718:tid 173868] [client 20.203.200.218:62437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/159.php"] [unique_id "amu0h0oi7QGnEa1uk6nOxAAAABM"]
[Thu Jul 30 15:31:03.638052 2026] [security2:error] [pid 173718:tid 173868] [client 20.203.200.218:62437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/159.php"] [unique_id "amu0h0oi7QGnEa1uk6nOxAAAABM"]
[Thu Jul 30 15:31:03.798777 2026] [security2:error] [pid 173718:tid 173964] [client 74.7.228.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.smoke-tfhk.com"] [uri "/index.php"] [unique_id "amu0hkoi7QGnEa1uk6nOsQAAAHM"]
[Thu Jul 30 15:31:03.798816 2026] [security2:error] [pid 173718:tid 173964] [client 74.7.228.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.smoke-tfhk.com"] [uri "/index.php"] [unique_id "amu0hkoi7QGnEa1uk6nOsQAAAHM"]
[Thu Jul 30 15:31:03.799720 2026] [security2:error] [pid 173718:tid 173863] [client 74.7.228.6:41390] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.smoke-tfhk.com"] [uri "/robots.txt"] [unique_id "amu0hkoi7QGnEa1uk6nOrgAADj4"]
[Thu Jul 30 15:31:03.995916 2026] [security2:error] [pid 173718:tid 173857] [client 105.214.17.145:39852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0h0oi7QGnEa1uk6nOwwAAAAg"], referer: https://alseermarine.com/
[Thu Jul 30 15:31:04.017747 2026] [core:notice] [pid 173718:tid 173862] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:04.022093 2026] [security2:error] [pid 173718:tid 173862] [client 94.124.160.31:62488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/JPA/user/register"] [unique_id "amu0h0oi7QGnEa1uk6nOwQAAAA0"]
[Thu Jul 30 15:31:04.390684 2026] [security2:error] [pid 173718:tid 173930] [client 172.202.44.182:12218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/php.php"] [unique_id "amu0iEoi7QGnEa1uk6nO1wAAAFE"]
[Thu Jul 30 15:31:05.129321 2026] [security2:error] [pid 173718:tid 173890] [client 20.203.200.218:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/tesla1.php"] [unique_id "amu0iUoi7QGnEa1uk6nO8AAAACk"]
[Thu Jul 30 15:31:05.129468 2026] [security2:error] [pid 173718:tid 173890] [client 20.203.200.218:61175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/tesla1.php"] [unique_id "amu0iUoi7QGnEa1uk6nO8AAAACk"]
[Thu Jul 30 15:31:05.281194 2026] [security2:error] [pid 173718:tid 173908] [client 74.7.228.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/index.php"] [unique_id "amu0iEoi7QGnEa1uk6nO3QAAADs"], referer: https://www.smoke-tfhk.com/robots.txt
[Thu Jul 30 15:31:05.282139 2026] [security2:error] [pid 173718:tid 173853] [client 74.7.228.6:41406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "smoke-tfhk.com"] [uri "/robots.txt"] [unique_id "amu0iEoi7QGnEa1uk6nO2gAABFA"], referer: https://www.smoke-tfhk.com/robots.txt
[Thu Jul 30 15:31:05.465838 2026] [security2:error] [pid 173718:tid 173915] [client 20.203.200.218:62429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/shadowx.php"] [unique_id "amu0iUoi7QGnEa1uk6nO9wAAAEI"]
[Thu Jul 30 15:31:05.465959 2026] [security2:error] [pid 173718:tid 173915] [client 20.203.200.218:62429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/shadowx.php"] [unique_id "amu0iUoi7QGnEa1uk6nO9wAAAEI"]
[Thu Jul 30 15:31:05.476217 2026] [security2:error] [pid 173718:tid 173864] [client 172.237.109.114:25497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0iEoi7QGnEa1uk6nO6AAAAA8"]
[Thu Jul 30 15:31:05.821741 2026] [security2:error] [pid 173718:tid 173851] [client 172.202.44.182:32274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/gmo.php"] [unique_id "amu0iUoi7QGnEa1uk6nO_gAAAAI"]
[Thu Jul 30 15:31:05.821928 2026] [security2:error] [pid 173718:tid 173887] [client 172.202.44.182:13648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/index.php"] [unique_id "amu0iUoi7QGnEa1uk6nO_wAAACY"]
[Thu Jul 30 15:31:06.060916 2026] [security2:error] [pid 173718:tid 173892] [client 20.203.200.218:61160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/hexor.php"] [unique_id "amu0ikoi7QGnEa1uk6nPBwAAACs"]
[Thu Jul 30 15:31:06.061029 2026] [security2:error] [pid 173718:tid 173892] [client 20.203.200.218:61160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/hexor.php"] [unique_id "amu0ikoi7QGnEa1uk6nPBwAAACs"]
[Thu Jul 30 15:31:06.156411 2026] [core:notice] [pid 173718:tid 173899] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:06.422480 2026] [core:notice] [pid 173718:tid 173806] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:06.645514 2026] [security2:error] [pid 173718:tid 173880] [client 20.203.200.218:52188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/leaf.php"] [unique_id "amu0ikoi7QGnEa1uk6nPGgAAAB8"]
[Thu Jul 30 15:31:06.645608 2026] [security2:error] [pid 173718:tid 173880] [client 20.203.200.218:52188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/leaf.php"] [unique_id "amu0ikoi7QGnEa1uk6nPGgAAAB8"]
[Thu Jul 30 15:31:06.969247 2026] [security2:error] [pid 173718:tid 173882] [client 172.202.44.182:12149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/a.php"] [unique_id "amu0ikoi7QGnEa1uk6nPHAAAACE"]
[Thu Jul 30 15:31:07.023832 2026] [security2:error] [pid 173718:tid 173897] [client 172.202.44.182:36522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/languages/index.php"] [unique_id "amu0i0oi7QGnEa1uk6nPHwAAADA"]
[Thu Jul 30 15:31:07.102422 2026] [security2:error] [pid 173718:tid 173900] [client 38.172.162.57:16623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0i0oi7QGnEa1uk6nPIwAAADM"]
[Thu Jul 30 15:31:07.102531 2026] [security2:error] [pid 173718:tid 173900] [client 38.172.162.57:16623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0i0oi7QGnEa1uk6nPIwAAADM"]
[Thu Jul 30 15:31:07.253606 2026] [core:notice] [pid 173718:tid 173837] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:07.260374 2026] [security2:error] [pid 173718:tid 173906] [client 20.203.200.218:52177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/FoxWSOv1.php"] [unique_id "amu0i0oi7QGnEa1uk6nPKAAAADk"]
[Thu Jul 30 15:31:07.260467 2026] [security2:error] [pid 173718:tid 173906] [client 20.203.200.218:52177] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/FoxWSOv1.php"] [unique_id "amu0i0oi7QGnEa1uk6nPKAAAADk"]
[Thu Jul 30 15:31:07.694206 2026] [core:notice] [pid 173718:tid 173951] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:08.043707 2026] [security2:error] [pid 173718:tid 173853] [client 20.203.200.218:52203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/foxwsov1.php"] [unique_id "amu0jEoi7QGnEa1uk6nPNgAAAAQ"]
[Thu Jul 30 15:31:08.043822 2026] [security2:error] [pid 173718:tid 173853] [client 20.203.200.218:52203] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/foxwsov1.php"] [unique_id "amu0jEoi7QGnEa1uk6nPNgAAAAQ"]
[Thu Jul 30 15:31:08.309840 2026] [security2:error] [pid 173718:tid 173956] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0i0oi7QGnEa1uk6nPNQAAAGs"]
[Thu Jul 30 15:31:08.316830 2026] [security2:error] [pid 173718:tid 173954] [client 172.202.44.182:32261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-the.php"] [unique_id "amu0jEoi7QGnEa1uk6nPQQAAAGk"]
[Thu Jul 30 15:31:08.906015 2026] [security2:error] [pid 173718:tid 173929] [client 20.203.200.218:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/FoxWSOv2.php"] [unique_id "amu0jEoi7QGnEa1uk6nPTAAAAFA"]
[Thu Jul 30 15:31:08.906172 2026] [security2:error] [pid 173718:tid 173929] [client 20.203.200.218:52191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/FoxWSOv2.php"] [unique_id "amu0jEoi7QGnEa1uk6nPTAAAAFA"]
[Thu Jul 30 15:31:09.033311 2026] [security2:error] [pid 173718:tid 173808] [remote 207.154.222.236:34476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.222.154.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-74678686.jvc.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amu0jEoi7QGnEa1uk6nPSwAAHFg"]
[Thu Jul 30 15:31:09.524966 2026] [security2:error] [pid 173718:tid 173885] [client 20.203.200.218:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/foxwsov2.php"] [unique_id "amu0jUoi7QGnEa1uk6nPVwAAACQ"]
[Thu Jul 30 15:31:09.525100 2026] [security2:error] [pid 173718:tid 173885] [client 20.203.200.218:51718] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/foxwsov2.php"] [unique_id "amu0jUoi7QGnEa1uk6nPVwAAACQ"]
[Thu Jul 30 15:31:09.709577 2026] [security2:error] [pid 173718:tid 173969] [client 172.202.44.182:22525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/404.php"] [unique_id "amu0jUoi7QGnEa1uk6nPXgAAAHg"]
[Thu Jul 30 15:31:09.809706 2026] [security2:error] [pid 173718:tid 173886] [client 167.88.167.87:42192] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alseermarine.com"] [uri "/"] [unique_id "amu0jUoi7QGnEa1uk6nPYwAAACU"]
[Thu Jul 30 15:31:09.983781 2026] [security2:error] [pid 173718:tid 173906] [client 20.203.200.218:62454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/shellx.php"] [unique_id "amu0jUoi7QGnEa1uk6nPZAAAADk"]
[Thu Jul 30 15:31:09.983897 2026] [security2:error] [pid 173718:tid 173906] [client 20.203.200.218:62454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/shellx.php"] [unique_id "amu0jUoi7QGnEa1uk6nPZAAAADk"]
[Thu Jul 30 15:31:09.993457 2026] [security2:error] [pid 173718:tid 173850] [client 68.221.186.136:5469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/js/about.php"] [unique_id "amu0jUoi7QGnEa1uk6nPZgAAAAE"]
[Thu Jul 30 15:31:10.143621 2026] [core:notice] [pid 173718:tid 173937] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:10.215423 2026] [security2:error] [pid 173718:tid 173921] [client 172.202.44.182:12148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/Text/about.php"] [unique_id "amu0jkoi7QGnEa1uk6nPawAAAEg"]
[Thu Jul 30 15:31:10.593629 2026] [security2:error] [pid 173718:tid 173923] [client 20.100.187.246:1580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/geju.php"] [unique_id "amu0jkoi7QGnEa1uk6nPegAAAEo"]
[Thu Jul 30 15:31:10.629465 2026] [security2:error] [pid 173718:tid 173956] [client 20.203.200.218:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/1index.php"] [unique_id "amu0jkoi7QGnEa1uk6nPewAAAGs"]
[Thu Jul 30 15:31:10.629553 2026] [security2:error] [pid 173718:tid 173956] [client 20.203.200.218:62441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/1index.php"] [unique_id "amu0jkoi7QGnEa1uk6nPewAAAGs"]
[Thu Jul 30 15:31:10.760042 2026] [security2:error] [pid 173718:tid 173953] [client 172.202.44.182:22488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/init.php"] [unique_id "amu0jkoi7QGnEa1uk6nPggAAAGg"]
[Thu Jul 30 15:31:10.929226 2026] [security2:error] [pid 173718:tid 173940] [client 68.221.186.136:8966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amu0jkoi7QGnEa1uk6nPiQAAAFs"]
[Thu Jul 30 15:31:11.230173 2026] [security2:error] [pid 173718:tid 173892] [client 20.100.187.246:1751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amu0j0oi7QGnEa1uk6nPjgAAACs"]
[Thu Jul 30 15:31:11.405878 2026] [security2:error] [pid 173718:tid 173943] [client 172.202.44.182:12045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin.php"] [unique_id "amu0j0oi7QGnEa1uk6nPlwAAAF4"]
[Thu Jul 30 15:31:11.443921 2026] [security2:error] [pid 173718:tid 173880] [client 204.8.98.55:42504] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amu0j0oi7QGnEa1uk6nPmAAAAB8"]
[Thu Jul 30 15:31:11.444026 2026] [security2:error] [pid 173718:tid 173880] [client 204.8.98.55:42504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kayomanis.com"] [uri "/xmlrpc.php"] [unique_id "amu0j0oi7QGnEa1uk6nPmAAAAB8"]
[Thu Jul 30 15:31:11.483834 2026] [security2:error] [pid 173718:tid 173882] [client 20.203.200.218:61155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/2index.php"] [unique_id "amu0j0oi7QGnEa1uk6nPmQAAACE"]
[Thu Jul 30 15:31:11.483937 2026] [security2:error] [pid 173718:tid 173882] [client 20.203.200.218:61155] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/2index.php"] [unique_id "amu0j0oi7QGnEa1uk6nPmQAAACE"]
[Thu Jul 30 15:31:11.553414 2026] [security2:error] [pid 173718:tid 173901] [client 68.221.186.136:25280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amu0j0oi7QGnEa1uk6nPmwAAADQ"]
[Thu Jul 30 15:31:12.043166 2026] [security2:error] [pid 173718:tid 173897] [client 20.100.187.246:3375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp.php"] [unique_id "amu0kEoi7QGnEa1uk6nPpQAAADA"]
[Thu Jul 30 15:31:12.209084 2026] [security2:error] [pid 173718:tid 173850] [client 68.221.186.136:8825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amu0kEoi7QGnEa1uk6nPpgAAAAE"]
[Thu Jul 30 15:31:12.383597 2026] [security2:error] [pid 173718:tid 173758] [remote 47.128.27.45:47542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/shop/page/3/"] [unique_id "amu0kEoi7QGnEa1uk6nPrQAAeiY"]
[Thu Jul 30 15:31:12.600227 2026] [security2:error] [pid 173718:tid 173893] [client 172.202.44.182:12287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/size.php"] [unique_id "amu0kEoi7QGnEa1uk6nPsQAAACw"]
[Thu Jul 30 15:31:12.635443 2026] [security2:error] [pid 173718:tid 173889] [client 20.203.200.218:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/3index.php"] [unique_id "amu0kEoi7QGnEa1uk6nPsgAAACg"]
[Thu Jul 30 15:31:12.635542 2026] [security2:error] [pid 173718:tid 173889] [client 20.203.200.218:62430] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/3index.php"] [unique_id "amu0kEoi7QGnEa1uk6nPsgAAACg"]
[Thu Jul 30 15:31:13.097408 2026] [core:notice] [pid 173718:tid 173751] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:13.130371 2026] [security2:error] [pid 173718:tid 173936] [client 20.203.200.218:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.200.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/4index.php"] [unique_id "amu0kUoi7QGnEa1uk6nPvgAAAFc"]
[Thu Jul 30 15:31:13.130461 2026] [security2:error] [pid 173718:tid 173936] [client 20.203.200.218:62436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.ghggeneralcontracting.com"] [uri "/4index.php"] [unique_id "amu0kUoi7QGnEa1uk6nPvgAAAFc"]
[Thu Jul 30 15:31:13.204699 2026] [core:error] [pid 173718:tid 173912] [client 193.47.62.167:55866] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:31:13.204717 2026] [core:error] [pid 173718:tid 173912] [client 193.47.62.167:55866] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:31:13.589038 2026] [security2:error] [pid 173718:tid 173925] [client 20.100.187.246:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/aaa.php"] [unique_id "amu0kUoi7QGnEa1uk6nPygAAAEw"]
[Thu Jul 30 15:31:13.818250 2026] [security2:error] [pid 173718:tid 173974] [client 141.94.94.45:50186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.94.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amu0kUoi7QGnEa1uk6nPywAAAH0"]
[Thu Jul 30 15:31:13.991916 2026] [security2:error] [pid 173718:tid 173917] [client 172.237.109.114:64397] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/button/readme.txt"] [unique_id "amu0kUoi7QGnEa1uk6nP1gAAAEQ"]
[Thu Jul 30 15:31:14.284268 2026] [security2:error] [pid 173718:tid 173973] [client 141.94.78.40:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.78.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amu0kkoi7QGnEa1uk6nP2gAAAHw"]
[Thu Jul 30 15:31:14.349503 2026] [security2:error] [pid 173718:tid 173901] [client 20.100.187.246:1570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/hoot.php"] [unique_id "amu0kkoi7QGnEa1uk6nP3QAAADQ"]
[Thu Jul 30 15:31:14.617803 2026] [security2:error] [pid 173718:tid 173975] [client 68.221.186.136:20614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amu0kkoi7QGnEa1uk6nP5QAAAH4"]
[Thu Jul 30 15:31:15.081225 2026] [security2:error] [pid 173718:tid 173859] [client 172.202.44.182:12133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/wp-class.php"] [unique_id "amu0k0oi7QGnEa1uk6nP7wAAAAo"]
[Thu Jul 30 15:31:15.247847 2026] [security2:error] [pid 173718:tid 173946] [client 68.221.186.136:6616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amu0k0oi7QGnEa1uk6nP9gAAAGE"]
[Thu Jul 30 15:31:15.773600 2026] [security2:error] [pid 173718:tid 173908] [client 57.141.0.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0k0oi7QGnEa1uk6nP9QAAADs"]
[Thu Jul 30 15:31:15.838249 2026] [security2:error] [pid 173718:tid 173871] [client 57.129.81.227:49758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amu0k0oi7QGnEa1uk6nQCAAAABY"]
[Thu Jul 30 15:31:16.005826 2026] [security2:error] [pid 173718:tid 173873] [client 2a03:2880:f800:2:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0k0oi7QGnEa1uk6nP-QAAGC4"]
[Thu Jul 30 15:31:16.358997 2026] [security2:error] [pid 173718:tid 173882] [client 51.77.211.229:58166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.211.77.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/group.php"] [unique_id "amu0lEoi7QGnEa1uk6nQGwAAACE"]
[Thu Jul 30 15:31:16.582575 2026] [security2:error] [pid 173718:tid 173901] [client 172.202.44.182:12275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/403.php"] [unique_id "amu0lEoi7QGnEa1uk6nQKAAAADQ"]
[Thu Jul 30 15:31:17.034541 2026] [security2:error] [pid 173718:tid 173878] [client 20.100.187.246:1541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/about.php"] [unique_id "amu0lUoi7QGnEa1uk6nQMgAAAB0"]
[Thu Jul 30 15:31:17.520843 2026] [security2:error] [pid 173718:tid 173913] [client 68.221.186.136:20670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/themes/about.php"] [unique_id "amu0lUoi7QGnEa1uk6nQPAAAAEA"]
[Thu Jul 30 15:31:17.693236 2026] [security2:error] [pid 173718:tid 173948] [client 38.172.162.57:16574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0lUoi7QGnEa1uk6nQQgAAAGM"]
[Thu Jul 30 15:31:17.693354 2026] [security2:error] [pid 173718:tid 173948] [client 38.172.162.57:16574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0lUoi7QGnEa1uk6nQQgAAAGM"]
[Thu Jul 30 15:31:17.751837 2026] [security2:error] [pid 173718:tid 173912] [client 74.7.230.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "www.illicali.com"] [uri "/robots.txt"] [unique_id "amu0lUoi7QGnEa1uk6nQQwAAP0I"]
[Thu Jul 30 15:31:17.796683 2026] [security2:error] [pid 173718:tid 173927] [client 172.202.44.182:12215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amu0lUoi7QGnEa1uk6nQSAAAAE4"]
[Thu Jul 30 15:31:17.798163 2026] [security2:error] [pid 173718:tid 173960] [client 216.73.216.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.guardian-heir.com"] [uri "/index.php"] [unique_id "amu0k0oi7QGnEa1uk6nP-AAAbzk"]
[Thu Jul 30 15:31:17.875140 2026] [security2:error] [pid 173718:tid 173915] [client 20.100.187.246:3348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/admin.php"] [unique_id "amu0lUoi7QGnEa1uk6nQSgAAAEI"]
[Thu Jul 30 15:31:18.917394 2026] [security2:error] [pid 173718:tid 173972] [client 172.202.44.182:12151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/as.php"] [unique_id "amu0lkoi7QGnEa1uk6nQrwAAAHs"]
[Thu Jul 30 15:31:19.161519 2026] [security2:error] [pid 173718:tid 173933] [client 74.7.175.175:52832] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.siw.lku.temporary.site"] [uri "/index.php"] [unique_id "amu0lUoi7QGnEa1uk6nQPgAAVFs"]
[Thu Jul 30 15:31:19.161561 2026] [security2:error] [pid 173718:tid 173933] [client 74.7.175.175:52832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.siw.lku.temporary.site"] [uri "/index.php"] [unique_id "amu0lUoi7QGnEa1uk6nQPgAAVFs"]
[Thu Jul 30 15:31:19.241528 2026] [security2:error] [pid 173718:tid 173947] [client 14.215.29.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "shop-kent.com"] [uri "/index.php"] [unique_id "amu0lkoi7QGnEa1uk6nQjgAAAGI"]
[Thu Jul 30 15:31:19.501681 2026] [core:notice] [pid 173718:tid 173944] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:19.959477 2026] [security2:error] [pid 173718:tid 173912] [client 74.7.175.175:52848] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siw.lku.temporary.site"] [uri "/index.php"] [unique_id "amu0l0oi7QGnEa1uk6nQzgAAPx0"], referer: https://www.siw.lku.temporary.site/robots.txt
[Thu Jul 30 15:31:19.973462 2026] [security2:error] [pid 173718:tid 173957] [client 204.8.98.55:59662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amu0l0oi7QGnEa1uk6nQ1AAAAGw"]
[Thu Jul 30 15:31:19.973580 2026] [security2:error] [pid 173718:tid 173957] [client 204.8.98.55:59662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amu0l0oi7QGnEa1uk6nQ1AAAAGw"]
[Thu Jul 30 15:31:20.024641 2026] [security2:error] [pid 173718:tid 173909] [client 172.202.44.182:12140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/includes/index.php"] [unique_id "amu0mEoi7QGnEa1uk6nQ1gAAADw"]
[Thu Jul 30 15:31:21.078404 2026] [security2:error] [pid 173718:tid 173922] [client 68.221.186.136:13154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amu0mUoi7QGnEa1uk6nQ9QAAAEk"]
[Thu Jul 30 15:31:21.478203 2026] [security2:error] [pid 173718:tid 173933] [client 172.202.44.182:12073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amu0mUoi7QGnEa1uk6nRAgAAAFQ"]
[Thu Jul 30 15:31:21.755918 2026] [security2:error] [pid 173718:tid 173929] [client 68.221.186.136:5461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/images/about.php"] [unique_id "amu0mUoi7QGnEa1uk6nRCQAAAFA"]
[Thu Jul 30 15:31:21.899070 2026] [security2:error] [pid 173718:tid 173962] [client 216.73.216.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guardian-heir.com"] [uri "/index.php"] [unique_id "amu0mUoi7QGnEa1uk6nRCgAAcUc"]
[Thu Jul 30 15:31:21.977567 2026] [security2:error] [pid 173718:tid 173942] [client 172.202.44.182:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/file5.php"] [unique_id "amu0mUoi7QGnEa1uk6nREQAAAF0"]
[Thu Jul 30 15:31:22.345456 2026] [security2:error] [pid 173718:tid 173862] [client 172.202.44.182:43401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/plugins.php"] [unique_id "amu0mkoi7QGnEa1uk6nRGAAAAA0"]
[Thu Jul 30 15:31:23.377838 2026] [security2:error] [pid 173718:tid 173893] [client 172.202.44.182:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/js/index.php"] [unique_id "amu0m0oi7QGnEa1uk6nRLAAAACw"]
[Thu Jul 30 15:31:23.703081 2026] [core:notice] [pid 173718:tid 173861] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:24.003590 2026] [security2:error] [pid 173718:tid 173952] [client 20.100.187.246:1547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amu0nEoi7QGnEa1uk6nROwAAAGc"]
[Thu Jul 30 15:31:24.714220 2026] [security2:error] [pid 173718:tid 173890] [client 20.100.187.246:4579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/db-cache.php"] [unique_id "amu0nEoi7QGnEa1uk6nRSwAAACk"]
[Thu Jul 30 15:31:25.084216 2026] [security2:error] [pid 173718:tid 173971] [client 172.202.44.182:56332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/go.php"] [unique_id "amu0nUoi7QGnEa1uk6nRWAAAAHo"]
[Thu Jul 30 15:31:25.385997 2026] [security2:error] [pid 173718:tid 173872] [client 172.202.44.182:40403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amu0nUoi7QGnEa1uk6nRXAAAABc"]
[Thu Jul 30 15:31:26.260547 2026] [security2:error] [pid 173718:tid 173964] [client 172.202.44.182:12286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/test1.php"] [unique_id "amu0nkoi7QGnEa1uk6nRcwAAAHM"]
[Thu Jul 30 15:31:26.346648 2026] [core:notice] [pid 173718:tid 173922] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:26.350026 2026] [security2:error] [pid 173718:tid 173922] [client 66.249.79.8:49660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Signal/article/view/877/561"] [unique_id "amu0nkoi7QGnEa1uk6nRdAAAAEk"]
[Thu Jul 30 15:31:26.353857 2026] [security2:error] [pid 173718:tid 173968] [client 172.202.44.182:58492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/shell.php"] [unique_id "amu0nkoi7QGnEa1uk6nRdQAAAHc"]
[Thu Jul 30 15:31:26.655870 2026] [security2:error] [pid 173718:tid 173856] [client 68.221.186.136:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amu0nkoi7QGnEa1uk6nRgAAAAAc"]
[Thu Jul 30 15:31:26.882158 2026] [security2:error] [pid 173718:tid 173798] [remote 97.74.93.24:52484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ldk.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amu0nkoi7QGnEa1uk6nRhAAAYE4"]
[Thu Jul 30 15:31:27.373966 2026] [security2:error] [pid 173718:tid 173892] [client 68.221.186.136:9022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/images/about.php"] [unique_id "amu0n0oi7QGnEa1uk6nRjgAAACs"]
[Thu Jul 30 15:31:27.402662 2026] [security2:error] [pid 173718:tid 173944] [client 74.7.175.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.clm.udi.temporary.site"] [uri "/index.php"] [unique_id "amu0nkoi7QGnEa1uk6nRewAAAF8"]
[Thu Jul 30 15:31:27.403508 2026] [security2:error] [pid 173718:tid 173905] [client 74.7.175.186:59932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.clm.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amu0nkoi7QGnEa1uk6nReQAAOGw"]
[Thu Jul 30 15:31:27.878336 2026] [core:notice] [pid 173718:tid 173898] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:28.279088 2026] [security2:error] [pid 173718:tid 173876] [client 57.141.0.13:53420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "happyspree.app"] [uri "/index.php"] [unique_id "amu0oEoi7QGnEa1uk6nRngAAG3Y"]
[Thu Jul 30 15:31:28.296984 2026] [security2:error] [pid 173718:tid 173941] [client 38.172.162.57:16078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0oEoi7QGnEa1uk6nRrwAAAFw"]
[Thu Jul 30 15:31:28.297093 2026] [security2:error] [pid 173718:tid 173941] [client 38.172.162.57:16078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0oEoi7QGnEa1uk6nRrwAAAFw"]
[Thu Jul 30 15:31:28.302793 2026] [security2:error] [pid 173718:tid 173966] [client 172.202.44.182:58464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/f35.php"] [unique_id "amu0oEoi7QGnEa1uk6nRsAAAAHU"]
[Thu Jul 30 15:31:28.391789 2026] [security2:error] [pid 173718:tid 173920] [client 20.100.187.246:4600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amu0oEoi7QGnEa1uk6nRsQAAAEc"]
[Thu Jul 30 15:31:28.462702 2026] [core:notice] [pid 173718:tid 173896] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:28.513705 2026] [security2:error] [pid 173718:tid 173864] [client 74.7.244.57:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "theaq.global"] [uri "/index.php"] [unique_id "amu0oEoi7QGnEa1uk6nRsgAADzw"]
[Thu Jul 30 15:31:28.533856 2026] [security2:error] [pid 173718:tid 173899] [client 68.221.186.136:9019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/about.php"] [unique_id "amu0oEoi7QGnEa1uk6nRuAAAADI"]
[Thu Jul 30 15:31:28.740625 2026] [security2:error] [pid 173718:tid 173904] [client 172.202.44.182:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/images/index.php"] [unique_id "amu0oEoi7QGnEa1uk6nRvQAAADc"]
[Thu Jul 30 15:31:28.913003 2026] [security2:error] [pid 173718:tid 173880] [client 57.141.0.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0oEoi7QGnEa1uk6nRrgAAAB8"]
[Thu Jul 30 15:31:30.040512 2026] [security2:error] [pid 173718:tid 173929] [client 172.202.44.182:58493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/new.php"] [unique_id "amu0okoi7QGnEa1uk6nR2wAAAFA"]
[Thu Jul 30 15:31:30.083961 2026] [security2:error] [pid 173718:tid 173965] [client 172.202.44.182:13686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/asd.php"] [unique_id "amu0okoi7QGnEa1uk6nR3AAAAHQ"]
[Thu Jul 30 15:31:30.450044 2026] [security2:error] [pid 173718:tid 173953] [client 74.7.230.51:59190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.aakmiddleast.com"] [uri "/index.php"] [unique_id "amu0oUoi7QGnEa1uk6nRxAAAaHg"]
[Thu Jul 30 15:31:30.909667 2026] [security2:error] [pid 173718:tid 173868] [client 172.213.232.128:33179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/--wp-lgj.php"] [unique_id "amu0okoi7QGnEa1uk6nR7wAAABM"]
[Thu Jul 30 15:31:31.821564 2026] [security2:error] [pid 173718:tid 173944] [client 20.100.187.246:3358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amu0o0oi7QGnEa1uk6nSFgAAAF8"]
[Thu Jul 30 15:31:31.897934 2026] [security2:error] [pid 173718:tid 173900] [client 57.141.0.58:24270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amu0oUoi7QGnEa1uk6nR2gAAM38"]
[Thu Jul 30 15:31:32.050506 2026] [security2:error] [pid 173718:tid 173877] [client 172.213.232.128:33407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/autoload_classmap.php"] [unique_id "amu0pEoi7QGnEa1uk6nSIAAAABw"]
[Thu Jul 30 15:31:32.184231 2026] [security2:error] [pid 173718:tid 173849] [client 204.8.98.55:50406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu0pEoi7QGnEa1uk6nSJAAAAAA"]
[Thu Jul 30 15:31:32.184331 2026] [security2:error] [pid 173718:tid 173849] [client 204.8.98.55:50406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu0pEoi7QGnEa1uk6nSJAAAAAA"]
[Thu Jul 30 15:31:33.043220 2026] [security2:error] [pid 173718:tid 173883] [client 172.213.232.128:33157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/flower.php"] [unique_id "amu0pUoi7QGnEa1uk6nSMgAAACI"]
[Thu Jul 30 15:31:33.059990 2026] [security2:error] [pid 173718:tid 173857] [client 68.221.186.136:5441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/cgi-bin/about.php"] [unique_id "amu0pUoi7QGnEa1uk6nSNgAAAAg"]
[Thu Jul 30 15:31:33.978679 2026] [security2:error] [pid 173718:tid 173946] [client 51.68.111.245:34135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amu0pUoi7QGnEa1uk6nSSgAAAGE"]
[Thu Jul 30 15:31:33.978802 2026] [security2:error] [pid 173718:tid 173946] [client 51.68.111.245:34135] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amu0pUoi7QGnEa1uk6nSSgAAAGE"]
[Thu Jul 30 15:31:34.322936 2026] [security2:error] [pid 173718:tid 173965] [client 20.100.187.246:3208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amu0pkoi7QGnEa1uk6nSVAAAAHQ"]
[Thu Jul 30 15:31:34.796457 2026] [security2:error] [pid 173718:tid 173866] [client 172.202.44.182:12250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/customize/index.php"] [unique_id "amu0pkoi7QGnEa1uk6nSXAAAABE"]
[Thu Jul 30 15:31:34.931869 2026] [security2:error] [pid 173718:tid 173932] [client 57.141.0.65:49436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.northyorksheridanmall.com"] [uri "/index.php"] [unique_id "amu0pkoi7QGnEa1uk6nSZgAAU18"]
[Thu Jul 30 15:31:35.364495 2026] [security2:error] [pid 173718:tid 173974] [client 68.221.186.136:20620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amu0p0oi7QGnEa1uk6nScQAAAH0"]
[Thu Jul 30 15:31:35.989022 2026] [security2:error] [pid 173718:tid 173868] [client 172.213.232.128:33215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/xleet.php"] [unique_id "amu0p0oi7QGnEa1uk6nShwAAABM"]
[Thu Jul 30 15:31:36.160173 2026] [security2:error] [pid 173718:tid 173856] [client 172.202.44.182:12251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amu0qEoi7QGnEa1uk6nSiQAAAAc"]
[Thu Jul 30 15:31:36.359353 2026] [security2:error] [pid 173718:tid 173972] [client 68.221.186.136:20642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amu0qEoi7QGnEa1uk6nSlgAAAHs"]
[Thu Jul 30 15:31:36.609958 2026] [security2:error] [pid 173718:tid 173849] [client 20.100.187.246:1794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amu0qEoi7QGnEa1uk6nSmwAAAAA"]
[Thu Jul 30 15:31:37.255198 2026] [security2:error] [pid 173718:tid 173954] [client 172.202.44.182:21668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/adminfuns.php"] [unique_id "amu0qUoi7QGnEa1uk6nSqgAAAGk"]
[Thu Jul 30 15:31:37.433037 2026] [security2:error] [pid 173718:tid 173912] [client 172.202.44.182:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/atomlib.php"] [unique_id "amu0qUoi7QGnEa1uk6nSsgAAAD8"]
[Thu Jul 30 15:31:37.905279 2026] [security2:error] [pid 173718:tid 173898] [client 20.100.187.246:3572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amu0qUoi7QGnEa1uk6nSvAAAADE"]
[Thu Jul 30 15:31:38.482806 2026] [security2:error] [pid 173718:tid 173888] [client 172.213.232.128:34976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/acme-challenge/flower.php"] [unique_id "amu0qkoi7QGnEa1uk6nSyAAAACc"]
[Thu Jul 30 15:31:38.587341 2026] [security2:error] [pid 173718:tid 173922] [client 172.202.44.182:33452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/fm.php"] [unique_id "amu0qkoi7QGnEa1uk6nSzAAAAEk"]
[Thu Jul 30 15:31:38.863655 2026] [security2:error] [pid 173718:tid 173970] [client 38.172.162.57:16007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0qkoi7QGnEa1uk6nS1QAAAHk"]
[Thu Jul 30 15:31:38.863767 2026] [security2:error] [pid 173718:tid 173970] [client 38.172.162.57:16007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0qkoi7QGnEa1uk6nS1QAAAHk"]
[Thu Jul 30 15:31:38.960972 2026] [security2:error] [pid 173718:tid 173828] [remote 110.249.201.140:17388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/assets/images/call%20for%20dubai%20desert%20safari.png"] [unique_id "amu0qkoi7QGnEa1uk6nS2QAAdGw"]
[Thu Jul 30 15:31:38.979938 2026] [security2:error] [pid 173718:tid 173933] [client 162.219.176.3:53764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amu0qkoi7QGnEa1uk6nS2gAAAFQ"]
[Thu Jul 30 15:31:38.980065 2026] [security2:error] [pid 173718:tid 173933] [client 162.219.176.3:53764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amu0qkoi7QGnEa1uk6nS2gAAAFQ"]
[Thu Jul 30 15:31:39.063121 2026] [security2:error] [pid 173718:tid 173955] [client 172.202.44.182:57347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amu0q0oi7QGnEa1uk6nS2wAAAGo"]
[Thu Jul 30 15:31:39.266527 2026] [security2:error] [pid 173718:tid 173924] [client 172.213.232.128:34935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/acme-challenge/xleet.php"] [unique_id "amu0q0oi7QGnEa1uk6nS3wAAAEs"]
[Thu Jul 30 15:31:39.273762 2026] [security2:error] [pid 173718:tid 173900] [client 68.221.186.136:2586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/css/about.php"] [unique_id "amu0q0oi7QGnEa1uk6nS4AAAADM"]
[Thu Jul 30 15:31:39.452382 2026] [core:error] [pid 173718:tid 173960] [client 104.155.75.151:52864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:31:39.452402 2026] [core:error] [pid 173718:tid 173960] [client 104.155.75.151:52864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:31:39.511220 2026] [security2:error] [pid 173718:tid 173819] [remote 74.7.243.224:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/storyf.php"] [unique_id "amu0q0oi7QGnEa1uk6nS6AAAZ2M"], referer: https://aded-rdc.org/category/autonomisation/uploads/partners/uploads/partners/uploads/partners/js/img/article.php?id=27
[Thu Jul 30 15:31:39.821352 2026] [security2:error] [pid 173718:tid 173863] [client 172.213.232.128:34939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amu0q0oi7QGnEa1uk6nS7gAAAA4"]
[Thu Jul 30 15:31:39.871196 2026] [security2:error] [pid 173718:tid 173854] [client 172.202.44.182:40387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/file.php"] [unique_id "amu0q0oi7QGnEa1uk6nS7wAAAAU"]
[Thu Jul 30 15:31:40.377330 2026] [security2:error] [pid 173718:tid 173961] [client 172.213.232.128:34180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/pki-validation/autoload_classmap.php"] [unique_id "amu0rEoi7QGnEa1uk6nS-wAAAHA"]
[Thu Jul 30 15:31:40.433994 2026] [security2:error] [pid 173718:tid 173834] [remote 57.141.0.63:36392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu0rEoi7QGnEa1uk6nTAAAASnI"]
[Thu Jul 30 15:31:40.640368 2026] [security2:error] [pid 173718:tid 173901] [client 68.221.186.136:22550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/images/about.php"] [unique_id "amu0rEoi7QGnEa1uk6nTBAAAADQ"]
[Thu Jul 30 15:31:40.661433 2026] [security2:error] [pid 173718:tid 173941] [client 172.202.44.182:56325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/inputs.php"] [unique_id "amu0rEoi7QGnEa1uk6nTBgAAAFw"]
[Thu Jul 30 15:31:41.059791 2026] [security2:error] [pid 173718:tid 173927] [client 69.171.231.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.magicmooncorp.com"] [uri "/index.php"] [unique_id "amu0qkoi7QGnEa1uk6nS0AAAAE4"]
[Thu Jul 30 15:31:41.214803 2026] [autoindex:error] [pid 173718:tid 173876] [client 103.151.125.97:57715] AH01276: Cannot serve directory /home1/yqegzjte/fintn.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:31:41.330311 2026] [http2:info] [pid 189611:tid 189611] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 15:31:41.590573 2026] [security2:error] [pid 173718:tid 173943] [client 20.100.187.246:3254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/content.php"] [unique_id "amu0rUoi7QGnEa1uk6nTFgAAAF4"]
[Thu Jul 30 15:31:41.823651 2026] [core:notice] [pid 189611:tid 189614] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:41.875400 2026] [security2:error] [pid 189611:tid 189743] [client 172.202.44.182:57406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/index.php"] [unique_id "amu0reWE7BvPuUzLJ99vDgAAAIc"]
[Thu Jul 30 15:31:42.278555 2026] [security2:error] [pid 189611:tid 189770] [client 68.221.186.136:22538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amu0ruWE7BvPuUzLJ99vHAAAAKI"]
[Thu Jul 30 15:31:42.278571 2026] [core:notice] [pid 189611:tid 189783] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:42.621531 2026] [core:notice] [pid 189611:tid 189803] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:43.124535 2026] [security2:error] [pid 189611:tid 189822] [client 172.213.232.128:30003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/pki-validation/flower.php"] [unique_id "amu0r-WE7BvPuUzLJ99vLAAAANY"]
[Thu Jul 30 15:31:43.420276 2026] [security2:error] [pid 189611:tid 189804] [client 172.202.44.182:57359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/network/index.php"] [unique_id "amu0r-WE7BvPuUzLJ99vNgAAAMQ"]
[Thu Jul 30 15:31:43.700121 2026] [core:notice] [pid 189611:tid 189841] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:43.922887 2026] [security2:error] [pid 189611:tid 189807] [client 68.221.186.136:15229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amu0r-WE7BvPuUzLJ99vQQAAAMc"]
[Thu Jul 30 15:31:43.936457 2026] [security2:error] [pid 189611:tid 189792] [client 172.202.44.182:33464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/bolt.php"] [unique_id "amu0r-WE7BvPuUzLJ99vQgAAALg"]
[Thu Jul 30 15:31:44.305384 2026] [security2:error] [pid 189611:tid 189862] [client 181.43.200.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu0sOWE7BvPuUzLJ99vRQAAAP4"], referer: https://cnpinyin.com
[Thu Jul 30 15:31:44.391142 2026] [security2:error] [pid 189611:tid 189859] [client 172.202.44.182:11677] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hmhs.ph"] [uri "/wp-content/1.php"] [unique_id "amu0sOWE7BvPuUzLJ99vTwAAAPs"]
[Thu Jul 30 15:31:44.391263 2026] [security2:error] [pid 189611:tid 189859] [client 172.202.44.182:11677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/1.php"] [unique_id "amu0sOWE7BvPuUzLJ99vTwAAAPs"]
[Thu Jul 30 15:31:44.407994 2026] [core:notice] [pid 189611:tid 189761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:44.526699 2026] [security2:error] [pid 189611:tid 189838] [client 172.213.232.128:29973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.well-known/pki-validation/xleet.php"] [unique_id "amu0sOWE7BvPuUzLJ99vVAAAAOY"]
[Thu Jul 30 15:31:44.959456 2026] [core:notice] [pid 189611:tid 189775] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:45.215481 2026] [security2:error] [pid 189611:tid 189779] [client 172.213.232.128:34230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.wp-cli/autoload_classmap.php"] [unique_id "amu0seWE7BvPuUzLJ99vYgAAAKs"]
[Thu Jul 30 15:31:45.237998 2026] [core:notice] [pid 189611:tid 189790] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:45.288841 2026] [security2:error] [pid 189611:tid 189778] [client 216.73.217.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.jacislamabad.com"] [uri "/index.php"] [unique_id "amu0seWE7BvPuUzLJ99vYAAAqho"]
[Thu Jul 30 15:31:45.396147 2026] [security2:error] [pid 189611:tid 189788] [client 172.202.44.182:11680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/plugin.php"] [unique_id "amu0seWE7BvPuUzLJ99vagAAALQ"]
[Thu Jul 30 15:31:45.515120 2026] [security2:error] [pid 189611:tid 189858] [client 54.87.112.51:39086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amu0sOWE7BvPuUzLJ99vRwAAAPo"], referer: https://globalmarks.pk/
[Thu Jul 30 15:31:46.012574 2026] [security2:error] [pid 189611:tid 189817] [client 172.213.232.128:27392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.wp-cli/flower.php"] [unique_id "amu0suWE7BvPuUzLJ99veQAAANE"]
[Thu Jul 30 15:31:46.094634 2026] [security2:error] [pid 189611:tid 189785] [client 172.202.44.182:40425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/3.php"] [unique_id "amu0suWE7BvPuUzLJ99vfQAAALE"]
[Thu Jul 30 15:31:46.592635 2026] [security2:error] [pid 189611:tid 189866] [client 172.213.232.128:27451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/.wp-cli/xleet.php"] [unique_id "amu0suWE7BvPuUzLJ99vjgAAAQI"]
[Thu Jul 30 15:31:46.619495 2026] [security2:error] [pid 189611:tid 189765] [client 68.221.186.136:15200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amu0suWE7BvPuUzLJ99vjwAAAJ0"]
[Thu Jul 30 15:31:46.815829 2026] [security2:error] [pid 189611:tid 189842] [client 172.202.44.182:11706] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hmhs.ph"] [uri "/1.php"] [unique_id "amu0suWE7BvPuUzLJ99vkQAAAOo"]
[Thu Jul 30 15:31:46.815958 2026] [security2:error] [pid 189611:tid 189842] [client 172.202.44.182:11706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/1.php"] [unique_id "amu0suWE7BvPuUzLJ99vkQAAAOo"]
[Thu Jul 30 15:31:47.048103 2026] [security2:error] [pid 189611:tid 189836] [client 20.100.187.246:1401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amu0s-WE7BvPuUzLJ99vmgAAAOQ"]
[Thu Jul 30 15:31:47.189091 2026] [security2:error] [pid 189611:tid 189773] [client 172.213.232.128:29995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amu0s-WE7BvPuUzLJ99vngAAAKU"]
[Thu Jul 30 15:31:47.260132 2026] [security2:error] [pid 189611:tid 189763] [client 68.221.186.136:9806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/cloud.php"] [unique_id "amu0s-WE7BvPuUzLJ99vnwAAAJs"]
[Thu Jul 30 15:31:47.313555 2026] [security2:error] [pid 189611:tid 189759] [client 172.202.44.182:40439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/222.php"] [unique_id "amu0s-WE7BvPuUzLJ99voAAAAJc"]
[Thu Jul 30 15:31:48.179724 2026] [security2:error] [pid 189611:tid 189813] [client 172.202.44.182:57372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/gg.php"] [unique_id "amu0tOWE7BvPuUzLJ99vtgAAAM0"]
[Thu Jul 30 15:31:48.412812 2026] [security2:error] [pid 189611:tid 189828] [client 162.243.64.70:55268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.ylw.gpl.temporary.site"] [uri "/.env"] [unique_id "amu0tOWE7BvPuUzLJ99vuwAAANw"]
[Thu Jul 30 15:31:48.434860 2026] [security2:error] [pid 189611:tid 189804] [client 103.245.38.203:58389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "alanturner.com.au"] [uri "/"] [unique_id "amu0tOWE7BvPuUzLJ99vvgAAAMQ"]
[Thu Jul 30 15:31:48.491073 2026] [security2:error] [pid 189611:tid 189786] [client 172.213.232.128:27079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amu0tOWE7BvPuUzLJ99vwAAAALI"]
[Thu Jul 30 15:31:48.928059 2026] [core:notice] [pid 189611:tid 189853] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:49.106277 2026] [security2:error] [pid 189611:tid 189856] [client 172.213.232.128:33377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/network/xleet.php/wp-content/flower.php"] [unique_id "amu0teWE7BvPuUzLJ99vzwAAAPg"]
[Thu Jul 30 15:31:49.355729 2026] [security2:error] [pid 189611:tid 189822] [client 68.221.186.136:25290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amu0teWE7BvPuUzLJ99v1wAAANY"]
[Thu Jul 30 15:31:49.385284 2026] [core:notice] [pid 189611:tid 189750] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:49.405843 2026] [security2:error] [pid 189611:tid 189764] [client 172.202.44.182:56373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp.php"] [unique_id "amu0teWE7BvPuUzLJ99v2QAAAJw"]
[Thu Jul 30 15:31:49.464834 2026] [security2:error] [pid 189611:tid 189848] [client 38.172.162.57:16361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0teWE7BvPuUzLJ99v3QAAAPA"]
[Thu Jul 30 15:31:49.465585 2026] [security2:error] [pid 189611:tid 189848] [client 38.172.162.57:16361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0teWE7BvPuUzLJ99v3QAAAPA"]
[Thu Jul 30 15:31:49.526393 2026] [core:notice] [pid 189611:tid 189825] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:49.900692 2026] [security2:error] [pid 189611:tid 189775] [client 172.213.232.128:34908] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.mydubaidesertsafari.com"] [uri "/1.php"] [unique_id "amu0teWE7BvPuUzLJ99v6gAAAKc"]
[Thu Jul 30 15:31:49.900817 2026] [security2:error] [pid 189611:tid 189775] [client 172.213.232.128:34908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/1.php"] [unique_id "amu0teWE7BvPuUzLJ99v6gAAAKc"]
[Thu Jul 30 15:31:49.917195 2026] [autoindex:error] [pid 189611:tid 189798] [client 52.202.41.153:18829] AH01276: Cannot serve directory /home2/meggzjte/01.serverkr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:31:49.924934 2026] [security2:error] [pid 189611:tid 189795] [client 68.221.186.136:39966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/updates.php"] [unique_id "amu0teWE7BvPuUzLJ99v7AAAALs"]
[Thu Jul 30 15:31:49.951193 2026] [core:notice] [pid 189611:tid 189794] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:49.954749 2026] [security2:error] [pid 189611:tid 189794] [client 66.249.74.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/30/33"] [unique_id "amu0teWE7BvPuUzLJ99v7QAAALo"]
[Thu Jul 30 15:31:50.402519 2026] [security2:error] [pid 189611:tid 189813] [client 68.221.186.136:9844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/css/cloud.php"] [unique_id "amu0tuWE7BvPuUzLJ99v-wAAAM0"]
[Thu Jul 30 15:31:50.630450 2026] [core:notice] [pid 189611:tid 189850] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:50.633539 2026] [security2:error] [pid 189611:tid 189850] [client 66.249.74.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/33/59"] [unique_id "amu0tuWE7BvPuUzLJ99wAAAAAPI"]
[Thu Jul 30 15:31:50.637394 2026] [security2:error] [pid 189611:tid 189841] [client 172.213.232.128:34900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/admin.php"] [unique_id "amu0tuWE7BvPuUzLJ99wAgAAAOk"]
[Thu Jul 30 15:31:50.849681 2026] [security2:error] [pid 189611:tid 189854] [client 20.100.187.246:1344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amu0tuWE7BvPuUzLJ99wCAAAAPY"]
[Thu Jul 30 15:31:50.943571 2026] [security2:error] [pid 189611:tid 189774] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0tuWE7BvPuUzLJ99v-gAApkI"]
[Thu Jul 30 15:31:51.008166 2026] [security2:error] [pid 189611:tid 189824] [client 172.202.44.182:28691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/blocks/about.php"] [unique_id "amu0t-WE7BvPuUzLJ99wCQAAANg"]
[Thu Jul 30 15:31:51.241893 2026] [security2:error] [pid 189611:tid 189761] [client 172.202.44.182:42053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amu0t-WE7BvPuUzLJ99wEwAAAJk"]
[Thu Jul 30 15:31:51.582678 2026] [security2:error] [pid 189611:tid 189757] [client 68.221.186.136:13804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amu0t-WE7BvPuUzLJ99wGwAAAJU"]
[Thu Jul 30 15:31:52.561448 2026] [security2:error] [pid 189611:tid 189793] [client 172.202.44.182:57361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/file.php"] [unique_id "amu0uOWE7BvPuUzLJ99wMQAAALk"]
[Thu Jul 30 15:31:52.620715 2026] [core:notice] [pid 189611:tid 189779] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:52.806270 2026] [security2:error] [pid 189611:tid 189820] [client 172.202.44.182:33426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amu0uOWE7BvPuUzLJ99wOQAAANQ"]
[Thu Jul 30 15:31:53.541509 2026] [security2:error] [pid 189611:tid 189841] [client 172.202.44.182:28692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/user/index.php"] [unique_id "amu0ueWE7BvPuUzLJ99wSAAAAOk"]
[Thu Jul 30 15:31:53.870586 2026] [core:notice] [pid 189611:tid 189824] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:53.916047 2026] [security2:error] [pid 189611:tid 189762] [client 172.213.232.128:34986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/as.php"] [unique_id "amu0ueWE7BvPuUzLJ99wUgAAAJo"]
[Thu Jul 30 15:31:54.772701 2026] [security2:error] [pid 189611:tid 189770] [client 172.202.44.182:42083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/admin.php"] [unique_id "amu0uuWE7BvPuUzLJ99wYwAAAKI"]
[Thu Jul 30 15:31:55.138248 2026] [security2:error] [pid 189611:tid 189743] [client 20.100.187.246:1966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amu0u-WE7BvPuUzLJ99wawAAAIc"]
[Thu Jul 30 15:31:55.183625 2026] [security2:error] [pid 189611:tid 189795] [client 172.202.44.182:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amu0u-WE7BvPuUzLJ99wbAAAALs"]
[Thu Jul 30 15:31:55.290173 2026] [security2:error] [pid 189611:tid 189858] [client 85.208.96.197:35796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/08/29/reveja-o-debate-de-ontem-na-band-na-integra-saiba-como-assistir/"] [unique_id "amu0u-WE7BvPuUzLJ99wbgAAAPo"]
[Thu Jul 30 15:31:55.290282 2026] [security2:error] [pid 189611:tid 189858] [client 85.208.96.197:35796] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/08/29/reveja-o-debate-de-ontem-na-band-na-integra-saiba-como-assistir/"] [unique_id "amu0u-WE7BvPuUzLJ99wbgAAAPo"]
[Thu Jul 30 15:31:55.351631 2026] [security2:error] [pid 189611:tid 189797] [client 68.221.186.136:9855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/img/cloud.php"] [unique_id "amu0u-WE7BvPuUzLJ99wcQAAAL0"]
[Thu Jul 30 15:31:56.034100 2026] [security2:error] [pid 189611:tid 189827] [client 172.202.44.182:11693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/index/function.php"] [unique_id "amu0vOWE7BvPuUzLJ99wfwAAANs"]
[Thu Jul 30 15:31:56.090097 2026] [core:notice] [pid 189611:tid 189717] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:56.095471 2026] [security2:error] [pid 189611:tid 189813] [client 74.7.230.41:50440] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/robots.txt"] [unique_id "amu0vOWE7BvPuUzLJ99wggAAzWk"]
[Thu Jul 30 15:31:56.214955 2026] [security2:error] [pid 189611:tid 189780] [client 172.213.232.128:27202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/autoload_classmap.php"] [unique_id "amu0vOWE7BvPuUzLJ99wgwAAAKw"]
[Thu Jul 30 15:31:56.534904 2026] [security2:error] [pid 189611:tid 189857] [client 172.202.44.182:40446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-configs.php"] [unique_id "amu0vOWE7BvPuUzLJ99wlQAAAPk"]
[Thu Jul 30 15:31:56.821849 2026] [security2:error] [pid 189611:tid 189830] [client 68.221.186.136:5178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amu0vOWE7BvPuUzLJ99wmgAAAN4"]
[Thu Jul 30 15:31:57.041752 2026] [security2:error] [pid 189611:tid 189762] [client 74.7.230.41:50450] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amu0vOWE7BvPuUzLJ99wnAAAmnE"], referer: https://carnetdeshopping.com/robots.txt
[Thu Jul 30 15:31:57.495788 2026] [security2:error] [pid 189611:tid 189751] [client 20.100.187.246:10265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amu0veWE7BvPuUzLJ99wqwAAAI8"]
[Thu Jul 30 15:31:57.853715 2026] [security2:error] [pid 189611:tid 189808] [client 68.221.186.136:4532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amu0veWE7BvPuUzLJ99wtgAAAMg"]
[Thu Jul 30 15:31:58.242109 2026] [core:notice] [pid 189611:tid 189737] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:58.368122 2026] [core:notice] [pid 189611:tid 189612] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:58.370643 2026] [core:notice] [pid 189611:tid 189613] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:58.384797 2026] [core:notice] [pid 189611:tid 189614] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:58.400881 2026] [core:notice] [pid 189611:tid 189615] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:31:58.485402 2026] [security2:error] [pid 189611:tid 189835] [client 172.202.44.182:42051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/php.php"] [unique_id "amu0vuWE7BvPuUzLJ99wyQAAAOM"]
[Thu Jul 30 15:31:58.597483 2026] [security2:error] [pid 189611:tid 189811] [client 172.213.232.128:34954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/back.php"] [unique_id "amu0vuWE7BvPuUzLJ99wzwAAAMs"]
[Thu Jul 30 15:31:58.615156 2026] [security2:error] [pid 189611:tid 189792] [client 68.221.186.136:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/avaa.php"] [unique_id "amu0vuWE7BvPuUzLJ99w1QAAALg"]
[Thu Jul 30 15:31:58.743186 2026] [security2:error] [pid 189611:tid 189755] [client 172.202.44.182:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/aaa.php"] [unique_id "amu0vuWE7BvPuUzLJ99w2gAAAJM"]
[Thu Jul 30 15:31:59.067023 2026] [security2:error] [pid 189611:tid 189837] [client 20.100.187.246:4911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amu0v-WE7BvPuUzLJ99w4QAAAOU"]
[Thu Jul 30 15:31:59.204770 2026] [security2:error] [pid 189611:tid 189742] [client 172.213.232.128:34914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/c/autoload_classmap.php"] [unique_id "amu0v-WE7BvPuUzLJ99w6AAAAIY"]
[Thu Jul 30 15:31:59.235508 2026] [security2:error] [pid 189611:tid 189860] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0vuWE7BvPuUzLJ99w1AAAAPw"]
[Thu Jul 30 15:31:59.410043 2026] [security2:error] [pid 189611:tid 189769] [client 172.202.44.182:40442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/index.php"] [unique_id "amu0v-WE7BvPuUzLJ99w7QAAAKE"]
[Thu Jul 30 15:31:59.414101 2026] [security2:error] [pid 189611:tid 189851] [client 180.102.110.147:46980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.marlboro-shop.com"] [uri "/"] [unique_id "amu0v-WE7BvPuUzLJ99w7wAAAPM"]
[Thu Jul 30 15:31:59.414197 2026] [security2:error] [pid 189611:tid 189851] [client 180.102.110.147:46980] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.marlboro-shop.com"] [uri "/"] [unique_id "amu0v-WE7BvPuUzLJ99w7wAAAPM"]
[Thu Jul 30 15:31:59.742595 2026] [security2:error] [pid 189611:tid 189788] [client 68.221.186.136:22019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/images/cloud.php"] [unique_id "amu0v-WE7BvPuUzLJ99w9QAAALQ"]
[Thu Jul 30 15:31:59.784025 2026] [security2:error] [pid 189611:tid 189777] [client 57.141.0.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0v-WE7BvPuUzLJ99w5wAAAKk"]
[Thu Jul 30 15:31:59.832807 2026] [security2:error] [pid 189611:tid 189863] [client 172.202.44.182:43659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/getid3-core.php"] [unique_id "amu0v-WE7BvPuUzLJ99w-QAAAP8"]
[Thu Jul 30 15:32:00.065832 2026] [security2:error] [pid 189611:tid 189798] [client 38.172.162.57:16515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0wOWE7BvPuUzLJ99w_QAAAL4"]
[Thu Jul 30 15:32:00.065952 2026] [security2:error] [pid 189611:tid 189798] [client 38.172.162.57:16515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0wOWE7BvPuUzLJ99w_QAAAL4"]
[Thu Jul 30 15:32:00.258093 2026] [security2:error] [pid 189611:tid 189816] [client 172.213.232.128:34980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/c/flower.php"] [unique_id "amu0wOWE7BvPuUzLJ99w_gAAANA"]
[Thu Jul 30 15:32:00.690095 2026] [security2:error] [pid 189611:tid 189823] [client 172.202.44.182:33416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/a.php"] [unique_id "amu0wOWE7BvPuUzLJ99xDgAAANc"]
[Thu Jul 30 15:32:00.764131 2026] [security2:error] [pid 189611:tid 189807] [client 20.100.187.246:7312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amu0wOWE7BvPuUzLJ99xDwAAAMc"]
[Thu Jul 30 15:32:00.961837 2026] [security2:error] [pid 189611:tid 189859] [client 68.221.186.136:15206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amu0wOWE7BvPuUzLJ99xFgAAAPs"]
[Thu Jul 30 15:32:01.051956 2026] [core:notice] [pid 189611:tid 189636] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:01.091934 2026] [core:notice] [pid 189611:tid 189638] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:01.178057 2026] [security2:error] [pid 189611:tid 189639] [remote 57.141.0.38:55376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/cicee/article/view/9139/4110"] [unique_id "amu0weWE7BvPuUzLJ99xHAAA_hs"]
[Thu Jul 30 15:32:01.201374 2026] [security2:error] [pid 189611:tid 189745] [client 172.213.232.128:38618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/c/xleet.php"] [unique_id "amu0weWE7BvPuUzLJ99xHQAAAIk"]
[Thu Jul 30 15:32:01.215851 2026] [core:notice] [pid 189611:tid 189640] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:01.218032 2026] [core:notice] [pid 189611:tid 189641] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:01.272387 2026] [security2:error] [pid 189611:tid 189813] [client 172.202.44.182:43661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/adminer.php"] [unique_id "amu0weWE7BvPuUzLJ99xIwAAAM0"]
[Thu Jul 30 15:32:01.526440 2026] [security2:error] [pid 189611:tid 189860] [client 68.221.186.136:4503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amu0weWE7BvPuUzLJ99xLgAAAPw"]
[Thu Jul 30 15:32:01.902286 2026] [security2:error] [pid 189611:tid 189803] [client 81.171.72.93:60200] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/"] [unique_id "amu0weWE7BvPuUzLJ99xNQAAAMM"]
[Thu Jul 30 15:32:01.902367 2026] [security2:error] [pid 189611:tid 189834] [client 81.171.72.93:60214] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/"] [unique_id "amu0weWE7BvPuUzLJ99xNAAAAOI"]
[Thu Jul 30 15:32:01.913357 2026] [security2:error] [pid 189611:tid 189818] [client 81.171.72.93:60202] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/"] [unique_id "amu0weWE7BvPuUzLJ99xNgAAANI"]
[Thu Jul 30 15:32:01.945190 2026] [security2:error] [pid 189611:tid 189648] [remote 57.141.0.70:53224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amu0weWE7BvPuUzLJ99xOwAAuSQ"]
[Thu Jul 30 15:32:02.087470 2026] [security2:error] [pid 189611:tid 189832] [client 172.213.232.128:34880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/classwithtostring.php"] [unique_id "amu0wuWE7BvPuUzLJ99xQgAAAOA"]
[Thu Jul 30 15:32:02.093016 2026] [security2:error] [pid 189611:tid 189743] [client 57.141.0.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0weWE7BvPuUzLJ99xLQAAAIc"]
[Thu Jul 30 15:32:02.197419 2026] [security2:error] [pid 189611:tid 189780] [client 172.202.44.182:42092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amu0wuWE7BvPuUzLJ99xRgAAAKw"]
[Thu Jul 30 15:32:02.222925 2026] [security2:error] [pid 189611:tid 189776] [client 20.100.187.246:10075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amu0wuWE7BvPuUzLJ99xRwAAAKg"]
[Thu Jul 30 15:32:02.569514 2026] [security2:error] [pid 189611:tid 189815] [client 81.171.72.93:60224] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/storage/logs/laravel.log"] [unique_id "amu0wuWE7BvPuUzLJ99xTgAAAM8"]
[Thu Jul 30 15:32:02.577722 2026] [security2:error] [pid 189611:tid 189845] [client 81.171.72.93:60242] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/etc/ssl/private/server.key"] [unique_id "amu0wuWE7BvPuUzLJ99xTwAAAO0"]
[Thu Jul 30 15:32:02.580129 2026] [security2:error] [pid 189611:tid 189799] [client 81.171.72.93:60258] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.env"] [unique_id "amu0wuWE7BvPuUzLJ99xUAAAAL8"]
[Thu Jul 30 15:32:02.587309 2026] [security2:error] [pid 189611:tid 189786] [client 81.171.72.93:60226] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/database.sql"] [unique_id "amu0wuWE7BvPuUzLJ99xUQAAALI"]
[Thu Jul 30 15:32:03.187986 2026] [security2:error] [pid 189611:tid 189851] [client 172.202.44.182:43675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/alfa.php"] [unique_id "amu0w-WE7BvPuUzLJ99xYAAAAPM"]
[Thu Jul 30 15:32:03.201401 2026] [security2:error] [pid 189611:tid 189765] [client 81.171.72.93:58848] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/config/production.json"] [unique_id "amu0w-WE7BvPuUzLJ99xYQAAAJ0"]
[Thu Jul 30 15:32:03.201573 2026] [security2:error] [pid 189611:tid 189746] [client 81.171.72.93:58842] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.vscode/sftp.json"] [unique_id "amu0w-WE7BvPuUzLJ99xYgAAAIo"]
[Thu Jul 30 15:32:03.204127 2026] [security2:error] [pid 189611:tid 189787] [client 81.171.72.93:58844] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.npmrc"] [unique_id "amu0w-WE7BvPuUzLJ99xYwAAALM"]
[Thu Jul 30 15:32:03.205168 2026] [security2:error] [pid 189611:tid 189813] [client 81.171.72.93:58862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/server.key"] [unique_id "amu0w-WE7BvPuUzLJ99xZAAAAM0"]
[Thu Jul 30 15:32:03.245848 2026] [security2:error] [pid 189611:tid 189773] [client 172.202.44.182:40445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin.php"] [unique_id "amu0w-WE7BvPuUzLJ99xZQAAAKU"]
[Thu Jul 30 15:32:03.336763 2026] [security2:error] [pid 189611:tid 189825] [client 81.171.72.93:58860] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/config.xml"] [unique_id "amu0w-WE7BvPuUzLJ99xZgAAANk"]
[Thu Jul 30 15:32:03.338718 2026] [security2:error] [pid 189611:tid 189838] [client 81.171.72.93:58852] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/api/.env"] [unique_id "amu0w-WE7BvPuUzLJ99xZwAAAOY"]
[Thu Jul 30 15:32:03.342499 2026] [security2:error] [pid 189611:tid 189844] [client 81.171.72.93:58830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/secrets.json"] [unique_id "amu0w-WE7BvPuUzLJ99xaAAAAOw"]
[Thu Jul 30 15:32:03.533273 2026] [security2:error] [pid 189611:tid 189658] [remote 103.124.95.161:51968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-login.php"] [unique_id "amu0w-WE7BvPuUzLJ99xbAAAny4"]
[Thu Jul 30 15:32:03.645133 2026] [security2:error] [pid 189611:tid 189850] [client 20.100.187.246:3986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amu0w-WE7BvPuUzLJ99xcwAAAPI"]
[Thu Jul 30 15:32:03.839493 2026] [security2:error] [pid 189611:tid 189843] [client 81.171.72.93:58924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.env.production"] [unique_id "amu0w-WE7BvPuUzLJ99xeAAAAOs"]
[Thu Jul 30 15:32:03.839493 2026] [security2:error] [pid 189611:tid 189810] [client 81.171.72.93:58892] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/user_secrets.yml"] [unique_id "amu0w-WE7BvPuUzLJ99xdwAAAMo"]
[Thu Jul 30 15:32:03.848198 2026] [security2:error] [pid 189611:tid 189832] [client 81.171.72.93:58906] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/phpinfo.php"] [unique_id "amu0w-WE7BvPuUzLJ99xeQAAAOA"]
[Thu Jul 30 15:32:03.859020 2026] [security2:error] [pid 189611:tid 189821] [client 81.171.72.93:58900] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/docker-compose.yml"] [unique_id "amu0w-WE7BvPuUzLJ99xegAAANU"]
[Thu Jul 30 15:32:03.978340 2026] [security2:error] [pid 189611:tid 189789] [client 81.171.72.93:58914] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/backup.tar.gz"] [unique_id "amu0w-WE7BvPuUzLJ99xewAAALU"]
[Thu Jul 30 15:32:03.980750 2026] [security2:error] [pid 189611:tid 189829] [client 81.171.72.93:58864] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/database_backup.sql"] [unique_id "amu0w-WE7BvPuUzLJ99xfQAAAN0"]
[Thu Jul 30 15:32:03.983781 2026] [security2:error] [pid 189611:tid 189855] [client 213.152.162.84:34606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amu0w-WE7BvPuUzLJ99xfAAAAPc"]
[Thu Jul 30 15:32:03.983937 2026] [security2:error] [pid 189611:tid 189855] [client 213.152.162.84:34606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amu0w-WE7BvPuUzLJ99xfAAAAPc"]
[Thu Jul 30 15:32:03.992869 2026] [security2:error] [pid 189611:tid 189785] [client 81.171.72.93:58866] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/wp-config.php"] [unique_id "amu0w-WE7BvPuUzLJ99xfgAAALE"]
[Thu Jul 30 15:32:04.009928 2026] [security2:error] [pid 189611:tid 189758] [client 172.213.232.128:33389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/content.php"] [unique_id "amu0xOWE7BvPuUzLJ99xfwAAAJY"]
[Thu Jul 30 15:32:04.084574 2026] [core:notice] [pid 189611:tid 189664] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:04.343833 2026] [security2:error] [pid 189611:tid 189762] [client 68.221.186.136:22077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amu0xOWE7BvPuUzLJ99xigAAAJo"]
[Thu Jul 30 15:32:04.507128 2026] [security2:error] [pid 189611:tid 189865] [client 81.171.72.93:58944] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/actuator/heapdump"] [unique_id "amu0xOWE7BvPuUzLJ99xiwAAAQE"]
[Thu Jul 30 15:32:04.510434 2026] [security2:error] [pid 189611:tid 189859] [client 81.171.72.93:58950] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/backup.zip"] [unique_id "amu0xOWE7BvPuUzLJ99xjAAAAPs"]
[Thu Jul 30 15:32:04.511737 2026] [security2:error] [pid 189611:tid 189752] [client 81.171.72.93:58978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.bash_history"] [unique_id "amu0xOWE7BvPuUzLJ99xjQAAAJA"]
[Thu Jul 30 15:32:04.512435 2026] [security2:error] [pid 189611:tid 189766] [client 81.171.72.93:58952] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.svn/wc.db"] [unique_id "amu0xOWE7BvPuUzLJ99xjgAAAJ4"]
[Thu Jul 30 15:32:04.648166 2026] [security2:error] [pid 189611:tid 189755] [client 81.171.72.93:58968] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.ssh/id_rsa"] [unique_id "amu0xOWE7BvPuUzLJ99xlQAAAJM"]
[Thu Jul 30 15:32:04.648853 2026] [security2:error] [pid 189611:tid 189830] [client 81.171.72.93:58948] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/dump.sql"] [unique_id "amu0xOWE7BvPuUzLJ99xlgAAAN4"]
[Thu Jul 30 15:32:04.654076 2026] [security2:error] [pid 189611:tid 189836] [client 81.171.72.93:58940] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/config.php"] [unique_id "amu0xOWE7BvPuUzLJ99xlwAAAOQ"]
[Thu Jul 30 15:32:05.030286 2026] [security2:error] [pid 189611:tid 189813] [client 20.100.187.246:1904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amu0xeWE7BvPuUzLJ99xoQAAAM0"]
[Thu Jul 30 15:32:05.081198 2026] [security2:error] [pid 189611:tid 189672] [remote 43.134.71.61:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lucky-strike-shop.com"] [uri "/product/kent-5/"] [unique_id "amu0xeWE7BvPuUzLJ99xowAAwTw"]
[Thu Jul 30 15:32:05.081392 2026] [security2:error] [pid 189611:tid 189801] [client 43.134.71.61:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lucky-strike-shop.com"] [uri "/product/kent-5/"] [unique_id "amu0xeWE7BvPuUzLJ99xowAAwTw"]
[Thu Jul 30 15:32:05.272736 2026] [security2:error] [pid 189611:tid 189775] [client 172.213.232.128:33359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/doc.php"] [unique_id "amu0xeWE7BvPuUzLJ99xsgAAAKc"]
[Thu Jul 30 15:32:05.279075 2026] [security2:error] [pid 189611:tid 189744] [client 81.171.72.93:58998] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/wp-admin/setup-config.php"] [unique_id "amu0xeWE7BvPuUzLJ99xswAAAIg"]
[Thu Jul 30 15:32:05.282004 2026] [security2:error] [pid 189611:tid 189834] [client 81.171.72.93:58984] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.ssh/id_ecdsa"] [unique_id "amu0xeWE7BvPuUzLJ99xtAAAAOI"]
[Thu Jul 30 15:32:05.283557 2026] [security2:error] [pid 189611:tid 189835] [client 81.171.72.93:59012] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.git/HEAD"] [unique_id "amu0xeWE7BvPuUzLJ99xtQAAAOM"]
[Thu Jul 30 15:32:05.284267 2026] [security2:error] [pid 189611:tid 189803] [client 81.171.72.93:59026] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/.ssh/id_ed25519"] [unique_id "amu0xeWE7BvPuUzLJ99xtgAAAMM"]
[Thu Jul 30 15:32:05.412136 2026] [security2:error] [pid 189611:tid 189839] [client 81.171.72.93:59004] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/_vti_pvt/service.pwd"] [unique_id "amu0xeWE7BvPuUzLJ99xvQAAAOc"]
[Thu Jul 30 15:32:05.415808 2026] [security2:error] [pid 189611:tid 189818] [client 81.171.72.93:58990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "website-e91d45c4.wrf.zzt.temporary.site"] [uri "/backup.sql"] [unique_id "amu0xeWE7BvPuUzLJ99xvgAAANI"]
[Thu Jul 30 15:32:05.665044 2026] [core:error] [pid 189611:tid 189681] [remote 74.7.244.60:42610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:32:05.665070 2026] [core:error] [pid 189611:tid 189681] [remote 74.7.244.60:42610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:32:05.665239 2026] [security2:error] [pid 189611:tid 189828] [client 74.7.244.60:42610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "mail.riisesolution.com"] [uri "/index.php"] [unique_id "amu0xeWE7BvPuUzLJ99xxQAA3EU"]
[Thu Jul 30 15:32:05.722308 2026] [security2:error] [pid 189611:tid 189841] [client 204.8.98.55:33118] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amu0xeWE7BvPuUzLJ99xyQAAAOk"]
[Thu Jul 30 15:32:05.722429 2026] [security2:error] [pid 189611:tid 189841] [client 204.8.98.55:33118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amu0xeWE7BvPuUzLJ99xyQAAAOk"]
[Thu Jul 30 15:32:05.944098 2026] [security2:error] [pid 189611:tid 189786] [client 172.213.232.128:33158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/dropdown.php"] [unique_id "amu0xeWE7BvPuUzLJ99xzgAAALI"]
[Thu Jul 30 15:32:06.345674 2026] [security2:error] [pid 189611:tid 189773] [client 172.202.44.182:43651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amu0xuWE7BvPuUzLJ99x4gAAAKU"]
[Thu Jul 30 15:32:06.986764 2026] [core:notice] [pid 189611:tid 189692] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:06.990057 2026] [security2:error] [pid 189611:tid 189795] [client 66.249.74.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/19/21"] [unique_id "amu0xuWE7BvPuUzLJ99x7AAAu1A"]
[Thu Jul 30 15:32:07.023683 2026] [security2:error] [pid 189611:tid 189776] [client 172.202.44.182:40428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/size.php"] [unique_id "amu0x-WE7BvPuUzLJ99x8gAAAKg"]
[Thu Jul 30 15:32:07.652373 2026] [security2:error] [pid 189611:tid 189792] [client 85.208.96.210:52528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amu0x-WE7BvPuUzLJ99yAwAAALg"]
[Thu Jul 30 15:32:07.652522 2026] [security2:error] [pid 189611:tid 189792] [client 85.208.96.210:52528] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "happyspree.app"] [uri "/robots.txt"] [unique_id "amu0x-WE7BvPuUzLJ99yAwAAALg"]
[Thu Jul 30 15:32:08.039108 2026] [security2:error] [pid 189611:tid 189758] [client 172.213.232.128:29391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/ee.php"] [unique_id "amu0yOWE7BvPuUzLJ99yFAAAAJY"]
[Thu Jul 30 15:32:08.137965 2026] [security2:error] [pid 189611:tid 189867] [client 20.100.187.246:9973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amu0yOWE7BvPuUzLJ99yGAAAAQM"]
[Thu Jul 30 15:32:08.172884 2026] [security2:error] [pid 189611:tid 189832] [client 172.202.44.182:28728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amu0yOWE7BvPuUzLJ99yGQAAAOA"]
[Thu Jul 30 15:32:08.209294 2026] [security2:error] [pid 189611:tid 189772] [client 85.208.96.207:63688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "happyspree.app"] [uri "/2020/10/"] [unique_id "amu0yOWE7BvPuUzLJ99yHQAAAKQ"]
[Thu Jul 30 15:32:08.209454 2026] [security2:error] [pid 189611:tid 189772] [client 85.208.96.207:63688] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "happyspree.app"] [uri "/2020/10/"] [unique_id "amu0yOWE7BvPuUzLJ99yHQAAAKQ"]
[Thu Jul 30 15:32:08.592331 2026] [security2:error] [pid 189611:tid 189831] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0x-WE7BvPuUzLJ99yEwAA31g"]
[Thu Jul 30 15:32:08.766502 2026] [security2:error] [pid 189611:tid 189863] [client 204.8.98.55:54020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amu0yOWE7BvPuUzLJ99yKwAAAP8"]
[Thu Jul 30 15:32:08.766603 2026] [security2:error] [pid 189611:tid 189863] [client 204.8.98.55:54020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amu0yOWE7BvPuUzLJ99yKwAAAP8"]
[Thu Jul 30 15:32:08.885934 2026] [security2:error] [pid 189611:tid 189788] [client 74.7.175.149:54348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.nmk.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amu0yOWE7BvPuUzLJ99yNQAAALQ"]
[Thu Jul 30 15:32:08.948143 2026] [security2:error] [pid 189611:tid 189751] [client 172.213.232.128:47272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/flower.php"] [unique_id "amu0yOWE7BvPuUzLJ99yNgAAAI8"]
[Thu Jul 30 15:32:08.966732 2026] [security2:error] [pid 189611:tid 189773] [client 68.221.186.136:22682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amu0yOWE7BvPuUzLJ99yNwAAAKU"]
[Thu Jul 30 15:32:09.363425 2026] [security2:error] [pid 189611:tid 189826] [client 85.208.96.203:34660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kendarikomputer.com"] [uri "/2024/01/mengatasi-pesan-error-couldnt-open"] [unique_id "amu0yeWE7BvPuUzLJ99yQgAAANo"]
[Thu Jul 30 15:32:09.363534 2026] [security2:error] [pid 189611:tid 189826] [client 85.208.96.203:34660] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kendarikomputer.com"] [uri "/2024/01/mengatasi-pesan-error-couldnt-open"] [unique_id "amu0yeWE7BvPuUzLJ99yQgAAANo"]
[Thu Jul 30 15:32:09.564861 2026] [security2:error] [pid 189611:tid 189825] [client 172.213.232.128:38269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/gecko-new.php"] [unique_id "amu0yeWE7BvPuUzLJ99yTQAAANk"]
[Thu Jul 30 15:32:09.575967 2026] [security2:error] [pid 189611:tid 189760] [client 172.202.44.182:40432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amu0yeWE7BvPuUzLJ99yTgAAAJg"]
[Thu Jul 30 15:32:09.793076 2026] [security2:error] [pid 189611:tid 189721] [remote 74.7.227.39:49770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amu0yeWE7BvPuUzLJ99yUgAAy20"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/wpforms-lite
[Thu Jul 30 15:32:10.137175 2026] [security2:error] [pid 189611:tid 189802] [client 172.213.232.128:29392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/m.php"] [unique_id "amu0yuWE7BvPuUzLJ99yWQAAAMI"]
[Thu Jul 30 15:32:10.656329 2026] [security2:error] [pid 189611:tid 189762] [client 38.172.162.57:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0yuWE7BvPuUzLJ99yZQAAAJo"]
[Thu Jul 30 15:32:10.657026 2026] [security2:error] [pid 189611:tid 189762] [client 38.172.162.57:16364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu0yuWE7BvPuUzLJ99yZQAAAJo"]
[Thu Jul 30 15:32:10.662250 2026] [security2:error] [pid 189611:tid 189855] [client 172.202.44.182:11681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amu0yuWE7BvPuUzLJ99yZgAAAPc"]
[Thu Jul 30 15:32:10.689367 2026] [security2:error] [pid 189611:tid 189758] [client 172.202.44.182:33441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/403.php"] [unique_id "amu0yuWE7BvPuUzLJ99yZwAAAJY"]
[Thu Jul 30 15:32:10.753319 2026] [security2:error] [pid 189611:tid 189777] [client 68.221.186.136:15220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amu0yuWE7BvPuUzLJ99yaAAAAKk"]
[Thu Jul 30 15:32:11.401381 2026] [security2:error] [pid 189611:tid 189768] [client 52.189.212.127:61015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amu0y-WE7BvPuUzLJ99yeAAAAKA"]
[Thu Jul 30 15:32:11.452155 2026] [security2:error] [pid 189611:tid 189798] [client 68.221.186.136:5142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/cloud.php"] [unique_id "amu0y-WE7BvPuUzLJ99yhwAAAL4"]
[Thu Jul 30 15:32:11.485621 2026] [security2:error] [pid 189611:tid 189812] [client 52.189.212.127:61018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/inputs.php"] [unique_id "amu0y-WE7BvPuUzLJ99yiQAAAMw"]
[Thu Jul 30 15:32:11.485661 2026] [security2:error] [pid 189611:tid 189814] [client 52.189.212.127:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/network/index.php"] [unique_id "amu0y-WE7BvPuUzLJ99yigAAAM4"]
[Thu Jul 30 15:32:11.813603 2026] [core:notice] [pid 189611:tid 189786] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:11.934265 2026] [security2:error] [pid 189611:tid 189803] [client 172.202.44.182:28696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/edit.php"] [unique_id "amu0y-WE7BvPuUzLJ99ymAAAAMM"]
[Thu Jul 30 15:32:12.427188 2026] [security2:error] [pid 189611:tid 189825] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu0y-WE7BvPuUzLJ99ylAAAANk"]
[Thu Jul 30 15:32:12.803083 2026] [security2:error] [pid 189611:tid 189791] [client 20.100.187.246:10014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/banners/about.php"] [unique_id "amu0zOWE7BvPuUzLJ99yrwAAALc"]
[Thu Jul 30 15:32:13.120593 2026] [security2:error] [pid 189611:tid 189773] [client 52.189.212.127:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/edit-tags.php"] [unique_id "amu0zeWE7BvPuUzLJ99yvwAAAKU"]
[Thu Jul 30 15:32:13.123784 2026] [security2:error] [pid 189611:tid 189795] [client 52.189.212.127:61103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/geju.php"] [unique_id "amu0zeWE7BvPuUzLJ99ywQAAALs"]
[Thu Jul 30 15:32:13.124020 2026] [security2:error] [pid 189611:tid 189759] [client 52.189.212.127:61106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/js/index.php"] [unique_id "amu0zeWE7BvPuUzLJ99ywgAAAJc"]
[Thu Jul 30 15:32:13.920159 2026] [security2:error] [pid 189611:tid 189849] [client 20.100.187.246:8586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/about.php"] [unique_id "amu0zeWE7BvPuUzLJ99y0AAAAPE"]
[Thu Jul 30 15:32:14.178756 2026] [security2:error] [pid 189611:tid 189755] [client 68.221.186.136:39991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/updates.php"] [unique_id "amu0zuWE7BvPuUzLJ99y2gAAAJM"]
[Thu Jul 30 15:32:14.482099 2026] [security2:error] [pid 189611:tid 189772] [client 52.189.212.127:61204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp.php"] [unique_id "amu0zuWE7BvPuUzLJ99y4AAAAKQ"]
[Thu Jul 30 15:32:14.482159 2026] [security2:error] [pid 189611:tid 189753] [client 52.189.212.127:61203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/admin.php"] [unique_id "amu0zuWE7BvPuUzLJ99y3wAAAJE"]
[Thu Jul 30 15:32:14.483876 2026] [security2:error] [pid 189611:tid 189756] [client 52.189.212.127:61205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/images/index.php"] [unique_id "amu0zuWE7BvPuUzLJ99y4QAAAJQ"]
[Thu Jul 30 15:32:14.955374 2026] [security2:error] [pid 189611:tid 189750] [client 172.202.44.182:51065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/sf.php"] [unique_id "amu0zuWE7BvPuUzLJ99y7gAAAI4"]
[Thu Jul 30 15:32:15.003589 2026] [security2:error] [pid 189611:tid 189794] [client 68.221.186.136:22078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amu0z-WE7BvPuUzLJ99y8gAAALo"]
[Thu Jul 30 15:32:16.014019 2026] [security2:error] [pid 189611:tid 189810] [client 68.221.186.136:13320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amu00OWE7BvPuUzLJ99zEAAAAMo"]
[Thu Jul 30 15:32:16.106596 2026] [core:notice] [pid 189611:tid 189643] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:16.118171 2026] [core:error] [pid 189611:tid 189643] [remote 66.249.65.194:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:32:16.118469 2026] [security2:error] [pid 189611:tid 189800] [client 66.249.65.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/37/39.html.html.html.html.html.html.html.html.html.html"] [unique_id "amu0z-WE7BvPuUzLJ99zCQAAwB8"]
[Thu Jul 30 15:32:16.223220 2026] [security2:error] [pid 189611:tid 189771] [client 172.202.44.182:51047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wso.php"] [unique_id "amu00OWE7BvPuUzLJ99zFgAAAKM"]
[Thu Jul 30 15:32:16.400558 2026] [security2:error] [pid 189611:tid 189839] [client 172.213.232.128:38606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/mah/autoload_classmap.php"] [unique_id "amu00OWE7BvPuUzLJ99zHAAAAOc"]
[Thu Jul 30 15:32:17.006681 2026] [security2:error] [pid 189611:tid 189772] [client 68.221.186.136:16766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amu00eWE7BvPuUzLJ99zKgAAAKQ"]
[Thu Jul 30 15:32:17.150903 2026] [security2:error] [pid 189611:tid 189761] [client 172.202.44.182:11649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/ioxi-o.php"] [unique_id "amu00eWE7BvPuUzLJ99zLgAAAJk"]
[Thu Jul 30 15:32:18.008760 2026] [security2:error] [pid 189611:tid 189809] [client 172.202.44.182:57345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/file56.php"] [unique_id "amu00uWE7BvPuUzLJ99zPwAAAMk"]
[Thu Jul 30 15:32:18.313922 2026] [security2:error] [pid 189611:tid 189827] [client 172.213.232.128:41199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/mah/flower.php"] [unique_id "amu00uWE7BvPuUzLJ99zRgAAANs"]
[Thu Jul 30 15:32:18.444965 2026] [security2:error] [pid 189611:tid 189746] [client 172.202.44.182:42100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amu00uWE7BvPuUzLJ99zSgAAAIo"]
[Thu Jul 30 15:32:18.721647 2026] [security2:error] [pid 189611:tid 189759] [client 68.221.186.136:22673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/alfa-rex.php7"] [unique_id "amu00uWE7BvPuUzLJ99zVAAAAJc"]
[Thu Jul 30 15:32:19.266435 2026] [security2:error] [pid 189611:tid 189829] [client 172.202.44.182:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amu00-WE7BvPuUzLJ99zYgAAAN0"]
[Thu Jul 30 15:32:19.283104 2026] [security2:error] [pid 189611:tid 189811] [client 172.213.232.128:38254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/mah/xleet.php"] [unique_id "amu00-WE7BvPuUzLJ99zYwAAAMs"]
[Thu Jul 30 15:32:19.704358 2026] [security2:error] [pid 189611:tid 189783] [client 68.221.186.136:5181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/alfanew.php"] [unique_id "amu00-WE7BvPuUzLJ99zaQAAAK8"]
[Thu Jul 30 15:32:20.063252 2026] [security2:error] [pid 189611:tid 189787] [client 172.213.232.128:29049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/mini.php"] [unique_id "amu01OWE7BvPuUzLJ99zdAAAALM"]
[Thu Jul 30 15:32:20.448307 2026] [core:notice] [pid 189611:tid 189679] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:20.452096 2026] [security2:error] [pid 189611:tid 189791] [client 66.249.74.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/232/226"] [unique_id "amu01OWE7BvPuUzLJ99zdQAAt0M"]
[Thu Jul 30 15:32:20.648809 2026] [security2:error] [pid 189611:tid 189806] [client 172.202.44.182:28707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-admin/css/index.php"] [unique_id "amu01OWE7BvPuUzLJ99zgAAAAMY"]
[Thu Jul 30 15:32:20.682083 2026] [security2:error] [pid 189611:tid 189779] [client 172.202.44.182:33457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/as.php"] [unique_id "amu01OWE7BvPuUzLJ99zggAAAKs"]
[Thu Jul 30 15:32:20.802957 2026] [security2:error] [pid 189611:tid 189748] [client 20.100.187.246:4958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/.well-known/about.php"] [unique_id "amu01OWE7BvPuUzLJ99zhgAAAIw"]
[Thu Jul 30 15:32:21.143868 2026] [security2:error] [pid 189611:tid 189821] [client 52.189.212.127:61891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/backup/inputs.php"] [unique_id "amu01eWE7BvPuUzLJ99zjQAAANU"]
[Thu Jul 30 15:32:21.184643 2026] [security2:error] [pid 189611:tid 189820] [client 38.172.162.57:16098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu01eWE7BvPuUzLJ99zjgAAANQ"]
[Thu Jul 30 15:32:21.185747 2026] [security2:error] [pid 189611:tid 189820] [client 38.172.162.57:16098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu01eWE7BvPuUzLJ99zjgAAANQ"]
[Thu Jul 30 15:32:21.216454 2026] [security2:error] [pid 189611:tid 189817] [client 52.189.212.127:61893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/css/index.php"] [unique_id "amu01eWE7BvPuUzLJ99zjwAAANE"]
[Thu Jul 30 15:32:21.448550 2026] [security2:error] [pid 189611:tid 189842] [client 52.189.212.127:61890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amu01eWE7BvPuUzLJ99zmQAAAOo"]
[Thu Jul 30 15:32:21.540351 2026] [security2:error] [pid 189611:tid 189795] [client 20.100.187.246:3938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amu01eWE7BvPuUzLJ99znQAAALs"]
[Thu Jul 30 15:32:21.600202 2026] [security2:error] [pid 189611:tid 189775] [client 172.202.44.182:11705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/wp-content/edit.php"] [unique_id "amu01eWE7BvPuUzLJ99zngAAAKc"]
[Thu Jul 30 15:32:21.804923 2026] [security2:error] [pid 189611:tid 189769] [client 172.213.232.128:37187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/moon.php"] [unique_id "amu01eWE7BvPuUzLJ99zoAAAAKE"]
[Thu Jul 30 15:32:21.840909 2026] [security2:error] [pid 189611:tid 189785] [client 172.202.44.182:40396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amu01eWE7BvPuUzLJ99zpAAAALE"]
[Thu Jul 30 15:32:21.948229 2026] [security2:error] [pid 189611:tid 189853] [client 68.221.186.136:16733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amu01eWE7BvPuUzLJ99zqAAAAPU"]
[Thu Jul 30 15:32:22.631498 2026] [security2:error] [pid 189611:tid 189799] [client 172.202.44.182:11999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmhs.ph"] [uri "/2.php"] [unique_id "amu01uWE7BvPuUzLJ99ztQAAAL8"]
[Thu Jul 30 15:32:23.460483 2026] [security2:error] [pid 189611:tid 189792] [client 68.221.186.136:5171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amu01-WE7BvPuUzLJ99zxQAAALg"]
[Thu Jul 30 15:32:24.134694 2026] [security2:error] [pid 189611:tid 189778] [client 172.202.44.182:40415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amu02OWE7BvPuUzLJ99z0wAAAKo"]
[Thu Jul 30 15:32:24.190922 2026] [security2:error] [pid 189611:tid 189777] [client 20.100.187.246:10010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amu02OWE7BvPuUzLJ99z1gAAAKk"]
[Thu Jul 30 15:32:24.409645 2026] [security2:error] [pid 189611:tid 189793] [client 172.213.232.128:34377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/new.php"] [unique_id "amu02OWE7BvPuUzLJ99z2AAAALk"]
[Thu Jul 30 15:32:24.467463 2026] [core:notice] [pid 189611:tid 189824] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:24.685746 2026] [core:notice] [pid 189611:tid 189711] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:24.819705 2026] [security2:error] [pid 189611:tid 189712] [remote 57.141.0.61:63562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/86927149125/feed/rss2/"] [unique_id "amu02OWE7BvPuUzLJ99z5AAA3GQ"]
[Thu Jul 30 15:32:24.853121 2026] [security2:error] [pid 189611:tid 189785] [client 20.100.187.246:6614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/img/about.php"] [unique_id "amu02OWE7BvPuUzLJ99z5QAAALE"]
[Thu Jul 30 15:32:24.897892 2026] [security2:error] [pid 189611:tid 189839] [client 52.189.212.127:62255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/uploads/inputs.php"] [unique_id "amu02OWE7BvPuUzLJ99z5gAAAOc"]
[Thu Jul 30 15:32:24.899130 2026] [security2:error] [pid 189611:tid 189749] [client 52.189.212.127:62258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/SimplePie/Content/Type/index.php"] [unique_id "amu02OWE7BvPuUzLJ99z5wAAAI0"]
[Thu Jul 30 15:32:24.976809 2026] [security2:error] [pid 189611:tid 189755] [client 172.213.232.128:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/radio.php"] [unique_id "amu02OWE7BvPuUzLJ99z6AAAAJM"]
[Thu Jul 30 15:32:25.202478 2026] [security2:error] [pid 189611:tid 189802] [client 52.189.212.127:62264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/geju.php"] [unique_id "amu02eWE7BvPuUzLJ99z7wAAAMI"]
[Thu Jul 30 15:32:25.578869 2026] [security2:error] [pid 189611:tid 189856] [client 172.202.44.182:40434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/plugins.php"] [unique_id "amu02eWE7BvPuUzLJ99z9gAAAPg"]
[Thu Jul 30 15:32:26.146922 2026] [security2:error] [pid 189611:tid 189791] [client 172.213.17.107:27482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu02uWE7BvPuUzLJ990AgAAALc"]
[Thu Jul 30 15:32:26.147088 2026] [security2:error] [pid 189611:tid 189791] [client 172.213.17.107:27482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu02uWE7BvPuUzLJ990AgAAALc"]
[Thu Jul 30 15:32:26.491050 2026] [security2:error] [pid 189611:tid 189764] [client 20.100.187.246:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/languages/about.php"] [unique_id "amu02uWE7BvPuUzLJ990CwAAAJw"]
[Thu Jul 30 15:32:27.637144 2026] [security2:error] [pid 189611:tid 189746] [client 20.100.187.246:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amu02-WE7BvPuUzLJ990IwAAAIo"]
[Thu Jul 30 15:32:27.736379 2026] [security2:error] [pid 189611:tid 189777] [client 172.202.44.182:33419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/js/index.php"] [unique_id "amu02-WE7BvPuUzLJ990KQAAAKk"]
[Thu Jul 30 15:32:27.867134 2026] [security2:error] [pid 189611:tid 189756] [client 52.189.212.127:62584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-includes/Requests/Auth/index.php"] [unique_id "amu02-WE7BvPuUzLJ990LQAAAJQ"]
[Thu Jul 30 15:32:27.873689 2026] [security2:error] [pid 189611:tid 189816] [client 52.189.212.127:62585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/plugins/inputs.php"] [unique_id "amu02-WE7BvPuUzLJ990LgAAANA"]
[Thu Jul 30 15:32:27.993423 2026] [security2:error] [pid 189611:tid 189762] [client 172.213.232.128:37224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/s.php"] [unique_id "amu02-WE7BvPuUzLJ990MwAAAJo"]
[Thu Jul 30 15:32:28.188593 2026] [security2:error] [pid 189611:tid 189803] [client 68.221.186.136:25299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-p.php7"] [unique_id "amu03OWE7BvPuUzLJ990NwAAAMM"]
[Thu Jul 30 15:32:28.857930 2026] [security2:error] [pid 189611:tid 189781] [client 52.189.212.127:62696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp.php"] [unique_id "amu03OWE7BvPuUzLJ990TAAAAK0"]
[Thu Jul 30 15:32:28.931434 2026] [security2:error] [pid 189611:tid 189808] [client 172.213.17.107:29425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu03OWE7BvPuUzLJ990TQAAAMg"]
[Thu Jul 30 15:32:28.931550 2026] [security2:error] [pid 189611:tid 189808] [client 172.213.17.107:29425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu03OWE7BvPuUzLJ990TQAAAMg"]
[Thu Jul 30 15:32:28.980700 2026] [security2:error] [pid 189611:tid 189851] [client 172.213.232.128:38593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/sim.php"] [unique_id "amu03OWE7BvPuUzLJ990TgAAAPM"]
[Thu Jul 30 15:32:29.008421 2026] [security2:error] [pid 189611:tid 189792] [client 172.202.44.182:40431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/go.php"] [unique_id "amu03eWE7BvPuUzLJ990TwAAALg"]
[Thu Jul 30 15:32:29.599263 2026] [security2:error] [pid 189611:tid 189849] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu03eWE7BvPuUzLJ990XAAAAPE"]
[Thu Jul 30 15:32:29.599408 2026] [security2:error] [pid 189611:tid 189849] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu03eWE7BvPuUzLJ990XAAAAPE"]
[Thu Jul 30 15:32:29.637754 2026] [security2:error] [pid 189611:tid 189780] [client 172.213.232.128:34376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/text.php"] [unique_id "amu03eWE7BvPuUzLJ990XQAAAKw"]
[Thu Jul 30 15:32:30.239246 2026] [security2:error] [pid 189611:tid 189829] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu03uWE7BvPuUzLJ990bAAAAN0"]
[Thu Jul 30 15:32:30.239371 2026] [security2:error] [pid 189611:tid 189829] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu03uWE7BvPuUzLJ990bAAAAN0"]
[Thu Jul 30 15:32:30.299884 2026] [security2:error] [pid 189611:tid 189815] [client 172.202.44.182:33470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/test1.php"] [unique_id "amu03uWE7BvPuUzLJ990cAAAAM8"]
[Thu Jul 30 15:32:30.485132 2026] [security2:error] [pid 189611:tid 189628] [remote 110.249.202.76:37186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/abu-dhabi-desert-safari-without-pickup.html"] [unique_id "amu03uWE7BvPuUzLJ990dAAArxA"]
[Thu Jul 30 15:32:30.670848 2026] [security2:error] [pid 189611:tid 189766] [client 172.213.232.128:46605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/user.php"] [unique_id "amu03uWE7BvPuUzLJ990dQAAAJ4"]
[Thu Jul 30 15:32:30.844119 2026] [security2:error] [pid 189611:tid 189742] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/bootstrap.php"] [unique_id "amu03uWE7BvPuUzLJ990fAAAAIY"]
[Thu Jul 30 15:32:30.844231 2026] [security2:error] [pid 189611:tid 189742] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/bootstrap.php"] [unique_id "amu03uWE7BvPuUzLJ990fAAAAIY"]
[Thu Jul 30 15:32:30.961444 2026] [security2:error] [pid 189611:tid 189830] [client 172.237.109.114:63466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/graphiql.php"] [unique_id "amu03uWE7BvPuUzLJ990gQAAAN4"]
[Thu Jul 30 15:32:31.186007 2026] [security2:error] [pid 189611:tid 189781] [client 172.213.17.107:14564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amu03-WE7BvPuUzLJ990lAAAAK0"]
[Thu Jul 30 15:32:31.186244 2026] [security2:error] [pid 189611:tid 189781] [client 172.213.17.107:14564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "amu03-WE7BvPuUzLJ990lAAAAK0"]
[Thu Jul 30 15:32:31.412038 2026] [security2:error] [pid 189611:tid 189764] [client 68.221.186.136:15370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-admin/repeater.php"] [unique_id "amu03-WE7BvPuUzLJ990nwAAAJw"]
[Thu Jul 30 15:32:31.580082 2026] [security2:error] [pid 189611:tid 189765] [client 172.213.232.128:37211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/webadmin.php"] [unique_id "amu03-WE7BvPuUzLJ990owAAAJ0"]
[Thu Jul 30 15:32:31.739434 2026] [security2:error] [pid 189611:tid 189806] [client 38.172.162.57:15925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu03-WE7BvPuUzLJ990pAAAAMY"]
[Thu Jul 30 15:32:31.740302 2026] [security2:error] [pid 189611:tid 189806] [client 38.172.162.57:15925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu03-WE7BvPuUzLJ990pAAAAMY"]
[Thu Jul 30 15:32:31.792847 2026] [security2:error] [pid 189611:tid 189771] [client 172.202.44.182:40385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/images/index.php"] [unique_id "amu03-WE7BvPuUzLJ990qAAAAKM"]
[Thu Jul 30 15:32:31.865549 2026] [security2:error] [pid 189611:tid 189767] [client 20.100.187.246:6606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amu03-WE7BvPuUzLJ990qgAAAJ8"]
[Thu Jul 30 15:32:32.158338 2026] [core:notice] [pid 189611:tid 189647] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:32.217201 2026] [security2:error] [pid 189611:tid 189755] [client 52.189.212.127:63085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "amu04OWE7BvPuUzLJ990uQAAAJM"]
[Thu Jul 30 15:32:32.304411 2026] [security2:error] [pid 189611:tid 189828] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-blog-header.php"] [unique_id "amu04OWE7BvPuUzLJ990vQAAANw"]
[Thu Jul 30 15:32:32.304641 2026] [security2:error] [pid 189611:tid 189828] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-blog-header.php"] [unique_id "amu04OWE7BvPuUzLJ990vQAAANw"]
[Thu Jul 30 15:32:32.390153 2026] [security2:error] [pid 189611:tid 189749] [client 172.213.232.128:28998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wordpress/wp-content/plugins/xcvbx/autoload_classmap.php"] [unique_id "amu04OWE7BvPuUzLJ990vgAAAI0"]
[Thu Jul 30 15:32:32.416806 2026] [security2:error] [pid 189611:tid 189772] [client 172.237.109.114:26094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990gAAAAKQ"]
[Thu Jul 30 15:32:32.444780 2026] [security2:error] [pid 189611:tid 189844] [client 172.237.109.114:33353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990iAAAAOw"]
[Thu Jul 30 15:32:32.448360 2026] [security2:error] [pid 189611:tid 189836] [client 172.237.109.114:56628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990gwAAAOQ"]
[Thu Jul 30 15:32:32.449446 2026] [security2:error] [pid 189611:tid 189745] [client 172.237.109.114:56683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990hgAAAIk"]
[Thu Jul 30 15:32:32.468021 2026] [security2:error] [pid 189611:tid 189799] [client 172.237.109.114:3136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990ggAAAL8"]
[Thu Jul 30 15:32:32.470216 2026] [security2:error] [pid 189611:tid 189797] [client 172.237.109.114:23677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990iQAAAL0"]
[Thu Jul 30 15:32:32.472177 2026] [security2:error] [pid 189611:tid 189769] [client 172.237.109.114:42402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990jAAAAKE"]
[Thu Jul 30 15:32:32.475908 2026] [security2:error] [pid 189611:tid 189833] [client 172.237.109.114:2373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990hAAAAOE"]
[Thu Jul 30 15:32:32.476618 2026] [security2:error] [pid 189611:tid 189794] [client 172.237.109.114:19641] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990jgAAALo"]
[Thu Jul 30 15:32:32.499303 2026] [security2:error] [pid 189611:tid 189809] [client 172.237.109.114:51458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990hQAAAMk"]
[Thu Jul 30 15:32:32.499762 2026] [security2:error] [pid 189611:tid 189750] [client 172.237.109.114:59745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990iwAAAI4"]
[Thu Jul 30 15:32:32.500181 2026] [security2:error] [pid 189611:tid 189863] [client 172.237.109.114:23058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990jQAAAP8"]
[Thu Jul 30 15:32:32.504997 2026] [security2:error] [pid 189611:tid 189754] [client 172.237.109.114:5711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03-WE7BvPuUzLJ990kAAAAJI"]
[Thu Jul 30 15:32:32.506595 2026] [security2:error] [pid 189611:tid 189787] [client 172.237.109.114:23279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990igAAALM"]
[Thu Jul 30 15:32:32.508920 2026] [security2:error] [pid 189611:tid 189860] [client 172.237.109.114:27464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03-WE7BvPuUzLJ990kQAAAPw"]
[Thu Jul 30 15:32:32.509972 2026] [security2:error] [pid 189611:tid 189859] [client 172.237.109.114:48551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03-WE7BvPuUzLJ990jwAAAPs"]
[Thu Jul 30 15:32:32.514012 2026] [security2:error] [pid 189611:tid 189813] [client 172.237.109.114:8943] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03-WE7BvPuUzLJ990kgAAAM0"]
[Thu Jul 30 15:32:32.530472 2026] [security2:error] [pid 189611:tid 189819] [client 172.237.109.114:50624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03uWE7BvPuUzLJ990hwAAANM"]
[Thu Jul 30 15:32:32.555538 2026] [security2:error] [pid 189611:tid 189858] [client 172.237.109.114:14952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu03-WE7BvPuUzLJ990kwAAAPo"]
[Thu Jul 30 15:32:32.799392 2026] [security2:error] [pid 189611:tid 189814] [client 20.100.187.246:9995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amu04OWE7BvPuUzLJ990ywAAAM4"]
[Thu Jul 30 15:32:32.891940 2026] [security2:error] [pid 189611:tid 189827] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-load.php"] [unique_id "amu04OWE7BvPuUzLJ990zwAAANs"]
[Thu Jul 30 15:32:32.892047 2026] [security2:error] [pid 189611:tid 189827] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-load.php"] [unique_id "amu04OWE7BvPuUzLJ990zwAAANs"]
[Thu Jul 30 15:32:33.193923 2026] [security2:error] [pid 189611:tid 189840] [client 172.202.44.182:58526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/asd.php"] [unique_id "amu04eWE7BvPuUzLJ9901wAAAOg"]
[Thu Jul 30 15:32:33.211823 2026] [security2:error] [pid 189611:tid 189864] [client 52.189.212.127:63087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/themes/inputs.php"] [unique_id "amu04eWE7BvPuUzLJ9902AAAAQA"]
[Thu Jul 30 15:32:33.406477 2026] [security2:error] [pid 189611:tid 189767] [client 172.213.232.128:46655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wordpress/wp-content/plugins/xcvbx/flower.php"] [unique_id "amu04eWE7BvPuUzLJ9903QAAAJ8"]
[Thu Jul 30 15:32:33.421418 2026] [security2:error] [pid 189611:tid 189780] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/edit.php"] [unique_id "amu04eWE7BvPuUzLJ9903gAAAKw"]
[Thu Jul 30 15:32:33.421504 2026] [security2:error] [pid 189611:tid 189780] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/edit.php"] [unique_id "amu04eWE7BvPuUzLJ9903gAAAKw"]
[Thu Jul 30 15:32:33.938495 2026] [security2:error] [pid 189611:tid 189778] [client 20.100.187.246:29460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amu04eWE7BvPuUzLJ9906AAAAKo"]
[Thu Jul 30 15:32:34.021180 2026] [proxy:error] [pid 189611:tid 189836] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:34.021234 2026] [proxy_http:error] [pid 189611:tid 189836] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:34.021817 2026] [proxy:error] [pid 189611:tid 189836] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:34.021860 2026] [proxy_http:error] [pid 189611:tid 189836] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:34.021941 2026] [security2:error] [pid 189611:tid 189836] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu04uWE7BvPuUzLJ9907AAAAOQ"]
[Thu Jul 30 15:32:34.312907 2026] [security2:error] [pid 189611:tid 189853] [client 172.213.232.128:29017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wordpress/wp-content/plugins/xcvbx/xleet.php"] [unique_id "amu04uWE7BvPuUzLJ9909AAAAPU"]
[Thu Jul 30 15:32:34.603332 2026] [security2:error] [pid 189611:tid 189855] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/mah.php"] [unique_id "amu04uWE7BvPuUzLJ990-wAAAPc"]
[Thu Jul 30 15:32:34.603434 2026] [security2:error] [pid 189611:tid 189855] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/mah.php"] [unique_id "amu04uWE7BvPuUzLJ990-wAAAPc"]
[Thu Jul 30 15:32:34.836371 2026] [security2:error] [pid 189611:tid 189857] [client 172.213.17.107:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/media.php"] [unique_id "amu04uWE7BvPuUzLJ990_wAAAPk"]
[Thu Jul 30 15:32:34.836516 2026] [security2:error] [pid 189611:tid 189857] [client 172.213.17.107:33188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/media.php"] [unique_id "amu04uWE7BvPuUzLJ990_wAAAPk"]
[Thu Jul 30 15:32:34.909385 2026] [security2:error] [pid 189611:tid 189670] [remote 74.7.227.39:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amu04uWE7BvPuUzLJ991AAAA5jo"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/pagelayer-pro
[Thu Jul 30 15:32:35.170530 2026] [security2:error] [pid 189611:tid 189792] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/archive.php"] [unique_id "amu04-WE7BvPuUzLJ991CgAAALg"]
[Thu Jul 30 15:32:35.170625 2026] [security2:error] [pid 189611:tid 189792] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/archive.php"] [unique_id "amu04-WE7BvPuUzLJ991CgAAALg"]
[Thu Jul 30 15:32:35.177745 2026] [security2:error] [pid 189611:tid 189841] [client 68.221.186.136:9594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-includes/repeater.php"] [unique_id "amu04-WE7BvPuUzLJ991CwAAAOk"]
[Thu Jul 30 15:32:35.232352 2026] [security2:error] [pid 189611:tid 189847] [client 172.202.44.182:33425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amu04-WE7BvPuUzLJ991DAAAAO8"]
[Thu Jul 30 15:32:35.408456 2026] [security2:error] [pid 189611:tid 189673] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-login.php"] [unique_id "amu04-WE7BvPuUzLJ991DQAA6z0"]
[Thu Jul 30 15:32:35.464121 2026] [security2:error] [pid 189611:tid 189830] [client 172.213.232.128:46648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wordpress/wp-content/themes/as/autoload_classmap.php"] [unique_id "amu04-WE7BvPuUzLJ991DgAAAN4"]
[Thu Jul 30 15:32:35.811731 2026] [security2:error] [pid 189611:tid 189840] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/hosty.php"] [unique_id "amu04-WE7BvPuUzLJ991GAAAAOg"]
[Thu Jul 30 15:32:35.811869 2026] [security2:error] [pid 189611:tid 189840] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/hosty.php"] [unique_id "amu04-WE7BvPuUzLJ991GAAAAOg"]
[Thu Jul 30 15:32:36.424495 2026] [proxy:error] [pid 189611:tid 189777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:36.424584 2026] [proxy_http:error] [pid 189611:tid 189777] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:36.425628 2026] [proxy:error] [pid 189611:tid 189777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:36.425693 2026] [proxy_http:error] [pid 189611:tid 189777] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:36.425822 2026] [security2:error] [pid 189611:tid 189777] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu05OWE7BvPuUzLJ991JgAAAKk"]
[Thu Jul 30 15:32:36.724249 2026] [security2:error] [pid 189611:tid 189778] [client 172.213.17.107:14544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/images.php"] [unique_id "amu05OWE7BvPuUzLJ991LwAAAKo"]
[Thu Jul 30 15:32:36.724354 2026] [security2:error] [pid 189611:tid 189778] [client 172.213.17.107:14544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/images.php"] [unique_id "amu05OWE7BvPuUzLJ991LwAAAKo"]
[Thu Jul 30 15:32:37.005814 2026] [security2:error] [pid 189611:tid 189750] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/admin.php"] [unique_id "amu05eWE7BvPuUzLJ991NQAAAI4"]
[Thu Jul 30 15:32:37.005956 2026] [security2:error] [pid 189611:tid 189750] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/admin.php"] [unique_id "amu05eWE7BvPuUzLJ991NQAAAI4"]
[Thu Jul 30 15:32:37.027123 2026] [core:notice] [pid 189611:tid 189861] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:37.355905 2026] [security2:error] [pid 189611:tid 189863] [client 172.213.232.128:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "amu05eWE7BvPuUzLJ991QQAAAP8"]
[Thu Jul 30 15:32:37.453084 2026] [security2:error] [pid 189611:tid 189754] [client 172.237.109.114:57665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu05OWE7BvPuUzLJ991NAAAAJI"]
[Thu Jul 30 15:32:37.556831 2026] [security2:error] [pid 189611:tid 189856] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/av.php"] [unique_id "amu05eWE7BvPuUzLJ991QgAAAPg"]
[Thu Jul 30 15:32:37.556995 2026] [security2:error] [pid 189611:tid 189856] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/av.php"] [unique_id "amu05eWE7BvPuUzLJ991QgAAAPg"]
[Thu Jul 30 15:32:37.737513 2026] [core:error] [pid 189611:tid 189763] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:32:37.737536 2026] [core:error] [pid 189611:tid 189763] [client 2a06:98c0:3600::103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:32:37.914633 2026] [security2:error] [pid 189611:tid 189796] [client 172.202.44.182:40402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amu05eWE7BvPuUzLJ991UAAAALw"]
[Thu Jul 30 15:32:38.078405 2026] [security2:error] [pid 189611:tid 189768] [client 94.154.43.184:24626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "progroup.jo"] [uri "/.env"] [unique_id "amu05uWE7BvPuUzLJ991UQAAAKA"]
[Thu Jul 30 15:32:38.106203 2026] [security2:error] [pid 189611:tid 189748] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/shell.php"] [unique_id "amu05uWE7BvPuUzLJ991UgAAAIw"]
[Thu Jul 30 15:32:38.106360 2026] [security2:error] [pid 189611:tid 189748] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/shell.php"] [unique_id "amu05uWE7BvPuUzLJ991UgAAAIw"]
[Thu Jul 30 15:32:38.146050 2026] [security2:error] [pid 189611:tid 189851] [client 94.154.43.186:61280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.progroup.jo"] [uri "/.env"] [unique_id "amu05uWE7BvPuUzLJ991VgAAAPM"]
[Thu Jul 30 15:32:38.336738 2026] [core:notice] [pid 189611:tid 189696] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:38.524854 2026] [security2:error] [pid 189611:tid 189790] [client 68.221.186.136:41529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.186.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alseermarine.com"] [uri "/wp-content/repeater.php"] [unique_id "amu05uWE7BvPuUzLJ991XgAAALY"]
[Thu Jul 30 15:32:38.654403 2026] [security2:error] [pid 189611:tid 189759] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/storage/index.php"] [unique_id "amu05uWE7BvPuUzLJ991YQAAAJc"]
[Thu Jul 30 15:32:38.654503 2026] [security2:error] [pid 189611:tid 189759] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/storage/index.php"] [unique_id "amu05uWE7BvPuUzLJ991YQAAAJc"]
[Thu Jul 30 15:32:38.737848 2026] [core:notice] [pid 189611:tid 189694] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:38.762625 2026] [security2:error] [pid 189611:tid 189820] [client 172.213.232.128:46628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wordpress/wp-content/themes/as/xleet.php"] [unique_id "amu05uWE7BvPuUzLJ991awAAANQ"]
[Thu Jul 30 15:32:39.151361 2026] [security2:error] [pid 189611:tid 189702] [remote 57.141.0.60:26588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/586148043/feed/rss2/"] [unique_id "amu05-WE7BvPuUzLJ991dAAA51o"]
[Thu Jul 30 15:32:39.218598 2026] [security2:error] [pid 189611:tid 189811] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/w.php"] [unique_id "amu05-WE7BvPuUzLJ991dQAAAMs"]
[Thu Jul 30 15:32:39.218725 2026] [security2:error] [pid 189611:tid 189811] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/w.php"] [unique_id "amu05-WE7BvPuUzLJ991dQAAAMs"]
[Thu Jul 30 15:32:39.237654 2026] [security2:error] [pid 189611:tid 189842] [client 20.100.187.246:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/js/about.php"] [unique_id "amu05-WE7BvPuUzLJ991dgAAAOo"]
[Thu Jul 30 15:32:39.633181 2026] [security2:error] [pid 189611:tid 189753] [client 172.213.17.107:8140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/adminner.php"] [unique_id "amu05-WE7BvPuUzLJ991gQAAAJE"]
[Thu Jul 30 15:32:39.633273 2026] [security2:error] [pid 189611:tid 189753] [client 172.213.17.107:8140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/adminner.php"] [unique_id "amu05-WE7BvPuUzLJ991gQAAAJE"]
[Thu Jul 30 15:32:39.805726 2026] [security2:error] [pid 189611:tid 189754] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/jp.php"] [unique_id "amu05-WE7BvPuUzLJ991iAAAAJI"]
[Thu Jul 30 15:32:39.805823 2026] [security2:error] [pid 189611:tid 189754] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/jp.php"] [unique_id "amu05-WE7BvPuUzLJ991iAAAAJI"]
[Thu Jul 30 15:32:39.919429 2026] [core:notice] [pid 189611:tid 189706] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:40.218164 2026] [security2:error] [pid 189611:tid 189807] [client 172.202.44.182:42079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/atomlib.php"] [unique_id "amu06OWE7BvPuUzLJ991lQAAAMc"]
[Thu Jul 30 15:32:40.330628 2026] [security2:error] [pid 189611:tid 189776] [client 20.100.187.246:9999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amu06OWE7BvPuUzLJ991lwAAAKg"]
[Thu Jul 30 15:32:40.382942 2026] [proxy:error] [pid 189611:tid 189764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:40.383024 2026] [proxy_http:error] [pid 189611:tid 189764] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:40.383866 2026] [proxy:error] [pid 189611:tid 189764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:40.383926 2026] [proxy_http:error] [pid 189611:tid 189764] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:40.384055 2026] [security2:error] [pid 189611:tid 189764] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu06OWE7BvPuUzLJ991mQAAAJw"]
[Thu Jul 30 15:32:40.415411 2026] [security2:error] [pid 189611:tid 189768] [client 47.128.121.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu06OWE7BvPuUzLJ991lgAAAKA"]
[Thu Jul 30 15:32:40.608163 2026] [security2:error] [pid 189611:tid 189775] [client 52.189.212.127:64112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/languages/index.php"] [unique_id "amu06OWE7BvPuUzLJ991oQAAAKc"]
[Thu Jul 30 15:32:40.669771 2026] [autoindex:error] [pid 189611:tid 189846] [client 4.240.96.129:56518] AH01276: Cannot serve directory /home1/yqegzjte/public_html/website_839e7477/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 15:32:40.675654 2026] [security2:error] [pid 189611:tid 189715] [remote 74.7.243.224:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/donatef.php"] [unique_id "amu06OWE7BvPuUzLJ991owAA7Wc"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/article.php?id=27
[Thu Jul 30 15:32:40.762851 2026] [security2:error] [pid 189611:tid 189780] [client 52.189.212.127:64136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/userfuns.php"] [unique_id "amu06OWE7BvPuUzLJ991pwAAAKw"]
[Thu Jul 30 15:32:40.793692 2026] [security2:error] [pid 189611:tid 189716] [remote 47.128.112.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.112.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/1"] [unique_id "amu06OWE7BvPuUzLJ991oAAAomg"]
[Thu Jul 30 15:32:40.952886 2026] [security2:error] [pid 189611:tid 189853] [client 172.213.232.128:36406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "amu06OWE7BvPuUzLJ991rgAAAPU"]
[Thu Jul 30 15:32:41.009557 2026] [security2:error] [pid 189611:tid 189793] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/ws77.php"] [unique_id "amu06eWE7BvPuUzLJ991rwAAALk"]
[Thu Jul 30 15:32:41.009700 2026] [security2:error] [pid 189611:tid 189793] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/ws77.php"] [unique_id "amu06eWE7BvPuUzLJ991rwAAALk"]
[Thu Jul 30 15:32:41.018874 2026] [core:notice] [pid 189611:tid 189722] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:41.022847 2026] [security2:error] [pid 189611:tid 189778] [client 47.128.112.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/1"] [unique_id "amu06eWE7BvPuUzLJ991sAAAqm4"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:32:41.109180 2026] [core:notice] [pid 189611:tid 189721] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:41.525375 2026] [core:notice] [pid 189611:tid 189854] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:41.538817 2026] [core:error] [pid 189611:tid 189854] [client 66.249.79.1:35717] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:32:41.539035 2026] [security2:error] [pid 189611:tid 189854] [client 66.249.79.1:35717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Perspective/article/view/9158/3976.html.html.html.html.html.html.html.html.html.html"] [unique_id "amu06eWE7BvPuUzLJ991ugAAAPY"]
[Thu Jul 30 15:32:41.562444 2026] [security2:error] [pid 189611:tid 189863] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/blass.php"] [unique_id "amu06eWE7BvPuUzLJ991wgAAAP8"]
[Thu Jul 30 15:32:41.562532 2026] [security2:error] [pid 189611:tid 189863] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/blass.php"] [unique_id "amu06eWE7BvPuUzLJ991wgAAAP8"]
[Thu Jul 30 15:32:41.633005 2026] [security2:error] [pid 189611:tid 189760] [client 20.100.187.246:10021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amu06eWE7BvPuUzLJ991wwAAAJg"]
[Thu Jul 30 15:32:42.117863 2026] [security2:error] [pid 189611:tid 189783] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-info.php"] [unique_id "amu06uWE7BvPuUzLJ9910QAAAK8"]
[Thu Jul 30 15:32:42.117969 2026] [security2:error] [pid 189611:tid 189783] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-info.php"] [unique_id "amu06uWE7BvPuUzLJ9910QAAAK8"]
[Thu Jul 30 15:32:42.325173 2026] [security2:error] [pid 189611:tid 189754] [client 38.172.162.57:16109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu06uWE7BvPuUzLJ9911AAAAJI"]
[Thu Jul 30 15:32:42.325282 2026] [security2:error] [pid 189611:tid 189754] [client 38.172.162.57:16109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu06uWE7BvPuUzLJ9911AAAAJI"]
[Thu Jul 30 15:32:42.634461 2026] [security2:error] [pid 189611:tid 189843] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/CDX1.php"] [unique_id "amu06uWE7BvPuUzLJ9913QAAAOs"]
[Thu Jul 30 15:32:42.634574 2026] [security2:error] [pid 189611:tid 189843] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/CDX1.php"] [unique_id "amu06uWE7BvPuUzLJ9913QAAAOs"]
[Thu Jul 30 15:32:42.926967 2026] [security2:error] [pid 189611:tid 189818] [client 172.213.17.107:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/admin.php"] [unique_id "amu06uWE7BvPuUzLJ9914gAAANI"]
[Thu Jul 30 15:32:42.927093 2026] [security2:error] [pid 189611:tid 189818] [client 172.213.17.107:33200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/admin.php"] [unique_id "amu06uWE7BvPuUzLJ9914gAAANI"]
[Thu Jul 30 15:32:42.981731 2026] [security2:error] [pid 189611:tid 189771] [client 172.202.44.182:33429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amu06uWE7BvPuUzLJ9916QAAAKM"]
[Thu Jul 30 15:32:43.204052 2026] [security2:error] [pid 189611:tid 189767] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wpc.php"] [unique_id "amu06-WE7BvPuUzLJ9916gAAAJ8"]
[Thu Jul 30 15:32:43.204160 2026] [security2:error] [pid 189611:tid 189767] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wpc.php"] [unique_id "amu06-WE7BvPuUzLJ9916gAAAJ8"]
[Thu Jul 30 15:32:43.359055 2026] [security2:error] [pid 189611:tid 189746] [client 172.213.232.128:39071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/colors/autoload_classmap.php"] [unique_id "amu06-WE7BvPuUzLJ9917gAAAIo"]
[Thu Jul 30 15:32:43.900708 2026] [security2:error] [pid 189611:tid 189836] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/jga.php"] [unique_id "amu06-WE7BvPuUzLJ991-gAAAOQ"]
[Thu Jul 30 15:32:43.900809 2026] [security2:error] [pid 189611:tid 189836] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/jga.php"] [unique_id "amu06-WE7BvPuUzLJ991-gAAAOQ"]
[Thu Jul 30 15:32:44.037725 2026] [security2:error] [pid 189611:tid 189769] [client 172.213.232.128:33121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/colors/flower.php"] [unique_id "amu07OWE7BvPuUzLJ992AwAAAKE"]
[Thu Jul 30 15:32:44.337514 2026] [core:notice] [pid 189611:tid 189848] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:44.533874 2026] [security2:error] [pid 189611:tid 189783] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/666.php"] [unique_id "amu07OWE7BvPuUzLJ992FQAAAK8"]
[Thu Jul 30 15:32:44.534005 2026] [security2:error] [pid 189611:tid 189783] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/666.php"] [unique_id "amu07OWE7BvPuUzLJ992FQAAAK8"]
[Thu Jul 30 15:32:44.689574 2026] [security2:error] [pid 189611:tid 189819] [client 57.141.0.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu07OWE7BvPuUzLJ992BgAAANM"]
[Thu Jul 30 15:32:44.806890 2026] [core:notice] [pid 189611:tid 189830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:44.829972 2026] [security2:error] [pid 189611:tid 189867] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu07OWE7BvPuUzLJ992CQAAAQM"]
[Thu Jul 30 15:32:44.976974 2026] [security2:error] [pid 189611:tid 189852] [client 20.52.125.110:12968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/json.php"] [unique_id "amu07OWE7BvPuUzLJ992GwAAAPQ"]
[Thu Jul 30 15:32:45.018918 2026] [security2:error] [pid 189611:tid 189744] [client 20.100.187.246:1866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amu07eWE7BvPuUzLJ992HwAAAIg"]
[Thu Jul 30 15:32:45.023771 2026] [security2:error] [pid 189611:tid 189747] [client 172.213.232.128:29019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/css/colors/xleet.php"] [unique_id "amu07eWE7BvPuUzLJ992IAAAAIs"]
[Thu Jul 30 15:32:45.120864 2026] [security2:error] [pid 189611:tid 189766] [client 172.213.17.107:20179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/ops.php"] [unique_id "amu07eWE7BvPuUzLJ992JQAAAJ4"]
[Thu Jul 30 15:32:45.120960 2026] [security2:error] [pid 189611:tid 189766] [client 172.213.17.107:20179] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/ops.php"] [unique_id "amu07eWE7BvPuUzLJ992JQAAAJ4"]
[Thu Jul 30 15:32:45.123378 2026] [security2:error] [pid 189611:tid 189775] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/htaccess.php"] [unique_id "amu07eWE7BvPuUzLJ992JgAAAKc"]
[Thu Jul 30 15:32:45.123454 2026] [security2:error] [pid 189611:tid 189775] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/htaccess.php"] [unique_id "amu07eWE7BvPuUzLJ992JgAAAKc"]
[Thu Jul 30 15:32:45.179125 2026] [security2:error] [pid 189611:tid 189770] [client 49.51.183.220:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "safaratraveltours.com"] [uri "/index.php"] [unique_id "amu06-WE7BvPuUzLJ9917QAAAKI"]
[Thu Jul 30 15:32:45.685881 2026] [security2:error] [pid 189611:tid 189778] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/m.php"] [unique_id "amu07eWE7BvPuUzLJ992MgAAAKo"]
[Thu Jul 30 15:32:45.685996 2026] [security2:error] [pid 189611:tid 189778] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/m.php"] [unique_id "amu07eWE7BvPuUzLJ992MgAAAKo"]
[Thu Jul 30 15:32:45.851646 2026] [security2:error] [pid 189611:tid 189745] [client 127.0.0.1:42608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu07eWE7BvPuUzLJ992NQAAAIk"]
[Thu Jul 30 15:32:45.851696 2026] [security2:error] [pid 189611:tid 189833] [client 127.0.0.1:42606] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ciunews.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu07eWE7BvPuUzLJ992NAAAAOE"]
[Thu Jul 30 15:32:45.851770 2026] [security2:error] [pid 189611:tid 189835] [client 74.7.175.149:50370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ciunews.com"] [uri "/robots.txt"] [unique_id "amu07eWE7BvPuUzLJ992MwAA4xI"]
[Thu Jul 30 15:32:45.941815 2026] [security2:error] [pid 189611:tid 189785] [client 20.52.125.110:12979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/mini.php"] [unique_id "amu07eWE7BvPuUzLJ992NgAAALE"]
[Thu Jul 30 15:32:46.280567 2026] [security2:error] [pid 189611:tid 189763] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/file.php"] [unique_id "amu07uWE7BvPuUzLJ992RgAAAJs"]
[Thu Jul 30 15:32:46.280669 2026] [security2:error] [pid 189611:tid 189763] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/file.php"] [unique_id "amu07uWE7BvPuUzLJ992RgAAAJs"]
[Thu Jul 30 15:32:46.302632 2026] [security2:error] [pid 189611:tid 189799] [client 172.213.232.128:27710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/flower.php"] [unique_id "amu07uWE7BvPuUzLJ992RwAAAL8"]
[Thu Jul 30 15:32:46.588300 2026] [security2:error] [pid 189611:tid 189808] [client 162.219.176.3:48286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amu07uWE7BvPuUzLJ992TgAAAMg"]
[Thu Jul 30 15:32:46.588394 2026] [security2:error] [pid 189611:tid 189808] [client 162.219.176.3:48286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ajakholding.net"] [uri "/xmlrpc.php"] [unique_id "amu07uWE7BvPuUzLJ992TgAAAMg"]
[Thu Jul 30 15:32:46.822645 2026] [security2:error] [pid 189611:tid 189798] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/.dj/index.php"] [unique_id "amu07uWE7BvPuUzLJ992VQAAAL4"]
[Thu Jul 30 15:32:46.822755 2026] [security2:error] [pid 189611:tid 189798] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/.dj/index.php"] [unique_id "amu07uWE7BvPuUzLJ992VQAAAL4"]
[Thu Jul 30 15:32:47.001082 2026] [core:notice] [pid 189611:tid 189789] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:47.132248 2026] [security2:error] [pid 189611:tid 189751] [client 172.213.232.128:46598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/maint/autoload_classmap.php"] [unique_id "amu07-WE7BvPuUzLJ992XwAAAI8"]
[Thu Jul 30 15:32:47.142545 2026] [security2:error] [pid 189611:tid 189771] [client 14.191.31.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu07uWE7BvPuUzLJ992WgAAAKM"]
[Thu Jul 30 15:32:47.183571 2026] [security2:error] [pid 189611:tid 189845] [client 162.219.176.3:48296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu07-WE7BvPuUzLJ992YwAAAO0"]
[Thu Jul 30 15:32:47.183679 2026] [security2:error] [pid 189611:tid 189845] [client 162.219.176.3:48296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu07-WE7BvPuUzLJ992YwAAAO0"]
[Thu Jul 30 15:32:47.332541 2026] [security2:error] [pid 189611:tid 189741] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amu07-WE7BvPuUzLJ992ZwAAAIU"]
[Thu Jul 30 15:32:47.332653 2026] [security2:error] [pid 189611:tid 189741] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amu07-WE7BvPuUzLJ992ZwAAAIU"]
[Thu Jul 30 15:32:47.443880 2026] [security2:error] [pid 189611:tid 189844] [client 20.100.187.246:29125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amu07-WE7BvPuUzLJ992aQAAAOw"]
[Thu Jul 30 15:32:47.455475 2026] [security2:error] [pid 189611:tid 189832] [client 172.237.109.114:50734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu07uWE7BvPuUzLJ992VgAAAOA"]
[Thu Jul 30 15:32:47.749259 2026] [security2:error] [pid 189611:tid 189778] [client 172.213.17.107:29415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/mac.php"] [unique_id "amu07-WE7BvPuUzLJ992cQAAAKo"]
[Thu Jul 30 15:32:47.749366 2026] [security2:error] [pid 189611:tid 189778] [client 172.213.17.107:29415] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/mac.php"] [unique_id "amu07-WE7BvPuUzLJ992cQAAAKo"]
[Thu Jul 30 15:32:47.842092 2026] [security2:error] [pid 189611:tid 189745] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/pages.php"] [unique_id "amu07-WE7BvPuUzLJ992dQAAAIk"]
[Thu Jul 30 15:32:47.842220 2026] [security2:error] [pid 189611:tid 189745] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/pages.php"] [unique_id "amu07-WE7BvPuUzLJ992dQAAAIk"]
[Thu Jul 30 15:32:47.950143 2026] [security2:error] [pid 189611:tid 189865] [client 172.213.232.128:35157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/maint/flower.php"] [unique_id "amu07-WE7BvPuUzLJ992dgAAAQE"]
[Thu Jul 30 15:32:47.992242 2026] [security2:error] [pid 189611:tid 189836] [client 172.237.109.114:22766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/graphql.php"] [unique_id "amu07-WE7BvPuUzLJ992fgAAAOQ"]
[Thu Jul 30 15:32:48.135043 2026] [security2:error] [pid 189611:tid 189835] [client 20.100.187.246:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amu08OWE7BvPuUzLJ992hQAAAOM"]
[Thu Jul 30 15:32:48.392448 2026] [security2:error] [pid 189611:tid 189763] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/adminfuns.php"] [unique_id "amu08OWE7BvPuUzLJ992jAAAAJs"]
[Thu Jul 30 15:32:48.392585 2026] [security2:error] [pid 189611:tid 189763] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/adminfuns.php"] [unique_id "amu08OWE7BvPuUzLJ992jAAAAJs"]
[Thu Jul 30 15:32:48.579013 2026] [security2:error] [pid 189611:tid 189813] [client 172.237.109.114:32980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu07-WE7BvPuUzLJ992egAAAM0"]
[Thu Jul 30 15:32:48.580337 2026] [security2:error] [pid 189611:tid 189785] [client 172.237.109.114:41427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu07-WE7BvPuUzLJ992dwAAALE"]
[Thu Jul 30 15:32:48.591120 2026] [security2:error] [pid 189611:tid 189794] [client 172.237.109.114:45985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu07-WE7BvPuUzLJ992eAAAALo"]
[Thu Jul 30 15:32:48.643911 2026] [security2:error] [pid 189611:tid 189842] [client 172.237.109.114:6692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu07-WE7BvPuUzLJ992eQAAAOo"]
[Thu Jul 30 15:32:48.658869 2026] [security2:error] [pid 189611:tid 189854] [client 172.237.109.114:65520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu07-WE7BvPuUzLJ992ewAAAPY"]
[Thu Jul 30 15:32:48.668255 2026] [security2:error] [pid 189611:tid 189742] [client 172.237.109.114:63145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu07-WE7BvPuUzLJ992fAAAAIY"]
[Thu Jul 30 15:32:48.691848 2026] [security2:error] [pid 189611:tid 189753] [client 172.237.109.114:12304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08OWE7BvPuUzLJ992gQAAAJE"]
[Thu Jul 30 15:32:48.692781 2026] [security2:error] [pid 189611:tid 189809] [client 172.237.109.114:58107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu07-WE7BvPuUzLJ992fwAAAMk"]
[Thu Jul 30 15:32:48.703346 2026] [security2:error] [pid 189611:tid 189787] [client 172.237.109.114:47681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu07-WE7BvPuUzLJ992fQAAALM"]
[Thu Jul 30 15:32:48.725436 2026] [core:notice] [pid 189611:tid 189754] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:48.730024 2026] [security2:error] [pid 189611:tid 189754] [client 66.249.79.1:36429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/Publika/article/view/8549/3342"] [unique_id "amu08OWE7BvPuUzLJ992lAAAAJI"]
[Thu Jul 30 15:32:48.732201 2026] [security2:error] [pid 189611:tid 189866] [client 172.237.109.114:35258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08OWE7BvPuUzLJ992gAAAAQI"]
[Thu Jul 30 15:32:48.742661 2026] [security2:error] [pid 189611:tid 189847] [client 52.189.212.127:65049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amu08OWE7BvPuUzLJ992lQAAAO8"]
[Thu Jul 30 15:32:48.780155 2026] [security2:error] [pid 189611:tid 189850] [client 52.189.212.127:65056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/plugins/userfuns.php"] [unique_id "amu08OWE7BvPuUzLJ992mQAAAPI"]
[Thu Jul 30 15:32:48.854814 2026] [security2:error] [pid 189611:tid 189757] [client 20.52.125.110:12982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/chosen.php"] [unique_id "amu08OWE7BvPuUzLJ992mwAAAJU"]
[Thu Jul 30 15:32:48.963964 2026] [security2:error] [pid 189611:tid 189789] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/aa.php"] [unique_id "amu08OWE7BvPuUzLJ992nAAAALU"]
[Thu Jul 30 15:32:48.964095 2026] [security2:error] [pid 189611:tid 189789] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/aa.php"] [unique_id "amu08OWE7BvPuUzLJ992nAAAALU"]
[Thu Jul 30 15:32:49.550069 2026] [security2:error] [pid 189611:tid 189806] [client 172.237.109.114:46201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08OWE7BvPuUzLJ992nQAAAMY"]
[Thu Jul 30 15:32:49.552960 2026] [security2:error] [pid 189611:tid 189834] [client 172.237.109.114:32981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08OWE7BvPuUzLJ992nwAAAOI"]
[Thu Jul 30 15:32:49.555753 2026] [security2:error] [pid 189611:tid 189818] [client 172.237.109.114:10141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08OWE7BvPuUzLJ992ngAAANI"]
[Thu Jul 30 15:32:49.565394 2026] [security2:error] [pid 189611:tid 189831] [client 172.237.109.114:39381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08OWE7BvPuUzLJ992owAAAN8"]
[Thu Jul 30 15:32:49.567179 2026] [security2:error] [pid 189611:tid 189771] [client 172.237.109.114:24639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08OWE7BvPuUzLJ992ogAAAKM"]
[Thu Jul 30 15:32:49.567915 2026] [security2:error] [pid 189611:tid 189853] [client 172.202.44.182:63972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/inputs.php"] [unique_id "amu08eWE7BvPuUzLJ992sgAAAPU"]
[Thu Jul 30 15:32:49.568756 2026] [proxy:error] [pid 189611:tid 189777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:49.568812 2026] [proxy_http:error] [pid 189611:tid 189777] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:49.569846 2026] [proxy:error] [pid 189611:tid 189777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:49.569898 2026] [proxy_http:error] [pid 189611:tid 189777] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:49.569988 2026] [security2:error] [pid 189611:tid 189777] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu08eWE7BvPuUzLJ992sQAAAKk"]
[Thu Jul 30 15:32:49.571100 2026] [security2:error] [pid 189611:tid 189775] [client 172.237.109.114:13519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08OWE7BvPuUzLJ992oAAAAKc"]
[Thu Jul 30 15:32:49.591428 2026] [security2:error] [pid 189611:tid 189751] [client 172.237.109.114:65334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08OWE7BvPuUzLJ992oQAAAI8"]
[Thu Jul 30 15:32:49.609745 2026] [security2:error] [pid 189611:tid 189791] [client 20.52.125.110:12932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/kj.php"] [unique_id "amu08eWE7BvPuUzLJ992swAAALc"]
[Thu Jul 30 15:32:49.612373 2026] [security2:error] [pid 189611:tid 189805] [client 172.237.109.114:51065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08eWE7BvPuUzLJ992pQAAAMU"]
[Thu Jul 30 15:32:49.612641 2026] [security2:error] [pid 189611:tid 189856] [client 172.237.109.114:31575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu08eWE7BvPuUzLJ992pAAAAPg"]
[Thu Jul 30 15:32:49.657227 2026] [core:error] [pid 189611:tid 189800] [client 172.213.17.107:20173] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:32:49.657253 2026] [core:error] [pid 189611:tid 189800] [client 172.213.17.107:20173] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:32:49.657354 2026] [security2:error] [pid 189611:tid 189800] [client 172.213.17.107:20173] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "chicago-mfg.com"] [uri "/index.php"] [unique_id "amu08eWE7BvPuUzLJ992twAAAMA"]
[Thu Jul 30 15:32:49.713887 2026] [security2:error] [pid 189611:tid 189799] [client 172.213.232.128:27681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/maint/xleet.php"] [unique_id "amu08eWE7BvPuUzLJ992uQAAAL8"]
[Thu Jul 30 15:32:50.173379 2026] [security2:error] [pid 189611:tid 189817] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/classwithtostring.php"] [unique_id "amu08uWE7BvPuUzLJ992wwAAANE"]
[Thu Jul 30 15:32:50.173488 2026] [security2:error] [pid 189611:tid 189817] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/classwithtostring.php"] [unique_id "amu08uWE7BvPuUzLJ992wwAAANE"]
[Thu Jul 30 15:32:50.494868 2026] [security2:error] [pid 189611:tid 189782] [client 172.202.44.182:22056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/index.php"] [unique_id "amu08uWE7BvPuUzLJ992zQAAAK4"]
[Thu Jul 30 15:32:50.537301 2026] [security2:error] [pid 189611:tid 189762] [client 20.52.125.110:12957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/wp-files.php"] [unique_id "amu08uWE7BvPuUzLJ992zgAAAJo"]
[Thu Jul 30 15:32:50.639195 2026] [security2:error] [pid 189611:tid 189761] [client 172.213.232.128:46618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "amu08uWE7BvPuUzLJ992zwAAAJk"]
[Thu Jul 30 15:32:50.780509 2026] [security2:error] [pid 189611:tid 189748] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/about.php"] [unique_id "amu08uWE7BvPuUzLJ9920wAAAIw"]
[Thu Jul 30 15:32:50.780650 2026] [security2:error] [pid 189611:tid 189748] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/about.php"] [unique_id "amu08uWE7BvPuUzLJ9920wAAAIw"]
[Thu Jul 30 15:32:51.271508 2026] [security2:error] [pid 189611:tid 189764] [client 20.52.125.110:12691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/wp-setup.php"] [unique_id "amu08-WE7BvPuUzLJ9923gAAAJw"]
[Thu Jul 30 15:32:51.280935 2026] [security2:error] [pid 189611:tid 189665] [remote 216.73.216.51:20928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu08-WE7BvPuUzLJ9923wAA7jU"]
[Thu Jul 30 15:32:51.393198 2026] [security2:error] [pid 189611:tid 189770] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/goods.php"] [unique_id "amu08-WE7BvPuUzLJ9925QAAAKI"]
[Thu Jul 30 15:32:51.393282 2026] [security2:error] [pid 189611:tid 189770] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/goods.php"] [unique_id "amu08-WE7BvPuUzLJ9925QAAAKI"]
[Thu Jul 30 15:32:52.005419 2026] [security2:error] [pid 189611:tid 189800] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/php8.php"] [unique_id "amu09OWE7BvPuUzLJ9928QAAAMA"]
[Thu Jul 30 15:32:52.005515 2026] [security2:error] [pid 189611:tid 189800] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/php8.php"] [unique_id "amu09OWE7BvPuUzLJ9928QAAAMA"]
[Thu Jul 30 15:32:52.058289 2026] [core:notice] [pid 189611:tid 189673] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:52.061896 2026] [security2:error] [pid 189611:tid 189756] [client 66.249.74.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/3/3"] [unique_id "amu09OWE7BvPuUzLJ9928gAAlD0"]
[Thu Jul 30 15:32:52.201968 2026] [security2:error] [pid 189611:tid 189790] [client 20.52.125.110:12683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/defaults.php"] [unique_id "amu09OWE7BvPuUzLJ9928wAAALY"]
[Thu Jul 30 15:32:52.268421 2026] [security2:error] [pid 189611:tid 189827] [client 172.213.232.128:47636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/network/flower.php"] [unique_id "amu09OWE7BvPuUzLJ9929AAAANs"]
[Thu Jul 30 15:32:52.625946 2026] [security2:error] [pid 189611:tid 189861] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/info.php"] [unique_id "amu09OWE7BvPuUzLJ992_gAAAP0"]
[Thu Jul 30 15:32:52.626086 2026] [security2:error] [pid 189611:tid 189861] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/info.php"] [unique_id "amu09OWE7BvPuUzLJ992_gAAAP0"]
[Thu Jul 30 15:32:53.260915 2026] [security2:error] [pid 189611:tid 189773] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/class-t.api.php"] [unique_id "amu09eWE7BvPuUzLJ993CwAAAKU"]
[Thu Jul 30 15:32:53.261039 2026] [security2:error] [pid 189611:tid 189773] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/class-t.api.php"] [unique_id "amu09eWE7BvPuUzLJ993CwAAAKU"]
[Thu Jul 30 15:32:53.413998 2026] [security2:error] [pid 189611:tid 189782] [client 172.213.17.107:20188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/pucci.php"] [unique_id "amu09eWE7BvPuUzLJ993EQAAAK4"]
[Thu Jul 30 15:32:53.414119 2026] [security2:error] [pid 189611:tid 189782] [client 172.213.17.107:20188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/pucci.php"] [unique_id "amu09eWE7BvPuUzLJ993EQAAAK4"]
[Thu Jul 30 15:32:53.435411 2026] [security2:error] [pid 189611:tid 189813] [client 172.213.232.128:46627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/network/xleet.php"] [unique_id "amu09eWE7BvPuUzLJ993EgAAAM0"]
[Thu Jul 30 15:32:53.818116 2026] [security2:error] [pid 189611:tid 189743] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/simple.php"] [unique_id "amu09eWE7BvPuUzLJ993GQAAAIc"]
[Thu Jul 30 15:32:53.818238 2026] [security2:error] [pid 189611:tid 189743] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/simple.php"] [unique_id "amu09eWE7BvPuUzLJ993GQAAAIc"]
[Thu Jul 30 15:32:54.065495 2026] [security2:error] [pid 189611:tid 189774] [client 172.213.232.128:47654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/user/autoload_classmap.php"] [unique_id "amu09uWE7BvPuUzLJ993KAAAAKY"]
[Thu Jul 30 15:32:54.382762 2026] [security2:error] [pid 189611:tid 189746] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/ioxi-o.php"] [unique_id "amu09uWE7BvPuUzLJ993KgAAAIo"]
[Thu Jul 30 15:32:54.382873 2026] [security2:error] [pid 189611:tid 189746] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/ioxi-o.php"] [unique_id "amu09uWE7BvPuUzLJ993KgAAAIo"]
[Thu Jul 30 15:32:54.444039 2026] [security2:error] [pid 189611:tid 189789] [client 172.237.109.114:63831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu09eWE7BvPuUzLJ993IQAAALU"]
[Thu Jul 30 15:32:54.583133 2026] [security2:error] [pid 189611:tid 189751] [client 172.213.17.107:14393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/wp-admin/js/index.php"] [unique_id "amu09uWE7BvPuUzLJ993NgAAAI8"]
[Thu Jul 30 15:32:54.583236 2026] [security2:error] [pid 189611:tid 189751] [client 172.213.17.107:14393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/wp-admin/js/index.php"] [unique_id "amu09uWE7BvPuUzLJ993NgAAAI8"]
[Thu Jul 30 15:32:54.736386 2026] [security2:error] [pid 189611:tid 189856] [client 172.213.232.128:36357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/user/flower.php"] [unique_id "amu09uWE7BvPuUzLJ993NwAAAPg"]
[Thu Jul 30 15:32:54.998185 2026] [proxy:error] [pid 189611:tid 189786] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:54.998254 2026] [proxy_http:error] [pid 189611:tid 189786] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:54.998828 2026] [proxy:error] [pid 189611:tid 189786] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:32:54.998874 2026] [proxy_http:error] [pid 189611:tid 189786] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:32:54.998951 2026] [security2:error] [pid 189611:tid 189786] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu09uWE7BvPuUzLJ993QAAAALI"]
[Thu Jul 30 15:32:55.293013 2026] [security2:error] [pid 189611:tid 189859] [client 193.47.62.167:60816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bss.nyx.temporary.site"] [uri "/index.php"] [unique_id "amu09eWE7BvPuUzLJ993CgAAAPs"]
[Thu Jul 30 15:32:55.351317 2026] [security2:error] [pid 189611:tid 189835] [client 172.213.232.128:47648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/user/xleet.php"] [unique_id "amu09-WE7BvPuUzLJ993SQAAAOM"]
[Thu Jul 30 15:32:55.598264 2026] [security2:error] [pid 189611:tid 189821] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp.php"] [unique_id "amu09-WE7BvPuUzLJ993UAAAANU"]
[Thu Jul 30 15:32:55.598430 2026] [security2:error] [pid 189611:tid 189821] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp.php"] [unique_id "amu09-WE7BvPuUzLJ993UAAAANU"]
[Thu Jul 30 15:32:55.958758 2026] [security2:error] [pid 189611:tid 189755] [client 20.52.125.110:12959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/gtc.php"] [unique_id "amu09-WE7BvPuUzLJ993VgAAAJM"]
[Thu Jul 30 15:32:56.099324 2026] [security2:error] [pid 189611:tid 189768] [client 172.213.17.107:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/8.php"] [unique_id "amu0-OWE7BvPuUzLJ993WwAAAKA"]
[Thu Jul 30 15:32:56.099416 2026] [security2:error] [pid 189611:tid 189768] [client 172.213.17.107:7233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/8.php"] [unique_id "amu0-OWE7BvPuUzLJ993WwAAAKA"]
[Thu Jul 30 15:32:56.109357 2026] [security2:error] [pid 189611:tid 189772] [client 52.189.212.127:49537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/IXR/index.php"] [unique_id "amu0-OWE7BvPuUzLJ993XAAAAKQ"]
[Thu Jul 30 15:32:56.147414 2026] [security2:error] [pid 189611:tid 189744] [client 52.189.212.127:49547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/themes/userfuns.php"] [unique_id "amu0-OWE7BvPuUzLJ993XQAAAIg"]
[Thu Jul 30 15:32:56.184223 2026] [security2:error] [pid 189611:tid 189825] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/file2.php"] [unique_id "amu0-OWE7BvPuUzLJ993YQAAANk"]
[Thu Jul 30 15:32:56.184327 2026] [security2:error] [pid 189611:tid 189825] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/file2.php"] [unique_id "amu0-OWE7BvPuUzLJ993YQAAANk"]
[Thu Jul 30 15:32:56.565429 2026] [security2:error] [pid 189611:tid 189770] [client 20.52.125.110:12698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/import.php"] [unique_id "amu0-OWE7BvPuUzLJ993aAAAAKI"]
[Thu Jul 30 15:32:56.607847 2026] [core:notice] [pid 189611:tid 189868] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:56.772713 2026] [security2:error] [pid 189611:tid 189775] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/images/class-config.php"] [unique_id "amu0-OWE7BvPuUzLJ993cAAAAKc"]
[Thu Jul 30 15:32:56.772806 2026] [security2:error] [pid 189611:tid 189775] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/images/class-config.php"] [unique_id "amu0-OWE7BvPuUzLJ993cAAAAKc"]
[Thu Jul 30 15:32:57.077585 2026] [security2:error] [pid 189611:tid 189826] [client 172.213.17.107:14369] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "chicago-mfg.com"] [uri "/1.php"] [unique_id "amu0-eWE7BvPuUzLJ993dAAAANo"]
[Thu Jul 30 15:32:57.077695 2026] [security2:error] [pid 189611:tid 189826] [client 172.213.17.107:14369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/1.php"] [unique_id "amu0-eWE7BvPuUzLJ993dAAAANo"]
[Thu Jul 30 15:32:57.077774 2026] [security2:error] [pid 189611:tid 189826] [client 172.213.17.107:14369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/1.php"] [unique_id "amu0-eWE7BvPuUzLJ993dAAAANo"]
[Thu Jul 30 15:32:57.099519 2026] [core:notice] [pid 189611:tid 189800] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:57.201156 2026] [security2:error] [pid 189611:tid 189774] [client 172.202.44.182:19089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/network/index.php"] [unique_id "amu0-eWE7BvPuUzLJ993fQAAAKY"]
[Thu Jul 30 15:32:57.279722 2026] [security2:error] [pid 189611:tid 189752] [client 20.52.125.110:12983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/lufix.php"] [unique_id "amu0-eWE7BvPuUzLJ993fgAAAJA"]
[Thu Jul 30 15:32:57.334299 2026] [security2:error] [pid 189611:tid 189865] [client 20.9.4.9:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/1.php"] [unique_id "amu0-eWE7BvPuUzLJ993gAAAAQE"]
[Thu Jul 30 15:32:57.334404 2026] [security2:error] [pid 189611:tid 189865] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/1.php"] [unique_id "amu0-eWE7BvPuUzLJ993gAAAAQE"]
[Thu Jul 30 15:32:57.334492 2026] [security2:error] [pid 189611:tid 189865] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/1.php"] [unique_id "amu0-eWE7BvPuUzLJ993gAAAAQE"]
[Thu Jul 30 15:32:57.385273 2026] [security2:error] [pid 189611:tid 189778] [client 172.213.232.128:27668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-admin/xleet.php"] [unique_id "amu0-eWE7BvPuUzLJ993gQAAAKo"]
[Thu Jul 30 15:32:57.567369 2026] [core:notice] [pid 189611:tid 189803] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:57.952414 2026] [security2:error] [pid 189611:tid 189782] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/222.php"] [unique_id "amu0-eWE7BvPuUzLJ993jQAAAK4"]
[Thu Jul 30 15:32:57.952521 2026] [security2:error] [pid 189611:tid 189782] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/222.php"] [unique_id "amu0-eWE7BvPuUzLJ993jQAAAK4"]
[Thu Jul 30 15:32:57.976264 2026] [security2:error] [pid 189611:tid 189763] [client 172.213.232.128:36411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.232.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mydubaidesertsafari.com"] [uri "/wp-config-sample.php"] [unique_id "amu0-eWE7BvPuUzLJ993jgAAAJs"]
[Thu Jul 30 15:32:57.978990 2026] [security2:error] [pid 189611:tid 189836] [client 20.52.125.110:12954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/Geforce.php"] [unique_id "amu0-eWE7BvPuUzLJ993jwAAAOQ"]
[Thu Jul 30 15:32:58.022187 2026] [core:notice] [pid 189611:tid 189855] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:58.373859 2026] [core:notice] [pid 189611:tid 189721] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:58.376929 2026] [security2:error] [pid 189611:tid 189847] [client 66.249.74.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/102/102"] [unique_id "amu0-uWE7BvPuUzLJ993mwAA720"]
[Thu Jul 30 15:32:58.597725 2026] [security2:error] [pid 189611:tid 189744] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/themes.php"] [unique_id "amu0-uWE7BvPuUzLJ993ngAAAIg"]
[Thu Jul 30 15:32:58.597840 2026] [security2:error] [pid 189611:tid 189744] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/themes.php"] [unique_id "amu0-uWE7BvPuUzLJ993ngAAAIg"]
[Thu Jul 30 15:32:59.101542 2026] [security2:error] [pid 189611:tid 189747] [client 172.213.17.107:19665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/wp-content/admin.php"] [unique_id "amu0--WE7BvPuUzLJ993pgAAAIs"]
[Thu Jul 30 15:32:59.101647 2026] [security2:error] [pid 189611:tid 189747] [client 172.213.17.107:19665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/wp-content/admin.php"] [unique_id "amu0--WE7BvPuUzLJ993pgAAAIs"]
[Thu Jul 30 15:32:59.176489 2026] [security2:error] [pid 189611:tid 189784] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/admin.php"] [unique_id "amu0--WE7BvPuUzLJ993qgAAALA"]
[Thu Jul 30 15:32:59.176574 2026] [security2:error] [pid 189611:tid 189784] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/admin.php"] [unique_id "amu0--WE7BvPuUzLJ993qgAAALA"]
[Thu Jul 30 15:32:59.494459 2026] [core:notice] [pid 189611:tid 189844] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:32:59.791092 2026] [security2:error] [pid 189611:tid 189793] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/dropdown.php"] [unique_id "amu0--WE7BvPuUzLJ993uwAAALk"]
[Thu Jul 30 15:32:59.791202 2026] [security2:error] [pid 189611:tid 189793] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/dropdown.php"] [unique_id "amu0--WE7BvPuUzLJ993uwAAALk"]
[Thu Jul 30 15:33:00.197009 2026] [security2:error] [pid 189611:tid 189826] [client 20.100.187.246:8595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/themes/about.php"] [unique_id "amu0_OWE7BvPuUzLJ993xAAAANo"]
[Thu Jul 30 15:33:00.886749 2026] [security2:error] [pid 189611:tid 189760] [client 172.213.17.107:24893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/wp-content/themes/index.php"] [unique_id "amu0_OWE7BvPuUzLJ9931QAAAJg"]
[Thu Jul 30 15:33:00.886904 2026] [security2:error] [pid 189611:tid 189760] [client 172.213.17.107:24893] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/wp-content/themes/index.php"] [unique_id "amu0_OWE7BvPuUzLJ9931QAAAJg"]
[Thu Jul 30 15:33:01.066667 2026] [security2:error] [pid 189611:tid 189776] [client 66.249.68.195:64507] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "website-40d88156.sby.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amu0_eWE7BvPuUzLJ9932QAAAKg"]
[Thu Jul 30 15:33:01.680235 2026] [security2:error] [pid 189611:tid 189742] [client 20.100.187.246:29149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amu0_eWE7BvPuUzLJ9936wAAAIY"]
[Thu Jul 30 15:33:01.751174 2026] [security2:error] [pid 189611:tid 189850] [client 52.189.212.127:50210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-admin/css/about.php"] [unique_id "amu0_eWE7BvPuUzLJ9937QAAAPI"]
[Thu Jul 30 15:33:01.923046 2026] [security2:error] [pid 189611:tid 189855] [client 2a03:2880:f800:44:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0_eWE7BvPuUzLJ9934AAA9wA"]
[Thu Jul 30 15:33:01.960869 2026] [security2:error] [pid 189611:tid 189861] [client 172.202.44.182:19130] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hoki188win.com"] [uri "/wp-content/1.php"] [unique_id "amu0_eWE7BvPuUzLJ993-AAAAP0"]
[Thu Jul 30 15:33:01.961017 2026] [security2:error] [pid 189611:tid 189861] [client 172.202.44.182:19130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/1.php"] [unique_id "amu0_eWE7BvPuUzLJ993-AAAAP0"]
[Thu Jul 30 15:33:02.091369 2026] [security2:error] [pid 189611:tid 189820] [client 85.204.70.116:52168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/wp-includes/wlwmanifest.xml"] [unique_id "amu0_uWE7BvPuUzLJ993-gAAANQ"]
[Thu Jul 30 15:33:02.324754 2026] [security2:error] [pid 189611:tid 189839] [client 172.213.17.107:7710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/222.php"] [unique_id "amu0_uWE7BvPuUzLJ993_gAAAOc"]
[Thu Jul 30 15:33:02.324841 2026] [security2:error] [pid 189611:tid 189839] [client 172.213.17.107:7710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/222.php"] [unique_id "amu0_uWE7BvPuUzLJ993_gAAAOc"]
[Thu Jul 30 15:33:02.503694 2026] [security2:error] [pid 189611:tid 189817] [client 85.204.70.116:52174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/blog/wp-includes/wlwmanifest.xml"] [unique_id "amu0_uWE7BvPuUzLJ994BwAAANE"]
[Thu Jul 30 15:33:02.646360 2026] [security2:error] [pid 189611:tid 189832] [client 2a03:2880:f800:40:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu0_eWE7BvPuUzLJ993-QAA4AI"]
[Thu Jul 30 15:33:02.795226 2026] [security2:error] [pid 189611:tid 189857] [client 85.204.70.116:57946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/web/wp-includes/wlwmanifest.xml"] [unique_id "amu0_uWE7BvPuUzLJ994CgAAAPk"]
[Thu Jul 30 15:33:03.076536 2026] [security2:error] [pid 189611:tid 189804] [client 85.204.70.116:38730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amu0_-WE7BvPuUzLJ994GAAAAMQ"]
[Thu Jul 30 15:33:03.125218 2026] [security2:error] [pid 189611:tid 189769] [client 172.202.44.182:63979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/plugin.php"] [unique_id "amu0_-WE7BvPuUzLJ994GQAAAKE"]
[Thu Jul 30 15:33:03.336375 2026] [security2:error] [pid 189611:tid 189762] [client 85.204.70.116:38736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/website/wp-includes/wlwmanifest.xml"] [unique_id "amu0_-WE7BvPuUzLJ994HgAAAJo"]
[Thu Jul 30 15:33:03.468591 2026] [security2:error] [pid 189611:tid 189851] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/inputs.php"] [unique_id "amu0_-WE7BvPuUzLJ994IwAAAPM"]
[Thu Jul 30 15:33:03.468704 2026] [security2:error] [pid 189611:tid 189851] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/inputs.php"] [unique_id "amu0_-WE7BvPuUzLJ994IwAAAPM"]
[Thu Jul 30 15:33:03.517646 2026] [security2:error] [pid 189611:tid 189821] [client 172.237.109.114:40879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0_uWE7BvPuUzLJ994FgAAANU"]
[Thu Jul 30 15:33:03.598284 2026] [security2:error] [pid 189611:tid 189768] [client 85.204.70.116:27106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/wp/wp-includes/wlwmanifest.xml"] [unique_id "amu0_-WE7BvPuUzLJ994KQAAAKA"]
[Thu Jul 30 15:33:03.598401 2026] [security2:error] [pid 189611:tid 189753] [client 172.237.109.114:37312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0_-WE7BvPuUzLJ994FwAAAJE"]
[Thu Jul 30 15:33:03.678426 2026] [security2:error] [pid 189611:tid 189764] [client 20.100.187.246:4029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/images/about.php"] [unique_id "amu0_-WE7BvPuUzLJ994KgAAAJw"]
[Thu Jul 30 15:33:03.882632 2026] [security2:error] [pid 189611:tid 189765] [client 85.204.70.116:38762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/news/wp-includes/wlwmanifest.xml"] [unique_id "amu0_-WE7BvPuUzLJ994KwAAAJ0"]
[Thu Jul 30 15:33:04.082137 2026] [security2:error] [pid 189611:tid 189844] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/100.php"] [unique_id "amu1AOWE7BvPuUzLJ994PgAAAOw"]
[Thu Jul 30 15:33:04.082260 2026] [security2:error] [pid 189611:tid 189844] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/100.php"] [unique_id "amu1AOWE7BvPuUzLJ994PgAAAOw"]
[Thu Jul 30 15:33:04.153210 2026] [security2:error] [pid 189611:tid 189790] [client 85.204.70.116:7633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/2018/wp-includes/wlwmanifest.xml"] [unique_id "amu1AOWE7BvPuUzLJ994PwAAALY"]
[Thu Jul 30 15:33:04.401658 2026] [security2:error] [pid 189611:tid 189777] [client 85.204.70.116:38770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/2019/wp-includes/wlwmanifest.xml"] [unique_id "amu1AOWE7BvPuUzLJ994QwAAAKk"]
[Thu Jul 30 15:33:04.575166 2026] [security2:error] [pid 189611:tid 189789] [client 172.237.109.114:33157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0_-WE7BvPuUzLJ994MgAAALU"]
[Thu Jul 30 15:33:04.575166 2026] [security2:error] [pid 189611:tid 189868] [client 172.237.109.114:28202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0_-WE7BvPuUzLJ994MQAAAQQ"]
[Thu Jul 30 15:33:04.580373 2026] [security2:error] [pid 189611:tid 189742] [client 172.237.109.114:48592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0_-WE7BvPuUzLJ994NAAAAIY"]
[Thu Jul 30 15:33:04.636151 2026] [security2:error] [pid 189611:tid 189850] [client 172.237.109.114:58620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0_-WE7BvPuUzLJ994NQAAAPI"]
[Thu Jul 30 15:33:04.637405 2026] [security2:error] [pid 189611:tid 189784] [client 172.237.109.114:56042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0_-WE7BvPuUzLJ994NgAAALA"]
[Thu Jul 30 15:33:04.655728 2026] [security2:error] [pid 189611:tid 189805] [client 172.237.109.114:25782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0_-WE7BvPuUzLJ994NwAAAMU"]
[Thu Jul 30 15:33:04.661937 2026] [security2:error] [pid 189611:tid 189786] [client 85.204.70.116:38780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/shop/wp-includes/wlwmanifest.xml"] [unique_id "amu1AOWE7BvPuUzLJ994SgAAALI"]
[Thu Jul 30 15:33:04.663552 2026] [security2:error] [pid 189611:tid 189815] [client 172.237.109.114:35527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu0_-WE7BvPuUzLJ994OAAAAM8"]
[Thu Jul 30 15:33:04.667785 2026] [security2:error] [pid 189611:tid 189828] [client 52.189.212.127:50551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-content/themes/about.php"] [unique_id "amu1AOWE7BvPuUzLJ994SwAAANw"]
[Thu Jul 30 15:33:04.692969 2026] [security2:error] [pid 189611:tid 189775] [client 172.237.109.114:50778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AOWE7BvPuUzLJ994PAAAAKc"]
[Thu Jul 30 15:33:04.701338 2026] [security2:error] [pid 189611:tid 189791] [client 172.237.109.114:38662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AOWE7BvPuUzLJ994OwAAALc"]
[Thu Jul 30 15:33:04.706122 2026] [security2:error] [pid 189611:tid 189803] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/autoload_classmap/function.php"] [unique_id "amu1AOWE7BvPuUzLJ994TAAAAMM"]
[Thu Jul 30 15:33:04.706211 2026] [security2:error] [pid 189611:tid 189803] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/autoload_classmap/function.php"] [unique_id "amu1AOWE7BvPuUzLJ994TAAAAMM"]
[Thu Jul 30 15:33:04.850170 2026] [security2:error] [pid 189611:tid 189797] [client 74.7.228.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-d982641d.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amu0_uWE7BvPuUzLJ994DwAAAL0"]
[Thu Jul 30 15:33:04.851211 2026] [security2:error] [pid 189611:tid 189826] [client 74.7.228.1:41808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.website-d982641d.dlr.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amu0_uWE7BvPuUzLJ994DQAA2g8"]
[Thu Jul 30 15:33:04.965144 2026] [security2:error] [pid 189611:tid 189782] [client 85.204.70.116:38792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amu1AOWE7BvPuUzLJ994UgAAAK4"]
[Thu Jul 30 15:33:04.972363 2026] [security2:error] [pid 189611:tid 189802] [client 172.237.109.114:16833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/v1/graphiql.php"] [unique_id "amu1AOWE7BvPuUzLJ994VQAAAMI"]
[Thu Jul 30 15:33:04.993891 2026] [security2:error] [pid 189611:tid 189787] [client 172.237.109.114:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/v1/graphql.php"] [unique_id "amu1AOWE7BvPuUzLJ994VwAAALM"]
[Thu Jul 30 15:33:05.216730 2026] [security2:error] [pid 189611:tid 189855] [client 20.100.187.246:9958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amu1AeWE7BvPuUzLJ994YQAAAPc"]
[Thu Jul 30 15:33:05.267747 2026] [security2:error] [pid 189611:tid 189851] [client 85.204.70.116:38808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/test/wp-includes/wlwmanifest.xml"] [unique_id "amu1AeWE7BvPuUzLJ994YwAAAPM"]
[Thu Jul 30 15:33:05.311046 2026] [security2:error] [pid 189611:tid 189824] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/php.php"] [unique_id "amu1AeWE7BvPuUzLJ994ZAAAANg"]
[Thu Jul 30 15:33:05.311178 2026] [security2:error] [pid 189611:tid 189824] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/php.php"] [unique_id "amu1AeWE7BvPuUzLJ994ZAAAANg"]
[Thu Jul 30 15:33:05.502139 2026] [security2:error] [pid 189611:tid 189783] [client 172.237.109.114:40469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AOWE7BvPuUzLJ994UwAAAK8"]
[Thu Jul 30 15:33:05.524217 2026] [security2:error] [pid 189611:tid 189841] [client 172.237.109.114:61758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AOWE7BvPuUzLJ994UQAAAOk"]
[Thu Jul 30 15:33:05.544392 2026] [security2:error] [pid 189611:tid 189763] [client 172.237.109.114:56411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AOWE7BvPuUzLJ994VAAAAJs"]
[Thu Jul 30 15:33:05.546688 2026] [security2:error] [pid 189611:tid 189801] [client 172.237.109.114:32279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AOWE7BvPuUzLJ994VgAAAME"]
[Thu Jul 30 15:33:05.547348 2026] [security2:error] [pid 189611:tid 189842] [client 172.237.109.114:59398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AOWE7BvPuUzLJ994UAAAAOo"]
[Thu Jul 30 15:33:05.562332 2026] [security2:error] [pid 189611:tid 189829] [client 85.204.70.116:38824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amu1AeWE7BvPuUzLJ994bAAAAN0"]
[Thu Jul 30 15:33:05.584359 2026] [security2:error] [pid 189611:tid 189837] [client 20.52.125.110:12928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/a4.php"] [unique_id "amu1AeWE7BvPuUzLJ994bwAAAOU"]
[Thu Jul 30 15:33:05.587858 2026] [security2:error] [pid 189611:tid 189836] [client 172.237.109.114:56748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AeWE7BvPuUzLJ994WgAAAOQ"]
[Thu Jul 30 15:33:05.599379 2026] [security2:error] [pid 189611:tid 189813] [client 172.237.109.114:63197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AeWE7BvPuUzLJ994WAAAAM0"]
[Thu Jul 30 15:33:05.602091 2026] [security2:error] [pid 189611:tid 189809] [client 172.237.109.114:53756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1AeWE7BvPuUzLJ994WQAAAMk"]
[Thu Jul 30 15:33:05.695155 2026] [security2:error] [pid 189611:tid 189830] [client 172.213.17.107:7702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.17.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicago-mfg.com"] [uri "/cgi-bin/index.php"] [unique_id "amu1AeWE7BvPuUzLJ994eAAAAN4"]
[Thu Jul 30 15:33:05.695246 2026] [security2:error] [pid 189611:tid 189830] [client 172.213.17.107:7702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chicago-mfg.com"] [uri "/cgi-bin/index.php"] [unique_id "amu1AeWE7BvPuUzLJ994eAAAAN4"]
[Thu Jul 30 15:33:05.697611 2026] [security2:error] [pid 189611:tid 189846] [client 52.189.212.127:50635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.212.189.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/wp-login.php"] [unique_id "amu1AeWE7BvPuUzLJ994ZQAAAO4"]
[Thu Jul 30 15:33:05.823646 2026] [security2:error] [pid 189611:tid 189861] [client 85.204.70.116:58113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/site/wp-includes/wlwmanifest.xml"] [unique_id "amu1AeWE7BvPuUzLJ994egAAAP0"]
[Thu Jul 30 15:33:05.919581 2026] [security2:error] [pid 189611:tid 189789] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/t.php"] [unique_id "amu1AeWE7BvPuUzLJ994ewAAALU"]
[Thu Jul 30 15:33:05.919690 2026] [security2:error] [pid 189611:tid 189789] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/t.php"] [unique_id "amu1AeWE7BvPuUzLJ994ewAAALU"]
[Thu Jul 30 15:33:06.108380 2026] [security2:error] [pid 189611:tid 189828] [client 85.204.70.116:11900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/cms/wp-includes/wlwmanifest.xml"] [unique_id "amu1AuWE7BvPuUzLJ994gwAAANw"]
[Thu Jul 30 15:33:06.237992 2026] [security2:error] [pid 189611:tid 189805] [client 20.52.125.110:12934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/accueil.php"] [unique_id "amu1AuWE7BvPuUzLJ994hwAAAMU"]
[Thu Jul 30 15:33:06.389132 2026] [security2:error] [pid 189611:tid 189864] [client 85.204.70.116:38838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bky.rty.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi/sito/wp-includes/wlwmanifest.xml"] [unique_id "amu1AuWE7BvPuUzLJ994iwAAAQA"]
[Thu Jul 30 15:33:06.445309 2026] [security2:error] [pid 189611:tid 189773] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-blink.php"] [unique_id "amu1AuWE7BvPuUzLJ994jAAAAKU"]
[Thu Jul 30 15:33:06.445435 2026] [security2:error] [pid 189611:tid 189773] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-blink.php"] [unique_id "amu1AuWE7BvPuUzLJ994jAAAAKU"]
[Thu Jul 30 15:33:06.707890 2026] [security2:error] [pid 189611:tid 189752] [client 20.100.187.246:1917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/images/about.php"] [unique_id "amu1AuWE7BvPuUzLJ994lgAAAJA"]
[Thu Jul 30 15:33:06.741879 2026] [security2:error] [pid 189611:tid 189811] [client 172.202.44.182:63953] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hoki188win.com"] [uri "/1.php"] [unique_id "amu1AuWE7BvPuUzLJ994lwAAAMs"]
[Thu Jul 30 15:33:06.741996 2026] [security2:error] [pid 189611:tid 189811] [client 172.202.44.182:63953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/1.php"] [unique_id "amu1AuWE7BvPuUzLJ994lwAAAMs"]
[Thu Jul 30 15:33:06.790486 2026] [security2:error] [pid 189611:tid 189845] [client 74.7.244.60:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "heatstickhk.com"] [uri "/index.php"] [unique_id "amu1AeWE7BvPuUzLJ994eQAA7SY"]
[Thu Jul 30 15:33:07.062788 2026] [security2:error] [pid 189611:tid 189746] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/xfun.php"] [unique_id "amu1A-WE7BvPuUzLJ994nQAAAIo"]
[Thu Jul 30 15:33:07.062923 2026] [security2:error] [pid 189611:tid 189746] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/xfun.php"] [unique_id "amu1A-WE7BvPuUzLJ994nQAAAIo"]
[Thu Jul 30 15:33:07.576601 2026] [security2:error] [pid 189611:tid 189808] [client 20.52.125.110:12940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/dashboard.php"] [unique_id "amu1A-WE7BvPuUzLJ994pwAAAMg"]
[Thu Jul 30 15:33:07.711864 2026] [security2:error] [pid 189611:tid 189809] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/p.php"] [unique_id "amu1A-WE7BvPuUzLJ994rAAAAMk"]
[Thu Jul 30 15:33:07.711987 2026] [security2:error] [pid 189611:tid 189809] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/p.php"] [unique_id "amu1A-WE7BvPuUzLJ994rAAAAMk"]
[Thu Jul 30 15:33:08.292805 2026] [security2:error] [pid 189611:tid 189674] [remote 57.141.0.51:55112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/63798190810/feed/rss2/"] [unique_id "amu1BOWE7BvPuUzLJ994uQAA3j4"]
[Thu Jul 30 15:33:08.334742 2026] [security2:error] [pid 189611:tid 189828] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amu1BOWE7BvPuUzLJ994vwAAANw"]
[Thu Jul 30 15:33:08.334840 2026] [security2:error] [pid 189611:tid 189828] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amu1BOWE7BvPuUzLJ994vwAAANw"]
[Thu Jul 30 15:33:08.892361 2026] [security2:error] [pid 189611:tid 189796] [client 20.100.187.246:4660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/about.php"] [unique_id "amu1BOWE7BvPuUzLJ9940QAAALw"]
[Thu Jul 30 15:33:08.925368 2026] [security2:error] [pid 189611:tid 189755] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/aaa.php"] [unique_id "amu1BOWE7BvPuUzLJ9941AAAAJM"]
[Thu Jul 30 15:33:08.925469 2026] [security2:error] [pid 189611:tid 189755] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/aaa.php"] [unique_id "amu1BOWE7BvPuUzLJ9941AAAAJM"]
[Thu Jul 30 15:33:09.226658 2026] [security2:error] [pid 189611:tid 189820] [client 2a03:2880:f800:3f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1BOWE7BvPuUzLJ994xQAA1Ek"]
[Thu Jul 30 15:33:09.247500 2026] [security2:error] [pid 189611:tid 189854] [client 20.52.125.110:12988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/radio.php"] [unique_id "amu1BeWE7BvPuUzLJ9943gAAAPY"]
[Thu Jul 30 15:33:09.472199 2026] [security2:error] [pid 189611:tid 189692] [remote 103.74.116.239:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saifalkhaleejest.com"] [uri "/wp-login.php"] [unique_id "amu1BeWE7BvPuUzLJ9945AAA1VA"]
[Thu Jul 30 15:33:09.479222 2026] [security2:error] [pid 189611:tid 189764] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/7.php"] [unique_id "amu1BeWE7BvPuUzLJ9945QAAAJw"]
[Thu Jul 30 15:33:09.479307 2026] [security2:error] [pid 189611:tid 189764] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/7.php"] [unique_id "amu1BeWE7BvPuUzLJ9945QAAAJw"]
[Thu Jul 30 15:33:09.491885 2026] [security2:error] [pid 189611:tid 189762] [client 172.237.109.114:48653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1BOWE7BvPuUzLJ9941QAAAJo"]
[Thu Jul 30 15:33:09.970897 2026] [security2:error] [pid 189611:tid 189780] [client 20.52.125.110:12676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/wpsml-sys.php"] [unique_id "amu1BeWE7BvPuUzLJ9949gAAAKw"]
[Thu Jul 30 15:33:10.086522 2026] [security2:error] [pid 189611:tid 189749] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/file5.php"] [unique_id "amu1BuWE7BvPuUzLJ9949wAAAI0"]
[Thu Jul 30 15:33:10.086630 2026] [security2:error] [pid 189611:tid 189749] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/file5.php"] [unique_id "amu1BuWE7BvPuUzLJ9949wAAAI0"]
[Thu Jul 30 15:33:10.687193 2026] [security2:error] [pid 189611:tid 189832] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/makeasmtp.php"] [unique_id "amu1BuWE7BvPuUzLJ995AwAAAOA"]
[Thu Jul 30 15:33:10.687304 2026] [security2:error] [pid 189611:tid 189832] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/makeasmtp.php"] [unique_id "amu1BuWE7BvPuUzLJ995AwAAAOA"]
[Thu Jul 30 15:33:11.301775 2026] [security2:error] [pid 189611:tid 189824] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/index.php"] [unique_id "amu1B-WE7BvPuUzLJ995GQAAANg"]
[Thu Jul 30 15:33:11.301895 2026] [security2:error] [pid 189611:tid 189824] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/index.php"] [unique_id "amu1B-WE7BvPuUzLJ995GQAAANg"]
[Thu Jul 30 15:33:11.326768 2026] [core:error] [pid 189611:tid 189820] [client 172.213.17.107:7704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:33:11.326790 2026] [core:error] [pid 189611:tid 189820] [client 172.213.17.107:7704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:33:11.326893 2026] [security2:error] [pid 189611:tid 189820] [client 172.213.17.107:7704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "chicago-mfg.com"] [uri "/index.php"] [unique_id "amu1B-WE7BvPuUzLJ995HAAAANQ"]
[Thu Jul 30 15:33:11.870159 2026] [security2:error] [pid 189611:tid 189777] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/atomlib.php"] [unique_id "amu1B-WE7BvPuUzLJ995KgAAAKk"]
[Thu Jul 30 15:33:11.870257 2026] [security2:error] [pid 189611:tid 189777] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/atomlib.php"] [unique_id "amu1B-WE7BvPuUzLJ995KgAAAKk"]
[Thu Jul 30 15:33:11.895832 2026] [security2:error] [pid 189611:tid 189782] [client 20.52.125.110:12674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/02.php"] [unique_id "amu1B-WE7BvPuUzLJ995LwAAAK4"]
[Thu Jul 30 15:33:12.195143 2026] [security2:error] [pid 189611:tid 189723] [remote 57.141.18.60:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amu1COWE7BvPuUzLJ995MwAAhm8"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,denim,linen,lycra,plastic,titanium,wood,silicon&min_price=300&orderby=menu_order&status=instock&unfilter=1
[Thu Jul 30 15:33:12.376817 2026] [security2:error] [pid 189611:tid 189865] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/min.php"] [unique_id "amu1COWE7BvPuUzLJ995OAAAAQE"]
[Thu Jul 30 15:33:12.376913 2026] [security2:error] [pid 189611:tid 189865] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/min.php"] [unique_id "amu1COWE7BvPuUzLJ995OAAAAQE"]
[Thu Jul 30 15:33:12.458915 2026] [security2:error] [pid 189611:tid 189724] [remote 57.141.18.64:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amu1COWE7BvPuUzLJ995NAAA53A"], referer: https://nafmedical.com/shops/shop-metro-sidebar/?filter_materials=carbon,denim,linen,lycra,plastic,titanium,wood,silicon&min_price=300&orderby=menu_order&status=instock&unfilter=1
[Thu Jul 30 15:33:12.463219 2026] [security2:error] [pid 189611:tid 189799] [client 172.202.44.182:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/gg.php"] [unique_id "amu1COWE7BvPuUzLJ995QAAAAL8"]
[Thu Jul 30 15:33:12.945290 2026] [security2:error] [pid 189611:tid 189802] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/moon.php"] [unique_id "amu1COWE7BvPuUzLJ995RwAAAMI"]
[Thu Jul 30 15:33:12.945407 2026] [security2:error] [pid 189611:tid 189802] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/moon.php"] [unique_id "amu1COWE7BvPuUzLJ995RwAAAMI"]
[Thu Jul 30 15:33:13.005669 2026] [security2:error] [pid 189611:tid 189826] [client 20.52.125.110:12977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/infos.php"] [unique_id "amu1CeWE7BvPuUzLJ995TgAAANo"]
[Thu Jul 30 15:33:13.486504 2026] [security2:error] [pid 189611:tid 189824] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/ws83.php"] [unique_id "amu1CeWE7BvPuUzLJ995VAAAANg"]
[Thu Jul 30 15:33:13.486665 2026] [security2:error] [pid 189611:tid 189824] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/ws83.php"] [unique_id "amu1CeWE7BvPuUzLJ995VAAAANg"]
[Thu Jul 30 15:33:13.665745 2026] [security2:error] [pid 189611:tid 189776] [client 20.52.125.110:12975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/updates.php"] [unique_id "amu1CeWE7BvPuUzLJ995XgAAAKg"]
[Thu Jul 30 15:33:13.867326 2026] [security2:error] [pid 189611:tid 189735] [remote 12.55.19.110:63063] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amu1CeWE7BvPuUzLJ995WQAAu3s"], referer: https://www.shorewooddaycare.com/
[Thu Jul 30 15:33:13.867377 2026] [security2:error] [pid 189611:tid 189735] [remote 12.55.19.110:63063] ModSecurity: Access denied with code 409 (phase 2). Match of "eq 1" against "&REQUEST_COOKIES:humans_21909" required. [file "/opt/mod_security/hg_rules.conf"] [line "1552"] [id "900424"] [msg "Transparent Bot Detection for Contact Forms"] [hostname "www.shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amu1CeWE7BvPuUzLJ995WQAAu3s"], referer: https://www.shorewooddaycare.com/
[Thu Jul 30 15:33:13.869270 2026] [security2:error] [pid 189611:tid 189771] [client 172.202.44.182:19135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp.php"] [unique_id "amu1CeWE7BvPuUzLJ995ZQAAAKM"]
[Thu Jul 30 15:33:13.995490 2026] [core:notice] [pid 189611:tid 189619] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:14.075188 2026] [security2:error] [pid 189611:tid 189812] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/403.php"] [unique_id "amu1CuWE7BvPuUzLJ995cgAAAMw"]
[Thu Jul 30 15:33:14.075338 2026] [security2:error] [pid 189611:tid 189812] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/403.php"] [unique_id "amu1CuWE7BvPuUzLJ995cgAAAMw"]
[Thu Jul 30 15:33:14.179449 2026] [security2:error] [pid 189611:tid 189617] [remote 12.55.19.110:63063] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amu1CuWE7BvPuUzLJ995cwAAnwU"], referer: https://www.shorewooddaycare.com/contact.php
[Thu Jul 30 15:33:14.223609 2026] [security2:error] [pid 189611:tid 189832] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1CeWE7BvPuUzLJ995UAAA4Hg"]
[Thu Jul 30 15:33:14.236708 2026] [core:error] [pid 189611:tid 189834] [client 74.7.241.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:33:14.236739 2026] [core:error] [pid 189611:tid 189834] [client 74.7.241.160:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:33:14.236935 2026] [security2:error] [pid 189611:tid 189834] [client 74.7.241.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.nfi.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "amu1CuWE7BvPuUzLJ995dgAAAOI"]
[Thu Jul 30 15:33:14.237719 2026] [security2:error] [pid 189611:tid 189770] [client 74.7.241.160:50654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.nfi.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "amu1CuWE7BvPuUzLJ995dAAAogQ"]
[Thu Jul 30 15:33:14.341608 2026] [security2:error] [pid 189611:tid 189751] [client 74.7.244.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.tfy.udi.temporary.site"] [uri "/index.php"] [unique_id "amu1COWE7BvPuUzLJ995SgAAAI8"]
[Thu Jul 30 15:33:14.342483 2026] [security2:error] [pid 189611:tid 189864] [client 74.7.244.63:33652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.tfy.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amu1COWE7BvPuUzLJ995SAABAHY"]
[Thu Jul 30 15:33:14.466755 2026] [security2:error] [pid 189611:tid 189865] [client 20.52.125.110:12974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/user.php"] [unique_id "amu1CuWE7BvPuUzLJ995gQAAAQE"]
[Thu Jul 30 15:33:14.471635 2026] [security2:error] [pid 189611:tid 189741] [client 172.237.109.114:4014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1CeWE7BvPuUzLJ995aQAAAIU"]
[Thu Jul 30 15:33:14.548469 2026] [security2:error] [pid 189611:tid 189842] [client 172.237.109.114:16848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1CeWE7BvPuUzLJ995awAAAOo"]
[Thu Jul 30 15:33:14.673736 2026] [security2:error] [pid 189611:tid 189820] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/api.php"] [unique_id "amu1CuWE7BvPuUzLJ995iQAAANQ"]
[Thu Jul 30 15:33:14.673860 2026] [security2:error] [pid 189611:tid 189820] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/api.php"] [unique_id "amu1CuWE7BvPuUzLJ995iQAAANQ"]
[Thu Jul 30 15:33:14.699015 2026] [core:notice] [pid 189611:tid 189621] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:14.831646 2026] [security2:error] [pid 189611:tid 189780] [client 20.100.187.246:10266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/cgi-bin/about.php"] [unique_id "amu1CuWE7BvPuUzLJ995iwAAAKw"]
[Thu Jul 30 15:33:15.020292 2026] [security2:error] [pid 189611:tid 189818] [client 74.7.228.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-f8ea1188.axm.gzj.temporary.site"] [uri "/index.php"] [unique_id "amu1CeWE7BvPuUzLJ995YQAAANI"]
[Thu Jul 30 15:33:15.021412 2026] [security2:error] [pid 189611:tid 189804] [client 74.7.228.10:56690] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-f8ea1188.axm.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amu1CeWE7BvPuUzLJ995XwAAxHc"]
[Thu Jul 30 15:33:15.041274 2026] [security2:error] [pid 189611:tid 189623] [remote 17.246.15.27:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.15.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lark-shop.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "amu1C-WE7BvPuUzLJ995mwAAmAs"], referer: https://lark-shop.com/product/peel-4/
[Thu Jul 30 15:33:15.238210 2026] [security2:error] [pid 189611:tid 189765] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/3.php"] [unique_id "amu1C-WE7BvPuUzLJ995oQAAAJ0"]
[Thu Jul 30 15:33:15.238388 2026] [security2:error] [pid 189611:tid 189765] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/3.php"] [unique_id "amu1C-WE7BvPuUzLJ995oQAAAJ0"]
[Thu Jul 30 15:33:15.517706 2026] [security2:error] [pid 189611:tid 189783] [client 172.237.109.114:59640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1CuWE7BvPuUzLJ995kwAAAK8"]
[Thu Jul 30 15:33:15.563196 2026] [security2:error] [pid 189611:tid 189852] [client 172.202.44.182:63966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amu1C-WE7BvPuUzLJ995pgAAAPQ"]
[Thu Jul 30 15:33:15.565356 2026] [security2:error] [pid 189611:tid 189776] [client 172.237.109.114:12661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1CuWE7BvPuUzLJ995kgAAAKg"]
[Thu Jul 30 15:33:15.624094 2026] [security2:error] [pid 189611:tid 189800] [client 172.237.109.114:35176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1CuWE7BvPuUzLJ995lAAAAMA"]
[Thu Jul 30 15:33:15.624317 2026] [security2:error] [pid 189611:tid 189768] [client 172.237.109.114:8205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1CuWE7BvPuUzLJ995lQAAAKA"]
[Thu Jul 30 15:33:15.648409 2026] [security2:error] [pid 189611:tid 189823] [client 172.237.109.114:14676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1CuWE7BvPuUzLJ995lgAAANc"]
[Thu Jul 30 15:33:15.656830 2026] [security2:error] [pid 189611:tid 189798] [client 172.237.109.114:11054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1CuWE7BvPuUzLJ995kQAAAL4"]
[Thu Jul 30 15:33:15.667721 2026] [security2:error] [pid 189611:tid 189744] [client 172.237.109.114:58132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1C-WE7BvPuUzLJ995lwAAAIg"]
[Thu Jul 30 15:33:15.678380 2026] [security2:error] [pid 189611:tid 189762] [client 172.237.109.114:13444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1C-WE7BvPuUzLJ995mQAAAJo"]
[Thu Jul 30 15:33:15.683303 2026] [security2:error] [pid 189611:tid 189789] [client 20.100.187.246:1349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amu1C-WE7BvPuUzLJ995qQAAALU"]
[Thu Jul 30 15:33:15.990487 2026] [security2:error] [pid 189611:tid 189848] [client 172.237.109.114:60505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/v2/graphql.php"] [unique_id "amu1C-WE7BvPuUzLJ995uwAAAPA"]
[Thu Jul 30 15:33:15.990529 2026] [security2:error] [pid 189611:tid 189847] [client 172.237.109.114:48537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/v2/graphiql.php"] [unique_id "amu1C-WE7BvPuUzLJ995ugAAAO8"]
[Thu Jul 30 15:33:16.496335 2026] [security2:error] [pid 189611:tid 189755] [client 172.237.109.114:13647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1C-WE7BvPuUzLJ995tQAAAJM"]
[Thu Jul 30 15:33:16.518833 2026] [security2:error] [pid 189611:tid 189794] [client 172.237.109.114:47288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1C-WE7BvPuUzLJ995swAAALo"]
[Thu Jul 30 15:33:16.526735 2026] [security2:error] [pid 189611:tid 189756] [client 172.237.109.114:17071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1C-WE7BvPuUzLJ995tAAAAJQ"]
[Thu Jul 30 15:33:16.533355 2026] [security2:error] [pid 189611:tid 189826] [client 172.237.109.114:45409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1C-WE7BvPuUzLJ995tgAAANo"]
[Thu Jul 30 15:33:16.536639 2026] [security2:error] [pid 189611:tid 189835] [client 20.226.5.174:62147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wsa.php"] [unique_id "amu1DOWE7BvPuUzLJ9950AAAAOM"]
[Thu Jul 30 15:33:16.543364 2026] [security2:error] [pid 189611:tid 189842] [client 172.237.109.114:4374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1C-WE7BvPuUzLJ995vQAAAOo"]
[Thu Jul 30 15:33:16.547246 2026] [security2:error] [pid 189611:tid 189750] [client 172.237.109.114:49793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1C-WE7BvPuUzLJ995vAAAAI4"]
[Thu Jul 30 15:33:16.551185 2026] [security2:error] [pid 189611:tid 189863] [client 172.237.109.114:34928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1C-WE7BvPuUzLJ995uAAAAP8"]
[Thu Jul 30 15:33:16.584004 2026] [security2:error] [pid 189611:tid 189769] [client 172.237.109.114:48969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1DOWE7BvPuUzLJ995vgAAAKE"]
[Thu Jul 30 15:33:16.753134 2026] [core:notice] [pid 189611:tid 189807] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:16.908379 2026] [core:notice] [pid 189611:tid 189759] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:17.019803 2026] [security2:error] [pid 189611:tid 189764] [client 172.202.44.182:22019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/file.php"] [unique_id "amu1DeWE7BvPuUzLJ9952wAAAJw"]
[Thu Jul 30 15:33:17.096284 2026] [security2:error] [pid 189611:tid 189812] [client 20.52.125.110:12672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/admin-ajax.php"] [unique_id "amu1DeWE7BvPuUzLJ9953wAAAMw"]
[Thu Jul 30 15:33:17.289523 2026] [core:error] [pid 189611:tid 189768] [client 172.213.17.107:61812] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:33:17.289550 2026] [core:error] [pid 189611:tid 189768] [client 172.213.17.107:61812] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:33:17.289699 2026] [security2:error] [pid 189611:tid 189768] [client 172.213.17.107:61812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "chicago-mfg.com"] [uri "/index.php"] [unique_id "amu1DeWE7BvPuUzLJ9954wAAAKA"]
[Thu Jul 30 15:33:17.647395 2026] [security2:error] [pid 189611:tid 189744] [client 20.226.5.174:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wsad.php"] [unique_id "amu1DeWE7BvPuUzLJ9956gAAAIg"]
[Thu Jul 30 15:33:18.318092 2026] [security2:error] [pid 189611:tid 189796] [client 20.52.125.110:12700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/alfa.php"] [unique_id "amu1DuWE7BvPuUzLJ9959wAAALw"]
[Thu Jul 30 15:33:18.847028 2026] [core:notice] [pid 189611:tid 189792] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:18.919593 2026] [security2:error] [pid 189611:tid 189854] [client 20.226.5.174:62149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wsanon.php"] [unique_id "amu1DuWE7BvPuUzLJ996BwAAAPY"]
[Thu Jul 30 15:33:18.954562 2026] [security2:error] [pid 189611:tid 189848] [client 172.202.44.182:22033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/user/index.php"] [unique_id "amu1DuWE7BvPuUzLJ996CAAAAPA"]
[Thu Jul 30 15:33:19.008039 2026] [security2:error] [pid 189611:tid 189794] [client 20.52.125.110:12937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/hehe.php"] [unique_id "amu1D-WE7BvPuUzLJ996CQAAALo"]
[Thu Jul 30 15:33:20.049750 2026] [security2:error] [pid 189611:tid 189759] [client 20.226.5.174:62158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wsback.php"] [unique_id "amu1EOWE7BvPuUzLJ996IAAAAJc"]
[Thu Jul 30 15:33:20.102059 2026] [security2:error] [pid 189611:tid 189830] [client 172.237.109.114:61433] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/m-wp-popup/readme.txt"] [unique_id "amu1EOWE7BvPuUzLJ996IQAAAN4"]
[Thu Jul 30 15:33:20.212844 2026] [security2:error] [pid 189611:tid 189861] [client 172.202.44.182:19133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amu1EOWE7BvPuUzLJ996JgAAAP0"]
[Thu Jul 30 15:33:20.502628 2026] [security2:error] [pid 189611:tid 189815] [client 172.237.109.114:61671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1EOWE7BvPuUzLJ996HwAAAM8"]
[Thu Jul 30 15:33:20.629207 2026] [core:notice] [pid 189611:tid 189800] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:20.839091 2026] [core:notice] [pid 189611:tid 189679] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:20.993634 2026] [security2:error] [pid 189611:tid 189825] [client 110.249.201.228:43510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiandubaisafari.com"] [uri "/dhow-marina.html"] [unique_id "amu1EOWE7BvPuUzLJ996OgAAANk"]
[Thu Jul 30 15:33:21.090845 2026] [security2:error] [pid 189611:tid 189867] [client 20.226.5.174:62165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wso-latest.php"] [unique_id "amu1EeWE7BvPuUzLJ996PAAAAQM"]
[Thu Jul 30 15:33:21.271954 2026] [core:notice] [pid 189611:tid 189680] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:21.526178 2026] [proxy:error] [pid 189611:tid 189807] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:21.526241 2026] [proxy_http:error] [pid 189611:tid 189807] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:21.526803 2026] [proxy:error] [pid 189611:tid 189807] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:21.526856 2026] [proxy_http:error] [pid 189611:tid 189807] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:21.526936 2026] [security2:error] [pid 189611:tid 189807] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu1EeWE7BvPuUzLJ996RwAAAMc"]
[Thu Jul 30 15:33:21.552286 2026] [security2:error] [pid 189611:tid 189831] [client 20.52.125.110:13013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/rk2.php"] [unique_id "amu1EeWE7BvPuUzLJ996SAAAAN8"]
[Thu Jul 30 15:33:21.952075 2026] [core:notice] [pid 189611:tid 189691] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:21.991746 2026] [security2:error] [pid 189611:tid 189848] [client 172.202.44.182:22064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/index/function.php"] [unique_id "amu1EeWE7BvPuUzLJ996VgAAAPA"]
[Thu Jul 30 15:33:22.232954 2026] [security2:error] [pid 189611:tid 189816] [client 20.226.5.174:62150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wso.php"] [unique_id "amu1EuWE7BvPuUzLJ996XQAAANA"]
[Thu Jul 30 15:33:22.343281 2026] [security2:error] [pid 189611:tid 189849] [client 20.52.125.110:12701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/setup-config.php"] [unique_id "amu1EuWE7BvPuUzLJ996YQAAAPE"]
[Thu Jul 30 15:33:23.300321 2026] [security2:error] [pid 189611:tid 189766] [client 20.226.5.174:62146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wso112233.php"] [unique_id "amu1E-WE7BvPuUzLJ996dAAAAJ4"]
[Thu Jul 30 15:33:24.121621 2026] [security2:error] [pid 189611:tid 189758] [client 20.52.125.110:12696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/a7.php"] [unique_id "amu1FOWE7BvPuUzLJ996hgAAAJY"]
[Thu Jul 30 15:33:24.359756 2026] [security2:error] [pid 189611:tid 189749] [client 20.226.5.174:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wso1337.php"] [unique_id "amu1FOWE7BvPuUzLJ996jgAAAI0"]
[Thu Jul 30 15:33:24.397382 2026] [core:notice] [pid 189611:tid 189706] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:24.438527 2026] [security2:error] [pid 189611:tid 189838] [client 172.202.44.182:63947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/aaa.php"] [unique_id "amu1FOWE7BvPuUzLJ996kAAAAOY"]
[Thu Jul 30 15:33:25.052664 2026] [security2:error] [pid 189611:tid 189785] [client 20.52.125.110:12694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/f7.php"] [unique_id "amu1FeWE7BvPuUzLJ996nwAAALE"]
[Thu Jul 30 15:33:25.350838 2026] [security2:error] [pid 189611:tid 189781] [client 20.226.5.174:62155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wso2.7.php"] [unique_id "amu1FeWE7BvPuUzLJ996qQAAAK0"]
[Thu Jul 30 15:33:25.482194 2026] [security2:error] [pid 189611:tid 189751] [client 172.202.44.182:22051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/getid3-core.php"] [unique_id "amu1FeWE7BvPuUzLJ996qwAAAI8"]
[Thu Jul 30 15:33:26.335188 2026] [security2:error] [pid 189611:tid 189854] [client 20.226.5.174:62145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wso2.8.php"] [unique_id "amu1FuWE7BvPuUzLJ996vAAAAPY"]
[Thu Jul 30 15:33:26.453828 2026] [core:notice] [pid 189611:tid 189845] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:26.879644 2026] [core:notice] [pid 189611:tid 189837] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:26.964329 2026] [core:notice] [pid 189611:tid 189810] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:26.997029 2026] [security2:error] [pid 189611:tid 189793] [client 20.52.125.110:13029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/nw.php"] [unique_id "amu1FuWE7BvPuUzLJ996zwAAALk"]
[Thu Jul 30 15:33:27.151770 2026] [security2:error] [pid 189611:tid 189808] [client 172.237.109.114:58287] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/vkontakte-wall-post/readme.txt"] [unique_id "amu1F-WE7BvPuUzLJ9960AAAAMg"]
[Thu Jul 30 15:33:27.401563 2026] [security2:error] [pid 189611:tid 189759] [client 20.226.5.174:62153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wso2.php"] [unique_id "amu1F-WE7BvPuUzLJ9961wAAAJc"]
[Thu Jul 30 15:33:27.846762 2026] [security2:error] [pid 189611:tid 189862] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/ws77.php"] [unique_id "amu1F-WE7BvPuUzLJ9963gAAAP4"]
[Thu Jul 30 15:33:27.846852 2026] [security2:error] [pid 189611:tid 189862] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/ws77.php"] [unique_id "amu1F-WE7BvPuUzLJ9963gAAAP4"]
[Thu Jul 30 15:33:28.297197 2026] [security2:error] [pid 189611:tid 189747] [client 172.202.44.182:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/adminer.php"] [unique_id "amu1GOWE7BvPuUzLJ9967gAAAIs"]
[Thu Jul 30 15:33:28.434786 2026] [security2:error] [pid 189611:tid 189761] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/nc4.php"] [unique_id "amu1GOWE7BvPuUzLJ9968gAAAJk"]
[Thu Jul 30 15:33:28.434892 2026] [security2:error] [pid 189611:tid 189761] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/nc4.php"] [unique_id "amu1GOWE7BvPuUzLJ9968gAAAJk"]
[Thu Jul 30 15:33:28.459245 2026] [security2:error] [pid 189611:tid 189855] [client 20.226.5.174:62177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wso2023.php"] [unique_id "amu1GOWE7BvPuUzLJ9968wAAAPc"]
[Thu Jul 30 15:33:28.845892 2026] [core:notice] [pid 189611:tid 189626] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:28.964098 2026] [security2:error] [pid 189611:tid 189760] [client 20.100.187.246:28963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amu1GOWE7BvPuUzLJ997AAAAAJg"]
[Thu Jul 30 15:33:29.038632 2026] [security2:error] [pid 189611:tid 189851] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/as.php"] [unique_id "amu1GeWE7BvPuUzLJ997AwAAAPM"]
[Thu Jul 30 15:33:29.038782 2026] [security2:error] [pid 189611:tid 189851] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/as.php"] [unique_id "amu1GeWE7BvPuUzLJ997AwAAAPM"]
[Thu Jul 30 15:33:29.065847 2026] [security2:error] [pid 189611:tid 189773] [client 20.52.125.110:12678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/ova.php"] [unique_id "amu1GeWE7BvPuUzLJ997BQAAAKU"]
[Thu Jul 30 15:33:29.486017 2026] [security2:error] [pid 189611:tid 189835] [client 172.237.109.114:26069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GOWE7BvPuUzLJ997AQAAAOM"]
[Thu Jul 30 15:33:29.507164 2026] [security2:error] [pid 189611:tid 189777] [client 20.226.5.174:62148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wso403.php"] [unique_id "amu1GeWE7BvPuUzLJ997GgAAAKk"]
[Thu Jul 30 15:33:29.554743 2026] [security2:error] [pid 189611:tid 189866] [client 172.237.109.114:60536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GOWE7BvPuUzLJ997AgAAAQI"]
[Thu Jul 30 15:33:29.563564 2026] [security2:error] [pid 189611:tid 189808] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/k.php"] [unique_id "amu1GeWE7BvPuUzLJ997GwAAAMg"]
[Thu Jul 30 15:33:29.563704 2026] [security2:error] [pid 189611:tid 189808] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/k.php"] [unique_id "amu1GeWE7BvPuUzLJ997GwAAAMg"]
[Thu Jul 30 15:33:29.669030 2026] [security2:error] [pid 189611:tid 189798] [client 172.202.44.182:22050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/alfa.php"] [unique_id "amu1GeWE7BvPuUzLJ997HwAAAL4"]
[Thu Jul 30 15:33:30.103624 2026] [security2:error] [pid 189611:tid 189796] [client 134.19.179.139:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu1GuWE7BvPuUzLJ997KgAAALw"]
[Thu Jul 30 15:33:30.103739 2026] [security2:error] [pid 189611:tid 189796] [client 134.19.179.139:43800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu1GuWE7BvPuUzLJ997KgAAALw"]
[Thu Jul 30 15:33:30.121716 2026] [security2:error] [pid 189611:tid 189849] [client 172.237.109.114:2580] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "amu1GuWE7BvPuUzLJ997KwAAAPE"]
[Thu Jul 30 15:33:30.457207 2026] [security2:error] [pid 189611:tid 189778] [client 20.100.187.246:29211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/css/about.php"] [unique_id "amu1GuWE7BvPuUzLJ997MgAAAKo"]
[Thu Jul 30 15:33:30.457850 2026] [security2:error] [pid 189611:tid 189862] [client 172.237.109.114:59077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GeWE7BvPuUzLJ997KQAAAP4"]
[Thu Jul 30 15:33:30.553700 2026] [security2:error] [pid 189611:tid 189787] [client 20.226.5.174:62173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wsoshell.php"] [unique_id "amu1GuWE7BvPuUzLJ997OQAAALM"]
[Thu Jul 30 15:33:30.674020 2026] [security2:error] [pid 189611:tid 189746] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/system_log.php"] [unique_id "amu1GuWE7BvPuUzLJ997OgAAAIo"]
[Thu Jul 30 15:33:30.674131 2026] [security2:error] [pid 189611:tid 189746] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/system_log.php"] [unique_id "amu1GuWE7BvPuUzLJ997OgAAAIo"]
[Thu Jul 30 15:33:30.718580 2026] [security2:error] [pid 189611:tid 189780] [client 20.52.125.110:12681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/robots.php"] [unique_id "amu1GuWE7BvPuUzLJ997PgAAAKw"]
[Thu Jul 30 15:33:31.070771 2026] [core:notice] [pid 189611:tid 189846] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:31.220604 2026] [core:notice] [pid 189611:tid 189810] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:31.297617 2026] [security2:error] [pid 189611:tid 189764] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/x.php"] [unique_id "amu1G-WE7BvPuUzLJ997WQAAAJw"]
[Thu Jul 30 15:33:31.297757 2026] [security2:error] [pid 189611:tid 189764] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/x.php"] [unique_id "amu1G-WE7BvPuUzLJ997WQAAAJw"]
[Thu Jul 30 15:33:31.372131 2026] [security2:error] [pid 189611:tid 189630] [remote 216.73.216.51:43389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu1G-WE7BvPuUzLJ997WgAA-BI"]
[Thu Jul 30 15:33:31.482025 2026] [security2:error] [pid 189611:tid 189776] [client 20.52.125.110:12985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/alf.php"] [unique_id "amu1G-WE7BvPuUzLJ997XgAAAKg"]
[Thu Jul 30 15:33:31.546628 2026] [core:notice] [pid 189611:tid 189635] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:31.559090 2026] [security2:error] [pid 189611:tid 189821] [client 172.237.109.114:9664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GuWE7BvPuUzLJ997QwAAANU"]
[Thu Jul 30 15:33:31.570870 2026] [security2:error] [pid 189611:tid 189794] [client 172.237.109.114:11322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GuWE7BvPuUzLJ997QgAAALo"]
[Thu Jul 30 15:33:31.576021 2026] [security2:error] [pid 189611:tid 189765] [client 20.226.5.174:62162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wsoyanz.php"] [unique_id "amu1G-WE7BvPuUzLJ997YwAAAJ0"]
[Thu Jul 30 15:33:31.616799 2026] [security2:error] [pid 189611:tid 189782] [client 172.237.109.114:64158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GuWE7BvPuUzLJ997SAAAAK4"]
[Thu Jul 30 15:33:31.616843 2026] [security2:error] [pid 189611:tid 189814] [client 172.237.109.114:64901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GuWE7BvPuUzLJ997SgAAAM4"]
[Thu Jul 30 15:33:31.617505 2026] [security2:error] [pid 189611:tid 189757] [client 172.237.109.114:44588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GuWE7BvPuUzLJ997RAAAAJU"]
[Thu Jul 30 15:33:31.622030 2026] [security2:error] [pid 189611:tid 189851] [client 172.237.109.114:61090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GuWE7BvPuUzLJ997RQAAAPM"]
[Thu Jul 30 15:33:31.627829 2026] [security2:error] [pid 189611:tid 189773] [client 172.237.109.114:21295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GuWE7BvPuUzLJ997RgAAAKU"]
[Thu Jul 30 15:33:31.628899 2026] [security2:error] [pid 189611:tid 189790] [client 172.237.109.114:34026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1GuWE7BvPuUzLJ997SQAAALY"]
[Thu Jul 30 15:33:31.637953 2026] [security2:error] [pid 189611:tid 189831] [client 172.237.109.114:6432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1G-WE7BvPuUzLJ997TQAAAN8"]
[Thu Jul 30 15:33:31.789735 2026] [security2:error] [pid 189611:tid 189770] [client 20.171.55.167:11180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/.well-knownwp.php"] [unique_id "amu1G-WE7BvPuUzLJ997ZgAAAKI"]
[Thu Jul 30 15:33:31.850000 2026] [security2:error] [pid 189611:tid 189816] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/autoload_classmap.php"] [unique_id "amu1G-WE7BvPuUzLJ997aAAAANA"]
[Thu Jul 30 15:33:31.850090 2026] [security2:error] [pid 189611:tid 189816] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/autoload_classmap.php"] [unique_id "amu1G-WE7BvPuUzLJ997aAAAANA"]
[Thu Jul 30 15:33:31.944111 2026] [security2:error] [pid 189611:tid 189759] [client 47.128.110.35:25330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bisbeetour.com"] [uri "/robots.txt"] [unique_id "amu1G-WE7BvPuUzLJ997aQAAAJc"]
[Thu Jul 30 15:33:31.967304 2026] [security2:error] [pid 189611:tid 189857] [client 172.237.109.114:57143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/v3/graphiql.php"] [unique_id "amu1G-WE7BvPuUzLJ997awAAAPk"]
[Thu Jul 30 15:33:32.008946 2026] [security2:error] [pid 189611:tid 189778] [client 172.237.109.114:48903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/v3/graphql.php"] [unique_id "amu1HOWE7BvPuUzLJ997dQAAAKo"]
[Thu Jul 30 15:33:32.384622 2026] [security2:error] [pid 189611:tid 189780] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/test1.php"] [unique_id "amu1HOWE7BvPuUzLJ997gAAAAKw"]
[Thu Jul 30 15:33:32.384763 2026] [security2:error] [pid 189611:tid 189780] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/test1.php"] [unique_id "amu1HOWE7BvPuUzLJ997gAAAAKw"]
[Thu Jul 30 15:33:32.397221 2026] [core:notice] [pid 189611:tid 189641] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:32.465366 2026] [security2:error] [pid 189611:tid 189867] [client 172.202.44.182:19123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amu1HOWE7BvPuUzLJ997ggAAAQM"]
[Thu Jul 30 15:33:32.495760 2026] [security2:error] [pid 189611:tid 189868] [client 172.237.109.114:11609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1G-WE7BvPuUzLJ997agAAAQQ"]
[Thu Jul 30 15:33:32.503880 2026] [security2:error] [pid 189611:tid 189747] [client 172.237.109.114:56712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1G-WE7BvPuUzLJ997bgAAAIs"]
[Thu Jul 30 15:33:32.509671 2026] [security2:error] [pid 189611:tid 189767] [client 172.237.109.114:59583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1G-WE7BvPuUzLJ997cwAAAJ8"]
[Thu Jul 30 15:33:32.518878 2026] [security2:error] [pid 189611:tid 189751] [client 172.237.109.114:28017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1G-WE7BvPuUzLJ997cgAAAI8"]
[Thu Jul 30 15:33:32.519664 2026] [security2:error] [pid 189611:tid 189860] [client 172.237.109.114:4896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1G-WE7BvPuUzLJ997bAAAAPw"]
[Thu Jul 30 15:33:32.533435 2026] [security2:error] [pid 189611:tid 189853] [client 172.237.109.114:6245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1G-WE7BvPuUzLJ997bwAAAPU"]
[Thu Jul 30 15:33:32.533436 2026] [security2:error] [pid 189611:tid 189822] [client 172.237.109.114:2430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1HOWE7BvPuUzLJ997dAAAANY"]
[Thu Jul 30 15:33:32.553160 2026] [security2:error] [pid 189611:tid 189758] [client 20.171.55.167:10894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/1234.php"] [unique_id "amu1HOWE7BvPuUzLJ997hgAAAJY"]
[Thu Jul 30 15:33:32.609931 2026] [security2:error] [pid 189611:tid 189844] [client 20.226.5.174:62144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wsr2.php"] [unique_id "amu1HOWE7BvPuUzLJ997igAAAOw"]
[Thu Jul 30 15:33:32.911574 2026] [core:notice] [pid 189611:tid 189637] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:32.929234 2026] [core:notice] [pid 189611:tid 189649] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:32.945027 2026] [proxy:error] [pid 189611:tid 189837] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:32.945097 2026] [proxy_http:error] [pid 189611:tid 189837] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:32.945662 2026] [proxy:error] [pid 189611:tid 189837] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:32.945705 2026] [proxy_http:error] [pid 189611:tid 189837] [client 20.9.4.9:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:32.945791 2026] [security2:error] [pid 189611:tid 189837] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu1HOWE7BvPuUzLJ997kAAAAOU"]
[Thu Jul 30 15:33:32.970377 2026] [core:notice] [pid 189611:tid 189651] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:32.988989 2026] [core:notice] [pid 189611:tid 189653] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:32.988992 2026] [core:notice] [pid 189611:tid 189652] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.017378 2026] [core:notice] [pid 189611:tid 189643] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.020899 2026] [core:notice] [pid 189611:tid 189720] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.031044 2026] [proxy:error] [pid 189611:tid 189776] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:33.031109 2026] [proxy_http:error] [pid 189611:tid 189776] [client 52.202.41.153:39171] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:33.031675 2026] [proxy:error] [pid 189611:tid 189776] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:33.031727 2026] [proxy_http:error] [pid 189611:tid 189776] [client 52.202.41.153:39171] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:33.037666 2026] [proxy:error] [pid 189611:tid 189848] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:33.037722 2026] [proxy_http:error] [pid 189611:tid 189848] [client 54.87.222.253:18494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:33.038313 2026] [proxy:error] [pid 189611:tid 189848] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:33.038373 2026] [proxy_http:error] [pid 189611:tid 189848] [client 54.87.222.253:18494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:33.073025 2026] [core:notice] [pid 189611:tid 189639] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.215960 2026] [core:notice] [pid 189611:tid 189640] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.219084 2026] [core:notice] [pid 189611:tid 189657] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.219600 2026] [core:notice] [pid 189611:tid 189656] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.232863 2026] [core:notice] [pid 189611:tid 189646] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.245822 2026] [core:notice] [pid 189611:tid 189658] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.279166 2026] [security2:error] [pid 189611:tid 189789] [client 20.171.55.167:11174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/2015/05/Marvins.php"] [unique_id "amu1HeWE7BvPuUzLJ997qAAAALU"]
[Thu Jul 30 15:33:33.284205 2026] [core:notice] [pid 189611:tid 189659] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.318884 2026] [core:notice] [pid 189611:tid 189664] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.417816 2026] [security2:error] [pid 189611:tid 189851] [client 20.100.187.246:3315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/images/about.php"] [unique_id "amu1HeWE7BvPuUzLJ997rgAAAPM"]
[Thu Jul 30 15:33:33.445400 2026] [security2:error] [pid 189611:tid 189852] [client 20.52.125.110:12695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/feedback.php"] [unique_id "amu1HeWE7BvPuUzLJ997rwAAAPQ"]
[Thu Jul 30 15:33:33.464599 2026] [security2:error] [pid 189611:tid 189816] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-signin.php"] [unique_id "amu1HeWE7BvPuUzLJ997sAAAANA"]
[Thu Jul 30 15:33:33.464689 2026] [security2:error] [pid 189611:tid 189816] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-signin.php"] [unique_id "amu1HeWE7BvPuUzLJ997sAAAANA"]
[Thu Jul 30 15:33:33.479365 2026] [core:notice] [pid 189611:tid 189665] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.679727 2026] [security2:error] [pid 189611:tid 189770] [client 20.226.5.174:62182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wto.php"] [unique_id "amu1HeWE7BvPuUzLJ997uAAAAKI"]
[Thu Jul 30 15:33:33.724407 2026] [core:notice] [pid 189611:tid 189671] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:33.887102 2026] [core:notice] [pid 189611:tid 189675] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:34.047524 2026] [security2:error] [pid 189611:tid 189754] [client 20.171.55.167:10882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/3.php"] [unique_id "amu1HuWE7BvPuUzLJ997xQAAAJI"]
[Thu Jul 30 15:33:34.102315 2026] [security2:error] [pid 189611:tid 189804] [client 20.52.125.110:13011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/gettest.php"] [unique_id "amu1HuWE7BvPuUzLJ997xgAAAMQ"]
[Thu Jul 30 15:33:34.135777 2026] [core:notice] [pid 189611:tid 189674] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:34.326565 2026] [proxy:error] [pid 189611:tid 189863] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:34.326648 2026] [proxy_http:error] [pid 189611:tid 189863] [client 44.216.125.112:12551] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:34.327251 2026] [proxy:error] [pid 189611:tid 189863] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:34.327299 2026] [proxy_http:error] [pid 189611:tid 189863] [client 44.216.125.112:12551] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:34.421512 2026] [proxy:error] [pid 189611:tid 189811] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:34.421594 2026] [proxy_http:error] [pid 189611:tid 189811] [client 18.211.55.47:21812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:34.422300 2026] [proxy:error] [pid 189611:tid 189811] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:33:34.422371 2026] [proxy_http:error] [pid 189611:tid 189811] [client 18.211.55.47:21812] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:33:34.497959 2026] [security2:error] [pid 189611:tid 189803] [client 172.202.44.182:19086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amu1HuWE7BvPuUzLJ9971wAAAMM"]
[Thu Jul 30 15:33:34.691774 2026] [security2:error] [pid 189611:tid 189846] [client 20.52.125.110:12675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/maint.php"] [unique_id "amu1HuWE7BvPuUzLJ9974QAAAO4"]
[Thu Jul 30 15:33:34.725550 2026] [security2:error] [pid 189611:tid 189802] [client 20.226.5.174:62169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wtu.php"] [unique_id "amu1HuWE7BvPuUzLJ9974gAAAMI"]
[Thu Jul 30 15:33:34.811814 2026] [security2:error] [pid 189611:tid 189838] [client 20.171.55.167:11137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/4x4.php"] [unique_id "amu1HuWE7BvPuUzLJ9975AAAAOY"]
[Thu Jul 30 15:33:35.079101 2026] [security2:error] [pid 189611:tid 189859] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/gg.php"] [unique_id "amu1H-WE7BvPuUzLJ9977gAAAPs"]
[Thu Jul 30 15:33:35.079190 2026] [security2:error] [pid 189611:tid 189859] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/gg.php"] [unique_id "amu1H-WE7BvPuUzLJ9977gAAAPs"]
[Thu Jul 30 15:33:35.541651 2026] [security2:error] [pid 189611:tid 189759] [client 20.171.55.167:11192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/8890.php"] [unique_id "amu1H-WE7BvPuUzLJ997-wAAAJc"]
[Thu Jul 30 15:33:35.603290 2026] [security2:error] [pid 189611:tid 189797] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/class.php"] [unique_id "amu1H-WE7BvPuUzLJ997_AAAAL0"]
[Thu Jul 30 15:33:35.603425 2026] [security2:error] [pid 189611:tid 189797] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/class.php"] [unique_id "amu1H-WE7BvPuUzLJ997_AAAAL0"]
[Thu Jul 30 15:33:35.691157 2026] [security2:error] [pid 189611:tid 189786] [client 38.172.162.57:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1H-WE7BvPuUzLJ998AgAAALI"]
[Thu Jul 30 15:33:35.691282 2026] [security2:error] [pid 189611:tid 189786] [client 38.172.162.57:16262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1H-WE7BvPuUzLJ998AgAAALI"]
[Thu Jul 30 15:33:35.725328 2026] [security2:error] [pid 189611:tid 189858] [client 20.226.5.174:62154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wui.php"] [unique_id "amu1H-WE7BvPuUzLJ998AwAAAPo"]
[Thu Jul 30 15:33:35.799682 2026] [security2:error] [pid 189611:tid 189781] [client 20.52.125.110:12703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/files.php"] [unique_id "amu1H-WE7BvPuUzLJ998BgAAAK0"]
[Thu Jul 30 15:33:36.087478 2026] [security2:error] [pid 189611:tid 189780] [client 20.100.187.246:10165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amu1IOWE7BvPuUzLJ998DgAAAKw"]
[Thu Jul 30 15:33:36.150627 2026] [security2:error] [pid 189611:tid 189760] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/404.php"] [unique_id "amu1IOWE7BvPuUzLJ998DwAAAJg"]
[Thu Jul 30 15:33:36.150804 2026] [security2:error] [pid 189611:tid 189760] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/404.php"] [unique_id "amu1IOWE7BvPuUzLJ998DwAAAJg"]
[Thu Jul 30 15:33:36.330422 2026] [security2:error] [pid 189611:tid 189844] [client 20.171.55.167:11170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/Cache/dropdown.php"] [unique_id "amu1IOWE7BvPuUzLJ998EwAAAOw"]
[Thu Jul 30 15:33:36.333580 2026] [security2:error] [pid 189611:tid 189753] [client 20.52.125.110:12688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/gecko.php"] [unique_id "amu1IOWE7BvPuUzLJ998FAAAAJE"]
[Thu Jul 30 15:33:36.376713 2026] [security2:error] [pid 189611:tid 189770] [client 172.202.44.182:63967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amu1IOWE7BvPuUzLJ998FQAAAKI"]
[Thu Jul 30 15:33:36.800882 2026] [security2:error] [pid 189611:tid 189810] [client 20.226.5.174:62152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/ww.php"] [unique_id "amu1IOWE7BvPuUzLJ998HwAAAMo"]
[Thu Jul 30 15:33:37.121242 2026] [security2:error] [pid 189611:tid 189814] [client 20.171.55.167:11143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/Diff/Engine/priv.php"] [unique_id "amu1IeWE7BvPuUzLJ998KQAAAM4"]
[Thu Jul 30 15:33:37.420166 2026] [security2:error] [pid 189611:tid 189830] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/lite.php"] [unique_id "amu1IeWE7BvPuUzLJ998LQAAAN4"]
[Thu Jul 30 15:33:37.420294 2026] [security2:error] [pid 189611:tid 189830] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/lite.php"] [unique_id "amu1IeWE7BvPuUzLJ998LQAAAN4"]
[Thu Jul 30 15:33:37.562875 2026] [security2:error] [pid 189611:tid 189742] [client 20.52.125.110:12971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/zwso.php"] [unique_id "amu1IeWE7BvPuUzLJ998MQAAAIY"]
[Thu Jul 30 15:33:37.873751 2026] [security2:error] [pid 189611:tid 189744] [client 20.226.5.174:62164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/www.php"] [unique_id "amu1IeWE7BvPuUzLJ998OQAAAIg"]
[Thu Jul 30 15:33:37.878005 2026] [security2:error] [pid 189611:tid 189743] [client 20.171.55.167:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/FoxWSO-full.php"] [unique_id "amu1IeWE7BvPuUzLJ998OgAAAIc"]
[Thu Jul 30 15:33:37.926428 2026] [security2:error] [pid 189611:tid 189759] [client 20.100.187.246:1549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amu1IeWE7BvPuUzLJ998OwAAAJc"]
[Thu Jul 30 15:33:38.120282 2026] [security2:error] [pid 189611:tid 189841] [client 172.202.44.182:22026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/edit.php"] [unique_id "amu1IuWE7BvPuUzLJ998PwAAAOk"]
[Thu Jul 30 15:33:38.131942 2026] [security2:error] [pid 189611:tid 189845] [client 20.52.125.110:12684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/13.php"] [unique_id "amu1IuWE7BvPuUzLJ998QAAAAO0"]
[Thu Jul 30 15:33:38.162707 2026] [security2:error] [pid 189611:tid 189745] [client 74.7.244.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.dubaiappliance.repair"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "amu1IuWE7BvPuUzLJ998QQAAiVI"]
[Thu Jul 30 15:33:38.588132 2026] [security2:error] [pid 189611:tid 189822] [client 20.171.55.167:10881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/M1.php"] [unique_id "amu1IuWE7BvPuUzLJ998SQAAANY"]
[Thu Jul 30 15:33:38.793098 2026] [security2:error] [pid 189611:tid 189844] [client 20.118.34.237:12290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "igetvapesonline.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amu1IuWE7BvPuUzLJ998UwAAAOw"]
[Thu Jul 30 15:33:38.822739 2026] [security2:error] [pid 189611:tid 189842] [client 20.100.187.246:4079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amu1IuWE7BvPuUzLJ998VwAAAOo"]
[Thu Jul 30 15:33:38.910206 2026] [core:notice] [pid 189611:tid 189769] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:38.943517 2026] [security2:error] [pid 189611:tid 189867] [client 20.226.5.174:62167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wxo.php"] [unique_id "amu1IuWE7BvPuUzLJ998XAAAAQM"]
[Thu Jul 30 15:33:39.118329 2026] [security2:error] [pid 189611:tid 189866] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/lock360.php"] [unique_id "amu1I-WE7BvPuUzLJ998XQAAAQI"]
[Thu Jul 30 15:33:39.118489 2026] [security2:error] [pid 189611:tid 189866] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/lock360.php"] [unique_id "amu1I-WE7BvPuUzLJ998XQAAAQI"]
[Thu Jul 30 15:33:39.195294 2026] [security2:error] [pid 189611:tid 189792] [client 20.52.125.110:12936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/ava.php"] [unique_id "amu1I-WE7BvPuUzLJ998YQAAALg"]
[Thu Jul 30 15:33:39.387416 2026] [security2:error] [pid 189611:tid 189835] [client 20.171.55.167:10384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/RxR_euzcx.php"] [unique_id "amu1I-WE7BvPuUzLJ998agAAAOM"]
[Thu Jul 30 15:33:39.753972 2026] [security2:error] [pid 189611:tid 189817] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "amu1I-WE7BvPuUzLJ998cgAAANE"]
[Thu Jul 30 15:33:39.754129 2026] [security2:error] [pid 189611:tid 189817] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "amu1I-WE7BvPuUzLJ998cgAAANE"]
[Thu Jul 30 15:33:39.839612 2026] [security2:error] [pid 189611:tid 189851] [client 20.52.125.110:12697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/main.php"] [unique_id "amu1I-WE7BvPuUzLJ998dwAAAPM"]
[Thu Jul 30 15:33:39.938806 2026] [security2:error] [pid 189611:tid 189852] [client 20.226.5.174:62171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/wzy.php"] [unique_id "amu1I-WE7BvPuUzLJ998fAAAAPQ"]
[Thu Jul 30 15:33:40.097262 2026] [security2:error] [pid 189611:tid 189818] [client 20.171.55.167:10887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/Summer2010/-/gif.php"] [unique_id "amu1JOWE7BvPuUzLJ998fQAAANI"]
[Thu Jul 30 15:33:40.251357 2026] [security2:error] [pid 189611:tid 189855] [client 20.100.187.246:3373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/cloud.php"] [unique_id "amu1JOWE7BvPuUzLJ998ggAAAPc"]
[Thu Jul 30 15:33:40.650250 2026] [security2:error] [pid 189611:tid 189760] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-links-opml.php"] [unique_id "amu1JOWE7BvPuUzLJ998iAAAAJg"]
[Thu Jul 30 15:33:40.650428 2026] [security2:error] [pid 189611:tid 189760] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-links-opml.php"] [unique_id "amu1JOWE7BvPuUzLJ998iAAAAJg"]
[Thu Jul 30 15:33:40.854121 2026] [security2:error] [pid 189611:tid 189780] [client 20.171.55.167:11155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/XxX.php"] [unique_id "amu1JOWE7BvPuUzLJ998jwAAAKw"]
[Thu Jul 30 15:33:40.894994 2026] [security2:error] [pid 189611:tid 189752] [client 20.226.5.174:62190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/x.php"] [unique_id "amu1JOWE7BvPuUzLJ998kwAAAJA"]
[Thu Jul 30 15:33:41.088646 2026] [core:error] [pid 189611:tid 189867] [client 17.22.245.207:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:33:41.088670 2026] [core:error] [pid 189611:tid 189867] [client 17.22.245.207:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:33:41.255970 2026] [security2:error] [pid 189611:tid 189838] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/uploads/min.php"] [unique_id "amu1JeWE7BvPuUzLJ998mQAAAOY"]
[Thu Jul 30 15:33:41.256093 2026] [security2:error] [pid 189611:tid 189838] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.lapakjitu78.com"] [uri "/wp-content/uploads/min.php"] [unique_id "amu1JeWE7BvPuUzLJ998mQAAAOY"]
[Thu Jul 30 15:33:41.581109 2026] [security2:error] [pid 189611:tid 189798] [client 20.171.55.167:11184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/about.php"] [unique_id "amu1JeWE7BvPuUzLJ998owAAAL4"]
[Thu Jul 30 15:33:41.834815 2026] [security2:error] [pid 189611:tid 189751] [client 20.52.125.110:12706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/wp-file.php"] [unique_id "amu1JeWE7BvPuUzLJ998qAAAAI8"]
[Thu Jul 30 15:33:41.862263 2026] [security2:error] [pid 189611:tid 189820] [client 20.100.187.246:9803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amu1JeWE7BvPuUzLJ998qwAAANQ"]
[Thu Jul 30 15:33:41.893131 2026] [security2:error] [pid 189611:tid 189774] [client 20.226.5.174:62186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/x1.php"] [unique_id "amu1JeWE7BvPuUzLJ998rAAAAKY"]
[Thu Jul 30 15:33:42.429700 2026] [security2:error] [pid 189611:tid 189819] [client 20.171.55.167:11154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/admin%201.php"] [unique_id "amu1JuWE7BvPuUzLJ998tgAAANM"]
[Thu Jul 30 15:33:42.804477 2026] [security2:error] [pid 189611:tid 189858] [client 20.100.187.246:1187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/updates.php"] [unique_id "amu1JuWE7BvPuUzLJ998vgAAAPo"]
[Thu Jul 30 15:33:42.872773 2026] [security2:error] [pid 189611:tid 189788] [client 20.226.5.174:62163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/x35.php"] [unique_id "amu1JuWE7BvPuUzLJ998wgAAALQ"]
[Thu Jul 30 15:33:43.129311 2026] [autoindex:error] [pid 189611:tid 189824] [client 146.251.181.223:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:33:43.224144 2026] [core:notice] [pid 189611:tid 189739] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:43.496587 2026] [security2:error] [pid 189611:tid 189622] [remote 57.141.0.32:64356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amu1J-WE7BvPuUzLJ9981gAAzQo"]
[Thu Jul 30 15:33:43.537158 2026] [security2:error] [pid 189611:tid 189822] [client 20.171.55.167:11199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/administratoralfa.php"] [unique_id "amu1J-WE7BvPuUzLJ998ywAAANY"]
[Thu Jul 30 15:33:43.598832 2026] [security2:error] [pid 189611:tid 189780] [client 20.100.187.246:6869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/css/cloud.php"] [unique_id "amu1J-WE7BvPuUzLJ9982gAAAKw"]
[Thu Jul 30 15:33:43.878366 2026] [security2:error] [pid 189611:tid 189857] [client 20.52.125.110:13006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/wp-signin.php"] [unique_id "amu1J-WE7BvPuUzLJ9983QAAAPk"]
[Thu Jul 30 15:33:43.917811 2026] [security2:error] [pid 189611:tid 189762] [client 20.226.5.174:62170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/x7.php"] [unique_id "amu1J-WE7BvPuUzLJ9983wAAAJo"]
[Thu Jul 30 15:33:44.243859 2026] [security2:error] [pid 189611:tid 189789] [client 20.171.55.167:11187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/ajax-actions.php"] [unique_id "amu1KOWE7BvPuUzLJ9985wAAALU"]
[Thu Jul 30 15:33:44.695115 2026] [autoindex:error] [pid 189611:tid 189743] [client 1.145.79.59:0] AH01276: Cannot serve directory /home2/mbmudite/tiger388.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:33:44.887275 2026] [security2:error] [pid 189611:tid 189761] [client 20.226.5.174:62157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/xBrain.php"] [unique_id "amu1KOWE7BvPuUzLJ998-AAAAJk"]
[Thu Jul 30 15:33:44.951666 2026] [security2:error] [pid 189611:tid 189777] [client 20.171.55.167:10895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/alfa1337.php"] [unique_id "amu1KOWE7BvPuUzLJ998_AAAAKk"]
[Thu Jul 30 15:33:44.965456 2026] [security2:error] [pid 189611:tid 189798] [client 20.100.187.246:4345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amu1KOWE7BvPuUzLJ998_QAAAL4"]
[Thu Jul 30 15:33:45.002712 2026] [security2:error] [pid 189611:tid 189623] [remote 74.7.243.224:41422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/js/article.php"] [unique_id "amu1KeWE7BvPuUzLJ999AAAA0gs"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 15:33:45.204306 2026] [security2:error] [pid 189611:tid 189824] [client 213.152.162.84:41784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amu1KeWE7BvPuUzLJ999BwAAANg"]
[Thu Jul 30 15:33:45.204435 2026] [security2:error] [pid 189611:tid 189824] [client 213.152.162.84:41784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amu1KeWE7BvPuUzLJ999BwAAANg"]
[Thu Jul 30 15:33:45.460421 2026] [core:notice] [pid 189611:tid 189810] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:45.545260 2026] [security2:error] [pid 189611:tid 189807] [client 172.237.109.114:47933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KeWE7BvPuUzLJ999AwAAAMc"]
[Thu Jul 30 15:33:45.549367 2026] [security2:error] [pid 189611:tid 189801] [client 20.52.125.110:12960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/simi.php"] [unique_id "amu1KeWE7BvPuUzLJ999EwAAAME"]
[Thu Jul 30 15:33:45.590643 2026] [security2:error] [pid 189611:tid 189788] [client 172.237.109.114:20117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KeWE7BvPuUzLJ999AgAAALQ"]
[Thu Jul 30 15:33:45.713265 2026] [security2:error] [pid 189611:tid 189793] [client 20.171.55.167:11168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/alfav4-1.php"] [unique_id "amu1KeWE7BvPuUzLJ999GAAAALk"]
[Thu Jul 30 15:33:45.857223 2026] [security2:error] [pid 189611:tid 189866] [client 20.226.5.174:62193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/xLB2NXAP.php"] [unique_id "amu1KeWE7BvPuUzLJ999GQAAAQI"]
[Thu Jul 30 15:33:45.961355 2026] [security2:error] [pid 189611:tid 189813] [client 38.172.162.57:15898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1KeWE7BvPuUzLJ999GgAAAM0"]
[Thu Jul 30 15:33:45.961508 2026] [security2:error] [pid 189611:tid 189813] [client 38.172.162.57:15898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1KeWE7BvPuUzLJ999GgAAAM0"]
[Thu Jul 30 15:33:46.176680 2026] [security2:error] [pid 189611:tid 189630] [remote 57.141.0.38:25004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/458796423/feed/rss2/"] [unique_id "amu1KuWE7BvPuUzLJ999JQAAthI"]
[Thu Jul 30 15:33:46.353589 2026] [core:notice] [pid 189611:tid 189634] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:46.435802 2026] [security2:error] [pid 189611:tid 189785] [client 20.171.55.167:10891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/anons79.php"] [unique_id "amu1KuWE7BvPuUzLJ999KgAAALE"]
[Thu Jul 30 15:33:46.512195 2026] [security2:error] [pid 189611:tid 189789] [client 172.237.109.114:47181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KuWE7BvPuUzLJ999HgAAALU"]
[Thu Jul 30 15:33:46.898796 2026] [security2:error] [pid 189611:tid 189809] [client 20.226.5.174:62172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/x_maxs.php"] [unique_id "amu1KuWE7BvPuUzLJ999OQAAAMk"]
[Thu Jul 30 15:33:46.929022 2026] [security2:error] [pid 189611:tid 189795] [client 51.75.23.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu1KuWE7BvPuUzLJ999OAAAALs"]
[Thu Jul 30 15:33:47.082173 2026] [security2:error] [pid 189611:tid 189822] [client 20.100.187.246:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/img/cloud.php"] [unique_id "amu1K-WE7BvPuUzLJ999RwAAANY"]
[Thu Jul 30 15:33:47.221213 2026] [security2:error] [pid 189611:tid 189863] [client 20.171.55.167:11160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/applicationbypass.php"] [unique_id "amu1K-WE7BvPuUzLJ999TwAAAP8"]
[Thu Jul 30 15:33:47.542190 2026] [security2:error] [pid 189611:tid 189860] [client 172.237.109.114:1654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KuWE7BvPuUzLJ999PQAAAPw"]
[Thu Jul 30 15:33:47.578393 2026] [security2:error] [pid 189611:tid 189855] [client 172.237.109.114:16153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KuWE7BvPuUzLJ999PAAAAPc"]
[Thu Jul 30 15:33:47.626275 2026] [security2:error] [pid 189611:tid 189771] [client 172.237.109.114:40347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KuWE7BvPuUzLJ999PgAAAKM"]
[Thu Jul 30 15:33:47.627904 2026] [security2:error] [pid 189611:tid 189758] [client 172.237.109.114:64483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KuWE7BvPuUzLJ999QAAAAJY"]
[Thu Jul 30 15:33:47.646335 2026] [security2:error] [pid 189611:tid 189811] [client 172.237.109.114:36818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KuWE7BvPuUzLJ999PwAAAMs"]
[Thu Jul 30 15:33:47.646353 2026] [security2:error] [pid 189611:tid 189824] [client 172.237.109.114:60950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KuWE7BvPuUzLJ999QQAAANg"]
[Thu Jul 30 15:33:47.647942 2026] [security2:error] [pid 189611:tid 189784] [client 172.237.109.114:9640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1KuWE7BvPuUzLJ999QgAAALA"]
[Thu Jul 30 15:33:47.684349 2026] [security2:error] [pid 189611:tid 189843] [client 172.237.109.114:54191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1K-WE7BvPuUzLJ999QwAAAOs"]
[Thu Jul 30 15:33:47.838622 2026] [security2:error] [pid 189611:tid 189652] [remote 52.167.144.147:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/195"] [unique_id "amu1K-WE7BvPuUzLJ999XAABAig"]
[Thu Jul 30 15:33:47.840642 2026] [security2:error] [pid 189611:tid 189801] [client 20.226.5.174:62179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/xc.php"] [unique_id "amu1K-WE7BvPuUzLJ999XQAAAME"]
[Thu Jul 30 15:33:47.962138 2026] [security2:error] [pid 189611:tid 189826] [client 172.237.109.114:42888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/v4/graphql.php"] [unique_id "amu1K-WE7BvPuUzLJ999XwAAANo"]
[Thu Jul 30 15:33:47.977962 2026] [security2:error] [pid 189611:tid 189805] [client 172.237.109.114:34527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/v4/graphiql.php"] [unique_id "amu1K-WE7BvPuUzLJ999YwAAAMU"]
[Thu Jul 30 15:33:47.978464 2026] [security2:error] [pid 189611:tid 189861] [client 20.171.55.167:11191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/asetalfa.php"] [unique_id "amu1K-WE7BvPuUzLJ999ZAAAAP0"]
[Thu Jul 30 15:33:48.059474 2026] [security2:error] [pid 189611:tid 189851] [client 172.202.44.182:33469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/sf.php"] [unique_id "amu1LOWE7BvPuUzLJ999agAAAPM"]
[Thu Jul 30 15:33:48.489258 2026] [security2:error] [pid 189611:tid 189754] [client 51.77.211.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu1LOWE7BvPuUzLJ999eQAAAJI"]
[Thu Jul 30 15:33:48.572910 2026] [security2:error] [pid 189611:tid 189830] [client 172.237.109.114:60179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1K-WE7BvPuUzLJ999ZQAAAN4"]
[Thu Jul 30 15:33:48.592156 2026] [security2:error] [pid 189611:tid 189767] [client 172.237.109.114:47560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1K-WE7BvPuUzLJ999YgAAAJ8"]
[Thu Jul 30 15:33:48.594441 2026] [security2:error] [pid 189611:tid 189742] [client 172.237.109.114:37289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1K-WE7BvPuUzLJ999YQAAAIY"]
[Thu Jul 30 15:33:48.603231 2026] [security2:error] [pid 189611:tid 189817] [client 172.237.109.114:1169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1LOWE7BvPuUzLJ999ZwAAANE"]
[Thu Jul 30 15:33:48.603939 2026] [security2:error] [pid 189611:tid 189862] [client 172.237.109.114:27885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1LOWE7BvPuUzLJ999aQAAAP4"]
[Thu Jul 30 15:33:48.604287 2026] [security2:error] [pid 189611:tid 189825] [client 172.237.109.114:62783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1K-WE7BvPuUzLJ999ZgAAANk"]
[Thu Jul 30 15:33:48.610092 2026] [security2:error] [pid 189611:tid 189790] [client 172.237.109.114:17693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1LOWE7BvPuUzLJ999aAAAALY"]
[Thu Jul 30 15:33:48.697366 2026] [security2:error] [pid 189611:tid 189845] [client 20.171.55.167:11142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/aua.php"] [unique_id "amu1LOWE7BvPuUzLJ999fQAAAO0"]
[Thu Jul 30 15:33:48.857438 2026] [security2:error] [pid 189611:tid 189743] [client 20.226.5.174:62181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azureskyfilms.com"] [uri "/xcv.php"] [unique_id "amu1LOWE7BvPuUzLJ999hAAAAIc"]
[Thu Jul 30 15:33:49.215382 2026] [security2:error] [pid 189611:tid 189741] [client 20.52.125.110:12941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/wp-conf.php"] [unique_id "amu1LeWE7BvPuUzLJ999jAAAAIU"]
[Thu Jul 30 15:33:49.280344 2026] [security2:error] [pid 189611:tid 189788] [client 172.202.44.182:22023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wso.php"] [unique_id "amu1LeWE7BvPuUzLJ999kAAAALQ"]
[Thu Jul 30 15:33:49.477790 2026] [security2:error] [pid 189611:tid 189828] [client 20.171.55.167:11140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/ayk.php"] [unique_id "amu1LeWE7BvPuUzLJ999lAAAANw"]
[Thu Jul 30 15:33:49.627163 2026] [security2:error] [pid 189611:tid 189792] [client 202.65.236.51:10363] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "pkf.jo"] [uri "/"] [unique_id "amu1LeWE7BvPuUzLJ999lQAAALg"]
[Thu Jul 30 15:33:49.820880 2026] [security2:error] [pid 189611:tid 189794] [client 68.67.112.82:45354] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "kicksity.com"] [uri "/robots.txt"] [unique_id "amu1LeWE7BvPuUzLJ999oAAAALo"]
[Thu Jul 30 15:33:49.850245 2026] [security2:error] [pid 189611:tid 189772] [client 202.65.236.51:9495] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "pkf.jo"] [uri "/wp-json/batch/v1"] [unique_id "amu1LeWE7BvPuUzLJ999oQAAAKQ"]
[Thu Jul 30 15:33:49.970181 2026] [security2:error] [pid 189611:tid 189775] [client 74.7.228.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wrf.zzt.temporary.site"] [uri "/index.php"] [unique_id "amu1LOWE7BvPuUzLJ999cAAAAKc"]
[Thu Jul 30 15:33:49.971153 2026] [security2:error] [pid 189611:tid 189773] [client 74.7.228.34:55810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "wrf.zzt.temporary.site"] [uri "/robots.txt"] [unique_id "amu1LOWE7BvPuUzLJ999bgAApWw"]
[Thu Jul 30 15:33:50.147969 2026] [security2:error] [pid 189611:tid 189797] [client 172.237.109.114:53051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/button/readme.txt"] [unique_id "amu1LuWE7BvPuUzLJ999pwAAAL0"]
[Thu Jul 30 15:33:50.213912 2026] [security2:error] [pid 189611:tid 189778] [client 51.38.115.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu1LuWE7BvPuUzLJ999pgAAAKo"]
[Thu Jul 30 15:33:50.239908 2026] [security2:error] [pid 189611:tid 189763] [client 20.171.55.167:10897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/bb.php"] [unique_id "amu1LuWE7BvPuUzLJ999rAAAAJs"]
[Thu Jul 30 15:33:50.327763 2026] [security2:error] [pid 189611:tid 189819] [client 202.65.236.51:3524] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu1LuWE7BvPuUzLJ999owAAANM"]
[Thu Jul 30 15:33:50.555745 2026] [security2:error] [pid 189611:tid 189761] [client 20.52.125.110:12970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/WZGHHra0r3.php"] [unique_id "amu1LuWE7BvPuUzLJ999tAAAAJk"]
[Thu Jul 30 15:33:50.664528 2026] [core:notice] [pid 189611:tid 189666] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:50.968307 2026] [security2:error] [pid 189611:tid 189867] [client 20.171.55.167:11188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/bless.php"] [unique_id "amu1LuWE7BvPuUzLJ999xQAAAQM"]
[Thu Jul 30 15:33:51.013320 2026] [security2:error] [pid 189611:tid 189853] [client 172.202.44.182:42058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/ioxi-o.php"] [unique_id "amu1L-WE7BvPuUzLJ999xgAAAPU"]
[Thu Jul 30 15:33:51.598735 2026] [security2:error] [pid 189611:tid 189782] [client 20.52.125.110:13000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/bala.php"] [unique_id "amu1L-WE7BvPuUzLJ9996gAAAK4"]
[Thu Jul 30 15:33:51.727191 2026] [security2:error] [pid 189611:tid 189804] [client 20.171.55.167:10889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/bootstrapbypass.php"] [unique_id "amu1L-WE7BvPuUzLJ9996wAAAMQ"]
[Thu Jul 30 15:33:51.934465 2026] [core:notice] [pid 189611:tid 189709] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:52.190929 2026] [core:notice] [pid 189611:tid 189864] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:52.280796 2026] [security2:error] [pid 189611:tid 189744] [client 172.202.44.182:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/file56.php"] [unique_id "amu1MOWE7BvPuUzLJ999-wAAAIg"]
[Thu Jul 30 15:33:52.313177 2026] [security2:error] [pid 189611:tid 189783] [client 20.100.187.246:4292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amu1MOWE7BvPuUzLJ999_AAAAK8"]
[Thu Jul 30 15:33:52.434265 2026] [security2:error] [pid 189611:tid 189781] [client 20.171.55.167:10935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/bv3.php"] [unique_id "amu1MOWE7BvPuUzLJ99-FQAAAK0"]
[Thu Jul 30 15:33:53.174211 2026] [security2:error] [pid 189611:tid 189857] [client 20.171.55.167:10883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/cachek.php"] [unique_id "amu1MeWE7BvPuUzLJ99-PgAAAPk"]
[Thu Jul 30 15:33:53.518666 2026] [security2:error] [pid 189611:tid 189741] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1MOWE7BvPuUzLJ99-KQAAAIU"]
[Thu Jul 30 15:33:53.883475 2026] [security2:error] [pid 189611:tid 189795] [client 20.171.55.167:11176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/cc.php"] [unique_id "amu1MeWE7BvPuUzLJ99-XQAAALs"]
[Thu Jul 30 15:33:54.234388 2026] [security2:error] [pid 189611:tid 189863] [client 20.100.187.246:19292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amu1MuWE7BvPuUzLJ99-aQAAAP8"]
[Thu Jul 30 15:33:54.667321 2026] [security2:error] [pid 189611:tid 189632] [remote 2a03:2880:f800:5:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1MuWE7BvPuUzLJ99-ZQAAoBQ"]
[Thu Jul 30 15:33:54.745315 2026] [security2:error] [pid 189611:tid 189760] [client 172.202.44.182:33446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amu1MuWE7BvPuUzLJ99-eQAAAJg"]
[Thu Jul 30 15:33:54.999112 2026] [security2:error] [pid 189611:tid 189824] [client 20.171.55.167:10892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/cgialfak.php"] [unique_id "amu1MuWE7BvPuUzLJ99-gAAAANg"]
[Thu Jul 30 15:33:55.011069 2026] [security2:error] [pid 189611:tid 189793] [client 202.155.143.185:54744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.143.155.202.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amu1MuWE7BvPuUzLJ99-egAAALk"], referer: https://thdinfinity.com/
[Thu Jul 30 15:33:55.083839 2026] [security2:error] [pid 189611:tid 189775] [client 20.52.125.110:12715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/bk.php"] [unique_id "amu1M-WE7BvPuUzLJ99-hwAAAKc"]
[Thu Jul 30 15:33:55.464835 2026] [security2:error] [pid 189611:tid 189864] [client 74.7.230.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.inmobiliariadia.com"] [uri "/cgi-sys/404.html"] [unique_id "amu1M-WE7BvPuUzLJ99-lwAAAQA"]
[Thu Jul 30 15:33:55.465450 2026] [security2:error] [pid 189611:tid 189850] [client 74.7.230.45:60598] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.inmobiliariadia.com"] [uri "/robots.txt"] [unique_id "amu1M-WE7BvPuUzLJ99-lQAA8is"]
[Thu Jul 30 15:33:55.533379 2026] [security2:error] [pid 189611:tid 189813] [client 20.100.187.246:6693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/avaa.php"] [unique_id "amu1M-WE7BvPuUzLJ99-nwAAAM0"]
[Thu Jul 30 15:33:55.708434 2026] [security2:error] [pid 189611:tid 189810] [client 20.52.125.110:12935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.125.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.radiojelli.com"] [uri "/ahax.php"] [unique_id "amu1M-WE7BvPuUzLJ99-pAAAAMo"]
[Thu Jul 30 15:33:55.778410 2026] [security2:error] [pid 189611:tid 189777] [client 20.171.55.167:10890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/class-ftp-pures.php"] [unique_id "amu1M-WE7BvPuUzLJ99-pgAAAKk"]
[Thu Jul 30 15:33:56.294583 2026] [autoindex:error] [pid 189611:tid 189762] [client 74.7.243.226:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:33:56.363055 2026] [security2:error] [pid 189611:tid 189812] [client 159.69.158.189:53544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amu1NOWE7BvPuUzLJ99-tgAAAMw"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:33:56.500927 2026] [security2:error] [pid 189611:tid 189851] [client 20.171.55.167:11150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/class-wp-filesystem-ftpsockets.php"] [unique_id "amu1NOWE7BvPuUzLJ99-vQAAAPM"]
[Thu Jul 30 15:33:56.701273 2026] [security2:error] [pid 189611:tid 189745] [client 38.172.162.57:16428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1NOWE7BvPuUzLJ99-xwAAAIk"]
[Thu Jul 30 15:33:56.701406 2026] [security2:error] [pid 189611:tid 189745] [client 38.172.162.57:16428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1NOWE7BvPuUzLJ99-xwAAAIk"]
[Thu Jul 30 15:33:56.911397 2026] [core:notice] [pid 189611:tid 189782] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:56.916858 2026] [security2:error] [pid 189611:tid 189782] [client 159.69.158.189:53554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amu1NOWE7BvPuUzLJ99-ygAAAK4"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:33:57.279097 2026] [security2:error] [pid 189611:tid 189849] [client 20.171.55.167:11157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/class-wp-session-href.php"] [unique_id "amu1NeWE7BvPuUzLJ99-1QAAAPE"]
[Thu Jul 30 15:33:57.483069 2026] [security2:error] [pid 189611:tid 189787] [client 74.7.228.27:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "whe.djb.temporary.site"] [uri "/index.php"] [unique_id "amu1M-WE7BvPuUzLJ99-lAAAALM"]
[Thu Jul 30 15:33:57.483889 2026] [security2:error] [pid 189611:tid 189751] [client 74.7.228.27:54144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "whe.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amu1M-WE7BvPuUzLJ99-kgAAjyU"]
[Thu Jul 30 15:33:57.507059 2026] [security2:error] [pid 189611:tid 189832] [client 159.69.158.189:53560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amu1NeWE7BvPuUzLJ99-1wAAAOA"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:33:57.542424 2026] [security2:error] [pid 189611:tid 189858] [client 172.202.44.182:40413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-admin/css/index.php"] [unique_id "amu1NeWE7BvPuUzLJ99-2gAAAPo"]
[Thu Jul 30 15:33:57.682378 2026] [security2:error] [pid 189611:tid 189742] [client 20.100.187.246:7139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/images/cloud.php"] [unique_id "amu1NeWE7BvPuUzLJ99-3wAAAIY"]
[Thu Jul 30 15:33:58.001244 2026] [security2:error] [pid 189611:tid 189863] [client 20.171.55.167:11167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/classsmtps.php"] [unique_id "amu1NuWE7BvPuUzLJ99-6gAAAP8"]
[Thu Jul 30 15:33:58.706357 2026] [security2:error] [pid 189611:tid 189799] [client 20.171.55.167:11173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/color/blue/maintenence.php"] [unique_id "amu1NuWE7BvPuUzLJ99-_QAAAL8"]
[Thu Jul 30 15:33:58.803452 2026] [core:notice] [pid 189611:tid 189686] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:59.091735 2026] [core:notice] [pid 189611:tid 189864] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:59.093966 2026] [security2:error] [pid 189611:tid 189852] [client 20.100.187.246:4138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amu1N-WE7BvPuUzLJ99_DQAAAPQ"]
[Thu Jul 30 15:33:59.297426 2026] [core:notice] [pid 189611:tid 189692] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:33:59.431542 2026] [security2:error] [pid 189611:tid 189751] [client 20.171.55.167:11145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/colors/blue/ds.php"] [unique_id "amu1N-WE7BvPuUzLJ99_IAAAAI8"]
[Thu Jul 30 15:33:59.596260 2026] [core:notice] [pid 189611:tid 189807] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:00.213424 2026] [security2:error] [pid 189611:tid 189741] [client 20.171.55.167:10899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/colors/coffee/admin.php"] [unique_id "amu1OOWE7BvPuUzLJ99_UQAAAIU"]
[Thu Jul 30 15:34:00.941454 2026] [security2:error] [pid 189611:tid 189750] [client 20.171.55.167:11189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/colors/coffee/xmrlpc.php"] [unique_id "amu1OOWE7BvPuUzLJ99_fAAAAI4"]
[Thu Jul 30 15:34:00.971328 2026] [security2:error] [pid 189611:tid 189798] [client 20.100.187.246:6971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amu1OOWE7BvPuUzLJ99_fQAAAL4"]
[Thu Jul 30 15:34:01.650347 2026] [security2:error] [pid 189611:tid 189848] [client 20.171.55.167:10369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/colors/light/profile.php"] [unique_id "amu1OeWE7BvPuUzLJ99_nAAAAPA"]
[Thu Jul 30 15:34:01.693023 2026] [security2:error] [pid 189611:tid 189822] [client 172.202.44.182:63987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/edit.php"] [unique_id "amu1OeWE7BvPuUzLJ99_nQAAANY"]
[Thu Jul 30 15:34:02.017607 2026] [core:notice] [pid 189611:tid 189700] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:02.043311 2026] [security2:error] [pid 189611:tid 189788] [client 20.100.187.246:28759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amu1OuWE7BvPuUzLJ99_rAAAALQ"]
[Thu Jul 30 15:34:02.104777 2026] [security2:error] [pid 189611:tid 189827] [client 57.141.0.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1OeWE7BvPuUzLJ99_mAAAANs"]
[Thu Jul 30 15:34:02.379862 2026] [security2:error] [pid 189611:tid 189745] [client 20.171.55.167:11138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/colors/sunrise/colors_95.php"] [unique_id "amu1OuWE7BvPuUzLJ99_tgAAAIk"]
[Thu Jul 30 15:34:02.497395 2026] [security2:error] [pid 189611:tid 189759] [client 172.237.109.114:13728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1OeWE7BvPuUzLJ99_pwAAAJc"]
[Thu Jul 30 15:34:02.502615 2026] [security2:error] [pid 189611:tid 189772] [client 172.237.109.114:62443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1OuWE7BvPuUzLJ99_qgAAAKQ"]
[Thu Jul 30 15:34:02.670694 2026] [core:notice] [pid 189611:tid 189807] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:02.857289 2026] [security2:error] [pid 189611:tid 189846] [client 172.202.44.182:40437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/2.php"] [unique_id "amu1OuWE7BvPuUzLJ99_wQAAAO4"]
[Thu Jul 30 15:34:03.156336 2026] [security2:error] [pid 189611:tid 189853] [client 20.171.55.167:11185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/compat.php"] [unique_id "amu1O-WE7BvPuUzLJ99_ywAAAPU"]
[Thu Jul 30 15:34:03.232713 2026] [security2:error] [pid 189611:tid 189787] [client 20.100.187.246:26961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amu1O-WE7BvPuUzLJ99_zAAAALM"]
[Thu Jul 30 15:34:03.304216 2026] [security2:error] [pid 189611:tid 189800] [client 66.249.74.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amu1OuWE7BvPuUzLJ99_rwAAAMA"]
[Thu Jul 30 15:34:03.452656 2026] [security2:error] [pid 189611:tid 189762] [client 172.237.109.114:63355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1OuWE7BvPuUzLJ99_yQAAAJo"]
[Thu Jul 30 15:34:03.777801 2026] [security2:error] [pid 189611:tid 189792] [client 172.202.44.182:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amu1O-WE7BvPuUzLJ99_3AAAALg"]
[Thu Jul 30 15:34:03.872438 2026] [security2:error] [pid 189611:tid 189789] [client 20.171.55.167:11169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/cong.php"] [unique_id "amu1O-WE7BvPuUzLJ99_3wAAALU"]
[Thu Jul 30 15:34:04.394563 2026] [core:notice] [pid 189611:tid 189753] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:04.464870 2026] [security2:error] [pid 189611:tid 189754] [client 172.237.109.114:22323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1O-WE7BvPuUzLJ99_5AAAAJI"]
[Thu Jul 30 15:34:04.598153 2026] [security2:error] [pid 189611:tid 189777] [client 20.171.55.167:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/core885.php"] [unique_id "amu1POWE7BvPuUzLJ99_9AAAAKk"]
[Thu Jul 30 15:34:05.307683 2026] [security2:error] [pid 189611:tid 189749] [client 20.171.55.167:10900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/css-ready/file.php"] [unique_id "amu1PeWE7BvPuUzLJ9-AAgAAAI0"]
[Thu Jul 30 15:34:05.588437 2026] [security2:error] [pid 189611:tid 189707] [remote 57.141.0.47:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amu1PeWE7BvPuUzLJ9-ADAAAwF8"]
[Thu Jul 30 15:34:05.932110 2026] [proxy:error] [pid 189611:tid 189843] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:34:05.932166 2026] [proxy_http:error] [pid 189611:tid 189843] [client 87.236.176.3:33199] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:34:05.932738 2026] [proxy:error] [pid 189611:tid 189843] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:34:05.932779 2026] [proxy_http:error] [pid 189611:tid 189843] [client 87.236.176.3:33199] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:34:06.002652 2026] [security2:error] [pid 189611:tid 189765] [client 172.202.44.182:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/mah.php"] [unique_id "amu1PuWE7BvPuUzLJ9-AGwAAAJ0"]
[Thu Jul 30 15:34:06.093070 2026] [security2:error] [pid 189611:tid 189830] [client 20.171.55.167:10905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/dashboardk.php"] [unique_id "amu1PuWE7BvPuUzLJ9-AIAAAAN4"]
[Thu Jul 30 15:34:06.411528 2026] [security2:error] [pid 189611:tid 189746] [client 31.94.31.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu1PuWE7BvPuUzLJ9-AJgAAAIo"], referer: https://cnpinyin.com
[Thu Jul 30 15:34:06.635848 2026] [security2:error] [pid 189611:tid 189767] [client 20.100.187.246:1643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amu1PuWE7BvPuUzLJ9-ALwAAAJ8"]
[Thu Jul 30 15:34:06.936037 2026] [security2:error] [pid 189611:tid 189779] [client 20.171.55.167:10931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/debug.php"] [unique_id "amu1PuWE7BvPuUzLJ9-ANgAAAKs"]
[Thu Jul 30 15:34:07.245009 2026] [security2:error] [pid 189611:tid 189828] [client 172.202.44.182:40416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/send.php"] [unique_id "amu1P-WE7BvPuUzLJ9-AQwAAANw"]
[Thu Jul 30 15:34:07.342484 2026] [security2:error] [pid 189611:tid 189853] [client 38.172.162.57:16547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1P-WE7BvPuUzLJ9-ARAAAAPU"]
[Thu Jul 30 15:34:07.342633 2026] [security2:error] [pid 189611:tid 189853] [client 38.172.162.57:16547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1P-WE7BvPuUzLJ9-ARAAAAPU"]
[Thu Jul 30 15:34:07.534501 2026] [security2:error] [pid 189611:tid 189633] [remote 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1PuWE7BvPuUzLJ9-ANQAA2RU"]
[Thu Jul 30 15:34:07.688271 2026] [security2:error] [pid 189611:tid 189776] [client 57.141.0.25:50328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koriusa.info"] [uri "/index.php"] [unique_id "amu1PeWE7BvPuUzLJ9-AAwAAqAA"]
[Thu Jul 30 15:34:07.737068 2026] [security2:error] [pid 189611:tid 189778] [client 57.141.0.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1P-WE7BvPuUzLJ9-APwAAAKo"]
[Thu Jul 30 15:34:07.828673 2026] [security2:error] [pid 189611:tid 189789] [client 20.171.55.167:11179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/dev.php"] [unique_id "amu1P-WE7BvPuUzLJ9-AUAAAALU"]
[Thu Jul 30 15:34:07.861017 2026] [core:notice] [pid 189611:tid 189647] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:08.069518 2026] [security2:error] [pid 189611:tid 189790] [client 20.100.187.246:1460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/cloud.php"] [unique_id "amu1QOWE7BvPuUzLJ9-AUgAAALY"]
[Thu Jul 30 15:34:08.257394 2026] [core:notice] [pid 189611:tid 189654] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:08.551406 2026] [security2:error] [pid 189611:tid 189764] [client 20.171.55.167:10396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/dist/edit-widgets/index.php"] [unique_id "amu1QOWE7BvPuUzLJ9-AYgAAAJw"]
[Thu Jul 30 15:34:08.964749 2026] [security2:error] [pid 189611:tid 189749] [client 20.100.187.246:26970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/updates.php"] [unique_id "amu1QOWE7BvPuUzLJ9-AcAAAAI0"]
[Thu Jul 30 15:34:09.029535 2026] [security2:error] [pid 189611:tid 189754] [client 172.202.44.182:40424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amu1QeWE7BvPuUzLJ9-AcgAAAJI"]
[Thu Jul 30 15:34:09.158048 2026] [security2:error] [pid 189611:tid 189866] [client 57.141.0.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1QOWE7BvPuUzLJ9-AZQAAAQI"]
[Thu Jul 30 15:34:09.289139 2026] [security2:error] [pid 189611:tid 189842] [client 20.171.55.167:10885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/docsbypass.php"] [unique_id "amu1QeWE7BvPuUzLJ9-AegAAAOo"]
[Thu Jul 30 15:34:09.520765 2026] [security2:error] [pid 189611:tid 189834] [client 134.19.179.139:44900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amu1QeWE7BvPuUzLJ9-AgAAAAOI"]
[Thu Jul 30 15:34:09.520871 2026] [security2:error] [pid 189611:tid 189834] [client 134.19.179.139:44900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "myintentionalreset.com"] [uri "/xmlrpc.php"] [unique_id "amu1QeWE7BvPuUzLJ9-AgAAAAOI"]
[Thu Jul 30 15:34:09.653171 2026] [core:notice] [pid 189611:tid 189650] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.664201 2026] [core:notice] [pid 189611:tid 189720] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.684128 2026] [security2:error] [pid 189611:tid 189833] [client 20.100.187.246:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amu1QeWE7BvPuUzLJ9-AiQAAAOE"]
[Thu Jul 30 15:34:09.714087 2026] [core:notice] [pid 189611:tid 189663] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.735346 2026] [core:notice] [pid 189611:tid 189661] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.736052 2026] [core:notice] [pid 189611:tid 189674] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.753806 2026] [core:notice] [pid 189611:tid 189670] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.754252 2026] [core:notice] [pid 189611:tid 189671] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.812377 2026] [core:notice] [pid 189611:tid 189673] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.896394 2026] [core:notice] [pid 189611:tid 189649] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.901759 2026] [core:notice] [pid 189611:tid 189681] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.955686 2026] [core:notice] [pid 189611:tid 189675] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.974391 2026] [core:notice] [pid 189611:tid 189683] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.974517 2026] [core:notice] [pid 189611:tid 189677] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:09.996160 2026] [security2:error] [pid 189611:tid 189765] [client 20.171.55.167:10921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/download.php"] [unique_id "amu1QeWE7BvPuUzLJ9-AoAAAAJ0"]
[Thu Jul 30 15:34:10.016779 2026] [core:notice] [pid 189611:tid 189688] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:10.124590 2026] [core:notice] [pid 189611:tid 189660] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:10.173406 2026] [core:notice] [pid 189611:tid 189687] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:10.415507 2026] [core:notice] [pid 189611:tid 189685] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:10.469135 2026] [security2:error] [pid 189611:tid 189846] [client 20.100.187.246:1448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amu1QuWE7BvPuUzLJ9-AtwAAAO4"]
[Thu Jul 30 15:34:10.596272 2026] [core:notice] [pid 189611:tid 189695] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:10.602123 2026] [security2:error] [pid 189611:tid 189779] [client 139.28.219.70:60796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amu1QuWE7BvPuUzLJ9-AuQAAAKs"]
[Thu Jul 30 15:34:10.684847 2026] [security2:error] [pid 189611:tid 189749] [client 204.8.98.55:34182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amu1QuWE7BvPuUzLJ9-AugAAAI0"]
[Thu Jul 30 15:34:10.684948 2026] [security2:error] [pid 189611:tid 189749] [client 204.8.98.55:34182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amu1QuWE7BvPuUzLJ9-AugAAAI0"]
[Thu Jul 30 15:34:10.752771 2026] [security2:error] [pid 189611:tid 189761] [client 20.171.55.167:11156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/editor.php"] [unique_id "amu1QuWE7BvPuUzLJ9-AvgAAAJk"]
[Thu Jul 30 15:34:10.847029 2026] [core:notice] [pid 189611:tid 189684] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:10.877202 2026] [security2:error] [pid 189611:tid 189837] [client 57.141.0.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1QuWE7BvPuUzLJ9-ArgAAAOU"]
[Thu Jul 30 15:34:10.885176 2026] [security2:error] [pid 189611:tid 189842] [client 139.28.219.70:60202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "asian-connect.com"] [uri "/xmlrpc.php"] [unique_id "amu1QuWE7BvPuUzLJ9-AxwAAAOo"]
[Thu Jul 30 15:34:11.411231 2026] [security2:error] [pid 189611:tid 189824] [client 139.28.219.70:60212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amu1Q-WE7BvPuUzLJ9-A2QAAANg"]
[Thu Jul 30 15:34:11.467114 2026] [security2:error] [pid 189611:tid 189788] [client 20.171.55.167:11182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/envato-market/inc/class-envato-market-github.php"] [unique_id "amu1Q-WE7BvPuUzLJ9-A2gAAALQ"]
[Thu Jul 30 15:34:11.689040 2026] [security2:error] [pid 189611:tid 189751] [client 139.28.219.70:60222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amu1Q-WE7BvPuUzLJ9-A6QAAAI8"]
[Thu Jul 30 15:34:11.865751 2026] [security2:error] [pid 189611:tid 189797] [client 20.100.187.246:28768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amu1Q-WE7BvPuUzLJ9-A9gAAAL0"]
[Thu Jul 30 15:34:11.941290 2026] [security2:error] [pid 189611:tid 189761] [client 172.202.44.182:42068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/about.php"] [unique_id "amu1Q-WE7BvPuUzLJ9-A-QAAAJk"]
[Thu Jul 30 15:34:11.953764 2026] [security2:error] [pid 189611:tid 189867] [client 139.28.219.70:60228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amu1Q-WE7BvPuUzLJ9-A-wAAAQM"]
[Thu Jul 30 15:34:11.997853 2026] [security2:error] [pid 189611:tid 189709] [remote 110.249.202.24:10952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/assets/images/morning-desert-safari-atv.jpg"] [unique_id "amu1Q-WE7BvPuUzLJ9-A_wAApmE"]
[Thu Jul 30 15:34:12.229415 2026] [security2:error] [pid 189611:tid 189825] [client 139.28.219.70:60242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amu1ROWE7BvPuUzLJ9-BBwAAANk"]
[Thu Jul 30 15:34:12.244515 2026] [security2:error] [pid 189611:tid 189772] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1Q-WE7BvPuUzLJ9-A3QAApEM"]
[Thu Jul 30 15:34:12.254472 2026] [security2:error] [pid 189611:tid 189763] [client 20.171.55.167:10914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/extension/extension/Not_Found.php"] [unique_id "amu1ROWE7BvPuUzLJ9-BCwAAAJs"]
[Thu Jul 30 15:34:12.494180 2026] [security2:error] [pid 189611:tid 189745] [client 139.28.219.70:60256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amu1ROWE7BvPuUzLJ9-BEgAAAIk"]
[Thu Jul 30 15:34:12.761917 2026] [security2:error] [pid 189611:tid 189810] [client 139.28.219.70:60270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amu1ROWE7BvPuUzLJ9-BFQAAAMo"]
[Thu Jul 30 15:34:12.898108 2026] [core:notice] [pid 189611:tid 189821] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:12.989215 2026] [security2:error] [pid 189611:tid 189850] [client 20.171.55.167:10910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/fdgfdgdsfd.php"] [unique_id "amu1ROWE7BvPuUzLJ9-BJQAAAPI"]
[Thu Jul 30 15:34:13.033204 2026] [security2:error] [pid 189611:tid 189858] [client 139.28.219.70:60276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amu1ReWE7BvPuUzLJ9-BKQAAAPo"]
[Thu Jul 30 15:34:13.042089 2026] [security2:error] [pid 189611:tid 189854] [client 172.202.44.182:33444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/options.php"] [unique_id "amu1ReWE7BvPuUzLJ9-BKgAAAPY"]
[Thu Jul 30 15:34:13.299053 2026] [security2:error] [pid 189611:tid 189754] [client 139.28.219.70:60282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amu1ReWE7BvPuUzLJ9-BMAAAAJI"]
[Thu Jul 30 15:34:13.509794 2026] [core:notice] [pid 189611:tid 189846] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:13.566721 2026] [security2:error] [pid 189611:tid 189772] [client 139.28.219.70:60294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amu1ReWE7BvPuUzLJ9-BPAAAAKQ"]
[Thu Jul 30 15:34:13.722960 2026] [security2:error] [pid 189611:tid 189863] [client 20.171.55.167:10880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/file6.php"] [unique_id "amu1ReWE7BvPuUzLJ9-BPgAAAP8"]
[Thu Jul 30 15:34:13.826366 2026] [security2:error] [pid 189611:tid 189795] [client 139.28.219.70:60308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amu1ReWE7BvPuUzLJ9-BQgAAALs"]
[Thu Jul 30 15:34:14.090749 2026] [security2:error] [pid 189611:tid 189838] [client 139.28.219.70:60322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amu1RuWE7BvPuUzLJ9-BTAAAAOY"]
[Thu Jul 30 15:34:14.367370 2026] [security2:error] [pid 189611:tid 189809] [client 20.100.187.246:28773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/alfa-rex.php7"] [unique_id "amu1RuWE7BvPuUzLJ9-BXQAAAMk"]
[Thu Jul 30 15:34:14.368061 2026] [security2:error] [pid 189611:tid 189777] [client 139.28.219.70:60334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amu1RuWE7BvPuUzLJ9-BXgAAAKk"]
[Thu Jul 30 15:34:14.517150 2026] [security2:error] [pid 189611:tid 189861] [client 20.171.55.167:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/filedokumenk.php"] [unique_id "amu1RuWE7BvPuUzLJ9-BZAAAAP0"]
[Thu Jul 30 15:34:14.636212 2026] [security2:error] [pid 189611:tid 189816] [client 139.28.219.70:60338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amu1RuWE7BvPuUzLJ9-BawAAANA"]
[Thu Jul 30 15:34:14.727731 2026] [autoindex:error] [pid 189611:tid 189760] [client 202.78.167.117:0] AH01276: Cannot serve directory /home2/mbmudite/ok.koidomino.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://ok.koidomino.click/
[Thu Jul 30 15:34:14.896747 2026] [security2:error] [pid 189611:tid 189748] [client 139.28.219.70:60344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asian-connect.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "amu1RuWE7BvPuUzLJ9-BcAAAAIw"]
[Thu Jul 30 15:34:15.261515 2026] [security2:error] [pid 189611:tid 189805] [client 20.171.55.167:10379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/fix/up.php"] [unique_id "amu1R-WE7BvPuUzLJ9-BegAAAMU"]
[Thu Jul 30 15:34:15.481856 2026] [core:notice] [pid 189611:tid 189739] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:15.719409 2026] [core:notice] [pid 189611:tid 189622] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:15.838858 2026] [core:error] [pid 189611:tid 189626] [remote 74.7.228.4:37950] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:34:15.838881 2026] [core:error] [pid 189611:tid 189626] [remote 74.7.228.4:37950] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:34:15.839055 2026] [security2:error] [pid 189611:tid 189789] [client 74.7.228.4:37950] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-6b70ee5c.wrf.zzt.temporary.site"] [uri "/website_6b70ee5c/index.php"] [unique_id "amu1R-WE7BvPuUzLJ9-BigAAtQ4"]
[Thu Jul 30 15:34:15.960487 2026] [security2:error] [pid 189611:tid 189730] [remote 57.141.0.46:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/45275225219/feed/rss2/"] [unique_id "amu1R-WE7BvPuUzLJ9-BjwAA4XY"]
[Thu Jul 30 15:34:16.010948 2026] [security2:error] [pid 189611:tid 189745] [client 20.171.55.167:11162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/foxx.php"] [unique_id "amu1SOWE7BvPuUzLJ9-BkgAAAIk"]
[Thu Jul 30 15:34:16.540466 2026] [core:notice] [pid 189611:tid 189615] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:16.797192 2026] [security2:error] [pid 189611:tid 189864] [client 20.171.55.167:10930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/geck.php"] [unique_id "amu1SOWE7BvPuUzLJ9-BrQAAAQA"]
[Thu Jul 30 15:34:16.863261 2026] [security2:error] [pid 189611:tid 189783] [client 20.100.187.246:29732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/alfanew.php"] [unique_id "amu1SOWE7BvPuUzLJ9-BrgAAAK8"]
[Thu Jul 30 15:34:16.894514 2026] [core:notice] [pid 189611:tid 189707] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:17.031109 2026] [core:notice] [pid 189611:tid 189623] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:17.310653 2026] [core:notice] [pid 189611:tid 189624] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:17.505553 2026] [security2:error] [pid 189611:tid 189824] [client 20.171.55.167:11163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/gmo.php"] [unique_id "amu1SeWE7BvPuUzLJ9-BvwAAANg"]
[Thu Jul 30 15:34:17.671826 2026] [security2:error] [pid 189611:tid 189774] [client 2a03:2880:f800:f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "spececigarette.com"] [uri "/wp-login.php"] [unique_id "amu1R-WE7BvPuUzLJ9-BfwAApno"]
[Thu Jul 30 15:34:17.972184 2026] [security2:error] [pid 189611:tid 189868] [client 38.172.162.57:16564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1SeWE7BvPuUzLJ9-B1QAAAQQ"]
[Thu Jul 30 15:34:17.972313 2026] [security2:error] [pid 189611:tid 189868] [client 38.172.162.57:16564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1SeWE7BvPuUzLJ9-B1QAAAQQ"]
[Thu Jul 30 15:34:18.206076 2026] [core:notice] [pid 189611:tid 189854] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:18.281971 2026] [security2:error] [pid 189611:tid 189797] [client 20.171.55.167:10920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/gzdecode.php"] [unique_id "amu1SuWE7BvPuUzLJ9-B5AAAAL0"]
[Thu Jul 30 15:34:19.021483 2026] [security2:error] [pid 189611:tid 189755] [client 20.171.55.167:11175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/hi.php"] [unique_id "amu1S-WE7BvPuUzLJ9-B9wAAAJM"]
[Thu Jul 30 15:34:19.790731 2026] [security2:error] [pid 189611:tid 189859] [client 172.202.44.182:63995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-content/themes/index.php"] [unique_id "amu1S-WE7BvPuUzLJ9-CCwAAAPs"]
[Thu Jul 30 15:34:19.800816 2026] [security2:error] [pid 189611:tid 189866] [client 134.19.179.139:42966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amu1S-WE7BvPuUzLJ9-CDAAAAQI"]
[Thu Jul 30 15:34:19.800890 2026] [security2:error] [pid 189611:tid 189866] [client 134.19.179.139:42966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghggeneralcontracting.com"] [uri "/xmlrpc.php"] [unique_id "amu1S-WE7BvPuUzLJ9-CDAAAAQI"]
[Thu Jul 30 15:34:19.909659 2026] [security2:error] [pid 189611:tid 189758] [client 20.171.55.167:10394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/i0004en.php//bk/index.php"] [unique_id "amu1S-WE7BvPuUzLJ9-CEAAAAJY"]
[Thu Jul 30 15:34:20.178053 2026] [security2:error] [pid 189611:tid 189760] [client 20.100.187.246:7208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amu1TOWE7BvPuUzLJ9-CEwAAAJg"]
[Thu Jul 30 15:34:20.190607 2026] [security2:error] [pid 189611:tid 189811] [client 213.165.69.184:39394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "kicksity.com"] [uri "/xmlrpc.php"] [unique_id "amu1TOWE7BvPuUzLJ9-CFgAAAMs"]
[Thu Jul 30 15:34:20.190741 2026] [security2:error] [pid 189611:tid 189811] [client 213.165.69.184:39394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "kicksity.com"] [uri "/xmlrpc.php"] [unique_id "amu1TOWE7BvPuUzLJ9-CFgAAAMs"]
[Thu Jul 30 15:34:20.634657 2026] [security2:error] [pid 189611:tid 189851] [client 20.171.55.167:11193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/imagealfa.php"] [unique_id "amu1TOWE7BvPuUzLJ9-CJQAAAPM"]
[Thu Jul 30 15:34:21.252148 2026] [security2:error] [pid 189611:tid 189785] [client 172.202.44.182:33433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/wp-file.php"] [unique_id "amu1TeWE7BvPuUzLJ9-CMAAAALE"]
[Thu Jul 30 15:34:21.406164 2026] [security2:error] [pid 189611:tid 189830] [client 20.171.55.167:10924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/includeswp-conflg.php"] [unique_id "amu1TeWE7BvPuUzLJ9-COwAAAN4"]
[Thu Jul 30 15:34:21.477054 2026] [core:notice] [pid 189611:tid 189819] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:22.114952 2026] [security2:error] [pid 189611:tid 189835] [client 20.171.55.167:11197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/instaall.php"] [unique_id "amu1TuWE7BvPuUzLJ9-CRwAAAOM"]
[Thu Jul 30 15:34:22.226804 2026] [security2:error] [pid 189611:tid 189764] [client 43.173.174.113:41704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Perspective/article/view/6089"] [unique_id "amu1TuWE7BvPuUzLJ9-CSAAAAJw"]
[Thu Jul 30 15:34:22.511530 2026] [security2:error] [pid 189611:tid 189859] [client 172.202.44.182:33435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.44.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hoki188win.com"] [uri "/sid3.php"] [unique_id "amu1TuWE7BvPuUzLJ9-CVAAAAPs"]
[Thu Jul 30 15:34:22.858641 2026] [core:notice] [pid 189611:tid 189863] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:22.889291 2026] [security2:error] [pid 189611:tid 189783] [client 20.171.55.167:11148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/iqb.php"] [unique_id "amu1TuWE7BvPuUzLJ9-CXQAAAK8"]
[Thu Jul 30 15:34:23.172051 2026] [security2:error] [pid 189611:tid 189829] [client 20.100.187.246:7194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amu1T-WE7BvPuUzLJ9-CawAAAN0"]
[Thu Jul 30 15:34:23.173549 2026] [security2:error] [pid 189611:tid 189854] [client 57.141.0.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1TuWE7BvPuUzLJ9-CVwAAAPY"]
[Thu Jul 30 15:34:23.432702 2026] [core:notice] [pid 189611:tid 189660] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:23.591440 2026] [core:notice] [pid 189611:tid 189868] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:23.600103 2026] [security2:error] [pid 189611:tid 189759] [client 20.171.55.167:10397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/joomlabypass.php"] [unique_id "amu1T-WE7BvPuUzLJ9-CgwAAAJc"]
[Thu Jul 30 15:34:23.693659 2026] [security2:error] [pid 189611:tid 189776] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1T-WE7BvPuUzLJ9-CaAAAAKg"]
[Thu Jul 30 15:34:23.911032 2026] [core:notice] [pid 189611:tid 189859] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:23.912833 2026] [core:notice] [pid 189611:tid 189800] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:24.039011 2026] [security2:error] [pid 189611:tid 189840] [client 57.141.0.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1T-WE7BvPuUzLJ9-CewAAAOg"]
[Thu Jul 30 15:34:24.121251 2026] [security2:error] [pid 189611:tid 189747] [client 57.141.0.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1T-WE7BvPuUzLJ9-CgQAAAIs"]
[Thu Jul 30 15:34:24.343228 2026] [security2:error] [pid 189611:tid 189762] [client 20.171.55.167:10399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/karak.php"] [unique_id "amu1UOWE7BvPuUzLJ9-ClAAAAJo"]
[Thu Jul 30 15:34:24.953516 2026] [security2:error] [pid 189611:tid 189839] [client 2a03:2880:f800:27:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1UOWE7BvPuUzLJ9-ClQAA508"]
[Thu Jul 30 15:34:25.030874 2026] [core:notice] [pid 189611:tid 189773] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:25.065133 2026] [security2:error] [pid 189611:tid 189853] [client 20.171.55.167:11194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/leaf_php.php"] [unique_id "amu1UeWE7BvPuUzLJ9-CrQAAAPU"]
[Thu Jul 30 15:34:25.233473 2026] [security2:error] [pid 189611:tid 189682] [remote 12.55.19.110:63071] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.shorewooddaycare.com"] [uri "/contact.php"] [unique_id "amu1UeWE7BvPuUzLJ9-CtAAA4UY"], referer: https://www.shorewooddaycare.com/contact.php
[Thu Jul 30 15:34:25.303141 2026] [security2:error] [pid 189611:tid 189694] [remote 57.141.0.22:33740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/33637472792/feed/rss2/"] [unique_id "amu1UeWE7BvPuUzLJ9-CtQAAsVI"]
[Thu Jul 30 15:34:25.901670 2026] [security2:error] [pid 189611:tid 189834] [client 20.171.55.167:10916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/linkpreview/alfa.php"] [unique_id "amu1UeWE7BvPuUzLJ9-CwwAAAOI"]
[Thu Jul 30 15:34:26.138792 2026] [security2:error] [pid 189611:tid 189722] [remote 152.53.111.131:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.palmtreepools.ca"] [uri "/wp-login.php"] [unique_id "amu1UuWE7BvPuUzLJ9-CywAAk24"]
[Thu Jul 30 15:34:26.172393 2026] [core:error] [pid 189611:tid 189799] [client 74.7.244.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:34:26.172423 2026] [core:error] [pid 189611:tid 189799] [client 74.7.244.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:34:26.172591 2026] [security2:error] [pid 189611:tid 189799] [client 74.7.244.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.jvw.gzj.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amu1UuWE7BvPuUzLJ9-C0QAAAL8"]
[Thu Jul 30 15:34:26.173219 2026] [security2:error] [pid 189611:tid 189859] [client 74.7.244.9:42948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.jvw.gzj.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amu1UuWE7BvPuUzLJ9-CzgAA-zg"]
[Thu Jul 30 15:34:26.678261 2026] [security2:error] [pid 189611:tid 189805] [client 20.171.55.167:11172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/lnedx.php"] [unique_id "amu1UuWE7BvPuUzLJ9-C3QAAAMU"]
[Thu Jul 30 15:34:26.853239 2026] [core:notice] [pid 189611:tid 189714] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:27.466636 2026] [security2:error] [pid 189611:tid 189849] [client 20.171.55.167:11161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/luxx.php"] [unique_id "amu1U-WE7BvPuUzLJ9-C6QAAAPE"]
[Thu Jul 30 15:34:27.853993 2026] [security2:error] [pid 189611:tid 189717] [remote 57.141.0.47:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4142453994/feed/rss2/"] [unique_id "amu1U-WE7BvPuUzLJ9-C9gAA02k"]
[Thu Jul 30 15:34:27.885367 2026] [security2:error] [pid 189611:tid 189761] [client 20.100.187.246:1630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-p.php7"] [unique_id "amu1U-WE7BvPuUzLJ9-C9wAAAJk"]
[Thu Jul 30 15:34:28.268369 2026] [security2:error] [pid 189611:tid 189741] [client 20.171.55.167:11196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/maintenance.php"] [unique_id "amu1VOWE7BvPuUzLJ9-DAwAAAIU"]
[Thu Jul 30 15:34:28.527493 2026] [security2:error] [pid 189611:tid 189868] [client 38.172.162.57:16590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1VOWE7BvPuUzLJ9-DBwAAAQQ"]
[Thu Jul 30 15:34:28.527622 2026] [security2:error] [pid 189611:tid 189868] [client 38.172.162.57:16590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1VOWE7BvPuUzLJ9-DBwAAAQQ"]
[Thu Jul 30 15:34:29.021237 2026] [security2:error] [pid 189611:tid 189859] [client 20.171.55.167:10915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/mas.php"] [unique_id "amu1VeWE7BvPuUzLJ9-DFAAAAPs"]
[Thu Jul 30 15:34:29.823093 2026] [security2:error] [pid 189611:tid 189778] [client 20.171.55.167:10386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/mediaadmin.php"] [unique_id "amu1VeWE7BvPuUzLJ9-DKQAAAKo"]
[Thu Jul 30 15:34:30.275558 2026] [security2:error] [pid 189611:tid 189762] [client 2a03:2880:f800:43:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1VeWE7BvPuUzLJ9-DIwAAmn8"]
[Thu Jul 30 15:34:30.654969 2026] [security2:error] [pid 189611:tid 189753] [client 20.171.55.167:10896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/moddofuns.php"] [unique_id "amu1VuWE7BvPuUzLJ9-DOQAAAJE"]
[Thu Jul 30 15:34:30.868944 2026] [security2:error] [pid 189611:tid 189667] [remote 5.161.62.209:3386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mty.djb.temporary.site"] [uri "/.env"] [unique_id "amu1VuWE7BvPuUzLJ9-DOwAAkjc"]
[Thu Jul 30 15:34:31.115308 2026] [security2:error] [pid 189611:tid 189780] [client 204.8.98.55:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amu1V-WE7BvPuUzLJ9-DRQAAAKw"]
[Thu Jul 30 15:34:31.115406 2026] [security2:error] [pid 189611:tid 189780] [client 204.8.98.55:35996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amu1V-WE7BvPuUzLJ9-DRQAAAKw"]
[Thu Jul 30 15:34:31.311356 2026] [core:notice] [pid 189611:tid 189707] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:31.675542 2026] [security2:error] [pid 189611:tid 189797] [client 20.100.187.246:1612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-admin/repeater.php"] [unique_id "amu1V-WE7BvPuUzLJ9-DVAAAAL0"]
[Thu Jul 30 15:34:31.884163 2026] [security2:error] [pid 189611:tid 189822] [client 20.171.55.167:10932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/mrjn.php"] [unique_id "amu1V-WE7BvPuUzLJ9-DVQAAANY"]
[Thu Jul 30 15:34:32.600881 2026] [security2:error] [pid 189611:tid 189766] [client 20.100.187.246:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-includes/repeater.php"] [unique_id "amu1WOWE7BvPuUzLJ9-DcAAAAJ4"]
[Thu Jul 30 15:34:32.632651 2026] [security2:error] [pid 189611:tid 189794] [client 57.141.0.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1V-WE7BvPuUzLJ9-DXgAAALo"]
[Thu Jul 30 15:34:32.650123 2026] [security2:error] [pid 189611:tid 189853] [client 20.171.55.167:10939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/ndak/marijuana.php"] [unique_id "amu1WOWE7BvPuUzLJ9-DdQAAAPU"]
[Thu Jul 30 15:34:33.405821 2026] [security2:error] [pid 189611:tid 189855] [client 20.171.55.167:11151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/noriumportfolio/alpha.php"] [unique_id "amu1WeWE7BvPuUzLJ9-DgwAAAPc"]
[Thu Jul 30 15:34:34.190452 2026] [security2:error] [pid 189611:tid 189856] [client 20.171.55.167:11019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/olux.php"] [unique_id "amu1WuWE7BvPuUzLJ9-DmwAAAPg"]
[Thu Jul 30 15:34:35.012927 2026] [security2:error] [pid 189611:tid 189765] [client 20.171.55.167:10911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/pDPTEa.php"] [unique_id "amu1W-WE7BvPuUzLJ9-DrgAAAJ0"]
[Thu Jul 30 15:34:35.876312 2026] [security2:error] [pid 189611:tid 189848] [client 20.171.55.167:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/php.php"] [unique_id "amu1W-WE7BvPuUzLJ9-DxQAAAPA"]
[Thu Jul 30 15:34:36.489759 2026] [proxy:error] [pid 189611:tid 189782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:34:36.489838 2026] [proxy_http:error] [pid 189611:tid 189782] [client 74.7.228.35:43960] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:34:36.490490 2026] [proxy:error] [pid 189611:tid 189782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:34:36.490536 2026] [proxy_http:error] [pid 189611:tid 189782] [client 74.7.228.35:43960] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:34:36.490644 2026] [security2:error] [pid 189611:tid 189782] [client 74.7.228.35:43960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.yie.nyx.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amu1XOWE7BvPuUzLJ9-D0wAAAK4"]
[Thu Jul 30 15:34:36.616819 2026] [security2:error] [pid 189611:tid 189867] [client 20.171.55.167:10898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/phpunit/src/Util/PHP/peli.php"] [unique_id "amu1XOWE7BvPuUzLJ9-D1QAAAQM"]
[Thu Jul 30 15:34:37.398564 2026] [security2:error] [pid 189611:tid 189849] [client 20.171.55.167:10938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/pluginsalfa.php"] [unique_id "amu1XeWE7BvPuUzLJ9-D6AAAAPE"]
[Thu Jul 30 15:34:37.744956 2026] [security2:error] [pid 189611:tid 189759] [client 20.100.187.246:1609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.187.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bisbeetour.com"] [uri "/wp-content/repeater.php"] [unique_id "amu1XeWE7BvPuUzLJ9-D7QAAAJc"]
[Thu Jul 30 15:34:38.189540 2026] [security2:error] [pid 189611:tid 189779] [client 20.171.55.167:10402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/ppus/up.php"] [unique_id "amu1XuWE7BvPuUzLJ9-D_AAAAKs"]
[Thu Jul 30 15:34:38.818640 2026] [security2:error] [pid 189611:tid 189861] [client 50.6.43.217:13168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amu1XuWE7BvPuUzLJ9-D-wAAAP0"]
[Thu Jul 30 15:34:39.009938 2026] [security2:error] [pid 189611:tid 189824] [client 20.171.55.167:10893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/priv8.php"] [unique_id "amu1X-WE7BvPuUzLJ9-EFgAAANg"]
[Thu Jul 30 15:34:39.137958 2026] [security2:error] [pid 189611:tid 189811] [client 38.172.162.57:15990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1X-WE7BvPuUzLJ9-EGQAAAMs"]
[Thu Jul 30 15:34:39.138092 2026] [security2:error] [pid 189611:tid 189811] [client 38.172.162.57:15990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1X-WE7BvPuUzLJ9-EGQAAAMs"]
[Thu Jul 30 15:34:39.543688 2026] [security2:error] [pid 189611:tid 189755] [client 50.6.43.217:13170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fireworkskenya.co.ke"] [uri "/index.php"] [unique_id "amu1XuWE7BvPuUzLJ9-ECwAAAJM"]
[Thu Jul 30 15:34:39.744295 2026] [security2:error] [pid 189611:tid 189844] [client 20.171.55.167:10901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/publicbypass.php"] [unique_id "amu1X-WE7BvPuUzLJ9-EJQAAAOw"]
[Thu Jul 30 15:34:40.600817 2026] [security2:error] [pid 189611:tid 189812] [client 20.171.55.167:10385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/racing.php"] [unique_id "amu1YOWE7BvPuUzLJ9-EOQAAAMw"]
[Thu Jul 30 15:34:41.263872 2026] [security2:error] [pid 189611:tid 189694] [remote 74.7.227.39:55688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amu1YeWE7BvPuUzLJ9-ERQAAiFI"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/wp-compat
[Thu Jul 30 15:34:41.749203 2026] [security2:error] [pid 189611:tid 189816] [client 20.171.55.167:10420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/resize.php"] [unique_id "amu1YeWE7BvPuUzLJ9-EUgAAANA"]
[Thu Jul 30 15:34:42.121168 2026] [core:notice] [pid 189611:tid 189668] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:42.716638 2026] [security2:error] [pid 189611:tid 189804] [client 20.171.55.167:10923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/rspp.php"] [unique_id "amu1YuWE7BvPuUzLJ9-EawAAAMQ"]
[Thu Jul 30 15:34:43.501255 2026] [security2:error] [pid 189611:tid 189791] [client 20.171.55.167:10388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/sb.php"] [unique_id "amu1Y-WE7BvPuUzLJ9-EeAAAALc"]
[Thu Jul 30 15:34:43.537402 2026] [core:notice] [pid 189611:tid 189758] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:44.293814 2026] [security2:error] [pid 189611:tid 189847] [client 20.171.55.167:10387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/seoplugins/mar.php"] [unique_id "amu1ZOWE7BvPuUzLJ9-EjwAAAO8"]
[Thu Jul 30 15:34:45.021929 2026] [security2:error] [pid 189611:tid 189810] [client 20.171.55.167:11136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/sh3ll.php"] [unique_id "amu1ZeWE7BvPuUzLJ9-EmgAAAMo"]
[Thu Jul 30 15:34:45.812814 2026] [security2:error] [pid 189611:tid 189820] [client 20.171.55.167:10919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/shxrtr.php"] [unique_id "amu1ZeWE7BvPuUzLJ9-ErgAAANQ"]
[Thu Jul 30 15:34:46.617875 2026] [security2:error] [pid 189611:tid 189741] [client 20.171.55.167:10389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/sitemaps.php"] [unique_id "amu1ZuWE7BvPuUzLJ9-ExAAAAIU"]
[Thu Jul 30 15:34:47.448695 2026] [security2:error] [pid 189611:tid 189845] [client 20.171.55.167:10942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/smilies/file.php"] [unique_id "amu1Z-WE7BvPuUzLJ9-E2AAAAO0"]
[Thu Jul 30 15:34:47.674021 2026] [core:notice] [pid 189611:tid 189629] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:48.261932 2026] [security2:error] [pid 189611:tid 189762] [client 20.171.55.167:10382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/src/index.php"] [unique_id "amu1aOWE7BvPuUzLJ9-E5wAAAJo"]
[Thu Jul 30 15:34:49.043274 2026] [security2:error] [pid 189611:tid 189850] [client 20.171.55.167:10926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/storage/upload/wp.php"] [unique_id "amu1aeWE7BvPuUzLJ9-E-gAAAPI"]
[Thu Jul 30 15:34:49.382614 2026] [security2:error] [pid 189611:tid 189758] [client 173.239.254.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.254.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "n1rmalabet88.com"] [uri "/wp-login.php"] [unique_id "amu1aeWE7BvPuUzLJ9-E-wAAAJY"]
[Thu Jul 30 15:34:49.698076 2026] [security2:error] [pid 189611:tid 189807] [client 38.172.162.57:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1aeWE7BvPuUzLJ9-FBQAAAMc"]
[Thu Jul 30 15:34:49.698247 2026] [security2:error] [pid 189611:tid 189807] [client 38.172.162.57:16335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1aeWE7BvPuUzLJ9-FBQAAAMc"]
[Thu Jul 30 15:34:49.845958 2026] [security2:error] [pid 189611:tid 189848] [client 20.171.55.167:10907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/sym.php"] [unique_id "amu1aeWE7BvPuUzLJ9-FBgAAAPA"]
[Thu Jul 30 15:34:50.356627 2026] [core:notice] [pid 189611:tid 189840] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:50.517148 2026] [security2:error] [pid 189611:tid 189612] [remote 74.7.243.224:40622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/js/article.php"] [unique_id "amu1auWE7BvPuUzLJ9-FGQAA2QA"], referer: https://aded-rdc.org/wp-content/plugins/clever-fox/inc/assets/js/img/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 15:34:50.617187 2026] [security2:error] [pid 189611:tid 189811] [client 20.171.55.167:11040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/templatesdex.php"] [unique_id "amu1auWE7BvPuUzLJ9-FHQAAAMs"]
[Thu Jul 30 15:34:51.295087 2026] [core:notice] [pid 189611:tid 189829] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:51.398827 2026] [security2:error] [pid 189611:tid 189761] [client 20.171.55.167:10902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/themes-install.php"] [unique_id "amu1a-WE7BvPuUzLJ9-FKQAAAJk"]
[Thu Jul 30 15:34:51.971827 2026] [core:notice] [pid 189611:tid 189776] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:52.353432 2026] [security2:error] [pid 189611:tid 189743] [client 20.171.55.167:11044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/tinymce/skins/wordpress/images/about.php"] [unique_id "amu1bOWE7BvPuUzLJ9-FRwAAAIc"]
[Thu Jul 30 15:34:52.553660 2026] [core:notice] [pid 189611:tid 189684] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:52.713550 2026] [core:notice] [pid 189611:tid 189680] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:34:53.253259 2026] [security2:error] [pid 189611:tid 189854] [client 20.171.55.167:10884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/travel/issue.php"] [unique_id "amu1beWE7BvPuUzLJ9-FgQAAAPY"]
[Thu Jul 30 15:34:54.153973 2026] [security2:error] [pid 189611:tid 189786] [client 3.18.101.17:38948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/04/favicon-300x300.jpg"] [unique_id "amu1buWE7BvPuUzLJ9-FqQAAsms"]
[Thu Jul 30 15:34:54.168263 2026] [security2:error] [pid 189611:tid 189751] [client 20.171.55.167:11086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/twentytwentyfour/about.php"] [unique_id "amu1buWE7BvPuUzLJ9-FqgAAAI8"]
[Thu Jul 30 15:34:54.759723 2026] [security2:error] [pid 189611:tid 189820] [client 3.140.193.154:22774] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alseermarine.com"] [uri "/wp-content/uploads/2024/05/parlx-services-commercial-5.jpg"] [unique_id "amu1beWE7BvPuUzLJ9-FmwAA1Gc"]
[Thu Jul 30 15:34:54.939084 2026] [security2:error] [pid 189611:tid 189748] [client 20.171.55.167:11141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/ubh/index.php"] [unique_id "amu1buWE7BvPuUzLJ9-FxwAAAIw"]
[Thu Jul 30 15:34:55.719376 2026] [security2:error] [pid 189611:tid 189757] [client 20.171.55.167:10968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/upload-size.php"] [unique_id "amu1b-WE7BvPuUzLJ9-F4gAAAJU"]
[Thu Jul 30 15:34:56.502465 2026] [security2:error] [pid 189611:tid 189743] [client 20.171.55.167:11003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/upspy/sllolx.php"] [unique_id "amu1cOWE7BvPuUzLJ9-GAQAAAIc"]
[Thu Jul 30 15:34:57.299332 2026] [security2:error] [pid 189611:tid 189627] [remote 57.141.0.32:53330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/4142453994/feed/rss2/"] [unique_id "amu1ceWE7BvPuUzLJ9-GEAAA6A8"]
[Thu Jul 30 15:34:57.311831 2026] [security2:error] [pid 189611:tid 189748] [client 20.171.55.167:10957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/v4.php"] [unique_id "amu1ceWE7BvPuUzLJ9-GEQAAAIw"]
[Thu Jul 30 15:34:57.999769 2026] [security2:error] [pid 189611:tid 189766] [client 185.191.171.15:20144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2016-ano-do-centenario-de-osmar-de-aquino-sera-que-havera-comemoracao/"] [unique_id "amu1ceWE7BvPuUzLJ9-GKwAAAJ4"]
[Thu Jul 30 15:34:57.999920 2026] [security2:error] [pid 189611:tid 189766] [client 185.191.171.15:20144] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2016-ano-do-centenario-de-osmar-de-aquino-sera-que-havera-comemoracao/"] [unique_id "amu1ceWE7BvPuUzLJ9-GKwAAAJ4"]
[Thu Jul 30 15:34:58.100333 2026] [security2:error] [pid 189611:tid 189790] [client 20.171.55.167:11072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/vuln.php"] [unique_id "amu1cuWE7BvPuUzLJ9-GLAAAALY"]
[Thu Jul 30 15:34:58.847261 2026] [security2:error] [pid 189611:tid 189814] [client 20.171.55.167:10986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/weo.php"] [unique_id "amu1cuWE7BvPuUzLJ9-GOQAAAM4"]
[Thu Jul 30 15:34:59.064024 2026] [security2:error] [pid 189611:tid 189835] [client 216.73.216.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.emberleafweeddeliverydispensary.delivery"] [uri "/index.php"] [unique_id "amu1cuWE7BvPuUzLJ9-GQgAAAOM"]
[Thu Jul 30 15:34:59.782425 2026] [security2:error] [pid 189611:tid 189828] [client 20.171.55.167:11002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/widgets/links.php"] [unique_id "amu1c-WE7BvPuUzLJ9-GTAAAANw"]
[Thu Jul 30 15:34:59.948483 2026] [core:notice] [pid 189611:tid 189661] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:00.266895 2026] [security2:error] [pid 189611:tid 189818] [client 38.172.162.57:16605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1dOWE7BvPuUzLJ9-GXAAAANI"]
[Thu Jul 30 15:35:00.267017 2026] [security2:error] [pid 189611:tid 189818] [client 38.172.162.57:16605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1dOWE7BvPuUzLJ9-GXAAAANI"]
[Thu Jul 30 15:35:00.561327 2026] [security2:error] [pid 189611:tid 189769] [client 20.171.55.167:10993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/woocommerce-square/index.php"] [unique_id "amu1dOWE7BvPuUzLJ9-GagAAAKE"]
[Thu Jul 30 15:35:00.819244 2026] [security2:error] [pid 189611:tid 189775] [client 213.152.162.84:43026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu1dOWE7BvPuUzLJ9-GawAAAKc"]
[Thu Jul 30 15:35:00.819394 2026] [security2:error] [pid 189611:tid 189775] [client 213.152.162.84:43026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu1dOWE7BvPuUzLJ9-GawAAAKc"]
[Thu Jul 30 15:35:01.155661 2026] [core:notice] [pid 189611:tid 189689] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.339806 2026] [security2:error] [pid 189611:tid 189754] [client 20.171.55.167:10431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wp-admins.php"] [unique_id "amu1deWE7BvPuUzLJ9-GdgAAAJI"]
[Thu Jul 30 15:35:01.630918 2026] [core:notice] [pid 189611:tid 189662] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.652472 2026] [core:notice] [pid 189611:tid 189672] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.720233 2026] [core:notice] [pid 189611:tid 189691] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.745285 2026] [core:notice] [pid 189611:tid 189692] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.758945 2026] [core:notice] [pid 189611:tid 189678] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.780164 2026] [core:notice] [pid 189611:tid 189676] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.781879 2026] [core:notice] [pid 189611:tid 189694] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.867569 2026] [core:notice] [pid 189611:tid 189682] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.906944 2026] [core:notice] [pid 189611:tid 189702] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.906944 2026] [core:notice] [pid 189611:tid 189697] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.962371 2026] [core:notice] [pid 189611:tid 189709] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:01.998788 2026] [core:notice] [pid 189611:tid 189699] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:02.147852 2026] [security2:error] [pid 189611:tid 189859] [client 57.141.0.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu1deWE7BvPuUzLJ9-GlAAAAPs"]
[Thu Jul 30 15:35:02.205732 2026] [core:notice] [pid 189611:tid 189679] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:02.209936 2026] [core:notice] [pid 189611:tid 189713] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:02.210100 2026] [core:notice] [pid 189611:tid 189715] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:02.294956 2026] [security2:error] [pid 189611:tid 189850] [client 20.171.55.167:10979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wp-commentin.php"] [unique_id "amu1duWE7BvPuUzLJ9-GoQAAAPI"]
[Thu Jul 30 15:35:02.304596 2026] [core:notice] [pid 189611:tid 189723] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:02.607053 2026] [core:notice] [pid 189611:tid 189711] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:02.611327 2026] [core:notice] [pid 189611:tid 189712] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:02.950661 2026] [core:notice] [pid 189611:tid 189703] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:02.996947 2026] [security2:error] [pid 189611:tid 189794] [client 110.249.202.105:13126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiandubaisafari.com"] [uri "/assets/images/dubai-safari-overnight-7.jpg"] [unique_id "amu1duWE7BvPuUzLJ9-GsQAAALo"]
[Thu Jul 30 15:35:03.085615 2026] [security2:error] [pid 189611:tid 189844] [client 20.171.55.167:10987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wp-crom.php"] [unique_id "amu1d-WE7BvPuUzLJ9-GswAAAOw"]
[Thu Jul 30 15:35:03.869385 2026] [security2:error] [pid 189611:tid 189787] [client 20.171.55.167:10951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wp-fmfile.php"] [unique_id "amu1d-WE7BvPuUzLJ9-GxwAAALM"]
[Thu Jul 30 15:35:04.570525 2026] [core:notice] [pid 189611:tid 189721] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:05.068311 2026] [core:notice] [pid 189611:tid 189788] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:05.335259 2026] [core:notice] [pid 189611:tid 189737] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:05.403807 2026] [security2:error] [pid 189611:tid 189840] [client 160.120.14.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1eOWE7BvPuUzLJ9-G0gAA6HU"], referer: https://allmontecristi.com
[Thu Jul 30 15:35:05.459181 2026] [security2:error] [pid 189611:tid 189745] [client 20.171.55.167:10996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wp-maill.php"] [unique_id "amu1eeWE7BvPuUzLJ9-G6gAAAIk"]
[Thu Jul 30 15:35:06.085656 2026] [core:notice] [pid 189611:tid 189619] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:06.169214 2026] [security2:error] [pid 189611:tid 189759] [client 20.171.55.167:10952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wp-root.php"] [unique_id "amu1euWE7BvPuUzLJ9-G_QAAAJc"]
[Thu Jul 30 15:35:06.287284 2026] [security2:error] [pid 189611:tid 189864] [client 204.8.98.55:55404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amu1euWE7BvPuUzLJ9-G_gAAAQA"]
[Thu Jul 30 15:35:06.287392 2026] [security2:error] [pid 189611:tid 189864] [client 204.8.98.55:55404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amu1euWE7BvPuUzLJ9-G_gAAAQA"]
[Thu Jul 30 15:35:06.954183 2026] [security2:error] [pid 189611:tid 189828] [client 20.171.55.167:11001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wp-tinymce.php"] [unique_id "amu1euWE7BvPuUzLJ9-HFwAAANw"]
[Thu Jul 30 15:35:07.018645 2026] [security2:error] [pid 189611:tid 189868] [client 66.249.90.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1euWE7BvPuUzLJ9-HBQAAAQQ"]
[Thu Jul 30 15:35:07.408457 2026] [security2:error] [pid 189611:tid 189748] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1euWE7BvPuUzLJ9-HFgAAAIw"]
[Thu Jul 30 15:35:07.512063 2026] [core:notice] [pid 189611:tid 189732] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:07.907904 2026] [security2:error] [pid 189611:tid 189855] [client 20.171.55.167:10994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wp_wol.php"] [unique_id "amu1e-WE7BvPuUzLJ9-HLAAAAPc"]
[Thu Jul 30 15:35:08.710733 2026] [security2:error] [pid 189611:tid 189784] [client 20.171.55.167:10991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wsanon.php"] [unique_id "amu1fOWE7BvPuUzLJ9-HPAAAALA"]
[Thu Jul 30 15:35:08.752043 2026] [security2:error] [pid 189611:tid 189809] [client 2a03:2880:f800:d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1fOWE7BvPuUzLJ9-HLQAAyQI"]
[Thu Jul 30 15:35:08.999536 2026] [core:notice] [pid 189611:tid 189631] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:09.111656 2026] [core:notice] [pid 189611:tid 189641] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:09.450319 2026] [security2:error] [pid 189611:tid 189833] [client 20.171.55.167:11082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/wzy.php"] [unique_id "amu1feWE7BvPuUzLJ9-HUQAAAOE"]
[Thu Jul 30 15:35:09.632092 2026] [security2:error] [pid 189611:tid 189744] [client 74.7.230.20:52496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.vpv.tqa.temporary.site"] [uri "/robots.txt"] [unique_id "amu1feWE7BvPuUzLJ9-HUgAAAIg"]
[Thu Jul 30 15:35:09.666834 2026] [security2:error] [pid 189611:tid 189632] [remote 157.55.39.10:58403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/humanitaria.php"] [unique_id "amu1feWE7BvPuUzLJ9-HTQAAzxQ"]
[Thu Jul 30 15:35:09.749470 2026] [core:notice] [pid 189611:tid 189674] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:10.340790 2026] [security2:error] [pid 189611:tid 189854] [client 20.171.55.167:11115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/xleet.php"] [unique_id "amu1fuWE7BvPuUzLJ9-HgAAAAPY"]
[Thu Jul 30 15:35:10.863727 2026] [security2:error] [pid 189611:tid 189745] [client 38.172.162.57:16451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1fuWE7BvPuUzLJ9-HkQAAAIk"]
[Thu Jul 30 15:35:10.863827 2026] [security2:error] [pid 189611:tid 189745] [client 38.172.162.57:16451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1fuWE7BvPuUzLJ9-HkQAAAIk"]
[Thu Jul 30 15:35:11.202671 2026] [security2:error] [pid 189611:tid 189766] [client 20.171.55.167:10985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/yanierin/akc.php"] [unique_id "amu1f-WE7BvPuUzLJ9-HmQAAAJ4"]
[Thu Jul 30 15:35:12.097996 2026] [security2:error] [pid 189611:tid 189800] [client 20.171.55.167:11006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.emmanueljrodriguez.com"] [uri "/zfox.php"] [unique_id "amu1gOWE7BvPuUzLJ9-HuQAAAMA"]
[Thu Jul 30 15:35:12.595667 2026] [security2:error] [pid 189611:tid 189700] [remote 95.108.213.218:49528] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "spacexpress.africa"] [uri "/tag/supplychain/"] [unique_id "amu1gOWE7BvPuUzLJ9-H0AAAuFg"]
[Thu Jul 30 15:35:12.776732 2026] [security2:error] [pid 189611:tid 189706] [remote 47.128.27.48:37878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/off-white-nike-dunk/"] [unique_id "amu1gOWE7BvPuUzLJ9-H2gAAr14"]
[Thu Jul 30 15:35:12.821023 2026] [security2:error] [pid 189611:tid 189861] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1gOWE7BvPuUzLJ9-HwQAA_Vs"]
[Thu Jul 30 15:35:13.348009 2026] [core:notice] [pid 189611:tid 189789] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:14.572918 2026] [security2:error] [pid 189611:tid 189823] [client 127.0.0.1:53696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu1guWE7BvPuUzLJ9-IEgAAANc"]
[Thu Jul 30 15:35:14.572956 2026] [security2:error] [pid 189611:tid 189832] [client 74.7.175.150:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "autodiscover.tiger388.shop"] [uri "/robots.txt"] [unique_id "amu1guWE7BvPuUzLJ9-IEQAAAOA"]
[Thu Jul 30 15:35:15.441833 2026] [security2:error] [pid 189611:tid 189743] [client 74.7.230.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ghggeneralcontracting.com"] [uri "/index.php"] [unique_id "amu1geWE7BvPuUzLJ9-H_gAAAIc"]
[Thu Jul 30 15:35:15.442729 2026] [security2:error] [pid 189611:tid 189754] [client 74.7.230.7:41310] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.ghggeneralcontracting.com"] [uri "/robots.txt"] [unique_id "amu1geWE7BvPuUzLJ9-H_AAAkgM"]
[Thu Jul 30 15:35:16.357080 2026] [security2:error] [pid 189611:tid 189759] [client 74.7.175.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "zdn.djb.temporary.site"] [uri "/index.php"] [unique_id "amu1geWE7BvPuUzLJ9-H7AAAAJc"]
[Thu Jul 30 15:35:16.357867 2026] [security2:error] [pid 189611:tid 189847] [client 74.7.175.184:54968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "zdn.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amu1geWE7BvPuUzLJ9-H6gAA7w4"]
[Thu Jul 30 15:35:16.680879 2026] [core:notice] [pid 189611:tid 189627] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:17.802892 2026] [core:error] [pid 189611:tid 189768] [client 74.7.230.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:35:17.802916 2026] [core:error] [pid 189611:tid 189768] [client 74.7.230.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:35:17.803077 2026] [security2:error] [pid 189611:tid 189768] [client 74.7.230.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.gkc.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amu1heWE7BvPuUzLJ9-IagAAAKA"]
[Thu Jul 30 15:35:17.803760 2026] [security2:error] [pid 189611:tid 189804] [client 74.7.230.51:51436] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.gkc.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amu1heWE7BvPuUzLJ9-IZwAAxBw"]
[Thu Jul 30 15:35:18.093533 2026] [core:notice] [pid 189611:tid 189659] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.107555 2026] [core:notice] [pid 189611:tid 189665] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.155755 2026] [core:notice] [pid 189611:tid 189644] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.184266 2026] [core:notice] [pid 189611:tid 189651] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.184416 2026] [core:notice] [pid 189611:tid 189673] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.208802 2026] [core:notice] [pid 189611:tid 189635] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.212116 2026] [core:notice] [pid 189611:tid 189671] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.273360 2026] [core:notice] [pid 189611:tid 189663] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.356234 2026] [core:notice] [pid 189611:tid 189670] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.404569 2026] [core:notice] [pid 189611:tid 189657] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.432245 2026] [core:notice] [pid 189611:tid 189681] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.465449 2026] [core:notice] [pid 189611:tid 189664] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.504658 2026] [core:notice] [pid 189611:tid 189683] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.510424 2026] [core:notice] [pid 189611:tid 189688] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.527828 2026] [core:notice] [pid 189611:tid 189696] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.622875 2026] [core:notice] [pid 189611:tid 189687] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:18.873383 2026] [core:notice] [pid 189611:tid 189661] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:19.070864 2026] [core:notice] [pid 189611:tid 189649] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:19.330886 2026] [core:notice] [pid 189611:tid 189685] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:20.412736 2026] [core:notice] [pid 189611:tid 189682] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:20.485663 2026] [proxy:error] [pid 189611:tid 189709] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:20.485714 2026] [proxy_http:error] [pid 189611:tid 189709] [remote 74.7.230.12:46196] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:20.486543 2026] [proxy:error] [pid 189611:tid 189709] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:20.486596 2026] [proxy_http:error] [pid 189611:tid 189709] [remote 74.7.230.12:46196] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:21.302351 2026] [security2:error] [pid 189611:tid 189765] [client 74.7.175.175:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ssa.djb.temporary.site"] [uri "/index.php"] [unique_id "amu1ieWE7BvPuUzLJ9-I1wAAAJ0"]
[Thu Jul 30 15:35:21.303328 2026] [security2:error] [pid 189611:tid 189806] [client 74.7.175.175:36662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ssa.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amu1ieWE7BvPuUzLJ9-I1AAAxm4"]
[Thu Jul 30 15:35:21.466915 2026] [security2:error] [pid 189611:tid 189775] [client 38.172.162.57:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1ieWE7BvPuUzLJ9-I5AAAAKc"]
[Thu Jul 30 15:35:21.467026 2026] [security2:error] [pid 189611:tid 189775] [client 38.172.162.57:16270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1ieWE7BvPuUzLJ9-I5AAAAKc"]
[Thu Jul 30 15:35:21.572296 2026] [core:notice] [pid 189611:tid 189767] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:22.651874 2026] [autoindex:error] [pid 189611:tid 189867] [client 202.78.167.207:0] AH01276: Cannot serve directory /home2/mbmudite/ok.otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://ok.otbola.click/
[Thu Jul 30 15:35:23.366860 2026] [security2:error] [pid 189611:tid 189830] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1iuWE7BvPuUzLJ9-I-AAA3mk"]
[Thu Jul 30 15:35:23.807402 2026] [security2:error] [pid 189611:tid 189824] [client 2a03:2880:f800:2d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1i-WE7BvPuUzLJ9-JDAAA2HA"]
[Thu Jul 30 15:35:24.834113 2026] [core:notice] [pid 189611:tid 189739] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:24.837801 2026] [security2:error] [pid 189611:tid 189775] [client 66.249.74.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/14/16"] [unique_id "amu1jOWE7BvPuUzLJ9-JJwAAp38"]
[Thu Jul 30 15:35:24.928045 2026] [proxy:error] [pid 189611:tid 189782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:24.928139 2026] [proxy_http:error] [pid 189611:tid 189782] [client 44.213.206.96:19094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:24.928921 2026] [proxy:error] [pid 189611:tid 189782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:24.928990 2026] [proxy_http:error] [pid 189611:tid 189782] [client 44.213.206.96:19094] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:24.936685 2026] [proxy:error] [pid 189611:tid 189837] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:24.936747 2026] [proxy_http:error] [pid 189611:tid 189837] [client 3.225.222.228:28498] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:24.937323 2026] [proxy:error] [pid 189611:tid 189837] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:24.937380 2026] [proxy_http:error] [pid 189611:tid 189837] [client 3.225.222.228:28498] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:25.960200 2026] [security2:error] [pid 189611:tid 189827] [client 172.237.109.114:2426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/wpdiscuz/readme.txt"] [unique_id "amu1jeWE7BvPuUzLJ9-JVgAAANs"]
[Thu Jul 30 15:35:26.304997 2026] [security2:error] [pid 189611:tid 189746] [client 57.141.0.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1jeWE7BvPuUzLJ9-JTQAAAIo"]
[Thu Jul 30 15:35:26.905245 2026] [core:notice] [pid 189611:tid 189648] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:27.079271 2026] [security2:error] [pid 189611:tid 189805] [client 172.237.109.114:27531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/pages/UI.php"] [unique_id "amu1j-WE7BvPuUzLJ9-JewAAAMU"]
[Thu Jul 30 15:35:28.097150 2026] [security2:error] [pid 189611:tid 189612] [remote 40.77.167.224:61005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.aded-rdc.org"] [uri "/rehabilitation-a-base-communautaire-2/article.php"] [unique_id "amu1kOWE7BvPuUzLJ9-JkgAAjgA"]
[Thu Jul 30 15:35:28.164370 2026] [core:notice] [pid 189611:tid 189843] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:29.012245 2026] [security2:error] [pid 189611:tid 189862] [client 162.219.176.3:49162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amu1keWE7BvPuUzLJ9-JqwAAAP4"]
[Thu Jul 30 15:35:29.012332 2026] [security2:error] [pid 189611:tid 189862] [client 162.219.176.3:49162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ladiessecretdepartment.com"] [uri "/xmlrpc.php"] [unique_id "amu1keWE7BvPuUzLJ9-JqwAAAP4"]
[Thu Jul 30 15:35:30.997992 2026] [security2:error] [pid 189611:tid 189849] [client 172.237.109.114:53229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/register"] [unique_id "amu1kuWE7BvPuUzLJ9-J0wAAAPE"]
[Thu Jul 30 15:35:31.379796 2026] [security2:error] [pid 189611:tid 189847] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1kuWE7BvPuUzLJ9-JxQAA7xc"]
[Thu Jul 30 15:35:31.430496 2026] [security2:error] [pid 189611:tid 189660] [remote 216.73.216.51:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu1k-WE7BvPuUzLJ9-J3QAAmDA"]
[Thu Jul 30 15:35:32.018772 2026] [security2:error] [pid 189611:tid 189866] [client 38.172.162.57:16225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1lOWE7BvPuUzLJ9-J7wAAAQI"]
[Thu Jul 30 15:35:32.019465 2026] [security2:error] [pid 189611:tid 189866] [client 38.172.162.57:16225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1lOWE7BvPuUzLJ9-J7wAAAQI"]
[Thu Jul 30 15:35:32.680372 2026] [autoindex:error] [pid 189611:tid 189677] [remote 146.75.193.37:21297] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:35:32.882019 2026] [security2:error] [pid 189611:tid 189675] [remote 57.141.0.8:63700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/article.php"] [unique_id "amu1lOWE7BvPuUzLJ9-KAwAA3T8"]
[Thu Jul 30 15:35:32.982264 2026] [autoindex:error] [pid 189611:tid 189649] [remote 146.75.193.37:21297] AH01276: Cannot serve directory /home1/uixgzjte/public_html/guethleentertainment.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:35:32.990619 2026] [security2:error] [pid 189611:tid 189756] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1lOWE7BvPuUzLJ9-J-AAAAJQ"]
[Thu Jul 30 15:35:33.477077 2026] [core:notice] [pid 189611:tid 189666] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:34.248701 2026] [security2:error] [pid 189611:tid 189680] [remote 57.141.0.9:61468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/5267181034/feed/rss2/"] [unique_id "amu1luWE7BvPuUzLJ9-KHwAAmEQ"]
[Thu Jul 30 15:35:36.058417 2026] [core:notice] [pid 189611:tid 189698] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:36.937129 2026] [autoindex:error] [pid 189611:tid 189774] [client 49.234.192.248:51466] AH01276: Cannot serve directory /home1/yqegzjte/hello-pal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:35:37.040953 2026] [security2:error] [pid 189611:tid 189845] [client 2a03:2880:f800:1:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1mOWE7BvPuUzLJ9-KUQAA7Wc"]
[Thu Jul 30 15:35:37.778750 2026] [core:notice] [pid 189611:tid 189716] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:37.792568 2026] [core:notice] [pid 189611:tid 189718] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:37.836161 2026] [core:notice] [pid 189611:tid 189726] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:37.841154 2026] [core:notice] [pid 189611:tid 189728] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:37.856236 2026] [core:notice] [pid 189611:tid 189708] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:37.856896 2026] [core:notice] [pid 189611:tid 189725] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:37.879305 2026] [core:notice] [pid 189611:tid 189700] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:37.891715 2026] [core:notice] [pid 189611:tid 189738] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:37.922452 2026] [core:notice] [pid 189611:tid 189717] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.016463 2026] [core:notice] [pid 189611:tid 189704] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.029254 2026] [core:notice] [pid 189611:tid 189727] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.070951 2026] [core:notice] [pid 189611:tid 189724] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.082194 2026] [core:notice] [pid 189611:tid 189736] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.094770 2026] [core:notice] [pid 189611:tid 189706] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.123705 2026] [core:notice] [pid 189611:tid 189703] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.160413 2026] [core:notice] [pid 189611:tid 189622] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.277003 2026] [core:notice] [pid 189611:tid 189616] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.314820 2026] [core:notice] [pid 189611:tid 189735] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.536241 2026] [core:notice] [pid 189611:tid 189619] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:38.561233 2026] [core:notice] [pid 189611:tid 189617] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:39.969943 2026] [security2:error] [pid 189611:tid 189782] [client 172.237.109.114:14639] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/extensive-vc-addon/readme.txt"] [unique_id "amu1m-WE7BvPuUzLJ9-KrwAAAK4"]
[Thu Jul 30 15:35:40.223546 2026] [security2:error] [pid 189611:tid 189808] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1m-WE7BvPuUzLJ9-KsAAAAMg"]
[Thu Jul 30 15:35:40.536673 2026] [security2:error] [pid 189611:tid 189615] [remote 157.66.47.83:47532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.47.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gyj.djb.temporary.site"] [uri "/wp-login.php"] [unique_id "amu1nOWE7BvPuUzLJ9-KvgAAxAM"]
[Thu Jul 30 15:35:41.047122 2026] [security2:error] [pid 189611:tid 189614] [remote 57.141.0.38:46626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/14744782368/feed/rss2/"] [unique_id "amu1neWE7BvPuUzLJ9-KyQABAQI"]
[Thu Jul 30 15:35:42.656504 2026] [security2:error] [pid 189611:tid 189776] [client 38.172.162.57:15936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1nuWE7BvPuUzLJ9-K7QAAAKg"]
[Thu Jul 30 15:35:42.656628 2026] [security2:error] [pid 189611:tid 189776] [client 38.172.162.57:15936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1nuWE7BvPuUzLJ9-K7QAAAKg"]
[Thu Jul 30 15:35:43.552156 2026] [security2:error] [pid 189611:tid 189846] [client 57.141.0.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1n-WE7BvPuUzLJ9-K_wAAAO4"]
[Thu Jul 30 15:35:44.971887 2026] [security2:error] [pid 189611:tid 189763] [client 172.237.109.114:40024] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/heureka/readme.txt"] [unique_id "amu1oOWE7BvPuUzLJ9-LHQAAAJs"]
[Thu Jul 30 15:35:45.122332 2026] [security2:error] [pid 189611:tid 189817] [client 172.237.109.114:44131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/simple/pages/UI.php"] [unique_id "amu1oeWE7BvPuUzLJ9-LHwAAANE"]
[Thu Jul 30 15:35:46.672366 2026] [security2:error] [pid 189611:tid 189841] [client 20.113.56.22:15630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu1ouWE7BvPuUzLJ9-LQwAAAOk"]
[Thu Jul 30 15:35:46.672476 2026] [security2:error] [pid 189611:tid 189841] [client 20.113.56.22:15630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu1ouWE7BvPuUzLJ9-LQwAAAOk"]
[Thu Jul 30 15:35:46.948357 2026] [security2:error] [pid 189611:tid 189796] [client 20.113.56.22:15631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu1ouWE7BvPuUzLJ9-LSgAAALw"]
[Thu Jul 30 15:35:46.948474 2026] [security2:error] [pid 189611:tid 189796] [client 20.113.56.22:15631] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu1ouWE7BvPuUzLJ9-LSgAAALw"]
[Thu Jul 30 15:35:47.216716 2026] [security2:error] [pid 189611:tid 189758] [client 20.113.56.22:15685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/x.php"] [unique_id "amu1o-WE7BvPuUzLJ9-LUgAAAJY"]
[Thu Jul 30 15:35:47.216867 2026] [security2:error] [pid 189611:tid 189758] [client 20.113.56.22:15685] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/x.php"] [unique_id "amu1o-WE7BvPuUzLJ9-LUgAAAJY"]
[Thu Jul 30 15:35:47.251569 2026] [security2:error] [pid 189611:tid 189744] [client 57.141.18.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "laduchessecollections.com"] [uri "/index.php"] [unique_id "amu1oeWE7BvPuUzLJ9-LHgAAiDM"]
[Thu Jul 30 15:35:47.501220 2026] [security2:error] [pid 189611:tid 189802] [client 20.113.56.22:15701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/mgrr.php"] [unique_id "amu1o-WE7BvPuUzLJ9-LWwAAAMI"]
[Thu Jul 30 15:35:47.501315 2026] [security2:error] [pid 189611:tid 189802] [client 20.113.56.22:15701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/mgrr.php"] [unique_id "amu1o-WE7BvPuUzLJ9-LWwAAAMI"]
[Thu Jul 30 15:35:47.525052 2026] [security2:error] [pid 189611:tid 189750] [client 57.141.0.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1ouWE7BvPuUzLJ9-LSQAAAI4"]
[Thu Jul 30 15:35:47.805009 2026] [security2:error] [pid 189611:tid 189780] [client 20.113.56.22:15726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/domvf.php"] [unique_id "amu1o-WE7BvPuUzLJ9-LXwAAAKw"]
[Thu Jul 30 15:35:47.805165 2026] [security2:error] [pid 189611:tid 189780] [client 20.113.56.22:15726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/domvf.php"] [unique_id "amu1o-WE7BvPuUzLJ9-LXwAAAKw"]
[Thu Jul 30 15:35:47.845840 2026] [security2:error] [pid 189611:tid 189831] [client 162.219.176.3:60340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amu1o-WE7BvPuUzLJ9-LYAAAAN8"]
[Thu Jul 30 15:35:47.845995 2026] [security2:error] [pid 189611:tid 189831] [client 162.219.176.3:60340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amu1o-WE7BvPuUzLJ9-LYAAAAN8"]
[Thu Jul 30 15:35:48.161268 2026] [security2:error] [pid 189611:tid 189854] [client 20.113.56.22:15721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/yup.php"] [unique_id "amu1pOWE7BvPuUzLJ9-LagAAAPY"]
[Thu Jul 30 15:35:48.161383 2026] [security2:error] [pid 189611:tid 189854] [client 20.113.56.22:15721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/yup.php"] [unique_id "amu1pOWE7BvPuUzLJ9-LagAAAPY"]
[Thu Jul 30 15:35:48.260426 2026] [security2:error] [pid 189611:tid 189801] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1o-WE7BvPuUzLJ9-LUwAAwSs"]
[Thu Jul 30 15:35:48.444373 2026] [security2:error] [pid 189611:tid 189856] [client 20.113.56.22:15670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/X.php"] [unique_id "amu1pOWE7BvPuUzLJ9-LbgAAAPg"]
[Thu Jul 30 15:35:48.444499 2026] [security2:error] [pid 189611:tid 189856] [client 20.113.56.22:15670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/X.php"] [unique_id "amu1pOWE7BvPuUzLJ9-LbgAAAPg"]
[Thu Jul 30 15:35:48.727840 2026] [security2:error] [pid 189611:tid 189861] [client 20.113.56.22:15680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amu1pOWE7BvPuUzLJ9-LewAAAP0"]
[Thu Jul 30 15:35:48.727949 2026] [security2:error] [pid 189611:tid 189861] [client 20.113.56.22:15680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "amu1pOWE7BvPuUzLJ9-LewAAAP0"]
[Thu Jul 30 15:35:49.029454 2026] [security2:error] [pid 189611:tid 189788] [client 20.113.56.22:15725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/gec.php"] [unique_id "amu1peWE7BvPuUzLJ9-LggAAALQ"]
[Thu Jul 30 15:35:49.029559 2026] [security2:error] [pid 189611:tid 189788] [client 20.113.56.22:15725] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/gec.php"] [unique_id "amu1peWE7BvPuUzLJ9-LggAAALQ"]
[Thu Jul 30 15:35:49.310859 2026] [security2:error] [pid 189611:tid 189783] [client 20.113.56.22:15681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/sky.php"] [unique_id "amu1peWE7BvPuUzLJ9-LiwAAAK8"]
[Thu Jul 30 15:35:49.310960 2026] [security2:error] [pid 189611:tid 189783] [client 20.113.56.22:15681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/sky.php"] [unique_id "amu1peWE7BvPuUzLJ9-LiwAAAK8"]
[Thu Jul 30 15:35:49.585572 2026] [security2:error] [pid 189611:tid 189775] [client 20.113.56.22:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/fffm.php"] [unique_id "amu1peWE7BvPuUzLJ9-LlAAAAKc"]
[Thu Jul 30 15:35:49.585665 2026] [security2:error] [pid 189611:tid 189775] [client 20.113.56.22:15646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/fffm.php"] [unique_id "amu1peWE7BvPuUzLJ9-LlAAAAKc"]
[Thu Jul 30 15:35:49.811455 2026] [core:notice] [pid 189611:tid 189821] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:50.030179 2026] [security2:error] [pid 189611:tid 189780] [client 20.113.56.22:15688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/sixxis.php"] [unique_id "amu1puWE7BvPuUzLJ9-LnAAAAKw"]
[Thu Jul 30 15:35:50.030344 2026] [security2:error] [pid 189611:tid 189780] [client 20.113.56.22:15688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/sixxis.php"] [unique_id "amu1puWE7BvPuUzLJ9-LnAAAAKw"]
[Thu Jul 30 15:35:50.325287 2026] [security2:error] [pid 189611:tid 189777] [client 20.113.56.22:15719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/yj09.php"] [unique_id "amu1puWE7BvPuUzLJ9-LrgAAAKk"]
[Thu Jul 30 15:35:50.325395 2026] [security2:error] [pid 189611:tid 189777] [client 20.113.56.22:15719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/yj09.php"] [unique_id "amu1puWE7BvPuUzLJ9-LrgAAAKk"]
[Thu Jul 30 15:35:50.592657 2026] [security2:error] [pid 189611:tid 189816] [client 20.113.56.22:15715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/k.php"] [unique_id "amu1puWE7BvPuUzLJ9-LswAAANA"]
[Thu Jul 30 15:35:50.592843 2026] [security2:error] [pid 189611:tid 189816] [client 20.113.56.22:15715] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/k.php"] [unique_id "amu1puWE7BvPuUzLJ9-LswAAANA"]
[Thu Jul 30 15:35:50.933563 2026] [security2:error] [pid 189611:tid 189757] [client 20.113.56.22:15708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/k2.php"] [unique_id "amu1puWE7BvPuUzLJ9-LuwAAAJU"]
[Thu Jul 30 15:35:50.933684 2026] [security2:error] [pid 189611:tid 189757] [client 20.113.56.22:15708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/k2.php"] [unique_id "amu1puWE7BvPuUzLJ9-LuwAAAJU"]
[Thu Jul 30 15:35:51.219778 2026] [security2:error] [pid 189611:tid 189849] [client 20.113.56.22:3036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/w.php"] [unique_id "amu1p-WE7BvPuUzLJ9-LyAAAAPE"]
[Thu Jul 30 15:35:51.219879 2026] [security2:error] [pid 189611:tid 189849] [client 20.113.56.22:3036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/w.php"] [unique_id "amu1p-WE7BvPuUzLJ9-LyAAAAPE"]
[Thu Jul 30 15:35:51.268168 2026] [security2:error] [pid 189611:tid 189750] [client 74.7.230.63:41192] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mty.djb.temporary.site"] [uri "/index.php"] [unique_id "amu1peWE7BvPuUzLJ9-LmwAAjlY"]
[Thu Jul 30 15:35:51.509696 2026] [security2:error] [pid 189611:tid 189843] [client 20.113.56.22:15626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/fpwch.php"] [unique_id "amu1p-WE7BvPuUzLJ9-LzQAAAOs"]
[Thu Jul 30 15:35:51.509802 2026] [security2:error] [pid 189611:tid 189843] [client 20.113.56.22:15626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/fpwch.php"] [unique_id "amu1p-WE7BvPuUzLJ9-LzQAAAOs"]
[Thu Jul 30 15:35:51.837660 2026] [security2:error] [pid 189611:tid 189745] [client 20.113.56.22:15741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/w2025.php"] [unique_id "amu1p-WE7BvPuUzLJ9-L2wAAAIk"]
[Thu Jul 30 15:35:51.837804 2026] [security2:error] [pid 189611:tid 189745] [client 20.113.56.22:15741] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/w2025.php"] [unique_id "amu1p-WE7BvPuUzLJ9-L2wAAAIk"]
[Thu Jul 30 15:35:52.145541 2026] [security2:error] [pid 189611:tid 189810] [client 20.113.56.22:15635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/FWAZ.php"] [unique_id "amu1qOWE7BvPuUzLJ9-L6AAAAMo"]
[Thu Jul 30 15:35:52.145646 2026] [security2:error] [pid 189611:tid 189810] [client 20.113.56.22:15635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/FWAZ.php"] [unique_id "amu1qOWE7BvPuUzLJ9-L6AAAAMo"]
[Thu Jul 30 15:35:52.409197 2026] [security2:error] [pid 189611:tid 189812] [client 20.113.56.22:15714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/qterm.php"] [unique_id "amu1qOWE7BvPuUzLJ9-L8gAAAMw"]
[Thu Jul 30 15:35:52.409311 2026] [security2:error] [pid 189611:tid 189812] [client 20.113.56.22:15714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/qterm.php"] [unique_id "amu1qOWE7BvPuUzLJ9-L8gAAAMw"]
[Thu Jul 30 15:35:52.678270 2026] [security2:error] [pid 189611:tid 189863] [client 20.113.56.22:15743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/blurbs.php"] [unique_id "amu1qOWE7BvPuUzLJ9-L9QAAAP8"]
[Thu Jul 30 15:35:52.678378 2026] [security2:error] [pid 189611:tid 189863] [client 20.113.56.22:15743] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/blurbs.php"] [unique_id "amu1qOWE7BvPuUzLJ9-L9QAAAP8"]
[Thu Jul 30 15:35:53.142555 2026] [security2:error] [pid 189611:tid 189865] [client 20.113.56.22:15728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-ws68.php"] [unique_id "amu1qeWE7BvPuUzLJ9-L_QAAAQE"]
[Thu Jul 30 15:35:53.142684 2026] [security2:error] [pid 189611:tid 189865] [client 20.113.56.22:15728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-ws68.php"] [unique_id "amu1qeWE7BvPuUzLJ9-L_QAAAQE"]
[Thu Jul 30 15:35:53.261701 2026] [security2:error] [pid 189611:tid 189781] [client 38.172.162.57:15948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1qeWE7BvPuUzLJ9-MAQAAAK0"]
[Thu Jul 30 15:35:53.261992 2026] [security2:error] [pid 189611:tid 189781] [client 38.172.162.57:15948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1qeWE7BvPuUzLJ9-MAQAAAK0"]
[Thu Jul 30 15:35:53.428402 2026] [security2:error] [pid 189611:tid 189809] [client 20.113.56.22:15707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/xyn.php"] [unique_id "amu1qeWE7BvPuUzLJ9-MCAAAAMk"]
[Thu Jul 30 15:35:53.428498 2026] [security2:error] [pid 189611:tid 189809] [client 20.113.56.22:15707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/xyn.php"] [unique_id "amu1qeWE7BvPuUzLJ9-MCAAAAMk"]
[Thu Jul 30 15:35:53.694671 2026] [security2:error] [pid 189611:tid 189771] [client 20.113.56.22:15682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/ccc.php"] [unique_id "amu1qeWE7BvPuUzLJ9-MDAAAAKM"]
[Thu Jul 30 15:35:53.694788 2026] [security2:error] [pid 189611:tid 189771] [client 20.113.56.22:15682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/ccc.php"] [unique_id "amu1qeWE7BvPuUzLJ9-MDAAAAKM"]
[Thu Jul 30 15:35:53.929300 2026] [core:notice] [pid 189611:tid 189750] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:35:53.932946 2026] [security2:error] [pid 189611:tid 189750] [client 66.249.74.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/59"] [unique_id "amu1qeWE7BvPuUzLJ9-MCwAAAI4"]
[Thu Jul 30 15:35:54.020438 2026] [security2:error] [pid 189611:tid 189762] [client 20.113.56.22:15700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/get.php"] [unique_id "amu1quWE7BvPuUzLJ9-MFwAAAJo"]
[Thu Jul 30 15:35:54.020561 2026] [security2:error] [pid 189611:tid 189762] [client 20.113.56.22:15700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/get.php"] [unique_id "amu1quWE7BvPuUzLJ9-MFwAAAJo"]
[Thu Jul 30 15:35:54.167702 2026] [proxy:error] [pid 189611:tid 189853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:54.167782 2026] [proxy_http:error] [pid 189611:tid 189853] [client 3.225.222.228:62689] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:54.168473 2026] [proxy:error] [pid 189611:tid 189853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:54.168529 2026] [proxy_http:error] [pid 189611:tid 189853] [client 3.225.222.228:62689] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:54.182766 2026] [proxy:error] [pid 189611:tid 189802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:54.182845 2026] [proxy_http:error] [pid 189611:tid 189802] [client 3.225.222.228:59930] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:54.183461 2026] [proxy:error] [pid 189611:tid 189802] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:35:54.183517 2026] [proxy_http:error] [pid 189611:tid 189802] [client 3.225.222.228:59930] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:35:54.285165 2026] [security2:error] [pid 189611:tid 189807] [client 20.113.56.22:15731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/images.php"] [unique_id "amu1quWE7BvPuUzLJ9-MJwAAAMc"]
[Thu Jul 30 15:35:54.285281 2026] [security2:error] [pid 189611:tid 189807] [client 20.113.56.22:15731] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/images.php"] [unique_id "amu1quWE7BvPuUzLJ9-MJwAAAMc"]
[Thu Jul 30 15:35:54.549965 2026] [security2:error] [pid 189611:tid 189777] [client 20.113.56.22:15695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/alls.php"] [unique_id "amu1quWE7BvPuUzLJ9-MMAAAAKk"]
[Thu Jul 30 15:35:54.550095 2026] [security2:error] [pid 189611:tid 189777] [client 20.113.56.22:15695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/alls.php"] [unique_id "amu1quWE7BvPuUzLJ9-MMAAAAKk"]
[Thu Jul 30 15:35:54.560112 2026] [security2:error] [pid 189611:tid 189618] [remote 110.249.202.98:25602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/"] [unique_id "amu1quWE7BvPuUzLJ9-MMQAAqAY"]
[Thu Jul 30 15:35:54.609365 2026] [security2:error] [pid 189611:tid 189828] [client 172.237.109.114:20916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1qeWE7BvPuUzLJ9-MFgAAANw"]
[Thu Jul 30 15:35:54.690830 2026] [security2:error] [pid 189611:tid 189625] [remote 142.44.146.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.146.44.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nafmedical.com"] [uri "/wp-login.php"] [unique_id "amu1quWE7BvPuUzLJ9-MMwAA8g0"]
[Thu Jul 30 15:35:54.811609 2026] [security2:error] [pid 189611:tid 189808] [client 20.113.56.22:15687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/coffexium.php"] [unique_id "amu1quWE7BvPuUzLJ9-MNwAAAMg"]
[Thu Jul 30 15:35:54.811734 2026] [security2:error] [pid 189611:tid 189808] [client 20.113.56.22:15687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/coffexium.php"] [unique_id "amu1quWE7BvPuUzLJ9-MNwAAAMg"]
[Thu Jul 30 15:35:54.959769 2026] [security2:error] [pid 189611:tid 189615] [remote 74.7.243.224:48958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amu1quWE7BvPuUzLJ9-MPgAA_AM"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 15:35:55.013749 2026] [security2:error] [pid 189611:tid 189804] [client 127.0.0.1:19584] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.1lightroom.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu1quWE7BvPuUzLJ9-MQAAAAMQ"]
[Thu Jul 30 15:35:55.013754 2026] [security2:error] [pid 189611:tid 189742] [client 127.0.0.1:19594] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu1quWE7BvPuUzLJ9-MQQAAAIY"]
[Thu Jul 30 15:35:55.013846 2026] [security2:error] [pid 189611:tid 189856] [client 74.7.241.181:48932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.1lightroom.com"] [uri "/robots.txt"] [unique_id "amu1quWE7BvPuUzLJ9-MPwAA-Hg"]
[Thu Jul 30 15:35:55.073210 2026] [security2:error] [pid 189611:tid 189741] [client 20.113.56.22:15639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/red.php"] [unique_id "amu1q-WE7BvPuUzLJ9-MQgAAAIU"]
[Thu Jul 30 15:35:55.073316 2026] [security2:error] [pid 189611:tid 189741] [client 20.113.56.22:15639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/red.php"] [unique_id "amu1q-WE7BvPuUzLJ9-MQgAAAIU"]
[Thu Jul 30 15:35:55.341316 2026] [security2:error] [pid 189611:tid 189836] [client 20.113.56.22:15687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1q-WE7BvPuUzLJ9-MQwAAAOQ"]
[Thu Jul 30 15:35:55.471168 2026] [security2:error] [pid 189611:tid 189751] [client 20.113.56.22:15687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amu1q-WE7BvPuUzLJ9-MSQAAAI8"]
[Thu Jul 30 15:35:55.471252 2026] [security2:error] [pid 189611:tid 189751] [client 20.113.56.22:15687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "amu1q-WE7BvPuUzLJ9-MSQAAAI8"]
[Thu Jul 30 15:35:55.740455 2026] [security2:error] [pid 189611:tid 189830] [client 20.113.56.22:15710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1q-WE7BvPuUzLJ9-MUwAAAN4"]
[Thu Jul 30 15:35:55.871615 2026] [security2:error] [pid 189611:tid 189762] [client 20.113.56.22:15710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1q-WE7BvPuUzLJ9-MWgAAAJo"]
[Thu Jul 30 15:35:56.004596 2026] [security2:error] [pid 189611:tid 189779] [client 20.113.56.22:15710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-content/index.php"] [unique_id "amu1rOWE7BvPuUzLJ9-MXwAAAKs"]
[Thu Jul 30 15:35:56.004734 2026] [security2:error] [pid 189611:tid 189779] [client 20.113.56.22:15710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-content/index.php"] [unique_id "amu1rOWE7BvPuUzLJ9-MXwAAAKs"]
[Thu Jul 30 15:35:56.281506 2026] [security2:error] [pid 189611:tid 189801] [client 20.113.56.22:15742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/admin.php"] [unique_id "amu1rOWE7BvPuUzLJ9-MZgAAAME"]
[Thu Jul 30 15:35:56.281614 2026] [security2:error] [pid 189611:tid 189801] [client 20.113.56.22:15742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/admin.php"] [unique_id "amu1rOWE7BvPuUzLJ9-MZgAAAME"]
[Thu Jul 30 15:35:56.546460 2026] [security2:error] [pid 189611:tid 189828] [client 20.113.56.22:15727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/177.php"] [unique_id "amu1rOWE7BvPuUzLJ9-MbQAAANw"]
[Thu Jul 30 15:35:56.546564 2026] [security2:error] [pid 189611:tid 189828] [client 20.113.56.22:15727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/177.php"] [unique_id "amu1rOWE7BvPuUzLJ9-MbQAAANw"]
[Thu Jul 30 15:35:56.724313 2026] [security2:error] [pid 189611:tid 189821] [client 57.141.0.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1rOWE7BvPuUzLJ9-MZQAAANU"]
[Thu Jul 30 15:35:56.814635 2026] [security2:error] [pid 189611:tid 189816] [client 20.113.56.22:15617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/199.php"] [unique_id "amu1rOWE7BvPuUzLJ9-McgAAANA"]
[Thu Jul 30 15:35:56.814785 2026] [security2:error] [pid 189611:tid 189816] [client 20.113.56.22:15617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/199.php"] [unique_id "amu1rOWE7BvPuUzLJ9-McgAAANA"]
[Thu Jul 30 15:35:57.117394 2026] [security2:error] [pid 189611:tid 189842] [client 20.113.56.22:15647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/file52.php"] [unique_id "amu1reWE7BvPuUzLJ9-MfAAAAOo"]
[Thu Jul 30 15:35:57.117491 2026] [security2:error] [pid 189611:tid 189842] [client 20.113.56.22:15647] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/file52.php"] [unique_id "amu1reWE7BvPuUzLJ9-MfAAAAOo"]
[Thu Jul 30 15:35:57.382883 2026] [security2:error] [pid 189611:tid 189813] [client 20.113.56.22:15713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/geck.php"] [unique_id "amu1reWE7BvPuUzLJ9-MfQAAAM0"]
[Thu Jul 30 15:35:57.383043 2026] [security2:error] [pid 189611:tid 189813] [client 20.113.56.22:15713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/geck.php"] [unique_id "amu1reWE7BvPuUzLJ9-MfQAAAM0"]
[Thu Jul 30 15:35:57.650413 2026] [security2:error] [pid 189611:tid 189855] [client 20.113.56.22:15634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/biufile.php"] [unique_id "amu1reWE7BvPuUzLJ9-MigAAAPc"]
[Thu Jul 30 15:35:57.650520 2026] [security2:error] [pid 189611:tid 189855] [client 20.113.56.22:15634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/biufile.php"] [unique_id "amu1reWE7BvPuUzLJ9-MigAAAPc"]
[Thu Jul 30 15:35:57.911712 2026] [security2:error] [pid 189611:tid 189809] [client 20.113.56.22:15654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/dejavu.php"] [unique_id "amu1reWE7BvPuUzLJ9-MiwAAAMk"]
[Thu Jul 30 15:35:57.911831 2026] [security2:error] [pid 189611:tid 189809] [client 20.113.56.22:15654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/dejavu.php"] [unique_id "amu1reWE7BvPuUzLJ9-MiwAAAMk"]
[Thu Jul 30 15:35:58.183139 2026] [security2:error] [pid 189611:tid 189769] [client 20.113.56.22:15722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/aaf.php"] [unique_id "amu1ruWE7BvPuUzLJ9-MmAAAAKE"]
[Thu Jul 30 15:35:58.183261 2026] [security2:error] [pid 189611:tid 189769] [client 20.113.56.22:15722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/aaf.php"] [unique_id "amu1ruWE7BvPuUzLJ9-MmAAAAKE"]
[Thu Jul 30 15:35:58.461484 2026] [security2:error] [pid 189611:tid 189814] [client 20.113.56.22:15704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/ha.php"] [unique_id "amu1ruWE7BvPuUzLJ9-MmQAAAM4"]
[Thu Jul 30 15:35:58.461651 2026] [security2:error] [pid 189611:tid 189814] [client 20.113.56.22:15704] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/ha.php"] [unique_id "amu1ruWE7BvPuUzLJ9-MmQAAAM4"]
[Thu Jul 30 15:35:58.726321 2026] [security2:error] [pid 189611:tid 189807] [client 20.113.56.22:15737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/hur.php"] [unique_id "amu1ruWE7BvPuUzLJ9-MowAAAMc"]
[Thu Jul 30 15:35:58.726443 2026] [security2:error] [pid 189611:tid 189807] [client 20.113.56.22:15737] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/hur.php"] [unique_id "amu1ruWE7BvPuUzLJ9-MowAAAMc"]
[Thu Jul 30 15:35:58.987233 2026] [security2:error] [pid 189611:tid 189866] [client 20.113.56.22:15643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/h02ugyh.php"] [unique_id "amu1ruWE7BvPuUzLJ9-MpQAAAQI"]
[Thu Jul 30 15:35:58.987332 2026] [security2:error] [pid 189611:tid 189866] [client 20.113.56.22:15643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/h02ugyh.php"] [unique_id "amu1ruWE7BvPuUzLJ9-MpQAAAQI"]
[Thu Jul 30 15:35:59.252486 2026] [security2:error] [pid 189611:tid 189761] [client 20.113.56.22:15733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/155.php"] [unique_id "amu1r-WE7BvPuUzLJ9-MuAAAAJk"]
[Thu Jul 30 15:35:59.252591 2026] [security2:error] [pid 189611:tid 189761] [client 20.113.56.22:15733] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/155.php"] [unique_id "amu1r-WE7BvPuUzLJ9-MuAAAAJk"]
[Thu Jul 30 15:35:59.528458 2026] [security2:error] [pid 189611:tid 189851] [client 20.113.56.22:15621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/ops.php"] [unique_id "amu1r-WE7BvPuUzLJ9-MuQAAAPM"]
[Thu Jul 30 15:35:59.528568 2026] [security2:error] [pid 189611:tid 189851] [client 20.113.56.22:15621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/ops.php"] [unique_id "amu1r-WE7BvPuUzLJ9-MuQAAAPM"]
[Thu Jul 30 15:35:59.797163 2026] [security2:error] [pid 189611:tid 189790] [client 20.113.56.22:3010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/ingfo.php"] [unique_id "amu1r-WE7BvPuUzLJ9-MxgAAALY"]
[Thu Jul 30 15:35:59.797255 2026] [security2:error] [pid 189611:tid 189790] [client 20.113.56.22:3010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/ingfo.php"] [unique_id "amu1r-WE7BvPuUzLJ9-MxgAAALY"]
[Thu Jul 30 15:35:59.924350 2026] [security2:error] [pid 189611:tid 189772] [client 185.177.72.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amu1r-WE7BvPuUzLJ9-MvQAAAKQ"]
[Thu Jul 30 15:36:00.059187 2026] [security2:error] [pid 189611:tid 189769] [client 20.113.56.22:15652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/error_log.php"] [unique_id "amu1sOWE7BvPuUzLJ9-MywAAAKE"]
[Thu Jul 30 15:36:00.059294 2026] [security2:error] [pid 189611:tid 189769] [client 20.113.56.22:15652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/error_log.php"] [unique_id "amu1sOWE7BvPuUzLJ9-MywAAAKE"]
[Thu Jul 30 15:36:00.324378 2026] [security2:error] [pid 189611:tid 189800] [client 20.113.56.22:15734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/koala.php"] [unique_id "amu1sOWE7BvPuUzLJ9-M0wAAAMA"]
[Thu Jul 30 15:36:00.324496 2026] [security2:error] [pid 189611:tid 189800] [client 20.113.56.22:15734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/koala.php"] [unique_id "amu1sOWE7BvPuUzLJ9-M0wAAAMA"]
[Thu Jul 30 15:36:00.600736 2026] [security2:error] [pid 189611:tid 189794] [client 20.113.56.22:3015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/mac.php"] [unique_id "amu1sOWE7BvPuUzLJ9-M1gAAALo"]
[Thu Jul 30 15:36:00.600850 2026] [security2:error] [pid 189611:tid 189794] [client 20.113.56.22:3015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/mac.php"] [unique_id "amu1sOWE7BvPuUzLJ9-M1gAAALo"]
[Thu Jul 30 15:36:00.856748 2026] [autoindex:error] [pid 189611:tid 189767] [client 185.177.72.10:0] AH01276: Cannot serve directory /home2/ylwgplte/nafmedical.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:36:00.866649 2026] [security2:error] [pid 189611:tid 189832] [client 20.113.56.22:15690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wefile.php"] [unique_id "amu1sOWE7BvPuUzLJ9-M4QAAAOA"]
[Thu Jul 30 15:36:00.866741 2026] [security2:error] [pid 189611:tid 189832] [client 20.113.56.22:15690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wefile.php"] [unique_id "amu1sOWE7BvPuUzLJ9-M4QAAAOA"]
[Thu Jul 30 15:36:01.132126 2026] [security2:error] [pid 189611:tid 189829] [client 20.113.56.22:15724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1seWE7BvPuUzLJ9-M6QAAAN0"]
[Thu Jul 30 15:36:01.266937 2026] [security2:error] [pid 189611:tid 189742] [client 20.113.56.22:15724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1seWE7BvPuUzLJ9-M7wAAAIY"]
[Thu Jul 30 15:36:01.398796 2026] [security2:error] [pid 189611:tid 189861] [client 20.113.56.22:15724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/makeasmtp.php"] [unique_id "amu1seWE7BvPuUzLJ9-M8wAAAP0"]
[Thu Jul 30 15:36:01.398911 2026] [security2:error] [pid 189611:tid 189861] [client 20.113.56.22:15724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/makeasmtp.php"] [unique_id "amu1seWE7BvPuUzLJ9-M8wAAAP0"]
[Thu Jul 30 15:36:01.472044 2026] [security2:error] [pid 189611:tid 189842] [client 185.177.72.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amu1seWE7BvPuUzLJ9-M6wAAAOo"]
[Thu Jul 30 15:36:01.639193 2026] [core:error] [pid 189611:tid 189669] [remote 74.7.241.180:48422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:01.639220 2026] [core:error] [pid 189611:tid 189669] [remote 74.7.241.180:48422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:01.639404 2026] [security2:error] [pid 189611:tid 189849] [client 74.7.241.180:48422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-298832dd.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amu1seWE7BvPuUzLJ9-M9AAA8Tk"]
[Thu Jul 30 15:36:01.680296 2026] [security2:error] [pid 189611:tid 189838] [client 20.113.56.22:15663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/2P.php"] [unique_id "amu1seWE7BvPuUzLJ9-M-AAAAOY"]
[Thu Jul 30 15:36:01.680411 2026] [security2:error] [pid 189611:tid 189838] [client 20.113.56.22:15663] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/2P.php"] [unique_id "amu1seWE7BvPuUzLJ9-M-AAAAOY"]
[Thu Jul 30 15:36:01.790401 2026] [security2:error] [pid 189611:tid 189843] [client 20.203.148.31:57598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/json.php"] [unique_id "amu1seWE7BvPuUzLJ9-M_QAAAOs"]
[Thu Jul 30 15:36:01.940611 2026] [security2:error] [pid 189611:tid 189825] [client 20.113.56.22:15637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/.well-known/about.php"] [unique_id "amu1seWE7BvPuUzLJ9-NAQAAANk"]
[Thu Jul 30 15:36:01.940710 2026] [security2:error] [pid 189611:tid 189825] [client 20.113.56.22:15637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/.well-known/about.php"] [unique_id "amu1seWE7BvPuUzLJ9-NAQAAANk"]
[Thu Jul 30 15:36:02.075001 2026] [autoindex:error] [pid 189611:tid 189809] [client 216.203.20.4:58228] AH01276: Cannot serve directory /home1/lldnyxte/public_html/website_8880a99c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:36:02.213470 2026] [security2:error] [pid 189611:tid 189775] [client 20.113.56.22:15730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-includes/ID3/about.php"] [unique_id "amu1suWE7BvPuUzLJ9-NCgAAAKc"]
[Thu Jul 30 15:36:02.213586 2026] [security2:error] [pid 189611:tid 189775] [client 20.113.56.22:15730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-includes/ID3/about.php"] [unique_id "amu1suWE7BvPuUzLJ9-NCgAAAKc"]
[Thu Jul 30 15:36:02.325319 2026] [security2:error] [pid 189611:tid 189858] [client 185.177.72.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amu1suWE7BvPuUzLJ9-NAgAAAPo"]
[Thu Jul 30 15:36:02.552878 2026] [security2:error] [pid 189611:tid 189802] [client 20.113.56.22:15619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/system_log.php"] [unique_id "amu1suWE7BvPuUzLJ9-NGwAAAMI"]
[Thu Jul 30 15:36:02.553013 2026] [security2:error] [pid 189611:tid 189802] [client 20.113.56.22:15619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/system_log.php"] [unique_id "amu1suWE7BvPuUzLJ9-NGwAAAMI"]
[Thu Jul 30 15:36:03.260034 2026] [security2:error] [pid 189611:tid 189783] [client 2a03:2880:f800:1b:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu1suWE7BvPuUzLJ9-NHAAAr1A"]
[Thu Jul 30 15:36:03.453516 2026] [security2:error] [pid 189611:tid 189694] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amu1s-WE7BvPuUzLJ9-NLQAA_1I"]
[Thu Jul 30 15:36:03.710783 2026] [autoindex:error] [pid 189611:tid 189860] [client 38.133.142.106:43738] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:36:03.815156 2026] [security2:error] [pid 189611:tid 189713] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/m.php"] [unique_id "amu1s-WE7BvPuUzLJ9-NOAAAy2U"]
[Thu Jul 30 15:36:03.828801 2026] [security2:error] [pid 189611:tid 189804] [client 20.113.56.22:15628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1s-WE7BvPuUzLJ9-NOQAAAMQ"]
[Thu Jul 30 15:36:03.849148 2026] [security2:error] [pid 189611:tid 189850] [client 38.172.162.57:16226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1s-WE7BvPuUzLJ9-NOgAAAPI"]
[Thu Jul 30 15:36:03.849250 2026] [security2:error] [pid 189611:tid 189850] [client 38.172.162.57:16226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1s-WE7BvPuUzLJ9-NOgAAAPI"]
[Thu Jul 30 15:36:03.962561 2026] [security2:error] [pid 189611:tid 189813] [client 20.113.56.22:15628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1s-WE7BvPuUzLJ9-NPwAAAM0"]
[Thu Jul 30 15:36:04.100505 2026] [security2:error] [pid 189611:tid 189849] [client 20.113.56.22:15628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/crgio.php"] [unique_id "amu1tOWE7BvPuUzLJ9-NQwAAAPE"]
[Thu Jul 30 15:36:04.100612 2026] [security2:error] [pid 189611:tid 189849] [client 20.113.56.22:15628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/crgio.php"] [unique_id "amu1tOWE7BvPuUzLJ9-NQwAAAPE"]
[Thu Jul 30 15:36:04.202800 2026] [security2:error] [pid 189611:tid 189715] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amu1s-WE7BvPuUzLJ9-NPgAA5Gc"]
[Thu Jul 30 15:36:04.387228 2026] [security2:error] [pid 189611:tid 189712] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wk/index.php"] [unique_id "amu1tOWE7BvPuUzLJ9-NSwAAi2Q"]
[Thu Jul 30 15:36:04.459077 2026] [security2:error] [pid 189611:tid 189768] [client 20.113.56.22:3054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/pucci.php"] [unique_id "amu1tOWE7BvPuUzLJ9-NTQAAAKA"]
[Thu Jul 30 15:36:04.459175 2026] [security2:error] [pid 189611:tid 189768] [client 20.113.56.22:3054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/pucci.php"] [unique_id "amu1tOWE7BvPuUzLJ9-NTQAAAKA"]
[Thu Jul 30 15:36:04.510568 2026] [security2:error] [pid 189611:tid 189718] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/mini.php"] [unique_id "amu1tOWE7BvPuUzLJ9-NUQAAo2o"]
[Thu Jul 30 15:36:04.709540 2026] [security2:error] [pid 189611:tid 189698] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/aa.php"] [unique_id "amu1tOWE7BvPuUzLJ9-NUwAAiFY"]
[Thu Jul 30 15:36:04.724959 2026] [security2:error] [pid 189611:tid 189796] [client 20.113.56.22:15659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1tOWE7BvPuUzLJ9-NVAAAALw"]
[Thu Jul 30 15:36:04.836038 2026] [security2:error] [pid 189611:tid 189725] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/w.php"] [unique_id "amu1tOWE7BvPuUzLJ9-NWQAA-XE"]
[Thu Jul 30 15:36:04.873998 2026] [security2:error] [pid 189611:tid 189770] [client 20.113.56.22:15659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1tOWE7BvPuUzLJ9-NWgAAAKI"]
[Thu Jul 30 15:36:04.943050 2026] [autoindex:error] [pid 189611:tid 189766] [client 38.133.142.106:60316] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:36:04.962495 2026] [security2:error] [pid 189611:tid 189708] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/admin.php"] [unique_id "amu1tOWE7BvPuUzLJ9-NYQAApWA"]
[Thu Jul 30 15:36:05.006719 2026] [security2:error] [pid 189611:tid 189803] [client 20.113.56.22:15659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-temp.php"] [unique_id "amu1teWE7BvPuUzLJ9-NYgAAAMM"]
[Thu Jul 30 15:36:05.006851 2026] [security2:error] [pid 189611:tid 189803] [client 20.113.56.22:15659] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-temp.php"] [unique_id "amu1teWE7BvPuUzLJ9-NYgAAAMM"]
[Thu Jul 30 15:36:05.087810 2026] [security2:error] [pid 189611:tid 189738] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/404.php"] [unique_id "amu1teWE7BvPuUzLJ9-NZgAAx34"]
[Thu Jul 30 15:36:05.216651 2026] [security2:error] [pid 189611:tid 189701] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/init.php"] [unique_id "amu1teWE7BvPuUzLJ9-NZwAA5Vk"]
[Thu Jul 30 15:36:05.269259 2026] [security2:error] [pid 189611:tid 189797] [client 20.113.56.22:15642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-admin/js/index.php"] [unique_id "amu1teWE7BvPuUzLJ9-NaAAAAL0"]
[Thu Jul 30 15:36:05.269373 2026] [security2:error] [pid 189611:tid 189797] [client 20.113.56.22:15642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-admin/js/index.php"] [unique_id "amu1teWE7BvPuUzLJ9-NaAAAAL0"]
[Thu Jul 30 15:36:05.363086 2026] [security2:error] [pid 189611:tid 189704] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/adminfuns.php"] [unique_id "amu1teWE7BvPuUzLJ9-NawAAklw"]
[Thu Jul 30 15:36:05.571365 2026] [security2:error] [pid 189611:tid 189721] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/file.php"] [unique_id "amu1teWE7BvPuUzLJ9-NcwAAsm0"]
[Thu Jul 30 15:36:05.721825 2026] [security2:error] [pid 189611:tid 189703] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/222.php"] [unique_id "amu1teWE7BvPuUzLJ9-NdwAAn1s"]
[Thu Jul 30 15:36:05.740446 2026] [security2:error] [pid 189611:tid 189764] [client 20.113.56.22:15625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/puc.php"] [unique_id "amu1teWE7BvPuUzLJ9-NeAAAAJw"]
[Thu Jul 30 15:36:05.740533 2026] [security2:error] [pid 189611:tid 189764] [client 20.113.56.22:15625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/puc.php"] [unique_id "amu1teWE7BvPuUzLJ9-NeAAAAJw"]
[Thu Jul 30 15:36:05.897877 2026] [security2:error] [pid 189611:tid 189719] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amu1teWE7BvPuUzLJ9-NfQAA4ms"]
[Thu Jul 30 15:36:06.005630 2026] [security2:error] [pid 189611:tid 189742] [client 20.113.56.22:15661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/dx.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NgQAAAIY"]
[Thu Jul 30 15:36:06.005785 2026] [security2:error] [pid 189611:tid 189742] [client 20.113.56.22:15661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/dx.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NgQAAAIY"]
[Thu Jul 30 15:36:06.152525 2026] [autoindex:error] [pid 189611:tid 189833] [client 38.133.142.106:0] AH01276: Cannot serve directory /home2/tfyudite/inmobiliariadia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:36:06.273121 2026] [security2:error] [pid 189611:tid 189747] [client 20.113.56.22:15738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1tuWE7BvPuUzLJ9-NiwAAAIs"]
[Thu Jul 30 15:36:06.279269 2026] [security2:error] [pid 189611:tid 189729] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/admin.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NjAAA63U"]
[Thu Jul 30 15:36:06.403554 2026] [security2:error] [pid 189611:tid 189750] [client 20.113.56.22:15738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/7.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NjQAAAI4"]
[Thu Jul 30 15:36:06.403679 2026] [security2:error] [pid 189611:tid 189750] [client 20.113.56.22:15738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/7.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NjQAAAI4"]
[Thu Jul 30 15:36:06.407261 2026] [security2:error] [pid 189611:tid 189617] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-configs.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NjgAAkQU"]
[Thu Jul 30 15:36:06.537923 2026] [security2:error] [pid 189611:tid 189733] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/php.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NlQAAlnk"]
[Thu Jul 30 15:36:06.623333 2026] [security2:error] [pid 189611:tid 189799] [client 20.203.148.31:41647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/mini.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NmQAAAL8"]
[Thu Jul 30 15:36:06.663008 2026] [security2:error] [pid 189611:tid 189629] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/index.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NmgAA7RE"]
[Thu Jul 30 15:36:06.694212 2026] [security2:error] [pid 189611:tid 189774] [client 20.113.56.22:3021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/8.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NmwAAAKY"]
[Thu Jul 30 15:36:06.694311 2026] [security2:error] [pid 189611:tid 189774] [client 20.113.56.22:3021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/8.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NmwAAAKY"]
[Thu Jul 30 15:36:06.831224 2026] [security2:error] [pid 189611:tid 189667] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/a.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NnAABAzc"]
[Thu Jul 30 15:36:06.868282 2026] [core:notice] [pid 189611:tid 189707] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:06.956180 2026] [security2:error] [pid 189611:tid 189789] [client 20.113.56.22:15717] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "rgserve.ph"] [uri "/1.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NngAAALU"]
[Thu Jul 30 15:36:06.956309 2026] [security2:error] [pid 189611:tid 189789] [client 20.113.56.22:15717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/1.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NngAAALU"]
[Thu Jul 30 15:36:06.956417 2026] [security2:error] [pid 189611:tid 189789] [client 20.113.56.22:15717] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/1.php"] [unique_id "amu1tuWE7BvPuUzLJ9-NngAAALU"]
[Thu Jul 30 15:36:07.219146 2026] [security2:error] [pid 189611:tid 189810] [client 20.113.56.22:15616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/about.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NrQAAAMo"]
[Thu Jul 30 15:36:07.219252 2026] [security2:error] [pid 189611:tid 189810] [client 20.113.56.22:15616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/about.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NrQAAAMo"]
[Thu Jul 30 15:36:07.416442 2026] [security2:error] [pid 189611:tid 189615] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NrgAAiQM"]
[Thu Jul 30 15:36:07.443240 2026] [core:notice] [pid 189611:tid 189862] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:07.489179 2026] [security2:error] [pid 189611:tid 189794] [client 20.113.56.22:3057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/admin.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NsgAAALo"]
[Thu Jul 30 15:36:07.489261 2026] [security2:error] [pid 189611:tid 189794] [client 20.113.56.22:3057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/admin.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NsgAAALo"]
[Thu Jul 30 15:36:07.544829 2026] [security2:error] [pid 189611:tid 189732] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NtAAA-3g"]
[Thu Jul 30 15:36:07.675435 2026] [security2:error] [pid 189611:tid 189734] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/size.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NuwAAl3o"]
[Thu Jul 30 15:36:07.757415 2026] [security2:error] [pid 189611:tid 189847] [client 20.113.56.22:3016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/edit.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NvAAAAO8"]
[Thu Jul 30 15:36:07.757519 2026] [security2:error] [pid 189611:tid 189847] [client 20.113.56.22:3016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/edit.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NvAAAAO8"]
[Thu Jul 30 15:36:07.811894 2026] [security2:error] [pid 189611:tid 189614] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NvQAA_AI"]
[Thu Jul 30 15:36:07.940153 2026] [core:notice] [pid 189611:tid 189829] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:07.958853 2026] [security2:error] [pid 189611:tid 189633] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/403.php"] [unique_id "amu1t-WE7BvPuUzLJ9-NwgAAxBU"]
[Thu Jul 30 15:36:08.018360 2026] [security2:error] [pid 189611:tid 189792] [client 20.113.56.22:15667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-content/admin.php"] [unique_id "amu1uOWE7BvPuUzLJ9-NxgAAALg"]
[Thu Jul 30 15:36:08.018456 2026] [security2:error] [pid 189611:tid 189792] [client 20.113.56.22:15667] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-content/admin.php"] [unique_id "amu1uOWE7BvPuUzLJ9-NxgAAALg"]
[Thu Jul 30 15:36:08.096751 2026] [security2:error] [pid 189611:tid 189645] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amu1uOWE7BvPuUzLJ9-NygAA1CE"]
[Thu Jul 30 15:36:08.227092 2026] [security2:error] [pid 189611:tid 189638] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/as.php"] [unique_id "amu1uOWE7BvPuUzLJ9-NzgAA8Ro"]
[Thu Jul 30 15:36:08.295424 2026] [security2:error] [pid 189611:tid 189838] [client 20.113.56.22:15624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/inputs.php"] [unique_id "amu1uOWE7BvPuUzLJ9-NzwAAAOY"]
[Thu Jul 30 15:36:08.295516 2026] [security2:error] [pid 189611:tid 189838] [client 20.113.56.22:15624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/inputs.php"] [unique_id "amu1uOWE7BvPuUzLJ9-NzwAAAOY"]
[Thu Jul 30 15:36:08.424828 2026] [security2:error] [pid 189611:tid 189648] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N0QAAlCQ"]
[Thu Jul 30 15:36:08.567044 2026] [security2:error] [pid 189611:tid 189753] [client 20.113.56.22:2952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/av.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N1QAAAJE"]
[Thu Jul 30 15:36:08.567166 2026] [security2:error] [pid 189611:tid 189753] [client 20.113.56.22:2952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/av.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N1QAAAJE"]
[Thu Jul 30 15:36:08.584632 2026] [security2:error] [pid 189611:tid 189634] [remote 179.43.134.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.134.43.179.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdogproductguide.com"] [uri "/wp-login.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N0AAA9xY"]
[Thu Jul 30 15:36:08.616221 2026] [security2:error] [pid 189611:tid 189632] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N2QAAoxQ"]
[Thu Jul 30 15:36:08.672663 2026] [security2:error] [pid 189611:tid 189772] [client 38.133.142.106:60316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inmobiliariadia.com"] [uri "/.env"] [unique_id "amu1uOWE7BvPuUzLJ9-N2wAAAKQ"]
[Thu Jul 30 15:36:08.747953 2026] [security2:error] [pid 189611:tid 189627] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/plugins.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N3wAAmg8"]
[Thu Jul 30 15:36:08.846661 2026] [security2:error] [pid 189611:tid 189799] [client 20.113.56.22:15706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/classwithtostring.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N4QAAAL8"]
[Thu Jul 30 15:36:08.846795 2026] [security2:error] [pid 189611:tid 189799] [client 20.113.56.22:15706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/classwithtostring.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N4QAAAL8"]
[Thu Jul 30 15:36:08.860781 2026] [security2:error] [pid 189611:tid 189837] [client 20.203.148.31:56832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/chosen.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N4gAAAOU"]
[Thu Jul 30 15:36:08.930379 2026] [security2:error] [pid 189611:tid 189652] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/js/index.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N5AAAzig"]
[Thu Jul 30 15:36:09.112882 2026] [security2:error] [pid 189611:tid 189852] [client 20.113.56.22:3020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-content/themes/index.php"] [unique_id "amu1ueWE7BvPuUzLJ9-N6gAAAPQ"]
[Thu Jul 30 15:36:09.112972 2026] [security2:error] [pid 189611:tid 189852] [client 20.113.56.22:3020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-content/themes/index.php"] [unique_id "amu1ueWE7BvPuUzLJ9-N6gAAAPQ"]
[Thu Jul 30 15:36:09.134044 2026] [security2:error] [pid 189611:tid 189654] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/go.php"] [unique_id "amu1ueWE7BvPuUzLJ9-N7AAAsCo"]
[Thu Jul 30 15:36:09.246373 2026] [security2:error] [pid 189611:tid 189774] [client 185.177.72.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amu1uOWE7BvPuUzLJ9-N4wAAAKY"]
[Thu Jul 30 15:36:09.261685 2026] [security2:error] [pid 189611:tid 189651] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/aaa.php"] [unique_id "amu1ueWE7BvPuUzLJ9-N8wAAvSc"]
[Thu Jul 30 15:36:09.375949 2026] [security2:error] [pid 189611:tid 189780] [client 20.113.56.22:15711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-blog.php"] [unique_id "amu1ueWE7BvPuUzLJ9-N9QAAAKw"]
[Thu Jul 30 15:36:09.376068 2026] [security2:error] [pid 189611:tid 189780] [client 20.113.56.22:15711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-blog.php"] [unique_id "amu1ueWE7BvPuUzLJ9-N9QAAAKw"]
[Thu Jul 30 15:36:09.423971 2026] [security2:error] [pid 189611:tid 189665] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/getid3-core.php"] [unique_id "amu1ueWE7BvPuUzLJ9-N9wAA1zU"]
[Thu Jul 30 15:36:09.551946 2026] [security2:error] [pid 189611:tid 189720] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/adminer.php"] [unique_id "amu1ueWE7BvPuUzLJ9-N-QAA2mw"]
[Thu Jul 30 15:36:09.645414 2026] [security2:error] [pid 189611:tid 189863] [client 20.113.56.22:3038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "rgserve.ph"] [uri "/cgi-sys/404.html"] [unique_id "amu1ueWE7BvPuUzLJ9-OBAAAAP8"]
[Thu Jul 30 15:36:09.722078 2026] [security2:error] [pid 189611:tid 189657] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amu1ueWE7BvPuUzLJ9-OCgAAny0"]
[Thu Jul 30 15:36:09.776149 2026] [security2:error] [pid 189611:tid 189848] [client 20.113.56.22:3038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/wp-content/admin.php"] [unique_id "amu1ueWE7BvPuUzLJ9-ODQAAAPA"]
[Thu Jul 30 15:36:09.776266 2026] [security2:error] [pid 189611:tid 189848] [client 20.113.56.22:3038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/wp-content/admin.php"] [unique_id "amu1ueWE7BvPuUzLJ9-ODQAAAPA"]
[Thu Jul 30 15:36:09.950511 2026] [security2:error] [pid 189611:tid 189787] [client 185.177.72.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amu1ueWE7BvPuUzLJ9-OCAAAALM"]
[Thu Jul 30 15:36:10.016377 2026] [security2:error] [pid 189611:tid 189643] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/alfa.php"] [unique_id "amu1uuWE7BvPuUzLJ9-ODwAAhR8"]
[Thu Jul 30 15:36:10.040067 2026] [security2:error] [pid 189611:tid 189842] [client 20.113.56.22:15665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/adminfuns.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OEAAAAOo"]
[Thu Jul 30 15:36:10.040209 2026] [security2:error] [pid 189611:tid 189842] [client 20.113.56.22:15665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/adminfuns.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OEAAAAOo"]
[Thu Jul 30 15:36:10.301295 2026] [security2:error] [pid 189611:tid 189771] [client 20.113.56.22:3040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/goods.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OHgAAAKM"]
[Thu Jul 30 15:36:10.301444 2026] [security2:error] [pid 189611:tid 189771] [client 20.113.56.22:3040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/goods.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OHgAAAKM"]
[Thu Jul 30 15:36:10.327539 2026] [security2:error] [pid 189611:tid 189696] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OHwAA3lQ"]
[Thu Jul 30 15:36:10.384824 2026] [security2:error] [pid 189611:tid 189750] [client 128.2.204.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OHQAAAI4"]
[Thu Jul 30 15:36:10.460747 2026] [security2:error] [pid 189611:tid 189677] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OIQAA2UE"]
[Thu Jul 30 15:36:10.574155 2026] [security2:error] [pid 189611:tid 189788] [client 20.113.56.22:2970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/ms-edit.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OIgAAALQ"]
[Thu Jul 30 15:36:10.574279 2026] [security2:error] [pid 189611:tid 189788] [client 20.113.56.22:2970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/ms-edit.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OIgAAALQ"]
[Thu Jul 30 15:36:10.625053 2026] [security2:error] [pid 189611:tid 189663] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OJQAAvDM"]
[Thu Jul 30 15:36:10.752206 2026] [security2:error] [pid 189611:tid 189669] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/edit.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OKgAAmDk"]
[Thu Jul 30 15:36:10.846287 2026] [security2:error] [pid 189611:tid 189769] [client 20.113.56.22:15693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/222.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OLgAAAKE"]
[Thu Jul 30 15:36:10.846440 2026] [security2:error] [pid 189611:tid 189769] [client 20.113.56.22:15693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/222.php"] [unique_id "amu1uuWE7BvPuUzLJ9-OLgAAAKE"]
[Thu Jul 30 15:36:11.074305 2026] [security2:error] [pid 189611:tid 189785] [client 20.203.148.31:41443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/kj.php"] [unique_id "amu1u-WE7BvPuUzLJ9-OMAAAALE"]
[Thu Jul 30 15:36:11.135269 2026] [security2:error] [pid 189611:tid 189867] [client 20.113.56.22:15629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.56.113.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgserve.ph"] [uri "/cgi-bin/index.php"] [unique_id "amu1u-WE7BvPuUzLJ9-OMgAAAQM"]
[Thu Jul 30 15:36:11.135393 2026] [security2:error] [pid 189611:tid 189867] [client 20.113.56.22:15629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rgserve.ph"] [uri "/cgi-bin/index.php"] [unique_id "amu1u-WE7BvPuUzLJ9-OMgAAAQM"]
[Thu Jul 30 15:36:11.177478 2026] [security2:error] [pid 189611:tid 189834] [client 38.133.142.106:43062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inmobiliariadia.com"] [uri "/backend/.env"] [unique_id "amu1u-WE7BvPuUzLJ9-OPAAAAOI"]
[Thu Jul 30 15:36:11.329885 2026] [security2:error] [pid 189611:tid 189653] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/file5.php"] [unique_id "amu1u-WE7BvPuUzLJ9-ORwAAryk"]
[Thu Jul 30 15:36:11.415889 2026] [security2:error] [pid 189611:tid 189742] [client 38.133.142.106:43072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inmobiliariadia.com"] [uri "/api/.env"] [unique_id "amu1u-WE7BvPuUzLJ9-OSQAAAIY"]
[Thu Jul 30 15:36:11.494320 2026] [security2:error] [pid 189611:tid 189690] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/sf.php"] [unique_id "amu1u-WE7BvPuUzLJ9-OTQAA1U4"]
[Thu Jul 30 15:36:11.785083 2026] [security2:error] [pid 189611:tid 189812] [client 20.203.148.31:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/wp-files.php"] [unique_id "amu1u-WE7BvPuUzLJ9-OVQAAAMw"]
[Thu Jul 30 15:36:11.791387 2026] [security2:error] [pid 189611:tid 189680] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wso.php"] [unique_id "amu1u-WE7BvPuUzLJ9-OVgAArkQ"]
[Thu Jul 30 15:36:11.812927 2026] [autoindex:error] [pid 189611:tid 189820] [client 44.213.206.96:46837] AH01276: Cannot serve directory /home2/tgvgzjte/public_html/website_65bcc734/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:36:11.918308 2026] [security2:error] [pid 189611:tid 189655] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/ioxi-o.php"] [unique_id "amu1u-WE7BvPuUzLJ9-OXAAAjCs"]
[Thu Jul 30 15:36:12.094828 2026] [security2:error] [pid 189611:tid 189693] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/file56.php"] [unique_id "amu1vOWE7BvPuUzLJ9-OYgAAxlE"]
[Thu Jul 30 15:36:12.219927 2026] [security2:error] [pid 189611:tid 189662] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amu1vOWE7BvPuUzLJ9-OZAAAmTI"]
[Thu Jul 30 15:36:12.359584 2026] [security2:error] [pid 189611:tid 189786] [client 121.229.156.97:55480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.womenclothingbox.com"] [uri "/"] [unique_id "amu1vOWE7BvPuUzLJ9-OaQAAALI"]
[Thu Jul 30 15:36:12.359694 2026] [security2:error] [pid 189611:tid 189786] [client 121.229.156.97:55480] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.womenclothingbox.com"] [uri "/"] [unique_id "amu1vOWE7BvPuUzLJ9-OaQAAALI"]
[Thu Jul 30 15:36:12.419028 2026] [security2:error] [pid 189611:tid 189709] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/css/index.php"] [unique_id "amu1vOWE7BvPuUzLJ9-OawAAyWE"]
[Thu Jul 30 15:36:12.547215 2026] [security2:error] [pid 189611:tid 189697] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/edit.php"] [unique_id "amu1vOWE7BvPuUzLJ9-ObwAAiFU"]
[Thu Jul 30 15:36:12.738009 2026] [security2:error] [pid 189611:tid 189702] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/2.php"] [unique_id "amu1vOWE7BvPuUzLJ9-OcAAApFo"]
[Thu Jul 30 15:36:12.867734 2026] [security2:error] [pid 189611:tid 189713] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amu1vOWE7BvPuUzLJ9-OdQAAkGU"]
[Thu Jul 30 15:36:12.993911 2026] [security2:error] [pid 189611:tid 189682] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/mah.php"] [unique_id "amu1vOWE7BvPuUzLJ9-OfAAA9EY"]
[Thu Jul 30 15:36:13.221899 2026] [security2:error] [pid 189611:tid 189723] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/send.php"] [unique_id "amu1veWE7BvPuUzLJ9-OfQAAy28"]
[Thu Jul 30 15:36:13.347483 2026] [security2:error] [pid 189611:tid 189712] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amu1veWE7BvPuUzLJ9-OgwAAsGQ"]
[Thu Jul 30 15:36:13.649009 2026] [security2:error] [pid 189611:tid 189716] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/about.php"] [unique_id "amu1veWE7BvPuUzLJ9-OiQAArGg"]
[Thu Jul 30 15:36:13.783652 2026] [security2:error] [pid 189611:tid 189698] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/options.php"] [unique_id "amu1veWE7BvPuUzLJ9-OjQAA9VY"]
[Thu Jul 30 15:36:13.919811 2026] [security2:error] [pid 189611:tid 189728] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/themes/index.php"] [unique_id "amu1veWE7BvPuUzLJ9-OkgABBHQ"]
[Thu Jul 30 15:36:14.099665 2026] [security2:error] [pid 189611:tid 189705] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-file.php"] [unique_id "amu1vuWE7BvPuUzLJ9-OlQAAql0"]
[Thu Jul 30 15:36:14.272586 2026] [security2:error] [pid 189611:tid 189828] [client 20.203.148.31:64341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/wp-setup.php"] [unique_id "amu1vuWE7BvPuUzLJ9-OlgAAANw"]
[Thu Jul 30 15:36:14.306264 2026] [security2:error] [pid 189611:tid 189700] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/sid3.php"] [unique_id "amu1vuWE7BvPuUzLJ9-OmQAAwVg"]
[Thu Jul 30 15:36:14.406718 2026] [security2:error] [pid 189611:tid 189777] [client 38.172.162.57:16553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1vuWE7BvPuUzLJ9-OngAAAKk"]
[Thu Jul 30 15:36:14.406817 2026] [security2:error] [pid 189611:tid 189777] [client 38.172.162.57:16553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1vuWE7BvPuUzLJ9-OngAAAKk"]
[Thu Jul 30 15:36:14.440188 2026] [security2:error] [pid 189611:tid 189701] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/themes.php"] [unique_id "amu1vuWE7BvPuUzLJ9-OoAAA0Fk"]
[Thu Jul 30 15:36:14.574048 2026] [security2:error] [pid 189611:tid 189704] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/index.php"] [unique_id "amu1vuWE7BvPuUzLJ9-OowAA6lw"]
[Thu Jul 30 15:36:14.912308 2026] [security2:error] [pid 189611:tid 189824] [client 20.203.148.31:64359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/defaults.php"] [unique_id "amu1vuWE7BvPuUzLJ9-OqgAAANg"]
[Thu Jul 30 15:36:15.141476 2026] [security2:error] [pid 189611:tid 189703] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/images/index.php"] [unique_id "amu1v-WE7BvPuUzLJ9-OsQAAtFs"]
[Thu Jul 30 15:36:15.277759 2026] [security2:error] [pid 189611:tid 189719] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/num.php"] [unique_id "amu1v-WE7BvPuUzLJ9-OsgAAoGs"]
[Thu Jul 30 15:36:15.530403 2026] [security2:error] [pid 189611:tid 189757] [client 172.237.109.114:22997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1vuWE7BvPuUzLJ9-OrAAAAJU"]
[Thu Jul 30 15:36:15.749888 2026] [security2:error] [pid 189611:tid 189729] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amu1v-WE7BvPuUzLJ9-OvwAAsXU"]
[Thu Jul 30 15:36:15.884647 2026] [security2:error] [pid 189611:tid 189617] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "amu1v-WE7BvPuUzLJ9-OwAAAoQU"]
[Thu Jul 30 15:36:16.019408 2026] [security2:error] [pid 189611:tid 189733] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "amu1wOWE7BvPuUzLJ9-OxwAAwnk"]
[Thu Jul 30 15:36:16.148302 2026] [security2:error] [pid 189611:tid 189629] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/gifclass.php"] [unique_id "amu1wOWE7BvPuUzLJ9-OzAAAwBE"]
[Thu Jul 30 15:36:16.457048 2026] [security2:error] [pid 189611:tid 189613] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amu1wOWE7BvPuUzLJ9-O0AAA1wE"]
[Thu Jul 30 15:36:16.499105 2026] [security2:error] [pid 189611:tid 189831] [client 20.203.148.31:61186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/gtc.php"] [unique_id "amu1wOWE7BvPuUzLJ9-O0gAAAN8"]
[Thu Jul 30 15:36:16.594948 2026] [security2:error] [pid 189611:tid 189625] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/css/index.php"] [unique_id "amu1wOWE7BvPuUzLJ9-O2QAAqg0"]
[Thu Jul 30 15:36:16.743073 2026] [security2:error] [pid 189611:tid 189620] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-cron.php"] [unique_id "amu1wOWE7BvPuUzLJ9-O2gAA4wg"]
[Thu Jul 30 15:36:16.883839 2026] [security2:error] [pid 189611:tid 189623] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-block.php"] [unique_id "amu1wOWE7BvPuUzLJ9-O2wAAlws"]
[Thu Jul 30 15:36:17.022067 2026] [security2:error] [pid 189611:tid 189731] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "amu1weWE7BvPuUzLJ9-O3wAAzHc"]
[Thu Jul 30 15:36:17.088923 2026] [security2:error] [pid 189611:tid 189863] [client 20.203.148.31:56852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/import.php"] [unique_id "amu1weWE7BvPuUzLJ9-O6QAAAP8"]
[Thu Jul 30 15:36:17.319079 2026] [security2:error] [pid 189611:tid 189648] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/classwithtostring.php"] [unique_id "amu1weWE7BvPuUzLJ9-O8gAA1iQ"]
[Thu Jul 30 15:36:17.452611 2026] [security2:error] [pid 189611:tid 189641] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/test1.php"] [unique_id "amu1weWE7BvPuUzLJ9-O8wAAlh0"]
[Thu Jul 30 15:36:17.819043 2026] [security2:error] [pid 189611:tid 189639] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/images/index.php"] [unique_id "amu1weWE7BvPuUzLJ9-PAAAA9Bs"]
[Thu Jul 30 15:36:18.197949 2026] [security2:error] [pid 189611:tid 189644] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/asd.php"] [unique_id "amu1wuWE7BvPuUzLJ9-PCwAA0SA"]
[Thu Jul 30 15:36:18.324710 2026] [security2:error] [pid 189611:tid 189651] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amu1wuWE7BvPuUzLJ9-PDQAA9Sc"]
[Thu Jul 30 15:36:18.485588 2026] [security2:error] [pid 189611:tid 189673] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amu1wuWE7BvPuUzLJ9-PDgAAtz0"]
[Thu Jul 30 15:36:18.612072 2026] [security2:error] [pid 189611:tid 189658] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/atomlib.php"] [unique_id "amu1wuWE7BvPuUzLJ9-PEgAA9i4"]
[Thu Jul 30 15:36:19.026840 2026] [security2:error] [pid 189611:tid 189752] [client 20.203.148.31:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/lufix.php"] [unique_id "amu1w-WE7BvPuUzLJ9-PJAAAAJA"]
[Thu Jul 30 15:36:19.092773 2026] [security2:error] [pid 189611:tid 189677] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amu1w-WE7BvPuUzLJ9-PKAAAs0E"]
[Thu Jul 30 15:36:19.147652 2026] [security2:error] [pid 189611:tid 189839] [client 74.7.175.185:50204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.oneuro.org"] [uri "/cgi-sys/404.html"] [unique_id "amu1w-WE7BvPuUzLJ9-PKgAA5zM"]
[Thu Jul 30 15:36:19.197227 2026] [core:error] [pid 189611:tid 189786] [client 74.7.230.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:19.197247 2026] [core:error] [pid 189611:tid 189786] [client 74.7.230.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:19.197339 2026] [security2:error] [pid 189611:tid 189786] [client 74.7.230.19:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/index.php"] [unique_id "amu1w-WE7BvPuUzLJ9-PMAAAALI"]
[Thu Jul 30 15:36:19.197945 2026] [security2:error] [pid 189611:tid 189856] [client 74.7.230.19:42308] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpanel.ldk.nyx.temporary.site"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "amu1w-WE7BvPuUzLJ9-PLgAA-Eo"]
[Thu Jul 30 15:36:19.218493 2026] [core:notice] [pid 189611:tid 189685] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:19.424700 2026] [fcgid:warn] [pid 189611:tid 189765] (70014)End of file found: [client 118.26.104.78:36922] mod_fcgid: can't get data from http client
[Thu Jul 30 15:36:19.756676 2026] [core:notice] [pid 189611:tid 189690] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:19.820929 2026] [core:error] [pid 189611:tid 189773] [client 23.95.96.140:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:19.820969 2026] [core:error] [pid 189611:tid 189773] [client 23.95.96.140:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:20.220564 2026] [security2:error] [pid 189611:tid 189655] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/inputs.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PWQAApis"]
[Thu Jul 30 15:36:20.348738 2026] [security2:error] [pid 189611:tid 189687] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/index.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PXQAAzEs"]
[Thu Jul 30 15:36:20.478013 2026] [security2:error] [pid 189611:tid 189695] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/network/index.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PYAAA8FM"]
[Thu Jul 30 15:36:20.605171 2026] [security2:error] [pid 189611:tid 189650] [remote 158.158.41.78:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "propertyspro.com"] [uri "/wp-content/1.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PYQAAuyY"]
[Thu Jul 30 15:36:20.605289 2026] [security2:error] [pid 189611:tid 189650] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/1.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PYQAAuyY"]
[Thu Jul 30 15:36:20.664104 2026] [security2:error] [pid 189611:tid 189820] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PXwAAANQ"]
[Thu Jul 30 15:36:20.664235 2026] [security2:error] [pid 189611:tid 189820] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PXwAAANQ"]
[Thu Jul 30 15:36:20.788494 2026] [security2:error] [pid 189611:tid 189702] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/plugin.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PagAA51o"]
[Thu Jul 30 15:36:20.915766 2026] [security2:error] [pid 189611:tid 189713] [remote 158.158.41.78:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "propertyspro.com"] [uri "/1.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PbgAA22U"]
[Thu Jul 30 15:36:20.915904 2026] [security2:error] [pid 189611:tid 189713] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/1.php"] [unique_id "amu1xOWE7BvPuUzLJ9-PbgAA22U"]
[Thu Jul 30 15:36:20.948233 2026] [core:notice] [pid 189611:tid 189722] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:20.972680 2026] [security2:error] [pid 189611:tid 189843] [client 172.237.109.114:55651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/wp-cloudy/readme.txt"] [unique_id "amu1xOWE7BvPuUzLJ9-PcAAAAOs"]
[Thu Jul 30 15:36:21.138128 2026] [security2:error] [pid 189611:tid 189682] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/gg.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PdwAAikY"]
[Thu Jul 30 15:36:21.153784 2026] [security2:error] [pid 189611:tid 189776] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PeAAAAKg"]
[Thu Jul 30 15:36:21.153891 2026] [security2:error] [pid 189611:tid 189776] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PeAAAAKg"]
[Thu Jul 30 15:36:21.440291 2026] [security2:error] [pid 189611:tid 189714] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-content/languages/index.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PggAAq2Y"]
[Thu Jul 30 15:36:21.564616 2026] [security2:error] [pid 189611:tid 189710] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PhgAA-mI"]
[Thu Jul 30 15:36:21.602801 2026] [security2:error] [pid 189611:tid 189786] [client 172.237.109.114:11221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PcwAAALI"]
[Thu Jul 30 15:36:21.655970 2026] [security2:error] [pid 189611:tid 189864] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wicked.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PhwAAAQA"]
[Thu Jul 30 15:36:21.656115 2026] [security2:error] [pid 189611:tid 189864] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wicked.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PhwAAAQA"]
[Thu Jul 30 15:36:21.690112 2026] [security2:error] [pid 189611:tid 189699] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PiwAAnlc"]
[Thu Jul 30 15:36:21.916753 2026] [security2:error] [pid 189611:tid 189668] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/file.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PkgAAvDg"]
[Thu Jul 30 15:36:22.042441 2026] [security2:error] [pid 189611:tid 189726] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/user/index.php"] [unique_id "amu1xuWE7BvPuUzLJ9-PkwAA2nI"]
[Thu Jul 30 15:36:22.178823 2026] [security2:error] [pid 189611:tid 189847] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wpx.php"] [unique_id "amu1xuWE7BvPuUzLJ9-PmgAAAO8"]
[Thu Jul 30 15:36:22.178933 2026] [security2:error] [pid 189611:tid 189847] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wpx.php"] [unique_id "amu1xuWE7BvPuUzLJ9-PmgAAAO8"]
[Thu Jul 30 15:36:22.403455 2026] [security2:error] [pid 189611:tid 189738] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amu1xuWE7BvPuUzLJ9-PqAAA4X4"]
[Thu Jul 30 15:36:22.489008 2026] [security2:error] [pid 189611:tid 189789] [client 8.217.211.177:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tereashops.com"] [uri "/index.php"] [unique_id "amu1xeWE7BvPuUzLJ9-PhQAAALU"]
[Thu Jul 30 15:36:22.534529 2026] [security2:error] [pid 189611:tid 189701] [remote 158.158.41.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "propertyspro.com"] [uri "/index/function.php"] [unique_id "amu1xuWE7BvPuUzLJ9-PqwAA21k"]
[Thu Jul 30 15:36:22.619681 2026] [security2:error] [pid 189611:tid 189821] [client 20.203.148.31:58010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/Geforce.php"] [unique_id "amu1xuWE7BvPuUzLJ9-PrAAAANU"]
[Thu Jul 30 15:36:22.695649 2026] [security2:error] [pid 189611:tid 189756] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/images.php"] [unique_id "amu1xuWE7BvPuUzLJ9-PsAAAAJQ"]
[Thu Jul 30 15:36:22.695753 2026] [security2:error] [pid 189611:tid 189756] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/images.php"] [unique_id "amu1xuWE7BvPuUzLJ9-PsAAAAJQ"]
[Thu Jul 30 15:36:23.179123 2026] [security2:error] [pid 189611:tid 189779] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/1xmomo.php"] [unique_id "amu1x-WE7BvPuUzLJ9-PvgAAAKs"]
[Thu Jul 30 15:36:23.179238 2026] [security2:error] [pid 189611:tid 189779] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/1xmomo.php"] [unique_id "amu1x-WE7BvPuUzLJ9-PvgAAAKs"]
[Thu Jul 30 15:36:23.219405 2026] [core:notice] [pid 189611:tid 189727] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:23.687084 2026] [security2:error] [pid 189611:tid 189846] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/1revo.php"] [unique_id "amu1x-WE7BvPuUzLJ9-PywAAAO4"]
[Thu Jul 30 15:36:23.687221 2026] [security2:error] [pid 189611:tid 189846] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/1revo.php"] [unique_id "amu1x-WE7BvPuUzLJ9-PywAAAO4"]
[Thu Jul 30 15:36:23.982025 2026] [security2:error] [pid 189611:tid 189794] [client 20.91.199.21:12916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/geju.php"] [unique_id "amu1x-WE7BvPuUzLJ9-P1gAAALo"]
[Thu Jul 30 15:36:24.173324 2026] [security2:error] [pid 189611:tid 189841] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/cong.php"] [unique_id "amu1yOWE7BvPuUzLJ9-P2AAAAOk"]
[Thu Jul 30 15:36:24.173437 2026] [security2:error] [pid 189611:tid 189841] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/cong.php"] [unique_id "amu1yOWE7BvPuUzLJ9-P2AAAAOk"]
[Thu Jul 30 15:36:24.672515 2026] [security2:error] [pid 189611:tid 189862] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/a.php"] [unique_id "amu1yOWE7BvPuUzLJ9-P5AAAAP4"]
[Thu Jul 30 15:36:24.672639 2026] [security2:error] [pid 189611:tid 189862] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/a.php"] [unique_id "amu1yOWE7BvPuUzLJ9-P5AAAAP4"]
[Thu Jul 30 15:36:24.949097 2026] [security2:error] [pid 189611:tid 189776] [client 38.172.162.57:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1yOWE7BvPuUzLJ9-P7gAAAKg"]
[Thu Jul 30 15:36:24.949238 2026] [security2:error] [pid 189611:tid 189776] [client 38.172.162.57:16320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1yOWE7BvPuUzLJ9-P7gAAAKg"]
[Thu Jul 30 15:36:25.028537 2026] [autoindex:error] [pid 189611:tid 189859] [client 64.23.168.244:36338] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:36:25.161581 2026] [security2:error] [pid 189611:tid 189805] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/srontol.php"] [unique_id "amu1yeWE7BvPuUzLJ9-P8AAAAMU"]
[Thu Jul 30 15:36:25.161702 2026] [security2:error] [pid 189611:tid 189805] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/srontol.php"] [unique_id "amu1yeWE7BvPuUzLJ9-P8AAAAMU"]
[Thu Jul 30 15:36:25.697209 2026] [security2:error] [pid 189611:tid 189848] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/reop3.php"] [unique_id "amu1yeWE7BvPuUzLJ9-P-wAAAPA"]
[Thu Jul 30 15:36:25.697319 2026] [security2:error] [pid 189611:tid 189848] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/reop3.php"] [unique_id "amu1yeWE7BvPuUzLJ9-P-wAAAPA"]
[Thu Jul 30 15:36:25.976067 2026] [core:notice] [pid 189611:tid 189620] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:26.219772 2026] [security2:error] [pid 189611:tid 189839] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/file5.php"] [unique_id "amu1yuWE7BvPuUzLJ9-QCQAAAOc"]
[Thu Jul 30 15:36:26.219860 2026] [security2:error] [pid 189611:tid 189839] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/file5.php"] [unique_id "amu1yuWE7BvPuUzLJ9-QCQAAAOc"]
[Thu Jul 30 15:36:26.453682 2026] [autoindex:error] [pid 189611:tid 189820] [client 64.23.168.244:60502] AH01276: Cannot serve directory /home2/kiinyxte/xexrecords.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:36:26.593206 2026] [core:notice] [pid 189611:tid 189614] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:26.621235 2026] [security2:error] [pid 189611:tid 189734] [remote 57.141.0.49:33608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/83915116186/feed/rss2/"] [unique_id "amu1yuWE7BvPuUzLJ9-QFgAAjno"]
[Thu Jul 30 15:36:26.704421 2026] [security2:error] [pid 189611:tid 189744] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/domvf.php"] [unique_id "amu1yuWE7BvPuUzLJ9-QFwAAAIg"]
[Thu Jul 30 15:36:26.704533 2026] [security2:error] [pid 189611:tid 189744] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/domvf.php"] [unique_id "amu1yuWE7BvPuUzLJ9-QFwAAAIg"]
[Thu Jul 30 15:36:27.193550 2026] [security2:error] [pid 189611:tid 189862] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/zero.php"] [unique_id "amu1y-WE7BvPuUzLJ9-QJAAAAP4"]
[Thu Jul 30 15:36:27.193655 2026] [security2:error] [pid 189611:tid 189862] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/zero.php"] [unique_id "amu1y-WE7BvPuUzLJ9-QJAAAAP4"]
[Thu Jul 30 15:36:27.338851 2026] [core:notice] [pid 189611:tid 189628] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:27.716125 2026] [security2:error] [pid 189611:tid 189823] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/002.php"] [unique_id "amu1y-WE7BvPuUzLJ9-QMQAAANc"]
[Thu Jul 30 15:36:27.716221 2026] [security2:error] [pid 189611:tid 189823] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/002.php"] [unique_id "amu1y-WE7BvPuUzLJ9-QMQAAANc"]
[Thu Jul 30 15:36:27.921060 2026] [security2:error] [pid 189611:tid 189784] [client 20.203.148.31:65200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/a4.php"] [unique_id "amu1y-WE7BvPuUzLJ9-QMwAAALA"]
[Thu Jul 30 15:36:28.233840 2026] [security2:error] [pid 189611:tid 189813] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/thoms.php"] [unique_id "amu1zOWE7BvPuUzLJ9-QQAAAAM0"]
[Thu Jul 30 15:36:28.233936 2026] [security2:error] [pid 189611:tid 189813] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/thoms.php"] [unique_id "amu1zOWE7BvPuUzLJ9-QQAAAAM0"]
[Thu Jul 30 15:36:28.428987 2026] [core:notice] [pid 189611:tid 189639] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:28.730717 2026] [security2:error] [pid 189611:tid 189788] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fi22.php"] [unique_id "amu1zOWE7BvPuUzLJ9-QTQAAALQ"]
[Thu Jul 30 15:36:28.730813 2026] [security2:error] [pid 189611:tid 189788] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fi22.php"] [unique_id "amu1zOWE7BvPuUzLJ9-QTQAAALQ"]
[Thu Jul 30 15:36:29.217858 2026] [proxy:error] [pid 189611:tid 189775] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:29.217921 2026] [proxy_http:error] [pid 189611:tid 189775] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:29.218488 2026] [proxy:error] [pid 189611:tid 189775] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:29.218533 2026] [proxy_http:error] [pid 189611:tid 189775] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:29.218622 2026] [security2:error] [pid 189611:tid 189775] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amu1zeWE7BvPuUzLJ9-QWAAAAKc"]
[Thu Jul 30 15:36:29.719944 2026] [security2:error] [pid 189611:tid 189792] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/82.php"] [unique_id "amu1zeWE7BvPuUzLJ9-QXwAAALg"]
[Thu Jul 30 15:36:29.720056 2026] [security2:error] [pid 189611:tid 189792] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/82.php"] [unique_id "amu1zeWE7BvPuUzLJ9-QXwAAALg"]
[Thu Jul 30 15:36:29.742761 2026] [core:error] [pid 189611:tid 189837] [client 23.95.96.140:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:29.742781 2026] [core:error] [pid 189611:tid 189837] [client 23.95.96.140:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:29.788752 2026] [security2:error] [pid 189611:tid 189763] [client 52.238.199.152:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.199.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkf.jo"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amu1zeWE7BvPuUzLJ9-QZgAAAJs"]
[Thu Jul 30 15:36:29.998193 2026] [security2:error] [pid 189611:tid 189757] [client 20.91.199.21:55162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amu1zeWE7BvPuUzLJ9-QagAAAJU"]
[Thu Jul 30 15:36:30.210813 2026] [security2:error] [pid 189611:tid 189671] [remote 57.141.0.15:47920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/96409857935/feed/rss2/"] [unique_id "amu1zuWE7BvPuUzLJ9-QbwAAzjs"]
[Thu Jul 30 15:36:30.236196 2026] [security2:error] [pid 189611:tid 189860] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sx.php"] [unique_id "amu1zuWE7BvPuUzLJ9-QcAAAAPw"]
[Thu Jul 30 15:36:30.236277 2026] [security2:error] [pid 189611:tid 189860] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sx.php"] [unique_id "amu1zuWE7BvPuUzLJ9-QcAAAAPw"]
[Thu Jul 30 15:36:30.649072 2026] [security2:error] [pid 189611:tid 189797] [client 20.203.148.31:65246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/accueil.php"] [unique_id "amu1zuWE7BvPuUzLJ9-QewAAAL0"]
[Thu Jul 30 15:36:30.773178 2026] [security2:error] [pid 189611:tid 189806] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/dex.php"] [unique_id "amu1zuWE7BvPuUzLJ9-QfwAAAMY"]
[Thu Jul 30 15:36:30.773338 2026] [security2:error] [pid 189611:tid 189806] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/dex.php"] [unique_id "amu1zuWE7BvPuUzLJ9-QfwAAAMY"]
[Thu Jul 30 15:36:30.924549 2026] [security2:error] [pid 189611:tid 189783] [client 134.19.179.139:34288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu1zuWE7BvPuUzLJ9-QgwAAAK8"]
[Thu Jul 30 15:36:30.924651 2026] [security2:error] [pid 189611:tid 189783] [client 134.19.179.139:34288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu1zuWE7BvPuUzLJ9-QgwAAAK8"]
[Thu Jul 30 15:36:31.045070 2026] [security2:error] [pid 189611:tid 189759] [client 20.91.199.21:12895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp.php"] [unique_id "amu1z-WE7BvPuUzLJ9-QiAAAAJc"]
[Thu Jul 30 15:36:31.123412 2026] [security2:error] [pid 189611:tid 189798] [client 20.203.148.31:62810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/dashboard.php"] [unique_id "amu1z-WE7BvPuUzLJ9-QiQAAAL4"]
[Thu Jul 30 15:36:31.261836 2026] [security2:error] [pid 189611:tid 189758] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fpwch.php"] [unique_id "amu1z-WE7BvPuUzLJ9-QjQAAAJY"]
[Thu Jul 30 15:36:31.262001 2026] [security2:error] [pid 189611:tid 189758] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fpwch.php"] [unique_id "amu1z-WE7BvPuUzLJ9-QjQAAAJY"]
[Thu Jul 30 15:36:31.305708 2026] [security2:error] [pid 189611:tid 189674] [remote 57.141.0.33:43966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu1z-WE7BvPuUzLJ9-QjgAAjj4"]
[Thu Jul 30 15:36:31.779680 2026] [security2:error] [pid 189611:tid 189815] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/black.php"] [unique_id "amu1z-WE7BvPuUzLJ9-QnAAAAM8"]
[Thu Jul 30 15:36:31.779767 2026] [security2:error] [pid 189611:tid 189815] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/black.php"] [unique_id "amu1z-WE7BvPuUzLJ9-QnAAAAM8"]
[Thu Jul 30 15:36:31.927353 2026] [security2:error] [pid 189611:tid 189768] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu1z-WE7BvPuUzLJ9-QlwAAAKA"]
[Thu Jul 30 15:36:32.033873 2026] [security2:error] [pid 189611:tid 189867] [client 183.60.87.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu1z-WE7BvPuUzLJ9-QogAAAQM"]
[Thu Jul 30 15:36:32.224429 2026] [security2:error] [pid 189611:tid 189840] [client 20.203.148.31:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/radio.php"] [unique_id "amu10OWE7BvPuUzLJ9-QrgAAAOg"]
[Thu Jul 30 15:36:32.297712 2026] [security2:error] [pid 189611:tid 189801] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/loader.php"] [unique_id "amu10OWE7BvPuUzLJ9-QrwAAAME"]
[Thu Jul 30 15:36:32.297827 2026] [security2:error] [pid 189611:tid 189801] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/loader.php"] [unique_id "amu10OWE7BvPuUzLJ9-QrwAAAME"]
[Thu Jul 30 15:36:32.793936 2026] [security2:error] [pid 189611:tid 189868] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/file61.php"] [unique_id "amu10OWE7BvPuUzLJ9-QuQAAAQQ"]
[Thu Jul 30 15:36:32.794068 2026] [security2:error] [pid 189611:tid 189868] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/file61.php"] [unique_id "amu10OWE7BvPuUzLJ9-QuQAAAQQ"]
[Thu Jul 30 15:36:33.089805 2026] [security2:error] [pid 189611:tid 189781] [client 127.0.0.1:55912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu10eWE7BvPuUzLJ9-QvgAAAK0"]
[Thu Jul 30 15:36:33.089893 2026] [security2:error] [pid 189611:tid 189813] [client 74.7.230.31:59394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.bwu.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amu10eWE7BvPuUzLJ9-QvQAAzTE"]
[Thu Jul 30 15:36:33.180741 2026] [core:notice] [pid 189611:tid 189690] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:33.281673 2026] [security2:error] [pid 189611:tid 189825] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-css.php"] [unique_id "amu10eWE7BvPuUzLJ9-QxwAAANk"]
[Thu Jul 30 15:36:33.281802 2026] [security2:error] [pid 189611:tid 189825] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-css.php"] [unique_id "amu10eWE7BvPuUzLJ9-QxwAAANk"]
[Thu Jul 30 15:36:33.669587 2026] [security2:error] [pid 189611:tid 189798] [client 191.232.199.39:9130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wk/index.php"] [unique_id "amu10eWE7BvPuUzLJ9-QywAAAL4"]
[Thu Jul 30 15:36:33.790745 2026] [security2:error] [pid 189611:tid 189849] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-blink.php"] [unique_id "amu10eWE7BvPuUzLJ9-Q0gAAAPE"]
[Thu Jul 30 15:36:33.790857 2026] [security2:error] [pid 189611:tid 189849] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-blink.php"] [unique_id "amu10eWE7BvPuUzLJ9-Q0gAAAPE"]
[Thu Jul 30 15:36:34.000847 2026] [security2:error] [pid 189611:tid 189762] [client 20.203.148.31:58872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/wpsml-sys.php"] [unique_id "amu10uWE7BvPuUzLJ9-Q2gAAAJo"]
[Thu Jul 30 15:36:34.259565 2026] [security2:error] [pid 189611:tid 189804] [client 20.91.199.21:41728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/aaa.php"] [unique_id "amu10uWE7BvPuUzLJ9-Q3gAAAMQ"]
[Thu Jul 30 15:36:34.306678 2026] [security2:error] [pid 189611:tid 189858] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/txets.php"] [unique_id "amu10uWE7BvPuUzLJ9-Q4AAAAPo"]
[Thu Jul 30 15:36:34.306768 2026] [security2:error] [pid 189611:tid 189858] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/txets.php"] [unique_id "amu10uWE7BvPuUzLJ9-Q4AAAAPo"]
[Thu Jul 30 15:36:34.410706 2026] [core:notice] [pid 189611:tid 189779] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:34.813875 2026] [security2:error] [pid 189611:tid 189743] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/pucci.php"] [unique_id "amu10uWE7BvPuUzLJ9-Q6gAAAIc"]
[Thu Jul 30 15:36:34.813968 2026] [security2:error] [pid 189611:tid 189743] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/pucci.php"] [unique_id "amu10uWE7BvPuUzLJ9-Q6gAAAIc"]
[Thu Jul 30 15:36:35.172427 2026] [security2:error] [pid 189611:tid 189860] [client 191.232.199.39:8557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/av.php"] [unique_id "amu10-WE7BvPuUzLJ9-Q9wAAAPw"]
[Thu Jul 30 15:36:35.210536 2026] [security2:error] [pid 189611:tid 189782] [client 43.173.178.65:48516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JPA/plagiarism"] [unique_id "amu10uWE7BvPuUzLJ9-Q9AAAAK4"]
[Thu Jul 30 15:36:35.282612 2026] [security2:error] [pid 189611:tid 189852] [client 213.152.162.84:37642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amu10-WE7BvPuUzLJ9-Q-gAAAPQ"]
[Thu Jul 30 15:36:35.282707 2026] [security2:error] [pid 189611:tid 189852] [client 213.152.162.84:37642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "safaratraveltours.com"] [uri "/xmlrpc.php"] [unique_id "amu10-WE7BvPuUzLJ9-Q-gAAAPQ"]
[Thu Jul 30 15:36:35.338891 2026] [security2:error] [pid 189611:tid 189781] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xwpg.php"] [unique_id "amu10-WE7BvPuUzLJ9-Q_AAAAK0"]
[Thu Jul 30 15:36:35.339002 2026] [security2:error] [pid 189611:tid 189781] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xwpg.php"] [unique_id "amu10-WE7BvPuUzLJ9-Q_AAAAK0"]
[Thu Jul 30 15:36:35.652525 2026] [security2:error] [pid 189611:tid 189797] [client 38.172.162.57:16340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu10-WE7BvPuUzLJ9-RAwAAAL0"]
[Thu Jul 30 15:36:35.652654 2026] [security2:error] [pid 189611:tid 189797] [client 38.172.162.57:16340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu10-WE7BvPuUzLJ9-RAwAAAL0"]
[Thu Jul 30 15:36:35.830656 2026] [security2:error] [pid 189611:tid 189798] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amu10-WE7BvPuUzLJ9-RCgAAAL4"]
[Thu Jul 30 15:36:35.830751 2026] [security2:error] [pid 189611:tid 189798] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amu10-WE7BvPuUzLJ9-RCgAAAL4"]
[Thu Jul 30 15:36:35.873093 2026] [core:notice] [pid 189611:tid 189750] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:36.009972 2026] [core:notice] [pid 189611:tid 189761] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:36.200571 2026] [security2:error] [pid 189611:tid 189794] [client 20.203.148.31:61687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/02.php"] [unique_id "amu11OWE7BvPuUzLJ9-RFQAAALo"]
[Thu Jul 30 15:36:36.332150 2026] [security2:error] [pid 189611:tid 189800] [client 20.48.234.177:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amu11OWE7BvPuUzLJ9-RGQAAAMA"]
[Thu Jul 30 15:36:36.332259 2026] [security2:error] [pid 189611:tid 189800] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amu11OWE7BvPuUzLJ9-RGQAAAMA"]
[Thu Jul 30 15:36:36.332363 2026] [security2:error] [pid 189611:tid 189800] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amu11OWE7BvPuUzLJ9-RGQAAAMA"]
[Thu Jul 30 15:36:36.607078 2026] [security2:error] [pid 189611:tid 189772] [client 191.232.199.39:8538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/mini.php"] [unique_id "amu11OWE7BvPuUzLJ9-RIgAAAKQ"]
[Thu Jul 30 15:36:36.861395 2026] [security2:error] [pid 189611:tid 189796] [client 43.172.196.36:42454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/JPA/$$$call$$$/page/page/css"] [unique_id "amu11OWE7BvPuUzLJ9-RIQAAALw"], referer: http://ejournalugj.com/
[Thu Jul 30 15:36:36.871677 2026] [security2:error] [pid 189611:tid 189812] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amu11OWE7BvPuUzLJ9-RKQAAAMw"]
[Thu Jul 30 15:36:36.871763 2026] [security2:error] [pid 189611:tid 189812] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amu11OWE7BvPuUzLJ9-RKQAAAMw"]
[Thu Jul 30 15:36:37.382443 2026] [security2:error] [pid 189611:tid 189839] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-admin/js/index.php"] [unique_id "amu11eWE7BvPuUzLJ9-ROgAAAOc"]
[Thu Jul 30 15:36:37.382574 2026] [security2:error] [pid 189611:tid 189839] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-admin/js/index.php"] [unique_id "amu11eWE7BvPuUzLJ9-ROgAAAOc"]
[Thu Jul 30 15:36:37.478968 2026] [security2:error] [pid 189611:tid 189836] [client 51.36.223.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu11eWE7BvPuUzLJ9-ROQAAAOQ"], referer: https://cnpinyin.com
[Thu Jul 30 15:36:37.905745 2026] [security2:error] [pid 189611:tid 189856] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/aa.php"] [unique_id "amu11eWE7BvPuUzLJ9-RRgAAAPg"]
[Thu Jul 30 15:36:37.905844 2026] [security2:error] [pid 189611:tid 189856] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/aa.php"] [unique_id "amu11eWE7BvPuUzLJ9-RRgAAAPg"]
[Thu Jul 30 15:36:38.041471 2026] [core:notice] [pid 189611:tid 189704] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:38.366726 2026] [security2:error] [pid 189611:tid 189741] [client 191.232.199.39:8544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/aa.php"] [unique_id "amu11uWE7BvPuUzLJ9-RWQAAAIU"]
[Thu Jul 30 15:36:38.451111 2026] [security2:error] [pid 189611:tid 189803] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xyn.php"] [unique_id "amu11uWE7BvPuUzLJ9-RXQAAAMM"]
[Thu Jul 30 15:36:38.451249 2026] [security2:error] [pid 189611:tid 189803] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xyn.php"] [unique_id "amu11uWE7BvPuUzLJ9-RXQAAAMM"]
[Thu Jul 30 15:36:38.976371 2026] [security2:error] [pid 189611:tid 189847] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-wp.php"] [unique_id "amu11uWE7BvPuUzLJ9-RZwAAAO8"]
[Thu Jul 30 15:36:38.976479 2026] [security2:error] [pid 189611:tid 189847] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-wp.php"] [unique_id "amu11uWE7BvPuUzLJ9-RZwAAAO8"]
[Thu Jul 30 15:36:39.246145 2026] [security2:error] [pid 189611:tid 189772] [client 20.203.148.31:63710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/infos.php"] [unique_id "amu11-WE7BvPuUzLJ9-RbwAAAKQ"]
[Thu Jul 30 15:36:39.479824 2026] [security2:error] [pid 189611:tid 189842] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/aw.php"] [unique_id "amu11-WE7BvPuUzLJ9-RcQAAAOo"]
[Thu Jul 30 15:36:39.479935 2026] [security2:error] [pid 189611:tid 189842] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/aw.php"] [unique_id "amu11-WE7BvPuUzLJ9-RcQAAAOo"]
[Thu Jul 30 15:36:39.683005 2026] [core:notice] [pid 189611:tid 189840] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:39.705855 2026] [security2:error] [pid 189611:tid 189787] [client 191.232.199.39:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/w.php"] [unique_id "amu11-WE7BvPuUzLJ9-RfgAAALM"]
[Thu Jul 30 15:36:39.731110 2026] [security2:error] [pid 189611:tid 189799] [client 52.167.144.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nafmedical.com"] [uri "/index.php"] [unique_id "amu11-WE7BvPuUzLJ9-RcAAAv3s"]
[Thu Jul 30 15:36:39.994625 2026] [security2:error] [pid 189611:tid 189798] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/classwithtostring.php"] [unique_id "amu11-WE7BvPuUzLJ9-RiAAAAL4"]
[Thu Jul 30 15:36:39.994745 2026] [security2:error] [pid 189611:tid 189798] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/classwithtostring.php"] [unique_id "amu11-WE7BvPuUzLJ9-RiAAAAL4"]
[Thu Jul 30 15:36:40.554841 2026] [security2:error] [pid 189611:tid 189794] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/yawa.php"] [unique_id "amu12OWE7BvPuUzLJ9-RmAAAALo"]
[Thu Jul 30 15:36:40.555018 2026] [security2:error] [pid 189611:tid 189794] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/yawa.php"] [unique_id "amu12OWE7BvPuUzLJ9-RmAAAALo"]
[Thu Jul 30 15:36:40.572542 2026] [security2:error] [pid 189611:tid 189788] [client 20.91.199.21:1590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/hoot.php"] [unique_id "amu12OWE7BvPuUzLJ9-RmQAAALQ"]
[Thu Jul 30 15:36:40.693953 2026] [security2:error] [pid 189611:tid 189765] [client 172.237.109.114:38374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu12OWE7BvPuUzLJ9-RjwAAAJ0"]
[Thu Jul 30 15:36:41.072952 2026] [security2:error] [pid 189611:tid 189784] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sym403.php"] [unique_id "amu12eWE7BvPuUzLJ9-RqgAAALA"]
[Thu Jul 30 15:36:41.073071 2026] [security2:error] [pid 189611:tid 189784] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sym403.php"] [unique_id "amu12eWE7BvPuUzLJ9-RqgAAALA"]
[Thu Jul 30 15:36:41.384542 2026] [security2:error] [pid 189611:tid 189782] [client 47.128.121.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu12eWE7BvPuUzLJ9-RtwAAAK4"]
[Thu Jul 30 15:36:41.436459 2026] [security2:error] [pid 189611:tid 189845] [client 20.91.199.21:12421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/about.php"] [unique_id "amu12eWE7BvPuUzLJ9-RwAAAAO0"]
[Thu Jul 30 15:36:41.581751 2026] [proxy:error] [pid 189611:tid 189752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:41.581820 2026] [proxy_http:error] [pid 189611:tid 189752] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:41.582448 2026] [proxy:error] [pid 189611:tid 189752] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:41.582498 2026] [proxy_http:error] [pid 189611:tid 189752] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:41.582587 2026] [security2:error] [pid 189611:tid 189752] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amu12eWE7BvPuUzLJ9-RwgAAAJA"]
[Thu Jul 30 15:36:41.726202 2026] [core:notice] [pid 189611:tid 189630] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:41.727164 2026] [security2:error] [pid 189611:tid 189749] [client 191.232.199.39:46231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/admin.php"] [unique_id "amu12eWE7BvPuUzLJ9-RzAAAAI0"]
[Thu Jul 30 15:36:41.859875 2026] [security2:error] [pid 189611:tid 189860] [client 17.22.245.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu12eWE7BvPuUzLJ9-RzwAAAPw"]
[Thu Jul 30 15:36:42.091913 2026] [security2:error] [pid 189611:tid 189820] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/adminner.php"] [unique_id "amu12uWE7BvPuUzLJ9-R0wAAANQ"]
[Thu Jul 30 15:36:42.092031 2026] [security2:error] [pid 189611:tid 189820] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/adminner.php"] [unique_id "amu12uWE7BvPuUzLJ9-R0wAAANQ"]
[Thu Jul 30 15:36:42.550920 2026] [security2:error] [pid 189611:tid 189770] [client 20.203.148.31:63718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/updates.php"] [unique_id "amu12uWE7BvPuUzLJ9-R5QAAAKI"]
[Thu Jul 30 15:36:42.611786 2026] [security2:error] [pid 189611:tid 189784] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/yup.php"] [unique_id "amu12uWE7BvPuUzLJ9-R5gAAALA"]
[Thu Jul 30 15:36:42.611893 2026] [security2:error] [pid 189611:tid 189784] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/yup.php"] [unique_id "amu12uWE7BvPuUzLJ9-R5gAAALA"]
[Thu Jul 30 15:36:42.767916 2026] [security2:error] [pid 189611:tid 189809] [client 20.91.199.21:1408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/admin.php"] [unique_id "amu12uWE7BvPuUzLJ9-R7QAAAMk"]
[Thu Jul 30 15:36:43.023574 2026] [security2:error] [pid 189611:tid 189831] [client 191.232.199.39:8556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amu12-WE7BvPuUzLJ9-R8gAAAN8"]
[Thu Jul 30 15:36:43.116370 2026] [core:notice] [pid 189611:tid 189772] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:43.126782 2026] [security2:error] [pid 189611:tid 189841] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/config.json.php"] [unique_id "amu12-WE7BvPuUzLJ9-R9AAAAOk"]
[Thu Jul 30 15:36:43.126868 2026] [security2:error] [pid 189611:tid 189841] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/config.json.php"] [unique_id "amu12-WE7BvPuUzLJ9-R9AAAAOk"]
[Thu Jul 30 15:36:43.615777 2026] [proxy:error] [pid 189611:tid 189787] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:43.615857 2026] [proxy_http:error] [pid 189611:tid 189787] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:43.616671 2026] [proxy:error] [pid 189611:tid 189787] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:43.616723 2026] [proxy_http:error] [pid 189611:tid 189787] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:43.616829 2026] [security2:error] [pid 189611:tid 189787] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amu12-WE7BvPuUzLJ9-SCAAAALM"]
[Thu Jul 30 15:36:43.679593 2026] [core:notice] [pid 189611:tid 189853] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:43.685959 2026] [core:notice] [pid 189611:tid 189720] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:43.741423 2026] [core:notice] [pid 189611:tid 189821] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:43.890273 2026] [security2:error] [pid 189611:tid 189797] [client 20.91.199.21:41733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "amu12-WE7BvPuUzLJ9-SFQAAAL0"]
[Thu Jul 30 15:36:44.097805 2026] [security2:error] [pid 189611:tid 189786] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/2.php"] [unique_id "amu13OWE7BvPuUzLJ9-SFwAAALI"]
[Thu Jul 30 15:36:44.097913 2026] [security2:error] [pid 189611:tid 189786] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/2.php"] [unique_id "amu13OWE7BvPuUzLJ9-SFwAAALI"]
[Thu Jul 30 15:36:44.206450 2026] [core:notice] [pid 189611:tid 189741] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:44.592388 2026] [security2:error] [pid 189611:tid 189757] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/f35.update.php"] [unique_id "amu13OWE7BvPuUzLJ9-SIwAAAJU"]
[Thu Jul 30 15:36:44.592502 2026] [security2:error] [pid 189611:tid 189757] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/f35.update.php"] [unique_id "amu13OWE7BvPuUzLJ9-SIwAAAJU"]
[Thu Jul 30 15:36:44.655138 2026] [security2:error] [pid 189611:tid 189794] [client 191.232.199.39:8978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/m.php"] [unique_id "amu13OWE7BvPuUzLJ9-SJAAAALo"]
[Thu Jul 30 15:36:45.105847 2026] [security2:error] [pid 189611:tid 189742] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/k.php"] [unique_id "amu13eWE7BvPuUzLJ9-SMQAAAIY"]
[Thu Jul 30 15:36:45.106017 2026] [security2:error] [pid 189611:tid 189742] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/k.php"] [unique_id "amu13eWE7BvPuUzLJ9-SMQAAAIY"]
[Thu Jul 30 15:36:45.582396 2026] [security2:error] [pid 189611:tid 189866] [client 20.91.199.21:21140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/db-cache.php"] [unique_id "amu13eWE7BvPuUzLJ9-SPwAAAQI"]
[Thu Jul 30 15:36:45.639211 2026] [proxy:error] [pid 189611:tid 189789] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:45.639285 2026] [proxy_http:error] [pid 189611:tid 189789] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:45.640179 2026] [proxy:error] [pid 189611:tid 189789] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:45.640236 2026] [proxy_http:error] [pid 189611:tid 189789] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:45.640324 2026] [security2:error] [pid 189611:tid 189789] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amu13eWE7BvPuUzLJ9-SQQAAALU"]
[Thu Jul 30 15:36:46.144958 2026] [security2:error] [pid 189611:tid 189790] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/spadex.php"] [unique_id "amu13uWE7BvPuUzLJ9-STQAAALY"]
[Thu Jul 30 15:36:46.145102 2026] [security2:error] [pid 189611:tid 189790] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/spadex.php"] [unique_id "amu13uWE7BvPuUzLJ9-STQAAALY"]
[Thu Jul 30 15:36:46.159563 2026] [core:error] [pid 189611:tid 189820] [client 23.95.96.140:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:46.159581 2026] [core:error] [pid 189611:tid 189820] [client 23.95.96.140:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:36:46.236088 2026] [security2:error] [pid 189611:tid 189777] [client 38.172.162.57:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SUAAAAKk"]
[Thu Jul 30 15:36:46.236197 2026] [security2:error] [pid 189611:tid 189777] [client 38.172.162.57:16175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SUAAAAKk"]
[Thu Jul 30 15:36:46.245865 2026] [security2:error] [pid 189611:tid 189804] [client 111.225.149.139:10178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiandubaisafari.com"] [uri "/abu-dhabi-desert-safari.html"] [unique_id "amu13uWE7BvPuUzLJ9-SUgAAAMQ"]
[Thu Jul 30 15:36:46.293541 2026] [security2:error] [pid 189611:tid 189783] [client 191.232.199.39:9021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amu13uWE7BvPuUzLJ9-SUwAAAK8"]
[Thu Jul 30 15:36:46.445775 2026] [security2:error] [pid 189611:tid 189797] [client 20.91.199.21:21954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "amu13uWE7BvPuUzLJ9-SaQAAAL0"]
[Thu Jul 30 15:36:46.447669 2026] [security2:error] [pid 189611:tid 189780] [client 98.159.36.147:46656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/newsite/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SagAAAKw"]
[Thu Jul 30 15:36:46.448059 2026] [security2:error] [pid 189611:tid 189760] [client 98.159.36.147:40389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp1/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SXgAAAJg"]
[Thu Jul 30 15:36:46.448302 2026] [security2:error] [pid 189611:tid 189791] [client 98.159.36.147:55501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/sandbox/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SYQAAALc"]
[Thu Jul 30 15:36:46.448539 2026] [security2:error] [pid 189611:tid 189862] [client 98.159.36.147:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SYAAAAP4"]
[Thu Jul 30 15:36:46.448586 2026] [security2:error] [pid 189611:tid 189785] [client 98.159.36.147:39668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/news/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SYwAAALE"]
[Thu Jul 30 15:36:46.448886 2026] [security2:error] [pid 189611:tid 189802] [client 98.159.36.147:6505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/web/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SawAAAMI"]
[Thu Jul 30 15:36:46.448928 2026] [security2:error] [pid 189611:tid 189855] [client 98.159.36.147:43062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/cms/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SXwAAAPc"]
[Thu Jul 30 15:36:46.449019 2026] [security2:error] [pid 189611:tid 189761] [client 98.159.36.147:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-old//xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SYgAAAJk"]
[Thu Jul 30 15:36:46.449115 2026] [security2:error] [pid 189611:tid 189744] [client 98.159.36.147:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/home/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SZgAAAIg"]
[Thu Jul 30 15:36:46.449139 2026] [security2:error] [pid 189611:tid 189817] [client 98.159.36.147:8065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/testing/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SZQAAANE"]
[Thu Jul 30 15:36:46.449378 2026] [security2:error] [pid 189611:tid 189741] [client 98.159.36.147:48920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/old/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SbAAAAIU"]
[Thu Jul 30 15:36:46.449652 2026] [security2:error] [pid 189611:tid 189745] [client 98.159.36.147:48973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/app/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SbQAAAIk"]
[Thu Jul 30 15:36:46.450158 2026] [security2:error] [pid 189611:tid 189833] [client 98.159.36.147:20794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/backup/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SbgAAAOE"]
[Thu Jul 30 15:36:46.450257 2026] [security2:error] [pid 189611:tid 189810] [client 98.159.36.147:54532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SbwAAAMo"]
[Thu Jul 30 15:36:46.450766 2026] [security2:error] [pid 189611:tid 189847] [client 98.159.36.147:20005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/temp/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-ScAAAAO8"]
[Thu Jul 30 15:36:46.451787 2026] [security2:error] [pid 189611:tid 189784] [client 98.159.36.147:17159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/dev/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-ScQAAALA"]
[Thu Jul 30 15:36:46.451996 2026] [security2:error] [pid 189611:tid 189766] [client 98.159.36.147:56971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/staging/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SZwAAAJ4"]
[Thu Jul 30 15:36:46.452287 2026] [security2:error] [pid 189611:tid 189826] [client 98.159.36.147:51193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/old-site/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SaAAAANo"]
[Thu Jul 30 15:36:46.452744 2026] [security2:error] [pid 189611:tid 189815] [client 98.159.36.147:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/OLD//xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SZAAAAM8"]
[Thu Jul 30 15:36:46.453576 2026] [security2:error] [pid 189611:tid 189823] [client 98.159.36.147:6005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/prod/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-ScgAAANc"]
[Thu Jul 30 15:36:46.456786 2026] [security2:error] [pid 189611:tid 189770] [client 98.159.36.147:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/main/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-ScwAAAKI"]
[Thu Jul 30 15:36:46.457886 2026] [security2:error] [pid 189611:tid 189778] [client 98.159.36.147:53143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SdAAAAKo"]
[Thu Jul 30 15:36:46.459641 2026] [security2:error] [pid 189611:tid 189743] [client 98.159.36.147:19467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/blog/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SdgAAAIc"]
[Thu Jul 30 15:36:46.459659 2026] [security2:error] [pid 189611:tid 189835] [client 98.159.36.147:49113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/site/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SdwAAAOM"]
[Thu Jul 30 15:36:46.474856 2026] [security2:error] [pid 189611:tid 189781] [client 98.159.36.147:52381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/core/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SeAAAAK0"]
[Thu Jul 30 15:36:46.475799 2026] [security2:error] [pid 189611:tid 189813] [client 98.159.36.147:1807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/new/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SeQAAAM0"]
[Thu Jul 30 15:36:46.481195 2026] [security2:error] [pid 189611:tid 189852] [client 98.159.36.147:60543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-content/xmlrpc.php"] [unique_id "amu13uWE7BvPuUzLJ9-SegAAAPQ"]
[Thu Jul 30 15:36:46.643030 2026] [security2:error] [pid 189611:tid 189759] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/mg.php"] [unique_id "amu13uWE7BvPuUzLJ9-SfAAAAJc"]
[Thu Jul 30 15:36:46.643148 2026] [security2:error] [pid 189611:tid 189759] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/mg.php"] [unique_id "amu13uWE7BvPuUzLJ9-SfAAAAJc"]
[Thu Jul 30 15:36:46.767184 2026] [security2:error] [pid 189611:tid 189805] [client 20.203.148.31:59809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/user.php"] [unique_id "amu13uWE7BvPuUzLJ9-SfQAAAMU"]
[Thu Jul 30 15:36:46.869970 2026] [core:notice] [pid 189611:tid 189680] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:46.873934 2026] [security2:error] [pid 189611:tid 189799] [client 70.40.19.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/1"] [unique_id "amu13uWE7BvPuUzLJ9-SewAAv0Q"]
[Thu Jul 30 15:36:47.056086 2026] [security2:error] [pid 189611:tid 189832] [client 98.159.36.147:53458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/backup/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SiAAAAOA"]
[Thu Jul 30 15:36:47.056307 2026] [security2:error] [pid 189611:tid 189787] [client 98.159.36.147:4991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/cms/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SiQAAALM"]
[Thu Jul 30 15:36:47.056501 2026] [security2:error] [pid 189611:tid 189860] [client 98.159.36.147:4675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/site/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SigAAAPw"]
[Thu Jul 30 15:36:47.056505 2026] [security2:error] [pid 189611:tid 189774] [client 98.159.36.147:43566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/core/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SjAAAAKY"]
[Thu Jul 30 15:36:47.056533 2026] [security2:error] [pid 189611:tid 189821] [client 98.159.36.147:13965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/web/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SiwAAANU"]
[Thu Jul 30 15:36:47.056686 2026] [security2:error] [pid 189611:tid 189746] [client 98.159.36.147:13986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/old-site/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SjQAAAIo"]
[Thu Jul 30 15:36:47.056954 2026] [security2:error] [pid 189611:tid 189811] [client 98.159.36.147:11210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/staging/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SjgAAAMs"]
[Thu Jul 30 15:36:47.056965 2026] [security2:error] [pid 189611:tid 189756] [client 98.159.36.147:1696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/testing/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SjwAAAJQ"]
[Thu Jul 30 15:36:47.057015 2026] [security2:error] [pid 189611:tid 189790] [client 98.159.36.147:2530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/news/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SkAAAALY"]
[Thu Jul 30 15:36:47.057163 2026] [security2:error] [pid 189611:tid 189849] [client 98.159.36.147:55391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/blog/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SkgAAAPE"]
[Thu Jul 30 15:36:47.057211 2026] [security2:error] [pid 189611:tid 189856] [client 98.159.36.147:42765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SkQAAAPg"]
[Thu Jul 30 15:36:47.057305 2026] [security2:error] [pid 189611:tid 189758] [client 98.159.36.147:35387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/newsite/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SkwAAAJY"]
[Thu Jul 30 15:36:47.057453 2026] [security2:error] [pid 189611:tid 189820] [client 98.159.36.147:64774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-old//xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SlAAAANQ"]
[Thu Jul 30 15:36:47.057521 2026] [security2:error] [pid 189611:tid 189769] [client 98.159.36.147:55162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/prod/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SlQAAAKE"]
[Thu Jul 30 15:36:47.057784 2026] [security2:error] [pid 189611:tid 189777] [client 98.159.36.147:64823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SlgAAAKk"]
[Thu Jul 30 15:36:47.058495 2026] [security2:error] [pid 189611:tid 189804] [client 98.159.36.147:7042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/app/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SlwAAAMQ"]
[Thu Jul 30 15:36:47.058690 2026] [security2:error] [pid 189611:tid 189816] [client 98.159.36.147:44733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/main/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SmQAAANA"]
[Thu Jul 30 15:36:47.058700 2026] [security2:error] [pid 189611:tid 189776] [client 98.159.36.147:53318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-content/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SmAAAAKg"]
[Thu Jul 30 15:36:47.064676 2026] [security2:error] [pid 189611:tid 189837] [client 98.159.36.147:3880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/OLD//xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SnQAAAOU"]
[Thu Jul 30 15:36:47.064700 2026] [security2:error] [pid 189611:tid 189765] [client 98.159.36.147:46657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/sandbox/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SnAAAAJ0"]
[Thu Jul 30 15:36:47.064728 2026] [security2:error] [pid 189611:tid 189807] [client 98.159.36.147:55166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp1/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SmwAAAMc"]
[Thu Jul 30 15:36:47.067000 2026] [security2:error] [pid 189611:tid 189753] [client 98.159.36.147:39400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/home/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SngAAAJE"]
[Thu Jul 30 15:36:47.067116 2026] [security2:error] [pid 189611:tid 189788] [client 98.159.36.147:60845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/temp/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SnwAAALQ"]
[Thu Jul 30 15:36:47.067704 2026] [security2:error] [pid 189611:tid 189783] [client 98.159.36.147:44567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/new/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SoAAAAK8"]
[Thu Jul 30 15:36:47.068183 2026] [security2:error] [pid 189611:tid 189818] [client 98.159.36.147:58223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/old/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SoQAAANI"]
[Thu Jul 30 15:36:47.069590 2026] [security2:error] [pid 189611:tid 189864] [client 98.159.36.147:63891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SogAAAQA"]
[Thu Jul 30 15:36:47.112243 2026] [security2:error] [pid 189611:tid 189802] [client 127.0.0.1:19916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu13-WE7BvPuUzLJ9-SpAAAAMI"]
[Thu Jul 30 15:36:47.112359 2026] [security2:error] [pid 189611:tid 189751] [client 74.7.244.45:32772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.qnj.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amu13-WE7BvPuUzLJ9-SowAAj0s"]
[Thu Jul 30 15:36:47.150050 2026] [security2:error] [pid 189611:tid 189810] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fnstall.php"] [unique_id "amu13-WE7BvPuUzLJ9-SqAAAAMo"]
[Thu Jul 30 15:36:47.150182 2026] [security2:error] [pid 189611:tid 189810] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fnstall.php"] [unique_id "amu13-WE7BvPuUzLJ9-SqAAAAMo"]
[Thu Jul 30 15:36:47.396884 2026] [core:notice] [pid 189611:tid 189709] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:47.510913 2026] [core:notice] [pid 189611:tid 189694] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:47.663469 2026] [security2:error] [pid 189611:tid 189797] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ortasekerli1.php"] [unique_id "amu13-WE7BvPuUzLJ9-StwAAAL0"]
[Thu Jul 30 15:36:47.663557 2026] [security2:error] [pid 189611:tid 189797] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ortasekerli1.php"] [unique_id "amu13-WE7BvPuUzLJ9-StwAAAL0"]
[Thu Jul 30 15:36:47.726279 2026] [security2:error] [pid 189611:tid 189825] [client 98.159.36.147:5264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/dev/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SuAAAANk"]
[Thu Jul 30 15:36:47.765799 2026] [security2:error] [pid 189611:tid 189858] [client 98.159.36.147:24451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/backup/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SuQAAAPo"]
[Thu Jul 30 15:36:47.766268 2026] [security2:error] [pid 189611:tid 189760] [client 98.159.36.147:8855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SugAAAJg"]
[Thu Jul 30 15:36:47.766409 2026] [security2:error] [pid 189611:tid 189791] [client 98.159.36.147:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/core/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SuwAAALc"]
[Thu Jul 30 15:36:47.776932 2026] [security2:error] [pid 189611:tid 189780] [client 98.159.36.147:42355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/staging/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SvAAAAKw"]
[Thu Jul 30 15:36:47.777804 2026] [security2:error] [pid 189611:tid 189862] [client 98.159.36.147:54711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/new/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SvQAAAP4"]
[Thu Jul 30 15:36:47.777886 2026] [security2:error] [pid 189611:tid 189757] [client 98.159.36.147:21526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SvgAAAJU"]
[Thu Jul 30 15:36:47.778130 2026] [security2:error] [pid 189611:tid 189832] [client 98.159.36.147:28137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/app/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SvwAAAOA"]
[Thu Jul 30 15:36:47.778724 2026] [security2:error] [pid 189611:tid 189787] [client 98.159.36.147:2406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/sandbox/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SwAAAALM"]
[Thu Jul 30 15:36:47.780012 2026] [security2:error] [pid 189611:tid 189860] [client 98.159.36.147:31614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-content/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SwQAAAPw"]
[Thu Jul 30 15:36:47.781088 2026] [security2:error] [pid 189611:tid 189774] [client 98.159.36.147:15032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-old//xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SwgAAAKY"]
[Thu Jul 30 15:36:47.781246 2026] [security2:error] [pid 189611:tid 189821] [client 98.159.36.147:60881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/main/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SwwAAANU"]
[Thu Jul 30 15:36:47.785375 2026] [security2:error] [pid 189611:tid 189746] [client 98.159.36.147:58282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/temp/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SxAAAAIo"]
[Thu Jul 30 15:36:47.792484 2026] [security2:error] [pid 189611:tid 189790] [client 98.159.36.147:34895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/blog/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SxQAAALY"]
[Thu Jul 30 15:36:47.793590 2026] [security2:error] [pid 189611:tid 189811] [client 98.159.36.147:33539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/home/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SxgAAAMs"]
[Thu Jul 30 15:36:47.793688 2026] [security2:error] [pid 189611:tid 189756] [client 98.159.36.147:8897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/old/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SxwAAAJQ"]
[Thu Jul 30 15:36:47.807406 2026] [security2:error] [pid 189611:tid 189856] [client 98.159.36.147:54408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp1/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SyAAAAPg"]
[Thu Jul 30 15:36:47.811888 2026] [security2:error] [pid 189611:tid 189820] [client 98.159.36.147:34066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/web/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SygAAANQ"]
[Thu Jul 30 15:36:47.816698 2026] [security2:error] [pid 189611:tid 189777] [client 98.159.36.147:45676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/newsite/xmlrpc.php"] [unique_id "amu13-WE7BvPuUzLJ9-SzAAAAKk"]
[Thu Jul 30 15:36:47.955265 2026] [security2:error] [pid 189611:tid 189779] [client 191.232.199.39:9117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/classwithtostring.php"] [unique_id "amu13-WE7BvPuUzLJ9-S1QAAAKs"]
[Thu Jul 30 15:36:47.960961 2026] [security2:error] [pid 189611:tid 189828] [client 20.91.199.21:21842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "amu13-WE7BvPuUzLJ9-S1wAAANw"]
[Thu Jul 30 15:36:48.159823 2026] [security2:error] [pid 189611:tid 189795] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sump1.php"] [unique_id "amu14OWE7BvPuUzLJ9-S3AAAALs"]
[Thu Jul 30 15:36:48.159928 2026] [security2:error] [pid 189611:tid 189795] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sump1.php"] [unique_id "amu14OWE7BvPuUzLJ9-S3AAAALs"]
[Thu Jul 30 15:36:48.172197 2026] [security2:error] [pid 189611:tid 189764] [client 98.159.36.147:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/app/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S3QAAAJw"]
[Thu Jul 30 15:36:48.172653 2026] [security2:error] [pid 189611:tid 189754] [client 98.159.36.147:43794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/staging/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S3gAAAJI"]
[Thu Jul 30 15:36:48.174244 2026] [security2:error] [pid 189611:tid 189793] [client 98.159.36.147:3033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/backup/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S3wAAALk"]
[Thu Jul 30 15:36:48.180159 2026] [security2:error] [pid 189611:tid 189763] [client 98.159.36.147:36435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/main/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S4AAAAJs"]
[Thu Jul 30 15:36:48.188191 2026] [security2:error] [pid 189611:tid 189842] [client 98.159.36.147:25460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/core/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S4QAAAOo"]
[Thu Jul 30 15:36:48.198087 2026] [security2:error] [pid 189611:tid 189852] [client 98.159.36.147:45300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S4gAAAPQ"]
[Thu Jul 30 15:36:48.198232 2026] [security2:error] [pid 189611:tid 189809] [client 98.159.36.147:30226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S4wAAAMk"]
[Thu Jul 30 15:36:48.200175 2026] [security2:error] [pid 189611:tid 189830] [client 98.159.36.147:46415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/news/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S5AAAAN4"]
[Thu Jul 30 15:36:48.201162 2026] [security2:error] [pid 189611:tid 189845] [client 98.159.36.147:44681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/site/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S5QAAAO0"]
[Thu Jul 30 15:36:48.201369 2026] [security2:error] [pid 189611:tid 189839] [client 98.159.36.147:21767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/newsite/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S5gAAAOc"]
[Thu Jul 30 15:36:48.202499 2026] [security2:error] [pid 189611:tid 189747] [client 98.159.36.147:8237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/prod/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S5wAAAIs"]
[Thu Jul 30 15:36:48.202516 2026] [security2:error] [pid 189611:tid 189861] [client 98.159.36.147:31507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/OLD//xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S6AAAAP0"]
[Thu Jul 30 15:36:48.202605 2026] [security2:error] [pid 189611:tid 189843] [client 98.159.36.147:37069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/cms/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S6QAAAOs"]
[Thu Jul 30 15:36:48.206743 2026] [security2:error] [pid 189611:tid 189836] [client 98.159.36.147:30385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/testing/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S6gAAAOQ"]
[Thu Jul 30 15:36:48.211713 2026] [security2:error] [pid 189611:tid 189806] [client 98.159.36.147:46426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/old/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S6wAAAMY"]
[Thu Jul 30 15:36:48.211759 2026] [security2:error] [pid 189611:tid 189742] [client 98.159.36.147:46410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/web/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S7AAAAIY"]
[Thu Jul 30 15:36:48.216468 2026] [security2:error] [pid 189611:tid 189841] [client 98.159.36.147:48337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/home/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S7QAAAOk"]
[Thu Jul 30 15:36:48.217160 2026] [security2:error] [pid 189611:tid 189772] [client 98.159.36.147:40774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-old//xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S7gAAAKQ"]
[Thu Jul 30 15:36:48.217956 2026] [security2:error] [pid 189611:tid 189775] [client 98.159.36.147:54727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/old-site/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S7wAAAKc"]
[Thu Jul 30 15:36:48.218157 2026] [security2:error] [pid 189611:tid 189800] [client 98.159.36.147:36677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/blog/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S8AAAAMA"]
[Thu Jul 30 15:36:48.218247 2026] [security2:error] [pid 189611:tid 189792] [client 98.159.36.147:57017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/temp/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S8QAAALg"]
[Thu Jul 30 15:36:48.219422 2026] [security2:error] [pid 189611:tid 189866] [client 98.159.36.147:31711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S8gAAAQI"]
[Thu Jul 30 15:36:48.228573 2026] [security2:error] [pid 189611:tid 189767] [client 98.159.36.147:27340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp1/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-S8wAAAJ8"]
[Thu Jul 30 15:36:48.338222 2026] [security2:error] [pid 189611:tid 189854] [client 20.203.148.31:56545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/admin-ajax.php"] [unique_id "amu14OWE7BvPuUzLJ9-S9AAAAPY"]
[Thu Jul 30 15:36:48.517393 2026] [security2:error] [pid 189611:tid 189864] [client 98.159.36.147:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/dev/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TAgAAAQA"]
[Thu Jul 30 15:36:48.519526 2026] [security2:error] [pid 189611:tid 189744] [client 98.159.36.147:45909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/new/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TAwAAAIg"]
[Thu Jul 30 15:36:48.604305 2026] [security2:error] [pid 189611:tid 189766] [client 98.159.36.147:4559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/sandbox/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TBgAAAJ4"]
[Thu Jul 30 15:36:48.613393 2026] [security2:error] [pid 189611:tid 189755] [client 98.159.36.147:54592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-content/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TCQAAAJM"]
[Thu Jul 30 15:36:48.645285 2026] [security2:error] [pid 189611:tid 189865] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amu14OWE7BvPuUzLJ9-TDQAAAQE"]
[Thu Jul 30 15:36:48.645391 2026] [security2:error] [pid 189611:tid 189865] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amu14OWE7BvPuUzLJ9-TDQAAAQE"]
[Thu Jul 30 15:36:48.661306 2026] [core:notice] [pid 189611:tid 189796] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:48.686009 2026] [core:notice] [pid 189611:tid 189699] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:48.689554 2026] [security2:error] [pid 189611:tid 189760] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/public/journals/1/pageHeaderLogoImage_en_US.jpg"] [unique_id "amu14OWE7BvPuUzLJ9-S-AAAmFc"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:48.696570 2026] [core:notice] [pid 189611:tid 189716] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:48.701257 2026] [security2:error] [pid 189611:tid 189756] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/index.php/JIPKL/---call---/page/page/css-name-font.css"] [unique_id "amu14OWE7BvPuUzLJ9-S-wAAlGg"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:48.710926 2026] [core:notice] [pid 189611:tid 189692] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:48.711098 2026] [core:notice] [pid 189611:tid 189718] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:48.715641 2026] [security2:error] [pid 189611:tid 189780] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/public/journals/1/homepageImage_en_US.jpg"] [unique_id "amu14OWE7BvPuUzLJ9-S-gAArGo"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:48.715709 2026] [security2:error] [pid 189611:tid 189791] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/public/journals/1/styleSheet_d-2021-12-25-15-59-02.css"] [unique_id "amu14OWE7BvPuUzLJ9-S-QAAt1A"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:48.731927 2026] [core:notice] [pid 189611:tid 189698] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:48.735116 2026] [security2:error] [pid 189611:tid 189757] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/lib/pkp/styles/fontawesome/fontawesome_v-3.3.0.8.css"] [unique_id "amu14OWE7BvPuUzLJ9-S_wAAlVY"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:48.744644 2026] [core:notice] [pid 189611:tid 189726] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:48.748772 2026] [security2:error] [pid 189611:tid 189787] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/index.php/JIPKL/---call---/page/page/css-name-stylesheet.css"] [unique_id "amu14OWE7BvPuUzLJ9-TAQAAs3I"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:48.794445 2026] [security2:error] [pid 189611:tid 189855] [client 98.159.36.147:36931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/testing/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TDwAAAPc"]
[Thu Jul 30 15:36:48.795184 2026] [security2:error] [pid 189611:tid 189826] [client 98.159.36.147:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TEAAAANo"]
[Thu Jul 30 15:36:48.795274 2026] [security2:error] [pid 189611:tid 189849] [client 98.159.36.147:38878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/site/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TEQAAAPE"]
[Thu Jul 30 15:36:48.795297 2026] [security2:error] [pid 189611:tid 189823] [client 98.159.36.147:25080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/cms/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TEgAAANc"]
[Thu Jul 30 15:36:48.795586 2026] [security2:error] [pid 189611:tid 189837] [client 98.159.36.147:56183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/OLD//xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TEwAAAOU"]
[Thu Jul 30 15:36:48.796033 2026] [security2:error] [pid 189611:tid 189761] [client 98.159.36.147:15180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/prod/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TFAAAAJk"]
[Thu Jul 30 15:36:48.822561 2026] [security2:error] [pid 189611:tid 189781] [client 98.159.36.147:51114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/newsite/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TFQAAAK0"]
[Thu Jul 30 15:36:48.823057 2026] [security2:error] [pid 189611:tid 189857] [client 98.159.36.147:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/web/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TFgAAAPk"]
[Thu Jul 30 15:36:48.824628 2026] [security2:error] [pid 189611:tid 189813] [client 98.159.36.147:10340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/app/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TFwAAAM0"]
[Thu Jul 30 15:36:48.827660 2026] [security2:error] [pid 189611:tid 189773] [client 98.159.36.147:55125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TGAAAAKU"]
[Thu Jul 30 15:36:48.828103 2026] [security2:error] [pid 189611:tid 189824] [client 98.159.36.147:3917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-includes/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TGQAAANg"]
[Thu Jul 30 15:36:48.848883 2026] [security2:error] [pid 189611:tid 189833] [client 98.159.36.147:38700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-content/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TGgAAAOE"]
[Thu Jul 30 15:36:48.849239 2026] [security2:error] [pid 189611:tid 189810] [client 98.159.36.147:48711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp1/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TGwAAAMo"]
[Thu Jul 30 15:36:48.852608 2026] [security2:error] [pid 189611:tid 189785] [client 98.159.36.147:44217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/sandbox/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-THAAAALE"]
[Thu Jul 30 15:36:48.863044 2026] [security2:error] [pid 189611:tid 189754] [client 98.159.36.147:58839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/backup/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-THQAAAJI"]
[Thu Jul 30 15:36:48.866078 2026] [security2:error] [pid 189611:tid 189751] [client 98.159.36.147:20932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/news/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-THgAAAI8"]
[Thu Jul 30 15:36:48.866510 2026] [security2:error] [pid 189611:tid 189741] [client 98.159.36.147:19051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/old-site/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-THwAAAIU"]
[Thu Jul 30 15:36:48.871469 2026] [security2:error] [pid 189611:tid 189842] [client 98.159.36.147:47924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/staging/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TIAAAAOo"]
[Thu Jul 30 15:36:48.872653 2026] [security2:error] [pid 189611:tid 189852] [client 98.159.36.147:40009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/main/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TIQAAAPQ"]
[Thu Jul 30 15:36:48.908693 2026] [security2:error] [pid 189611:tid 189783] [client 98.159.36.147:10336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/new/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TJQAAAK8"]
[Thu Jul 30 15:36:48.909902 2026] [security2:error] [pid 189611:tid 189818] [client 98.159.36.147:2182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/dev/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TJgAAANI"]
[Thu Jul 30 15:36:48.933102 2026] [security2:error] [pid 189611:tid 189802] [client 98.159.36.147:63719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/blog/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TJwAAAMI"]
[Thu Jul 30 15:36:48.939921 2026] [security2:error] [pid 189611:tid 189807] [client 98.159.36.147:37306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/wp-old//xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TKAAAAMc"]
[Thu Jul 30 15:36:48.967057 2026] [security2:error] [pid 189611:tid 189867] [client 98.159.36.147:31478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/web/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TKQAAAQM"]
[Thu Jul 30 15:36:48.974620 2026] [security2:error] [pid 189611:tid 189846] [client 98.159.36.147:57309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/newsite/xmlrpc.php"] [unique_id "amu14OWE7BvPuUzLJ9-TKwAAAO4"]
[Thu Jul 30 15:36:49.030358 2026] [core:notice] [pid 189611:tid 189738] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.132866 2026] [security2:error] [pid 189611:tid 189862] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-post-data.php"] [unique_id "amu14eWE7BvPuUzLJ9-TMAAAAP4"]
[Thu Jul 30 15:36:49.132967 2026] [security2:error] [pid 189611:tid 189862] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-post-data.php"] [unique_id "amu14eWE7BvPuUzLJ9-TMAAAAP4"]
[Thu Jul 30 15:36:49.238920 2026] [security2:error] [pid 189611:tid 189803] [client 98.159.36.147:33782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/staging/xmlrpc.php"] [unique_id "amu14eWE7BvPuUzLJ9-TNQAAAMM"]
[Thu Jul 30 15:36:49.247274 2026] [security2:error] [pid 189611:tid 189782] [client 98.159.36.147:56307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/main/xmlrpc.php"] [unique_id "amu14eWE7BvPuUzLJ9-TNgAAAK4"]
[Thu Jul 30 15:36:49.247600 2026] [security2:error] [pid 189611:tid 189790] [client 98.159.36.147:56571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.36.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mjsnailspa.com"] [uri "/backup/xmlrpc.php"] [unique_id "amu14eWE7BvPuUzLJ9-TNwAAALY"]
[Thu Jul 30 15:36:49.282913 2026] [security2:error] [pid 189611:tid 189828] [client 57.141.0.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu14OWE7BvPuUzLJ9-TDAAAANw"]
[Thu Jul 30 15:36:49.379105 2026] [core:notice] [pid 189611:tid 189747] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.395036 2026] [core:notice] [pid 189611:tid 189711] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.398458 2026] [security2:error] [pid 189611:tid 189791] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/download/barcode/dok_sk/2022/12/BARCODE_2964068700.png"] [unique_id "amu14eWE7BvPuUzLJ9-TOQAAt2M"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.400002 2026] [core:notice] [pid 189611:tid 189711] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.403075 2026] [security2:error] [pid 189611:tid 189824] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/public/site/images/adminadiba/wa2-99e5d9390ba38d1e97c7747562c1bcf5.png"] [unique_id "amu14eWE7BvPuUzLJ9-TOgAA2GM"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.403681 2026] [core:notice] [pid 189611:tid 189724] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.405643 2026] [core:notice] [pid 189611:tid 189717] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.406836 2026] [security2:error] [pid 189611:tid 189787] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/ojs/public/site/images/admintranspublika/google-index-22.png"] [unique_id "amu14eWE7BvPuUzLJ9-TOwAAs3A"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.408665 2026] [security2:error] [pid 189611:tid 189757] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/ojs/public/site/images/admintranspublika/road-index.png"] [unique_id "amu14eWE7BvPuUzLJ9-TPAAAlWk"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.410891 2026] [core:notice] [pid 189611:tid 189727] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.412794 2026] [core:notice] [pid 189611:tid 189721] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.413969 2026] [security2:error] [pid 189611:tid 189810] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/ojs/public/site/images/admintranspublika/scilit.png"] [unique_id "amu14eWE7BvPuUzLJ9-TPQAAynM"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.416251 2026] [security2:error] [pid 189611:tid 189826] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/count2/mAe5/bg_FFFFFF/txt_000000/border_1B1BCC/columns_2/maxflags_10/viewers_0/labels_0/pageviews_1/flags_0/percent_0/image_file.jpg"] [unique_id "amu14eWE7BvPuUzLJ9-TPgAA2m0"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.422729 2026] [core:notice] [pid 189611:tid 189619] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.425760 2026] [security2:error] [pid 189611:tid 189823] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/templates/images/ojs_brand.png"] [unique_id "amu14eWE7BvPuUzLJ9-TSAAA1wc"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.441217 2026] [core:notice] [pid 189611:tid 189739] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.444190 2026] [security2:error] [pid 189611:tid 189849] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/ojs/public/site/images/admintranspublika/pkp-index4.png"] [unique_id "amu14eWE7BvPuUzLJ9-TSgAA8X8"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.445486 2026] [core:notice] [pid 189611:tid 189735] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.448986 2026] [core:notice] [pid 189611:tid 189733] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.449510 2026] [security2:error] [pid 189611:tid 189837] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/public/site/images/admin/footer2.png"] [unique_id "amu14eWE7BvPuUzLJ9-TSwAA5Xs"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.451913 2026] [core:notice] [pid 189611:tid 189729] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.452122 2026] [security2:error] [pid 189611:tid 189781] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/ojs/public/site/images/admintranspublika/garuda-index.png"] [unique_id "amu14eWE7BvPuUzLJ9-TTAAArXk"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.455112 2026] [security2:error] [pid 189611:tid 189857] [client 69.164.87.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/12657422/0/82011901/0/image_file.jpg"] [unique_id "amu14eWE7BvPuUzLJ9-TTQAA-XU"], referer: https://jipkl.com/index.php/JIPKL/article/view/1
[Thu Jul 30 15:36:49.487627 2026] [security2:error] [pid 189611:tid 189830] [client 127.0.0.1:19928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu14eWE7BvPuUzLJ9-TTwAAAN4"]
[Thu Jul 30 15:36:49.487714 2026] [security2:error] [pid 189611:tid 189847] [client 74.7.228.26:33874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.zjp.nyx.temporary.site"] [uri "/robots.txt"] [unique_id "amu14eWE7BvPuUzLJ9-TTgAA7wE"]
[Thu Jul 30 15:36:49.634845 2026] [security2:error] [pid 189611:tid 189863] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/root.php"] [unique_id "amu14eWE7BvPuUzLJ9-TWQAAAP8"]
[Thu Jul 30 15:36:49.634947 2026] [security2:error] [pid 189611:tid 189863] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/root.php"] [unique_id "amu14eWE7BvPuUzLJ9-TWQAAAP8"]
[Thu Jul 30 15:36:49.655387 2026] [core:notice] [pid 189611:tid 189625] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:49.877674 2026] [security2:error] [pid 189611:tid 189836] [client 191.232.199.39:46242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/gmo.php"] [unique_id "amu14eWE7BvPuUzLJ9-TXgAAAOQ"]
[Thu Jul 30 15:36:49.994019 2026] [core:notice] [pid 189611:tid 189789] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:50.159844 2026] [security2:error] [pid 189611:tid 189746] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/v543.php"] [unique_id "amu14uWE7BvPuUzLJ9-TbAAAAIo"]
[Thu Jul 30 15:36:50.159952 2026] [security2:error] [pid 189611:tid 189746] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/v543.php"] [unique_id "amu14uWE7BvPuUzLJ9-TbAAAAIo"]
[Thu Jul 30 15:36:50.309898 2026] [security2:error] [pid 189611:tid 189732] [remote 192.250.239.84:33644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.239.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.eow.nyx.temporary.site"] [uri "/wp-login.php"] [unique_id "amu14uWE7BvPuUzLJ9-TcAAA1Hg"]
[Thu Jul 30 15:36:50.399093 2026] [security2:error] [pid 189611:tid 189743] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu14uWE7BvPuUzLJ9-TcwAAAIc"]
[Thu Jul 30 15:36:50.399218 2026] [security2:error] [pid 189611:tid 189743] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu14uWE7BvPuUzLJ9-TcwAAAIc"]
[Thu Jul 30 15:36:50.684191 2026] [security2:error] [pid 189611:tid 189855] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sixxis.php"] [unique_id "amu14uWE7BvPuUzLJ9-TfgAAAPc"]
[Thu Jul 30 15:36:50.684297 2026] [security2:error] [pid 189611:tid 189855] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sixxis.php"] [unique_id "amu14uWE7BvPuUzLJ9-TfgAAAPc"]
[Thu Jul 30 15:36:50.737770 2026] [security2:error] [pid 189611:tid 189865] [client 20.203.148.31:63711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/alfa.php"] [unique_id "amu14uWE7BvPuUzLJ9-TfwAAAQE"]
[Thu Jul 30 15:36:50.798935 2026] [core:notice] [pid 189611:tid 189636] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:51.005955 2026] [security2:error] [pid 189611:tid 189751] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu14-WE7BvPuUzLJ9-TgwAAAI8"]
[Thu Jul 30 15:36:51.006146 2026] [security2:error] [pid 189611:tid 189751] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu14-WE7BvPuUzLJ9-TgwAAAI8"]
[Thu Jul 30 15:36:51.214800 2026] [security2:error] [pid 189611:tid 189775] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ip.php"] [unique_id "amu14-WE7BvPuUzLJ9-TjwAAAKc"]
[Thu Jul 30 15:36:51.214938 2026] [security2:error] [pid 189611:tid 189775] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ip.php"] [unique_id "amu14-WE7BvPuUzLJ9-TjwAAAKc"]
[Thu Jul 30 15:36:51.585796 2026] [security2:error] [pid 189611:tid 189834] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/bootstrap.php"] [unique_id "amu14-WE7BvPuUzLJ9-TkwAAAOI"]
[Thu Jul 30 15:36:51.585907 2026] [security2:error] [pid 189611:tid 189834] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/bootstrap.php"] [unique_id "amu14-WE7BvPuUzLJ9-TkwAAAOI"]
[Thu Jul 30 15:36:51.730496 2026] [security2:error] [pid 189611:tid 189837] [client 191.232.199.39:8254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/languages/index.php"] [unique_id "amu14-WE7BvPuUzLJ9-TnwAAAOU"]
[Thu Jul 30 15:36:51.751738 2026] [security2:error] [pid 189611:tid 189768] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/kq1.php"] [unique_id "amu14-WE7BvPuUzLJ9-ToAAAAKA"]
[Thu Jul 30 15:36:51.751827 2026] [security2:error] [pid 189611:tid 189768] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/kq1.php"] [unique_id "amu14-WE7BvPuUzLJ9-ToAAAAKA"]
[Thu Jul 30 15:36:51.882728 2026] [security2:error] [pid 189611:tid 189833] [client 178.156.187.238:53676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "globalmarks.pk"] [uri "/index.php"] [unique_id "amu14-WE7BvPuUzLJ9-TngAAAOE"], referer: https://globalmarks.pk/
[Thu Jul 30 15:36:52.105191 2026] [security2:error] [pid 189611:tid 189774] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-blog-header.php"] [unique_id "amu15OWE7BvPuUzLJ9-TpwAAAKY"]
[Thu Jul 30 15:36:52.105283 2026] [security2:error] [pid 189611:tid 189774] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-blog-header.php"] [unique_id "amu15OWE7BvPuUzLJ9-TpwAAAKY"]
[Thu Jul 30 15:36:52.265672 2026] [security2:error] [pid 189611:tid 189760] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fw/faiyy.php"] [unique_id "amu15OWE7BvPuUzLJ9-TsQAAAJg"]
[Thu Jul 30 15:36:52.265755 2026] [security2:error] [pid 189611:tid 189760] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fw/faiyy.php"] [unique_id "amu15OWE7BvPuUzLJ9-TsQAAAJg"]
[Thu Jul 30 15:36:52.286227 2026] [security2:error] [pid 189611:tid 189856] [client 20.91.199.21:12456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "amu15OWE7BvPuUzLJ9-TswAAAPg"]
[Thu Jul 30 15:36:52.616383 2026] [proxy:error] [pid 189611:tid 189806] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:52.616454 2026] [proxy_http:error] [pid 189611:tid 189806] [client 20.203.148.31:62736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:52.617075 2026] [proxy:error] [pid 189611:tid 189806] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:52.617122 2026] [proxy_http:error] [pid 189611:tid 189806] [client 20.203.148.31:62736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:52.641793 2026] [security2:error] [pid 189611:tid 189757] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-load.php"] [unique_id "amu15OWE7BvPuUzLJ9-TuAAAAJU"]
[Thu Jul 30 15:36:52.641903 2026] [security2:error] [pid 189611:tid 189757] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-load.php"] [unique_id "amu15OWE7BvPuUzLJ9-TuAAAAJU"]
[Thu Jul 30 15:36:52.776559 2026] [security2:error] [pid 189611:tid 189785] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/h02ugyh.php"] [unique_id "amu15OWE7BvPuUzLJ9-TvwAAALE"]
[Thu Jul 30 15:36:52.776679 2026] [security2:error] [pid 189611:tid 189785] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/h02ugyh.php"] [unique_id "amu15OWE7BvPuUzLJ9-TvwAAALE"]
[Thu Jul 30 15:36:53.170443 2026] [security2:error] [pid 189611:tid 189754] [client 20.91.199.21:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "amu15eWE7BvPuUzLJ9-TwAAAAJI"]
[Thu Jul 30 15:36:53.222868 2026] [security2:error] [pid 189611:tid 189853] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/edit.php"] [unique_id "amu15eWE7BvPuUzLJ9-TxQAAAPU"]
[Thu Jul 30 15:36:53.222954 2026] [security2:error] [pid 189611:tid 189853] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/edit.php"] [unique_id "amu15eWE7BvPuUzLJ9-TxQAAAPU"]
[Thu Jul 30 15:36:53.265392 2026] [security2:error] [pid 189611:tid 189775] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-temp.php"] [unique_id "amu15eWE7BvPuUzLJ9-TyAAAAKc"]
[Thu Jul 30 15:36:53.265539 2026] [security2:error] [pid 189611:tid 189775] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-temp.php"] [unique_id "amu15eWE7BvPuUzLJ9-TyAAAAKc"]
[Thu Jul 30 15:36:53.458067 2026] [security2:error] [pid 189611:tid 189791] [client 191.232.199.39:8202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-the.php"] [unique_id "amu15eWE7BvPuUzLJ9-TzQAAALc"]
[Thu Jul 30 15:36:53.770647 2026] [security2:error] [pid 189611:tid 189832] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-content/cong.php"] [unique_id "amu15eWE7BvPuUzLJ9-T2AAAAOA"]
[Thu Jul 30 15:36:53.770757 2026] [security2:error] [pid 189611:tid 189832] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-content/cong.php"] [unique_id "amu15eWE7BvPuUzLJ9-T2AAAAOA"]
[Thu Jul 30 15:36:53.981701 2026] [core:notice] [pid 189611:tid 189670] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:36:53.992710 2026] [security2:error] [pid 189611:tid 189817] [client 20.91.199.21:41768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "amu15eWE7BvPuUzLJ9-T3gAAANE"]
[Thu Jul 30 15:36:54.289043 2026] [proxy:error] [pid 189611:tid 189773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:54.289114 2026] [proxy_http:error] [pid 189611:tid 189773] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:54.289772 2026] [proxy:error] [pid 189611:tid 189773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:36:54.289816 2026] [proxy_http:error] [pid 189611:tid 189773] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:36:54.289890 2026] [security2:error] [pid 189611:tid 189773] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amu15uWE7BvPuUzLJ9-T5QAAAKU"]
[Thu Jul 30 15:36:54.667778 2026] [security2:error] [pid 189611:tid 189866] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.applinex.pro"] [uri "/cgi-bin"] [unique_id "amu15uWE7BvPuUzLJ9-T6QAAAQI"]
[Thu Jul 30 15:36:54.768045 2026] [security2:error] [pid 189611:tid 189831] [client 191.232.199.39:8216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/404.php"] [unique_id "amu15uWE7BvPuUzLJ9-T7gAAAN8"]
[Thu Jul 30 15:36:54.803652 2026] [security2:error] [pid 189611:tid 189834] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-includes/css/index.php"] [unique_id "amu15uWE7BvPuUzLJ9-T8gAAAOI"]
[Thu Jul 30 15:36:54.803791 2026] [security2:error] [pid 189611:tid 189834] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-includes/css/index.php"] [unique_id "amu15uWE7BvPuUzLJ9-T8gAAAOI"]
[Thu Jul 30 15:36:55.317185 2026] [security2:error] [pid 189611:tid 189769] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/jj.php"] [unique_id "amu15-WE7BvPuUzLJ9-T_QAAAKE"]
[Thu Jul 30 15:36:55.317308 2026] [security2:error] [pid 189611:tid 189769] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/jj.php"] [unique_id "amu15-WE7BvPuUzLJ9-T_QAAAKE"]
[Thu Jul 30 15:36:55.831713 2026] [security2:error] [pid 189611:tid 189835] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/class-walker-footer-dev.php"] [unique_id "amu15-WE7BvPuUzLJ9-UBwAAAOM"]
[Thu Jul 30 15:36:55.831806 2026] [security2:error] [pid 189611:tid 189835] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/class-walker-footer-dev.php"] [unique_id "amu15-WE7BvPuUzLJ9-UBwAAAOM"]
[Thu Jul 30 15:36:56.340226 2026] [security2:error] [pid 189611:tid 189764] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xpwer1.php"] [unique_id "amu16OWE7BvPuUzLJ9-UDwAAAJw"]
[Thu Jul 30 15:36:56.340335 2026] [security2:error] [pid 189611:tid 189764] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xpwer1.php"] [unique_id "amu16OWE7BvPuUzLJ9-UDwAAAJw"]
[Thu Jul 30 15:36:56.628627 2026] [security2:error] [pid 189611:tid 189758] [client 191.232.199.39:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/init.php"] [unique_id "amu16OWE7BvPuUzLJ9-UGQAAAJY"]
[Thu Jul 30 15:36:56.651647 2026] [cgid:error] [pid 189611:tid 189783] [client 20.9.4.9:0] AH01265: stderr from /home1/glbnyxte/public_html/website_ed9bceb3/cgi-bin/: attempt to invoke directory as script
[Thu Jul 30 15:36:56.652413 2026] [security2:error] [pid 189611:tid 189783] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.applinex.pro"] [uri "/cgi-sys/403.html"] [unique_id "amu16OWE7BvPuUzLJ9-UGgAAAK8"]
[Thu Jul 30 15:36:56.797647 2026] [security2:error] [pid 189611:tid 189849] [client 20.91.199.21:41789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/content.php"] [unique_id "amu16OWE7BvPuUzLJ9-UGwAAAPE"]
[Thu Jul 30 15:36:56.852466 2026] [security2:error] [pid 189611:tid 189742] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/flox.php"] [unique_id "amu16OWE7BvPuUzLJ9-UHwAAAIY"]
[Thu Jul 30 15:36:56.852620 2026] [security2:error] [pid 189611:tid 189742] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/flox.php"] [unique_id "amu16OWE7BvPuUzLJ9-UHwAAAIY"]
[Thu Jul 30 15:36:56.890948 2026] [security2:error] [pid 189611:tid 189751] [client 38.172.162.57:15910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu16OWE7BvPuUzLJ9-UJgAAAI8"]
[Thu Jul 30 15:36:56.891425 2026] [security2:error] [pid 189611:tid 189751] [client 38.172.162.57:15910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu16OWE7BvPuUzLJ9-UJgAAAI8"]
[Thu Jul 30 15:36:56.903817 2026] [security2:error] [pid 189611:tid 189827] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/mah.php"] [unique_id "amu16OWE7BvPuUzLJ9-UJwAAANs"]
[Thu Jul 30 15:36:56.903921 2026] [security2:error] [pid 189611:tid 189827] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/mah.php"] [unique_id "amu16OWE7BvPuUzLJ9-UJwAAANs"]
[Thu Jul 30 15:36:57.360638 2026] [security2:error] [pid 189611:tid 189803] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/popo.php"] [unique_id "amu16eWE7BvPuUzLJ9-UMQAAAMM"]
[Thu Jul 30 15:36:57.360786 2026] [security2:error] [pid 189611:tid 189803] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/popo.php"] [unique_id "amu16eWE7BvPuUzLJ9-UMQAAAMM"]
[Thu Jul 30 15:36:57.894511 2026] [security2:error] [pid 189611:tid 189773] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/yas.php"] [unique_id "amu16eWE7BvPuUzLJ9-UPAAAAKU"]
[Thu Jul 30 15:36:57.894618 2026] [security2:error] [pid 189611:tid 189773] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/yas.php"] [unique_id "amu16eWE7BvPuUzLJ9-UPAAAAKU"]
[Thu Jul 30 15:36:58.043716 2026] [security2:error] [pid 189611:tid 189779] [client 191.232.199.39:8902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/file5.php"] [unique_id "amu16uWE7BvPuUzLJ9-UQgAAAKs"]
[Thu Jul 30 15:36:58.406889 2026] [security2:error] [pid 189611:tid 189857] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/water.php"] [unique_id "amu16uWE7BvPuUzLJ9-USAAAAPk"]
[Thu Jul 30 15:36:58.407025 2026] [security2:error] [pid 189611:tid 189857] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/water.php"] [unique_id "amu16uWE7BvPuUzLJ9-USAAAAPk"]
[Thu Jul 30 15:36:58.426124 2026] [security2:error] [pid 189611:tid 189852] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/archive.php"] [unique_id "amu16uWE7BvPuUzLJ9-USgAAAPQ"]
[Thu Jul 30 15:36:58.426208 2026] [security2:error] [pid 189611:tid 189852] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/archive.php"] [unique_id "amu16uWE7BvPuUzLJ9-USgAAAPQ"]
[Thu Jul 30 15:36:58.602540 2026] [security2:error] [pid 189611:tid 189842] [client 20.91.199.21:41748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "amu16uWE7BvPuUzLJ9-UVAAAAOo"]
[Thu Jul 30 15:36:58.789145 2026] [security2:error] [pid 189611:tid 189818] [client 116.179.37.171:21693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "online-hope.com"] [uri "/wp-content/plugins/litespeed-cache/guest.vary.php"] [unique_id "amu16uWE7BvPuUzLJ9-UVQAAANI"], referer: https://online-hope.com/
[Thu Jul 30 15:36:58.914817 2026] [security2:error] [pid 189611:tid 189867] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/nano.php"] [unique_id "amu16uWE7BvPuUzLJ9-UVgAAAQM"]
[Thu Jul 30 15:36:58.914996 2026] [security2:error] [pid 189611:tid 189867] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/nano.php"] [unique_id "amu16uWE7BvPuUzLJ9-UVgAAAQM"]
[Thu Jul 30 15:36:58.968764 2026] [security2:error] [pid 189611:tid 189863] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/hosty.php"] [unique_id "amu16uWE7BvPuUzLJ9-UWgAAAP8"]
[Thu Jul 30 15:36:58.968867 2026] [security2:error] [pid 189611:tid 189863] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/hosty.php"] [unique_id "amu16uWE7BvPuUzLJ9-UWgAAAP8"]
[Thu Jul 30 15:36:59.398951 2026] [security2:error] [pid 189611:tid 189794] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/moon.php"] [unique_id "amu16-WE7BvPuUzLJ9-UYQAAALo"]
[Thu Jul 30 15:36:59.399066 2026] [security2:error] [pid 189611:tid 189794] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/moon.php"] [unique_id "amu16-WE7BvPuUzLJ9-UYQAAALo"]
[Thu Jul 30 15:36:59.493632 2026] [security2:error] [pid 189611:tid 189750] [client 191.232.199.39:46252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amu16-WE7BvPuUzLJ9-UZQAAAI4"]
[Thu Jul 30 15:36:59.539851 2026] [autoindex:error] [pid 189611:tid 189767] [client 20.9.4.9:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_ed9bceb3/wp-includes/Text/Diff/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:36:59.540618 2026] [security2:error] [pid 189611:tid 189767] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.applinex.pro"] [uri "/cgi-sys/403.html"] [unique_id "amu16-WE7BvPuUzLJ9-UZgAAAJ8"]
[Thu Jul 30 15:36:59.853923 2026] [security2:error] [pid 189611:tid 189770] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/admin.php"] [unique_id "amu16-WE7BvPuUzLJ9-UbQAAAKI"]
[Thu Jul 30 15:36:59.854070 2026] [security2:error] [pid 189611:tid 189770] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/admin.php"] [unique_id "amu16-WE7BvPuUzLJ9-UbQAAAKI"]
[Thu Jul 30 15:36:59.904118 2026] [security2:error] [pid 189611:tid 189773] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-info.php"] [unique_id "amu16-WE7BvPuUzLJ9-UbgAAAKU"]
[Thu Jul 30 15:36:59.904217 2026] [security2:error] [pid 189611:tid 189773] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-info.php"] [unique_id "amu16-WE7BvPuUzLJ9-UbgAAAKU"]
[Thu Jul 30 15:37:00.405537 2026] [security2:error] [pid 189611:tid 189806] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/av.php"] [unique_id "amu17OWE7BvPuUzLJ9-UdgAAAMY"]
[Thu Jul 30 15:37:00.405688 2026] [security2:error] [pid 189611:tid 189806] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/av.php"] [unique_id "amu17OWE7BvPuUzLJ9-UdgAAAMY"]
[Thu Jul 30 15:37:00.415954 2026] [security2:error] [pid 189611:tid 189865] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/file5.php"] [unique_id "amu17OWE7BvPuUzLJ9-UdwAAAQE"]
[Thu Jul 30 15:37:00.416100 2026] [security2:error] [pid 189611:tid 189865] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/file5.php"] [unique_id "amu17OWE7BvPuUzLJ9-UdwAAAQE"]
[Thu Jul 30 15:37:00.519211 2026] [security2:error] [pid 189611:tid 189723] [remote 74.7.243.224:57240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amu17OWE7BvPuUzLJ9-UfAAAhW8"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 15:37:00.734908 2026] [security2:error] [pid 189611:tid 189764] [client 191.232.199.39:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/shell.php"] [unique_id "amu17OWE7BvPuUzLJ9-UgQAAAJw"]
[Thu Jul 30 15:37:00.932256 2026] [security2:error] [pid 189611:tid 189763] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/2000.php"] [unique_id "amu17OWE7BvPuUzLJ9-UiwAAAJs"]
[Thu Jul 30 15:37:00.932347 2026] [security2:error] [pid 189611:tid 189763] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/2000.php"] [unique_id "amu17OWE7BvPuUzLJ9-UiwAAAJs"]
[Thu Jul 30 15:37:00.941912 2026] [security2:error] [pid 189611:tid 189819] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/shell.php"] [unique_id "amu17OWE7BvPuUzLJ9-UjAAAANM"]
[Thu Jul 30 15:37:00.942006 2026] [security2:error] [pid 189611:tid 189819] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/shell.php"] [unique_id "amu17OWE7BvPuUzLJ9-UjAAAANM"]
[Thu Jul 30 15:37:01.039936 2026] [security2:error] [pid 189611:tid 189827] [client 204.8.98.55:41326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amu17eWE7BvPuUzLJ9-UjQAAANs"]
[Thu Jul 30 15:37:01.040043 2026] [security2:error] [pid 189611:tid 189827] [client 204.8.98.55:41326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amu17eWE7BvPuUzLJ9-UjQAAANs"]
[Thu Jul 30 15:37:01.461138 2026] [security2:error] [pid 189611:tid 189833] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/122.php"] [unique_id "amu17eWE7BvPuUzLJ9-UmAAAAOE"]
[Thu Jul 30 15:37:01.461220 2026] [security2:error] [pid 189611:tid 189833] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/122.php"] [unique_id "amu17eWE7BvPuUzLJ9-UmAAAAOE"]
[Thu Jul 30 15:37:01.469629 2026] [security2:error] [pid 189611:tid 189801] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/storage/index.php"] [unique_id "amu17eWE7BvPuUzLJ9-UmQAAAME"]
[Thu Jul 30 15:37:01.469706 2026] [security2:error] [pid 189611:tid 189801] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/storage/index.php"] [unique_id "amu17eWE7BvPuUzLJ9-UmQAAAME"]
[Thu Jul 30 15:37:01.947046 2026] [security2:error] [pid 189611:tid 189829] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/mds.php"] [unique_id "amu17eWE7BvPuUzLJ9-UpwAAAN0"]
[Thu Jul 30 15:37:01.947154 2026] [security2:error] [pid 189611:tid 189829] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/mds.php"] [unique_id "amu17eWE7BvPuUzLJ9-UpwAAAN0"]
[Thu Jul 30 15:37:01.994377 2026] [security2:error] [pid 189611:tid 189803] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/w.php"] [unique_id "amu17eWE7BvPuUzLJ9-UqgAAAMM"]
[Thu Jul 30 15:37:01.994559 2026] [security2:error] [pid 189611:tid 189803] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/w.php"] [unique_id "amu17eWE7BvPuUzLJ9-UqgAAAMM"]
[Thu Jul 30 15:37:02.000043 2026] [security2:error] [pid 189611:tid 189868] [client 191.232.199.39:46266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/f35.php"] [unique_id "amu17eWE7BvPuUzLJ9-UrAAAAQQ"]
[Thu Jul 30 15:37:02.163650 2026] [core:notice] [pid 189611:tid 189726] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:02.438394 2026] [security2:error] [pid 189611:tid 189845] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/zc-208.php"] [unique_id "amu17uWE7BvPuUzLJ9-UwAAAAO0"]
[Thu Jul 30 15:37:02.438501 2026] [security2:error] [pid 189611:tid 189845] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/zc-208.php"] [unique_id "amu17uWE7BvPuUzLJ9-UwAAAAO0"]
[Thu Jul 30 15:37:02.953938 2026] [security2:error] [pid 189611:tid 189747] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sid4.php"] [unique_id "amu17uWE7BvPuUzLJ9-U0QAAAIs"]
[Thu Jul 30 15:37:02.954074 2026] [security2:error] [pid 189611:tid 189747] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sid4.php"] [unique_id "amu17uWE7BvPuUzLJ9-U0QAAAIs"]
[Thu Jul 30 15:37:03.416137 2026] [security2:error] [pid 189611:tid 189763] [client 191.232.199.39:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/new.php"] [unique_id "amu17-WE7BvPuUzLJ9-U2QAAAJs"]
[Thu Jul 30 15:37:03.462746 2026] [proxy:error] [pid 189611:tid 189753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:03.462815 2026] [proxy_http:error] [pid 189611:tid 189753] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:03.463422 2026] [proxy:error] [pid 189611:tid 189753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:03.463467 2026] [proxy_http:error] [pid 189611:tid 189753] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:03.463546 2026] [security2:error] [pid 189611:tid 189753] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amu17-WE7BvPuUzLJ9-U2gAAAJE"]
[Thu Jul 30 15:37:03.667514 2026] [core:notice] [pid 189611:tid 189721] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:03.979317 2026] [security2:error] [pid 189611:tid 189797] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wmore1.php"] [unique_id "amu17-WE7BvPuUzLJ9-U7QAAAL0"]
[Thu Jul 30 15:37:03.979453 2026] [security2:error] [pid 189611:tid 189797] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wmore1.php"] [unique_id "amu17-WE7BvPuUzLJ9-U7QAAAL0"]
[Thu Jul 30 15:37:04.504059 2026] [security2:error] [pid 189611:tid 189866] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/solo1.php"] [unique_id "amu18OWE7BvPuUzLJ9-U-wAAAQI"]
[Thu Jul 30 15:37:04.504178 2026] [security2:error] [pid 189611:tid 189866] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/solo1.php"] [unique_id "amu18OWE7BvPuUzLJ9-U-wAAAQI"]
[Thu Jul 30 15:37:04.665619 2026] [security2:error] [pid 189611:tid 189865] [client 191.232.199.39:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/adminfuns.php"] [unique_id "amu18OWE7BvPuUzLJ9-VAAAAAQE"]
[Thu Jul 30 15:37:05.014262 2026] [proxy:error] [pid 189611:tid 189776] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:05.014336 2026] [proxy_http:error] [pid 189611:tid 189776] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:05.015201 2026] [proxy:error] [pid 189611:tid 189776] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:05.015257 2026] [proxy_http:error] [pid 189611:tid 189776] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:05.015362 2026] [security2:error] [pid 189611:tid 189776] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amu18eWE7BvPuUzLJ9-VBgAAAKg"]
[Thu Jul 30 15:37:05.140133 2026] [security2:error] [pid 189611:tid 189834] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/jp.php"] [unique_id "amu18eWE7BvPuUzLJ9-VDgAAAOI"]
[Thu Jul 30 15:37:05.140247 2026] [security2:error] [pid 189611:tid 189834] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/jp.php"] [unique_id "amu18eWE7BvPuUzLJ9-VDgAAAOI"]
[Thu Jul 30 15:37:05.555766 2026] [proxy:error] [pid 189611:tid 189778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:05.555833 2026] [proxy_http:error] [pid 189611:tid 189778] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:05.556423 2026] [proxy:error] [pid 189611:tid 189778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:05.556480 2026] [proxy_http:error] [pid 189611:tid 189778] [client 20.48.234.177:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:05.556567 2026] [security2:error] [pid 189611:tid 189778] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "amu18eWE7BvPuUzLJ9-VGQAAAKo"]
[Thu Jul 30 15:37:05.605080 2026] [security2:error] [pid 189611:tid 189854] [client 20.91.199.21:41821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "amu18eWE7BvPuUzLJ9-VHQAAAPY"]
[Thu Jul 30 15:37:05.647694 2026] [authz_core:error] [pid 189611:tid 189774] [client 20.9.4.9:0] AH01630: client denied by server configuration: /home1/glbnyxte/public_html/website_ed9bceb3/php.ini
[Thu Jul 30 15:37:05.648418 2026] [security2:error] [pid 189611:tid 189774] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.applinex.pro"] [uri "/cgi-sys/403.html"] [unique_id "amu18eWE7BvPuUzLJ9-VHgAAAKY"]
[Thu Jul 30 15:37:05.907006 2026] [security2:error] [pid 189611:tid 189810] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/ws77.php"] [unique_id "amu18eWE7BvPuUzLJ9-VIwAAAMo"]
[Thu Jul 30 15:37:05.907114 2026] [security2:error] [pid 189611:tid 189810] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/ws77.php"] [unique_id "amu18eWE7BvPuUzLJ9-VIwAAAMo"]
[Thu Jul 30 15:37:06.073879 2026] [security2:error] [pid 189611:tid 189808] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/public/css.php"] [unique_id "amu18uWE7BvPuUzLJ9-VJwAAAMg"]
[Thu Jul 30 15:37:06.074003 2026] [security2:error] [pid 189611:tid 189808] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/public/css.php"] [unique_id "amu18uWE7BvPuUzLJ9-VJwAAAMg"]
[Thu Jul 30 15:37:06.595303 2026] [security2:error] [pid 189611:tid 189826] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/output.php"] [unique_id "amu18uWE7BvPuUzLJ9-VOAAAANo"]
[Thu Jul 30 15:37:06.595424 2026] [security2:error] [pid 189611:tid 189826] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/output.php"] [unique_id "amu18uWE7BvPuUzLJ9-VOAAAANo"]
[Thu Jul 30 15:37:06.638323 2026] [security2:error] [pid 189611:tid 189741] [client 20.203.148.31:63694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/hehe.php"] [unique_id "amu18uWE7BvPuUzLJ9-VOwAAAIU"]
[Thu Jul 30 15:37:07.086049 2026] [security2:error] [pid 189611:tid 189819] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-file-120.php"] [unique_id "amu18-WE7BvPuUzLJ9-VRgAAANM"]
[Thu Jul 30 15:37:07.086143 2026] [security2:error] [pid 189611:tid 189819] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-file-120.php"] [unique_id "amu18-WE7BvPuUzLJ9-VRgAAANM"]
[Thu Jul 30 15:37:07.155964 2026] [core:notice] [pid 189611:tid 189629] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:07.166195 2026] [security2:error] [pid 189611:tid 189805] [client 191.232.199.39:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/fm.php"] [unique_id "amu18-WE7BvPuUzLJ9-VTgAAAMU"]
[Thu Jul 30 15:37:07.353685 2026] [security2:error] [pid 189611:tid 189837] [client 38.172.162.57:16264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu18-WE7BvPuUzLJ9-VTwAAAOU"]
[Thu Jul 30 15:37:07.353801 2026] [security2:error] [pid 189611:tid 189837] [client 38.172.162.57:16264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu18-WE7BvPuUzLJ9-VTwAAAOU"]
[Thu Jul 30 15:37:07.447276 2026] [security2:error] [pid 189611:tid 189812] [client 20.91.199.21:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "amu18-WE7BvPuUzLJ9-VUAAAAMw"]
[Thu Jul 30 15:37:07.475743 2026] [security2:error] [pid 189611:tid 189765] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/blass.php"] [unique_id "amu18-WE7BvPuUzLJ9-VUQAAAJ0"]
[Thu Jul 30 15:37:07.475837 2026] [security2:error] [pid 189611:tid 189765] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/blass.php"] [unique_id "amu18-WE7BvPuUzLJ9-VUQAAAJ0"]
[Thu Jul 30 15:37:07.602706 2026] [security2:error] [pid 189611:tid 189788] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/special.php"] [unique_id "amu18-WE7BvPuUzLJ9-VVQAAALQ"]
[Thu Jul 30 15:37:07.602813 2026] [security2:error] [pid 189611:tid 189788] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/special.php"] [unique_id "amu18-WE7BvPuUzLJ9-VVQAAALQ"]
[Thu Jul 30 15:37:07.995672 2026] [security2:error] [pid 189611:tid 189753] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-info.php"] [unique_id "amu18-WE7BvPuUzLJ9-VXAAAAJE"]
[Thu Jul 30 15:37:07.995789 2026] [security2:error] [pid 189611:tid 189753] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-info.php"] [unique_id "amu18-WE7BvPuUzLJ9-VXAAAAJE"]
[Thu Jul 30 15:37:08.124365 2026] [security2:error] [pid 189611:tid 189784] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/as.php"] [unique_id "amu19OWE7BvPuUzLJ9-VYQAAALA"]
[Thu Jul 30 15:37:08.124466 2026] [security2:error] [pid 189611:tid 189784] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/as.php"] [unique_id "amu19OWE7BvPuUzLJ9-VYQAAALA"]
[Thu Jul 30 15:37:08.215500 2026] [security2:error] [pid 189611:tid 189792] [client 20.203.148.31:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/rk2.php"] [unique_id "amu19OWE7BvPuUzLJ9-VZQAAALg"]
[Thu Jul 30 15:37:08.549127 2026] [security2:error] [pid 189611:tid 189779] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/CDX1.php"] [unique_id "amu19OWE7BvPuUzLJ9-VagAAAKs"]
[Thu Jul 30 15:37:08.549277 2026] [security2:error] [pid 189611:tid 189779] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/CDX1.php"] [unique_id "amu19OWE7BvPuUzLJ9-VagAAAKs"]
[Thu Jul 30 15:37:08.614273 2026] [security2:error] [pid 189611:tid 189851] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/cgi-bin/index.php"] [unique_id "amu19OWE7BvPuUzLJ9-VawAAAPM"]
[Thu Jul 30 15:37:08.614405 2026] [security2:error] [pid 189611:tid 189851] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/cgi-bin/index.php"] [unique_id "amu19OWE7BvPuUzLJ9-VawAAAPM"]
[Thu Jul 30 15:37:08.905083 2026] [security2:error] [pid 189611:tid 189734] [remote 92.222.104.223:26258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lark-shop.com"] [uri "/robots.txt"] [unique_id "amu19OWE7BvPuUzLJ9-VdgAAyXo"]
[Thu Jul 30 15:37:08.905245 2026] [security2:error] [pid 189611:tid 189809] [client 92.222.104.223:26258] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lark-shop.com"] [uri "/robots.txt"] [unique_id "amu19OWE7BvPuUzLJ9-VdgAAyXo"]
[Thu Jul 30 15:37:09.105633 2026] [security2:error] [pid 189611:tid 189865] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/w1px.php"] [unique_id "amu19eWE7BvPuUzLJ9-VdwAAAQE"]
[Thu Jul 30 15:37:09.105768 2026] [security2:error] [pid 189611:tid 189865] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/w1px.php"] [unique_id "amu19eWE7BvPuUzLJ9-VdwAAAQE"]
[Thu Jul 30 15:37:09.145701 2026] [security2:error] [pid 189611:tid 189742] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wpc.php"] [unique_id "amu19eWE7BvPuUzLJ9-VfAAAAIY"]
[Thu Jul 30 15:37:09.145843 2026] [security2:error] [pid 189611:tid 189742] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wpc.php"] [unique_id "amu19eWE7BvPuUzLJ9-VfAAAAIY"]
[Thu Jul 30 15:37:09.220651 2026] [core:notice] [pid 189611:tid 189842] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:09.479548 2026] [security2:error] [pid 189611:tid 189797] [client 20.91.199.21:22485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "amu19eWE7BvPuUzLJ9-VhQAAAL0"]
[Thu Jul 30 15:37:09.629482 2026] [security2:error] [pid 189611:tid 189799] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/js.php"] [unique_id "amu19eWE7BvPuUzLJ9-ViQAAAL8"]
[Thu Jul 30 15:37:09.629578 2026] [security2:error] [pid 189611:tid 189799] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/js.php"] [unique_id "amu19eWE7BvPuUzLJ9-ViQAAAL8"]
[Thu Jul 30 15:37:09.726104 2026] [security2:error] [pid 189611:tid 189788] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/jga.php"] [unique_id "amu19eWE7BvPuUzLJ9-VjgAAALQ"]
[Thu Jul 30 15:37:09.726212 2026] [security2:error] [pid 189611:tid 189788] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/jga.php"] [unique_id "amu19eWE7BvPuUzLJ9-VjgAAALQ"]
[Thu Jul 30 15:37:09.913960 2026] [core:notice] [pid 189611:tid 189765] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:09.945860 2026] [security2:error] [pid 189611:tid 189862] [client 191.232.199.39:9128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/file.php"] [unique_id "amu19eWE7BvPuUzLJ9-VlgAAAP4"]
[Thu Jul 30 15:37:10.180947 2026] [security2:error] [pid 189611:tid 189794] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/core.php"] [unique_id "amu19uWE7BvPuUzLJ9-VmAAAALo"]
[Thu Jul 30 15:37:10.181070 2026] [security2:error] [pid 189611:tid 189794] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/core.php"] [unique_id "amu19uWE7BvPuUzLJ9-VmAAAALo"]
[Thu Jul 30 15:37:10.289304 2026] [security2:error] [pid 189611:tid 189639] [remote 198.244.226.153:61062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lark-shop.com"] [uri "/shop1/"] [unique_id "amu19uWE7BvPuUzLJ9-VnwAAjRs"]
[Thu Jul 30 15:37:10.289439 2026] [security2:error] [pid 189611:tid 189749] [client 198.244.226.153:61062] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lark-shop.com"] [uri "/shop1/"] [unique_id "amu19uWE7BvPuUzLJ9-VnwAAjRs"]
[Thu Jul 30 15:37:10.309064 2026] [security2:error] [pid 189611:tid 189868] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/666.php"] [unique_id "amu19uWE7BvPuUzLJ9-VogAAAQQ"]
[Thu Jul 30 15:37:10.309144 2026] [security2:error] [pid 189611:tid 189868] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/666.php"] [unique_id "amu19uWE7BvPuUzLJ9-VogAAAQQ"]
[Thu Jul 30 15:37:10.423218 2026] [core:notice] [pid 189611:tid 189659] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:10.704581 2026] [security2:error] [pid 189611:tid 189856] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fffm.php"] [unique_id "amu19uWE7BvPuUzLJ9-VpgAAAPg"]
[Thu Jul 30 15:37:10.704683 2026] [security2:error] [pid 189611:tid 189856] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fffm.php"] [unique_id "amu19uWE7BvPuUzLJ9-VpgAAAPg"]
[Thu Jul 30 15:37:10.841931 2026] [security2:error] [pid 189611:tid 189757] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/htaccess.php"] [unique_id "amu19uWE7BvPuUzLJ9-VrQAAAJU"]
[Thu Jul 30 15:37:10.842062 2026] [security2:error] [pid 189611:tid 189757] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/htaccess.php"] [unique_id "amu19uWE7BvPuUzLJ9-VrQAAAJU"]
[Thu Jul 30 15:37:11.214399 2026] [security2:error] [pid 189611:tid 189775] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ww.php"] [unique_id "amu19-WE7BvPuUzLJ9-VsQAAAKc"]
[Thu Jul 30 15:37:11.214554 2026] [security2:error] [pid 189611:tid 189775] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ww.php"] [unique_id "amu19-WE7BvPuUzLJ9-VsQAAAKc"]
[Thu Jul 30 15:37:11.337498 2026] [security2:error] [pid 189611:tid 189790] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/m.php"] [unique_id "amu19-WE7BvPuUzLJ9-VuQAAALY"]
[Thu Jul 30 15:37:11.337587 2026] [security2:error] [pid 189611:tid 189790] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/m.php"] [unique_id "amu19-WE7BvPuUzLJ9-VuQAAALY"]
[Thu Jul 30 15:37:11.345055 2026] [security2:error] [pid 189611:tid 189745] [client 20.91.199.21:17322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "amu19-WE7BvPuUzLJ9-VugAAAIk"]
[Thu Jul 30 15:37:11.460388 2026] [security2:error] [pid 189611:tid 189830] [client 66.249.74.41:54218] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.388iendd.site"] [uri "/robots.txt"] [unique_id "amu19-WE7BvPuUzLJ9-VvgAAAN4"]
[Thu Jul 30 15:37:11.518675 2026] [security2:error] [pid 189611:tid 189844] [client 20.203.148.31:61214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/setup-config.php"] [unique_id "amu19-WE7BvPuUzLJ9-VvwAAAOw"]
[Thu Jul 30 15:37:11.722003 2026] [security2:error] [pid 189611:tid 189849] [client 191.232.199.39:61497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/bolt.php"] [unique_id "amu19-WE7BvPuUzLJ9-VwgAAAPE"]
[Thu Jul 30 15:37:11.744311 2026] [security2:error] [pid 189611:tid 189843] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/domvf.php"] [unique_id "amu19-WE7BvPuUzLJ9-VxAAAAOs"]
[Thu Jul 30 15:37:11.744427 2026] [security2:error] [pid 189611:tid 189843] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/domvf.php"] [unique_id "amu19-WE7BvPuUzLJ9-VxAAAAOs"]
[Thu Jul 30 15:37:11.889595 2026] [security2:error] [pid 189611:tid 189801] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/file.php"] [unique_id "amu19-WE7BvPuUzLJ9-VywAAAME"]
[Thu Jul 30 15:37:11.889697 2026] [security2:error] [pid 189611:tid 189801] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/file.php"] [unique_id "amu19-WE7BvPuUzLJ9-VywAAAME"]
[Thu Jul 30 15:37:12.173671 2026] [security2:error] [pid 189611:tid 189762] [client 20.91.199.21:41838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "amu1-OWE7BvPuUzLJ9-VzQAAAJo"]
[Thu Jul 30 15:37:12.241312 2026] [security2:error] [pid 189611:tid 189765] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/echkm.php"] [unique_id "amu1-OWE7BvPuUzLJ9-V0QAAAJ0"]
[Thu Jul 30 15:37:12.241418 2026] [security2:error] [pid 189611:tid 189765] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/echkm.php"] [unique_id "amu1-OWE7BvPuUzLJ9-V0QAAAJ0"]
[Thu Jul 30 15:37:12.366610 2026] [security2:error] [pid 189611:tid 189671] [remote 57.141.0.44:38438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/491057609/feed/rss2/"] [unique_id "amu1-OWE7BvPuUzLJ9-V2gAA1Ts"]
[Thu Jul 30 15:37:12.382185 2026] [security2:error] [pid 189611:tid 189825] [client 20.203.148.31:63692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/a7.php"] [unique_id "amu1-OWE7BvPuUzLJ9-V3AAAANk"]
[Thu Jul 30 15:37:12.474790 2026] [security2:error] [pid 189611:tid 189787] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/.dj/index.php"] [unique_id "amu1-OWE7BvPuUzLJ9-V3QAAALM"]
[Thu Jul 30 15:37:12.474910 2026] [security2:error] [pid 189611:tid 189787] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/.dj/index.php"] [unique_id "amu1-OWE7BvPuUzLJ9-V3QAAALM"]
[Thu Jul 30 15:37:12.722935 2026] [security2:error] [pid 189611:tid 189766] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ano.php"] [unique_id "amu1-OWE7BvPuUzLJ9-V4QAAAJ4"]
[Thu Jul 30 15:37:12.723067 2026] [security2:error] [pid 189611:tid 189766] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ano.php"] [unique_id "amu1-OWE7BvPuUzLJ9-V4QAAAJ4"]
[Thu Jul 30 15:37:13.041507 2026] [security2:error] [pid 189611:tid 189767] [client 191.232.199.39:46067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/3.php"] [unique_id "amu1-eWE7BvPuUzLJ9-V7AAAAJ8"]
[Thu Jul 30 15:37:13.171906 2026] [security2:error] [pid 189611:tid 189743] [client 20.203.148.31:60810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/f7.php"] [unique_id "amu1-eWE7BvPuUzLJ9-V7QAAAIc"]
[Thu Jul 30 15:37:13.215181 2026] [security2:error] [pid 189611:tid 189741] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ah25.php"] [unique_id "amu1-eWE7BvPuUzLJ9-V7gAAAIU"]
[Thu Jul 30 15:37:13.215322 2026] [security2:error] [pid 189611:tid 189741] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ah25.php"] [unique_id "amu1-eWE7BvPuUzLJ9-V7gAAAIU"]
[Thu Jul 30 15:37:13.520784 2026] [security2:error] [pid 189611:tid 189865] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-admin/maint/index.php"] [unique_id "amu1-eWE7BvPuUzLJ9-V9wAAAQE"]
[Thu Jul 30 15:37:13.520870 2026] [security2:error] [pid 189611:tid 189865] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-admin/maint/index.php"] [unique_id "amu1-eWE7BvPuUzLJ9-V9wAAAQE"]
[Thu Jul 30 15:37:13.697901 2026] [security2:error] [pid 189611:tid 189842] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/term.php"] [unique_id "amu1-eWE7BvPuUzLJ9-V-QAAAOo"]
[Thu Jul 30 15:37:13.698054 2026] [security2:error] [pid 189611:tid 189842] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/term.php"] [unique_id "amu1-eWE7BvPuUzLJ9-V-QAAAOo"]
[Thu Jul 30 15:37:13.890007 2026] [security2:error] [pid 189611:tid 189677] [remote 57.141.0.22:20796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/about/contact"] [unique_id "amu1-eWE7BvPuUzLJ9-WAAAAx0E"]
[Thu Jul 30 15:37:14.098911 2026] [security2:error] [pid 189611:tid 189849] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/pages.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WBwAAAPE"]
[Thu Jul 30 15:37:14.099024 2026] [security2:error] [pid 189611:tid 189849] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/pages.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WBwAAAPE"]
[Thu Jul 30 15:37:14.188578 2026] [security2:error] [pid 189611:tid 189816] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/we.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WCAAAANA"]
[Thu Jul 30 15:37:14.188700 2026] [security2:error] [pid 189611:tid 189816] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/we.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WCAAAANA"]
[Thu Jul 30 15:37:14.403158 2026] [security2:error] [pid 189611:tid 189751] [client 191.232.199.39:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/222.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WDQAAAI8"]
[Thu Jul 30 15:37:14.628484 2026] [security2:error] [pid 189611:tid 189774] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/adminfuns.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WFAAAAKY"]
[Thu Jul 30 15:37:14.628579 2026] [security2:error] [pid 189611:tid 189774] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/adminfuns.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WFAAAAKY"]
[Thu Jul 30 15:37:14.671969 2026] [security2:error] [pid 189611:tid 189768] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/zip-onee.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WFQAAAKA"]
[Thu Jul 30 15:37:14.672093 2026] [security2:error] [pid 189611:tid 189768] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/zip-onee.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WFQAAAKA"]
[Thu Jul 30 15:37:14.820712 2026] [security2:error] [pid 189611:tid 189769] [client 20.91.199.21:17325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "amu1-uWE7BvPuUzLJ9-WGQAAAKE"]
[Thu Jul 30 15:37:15.152850 2026] [security2:error] [pid 189611:tid 189782] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/il.php"] [unique_id "amu1--WE7BvPuUzLJ9-WIwAAAK4"]
[Thu Jul 30 15:37:15.152991 2026] [security2:error] [pid 189611:tid 189782] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/il.php"] [unique_id "amu1--WE7BvPuUzLJ9-WIwAAAK4"]
[Thu Jul 30 15:37:15.214412 2026] [security2:error] [pid 189611:tid 189808] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/aa.php"] [unique_id "amu1--WE7BvPuUzLJ9-WJAAAAMg"]
[Thu Jul 30 15:37:15.214520 2026] [security2:error] [pid 189611:tid 189808] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/aa.php"] [unique_id "amu1--WE7BvPuUzLJ9-WJAAAAMg"]
[Thu Jul 30 15:37:15.636950 2026] [security2:error] [pid 189611:tid 189853] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/one.php"] [unique_id "amu1--WE7BvPuUzLJ9-WMQAAAPU"]
[Thu Jul 30 15:37:15.637066 2026] [security2:error] [pid 189611:tid 189853] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/one.php"] [unique_id "amu1--WE7BvPuUzLJ9-WMQAAAPU"]
[Thu Jul 30 15:37:15.771573 2026] [security2:error] [pid 189611:tid 189803] [client 191.232.199.39:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amu1--WE7BvPuUzLJ9-WMgAAAMM"]
[Thu Jul 30 15:37:15.790902 2026] [autoindex:error] [pid 189611:tid 189761] [client 20.9.4.9:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_ed9bceb3/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:37:15.791666 2026] [security2:error] [pid 189611:tid 189761] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.applinex.pro"] [uri "/cgi-sys/403.html"] [unique_id "amu1--WE7BvPuUzLJ9-WMwAAAJk"]
[Thu Jul 30 15:37:16.061989 2026] [security2:error] [pid 189611:tid 189747] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/classwithtostring.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WOgAAAIs"]
[Thu Jul 30 15:37:16.062091 2026] [security2:error] [pid 189611:tid 189747] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/classwithtostring.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WOgAAAIs"]
[Thu Jul 30 15:37:16.120303 2026] [security2:error] [pid 189611:tid 189780] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/002.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WPAAAAKw"]
[Thu Jul 30 15:37:16.120405 2026] [security2:error] [pid 189611:tid 189780] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/002.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WPAAAAKw"]
[Thu Jul 30 15:37:16.482095 2026] [security2:error] [pid 189611:tid 189766] [client 20.91.199.21:1496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WRAAAAJ4"]
[Thu Jul 30 15:37:16.482594 2026] [security2:error] [pid 189611:tid 189745] [client 20.226.5.174:2119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Avada/licensing/style.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WRQAAAIk"]
[Thu Jul 30 15:37:16.615849 2026] [security2:error] [pid 189611:tid 189848] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/about.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WTAAAAPA"]
[Thu Jul 30 15:37:16.615955 2026] [security2:error] [pid 189611:tid 189848] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/about.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WTAAAAPA"]
[Thu Jul 30 15:37:16.626786 2026] [security2:error] [pid 189611:tid 189755] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/file1.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WTgAAAJM"]
[Thu Jul 30 15:37:16.626867 2026] [security2:error] [pid 189611:tid 189755] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/file1.php"] [unique_id "amu1_OWE7BvPuUzLJ9-WTgAAAJM"]
[Thu Jul 30 15:37:17.108845 2026] [security2:error] [pid 189611:tid 189774] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/akimet.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WVQAAAKY"]
[Thu Jul 30 15:37:17.108939 2026] [security2:error] [pid 189611:tid 189774] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/akimet.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WVQAAAKY"]
[Thu Jul 30 15:37:17.193695 2026] [security2:error] [pid 189611:tid 189821] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/goods.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WXAAAANU"]
[Thu Jul 30 15:37:17.193783 2026] [security2:error] [pid 189611:tid 189821] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/goods.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WXAAAANU"]
[Thu Jul 30 15:37:17.413398 2026] [security2:error] [pid 189611:tid 189812] [client 191.232.199.39:46260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WXQAAAMw"]
[Thu Jul 30 15:37:17.440615 2026] [security2:error] [pid 189611:tid 189858] [client 20.226.5.174:2130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/BDKR28_nfbxj7ov.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WXgAAAPo"]
[Thu Jul 30 15:37:17.601428 2026] [security2:error] [pid 189611:tid 189838] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/reop3.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WZQAAAOY"]
[Thu Jul 30 15:37:17.601538 2026] [security2:error] [pid 189611:tid 189838] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/reop3.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WZQAAAOY"]
[Thu Jul 30 15:37:17.755544 2026] [security2:error] [pid 189611:tid 189860] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/php8.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WawAAAPw"]
[Thu Jul 30 15:37:17.755653 2026] [security2:error] [pid 189611:tid 189860] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/php8.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WawAAAPw"]
[Thu Jul 30 15:37:17.964153 2026] [security2:error] [pid 189611:tid 189784] [client 38.172.162.57:16412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WbQAAALA"]
[Thu Jul 30 15:37:17.964369 2026] [security2:error] [pid 189611:tid 189784] [client 38.172.162.57:16412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu1_eWE7BvPuUzLJ9-WbQAAALA"]
[Thu Jul 30 15:37:18.118593 2026] [security2:error] [pid 189611:tid 189820] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/h.php"] [unique_id "amu1_uWE7BvPuUzLJ9-WdAAAANQ"]
[Thu Jul 30 15:37:18.118697 2026] [security2:error] [pid 189611:tid 189820] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/h.php"] [unique_id "amu1_uWE7BvPuUzLJ9-WdAAAANQ"]
[Thu Jul 30 15:37:18.132778 2026] [security2:error] [pid 189611:tid 189829] [client 20.91.199.21:1556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "amu1_uWE7BvPuUzLJ9-WdQAAAN0"]
[Thu Jul 30 15:37:18.296140 2026] [security2:error] [pid 189611:tid 189758] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/info.php"] [unique_id "amu1_uWE7BvPuUzLJ9-WfQAAAJY"]
[Thu Jul 30 15:37:18.296247 2026] [security2:error] [pid 189611:tid 189758] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/info.php"] [unique_id "amu1_uWE7BvPuUzLJ9-WfQAAAJY"]
[Thu Jul 30 15:37:18.386190 2026] [security2:error] [pid 189611:tid 189824] [client 20.226.5.174:2115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/BIBIL.php"] [unique_id "amu1_uWE7BvPuUzLJ9-WfgAAANg"]
[Thu Jul 30 15:37:18.495655 2026] [security2:error] [pid 189611:tid 189802] [client 20.203.148.31:60849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/nw.php"] [unique_id "amu1_uWE7BvPuUzLJ9-WfwAAAMI"]
[Thu Jul 30 15:37:18.621881 2026] [security2:error] [pid 189611:tid 189780] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/2x.php"] [unique_id "amu1_uWE7BvPuUzLJ9-WggAAAKw"]
[Thu Jul 30 15:37:18.622005 2026] [security2:error] [pid 189611:tid 189780] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/2x.php"] [unique_id "amu1_uWE7BvPuUzLJ9-WggAAAKw"]
[Thu Jul 30 15:37:19.121617 2026] [security2:error] [pid 189611:tid 189849] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/petx.php"] [unique_id "amu1_-WE7BvPuUzLJ9-WjwAAAPE"]
[Thu Jul 30 15:37:19.121706 2026] [security2:error] [pid 189611:tid 189849] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/petx.php"] [unique_id "amu1_-WE7BvPuUzLJ9-WjwAAAPE"]
[Thu Jul 30 15:37:19.237505 2026] [security2:error] [pid 189611:tid 189848] [client 20.203.148.31:61633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/ova.php"] [unique_id "amu1_-WE7BvPuUzLJ9-WlAAAAPA"]
[Thu Jul 30 15:37:19.328644 2026] [security2:error] [pid 189611:tid 189811] [client 20.226.5.174:2132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Cache.php"] [unique_id "amu1_-WE7BvPuUzLJ9-WmQAAAMs"]
[Thu Jul 30 15:37:19.354910 2026] [security2:error] [pid 189611:tid 189815] [client 191.232.199.39:8945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/admin.php"] [unique_id "amu1_-WE7BvPuUzLJ9-WmgAAAM8"]
[Thu Jul 30 15:37:19.609740 2026] [security2:error] [pid 189611:tid 189753] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/zxz.php"] [unique_id "amu1_-WE7BvPuUzLJ9-WnQAAAJE"]
[Thu Jul 30 15:37:19.609850 2026] [security2:error] [pid 189611:tid 189753] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/zxz.php"] [unique_id "amu1_-WE7BvPuUzLJ9-WnQAAAJE"]
[Thu Jul 30 15:37:20.032504 2026] [security2:error] [pid 189611:tid 189782] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/class-t.api.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WpwAAAK4"]
[Thu Jul 30 15:37:20.032619 2026] [security2:error] [pid 189611:tid 189782] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/class-t.api.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WpwAAAK4"]
[Thu Jul 30 15:37:20.096751 2026] [security2:error] [pid 189611:tid 189813] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/2.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WqQAAAM0"]
[Thu Jul 30 15:37:20.096846 2026] [security2:error] [pid 189611:tid 189813] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/2.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WqQAAAM0"]
[Thu Jul 30 15:37:20.135937 2026] [security2:error] [pid 189611:tid 189787] [client 20.203.148.31:60470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/robots.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WrQAAALM"]
[Thu Jul 30 15:37:20.224795 2026] [security2:error] [pid 189611:tid 189792] [client 20.226.5.174:2133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Cache/Cache.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WsQAAALg"]
[Thu Jul 30 15:37:20.580130 2026] [security2:error] [pid 189611:tid 189761] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/op.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WtwAAAJk"]
[Thu Jul 30 15:37:20.580247 2026] [security2:error] [pid 189611:tid 189761] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/op.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WtwAAAJk"]
[Thu Jul 30 15:37:20.626034 2026] [security2:error] [pid 189611:tid 189803] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/simple.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WuAAAAMM"]
[Thu Jul 30 15:37:20.626207 2026] [security2:error] [pid 189611:tid 189803] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/simple.php"] [unique_id "amu2AOWE7BvPuUzLJ9-WuAAAAMM"]
[Thu Jul 30 15:37:21.066607 2026] [security2:error] [pid 189611:tid 189805] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/a5.php"] [unique_id "amu2AeWE7BvPuUzLJ9-WxgAAAMU"]
[Thu Jul 30 15:37:21.066706 2026] [security2:error] [pid 189611:tid 189805] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/a5.php"] [unique_id "amu2AeWE7BvPuUzLJ9-WxgAAAMU"]
[Thu Jul 30 15:37:21.177882 2026] [security2:error] [pid 189611:tid 189742] [client 20.226.5.174:2113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Cache/about.php"] [unique_id "amu2AeWE7BvPuUzLJ9-WyQAAAIY"]
[Thu Jul 30 15:37:21.232554 2026] [security2:error] [pid 189611:tid 189863] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/ioxi-o.php"] [unique_id "amu2AeWE7BvPuUzLJ9-WywAAAP8"]
[Thu Jul 30 15:37:21.232641 2026] [security2:error] [pid 189611:tid 189863] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/ioxi-o.php"] [unique_id "amu2AeWE7BvPuUzLJ9-WywAAAP8"]
[Thu Jul 30 15:37:21.304617 2026] [core:notice] [pid 189611:tid 189802] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:21.359191 2026] [security2:error] [pid 189611:tid 189827] [client 51.77.210.64:47190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.210.77.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/modules/gsnippetsreviews/ws-gsnippetsreviews.php"] [unique_id "amu2AeWE7BvPuUzLJ9-W0wAAANs"]
[Thu Jul 30 15:37:21.444605 2026] [security2:error] [pid 189611:tid 189744] [client 20.91.199.21:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amu2AeWE7BvPuUzLJ9-W1AAAAIg"]
[Thu Jul 30 15:37:21.568678 2026] [security2:error] [pid 189611:tid 189762] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ws80.php"] [unique_id "amu2AeWE7BvPuUzLJ9-W1QAAAJo"]
[Thu Jul 30 15:37:21.568805 2026] [security2:error] [pid 189611:tid 189762] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ws80.php"] [unique_id "amu2AeWE7BvPuUzLJ9-W1QAAAJo"]
[Thu Jul 30 15:37:21.724869 2026] [security2:error] [pid 189611:tid 189766] [client 20.203.148.31:63456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/alf.php"] [unique_id "amu2AeWE7BvPuUzLJ9-W2gAAAJ4"]
[Thu Jul 30 15:37:21.787106 2026] [security2:error] [pid 189611:tid 189781] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.applinex.pro"] [uri "/wp-admin"] [unique_id "amu2AeWE7BvPuUzLJ9-W3QAAAK0"]
[Thu Jul 30 15:37:22.076455 2026] [security2:error] [pid 189611:tid 189782] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xa.php"] [unique_id "amu2AuWE7BvPuUzLJ9-W7AAAAK4"]
[Thu Jul 30 15:37:22.076553 2026] [security2:error] [pid 189611:tid 189782] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xa.php"] [unique_id "amu2AuWE7BvPuUzLJ9-W7AAAAK4"]
[Thu Jul 30 15:37:22.099239 2026] [security2:error] [pid 189611:tid 189822] [client 141.94.94.32:47252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.94.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/modules/gsnippetsreviews/ws-gsnippetsreviews.php"] [unique_id "amu2AeWE7BvPuUzLJ9-W4QAAANY"]
[Thu Jul 30 15:37:22.255876 2026] [security2:error] [pid 189611:tid 189818] [client 20.226.5.174:2138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Cache/dropdown.php"] [unique_id "amu2AuWE7BvPuUzLJ9-W8wAAANI"]
[Thu Jul 30 15:37:22.375454 2026] [proxy:error] [pid 189611:tid 189795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:22.375510 2026] [proxy_http:error] [pid 189611:tid 189795] [client 74.7.241.152:33198] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:22.376093 2026] [proxy:error] [pid 189611:tid 189795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:22.376139 2026] [proxy_http:error] [pid 189611:tid 189795] [client 74.7.241.152:33198] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:22.401393 2026] [security2:error] [pid 189611:tid 189861] [client 20.203.148.31:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/feedback.php"] [unique_id "amu2AuWE7BvPuUzLJ9-W_QAAAP0"]
[Thu Jul 30 15:37:22.403805 2026] [security2:error] [pid 189611:tid 189749] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.applinex.pro"] [uri "/wp-admin/index.php"] [unique_id "amu2AuWE7BvPuUzLJ9-W6wAAAI0"]
[Thu Jul 30 15:37:22.598859 2026] [security2:error] [pid 189611:tid 189807] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/asd67.php"] [unique_id "amu2AuWE7BvPuUzLJ9-XAQAAAMc"]
[Thu Jul 30 15:37:22.599028 2026] [security2:error] [pid 189611:tid 189807] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/asd67.php"] [unique_id "amu2AuWE7BvPuUzLJ9-XAQAAAMc"]
[Thu Jul 30 15:37:22.890393 2026] [core:notice] [pid 189611:tid 189623] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:23.111304 2026] [security2:error] [pid 189611:tid 189762] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/bk.php"] [unique_id "amu2A-WE7BvPuUzLJ9-XEAAAAJo"]
[Thu Jul 30 15:37:23.111435 2026] [security2:error] [pid 189611:tid 189762] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/bk.php"] [unique_id "amu2A-WE7BvPuUzLJ9-XEAAAAJo"]
[Thu Jul 30 15:37:23.396811 2026] [security2:error] [pid 189611:tid 189744] [client 20.226.5.174:2134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Cache/index.php"] [unique_id "amu2A-WE7BvPuUzLJ9-XGQAAAIg"]
[Thu Jul 30 15:37:23.496833 2026] [core:notice] [pid 189611:tid 189631] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:23.603309 2026] [security2:error] [pid 189611:tid 189858] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-links.php"] [unique_id "amu2A-WE7BvPuUzLJ9-XHgAAAPo"]
[Thu Jul 30 15:37:23.603432 2026] [security2:error] [pid 189611:tid 189858] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-links.php"] [unique_id "amu2A-WE7BvPuUzLJ9-XHgAAAPo"]
[Thu Jul 30 15:37:23.748378 2026] [core:notice] [pid 189611:tid 189841] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:23.837187 2026] [security2:error] [pid 189611:tid 189784] [client 191.232.199.39:61455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-configs.php"] [unique_id "amu2A-WE7BvPuUzLJ9-XJgAAALA"]
[Thu Jul 30 15:37:24.094108 2026] [security2:error] [pid 189611:tid 189851] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/mosty.php"] [unique_id "amu2BOWE7BvPuUzLJ9-XMAAAAPM"]
[Thu Jul 30 15:37:24.094413 2026] [security2:error] [pid 189611:tid 189851] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/mosty.php"] [unique_id "amu2BOWE7BvPuUzLJ9-XMAAAAPM"]
[Thu Jul 30 15:37:24.129378 2026] [security2:error] [pid 189611:tid 189833] [client 85.208.96.209:44012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/04/24/apos-licenca-joao-azevedo-reassume-governo-do-estado-neste-domingo-24/"] [unique_id "amu2BOWE7BvPuUzLJ9-XMQAAAOE"]
[Thu Jul 30 15:37:24.129545 2026] [security2:error] [pid 189611:tid 189833] [client 85.208.96.209:44012] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/04/24/apos-licenca-joao-azevedo-reassume-governo-do-estado-neste-domingo-24/"] [unique_id "amu2BOWE7BvPuUzLJ9-XMQAAAOE"]
[Thu Jul 30 15:37:24.405949 2026] [security2:error] [pid 189611:tid 189826] [client 20.226.5.174:2126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Cache/upfile.php"] [unique_id "amu2BOWE7BvPuUzLJ9-XNQAAANo"]
[Thu Jul 30 15:37:24.590946 2026] [security2:error] [pid 189611:tid 189819] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sump3.php"] [unique_id "amu2BOWE7BvPuUzLJ9-XPAAAANM"]
[Thu Jul 30 15:37:24.591082 2026] [security2:error] [pid 189611:tid 189819] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/sump3.php"] [unique_id "amu2BOWE7BvPuUzLJ9-XPAAAANM"]
[Thu Jul 30 15:37:25.012722 2026] [security2:error] [pid 189611:tid 189790] [client 191.232.199.39:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/php.php"] [unique_id "amu2BeWE7BvPuUzLJ9-XQQAAALY"]
[Thu Jul 30 15:37:25.074042 2026] [security2:error] [pid 189611:tid 189752] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/first.php"] [unique_id "amu2BeWE7BvPuUzLJ9-XRQAAAJA"]
[Thu Jul 30 15:37:25.074139 2026] [security2:error] [pid 189611:tid 189752] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/first.php"] [unique_id "amu2BeWE7BvPuUzLJ9-XRQAAAJA"]
[Thu Jul 30 15:37:25.574936 2026] [core:notice] [pid 189611:tid 189827] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:25.579214 2026] [security2:error] [pid 189611:tid 189854] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/acp.php"] [unique_id "amu2BeWE7BvPuUzLJ9-XUgAAAPY"]
[Thu Jul 30 15:37:25.579291 2026] [security2:error] [pid 189611:tid 189854] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/acp.php"] [unique_id "amu2BeWE7BvPuUzLJ9-XUgAAAPY"]
[Thu Jul 30 15:37:25.760326 2026] [security2:error] [pid 189611:tid 189765] [client 20.203.148.31:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/gettest.php"] [unique_id "amu2BeWE7BvPuUzLJ9-XVwAAAJ0"]
[Thu Jul 30 15:37:26.086135 2026] [security2:error] [pid 189611:tid 189858] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-good.php"] [unique_id "amu2BuWE7BvPuUzLJ9-XXwAAAPo"]
[Thu Jul 30 15:37:26.086247 2026] [security2:error] [pid 189611:tid 189858] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-good.php"] [unique_id "amu2BuWE7BvPuUzLJ9-XXwAAAPo"]
[Thu Jul 30 15:37:26.223489 2026] [security2:error] [pid 189611:tid 189842] [client 20.226.5.174:2153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Canonical.php"] [unique_id "amu2BuWE7BvPuUzLJ9-XYwAAAOo"]
[Thu Jul 30 15:37:26.248810 2026] [security2:error] [pid 189611:tid 189743] [client 191.232.199.39:8493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/index.php"] [unique_id "amu2BuWE7BvPuUzLJ9-XZAAAAIc"]
[Thu Jul 30 15:37:26.600069 2026] [security2:error] [pid 189611:tid 189867] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/daerl3.php"] [unique_id "amu2BuWE7BvPuUzLJ9-XbQAAAQM"]
[Thu Jul 30 15:37:26.600181 2026] [security2:error] [pid 189611:tid 189867] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/daerl3.php"] [unique_id "amu2BuWE7BvPuUzLJ9-XbQAAAQM"]
[Thu Jul 30 15:37:26.802256 2026] [security2:error] [pid 189611:tid 189771] [client 20.203.148.31:61637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/maint.php"] [unique_id "amu2BuWE7BvPuUzLJ9-XcQAAAKM"]
[Thu Jul 30 15:37:27.099210 2026] [security2:error] [pid 189611:tid 189794] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/php5.php"] [unique_id "amu2B-WE7BvPuUzLJ9-XegAAALo"]
[Thu Jul 30 15:37:27.099317 2026] [security2:error] [pid 189611:tid 189794] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/php5.php"] [unique_id "amu2B-WE7BvPuUzLJ9-XegAAALo"]
[Thu Jul 30 15:37:27.161300 2026] [security2:error] [pid 189611:tid 189857] [client 74.7.230.54:36496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.klg.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amu2B-WE7BvPuUzLJ9-XgQAAAPk"]
[Thu Jul 30 15:37:27.282311 2026] [security2:error] [pid 189611:tid 189861] [client 20.226.5.174:2129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Capi.php"] [unique_id "amu2B-WE7BvPuUzLJ9-XgwAAAP0"]
[Thu Jul 30 15:37:27.601740 2026] [security2:error] [pid 189611:tid 189753] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xoot.php"] [unique_id "amu2B-WE7BvPuUzLJ9-XiwAAAJE"]
[Thu Jul 30 15:37:27.601848 2026] [security2:error] [pid 189611:tid 189753] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/xoot.php"] [unique_id "amu2B-WE7BvPuUzLJ9-XiwAAAJE"]
[Thu Jul 30 15:37:27.825062 2026] [security2:error] [pid 189611:tid 189772] [client 191.232.199.39:9145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/a.php"] [unique_id "amu2B-WE7BvPuUzLJ9-XkgAAAKQ"]
[Thu Jul 30 15:37:28.108597 2026] [security2:error] [pid 189611:tid 189856] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/clxcc.php"] [unique_id "amu2COWE7BvPuUzLJ9-XmgAAAPg"]
[Thu Jul 30 15:37:28.108708 2026] [security2:error] [pid 189611:tid 189856] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/clxcc.php"] [unique_id "amu2COWE7BvPuUzLJ9-XmgAAAPg"]
[Thu Jul 30 15:37:28.296519 2026] [security2:error] [pid 189611:tid 189858] [client 20.91.199.21:1546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/banners/about.php"] [unique_id "amu2COWE7BvPuUzLJ9-XogAAAPo"]
[Thu Jul 30 15:37:28.402665 2026] [security2:error] [pid 189611:tid 189811] [client 20.203.148.31:61646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/files.php"] [unique_id "amu2COWE7BvPuUzLJ9-XpAAAAMs"]
[Thu Jul 30 15:37:28.482989 2026] [security2:error] [pid 189611:tid 189774] [client 20.226.5.174:2137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Content/Type/index.php"] [unique_id "amu2COWE7BvPuUzLJ9-XpQAAAKY"]
[Thu Jul 30 15:37:28.555462 2026] [security2:error] [pid 189611:tid 189842] [client 38.172.162.57:16535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2COWE7BvPuUzLJ9-XqAAAAOo"]
[Thu Jul 30 15:37:28.556172 2026] [security2:error] [pid 189611:tid 189842] [client 38.172.162.57:16535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2COWE7BvPuUzLJ9-XqAAAAOo"]
[Thu Jul 30 15:37:28.615991 2026] [security2:error] [pid 189611:tid 189828] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ai.php"] [unique_id "amu2COWE7BvPuUzLJ9-XrAAAANw"]
[Thu Jul 30 15:37:28.616081 2026] [security2:error] [pid 189611:tid 189828] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ai.php"] [unique_id "amu2COWE7BvPuUzLJ9-XrAAAANw"]
[Thu Jul 30 15:37:29.114272 2026] [security2:error] [pid 189611:tid 189805] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/nwflm.php"] [unique_id "amu2CeWE7BvPuUzLJ9-XtwAAAMU"]
[Thu Jul 30 15:37:29.114393 2026] [security2:error] [pid 189611:tid 189805] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/nwflm.php"] [unique_id "amu2CeWE7BvPuUzLJ9-XtwAAAMU"]
[Thu Jul 30 15:37:29.424130 2026] [security2:error] [pid 189611:tid 189857] [client 20.91.199.21:12537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/about.php"] [unique_id "amu2CeWE7BvPuUzLJ9-XvwAAAPk"]
[Thu Jul 30 15:37:29.612226 2026] [security2:error] [pid 189611:tid 189796] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/hypo.php"] [unique_id "amu2CeWE7BvPuUzLJ9-XwQAAALw"]
[Thu Jul 30 15:37:29.612348 2026] [security2:error] [pid 189611:tid 189796] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/hypo.php"] [unique_id "amu2CeWE7BvPuUzLJ9-XwQAAALw"]
[Thu Jul 30 15:37:29.619010 2026] [security2:error] [pid 189611:tid 189830] [client 20.203.148.31:59211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/gecko.php"] [unique_id "amu2CeWE7BvPuUzLJ9-XwwAAAN4"]
[Thu Jul 30 15:37:29.794766 2026] [security2:error] [pid 189611:tid 189843] [client 20.226.5.174:2114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Content/Type/wp-login.php"] [unique_id "amu2CeWE7BvPuUzLJ9-XwAAAAOs"]
[Thu Jul 30 15:37:30.102823 2026] [security2:error] [pid 189611:tid 189750] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/w3llscc.php"] [unique_id "amu2CuWE7BvPuUzLJ9-XzwAAAI4"]
[Thu Jul 30 15:37:30.102919 2026] [security2:error] [pid 189611:tid 189750] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/w3llscc.php"] [unique_id "amu2CuWE7BvPuUzLJ9-XzwAAAI4"]
[Thu Jul 30 15:37:30.216465 2026] [core:notice] [pid 189611:tid 189684] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:30.220010 2026] [security2:error] [pid 189611:tid 189813] [client 20.203.148.31:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/zwso.php"] [unique_id "amu2CuWE7BvPuUzLJ9-X1AAAAM0"]
[Thu Jul 30 15:37:30.474386 2026] [core:notice] [pid 189611:tid 189661] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:30.475811 2026] [security2:error] [pid 189611:tid 189825] [client 191.232.199.39:30007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amu2CuWE7BvPuUzLJ9-X3gAAANk"]
[Thu Jul 30 15:37:30.603128 2026] [security2:error] [pid 189611:tid 189811] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/11PJcpMFsD8B.php"] [unique_id "amu2CuWE7BvPuUzLJ9-X3wAAAMs"]
[Thu Jul 30 15:37:30.603239 2026] [security2:error] [pid 189611:tid 189811] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/11PJcpMFsD8B.php"] [unique_id "amu2CuWE7BvPuUzLJ9-X3wAAAMs"]
[Thu Jul 30 15:37:30.615174 2026] [security2:error] [pid 189611:tid 189743] [client 20.91.199.21:22426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/about.php"] [unique_id "amu2CuWE7BvPuUzLJ9-X4AAAAIc"]
[Thu Jul 30 15:37:30.903282 2026] [security2:error] [pid 189611:tid 189775] [client 20.226.5.174:2125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Content/index.php"] [unique_id "amu2CuWE7BvPuUzLJ9-X6wAAAKc"]
[Thu Jul 30 15:37:31.096570 2026] [security2:error] [pid 189611:tid 189785] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amu2C-WE7BvPuUzLJ9-X7QAAALE"]
[Thu Jul 30 15:37:31.096719 2026] [security2:error] [pid 189611:tid 189785] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amu2C-WE7BvPuUzLJ9-X7QAAALE"]
[Thu Jul 30 15:37:31.542987 2026] [security2:error] [pid 189611:tid 189824] [client 20.91.199.21:21872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amu2C-WE7BvPuUzLJ9-X_QAAANg"]
[Thu Jul 30 15:37:31.618796 2026] [security2:error] [pid 189611:tid 189760] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fnstall.php"] [unique_id "amu2C-WE7BvPuUzLJ9-X_gAAAJg"]
[Thu Jul 30 15:37:31.618915 2026] [security2:error] [pid 189611:tid 189760] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fnstall.php"] [unique_id "amu2C-WE7BvPuUzLJ9-X_gAAAJg"]
[Thu Jul 30 15:37:31.757747 2026] [security2:error] [pid 189611:tid 189846] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "mail.applinex.pro"] [uri "/wp-admin/index.php"] [unique_id "amu2C-WE7BvPuUzLJ9-X-AAA7jw"]
[Thu Jul 30 15:37:31.934115 2026] [security2:error] [pid 189611:tid 189788] [client 20.203.148.31:60483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/13.php"] [unique_id "amu2C-WE7BvPuUzLJ9-YBgAAALQ"]
[Thu Jul 30 15:37:32.007179 2026] [core:notice] [pid 189611:tid 189805] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:32.044663 2026] [security2:error] [pid 189611:tid 189755] [client 20.226.5.174:2124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Cookie/wp-login.php"] [unique_id "amu2DOWE7BvPuUzLJ9-YCwAAAJM"]
[Thu Jul 30 15:37:32.071706 2026] [security2:error] [pid 189611:tid 189847] [client 112.86.225.40:37382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/louis-vuitton-sneaker-white/"] [unique_id "amu2DOWE7BvPuUzLJ9-YDAAAAO8"]
[Thu Jul 30 15:37:32.071810 2026] [security2:error] [pid 189611:tid 189847] [client 112.86.225.40:37382] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/louis-vuitton-sneaker-white/"] [unique_id "amu2DOWE7BvPuUzLJ9-YDAAAAO8"]
[Thu Jul 30 15:37:32.147394 2026] [security2:error] [pid 189611:tid 189768] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/edorxrr.php"] [unique_id "amu2DOWE7BvPuUzLJ9-YEAAAAKA"]
[Thu Jul 30 15:37:32.147489 2026] [security2:error] [pid 189611:tid 189768] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/edorxrr.php"] [unique_id "amu2DOWE7BvPuUzLJ9-YEAAAAKA"]
[Thu Jul 30 15:37:32.501599 2026] [security2:error] [pid 189611:tid 189793] [client 191.232.199.39:30013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin.php"] [unique_id "amu2DOWE7BvPuUzLJ9-YFwAAALk"]
[Thu Jul 30 15:37:32.658261 2026] [security2:error] [pid 189611:tid 189767] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/setup.php"] [unique_id "amu2DOWE7BvPuUzLJ9-YHAAAAJ8"]
[Thu Jul 30 15:37:32.658387 2026] [security2:error] [pid 189611:tid 189767] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/setup.php"] [unique_id "amu2DOWE7BvPuUzLJ9-YHAAAAJ8"]
[Thu Jul 30 15:37:32.994804 2026] [security2:error] [pid 189611:tid 189827] [client 20.203.148.31:61221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/ava.php"] [unique_id "amu2DOWE7BvPuUzLJ9-YIwAAANs"]
[Thu Jul 30 15:37:33.083647 2026] [security2:error] [pid 189611:tid 189825] [client 20.226.5.174:2128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Core-Econ/index.php"] [unique_id "amu2DeWE7BvPuUzLJ9-YJwAAANk"]
[Thu Jul 30 15:37:33.170843 2026] [security2:error] [pid 189611:tid 189800] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/6.php"] [unique_id "amu2DeWE7BvPuUzLJ9-YKAAAAMA"]
[Thu Jul 30 15:37:33.170957 2026] [security2:error] [pid 189611:tid 189800] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/6.php"] [unique_id "amu2DeWE7BvPuUzLJ9-YKAAAAMA"]
[Thu Jul 30 15:37:33.657461 2026] [security2:error] [pid 189611:tid 189763] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/w3lls.php"] [unique_id "amu2DeWE7BvPuUzLJ9-YOAAAAJs"]
[Thu Jul 30 15:37:33.657568 2026] [security2:error] [pid 189611:tid 189763] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/w3lls.php"] [unique_id "amu2DeWE7BvPuUzLJ9-YOAAAAJs"]
[Thu Jul 30 15:37:33.774157 2026] [security2:error] [pid 189611:tid 189679] [remote 74.7.227.39:58828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com.yqe.gzj.temporary.site"] [uri "/"] [unique_id "amu2DeWE7BvPuUzLJ9-YOgAA5kM"], referer: https://thdinfinity.com.yqe.gzj.temporary.site/?path=/home1/yqegzjte/thdinfinity.com/wp-content/plugins/wp-defence
[Thu Jul 30 15:37:33.791551 2026] [security2:error] [pid 189611:tid 189752] [client 20.203.148.31:59225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/main.php"] [unique_id "amu2DeWE7BvPuUzLJ9-YOwAAAJA"]
[Thu Jul 30 15:37:33.959295 2026] [security2:error] [pid 189611:tid 189741] [client 191.232.199.39:8909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/size.php"] [unique_id "amu2DeWE7BvPuUzLJ9-YQQAAAIU"]
[Thu Jul 30 15:37:34.145926 2026] [security2:error] [pid 189611:tid 189806] [client 20.226.5.174:2112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Core-Econ/upH.php"] [unique_id "amu2DuWE7BvPuUzLJ9-YSwAAAMY"]
[Thu Jul 30 15:37:34.162022 2026] [security2:error] [pid 189611:tid 189847] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/99.php"] [unique_id "amu2DuWE7BvPuUzLJ9-YTAAAAO8"]
[Thu Jul 30 15:37:34.162121 2026] [security2:error] [pid 189611:tid 189847] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/99.php"] [unique_id "amu2DuWE7BvPuUzLJ9-YTAAAAO8"]
[Thu Jul 30 15:37:34.350053 2026] [security2:error] [pid 189611:tid 189751] [client 255.202.3.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amu2DeWE7BvPuUzLJ9-YLAAAjyY"], referer: https://flixon.net/video/you-me-and-tuscany-vj-junior/
[Thu Jul 30 15:37:34.441230 2026] [core:notice] [pid 189611:tid 189856] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:34.640929 2026] [security2:error] [pid 189611:tid 189864] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amu2DuWE7BvPuUzLJ9-YWQAAAQA"]
[Thu Jul 30 15:37:34.641046 2026] [security2:error] [pid 189611:tid 189864] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-content/admin.php"] [unique_id "amu2DuWE7BvPuUzLJ9-YWQAAAQA"]
[Thu Jul 30 15:37:35.120240 2026] [security2:error] [pid 189611:tid 189835] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/media.php"] [unique_id "amu2D-WE7BvPuUzLJ9-YZAAAAOM"]
[Thu Jul 30 15:37:35.120348 2026] [security2:error] [pid 189611:tid 189835] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/media.php"] [unique_id "amu2D-WE7BvPuUzLJ9-YZAAAAOM"]
[Thu Jul 30 15:37:35.177896 2026] [security2:error] [pid 189611:tid 189793] [client 191.232.199.39:8910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amu2D-WE7BvPuUzLJ9-YZwAAALk"]
[Thu Jul 30 15:37:35.209782 2026] [security2:error] [pid 189611:tid 189851] [client 20.226.5.174:2146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Core-EconX/up.php"] [unique_id "amu2D-WE7BvPuUzLJ9-YagAAAPM"]
[Thu Jul 30 15:37:35.617367 2026] [security2:error] [pid 189611:tid 189854] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amu2D-WE7BvPuUzLJ9-YdAAAAPY"]
[Thu Jul 30 15:37:35.617480 2026] [security2:error] [pid 189611:tid 189854] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-includes/blocks/audio/index.php"] [unique_id "amu2D-WE7BvPuUzLJ9-YdAAAAPY"]
[Thu Jul 30 15:37:35.681517 2026] [core:notice] [pid 189611:tid 189701] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:36.148058 2026] [security2:error] [pid 189611:tid 189805] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/222.php"] [unique_id "amu2EOWE7BvPuUzLJ9-YggAAAMU"]
[Thu Jul 30 15:37:36.148177 2026] [security2:error] [pid 189611:tid 189805] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/222.php"] [unique_id "amu2EOWE7BvPuUzLJ9-YggAAAMU"]
[Thu Jul 30 15:37:36.187300 2026] [security2:error] [pid 189611:tid 189807] [client 20.226.5.174:2150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/DJP9.php"] [unique_id "amu2EOWE7BvPuUzLJ9-YhgAAAMc"]
[Thu Jul 30 15:37:36.438789 2026] [security2:error] [pid 189611:tid 189821] [client 191.232.199.39:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/403.php"] [unique_id "amu2EOWE7BvPuUzLJ9-YiwAAANU"]
[Thu Jul 30 15:37:36.661788 2026] [security2:error] [pid 189611:tid 189864] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-load.php"] [unique_id "amu2EOWE7BvPuUzLJ9-YjwAAAQA"]
[Thu Jul 30 15:37:36.661896 2026] [security2:error] [pid 189611:tid 189864] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-load.php"] [unique_id "amu2EOWE7BvPuUzLJ9-YjwAAAQA"]
[Thu Jul 30 15:37:36.729253 2026] [security2:error] [pid 189611:tid 189723] [remote 110.249.201.220:29868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/abu-dhabi-desert-safari-4x4.html"] [unique_id "amu2EOWE7BvPuUzLJ9-YkgAA5W8"]
[Thu Jul 30 15:37:36.925284 2026] [core:notice] [pid 189611:tid 189865] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:37.106297 2026] [security2:error] [pid 189611:tid 189818] [client 20.226.5.174:2123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff.php"] [unique_id "amu2EeWE7BvPuUzLJ9-YmAAAANI"]
[Thu Jul 30 15:37:37.172300 2026] [security2:error] [pid 189611:tid 189764] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-content/themes/index.php"] [unique_id "amu2EeWE7BvPuUzLJ9-YnwAAAJw"]
[Thu Jul 30 15:37:37.172412 2026] [security2:error] [pid 189611:tid 189764] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-content/themes/index.php"] [unique_id "amu2EeWE7BvPuUzLJ9-YnwAAAJw"]
[Thu Jul 30 15:37:37.605757 2026] [security2:error] [pid 189611:tid 189748] [client 20.203.148.31:60520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/wp-file.php"] [unique_id "amu2EeWE7BvPuUzLJ9-YpwAAAIw"]
[Thu Jul 30 15:37:37.677676 2026] [security2:error] [pid 189611:tid 189861] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-admin/js/index.php"] [unique_id "amu2EeWE7BvPuUzLJ9-YqwAAAP0"]
[Thu Jul 30 15:37:37.677761 2026] [security2:error] [pid 189611:tid 189861] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-admin/js/index.php"] [unique_id "amu2EeWE7BvPuUzLJ9-YqwAAAP0"]
[Thu Jul 30 15:37:37.792953 2026] [core:notice] [pid 189611:tid 189616] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:37.819549 2026] [security2:error] [pid 189611:tid 189785] [client 191.232.199.39:9011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amu2EeWE7BvPuUzLJ9-YsQAAALE"]
[Thu Jul 30 15:37:37.970919 2026] [security2:error] [pid 189611:tid 189829] [client 20.91.199.21:1581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "amu2EeWE7BvPuUzLJ9-YswAAAN0"]
[Thu Jul 30 15:37:38.035292 2026] [security2:error] [pid 189611:tid 189760] [client 20.226.5.174:2127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Engine.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YtwAAAJg"]
[Thu Jul 30 15:37:38.098027 2026] [core:error] [pid 189611:tid 189733] (36)File name too long: [remote 48.44.107.25:42571] AH00036: access to /&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N/A&quot;,&quot;display_price&quot;:199,&quot;display_regular_price&quot;:199,&quot;image&quot;:{&quot;title&quot;:&quot;g-min-3.jpg&quot;,&quot;caption&quot;:&quot;&quot;,&quot;url&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/07/g-min-3.jpg&quot;,&quot;alt&quot;:&quot;g-min-3.jpg&quot;,&quot;src&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/07/g-min-3.jpg&quot;,&quot;srcset&quot;:&quot;https:/kicksity.com/wp-content/uploads/2023/07/g-min-3.jpg failed (filesystem path '/home1/vdbnyxte/public_html/website_3f9373c9/&gt;&quot;,&quot;sale_flash_html&quot;:&quot;&quot;},{&quot;attributes&quot;:{&quot;attribute_size&quot;:&quot;&quot;},&quot;availability_html&quot;:&quot;&quot;,&quot;backorders_allowed&quot;:false,&quot;dimensions&quot;:{&quot;length&quot;:&quot;&quot;,&quot;width&quot;:&quot;&quot;,&quot;height&quot;:&quot;&quot;},&quot;dimensions_html&quot;:&quot;N'), referer: https://kicksity.com/product/monolith-loafers-kpu-white-2/
[Thu Jul 30 15:37:38.154137 2026] [security2:error] [pid 189611:tid 189850] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/memberfuns.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YuQAAAPI"]
[Thu Jul 30 15:37:38.154241 2026] [security2:error] [pid 189611:tid 189850] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/memberfuns.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YuQAAAPI"]
[Thu Jul 30 15:37:38.269269 2026] [security2:error] [pid 189611:tid 189843] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YwAAAAOs"]
[Thu Jul 30 15:37:38.269390 2026] [security2:error] [pid 189611:tid 189843] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YwAAAAOs"]
[Thu Jul 30 15:37:38.640047 2026] [security2:error] [pid 189611:tid 189823] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/orange3.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YxwAAANc"]
[Thu Jul 30 15:37:38.640182 2026] [security2:error] [pid 189611:tid 189823] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/orange3.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YxwAAANc"]
[Thu Jul 30 15:37:38.801841 2026] [security2:error] [pid 189611:tid 189812] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/file2.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YzgAAAMw"]
[Thu Jul 30 15:37:38.801951 2026] [security2:error] [pid 189611:tid 189812] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/file2.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YzgAAAMw"]
[Thu Jul 30 15:37:38.871443 2026] [security2:error] [pid 189611:tid 189806] [client 57.141.0.10:39454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "igetvape-australia.com"] [uri "/index.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YwQAAxnU"], referer: https://igetvape-australia.com/product/alibarbar-rich-8000-puffs-2/
[Thu Jul 30 15:37:38.974015 2026] [security2:error] [pid 189611:tid 189750] [client 20.226.5.174:2135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Engine/about.php"] [unique_id "amu2EuWE7BvPuUzLJ9-YzwAAAI4"]
[Thu Jul 30 15:37:39.117281 2026] [security2:error] [pid 189611:tid 189751] [client 20.91.199.21:17343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/img/about.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y0wAAAI8"]
[Thu Jul 30 15:37:39.139373 2026] [security2:error] [pid 189611:tid 189851] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y1AAAAPM"]
[Thu Jul 30 15:37:39.139456 2026] [security2:error] [pid 189611:tid 189851] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y1AAAAPM"]
[Thu Jul 30 15:37:39.156252 2026] [security2:error] [pid 189611:tid 189756] [client 38.172.162.57:16257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y1QAAAJQ"]
[Thu Jul 30 15:37:39.156372 2026] [security2:error] [pid 189611:tid 189756] [client 38.172.162.57:16257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y1QAAAJQ"]
[Thu Jul 30 15:37:39.371050 2026] [security2:error] [pid 189611:tid 189855] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/images/class-config.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y3AAAAPc"]
[Thu Jul 30 15:37:39.371141 2026] [security2:error] [pid 189611:tid 189855] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/images/class-config.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y3AAAAPc"]
[Thu Jul 30 15:37:39.647289 2026] [security2:error] [pid 189611:tid 189832] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-the.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y4AAAAOA"]
[Thu Jul 30 15:37:39.647384 2026] [security2:error] [pid 189611:tid 189832] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/wp-the.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y4AAAAOA"]
[Thu Jul 30 15:37:39.890105 2026] [security2:error] [pid 189611:tid 189840] [client 20.226.5.174:2120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Engine/admin-ajax.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y5wAAAOg"]
[Thu Jul 30 15:37:39.997232 2026] [security2:error] [pid 189611:tid 189863] [client 20.9.4.9:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.applinex.pro"] [uri "/1.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y6AAAAP8"]
[Thu Jul 30 15:37:39.997357 2026] [security2:error] [pid 189611:tid 189863] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/1.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y6AAAAP8"]
[Thu Jul 30 15:37:39.997462 2026] [security2:error] [pid 189611:tid 189863] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/1.php"] [unique_id "amu2E-WE7BvPuUzLJ9-Y6AAAAP8"]
[Thu Jul 30 15:37:40.113564 2026] [security2:error] [pid 189611:tid 189802] [client 191.232.199.39:8943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/as.php"] [unique_id "amu2FOWE7BvPuUzLJ9-Y7QAAAMI"]
[Thu Jul 30 15:37:40.169865 2026] [security2:error] [pid 189611:tid 189829] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/crgio.php"] [unique_id "amu2FOWE7BvPuUzLJ9-Y7gAAAN0"]
[Thu Jul 30 15:37:40.169988 2026] [security2:error] [pid 189611:tid 189829] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/crgio.php"] [unique_id "amu2FOWE7BvPuUzLJ9-Y7gAAAN0"]
[Thu Jul 30 15:37:40.303364 2026] [security2:error] [pid 189611:tid 189866] [client 20.203.148.31:59252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/wp-signin.php"] [unique_id "amu2FOWE7BvPuUzLJ9-Y7wAAAQI"]
[Thu Jul 30 15:37:40.525555 2026] [security2:error] [pid 189611:tid 189744] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/222.php"] [unique_id "amu2FOWE7BvPuUzLJ9-Y9wAAAIg"]
[Thu Jul 30 15:37:40.525706 2026] [security2:error] [pid 189611:tid 189744] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/222.php"] [unique_id "amu2FOWE7BvPuUzLJ9-Y9wAAAIg"]
[Thu Jul 30 15:37:40.655763 2026] [security2:error] [pid 189611:tid 189789] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ws13.php"] [unique_id "amu2FOWE7BvPuUzLJ9-Y-wAAALU"]
[Thu Jul 30 15:37:40.655881 2026] [security2:error] [pid 189611:tid 189789] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ws13.php"] [unique_id "amu2FOWE7BvPuUzLJ9-Y-wAAALU"]
[Thu Jul 30 15:37:40.790577 2026] [security2:error] [pid 189611:tid 189842] [client 20.226.5.174:2158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Engine/com_search.php"] [unique_id "amu2FOWE7BvPuUzLJ9-Y_AAAAOo"]
[Thu Jul 30 15:37:41.040571 2026] [security2:error] [pid 189611:tid 189813] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/themes.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZAwAAAM0"]
[Thu Jul 30 15:37:41.040696 2026] [security2:error] [pid 189611:tid 189813] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/themes.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZAwAAAM0"]
[Thu Jul 30 15:37:41.133621 2026] [security2:error] [pid 189611:tid 189792] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/srontol.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZBwAAALg"]
[Thu Jul 30 15:37:41.133726 2026] [security2:error] [pid 189611:tid 189792] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/srontol.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZBwAAALg"]
[Thu Jul 30 15:37:41.392056 2026] [core:notice] [pid 189611:tid 189641] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:41.423925 2026] [security2:error] [pid 189611:tid 189784] [client 191.232.199.39:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZEAAAALA"]
[Thu Jul 30 15:37:41.496694 2026] [security2:error] [pid 189611:tid 189845] [client 20.91.199.21:17316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/languages/about.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZEQAAAO0"]
[Thu Jul 30 15:37:41.606678 2026] [security2:error] [pid 189611:tid 189793] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-content/admin.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZEgAAALk"]
[Thu Jul 30 15:37:41.606838 2026] [security2:error] [pid 189611:tid 189793] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-content/admin.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZEgAAALk"]
[Thu Jul 30 15:37:41.620646 2026] [security2:error] [pid 189611:tid 189858] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/miru3.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZEwAAAPo"]
[Thu Jul 30 15:37:41.620774 2026] [security2:error] [pid 189611:tid 189858] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/miru3.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZEwAAAPo"]
[Thu Jul 30 15:37:41.736227 2026] [security2:error] [pid 189611:tid 189750] [client 20.226.5.174:2166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Engine/doc.php"] [unique_id "amu2FeWE7BvPuUzLJ9-ZFwAAAI4"]
[Thu Jul 30 15:37:42.102261 2026] [security2:error] [pid 189611:tid 189854] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ingfo.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZIQAAAPY"]
[Thu Jul 30 15:37:42.102374 2026] [security2:error] [pid 189611:tid 189854] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ingfo.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZIQAAAPY"]
[Thu Jul 30 15:37:42.242611 2026] [security2:error] [pid 189611:tid 189825] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/dropdown.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZKAAAANk"]
[Thu Jul 30 15:37:42.242699 2026] [security2:error] [pid 189611:tid 189825] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/dropdown.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZKAAAANk"]
[Thu Jul 30 15:37:42.294236 2026] [security2:error] [pid 189611:tid 189799] [client 20.91.199.21:1422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/customize/about.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZKQAAAL8"]
[Thu Jul 30 15:37:42.615069 2026] [security2:error] [pid 189611:tid 189866] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ey5.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZMAAAAQI"]
[Thu Jul 30 15:37:42.615195 2026] [security2:error] [pid 189611:tid 189866] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/ey5.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZMAAAAQI"]
[Thu Jul 30 15:37:42.747352 2026] [security2:error] [pid 189611:tid 189840] [client 20.226.5.174:2131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Engine/index.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZNAAAAOg"]
[Thu Jul 30 15:37:42.801563 2026] [security2:error] [pid 189611:tid 189814] [client 20.203.148.31:60470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/simi.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZNQAAAM4"]
[Thu Jul 30 15:37:42.802831 2026] [security2:error] [pid 189611:tid 189838] [client 191.232.199.39:8961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZNgAAAOY"]
[Thu Jul 30 15:37:42.836524 2026] [security2:error] [pid 189611:tid 189745] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/inputs.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZNwAAAIk"]
[Thu Jul 30 15:37:42.836612 2026] [security2:error] [pid 189611:tid 189745] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/inputs.php"] [unique_id "amu2FuWE7BvPuUzLJ9-ZNwAAAIk"]
[Thu Jul 30 15:37:43.144291 2026] [security2:error] [pid 189611:tid 189778] [client 20.48.234.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.234.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fine.php"] [unique_id "amu2F-WE7BvPuUzLJ9-ZPwAAAKo"]
[Thu Jul 30 15:37:43.144381 2026] [security2:error] [pid 189611:tid 189778] [client 20.48.234.177:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.greecevisaassistanceislamabad.online"] [uri "/fine.php"] [unique_id "amu2F-WE7BvPuUzLJ9-ZPwAAAKo"]
[Thu Jul 30 15:37:43.399429 2026] [security2:error] [pid 189611:tid 189785] [client 20.203.148.31:64772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/wp-conf.php"] [unique_id "amu2F-WE7BvPuUzLJ9-ZQwAAALE"]
[Thu Jul 30 15:37:43.749008 2026] [security2:error] [pid 189611:tid 189864] [client 20.226.5.174:2155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Engine/priv.php"] [unique_id "amu2F-WE7BvPuUzLJ9-ZSgAAAQA"]
[Thu Jul 30 15:37:44.068720 2026] [security2:error] [pid 189611:tid 189865] [client 20.91.199.21:4203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "amu2GOWE7BvPuUzLJ9-ZVwAAAQE"]
[Thu Jul 30 15:37:44.444598 2026] [security2:error] [pid 189611:tid 189720] [remote 194.247.173.99:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/robots.txt"] [unique_id "amu2GOWE7BvPuUzLJ9-ZXwAA3Gw"]
[Thu Jul 30 15:37:44.444774 2026] [security2:error] [pid 189611:tid 189828] [client 194.247.173.99:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spececigarette.com"] [uri "/robots.txt"] [unique_id "amu2GOWE7BvPuUzLJ9-ZXwAA3Gw"]
[Thu Jul 30 15:37:44.572999 2026] [core:notice] [pid 189611:tid 189868] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:44.582029 2026] [security2:error] [pid 189611:tid 189777] [client 114.119.153.104:56895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jesus.claims"] [uri "/i-am-the-true-vine/i-am-the-true-vine-2/"] [unique_id "amu2GOWE7BvPuUzLJ9-ZZwAAAKk"], referer: https://www.jesus.claims/i-am-the-true-vine/i-am-the-true-vine-2
[Thu Jul 30 15:37:44.774331 2026] [security2:error] [pid 189611:tid 189797] [client 20.226.5.174:2147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Engine/wp-login.php"] [unique_id "amu2GOWE7BvPuUzLJ9-ZaAAAAL0"]
[Thu Jul 30 15:37:44.842944 2026] [security2:error] [pid 189611:tid 189809] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/100.php"] [unique_id "amu2GOWE7BvPuUzLJ9-ZbQAAAMk"]
[Thu Jul 30 15:37:44.843053 2026] [security2:error] [pid 189611:tid 189809] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/100.php"] [unique_id "amu2GOWE7BvPuUzLJ9-ZbQAAAMk"]
[Thu Jul 30 15:37:44.928525 2026] [security2:error] [pid 189611:tid 189646] [remote 57.141.0.13:50044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu2GOWE7BvPuUzLJ9-ZbgAAvCI"]
[Thu Jul 30 15:37:44.935200 2026] [security2:error] [pid 189611:tid 189749] [client 20.203.148.31:37666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/WZGHHra0r3.php"] [unique_id "amu2GOWE7BvPuUzLJ9-ZbwAAAI0"]
[Thu Jul 30 15:37:44.962892 2026] [proxy:error] [pid 189611:tid 189763] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:44.962962 2026] [proxy_http:error] [pid 189611:tid 189763] [client 104.233.59.30:3130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:44.963660 2026] [proxy:error] [pid 189611:tid 189763] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:44.963707 2026] [proxy_http:error] [pid 189611:tid 189763] [client 104.233.59.30:3130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:45.383759 2026] [security2:error] [pid 189611:tid 189771] [client 191.232.199.39:46222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/plugins.php"] [unique_id "amu2GeWE7BvPuUzLJ9-ZggAAAKM"]
[Thu Jul 30 15:37:45.405902 2026] [security2:error] [pid 189611:tid 189859] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/autoload_classmap/function.php"] [unique_id "amu2GeWE7BvPuUzLJ9-ZgwAAAPs"]
[Thu Jul 30 15:37:45.406007 2026] [security2:error] [pid 189611:tid 189859] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/autoload_classmap/function.php"] [unique_id "amu2GeWE7BvPuUzLJ9-ZgwAAAPs"]
[Thu Jul 30 15:37:45.718768 2026] [security2:error] [pid 189611:tid 189855] [client 20.226.5.174:2142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Renderer/about.php"] [unique_id "amu2GeWE7BvPuUzLJ9-ZjQAAAPc"]
[Thu Jul 30 15:37:45.968591 2026] [security2:error] [pid 189611:tid 189769] [client 57.141.0.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2GeWE7BvPuUzLJ9-ZgQAAAKE"]
[Thu Jul 30 15:37:45.980413 2026] [security2:error] [pid 189611:tid 189767] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/php.php"] [unique_id "amu2GeWE7BvPuUzLJ9-ZkQAAAJ8"]
[Thu Jul 30 15:37:45.980540 2026] [security2:error] [pid 189611:tid 189767] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/php.php"] [unique_id "amu2GeWE7BvPuUzLJ9-ZkQAAAJ8"]
[Thu Jul 30 15:37:46.438715 2026] [security2:error] [pid 189611:tid 189858] [client 20.203.148.31:36560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/bala.php"] [unique_id "amu2GuWE7BvPuUzLJ9-ZnwAAAPo"]
[Thu Jul 30 15:37:46.528686 2026] [security2:error] [pid 189611:tid 189677] [remote 194.247.173.99:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "spececigarette.com"] [uri "/product/duke-%E0%B8%94%E0%B8%B8%E0%B9%8A%E0%B8%81-%E0%B9%80%E0%B8%A1%E0%B8%99%E0%B8%97%E0%B8%AD%E0%B8%A5-%E0%B8%8B%E0%B8%AD%E0%B8%87%E0%B9%81%E0%B8%82%E0%B9%87%E0%B8%87/"] [unique_id "amu2GuWE7BvPuUzLJ9-ZoAAA2kE"]
[Thu Jul 30 15:37:46.528906 2026] [security2:error] [pid 189611:tid 189826] [client 194.247.173.99:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "spececigarette.com"] [uri "/product/duke-%E0%B8%94%E0%B8%B8%E0%B9%8A%E0%B8%81-%E0%B9%80%E0%B8%A1%E0%B8%99%E0%B8%97%E0%B8%AD%E0%B8%A5-%E0%B8%8B%E0%B8%AD%E0%B8%87%E0%B9%81%E0%B8%82%E0%B9%87%E0%B8%87/"] [unique_id "amu2GuWE7BvPuUzLJ9-ZoAAA2kE"]
[Thu Jul 30 15:37:46.536506 2026] [security2:error] [pid 189611:tid 189742] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/t.php"] [unique_id "amu2GuWE7BvPuUzLJ9-ZoQAAAIY"]
[Thu Jul 30 15:37:46.536645 2026] [security2:error] [pid 189611:tid 189742] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/t.php"] [unique_id "amu2GuWE7BvPuUzLJ9-ZoQAAAIY"]
[Thu Jul 30 15:37:46.686469 2026] [security2:error] [pid 189611:tid 189756] [client 191.232.199.39:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/js/index.php"] [unique_id "amu2GuWE7BvPuUzLJ9-ZqAAAAJQ"]
[Thu Jul 30 15:37:46.727078 2026] [security2:error] [pid 189611:tid 189852] [client 20.226.5.174:2141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Renderer/alfa-rex.php"] [unique_id "amu2GuWE7BvPuUzLJ9-ZqgAAAPQ"]
[Thu Jul 30 15:37:46.727128 2026] [security2:error] [pid 189611:tid 189666] [remote 57.141.0.34:54352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu2GuWE7BvPuUzLJ9-ZqQAAkjY"]
[Thu Jul 30 15:37:46.919972 2026] [security2:error] [pid 189611:tid 189750] [client 2a03:2880:f800:34:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2GuWE7BvPuUzLJ9-ZmAAAjko"]
[Thu Jul 30 15:37:47.109490 2026] [security2:error] [pid 189611:tid 189749] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-blink.php"] [unique_id "amu2G-WE7BvPuUzLJ9-ZsQAAAI0"]
[Thu Jul 30 15:37:47.109596 2026] [security2:error] [pid 189611:tid 189749] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-blink.php"] [unique_id "amu2G-WE7BvPuUzLJ9-ZsQAAAI0"]
[Thu Jul 30 15:37:47.419451 2026] [security2:error] [pid 189611:tid 189838] [client 20.203.148.31:36549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/bk.php"] [unique_id "amu2G-WE7BvPuUzLJ9-ZugAAAOY"]
[Thu Jul 30 15:37:47.693468 2026] [security2:error] [pid 189611:tid 189841] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/xfun.php"] [unique_id "amu2G-WE7BvPuUzLJ9-ZxAAAAOk"]
[Thu Jul 30 15:37:47.693571 2026] [security2:error] [pid 189611:tid 189841] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/xfun.php"] [unique_id "amu2G-WE7BvPuUzLJ9-ZxAAAAOk"]
[Thu Jul 30 15:37:47.724678 2026] [security2:error] [pid 189611:tid 189747] [client 20.226.5.174:2122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Renderer/index.php"] [unique_id "amu2G-WE7BvPuUzLJ9-ZxQAAAIs"]
[Thu Jul 30 15:37:48.272365 2026] [security2:error] [pid 189611:tid 189743] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/p.php"] [unique_id "amu2HOWE7BvPuUzLJ9-Z0AAAAIc"]
[Thu Jul 30 15:37:48.272481 2026] [security2:error] [pid 189611:tid 189743] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/p.php"] [unique_id "amu2HOWE7BvPuUzLJ9-Z0AAAAIc"]
[Thu Jul 30 15:37:48.610529 2026] [security2:error] [pid 189611:tid 189810] [client 191.232.199.39:46238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/go.php"] [unique_id "amu2HOWE7BvPuUzLJ9-Z1QAAAMo"]
[Thu Jul 30 15:37:48.631175 2026] [security2:error] [pid 189611:tid 189760] [client 74.7.175.169:54494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "clubnails.bonafideadvisors.com"] [uri "/index.php"] [unique_id "amu2G-WE7BvPuUzLJ9-ZuAAAmDM"]
[Thu Jul 30 15:37:48.682406 2026] [security2:error] [pid 189611:tid 189812] [client 20.226.5.174:2162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/Renderer/wp-login.php"] [unique_id "amu2HOWE7BvPuUzLJ9-Z2AAAAMw"]
[Thu Jul 30 15:37:48.797013 2026] [security2:error] [pid 189611:tid 189778] [client 20.203.148.31:37689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.148.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nordeste1.com"] [uri "/ahax.php"] [unique_id "amu2HOWE7BvPuUzLJ9-Z2wAAAKo"]
[Thu Jul 30 15:37:48.865601 2026] [security2:error] [pid 189611:tid 189806] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-content/themes/admin.php"] [unique_id "amu2HOWE7BvPuUzLJ9-Z3QAAAMY"]
[Thu Jul 30 15:37:48.865722 2026] [security2:error] [pid 189611:tid 189806] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-content/themes/admin.php"] [unique_id "amu2HOWE7BvPuUzLJ9-Z3QAAAMY"]
[Thu Jul 30 15:37:49.414870 2026] [security2:error] [pid 189611:tid 189756] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/aaa.php"] [unique_id "amu2HeWE7BvPuUzLJ9-Z6gAAAJQ"]
[Thu Jul 30 15:37:49.415001 2026] [security2:error] [pid 189611:tid 189756] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/aaa.php"] [unique_id "amu2HeWE7BvPuUzLJ9-Z6gAAAJQ"]
[Thu Jul 30 15:37:49.672880 2026] [security2:error] [pid 189611:tid 189832] [client 20.226.5.174:2169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alanturner.com.au"] [uri "/Diff/about.php"] [unique_id "amu2HeWE7BvPuUzLJ9-Z8gAAAOA"]
[Thu Jul 30 15:37:49.788583 2026] [security2:error] [pid 189611:tid 189777] [client 38.172.162.57:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2HeWE7BvPuUzLJ9-Z8wAAAKk"]
[Thu Jul 30 15:37:49.788714 2026] [security2:error] [pid 189611:tid 189777] [client 38.172.162.57:16175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2HeWE7BvPuUzLJ9-Z8wAAAKk"]
[Thu Jul 30 15:37:49.990049 2026] [security2:error] [pid 189611:tid 189828] [client 191.232.199.39:46225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/test1.php"] [unique_id "amu2HeWE7BvPuUzLJ9-Z-wAAANw"]
[Thu Jul 30 15:37:50.046221 2026] [security2:error] [pid 189611:tid 189822] [client 119.7.192.217:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu2HeWE7BvPuUzLJ9-Z9gAAANY"]
[Thu Jul 30 15:37:51.281223 2026] [security2:error] [pid 189611:tid 189861] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/7.php"] [unique_id "amu2H-WE7BvPuUzLJ9-aIAAAAP0"]
[Thu Jul 30 15:37:51.281357 2026] [security2:error] [pid 189611:tid 189861] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/7.php"] [unique_id "amu2H-WE7BvPuUzLJ9-aIAAAAP0"]
[Thu Jul 30 15:37:51.780320 2026] [security2:error] [pid 189611:tid 189830] [client 191.232.199.39:8721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/images/index.php"] [unique_id "amu2H-WE7BvPuUzLJ9-aKwAAAN4"]
[Thu Jul 30 15:37:52.132825 2026] [security2:error] [pid 189611:tid 189700] [remote 216.73.216.51:53831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu2IOWE7BvPuUzLJ9-aMAAA_lg"]
[Thu Jul 30 15:37:52.299468 2026] [security2:error] [pid 189611:tid 189828] [client 52.202.233.37:20011] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "hmhs.ph"] [uri "/"] [unique_id "amu2IOWE7BvPuUzLJ9-aNAAAANw"]
[Thu Jul 30 15:37:52.371842 2026] [security2:error] [pid 189611:tid 189753] [client 20.91.199.21:12015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/widgets/about.php"] [unique_id "amu2IOWE7BvPuUzLJ9-aOAAAAJE"]
[Thu Jul 30 15:37:53.313561 2026] [security2:error] [pid 189611:tid 189818] [client 191.232.199.39:8907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/asd.php"] [unique_id "amu2IeWE7BvPuUzLJ9-aSgAAANI"]
[Thu Jul 30 15:37:53.718193 2026] [security2:error] [pid 189611:tid 189761] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/file5.php"] [unique_id "amu2IeWE7BvPuUzLJ9-aUwAAAJk"]
[Thu Jul 30 15:37:53.718299 2026] [security2:error] [pid 189611:tid 189761] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/file5.php"] [unique_id "amu2IeWE7BvPuUzLJ9-aUwAAAJk"]
[Thu Jul 30 15:37:54.218046 2026] [security2:error] [pid 189611:tid 189800] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/makeasmtp.php"] [unique_id "amu2IuWE7BvPuUzLJ9-aXwAAAMA"]
[Thu Jul 30 15:37:54.218151 2026] [security2:error] [pid 189611:tid 189800] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/makeasmtp.php"] [unique_id "amu2IuWE7BvPuUzLJ9-aXwAAAMA"]
[Thu Jul 30 15:37:54.610111 2026] [security2:error] [pid 189611:tid 189776] [client 191.232.199.39:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amu2IuWE7BvPuUzLJ9-aaQAAAKg"]
[Thu Jul 30 15:37:54.677253 2026] [security2:error] [pid 189611:tid 189764] [client 20.91.199.21:8387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/IXR/about.php"] [unique_id "amu2IuWE7BvPuUzLJ9-aawAAAJw"]
[Thu Jul 30 15:37:54.720603 2026] [security2:error] [pid 189611:tid 189808] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-content/index.php"] [unique_id "amu2IuWE7BvPuUzLJ9-abwAAAMg"]
[Thu Jul 30 15:37:54.720736 2026] [security2:error] [pid 189611:tid 189808] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-content/index.php"] [unique_id "amu2IuWE7BvPuUzLJ9-abwAAAMg"]
[Thu Jul 30 15:37:55.229833 2026] [security2:error] [pid 189611:tid 189829] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/atomlib.php"] [unique_id "amu2I-WE7BvPuUzLJ9-adgAAAN0"]
[Thu Jul 30 15:37:55.229952 2026] [security2:error] [pid 189611:tid 189829] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/atomlib.php"] [unique_id "amu2I-WE7BvPuUzLJ9-adgAAAN0"]
[Thu Jul 30 15:37:55.344915 2026] [security2:error] [pid 189611:tid 189838] [client 20.91.199.21:9907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/js/about.php"] [unique_id "amu2I-WE7BvPuUzLJ9-aegAAAOY"]
[Thu Jul 30 15:37:55.426681 2026] [proxy:error] [pid 189611:tid 189625] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:55.426733 2026] [proxy_http:error] [pid 189611:tid 189625] [remote 74.7.175.134:57596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:55.427389 2026] [proxy:error] [pid 189611:tid 189625] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:37:55.427435 2026] [proxy_http:error] [pid 189611:tid 189625] [remote 74.7.175.134:57596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:37:55.792855 2026] [security2:error] [pid 189611:tid 189769] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/min.php"] [unique_id "amu2I-WE7BvPuUzLJ9-agwAAAKE"]
[Thu Jul 30 15:37:55.792961 2026] [security2:error] [pid 189611:tid 189769] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/min.php"] [unique_id "amu2I-WE7BvPuUzLJ9-agwAAAKE"]
[Thu Jul 30 15:37:55.834654 2026] [core:notice] [pid 189611:tid 189615] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:56.083121 2026] [security2:error] [pid 189611:tid 189788] [client 74.7.244.35:56206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "tgr-fiyan-co.nxt.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amu2JOWE7BvPuUzLJ9-ajwAAtBM"]
[Thu Jul 30 15:37:56.088130 2026] [security2:error] [pid 189611:tid 189840] [client 152.32.151.39:48480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims.wdr.gpl.temporary.site"] [uri "/index.php"] [unique_id "amu2I-WE7BvPuUzLJ9-ajgAAAOg"]
[Thu Jul 30 15:37:56.251853 2026] [security2:error] [pid 189611:tid 189768] [client 20.91.199.21:8389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "amu2JOWE7BvPuUzLJ9-akgAAAKA"]
[Thu Jul 30 15:37:56.365214 2026] [security2:error] [pid 189611:tid 189813] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/moon.php"] [unique_id "amu2JOWE7BvPuUzLJ9-algAAAM0"]
[Thu Jul 30 15:37:56.365332 2026] [security2:error] [pid 189611:tid 189813] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/moon.php"] [unique_id "amu2JOWE7BvPuUzLJ9-algAAAM0"]
[Thu Jul 30 15:37:56.714637 2026] [security2:error] [pid 189611:tid 189777] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu2JOWE7BvPuUzLJ9-aoQAAAKk"]
[Thu Jul 30 15:37:56.714748 2026] [security2:error] [pid 189611:tid 189777] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu2JOWE7BvPuUzLJ9-aoQAAAKk"]
[Thu Jul 30 15:37:56.881163 2026] [security2:error] [pid 189611:tid 189749] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/ws83.php"] [unique_id "amu2JOWE7BvPuUzLJ9-apQAAAI0"]
[Thu Jul 30 15:37:56.881277 2026] [security2:error] [pid 189611:tid 189749] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/ws83.php"] [unique_id "amu2JOWE7BvPuUzLJ9-apQAAAI0"]
[Thu Jul 30 15:37:56.964572 2026] [security2:error] [pid 189611:tid 189822] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu2JOWE7BvPuUzLJ9-aqQAAANY"]
[Thu Jul 30 15:37:56.964716 2026] [security2:error] [pid 189611:tid 189822] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu2JOWE7BvPuUzLJ9-aqQAAANY"]
[Thu Jul 30 15:37:57.013045 2026] [security2:error] [pid 189611:tid 189810] [client 191.232.199.39:46227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amu2JeWE7BvPuUzLJ9-arAAAAMo"]
[Thu Jul 30 15:37:57.033399 2026] [security2:error] [pid 189611:tid 189796] [client 20.91.199.21:41165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "amu2JeWE7BvPuUzLJ9-argAAALw"]
[Thu Jul 30 15:37:57.274870 2026] [security2:error] [pid 189611:tid 189747] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/images/pearl/index.php"] [unique_id "amu2JeWE7BvPuUzLJ9-asQAAAIs"]
[Thu Jul 30 15:37:57.275011 2026] [security2:error] [pid 189611:tid 189747] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/images/pearl/index.php"] [unique_id "amu2JeWE7BvPuUzLJ9-asQAAAIs"]
[Thu Jul 30 15:37:57.419261 2026] [security2:error] [pid 189611:tid 189860] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/403.php"] [unique_id "amu2JeWE7BvPuUzLJ9-atgAAAPw"]
[Thu Jul 30 15:37:57.419381 2026] [security2:error] [pid 189611:tid 189860] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/403.php"] [unique_id "amu2JeWE7BvPuUzLJ9-atgAAAPw"]
[Thu Jul 30 15:37:57.513177 2026] [security2:error] [pid 189611:tid 189626] [remote 57.141.0.55:63424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap13.xml"] [unique_id "amu2JeWE7BvPuUzLJ9-augAArw4"]
[Thu Jul 30 15:37:57.520068 2026] [security2:error] [pid 189611:tid 189837] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/bypass.php"] [unique_id "amu2JeWE7BvPuUzLJ9-auwAAAOU"]
[Thu Jul 30 15:37:57.520144 2026] [security2:error] [pid 189611:tid 189837] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/bypass.php"] [unique_id "amu2JeWE7BvPuUzLJ9-auwAAAOU"]
[Thu Jul 30 15:37:57.617075 2026] [core:notice] [pid 189611:tid 189638] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:37:57.620589 2026] [security2:error] [pid 189611:tid 189807] [client 66.249.74.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jipkl.com"] [uri "/index.php/JIPKL/article/view/81/84"] [unique_id "amu2JeWE7BvPuUzLJ9-atQAAxxo"]
[Thu Jul 30 15:37:57.758953 2026] [security2:error] [pid 189611:tid 189853] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wp-admin/about.php"] [unique_id "amu2JeWE7BvPuUzLJ9-avwAAAPU"]
[Thu Jul 30 15:37:57.759084 2026] [security2:error] [pid 189611:tid 189853] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wp-admin/about.php"] [unique_id "amu2JeWE7BvPuUzLJ9-avwAAAPU"]
[Thu Jul 30 15:37:57.776907 2026] [security2:error] [pid 189611:tid 189769] [client 20.91.199.21:4179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "amu2JeWE7BvPuUzLJ9-awAAAAKE"]
[Thu Jul 30 15:37:57.993871 2026] [security2:error] [pid 189611:tid 189789] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/api.php"] [unique_id "amu2JeWE7BvPuUzLJ9-aygAAALU"]
[Thu Jul 30 15:37:57.993966 2026] [security2:error] [pid 189611:tid 189789] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/api.php"] [unique_id "amu2JeWE7BvPuUzLJ9-aygAAALU"]
[Thu Jul 30 15:37:57.996879 2026] [security2:error] [pid 189611:tid 189861] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/12.php"] [unique_id "amu2JeWE7BvPuUzLJ9-aywAAAP0"]
[Thu Jul 30 15:37:57.996965 2026] [security2:error] [pid 189611:tid 189861] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/12.php"] [unique_id "amu2JeWE7BvPuUzLJ9-aywAAAP0"]
[Thu Jul 30 15:37:58.232465 2026] [security2:error] [pid 189611:tid 189826] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/nothing2.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a0QAAANo"]
[Thu Jul 30 15:37:58.232584 2026] [security2:error] [pid 189611:tid 189826] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/nothing2.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a0QAAANo"]
[Thu Jul 30 15:37:58.414294 2026] [security2:error] [pid 189611:tid 189775] [client 191.232.199.39:8716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/atomlib.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a1gAAAKc"]
[Thu Jul 30 15:37:58.484023 2026] [security2:error] [pid 189611:tid 189839] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/media.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a2gAAAOc"]
[Thu Jul 30 15:37:58.484135 2026] [security2:error] [pid 189611:tid 189839] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/media.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a2gAAAOc"]
[Thu Jul 30 15:37:58.535110 2026] [security2:error] [pid 189611:tid 189778] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/3.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a2wAAAKo"]
[Thu Jul 30 15:37:58.535199 2026] [security2:error] [pid 189611:tid 189778] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/3.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a2wAAAKo"]
[Thu Jul 30 15:37:58.611274 2026] [security2:error] [pid 189611:tid 189748] [client 20.91.199.21:1488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/updraft/about.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a3wAAAIw"]
[Thu Jul 30 15:37:58.719750 2026] [security2:error] [pid 189611:tid 189816] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/file2.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a4AAAANA"]
[Thu Jul 30 15:37:58.719862 2026] [security2:error] [pid 189611:tid 189816] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/file2.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a4AAAANA"]
[Thu Jul 30 15:37:58.963083 2026] [security2:error] [pid 189611:tid 189781] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/simple.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a5AAAAK0"]
[Thu Jul 30 15:37:58.963206 2026] [security2:error] [pid 189611:tid 189781] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/simple.php"] [unique_id "amu2JuWE7BvPuUzLJ9-a5AAAAK0"]
[Thu Jul 30 15:37:59.199954 2026] [security2:error] [pid 189611:tid 189821] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/mac.php"] [unique_id "amu2J-WE7BvPuUzLJ9-a7gAAANU"]
[Thu Jul 30 15:37:59.200072 2026] [security2:error] [pid 189611:tid 189821] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/mac.php"] [unique_id "amu2J-WE7BvPuUzLJ9-a7gAAANU"]
[Thu Jul 30 15:37:59.387609 2026] [security2:error] [pid 189611:tid 189859] [client 20.91.199.21:4205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "amu2J-WE7BvPuUzLJ9-a7wAAAPs"]
[Thu Jul 30 15:37:59.436161 2026] [security2:error] [pid 189611:tid 189843] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/install.php"] [unique_id "amu2J-WE7BvPuUzLJ9-a8AAAAOs"]
[Thu Jul 30 15:37:59.436261 2026] [security2:error] [pid 189611:tid 189843] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/install.php"] [unique_id "amu2J-WE7BvPuUzLJ9-a8AAAAOs"]
[Thu Jul 30 15:37:59.668483 2026] [security2:error] [pid 189611:tid 189818] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wsx.php"] [unique_id "amu2J-WE7BvPuUzLJ9-a-gAAANI"]
[Thu Jul 30 15:37:59.668590 2026] [security2:error] [pid 189611:tid 189818] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wsx.php"] [unique_id "amu2J-WE7BvPuUzLJ9-a-gAAANI"]
[Thu Jul 30 15:37:59.725355 2026] [security2:error] [pid 189611:tid 189750] [client 152.32.151.39:48496] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "jesus.claims.wdr.gpl.temporary.site"] [uri "/wp-content/plugins/fusion-builder/readme.txt"] [unique_id "amu2J-WE7BvPuUzLJ9-a-wAAAI4"]
[Thu Jul 30 15:37:59.731116 2026] [security2:error] [pid 189611:tid 189842] [client 20.226.5.174:20240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/storage/upload/alfa.php"] [unique_id "amu2J-WE7BvPuUzLJ9-a_AAAAOo"]
[Thu Jul 30 15:37:59.982177 2026] [security2:error] [pid 189611:tid 189864] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/alfa.php"] [unique_id "amu2J-WE7BvPuUzLJ9-bAQAAAQA"]
[Thu Jul 30 15:37:59.982278 2026] [security2:error] [pid 189611:tid 189864] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/alfa.php"] [unique_id "amu2J-WE7BvPuUzLJ9-bAQAAAQA"]
[Thu Jul 30 15:38:00.233407 2026] [security2:error] [pid 189611:tid 189792] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/dlu.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bDAAAALg"]
[Thu Jul 30 15:38:00.233497 2026] [security2:error] [pid 189611:tid 189792] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/dlu.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bDAAAALg"]
[Thu Jul 30 15:38:00.316249 2026] [security2:error] [pid 189611:tid 189853] [client 38.172.162.57:15942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bDgAAAPU"]
[Thu Jul 30 15:38:00.316360 2026] [security2:error] [pid 189611:tid 189853] [client 38.172.162.57:15942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bDgAAAPU"]
[Thu Jul 30 15:38:00.395460 2026] [security2:error] [pid 189611:tid 189789] [client 213.152.187.235:49040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bBgAAALU"]
[Thu Jul 30 15:38:00.395630 2026] [security2:error] [pid 189611:tid 189789] [client 213.152.187.235:49040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bBgAAALU"]
[Thu Jul 30 15:38:00.473940 2026] [security2:error] [pid 189611:tid 189756] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/f6.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bEgAAAJQ"]
[Thu Jul 30 15:38:00.474054 2026] [security2:error] [pid 189611:tid 189756] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/f6.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bEgAAAJQ"]
[Thu Jul 30 15:38:00.560203 2026] [security2:error] [pid 189611:tid 189827] [client 191.232.199.39:46131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bFQAAANs"]
[Thu Jul 30 15:38:00.665559 2026] [security2:error] [pid 189611:tid 189664] [remote 74.7.243.224:38468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/article.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bGQAA2jQ"], referer: https://aded-rdc.org/author/aded/uploads/partners/uploads/partners/uploads/partners/img/img/js/bootstrap.bundle.min.js
[Thu Jul 30 15:38:00.747325 2026] [security2:error] [pid 189611:tid 189775] [client 152.32.151.39:48510] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "jesus.claims.wdr.gpl.temporary.site"] [uri "/wp-content/plugins/*\\",\\"/readme.txt"] [unique_id "amu2KOWE7BvPuUzLJ9-bHgAAAKc"]
[Thu Jul 30 15:38:00.828918 2026] [security2:error] [pid 189611:tid 189802] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/0x.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bHwAAAMI"]
[Thu Jul 30 15:38:00.829059 2026] [security2:error] [pid 189611:tid 189802] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/0x.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bHwAAAMI"]
[Thu Jul 30 15:38:00.887963 2026] [security2:error] [pid 189611:tid 189839] [client 20.226.5.174:20237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/storage/upload/bypass.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bIAAAAOc"]
[Thu Jul 30 15:38:00.998374 2026] [security2:error] [pid 189611:tid 189867] [client 2a03:2880:f800:23:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2KOWE7BvPuUzLJ9-bDwABAz4"]
[Thu Jul 30 15:38:01.031293 2026] [security2:error] [pid 189611:tid 189794] [client 20.171.55.167:2466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/.env.sample.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bJAAAALo"]
[Thu Jul 30 15:38:01.081964 2026] [security2:error] [pid 189611:tid 189810] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/geck.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bJQAAAMo"]
[Thu Jul 30 15:38:01.082072 2026] [security2:error] [pid 189611:tid 189810] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/geck.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bJQAAAMo"]
[Thu Jul 30 15:38:01.324940 2026] [security2:error] [pid 189611:tid 189751] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/8.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bLAAAAI8"]
[Thu Jul 30 15:38:01.325050 2026] [security2:error] [pid 189611:tid 189751] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/8.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bLAAAAI8"]
[Thu Jul 30 15:38:01.358565 2026] [autoindex:error] [pid 189611:tid 189747] [client 20.9.4.9:0] AH01276: Cannot serve directory /home1/glbnyxte/public_html/website_ed9bceb3/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:38:01.359289 2026] [security2:error] [pid 189611:tid 189747] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.applinex.pro"] [uri "/cgi-sys/403.html"] [unique_id "amu2KeWE7BvPuUzLJ9-bLQAAAIs"]
[Thu Jul 30 15:38:01.609274 2026] [security2:error] [pid 189611:tid 189818] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/133.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bMwAAANI"]
[Thu Jul 30 15:38:01.609415 2026] [security2:error] [pid 189611:tid 189818] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/133.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bMwAAANI"]
[Thu Jul 30 15:38:01.714205 2026] [security2:error] [pid 189611:tid 189798] [client 152.32.151.39:48526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims.wdr.gpl.temporary.site"] [uri "/index.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bMgAAAL4"]
[Thu Jul 30 15:38:01.851871 2026] [security2:error] [pid 189611:tid 189783] [client 20.171.55.167:2462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/07.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bOwAAAK8"]
[Thu Jul 30 15:38:01.954025 2026] [security2:error] [pid 189611:tid 189823] [client 20.226.5.174:20244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/storage/upload/index.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bPAAAANc"]
[Thu Jul 30 15:38:01.983431 2026] [security2:error] [pid 189611:tid 189861] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/11.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bPQAAAP0"]
[Thu Jul 30 15:38:01.983532 2026] [security2:error] [pid 189611:tid 189861] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/11.php"] [unique_id "amu2KeWE7BvPuUzLJ9-bPQAAAP0"]
[Thu Jul 30 15:38:02.481582 2026] [security2:error] [pid 189611:tid 189797] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/3.php"] [unique_id "amu2KuWE7BvPuUzLJ9-bSQAAAL0"]
[Thu Jul 30 15:38:02.481688 2026] [security2:error] [pid 189611:tid 189797] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/3.php"] [unique_id "amu2KuWE7BvPuUzLJ9-bSQAAAL0"]
[Thu Jul 30 15:38:02.662873 2026] [security2:error] [pid 189611:tid 189836] [client 20.171.55.167:2439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/15.php"] [unique_id "amu2KuWE7BvPuUzLJ9-bTQAAAOQ"]
[Thu Jul 30 15:38:03.019627 2026] [security2:error] [pid 189611:tid 189839] [client 172.213.216.126:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bWAAAAOc"]
[Thu Jul 30 15:38:03.019741 2026] [security2:error] [pid 189611:tid 189839] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bWAAAAOc"]
[Thu Jul 30 15:38:03.019846 2026] [security2:error] [pid 189611:tid 189839] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/1.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bWAAAAOc"]
[Thu Jul 30 15:38:03.057798 2026] [security2:error] [pid 189611:tid 189758] [client 20.226.5.174:20241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/storage/upload/k.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bWgAAAJY"]
[Thu Jul 30 15:38:03.216601 2026] [security2:error] [pid 189611:tid 189753] [client 191.232.199.39:46250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/inputs.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bXQAAAJE"]
[Thu Jul 30 15:38:03.264332 2026] [security2:error] [pid 189611:tid 189810] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ouh.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bXgAAAMo"]
[Thu Jul 30 15:38:03.264453 2026] [security2:error] [pid 189611:tid 189810] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ouh.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bXgAAAMo"]
[Thu Jul 30 15:38:03.444827 2026] [security2:error] [pid 189611:tid 189828] [client 20.171.55.167:2459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/2021/file.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bZQAAANw"]
[Thu Jul 30 15:38:03.502586 2026] [security2:error] [pid 189611:tid 189805] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ioxi-o.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bZgAAAMU"]
[Thu Jul 30 15:38:03.502696 2026] [security2:error] [pid 189611:tid 189805] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ioxi-o.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bZgAAAMU"]
[Thu Jul 30 15:38:03.784225 2026] [security2:error] [pid 189611:tid 189743] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ar.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bagAAAIc"]
[Thu Jul 30 15:38:03.784347 2026] [security2:error] [pid 189611:tid 189743] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ar.php"] [unique_id "amu2K-WE7BvPuUzLJ9-bagAAAIc"]
[Thu Jul 30 15:38:03.892214 2026] [security2:error] [pid 189611:tid 189807] [client 139.28.219.70:57058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.adviseassociates.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amu2K-WE7BvPuUzLJ9-bcQAAAMc"]
[Thu Jul 30 15:38:04.025714 2026] [security2:error] [pid 189611:tid 189864] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/info.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bcgAAAQA"]
[Thu Jul 30 15:38:04.025842 2026] [security2:error] [pid 189611:tid 189864] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/info.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bcgAAAQA"]
[Thu Jul 30 15:38:04.093787 2026] [security2:error] [pid 189611:tid 189803] [client 20.226.5.174:20252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/storage/upload/wp.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bcwAAAMM"]
[Thu Jul 30 15:38:04.183425 2026] [security2:error] [pid 189611:tid 189793] [client 20.171.55.167:2446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/4.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bdwAAALk"]
[Thu Jul 30 15:38:04.292950 2026] [security2:error] [pid 189611:tid 189760] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/123.php"] [unique_id "amu2LOWE7BvPuUzLJ9-beAAAAJg"]
[Thu Jul 30 15:38:04.293071 2026] [security2:error] [pid 189611:tid 189760] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/123.php"] [unique_id "amu2LOWE7BvPuUzLJ9-beAAAAJg"]
[Thu Jul 30 15:38:04.355244 2026] [core:notice] [pid 189611:tid 189861] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:04.416733 2026] [security2:error] [pid 189611:tid 189769] [client 139.28.219.70:57070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.adviseassociates.com"] [uri "/xmlrpc.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bfgAAAKE"]
[Thu Jul 30 15:38:04.542040 2026] [security2:error] [pid 189611:tid 189759] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/33.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bgQAAAJc"]
[Thu Jul 30 15:38:04.542148 2026] [security2:error] [pid 189611:tid 189759] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/33.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bgQAAAJc"]
[Thu Jul 30 15:38:04.678945 2026] [security2:error] [pid 189611:tid 189662] [remote 57.141.0.15:31828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amu2LOWE7BvPuUzLJ9-bhQAA0zI"]
[Thu Jul 30 15:38:04.776863 2026] [security2:error] [pid 189611:tid 189825] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/bak.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bhgAAANk"]
[Thu Jul 30 15:38:04.777020 2026] [security2:error] [pid 189611:tid 189825] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/bak.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bhgAAANk"]
[Thu Jul 30 15:38:04.878631 2026] [core:notice] [pid 189611:tid 189868] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:04.960267 2026] [security2:error] [pid 189611:tid 189813] [client 191.232.199.39:46208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/index.php"] [unique_id "amu2LOWE7BvPuUzLJ9-bjwAAAM0"]
[Thu Jul 30 15:38:05.007994 2026] [security2:error] [pid 189611:tid 189806] [client 20.171.55.167:2444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/5index.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bkAAAAMY"]
[Thu Jul 30 15:38:05.016251 2026] [security2:error] [pid 189611:tid 189809] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/term.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bkQAAAMk"]
[Thu Jul 30 15:38:05.016360 2026] [security2:error] [pid 189611:tid 189809] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/term.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bkQAAAMk"]
[Thu Jul 30 15:38:05.100438 2026] [security2:error] [pid 189611:tid 189800] [client 20.226.5.174:20232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/str_replace.php"] [unique_id "amu2LeWE7BvPuUzLJ9-blQAAAMA"]
[Thu Jul 30 15:38:05.170208 2026] [security2:error] [pid 189611:tid 189702] [remote 57.141.0.14:54972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu2LeWE7BvPuUzLJ9-blgAA5Fo"]
[Thu Jul 30 15:38:05.255071 2026] [security2:error] [pid 189611:tid 189758] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/opts.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bmgAAAJY"]
[Thu Jul 30 15:38:05.255198 2026] [security2:error] [pid 189611:tid 189758] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/opts.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bmgAAAJY"]
[Thu Jul 30 15:38:05.261427 2026] [security2:error] [pid 189611:tid 189679] [remote 57.141.0.30:28964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/post-sitemap13.xml"] [unique_id "amu2LeWE7BvPuUzLJ9-bmwAAjEM"]
[Thu Jul 30 15:38:05.451583 2026] [core:notice] [pid 189611:tid 189714] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:05.508603 2026] [security2:error] [pid 189611:tid 189838] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wkl.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bowAAAOY"]
[Thu Jul 30 15:38:05.508703 2026] [security2:error] [pid 189611:tid 189838] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wkl.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bowAAAOY"]
[Thu Jul 30 15:38:05.746081 2026] [security2:error] [pid 189611:tid 189859] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/we.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bqAAAAPs"]
[Thu Jul 30 15:38:05.746176 2026] [security2:error] [pid 189611:tid 189859] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/we.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bqAAAAPs"]
[Thu Jul 30 15:38:05.879521 2026] [security2:error] [pid 189611:tid 189829] [client 20.171.55.167:2509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ALFA_DATAadmin.php"] [unique_id "amu2LeWE7BvPuUzLJ9-brQAAAN0"]
[Thu Jul 30 15:38:05.938866 2026] [security2:error] [pid 189611:tid 189805] [client 20.91.199.21:1568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/themes/about.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bsAAAAMU"]
[Thu Jul 30 15:38:05.985146 2026] [security2:error] [pid 189611:tid 189804] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/7.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bsgAAAMQ"]
[Thu Jul 30 15:38:05.985232 2026] [security2:error] [pid 189611:tid 189804] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/7.php"] [unique_id "amu2LeWE7BvPuUzLJ9-bsgAAAMQ"]
[Thu Jul 30 15:38:06.120235 2026] [security2:error] [pid 189611:tid 189751] [client 20.226.5.174:20238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/streams.php"] [unique_id "amu2LuWE7BvPuUzLJ9-btAAAAI8"]
[Thu Jul 30 15:38:06.203255 2026] [security2:error] [pid 189611:tid 189770] [client 213.152.187.235:38028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amu2LuWE7BvPuUzLJ9-btgAAAKI"]
[Thu Jul 30 15:38:06.203369 2026] [security2:error] [pid 189611:tid 189770] [client 213.152.187.235:38028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "montageluxuryhotel.com"] [uri "/xmlrpc.php"] [unique_id "amu2LuWE7BvPuUzLJ9-btgAAAKI"]
[Thu Jul 30 15:38:06.223064 2026] [security2:error] [pid 189611:tid 189750] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ls.php"] [unique_id "amu2LuWE7BvPuUzLJ9-btwAAAI4"]
[Thu Jul 30 15:38:06.223154 2026] [security2:error] [pid 189611:tid 189750] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ls.php"] [unique_id "amu2LuWE7BvPuUzLJ9-btwAAAI4"]
[Thu Jul 30 15:38:06.343467 2026] [security2:error] [pid 189611:tid 189757] [client 191.232.199.39:8987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/network/index.php"] [unique_id "amu2LuWE7BvPuUzLJ9-buwAAAJU"]
[Thu Jul 30 15:38:06.468847 2026] [core:error] [pid 189611:tid 189756] [client 66.249.73.130:64975] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:38:06.468869 2026] [core:error] [pid 189611:tid 189756] [client 66.249.73.130:64975] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:38:06.474412 2026] [security2:error] [pid 189611:tid 189825] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ant.php"] [unique_id "amu2LuWE7BvPuUzLJ9-bwwAAANk"]
[Thu Jul 30 15:38:06.474510 2026] [security2:error] [pid 189611:tid 189825] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ant.php"] [unique_id "amu2LuWE7BvPuUzLJ9-bwwAAANk"]
[Thu Jul 30 15:38:06.620499 2026] [security2:error] [pid 189611:tid 189797] [client 139.28.219.70:57072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.adviseassociates.com"] [uri "/xmlrpc.php"] [unique_id "amu2LuWE7BvPuUzLJ9-bxQAAAL0"]
[Thu Jul 30 15:38:06.620621 2026] [security2:error] [pid 189611:tid 189797] [client 139.28.219.70:57072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.adviseassociates.com"] [uri "/xmlrpc.php"] [unique_id "amu2LuWE7BvPuUzLJ9-bxQAAAL0"]
[Thu Jul 30 15:38:06.738958 2026] [security2:error] [pid 189611:tid 189811] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/155.php"] [unique_id "amu2LuWE7BvPuUzLJ9-bxgAAAMs"]
[Thu Jul 30 15:38:06.739073 2026] [security2:error] [pid 189611:tid 189811] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/155.php"] [unique_id "amu2LuWE7BvPuUzLJ9-bxgAAAMs"]
[Thu Jul 30 15:38:06.742423 2026] [security2:error] [pid 189611:tid 189789] [client 20.171.55.167:2441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/Content/Type/index.php"] [unique_id "amu2LuWE7BvPuUzLJ9-bxwAAALU"]
[Thu Jul 30 15:38:07.100466 2026] [security2:error] [pid 189611:tid 189826] [client 20.226.5.174:20236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sts.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b1AAAANo"]
[Thu Jul 30 15:38:07.124125 2026] [security2:error] [pid 189611:tid 189810] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/file9.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b1QAAAMo"]
[Thu Jul 30 15:38:07.124228 2026] [security2:error] [pid 189611:tid 189810] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/file9.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b1QAAAMo"]
[Thu Jul 30 15:38:07.162798 2026] [security2:error] [pid 189611:tid 189845] [client 139.28.219.70:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.adviseassociates.com"] [uri "/xmlrpc.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b1gAAAO0"]
[Thu Jul 30 15:38:07.162926 2026] [security2:error] [pid 189611:tid 189845] [client 139.28.219.70:57074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.adviseassociates.com"] [uri "/xmlrpc.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b1gAAAO0"]
[Thu Jul 30 15:38:07.345897 2026] [security2:error] [pid 189611:tid 189827] [client 20.91.199.21:41161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/includes/about.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b2gAAANs"]
[Thu Jul 30 15:38:07.383868 2026] [security2:error] [pid 189611:tid 189744] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/css.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b2wAAAIg"]
[Thu Jul 30 15:38:07.383991 2026] [security2:error] [pid 189611:tid 189744] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/css.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b2wAAAIg"]
[Thu Jul 30 15:38:07.469804 2026] [security2:error] [pid 189611:tid 189817] [client 20.171.55.167:2490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/Diff/Renderer/wp-login.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b3wAAANE"]
[Thu Jul 30 15:38:07.620141 2026] [security2:error] [pid 189611:tid 189784] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/js.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b5gAAALA"]
[Thu Jul 30 15:38:07.620277 2026] [security2:error] [pid 189611:tid 189784] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/js.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b5gAAALA"]
[Thu Jul 30 15:38:07.652737 2026] [security2:error] [pid 189611:tid 189831] [client 191.232.199.39:8966] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "pkfiraq.com"] [uri "/wp-content/1.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b5wAAAN8"]
[Thu Jul 30 15:38:07.652877 2026] [security2:error] [pid 189611:tid 189831] [client 191.232.199.39:8966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/1.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b5wAAAN8"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Thu Jul 30 15:38:07.928565 2026] [security2:error] [pid 189611:tid 189864] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/lock360.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b8QAAAQA"]
[Thu Jul 30 15:38:07.928678 2026] [security2:error] [pid 189611:tid 189864] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/lock360.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b8QAAAQA"]
[Thu Jul 30 15:38:08.034443 2026] [security2:error] [pid 189611:tid 189805] [client 20.226.5.174:20229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sty.php"] [unique_id "amu2MOWE7BvPuUzLJ9-b9QAAAMU"]
[Thu Jul 30 15:38:08.094655 2026] [security2:error] [pid 189611:tid 189753] [client 66.249.73.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mjsnailspa.com"] [uri "/index.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b0wAAAJE"]
[Thu Jul 30 15:38:08.167040 2026] [security2:error] [pid 189611:tid 189851] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/v.php"] [unique_id "amu2MOWE7BvPuUzLJ9-b-wAAAPM"]
[Thu Jul 30 15:38:08.167149 2026] [security2:error] [pid 189611:tid 189851] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/v.php"] [unique_id "amu2MOWE7BvPuUzLJ9-b-wAAAPM"]
[Thu Jul 30 15:38:08.298378 2026] [security2:error] [pid 189611:tid 189751] [client 20.171.55.167:2502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/HelloDollyV2/hello_dolly_v2.php"] [unique_id "amu2MOWE7BvPuUzLJ9-b_QAAAI8"]
[Thu Jul 30 15:38:08.315385 2026] [security2:error] [pid 189611:tid 189812] [client 57.141.0.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2L-WE7BvPuUzLJ9-b6wAAAMw"]
[Thu Jul 30 15:38:08.350553 2026] [security2:error] [pid 189611:tid 189824] [client 20.91.199.21:4184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/images/about.php"] [unique_id "amu2MOWE7BvPuUzLJ9-cAAAAANg"]
[Thu Jul 30 15:38:08.528299 2026] [security2:error] [pid 189611:tid 189819] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/pucci.php"] [unique_id "amu2MOWE7BvPuUzLJ9-cBQAAANM"]
[Thu Jul 30 15:38:08.528406 2026] [security2:error] [pid 189611:tid 189819] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/pucci.php"] [unique_id "amu2MOWE7BvPuUzLJ9-cBQAAANM"]
[Thu Jul 30 15:38:08.854123 2026] [security2:error] [pid 189611:tid 189756] [client 191.232.199.39:46074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/plugin.php"] [unique_id "amu2MOWE7BvPuUzLJ9-cDQAAAJQ"]
[Thu Jul 30 15:38:09.046121 2026] [security2:error] [pid 189611:tid 189749] [client 20.226.5.174:20245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/style-css.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cEwAAAI0"]
[Thu Jul 30 15:38:09.071696 2026] [security2:error] [pid 189611:tid 189808] [client 20.171.55.167:2506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/Mo0n.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cFgAAAMg"]
[Thu Jul 30 15:38:09.224753 2026] [security2:error] [pid 189611:tid 189845] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/file4.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cGwAAAO0"]
[Thu Jul 30 15:38:09.224850 2026] [security2:error] [pid 189611:tid 189845] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/file4.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cGwAAAO0"]
[Thu Jul 30 15:38:09.467083 2026] [security2:error] [pid 189611:tid 189846] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/222.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cIAAAAO4"]
[Thu Jul 30 15:38:09.467216 2026] [security2:error] [pid 189611:tid 189846] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/222.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cIAAAAO4"]
[Thu Jul 30 15:38:09.527902 2026] [security2:error] [pid 189611:tid 189854] [client 57.141.0.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2MOWE7BvPuUzLJ9-cEQAAAPY"]
[Thu Jul 30 15:38:09.668010 2026] [security2:error] [pid 189611:tid 189850] [client 20.91.199.21:16144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cKAAAAPI"]
[Thu Jul 30 15:38:09.708115 2026] [security2:error] [pid 189611:tid 189855] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/shellalfa.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cKQAAAPc"]
[Thu Jul 30 15:38:09.708209 2026] [security2:error] [pid 189611:tid 189855] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/shellalfa.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cKQAAAPc"]
[Thu Jul 30 15:38:09.954822 2026] [security2:error] [pid 189611:tid 189804] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/aaa.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cLgAAAMQ"]
[Thu Jul 30 15:38:09.954918 2026] [security2:error] [pid 189611:tid 189804] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/aaa.php"] [unique_id "amu2MeWE7BvPuUzLJ9-cLgAAAMQ"]
[Thu Jul 30 15:38:10.006866 2026] [security2:error] [pid 189611:tid 189771] [client 20.226.5.174:20239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/style.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cLwAAAKM"]
[Thu Jul 30 15:38:10.193330 2026] [security2:error] [pid 189611:tid 189805] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/abcd.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cNgAAAMU"]
[Thu Jul 30 15:38:10.193440 2026] [security2:error] [pid 189611:tid 189805] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/abcd.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cNgAAAMU"]
[Thu Jul 30 15:38:10.364267 2026] [security2:error] [pid 189611:tid 189772] [client 191.232.199.39:8587] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "pkfiraq.com"] [uri "/1.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cNwAAAKQ"]
[Thu Jul 30 15:38:10.364401 2026] [security2:error] [pid 189611:tid 189772] [client 191.232.199.39:8587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/1.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cNwAAAKQ"]
[Thu Jul 30 15:38:10.444112 2026] [security2:error] [pid 189611:tid 189781] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/about.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cOgAAAK0"]
[Thu Jul 30 15:38:10.444235 2026] [security2:error] [pid 189611:tid 189781] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/about.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cOgAAAK0"]
[Thu Jul 30 15:38:10.534491 2026] [core:notice] [pid 189611:tid 189733] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:10.681820 2026] [security2:error] [pid 189611:tid 189792] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wsd.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cRQAAALg"]
[Thu Jul 30 15:38:10.681925 2026] [security2:error] [pid 189611:tid 189792] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wsd.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cRQAAALg"]
[Thu Jul 30 15:38:10.894972 2026] [security2:error] [pid 189611:tid 189768] [client 38.172.162.57:16430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cRgAAAKA"]
[Thu Jul 30 15:38:10.895117 2026] [security2:error] [pid 189611:tid 189768] [client 38.172.162.57:16430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cRgAAAKA"]
[Thu Jul 30 15:38:10.924434 2026] [security2:error] [pid 189611:tid 189782] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ab.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cRwAAAK4"]
[Thu Jul 30 15:38:10.924534 2026] [security2:error] [pid 189611:tid 189782] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ab.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cRwAAAK4"]
[Thu Jul 30 15:38:10.958108 2026] [security2:error] [pid 189611:tid 189858] [client 20.226.5.174:20227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/style2.php"] [unique_id "amu2MuWE7BvPuUzLJ9-cSgAAAPo"]
[Thu Jul 30 15:38:11.006808 2026] [security2:error] [pid 189611:tid 189767] [client 20.91.199.21:9882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/images/about.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cTAAAAJ8"]
[Thu Jul 30 15:38:11.164050 2026] [security2:error] [pid 189611:tid 189776] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/gt.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cUQAAAKg"]
[Thu Jul 30 15:38:11.164164 2026] [security2:error] [pid 189611:tid 189776] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/gt.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cUQAAAKg"]
[Thu Jul 30 15:38:11.259732 2026] [core:notice] [pid 189611:tid 189729] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:11.406422 2026] [security2:error] [pid 189611:tid 189845] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/taff.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cVgAAAO0"]
[Thu Jul 30 15:38:11.406545 2026] [security2:error] [pid 189611:tid 189845] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/taff.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cVgAAAO0"]
[Thu Jul 30 15:38:11.583069 2026] [security2:error] [pid 189611:tid 189758] [client 191.232.199.39:46242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/gg.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cXQAAAJY"]
[Thu Jul 30 15:38:11.781482 2026] [security2:error] [pid 189611:tid 189747] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ee.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cYQAAAIs"]
[Thu Jul 30 15:38:11.781608 2026] [security2:error] [pid 189611:tid 189747] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/ee.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cYQAAAIs"]
[Thu Jul 30 15:38:11.932558 2026] [security2:error] [pid 189611:tid 189764] [client 20.171.55.167:2498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/RxR_qagvb.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cYgAAAJw"]
[Thu Jul 30 15:38:11.975968 2026] [security2:error] [pid 189611:tid 189766] [client 20.226.5.174:20247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/stylec.php"] [unique_id "amu2M-WE7BvPuUzLJ9-cYwAAAJ4"]
[Thu Jul 30 15:38:12.016722 2026] [security2:error] [pid 189611:tid 189821] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/max.php"] [unique_id "amu2NOWE7BvPuUzLJ9-cZgAAANU"]
[Thu Jul 30 15:38:12.016822 2026] [security2:error] [pid 189611:tid 189821] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/max.php"] [unique_id "amu2NOWE7BvPuUzLJ9-cZgAAANU"]
[Thu Jul 30 15:38:12.094091 2026] [security2:error] [pid 189611:tid 189865] [client 20.91.199.21:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/about.php"] [unique_id "amu2NOWE7BvPuUzLJ9-caAAAAQE"]
[Thu Jul 30 15:38:12.267349 2026] [security2:error] [pid 189611:tid 189798] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/aa.php"] [unique_id "amu2NOWE7BvPuUzLJ9-ccAAAAL4"]
[Thu Jul 30 15:38:12.267501 2026] [security2:error] [pid 189611:tid 189798] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/aa.php"] [unique_id "amu2NOWE7BvPuUzLJ9-ccAAAAL4"]
[Thu Jul 30 15:38:12.515066 2026] [security2:error] [pid 189611:tid 189848] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/system_log.php"] [unique_id "amu2NOWE7BvPuUzLJ9-ccgAAAPA"]
[Thu Jul 30 15:38:12.515191 2026] [security2:error] [pid 189611:tid 189848] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/system_log.php"] [unique_id "amu2NOWE7BvPuUzLJ9-ccgAAAPA"]
[Thu Jul 30 15:38:12.747276 2026] [security2:error] [pid 189611:tid 189851] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/201.php"] [unique_id "amu2NOWE7BvPuUzLJ9-cfAAAAPM"]
[Thu Jul 30 15:38:12.747405 2026] [security2:error] [pid 189611:tid 189851] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/201.php"] [unique_id "amu2NOWE7BvPuUzLJ9-cfAAAAPM"]
[Thu Jul 30 15:38:12.821691 2026] [security2:error] [pid 189611:tid 189840] [client 20.171.55.167:2445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/Transport/partners.php"] [unique_id "amu2NOWE7BvPuUzLJ9-cfgAAAOg"]
[Thu Jul 30 15:38:12.876170 2026] [security2:error] [pid 189611:tid 189842] [client 20.226.5.174:20262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/su.php"] [unique_id "amu2NOWE7BvPuUzLJ9-cfwAAAOo"]
[Thu Jul 30 15:38:13.002279 2026] [security2:error] [pid 189611:tid 189795] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/100.php"] [unique_id "amu2NeWE7BvPuUzLJ9-cgAAAALs"]
[Thu Jul 30 15:38:13.002402 2026] [security2:error] [pid 189611:tid 189795] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/100.php"] [unique_id "amu2NeWE7BvPuUzLJ9-cgAAAALs"]
[Thu Jul 30 15:38:13.345378 2026] [security2:error] [pid 189611:tid 189811] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wp-blink.php"] [unique_id "amu2NeWE7BvPuUzLJ9-ciwAAAMs"]
[Thu Jul 30 15:38:13.345492 2026] [security2:error] [pid 189611:tid 189811] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/wp-blink.php"] [unique_id "amu2NeWE7BvPuUzLJ9-ciwAAAMs"]
[Thu Jul 30 15:38:13.556025 2026] [security2:error] [pid 189611:tid 189858] [client 20.171.55.167:2464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/_adminer.php"] [unique_id "amu2NeWE7BvPuUzLJ9-cjAAAAPo"]
[Thu Jul 30 15:38:13.593744 2026] [security2:error] [pid 189611:tid 189806] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/images.php"] [unique_id "amu2NeWE7BvPuUzLJ9-ckAAAAMY"]
[Thu Jul 30 15:38:13.593848 2026] [security2:error] [pid 189611:tid 189806] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/images.php"] [unique_id "amu2NeWE7BvPuUzLJ9-ckAAAAMY"]
[Thu Jul 30 15:38:13.624210 2026] [core:notice] [pid 189611:tid 189775] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:13.652686 2026] [security2:error] [pid 189611:tid 189794] [client 191.232.199.39:48576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp.php"] [unique_id "amu2NeWE7BvPuUzLJ9-cmAAAALo"]
[Thu Jul 30 15:38:13.798939 2026] [security2:error] [pid 189611:tid 189809] [client 20.226.5.174:20276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/success.php"] [unique_id "amu2NeWE7BvPuUzLJ9-cnAAAAMk"]
[Thu Jul 30 15:38:13.886219 2026] [security2:error] [pid 189611:tid 189742] [client 20.91.199.21:7185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/cgi-bin/about.php"] [unique_id "amu2NeWE7BvPuUzLJ9-coAAAAIY"]
[Thu Jul 30 15:38:14.172946 2026] [security2:error] [pid 189611:tid 189799] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/fm.php"] [unique_id "amu2NuWE7BvPuUzLJ9-cpQAAAL8"]
[Thu Jul 30 15:38:14.173111 2026] [security2:error] [pid 189611:tid 189799] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/fm.php"] [unique_id "amu2NuWE7BvPuUzLJ9-cpQAAAL8"]
[Thu Jul 30 15:38:14.328441 2026] [security2:error] [pid 189611:tid 189766] [client 20.171.55.167:2460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/access.php"] [unique_id "amu2NuWE7BvPuUzLJ9-cqQAAAJ4"]
[Thu Jul 30 15:38:14.534382 2026] [security2:error] [pid 189611:tid 189785] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/rrr.php"] [unique_id "amu2NuWE7BvPuUzLJ9-crgAAALE"]
[Thu Jul 30 15:38:14.534518 2026] [security2:error] [pid 189611:tid 189785] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/rrr.php"] [unique_id "amu2NuWE7BvPuUzLJ9-crgAAALE"]
[Thu Jul 30 15:38:14.758462 2026] [security2:error] [pid 189611:tid 189773] [client 20.226.5.174:20269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sunda.php"] [unique_id "amu2NuWE7BvPuUzLJ9-ctQAAAKU"]
[Thu Jul 30 15:38:14.770375 2026] [security2:error] [pid 189611:tid 189779] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/mail.php"] [unique_id "amu2NuWE7BvPuUzLJ9-ctgAAAKs"]
[Thu Jul 30 15:38:14.770456 2026] [security2:error] [pid 189611:tid 189779] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/mail.php"] [unique_id "amu2NuWE7BvPuUzLJ9-ctgAAAKs"]
[Thu Jul 30 15:38:14.889837 2026] [security2:error] [pid 189611:tid 189769] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/ws77.php"] [unique_id "amu2NuWE7BvPuUzLJ9-cugAAAKE"]
[Thu Jul 30 15:38:14.889984 2026] [security2:error] [pid 189611:tid 189769] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/ws77.php"] [unique_id "amu2NuWE7BvPuUzLJ9-cugAAAKE"]
[Thu Jul 30 15:38:14.903124 2026] [security2:error] [pid 189611:tid 189772] [client 223.109.252.247:38052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/af-1-07-lv8-utility-white-3/"] [unique_id "amu2NuWE7BvPuUzLJ9-cuwAAAKQ"]
[Thu Jul 30 15:38:14.903223 2026] [security2:error] [pid 189611:tid 189772] [client 223.109.252.247:38052] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kicksity.com"] [uri "/product/af-1-07-lv8-utility-white-3/"] [unique_id "amu2NuWE7BvPuUzLJ9-cuwAAAKQ"]
[Thu Jul 30 15:38:15.009850 2026] [security2:error] [pid 189611:tid 189751] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/chosen.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cvAAAAI8"]
[Thu Jul 30 15:38:15.009959 2026] [security2:error] [pid 189611:tid 189751] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/chosen.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cvAAAAI8"]
[Thu Jul 30 15:38:15.065012 2026] [security2:error] [pid 189611:tid 189640] [remote 57.141.0.29:59144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu2N-WE7BvPuUzLJ9-cvQAAkxw"]
[Thu Jul 30 15:38:15.156884 2026] [security2:error] [pid 189611:tid 189820] [client 20.171.55.167:2454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/admin-header.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cvwAAANQ"]
[Thu Jul 30 15:38:15.260798 2026] [security2:error] [pid 189611:tid 189757] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/doti.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cwAAAAJU"]
[Thu Jul 30 15:38:15.260914 2026] [security2:error] [pid 189611:tid 189757] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/doti.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cwAAAAJU"]
[Thu Jul 30 15:38:15.367115 2026] [security2:error] [pid 189611:tid 189842] [client 20.215.191.139:39094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.tmb/LA.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cwQAAAOo"]
[Thu Jul 30 15:38:15.390040 2026] [security2:error] [pid 189611:tid 189857] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/nc4.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cwgAAAPk"]
[Thu Jul 30 15:38:15.390129 2026] [security2:error] [pid 189611:tid 189857] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/nc4.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cwgAAAPk"]
[Thu Jul 30 15:38:15.458887 2026] [security2:error] [pid 189611:tid 189812] [client 191.232.199.39:46568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cwwAAAMw"]
[Thu Jul 30 15:38:15.500759 2026] [security2:error] [pid 189611:tid 189782] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/x0.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cxAAAAK4"]
[Thu Jul 30 15:38:15.500853 2026] [security2:error] [pid 189611:tid 189782] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/x0.php"] [unique_id "amu2N-WE7BvPuUzLJ9-cxAAAAK4"]
[Thu Jul 30 15:38:15.700846 2026] [security2:error] [pid 189611:tid 189863] [client 20.226.5.174:20260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sup.php"] [unique_id "amu2N-WE7BvPuUzLJ9-czgAAAP8"]
[Thu Jul 30 15:38:15.876718 2026] [security2:error] [pid 189611:tid 189816] [client 20.171.55.167:2480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/adminwebadmin.php"] [unique_id "amu2N-WE7BvPuUzLJ9-c0gAAANA"]
[Thu Jul 30 15:38:15.892117 2026] [security2:error] [pid 189611:tid 189845] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/bless.php"] [unique_id "amu2N-WE7BvPuUzLJ9-c0wAAAO0"]
[Thu Jul 30 15:38:15.892201 2026] [security2:error] [pid 189611:tid 189845] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/bless.php"] [unique_id "amu2N-WE7BvPuUzLJ9-c0wAAAO0"]
[Thu Jul 30 15:38:15.918410 2026] [security2:error] [pid 189611:tid 189786] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/as.php"] [unique_id "amu2N-WE7BvPuUzLJ9-c1AAAALI"]
[Thu Jul 30 15:38:15.918495 2026] [security2:error] [pid 189611:tid 189786] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/as.php"] [unique_id "amu2N-WE7BvPuUzLJ9-c1AAAALI"]
[Thu Jul 30 15:38:15.991532 2026] [security2:error] [pid 189611:tid 189822] [client 20.215.191.139:39068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.tmb/admin.php"] [unique_id "amu2N-WE7BvPuUzLJ9-c1QAAANY"]
[Thu Jul 30 15:38:16.144393 2026] [security2:error] [pid 189611:tid 189754] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/cgi-bin/index.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c2QAAAJI"]
[Thu Jul 30 15:38:16.144527 2026] [security2:error] [pid 189611:tid 189754] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/cgi-bin/index.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c2QAAAJI"]
[Thu Jul 30 15:38:16.382197 2026] [security2:error] [pid 189611:tid 189798] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/size.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c4QAAAL4"]
[Thu Jul 30 15:38:16.382363 2026] [security2:error] [pid 189611:tid 189798] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/size.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c4QAAAL4"]
[Thu Jul 30 15:38:16.495235 2026] [security2:error] [pid 189611:tid 189746] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/k.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c4gAAAIo"]
[Thu Jul 30 15:38:16.495361 2026] [security2:error] [pid 189611:tid 189746] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/k.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c4gAAAIo"]
[Thu Jul 30 15:38:16.636563 2026] [security2:error] [pid 189611:tid 189779] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/lala.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c6AAAAKs"]
[Thu Jul 30 15:38:16.636658 2026] [security2:error] [pid 189611:tid 189779] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/lala.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c6AAAAKs"]
[Thu Jul 30 15:38:16.642337 2026] [security2:error] [pid 189611:tid 189766] [client 20.171.55.167:2443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/aks.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c6gAAAJ4"]
[Thu Jul 30 15:38:16.645087 2026] [security2:error] [pid 189611:tid 189784] [client 20.226.5.174:20273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sure.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c6wAAALA"]
[Thu Jul 30 15:38:16.955894 2026] [security2:error] [pid 189611:tid 189833] [client 172.213.216.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.216.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bensecuritylocksmith.site"] [uri "/file1.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c9gAAAOE"]
[Thu Jul 30 15:38:16.956009 2026] [security2:error] [pid 189611:tid 189833] [client 172.213.216.126:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.bensecuritylocksmith.site"] [uri "/file1.php"] [unique_id "amu2OOWE7BvPuUzLJ9-c9gAAAOE"]
[Thu Jul 30 15:38:17.027853 2026] [security2:error] [pid 189611:tid 189796] [client 20.91.199.21:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/gallery/about.php"] [unique_id "amu2OeWE7BvPuUzLJ9-c9wAAALw"]
[Thu Jul 30 15:38:17.095033 2026] [security2:error] [pid 189611:tid 189819] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/system_log.php"] [unique_id "amu2OeWE7BvPuUzLJ9-c-AAAANM"]
[Thu Jul 30 15:38:17.095131 2026] [security2:error] [pid 189611:tid 189819] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/system_log.php"] [unique_id "amu2OeWE7BvPuUzLJ9-c-AAAANM"]
[Thu Jul 30 15:38:17.351659 2026] [security2:error] [pid 189611:tid 189868] [client 20.171.55.167:2491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/alfacgiapi/perl.alfa.php"] [unique_id "amu2OeWE7BvPuUzLJ9-dAwAAAQQ"]
[Thu Jul 30 15:38:17.403860 2026] [security2:error] [pid 189611:tid 189864] [client 191.232.199.39:8710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/file.php"] [unique_id "amu2OeWE7BvPuUzLJ9-dBAAAAQA"]
[Thu Jul 30 15:38:17.600164 2026] [security2:error] [pid 189611:tid 189777] [client 20.226.5.174:20226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/swm.php"] [unique_id "amu2OeWE7BvPuUzLJ9-dBwAAAKk"]
[Thu Jul 30 15:38:17.633743 2026] [security2:error] [pid 189611:tid 189791] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/x.php"] [unique_id "amu2OeWE7BvPuUzLJ9-dCAAAALc"]
[Thu Jul 30 15:38:17.633861 2026] [security2:error] [pid 189611:tid 189791] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/x.php"] [unique_id "amu2OeWE7BvPuUzLJ9-dCAAAALc"]
[Thu Jul 30 15:38:18.070964 2026] [security2:error] [pid 189611:tid 189790] [client 77.110.100.216:39212] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "agr8story.site"] [uri "/wp-comments-post.php"] [unique_id "amu2OeWE7BvPuUzLJ9-dBgAAALY"]
[Thu Jul 30 15:38:18.130329 2026] [security2:error] [pid 189611:tid 189809] [client 20.171.55.167:2525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/alivos.php"] [unique_id "amu2OuWE7BvPuUzLJ9-dFwAAAMk"]
[Thu Jul 30 15:38:18.176813 2026] [security2:error] [pid 189611:tid 189828] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/autoload_classmap.php"] [unique_id "amu2OuWE7BvPuUzLJ9-dGAAAANw"]
[Thu Jul 30 15:38:18.176933 2026] [security2:error] [pid 189611:tid 189828] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/autoload_classmap.php"] [unique_id "amu2OuWE7BvPuUzLJ9-dGAAAANw"]
[Thu Jul 30 15:38:18.187249 2026] [security2:error] [pid 189611:tid 189790] [client 77.110.100.216:39212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "agr8story.site"] [uri "/wp-comments-post.php"] [unique_id "amu2OeWE7BvPuUzLJ9-dBgAAALY"]
[Thu Jul 30 15:38:18.265189 2026] [security2:error] [pid 189611:tid 189842] [client 20.215.191.139:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.tmb/class_api.php"] [unique_id "amu2OuWE7BvPuUzLJ9-dGwAAAOo"]
[Thu Jul 30 15:38:18.543449 2026] [security2:error] [pid 189611:tid 189829] [client 20.226.5.174:20231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sx.php"] [unique_id "amu2OuWE7BvPuUzLJ9-dJAAAAN0"]
[Thu Jul 30 15:38:18.731162 2026] [core:notice] [pid 189611:tid 189749] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:18.869830 2026] [security2:error] [pid 189611:tid 189688] [remote 172.93.219.170:44412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.219.93.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.lxw.gpl.temporary.site"] [uri "/wp-login.php"] [unique_id "amu2OuWE7BvPuUzLJ9-dKwAA1Ew"]
[Thu Jul 30 15:38:18.987923 2026] [security2:error] [pid 189611:tid 189844] [client 20.215.191.139:55167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.tmb/cpabpkyk.php"] [unique_id "amu2OuWE7BvPuUzLJ9-dLwAAAOw"]
[Thu Jul 30 15:38:19.015007 2026] [security2:error] [pid 189611:tid 189783] [client 20.171.55.167:2500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/antiheker.php"] [unique_id "amu2O-WE7BvPuUzLJ9-dMAAAAK8"]
[Thu Jul 30 15:38:19.204107 2026] [core:notice] [pid 189611:tid 189674] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:19.424690 2026] [core:notice] [pid 189611:tid 189677] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:19.497193 2026] [security2:error] [pid 189611:tid 189833] [client 20.226.5.174:20235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sx21_1.php"] [unique_id "amu2O-WE7BvPuUzLJ9-dPQAAAOE"]
[Thu Jul 30 15:38:19.539750 2026] [security2:error] [pid 189611:tid 189847] [client 191.232.199.39:46552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/user/index.php"] [unique_id "amu2O-WE7BvPuUzLJ9-dPgAAAO8"]
[Thu Jul 30 15:38:19.773826 2026] [security2:error] [pid 189611:tid 189776] [client 20.91.199.21:1504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amu2O-WE7BvPuUzLJ9-dQAAAAKg"]
[Thu Jul 30 15:38:19.783370 2026] [security2:error] [pid 189611:tid 189759] [client 20.171.55.167:2519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ar.php"] [unique_id "amu2O-WE7BvPuUzLJ9-dQQAAAJc"]
[Thu Jul 30 15:38:19.814066 2026] [security2:error] [pid 189611:tid 189779] [client 2a03:2880:f800:8:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2O-WE7BvPuUzLJ9-dMgAAqzs"]
[Thu Jul 30 15:38:19.882399 2026] [security2:error] [pid 189611:tid 189789] [client 20.215.191.139:40964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.tmb/wp-login.php"] [unique_id "amu2O-WE7BvPuUzLJ9-dPwAAALU"]
[Thu Jul 30 15:38:20.302609 2026] [core:notice] [pid 189611:tid 189689] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:20.304837 2026] [core:notice] [pid 189611:tid 189669] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:20.434286 2026] [security2:error] [pid 189611:tid 189827] [client 20.226.5.174:20233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sxo.php"] [unique_id "amu2POWE7BvPuUzLJ9-dUwAAANs"]
[Thu Jul 30 15:38:20.446535 2026] [security2:error] [pid 189611:tid 189817] [client 20.91.199.21:10155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/css/about.php"] [unique_id "amu2POWE7BvPuUzLJ9-dVAAAANE"]
[Thu Jul 30 15:38:20.453462 2026] [security2:error] [pid 189611:tid 189741] [client 20.215.191.139:39646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known//.well-known/owlmailer.php"] [unique_id "amu2POWE7BvPuUzLJ9-dVQAAAIU"]
[Thu Jul 30 15:38:20.472604 2026] [core:notice] [pid 189611:tid 189821] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:20.603740 2026] [security2:error] [pid 189611:tid 189758] [client 20.171.55.167:2478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/aslo.php"] [unique_id "amu2POWE7BvPuUzLJ9-dXgAAAJY"]
[Thu Jul 30 15:38:20.639686 2026] [core:notice] [pid 189611:tid 189680] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:20.865197 2026] [security2:error] [pid 189611:tid 189832] [client 152.32.131.245:55150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.mediaspawn.com"] [uri "/index.php"] [unique_id "amu2POWE7BvPuUzLJ9-dYQAAAOA"]
[Thu Jul 30 15:38:21.087737 2026] [core:notice] [pid 189611:tid 189691] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:21.164047 2026] [security2:error] [pid 189611:tid 189824] [client 191.232.199.39:46587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dbQAAANg"]
[Thu Jul 30 15:38:21.181677 2026] [security2:error] [pid 189611:tid 189815] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/test1.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dbgAAAM8"]
[Thu Jul 30 15:38:21.181809 2026] [security2:error] [pid 189611:tid 189815] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/test1.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dbgAAAM8"]
[Thu Jul 30 15:38:21.364876 2026] [security2:error] [pid 189611:tid 189829] [client 20.215.191.139:38075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/991176.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dcAAAAN0"]
[Thu Jul 30 15:38:21.367917 2026] [security2:error] [pid 189611:tid 189814] [client 20.171.55.167:2515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/authorize.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dcQAAAM4"]
[Thu Jul 30 15:38:21.373043 2026] [security2:error] [pid 189611:tid 189820] [client 20.226.5.174:20264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sxx.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dcgAAANQ"]
[Thu Jul 30 15:38:21.547360 2026] [security2:error] [pid 189611:tid 189825] [client 38.172.162.57:16066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dfAAAANk"]
[Thu Jul 30 15:38:21.547493 2026] [security2:error] [pid 189611:tid 189825] [client 38.172.162.57:16066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dfAAAANk"]
[Thu Jul 30 15:38:21.665304 2026] [core:notice] [pid 189611:tid 189697] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:22.047825 2026] [security2:error] [pid 189611:tid 189806] [client 20.9.4.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dfgAAAMY"]
[Thu Jul 30 15:38:22.047851 2026] [security2:error] [pid 189611:tid 189806] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.applinex.pro"] [uri "/index.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dfgAAAMY"]
[Thu Jul 30 15:38:22.192356 2026] [security2:error] [pid 189611:tid 189851] [client 45.82.244.214:36628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lilyinspires.com"] [uri "/index.php"] [unique_id "amu2PeWE7BvPuUzLJ9-dbwAA81M"]
[Thu Jul 30 15:38:22.227131 2026] [security2:error] [pid 189611:tid 189762] [client 20.171.55.167:2533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/b374k.php"] [unique_id "amu2PuWE7BvPuUzLJ9-diQAAAJo"]
[Thu Jul 30 15:38:22.346845 2026] [security2:error] [pid 189611:tid 189791] [client 20.226.5.174:20242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/syd.php"] [unique_id "amu2PuWE7BvPuUzLJ9-diwAAALc"]
[Thu Jul 30 15:38:22.661813 2026] [security2:error] [pid 189611:tid 189742] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-signin.php"] [unique_id "amu2PuWE7BvPuUzLJ9-dlgAAAIY"]
[Thu Jul 30 15:38:22.661945 2026] [security2:error] [pid 189611:tid 189742] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-signin.php"] [unique_id "amu2PuWE7BvPuUzLJ9-dlgAAAIY"]
[Thu Jul 30 15:38:22.744156 2026] [security2:error] [pid 189611:tid 189770] [client 141.98.102.227:54934] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amu2PuWE7BvPuUzLJ9-dkQAAAKI"]
[Thu Jul 30 15:38:22.744289 2026] [security2:error] [pid 189611:tid 189770] [client 141.98.102.227:54934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "online-hope.com"] [uri "/xmlrpc.php"] [unique_id "amu2PuWE7BvPuUzLJ9-dkQAAAKI"]
[Thu Jul 30 15:38:22.816935 2026] [security2:error] [pid 189611:tid 189849] [client 191.232.199.39:46556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/index/function.php"] [unique_id "amu2PuWE7BvPuUzLJ9-dlwAAAPE"]
[Thu Jul 30 15:38:22.984443 2026] [security2:error] [pid 189611:tid 189650] [remote 216.73.216.51:32173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu2PuWE7BvPuUzLJ9-dnAAAhyY"]
[Thu Jul 30 15:38:23.068411 2026] [security2:error] [pid 189611:tid 189817] [client 20.171.55.167:2507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/bhx1.php"] [unique_id "amu2P-WE7BvPuUzLJ9-doAAAANE"]
[Thu Jul 30 15:38:23.092095 2026] [security2:error] [pid 189611:tid 189761] [client 172.237.109.114:53068] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/wpdiscuz/readme.txt"] [unique_id "amu2P-WE7BvPuUzLJ9-dpAAAAJk"]
[Thu Jul 30 15:38:23.213412 2026] [core:notice] [pid 189611:tid 189798] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:23.344544 2026] [security2:error] [pid 189611:tid 189852] [client 20.226.5.174:20266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sym.php"] [unique_id "amu2P-WE7BvPuUzLJ9-dpgAAAPQ"]
[Thu Jul 30 15:38:23.437794 2026] [security2:error] [pid 189611:tid 189741] [client 2a03:2880:f800:2e:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2PuWE7BvPuUzLJ9-dmAAAhWQ"]
[Thu Jul 30 15:38:23.439650 2026] [security2:error] [pid 189611:tid 189859] [client 20.215.191.139:39043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/adminfuns.php"] [unique_id "amu2P-WE7BvPuUzLJ9-dqAAAAPs"]
[Thu Jul 30 15:38:23.731030 2026] [security2:error] [pid 189611:tid 189771] [client 66.249.73.97:49105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu2P-WE7BvPuUzLJ9-dpwAAAKM"]
[Thu Jul 30 15:38:23.939535 2026] [security2:error] [pid 189611:tid 189820] [client 20.171.55.167:2332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/block-supports/index.php"] [unique_id "amu2P-WE7BvPuUzLJ9-dswAAANQ"]
[Thu Jul 30 15:38:24.114041 2026] [security2:error] [pid 189611:tid 189792] [client 20.215.191.139:39050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "amu2QOWE7BvPuUzLJ9-dugAAALg"]
[Thu Jul 30 15:38:24.363801 2026] [security2:error] [pid 189611:tid 189795] [client 20.226.5.174:20258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sym403.php"] [unique_id "amu2QOWE7BvPuUzLJ9-dwgAAALs"]
[Thu Jul 30 15:38:24.442265 2026] [security2:error] [pid 189611:tid 189782] [client 169.224.94.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu2QOWE7BvPuUzLJ9-dwQAAAK4"], referer: http://cnpinyin.com
[Thu Jul 30 15:38:24.506225 2026] [core:notice] [pid 189611:tid 189776] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:24.720623 2026] [security2:error] [pid 189611:tid 189810] [client 20.171.55.167:2461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/bowo.php"] [unique_id "amu2QOWE7BvPuUzLJ9-d0QAAAMo"]
[Thu Jul 30 15:38:24.841202 2026] [security2:error] [pid 189611:tid 189822] [client 191.232.199.39:48616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/aaa.php"] [unique_id "amu2QOWE7BvPuUzLJ9-d0wAAANY"]
[Thu Jul 30 15:38:25.070418 2026] [core:notice] [pid 189611:tid 189705] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:25.076283 2026] [security2:error] [pid 189611:tid 189789] [client 66.249.65.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.jipkl.com"] [uri "/index.php/JIPKL/article/view/89/92"] [unique_id "amu2QOWE7BvPuUzLJ9-d0gAAtV0"]
[Thu Jul 30 15:38:25.361292 2026] [security2:error] [pid 189611:tid 189845] [client 20.226.5.174:20271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/symlink.php"] [unique_id "amu2QeWE7BvPuUzLJ9-d4gAAAO0"]
[Thu Jul 30 15:38:25.515184 2026] [security2:error] [pid 189611:tid 189790] [client 20.171.55.167:2479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/bypass.php"] [unique_id "amu2QeWE7BvPuUzLJ9-d4wAAALY"]
[Thu Jul 30 15:38:25.666967 2026] [core:notice] [pid 189611:tid 189617] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:25.781606 2026] [security2:error] [pid 189611:tid 189766] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/gg.php"] [unique_id "amu2QeWE7BvPuUzLJ9-d7gAAAJ4"]
[Thu Jul 30 15:38:25.781752 2026] [security2:error] [pid 189611:tid 189766] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/gg.php"] [unique_id "amu2QeWE7BvPuUzLJ9-d7gAAAJ4"]
[Thu Jul 30 15:38:26.163012 2026] [security2:error] [pid 189611:tid 189838] [client 20.215.191.139:55135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/classsmtps.php"] [unique_id "amu2QuWE7BvPuUzLJ9-d-QAAAOY"]
[Thu Jul 30 15:38:26.218386 2026] [core:notice] [pid 189611:tid 189622] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:26.250179 2026] [security2:error] [pid 189611:tid 189749] [client 191.232.199.39:49631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/getid3-core.php"] [unique_id "amu2QuWE7BvPuUzLJ9-eAwAAAI0"]
[Thu Jul 30 15:38:26.274264 2026] [security2:error] [pid 189611:tid 189805] [client 20.171.55.167:2473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/cakiltheme/up.php"] [unique_id "amu2QuWE7BvPuUzLJ9-eBQAAAMU"]
[Thu Jul 30 15:38:26.356925 2026] [security2:error] [pid 189611:tid 189783] [client 20.226.5.174:20246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/sys.php"] [unique_id "amu2QuWE7BvPuUzLJ9-eBwAAAK8"]
[Thu Jul 30 15:38:26.395235 2026] [security2:error] [pid 189611:tid 189851] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/class.php"] [unique_id "amu2QuWE7BvPuUzLJ9-eCAAAAPM"]
[Thu Jul 30 15:38:26.395328 2026] [security2:error] [pid 189611:tid 189851] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/class.php"] [unique_id "amu2QuWE7BvPuUzLJ9-eCAAAAPM"]
[Thu Jul 30 15:38:26.943897 2026] [security2:error] [pid 189611:tid 189809] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/404.php"] [unique_id "amu2QuWE7BvPuUzLJ9-eEgAAAMk"]
[Thu Jul 30 15:38:26.944003 2026] [security2:error] [pid 189611:tid 189809] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/404.php"] [unique_id "amu2QuWE7BvPuUzLJ9-eEgAAAMk"]
[Thu Jul 30 15:38:27.089707 2026] [security2:error] [pid 189611:tid 189843] [client 20.171.55.167:2530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/cekidot/alf.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eEwAAAOs"]
[Thu Jul 30 15:38:27.150948 2026] [security2:error] [pid 189611:tid 189835] [client 172.237.109.114:37865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/register"] [unique_id "amu2Q-WE7BvPuUzLJ9-eFwAAAOM"]
[Thu Jul 30 15:38:27.328065 2026] [security2:error] [pid 189611:tid 189821] [client 20.226.5.174:20224] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "523"] [id "900207"] [msg "Sys[0-9]+ Mailer"] [hostname "mail.revolutionary-technologies.com"] [uri "/sys32.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eHgAAANU"]
[Thu Jul 30 15:38:27.453565 2026] [security2:error] [pid 189611:tid 189841] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/lite.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eHwAAAOk"]
[Thu Jul 30 15:38:27.453683 2026] [security2:error] [pid 189611:tid 189841] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/lite.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eHwAAAOk"]
[Thu Jul 30 15:38:27.717102 2026] [security2:error] [pid 189611:tid 189832] [client 20.215.191.139:40993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eJgAAAOA"]
[Thu Jul 30 15:38:27.810662 2026] [security2:error] [pid 189611:tid 189804] [client 20.91.199.21:21905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/images/about.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eKgAAAMQ"]
[Thu Jul 30 15:38:27.840607 2026] [security2:error] [pid 189611:tid 189741] [client 20.171.55.167:2318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/chitoge.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eKwAAAIU"]
[Thu Jul 30 15:38:27.959261 2026] [security2:error] [pid 189611:tid 189798] [client 191.232.199.39:48623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/adminer.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eLQAAAL4"]
[Thu Jul 30 15:38:27.977901 2026] [security2:error] [pid 189611:tid 189825] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/lock360.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eLgAAANk"]
[Thu Jul 30 15:38:27.978028 2026] [security2:error] [pid 189611:tid 189825] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/lock360.php"] [unique_id "amu2Q-WE7BvPuUzLJ9-eLgAAANk"]
[Thu Jul 30 15:38:28.038741 2026] [security2:error] [pid 189611:tid 189731] [remote 110.249.201.141:21694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/salalah-oman-tour.html"] [unique_id "amu2ROWE7BvPuUzLJ9-eLwAA_Hc"]
[Thu Jul 30 15:38:28.279031 2026] [security2:error] [pid 189611:tid 189781] [client 20.226.5.174:20228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/system.php"] [unique_id "amu2ROWE7BvPuUzLJ9-eOQAAAK0"]
[Thu Jul 30 15:38:28.542365 2026] [security2:error] [pid 189611:tid 189805] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-content/wp-conflg.php"] [unique_id "amu2ROWE7BvPuUzLJ9-ePgAAAMU"]
[Thu Jul 30 15:38:28.542481 2026] [security2:error] [pid 189611:tid 189805] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-content/wp-conflg.php"] [unique_id "amu2ROWE7BvPuUzLJ9-ePgAAAMU"]
[Thu Jul 30 15:38:28.637741 2026] [proxy:error] [pid 189611:tid 189791] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:38:28.637806 2026] [proxy_http:error] [pid 189611:tid 189791] [client 18.211.55.47:49192] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:38:28.638398 2026] [proxy:error] [pid 189611:tid 189791] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:38:28.638446 2026] [proxy_http:error] [pid 189611:tid 189791] [client 18.211.55.47:49192] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:38:28.661438 2026] [security2:error] [pid 189611:tid 189759] [client 20.171.55.167:2440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/class-snoopye_wso.php"] [unique_id "amu2ROWE7BvPuUzLJ9-eSwAAAJc"]
[Thu Jul 30 15:38:28.673393 2026] [proxy:error] [pid 189611:tid 189864] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:38:28.673459 2026] [proxy_http:error] [pid 189611:tid 189864] [client 98.87.102.177:13891] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:38:28.674037 2026] [proxy:error] [pid 189611:tid 189864] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:38:28.674084 2026] [proxy_http:error] [pid 189611:tid 189864] [client 98.87.102.177:13891] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:38:28.684422 2026] [security2:error] [pid 189611:tid 189787] [client 20.215.191.139:38026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/doc.php"] [unique_id "amu2ROWE7BvPuUzLJ9-eUwAAALM"]
[Thu Jul 30 15:38:29.061135 2026] [security2:error] [pid 189611:tid 189817] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-links-opml.php"] [unique_id "amu2ReWE7BvPuUzLJ9-eXgAAANE"]
[Thu Jul 30 15:38:29.061248 2026] [security2:error] [pid 189611:tid 189817] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-links-opml.php"] [unique_id "amu2ReWE7BvPuUzLJ9-eXgAAANE"]
[Thu Jul 30 15:38:29.260449 2026] [security2:error] [pid 189611:tid 189752] [client 20.226.5.174:20249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/system_log.php"] [unique_id "amu2ReWE7BvPuUzLJ9-eZwAAAJA"]
[Thu Jul 30 15:38:29.417618 2026] [security2:error] [pid 189611:tid 189758] [client 20.171.55.167:2436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/class-wp-http.php"] [unique_id "amu2ReWE7BvPuUzLJ9-eawAAAJY"]
[Thu Jul 30 15:38:29.583657 2026] [security2:error] [pid 189611:tid 189798] [client 20.9.4.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.4.9.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.applinex.pro"] [uri "/wp-content/uploads/min.php"] [unique_id "amu2ReWE7BvPuUzLJ9-ebwAAAL4"]
[Thu Jul 30 15:38:29.583807 2026] [security2:error] [pid 189611:tid 189798] [client 20.9.4.9:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.applinex.pro"] [uri "/wp-content/uploads/min.php"] [unique_id "amu2ReWE7BvPuUzLJ9-ebwAAAL4"]
[Thu Jul 30 15:38:29.836257 2026] [core:notice] [pid 189611:tid 189640] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:29.879999 2026] [security2:error] [pid 189611:tid 189819] [client 145.239.87.55:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.87.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/el/index.php"] [unique_id "amu2ReWE7BvPuUzLJ9-ecAAAANM"]
[Thu Jul 30 15:38:30.202166 2026] [security2:error] [pid 189611:tid 189851] [client 51.91.255.135:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.255.91.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.toscanamall.com"] [uri "/el/index.php"] [unique_id "amu2RuWE7BvPuUzLJ9-efgAAAPM"]
[Thu Jul 30 15:38:30.233595 2026] [security2:error] [pid 189611:tid 189776] [client 20.171.55.167:2495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/class-wp-textdomain-registry.php"] [unique_id "amu2RuWE7BvPuUzLJ9-eggAAAKg"]
[Thu Jul 30 15:38:30.258210 2026] [security2:error] [pid 189611:tid 189823] [client 20.226.5.174:20253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.5.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.revolutionary-technologies.com"] [uri "/system_logs.php"] [unique_id "amu2RuWE7BvPuUzLJ9-egwAAANc"]
[Thu Jul 30 15:38:30.261355 2026] [security2:error] [pid 189611:tid 189787] [client 191.232.199.39:48625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/alfa.php"] [unique_id "amu2RuWE7BvPuUzLJ9-ehAAAALM"]
[Thu Jul 30 15:38:30.956160 2026] [security2:error] [pid 189611:tid 189854] [client 43.172.197.146:39300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amu2RuWE7BvPuUzLJ9-ejwAAAPY"]
[Thu Jul 30 15:38:30.986972 2026] [security2:error] [pid 189611:tid 189848] [client 20.171.55.167:2438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/cloud.php"] [unique_id "amu2RuWE7BvPuUzLJ9-emgAAAPA"]
[Thu Jul 30 15:38:31.359079 2026] [security2:error] [pid 189611:tid 189741] [client 213.152.187.235:60388] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amu2R-WE7BvPuUzLJ9-eoAAAAIU"]
[Thu Jul 30 15:38:31.359172 2026] [security2:error] [pid 189611:tid 189741] [client 213.152.187.235:60388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "magicmooncorp.com"] [uri "/xmlrpc.php"] [unique_id "amu2R-WE7BvPuUzLJ9-eoAAAAIU"]
[Thu Jul 30 15:38:31.586078 2026] [security2:error] [pid 189611:tid 189867] [client 43.135.133.194:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.133.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helper.adtop.net"] [uri "/bbs/login_check.php"] [unique_id "amu2R-WE7BvPuUzLJ9-engAAAQM"]
[Thu Jul 30 15:38:31.666670 2026] [security2:error] [pid 189611:tid 189830] [client 20.215.191.139:55160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/fond.php"] [unique_id "amu2R-WE7BvPuUzLJ9-epwAAAN4"]
[Thu Jul 30 15:38:31.813600 2026] [security2:error] [pid 189611:tid 189816] [client 20.171.55.167:2486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/colors/blue/CasperExV1.php"] [unique_id "amu2R-WE7BvPuUzLJ9-erAAAANA"]
[Thu Jul 30 15:38:32.142880 2026] [security2:error] [pid 189611:tid 189776] [client 191.232.199.39:46576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amu2SOWE7BvPuUzLJ9-eswAAAKg"]
[Thu Jul 30 15:38:32.190097 2026] [security2:error] [pid 189611:tid 189753] [client 38.172.162.57:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2SOWE7BvPuUzLJ9-etAAAAJE"]
[Thu Jul 30 15:38:32.190222 2026] [security2:error] [pid 189611:tid 189753] [client 38.172.162.57:16267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2SOWE7BvPuUzLJ9-etAAAAJE"]
[Thu Jul 30 15:38:32.300624 2026] [security2:error] [pid 189611:tid 189791] [client 20.215.191.139:41022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "amu2SOWE7BvPuUzLJ9-etQAAALc"]
[Thu Jul 30 15:38:32.593872 2026] [security2:error] [pid 189611:tid 189864] [client 20.171.55.167:2468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/colors/blue/lmfi.php"] [unique_id "amu2SOWE7BvPuUzLJ9-evwAAAQA"]
[Thu Jul 30 15:38:32.928451 2026] [security2:error] [pid 189611:tid 189842] [client 20.215.191.139:55149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "amu2SOWE7BvPuUzLJ9-ewwAAAOo"]
[Thu Jul 30 15:38:32.987156 2026] [security2:error] [pid 189611:tid 189646] [remote 216.73.216.51:48336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amu2SOWE7BvPuUzLJ9-eyAAAiSI"]
[Thu Jul 30 15:38:33.415018 2026] [security2:error] [pid 189611:tid 189788] [client 20.171.55.167:2484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/colors/coffee/black.php"] [unique_id "amu2SeWE7BvPuUzLJ9-ezAAAALQ"]
[Thu Jul 30 15:38:33.683572 2026] [security2:error] [pid 189611:tid 189761] [client 20.91.199.21:7289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "amu2SeWE7BvPuUzLJ9-e1gAAAJk"]
[Thu Jul 30 15:38:33.809006 2026] [security2:error] [pid 189611:tid 189832] [client 20.215.191.139:38065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/mariju.php"] [unique_id "amu2SeWE7BvPuUzLJ9-e1wAAAOA"]
[Thu Jul 30 15:38:33.996707 2026] [security2:error] [pid 189611:tid 189764] [client 216.73.216.176:21655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mediaspawn.com"] [uri "/index.php"] [unique_id "amu2SeWE7BvPuUzLJ9-e2AAAnEw"]
[Thu Jul 30 15:38:34.122735 2026] [security2:error] [pid 189611:tid 189817] [client 191.232.199.39:8711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amu2SuWE7BvPuUzLJ9-e4wAAANE"]
[Thu Jul 30 15:38:34.236330 2026] [security2:error] [pid 189611:tid 189799] [client 20.171.55.167:2496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/colors/ectoplasm/admin.php"] [unique_id "amu2SuWE7BvPuUzLJ9-e6AAAAL8"]
[Thu Jul 30 15:38:34.579044 2026] [security2:error] [pid 189611:tid 189812] [client 128.2.204.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu2SuWE7BvPuUzLJ9-e7AAAAMw"]
[Thu Jul 30 15:38:34.999795 2026] [security2:error] [pid 189611:tid 189786] [client 20.171.55.167:2522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/colors/midnight/colors.php"] [unique_id "amu2SuWE7BvPuUzLJ9-e9gAAALI"]
[Thu Jul 30 15:38:35.530662 2026] [security2:error] [pid 189611:tid 189826] [client 152.32.131.245:44760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mediaspawn.com"] [uri "/index.php"] [unique_id "amu2S-WE7BvPuUzLJ9-fAAAAANo"]
[Thu Jul 30 15:38:35.762282 2026] [security2:error] [pid 189611:tid 189856] [client 20.171.55.167:2305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/colorsadmin.php"] [unique_id "amu2S-WE7BvPuUzLJ9-fCgAAAPg"]
[Thu Jul 30 15:38:35.868722 2026] [security2:error] [pid 189611:tid 189842] [client 110.249.201.136:13850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cmplboard.com"] [uri "/robots.txt"] [unique_id "amu2S-WE7BvPuUzLJ9-fDAAAAOo"]
[Thu Jul 30 15:38:35.892862 2026] [security2:error] [pid 189611:tid 189746] [client 20.215.191.139:55113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/moon.php"] [unique_id "amu2S-WE7BvPuUzLJ9-fDQAAAIo"]
[Thu Jul 30 15:38:36.282209 2026] [security2:error] [pid 189611:tid 189747] [client 66.249.73.97:44469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "pkf.jo"] [uri "/index.php"] [unique_id "amu2S-WE7BvPuUzLJ9-fDgAAAIs"]
[Thu Jul 30 15:38:36.443746 2026] [security2:error] [pid 189611:tid 189788] [client 191.232.199.39:48632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amu2TOWE7BvPuUzLJ9-fGAAAALQ"]
[Thu Jul 30 15:38:36.596144 2026] [security2:error] [pid 189611:tid 189808] [client 20.171.55.167:2513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/componentsk.php"] [unique_id "amu2TOWE7BvPuUzLJ9-fHQAAAMg"]
[Thu Jul 30 15:38:36.828468 2026] [security2:error] [pid 189611:tid 189797] [client 20.215.191.139:55124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "amu2TOWE7BvPuUzLJ9-fKAAAAL0"]
[Thu Jul 30 15:38:37.012125 2026] [security2:error] [pid 189611:tid 189814] [client 216.73.216.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thesounddepot.com"] [uri "/index.php"] [unique_id "amu2SuWE7BvPuUzLJ9-e6QAAzkg"], referer: https://thesounddepot.com/sitemap.xml
[Thu Jul 30 15:38:37.257684 2026] [core:notice] [pid 189611:tid 189678] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:37.371883 2026] [security2:error] [pid 189611:tid 189838] [client 20.171.55.167:2434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/contacts.php"] [unique_id "amu2TeWE7BvPuUzLJ9-fMwAAAOY"]
[Thu Jul 30 15:38:37.706316 2026] [security2:error] [pid 189611:tid 189776] [client 20.215.191.139:35345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/sx.php"] [unique_id "amu2TeWE7BvPuUzLJ9-fPQAAAKg"]
[Thu Jul 30 15:38:37.998927 2026] [security2:error] [pid 189611:tid 189823] [client 191.232.199.39:49623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/edit.php"] [unique_id "amu2TeWE7BvPuUzLJ9-fRAAAANc"]
[Thu Jul 30 15:38:38.093111 2026] [security2:error] [pid 189611:tid 189859] [client 20.171.55.167:2504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/corewp.php"] [unique_id "amu2TuWE7BvPuUzLJ9-fRQAAAPs"]
[Thu Jul 30 15:38:38.123663 2026] [security2:error] [pid 189611:tid 189854] [client 172.237.109.114:53882] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/extensive-vc-addon/readme.txt"] [unique_id "amu2TuWE7BvPuUzLJ9-fRgAAAPY"]
[Thu Jul 30 15:38:38.394924 2026] [security2:error] [pid 189611:tid 189774] [client 43.154.124.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu2TuWE7BvPuUzLJ9-fTAAAAKY"], referer: http://cnpinyin.com/voc-test?miv-id=mv0603_%e5%a5%87%e6%98%9f%e8%ae%b0%e7%ac%ac26%e9%9b%86_Magic-Star_e26_p3
[Thu Jul 30 15:38:38.503301 2026] [security2:error] [pid 189611:tid 189772] [client 20.215.191.139:55140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "amu2TuWE7BvPuUzLJ9-fUwAAAKQ"]
[Thu Jul 30 15:38:38.595092 2026] [security2:error] [pid 189611:tid 189857] [client 66.249.72.201:49874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.deltaedu.net"] [uri "/index.php"] [unique_id "amu2TuWE7BvPuUzLJ9-fVAAAAPk"]
[Thu Jul 30 15:38:38.792722 2026] [security2:error] [pid 189611:tid 189803] [client 20.91.199.21:4188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "amu2TuWE7BvPuUzLJ9-fXAAAAMM"]
[Thu Jul 30 15:38:38.821677 2026] [security2:error] [pid 189611:tid 189804] [client 20.171.55.167:2455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/customize.php"] [unique_id "amu2TuWE7BvPuUzLJ9-fXQAAAMQ"]
[Thu Jul 30 15:38:39.307760 2026] [security2:error] [pid 189611:tid 189815] [client 20.215.191.139:38106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/amaxx.php"] [unique_id "amu2T-WE7BvPuUzLJ9-fbQAAAM8"]
[Thu Jul 30 15:38:39.643868 2026] [security2:error] [pid 189611:tid 189785] [client 20.171.55.167:2516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/date.php"] [unique_id "amu2T-WE7BvPuUzLJ9-fdwAAALE"]
[Thu Jul 30 15:38:39.917267 2026] [security2:error] [pid 189611:tid 189843] [client 20.215.191.139:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/bek.php"] [unique_id "amu2T-WE7BvPuUzLJ9-fggAAAOs"]
[Thu Jul 30 15:38:40.015664 2026] [security2:error] [pid 189611:tid 189831] [client 191.232.199.39:49601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/sf.php"] [unique_id "amu2UOWE7BvPuUzLJ9-fgwAAAN8"]
[Thu Jul 30 15:38:40.374290 2026] [security2:error] [pid 189611:tid 189818] [client 20.171.55.167:2488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/defaul1.php"] [unique_id "amu2UOWE7BvPuUzLJ9-figAAANI"]
[Thu Jul 30 15:38:41.107048 2026] [core:notice] [pid 189611:tid 189705] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:41.161625 2026] [security2:error] [pid 189611:tid 189860] [client 20.171.55.167:2470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/digital-download/new.php"] [unique_id "amu2UeWE7BvPuUzLJ9-fmQAAAPw"]
[Thu Jul 30 15:38:41.653664 2026] [security2:error] [pid 189611:tid 189747] [client 20.215.191.139:38029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/caches.php.suspected"] [unique_id "amu2UeWE7BvPuUzLJ9-fpgAAAIs"]
[Thu Jul 30 15:38:41.936491 2026] [security2:error] [pid 189611:tid 189815] [client 20.171.55.167:2477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/dist/widgets/about.php"] [unique_id "amu2UeWE7BvPuUzLJ9-frgAAAM8"]
[Thu Jul 30 15:38:41.939397 2026] [security2:error] [pid 189611:tid 189748] [client 191.232.199.39:48602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wso.php"] [unique_id "amu2UeWE7BvPuUzLJ9-frwAAAIw"]
[Thu Jul 30 15:38:41.959596 2026] [security2:error] [pid 189611:tid 189760] [client 43.164.0.96:56256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.0.164.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adbacklink.online"] [uri "/bbs/register.php"] [unique_id "amu2UeWE7BvPuUzLJ9-foQAAAJg"]
[Thu Jul 30 15:38:42.518053 2026] [core:error] [pid 189611:tid 189846] [client 66.249.66.3:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:38:42.518079 2026] [core:error] [pid 189611:tid 189846] [client 66.249.66.3:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:38:42.532938 2026] [security2:error] [pid 189611:tid 189789] [client 20.215.191.139:39649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/class.api.php"] [unique_id "amu2UuWE7BvPuUzLJ9-fvQAAALU"]
[Thu Jul 30 15:38:42.724748 2026] [security2:error] [pid 189611:tid 189850] [client 20.171.55.167:2449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/documentsbypass.php"] [unique_id "amu2UuWE7BvPuUzLJ9-fwQAAAPI"]
[Thu Jul 30 15:38:42.873017 2026] [security2:error] [pid 189611:tid 189864] [client 38.172.162.57:16400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2UuWE7BvPuUzLJ9-fxgAAAQA"]
[Thu Jul 30 15:38:42.873717 2026] [security2:error] [pid 189611:tid 189864] [client 38.172.162.57:16400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2UuWE7BvPuUzLJ9-fxgAAAQA"]
[Thu Jul 30 15:38:43.243476 2026] [security2:error] [pid 189611:tid 189852] [client 20.215.191.139:38061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/cong.php"] [unique_id "amu2U-WE7BvPuUzLJ9-fzgAAAPQ"]
[Thu Jul 30 15:38:43.392340 2026] [core:notice] [pid 189611:tid 189840] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:43.545267 2026] [security2:error] [pid 189611:tid 189859] [client 191.232.199.39:46537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/ioxi-o.php"] [unique_id "amu2U-WE7BvPuUzLJ9-f2QAAAPs"]
[Thu Jul 30 15:38:43.555714 2026] [security2:error] [pid 189611:tid 189771] [client 20.171.55.167:2553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ds.php"] [unique_id "amu2U-WE7BvPuUzLJ9-f2gAAAKM"]
[Thu Jul 30 15:38:44.045863 2026] [core:notice] [pid 189611:tid 189795] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:44.091202 2026] [security2:error] [pid 189611:tid 189781] [client 172.237.109.114:26584] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/heureka/readme.txt"] [unique_id "amu2VOWE7BvPuUzLJ9-f6gAAAK0"]
[Thu Jul 30 15:38:44.205556 2026] [security2:error] [pid 189611:tid 189804] [client 20.91.199.21:7222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/network/cloud.php"] [unique_id "amu2VOWE7BvPuUzLJ9-f7gAAAMQ"]
[Thu Jul 30 15:38:44.300883 2026] [security2:error] [pid 189611:tid 189817] [client 20.215.191.139:55156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/content.php"] [unique_id "amu2VOWE7BvPuUzLJ9-f7wAAANE"]
[Thu Jul 30 15:38:44.315530 2026] [security2:error] [pid 189611:tid 189836] [client 20.171.55.167:2505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/eew.php"] [unique_id "amu2VOWE7BvPuUzLJ9-f8AAAAOQ"]
[Thu Jul 30 15:38:44.478916 2026] [security2:error] [pid 189611:tid 189625] [remote 57.141.0.35:37348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/76531776832/feed/rss2/"] [unique_id "amu2VOWE7BvPuUzLJ9-f9QAAvw0"]
[Thu Jul 30 15:38:44.843093 2026] [security2:error] [pid 189611:tid 189748] [client 191.232.199.39:48600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/file56.php"] [unique_id "amu2VOWE7BvPuUzLJ9-f_QAAAIw"]
[Thu Jul 30 15:38:44.983471 2026] [security2:error] [pid 189611:tid 189861] [client 20.91.199.21:7179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/cloud.php"] [unique_id "amu2VOWE7BvPuUzLJ9-f_wAAAP0"]
[Thu Jul 30 15:38:45.089223 2026] [security2:error] [pid 189611:tid 189797] [client 20.171.55.167:2546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/erinyani/gebase.php"] [unique_id "amu2VeWE7BvPuUzLJ9-gAwAAAL0"]
[Thu Jul 30 15:38:45.115533 2026] [core:notice] [pid 189611:tid 189826] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:45.470407 2026] [security2:error] [pid 189611:tid 189823] [client 20.215.191.139:17672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/cwianpri.php"] [unique_id "amu2VeWE7BvPuUzLJ9-gDAAAANc"]
[Thu Jul 30 15:38:45.862569 2026] [security2:error] [pid 189611:tid 189852] [client 20.171.55.167:2492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ez.php"] [unique_id "amu2VeWE7BvPuUzLJ9-gGAAAAPQ"]
[Thu Jul 30 15:38:45.990572 2026] [core:notice] [pid 189611:tid 189768] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:46.049615 2026] [core:notice] [pid 189611:tid 189746] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:46.270670 2026] [security2:error] [pid 189611:tid 189845] [client 20.215.191.139:55142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/elp.php"] [unique_id "amu2VuWE7BvPuUzLJ9-gIwAAAO0"]
[Thu Jul 30 15:38:46.481258 2026] [security2:error] [pid 189611:tid 189772] [client 191.232.199.39:46546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amu2VuWE7BvPuUzLJ9-gJgAAAKQ"]
[Thu Jul 30 15:38:46.540317 2026] [security2:error] [pid 189611:tid 189808] [client 20.91.199.21:41375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/cgi-bin/cloud.php"] [unique_id "amu2VuWE7BvPuUzLJ9-gKgAAAMg"]
[Thu Jul 30 15:38:46.629169 2026] [security2:error] [pid 189611:tid 189782] [client 20.171.55.167:2537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ff2.php"] [unique_id "amu2VuWE7BvPuUzLJ9-gLwAAAK4"]
[Thu Jul 30 15:38:47.031047 2026] [core:notice] [pid 189611:tid 189799] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:47.183774 2026] [core:notice] [pid 189611:tid 189742] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:47.486956 2026] [security2:error] [pid 189611:tid 189868] [client 20.171.55.167:2476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/file_uploadalfa.php"] [unique_id "amu2V-WE7BvPuUzLJ9-gQQAAAQQ"]
[Thu Jul 30 15:38:47.695625 2026] [core:notice] [pid 189611:tid 189640] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:47.998046 2026] [security2:error] [pid 189611:tid 189828] [client 20.91.199.21:6907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/updates.php"] [unique_id "amu2V-WE7BvPuUzLJ9-gUAAAANw"]
[Thu Jul 30 15:38:48.206579 2026] [security2:error] [pid 189611:tid 189789] [client 191.232.199.39:8744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-admin/css/index.php"] [unique_id "amu2WOWE7BvPuUzLJ9-gWAAAALU"]
[Thu Jul 30 15:38:48.237641 2026] [security2:error] [pid 189611:tid 189827] [client 57.141.0.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2V-WE7BvPuUzLJ9-gRwAAANs"]
[Thu Jul 30 15:38:48.346523 2026] [security2:error] [pid 189611:tid 189821] [client 20.171.55.167:2475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/filemanager/connectors/php/upload.php"] [unique_id "amu2WOWE7BvPuUzLJ9-gWwAAANU"]
[Thu Jul 30 15:38:48.626845 2026] [security2:error] [pid 189611:tid 189825] [client 104.210.56.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kbaagency.com"] [uri "/index.php"] [unique_id "amu2VuWE7BvPuUzLJ9-gKwAA2RA"]
[Thu Jul 30 15:38:48.661304 2026] [security2:error] [pid 189611:tid 189822] [client 216.244.66.233:58362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amu2WOWE7BvPuUzLJ9-gYQAAANY"]
[Thu Jul 30 15:38:48.661450 2026] [security2:error] [pid 189611:tid 189822] [client 216.244.66.233:58362] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amu2WOWE7BvPuUzLJ9-gYQAAANY"]
[Thu Jul 30 15:38:49.073245 2026] [security2:error] [pid 189611:tid 189741] [client 20.91.199.21:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/css/cloud.php"] [unique_id "amu2WeWE7BvPuUzLJ9-gaAAAAIU"]
[Thu Jul 30 15:38:49.119010 2026] [security2:error] [pid 189611:tid 189777] [client 20.171.55.167:2511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/fm1.php"] [unique_id "amu2WeWE7BvPuUzLJ9-gaQAAAKk"]
[Thu Jul 30 15:38:49.127819 2026] [security2:error] [pid 189611:tid 189627] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wk/index.php"] [unique_id "amu2WeWE7BvPuUzLJ9-gagAAug8"]
[Thu Jul 30 15:38:49.186470 2026] [fcgid:warn] [pid 189611:tid 189819] (70014)End of file found: [client 152.32.131.245:35264] mod_fcgid: can't get data from http client
[Thu Jul 30 15:38:49.477906 2026] [core:notice] [pid 189611:tid 189769] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:49.510213 2026] [security2:error] [pid 189611:tid 189749] [client 191.232.199.39:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/edit.php"] [unique_id "amu2WeWE7BvPuUzLJ9-geAAAAI0"]
[Thu Jul 30 15:38:49.551662 2026] [security2:error] [pid 189611:tid 189656] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/av.php"] [unique_id "amu2WeWE7BvPuUzLJ9-geQAAkSw"]
[Thu Jul 30 15:38:49.571782 2026] [security2:error] [pid 189611:tid 189745] [client 20.215.191.139:38031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/kwggvpup.php"] [unique_id "amu2WeWE7BvPuUzLJ9-gegAAAIk"]
[Thu Jul 30 15:38:49.680956 2026] [security2:error] [pid 189611:tid 189635] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/mini.php"] [unique_id "amu2WeWE7BvPuUzLJ9-gfAAA4xc"]
[Thu Jul 30 15:38:49.810661 2026] [security2:error] [pid 189611:tid 189651] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/aa.php"] [unique_id "amu2WeWE7BvPuUzLJ9-ggAABBCc"]
[Thu Jul 30 15:38:49.898691 2026] [security2:error] [pid 189611:tid 189756] [client 20.171.55.167:2551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/functionsf.php"] [unique_id "amu2WeWE7BvPuUzLJ9-ghwAAAJQ"]
[Thu Jul 30 15:38:49.942579 2026] [security2:error] [pid 189611:tid 189660] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/w.php"] [unique_id "amu2WeWE7BvPuUzLJ9-gigAAkDA"]
[Thu Jul 30 15:38:49.980487 2026] [core:notice] [pid 189611:tid 189814] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:50.069516 2026] [security2:error] [pid 189611:tid 189657] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/admin.php"] [unique_id "amu2WuWE7BvPuUzLJ9-gjAAA0i0"]
[Thu Jul 30 15:38:50.198456 2026] [security2:error] [pid 189611:tid 189854] [client 20.215.191.139:35414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/101d2ae2-f2f3-4977-b35d-b3a0ad74a469.php"] [unique_id "amu2WuWE7BvPuUzLJ9-gjgAAAPY"]
[Thu Jul 30 15:38:50.208310 2026] [security2:error] [pid 189611:tid 189688] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amu2WuWE7BvPuUzLJ9-gjwAA4kw"]
[Thu Jul 30 15:38:50.334960 2026] [security2:error] [pid 189611:tid 189674] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/m.php"] [unique_id "amu2WuWE7BvPuUzLJ9-glAAAmT4"]
[Thu Jul 30 15:38:50.553827 2026] [security2:error] [pid 189611:tid 189677] [remote 216.73.216.51:28239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu2WuWE7BvPuUzLJ9-gnQAAwEE"]
[Thu Jul 30 15:38:50.682257 2026] [security2:error] [pid 189611:tid 189811] [client 20.171.55.167:2483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/gel4y.php"] [unique_id "amu2WuWE7BvPuUzLJ9-gngAAAMs"]
[Thu Jul 30 15:38:50.759671 2026] [security2:error] [pid 189611:tid 189829] [client 172.237.109.114:55106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu2WuWE7BvPuUzLJ9-gjQAAAN0"]
[Thu Jul 30 15:38:50.796068 2026] [security2:error] [pid 189611:tid 189675] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amu2WuWE7BvPuUzLJ9-gnAAA-T8"]
[Thu Jul 30 15:38:50.905004 2026] [security2:error] [pid 189611:tid 189771] [client 191.232.199.39:49605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/2.php"] [unique_id "amu2WuWE7BvPuUzLJ9-gpQAAAKM"]
[Thu Jul 30 15:38:50.924998 2026] [core:notice] [pid 189611:tid 189666] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:51.056804 2026] [security2:error] [pid 189611:tid 189669] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/classwithtostring.php"] [unique_id "amu2W-WE7BvPuUzLJ9-grgAAljk"]
[Thu Jul 30 15:38:51.185941 2026] [security2:error] [pid 189611:tid 189653] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/gmo.php"] [unique_id "amu2W-WE7BvPuUzLJ9-gsAAAlyk"]
[Thu Jul 30 15:38:51.293279 2026] [security2:error] [pid 189611:tid 189847] [client 20.215.191.139:39638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/LA.php"] [unique_id "amu2W-WE7BvPuUzLJ9-gtAAAAO8"]
[Thu Jul 30 15:38:51.316091 2026] [security2:error] [pid 189611:tid 189672] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/languages/index.php"] [unique_id "amu2W-WE7BvPuUzLJ9-gtQAA5zw"]
[Thu Jul 30 15:38:51.338745 2026] [security2:error] [pid 189611:tid 189788] [client 20.91.199.21:1329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/user/cloud.php"] [unique_id "amu2W-WE7BvPuUzLJ9-gtgAAALQ"]
[Thu Jul 30 15:38:51.522543 2026] [security2:error] [pid 189611:tid 189791] [client 20.171.55.167:2447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/goh.php"] [unique_id "amu2W-WE7BvPuUzLJ9-gvQAAALc"]
[Thu Jul 30 15:38:51.714245 2026] [security2:error] [pid 189611:tid 189685] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-the.php"] [unique_id "amu2W-WE7BvPuUzLJ9-gvgAA7kk"]
[Thu Jul 30 15:38:52.039531 2026] [security2:error] [pid 189611:tid 189663] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/404.php"] [unique_id "amu2XOWE7BvPuUzLJ9-gygAAvDM"]
[Thu Jul 30 15:38:52.168373 2026] [security2:error] [pid 189611:tid 189662] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/init.php"] [unique_id "amu2XOWE7BvPuUzLJ9-gzwAAijI"]
[Thu Jul 30 15:38:52.210426 2026] [security2:error] [pid 189611:tid 189756] [client 191.232.199.39:49649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amu2XOWE7BvPuUzLJ9-g0AAAAJQ"]
[Thu Jul 30 15:38:52.288416 2026] [security2:error] [pid 189611:tid 189848] [client 20.171.55.167:2534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/hava.php"] [unique_id "amu2XOWE7BvPuUzLJ9-g1AAAAPA"]
[Thu Jul 30 15:38:52.297473 2026] [security2:error] [pid 189611:tid 189697] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/file5.php"] [unique_id "amu2XOWE7BvPuUzLJ9-g1QAAjlU"]
[Thu Jul 30 15:38:52.384583 2026] [security2:error] [pid 189611:tid 189849] [client 20.91.199.21:15591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/img/cloud.php"] [unique_id "amu2XOWE7BvPuUzLJ9-g1gAAAPE"]
[Thu Jul 30 15:38:52.428263 2026] [security2:error] [pid 189611:tid 189702] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amu2XOWE7BvPuUzLJ9-g1wABA1o"]
[Thu Jul 30 15:38:52.598199 2026] [security2:error] [pid 189611:tid 189676] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/shell.php"] [unique_id "amu2XOWE7BvPuUzLJ9-g3gAAm0A"]
[Thu Jul 30 15:38:52.751427 2026] [security2:error] [pid 189611:tid 189820] [client 2a03:2880:f800:1c:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2XOWE7BvPuUzLJ9-gzgAA1E8"]
[Thu Jul 30 15:38:52.791102 2026] [security2:error] [pid 189611:tid 189682] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/f35.php"] [unique_id "amu2XOWE7BvPuUzLJ9-g4gAArkY"]
[Thu Jul 30 15:38:52.921493 2026] [security2:error] [pid 189611:tid 189714] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/new.php"] [unique_id "amu2XOWE7BvPuUzLJ9-g4wAA02Y"]
[Thu Jul 30 15:38:53.050788 2026] [security2:error] [pid 189611:tid 189728] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/adminfuns.php"] [unique_id "amu2XeWE7BvPuUzLJ9-g5gAAtnQ"]
[Thu Jul 30 15:38:53.059951 2026] [security2:error] [pid 189611:tid 189741] [client 20.171.55.167:2458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/homeadmin.php"] [unique_id "amu2XeWE7BvPuUzLJ9-g6AAAAIU"]
[Thu Jul 30 15:38:53.181363 2026] [core:notice] [pid 189611:tid 189668] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:53.405860 2026] [core:notice] [pid 189611:tid 189712] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:53.463746 2026] [security2:error] [pid 189611:tid 189812] [client 191.232.199.39:48603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/mah.php"] [unique_id "amu2XeWE7BvPuUzLJ9-g8QAAAMw"]
[Thu Jul 30 15:38:53.481152 2026] [security2:error] [pid 189611:tid 189836] [client 38.172.162.57:16038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2XeWE7BvPuUzLJ9-g8gAAAOQ"]
[Thu Jul 30 15:38:53.481244 2026] [security2:error] [pid 189611:tid 189836] [client 38.172.162.57:16038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2XeWE7BvPuUzLJ9-g8gAAAOQ"]
[Thu Jul 30 15:38:53.536740 2026] [security2:error] [pid 189611:tid 189716] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/fm.php"] [unique_id "amu2XeWE7BvPuUzLJ9-g8wAA42g"]
[Thu Jul 30 15:38:53.759266 2026] [core:notice] [pid 189611:tid 189715] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:53.865066 2026] [security2:error] [pid 189611:tid 189809] [client 20.171.55.167:2501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/i0004en.php//wp-content/uploads/bk/index.php"] [unique_id "amu2XeWE7BvPuUzLJ9-g_gAAAMk"]
[Thu Jul 30 15:38:53.892268 2026] [security2:error] [pid 189611:tid 189726] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/file.php"] [unique_id "amu2XeWE7BvPuUzLJ9-g_wAAsnI"]
[Thu Jul 30 15:38:53.971689 2026] [security2:error] [pid 189611:tid 189752] [client 172.237.109.114:53846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/sp-rental-manager/readme.txt"] [unique_id "amu2XeWE7BvPuUzLJ9-hAgAAAJA"]
[Thu Jul 30 15:38:53.972498 2026] [core:notice] [pid 189611:tid 189818] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:53.998876 2026] [security2:error] [pid 189611:tid 189791] [client 20.91.199.21:7662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "amu2XeWE7BvPuUzLJ9-hAwAAALc"]
[Thu Jul 30 15:38:54.023230 2026] [core:notice] [pid 189611:tid 189701] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:54.042105 2026] [security2:error] [pid 189611:tid 189708] [remote 57.141.0.70:39104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/718396362/feed/rss2/"] [unique_id "amu2XuWE7BvPuUzLJ9-hBQAA7mA"]
[Thu Jul 30 15:38:54.158134 2026] [security2:error] [pid 189611:tid 189722] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/bolt.php"] [unique_id "amu2XuWE7BvPuUzLJ9-hCQAA6m4"]
[Thu Jul 30 15:38:54.359760 2026] [security2:error] [pid 189611:tid 189700] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/3.php"] [unique_id "amu2XuWE7BvPuUzLJ9-hEAAA-1g"]
[Thu Jul 30 15:38:54.465874 2026] [core:notice] [pid 189611:tid 189856] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:54.563400 2026] [security2:error] [pid 189611:tid 189724] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/222.php"] [unique_id "amu2XuWE7BvPuUzLJ9-hEgAAnXA"]
[Thu Jul 30 15:38:54.708454 2026] [security2:error] [pid 189611:tid 189861] [client 20.171.55.167:2523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/imagesalfa.php"] [unique_id "amu2XuWE7BvPuUzLJ9-hGQAAAP0"]
[Thu Jul 30 15:38:54.747549 2026] [security2:error] [pid 189611:tid 189725] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amu2XuWE7BvPuUzLJ9-hGgAA8XE"]
[Thu Jul 30 15:38:54.888945 2026] [security2:error] [pid 189611:tid 189721] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amu2XuWE7BvPuUzLJ9-hHgAAwW0"]
[Thu Jul 30 15:38:54.899178 2026] [security2:error] [pid 189611:tid 189855] [client 191.232.199.39:49618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/send.php"] [unique_id "amu2XuWE7BvPuUzLJ9-hHwAAAPc"]
[Thu Jul 30 15:38:55.002151 2026] [security2:error] [pid 189611:tid 189800] [client 20.91.199.21:1296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/images/cloud.php"] [unique_id "amu2X-WE7BvPuUzLJ9-hIAAAAMA"]
[Thu Jul 30 15:38:55.047804 2026] [security2:error] [pid 189611:tid 189717] [remote 216.73.216.51:28239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu2X-WE7BvPuUzLJ9-hIQAA-Wk"]
[Thu Jul 30 15:38:55.085684 2026] [core:notice] [pid 189611:tid 189727] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:55.223372 2026] [security2:error] [pid 189611:tid 189719] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/admin.php"] [unique_id "amu2X-WE7BvPuUzLJ9-hJgAAi2s"]
[Thu Jul 30 15:38:55.351480 2026] [security2:error] [pid 189611:tid 189616] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-configs.php"] [unique_id "amu2X-WE7BvPuUzLJ9-hKgAAxAQ"]
[Thu Jul 30 15:38:55.498204 2026] [security2:error] [pid 189611:tid 189735] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/php.php"] [unique_id "amu2X-WE7BvPuUzLJ9-hLgABAXs"]
[Thu Jul 30 15:38:55.627552 2026] [security2:error] [pid 189611:tid 189733] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/index.php"] [unique_id "amu2X-WE7BvPuUzLJ9-hLwAAsXk"]
[Thu Jul 30 15:38:55.785774 2026] [security2:error] [pid 189611:tid 189667] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/a.php"] [unique_id "amu2X-WE7BvPuUzLJ9-hNwAAkTc"]
[Thu Jul 30 15:38:55.958097 2026] [core:notice] [pid 189611:tid 189621] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:56.014440 2026] [security2:error] [pid 189611:tid 189781] [client 20.171.55.167:2474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/index.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hPAAAAK0"]
[Thu Jul 30 15:38:56.142609 2026] [core:notice] [pid 189611:tid 189729] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:56.276747 2026] [security2:error] [pid 189611:tid 189620] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hRAAArAg"]
[Thu Jul 30 15:38:56.369308 2026] [security2:error] [pid 189611:tid 189835] [client 191.232.199.39:49600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hSAAAAOM"]
[Thu Jul 30 15:38:56.404513 2026] [security2:error] [pid 189611:tid 189622] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hSQAAkAo"]
[Thu Jul 30 15:38:56.532970 2026] [security2:error] [pid 189611:tid 189731] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/size.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hTQAAsHc"]
[Thu Jul 30 15:38:56.626850 2026] [security2:error] [pid 189611:tid 189868] [client 57.141.0.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hPwAAAQQ"]
[Thu Jul 30 15:38:56.660470 2026] [security2:error] [pid 189611:tid 189615] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/wp-class.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hTgAAuwM"]
[Thu Jul 30 15:38:56.788939 2026] [security2:error] [pid 189611:tid 189648] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/403.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hUgAA6SQ"]
[Thu Jul 30 15:38:56.800061 2026] [security2:error] [pid 189611:tid 189796] [client 20.171.55.167:2558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/intense/block-css.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hUwAAALw"]
[Thu Jul 30 15:38:56.967449 2026] [security2:error] [pid 189611:tid 189618] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amu2YOWE7BvPuUzLJ9-hWwAAwgY"]
[Thu Jul 30 15:38:57.145448 2026] [security2:error] [pid 189611:tid 189645] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/as.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hXAAAlSE"]
[Thu Jul 30 15:38:57.275326 2026] [security2:error] [pid 189611:tid 189614] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/includes/index.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hXgAAywI"]
[Thu Jul 30 15:38:57.401780 2026] [core:notice] [pid 189611:tid 189750] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:57.404763 2026] [security2:error] [pid 189611:tid 189624] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hZAAAwQw"]
[Thu Jul 30 15:38:57.512236 2026] [core:notice] [pid 189611:tid 189612] AH00113: /home1/vdbnyxte/public_html/website_e4dc3cbf/.htaccess:13 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:57.569461 2026] [security2:error] [pid 189611:tid 189734] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/plugins.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hbQAApHo"]
[Thu Jul 30 15:38:57.692755 2026] [security2:error] [pid 189611:tid 189826] [client 20.215.191.139:35427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/Newsupway.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hbgAAANo"]
[Thu Jul 30 15:38:57.699447 2026] [security2:error] [pid 189611:tid 189641] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/js/index.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hbwAAox0"]
[Thu Jul 30 15:38:57.711596 2026] [security2:error] [pid 189611:tid 189805] [client 20.171.55.167:2503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/jcrop/jcrop.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hcAAAAMU"]
[Thu Jul 30 15:38:57.741187 2026] [security2:error] [pid 189611:tid 189817] [client 57.141.0.55:34446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koriusa.info"] [uri "/index.php"] [unique_id "amu2X-WE7BvPuUzLJ9-hMAAA0Xw"]
[Thu Jul 30 15:38:57.810409 2026] [security2:error] [pid 189611:tid 189803] [client 20.91.199.21:10135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/avaa.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hcgAAAMM"]
[Thu Jul 30 15:38:57.831558 2026] [security2:error] [pid 189611:tid 189638] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/go.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hdAAAzRo"]
[Thu Jul 30 15:38:57.960931 2026] [security2:error] [pid 189611:tid 189632] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/test1.php"] [unique_id "amu2YeWE7BvPuUzLJ9-hegAAlhQ"]
[Thu Jul 30 15:38:58.089620 2026] [core:notice] [pid 189611:tid 189652] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:58.225689 2026] [security2:error] [pid 189611:tid 189659] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/images/index.php"] [unique_id "amu2YuWE7BvPuUzLJ9-hgwABAi8"]
[Thu Jul 30 15:38:58.362179 2026] [autoindex:error] [pid 189611:tid 189863] [client 3.228.112.215:11018] AH01276: Cannot serve directory /home2/tgvgzjte/public_html/website_65bcc734/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:38:58.364585 2026] [core:notice] [pid 189611:tid 189628] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:58.414735 2026] [security2:error] [pid 189611:tid 189809] [client 191.232.199.39:49653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/about.php"] [unique_id "amu2YuWE7BvPuUzLJ9-hjAAAAMk"]
[Thu Jul 30 15:38:58.457508 2026] [security2:error] [pid 189611:tid 189776] [client 20.215.191.139:39643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/a.php"] [unique_id "amu2YuWE7BvPuUzLJ9-hjgAAAKg"]
[Thu Jul 30 15:38:58.494828 2026] [security2:error] [pid 189611:tid 189665] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/asd.php"] [unique_id "amu2YuWE7BvPuUzLJ9-hjwAArzU"]
[Thu Jul 30 15:38:58.589633 2026] [security2:error] [pid 189611:tid 189836] [client 20.171.55.167:2549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/jqphfkxu.php"] [unique_id "amu2YuWE7BvPuUzLJ9-hkwAAAOQ"]
[Thu Jul 30 15:38:58.685167 2026] [security2:error] [pid 189611:tid 189627] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/customize/index.php"] [unique_id "amu2YuWE7BvPuUzLJ9-hlAAAmA8"]
[Thu Jul 30 15:38:58.815427 2026] [security2:error] [pid 189611:tid 189673] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "amu2YuWE7BvPuUzLJ9-hlQAA6T0"]
[Thu Jul 30 15:38:58.949510 2026] [security2:error] [pid 189611:tid 189656] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/atomlib.php"] [unique_id "amu2YuWE7BvPuUzLJ9-hnAAA2yw"]
[Thu Jul 30 15:38:58.969708 2026] [core:notice] [pid 189611:tid 189756] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:59.126049 2026] [core:notice] [pid 189611:tid 189670] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:59.257875 2026] [core:notice] [pid 189611:tid 189720] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:59.332111 2026] [security2:error] [pid 189611:tid 189761] [client 20.171.55.167:2521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/kndw1.php"] [unique_id "amu2Y-WE7BvPuUzLJ9-howAAAJk"]
[Thu Jul 30 15:38:59.352596 2026] [security2:error] [pid 189611:tid 189768] [client 20.215.191.139:35368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "amu2Y-WE7BvPuUzLJ9-hpwAAAKA"]
[Thu Jul 30 15:38:59.389232 2026] [security2:error] [pid 189611:tid 189681] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/IXR/chosen.php"] [unique_id "amu2Y-WE7BvPuUzLJ9-hqwAA_UU"]
[Thu Jul 30 15:38:59.447801 2026] [security2:error] [pid 189611:tid 189798] [client 141.98.102.227:52182] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amu2Y-WE7BvPuUzLJ9-hrAAAAL4"]
[Thu Jul 30 15:38:59.447947 2026] [security2:error] [pid 189611:tid 189798] [client 141.98.102.227:52182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "worldofwhiskers.com"] [uri "/xmlrpc.php"] [unique_id "amu2Y-WE7BvPuUzLJ9-hrAAAAL4"]
[Thu Jul 30 15:38:59.477701 2026] [core:notice] [pid 189611:tid 189867] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:59.518629 2026] [core:notice] [pid 189611:tid 189688] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:59.653231 2026] [core:notice] [pid 189611:tid 189696] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:59.848329 2026] [core:notice] [pid 189611:tid 189674] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:38:59.986388 2026] [security2:error] [pid 189611:tid 189817] [client 20.215.191.139:40987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/amaxx.php"] [unique_id "amu2Y-WE7BvPuUzLJ9-hvgAAANE"]
[Thu Jul 30 15:39:00.014066 2026] [security2:error] [pid 189611:tid 189664] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/inputs.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-hvwAAiTQ"]
[Thu Jul 30 15:39:00.037757 2026] [security2:error] [pid 189611:tid 189826] [client 191.232.199.39:46563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/options.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-hwAAAANo"]
[Thu Jul 30 15:39:00.090451 2026] [security2:error] [pid 189611:tid 189803] [client 20.171.55.167:2310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/legal.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-hwQAAAMM"]
[Thu Jul 30 15:39:00.143223 2026] [security2:error] [pid 189611:tid 189643] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/index.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-hxQAA7B8"]
[Thu Jul 30 15:39:00.309635 2026] [security2:error] [pid 189611:tid 189661] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/network/index.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-hxgAAmjE"]
[Thu Jul 30 15:39:00.353332 2026] [security2:error] [pid 189611:tid 189675] [remote 57.141.0.10:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/64637765089/feed/rss2/"] [unique_id "amu2ZOWE7BvPuUzLJ9-hxwAAtD8"]
[Thu Jul 30 15:39:00.437409 2026] [security2:error] [pid 189611:tid 189686] [remote 172.213.208.20:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "teknomalay.com"] [uri "/wp-content/1.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-hywAAjEo"]
[Thu Jul 30 15:39:00.437532 2026] [security2:error] [pid 189611:tid 189686] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/1.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-hywAAjEo"]
[Thu Jul 30 15:39:00.596361 2026] [security2:error] [pid 189611:tid 189655] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/plugin.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-h0wAA5Cs"]
[Thu Jul 30 15:39:00.709776 2026] [security2:error] [pid 189611:tid 189672] [remote 216.73.216.51:1135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amu2ZOWE7BvPuUzLJ9-h1AAAyTw"]
[Thu Jul 30 15:39:00.727725 2026] [security2:error] [pid 189611:tid 189690] [remote 172.213.208.20:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "teknomalay.com"] [uri "/1.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-h1gABBE4"]
[Thu Jul 30 15:39:00.727835 2026] [security2:error] [pid 189611:tid 189690] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/1.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-h1gABBE4"]
[Thu Jul 30 15:39:00.868787 2026] [security2:error] [pid 189611:tid 189680] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/gg.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-h1wAA50Q"]
[Thu Jul 30 15:39:00.881153 2026] [security2:error] [pid 189611:tid 189784] [client 20.171.55.167:2432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/linkpreview/k.php"] [unique_id "amu2ZOWE7BvPuUzLJ9-h2AAAALA"]
[Thu Jul 30 15:39:01.004942 2026] [core:notice] [pid 189611:tid 189693] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:01.046448 2026] [security2:error] [pid 189611:tid 189752] [client 20.91.199.21:6525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/images/cloud.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h4AAAAJA"]
[Thu Jul 30 15:39:01.160863 2026] [security2:error] [pid 189611:tid 189760] [client 20.215.191.139:38074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/bb.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h5AAAAJg"]
[Thu Jul 30 15:39:01.190310 2026] [security2:error] [pid 189611:tid 189684] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h5QAA1Ug"]
[Thu Jul 30 15:39:01.366130 2026] [security2:error] [pid 189611:tid 189662] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h5wAAoDI"]
[Thu Jul 30 15:39:01.496246 2026] [security2:error] [pid 189611:tid 189709] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/file.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h6wAA-mE"]
[Thu Jul 30 15:39:01.562135 2026] [security2:error] [pid 189611:tid 189827] [client 191.232.199.39:46542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-content/themes/index.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h7QAAANs"]
[Thu Jul 30 15:39:01.625846 2026] [security2:error] [pid 189611:tid 189713] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/user/index.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h8QAAy2U"]
[Thu Jul 30 15:39:01.653470 2026] [security2:error] [pid 189611:tid 189856] [client 20.171.55.167:2489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/locale.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h9AAAAPg"]
[Thu Jul 30 15:39:01.798906 2026] [core:notice] [pid 189611:tid 189679] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:01.931554 2026] [security2:error] [pid 189611:tid 189691] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h9wAAiE8"]
[Thu Jul 30 15:39:02.060015 2026] [security2:error] [pid 189611:tid 189714] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/index/function.php"] [unique_id "amu2ZuWE7BvPuUzLJ9-h_gAA5WY"]
[Thu Jul 30 15:39:02.070024 2026] [security2:error] [pid 189611:tid 189750] [client 20.215.191.139:40962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/cifcxgxm.php"] [unique_id "amu2ZuWE7BvPuUzLJ9-h_wAAAI4"]
[Thu Jul 30 15:39:02.084070 2026] [security2:error] [pid 189611:tid 189763] [client 20.91.199.21:15592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "amu2ZuWE7BvPuUzLJ9-iAAAAAJs"]
[Thu Jul 30 15:39:02.187902 2026] [security2:error] [pid 189611:tid 189769] [client 2a03:2880:f800:12:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2ZeWE7BvPuUzLJ9-h7AAAoVU"]
[Thu Jul 30 15:39:02.214596 2026] [security2:error] [pid 189611:tid 189777] [client 152.32.131.245:33972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.mediaspawn.com"] [uri "/index.php"] [unique_id "amu2ZuWE7BvPuUzLJ9-iAQAAAKk"]
[Thu Jul 30 15:39:02.220510 2026] [core:notice] [pid 189611:tid 189658] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:02.353595 2026] [core:notice] [pid 189611:tid 189650] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:02.422589 2026] [security2:error] [pid 189611:tid 189819] [client 20.171.55.167:2554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/lztxdiyi.php"] [unique_id "amu2ZuWE7BvPuUzLJ9-iBwAAANM"]
[Thu Jul 30 15:39:02.486378 2026] [security2:error] [pid 189611:tid 189668] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/aaa.php"] [unique_id "amu2ZuWE7BvPuUzLJ9-iCAAAhjg"]
[Thu Jul 30 15:39:02.618291 2026] [security2:error] [pid 189611:tid 189712] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/getid3-core.php"] [unique_id "amu2ZuWE7BvPuUzLJ9-iDAAA72Q"]
[Thu Jul 30 15:39:02.747669 2026] [security2:error] [pid 189611:tid 189715] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/adminer.php"] [unique_id "amu2ZuWE7BvPuUzLJ9-iFAAA62c"]
[Thu Jul 30 15:39:02.880437 2026] [core:notice] [pid 189611:tid 189698] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:02.972358 2026] [security2:error] [pid 189611:tid 189726] [remote 74.7.243.224:51850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/article.php"] [unique_id "amu2ZuWE7BvPuUzLJ9-iFgAA_nI"], referer: https://aded-rdc.org/author/aded/js/uploads/partners/uploads/partners/uploads/partners/js/img/1784117929_IMG_3676.jpg
[Thu Jul 30 15:39:03.012916 2026] [security2:error] [pid 189611:tid 189708] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/alfa.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iGAAAuGA"]
[Thu Jul 30 15:39:03.031011 2026] [security2:error] [pid 189611:tid 189743] [client 20.215.191.139:38042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/ckyocyyp.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iGwAAAIc"]
[Thu Jul 30 15:39:03.194366 2026] [core:notice] [pid 189611:tid 189704] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:03.213066 2026] [security2:error] [pid 189611:tid 189783] [client 20.171.55.167:2471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/majalahpro-core/lib/external/index.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iIAAAAK8"]
[Thu Jul 30 15:39:03.331996 2026] [security2:error] [pid 189611:tid 189700] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iJAAA11g"]
[Thu Jul 30 15:39:03.503673 2026] [security2:error] [pid 189611:tid 189705] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iJQAA4l0"]
[Thu Jul 30 15:39:03.683611 2026] [security2:error] [pid 189611:tid 189723] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iLQAAmG8"]
[Thu Jul 30 15:39:03.701962 2026] [security2:error] [pid 189611:tid 189852] [client 20.215.191.139:39627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/classwithtostring.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iLgAAAPQ"]
[Thu Jul 30 15:39:03.862592 2026] [security2:error] [pid 189611:tid 189721] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/edit.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iMgAA8W0"]
[Thu Jul 30 15:39:03.916867 2026] [security2:error] [pid 189611:tid 189757] [client 141.98.102.227:48128] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iMwAAAJU"]
[Thu Jul 30 15:39:03.916967 2026] [security2:error] [pid 189611:tid 189757] [client 141.98.102.227:48128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thdinfinity.com"] [uri "/xmlrpc.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iMwAAAJU"]
[Thu Jul 30 15:39:04.091498 2026] [security2:error] [pid 189611:tid 189828] [client 38.172.162.57:16528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2aOWE7BvPuUzLJ9-iNAAAANw"]
[Thu Jul 30 15:39:04.091632 2026] [security2:error] [pid 189611:tid 189828] [client 38.172.162.57:16528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2aOWE7BvPuUzLJ9-iNAAAANw"]
[Thu Jul 30 15:39:04.117871 2026] [security2:error] [pid 189611:tid 189848] [client 20.171.55.167:2524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/maw.php"] [unique_id "amu2aOWE7BvPuUzLJ9-iOAAAAPA"]
[Thu Jul 30 15:39:04.155820 2026] [security2:error] [pid 189611:tid 189780] [client 2a03:2880:f800:38:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2Z-WE7BvPuUzLJ9-iJgAArHA"]
[Thu Jul 30 15:39:04.166382 2026] [security2:error] [pid 189611:tid 189776] [client 191.232.199.39:46533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/wp-file.php"] [unique_id "amu2aOWE7BvPuUzLJ9-iPAAAAKg"]
[Thu Jul 30 15:39:04.244452 2026] [core:notice] [pid 189611:tid 189727] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:04.291915 2026] [proxy:error] [pid 189611:tid 189855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:04.292023 2026] [proxy_http:error] [pid 189611:tid 189855] [client 98.87.102.177:25192] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:04.292711 2026] [proxy:error] [pid 189611:tid 189855] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:04.292760 2026] [proxy_http:error] [pid 189611:tid 189855] [client 98.87.102.177:25192] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:04.312589 2026] [proxy:error] [pid 189611:tid 189747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:04.312656 2026] [proxy_http:error] [pid 189611:tid 189747] [client 98.87.102.177:21011] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:04.313213 2026] [proxy:error] [pid 189611:tid 189747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:04.313257 2026] [proxy_http:error] [pid 189611:tid 189747] [client 98.87.102.177:21011] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:04.451037 2026] [security2:error] [pid 189611:tid 189800] [client 157.90.156.63:5704] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "womenclothingbox.com"] [uri "/refund-policy/"] [unique_id "amu2aOWE7BvPuUzLJ9-iSQAAAMA"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:39:04.455221 2026] [security2:error] [pid 189611:tid 189793] [client 20.91.199.21:15611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "amu2aOWE7BvPuUzLJ9-iSgAAALk"]
[Thu Jul 30 15:39:04.530914 2026] [core:notice] [pid 189611:tid 189703] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:04.664949 2026] [security2:error] [pid 189611:tid 189739] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/sf.php"] [unique_id "amu2aOWE7BvPuUzLJ9-iUAAAln8"]
[Thu Jul 30 15:39:04.669857 2026] [security2:error] [pid 189611:tid 189861] [client 172.237.109.114:62244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu2aOWE7BvPuUzLJ9-iNQAAAP0"]
[Thu Jul 30 15:39:04.797173 2026] [core:notice] [pid 189611:tid 189733] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:04.833420 2026] [core:notice] [pid 189611:tid 189851] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:04.837583 2026] [security2:error] [pid 189611:tid 189851] [client 157.90.156.63:5710] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/"] [unique_id "amu2aOWE7BvPuUzLJ9-iVQAAAPM"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:39:04.872814 2026] [security2:error] [pid 189611:tid 189853] [client 20.171.55.167:2452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/mega.php"] [unique_id "amu2aOWE7BvPuUzLJ9-iWQAAAPU"]
[Thu Jul 30 15:39:04.932835 2026] [security2:error] [pid 189611:tid 189707] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wso.php"] [unique_id "amu2aOWE7BvPuUzLJ9-iWgAAvV8"]
[Thu Jul 30 15:39:05.061178 2026] [security2:error] [pid 189611:tid 189619] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/ioxi-o.php"] [unique_id "amu2aeWE7BvPuUzLJ9-iWwAA6wc"]
[Thu Jul 30 15:39:05.081665 2026] [security2:error] [pid 189611:tid 189621] [remote 57.141.0.38:37628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu2aeWE7BvPuUzLJ9-iXQAA7wk"]
[Thu Jul 30 15:39:05.189749 2026] [security2:error] [pid 189611:tid 189623] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/file56.php"] [unique_id "amu2aeWE7BvPuUzLJ9-iYQAA5As"]
[Thu Jul 30 15:39:05.341310 2026] [security2:error] [pid 189611:tid 189818] [client 157.90.156.63:5722] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amu2aeWE7BvPuUzLJ9-iaAAAANI"], referer: http://gpstrackerforandroid.com
[Thu Jul 30 15:39:05.367934 2026] [security2:error] [pid 189611:tid 189622] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "amu2aeWE7BvPuUzLJ9-iaQAAvAo"]
[Thu Jul 30 15:39:05.497500 2026] [security2:error] [pid 189611:tid 189731] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-admin/css/index.php"] [unique_id "amu2aeWE7BvPuUzLJ9-ibQAAkHc"]
[Thu Jul 30 15:39:05.545161 2026] [security2:error] [pid 189611:tid 189766] [client 57.141.0.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2aeWE7BvPuUzLJ9-iZwAAAJ4"]
[Thu Jul 30 15:39:05.608422 2026] [security2:error] [pid 189611:tid 189781] [client 20.91.199.21:7225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "amu2aeWE7BvPuUzLJ9-icQAAAK0"]
[Thu Jul 30 15:39:05.632136 2026] [security2:error] [pid 189611:tid 189625] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/edit.php"] [unique_id "amu2aeWE7BvPuUzLJ9-icgAAnw0"]
[Thu Jul 30 15:39:05.666716 2026] [security2:error] [pid 189611:tid 189782] [client 20.171.55.167:2469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/module.audio-video.matroska-meta.php"] [unique_id "amu2aeWE7BvPuUzLJ9-icwAAAK4"]
[Thu Jul 30 15:39:05.762064 2026] [security2:error] [pid 189611:tid 189648] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/2.php"] [unique_id "amu2aeWE7BvPuUzLJ9-idwAAmSQ"]
[Thu Jul 30 15:39:05.825468 2026] [security2:error] [pid 189611:tid 189779] [client 191.232.199.39:48615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pkfiraq.com"] [uri "/sid3.php"] [unique_id "amu2aeWE7BvPuUzLJ9-iewAAAKs"]
[Thu Jul 30 15:39:05.890094 2026] [security2:error] [pid 189611:tid 189732] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "amu2aeWE7BvPuUzLJ9-ifAAArHg"]
[Thu Jul 30 15:39:06.019492 2026] [security2:error] [pid 189611:tid 189618] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/mah.php"] [unique_id "amu2auWE7BvPuUzLJ9-igQAA-AY"]
[Thu Jul 30 15:39:06.188585 2026] [security2:error] [pid 189611:tid 189614] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/send.php"] [unique_id "amu2auWE7BvPuUzLJ9-ihAAAjwI"]
[Thu Jul 30 15:39:06.362688 2026] [security2:error] [pid 189611:tid 189855] [client 20.215.191.139:35353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/content.php"] [unique_id "amu2auWE7BvPuUzLJ9-ijAAAAPc"]
[Thu Jul 30 15:39:06.371036 2026] [security2:error] [pid 189611:tid 189636] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "amu2auWE7BvPuUzLJ9-ijQAAkhg"]
[Thu Jul 30 15:39:06.384437 2026] [security2:error] [pid 189611:tid 189813] [client 20.79.29.209:16240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/modul.php"] [unique_id "amu2auWE7BvPuUzLJ9-ijgAAAM0"]
[Thu Jul 30 15:39:06.384531 2026] [security2:error] [pid 189611:tid 189813] [client 20.79.29.209:16240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/modul.php"] [unique_id "amu2auWE7BvPuUzLJ9-ijgAAAM0"]
[Thu Jul 30 15:39:06.391259 2026] [security2:error] [pid 189611:tid 189822] [client 20.171.55.167:2336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ms.php"] [unique_id "amu2auWE7BvPuUzLJ9-ijwAAANY"]
[Thu Jul 30 15:39:06.502966 2026] [core:notice] [pid 189611:tid 189633] AH00113: /home1/vdbnyxte/public_html/website_167e4a7a/.htaccess:15 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:06.633541 2026] [security2:error] [pid 189611:tid 189734] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/about.php"] [unique_id "amu2auWE7BvPuUzLJ9-ilAAAlno"]
[Thu Jul 30 15:39:06.654909 2026] [security2:error] [pid 189611:tid 189785] [client 20.79.29.209:16206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/configuration.php"] [unique_id "amu2auWE7BvPuUzLJ9-ilQAAALE"]
[Thu Jul 30 15:39:06.655021 2026] [security2:error] [pid 189611:tid 189785] [client 20.79.29.209:16206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/configuration.php"] [unique_id "amu2auWE7BvPuUzLJ9-ilQAAALE"]
[Thu Jul 30 15:39:06.762068 2026] [security2:error] [pid 189611:tid 189736] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/options.php"] [unique_id "amu2auWE7BvPuUzLJ9-imQAAv3w"]
[Thu Jul 30 15:39:06.783485 2026] [core:notice] [pid 189611:tid 189829] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:06.891649 2026] [security2:error] [pid 189611:tid 189626] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-content/themes/index.php"] [unique_id "amu2auWE7BvPuUzLJ9-ingAA9Q4"]
[Thu Jul 30 15:39:06.916278 2026] [security2:error] [pid 189611:tid 189775] [client 20.79.29.209:16229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/tai.php"] [unique_id "amu2auWE7BvPuUzLJ9-inwAAAKc"]
[Thu Jul 30 15:39:06.916375 2026] [security2:error] [pid 189611:tid 189775] [client 20.79.29.209:16229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/tai.php"] [unique_id "amu2auWE7BvPuUzLJ9-inwAAAKc"]
[Thu Jul 30 15:39:07.021671 2026] [security2:error] [pid 189611:tid 189632] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/wp-file.php"] [unique_id "amu2a-WE7BvPuUzLJ9-iowAA5hQ"]
[Thu Jul 30 15:39:07.131132 2026] [security2:error] [pid 189611:tid 189749] [client 20.215.191.139:35348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/content.php.suspected"] [unique_id "amu2a-WE7BvPuUzLJ9-ipQAAAI0"]
[Thu Jul 30 15:39:07.154111 2026] [security2:error] [pid 189611:tid 189630] [remote 172.213.208.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teknomalay.com"] [uri "/sid3.php"] [unique_id "amu2a-WE7BvPuUzLJ9-ipgAA7xI"]
[Thu Jul 30 15:39:07.170011 2026] [security2:error] [pid 189611:tid 189787] [client 20.91.199.21:1326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/includes/cloud.php"] [unique_id "amu2a-WE7BvPuUzLJ9-ipwAAALM"]
[Thu Jul 30 15:39:07.181027 2026] [security2:error] [pid 189611:tid 189835] [client 20.79.29.209:16244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/www.php"] [unique_id "amu2a-WE7BvPuUzLJ9-iqAAAAOM"]
[Thu Jul 30 15:39:07.181157 2026] [security2:error] [pid 189611:tid 189835] [client 20.79.29.209:16244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/www.php"] [unique_id "amu2a-WE7BvPuUzLJ9-iqAAAAOM"]
[Thu Jul 30 15:39:07.191603 2026] [security2:error] [pid 189611:tid 189851] [client 20.171.55.167:2482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/new-index.php"] [unique_id "amu2a-WE7BvPuUzLJ9-iqQAAAPM"]
[Thu Jul 30 15:39:07.411611 2026] [core:notice] [pid 189611:tid 189743] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:07.518662 2026] [security2:error] [pid 189611:tid 189846] [client 20.79.29.209:16197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/x13.php"] [unique_id "amu2a-WE7BvPuUzLJ9-itwAAAO4"]
[Thu Jul 30 15:39:07.518773 2026] [security2:error] [pid 189611:tid 189846] [client 20.79.29.209:16197] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/x13.php"] [unique_id "amu2a-WE7BvPuUzLJ9-itwAAAO4"]
[Thu Jul 30 15:39:07.726925 2026] [security2:error] [pid 189611:tid 189789] [client 20.215.191.139:35408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/doc.php"] [unique_id "amu2a-WE7BvPuUzLJ9-iuwAAALU"]
[Thu Jul 30 15:39:07.801461 2026] [security2:error] [pid 189611:tid 189832] [client 20.79.29.209:16158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/ntaps.php"] [unique_id "amu2a-WE7BvPuUzLJ9-ivQAAAOA"]
[Thu Jul 30 15:39:07.801576 2026] [security2:error] [pid 189611:tid 189832] [client 20.79.29.209:16158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/ntaps.php"] [unique_id "amu2a-WE7BvPuUzLJ9-ivQAAAOA"]
[Thu Jul 30 15:39:07.953458 2026] [security2:error] [pid 189611:tid 189852] [client 20.171.55.167:2552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/npi.php"] [unique_id "amu2a-WE7BvPuUzLJ9-iwwAAAPQ"]
[Thu Jul 30 15:39:08.063680 2026] [security2:error] [pid 189611:tid 189860] [client 20.79.29.209:16140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/zip.php"] [unique_id "amu2bOWE7BvPuUzLJ9-iygAAAPw"]
[Thu Jul 30 15:39:08.063788 2026] [security2:error] [pid 189611:tid 189860] [client 20.79.29.209:16140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/zip.php"] [unique_id "amu2bOWE7BvPuUzLJ9-iygAAAPw"]
[Thu Jul 30 15:39:08.129572 2026] [core:notice] [pid 189611:tid 189840] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:08.324607 2026] [security2:error] [pid 189611:tid 189753] [client 20.79.29.209:16247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/@.php"] [unique_id "amu2bOWE7BvPuUzLJ9-i0gAAAJE"]
[Thu Jul 30 15:39:08.324743 2026] [security2:error] [pid 189611:tid 189753] [client 20.79.29.209:16247] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/@.php"] [unique_id "amu2bOWE7BvPuUzLJ9-i0gAAAJE"]
[Thu Jul 30 15:39:08.607867 2026] [security2:error] [pid 189611:tid 189742] [client 20.79.29.209:16252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/ea.php"] [unique_id "amu2bOWE7BvPuUzLJ9-i1wAAAIY"]
[Thu Jul 30 15:39:08.608018 2026] [security2:error] [pid 189611:tid 189742] [client 20.79.29.209:16252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/ea.php"] [unique_id "amu2bOWE7BvPuUzLJ9-i1wAAAIY"]
[Thu Jul 30 15:39:08.851506 2026] [security2:error] [pid 189611:tid 189759] [client 20.171.55.167:2315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/optimizer.php"] [unique_id "amu2bOWE7BvPuUzLJ9-i3wAAAJc"]
[Thu Jul 30 15:39:08.872790 2026] [security2:error] [pid 189611:tid 189831] [client 20.79.29.209:16250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/aaaa.php"] [unique_id "amu2bOWE7BvPuUzLJ9-i4gAAAN8"]
[Thu Jul 30 15:39:08.872882 2026] [security2:error] [pid 189611:tid 189831] [client 20.79.29.209:16250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/aaaa.php"] [unique_id "amu2bOWE7BvPuUzLJ9-i4gAAAN8"]
[Thu Jul 30 15:39:09.075371 2026] [security2:error] [pid 189611:tid 189767] [client 20.91.199.21:7675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "amu2beWE7BvPuUzLJ9-i5QAAAJ8"]
[Thu Jul 30 15:39:09.133113 2026] [security2:error] [pid 189611:tid 189792] [client 20.79.29.209:16222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/cinfo.php"] [unique_id "amu2beWE7BvPuUzLJ9-i6QAAALg"]
[Thu Jul 30 15:39:09.133225 2026] [security2:error] [pid 189611:tid 189792] [client 20.79.29.209:16222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/cinfo.php"] [unique_id "amu2beWE7BvPuUzLJ9-i6QAAALg"]
[Thu Jul 30 15:39:09.453686 2026] [security2:error] [pid 189611:tid 189866] [client 20.79.29.209:16129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/newfile.php"] [unique_id "amu2beWE7BvPuUzLJ9-i8QAAAQI"]
[Thu Jul 30 15:39:09.453785 2026] [security2:error] [pid 189611:tid 189866] [client 20.79.29.209:16129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/newfile.php"] [unique_id "amu2beWE7BvPuUzLJ9-i8QAAAQI"]
[Thu Jul 30 15:39:09.628221 2026] [security2:error] [pid 189611:tid 189796] [client 20.171.55.167:2467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/pageb.php"] [unique_id "amu2beWE7BvPuUzLJ9-i8gAAALw"]
[Thu Jul 30 15:39:09.714218 2026] [security2:error] [pid 189611:tid 189743] [client 20.79.29.209:16242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/pro.php"] [unique_id "amu2beWE7BvPuUzLJ9-i9gAAAIc"]
[Thu Jul 30 15:39:09.714310 2026] [security2:error] [pid 189611:tid 189743] [client 20.79.29.209:16242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/pro.php"] [unique_id "amu2beWE7BvPuUzLJ9-i9gAAAIc"]
[Thu Jul 30 15:39:09.815955 2026] [core:notice] [pid 189611:tid 189813] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:09.985425 2026] [security2:error] [pid 189611:tid 189757] [client 20.79.29.209:16235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/edit.php"] [unique_id "amu2beWE7BvPuUzLJ9-i_gAAAJU"]
[Thu Jul 30 15:39:09.985530 2026] [security2:error] [pid 189611:tid 189757] [client 20.79.29.209:16235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/edit.php"] [unique_id "amu2beWE7BvPuUzLJ9-i_gAAAJU"]
[Thu Jul 30 15:39:10.079923 2026] [security2:error] [pid 189611:tid 189765] [client 172.237.109.114:57835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/wp-cloudy/readme.txt"] [unique_id "amu2buWE7BvPuUzLJ9-jAQAAAJ0"]
[Thu Jul 30 15:39:10.249668 2026] [security2:error] [pid 189611:tid 189772] [client 20.79.29.209:16241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/11.php"] [unique_id "amu2buWE7BvPuUzLJ9-jBgAAAKQ"]
[Thu Jul 30 15:39:10.249785 2026] [security2:error] [pid 189611:tid 189772] [client 20.79.29.209:16241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/11.php"] [unique_id "amu2buWE7BvPuUzLJ9-jBgAAAKQ"]
[Thu Jul 30 15:39:10.372877 2026] [security2:error] [pid 189611:tid 189811] [client 20.171.55.167:2532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/phpadmin/acp.php"] [unique_id "amu2buWE7BvPuUzLJ9-jBwAAAMs"]
[Thu Jul 30 15:39:10.514080 2026] [security2:error] [pid 189611:tid 189801] [client 20.79.29.209:16151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/title.php"] [unique_id "amu2buWE7BvPuUzLJ9-jCwAAAME"]
[Thu Jul 30 15:39:10.514176 2026] [security2:error] [pid 189611:tid 189801] [client 20.79.29.209:16151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/title.php"] [unique_id "amu2buWE7BvPuUzLJ9-jCwAAAME"]
[Thu Jul 30 15:39:11.035720 2026] [security2:error] [pid 189611:tid 189804] [client 20.79.29.209:16146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/xmlrpc.php"] [unique_id "amu2buWE7BvPuUzLJ9-jEwAAAMQ"]
[Thu Jul 30 15:39:11.035816 2026] [security2:error] [pid 189611:tid 189804] [client 20.79.29.209:16146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/xmlrpc.php"] [unique_id "amu2buWE7BvPuUzLJ9-jEwAAAMQ"]
[Thu Jul 30 15:39:11.209450 2026] [security2:error] [pid 189611:tid 189741] [client 20.171.55.167:2451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/pi.php"] [unique_id "amu2b-WE7BvPuUzLJ9-jIgAAAIU"]
[Thu Jul 30 15:39:11.296508 2026] [security2:error] [pid 189611:tid 189863] [client 20.79.29.209:16195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/pass.php"] [unique_id "amu2b-WE7BvPuUzLJ9-jIwAAAP8"]
[Thu Jul 30 15:39:11.296624 2026] [security2:error] [pid 189611:tid 189863] [client 20.79.29.209:16195] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/pass.php"] [unique_id "amu2b-WE7BvPuUzLJ9-jIwAAAP8"]
[Thu Jul 30 15:39:11.474691 2026] [security2:error] [pid 189611:tid 189758] [client 191.96.227.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vanguardlegalassociates.team"] [uri "/index.php"] [unique_id "amu2b-WE7BvPuUzLJ9-jGgAAlh8"]
[Thu Jul 30 15:39:11.643108 2026] [security2:error] [pid 189611:tid 189807] [client 20.79.29.209:16159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.29.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.kevinderarslanian.com"] [uri "/Cpanel.php"] [unique_id "amu2b-WE7BvPuUzLJ9-jKwAAAMc"]
[Thu Jul 30 15:39:11.643218 2026] [security2:error] [pid 189611:tid 189807] [client 20.79.29.209:16159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.kevinderarslanian.com"] [uri "/Cpanel.php"] [unique_id "amu2b-WE7BvPuUzLJ9-jKwAAAMc"]
[Thu Jul 30 15:39:12.014316 2026] [autoindex:error] [pid 189611:tid 189766] [client 49.233.45.47:0] AH01276: Cannot serve directory /home2/mbmudite/otbola.click/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://otbola.click
[Thu Jul 30 15:39:12.016494 2026] [security2:error] [pid 189611:tid 189866] [client 20.171.55.167:2538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/pm.php"] [unique_id "amu2cOWE7BvPuUzLJ9-jMwAAAQI"]
[Thu Jul 30 15:39:12.256955 2026] [core:notice] [pid 189611:tid 189746] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:12.724779 2026] [core:notice] [pid 189611:tid 189776] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:12.900542 2026] [security2:error] [pid 189611:tid 189867] [client 20.171.55.167:2309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/price.php"] [unique_id "amu2cOWE7BvPuUzLJ9-jSAAAAQM"]
[Thu Jul 30 15:39:13.343063 2026] [security2:error] [pid 189611:tid 189684] [remote 47.128.27.97:44048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kicksity.com"] [uri "/product/ugg-w-classic-ultra-mini-all-black-and-velvet/"] [unique_id "amu2ceWE7BvPuUzLJ9-jVAAA2kg"]
[Thu Jul 30 15:39:13.709997 2026] [security2:error] [pid 189611:tid 189812] [client 20.171.55.167:2435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/profile.php"] [unique_id "amu2ceWE7BvPuUzLJ9-jWwAAAMw"]
[Thu Jul 30 15:39:13.987806 2026] [security2:error] [pid 189611:tid 189767] [client 20.215.191.139:36157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/fond.php"] [unique_id "amu2ceWE7BvPuUzLJ9-jXwAAAJ8"]
[Thu Jul 30 15:39:14.236169 2026] [security2:error] [pid 189611:tid 189838] [client 20.91.199.21:6453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/cloud.php"] [unique_id "amu2cuWE7BvPuUzLJ9-jZgAAAOY"]
[Thu Jul 30 15:39:14.541110 2026] [security2:error] [pid 189611:tid 189834] [client 20.171.55.167:2510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/pwnd-1/admin.php"] [unique_id "amu2cuWE7BvPuUzLJ9-jbAAAAOI"]
[Thu Jul 30 15:39:14.582770 2026] [security2:error] [pid 189611:tid 189695] [remote 57.141.0.29:27838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu2cuWE7BvPuUzLJ9-jbQAA7lM"]
[Thu Jul 30 15:39:14.752019 2026] [security2:error] [pid 189611:tid 189868] [client 38.172.162.57:15909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2cuWE7BvPuUzLJ9-jdQAAAQQ"]
[Thu Jul 30 15:39:14.752757 2026] [security2:error] [pid 189611:tid 189868] [client 38.172.162.57:15909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2cuWE7BvPuUzLJ9-jdQAAAQQ"]
[Thu Jul 30 15:39:14.752927 2026] [security2:error] [pid 189611:tid 189782] [client 152.32.131.245:60530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mediaspawn.com"] [uri "/index.php"] [unique_id "amu2cuWE7BvPuUzLJ9-jcQAAAK4"]
[Thu Jul 30 15:39:14.825680 2026] [security2:error] [pid 189611:tid 189796] [client 20.215.191.139:35373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/gkiliuew.php"] [unique_id "amu2cuWE7BvPuUzLJ9-jeQAAALw"]
[Thu Jul 30 15:39:15.781208 2026] [http2:info] [pid 215691:tid 215691] h2_workers: created with min=128 max=192 idle_ms=600000
[Thu Jul 30 15:39:15.799701 2026] [security2:error] [pid 215691:tid 215821] [client 220.181.108.92:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/8980"] [unique_id "amu2cwVxQfK7jpOg6v9HCgAAAAA"]
[Thu Jul 30 15:39:15.953628 2026] [security2:error] [pid 215691:tid 215826] [client 20.215.191.139:42711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/iR7SzrsOUEP.php"] [unique_id "amu2cwVxQfK7jpOg6v9HDQAAAAU"]
[Thu Jul 30 15:39:16.045501 2026] [security2:error] [pid 215691:tid 215822] [client 20.171.55.167:2539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/randkeyword.php"] [unique_id "amu2dAVxQfK7jpOg6v9HFwAAAAE"]
[Thu Jul 30 15:39:16.100219 2026] [security2:error] [pid 215691:tid 215830] [client 122.172.85.206:1613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2cwVxQfK7jpOg6v9HDAAAAAk"]
[Thu Jul 30 15:39:16.100417 2026] [security2:error] [pid 215691:tid 215830] [client 122.172.85.206:1613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2cwVxQfK7jpOg6v9HDAAAAAk"]
[Thu Jul 30 15:39:16.237493 2026] [security2:error] [pid 215691:tid 215851] [client 119.249.100.239:48814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.100.249.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ejournalugj.com"] [uri "/index.php/Euclid/article/view/8980"] [unique_id "amu2dAVxQfK7jpOg6v9HGAAAAB4"]
[Thu Jul 30 15:39:16.506377 2026] [security2:error] [pid 189611:tid 189797] [client 20.91.199.21:1387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/updates.php"] [unique_id "amu2dOWE7BvPuUzLJ9-jfwAAAL0"]
[Thu Jul 30 15:39:16.627338 2026] [security2:error] [pid 215691:tid 215863] [client 20.215.191.139:39640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/ibkejxnu.php"] [unique_id "amu2dAVxQfK7jpOg6v9HIwAAACo"]
[Thu Jul 30 15:39:16.914958 2026] [security2:error] [pid 215691:tid 215874] [client 20.171.55.167:2304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/revslider/includes/external/page/index.php"] [unique_id "amu2dAVxQfK7jpOg6v9HJQAAADU"]
[Thu Jul 30 15:39:17.204588 2026] [core:notice] [pid 215691:tid 215879] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:17.419825 2026] [security2:error] [pid 215691:tid 215895] [client 20.91.199.21:21067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/libraries/legacy/updates.php"] [unique_id "amu2dQVxQfK7jpOg6v9HMwAAAEo"]
[Thu Jul 30 15:39:17.699735 2026] [security2:error] [pid 215691:tid 215901] [client 20.171.55.167:2453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/rus.php"] [unique_id "amu2dQVxQfK7jpOg6v9HPQAAAFA"]
[Thu Jul 30 15:39:17.940841 2026] [core:notice] [pid 215691:tid 215884] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:18.220329 2026] [security2:error] [pid 215691:tid 215916] [client 20.91.199.21:1369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/libraries/phpmailer/updates.php"] [unique_id "amu2dgVxQfK7jpOg6v9HSgAAAF8"]
[Thu Jul 30 15:39:18.568255 2026] [security2:error] [pid 215691:tid 215941] [client 20.171.55.167:2548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/sct.php"] [unique_id "amu2dgVxQfK7jpOg6v9HVwAAAHg"]
[Thu Jul 30 15:39:19.081793 2026] [security2:error] [pid 215691:tid 215835] [client 20.91.199.21:21008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/libraries/vendor/updates.php"] [unique_id "amu2dwVxQfK7jpOg6v9HYQAAAA4"]
[Thu Jul 30 15:39:19.304837 2026] [security2:error] [pid 215691:tid 215864] [client 111.225.149.152:59262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiandubaisafari.com"] [uri "/assets/images/dubai-safari-basic-3.jpg"] [unique_id "amu2dwVxQfK7jpOg6v9HZQAAACs"]
[Thu Jul 30 15:39:19.474020 2026] [security2:error] [pid 215691:tid 215855] [client 20.171.55.167:2542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/seox/randkeyword.php"] [unique_id "amu2dwVxQfK7jpOg6v9HaQAAACI"]
[Thu Jul 30 15:39:19.612073 2026] [security2:error] [pid 215691:tid 215893] [client 20.215.191.139:36102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/install.php"] [unique_id "amu2dwVxQfK7jpOg6v9HcgAAAEg"]
[Thu Jul 30 15:39:19.700556 2026] [proxy:error] [pid 215691:tid 215889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:19.700615 2026] [proxy_http:error] [pid 215691:tid 215889] [client 34.224.175.62:18100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:19.701184 2026] [proxy:error] [pid 215691:tid 215889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:19.701229 2026] [proxy_http:error] [pid 215691:tid 215889] [client 34.224.175.62:18100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:19.796871 2026] [proxy:error] [pid 215691:tid 215895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:19.796939 2026] [proxy_http:error] [pid 215691:tid 215895] [client 32.194.121.99:9991] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:19.797572 2026] [proxy:error] [pid 215691:tid 215895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:19.797622 2026] [proxy_http:error] [pid 215691:tid 215895] [client 32.194.121.99:9991] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:20.047831 2026] [security2:error] [pid 215691:tid 215878] [client 20.91.199.21:29573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/alfa-rex.php7"] [unique_id "amu2eAVxQfK7jpOg6v9HfgAAADk"]
[Thu Jul 30 15:39:20.252034 2026] [security2:error] [pid 215691:tid 215911] [client 20.171.55.167:2320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/shell/noimg.php"] [unique_id "amu2eAVxQfK7jpOg6v9HiQAAAFo"]
[Thu Jul 30 15:39:20.364392 2026] [security2:error] [pid 215691:tid 215900] [client 20.215.191.139:35447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/lang-load-role.php"] [unique_id "amu2eAVxQfK7jpOg6v9HjAAAAE8"]
[Thu Jul 30 15:39:20.529073 2026] [security2:error] [pid 215691:tid 215723] [remote 216.73.216.51:57967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu2eAVxQfK7jpOg6v9HkAAAah8"]
[Thu Jul 30 15:39:21.085450 2026] [security2:error] [pid 215691:tid 215821] [client 20.171.55.167:2463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/sidwso.php"] [unique_id "amu2eQVxQfK7jpOg6v9HnQAAAAA"]
[Thu Jul 30 15:39:21.099849 2026] [security2:error] [pid 215691:tid 215829] [client 20.215.191.139:61101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/link.php"] [unique_id "amu2eQVxQfK7jpOg6v9HngAAAAg"]
[Thu Jul 30 15:39:21.105673 2026] [core:notice] [pid 215691:tid 215841] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:21.554323 2026] [core:notice] [pid 215691:tid 215862] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:21.588381 2026] [core:notice] [pid 215691:tid 215871] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:21.627105 2026] [security2:error] [pid 215691:tid 215822] [client 20.91.199.21:1122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/alfanew.php"] [unique_id "amu2eQVxQfK7jpOg6v9HsAAAAAE"]
[Thu Jul 30 15:39:21.813908 2026] [security2:error] [pid 215691:tid 215864] [client 20.215.191.139:40910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/mar.php"] [unique_id "amu2eQVxQfK7jpOg6v9HtQAAACs"]
[Thu Jul 30 15:39:21.874351 2026] [security2:error] [pid 215691:tid 215863] [client 20.171.55.167:2494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/sk.php"] [unique_id "amu2eQVxQfK7jpOg6v9HtgAAACo"]
[Thu Jul 30 15:39:22.094760 2026] [security2:error] [pid 215691:tid 215854] [client 57.141.0.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2eQVxQfK7jpOg6v9HqAAAACE"]
[Thu Jul 30 15:39:22.301351 2026] [security2:error] [pid 215691:tid 215905] [client 20.91.199.21:4270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "amu2egVxQfK7jpOg6v9HwQAAAFQ"]
[Thu Jul 30 15:39:22.452972 2026] [security2:error] [pid 215691:tid 215918] [client 20.215.191.139:36112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "amu2egVxQfK7jpOg6v9HwgAAAGE"]
[Thu Jul 30 15:39:22.669047 2026] [security2:error] [pid 215691:tid 215915] [client 20.171.55.167:2337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/snd.php"] [unique_id "amu2egVxQfK7jpOg6v9HxgAAAF4"]
[Thu Jul 30 15:39:23.145006 2026] [security2:error] [pid 215691:tid 215934] [client 213.152.187.235:33342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu2ewVxQfK7jpOg6v9HzQAAAHE"]
[Thu Jul 30 15:39:23.145122 2026] [security2:error] [pid 215691:tid 215934] [client 213.152.187.235:33342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu2ewVxQfK7jpOg6v9HzQAAAHE"]
[Thu Jul 30 15:39:23.212222 2026] [security2:error] [pid 215691:tid 215939] [client 20.215.191.139:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "amu2ewVxQfK7jpOg6v9H0wAAAHY"]
[Thu Jul 30 15:39:23.398718 2026] [security2:error] [pid 215691:tid 215740] [remote 47.128.96.124:16884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.96.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/2138"] [unique_id "amu2ewVxQfK7jpOg6v9HzgAAfDA"]
[Thu Jul 30 15:39:23.440494 2026] [security2:error] [pid 215691:tid 215943] [client 20.171.55.167:2497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/st.php"] [unique_id "amu2ewVxQfK7jpOg6v9H2QAAAHo"]
[Thu Jul 30 15:39:23.471621 2026] [core:notice] [pid 215691:tid 215744] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:23.476884 2026] [security2:error] [pid 215691:tid 215824] [client 47.128.96.124:16884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ejournalugj.com"] [uri "/index.php/RILL/article/view/2138"] [unique_id "amu2ewVxQfK7jpOg6v9H2gAAAzQ"], referer: https://ejournalugj.com/index.php/RILL/article/view/2138?articlesBySimilarityPage=2
[Thu Jul 30 15:39:23.605218 2026] [security2:error] [pid 215691:tid 215860] [client 20.91.199.21:29607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "amu2ewVxQfK7jpOg6v9H3AAAACc"]
[Thu Jul 30 15:39:23.638826 2026] [core:notice] [pid 215691:tid 215746] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:23.720742 2026] [core:notice] [pid 215691:tid 215748] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:23.783593 2026] [core:notice] [pid 215691:tid 215750] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:24.287650 2026] [security2:error] [pid 215691:tid 215869] [client 20.171.55.167:2564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/style-css.php"] [unique_id "amu2fAVxQfK7jpOg6v9H8QAAADA"]
[Thu Jul 30 15:39:24.430876 2026] [security2:error] [pid 215691:tid 215876] [client 20.215.191.139:39971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/plugins.php"] [unique_id "amu2fAVxQfK7jpOg6v9H-AAAADc"]
[Thu Jul 30 15:39:24.544021 2026] [security2:error] [pid 215691:tid 215873] [client 2a03:2880:f800:6:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2ewVxQfK7jpOg6v9H6AAANDw"]
[Thu Jul 30 15:39:24.791261 2026] [core:error] [pid 215691:tid 215905] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://vanguardlegalassociates.team/
[Thu Jul 30 15:39:24.791283 2026] [core:error] [pid 215691:tid 215905] [client 191.96.227.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://vanguardlegalassociates.team/
[Thu Jul 30 15:39:24.955628 2026] [security2:error] [pid 215691:tid 215903] [client 20.91.199.21:11540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-p.php7"] [unique_id "amu2fAVxQfK7jpOg6v9IBwAAAFI"]
[Thu Jul 30 15:39:25.330889 2026] [security2:error] [pid 215691:tid 215915] [client 38.172.162.57:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2fQVxQfK7jpOg6v9IEAAAAF4"]
[Thu Jul 30 15:39:25.331003 2026] [security2:error] [pid 215691:tid 215915] [client 38.172.162.57:16322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2fQVxQfK7jpOg6v9IEAAAAF4"]
[Thu Jul 30 15:39:25.600442 2026] [security2:error] [pid 215691:tid 215917] [client 20.171.55.167:2322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/system.php"] [unique_id "amu2fQVxQfK7jpOg6v9IFgAAAGA"]
[Thu Jul 30 15:39:25.727104 2026] [security2:error] [pid 215691:tid 215930] [client 20.215.191.139:61080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/post.php"] [unique_id "amu2fQVxQfK7jpOg6v9IGgAAAG0"]
[Thu Jul 30 15:39:26.053097 2026] [security2:error] [pid 215691:tid 215910] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2fQVxQfK7jpOg6v9IFQAAWUs"]
[Thu Jul 30 15:39:26.145802 2026] [security2:error] [pid 215691:tid 215846] [client 122.172.85.206:5447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2fgVxQfK7jpOg6v9IJQAAABk"]
[Thu Jul 30 15:39:26.145950 2026] [security2:error] [pid 215691:tid 215846] [client 122.172.85.206:5447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2fgVxQfK7jpOg6v9IJQAAABk"]
[Thu Jul 30 15:39:26.489312 2026] [security2:error] [pid 215691:tid 215855] [client 20.171.55.167:2567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/test.php"] [unique_id "amu2fgVxQfK7jpOg6v9ILwAAACI"]
[Thu Jul 30 15:39:26.611825 2026] [security2:error] [pid 215691:tid 215872] [client 20.215.191.139:42694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/shell.php"] [unique_id "amu2fgVxQfK7jpOg6v9IMAAAADM"]
[Thu Jul 30 15:39:27.259871 2026] [security2:error] [pid 215691:tid 215922] [client 20.171.55.167:2556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/thoms.php"] [unique_id "amu2fwVxQfK7jpOg6v9IOgAAAGU"]
[Thu Jul 30 15:39:27.514097 2026] [security2:error] [pid 215691:tid 215914] [client 20.215.191.139:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/ssl.php"] [unique_id "amu2fwVxQfK7jpOg6v9IQgAAAF0"]
[Thu Jul 30 15:39:27.918659 2026] [security2:error] [pid 215691:tid 215888] [client 20.91.199.21:4279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-admin/repeater.php"] [unique_id "amu2fwVxQfK7jpOg6v9ISAAAAEM"]
[Thu Jul 30 15:39:28.090141 2026] [security2:error] [pid 215691:tid 215853] [client 20.171.55.167:2487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/tmp.php"] [unique_id "amu2gAVxQfK7jpOg6v9IUQAAACA"]
[Thu Jul 30 15:39:28.143853 2026] [security2:error] [pid 215691:tid 215925] [client 20.215.191.139:35423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/sx.php"] [unique_id "amu2gAVxQfK7jpOg6v9IUgAAAGg"]
[Thu Jul 30 15:39:28.978925 2026] [security2:error] [pid 215691:tid 215831] [client 20.171.55.167:2341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/tt.php"] [unique_id "amu2gAVxQfK7jpOg6v9IaAAAAAo"]
[Thu Jul 30 15:39:29.223634 2026] [security2:error] [pid 215691:tid 215857] [client 20.215.191.139:41010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/themes.php"] [unique_id "amu2gQVxQfK7jpOg6v9IcgAAACQ"]
[Thu Jul 30 15:39:29.708675 2026] [security2:error] [pid 215691:tid 215882] [client 20.91.199.21:37996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-includes/repeater.php"] [unique_id "amu2gQVxQfK7jpOg6v9IfQAAAD0"]
[Thu Jul 30 15:39:29.744516 2026] [security2:error] [pid 215691:tid 215898] [client 20.171.55.167:2512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/twentytwentyone/alfa-rex.php"] [unique_id "amu2gQVxQfK7jpOg6v9IfgAAAE0"]
[Thu Jul 30 15:39:29.990479 2026] [security2:error] [pid 215691:tid 215897] [client 20.215.191.139:35422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/worksec.php"] [unique_id "amu2gQVxQfK7jpOg6v9IgwAAAEw"]
[Thu Jul 30 15:39:30.581507 2026] [security2:error] [pid 215691:tid 215932] [client 20.171.55.167:2529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/ula.php"] [unique_id "amu2ggVxQfK7jpOg6v9IkgAAAG8"]
[Thu Jul 30 15:39:30.729849 2026] [security2:error] [pid 215691:tid 215808] [remote 184.168.126.180:52170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.126.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "magicmooncorp.com"] [uri "/wp-login.php"] [unique_id "amu2ggVxQfK7jpOg6v9IlwAAcHQ"]
[Thu Jul 30 15:39:30.843308 2026] [security2:error] [pid 215691:tid 215931] [client 20.215.191.139:42697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/wp-admin/install.php"] [unique_id "amu2ggVxQfK7jpOg6v9ImwAAAG4"]
[Thu Jul 30 15:39:30.992946 2026] [security2:error] [pid 215691:tid 215935] [client 20.91.199.21:41606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.199.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.progroupdoha.com"] [uri "/wp-content/repeater.php"] [unique_id "amu2ggVxQfK7jpOg6v9InQAAAHI"]
[Thu Jul 30 15:39:31.295317 2026] [security2:error] [pid 215691:tid 215828] [client 135.119.63.61:28102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/11.php"] [unique_id "amu2gwVxQfK7jpOg6v9IowAAAAc"]
[Thu Jul 30 15:39:31.431523 2026] [security2:error] [pid 215691:tid 215858] [client 20.171.55.167:2394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/uploadfilewp.php"] [unique_id "amu2gwVxQfK7jpOg6v9IpwAAACU"]
[Thu Jul 30 15:39:31.788569 2026] [security2:error] [pid 215691:tid 215868] [client 20.215.191.139:61083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.191.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bonafideadvisors.com"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "amu2gwVxQfK7jpOg6v9IqwAAAC8"]
[Thu Jul 30 15:39:32.229220 2026] [core:error] [pid 215691:tid 215817] [remote 216.73.216.251:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:39:32.229247 2026] [core:error] [pid 215691:tid 215817] [remote 216.73.216.251:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:39:32.325004 2026] [security2:error] [pid 215691:tid 215848] [client 20.171.55.167:2383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/user-new.php"] [unique_id "amu2hAVxQfK7jpOg6v9IuQAAABs"]
[Thu Jul 30 15:39:32.495814 2026] [security2:error] [pid 215691:tid 215859] [client 135.119.63.61:28130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/11index.php"] [unique_id "amu2hAVxQfK7jpOg6v9IvgAAACY"]
[Thu Jul 30 15:39:33.209422 2026] [security2:error] [pid 215691:tid 215900] [client 20.171.55.167:2385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/vendork.php"] [unique_id "amu2hQVxQfK7jpOg6v9IywAAAE8"]
[Thu Jul 30 15:39:33.560213 2026] [security2:error] [pid 215691:tid 215934] [client 135.119.63.61:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/12.php"] [unique_id "amu2hQVxQfK7jpOg6v9I1gAAAHE"]
[Thu Jul 30 15:39:33.791686 2026] [security2:error] [pid 215691:tid 215892] [client 135.119.63.61:51007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/011i.php"] [unique_id "amu2hQVxQfK7jpOg6v9I2gAAAEc"]
[Thu Jul 30 15:39:33.886152 2026] [proxy:error] [pid 215691:tid 215860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:33.886248 2026] [proxy_http:error] [pid 215691:tid 215860] [client 44.213.206.96:47628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:33.887158 2026] [proxy:error] [pid 215691:tid 215860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:33.887221 2026] [proxy_http:error] [pid 215691:tid 215860] [client 44.213.206.96:47628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:33.928859 2026] [proxy:error] [pid 215691:tid 215843] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:33.928935 2026] [proxy_http:error] [pid 215691:tid 215843] [client 52.4.19.39:33346] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:33.929826 2026] [proxy:error] [pid 215691:tid 215843] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:39:33.929886 2026] [proxy_http:error] [pid 215691:tid 215843] [client 52.4.19.39:33346] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:39:34.072940 2026] [security2:error] [pid 215691:tid 215837] [client 20.171.55.167:2381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/vy2m7.php"] [unique_id "amu2hgVxQfK7jpOg6v9I7QAAABA"]
[Thu Jul 30 15:39:34.323347 2026] [security2:error] [pid 215691:tid 215867] [client 213.152.187.235:55784] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu2hgVxQfK7jpOg6v9I9AAAAC4"]
[Thu Jul 30 15:39:34.323479 2026] [security2:error] [pid 215691:tid 215867] [client 213.152.187.235:55784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "smoke-tfhk.com"] [uri "/xmlrpc.php"] [unique_id "amu2hgVxQfK7jpOg6v9I9AAAAC4"]
[Thu Jul 30 15:39:34.672185 2026] [security2:error] [pid 215691:tid 215877] [client 135.119.63.61:37779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/120f9.php"] [unique_id "amu2hgVxQfK7jpOg6v9I_gAAADg"]
[Thu Jul 30 15:39:34.849883 2026] [security2:error] [pid 215691:tid 215887] [client 20.171.55.167:2547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/widgets.php"] [unique_id "amu2hgVxQfK7jpOg6v9I_wAAAEI"]
[Thu Jul 30 15:39:34.873933 2026] [security2:error] [pid 215691:tid 215885] [client 135.119.63.61:51063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/03a005685d.php"] [unique_id "amu2hgVxQfK7jpOg6v9JAQAAAEA"]
[Thu Jul 30 15:39:34.875426 2026] [core:notice] [pid 215691:tid 215886] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:34.949327 2026] [security2:error] [pid 215691:tid 215873] [client 94.154.43.187:19898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.kendarikomputer.com"] [uri "/.env"] [unique_id "amu2hgVxQfK7jpOg6v9JAgAAADQ"]
[Thu Jul 30 15:39:35.085623 2026] [security2:error] [pid 215691:tid 215710] [remote 216.73.216.51:57967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/cdn-cgi/styles/cf.errors.css"] [unique_id "amu2hwVxQfK7jpOg6v9JCQAAUhI"]
[Thu Jul 30 15:39:35.643868 2026] [security2:error] [pid 215691:tid 215936] [client 20.171.55.167:2405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/widgetsadmin.php"] [unique_id "amu2hwVxQfK7jpOg6v9JFQAAAHM"]
[Thu Jul 30 15:39:35.835023 2026] [security2:error] [pid 215691:tid 215916] [client 43.157.181.189:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.181.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/wp-admin/update-core.php"] [unique_id "amu2hwVxQfK7jpOg6v9JFAAAAF8"]
[Thu Jul 30 15:39:35.973476 2026] [security2:error] [pid 215691:tid 215919] [client 38.172.162.57:16214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2hwVxQfK7jpOg6v9JGQAAAGI"]
[Thu Jul 30 15:39:35.974433 2026] [security2:error] [pid 215691:tid 215919] [client 38.172.162.57:16214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2hwVxQfK7jpOg6v9JGQAAAGI"]
[Thu Jul 30 15:39:36.160076 2026] [security2:error] [pid 215691:tid 215862] [client 74.7.175.137:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yaz.gzj.temporary.site"] [uri "/index.php"] [unique_id "amu2hgVxQfK7jpOg6v9I7AAAACk"]
[Thu Jul 30 15:39:36.160745 2026] [security2:error] [pid 215691:tid 215931] [client 74.7.175.137:43314] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yaz.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amu2hgVxQfK7jpOg6v9I6gAAbgo"]
[Thu Jul 30 15:39:36.213600 2026] [security2:error] [pid 215691:tid 215920] [client 135.119.63.61:51069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/403.php"] [unique_id "amu2iAVxQfK7jpOg6v9JJAAAAGM"]
[Thu Jul 30 15:39:36.399920 2026] [security2:error] [pid 215691:tid 215942] [client 20.171.55.167:2398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/workart/db.php"] [unique_id "amu2iAVxQfK7jpOg6v9JKQAAAHk"]
[Thu Jul 30 15:39:36.780097 2026] [security2:error] [pid 215691:tid 215854] [client 122.172.85.206:5885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2iAVxQfK7jpOg6v9JMQAAACE"]
[Thu Jul 30 15:39:36.780424 2026] [security2:error] [pid 215691:tid 215854] [client 122.172.85.206:5885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2iAVxQfK7jpOg6v9JMQAAACE"]
[Thu Jul 30 15:39:37.194082 2026] [security2:error] [pid 215691:tid 215902] [client 20.171.55.167:2389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-atom.php"] [unique_id "amu2iQVxQfK7jpOg6v9JPAAAAFE"]
[Thu Jul 30 15:39:37.384481 2026] [security2:error] [pid 215691:tid 215886] [client 135.119.63.61:50974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/404.php"] [unique_id "amu2iQVxQfK7jpOg6v9JQgAAAEE"]
[Thu Jul 30 15:39:37.574173 2026] [security2:error] [pid 215691:tid 215727] [remote 72.167.132.114:56548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northyorksheridanmall.com"] [uri "/wp-login.php"] [unique_id "amu2iQVxQfK7jpOg6v9JQwAAWyM"]
[Thu Jul 30 15:39:37.915246 2026] [security2:error] [pid 215691:tid 215852] [client 135.119.63.61:14473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/123.php"] [unique_id "amu2iQVxQfK7jpOg6v9JTwAAAB8"]
[Thu Jul 30 15:39:37.957065 2026] [security2:error] [pid 215691:tid 215915] [client 20.171.55.167:2323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-config-sample.php"] [unique_id "amu2iQVxQfK7jpOg6v9JUAAAAF4"]
[Thu Jul 30 15:39:38.077779 2026] [security2:error] [pid 215691:tid 215733] [remote 88.198.14.102:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.14.198.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "openspacelab.club"] [uri "/wordpress/xmlrpc.php"] [unique_id "amu2iQVxQfK7jpOg6v9JTgAAdSk"]
[Thu Jul 30 15:39:38.078064 2026] [security2:error] [pid 215691:tid 215938] [client 88.198.14.102:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "openspacelab.club"] [uri "/wordpress/xmlrpc.php"] [unique_id "amu2iQVxQfK7jpOg6v9JTgAAdSk"]
[Thu Jul 30 15:39:38.167559 2026] [core:notice] [pid 215691:tid 215845] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:38.795286 2026] [security2:error] [pid 215691:tid 215935] [client 20.171.55.167:2517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-db-ajax-made/wp-ajax.php"] [unique_id "amu2igVxQfK7jpOg6v9JZAAAAHI"]
[Thu Jul 30 15:39:38.994419 2026] [core:notice] [pid 215691:tid 215860] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:39.065757 2026] [security2:error] [pid 215691:tid 215841] [client 135.119.63.61:14485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1234.php"] [unique_id "amu2iwVxQfK7jpOg6v9JagAAABQ"]
[Thu Jul 30 15:39:39.334088 2026] [security2:error] [pid 215691:tid 215844] [client 135.119.63.61:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/aa.php"] [unique_id "amu2iwVxQfK7jpOg6v9JcgAAABc"]
[Thu Jul 30 15:39:39.343089 2026] [core:notice] [pid 215691:tid 215943] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:39.577090 2026] [security2:error] [pid 215691:tid 215842] [client 20.171.55.167:2430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-freeform/wawe.php"] [unique_id "amu2iwVxQfK7jpOg6v9JfwAAABU"]
[Thu Jul 30 15:39:39.603135 2026] [security2:error] [pid 215691:tid 215891] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2igVxQfK7jpOg6v9JaAAARjE"]
[Thu Jul 30 15:39:40.050391 2026] [security2:error] [pid 215691:tid 215894] [client 135.119.63.61:37775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/12r4jd.php"] [unique_id "amu2jAVxQfK7jpOg6v9JjgAAAEk"]
[Thu Jul 30 15:39:40.365678 2026] [security2:error] [pid 215691:tid 215918] [client 135.119.63.61:51036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/aafewc0k.php"] [unique_id "amu2jAVxQfK7jpOg6v9JlQAAAGE"]
[Thu Jul 30 15:39:40.397493 2026] [security2:error] [pid 215691:tid 215754] [remote 57.141.0.18:42242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/6146521103/feed/rss2/"] [unique_id "amu2jAVxQfK7jpOg6v9JlwAAOj4"]
[Thu Jul 30 15:39:40.463863 2026] [security2:error] [pid 215691:tid 215938] [client 20.171.55.167:2370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-index.php"] [unique_id "amu2jAVxQfK7jpOg6v9JmwAAAHU"]
[Thu Jul 30 15:39:40.487404 2026] [security2:error] [pid 215691:tid 215936] [client 141.98.102.227:53548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amu2jAVxQfK7jpOg6v9JkgAAAHM"]
[Thu Jul 30 15:39:40.487502 2026] [security2:error] [pid 215691:tid 215936] [client 141.98.102.227:53548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fireworkskenya.com"] [uri "/xmlrpc.php"] [unique_id "amu2jAVxQfK7jpOg6v9JkgAAAHM"]
[Thu Jul 30 15:39:41.028471 2026] [security2:error] [pid 215691:tid 215920] [client 135.119.63.61:37806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/13.php"] [unique_id "amu2jQVxQfK7jpOg6v9JqQAAAGM"]
[Thu Jul 30 15:39:41.373171 2026] [security2:error] [pid 215691:tid 215883] [client 20.171.55.167:2407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-pano.php"] [unique_id "amu2jQVxQfK7jpOg6v9JtQAAAD4"]
[Thu Jul 30 15:39:41.611989 2026] [security2:error] [pid 215691:tid 215904] [client 135.119.63.61:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/abcd.php"] [unique_id "amu2jQVxQfK7jpOg6v9JvAAAAFM"]
[Thu Jul 30 15:39:42.188586 2026] [security2:error] [pid 215691:tid 215929] [client 20.171.55.167:2437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-set.php"] [unique_id "amu2jgVxQfK7jpOg6v9JyAAAAGw"]
[Thu Jul 30 15:39:42.436309 2026] [core:notice] [pid 215691:tid 215834] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:42.822909 2026] [security2:error] [pid 215691:tid 215916] [client 135.119.63.61:50994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/about.php"] [unique_id "amu2jgVxQfK7jpOg6v9J1gAAAF8"]
[Thu Jul 30 15:39:43.057179 2026] [security2:error] [pid 215691:tid 215843] [client 20.171.55.167:2333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wp-uploads.php"] [unique_id "amu2jwVxQfK7jpOg6v9J4wAAABY"]
[Thu Jul 30 15:39:43.851543 2026] [security2:error] [pid 215691:tid 215873] [client 20.171.55.167:2423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wpn.php"] [unique_id "amu2jwVxQfK7jpOg6v9J8wAAADQ"]
[Thu Jul 30 15:39:44.281595 2026] [fcgid:warn] [pid 215691:tid 215907] (70014)End of file found: [client 152.32.151.39:44318] mod_fcgid: can't get data from http client
[Thu Jul 30 15:39:44.432423 2026] [security2:error] [pid 215691:tid 215900] [client 85.208.96.202:57598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nordeste1.com"] [uri "/2022/09/22/soraya-paralisa-campanha-por-falta-de-dinheiro/"] [unique_id "amu2kAVxQfK7jpOg6v9KAAAAAE8"]
[Thu Jul 30 15:39:44.432529 2026] [security2:error] [pid 215691:tid 215900] [client 85.208.96.202:57598] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nordeste1.com"] [uri "/2022/09/22/soraya-paralisa-campanha-por-falta-de-dinheiro/"] [unique_id "amu2kAVxQfK7jpOg6v9KAAAAAE8"]
[Thu Jul 30 15:39:44.533635 2026] [core:notice] [pid 215691:tid 215793] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:44.688040 2026] [security2:error] [pid 215691:tid 215928] [client 135.119.63.61:28151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1337.php"] [unique_id "amu2kAVxQfK7jpOg6v9KDQAAAGs"]
[Thu Jul 30 15:39:44.734570 2026] [security2:error] [pid 215691:tid 215850] [client 20.171.55.167:2339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/wso1337.php"] [unique_id "amu2kAVxQfK7jpOg6v9KDgAAAB0"]
[Thu Jul 30 15:39:45.361653 2026] [security2:error] [pid 215691:tid 215925] [client 172.202.44.182:10368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cpcalendars.progroupdoha.com"] [uri "/"] [unique_id "amu2kQVxQfK7jpOg6v9KHQAAAGg"]
[Thu Jul 30 15:39:45.506145 2026] [core:notice] [pid 215691:tid 215804] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:45.644950 2026] [security2:error] [pid 215691:tid 215840] [client 135.119.63.61:28113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/13k.php"] [unique_id "amu2kQVxQfK7jpOg6v9KJQAAABM"]
[Thu Jul 30 15:39:45.683413 2026] [security2:error] [pid 215691:tid 215932] [client 172.237.109.114:53058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu2kQVxQfK7jpOg6v9KFQAAAG8"]
[Thu Jul 30 15:39:45.696255 2026] [security2:error] [pid 215691:tid 215897] [client 135.119.63.61:51070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/admin.php"] [unique_id "amu2kQVxQfK7jpOg6v9KJwAAAEw"]
[Thu Jul 30 15:39:45.789482 2026] [security2:error] [pid 215691:tid 215841] [client 20.171.55.167:2376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xBrain.php"] [unique_id "amu2kQVxQfK7jpOg6v9KKwAAABQ"]
[Thu Jul 30 15:39:45.793922 2026] [core:notice] [pid 215691:tid 215801] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:45.925815 2026] [security2:error] [pid 215691:tid 215823] [client 172.202.44.182:10368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cpcalendars.progroupdoha.com"] [uri "/"] [unique_id "amu2kQVxQfK7jpOg6v9KLwAAAAI"]
[Thu Jul 30 15:39:46.521535 2026] [security2:error] [pid 215691:tid 215908] [client 38.172.162.57:15911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2kgVxQfK7jpOg6v9KPQAAAFc"]
[Thu Jul 30 15:39:46.521693 2026] [security2:error] [pid 215691:tid 215908] [client 38.172.162.57:15911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2kgVxQfK7jpOg6v9KPQAAAFc"]
[Thu Jul 30 15:39:46.559012 2026] [security2:error] [pid 215691:tid 215900] [client 135.119.63.61:50966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/adminfuns.php"] [unique_id "amu2kgVxQfK7jpOg6v9KQAAAAE8"]
[Thu Jul 30 15:39:46.624860 2026] [security2:error] [pid 215691:tid 215921] [client 20.171.55.167:2374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/xml.php"] [unique_id "amu2kgVxQfK7jpOg6v9KRQAAAGQ"]
[Thu Jul 30 15:39:46.735531 2026] [security2:error] [pid 215691:tid 215859] [client 135.119.63.61:14920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/15.php"] [unique_id "amu2kgVxQfK7jpOg6v9KRgAAACY"]
[Thu Jul 30 15:39:47.377704 2026] [security2:error] [pid 215691:tid 215861] [client 20.171.55.167:2380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/yes.php"] [unique_id "amu2kwVxQfK7jpOg6v9KVgAAACg"]
[Thu Jul 30 15:39:47.392458 2026] [security2:error] [pid 215691:tid 215941] [client 50.6.43.217:25076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amu2kwVxQfK7jpOg6v9KUwAAAHg"]
[Thu Jul 30 15:39:47.408598 2026] [security2:error] [pid 215691:tid 215849] [client 122.172.85.206:29204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2kwVxQfK7jpOg6v9KWAAAABw"]
[Thu Jul 30 15:39:47.408873 2026] [security2:error] [pid 215691:tid 215849] [client 122.172.85.206:29204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2kwVxQfK7jpOg6v9KWAAAABw"]
[Thu Jul 30 15:39:47.510030 2026] [security2:error] [pid 215691:tid 215935] [client 50.6.43.217:25080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jesus.claims"] [uri "/index.php"] [unique_id "amu2kwVxQfK7jpOg6v9KVwAAAHI"]
[Thu Jul 30 15:39:47.805045 2026] [security2:error] [pid 215691:tid 215870] [client 135.119.63.61:51023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/albin.php"] [unique_id "amu2kwVxQfK7jpOg6v9KXwAAADE"]
[Thu Jul 30 15:39:48.265611 2026] [security2:error] [pid 215691:tid 215854] [client 20.171.55.167:2278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.55.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lilyinspires.com"] [uri "/zmFM.php"] [unique_id "amu2lAVxQfK7jpOg6v9KagAAACE"]
[Thu Jul 30 15:39:48.473954 2026] [security2:error] [pid 215691:tid 215883] [client 135.119.63.61:28097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1945.php"] [unique_id "amu2lAVxQfK7jpOg6v9KbgAAAD4"]
[Thu Jul 30 15:39:48.616053 2026] [security2:error] [pid 215691:tid 215940] [client 135.119.63.61:51037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/amfsqvgv.php"] [unique_id "amu2lAVxQfK7jpOg6v9KbwAAAHc"]
[Thu Jul 30 15:39:49.110279 2026] [security2:error] [pid 215691:tid 215701] [remote 57.141.0.55:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/64637765089/feed/rss2/"] [unique_id "amu2lQVxQfK7jpOg6v9KeQAAaQk"]
[Thu Jul 30 15:39:49.769489 2026] [security2:error] [pid 215691:tid 215839] [client 135.119.63.61:51036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/ant.php"] [unique_id "amu2lQVxQfK7jpOg6v9KhgAAABI"]
[Thu Jul 30 15:39:50.680412 2026] [security2:error] [pid 215691:tid 215831] [client 82.102.18.188:37436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "amu2lgVxQfK7jpOg6v9KoAAAAAo"]
[Thu Jul 30 15:39:50.865247 2026] [security2:error] [pid 215691:tid 215945] [client 135.119.63.61:28121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1975.php"] [unique_id "amu2lgVxQfK7jpOg6v9KpwAAAHw"]
[Thu Jul 30 15:39:50.958849 2026] [security2:error] [pid 215691:tid 215883] [client 82.102.18.188:37452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/xmlrpc.php"] [unique_id "amu2lgVxQfK7jpOg6v9KqwAAAD4"]
[Thu Jul 30 15:39:51.028827 2026] [core:notice] [pid 215691:tid 215870] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:51.374883 2026] [security2:error] [pid 215691:tid 215829] [client 82.102.18.188:37458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "amu2lwVxQfK7jpOg6v9KtwAAAAg"]
[Thu Jul 30 15:39:51.431316 2026] [security2:error] [pid 215691:tid 215915] [client 52.176.39.128:3080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.39.176.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jesus.claims"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amu2lwVxQfK7jpOg6v9KuAAAAF4"]
[Thu Jul 30 15:39:51.588107 2026] [security2:error] [pid 215691:tid 215925] [client 57.141.0.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2lQVxQfK7jpOg6v9KjwAAAGg"]
[Thu Jul 30 15:39:51.651240 2026] [security2:error] [pid 215691:tid 215722] [remote 216.73.216.51:23327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu2lwVxQfK7jpOg6v9KvQAAOh4"]
[Thu Jul 30 15:39:51.673055 2026] [security2:error] [pid 215691:tid 215858] [client 82.102.18.188:37464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "amu2lwVxQfK7jpOg6v9KvgAAACU"]
[Thu Jul 30 15:39:51.771951 2026] [security2:error] [pid 215691:tid 215916] [client 127.0.0.1:37332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "amu2lwVxQfK7jpOg6v9KwAAAAF8"]
[Thu Jul 30 15:39:51.771987 2026] [security2:error] [pid 215691:tid 215937] [client 74.7.230.11:34316] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.ghm.hmu.temporary.site"] [uri "/robots.txt"] [unique_id "amu2lwVxQfK7jpOg6v9KvwAAAHQ"]
[Thu Jul 30 15:39:51.950417 2026] [security2:error] [pid 215691:tid 215924] [client 82.102.18.188:37480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "amu2lwVxQfK7jpOg6v9KxwAAAGc"]
[Thu Jul 30 15:39:52.216885 2026] [security2:error] [pid 215691:tid 215860] [client 82.102.18.188:37492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "amu2mAVxQfK7jpOg6v9KyAAAACc"]
[Thu Jul 30 15:39:52.488490 2026] [security2:error] [pid 215691:tid 215828] [client 135.119.63.61:30636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1975Team.php"] [unique_id "amu2mAVxQfK7jpOg6v9K0gAAAAc"]
[Thu Jul 30 15:39:52.494901 2026] [security2:error] [pid 215691:tid 215948] [client 82.102.18.188:37494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "amu2mAVxQfK7jpOg6v9K0wAAAH8"]
[Thu Jul 30 15:39:52.768288 2026] [security2:error] [pid 215691:tid 215841] [client 82.102.18.188:37504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "amu2mAVxQfK7jpOg6v9K1wAAABQ"]
[Thu Jul 30 15:39:53.032196 2026] [security2:error] [pid 215691:tid 215867] [client 82.102.18.188:37520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "amu2mQVxQfK7jpOg6v9K4AAAAC4"]
[Thu Jul 30 15:39:53.070096 2026] [autoindex:error] [pid 215691:tid 215906] [client 209.97.166.251:54935] AH01276: Cannot serve directory /home1/ncozztte/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Thu Jul 30 15:39:53.238815 2026] [security2:error] [pid 215691:tid 215894] [client 41.208.169.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amu2lwVxQfK7jpOg6v9KvAAASR8"]
[Thu Jul 30 15:39:53.298911 2026] [security2:error] [pid 215691:tid 215923] [client 82.102.18.188:37526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "amu2mQVxQfK7jpOg6v9K5QAAAGY"]
[Thu Jul 30 15:39:53.565863 2026] [security2:error] [pid 215691:tid 215852] [client 82.102.18.188:37542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "amu2mQVxQfK7jpOg6v9K7AAAAB8"]
[Thu Jul 30 15:39:53.826285 2026] [security2:error] [pid 215691:tid 215914] [client 135.119.63.61:30646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1@.php"] [unique_id "amu2mQVxQfK7jpOg6v9K8QAAAF0"]
[Thu Jul 30 15:39:53.828122 2026] [security2:error] [pid 215691:tid 215843] [client 82.102.18.188:37544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "amu2mQVxQfK7jpOg6v9K8gAAABY"]
[Thu Jul 30 15:39:54.145508 2026] [security2:error] [pid 215691:tid 215917] [client 82.102.18.188:49494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "amu2mgVxQfK7jpOg6v9K_AAAAGA"]
[Thu Jul 30 15:39:54.415394 2026] [security2:error] [pid 215691:tid 215919] [client 82.102.18.188:23304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "amu2mgVxQfK7jpOg6v9K_QAAAGI"]
[Thu Jul 30 15:39:54.681625 2026] [security2:error] [pid 215691:tid 215892] [client 82.102.18.188:49512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "amu2mgVxQfK7jpOg6v9LCAAAAEc"]
[Thu Jul 30 15:39:54.948604 2026] [security2:error] [pid 215691:tid 215941] [client 82.102.18.188:49528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "amu2mgVxQfK7jpOg6v9LCgAAAHg"]
[Thu Jul 30 15:39:54.950588 2026] [security2:error] [pid 215691:tid 215936] [client 74.7.228.38:38616] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.mogomogolessons4.com"] [uri "/robots.txt"] [unique_id "amu2mgVxQfK7jpOg6v9LCwAAAHM"]
[Thu Jul 30 15:39:55.132409 2026] [core:notice] [pid 215691:tid 215746] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:55.232401 2026] [security2:error] [pid 215691:tid 215857] [client 82.102.18.188:49540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.abudhabicarrecoveryllc.site"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "amu2mwVxQfK7jpOg6v9LFQAAACQ"]
[Thu Jul 30 15:39:55.253523 2026] [security2:error] [pid 215691:tid 215938] [client 135.119.63.61:37783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1aa.php"] [unique_id "amu2mwVxQfK7jpOg6v9LFgAAAHU"]
[Thu Jul 30 15:39:55.689332 2026] [core:notice] [pid 215691:tid 215751] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:55.794920 2026] [security2:error] [pid 215691:tid 215758] [remote 216.73.216.51:23327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/sitemap.xml"] [unique_id "amu2mwVxQfK7jpOg6v9LIwAARUI"]
[Thu Jul 30 15:39:56.249754 2026] [security2:error] [pid 215691:tid 215841] [client 77.169.2.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amu2mwVxQfK7jpOg6v9LHgAAFD4"]
[Thu Jul 30 15:39:56.675857 2026] [security2:error] [pid 215691:tid 215927] [client 135.119.63.61:30600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1index.php"] [unique_id "amu2nAVxQfK7jpOg6v9LNgAAAGo"]
[Thu Jul 30 15:39:56.925035 2026] [security2:error] [pid 215691:tid 215925] [client 152.32.151.39:41428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jesus.claims.wdr.gpl.temporary.site"] [uri "/index.php"] [unique_id "amu2nAVxQfK7jpOg6v9LNwAAAGg"]
[Thu Jul 30 15:39:57.060551 2026] [security2:error] [pid 215691:tid 215843] [client 38.172.162.57:16025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2nQVxQfK7jpOg6v9LPwAAABY"]
[Thu Jul 30 15:39:57.060686 2026] [security2:error] [pid 215691:tid 215843] [client 38.172.162.57:16025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2nQVxQfK7jpOg6v9LPwAAABY"]
[Thu Jul 30 15:39:57.499066 2026] [core:notice] [pid 215691:tid 215933] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:57.503954 2026] [security2:error] [pid 215691:tid 215933] [client 195.23.32.200:41508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.carnetdeshopping.com"] [uri "/feed/"] [unique_id "amu2nQVxQfK7jpOg6v9LRwAAAHA"]
[Thu Jul 30 15:39:57.985569 2026] [security2:error] [pid 215691:tid 215947] [client 176.44.201.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu2nQVxQfK7jpOg6v9LUAAAAH4"], referer: https://cnpinyin.com
[Thu Jul 30 15:39:58.091743 2026] [security2:error] [pid 215691:tid 215877] [client 122.172.85.206:19044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2ngVxQfK7jpOg6v9LVgAAADg"]
[Thu Jul 30 15:39:58.092065 2026] [security2:error] [pid 215691:tid 215877] [client 122.172.85.206:19044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2ngVxQfK7jpOg6v9LVgAAADg"]
[Thu Jul 30 15:39:58.171028 2026] [core:notice] [pid 215691:tid 215767] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:58.463631 2026] [security2:error] [pid 215691:tid 215835] [client 14.229.199.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amu2nQVxQfK7jpOg6v9LVAAADlA"]
[Thu Jul 30 15:39:58.871242 2026] [core:notice] [pid 215691:tid 215904] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:39:58.876155 2026] [security2:error] [pid 215691:tid 215904] [client 195.23.32.200:41586] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/feed/"] [unique_id "amu2ngVxQfK7jpOg6v9LaAAAAFM"]
[Thu Jul 30 15:39:58.973404 2026] [security2:error] [pid 215691:tid 215923] [client 135.119.63.61:50999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/appreciators.php"] [unique_id "amu2ngVxQfK7jpOg6v9LbAAAAGY"]
[Thu Jul 30 15:39:59.105012 2026] [security2:error] [pid 215691:tid 215871] [client 135.119.63.61:14993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1nt3pqdk.php"] [unique_id "amu2nwVxQfK7jpOg6v9LbgAAADI"]
[Thu Jul 30 15:40:00.383673 2026] [security2:error] [pid 215691:tid 215944] [client 135.119.63.61:37768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/1wx.php"] [unique_id "amu2oAVxQfK7jpOg6v9LiwAAAHs"]
[Thu Jul 30 15:40:00.625796 2026] [security2:error] [pid 215691:tid 215892] [client 113.177.203.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amu2oAVxQfK7jpOg6v9LgwAAR2E"]
[Thu Jul 30 15:40:00.685863 2026] [security2:error] [pid 215691:tid 215833] [client 195.23.32.200:41664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sellvia.womenclothingbox.com"] [uri "/index.html"] [unique_id "amu2oAVxQfK7jpOg6v9LigAAAAw"]
[Thu Jul 30 15:40:01.086063 2026] [security2:error] [pid 215691:tid 215889] [client 135.119.63.61:50987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/archive.php"] [unique_id "amu2oQVxQfK7jpOg6v9LowAAAEQ"]
[Thu Jul 30 15:40:01.389286 2026] [security2:error] [pid 215691:tid 215941] [client 2a03:2880:f800:19:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2oAVxQfK7jpOg6v9LmAAAeGc"]
[Thu Jul 30 15:40:01.660989 2026] [security2:error] [pid 215691:tid 215923] [client 135.119.63.61:37772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2.php"] [unique_id "amu2oQVxQfK7jpOg6v9LuwAAAGY"]
[Thu Jul 30 15:40:01.735325 2026] [security2:error] [pid 215691:tid 215890] [client 74.7.244.39:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-680e7f9d.mth.gzj.temporary.site"] [uri "/index.php"] [unique_id "amu2oAVxQfK7jpOg6v9LnwAAAEU"]
[Thu Jul 30 15:40:01.736072 2026] [security2:error] [pid 215691:tid 215947] [client 74.7.244.39:33772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-680e7f9d.mth.gzj.temporary.site"] [uri "/robots.txt"] [unique_id "amu2oAVxQfK7jpOg6v9LnQAAfmI"]
[Thu Jul 30 15:40:02.226364 2026] [security2:error] [pid 215691:tid 215838] [client 135.119.63.61:50964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/as.php"] [unique_id "amu2ogVxQfK7jpOg6v9LywAAABE"]
[Thu Jul 30 15:40:02.379799 2026] [security2:error] [pid 215691:tid 215866] [client 74.7.228.24:43130] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.wma.gpl.temporary.site"] [uri "/robots.txt"] [unique_id "amu2ogVxQfK7jpOg6v9LzQAAAC0"]
[Thu Jul 30 15:40:02.738633 2026] [security2:error] [pid 215691:tid 215943] [client 74.7.241.181:45372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.zbj.udi.temporary.site"] [uri "/robots.txt"] [unique_id "amu2ogVxQfK7jpOg6v9L0QAAAHo"]
[Thu Jul 30 15:40:03.374530 2026] [security2:error] [pid 215691:tid 215693] [remote 74.7.243.224:35554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/img/misionf.php"] [unique_id "amu2owVxQfK7jpOg6v9L4QAARAE"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/img/main_image_6a2032acb13c3.jpg
[Thu Jul 30 15:40:03.465182 2026] [security2:error] [pid 215691:tid 215828] [client 135.119.63.61:14980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/20112011.php"] [unique_id "amu2owVxQfK7jpOg6v9L4gAAAAc"]
[Thu Jul 30 15:40:03.468326 2026] [security2:error] [pid 215691:tid 215855] [client 135.119.63.61:50876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/atomlib.php"] [unique_id "amu2owVxQfK7jpOg6v9L4wAAACI"]
[Thu Jul 30 15:40:04.458844 2026] [security2:error] [pid 215691:tid 215884] [client 135.119.63.61:15002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2014/02/mt_srand.php"] [unique_id "amu2pAVxQfK7jpOg6v9L_AAAAD8"]
[Thu Jul 30 15:40:04.582616 2026] [security2:error] [pid 215691:tid 215932] [client 103.138.223.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lucky-strike-shop.com"] [uri "/index.php"] [unique_id "amu2owVxQfK7jpOg6v9L7gAAbwU"]
[Thu Jul 30 15:40:05.281492 2026] [security2:error] [pid 215691:tid 215896] [client 135.119.63.61:14663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2014/03/smile.php"] [unique_id "amu2pQVxQfK7jpOg6v9MCwAAAEs"]
[Thu Jul 30 15:40:05.310223 2026] [security2:error] [pid 215691:tid 215934] [client 74.7.228.28:60542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "xsx.acn.temporary.site"] [uri "/index.php"] [unique_id "amu2pAVxQfK7jpOg6v9MAAAAcQ4"]
[Thu Jul 30 15:40:05.427989 2026] [security2:error] [pid 215691:tid 215709] [remote 103.149.169.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.169.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sama-architect.com"] [uri "/wp-login.php"] [unique_id "amu2pQVxQfK7jpOg6v9MBwAAABE"]
[Thu Jul 30 15:40:05.799801 2026] [security2:error] [pid 215691:tid 215717] [remote 216.73.216.51:26894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/"] [unique_id "amu2pQVxQfK7jpOg6v9MFgAAfRk"]
[Thu Jul 30 15:40:06.618284 2026] [security2:error] [pid 215691:tid 215877] [client 135.119.63.61:14682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2014/07/olx.php"] [unique_id "amu2pgVxQfK7jpOg6v9MKQAAADg"]
[Thu Jul 30 15:40:07.646926 2026] [security2:error] [pid 215691:tid 215923] [client 38.172.162.57:16009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2pwVxQfK7jpOg6v9MPwAAAGY"]
[Thu Jul 30 15:40:07.647059 2026] [security2:error] [pid 215691:tid 215923] [client 38.172.162.57:16009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2pwVxQfK7jpOg6v9MPwAAAGY"]
[Thu Jul 30 15:40:07.797668 2026] [security2:error] [pid 215691:tid 215890] [client 135.119.63.61:37610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2014/was-wp.php"] [unique_id "amu2pwVxQfK7jpOg6v9MQAAAAEU"]
[Thu Jul 30 15:40:07.883190 2026] [security2:error] [pid 215691:tid 215920] [client 135.119.63.61:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/autoload_classmap.php"] [unique_id "amu2pwVxQfK7jpOg6v9MRAAAAGM"]
[Thu Jul 30 15:40:08.815260 2026] [security2:error] [pid 215691:tid 215825] [client 122.172.85.206:28302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2qAVxQfK7jpOg6v9MWwAAAAQ"]
[Thu Jul 30 15:40:08.815443 2026] [security2:error] [pid 215691:tid 215825] [client 122.172.85.206:28302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2qAVxQfK7jpOg6v9MWwAAAAQ"]
[Thu Jul 30 15:40:08.862139 2026] [security2:error] [pid 215691:tid 215885] [client 35.204.135.22:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.carnetdeshopping.com"] [uri "/"] [unique_id "amu2qAVxQfK7jpOg6v9MXAAAAEA"]
[Thu Jul 30 15:40:08.862231 2026] [security2:error] [pid 215691:tid 215885] [client 35.204.135.22:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webmail.carnetdeshopping.com"] [uri "/"] [unique_id "amu2qAVxQfK7jpOg6v9MXAAAAEA"]
[Thu Jul 30 15:40:09.539675 2026] [security2:error] [pid 215691:tid 215848] [client 135.119.63.61:38074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2015/05/Marvins.php"] [unique_id "amu2qQVxQfK7jpOg6v9McgAAABs"]
[Thu Jul 30 15:40:09.855826 2026] [security2:error] [pid 215691:tid 215747] [remote 110.249.201.150:21244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arabiandubaisafari.com"] [uri "/assets/images/abu-dhabi-desert-safari-quad-bike.jpg"] [unique_id "amu2qQVxQfK7jpOg6v9MegAAZjc"]
[Thu Jul 30 15:40:10.010026 2026] [proxy:error] [pid 215691:tid 215917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:40:10.010091 2026] [proxy_http:error] [pid 215691:tid 215917] [client 9.249.81.158:44192] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:40:10.010928 2026] [proxy:error] [pid 215691:tid 215917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:40:10.011003 2026] [proxy_http:error] [pid 215691:tid 215917] [client 9.249.81.158:44192] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:40:10.508912 2026] [security2:error] [pid 215691:tid 215896] [client 135.119.63.61:38030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2017-------/09/wp-console.php"] [unique_id "amu2qgVxQfK7jpOg6v9MiwAAAEs"]
[Thu Jul 30 15:40:10.563372 2026] [core:notice] [pid 215691:tid 215887] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:10.640223 2026] [security2:error] [pid 215691:tid 215909] [client 135.119.63.61:51031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/bb.php"] [unique_id "amu2qgVxQfK7jpOg6v9MkQAAAFg"]
[Thu Jul 30 15:40:11.322481 2026] [security2:error] [pid 215691:tid 215874] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2qgVxQfK7jpOg6v9MmAAAADU"]
[Thu Jul 30 15:40:11.936549 2026] [security2:error] [pid 215691:tid 215855] [client 41.210.145.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/wp-login.php"] [unique_id "amu2qQVxQfK7jpOg6v9MYAAAIi8"], referer: https://flixon.net/free-movies/
[Thu Jul 30 15:40:12.824634 2026] [core:notice] [pid 215691:tid 215839] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:12.829012 2026] [security2:error] [pid 215691:tid 215839] [client 66.249.79.231:42370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.ejournalugj.com"] [uri "/index.php/RILL/article/view/1143"] [unique_id "amu2rAVxQfK7jpOg6v9MvwAAABI"]
[Thu Jul 30 15:40:14.346758 2026] [security2:error] [pid 215691:tid 215941] [client 135.119.63.61:38069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2018/03/class-wp-type-registroy.php"] [unique_id "amu2rgVxQfK7jpOg6v9M4gAAAHg"]
[Thu Jul 30 15:40:14.609649 2026] [security2:error] [pid 215691:tid 215837] [client 135.119.63.61:51054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/bnm.php"] [unique_id "amu2rgVxQfK7jpOg6v9M6QAAABA"]
[Thu Jul 30 15:40:15.303906 2026] [security2:error] [pid 215691:tid 215831] [client 135.119.63.61:38067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2019/08/w-1.php"] [unique_id "amu2rwVxQfK7jpOg6v9NAAAAAAo"]
[Thu Jul 30 15:40:15.687215 2026] [security2:error] [pid 215691:tid 215859] [client 172.237.109.114:17267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu2rwVxQfK7jpOg6v9M_AAAACY"]
[Thu Jul 30 15:40:15.945904 2026] [security2:error] [pid 215691:tid 215862] [client 191.232.199.39:2600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wk/index.php"] [unique_id "amu2rwVxQfK7jpOg6v9NEQAAACk"]
[Thu Jul 30 15:40:16.107135 2026] [security2:error] [pid 215691:tid 215826] [client 135.119.63.61:51056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/bootstrap.php"] [unique_id "amu2sAVxQfK7jpOg6v9NFwAAAAU"]
[Thu Jul 30 15:40:16.171087 2026] [core:notice] [pid 215691:tid 215843] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:16.302670 2026] [proxy:error] [pid 215691:tid 215847] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:40:16.302752 2026] [proxy_http:error] [pid 215691:tid 215847] [client 52.202.41.153:65380] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:40:16.303477 2026] [proxy:error] [pid 215691:tid 215847] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:40:16.303529 2026] [proxy_http:error] [pid 215691:tid 215847] [client 52.202.41.153:65380] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:40:16.367810 2026] [proxy:error] [pid 215691:tid 215883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:40:16.367902 2026] [proxy_http:error] [pid 215691:tid 215883] [client 54.87.222.253:39425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:40:16.368751 2026] [proxy:error] [pid 215691:tid 215883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:40:16.368807 2026] [proxy_http:error] [pid 215691:tid 215883] [client 54.87.222.253:39425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:40:17.338614 2026] [security2:error] [pid 215691:tid 215908] [client 191.232.199.39:44184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/av.php"] [unique_id "amu2sQVxQfK7jpOg6v9NUwAAAFc"]
[Thu Jul 30 15:40:18.167669 2026] [security2:error] [pid 215691:tid 215890] [client 135.119.63.61:51020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/buy.php"] [unique_id "amu2sgVxQfK7jpOg6v9NZAAAAEU"]
[Thu Jul 30 15:40:18.256735 2026] [security2:error] [pid 215691:tid 215903] [client 38.172.162.57:16108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2sgVxQfK7jpOg6v9NaQAAAFI"]
[Thu Jul 30 15:40:18.256865 2026] [security2:error] [pid 215691:tid 215903] [client 38.172.162.57:16108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2sgVxQfK7jpOg6v9NaQAAAFI"]
[Thu Jul 30 15:40:18.554462 2026] [security2:error] [pid 215691:tid 215907] [client 191.232.199.39:2996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/mini.php"] [unique_id "amu2sgVxQfK7jpOg6v9NbQAAAFY"]
[Thu Jul 30 15:40:18.781433 2026] [security2:error] [pid 215691:tid 215855] [client 135.119.63.61:37604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2020/02/rest-api.php"] [unique_id "amu2sgVxQfK7jpOg6v9NcgAAACI"]
[Thu Jul 30 15:40:19.174538 2026] [security2:error] [pid 215691:tid 215900] [client 135.119.63.61:51043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/chosen.php"] [unique_id "amu2swVxQfK7jpOg6v9NewAAAE8"]
[Thu Jul 30 15:40:19.278782 2026] [core:notice] [pid 215691:tid 215882] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:19.602532 2026] [security2:error] [pid 215691:tid 215933] [client 122.172.85.206:19655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2swVxQfK7jpOg6v9NigAAAHA"]
[Thu Jul 30 15:40:19.602745 2026] [security2:error] [pid 215691:tid 215933] [client 122.172.85.206:19655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2swVxQfK7jpOg6v9NigAAAHA"]
[Thu Jul 30 15:40:19.753449 2026] [security2:error] [pid 215691:tid 215836] [client 191.232.199.39:2613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/aa.php"] [unique_id "amu2swVxQfK7jpOg6v9NjgAAAA8"]
[Thu Jul 30 15:40:20.276928 2026] [security2:error] [pid 215691:tid 215916] [client 135.119.63.61:38059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2021/file.php"] [unique_id "amu2tAVxQfK7jpOg6v9NmAAAAF8"]
[Thu Jul 30 15:40:20.859921 2026] [security2:error] [pid 215691:tid 215843] [client 41.210.145.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/wp-login.php"] [unique_id "amu2tAVxQfK7jpOg6v9NogAAFhI"], referer: https://flixon.net/free-movies/
[Thu Jul 30 15:40:21.101589 2026] [security2:error] [pid 215691:tid 215911] [client 43.173.182.144:42510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/12/19/harcourt-brow-studio/"] [unique_id "amu2tAVxQfK7jpOg6v9NsAAAAFo"]
[Thu Jul 30 15:40:21.191825 2026] [security2:error] [pid 215691:tid 215941] [client 191.232.199.39:2964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/w.php"] [unique_id "amu2tQVxQfK7jpOg6v9NswAAAHg"]
[Thu Jul 30 15:40:21.211597 2026] [security2:error] [pid 215691:tid 215894] [client 135.119.63.61:38062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2022/bidlbdgp.php"] [unique_id "amu2tQVxQfK7jpOg6v9NtgAAAEk"]
[Thu Jul 30 15:40:22.095005 2026] [core:notice] [pid 215691:tid 215830] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:22.100063 2026] [security2:error] [pid 215691:tid 215830] [client 43.173.181.247:44858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carnetdeshopping.com"] [uri "/index.php/2016/12/19/harcourt-brow-studio/"] [unique_id "amu2tgVxQfK7jpOg6v9NyQAAAAk"], referer: https://carnetdeshopping.com/index.php/2016/12/19/harcourt-brow-studio/
[Thu Jul 30 15:40:22.623070 2026] [security2:error] [pid 215691:tid 215885] [client 135.119.63.61:37595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jesus.claims"] [uri "/2022/themes.php"] [unique_id "amu2tgVxQfK7jpOg6v9N4AAAAEA"]
[Thu Jul 30 15:40:22.664492 2026] [security2:error] [pid 215691:tid 215929] [client 191.232.199.39:42560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/admin.php"] [unique_id "amu2tgVxQfK7jpOg6v9N4QAAAGw"]
[Thu Jul 30 15:40:23.333661 2026] [security2:error] [pid 215691:tid 215865] [client 135.119.63.61:51046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/class-wp-image.php"] [unique_id "amu2twVxQfK7jpOg6v9N8wAAACw"]
[Thu Jul 30 15:40:23.510499 2026] [security2:error] [pid 215691:tid 215850] [client 74.7.175.152:51236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dl.happymod-apk.com.mx.kev.udi.temporary.site"] [uri "/cgi-sys/404.html"] [unique_id "amu2twVxQfK7jpOg6v9N9wAAHT8"]
[Thu Jul 30 15:40:23.538073 2026] [core:error] [pid 215691:tid 215754] [remote 74.7.244.4:60422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:40:23.538101 2026] [core:error] [pid 215691:tid 215754] [remote 74.7.244.4:60422] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:40:23.538352 2026] [security2:error] [pid 215691:tid 215878] [client 74.7.244.4:60422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "website-a874a23e.glb.nyx.temporary.site"] [uri "/index.php"] [unique_id "amu2twVxQfK7jpOg6v9N-wAAOT4"]
[Thu Jul 30 15:40:23.897284 2026] [security2:error] [pid 215691:tid 215923] [client 191.232.199.39:2212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-content/themes/admin.php"] [unique_id "amu2twVxQfK7jpOg6v9OCAAAAGY"]
[Thu Jul 30 15:40:24.356294 2026] [security2:error] [pid 215691:tid 215946] [client 172.213.208.20:23663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/themes/admin.php"] [unique_id "amu2uAVxQfK7jpOg6v9OFQAAAH0"]
[Thu Jul 30 15:40:25.166549 2026] [security2:error] [pid 215691:tid 215906] [client 172.213.208.20:42205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/m.php"] [unique_id "amu2uQVxQfK7jpOg6v9OKAAAAFU"]
[Thu Jul 30 15:40:25.288209 2026] [security2:error] [pid 215691:tid 215912] [client 191.232.199.39:2224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/m.php"] [unique_id "amu2uQVxQfK7jpOg6v9OKQAAAFs"]
[Thu Jul 30 15:40:25.635040 2026] [security2:error] [pid 215691:tid 215823] [client 2a03:2880:f800:1f:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2uAVxQfK7jpOg6v9OJAAAAlM"]
[Thu Jul 30 15:40:25.723728 2026] [security2:error] [pid 215691:tid 215868] [client 135.119.63.61:50850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/classsmtps.php"] [unique_id "amu2uQVxQfK7jpOg6v9ONAAAAC8"]
[Thu Jul 30 15:40:25.806364 2026] [core:notice] [pid 215691:tid 215856] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:26.223013 2026] [security2:error] [pid 215691:tid 215920] [client 172.213.208.20:42200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amu2ugVxQfK7jpOg6v9OQwAAAGM"]
[Thu Jul 30 15:40:26.296331 2026] [security2:error] [pid 215691:tid 215782] [remote 57.141.0.35:46108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu2ugVxQfK7jpOg6v9ORAAAS1o"]
[Thu Jul 30 15:40:26.993387 2026] [security2:error] [pid 215691:tid 215942] [client 172.213.208.20:14048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wk/index.php"] [unique_id "amu2ugVxQfK7jpOg6v9OUQAAAHk"]
[Thu Jul 30 15:40:27.257895 2026] [security2:error] [pid 215691:tid 215859] [client 191.232.199.39:44202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "amu2ugVxQfK7jpOg6v9OUwAAACY"]
[Thu Jul 30 15:40:28.430373 2026] [security2:error] [pid 215691:tid 215829] [client 172.213.208.20:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/mini.php"] [unique_id "amu2vAVxQfK7jpOg6v9OdQAAAAg"]
[Thu Jul 30 15:40:28.634539 2026] [core:notice] [pid 215691:tid 215924] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:28.675212 2026] [security2:error] [pid 215691:tid 215802] [remote 57.141.0.13:39224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/3407506124/feed/rss2/"] [unique_id "amu2vAVxQfK7jpOg6v9OfQAAE24"]
[Thu Jul 30 15:40:28.879842 2026] [security2:error] [pid 215691:tid 215934] [client 38.172.162.57:16141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2vAVxQfK7jpOg6v9OgAAAAHE"]
[Thu Jul 30 15:40:28.879989 2026] [security2:error] [pid 215691:tid 215934] [client 38.172.162.57:16141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2vAVxQfK7jpOg6v9OgAAAAHE"]
[Thu Jul 30 15:40:29.051059 2026] [security2:error] [pid 215691:tid 215844] [client 191.232.199.39:2184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/classwithtostring.php"] [unique_id "amu2vQVxQfK7jpOg6v9OhAAAABc"]
[Thu Jul 30 15:40:29.238540 2026] [security2:error] [pid 215691:tid 215821] [client 172.213.208.20:42231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/aa.php"] [unique_id "amu2vQVxQfK7jpOg6v9OiwAAAAA"]
[Thu Jul 30 15:40:29.893461 2026] [security2:error] [pid 215691:tid 215879] [client 172.213.208.20:25993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/w.php"] [unique_id "amu2vQVxQfK7jpOg6v9OlgAAADo"]
[Thu Jul 30 15:40:30.238637 2026] [security2:error] [pid 215691:tid 215915] [client 122.172.85.206:1233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2vgVxQfK7jpOg6v9OnQAAAF4"]
[Thu Jul 30 15:40:30.238748 2026] [security2:error] [pid 215691:tid 215915] [client 122.172.85.206:1233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2vgVxQfK7jpOg6v9OnQAAAF4"]
[Thu Jul 30 15:40:30.381325 2026] [security2:error] [pid 215691:tid 215893] [client 135.119.63.61:50954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/classwithtostring.php"] [unique_id "amu2vgVxQfK7jpOg6v9OoQAAAEg"]
[Thu Jul 30 15:40:30.437871 2026] [security2:error] [pid 215691:tid 215828] [client 191.232.199.39:2990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/gmo.php"] [unique_id "amu2vgVxQfK7jpOg6v9OogAAAAc"]
[Thu Jul 30 15:40:30.690420 2026] [security2:error] [pid 215691:tid 215833] [client 172.213.208.20:25723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/admin.php"] [unique_id "amu2vgVxQfK7jpOg6v9OpwAAAAw"]
[Thu Jul 30 15:40:31.264834 2026] [security2:error] [pid 215691:tid 215838] [client 172.213.208.20:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/404.php"] [unique_id "amu2vwVxQfK7jpOg6v9OugAAABE"]
[Thu Jul 30 15:40:31.510590 2026] [security2:error] [pid 215691:tid 215924] [client 135.119.63.61:50869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/config.php"] [unique_id "amu2vwVxQfK7jpOg6v9OwQAAAGc"]
[Thu Jul 30 15:40:31.779400 2026] [security2:error] [pid 215691:tid 215937] [client 191.232.199.39:2959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-content/languages/index.php"] [unique_id "amu2vwVxQfK7jpOg6v9OxQAAAHQ"]
[Thu Jul 30 15:40:33.122214 2026] [security2:error] [pid 215691:tid 215898] [client 135.119.63.61:51027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/core.php"] [unique_id "amu2wQVxQfK7jpOg6v9O5AAAAE0"]
[Thu Jul 30 15:40:33.635042 2026] [security2:error] [pid 215691:tid 215905] [client 191.232.199.39:2588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-the.php"] [unique_id "amu2wQVxQfK7jpOg6v9O7gAAAFQ"]
[Thu Jul 30 15:40:34.341196 2026] [security2:error] [pid 215691:tid 215846] [client 172.213.208.20:17665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/init.php"] [unique_id "amu2wgVxQfK7jpOg6v9O-QAAABk"]
[Thu Jul 30 15:40:34.414353 2026] [core:notice] [pid 215691:tid 215863] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:34.675813 2026] [security2:error] [pid 215691:tid 215929] [client 2a03:2880:f800:3a:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu2wgVxQfK7jpOg6v9O8gAAbAs"]
[Thu Jul 30 15:40:35.015259 2026] [autoindex:error] [pid 215691:tid 215944] [client 46.225.209.92:49862] AH01276: Cannot serve directory /home2/mbmudite/melatipkr.xyz/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:40:35.908518 2026] [security2:error] [pid 215691:tid 215864] [client 191.232.199.39:2603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/404.php"] [unique_id "amu2wwVxQfK7jpOg6v9PGwAAACs"]
[Thu Jul 30 15:40:35.928019 2026] [core:notice] [pid 215691:tid 215902] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:35.942871 2026] [security2:error] [pid 215691:tid 215933] [client 135.119.63.61:50870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/css.php"] [unique_id "amu2wwVxQfK7jpOg6v9PHQAAAHA"]
[Thu Jul 30 15:40:36.029422 2026] [security2:error] [pid 215691:tid 215937] [client 172.213.208.20:25984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/adminfuns.php"] [unique_id "amu2xAVxQfK7jpOg6v9PIQAAAHQ"]
[Thu Jul 30 15:40:36.046524 2026] [core:notice] [pid 215691:tid 215907] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:36.110951 2026] [autoindex:error] [pid 215691:tid 215867] [client 66.132.186.178:36486] AH01276: Cannot serve directory /home1/khwnyxte/kingstarenterprises.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Thu Jul 30 15:40:36.239202 2026] [core:error] [pid 215691:tid 215729] [remote 52.167.144.191:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:40:36.239229 2026] [core:error] [pid 215691:tid 215729] [remote 52.167.144.191:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Thu Jul 30 15:40:36.590429 2026] [security2:error] [pid 215691:tid 215823] [client 172.213.208.20:42225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/file.php"] [unique_id "amu2xAVxQfK7jpOg6v9PNAAAAAI"]
[Thu Jul 30 15:40:36.894245 2026] [security2:error] [pid 215691:tid 215931] [client 52.167.144.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "heatstickhk.com"] [uri "/index.php"] [unique_id "amu2wwVxQfK7jpOg6v9PGgAAbiM"]
[Thu Jul 30 15:40:37.105602 2026] [core:notice] [pid 215691:tid 215832] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:37.161258 2026] [security2:error] [pid 215691:tid 215845] [client 191.232.199.39:44192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/init.php"] [unique_id "amu2xQVxQfK7jpOg6v9PRQAAABg"]
[Thu Jul 30 15:40:37.201558 2026] [security2:error] [pid 215691:tid 215905] [client 135.119.63.61:50947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/database.php"] [unique_id "amu2xQVxQfK7jpOg6v9PSAAAAFQ"]
[Thu Jul 30 15:40:37.337898 2026] [security2:error] [pid 215691:tid 215858] [client 20.118.34.237:6403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amu2xQVxQfK7jpOg6v9PTQAAACU"]
[Thu Jul 30 15:40:37.535434 2026] [security2:error] [pid 215691:tid 215849] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2xAVxQfK7jpOg6v9PQAAAABw"]
[Thu Jul 30 15:40:38.018087 2026] [security2:error] [pid 215691:tid 215866] [client 172.213.208.20:14033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/222.php"] [unique_id "amu2xgVxQfK7jpOg6v9PXAAAAC0"]
[Thu Jul 30 15:40:38.023585 2026] [security2:error] [pid 215691:tid 215821] [client 223.109.252.208:50174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mediaspawn.com"] [uri "/"] [unique_id "amu2xgVxQfK7jpOg6v9PXQAAAAA"]
[Thu Jul 30 15:40:38.023696 2026] [security2:error] [pid 215691:tid 215821] [client 223.109.252.208:50174] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.mediaspawn.com"] [uri "/"] [unique_id "amu2xgVxQfK7jpOg6v9PXQAAAAA"]
[Thu Jul 30 15:40:38.237176 2026] [security2:error] [pid 215691:tid 215881] [client 41.210.145.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "flixon.net"] [uri "/index.php"] [unique_id "amu2xQVxQfK7jpOg6v9PWwAAPDw"], referer: https://flixon.net/login/
[Thu Jul 30 15:40:38.292363 2026] [security2:error] [pid 215691:tid 215844] [client 135.119.63.61:50847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/db.php"] [unique_id "amu2xgVxQfK7jpOg6v9PZAAAABc"]
[Thu Jul 30 15:40:38.410605 2026] [security2:error] [pid 215691:tid 215908] [client 57.141.0.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2xQVxQfK7jpOg6v9PWgAAAFc"]
[Thu Jul 30 15:40:38.595202 2026] [security2:error] [pid 215691:tid 215938] [client 191.232.199.39:3001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/file5.php"] [unique_id "amu2xgVxQfK7jpOg6v9PaQAAAHU"]
[Thu Jul 30 15:40:38.964495 2026] [security2:error] [pid 215691:tid 215843] [client 172.213.208.20:25673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amu2xgVxQfK7jpOg6v9PcwAAABY"]
[Thu Jul 30 15:40:38.972832 2026] [security2:error] [pid 215691:tid 215904] [client 172.237.109.114:11722] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/pilotpress/readme.txt"] [unique_id "amu2xgVxQfK7jpOg6v9PdAAAAFM"]
[Thu Jul 30 15:40:39.431565 2026] [security2:error] [pid 215691:tid 215841] [client 38.172.162.57:16583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2xwVxQfK7jpOg6v9PfgAAABQ"]
[Thu Jul 30 15:40:39.431681 2026] [security2:error] [pid 215691:tid 215841] [client 38.172.162.57:16583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu2xwVxQfK7jpOg6v9PfgAAABQ"]
[Thu Jul 30 15:40:39.837063 2026] [security2:error] [pid 215691:tid 215882] [client 191.232.199.39:2972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-admin/maint/index.php"] [unique_id "amu2xwVxQfK7jpOg6v9PggAAAD0"]
[Thu Jul 30 15:40:39.980224 2026] [security2:error] [pid 215691:tid 215762] [remote 20.118.34.237:6417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arabiantourz.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "amu2xwVxQfK7jpOg6v9PiQAAfkY"]
[Thu Jul 30 15:40:40.090592 2026] [security2:error] [pid 215691:tid 215896] [client 20.151.221.234:29825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webdisk.pnimanpower.net"] [uri "/"] [unique_id "amu2yAVxQfK7jpOg6v9PigAAAEs"]
[Thu Jul 30 15:40:40.294808 2026] [security2:error] [pid 215691:tid 215828] [client 135.119.63.61:50685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/default.php"] [unique_id "amu2yAVxQfK7jpOg6v9PjgAAAAc"]
[Thu Jul 30 15:40:40.595384 2026] [security2:error] [pid 215691:tid 215944] [client 20.151.221.234:49743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webdisk.pnimanpower.net"] [uri "/"] [unique_id "amu2yAVxQfK7jpOg6v9PlgAAAHs"]
[Thu Jul 30 15:40:40.922612 2026] [security2:error] [pid 215691:tid 215821] [client 122.172.85.206:15392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2yAVxQfK7jpOg6v9PoQAAAAA"]
[Thu Jul 30 15:40:40.922826 2026] [security2:error] [pid 215691:tid 215821] [client 122.172.85.206:15392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu2yAVxQfK7jpOg6v9PoQAAAAA"]
[Thu Jul 30 15:40:41.059812 2026] [security2:error] [pid 215691:tid 215940] [client 191.232.199.39:2568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/shell.php"] [unique_id "amu2yQVxQfK7jpOg6v9PpwAAAHc"]
[Thu Jul 30 15:40:41.403427 2026] [security2:error] [pid 215691:tid 215912] [client 47.128.121.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cnpinyin.com"] [uri "/index.php"] [unique_id "amu2yQVxQfK7jpOg6v9PrAAAAFs"]
[Thu Jul 30 15:40:42.451308 2026] [security2:error] [pid 215691:tid 215931] [client 191.232.199.39:2947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/f35.php"] [unique_id "amu2ygVxQfK7jpOg6v9P0QAAAG4"]
[Thu Jul 30 15:40:42.908320 2026] [security2:error] [pid 215691:tid 215845] [client 57.141.0.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "saifalkhaleejest.com"] [uri "/index.php"] [unique_id "amu2ygVxQfK7jpOg6v9PyQAAABg"]
[Thu Jul 30 15:40:43.994444 2026] [security2:error] [pid 215691:tid 215870] [client 172.237.109.114:45012] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/addon-elements-for-elementor-page-builder/readme.txt"] [unique_id "amu2ywVxQfK7jpOg6v9P9AAAADE"]
[Thu Jul 30 15:40:44.008786 2026] [security2:error] [pid 215691:tid 215928] [client 141.98.102.227:33836] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu2zAVxQfK7jpOg6v9P9gAAAGs"]
[Thu Jul 30 15:40:44.008877 2026] [security2:error] [pid 215691:tid 215928] [client 141.98.102.227:33836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "upns.ca"] [uri "/xmlrpc.php"] [unique_id "amu2zAVxQfK7jpOg6v9P9gAAAGs"]
[Thu Jul 30 15:40:44.167796 2026] [security2:error] [pid 215691:tid 215927] [client 191.232.199.39:42562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/new.php"] [unique_id "amu2zAVxQfK7jpOg6v9P-wAAAGo"]
[Thu Jul 30 15:40:44.628834 2026] [security2:error] [pid 215691:tid 215852] [client 172.213.208.20:14043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-content/admin.php"] [unique_id "amu2zAVxQfK7jpOg6v9QBwAAAB8"]
[Thu Jul 30 15:40:44.688762 2026] [security2:error] [pid 215691:tid 215850] [client 135.119.63.61:50681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/dropdown.php"] [unique_id "amu2zAVxQfK7jpOg6v9QCAAAAB0"]
[Thu Jul 30 15:40:45.255479 2026] [security2:error] [pid 215691:tid 215899] [client 172.213.208.20:56202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-configs.php"] [unique_id "amu2zQVxQfK7jpOg6v9QEQAAAE4"]
[Thu Jul 30 15:40:45.504049 2026] [security2:error] [pid 215691:tid 215937] [client 191.232.199.39:2988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/adminfuns.php"] [unique_id "amu2zQVxQfK7jpOg6v9QHgAAAHQ"]
[Thu Jul 30 15:40:45.528445 2026] [security2:error] [pid 215691:tid 215838] [client 135.119.63.61:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/edit.php"] [unique_id "amu2zQVxQfK7jpOg6v9QHwAAABE"]
[Thu Jul 30 15:40:45.836159 2026] [core:notice] [pid 215691:tid 215941] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:46.358462 2026] [security2:error] [pid 215691:tid 215827] [client 135.119.63.61:50645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/f35.php"] [unique_id "amu2zgVxQfK7jpOg6v9QPQAAAAY"]
[Thu Jul 30 15:40:46.948569 2026] [core:notice] [pid 215691:tid 215870] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:47.332704 2026] [security2:error] [pid 215691:tid 215860] [client 135.119.63.61:50871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.63.119.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.arabian-tours.com"] [uri "/f7.php"] [unique_id "amu2zwVxQfK7jpOg6v9QVAAAACc"]
[Thu Jul 30 15:40:47.349528 2026] [core:notice] [pid 215691:tid 215872] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:47.693921 2026] [security2:error] [pid 215691:tid 215846] [client 191.232.199.39:44212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/fm.php"] [unique_id "amu2zwVxQfK7jpOg6v9QWgAAABk"]
[Thu Jul 30 15:40:47.969339 2026] [security2:error] [pid 215691:tid 215945] [client 172.237.109.114:30035] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "alseermarine.com"] [uri "/wp-content/plugins/nicebackgrounds/readme.txt"] [unique_id "amu2zwVxQfK7jpOg6v9QYgAAAHw"]
[Thu Jul 30 15:40:49.087262 2026] [security2:error] [pid 215691:tid 215862] [client 172.213.208.20:17717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/php.php"] [unique_id "amu20QVxQfK7jpOg6v9QdwAAACk"]
[Thu Jul 30 15:40:49.815327 2026] [core:notice] [pid 215691:tid 215857] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:49.913174 2026] [security2:error] [pid 215691:tid 215854] [client 172.213.208.20:17682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/index.php"] [unique_id "amu20QVxQfK7jpOg6v9QiwAAACE"]
[Thu Jul 30 15:40:50.019575 2026] [security2:error] [pid 215691:tid 215900] [client 38.172.162.57:16015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu20gVxQfK7jpOg6v9QjAAAAE8"]
[Thu Jul 30 15:40:50.020526 2026] [security2:error] [pid 215691:tid 215900] [client 38.172.162.57:16015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu20gVxQfK7jpOg6v9QjAAAAE8"]
[Thu Jul 30 15:40:50.161281 2026] [security2:error] [pid 215691:tid 215833] [client 191.232.199.39:2564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/file.php"] [unique_id "amu20gVxQfK7jpOg6v9QjQAAAAw"]
[Thu Jul 30 15:40:50.855745 2026] [security2:error] [pid 215691:tid 215843] [client 2a03:2880:f800:17:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu20gVxQfK7jpOg6v9QjgAAFik"]
[Thu Jul 30 15:40:51.564392 2026] [security2:error] [pid 215691:tid 215906] [client 122.172.85.206:9669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu20wVxQfK7jpOg6v9QsQAAAFU"]
[Thu Jul 30 15:40:51.564584 2026] [security2:error] [pid 215691:tid 215906] [client 122.172.85.206:9669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu20wVxQfK7jpOg6v9QsQAAAFU"]
[Thu Jul 30 15:40:51.691165 2026] [security2:error] [pid 215691:tid 215860] [client 172.213.208.20:56245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/a.php"] [unique_id "amu20wVxQfK7jpOg6v9QsgAAACc"]
[Thu Jul 30 15:40:52.146232 2026] [core:notice] [pid 215691:tid 215840] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:52.500991 2026] [security2:error] [pid 215691:tid 215917] [client 191.232.199.39:2979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/bolt.php"] [unique_id "amu21AVxQfK7jpOg6v9QwwAAAGA"]
[Thu Jul 30 15:40:53.060335 2026] [security2:error] [pid 215691:tid 215875] [client 172.213.208.20:56253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/Text/about.php"] [unique_id "amu21QVxQfK7jpOg6v9Q1gAAADY"]
[Thu Jul 30 15:40:53.999205 2026] [security2:error] [pid 215691:tid 215948] [client 191.232.199.39:42582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/3.php"] [unique_id "amu21QVxQfK7jpOg6v9Q4wAAAH8"]
[Thu Jul 30 15:40:54.485799 2026] [security2:error] [pid 215691:tid 215872] [client 172.213.208.20:56225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin.php"] [unique_id "amu21gVxQfK7jpOg6v9Q7gAAADM"]
[Thu Jul 30 15:40:55.268729 2026] [security2:error] [pid 215691:tid 215911] [client 172.237.109.114:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.109.237.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alseermarine.com"] [uri "/status.php"] [unique_id "amu21wVxQfK7jpOg6v9Q-AAAAFo"]
[Thu Jul 30 15:40:55.386661 2026] [security2:error] [pid 215691:tid 215912] [client 172.213.208.20:17722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/size.php"] [unique_id "amu21wVxQfK7jpOg6v9Q_wAAAFs"]
[Thu Jul 30 15:40:55.518811 2026] [security2:error] [pid 215691:tid 215862] [client 191.232.199.39:42596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/222.php"] [unique_id "amu21wVxQfK7jpOg6v9RAwAAACk"]
[Thu Jul 30 15:40:56.917329 2026] [security2:error] [pid 215691:tid 215931] [client 191.232.199.39:2983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-admin/images/admin.php"] [unique_id "amu22AVxQfK7jpOg6v9RIAAAAG4"]
[Thu Jul 30 15:40:58.116385 2026] [security2:error] [pid 215691:tid 215839] [client 172.213.208.20:17692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/wp-class.php"] [unique_id "amu22gVxQfK7jpOg6v9RPQAAABI"]
[Thu Jul 30 15:40:58.324359 2026] [security2:error] [pid 215691:tid 215913] [client 191.232.199.39:2612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "amu22gVxQfK7jpOg6v9RRwAAAFw"]
[Thu Jul 30 15:40:58.562738 2026] [security2:error] [pid 215691:tid 215881] [client 74.7.228.36:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-4bf50d02.dlr.djb.temporary.site"] [uri "/index.php"] [unique_id "amu22QVxQfK7jpOg6v9ROAAAADw"]
[Thu Jul 30 15:40:58.563485 2026] [security2:error] [pid 215691:tid 215895] [client 74.7.228.36:49080] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "website-4bf50d02.dlr.djb.temporary.site"] [uri "/robots.txt"] [unique_id "amu22QVxQfK7jpOg6v9RNgAASl0"]
[Thu Jul 30 15:40:58.790320 2026] [security2:error] [pid 215691:tid 215912] [client 172.213.208.20:14063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/403.php"] [unique_id "amu22gVxQfK7jpOg6v9RTQAAAFs"]
[Thu Jul 30 15:40:58.991305 2026] [security2:error] [pid 215691:tid 215853] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu22gVxQfK7jpOg6v9RVgAAACA"]
[Thu Jul 30 15:40:58.991467 2026] [security2:error] [pid 215691:tid 215853] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amu22gVxQfK7jpOg6v9RVgAAACA"]
[Thu Jul 30 15:40:59.232464 2026] [security2:error] [pid 215691:tid 215882] [client 74.7.244.58:59508] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "online-hope.com"] [uri "/robots.txt"] [unique_id "amu22wVxQfK7jpOg6v9RWQAAPXE"]
[Thu Jul 30 15:40:59.241066 2026] [security2:error] [pid 215691:tid 215899] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu22wVxQfK7jpOg6v9RXgAAAE4"]
[Thu Jul 30 15:40:59.241210 2026] [security2:error] [pid 215691:tid 215899] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "amu22wVxQfK7jpOg6v9RXgAAAE4"]
[Thu Jul 30 15:40:59.472059 2026] [security2:error] [pid 215691:tid 215861] [client 172.237.109.114:45025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alseermarine.com"] [uri "/index.php"] [unique_id "amu22gVxQfK7jpOg6v9RVQAAACg"]
[Thu Jul 30 15:40:59.494965 2026] [security2:error] [pid 215691:tid 215942] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/3PJcpMFsD8B.php"] [unique_id "amu22wVxQfK7jpOg6v9RZQAAAHk"]
[Thu Jul 30 15:40:59.495097 2026] [security2:error] [pid 215691:tid 215942] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/3PJcpMFsD8B.php"] [unique_id "amu22wVxQfK7jpOg6v9RZQAAAHk"]
[Thu Jul 30 15:40:59.645277 2026] [core:notice] [pid 215691:tid 215909] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:40:59.732645 2026] [security2:error] [pid 215691:tid 215943] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/err.php"] [unique_id "amu22wVxQfK7jpOg6v9RZwAAAHo"]
[Thu Jul 30 15:40:59.732754 2026] [security2:error] [pid 215691:tid 215943] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/err.php"] [unique_id "amu22wVxQfK7jpOg6v9RZwAAAHo"]
[Thu Jul 30 15:41:00.058183 2026] [security2:error] [pid 215691:tid 215920] [client 191.232.199.39:2593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-content/admin.php"] [unique_id "amu23AVxQfK7jpOg6v9RcQAAAGM"]
[Thu Jul 30 15:41:00.173744 2026] [security2:error] [pid 215691:tid 215886] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/img.php"] [unique_id "amu23AVxQfK7jpOg6v9RcgAAAEE"]
[Thu Jul 30 15:41:00.173890 2026] [security2:error] [pid 215691:tid 215886] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/img.php"] [unique_id "amu23AVxQfK7jpOg6v9RcgAAAEE"]
[Thu Jul 30 15:41:00.180213 2026] [core:notice] [pid 215691:tid 215869] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:41:00.215364 2026] [security2:error] [pid 215691:tid 215834] [client 172.213.208.20:42186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "amu23AVxQfK7jpOg6v9RdAAAAA0"]
[Thu Jul 30 15:41:00.373961 2026] [security2:error] [pid 215691:tid 215887] [client 111.225.148.171:12412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arabiandubaisafari.com"] [uri "/dubai-safari-quadbike.html"] [unique_id "amu23AVxQfK7jpOg6v9RfAAAAEI"]
[Thu Jul 30 15:41:00.421174 2026] [security2:error] [pid 215691:tid 215826] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aa.php"] [unique_id "amu23AVxQfK7jpOg6v9RfwAAAAU"]
[Thu Jul 30 15:41:00.421315 2026] [security2:error] [pid 215691:tid 215826] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/aa.php"] [unique_id "amu23AVxQfK7jpOg6v9RfwAAAAU"]
[Thu Jul 30 15:41:00.683755 2026] [security2:error] [pid 215691:tid 215928] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/av.php"] [unique_id "amu23AVxQfK7jpOg6v9RjQAAAGs"]
[Thu Jul 30 15:41:00.683844 2026] [security2:error] [pid 215691:tid 215928] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/av.php"] [unique_id "amu23AVxQfK7jpOg6v9RjQAAAGs"]
[Thu Jul 30 15:41:00.805794 2026] [security2:error] [pid 215691:tid 215880] [client 38.172.162.57:16189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.162.172.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu23AVxQfK7jpOg6v9RkQAAADs"]
[Thu Jul 30 15:41:00.805951 2026] [security2:error] [pid 215691:tid 215880] [client 38.172.162.57:16189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "seven-stars-shop.com"] [uri "/xmlrpc.php"] [unique_id "amu23AVxQfK7jpOg6v9RkQAAADs"]
[Thu Jul 30 15:41:00.936408 2026] [security2:error] [pid 215691:tid 215853] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xa.php"] [unique_id "amu23AVxQfK7jpOg6v9RnwAAACA"]
[Thu Jul 30 15:41:00.936514 2026] [security2:error] [pid 215691:tid 215853] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xa.php"] [unique_id "amu23AVxQfK7jpOg6v9RnwAAACA"]
[Thu Jul 30 15:41:00.999320 2026] [security2:error] [pid 215691:tid 215849] [client 2a03:2880:f800:18:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allmontecristi.com"] [uri "/index.php"] [unique_id "amu23AVxQfK7jpOg6v9ReAAAHG8"]
[Thu Jul 30 15:41:01.206377 2026] [security2:error] [pid 215691:tid 215932] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/media.php"] [unique_id "amu23QVxQfK7jpOg6v9RogAAAG8"]
[Thu Jul 30 15:41:01.206473 2026] [security2:error] [pid 215691:tid 215932] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/media.php"] [unique_id "amu23QVxQfK7jpOg6v9RogAAAG8"]
[Thu Jul 30 15:41:01.359684 2026] [security2:error] [pid 215691:tid 215891] [client 191.232.199.39:42622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-configs.php"] [unique_id "amu23QVxQfK7jpOg6v9RqgAAAEY"]
[Thu Jul 30 15:41:01.445117 2026] [security2:error] [pid 215691:tid 215931] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/images.php"] [unique_id "amu23QVxQfK7jpOg6v9RswAAAG4"]
[Thu Jul 30 15:41:01.445264 2026] [security2:error] [pid 215691:tid 215931] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/images.php"] [unique_id "amu23QVxQfK7jpOg6v9RswAAAG4"]
[Thu Jul 30 15:41:01.464966 2026] [security2:error] [pid 215691:tid 215939] [client 172.213.208.20:17681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/as.php"] [unique_id "amu23QVxQfK7jpOg6v9RuQAAAHY"]
[Thu Jul 30 15:41:01.687614 2026] [security2:error] [pid 215691:tid 215926] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/gecko.php"] [unique_id "amu23QVxQfK7jpOg6v9RuwAAAGk"]
[Thu Jul 30 15:41:01.687725 2026] [security2:error] [pid 215691:tid 215926] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/gecko.php"] [unique_id "amu23QVxQfK7jpOg6v9RuwAAAGk"]
[Thu Jul 30 15:41:01.930136 2026] [security2:error] [pid 215691:tid 215913] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/82.php"] [unique_id "amu23QVxQfK7jpOg6v9RyQAAAFw"]
[Thu Jul 30 15:41:01.930299 2026] [security2:error] [pid 215691:tid 215913] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/82.php"] [unique_id "amu23QVxQfK7jpOg6v9RyQAAAFw"]
[Thu Jul 30 15:41:01.955189 2026] [core:notice] [pid 215691:tid 215707] AH00113: /home1/vdbnyxte/public_html/website_7c59acf7/.htaccess:23 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:41:02.184677 2026] [security2:error] [pid 215691:tid 215915] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xstelth.php"] [unique_id "amu23gVxQfK7jpOg6v9R0gAAAF4"]
[Thu Jul 30 15:41:02.184792 2026] [security2:error] [pid 215691:tid 215915] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xstelth.php"] [unique_id "amu23gVxQfK7jpOg6v9R0gAAAF4"]
[Thu Jul 30 15:41:02.257421 2026] [security2:error] [pid 215691:tid 215854] [client 122.172.85.206:17760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.85.172.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu23gVxQfK7jpOg6v9R0wAAACE"]
[Thu Jul 30 15:41:02.257596 2026] [security2:error] [pid 215691:tid 215854] [client 122.172.85.206:17760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "linasteamrunning.com"] [uri "/xmlrpc.php"] [unique_id "amu23gVxQfK7jpOg6v9R0wAAACE"]
[Thu Jul 30 15:41:02.281155 2026] [security2:error] [pid 215691:tid 215842] [client 172.213.208.20:23641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/includes/index.php"] [unique_id "amu23gVxQfK7jpOg6v9R1AAAABU"]
[Thu Jul 30 15:41:02.421872 2026] [security2:error] [pid 215691:tid 215832] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xp.php"] [unique_id "amu23gVxQfK7jpOg6v9R2gAAAAs"]
[Thu Jul 30 15:41:02.421972 2026] [security2:error] [pid 215691:tid 215832] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/xp.php"] [unique_id "amu23gVxQfK7jpOg6v9R2gAAAAs"]
[Thu Jul 30 15:41:02.690084 2026] [security2:error] [pid 215691:tid 215919] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amu23gVxQfK7jpOg6v9R3wAAAGI"]
[Thu Jul 30 15:41:02.690204 2026] [security2:error] [pid 215691:tid 215919] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amu23gVxQfK7jpOg6v9R3wAAAGI"]
[Thu Jul 30 15:41:02.696576 2026] [security2:error] [pid 215691:tid 215837] [client 191.232.199.39:2145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/php.php"] [unique_id "amu23gVxQfK7jpOg6v9R4AAAABA"]
[Thu Jul 30 15:41:02.940727 2026] [security2:error] [pid 215691:tid 215896] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/adminner.php"] [unique_id "amu23gVxQfK7jpOg6v9R5wAAAEs"]
[Thu Jul 30 15:41:02.940826 2026] [security2:error] [pid 215691:tid 215896] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/adminner.php"] [unique_id "amu23gVxQfK7jpOg6v9R5wAAAEs"]
[Thu Jul 30 15:41:03.114322 2026] [security2:error] [pid 215691:tid 215870] [client 172.213.208.20:23675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "amu23wVxQfK7jpOg6v9R7AAAADE"]
[Thu Jul 30 15:41:03.175689 2026] [security2:error] [pid 215691:tid 215711] [remote 112.78.134.58:47044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fireworkskenya.co.ke"] [uri "/wp-login.php"] [unique_id "amu23wVxQfK7jpOg6v9R7QAATxM"]
[Thu Jul 30 15:41:03.186613 2026] [security2:error] [pid 215691:tid 215943] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/a.php"] [unique_id "amu23wVxQfK7jpOg6v9R7gAAAHo"]
[Thu Jul 30 15:41:03.186699 2026] [security2:error] [pid 215691:tid 215943] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/a.php"] [unique_id "amu23wVxQfK7jpOg6v9R7gAAAHo"]
[Thu Jul 30 15:41:03.237597 2026] [core:notice] [pid 215691:tid 215905] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:41:03.434107 2026] [security2:error] [pid 215691:tid 215822] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/k.php"] [unique_id "amu23wVxQfK7jpOg6v9R8wAAAAE"]
[Thu Jul 30 15:41:03.434205 2026] [security2:error] [pid 215691:tid 215822] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/k.php"] [unique_id "amu23wVxQfK7jpOg6v9R8wAAAAE"]
[Thu Jul 30 15:41:03.571866 2026] [core:notice] [pid 215691:tid 215925] AH00113: /home1/vdbnyxte/public_html/website_2258ef87/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:41:03.688322 2026] [security2:error] [pid 215691:tid 215921] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/222.php"] [unique_id "amu23wVxQfK7jpOg6v9R_gAAAGQ"]
[Thu Jul 30 15:41:03.688471 2026] [security2:error] [pid 215691:tid 215921] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/222.php"] [unique_id "amu23wVxQfK7jpOg6v9R_gAAAGQ"]
[Thu Jul 30 15:41:03.744750 2026] [security2:error] [pid 215691:tid 215947] [client 172.213.208.20:23647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/plugins.php"] [unique_id "amu23wVxQfK7jpOg6v9R_wAAAH4"]
[Thu Jul 30 15:41:03.787943 2026] [security2:error] [pid 215691:tid 215847] [client 85.208.96.194:60322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amu23wVxQfK7jpOg6v9SAAAAABo"]
[Thu Jul 30 15:41:03.788145 2026] [security2:error] [pid 215691:tid 215847] [client 85.208.96.194:60322] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amu23wVxQfK7jpOg6v9SAAAAABo"]
[Thu Jul 30 15:41:03.886890 2026] [security2:error] [pid 215691:tid 215938] [client 35.204.109.104:4096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.carnetdeshopping.com"] [uri "/"] [unique_id "amu23wVxQfK7jpOg6v9SAgAAAHU"]
[Thu Jul 30 15:41:03.887006 2026] [security2:error] [pid 215691:tid 215938] [client 35.204.109.104:4096] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.carnetdeshopping.com"] [uri "/"] [unique_id "amu23wVxQfK7jpOg6v9SAgAAAHU"]
[Thu Jul 30 15:41:03.915253 2026] [security2:error] [pid 215691:tid 215827] [client 191.232.199.39:2570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-includes/index.php"] [unique_id "amu23wVxQfK7jpOg6v9SAwAAAAY"]
[Thu Jul 30 15:41:03.928363 2026] [security2:error] [pid 215691:tid 215929] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amu23wVxQfK7jpOg6v9SBwAAAGw"]
[Thu Jul 30 15:41:03.928508 2026] [security2:error] [pid 215691:tid 215929] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/mac.php"] [unique_id "amu23wVxQfK7jpOg6v9SBwAAAGw"]
[Thu Jul 30 15:41:03.975268 2026] [core:notice] [pid 215691:tid 215894] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:41:04.171590 2026] [proxy:error] [pid 215691:tid 215881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:41:04.171677 2026] [proxy_http:error] [pid 215691:tid 215881] [client 4.184.185.91:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:41:04.172259 2026] [proxy:error] [pid 215691:tid 215881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:41:04.172304 2026] [proxy_http:error] [pid 215691:tid 215881] [client 4.184.185.91:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:41:04.172395 2026] [security2:error] [pid 215691:tid 215881] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu24AVxQfK7jpOg6v9SDwAAADw"]
[Thu Jul 30 15:41:04.422591 2026] [proxy:error] [pid 215691:tid 215823] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:41:04.422663 2026] [proxy_http:error] [pid 215691:tid 215823] [client 4.184.185.91:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:41:04.423327 2026] [proxy:error] [pid 215691:tid 215823] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:41:04.423380 2026] [proxy_http:error] [pid 215691:tid 215823] [client 4.184.185.91:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:41:04.423477 2026] [security2:error] [pid 215691:tid 215823] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu24AVxQfK7jpOg6v9SEAAAAAI"]
[Thu Jul 30 15:41:04.680813 2026] [security2:error] [pid 215691:tid 215867] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amu24AVxQfK7jpOg6v9SGwAAAC4"]
[Thu Jul 30 15:41:04.680915 2026] [security2:error] [pid 215691:tid 215867] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ops.php"] [unique_id "amu24AVxQfK7jpOg6v9SGwAAAC4"]
[Thu Jul 30 15:41:04.908268 2026] [security2:error] [pid 215691:tid 215736] [remote 57.141.0.41:41276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/55997217192/feed/rss2/"] [unique_id "amu24AVxQfK7jpOg6v9SGgAASCw"]
[Thu Jul 30 15:41:04.932439 2026] [security2:error] [pid 215691:tid 215879] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amu24AVxQfK7jpOg6v9SHQAAADo"]
[Thu Jul 30 15:41:04.932534 2026] [security2:error] [pid 215691:tid 215879] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/8.php"] [unique_id "amu24AVxQfK7jpOg6v9SHQAAADo"]
[Thu Jul 30 15:41:05.110256 2026] [security2:error] [pid 215691:tid 215737] [remote 74.7.243.224:58680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aded-rdc.org"] [uri "/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/misionf.php"] [unique_id "amu24QVxQfK7jpOg6v9SJgAANy0"], referer: https://aded-rdc.org/category/autonomisation/img/js/uploads/partners/uploads/partners/uploads/partners/js/bootstrap.bundle.min.js
[Thu Jul 30 15:41:05.191003 2026] [security2:error] [pid 215691:tid 215877] [client 191.232.199.39:2623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-admin/a.php"] [unique_id "amu24QVxQfK7jpOg6v9SKwAAADg"]
[Thu Jul 30 15:41:05.335400 2026] [security2:error] [pid 215691:tid 215896] [client 185.191.171.12:58154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amu24QVxQfK7jpOg6v9SLAAAAEs"]
[Thu Jul 30 15:41:05.335552 2026] [security2:error] [pid 215691:tid 215896] [client 185.191.171.12:58154] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/robots.txt"] [unique_id "amu24QVxQfK7jpOg6v9SLAAAAEs"]
[Thu Jul 30 15:41:05.344423 2026] [security2:error] [pid 215691:tid 215945] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/FWAZ.php"] [unique_id "amu24QVxQfK7jpOg6v9SLQAAAHw"]
[Thu Jul 30 15:41:05.344521 2026] [security2:error] [pid 215691:tid 215945] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/FWAZ.php"] [unique_id "amu24QVxQfK7jpOg6v9SLQAAAHw"]
[Thu Jul 30 15:41:05.584781 2026] [security2:error] [pid 215691:tid 215941] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/biufile.php"] [unique_id "amu24QVxQfK7jpOg6v9SMQAAAHg"]
[Thu Jul 30 15:41:05.584879 2026] [security2:error] [pid 215691:tid 215941] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/biufile.php"] [unique_id "amu24QVxQfK7jpOg6v9SMQAAAHg"]
[Thu Jul 30 15:41:06.094238 2026] [security2:error] [pid 215691:tid 215894] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/coffexium.php"] [unique_id "amu24gVxQfK7jpOg6v9SQQAAAEk"]
[Thu Jul 30 15:41:06.094355 2026] [security2:error] [pid 215691:tid 215894] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/coffexium.php"] [unique_id "amu24gVxQfK7jpOg6v9SQQAAAEk"]
[Thu Jul 30 15:41:06.333950 2026] [security2:error] [pid 215691:tid 215829] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/simple.php"] [unique_id "amu24gVxQfK7jpOg6v9SSAAAAAg"]
[Thu Jul 30 15:41:06.334088 2026] [security2:error] [pid 215691:tid 215829] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/simple.php"] [unique_id "amu24gVxQfK7jpOg6v9SSAAAAAg"]
[Thu Jul 30 15:41:06.436278 2026] [security2:error] [pid 215691:tid 215912] [client 172.213.208.20:17677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/wp-includes/js/index.php"] [unique_id "amu24gVxQfK7jpOg6v9SSQAAAFs"]
[Thu Jul 30 15:41:06.460196 2026] [security2:error] [pid 215691:tid 215911] [client 185.191.171.6:29798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/fact-sheet/"] [unique_id "amu24gVxQfK7jpOg6v9SSgAAAFo"]
[Thu Jul 30 15:41:06.460327 2026] [security2:error] [pid 215691:tid 215911] [client 185.191.171.6:29798] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/fact-sheet/"] [unique_id "amu24gVxQfK7jpOg6v9SSgAAAFo"]
[Thu Jul 30 15:41:06.577672 2026] [security2:error] [pid 215691:tid 215899] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fpwch.php"] [unique_id "amu24gVxQfK7jpOg6v9STAAAAE4"]
[Thu Jul 30 15:41:06.577828 2026] [security2:error] [pid 215691:tid 215899] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fpwch.php"] [unique_id "amu24gVxQfK7jpOg6v9STAAAAE4"]
[Thu Jul 30 15:41:06.767115 2026] [core:notice] [pid 215691:tid 215871] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:41:06.821575 2026] [security2:error] [pid 215691:tid 215931] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dex.php"] [unique_id "amu24gVxQfK7jpOg6v9SVwAAAG4"]
[Thu Jul 30 15:41:06.821714 2026] [security2:error] [pid 215691:tid 215931] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/dex.php"] [unique_id "amu24gVxQfK7jpOg6v9SVwAAAG4"]
[Thu Jul 30 15:41:07.060383 2026] [security2:error] [pid 215691:tid 215866] [client 4.184.185.91:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amu24wVxQfK7jpOg6v9SWAAAAC0"]
[Thu Jul 30 15:41:07.060490 2026] [security2:error] [pid 215691:tid 215866] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amu24wVxQfK7jpOg6v9SWAAAAC0"]
[Thu Jul 30 15:41:07.060600 2026] [security2:error] [pid 215691:tid 215866] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/1.php"] [unique_id "amu24wVxQfK7jpOg6v9SWAAAAC0"]
[Thu Jul 30 15:41:07.095492 2026] [security2:error] [pid 215691:tid 215740] [remote 97.74.93.24:39944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jgp.fxh.temporary.site"] [uri "/wp-login.php"] [unique_id "amu24wVxQfK7jpOg6v9SWQAARjA"]
[Thu Jul 30 15:41:07.125160 2026] [core:notice] [pid 215691:tid 215939] AH00113: /home1/vdbnyxte/public_html/website_b7115048/.htaccess:12 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:41:07.143088 2026] [core:notice] [pid 215691:tid 215750] AH00113: /home1/vdbnyxte/public_html/website_ab4e48f3/.htaccess:20 cannot use a full URL in a 401 ErrorDocument directive --- ignoring!
[Thu Jul 30 15:41:07.322387 2026] [proxy:error] [pid 215691:tid 215838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:41:07.322470 2026] [proxy_http:error] [pid 215691:tid 215838] [client 4.184.185.91:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:41:07.323433 2026] [proxy:error] [pid 215691:tid 215838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:41:07.323491 2026] [proxy_http:error] [pid 215691:tid 215838] [client 4.184.185.91:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:41:07.323605 2026] [security2:error] [pid 215691:tid 215838] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu24wVxQfK7jpOg6v9SZQAAABE"]
[Thu Jul 30 15:41:07.523632 2026] [security2:error] [pid 215691:tid 215901] [client 191.232.199.39:2563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-includes/Text/about.php"] [unique_id "amu24wVxQfK7jpOg6v9SaQAAAFA"]
[Thu Jul 30 15:41:07.566858 2026] [security2:error] [pid 215691:tid 215916] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/config.json.php"] [unique_id "amu24wVxQfK7jpOg6v9SagAAAF8"]
[Thu Jul 30 15:41:07.567038 2026] [security2:error] [pid 215691:tid 215916] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/config.json.php"] [unique_id "amu24wVxQfK7jpOg6v9SagAAAF8"]
[Thu Jul 30 15:41:07.802893 2026] [security2:error] [pid 215691:tid 215880] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/k2.php"] [unique_id "amu24wVxQfK7jpOg6v9ScwAAADs"]
[Thu Jul 30 15:41:07.803001 2026] [security2:error] [pid 215691:tid 215880] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/k2.php"] [unique_id "amu24wVxQfK7jpOg6v9ScwAAADs"]
[Thu Jul 30 15:41:08.050605 2026] [security2:error] [pid 215691:tid 215895] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/raw.php"] [unique_id "amu25AVxQfK7jpOg6v9SdQAAAEo"]
[Thu Jul 30 15:41:08.050715 2026] [security2:error] [pid 215691:tid 215895] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/raw.php"] [unique_id "amu25AVxQfK7jpOg6v9SdQAAAEo"]
[Thu Jul 30 15:41:08.292762 2026] [security2:error] [pid 215691:tid 215853] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp.php"] [unique_id "amu25AVxQfK7jpOg6v9SfQAAACA"]
[Thu Jul 30 15:41:08.292863 2026] [security2:error] [pid 215691:tid 215853] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/wp.php"] [unique_id "amu25AVxQfK7jpOg6v9SfQAAACA"]
[Thu Jul 30 15:41:08.296036 2026] [security2:error] [pid 215691:tid 215852] [client 216.244.66.230:56272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alseermarine.com"] [uri "/shop/"] [unique_id "amu25AVxQfK7jpOg6v9SfgAAAB8"]
[Thu Jul 30 15:41:08.296178 2026] [security2:error] [pid 215691:tid 215852] [client 216.244.66.230:56272] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.alseermarine.com"] [uri "/shop/"] [unique_id "amu25AVxQfK7jpOg6v9SfgAAAB8"]
[Thu Jul 30 15:41:08.537717 2026] [security2:error] [pid 215691:tid 215882] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fffm.php"] [unique_id "amu25AVxQfK7jpOg6v9SgwAAAD0"]
[Thu Jul 30 15:41:08.537825 2026] [security2:error] [pid 215691:tid 215882] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/fffm.php"] [unique_id "amu25AVxQfK7jpOg6v9SgwAAAD0"]
[Thu Jul 30 15:41:08.681422 2026] [security2:error] [pid 215691:tid 215909] [client 172.213.208.20:42209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.208.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.pkf.jo"] [uri "/go.php"] [unique_id "amu25AVxQfK7jpOg6v9ShAAAAFg"]
[Thu Jul 30 15:41:08.777872 2026] [security2:error] [pid 215691:tid 215867] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/111.php"] [unique_id "amu25AVxQfK7jpOg6v9SiAAAAC4"]
[Thu Jul 30 15:41:08.778032 2026] [security2:error] [pid 215691:tid 215867] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/111.php"] [unique_id "amu25AVxQfK7jpOg6v9SiAAAAC4"]
[Thu Jul 30 15:41:09.022013 2026] [proxy:error] [pid 215691:tid 215948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:41:09.022111 2026] [proxy_http:error] [pid 215691:tid 215948] [client 4.184.185.91:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:41:09.022951 2026] [proxy:error] [pid 215691:tid 215948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Thu Jul 30 15:41:09.023032 2026] [proxy_http:error] [pid 215691:tid 215948] [client 4.184.185.91:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Thu Jul 30 15:41:09.023157 2026] [security2:error] [pid 215691:tid 215948] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "amu25QVxQfK7jpOg6v9SkgAAAH8"]
[Thu Jul 30 15:41:09.272512 2026] [security2:error] [pid 215691:tid 215825] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ws.php"] [unique_id "amu25QVxQfK7jpOg6v9SkwAAAAQ"]
[Thu Jul 30 15:41:09.272613 2026] [security2:error] [pid 215691:tid 215825] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/ws.php"] [unique_id "amu25QVxQfK7jpOg6v9SkwAAAAQ"]
[Thu Jul 30 15:41:09.276321 2026] [security2:error] [pid 215691:tid 215922] [client 191.232.199.39:2615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/wp-admin.php"] [unique_id "amu25QVxQfK7jpOg6v9SlAAAAGU"]
[Thu Jul 30 15:41:09.323212 2026] [security2:error] [pid 215691:tid 215762] [remote 57.141.0.8:54096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejournalugj.com"] [uri "/index.php/Responsif/about/editorialTeam"] [unique_id "amu25QVxQfK7jpOg6v9SmAAAKEY"]
[Thu Jul 30 15:41:09.510129 2026] [security2:error] [pid 215691:tid 215917] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/coffee.php"] [unique_id "amu25QVxQfK7jpOg6v9SoAAAAGA"]
[Thu Jul 30 15:41:09.510229 2026] [security2:error] [pid 215691:tid 215917] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/coffee.php"] [unique_id "amu25QVxQfK7jpOg6v9SoAAAAGA"]
[Thu Jul 30 15:41:09.531389 2026] [security2:error] [pid 215691:tid 215766] [remote 57.141.0.45:32726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.0.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thdinfinity.com"] [uri "/search/432552404/feed/rss2/"] [unique_id "amu25QVxQfK7jpOg6v9SoQAAJUo"]
[Thu Jul 30 15:41:09.750542 2026] [security2:error] [pid 215691:tid 215926] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/goods.php"] [unique_id "amu25QVxQfK7jpOg6v9SowAAAGk"]
[Thu Jul 30 15:41:09.750660 2026] [security2:error] [pid 215691:tid 215926] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/goods.php"] [unique_id "amu25QVxQfK7jpOg6v9SowAAAGk"]
[Thu Jul 30 15:41:09.997986 2026] [security2:error] [pid 215691:tid 215887] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amu25QVxQfK7jpOg6v9SrQAAAEI"]
[Thu Jul 30 15:41:09.998107 2026] [security2:error] [pid 215691:tid 215887] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amu25QVxQfK7jpOg6v9SrQAAAEI"]
[Thu Jul 30 15:41:10.251166 2026] [security2:error] [pid 215691:tid 215901] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amu25gVxQfK7jpOg6v9SrgAAAFA"]
[Thu Jul 30 15:41:10.251276 2026] [security2:error] [pid 215691:tid 215901] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/about.php"] [unique_id "amu25gVxQfK7jpOg6v9SrgAAAFA"]
[Thu Jul 30 15:41:10.461593 2026] [security2:error] [pid 215691:tid 215844] [client 191.232.199.39:42607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.199.232.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radiojelli.com"] [uri "/size.php"] [unique_id "amu25gVxQfK7jpOg6v9StgAAABc"]
[Thu Jul 30 15:41:10.505538 2026] [security2:error] [pid 215691:tid 215898] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amu25gVxQfK7jpOg6v9SugAAAE0"]
[Thu Jul 30 15:41:10.505645 2026] [security2:error] [pid 215691:tid 215898] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/admin.php"] [unique_id "amu25gVxQfK7jpOg6v9SugAAAE0"]
[Thu Jul 30 15:41:10.761355 2026] [security2:error] [pid 215691:tid 215884] [client 4.184.185.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.185.184.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/inputs.php"] [unique_id "amu25gVxQfK7jpOg6v9SvAAAAD8"]
[Thu Jul 30 15:41:10.761512 2026] [security2:error] [pid 215691:tid 215884] [client 4.184.185.91:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.greecevisaassistanceislamabad.online"] [uri "/inputs.php"] [unique_id "amu25gVxQfK7jpOg6v9SvAAAAD8"]